Skip to content

Commit 3e060fc

Browse files
LeviYeoReumgregkh
authored andcommitted
perf: Fix dangling cgroup pointer in cpuctx
[ Upstream commit 3b7a34a ] Commit a3c3c66("perf/core: Fix child_total_time_enabled accounting bug at task exit") moves the event->state update to before list_del_event(). This makes the event->state test in list_del_event() always false; never calling perf_cgroup_event_disable(). As a result, cpuctx->cgrp won't be cleared properly; causing havoc. Fixes: a3c3c66("perf/core: Fix child_total_time_enabled accounting bug at task exit") Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Tested-by: David Wang <00107082@163.com> Link: https://lore.kernel.org/all/aD2TspKH%2F7yvfYoO@e129823.arm.com/ Stable-dep-of: 42c5ca1 ("perf/core: Fix group leader use-after-free after sibling detach") Signed-off-by: Sasha Levin <sashal@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent b5b89f1 commit 3e060fc

1 file changed

Lines changed: 4 additions & 12 deletions

File tree

‎kernel/events/core.c‎

Lines changed: 4 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -2110,18 +2110,6 @@ list_del_event(struct perf_event *event, struct perf_event_context *ctx)
21102110
if (event->group_leader == event)
21112111
del_event_from_groups(event, ctx);
21122112

2113-
/*
2114-
* If event was in error state, then keep it
2115-
* that way, otherwise bogus counts will be
2116-
* returned on read(). The only way to get out
2117-
* of error state is by explicit re-enabling
2118-
* of the event
2119-
*/
2120-
if (event->state > PERF_EVENT_STATE_OFF) {
2121-
perf_cgroup_event_disable(event, ctx);
2122-
perf_event_set_state(event, PERF_EVENT_STATE_OFF);
2123-
}
2124-
21252113
ctx->generation++;
21262114
}
21272115

@@ -2469,6 +2457,10 @@ __perf_remove_from_context(struct perf_event *event,
24692457
state = PERF_EVENT_STATE_DEAD;
24702458
}
24712459
event_sched_out(event, cpuctx, ctx);
2460+
2461+
if (event->state > PERF_EVENT_STATE_OFF)
2462+
perf_cgroup_event_disable(event, ctx);
2463+
24722464
perf_event_set_state(event, min(event->state, state));
24732465
if (flags & DETACH_GROUP)
24742466
perf_group_detach(event);

0 commit comments

Comments
 (0)