Re: [PATCH printk] printk/nbcon: Change nbcon_irq_work to IRQ_WORK_LAZY

From: John Ogness

Date: Fri Aug 28 2026 - 05:40:43 EST


On 2026-08-27, Sashiko wrote:
>> diff --git a/kernel/printk/nbcon.c b/kernel/printk/nbcon.c
>> index a5921a84a80ed..ad79e30afd647 100644
>> --- a/kernel/printk/nbcon.c
>> +++ b/kernel/printk/nbcon.c
>> @@ -1782,7 +1782,7 @@ bool nbcon_alloc(struct console *con)
>> }
>>
>> rcuwait_init(&con->rcuwait);
>> - init_irq_work(&con->irq_work, nbcon_irq_work);
>> + con->irq_work = IRQ_WORK_INIT_LAZY(nbcon_irq_work);
>
> This is a pre-existing issue, but does missing irq_work_sync() during
> console unregistration lead to a use-after-free and lockless list corruption,
> which is heavily exacerbated by the shift to IRQ_WORK_LAZY here?
>
> In a rapid unregister/re-register cycle, overwriting con->irq_work without a
> prior sync corrupts the lockless llist if the old irq_work was still queued.
>
> When a console is unregistered (e.g., via module unload or hotplug unplug),
> nbcon_free() stops the printing kthread:
>
> kernel/printk/nbcon.c:nbcon_free() {
> ...
> if (printk_kthreads_running) {
> nbcon_kthread_stop(con);
> ...
> }
>
> However, it does not call irq_work_sync(&con->irq_work) before the driver
> frees the console structure.
>
> Since this patch changes the initialization to IRQ_WORK_LAZY, the irq_work
> execution is deferred until the next timer tick.
>
> This massively widens the race window, guaranteeing the irq_work remains
> queued on the CPU's lazy_list while the console is being freed.
>
> The asynchronous callback then dereferences the freed console object:
>
> kernel/printk/nbcon.c:nbcon_irq_work() {
> struct console *con = container_of(irq_work, struct console, irq_work);
>
> nbcon_kthread_wake(con);
> }
>
> Should nbcon_free() be updated to include irq_work_sync(&con->irq_work) to
> flush pending work before the driver is allowed to free the console memory?

Yes, this is needed. I will post a v2 series with a preceeding patch to
add the irq_work_sync().

John