From nobody Mon Sep 28 23:53:35 2026 Received: from mail-wr1-f44.google.com (mail-wr1-f44.google.com [209.85.221.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C3E3531813A for ; Fri, 14 Aug 2026 22:20:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.44 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786746028; cv=none; b=iqZIOAE0Q2qhYNNMb7EVmYIxICvFycFFBJ5EARh4rbBPxYlpNdUpFS/Fui3XE9MWv3cwRftJNJGwi3AfNYxQlr5ZTb+BGnM7UeTgUjIkj8YeVfJK8e7dwHMBnaNeEac4I39+kMxlTm/PPvgOjSxczk8NT9Qtm32kCDqKSgT8Nms= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786746028; c=relaxed/simple; bh=w/YqicePv7emVd0mcauY6NNDXMttoi4zTr3TxZ0+Bv8=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=tDu5c/gZTUHpCYj47y/PJy8XUoD8Orm+t90x8lmd1i6acDnvfMeOVdMCpSx5KUc3z6mg5GGyJBwxKZ3u9ga0Vv8xQyqDL566COEzQ4Hc2vsPksXDySAgvBHrw5B1QmyWq4EL6C4mV5nzLxACPoFHYtNGJH0qTid1dskPiW1W0uI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=YV4+mZVk; arc=none smtp.client-ip=209.85.221.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="YV4+mZVk" Received: by mail-wr1-f44.google.com with SMTP id ffacd0b85a97d-47c2b362ee2so1243454f8f.1 for ; Fri, 14 Aug 2026 15:20:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786746025; x=1787350825; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=e7i9VfPYGddFq4sUtK22qI3FlKr+Eu20bYiNUQXZ9HA=; b=YV4+mZVkTEQYoVeER0MOmyYHF9tYO88svVr02aIrHBBXiSh9stSG4X4BoAjB/M1E95 0ntjE8MYRgCiciQ8WGpYLvjLPcab5Y8VQg4czZlR7m+HelsnEQmfcGVepxrEjWSYyBgt jrVtZBYJxmGYEPd0+X4KHiJo9aR6QMBKePmUsS8U9LY/hnCjcwgvG1ZVDUyQ1nMTedY6 13c6Tun5cIEfGfM8d0iYBie7SNvBrZfWDvWvrew1DODxi4LxY7KEa5zSmMwizkvfyiD7 Qn7aT1f+wFezmX/3gLQGj1eEOuWj6AHTxJ0pGo3vEUoL8XdJQufha0mpQfsEeI37EVq/ Dn1w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786746025; x=1787350825; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=e7i9VfPYGddFq4sUtK22qI3FlKr+Eu20bYiNUQXZ9HA=; b=WRtPlq8QJVtL2mBVFvsETMKZtCBk8W3vKXHMhZgC7I1NcrmLa4g+PePtGJnC2wZ49W +BvepY9gtf37Sn+8iWEY9VxEx2K1SqaXbRDDjErYUqNVoCLDQcZBgLsOfU4XOyRxwzTb uMVU7YhjqtPwknTuaRI17OLHna4k7I+4voFyN2wsHHQlXC0w57MQQzA1ylMZQj9ge55m W9p1n8tcvjDOpFUFQrOW+e9jR16/Wl/o0/Qfaq0225I5tGdKX6kxfb1qII4npRPu24cr oCiD8kQC2ChQxXYdbh125orq51rpk7e6TrAGd3hhPuru6Z/uwwXdJfiqkkxwYNHCemPy 5gyA== X-Forwarded-Encrypted: i=1; AHgh+Rqpuj4ez5TKJ0ILYk1qC/009oAoJTwnLL1wGw6u7Ibc0VPCiSWzZdX/GaJfRYMIUBZemjoRHPbQoJ8nENI=@vger.kernel.org X-Gm-Message-State: AOJu0Yx9cfVJG7C6jGTtHyh1+eFtEWdl1a+6vfCiZ9x9t5JZOVAFPbxi Uygm1bwTaeQzr6Kcwa6t2NEO6uowyRN/nKxayN0Yoqxb0wHMRBOZMuVtPveq X-Gm-Gg: AR+sD11eVc5R5O94+9Nm69K5stUgEM9mXURe3/uziw9VpFrSdBKVLv+wmoO8ViHZzOo AvhTnPsNnTq9zbyC6maUJX5rlklyAT4SJiR2tVzl4mHHipP8Hoek96eCfmmQ5wm7XR1dKUv0TpH /FV+unJmHJyBw0ijd1LgSpR31dIrp9Rzf+ZwY5/VZ5SOEfwLAVeFYfEmMuBn36+L5QRNwQKFgeG vuAHn1TLRESlDlZKFNyrSZcLyxRRHl3SwgEKBUQYBGdsfQCDnMwfNXM7/MvaSr8KR6mcbR1iT/3 ZdYU0uVxQMSfNLswFp8aW6m0T+EJ98vy4WR8OLiqsV08PsJvuv91bTOSomQ8C4PNPNnyRpIpVfB 3yOWw2bH6rSFaFMQfw76Qcw8w1wUEpY7Uj2Qs1eeZKsvz6WT6E9R4mZeuOiQCool1xy2KVSwCmV IKxCyDoVc1gKayTNyb+V/vYV4OqTfwsQ== X-Received: by 2002:a05:6000:1844:b0:47d:fc20:e7ab with SMTP id ffacd0b85a97d-481607369bamr13831202f8f.4.1786746024753; Fri, 14 Aug 2026 15:20:24 -0700 (PDT) Received: from debian.. ([2001:41d0:303:db6b::]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4815f1ffffdsm11219222f8f.2.2026.08.14.15.20.19 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 14 Aug 2026 15:20:23 -0700 (PDT) From: Tristan Madani To: Andrew Morton Cc: Tetsuo Handa , Rusty Russell , linux-kernel@vger.kernel.org, stable@vger.kernel.org, Tristan Madani Subject: [PATCH v3] profiling: don't free prof_cpu_mask on init failure Date: Fri, 14 Aug 2026 22:20:19 +0000 Message-ID: <20260814222019.3054116-1-tristmd@gmail.com> X-Mailer: git-send-email 2.47.3 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Tristan Madani When profiling is enabled at runtime via /sys/kernel/profiling, profile_init() allocates prof_cpu_mask then attempts to allocate prof_buffer. If all prof_buffer allocations fail, the error path frees prof_cpu_mask but leaves prof_on set. Since profile_tick() runs from timer interrupt context and reads prof_cpu_mask on every tick, it can access the freed cpumask between the free and the next reboot. Don't free prof_cpu_mask in the error path. The cpumask allocation already succeeded and is small; keeping it on this rare failure path avoids the stale access without additional synchronization. Note: mainline removed prof_cpu_mask entirely in commit 7c51f7bbf057 ("profiling: remove prof_cpu_mask"). This is a minimal fix for stable trees where the variable is still present. Fixes: c309b917cab55 ("cpumask: convert kernel/profile.c") Cc: stable@vger.kernel.org Suggested-by: Tetsuo Handa Signed-off-by: Tristan Madani Reviewed-by: Bradley Morgan --- Changes in v3: - Added comment explaining deliberate leak (Andrew Morton) - Corrected Fixes tag from 22b8ce94708f to c309b917cab55 (Tetsuo Handa) - Added stable-only context in commit message Changes in v2: - Remove the free_cpumask_var() call instead of adding a prof_on guard in profile_tick(), which still raced with the free (Tetsuo Handa) kernel/profile.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/kernel/profile.c b/kernel/profile.c index 984f819b701c9..dcb65a2501558 100644 --- a/kernel/profile.c +++ b/kernel/profile.c @@ -123,7 +123,14 @@ int __ref profile_init(void) if (prof_buffer) return 0; =20 - free_cpumask_var(prof_cpu_mask); + /* + * Do not free prof_cpu_mask here. profile_tick() accesses it from + * timer interrupt context without synchronization, so freeing it + * while prof_on is set leads to a stale read. The cpumask is small + * and this error path is rare, so the leak is harmless. + * This code was removed entirely by commit 7c51f7bbf057 + * ("profiling: remove prof_cpu_mask") in v6.11. + */ return -ENOMEM; } =20 --=20 2.47.3