[PATCH 0/2] coresight: etm-perf: fix resume AUX leak and exclude_kernel bypass

Junrui Luo via B4 Relay devnull+moonafterrain.outlook.com at kernel.org
Thu Aug 13 05:47:15 PDT 2026


Two independent fixes for coresight-etm-perf.c, both tagged for stable.

Patch 1: etm_event_start() shares one error label between the initial
start and the PERF_EF_RESUME path. Taking it on resume skips
fail_end_stop, leaving the AUX transaction from the earlier successful
start outstanding while the event is marked PERF_HES_STOPPED.
etm_event_stop() then returns early, so the AUX handle, the sink, the
remaining path elements and the trace ID are all leaked.

Patch 2: etm_event_init() accepts events with both attr.exclude_kernel
and attr.exclude_user set. Neither config parser ORs the mode bits, so
ETM_MODE_EXCL_KERN is overwritten by ETM_MODE_EXCL_USER and the tracer
is programmed to trace the kernel instead. perf_event_open() skips
perf_allow_kernel() when attr.exclude_kernel is set, so an unprivileged
caller can reach this.

Build tested for arm64. I have no CoreSight hardware, so neither fix has
been exercised at runtime.

Signed-off-by: Junrui Luo <moonafterrain at outlook.com>
---
Junrui Luo (2):
      coresight: etm-perf: don't leak the AUX handle on failed resume
      coresight: etm-perf: reject events that exclude both kernel and user space

 drivers/hwtracing/coresight/coresight-etm-perf.c | 20 ++++++++++++++++++--
 1 file changed, 18 insertions(+), 2 deletions(-)
---
base-commit: f5bbbfec59b4e2fb7520a91de3df8a6174325d6a
change-id: 20260813-coresight-fixes-7d90d0240dda

Best regards,
-- 
Junrui Luo <moonafterrain at outlook.com>





More information about the linux-arm-kernel mailing list