BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Masami Hiramatsu (Google)" <mhiramat@kernel.org>
Cc: bpf@vger.kernel.org, linux-trace-kernel@vger.kernel.org
Subject: Re: [RFC PATCH 2/3] rhashtable: Add use_tasks_rude parameter to defer bucket table free
Date: Mon, 28 Sep 2026 14:43:54 +0000	[thread overview]
Message-ID: <20260928144354.DE87C1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <179060578063.372125.17243688315867196392.stgit@devnote2>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] rhashtable: UAF in standard walkers and inserts due to Tasks Rude RCU mismatch
--

commit 72dce4af7330e16ac9fafbde35eaffd5f5d340ca
Author: Masami Hiramatsu (Google) <mhiramat@kernel.org>

rhashtable: Add use_tasks_rude parameter to defer bucket table free

This commit adds a use_tasks_rude boolean flag to struct rhashtable_params.
When enabled, old bucket tables are freed using call_rcu_tasks_rude()
instead of call_rcu() to support callers that operate under preempt_disable()
without holding rcu_read_lock().

> diff --git a/lib/rhashtable.c b/lib/rhashtable.c
> index 6362896e4f099..b183fb112a705 100644
> --- a/lib/rhashtable.c
> +++ b/lib/rhashtable.c
> @@ -359,7 +359,10 @@ static int rhashtable_rehash_table(struct rhashtable *ht)
>  	 * rhashtable_walk_stop() can use rcu_head_after_call_rcu()
>  	 * to check if it should not re-link the table.
>  	 */
> -	call_rcu(&old_tbl->rcu, bucket_table_free_rcu);
> +	if (ht->p.use_tasks_rude)
> +		call_rcu_tasks_rude(&old_tbl->rcu, bucket_table_free_rcu);

[Severity: High]
Does this create a use-after-free for standard readers when
CONFIG_PREEMPT_RCU=y is enabled?

Standard rhashtable operations like __rhashtable_insert_fast() and
rhashtable_walk_start_check() acquire standard RCU read locks:

lib/rhashtable.c:rhashtable_walk_start_check() {
    ...
    rcu_read_lock();
    iter->walker.tbl = rht_dereference_rcu(ht->tbl, ht);
    ...
}

include/linux/rhashtable.h:__rhashtable_insert_fast() {
    ...
    rcu_read_lock();
    tbl = rht_dereference_rcu(ht->tbl, ht);
    ...
}

Under CONFIG_PREEMPT_RCU, rcu_read_lock() does not disable preemption. If a
task is preempted during an insert or walk, a Tasks Rude RCU grace period
can complete while the preempted task is still accessing the old bucket
table. Since Tasks Rude RCU only waits for preempt-disabled regions and not
standard RCU read-side critical sections, the bucket table could be freed
before the preempted standard reader finishes.

> +	else
> +		call_rcu(&old_tbl->rcu, bucket_table_free_rcu);
>  	spin_unlock(&ht->lock);
>  
>  	return rht_dereference(new_tbl->future_tbl, ht) ? -EAGAIN : 0;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/179060575297.372125.10581329083761385407.stgit@devnote2?part=2

  reply	other threads:[~2026-09-28 14:43 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 14:29 [RFC PATCH 0/3] fprobe, rcu/tasks, rhashtable: Switch fprobe and BPF kprobe-multi to Tasks-Rude RCU Masami Hiramatsu (Google)
2026-09-28 14:29 ` [RFC PATCH 1/3] rcu/tasks: Export call_rcu_tasks_rude() Masami Hiramatsu (Google)
2026-09-28 14:39   ` sashiko-bot
2026-09-28 15:17   ` bot+bpf-ci
2026-09-28 14:29 ` [RFC PATCH 2/3] rhashtable: Add use_tasks_rude parameter to defer bucket table free Masami Hiramatsu (Google)
2026-09-28 14:43   ` sashiko-bot [this message]
2026-09-28 14:29 ` [RFC PATCH 3/3] fprobe: Switch fprobe and BPF kprobe-multi to Tasks-Rude RCU Masami Hiramatsu (Google)
2026-09-28 14:46   ` sashiko-bot
2026-09-28 16:25 ` [RFC PATCH 0/3] fprobe, rcu/tasks, rhashtable: " Paul E. McKenney
2026-09-28 23:28   ` Masami Hiramatsu
2026-09-29  0:04     ` Paul E. McKenney
2026-09-29  0:33       ` Andrii Nakryiko
2026-09-29  0:41         ` Paul E. McKenney
2026-09-30  0:35           ` Masami Hiramatsu
2026-09-30  0:47             ` Paul E. McKenney

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928144354.DE87C1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=mhiramat@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox