From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
To: Peter Zijlstra <peterz@infradead.org>
Cc: Andrii Nakryiko <andrii.nakryiko@gmail.com>,
Oleg Nesterov <oleg@redhat.com>, Breno Leitao <leitao@debian.org>,
Ingo Molnar <mingo@redhat.com>,
Arnaldo Carvalho de Melo <acme@kernel.org>,
Namhyung Kim <namhyung@kernel.org>,
Mark Rutland <mark.rutland@arm.com>,
Alexander Shishkin <alexander.shishkin@linux.intel.com>,
Jiri Olsa <jolsa@kernel.org>, Ian Rogers <irogers@google.com>,
Adrian Hunter <adrian.hunter@intel.com>,
James Clark <james.clark@linaro.org>,
Andrii Nakryiko <andrii@kernel.org>,
linux-perf-users@vger.kernel.org, linux-kernel@vger.kernel.org,
linux-trace-kernel@vger.kernel.org, kernel-team@meta.com,
stable@vger.kernel.org
Subject: Re: [PATCH] uprobes: Fix NULL pointer dereference in hprobe_expire()
Date: Fri, 31 Jul 2026 09:56:52 +0900 [thread overview]
Message-ID: <20260731095652.fc5d64f8c122d7dc6ddd89be@kernel.org> (raw)
In-Reply-To: <20260730103824.GD751831@noisy.programming.kicks-ass.net>
On Thu, 30 Jul 2026 12:38:24 +0200
Peter Zijlstra <peterz@infradead.org> wrote:
> On Thu, Jul 30, 2026 at 08:54:21AM +0900, Masami Hiramatsu wrote:
> > On Wed, 29 Jul 2026 12:31:08 -0700
> > Andrii Nakryiko <andrii.nakryiko@gmail.com> wrote:
> >
> > > On Wed, Jul 29, 2026 at 9:02 AM Oleg Nesterov <oleg@redhat.com> wrote:
> > > >
> > > > On 07/29, Breno Leitao wrote:
> > > > >
> > > > > --- a/kernel/events/uprobes.c
> > > > > +++ b/kernel/events/uprobes.c
> > > > > @@ -832,7 +832,7 @@ static struct uprobe *hprobe_expire(struct hprobe *hprobe, bool get)
> > > > > if (try_cmpxchg(&hprobe->state, &hstate, uprobe ? HPROBE_STABLE : HPROBE_GONE)) {
> > > > > /* We won the race, we are the ones to unlock SRCU */
> > > > > __srcu_read_unlock(&uretprobes_srcu, hprobe->srcu_idx);
> > > > > - return get ? get_uprobe(uprobe) : uprobe;
> > > > > + return get && uprobe ? get_uprobe(uprobe) : uprobe;
> > > >
> > > > Well, looks "obviously correct". At least the current code is obviously
> > > > wrong, it even checks uprobe != NULL 3 lines above.
> > > >
> > > > Andrii ?
> > > >
> > >
> > > Yes, indeed, I'm more surprised this didn't come up much earlier
> > > (probably it's rare enough to have uretprobe with refcnt at zero
> > > during fork). The fix looks good, thanks!
> > >
> > > Acked-by: Andrii Nakryiko <andrii@kernel.org>
> > >
> > > > Acked-by: Oleg Nesterov <oleg@redhat.com>
> > > >
> >
> > Thanks, this seems good to me. (uprobe is NULL checked in try_cmpxchg(),
> > so it could be NULL.)
> >
> > Can I pick this to probes/fixes branch?
>
> tip/perf/urgent ?
Either way works. Can we update MAINTAINERS file if you will maintain
uprobe in tip tree?
Thank you,
--
Masami Hiramatsu (Google) <mhiramat@kernel.org>
prev parent reply other threads:[~2026-07-31 0:56 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 14:44 [PATCH] uprobes: Fix NULL pointer dereference in hprobe_expire() Breno Leitao
2026-07-29 16:02 ` Oleg Nesterov
2026-07-29 19:31 ` Andrii Nakryiko
2026-07-29 23:54 ` Masami Hiramatsu
2026-07-30 10:38 ` Peter Zijlstra
2026-07-31 0:56 ` Masami Hiramatsu [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260731095652.fc5d64f8c122d7dc6ddd89be@kernel.org \
--to=mhiramat@kernel.org \
--cc=acme@kernel.org \
--cc=adrian.hunter@intel.com \
--cc=alexander.shishkin@linux.intel.com \
--cc=andrii.nakryiko@gmail.com \
--cc=andrii@kernel.org \
--cc=irogers@google.com \
--cc=james.clark@linaro.org \
--cc=jolsa@kernel.org \
--cc=kernel-team@meta.com \
--cc=leitao@debian.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=mark.rutland@arm.com \
--cc=mingo@redhat.com \
--cc=namhyung@kernel.org \
--cc=oleg@redhat.com \
--cc=peterz@infradead.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.