From nobody Tue Sep 29 08:26:17 2026 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3800C299920; Mon, 10 Aug 2026 15:53:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.142.43.55 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786377215; cv=none; b=VPjW5ddVjDXIBqS6VyrwSWK1v58toWPkGt9OiTC4GNUQdG99u8st/CPdch599TXFcrVo8yE9rUZHSUN5uH64xtRrJQ8x7LYhOxWxTbHRt6mgLeniq2FHMBDFUsCRQhm+bKdsYkzCuzoCSiBjoGsL9L3Lfg5k3ZmShEjG0rb6zMQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786377215; c=relaxed/simple; bh=j0PrJVcDBScxmEHqrVTUUUui4a0atENg2Q2PJrnKOkU=; h=Date:From:To:Subject:Cc:In-Reply-To:References:MIME-Version: Message-ID:Content-Type; b=E2bFw4Q5YrdnJSdmNBWXesPW/c/0e7ov36gG4CbBYaYUgyRqyMVW3jxi8Kiz5LtgHI/G/jeU9pNX44Q7zjJ8rtdLS4pan4B0vUMXo2BrxanhIcbyQ5fTmwi3Kf5Agu7VlE0BGSgOz8+o+fr7/YjYfcbC5ISuDLrbHvswfJkOUSQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de; spf=pass smtp.mailfrom=linutronix.de; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=bJbVI1pn; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=NoDC7RxV; arc=none smtp.client-ip=193.142.43.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linutronix.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="bJbVI1pn"; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="NoDC7RxV" Date: Mon, 10 Aug 2026 15:53:30 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1786377211; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=SvPVQ6OKNChOCGJRdxQGAiyeZRWSNHs+YW9pOYAeRjI=; b=bJbVI1pnXkBhRoDXVY08fC9XAY5GD0zltqsX3zPV5Rl02VSzTWflsEjWjhjeCHYfHwJN4H 71TS+fV9znZpioNIncEJl/kaWDJOpb7ZHnglCqDZiBHRraCb6tCbH30cWeD5qwe4w1Eo5N EPB94eIvr0HPmdg/21h7I76LHSqeWJ8nvus79BREY9DlhtEs6pL9NbBknGDP0kt/Iti17a 7dcnmUo2au2o7+mcm7OHXeOE64EHnrL5xL6UXHmFljf/z3UKamKoIWN6wq/QhLL9uZDjAP 7IEzi7iGjvL7zIjGL6US5MZKuI0bNL/mJhrzymbeyHhVg9O2TYxjTCI0QqL4yQ== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1786377211; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=SvPVQ6OKNChOCGJRdxQGAiyeZRWSNHs+YW9pOYAeRjI=; b=NoDC7RxVOw/oCYIZw8ycmjGp9aHZLeXJKHgGohfl2H/VMZF3LR74wHX7SizDC9RHes5iB1 69y1wwvAw0fIV9Bw== From: "tip-bot2 for Dennis Moshegov" Sender: tip-bot2@linutronix.de Reply-to: linux-kernel@vger.kernel.org To: linux-tip-commits@vger.kernel.org Subject: [tip: timers/core] timekeeping: Use READ_ONCE/WRITE_ONCE() for xtime_sec to prevent tearing Cc: syzbot+72789cd1697965e714ca@syzkaller.appspotmail.com, Dennis Moshegov , Thomas Gleixner , x86@kernel.org, linux-kernel@vger.kernel.org In-Reply-To: <20260724154405.70-1-dennis@xzync.uk> References: <20260724154405.70-1-dennis@xzync.uk> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-ID: <178637721001.442315.6044624997355316731.tip-bot2@tip-bot2> Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails Precedence: bulk Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The following commit has been merged into the timers/core branch of tip: Commit-ID: d7fc133bf91f713df72facebd41ae9dfc83e35f7 Gitweb: https://git.kernel.org/tip/d7fc133bf91f713df72facebd41ae9dfc= 83e35f7 Author: Dennis Moshegov AuthorDate: Fri, 24 Jul 2026 16:43:55 +01:00 Committer: Thomas Gleixner CommitterDate: Mon, 10 Aug 2026 17:52:19 +02:00 timekeeping: Use READ_ONCE/WRITE_ONCE() for xtime_sec to prevent tearing The timekeeper update path uses a bulk memcpy() to synchronize the timekeeper structure, which is not guaranteed to be atomic. This allows for torn reads in ktime_get_real_seconds() on 64-bit systems, where the sequence counter protection is bypassed for performance. To prevent reading a torn 64-bit xtime_sec value, enforce atomic-like access by using WRITE_ONCE() for the critical field before the bulk memcpy() in timekeeping_update_from_shadow(). Correspondingly, use READ_ONCE() in ktime_get_real_seconds() to ensure a fresh, consistent load from memory. [ tglx: Format changelog and add comment ] Reported-by: syzbot+72789cd1697965e714ca@syzkaller.appspotmail.com Signed-off-by: Dennis Moshegov Signed-off-by: Thomas Gleixner Link: https://patch.msgid.link/20260724154405.70-1-dennis@xzync.uk Closes: https://syzkaller.appspot.com/bug?extid=3D72789cd1697965e714ca --- kernel/time/timekeeping.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/kernel/time/timekeeping.c b/kernel/time/timekeeping.c index 97db2e9..c4230f4 100644 --- a/kernel/time/timekeeping.c +++ b/kernel/time/timekeeping.c @@ -858,7 +858,11 @@ static void timekeeping_update_from_shadow(struct tk_d= ata *tkd, unsigned int act * the downside that the reader side does not longer benefit from * the cacheline optimized data layout of the timekeeper and requires * another indirection. + * + * Write xtime_sec first so that even if the memcpy() tears the store + * data integrity is provided for ktime_get_real_seconds(). */ + WRITE_ONCE(tkd->timekeeper.xtime_sec, tk->xtime_sec); memcpy(&tkd->timekeeper, tk, sizeof(*tk)); write_seqcount_end(&tkd->seq); } @@ -1186,11 +1190,11 @@ time64_t ktime_get_real_seconds(void) unsigned int seq; =20 if (IS_ENABLED(CONFIG_64BIT)) - return tk->xtime_sec; + return READ_ONCE(tk->xtime_sec); =20 do { seq =3D read_seqcount_begin(&tk_core.seq); - seconds =3D tk->xtime_sec; + seconds =3D READ_ONCE(tk->xtime_sec); =20 } while (read_seqcount_retry(&tk_core.seq, seq)); =20 @@ -1212,7 +1216,7 @@ noinstr time64_t __ktime_get_real_seconds(void) { struct timekeeper *tk =3D &tk_core.timekeeper; =20 - return tk->xtime_sec; + return READ_ONCE(tk->xtime_sec); } =20 static inline u64 tk_clock_read_snapshot(const struct tk_read_base *tkr,