Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1548170 > unrolled thread

Re: [PATCH v2 perf/core] perf script: fix a use after free crash.

Started byKrister Johansen <kjlx@templeofstupid.com>
First post2016-12-29 02:50 +0100
Last post2017-01-03 01:40 +0100
Articles 6 — 2 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: [PATCH v2 perf/core] perf script: fix a use after free crash. Krister Johansen <kjlx@templeofstupid.com> - 2016-12-29 02:50 +0100
    Re: [PATCH v2 perf/core] perf script: fix a use after free crash. Arnaldo Carvalho de Melo <acme@kernel.org> - 2017-01-02 16:20 +0100
      Re: [PATCH v2 perf/core] perf script: fix a use after free crash. Arnaldo Carvalho de Melo <acme@kernel.org> - 2017-01-02 18:40 +0100
        Re: [PATCH v2 perf/core] perf script: fix a use after free crash. Arnaldo Carvalho de Melo <acme@kernel.org> - 2017-01-02 18:40 +0100
          Re: [PATCH v2 perf/core] perf script: fix a use after free crash. Arnaldo Carvalho de Melo <acme@kernel.org> - 2017-01-02 20:50 +0100
            Re: [PATCH v2 perf/core] perf script: fix a use after free crash. Arnaldo Carvalho de Melo <acme@kernel.org> - 2017-01-03 01:40 +0100

#1548170 — Re: [PATCH v2 perf/core] perf script: fix a use after free crash.

FromKrister Johansen <kjlx@templeofstupid.com>
Date2016-12-29 02:50 +0100
SubjectRe: [PATCH v2 perf/core] perf script: fix a use after free crash.
Message-ID<sTy0V-8mv-1@gated-at.bofh.it>
On Tue, Nov 22, 2016 at 04:01:06PM -0300, Arnaldo Carvalho de Melo wrote:
> Sorry for the overly long delay, trying it now after fixing up a
> conflict with a recent patchkit (branch stuff) I tested it by running
> 'perf top -g' and I'm getting some assertion bugs:
> 
> 
> # perf top -g
>            1.34% filemap_map_pages
>          - 0.59% alloc_pages_vma
>               1.20% __alloc_pages_nodemask
> -    5.87%     0.45%  [kernel]                            [k] handle_mm_fault
>    - 1.94% handle_mm_fault
>         1.34% filemap_map_pages
>       - 0.59% alloc_pages_vma
>            1.22% __alloc_pages_nodemask
> +    5.75%     0.03%  perf                                [.] hist_entry_iter__add
> +    4.46%     0.00%  [unknown]                           [.] 0000000000000000
> -    4.06%     2.74%  libc-2.23.so                        [.] _int_malloc
>    - 1.95% 0
>         1.94% _int_malloc
> -    3.20%     0.23%  perf                                [.] iter_add_next_cumulative_entry
>    - 1.49% iter_add_next_cumulative_entry
>       - 1.43% __hists__add_entry
>      2.58%     0.01%  [kernel]                            [k] return_from_SYSCALL_64
>      2.57%     2.55%  libperl.so.5.22.2                   [.] Perl_fbm_instr
> -    2.54%     2.51%  liblzma.so.5.2.2                    [.] lzma_decode
>    - 2.51% lzma_decode
>      2.33%     0.00%  ld-2.23.so                          [.] _dl_sysdep_start
> +    2.24%     0.04%  ld-2.23.so                          [.] dl_main
>      2.13%     0.03%  [kernel]                            [k] ext4_readdir
>      2.09%     0.01%  [kernel]                            [k] sys_newstat
>      2.08%     0.04%  [kernel]                            [k] vfs_fstatat
>      2.07%     0.02%  [kernel]                            [k] SYSC_newstat
>      2.02%     0.01%  [kernel]                            [k] iterate_dir
> -    1.96%     0.17%  [kernel]                            [k] __alloc_pages_nodemask
>    - 1.37% __alloc_pages_nodemask
> perf: util/map.c:246: map__exit: Assertion `!(!((&map->rb_node)->__rb_parent_color == (unsigned long)(&map->rb_node)))' failed.
>                                                                                                                                Aborted (core dumped)
> [root@jouet ~]# 
> 
> 
> I'll try to investigate this further later/tomorrow, find the updated patch below.
> 
> - Arnaldo
> 
> commit af04d2c4a5d1f6bd7f4971118e4e1153cc7c2506
> Author: Krister Johansen <kjlx@templeofstupid.com>
> Date:   Tue Oct 11 02:28:39 2016 -0700
> 
>     perf callchain: Fix a use after free crash due to refcounting bug
>     
>     If dso__load_kcore frees all of the existing maps, but one has already
>     been attached to a callchain cursor node, then we can get a SIGSEGV in
>     any function that happens to try to use this invalid cursor.  Use the
>     existing map refcount mechanism to forestall cleanup of a map until the
>     cursor iterates past the node.
>     
>     Signed-off-by: Krister Johansen <kjlx@templeofstupid.com>
>     Cc: Frederic Weisbecker <fweisbec@gmail.com>
>     Cc: Masami Hiramatsu <mhiramat@kernel.org>
>     Cc: Namhyung Kim <namhyung@kernel.org>
>     Link: http://lkml.kernel.org/r/20161011092839.GC7837@templeofstupid.com
>     Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
> 
> diff --git a/tools/perf/util/callchain.c b/tools/perf/util/callchain.c
> index 823befd8209a..18bb7caee535 100644
> --- a/tools/perf/util/callchain.c
> +++ b/tools/perf/util/callchain.c
> @@ -437,7 +437,7 @@ fill_node(struct callchain_node *node, struct callchain_cursor *cursor)
>  		}
>  		call->ip = cursor_node->ip;
>  		call->ms.sym = cursor_node->sym;
> -		call->ms.map = cursor_node->map;
> +		call->ms.map = map__get(cursor_node->map);
>  
>  		if (cursor_node->branch) {
>  			call->branch_count = 1;
> @@ -477,6 +477,7 @@ add_child(struct callchain_node *parent,
>  
>  		list_for_each_entry_safe(call, tmp, &new->val, list) {
>  			list_del(&call->list);
> +			map__zput(call->ms.map);
>  			free(call);
>  		}
>  		free(new);
> @@ -761,6 +762,7 @@ merge_chain_branch(struct callchain_cursor *cursor,
>  					list->ms.map, list->ms.sym,
>  					false, NULL, 0, 0);
>  		list_del(&list->list);
> +		map__zput(list->ms.map);
>  		free(list);
>  	}
>  
> @@ -811,7 +813,8 @@ int callchain_cursor_append(struct callchain_cursor *cursor,
>  	}
>  
>  	node->ip = ip;
> -	node->map = map;
> +	map__zput(node->map);
> +	node->map = map__get(map);
>  	node->sym = sym;
>  	node->branch = branch;
>  	node->nr_loop_iter = nr_loop_iter;
> @@ -868,6 +871,8 @@ int fill_callchain_info(struct addr_location *al, struct callchain_cursor_node *
>  			goto out;
>  	}
>  
> +	map__get(al->map);
> +
>  	if (al->map->groups == &al->machine->kmaps) {
>  		if (machine__is_host(al->machine)) {
>  			al->cpumode = PERF_RECORD_MISC_KERNEL;
> @@ -1142,11 +1147,13 @@ static void free_callchain_node(struct callchain_node *node)
>  
>  	list_for_each_entry_safe(list, tmp, &node->parent_val, list) {
>  		list_del(&list->list);
> +		map__zput(list->ms.map);
>  		free(list);
>  	}
>  
>  	list_for_each_entry_safe(list, tmp, &node->val, list) {
>  		list_del(&list->list);
> +		map__zput(list->ms.map);
>  		free(list);
>  	}
>  
> @@ -1210,6 +1217,7 @@ int callchain_node__make_parent_list(struct callchain_node *node)
>  				goto out;
>  			*new = *chain;
>  			new->has_children = false;
> +			map__get(new->ms.map);
>  			list_add_tail(&new->list, &head);
>  		}
>  		parent = parent->parent;
> @@ -1230,6 +1238,7 @@ int callchain_node__make_parent_list(struct callchain_node *node)
>  out:
>  	list_for_each_entry_safe(chain, new, &head, list) {
>  		list_del(&chain->list);
> +		map__zput(chain->ms.map);
>  		free(chain);
>  	}
>  	return -ENOMEM;
> diff --git a/tools/perf/util/callchain.h b/tools/perf/util/callchain.h
> index d9c70dccf06a..f551fd2cfe5a 100644
> --- a/tools/perf/util/callchain.h
> +++ b/tools/perf/util/callchain.h
> @@ -5,6 +5,7 @@
>  #include <linux/list.h>
>  #include <linux/rbtree.h>
>  #include "event.h"
> +#include "map.h"
>  #include "symbol.h"
>  
>  #define HELP_PAD "\t\t\t\t"
> @@ -184,8 +185,13 @@ int callchain_merge(struct callchain_cursor *cursor,
>   */
>  static inline void callchain_cursor_reset(struct callchain_cursor *cursor)
>  {
> +	struct callchain_cursor_node *node;
> +
>  	cursor->nr = 0;
>  	cursor->last = &cursor->first;
> +
> +	for (node = cursor->first; node != NULL; node = node->next)
> +		map__zput(node->map);
>  }
>  
>  int callchain_cursor_append(struct callchain_cursor *cursor, u64 ip,
> diff --git a/tools/perf/util/hist.c b/tools/perf/util/hist.c
> index e1be4132054d..be4b07145705 100644
> --- a/tools/perf/util/hist.c
> +++ b/tools/perf/util/hist.c
> @@ -1,6 +1,7 @@
>  #include "util.h"
>  #include "build-id.h"
>  #include "hist.h"
> +#include "map.h"
>  #include "session.h"
>  #include "sort.h"
>  #include "evlist.h"
> @@ -979,6 +980,7 @@ iter_finish_cumulative_entry(struct hist_entry_iter *iter,
>  {
>  	zfree(&iter->priv);
>  	iter->he = NULL;
> +	map__zput(al->map);
>  
>  	return 0;
>  }


As part of trying to tie up the year-end loose-ends, I went back and
re-tested a rebase'd version of this patch against perf/core.  I ended
up with a merge that's identical to yours, except that I'm not seeing
any assertion failures with 'perf top -g', 'perf script', or 'perf
report'.  Was perf/core the branch that was giving you trouble?

-K

[toc] | [next] | [standalone]


#1549241

FromArnaldo Carvalho de Melo <acme@kernel.org>
Date2017-01-02 16:20 +0100
Message-ID<sVcyZ-gi-9@gated-at.bofh.it>
In reply to#1548170
Em Wed, Dec 28, 2016 at 05:39:47PM -0800, Krister Johansen escreveu:
> On Tue, Nov 22, 2016 at 04:01:06PM -0300, Arnaldo Carvalho de Melo wrote:
> >  #include "evlist.h"
> > @@ -979,6 +980,7 @@ iter_finish_cumulative_entry(struct hist_entry_iter *iter,
> >  {
> >  	zfree(&iter->priv);
> >  	iter->he = NULL;
> > +	map__zput(al->map);
 
> As part of trying to tie up the year-end loose-ends, I went back and
> re-tested a rebase'd version of this patch against perf/core.  I ended
> up with a merge that's identical to yours, except that I'm not seeing
> any assertion failures with 'perf top -g', 'perf script', or 'perf
> report'.  Was perf/core the branch that was giving you trouble?

Yeah, I just tested it with my tip/perf/core and got this:

     0.00%     0.00%  [kernel]                    [k] file_free_rcu
     0.00%     0.00%  [kernel]                    [k] timerqueue_del
     0.00%     0.00%  [kernel]                    [k] irq_work_run
     0.00%     0.00%  [kernel]                    [k] native_irq_return_iret
     0.00%     0.00%  [kernel]                    [k] native_sched_clock
perf: util/map.c:246: map__exit: Assertion
`!(!((&map->rb_node)->__rb_parent_color == (unsigned long)(&map->rb_node)))' failed.
                                                                                                                               Aborted
(core dumped)
[root@jouet 3.4]#

Tried it again with what is in Linus' tree + your patch and got the same
problem:

[acme@jouet linux]$ git remote -v | grep torvalds.*fetch
torvalds	git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git (fetch)
[acme@jouet linux]$ git checkout -b test-branch torvalds/master
Branch test-branch set up to track remote branch master from torvalds.
Switched to a new branch 'test-branch'
[acme@jouet linux]$ git cherry-pick f7347a33099dbad7e9fb3c22cea211f238bfd320
[test-branch 7d786f548b62] perf callchain: Fix a use after free crash due to refcounting bug
 Author: Krister Johansen <kjlx@templeofstupid.com>
 Date: Mon Jan 2 12:06:55 2017 -0300
 3 files changed, 19 insertions(+), 2 deletions(-)
[acme@jouet linux]$ rm -rf /tmp/build/perf/ ; mkdir -p /tmp/build/perf ; make O=/tmp/build/perf -C tools/perf install-bin
make: Entering directory '/home/acme/git/linux/tools/perf'
  BUILD:   Doing 'make -j4' parallel build
  HOSTCC   /tmp/build/perf/fixdep.o
<SNIP>

Then I run it with a higher frequency and no delay in refreshing the screen, to
stress the refcounting code:

# perf top -F 10000 -g -d 0

Do it while running something like 'make -j32 allmodconfig' to create lots of
short lived processes (or use stress-ng, etc).

+    0.79%     0.00%  [kernel]                    [k] search_binary_handler
+    0.79%     0.00%  [kernel]                    [k] do_execveat_common.isra.37
+    0.79%     0.00%  [kernel]                    [k] sys_execve
+    0.79%     0.00%  [kernel]                    [k] do_syscall_64
perf: util/map.c:246: map__exit: Assertion `!(!((&map->rb_node)->__rb_parent_color == (unsigned long)(&map->rb_node)))' failed.
                                                                                                                               Aborted (core dumped)
[root@jouet 3.4]# 

- Arnaldo

[toc] | [prev] | [next] | [standalone]


#1549322

FromArnaldo Carvalho de Melo <acme@kernel.org>
Date2017-01-02 18:40 +0100
Message-ID<sVeKu-1QB-9@gated-at.bofh.it>
In reply to#1549241
Em Mon, Jan 02, 2017 at 12:15:14PM -0300, Arnaldo Carvalho de Melo escreveu:
> Tried it again with what is in Linus' tree + your patch and got the same
> problem:
> 
> [acme@jouet linux]$ git remote -v | grep torvalds.*fetch
> torvalds	git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git (fetch)
> [acme@jouet linux]$ git checkout -b test-branch torvalds/master
> Branch test-branch set up to track remote branch master from torvalds.
> Switched to a new branch 'test-branch'
> [acme@jouet linux]$ git cherry-pick f7347a33099dbad7e9fb3c22cea211f238bfd320
> [test-branch 7d786f548b62] perf callchain: Fix a use after free crash due to refcounting bug
>  Author: Krister Johansen <kjlx@templeofstupid.com>
>  Date: Mon Jan 2 12:06:55 2017 -0300
>  3 files changed, 19 insertions(+), 2 deletions(-)
> [acme@jouet linux]$ rm -rf /tmp/build/perf/ ; mkdir -p /tmp/build/perf ; make O=/tmp/build/perf -C tools/perf install-bin
> make: Entering directory '/home/acme/git/linux/tools/perf'
>   BUILD:   Doing 'make -j4' parallel build
>   HOSTCC   /tmp/build/perf/fixdep.o
> <SNIP>
> 
> Then I run it with a higher frequency and no delay in refreshing the screen, to
> stress the refcounting code:
> 
> # perf top -F 10000 -g -d 0
> 
> Do it while running something like 'make -j32 allmodconfig' to create lots of
> short lived processes (or use stress-ng, etc).

Back to acme/perf/core and with debugging, we're getting a refcount hitting zero
while the map is still in a rbtree:

perf: util/map.c:246: map__exit: Assertion `!(!((&map->rb_node)->__rb_parent_color == (unsigned long)(&map->rb_node)))' failed.

                                                                                                                               Thread 1 "perf" received signal SIGABRT, Aborted.
                  0x00007ffff522691f in raise () from /lib64/libc.so.6
(gdb) bt
#0  0x00007ffff522691f in raise () from /lib64/libc.so.6
#1  0x00007ffff522851a in abort () from /lib64/libc.so.6
#2  0x00007ffff521eda7 in __assert_fail_base () from /lib64/libc.so.6
#3  0x00007ffff521ee52 in __assert_fail () from /lib64/libc.so.6
#4  0x0000000000504e57 in map__exit (map=0x2393790) at util/map.c:246
#5  0x0000000000504ea5 in map__delete (map=0x2393790) at util/map.c:252
#6  0x0000000000504f0a in map__put (map=0x2393790) at util/map.c:259
#7  0x000000000052fa01 in __map__zput (map=0x7fffffff8230) at util/map.h:161
#8  0x000000000053295b in iter_finish_cumulative_entry (iter=0x7fffffff8260, al=0x7fffffff8220) at util/hist.c:983
#9  0x0000000000532b53 in hist_entry_iter__add (iter=0x7fffffff8260, al=0x7fffffff8220, max_stack_depth=127, arg=0x7fffffffa7b0) at util/hist.c:1059
#10 0x000000000044f5cf in perf_event__process_sample (tool=0x7fffffffa7b0, event=0x7ffff7e24578, evsel=0x21515d0, sample=0x7fffffff8410, machine=0x21b2bf8)
    at builtin-top.c:774
#11 0x000000000044f8ee in perf_top__mmap_read_idx (top=0x7fffffffa7b0, idx=2) at builtin-top.c:840
#12 0x000000000044fa0d in perf_top__mmap_read (top=0x7fffffffa7b0) at builtin-top.c:857
#13 0x0000000000450080 in __cmd_top (top=0x7fffffffa7b0) at builtin-top.c:1002
#14 0x00000000004514e0 in cmd_top (argc=0, argv=0x7fffffffe130, prefix=0x0) at builtin-top.c:1330
#15 0x00000000004b5af5 in run_builtin (p=0xa0baf8 <commands+312>, argc=6, argv=0x7fffffffe130) at perf.c:358
#16 0x00000000004b5d62 in handle_internal_command (argc=6, argv=0x7fffffffe130) at perf.c:420
#17 0x00000000004b5ea7 in run_argv (argcp=0x7fffffffdf8c, argv=0x7fffffffdf80) at perf.c:466
#18 0x00000000004b6290 in main (argc=6, argv=0x7fffffffe130) at perf.c:610
(gdb) fr 4
#4  0x0000000000504e57 in map__exit (map=0x2393790) at util/map.c:246
246		BUG_ON(!RB_EMPTY_NODE(&map->rb_node));
(gdb) p map
$1 = (struct map *) 0x2393790
(gdb) p *map
$2 = {{rb_node = {__rb_parent_color = 37304353, rb_right = 0x0, rb_left = 0x0}, node = {next = 0x2393821, prev = 0x0}}, start = 140434683187200, 
  end = 140434690723840, type = 0 '\000', erange_warned = false, priv = 0, prot = 5, flags = 2, pgoff = 0, reloc = 0, maj = 253, min = 0, ino = 132875, 
  ino_generation = 3472328296227680304, map_ip = 0x504125 <map__map_ip>, unmap_ip = 0x504174 <map__unmap_ip>, dso = 0x22b3890, groups = 0x2385290, refcnt = {
    counter = 0}}
(gdb)

[toc] | [prev] | [next] | [standalone]


#1549325

FromArnaldo Carvalho de Melo <acme@kernel.org>
Date2017-01-02 18:40 +0100
Message-ID<sVeKu-1QB-17@gated-at.bofh.it>
In reply to#1549322
Em Mon, Jan 02, 2017 at 02:35:30PM -0300, Arnaldo Carvalho de Melo escreveu:
> Em Mon, Jan 02, 2017 at 12:15:14PM -0300, Arnaldo Carvalho de Melo escreveu:
> > Tried it again with what is in Linus' tree + your patch and got the same
> > problem:
> > 
> > [acme@jouet linux]$ git remote -v | grep torvalds.*fetch
> > torvalds	git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git (fetch)
> > [acme@jouet linux]$ git checkout -b test-branch torvalds/master
> > Branch test-branch set up to track remote branch master from torvalds.
> > Switched to a new branch 'test-branch'
> > [acme@jouet linux]$ git cherry-pick f7347a33099dbad7e9fb3c22cea211f238bfd320
> > [test-branch 7d786f548b62] perf callchain: Fix a use after free crash due to refcounting bug
> >  Author: Krister Johansen <kjlx@templeofstupid.com>
> >  Date: Mon Jan 2 12:06:55 2017 -0300
> >  3 files changed, 19 insertions(+), 2 deletions(-)
> > [acme@jouet linux]$ rm -rf /tmp/build/perf/ ; mkdir -p /tmp/build/perf ; make O=/tmp/build/perf -C tools/perf install-bin
> > make: Entering directory '/home/acme/git/linux/tools/perf'
> >   BUILD:   Doing 'make -j4' parallel build
> >   HOSTCC   /tmp/build/perf/fixdep.o
> > <SNIP>
> > 
> > Then I run it with a higher frequency and no delay in refreshing the screen, to
> > stress the refcounting code:
> > 
> > # perf top -F 10000 -g -d 0
> > 
> > Do it while running something like 'make -j32 allmodconfig' to create lots of
> > short lived processes (or use stress-ng, etc).
> 
> Back to acme/perf/core and with debugging, we're getting a refcount hitting zero
> while the map is still in a rbtree:

And this was introduced by your patch:

diff --git a/tools/perf/util/hist.c b/tools/perf/util/hist.c
index 6770a9645609..72f5c82798e9 100644
--- a/tools/perf/util/hist.c
+++ b/tools/perf/util/hist.c
@@ -1,6 +1,7 @@
 #include "util.h"
 #include "build-id.h"
 #include "hist.h"
+#include "map.h"
 #include "session.h"
 #include "sort.h"
 #include "evlist.h"
@@ -979,6 +980,7 @@ iter_finish_cumulative_entry(struct hist_entry_iter *iter,
 {
        zfree(&iter->priv);
        iter->he = NULL;
+       map__zput(al->map);
 
        return 0;
 }
 
> perf: util/map.c:246: map__exit: Assertion `!(!((&map->rb_node)->__rb_parent_color == (unsigned long)(&map->rb_node)))' failed.
> 
>                                                                                                                                Thread 1 "perf" received signal SIGABRT, Aborted.
>                   0x00007ffff522691f in raise () from /lib64/libc.so.6
> (gdb) bt
> #0  0x00007ffff522691f in raise () from /lib64/libc.so.6
> #1  0x00007ffff522851a in abort () from /lib64/libc.so.6
> #2  0x00007ffff521eda7 in __assert_fail_base () from /lib64/libc.so.6
> #3  0x00007ffff521ee52 in __assert_fail () from /lib64/libc.so.6
> #4  0x0000000000504e57 in map__exit (map=0x2393790) at util/map.c:246
> #5  0x0000000000504ea5 in map__delete (map=0x2393790) at util/map.c:252
> #6  0x0000000000504f0a in map__put (map=0x2393790) at util/map.c:259
> #7  0x000000000052fa01 in __map__zput (map=0x7fffffff8230) at util/map.h:161
> #8  0x000000000053295b in iter_finish_cumulative_entry (iter=0x7fffffff8260, al=0x7fffffff8220) at util/hist.c:983
> #9  0x0000000000532b53 in hist_entry_iter__add (iter=0x7fffffff8260, al=0x7fffffff8220, max_stack_depth=127, arg=0x7fffffffa7b0) at util/hist.c:1059
> #10 0x000000000044f5cf in perf_event__process_sample (tool=0x7fffffffa7b0, event=0x7ffff7e24578, evsel=0x21515d0, sample=0x7fffffff8410, machine=0x21b2bf8)
>     at builtin-top.c:774
> #11 0x000000000044f8ee in perf_top__mmap_read_idx (top=0x7fffffffa7b0, idx=2) at builtin-top.c:840
> #12 0x000000000044fa0d in perf_top__mmap_read (top=0x7fffffffa7b0) at builtin-top.c:857
> #13 0x0000000000450080 in __cmd_top (top=0x7fffffffa7b0) at builtin-top.c:1002
> #14 0x00000000004514e0 in cmd_top (argc=0, argv=0x7fffffffe130, prefix=0x0) at builtin-top.c:1330
> #15 0x00000000004b5af5 in run_builtin (p=0xa0baf8 <commands+312>, argc=6, argv=0x7fffffffe130) at perf.c:358
> #16 0x00000000004b5d62 in handle_internal_command (argc=6, argv=0x7fffffffe130) at perf.c:420
> #17 0x00000000004b5ea7 in run_argv (argcp=0x7fffffffdf8c, argv=0x7fffffffdf80) at perf.c:466
> #18 0x00000000004b6290 in main (argc=6, argv=0x7fffffffe130) at perf.c:610
> (gdb) fr 4
> #4  0x0000000000504e57 in map__exit (map=0x2393790) at util/map.c:246
> 246		BUG_ON(!RB_EMPTY_NODE(&map->rb_node));
> (gdb) p map
> $1 = (struct map *) 0x2393790
> (gdb) p *map
> $2 = {{rb_node = {__rb_parent_color = 37304353, rb_right = 0x0, rb_left = 0x0}, node = {next = 0x2393821, prev = 0x0}}, start = 140434683187200, 
>   end = 140434690723840, type = 0 '\000', erange_warned = false, priv = 0, prot = 5, flags = 2, pgoff = 0, reloc = 0, maj = 253, min = 0, ino = 132875, 
>   ino_generation = 3472328296227680304, map_ip = 0x504125 <map__map_ip>, unmap_ip = 0x504174 <map__unmap_ip>, dso = 0x22b3890, groups = 0x2385290, refcnt = {
>     counter = 0}}
> (gdb)

[toc] | [prev] | [next] | [standalone]


#1549370

FromArnaldo Carvalho de Melo <acme@kernel.org>
Date2017-01-02 20:50 +0100
Message-ID<sVgMh-3mY-9@gated-at.bofh.it>
In reply to#1549325
Em Mon, Jan 02, 2017 at 02:36:57PM -0300, Arnaldo Carvalho de Melo escreveu:
> Em Mon, Jan 02, 2017 at 02:35:30PM -0300, Arnaldo Carvalho de Melo escreveu:
> > Em Mon, Jan 02, 2017 at 12:15:14PM -0300, Arnaldo Carvalho de Melo escreveu:
>  {
>         zfree(&iter->priv);
>         iter->he = NULL;
> +       map__zput(al->map);

What this pairs to? I was expecting that since this is called via:

   hist_entry_iter__add()
   {
           <SNIP>
           err2 = iter->ops->finish_entry(iter, al);
   }

Then it would have to match something done earlier in
hist_entry_iter__add(), most likely by some iter->ops->() method, but I
couldn'd find anything to that extent, can you clarify?

- Arnaldo
  
>         return 0;
>  }
>  
> > perf: util/map.c:246: map__exit: Assertion `!(!((&map->rb_node)->__rb_parent_color == (unsigned long)(&map->rb_node)))' failed.
> > 
> >                                                                                                                                Thread 1 "perf" received signal SIGABRT, Aborted.
> >                   0x00007ffff522691f in raise () from /lib64/libc.so.6
> > (gdb) bt
> > #0  0x00007ffff522691f in raise () from /lib64/libc.so.6
> > #1  0x00007ffff522851a in abort () from /lib64/libc.so.6
> > #2  0x00007ffff521eda7 in __assert_fail_base () from /lib64/libc.so.6
> > #3  0x00007ffff521ee52 in __assert_fail () from /lib64/libc.so.6
> > #4  0x0000000000504e57 in map__exit (map=0x2393790) at util/map.c:246
> > #5  0x0000000000504ea5 in map__delete (map=0x2393790) at util/map.c:252
> > #6  0x0000000000504f0a in map__put (map=0x2393790) at util/map.c:259
> > #7  0x000000000052fa01 in __map__zput (map=0x7fffffff8230) at util/map.h:161
> > #8  0x000000000053295b in iter_finish_cumulative_entry (iter=0x7fffffff8260, al=0x7fffffff8220) at util/hist.c:983
> > #9  0x0000000000532b53 in hist_entry_iter__add (iter=0x7fffffff8260, al=0x7fffffff8220, max_stack_depth=127, arg=0x7fffffffa7b0) at util/hist.c:1059
> > #10 0x000000000044f5cf in perf_event__process_sample (tool=0x7fffffffa7b0, event=0x7ffff7e24578, evsel=0x21515d0, sample=0x7fffffff8410, machine=0x21b2bf8)
> >     at builtin-top.c:774
> > #11 0x000000000044f8ee in perf_top__mmap_read_idx (top=0x7fffffffa7b0, idx=2) at builtin-top.c:840
> > #12 0x000000000044fa0d in perf_top__mmap_read (top=0x7fffffffa7b0) at builtin-top.c:857
> > #13 0x0000000000450080 in __cmd_top (top=0x7fffffffa7b0) at builtin-top.c:1002
> > #14 0x00000000004514e0 in cmd_top (argc=0, argv=0x7fffffffe130, prefix=0x0) at builtin-top.c:1330
> > #15 0x00000000004b5af5 in run_builtin (p=0xa0baf8 <commands+312>, argc=6, argv=0x7fffffffe130) at perf.c:358
> > #16 0x00000000004b5d62 in handle_internal_command (argc=6, argv=0x7fffffffe130) at perf.c:420
> > #17 0x00000000004b5ea7 in run_argv (argcp=0x7fffffffdf8c, argv=0x7fffffffdf80) at perf.c:466
> > #18 0x00000000004b6290 in main (argc=6, argv=0x7fffffffe130) at perf.c:610
> > (gdb) fr 4
> > #4  0x0000000000504e57 in map__exit (map=0x2393790) at util/map.c:246
> > 246		BUG_ON(!RB_EMPTY_NODE(&map->rb_node));
> > (gdb) p map
> > $1 = (struct map *) 0x2393790
> > (gdb) p *map
> > $2 = {{rb_node = {__rb_parent_color = 37304353, rb_right = 0x0, rb_left = 0x0}, node = {next = 0x2393821, prev = 0x0}}, start = 140434683187200, 
> >   end = 140434690723840, type = 0 '\000', erange_warned = false, priv = 0, prot = 5, flags = 2, pgoff = 0, reloc = 0, maj = 253, min = 0, ino = 132875, 
> >   ino_generation = 3472328296227680304, map_ip = 0x504125 <map__map_ip>, unmap_ip = 0x504174 <map__unmap_ip>, dso = 0x22b3890, groups = 0x2385290, refcnt = {
> >     counter = 0}}
> > (gdb)

[toc] | [prev] | [next] | [standalone]


#1549475

FromArnaldo Carvalho de Melo <acme@kernel.org>
Date2017-01-03 01:40 +0100
Message-ID<sVliW-6vr-13@gated-at.bofh.it>
In reply to#1549370
Em Mon, Jan 02, 2017 at 04:39:04PM -0300, Arnaldo Carvalho de Melo escreveu:
> Em Mon, Jan 02, 2017 at 02:36:57PM -0300, Arnaldo Carvalho de Melo escreveu:
> > Em Mon, Jan 02, 2017 at 02:35:30PM -0300, Arnaldo Carvalho de Melo escreveu:
> > > Em Mon, Jan 02, 2017 at 12:15:14PM -0300, Arnaldo Carvalho de Melo escreveu:
> >  {
> >         zfree(&iter->priv);
> >         iter->he = NULL;
> > +       map__zput(al->map);
> 
> What this pairs to? I was expecting that since this is called via:
> 
>    hist_entry_iter__add()
>    {
>            <SNIP>
>            err2 = iter->ops->finish_entry(iter, al);
>    }
> 
> Then it would have to match something done earlier in
> hist_entry_iter__add(), most likely by some iter->ops->() method, but I
> couldn'd find anything to that extent, can you clarify?

With the following patch it has been running all day, care to explain
why it is needed? I need to run this on valgrind or with Masami's
refcount debugger to get more clues :-\

- Arnaldo

diff --git a/tools/perf/util/hist.c b/tools/perf/util/hist.c
index 72f5c82798e9..c27bda16e9cd 100644
--- a/tools/perf/util/hist.c
+++ b/tools/perf/util/hist.c
@@ -980,7 +980,6 @@ iter_finish_cumulative_entry(struct hist_entry_iter *iter,
 {
 	zfree(&iter->priv);
 	iter->he = NULL;
-	map__zput(al->map);
 
 	return 0;
 }

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web