BPF List
 help / color / mirror / Atom feed
* [PATCH bpf-next v2 0/2] bpf: Fix task work scheduling race
@ 2026-09-21 10:14 Yun Lu
  2026-09-21 10:14 ` [PATCH bpf-next v2 1/2] bpf: Fix task work scheduling and callback race Yun Lu
  2026-09-21 10:14 ` [PATCH bpf-next v2 2/2] selftests/bpf: Add task work scheduling race test Yun Lu
  0 siblings, 2 replies; 5+ messages in thread
From: Yun Lu @ 2026-09-21 10:14 UTC (permalink / raw)
  To: ast, daniel, andrii, eddyz87, memxor, martin.lau, song,
	yonghong.song, jolsa, emil, ihor.solodrai
  Cc: yatsenko, bpf

From: Yun Lu <luyun@kylinos.cn>

This series fixes a race in the bpf_task_work scheduling kfuncs and
adds a regression test for it.

bpf_task_work_irq() publishes a task_work callback before it finishes
using the scheduling round.  A target task running on another CPU can
execute the callback, reset ctx->task and publish STANDBY before the
irq_work handler performs its final state transition.  Concurrent map
value deletion can then make the handler call task_work_cancel() with a
NULL task.  The early STANDBY transition can also let a new round reuse
the context and irq_work while the old irq_work handler is still
running.

Patch 1 makes the callback claim RUNNING before waiting for the
scheduling irq_work invocation to finish via irq_work_sync().  A single
temporary reference taken from the existing ctx refcount keeps ctx->task
alive when deletion wins before the callback claims the round.  A BUSY
check covers the add-failure path, where there is no callback to perform
the wait.  No fields or states are added to the context, and the
cancellation and destruction paths are unchanged.

Patch 2 adds a 1500-round cross-CPU regression test covering context
reuse, callback completion followed by deletion, and deletion racing
with scheduling.

Changes since v1:

- Kernel: rework the fix per review feedback.  Replace the round_refs
  ownership counter and the extra irq_work objects with a completion
  edge: the callback claims RUNNING and waits for the scheduling
  irq_work via irq_work_sync(), plus one temporary reference from the
  existing ctx refcount and a BUSY check covering the add-failure
  path.  No context fields or states are added.
- Selftest: address review feedback (single packed result store,
  bounded thread-start wait, tolerate the expected deletion-race
  outcomes).

v1: https://lore.kernel.org/bpf/20260918080014.54012-1-luyun_611@163.com/

Testing:

- Built with KASAN, PROVE_LOCKING, PROVE_RCU and DEBUG_ATOMIC_SLEEP;
  ran test_progs -t task_work and 900 race-test rounds in QEMU, all
  clean.
- Replayed the deterministic reproducer (debug-delay only, not part of
  the series): without the fix it panics reliably in
  task_work_cancel(); with the fix the callback visibly waits for the
  handler and the guest stays healthy.

Yun Lu (2):
  bpf: Fix task work scheduling and callback race
  selftests/bpf: Add task work scheduling race test

 kernel/bpf/helpers.c                          |  46 ++-
 .../selftests/bpf/prog_tests/test_task_work.c | 283 ++++++++++++++++++
 .../selftests/bpf/progs/task_work_race.c      | 126 ++++++++
 3 files changed, 449 insertions(+), 6 deletions(-)
 create mode 100644 tools/testing/selftests/bpf/progs/task_work_race.c


-- 
2.43.0


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-22  6:38 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-21 10:14 [PATCH bpf-next v2 0/2] bpf: Fix task work scheduling race Yun Lu
2026-09-21 10:14 ` [PATCH bpf-next v2 1/2] bpf: Fix task work scheduling and callback race Yun Lu
2026-09-21 15:54   ` Mykyta Yatsenko
2026-09-22  6:34     ` luyun
2026-09-21 10:14 ` [PATCH bpf-next v2 2/2] selftests/bpf: Add task work scheduling race test Yun Lu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox