From nobody Fri Jul 24 05:22:28 2026 Received: from dggsgout12.his.huawei.com (dggsgout12.his.huawei.com [45.249.212.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 73D5B4D90AD; Thu, 23 Jul 2026 13:34:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=45.249.212.56 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784813660; cv=none; b=VUYC+AIKOdWO4klDShqipN/T6bEudvbbSL8ABE8Lz7m3bk27500RVk2vgbC3aJVHl9nBSzKUm/rSbeL5xc/Sqb0KK4phB/h4sBYaH3JJwivnl7PvKyCPJmR/5qyp8K50wKjiM/RLnGlq1c19J+EBq+JA2a4S3d2YBqaoHWHY6+0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784813660; c=relaxed/simple; bh=B/Bko4FQsTUgYfQhKDeCyNcSjkPOM1OI6RxHX7o0T0Q=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=cXFV2uWeb8zrcKBL1WKqrkv2YVGf+WwVKrDQOyqGL1ejlgR77NCJGySEgjOgup8ScUQc5X33EmALZKt/9Dchnv5uTM2S5Bog2ldADd3hPn+6rYmmkDZa1Y1GSlLFSufiOadI2epQdiE+7mIQk5BKNOQpt7PMIESTK+glNNwSZ88= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=huaweicloud.com; spf=none smtp.mailfrom=huaweicloud.com; arc=none smtp.client-ip=45.249.212.56 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=huaweicloud.com Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=huaweicloud.com Received: from mail.maildlp.com (unknown [172.19.163.198]) by dggsgout12.his.huawei.com (SkyGuard) with ESMTPS id 4h5XBZ2pzfzKHMMS; Thu, 23 Jul 2026 21:33:26 +0800 (CST) Received: from mail02.huawei.com (unknown [10.116.40.112]) by mail.maildlp.com (Postfix) with ESMTP id BA8FE406C2; Thu, 23 Jul 2026 21:34:11 +0800 (CST) Received: from huawei.com (unknown [10.67.174.45]) by APP1 (Coremail) with UTF8SMTPA id cCh0CgAnOHRNGGJqZdoXCQ--.17802S2; Thu, 23 Jul 2026 21:34:11 +0800 (CST) From: Tengda Wu To: Steven Rostedt , Masami Hiramatsu Cc: Mark Rutland , Mathieu Desnoyers , linux-trace-kernel@vger.kernel.org, linux-kernel@vger.kernel.org, Tengda Wu Subject: [PATCH v3] ftrace: Add global mutex to serialize trace_parser access Date: Thu, 23 Jul 2026 13:34:04 +0000 Message-Id: <20260723133404.1926732-1-wutengda@huaweicloud.com> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: cCh0CgAnOHRNGGJqZdoXCQ--.17802S2 X-Coremail-Antispam: 1UD129KBjvJXoWxXF45Zw4DWr45JFykCrykZrb_yoW5uF45pF y5Krs2kr47tFs2krsF9a18XF18X345Kry5GF95J34ftFnrJF129ry29FZxuF15tr17JrW3 tr4F9r1UKr4UZ3DanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUkG14x267AKxVW8JVW5JwAFc2x0x2IEx4CE42xK8VAvwI8IcIk0 rVWrJVCq3wAFIxvE14AKwVWUJVWUGwA2ocxC64kIII0Yj41l84x0c7CEw4AK67xGY2AK02 1l84ACjcxK6xIIjxv20xvE14v26r1j6r1xM28EF7xvwVC0I7IYx2IY6xkF7I0E14v26r4j 6F4UM28EF7xvwVC2z280aVAFwI0_Cr1j6rxdM28EF7xvwVC2z280aVCY1x0267AKxVW0oV Cq3wAS0I0E0xvYzxvE52x082IY62kv0487Mc02F40EFcxC0VAKzVAqx4xG6I80ewAv7VC0 I7IYx2IY67AKxVWUJVWUGwAv7VC2z280aVAFwI0_Jr0_Gr1lOx8S6xCaFVCjc4AY6r1j6r 4UM4x0Y48IcxkI7VAKI48JM4x0x7Aq67IIx4CEVc8vx2IErcIFxwCY1x0262kKe7AKxVWU AVWUtwCF04k20xvY0x0EwIxGrwCFx2IqxVCFs4IE7xkEbVWUJVW8JwC20s026c02F40E14 v26r1j6r18MI8I3I0E7480Y4vE14v26r106r1rMI8E67AF67kF1VAFwI0_JF0_Jw1lIxkG c2Ij64vIr41lIxAIcVC0I7IYx2IY67AKxVWUJVWUCwCI42IY6xIIjxv20xvEc7CjxVAFwI 0_Jr0_Gr1lIxAIcVCF04k26cxKx2IYs7xG6r1j6r1xMIIF0xvEx4A2jsIE14v26r1j6r4U MIIF0xvEx4A2jsIEc7CjxVAFwI0_Gr0_Gr1UYxBIdaVFxhVjvjDU0xZFpf9x0JUBVbkUUU UU= X-CM-SenderInfo: pzxwv0hjgdqx5xdzvxpfor3voofrz/ Content-Type: text/plain; charset="utf-8" In ftrace, the trace_parser structure is allocated and initialized when a trace file is opened, and is subsequently used across write and release handlers to parse user input. The affected handler paths and their specific functions are: - Open paths: ftrace_regex_open(), ftrace_graph_open() - Write paths: ftrace_regex_write(), ftrace_graph_write() - Release paths: ftrace_regex_release(), ftrace_graph_release() If userspace opens a trace file descriptor and shares it across multiple threads, concurrent write calls will race on the parser's internal state, specifically the 'idx', 'cont', and 'buffer' fields, leading to corrupted input or undefined behavior. Fix this by adding a global mutex, parser_lock, to serialize all access to trace_parser across write and release paths, preventing concurrent corruption of parser state. Fixes: e704eff3ff51 ("ftrace: Have set_graph_function handle multiple funct= ions in one write") Fixes: 689fd8b65d66 ("tracing: trace parser support for function and graph") Cc: stable@vger.kernel.org Signed-off-by: Tengda Wu --- v3: Switch from per-parser lock to global parser_lock (v1 approach). v2: https://lore.kernel.org/all/20260715081937.1469757-1-wutengda@huaweiclo= ud.com/ v1: https://lore.kernel.org/all/20260713134640.708323-1-wutengda@huaweiclou= d.com/ kernel/trace/ftrace.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/kernel/trace/ftrace.c b/kernel/trace/ftrace.c index f93e34dd2328..ba27f31c6ff4 100644 --- a/kernel/trace/ftrace.c +++ b/kernel/trace/ftrace.c @@ -1097,6 +1097,12 @@ struct ftrace_ops global_ops =3D { FTRACE_OPS_FL_PID, }; =20 +/* + * parser_lock - Protects trace_parser state against concurrent operations. + * Held across trace_get_user() and subsequent buffer parsing to prevent r= aces. + */ +DEFINE_MUTEX(parser_lock); + /* * Used by the stack unwinder to know about dynamic ftrace trampolines. */ @@ -5842,6 +5848,8 @@ ftrace_regex_write(struct file *file, const char __us= er *ubuf, /* iter->hash is a local copy, so we don't need regex_lock */ =20 parser =3D &iter->parser; + + guard(mutex)(&parser_lock); read =3D trace_get_user(parser, ubuf, cnt, ppos); =20 if (read >=3D 0 && trace_parser_loaded(parser) && @@ -6984,12 +6992,14 @@ int ftrace_regex_release(struct inode *inode, struc= t file *file) iter =3D file->private_data; =20 parser =3D &iter->parser; + mutex_lock(&parser_lock); if (trace_parser_loaded(parser)) { int enable =3D !(iter->flags & FTRACE_ITER_NOTRACE); =20 ftrace_process_regex(iter, parser->buffer, parser->idx, enable); } + mutex_unlock(&parser_lock); =20 trace_parser_put(parser); =20 @@ -7321,10 +7331,12 @@ ftrace_graph_release(struct inode *inode, struct fi= le *file) =20 parser =3D &fgd->parser; =20 + mutex_lock(&parser_lock); if (trace_parser_loaded((parser))) { ret =3D ftrace_graph_set_hash(fgd->new_hash, parser->buffer); } + mutex_unlock(&parser_lock); =20 trace_parser_put(parser); =20 @@ -7437,6 +7449,7 @@ ftrace_graph_write(struct file *file, const char __us= er *ubuf, =20 parser =3D &fgd->parser; =20 + guard(mutex)(&parser_lock); read =3D trace_get_user(parser, ubuf, cnt, ppos); =20 if (read >=3D 0 && trace_parser_loaded(parser) && --=20 2.34.1