[PATCH -tip] locking/rtmutex: Skip remove_waiter() when waiter is not enqueued

Davidlohr Bueso posted 1 patch 1 month, 1 week ago
There is a newer version of this series
kernel/locking/rtmutex.c     | 3 +++
kernel/locking/rtmutex_api.c | 2 +-
2 files changed, 4 insertions(+), 1 deletion(-)
[PATCH -tip] locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
Posted by Davidlohr Bueso 1 month, 1 week ago
syzbot triggered the following splat in remove_waiter() via
FUTEX_CMP_REQUEUE_PI:

  KASAN: null-ptr-deref in range [0x0000000000000a88-0x0000000000000a8f]
   class_raw_spinlock_constructor
   remove_waiter+0x159/0x1200 kernel/locking/rtmutex.c:1561
   rt_mutex_start_proxy_lock+0x103/0x120
   futex_requeue+0x10e4/0x20d0
   __x64_sys_futex+0x34f/0x4d0

task_blocks_on_rt_mutex() does not arm the waiter upon deadlock detection,
leaving waiter->task nil, where 3bfdc63936dd ("rtmutex: Use waiter::task instead
of current in remove_waiter()") made this fatal.

Furthermore, rt_mutex_start_proxy_lock() should not be calling into remove_waiter()
upon a successfully grabbing the rtmutex. 1a1fb985f2e2 ("futex: Handle early deadlock
return correctly"), moved the remove_waiter() out of __rt_mutex_start_proxy_lock()
(where 'ret' was only ever 0 or < 0) into the wrapper. Tighten this check to
account for try_to_take_rt_mutex().

Fixes: 3bfdc63936dd ("rtmutex: Use waiter::task instead of current in remove_waiter()")
Link: https://lore.kernel.org/all/69f114ac.050a0220.ac8b.0003.GAE@google.com/
Reported-by: syzbot+78147abe6c524f183ee9@syzkaller.appspotmail.com
Signed-off-by: Davidlohr Bueso <dave@stgolabs.net>
---
 kernel/locking/rtmutex.c     | 3 +++
 kernel/locking/rtmutex_api.c | 2 +-
 2 files changed, 4 insertions(+), 1 deletion(-)

diff --git a/kernel/locking/rtmutex.c b/kernel/locking/rtmutex.c
index 4f386ea6c792..daeeeef973e2 100644
--- a/kernel/locking/rtmutex.c
+++ b/kernel/locking/rtmutex.c
@@ -1558,6 +1558,9 @@ static void __sched remove_waiter(struct rt_mutex_base *lock,
 
 	lockdep_assert_held(&lock->wait_lock);
 
+	if (!waiter_task) /* never enqueued */
+		return;
+
 	scoped_guard(raw_spinlock, &waiter_task->pi_lock) {
 		rt_mutex_dequeue(lock, waiter);
 		waiter_task->pi_blocked_on = NULL;
diff --git a/kernel/locking/rtmutex_api.c b/kernel/locking/rtmutex_api.c
index 124219aea46e..514fce7a4e0a 100644
--- a/kernel/locking/rtmutex_api.c
+++ b/kernel/locking/rtmutex_api.c
@@ -365,7 +365,7 @@ int __sched rt_mutex_start_proxy_lock(struct rt_mutex_base *lock,
 
 	raw_spin_lock_irq(&lock->wait_lock);
 	ret = __rt_mutex_start_proxy_lock(lock, waiter, task, &wake_q);
-	if (unlikely(ret))
+	if (unlikely(ret < 0))
 		remove_waiter(lock, waiter);
 	preempt_disable();
 	raw_spin_unlock_irq(&lock->wait_lock);
-- 
2.39.5
Re: [PATCH -tip] locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
Posted by Davidlohr Bueso 1 week, 2 days ago
ping

On Thu, 07 May 2026, Davidlohr Bueso wrote:

>syzbot triggered the following splat in remove_waiter() via
>FUTEX_CMP_REQUEUE_PI:
>
>  KASAN: null-ptr-deref in range [0x0000000000000a88-0x0000000000000a8f]
>   class_raw_spinlock_constructor
>   remove_waiter+0x159/0x1200 kernel/locking/rtmutex.c:1561
>   rt_mutex_start_proxy_lock+0x103/0x120
>   futex_requeue+0x10e4/0x20d0
>   __x64_sys_futex+0x34f/0x4d0
>
>task_blocks_on_rt_mutex() does not arm the waiter upon deadlock detection,
>leaving waiter->task nil, where 3bfdc63936dd ("rtmutex: Use waiter::task instead
>of current in remove_waiter()") made this fatal.
>
>Furthermore, rt_mutex_start_proxy_lock() should not be calling into remove_waiter()
>upon a successfully grabbing the rtmutex. 1a1fb985f2e2 ("futex: Handle early deadlock
>return correctly"), moved the remove_waiter() out of __rt_mutex_start_proxy_lock()
>(where 'ret' was only ever 0 or < 0) into the wrapper. Tighten this check to
>account for try_to_take_rt_mutex().
>
>Fixes: 3bfdc63936dd ("rtmutex: Use waiter::task instead of current in remove_waiter()")
>Link: https://lore.kernel.org/all/69f114ac.050a0220.ac8b.0003.GAE@google.com/
>Reported-by: syzbot+78147abe6c524f183ee9@syzkaller.appspotmail.com
>Signed-off-by: Davidlohr Bueso <dave@stgolabs.net>
>---
> kernel/locking/rtmutex.c     | 3 +++
> kernel/locking/rtmutex_api.c | 2 +-
> 2 files changed, 4 insertions(+), 1 deletion(-)
>
>diff --git a/kernel/locking/rtmutex.c b/kernel/locking/rtmutex.c
>index 4f386ea6c792..daeeeef973e2 100644
>--- a/kernel/locking/rtmutex.c
>+++ b/kernel/locking/rtmutex.c
>@@ -1558,6 +1558,9 @@ static void __sched remove_waiter(struct rt_mutex_base *lock,
>
> 	lockdep_assert_held(&lock->wait_lock);
>
>+	if (!waiter_task) /* never enqueued */
>+		return;
>+
> 	scoped_guard(raw_spinlock, &waiter_task->pi_lock) {
> 		rt_mutex_dequeue(lock, waiter);
> 		waiter_task->pi_blocked_on = NULL;
>diff --git a/kernel/locking/rtmutex_api.c b/kernel/locking/rtmutex_api.c
>index 124219aea46e..514fce7a4e0a 100644
>--- a/kernel/locking/rtmutex_api.c
>+++ b/kernel/locking/rtmutex_api.c
>@@ -365,7 +365,7 @@ int __sched rt_mutex_start_proxy_lock(struct rt_mutex_base *lock,
>
> 	raw_spin_lock_irq(&lock->wait_lock);
> 	ret = __rt_mutex_start_proxy_lock(lock, waiter, task, &wake_q);
>-	if (unlikely(ret))
>+	if (unlikely(ret < 0))
> 		remove_waiter(lock, waiter);
> 	preempt_disable();
> 	raw_spin_unlock_irq(&lock->wait_lock);
>-- 
>2.39.5
>
[tip: locking/urgent] locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
Posted by tip-bot2 for Davidlohr Bueso 1 week, 2 days ago
The following commit has been merged into the locking/urgent branch of tip:

Commit-ID:     40a25d59e85b3c8709ac2424d44f65610467871e
Gitweb:        https://git.kernel.org/tip/40a25d59e85b3c8709ac2424d44f65610467871e
Author:        Davidlohr Bueso <dave@stgolabs.net>
AuthorDate:    Thu, 07 May 2026 04:29:13 -07:00
Committer:     Thomas Gleixner <tglx@kernel.org>
CommitterDate: Wed, 03 Jun 2026 22:11:53 +02:00

locking/rtmutex: Skip remove_waiter() when waiter is not enqueued

syzbot triggered the following splat in remove_waiter() via
FUTEX_CMP_REQUEUE_PI:

  KASAN: null-ptr-deref in range [0x0000000000000a88-0x0000000000000a8f]
   class_raw_spinlock_constructor
   remove_waiter+0x159/0x1200 kernel/locking/rtmutex.c:1561
   rt_mutex_start_proxy_lock+0x103/0x120
   futex_requeue+0x10e4/0x20d0
   __x64_sys_futex+0x34f/0x4d0

task_blocks_on_rt_mutex() does not arm the waiter upon deadlock detection,
leaving waiter->task nil, where 3bfdc63936dd ("rtmutex: Use waiter::task instead
of current in remove_waiter()") made this fatal.

Furthermore, rt_mutex_start_proxy_lock() should not be calling into remove_waiter()
upon a successfully grabbing the rtmutex. 1a1fb985f2e2 ("futex: Handle early deadlock
return correctly"), moved the remove_waiter() out of __rt_mutex_start_proxy_lock()
(where 'ret' was only ever 0 or < 0) into the wrapper. Tighten this check to
account for try_to_take_rt_mutex().

Fixes: 3bfdc63936dd ("rtmutex: Use waiter::task instead of current in remove_waiter()")
Reported-by: syzbot+78147abe6c524f183ee9@syzkaller.appspotmail.com
Signed-off-by: Davidlohr Bueso <dave@stgolabs.net>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Cc: stable@vger.kernel.org
Closes: https://lore.kernel.org/all/69f114ac.050a0220.ac8b.0003.GAE@google.com/
Link: https://patch.msgid.link/20260507112913.1019537-1-dave@stgolabs.net
---
 kernel/locking/rtmutex.c     | 3 +++
 kernel/locking/rtmutex_api.c | 2 +-
 2 files changed, 4 insertions(+), 1 deletion(-)

diff --git a/kernel/locking/rtmutex.c b/kernel/locking/rtmutex.c
index 4f386ea..daeeeef 100644
--- a/kernel/locking/rtmutex.c
+++ b/kernel/locking/rtmutex.c
@@ -1558,6 +1558,9 @@ static void __sched remove_waiter(struct rt_mutex_base *lock,
 
 	lockdep_assert_held(&lock->wait_lock);
 
+	if (!waiter_task) /* never enqueued */
+		return;
+
 	scoped_guard(raw_spinlock, &waiter_task->pi_lock) {
 		rt_mutex_dequeue(lock, waiter);
 		waiter_task->pi_blocked_on = NULL;
diff --git a/kernel/locking/rtmutex_api.c b/kernel/locking/rtmutex_api.c
index 124219a..514fce7 100644
--- a/kernel/locking/rtmutex_api.c
+++ b/kernel/locking/rtmutex_api.c
@@ -365,7 +365,7 @@ int __sched rt_mutex_start_proxy_lock(struct rt_mutex_base *lock,
 
 	raw_spin_lock_irq(&lock->wait_lock);
 	ret = __rt_mutex_start_proxy_lock(lock, waiter, task, &wake_q);
-	if (unlikely(ret))
+	if (unlikely(ret < 0))
 		remove_waiter(lock, waiter);
 	preempt_disable();
 	raw_spin_unlock_irq(&lock->wait_lock);