Making The Keyboard Funky - #1
Open
yungFundamental wants to merge 3 commits into
Open
Conversation
yungFundamental
pushed a commit
that referenced
this pull request
Jul 19, 2026
…prio-multiq' Bryam Vargas says: ==================== net/sched: finish the qdisc_dequeue_peeked conversion (taprio, multiq) Commit 77be155 added peek emulation: a non-work-conserving qdisc's ->peek dequeues one skb and stashes it in the child's gso_skb. A parent that peeks such a child must then take the packet with qdisc_dequeue_peeked(), not a direct ->dequeue(), or the stashed skb is bypassed and the child's qlen/backlog desync. sch_red and sch_sfb were just fixed for this; taprio and multiq still take the direct path. With a qfq child the desync re-enters qfq_dequeue on an emptied aggregate list and dereferences NULL, panicking from softirq on ordinary egress. taprio reaches it on its own (root-only software path, all gates open); multiq reaches it when a peeking parent such as tbf wraps it over a non-work-conserving grandchild. Both need only CAP_NET_ADMIN. Confirmed under KASAN: the unpatched arm panics, the patched arm is clean, and a work-conserving-child control is clean. The reproducers and splats for both are below; the per-patch changes are one line each. taprio reproducer (self-triggering, no parent qdisc needed): ip link add dummy0 numtxqueues 4 type dummy; ip link set dummy0 up ip addr add 10.10.11.10/24 dev dummy0 tc qdisc add dev dummy0 root handle 1: taprio num_tc 2 \ map 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 queues 1@0 1@1 \ base-time 9000000000000000000 sched-entry S 03 200000 flags 0x0 clockid CLOCK_TAI tc qdisc replace dev dummy0 parent 1:1 handle 3: qfq tc class add dev dummy0 classid 3:1 parent 3: qfq maxpkt 512 weight 1 tc filter add dev dummy0 parent 3: protocol ip prio 1 matchall classid 3:1 ping -c1 10.10.11.99 -I dummy0 [ 903.769174] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000009: 0000 [#1] SMP KASAN NOPTI [ 903.769953] KASAN: null-ptr-deref in range [0x0000000000000048-0x000000000000004f] [ 903.770456] CPU: 7 UID: 0 PID: 16162 Comm: ping Not tainted 7.1.0-rc5 #1 PREEMPT(lazy) [ 903.771725] RIP: 0010:qfq_dequeue+0x362/0x1580 [sch_qfq] [ 903.777452] Call Trace: [ 903.778311] taprio_dequeue_from_txq+0x383/0x680 [sch_taprio] [ 903.778685] taprio_dequeue_tc_priority+0x19a/0x330 [sch_taprio] [ 903.779645] taprio_dequeue+0xa6/0x330 [sch_taprio] [ 903.780299] __qdisc_run+0x16c/0x1890 [ 903.780854] __dev_queue_xmit+0x1ece/0x3390 [ 903.784109] ip_finish_output2+0x571/0x1da0 [ 903.785996] ip_output+0x26c/0x4d0 [ 903.789572] ping_v4_sendmsg+0xd22/0x12b0 [ 903.796118] __x64_sys_sendto+0xe0/0x1c0 [ 903.796612] do_syscall_64+0xee/0x590 [ 903.818669] Kernel panic - not syncing: Fatal exception in interrupt multiq reproducer (needs a peeking parent over a stashing child; tbf values chosen to force it to throttle): ip link add dummy0 numtxqueues 2 type dummy; ip link set dummy0 up ip addr add 10.10.11.10/24 dev dummy0 tc qdisc add dev dummy0 root handle 1: tbf rate 88bit burst 1661b \ peakrate 2257333 minburst 1024 limit 7b tc qdisc add dev dummy0 parent 1: handle 2: multiq for b in 1 2; do # qfq on every band tc qdisc add dev dummy0 parent 2:$b handle 3$b: qfq tc class add dev dummy0 classid 3$b:1 parent 3$b: qfq maxpkt 512 weight 1 tc filter add dev dummy0 parent 3$b: protocol ip prio 1 matchall classid 3$b:1 done ping -c12 10.10.11.99 -I dummy0 [ 1066.385097] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000009: 0000 [#1] SMP KASAN NOPTI [ 1066.386385] KASAN: null-ptr-deref in range [0x0000000000000048-0x000000000000004f] [ 1066.387227] CPU: 1 UID: 0 PID: 5357 Comm: ping Not tainted 7.1.0-rc5 #1 PREEMPT(lazy) [ 1066.389183] RIP: 0010:qfq_dequeue+0x362/0x1580 [sch_qfq] [ 1066.396316] Call Trace: [ 1066.396768] multiq_dequeue+0x163/0x360 [sch_multiq] [ 1066.397885] tbf_dequeue+0x6b9/0xf17 [sch_tbf] [ 1066.398269] __qdisc_run+0x16c/0x1890 [ 1066.399315] __dev_queue_xmit+0x1ece/0x3390 [ 1066.403276] ip_finish_output2+0x571/0x1da0 [ 1066.404818] ip_output+0x26c/0x4d0 [ 1066.408620] ping_v4_sendmsg+0xd22/0x12b0 [ 1066.415264] __x64_sys_sendto+0xe0/0x1c0 [ 1066.416251] do_syscall_64+0xee/0x590 [ 1066.441210] Kernel panic - not syncing: Fatal exception in interrupt ==================== Link: https://patch.msgid.link/20260625-b4-disp-31bcb279-v1-0-85c40b83c529@proton.me Signed-off-by: Jakub Kicinski <kuba@kernel.org>
yungFundamental
pushed a commit
that referenced
this pull request
Jul 19, 2026
Call rcu_barrier() in module exit to wait for outstanding call_rcu() callbacks before freeing module text, preventing late callback execution in freed memory. BUG: unable to handle page fault for address: ffffffffc1d59c40 PGD 6a12067 P4D 6a12067 PUD 6a14067 PMD 13698b067 PTE 0 Oops: 0010 [#1] SMP NOPTI RIP: 0010:0xffffffffc1d59c40 Code: Unable to access opcode bytes at RIP 0xffffffffc1d59c16. RSP: 0018:ffffc900198c0f28 EFLAGS: 00010286 RAX: ffffffffc1d59c40 RBX: ffff897c7d6b61c0 RCX: ffff88826aff4590 RDX: ffff8884d8b35490 RSI: ffffc900198c0f30 RDI: ffff88812af67290 RBP: 000000000000000a (DONE segment entries) R08: 0000000000000000 R09: 0000000000000100 R10: 0000000000000000 R11: ffffffff82a06100 R12: ffff88811a4e3700 R13: 0000000000000000 R14: ffff897c7d6b6270 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff897c7d680000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: ffffffffc1d59c16 CR3: 00000104a980a001 CR4: 0000000002770ee0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400 PKRU: 55555554 Call Trace: <IRQ> ? rcu_do_batch+0x163/0x450 ? rcu_core+0x177/0x1c0 ? __do_softirq+0xc1/0x280 ? asm_call_irq_on_stack+0xf/0x20 </IRQ> ? do_softirq_own_stack+0x37/0x50 ? irq_exit_rcu+0xc4/0x100 ? sysvec_apic_timer_interrupt+0x36/0x80 ? asm_sysvec_apic_timer_interrupt+0x12/0x20 ? cpuidle_enter_state+0xd4/0x360 ? cpuidle_enter+0x29/0x40 ? cpuidle_idle_call+0x108/0x1a0 ? do_idle+0x77/0xf0 ? cpu_startup_entry+0x19/0x20 ? secondary_startup_64_no_verify+0xbf/0xcb Signed-off-by: Perry Yuan <perry.yuan@amd.com> Reviewed-by: Yifan Zhang <yifan1.zhang@amd.com> Reviewed-by: Christian König <christian.koenig@amd.com> Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
yungFundamental
pushed a commit
that referenced
this pull request
Jul 19, 2026
Call rcu_barrier() in module exit to wait for outstanding call_rcu() callbacks before freeing module text, preventing late callback execution in freed memory. BUG: unable to handle page fault for address: ffffffffc1d59c40 PGD 6a12067 P4D 6a12067 PUD 6a14067 PMD 13698b067 PTE 0 Oops: 0010 [#1] SMP NOPTI RIP: 0010:0xffffffffc1d59c40 Code: Unable to access opcode bytes at RIP 0xffffffffc1d59c16. RSP: 0018:ffffc900198c0f28 EFLAGS: 00010286 RAX: ffffffffc1d59c40 RBX: ffff897c7d6b61c0 RCX: ffff88826aff4590 RDX: ffff8884d8b35490 RSI: ffffc900198c0f30 RDI: ffff88812af67290 RBP: 000000000000000a (DONE segment entries) R08: 0000000000000000 R09: 0000000000000100 R10: 0000000000000000 R11: ffffffff82a06100 R12: ffff88811a4e3700 R13: 0000000000000000 R14: ffff897c7d6b6270 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff897c7d680000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: ffffffffc1d59c16 CR3: 00000104a980a001 CR4: 0000000002770ee0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400 PKRU: 55555554 Call Trace: <IRQ> ? rcu_do_batch+0x163/0x450 ? rcu_core+0x177/0x1c0 ? __do_softirq+0xc1/0x280 ? asm_call_irq_on_stack+0xf/0x20 </IRQ> ? do_softirq_own_stack+0x37/0x50 ? irq_exit_rcu+0xc4/0x100 ? sysvec_apic_timer_interrupt+0x36/0x80 ? asm_sysvec_apic_timer_interrupt+0x12/0x20 ? cpuidle_enter_state+0xd4/0x360 ? cpuidle_enter+0x29/0x40 ? cpuidle_idle_call+0x108/0x1a0 ? do_idle+0x77/0xf0 ? cpu_startup_entry+0x19/0x20 ? secondary_startup_64_no_verify+0xbf/0xcb Signed-off-by: Perry Yuan <perry.yuan@amd.com> Reviewed-by: Yifan Zhang <yifan1.zhang@amd.com> Reviewed-by: Christian König <christian.koenig@amd.com> Signed-off-by: Alex Deucher <alexander.deucher@amd.com> (cherry picked from commit feaa503)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Altered the keycode-scancode mapping to make each key represent the key to the right, wrapping around.
Altered at the atkbd driver level.