[PATCH v4] perf fdarray: Fix destructor invocation and event counting in fdarray__filter

Ian Rogers posted 1 patch 1 month, 1 week ago
tools/lib/api/fd/array.c | 16 +++++++++++++---
1 file changed, 13 insertions(+), 3 deletions(-)
[PATCH v4] perf fdarray: Fix destructor invocation and event counting in fdarray__filter
Posted by Ian Rogers 1 month, 1 week ago
When processing POLLHUP or POLLERR for an event in fdarray__filter, the
function invokes its destructor callback. However, the exact behavior
around unhandled POLLHUP events on control pipe descriptors caused
premature termination due to thread and evlist pollfd index mismatches.
This occurred because they were skipped by the early nonfilterable continue.

Address this by refining the early continue filter to only skip system-wide
perf events (which are nonfilterable but not non_perf_event). Control
descriptors (non_perf_event) now fall through to appropriately have their
fd value unset to -1 on POLLHUP while avoiding their destructors. Finally,
maintain the invariant that the active event counter (nr) increments strictly
and only for completely filterable events.

Fixes: fb4751e79c45 ("perf record: Fix teardown hang on system-wide multi-threaded sessions")
Assisted-by: Gemini:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@google.com>
---
 tools/lib/api/fd/array.c | 16 +++++++++++++---
 1 file changed, 13 insertions(+), 3 deletions(-)

diff --git a/tools/lib/api/fd/array.c b/tools/lib/api/fd/array.c
index 67b73481df27..3681ad7c6527 100644
--- a/tools/lib/api/fd/array.c
+++ b/tools/lib/api/fd/array.c
@@ -116,14 +116,23 @@ int fdarray__filter(struct fdarray *fda, short revents,
 		return 0;
 
 	for (fd = 0; fd < fda->nr; ++fd) {
-		if (fda->priv[fd].flags & fdarray_flag__nonfilterable)
+		/*
+		 * System-wide perf events are nonfilterable but not non_perf_event.
+		 * We want to skip them entirely and never process revents on them.
+		 */
+		if ((fda->priv[fd].flags & fdarray_flag__nonfilterable) &&
+		    !(fda->priv[fd].flags & fdarray_flag__non_perf_event))
 			continue;
 
 		if (!fda->entries[fd].events)
 			continue;
 
 		if (fda->entries[fd].revents & revents) {
-			if (entry_destructor)
+			/*
+			 * Control descriptors are non_perf_event and don't need
+			 * their perf-specific destructors triggered.
+			 */
+			if (entry_destructor && !(fda->priv[fd].flags & fdarray_flag__non_perf_event))
 				entry_destructor(fda, fd, arg);
 
 			/*
@@ -136,7 +145,8 @@ int fdarray__filter(struct fdarray *fda, short revents,
 			continue;
 		}
 
-		++nr;
+		if (!(fda->priv[fd].flags & fdarray_flag__nonfilterable))
+			++nr;
 	}
 
 	return nr;
-- 
2.55.0.699.gb54405d56f-goog
Re: [PATCH v4] perf fdarray: Fix destructor invocation and event counting in fdarray__filter
Posted by Namhyung Kim 1 month, 1 week ago
On Mon, Aug 17, 2026 at 04:04:31PM -0700, Ian Rogers wrote:
> When processing POLLHUP or POLLERR for an event in fdarray__filter, the
> function invokes its destructor callback. However, the exact behavior
> around unhandled POLLHUP events on control pipe descriptors caused
> premature termination due to thread and evlist pollfd index mismatches.
> This occurred because they were skipped by the early nonfilterable continue.

Do you have a concrete scenario to check this behavior so that we can
verify the fix?  It'd be great if we can add a test case.

Thanks,
Namhyung

> 
> Address this by refining the early continue filter to only skip system-wide
> perf events (which are nonfilterable but not non_perf_event). Control
> descriptors (non_perf_event) now fall through to appropriately have their
> fd value unset to -1 on POLLHUP while avoiding their destructors. Finally,
> maintain the invariant that the active event counter (nr) increments strictly
> and only for completely filterable events.
> 
> Fixes: fb4751e79c45 ("perf record: Fix teardown hang on system-wide multi-threaded sessions")
> Assisted-by: Gemini:gemini-3.1-pro
> Signed-off-by: Ian Rogers <irogers@google.com>
> ---
>  tools/lib/api/fd/array.c | 16 +++++++++++++---
>  1 file changed, 13 insertions(+), 3 deletions(-)
> 
> diff --git a/tools/lib/api/fd/array.c b/tools/lib/api/fd/array.c
> index 67b73481df27..3681ad7c6527 100644
> --- a/tools/lib/api/fd/array.c
> +++ b/tools/lib/api/fd/array.c
> @@ -116,14 +116,23 @@ int fdarray__filter(struct fdarray *fda, short revents,
>  		return 0;
>  
>  	for (fd = 0; fd < fda->nr; ++fd) {
> -		if (fda->priv[fd].flags & fdarray_flag__nonfilterable)
> +		/*
> +		 * System-wide perf events are nonfilterable but not non_perf_event.
> +		 * We want to skip them entirely and never process revents on them.
> +		 */
> +		if ((fda->priv[fd].flags & fdarray_flag__nonfilterable) &&
> +		    !(fda->priv[fd].flags & fdarray_flag__non_perf_event))
>  			continue;
>  
>  		if (!fda->entries[fd].events)
>  			continue;
>  
>  		if (fda->entries[fd].revents & revents) {
> -			if (entry_destructor)
> +			/*
> +			 * Control descriptors are non_perf_event and don't need
> +			 * their perf-specific destructors triggered.
> +			 */
> +			if (entry_destructor && !(fda->priv[fd].flags & fdarray_flag__non_perf_event))
>  				entry_destructor(fda, fd, arg);
>  
>  			/*
> @@ -136,7 +145,8 @@ int fdarray__filter(struct fdarray *fda, short revents,
>  			continue;
>  		}
>  
> -		++nr;
> +		if (!(fda->priv[fd].flags & fdarray_flag__nonfilterable))
> +			++nr;
>  	}
>  
>  	return nr;
> -- 
> 2.55.0.699.gb54405d56f-goog
>
Re: [PATCH v4] perf fdarray: Fix destructor invocation and event counting in fdarray__filter
Posted by Ian Rogers 1 month, 1 week ago
On Mon, Aug 17, 2026 at 4:17 PM Namhyung Kim <namhyung@kernel.org> wrote:
>
> On Mon, Aug 17, 2026 at 04:04:31PM -0700, Ian Rogers wrote:
> > When processing POLLHUP or POLLERR for an event in fdarray__filter, the
> > function invokes its destructor callback. However, the exact behavior
> > around unhandled POLLHUP events on control pipe descriptors caused
> > premature termination due to thread and evlist pollfd index mismatches.
> > This occurred because they were skipped by the early nonfilterable continue.
>
> Do you have a concrete scenario to check this behavior so that we can
> verify the fix?  It'd be great if we can add a test case.

So the fix is trying to address hangs I see in the TPEBS test. We
should be able to add a C unit test. I can do that while I wrangle
with Sashiko.

Thanks,
Ian

> Thanks,
> Namhyung
>
> >
> > Address this by refining the early continue filter to only skip system-wide
> > perf events (which are nonfilterable but not non_perf_event). Control
> > descriptors (non_perf_event) now fall through to appropriately have their
> > fd value unset to -1 on POLLHUP while avoiding their destructors. Finally,
> > maintain the invariant that the active event counter (nr) increments strictly
> > and only for completely filterable events.
> >
> > Fixes: fb4751e79c45 ("perf record: Fix teardown hang on system-wide multi-threaded sessions")
> > Assisted-by: Gemini:gemini-3.1-pro
> > Signed-off-by: Ian Rogers <irogers@google.com>
> > ---
> >  tools/lib/api/fd/array.c | 16 +++++++++++++---
> >  1 file changed, 13 insertions(+), 3 deletions(-)
> >
> > diff --git a/tools/lib/api/fd/array.c b/tools/lib/api/fd/array.c
> > index 67b73481df27..3681ad7c6527 100644
> > --- a/tools/lib/api/fd/array.c
> > +++ b/tools/lib/api/fd/array.c
> > @@ -116,14 +116,23 @@ int fdarray__filter(struct fdarray *fda, short revents,
> >               return 0;
> >
> >       for (fd = 0; fd < fda->nr; ++fd) {
> > -             if (fda->priv[fd].flags & fdarray_flag__nonfilterable)
> > +             /*
> > +              * System-wide perf events are nonfilterable but not non_perf_event.
> > +              * We want to skip them entirely and never process revents on them.
> > +              */
> > +             if ((fda->priv[fd].flags & fdarray_flag__nonfilterable) &&
> > +                 !(fda->priv[fd].flags & fdarray_flag__non_perf_event))
> >                       continue;
> >
> >               if (!fda->entries[fd].events)
> >                       continue;
> >
> >               if (fda->entries[fd].revents & revents) {
> > -                     if (entry_destructor)
> > +                     /*
> > +                      * Control descriptors are non_perf_event and don't need
> > +                      * their perf-specific destructors triggered.
> > +                      */
> > +                     if (entry_destructor && !(fda->priv[fd].flags & fdarray_flag__non_perf_event))
> >                               entry_destructor(fda, fd, arg);
> >
> >                       /*
> > @@ -136,7 +145,8 @@ int fdarray__filter(struct fdarray *fda, short revents,
> >                       continue;
> >               }
> >
> > -             ++nr;
> > +             if (!(fda->priv[fd].flags & fdarray_flag__nonfilterable))
> > +                     ++nr;
> >       }
> >
> >       return nr;
> > --
> > 2.55.0.699.gb54405d56f-goog
> >
[PATCH v5] perf record: Fix unhandled POLLHUP on non_perf_event descriptors
Posted by Ian Rogers 1 month, 1 week ago
When processing POLLHUP or POLLERR for an event in fdarray__filter, the
function's prior iterations incorrectly mutated non_perf_event control
descriptors by zeroing their events when a POLLHUP occurred. This caused
premature termination due to index mismatches or hangs since the core
evlist logic was prevented from safely finalizing the poll array setup via
evlist__ctlfd_process().

Revert the logic in fdarray__filter to cleanly bypass all nonfilterable
events as introduced by fb4751e79c45. Instead, fix the underlying logic
within record__update_evlist_pollfd_from_thread() in builtin-record.c to
sustainably reflect teardown statuses (-1) originating from
evlist__finalize_ctlfd(). This correctly mirrors the finalized state to the
thread's poll structure avoiding both invalid -EINVAL index crashes and
POLLHUP spin loops.

Included is a unit test to enforce that fdarray_flag__nonfilterable items
are accurately completely circumvented during revents filtering loops.

Fixes: fb4751e79c45 ("perf record: Fix teardown hang on system-wide multi-threaded sessions")
Assisted-by: Gemini:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@google.com>
---
 tools/perf/builtin-record.c | 10 ++++++++++
 tools/perf/tests/fdarray.c  | 24 ++++++++++++++++++++++++
 2 files changed, 34 insertions(+)

diff --git a/tools/perf/builtin-record.c b/tools/perf/builtin-record.c
index a57987851cf0..d7c083803029 100644
--- a/tools/perf/builtin-record.c
+++ b/tools/perf/builtin-record.c
@@ -1169,6 +1169,16 @@ static int record__update_evlist_pollfd_from_thread(struct record *rec,
 		int e_pos = rec->index_map[i].evlist_pollfd_index;
 		int t_pos = rec->index_map[i].thread_pollfd_index;
 
+		if (e_entries[e_pos].fd == -1 || e_entries[e_pos].events == 0) {
+			/*
+			 * e_entries might have been finalized by evlist__finalize_ctlfd().
+			 * We must propagate it to t_entries to avoid index mismatches
+			 * and to prevent a poll storm on the next iteration.
+			 */
+			t_entries[t_pos].fd = -1;
+			t_entries[t_pos].events = 0;
+		}
+
 		if (e_entries[e_pos].fd != t_entries[t_pos].fd ||
 		    e_entries[e_pos].events != t_entries[t_pos].events) {
 			pr_err("Thread and evlist pollfd index mismatch\n");
diff --git a/tools/perf/tests/fdarray.c b/tools/perf/tests/fdarray.c
index 40983c3574b1..2d3db7b754a1 100644
--- a/tools/perf/tests/fdarray.c
+++ b/tools/perf/tests/fdarray.c
@@ -80,6 +80,30 @@ static int test__fdarray__filter(struct test_suite *test __maybe_unused, int sub
 		goto out_delete;
 	}
 
+	fdarray__init_revents(fda, POLLHUP);
+	fda->priv[2].flags = fdarray_flag__nonfilterable;
+
+	pr_debug("\nfiltering all but fda->entries[2] (nonfilterable):");
+	fdarray__fprintf_prefix(fda, "before", stderr);
+	nr_fds = fdarray__filter(fda, POLLHUP, NULL, NULL);
+	fdarray__fprintf_prefix(fda, " after", stderr);
+
+	if (nr_fds != 0) {
+		pr_debug("\nfdarray__filter()=%d != 0, should be 0\n",
+			 nr_fds);
+		goto out_delete;
+	}
+	if (fda->entries[2].fd == -1) {
+		pr_debug("\nfdarray__filter() illegally modified nonfilterable fd!");
+		goto out_delete;
+	}
+	if (fda->entries[2].revents != POLLHUP) {
+		pr_debug("\nfdarray__filter() illegally modified nonfilterable revents!");
+		goto out_delete;
+	}
+
+	fda->priv[2].flags = 0; /* reset flags */
+
 	pr_debug("\n");
 
 	err = 0;
-- 
2.55.0.699.gb54405d56f-goog
[PATCH v6] perf record: Fix unhandled POLLHUP on non_perf_event descriptors
Posted by Ian Rogers 1 month, 1 week ago
When processing POLLHUP on a non_perf_event control descriptor (like ctl_fd),
evlist__finalize_ctlfd() is invoked to finalize the setup, correctly setting
the core evlist's poll array file descriptor to -1. However, this finalized
teardown state is never propagated back to the individual thread's local
replica of the pollfd array.

Consequently, on the next iteration of the main recording loop,
record__update_evlist_pollfd_from_thread() performs a strict equivalence
check between the core evlist's array and the thread's localized poll array,
detecting that the fd values no longer match (-1 != original_fd). This causes
an immediate -EINVAL abort and a premature, ungraceful teardown.

Fix the underlying logic within record__update_evlist_pollfd_from_thread()
to sustainably propagate the finalized teardown statuses (-1) originating
from the core evlist back to the thread's localized poll structure. This
correctly maintains synchronization and entirely prevents the unhandled
index mismatch crashes.

Additionally, add a unit test that explicitly validates that fdarray__filter()
preserves its invariants regarding fdarray_flag__nonfilterable items to
guard against future regressions.

Fixes: fb4751e79c45 ("perf record: Fix teardown hang on system-wide multi-threaded sessions")
Assisted-by: Gemini:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@google.com>
---
 tools/perf/builtin-record.c | 10 ++++++++++
 tools/perf/tests/fdarray.c  | 24 ++++++++++++++++++++++++
 2 files changed, 34 insertions(+)

diff --git a/tools/perf/builtin-record.c b/tools/perf/builtin-record.c
index a57987851cf0..d7c083803029 100644
--- a/tools/perf/builtin-record.c
+++ b/tools/perf/builtin-record.c
@@ -1169,6 +1169,16 @@ static int record__update_evlist_pollfd_from_thread(struct record *rec,
 		int e_pos = rec->index_map[i].evlist_pollfd_index;
 		int t_pos = rec->index_map[i].thread_pollfd_index;
 
+		if (e_entries[e_pos].fd == -1 || e_entries[e_pos].events == 0) {
+			/*
+			 * e_entries might have been finalized by evlist__finalize_ctlfd().
+			 * We must propagate it to t_entries to avoid index mismatches
+			 * and to prevent a poll storm on the next iteration.
+			 */
+			t_entries[t_pos].fd = -1;
+			t_entries[t_pos].events = 0;
+		}
+
 		if (e_entries[e_pos].fd != t_entries[t_pos].fd ||
 		    e_entries[e_pos].events != t_entries[t_pos].events) {
 			pr_err("Thread and evlist pollfd index mismatch\n");
diff --git a/tools/perf/tests/fdarray.c b/tools/perf/tests/fdarray.c
index 40983c3574b1..2d3db7b754a1 100644
--- a/tools/perf/tests/fdarray.c
+++ b/tools/perf/tests/fdarray.c
@@ -80,6 +80,30 @@ static int test__fdarray__filter(struct test_suite *test __maybe_unused, int sub
 		goto out_delete;
 	}
 
+	fdarray__init_revents(fda, POLLHUP);
+	fda->priv[2].flags = fdarray_flag__nonfilterable;
+
+	pr_debug("\nfiltering all but fda->entries[2] (nonfilterable):");
+	fdarray__fprintf_prefix(fda, "before", stderr);
+	nr_fds = fdarray__filter(fda, POLLHUP, NULL, NULL);
+	fdarray__fprintf_prefix(fda, " after", stderr);
+
+	if (nr_fds != 0) {
+		pr_debug("\nfdarray__filter()=%d != 0, should be 0\n",
+			 nr_fds);
+		goto out_delete;
+	}
+	if (fda->entries[2].fd == -1) {
+		pr_debug("\nfdarray__filter() illegally modified nonfilterable fd!");
+		goto out_delete;
+	}
+	if (fda->entries[2].revents != POLLHUP) {
+		pr_debug("\nfdarray__filter() illegally modified nonfilterable revents!");
+		goto out_delete;
+	}
+
+	fda->priv[2].flags = 0; /* reset flags */
+
 	pr_debug("\n");
 
 	err = 0;
-- 
2.55.0.737.g08866a6d13-goog
[PATCH v7] perf record: Fix unhandled POLLHUP on non_perf_event descriptors
Posted by Ian Rogers 1 month, 1 week ago
When processing POLLHUP on a non_perf_event control descriptor,
evlist__finalize_ctlfd() is invoked to finalize the setup, correctly
setting the core evlist's poll array file descriptor to -1. However,
this finalized teardown state is never propagated back to the
individual thread's local replica of the pollfd array.

Consequently, on the next iteration of the main recording loop,
record__update_evlist_pollfd_from_thread() performs a strict
equivalence check between the core evlist's array and the thread's
localized poll array, detecting that the fd values no longer match.
This causes an immediate -EINVAL abort and a premature teardown.

Fix the underlying logic within
record__update_evlist_pollfd_from_thread() to sustainably propagate
the finalized teardown statuses (-1) originating from the core evlist
back to the thread's localized poll structure. This correctly
maintains synchronization and entirely prevents the unhandled
index mismatch crashes.

Additionally, add a unit test that explicitly validates that
fdarray__filter() preserves its invariants regarding
fdarray_flag__nonfilterable items to guard against regressions.

Fixes: fb4751e79c45 ("perf record: Fix teardown hang on system-wide multi-threaded sessions")
Assisted-by: Gemini:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@google.com>
---
 tools/perf/builtin-record.c | 15 +++++++++++++++
 tools/perf/tests/fdarray.c  | 32 ++++++++++++++++++++++++++++++++
 2 files changed, 47 insertions(+)

diff --git a/tools/perf/builtin-record.c b/tools/perf/builtin-record.c
index a57987851cf0..ad81458989b5 100644
--- a/tools/perf/builtin-record.c
+++ b/tools/perf/builtin-record.c
@@ -1169,6 +1169,21 @@ static int record__update_evlist_pollfd_from_thread(struct record *rec,
 		int e_pos = rec->index_map[i].evlist_pollfd_index;
 		int t_pos = rec->index_map[i].thread_pollfd_index;
 
+		if (e_entries[e_pos].fd == -1 || e_entries[e_pos].events == 0) {
+			/*
+			 * If the control file descriptor was closed, then evlist__ctlfd_process()
+			 * will have called evlist__finalize_ctlfd() on the PREVIOUS loop iteration
+			 * to cleanly set the core evlist's e_entries[e_pos].fd to -1.
+			 *
+			 * Since nonfilterable items are skipped by fdarray__filter(), the
+			 * thread's local t_entries[t_pos] retains its original state.
+			 * We must explicitly propagate the finalized -1 state to t_entries
+			 * BEFORE evaluating the strict equivalence check below.
+			 */
+			t_entries[t_pos].fd = -1;
+			t_entries[t_pos].events = 0;
+		}
+
 		if (e_entries[e_pos].fd != t_entries[t_pos].fd ||
 		    e_entries[e_pos].events != t_entries[t_pos].events) {
 			pr_err("Thread and evlist pollfd index mismatch\n");
diff --git a/tools/perf/tests/fdarray.c b/tools/perf/tests/fdarray.c
index 40983c3574b1..23860edb8ef0 100644
--- a/tools/perf/tests/fdarray.c
+++ b/tools/perf/tests/fdarray.c
@@ -80,6 +80,38 @@ static int test__fdarray__filter(struct test_suite *test __maybe_unused, int sub
 		goto out_delete;
 	}
 
+	fdarray__init_revents(fda, POLLHUP);
+	fda->priv[2].flags = fdarray_flag__nonfilterable;
+
+	pr_debug("\nfiltering all but fda->entries[2] (nonfilterable):");
+	fdarray__fprintf_prefix(fda, "before", stderr);
+
+	/*
+	 * Note: fdarray__filter() in tools/lib/api/fd/array.c evaluates the
+	 * fdarray_flag__nonfilterable flag at the very top of its loop via an
+	 * early continue. Therefore, it completely skips all processing for this
+	 * descriptor, guaranteeing its fd, events, and revents fields remain
+	 * entirely untouched by the filter mask evaluation below it.
+	 */
+	nr_fds = fdarray__filter(fda, POLLHUP, NULL, NULL);
+	fdarray__fprintf_prefix(fda, " after", stderr);
+
+	if (nr_fds != 0) {
+		pr_debug("\nfdarray__filter()=%d != 0, should be 0\n",
+			 nr_fds);
+		goto out_delete;
+	}
+	if (fda->entries[2].fd == -1) {
+		pr_debug("\nfdarray__filter() illegally modified nonfilterable fd!");
+		goto out_delete;
+	}
+	if (fda->entries[2].revents != POLLHUP) {
+		pr_debug("\nfdarray__filter() illegally modified nonfilterable revents!");
+		goto out_delete;
+	}
+
+	fda->priv[2].flags = 0; /* reset flags */
+
 	pr_debug("\n");
 
 	err = 0;
-- 
2.55.0.766.g2966f0265a-goog
[PATCH v8] perf record: Fix unhandled POLLHUP on non_perf_event descriptors
Posted by Ian Rogers 1 month, 1 week ago
When processing POLLHUP on a non_perf_event control descriptor,
evlist__finalize_ctlfd() is invoked to finalize the setup, correctly
setting the core evlist's poll array file descriptor to -1. However,
this finalized teardown state is never propagated back to the
individual thread's local replica of the pollfd array.

Consequently, on the next iteration of the main recording loop,
record__update_evlist_pollfd_from_thread() performs a strict
equivalence check between the core evlist's array and the thread's
localized poll array, detecting that the fd values no longer match.
This causes an immediate -EINVAL abort and a premature teardown.

Fix the underlying logic within
record__update_evlist_pollfd_from_thread() to sustainably propagate
the finalized teardown statuses (-1) originating from the core evlist
back to the thread's localized poll structure. This correctly
maintains synchronization and entirely prevents the unhandled
index mismatch crashes.

Additionally, add a unit test that explicitly validates that
fdarray__filter() preserves its invariants regarding
fdarray_flag__nonfilterable items to guard against regressions.

Fixes: fb4751e79c45 ("perf record: Fix teardown hang on system-wide multi-threaded sessions")
Assisted-by: Gemini:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@google.com>
---
 tools/lib/api/fd/array.c    |  4 ++++
 tools/perf/builtin-record.c | 15 +++++++++++++++
 tools/perf/tests/fdarray.c  | 32 ++++++++++++++++++++++++++++++++
 3 files changed, 51 insertions(+)

diff --git a/tools/lib/api/fd/array.c b/tools/lib/api/fd/array.c
index 67b73481df27..3200746d1657 100644
--- a/tools/lib/api/fd/array.c
+++ b/tools/lib/api/fd/array.c
@@ -116,6 +116,10 @@ int fdarray__filter(struct fdarray *fda, short revents,
 		return 0;
 
 	for (fd = 0; fd < fda->nr; ++fd) {
+		/*
+		 * Explicitly bypass nonfilterable items (e.g. control descriptors).
+		 * This ensures their fd, events, and revents remain completely untouched.
+		 */
 		if (fda->priv[fd].flags & fdarray_flag__nonfilterable)
 			continue;
 
diff --git a/tools/perf/builtin-record.c b/tools/perf/builtin-record.c
index a57987851cf0..ad81458989b5 100644
--- a/tools/perf/builtin-record.c
+++ b/tools/perf/builtin-record.c
@@ -1169,6 +1169,21 @@ static int record__update_evlist_pollfd_from_thread(struct record *rec,
 		int e_pos = rec->index_map[i].evlist_pollfd_index;
 		int t_pos = rec->index_map[i].thread_pollfd_index;
 
+		if (e_entries[e_pos].fd == -1 || e_entries[e_pos].events == 0) {
+			/*
+			 * If the control file descriptor was closed, then evlist__ctlfd_process()
+			 * will have called evlist__finalize_ctlfd() on the PREVIOUS loop iteration
+			 * to cleanly set the core evlist's e_entries[e_pos].fd to -1.
+			 *
+			 * Since nonfilterable items are skipped by fdarray__filter(), the
+			 * thread's local t_entries[t_pos] retains its original state.
+			 * We must explicitly propagate the finalized -1 state to t_entries
+			 * BEFORE evaluating the strict equivalence check below.
+			 */
+			t_entries[t_pos].fd = -1;
+			t_entries[t_pos].events = 0;
+		}
+
 		if (e_entries[e_pos].fd != t_entries[t_pos].fd ||
 		    e_entries[e_pos].events != t_entries[t_pos].events) {
 			pr_err("Thread and evlist pollfd index mismatch\n");
diff --git a/tools/perf/tests/fdarray.c b/tools/perf/tests/fdarray.c
index 40983c3574b1..23860edb8ef0 100644
--- a/tools/perf/tests/fdarray.c
+++ b/tools/perf/tests/fdarray.c
@@ -80,6 +80,38 @@ static int test__fdarray__filter(struct test_suite *test __maybe_unused, int sub
 		goto out_delete;
 	}
 
+	fdarray__init_revents(fda, POLLHUP);
+	fda->priv[2].flags = fdarray_flag__nonfilterable;
+
+	pr_debug("\nfiltering all but fda->entries[2] (nonfilterable):");
+	fdarray__fprintf_prefix(fda, "before", stderr);
+
+	/*
+	 * Note: fdarray__filter() in tools/lib/api/fd/array.c evaluates the
+	 * fdarray_flag__nonfilterable flag at the very top of its loop via an
+	 * early continue. Therefore, it completely skips all processing for this
+	 * descriptor, guaranteeing its fd, events, and revents fields remain
+	 * entirely untouched by the filter mask evaluation below it.
+	 */
+	nr_fds = fdarray__filter(fda, POLLHUP, NULL, NULL);
+	fdarray__fprintf_prefix(fda, " after", stderr);
+
+	if (nr_fds != 0) {
+		pr_debug("\nfdarray__filter()=%d != 0, should be 0\n",
+			 nr_fds);
+		goto out_delete;
+	}
+	if (fda->entries[2].fd == -1) {
+		pr_debug("\nfdarray__filter() illegally modified nonfilterable fd!");
+		goto out_delete;
+	}
+	if (fda->entries[2].revents != POLLHUP) {
+		pr_debug("\nfdarray__filter() illegally modified nonfilterable revents!");
+		goto out_delete;
+	}
+
+	fda->priv[2].flags = 0; /* reset flags */
+
 	pr_debug("\n");
 
 	err = 0;
-- 
2.55.0.766.g2966f0265a-goog