From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S966660AbbBDXqV (ORCPT ); Wed, 4 Feb 2015 18:46:21 -0500 Received: from mail.linuxfoundation.org ([140.211.169.12]:48726 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S966070AbbBDXqU (ORCPT ); Wed, 4 Feb 2015 18:46:20 -0500 Date: Wed, 4 Feb 2015 15:46:18 -0800 From: Andrew Morton To: Sasha Levin Cc: Peter Zijlstra , Ingo Molnar , Linus Torvalds , Andrey Ryabinin , Dave Jones , LKML Subject: Re: sched: memory corruption on completing completions Message-Id: <20150204154618.36511661ab558c0a9e047a77@linux-foundation.org> In-Reply-To: <54D2AA16.6030706@oracle.com> References: <54D2AA16.6030706@oracle.com> X-Mailer: Sylpheed 3.4.1 (GTK+ 2.24.23; x86_64-pc-linux-gnu) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Wed, 04 Feb 2015 18:24:06 -0500 Sasha Levin wrote: > Hi all, > > I was fuzzing with trinity on a -next kernel with the KASan patchset, and > got what initially appeared to be a rather odd trace: > > ... > > > I now have a theory for why it happens: > > Thread A Thread B > ---------------------------------------------------------- > > [Enter function] > DECLARE_COMPLETION_ONSTACK(x) > wait_for_completion(x) > complete(x) > [In complete(x):] > spin_lock_irqsave(&x->wait.lock, flags); > x->done++; > __wake_up_locked(&x->wait, TASK_NORMAL, 1); > [Done waiting, wakes up] > [Exit function] > spin_unlock_irqrestore(&x->wait.lock, flags); > > > > So the spin_unlock_irqrestore() at the end of complete() would proceed to corruption > the stack of thread A. But wait_for_completion() takes ->wait.lock as well, which should provide the needed synchronization (__wait_for_common, do_wait_for_common). I'm not seeing a hole in the logic, but it looks like there might be one.