* [PATCH 1/2] s390/cpum_cf: Check session mask before cpu offline
2026-10-06 11:13 [PATCH 0/2] s390/cpum_cf: Check session cpu mask during hotplug Sumanth Korikkar
@ 2026-10-06 11:13 ` Sumanth Korikkar
2026-10-06 11:24 ` sashiko-bot
2026-10-06 11:13 ` [PATCH 2/2] s390/cpum_cf: Honor hwctr session cpu mask during hotplug Sumanth Korikkar
2026-10-06 14:04 ` [PATCH 0/2] s390/cpum_cf: Check " Heiko Carstens
2 siblings, 1 reply; 7+ messages in thread
From: Sumanth Korikkar @ 2026-10-06 11:13 UTC (permalink / raw)
To: Heiko Carstens, Vasily Gorbik, Alexander Gordeev,
Ilya Leoshkevich, Christian Borntraeger, Jan Polensky, linux-s390
Cc: sumanthk
cfset_offline_cpu() stops counter sets for every active session without
checking whether the outgoing cpu belongs to the session mask.
For example, run an hwctr session on cpu0 and a cpu bound perf event on
cpu1:
lshwc -l 9999 -i 5 0:b
perf stat -C 1 -e cpum_cf/CPU_CYCLES/ sleep 120
chcpu -d 1
chcpu -e 1
Although the hwctr session does not include cpu1, cfset_offline_cpu()
decrements its counter set reference count. The subsequent perf teardown
decrements it again, causing it to underflow.
The perf event keeps the percpu state alive across hotplug. When cpu1
comes online, the hwctr session is started there and the reference count
moves from -1 to 0. Stopping the hwctr session then decrements it to -1
again, so the zero triggered counter set disable path is skipped.
Check the session mask before stopping counter sets on the outgoing cpu.
This prevents the unmatched decrement and the resulting reference count
underflow.
Fixes: a029a4eab39e ("s390/cpumf: Allow concurrent access for CPU Measurement Counter Facility")
Reported-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Cc: stable@vger.kernel.org # v5.14+
Signed-off-by: Sumanth Korikkar <sumanthk@linux.ibm.com>
---
arch/s390/kernel/perf_cpum_cf.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/arch/s390/kernel/perf_cpum_cf.c b/arch/s390/kernel/perf_cpum_cf.c
index 69fa303cd479..1d63dc3b0ab9 100644
--- a/arch/s390/kernel/perf_cpum_cf.c
+++ b/arch/s390/kernel/perf_cpum_cf.c
@@ -1797,6 +1797,9 @@ static int cfset_offline_cpu(unsigned int cpu)
if (!list_empty(&cfset_session.head)) {
list_for_each_entry(rp, &cfset_session.head, node) {
+ if (!cpumask_test_cpu(cpu, &rp->mask))
+ continue;
+
p.sets = rp->ctrset;
cfset_ioctl_off(&p);
cpumask_clear_cpu(cpu, &rp->mask);
--
2.53.0
^ permalink raw reply related [flat|nested] 7+ messages in thread* Re: [PATCH 1/2] s390/cpum_cf: Check session mask before cpu offline
2026-10-06 11:13 ` [PATCH 1/2] s390/cpum_cf: Check session mask before cpu offline Sumanth Korikkar
@ 2026-10-06 11:24 ` sashiko-bot
0 siblings, 0 replies; 7+ messages in thread
From: sashiko-bot @ 2026-10-06 11:24 UTC (permalink / raw)
To: Sumanth Korikkar
Cc: Heiko Carstens, linux-s390, Vasily Gorbik, Alexander Gordeev,
Christian Borntraeger
> cfset_offline_cpu() stops counter sets for every active session without
> checking whether the outgoing cpu belongs to the session mask.
>
> For example, run an hwctr session on cpu0 and a cpu bound perf event on
> cpu1:
>
> lshwc -l 9999 -i 5 0:b
> perf stat -C 1 -e cpum_cf/CPU_CYCLES/ sleep 120
> chcpu -d 1
> chcpu -e 1
>
> Although the hwctr session does not include cpu1, cfset_offline_cpu()
> decrements its counter set reference count. The subsequent perf teardown
> decrements it again, causing it to underflow.
>
> The perf event keeps the percpu state alive across hotplug. When cpu1
> comes online, the hwctr session is started there and the reference count
> moves from -1 to 0. Stopping the hwctr session then decrements it to -1
> again, so the zero triggered counter set disable path is skipped.
>
> Check the session mask before stopping counter sets on the outgoing cpu.
> This prevents the unmatched decrement and the resulting reference count
> underflow.
>
> Fixes: a029a4eab39e ("s390/cpumf: Allow concurrent access for CPU Measurement Counter Facility")
> Reported-by: Christian Borntraeger <borntraeger@linux.ibm.com>
> Cc: stable@vger.kernel.org # v5.14+
> Signed-off-by: Sumanth Korikkar <sumanthk@linux.ibm.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261006111304.4023017-1-sumanthk@linux.ibm.com?part=1
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH 2/2] s390/cpum_cf: Honor hwctr session cpu mask during hotplug
2026-10-06 11:13 [PATCH 0/2] s390/cpum_cf: Check session cpu mask during hotplug Sumanth Korikkar
2026-10-06 11:13 ` [PATCH 1/2] s390/cpum_cf: Check session mask before cpu offline Sumanth Korikkar
@ 2026-10-06 11:13 ` Sumanth Korikkar
2026-10-06 11:24 ` sashiko-bot
2026-10-06 14:04 ` [PATCH 0/2] s390/cpum_cf: Check " Heiko Carstens
2 siblings, 1 reply; 7+ messages in thread
From: Sumanth Korikkar @ 2026-10-06 11:13 UTC (permalink / raw)
To: Heiko Carstens, Vasily Gorbik, Alexander Gordeev,
Ilya Leoshkevich, Christian Borntraeger, Jan Polensky, linux-s390
Cc: sumanthk
cfset_online_cpu() and cfset_offline_cpu() cpu hotplug callbacks start
and stop counter sets for every active hwctr session without checking
the session cpu mask, and dynamically modify that mask on each hotplug
event.
For example, assume cpu0 and cpu1 are online and cpu2 is offline. Start
an hwctr session restricted to cpu0 and cpu1, and then bring cpu2 online:
lshwc -l 9999 -i 5 0-1:b
chcpu -e 2
Although cpu2 is not part of the requested mask, cfset_online_cpu()
starts the counter sets on cpu2 and adds it to the session mask. cpu2
can then appear in lshwc output (s390-tools) and is handled as part of
the session until it is stopped.
Keep the userspace provided cpu mask unchanged and update counter sets
only when the hotplugged cpu belongs to that mask. For all cpu requests,
lshwc should supply the possible cpu mask so that cpus coming online later
remain part of the session.
Note:
A corresponding lshwc (s390-tools) change is needed to supply the
possible cpu mask for allcpu sessions, ensuring that cpus coming online
later remain part of the session. Without it, newly online cpus would be
silently excluded from an active session.
Since this userspace change is not yet available, the patch is not
suitable for stable kernels and intentionally omits a Fixes: tag. The
prerequisite bug fix is in "s390/cpum_cf: Check session mask before cpu
offline".
Reported-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Sumanth Korikkar <sumanthk@linux.ibm.com>
---
arch/s390/kernel/perf_cpum_cf.c | 16 +++++++++-------
1 file changed, 9 insertions(+), 7 deletions(-)
diff --git a/arch/s390/kernel/perf_cpum_cf.c b/arch/s390/kernel/perf_cpum_cf.c
index 1d63dc3b0ab9..a2334af51544 100644
--- a/arch/s390/kernel/perf_cpum_cf.c
+++ b/arch/s390/kernel/perf_cpum_cf.c
@@ -1768,8 +1768,9 @@ static struct miscdevice cfset_dev = {
.mode = 0666,
};
-/* Hotplug add of a CPU. Scan through all active processes and add
- * that CPU to the list of CPUs supplied with ioctl(..., START, ...).
+/*
+ * Start counter sets on a newly online CPU for each active hwctr session that
+ * includes this CPU in its requested mask.
*/
static int cfset_online_cpu(unsigned int cpu)
{
@@ -1778,17 +1779,19 @@ static int cfset_online_cpu(unsigned int cpu)
if (!list_empty(&cfset_session.head)) {
list_for_each_entry(rp, &cfset_session.head, node) {
+ if (!cpumask_test_cpu(cpu, &rp->mask))
+ continue;
+
p.sets = rp->ctrset;
cfset_ioctl_on(&p);
- cpumask_set_cpu(cpu, &rp->mask);
}
}
return 0;
}
-/* Hotplug remove of a CPU. Scan through all active processes and clear
- * that CPU from the list of CPUs supplied with ioctl(..., START, ...).
- * Adjust reference counts.
+/*
+ * Stop counter sets on an outgoing CPU for each active hwctr session that
+ * includes this CPU in its requested mask.
*/
static int cfset_offline_cpu(unsigned int cpu)
{
@@ -1802,7 +1805,6 @@ static int cfset_offline_cpu(unsigned int cpu)
p.sets = rp->ctrset;
cfset_ioctl_off(&p);
- cpumask_clear_cpu(cpu, &rp->mask);
}
}
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 7+ messages in thread* Re: [PATCH 2/2] s390/cpum_cf: Honor hwctr session cpu mask during hotplug
2026-10-06 11:13 ` [PATCH 2/2] s390/cpum_cf: Honor hwctr session cpu mask during hotplug Sumanth Korikkar
@ 2026-10-06 11:24 ` sashiko-bot
2026-10-06 11:53 ` Sumanth Korikkar
0 siblings, 1 reply; 7+ messages in thread
From: sashiko-bot @ 2026-10-06 11:24 UTC (permalink / raw)
To: Sumanth Korikkar
Cc: linux-s390, Alexander Gordeev, Heiko Carstens, Vasily Gorbik,
Christian Borntraeger
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] s390/cpum_cf: strict mask enforcement breaks legacy lshwc tools
--
commit d3def3a5308e1d518c4fe69c3d9a0fc29e832d28
Author: Sumanth Korikkar <sumanthk@linux.ibm.com>
s390/cpum_cf: Honor hwctr session cpu mask during hotplug
This commit updates cfset_online_cpu() and cfset_offline_cpu() to start and
stop counter sets only for active hwctr sessions that include the CPU in
their requested mask. It prevents the kernel from dynamically modifying
the session mask on each hotplug event.
> diff --git a/arch/s390/kernel/perf_cpum_cf.c b/arch/s390/kernel/perf_cpum_cf.c
> index 1d63dc3b0ab99..a2334af515447 100644
> --- a/arch/s390/kernel/perf_cpum_cf.c
> +++ b/arch/s390/kernel/perf_cpum_cf.c
> @@ -1778,17 +1779,19 @@ static int cfset_online_cpu(unsigned int cpu)
>
> if (!list_empty(&cfset_session.head)) {
> list_for_each_entry(rp, &cfset_session.head, node) {
> + if (!cpumask_test_cpu(cpu, &rp->mask))
> + continue;
> +
[Severity: Critical]
Could this strict mask enforcement cause a userspace regression with legacy
lshwc tools?
Legacy versions of lshwc initiate 'allcpu' sessions by providing the currently
online CPU mask instead of the possible CPU mask.
When a new CPU is hotplugged, this strict evaluation will silently exclude the
new CPU, preventing the legacy behavior of dynamically expanding the session
mask to newly onlined CPUs.
Since this change alters the semantic behavior of hwctr sessions, will systems
using legacy s390-tools on an updated kernel encounter incomplete data for newly
hotplugged CPUs?
Breaking existing userspace applications, even when fixing a bug such as the
incorrect inclusion of CPUs in subset masks, is generally considered an ABI
regression.
> p.sets = rp->ctrset;
> cfset_ioctl_on(&p);
> - cpumask_set_cpu(cpu, &rp->mask);
> }
> }
> return 0;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261006111304.4023017-1-sumanthk@linux.ibm.com?part=2
^ permalink raw reply [flat|nested] 7+ messages in thread* Re: [PATCH 2/2] s390/cpum_cf: Honor hwctr session cpu mask during hotplug
2026-10-06 11:24 ` sashiko-bot
@ 2026-10-06 11:53 ` Sumanth Korikkar
0 siblings, 0 replies; 7+ messages in thread
From: Sumanth Korikkar @ 2026-10-06 11:53 UTC (permalink / raw)
To: sashiko-reviews
Cc: linux-s390, Alexander Gordeev, Heiko Carstens, Vasily Gorbik,
Christian Borntraeger
On Tue, Oct 06, 2026 at 11:24:17AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [Critical] s390/cpum_cf: strict mask enforcement breaks legacy lshwc tools
> --
>
> commit d3def3a5308e1d518c4fe69c3d9a0fc29e832d28
> Author: Sumanth Korikkar <sumanthk@linux.ibm.com>
>
> s390/cpum_cf: Honor hwctr session cpu mask during hotplug
>
> This commit updates cfset_online_cpu() and cfset_offline_cpu() to start and
> stop counter sets only for active hwctr sessions that include the CPU in
> their requested mask. It prevents the kernel from dynamically modifying
> the session mask on each hotplug event.
>
> > diff --git a/arch/s390/kernel/perf_cpum_cf.c b/arch/s390/kernel/perf_cpum_cf.c
> > index 1d63dc3b0ab99..a2334af515447 100644
> > --- a/arch/s390/kernel/perf_cpum_cf.c
> > +++ b/arch/s390/kernel/perf_cpum_cf.c
> > @@ -1778,17 +1779,19 @@ static int cfset_online_cpu(unsigned int cpu)
> >
> > if (!list_empty(&cfset_session.head)) {
> > list_for_each_entry(rp, &cfset_session.head, node) {
> > + if (!cpumask_test_cpu(cpu, &rp->mask))
> > + continue;
> > +
>
> [Severity: Critical]
> Could this strict mask enforcement cause a userspace regression with legacy
> lshwc tools?
>
> Legacy versions of lshwc initiate 'allcpu' sessions by providing the currently
> online CPU mask instead of the possible CPU mask.
>
> When a new CPU is hotplugged, this strict evaluation will silently exclude the
> new CPU, preventing the legacy behavior of dynamically expanding the session
> mask to newly onlined CPUs.
>
> Since this change alters the semantic behavior of hwctr sessions, will systems
> using legacy s390-tools on an updated kernel encounter incomplete data for newly
> hotplugged CPUs?
>
> Breaking existing userspace applications, even when fixing a bug such as the
> incorrect inclusion of CPUs in subset masks, is generally considered an ABI
> regression.
>
> > p.sets = rp->ctrset;
> > cfset_ioctl_on(&p);
> > - cpumask_set_cpu(cpu, &rp->mask);
> > }
> > }
> > return 0;
> > }
>
> --
> Sashiko AI review · https://sashiko.dev/#/patchset/20261006111304.4023017-1-sumanthk@linux.ibm.com?part=2
Without this patch, newly online cpus are added to the hwctr session
unconditionally, ignoring the cpu mask provided by lshwc userspace.
With the patch, the kernel honors the cpu mask provided by userspace.
For the allcpu case, the corresponding lshwc change to use "all possible
cpus" is also needed.
This is already mentioned in the note. Patch "s390/cpum_cf: Honor hwctr
session cpu mask during hotplug" should not be backported to stable
until the corresponding lshwc change is available.
Thanks
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH 0/2] s390/cpum_cf: Check session cpu mask during hotplug
2026-10-06 11:13 [PATCH 0/2] s390/cpum_cf: Check session cpu mask during hotplug Sumanth Korikkar
2026-10-06 11:13 ` [PATCH 1/2] s390/cpum_cf: Check session mask before cpu offline Sumanth Korikkar
2026-10-06 11:13 ` [PATCH 2/2] s390/cpum_cf: Honor hwctr session cpu mask during hotplug Sumanth Korikkar
@ 2026-10-06 14:04 ` Heiko Carstens
2 siblings, 0 replies; 7+ messages in thread
From: Heiko Carstens @ 2026-10-06 14:04 UTC (permalink / raw)
To: Sumanth Korikkar
Cc: Vasily Gorbik, Alexander Gordeev, Ilya Leoshkevich,
Christian Borntraeger, Jan Polensky, linux-s390
On Tue, Oct 06, 2026 at 01:13:02PM +0200, Sumanth Korikkar wrote:
> The cpu hotplug callbacks start and stop counter sets for every active
> hwctr session without checking the session cpu mask. This causes a
> reference count underflow when an unrelated cpu goes offline, and
> silently adds cpus to a session when they come online.
>
> Patch 1 fixes the reference count underflow in cfset_offline_cpu() and
> is suitable for stable kernels. It does not change the online behavior,
> so no matching lshwc change is required.
>
> Patch 2 extends the mask check to cfset_online_cpu() and keeps the
> userspace provided cpu mask unchanged across hotplug events. It requires
> a matching lshwc change and is therefore kept separate from patch 1.
>
> Sumanth Korikkar (2):
> s390/cpum_cf: Check session mask before cpu offline
> s390/cpum_cf: Honor hwctr session cpu mask during hotplug
>
> arch/s390/kernel/perf_cpum_cf.c | 19 ++++++++++++-------
> 1 file changed, 12 insertions(+), 7 deletions(-)
Series applied. Thanks!
^ permalink raw reply [flat|nested] 7+ messages in thread