tracing: Fix checking of freed trace_event_file for hist files

JIRA: https://issues.redhat.com/browse/RHEL-151695

commit f0a0da1f907e8488826d91c465f7967a56a95aca
Author: Petr Pavlu <petr.pavlu@suse.com>
Date:   Thu Feb 19 17:27:01 2026 +0100

    tracing: Fix checking of freed trace_event_file for hist files

    The event_hist_open() and event_hist_poll() functions currently retrieve
    a trace_event_file pointer from a file struct by invoking
    event_file_data(), which simply returns file->f_inode->i_private. The
    functions then check if the pointer is NULL to determine whether the event
    is still valid. This approach is flawed because i_private is assigned when
    an eventfs inode is allocated and remains set throughout its lifetime.
    Instead, the code should call event_file_file(), which checks for
    EVENT_FILE_FL_FREED. Using the incorrect access function may result in the
    code potentially opening a hist file for an event that is being removed or
    becoming stuck while polling on this file.

    Correct the access method to event_file_file() in both functions.

    Cc: stable@vger.kernel.org
    Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
    Cc: Tom Zanussi <zanussi@kernel.org>
    Link: https://patch.msgid.link/20260219162737.314231-2-petr.pavlu@suse.com
    Fixes: 1bd13edbbed6 ("tracing/hist: Add poll(POLLIN) support on hist file")
    Signed-off-by: Petr Pavlu <petr.pavlu@suse.com>
    Acked-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
    Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>

Signed-off-by: Jerome Marchand <jmarchan@redhat.com>
This commit is contained in:
Jerome Marchand
2026-03-06 09:28:24 +01:00
parent 42fab7a3d7
commit 6ad6f3619c
+2 -2
View File
@@ -5752,7 +5752,7 @@ static __poll_t event_hist_poll(struct file *file, struct poll_table_struct *wai
guard(mutex)(&event_mutex);
event_file = event_file_data(file);
event_file = event_file_file(file);
if (!event_file)
return EPOLLERR;
@@ -5790,7 +5790,7 @@ static int event_hist_open(struct inode *inode, struct file *file)
guard(mutex)(&event_mutex);
event_file = event_file_data(file);
event_file = event_file_file(file);
if (!event_file) {
ret = -ENODEV;
goto err;