From: Ian Rogers <irogers@google.com>
To: irogers@google.com, acme@kernel.org, namhyung@kernel.org
Cc: adrian.hunter@intel.com, james.clark@linaro.org,
jolsa@kernel.org, linux-kernel@vger.kernel.org,
linux-perf-users@vger.kernel.org, mingo@redhat.com,
peterz@infradead.org
Subject: [PATCH v2 9/9] perf pmu: Fix race with concurrent tracepoint creation and removal in perf list
Date: Mon, 28 Sep 2026 23:29:37 -0700 [thread overview]
Message-ID: <20260929062937.374137-10-irogers@google.com> (raw)
In-Reply-To: <20260929062937.374137-1-irogers@google.com>
perf_pmus__print_pmu_events() first counts events via
perf_pmu__num_events() to allocate the aliases array, then populates it
via perf_pmu__for_each_event(). When dynamic tracepoints (such as
kprobes or uprobes during 'perf test' runs) are concurrently created or
removed between the two passes:
- If an event is removed, state.index is smaller than the allocated len,
leaving trailing zeroed entries in aliases[] with name == NULL and
pmu == NULL, which causes qsort(cmp_sevent) or the print loop to crash
with SIGSEGV.
- If a dynamic tracepoint subsystem directory is removed while scanning
/sys/kernel/tracing/events, tp_pmu__for_each_tp_event() returns
-ENOENT and aborts enumeration of all remaining tracepoint subsystems.
- If an event is added, perf_pmus__print_pmu_events__callback() aborts
enumeration when state->index reaches state->aliases_len.
Grow state->aliases dynamically via realloc() when needed, use
state.index as the actual populated length for sorting and printing, and
ignore -ENOENT when a tracepoint subsystem directory disappears during
enumeration.
Fixes: c3245d2093c1 ("perf pmu: Abstract alias/event struct")
Fixes: 45b6e281cb06 ("perf tp_pmu: Add event APIs")
Assisted-by: Antigravity:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@google.com>
---
tools/perf/util/pmus.c | 21 +++++++++++++++++----
tools/perf/util/tp_pmu.c | 8 ++++++--
2 files changed, 23 insertions(+), 6 deletions(-)
diff --git a/tools/perf/util/pmus.c b/tools/perf/util/pmus.c
index e0a4cb2428ca..1355b317f3ed 100644
--- a/tools/perf/util/pmus.c
+++ b/tools/perf/util/pmus.c
@@ -8,6 +8,7 @@
#include <sys/types.h>
#include <ctype.h>
#include <pthread.h>
+#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include "cpumap.h"
@@ -571,7 +572,7 @@ static int cmp_sevent(const void *a, const void *b)
}
/* Order by event name. */
- return strcmp(as->name, bs->name);
+ return strcmp(as->name ?: "", bs->name ?: "");
}
static bool pmu_alias_is_duplicate(struct sevent *a, struct sevent *b)
@@ -581,7 +582,7 @@ static bool pmu_alias_is_duplicate(struct sevent *a, struct sevent *b)
return false;
/* Don't remove duplicates for different PMUs */
- return strcmp(a->pmu_name, b->pmu_name) == 0;
+ return strcmp(a->pmu_name ?: "", b->pmu_name ?: "") == 0;
}
struct events_callback_state {
@@ -597,8 +598,18 @@ static int perf_pmus__print_pmu_events__callback(void *vstate,
struct sevent *s;
if (state->index >= state->aliases_len) {
- pr_err("Unexpected event %s/%s/\n", info->pmu->name, info->name);
- return 1;
+ size_t new_len = max_t(size_t, 16, state->aliases_len * 2);
+ struct sevent *new_aliases;
+
+ new_aliases = realloc(state->aliases, new_len * sizeof(struct sevent));
+ if (!new_aliases) {
+ pr_err("Unexpected event %s/%s/\n", info->pmu->name, info->name);
+ return 1;
+ }
+ memset(&new_aliases[state->aliases_len], 0,
+ (new_len - state->aliases_len) * sizeof(struct sevent));
+ state->aliases = new_aliases;
+ state->aliases_len = new_len;
}
assert(info->pmu != NULL || info->name != NULL);
s = &state->aliases[state->index];
@@ -654,6 +665,8 @@ void perf_pmus__print_pmu_events(const struct print_callbacks *print_cb, void *p
perf_pmu__for_each_event(pmu, skip_duplicate_pmus, &state,
perf_pmus__print_pmu_events__callback);
}
+ aliases = state.aliases;
+ len = state.index;
qsort(aliases, len, sizeof(struct sevent), cmp_sevent);
for (int j = 0; j < len; j++) {
/* Skip duplicates */
diff --git a/tools/perf/util/tp_pmu.c b/tools/perf/util/tp_pmu.c
index c2be8c9f9084..5ac732e06841 100644
--- a/tools/perf/util/tp_pmu.c
+++ b/tools/perf/util/tp_pmu.c
@@ -151,7 +151,9 @@ static int for_each_event_cb(void *state, const char *sys_name, const char *evt_
static int for_each_event_sys_cb(void *state, const char *sys_name)
{
- return tp_pmu__for_each_tp_event(sys_name, state, for_each_event_cb);
+ int ret = tp_pmu__for_each_tp_event(sys_name, state, for_each_event_cb);
+
+ return ret == -ENOENT ? 0 : ret;
}
int tp_pmu__for_each_event(struct perf_pmu *pmu, void *state, pmu_event_callback cb)
@@ -176,7 +178,9 @@ static int num_events_cb(void *state, const char *sys_name __maybe_unused,
static int num_events_sys_cb(void *state, const char *sys_name)
{
- return tp_pmu__for_each_tp_event(sys_name, state, num_events_cb);
+ int ret = tp_pmu__for_each_tp_event(sys_name, state, num_events_cb);
+
+ return ret == -ENOENT ? 0 : ret;
}
size_t tp_pmu__num_events(struct perf_pmu *pmu __maybe_unused)
--
2.56.0.rc1.315.gc6ed9934b7-goog
next prev parent reply other threads:[~2026-09-29 6:30 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 2:19 [PATCH v1 0/9] perf python: Follow-up fixes and shell test deflaking Ian Rogers
2026-09-29 2:19 ` [PATCH v1 1/9] perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events Ian Rogers
2026-09-29 2:19 ` [PATCH v1 2/9] perf python sctop: Fix offline interval printing and test flakiness Ian Rogers
2026-09-29 2:19 ` [PATCH v1 3/9] perf python stat-cpi: Fix live mode signal races " Ian Rogers
2026-09-29 2:19 ` [PATCH v1 4/9] perf test: Deflake Intel PT Python shell tests under load Ian Rogers
2026-09-29 2:19 ` [PATCH v1 5/9] perf test: Deflake failed-syscalls " Ian Rogers
2026-09-29 2:19 ` [PATCH v1 6/9] perf test: Reduce overhead and contention in Python shell tests Ian Rogers
2026-09-29 2:19 ` [PATCH v1 7/9] perf python event_analyzing_sample: Default to in-memory SQLite database Ian Rogers
2026-09-29 2:19 ` [PATCH v1 8/9] perf python: Initialize debug output on module load Ian Rogers
2026-09-29 2:19 ` [PATCH v1 9/9] perf pmu: Fix race with concurrent tracepoint creation and removal in perf list Ian Rogers
2026-09-29 6:29 ` [PATCH v2 0/9] perf python: Follow-up fixes and shell test deflaking Ian Rogers
2026-09-29 6:29 ` [PATCH v2 1/9] perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events Ian Rogers
2026-09-29 6:29 ` [PATCH v2 2/9] perf python sctop: Fix offline interval printing and test flakiness Ian Rogers
2026-09-29 6:29 ` [PATCH v2 3/9] perf python stat-cpi: Fix live mode signal races " Ian Rogers
2026-09-29 6:29 ` [PATCH v2 4/9] perf test: Deflake Intel PT Python shell tests under load Ian Rogers
2026-09-29 6:29 ` [PATCH v2 5/9] perf test: Deflake failed-syscalls " Ian Rogers
2026-09-29 6:29 ` [PATCH v2 6/9] perf test: Reduce overhead and contention in Python shell tests Ian Rogers
2026-09-29 6:29 ` [PATCH v2 7/9] perf python event_analyzing_sample: Default to in-memory SQLite database Ian Rogers
2026-09-29 6:29 ` [PATCH v2 8/9] perf python: Initialize debug output on module load Ian Rogers
2026-09-29 6:29 ` Ian Rogers [this message]
2026-09-29 6:58 ` [PATCH v3 0/9] perf python: Follow-up fixes and shell test deflaking Ian Rogers
2026-09-29 6:58 ` [PATCH v3 1/9] perf evsel: Clamp sample_id size for ksymbol, bpf, and text_poke events Ian Rogers
2026-09-29 6:58 ` [PATCH v3 2/9] perf python sctop: Fix offline interval printing and test flakiness Ian Rogers
2026-09-29 6:58 ` [PATCH v3 3/9] perf python stat-cpi: Fix live mode signal races " Ian Rogers
2026-09-29 6:58 ` [PATCH v3 4/9] perf test: Deflake Intel PT Python shell tests under load Ian Rogers
2026-09-29 6:58 ` [PATCH v3 5/9] perf test: Deflake failed-syscalls " Ian Rogers
2026-09-29 6:58 ` [PATCH v3 6/9] perf test: Reduce overhead and contention in Python shell tests Ian Rogers
2026-09-29 6:58 ` [PATCH v3 7/9] perf python event_analyzing_sample: Default to in-memory SQLite database Ian Rogers
2026-09-29 6:58 ` [PATCH v3 8/9] perf python: Initialize debug output on module load Ian Rogers
2026-09-29 6:58 ` [PATCH v3 9/9] perf pmu: Fix race with concurrent tracepoint creation and removal in perf list Ian Rogers
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929062937.374137-10-irogers@google.com \
--to=irogers@google.com \
--cc=acme@kernel.org \
--cc=adrian.hunter@intel.com \
--cc=james.clark@linaro.org \
--cc=jolsa@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=namhyung@kernel.org \
--cc=peterz@infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®