From: Josef Bacik <josef@toxicpanda.com>
To: sashiko-reviews@lists.linux.dev
Cc: linux-trace-kernel@vger.kernel.org, bpf@vger.kernel.org
Subject: Re: [PATCH RFC v3 03/13] rcu-tasks: Add a Tasks RCU implementation for reader-marked trampolines
Date: Tue, 15 Sep 2026 16:02:31 +0000 [thread overview]
Message-ID: <162b7a9a7e12191a9661465090319408.josef@toxicpanda.com> (raw)
In-Reply-To: <20260915132919.E868D1F000FF@smtp.kernel.org>
On Tue, 15 Sep 2026 13:29:19 +0000, sashiko-bot@kernel.org wrote:
> > + if (!(ct_rcu_watching_cpu(cpu) & CT_RCU_WATCHING))
> > + return true;
> > + return idle_cpu(cpu);
> > +}
>
> [Severity: High]
> Could the unconditional return of idle_cpu() lead to a use-after-free crash
> if the idle task was interrupted in trampoline code?
Yes, this one is right. The classic flavor ignores idle tasks too and
leans on Tasks Rude for that, but the idle_cpu() shortcut here made it
worse than it needs to be: an idle CPU with an interrupt sitting on top
of a trampoline the idle loop had called into would be passed
immediately, and since idle is never preempted from irq exit nothing
else catches it.
For v4 that line is gone and an idle CPU only counts while RCU is not
watching it. If it is watching (the interrupt, or the traceable part of
the idle loop) it gets the resched_cpu() like any other straggler and
counts once the idle loop itself schedules, which it cannot do from
inside a trampoline. So idle ends up covered rather than ignored.
Thanks,
Josef
next prev parent reply other threads:[~2026-09-15 16:02 UTC|newest]
Thread overview: 42+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-15 13:17 [PATCH RFC v3 00/13] rcu-tasks: build Tasks RCU on Tasks Trace readers in trampolines Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 01/13] entry: Pass pt_regs to irqentry_exit_cond_resched() Josef Bacik
2026-09-15 14:17 ` bot+bpf-ci
2026-09-15 13:17 ` [PATCH RFC v3 02/13] rcu-tasks-trace: Inline rcu_read_lock_trace() and annotate inside the reader Josef Bacik
2026-09-15 14:17 ` bot+bpf-ci
2026-09-15 13:17 ` [PATCH RFC v3 03/13] rcu-tasks: Add a Tasks RCU implementation for reader-marked trampolines Josef Bacik
2026-09-15 13:29 ` sashiko-bot
2026-09-15 16:02 ` Josef Bacik [this message]
2026-09-15 15:14 ` Frederic Weisbecker
2026-09-15 23:56 ` Paul E. McKenney
2026-09-16 12:40 ` Frederic Weisbecker
2026-09-16 14:26 ` Paul E. McKenney
2026-09-16 14:35 ` Frederic Weisbecker
2026-09-16 14:47 ` Frederic Weisbecker
2026-09-16 14:55 ` Paul E. McKenney
2026-09-16 15:23 ` Frederic Weisbecker
2026-09-16 15:41 ` Paul E. McKenney
2026-09-17 12:14 ` Frederic Weisbecker
2026-09-17 15:40 ` Paul E. McKenney
2026-09-17 16:35 ` Josef Bacik
2026-09-17 16:55 ` Paul E. McKenney
2026-09-17 18:45 ` Frederic Weisbecker
2026-09-17 19:25 ` Paul E. McKenney
2026-09-17 20:31 ` Paul E. McKenney
2026-09-17 20:20 ` Frederic Weisbecker
2026-09-22 15:42 ` Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 04/13] kprobes: Expose the optprobe jump window to Tasks RCU Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 05/13] ftrace: Mark modules hosting direct-call trampolines for " Josef Bacik
2026-09-15 14:17 ` bot+bpf-ci
2026-09-15 16:03 ` Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 06/13] bpf: Take a Tasks Trace reader in the trampoline glue Josef Bacik
2026-09-16 3:45 ` Alexei Starovoitov
2026-09-17 1:16 ` Josef Bacik
2026-09-17 2:24 ` Alexei Starovoitov
2026-09-15 13:17 ` [PATCH RFC v3 07/13] x86/ftrace: Take a Tasks Trace reader around ftrace_caller's call-out Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 08/13] x86/kprobes: Take a Tasks Trace reader in the optprobe template Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 09/13] arm64: ftrace: Take a Tasks Trace reader around ftrace_caller's call-out Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 10/13] samples: ftrace: Make the direct-call trampolines Tasks Trace readers Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 11/13] rcutorture: Make Tasks RCU readers Tasks Trace readers where required Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 12/13] rcu-tasks-trace: Assert no reader is held on return to userspace Josef Bacik
2026-09-15 13:17 ` [PATCH RFC v3 13/13] x86, arm64: Build Tasks RCU on Tasks Trace readers in trampolines Josef Bacik
2026-09-15 14:17 ` bot+bpf-ci
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=162b7a9a7e12191a9661465090319408.josef@toxicpanda.com \
--to=josef@toxicpanda.com \
--cc=bpf@vger.kernel.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox