From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B2F9E2E06E4; Tue, 25 Aug 2026 13:51:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787665899; cv=none; b=K5O9TiaK2A8VSZ5Erx6cR5tCKjJH/lRlaip5d8OEVS3lzHNtbdCFN0yCAXMz/ae1M4w+cpzPhKIWw4GTAlg8SAvoLDwgNFhgaGuMM89K0w6QzUvNwxpQVeiyybVjGw7JQWsmWtbei99ak+vxmUCyk/Fai2HxmhqKZ+EvO28GKbY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787665899; c=relaxed/simple; bh=4/6aiuFroIqxStYRmt5epqxinN20BZWs6evIvQobWcY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=VrHONBXGnQ3PmmEsqyCKCSnV6yLxKifQeoEDR1cwCrqd8anyf3vL/WF2zlMQS6zgZtVjYQvWBaOlBXsqYXfGrNXCqTnITRgvK/+c5OMUMmLZ8TSAXuezQYZdDJfPVSvzvDAVyKtKLoiAS69ufpETpj2EsV8P9mC3Ej9jpuPzUuY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=0EaKO5l2; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="0EaKO5l2" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 122641F000E9; Tue, 25 Aug 2026 13:51:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1787665897; bh=jxSGqv8WRKV6OweoVBBTJZy1NTAyChM4Xcln8WjOCMA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=0EaKO5l2b3V6qumygPIjwRHgjvsPEmxKNuzPgHdhRGNSdsKlsCOwIe5ZhWNHuBGgg SCn5IxndRVYz65gT3sLwbgIGWYgrs38MMBaSWufcdbo+bQMMnWGoGmHEUbalbdgr+v FS55D4LMzhSPisEAKCc2ckLcrluV3u9rdXKFsCyE= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Leo Yan , "Peter Zijlstra (Intel)" , Sasha Levin Subject: [PATCH 6.1 16/79] perf: Fix cgroup state vs ERROR Date: Tue, 25 Aug 2026 15:25:56 +0200 Message-ID: <20260825132542.309842108@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260825132541.677185791@linuxfoundation.org> References: <20260825132541.677185791@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.1-stable review patch. If anyone has any objections, please let me know. ------------------ From: Peter Zijlstra [ Upstream commit 61988e36dc5457cdff7ae7927e8d9ad1419ee998 ] While chasing down a missing perf_cgroup_event_disable() elsewhere, Leo Yan found that both perf_put_aux_event() and perf_remove_sibling_event() were also missing one. Specifically, the rule is that events that switch to OFF,ERROR need to call perf_cgroup_event_disable(). Unify the disable paths to ensure this. Fixes: ab43762ef010 ("perf: Allow normal events to output AUX data") Fixes: 9f0c4fa111dc ("perf/core: Add a new PERF_EV_CAP_SIBLING event capability") Reported-by: Leo Yan Signed-off-by: Peter Zijlstra (Intel) Link: https://lkml.kernel.org/r/20250605123343.GD35970@noisy.programming.kicks-ass.net Stable-dep-of: 42c5ca1f0a28 ("perf/core: Fix group leader use-after-free after sibling detach") Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- kernel/events/core.c | 56 +++++++++++++++++++++++++++------------------------ 1 file changed, 30 insertions(+), 26 deletions(-) --- a/kernel/events/core.c +++ b/kernel/events/core.c @@ -2059,14 +2059,13 @@ perf_aux_output_match(struct perf_event } static void put_event(struct perf_event *event); -static void event_sched_out(struct perf_event *event, - struct perf_cpu_context *cpuctx, - struct perf_event_context *ctx); +static void __event_disable(struct perf_event *event, + struct perf_event_context *ctx, + enum perf_event_state state); static void perf_put_aux_event(struct perf_event *event) { struct perf_event_context *ctx = event->ctx; - struct perf_cpu_context *cpuctx = __get_cpu_context(ctx); struct perf_event *iter; /* @@ -2095,8 +2094,7 @@ static void perf_put_aux_event(struct pe * state so that we don't try to schedule it again. Note * that perf_event_enable() will clear the ERROR status. */ - event_sched_out(iter, cpuctx, ctx); - perf_event_set_state(event, PERF_EVENT_STATE_ERROR); + __event_disable(iter, ctx, PERF_EVENT_STATE_ERROR); } } @@ -2150,21 +2148,6 @@ static inline struct list_head *get_even return event->attr.pinned ? &ctx->pinned_active : &ctx->flexible_active; } -/* - * Events that have PERF_EV_CAP_SIBLING require being part of a group and - * cannot exist on their own, schedule them out and move them into the ERROR - * state. Also see _perf_event_enable(), it will not be able to recover - * this ERROR state. - */ -static inline void perf_remove_sibling_event(struct perf_event *event) -{ - struct perf_event_context *ctx = event->ctx; - struct perf_cpu_context *cpuctx = __get_cpu_context(ctx); - - event_sched_out(event, cpuctx, ctx); - perf_event_set_state(event, PERF_EVENT_STATE_ERROR); -} - static void perf_group_detach(struct perf_event *event) { struct perf_event *leader = event->group_leader; @@ -2200,8 +2183,15 @@ static void perf_group_detach(struct per */ list_for_each_entry_safe(sibling, tmp, &event->sibling_list, sibling_list) { + /* + * Events that have PERF_EV_CAP_SIBLING require being part of + * a group and cannot exist on their own, schedule them out + * and move them into the ERROR state. Also see + * _perf_event_enable(), it will not be able to recover this + * ERROR state. + */ if (sibling->event_caps & PERF_EV_CAP_SIBLING) - perf_remove_sibling_event(sibling); + __event_disable(sibling, ctx, PERF_EVENT_STATE_ERROR); sibling->group_leader = sibling; list_del_init(&sibling->sibling_list); @@ -2463,6 +2453,15 @@ static void perf_remove_from_context(str event_function_call(event, __perf_remove_from_context, (void *)flags); } +static void __event_disable(struct perf_event *event, + struct perf_event_context *ctx, + enum perf_event_state state) +{ + event_sched_out(event, __get_cpu_context(ctx), ctx); + perf_cgroup_event_disable(event, ctx); + perf_event_set_state(event, state); +} + /* * Cross CPU call to disable a performance event */ @@ -2479,13 +2478,18 @@ static void __perf_event_disable(struct update_cgrp_time_from_event(event); } + /* + * When disabling a group leader, the whole group becomes ineligible + * to run, so schedule out the full group. + */ if (event == event->group_leader) group_sched_out(event, cpuctx, ctx); - else - event_sched_out(event, cpuctx, ctx); - perf_event_set_state(event, PERF_EVENT_STATE_OFF); - perf_cgroup_event_disable(event, ctx); + /* + * But only mark the leader OFF; the siblings will remain + * INACTIVE. + */ + __event_disable(event, ctx, PERF_EVENT_STATE_OFF); } /*