]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
rseq: Prevent hard lockup on granted time slice extension
authorNiels Pressel <npressel@ethz.ch>
Sun, 2 Aug 2026 12:44:23 +0000 (14:44 +0200)
committerThomas Gleixner <tglx@kernel.org>
Mon, 10 Aug 2026 07:37:54 +0000 (09:37 +0200)
__exit_to_user_mode_loop() invokes rseq_grant_timeslice_extension() with
interrupts enabled. If the extension is granted it invokes
hrtimer_rearm_deferred_tif() to ensure that a pending deferred hrtimer
rearm is handled before exiting to user space.

Though this invokes __hrtimer_rearm_deferred() which expects to be invoked
with interrupts disabled as it takes hrtimer_cpu_base::lock with
raw_spin_lock(). That's a livelock waiting to happen and caught by lockdep:

    WARNING: ./include/linux/hrtimer_rearm.h:17 at irqentry_exit, CPU#1: slice_test
    WARNING: inconsistent lock state
    inconsistent {IN-HARDIRQ-W} -> {HARDIRQ-ON-W} usage.

Prevent this by disabling interrupts around the invocation of
hrtimer_rearm_deferred_tif() in rseq_grant_timeslice_extension().

[ tglx: Massaged change log ]

Fixes: 15dd3a948855 ("hrtimer: Push reprogramming timers into the interrupt return path")
Signed-off-by: Niels Pressel <npressel@ethz.ch>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260802124423.51616-1-npressel@ethz.ch
include/linux/rseq_entry.h

index ed9da6e41a2aad5b2253414fec4ff4d485f808bb..31ce349ed42ce88cca7a4b0d9848abd6b899c1c1 100644 (file)
@@ -233,6 +233,7 @@ efault:
 static __always_inline bool rseq_grant_slice_extension(unsigned long ti_work, unsigned long mask)
 {
        if (unlikely(__rseq_grant_slice_extension(ti_work & mask))) {
+               guard(irq)();
                hrtimer_rearm_deferred_tif(ti_work);
                return true;
        }