<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux-next.git/kernel/trace, branch master</title>
<subtitle>Linux kernel latest source</subtitle>
<id>http://mirrors.hust.edu.cn/git/linux-next.git/atom?h=master</id>
<link rel='self' href='http://mirrors.hust.edu.cn/git/linux-next.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/'/>
<updated>2026-10-05T11:44:38+00:00</updated>
<entry>
<title>Merge branch 'for-next' of https://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace.git</title>
<updated>2026-10-05T11:44:38+00:00</updated>
<author>
<name>Mark Brown</name>
<email>broonie@kernel.org</email>
</author>
<published>2026-10-05T11:44:38+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=0b4c1aa39c4df59062510c066b020feeab05456b'/>
<id>urn:sha1:0b4c1aa39c4df59062510c066b020feeab05456b</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Merge branch 'for-next' of https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git</title>
<updated>2026-10-05T10:47:23+00:00</updated>
<author>
<name>Mark Brown</name>
<email>broonie@kernel.org</email>
</author>
<published>2026-10-05T10:47:22+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=855c706f21797f6f99df2726d93d0e902d7e0cfa'/>
<id>urn:sha1:855c706f21797f6f99df2726d93d0e902d7e0cfa</id>
<content type='text'>
</content>
</entry>
<entry>
<title>tracing/probes: Add const to new_argv allocation type</title>
<updated>2026-10-03T00:27:54+00:00</updated>
<author>
<name>Kees Cook</name>
<email>kees+treewide@kernel.org</email>
</author>
<published>2026-09-29T15:09:42+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=f3c6c0549e87b92d309700cf2c0ebe94056428e0'/>
<id>urn:sha1:f3c6c0549e87b92d309700cf2c0ebe94056428e0</id>
<content type='text'>
In preparation for converting the kmalloc family of allocators to the
type-aware kmalloc_obj family, we need to make sure that the returned
type from the allocation matches the type of the variable being
assigned. (The kmalloc family returns "void *", which can be implicitly
cast to any pointer type.)

The assigned type is "const char **", but the converted allocation type
would be "char **", which is the same type without the const qualifier.
As there is no general way to safely add const qualifiers, take the size
from the assignment target instead. No change in allocation size
results.

Build tested ARCH=x86_64 allmodconfig with GCC 16.2.0:
kernel/trace/trace_probe.o

Link: https://lore.kernel.org/all/20260917211022.i.677-kees@kernel.org/

Assisted-by: LLM coccinelle
Signed-off-by: Kees Cook &lt;kees+treewide@kernel.org&gt;
Signed-off-by: Masami Hiramatsu (Google) &lt;mhiramat@kernel.org&gt;
</content>
</entry>
<entry>
<title>Merge git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf 7.3-rc5</title>
<updated>2026-10-02T21:34:41+00:00</updated>
<author>
<name>Alexei Starovoitov</name>
<email>ast@kernel.org</email>
</author>
<published>2026-10-02T21:24:53+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=2b5440b31cafad2fb4b4a83efb780a6d7430a385'/>
<id>urn:sha1:2b5440b31cafad2fb4b4a83efb780a6d7430a385</id>
<content type='text'>
Cross-merge BPF and other fixes after downstream PR.

Conflicts:
  arch/arm64/net/bpf_jit_comp.c
  arch/x86/net/bpf_jit_comp.c

Signed-off-by: Alexei Starovoitov &lt;ast@kernel.org&gt;
</content>
</entry>
<entry>
<title>fprobe: Use guard(rcu_sched_notrace) and check rcu_is_watching()</title>
<updated>2026-09-29T23:41:31+00:00</updated>
<author>
<name>Masami Hiramatsu (Google)</name>
<email>mhiramat@kernel.org</email>
</author>
<published>2026-09-29T00:19:12+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=e0a6249190402a28f1e2925a81acf573157d55ef'/>
<id>urn:sha1:e0a6249190402a28f1e2925a81acf573157d55ef</id>
<content type='text'>
unregister_fprobe() and unregister_fprobe_async() (used by BPF
kprobe-multi) rely on standard RCU grace periods (synchronize_rcu()
and call_rcu()) to wait until in-flight fprobe handlers complete before
freeing the fprobe.

However, if an fprobe handler executes while RCU is not watching (such
as in the idle loop or nohz_full extended quiescent states), standard
RCU does not track preemption-disabled sections. Consequently,
synchronize_rcu() does not wait for those executions, which can lead
to a use-after-free if the fprobe is freed immediately after
unregistration. Ensure handlers exit early when !rcu_is_watching().

Furthermore, fprobe_fgraph_entry() and fprobe_ftrace_entry() previously
used guard(rcu)() and rcu_read_lock(), which invoke lockdep on every
hit under CONFIG_PROVE_LOCKING. This adds overhead and can cause lockdep
recursion if probed functions interact with lockdep.

Since rhltable_lookup() and rhl_for_each_entry_rcu() use
rcu_dereference_all_check() (which checks rcu_read_lock_any_held()),
holding preemption disabled via rcu_read_lock_sched_notrace() is fully
valid and sufficient so long as rcu_is_watching() is true.

Define and use guard(rcu_sched_notrace)() across fprobe_ftrace_entry(),
fprobe_fgraph_entry(), and fprobe_return(). This eliminates fast-path
rcu_read_lock() and lockdep overhead while guaranteeing safe grace
period synchronization.

Link: https://lore.kernel.org/all/179064115227.394389.16910234241400391996.stgit@devnote2/

Reported-by: Sashiko &lt;sashiko-bot@kernel.org&gt;
Closes: https://sashiko.dev/#/bug/linux-e46bcd68-4a56-4f19-a255-e3772980e5e3
Fixes: 657b594b2084 ("fprobe: Fix unregister_fprobe() to wait for RCU grace period")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Masami Hiramatsu (Google) &lt;mhiramat@kernel.org&gt;
Reviewed-by: Paul E. McKenney &lt;paulmck@kernel.org&gt;
</content>
</entry>
<entry>
<title>Merge tag 'probes-fixes-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace</title>
<updated>2026-09-26T15:36:29+00:00</updated>
<author>
<name>Linus Torvalds</name>
<email>torvalds@linux-foundation.org</email>
</author>
<published>2026-09-26T15:36:29+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=efb27d47677397961c9017c0f8f469eb25a15d68'/>
<id>urn:sha1:efb27d47677397961c9017c0f8f469eb25a15d68</id>
<content type='text'>
Pull probe fixes from Masami Hiramatsu:

 - kprobes: Fix permanent hang when flushing the kprobe optimizer

   Fix a deadlock when disabling kprobe optimization via sysctl or
   debugfs where flushers hung waiting for optimizer_completion.
   Replaced the completion with an optimizer_passes counter and
   wait_var_event_mutex() under kprobe_mutex so concurrent flushers can
   wait and wake up safely.

 - fprobe: Terminate the fgraph_data list when the reservation is not
   filled

   Fix an issue where unused shadow stack data left uninitialized by
   fprobe_fgraph_entry() was misparsed as stale fprobe headers on
   return. Explicitly write a zero word to terminate the list and update
   read_fprobe_header() to handle the zeroed slot properly.

 - ftracetest: Fix unique symbol check in kprobe_non_uniq_symbol.tc

   Fix false test failures in kprobe_non_uniq_symbol.tc on architectures
   like s390 where a symbol exists once in core kernel but also in
   modules. Anchor the /proc/kallsyms search regex to the end of the
   line so that module symbols are not incorrectly counted.

* tag 'probes-fixes-v7.3-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace:
  kprobes: Fix permanent hang when flushing the kprobe optimizer
  fprobe: Terminate the fgraph_data list when the reservation is not filled
  selftests/ftrace: Fix unique symbol check in kprobe_non_uniq_symbol.tc
</content>
</entry>
<entry>
<title>Merge git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf 7.3-rc4</title>
<updated>2026-09-24T16:15:14+00:00</updated>
<author>
<name>Alexei Starovoitov</name>
<email>ast@kernel.org</email>
</author>
<published>2026-09-24T16:10:16+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=0e4cf80d0d4893d8227ba816d0559ab778af8125'/>
<id>urn:sha1:0e4cf80d0d4893d8227ba816d0559ab778af8125</id>
<content type='text'>
Cross-merge BPF and other fixes after downstream PR.

Conflicts:
  kernel/bpf/helpers.c
  tools/testing/selftests/bpf/prog_tests/cb_refs.c
  tools/testing/selftests/bpf/prog_tests/verifier.c

Signed-off-by: Alexei Starovoitov &lt;ast@kernel.org&gt;
</content>
</entry>
<entry>
<title>bpf: Preserve stack initialization for generic output buffers</title>
<updated>2026-09-21T17:12:39+00:00</updated>
<author>
<name>Kumar Kartikeya Dwivedi</name>
<email>memxor@gmail.com</email>
</author>
<published>2026-09-21T02:38:32+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=5da4a9f26fca03ccd8afcc88f5c709c459c00ab8'/>
<id>urn:sha1:5da4a9f26fca03ccd8afcc88f5c709c459c00ab8</id>
<content type='text'>
Partial-output helpers such as bpf_snprintf() do not read incoming buffer
contents, but may leave some bytes untouched. Let them accept uninitialized
storage without promising full initialization to callers that cannot read
uninitialized stack memory.

Make this the default for generic MEM_UNINIT buffers, including __uninit
kfunc arguments. Allow invalid stack bytes through the output check but
leave them invalid when uninitialized stack reads are not allowed. Scrub
initialized bytes and scalar spills as possible writes, retaining the
existing restrictions on spilled pointers and special stack objects.

Retain the output annotation for variable-sized arguments and track their
raw-mode eligibility separately. Callers allowed uninitialized stack reads
can continue treating the potentially written range as initialized. For
constant ranges, defer that initialization until all inputs are checked.

Keep prior stack contents live for generic outputs when the caller cannot
read uninitialized stack memory. Such calls do not define the entire range,
so liveness must preserve initialization facts that remain relevant after
the call. Dynptr and iterator constructors still define their storage.

Annotate the snprintf, sysctl name, d_path, snprintf_btf and branch-record
destinations with MEM_UNINIT, and document that generic __uninit kfuncs may
leave bytes untouched. This also changes readback from existing full-writing
helpers: without permission to read uninitialized stack memory, programs
must initialize those bytes themselves before reading them after a call.

Suggested-by: Eduard Zingerman &lt;eddyz87@gmail.com&gt;
Signed-off-by: Kumar Kartikeya Dwivedi &lt;memxor@gmail.com&gt;
Signed-off-by: Alexei Starovoitov &lt;ast@kernel.org&gt;
Link: https://patch.msgid.link/20260921023843.411943-9-memxor@gmail.com
</content>
</entry>
<entry>
<title>fprobe: Terminate the fgraph_data list when the reservation is not filled</title>
<updated>2026-09-18T00:51:49+00:00</updated>
<author>
<name>David Carlier</name>
<email>devnexen@gmail.com</email>
</author>
<published>2026-09-17T21:24:07+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=1d653a183973f5283a3db5a38cd5e195eb152244'/>
<id>urn:sha1:1d653a183973f5283a3db5a38cd5e195eb152244</id>
<content type='text'>
fprobe_fgraph_entry() reserves shadow stack space for every fprobe with
an exit handler, but only fills it for those whose entry handler returns
0. fgraph_reserve_data() does not clear the area, so fprobe_return()
parses the unused tail as headers left over from an earlier call, and an
exit handler can run twice or despite its entry handler asking to skip
it.

Write a zero word after the last entry to terminate the walk. A zeroed
slot does not decode to a NULL fprobe on the arches that encode the
header into one unsigned long, since arch_decode_fprobe_header_fp() ORs
in FPROBE_HEADER_MSB_PATTERN, so make read_fprobe_header() return NULL
for a zeroed slot.

Link: https://lore.kernel.org/all/20260917212407.384468-1-devnexen@gmail.com/

Fixes: e0a384434ae1 ("tracing: fprobe: do not zero out unused fgraph_data")
Cc: stable@vger.kernel.org
Suggested-by: Masami Hiramatsu (Google) &lt;mhiramat@kernel.org&gt;
Signed-off-by: David Carlier &lt;devnexen@gmail.com&gt;
Signed-off-by: Masami Hiramatsu (Google) &lt;mhiramat@kernel.org&gt;
</content>
</entry>
<entry>
<title>ring-buffer: Check resize_disabled before publishing the new subbuf order</title>
<updated>2026-09-13T17:06:43+00:00</updated>
<author>
<name>David Carlier</name>
<email>devnexen@gmail.com</email>
</author>
<published>2026-09-12T10:39:38+00:00</published>
<link rel='alternate' type='text/html' href='http://mirrors.hust.edu.cn/git/linux-next.git/commit/?id=d860c67c051685abb0460b593b193f0f45f4fa92'/>
<id>urn:sha1:d860c67c051685abb0460b593b193f0f45f4fa92</id>
<content type='text'>
ring_buffer_subbuf_order_set() stores the new order and only then walks
the CPUs, returning -EBUSY if any of them has resizing disabled. A user
mapped buffer has resizing disabled, and __rb_map_vma() reads
buffer-&gt;subbuf_order without buffer-&gt;mutex, so an mmap of an already
mapped CPU racing the failing order change sizes the mapping with the
new order and inserts pages past the sub-buffer into the VMA.

Check the CPUs before storing the new order.

Cc: stable@vger.kernel.org
Fixes: 117c39200d9d ("ring-buffer: Introducing ring-buffer mapping functions")
Link: https://patch.msgid.link/20260912103938.1127021-1-devnexen@gmail.com
Signed-off-by: David Carlier &lt;devnexen@gmail.com&gt;
Signed-off-by: Steven Rostedt &lt;rostedt@goodmis.org&gt;
</content>
</entry>
</feed>
