Commit 22098763a10d for kernel

commit 22098763a10d9c1340827fcf6edab66f153b27f0
Merge: d681d7ef617e d860c67c0516
Author: Linus Torvalds <torvalds@linux-foundation.org>
Date:   Sun Sep 13 12:27:00 2026 -0700

    Merge tag 'trace-v7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace

    Pull tracing fixes from Steven Rostedt:

     - Don't destroy user event fields when removal fails

       User event fields are destroyed before the event is removed from
       visibility. But that can fail leaving the still visible event with no
       fields. Move the destroying of the fields to after the event is
       successfully removed from visibility.

     - Initialize function graph state is fork before calling
       copy_exec_state()

       For non-CLONE_VM forks, copy_exec_state() allocates a new
       task_exec_state. If that allocation fails, ftrace_graph_exit_task()
       will free the tasks ret_stack pointer. Since that pointer is still
       using the parent's ret_stack, it mistakenly frees the parent's
       pointer too.

       Call ftrace_graph_init() on the task first which will NULL out the
       new tasks's ret_stack and if the copy fails, it will not free
       anything.

     - Remove FGRAPH_MAX_INDEX

       The macro FGRAPH_MAX_INDEX was added but never used. Remove it.

     - Save ent_size in function graph printing of nested functions

       The function graph tracer needs to look at the next event to see if
       the next event is the return of the current function entry. If it is,
       it prints a single line:

            ktime_get();

       Otherwise it prints it like a nested function:

            tick_nohz_irq_exit() {
                ktime_get();
                kcpustat_irq_exit();
            }

       In order to look at the next event, it must save the current event so
       that it has the information to print from it. It saves the event in
       the iterator descriptor called "ent". What it doesn't save is the
       ent_size of the event which is now used to know if the function graph
       arguments are to be printed. The peek doesn't save the size so the
       size used happens to be that of the size of the last event that was
       seen.

       Save the entry event size in the iterator descriptor so that the
       correct size is used.

     - Fix several errors with freeing data in the histogram code

       The histogram code had a lot of leaked or or incorrect accounting
       when failures happen. Correct them.

     - Fix histogram regression of .percent and .graph modifiers

       Up until 6.3 histogram values could have "percent" or "graph"
       modifiers that changed how they were printed. But a change that added
       restricting histograms values from being strings, stack traces and
       other modifiers inadvertently prevented them from using the percent
       and graph modifiers, which were legal use cases for values.

       Put back the percent and graph modifiers.

     - Fix various typos in the comments

     - Set the trace_clock before initializing a histogram with clock
       argument

       The histogram API allows the user to specific which trace clock to
       use via a "clock=" string. The histogram is set up first before the
       clock is checked. If the passed in clock is not valid, it exits
       without fully fixing up the histogram leaving it on the list and a
       use-after-free can trigger.

       Update the clock argument first and if it fails then exit gracefully
       before the histogram trigger is placed on any lists.

     - Restore :mod: trailer after parsing in ftrace_set_clr_event

       The function ftrace_set_clr_event() modifies the parse string and
       needs to put it back to what was passed in. It searches for ":mod:"
       via a strsep() but fails to put back the first ':' in the string.

       Add back the ':' in the passed in string.

     - Take trace_array reference when opening a tracer options file

       The options files are dynamically created and some tracers add their
       own options. When a tracer adds their own list of options, the
       trace_array holding them has an array to hold the list of options for
       each tracer. This array increases in size via a krealloc(), and the
       new entry gets a newly allocated array to hold the options of the new
       tracer being added.

       The element in each entry of the tracer's option array holds a
       pointer back to the trace_array, a pointer to the tracer it is
       associated to, a pointer to the flags of the option.

       The issue is that these arrays are freed when the trace_array is
       freed when its instance it represents is removed from the instances
       directory. There's a race that an open of one of these options files
       can happen when the instance is being removed.

       Add a new helper function to be called by the open function of the
       options file to iterate all existing trace_arrays under a lock and
       find the one that has the given option element in one of it's tracer
       arrays. If found, then update the associated trace_array's reference
       counter to keep it from being freed. If not found, have the open call
       return -ENODEV.

     - Disable interrupts when acquiring the lock in rb_wake_up_waiters()

       The function rb_wake_up_waiters() assumes it will be called in
       interrupt context and does not disable irqs when taking
       cpu_buffer->reader_lock, which can be called in hard interrupt
       context. The issue is in PREEMPT_RT, this function is called in
       thread context leaving this lock open to a deadlock.

       Take the lock with interrupts disabled.

     - Use rcu_assign_pointer() for tmp_ops filter hash

       The tmp_ops used in update_ftrace_direct_mod() assigns its
       filter_hash field directly, but that field is annotated as __rcu and
       sparse complains. Assign it with rcu_assign_pointer()

     - Fix use-after-free in enable_trigger_private_data_free()

       The trace_event_call is accessed through the event_trigger_data's
       trace_event_file pointer to put the trace_event_call on freeing. The
       issue is that the trace_event_file data may have been freed already
       causing a use-after-free. Add a field to the event_trigger_data that
       points directly to the trace_event_call so that it can decrement its
       reference directly without needing to go through the
       trace_event_file.

     - Fix accounting of buffer data remote headers

       trace_buffer_desc_size() and trace_remote_alloc_buffer() undercount
       the number of pages is needed for the asked for size as it doesn't
       take into account the meta data on each page. Add a helper function
       to do the calculation properly and use that in these functions.

     - Catch nr_page_va overflow in ring_buffer_desc sizing

       The number of pages per remote ring buffer is capped by
       ring_buffer_desc::nr_page_va (32 bits). A buffer_size large enough to
       overflow that field would silently allocate a descriptor smaller than
       what was asked for.

     - Do not resize the subbuf order if any per_cpu buffer is disabled

       The mmapping of ring buffers disables resizing the subbuffers, but it
       is done per-cpu whereas the subbuf size change is done for all the
       per_cpu buffers under the buffer->mutex. It could change the size of
       some while the mapping is happening on others. Have the resize of the
       subbuf order check all the per_cpu buffers under the lock to see if
       any of them is disabled before starting and causing an inconsistency
       between buffers that are being mapped.

    * tag 'trace-v7.3-rc2' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace: (25 commits)
      ring-buffer: Check resize_disabled before publishing the new subbuf order
      tracing/remotes: Catch nr_page_va overflow in ring_buffer_desc sizing
      tracing/remotes: Account for ring buffer page header in size calculation
      tracing: Don't dereference trace_event_file in deferred trigger free
      ftrace: Use rcu_assign_pointer() for tmp_ops filter hash
      ring-buffer: Acquire the lock with irqsave in rb_wake_up_waiters()
      tracing: Take trace_array reference when opening a tracer options file
      tracing: Fix ring_buffer_read_page_size() kernel-doc
      tracing: Restore :mod: trailer after parsing in ftrace_set_clr_event()
      tracing: Fix memory corruption from a "STACKTRACE" histogram key
      tracing: Fix memory corruption from the histogram stacktrace modifier
      tracing: Undo the registration when enabling the histogram trigger fails
      tracing: Take the reference before publishing the named histogram trigger
      tracing: Set the trace clock before registering the histogram trigger
      tracing: Fix typo "preceeded" in comment
      tracing: Fix typo "availabe" in comment
      tracing: Let histogram values keep the percent and graph modifiers
      tracing: Keep the entry count when the histogram stats allocation fails
      tracing: Free histogram the field rejected for a bad modifier
      tracing: Free histogram the var ref when its initialization fails
      ...