Revision 6e2df0581f569038719cf2bc2b3baa3fcc83cab4 authored by Peter Zijlstra on 08 November 2019, 10:11:52 UTC, committed by Peter Zijlstra on 08 November 2019, 21:34:14 UTC
Commit 67692435c411 ("sched: Rework pick_next_task() slow-path")
inadvertly introduced a race because it changed a previously
unexplored dependency between dropping the rq->lock and
sched_class::put_prev_task().

The comments about dropping rq->lock, in for example
newidle_balance(), only mentions the task being current and ->on_cpu
being set. But when we look at the 'change' pattern (in for example
sched_setnuma()):

	queued = task_on_rq_queued(p); /* p->on_rq == TASK_ON_RQ_QUEUED */
	running = task_current(rq, p); /* rq->curr == p */

	if (queued)
		dequeue_task(...);
	if (running)
		put_prev_task(...);

	/* change task properties */

	if (queued)
		enqueue_task(...);
	if (running)
		set_next_task(...);

It becomes obvious that if we do this after put_prev_task() has
already been called on @p, things go sideways. This is exactly what
the commit in question allows to happen when it does:

	prev->sched_class->put_prev_task(rq, prev, rf);
	if (!rq->nr_running)
		newidle_balance(rq, rf);

The newidle_balance() call will drop rq->lock after we've called
put_prev_task() and that allows the above 'change' pattern to
interleave and mess up the state.

Furthermore, it turns out we lost the RT-pull when we put the last DL
task.

Fix both problems by extracting the balancing from put_prev_task() and
doing a multi-class balance() pass before put_prev_task().

Fixes: 67692435c411 ("sched: Rework pick_next_task() slow-path")
Reported-by: Quentin Perret <qperret@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Tested-by: Quentin Perret <qperret@google.com>
Tested-by: Valentin Schneider <valentin.schneider@arm.com>
1 parent e3b8b6a
History
File Mode Size
Kconfig -rw-r--r-- 7.8 KB
Makefile -rw-r--r-- 891 bytes
block.c -rw-r--r-- 4.9 KB
cache.c -rw-r--r-- 11.0 KB
decompressor.c -rw-r--r-- 3.3 KB
decompressor.h -rw-r--r-- 1.3 KB
decompressor_multi.c -rw-r--r-- 4.5 KB
decompressor_multi_percpu.c -rw-r--r-- 2.2 KB
decompressor_single.c -rw-r--r-- 1.7 KB
dir.c -rw-r--r-- 5.2 KB
export.c -rw-r--r-- 4.0 KB
file.c -rw-r--r-- 13.5 KB
file_cache.c -rw-r--r-- 887 bytes
file_direct.c -rw-r--r-- 4.1 KB
fragment.c -rw-r--r-- 2.6 KB
id.c -rw-r--r-- 2.3 KB
inode.c -rw-r--r-- 11.8 KB
lz4_wrapper.c -rw-r--r-- 2.8 KB
lzo_wrapper.c -rw-r--r-- 2.4 KB
namei.c -rw-r--r-- 6.8 KB
page_actor.c -rw-r--r-- 2.5 KB
page_actor.h -rw-r--r-- 1.9 KB
squashfs.h -rw-r--r-- 3.4 KB
squashfs_fs.h -rw-r--r-- 10.3 KB
squashfs_fs_i.h -rw-r--r-- 764 bytes
squashfs_fs_sb.h -rw-r--r-- 1.5 KB
super.c -rw-r--r-- 13.3 KB
symlink.c -rw-r--r-- 3.0 KB
xattr.c -rw-r--r-- 6.7 KB
xattr.h -rw-r--r-- 923 bytes
xattr_id.c -rw-r--r-- 2.0 KB
xz_wrapper.c -rw-r--r-- 3.6 KB
zlib_wrapper.c -rw-r--r-- 2.4 KB
zstd_wrapper.c -rw-r--r-- 2.9 KB

back to top