[PATCH 1/2] coresight: etm-perf: don't leak the AUX handle on failed resume
Junrui Luo via B4 Relay
devnull+moonafterrain.outlook.com at kernel.org
Thu Aug 13 05:47:16 PDT 2026
From: Junrui Luo <moonafterrain at outlook.com>
etm_event_start() shares one error label between the initial start and
the PERF_EF_RESUME path. On the initial start, reaching 'fail' means
perf_aux_output_begin() has not succeeded, so marking the event
PERF_HES_STOPPED is correct. On resume, an AUX transaction opened by the
earlier successful start is still outstanding, and 'goto fail' jumps past
fail_end_stop, which would have ended it.
The following etm_event_stop() returns early on PERF_HES_STOPPED, ahead
of perf_aux_output_end(), coresight_disable_source() and
coresight_disable_path(). This leaks the AUX ring buffer reference and
leaves the sink, the remaining path elements and the trace ID held, so no
later session can use them. ctxt->event_data is cleared just above that
early return, so the leak is silent.
Make resume infallible as pt_event_start() does: leave hw.state alone so
the regular stop path still runs the full teardown. etm_event_resume()
already logs the failure.
Fixes: abffe22e93d7 ("coresight: perf: Support AUX trace pause and resume")
Reported-by: Yuhao Jiang <danisjiang at gmail.com>
Assisted-by: Claude:claude-opus-5
Cc: stable at vger.kernel.org
Signed-off-by: Junrui Luo <moonafterrain at outlook.com>
---
drivers/hwtracing/coresight/coresight-etm-perf.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/drivers/hwtracing/coresight/coresight-etm-perf.c b/drivers/hwtracing/coresight/coresight-etm-perf.c
index 09b21a711a87..af0295eab143 100644
--- a/drivers/hwtracing/coresight/coresight-etm-perf.c
+++ b/drivers/hwtracing/coresight/coresight-etm-perf.c
@@ -548,8 +548,13 @@ static void etm_event_start(struct perf_event *event, int flags)
if (flags & PERF_EF_RESUME) {
path = etm_event_get_ctxt_path(ctxt);
- if (etm_event_resume(path) < 0)
- goto fail;
+ /*
+ * Don't mark the event stopped on failure: the AUX transaction
+ * from the initial start is still live and etm_event_stop()
+ * bails out early on PERF_HES_STOPPED, leaking it and the path.
+ * etm_event_resume() already reports the error.
+ */
+ etm_event_resume(path);
return;
}
--
2.51.2
More information about the linux-arm-kernel
mailing list