Re: [PATCH v5] tracing: Fix race between update_event_fields and, event_define_fields

Steven Rostedt <[email protected]>
Newsgroups org.kernel.vger.linux-trace-kernel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Mon, 10 Aug 2026 14:32:30 +0800
Michael Wu <[email protected]> wrote:

> The following sequence may leads race between event_define_fields()
> and update_event_fields():

>   CPU0 (module A, pri=1 notifier)        CPU1 (module B, pri=0 notifier)

What does the above mean? Are you loading two modules at the same time?
What does "pri=X notifier" mean? What function calls are these coming from?

-- Steve

>   ===============================        ===============================
>   event_define_fields(call_A)            trace_event_update_all()
>     for each f:                            list_for_each_entry(...,
>       list_add(&f->link,                                &ftrace_events)
>                &class->fields)               -> finds call_A
>         f->link.next = next;        (2)
>                                            update_event_fields(call_A)
>         WRITE_ONCE(class->fields->next,
>                    &f->link);       (4)
>                                              list_for_each_entry(field,
>                                                &class->fields, link)
>                                              -> field = class->fields->next  
>                                                   = &f->link
>                                                   = f (offset 0)
>                                              -> arm64 weak ordering:  
>                                                 (4) visible before (2)
>                                                 field->link.next == 0
>                                              -> next iteration:  
>                                                 field = (void *)0 = NULL
>                                              -> crash at NULL->type (0x18)  
> 
> This produces the following panic:
>    Unable to handle kernel access ... at virtual address 0000000000000018
>    pc : update_event_fields+0xf8/0x368
>    Call trace:
>     update_event_fields+0xf8/0x368
>     trace_event_update_all+0x7c/0x2b4
>     trace_module_notify+0x4c/0x1dc
>     notifier_call_chain+0x84/0x168
>     blocking_notifier_call_chain_robust+0x64/0xd4
>     load_module+0x10c8/0x123c
>     __arm64_sys_finit_module+0x230/0x31c
> 
> Fix by taking event_mutex in trace_event_update_all() before
> trace_event_sem.
> 
> Fixes: b3bc8547d3be ("tracing: Have TRACE_DEFINE_ENUM affect trace event types as well")
> Cc: [email protected]
> Signed-off-by: Michael Wu <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.