From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2C88EC77B7A for ; Wed, 24 May 2023 06:05:11 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 95879900003; Wed, 24 May 2023 02:05:10 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 8E254900002; Wed, 24 May 2023 02:05:10 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 75A97900003; Wed, 24 May 2023 02:05:10 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0016.hostedemail.com [216.40.44.16]) by kanga.kvack.org (Postfix) with ESMTP id 61432900002 for ; Wed, 24 May 2023 02:05:10 -0400 (EDT) Received: from smtpin06.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay08.hostedemail.com (Postfix) with ESMTP id 2BE081408A5 for ; Wed, 24 May 2023 06:05:10 +0000 (UTC) X-FDA: 80824110780.06.A5CD686 Received: from mail-pf1-f173.google.com (mail-pf1-f173.google.com [209.85.210.173]) by imf09.hostedemail.com (Postfix) with ESMTP id 5FFC0140005 for ; Wed, 24 May 2023 06:05:08 +0000 (UTC) Authentication-Results: imf09.hostedemail.com; dkim=pass header.d=gmail.com header.s=20221208 header.b="JH7/tN5i"; spf=pass (imf09.hostedemail.com: domain of npiggin@gmail.com designates 209.85.210.173 as permitted sender) smtp.mailfrom=npiggin@gmail.com; dmarc=pass (policy=none) header.from=gmail.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1684908308; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-transfer-encoding:content-transfer-encoding: in-reply-to:references:dkim-signature; bh=h76hRggjcOPyKeT4qZCjFVlxoGbcWZbH0agh7LoEb/E=; b=cVNWUtntS6pPnefeKyhj+z4cLh0TF8sLhv9Atz2J44JyQXGb5yVIUD4FCRTjRq/d/4BzXQ jNtoLYN14fIe3ixx2DIokz7R11g6MTDi8Ct+a6H78yosNU0wca+SGJAOtngMX5U9dXnR3/ flf1BjHrkmAcSHWpZm37An9V9TT6t0A= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1684908308; a=rsa-sha256; cv=none; b=nlz1/+WuddllusA9wZ4gH7GmxCe2+Ge4zR4L7QJTG+OidVxMjHwJrCtt5EZiWo7gy4IAOA NOpK/5BzZY2Sd2kUw/SjitsRUrsHRgz7U3d3m8Br25N0YOUCcaLk245Q2WxJz2ILPR2Qb6 h1Pfjxbli8J+OX7UNnhtq3tmxmO17vE= ARC-Authentication-Results: i=1; imf09.hostedemail.com; dkim=pass header.d=gmail.com header.s=20221208 header.b="JH7/tN5i"; spf=pass (imf09.hostedemail.com: domain of npiggin@gmail.com designates 209.85.210.173 as permitted sender) smtp.mailfrom=npiggin@gmail.com; dmarc=pass (policy=none) header.from=gmail.com Received: by mail-pf1-f173.google.com with SMTP id d2e1a72fcca58-64d5f65a2f7so351636b3a.1 for ; Tue, 23 May 2023 23:05:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20221208; t=1684908307; x=1687500307; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=h76hRggjcOPyKeT4qZCjFVlxoGbcWZbH0agh7LoEb/E=; b=JH7/tN5i/taJtcD8ZS9eOTiUsqc6vwgZ46sg9LHPOr24Zz9ChJB9x+qCYyBvQRyVVY Mn/tE2JQvyTwNt2CAyr3fez7Hvmz3nrPPObxHmhJHy0NvrqHvXfnvBLXy1SzIGQAP+wq vPHwLxZknPrWwx68HVc94NrbyewdTYS8bI9qnvJYSxkNXAWFkZmGw9YQNxDOxpG6tj+Z 3VSwVwlfI4Tl6nGMN3W/5Ii0UgFCoOMDGLMgx9v0UX2bJu5Njp+p9fdcp9MMK1NkIZ+6 fnFJwImEtJb3jsaiRuBHltbDJRxZIdkiHMaI4+K+U8YJ5VWLypsYSM96y4sijvg1iz6h wGNQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1684908307; x=1687500307; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=h76hRggjcOPyKeT4qZCjFVlxoGbcWZbH0agh7LoEb/E=; b=aqZ92CRg8F4GRj0PmD/oceZXRIgr+aGBF2FLt6DMZGaEDoHgPafEOwfF0HQB+0uUs9 bxfWB/KinC50gan6dKti07PnjLBmubH2aJVsb+saSezS6/v8p2dttl7O0tapPNnb0ugw OE5iglEwcwcJpmnyK2OGVoyAvOfZUh5ZYOgad880HsNLwdYzo/+yKekCSpwyOjxJk0Mf hq1l5IEyF5/dtjRXSQTWbQ+QrL5Bsr2lQWBpayO/fs4IgaUv88t7zBv6WHgtz64KMDFM JxulR2pBQuIhygh1VHhanWkGoXf92ztXAdGhaY0Z4C5zMYMoftwR9lFgRN7TwfLsBZ7T 33mw== X-Gm-Message-State: AC+VfDyy3o6vmNdZ1zp6qNs+4rLKxRaNLOvJCGfr8Qj2I+hNFMHI1AYM i7owFsKwgQ7rYFEE8pPV3IU= X-Google-Smtp-Source: ACHHUZ5h8gmTlVFgyzOdv6CRG0hYaebOlspy3KPJgiMnmH+PNp/erWFdKQaV209RguXZ/VoWnFMI/Q== X-Received: by 2002:a05:6a00:194e:b0:644:8172:3ea9 with SMTP id s14-20020a056a00194e00b0064481723ea9mr1898844pfk.15.1684908306855; Tue, 23 May 2023 23:05:06 -0700 (PDT) Received: from wheely.local0.net ([220.240.241.243]) by smtp.gmail.com with ESMTPSA id k25-20020aa792d9000000b00646e7d2b5a7sm6678426pfa.112.2023.05.23.23.05.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 23 May 2023 23:05:05 -0700 (PDT) From: Nicholas Piggin To: Andrew Morton Cc: Nicholas Piggin , Linus Torvalds , Peter Zijlstra , linuxppc-dev@lists.ozlabs.org, linux-mm@kvack.org Subject: [PATCH 1/2] lazy tlb: fix hotplug exit race with MMU_LAZY_TLB_SHOOTDOWN Date: Wed, 24 May 2023 16:04:54 +1000 Message-Id: <20230524060455.147699-1-npiggin@gmail.com> X-Mailer: git-send-email 2.40.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Rspamd-Queue-Id: 5FFC0140005 X-Rspam-User: X-Stat-Signature: pt8brqay4bcgu1od8f9491bohk17oh3s X-Rspamd-Server: rspam03 X-HE-Tag: 1684908308-739881 X-HE-Meta: U2FsdGVkX19+EZzm2Zyx2j7II74sHypnrTjEo66SKtxIhwgnV1gBo5h3ZItBx/um/TAiKsInE/ZO6+ei3nI034sVVxoxmm+jcpAMuw1UHNX1q/HH7njB6Ibc5e2gT5JlO3/K42TX+WYzpjbK7zv0p1t1TinDq7TCf35gdGGskIKvPYG/xq/omEgiZkj8Y/bpE7r784usSjVWV9hW4Z/QUx28C6vhXAR03xebAlODP+sKvxqHZentdsk0EPPOFprZzm3L9bD6DM8XemMoy8g0QvxF00ch8ykosUizeDEDOzSleoWrTOK8IaMrhRrcT5d+5JI8jpugsGY0Y5tZ8aWmi1qtzqCyen9B8sQ54x5yQNoGgIueVT38p2GRXzplQavgw9dMVCBib6w/7iYmmOZOxHAfeZ5CWej7Hq93VDaRG6Dkh/rJS0g1ZWkutGbSsEmr0CU11DyTrI4y8/T/Np2EQIv5bPsSzma8Vtk4+X8RTjBlDyC3BFJXchWdJFkfPmjzanBWIbGoXEv/wEmTJHD6SZwgmhY7QRfjKAs8t7TJkiSUtuH9kCSoAgPqWoh9fl0nUrWcySa/LeOeg4oaR6C2+fKsSBRH+UccFAruf4TH3B75nUhcJcS+vqOF0VokKQHWf+zy0z9EGxY7b3cfrq4Q1lCK+5cXlr3/0EO/VOFu+YwtZDYnOCnRHUEYiA9SP1ZW40Ds+avJhALX+bsQp6yIHpBLMHZ93M+qmbSEVq3QIW94692JL50ym+3/5zStyyPt63/tcHeQGa2prIkaZSF/GjDno+D5NbQLOnPLa/Ta2tlLAV4Qu3VRh81mBDwuTru3RmDBkKS1uXm1Y4+eHbS1kIe5GSsfpmgbDoV/nVM0a9hgQi+VbHZE9spfkCLQ0/KUapVTxD8VLHgRlqBzRtplM5Kr5W1/bkdn1MQ2BEICATbX41GE+LDH5I5K24eT6rCY/pkm7JOChD1WWTZn7XD 5wZqX8VM JJspMdRqL0NN31J+GaKpYD5rvGO3MSsfuSB2luZpeoEmLyOcvUJM3zKjWmNFbj3q+EKpi6Wja+74SC4M0mpKEU0lI4GEASD7KFMXCZQbjYi9tFwG8ciavW0PKjSaJIlQ0v2Hcg41pZOnArFGDX6ktlaPu3OXskDuiLvVJVNdl12niO47uzYf4w+h66/4y1TEqzOplBCxsYoQAPXHGjQwAEA+kDtR2p2OIRMFNKsQYNny8tSEiRekfWZtZoE8YDN8RE10uKCekKsggMxTwhsp8Kwk+GjcVmBSri1LpuqhUFmjlzRf0KKfxzj7uQFV2AN9Szv2jkv2ZY08fmiqQwGd1LrG7ay1igwr896Jxumeu8+f79uTJgDmaxWE8z45lGpOoPFbRt6/D4l3cWHaFTBMNCJPE491wkRdHZSfhXrmhIWx18pQ6W1YdmPMqHX0dRDVleFKAQuhW3eXA89y8kLu2b7LwRaYyiLlRmMa31TE7SAPzzDQ= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: CPU unplug first calls __cpu_disable(), and that's where powerpc calls cleanup_cpu_mmu_context(), which clears this CPU from mm_cpumask() of all mms in the system. However this CPU may still be using a lazy tlb mm, and its mm_cpumask bit will be cleared from it. The CPU does not switch away from the lazy tlb mm until arch_cpu_idle_dead() calls idle_task_exit(). If that user mm exits in this window, it will not be subject to the lazy tlb mm shootdown and may be freed while in use as a lazy mm by the CPU that is being unplugged. cleanup_cpu_mmu_context() could be moved later, but it looks better to move the lazy tlb mm switching earlier. The problem with doing the lazy mm switching in idle_task_exit() is explained in commit bf2c59fce4074 ("sched/core: Fix illegal RCU from offline CPUs"), which added a wart to switch away from the mm but leave it set in active_mm to be cleaned up later. So instead, switch away from the lazy tlb mm on the stopper kthread before the CPU is taken down. This CPU will never switch to a user thread from this point, so it has no chance to pick up a new lazy tlb mm. This removes the lazy tlb mm handling wart in CPU unplug. idle_task_exit() remains to reduce churn in the patch. It could be removed entirely after this because finish_cpu() makes a similar check. finish_cpu() itself is not strictly needed because init_mm will never have its refcount drop to zero. But it is conceptually nicer to keep it rather than have the idle thread drop the reference on the mm it is using. Fixes: 2655421ae69fa ("lazy tlb: shoot lazies, non-refcounting lazy tlb mm reference handling scheme") Signed-off-by: Nicholas Piggin --- include/linux/sched/hotplug.h | 2 ++ kernel/cpu.c | 11 +++++++---- kernel/sched/core.c | 24 +++++++++++++++++++----- 3 files changed, 28 insertions(+), 9 deletions(-) diff --git a/include/linux/sched/hotplug.h b/include/linux/sched/hotplug.h index 412cdaba33eb..cb447d8e3f9a 100644 --- a/include/linux/sched/hotplug.h +++ b/include/linux/sched/hotplug.h @@ -19,8 +19,10 @@ extern int sched_cpu_dying(unsigned int cpu); #endif #ifdef CONFIG_HOTPLUG_CPU +extern void idle_task_prepare_exit(void); extern void idle_task_exit(void); #else +static inline void idle_task_prepare_exit(void) {} static inline void idle_task_exit(void) {} #endif diff --git a/kernel/cpu.c b/kernel/cpu.c index f4a2c5845bcb..584def27ff24 100644 --- a/kernel/cpu.c +++ b/kernel/cpu.c @@ -618,12 +618,13 @@ static int finish_cpu(unsigned int cpu) struct mm_struct *mm = idle->active_mm; /* - * idle_task_exit() will have switched to &init_mm, now - * clean up any remaining active_mm state. + * idle_task_prepare_exit() ensured the idle task was using + * &init_mm. Now that the CPU has stopped, drop that refcount. */ - if (mm != &init_mm) - idle->active_mm = &init_mm; + WARN_ON(mm != &init_mm); + idle->active_mm = NULL; mmdrop_lazy_tlb(mm); + return 0; } @@ -1030,6 +1031,8 @@ static int take_cpu_down(void *_param) enum cpuhp_state target = max((int)st->target, CPUHP_AP_OFFLINE); int err, cpu = smp_processor_id(); + idle_task_prepare_exit(); + /* Ensure this CPU doesn't handle any more interrupts. */ err = __cpu_disable(); if (err < 0) diff --git a/kernel/sched/core.c b/kernel/sched/core.c index a68d1276bab0..bc4ef1f3394b 100644 --- a/kernel/sched/core.c +++ b/kernel/sched/core.c @@ -9373,19 +9373,33 @@ void sched_setnuma(struct task_struct *p, int nid) * Ensure that the idle task is using init_mm right before its CPU goes * offline. */ -void idle_task_exit(void) +void idle_task_prepare_exit(void) { struct mm_struct *mm = current->active_mm; - BUG_ON(cpu_online(smp_processor_id())); - BUG_ON(current != this_rq()->idle); + WARN_ON(!irqs_disabled()); if (mm != &init_mm) { - switch_mm(mm, &init_mm, current); + mmgrab_lazy_tlb(&init_mm); + current->active_mm = &init_mm; + switch_mm_irqs_off(mm, &init_mm, current); finish_arch_post_lock_switch(); + mmdrop_lazy_tlb(mm); } + /* finish_cpu() will mmdrop the init_mm ref after this CPU stops */ +} + +/* + * After the CPU is offline, double check that it was previously switched to + * init_mm. This call can be removed because the condition is caught in + * finish_cpu() as well. + */ +void idle_task_exit(void) +{ + BUG_ON(cpu_online(smp_processor_id())); + BUG_ON(current != this_rq()->idle); - /* finish_cpu(), as ran on the BP, will clean up the active_mm state */ + WARN_ON_ONCE(current->active_mm != &init_mm); } static int __balance_push_cpu_stop(void *arg) -- 2.40.1