[PATCH 1/3] perf/core: publish the aux_event link with release semantics

From: Jaidev Shastri via B4 Relay

Date: Mon Sep 21 2026 - 21:13:54 EST


From: Jaidev Shastri <jaidevshastri@xxxxxx>

perf_get_aux_event() links an aux_output event to its group leader with
a plain store to event->aux_event once the leader has been validated.
perf_aux_output_begin() and the AUX sample path read the link with plain
loads, from the PMU interrupt on the CPU the event is scheduled on.

Store the link with smp_store_release() and read it with
smp_load_acquire(), so that a reader that sees the link also sees the
state of the leader it points at.

Found with MBCheck, a static herd7-based memory consistency checker.

Signed-off-by: Jaidev Shastri <jaidevshastri@xxxxxx>
---
kernel/events/core.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/kernel/events/core.c b/kernel/events/core.c
index db7b76d6b..7cce3fc7c 100644
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -2332,7 +2332,8 @@ static int perf_get_aux_event(struct perf_event *event,
* group in torn down, the aux_output events loose their
* link to the aux_event and can't schedule any more.
*/
- event->aux_event = group_leader;
+ /* Pairs with the smp_load_acquire() in the AUX output paths. */
+ smp_store_release(&event->aux_event, group_leader);

return 1;
}
@@ -7974,7 +7975,8 @@ static unsigned long perf_prepare_sample_aux(struct perf_event *event,
struct perf_sample_data *data,
size_t size)
{
- struct perf_event *sampler = event->aux_event;
+ /* Pairs with the smp_store_release() in perf_get_aux_event(). */
+ struct perf_event *sampler = smp_load_acquire(&event->aux_event);
struct perf_buffer *rb;

data->aux_size = 0;
@@ -8046,7 +8048,8 @@ static void perf_aux_sample_output(struct perf_event *event,
struct perf_output_handle *handle,
struct perf_sample_data *data)
{
- struct perf_event *sampler = event->aux_event;
+ /* Pairs with the smp_store_release() in perf_get_aux_event(). */
+ struct perf_event *sampler = smp_load_acquire(&event->aux_event);
struct perf_buffer *rb;
unsigned long pad;
long size;

--
2.43.0