BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Josef Bacik" <josef@toxicpanda.com>
Cc: bpf@vger.kernel.org, linux-trace-kernel@vger.kernel.org
Subject: Re: [PATCH v6 03/14] rcu-tasks: Add a Tasks RCU implementation for reader-marked trampolines
Date: Tue, 29 Sep 2026 17:35:32 +0000	[thread overview]
Message-ID: <20260929173532.C88191F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929-b4-rcu-tasks-preempt-qs-v6-3-c111ee02caca@toxicpanda.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] rcu-tasks: Use-After-Free if task oopses inside irq-exit preemption
--

commit 6894dfa1f4c077dbeacd53dcfc82e1697f747465
Author: Josef Bacik <josef@toxicpanda.com>

rcu-tasks: Add a Tasks RCU implementation for reader-marked trampolines

This commit introduces a new Tasks RCU implementation for architectures
where trampolines are marked as Tasks Trace RCU readers. It tracks context
switches and preemptions during irq exits to wait for tasks that might
be lingering in unmarked trampoline text.

> diff --git a/kernel/rcu/tasks.h b/kernel/rcu/tasks.h
> index 627295396cd91..e7498601c28c3 100644
> --- a/kernel/rcu/tasks.h
> +++ b/kernel/rcu/tasks.h
[ ... ]
> +static void rcu_tasks_tramp_hold(struct task_struct *t)
> +{
> +	unsigned long flags;
> +
> +	if (t->rcu_tasks_holdout)
> +		return;
> +	raw_spin_lock_irqsave(&rcu_tasks_tramp_lock, flags);
> +	list_add_tail(&t->rcu_tasks_holdout_list, &rcu_tasks_tramp_holdouts);
> +	WRITE_ONCE(t->rcu_tasks_holdout, true);
> +	raw_spin_unlock_irqrestore(&rcu_tasks_tramp_lock, flags);
> +}

[Severity: Medium]
Does this code risk a use-after-free of the task struct?

It appears that the task is added to the holdout list without incrementing its
reference count (e.g., unlike the classic flavor which deliberately calls
get_task_struct()).

If a task is preempted inside unmarked trampoline text,
rcu_tasks_irq_resched_enter() adds it to rcu_tasks_tramp_holdouts. If the task
subsequently suffers a hardware exception or kernel oops while executing
preempt_schedule_irq(), it will be killed via make_task_dead() and do_exit().
Because rcu_tasks_irq_resched_exit() would never be reached to clear
t->rcu_tasks_irq_ip, rcu_tasks_note_qs() skips removing it from the holdout
list, leaving a dangling pointer when the task is later freed.

[ ... ]
> +static void rcu_tasks_tramp_wait_holdouts(struct rcu_tasks *rtp, unsigned long *lastreport)
> +{
> +	struct task_struct *t;
> +	unsigned long flags;
> +	int cpu;
> +
> +	raw_spin_lock_irqsave(&rcu_tasks_tramp_lock, flags);
> +	list_splice_tail_init(&rcu_tasks_tramp_holdouts, &rcu_tasks_gp_holdouts);
> +	raw_spin_unlock_irqrestore(&rcu_tasks_tramp_lock, flags);
> +
> +	for (;;) {
> +		struct cpumask *kick = &rcu_tasks_pending_cpus;
> +		struct task_struct *show[8];
> +		int nshow = 0, i;
> +		bool empty, report;
> +
> +		report = rcu_tasks_tramp_stall(rtp, lastreport,
> +					       "tasks preempted in trampoline text");
> +		cpumask_clear(kick);
> +		raw_spin_lock_irqsave(&rcu_tasks_tramp_lock, flags);
> +		empty = list_empty(&rcu_tasks_gp_holdouts);
> +		list_for_each_entry(t, &rcu_tasks_gp_holdouts, rcu_tasks_holdout_list) {
> +			if (task_curr(t))
> +				__cpumask_set_cpu(task_cpu(t), kick);

[Severity: Medium]
If the scenario described above occurs and the task struct has been freed,
could we hit a use-after-free here when iterating over the holdout list and
accessing t?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260929-b4-rcu-tasks-preempt-qs-v6-0-c111ee02caca@toxicpanda.com?part=3

  reply	other threads:[~2026-09-29 17:35 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29 17:07 [PATCH v6 00/14] rcu-tasks: build Tasks RCU on Tasks Trace readers in trampolines Josef Bacik
2026-09-29 17:07 ` [PATCH v6 01/14] rcu-tasks-trace: Let TASKS_TRACE_RCU_NO_MB default on without RCU_EXPERT Josef Bacik
2026-10-06 18:34   ` Paul E. McKenney
2026-09-29 17:07 ` [PATCH v6 02/14] entry: Pass pt_regs to irqentry_exit_cond_resched() Josef Bacik
2026-09-29 17:07 ` [PATCH v6 03/14] rcu-tasks: Add a Tasks RCU implementation for reader-marked trampolines Josef Bacik
2026-09-29 17:35   ` sashiko-bot [this message]
2026-09-29 17:07 ` [PATCH v6 04/14] kprobes: Expose the optprobe jump window to Tasks RCU Josef Bacik
2026-09-29 17:07 ` [PATCH v6 05/14] ftrace: Mark modules hosting direct-call trampolines for " Josef Bacik
2026-09-29 17:07 ` [PATCH v6 06/14] x86/ftrace: Take a Tasks Trace reader around ftrace_caller's call-out Josef Bacik
2026-09-29 17:07 ` [PATCH v6 07/14] x86/kprobes: Take a Tasks Trace reader in the optprobe template Josef Bacik
2026-09-29 17:07 ` [PATCH v6 08/14] bpf, x86: Take a Tasks Trace reader in the trampoline around its call-outs Josef Bacik
2026-09-29 17:07 ` [PATCH v6 09/14] arm64: ftrace: Take a Tasks Trace reader around ftrace_caller's call-out Josef Bacik
2026-09-29 17:07 ` [PATCH v6 10/14] bpf, arm64: Take a Tasks Trace reader in the trampoline around its call-outs Josef Bacik
2026-09-29 17:07 ` [PATCH v6 11/14] samples: ftrace: Make the direct-call trampolines Tasks Trace readers Josef Bacik
2026-09-29 17:07 ` [PATCH v6 12/14] rcutorture: Make Tasks RCU readers Tasks Trace readers where required Josef Bacik
2026-09-29 17:07 ` [PATCH v6 13/14] rcu-tasks-trace: Assert no reader is held on return to userspace Josef Bacik
2026-09-29 17:07 ` [PATCH v6 14/14] x86, arm64: Build Tasks RCU on Tasks Trace readers in trampolines Josef Bacik

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929173532.C88191F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=josef@toxicpanda.com \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox