[tip: timers/core] timers/migration: Mark racy updates to tmigr_event::ignore field

From: tip-bot2 for Paul E. McKenney

Date: Tue Sep 29 2026 - 15:14:52 EST


The following commit has been merged into the timers/core branch of tip:

Commit-ID: bb41ece16463b76b4d73fc47e6648fd823236765
Gitweb: https://git.kernel.org/tip/bb41ece16463b76b4d73fc47e6648fd823236765
Author: Paul E. McKenney <paulmck@xxxxxxxxxx>
AuthorDate: Fri, 18 Sep 2026 17:25:23 -07:00
Committer: Thomas Gleixner <tglx@xxxxxxxxxx>
CommitterDate: Tue, 29 Sep 2026 21:07:15 +02:00

timers/migration: Mark racy updates to tmigr_event::ignore field

The tmigr_event structure's ignore field is sometimes accessed locklessly,
but the __tmigr_cpu_activate(), tmigr_cpu_new_timer(), and
__tmigr_cpu_deactivate() functions do not mark accesses to this field.

Therefore, use READ_ONCE() for the tmigr_cpu_new_timer() function's
lockless load and WRITE_ONCE() for the __tmigr_cpu_activate() and
__tmigr_cpu_deactivate() functions' stores.

KCSAN located this issue.

Signed-off-by: Paul E. McKenney <paulmck@xxxxxxxxxx>
Signed-off-by: Thomas Gleixner <tglx@xxxxxxxxxx>
Link: https://patch.msgid.link/20260919002523.3133928-2-paulmck@xxxxxxxxxx
---
kernel/time/timer_migration.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/kernel/time/timer_migration.c b/kernel/time/timer_migration.c
index 059d433..f920e73 100644
--- a/kernel/time/timer_migration.c
+++ b/kernel/time/timer_migration.c
@@ -715,7 +715,7 @@ static void __tmigr_cpu_activate(struct tmigr_cpu *tmc)

trace_tmigr_cpu_active(tmc);

- tmc->cpuevt.ignore = true;
+ WRITE_ONCE(tmc->cpuevt.ignore, true);
WRITE_ONCE(tmc->wakeup, KTIME_MAX);

walk_groups(&tmigr_active_up, &data, tmc);
@@ -1258,7 +1258,7 @@ u64 tmigr_cpu_new_timer(u64 nextexp)
ret = READ_ONCE(tmc->wakeup);
if (nextexp != KTIME_MAX) {
if (nextexp != tmc->cpuevt.nextevt.expires ||
- tmc->cpuevt.ignore) {
+ READ_ONCE(tmc->cpuevt.ignore)) {
ret = tmigr_new_timer(tmc, nextexp);
/*
* Make sure the reevaluation of timers in idle path
@@ -1362,7 +1362,7 @@ static u64 __tmigr_cpu_deactivate(struct tmigr_cpu *tmc, u64 nextexp)
* or CPU goes offline.
*/
if (nextexp != KTIME_MAX)
- tmc->cpuevt.ignore = false;
+ WRITE_ONCE(tmc->cpuevt.ignore, false);

walk_groups(&tmigr_inactive_up, &data, tmc);
return data.firstexp;