Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

kthread_worker: prevent queuing delayed work from timer_fn when it is being canceled

There is a small race window when a delayed work is being canceled and
the work still might be queued from the timer_fn:

CPU0 CPU1
kthread_cancel_delayed_work_sync()
__kthread_cancel_work_sync()
__kthread_cancel_work()
work->canceling++;
kthread_delayed_work_timer_fn()
kthread_insert_work();

BUG: kthread_insert_work() should not get called when work->canceling is
set.

Signed-off-by: Zqiang <qiang.zhang@windriver.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: Petr Mladek <pmladek@suse.com>
Acked-by: Tejun Heo <tj@kernel.org>
Cc: <stable@vger.kernel.org>
Link: https://lkml.kernel.org/r/20201014083030.16895-1-qiang.zhang@windriver.com
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>

authored by

Zqiang and committed by
Linus Torvalds
6993d0fd a77eedbc

+2 -1
+2 -1
kernel/kthread.c
··· 897 897 /* Move the work from worker->delayed_work_list. */ 898 898 WARN_ON_ONCE(list_empty(&work->node)); 899 899 list_del_init(&work->node); 900 - kthread_insert_work(worker, work, &worker->work_list); 900 + if (!work->canceling) 901 + kthread_insert_work(worker, work, &worker->work_list); 901 902 902 903 raw_spin_unlock_irqrestore(&worker->lock, flags); 903 904 }