)]}'
{
  "commit": "fcbe4307bda074abc8132bfe746eeb0e502d74ab",
  "tree": "70db06f415c33f68049a1f91c613180a0039216f",
  "parents": [
    "72d3fcf802c45d00b300f25b848a93c3a2bd7c7e"
  ],
  "author": {
    "name": "Jann Horn",
    "email": "jannh@google.com",
    "time": "Tue Sep 29 18:31:32 2026 +0200"
  },
  "committer": {
    "name": "Peter Zijlstra",
    "email": "peterz@infradead.org",
    "time": "Thu Oct 01 14:00:38 2026 +0200"
  },
  "message": "futex: Fix mm reuse handling for FUT_OFF_MMSHARED\n\nA FUT_OFF_MMSHARED futex is a shared futex that refers to an MM.\nIt is possible for a process to wait on a shared futex with a different MM\nbecause a FUT_OFF_INODE waiter can be requeued onto a FUT_OFF_MMSHARED\nfutex by another process.\nThis can cause FUT_OFF_MMSHARED waiters on a freed MM to consume\nwakeups intended for a newly allocated MM at the same address.\n\nFix it by keying FUT_OFF_MMSHARED using a unique 64-bit per-MM ID.\nLeave private futexes as before to avoid influencing the performance of the\nhotpath.\n\n(Multi-threaded processes typically implicitly use FUT_OFF_MMSHARED by\nsetting clear_child_tid such that it points into anonymous memory, which\ncauses mm_release() in a multi-threaded mm to perform FUTEX_WAKE.)\n\nFixes: 222993395ed3 (\"futex: Remove pointless mmgrap() + mmdrop()\")\nCloses: https://lore.kernel.org/r/CAG48ez0dLBpc3QtbAhMMVNHwHL94iHh2G+h-\u003dBVFR4dDuzZr1g@mail.gmail.com/\nSigned-off-by: Jann Horn \u003cjannh@google.com\u003e\nSigned-off-by: Peter Zijlstra (Intel) \u003cpeterz@infradead.org\u003e\nCc: stable@vger.kernel.org\nLink: https://patch.msgid.link/20260929-futex-mmshared-fix-v1-1-262b1ffeb3d0@google.com\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "18ed18d5cbc1d90a5fa5de4b02e73f5536f82e08",
      "old_mode": 33188,
      "old_path": "include/linux/futex.h",
      "new_id": "7eb645e49dd4ae0e3e06f5bcac2b648a42650252",
      "new_mode": 33188,
      "new_path": "include/linux/futex.h"
    },
    {
      "type": "modify",
      "old_id": "d320c0571f0c8c9740cf6f9972a984393097f421",
      "old_mode": 33188,
      "old_path": "include/linux/futex_types.h",
      "new_id": "34b16f2828e7065ef1a12617b7e6efbfad19bd3c",
      "new_mode": 33188,
      "new_path": "include/linux/futex_types.h"
    },
    {
      "type": "modify",
      "old_id": "a061f54b606dd0ea27b533bb688189c8f21dd4fb",
      "old_mode": 33188,
      "old_path": "kernel/futex/core.c",
      "new_id": "3593d8a328e9444d2f77add99854b40d1f72ea1d",
      "new_mode": 33188,
      "new_path": "kernel/futex/core.c"
    }
  ]
}
