[PATCH v7 0/7] x86,fs/resctrl: Fix long-standing issues
From: Reinette Chatre
Date: Mon Jul 13 2026 - 13:40:34 EST
v6: https://lore.kernel.org/lkml/cover.1783377598.git.reinette.chatre@xxxxxxxxx/
v5: https://lore.kernel.org/lkml/cover.1781029125.git.reinette.chatre@xxxxxxxxx/
v4: https://lore.kernel.org/lkml/cover.1780456704.git.reinette.chatre@xxxxxxxxx/
v3: https://lore.kernel.org/lkml/cover.1779476724.git.reinette.chatre@xxxxxxxxx/
v2: https://lore.kernel.org/lkml/20260515193944.15114-1-tony.luck@xxxxxxxxx/
v1: https://lore.kernel.org/all/20260508182143.14592-1-tony.luck@xxxxxxxxx/
While reviewing the AET series [1] Sashiko reported a deadlock during mount,
and a use-after-free when an L3 domain is removed during CPU offline. More issues
were uncovered as fixes were developed and reviewed. While the goal is to
fix all issues the races surrounding pseudo-locked regions are not yet
solved and have been removed from this series (last appearance was in V3 of
this series).
Applies against v7.2-rc3.
Changes since V6:
- Drop first three patches that are in v7.2-rc3.
- Remove extra blank lines. (Tony)
- No functional changes.
Changes since V5:
- Drop patch #1 (x86,fs/resctrl: Prevent out-of-bounds access while offlining
CPU when SNC enabled) that can be found in v7.2-rc2.
- Re-order remaining patches so that stable candidate patches are at
beginning of series. The stable candidates are:
Patch 1: fs/resctrl: Free mon_data structures on rdt_get_tree() failure
Patch 2: fs/resctrl: Fix use-after-free during unmount
Patch 3: fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list
- To support the backporting to stable patch #1 adds a forward declaration
that is removed in patch #5 that moves the actual functions to avoid too many
forward declarations.
- The end result of changes since v5: v6 net changes are identical to V5
changes.
Changes since V4:
- Add new fix to prevent out-of-bouds read when SNC is enabled and domain
with busy RMID goes offline.
- Add substitute for "is domain going offline" check to workers to avoid
reading any event counters on soon-to-be-offline domain since its
cpu_mask is empty and reading an event counter on an SNC enabled system
depends on knowing a CPU associated with the domain.
Changes since V3:
- Drop majority of pseudo-locking fixes, only keep the double free/double
list add fix.
- Add patch to help document safe RCU list traversal.
- See individual patches for detailed changes.
[1] https://sashiko.dev/#/patchset/20260429184858.36423-1-tony.luck%40intel.com
Reinette Chatre (6):
x86,fs/resctrl: Document safe RCU list traversal
fs/resctrl: Fix deadlock on errors during mount
fs/resctrl: Prevent use-after-free in rdtgroup_kn_put()
fs/resctrl: Prevent deadlock and use-after-free in info file handlers
x86/resctrl: Ensure domain fully initialized before placed on RCU list
fs/resctrl: Fix UAF from worker threads when domains are removed
Tony Luck (1):
fs/resctrl: Move functions to avoid forward references in subsequent
fixes
arch/x86/kernel/cpu/resctrl/core.c | 18 +-
arch/x86/kernel/cpu/resctrl/ctrlmondata.c | 4 +-
arch/x86/kernel/cpu/resctrl/intel_aet.c | 5 +-
arch/x86/kernel/cpu/resctrl/monitor.c | 2 +-
arch/x86/kernel/cpu/resctrl/rdtgroup.c | 4 +-
fs/resctrl/ctrlmondata.c | 50 +-
fs/resctrl/internal.h | 3 +-
fs/resctrl/monitor.c | 131 ++--
fs/resctrl/pseudo_lock.c | 2 +-
fs/resctrl/rdtgroup.c | 858 +++++++++++++---------
10 files changed, 660 insertions(+), 417 deletions(-)
base-commit: a13c140cc289c0b7b3770bce5b3ad42ab35074aa
--
2.54.0