From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8CFFF4B04B4; Sun, 9 Aug 2026 02:32:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242736; cv=none; b=f1/UgcDbVLwfRwy3v562Q+sd2cz6rLDVPwoP/XUpv9pwS8IkyeKY/RZNz3LNg/byBjOFj1Z05hFi8QdY5q9jLDqG8LZR512Q5Nfli8ngR+xX5CWGuINSqgk9lqo4Pmxn87bd07+kRYqTg/jVLAUhRvuGZvhOGDPGusB1NRkcno8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242736; c=relaxed/simple; bh=naau0ZOdwTgmpgP6cMAH3GyyjG/taDOzyWzYW6EhqFA=; h=Message-ID:Date:From:To:Cc:Subject:References:MIME-Version: Content-Type; b=f8eBUmWVXA2iyywyAOAux+UclWzGdDzUTSQx+CVlrGpq521mK8rjjWtoli8ADMFpQMEKWrs7vCje1ISkuv/ZNklHOwLgO3nIYdHtO+tLBkwM6jOaS+XTBPvJRMLuzw1EEjYfmbvncCMho9GHguGK2zO0W/xjeNC0NRk1v7nnH8M= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=dwzlAUl4; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="dwzlAUl4" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 2DCB01F000E9; Sun, 9 Aug 2026 02:32:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786242735; bh=uqDm7PtLMIMrxxQDn6i+3zQIKR04zfptQqpulm1NEP0=; h=Date:From:To:Cc:Subject:References; b=dwzlAUl4R3s2t7Dg/kJFoXTKnfLrrsnXjxiLNKWifFeb8UzkZNsd2o8ZymOZ5XZPn cwuOru7O0vBKjWzZBuzcLFHV66TO96aGkUrYrIWZkAMGTlYzk6nSs62FxJvGPgr/S5 fBXBRru5rjLDnXJ7IKSOn+x+RJOrJrulmUFpZygNS5xkuJQ/wRvmdL1I2LhNjwxspt nRIKjsYifUc/Pm8cQ35/YByC4dFUgh/EBJ61nuKX8on2Dp4hiQroFPnkUQQ/XLmetf LjnEu+yNnS7HREFExArkZV4VWxkJvZYn/cwbvFr6P6ZJzJzq+yNzi4wUYZ1qqD1lqT mYSgdtzI0qOvg== Received: from rostedt by gandalf with local (Exim 4.99.4) (envelope-from ) id 1wstKn-00000001N2l-28sU; Sat, 08 Aug 2026 22:32:21 -0400 Message-ID: <20260809023221.366243140@kernel.org> User-Agent: quilt/0.69 Date: Sat, 08 Aug 2026 22:31:45 -0400 From: Steven Rostedt To: linux-kernel@vger.kernel.org Cc: Masami Hiramatsu , Mark Rutland , Mathieu Desnoyers , Andrew Morton , stable@vger.kernel.org, Shuangpeng Bai Subject: [for-linus][PATCH 01/12] eventfs: Fix use-after-free in eventfs_remove_rec() References: <20260809023144.852271250@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Shuangpeng Bai eventfs_remove_rec() recursively removes the child at the current loop position. After the recursive call returns, list_for_each_entry() advances by reading list.next from the removed child. If free_ei() drops the final reference, release_ei() reuses the list/rcu union to queue an SRCU callback. The child may be freed before that read. The eventfs_mutex serializes list updates, but it does not keep the removed child alive or prevent the SRCU callback from running. Use list_for_each_entry_safe() to save the next sibling before recursively removing the current child. Cc: stable@vger.kernel.org Fixes: 43aa6f97c2d0 ("eventfs: Get rid of dentry pointers without refcounts= ") Link: https://patch.msgid.link/20260806022719.375354-1-shuangpeng.kernel@gm= ail.com Signed-off-by: Shuangpeng Bai Acked-by: Masami Hiramatsu (Google) Signed-off-by: Steven Rostedt --- fs/tracefs/event_inode.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/fs/tracefs/event_inode.c b/fs/tracefs/event_inode.c index 39c7a34531e8..93bc4f83b73e 100644 --- a/fs/tracefs/event_inode.c +++ b/fs/tracefs/event_inode.c @@ -822,7 +822,7 @@ struct eventfs_inode *eventfs_create_events_dir(const c= har *name, struct dentry */ static void eventfs_remove_rec(struct eventfs_inode *ei, int level) { - struct eventfs_inode *ei_child; + struct eventfs_inode *ei_child, *tmp; =20 /* * Check recursion depth. It should never be greater than 3: @@ -835,7 +835,7 @@ static void eventfs_remove_rec(struct eventfs_inode *ei= , int level) return; =20 /* search for nested folders or files */ - list_for_each_entry(ei_child, &ei->children, list) + list_for_each_entry_safe(ei_child, tmp, &ei->children, list) eventfs_remove_rec(ei_child, level + 1); =20 list_del_rcu(&ei->list); --=20 2.53.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D9711A0BF1; Sun, 9 Aug 2026 02:32:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242737; cv=none; b=fbkcHX2dmyB5WH0HI5zp8GDo1Vr1GfpyDwQeVfS3LRhkH0cIhyAb9AgoqqR8+ePtjdbYWv8cRIoIz3RDm3ab7vd9WYtUHHehTYyhVRaVRwNWpiDKVVZA4xBA4uHYZyI0mqJFnQLCuTer6p3K8Z91vfZBzbceqXIstLrTWFZjdnU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242737; c=relaxed/simple; bh=Nz3OSV1ZyAgSdAm0VfF9pGpSvkaRgZa2frgmYTSJLuI=; h=Message-ID:Date:From:To:Cc:Subject:References:MIME-Version: Content-Type; b=AU6y5zX1C4QoRL11HbPzHuVprTsX193oCH3b3bnZNbuNTaWnmFm9Wxe0I2067N1yz+yzdWXY/F5yEZCL95LdNWrR6/qcxZCd2BAFLg0sUR0NKA/beokKc+N9SlsM/LKWEI/addEaTHo9lugbpPs0MOosrki3FjPsm+JpICqdFxY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Rfk3+Skh; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Rfk3+Skh" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5432B1F00A3F; Sun, 9 Aug 2026 02:32:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786242735; bh=carAygDWo2gMyBfxlUBqWt9GVu4GcVCiEGXoTXpM3YI=; h=Date:From:To:Cc:Subject:References; b=Rfk3+SkhOPL5P1fLg/+mvaxcJFavlSGy1zAD4ZxMHacz37iV+E0zq5UkXklal6KSD F0vqLJQJ8rinXWV8K1tDGjUeEY7Y9ufGaq494zt5SXi5i+kG9BpuCtSWcYykRx625M NwhAwS1sObZm8/7+u6t7WqceaKWIf/FxuLYCmwNbPezspYXDsLlI9grebyrScwxbvh 4IEy6joZEvzGko9V9BOah1LJR1lmV6cTSodM6PrqCcGVKbb1bv8PPdfuOjbTHxIxaS pZeoiSM+7ryOodCgVckY38FqrhtOFC3sZeB0WtuMoipK5DF/T+Yt1o+EYHaKa6+UcL Qt7+JAc6a/Qkg== Received: from rostedt by gandalf with local (Exim 4.99.4) (envelope-from ) id 1wstKn-00000001N3F-2pPD; Sat, 08 Aug 2026 22:32:21 -0400 Message-ID: <20260809023221.529998042@kernel.org> User-Agent: quilt/0.69 Date: Sat, 08 Aug 2026 22:31:46 -0400 From: Steven Rostedt To: linux-kernel@vger.kernel.org Cc: Masami Hiramatsu , Mark Rutland , Mathieu Desnoyers , Andrew Morton , stable@vger.kernel.org, Sashiko Subject: [for-linus][PATCH 02/12] eventfs: Use children field for rcu head and add memory barriers References: <20260809023144.852271250@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Steven Rostedt When an eventfs inode is freed, it sets ei->is_freed and then uses its ei->list to add it to the srcu link list as the list field is a union with the rcu list head. As the ei->list is used to iterate over an SRCU protected list without taking the eventfs_mutex, there's nothing stopping the iteration over that list to see the ei->rcu instead of the ei->list and it will read a corrupt target. To fix this, change the union of the rcu list head with the children list. On freeing the eventfs inode, set the is_free and execute a smp_wmb() before adding the eventfs inode to the SRCU list. On iteration of the ei->children list, at the start, execute a smp_rmb() and then read the is_freed of the ei to see if the children list is still valid. If is_freed is set, then the ei_child read is not valid and the loop should exit immediately. Cc: stable@vger.kernel.org Link: https://patch.msgid.link/20260808094215.4252430d@robin Fixes: 704f960dbee2f ("eventfs: Read ei->entries before ei->children in eve= ntfs_iterate()") Reported-by: Sashiko Closes: https://sashiko.dev/#/patchset/20260806022719.375354-1-shuangpeng.k= ernel%40gmail.com Reviewed-by: Masami Hiramatsu (Google) Signed-off-by: Steven Rostedt --- fs/tracefs/event_inode.c | 24 ++++++++++++++++++++++++ fs/tracefs/internal.h | 4 ++-- 2 files changed, 26 insertions(+), 2 deletions(-) diff --git a/fs/tracefs/event_inode.c b/fs/tracefs/event_inode.c index 93bc4f83b73e..a52458435327 100644 --- a/fs/tracefs/event_inode.c +++ b/fs/tracefs/event_inode.c @@ -124,7 +124,17 @@ static inline void put_ei(struct eventfs_inode *ei) static inline void free_ei(struct eventfs_inode *ei) { if (ei) { + /* The ei should have no children if it is being freed. */ + WARN_ON_ONCE(!list_empty(&ei->children)); ei->is_freed =3D 1; + /* + * The SRCU iteration has a smp_rmb() to make sure it + * sees a child (that may have already been freed) + * before it reads is_free. If is_free is set, it must + * not use the child it acquired from ei->children, as + * the list may be used for SRCU. + */ + smp_wmb(); put_ei(ei); } } @@ -627,6 +637,20 @@ static int eventfs_iterate(struct file *file, struct d= ir_context *ctx) list_for_each_entry_srcu(ei_child, &ei->children, list, srcu_read_lock_held(&eventfs_srcu)) { =20 + /* + * If the ei is being freed, then the ei->children may be + * being used as the rcu list, which means the next element + * may be garbage. The ei->is_free is set before switching + * the ei->children over to ei->rcu. The read memory barrier + * here makes sure the ei_child is read before is_free is + * updated. + * + * Matches the smp_wmb() in free_ei() + */ + smp_rmb(); + if (ei->is_freed) + return -EINVAL; + if (c > 0) { c--; continue; diff --git a/fs/tracefs/internal.h b/fs/tracefs/internal.h index a4a7f8431aff..c61481d04c8e 100644 --- a/fs/tracefs/internal.h +++ b/fs/tracefs/internal.h @@ -46,11 +46,11 @@ struct eventfs_attr { * @ino: The saved inode number */ struct eventfs_inode { + struct list_head list; union { - struct list_head list; + struct list_head children; struct rcu_head rcu; }; - struct list_head children; const struct eventfs_entry *entries; const char *name; struct eventfs_attr *entry_attrs; --=20 2.53.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C44542288D5; Sun, 9 Aug 2026 02:32:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242737; cv=none; b=TTxBjp+islt7JzDA80ViL09ouRctsImXcwY8jMXvAm4F4MFKcpJ1JQRMumUbBvAODoWpNZdbpcAAecIVcfb1ZFRaO7gTrWhdSXH3GrJP9/Ejk+aCR+MGFMoX1L/2Z1L4+T3swAdwziE/aGoLxkPWSxmKotKGgRpWgK9T7IQVoE4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242737; c=relaxed/simple; bh=YNR0P/zFuUV7bXFyQhPjlznSIw0c98m1qcxNvY1hGMw=; h=Message-ID:Date:From:To:Cc:Subject:References:MIME-Version: Content-Type; b=nfyJTYJtCcEK6Asp2ubm16ZLCHWm5lccPsI2v5FBSqSlOxYkCg8sWmqU4EY3q7JlADYK02HButZR/58cIaS+p5Yzt1o9cHWKNDlII3cOCd/ww/d00EPz/Kr4p3c0CxhojSkBoflooTojH8IFHqudK8EVCLM/XQ46Mvs7YKnVvZs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=C0BBPO/7; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="C0BBPO/7" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 82C471F00ACF; Sun, 9 Aug 2026 02:32:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786242735; bh=fxBXChhYmXgLyv5TgSo4dJdJjV7r0PgcnZo4WSFSkcg=; h=Date:From:To:Cc:Subject:References; b=C0BBPO/7Okfh+zHRr4IJlqcW4JbMGUl8TfDB64PVKCm+RPAh6H5FtQqKZ3yzWcxY6 OzOkeGNQxUjEyPxWQ+GHSdeornZVSz8FIYg1R4TyR+NlgTekIveYi3RbWkfY4uUgTu jSa+0idfynVNgr7VqqpFaxNpEZFFOEKwkuTJ+NPB7E/g26pCIYP15IuVxXVyYfuSZ0 ZAyZfJ28Xaz2/e+HRbmlZtiYMdyfDGU+6fBfcEbYsivhzBgZ6vcDRZ1gkoG+F11RME cWBTV0xyhR90BlCG1GYybbcorNMO9YpMb/Wl0tA3hg+7NiUn1alDrXahApE82UU+h5 q9OoJMLhIl/Gg== Received: from rostedt by gandalf with local (Exim 4.99.4) (envelope-from ) id 1wstKn-00000001N3j-3VY5; Sat, 08 Aug 2026 22:32:21 -0400 Message-ID: <20260809023221.693441329@kernel.org> User-Agent: quilt/0.69 Date: Sat, 08 Aug 2026 22:31:47 -0400 From: Steven Rostedt To: linux-kernel@vger.kernel.org Cc: Masami Hiramatsu , Mark Rutland , Mathieu Desnoyers , Andrew Morton , stable@vger.kernel.org, Jiri Olsa , Leon Hwang Subject: [for-linus][PATCH 03/12] ftrace: Protect direct_functions in ftrace_find_rec_direct References: <20260809023144.852271250@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Leon Hwang Fix accessing the __rcu pointer direct_functions with RCU protection. Cc: stable@vger.kernel.org Link: https://patch.msgid.link/20260730150411.88667-2-leon.hwang@linux.dev Fixes: d05cb470663a ("ftrace: Fix modification of direct_function hash whil= e in use") Acked-by: Jiri Olsa Suggested-by: Steven Rostedt Signed-off-by: Leon Hwang Signed-off-by: Steven Rostedt --- kernel/trace/ftrace.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/kernel/trace/ftrace.c b/kernel/trace/ftrace.c index 6c47a94f5924..c5d1d0d42ccc 100644 --- a/kernel/trace/ftrace.c +++ b/kernel/trace/ftrace.c @@ -2645,7 +2645,8 @@ unsigned long ftrace_find_rec_direct(unsigned long ip) { struct ftrace_func_entry *entry; =20 - entry =3D __ftrace_lookup_ip(direct_functions, ip); + guard(preempt_notrace)(); + entry =3D __ftrace_lookup_ip(rcu_dereference_sched(direct_functions), ip); if (!entry) return 0; =20 --=20 2.53.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D64F02D9484; Sun, 9 Aug 2026 02:32:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242737; cv=none; b=TyWajyd4qS7Uz7F0NOuY7e9ASTnAf95grv02oKySbr/GTgmVX/HwFyM+WiQR85ctKMgoAeVKTbXdkfhKiXwSDv5v5kG9escUhpbTA/EXh/5JnrIiN89lDlvHD0lUvJc+9rCmpapr5jiiFAofqlj+749bFcXvHFmekx4dNU6KLO8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242737; c=relaxed/simple; bh=oiqWJDC2i3077dMUP6JnqZ64oRUCFp35NaNbNec2s6U=; h=Message-ID:Date:From:To:Cc:Subject:References:MIME-Version: Content-Type; b=b8aYcXJtvjjnJQmKywKthe3TAbCmCQSxH61dOgZ26kYqbl3mBZ2n+Lgq4wS7WYHpbjQHuFphiA+A6emkGqtrf3msRxpnR070Sf9Nwmg8eGlhC9Ftg5sMVj3goWr2irUFamoZ0IK3DGv/OkVGPlTIU6mvAguc5Bf8z9EX68+1xN8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=YVbK13Ow; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="YVbK13Ow" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 9C5871F00ADB; Sun, 9 Aug 2026 02:32:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786242735; bh=PGNsOxfqDTW8bFGdBdNdVIBp6Eh0qzmzMbRY+9D8jJc=; h=Date:From:To:Cc:Subject:References; b=YVbK13OwH0iis+bCQhTOas5moKgfbeKqTezJe3A3WWK+H2jrOLwXpEloj3U6Eq6vr FS+f0RROLAn+YanT1P4kMZWqn9+AjjhoyPZHmE55syMy8DVc+1ZfgeLGQaHc/Ku2TP csIbIZtydQRREF7pZBGk85g+zfwWI1TpifHN6pyCWu38HbJNu+rdXelnS2y0JMkvGe zXSJeySqDwhmSTOMNVcJJcFqCxVjbPs8JDZ5p2a1sv7XFDW+juprI3J0dRtDBOq1FE TndFR6KuTRSawT5lOxcUgWwQNzVQ6+h5ZpJ2G8ZKG3FefRfW8aheLLbiX8ncaN6wuv SADX57NkWDs3g== Received: from rostedt by gandalf with local (Exim 4.99.4) (envelope-from ) id 1wstKn-00000001N4D-4BNk; Sat, 08 Aug 2026 22:32:21 -0400 Message-ID: <20260809023221.854869492@kernel.org> User-Agent: quilt/0.69 Date: Sat, 08 Aug 2026 22:31:48 -0400 From: Steven Rostedt To: linux-kernel@vger.kernel.org Cc: Masami Hiramatsu , Mark Rutland , Mathieu Desnoyers , Andrew Morton , stable@vger.kernel.org, Jiri Olsa , Leon Hwang Subject: [for-linus][PATCH 04/12] ftrace: Protect direct_functions in update_ftrace_direct_del References: <20260809023144.852271250@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Leon Hwang Fix accessing the __rcu pointer direct_functions with RCU protection. Cc: stable@vger.kernel.org Link: https://patch.msgid.link/20260730150411.88667-3-leon.hwang@linux.dev Fixes: 8d2c1233f371 ("ftrace: Add update_ftrace_direct_del function") Acked-by: Jiri Olsa Signed-off-by: Leon Hwang Signed-off-by: Steven Rostedt --- kernel/trace/ftrace.c | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/kernel/trace/ftrace.c b/kernel/trace/ftrace.c index c5d1d0d42ccc..9ea39110927f 100644 --- a/kernel/trace/ftrace.c +++ b/kernel/trace/ftrace.c @@ -6512,6 +6512,7 @@ int update_ftrace_direct_del(struct ftrace_ops *ops, = struct ftrace_hash *hash) struct ftrace_hash *new_direct_functions; struct ftrace_hash *new_filter_hash =3D NULL; struct ftrace_hash *old_filter_hash; + struct ftrace_hash *direct_hash; struct ftrace_func_entry *entry; struct ftrace_func_entry *del; unsigned long size; @@ -6523,11 +6524,13 @@ int update_ftrace_direct_del(struct ftrace_ops *ops= , struct ftrace_hash *hash) return -EINVAL; if (!(ops->flags & FTRACE_OPS_FL_ENABLED)) return -EINVAL; - if (direct_functions =3D=3D EMPTY_HASH) - return -EINVAL; =20 mutex_lock(&direct_mutex); =20 + direct_hash =3D rcu_dereference_protected(direct_functions, lockdep_is_he= ld(&direct_mutex)); + if (direct_hash =3D=3D EMPTY_HASH) + goto out_unlock; + old_filter_hash =3D ops->func_hash ? ops->func_hash->filter_hash : NULL; =20 if (!hash_count(old_filter_hash)) @@ -6537,7 +6540,7 @@ int update_ftrace_direct_del(struct ftrace_ops *ops, = struct ftrace_hash *hash) size =3D 1 << hash->size_bits; for (int i =3D 0; i < size; i++) { hlist_for_each_entry(entry, &hash->buckets[i], hlist) { - del =3D __ftrace_lookup_ip(direct_functions, entry->ip); + del =3D __ftrace_lookup_ip(direct_hash, entry->ip); if (!del || del->direct !=3D entry->direct) goto out_unlock; } @@ -6548,7 +6551,7 @@ int update_ftrace_direct_del(struct ftrace_ops *ops, = struct ftrace_hash *hash) if (!new_filter_hash) goto out_unlock; =20 - new_direct_functions =3D hash_sub(direct_functions, hash); + new_direct_functions =3D hash_sub(direct_hash, hash); if (!new_direct_functions) goto out_unlock; =20 @@ -6575,7 +6578,7 @@ int update_ftrace_direct_del(struct ftrace_ops *ops, = struct ftrace_hash *hash) /* free the new_direct_functions */ old_direct_functions =3D new_direct_functions; } else { - old_direct_functions =3D direct_functions; + old_direct_functions =3D direct_hash; rcu_assign_pointer(direct_functions, new_direct_functions); } =20 --=20 2.53.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CED8B2EA173; Sun, 9 Aug 2026 02:32:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242739; cv=none; b=b+tMj2Ap15+4Rov3CAyECmxa9h83jCrxfUjFQ3QxOhP9TcTbABuF0PHJ95Wn+iWuCT5EVUp1npNnkULXYQGDjbd2wqMRV9RlD+CpChJ08vk2/EJCdhKWaLoCgJLRlRhrDO62l5ME3+fdrMpnkCub+pzCB5csEYYzNXdV0mrdPbk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242739; c=relaxed/simple; bh=4tHQQ/TC9Ps5V52OnJO9ZG5HWaloPksoqbBdYg+QS4k=; h=Message-ID:Date:From:To:Cc:Subject:References:MIME-Version: Content-Type; b=ebWArXPVUtdFrgfA7OZIrDhLPkh6xxApdUpGGs8tu6kPhzxia+UgNnBuQRzgDJssGcn7E0JPpMuolLhUolNOlGRksYVTPGP/GfhK9oVpEHbIPnRUDJnnsaoGWSRHAUHrFDqHJQPAbmWouhG4Z6TSOZQF1+nSl+cMCVxT0MyUtTo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=WIm8LoBc; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="WIm8LoBc" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D13AB1F00A3D; Sun, 9 Aug 2026 02:32:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786242735; bh=3oqIcwX3j3haPT4xkNNwGbJOelqgOzMzs+rDkN86LB8=; h=Date:From:To:Cc:Subject:References; b=WIm8LoBcLrH64DCLPxvPojFXT2Gj4wOc1RSZlkH9LQjzVlQmHzZtps2CBd324z/ze u+Gs8jvFQ/AQWHPIRcpypO4cXo4EBMy4HVSt73Odk6NWlOcFaRuFtXHv7bQPKN2fcT oz0cGgrlAxfXwK8Z9UqS/qiIt+hV2lpl5l/7vovBGmA6QbGkcrt7shleAgibiN+HPO RueJRson6BFxQLQUKdKXGrck8FcY82pX8LUeYuhOHMelhGhFhj4D3VIe+FiPFejzBm mZyFjHc71UjLxCpDtvll24elc2ETZ4Hh/AzcbsTrGy4XHL1ImNoA0q7n3KMVgmM7Rb Sy5mfApmuuH5Q== Received: from rostedt by gandalf with local (Exim 4.99.4) (envelope-from ) id 1wstKo-00000001N4h-0fFm; Sat, 08 Aug 2026 22:32:22 -0400 Message-ID: <20260809023222.015703108@kernel.org> User-Agent: quilt/0.69 Date: Sat, 08 Aug 2026 22:31:49 -0400 From: Steven Rostedt To: linux-kernel@vger.kernel.org Cc: Masami Hiramatsu , Mark Rutland , Mathieu Desnoyers , Andrew Morton , stable@vger.kernel.org, Jiri Olsa , Leon Hwang Subject: [for-linus][PATCH 05/12] ftrace: Protect direct_functions in update_ftrace_direct_mod References: <20260809023144.852271250@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Leon Hwang Fix accessing the __rcu pointer direct_functions with RCU protection. Cc: stable@vger.kernel.org Link: https://patch.msgid.link/20260730150411.88667-4-leon.hwang@linux.dev Fixes: e93672f770d7 ("ftrace: Add update_ftrace_direct_mod function") Acked-by: Jiri Olsa Signed-off-by: Leon Hwang Signed-off-by: Steven Rostedt --- kernel/trace/ftrace.c | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/kernel/trace/ftrace.c b/kernel/trace/ftrace.c index 9ea39110927f..414e425c2d80 100644 --- a/kernel/trace/ftrace.c +++ b/kernel/trace/ftrace.c @@ -6617,6 +6617,7 @@ int update_ftrace_direct_mod(struct ftrace_ops *ops, = struct ftrace_hash *hash, b .func =3D ftrace_stub, .flags =3D FTRACE_OPS_FL_STUB, }; + struct ftrace_hash *direct_hash; struct ftrace_hash *orig_hash; unsigned long size, i; int err =3D -EINVAL; @@ -6627,8 +6628,6 @@ int update_ftrace_direct_mod(struct ftrace_ops *ops, = struct ftrace_hash *hash, b return -EINVAL; if (!(ops->flags & FTRACE_OPS_FL_ENABLED)) return -EINVAL; - if (direct_functions =3D=3D EMPTY_HASH) - return -EINVAL; =20 /* * We can be called from within ops_func callback with direct_mutex @@ -6636,6 +6635,12 @@ int update_ftrace_direct_mod(struct ftrace_ops *ops,= struct ftrace_hash *hash, b */ if (do_direct_lock) mutex_lock(&direct_mutex); + else + lockdep_assert_held_once(&direct_mutex); + + direct_hash =3D rcu_dereference_protected(direct_functions, lockdep_is_he= ld(&direct_mutex)); + if (direct_hash =3D=3D EMPTY_HASH) + goto unlock; =20 orig_hash =3D ops->func_hash ? ops->func_hash->filter_hash : NULL; if (!orig_hash) @@ -6667,7 +6672,7 @@ int update_ftrace_direct_mod(struct ftrace_ops *ops, = struct ftrace_hash *hash, b size =3D 1 << hash->size_bits; for (i =3D 0; i < size; i++) { hlist_for_each_entry(entry, &hash->buckets[i], hlist) { - tmp =3D __ftrace_lookup_ip(direct_functions, entry->ip); + tmp =3D __ftrace_lookup_ip(direct_hash, entry->ip); if (!tmp) continue; tmp->direct =3D entry->direct; --=20 2.53.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CF8582DF3F2 for ; Sun, 9 Aug 2026 02:32:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242738; cv=none; b=jXc1a2O0AmPld+tL+iRsm/LChkW/R1bSZPDjCaWTaIBGOECSaZtdqBX26OzRCmt6AHXkb6Sbk10YXz7oDcE+72MMkZWhP0SqXlZCaCx3MFTu3rnxJShFfcGZF25fzT61qgoLlmVnUKHGGujQR8Kic2vjFEbFcD/DxfUBpFTNaj4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242738; c=relaxed/simple; bh=SVomNVJDLM5oxbSUaIId6sZJgdo5w8WQBqOuTn1HxiE=; h=Message-ID:Date:From:To:Cc:Subject:References:MIME-Version: Content-Type; b=hUAoTJlmDN6F/1f6tQtx2I1pEQBhySRQ9eX0cofamnBHCVqlkqXQgqOa2Z/20HmpXhekSM18BUrrfc+EilVGh3HPtoGRSWSEyRD1HXGFMvtrZZwh0R9fz2qOqfOisKn/+FraNo1FNc8MrmQ9Gy5GptV4zDREWQ/IRr19u8548nA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=l9AB1hDu; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="l9AB1hDu" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 01EFF1F00ACA; Sun, 9 Aug 2026 02:32:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786242736; bh=yys6VaAHDQ1dMfZ7DqF6mJPGviqgrBaUmK7fTPco0pI=; h=Date:From:To:Cc:Subject:References; b=l9AB1hDuEz/98WVrHMlsUclz7BxjO1IMA4xt869+CqM1pZOj02sMRmXDyCAeXz3gI fkcbe2JPoU4vpnbvE1sehhLzT75aa/HafMT65ksCBWuMGV6ImLuYzKoBzAs0bsANuu Cz91f95ZI0NK5cHsRkJMKSR5vZp9TNOHRd1NSjPNGPVrEc7ks/Utfu/B40172xMFvh UTkspUM+cTbQ8BFaEFHG3hxduybsttwIvj5oCJ67jjy+LMwx883ej6SuGjay32VsDo 8oWKxmrJ248188k56jnZ7/bEvvqXLcIYCZyaPkUn4VNeUHFOFPXqWGyKumSMqy+Mql 4Wt/1AzZnwXSA== Received: from rostedt by gandalf with local (Exim 4.99.4) (envelope-from ) id 1wstKo-00000001N5B-1LTX; Sat, 08 Aug 2026 22:32:22 -0400 Message-ID: <20260809023222.175823547@kernel.org> User-Agent: quilt/0.69 Date: Sat, 08 Aug 2026 22:31:50 -0400 From: Steven Rostedt To: linux-kernel@vger.kernel.org Cc: Masami Hiramatsu , Mark Rutland , Mathieu Desnoyers , Andrew Morton , Jiri Olsa , Leon Hwang Subject: [for-linus][PATCH 06/12] ftrace: Drop extra comma in trace_buffered_event_enable References: <20260809023144.852271250@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Leon Hwang Drop the extra comma in "scoped_guard()" to cleanup the code. Link: https://patch.msgid.link/20260730150411.88667-5-leon.hwang@linux.dev Acked-by: Jiri Olsa Signed-off-by: Leon Hwang Signed-off-by: Steven Rostedt --- kernel/trace/trace.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kernel/trace/trace.c b/kernel/trace/trace.c index 01a5e87af299..395238b2b715 100644 --- a/kernel/trace/trace.c +++ b/kernel/trace/trace.c @@ -1788,7 +1788,7 @@ void trace_buffered_event_enable(void) =20 per_cpu(trace_buffered_event, cpu) =3D event; =20 - scoped_guard(preempt,) { + scoped_guard(preempt) { if (cpu =3D=3D smp_processor_id() && __this_cpu_read(trace_buffered_event) !=3D per_cpu(trace_buffered_event, cpu)) --=20 2.53.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 186D137C10A; Sun, 9 Aug 2026 02:32:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242738; cv=none; b=mXran7ZCU1zlSLwtiVMK2x9ifveHkjTcJD+UMWU0B3FPt50kveu++0mVPLzbK1GWPhBbP6ghfH/XDH1myy6RxbSbXVymC5z6qZRTNpBWJNVR7rjbLF/NYMD22LCrjjXV73T0Kbp4pol9FywZ/n9jewPqShyEe6pCl752RKLTUPQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242738; c=relaxed/simple; bh=7lujbEOmldkRiLrS41CTuOilo6e/XBJd+Wp/yIsUFyQ=; h=Message-ID:Date:From:To:Cc:Subject:References:MIME-Version: Content-Type; b=GiSkNocfIiS3uEyvj9Glb9UZ8btHtShUTtA45rM645B4oet7ji0gH89eshts+52E5tYMlpVuiUVEDO+7K8eUennrfrwTaQixOGWaH0mpwlkIkLLBIAbf6TkJX/JLTHowj1jIKe1bHQzsFnmz0Sdjy+YY8sbzRz8BhaV1LunyIU4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Q2e3LFQG; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Q2e3LFQG" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 2A9541F00A3E; Sun, 9 Aug 2026 02:32:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786242736; bh=RsZajquT8PdTHqA0S7T6sbbrTm5qKWASenU4d6SqLAk=; h=Date:From:To:Cc:Subject:References; b=Q2e3LFQG19dSfuy6kAfEAxyiE6Vu2O8mHOH9xigpsRTgTKoUK4OC7RsPQSiWx75T2 DblYojEGTo44Cr0fmfCyV5V+Xe9zIQoAzGwcwWVGCWvGUPjOtdAZkEMxJAe3PnONAb VQ6JFbn63ZlHDw39+2FNsNkgx65hQgyZAkY4zoZvObydSXNRohnGErdpN0zBvz+nKi HX1p0nSelUE83OMvzIaZ60BXGhriCRNl3ByL1eSXW567sxHnYRzPBFCrNVogejgBD3 p8vmKlEpeBRdXRC0MWjqb2eLfOiIHdXezDeKNj7tv9LXhsGm+fu1hqiI69T6DJjjHl uV9AIDJUMVPhA== Received: from rostedt by gandalf with local (Exim 4.99.4) (envelope-from ) id 1wstKo-00000001N5h-20N7; Sat, 08 Aug 2026 22:32:22 -0400 Message-ID: <20260809023222.338674181@kernel.org> User-Agent: quilt/0.69 Date: Sat, 08 Aug 2026 22:31:51 -0400 From: Steven Rostedt To: linux-kernel@vger.kernel.org Cc: Masami Hiramatsu , Mark Rutland , Mathieu Desnoyers , Andrew Morton , stable@vger.kernel.org, Tengda Wu Subject: [for-linus][PATCH 07/12] ring-buffer: Use current_context for safe per-CPU buffer swap References: <20260809023144.852271250@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Tengda Wu The ring_buffer_swap_cpu() function currently checks the per-CPU committing counter to determine if a buffer is actively being written to before performing the swap. However, there exists a race window where this check can be bypassed: ring_buffer_lock_reserve cpu_buffer =3D buffer->buffers[cpu]; // cpu_buffer_a rb_reserve_next_event rb_start_commit // inc committing if (unlikely(READ_ONCE(cpu_buffer->buffer) !=3D buffer)) {...} __rb_reserve_next rb_move_tail rb_end_commit(cpu_buffer); // dec committing =3D> 0 /* interrupt hits here, successfully swaps! */ local_inc(&cpu_buffer->committing); ring_buffer_unlock_commit cpu_buffer =3D buffer->buffers[cpu]; // cpu_buffer_b rb_commit rb_end_commit RB_WARN_ON(cpu_buffer, !local_read(&cpu_buffer->committing)) // triggers warning The committing counter can temporarily drop to 0 during a single write operation (within rb_move_tail), creating a window where swap can succeed even though the write is still in progress. This leads to inconsistent buffer state and triggers the RB_WARN_ON in rb_commit(). Replace the committing counter check with current_context checks, which are set at the entry of ring_buffer_lock_reserve() and remain valid throughout the entire write operation, providing a reliable indicator of buffer busy state during swap. Cc: stable@vger.kernel.org Fixes: 4239c38fe0b3 ("ring-buffer: Process commits whenever moving to a new= page.") Link: https://patch.msgid.link/20260803005640.2445666-2-wutengda@huaweiclou= d.com Signed-off-by: Tengda Wu Signed-off-by: Steven Rostedt --- kernel/trace/ring_buffer.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/kernel/trace/ring_buffer.c b/kernel/trace/ring_buffer.c index 8e2485bb3aa8..58dc8995a88d 100644 --- a/kernel/trace/ring_buffer.c +++ b/kernel/trace/ring_buffer.c @@ -6852,7 +6852,7 @@ int ring_buffer_swap_cpu(struct trace_buffer *buffer_= a, { struct ring_buffer_per_cpu *cpu_buffer_a; struct ring_buffer_per_cpu *cpu_buffer_b; - int ret =3D -EINVAL; + int ret =3D -EBUSY; =20 if (!cpumask_test_cpu(cpu, buffer_a->cpumask) || !cpumask_test_cpu(cpu, buffer_b->cpumask)) @@ -6893,10 +6893,10 @@ int ring_buffer_swap_cpu(struct trace_buffer *buffe= r_a, atomic_inc(&cpu_buffer_a->record_disabled); atomic_inc(&cpu_buffer_b->record_disabled); =20 - ret =3D -EBUSY; - if (local_read(&cpu_buffer_a->committing)) + /* Do not swap if either buffer is in the process of writing */ + if (cpu_buffer_a->current_context) goto out_dec; - if (local_read(&cpu_buffer_b->committing)) + if (cpu_buffer_b->current_context) goto out_dec; =20 /* --=20 2.53.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 18FC737DAAE; Sun, 9 Aug 2026 02:32:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242738; cv=none; b=IcjbPmYJzhqEatqRyj533A01BXPHxvMpSjQ6mlOWKYJUKGmlMHbn9O/GDcU6iSCQ1j/1Myvsws68UC9ossi7fzDEoUzVGOZk35TTW3zu5o7fYWF3AV/uCBiZuunxEANUQo9HKVV0Y3i+8WIkgJflf+Wwbj5/IuxOnQX2wBcFYa0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242738; c=relaxed/simple; bh=qYArbJM/Ky7ieTV7mLSRd5w7dIPe9cHsHZQxM03DSE8=; h=Message-ID:Date:From:To:Cc:Subject:References:MIME-Version: Content-Type; b=EZCmVOf95W84pq4mNA/ZLb5ypU3eKiUzpEOBBCsTo1bzZLiy5dkdC5r8LQZjsjOn9HntySr0TJgRWD44dmgGylrBRr8W5tvJGvaIcodDPGHcQqv9H11o0ODK1oZw26M0vLzbTvXomCymspjwEPLMDfmQEflXMOxd2njf30os/Vg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Lu1llMDC; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Lu1llMDC" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 3F6EF1F00AC4; Sun, 9 Aug 2026 02:32:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786242736; bh=pTR46X70duIEW3e4MGyPdQ0CYj/oUx/vVN7OebHihLA=; h=Date:From:To:Cc:Subject:References; b=Lu1llMDCrCUI4g0Ew1KuH9XWoDj8v32ATCJVUKm6Mhghi2OxdTmtRGiV6ALzfNSMm qhIxe/K7AE9DVT81uPNGhoXddk3YMHRUgz+EvK3+9CDDUJfGovWJGjBVhoTNIKqrSY ko9ZUg3mYYfdMl36qidsRSxDwgmltW0BkclYas7wDsuwxIzGDbj888PpVjgdCD8T0x DcSw8IOvrs4lPv9ZbdEVwlI/gmk3peXeAnd0TECXJ+PXrkh+A1Ua4FNvjmPEj1M9V0 TKk/iEUI+fjtav+PJo3dcUvF/NX5BF1J1VZeI4gJTz+jPQjU1mxukSNEeOBeuM1wle w/B775sj0uLiw== Received: from rostedt by gandalf with local (Exim 4.99.4) (envelope-from ) id 1wstKo-00000001N6C-2fxo; Sat, 08 Aug 2026 22:32:22 -0400 Message-ID: <20260809023222.497514011@kernel.org> User-Agent: quilt/0.69 Date: Sat, 08 Aug 2026 22:31:52 -0400 From: Steven Rostedt To: linux-kernel@vger.kernel.org Cc: Masami Hiramatsu , Mark Rutland , Mathieu Desnoyers , Andrew Morton , stable@vger.kernel.org, Josh Poimboeuf Subject: [for-linus][PATCH 08/12] ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() References: <20260809023144.852271250@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Josh Poimboeuf When a module's init text is freed, do_init_module() calls ftrace_free_mem() with a half-open [start, end) range. However the ftrace_cmp_recs() comparator treats the upper bound as inclusive, as all its other users do, passing 'ip + size - 1'. So ftrace_free_mem() can delete a record sitting exactly at 'end', which is outside the freed range. For a kernel without CFI or IBT, the first record of a function is at the function start, which for the first function in a module is also the base of its text allocation. As the module allocator packs its regions, that address is often the 'end' passed by a neighboring module's do_init_module(), causing the first function's ftrace location to get disabled, preventing an attempt to livepatch it: livepatch: failed to find location for function 'pcspkr_probe' Convert the exclusive end to the inclusive 'end - 1' the comparator expects, and return early for an empty range to avoid the subtraction from underflowing when the init text size is zero. Cc: stable@vger.kernel.org Fixes: 42c269c88dc1 ("ftrace: Allow for function tracing to record init fun= ctions on boot up") Link: https://patch.msgid.link/1b5ccfa8095bdb1277f84af1c2c2e2205aca03ae.178= 5992188.git.jpoimboe@kernel.org Signed-off-by: Josh Poimboeuf Acked-by: Masami Hiramatsu (Google) Signed-off-by: Steven Rostedt --- kernel/trace/ftrace.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/kernel/trace/ftrace.c b/kernel/trace/ftrace.c index 414e425c2d80..7c50f8ae5a0c 100644 --- a/kernel/trace/ftrace.c +++ b/kernel/trace/ftrace.c @@ -8305,7 +8305,8 @@ static void add_to_clear_hash_list(struct list_head *= clear_list, void ftrace_free_mem(struct module *mod, void *start_ptr, void *end_ptr) { unsigned long start =3D (unsigned long)(start_ptr); - unsigned long end =3D (unsigned long)(end_ptr); + /* end is inclusive and end_ptr is exclusive */ + unsigned long end =3D (unsigned long)(end_ptr) - 1; struct ftrace_page **last_pg =3D &ftrace_pages_start; struct ftrace_page *tmp_page =3D NULL; struct ftrace_page *pg; @@ -8315,6 +8316,9 @@ void ftrace_free_mem(struct module *mod, void *start_= ptr, void *end_ptr) struct ftrace_init_func *func, *func_next; LIST_HEAD(clear_hash); =20 + if (start_ptr >=3D end_ptr) + return; + key.ip =3D start; key.flags =3D end; /* overload flags, as it is unsigned long */ =20 --=20 2.53.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 187B037DAAD; Sun, 9 Aug 2026 02:32:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242738; cv=none; b=lEh0lM3Hu+DwOhpviLZSgGl8CdRRiYTSF5UFqdSOgx8MXjrvrud340UpGQ2KvKJIrM7k3+Lf0MAKikmCQIetdOLeerwj7W3FHnUCezz233GjJHBypJeHzV/lAbeQQqJv/X8QPXfwFsbniRSHPH3YyDWx+vF//oda6BiKcQgkYUs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242738; c=relaxed/simple; bh=I4DN6ZYjV/wENBq9wuCDrz5eYZLp+C048DJDjL/cBwk=; h=Message-ID:Date:From:To:Cc:Subject:References:MIME-Version: Content-Type; b=fiP+nF+bsRmiTIuwIHDdstrmHmDJcZ9w1GNJqvUWGGq13imxP80lT7/rspIlsNL8LAO4B+L6XFw5NXVDCnA4b7Lc56oELFUt+AUDHcYL4HIbPNcKwVhVTXIwwmW2QXDof/KQx/5KGKJMGJinSBt93+wDvYcY/uUrgKregaHQnkM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=HIuSuHgU; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="HIuSuHgU" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5C3F31F01558; Sun, 9 Aug 2026 02:32:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786242736; bh=Q817XsXLmkmpVcUhbLOK+pXdDdo488E7ve87OMODTEU=; h=Date:From:To:Cc:Subject:References; b=HIuSuHgUqFZFe21QtpTtP/SSDb8nrIng1FbgAZYCsNe9G9Q7Bn6v3kv/EatGpqJwu PAxFUqS548JpxzVKlvrpqcLWsEXT2H0KHadYx+tr2pLy2t2ZsbjawkqJg652fOv2Q1 iKNJJtquQQK5ZEH4YrXMD9EzLMwhb6wRP+7LxMocMNHO0QNBAMCVuNXuH4LcwcsZsS I23yanFHniFtTI6o5tSamb7H3EYdhNvhYdXevgdpXFvd3Logcz3CPKholyOvT/gW9F rXDM5eRbLD9osuAgaTNSgIGkct1zIrebcq3YO37EFVoaGD0Dgdzk9KYqVBDY7ItNGo 1wHgte5Nk7lZA== Received: from rostedt by gandalf with local (Exim 4.99.4) (envelope-from ) id 1wstKo-00000001N6g-3H4Z; Sat, 08 Aug 2026 22:32:22 -0400 Message-ID: <20260809023222.657322893@kernel.org> User-Agent: quilt/0.69 Date: Sat, 08 Aug 2026 22:31:53 -0400 From: Steven Rostedt To: linux-kernel@vger.kernel.org Cc: Masami Hiramatsu , Mark Rutland , Mathieu Desnoyers , Andrew Morton , stable@vger.kernel.org, Vincent Donnefort Subject: [for-linus][PATCH 09/12] ring-buffer: Prevent resizing of persistent ring buffer References: <20260809023144.852271250@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Vincent Donnefort Dynamically resizing a persistent ring buffer is not possible. Disable the feature. Cc: stable@vger.kernel.org Fixes: be68d63a139b ("ring-buffer: Add ring_buffer_alloc_range()") Link: https://patch.msgid.link/20260806211306.3704194-2-vdonnefort@google.c= om Signed-off-by: Vincent Donnefort Signed-off-by: Steven Rostedt --- kernel/trace/ring_buffer.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/kernel/trace/ring_buffer.c b/kernel/trace/ring_buffer.c index 58dc8995a88d..09d502ef4c55 100644 --- a/kernel/trace/ring_buffer.c +++ b/kernel/trace/ring_buffer.c @@ -2528,6 +2528,8 @@ rb_allocate_cpu_buffer(struct trace_buffer *buffer, l= ong nr_pages, int cpu) if (cpu_buffer->ring_meta->head_buffer) rb_meta_buffer_update(cpu_buffer, bpage); bpage->range =3D 1; + + atomic_inc(&cpu_buffer->resize_disabled); } else if (buffer->remote) { struct ring_buffer_desc *desc =3D ring_buffer_desc(buffer->remote->desc,= cpu); =20 --=20 2.53.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 53C1337DEAA; Sun, 9 Aug 2026 02:32:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242738; cv=none; b=QdMgqbYrSjhT2Iv8qV2C1HpRDiAtsaaAAe69AIhopPuw9+2VQoxn8H5xBGmWkFu7gLZm2XL/7c9c3ZOSEmrZIuuOd2Iy9ZKybWEyFJcbjXADhyfpoHRbPZbjtqS9qa/KO+TI2uESHHzr7iLvuy8c0unSpuoRs0fEPI5ajSR+GNk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242738; c=relaxed/simple; bh=afozUb8E/5FXp1IRFFB2cQW7YrWaCKo+79vBmXSiE/Y=; h=Message-ID:Date:From:To:Cc:Subject:References:MIME-Version: Content-Type; b=hgLeaGC2nqJt3wDDdGgPBb4Ws2RyHux8mBK8qaogJiXQa/Sy/Qus7PrJRvm0nQUulbdvUf23ki6lEdaWUsvmhbJaiJHhZwgosmfJt72my03efqe1T28C4MYIqdO+VWE4KpiKZbxHF5mH94pO16bAw898E56CeDqEkd4sKWaLjLE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Qg/Yjanv; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Qg/Yjanv" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8C3BE1F00ADE; Sun, 9 Aug 2026 02:32:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786242736; bh=JrxP5G/FB4r8xdT3E+9AH8xbkYjIv2lSi5v0y68eIGE=; h=Date:From:To:Cc:Subject:References; b=Qg/YjanvPmshHuWNqXtAj6WhQm3/mTZC4lT/wJXUEM5WqCP5DdaRTXlOmdHdX7BEE sf/w1ByR9NeY1RIjCg2y9tfsyfuCKhtA/X6L7IQqSsagFo9tdPjApdYnb2Wt+mbsuz 96QT69JpAK/P8kjV6YZytcC9REBzu2b9Iz43nu+YR7TieWYg4Y4LSdxzeTqRuPn41J iw8NeYujBeSaqLI9l59TyYWlYpoQ0epJcmgBvcVmSLjWj2hGFb83xaxTt946QGa0JO a1jkYEEgfUXTzE9Ed0Kgse/BhmkTr6XHM9NPd1vmO4eOeqhfxZ55fQOeZL/sgMuvzk 8anUHbqqxUnNA== Received: from rostedt by gandalf with local (Exim 4.99.4) (envelope-from ) id 1wstKo-00000001N7C-3ucB; Sat, 08 Aug 2026 22:32:22 -0400 Message-ID: <20260809023222.799156348@kernel.org> User-Agent: quilt/0.69 Date: Sat, 08 Aug 2026 22:31:54 -0400 From: Steven Rostedt To: linux-kernel@vger.kernel.org Cc: Masami Hiramatsu , Mark Rutland , Mathieu Desnoyers , Andrew Morton , stable@vger.kernel.org, syzbot+e0cc44465d6bae735679@syzkaller.appspotmail.com, Vincent Donnefort Subject: [for-linus][PATCH 10/12] ring-buffer: Prevent subbuf order change when resizing is disabled References: <20260809023144.852271250@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Vincent Donnefort Because ring_buffer_subbuf_order_set() frees buffer pages, we can't allow it when resizing is disabled. A non-consuming reader is at risk of use-after-free (rb_advance_iter()). Return -EBUSY on resize_disabled, matching ring_buffer_resize() behaviour. Cc: stable@vger.kernel.org Fixes: f9b94daa542a ("ring-buffer: Set new size of the ring buffer sub page= ") Link: https://patch.msgid.link/20260806211306.3704194-3-vdonnefort@google.c= om Reported-by: syzbot+e0cc44465d6bae735679@syzkaller.appspotmail.com Signed-off-by: Vincent Donnefort Signed-off-by: Steven Rostedt --- kernel/trace/ring_buffer.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kernel/trace/ring_buffer.c b/kernel/trace/ring_buffer.c index 09d502ef4c55..6cbd80ccef37 100644 --- a/kernel/trace/ring_buffer.c +++ b/kernel/trace/ring_buffer.c @@ -7360,7 +7360,7 @@ int ring_buffer_subbuf_order_set(struct trace_buffer = *buffer, int order) =20 cpu_buffer =3D buffer->buffers[cpu]; =20 - if (cpu_buffer->mapped) { + if (atomic_read(&cpu_buffer->resize_disabled)) { err =3D -EBUSY; goto error; } --=20 2.53.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 651FB38AC83; Sun, 9 Aug 2026 02:32:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242739; cv=none; b=hR8GCKH1BXHTbAArc2QQsXU7mBqpAvlyjyZksW/VeU+ql12EdEDaaV54EZOkYkAy90XxyYrHu4Y5iZQoSRL1HgGVuRpsB7EalFQaqxW2JI2E8KW4Qy8bNmwF2McFBjmCuAiCD8Op9XxkeIiGQUFvfCe0W7or2X2E2S0ja2LJOsI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242739; c=relaxed/simple; bh=G2JcI7zZny1pDHlT26ifDULaTmvkqZrOzjFrh01/dJY=; h=Message-ID:Date:From:To:Cc:Subject:References:MIME-Version: Content-Type; b=OMNmJqec67Im4jIAP/6Ql4Ue2qLuLzqm+Xm3AeKcCeoQn7kaUBsJ83FyAX/Uj8X9gOKWiDmSxgkVZ749cJ0soPeBOErCVrAcqYYKGSURpQRypyr7mZtOOGRGanE7rkpZEVvmHf5IBjgthu8DOiZBhWtuXCsPdDpyMW6E5T9w5FA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=LVRvQqlH; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="LVRvQqlH" Received: by smtp.kernel.org (Postfix) with ESMTPSA id AA8631F01559; Sun, 9 Aug 2026 02:32:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786242736; bh=UyyWp3NwzGcFwkjSQWDprdH9t2NSEehPe+aAU1OMBpU=; h=Date:From:To:Cc:Subject:References; b=LVRvQqlHg0UjneGi9ZeJIErL3tT3J+heCabWPBa/me0CyFGWQdD6nu9ha8sOwLwBW tNIIh/Lnz6zJh56p2/yNIEbaQ/wZ/CBHsNqxms05OjZ6FdajJ/7i7Lzd1agX8fHpfI AKNb8Wqb7TOF//E7XblqjGpsTlSmm6J7tohH6Tg12Pc49ASNE/+9+PfWlnfgEP8aVM QOxCRMeFF65VikOm4p3/XPgOgushjcejGEtJJGeRlYw2Z8eKAbdHYTAq1B7+LjSNud 9fPWBe3/gDxxmf8dN5+sYFGW8lIXf0F3G/9G9qWaIGWmcwT0JCRpDwFTshSif2qTMA 4wRAxIi0h/WGA== Received: from rostedt by gandalf with local (Exim 4.99.4) (envelope-from ) id 1wstKp-00000001N7g-0L6P; Sat, 08 Aug 2026 22:32:23 -0400 Message-ID: <20260809023222.955041844@kernel.org> User-Agent: quilt/0.69 Date: Sat, 08 Aug 2026 22:31:55 -0400 From: Steven Rostedt To: linux-kernel@vger.kernel.org Cc: Masami Hiramatsu , Mark Rutland , Mathieu Desnoyers , Andrew Morton , stable@vger.kernel.org, Vincent Donnefort Subject: [for-linus][PATCH 11/12] ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer() References: <20260809023144.852271250@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Vincent Donnefort In rb_allocate_cpu_buffer(), bpage->order was omitted, leaving it as 0. This is an issue for a ring-buffer with subbufs bigger than PAGE_SIZE if when freed: free_buffer_page() relies on this value. Align the value with the actual allocation size (buffer::subbuf_order). Cc: stable@vger.kernel.org Fixes: f9b94daa542a ("ring-buffer: Set new size of the ring buffer sub page= ") Link: https://patch.msgid.link/20260806211306.3704194-4-vdonnefort@google.c= om Signed-off-by: Vincent Donnefort Signed-off-by: Steven Rostedt --- kernel/trace/ring_buffer.c | 1 + 1 file changed, 1 insertion(+) diff --git a/kernel/trace/ring_buffer.c b/kernel/trace/ring_buffer.c index 6cbd80ccef37..760a00e8505c 100644 --- a/kernel/trace/ring_buffer.c +++ b/kernel/trace/ring_buffer.c @@ -2510,6 +2510,7 @@ rb_allocate_cpu_buffer(struct trace_buffer *buffer, l= ong nr_pages, int cpu) bpage =3D alloc_cpu_page(cpu); if (!bpage) return NULL; + bpage->order =3D cpu_buffer->buffer->subbuf_order; =20 rb_check_bpage(cpu_buffer, bpage); =20 --=20 2.53.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7903B3A0B13; Sun, 9 Aug 2026 02:32:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242739; cv=none; b=ab1cSJMu3/IZ4abSoeLdxL/c1Exa8+76LqzPQr900a6G9cb4ow89g/w4JdjNmSpGh39qM6tHr90g1Yhv9s9aqsIStBUi5MYaPsZ+YKAqd6JCi+cmSvW+O5tvi0VIDO3fch7As13WFcMfReMizzggzubcfF9GC3VmvGA/L8DILw0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786242739; c=relaxed/simple; bh=aKVMLffV36JJyvmlxsMLg1QEYQKPju/acbqSOYLKtnU=; h=Message-ID:Date:From:To:Cc:Subject:References:MIME-Version: Content-Type; b=HDsVeCjdBy0ANxrT0+nOeHIqR02kA+SxjCY13J5SsyrkT2/pKCMwSFti197g4Lx9t1547RmKzg319+Ct0iKDQzD39lOPzgxBBOPSLFJkPRdkjxSN4q/D3qLJtvp/FQWeSqJinEYhzGYhjCcFFyYxpQB93IhWBmNMMUcOT/JEX+Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=YTIi23l8; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="YTIi23l8" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D5E0C1F000E9; Sun, 9 Aug 2026 02:32:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786242736; bh=vrM2+TD+0MkuWqm0kWaBZvs35CJnjmmoRSUJZIkU/3k=; h=Date:From:To:Cc:Subject:References; b=YTIi23l8zxd0bZTQ+AotYTkZ5w+lp4pe2P2ZGI7pFj9qgUPBdigGN2afvd4oy56B7 vvWSSktG9zdh1Xxfj0pm7deKtN1edEoK6QMlsmk6WKTyvdmX6M61sPGMC2ncDp+gG/ AJvxsEnlgC5D87fOFvKYEB5uuh5AQdPGuqy+bWB5BXDjG2+W6awK0sTSePVhZj7Gkz yZ0VXdrqPTsK+Q+5V6Qu4hBIY1XM9IhSc0qWlBmTGpf8RdqYKeaKSfaUSmFMFmRS5W TABROXsGypppdIbrATQkCz2yd3apKJUTo7fQ7o+Sdv19Er1AFWvZyyMSOuww7iCfbn CCUsTQZ2Ag9nw== Received: from rostedt by gandalf with local (Exim 4.99.4) (envelope-from ) id 1wstKp-00000001N8B-0vAX; Sat, 08 Aug 2026 22:32:23 -0400 Message-ID: <20260809023223.100369362@kernel.org> User-Agent: quilt/0.69 Date: Sat, 08 Aug 2026 22:31:56 -0400 From: Steven Rostedt To: linux-kernel@vger.kernel.org Cc: Masami Hiramatsu , Mark Rutland , Mathieu Desnoyers , Andrew Morton , stable@vger.kernel.org, Hui Su , Vincent Donnefort Subject: [for-linus][PATCH 12/12] ring-buffer: Fix crash passing ERR_PTR to kthread_stop() References: <20260809023144.852271250@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Hui Su In test_ringbuffer()'s out_free cleanup loop, the check `!rb_threads[cpu]` only catches NULL entries and misses entries that hold an ERR_PTR. rb_threads[] is static, so unassigned slots are NULL. But when kthread_run_on_cpu() fails for a cpu, it stores ERR_PTR(-ENOMEM) (or -EINTR) in rb_threads[cpu] before the creation loop jumps to out_free. That entry is non-NULL, so the old `!ptr` check does not break, and the cleanup proceeds to call kthread_stop() on the ERR_PTR. kthread_stop() then dereferences the bogus pointer, crashing the kernel during the late_initcall self-test. crash logs: BUG: kernel NULL pointer dereference, address: 000000000000001c Oops: 0002 [#1] SMP NOPTI CPU: 1 PID: 1 Comm: swapper/0 Not tainted 7.2.0-rc6-dirty #7 PREEMPT(lazy) RIP: 0010:kthread_stop+0x2e/0x220 RBX: fffffffffffffff4 CR2: 000000000000001c Call Trace: test_ringbuffer+0x1ec/0x650 do_one_initcall+0x6c/0x2c0 kernel_init_freeable+0x21d/0x420 kernel_init+0x15/0x1c0 ret_from_fork+0x21b/0x320 Kernel panic - not syncing: Fatal exception Cc: stable@vger.kernel.org Fixes: 64ed3a049e3e ("ring-buffer: make use of the helper function kthread_= run_on_cpu()") Link: https://patch.msgid.link/20260807154145.2846521-2-sh_def@163.com Signed-off-by: Hui Su Reviewed-by: Vincent Donnefort Acked-by: Masami Hiramatsu (Google) Signed-off-by: Steven Rostedt --- kernel/trace/ring_buffer.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kernel/trace/ring_buffer.c b/kernel/trace/ring_buffer.c index 760a00e8505c..2667992f0aa2 100644 --- a/kernel/trace/ring_buffer.c +++ b/kernel/trace/ring_buffer.c @@ -8217,7 +8217,7 @@ static __init int test_ringbuffer(void) =20 out_free: for_each_online_cpu(cpu) { - if (!rb_threads[cpu]) + if (IS_ERR_OR_NULL(rb_threads[cpu])) break; kthread_stop(rb_threads[cpu]); } --=20 2.53.0