Jiri,

Because you now run queued_events__queue() lockless with that condvar
trick, it is possible for top->qe.in to be seen as one past the data[]
array, this is because the rotate_queues() code goes:

        if (++top->qe.in > &top->qe.data[1])
                top->qe.in = &top->qe.data[0];

So for a brief moment top->qe.in is out of range and thus
perf_top__mmap_read_idx() can try to enqueue to top->qe.data[2]

We can just do:

        if (top->qe.in == &top->qe.data[1])
                top->qe.in = &top->qe.data[0];
        else
                top->qe.in = &top->qe.data[1];

Or, make top->qe.in an index, and simply go:

        top->qe.in ^= 1;

Either way will fix the bug.

Reply via email to