From: Ivan Immanuel Shaji via B4 Relay <devnull+ivanimmanuel1234.gmail.com@kernel.org> Date: 2026-08-25 16:53:24
The simple ring buffer's reader-page swap retry loop mishandles its last
attempt. A success at that point is reported as an error, while a failure
is allowed to continue into the pointer updates. The remote ring buffer
consumer compounds callback failures by warning and continuing with stale
reader metadata.
Fix the retry result in the provider, then stop the remote consumer before
it mutates its local page list when the swap fails.
These paths are used by remote tracing, including arm64 nVHE EL2 tracing
and CONFIG_TRACE_REMOTE_TEST.
Testing:
make C=2 W=1 kernel/trace/simple_ring_buffer.o kernel/trace/ring_buffer.o
scripts/checkpatch.pl --no-tree (each formatted patch)
No runtime reproducer was run. The two final-attempt outcomes follow from
the retry counter's post-decrement semantics. An arm64 cross-compiler was
not available.
---
Changes in v2:
- Report callback failures with pr_warn_ratelimited() instead of
WARN_ON_ONCE(), as suggested by Vincent Donnefort.
- Add Vincent Donnefort's Reviewed-by tag to patch 1.
- Link to v1: https://lore.kernel.org/r/20260825-kernel-patch-1-v1-0-e9349aa0b165@gmail.com
---
Ivan Immanuel Shaji (2):
tracing: Fix retry exhaustion in simple ring buffer reader swap
ring-buffer: Stop remote reader update when page swap fails
kernel/trace/ring_buffer.c | 7 +++++--
kernel/trace/simple_ring_buffer.c | 4 ++--
2 files changed, 7 insertions(+), 4 deletions(-)
---
base-commit: 66498c75b4f8017f62d720d9b59675bdf3abce91
change-id: 20260825-kernel-patch-1-d806e3de01a5
Best regards,
--
Ivan Immanuel Shaji [off-list ref]
From: Ivan Immanuel Shaji via B4 Relay <devnull+ivanimmanuel1234.gmail.com@kernel.org> Date: 2026-08-25 16:53:24
From: Ivan Immanuel Shaji <redacted>
The remote swap_reader_page callback can return -EBUSY when the writer
moves the head before the remote catches it, particularly during an event
storm on a small buffer. __rb_get_reader_page_from_remote() currently
warns about that failure but continues with the unchanged reader ID and
rearranges the local page list as though the swap succeeded.
Handle the callback failure as a recoverable error. Report it with
pr_warn_ratelimited() and return NULL. Callers already handle a NULL reader
page as a failed attempt. This avoids splicing the same page as both the
previous and new reader without flooding the log under contention.
Fixes: 2e67fabd8b77 ("ring-buffer: Introduce ring-buffer remotes")
Cc: stable@vger.kernel.org
Assisted-by: LLM sparse
Signed-off-by: Ivan Immanuel Shaji <redacted>
---
kernel/trace/ring_buffer.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
From: Ivan Immanuel Shaji via B4 Relay <devnull+ivanimmanuel1234.gmail.com@kernel.org> Date: 2026-08-25 16:53:24
From: Ivan Immanuel Shaji <redacted>
simple_ring_buffer_swap_reader_page() starts with retry set to 8 and
post-decrements it only after a failed link replacement. On the final
attempt, a successful replacement leaves retry at zero, while a failed
replacement leaves it at -1.
The current !retry test reverses both outcomes. It returns an error after
a successful final replacement, leaving the link update complete but the
reader bookkeeping unfinished. After a failed final replacement, it
falls through and updates the head and reader pointers as though the
replacement succeeded, which can corrupt the ring.
Treat only a negative counter as exhaustion and return the documented
-EBUSY error.
Fixes: 34e5b958bdad ("tracing: Introduce simple_ring_buffer")
Cc: stable@vger.kernel.org
Assisted-by: LLM sparse
Reviewed-by: Vincent Donnefort <redacted>
Signed-off-by: Ivan Immanuel Shaji <redacted>
---
kernel/trace/simple_ring_buffer.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)