From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753522AbbC0LrR (ORCPT ); Fri, 27 Mar 2015 07:47:17 -0400 Received: from terminus.zytor.com ([198.137.202.10]:37324 "EHLO terminus.zytor.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752986AbbC0LrO (ORCPT ); Fri, 27 Mar 2015 07:47:14 -0400 Date: Fri, 27 Mar 2015 04:46:26 -0700 From: tip-bot for Peter Zijlstra Message-ID: Cc: tglx@linutronix.de, sasha.levin@oracle.com, linux-kernel@vger.kernel.org, peterz@infradead.org, hpa@zytor.com, jolsa@redhat.com, mingo@kernel.org, vincent.weaver@maine.edu Reply-To: vincent.weaver@maine.edu, mingo@kernel.org, hpa@zytor.com, peterz@infradead.org, jolsa@redhat.com, linux-kernel@vger.kernel.org, sasha.levin@oracle.com, tglx@linutronix.de In-Reply-To: <20150225151639.GL5029@twins.programming.kicks-ass.net> References: <20150225151639.GL5029@twins.programming.kicks-ass.net> To: linux-tip-commits@vger.kernel.org Subject: [tip:perf/core] perf: Fix racy group access Git-Commit-ID: ccd41c86ad4d464d0ed4e48d80759ff85c2115b0 X-Mailer: tip-git-log-daemon Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset=UTF-8 Content-Disposition: inline Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Commit-ID: ccd41c86ad4d464d0ed4e48d80759ff85c2115b0 Gitweb: http://git.kernel.org/tip/ccd41c86ad4d464d0ed4e48d80759ff85c2115b0 Author: Peter Zijlstra AuthorDate: Wed, 25 Feb 2015 15:56:04 +0100 Committer: Ingo Molnar CommitDate: Fri, 27 Mar 2015 09:49:45 +0100 perf: Fix racy group access While looking at some fuzzer output I noticed that we do not hold any locks on leader->ctx and therefore the sibling_list iteration is unsafe. Acquire the relevant ctx->mutex before calling into the pmu specific code. Signed-off-by: Peter Zijlstra (Intel) Cc: Vince Weaver Cc: Jiri Olsa Cc: Sasha Levin Link: http://lkml.kernel.org/r/20150225151639.GL5029@twins.programming.kicks-ass.net Signed-off-by: Ingo Molnar --- kernel/events/core.c | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/kernel/events/core.c b/kernel/events/core.c index b01dfb6..bb1a7c3 100644 --- a/kernel/events/core.c +++ b/kernel/events/core.c @@ -7036,12 +7036,23 @@ EXPORT_SYMBOL_GPL(perf_pmu_unregister); static int perf_try_init_event(struct pmu *pmu, struct perf_event *event) { + struct perf_event_context *ctx = NULL; int ret; if (!try_module_get(pmu->module)) return -ENODEV; + + if (event->group_leader != event) { + ctx = perf_event_ctx_lock(event->group_leader); + BUG_ON(!ctx); + } + event->pmu = pmu; ret = pmu->event_init(event); + + if (ctx) + perf_event_ctx_unlock(event->group_leader, ctx); + if (ret) module_put(pmu->module);