All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Josef Bacik" <josef@toxicpanda.com>
Cc: bpf@vger.kernel.org, linux-trace-kernel@vger.kernel.org
Subject: Re: [PATCH RFC v3 03/13] rcu-tasks: Add a Tasks RCU implementation for reader-marked trampolines
Date: Tue, 15 Sep 2026 13:29:19 +0000	[thread overview]
Message-ID: <20260915132919.E868D1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260915-b4-rcu-tasks-preempt-qs-v3-3-0ad30c4c5ee7@toxicpanda.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] rcu-tasks: Use-after-free in trampolines executed by the idle task
--

commit 4dc15eb660eecbf1c68e4f2d97dcdde7b8456c35
Author: Josef Bacik <josef@toxicpanda.com>

    rcu-tasks: Add a Tasks RCU implementation for reader-marked trampolines

    Tasks RCU waits for every task to pass through a voluntary context switch,
    usermode or idle, because a preempted task might be sitting in a trampoline
    that is about to be freed and nothing marks it as such. This adds a new
    Tasks RCU implementation for architectures that make their trampolines Tasks
    Trace RCU readers.

> diff --git a/kernel/entry/common.c b/kernel/entry/common.c
> index e4acd50bd81a1..94318519998c8 100644
> --- a/kernel/entry/common.c
> +++ b/kernel/entry/common.c
> @@ -141,8 +142,13 @@ void raw_irqentry_exit_cond_resched(struct pt_regs *regs)
>  		rcu_irq_exit_check_preempt();
>  		if (IS_ENABLED(CONFIG_DEBUG_ENTRY))
>  			WARN_ON_ONCE(!on_thread_stack());
> -		if (need_resched() && arch_irqentry_exit_need_resched())
> +		if (need_resched() && arch_irqentry_exit_need_resched()) {
> +			if (IS_ENABLED(CONFIG_TASKS_RCU_TRAMPOLINE_READERS))
> +				rcu_tasks_irq_resched_enter(instruction_pointer(regs));

[Severity: High]
Does this logic leave the idle task off the holdout list if it is
interrupted while executing trampoline text?

If an IRQ interrupts the idle task (for example, while executing a traced
function before entering an RCU extended quiescent state) and enters the
trampoline's unmarked preamble, but does not wake any new tasks,
need_resched() will be false.

Because need_resched() is false, raw_irqentry_exit_cond_resched() will not
call rcu_tasks_irq_resched_enter(), meaning the idle task is never added to
the holdout list.

>  			preempt_schedule_irq();
> +			if (IS_ENABLED(CONFIG_TASKS_RCU_TRAMPOLINE_READERS))
> +				rcu_tasks_irq_resched_exit();
> +		}
>  	}
>  }

[ ... ]

> diff --git a/kernel/rcu/tasks.h b/kernel/rcu/tasks.h
> index 627295396cd91..3a7c092361a66 100644
> --- a/kernel/rcu/tasks.h
> +++ b/kernel/rcu/tasks.h

[ ... ]

> +/* Has @cpu passed a quiescent event since the snapshot, or need it not? */
> +static bool rcu_tasks_cpu_quiescent(int cpu)
> +{
> +	if (!cpu_online(cpu))
> +		return true;
> +	/* Pairs with the release in rcu_tasks_qs_event(). */
> +	if (smp_load_acquire(per_cpu_ptr(&rcu_tasks_qs_seq, cpu)) !=
> +	    per_cpu(rcu_tasks_qs_snap, cpu))
> +		return true;
> +	/*
> +	 * Idle or nohz_full userspace (an RCU extended quiescent state): no
> +	 * task-level kernel frames there, and whatever ran before has switched
> +	 * out.  As with the classic flavor, the idle task itself is not waited
> +	 * for.
> +	 */
> +	if (!(ct_rcu_watching_cpu(cpu) & CT_RCU_WATCHING))
> +		return true;
> +	return idle_cpu(cpu);
> +}

[Severity: High]
Could the unconditional return of idle_cpu() lead to a use-after-free crash
if the idle task was interrupted in trampoline code?

Since the idle task wasn't added to the holdout list during IRQ exit
(because need_resched() was false in raw_irqentry_exit_cond_resched()), the
grace period thread relies entirely on rcu_tasks_cpu_quiescent().

Because idle_cpu(cpu) returns true, the QS sequence check for the idle task
is bypassed. The GP thread will assume the CPU has passed a quiescent state,
complete the grace period, and free the trampoline memory.

When the IRQ returns, the idle task will resume execution in the now-freed
trampoline memory, which can lead to a kernel panic.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260915-b4-rcu-tasks-preempt-qs-v3-0-0ad30c4c5ee7@toxicpanda.com?part=3

  reply	other threads:[~2026-09-15 13:29 UTC|newest]

Thread overview: 42+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-15 13:17 [PATCH RFC v3 00/13] rcu-tasks: build Tasks RCU on Tasks Trace readers in trampolines Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 01/13] entry: Pass pt_regs to irqentry_exit_cond_resched() Josef Bacik
2026-09-15 14:17   ` bot+bpf-ci
2026-09-15 13:17 ` [PATCH RFC v3 02/13] rcu-tasks-trace: Inline rcu_read_lock_trace() and annotate inside the reader Josef Bacik
2026-09-15 14:17   ` bot+bpf-ci
2026-09-15 13:17 ` [PATCH RFC v3 03/13] rcu-tasks: Add a Tasks RCU implementation for reader-marked trampolines Josef Bacik
2026-09-15 13:29   ` sashiko-bot [this message]
2026-09-15 16:02     ` Josef Bacik
2026-09-15 15:14   ` Frederic Weisbecker
2026-09-15 23:56     ` Paul E. McKenney
2026-09-16 12:40       ` Frederic Weisbecker
2026-09-16 14:26         ` Paul E. McKenney
2026-09-16 14:35           ` Frederic Weisbecker
2026-09-16 14:47             ` Frederic Weisbecker
2026-09-16 14:55               ` Paul E. McKenney
2026-09-16 15:23                 ` Frederic Weisbecker
2026-09-16 15:41                   ` Paul E. McKenney
2026-09-17 12:14                     ` Frederic Weisbecker
2026-09-17 15:40                       ` Paul E. McKenney
2026-09-17 16:35                         ` Josef Bacik
2026-09-17 16:55                           ` Paul E. McKenney
2026-09-17 18:45                         ` Frederic Weisbecker
2026-09-17 19:25                           ` Paul E. McKenney
2026-09-17 20:31                             ` Paul E. McKenney
2026-09-17 20:20   ` Frederic Weisbecker
2026-09-22 15:42     ` Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 04/13] kprobes: Expose the optprobe jump window to Tasks RCU Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 05/13] ftrace: Mark modules hosting direct-call trampolines for " Josef Bacik
2026-09-15 14:17   ` bot+bpf-ci
2026-09-15 16:03     ` Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 06/13] bpf: Take a Tasks Trace reader in the trampoline glue Josef Bacik
2026-09-16  3:45   ` Alexei Starovoitov
2026-09-17  1:16     ` Josef Bacik
2026-09-17  2:24       ` Alexei Starovoitov
2026-09-15 13:17 ` [PATCH RFC v3 07/13] x86/ftrace: Take a Tasks Trace reader around ftrace_caller's call-out Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 08/13] x86/kprobes: Take a Tasks Trace reader in the optprobe template Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 09/13] arm64: ftrace: Take a Tasks Trace reader around ftrace_caller's call-out Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 10/13] samples: ftrace: Make the direct-call trampolines Tasks Trace readers Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 11/13] rcutorture: Make Tasks RCU readers Tasks Trace readers where required Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 12/13] rcu-tasks-trace: Assert no reader is held on return to userspace Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 13/13] x86, arm64: Build Tasks RCU on Tasks Trace readers in trampolines Josef Bacik
2026-09-15 14:17   ` bot+bpf-ci

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260915132919.E868D1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=josef@toxicpanda.com \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.