mirror of
https://github.com/torvalds/linux.git
synced 2026-09-23 22:14:03 +02:00
The PEBS buffer is shared by all events on a CPU, so drain_pebs() must
not be reentered. If so, one instance may observe stale buffer state and
potentially access out-of-bound memory.
Most invocations happen in NMI context, which naturally prevents reentry.
However, drain_pebs() is also reachable from process context via
intel_pmu_drain_pebs_buffer().
In those paths, the PMU is often already disabled, but not guaranteed.
For example, __intel_pmu_pebs_disable() only disables the target counter,
so other active counters can still raise a PMI and interrupt an in-flight
drain_pebs(). Here is an example,
__perf_addr_filters_adjust()
perf_event_stop()
__perf_event_stop()
x86_pmu_stop() (event->pmu->stop)
intel_pmu_disable_event()
intel_pmu_pebs_disable()
__intel_pmu_pebs_disable()
intel_pmu_drain_large_pebs()
intel_pmu_drain_pebs_buffer()
Introduce __intel_pmu_quiesce() and __intel_pmu_resume() helpers and
use them in intel_pmu_drain_large_pebs() to disable the full PMU
around the intel_pmu_drain_pebs_buffer() call, preventing reentry.
Also add a warning in intel_pmu_drain_pebs_buffer() when the full PMU is
not disabled.
Fixes:
|
||
|---|---|---|
| .. | ||
| bts.c | ||
| core.c | ||
| cstate.c | ||
| ds.c | ||
| knc.c | ||
| lbr.c | ||
| Makefile | ||
| p4.c | ||
| p6.c | ||
| pt.c | ||
| pt.h | ||
| uncore_discovery.c | ||
| uncore_discovery.h | ||
| uncore_nhmex.c | ||
| uncore_snb.c | ||
| uncore_snbep.c | ||
| uncore.c | ||
| uncore.h | ||