[PATCH v2] Fix data races on hrtimer_sleeper ->task field
WARM2d
From: "Paul E. McKenney" <paulmck@kernel.org>
Date: 2026-09-19 00:13:23
Also in:
io-uring, linux-fsdevel, lkml
Hello! In CONFIG_KCSAN_STRICT=y mode, KCSAN finds data races on the hrtimer_sleeper structure's ->task field. This field is used to indicate owner of this structure, and also to signal the sleeper that the sleep is over through use of a store of NULL. Because access to the ->task field is open-coded across several kernel subsystems, this series creates accessor functions creatively named hrtimer_sleeper_task_get() and hrtimer_sleeper_task_set(), and uses these throughout. While in the area, also apply READ_ONCE() to lockless loads from base->running. A key goal of this and similar serieses is to reduce KCSAN noise in strict mode so that new data races are more visible. The series is as follows: 1. Mark data-racy accesses to hrtimer_sleeper ->task field. 2. Use accessor for hrtimer_sleeper ->task field. 3. Use accessor for hrtimer_sleeper ->task field. 4. Use accessor for hrtimer_sleeper ->task field. 5. Use accessor for hrtimer_sleeper ->task field in waitwake.c. 6. Use accessor for hrtimer_sleeper ->task field in sleep_timeout.c. 7. pktgen: Use accessor for hrtimer_sleeper ->task field. 8. Use accessor for hrtimer_sleeper ->task field. 9. Use accessor for hrtimer_sleeper ->task field in requeue. 10. Update hrtimer_resolution only if value changes. 11. Mark the hrtimer_sleeper structure's ->task field __private. 12. Apply READ_ONCE() to lockless base->running loads. Thanx, Paul Changes since RFC v1: o Add patch 10 to avoid both cache misses and KCSAN false positives when updating hrtimer_resolution. o Add patch 11 to mark the hrtimer_sleeper structure's ->task field __private, as suggested by Thomas Gleixner. o Add patch 12 for a similar KCSAN issue involving lockless loads from base->running. ------------------------------------------------------------------------ b/fs/aio.c | 2 +- b/include/linux/hrtimer.h | 8 ++++++++ b/include/linux/wait.h | 2 +- b/io_uring/rw.c | 2 +- b/kernel/futex/requeue.c | 2 +- b/kernel/futex/waitwake.c | 8 ++++---- b/kernel/locking/rtmutex.c | 2 +- b/kernel/time/hrtimer.c | 14 +++++++------- b/kernel/time/sleep_timeout.c | 4 ++-- b/net/core/pktgen.c | 4 ++-- include/linux/hrtimer.h | 6 +++--- kernel/time/hrtimer.c | 9 +++++---- 12 files changed, 36 insertions(+), 27 deletions(-)