Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1579533

[tip:timers/urgent] tick/broadcast: Prevent deadlock on tick_broadcast_lock

From tip-bot for Mike Galbraith <tipbot@zytor.com>
Newsgroups linux.kernel
Subject [tip:timers/urgent] tick/broadcast: Prevent deadlock on tick_broadcast_lock
Date 2017-02-13 10:00 +0100
Message-ID <takEi-1mF-9@gated-at.bofh.it> (permalink)
References <taeIx-5Qx-9@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Commit-ID:  202461e2f3c15dbfb05825d29ace0d20cdf55fa4
Gitweb:     http://git.kernel.org/tip/202461e2f3c15dbfb05825d29ace0d20cdf55fa4
Author:     Mike Galbraith <efault@gmx.de>
AuthorDate: Mon, 13 Feb 2017 03:31:55 +0100
Committer:  Thomas Gleixner <tglx@linutronix.de>
CommitDate: Mon, 13 Feb 2017 09:49:31 +0100

tick/broadcast: Prevent deadlock on tick_broadcast_lock

tick_broadcast_lock is taken from interrupt context, but the following call
chain takes the lock without disabling interrupts:

[   12.703736]  _raw_spin_lock+0x3b/0x50
[   12.703738]  tick_broadcast_control+0x5a/0x1a0
[   12.703742]  intel_idle_cpu_online+0x22/0x100
[   12.703744]  cpuhp_invoke_callback+0x245/0x9d0
[   12.703752]  cpuhp_thread_fun+0x52/0x110
[   12.703754]  smpboot_thread_fn+0x276/0x320

So the following deadlock can happen:

   lock(tick_broadcast_lock);
   <Interrupt>
      lock(tick_broadcast_lock);

intel_idle_cpu_online() is the only place which violates the calling
convention of tick_broadcast_control(). This was caused by the removal of
the smp function call in course of the cpu hotplug rework.

Instead of slapping local_irq_disable/enable() at the call site, we can
relax the calling convention and handle it in the core code, which makes
the whole machinery more robust.

Fixes: 29d7bbada98e ("intel_idle: Remove superfluous SMP fuction call")
Reported-by: Gabriel C <nix.or.die@gmail.com>
Signed-off-by: Mike Galbraith <efault@gmx.de>
Cc: Ruslan Ruslichenko <rruslich@cisco.com>
Cc: Jiri Slaby <jslaby@suse.cz>
Cc: Greg KH <gregkh@linuxfoundation.org>
Cc: Borislav Petkov <bp@alien8.de>
Cc: lwn@lwn.net
Cc: Andrew Morton <akpm@linux-foundation.org>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Anna-Maria Gleixner <anna-maria@linutronix.de>
Cc: Sebastian Siewior <bigeasy@linutronix.de>
Cc: stable <stable@vger.kernel.org>
Link: http://lkml.kernel.org/r/1486953115.5912.4.camel@gmx.de
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>

---
 kernel/time/tick-broadcast.c | 15 +++++++--------
 1 file changed, 7 insertions(+), 8 deletions(-)

diff --git a/kernel/time/tick-broadcast.c b/kernel/time/tick-broadcast.c
index 3109204..17ac99b 100644
--- a/kernel/time/tick-broadcast.c
+++ b/kernel/time/tick-broadcast.c
@@ -347,17 +347,16 @@ static void tick_handle_periodic_broadcast(struct clock_event_device *dev)
  *
  * Called when the system enters a state where affected tick devices
  * might stop. Note: TICK_BROADCAST_FORCE cannot be undone.
- *
- * Called with interrupts disabled, so clockevents_lock is not
- * required here because the local clock event device cannot go away
- * under us.
  */
 void tick_broadcast_control(enum tick_broadcast_mode mode)
 {
 	struct clock_event_device *bc, *dev;
 	struct tick_device *td;
 	int cpu, bc_stopped;
+	unsigned long flags;
 
+	/* Protects also the local clockevent device. */
+	raw_spin_lock_irqsave(&tick_broadcast_lock, flags);
 	td = this_cpu_ptr(&tick_cpu_device);
 	dev = td->evtdev;
 
@@ -365,12 +364,11 @@ void tick_broadcast_control(enum tick_broadcast_mode mode)
 	 * Is the device not affected by the powerstate ?
 	 */
 	if (!dev || !(dev->features & CLOCK_EVT_FEAT_C3STOP))
-		return;
+		goto out;
 
 	if (!tick_device_is_functional(dev))
-		return;
+		goto out;
 
-	raw_spin_lock(&tick_broadcast_lock);
 	cpu = smp_processor_id();
 	bc = tick_broadcast_device.evtdev;
 	bc_stopped = cpumask_empty(tick_broadcast_mask);
@@ -420,7 +418,8 @@ void tick_broadcast_control(enum tick_broadcast_mode mode)
 				tick_broadcast_setup_oneshot(bc);
 		}
 	}
-	raw_spin_unlock(&tick_broadcast_lock);
+out:
+	raw_spin_unlock_irqrestore(&tick_broadcast_lock, flags);
 }
 EXPORT_SYMBOL_GPL(tick_broadcast_control);
 

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Gabriel C <nix.or.die@gmail.com> - 2017-02-06 18:40 +0100
  Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Greg KH <gregkh@linuxfoundation.org> - 2017-02-06 18:50 +0100
    Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) "Ruslan Ruslichenko -X (rruslich - GLOBALLOGIC INC at Cisco)"          <rruslich@cisco.com> - 2017-02-06 20:10 +0100
      Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Gabriel C <nix.or.die@gmail.com> - 2017-02-06 21:40 +0100
  Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Linus Torvalds <torvalds@linux-foundation.org> - 2017-02-07 00:10 +0100
    Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Thomas Gleixner <tglx@linutronix.de> - 2017-02-07 22:10 +0100
      Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Thomas Gleixner <tglx@linutronix.de> - 2017-02-07 22:30 +0100
        Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Gabriel C <nix.or.die@gmail.com> - 2017-02-11 00:20 +0100
          Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Gabriel C <nix.or.die@gmail.com> - 2017-02-11 02:50 +0100
          Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Thomas Gleixner <tglx@linutronix.de> - 2017-02-11 10:10 +0100
            Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Gabriel C <nix.or.die@gmail.com> - 2017-02-11 14:10 +0100
              Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Borislav Petkov <bp@alien8.de> - 2017-02-11 15:30 +0100
                Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Gabriel C <nix.or.die@gmail.com> - 2017-02-11 22:00 +0100
                Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Borislav Petkov <bp@alien8.de> - 2017-02-11 22:40 +0100
                Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Gabriel C <nix.or.die@gmail.com> - 2017-02-12 21:30 +0100
                Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Borislav Petkov <bp@alien8.de> - 2017-02-12 22:20 +0100
                Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Gabriel C <nix.or.die@gmail.com> - 2017-02-12 23:30 +0100
                Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Borislav Petkov <bp@alien8.de> - 2017-02-13 01:40 +0100
                Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Gabriel C <nix.or.die@gmail.com> - 2017-02-13 02:30 +0100
                Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Mike Galbraith <efault@gmx.de> - 2017-02-13 03:40 +0100
                Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Thomas Gleixner <tglx@linutronix.de> - 2017-02-13 09:50 +0100
                [tip:timers/urgent] tick/broadcast: Prevent deadlock on  tick_broadcast_lock tip-bot for Mike Galbraith <tipbot@zytor.com> - 2017-02-13 10:00 +0100
                Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Borislav Petkov <bp@alien8.de> - 2017-02-13 11:30 +0100
    Re: Linux 4.9.6 ( Restore IO-APIC irq_chip retrigger callback ,  breaks my box ) Thomas Gleixner <tglx@linutronix.de> - 2017-02-07 23:10 +0100

csiph-web