The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: "Paul E. McKenney" <paulmck@kernel.org>
To: rcu@vger.kernel.org
Cc: linux-kernel@vger.kernel.org, kernel-team@meta.com,
	rostedt@goodmis.org, Joel Fernandes <joelagnelf@nvidia.com>,
	"Paul E . McKenney" <paulmck@kernel.org>
Subject: [PATCH RFC 06/16] rcu: clear defer_qs_pending in deferred-QS bail when nesting > 0
Date: Thu, 30 Jul 2026 18:01:43 -0700	[thread overview]
Message-ID: <20260731010153.3531313-6-paulmck@kernel.org> (raw)
In-Reply-To: <9de287bc-e565-4f21-bd3c-5c17792e6abc@paulmck-laptop>

From: Joel Fernandes <joelagnelf@nvidia.com>

Paul McKenney noted that a softirq (or irq_work) handler arming for a
deferred QS can fire and find rcu_preempt_depth() > 0 -- the task is
still inside its outer reader, so rcu_preempt_need_deferred_qs() bails
without reporting the QS.  At that point the queued mechanism has been
consumed but ->defer_qs_pending stays in DEFER_QS_PENDING.

In the meantime, the only remaining path back to a quiescent state on
this CPU may be a local_irq_disable()/_enable() pair that does not
call preempt_check_resched() (it is just `sti`/`cli`).  patch 6's
unconditional set_need_resched_current() makes need_resched true, but
without an irq_work being raised the next outer rcu_read_unlock_special()
hits the P-gate at the arming code:

    if (rdp->defer_qs_pending != DEFER_QS_PENDING) {
        rdp->defer_qs_pending = DEFER_QS_PENDING;
        irq_work_queue_on(...);                 // <-- skipped
    }

so no irq_work is queued for the hardirq-exit preempt_schedule_irq()
path either.  The deferred QS now waits until the next timer tick (or
similar preempt-safe boundary), needlessly extending expedited grace
period latency.

Clear ->defer_qs_pending in the bail-out path of rcu_preempt_deferred_qs()
when rcu_preempt_depth() > 0.  The recursion guard semantics introduced
by commit b41642c87716 ("rcu: Fix rcu_read_unlock() deadloop due to IRQ
work").

The clear is also safe against fresh recursion at this exact program
point: rcu_preempt_depth() > 0 guarantees we are still inside an outer
reader, so any inner rcu_read_unlock() from tracing infrastructure
brings nesting back to outer (>0), never to 0.  The slow path of
rcu_read_unlock_special() is structurally unreachable under that
condition, so no recursive raise_softirq_irqoff()/irq_work_queue_on()
can be triggered by the clear. Essentially, the mechanism will work to
prevent the following recursion which Xiongfeng had previously reported:

irq_exit() -> __irq_exit_rcu()
  -> tick_irq_exit() -> tick_nohz_irq_exit() -> tick_nohz_stop_sched_tick()
    -> trace_tick_stop()                    // BPF prog hooked here
      -> rcu_read_unlock_special()
        -> irq_work_queue_on(&rdp->defer_qs_iw, rdp->cpu)   // self-IPI re-enters irq_exit

Reported-by: Paul E. McKenney <paulmck@kernel.org>
Signed-off-by: Joel Fernandes <joelagnelf@nvidia.com>
Signed-off-by: Paul E. McKenney <paulmck@kernel.org>
---
 kernel/rcu/tree_plugin.h | 28 +++++++++++++++++++++++++++-
 1 file changed, 27 insertions(+), 1 deletion(-)

diff --git a/kernel/rcu/tree_plugin.h b/kernel/rcu/tree_plugin.h
index 8637f405cb472f..9ba136a4233a26 100644
--- a/kernel/rcu/tree_plugin.h
+++ b/kernel/rcu/tree_plugin.h
@@ -614,9 +614,35 @@ static notrace bool rcu_preempt_need_deferred_qs(struct task_struct *t)
 notrace void rcu_preempt_deferred_qs(struct task_struct *t)
 {
 	unsigned long flags;
+	struct rcu_data *rdp;
 
-	if (!rcu_preempt_need_deferred_qs(t))
+	if (!rcu_preempt_need_deferred_qs(t)) {
+		/*
+		 * If we got here from a softirq/irq_work that fired while
+		 * rcu_preempt_depth() > 0, the deferred-QS mechanism has been
+		 * consumed without doing any work: rcu_preempt_need_deferred_qs()
+		 * just returned false because the task is still in a reader, so
+		 * the actual QS report has to wait for the next
+		 * rcu_read_unlock().
+		 *
+		 * Clear ->defer_qs_pending here so the next outer
+		 * rcu_read_unlock_special() can re-arm a fresh mechanism (in
+		 * particular the irq_work path, which the local_irq_enable()
+		 * recovery boundary cannot itself reschedule from).
+		 *
+		 * Recursion safety: rcu_preempt_depth() > 0 means we are inside
+		 * an outer reader, so any inner rcu_read_unlock() reached via
+		 * tracing (bpf programs attached to trace points) brings
+		 * nesting to outer (> 0), never to 0, so no recursive
+		 * raise_softirq_irqoff()/irq_work_queue_on() can be triggered
+		 * by this clear.
+		 */
+		if (rcu_preempt_depth() > 0) {
+			rdp = this_cpu_ptr(&rcu_data);
+			rcu_defer_qs_clear(rdp);
+		}
 		return;
+	}
 	local_irq_save(flags);
 	rcu_preempt_deferred_qs_irqrestore(t, flags);
 }
-- 
2.40.1


  parent reply	other threads:[~2026-07-31  1:01 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-16  0:23 [PATCH 0/10] Miscellaneous RCU updates for v7.3 Paul E. McKenney
2026-07-16  0:23 ` [PATCH 01/10] rcu-tasks: TASKS_TRACE_RCU doesn't need IRQ_WORK Paul E. McKenney
2026-07-16  0:23 ` [PATCH 02/10] rcu: Use task_state_to_char() in stall-warning prints Paul E. McKenney
2026-07-16  0:23 ` [PATCH 03/10] rcu: Mark __rcu_access_pointer() as context_unsafe() Paul E. McKenney
2026-07-16  0:23 ` [PATCH 04/10] doc: RCU: Adopt new coding style of type-aware kmalloc-family - part 2/2 Paul E. McKenney
2026-07-16  0:23 ` [PATCH 05/10] rcu-tasks: Remove unused struct rcu_tasks's->n_ipis_fails variables Paul E. McKenney
2026-07-16  0:23 ` [PATCH 06/10] rcu-tasks: Dump rcu tasks status when the boot-test failed Paul E. McKenney
2026-07-16  0:23 ` [PATCH 07/10] doc: RCU: Fix brackets Paul E. McKenney
2026-07-16  0:23 ` [PATCH 08/10] rcu-tasks: Apply READ_ONCE() and WRITE_ONCE() to fix data race Paul E. McKenney
2026-07-16  0:23 ` [PATCH 09/10] rcu-tasks: Remove smp_mb() in rcu_spawn_tasks_kthread_generic() Paul E. McKenney
2026-07-16  0:23 ` [PATCH 10/10] rcu-tasks: Update comments in call_rcu_tasks_generic() Paul E. McKenney
2026-07-31  1:01 ` [PATCH v2 0/16] Miscellaneous RCU updates for v7.3 Paul E. McKenney
2026-07-31  1:01   ` [PATCH RFC 01/16] rcu: Use task_state_to_char() in stall-warning prints Paul E. McKenney
2026-07-31  1:01   ` [PATCH RFC 02/16] rcu: Mark __rcu_access_pointer() as context_unsafe() Paul E. McKenney
2026-07-31  1:01   ` [PATCH RFC 03/16] doc: RCU: Adopt new coding style of type-aware kmalloc-family - part 2/2 Paul E. McKenney
2026-07-31  1:01   ` [PATCH RFC 04/16] doc: RCU: Fix brackets Paul E. McKenney
2026-07-31  1:01   ` [PATCH RFC 05/16] rcu: introduce rcu_defer_qs_clear() helper Paul E. McKenney
2026-07-31  1:01   ` Paul E. McKenney [this message]
2026-07-31  1:01   ` [PATCH RFC 07/16] rcu: Use this_cpu_{read,write}() for ->cpu_no_qs.b.exp Paul E. McKenney
2026-07-31  1:01   ` [PATCH RFC 08/16] rcu: Use WRITE_ONCE() for ->rcu_need_heavy_qs Paul E. McKenney
2026-07-31  1:01   ` [PATCH RFC 09/16] rcu: Remove unused expedited_need_qs field from rcu_state Paul E. McKenney
2026-07-31  1:01   ` [PATCH RFC 10/16] rcu: Remove unused func parameter from callback-enqueue functions Paul E. McKenney
2026-07-31  1:01   ` [PATCH RFC 11/16] rcu: Mark accesses to rdp->rcu_cpu_has_work Paul E. McKenney
2026-07-31  1:01   ` [PATCH RFC 12/16] rcu: Mark interrupts-enabled accesses to rdp->cpu_no_qs.b.norm Paul E. McKenney
2026-07-31  1:01   ` [PATCH RFC 13/16] rcu: Remove unused rdp parameter from rcu_check_gp_start_stall() Paul E. McKenney
2026-07-31  1:01   ` [PATCH RFC 14/16] rcu: Mark accesses to ->rcu_urgent_qs and ->rcu_need_heavy_qs Paul E. McKenney
2026-07-31  1:01   ` [PATCH RFC 15/16] rcu: Reduce stack usage in show_rcu_gp_kthreads() Paul E. McKenney
2026-07-31  1:01   ` [PATCH RFC 16/16] rcu: Mark interrupts-enabled accesses to rdp->cpu_no_qs.s Paul E. McKenney

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260731010153.3531313-6-paulmck@kernel.org \
    --to=paulmck@kernel.org \
    --cc=joelagnelf@nvidia.com \
    --cc=kernel-team@meta.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=rcu@vger.kernel.org \
    --cc=rostedt@goodmis.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox