From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751885AbcF0NPS (ORCPT ); Mon, 27 Jun 2016 09:15:18 -0400 Received: from www.linutronix.de ([62.245.132.108]:33206 "EHLO Galois.linutronix.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751742AbcF0NPQ (ORCPT ); Mon, 27 Jun 2016 09:15:16 -0400 Date: Mon, 27 Jun 2016 15:13:01 +0200 (CEST) From: Thomas Gleixner To: Vegard Nossum cc: Sasha Levin , Tejun Heo , Lai Jiangshan , Changbin Du , giometti@enneenne.com, LKML , syzkaller Subject: Re: Freeing active kobject in pps_device_destruct In-Reply-To: Message-ID: References: <5657DC80.7030007@oracle.com> User-Agent: Alpine 2.11 (DEB 23 2013-08-11) MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII X-Linutronix-Spam-Score: -1.0 X-Linutronix-Spam-Level: - X-Linutronix-Spam-Status: No , -1.0 points, 5.0 required, ALL_TRUSTED=-1,SHORTCIRCUIT=-0.0001,URIBL_BLOCKED=0.001 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Sat, 25 Jun 2016, Vegard Nossum wrote: > On 27 November 2015 at 05:30, Sasha Levin wrote: > > (active state 0) object type: timer_list hint: delayed_work_timer_fn+0x0/0x90 > > [ 1167.394563] Workqueue: events kobject_delayed_cleanup > > [ 1167.410301] [] kfree+0x1fc/0x2f0 > > [ 1167.410734] [] pps_device_destruct+0x107/0x110 > > [ 1167.413495] [] kobject_delayed_cleanup+0x34d/0x3b0 > > [ 1167.414049] [] process_one_work+0xab7/0x13b0 > > [ 1167.417188] [] worker_thread+0x93d/0xd20 > > [ 1167.418782] [] kthread+0x290/0x2b0 > > [ 1167.422467] [] ret_from_fork+0x3f/0x70 > ODEBUG: free active (active state 0) object type: timer_list hint: > delayed_work_timer_fn+0x0/0x50 > [] kfree+0x103/0x2f0 > [] disk_release+0x141/0x180 > [] device_release+0x4a/0x100 > [] kobject_delayed_cleanup+0x6c/0xb0 > [] process_one_work+0x46d/0xa60 > [] worker_thread+0x8b/0x730 > [] kthread+0x192/0x1b0 > [] ret_from_fork+0x1f/0x40 > As far as I can tell, it seems like a general problem with > kobject_delayed_cleanup() OR delayed work handling. debugobjects is > complaining about the timer used to delay the work is still "active" > (not as in hasn't fired but as in not destroyed) when disk_release() State active means: The timer is queued and has not yet fired. Which is completely confusing because the delayed work will only be processed after the timer has fired. And when the timer fires it is deactivated in debug objects before the callback function is invoked. So it's really puzzling why the debug objects state of the timer would be ODEBUG_STATE_ACTIVE, which is the only way that the debug objects free check can trigger. Confused! tglx