summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLinus Torvalds <torvalds@linux-foundation.org>2026-10-04 08:29:27 -0700
committerLinus Torvalds <torvalds@linux-foundation.org>2026-10-04 08:29:27 -0700
commit1c915d6007fab5b87a8c2516dfd37dd614875f9c (patch)
tree0f849230583ce24a91f1b4c3090cad78d15d0c7c
parent6addb4f385570ebc11c4eb499a4f1c149f313e84 (diff)
parentf35e3b5784221654f9cdbd6222275a7fa203f6c3 (diff)
downloadlinux-stable-1c915d6007fab5b87a8c2516dfd37dd614875f9c.tar.gz
linux-stable-1c915d6007fab5b87a8c2516dfd37dd614875f9c.zip
Merge tag 'locking-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull locking fixes from Ingo Molnar: - Don't run refcount kunit self-test when !CONFIG_KUNIT_ALL_TESTS (Kuan-Wei Chiu) - Fix futex private hash use-after-free on resize (Chris Mason) * tag 'locking-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip: futex: Fix private hash use-after-free on resize irq: Make refcount_interrupt kunit test selectable
-rw-r--r--kernel/futex/core.c10
-rw-r--r--kernel/irq/Kconfig12
-rw-r--r--kernel/irq/Makefile2
3 files changed, 19 insertions, 5 deletions
diff --git a/kernel/futex/core.c b/kernel/futex/core.c
index a061f54b6..095f9fe44 100644
--- a/kernel/futex/core.c
+++ b/kernel/futex/core.c
@@ -213,10 +213,12 @@ static bool __futex_pivot_hash(struct mm_struct *mm, struct futex_private_hash *
futex_rehash_private(fph, new);
}
new->state = FR_PERCPU;
- scoped_guard(rcu) {
- mmph->batches = get_state_synchronize_rcu();
- rcu_assign_pointer(mmph->hash, new);
- }
+ rcu_assign_pointer(mmph->hash, new);
+ /*
+ * mmph->batches must reference a grace period which started after
+ * mmph->hash was assigned. See futex_ref_drop().
+ */
+ mmph->batches = get_state_synchronize_rcu();
kvfree_rcu(fph, rcu);
return true;
}
diff --git a/kernel/irq/Kconfig b/kernel/irq/Kconfig
index 05cba4e16..6923f37ea 100644
--- a/kernel/irq/Kconfig
+++ b/kernel/irq/Kconfig
@@ -150,6 +150,18 @@ config IRQ_KUNIT_TEST
If unsure, say N.
+config REFCOUNT_INTERRUPT_KUNIT_TEST
+ tristate "Test refcounted interrupt enable/disable" if !KUNIT_ALL_TESTS
+ depends on KUNIT
+ default KUNIT_ALL_TESTS
+ help
+ This builds the kunit tests for the refcounted interrupt
+ infrastructure. It verifies the correctness of single, nested,
+ and multiple interrupt enable/disable state changes and ensures
+ that the underlying reference counting mechanisms work as expected.
+
+ If unsure, say N.
+
endmenu
config GENERIC_IRQ_MULTI_HANDLER
diff --git a/kernel/irq/Makefile b/kernel/irq/Makefile
index 44c4d6fc5..0e5df962a 100644
--- a/kernel/irq/Makefile
+++ b/kernel/irq/Makefile
@@ -16,4 +16,4 @@ obj-$(CONFIG_SMP) += affinity.o
obj-$(CONFIG_GENERIC_IRQ_DEBUGFS) += debugfs.o
obj-$(CONFIG_GENERIC_IRQ_MATRIX_ALLOCATOR) += matrix.o
obj-$(CONFIG_IRQ_KUNIT_TEST) += irq_test.o
-obj-$(CONFIG_KUNIT) += refcount_interrupt_test.o
+obj-$(CONFIG_REFCOUNT_INTERRUPT_KUNIT_TEST) += refcount_interrupt_test.o