On Thu, Oct 1, 2026 at 9:17 PM Babanpreet Singh <[email protected]> wrote:
>
> audit_ctl_owner_current() reads the lock owner without taking the lock
> and KCSAN complains about it. Only the current task can store itself as
> owner, so the check can't give a wrong answer. Mark the accesses with
> READ_ONCE() and WRITE_ONCE().
>
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=39b8fea0641107a1ccee
> Assisted-by: Claude:claude-opus-5-5
> Signed-off-by: Babanpreet Singh <[email protected]>
> ---
> Paul, you looked at this race in 2022 and asked whether READ_ONCE()
> was worth it and what it would cost:
> https://lore.kernel.org/all/CAHC9VhTXNPWBDRoPcz-Jw=f+nnaehxbh-ysc56cud-zbubo...@mail.gmail.com/
> Compile tested only (gcc and the KCSAN instrumentation diff); I could
> not reproduce the race in QEMU.
>
> kernel/audit.c | 11 ++++++++---
> 1 file changed, 8 insertions(+), 3 deletions(-)
Thanks for the patch.
I stand by my previous comments, but given the current state of LLM
assisted reporting and submissions it's probably worth making the
change. I would like to see one small change, see below ...
> diff --git a/kernel/audit.c b/kernel/audit.c
> index 631d6d4a23cfd..f8c43ac6d5b82 100644
> --- a/kernel/audit.c
> +++ b/kernel/audit.c
> @@ -268,7 +268,12 @@ void audit_ctl_unlock(void)
> */
> static bool audit_ctl_owner_current(void)
> {
> - return (current == audit_cmd_mutex.owner);
> + /*
> + * Lockless read: the owner can only equal current if current set
> + * it, so another task changing the owner concurrently can never
> + * make this return the wrong answer.
> + */
This code is fairly easy to understand so I don't believe this comment
is necessary or adds any value, please drop this commment and
resubmit.
> + return (current == READ_ONCE(audit_cmd_mutex.owner));
> }
--
paul-moore.com