All of lore.kernel.org
 help / color / mirror / Atom feed
From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
To: "Masami Hiramatsu (Google)" <mhiramat@kernel.org>
Cc: Steven Rostedt <rostedt@goodmis.org>,
	Peter Zijlstra <peterz@infradead.org>,
	Ingo Molnar <mingo@kernel.org>,
	x86@kernel.org, Jinchao Wang <wangjinchao600@gmail.com>,
	Mathieu Desnoyers <mathieu.desnoyers@efficios.com>,
	Thomas Gleixner <tglx@linutronix.de>,
	Borislav Petkov <bp@alien8.de>,
	Dave Hansen <dave.hansen@linux.intel.com>,
	"H . Peter Anvin" <hpa@zytor.com>,
	Alexander Shishkin <alexander.shishkin@linux.intel.com>,
	Ian Rogers <irogers@google.com>,
	linux-kernel@vger.kernel.org, linux-trace-kernel@vger.kernel.org,
	linux-doc@vger.kernel.org, linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v14 03/14] kprobes: Protect kprobe_blacklist with RCU
Date: Wed, 2 Sep 2026 10:30:49 +0900	[thread overview]
Message-ID: <20260902103049.78b8a90f58ddfcc89db71237@kernel.org> (raw)
In-Reply-To: <178810004323.64882.16493230858653316962.stgit@devnote2>

On Sun, 30 Aug 2026 23:27:23 +0900
"Masami Hiramatsu (Google)" <mhiramat@kernel.org> wrote:

> From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
> 
> __within_kprobe_blacklist() traverses kprobe_blacklist without holding
> kprobe_mutex. When a module is unloaded, kprobe_remove_area_blacklist()
> removes blacklist entries and immediately frees them with kfree().
> A concurrent call to within_kprobe_blacklist() can therefore dereference
> freed memory.
> 
> Furthermore, within_kprobe_blacklist() can be called in atomic or
> non-preemptible contexts where the sleeping kprobe_mutex cannot be taken.
> 
> Protect kprobe_blacklist with RCU. Use guard(rcu)() and
> list_for_each_entry_rcu() for traversal, list_add_tail_rcu() for
> insertions, list_del_rcu() for deletions, and kfree_rcu() to reclaim
> entries safely after a grace period.

I realized this is required even without wprobe. So let me take this
as a stable fix with following tags.

Fixes: 376e242429bf ("kprobes: Introduce NOKPROBE_SYMBOL() macro to maintain kprobes blacklist")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260807155802.F06041F000E9@smtp.kernel.org/

Thanks,

> 
> Assisted-by: Antigravity:gemini-3.7-flash
> Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
> ---
> Changes in v13:
>  - Newly added.
> ---
>  include/linux/kprobes.h |    1 +
>  kernel/kprobes.c        |   14 ++++++++++----
>  2 files changed, 11 insertions(+), 4 deletions(-)
> 
> diff --git a/include/linux/kprobes.h b/include/linux/kprobes.h
> index 8c4f3bb24429..e6de7ae55bda 100644
> --- a/include/linux/kprobes.h
> +++ b/include/linux/kprobes.h
> @@ -181,6 +181,7 @@ struct kprobe_blacklist_entry {
>  	struct list_head list;
>  	unsigned long start_addr;
>  	unsigned long end_addr;
> +	struct rcu_head rcu;
>  };
>  
>  #ifdef CONFIG_KPROBES
> diff --git a/kernel/kprobes.c b/kernel/kprobes.c
> index bfc89083daa9..6337da5cab9e 100644
> --- a/kernel/kprobes.c
> +++ b/kernel/kprobes.c
> @@ -1447,8 +1447,14 @@ static bool __within_kprobe_blacklist(unsigned long addr)
>  	/*
>  	 * If 'kprobe_blacklist' is defined, check the address and
>  	 * reject any probe registration in the prohibited area.
> +	 * Note: this can return true during transition period where
> +	 * (start_addr, end_addr) in the black list is shrinking
> +	 * but old entry has not been removed yet. This is acceptable
> +	 * because the worst case is that we reject more probes than
> +	 * we should.
>  	 */
> -	list_for_each_entry(ent, &kprobe_blacklist, list) {
> +	guard(rcu)();
> +	list_for_each_entry_rcu(ent, &kprobe_blacklist, list) {
>  		if (addr >= ent->start_addr && addr < ent->end_addr)
>  			return true;
>  	}
> @@ -2509,7 +2515,7 @@ int kprobe_add_ksym_blacklist(unsigned long entry)
>  	ent->start_addr = entry;
>  	ent->end_addr = entry + size;
>  	INIT_LIST_HEAD(&ent->list);
> -	list_add_tail(&ent->list, &kprobe_blacklist);
> +	list_add_tail_rcu(&ent->list, &kprobe_blacklist);
>  
>  	return (int)size;
>  }
> @@ -2603,8 +2609,8 @@ static void kprobe_remove_area_blacklist(unsigned long start, unsigned long end)
>  	list_for_each_entry_safe(ent, n, &kprobe_blacklist, list) {
>  		if (ent->start_addr < start || ent->start_addr >= end)
>  			continue;
> -		list_del(&ent->list);
> -		kfree(ent);
> +		list_del_rcu(&ent->list);
> +		kfree_rcu(ent, rcu);
>  	}
>  }
>  
> 


-- 
Masami Hiramatsu (Google) <mhiramat@kernel.org>

  parent reply	other threads:[~2026-09-02  1:30 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-30 14:26 [PATCH v14 00/14] tracing: wprobe: x86: Add wprobe for watchpoint Masami Hiramatsu (Google)
2026-08-30 14:27 ` [PATCH v14 01/14] x86/mce: Fix hardware debug register corruption on task migration Masami Hiramatsu (Google)
2026-08-30 14:40   ` sashiko-bot
2026-09-06 13:03     ` Masami Hiramatsu
2026-08-30 14:27 ` [PATCH v14 02/14] tracing/probes: Fix BTF kflag check for anonymous struct member access Masami Hiramatsu (Google)
2026-08-30 14:38   ` sashiko-bot
2026-08-31  1:24     ` Masami Hiramatsu
2026-08-30 14:27 ` [PATCH v14 03/14] kprobes: Protect kprobe_blacklist with RCU Masami Hiramatsu (Google)
2026-08-30 14:33   ` sashiko-bot
2026-09-02  1:30   ` Masami Hiramatsu [this message]
2026-08-30 14:27 ` [PATCH v14 04/14] x86/hw_breakpoints: Make DR7 updates NMI safe Masami Hiramatsu (Google)
2026-08-30 14:45   ` sashiko-bot
2026-09-06 15:28     ` Masami Hiramatsu
2026-08-30 14:27 ` [PATCH v14 05/14] x86/hw_breakpoints: Add arch_modify_local_hw_breakpoint_addr() API Masami Hiramatsu (Google)
2026-08-30 14:38   ` sashiko-bot
2026-09-06 15:42     ` Masami Hiramatsu
2026-08-30 14:27 ` [PATCH v14 06/14] HWBP: Add modify_local_hw_breakpoint_addr() API Masami Hiramatsu (Google)
2026-08-30 14:40   ` sashiko-bot
2026-09-06 15:43     ` Masami Hiramatsu
2026-08-30 14:28 ` [PATCH v14 07/14] tracing/wprobe: Add wprobe (watchpoint probe) trace event support Masami Hiramatsu (Google)
2026-08-30 14:42   ` sashiko-bot
2026-08-30 14:28 ` [PATCH v14 08/14] x86: hw_breakpoint: Add a kconfig to clarify when a breakpoint fires Masami Hiramatsu (Google)
2026-08-30 14:33   ` sashiko-bot
2026-08-30 14:28 ` [PATCH v14 09/14] selftests: tracing: Add a basic testcase for wprobe Masami Hiramatsu (Google)
2026-08-30 14:34   ` sashiko-bot
2026-08-30 14:28 ` [PATCH v14 10/14] selftests: tracing: Add syntax " Masami Hiramatsu (Google)
2026-08-30 14:37   ` sashiko-bot
2026-08-30 14:28 ` [PATCH v14 11/14] tracing/wprobe: Add set_wprobe and clear_wprobe event triggers Masami Hiramatsu (Google)
2026-08-30 14:52   ` sashiko-bot
2026-09-06 15:50     ` Masami Hiramatsu
2026-08-30 14:29 ` [PATCH v14 12/14] selftests: ftrace: Add wprobe trigger testcase Masami Hiramatsu (Google)
2026-08-30 14:44   ` sashiko-bot
2026-08-30 14:29 ` [PATCH v14 13/14] tracing/wprobe: Support BTF typecast in fetchargs Masami Hiramatsu (Google)
2026-08-30 14:44   ` sashiko-bot
2026-08-30 14:29 ` [PATCH v14 14/14] tracing/wprobe: Support BTF struct offset resolution in set_wprobe trigger Masami Hiramatsu (Google)
2026-08-30 14:46   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260902103049.78b8a90f58ddfcc89db71237@kernel.org \
    --to=mhiramat@kernel.org \
    --cc=alexander.shishkin@linux.intel.com \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=hpa@zytor.com \
    --cc=irogers@google.com \
    --cc=linux-doc@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=mathieu.desnoyers@efficios.com \
    --cc=mingo@kernel.org \
    --cc=peterz@infradead.org \
    --cc=rostedt@goodmis.org \
    --cc=tglx@linutronix.de \
    --cc=wangjinchao600@gmail.com \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.