From nobody Mon Jun 22 15:24:23 2026 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0CE09C433EF for ; Tue, 22 Mar 2022 00:28:51 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234289AbiCVAaP (ORCPT ); Mon, 21 Mar 2022 20:30:15 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:43012 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S234272AbiCVAaG (ORCPT ); Mon, 21 Mar 2022 20:30:06 -0400 Received: from smtp-fw-2101.amazon.com (smtp-fw-2101.amazon.com [72.21.196.25]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 67DF53612DC; Mon, 21 Mar 2022 17:28:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amazon.co.jp; i=@amazon.co.jp; q=dns/txt; s=amazon201209; t=1647908917; x=1679444917; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=agOxzUqDGtqlNdjLm8hNhKlsl9t7+j3Z8uIT1bwF42g=; b=pzZ2mISk0Q/TIEOZrxCoSBwiNcGO1r4L61hSSW57qK47RWfwyJ/HBCQ8 iMgqFsls6ryxRjrDom+UO0Xh5vjgP7dv890/kNlDIie8GZtAGZshK8Dxv M57O0/z9F+Xy9SDGihhRBKda0AqIvVaSbX1z5CyS+HLCKkyErOHRVYhwP I=; X-IronPort-AV: E=Sophos;i="5.90,200,1643673600"; d="scan'208";a="183375656" Received: from iad12-co-svc-p1-lb1-vlan2.amazon.com (HELO email-inbound-relay-iad-1d-9a235a16.us-east-1.amazon.com) ([10.43.8.2]) by smtp-border-fw-2101.iad2.amazon.com with ESMTP; 22 Mar 2022 00:28:33 +0000 Received: from EX13MTAUWB001.ant.amazon.com (iad12-ws-svc-p26-lb9-vlan3.iad.amazon.com [10.40.163.38]) by email-inbound-relay-iad-1d-9a235a16.us-east-1.amazon.com (Postfix) with ESMTPS id 52DCA81537; Tue, 22 Mar 2022 00:28:31 +0000 (UTC) Received: from EX13D04ANC001.ant.amazon.com (10.43.157.89) by EX13MTAUWB001.ant.amazon.com (10.43.161.207) with Microsoft SMTP Server (TLS) id 15.0.1497.32; Tue, 22 Mar 2022 00:28:30 +0000 Received: from 88665a182662.ant.amazon.com (10.43.160.180) by EX13D04ANC001.ant.amazon.com (10.43.157.89) with Microsoft SMTP Server (TLS) id 15.0.1497.32; Tue, 22 Mar 2022 00:28:26 +0000 From: Kuniyuki Iwashima To: Al Viro , Andrew Morton CC: Kuniyuki Iwashima , Kuniyuki Iwashima , , , Linus Torvalds Subject: [PATCH 1/2] pipe: Make poll_usage boolean and annotate its access. Date: Tue, 22 Mar 2022 09:26:52 +0900 Message-ID: <20220322002653.33865-2-kuniyu@amazon.co.jp> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20220322002653.33865-1-kuniyu@amazon.co.jp> References: <20220322002653.33865-1-kuniyu@amazon.co.jp> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Originating-IP: [10.43.160.180] X-ClientProxiedBy: EX13D45UWA004.ant.amazon.com (10.43.160.151) To EX13D04ANC001.ant.amazon.com (10.43.157.89) Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Type: text/plain; charset="utf-8" pipe_poll() runs locklessly and assigns 1 to poll_usage. Once poll_usage is set to 1, it never changes in other places. However, concurrent writes of a value trigger KCSAN, so let's make KCSAN happy. BUG: KCSAN: data-race in pipe_poll / pipe_poll write to 0xffff8880042f6678 of 4 bytes by task 174 on cpu 3: pipe_poll (fs/pipe.c:656) ep_item_poll.isra.0 (./include/linux/poll.h:88 fs/eventpoll.c:853) do_epoll_wait (fs/eventpoll.c:1692 fs/eventpoll.c:1806 fs/eventpoll.c:2234) __x64_sys_epoll_wait (fs/eventpoll.c:2246 fs/eventpoll.c:2241 fs/eventpoll= .c:2241) do_syscall_64 (arch/x86/entry/common.c:50 arch/x86/entry/common.c:80) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:113) write to 0xffff8880042f6678 of 4 bytes by task 177 on cpu 1: pipe_poll (fs/pipe.c:656) ep_item_poll.isra.0 (./include/linux/poll.h:88 fs/eventpoll.c:853) do_epoll_wait (fs/eventpoll.c:1692 fs/eventpoll.c:1806 fs/eventpoll.c:2234) __x64_sys_epoll_wait (fs/eventpoll.c:2246 fs/eventpoll.c:2241 fs/eventpoll= .c:2241) do_syscall_64 (arch/x86/entry/common.c:50 arch/x86/entry/common.c:80) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:113) Reported by Kernel Concurrency Sanitizer on: CPU: 1 PID: 177 Comm: epoll_race Not tainted 5.17.0-58927-gf443e374ae13 #6 Hardware name: Red Hat KVM, BIOS 1.11.0-2.amzn2 04/01/2014 Fixes: 3b844826b6c6 ("pipe: avoid unnecessary EPOLLET wakeups under normal = loads") Signed-off-by: Kuniyuki Iwashima --- CC: Linus Torvalds Note that the message is false positive for now, so the Fixes tag might not be necessary. --- fs/pipe.c | 2 +- include/linux/pipe_fs_i.h | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/fs/pipe.c b/fs/pipe.c index 9648ac151..e9f8290f8 100644 --- a/fs/pipe.c +++ b/fs/pipe.c @@ -653,7 +653,7 @@ pipe_poll(struct file *filp, poll_table *wait) unsigned int head, tail; =20 /* Epoll has some historical nasty semantics, this enables them */ - pipe->poll_usage =3D 1; + WRITE_ONCE(pipe->poll_usage, true); =20 /* * Reading pipe state only -- no need for acquiring the semaphore. diff --git a/include/linux/pipe_fs_i.h b/include/linux/pipe_fs_i.h index c00c618ef..cb0fd633a 100644 --- a/include/linux/pipe_fs_i.h +++ b/include/linux/pipe_fs_i.h @@ -71,7 +71,7 @@ struct pipe_inode_info { unsigned int files; unsigned int r_counter; unsigned int w_counter; - unsigned int poll_usage; + bool poll_usage; struct page *tmp_page; struct fasync_struct *fasync_readers; struct fasync_struct *fasync_writers; --=20 2.30.2 From nobody Mon Jun 22 15:24:23 2026 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 23F37C433EF for ; Tue, 22 Mar 2022 00:28:57 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234270AbiCVAaV (ORCPT ); Mon, 21 Mar 2022 20:30:21 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:43828 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S234272AbiCVAaS (ORCPT ); Mon, 21 Mar 2022 20:30:18 -0400 Received: from smtp-fw-9102.amazon.com (smtp-fw-9102.amazon.com [207.171.184.29]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id DB18F361A85; Mon, 21 Mar 2022 17:28:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amazon.co.jp; i=@amazon.co.jp; q=dns/txt; s=amazon201209; t=1647908932; x=1679444932; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=z1/Lf01ROKGSKNl7HGZbZ1PwqeyhtCw4pQnh4qOJV1o=; b=goHa8vW8O/L5Ngmo0JEZmZkEjF7NNaHxHL+zQGDRcjpg0GURk3EoaWlQ BOvLbENejDU+xO8G7q/6BVVybe027bD3jsHKwFL7DvDgHLBKHF7dK8h7x 97bTnE0pLNttRR0R/xrrffvaTlq/6+Mb23TXgWkBjdbdvGahicXmX2W1/ s=; X-IronPort-AV: E=Sophos;i="5.90,200,1643673600"; d="scan'208";a="204241028" Received: from pdx4-co-svc-p1-lb2-vlan3.amazon.com (HELO email-inbound-relay-iad-1a-2d7489a4.us-east-1.amazon.com) ([10.25.36.214]) by smtp-border-fw-9102.sea19.amazon.com with ESMTP; 22 Mar 2022 00:28:50 +0000 Received: from EX13MTAUWB001.ant.amazon.com (iad12-ws-svc-p26-lb9-vlan2.iad.amazon.com [10.40.163.34]) by email-inbound-relay-iad-1a-2d7489a4.us-east-1.amazon.com (Postfix) with ESMTPS id D0E9497D1A; Tue, 22 Mar 2022 00:28:47 +0000 (UTC) Received: from EX13D04ANC001.ant.amazon.com (10.43.157.89) by EX13MTAUWB001.ant.amazon.com (10.43.161.207) with Microsoft SMTP Server (TLS) id 15.0.1497.32; Tue, 22 Mar 2022 00:28:46 +0000 Received: from 88665a182662.ant.amazon.com (10.43.160.180) by EX13D04ANC001.ant.amazon.com (10.43.157.89) with Microsoft SMTP Server (TLS) id 15.0.1497.32; Tue, 22 Mar 2022 00:28:42 +0000 From: Kuniyuki Iwashima To: Al Viro , Andrew Morton CC: Kuniyuki Iwashima , Kuniyuki Iwashima , , , , "Soheil Hassas Yeganeh" , Davidlohr Bueso , "Sridhar Samudrala" , Alexander Duyck Subject: [PATCH 2/2] list: Fix a data-race around ep->rdllist. Date: Tue, 22 Mar 2022 09:26:53 +0900 Message-ID: <20220322002653.33865-3-kuniyu@amazon.co.jp> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20220322002653.33865-1-kuniyu@amazon.co.jp> References: <20220322002653.33865-1-kuniyu@amazon.co.jp> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Originating-IP: [10.43.160.180] X-ClientProxiedBy: EX13D45UWA004.ant.amazon.com (10.43.160.151) To EX13D04ANC001.ant.amazon.com (10.43.157.89) Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Type: text/plain; charset="utf-8" ep_poll() first calls ep_events_available() with no lock held and checks if ep->rdllist is empty by list_empty_careful(), which reads rdllist->prev. Thus all accesses to it need some protection to avoid store/load-tearing. Note INIT_LIST_HEAD_RCU() already has the annotation for both prev and next. Commit bf3b9f6372c4 ("epoll: Add busy poll support to epoll with socket fds.") added the first lockless ep_events_available(), and commit c5a282e9635e ("fs/epoll: reduce the scope of wq lock in epoll_wait()") made some ep_events_available() calls lockless and added single call under a lock, finally commit e59d3c64cba6 ("epoll: eliminate unnecessary lock for zero timeout") made the last ep_events_available() lockless. BUG: KCSAN: data-race in do_epoll_wait / do_epoll_wait write to 0xffff88810480c7d8 of 8 bytes by task 1802 on cpu 0: INIT_LIST_HEAD include/linux/list.h:38 [inline] list_splice_init include/linux/list.h:492 [inline] ep_start_scan fs/eventpoll.c:622 [inline] ep_send_events fs/eventpoll.c:1656 [inline] ep_poll fs/eventpoll.c:1806 [inline] do_epoll_wait+0x4eb/0xf40 fs/eventpoll.c:2234 do_epoll_pwait fs/eventpoll.c:2268 [inline] __do_sys_epoll_pwait fs/eventpoll.c:2281 [inline] __se_sys_epoll_pwait+0x12b/0x240 fs/eventpoll.c:2275 __x64_sys_epoll_pwait+0x74/0x80 fs/eventpoll.c:2275 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x44/0xd0 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x44/0xae read to 0xffff88810480c7d8 of 8 bytes by task 1799 on cpu 1: list_empty_careful include/linux/list.h:329 [inline] ep_events_available fs/eventpoll.c:381 [inline] ep_poll fs/eventpoll.c:1797 [inline] do_epoll_wait+0x279/0xf40 fs/eventpoll.c:2234 do_epoll_pwait fs/eventpoll.c:2268 [inline] __do_sys_epoll_pwait fs/eventpoll.c:2281 [inline] __se_sys_epoll_pwait+0x12b/0x240 fs/eventpoll.c:2275 __x64_sys_epoll_pwait+0x74/0x80 fs/eventpoll.c:2275 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x44/0xd0 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x44/0xae value changed: 0xffff88810480c7d0 -> 0xffff888103c15098 Reported by Kernel Concurrency Sanitizer on: CPU: 1 PID: 1799 Comm: syz-fuzzer Tainted: G W 5.17.0-rc7-sy= zkaller-dirty #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Goo= gle 01/01/2011 Fixes: e59d3c64cba6 ("epoll: eliminate unnecessary lock for zero timeout") Fixes: c5a282e9635e ("fs/epoll: reduce the scope of wq lock in epoll_wait()= ") Fixes: bf3b9f6372c4 ("epoll: Add busy poll support to epoll with socket fds= .") Reported-by: syzbot+bdd6e38a1ed5ee58d8bd@syzkaller.appspotmail.com Signed-off-by: Kuniyuki Iwashima --- CC: Soheil Hassas Yeganeh CC: Davidlohr Bueso CC: Sridhar Samudrala CC: Alexander Duyck --- include/linux/list.h | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/include/linux/list.h b/include/linux/list.h index dd6c2041d..d7d2bfa1a 100644 --- a/include/linux/list.h +++ b/include/linux/list.h @@ -35,7 +35,7 @@ static inline void INIT_LIST_HEAD(struct list_head *list) { WRITE_ONCE(list->next, list); - list->prev =3D list; + WRITE_ONCE(list->prev, list); } =20 #ifdef CONFIG_DEBUG_LIST @@ -306,7 +306,7 @@ static inline int list_empty(const struct list_head *he= ad) static inline void list_del_init_careful(struct list_head *entry) { __list_del_entry(entry); - entry->prev =3D entry; + WRITE_ONCE(entry->prev, entry); smp_store_release(&entry->next, entry); } =20 @@ -326,7 +326,7 @@ static inline void list_del_init_careful(struct list_he= ad *entry) static inline int list_empty_careful(const struct list_head *head) { struct list_head *next =3D smp_load_acquire(&head->next); - return list_is_head(next, head) && (next =3D=3D head->prev); + return list_is_head(next, head) && (next =3D=3D READ_ONCE(head->prev)); } =20 /** --=20 2.30.2