From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp153-141.sina.com.cn (smtp153-141.sina.com.cn [61.135.153.141]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C36AD3A1D0B for ; Thu, 26 Feb 2026 10:05:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=61.135.153.141 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772100348; cv=none; b=FBCGayuRg/aw2Z1+nOsUep/nnIfslPJnxL9s7sVEchrQn9hi3QVuTOFle30LrbLQXVgoSLVV4JL3Tba0JKISfUXEUlvDIemRudD3t2/tp8wA4yv5UV17pFv2At7ydocK8M8yMFPn3Ph9uexvJylSYNeVxHL4ohhFfwxoujOxrxI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772100348; c=relaxed/simple; bh=jRM/moQHrbc0Cb0CJu7f4UFsjE5p527I7yxcVDiO5YQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=duAZcD78YoloGWYbxA4/Vydr3tQ5F74/T+mTeX43w66c4ChgZKnswjpXsrYx3B9e8JrKPwqM7FolhEXXHhBNSd9ImjGLMklDnqE3dP1LL+ZFEeIP7T3wK2+iuJN8XZp+GbKOuFD2+dRCHzOVzwunqrJvGEUgIls4y69pC/fK91E= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=sina.com; spf=pass smtp.mailfrom=sina.com; dkim=pass (1024-bit key) header.d=sina.com header.i=@sina.com header.b=mes5TdWv; arc=none smtp.client-ip=61.135.153.141 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=sina.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=sina.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=sina.com header.i=@sina.com header.b="mes5TdWv" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sina.com; s=201208; t=1772100340; bh=9nxvYoWX2bRy4kjk+cVmpHUm8rsCYlbaa0LNHK7hqAg=; h=From:Subject:Date:Message-ID; b=mes5TdWvHdkKdIU/9+TRL4HXu48dwEFLX1rOzZvP649kvabjxi6WeDuptdwYqgsRP Y5rktjC8zWYL290I9u29JdE3sv+H8z4iRAwb+sV3TMInwdwGNp1Noz7zPIZyiddfoW xLBNbpyRQY1l9tFEMSQJgz0SyP7s3ipx4Z2RjutI= X-SMAIL-HELO: localhost.localdomain Received: from unknown (HELO localhost.localdomain)([114.249.62.144]) by sina.com (10.54.253.31) with ESMTP id 69A01AED00006231; Thu, 26 Feb 2026 18:05:36 +0800 (CST) X-Sender: hdanton@sina.com X-Auth-ID: hdanton@sina.com Authentication-Results: sina.com; spf=none smtp.mailfrom=hdanton@sina.com; dkim=none header.i=none; dmarc=none action=none header.from=hdanton@sina.com X-SMAIL-MID: 1923186816215 X-SMAIL-UIID: 1AF9D68F17C043EFA64157A503D17D31-20260226-180536-1 From: Hillf Danton To: syzbot Cc: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Subject: Re: [syzbot] [kernel?] INFO: task hung in restrict_one_thread_callback Date: Thu, 26 Feb 2026 18:04:44 +0800 Message-ID: <20260226100526.523-1-hdanton@sina.com> In-Reply-To: <69984159.050a0220.21cd75.01bb.GAE@google.com> References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit On Fri, Feb 20, 2026 at 03:11:21AM -0800 > Hello, > > syzbot found the following issue on: > > HEAD commit: 635c467cc14e Add linux-next specific files for 20260213 > git tree: linux-next > console output: https://syzkaller.appspot.com/x/log.txt?x=1452f6e6580000 > kernel config: https://syzkaller.appspot.com/x/.config?x=61690c38d1398936 > dashboard link: https://syzkaller.appspot.com/bug?extid=7ea2f5e9dfd468201817 > compiler: Debian clang version 21.1.8 (++20251221033036+2078da43e25a-1~exp1~20251221153213.50), Debian LLD 21.1.8 > syz repro: https://syzkaller.appspot.com/x/repro.syz?x=16e41c02580000 > C reproducer: https://syzkaller.appspot.com/x/repro.c?x=15813652580000 #syz test upstream master --- x/security/landlock/tsync.c +++ y/security/landlock/tsync.c @@ -391,7 +391,8 @@ static bool schedule_task_work(struct ts ctx->task = NULL; atomic_dec(&shared_ctx->num_preparing); - atomic_dec(&shared_ctx->num_unfinished); + if (atomic_dec_return(&shared_ctx->num_unfinished) == 0) + complete_all(&shared_ctx->all_finished); } } @@ -432,16 +433,21 @@ static void cancel_tsync_works(struct ts int landlock_restrict_sibling_threads(const struct cred *old_cred, const struct cred *new_cred) { + static int concur = 0; int err; struct tsync_shared_context shared_ctx; struct tsync_works works = {}; size_t newly_discovered_threads; bool found_more_threads; + if (concur++) { + concur--; + return -EBUSY; + } atomic_set(&shared_ctx.preparation_error, 0); init_completion(&shared_ctx.all_prepared); init_completion(&shared_ctx.ready_to_commit); - atomic_set(&shared_ctx.num_unfinished, 1); + atomic_set(&shared_ctx.num_unfinished, 0); init_completion(&shared_ctx.all_finished); shared_ctx.old_cred = old_cred; shared_ctx.new_cred = new_cred; @@ -502,11 +508,8 @@ int landlock_restrict_sibling_threads(co * of for_each_thread(). We can reset it on each loop iteration because * all previous loop iterations are done with it already. * - * num_preparing is initialized to 1 so that the counter can not go to 0 - * and mark the completion as done before all task works are registered. - * We decrement it at the end of the loop body. */ - atomic_set(&shared_ctx.num_preparing, 1); + atomic_set(&shared_ctx.num_preparing, 0); reinit_completion(&shared_ctx.all_prepared); /* @@ -515,11 +518,7 @@ int landlock_restrict_sibling_threads(co */ found_more_threads = schedule_task_work(&works, &shared_ctx); - /* - * Decrement num_preparing for current, to undo that we initialized it - * to 1 a few lines above. - */ - if (atomic_dec_return(&shared_ctx.num_preparing) > 0) { + if (atomic_read(&shared_ctx.num_preparing) > 0) { if (wait_for_completion_interruptible( &shared_ctx.all_prepared)) { /* In case of interruption, we need to retry the system call. */ @@ -548,14 +547,11 @@ int landlock_restrict_sibling_threads(co */ complete_all(&shared_ctx.ready_to_commit); - /* - * Decrement num_unfinished for current, to undo that we initialized it to 1 - * at the beginning. - */ - if (atomic_dec_return(&shared_ctx.num_unfinished) > 0) + if (atomic_read(&shared_ctx.num_unfinished) > 0) wait_for_completion(&shared_ctx.all_finished); tsync_works_release(&works); + concur--; return atomic_read(&shared_ctx.preparation_error); } --