From 7aef540078adc7cdfa5ee2c9784269b49f51b539 Mon Sep 17 00:00:00 2001 From: Breno Leitao Date: Wed, 12 Aug 2026 09:03:18 -0700 Subject: [PATCH] workqueue: use rcu_dereference_sched() in workqueue_congested() workqueue_congested() fetches the pwq out of wq->cpu_pwq with a plain load, so sparse complains about the dropped __rcu: kernel/workqueue.c:6304:13: sparse: incorrect type in assignment (different address spaces) @@ expected struct pool_workqueue *pwq @@ got struct pool_workqueue [noderef] __rcu * @@ A pwq is released with kfree_rcu() and the read is protected by the surrounding preempt_disable(), which is what commit fd5081f4ef33 ("workqueue: Remove redundant rcu_read_lock/unlock() in workqueue_congested()") relied on when it dropped the rcu_read_lock() here. Use the rcu_dereference_sched() helper to make that explicit. Reported-by: kernel test robot Closes: https://lore.kernel.org/oe-kbuild-all/202608120931.tvTzq1gD-lkp@intel.com/ Signed-off-by: Breno Leitao Signed-off-by: Tejun Heo --- kernel/workqueue.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kernel/workqueue.c b/kernel/workqueue.c index 8fd6af72ffd8..e66ee1016568 100644 --- a/kernel/workqueue.c +++ b/kernel/workqueue.c @@ -6317,7 +6317,7 @@ bool workqueue_congested(int cpu, struct workqueue_struct *wq) if (cpu == WORK_CPU_UNBOUND) cpu = smp_processor_id(); - pwq = *per_cpu_ptr(wq->cpu_pwq, cpu); + pwq = rcu_dereference_sched(*per_cpu_ptr(wq->cpu_pwq, cpu)); ret = !list_empty(&pwq->inactive_works); preempt_enable();