[PATCH v2] panic: stop CPUs that lose the panic_redirect_cpu race

From: Bradley Morgan

Date: Tue Jul 07 2026 - 14:34:19 EST


Loser of the redirect cmpxchg must stop, not fall through to
panic_try_start().

This issue was found by sashiko [1].

[1] https://sashiko.dev/#/patchset/20260705164123.18746-1-include%40grrlz.net

Signed-off-by: Bradley Morgan <include@xxxxxxxxx>
---
kernel/panic.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)

Changes since v1: a nested panic on the CPU that already holds
panic_redirect_cpu would fail its own cmpxchg and, with v1's
unconditional return true, halt itself and abandon the panic.
Check old_cpu == this_cpu so the winner of a nested reentry
falls through to panic_try_start() instead.

diff --git a/kernel/panic.c b/kernel/panic.c
index 03f1eef07b17..e46c37b39c40 100644
--- a/kernel/panic.c
+++ b/kernel/panic.c
@@ -400,12 +400,9 @@ static bool panic_try_force_cpu(const char *fmt, va_list args)
if (panic_in_progress())
return false;

- /*
- * Only one CPU can do the redirect. Use atomic cmpxchg to ensure
- * we don't race with another CPU also trying to redirect.
- */
+ /* Which CPU won the race? */
if (!atomic_try_cmpxchg(&panic_redirect_cpu, &old_cpu, this_cpu))
- return false;
+ return old_cpu != this_cpu;

/*
* Use dynamically allocated buffer if available, otherwise
--
2.53.0