Chen Ridong
cabadd7fd1
cgroup: split cgroup_destroy_wq into 3 workqueues
...
[ Upstream commit 79f919a89c9d06816dbdbbd168fa41d27411a7f9 ]
A hung task can occur during [1] LTP cgroup testing when repeatedly
mounting/unmounting perf_event and net_prio controllers with
systemd.unified_cgroup_hierarchy=1. The hang manifests in
cgroup_lock_and_drain_offline() during root destruction.
Related case:
cgroup_fj_function_perf_event cgroup_fj_function.sh perf_event
cgroup_fj_function_net_prio cgroup_fj_function.sh net_prio
Call Trace:
cgroup_lock_and_drain_offline+0x14c/0x1e8
cgroup_destroy_root+0x3c/0x2c0
css_free_rwork_fn+0x248/0x338
process_one_work+0x16c/0x3b8
worker_thread+0x22c/0x3b0
kthread+0xec/0x100
ret_from_fork+0x10/0x20
Root Cause:
CPU0 CPU1
mount perf_event umount net_prio
cgroup1_get_tree cgroup_kill_sb
rebind_subsystems // root destruction enqueues
// cgroup_destroy_wq
// kill all perf_event css
// one perf_event css A is dying
// css A offline enqueues cgroup_destroy_wq
// root destruction will be executed first
css_free_rwork_fn
cgroup_destroy_root
cgroup_lock_and_drain_offline
// some perf descendants are dying
// cgroup_destroy_wq max_active = 1
// waiting for css A to die
Problem scenario:
1. CPU0 mounts perf_event (rebind_subsystems)
2. CPU1 unmounts net_prio (cgroup_kill_sb), queuing root destruction work
3. A dying perf_event CSS gets queued for offline after root destruction
4. Root destruction waits for offline completion, but offline work is
blocked behind root destruction in cgroup_destroy_wq (max_active=1)
Solution:
Split cgroup_destroy_wq into three dedicated workqueues:
cgroup_offline_wq – Handles CSS offline operations
cgroup_release_wq – Manages resource release
cgroup_free_wq – Performs final memory deallocation
This separation eliminates blocking in the CSS free path while waiting for
offline operations to complete.
[1] https://github.com/linux-test-project/ltp/blob/master/runtest/controllers
Fixes: 334c3679ec ("cgroup: reimplement rebind_subsystems() using cgroup_apply_control() and friends")
Reported-by: Gao Yingjie <gaoyingjie@uniontech.com>
Signed-off-by: Chen Ridong <chenridong@huawei.com>
Suggested-by: Teju Heo <tj@kernel.org>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-10-02 13:34:30 +02:00
..
bpf
bpf: fix potential error return
2025-01-09 13:23:36 +01:00
cgroup
cgroup: split cgroup_destroy_wq into 3 workqueues
2025-10-02 13:34:30 +02:00
configs
debug
kdb: Use the passed prompt in kdb_position_cursor()
2024-08-19 05:33:40 +02:00
dma
dma: fix call order in dmam_free_coherent
2024-08-19 05:33:41 +02:00
events
perf/core: Prevent VMA split of buffer mappings
2025-08-28 16:21:23 +02:00
gcov
gcov: add support for GCC 14
2024-07-05 09:08:24 +02:00
irq
genirq: Provide new interfaces for affinity hints
2025-10-02 13:34:29 +02:00
livepatch
livepatch: fix race between fork and KLP transition
2022-10-26 13:22:18 +02:00
locking
locking/lockdep: Decrease nr_unused_locks if lock unused in zap_class()
2025-05-02 07:39:15 +02:00
power
PM: sleep: console: Fix the black screen issue
2025-08-28 16:21:25 +02:00
printk
printk: Fix signed integer overflow when defining LOG_BUF_LEN_MAX
2025-03-13 12:43:02 +01:00
rcu
rcu: Protect ->defer_qs_iw_pending from data race
2025-08-28 16:21:26 +02:00
sched
cpufreq/sched: Explicitly synchronize limits_changed flag handling
2025-09-09 18:44:00 +02:00
time
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
2025-06-27 11:02:57 +01:00
trace
ftrace: Fix potential warning in trace_printk_seq during ftrace_dump
2025-09-04 14:05:53 +02:00
.gitignore
kbuild: update config_data.gz only when the content of .config is changed
2021-05-11 14:04:16 +02:00
acct.c
acct: perform last write from workqueue
2025-03-13 12:43:26 +01:00
async.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
audit.c
audit: Send netlink ACK before setting connection in auditd_set
2024-02-23 08:24:54 +01:00
audit.h
audit: log AUDIT_TIME_* records only from rules
2022-04-15 14:18:04 +02:00
audit_fsnotify.c
audit: fix potential double free on error path from fsnotify_add_inode_mark
2022-09-05 10:27:38 +02:00
audit_tree.c
audit: move put_tree() to avoid trim_trees refcount underflow and UAF
2021-09-03 10:08:16 +02:00
audit_watch.c
audit: don't WARN_ON_ONCE(!current->mm) in audit_exe_compare()
2023-11-28 16:50:18 +00:00
auditfilter.c
auditsc.c
audit: fix possible soft lockup in __audit_inode_child()
2023-09-23 10:59:46 +02:00
backtracetest.c
treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD()
2023-04-20 12:07:32 +02:00
bounds.c
bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS
2024-05-02 16:18:37 +02:00
capability.c
compat.c
sched_getaffinity: don't assume 'cpumask_size()' is fully initialized
2023-04-05 11:16:42 +02:00
configs.c
context_tracking.c
cpu.c
hrtimers: Handle CPU state correctly on hotplug
2025-02-01 18:18:51 +01:00
cpu_pm.c
crash_core.c
crash_dump.c
cred.c
cred: switch to using atomic_long_t
2023-12-20 15:41:18 +01:00
delayacct.c
dma.c
exec_domain.c
exit.c
perf: Fix sample vs do_exit()
2025-06-27 11:02:58 +01:00
extable.c
kernel/extable.c: use address-of operator on section symbols
2023-06-09 10:29:01 +02:00
fail_function.c
kernel/fail_function: fix memory leak with using debugfs_lookup()
2023-03-11 16:44:15 +01:00
fork.c
mm: drop the assumption that VM_SHARED always implies writable
2025-08-28 16:21:36 +02:00
freezer.c
futex.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
gen_kheaders.sh
kheaders: Ignore silly-rename files
2025-02-01 18:18:51 +01:00
groups.c
hung_task.c
iomem.c
irq_work.c
jump_label.c
kallsyms.c
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_core.c
kexec: fix a memory leak in crash_shrink_memory()
2023-07-27 08:37:10 +02:00
kexec_elf.c
kexec: initialize ELF lowest address to ULONG_MAX
2025-04-10 14:29:41 +02:00
kexec_file.c
kexec: support purgatories with .text.hot sections
2023-06-21 15:44:10 +02:00
kexec_internal.h
kheaders.c
kheaders: Use array declaration instead of char
2023-05-17 11:35:33 +02:00
kmod.c
kprobes.c
kprobes: Fix possible use-after-free issue on kprobe registration
2024-05-02 16:18:30 +02:00
ksysfs.c
kthread.c
kthread: fix task state in kthread worker if being frozen
2024-11-08 16:20:30 +01:00
latencytop.c
Makefile
kbuild: update config_data.gz only when the content of .config is changed
2021-05-11 14:04:16 +02:00
module-internal.h
module.c
modules: only allow symbol_get of EXPORT_SYMBOL_GPL modules
2023-09-23 10:59:36 +02:00
module_signature.c
module: harden ELF info handling
2021-04-07 14:47:38 +02:00
module_signing.c
module: harden ELF info handling
2021-04-07 14:47:38 +02:00
notifier.c
nsproxy.c
padata.c
padata: fix sysfs store callback check
2025-03-13 12:42:56 +01:00
panic.c
panic: Flush kernel log buffer at the end
2024-04-13 12:51:37 +02:00
params.c
module: ensure that kobject_put() is safe for module type kobjects
2025-06-04 14:32:27 +02:00
pid.c
pid_namespace.c
memcg: enable accounting for pids in nested pid namespaces
2021-09-22 12:26:37 +02:00
profile.c
profiling: fix shift too large makes kernel panic
2022-08-25 11:18:02 +02:00
ptrace.c
ptrace: Reimplement PTRACE_KILL by always sending SIGKILL
2022-06-14 18:11:24 +02:00
range.c
reboot.c
kernel/reboot: emergency_restart: Set correct system_state
2023-11-28 16:50:19 +00:00
relay.c
relayfs: fix out-of-bounds access in relay_file_read
2023-05-17 11:35:58 +02:00
resource.c
resource: fix region_intersects() vs add_memory_driver_managed()
2024-11-08 16:20:46 +01:00
rseq.c
seccomp.c
seccomp: Invalidate seccomp mode to catch death failures
2022-02-16 12:52:53 +01:00
signal.c
signal: Replace BUG_ON()s
2024-11-08 16:20:38 +01:00
smp.c
smp: Add missing destroy_work_on_stack() call in smp_call_on_cpu()
2024-09-12 11:03:54 +02:00
smpboot.c
smpboot.h
softirq.c
tasklet: Introduce new initialization API
2025-03-13 12:43:04 +01:00
stackleak.c
stacktrace.c
stop_machine.c
sys.c
getrusage: use sig->stats_lock rather than lock_task_sighand()
2024-03-15 10:48:19 -04:00
sys_ni.c
kernel/sys_ni: add compat entry for fadvise64_64
2022-09-05 10:27:38 +02:00
sysctl-test.c
sysctl.c
sched/rt: Disallow writing invalid values to sched_rt_period_us
2024-03-01 13:13:33 +01:00
sysctl_binary.c
task_work.c
taskstats.c
test_kprobes.c
torture.c
tracepoint.c
tracepoint: Add tracepoint_probe_register_may_exist() for BPF tracing
2021-07-14 16:53:08 +02:00
tsacct.c
taskstats: Cleanup the use of task->exit_code
2022-02-23 11:59:57 +01:00
ucount.c
uid16.c
uid16.h
umh.c
up.c
smp: Fix smp_call_function_single_async prototype
2021-05-14 09:44:33 +02:00
user-return-notifier.c
user.c
user_namespace.c
utsname.c
utsname_sysctl.c
watchdog.c
watchdog: export lockup_detector_reconfigure
2022-08-25 11:18:37 +02:00
watchdog_hld.c
watchdog/perf: properly initialize the turbo mode timestamp and rearm counter
2024-08-19 05:33:39 +02:00
workqueue.c
workqueue: Override implicit ordered attribute in workqueue_apply_unbound_cpumask()
2023-10-25 11:53:18 +02:00
workqueue_internal.h