From: Hui Su <sh_def@163.com>
To: Arnaldo Carvalho de Melo <acme@kernel.org>,
Namhyung Kim <namhyung@kernel.org>
Cc: Ian Rogers <irogers@google.com>,
Adrian Hunter <adrian.hunter@intel.com>,
James Clark <james.clark@linaro.org>,
Jiri Olsa <jolsa@kernel.org>,
linux-perf-users@vger.kernel.org, linux-kernel@vger.kernel.org,
Hui Su <sh_def@163.com>
Subject: [PATCH] perf synthetic-events: Fix schedstat event lifetime handling
Date: Sat, 12 Sep 2026 14:56:19 +0900 [thread overview]
Message-ID: <20260912055619.2284443-1-sh_def@163.com> (raw)
perf_event__synthesize_schedstat() has two event lifetime issues.
After a successful iteration, event is freed but retains its value. If
the next iteration starts with an unrecognized schedstat record type,
neither synthesizer assigns a new value. The stale pointer then passes
the NULL check, may be passed to process(), and is freed again.
In addition, when user_requested_cpus filters out a synthesized event,
the continue path skips free(event), leaking the event.
Make event local to each loop iteration so it always starts as NULL.
Also avoid the filter continue and unconditionally free each synthesized
event at the end of the iteration.
Fixes: c3030995f23b ("perf sched stats: Add record and rawdump support")
Signed-off-by: Hui Su <sh_def@163.com>
---
tools/perf/util/synthetic-events.c | 14 +++++++-------
1 file changed, 7 insertions(+), 7 deletions(-)
diff --git a/tools/perf/util/synthetic-events.c b/tools/perf/util/synthetic-events.c
index 0c150193cca8..2eac2310a01d 100644
--- a/tools/perf/util/synthetic-events.c
+++ b/tools/perf/util/synthetic-events.c
@@ -2817,7 +2817,6 @@ int perf_event__synthesize_schedstat(const struct perf_tool *tool,
struct perf_cpu_map *user_requested_cpus)
{
char *line = NULL, path[PATH_MAX];
- union perf_event *event = NULL;
size_t line_len = 0;
char bf[BUFSIZ];
__u64 timestamp;
@@ -2858,6 +2857,7 @@ int perf_event__synthesize_schedstat(const struct perf_tool *tool,
* for filtered out cpus.
*/
for (ch = io__get_char(&io); !io.eof; ch = io__get_char(&io)) {
+ union perf_event *event = NULL;
struct perf_cpu this_cpu;
if (ch == 'c') {
@@ -2872,12 +2872,12 @@ int perf_event__synthesize_schedstat(const struct perf_tool *tool,
this_cpu.cpu = cpu;
- if (user_requested_cpus && !perf_cpu_map__has(user_requested_cpus, this_cpu))
- continue;
-
- if (process(tool, event, NULL, NULL) < 0) {
- free(event);
- goto out_free_line;
+ if (!user_requested_cpus ||
+ perf_cpu_map__has(user_requested_cpus, this_cpu)) {
+ if (process(tool, event, NULL, NULL) < 0) {
+ free(event);
+ goto out_free_line;
+ }
}
free(event);
--
2.55.0
next reply other threads:[~2026-09-12 5:56 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-12 5:56 Hui Su [this message]
2026-09-15 19:41 ` Ian Rogers
2026-09-22 12:36 ` Arnaldo Carvalho de Melo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260912055619.2284443-1-sh_def@163.com \
--to=sh_def@163.com \
--cc=acme@kernel.org \
--cc=adrian.hunter@intel.com \
--cc=irogers@google.com \
--cc=james.clark@linaro.org \
--cc=jolsa@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=namhyung@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®