Thread (4 messages) 4 messages, 2 authors, 14d ago

Re: [PATCH v2] ring-buffer: Take cpus_read_lock() when changing the subbuf order

From: Vincent Donnefort <hidden>
Date: 2026-09-17 06:55:36
Also in: lkml, stable

On Wed, Sep 16, 2026 at 08:26:28PM +0100, David Carlier wrote:
A CPU coming online for the first time gets its per CPU buffer allocated
by trace_rb_cpu_prepare(), which then adds it to buffer->cpumask. If that
happens while ring_buffer_subbuf_order_set() is running, the CPU shows up
after the allocation loop and the install loop walks it with an empty
new_pages list, corrupting the buffer.

Take cpus_read_lock() as ring_buffer_resize() does.

Fixes: f9b94daa542a ("ring-buffer: Set new size of the ring buffer sub page")
Cc: stable@vger.kernel.org
Signed-off-by: David Carlier <redacted>
It is usually good practice to not link the different versions of patches
together.

Beside,

Reviewed-by: Vincent Donnefort <redacted>
quoted hunk ↗ jump to hunk
---

Notes:
    v2:
     - Reword the changelog: offlined CPUs stay in ->cpumask, so only a CPU
       coming online for the first time can appear mid-flight (Vincent)
     - Drop the comment above guard(cpus_read_lock)() (Vincent)
    
    v1: https://lore.kernel.org/linux-trace-kernel/20260914182850.21449-1-devnexen@gmail.com/ (local)

 kernel/trace/ring_buffer.c | 2 ++
 1 file changed, 2 insertions(+)
diff --git a/kernel/trace/ring_buffer.c b/kernel/trace/ring_buffer.c
index 04bb94c29f58..e78fb4bb2195 100644
--- a/kernel/trace/ring_buffer.c
+++ b/kernel/trace/ring_buffer.c
@@ -7464,6 +7464,8 @@ int ring_buffer_subbuf_order_set(struct trace_buffer *buffer, int order)
 	if (psize > RB_WRITE_MASK + 1)
 		return -EINVAL;
 
+	guard(cpus_read_lock)();
+
 	/* prevent another thread from changing buffer sizes */
 	guard(mutex)(&buffer->mutex);
 
-- 
2.55.0
-- 
Vincent
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help