[for-linus][PATCH 0/7] tracing: Fixes for v7.3
From: Steven Rostedt
Date: Thu Aug 27 2026 - 11:10:23 EST
tracing fixes for v7.3:
- Fix error output of boot instance creation failure
Currently if a boot instance creation fails, instead of printing out the
name of the instance that failed, it prints "(null)". That is because it
prints "cur_str" that had already been processed by strsep(). Print the
saved name instead.
While at it, print the error code of the failure.
- Fix use-after-free for same named historgrams
Histograms can be named so that they can be used in multiple events. But
if the named histogram has a variable attached, the second event that uses
the named histogram which duplicates it and needs to free the original
after duplication leaves the old variable in place and still visible. If
another histogram uses than variable, it will use the stale one which will
try to reference the freed duplicate histogram and crash the kernel.
Free the duplicate variables along with the duplicated histogram data.
- Check return value of kthread_run() in event self test
The events self tests uses a kthread for testing but does not check if it
succeeded in creating a kthread. If the kthread creation were to fail, the
code will still try to call kthread_stop() on the error returned.
- Fix race between reading trace_pipe and updating subbuffer size
If a user is reading the trace_pipe file at the same time they update the
ring buffer sub-buffer size, can cause the trace_pipe read to read stale
data. Add trace_access_lock() around updating the ring buffer sub-buffer
size.
- Fix eventfs_inode on failure path in creation of the events directory
In the creation of the "events" directory, if after allocating the
eventfs_inode a failure is detected, it calls cleanup_ei() which calls
free_ei(). The free_ei() will test if eventfs_inode being freed has no
children. It is a bug if it does. But on the failure case of the creation
of the "events" directory, the children lists have not yet been
initialized and the free will trigger a warning because list_empty() on an
uninitialized list returns false.
Move the initialization into init_ei() where it makes more sense and makes
sure that a created eventfs_inode has its lists initialized upon creation.
- Check return value of kthread_run() in ftrace direct sample code
The sample code that shows how to use the ftrace direct calls does not
test the return of kthread_run() to see if it succeeds. Return a failure
if the kthread_run() doesn't succeed.
git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace.git
trace/fixes
Head SHA1: 6727b7618f49401acf373fa3ec5712e2ec52e5cf
Deepanshu Kartikey (2):
tracing: Fix use-after-free in trace_pipe read on sub-buffer order change
eventfs: Initialize ei->children and ei->list in init_ei()
Haotian Zhang (2):
samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-modify
samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify
Hui Su (2):
tracing: Fix use-after-free with same-name named triggers
tracing: Fix crash passing ERR_PTR to kthread_stop()
Vincent Donnefort (1):
tracing: Fix logged instance name on creation failure
----
fs/tracefs/event_inode.c | 7 ++-----
kernel/trace/trace.c | 6 +++++-
kernel/trace/trace_events.c | 2 ++
kernel/trace/trace_events_hist.c | 4 +++-
samples/ftrace/ftrace-direct-modify.c | 12 +++++++++---
samples/ftrace/ftrace-direct-multi-modify.c | 12 +++++++++---
6 files changed, 30 insertions(+), 13 deletions(-)