From: Steven Rostedt <rostedt@kernel.org>
To: linux-kernel@vger.kernel.org
Cc: Masami Hiramatsu <mhiramat@kernel.org>,
Mark Rutland <mark.rutland@arm.com>,
Mathieu Desnoyers <mathieu.desnoyers@efficios.com>,
Andrew Morton <akpm@linux-foundation.org>,
stable@vger.kernel.org,
syzbot+e0cc44465d6bae735679@syzkaller.appspotmail.com,
Vincent Donnefort <vdonnefort@google.com>
Subject: [for-linus][PATCH 10/12] ring-buffer: Prevent subbuf order change when resizing is disabled
Date: Sat, 08 Aug 2026 22:31:54 -0400 [thread overview]
Message-ID: <20260809023222.799156348@kernel.org> (raw)
In-Reply-To: 20260809023144.852271250@kernel.org
From: Vincent Donnefort <vdonnefort@google.com>
Because ring_buffer_subbuf_order_set() frees buffer pages, we can't
allow it when resizing is disabled. A non-consuming reader is at risk of
use-after-free (rb_advance_iter()).
Return -EBUSY on resize_disabled, matching ring_buffer_resize()
behaviour.
Cc: stable@vger.kernel.org
Fixes: f9b94daa542a ("ring-buffer: Set new size of the ring buffer sub page")
Link: https://patch.msgid.link/20260806211306.3704194-3-vdonnefort@google.com
Reported-by: syzbot+e0cc44465d6bae735679@syzkaller.appspotmail.com
Signed-off-by: Vincent Donnefort <vdonnefort@google.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
---
kernel/trace/ring_buffer.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/trace/ring_buffer.c b/kernel/trace/ring_buffer.c
index 09d502ef4c55..6cbd80ccef37 100644
--- a/kernel/trace/ring_buffer.c
+++ b/kernel/trace/ring_buffer.c
@@ -7360,7 +7360,7 @@ int ring_buffer_subbuf_order_set(struct trace_buffer *buffer, int order)
cpu_buffer = buffer->buffers[cpu];
- if (cpu_buffer->mapped) {
+ if (atomic_read(&cpu_buffer->resize_disabled)) {
err = -EBUSY;
goto error;
}
--
2.53.0
next prev parent reply other threads:[~2026-08-09 2:32 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-09 2:31 [for-linus][PATCH 00/12] tracing: Fixes for 7.2 Steven Rostedt
2026-08-09 2:31 ` [for-linus][PATCH 01/12] eventfs: Fix use-after-free in eventfs_remove_rec() Steven Rostedt
2026-08-09 2:31 ` [for-linus][PATCH 02/12] eventfs: Use children field for rcu head and add memory barriers Steven Rostedt
2026-08-09 2:31 ` [for-linus][PATCH 03/12] ftrace: Protect direct_functions in ftrace_find_rec_direct Steven Rostedt
2026-08-09 2:31 ` [for-linus][PATCH 04/12] ftrace: Protect direct_functions in update_ftrace_direct_del Steven Rostedt
2026-08-09 2:31 ` [for-linus][PATCH 05/12] ftrace: Protect direct_functions in update_ftrace_direct_mod Steven Rostedt
2026-08-09 2:31 ` [for-linus][PATCH 06/12] ftrace: Drop extra comma in trace_buffered_event_enable Steven Rostedt
2026-08-09 2:31 ` [for-linus][PATCH 07/12] ring-buffer: Use current_context for safe per-CPU buffer swap Steven Rostedt
2026-08-09 2:31 ` [for-linus][PATCH 08/12] ftrace: Fix off-by-one fentry site disable in ftrace_free_mem() Steven Rostedt
2026-08-09 2:31 ` [for-linus][PATCH 09/12] ring-buffer: Prevent resizing of persistent ring buffer Steven Rostedt
2026-08-09 2:31 ` Steven Rostedt [this message]
2026-08-09 2:31 ` [for-linus][PATCH 11/12] ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer() Steven Rostedt
2026-08-09 2:31 ` [for-linus][PATCH 12/12] ring-buffer: Fix crash passing ERR_PTR to kthread_stop() Steven Rostedt
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260809023222.799156348@kernel.org \
--to=rostedt@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mark.rutland@arm.com \
--cc=mathieu.desnoyers@efficios.com \
--cc=mhiramat@kernel.org \
--cc=stable@vger.kernel.org \
--cc=syzbot+e0cc44465d6bae735679@syzkaller.appspotmail.com \
--cc=vdonnefort@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.