From: Hillf Danton <hdanton@sina.com>
To: Tejun Heo <tj@kernel.org>
Cc: Tadeusz Struk <tadeusz.struk@linaro.org>,
Michal Koutny <mkoutny@suse.com>,
linux-kernel@vger.kernel.org, linux-mm@kvack.org,
syzbot+e42ae441c3b10acf9e9d@syzkaller.appspotmail.com
Subject: Re: [PATCH] cgroup: don't queue css_release_work if one already pending
Date: Thu, 19 May 2022 19:23:19 +0800 [thread overview]
Message-ID: <20220519112319.2455-1-hdanton@sina.com> (raw)
In-Reply-To: <317701e1-20a7-206f-92cd-cd36d436eee2@linaro.org>
On Wed, 18 May 2022 09:48:21 -0700 Tadeusz Struk wrote:
> On 4/22/22 04:05, Michal Koutny wrote:
> > On Thu, Apr 21, 2022 at 02:00:56PM -1000, Tejun Heo <tj@kernel.org> wrote:
> >> If this is the case, we need to hold an extra reference to be put by the
> >> css_killed_work_fn(), right?
That put could trigger INIT_WORK in css_release() and warning [1]
on init active (active state 0) object OTOH as the same
css->destroy_work is used in both kill and release pathes.
Hillf
[1] https://lore.kernel.org/lkml/000000000000ff747805debce6c6@google.com/
> >
> > I looked into it a bit more lately and found that there already is such
> > a fuse in kill_css() [1].
> >
> > At the same type syzbots stack trace demonstrates the fuse is
> > ineffective
> >
> >> css_release+0xae/0xc0 kernel/cgroup/cgroup.c:5146 (**)
> >> percpu_ref_put_many include/linux/percpu-refcount.h:322 [inline]
> >> percpu_ref_put include/linux/percpu-refcount.h:338 [inline]
> >> percpu_ref_call_confirm_rcu lib/percpu-refcount.c:162 [inline] (*)
> >> percpu_ref_switch_to_atomic_rcu+0x5a2/0x5b0 lib/percpu-refcount.c:199
> >> rcu_do_batch+0x4f8/0xbc0 kernel/rcu/tree.c:2485
> >> rcu_core+0x59b/0xe30 kernel/rcu/tree.c:2722
> >> rcu_core_si+0x9/0x10 kernel/rcu/tree.c:2735
> >> __do_softirq+0x27e/0x596 kernel/softirq.c:305
> >
> > (*) this calls css_killed_ref_fn confirm_switch
> > (**) zero references after confirmed kill?
> >
> > So, I was also looking at the possible race with css_free_rwork_fn()
> > (from failed css_create()) but that would likely emit a warning from
> > __percpu_ref_exit().
> >
> > So, I still think there's something fishy (so far possible only via
> > artificial ENOMEM injection) that needs an explanation...
>
> I can't reliably reproduce this issue on neither mainline nor v5.10, where
> syzbot originally found it. It still triggers for syzbot though.
>
> --
> Thanks,
> Tadeusz
next parent reply other threads:[~2022-05-19 11:23 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20220412192459.227740-1-tadeusz.struk@linaro.org>
[not found] ` <20220414164409.GA5404@blackbody.suse.cz>
[not found] ` <YmHwOAdGY2Lwl+M3@slm.duckdns.org>
[not found] ` <20220422100400.GA29552@blackbody.suse.cz>
[not found] ` <317701e1-20a7-206f-92cd-cd36d436eee2@linaro.org>
2022-05-19 11:23 ` Hillf Danton [this message]
2022-05-19 23:26 ` Tadeusz Struk
2022-05-20 8:13 ` Tejun Heo
2022-05-20 16:38 ` Tadeusz Struk
2022-05-20 16:42 ` Michal Koutný
2022-05-20 16:56 ` Tadeusz Struk
2022-05-23 19:00 ` Tadeusz Struk
2022-05-23 19:02 ` Tejun Heo
2022-05-23 19:08 ` Tadeusz Struk
2022-05-23 20:05 ` Tadeusz Struk
2022-05-20 23:48 ` Hillf Danton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20220519112319.2455-1-hdanton@sina.com \
--to=hdanton@sina.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=mkoutny@suse.com \
--cc=syzbot+e42ae441c3b10acf9e9d@syzkaller.appspotmail.com \
--cc=tadeusz.struk@linaro.org \
--cc=tj@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox