From: Thomas Gleixner <tglx@linutronix.de>
To: LKML <linux-kernel@vger.kernel.org>
Cc: Anna-Maria Behnsen <anna-maria@linutronix.de>,
Frederic Weisbecker <frederic@kernel.org>,
John Stultz <jstultz@google.com>,
Peter Zijlstra <peterz@infradead.org>,
Ingo Molnar <mingo@kernel.org>, Stephen Boyd <sboyd@kernel.org>,
Eric Biederman <ebiederm@xmission.com>,
Oleg Nesterov <oleg@redhat.com>
Subject: [patch V7 00/21] posix-timers: Cure the SIG_IGN mess
Date: Tue, 5 Nov 2024 09:14:28 +0100 (CET) [thread overview]
Message-ID: <20241105063544.565410398@linutronix.de> (raw)
This are the remaining bits to cure the SIG_IGN mess. Version 5 can be found
here:
https://lore.kernel.org/lkml/20241001083138.922192481@linutronix.de
Last year I reread a 15 years old comment about the SIG_IGN problem:
"FIXME: What we really want, is to stop this timer completely and restart
it in case the SIG_IGN is removed. This is a non trivial change which
involves sighand locking (sigh !), which we don't want to do late in the
release cycle. ... A more complex fix which solves also another related
inconsistency is already in the pipeline."
The embarrasing part was that I put that comment in back then. So I went
back and rumaged through old notes as I completely had forgotten why our
attempts to fix this back then failed.
It turned out that the comment is about right: sighand locking and life
time issues. So I sat down with the old notes and started to wrap my head
around this again.
The problem to solve:
Posix interval timers are not rearmed automatically by the kernel for
various reasons:
1) To prevent DoS by extremly short intervals.
2) To avoid timer overhead when a signal is pending and has not
yet been delivered.
This is achieved by queueing the signal at timer expiry and rearming the
timer at signal delivery to user space. This puts the rearming basically
under scheduler control and the work happens in context of the task which
asked for the signal.
There is a problem with that vs. SIG_IGN. If a signal has SIG_IGN installed
as handler, the related signals are discarded. So in case of posix interval
timers this means that such a timer is never rearmed even when SIG_IGN is
replaced later with a real handler (including SIG_DFL).
To work around that the kernel self rearms those timers and throttles them
when the interval is smaller than a tick to prevent a DoS.
That just keeps timers ticking, which obviously has effects on power and
just creates work for nothing.
So ideally these timers should be stopped and rearmed when SIG_IGN is
replaced, which aligns with the regular handling of posix timers.
Sounds trivial, but isn't:
1) Lock ordering.
The timer lock cannot be taken with sighand lock held which is
problematic vs. the atomicity of sigaction().
2) Life time rules
The timer and the sigqueue are separate entities which requires a
lookup of the timer ID in the signal rearm code. This can be handled,
but the separate life time rules are not necessarily robust.
3) Finding the relevant timers
Obviosly it is possible to walk the posix timer list under sighand
lock and handle it from there. That can be expensive especially in the
case that there are no affected timers as the walk would just end up
doing nothing.
The following series is a new and this time actually working attempt to
solve this. It addresses it by:
1) Embedding the preallocated sigqueue into struct k_itimer, which makes
the life time rules way simpler and just needs a trivial reference
count.
2) Having a separate list in task::signal on which ignored timers are
queued.
This avoids walking a potentially large timer list for nothing on a
SIG_IGN to handler transition.
3) Requeueing the timers signal in the relevant signal queue so the timer
is rearmed when the signal is actually delivered
That turned out to be the least complicated way to address the sighand
lock vs. timer lock ordering issue.
With that timers which have their signal ignored are not longer self
rearmed and the relevant workarounds including throttling for DoS
prevention are removed.
The series is based on:
git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip timers/core
The series is also available from git:
git://git.kernel.org/pub/scm/linux/kernel/git/tglx/devel.git posixt-v7
Changes vs. V6:
- Update timer state consistently in posix_cpu_timer_del() - Frederic
- Cured the timer delete/exit issue vs. SIG_IGN - Frederic
- Use the proper list head in the exit path - Frederic
- Picked up Reviewed-by tags as appropriate
Thanks,
tglx
---
drivers/power/supply/charger-manager.c | 3
fs/proc/base.c | 4
fs/timerfd.c | 4
include/linux/alarmtimer.h | 10
include/linux/posix-timers.h | 61 +++++
include/linux/sched/signal.h | 4
include/uapi/asm-generic/siginfo.h | 2
init/init_task.c | 5
kernel/fork.c | 1
kernel/signal.c | 343 ++++++++++++++++++++++-----------
kernel/time/alarmtimer.c | 87 +-------
kernel/time/posix-cpu-timers.c | 59 +++--
kernel/time/posix-timers.c | 234 ++++++++++------------
kernel/time/posix-timers.h | 2
net/netfilter/xt_IDLETIMER.c | 4
15 files changed, 463 insertions(+), 360 deletions(-)
next reply other threads:[~2024-11-05 8:14 UTC|newest]
Thread overview: 50+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-11-05 8:14 Thomas Gleixner [this message]
2024-11-05 8:14 ` [patch V7 01/21] posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() Thomas Gleixner
2024-11-05 12:02 ` Frederic Weisbecker
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 02/21] posix-timers: Make signal delivery consistent Thomas Gleixner
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 03/21] posix-timers: Make signal overrun accounting sensible Thomas Gleixner
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 04/21] posix-cpu-timers: Cleanup the firing logic Thomas Gleixner
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 05/21] posix-cpu-timers: Use dedicated flag for CPU timer nanosleep Thomas Gleixner
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 06/21] posix-timers: Add a refcount to struct k_itimer Thomas Gleixner
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 07/21] signal: Split up __sigqueue_alloc() Thomas Gleixner
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 08/21] signal: Provide posixtimer_sigqueue_init() Thomas Gleixner
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 09/21] posix-timers: Store PID type in the timer Thomas Gleixner
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 10/21] signal: Refactor send_sigqueue() Thomas Gleixner
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 11/21] signal: Replace resched_timer logic Thomas Gleixner
2024-11-05 12:08 ` Frederic Weisbecker
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 12/21] posix-timers: Embed sigqueue in struct k_itimer Thomas Gleixner
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 13/21] signal: Cleanup unused posix-timer leftovers Thomas Gleixner
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 14/21] posix-timers: Move sequence logic into struct k_itimer Thomas Gleixner
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 15/21] signal: Provide ignored_posix_timers list Thomas Gleixner
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 16/21] posix-timers: Handle ignored list on delete and exit Thomas Gleixner
2024-11-05 13:08 ` Frederic Weisbecker
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 17/21] signal: Handle ignored signals in do_sigaction(action != SIG_IGN) Thomas Gleixner
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 18/21] signal: Queue ignored posixtimers on ignore list Thomas Gleixner
2024-11-05 14:02 ` Frederic Weisbecker
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 19/21] posix-timers: Cleanup SIG_IGN workaround leftovers Thomas Gleixner
2024-11-05 14:26 ` Frederic Weisbecker
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 20/21] alarmtimers: Remove the throttle mechanism from alarm_forward_now() Thomas Gleixner
2024-11-05 14:29 ` Frederic Weisbecker
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
2024-11-05 8:14 ` [patch V7 21/21] alarmtimers: Remove return value from alarm functions Thomas Gleixner
2024-11-05 14:34 ` Frederic Weisbecker
2024-11-07 1:31 ` [tip: timers/core] " tip-bot2 for Thomas Gleixner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20241105063544.565410398@linutronix.de \
--to=tglx@linutronix.de \
--cc=anna-maria@linutronix.de \
--cc=ebiederm@xmission.com \
--cc=frederic@kernel.org \
--cc=jstultz@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@kernel.org \
--cc=oleg@redhat.com \
--cc=peterz@infradead.org \
--cc=sboyd@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®