From: sashiko-bot@kernel.org
To: "Ian Rogers" <irogers@google.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v8 1/2] perf: Add Raspberry Pi BCM2835 AXI PMU driver
Date: Thu, 13 Aug 2026 06:51:57 +0000 [thread overview]
Message-ID: <20260813065157.5B2051F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260813064228.2799872-2-irogers@google.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] Registering the PMU before completing all initialization steps creates a use-after-free race condition if probe fails.
- [Low] Usage of `#if LINUX_VERSION_CODE` shim for backward compatibility in an upstream patch.
--
--- Patch [1]: [PATCH v8 1/2] perf: Add Raspberry Pi BCM2835 AXI PMU driver ---
commit e754b178c7f623d2ebff89b932e852beed8622b9
Author: Ian Rogers <irogers@google.com>
Subject: perf: Add Raspberry Pi BCM2835 AXI PMU driver
This commit adds a new performance monitoring driver for the Raspberry Pi
AXI bus (BCM2835/2711), exposing system-level and VideoCore PMU hardware to
the Linux perf subsystem.
> diff --git a/drivers/perf/rpi_axi_pmu.c b/drivers/perf/rpi_axi_pmu.c
> new file mode 100644
> index 0000000000000..676c2a3d5962e
> --- /dev/null
> +++ b/drivers/perf/rpi_axi_pmu.c
[ ... ]
> +#if LINUX_VERSION_CODE < KERNEL_VERSION(6, 13, 0)
> +static inline void rpi_hrtimer_setup(struct hrtimer *timer,
> + enum hrtimer_restart (*function)(struct hrtimer *),
> + clockid_t clock_id, enum hrtimer_mode mode)
> +{
> + hrtimer_init(timer, clock_id, mode);
> + timer->function = function;
> +}
> +#define hrtimer_setup rpi_hrtimer_setup
> +#endif
[Severity: Low]
This isn't a bug, but is this version compatibility shim intended for upstream
inclusion? Upstream patches typically target the current API of the tree they
are being merged into without including out-of-tree macro shims for backward
compatibility with older kernels.
[ ... ]
> + ret = perf_pmu_register(&pmu->pmu, PMU_NAME, /*type=*/-1);
> + if (ret) {
> + dev_err(dev, "PMU register failed %d\n", ret);
> + goto err_teardown;
> + }
> +
> + ret = cpuhp_state_add_instance(rpi_axi_pmu_cpuhp_state, &pmu->cpuhp_node);
> + if (ret) {
> + dev_err(dev, "Failed to add cpuhp instance %d\n", ret);
> + goto err_pmu_unregister;
> + }
[Severity: High]
Could this expose a use-after-free race condition if probe fails here?
When perf_pmu_register() completes, the PMU is exposed to userspace. If
cpuhp_state_add_instance() fails immediately after, the error path goes to
err_pmu_unregister and calls perf_pmu_unregister().
However, perf_pmu_unregister() does not revoke existing open events. If
userspace opens a perf event on this PMU in the small window between
registration and unregistration, the event will retain a pointer to the pmu
struct.
Because the pmu struct was allocated with devm_kzalloc(), it will be freed
by the devres manager as soon as the probe function returns the error, leaving
the open event with a dangling pointer that can corrupt memory upon subsequent
accesses. Would it be safer to register the CPU hotplug instance before
exposing the PMU to userspace?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260813064228.2799872-1-irogers@google.com?part=1
next prev parent reply other threads:[~2026-08-13 6:51 UTC|newest]
Thread overview: 60+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-11 8:38 [PATCH v1 0/2] perf: Add Raspberry Pi AXI PMU driver Ian Rogers
2026-08-11 8:38 ` [PATCH v1 1/2] perf: Add Raspberry Pi BCM2835 " Ian Rogers
2026-08-11 14:32 ` Uwe Kleine-König
2026-08-11 8:38 ` [PATCH v1 2/2] perf: Add Raspberry Pi 5 (BCM2712) AXI PMU support Ian Rogers
2026-08-11 23:51 ` [PATCH v2 0/2] perf: Add Raspberry Pi AXI PMU driver Ian Rogers
2026-08-11 23:51 ` [PATCH v2 1/2] perf: Add Raspberry Pi BCM2835 " Ian Rogers
2026-08-12 0:04 ` sashiko-bot
2026-08-11 23:51 ` [PATCH v2 2/2] perf: Add Raspberry Pi 5 (BCM2712) AXI PMU support Ian Rogers
2026-08-12 0:05 ` sashiko-bot
2026-08-12 0:27 ` [PATCH v3 0/2] perf: Add Raspberry Pi AXI PMU driver Ian Rogers
2026-08-12 0:27 ` [PATCH v3 1/2] perf: Add Raspberry Pi BCM2835 " Ian Rogers
2026-08-12 0:40 ` sashiko-bot
2026-08-12 0:27 ` [PATCH v3 2/2] perf: Add Raspberry Pi 5 (BCM2712) AXI PMU support Ian Rogers
2026-08-12 0:40 ` sashiko-bot
2026-08-12 5:24 ` [PATCH v4 0/2] perf: Add Raspberry Pi AXI PMU driver Ian Rogers
2026-08-12 5:24 ` [PATCH v4 1/2] perf: Add Raspberry Pi BCM2835 " Ian Rogers
2026-08-12 5:36 ` sashiko-bot
2026-08-12 5:24 ` [PATCH v4 2/2] perf: Add Raspberry Pi 5 (BCM2712) AXI PMU support Ian Rogers
2026-08-12 5:34 ` sashiko-bot
2026-08-12 8:27 ` [PATCH v4 0/2] perf: Add Raspberry Pi AXI PMU driver Will Deacon
2026-08-12 13:38 ` Ian Rogers
2026-08-12 16:26 ` Uwe Kleine-König
2026-08-12 21:37 ` Ian Rogers
2026-08-13 6:59 ` Uwe Kleine-König
2026-08-13 8:41 ` Will Deacon
2026-08-12 23:01 ` [PATCH v5 " Ian Rogers
2026-08-12 23:01 ` [PATCH v5 1/2] perf: Add Raspberry Pi BCM2835 " Ian Rogers
2026-08-12 23:15 ` sashiko-bot
2026-08-12 23:01 ` [PATCH v5 2/2] perf: Add Raspberry Pi 5 (BCM2712) AXI PMU support Ian Rogers
2026-08-12 23:18 ` sashiko-bot
2026-08-12 23:07 ` [PATCH v5 0/2] perf: Add Raspberry Pi AXI PMU driver Ian Rogers
2026-08-12 23:07 ` Ian Rogers
2026-08-12 23:07 ` [PATCH v5 1/2] perf: Add Raspberry Pi BCM2835 " Ian Rogers
2026-08-12 23:25 ` sashiko-bot
2026-08-13 0:06 ` Florian Fainelli
2026-08-12 23:08 ` [PATCH v5 2/2] perf: Add Raspberry Pi 5 (BCM2712) AXI PMU support Ian Rogers
2026-08-12 23:24 ` sashiko-bot
2026-08-13 4:35 ` [PATCH v6 0/2] perf: Add Raspberry Pi AXI PMU driver Ian Rogers
2026-08-13 4:35 ` [PATCH v6 1/2] perf: Add Raspberry Pi BCM2835 " Ian Rogers
2026-08-13 4:48 ` sashiko-bot
2026-08-13 4:35 ` [PATCH v6 2/2] perf: Add Raspberry Pi 5 (BCM2712) AXI PMU support Ian Rogers
2026-08-13 4:43 ` sashiko-bot
2026-08-13 5:24 ` [PATCH v7 0/2] perf: Add Raspberry Pi AXI PMU driver Ian Rogers
2026-08-13 5:24 ` [PATCH v7 1/2] perf: Add Raspberry Pi BCM2835 " Ian Rogers
2026-08-13 5:35 ` sashiko-bot
2026-08-13 5:24 ` [PATCH v7 2/2] perf: Add Raspberry Pi 5 (BCM2712) AXI PMU support Ian Rogers
2026-08-13 5:46 ` sashiko-bot
2026-08-13 6:42 ` [PATCH v8 0/2] perf: Add Raspberry Pi AXI PMU driver Ian Rogers
2026-08-13 6:42 ` [PATCH v8 1/2] perf: Add Raspberry Pi BCM2835 " Ian Rogers
2026-08-13 6:51 ` sashiko-bot [this message]
2026-08-13 6:42 ` [PATCH v8 2/2] perf: Add Raspberry Pi 5 (BCM2712) AXI PMU support Ian Rogers
2026-08-13 6:52 ` sashiko-bot
2026-08-13 7:30 ` [PATCH v9 0/2] perf: Add Raspberry Pi AXI PMU driver Ian Rogers
2026-08-13 8:03 ` [PATCH v10 " Ian Rogers
2026-08-13 7:30 ` perf: Add Raspberry Pi BCM2835 " Ian Rogers
2026-08-13 7:40 ` sashiko-bot
2026-08-13 7:30 ` perf: Add Raspberry Pi 5 (BCM2712) AXI PMU support Ian Rogers
2026-08-13 8:03 ` perf: Add Raspberry Pi BCM2835 AXI PMU driver Ian Rogers
2026-08-13 8:13 ` sashiko-bot
2026-08-13 8:03 ` perf: Add Raspberry Pi 5 (BCM2712) AXI PMU support Ian Rogers
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260813065157.5B2051F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=irogers@google.com \
--cc=linux-perf-users@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.