[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH 9/9] x86/mwait-idle: Add C-states validation


  • To: Jan Beulich <jbeulich@xxxxxxxx>
  • From: Roger Pau Monné <roger.pau@xxxxxxxxxx>
  • Date: Fri, 24 Apr 2026 21:15:30 +0200
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=citrix.com; dmarc=pass action=none header.from=citrix.com; dkim=pass header.d=citrix.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=QHzQLGZqAPS6Un18SKcZpDDR3UEdvXn7IETSLm5u8h8=; b=uCSKl2f84tCXE7BAuT5u4kbyIYFwfEjxbe7cGKI1EqbFb1V+8CjQTVY7Dg5H4kqj65T5dA1GN1Ac4SKWeyT3c+Yb5j9/b2k9zlrbp2j4AIdqqDhWkRWfhNxAKInl9zzRckzbTgNQlk0xyMD7fiARchKDuvRBC7/fWOLM1A+arABK3m4A6SEBon6x+pVgUCkcGGYrivekGCr7n9wPe3LAmGmvNyyVQUXCF0kqgDQ+6IdLTYEc2HXGm1GbJhuYqsomCpopa/mGP0yH82KYD9puPuZwoUEY1dq4BLE7kwsiGJSBITIDXUylVJEDeVJsZETUyMeFKcteBRQRDYdKw1Euzg==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=ZzvKsK4R6MmIQHzdw4Cv5/SLeZbPrwYEqzrYmCn6bHWH80N0LlgaCVmH4j3SS4xVlZKrqP2XqvlqAwBRipo8PPhUlkOJ8HUn/70zRaDxODn01QWETwtjUoaDIUuil8U/PIEiNTXit9NtKrdsI3jaUaqB+p/c1Thh8Er3N9RnJGwvbsp4tG4rVdCLOwSSxiA3S5lsm5EQXVKuLjObLp+b5vk9C6dmlswSHEfnfqeUoWWAqVes1ncxxDQtAvsc7JrxL4Z4vby205WcJ/wwV9CWNgga9qm5s2eMu4poy9MiGuBds9/bChIL5B4RXhmzAJuxKFDJgeE2djOmoSltan+/Hw==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=citrix.com header.i="@citrix.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=citrix.com;
  • Cc: "xen-devel@xxxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxxx>, Andrew Cooper <andrew.cooper3@xxxxxxxxxx>
  • Delivery-date: Fri, 24 Apr 2026 19:15:41 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

On Thu, Mar 12, 2026 at 05:58:21PM +0100, Jan Beulich wrote:
> From: Artem Bityutskiy <artem.bityutskiy@xxxxxxxxxxxxxxx>
> 
> Add validation for C-states specified via the "table=" module parameter.
> Treat this module parameter as untrusted input and validate it thoroughly.
> 
> Signed-off-by: Artem Bityutskiy <artem.bityutskiy@xxxxxxxxxxxxxxx>
> Link: https://patch.msgid.link/20251216080402.156988-4-dedekind1@xxxxxxxxx
> Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@xxxxxxxxx>
> Origin: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 
> be6a150829b3
> 
> Add __init to validate_cmdline_cstate(). Other adjustments to fit our env.
> 
> Signed-off-by: Jan Beulich <jbeulich@xxxxxxxx>
> 
> --- a/xen/arch/x86/cpu/mwait-idle.c
> +++ b/xen/arch/x86/cpu/mwait-idle.c
> @@ -72,6 +72,11 @@ boolean_param("mwait-idle", opt_mwait_id
>  
>  /* The maximum allowed length for the 'table' module parameter  */
>  #define MAX_CMDLINE_TABLE_LEN 256
> +/* Maximum allowed C-state latency */
> +#define MAX_CMDLINE_LATENCY_US (5 * 1000 /* USEC_PER_MSEC */)
> +/* Maximum allowed C-state target residency */
> +#define MAX_CMDLINE_RESIDENCY_US (100 * 1000 /* USEC_PER_MSEC */)
> +
>  static char cmdline_table_str[MAX_CMDLINE_TABLE_LEN] __initdata;
>  string_param("mwait-idle.table", cmdline_table_str);
>  
> @@ -1589,6 +1594,41 @@ static char *__init get_cmdline_field(ch
>  }
>  
>  /**
> + * validate_cmdline_cstate - Validate a C-state from cmdline.
> + * @state: The C-state to validate.
> + * @prev_state: The previous C-state in the table or NULL.
> + *
> + * Return: 0 if the C-state is valid or -EINVAL otherwise.

Hm, I know we picked this up from upstream, but this function would
better return a boolean, rather than 0 or -EINVAL.

> + */
> +static int __init validate_cmdline_cstate(struct cpuidle_state *state,
> +                                       struct cpuidle_state *prev_state)
> +{
> +     if (state->exit_latency == 0)
> +             /* Exit latency 0 can only be used for the POLL state */
> +             return -EINVAL;
> +
> +     if (state->exit_latency > MAX_CMDLINE_LATENCY_US)
> +             return -EINVAL;
> +
> +     if (state->target_residency > MAX_CMDLINE_RESIDENCY_US)
> +             return -EINVAL;
> +
> +     if (state->target_residency < state->exit_latency)
> +             return -EINVAL;
> +
> +     if (!prev_state)
> +             return 0;
> +
> +     if (state->exit_latency <= prev_state->exit_latency)
> +             return -EINVAL;
> +
> +     if (state->target_residency <= prev_state->target_residency)
> +             return -EINVAL;

I'm not an expert on C-states, but isn't this checking against the
previous value kind of defeating part of the purpose of the command
line?

Also, it might help to also write down those limits in the command
line documentation.

Thanks, Roger.



 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.