]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
tracing: Fix context switch counter truncation
authorUsama Arif <usama.arif@linux.dev>
Fri, 17 Jul 2026 17:32:52 +0000 (10:32 -0700)
committerSteven Rostedt <rostedt@goodmis.org>
Fri, 24 Jul 2026 17:43:18 +0000 (13:43 -0400)
trace_user_fault_read() samples nr_context_switches_cpu() before enabling
preemption and retries the user copy if the counter changes. The helper
returns unsigned long long because rq->nr_switches is u64, but the saved
value is unsigned int.

Once a CPU has performed 2^32 context switches, assigning the counter to
cnt discards its upper bits. The comparison after the copy promotes cnt
back to unsigned long long, but the lost bits remain zero, so it reports a
change even when the task was never scheduled out. Every retry then fails
the same way until the 100-try guard warns and the user copy is abandoned.

This affects long-running systems and workloads with high context-switch
rates. A CPU switching 1,000 times per second takes about 50 days.

Store the sampled count in unsigned long long so the full value is
preserved.

Cc: stable@vger.kernel.org
Fixes: 64cf7d058a00 ("tracing: Have trace_marker use per-cpu data to read user space")
Link: https://patch.msgid.link/20260717173252.3431565-1-usama.arif@linux.dev
Reported-by: Breno Leitao <leitao@debian.org>
Signed-off-by: Usama Arif <usama.arif@linux.dev>
Acked-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Reviewed-by: Breno Leitao <leitao@debian.org>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
kernel/trace/trace.c

index 18710c190c924f3d9528c424b4fdb1a5cf6dbc5a..01a5e87af2998eb61a1ca8849528cc27a5c96b42 100644 (file)
@@ -6187,7 +6187,7 @@ char *trace_user_fault_read(struct trace_user_buf_info *tinfo,
 {
        int cpu = smp_processor_id();
        char *buffer = per_cpu_ptr(tinfo->tbuf, cpu)->buf;
-       unsigned int cnt;
+       unsigned long long cnt;
        int trys = 0;
        int ret;