From nobody Tue Dec 30 13:26:57 2025 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2DFD6C47075 for ; Wed, 15 Nov 2023 03:23:57 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234368AbjKODX6 (ORCPT ); Tue, 14 Nov 2023 22:23:58 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:48724 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S234348AbjKODX4 (ORCPT ); Tue, 14 Nov 2023 22:23:56 -0500 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 4FCDCD5; Tue, 14 Nov 2023 19:23:53 -0800 (PST) Date: Wed, 15 Nov 2023 03:23:50 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1700018631; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=pdCBWbh2ujnjFYIEsg2mtFEUG5LGXDTFpqB0nUoHOiA=; b=vkJoX7AQ367Y3jzFVsmGbaH+hcL0FsZrc1PtMBNAaisgFXgkGJQIGs3l6weRi61vxksxn1 YBMP2IpeduQbZBK/ZaBmQ2fS4du73NWu3thm76MIQVCrmpEJBhxsCBWh5mq01DkBQZGVzf 7gBX/pDXL5XaeTUxh4HdCAlta5ahBD1X7w9jxxeE4RMyA3/h5yyo2bOXFvZ0UhAF47J0ri Vae0nYN9TcOwL5vOFK4aALVUXo932lk0heRdbl7mQZUNrmpHVo8StJxLWb/hUJm6MYBROi SY41LjXC3vWYNxCJU3Qo30e+eHe2GZxrOY1kXQe4PyxQ3pjc+p9Eq6cJhX3oog== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1700018631; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=pdCBWbh2ujnjFYIEsg2mtFEUG5LGXDTFpqB0nUoHOiA=; b=yKxcv1WyXTEMNfaNHFL6bEwzIC4/2fMpbd2DIAuXstYaOCobpezimWbrj8MhpHluQUSUW7 Wh8TVJ0DPLx9dXCA== From: "tip-bot2 for Peter Zijlstra" Sender: tip-bot2@linutronix.de Reply-to: linux-kernel@vger.kernel.org To: linux-tip-commits@vger.kernel.org Subject: [tip: perf/urgent] perf/core: Fix cpuctx refcounting Cc: "Peter Zijlstra (Intel)" , Ingo Molnar , , x86@kernel.org, linux-kernel@vger.kernel.org In-Reply-To: <20230612093539.085862001@infradead.org> References: <20230612093539.085862001@infradead.org> MIME-Version: 1.0 Message-ID: <170001863083.391.17242045529374846563.tip-bot2@tip-bot2> Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org The following commit has been merged into the perf/urgent branch of tip: Commit-ID: 889c58b3155ff4c8e8671c95daef63d6fabbb6b1 Gitweb: https://git.kernel.org/tip/889c58b3155ff4c8e8671c95daef63d6f= abbb6b1 Author: Peter Zijlstra AuthorDate: Fri, 09 Jun 2023 12:34:46 +02:00 Committer: Ingo Molnar CommitterDate: Wed, 15 Nov 2023 04:18:31 +01:00 perf/core: Fix cpuctx refcounting Audit of the refcounting turned up that perf_pmu_migrate_context() fails to migrate the ctx refcount. Fixes: bd2756811766 ("perf: Rewrite core context handling") Signed-off-by: Peter Zijlstra (Intel) Signed-off-by: Ingo Molnar Link: https://lkml.kernel.org/r/20230612093539.085862001@infradead.org Cc: --- include/linux/perf_event.h | 13 ++++++++----- kernel/events/core.c | 17 +++++++++++++++++ 2 files changed, 25 insertions(+), 5 deletions(-) diff --git a/include/linux/perf_event.h b/include/linux/perf_event.h index afb028c..5547ba6 100644 --- a/include/linux/perf_event.h +++ b/include/linux/perf_event.h @@ -843,11 +843,11 @@ struct perf_event { }; =20 /* - * ,-----------------------[1:n]----------------------. - * V V - * perf_event_context <-[1:n]-> perf_event_pmu_context <--- perf_event - * ^ ^ | | - * `--------[1:n]---------' `-[n:1]-> pmu <-[1:n]-' + * ,-----------------------[1:n]------------------------. + * V V + * perf_event_context <-[1:n]-> perf_event_pmu_context <-[1:n]- perf_event + * | | + * `--[n:1]-> pmu <-[1:n]--' * * * struct perf_event_pmu_context lifetime is refcount based and RCU freed @@ -865,6 +865,9 @@ struct perf_event { * ctx->mutex pinning the configuration. Since we hold a reference on * group_leader (through the filedesc) it can't go away, therefore it's * associated pmu_ctx must exist and cannot change due to ctx->mutex. + * + * perf_event holds a refcount on perf_event_context + * perf_event holds a refcount on perf_event_pmu_context */ struct perf_event_pmu_context { struct pmu *pmu; diff --git a/kernel/events/core.c b/kernel/events/core.c index 683dc08..b704d83 100644 --- a/kernel/events/core.c +++ b/kernel/events/core.c @@ -4828,6 +4828,11 @@ find_get_pmu_context(struct pmu *pmu, struct perf_ev= ent_context *ctx, void *task_ctx_data =3D NULL; =20 if (!ctx->task) { + /* + * perf_pmu_migrate_context() / __perf_pmu_install_event() + * relies on the fact that find_get_pmu_context() cannot fail + * for CPU contexts. + */ struct perf_cpu_pmu_context *cpc; =20 cpc =3D per_cpu_ptr(pmu->cpu_pmu_context, event->cpu); @@ -12889,6 +12894,9 @@ static void __perf_pmu_install_event(struct pmu *pm= u, int cpu, struct perf_event *event) { struct perf_event_pmu_context *epc; + struct perf_event_context *old_ctx =3D event->ctx; + + get_ctx(ctx); /* normally find_get_context() */ =20 event->cpu =3D cpu; epc =3D find_get_pmu_context(pmu, ctx, event); @@ -12897,6 +12905,11 @@ static void __perf_pmu_install_event(struct pmu *p= mu, if (event->state >=3D PERF_EVENT_STATE_OFF) event->state =3D PERF_EVENT_STATE_INACTIVE; perf_install_in_context(ctx, event, cpu); + + /* + * Now that event->ctx is updated and visible, put the old ctx. + */ + put_ctx(old_ctx); } =20 static void __perf_pmu_install(struct perf_event_context *ctx, @@ -12935,6 +12948,10 @@ void perf_pmu_migrate_context(struct pmu *pmu, int= src_cpu, int dst_cpu) struct perf_event_context *src_ctx, *dst_ctx; LIST_HEAD(events); =20 + /* + * Since per-cpu context is persistent, no need to grab an extra + * reference. + */ src_ctx =3D &per_cpu_ptr(&perf_cpu_context, src_cpu)->ctx; dst_ctx =3D &per_cpu_ptr(&perf_cpu_context, dst_cpu)->ctx;