diff options
| author | Linus Torvalds <torvalds@linux-foundation.org> | 2026-10-04 08:29:27 -0700 |
|---|---|---|
| committer | Linus Torvalds <torvalds@linux-foundation.org> | 2026-10-04 08:29:27 -0700 |
| commit | 1c915d6007fab5b87a8c2516dfd37dd614875f9c (patch) | |
| tree | 0f849230583ce24a91f1b4c3090cad78d15d0c7c | |
| parent | 6addb4f385570ebc11c4eb499a4f1c149f313e84 (diff) | |
| parent | f35e3b5784221654f9cdbd6222275a7fa203f6c3 (diff) | |
| download | linux-stable-1c915d6007fab5b87a8c2516dfd37dd614875f9c.tar.gz linux-stable-1c915d6007fab5b87a8c2516dfd37dd614875f9c.zip | |
Merge tag 'locking-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
Pull locking fixes from Ingo Molnar:
- Don't run refcount kunit self-test when !CONFIG_KUNIT_ALL_TESTS
(Kuan-Wei Chiu)
- Fix futex private hash use-after-free on resize (Chris Mason)
* tag 'locking-urgent-2026-10-04' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
futex: Fix private hash use-after-free on resize
irq: Make refcount_interrupt kunit test selectable
| -rw-r--r-- | kernel/futex/core.c | 10 | ||||
| -rw-r--r-- | kernel/irq/Kconfig | 12 | ||||
| -rw-r--r-- | kernel/irq/Makefile | 2 |
3 files changed, 19 insertions, 5 deletions
diff --git a/kernel/futex/core.c b/kernel/futex/core.c index a061f54b6..095f9fe44 100644 --- a/kernel/futex/core.c +++ b/kernel/futex/core.c @@ -213,10 +213,12 @@ static bool __futex_pivot_hash(struct mm_struct *mm, struct futex_private_hash * futex_rehash_private(fph, new); } new->state = FR_PERCPU; - scoped_guard(rcu) { - mmph->batches = get_state_synchronize_rcu(); - rcu_assign_pointer(mmph->hash, new); - } + rcu_assign_pointer(mmph->hash, new); + /* + * mmph->batches must reference a grace period which started after + * mmph->hash was assigned. See futex_ref_drop(). + */ + mmph->batches = get_state_synchronize_rcu(); kvfree_rcu(fph, rcu); return true; } diff --git a/kernel/irq/Kconfig b/kernel/irq/Kconfig index 05cba4e16..6923f37ea 100644 --- a/kernel/irq/Kconfig +++ b/kernel/irq/Kconfig @@ -150,6 +150,18 @@ config IRQ_KUNIT_TEST If unsure, say N. +config REFCOUNT_INTERRUPT_KUNIT_TEST + tristate "Test refcounted interrupt enable/disable" if !KUNIT_ALL_TESTS + depends on KUNIT + default KUNIT_ALL_TESTS + help + This builds the kunit tests for the refcounted interrupt + infrastructure. It verifies the correctness of single, nested, + and multiple interrupt enable/disable state changes and ensures + that the underlying reference counting mechanisms work as expected. + + If unsure, say N. + endmenu config GENERIC_IRQ_MULTI_HANDLER diff --git a/kernel/irq/Makefile b/kernel/irq/Makefile index 44c4d6fc5..0e5df962a 100644 --- a/kernel/irq/Makefile +++ b/kernel/irq/Makefile @@ -16,4 +16,4 @@ obj-$(CONFIG_SMP) += affinity.o obj-$(CONFIG_GENERIC_IRQ_DEBUGFS) += debugfs.o obj-$(CONFIG_GENERIC_IRQ_MATRIX_ALLOCATOR) += matrix.o obj-$(CONFIG_IRQ_KUNIT_TEST) += irq_test.o -obj-$(CONFIG_KUNIT) += refcount_interrupt_test.o +obj-$(CONFIG_REFCOUNT_INTERRUPT_KUNIT_TEST) += refcount_interrupt_test.o |
