From: Kyle Zeng <kylebot@openai.com>
To: linux-kernel@vger.kernel.org
Cc: tglx@kernel.org, mingo@redhat.com,
outbounddisclosures@openai.com, Kyle Zeng <kylebot@openai.com>
Subject: [PATCH] futex: Use a keyed hash for global futex buckets
Date: Tue, 6 Oct 2026 15:24:50 -0700 [thread overview]
Message-ID: <20261006222450.42518-1-kylebot@openai.com> (raw)
The global futex hash is a public jhash2 of the key, which for private
and shared-anonymous futexes includes an mm_struct pointer. A task can
populate a bucket with futex_waitv() and time nonmatching wakes to learn
which chosen user addresses collide. Shared-file keys have predictable
inode sequence numbers, so the task can also identify the bucket and
turn those timings into constraints on current->mm.
The per-mm private hash does not prevent this: a task can disable it
through PR_FUTEX_HASH. NUMA-routed private futexes and shared-anonymous
keys also use the global hash.
Use SipHash-2-4 with a boot-time random key for global bucket selection.
Hash the three identity fields individually, without padding or the
separately handled NUMA node. Keep the original futex keys and equality
checks, and leave the per-mm hash, which only hashes userspace addresses
and offsets, unchanged. Initialize the secret before the global tables
are made available and keep it fixed for their lifetime.
Assisted-by: Codex:gpt-6-astra
Signed-off-by: Kyle Zeng <kylebot@openai.com>
---
kernel/futex/core.c | 13 +++++++++++--
1 file changed, 11 insertions(+), 2 deletions(-)
diff --git a/kernel/futex/core.c b/kernel/futex/core.c
index a061f54b606d..941713b62ee1 100644
--- a/kernel/futex/core.c
+++ b/kernel/futex/core.c
@@ -42,7 +42,9 @@
#include <linux/pagemap.h>
#include <linux/plist.h>
#include <linux/prctl.h>
+#include <linux/random.h>
#include <linux/rseq.h>
+#include <linux/siphash.h>
#include <linux/slab.h>
#include <linux/vmalloc.h>
#include <linux/kmemleak.h>
@@ -58,6 +60,7 @@
static u32 __futex_mask __ro_after_init;
static u32 __futex_shift __ro_after_init;
static struct futex_hash_bucket **__futex_queues __ro_after_init;
+static siphash_key_t futex_hash_key __ro_after_init;
static __always_inline struct futex_hash_bucket **futex_queues(void)
{
@@ -386,8 +389,12 @@ __futex_hash(union futex_key *key, struct futex_private_hash *fph, struct futex_
}
#endif
- hash = jhash2((u32 *)key, offsetof(typeof(*key), both.offset) / sizeof(u32),
- key->both.offset);
+ /*
+ * Global bucket collisions are observable through futex operations.
+ * Use a keyed hash so they do not disclose the mm pointer in the key.
+ */
+ hash = siphash_3u64(key->both.ptr, key->both.word, key->both.offset,
+ &futex_hash_key);
if (node == FUTEX_NO_NODE) {
/*
@@ -2090,6 +2097,8 @@ static int __init futex_init(void)
unsigned int order, n;
unsigned long size;
+ get_random_bytes(&futex_hash_key, sizeof(futex_hash_key));
+
#ifdef CONFIG_BASE_SMALL
hashsize = 16;
#else
reply other threads:[~2026-10-06 22:24 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261006222450.42518-1-kylebot@openai.com \
--to=kylebot@openai.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=outbounddisclosures@openai.com \
--cc=tglx@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®