From nobody Fri Jul 24 22:55:03 2026 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C810237FF4E; Wed, 22 Jul 2026 18:58:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.142.43.55 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784746703; cv=none; b=KtXb1TgHqqXtZTVraJDTYgvy0XKAwrDgTevJJF8SZ63ayxkb32tiY7mGPPrT3Ddnhcz9gOvjJdeCMSq53aMsKjhckWBAS6TI1Xv0GJFsD1kQcDCIzFim38zX+2RRlCUJgcn7nyIjevQNzngcIpjJQbfS4i806ic6BAUffPwZ5MA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784746703; c=relaxed/simple; bh=XSvB+CcqIhK/qLGeoFQPrUIOW/LAzlC+j05V/qW0YyU=; h=Date:From:To:Subject:Cc:In-Reply-To:References:MIME-Version: Message-ID:Content-Type; b=hIrpbPyXOVud/9kwG89eJt3+NFVY+dAYBRYpWdqmNorhdgIYLflq+Xv4OiP8lkQ3exk+sLDf4awF4WHNTpRB0ByqPdPgHXLl4mJNtqg2VTi4MyA6OogVxxNwVAsW1ED3bQ4SKdQqFt/hRVd7GCIaSJs3gqgqgn2AtBBV0hPFMM0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de; spf=pass smtp.mailfrom=linutronix.de; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=WrNG4lse; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=Zq1WZ9Wz; arc=none smtp.client-ip=193.142.43.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linutronix.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="WrNG4lse"; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="Zq1WZ9Wz" Date: Wed, 22 Jul 2026 18:58:14 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1784746696; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ThWd5v4a5rfCyENR/P8Q2vk+iDDMlFdzYidKF1+5HBk=; b=WrNG4lsexEpvbiNbFyGSghzBwHrlYfJf+Q1xisptea3yuC8zx5bWe2wOo+8PqVMVOfQzyl o4wfSDAKg1AlLfYuqBUZnyIKPNeuJrl+FB0nLAwomU7D/FK4HNOX9ZAlgVFhlDE8ueq+IJ kaJTbYv0gEwQWCtNztqVoRs2YRBk/bYIXR11dO5po0wNJB35sTXXcpktzHN8D/gLLN9D2G KI49JsEthiSr0NXoP7LkW2dg1xMTLQxNa3by4e85AQR3gdcmBz9c8eU/xzmU+gXHsvCu/O hOsLd3BsJIg2D65M4/3khtuRJxl66neFBFcEUCp92qSmMSlI8uNxsK62iED7vg== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1784746696; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ThWd5v4a5rfCyENR/P8Q2vk+iDDMlFdzYidKF1+5HBk=; b=Zq1WZ9Wz+CPqOvqirUGWa8OI+m6fpzawD/ASaC1+1dG9MM+F7Ny0pHgBCNfNwiJGakjiY+ B5VOYwDmLiVssGAg== From: "tip-bot2 for Chuyi Zhou" Sender: tip-bot2@linutronix.de Reply-to: linux-kernel@vger.kernel.org To: linux-tip-commits@vger.kernel.org Subject: [tip: smp/urgent] smp: Avoid invalid per-CPU CSD lookup with CSD lock debug Cc: Chuyi Zhou , "Paul E. McKenney" , Thomas Gleixner , Muchun Song , x86@kernel.org, linux-kernel@vger.kernel.org In-Reply-To: <20260716004539.13983-1-paulmck@kernel.org> References: <20260716004539.13983-1-paulmck@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-ID: <178474669466.2943223.12474189073138222320.tip-bot2@tip-bot2> Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails Precedence: bulk Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The following commit has been merged into the smp/urgent branch of tip: Commit-ID: c58ea9adf7342508c6ac0b7ad79ef10d589f9c6e Gitweb: https://git.kernel.org/tip/c58ea9adf7342508c6ac0b7ad79ef10d5= 89f9c6e Author: Chuyi Zhou AuthorDate: Wed, 15 Jul 2026 17:45:38 -07:00 Committer: Thomas Gleixner CommitterDate: Wed, 22 Jul 2026 20:57:07 +02:00 smp: Avoid invalid per-CPU CSD lookup with CSD lock debug Commit b0473dcd4b1d ("smp: Improve smp_call_function_single() CSD-lock diagnostics") made smp_call_function_single() use the destination CPU's csd_data when CSD lock debugging is enabled. That lets the debug code associate a stuck CSD lock with the target CPU, but it also means the CPU argument is used in per_cpu_ptr() before generic_exec_single() has a chance to validate it. This becomes unsafe when smp_call_function_any() cannot find an online CPU in the supplied mask. In that case the selected CPU can be nr_cpu_ids, and the !wait path calls get_single_csd_data(cpu) before generic_exec_single() returns -ENXIO. With csdlock_debug_enabled set, that indexes the per-CPU offset array with an invalid CPU number. Use the destination CPU's csd_data only when the CPU number is within nr_cpu_ids. For invalid CPU numbers, fall back to the local CPU's csd_data and let generic_exec_single() perform the existing validation and return -ENXIO. Fixes: b0473dcd4b1d ("smp: Improve smp_call_function_single() CSD-lock diag= nostics") Signed-off-by: Chuyi Zhou Signed-off-by: Paul E. McKenney Signed-off-by: Thomas Gleixner Reviewed-by: Paul E. McKenney Acked-by: Muchun Song Link: https://patch.msgid.link/20260716004539.13983-1-paulmck@kernel.org --- kernel/smp.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/kernel/smp.c b/kernel/smp.c index a0bb56b..dc6582b 100644 --- a/kernel/smp.c +++ b/kernel/smp.c @@ -380,7 +380,8 @@ static DEFINE_PER_CPU_SHARED_ALIGNED(call_single_data_t= , csd_data); #ifdef CONFIG_CSD_LOCK_WAIT_DEBUG static call_single_data_t *get_single_csd_data(int cpu) { - if (static_branch_unlikely(&csdlock_debug_enabled)) + if (static_branch_unlikely(&csdlock_debug_enabled) && + (unsigned int)cpu < nr_cpu_ids) return per_cpu_ptr(&csd_data, cpu); return this_cpu_ptr(&csd_data); }