From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B7192377007 for ; Sun, 9 Aug 2026 02:06:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.50 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786241204; cv=none; b=JOb9h7o/mAEs6C7YInQJTHPjlKza/QCHIJYSDoFcmQxXWwHRP/n5wTa7PWxTUFu0uUhooqj29sXM96aCoryjTjksCfwRfmY3V6OkgVp0hajIOqNjVhSdJm5qTahxsENNtUj87YB0y3RHHMN0viDqPKRPzfaIaCinqIN3adxSkpQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786241204; c=relaxed/simple; bh=hJrKzkOWzxqkGrUmikEr/V20FKCfell32fsSs9xXSVI=; h=Date:From:To:Cc:Subject:Message-ID:MIME-Version:Content-Type: Content-Disposition; b=AgHbBvlxDlMb5G6oZ8Cp3uCnXoU5tdodueyiB34DkTZjqeCNjV8Dc22/FHN45BFyYN8/+ZUWc163DKDvBHoifiL8OlaJ/cm0J5C3pPHAWsDmauwf+2or4scx+y27dvwGyUIit02qWvaJXbXDPF0PQ2vrL20q9qLFYWn6sk5lKwk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=O7thCw3+; arc=none smtp.client-ip=209.85.216.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="O7thCw3+" Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-38759bcd877so753150a91.2 for ; Sat, 08 Aug 2026 19:06:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786241202; x=1786846002; darn=vger.kernel.org; h=content-disposition:content-type:mime-version:message-id:subject:cc :to:from:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=JUi5CZ/mm/6LIkM/Ynog72l5rYYaKtcE2jJwcesfnKA=; b=O7thCw3+oS6AYLbRYh5I08vzcAGwWjvk2KII2htdapj+YOp9BTFaeZ0PdvusZE1ldC Rv4ijXPsS1/Bkg7HVtNt/MOuuDMg6GtE4RYa1o4my7gixQ+EqliHHEvxpXusY5ZjmvMF Ocrhds8Yz4v0fIWFaac2FMkjd9cd35LfKVy6M1+NA/TkaGTC3FaoESaIHhvJgqQYPRQh Lk3Ch8uPVyFT8MXHPW2w60J4FSlMHmSx1wSCEOwSjmHRanSOSOqZNuQQyFE4J02L+tjp Cc79R2jW1qpDTY1HGZsGsMYQ90t40/opd9nYQcXE+NO2mOcBkFN4H0Ys4iI0EGMOjBYZ 0sFw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786241202; x=1786846002; h=content-disposition:content-type:mime-version:message-id:subject:cc :to:from:date:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=JUi5CZ/mm/6LIkM/Ynog72l5rYYaKtcE2jJwcesfnKA=; b=GFMt3lgqtvNo6r+JeFMg7kz7mCa8PA9+Kd5mqtvVex0YdSF8suhWvzUUzdRO3nM8DV GsAMpczHfwf3mFbHccj+hHqP1y2dYPwRh95Eg1smLx+Lm4EdvZoNBtdmgcTHE9TNBhrK St/ncRhLQKTruvw5+ov+UFoXjHqanQOF/5SCVu2yOBUHR3zPXgiIK19TyORY2NKXs8Ht X6Krh5lFDy7nKDOVsdpUw85h7wXW1T4imePM/y0GiD8J5u9RpY70sAxKiMrQ8kXcUi/m 2X/Hntvgg0AfeVznXOKRwSs4aaZDK0pFvtertdwr/ObHc/z9Hf+twgoW9QmeXrfqqW2N m/Bg== X-Forwarded-Encrypted: i=1; AHgh+RpgBVn789IyK8sn9SqI9GRDld9bZSc3Ee/sl6ftu+o+jv5XCY06j86GtD5Ne0ZRMoFGAADp0vnblhLoyyA=@vger.kernel.org X-Gm-Message-State: AOJu0YxNdlMk4K1cI8dhNRTayM1fO1tG/Wu6lsIf13/yc6wt9iEfR3E2 y0psURlXFifooIjDrva4j2nW/Wo3KU98AvGKbjLQVCkWI1YS1zD6Q1sG X-Gm-Gg: AR+sD130EzzLcFsRL1tl0BqiRjSdy544/jykrqmRl1mFUhCRCQTmV7GujTfie6I8Wcb BysT6kQ/ZA95Qz4ltkDZFy+3xjJAyzbA1Qrb3BWrBRLA/42v4KLjfu1SyOcSSnt/cvUiGSKkc6p OOgrAMC+GvqKdXcktlR58p2jm4JzxQrmAdihkNXwQfMi9uv/er6BYN/lj4skGj8Ii+cQ7/OgKu1 Ug5686ewyONp5bX0ZMvnVWEGwFL+L3GSrWW6YMyOyPDi1KFvXNdxbFXno9USQsYB7LcJQX7y6+D ALL0p0T8pt3XZaZ7blb0WeLEtmLPBPuEy8/aK1ubVLns6qfKJWOagRzqLnq3RBd3JFbUP/uL8r7 VHe8lGxVPp2478KkZAV2LSi2Bn5J6UkMMET6/6AN3HMnU1aTJbJh1yWOT+MW5rXrxZ6vWcoxJY3 L3F/KyZ2Kaw1m2jXfo2YAqM3dFaQZFPk0TPbNCEOM+FmvXp3yZ0+jg7FrjkodFrV/BKXeKAK4yv wsuQgLTOV/4ZJep1sc= X-Received: by 2002:a17:90a:d010:b0:38d:eaec:4396 with SMTP id 98e67ed59e1d1-3903c58bdd2mr33450215a91.11.1786241202015; Sat, 08 Aug 2026 19:06:42 -0700 (PDT) Received: from v4bel ([58.123.110.97]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39085dc396dsm10023664a91.3.2026.08.08.19.06.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 19:06:41 -0700 (PDT) Date: Sun, 9 Aug 2026 11:06:38 +0900 From: Hyunwoo Kim To: viro@zeniv.linux.org.uk, brauner@kernel.org, tglx@kernel.org, ebiederm@xmission.com Cc: linux-fsdevel@vger.kernel.org, linux-mm@kvack.org, linux-kernel@vger.kernel.org, imv4bel@gmail.com Subject: [PATCH] posix-cpu-timers: Dequeue per-thread timers before exchange_tids() Message-ID: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline A per-thread CPU timer holds a reference to the PID of the thread it is attached to and, while it is armed, its node is queued in that thread's posix_cputimers. The task is looked up by that PID. When a non-leader thread exec()s, de_thread() changes which task owns that PID: de_thread(tsk) exchange_tids(tsk, leader); // tsk's PID now belongs to leader ... release_task(leader) __exit_signal(leader) posix_cpu_timers_exit(leader); // cleans leader's queue, not tsk's __unhash_process(leader) // that PID has no task anymore pid_task(timer->it.cpu.pid, PIDTYPE_PID) then returns NULL, but the node is still queued on tsk, which is alive. timer_lock_sighand() takes a failed lookup to mean that the node is already dequeued, so it has nothing to undo. begin_new_exec() calls posix_cpu_timers_exit(me) right after exec_task_namespaces() and that removes the leftover node, so the state normally stays invisible. But bprm->point_of_no_return is set before de_thread(), so if unshare_files(), set_mm_exe_file(), exec_mmap() or exec_task_namespaces() fails, the task dies before it gets there. exit_itimers() then frees the k_itimer while its node is still queued, and reaping tsk later erases that freed node from the rbtree. Dequeue the per-thread CPU timers of tsk before the PID changes hands, so that a failed lookup again implies a dequeued node. Process-wide timers are looked up with PIDTYPE_TGID and transfer_pid() moves that link to tsk, so they are left alone. Fixes: 55e8c8eb2c7b ("posix-cpu-timers: Store a reference to a pid not a task") Cc: stable@vger.kernel.org Signed-off-by: Hyunwoo Kim --- fs/exec.c | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/fs/exec.c b/fs/exec.c index c7b8f2d6366c44..f80f70e1c26de4 100644 --- a/fs/exec.c +++ b/fs/exec.c @@ -1000,6 +1000,18 @@ static int de_thread(struct task_struct *tsk) * the former thread group leader: */ +#ifdef CONFIG_POSIX_TIMERS + /* + * exchange_tids() hands this thread's PID to the old leader, + * which is reaped right after. The PID lookup in + * timer_lock_sighand() then fails while the per thread CPU + * timers are still queued here, so dequeue them first. + */ + spin_lock(lock); + posix_cpu_timers_exit(tsk); + spin_unlock(lock); +#endif + /* Become a process group leader with the old leader's pid. * The old leader becomes a thread of the this thread group. */ -- 2.43.0