Skip to content

Commit d8aa5dd

Browse files
Peter ZijlstraThomas Gleixner
authored andcommitted
futex: Fix might_sleep() warning in futex_pivot_pending()
A younger me put a WARN in might_sleep() to warn about nested sleep loops. This younger me also build a wait-loop variant that can deal with it. This wait-loop variant doesn't have all the fancy wrappers, since it isn't used much. It also lacks wait-bit support. Add the wait-bit support and use it to fix the nested wait issue. Fixes: 8e7ff73 ("futex: Fix race in futex_pivot_pending() during private hash resize") Reported-by: syzbot+350a93852ac854927f45@syzkaller.appspotmail.com Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Signed-off-by: Thomas Gleixner <tglx@kernel.org> Link: https://patch.msgid.link/20260820074927.GH1246887@noisy.programming.kicks-ass.net Closes: https://syzkaller.appspot.com/bug?extid=350a93852ac854927f45
1 parent bde0238 commit d8aa5dd

5 files changed

Lines changed: 54 additions & 4 deletions

File tree

‎include/linux/wait.h‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1228,6 +1228,7 @@ long prepare_to_wait_event(struct wait_queue_head *wq_head, struct wait_queue_en
12281228
void finish_wait(struct wait_queue_head *wq_head, struct wait_queue_entry *wq_entry);
12291229
long wait_woken(struct wait_queue_entry *wq_entry, unsigned mode, long timeout);
12301230
int woken_wake_function(struct wait_queue_entry *wq_entry, unsigned mode, int sync, void *key);
1231+
int woken_wake_bit_function(struct wait_queue_entry *wq_entry, unsigned mode, int sync, void *key);
12311232
int autoremove_wake_function(struct wait_queue_entry *wq_entry, unsigned mode, int sync, void *key);
12321233

12331234
#define DEFINE_WAIT_FUNC(name, function) \

‎include/linux/wait_bit.h‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@ int out_of_line_wait_on_bit_timeout(unsigned long *word, int, wait_bit_action_f
3232
int out_of_line_wait_on_bit_lock(unsigned long *word, int, wait_bit_action_f *action, unsigned int mode);
3333
struct wait_queue_head *bit_waitqueue(unsigned long *word, int bit);
3434
extern void __init wait_bit_init(void);
35+
extern struct wait_bit_key *__var_wake_key(struct wait_queue_entry *wq_entry, void *arg);
3536

3637
int wake_bit_function(struct wait_queue_entry *wq_entry, unsigned mode, int sync, void *key);
3738

‎kernel/futex/core.c‎

Lines changed: 26 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,6 +45,7 @@
4545
#include <linux/rseq.h>
4646
#include <linux/slab.h>
4747
#include <linux/vmalloc.h>
48+
#include <linux/wait_bit.h>
4849

4950
#include <vdso/futex.h>
5051

@@ -1884,11 +1885,35 @@ static int futex_hash_allocate(unsigned int hash_slots, unsigned int flags)
18841885
futex_hash_bucket_init(&fph->queues[i]);
18851886

18861887
if (custom) {
1888+
struct wait_bit_queue_entry __wbq_entry;
1889+
struct wait_queue_head *__wq_head;
1890+
18871891
/*
18881892
* Only let prctl() wait / retry; don't unduly delay clone().
18891893
*/
18901894
again:
1891-
wait_var_event(mm, futex_pivot_pending(mm));
1895+
__wq_head = __var_waitqueue(mm);
1896+
init_wait_var_entry(&__wbq_entry, mm, 0);
1897+
__wbq_entry.wq_entry.func = woken_wake_bit_function;
1898+
add_wait_queue(__wq_head, &__wbq_entry.wq_entry);
1899+
1900+
/*
1901+
* add_wait_queue() futex_ref_put()
1902+
* MB (this) MB (implied)
1903+
* futex_pivot_pending() wake_up_var()
1904+
* waitqueue_active()
1905+
*
1906+
* Notably, it must not be possible to see
1907+
* !futex_pivot_pending() && !waitqueue_active().
1908+
*/
1909+
smp_mb();
1910+
1911+
while (!futex_pivot_pending(mm) &&
1912+
wait_woken(&__wbq_entry.wq_entry, TASK_UNINTERRUPTIBLE,
1913+
MAX_SCHEDULE_TIMEOUT))
1914+
/* empty */;
1915+
1916+
remove_wait_queue(__wq_head, &__wbq_entry.wq_entry);
18921917
}
18931918

18941919
scoped_guard(mutex, &mm->futex.phash.lock) {

‎kernel/sched/wait.c‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@
55
* (C) 2004 Nadia Yvette Chambers, Oracle
66
*/
77
#include "sched.h"
8+
#include <linux/wait_bit.h>
89

910
void __init_waitqueue_head(struct wait_queue_head *wq_head, const char *name, struct lock_class_key *key)
1011
{
@@ -463,3 +464,17 @@ int woken_wake_function(struct wait_queue_entry *wq_entry, unsigned mode, int sy
463464
return default_wake_function(wq_entry, mode, sync, key);
464465
}
465466
EXPORT_SYMBOL(woken_wake_function);
467+
468+
int woken_wake_bit_function(struct wait_queue_entry *wq_entry, unsigned mode, int sync, void *arg)
469+
{
470+
struct wait_bit_key *key = __var_wake_key(wq_entry, arg);
471+
if (!key)
472+
return 0;
473+
474+
/* Pairs with the smp_store_mb() in wait_woken(). */
475+
smp_mb(); /* C */
476+
wq_entry->flags |= WQ_FLAG_WOKEN;
477+
478+
return default_wake_function(wq_entry, mode, sync, key);
479+
}
480+
EXPORT_SYMBOL(woken_wake_bit_function);

‎kernel/sched/wait_bit.c‎

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -167,16 +167,24 @@ wait_queue_head_t *__var_waitqueue(void *p)
167167
}
168168
EXPORT_SYMBOL(__var_waitqueue);
169169

170-
static int
171-
var_wake_function(struct wait_queue_entry *wq_entry, unsigned int mode,
172-
int sync, void *arg)
170+
struct wait_bit_key *__var_wake_key(struct wait_queue_entry *wq_entry, void *arg)
173171
{
174172
struct wait_bit_key *key = arg;
175173
struct wait_bit_queue_entry *wbq_entry =
176174
container_of(wq_entry, struct wait_bit_queue_entry, wq_entry);
177175

178176
if (wbq_entry->key.flags != key->flags ||
179177
wbq_entry->key.bit_nr != key->bit_nr)
178+
return NULL;
179+
180+
return key;
181+
}
182+
183+
static int var_wake_function(struct wait_queue_entry *wq_entry, unsigned int mode,
184+
int sync, void *arg)
185+
{
186+
struct wait_bit_key *key = __var_wake_key(wq_entry, arg);
187+
if (!key)
180188
return 0;
181189

182190
return autoremove_wake_function(wq_entry, mode, sync, key);

0 commit comments

Comments
 (0)