From: Shaobo Huang <huangshaobo3@xiaomi.com>
To: <ljs@kernel.org>
Cc: <akpm@linux-foundation.org>, <bsegall@google.com>,
<david@kernel.org>, <dietmar.eggemann@arm.com>,
<huangshaobo3@xiaomi.com>, <juri.lelli@redhat.com>,
<kees@kernel.org>, <kprateek.nayak@amd.com>, <liam@infradead.org>,
<linux-kernel@vger.kernel.org>, <linux-mm@kvack.org>,
<mgorman@suse.de>, <mhocko@suse.com>, <mingo@redhat.com>,
<peterz@infradead.org>, <rostedt@goodmis.org>, <rppt@kernel.org>,
<ryabinin.a.a@gmail.com>, <stable@vger.kernel.org>,
<surenb@google.com>, <vbabka@kernel.org>,
<vincent.guittot@linaro.org>, <vschneid@redhat.com>
Subject: Re: [PATCH] fork: reset pointer tag of vmapped thread stack before vfree
Date: Mon, 14 Sep 2026 17:19:56 +0800 [thread overview]
Message-ID: <20260914091956.100424-1-huangshaobo3@xiaomi.com> (raw)
In-Reply-To: <anSVlVpUXrA8ra_z@lucifer>
[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #1: Type: text/plain; charset="yes", Size: 2976 bytes --]
On Thu, Aug 06, 2026 at 03:13:31PM +0100, Lorenzo Stoakes (ARM) wrote:
> This looks AI-generated but I see no Assisted-by tag, please follow kernel
> procedure on this please.
>
> https://docs.kernel.org/process/coding-assistants.html
>
> None of your 4 patches pre-dating the slopularity look anything like this.
>
> Also please use a real name.
Thanks for the review. v2 addresses all of these:
- Added Assisted-by: tag per Documentation/process/coding-assistants.rst.
- Used my real name (Shaobo Huang).
- Dropped the verbose comment; the fix is a one-liner.
- Fixed the Fixes: tag (see below).
- Trimmed the commit message; removed the full KASAN dump.
> Output from a repro that you don't share, brilliant.
Fair — should have included it from the start. Here it is:
Prerequisites:
- CONFIG_KASAN_SW_TAGS + CONFIG_KASAN_STACK + CONFIG_VMAP_STACK
- /sys/power/mem_sleep set to "deep" (s2idle does not enter
cpu_suspend and will not trigger the bug)
- A wake source (RTC alarm, power button, etc.)
Method 1 (deterministic, single command):
# rtcwake -m mem -s 3
rtcwake writes "mem" to /sys/power/state, driving suspend-to-RAM.
At _cpu_resume, kasan_unpoison_task_stack_below() rewrites the
rtcwake process's kernel stack shadow [base, sp] to
KASAN_TAG_KERNEL (0xff). On resume, rtcwake exits; its thread
stack is freed via RCU callback (thread_stack_free_rcu -> vfree
-> vfree_atomic), and the llist_add write trips KASAN.
Method 2 (how the original report was captured):
1. Trigger system suspend (screen off, or `echo mem >
/sys/power/state` with an RTC alarm) -- the suspend-driving
task's stack gets 0xff'd on resume.
2. Trigger reboot/shutdown (`reboot bootloader`) -- during
shutdown, init kills services; the suspend-driving thread
exits, its stack is RCU-freed, and vfree_atomic trips.
The original KASAN report in v1 was from method 2 on a Xiaomi
Xring_o1 (arm64, 4K pages, SW_TAGS).
> A 2016 Fixes for some KASAN state bug? Really?
Fixed in v2: Fixes: 9f7d416c3612 ("kprobes: Unpoison stack in jprobe_return()
for KASAN") -- the commit that introduced kasan_unpoison_task_stack_below(),
adding both the function definition and the _cpu_resume() call site that
writes 0xff to the stack shadow on every CPU resume. The v1's Fixes
(0f110a9b956c, the vfree_atomic commit) was incorrect: vfree_atomic is
fine; the issue is the shadow/pointer tag divergence introduced by
kasan_unpoison_task_stack_below().
> And of course Cc: stable...
Cc: stable is retained in v2: the fix is one line, and the bug affects
any stable kernel with SW_TAGS + KASAN_STACK + VMAP_STACK where a
non-idle task drives system suspend and later exits. Happy to drop it
if you'd prefer the stable team evaluate separately.
> Nobody in their right mind does a comment like this for a kasan_reset_tag().
Agreed -- dropped in v2.
v2 will follow shortly.
Cheers,
Shaobo
next prev parent reply other threads:[~2026-09-14 9:20 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-06 12:30 [PATCH] fork: reset pointer tag of vmapped thread stack before vfree sparkhuang
2026-08-06 14:13 ` Lorenzo Stoakes (ARM)
2026-08-07 6:53 ` sparkhuang
2026-08-07 7:56 ` Lorenzo Stoakes (ARM)
2026-08-07 7:57 ` David Hildenbrand (Arm)
2026-08-07 7:58 ` Lorenzo Stoakes (ARM)
2026-08-07 8:00 ` David Hildenbrand (Arm)
2026-09-14 9:19 ` Shaobo Huang [this message]
2026-08-07 9:27 ` David Hildenbrand (Arm)
2026-08-07 10:41 ` sparkhuang
2026-08-07 10:47 ` David Hildenbrand (Arm)
2026-08-07 11:20 ` David Hildenbrand (Arm)
2026-09-14 9:33 ` [PATCH v2] " Shaobo Huang
2026-09-14 9:44 ` Lorenzo Stoakes (ARM)
2026-09-15 14:49 ` Uladzislau Rezki
2026-09-16 17:45 ` Andrey Ryabinin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260914091956.100424-1-huangshaobo3@xiaomi.com \
--to=huangshaobo3@xiaomi.com \
--cc=akpm@linux-foundation.org \
--cc=bsegall@google.com \
--cc=david@kernel.org \
--cc=dietmar.eggemann@arm.com \
--cc=juri.lelli@redhat.com \
--cc=kees@kernel.org \
--cc=kprateek.nayak@amd.com \
--cc=liam@infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=ljs@kernel.org \
--cc=mgorman@suse.de \
--cc=mhocko@suse.com \
--cc=mingo@redhat.com \
--cc=peterz@infradead.org \
--cc=rostedt@goodmis.org \
--cc=rppt@kernel.org \
--cc=ryabinin.a.a@gmail.com \
--cc=stable@vger.kernel.org \
--cc=surenb@google.com \
--cc=vbabka@kernel.org \
--cc=vincent.guittot@linaro.org \
--cc=vschneid@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox