From: Shashank Mohan Jain <jain.sm@gmail.com>
To: Masami Hiramatsu <mhiramat@kernel.org>,
Matt Wu <wuqiang.matt@bytedance.com>
Cc: Andrew Morton <akpm@linux-foundation.org>,
linux-trace-kernel@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [PATCH 0/2] objpool: fix nested pushes from NMI context
Date: Mon, 28 Sep 2026 14:11:23 +0530 [thread overview]
Message-ID: <20260928084125.67104-1-jain.sm@gmail.com> (raw)
objpool_push() runs with interrupts disabled, but a kretprobe that
returns in NMI context can push to the same per-CPU slot in the middle
of it. With rethook-based kretprobes (and, before v6.14, fprobe) this is
reachable since kretprobes moved to objpool in v6.7. The nested push
publishes slot->last past the unwritten entry of the interrupted push,
so a pop on another CPU can take a NULL or stale pointer, which hands
an object out twice and loses another, and slot->last can move
backwards, after which a pop on the owning CPU spins with interrupts
disabled.
Patch 1 publishes the entries in order with a cmpxchg() on slot->last.
Patch 2 adds a KUnit test in which a pinned hard hrtimer stands in for
the NMI. It fails without patch 1 and passes with it.
The race was found with a TLA+ model of __objpool_try_add_slot() and
__objpool_try_get_slot() on one slot: a task push that an NMI push can
interrupt at every step, pops on another CPU, and recycled objects.
Memory is sequentially consistent, with one level of nesting. TLC finds
the bug in current code, no violation with patch 1 (up to five objects,
four task pushes, three nested pushes, five remote pops), and shows that
a plain-store version of the fix lets last fall behind head. The model
(Objpool.tla and its .cfg files) can be posted if that is useful.
No earlier report of this was found: searches of patchwork (objpool,
rethook, kretprobe, objpool_push) and of the linux-kernel archive on
marc.info (objpool NMI, objpool_push, rethook NMI, kretprobe NMI) turned
up nothing related. lore was not searched.
Testing is described under "---" in each patch. In short: KUnit on UML
x86_64 (4 CPUs, 3 runs before and after, plus 1 CPU and CONFIG_SMP=n),
W=1 builds for x86_64 and i386, checkpatch --strict. Not tested: real
NMIs through a kretprobe on hardware, weakly ordered architectures, and
performance in the kernel.
This series was prepared with Claude Code (Anthropic), model Claude
Opus 5.5 (claude-opus-5-5). The code, the test, the changelogs and this
cover letter were written with the assistant; the TLA+ model checker
TLC found the race.
Shashank Mohan Jain (2):
objpool: keep objpool_push() correct when a push from NMI nests in it
lib/tests: add KUnit test for nested objpool pushes
MAINTAINERS | 1 +
include/linux/objpool.h | 37 ++++-
lib/Kconfig.debug | 13 ++
lib/tests/Makefile | 1 +
lib/tests/objpool_kunit.c | 329 ++++++++++++++++++++++++++++++++++++++
5 files changed, 373 insertions(+), 8 deletions(-)
create mode 100644 lib/tests/objpool_kunit.c
--
2.43.0
next reply other threads:[~2026-09-28 8:41 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 8:41 Shashank Mohan Jain [this message]
2026-09-28 8:41 ` [PATCH 1/2] objpool: keep objpool_push() correct when a push from NMI nests in it Shashank Mohan Jain
2026-09-28 22:44 ` Andrew Morton
2026-09-29 1:20 ` shashank Jain
2026-09-28 8:41 ` [PATCH 2/2] lib/tests: add KUnit test for nested objpool pushes Shashank Mohan Jain
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928084125.67104-1-jain.sm@gmail.com \
--to=jain.sm@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=mhiramat@kernel.org \
--cc=wuqiang.matt@bytedance.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®