All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Paul E. McKenney" <paulmck@kernel.org>
To: rcu@vger.kernel.org
Cc: linux-kernel@vger.kernel.org, kernel-team@meta.com,
	rostedt@goodmis.org, "Paul E. McKenney" <paulmck@kernel.org>
Subject: [PATCH RFC 08/10] rcu-tasks: Fix IRQ read lock/unlock data race
Date: Thu, 30 Jul 2026 18:03:59 -0700	[thread overview]
Message-ID: <20260731010401.3531631-8-paulmck@kernel.org> (raw)
In-Reply-To: <c50fb3e6-8d9f-4311-953e-a4703ba1e863@paulmck-laptop>

As noted by Marco Elver:

rcu_read_lock_trace()
   ....
t->trc_reader_scp = __srcu_read_lock_fast(&rcu_tasks_trace_srcu_struct);
	<interrupt>
					rcu_read_unlock_trace()
					< ... var decls only ... >
					scp = t->trc_reader_scp;

This constitutes a data race between these two accesses to
t->trc_reader_scp.  If rcu_read_lock_trace() were to tear its store,
this value would be corrupted.

This commit therefore defers the rcu_read_lock_untrace() function's
load from t->trc_reader_scp until after it has verified that this is
the outermost rcu_read_unlock_trace().  With this change, the interrupt
handler increments and decrements t->trc_reader_nesting and does not
access t->trc_reader_scp, thus avoiding the data race.

KCSAN located this issue.

Signed-off-by: Paul E. McKenney <paulmck@kernel.org>
---
 include/linux/rcupdate_trace.h | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/include/linux/rcupdate_trace.h b/include/linux/rcupdate_trace.h
index fd3ddeb6aa3bd2..70decf877348a6 100644
--- a/include/linux/rcupdate_trace.h
+++ b/include/linux/rcupdate_trace.h
@@ -126,11 +126,13 @@ static inline void rcu_read_unlock_trace(void)
 	struct srcu_ctr __percpu *scp;
 	struct task_struct *t = current;
 
-	scp = t->trc_reader_scp;
-	barrier();  // scp before nesting to protect against interrupt handler.
 	n = READ_ONCE(t->trc_reader_nesting) - 1;
-	WRITE_ONCE(t->trc_reader_nesting, n);
-	if (!n) {
+	if (n) {
+		WRITE_ONCE(t->trc_reader_nesting, n);
+	} else {
+		scp = t->trc_reader_scp; // Compiler cannot hoist load due to data raciness.
+		barrier();  // scp before nesting to protect against interrupt handler.
+		WRITE_ONCE(t->trc_reader_nesting, n);
 		if (!IS_ENABLED(CONFIG_TASKS_TRACE_RCU_NO_MB))
 			smp_mb(); // Placeholder for more selective ordering
 		__srcu_read_unlock_fast(&rcu_tasks_trace_srcu_struct, scp);
-- 
2.40.1


  parent reply	other threads:[~2026-07-31  1:04 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-31  1:03 [PATCH 0/10] RCU Tasks updates for v7.3 Paul E. McKenney
2026-07-31  1:03 ` [PATCH RFC 01/10] rcu-tasks: TASKS_TRACE_RCU doesn't need IRQ_WORK Paul E. McKenney
2026-07-31  1:03 ` [PATCH RFC 02/10] rcu-tasks: Remove unused struct rcu_tasks's->n_ipis_fails variables Paul E. McKenney
2026-07-31  1:03 ` [PATCH RFC 03/10] rcu-tasks: Dump rcu tasks status when the boot-test failed Paul E. McKenney
2026-07-31  1:03 ` [PATCH RFC 04/10] rcu-tasks: Apply READ_ONCE() and WRITE_ONCE() to fix data race Paul E. McKenney
2026-07-31  1:03 ` [PATCH RFC 05/10] rcu-tasks: Remove smp_mb() in rcu_spawn_tasks_kthread_generic() Paul E. McKenney
2026-07-31  1:03 ` [PATCH RFC 06/10] rcu-tasks: Update comments in call_rcu_tasks_generic() Paul E. McKenney
2026-07-31  1:03 ` [PATCH RFC 07/10] rcu-tasks: Dump rtpcp->lazy_timer status in show_rcu_tasks_generic_gp_kthread() Paul E. McKenney
2026-07-31  1:03 ` Paul E. McKenney [this message]
2026-07-31  1:04 ` [PATCH RFC 09/10] rcu-tasks: Rename tasks_rcu_exit_srcu_stall_timer to tasks_rcu_exit_stall_timer Paul E. McKenney
2026-07-31  1:04 ` [PATCH RFC 10/10] rcu-tasks: Fix some comments for call_rcu_tasks() and call_rcu_tasks_rude() Paul E. McKenney

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260731010401.3531631-8-paulmck@kernel.org \
    --to=paulmck@kernel.org \
    --cc=kernel-team@meta.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=rcu@vger.kernel.org \
    --cc=rostedt@goodmis.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.