From nobody Tue Feb 10 12:42:37 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6FB541DF759; Tue, 20 Jan 2026 01:09:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768871378; cv=none; b=S8gcDELs/dGDRdF5l4FE7VoYxr260zrQB27hn4ZXYdEdb5FRoaOc0AxN+H26401BINw4lPRBEq9VMFBVL2TCXgMHO5c6On/kKMiSXgH+2iiD+I2uQ4tu5nxCCM7zxTyaoZ1SVM9Z4zWhycVwRmAwifxKv0zZ5acvdE/p7TT/TJc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768871378; c=relaxed/simple; bh=02uMh0DSJHWfU5iNanMhWiCifsZ88h4j/+7JbgwiCqs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=lECizu3igz+sTZ/44bz4z+2A1FxtVmGeB36RjFGiWGElp0qqlOBSG6fs6I6DYUVrlI9aH593PlZuUi/qPmFfgNQXy+nPpgRqg5OQ4z3ag8VmO7/pI5GB0Yc9KJvDkCtA60bKLn4mSlsNYIpyZKegt6/mVZUjvY4HwGRRnc71UPo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=VCA0LvZj; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="VCA0LvZj" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 4C5AEC116C6; Tue, 20 Jan 2026 01:09:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1768871378; bh=02uMh0DSJHWfU5iNanMhWiCifsZ88h4j/+7JbgwiCqs=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=VCA0LvZjQ9Y76iGrknKtUVrgcvsCWRR7G3/mnqDFnbw6oqC+OB2mu+g+S+R2PibRw 2LfkTwt0ccB927QY/2EfspG5dmvw5833h655Q10L2KLA3K8xXveLv54dcR5ecDYe4i GaCAv/spxoVgB/GD44hI5JAbZoIl1rIlWYDKmEo4DALs3xluRJzZVNsICel+VWg9mm aXTgVCR6PRkQmSWr9TJwMjnzh5uzQm3gaMsiNzS7l0WAv4xSOOOXt6GqkAqZd04mQY OGS2uklTcmjC6mB+ZZ+3fZTmmMS8rRy840xIvF2ZaR1+P/dJyhTb3iHZ71f899u0HI SK9GaLdJQPDsQ== From: "Masami Hiramatsu (Google)" To: Steven Rostedt Cc: Masami Hiramatsu , Mathieu Desnoyers , linux-kernel@vger.kernel.org, linux-trace-kernel@vger.kernel.org Subject: [PATCH v4 2/4] tracing: Make the backup instance non-reusable Date: Tue, 20 Jan 2026 10:09:35 +0900 Message-ID: <176887137556.578403.17994205756247311821.stgit@mhiramat.tok.corp.google.com> X-Mailer: git-send-email 2.52.0.457.g6b5491de43-goog In-Reply-To: <176887135615.578403.6988045330349053692.stgit@mhiramat.tok.corp.google.com> References: <176887135615.578403.6988045330349053692.stgit@mhiramat.tok.corp.google.com> User-Agent: StGit/0.19 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Masami Hiramatsu (Google) Since there is no reason to reuse the backup instance, make it readonly (but erasable). Note that only backup instances are readonly, because other trace instances will be empty unless it is writable. Only backup instances have copy entries from the original. With this change, most of the trace control files are removed from the backup instance, including eventfs enable/filter etc. # find /sys/kernel/tracing/instances/backup/events/ | wc -l 4093 # find /sys/kernel/tracing/instances/boot_map/events/ | wc -l 9573 Signed-off-by: Masami Hiramatsu (Google) --- Changes in v4: - Make trace data erasable. (not reusable) Changes in v3: - Resuse the beginning part of event_entries for readonly files. - Remove readonly file_operations and checking readonly flag in each write operation. Changes in v2: - Use readonly file_operations to prohibit writing instead of checking flags in write() callbacks. - Remove writable files from eventfs. --- kernel/trace/trace.c | 93 ++++++++++++++++++++++++++++++---------= ---- kernel/trace/trace.h | 8 +++- kernel/trace/trace_boot.c | 5 +- kernel/trace/trace_events.c | 68 +++++++++++++++++++------------ 4 files changed, 117 insertions(+), 57 deletions(-) diff --git a/kernel/trace/trace.c b/kernel/trace/trace.c index 5ddaeced9cb3..b27e1cdeffb0 100644 --- a/kernel/trace/trace.c +++ b/kernel/trace/trace.c @@ -5034,6 +5034,11 @@ static ssize_t tracing_write_stub(struct file *filp, const char __user *ubuf, size_t count, loff_t *ppos) { + struct trace_array *tr =3D file_inode(filp)->i_private; + + if (trace_array_is_readonly(tr)) + return -EPERM; + return count; } =20 @@ -5134,6 +5139,9 @@ tracing_cpumask_write(struct file *filp, const char _= _user *ubuf, cpumask_var_t tracing_cpumask_new; int err; =20 + if (trace_array_is_readonly(tr)) + return -EPERM; + if (count =3D=3D 0 || count > KMALLOC_MAX_SIZE) return -EINVAL; =20 @@ -6418,6 +6426,9 @@ tracing_set_trace_write(struct file *filp, const char= __user *ubuf, size_t ret; int err; =20 + if (trace_array_is_readonly(tr)) + return -EPERM; + ret =3D cnt; =20 if (cnt > MAX_TRACER_SIZE) @@ -7052,6 +7063,9 @@ tracing_entries_write(struct file *filp, const char _= _user *ubuf, unsigned long val; int ret; =20 + if (trace_array_is_readonly(tr)) + return -EPERM; + ret =3D kstrtoul_from_user(ubuf, cnt, 10, &val); if (ret) return ret; @@ -7806,6 +7820,9 @@ static ssize_t tracing_clock_write(struct file *filp,= const char __user *ubuf, const char *clockstr; int ret; =20 + if (trace_array_is_readonly(tr)) + return -EPERM; + if (cnt >=3D sizeof(buf)) return -EINVAL; =20 @@ -9360,12 +9377,16 @@ static void tracing_init_tracefs_percpu(struct trace_array *tr, long cpu) { struct dentry *d_percpu =3D tracing_dentry_percpu(tr, cpu); + umode_t writable_mode =3D TRACE_MODE_WRITE; struct dentry *d_cpu; char cpu_dir[30]; /* 30 characters should be more than enough */ =20 if (!d_percpu) return; =20 + if (trace_array_is_readonly(tr)) + writable_mode =3D TRACE_MODE_READ; + snprintf(cpu_dir, 30, "cpu%ld", cpu); d_cpu =3D tracefs_create_dir(cpu_dir, d_percpu); if (!d_cpu) { @@ -9588,7 +9609,6 @@ struct dentry *trace_create_file(const char *name, return ret; } =20 - static struct dentry *trace_options_init_dentry(struct trace_array *tr) { struct dentry *d_tracer; @@ -9818,6 +9838,9 @@ rb_simple_write(struct file *filp, const char __user = *ubuf, unsigned long val; int ret; =20 + if (trace_array_is_readonly(tr)) + return -EPERM; + ret =3D kstrtoul_from_user(ubuf, cnt, 10, &val); if (ret) return ret; @@ -9924,6 +9947,9 @@ buffer_subbuf_size_write(struct file *filp, const cha= r __user *ubuf, int pages; int ret; =20 + if (trace_array_is_readonly(tr)) + return -EPERM; + ret =3D kstrtoul_from_user(ubuf, cnt, 10, &val); if (ret) return ret; @@ -10604,17 +10630,23 @@ static __init void create_trace_instances(struct = dentry *d_tracer) static void init_tracer_tracefs(struct trace_array *tr, struct dentry *d_tracer) { + umode_t writable_mode =3D TRACE_MODE_WRITE; + bool readonly =3D trace_array_is_readonly(tr); int cpu; =20 + if (readonly) + writable_mode =3D TRACE_MODE_READ; + trace_create_file("available_tracers", TRACE_MODE_READ, d_tracer, - tr, &show_traces_fops); + tr, &show_traces_fops); =20 - trace_create_file("current_tracer", TRACE_MODE_WRITE, d_tracer, - tr, &set_tracer_fops); + trace_create_file("current_tracer", writable_mode, d_tracer, + tr, &set_tracer_fops); =20 - trace_create_file("tracing_cpumask", TRACE_MODE_WRITE, d_tracer, + trace_create_file("tracing_cpumask", writable_mode, d_tracer, tr, &tracing_cpumask_fops); =20 + /* Options are used for changing print-format even for readonly instance.= */ trace_create_file("trace_options", TRACE_MODE_WRITE, d_tracer, tr, &tracing_iter_fops); =20 @@ -10624,27 +10656,35 @@ init_tracer_tracefs(struct trace_array *tr, struc= t dentry *d_tracer) trace_create_file("trace_pipe", TRACE_MODE_READ, d_tracer, tr, &tracing_pipe_fops); =20 - trace_create_file("buffer_size_kb", TRACE_MODE_WRITE, d_tracer, + trace_create_file("buffer_size_kb", writable_mode, d_tracer, tr, &tracing_entries_fops); =20 trace_create_file("buffer_total_size_kb", TRACE_MODE_READ, d_tracer, tr, &tracing_total_entries_fops); =20 - trace_create_file("free_buffer", 0200, d_tracer, - tr, &tracing_free_buffer_fops); + if (!readonly) { + trace_create_file("free_buffer", 0200, d_tracer, + tr, &tracing_free_buffer_fops); =20 - trace_create_file("trace_marker", 0220, d_tracer, - tr, &tracing_mark_fops); + trace_create_file("trace_marker", 0220, d_tracer, + tr, &tracing_mark_fops); =20 - tr->trace_marker_file =3D __find_event_file(tr, "ftrace", "print"); + tr->trace_marker_file =3D __find_event_file(tr, "ftrace", "print"); =20 - trace_create_file("trace_marker_raw", 0220, d_tracer, - tr, &tracing_mark_raw_fops); + trace_create_file("trace_marker_raw", 0220, d_tracer, + tr, &tracing_mark_raw_fops); =20 - trace_create_file("trace_clock", TRACE_MODE_WRITE, d_tracer, tr, + trace_create_file("buffer_percent", TRACE_MODE_WRITE, d_tracer, + tr, &buffer_percent_fops); + + trace_create_file("syscall_user_buf_size", TRACE_MODE_WRITE, d_tracer, + tr, &tracing_syscall_buf_fops); + } + + trace_create_file("trace_clock", writable_mode, d_tracer, tr, &trace_clock_fops); =20 - trace_create_file("tracing_on", TRACE_MODE_WRITE, d_tracer, + trace_create_file("tracing_on", writable_mode, d_tracer, tr, &rb_simple_fops); =20 trace_create_file("timestamp_mode", TRACE_MODE_READ, d_tracer, tr, @@ -10652,41 +10692,38 @@ init_tracer_tracefs(struct trace_array *tr, struc= t dentry *d_tracer) =20 tr->buffer_percent =3D 50; =20 - trace_create_file("buffer_percent", TRACE_MODE_WRITE, d_tracer, - tr, &buffer_percent_fops); - - trace_create_file("buffer_subbuf_size_kb", TRACE_MODE_WRITE, d_tracer, + trace_create_file("buffer_subbuf_size_kb", writable_mode, d_tracer, tr, &buffer_subbuf_size_fops); =20 - trace_create_file("syscall_user_buf_size", TRACE_MODE_WRITE, d_tracer, - tr, &tracing_syscall_buf_fops); - create_trace_options_dir(tr); =20 #ifdef CONFIG_TRACER_MAX_TRACE - trace_create_maxlat_file(tr, d_tracer); + if (!readonly) + trace_create_maxlat_file(tr, d_tracer); #endif =20 - if (ftrace_create_function_files(tr, d_tracer)) + if (!readonly && ftrace_create_function_files(tr, d_tracer)) MEM_FAIL(1, "Could not allocate function filter files"); =20 if (tr->range_addr_start) { trace_create_file("last_boot_info", TRACE_MODE_READ, d_tracer, tr, &last_boot_fops); #ifdef CONFIG_TRACER_SNAPSHOT - } else { + } else if (!readonly) { trace_create_file("snapshot", TRACE_MODE_WRITE, d_tracer, tr, &snapshot_fops); #endif } =20 - trace_create_file("error_log", TRACE_MODE_WRITE, d_tracer, - tr, &tracing_err_log_fops); + if (!readonly) + trace_create_file("error_log", TRACE_MODE_WRITE, d_tracer, + tr, &tracing_err_log_fops); =20 for_each_tracing_cpu(cpu) tracing_init_tracefs_percpu(tr, cpu); =20 - ftrace_init_tracefs(tr, d_tracer); + if (!readonly) + ftrace_init_tracefs(tr, d_tracer); } =20 #ifdef CONFIG_TRACEFS_AUTOMOUNT_DEPRECATED diff --git a/kernel/trace/trace.h b/kernel/trace/trace.h index b6d42fe06115..a098011951cc 100644 --- a/kernel/trace/trace.h +++ b/kernel/trace/trace.h @@ -33,6 +33,7 @@ =20 #define TRACE_MODE_WRITE 0640 #define TRACE_MODE_READ 0440 +#define TRACE_MODE_WRITE_MASK (TRACE_MODE_WRITE & ~TRACE_MODE_READ) =20 enum trace_type { __TRACE_FIRST_TYPE =3D 0, @@ -483,6 +484,12 @@ extern bool trace_clock_in_ns(struct trace_array *tr); =20 extern unsigned long trace_adjust_address(struct trace_array *tr, unsigned= long addr); =20 +static inline bool trace_array_is_readonly(struct trace_array *tr) +{ + /* backup instance is read only. */ + return tr->flags & TRACE_ARRAY_FL_VMALLOC; +} + /* * The global tracer (top) should be the first trace array added, * but we check the flag anyway. @@ -681,7 +688,6 @@ struct dentry *trace_create_file(const char *name, void *data, const struct file_operations *fops); =20 - /** * tracer_tracing_is_on_cpu - show real state of ring buffer enabled on fo= r a cpu * @tr : the trace array to know if ring buffer is enabled diff --git a/kernel/trace/trace_boot.c b/kernel/trace/trace_boot.c index dbe29b4c6a7a..2ca2541c8a58 100644 --- a/kernel/trace/trace_boot.c +++ b/kernel/trace/trace_boot.c @@ -61,7 +61,8 @@ trace_boot_set_instance_options(struct trace_array *tr, s= truct xbc_node *node) v =3D memparse(p, NULL); if (v < PAGE_SIZE) pr_err("Buffer size is too small: %s\n", p); - if (tracing_resize_ring_buffer(tr, v, RING_BUFFER_ALL_CPUS) < 0) + if (trace_array_is_readonly(tr) || + tracing_resize_ring_buffer(tr, v, RING_BUFFER_ALL_CPUS) < 0) pr_err("Failed to resize trace buffer to %s\n", p); } =20 @@ -597,7 +598,7 @@ trace_boot_enable_tracer(struct trace_array *tr, struct= xbc_node *node) =20 p =3D xbc_node_find_value(node, "tracer", NULL); if (p && *p !=3D '\0') { - if (tracing_set_tracer(tr, p) < 0) + if (trace_array_is_readonly(tr) || tracing_set_tracer(tr, p) < 0) pr_err("Failed to set given tracer: %s\n", p); } =20 diff --git a/kernel/trace/trace_events.c b/kernel/trace/trace_events.c index 9b07ad9eb284..5a9e03470b03 100644 --- a/kernel/trace/trace_events.c +++ b/kernel/trace/trace_events.c @@ -1379,6 +1379,9 @@ static int __ftrace_set_clr_event(struct trace_array = *tr, const char *match, { int ret; =20 + if (trace_array_is_readonly(tr)) + return -EPERM; + mutex_lock(&event_mutex); ret =3D __ftrace_set_clr_event_nolock(tr, match, sub, event, set, mod); mutex_unlock(&event_mutex); @@ -2817,8 +2820,8 @@ event_subsystem_dir(struct trace_array *tr, const cha= r *name, } else __get_system(system); =20 - /* ftrace only has directories no files */ - if (strcmp(name, "ftrace") =3D=3D 0) + /* ftrace only has directories no files, readonly instance too. */ + if (strcmp(name, "ftrace") =3D=3D 0 || trace_array_is_readonly(tr)) nr_entries =3D 0; else nr_entries =3D ARRAY_SIZE(system_entries); @@ -2983,28 +2986,30 @@ event_create_dir(struct eventfs_inode *parent, stru= ct trace_event_file *file) int ret; static struct eventfs_entry event_entries[] =3D { { - .name =3D "enable", + .name =3D "format", .callback =3D event_callback, - .release =3D event_release, }, +#ifdef CONFIG_PERF_EVENTS { - .name =3D "filter", + .name =3D "id", .callback =3D event_callback, }, +#endif +#define NR_RO_EVENT_ENTRIES (1 + IS_ENABLED(CONFIG_PERF_EVENTS)) +/* Readonly files must be above this line and counted by NR_RO_EVENT_ENTRI= ES. */ { - .name =3D "trigger", + .name =3D "enable", .callback =3D event_callback, + .release =3D event_release, }, { - .name =3D "format", + .name =3D "filter", .callback =3D event_callback, }, -#ifdef CONFIG_PERF_EVENTS { - .name =3D "id", + .name =3D "trigger", .callback =3D event_callback, }, -#endif #ifdef CONFIG_HIST_TRIGGERS { .name =3D "hist", @@ -3037,9 +3042,13 @@ event_create_dir(struct eventfs_inode *parent, struc= t trace_event_file *file) if (!e_events) return -ENOMEM; =20 - nr_entries =3D ARRAY_SIZE(event_entries); + if (trace_array_is_readonly(tr)) + nr_entries =3D NR_RO_EVENT_ENTRIES; + else + nr_entries =3D ARRAY_SIZE(event_entries); =20 name =3D trace_event_name(call); + ei =3D eventfs_create_dir(name, e_events, event_entries, nr_entries, file= ); if (IS_ERR(ei)) { pr_warn("Could not create tracefs '%s' directory\n", name); @@ -4381,25 +4390,25 @@ create_event_toplevel_files(struct dentry *parent, = struct trace_array *tr) int nr_entries; static struct eventfs_entry events_entries[] =3D { { - .name =3D "enable", + .name =3D "header_page", .callback =3D events_callback, }, { - .name =3D "header_page", + .name =3D "header_event", .callback =3D events_callback, }, +#define NR_RO_TOP_ENTRIES 2 +/* Readonly files must be above this line and counted by NR_RO_TOP_ENTRIES= . */ { - .name =3D "header_event", + .name =3D "enable", .callback =3D events_callback, }, }; =20 - entry =3D trace_create_file("set_event", TRACE_MODE_WRITE, parent, - tr, &ftrace_set_event_fops); - if (!entry) - return -ENOMEM; - - nr_entries =3D ARRAY_SIZE(events_entries); + if (trace_array_is_readonly(tr)) + nr_entries =3D NR_RO_TOP_ENTRIES; + else + nr_entries =3D ARRAY_SIZE(events_entries); =20 e_events =3D eventfs_create_events_dir("events", parent, events_entries, nr_entries, tr); @@ -4408,15 +4417,22 @@ create_event_toplevel_files(struct dentry *parent, = struct trace_array *tr) return -ENOMEM; } =20 - /* There are not as crucial, just warn if they are not created */ + if (!trace_array_is_readonly(tr)) { =20 - trace_create_file("set_event_pid", TRACE_MODE_WRITE, parent, - tr, &ftrace_set_event_pid_fops); + entry =3D trace_create_file("set_event", TRACE_MODE_WRITE, parent, + tr, &ftrace_set_event_fops); + if (!entry) + return -ENOMEM; + + /* There are not as crucial, just warn if they are not created */ =20 - trace_create_file("set_event_notrace_pid", - TRACE_MODE_WRITE, parent, tr, - &ftrace_set_event_notrace_pid_fops); + trace_create_file("set_event_pid", TRACE_MODE_WRITE, parent, + tr, &ftrace_set_event_pid_fops); =20 + trace_create_file("set_event_notrace_pid", + TRACE_MODE_WRITE, parent, tr, + &ftrace_set_event_notrace_pid_fops); + } tr->event_dir =3D e_events; =20 return 0;