From nobody Tue Sep 29 06:58:32 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 33262411661 for ; Tue, 11 Aug 2026 08:12:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786435959; cv=none; b=jyMi6J00C2OUWzDdadPJdTg9iBGFxUO4fbz+Q9G67QwNNf5SyAnPs2k6YINc32sg0JEOENLrt/+H2+mXcLDKScXOWbxXoadeyDPMB4cv4JXGnzx0zfMabk8yozmYjq8oixYY7xCdizyEOEVgQunrXOj+8lwLGN3U36xDkByWs4o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786435959; c=relaxed/simple; bh=PHx2mMVsogjJ0Yit+7yeP2NarwTDQc9sCbOPmoVs01A=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:To:Cc; b=UdaLclg4hky0wRMU2gP2z5bUmxA2SkvtWs+Bsvi2fmmNMPL2SN9gTIzh/jNctbOl66m5p4L2xX29cjI9cdUNJG3SujNdmVCWFgc25YtDU4UvgqXOgnxMSv8ZzlhAtwWNgMoXXVFIBy85eSxnyL8BzrUIQvJM0tm9RMtFkV3IZK8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=anA2p05Q; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="anA2p05Q" Received: by smtp.kernel.org (Postfix) with ESMTPS id 8872EC2BCC7; Tue, 11 Aug 2026 08:12:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1786435958; bh=PHx2mMVsogjJ0Yit+7yeP2NarwTDQc9sCbOPmoVs01A=; h=From:Date:Subject:To:Cc:Reply-To:From; b=anA2p05QBawoF662TrouaQjVpYWgFIMHjSEnRV4SHZCNojQ2pV9qOuwSlxssljVvn 7xLC7otzGV+vky/8VeLexGvzvDMnVUL3hEh7MqyO6u5igRO1JmdtFHfOPWaYfJDiXw e8YhxwUh37u8aW46IsXnJ6Ak+bNg8dpSPJjgTn1aUvHk3wnYBAgURj4h5KFFne2dMc 6/JlRH2WnlYgz2m+3pKI4EiQBx4OJzliDuv2WY2Yjvg4snK0pCfddHTWp2lTo5fSi8 8xBkzl65qA8gpEcM9bvQ0yFhNkyZqXHk1vnxsM8hnITw/1bZcjBSwEZhpOOdTJoKLB LiXHXSQiV4gmA== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 67617C5B574; Tue, 11 Aug 2026 08:12:38 +0000 (UTC) From: Changyu Li via B4 Relay Date: Tue, 11 Aug 2026 04:12:20 -0400 Subject: [PATCH] ipc: fix hung task in copy_ipcs() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-work-v1-1-df28655110a0@gmail.com> X-B4-Tracking: v=1; b=H4sIAGPZemoC/6tWKk4tykwtVrJSqFYqSi3LLM7MzwNyDHUUlJIzE vPSU3UzU4B8JSMDIzMDC0ND3fL8omxdU2MjC8tUC8OkFOM0JaDSgqLUtMwKsDHRsRB+cWlSVmp yCUivUm0tANC+r1VoAAAA X-Change-ID: 20260811-work-53289e81bd3f To: linux-kernel@vger.kernel.org Cc: syzbot+97a62389c5611b0477f3@syzkaller.appspotmail.com, Changyu Li X-Mailer: b4 0.16.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2847; i=ihaveihaveihavea@gmail.com; h=from:subject:message-id; bh=mmV3V1+8ai5Y8M4gkr3IAIu4s2zOEMfEy4G4kkpygHI=; b=owGbwMvMwCW2u2xN/2eLjV8ZT6slMWRV3Szrf1DxYO4cl5J23q3rpq1rm7w0Iev2oem3zor0H ShwXRJe3lHCwiDGxSArpsiiZ80sta9xivPea9/2w8xhZQIZwsDFKQAT2dXP8L1iyrb1hy5v4ito iPKzkn7SeCTao5L7s2H2QeG+XcJV6xn+hyXn7f+czxx3dO7bApPY54kJ97pfyYRX2kobsghzVex gBAA= X-Developer-Key: i=ihaveihaveihavea@gmail.com; a=openpgp; fpr=2E3B031ABE819443BDD6F6BFBB76AC8FF338B1F5 X-Endpoint-Received: by B4 Relay for ihaveihaveihavea@gmail.com/default with auth_id=936 X-Original-From: Changyu Li Reply-To: ihaveihaveihavea@gmail.com From: Changyu Li When the user_ns's UCOUNT_IPC_NAMESPACES limit is reached, copy_ipcs eventually calls flush_work(&free_ipc_work) to wait for in-flight work to reduce the number of ipc_namespaces so it can proceed. Unfortunately flush_work() enters uninterruptible sleep and if there are enough pending items to be freed by free_ipc_work then this would trip hung task watchdog. INFO: task blocked for more than 143 seconds. Not tainted syzkaller #0 task:syz-executor845 state:D stack:27496 pid:5856 Call Trace: __flush_work+0x9c2/0xd70 kernel/workqueue.c:4431 create_ipc_ns ipc/namespace.c:55 [inline] copy_ipcs+0x19b/0x6c0 ipc/namespace.c:116 create_new_namespaces+0x210/0x6b0 kernel/nsproxy.c:112 unshare_nsproxy_namespaces+0x149/0x190 kernel/nsproxy.c:234 ksys_unshare+0x5a7/0x950 kernel/fork.c:3291 Replace the uninterruptible flush_work() with a polling loop that checks if there's an in-flight free_ipc_work. If there is then wait interruptibly a short interval for forward progress in free_ipc_work and retry. If free_ipc_work is not in-flight nothing will free up quota so bail with -ENOSPC as before. Otherwise wait interruptibly to not trip hung task watchdog. Reported-by: syzbot+97a62389c5611b0477f3@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D97a62389c5611b0477f3 Signed-off-by: Changyu Li --- ipc/namespace.c | 19 ++++++++++++++----- 1 file changed, 14 insertions(+), 5 deletions(-) diff --git a/ipc/namespace.c b/ipc/namespace.c index 1e71353bdb..e8ea422d79 100644 --- a/ipc/namespace.c +++ b/ipc/namespace.c @@ -26,6 +26,8 @@ static void free_ipc(struct work_struct *unused); static DECLARE_WORK(free_ipc_work, free_ipc); =20 +#define FREE_IPC_WAIT_JIFFIES 5 + static struct ucounts *inc_ipc_namespaces(struct user_namespace *ns) { return inc_ucount(ns, current_euid(), UCOUNT_IPC_NAMESPACES); @@ -49,12 +51,19 @@ static struct ipc_namespace *create_ipc_ns(struct user_= namespace *user_ns, if (!ucounts) { /* * IPC namespaces are freed asynchronously, by free_ipc_work. - * If frees were pending, flush_work will wait, and - * return true. Fail the allocation if no frees are pending. + * If there is in flight free_ipc_work, we'll wait for it to + * make progress otherwise fail immediately. */ - if (flush_work(&free_ipc_work)) - goto again; - goto fail; + if (!work_busy(&free_ipc_work)) + goto fail; + + schedule_timeout_interruptible(FREE_IPC_WAIT_JIFFIES); + if (signal_pending(current)) { + err =3D -ERESTARTSYS; + goto fail; + } + + goto again; } =20 err =3D -ENOMEM; --- base-commit: 3d08ff75a47a3e7e2ab45a3bcab6723b4d906422 change-id: 20260811-work-53289e81bd3f Best regards, -- =20 Changyu Li