[PATCH 3/3] perf/core: publish perf_event_cache with release semantics

From: Jaidev Shastri via B4 Relay

Date: Mon Sep 21 2026 - 21:13:53 EST


From: Jaidev Shastri <jaidevshastri@xxxxxx>

perf_event_init() creates perf_event_cache with a plain store, after the
pmu_idr has been set up. free_event_rcu() reads the pointer with a plain
load from an RCU callback on any CPU.

Store it with smp_store_release() and read it with smp_load_acquire().

Found with MBCheck, a static herd7-based memory consistency checker.

Signed-off-by: Jaidev Shastri <jaidevshastri@xxxxxx>
---
kernel/events/core.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/kernel/events/core.c b/kernel/events/core.c
index 3b5c59263..74cfb13fe 100644
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -5313,7 +5313,8 @@ static void free_event_rcu(struct rcu_head *head)
put_pid_ns(event->ns);
perf_event_free_filter(event);
kfree(event->addr_filter_ranges);
- kmem_cache_free(perf_event_cache, event);
+ /* Pairs with the smp_store_release() in perf_event_init(). */
+ kmem_cache_free(smp_load_acquire(&perf_event_cache), event);
}

static void ring_buffer_attach(struct perf_event *event,
@@ -15404,7 +15405,8 @@ void __init perf_event_init(void)
ret = init_hw_breakpoint();
WARN(ret, "hw_breakpoint initialization failed with: %d", ret);

- perf_event_cache = KMEM_CACHE(perf_event, SLAB_PANIC);
+ /* Pairs with the smp_load_acquire() in free_event_rcu(). */
+ smp_store_release(&perf_event_cache, KMEM_CACHE(perf_event, SLAB_PANIC));

/*
* Build time assertion that we keep the data_head at the intended

--
2.43.0