Skip to content

Commit 7c631e5

Browse files
Luo Gengkungregkh
authored andcommitted
perf/core: Fix WARN in perf_cgroup_switch()
[ Upstream commit 3172fb9 ] There may be concurrency between perf_cgroup_switch and perf_cgroup_event_disable. Consider the following scenario: after a new perf cgroup event is created on CPU0, the new event may not trigger a reprogramming, causing ctx->is_active to be 0. In this case, when CPU1 disables this perf event, it executes __perf_remove_from_context-> list _del_event->perf_cgroup_event_disable on CPU1, which causes a race with perf_cgroup_switch running on CPU0. The following describes the details of this concurrency scenario: CPU0 CPU1 perf_cgroup_switch: ... # cpuctx->cgrp is not NULL here if (READ_ONCE(cpuctx->cgrp) == NULL) return; perf_remove_from_context: ... raw_spin_lock_irq(&ctx->lock); ... # ctx->is_active == 0 because reprogramm is not # tigger, so CPU1 can do __perf_remove_from_context # for CPU0 __perf_remove_from_context: perf_cgroup_event_disable: ... if (--ctx->nr_cgroups) ... # this warning will happened because CPU1 changed # ctx.nr_cgroups to 0. WARN_ON_ONCE(cpuctx->ctx.nr_cgroups == 0); [peterz: use guard instead of goto unlock] Fixes: db4a835 ("perf/core: Set cgroup in CPU contexts for new cgroup events") Signed-off-by: Luo Gengkun <luogengkun@huaweicloud.com> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Link: https://lkml.kernel.org/r/20250604033924.3914647-3-luogengkun@huaweicloud.com Signed-off-by: Sasha Levin <sashal@kernel.org>
1 parent bddec73 commit 7c631e5

1 file changed

Lines changed: 20 additions & 2 deletions

File tree

kernel/events/core.c

Lines changed: 20 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -171,6 +171,19 @@ static void perf_ctx_unlock(struct perf_cpu_context *cpuctx,
171171
raw_spin_unlock(&cpuctx->ctx.lock);
172172
}
173173

174+
typedef struct {
175+
struct perf_cpu_context *cpuctx;
176+
struct perf_event_context *ctx;
177+
} class_perf_ctx_lock_t;
178+
179+
static inline void class_perf_ctx_lock_destructor(class_perf_ctx_lock_t *_T)
180+
{ perf_ctx_unlock(_T->cpuctx, _T->ctx); }
181+
182+
static inline class_perf_ctx_lock_t
183+
class_perf_ctx_lock_constructor(struct perf_cpu_context *cpuctx,
184+
struct perf_event_context *ctx)
185+
{ perf_ctx_lock(cpuctx, ctx); return (class_perf_ctx_lock_t){ cpuctx, ctx }; }
186+
174187
#define TASK_TOMBSTONE ((void *)-1L)
175188

176189
static bool is_kernel_event(struct perf_event *event)
@@ -866,7 +879,13 @@ static void perf_cgroup_switch(struct task_struct *task)
866879
if (READ_ONCE(cpuctx->cgrp) == cgrp)
867880
return;
868881

869-
perf_ctx_lock(cpuctx, cpuctx->task_ctx);
882+
guard(perf_ctx_lock)(cpuctx, cpuctx->task_ctx);
883+
/*
884+
* Re-check, could've raced vs perf_remove_from_context().
885+
*/
886+
if (READ_ONCE(cpuctx->cgrp) == NULL)
887+
return;
888+
870889
perf_ctx_disable(&cpuctx->ctx, true);
871890

872891
ctx_sched_out(&cpuctx->ctx, EVENT_ALL|EVENT_CGROUP);
@@ -884,7 +903,6 @@ static void perf_cgroup_switch(struct task_struct *task)
884903
ctx_sched_in(&cpuctx->ctx, EVENT_ALL|EVENT_CGROUP);
885904

886905
perf_ctx_enable(&cpuctx->ctx, true);
887-
perf_ctx_unlock(cpuctx, cpuctx->task_ctx);
888906
}
889907

890908
static int perf_cgroup_ensure_storage(struct perf_event *event,

0 commit comments

Comments
 (0)