CARDSHARK: Understanding and Stablizing Linux Kernel Concurrency Bugs Against the Odds
Tianshuo Han, Xiaorui Gong, Jian Liu
摘要
Concurrency bugs in the Linux kernel are notoriously difficult to reproduce and debug due to their non-deterministic nature. While they bring constant headaches to Linux kernel developers, the reasons behind the non-determinism and how to improve the efficiency in triggering concurrency bugs to ease the debugging process still need to be studied. This work aims to fill the gap. We comprehensively study the concurrency bug stability problem in the Linux kernel, dissect the factors behind the non-determinism, and systematize the insights into a model to explain the non-deterministic nature of concurrency bugs. Based on insights derived from the model, we identify an under-studied factor, named misalignment, which plays a vital role in triggering concurrency bugs. By controlling this factor, we significantly reduce the randomness in the concurrency bug-triggering process. Inspired by this insight, we design a novel technique, named CARDSHARK, that can significantly improve the efficiency in triggering concurrency bugs when kernel instrumentation is possible. A variant of CARDSHARK, named BLIND-SHARK, enables developers to improve efficiency in triggering concurrency bugs without knowing their root causes, making the use of CARDSHARK practical. In our evaluation of 12 real-world concurrency bugs, CARDSHARK and BLINDSHARK significantly reduce the needed time and the number of attempts to trigger concurrency bugs in the Linux kernel. Notably, CARDSHARK can deterministically trigger 10 out of the 12 concurrency bugs with a single attempt. Our evaluation shows that CARDSHARK significantly outperforms existing works in stabilizing concurrency bugs, making it a potential great help to developers in analyzing and fixing concurrency bugs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Reviving Discarded Vulnerabilities: Exploiting Previously Unexploitable Linux Kernel Bugs Through Control Metadata FieldsHao Zhang, Jian Liu, Jie Lu, Shaomin Chen 等CCS 2025
- Concurrency Fuzzing of the Linux Kernel with eBPFJiacheng Xu, Dylan Wolff, Xing Yi Han, Jialin Li 等USENIX Security 2026
它引用的顶会 Paper8
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee 等S&P 2019 · 被引用 202 次
- Precise and Scalable Detection of Double-Fetch Bugs in OS KernelsMeng Xu, Chenxiong Qian, Kangjie Lu, Michael Backes 等S&P 2018 · 被引用 95 次
- RAProducer: efficiently diagnose and reproduce data race bugs for binaries via trace analysisMing Yuan, Yeseop Lee, Chao Zhang, Yun Li 等ISSTA 2021 · 被引用 7 次
- Diagnosing Kernel Concurrency Failures with AITIADae R. Jeong, Minkyu Jung, Yoochan Lee, Byoungyoung Lee 等EuroSys 2023 · 被引用 3 次
- Precise Detection of Kernel Data Races with Probabilistic Lockset AnalysisGabriel Ryan, Abhishek Shah, Dongdong She, Suman JanaS&P 2023
相关 Paper
- A Comprehensive Study of Concurrency Bugs in the Linux KernelSishuai Gong, Chih-En Lin, Kevin Wu, Edwin Lu 等ICSE 2026 · 被引用 1 次
- OZZ: Identifying Kernel Out-of-Order Concurrency Bugs with In-Vivo Memory Access ReorderingDae R. Jeong, Yewon Choi, Byoungyoung Lee, Insik Shin 等SOSP 2024 · 被引用 4 次
- SegFuzz: Segmentizing Thread Interleaving to Discover Kernel Concurrency Bugs through FuzzingDae R. Jeong, Byoungyoung Lee, Insik Shin, Youngjin KwonS&P 2023
- DDRace: Finding Concurrency UAF Vulnerabilities in Linux Drivers with Directed FuzzingMing Yuan, Bodong Zhao, Penghui Li, Jiashuo Liang 等USENIX Security 2023
- OFence: Pairing Barriers to Find Concurrency Bugs in the Linux KernelBaptiste Lepers, Josselin Giet, Willy Zwaenepoel, Julia LawallEuroSys 2023 · 被引用 1 次
