From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mta1.migadu.com (out-189.mta1.migadu.com [95.215.58.189]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E887B22B8AB for ; Wed, 30 Sep 2026 01:57:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.189 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790733442; cv=none; b=aSokYazBDx7R6uIuOnUsaXFq0oufRAT5wd7tcpYOrIU33y1lLlQpqwI2fCryu3Lx613U86lk+ZgayC4L96AFThSYuNfgeyijHUijY9omuLk9JxwohFWRxmRBaT0SaLviauavldAAE1thDiucRybZIwc7ZT4GDScFqv6yRowsNaE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790733442; c=relaxed/simple; bh=4gjicBS7+xysVtPZ+uaOJ5pxKfc6JICBFUNecihq6yc=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=ZNWTjSnOIAmL8u8l7WZaNAk19J5yO85Fe4/hXT6A3AzNTGHJ4kts0ABt0UsuXYTnw3XWweskcPg0O8lM2qFjjpq1xDv6YEfSw2h9oGMfifo1ye4MIEQ94oO9aPGvWr1NNFai5QzPa1/S5C/PU6NMOn7uVw7mdOdFEwEcgaR1JT8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=kwOmY4wI; arc=none smtp.client-ip=95.215.58.189 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="kwOmY4wI" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=4gjicBS7+xysVtPZ+uaOJ5pxKfc6JICBFUNecihq6yc=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1790733439; v=1; x=1791338239; b=kwOmY4wIgw4XHLor6rKvK7NqOzLf3zOoM7lxfsgtXGn7oe7E4IcClBGV+ENgMQ4J9Az7hGsK plOq9zRL0SOsEO1wTdpmizyu8AyooOXvhiRTrv/HEWoUlPmnXKEh62GnalaVSFk/1a5bHww5kng FhEV4NRTb665S2MJBuGqiV44= X-Envelope-To: linux-kernel@vger.kernel.org Received: by smtp.migadu.com with ESMTPS id adc322b5cf7af8d2; Wed, 30 Sep 2026 01:57:19 +0000 X-Mizu-Trace-ID: adc322b5cf7af8d2 X-Migadu-Flow: FLOW_OUT Message-ID: <3d8bbe2c-8baa-43a6-9926-66669b96bfb9@linux.dev> Date: Wed, 30 Sep 2026 09:57:11 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] cgroup/cpuset: Don't access cpuset_cgrp_subsys.root in is_in_v2_mode() To: Waiman Long , Tejun Heo , Johannes Weiner , =?UTF-8?Q?Michal_Koutn=C3=BD?= Cc: cgroups@vger.kernel.org, linux-kernel@vger.kernel.org, Andrea Righi References: <20260930012819.651526-1-longman@redhat.com> From: Ridong Chen In-Reply-To: <20260930012819.651526-1-longman@redhat.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 9/30/2026 9:28 AM, Waiman Long wrote: > After seeing the patch [1] to guard is_in_v2_mode() with RCU, it makes > me realize that is_in_v2_mode() may be called in a context where a new > cgroup filesystem is being rebound with stale cpuset_cgrp_subsys.root > pointer. Avoid this potential UaF situation by adding a new cpuset_v2_mode > flag which is set when the cpuset_v2_mode mount option is used. This > flag is written into only when cpuset_bind() is being called with a > stable cpuset_cgrp_subsys.root value. The is_in_v2_mode() helper is > modified to read the new cpuset_v2_mode flag instead of accessing > cpuset_cgrp_subsys.root directly. > > [1] https://lore.kernel.org/lkml/20260929084124.626693-2-arighi@nvidia.com > > Fixes: b8d1b8ee93df ("cpuset: Allow v2 behavior in v1 cgroup") > Signed-off-by: Waiman Long > --- > kernel/cgroup/cpuset.c | 10 ++++++++-- > 1 file changed, 8 insertions(+), 2 deletions(-) > > diff --git a/kernel/cgroup/cpuset.c b/kernel/cgroup/cpuset.c > index 19661df6244f..266ce17d1af0 100644 > --- a/kernel/cgroup/cpuset.c > +++ b/kernel/cgroup/cpuset.c > @@ -147,6 +147,11 @@ static cpumask_var_t subpartitions_cpus; /* RWCS */ > */ > static cpumask_var_t isolated_cpus; /* CSCB */ > > +/* > + * Set if "cpuset_v2_mode" mount option is used > + */ > +static bool cpuset_v2_mode; /* Unprotected */ > + Nit. `Unprotected` is wired here, will it be better with: /* Cached at bind time; accessed via {READ,WRITE}_ONCE */ > /* > * Set if housekeeping cpumasks are to be updated. > */ > @@ -439,8 +444,7 @@ static inline bool cpuset_v2(void) > */ > static inline bool is_in_v2_mode(void) > { > - return cpuset_v2() || > - (cpuset_cgrp_subsys.root->flags & CGRP_ROOT_CPUSET_V2_MODE); > + return cpuset_v2() || READ_ONCE(cpuset_v2_mode); > } > > /** > @@ -3664,6 +3668,8 @@ static void cpuset_bind(struct cgroup_subsys_state *root_css) > mutex_lock(&cpuset_mutex); > spin_lock_irq(&callback_lock); > > + WRITE_ONCE(cpuset_v2_mode, > + !!(cpuset_cgrp_subsys.root->flags & CGRP_ROOT_CPUSET_V2_MODE)); > if (is_in_v2_mode()) { > cpumask_copy(top_cpuset.cpus_allowed, cpu_possible_mask); > cpumask_copy(top_cpuset.effective_xcpus, cpu_possible_mask); Reviewed-by: Ridong Chen Thanks. -- Best regards Ridong