From: Oleg Nesterov <oleg@redhat.com>
To: "Metzger, Markus T" <markus.t.metzger@intel.com>
Cc: "Kleen, Andi" <andi.kleen@intel.com>, Ingo Molnar <mingo@elte.hu>,
Roland McGrath <roland@redhat.com>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"markus.t.metzger@gmail.com" <markus.t.metzger@gmail.com>
Subject: Re: [rfc] x86, bts: fix crash
Date: Fri, 27 Mar 2009 17:50:38 +0100 [thread overview]
Message-ID: <20090327165038.GA25762@redhat.com> (raw)
In-Reply-To: <928CFBE8E7CB0040959E56B4EA41A77E9266B699@irsmsx504.ger.corp.intel.com>
On 03/27, Metzger, Markus T wrote:
>
> >> @@ -752,6 +752,14 @@ void ds_release_bts(struct bts_tracer *t
> >>
> >> ds_suspend_bts(tracer);
> >>
> >> + /*
> >> + * We must wait for the suspend to take effect before we may
> >> + * free the tracer and the ds configuration.
> >> + */
> >> + if (tracer->ds.context->task &&
> >> + (tracer->ds.context->task != current))
> >> + wait_task_inactive(tracer->ds.context->task, 0);
> >
> >I am not sure I understand the problem. From the changelog:
> >
> > If the children are currently executing, the buffer
> > may be freed while the hardware is still tracing.
> > This might cause the hardware to overwrite memory.
> >
> >So, the problem is that ds.context->task must not be running before we
> >can start to disable/free ds, yes? Something like ds_switch_to() should
> >be completed, right?
> >
> >In that case I don't really understand how wait_task_inactive() can help.
> >If the task is killed it can be scheduled again, right after
> >wait_task_inactive() returns.
>
> We first call ds_suspend_bts().
> This clears the branch tracing control bits for the traced task and already
> writes the updated value to the msr, if running on the current cpu.
> If the task is running on a different cpu, the updated value will be written
> when the task is scheduled out.
> By waiting for the task to become inactive, we know that it has been scheduled out
> at least once after we changed the bits. So we know that the hardware will not use
> the tracing configuration for that task and we can safely free the memory.
Still can't understand...
Let's suppose the traced task is scheduled again, right after
wait_task_inactive() returns a before we set ds.context->bts_master = NULL.
In this case, can't ds_switch_to() (which plays with ds_context) race
with ds_put_context()->kfree(context) ?
> >Also. This function is called from ptrace_bts_exit_tracer(), when the
> >tracee is not stopped. In this case wait_task_inactive() can spin forever.
> >For example, if the tracee simply does "for (;;) ;" it never succeeds.
>
> As far as I understand, wait_task_inactive() returns when the task is scheduled out.
Yes. But the task does above is never scheduled out, it is always running
even if preempted by another task. wait_task_inactive() returns when
->on_rq == 0, iow when the task sleeps.
This means that the tracer can hang "forever" during exit, until the tracee
does the blocking syscall or exits.
This is not acceptable, imho.
Oleg.
next prev parent reply other threads:[~2009-03-27 16:54 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <928CFBE8E7CB0040959E56B4EA41A77E9260843D@irsmsx504.ger.corp.intel.com>
2009-03-26 1:58 ` [rfc] x86, bts: fix crash Oleg Nesterov
2009-03-27 15:01 ` Metzger, Markus T
2009-03-27 16:50 ` Oleg Nesterov [this message]
2009-03-27 17:33 ` Markus Metzger
2009-03-27 21:29 ` Oleg Nesterov
2009-03-30 7:24 ` Metzger, Markus T
2009-03-30 11:29 ` Metzger, Markus T
2009-03-30 13:29 ` Oleg Nesterov
2009-03-30 13:55 ` Metzger, Markus T
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20090327165038.GA25762@redhat.com \
--to=oleg@redhat.com \
--cc=andi.kleen@intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=markus.t.metzger@gmail.com \
--cc=markus.t.metzger@intel.com \
--cc=mingo@elte.hu \
--cc=roland@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox