From: Vincent Donnefort <vdonnefort@google.com>
To: David Carlier <devnexen@gmail.com>
Cc: Steven Rostedt <rostedt@goodmis.org>,
Masami Hiramatsu <mhiramat@kernel.org>,
Mathieu Desnoyers <mathieu.desnoyers@efficios.com>,
linux-trace-kernel@vger.kernel.org, linux-kernel@vger.kernel.org,
stable@vger.kernel.org
Subject: Re: [PATCH] ring-buffer: Check resize_disabled before publishing the new subbuf order
Date: Sun, 13 Sep 2026 21:41:14 +0100 [thread overview]
Message-ID: <aqcKav91XJsCLxPJ@google.com> (raw)
In-Reply-To: <aqcJq1-R-LaK9uBi@google.com>
On Sun, Sep 13, 2026 at 09:38:03PM +0100, Vincent Donnefort wrote:
> On Sat, Sep 12, 2026 at 11:39:38AM +0100, David Carlier wrote:
> > ring_buffer_subbuf_order_set() stores the new order and only then walks
> > the CPUs, returning -EBUSY if any of them has resizing disabled. A user
> > mapped buffer has resizing disabled, and __rb_map_vma() reads
> > buffer->subbuf_order without buffer->mutex, so an mmap of an already
> > mapped CPU racing the failing order change sizes the mapping with the
> > new order and inserts pages past the sub-buffer into the VMA.
> >
> > Check the CPUs before storing the new order.
> >
> > Fixes: 117c39200d9d ("ring-buffer: Introducing ring-buffer mapping functions")
> > Cc: stable@vger.kernel.org
> > Signed-off-by: David Carlier <devnexen@gmail.com>
> > ---
> > kernel/trace/ring_buffer.c | 8 ++++++++
> > 1 file changed, 8 insertions(+)
> >
> > diff --git a/kernel/trace/ring_buffer.c b/kernel/trace/ring_buffer.c
> > index 9c03a555a6ba..d7e5e4620d09 100644
> > --- a/kernel/trace/ring_buffer.c
> > +++ b/kernel/trace/ring_buffer.c
> > @@ -7474,6 +7474,14 @@ int ring_buffer_subbuf_order_set(struct trace_buffer *buffer, int order)
> >
> > old_capacity = rb_subbuf_capacity(buffer);
> >
> > + /* The mmap fast path reads subbuf_order without buffer->mutex. */
> > + for_each_buffer_cpu(buffer, cpu) {
> > + if (!cpumask_test_cpu(cpu, buffer->cpumask))
> > + continue;
> > + if (atomic_read(&buffer->buffers[cpu]->resize_disabled))
> > + return -EBUSY;
> > + }
> > +
> > atomic_inc(&buffer->record_disabled);
> >
> > /* Make sure all commits have finished */
> > --
> > 2.55.0
> >
>
> I do not think this is correct.
>
> __rb_map_vma() reads subbuf_order without the the buffer lock __only__ if it is
> already ->user_mapped, which means it has already the resized disabled.
>
> During the first setup, it takes buffer->mutex.
>
> --
> Vincent
Ha my bad, that function also modifies the subbuf_order __before__ checking the
resize_disabled.
Could we also clean the later resize_disabled check in the following loop?
--
Vincent
prev parent reply other threads:[~2026-09-13 20:41 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-12 10:39 [PATCH] ring-buffer: Check resize_disabled before publishing the new subbuf order David Carlier
2026-09-12 10:56 ` sashiko-bot
2026-09-12 11:59 ` David CARLIER
2026-09-13 20:38 ` Vincent Donnefort
2026-09-13 20:41 ` Vincent Donnefort [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aqcKav91XJsCLxPJ@google.com \
--to=vdonnefort@google.com \
--cc=devnexen@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=mathieu.desnoyers@efficios.com \
--cc=mhiramat@kernel.org \
--cc=rostedt@goodmis.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.