From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9E3B73939D2 for ; Mon, 14 Sep 2026 23:48:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.43 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789429684; cv=none; b=opKan83Y753tH5RSZLFvsmXbiKTDX1y0zD6xYU9BgB3aSjxVUmStfP9vujD/7deHgaoN6q8Y3aec+mjmvs+Jf+/PNsyO5tYvx1tMHZi4ivQeCfZRVbVsUg1/fdEniZAjMoXF3rrUvk/JRMxVgtSVIWbkrBJEsW+n7xmYJaJR1DE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789429684; c=relaxed/simple; bh=tUORdNhrHwcWgp/YbkquRctE7GdPcEM18x4s7AbvUVo=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=X3r+ZzalDBuuXCzIR0hZmhxoW/mzw29mT3ParnEg7+cHLxv23kyVo4Q3zR4mH5hbAGOS+WiMU+wDnrlUk5YaTOTGdi/e4YWNRftoYWWhdVoGsT67bTD4Umvc51qmiXCD8sZAbzQ8gmvz/c78zlMOLFDunmqrSRzia745sacsHQM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=CexfMKi9; arc=none smtp.client-ip=74.125.228.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="CexfMKi9" Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-86b90133ae8so2088211b3a.1 for ; Mon, 14 Sep 2026 16:48:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789429682; x=1790034482; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=JyCNMJxkTrShME/DIcrG5BOzzpAUEE889vj8TyhVyz0=; b=CexfMKi9RbWBmLaj9nMBqSky0LVtCcxLwEdh6f+YoPtKtZKi8mSRDD6n98CjdJEJTM 80yYCWHNPs79FYKOK1tBc4tSJQd4gvJ//Uo3dVIP37Biql6haVxeyFJUETd8Jt6NX2MC nUS1d7zde+1EKR8KcHOnRrswIHRHafVi+OlQ4q5YXSAvGHhLmdhX/gAekJG602X2nH/D soyLFnDCQPU6IgYhiJDoTYOq84SBHpuAzRLePlqis4sfoPWaDKrzyjMHSFSfWcgqYa8H o75q3e9FwpSwaA7bwVPuRU52cuDazADDriL9xcpirVXtMAwpYhCKdlylpq1UYoIHyGOg uMnw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789429682; x=1790034482; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=JyCNMJxkTrShME/DIcrG5BOzzpAUEE889vj8TyhVyz0=; b=YbIyOzOKAjVoCYFVLWNvfGrSV8P75swRqa9bGsgWdAsWNsN1oGVqKexK3qyk3YqcOq JYRwz3ctUayt3xRgvZ2qSXF4rleYcb5m2LppxTv9tR75mYn3wKZlLioQcCvvUcgV/1ed wmnyt+vUF1ZVm4uWqQQC9yx/Fy2hjMp7SIVN8EyA34yeHHq1ojTXAhwRH12VYXE7NL5g wthZ+gHJO57522YZSs2yhNb4jJl12CorDWcug6mjKhHovkbBgAfc3kmZM5q74eHnw6Pe 9HsqWf2nboITc06dsEdXD0L0xdlEgjURIaiJesXLYLs9YpXOKB2ibjSvemTu04LuNiGc L+yw== X-Forwarded-Encrypted: i=1; AKwUvBxRadhejC25Ws0xXKSZ2qtrV3Kt7za5ymV70CyuC+SXpgSEbbD7D8YresFFe4jaTf+lmu9S0/rWbPHBPtw=@vger.kernel.org X-Gm-Message-State: AFuF++nIo2y2zZ/hRHFMOVlcHWlu6ZfUUxcT+NH/Zt9XRY3WM+UPll1Q OJpS8/V+nwUDe8jsvm8MEK2TJjG4IQ8mb7thhz8EBImb/UFnYYne5d8= X-Gm-Gg: AYBFou1AbYks+U6ubUJfdypReK6Rzoy22BPt7/KS3N3p95BP382s0br13+9QEHbxJSW uucYbQUYLTxmxUQ/Bu10e3Zn8lWN6yFmObM+xShpfAXrNP1LHnjK7UCSjBveaqyHFyfME/nCaos CsIgQJ8HLPbRG2GI6/rTvkI4fnue9JusVRLs7fUfLBe7QrRSN+t/ThUOSxdf8QdfQp7suM1AXIS Cy6f3klw4GJNH4LYM604y5GndZ/Xm3Om7MORU2P/Pc+We8QZ/gvi8rFCT9Wvx0qKe5+gZ7r9xGF ZT10mk5TA+Q9mzX/cjYQjcamOM9B2+ezrbmkvh4fO3mrup73sRDQnGBDHU9oE+f7TSLe4/u9ge5 oc1Q7g2IZYC6uTX0EfcGK2h96m7dyur5P59oU9Adth8Vd5hpdHWdeqZzLsNPimusJ1FyDriJyWx f9+K0TgquFEUGFFGCPQ2qvMSST5XMh84g/Jk+78v3xAZ/1HoQKZ/B2/NqeJt0/T0g0U6FQqR/sx DA7D9EVesV7tHZKKvheHWBfpOj38g+eV7Rvbw== X-Received: by 2002:a05:6a20:4323:b0:3d2:df:1854 with SMTP id adf61e73a8af0-3db4044754dmr8579967637.6.1789429681864; Mon, 14 Sep 2026 16:48:01 -0700 (PDT) Received: from ydg-Zenbook-14-UM3406GA ([2001:2d8:7f00:8c85:556:537c:f7cd:8a1b]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba4f5833fsm34777608eec.23.2026.09.14.16.47.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 14 Sep 2026 16:48:01 -0700 (PDT) From: Donggeun Yoo To: Steven Rostedt , Masami Hiramatsu Cc: Mathieu Desnoyers , Tom Zanussi , Sashiko , linux-trace-kernel@vger.kernel.org, linux-kernel@vger.kernel.org, Donggeun Yoo , stable@vger.kernel.org Subject: [PATCH] tracing: Save the event file instead of the compatible histogram Date: Tue, 15 Sep 2026 08:47:54 +0900 Message-ID: <20260914234754.3676905-1-donggeunyoo.kernel@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit create_field_var_hist() creates a histogram on the matched event to supply a field variable, and records it on the target so it can be torn down later: hist_data = find_compatible_hist(target_hist_data, file); ... /* Save the compatible histogram information */ var_hist->hist_data = hist_data; hist_data is not the histogram it creates. It is one that was already there, whose keys the new one copies. The saved pointer has a single user, unregister_field_var_hists(), which runs when the target is removed: file = hist_data->field_var_hists[i]->hist_data->event_file; find_compatible_hist() matches on keys alone, so it can pick one with no variables of its own. check_var_refs() then returns false and the user can remove it while the target still points at it: BUG: KASAN: slab-use-after-free in event_hist_trigger_free+0x2b2/0x320 Read of size 8 at addr ffff8880093b90e0 by task init/1 Freed by task 1: kfree+0x154/0x420 event_hist_trigger_free+0x1d5/0x320 event_hist_trigger_parse+0x35f3/0x69e0 trigger_process_regex+0x1a6/0x250 Save the event file instead. It is all the dereference ever wanted, and it does not go away when the user removes a trigger. Reported-by: Sashiko Link: https://lore.kernel.org/all/20260914110753.221E61F000FF@smtp.kernel.org/ Cc: stable@vger.kernel.org Fixes: 02205a6752f2 ("tracing: Add support for 'field variables'") Signed-off-by: Donggeun Yoo Assisted-by: Claude:claude-fable-5 --- x86_64 under QEMU/KVM, CONFIG_KASAN=y, 2 CPUs, base 587858367581. One kernel config; one initramfs image per arm, differing only where stated. A compatible histogram on sched_waking, an onmatch() target on sched_switch naming sched_waking's prio so a field variable is forced, then the compatible histogram removed, then the target: echo 'hist:keys=pid' > events/sched/sched_waking/trigger echo 'hist:keys=next_pid:onmatch(sched.sched_waking).my_synth(prio)' \ > events/sched/sched_switch/trigger echo '!hist:keys=pid' > events/sched/sched_waking/trigger echo '!hist:keys=next_pid:onmatch(...)' > events/sched/sched_switch/trigger unfixed 1 KASAN slab-use-after-free, above unfixed, 3rd command omitted 0 patched 0 The second arm is the control: the other three commands are identical, so the report is the removal and not the harness. The read is on freed memory rather than a pointer that is reliably wrong -- whether the '!hist' still reaches the right file depends on what the slab has handed out since. trigger-field-variable-support.tc covers this path, and its removal step goes through the line this patch changes. Run by hand against both arms, since the initramfs carries no ftracetest: inter-event histogram PASS, field variable created PASS, field variable removed PASS, on both, with no KASAN report on either. kernel/trace/trace_events_hist.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/kernel/trace/trace_events_hist.c b/kernel/trace/trace_events_hist.c index 8af97fd4ee2d..cc22bba011b2 100644 --- a/kernel/trace/trace_events_hist.c +++ b/kernel/trace/trace_events_hist.c @@ -549,7 +549,7 @@ struct field_var { }; struct field_var_hist { - struct hist_trigger_data *hist_data; + struct trace_event_file *file; char *cmd; }; @@ -3118,8 +3118,8 @@ create_field_var_hist(struct hist_trigger_data *target_hist_data, return ERR_PTR(-ENOMEM); } - /* Save the compatible histogram information */ - var_hist->hist_data = hist_data; + /* Needed to remove the histogram when the target goes away */ + var_hist->file = file; /* Create the new histogram with our variable */ ret = event_hist_trigger_parse(&trigger_hist_cmd, file, @@ -6344,7 +6344,7 @@ static void unregister_field_var_hists(struct hist_trigger_data *hist_data) int ret; for (i = 0; i < hist_data->n_field_var_hists; i++) { - file = hist_data->field_var_hists[i]->hist_data->event_file; + file = hist_data->field_var_hists[i]->file; cmd = hist_data->field_var_hists[i]->cmd; ret = event_hist_trigger_parse(&trigger_hist_cmd, file, "!hist", "hist", cmd); base-commit: 587858367581b9c55c3690f4e63382ad622719d4 -- 2.53.0