[PATCH v2 9/9] perf pmu: Fix race with concurrent tracepoint creation and removal in perf list
From: Ian Rogers
Date: Tue Sep 29 2026 - 02:31:56 EST
perf_pmus__print_pmu_events() first counts events via
perf_pmu__num_events() to allocate the aliases array, then populates it
via perf_pmu__for_each_event(). When dynamic tracepoints (such as
kprobes or uprobes during 'perf test' runs) are concurrently created or
removed between the two passes:
- If an event is removed, state.index is smaller than the allocated len,
leaving trailing zeroed entries in aliases[] with name == NULL and
pmu == NULL, which causes qsort(cmp_sevent) or the print loop to crash
with SIGSEGV.
- If a dynamic tracepoint subsystem directory is removed while scanning
/sys/kernel/tracing/events, tp_pmu__for_each_tp_event() returns
-ENOENT and aborts enumeration of all remaining tracepoint subsystems.
- If an event is added, perf_pmus__print_pmu_events__callback() aborts
enumeration when state->index reaches state->aliases_len.
Grow state->aliases dynamically via realloc() when needed, use
state.index as the actual populated length for sorting and printing, and
ignore -ENOENT when a tracepoint subsystem directory disappears during
enumeration.
Fixes: c3245d2093c1 ("perf pmu: Abstract alias/event struct")
Fixes: 45b6e281cb06 ("perf tp_pmu: Add event APIs")
Assisted-by: Antigravity:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@xxxxxxxxxx>
---
tools/perf/util/pmus.c | 21 +++++++++++++++++----
tools/perf/util/tp_pmu.c | 8 ++++++--
2 files changed, 23 insertions(+), 6 deletions(-)
diff --git a/tools/perf/util/pmus.c b/tools/perf/util/pmus.c
index e0a4cb2428ca..1355b317f3ed 100644
--- a/tools/perf/util/pmus.c
+++ b/tools/perf/util/pmus.c
@@ -8,6 +8,7 @@
#include <sys/types.h>
#include <ctype.h>
#include <pthread.h>
+#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include "cpumap.h"
@@ -571,7 +572,7 @@ static int cmp_sevent(const void *a, const void *b)
}
/* Order by event name. */
- return strcmp(as->name, bs->name);
+ return strcmp(as->name ?: "", bs->name ?: "");
}
static bool pmu_alias_is_duplicate(struct sevent *a, struct sevent *b)
@@ -581,7 +582,7 @@ static bool pmu_alias_is_duplicate(struct sevent *a, struct sevent *b)
return false;
/* Don't remove duplicates for different PMUs */
- return strcmp(a->pmu_name, b->pmu_name) == 0;
+ return strcmp(a->pmu_name ?: "", b->pmu_name ?: "") == 0;
}
struct events_callback_state {
@@ -597,8 +598,18 @@ static int perf_pmus__print_pmu_events__callback(void *vstate,
struct sevent *s;
if (state->index >= state->aliases_len) {
- pr_err("Unexpected event %s/%s/\n", info->pmu->name, info->name);
- return 1;
+ size_t new_len = max_t(size_t, 16, state->aliases_len * 2);
+ struct sevent *new_aliases;
+
+ new_aliases = realloc(state->aliases, new_len * sizeof(struct sevent));
+ if (!new_aliases) {
+ pr_err("Unexpected event %s/%s/\n", info->pmu->name, info->name);
+ return 1;
+ }
+ memset(&new_aliases[state->aliases_len], 0,
+ (new_len - state->aliases_len) * sizeof(struct sevent));
+ state->aliases = new_aliases;
+ state->aliases_len = new_len;
}
assert(info->pmu != NULL || info->name != NULL);
s = &state->aliases[state->index];
@@ -654,6 +665,8 @@ void perf_pmus__print_pmu_events(const struct print_callbacks *print_cb, void *p
perf_pmu__for_each_event(pmu, skip_duplicate_pmus, &state,
perf_pmus__print_pmu_events__callback);
}
+ aliases = state.aliases;
+ len = state.index;
qsort(aliases, len, sizeof(struct sevent), cmp_sevent);
for (int j = 0; j < len; j++) {
/* Skip duplicates */
diff --git a/tools/perf/util/tp_pmu.c b/tools/perf/util/tp_pmu.c
index c2be8c9f9084..5ac732e06841 100644
--- a/tools/perf/util/tp_pmu.c
+++ b/tools/perf/util/tp_pmu.c
@@ -151,7 +151,9 @@ static int for_each_event_cb(void *state, const char *sys_name, const char *evt_
static int for_each_event_sys_cb(void *state, const char *sys_name)
{
- return tp_pmu__for_each_tp_event(sys_name, state, for_each_event_cb);
+ int ret = tp_pmu__for_each_tp_event(sys_name, state, for_each_event_cb);
+
+ return ret == -ENOENT ? 0 : ret;
}
int tp_pmu__for_each_event(struct perf_pmu *pmu, void *state, pmu_event_callback cb)
@@ -176,7 +178,9 @@ static int num_events_cb(void *state, const char *sys_name __maybe_unused,
static int num_events_sys_cb(void *state, const char *sys_name)
{
- return tp_pmu__for_each_tp_event(sys_name, state, num_events_cb);
+ int ret = tp_pmu__for_each_tp_event(sys_name, state, num_events_cb);
+
+ return ret == -ENOENT ? 0 : ret;
}
size_t tp_pmu__num_events(struct perf_pmu *pmu __maybe_unused)
--
2.56.0.rc1.315.gc6ed9934b7-goog