https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=298762

            Bug ID: 298762
           Summary: vt(4): data races on vw_flags/vd_flags and the mouse
                    cursor position (found by KCSAN)
           Product: Base System
           Version: 16.0-CURRENT
          Hardware: Any
                OS: Any
            Status: New
          Keywords: vt
          Severity: Affects Only Me
          Priority: ---
         Component: kern
          Assignee: [email protected]
          Reporter: [email protected]
                CC: [email protected], [email protected]
 Attachment #275010 text/plain
         mime type:

Created attachment 275010
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=275010&action=edit
Stressor

Since I found we had KCSAN while discussing work on vt(4), see
https://reviews.freebsd.org/D59814, I used it and found a couple of races.

Reproduction:
- Build a GENERIC kernel with "options KCSAN" (amd64).
- Run the attached vwkcsan.c: three threads on one /dev/ttyvN issuing KDSETMODE
KD_GRAPHICS/KD_TEXT, VT_LOCKSWITCH lock/unlock, and CONS_MOUSECTL
MOUSE_HIDE/SHOW.
- dmesg shows "CSan: Racy Access" reports on the vt_window flag word, the
vt_device flag word, and the mouse cursor position.

KCSAN result:
--- vw_flags races (VWF_MOUSE_HIDE vs VWF_GRAPHICS/VWF_VTYLOCK on one window)
---
CSan: Racy Access [Cpu0 Write Addr=0xfffff800014bcca8 Size=4 PC=vt_mouse_state]
[Cpu1 Write Addr=0xfffff800014bcca8 Size=4 PC=vtterm_ioctl]
CSan: Racy Access [Cpu0 Write Addr=0xfffff800014bcca8 Size=4 PC=vt_mouse_state]
[Cpu3 Write Addr=0xfffff800014bcca8 Size=4 PC=vtterm_ioctl]
CSan: Racy Access [Cpu0 Write Addr=0xfffff800014bcca8 Size=4 PC=vtterm_ioctl] 
[Cpu1 Write Addr=0xfffff800014bcca8 Size=4 PC=vt_mouse_state]
CSan: Racy Access [Cpu2 Write Addr=0xfffff800014bcca8 Size=4 PC=vt_mouse_state]
[Cpu1 Write Addr=0xfffff800014bcca8 Size=4 PC=vtterm_ioctl]
CSan: Racy Access [Cpu3 Write Addr=0xfffff800014bcca8 Size=4 PC=vt_mouse_state]
[Cpu1 Write Addr=0xfffff800014bcca8 Size=4 PC=vtterm_ioctl]

--- vd_flags races (VDF_MOUSECURSOR write in CONS_MOUSECTL vs vtterm_done read)
---
CSan: Racy Access [Cpu0 Read Addr=0xffffffff822a800c Size=4 PC=vtterm_done]
[Cpu2 Write Addr=0xffffffff822a800c Size=4 PC=vtterm_ioctl]
CSan: Racy Access [Cpu0 Read Addr=0xffffffff822a800c Size=4 PC=vtterm_done]
[Cpu3 Write Addr=0xffffffff822a800c Size=4 PC=vtterm_ioctl]
CSan: Racy Access [Cpu1 Read Addr=0xffffffff822a800c Size=4 PC=vtterm_done]
[Cpu0 Write Addr=0xffffffff822a800c Size=4 PC=vtterm_ioctl]
CSan: Racy Access [Cpu1 Read Addr=0xffffffff822a800c Size=4 PC=vtterm_done]
[Cpu2 Write Addr=0xffffffff822a800c Size=4 PC=vtterm_ioctl]

--- mouse cursor position races (after fixing the flags) ---
CSan: Racy Access [Cpu3 Read  Addr=0xffffffff822a7f78 Size=4
PC=vt_mark_mouse_position_as_dirty] [Cpu0 Write Addr=0xffffffff822a7f78 Size=4
PC=vt_flush]
CSan: Racy Access [Cpu0 Read  Addr=0xffffffff822a7f80 Size=2 PC=vt_flush] [Cpu2
Write Addr=0xffffffff822a7f80 Size=2 PC=vtterm_ioctl]

This most likely never or almost never happens in regular production, and the
resulting bugs are mostly transient, if noticeable, but I will propose some
patches for correctness.

-- 
You are receiving this mail because:
You are the assignee for the bug.

Reply via email to