The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: "Paul E. McKenney" <paulmck@kernel.org>
To: Anna-Maria Behnsen <anna-maria@linutronix.de>,
	Frederic Weisbecker <frederic@kernel.org>,
	Thomas Gleixner <tglx@kernel.org>
Cc: "Peter Zijlstra (Intel)" <peterz@infradead.org>,
	linux-kernel@vger.kernel.org, kernel-team@meta.com,
	"Paul E. McKenney" <paulmck@kernel.org>
Subject: [PATCH RFC 1/9] hrtimer: Mark data-racy accesses to hrtimer_sleeper ->task field
Date: Thu, 30 Jul 2026 17:40:11 -0700	[thread overview]
Message-ID: <20260731004019.3530210-1-paulmck@kernel.org> (raw)
In-Reply-To: <e76a426b-f65c-4357-b263-96506d877136@paulmck-laptop>

The hrtimer_sleeper structure's ->task field is used as a flag to indicate
that the associated hrtimer has expired.  This means that the hrtimer
handler can be storing to this field while other code is loading from it
to check for expiry.  Note that additional races appear for hrtimers that
can be restarted, which could be argued to be a user error.  However,
that is no reason to let the compiler introduce additional confusion.

Therefore, mark data-racy accesses to the hrtimer_sleeper ->task field
using READ_ONCE() (using a new hrtimer_sleeper_task_get() access function)
and WRITE_ONCE() (using a new hrtimer_sleeper_task_set() access function).

KCSAN located this issue.

Signed-off-by: Paul E. McKenney <paulmck@kernel.org>
Cc: Anna-Maria Behnsen <anna-maria@linutronix.de>
Cc: Frederic Weisbecker <frederic@kernel.org>
Cc: Thomas Gleixner <tglx@kernel.org>
---
 include/linux/hrtimer.h |  8 ++++++++
 kernel/time/hrtimer.c   | 14 +++++++-------
 2 files changed, 15 insertions(+), 7 deletions(-)

diff --git a/include/linux/hrtimer.h b/include/linux/hrtimer.h
index 6862dea0acc52f..838ea7bce99c1d 100644
--- a/include/linux/hrtimer.h
+++ b/include/linux/hrtimer.h
@@ -350,6 +350,14 @@ extern int schedule_hrtimeout_range_clock(ktime_t *expires,
 					  const enum hrtimer_mode mode,
 					  clockid_t clock_id);
 extern int schedule_hrtimeout(ktime_t *expires, const enum hrtimer_mode mode);
+static inline struct task_struct *hrtimer_sleeper_task_get(struct hrtimer_sleeper *sl)
+{
+	return READ_ONCE(sl->task);
+}
+static inline void hrtimer_sleeper_task_set(struct hrtimer_sleeper *sl, struct task_struct *t)
+{
+	WRITE_ONCE(sl->task, t);
+}
 
 /* Soft interrupt function to run the hrtimer queues: */
 extern void hrtimer_run_queues(void);
diff --git a/kernel/time/hrtimer.c b/kernel/time/hrtimer.c
index 313dcea127fe48..84ea341a6efcc4 100644
--- a/kernel/time/hrtimer.c
+++ b/kernel/time/hrtimer.c
@@ -2286,9 +2286,9 @@ void hrtimer_run_queues(void)
 static enum hrtimer_restart hrtimer_wakeup(struct hrtimer *timer)
 {
 	struct hrtimer_sleeper *t = container_of(timer, struct hrtimer_sleeper, timer);
-	struct task_struct *task = t->task;
+	struct task_struct *task = hrtimer_sleeper_task_get(t);
 
-	t->task = NULL;
+	hrtimer_sleeper_task_set(t, NULL);
 	if (task)
 		wake_up_process(task);
 
@@ -2317,7 +2317,7 @@ void hrtimer_sleeper_start_expires(struct hrtimer_sleeper *sl, enum hrtimer_mode
 
 	/* If already expired, clear the task pointer and set current state to running */
 	if (!hrtimer_start_expires_user(&sl->timer, mode)) {
-		sl->task = NULL;
+		hrtimer_sleeper_task_set(sl, NULL);
 		__set_current_state(TASK_RUNNING);
 	}
 }
@@ -2351,7 +2351,7 @@ static void __hrtimer_setup_sleeper(struct hrtimer_sleeper *sl, clockid_t clock_
 	}
 
 	__hrtimer_setup(&sl->timer, hrtimer_wakeup, clock_id, mode);
-	sl->task = current;
+	hrtimer_sleeper_task_set(sl, current);
 }
 
 /**
@@ -2395,17 +2395,17 @@ static int __sched do_nanosleep(struct hrtimer_sleeper *t, enum hrtimer_mode mod
 		set_current_state(TASK_INTERRUPTIBLE|TASK_FREEZABLE);
 		hrtimer_sleeper_start_expires(t, mode);
 
-		if (likely(t->task))
+		if (likely(hrtimer_sleeper_task_get(t)))
 			schedule();
 
 		hrtimer_cancel(&t->timer);
 		mode = HRTIMER_MODE_ABS;
 
-	} while (t->task && !signal_pending(current));
+	} while (hrtimer_sleeper_task_get(t) && !signal_pending(current));
 
 	__set_current_state(TASK_RUNNING);
 
-	if (!t->task)
+	if (!hrtimer_sleeper_task_get(t))
 		return 0;
 
 	restart = &current->restart_block;
-- 
2.40.1


  reply	other threads:[~2026-07-31  0:40 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-31  0:39 [PATCH RFC 0/9] Fix data races on hrtimer_sleeper ->task field Paul E. McKenney
2026-07-31  0:40 ` Paul E. McKenney [this message]
2026-08-04 17:25   ` [PATCH RFC 1/9] hrtimer: Mark data-racy accesses to " Dmitry Ilvokhin
2026-07-31  0:40 ` [PATCH RFC 2/9] aio: Use accessor for " Paul E. McKenney
2026-07-31 12:32   ` Jan Kara
2026-07-31 12:57   ` Christian Brauner
2026-07-31 17:40     ` Paul E. McKenney
2026-07-31  0:40 ` [PATCH RFC 3/9] wait: " Paul E. McKenney
2026-07-31  0:40 ` [PATCH RFC 4/9] io-uring/rw: " Paul E. McKenney
2026-07-31 15:03   ` Jens Axboe
2026-07-31 17:42     ` Paul E. McKenney
2026-07-31  0:40 ` [PATCH RFC 5/9] futex: Use accessor for hrtimer_sleeper ->task field in waitwake.c Paul E. McKenney
2026-08-03 15:20   ` André Almeida
2026-08-04 17:29   ` Dmitry Ilvokhin
2026-07-31  0:40 ` [PATCH RFC 6/9] timers: Use accessor for hrtimer_sleeper ->task field in sleep_timeout.c Paul E. McKenney
2026-08-04 17:31   ` Dmitry Ilvokhin
2026-07-31  0:40 ` [PATCH RFC 7/9] net: pktgen: Use accessor for hrtimer_sleeper ->task field Paul E. McKenney
2026-07-31  0:40 ` [PATCH RFC 8/9] rtmutex: " Paul E. McKenney
2026-08-04 17:32   ` Dmitry Ilvokhin
2026-08-04 20:15     ` Paul E. McKenney
2026-07-31  0:40 ` [PATCH RFC 9/9] futex: Use accessor for hrtimer_sleeper ->task field in requeue Paul E. McKenney
2026-08-03 15:21   ` André Almeida
2026-08-03 15:45     ` Paul E. McKenney

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260731004019.3530210-1-paulmck@kernel.org \
    --to=paulmck@kernel.org \
    --cc=anna-maria@linutronix.de \
    --cc=frederic@kernel.org \
    --cc=kernel-team@meta.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=peterz@infradead.org \
    --cc=tglx@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox