From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f170.google.com (mail-pg1-f170.google.com [209.85.215.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7DFE03EFFC9 for ; Sat, 22 Aug 2026 15:09:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.170 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787411370; cv=none; b=IJINy5IK6LOn6WZ7cdDX+iqb+UoAIkQhOtvRrwZsTewxwOgltVbEn+GgVHh+xONyraQBWm8MovsIf3fmRlUZMXSjmBcpu/t8JWLl1AdZfUgrf0AGROg4BkILgT75HrL/HhwVHOGes1vt1K0ogBnQ0HlWTh9To44HtA+L1JhENpo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787411370; c=relaxed/simple; bh=IGYS9/MJmi0crQrMqbiomdqqv5fS8S+rJ101ghPw26E=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=MyFKe1sdl1aehdIAr2xUt7jdYQxN/xPlp2pqc+6YVRNOQ4ss/FMGItt6jnTR7G7w+52vIAUPenXfmpeWtQPniCvaUFBSyS4qfxqEb+l7mSnTIse2QCkmwGljN7lotpUg84SdRaQjqusmflLfwjVX39hZeezt20QG5zYOy6NfnW8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=YM7SrUrt; arc=none smtp.client-ip=209.85.215.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="YM7SrUrt" Received: by mail-pg1-f170.google.com with SMTP id 41be03b00d2f7-c96b08cdd1cso1640934a12.0 for ; Sat, 22 Aug 2026 08:09:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787411367; x=1788016167; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=xN4hXMOwbHYw8YYoHSGskBU1Hru9hAdLN66h2VVXOns=; b=YM7SrUrtYAnhHYAaeIsAdACdKCoehgVqosn8VSUcPiYv7S5UXVIE6/f/GWmYdyLSSg olfwtyOA0EzuPMwWoMVN0TpOMYvpey2qY18eUwO/6fSPYe4Ni5bjfMZYwMRRGjoTJj7e obec/wGWWF5/P0/9Qx3eOxU/6pVaixqytZbrsKtf9VFK1DPC+ekED/+tjgU1NZbW8hhP NZR7cWUdjp2Qx46Hzqcl7rk340Nc6xoQRYOQDf7FkN1wqTOeElXbu9j+Z2KsBjB002If 11ybhfHXz3RpfqT9LnZVryktLlPdV7qsRhvlC/EDjEUhy8oKJiNB4Jxa5o6sRnshBEgP lFsw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787411367; x=1788016167; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=xN4hXMOwbHYw8YYoHSGskBU1Hru9hAdLN66h2VVXOns=; b=InIqmhEbgmyszk/vTimVa2fE+5rXeZGYYlXiS246V9uD9nuI9kFTg8W5Bwg2+jbwY+ RpI0p9oezaSH9eP/9TyT2J6L6cyL6OzXhjIZ5YS/PgxNmHJsmvkrsq4C+f0fI2j2nKhD r8bh6RnxYx0szevOezjdosrB2rfZRUOfrC5KKWxTe24HGjLAkVpgwZEeIdpT01zzQFWH AEEKKXGo2Eo/lIuA7gqPT4+6JrYuC6/kOZIVmiXOG8xyroK8D9oS063dVTstpcPYbCxr crRM2n2iebuJl+75k7Sc+EEEvFNVBrYukoiIRUbbVQ3RaweLffBr+2Q03umr89+qK81+ eKSg== X-Gm-Message-State: AFuF++m3Fg3096FgpTK1EOsyHuge04L7S3EWI7ljdvtZqVrwT22u0V+i 7xTaKefGyhBEO4uQD/kxJ1tK6niTwocbJqZFv5GiGsjL+YwfTxwPXAiT X-Gm-Gg: AR+sD13xEWx2sIWGmw7g1DMGWoWfvKMNk4zJVMpARWFLJtKILxlAT7UotiDKQDllS9f UtxLpQ1LVFMQWUQaJptzG7RmoQ06+N1Bzonid9HCP4O2hJiIteDiAoygY/kLqXy1UK3bSbvdOnh SH5hZp6Xo8aMKVoewbygTGKBGRanP6qgc/X2p7EwGIPpDEQtrRNw98yP+YbN76gx2SRAY1Eb0vd RR60aPRELNeod9hSXWWkSgcWjgIv4A5EzSm2QXBJs9f8jGFaHBAzOzNnfzdrKhxHfJFLIhRmknc eMF1Lk9rgGC/oCpGG4cA5g4gFe1Fqy0Vled8VCOlhfixAW4q+kYqK98s3LgXRTj/f96gh+LI9Xm dZdAUhIEmpcBWpCy4eoM8H2eHF1LP9d4q4cC4KsyqJRWNQOuKum7neA4Xf7cfAbjHvOOtO4CKvD fES8xb7RqEvoyQ0OKRmrmrc0MsSsRXk+GC8+YaJt/RQ4msEnHcsQNXSXdaMC0WZC3Svp7LW6Iat RzVRIz1OPvW3er8W36SvTFJ3g== X-Received: by 2002:a17:90b:2cc3:b0:392:e5b1:d833 with SMTP id 98e67ed59e1d1-395df29666cmr11845108a91.13.1787411366593; Sat, 22 Aug 2026 08:09:26 -0700 (PDT) Received: from jvle-ThinkPad-X1-Carbon-Gen-8.. ([117.172.228.137]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-1418619d6ecsm8057043c88.14.2026.08.22.08.09.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 22 Aug 2026 08:09:25 -0700 (PDT) From: Keke Ming To: Masami Hiramatsu , Oleg Nesterov , Peter Zijlstra Cc: linux-kernel@vger.kernel.org, linux-trace-kernel@vger.kernel.org, linux-perf-users@vger.kernel.org, Keke Ming Subject: [PATCH v2] uprobes: Free utask on dup_return_instance() failure Date: Sat, 22 Aug 2026 23:09:06 +0800 Message-ID: <20260822150906.528208-1-ming.jvle@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260822054620.452262-1-ming.jvle@gmail.com> References: <20260822054620.452262-1-ming.jvle@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit dup_utask() installs the new uprobe_task in t->utask before copying return_instances. If dup_return_instance() fails, the partially copied utask is left attached to the child task. Free the partially copied utask before returning -ENOMEM. Also, dup_return_instance() copies the return_instance before fixing up extra_consumers. Here, if no deep copy is needed, clear the copied extra_consumers pointer. Signed-off-by: Keke Ming --- v2 changes: - Clear ri->extra_consumers = NULL when old->cons_cnt <= 1 in dup_return_instance(), fixing a potential double free during cleanup. - Keep the dup_utask() error cleanup from v1. kernel/events/uprobes.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/kernel/events/uprobes.c b/kernel/events/uprobes.c index b25531331902..73a6620c5701 100644 --- a/kernel/events/uprobes.c +++ b/kernel/events/uprobes.c @@ -2118,6 +2118,8 @@ static struct return_instance *dup_return_instance(struct return_instance *old) kfree(ri); return NULL; } + } else { + ri->extra_consumers = NULL; } return ri; @@ -2140,8 +2142,10 @@ static int dup_utask(struct task_struct *t, struct uprobe_task *o_utask) p = &n_utask->return_instances; for (o = o_utask->return_instances; o; o = o->next) { n = dup_return_instance(o); - if (!n) + if (!n) { + uprobe_free_utask(t); return -ENOMEM; + } /* if uprobe is non-NULL, we'll have an extra refcount for uprobe */ uprobe = hprobe_expire(&o->hprobe, true); -- 2.43.0