]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
authorDavidlohr Bueso <dave@stgolabs.net>
Thu, 7 May 2026 11:29:13 +0000 (04:29 -0700)
committerThomas Gleixner <tglx@kernel.org>
Wed, 3 Jun 2026 20:11:53 +0000 (22:11 +0200)
syzbot triggered the following splat in remove_waiter() via
FUTEX_CMP_REQUEUE_PI:

  KASAN: null-ptr-deref in range [0x0000000000000a88-0x0000000000000a8f]
   class_raw_spinlock_constructor
   remove_waiter+0x159/0x1200 kernel/locking/rtmutex.c:1561
   rt_mutex_start_proxy_lock+0x103/0x120
   futex_requeue+0x10e4/0x20d0
   __x64_sys_futex+0x34f/0x4d0

task_blocks_on_rt_mutex() does not arm the waiter upon deadlock detection,
leaving waiter->task nil, where 3bfdc63936dd ("rtmutex: Use waiter::task instead
of current in remove_waiter()") made this fatal.

Furthermore, rt_mutex_start_proxy_lock() should not be calling into remove_waiter()
upon a successfully grabbing the rtmutex. 1a1fb985f2e2 ("futex: Handle early deadlock
return correctly"), moved the remove_waiter() out of __rt_mutex_start_proxy_lock()
(where 'ret' was only ever 0 or < 0) into the wrapper. Tighten this check to
account for try_to_take_rt_mutex().

Fixes: 3bfdc63936dd ("rtmutex: Use waiter::task instead of current in remove_waiter()")
Reported-by: syzbot+78147abe6c524f183ee9@syzkaller.appspotmail.com
Signed-off-by: Davidlohr Bueso <dave@stgolabs.net>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Cc: stable@vger.kernel.org
Closes: https://lore.kernel.org/all/69f114ac.050a0220.ac8b.0003.GAE@google.com/
Link: https://patch.msgid.link/20260507112913.1019537-1-dave@stgolabs.net
kernel/locking/rtmutex.c
kernel/locking/rtmutex_api.c

index 4f386ea6c79284180bfbdb402eabea37971f0ee6..daeeeef973e2d73448df6cce82530c0f60e73459 100644 (file)
@@ -1558,6 +1558,9 @@ static void __sched remove_waiter(struct rt_mutex_base *lock,
 
        lockdep_assert_held(&lock->wait_lock);
 
+       if (!waiter_task) /* never enqueued */
+               return;
+
        scoped_guard(raw_spinlock, &waiter_task->pi_lock) {
                rt_mutex_dequeue(lock, waiter);
                waiter_task->pi_blocked_on = NULL;
index 124219aea46e4445349f6e8fb53c9e8e8fc1d4c9..514fce7a4e0a44c2740ee7a823d186e134b79285 100644 (file)
@@ -365,7 +365,7 @@ int __sched rt_mutex_start_proxy_lock(struct rt_mutex_base *lock,
 
        raw_spin_lock_irq(&lock->wait_lock);
        ret = __rt_mutex_start_proxy_lock(lock, waiter, task, &wake_q);
-       if (unlikely(ret))
+       if (unlikely(ret < 0))
                remove_waiter(lock, waiter);
        preempt_disable();
        raw_spin_unlock_irq(&lock->wait_lock);