mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Thomas Gleixner <tglx@linutronix.de>
To: LKML <linux-kernel@vger.kernel.org>
Cc: Anna-Maria Behnsen <anna-maria@linutronix.de>,
	Frederic Weisbecker <frederic@kernel.org>,
	John Stultz <jstultz@google.com>,
	Peter Zijlstra <peterz@infradead.org>,
	Ingo Molnar <mingo@kernel.org>, Stephen Boyd <sboyd@kernel.org>,
	Eric Biederman <ebiederm@xmission.com>,
	Oleg Nesterov <oleg@redhat.com>
Subject: [patch v4 09/27] posix-timers: Make signal delivery consistent
Date: Fri, 27 Sep 2024 10:48:50 +0200 (CEST)	[thread overview]
Message-ID: <20240927084817.449464642@linutronix.de> (raw)
In-Reply-To: <20240927083900.989915582@linutronix.de>

From: Thomas Gleixner <tglx@linutronix.de>

Signals of timers which are reprogammed, disarmed or deleted can deliver
signals related to the past. The POSIX spec is blury about this:

 - "The effect of disarming or resetting a timer with pending expiration
   notifications is unspecified."

 - "The disposition of pending signals for the deleted timer is
    unspecified."

In both cases it is reasonable to expect that pending signals are
discarded. Especially in the reprogramming case it does not make sense to
account for previous overruns or to deliver a signal for a timer which has
been disarmed. This makes the behaviour consistent and understandable.

Remove the si_sys_private check from the signal delivery code and invoke
posix_timer_deliver_signal() unconditionally.

Change that function so it controls the actual signal delivery via the
return value. It now instructs the signal code to drop the signal when:

  1) The timer does not longer exist in the hash table

  2) The timer signal_seq value is not the same as the si_sys_private value
     which was set when the signal was queued.

Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>

---
 include/linux/posix-timers.h   |  2 --
 kernel/signal.c                |  2 +-
 kernel/time/posix-cpu-timers.c |  2 +-
 kernel/time/posix-timers.c     | 25 +++++++++++++++----------
 4 files changed, 17 insertions(+), 14 deletions(-)
---
diff --git a/include/linux/posix-timers.h b/include/linux/posix-timers.h
index 02afbb4da7f7..8c6d97412526 100644
--- a/include/linux/posix-timers.h
+++ b/include/linux/posix-timers.h
@@ -137,8 +137,6 @@ static inline void clear_posix_cputimers_work(struct task_struct *p) { }
 static inline void posix_cputimers_init_work(void) { }
 #endif
 
-#define REQUEUE_PENDING 1
-
 /**
  * struct k_itimer - POSIX.1b interval timer structure.
  * @list:		List head for binding the timer to signals->posix_timers
diff --git a/kernel/signal.c b/kernel/signal.c
index c35b6ff52767..a407724f1267 100644
--- a/kernel/signal.c
+++ b/kernel/signal.c
@@ -617,7 +617,7 @@ int dequeue_signal(sigset_t *mask, kernel_siginfo_t *info, enum pid_type *type)
 	}
 
 	if (IS_ENABLED(CONFIG_POSIX_TIMERS)) {
-		if (unlikely(info->si_code == SI_TIMER && info->si_sys_private)) {
+		if (unlikely(info->si_code == SI_TIMER)) {
 			if (!posixtimer_deliver_signal(info))
 				goto again;
 		}
diff --git a/kernel/time/posix-cpu-timers.c b/kernel/time/posix-cpu-timers.c
index 12f828d704b1..bc2cd32b7a40 100644
--- a/kernel/time/posix-cpu-timers.c
+++ b/kernel/time/posix-cpu-timers.c
@@ -746,7 +746,7 @@ static void __posix_cpu_timer_get(struct k_itimer *timer, struct itimerspec64 *i
 	 *  - Timers which expired, but the signal has not yet been
 	 *    delivered
 	 */
-	if (iv && ((timer->it_signal_seq & REQUEUE_PENDING) || sigev_none))
+	if (iv && timer->it_status != POSIX_TIMER_ARMED)
 		expires = bump_cpu_timer(timer, now);
 	else
 		expires = cpu_timer_getexpires(&timer->it.cpu);
diff --git a/kernel/time/posix-timers.c b/kernel/time/posix-timers.c
index 6f0dacec25e0..1231efb7c30f 100644
--- a/kernel/time/posix-timers.c
+++ b/kernel/time/posix-timers.c
@@ -269,7 +269,10 @@ bool posixtimer_deliver_signal(struct kernel_siginfo *info)
 	if (!timr)
 		goto out;
 
-	if (timr->it_interval && timr->it_signal_seq == info->si_sys_private) {
+	if (timr->it_signal_seq != info->si_sys_private)
+		goto out_unlock;
+
+	if (timr->it_interval && timr->it_status == POSIX_TIMER_REQUEUE_PENDING) {
 		timr->kclock->timer_rearm(timr);
 
 		timr->it_status = POSIX_TIMER_ARMED;
@@ -281,6 +284,7 @@ bool posixtimer_deliver_signal(struct kernel_siginfo *info)
 	}
 	ret = true;
 
+out_unlock:
 	unlock_timer(timr, flags);
 out:
 	spin_lock(&current->sighand->siglock);
@@ -293,19 +297,19 @@ bool posixtimer_deliver_signal(struct kernel_siginfo *info)
 int posix_timer_queue_signal(struct k_itimer *timr)
 {
 	enum posix_timer_state state = POSIX_TIMER_DISARMED;
-	int ret, si_private = 0;
 	enum pid_type type;
+	int ret;
 
 	lockdep_assert_held(&timr->it_lock);
 
 	if (timr->it_interval) {
+		timr->it_signal_seq++;
 		state = POSIX_TIMER_REQUEUE_PENDING;
-		si_private = ++timr->it_signal_seq;
 	}
 	timr->it_status = state;
 
 	type = !(timr->it_sigev_notify & SIGEV_THREAD_ID) ? PIDTYPE_TGID : PIDTYPE_PID;
-	ret = send_sigqueue(timr->sigq, timr->it_pid, type, si_private);
+	ret = send_sigqueue(timr->sigq, timr->it_pid, type, timr->it_signal_seq);
 	/* If we failed to send the signal the timer stops. */
 	return ret > 0;
 }
@@ -670,7 +674,7 @@ void common_timer_get(struct k_itimer *timr, struct itimerspec64 *cur_setting)
 	 * is a SIGEV_NONE timer move the expiry time forward by intervals,
 	 * so expiry is > now.
 	 */
-	if (iv && (timr->it_signal_seq & REQUEUE_PENDING || sig_none))
+	if (iv && timr->it_status != POSIX_TIMER_ARMED)
 		timr->it_overrun += kc->timer_forward(timr, now);
 
 	remaining = kc->timer_remaining(timr, now);
@@ -870,8 +874,6 @@ void posix_timer_set_common(struct k_itimer *timer, struct itimerspec64 *new_set
 	else
 		timer->it_interval = 0;
 
-	/* Prevent reloading in case there is a signal pending */
-	timer->it_signal_seq = (timer->it_signal_seq + 2) & ~REQUEUE_PENDING;
 	/* Reset overrun accounting */
 	timer->it_overrun_last = 0;
 	timer->it_overrun = -1LL;
@@ -889,8 +891,6 @@ int common_timer_set(struct k_itimer *timr, int flags,
 	if (old_setting)
 		common_timer_get(timr, old_setting);
 
-	/* Prevent rearming by clearing the interval */
-	timr->it_interval = 0;
 	/*
 	 * Careful here. On SMP systems the timer expiry function could be
 	 * active and spinning on timr->it_lock.
@@ -940,6 +940,9 @@ static int do_timer_settime(timer_t timer_id, int tmr_flags,
 	if (old_spec64)
 		old_spec64->it_interval = ktime_to_timespec64(timr->it_interval);
 
+	/* Prevent signal delivery and rearming. */
+	timr->it_signal_seq++;
+
 	kc = timr->kclock;
 	if (WARN_ON_ONCE(!kc || !kc->timer_set))
 		error = -EINVAL;
@@ -1008,7 +1011,6 @@ int common_timer_del(struct k_itimer *timer)
 {
 	const struct k_clock *kc = timer->kclock;
 
-	timer->it_interval = 0;
 	if (kc->timer_try_to_cancel(timer) < 0)
 		return TIMER_RETRY;
 	timer->it_status = POSIX_TIMER_DISARMED;
@@ -1036,6 +1038,9 @@ SYSCALL_DEFINE1(timer_delete, timer_t, timer_id)
 	if (!timer)
 		return -EINVAL;
 
+	/* Prevent signal delivery and rearming. */
+	timer->it_signal_seq++;
+
 	if (unlikely(timer_delete_hook(timer) == TIMER_RETRY)) {
 		/* Unlocks and relocks the timer if it still exists */
 		timer = timer_wait_running(timer, &flags);


  parent reply	other threads:[~2024-09-27  8:48 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-09-27  8:48 [patch v4 00/27] posix-timers: Cure the SIG_IGN mess Thomas Gleixner
2024-09-27  8:48 ` [patch v4 01/27] signal: Confine POSIX_TIMERS properly Thomas Gleixner
2024-09-27 12:21   ` Frederic Weisbecker
2024-09-27  8:48 ` [patch v4 02/27] signal: Prevent user space from setting si_sys_private Thomas Gleixner
2024-09-27 12:37   ` Frederic Weisbecker
2024-09-27 13:40   ` Eric W. Biederman
2024-09-27  8:48 ` [patch v4 03/27] signal: Get rid of resched_timer logic Thomas Gleixner
2024-09-27 13:08   ` Frederic Weisbecker
2024-09-27 13:53   ` Eric W. Biederman
2024-09-27  8:48 ` [patch v4 04/27] posix-timers: Cure si_sys_private race Thomas Gleixner
2024-09-27 14:02   ` Eric W. Biederman
2024-09-27  8:48 ` [patch v4 05/27] signal: Allow POSIX timer signals to be dropped Thomas Gleixner
2024-09-27  8:48 ` [patch v4 06/27] posix-timers: Drop signal if timer has been deleted or reprogrammed Thomas Gleixner
2024-09-27  8:48 ` [patch v4 07/27] posix-timers: Rename k_itimer::it_requeue_pending Thomas Gleixner
2024-09-27  8:48 ` [patch v4 08/27] posix-timers: Add proper state tracking Thomas Gleixner
2024-09-27  8:48 ` Thomas Gleixner [this message]
2024-09-27  8:48 ` [patch v4 10/27] posix-timers: Make signal overrun accounting sensible Thomas Gleixner
2024-09-27  8:48 ` [patch v4 11/27] posix-cpu-timers: Use dedicated flag for CPU timer nanosleep Thomas Gleixner
2024-09-27  8:48 ` [patch v4 12/27] posix-timers: Add a refcount to struct k_itimer Thomas Gleixner
2024-09-27  8:48 ` [patch v4 13/27] signal: Split up __sigqueue_alloc() Thomas Gleixner
2024-09-27  8:48 ` [patch v4 14/27] signal: Provide posixtimer_sigqueue_init() Thomas Gleixner
2024-09-27  8:48 ` [patch v4 15/27] signal: Add sys_private_ptr to siginfo::_sifields:: _timer Thomas Gleixner
2024-09-27  8:48 ` [patch v4 16/27] posix-timers: Store PID type in the timer Thomas Gleixner
2024-09-27  8:48 ` [patch v4 17/27] signal: Refactor send_sigqueue() Thomas Gleixner
2024-09-27  8:49 ` [patch v4 18/27] posix-timers: Embed sigqueue in struct k_itimer Thomas Gleixner
2024-09-27  8:49 ` [patch v4 19/27] signal: Cleanup unused posix-timer leftovers Thomas Gleixner
2024-09-27  8:49 ` [patch v4 20/27] signal: Add task argument to flush_sigqueue_mask() Thomas Gleixner
2024-09-27  8:49 ` [patch v4 21/27] signal: Provide ignored_posix_timers list Thomas Gleixner
2024-09-27  8:49 ` [patch v4 22/27] posix-timers: Handle ignored list on delete and exit Thomas Gleixner
2024-09-27  8:49 ` [patch v4 23/27] signal: Handle ignored signals in do_sigaction(action != SIG_IGN) Thomas Gleixner
2024-09-27  8:49 ` [patch v4 24/27] signal: Queue ignored posixtimers on ignore list Thomas Gleixner
2024-09-27  8:49 ` [patch v4 25/27] posix-timers: Cleanup SIG_IGN workaround leftovers Thomas Gleixner
2024-09-27  8:49 ` [patch v4 26/27] alarmtimers: Remove the throttle mechanism from alarm_forward_now() Thomas Gleixner
2024-09-27  8:49 ` [patch v4 27/27] alarmtimers: Remove return value from alarm functions Thomas Gleixner
2024-09-27 14:39 ` [patch v4 00/27] posix-timers: Cure the SIG_IGN mess Eric W. Biederman
2024-09-27 19:24   ` Thomas Gleixner

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240927084817.449464642@linutronix.de \
    --to=tglx@linutronix.de \
    --cc=anna-maria@linutronix.de \
    --cc=ebiederm@xmission.com \
    --cc=frederic@kernel.org \
    --cc=jstultz@google.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@kernel.org \
    --cc=oleg@redhat.com \
    --cc=peterz@infradead.org \
    --cc=sboyd@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome