From nobody Fri Oct 2 01:10:34 2026 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 89D261990A7; Thu, 6 Aug 2026 12:48:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.142.43.55 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786020498; cv=none; b=PgAFN1GOAUiFGbbX1tULyZv4NOKAKJR7tRJPXdzVKiGA5bFHJO7wpqTlQVdmESRxPq3zW2EdEWs0jZUlHM9iepGdm4VIpZUpjOGKxYigB2W5MUZOYps2HoVqbVDaphMs1VG4flevk/f8ijyjdM/z4fVCCEWmXFIkuRF12eWa3cg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786020498; c=relaxed/simple; bh=c1HiCfygsjDSLwtQn/Pr89FJD3FyF6Cks2+bSYzXQmw=; h=Date:From:To:Subject:Cc:In-Reply-To:References:MIME-Version: Message-ID:Content-Type; b=JhzYnMkrQpgfXtsmS3tuCMlmzZ7cSEDqO5bMg/i1/vFoCD8ijsbg/J2GCVreOKxYTiGGcyFT7XXDrrd/SPfDWd9ESGjXcQyEcekbCClkjl8Zoj5VZ62dawZ4kRn/vvoSJJ06ibQIwpUx6Hf5QsSJXnqUqwkFaMcbU/AjqXBwI9c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de; spf=pass smtp.mailfrom=linutronix.de; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=Sn7nQmnd; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=SJnv5o00; arc=none smtp.client-ip=193.142.43.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linutronix.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="Sn7nQmnd"; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="SJnv5o00" Date: Thu, 06 Aug 2026 12:48:05 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1786020487; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Rlj3tsPCJWoD83ZoC32aLV+lxtViSr6TCi2y42mp0l0=; b=Sn7nQmnd4oDkdOi8AQgb8ha7ufw5fGF38IwrlYjZpd3gXGSBYtlZtXrM005Gduhv6KVKBd axxlVNZGuKdTsafW9C+9JGruNANCAJesTrC31lZH28Qh+WDyVtKgZRzGrMAjjHtr27yROK YY+RJ8j/++YHnYZPlzXDVGfxUBY4yiRQSMCPsH5yxYgpGcQttvmoPl6ZRRjBSS4BhKOiHk 1+8Ci2Eo9MOJyvch9R/gXv+3a7wklT+7zkMaBqOc52VqPVljk4aa6QiSB8z1WJvqxQGi7d ji2GyXLmb+msaseY1fvKC15uKc3DzMvEmC0GG/ZDUa572tuUGpyOJL2LBynBPA== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1786020487; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Rlj3tsPCJWoD83ZoC32aLV+lxtViSr6TCi2y42mp0l0=; b=SJnv5o00KH8r74vVaWBuiJJ+j4nsrBmPb1ZXc5XCdha8XSlyNRPwdcbkEguTB6xnzxGrss niXR3hLMdYFstyAw== From: "tip-bot2 for Niels Pressel" Sender: tip-bot2@linutronix.de Reply-to: linux-kernel@vger.kernel.org To: linux-tip-commits@vger.kernel.org Subject: [tip: core/urgent] entry/rseq: Fix hard lockup on granted time slice extension Cc: Niels Pressel , "Peter Zijlstra (Intel)" , x86@kernel.org, linux-kernel@vger.kernel.org In-Reply-To: <20260806113429.38333-1-npressel@ethz.ch> References: <20260806113429.38333-1-npressel@ethz.ch> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-ID: <178602048581.708.11608729612787939146.tip-bot2@tip-bot2> Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails Precedence: bulk Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The following commit has been merged into the core/urgent branch of tip: Commit-ID: f81845889e128d2e5f8f2f38eb7339cc74640f4f Gitweb: https://git.kernel.org/tip/f81845889e128d2e5f8f2f38eb7339cc7= 4640f4f Author: Niels Pressel AuthorDate: Thu, 06 Aug 2026 13:34:29 +02:00 Committer: Peter Zijlstra CommitterDate: Thu, 06 Aug 2026 14:42:22 +02:00 entry/rseq: Fix hard lockup on granted time slice extension In __exit_to_user_mode_loop(), TSE eligibility is checked while IRQs are enabled. Granting a TSE might involve rearming the hrtimers. However, hrtimer_rearm_deferred_tif() is expected to be called with IRQs disabled (see include/linux/hrtimer_rearm.h:17). Calling the function with IRQs enabled can lead to a hard lockup because __hrtimer_rearm_deferred() acquires a raw spinlock (without disabling IRQs) that is also acquired in hard IRQ context within hrtimer_run_queues(). Lockdep flags the issue when running the rseq selftests on the 7.2-rc5 release: WARNING: ./include/linux/hrtimer_rearm.h:17 at irqentry_exit, CPU#1: sl= ice_test Originally, the issue was discovered because of intermittent lockups when heavily using rseq TSEs. Following the suggestion from Peter Zijlstra, fix this potential lockup by reflowing __exit_to_user_mode_loop() to only enable IRQs after the TSE check. Fixes: 15dd3a948855 ("hrtimer: Push reprogramming timers into the interrupt= return path") Signed-off-by: Niels Pressel Signed-off-by: Peter Zijlstra (Intel) Link: https://patch.msgid.link/20260806113429.38333-1-npressel@ethz.ch --- include/linux/rseq_entry.h | 8 ++++---- kernel/entry/common.c | 10 +++++----- 2 files changed, 9 insertions(+), 9 deletions(-) diff --git a/include/linux/rseq_entry.h b/include/linux/rseq_entry.h index ed9da6e..772e72d 100644 --- a/include/linux/rseq_entry.h +++ b/include/linux/rseq_entry.h @@ -132,6 +132,8 @@ static __always_inline bool __rseq_grant_slice_extensio= n(bool work_pending) union rseq_slice_state state; struct rseq __user *rseq; =20 + lockdep_assert_irqs_disabled(); + if (!rseq_slice_extension_enabled()) return false; =20 @@ -219,10 +221,8 @@ static __always_inline bool __rseq_grant_slice_extensi= on(bool work_pending) * * which would be inconsistent state. */ - scoped_guard(irq) { - clear_tsk_need_resched(curr); - clear_preempt_need_resched(); - } + clear_tsk_need_resched(curr); + clear_preempt_need_resched(); return true; =20 efault: diff --git a/kernel/entry/common.c b/kernel/entry/common.c index e3d381f..e7dae46 100644 --- a/kernel/entry/common.c +++ b/kernel/entry/common.c @@ -47,13 +47,13 @@ static __always_inline unsigned long __exit_to_user_mod= e_loop(struct pt_regs *re * items have been completed. */ while (ti_work & EXIT_TO_USER_MODE_WORK_LOOP) { - + /* Check rseq slice extensions with IRQs disabled */ + bool sched =3D (ti_work & (_TIF_NEED_RESCHED | _TIF_NEED_RESCHED_LAZY)) = && + !rseq_grant_slice_extension(ti_work, TIF_SLICE_EXT_DENY); local_irq_enable(); =20 - if (ti_work & (_TIF_NEED_RESCHED | _TIF_NEED_RESCHED_LAZY)) { - if (!rseq_grant_slice_extension(ti_work, TIF_SLICE_EXT_DENY)) - schedule(); - } + if (sched) + schedule(); =20 if (ti_work & _TIF_UPROBE) uprobe_notify_resume(regs);