Skip to content

Commit c1925c8

Browse files
Luo Gengkunopsiff
authored andcommitted
perf/core: Fix WARN in perf_cgroup_switch()
[ Upstream commit 3172fb9 ] There may be concurrency between perf_cgroup_switch and perf_cgroup_event_disable. Consider the following scenario: after a new perf cgroup event is created on CPU0, the new event may not trigger a reprogramming, causing ctx->is_active to be 0. In this case, when CPU1 disables this perf event, it executes __perf_remove_from_context-> list _del_event->perf_cgroup_event_disable on CPU1, which causes a race with perf_cgroup_switch running on CPU0. The following describes the details of this concurrency scenario: CPU0 CPU1 perf_cgroup_switch: ... # cpuctx->cgrp is not NULL here if (READ_ONCE(cpuctx->cgrp) == NULL) return; perf_remove_from_context: ... raw_spin_lock_irq(&ctx->lock); ... # ctx->is_active == 0 because reprogramm is not # tigger, so CPU1 can do __perf_remove_from_context # for CPU0 __perf_remove_from_context: perf_cgroup_event_disable: ... if (--ctx->nr_cgroups) ... # this warning will happened because CPU1 changed # ctx.nr_cgroups to 0. WARN_ON_ONCE(cpuctx->ctx.nr_cgroups == 0); [peterz: use guard instead of goto unlock] Fixes: db4a835 ("perf/core: Set cgroup in CPU contexts for new cgroup events") Signed-off-by: Luo Gengkun <luogengkun@huaweicloud.com> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Link: https://lkml.kernel.org/r/20250604033924.3914647-3-luogengkun@huaweicloud.com Signed-off-by: Sasha Levin <sashal@kernel.org> (cherry picked from commit fd199366bf3862402116b2e270d5c9e7adbc5c0a)
1 parent f63a6f9 commit c1925c8

1 file changed

Lines changed: 20 additions & 2 deletions

File tree

kernel/events/core.c

Lines changed: 20 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -206,6 +206,19 @@ static void perf_ctx_unlock(struct perf_cpu_context *cpuctx,
206206
__perf_ctx_unlock(&cpuctx->ctx);
207207
}
208208

209+
typedef struct {
210+
struct perf_cpu_context *cpuctx;
211+
struct perf_event_context *ctx;
212+
} class_perf_ctx_lock_t;
213+
214+
static inline void class_perf_ctx_lock_destructor(class_perf_ctx_lock_t *_T)
215+
{ perf_ctx_unlock(_T->cpuctx, _T->ctx); }
216+
217+
static inline class_perf_ctx_lock_t
218+
class_perf_ctx_lock_constructor(struct perf_cpu_context *cpuctx,
219+
struct perf_event_context *ctx)
220+
{ perf_ctx_lock(cpuctx, ctx); return (class_perf_ctx_lock_t){ cpuctx, ctx }; }
221+
209222
#define TASK_TOMBSTONE ((void *)-1L)
210223

211224
static bool is_kernel_event(struct perf_event *event)
@@ -898,7 +911,13 @@ static void perf_cgroup_switch(struct task_struct *task)
898911
if (READ_ONCE(cpuctx->cgrp) == cgrp)
899912
return;
900913

901-
perf_ctx_lock(cpuctx, cpuctx->task_ctx);
914+
guard(perf_ctx_lock)(cpuctx, cpuctx->task_ctx);
915+
/*
916+
* Re-check, could've raced vs perf_remove_from_context().
917+
*/
918+
if (READ_ONCE(cpuctx->cgrp) == NULL)
919+
return;
920+
902921
perf_ctx_disable(&cpuctx->ctx, true);
903922

904923
ctx_sched_out(&cpuctx->ctx, NULL, EVENT_ALL|EVENT_CGROUP);
@@ -916,7 +935,6 @@ static void perf_cgroup_switch(struct task_struct *task)
916935
ctx_sched_in(&cpuctx->ctx, NULL, EVENT_ALL|EVENT_CGROUP);
917936

918937
perf_ctx_enable(&cpuctx->ctx, true);
919-
perf_ctx_unlock(cpuctx, cpuctx->task_ctx);
920938
}
921939

922940
static int perf_cgroup_ensure_storage(struct perf_event *event,

0 commit comments

Comments
 (0)