[PATCH 2/3] perf/core: install the guest callbacks before the guest_state gate

From: Jaidev Shastri via B4 Relay

Date: Mon Sep 21 2026 - 21:13:42 EST


From: Jaidev Shastri <jaidevshastri@xxxxxx>

perf_register_guest_info_callbacks() updates the __perf_guest_state
static call first and __perf_guest_get_ip and the interrupt handlers
afterwards. perf_instruction_pointer() and perf_misc_flags() test
perf_guest_state() and then call perf_guest_get_ip().

Without CONFIG_HAVE_STATIC_CALL, which arm64 selects only under CFI, a
static call is a plain load of key->func. A PMI on another CPU can then
see the new state callback while get_ip still resolves to the RET0
default, and report an instruction pointer of zero for a guest sample.

Install the callees first and the gate last, separated by smp_wmb(). The
reader keeps its control dependency.

Found with MBCheck, a static herd7-based memory consistency checker.

Signed-off-by: Jaidev Shastri <jaidevshastri@xxxxxx>
---
kernel/events/core.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)

diff --git a/kernel/events/core.c b/kernel/events/core.c
index 7cce3fc7c..3b5c59263 100644
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -7760,7 +7760,14 @@ void perf_register_guest_info_callbacks(struct perf_guest_info_callbacks *cbs)
return;

rcu_assign_pointer(perf_guest_cbs, cbs);
- static_call_update(__perf_guest_state, cbs->state);
+
+ /*
+ * perf_guest_state() is the gate the PMI paths test before they call
+ * perf_guest_get_ip() and the interrupt handlers. On architectures
+ * without inline static calls the updates are plain pointer stores,
+ * so install the callees first and the gate last, behind a write
+ * barrier.
+ */
static_call_update(__perf_guest_get_ip, cbs->get_ip);

/* Implementing ->handle_intel_pt_intr is optional. */
@@ -7771,6 +7778,10 @@ void perf_register_guest_info_callbacks(struct perf_guest_info_callbacks *cbs)
if (cbs->handle_mediated_pmi)
static_call_update(__perf_guest_handle_mediated_pmi,
cbs->handle_mediated_pmi);
+
+ /* Order the callee updates above before the gate below. */
+ smp_wmb();
+ static_call_update(__perf_guest_state, cbs->state);
}
EXPORT_SYMBOL_GPL(perf_register_guest_info_callbacks);


--
2.43.0