On Fri, 17 Jul 2026 10:32:52 -0700
Usama Arif <[email protected]> wrote:

> trace_user_fault_read() samples nr_context_switches_cpu() before enabling
> preemption and retries the user copy if the counter changes. The helper
> returns unsigned long long because rq->nr_switches is u64, but the saved
> value is unsigned int.
> 
> Once a CPU has performed 2^32 context switches, assigning the counter to
> cnt discards its upper bits. The comparison after the copy promotes cnt
> back to unsigned long long, but the lost bits remain zero, so it reports a
> change even when the task was never scheduled out. Every retry then fails
> the same way until the 100-try guard warns and the user copy is abandoned.
> 
> This affects long-running systems and workloads with high context-switch
> rates. A CPU switching 1,000 times per second takes about 50 days.
> 
> Store the sampled count in unsigned long long so the full value is
> preserved.

Looks good to me.

Acked-by: Masami Hiramatsu (Google) <[email protected]>

Thanks!

> 
> Fixes: 64cf7d058a00 ("tracing: Have trace_marker use per-cpu data to read 
> user space")
> Cc: [email protected]
> Reported-by: Breno Leitao <[email protected]>
> Signed-off-by: Usama Arif <[email protected]>
> ---
>  kernel/trace/trace.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/kernel/trace/trace.c b/kernel/trace/trace.c
> index 1146b83b711a..412a8daf2162 100644
> --- a/kernel/trace/trace.c
> +++ b/kernel/trace/trace.c
> @@ -6188,7 +6188,7 @@ char *trace_user_fault_read(struct trace_user_buf_info 
> *tinfo,
>  {
>       int cpu = smp_processor_id();
>       char *buffer = per_cpu_ptr(tinfo->tbuf, cpu)->buf;
> -     unsigned int cnt;
> +     unsigned long long cnt;
>       int trys = 0;
>       int ret;
>  
> -- 
> 2.53.0-Meta
> 


-- 
Masami Hiramatsu (Google) <[email protected]>

Reply via email to