kernel-locking-concurrency
gvago/unofficial-qodo-review-skills/skills/kernel-locking-concurrency/SKILL.md
Use when a Linux kernel PR diff touches locks, atomics, RCU, IRQs, or deferred work, concurrency audit (Sashiko stage 5): races, deadlocks, lock-context violations, missing barriers, RCU misuse. Every finding must name the two racing contexts. Part of the linux-kernel-review suite.
Skill2 starsChanged 9 days ago
What's in it
- kernel-locking-concurrency
- How to apply
- Rule index
- Mapping a finding to the contract
- What NOT to flag
- References (load only when needed)
- Sourcing
--- name: kernel-locking-concurrency description: "Use when a Linux kernel PR diff touches locks, atomics, RCU, IRQs, or deferred work, concurrency audit (Sashiko stage 5): races, deadlocks, lock-context violations, missing barriers, RCU misuse. Every finding must name the two racing contexts. Part of the linux-kernel-review suite." license: Apache-2.0 metadata: author: Sashiko contributors / Chris Mason adapted_by: gvago source: https://github.com/sashiko-dev/sashiko (Apache-2.0), references from masoncl/review-prompts (MIT) variant: review version: 1.0.0 --- # kernel-locking-concurrency Lens for locking and synchronization audit (Sashiko stage 5). World-class concurrency review of the diff. This is the noisiest domain in kernel review, every finding must name the two racing contexts. ## How to apply - Identify every lock, RCU section, and lockless access the diff touches. - For each concern, name context A, context B, and the interleaving that breaks. If you cannot construct the interleaving, route the concern to kernel-review-discipline as speculative. - Load references/locking.md for the full invariant catalog before deep analysis; references/rcu.md whenever call_rcu/synchronize_rcu/kfree_rcu or RCU list ops appear. ## Rule index - C1. Sleeping in atomic context: mutex_lock, GFP_KERNEL allocation, msleep, cond_resched, flush_workqueue, synchronize_rcu, cancel_work_sync under a spinlock, rwlock, or rcu_read_lock. - C2. Lock ordering and deadlock: AB-BA orders, acquiring a lock already held by a higher layer (e.g. ethtool), missing _irqsave when the lock is taken in hardirq context. - C3. Races and lockless access: shared state touched without the owning lock, missing smp_mb/smp_wmb/smp_rmb where lockless access is intended, TOCTOU where state is checked outside the lock and relied on inside. - C4. Locking freed memory: unlock on freed objects; works/timers destroyed after the subsystem that can still schedule them is gone; "initialized" flags set before private data is ready. - C5. RCU rules: non-RCU-safe ops (list_splice_init) on RCU-protected lists; list_for_each_rcu without rcu_read_lock; removal-vs-call_rcu ordering (see references/rcu.md). - C6. Unprotected state modification: state checked before lock acquisition, hardware state/flags/stats updated without protection. - C7. Sequence counters: double counting inside u64_stats_fetch_retry loops; interrupt reading a seqcount its own interrupted context writes. - C8. Lock lifecycle: re-initializing a live lock; destroying a lock on a failure path other paths still use. - C9. Missing locking on publication: a port/file exposed to userspace before linking completes; a worker racing cleanup. ## Mapping a finding to the contract - action_level: action_required for a constructed deadlock, sleep-in-atomic, or race with memory corruption; remediation_recommended for inefficient but correct locking. - category: Correctness (Security if the race is user-triggerable). - evidence: both contexts, the shared object, the interleaving, lines. ## What NOT to flag - READ_ONCE absence when the data is protected by a lock currently held. - Races that existing memory barriers or lock coverage already close , read references/locking.md before asserting a barrier is missing. - Theoretical races with no constructible interleaving. ## References (load only when needed) - references/locking.md, full locking invariant catalog (512 lines). - references/rcu.md, RCU lifecycle and list rules. ## Sourcing Stage text adapted from Sashiko (Apache-2.0). References reproduced from masoncl/review-prompts (MIT).
More agent context in gvago/unofficial-qodo-review-skills
18 other files this repository gives its agents.
Skill
- accessibility-reviewskills/accessibility-review/SKILL.md
- apex-reviewskills/apex-review/SKILL.md
- appsec-compliance-reviewskills/appsec-compliance-review/SKILL.md
- clang-formatskills/clang-format/SKILL.md
- commit-message-reviewskills/commit-message-review/SKILL.md
- design-doc-conformanceskills/design-doc-conformance/SKILL.md
- guideline-distillerskills/guideline-distiller/SKILL.md
- kernel-change-intentskills/kernel-change-intent/SKILL.md
- kernel-driver-hardwareskills/kernel-driver-hardware/SKILL.md
- kernel-execution-flowskills/kernel-execution-flow/SKILL.md
- kernel-resource-lifecycleskills/kernel-resource-lifecycle/SKILL.md
- kernel-review-disciplineskills/kernel-review-discipline/SKILL.md
- kernel-security-auditskills/kernel-security-audit/SKILL.md
- kernel-subsystem-guidesskills/kernel-subsystem-guides/SKILL.md
- linux-kernel-reviewskills/linux-kernel-review/SKILL.md
- qodo-calibrate-rulesskills/qodo-calibrate-rules/SKILL.md
- terraform-reviewskills/terraform-review/SKILL.md
- toml-portal-migration-auditskills/toml-portal-migration-audit/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
Reports can't be read right now.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

