[PATCH 2/2] tracing/user_events: Share tracing state between existing threads

From: Jeff Barnes

Date: Fri Oct 02 2026 - 11:40:44 EST


Threads created before the first user-events registration can share an
mm_struct while each has a NULL user_event_mm pointer.

When one thread registers an event, current_user_event_mm() creates a
user_event_mm and attaches it only to that task. A pre-existing sibling
thread sharing the same mm_struct can later create another user_event_mm.
The two wrappers have independent enabler lists, allowing both threads to
register different events using the same enable address and bit despite
the EADDRINUSE check.

Look for an active user_event_mm associated with the current mm_struct
before allocating a new one. Attach the current task to that wrapper and
increment its task count.

Serialize lookup and attachment with the final task-count decrement and
list removal so that a task cannot attach to a wrapper after its
last-task transition has begun.

Without this change, the new selftest reports that the second
registration succeeds. With the change, it is rejected with
EADDRINUSE, and all user_events ABI tests pass.

Signed-off-by: Jeff Barnes <jeffbarnes@xxxxxxxxxxxxxxxxxxx>
---
kernel/trace/trace_events_user.c | 78 ++++++++++++++++++++++++++------
1 file changed, 64 insertions(+), 14 deletions(-)

diff --git a/kernel/trace/trace_events_user.c b/kernel/trace/trace_events_user.c
index f658c3a77aa7..950d8a3cd0e3 100644
--- a/kernel/trace/trace_events_user.c
+++ b/kernel/trace/trace_events_user.c
@@ -210,6 +210,7 @@ static int user_event_parse(struct user_event_group *group, char *name,

static struct user_event_mm *user_event_mm_get(struct user_event_mm *mm);
static struct user_event_mm *user_event_mm_get_all(struct user_event *user);
+static void user_event_mm_destroy(struct user_event_mm *mm);
static void user_event_mm_put(struct user_event_mm *mm);
static int destroy_user_event(struct user_event *user);
static bool user_fields_match(struct user_event *user, int argc,
@@ -754,33 +755,78 @@ static struct user_event_mm *user_event_mm_alloc(struct task_struct *t)
return user_mm;
}

+static struct user_event_mm *
+user_event_mm_find_locked(struct mm_struct *mm)
+{
+ struct user_event_mm *user_mm;
+
+ lockdep_assert_held(&user_event_mms_lock);
+
+ list_for_each_entry(user_mm, &user_event_mms, mms_link)
+ if (user_mm->mm == mm)
+ return user_mm;
+
+ return NULL;
+}
+
static void user_event_mm_attach(struct user_event_mm *user_mm, struct task_struct *t)
{
unsigned long flags;

spin_lock_irqsave(&user_event_mms_lock, flags);
list_add_rcu(&user_mm->mms_link, &user_event_mms);
- spin_unlock_irqrestore(&user_event_mms_lock, flags);
-
t->user_event_mm = user_mm;
+ spin_unlock_irqrestore(&user_event_mms_lock, flags);
}

static struct user_event_mm *current_user_event_mm(void)
{
+ struct user_event_mm *new_mm;
struct user_event_mm *user_mm = current->user_event_mm;
+ unsigned long flags;

if (user_mm)
- goto inc;
+ return user_event_mm_get(user_mm);

- user_mm = user_event_mm_alloc(current);
+ spin_lock_irqsave(&user_event_mms_lock, flags);

- if (!user_mm)
- goto error;
+ user_mm = user_event_mm_find_locked(current->mm);
+
+ if (user_mm) {
+ refcount_inc(&user_mm->tasks);
+ current->user_event_mm = user_mm;
+ user_event_mm_get(user_mm);
+ }
+
+ spin_unlock_irqrestore(&user_event_mms_lock, flags);
+
+ if (user_mm)
+ return user_mm;
+
+ new_mm = user_event_mm_alloc(current);
+
+ spin_lock_irqsave(&user_event_mms_lock, flags);
+
+ user_mm = user_event_mm_find_locked(current->mm);
+
+ if (user_mm) {
+ refcount_inc(&user_mm->tasks);
+ } else if (new_mm) {
+ user_mm = new_mm;
+ list_add_rcu(&user_mm->mms_link, &user_event_mms);
+ } else {
+ spin_unlock_irqrestore(&user_event_mms_lock, flags);
+ return NULL;
+ }
+
+ current->user_event_mm = user_mm;
+ user_event_mm_get(user_mm);
+
+ spin_unlock_irqrestore(&user_event_mms_lock, flags);
+
+ if (new_mm && new_mm != user_mm)
+ user_event_mm_destroy(new_mm);

- user_event_mm_attach(user_mm, current);
-inc:
- refcount_inc(&user_mm->refcnt);
-error:
return user_mm;
}

@@ -817,14 +863,18 @@ void user_event_mm_remove(struct task_struct *t)
might_sleep();

mm = t->user_event_mm;
+
+ spin_lock_irqsave(&user_event_mms_lock, flags);
+
t->user_event_mm = NULL;

- /* Clone will increment the tasks, only remove if last clone */
- if (!refcount_dec_and_test(&mm->tasks))
+ /* Clones and attached tasks increment this count. */
+ if (!refcount_dec_and_test(&mm->tasks)) {
+ spin_unlock_irqrestore(&user_event_mms_lock, flags);
return;
+ }

- /* Remove the mm from the list, so it can no longer be enabled */
- spin_lock_irqsave(&user_event_mms_lock, flags);
+ /* Prevent new tasks from attaching after the last-task transition. */
list_del_rcu(&mm->mms_link);
spin_unlock_irqrestore(&user_event_mms_lock, flags);

--
2.43.0