From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f46.google.com (mail-pj1-f46.google.com [209.85.216.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B691E44838C for ; Mon, 24 Aug 2026 14:47:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.46 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787582828; cv=none; b=FBnPPVWRtdAy/l1goKhDSt/VTspyycrm0mCVETodJ+tPV+OTjWTzVItkzck/s4IB6VtodmR8bwpjoJdMpdsAfhJPTU13ejNukrTpakP2HJufqwWJJYmDCgqHVr+qhnti6qDxRKpX0AGyDgeD8B7TDyBA8DmNr/Je3SzoCougI7Q= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787582828; c=relaxed/simple; bh=NXG7bE790VEEAyF28aLFVFci8yXbRztC6StC9DoElGM=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=JQRER1sLbt0581HDbnMueG96P6woxaiAxoQh0tWWLPS3m8SAeNGHsJucCZTjy7/5bPlA4FVWHsHis2MVQeu77h51CLM5y16b8B1mFIEFDdxcgtIY88/rxtRjc6Uqr+oLxd5vHdBILg/kS/FTzGLXVcRCWc1hws4edhTaV5DG9gc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=KawySjtM; arc=none smtp.client-ip=209.85.216.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="KawySjtM" Received: by mail-pj1-f46.google.com with SMTP id 98e67ed59e1d1-38dcbade417so4224215a91.1 for ; Mon, 24 Aug 2026 07:47:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787582825; x=1788187625; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=HbTvMJOA5pAnK3dUzCcI4B1WpzStHPSu12W55oNjXVo=; b=KawySjtMyaKjpiaTzAegy+9sFaXa9f+QcH53evqIh6Eai+w+efb+S4fJ5WTZY851vR qwSITmHO6w/HydKbTUTRKeR3G+2fdegdqJPEy9OQNJcuq2JPqqco4/clcTQ7rn4LbgDP TOdX1wN3re/qmKUJUwYFR2KmgJEdtik/Fvu3RblSbujkY/G9SJaVCBehNwnqHE4h5P9J V/PMqa5t5KahtDp4/yLsSQGicbt2SgVVqBrrtgSgrncxA0QdFwp7lre4KL9TCnOW4wzY i6WcLo7T9PipZX7GplPH+TP5s/wBdyxwmZRpxWXgNfdgPxeYEBw0A641CfSf17PbNkZW sK2g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787582825; x=1788187625; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=HbTvMJOA5pAnK3dUzCcI4B1WpzStHPSu12W55oNjXVo=; b=NfI1DYQbx1tLfP/J7uxhKySbJj3KNubudUwGvFF8WE+tCDKs9+hv/96rAgp2r/4TZ5 QKy1f01HTuJQE6kCaqxSnwa1aYo48ux+bvkhYYRT40ntBNgjCmC/zuJ8nCUffQKw66VK PidqMEe439ZFvZtvetPB/lPOlOcZT0yjhp8PzIYRUgr58b8yU4paTtFIrHJC+1nYItUM 62+Ub/4QxE/c0WWLRSkiaX5/lZUMVkcdNNpO2ReV3wrqM3Bj+qNu2nvyhQviS78nnGsf tdxfgmmVIYTD6+UfEu3iH4KI+ga90ptAr/g7+2dL8n0W1rS0w4+tBVBSmMZgpODoTq3N Ocow== X-Gm-Message-State: AFuF++kQ6CfEjWa77byBfGCTvnDa9OpErXpo8StfmUM8Lc5kGA/z5d7i C/y5fhE06j9fFVxxtRBAFmHTMOO+nLSMY03OVDIGkgJrQj4vaqGZ6Fpm6s0+BQ== X-Gm-Gg: AR+sD10wWh2xEP8GtzsQVXrQhzg5WQbSCPjpFwZtEls6nL0j/YJkUHrty6sJTOgjCCh b0vHN+z7QvtKIYi19+HOecTrn7IXLpcD0SO7G/LVWqu30TkM4UiSEMA95T06NLHcrQjwcC52k3h hjsdWTf/1MJyNPKeeKZETCFX1y5dJFixnb+RFEoyWlMVW32MaEqhfnHt4Nd2/HFajtKKJMlTV6p w4/5UGP1oWRsE5VNaiKzhFhccqsqH96wDmBW2EdEbFGNaU5pnXnce6p360Rn5Ut/mXpSaUxc6cf VrJgrJG+CDH+i8QzEYLNTUxpoNgb14O8U1KfcLbexOmIWortk0tLMaMb9SzgjZjbDpIqivsrdnu uhnd6QOHVucgiLwoO5gfYpLow27POV4Rid2ea2WJ0ERrlNJzJHKux2mMoq7Q50a2ydcRoohh4t1 kSTihee2oPIBTBz8mQXtzggGuRnim0sbpXWbHx8/speSdJ0j4dOb3iTQTUEirmAsw7Ka0kcv8R2 4j8+t612Ti5u6uB4BlMWk8= X-Received: by 2002:a17:90a:100f:b0:396:40e6:f631 with SMTP id 98e67ed59e1d1-39640e6f6d9mr1017779a91.3.1787582824587; Mon, 24 Aug 2026 07:47:04 -0700 (PDT) Received: from deepanshu.. ([2405:201:682f:383f:4cf4:9e7a:69d:2900]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-141861732f8sm25774770c88.10.2026.08.24.07.46.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 07:47:01 -0700 (PDT) From: Deepanshu Kartikey To: rostedt@goodmis.org, mhiramat@kernel.org, mathieu.desnoyers@efficios.com Cc: linux-kernel@vger.kernel.org, linux-trace-kernel@vger.kernel.org, Deepanshu Kartikey , syzbot+3ef80b4ed02226d04a06@syzkaller.appspotmail.com, stable@vger.kernel.org Subject: [PATCH] eventfs: Initialize ei->children and ei->list in init_ei() Date: Mon, 24 Aug 2026 20:16:53 +0530 Message-Id: <20260824144653.54044-1-kartikey406@gmail.com> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit eventfs_create_events_dir() allocates the eventfs_inode via alloc_root_ei(), but only calls INIT_LIST_HEAD() on ei->children and ei->list after the tracefs_get_inode() check. If that check fails, the code jumps to the fail label and calls cleanup_ei(), which calls free_ei(): WARN_ON_ONCE(!list_empty(&ei->children)); Since ei was allocated with kzalloc(), ei->children.next is NULL at this point, not a self-referencing pointer. list_empty() checks head->next == head, so it returns false on an uninitialized list head, triggering a false-positive WARN_ON_ONCE() even though the list was never used. eventfs_create_dir() has the same latent issue: alloc_ei() is called before INIT_LIST_HEAD(), leaving a window where an early failure path could hit cleanup_ei() on an uninitialized list head. Move the INIT_LIST_HEAD() calls into init_ei(), which is called by both alloc_ei() and alloc_root_ei() immediately after allocation. This guarantees every eventfs_inode has a valid, self-linked, empty children/list the moment it is allocated, regardless of which failure path runs afterward. Fixes: 5790b1fb3d67 ("eventfs: Remove eventfs_file and just use eventfs_inode") Reported-by: syzbot+3ef80b4ed02226d04a06@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3ef80b4ed02226d04a06 Cc: stable@vger.kernel.org Signed-off-by: Deepanshu Kartikey --- fs/tracefs/event_inode.c | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/fs/tracefs/event_inode.c b/fs/tracefs/event_inode.c index 604ba3e841d2..6e3513b13cfa 100644 --- a/fs/tracefs/event_inode.c +++ b/fs/tracefs/event_inode.c @@ -438,6 +438,8 @@ static inline struct eventfs_inode *init_ei(struct eventfs_inode *ei, const char if (!ei->name) return NULL; kref_init(&ei->kref); + INIT_LIST_HEAD(&ei->children); + INIT_LIST_HEAD(&ei->list); return ei; } @@ -729,8 +731,6 @@ struct eventfs_inode *eventfs_create_dir(const char *name, struct eventfs_inode ei->entries = entries; ei->nr_entries = size; ei->data = data; - INIT_LIST_HEAD(&ei->children); - INIT_LIST_HEAD(&ei->list); scoped_guard(mutex, &eventfs_mutex) { if (!parent->is_freed) @@ -802,9 +802,6 @@ struct eventfs_inode *eventfs_create_events_dir(const char *name, struct dentry ei->attr.uid = uid; ei->attr.gid = gid; - INIT_LIST_HEAD(&ei->children); - INIT_LIST_HEAD(&ei->list); - ti = get_tracefs(inode); ti->flags |= TRACEFS_EVENT_INODE; ti->private = ei; -- 2.34.1