From nobody Mon Sep 28 21:54:44 2026 Received: from out203-205-221-233.mail.qq.com (out203-205-221-233.mail.qq.com [203.205.221.233]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0794638DC58 for ; Mon, 17 Aug 2026 05:33:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=203.205.221.233 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786944795; cv=none; b=iet0maXZ868Atbd48tf3RKXJE7IVWJfee4XiMy5GRnZdFNhqlhCjJOlMyawm3y2DNMbJtxh1+jhAvWDti+yMKxEgmV83ykUu/Yr0zHo9pXOY/qM/XgXNF4AQaeP9lBtnrlh47ti8hdoQZ+83IZHlRo6fgN47pcSUH4v44gZyynE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786944795; c=relaxed/simple; bh=/fwhjkY0Bidfjh9Qa+I5t6c6xc4EtyKGrD3KG6iC3xc=; h=Message-ID:From:To:Cc:Subject:Date:In-Reply-To:References: MIME-Version; b=jmy0p5OsHWAssJHMHya3z2Sl84DO0C6+UZAiVwgJC3NIYXGBt5xiukin+MywhBxZqdS/pWnhh7kZS/9jKn0RNXeyDzpRmW9Eq2CSGS7hOZUa7KM13zOUGcSwb/ZRpSD3eyaZbBKh4gKlrxD0f1Xtnf3x9aMuLvSxNLgfzfYZYAg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=qq.com; spf=pass smtp.mailfrom=qq.com; dkim=pass (1024-bit key) header.d=qq.com header.i=@qq.com header.b=xtitHEp0; arc=none smtp.client-ip=203.205.221.233 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=qq.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=qq.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=qq.com header.i=@qq.com header.b="xtitHEp0" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qq.com; s=s201512; t=1786944784; bh=4GTqCDhkaYeVaAOVdcapoHJLk8k8G2J6zGUbJsg/Mrw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=xtitHEp0KtFyYDKO2Ki+X69URki7BSVgBg85tm9MgLNZVyMLa46fZad9tTw0yTsjo UUNiFEdLF/xnUVBKBFMsiBx7oNF1QWBuXFqXMV0R3iHpn58h//SOB9f/ubSRQeOmaK iFXDrVKkLe3K4ex4rlOR5rF5mMe7NmtlHaXE3JtE= Received: from lxu-ped-host.. ([111.198.231.89]) by newxmesmtplogicsvrszc56-0.qq.com (NewEsmtp) with SMTP id 8408AC82; Mon, 17 Aug 2026 13:33:00 +0800 X-QQ-mid: xmsmtpt1786944780th8ur8uxq Message-ID: X-QQ-XMAILINFO: OABzg/kr8LENKKr4PXEDpQZbc4omYdegT69NHhOCvR+ahYXn5NXhGPbZu0lgEz LlteIxFXg9T9QJMIc+gOqIP2tVsW3bNqlQD17vfnt035+H9DujzKQyLsXL5q5P+kFHLx/6qP9tjN 2ijrDsX0DBBEZ6BuIWFSviZrarkI69fPCa7OTchoH/nG0G99SBYLKHuBToqjkI6X6rvlVzsptYoo C0wkqLQhX+NoPg7zo8FzEurK9PjiKv7dids+NE6TJzfMzn/A5iGHm4WtVp/tlbjENT/3b/uo5/dz PS3J37wStPi+Ko6zOLiT9clApW/HdJmFuejh6PtiNX4v8fAeKePb2TCuCnya+dkG74FVLDaQ+nLQ g3cZi30hXRDH2mbLWToybZ5O0wRZnK8sKH/tfB1jXqcxv32XgTDEXXlElvqkFC5uEP3GaSeJMoOG crToIkTNVu7gE1XDnAguDGv6lzL4MNiOb+uDKp3kUfmKlKQFI+tMBfZrc4s7TUcsrv5C78u+ZjID k/ptE4/ucQTDmqI5VlcD3xMFKaEJIFAB+rCDtPHqDeaeC2xlruEoamZbo8qrFNEKu5dgiYr3/6qt INzZ1K6xfPPuJeJxfRfdWzauvAEkY9816iZfiVb6XpRhn0nEJPCKLE12QezklSXgse7UUwpzrMgY v2JFNCte4ku1dPA2Ksd7iiThh2PvHmhMT1PEfcgljyydfLtEKadm1PZlyX6Rv16ixPargsPMqxVF MJwC9c5LjA2f4NAGPk3kN7ivQLFzKFxe1xAoRjnJWwp4PosIiJfNffqT4TiR/CzBLIzOJ9gqVjGo XKBM9yXBuJ99bRC2quEBL4yly+pZu2uhQ/b9teUNY+C3VZx7pCHjNyIkV90+Fg4vl5DE70pRsmZY sOjrtCO5mbtHRNBhpBwvbj1ZUu7/tmeGbVcsVK3wk2mkeAhGNqneqGXzCroLKJY7rVRZKJG6dQua zV/iKJNITcd38K9qms1K+Ps4OYdPqeT1EJzcT0RR5Dvjknv3ZK+oH/xeR5Z3QGkjtSWsVX+I41KM FR3XPT8M/S35pj8VAbft0RRULJUtE= X-QQ-XMRINFO: NyFYKkN4Ny6FuXrnB5Ye7Aabb3ujjtK+gg== From: Edward Adam Davis To: syzbot+9c28ada89c468ad30713@syzkaller.appspotmail.com Cc: andrealmeid@igalia.com, dave@stgolabs.net, dvhart@infradead.org, linux-kernel@vger.kernel.org, mingo@redhat.com, peterz@infradead.org, yaokai34@huawei.com, syzkaller-bugs@googlegroups.com, tglx@kernel.org Subject: [PATCH] futex: Temporarily set the task state to running for pivot pending Date: Mon, 17 Aug 2026 13:33:00 +0800 X-OQ-MSGID: <20260817053259.334913-2-eadavis@qq.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <6a807971.dbb3a75c.20434b.0018.GAE@google.com> References: <6a807971.dbb3a75c.20434b.0018.GAE@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" There is a report of futex_pivot_pending() locking a mutex while not TASK_RUNNING, which is due to wait_var_event(mm, futex_pivot_pending(mm)) calls __wait_var_event(), which sets the current task state to 2 before the condition function `futex_pivot_pending()` executes, which triggers the warning in [1]. Temporarily set the current task state to 0 within futex_pivot_pending() to allow `mmph->lock` to complete its lifecycle normally. [1] do not call blocking ops when !TASK_RUNNING; state=3D2 set at [<000000003d6= 2a0c3>] prepare_to_wait_event+0x2e4/0x3ac kernel/sched/wait.c:-1 WARNING: kernel/sched/core.c:9124 at __might_sleep+0xc0/0xdc kernel/sched/c= ore.c:9120, CPU#0: syz.0.17/4920 Call trace: class_mutex_constructor include/linux/mutex.h:253 [inline] futex_pivot_pending+0x30/0xa4 kernel/futex/core.c:1789 futex_hash_allocate+0x73c/0xc20 kernel/futex/core.c:1872 futex_hash_prctl+0xd0/0x324 kernel/futex/core.c:2027 Fixes: 8e7ff730dd96 ("futex: Fix race in futex_pivot_pending() during priva= te hash resize") Reported-by: syzbot+9c28ada89c468ad30713@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D9c28ada89c468ad30713 Tested-by: syzbot+9c28ada89c468ad30713@syzkaller.appspotmail.com Signed-off-by: Edward Adam Davis --- kernel/futex/core.c | 22 ++++++++++++++++------ 1 file changed, 16 insertions(+), 6 deletions(-) diff --git a/kernel/futex/core.c b/kernel/futex/core.c index 128c5752f225..a0b17d2f41da 100644 --- a/kernel/futex/core.c +++ b/kernel/futex/core.c @@ -1785,14 +1785,24 @@ static bool futex_pivot_pending(struct mm_struct *m= m) { struct futex_mm_phash *mmph =3D &mm->futex.phash; struct futex_private_hash *fph; + unsigned int state; + bool ret; + + state =3D current->__state; + __set_current_state(TASK_RUNNING); + scoped_guard(mutex, &mmph->lock) { + if (!mmph->hash_new) { + ret =3D true; + goto out; + } =20 - guard(mutex)(&mmph->lock); - - if (!mmph->hash_new) - return true; + fph =3D rcu_dereference_raw(mmph->hash); + ret =3D futex_ref_is_dead(fph); + } +out: + __set_current_state(state); + return ret; =20 - fph =3D rcu_dereference_raw(mmph->hash); - return futex_ref_is_dead(fph); } =20 static bool futex_hash_less(struct futex_private_hash *a, --=20 2.43.0