From nobody Tue Sep 29 04:47:17 2026 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C22E942FCA1; Wed, 12 Aug 2026 14:11:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.142.43.55 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786543891; cv=none; b=ZRoAgDx/DIuNfZMM4tdhexxycO/EYx25/j4dSWwwGWJBy1uxSJ4KzXTqrA2zTv6gJd3lRD50q3GvIhoPdZ9yDCW/UoVu2G/QFYAzh6lkRTwICj5Gs2C+K8fAekS5rIZOZW9O3JcG4OsO8nN9lB5QzbkF1KXAgKj3uUtPlTGaU/k= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786543891; c=relaxed/simple; bh=UPy+pOQxSCqyBpoUXlhc8AsJYZw5d88oWZdV2vN0zcI=; h=Date:From:To:Subject:Cc:In-Reply-To:References:MIME-Version: Message-ID:Content-Type; b=nrncwsQAoW13eahVai//H/XAQGhzIYwG/yXmqOq6TqWxEMNXVH/u1EIYLH+5ejYgacy6zKS3Do6UXgk22fiP9Fq7DfE8W5HUHjwTkfnF2vLS7Y/mJCH5mnVDPpid9a+0h/RU7HPvnA04Qq/pEi25P1XpcvYrKwnvraaRGsTjq94= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de; spf=pass smtp.mailfrom=linutronix.de; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=kIrEbz8C; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=szn/BcCj; arc=none smtp.client-ip=193.142.43.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linutronix.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="kIrEbz8C"; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="szn/BcCj" Date: Wed, 12 Aug 2026 14:11:26 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1786543887; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=FEcXD44cZBYPU04Jkb5cANMhHBca7h4UsbmeJZLlq6U=; b=kIrEbz8CSl15BUKQLM9zJv4xTv1IJ7anzjO8saNGCI3GZYBPG1HkxVo0Vq6yqTrR0IsSob K6BFSjkKVV/VM/uW/yjMKDRrClxqJ/AONlNYT8pz8CCR9F0k9/VcnzvPzrwZgKR+4lorir Tv658m6BWbUxSADxDMNxmnASTfDuCDHOZQHv4WKym1UpVXJJgRvLq3tGf5i+cpsO5y6IAp WZS3zQqD1NfEVIq+tEvJd4R/xiRdhY3NLTz7pFUmT26L6iF+2DlyqWYWaIfpOrwK7gj8nI 4Uf2IJCscTzMzWMSVvy+gn+/k8SB6zw4BS4yNhIaVCfhlaoZDXN55hou2qXOig== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1786543887; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=FEcXD44cZBYPU04Jkb5cANMhHBca7h4UsbmeJZLlq6U=; b=szn/BcCjrK5wCoreMe8SotU3YJOEUV8RFbKuQCq4idi1GitVPf6lVeCqPZGBmHulOeFxN6 M977syW11fpoaDDg== From: "tip-bot2 for Dapeng Mi" Sender: tip-bot2@linutronix.de Reply-to: linux-kernel@vger.kernel.org To: linux-tip-commits@vger.kernel.org Subject: [tip: perf/core] perf/x86: Guard intel_pmu_cpu_dead() against invalid hybrid PMU casts Cc: Dapeng Mi , "Peter Zijlstra (Intel)" , Thomas Falcon , Zide Chen , x86@kernel.org, linux-kernel@vger.kernel.org In-Reply-To: <20260717080342.1879573-4-dapeng1.mi@linux.intel.com> References: <20260717080342.1879573-4-dapeng1.mi@linux.intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-ID: <178654388600.442315.9350863258121061497.tip-bot2@tip-bot2> Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails Precedence: bulk Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The following commit has been merged into the perf/core branch of tip: Commit-ID: 278a3731c9d08bc6ea489c1987c6b7a7020f5d2b Gitweb: https://git.kernel.org/tip/278a3731c9d08bc6ea489c1987c6b7a70= 20f5d2b Author: Dapeng Mi AuthorDate: Fri, 17 Jul 2026 16:03:37 +08:00 Committer: Peter Zijlstra CommitterDate: Mon, 10 Aug 2026 15:05:47 +02:00 perf/x86: Guard intel_pmu_cpu_dead() against invalid hybrid PMU casts In failure paths, cpuc->pmu can still point to the global static pmu instead of an embedded x86_hybrid_pmu::pmu. Calling hybrid_pmu() on that pointer causes an invalid container conversion and may lead to out-of-bounds access. This can happen in at least two cases: - init_hybrid_pmu() fails check_hw_exists() and leaves cpuc->pmu as-is. - CPU hotplug fails between CPUHP_PERF_X86_PREPARE and CPUHP_AP_PERF_X86_STARTING, and rollback invokes intel_pmu_cpu_dead(). Fix both paths by: - Clear cpuc->pmu to NULL when check_hw_exists() fails. - Validat that cpuc->pmu is not the global static pmu before calling hybrid_pmu() in intel_pmu_cpu_dead(). A new helper x86_get_static_pmu() is added to get the global static pmu. Signed-off-by: Dapeng Mi Signed-off-by: Peter Zijlstra (Intel) Reviewed-by: Thomas Falcon Reviewed-by: Zide Chen Link: https://patch.msgid.link/20260717080342.1879573-4-dapeng1.mi@linux.in= tel.com --- arch/x86/events/core.c | 5 +++++ arch/x86/events/intel/core.c | 7 +++++-- arch/x86/events/perf_event.h | 1 + 3 files changed, 11 insertions(+), 2 deletions(-) diff --git a/arch/x86/events/core.c b/arch/x86/events/core.c index 6c63b27..a02f303 100644 --- a/arch/x86/events/core.c +++ b/arch/x86/events/core.c @@ -790,6 +790,11 @@ int is_x86_event(struct perf_event *event) return false; } =20 +inline struct pmu *x86_get_static_pmu(void) +{ + return &pmu; +} + struct pmu *x86_get_pmu(unsigned int cpu) { struct cpu_hw_events *cpuc =3D &per_cpu(cpu_hw_events, cpu); diff --git a/arch/x86/events/intel/core.c b/arch/x86/events/intel/core.c index b39c6ce..a991fc4 100644 --- a/arch/x86/events/intel/core.c +++ b/arch/x86/events/intel/core.c @@ -6329,8 +6329,10 @@ static bool init_hybrid_pmu(int cpu) =20 intel_pmu_check_hybrid_pmus(pmu); =20 - if (!check_hw_exists(&pmu->pmu, pmu->cntr_mask, pmu->fixed_cntr_mask)) + if (!check_hw_exists(&pmu->pmu, pmu->cntr_mask, pmu->fixed_cntr_mask)) { + cpuc->pmu =3D NULL; return false; + } =20 pr_info("%s PMU driver: ", pmu->name); =20 @@ -6475,11 +6477,12 @@ void intel_cpuc_finish(struct cpu_hw_events *cpuc) static void intel_pmu_cpu_dead(int cpu) { struct cpu_hw_events *cpuc =3D &per_cpu(cpu_hw_events, cpu); + struct pmu *pmu =3D x86_get_static_pmu(); =20 release_arch_pebs_buf_on_cpu(cpu); intel_cpuc_finish(cpuc); =20 - if (is_hybrid() && cpuc->pmu) + if (is_hybrid() && cpuc->pmu && cpuc->pmu !=3D pmu) cpumask_clear_cpu(cpu, &hybrid_pmu(cpuc->pmu)->supported_cpus); } =20 diff --git a/arch/x86/events/perf_event.h b/arch/x86/events/perf_event.h index a8afea8..01ae287 100644 --- a/arch/x86/events/perf_event.h +++ b/arch/x86/events/perf_event.h @@ -1161,6 +1161,7 @@ static struct perf_pmu_format_hybrid_attr format_attr= _hybrid_##_name =3D {\ .pmu_type =3D _pmu, \ } =20 +struct pmu *x86_get_static_pmu(void); struct pmu *x86_get_pmu(unsigned int cpu); extern struct x86_pmu x86_pmu __read_mostly; =20