futex: Acquire a hash reference in futex_wait_multiple_setup()
authorSebastian Andrzej Siewior <bigeasy@linutronix.de>
Wed, 16 Apr 2025 16:29:08 +0000 (18:29 +0200)
committerPeter Zijlstra <peterz@infradead.org>
Sat, 3 May 2025 10:02:06 +0000 (12:02 +0200)
futex_wait_multiple_setup() changes task_struct::__state to
!TASK_RUNNING and then enqueues on multiple futexes. Every
futex_q_lock() acquires a reference on the global hash which is
dropped later.

If a rehash is in progress then the loop will block on
mm_struct::futex_hash_bucket for the rehash to complete and this will
lose the previously set task_struct::__state.

Acquire a reference on the local hash to avoiding blocking on
mm_struct::futex_hash_bucket.

Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://lore.kernel.org/r/20250416162921.513656-9-bigeasy@linutronix.de
kernel/futex/waitwake.c

index d52541bcc07e9498bd04ba6254af3e78a966a75c..bd8fef0f8d1800f40c49fd2cf54d195982a82638 100644 (file)
@@ -406,6 +406,12 @@ int futex_wait_multiple_setup(struct futex_vector *vs, int count, int *woken)
        int ret, i;
        u32 uval;
 
+       /*
+        * Make sure to have a reference on the private_hash such that we
+        * don't block on rehash after changing the task state below.
+        */
+       guard(private_hash)();
+
        /*
         * Enqueuing multiple futexes is tricky, because we need to enqueue
         * each futex on the list before dealing with the next one to avoid