From nobody Fri Oct 2 04:35:51 2026 Received: from stravinsky.debian.org (stravinsky.debian.org [82.195.75.108]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B1B723C3F60 for ; Wed, 5 Aug 2026 11:17:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=82.195.75.108 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785928679; cv=none; b=ji0cULjjzZjZQ8g7yGvUdzQqQg/JBQg4hTsn3lwpyYbS8s1wH+ZJENC0Rhpm0uLqOeKPElOIYcD9dT9EhIrB9yZYz4S05bl4uMI40rFu5LR+x8duha8nduJJg+G7C6Z0zQM2S5xGRDZ7qsvZVmH6HQJcqEfZG/Jp66tzgUdjwLI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785928679; c=relaxed/simple; bh=aYyYcz8LHElOYB6R48TEUlid8SRHbqGJHcybEVfiwFQ=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:To:Cc; b=LsQb+4xe0x4NaGRXC2/0PCBdPp4mano4LyOqrOHO89hKilAp1zVVIzecKnvw4q0Gv5ZvGshBVAxClBXwDpLu0i/SMo3jQ64euNMldT8Jyol/UW9neSzeMVQjZkzNU8PP6OlIDU4eZ3nTecZ7REXIyT5aFSFbDcG2SSlNpNHMYkE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=debian.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b=PSidPtm3; arc=none smtp.client-ip=82.195.75.108 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=debian.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b="PSidPtm3" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.stravinsky; h=X-Debian-User:Cc:To:Message-Id: Content-Transfer-Encoding:Content-Type:MIME-Version:Subject:Date:From: Reply-To:Content-ID:Content-Description:In-Reply-To:References; bh=+qwfWU1mc77lcxz8moQIWA73WRf+PkzOR0qLz8Fo2D8=; b=PSidPtm3PHFmBSg8SxP4pMFNfQ cN+/FhsFPqCn4V7IrHufsv1TZswlBUOTeIsSSRd0T3KldSLJc1HlKUGxC/n/wHHXmddVA92GgoX39 TWGHz8y7Nd1oMoPcrQErMtJVTnSErpHNsJ8t5pIiyqI0iXedeoTm8Y0Kt7dBXz9enT1cEw3ZkRTVt oIRutgSuGk33oTLpe2L5JvcPEPVLjD2HBcYrXFz6cAgJiS6C3Vkhj542FZQK1ong7N/4woYE8JOeF wfurcThPn1hJCW9/jSC3o/Z4xRymdwtROhzcmrzxYDsoKbF5R5LlAN0xU6WkrRodOGIBieP0De4wO rH/yHDKA==; Received: from authenticated-user by stravinsky.debian.org with esmtpsa (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from ) id 1wrZdB-00DsXL-24; Wed, 05 Aug 2026 11:17:53 +0000 From: Breno Leitao Date: Wed, 05 Aug 2026 04:17:48 -0700 Subject: [PATCH] workqueue: read p->wake_cpu once in kick_pool_pick() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260805-wq_race_kick-v1-1-d55adc12416b@debian.org> X-B4-Tracking: v=1; b=H4sIANsbc2oC/x3MWwqAIBAF0K0M9zvBJCvcSkSITjUEPRQqiPYed BZwHmROwhmOHiQ+Jcu2wlFZEMLs14mVRDiC0abWrbbqOobkAw+LhEXFxrMNZWVsG1EQ9sSj3H/ X9e/7AaMLsRleAAAA X-Change-ID: 20260805-wq_race_kick-d7ae5c14258d To: Tejun Heo , Lai Jiangshan Cc: linux-kernel@vger.kernel.org, kernel-team@meta.com, Breno Leitao X-Mailer: b4 0.16-dev-f8e9d X-Developer-Signature: v=1; a=openpgp-sha256; l=1732; i=leitao@debian.org; h=from:subject:message-id; bh=aYyYcz8LHElOYB6R48TEUlid8SRHbqGJHcybEVfiwFQ=; b=owEBbQKS/ZANAwAIATWjk5/8eHdtAcsmYgBqcxveF5scEM+IBDBycfTizNWFK1WyipcP+uBbu IDuXBFw+3yJAjMEAAEIAB0WIQSshTmm6PRnAspKQ5s1o5Of/Hh3bQUCanMb3gAKCRA1o5Of/Hh3 bRZXD/9VzmP2NJbRno3mTlhuD4zTdi0jbejK3K7x7CjAxjWx0MV8Ogot7EnGTbvNGhv8qnAc3da FIwEhhaA39ltT/wouiFOynIrfqkO03TXCPRRzzjSHxGxmTRW5cD8jd617MYkEJfOUIfTNyMtzRj k6CIAjFAkdeCBDo031zCZtWqcPym6us2wEYtM31NcsQ4HjvCA7ipdjX3VL5JYeDlJekcfoYzcdE HSEkSDLSRvn4CgJfeyZ10672DJRO9mDlOp5BiOm0aKcEyX3lxv3IsYjqTylHvjKuL6kBhlX8Epw GE9XaF26csXrGubW3ASAab4IUUTELol/JbCC/xYfa7mqpLxEu2/1SFrJM81wUSPEgXElaEBeVFT ICu9r79tIHgQuD693AGpUcqA/L0Mgb0h4WthCltxIZaVsi7UnpY+o3ll1Na22Rv8K33Pimi2c9s A+drlm+bMuDIcpLEMx5Z5yc3TAmZ7PV/3qhWY9JPug1RaM6968nnHvQgv+wkSAyF535yG4p0BzE 8TMR7CHjLRUk5UL3U+B/CoYISRQVkHIe0EXE6N7fN7+8+8GhXXQCnI4RYZj/E6pnonS6YIZHoK+ mxzudJpQcKUGK7JazGWpgitpmYSoMWMCU2dvp5f/RkO6dMzXCKOW+rmmBNiayRzOMxmkFOYIYKk m8R9F8iv4mzo7hg== X-Developer-Key: i=leitao@debian.org; a=openpgp; fpr=AC8539A6E8F46702CA4A439B35A3939FFC78776D X-Debian-User: leitao kick_pool_pick() reads p->wake_cpu in a racy way with scheduler. This gets the following message in KCSAN BUG: KCSAN: data-race in kick_pool_pick+0xf8/0x2d8 race at unknown origin, with read to 0xffff000663229da4 of 4 bytes by task 1817002 on cpu 40: kick_pool_pick+0xf8/0x2d8 process_scheduled_works+0x2bc/0x888 worker_thread+0x394/0x548 kthread+0x1b8/0x1f0 ret_from_fork+0x10/0x20 value changed: 0x0000002b -> 0x0000002f Mark p->wake_cpu's read as READ_ONCE(p->wake_cpu), in order to a) avoid torn down reads, b) acknowledge this racy read, and c) silent KCSAN. Signed-off-by: Breno Leitao Reviewed-by: Bradley Morgan --- kernel/workqueue.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/kernel/workqueue.c b/kernel/workqueue.c index 26d5680c751c6..333752ac38298 100644 --- a/kernel/workqueue.c +++ b/kernel/workqueue.c @@ -1308,8 +1308,10 @@ static bool kick_pool_pick(struct worker_pool *pool,= struct task_struct **wakep) * If @pool has non-strict affinity, @worker might have ended up outside * its affinity scope. Repatriate. */ - if (!pool->attrs->affn_strict && - !cpumask_test_cpu(p->wake_cpu, pool->attrs->__pod_cpumask)) { + bool wake_cpu_in_pod =3D cpumask_test_cpu(READ_ONCE(p->wake_cpu), + pool->attrs->__pod_cpumask); + + if (!pool->attrs->affn_strict && !wake_cpu_in_pod) { struct work_struct *work =3D list_first_entry(&pool->worklist, struct work_struct, entry); int wake_cpu =3D cpumask_any_and_distribute(pool->attrs->__pod_cpumask, --- base-commit: 0f6da28aab51b16762ed82e8fdeaa5042da45b08 change-id: 20260805-wq_race_kick-d7ae5c14258d Best regards, -- =20 Breno Leitao