From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 031C22E06E4; Tue, 25 Aug 2026 13:59:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787666364; cv=none; b=RpVY2wHSR0Su6DuKoCISbaFvoYYN7mI1GBG5uqAlGVzJOKXgFuIZY6mKLaFSHfRZ6aQja5hc0qzFW8VtYn+1BRO6Aiy7sFqaf0LEQ9C2NHx0fhD+E6b9ma3jHWsJlmRKVPAycXhAI0qfxe3PoCS67dgNpXFmCHpYeg3MZNQlVYA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787666364; c=relaxed/simple; bh=nxtD5SxP2PAaftVJ9mqd+4oQ9tDTpAChph3T5mcSmUk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gIDkDpCcFZBzQiLn7CQ7pcmMpqrAZdrEraBeURmeQGevKkyFBWHf/fktPkT+pK81zKDShTUdsFve5FUUO+4ycnOYls7oUxsFyhcDeMCm7gSNO/JeXjEsvEBiAStaPOTg43tT3OuCWLz9goVy9TIkyqM68314TFLIDTjt5tJMc9M= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=U6no6cpu; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="U6no6cpu" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 4E3231F000E9; Tue, 25 Aug 2026 13:59:22 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1787666362; bh=GzbhAHcmEzdy5eiUCqToEBLreADPbFp5Vse0hzskwD0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=U6no6cpuEqGPPIDkaH1Ysvm8BKviJxvzbu/+rM96MCyXWXItEyoatfuJPcj5X6wzb 6j3IwuYIC5prFvYsHOys1baNKD7npKQ/dlXJrDnOXOWNrb00VC98EcpiHRrUOl/RoK Gk9LvNQc+c5tzFlpBmSsHBOY+jB1nAp20OPwdsvw= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Yeoreum Yun , "Peter Zijlstra (Intel)" , David Wang <00107082@163.com>, Sasha Levin Subject: [PATCH 5.10 18/57] perf: Fix dangling cgroup pointer in cpuctx Date: Tue, 25 Aug 2026 15:26:40 +0200 Message-ID: <20260825132541.999977625@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260825132541.342390421@linuxfoundation.org> References: <20260825132541.342390421@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 5.10-stable review patch. If anyone has any objections, please let me know. ------------------ From: Yeoreum Yun [ Upstream commit 3b7a34aebbdf2a4b7295205bf0c654294283ec82 ] Commit a3c3c6667("perf/core: Fix child_total_time_enabled accounting bug at task exit") moves the event->state update to before list_del_event(). This makes the event->state test in list_del_event() always false; never calling perf_cgroup_event_disable(). As a result, cpuctx->cgrp won't be cleared properly; causing havoc. Fixes: a3c3c6667("perf/core: Fix child_total_time_enabled accounting bug at task exit") Signed-off-by: Yeoreum Yun Signed-off-by: Peter Zijlstra (Intel) Tested-by: David Wang <00107082@163.com> Link: https://lore.kernel.org/all/aD2TspKH%2F7yvfYoO@e129823.arm.com/ Stable-dep-of: 42c5ca1f0a28 ("perf/core: Fix group leader use-after-free after sibling detach") Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- kernel/events/core.c | 19 +++++++------------ 1 file changed, 7 insertions(+), 12 deletions(-) --- a/kernel/events/core.c +++ b/kernel/events/core.c @@ -2117,18 +2117,6 @@ list_del_event(struct perf_event *event, if (event->group_leader == event) del_event_from_groups(event, ctx); - /* - * If event was in error state, then keep it - * that way, otherwise bogus counts will be - * returned on read(). The only way to get out - * of error state is by explicit re-enabling - * of the event - */ - if (event->state > PERF_EVENT_STATE_OFF) { - perf_cgroup_event_disable(event, ctx); - perf_event_set_state(event, PERF_EVENT_STATE_OFF); - } - ctx->generation++; } @@ -2422,6 +2410,7 @@ __perf_remove_from_context(struct perf_e struct perf_event_context *ctx, void *info) { + enum perf_event_state state = PERF_EVENT_STATE_OFF; unsigned long flags = (unsigned long)info; if (ctx->is_active & EVENT_TIME) { @@ -2430,6 +2419,12 @@ __perf_remove_from_context(struct perf_e } event_sched_out(event, cpuctx, ctx); + + if (event->state > PERF_EVENT_STATE_OFF) + perf_cgroup_event_disable(event, ctx); + + perf_event_set_state(event, min(event->state, state)); + if (flags & DETACH_GROUP) perf_group_detach(event); list_del_event(event, ctx);