Received: by 2002:a25:5b86:0:0:0:0:0 with SMTP id p128csp1768237ybb; Fri, 29 Mar 2019 10:55:31 -0700 (PDT) X-Google-Smtp-Source: APXvYqy1wet89loE28C8RfJa+qbB16l/fSUHywtcyb2SfO9OP05pYODXESa0NWqnfUYZt+Lkc3eM X-Received: by 2002:a63:f310:: with SMTP id l16mr46393210pgh.72.1553882131354; Fri, 29 Mar 2019 10:55:31 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1553882131; cv=none; d=google.com; s=arc-20160816; b=Vzt4cs7xshGUrhmFUXnQYjuixxjNOi+6VAOiLRVpaFO9j6v32ZlQ/s809yrWxf2gM7 R3OfUMK/FXknUSP1Vvei7nlbBSGYlDSWWKq0nath/2zriLkTakD+jVc6XZgyBUzc6bKv AFY2qJj40PR7tn3Fc2ww+pssggJJBHW1W9lno+K0frLQFfXqy2/4108FgnHl0e7avC1j W3RD67sdV6yDaukXJsLfsaVtfCB1vnZLHJInH9yAuDE2OsPWvWifU3aSAU32tN3/NrW9 oPSaR0krQa2Nvx0FmDunaANzghIxO88FLVSLjK9vxe+jgCEwsH3V6451vNFViqcvU+tT 880g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-language :content-transfer-encoding:in-reply-to:mime-version:user-agent:date :message-id:organization:autocrypt:openpgp:from:references:to :subject; bh=0nF1ST5eaCqXYslNX5eZ9FJ4YCzhi/4wy7CdS5ycCjI=; b=NfdVYDWFyT+ahLVFofmcOJZB8UN16Ugn0EsogIJ7S7PGWbvf2F5c1+uizY0C6YYiIl xBS3SF4Dvgl+EdESXptbWYNB51TXuKoUUNpaTXzHLOTNbGTR8Tx8vzkoVQTJAczQJ3t5 Ejwzbt+JIqwJMPV0D4FCfLAUNofn+3BrWG8wp6t47+2bhsI5eOD9pHL8suszx/2wUa1g QHVV4ZOthN1zQ9GIcZucBi7+q/udmI10T09GsjQg/ougFwEErdEDus52GxFGRwgKxetE xJpErwSk1FdoVmK/0KqRcHjCOlDAcTAofgtlHrvK+q2jL9LhIHfUJJsIiL421TJwTzqO OUTw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=redhat.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id r184si2263188pgr.24.2019.03.29.10.55.16; Fri, 29 Mar 2019 10:55:31 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=redhat.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1729904AbfC2RxZ convert rfc822-to-8bit (ORCPT + 99 others); Fri, 29 Mar 2019 13:53:25 -0400 Received: from mx1.redhat.com ([209.132.183.28]:45936 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1729650AbfC2RxY (ORCPT ); Fri, 29 Mar 2019 13:53:24 -0400 Received: from smtp.corp.redhat.com (int-mx03.intmail.prod.int.phx2.redhat.com [10.5.11.13]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id F1D55307D914; Fri, 29 Mar 2019 17:53:23 +0000 (UTC) Received: from llong.remote.csb (dhcp-17-19.bos.redhat.com [10.18.17.19]) by smtp.corp.redhat.com (Postfix) with ESMTP id 1190C17AD8; Fri, 29 Mar 2019 17:53:22 +0000 (UTC) Subject: Re: fs/coda oops bisected to (925b9cd1b8) "locking/rwsem: Make owner store task pointer of last owning reader" To: Ingo Molnar , Peter Zijlstra , Alexander Viro , Pedro Cuadra Chamorro , linux-kernel@vger.kernel.org References: <20190329161014.ri4hzemg3ibvjw46@cs.cmu.edu> From: Waiman Long Openpgp: preference=signencrypt Autocrypt: addr=longman@redhat.com; prefer-encrypt=mutual; keydata= xsFNBFgsZGsBEAC3l/RVYISY3M0SznCZOv8aWc/bsAgif1H8h0WPDrHnwt1jfFTB26EzhRea XQKAJiZbjnTotxXq1JVaWxJcNJL7crruYeFdv7WUJqJzFgHnNM/upZuGsDIJHyqBHWK5X9ZO jRyfqV/i3Ll7VIZobcRLbTfEJgyLTAHn2Ipcpt8mRg2cck2sC9+RMi45Epweu7pKjfrF8JUY r71uif2ThpN8vGpn+FKbERFt4hW2dV/3awVckxxHXNrQYIB3I/G6mUdEZ9yrVrAfLw5M3fVU CRnC6fbroC6/ztD40lyTQWbCqGERVEwHFYYoxrcGa8AzMXN9CN7bleHmKZrGxDFWbg4877zX 0YaLRypme4K0ULbnNVRQcSZ9UalTvAzjpyWnlnXCLnFjzhV7qsjozloLTkZjyHimSc3yllH7 VvP/lGHnqUk7xDymgRHNNn0wWPuOpR97J/r7V1mSMZlni/FVTQTRu87aQRYu3nKhcNJ47TGY evz/U0ltaZEU41t7WGBnC7RlxYtdXziEn5fC8b1JfqiP0OJVQfdIMVIbEw1turVouTovUA39 Qqa6Pd1oYTw+Bdm1tkx7di73qB3x4pJoC8ZRfEmPqSpmu42sijWSBUgYJwsziTW2SBi4hRjU h/Tm0NuU1/R1bgv/EzoXjgOM4ZlSu6Pv7ICpELdWSrvkXJIuIwARAQABzR9Mb25nbWFuIExv bmcgPGxsb25nQHJlZGhhdC5jb20+wsF/BBMBAgApBQJYLGRrAhsjBQkJZgGABwsJCAcDAgEG FQgCCQoLBBYCAwECHgECF4AACgkQbjBXZE7vHeYwBA//ZYxi4I/4KVrqc6oodVfwPnOVxvyY oKZGPXZXAa3swtPGmRFc8kGyIMZpVTqGJYGD9ZDezxpWIkVQDnKM9zw/qGarUVKzElGHcuFN ddtwX64yxDhA+3Og8MTy8+8ZucM4oNsbM9Dx171bFnHjWSka8o6qhK5siBAf9WXcPNogUk4S fMNYKxexcUayv750GK5E8RouG0DrjtIMYVJwu+p3X1bRHHDoieVfE1i380YydPd7mXa7FrRl 7unTlrxUyJSiBc83HgKCdFC8+ggmRVisbs+1clMsK++ehz08dmGlbQD8Fv2VK5KR2+QXYLU0 rRQjXk/gJ8wcMasuUcywnj8dqqO3kIS1EfshrfR/xCNSREcv2fwHvfJjprpoE9tiL1qP7Jrq 4tUYazErOEQJcE8Qm3fioh40w8YrGGYEGNA4do/jaHXm1iB9rShXE2jnmy3ttdAh3M8W2OMK 4B/Rlr+Awr2NlVdvEF7iL70kO+aZeOu20Lq6mx4Kvq/WyjZg8g+vYGCExZ7sd8xpncBSl7b3 99AIyT55HaJjrs5F3Rl8dAklaDyzXviwcxs+gSYvRCr6AMzevmfWbAILN9i1ZkfbnqVdpaag QmWlmPuKzqKhJP+OMYSgYnpd/vu5FBbc+eXpuhydKqtUVOWjtp5hAERNnSpD87i1TilshFQm TFxHDzbOwU0EWCxkawEQALAcdzzKsZbcdSi1kgjfce9AMjyxkkZxcGc6Rhwvt78d66qIFK9D Y9wfcZBpuFY/AcKEqjTo4FZ5LCa7/dXNwOXOdB1Jfp54OFUqiYUJFymFKInHQYlmoES9EJEU yy+2ipzy5yGbLh3ZqAXyZCTmUKBU7oz/waN7ynEP0S0DqdWgJnpEiFjFN4/ovf9uveUnjzB6 lzd0BDckLU4dL7aqe2ROIHyG3zaBMuPo66pN3njEr7IcyAL6aK/IyRrwLXoxLMQW7YQmFPSw drATP3WO0x8UGaXlGMVcaeUBMJlqTyN4Swr2BbqBcEGAMPjFCm6MjAPv68h5hEoB9zvIg+fq M1/Gs4D8H8kUjOEOYtmVQ5RZQschPJle95BzNwE3Y48ZH5zewgU7ByVJKSgJ9HDhwX8Ryuia 79r86qZeFjXOUXZjjWdFDKl5vaiRbNWCpuSG1R1Tm8o/rd2NZ6l8LgcK9UcpWorrPknbE/pm MUeZ2d3ss5G5Vbb0bYVFRtYQiCCfHAQHO6uNtA9IztkuMpMRQDUiDoApHwYUY5Dqasu4ZDJk bZ8lC6qc2NXauOWMDw43z9He7k6LnYm/evcD+0+YebxNsorEiWDgIW8Q/E+h6RMS9kW3Rv1N qd2nFfiC8+p9I/KLcbV33tMhF1+dOgyiL4bcYeR351pnyXBPA66ldNWvABEBAAHCwWUEGAEC AA8FAlgsZGsCGwwFCQlmAYAACgkQbjBXZE7vHeYxSQ/+PnnPrOkKHDHQew8Pq9w2RAOO8gMg 9Ty4L54CsTf21Mqc6GXj6LN3WbQta7CVA0bKeq0+WnmsZ9jkTNh8lJp0/RnZkSUsDT9Tza9r GB0svZnBJMFJgSMfmwa3cBttCh+vqDV3ZIVSG54nPmGfUQMFPlDHccjWIvTvyY3a9SLeamaR jOGye8MQAlAD40fTWK2no6L1b8abGtziTkNh68zfu3wjQkXk4kA4zHroE61PpS3oMD4AyI9L 7A4Zv0Cvs2MhYQ4Qbbmafr+NOhzuunm5CoaRi+762+c508TqgRqH8W1htZCzab0pXHRfywtv 0P+BMT7vN2uMBdhr8c0b/hoGqBTenOmFt71tAyyGcPgI3f7DUxy+cv3GzenWjrvf3uFpxYx4 yFQkUcu06wa61nCdxXU/BWFItryAGGdh2fFXnIYP8NZfdA+zmpymJXDQeMsAEHS0BLTVQ3+M 7W5Ak8p9V+bFMtteBgoM23bskH6mgOAw6Cj/USW4cAJ8b++9zE0/4Bv4iaY5bcsL+h7TqQBH Lk1eByJeVooUa/mqa2UdVJalc8B9NrAnLiyRsg72Nurwzvknv7anSgIkL+doXDaG21DgCYTD wGA5uquIgb8p3/ENgYpDPrsZ72CxVC2NEJjJwwnRBStjJOGQX4lV1uhN1XsZjBbRHdKF2W9g weim8xU= Organization: Red Hat Message-ID: <03bdbcb2-2ed7-1c0a-3c70-89c5c2e582f3@redhat.com> Date: Fri, 29 Mar 2019 13:53:22 -0400 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.9.1 MIME-Version: 1.0 In-Reply-To: <20190329161014.ri4hzemg3ibvjw46@cs.cmu.edu> Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8BIT Content-Language: en-US X-Scanned-By: MIMEDefang 2.79 on 10.5.11.13 X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.48]); Fri, 29 Mar 2019 17:53:24 +0000 (UTC) Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 03/29/2019 12:10 PM, Jan Harkes wrote: > I was testing Coda on the 5.1-rc2 kernel and noticed that when I run a > binary out of /coda, the binary would never exit and the system would > detect a soft lockup. I narrowed it down to a very simple reproducible > case of running a statically linked executable (busybox) from /coda with > the cwd outside of Coda, so the only Coda file reference is from the > executable itself. > > I knew I definitely had never seen this problem with the stable kernel > on Ubuntu xenial (4.4) so I bisected between v4.4 and v5.1-rc2 and ended > up at > > # first bad commit: [925b9cd1b89a94b7124d128c80dfc48f78a63098] > # locking/rwsem: Make owner store task pointer of last owning reader > > When I revert this particular commit on 5.1-rc2, I am not able to > reproduce the problem anymore. > > The puzzling thing to me is that a lot of that particular patch touches > codepaths that are not even enabled in the kernels that I run, because I > do not have CONFIG_RWSEM_DEBUG enabled. > > $ grep RWSEM .config > CONFIG_RWSEM_XCHGADD_ALGORITHM=y > CONFIG_RWSEM_SPIN_ON_OWNER=y > # CONFIG_DEBUG_RWSEMS is not set > > And this patch is for rwsem, while my soft lockup is on a spinlock. > So either I have a race in fs/coda that got somehow uncovered by this > patch, or something else is going on here but I have not been able to > figure it out. > > Jan Without CONFIG_DEBUG_RWSEMS, the only behavioral change of this patch is to do an unconditional write of task_structure pointer into sem->owner after acquiring the read lock in down_read(). Before this patch, it does conditional write of 0x1 into sem->owner if it was not 0x1. The only possible scenario that I can think of that can cause the soft lockup you see is use-after-free of memory objects. Cheers, Longman