From: "Alexei Starovoitov" <alexei.starovoitov@gmail.com>
To: "Yun Lu" <luyun_611@163.com>, <daniel@iogearbox.net>,
<andrii@kernel.org>, <eddyz87@gmail.com>, <memxor@gmail.com>,
<martin.lau@linux.dev>, <song@kernel.org>,
<yonghong.song@linux.dev>, <jolsa@kernel.org>,
<emil@etsalapatis.com>, <ihor.solodrai@linux.dev>
Cc: <yatsenko@meta.com>, <bpf@vger.kernel.org>
Subject: Re: [PATCH bpf-next v3 1/2] bpf: Fix task work scheduling and callback race
Date: Wed, 23 Sep 2026 23:04:03 +0000 [thread overview]
Message-ID: <DLN2KZR6RHH5.2OO4ZIR0XA36T@gmail.com> (raw)
In-Reply-To: <20260922100042.136818-2-luyun_611@163.com>
On Tue, Sep 22, 2026 at 06:00 PM Yun Lu <luyun_611@163.com> wrote:
> - err = task_work_add(ctx->task, &ctx->work, ctx->mode);
> + task = get_task_struct(ctx->task);
> + err = task_work_add(task, &ctx->work, ctx->mode);
Why?
There should be no need for get_task_struct().
rcu_read_lock() keeps task_struct around.
bpf_task_release() is put_task_struct_rcu_user(), so the task is
freed after rcu gp and guard(rcu)() covers the whole handler.
task = ctx->task;
is enough.
The commit log still says that rcu_read_lock() "does not retain
ctx->task". why?
[...]
> + if (unlikely(irq_work_is_busy(&ctx->irq_work))) {
> + (void)cmpxchg(&ctx->state, BPF_TW_PENDING, BPF_TW_STANDBY);
> + bpf_task_work_ctx_put(ctx);
> + return ERR_PTR(-EBUSY);
> + }
This is a fix for a different bug.
Pls split it into a separate patch and describe the sequence in
its commit log the way it's done for the first one.
"publishing a false SCHEDULED state" doesn't say what breaks.
pw-bot: cr
next prev parent reply other threads:[~2026-09-23 23:04 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 10:00 [PATCH bpf-next v3 0/2] bpf: Fix task work scheduling race Yun Lu
2026-09-22 10:00 ` [PATCH bpf-next v3 1/2] bpf: Fix task work scheduling and callback race Yun Lu
2026-09-23 17:46 ` Mykyta Yatsenko
2026-09-23 23:04 ` Alexei Starovoitov [this message]
2026-09-24 9:55 ` luyun
2026-09-22 10:00 ` [PATCH bpf-next v3 2/2] selftests/bpf: Add task work scheduling race test Yun Lu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DLN2KZR6RHH5.2OO4ZIR0XA36T@gmail.com \
--to=alexei.starovoitov@gmail.com \
--cc=andrii@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=emil@etsalapatis.com \
--cc=ihor.solodrai@linux.dev \
--cc=jolsa@kernel.org \
--cc=luyun_611@163.com \
--cc=martin.lau@linux.dev \
--cc=memxor@gmail.com \
--cc=song@kernel.org \
--cc=yatsenko@meta.com \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox