From: Peter Zijlstra <peterz@infradead.org>
To: jpoimboe@kernel.org, rostedt@kernel.org
Cc: linux-kernel@vger.kernel.org, peterz@infradead.org
Subject: [PATCH 01/12] task_work: Fix NMI race condition
Date: Wed, 24 Sep 2025 09:59:49 +0200 [thread overview]
Message-ID: <20250924080118.425949403@infradead.org> (raw)
In-Reply-To: 20250924075948.579302904@infradead.org
__schedule()
// disable irqs
<NMI>
task_work_add(current, work, TWA_NMI_CURRENT);
</NMI>
// current = next;
// enable irqs
<IRQ>
task_work_set_notify_irq()
test_and_set_tsk_thread_flag(current,
TIF_NOTIFY_RESUME); // wrong task!
</IRQ>
// original task skips task work on its next return to user (or exit!)
Fixes: 466e4d801cd4 ("task_work: Add TWA_NMI_CURRENT as an additional notify mode.")
Reported-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
---
kernel/task_work.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
--- a/kernel/task_work.c
+++ b/kernel/task_work.c
@@ -9,7 +9,12 @@ static struct callback_head work_exited;
#ifdef CONFIG_IRQ_WORK
static void task_work_set_notify_irq(struct irq_work *entry)
{
- test_and_set_tsk_thread_flag(current, TIF_NOTIFY_RESUME);
+ /*
+ * no-op IPI
+ *
+ * TWA_NMI_CURRENT will already have set the TIF flag, all
+ * this interrupt does it tickle the return-to-user path.
+ */
}
static DEFINE_PER_CPU(struct irq_work, irq_work_NMI_resume) =
IRQ_WORK_INIT_HARD(task_work_set_notify_irq);
@@ -86,6 +91,7 @@ int task_work_add(struct task_struct *ta
break;
#ifdef CONFIG_IRQ_WORK
case TWA_NMI_CURRENT:
+ set_tsk_thread_flag(current, TIF_NOTIFY_RESUME);
irq_work_queue(this_cpu_ptr(&irq_work_NMI_resume));
break;
#endif
next prev parent reply other threads:[~2025-09-24 8:03 UTC|newest]
Thread overview: 53+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-09-24 7:59 [PATCH 00/12] Various fixes and x86 support Peter Zijlstra
2025-09-24 7:59 ` Peter Zijlstra [this message]
2025-10-01 15:31 ` [PATCH 01/12] task_work: Fix NMI race condition Steven Rostedt
2025-10-29 9:36 ` [tip: perf/core] " tip-bot2 for Peter Zijlstra
2025-09-24 7:59 ` [PATCH 02/12] unwind: Shorten lines Peter Zijlstra
2025-10-01 15:32 ` Steven Rostedt
2025-10-29 9:36 ` [tip: perf/core] " tip-bot2 for Peter Zijlstra
2025-09-24 7:59 ` [PATCH 03/12] unwind: Add required include files Peter Zijlstra
2025-10-01 15:32 ` Steven Rostedt
2025-10-29 9:36 ` [tip: perf/core] " tip-bot2 for Peter Zijlstra
2025-09-24 7:59 ` [PATCH 04/12] unwind: Simplify unwind_reset_info() Peter Zijlstra
2025-10-01 15:33 ` Steven Rostedt
2025-10-29 9:36 ` [tip: perf/core] " tip-bot2 for Peter Zijlstra
2025-09-24 7:59 ` [PATCH 05/12] unwind: Add comment to unwind_deferred_task_exit() Peter Zijlstra
2025-10-01 15:35 ` Steven Rostedt
2025-10-20 10:16 ` Peter Zijlstra
2025-10-22 15:16 ` Steven Rostedt
2025-10-29 9:36 ` [tip: perf/core] " tip-bot2 for Peter Zijlstra
2025-09-24 7:59 ` [PATCH 06/12] unwind: Fix unwind_deferred_request() vs NMI Peter Zijlstra
2025-10-01 15:37 ` Steven Rostedt
2025-10-29 9:36 ` [tip: perf/core] " tip-bot2 for Peter Zijlstra
2025-09-24 7:59 ` [PATCH 07/12] unwind: Clarify calling context Peter Zijlstra
2025-10-01 15:38 ` Steven Rostedt
2025-10-29 9:36 ` [tip: perf/core] " tip-bot2 for Peter Zijlstra
2025-09-24 7:59 ` [PATCH 08/12] unwind: Simplify unwind_user_faultable() Peter Zijlstra
2025-10-01 15:40 ` Steven Rostedt
2025-10-20 10:17 ` Peter Zijlstra
2025-10-29 9:36 ` [tip: perf/core] " tip-bot2 for Peter Zijlstra
2025-09-24 7:59 ` [PATCH 09/12] unwind: Make unwind_task_info::unwind_mask consistent Peter Zijlstra
2025-10-01 15:47 ` Steven Rostedt
2025-10-20 10:20 ` Peter Zijlstra
2025-10-29 9:36 ` [tip: perf/core] " tip-bot2 for Peter Zijlstra
2025-09-24 7:59 ` [PATCH 10/12] unwind: Simplify unwind_user_next_fp() alignment check Peter Zijlstra
2025-10-01 15:55 ` Steven Rostedt
2025-10-20 10:28 ` Peter Zijlstra
2025-10-22 15:20 ` Steven Rostedt
2025-10-23 9:53 ` Peter Zijlstra
2025-10-29 9:36 ` [tip: perf/core] " tip-bot2 for Peter Zijlstra
2025-09-24 7:59 ` [PATCH 11/12] unwind: Implement compat fp unwind Peter Zijlstra
2025-10-17 15:47 ` Jens Remus
2025-10-20 9:16 ` Jens Remus
2025-10-20 10:39 ` Peter Zijlstra
2025-10-20 10:48 ` Peter Zijlstra
2025-10-22 15:23 ` Steven Rostedt
2025-10-24 13:45 ` Peter Zijlstra
2025-10-22 14:55 ` Jens Remus
2025-10-24 13:40 ` Peter Zijlstra
2025-10-20 10:38 ` Peter Zijlstra
2025-10-22 18:31 ` Steven Rostedt
2025-10-24 14:10 ` Peter Zijlstra
2025-10-24 14:16 ` Peter Zijlstra
2025-10-29 9:36 ` [tip: perf/core] " tip-bot2 for Peter Zijlstra
2025-09-24 8:00 ` [PATCH 12/12] unwind_user/x86: Enable frame pointer unwinding on x86 Peter Zijlstra
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20250924080118.425949403@infradead.org \
--to=peterz@infradead.org \
--cc=jpoimboe@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=rostedt@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox