mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Tejun Heo <tj@kernel.org>
To: Arun KS <arunks.linux@gmail.com>
Cc: "linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	laijs@cn.fujitsu.com, Silesh C V <saileshcv@gmail.com>,
	Arun KS <getarunks@gmail.com>
Subject: Re: [Workqueue] crash in process_one_work
Date: Mon, 6 Oct 2014 11:32:24 -0400	[thread overview]
Message-ID: <20141006153224.GC18303@htj.dyndns.org> (raw)
In-Reply-To: <CAKZGPAPS+x2V3Ajj323EUStpWGmZ6taOuovjqA3_kaYXA3T_Ag@mail.gmail.com>

Hello, Arun.

On Mon, Sep 29, 2014 at 09:40:50PM +0530, Arun KS wrote:
...
> The value of data is 0xffffffe0, which is basically the value after an
> INIT_WORK() or WORK_DATA_INIT().
> This can happen if a driver calls INIT_WORK on same struct work again
> after queuing it.
> 
> From the above details of the work_struct shows that the work is
> queued from kernel/async.c. async_schedule dynamically allocates the
> work_struct and queues it to system_unbonded_wq. And possibility of
> calling INIT_WORK on same work is not there.
> 
> After inspecting ramdump for async_entry structure in kernel/async.c
> 
> crash> struct async_entry ed7cf140
> struct async_entry {
>   domain_list = {
>     next = 0xed7cf140,
>     prev = 0xed7cf140
>   },
>   global_list = {
>     next = 0xed7cf148,
>     prev = 0xed7cf148
>   },
>   work = {
>     data = {
>       counter = 0xffffffe0
>     },
>     entry = {
>       next = 0xed7cf154,
>       prev = 0xed7cf154
>     },
>     func = 0xc0140ac4 <async_run_entry_fn>
>   },
>   cookie = 0x263e5,
>   func = 0xc074dda0 <dapm_post_sequence_async>,
>   data = 0xed48432c,
>   domain = 0xe5457dec
> }
> 
> the func points to dapm_post_sequence_async. and you can see the
> domain_list and global_list is empty. Which shows that the work has
> finished execution and there is no pending execution in async.
> 
> But how come this struct work was with work queue data structures?
> Is there any corner case in work queue which can miss unlinking the
> struct_work from pool_workqueue after executing them?

I sure hope not.  How reproducible is the issue?  Can you try w/
CONFIG_DEBUG_OBJECTS_WORK enabled?

Thanks.

-- 
tejun

  reply	other threads:[~2014-10-06 15:32 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-09-29 16:10 Arun KS
2014-10-06 15:32 ` Tejun Heo [this message]
2014-10-08 12:00   ` Arun KS
2014-10-08 12:15     ` Tejun Heo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20141006153224.GC18303@htj.dyndns.org \
    --to=tj@kernel.org \
    --cc=arunks.linux@gmail.com \
    --cc=getarunks@gmail.com \
    --cc=laijs@cn.fujitsu.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=saileshcv@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®