Linux-mm Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Shaobo Huang <huangshaobo3@xiaomi.com>
To: <ljs@kernel.org>
Cc: <akpm@linux-foundation.org>, <bsegall@google.com>,
	<david@kernel.org>, <dietmar.eggemann@arm.com>,
	<huangshaobo3@xiaomi.com>, <juri.lelli@redhat.com>,
	<kees@kernel.org>, <kprateek.nayak@amd.com>, <liam@infradead.org>,
	<linux-kernel@vger.kernel.org>, <linux-mm@kvack.org>,
	<mgorman@suse.de>, <mhocko@suse.com>, <mingo@redhat.com>,
	<peterz@infradead.org>, <rostedt@goodmis.org>, <rppt@kernel.org>,
	<ryabinin.a.a@gmail.com>, <stable@vger.kernel.org>,
	<surenb@google.com>, <vbabka@kernel.org>,
	<vincent.guittot@linaro.org>, <vschneid@redhat.com>
Subject: Re: [PATCH] fork: reset pointer tag of vmapped thread stack before vfree
Date: Mon, 14 Sep 2026 17:19:56 +0800	[thread overview]
Message-ID: <20260914091956.100424-1-huangshaobo3@xiaomi.com> (raw)
In-Reply-To: <anSVlVpUXrA8ra_z@lucifer>

[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #1: Type: text/plain; charset="yes", Size: 2976 bytes --]

On Thu, Aug 06, 2026 at 03:13:31PM +0100, Lorenzo Stoakes (ARM) wrote:
> This looks AI-generated but I see no Assisted-by tag, please follow kernel
> procedure on this please.
>
> https://docs.kernel.org/process/coding-assistants.html
>
> None of your 4 patches pre-dating the slopularity look anything like this.
>
> Also please use a real name.

Thanks for the review.  v2 addresses all of these:

  - Added Assisted-by: tag per Documentation/process/coding-assistants.rst.
  - Used my real name (Shaobo Huang).
  - Dropped the verbose comment; the fix is a one-liner.
  - Fixed the Fixes: tag (see below).
  - Trimmed the commit message; removed the full KASAN dump.

> Output from a repro that you don't share, brilliant.

Fair — should have included it from the start.  Here it is:

  Prerequisites:
    - CONFIG_KASAN_SW_TAGS + CONFIG_KASAN_STACK + CONFIG_VMAP_STACK
    - /sys/power/mem_sleep set to "deep" (s2idle does not enter
      cpu_suspend and will not trigger the bug)
    - A wake source (RTC alarm, power button, etc.)

  Method 1 (deterministic, single command):

    # rtcwake -m mem -s 3

    rtcwake writes "mem" to /sys/power/state, driving suspend-to-RAM.
    At _cpu_resume, kasan_unpoison_task_stack_below() rewrites the
    rtcwake process's kernel stack shadow [base, sp] to
    KASAN_TAG_KERNEL (0xff).  On resume, rtcwake exits; its thread
    stack is freed via RCU callback (thread_stack_free_rcu -> vfree
    -> vfree_atomic), and the llist_add write trips KASAN.

  Method 2 (how the original report was captured):

    1. Trigger system suspend (screen off, or `echo mem >
       /sys/power/state` with an RTC alarm) -- the suspend-driving
       task's stack gets 0xff'd on resume.
    2. Trigger reboot/shutdown (`reboot bootloader`) -- during
       shutdown, init kills services; the suspend-driving thread
       exits, its stack is RCU-freed, and vfree_atomic trips.

  The original KASAN report in v1 was from method 2 on a Xiaomi
  Xring_o1 (arm64, 4K pages, SW_TAGS).

> A 2016 Fixes for some KASAN state bug? Really?

Fixed in v2: Fixes: 9f7d416c3612 ("kprobes: Unpoison stack in jprobe_return()
for KASAN") -- the commit that introduced kasan_unpoison_task_stack_below(),
adding both the function definition and the _cpu_resume() call site that
writes 0xff to the stack shadow on every CPU resume.  The v1's Fixes
(0f110a9b956c, the vfree_atomic commit) was incorrect: vfree_atomic is
fine; the issue is the shadow/pointer tag divergence introduced by
kasan_unpoison_task_stack_below().

> And of course Cc: stable...

Cc: stable is retained in v2: the fix is one line, and the bug affects
any stable kernel with SW_TAGS + KASAN_STACK + VMAP_STACK where a
non-idle task drives system suspend and later exits.  Happy to drop it
if you'd prefer the stable team evaluate separately.

> Nobody in their right mind does a comment like this for a kasan_reset_tag().

Agreed -- dropped in v2.

v2 will follow shortly.

Cheers,
Shaobo


  parent reply	other threads:[~2026-09-14  9:20 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-06 12:30 [PATCH] fork: reset pointer tag of vmapped thread stack before vfree sparkhuang
2026-08-06 14:13 ` Lorenzo Stoakes (ARM)
2026-08-07  6:53   ` sparkhuang
2026-08-07  7:56     ` Lorenzo Stoakes (ARM)
2026-08-07  7:57       ` David Hildenbrand (Arm)
2026-08-07  7:58         ` Lorenzo Stoakes (ARM)
2026-08-07  8:00           ` David Hildenbrand (Arm)
2026-09-14  9:19   ` Shaobo Huang [this message]
2026-08-07  9:27 ` David Hildenbrand (Arm)
2026-08-07 10:41   ` sparkhuang
2026-08-07 10:47     ` David Hildenbrand (Arm)
2026-08-07 11:20     ` David Hildenbrand (Arm)
2026-09-14  9:33 ` [PATCH v2] " Shaobo Huang
2026-09-14  9:44   ` Lorenzo Stoakes (ARM)
2026-09-15 14:49     ` Uladzislau Rezki
2026-09-16 17:45   ` Andrey Ryabinin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260914091956.100424-1-huangshaobo3@xiaomi.com \
    --to=huangshaobo3@xiaomi.com \
    --cc=akpm@linux-foundation.org \
    --cc=bsegall@google.com \
    --cc=david@kernel.org \
    --cc=dietmar.eggemann@arm.com \
    --cc=juri.lelli@redhat.com \
    --cc=kees@kernel.org \
    --cc=kprateek.nayak@amd.com \
    --cc=liam@infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=ljs@kernel.org \
    --cc=mgorman@suse.de \
    --cc=mhocko@suse.com \
    --cc=mingo@redhat.com \
    --cc=peterz@infradead.org \
    --cc=rostedt@goodmis.org \
    --cc=rppt@kernel.org \
    --cc=ryabinin.a.a@gmail.com \
    --cc=stable@vger.kernel.org \
    --cc=surenb@google.com \
    --cc=vbabka@kernel.org \
    --cc=vincent.guittot@linaro.org \
    --cc=vschneid@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox