From nobody Mon Sep 28 08:07:25 2026 Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id ADD9744C652 for ; Mon, 24 Aug 2026 15:56:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.50 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787587003; cv=none; b=D2UcT1Ax/mh4Pv6M4WzxPB8Vl6hGK61aR8Ts5Qf22al98gh342JrkhBaus6QybXVCMhz5EEi+vjRj3DwOMesu3Cvfp7Ar/jXJM/T9dShOai1IznC5WNxgkMAZv8fNVMDfReH2LoyMNGEpJaIpQoCWlNUpSvugj1DrE/oCovopf0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787587003; c=relaxed/simple; bh=uO+FlapmPISqgzvlHWT7A/PRH9au4RHwxIrIqEw4NqY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=gWwNllEoR46QfcqUV0n7J4JeLp0bTXmB5O86caknB/34uig1GMcpnXzPoUVG05o0J3VNXCi3j4QskglARGX30KvaHFvrcoSt2T0Iv1PT6XLG3b1rD0nZaFCjGqbzieFjvGfnIs4Nd7dU5VgGbSrXijyD5D1lVQDXbLG+h+UHDsY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=snu.ac.kr; spf=pass smtp.mailfrom=snu.ac.kr; dkim=pass (1024-bit key) header.d=snu.ac.kr header.i=@snu.ac.kr header.b=GdkSfxIa; arc=none smtp.client-ip=209.85.216.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=snu.ac.kr Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=snu.ac.kr Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=snu.ac.kr header.i=@snu.ac.kr header.b="GdkSfxIa" Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-383b4a3755fso3966015a91.3 for ; Mon, 24 Aug 2026 08:56:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=snu.ac.kr; s=google; t=1787586995; x=1788191795; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=EZ3ukP91qVL4UwV52qeMYFaB9h7OFZKEqbp7w0YVgIg=; b=GdkSfxIa/ajhZjN/ybrChcICL3wn+BPCbNogMmcSwu5CDLB5mmfi+dmTzSEgAc7jZj w4ff+VABcf7zmO95d/loTGZFn5Rco6Y/5bSM7B2ifLketH4hYGgU8mweUTnr+YOh4K7d bHlUlL2zgLe1DV4DKnFD6YRvGG+3rRMqLkRTE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787586995; x=1788191795; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=EZ3ukP91qVL4UwV52qeMYFaB9h7OFZKEqbp7w0YVgIg=; b=rPSJpCQJ3JkKbZZTX1TSgyoIyuPuTIgDpTq7vjEqtBv4jJsPf7fWZA5mX7JVxXWWfH CfL7dGKvaUHbHpFEiODQ8rckpFynsw9u/5Gv/Njy90vlimBnacBrnpFPdB2nvb8u+2k6 Kq4XYphHxDrXE73yHWhper9liZxhxX97EV1uCZku5Tfuvf3Jj0ZLury3LN4UHMm87EVJ xmUeVrHvHMlUCcJkdP2hljPwj4eRGCOv5sSlCAAc2uxpf3R8Q4190l0J/X8gz04Pq4iX aeDaN2tGgudGfrV+fK6GAvjwMhUi3ZxEOHp1yg02mhH+HYBZJRHB8c1Qrb4J7ovNssML NqaA== X-Gm-Message-State: AFuF++mJZ3B7zuSOwGITiISw1FN6x+O3d2A9E4f8m9IxyBHEjsW43ibw UBVkyTJLAaiF/oxCYr5QS8o6HB2JTyuCpFSFkNJWW5nwk13+lUiWt15wXtwPcom15gA= X-Gm-Gg: AR+sD11zpQqg9ylIhkw6K5pOzHwPmgcquyd+W2CAZi+I6jF6uTnVkkxuR47bvx7A+jK mCkGW5wE0mU+cie0O15mdVEzfO/rvA/EK/NgJ44qRfKQOZhy2YyF1ChJo9xsIreW8BL2uWFDcHY bslQxDl77q4hz61bDffhyn6pfAlSgjwcQAKJfSmoHPr1H6TVZHWMmrG8Fklu+oElkAf+P0CZb0J EteJ2yCTtuTxS50Aw1fX4BmZDKeruriMcrly7Mahmy6Wr8eXG2S682cgqlxbCUFVSjELgV2OhYb TlNqki1UWA48gbn10PqRwSNvZpPbgMkg477wowZMjouq6z5HRAZ4j17xSkzOsbNuND5yFFtrTES aJ2TU5rAeN5HyjP/fgTd0v1OPorolKU2iJoEgzgn1uERmDkqja0DBdMLObor0ggwQb21wkQZ1DE bRv7Dc1Tdt8dY4QLQFv0hmtN65e8jaWlZN4BmiypiRbk9ASEkVAxKKmTZamQrNhmJ5sT6ZTmtI1 KPtuFOM8fL8cLRQj2FOOARAK/1Egp9BYgKzeKoJugndw+wr6C5DeTQ9+tDShgsYXXxgnxW4WXBX 4lz0SFG+aVdIowQjb7F6OUnKy6S0j8OaU5ly01YvYY3DnsJKI4R28A== X-Received: by 2002:a17:90b:54d0:b0:36d:b424:4f17 with SMTP id 98e67ed59e1d1-395c35188fcmr54068492a91.1.1787586994592; Mon, 24 Aug 2026 08:56:34 -0700 (PDT) Received: from leesin ([147.46.121.37]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39645d31e8csm34039a91.9.2026.08.24.08.56.32 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 08:56:34 -0700 (PDT) From: Jaeyoung Chung To: christian.koenig@amd.com, dri-devel@lists.freedesktop.org, linaro-mm-sig@lists.linaro.org, linux-media@vger.kernel.org, sumit.semwal@linaro.org Cc: linux-kernel@vger.kernel.org, eulgyukim@snu.ac.kr, jjy600901@snu.ac.kr Subject: [BUG] WARNING: refcount bug in sync_timeline_signal Date: Tue, 25 Aug 2026 00:56:28 +0900 Message-ID: <20260824155629.2370441-1-jjy600901@snu.ac.kr> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Hello, We found a "WARNING: refcount bug in sync_timeline_signal" on Linux v7.2. The issue was found by our own race fuzzer. We have not analyzed the root c= ause, so we do not have a proposed fix to offer. To reproduce the race reliably, we applied the delay patch below to the kernel and ran the C reproducer as root inside an x86_64 QEMU guest. The crash log we observed, the delay patch and the reproducer are all included below. The following kernel config options are required to reproduce the issue: CONFIG_SW_SYNC=3Dy CONFIG_SYNC_FILE=3Dy CONFIG_DMA_SHARED_BUFFER=3Dy CONFIG_DEBUG_FS=3Dy CONFIG_KASAN=3Dy We hope this report is useful. Please let us know if any further information would help. Reported-by: Eulgyu Kim Reported-by: Jaeyoung Chung Kernel delay patch: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D diff --git a/drivers/dma-buf/sw_sync.c b/drivers/dma-buf/sw_sync.c index 8df20b0218a9..d30ce9d915ba 100644 --- a/drivers/dma-buf/sw_sync.c +++ b/drivers/dma-buf/sw_sync.c @@ -8,6 +8,7 @@ #include #include #include +#include #include #include #include @@ -215,6 +216,10 @@ static void sync_timeline_signal(struct sync_timeline = *obj, unsigned int inc) =20 spin_lock_irq(&obj->lock); =20 + if (strncmp(current->comm, "syzrepro1", 9) =3D=3D 0) { + mdelay(50); + } + obj->value +=3D inc; =20 list_for_each_entry_safe(pt, next, &obj->pt_list, link) { =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D C reproducer: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D #define _GNU_SOURCE #include #include #include #include #include #include #include #include #include #include #include #include #include #include #define SYSCHK(x) ({ long __r =3D (long)(x); if (__r =3D=3D -1L) { perror(#= x); exit(1); } __r; }) #define SW_SYNC_IOC_CREATE_FENCE 0xc0285700u #define SW_SYNC_IOC_INC 0x40045701u #define SWSYNC "/sys/kernel/debug/sync/sw_sync" #define BIAS_US 2000 struct fence_data { uint32_t value; char name[32]; int32_t fence; }; static volatile int g_round, g_stop, g_tl_fd =3D -1, g_fence_fd =3D -1; static volatile int g_armed, g_done0, g_done1; static void spin_us(long us) { struct timespec a, b; clock_gettime(CLOCK_MONOTONIC, &a); do { clock_gettime(CLOCK_MONOTONIC, &b); __asm__ __volatile__("pause" ::: "memory"); } while ((b.tv_sec - a.tv_sec) * 1000000L + (b.tv_nsec - a.tv_nsec) / 1000= L < us); } static void pin_cpu(int cpu) { cpu_set_t set; CPU_ZERO(&set); CPU_SET(cpu, &set); sched_setaffinity(0, sizeof(set), &set); } static int wait_round(int *last) { while (g_round =3D=3D *last && !g_stop) sched_yield(); if (g_stop) return 0; *last =3D g_round; return 1; } /* T1: advances the timeline, signalling the pt */ static void *thr_inc(void *a) { unsigned int v =3D 1; int last =3D 0; (void)a; prctl(PR_SET_NAME, "syzrepro1", 0, 0, 0); pin_cpu(0); while (wait_round(&last)) { g_armed =3D 1; __sync_synchronize(); ioctl(g_tl_fd, SW_SYNC_IOC_INC, &v); __sync_synchronize(); g_done1 =3D 1; } return NULL; } /* T0: closes the fence mid-signal, dropping the pt's last reference */ static void *thr_close(void *a) { int last =3D 0; (void)a; prctl(PR_SET_NAME, "syzrepro0", 0, 0, 0); pin_cpu(1); while (wait_round(&last)) { while (!g_armed && !g_stop) __asm__ __volatile__("pause" ::: "memory"); if (g_stop) break; spin_us(BIAS_US); close(g_fence_fd); __sync_synchronize(); g_done0 =3D 1; } return NULL; } static int open_sw_sync(void) { int fd =3D open(SWSYNC, O_RDWR); if (fd >=3D 0 || errno !=3D ENOENT) return fd; mkdir("/sys/kernel/debug", 0755); mount("debugfs", "/sys/kernel/debug", "debugfs", 0, NULL); return open(SWSYNC, O_RDWR); } int main(void) { pthread_t t0, t1; long i; close(SYSCHK(open_sw_sync())); pthread_create(&t1, NULL, thr_inc, NULL); pthread_create(&t0, NULL, thr_close, NULL); for (i =3D 0; i < 200 && !g_stop; i++) { struct fence_data d =3D { .value =3D 1, .name =3D "syzrepro_pt", .fence = =3D -1 }; int tl =3D SYSCHK(open_sw_sync()), w; SYSCHK(ioctl(tl, SW_SYNC_IOC_CREATE_FENCE, &d)); g_tl_fd =3D tl; g_fence_fd =3D d.fence; g_armed =3D g_done0 =3D g_done1 =3D 0; __sync_synchronize(); g_round =3D i + 1; for (w =3D 0; w < 5000 && !(g_done0 && g_done1); w++) { struct timespec ts =3D { 0, 1000000 }; nanosleep(&ts, NULL); } close(tl); } g_stop =3D 1; __sync_synchronize(); g_round++; pthread_join(t1, NULL); pthread_join(t0, NULL); return 0; } =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Crash log: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D refcount_t: addition on 0; use-after-free. WARNING: lib/refcount.c:25 at refcount_warn_saturate+0x76/0xd0 lib/refcount= .c:25, CPU#0: syzrepro1/402 Modules linked in: CPU: 0 UID: 0 PID: 402 Comm: syzrepro1 Tainted: G L 7.2.0-= dirty #2 PREEMPT=20 Tainted: [L]=3DSOFTLOCKUP Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1= .1 04/01/2014 RIP: 0010:refcount_warn_saturate+0x76/0xd0 lib/refcount.c:25 Code: 3d ff e4 bb 04 67 48 0f b9 3a eb 4d 85 db 74 2f 83 fb 01 75 38 48 8d = 3d f8 e4 bb 04 67 48 0f b9 3a eb 36 48 8d 3d fa e4 bb 04 <67> 48 0f b9 3a e= b 28 48 8d 3d fc e4 bb 04 67 48 0f b9 3a eb 1a 48 RSP: 0018:ffff88810cd47d68 EFLAGS: 00010046 RAX: 0000000000000000 RBX: 0000000000000002 RCX: dffffc0000000000 RDX: 0000000000000001 RSI: 0000000000000004 RDI: ffffffff9be2c840 RBP: ffff888102a5dc40 R08: ffff888102a5d73b R09: 1ffff1102054bae7 R10: dffffc0000000000 R11: ffffed102054bae8 R12: dffffc0000000000 R13: ffff888102a5d740 R14: ffff888102a5d738 R15: ffff888102a5d738 FS: 00007ae687b8f6c0(0000) GS:ffff88817d75f000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000578dd65f7e58 CR3: 000000010b72c000 CR4: 00000000000006f0 Call Trace: __refcount_add include/linux/refcount.h:-1 [inline] __refcount_inc include/linux/refcount.h:366 [inline] refcount_inc include/linux/refcount.h:383 [inline] kref_get include/linux/kref.h:45 [inline] dma_fence_get include/linux/dma-fence.h:317 [inline] sync_timeline_signal+0x383/0x550 drivers/dma-buf/sw_sync.c:229 sw_sync_ioctl_inc drivers/dma-buf/sw_sync.c:410 [inline] sw_sync_ioctl+0x140/0x980 drivers/dma-buf/sw_sync.c:475 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl+0xb6/0x100 fs/ioctl.c:583 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xf7/0x370 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x7ae687c90d6b Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 = 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 f= f ff 77 1c 48 8b 44 24 18 64 48 2b 04 25 28 00 00 RSP: 002b:00007ae687b8edd0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RBX: 00007ae687b8ee3c RCX: 00007ae687c90d6b RDX: 00007ae687b8ee38 RSI: 0000000040045701 RDI: 0000000000000003 RBP: 0000000000000000 R08: 0000000000000000 R09: 00007ffcdb19abc7 R10: 0000000000000000 R11: 0000000000000246 R12: ffffffffffffff80 R13: 0000000000000000 R14: 00007ffcdb19aad0 R15: 00007ae68738f000 ---------------- Code disassembly (best guess): 0: 3d ff e4 bb 04 cmp $0x4bbe4ff,%eax 5: 67 48 0f b9 3a ud1 (%edx),%rdi a: eb 4d jmp 0x59 c: 85 db test %ebx,%ebx e: 74 2f je 0x3f 10: 83 fb 01 cmp $0x1,%ebx 13: 75 38 jne 0x4d 15: 48 8d 3d f8 e4 bb 04 lea 0x4bbe4f8(%rip),%rdi # 0x4bbe514 1c: 67 48 0f b9 3a ud1 (%edx),%rdi 21: eb 36 jmp 0x59 23: 48 8d 3d fa e4 bb 04 lea 0x4bbe4fa(%rip),%rdi # 0x4bbe524 * 2a: 67 48 0f b9 3a ud1 (%edx),%rdi <-- trapping instruction 2f: eb 28 jmp 0x59 31: 48 8d 3d fc e4 bb 04 lea 0x4bbe4fc(%rip),%rdi # 0x4bbe534 38: 67 48 0f b9 3a ud1 (%edx),%rdi 3d: eb 1a jmp 0x59 3f: 48 rex.W =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D