| From 0e217c289cf4c7599bcc7aa323b97c86e03118d8 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Fri, 1 May 2020 08:52:56 +0800 |
| Subject: io_uring: use cond_resched() in io_ring_ctx_wait_and_kill() |
| |
| From: Xiaoguang Wang <xiaoguang.wang@linux.alibaba.com> |
| |
| [ Upstream commit 3fd44c86711f71156b586c22b0495c58f69358bb ] |
| |
| While working on to make io_uring sqpoll mode support syscalls that need |
| struct files_struct, I got cpu soft lockup in io_ring_ctx_wait_and_kill(), |
| |
| while (ctx->sqo_thread && !wq_has_sleeper(&ctx->sqo_wait)) |
| cpu_relax(); |
| |
| above loop never has an chance to exit, it's because preempt isn't enabled |
| in the kernel, and the context calling io_ring_ctx_wait_and_kill() and |
| io_sq_thread() run in the same cpu, if io_sq_thread calls a cond_resched() |
| yield cpu and another context enters above loop, then io_sq_thread() will |
| always in runqueue and never exit. |
| |
| Use cond_resched() can fix this issue. |
| |
| Reported-by: syzbot+66243bb7126c410cefe6@syzkaller.appspotmail.com |
| Signed-off-by: Xiaoguang Wang <xiaoguang.wang@linux.alibaba.com> |
| Signed-off-by: Jens Axboe <axboe@kernel.dk> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| fs/io_uring.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| diff --git a/fs/io_uring.c b/fs/io_uring.c |
| index 9690c845a3e4b..01f71b9efb88f 100644 |
| --- a/fs/io_uring.c |
| +++ b/fs/io_uring.c |
| @@ -6451,7 +6451,7 @@ static void io_ring_ctx_wait_and_kill(struct io_ring_ctx *ctx) |
| * it could cause shutdown to hang. |
| */ |
| while (ctx->sqo_thread && !wq_has_sleeper(&ctx->sqo_wait)) |
| - cpu_relax(); |
| + cond_resched(); |
| |
| io_kill_timeouts(ctx); |
| io_poll_remove_all(ctx); |
| -- |
| 2.20.1 |
| |