Re: [PATCH] maple_tree: Annotate lockless pivot reads for KCSAN

From: Andrew Morton

Date: Wed Aug 26 2026 - 13:07:39 EST


On Wed, 26 Aug 2026 15:44:30 +0800 "Hui Zhu" <hui.zhu@xxxxxxxxx> wrote:

> In RCU mode, replaced maple nodes are marked dead and freed via RCU
> after the new node has been published. Arming the RCU free writes
> node->rcu.next and node->rcu.func, which share storage with
> pivot[0] and pivot[1] (see struct maple_node), while lockless
> readers may still walk the dead node. These stores therefore race
> with the pivot loads performed by the walkers.
>
> This is harmless: the writer marks the node dead with an smp_wmb()
> before arming the rcu_head, and the walkers re-check ma_dead_node()
> after reading the node and restart the walk when the node is dead,
> so any pivot read that raced with the rcu_head stores is discarded.
> KCSAN cannot see this protocol and reports the plain accesses, so
> annotate the lockless pivot reads with data_race() through a new
> ma_pivot_rcu() helper.
>
> Found by fuzzing on a 6.6 kernel; the race still exists on
> mainline. No functional change intended.


Thanks. AI review suggests that the patch is correct, but incomplete?

https://sashiko.dev/#/patchset/20260826074430.1139325-1-hui.zhu@xxxxxxxxx