https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=298762
Bug ID: 298762
Summary: vt(4): data races on vw_flags/vd_flags and the mouse
cursor position (found by KCSAN)
Product: Base System
Version: 16.0-CURRENT
Hardware: Any
OS: Any
Status: New
Keywords: vt
Severity: Affects Only Me
Priority: ---
Component: kern
Assignee: [email protected]
Reporter: [email protected]
CC: [email protected], [email protected]
Attachment #275010 text/plain
mime type:
Created attachment 275010
--> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=275010&action=edit
Stressor
Since I found we had KCSAN while discussing work on vt(4), see
https://reviews.freebsd.org/D59814, I used it and found a couple of races.
Reproduction:
- Build a GENERIC kernel with "options KCSAN" (amd64).
- Run the attached vwkcsan.c: three threads on one /dev/ttyvN issuing KDSETMODE
KD_GRAPHICS/KD_TEXT, VT_LOCKSWITCH lock/unlock, and CONS_MOUSECTL
MOUSE_HIDE/SHOW.
- dmesg shows "CSan: Racy Access" reports on the vt_window flag word, the
vt_device flag word, and the mouse cursor position.
KCSAN result:
--- vw_flags races (VWF_MOUSE_HIDE vs VWF_GRAPHICS/VWF_VTYLOCK on one window)
---
CSan: Racy Access [Cpu0 Write Addr=0xfffff800014bcca8 Size=4 PC=vt_mouse_state]
[Cpu1 Write Addr=0xfffff800014bcca8 Size=4 PC=vtterm_ioctl]
CSan: Racy Access [Cpu0 Write Addr=0xfffff800014bcca8 Size=4 PC=vt_mouse_state]
[Cpu3 Write Addr=0xfffff800014bcca8 Size=4 PC=vtterm_ioctl]
CSan: Racy Access [Cpu0 Write Addr=0xfffff800014bcca8 Size=4 PC=vtterm_ioctl]
[Cpu1 Write Addr=0xfffff800014bcca8 Size=4 PC=vt_mouse_state]
CSan: Racy Access [Cpu2 Write Addr=0xfffff800014bcca8 Size=4 PC=vt_mouse_state]
[Cpu1 Write Addr=0xfffff800014bcca8 Size=4 PC=vtterm_ioctl]
CSan: Racy Access [Cpu3 Write Addr=0xfffff800014bcca8 Size=4 PC=vt_mouse_state]
[Cpu1 Write Addr=0xfffff800014bcca8 Size=4 PC=vtterm_ioctl]
--- vd_flags races (VDF_MOUSECURSOR write in CONS_MOUSECTL vs vtterm_done read)
---
CSan: Racy Access [Cpu0 Read Addr=0xffffffff822a800c Size=4 PC=vtterm_done]
[Cpu2 Write Addr=0xffffffff822a800c Size=4 PC=vtterm_ioctl]
CSan: Racy Access [Cpu0 Read Addr=0xffffffff822a800c Size=4 PC=vtterm_done]
[Cpu3 Write Addr=0xffffffff822a800c Size=4 PC=vtterm_ioctl]
CSan: Racy Access [Cpu1 Read Addr=0xffffffff822a800c Size=4 PC=vtterm_done]
[Cpu0 Write Addr=0xffffffff822a800c Size=4 PC=vtterm_ioctl]
CSan: Racy Access [Cpu1 Read Addr=0xffffffff822a800c Size=4 PC=vtterm_done]
[Cpu2 Write Addr=0xffffffff822a800c Size=4 PC=vtterm_ioctl]
--- mouse cursor position races (after fixing the flags) ---
CSan: Racy Access [Cpu3 Read Addr=0xffffffff822a7f78 Size=4
PC=vt_mark_mouse_position_as_dirty] [Cpu0 Write Addr=0xffffffff822a7f78 Size=4
PC=vt_flush]
CSan: Racy Access [Cpu0 Read Addr=0xffffffff822a7f80 Size=2 PC=vt_flush] [Cpu2
Write Addr=0xffffffff822a7f80 Size=2 PC=vtterm_ioctl]
This most likely never or almost never happens in regular production, and the
resulting bugs are mostly transient, if noticeable, but I will propose some
patches for correctness.
--
You are receiving this mail because:
You are the assignee for the bug.