当前位置:首页>Linux>Linux Kernel PM 子系统周报 | 2026-06-15 ~ 2026-06-28

Linux Kernel PM 子系统周报 | 2026-06-15 ~ 2026-06-28

  • 2026-10-11 05:39:48
Linux Kernel PM 子系统周报 | 2026-06-15 ~ 2026-06-28

Linux Kernel PM 周报

2026-06-15 ~ 2026-06-28 · linux-next

6 commits

一、本周变更总览

ACPI

4

FIXACPICA: Unbreak tools build after switching over to strscpy_pad() 292db66afd20▸ 修复 ACPICA 工具在切换到 strscpy_pad() 后的构建问题,确保编译正常通过

Rafael J. Wysocki

FIXACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() 71b57aca295d▸ 修复 ipmi_bmc_gone() 中接口匹配逻辑反转的 bug:重构时 != 未同步改为 ==,导致 BMC 消失时错误移除其他接口

Xu Rao

OTHERACPI: resource: Amend kernel-doc style 78ad5c7722b7▸ 修正 ACPI 资源模块 kernel-doc 中函数引用格式,将常量标记从 func() 改为 %func() 以正确渲染

Andy Shevchenko

FIXACPI: sysfs: Fix path of module parameters in comments b2b42ad22828▸ 修正 ACPI sysfs 注释中模块参数路径为正确的 /sys/module/acpi/parameters/xxx

Zenghui Yu

thermal

2

OTHERthermal: testing: zone: Flush work items during cleanup fb1a5dfe86d3▸ 修复 thermal testing 模块中 zone 清理时未 flush work items 的问题,避免残留工作项导致异常

Rafael J. Wysocki

FIXthermal: intel: Fix dangling resources on thermal_throttle_online b91d287fa7a1▸ 修复 thermal_throttle_online() 失败时资源泄漏:将可能失败的调用提前,避免后续资源无法释放

Ricardo Neri

二、重要补丁详细分析

严重 bugACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() 71b57aca295d

问题根因

在提交 a1a69b297e47 重构 ipmi_bmc_gone() 时,将原来的 if (ipmi_ifnum != iface) continue; __ipmi_dev_kill(iter); 模式合并为单条件判断,但忘记将 != 改为 ==。这导致语义完全反转:原本「跳过不匹配的、处理匹配的」变成了「处理不匹配的、跳过匹配的」。

实际影响

当 BMC 消失时,ipmi_bmc_gone() 会错误地移除第一个接口号不匹配的设备,而真正应该被移除的设备却留在链表中。这个残留条目未被标记为 dead,可能继续被选中执行 ACPI IPMI 事务,还会阻止同一 ACPI handle 重新注册。

代码变更

关键 diff

@@ -490,7 +490,7 @@ static void ipmi_bmc_gone(int iface)     mutex_lock(&driver_data.ipmi_lock);     list_for_each_entry_safe(iter, temp,                  &driver_data.ipmi_devices, head) {-        if (iter->ipmi_ifnum != iface) {+        if (iter->ipmi_ifnum == iface) {             ipmi_device = iter;             __ipmi_dev_kill(iter);             break;

安全修复thermal: testing: zone: Flush work items during cleanup fb1a5dfe86d3

问题背景

thermal testing 模块通过 debugfs 接口接收命令并异步执行。模块卸载时,如果有正在执行的 work item 尚未完成,模块代码被释放后 work item 回调仍会执行,导致 use-after-free。此问题由 Trail of Bits 安全审计发现并报告。

修复方案

新增专用工作队列 tt_wq,所有 thermal testing 命令都提交到这个队列。模块退出时:① 先移除 debugfs 文件阻止新命令输入;② flush_workqueue() 等待进行中的命令完成;③ destroy_workqueue() 销毁工作队列。同时完善了 init 函数的错误处理路径(goto 链)。

代码变更

关键 diff

static int __init thermal_testing_init(void) {+    int error;+    tt_wq = alloc_workqueue("thermal_testing", WQ_UNBOUND, 0);+    if (!tt_wq)+        return -ENOMEM;+     d_testing = debugfs_create_dir("thermal-testing", NULL);-    if (!IS_ERR(d_testing))-        debugfs_create_file("command", 0200, ...);+    if (IS_ERR(d_testing)) { error = PTR_ERR(d_testing); goto destroy_wq; }+    d_command = debugfs_create_file("command", ...);+    if (IS_ERR(d_command)) { error = PTR_ERR(d_command); goto remove_d_testing; }     return 0;+remove_d_testing: 

+    debugfs_remove(d_testing);
+destroy_wq: 
+    destroy_workqueue(tt_wq); 
+    return error;
 } static void __exit thermal_testing_exit(void) {+    debugfs_remove(d_command);  /* 阻止新命令 */+    flush_workqueue(tt_wq);     /* 等待进行中命令 */+    destroy_workqueue(tt_wq);   /* 销毁工作队列 */
资源泄漏thermal: intel: Fix dangling resources on thermal_throttle_online b91d287fa7a1

问题背景

thermal_throttle_online() 是 CPU hotplug 的 online 回调。如果该回调失败,hotplug 框架不会调用对应的 offline 回调来清理已分配资源。原代码将可能失败的 thermal_throttle_add_dev() 放在函数末尾,此时 throttle level 设置、sysfs 属性注册、APIC LVT 配置等已完成,一旦失败这些资源就会泄漏。

修复方案

将 thermal_throttle_add_dev() 移到函数最前面。由于它是唯一可能失败的步骤,此时还没分配其他资源,失败直接返回错误码即可,不存在泄漏问题。

代码变更

关键 diff

@@ -529,8 +529,13 @@ static int thermal_throttle_online(unsigned int cpu) {     struct thermal_state *state = &per_cpu(thermal_state, cpu);     struct device *dev = get_cpu_device(cpu);+    int err;     u32 l;+    /* 先调用可能失败的函数,此时还未分配其他资源 */+    err = thermal_throttle_add_dev(dev, cpu);+    if (err)+        return err;+     state->package_throttle.level = PACKAGE_LEVEL;     state->core_throttle.level = CORE_LEVEL;     ...@@ -548,7 +553,7 @@ static int thermal_throttle_online(unsigned int cpu)     l = apic_read(APIC_LVTTHMR);     apic_write(APIC_LVTTHMR, l & ~APIC_LVT_MASKED);-    return thermal_throttle_add_dev(dev, cpu);  /* 原:最后调用,失败时前面资源已泄漏 */+    return err;  /* 改:直接返回,前面不会失败 */ }

构建修复ACPICA: Unbreak tools build after switching over to strscpy_pad() 292db66afd20

问题背景

提交 97f7d3f9c9ac 将 acpi_ut_safe_strncpy() 从 strncpy() + 手动 NUL 终止切换为 strscpy_pad()。但 strscpy_pad() 是内核专有函数,ACPICA 工具(如 acpidump)在用户空间编译时没有该函数定义,导致构建失败。

修复方案

通过 #ifdef __KERNEL__ 条件编译区分:内核中继续使用 strscpy_pad();工具构建时回退到 strncpy() + 手动终止。

代码变更

关键 diff

@@ -168,7 +168,16 @@ void acpi_ut_safe_strncpy(...) {     /* Always terminate destination string */+#ifdef __KERNEL__     strscpy_pad(dest, source, dest_size);+#else+    /*+     * strscpy_pad() is not defined in ACPICA tools builds,+     * so use strncpy() and directly NUL-terminate.+     */+    strncpy(dest, source, dest_size);+    dest[dest_size - 1] = 0;+#endif }

linux-pm-ribao 自动生成

最新文章

随机文章