From nobody Tue Sep 29 02:03:45 2026 Received: from stravinsky.debian.org (stravinsky.debian.org [82.195.75.108]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6A49C47D466 for ; Thu, 13 Aug 2026 13:12:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=82.195.75.108 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786626745; cv=none; b=JhKsDjBOZ4+CovPBoYBq1svFTPflsA8qoM/GYgfNJWXKYuPcc8MJc3KjOtNwRukNYfW8J85lRCP1YqMdLYFXrJWBF6bfzkigKaWxEQ9cxcjY/UGFcHObM/JFkZD+YHVjTwV1No21NiH6xvt3fQtxiKXG+T7lPcLWTQEIZwn5NoE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786626745; c=relaxed/simple; bh=CmuJ88dvvi6v+jmz4kT+4yGp/E4fWyxCUgv6SyCQ3dM=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:To:Cc; b=GEq5vOsl3uZ0wtJdqgyrylgDvIDHFcifXX3ShqEr/YnUkUqiOz+AclRSrL+8tnA3OGGSmrv9VxcycYOLCs9SzeZwndoOkTYyRB3BJ4se50z5ubnQ8/LmA/738qjtcW5SDgl52JEdha45tTCHowdySNTL3icKzlju3D/HwAGXFrw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=debian.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b=F5ILHSZJ; arc=none smtp.client-ip=82.195.75.108 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=debian.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=debian.org header.i=@debian.org header.b="F5ILHSZJ" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.stravinsky; h=X-Debian-User:Cc:To:Message-Id: Content-Transfer-Encoding:Content-Type:MIME-Version:Subject:Date:From: Reply-To:Content-ID:Content-Description:In-Reply-To:References; bh=G2u6GZnVIW+54E6q53dCEBDW2D7gX6/s6mHJxfpbYZY=; b=F5ILHSZJE4v1tnFlqDQE9WIQQU ozWJ18PxIv9MK+uYFIGEZgK+rk/oNfxFNufWBvO7S+3VaaDv4MxK64RoWyJai50NsBlYo4mlSa3wH SjwdO41GCmtV6y+BW6+hi0aUZ0gOsQ1BIjqgBBdZ9L6pQg8uWco70xPKnYR6YW0gzKH2hSfEGXtFp keEdU1jQh2hckIaZUXwYtcrs3jNtLKW57U/5jc4rsi4VPFUf3uKHRC7ZFcqaUoC6fD55GcQnlt2G0 rtvzZbgJAdsCFJaEad+4Xo7E0MRFgrYc2x2LrZZmxirzTMpjHX5nM90MKrjvkf6CKTzXeinsNJbZb uvz5PIAg==; Received: from authenticated-user by stravinsky.debian.org with esmtpsa (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from ) id 1wuVEG-0058HI-0a; Thu, 13 Aug 2026 13:12:17 +0000 From: Breno Leitao Date: Thu, 13 Aug 2026 06:12:12 -0700 Subject: [PATCH v3] workqueue: annotate racy p->wake_cpu accesses in kick_pool_pick() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260813-wq_race_kick-v3-1-00c93baa23f2@debian.org> X-B4-Tracking: v=1; b=H4sIAKvCfWoC/3XM0QqCMBSA4VcZ59qFZ7klXvUeETK3ox4EtS1WI b576FUF3f7wfwtECkwRKrFAoMSRpxEqccwEuN6OHUn2UAlQuTJ5mWv5uNXBOqoHdoP0J0vaYaF 06SETMAdq+blzl2smoOd4n8Jr1xNu9Q+UUKL0WlvvUBVomrOnhu14mEIHm5TUx434cyuJ0pAxb YvKl5a+7nVd30/qyf7nAAAA X-Change-ID: 20260805-wq_race_kick-d7ae5c14258d To: Tejun Heo , Lai Jiangshan Cc: linux-kernel@vger.kernel.org, kernel-team@meta.com, Breno Leitao , Bradley Morgan X-Mailer: b4 0.16-dev-f8e9d X-Developer-Signature: v=1; a=openpgp-sha256; l=2652; i=leitao@debian.org; h=from:subject:message-id; bh=CmuJ88dvvi6v+jmz4kT+4yGp/E4fWyxCUgv6SyCQ3dM=; b=owEBbQKS/ZANAwAIATWjk5/8eHdtAcsmYgBqfcKsVSMv6uVpDujjRifqPYaXUKV0ftXofnbQd USRhKIBM8CJAjMEAAEIAB0WIQSshTmm6PRnAspKQ5s1o5Of/Hh3bQUCan3CrAAKCRA1o5Of/Hh3 bU9BEACxngjoDzRY/VfBlOvRFDK3PCf3Kt/WmMtyq8jXfEAplTTHvB8KKTq2U+UVi0bGxb0+KWU BujoODTjujuE3XrmbYhjw2eHJKcoHCUgcYvD4fAPjU+IT+RLtonasAmrpNNFDapN3pcAcAizXNC 2auC88w3YTc+w27R/quXL519vsTcI0ANMmPP2KMY8C/8fzNSW/9AMkjNQNNWvke2+a1T9Vgepvt ar5O+UQwS8rg7oZKkRtOAU84VoClx0YoiC7Pr/0AMPc8QR9juK4uzaGDlpHf9hZinN74Jdqw8jE RS8hRHXYTOwT/WeLqIL5ABTt1ryAOKEs5dZMHHQRSMOzhMlxFjV1uGNTxvBE3FZ4Kc3sddpQOJ5 8mDXPjTBZAdaEgbXg5dHv915d1dzCfVuVnsaLsMeupxrvRG2okjINuA9Kj2+3FhQPBJhOCghim+ r4HK0Gx5E1/MJt8npZJQmu1k4/OOP868FcKYqh4prstj3Y7vrURzCoU0TN2D3FAC4XwT8o5ojdp xURYugNKi5fOveFn6fuHlTjf1O9kcC27ptcyGedN9oD9KCgb4/5TmgmG+hMh/kMDUearLyD5l2s zf01wFRjmypoQjPAMjjTgzldCVjJcvQ2t5//NTD2JX6nnoXvR3QBQmFQWbKmWTfWcwyoWQpuqEL azmAr721jTg8XsA== X-Developer-Key: i=leitao@debian.org; a=openpgp; fpr=AC8539A6E8F46702CA4A439B35A3939FFC78776D X-Debian-User: leitao kick_pool_pick() reads and writes p->wake_cpu while the scheduler can update it concurrently. KCSAN reports: BUG: KCSAN: data-race in kick_pool_pick+0xf8/0x2d8 race at unknown origin, with read to 0xffff000663229da4 of 4 bytes by task 1817002 on cpu 40: kick_pool_pick+0xf8/0x2d8 process_scheduled_works+0x2bc/0x888 worker_thread+0x394/0x548 kthread+0x1b8/0x1f0 ret_from_fork+0x10/0x20 value changed: 0x0000002b -> 0x0000002f The race is harmless. wake_cpu is a best-effort placement hint: every writer stores a valid CPU id and the wakeup path validates it through select_task_rq(), so a stale value only affects which CPU the worker wakes up on. Mark both accesses with READ_ONCE() and WRITE_ONCE() to document that they are intentionally racy and to stop the compiler from reloading or tearing them. Signed-off-by: Breno Leitao Reviewed-by: Bradley Morgan --- Changes in v3: - Keep the cpumask test inline in the condition, restoring the !affn_strict short-circuit (Tejun) - Spell out in the changelog why the race is harmless (Tejun) - Link to v2: https://patch.msgid.link/20260811-wq_race_kick-v2-1-6e66ff12d= 8ae@debian.org Changes in v2: - Mark the p->wake_cpu store with WRITE_ONCE() as well (Tejun) - Say in the changelog that the race is harmless, and why - Carried Bradley's Reviewed-by across the WRITE_ONCE() addition - Link to v1: https://patch.msgid.link/20260805-wq_race_kick-v1-1-d55adc124= 16b@debian.org --- kernel/workqueue.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/kernel/workqueue.c b/kernel/workqueue.c index de888e043d115..c94c519441d48 100644 --- a/kernel/workqueue.c +++ b/kernel/workqueue.c @@ -1309,13 +1309,14 @@ static bool kick_pool_pick(struct worker_pool *pool= , struct task_struct **wakep) * its affinity scope. Repatriate. */ if (!pool->attrs->affn_strict && - !cpumask_test_cpu(p->wake_cpu, pool->attrs->__pod_cpumask)) { + !cpumask_test_cpu(READ_ONCE(p->wake_cpu), + pool->attrs->__pod_cpumask)) { struct work_struct *work =3D list_first_entry(&pool->worklist, struct work_struct, entry); int wake_cpu =3D cpumask_any_and_distribute(pool->attrs->__pod_cpumask, cpu_online_mask); if (wake_cpu < nr_cpu_ids) { - p->wake_cpu =3D wake_cpu; + WRITE_ONCE(p->wake_cpu, wake_cpu); get_work_pwq(work)->stats[PWQ_STAT_REPATRIATED]++; } } --- base-commit: 28d012efb4327f9c75d5e042a7c91e9a542efa98 change-id: 20260805-wq_race_kick-d7ae5c14258d Best regards, -- =20 Breno Leitao