From nobody Tue Sep 29 04:43:03 2026 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C8AEC44E041; Wed, 12 Aug 2026 14:11:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.142.43.55 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786543888; cv=none; b=CYmAorfFh9VnSRr3h39IliplLkxm90R+OnNVa2gcbfU3mvlwjBhjXnZKGn1DNbx5NPGPbsazE0gM0mSd2A0Zj5f/tPSobx+eXj768E4toP08jBPF65gDdlDLfiSpmpbnfYnTZipZyexiNiiwq7QJ26wvQfrHFg1WnUn+nr6j5FY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786543888; c=relaxed/simple; bh=9bjsQyZv/kIvyBV96idGZqHGOAHx8sesG2cYIVecDSU=; h=Date:From:To:Subject:Cc:In-Reply-To:References:MIME-Version: Message-ID:Content-Type; b=kzjDK8GzqhkEmo+9+d6EhX6Cx2TqXL5pzp9EJHLqMn4XAHNmXdd7hZ11rUlQf9a0ze5d+X3BdUatjiPvlqFk3aCkPgK/Pt/Ewa87zGCHUcvTMlB6DGVEnk5bg7BlNGXk1TTzo6mfL1n3hAZqicyrihnEGx3PVU4G/giXLzMA7Qc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de; spf=pass smtp.mailfrom=linutronix.de; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=y7CyKMik; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=oGI0yKsc; arc=none smtp.client-ip=193.142.43.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linutronix.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="y7CyKMik"; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="oGI0yKsc" Date: Wed, 12 Aug 2026 14:11:23 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1786543884; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=5i016/7Vb9vBAMGkRSmYtbq8kklUG+qH/VNpzIo/W+4=; b=y7CyKMikc47r3g7BMAQZJXn1hIW16RO+1zMfWjkHAJ0+Z/vD2Zu3VDqHChLOKHgvGxz93z r9QOVgIdmKVdEnHxog48Itk6jWVDDMd2RCZ3qkP6X1TBOmGyvEgc37UTqK9yGZTY5Shrww hMb4JEHf6IH1hMXQ1sI8F8ls9EpfaEglyExEIEdU0gJB606QJjDgWheiKqa0Ypqaa93/2+ aSawt9uoCThzvpiyxcH7UCxdYR/n2PKjsGeA298d3R1I3XvnvKUSAQFxW5cODWVS4QsTlb Qtsf0Pcg0xO76wfXF2R3otb0Yd1kuuLbX+2cMHSdSslLuC+4/r1hOqKojcEazA== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1786543884; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=5i016/7Vb9vBAMGkRSmYtbq8kklUG+qH/VNpzIo/W+4=; b=oGI0yKscwEYBNSPNmJn9utBpneKUvzsx/9FWmVupWF2Mj3E9HaM3Ub5YR0eBzztDk/QPEf 81eKpoL2hG8bP7BQ== From: "tip-bot2 for Dapeng Mi" Sender: tip-bot2@linutronix.de Reply-to: linux-kernel@vger.kernel.org To: linux-tip-commits@vger.kernel.org Subject: [tip: perf/core] perf/x86: Remove stale fixed counter helper and fix hybrid PMU access Cc: Dapeng Mi , "Peter Zijlstra (Intel)" , Thomas Falcon , Zide Chen , x86@kernel.org, linux-kernel@vger.kernel.org In-Reply-To: <20260717080342.1879573-6-dapeng1.mi@linux.intel.com> References: <20260717080342.1879573-6-dapeng1.mi@linux.intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-ID: <178654388316.442315.7147346400503600640.tip-bot2@tip-bot2> Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails Precedence: bulk Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The following commit has been merged into the perf/core branch of tip: Commit-ID: 3ba87c5bf11bea80e56abe17730085bc962ecfbe Gitweb: https://git.kernel.org/tip/3ba87c5bf11bea80e56abe17730085bc9= 62ecfbe Author: Dapeng Mi AuthorDate: Fri, 17 Jul 2026 16:03:39 +08:00 Committer: Peter Zijlstra CommitterDate: Mon, 10 Aug 2026 15:05:48 +02:00 perf/x86: Remove stale fixed counter helper and fix hybrid PMU access On hybrid systems, init_hw_perf_events() can call check_hw_exists() with the global PMU pointer after perf_is_hybrid is set. In that case, fixed_counter_disabled() uses hybrid() on a non-hybrid PMU object, so the intel_ctrl access is taken from the wrong layout and can read out of bounds. fixed_counter_disabled() was added in commit 32451614da2a ("perf/x86/intel: Support CPUID 10.ECX to disable fixed counters"), when fixed counters were tracked via num_fixed_counters. Today fixed counters are represented by fixed_cntr_mask, so this helper is obsolete. Remove fixed_counter_disabled() and its callers, and rely directly on the fixed-counter bitmask. With the helper gone, check_hw_exists() no longer needs a PMU argument, so drop that parameter as well. This removes the invalid hybrid access and closes the out-of-bounds read risk. Signed-off-by: Dapeng Mi Signed-off-by: Peter Zijlstra (Intel) Reviewed-by: Thomas Falcon Reviewed-by: Zide Chen Link: https://patch.msgid.link/20260717080342.1879573-6-dapeng1.mi@linux.in= tel.com --- arch/x86/events/core.c | 8 ++------ arch/x86/events/intel/core.c | 4 +--- arch/x86/events/perf_event.h | 9 +-------- 3 files changed, 4 insertions(+), 17 deletions(-) diff --git a/arch/x86/events/core.c b/arch/x86/events/core.c index a02f303..143a6e7 100644 --- a/arch/x86/events/core.c +++ b/arch/x86/events/core.c @@ -265,7 +265,7 @@ static void release_pmc_hardware(void) {} =20 #endif =20 -bool check_hw_exists(struct pmu *pmu, unsigned long *cntr_mask, +bool check_hw_exists(unsigned long *cntr_mask, unsigned long *fixed_cntr_mask) { u64 val, val_fail =3D -1, val_new=3D ~0; @@ -297,8 +297,6 @@ bool check_hw_exists(struct pmu *pmu, unsigned long *cn= tr_mask, if (ret) goto msr_fail; for_each_set_bit(i, fixed_cntr_mask, X86_PMC_IDX_MAX) { - if (fixed_counter_disabled(i, pmu)) - continue; if (val & (0x03ULL << i*4)) { bios_fail =3D 1; val_fail =3D val; @@ -1618,8 +1616,6 @@ void perf_event_print_debug(void) cpu, idx, prev_left); } for_each_set_bit(idx, fixed_cntr_mask, X86_PMC_IDX_MAX) { - if (fixed_counter_disabled(idx, cpuc->pmu)) - continue; rdmsrq(x86_pmu_fixed_ctr_addr(idx), pmc_count); =20 pr_info("CPU#%d: fixed-PMC%d count: %016llx\n", @@ -2180,7 +2176,7 @@ static int __init init_hw_perf_events(void) pmu_check_apic(); =20 /* sanity check that the hardware exists or is emulated */ - if (!check_hw_exists(&pmu, x86_pmu.cntr_mask, x86_pmu.fixed_cntr_mask)) + if (!check_hw_exists(x86_pmu.cntr_mask, x86_pmu.fixed_cntr_mask)) goto out_bad_pmu; =20 pr_cont("%s PMU driver.\n", x86_pmu.name); diff --git a/arch/x86/events/intel/core.c b/arch/x86/events/intel/core.c index b47d2f0..c418176 100644 --- a/arch/x86/events/intel/core.c +++ b/arch/x86/events/intel/core.c @@ -3713,8 +3713,6 @@ static void intel_pmu_reset(void) wrmsrq_safe(x86_pmu_event_addr(idx), 0ull); } for_each_set_bit(idx, fixed_cntr_mask, INTEL_PMC_MAX_FIXED) { - if (fixed_counter_disabled(idx, cpuc->pmu)) - continue; wrmsrq_safe(x86_pmu_fixed_ctr_addr(idx), 0ull); } =20 @@ -6336,7 +6334,7 @@ static bool init_hybrid_pmu(int cpu) =20 intel_pmu_check_hybrid_pmus(pmu); =20 - if (!check_hw_exists(&pmu->pmu, pmu->cntr_mask, pmu->fixed_cntr_mask)) { + if (!check_hw_exists(pmu->cntr_mask, pmu->fixed_cntr_mask)) { cpuc->pmu =3D NULL; return false; } diff --git a/arch/x86/events/perf_event.h b/arch/x86/events/perf_event.h index 01ae287..cc9cfaa 100644 --- a/arch/x86/events/perf_event.h +++ b/arch/x86/events/perf_event.h @@ -1243,7 +1243,7 @@ static inline int x86_pmu_rdpmc_index(int index) return x86_pmu.rdpmc_index ? x86_pmu.rdpmc_index(index) : index; } =20 -bool check_hw_exists(struct pmu *pmu, unsigned long *cntr_mask, +bool check_hw_exists(unsigned long *cntr_mask, unsigned long *fixed_cntr_mask); =20 int x86_add_exclusive(unsigned int what); @@ -1456,13 +1456,6 @@ ssize_t events_hybrid_sysfs_show(struct device *dev, struct device_attribute *attr, char *page); =20 -static inline bool fixed_counter_disabled(int i, struct pmu *pmu) -{ - u64 intel_ctrl =3D hybrid(pmu, intel_ctrl); - - return !(intel_ctrl >> (i + INTEL_PMC_IDX_FIXED)); -} - #ifdef CONFIG_CPU_SUP_AMD =20 int amd_pmu_init(void);