{"id":2227437,"url":"http://patchwork.ozlabs.org/api/patches/2227437/?format=json","web_url":"http://patchwork.ozlabs.org/project/linux-ext4/patch/20260423173700.GA2187084@chcpu16/","project":{"id":8,"url":"http://patchwork.ozlabs.org/api/projects/8/?format=json","name":"Linux ext4 filesystem development","link_name":"linux-ext4","list_id":"linux-ext4.vger.kernel.org","list_email":"linux-ext4@vger.kernel.org","web_url":null,"scm_url":null,"webscm_url":null,"list_archive_url":"","list_archive_url_format":"","commit_url_format":""},"msgid":"<20260423173700.GA2187084@chcpu16>","list_archive_url":null,"date":"2026-04-23T17:37:16","name":"[BUG] ext4: KCSAN: lockless i_es_all_nr reads in es_shrinker_info","commit_ref":null,"pull_url":null,"state":"new","archived":false,"hash":"36f03a33f6c68130a49b37bfbb3789c1b16af3c5","submitter":{"id":91564,"url":"http://patchwork.ozlabs.org/api/people/91564/?format=json","name":"Shuhao Fu","email":"sfual@cse.ust.hk"},"delegate":null,"mbox":"http://patchwork.ozlabs.org/project/linux-ext4/patch/20260423173700.GA2187084@chcpu16/mbox/","series":[{"id":501229,"url":"http://patchwork.ozlabs.org/api/series/501229/?format=json","web_url":"http://patchwork.ozlabs.org/project/linux-ext4/list/?series=501229","date":"2026-04-23T17:37:16","name":"[BUG] ext4: KCSAN: lockless i_es_all_nr reads in es_shrinker_info","version":1,"mbox":"http://patchwork.ozlabs.org/series/501229/mbox/"}],"comments":"http://patchwork.ozlabs.org/api/patches/2227437/comments/","check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/2227437/checks/","tags":{},"related":[],"headers":{"Return-Path":"\n <SRS0=D6qC=CW=vger.kernel.org=linux-ext4+bounces-16069-patchwork-incoming=ozlabs.org@ozlabs.org>","X-Original-To":["incoming@patchwork.ozlabs.org","linux-ext4@vger.kernel.org"],"Delivered-To":["patchwork-incoming@legolas.ozlabs.org","patchwork-incoming@ozlabs.org"],"Authentication-Results":["legolas.ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n unprotected) header.d=cse.ust.hk header.i=@cse.ust.hk header.a=rsa-sha256\n header.s=cseusthk header.b=lePdqm4q;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org\n (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org;\n envelope-from=srs0=d6qc=cw=vger.kernel.org=linux-ext4+bounces-16069-patchwork-incoming=ozlabs.org@ozlabs.org;\n receiver=patchwork.ozlabs.org)","gandalf.ozlabs.org;\n arc=fail smtp.remote-ip=\"2600:3c0a:e001:db::12fc:5321\"","gandalf.ozlabs.org;\n dmarc=fail (p=none dis=none) header.from=cse.ust.hk","gandalf.ozlabs.org;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key;\n unprotected) header.d=cse.ust.hk header.i=@cse.ust.hk header.a=rsa-sha256\n header.s=cseusthk header.b=lePdqm4q;\n\tdkim-atps=neutral","gandalf.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org\n (client-ip=2600:3c0a:e001:db::12fc:5321; helo=sea.lore.kernel.org;\n envelope-from=linux-ext4+bounces-16069-patchwork-incoming=ozlabs.org@vger.kernel.org;\n receiver=ozlabs.org)","smtp.subspace.kernel.org;\n\tdkim=fail reason=\"signature verification failed\" (1024-bit key)\n header.d=cse.ust.hk header.i=@cse.ust.hk header.b=\"lePdqm4q\"","smtp.subspace.kernel.org;\n arc=fail smtp.client-ip=143.89.41.157","smtp.subspace.kernel.org;\n dmarc=pass (p=none dis=none) header.from=cse.ust.hk","smtp.subspace.kernel.org;\n spf=pass smtp.mailfrom=cse.ust.hk"],"Received":["from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4g1jwt27kqz1y2d\n\tfor <incoming@patchwork.ozlabs.org>; Fri, 24 Apr 2026 03:38:06 +1000 (AEST)","from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3])\n\tby gandalf.ozlabs.org (Postfix) with ESMTP id 4g1jwt1gg7z4w1d\n\tfor <incoming@patchwork.ozlabs.org>; Fri, 24 Apr 2026 03:38:06 +1000 (AEST)","by gandalf.ozlabs.org (Postfix)\n\tid 4g1jwt1b03z4wKC; Fri, 24 Apr 2026 03:38:06 +1000 (AEST)","from sea.lore.kernel.org (sea.lore.kernel.org\n [IPv6:2600:3c0a:e001:db::12fc:5321])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519)\n\t(No client certificate requested)\n\tby gandalf.ozlabs.org (Postfix) with ESMTPS id 4g1jwl3G5Qz4w1d\n\tfor <patchwork-incoming@ozlabs.org>; Fri, 24 Apr 2026 03:37:59 +1000 (AEST)","from smtp.subspace.kernel.org (conduit.subspace.kernel.org\n [100.90.174.1])\n\tby sea.lore.kernel.org (Postfix) with ESMTP id 700CD300B63E\n\tfor <patchwork-incoming@ozlabs.org>; Thu, 23 Apr 2026 17:37:42 +0000 (UTC)","from localhost.localdomain (localhost.localdomain [127.0.0.1])\n\tby smtp.subspace.kernel.org (Postfix) with ESMTP id 705A23A7F45;\n\tThu, 23 Apr 2026 17:37:41 +0000 (UTC)","from cse.ust.hk (cssvr7.cse.ust.hk [143.89.41.157])\n\t(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))\n\t(No client certificate requested)\n\tby smtp.subspace.kernel.org (Postfix) with ESMTPS id BEF2C2D97B7;\n\tThu, 23 Apr 2026 17:37:36 +0000 (UTC)","from chcpu16 (191host045.mobilenet.cse.ust.hk [143.89.191.45])\n\t(authenticated bits=0)\n\tby cse.ust.hk (8.18.1/8.12.5) with ESMTPSA id 63NHbL7v1768571\n\t(version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT);\n\tFri, 24 Apr 2026 01:37:28 +0800"],"ARC-Seal":["i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116;\n\tt=1776965861; cv=fail;\n b=S22OQnjHtzOtTkkyJZuQFASYXbzoU/J9vqd1zbeXgfrMqoduJ1cZFuWGCy16oG17477om6Xw79htifW92C1tuPFg3Ynw/hUW6imipmM2uviksPh3ZkqidM5NyDqq/wI5EwLu3JpCdhPwxuy9HmZtBJjZ6Ge4HZ1T+RBaXZ9h7CI=","i=1; d=cse.ust.hk; s=arccse; a=rsa-sha256; cv=none; t=1776965848;\n\tb=AjAF/AUxsrDhjwvI6hRS7wW0fNQGqfwdHdlGfnbSWlODoNBFi7eCunougQj7njU9Srmh\n\t Aph11WHgAkMeJjCxSfm07htXs+OyYtX+EtUsqrT8l49NiRV03b/HBR11417ucfa+2u8Zj\n\t CSrkCILafu0ooYCTC/h4K/Uc3vIgpPsN7k="],"ARC-Message-Signature":["i=2; a=rsa-sha256; d=subspace.kernel.org;\n\ts=arc-20240116; t=1776965861; c=relaxed/simple;\n\tbh=0x/auHbOhhE+j/6Df10ZM/NGURUzqWqfjC2ekyvD5HY=;\n\th=Date:From:To:Cc:Subject:Message-ID:MIME-Version:Content-Type:\n\t Content-Disposition;\n b=C9ZPayjCCx3sscT/SlfUy+DNs4fBQjHm+y6J+z5LMu/OGn1BghGwWUrMZoD4Jnx8STQD42zNVU6Yd8WDY2mC7rOiWki7VCufz8QDo+PKi5QZgrjc7hkrKmWuSENToNjMYu2ASiMMPgoNqoCrds3e3btxt8aeqbGs/pUiYPSJcDY=","i=1; d=cse.ust.hk; s=arccse; a=rsa-sha256;\n\tc=relaxed/relaxed; t=1776965848;\n\th=DKIM-Signature:Date:From:To:Subject:Message-ID:MIME-Version;\n\tbh=ooBVeHO5BNHGyWf9t7ZufVl29d6IT3b4Z7fohAbfVwc=;\n\tb=ZbWEHSL0T/fII8NM4r/zhxiWvhf6D2UYNsBUabgJfepQpQpZPtEJ4B/egsb8mOX9xnFn\n\t 028uS9esS5+iz+9lcXNauKtpde6grj8I9F3VItQpF0gNTgQOFkPOvvWPPRViaQ0zGERPh\n\t eUKbexZBOi+vPQt890sADqcc4J4pE1Y5l8="],"ARC-Authentication-Results":["i=2; smtp.subspace.kernel.org;\n dmarc=pass (p=none dis=none) header.from=cse.ust.hk;\n spf=pass smtp.mailfrom=cse.ust.hk;\n dkim=fail (1024-bit key) header.d=cse.ust.hk header.i=@cse.ust.hk\n header.b=lePdqm4q reason=\"signature verification failed\";\n arc=fail smtp.client-ip=143.89.41.157","i=1; cse.ust.hk;\n arc=none smtp.remote-ip=143.89.191.45"],"DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed; d=cse.ust.hk;\n\ts=cseusthk; t=1776965848;\n\tbh=ooBVeHO5BNHGyWf9t7ZufVl29d6IT3b4Z7fohAbfVwc=;\n\th=Date:From:To:Cc:Subject:From;\n\tb=lePdqm4qB7eWJYQqIPHt9brQXb3SuRd91nj6sGelvFEovd3IICbaMLCqYMUwOfDnd\n\t DZh1/AOXe3Uek/B2JI3o56S9yIaY7VcaoTDxinZi8E/Ite3YXlkps61XDv1OkefZtM\n\t p+QyBDqYU0kvXG5tO2FM/0pfJ8wHv8ZzV9mZ3XLk=","Date":"Fri, 24 Apr 2026 01:37:16 +0800","From":"Shuhao Fu <sfual@cse.ust.hk>","To":"\"Theodore Ts'o\" <tytso@mit.edu>, linux-ext4@vger.kernel.org","Cc":"linux-kernel@vger.kernel.org","Subject":"[BUG] ext4: KCSAN: lockless i_es_all_nr reads in es_shrinker_info","Message-ID":"<20260423173700.GA2187084@chcpu16>","Precedence":"bulk","X-Mailing-List":"linux-ext4@vger.kernel.org","List-Id":"<linux-ext4.vger.kernel.org>","List-Subscribe":"<mailto:linux-ext4+subscribe@vger.kernel.org>","List-Unsubscribe":"<mailto:linux-ext4+unsubscribe@vger.kernel.org>","MIME-Version":"1.0","Content-Type":"text/plain; charset=us-ascii","Content-Disposition":"inline","X-Env-From":"sfual","X-Spam-Status":"No, score=0.0 required=5.0 tests=ARC_SIGNED,ARC_VALID,\n\tDKIM_INVALID,DKIM_SIGNED,DMARC_NONE,HEADER_FROM_DIFFERENT_DOMAINS,\n\tMAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS autolearn=disabled\n\tversion=4.0.1","X-Spam-Checker-Version":"SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org"},"content":"Hi,\n\nReading /proc/fs/ext4/<sb>/es_shrinker_info can overlap with extent-status\nupdates and trigger KCSAN reports on the per-inode ES counters (I saw this on\ni_es_all_nr; i_es_shk_nr is read the same way in this proc path). From what I\ncan see, the user-visible impact appears limited to stale/inconsistent procfs\nstats output (I do not have evidence of corruption or crash from this path).\n\nI reproduced this on a local KCSAN-instrumented tree based on linux commit\nd8a9a4b11a13, using an x86_64 QEMU workload with userspace reader/writer loops.\nTo increase the race window, I added small debug-only hooks in my local tree:\nafter the writer updates the counter, it briefly delays and records which inode\nit just touched; the proc reader then samples that inode's counters during the\ns_es_list walk. I also wrapped the i_es_all_nr load in a local helper\next4_es_shrinker_read_all_nr() so the read-side stack has a stable symbol;\nupstream reads happen directly in ext4_seq_es_shrinker_info_show().\n\nWith that setup, KCSAN prints the following summary line (naming the two\nracing functions):\n\n  BUG: KCSAN: data-race in ext4_es_init_extent / ext4_es_shrinker_read_all_nr\n\nThe first clean hit in my local log was:\n\n  read to 0xffff917cc15222c8 of 4 bytes by task 107 on cpu 0:\n   ext4_es_shrinker_read_all_nr+0x26/0x50\n   ext4_es_kcsan_probe_hot_inode+0x2b9/0x400\n   ext4_seq_es_shrinker_info_show+0x9b/0xd40\n   ...\n   __x64_sys_sendfile64+0xc2/0x100\n   do_syscall_64+0x13f/0x3c0\n\n  write (reordered) to 0xffff917cc15222c8 of 4 bytes by task 108 on cpu 2:\n   ext4_es_init_extent+0x6aa/0xa00\n   __es_insert_extent+0x477/0xaa0\n   ...\n   ext4_do_fallocate+0x127/0x310\n   __x64_sys_fallocate+0x75/0xb0\n\nI then saw the same pair again later in the same run (for example around\n129.529391 and 129.579938), still on the same 4-byte address.\n\nIt looks like i_es_all_nr and i_es_shk_nr are documented as protected by\ni_es_lock, and writers update them under i_es_lock, but\next4_seq_es_shrinker_info_show() reads them while walking the list under\ns_es_lock (the list lock), not i_es_lock.\n\nThe reproducer shape from normal userspace APIs is one reader loop running\ncat /proc/fs/ext4/<sb>/es_shrinker_info while a writer loop runs fallocate,\nbuffered writes, punch-hole, and truncate on the same filesystem.\n\nSince this appears to be an observational procfs stats path, would you prefer\nmarking these loads with data_race(...) so the intentionally approximate reads\nare explicit and this path stops generating repeated KCSAN warnings?\n\nThe rough change I had in mind is:\n\n+++ b/fs/ext4/extents_status.c\n@@\n int ext4_seq_es_shrinker_info_show(struct seq_file *seq, void *v)\n {\n \t...\n \tlist_for_each_entry(ei, &sbi->s_es_list, i_es_list) {\n \t\tinode_cnt++;\n \t\tei_all_nr = data_race(ei->i_es_all_nr);\n \t\tei_shk_nr = data_race(ei->i_es_shk_nr);\n \t\t...\n  }\n\nIf this direction is preferred, I can send a formal patch.\n\nThanks,\nShuhao","diff":"diff --git a/fs/ext4/extents_status.c b/fs/ext4/extents_status.c\nindex ... .. ...\n--- a/fs/ext4/extents_status.c\n","prefixes":["BUG"]}