Re: [PATCH] perf synthetic-events: Fix schedstat event lifetime handling
From: Arnaldo Carvalho de Melo
Date: Tue Sep 22 2026 - 08:41:00 EST
On Tue, Sep 15, 2026 at 12:41:03PM -0700, Ian Rogers wrote:
> On Fri, Sep 11, 2026 at 10:56 PM Hui Su <sh_def@xxxxxxx> wrote:
> >
> > perf_event__synthesize_schedstat() has two event lifetime issues.
> >
> > After a successful iteration, event is freed but retains its value. If
> > the next iteration starts with an unrecognized schedstat record type,
> > neither synthesizer assigns a new value. The stale pointer then passes
> > the NULL check, may be passed to process(), and is freed again.
> >
> > In addition, when user_requested_cpus filters out a synthesized event,
> > the continue path skips free(event), leaking the event.
> >
> > Make event local to each loop iteration so it always starts as NULL.
> > Also avoid the filter continue and unconditionally free each synthesized
> > event at the end of the iteration.
> >
> > Fixes: c3030995f23b ("perf sched stats: Add record and rawdump support")
> > Signed-off-by: Hui Su <sh_def@xxxxxxx>
>
> Reviewed-by: Ian Rogers <irogers@xxxxxxxxxx>
Thanks, applied to perf-tools-next, for v7.4.
- Arnaldo