From nobody Tue Sep 29 06:59:46 2026 Received: from stravinsky.debian.org (stravinsky.debian.org [82.195.75.108]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A3F6E3FB7EB for ; Tue, 11 Aug 2026 09:56:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=82.195.75.108 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786442181; cv=none; b=tcwkEWLRQx6tSdHiWab0KhYQ7fQJbDWcSFBuojXx+MuN+WuYP3iF9cLFLfI8l5u9UKEKm5VhGA6I4ZhBwl49q3uvz62XeiT/MUCh39BqxVVo8ByymudngtlcD+1PfvFqF4ju5lScbfm0Xb/9Ytf7VQNwKiZZ9k+1JduPrKnIzK8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786442181; c=relaxed/simple; bh=9YPBbCQ9pX7fph7Sbp+1SMH7E/sd2oguRRrw+F9u9ms=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:To:Cc; b=oOz6nQ5icvm3ZdOPqy0PEfz908lgRi/h/Mk3Lm0WvQ9xmzGcjoLGwrcVAaX1wgzKQEJn1aKuYPadHi82etJBq3rkcndBPAaEA2OXQAj/3FqRVPwKwhPb23B4HBB2PM+ade88eb1T6FPt2Pnq6sSIWMvUUpAe3MZW+sU2aw8R3DM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=debian.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b=JqnG1Gw2; arc=none smtp.client-ip=82.195.75.108 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=debian.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b="JqnG1Gw2" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.stravinsky; h=X-Debian-User:Cc:To:Message-Id: Content-Transfer-Encoding:Content-Type:MIME-Version:Subject:Date:From: Reply-To:Content-ID:Content-Description:In-Reply-To:References; bh=1Abv3cR2rWExrX2UayAXYtP/l7brEF5ATBQplfLBu7k=; b=JqnG1Gw2Zpgw+gMDIUdVRwP/6e PGN7matDcyLyks+89GXuXfR7hHEJpFbPTPKCA+yokhFZCBYO8Zga7J+LI2b99/CHsrI7qa6z7hrUT WvYowfR/QLikee0Ni7gGbdIiWlnt3ziLRuFf1G0KNjGhrX5HcxhMgMjMfhx3OdStfMbvHulwnuIaz wWi4zCGYMDbiN9A8xaOF8PfMHd4XG25CM7Fe2Ql0IBbSknJvbFOG4M0jp/tpfpa/Wj3tud80mAM5w D6IIAb1E9xQL39wiAhNb6YGm4TMOccfb7p1qBK9RlA4r185uf9QwyDtMkxvK1P6BBlmw7qd63kgZ+ Np/3VcUQ==; Received: from authenticated-user by stravinsky.debian.org with esmtpsa (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from ) id 1wtjDT-003TtM-12; Tue, 11 Aug 2026 09:56:16 +0000 From: Breno Leitao Date: Tue, 11 Aug 2026 02:55:56 -0700 Subject: [PATCH v2] workqueue: annotate racy p->wake_cpu accesses in kick_pool_pick() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-wq_race_kick-v2-1-6e66ff12d8ae@debian.org> X-B4-Tracking: v=1; b=H4sIAKvxemoC/3XM0QrCIBQA0F+R+6yhMtfwqf+IMZzetstAS8OK4 b9He+/1PJwdCmbCApbtkLFSoRTBMs0Z+NXFBQUFsAy01L0cpBGvx5Sdx2kjv4lwdmi86rQZAnA G94w3eh/ddeQMVirPlD/HXtVP/0RVCSWCMS54pTvVz5eAM7l4SnmBsbX2BVqBMvepAAAA X-Change-ID: 20260805-wq_race_kick-d7ae5c14258d To: Tejun Heo , Lai Jiangshan Cc: linux-kernel@vger.kernel.org, kernel-team@meta.com, Breno Leitao , Bradley Morgan X-Mailer: b4 0.16-dev-f8e9d X-Developer-Signature: v=1; a=openpgp-sha256; l=2406; i=leitao@debian.org; h=from:subject:message-id; bh=9YPBbCQ9pX7fph7Sbp+1SMH7E/sd2oguRRrw+F9u9ms=; b=owEBbQKS/ZANAwAIATWjk5/8eHdtAcsmYgBqevG8ew3d3Y6/rbrdfM8/Pz+rAKQw37Ew5eN2E pHHApxBrcSJAjMEAAEIAB0WIQSshTmm6PRnAspKQ5s1o5Of/Hh3bQUCanrxvAAKCRA1o5Of/Hh3 bSHTD/sFKsLHQrvHIa4ifsBFRiq92/BlddRUFsn4kP/LaVSV5R13bW+uVDfxGAxC8fNXv3zrlav IOE7v9RUXiYo4TvIYn1LIIVcksQ3E/5m2WWvwsZFB4jI0jvy/5Gf4ihRfUCXc0AIyrzIr41GYJ5 bHtUSx12IuXZodd54mwXWZOKx2BpvsV8D7TTsPeDZNewLOViiBi7vbyhOAet+3KNL5LmOUtXK/G ssfvi25XSr1HuWYMAB1vDIz5MSA1Y7+XCURFFi9iZC1nXcO9Y7we1Dv8UgYSRf/2O8LVOdAhC0/ bXbKHtkhuHOAI76cl7dyjiBAyhL7lhb2ML+1/1hqSmTqITsfM/Z0Y44405MLzutAb0RqwBU8k94 eEBDYF+JhQiT5G98KAGN+BdEyOdvFQC/enqdaw/VevMVrWIOCJeTgA0fODYipiYd2cxgTkNldpm Sja2E3FeGV/9xYIrD1X4hLIhaHoQYmIsmQWmIDEVu1wWF1OuRQakuEMBjsXti3ftDD5XTgeL1rC aOkPQVfhoX7Wc6jcreEgd8yw4FZGj/qXA30lucic0I8SapAAtbgXjnIZEWTBCo05kcG3VbjeoOU E8QQBtoAdnyUWkCLJTVBTq7l8K5gypn9V9Q3h4hQ7xGMGBDoaxu4xH0lYg7Xx5nyVbe+mqs4jlA 2uNW5nOGZMA3Ltg== X-Developer-Key: i=leitao@debian.org; a=openpgp; fpr=AC8539A6E8F46702CA4A439B35A3939FFC78776D X-Debian-User: leitao kick_pool_pick() reads and writes p->wake_cpu while the scheduler can update it concurrently. KCSAN reports: BUG: KCSAN: data-race in kick_pool_pick+0xf8/0x2d8 race at unknown origin, with read to 0xffff000663229da4 of 4 bytes by task 1817002 on cpu 40: kick_pool_pick+0xf8/0x2d8 process_scheduled_works+0x2bc/0x888 worker_thread+0x394/0x548 kthread+0x1b8/0x1f0 ret_from_fork+0x10/0x20 value changed: 0x0000002b -> 0x0000002f The race is harmless, this patch only acknowledge that this is racy and it is fine, silenting KCSAN. Mark both accesses with READ_ONCE() and WRITE_ONCE() to document that they are intentionally racy and to stop the compiler from reloading or tearing them. Signed-off-by: Breno Leitao Reviewed-by: Bradley Morgan --- Changes in v2: - Mark the p->wake_cpu store with WRITE_ONCE() as well (Tejun) - Say in the changelog that the race is harmless, and why - Carried Bradley's Reviewed-by across the WRITE_ONCE() addition - Link to v1: https://patch.msgid.link/20260805-wq_race_kick-v1-1-d55adc124= 16b@debian.org --- kernel/workqueue.c | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/kernel/workqueue.c b/kernel/workqueue.c index 8fd6af72ffd8d..503cab539ec80 100644 --- a/kernel/workqueue.c +++ b/kernel/workqueue.c @@ -1308,14 +1308,16 @@ static bool kick_pool_pick(struct worker_pool *pool= , struct task_struct **wakep) * If @pool has non-strict affinity, @worker might have ended up outside * its affinity scope. Repatriate. */ - if (!pool->attrs->affn_strict && - !cpumask_test_cpu(p->wake_cpu, pool->attrs->__pod_cpumask)) { + bool wake_cpu_in_pod =3D cpumask_test_cpu(READ_ONCE(p->wake_cpu), + pool->attrs->__pod_cpumask); + + if (!pool->attrs->affn_strict && !wake_cpu_in_pod) { struct work_struct *work =3D list_first_entry(&pool->worklist, struct work_struct, entry); int wake_cpu =3D cpumask_any_and_distribute(pool->attrs->__pod_cpumask, cpu_online_mask); if (wake_cpu < nr_cpu_ids) { - p->wake_cpu =3D wake_cpu; + WRITE_ONCE(p->wake_cpu, wake_cpu); get_work_pwq(work)->stats[PWQ_STAT_REPATRIATED]++; } } --- base-commit: a5bde5d8fde8a8cb28e59a672d5ddc5b9c1e7656 change-id: 20260805-wq_race_kick-d7ae5c14258d Best regards, -- =20 Breno Leitao