Received: by 2002:a05:6a10:413:0:0:0:0 with SMTP id 19csp1763768pxp; Mon, 7 Mar 2022 01:44:28 -0800 (PST) X-Google-Smtp-Source: ABdhPJxjIAXFgqIQwC1ncJBtRAq1nBVMvqLJFSfdIea8xkLyMX+MiP3AU4Ibf6w+My8Zi456FOZw X-Received: by 2002:a05:6402:440b:b0:415:c50d:853b with SMTP id y11-20020a056402440b00b00415c50d853bmr10189430eda.346.1646646267849; Mon, 07 Mar 2022 01:44:27 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1646646267; cv=none; d=google.com; s=arc-20160816; b=tY4q8DqMM2Uqo18qn5Q57LDt0aPjm1Yunu6OlvXGIhDDi4dsRJ4rJoeyVsME/5O/zG zjHrI+xfY0RGP64zBYbJ5KZmvcbrhIl2mgMxFu1CSUeUOzleLysx02NKbpHDLfI22gD6 wfneUm2g3Xm9Fk+kmEUp/HUlc98WQfVa1gBt00S8g8BVBU2FVDNeZlD16Jd7RYsu5tWD CknzuX5I2a2onddJxR7mZuQSUyGIypLFeWPSuzL5GAfx3aejQL6a3rVjpy8GrePqIQzZ AU7YQtbb7j2Vz/TGpW1BJBiuvWFEYW+AMdcHI7hjpZE50cbEb/Rka0/9gdHPllP6FH07 Xk0g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:mime-version:user-agent:references:in-reply-to :subject:cc:to:from:message-id:date:dkim-signature:dkim-signature; bh=ODYQkIzrW67UKhaDilLjCn994IjpCUyWTB8wXc1WOVc=; b=mXLXcHPhiQM1Z+airlcoxZJPhr8lf2aNZwKh8ejqptyVUj8q2fYjEhfHaNuvzrPmvd wl/jK6SEz2bn1MdDNa0RNEGKm+JbbNEohzqlny04Eg8CeNROw0tjQuCh2H9J1UhlCrCa 9hsMDY31vNKzCpdD30m3ig9iIvgxo20Gh+x+HCyZL0KmBmfesbPogrE/rjzr0faKkax4 TB7BF7PBaJJ5pN2L6RdDYBbIbJRuRKhzttz4foj93dY1RwmFqa/3QOvVzu8mMHeDepYk kC1GMhYF8nnML1jzP7KHg4/nySvJmQLXq+rXUz6XHHjwkzaDO5UeI2UJqy5ECADTuImt PcIg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@suse.de header.s=susede2_rsa header.b=ol+gn0so; dkim=neutral (no key) header.i=@suse.de header.s=susede2_ed25519 header.b=wd0H1Wot; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=suse.de Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id p4-20020a05640243c400b00413b7789b53si7220063edc.531.2022.03.07.01.44.05; Mon, 07 Mar 2022 01:44:27 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@suse.de header.s=susede2_rsa header.b=ol+gn0so; dkim=neutral (no key) header.i=@suse.de header.s=susede2_ed25519 header.b=wd0H1Wot; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=suse.de Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S236148AbiCGIcP (ORCPT + 99 others); Mon, 7 Mar 2022 03:32:15 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:47772 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S236161AbiCGIcL (ORCPT ); Mon, 7 Mar 2022 03:32:11 -0500 Received: from smtp-out2.suse.de (smtp-out2.suse.de [195.135.220.29]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id B991562A0D for ; Mon, 7 Mar 2022 00:31:17 -0800 (PST) Received: from relay2.suse.de (relay2.suse.de [149.44.160.134]) by smtp-out2.suse.de (Postfix) with ESMTP id 6AAB61F38E; Mon, 7 Mar 2022 08:31:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_rsa; t=1646641876; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=ODYQkIzrW67UKhaDilLjCn994IjpCUyWTB8wXc1WOVc=; b=ol+gn0so01KDiKkfiN/jbU72CMraXTJlZEckaq2G2FwP6WQ6AHPkFBd7jefHSTpfN/Ev8i eesiSMTcK22H6gMsj7v/w99PS2IXLTbMTVg+JQHBxp9bDMI2Fvs7t2eN/vNdUNt60IRGkc +/T7iZrjEq/nSU6XQwMGFqW9NS6nNIc= DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=suse.de; s=susede2_ed25519; t=1646641876; h=from:from:reply-to:date:date:message-id:message-id:to:to:cc:cc: mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=ODYQkIzrW67UKhaDilLjCn994IjpCUyWTB8wXc1WOVc=; b=wd0H1WotfzzbWJfNNy4pFPQkwBF3B0QuaXDa+aP8hz1Xtk+gen6jzXRHvdpTr0y1THZYLv IPaYpuuy8V8DWUCg== Received: from alsa1.suse.de (alsa1.suse.de [10.160.4.42]) by relay2.suse.de (Postfix) with ESMTP id 5880BA3B8A; Mon, 7 Mar 2022 08:31:16 +0000 (UTC) Date: Mon, 07 Mar 2022 09:31:16 +0100 Message-ID: From: Takashi Iwai To: Hillf Danton Cc: syzbot , alsa-devel@alsa-project.org, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com, tiwai@suse.com Subject: Re: [syzbot] possible deadlock in snd_timer_interrupt (2) In-Reply-To: <20220307080520.3199-1-hdanton@sina.com> References: <00000000000048c71405d96594c7@google.com> <20220307080520.3199-1-hdanton@sina.com> User-Agent: Wanderlust/2.15.9 (Almost Unreal) SEMI/1.14.6 (Maruoka) FLIM/1.14.9 (=?UTF-8?B?R29qxY0=?=) APEL/10.8 Emacs/25.3 (x86_64-suse-linux-gnu) MULE/6.0 (HANACHIRUSATO) MIME-Version: 1.0 (generated by SEMI 1.14.6 - "Maruoka") Content-Type: text/plain; charset=US-ASCII X-Spam-Status: No, score=-4.4 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_MED,SPF_HELO_NONE, SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, 07 Mar 2022 09:05:20 +0100, Hillf Danton wrote: > > Walk around the deadlock by trying to lock tasklist_lock for write on > timer irq and scheduling workqueue work if any lock owner detected. Oh no, that's toooo ugly. And the problem isn't only here; take a look at commits f671a691e299 and 2f488f698fda. There are other users of kill_fasync() with the hard-IRQ disabled, too. So, IMO, the handling of tasklist_lock around kill_fasync() looks broken and the fix should be needed there (or other core part), instead of messing round each caller's code. thanks, Takashi > > Only for thoughts now. > > Hillf > > #syz test: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/ 38f80f42147f > > --- x/sound/core/timer.c > +++ y/sound/core/timer.c > @@ -916,7 +916,14 @@ void snd_timer_interrupt(struct snd_time > } > > /* now process all fast callbacks */ > - snd_timer_process_callbacks(timer, &timer->ack_list_head); > + if (write_trylock(&tasklist_lock)) { > + write_unlock(&tasklist_lock); > + snd_timer_process_callbacks(timer, &timer->ack_list_head); > + } else { > + /* go the slow path to avoid deadlock by calling kill_fasync() */ > + list_splice_init(&timer->ack_list_head, > + &timer->sack_list_head); > + } > > /* do we have any slow callbacks? */ > use_work = !list_empty(&timer->sack_list_head); > -- >