From: Linus Torvalds <torvalds@linux-foundation.org>
To: Thomas Gleixner <tglx@linutronix.de>
Cc: Andrew Morton <akpm@linux-foundation.org>,
LKML <linux-kernel@vger.kernel.org>, Ingo Molnar <mingo@elte.hu>
Subject: Re: [GIT pull] genirq fixes for 2.6.31
Date: Thu, 13 Aug 2009 12:24:18 -0700 (PDT) [thread overview]
Message-ID: <alpine.LFD.2.01.0908131211550.28882@localhost.localdomain> (raw)
In-Reply-To: <alpine.LFD.2.00.0908132100210.1283@localhost.localdomain>
On Thu, 13 Aug 2009, Thomas Gleixner wrote:
>
> Please pull the latest irq-fixes-for-linus git tree from:
>
> git://git.kernel.org/pub/scm/linux/kernel/git/tip/linux-2.6-tip.git irq-fixes-for-linus
Not without lots more explanations - or at least _fixed_ explanations.
> Thomas Gleixner (1):
> genirq: Prevent race between free_irq() and handle_IRQ_event()
>
>
> kernel/irq/handle.c | 10 +++++++++-
> 1 files changed, 9 insertions(+), 1 deletions(-)
>
> diff --git a/kernel/irq/handle.c b/kernel/irq/handle.c
> index 065205b..4e7f17a 100644
> --- a/kernel/irq/handle.c
> +++ b/kernel/irq/handle.c
> @@ -403,8 +403,16 @@ irqreturn_t handle_IRQ_event(unsigned int irq, struct irqaction *action)
> */
> if (likely(!test_bit(IRQTF_DIED,
> &action->thread_flags))) {
> + struct task_struct *tsk = action->thread;
> +
> set_bit(IRQTF_RUNTHREAD, &action->thread_flags);
> - wake_up_process(action->thread);
> + /*
> + * Check tsk as we might race against
> + * free_irq which sets action->thread
> + * to NULL
> + */
> + if (tsk)
> + wake_up_process(tsk);
Seriously, this looks entirely bogus.
The thing is, if "action" has been free'd, then dammit, 'tsk' is gone too.
In fact, just look at _free_irq(), and realise how it does the
if (irqthread) {
if (!test_bit(IRQTF_DIED, &action->thread_flags))
kthread_stop(irqthread);
put_task_struct(irqthread);
}
_before_ it free's 'action'. So what does that fix?
There is no race that I can see - we're holding "action->lock" while all
this happens.
Now, I can see a bug, which is that "action->tsk" may have been set to
NULL. But I can't see a race, and I can't see a reason for all the code
movement. So quite frankly, I think the comments (both in the code and in
the commit message) are just wrong. And the odd "load it first, then do
other things" code looks confused.
So why is this not just a
if (action->thread)
wake_up_process(action->thread);
with appropriate comments?
Or, alternatively, just move all the "clear action->thread" in free_irq()
to after having done the "synchronize_irq()" thing, and then - afaik -
you'll not need that test at all, because you're guaranteed that as long
as you're in an interrupt handler, the thing shouldn't be cleared.
No?
Linus
next prev parent reply other threads:[~2009-08-13 19:25 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-08-13 19:02 Thomas Gleixner
2009-08-13 19:24 ` Linus Torvalds [this message]
2009-08-13 19:52 ` Thomas Gleixner
2009-08-13 19:59 ` Thomas Gleixner
2009-08-13 20:05 ` Linus Torvalds
2009-08-13 20:24 ` Thomas Gleixner
-- strict thread matches above, loose matches on Subject: below --
2009-07-22 14:56 Thomas Gleixner
2009-07-22 23:28 ` Kevin Winchester
2009-07-22 23:33 ` Kevin Winchester
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=alpine.LFD.2.01.0908131211550.28882@localhost.localdomain \
--to=torvalds@linux-foundation.org \
--cc=akpm@linux-foundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@elte.hu \
--cc=tglx@linutronix.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome