mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] workqueue: Fix NULL current_pwq deref in chained work check
@ 2026-09-28  3:48 Pavankumar Kondeti
  2026-09-28 18:18 ` Tejun Heo
  0 siblings, 1 reply; 2+ messages in thread
From: Pavankumar Kondeti @ 2026-09-28  3:48 UTC (permalink / raw)
  To: Tejun Heo, Lai Jiangshan; +Cc: linux-kernel, stable, Pavankumar Kondeti

current_wq_worker() only tells us that %current is a kworker. It does
not guarantee that the worker is currently executing a work item, as
worker->current_pwq is populated only while process_one_work() is running
the work function.

is_chained_work() can be reached while queueing on a draining or
destroying workqueue. If a kworker outside work-item execution reaches
that path, current_wq_worker() returns a worker but worker->current_pwq is
NULL, and the chained-work test can fault before it emits the intended
warning.

Guard the chained-work test with worker->current_pwq. A kworker without
current_pwq is not executing work on the target workqueue, so the helper
should return false and let the draining/destroying warning fire.

Fixes: c8efcc258946 ("workqueue: allow chained queueing during destruction")
Cc: stable@vger.kernel.org
Signed-off-by: Pavankumar Kondeti <pavan.kondeti@oss.qualcomm.com>
---
 kernel/workqueue.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/kernel/workqueue.c b/kernel/workqueue.c
index 959525393739..c56c042d1c35 100644
--- a/kernel/workqueue.c
+++ b/kernel/workqueue.c
@@ -2290,7 +2290,7 @@ static bool is_chained_work(struct workqueue_struct *wq)
 	 * Return %true iff I'm a worker executing a work item on @wq.  If
 	 * I'm @worker, it's safe to dereference it without locking.
 	 */
-	return worker && worker->current_pwq->wq == wq;
+	return worker && worker->current_pwq && worker->current_pwq->wq == wq;
 }
 
 /*

---
base-commit: 72d3fcf802c45d00b300f25b848a93c3a2bd7c7e
change-id: 20260928-wq_chain_fix-9f3814625b1a

Best regards,
-- 
Pavankumar Kondeti <pavan.kondeti@oss.qualcomm.com>


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] workqueue: Fix NULL current_pwq deref in chained work check
  2026-09-28  3:48 [PATCH] workqueue: Fix NULL current_pwq deref in chained work check Pavankumar Kondeti
@ 2026-09-28 18:18 ` Tejun Heo
  0 siblings, 0 replies; 2+ messages in thread
From: Tejun Heo @ 2026-09-28 18:18 UTC (permalink / raw)
  To: Pavankumar Kondeti; +Cc: Lai Jiangshan, linux-kernel, stable

Applied to wq/for-7.3-fixes with the Fixes tag updated to the commit that
added the unguarded deref:

  Fixes: 8d03ecfe4718 ("workqueue: reimplement is_chained_work() using current_wq_worker()")

Thanks.

--
tejun

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-28 18:18 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28  3:48 [PATCH] workqueue: Fix NULL current_pwq deref in chained work check Pavankumar Kondeti
2026-09-28 18:18 ` Tejun Heo

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®