From: sashiko-bot@kernel.org
To: "Danish Khateeb" <danishkhateeb03@gmail.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH] perf/core: Don't send SIGTRAP after exec removed the event
Date: Tue, 29 Sep 2026 18:46:38 +0000 [thread overview]
Message-ID: <20260929184639.53F4E1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929182935.355892-1-danishkhateeb03@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] perf: strict event->state check allows fatal SIGTRAP on execve with O_CLOEXEC
--
commit 7195999db39d67f15f48d557a068f0dc7588f8ab
Author: Danish Khateeb <danishkhateeb03@gmail.com>
perf/core: Don't send SIGTRAP after exec removed the event
This commit prevents a SIGTRAP from reaching a newly executed program if an
event with remove_on_exec overflows right before execve(). It adds a check for
the PERF_EVENT_STATE_EXIT state in perf_sigtrap() to drop the signal if the
event was removed during exec.
> diff --git a/kernel/events/core.c b/kernel/events/core.c
> index 634d2ccbab82d..948583ffeb535 100644
> --- a/kernel/events/core.c
> +++ b/kernel/events/core.c
> @@ -7631,6 +7631,14 @@ static void perf_sigtrap(struct perf_event *event)
> if (current->flags & PF_EXITING)
> return;
>
> + /*
> + * exec() removed the event (remove_on_exec) after this signal was
> + * queued. The new program has default signal handlers, so a SIGTRAP
> + * would kill it.
> + */
> + if (event->state == PERF_EVENT_STATE_EXIT)
[Severity: High]
Does this strict equality check account for the PERF_EVENT_STATE_DEAD state
caused by O_CLOEXEC processing?
If a perf event is configured with remove_on_exec=1, sigtrap=1, and the file
descriptor is opened with O_CLOEXEC, an event overflow queues
perf_pending_task() via task_work_add().
When the task begins execve(), do_close_on_exec() closes the O_CLOEXEC file
descriptor. fput() then queues ____fput via task_work_add(). Because the
task_works list executes in LIFO order (works are prepended to the head),
____fput is positioned to run before perf_pending_task().
After perf_event_exec() removes the event and sets
event->state = PERF_EVENT_STATE_EXIT, execve() completes and task_work_run()
begins processing:
____fput()
perf_release()
perf_event_release_kernel()
event->state = PERF_EVENT_STATE_DEAD;
When perf_pending_task() subsequently runs and calls perf_sigtrap(), the
event state is PERF_EVENT_STATE_DEAD (-5). Since -5 != PERF_EVENT_STATE_EXIT
(-3), the strict equality check bypasses the filter, erroneously sending
SIGTRAP and killing the new program.
Should this check for detached states via
if (event->state <= PERF_EVENT_STATE_EXIT) instead?
> + return;
> +
> /*
> * We'd expect this to only occur if the irq_work is delayed and either
> * ctx->task or current has changed in the meantime. This can be the
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260929182935.355892-1-danishkhateeb03@gmail.com?part=1
prev parent reply other threads:[~2026-09-29 18:46 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 18:29 [PATCH] perf/core: Don't send SIGTRAP after exec removed the event Danish Khateeb
2026-09-29 18:46 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929184639.53F4E1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=danishkhateeb03@gmail.com \
--cc=linux-perf-users@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox