From: Gabriel Krisman Bertazi <krisman@suse.de>
To: Vishnu Razdan via B4 Relay
<devnull+vrazdan.openai.com@kernel.org>,
axboe@kernel.dk
Cc: io-uring@vger.kernel.org, vrazdan@openai.com,
linux-kernel@vger.kernel.org, asml.silence@gmail.com
Subject: Re: [PATCH] io_uring/io-wq: fix worker accounting when canceling creation callbacks
Date: Tue, 11 Aug 2026 13:02:07 -0400 [thread overview]
Message-ID: <87mruspp4g.fsf@mailhost.krisman.be> (raw)
In-Reply-To: <20260811-vrazdan-io-wq-b4-submit-v1-1-719ced16c921@openai.com>
Vishnu Razdan via B4 Relay <devnull+vrazdan.openai.com@kernel.org>
writes:
> From: Vishnu Razdan <vrazdan@openai.com>
>
> create_worker_cb() reserves an io-wq worker slot only after its
> task-work callback runs. If the callback is canceled before then,
> io_worker_cancel_cb() still decrements acct->nr_workers. When an
> existing worker retires with its creation callback pending, that
> worker has already decremented the same account's worker count.
>
> The resulting undercount permits worker creation beyond the account's
> configured limit. On an AST2600 OpenBMC system, an unchanged sensor
> daemon reached 4,291 threads with the original kernel. With an
> equivalent downstream fix, 25 passive samples under its normal
> workload showed 6-9 threads.
>
> Decrement nr_workers only when the canceled callback is not
> create_worker_cb(). Continuation callbacks still release their reserved
> slot, and both callback types retain the existing running-count,
> reference-count, and create-state cleanup.
>
> Fixes: 1d5f5ea7cb7d ("io-wq: remove worker to owner tw dependency")
> Cc: stable@vger.kernel.org
> Assisted-by: Codex:gpt-5.6-sol
> Signed-off-by: Vishnu Razdan <vrazdan@openai.com>
> ---
Reviewed-by: Gabriel Krisman Bertazi <krisman@suse.de>
> Prevent unreserved worker-creation callbacks from decrementing the worker count.
> ---
> io_uring/io-wq.c | 9 ++++++---
> 1 file changed, 6 insertions(+), 3 deletions(-)
>
> diff --git a/io_uring/io-wq.c b/io_uring/io-wq.c
> index 2e14880ee..fa403ed24 100644
> --- a/io_uring/io-wq.c
> +++ b/io_uring/io-wq.c
> @@ -211,9 +211,12 @@ static void io_worker_cancel_cb(struct io_worker *worker)
> struct io_wq *wq = worker->wq;
>
> atomic_dec(&acct->nr_running);
> - raw_spin_lock(&acct->workers_lock);
> - acct->nr_workers--;
> - raw_spin_unlock(&acct->workers_lock);
> + /* create_worker_cb() has not reserved a worker slot yet. */
> + if (worker->create_work.func != create_worker_cb) {
> + raw_spin_lock(&acct->workers_lock);
> + acct->nr_workers--;
> + raw_spin_unlock(&acct->workers_lock);
> + }
> io_worker_ref_put(wq);
> clear_bit_unlock(0, &worker->create_state);
> io_worker_release(worker);
>
> ---
> base-commit: d58772d8520c7ef247c4b95c9bd76d3a25da9ff5
> change-id: 20260810-vrazdan-io-wq-b4-submit-9c94df145718
>
> Best regards,
> --
> Vishnu Razdan <vrazdan@openai.com>
>
>
--
Gabriel Krisman Bertazi
prev parent reply other threads:[~2026-08-11 17:02 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-11 7:01 [PATCH] io_uring/io-wq: fix worker accounting when canceling creation callbacks Vishnu Razdan via B4 Relay
2026-08-11 17:02 ` Gabriel Krisman Bertazi [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87mruspp4g.fsf@mailhost.krisman.be \
--to=krisman@suse.de \
--cc=asml.silence@gmail.com \
--cc=axboe@kernel.dk \
--cc=devnull+vrazdan.openai.com@kernel.org \
--cc=io-uring@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=vrazdan@openai.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox