Skip to content

Commit

Permalink
page_pool: avoid infinite loop to schedule delayed worker
Browse files Browse the repository at this point in the history
[ Upstream commit 43130d0 ]

We noticed the kworker in page_pool_release_retry() was waken
up repeatedly and infinitely in production because of the
buggy driver causing the inflight less than 0 and warning
us in page_pool_inflight()[1].

Since the inflight value goes negative, it means we should
not expect the whole page_pool to get back to work normally.

This patch mitigates the adverse effect by not rescheduling
the kworker when detecting the inflight negative in
page_pool_release_retry().

[1]
[Mon Feb 10 20:36:11 2025] ------------[ cut here ]------------
[Mon Feb 10 20:36:11 2025] Negative(-51446) inflight packet-pages
...
[Mon Feb 10 20:36:11 2025] Call Trace:
[Mon Feb 10 20:36:11 2025]  page_pool_release_retry+0x23/0x70
[Mon Feb 10 20:36:11 2025]  process_one_work+0x1b1/0x370
[Mon Feb 10 20:36:11 2025]  worker_thread+0x37/0x3a0
[Mon Feb 10 20:36:11 2025]  kthread+0x11a/0x140
[Mon Feb 10 20:36:11 2025]  ? process_one_work+0x370/0x370
[Mon Feb 10 20:36:11 2025]  ? __kthread_cancel_work+0x40/0x40
[Mon Feb 10 20:36:11 2025]  ret_from_fork+0x35/0x40
[Mon Feb 10 20:36:11 2025] ---[ end trace ebffe800f33e7e34 ]---
Note: before this patch, the above calltrace would flood the
dmesg due to repeated reschedule of release_dw kworker.

Signed-off-by: Jason Xing <kerneljasonxing@gmail.com>
Reviewed-by: Mina Almasry <almasrymina@google.com>
Link: https://patch.msgid.link/20250214064250.85987-1-kerneljasonxing@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
  • Loading branch information
Jason Xing authored and Greg Kroah-Hartman committed May 2, 2025
1 parent 691d459 commit 91522ab
Showing 1 changed file with 7 additions and 1 deletion.
8 changes: 7 additions & 1 deletion net/core/page_pool.c
Original file line number Diff line number Diff line change
Expand Up @@ -699,7 +699,13 @@ static void page_pool_release_retry(struct work_struct *wq)
int inflight;

inflight = page_pool_release(pool);
if (!inflight)
/* In rare cases, a driver bug may cause inflight to go negative.
* Don't reschedule release if inflight is 0 or negative.
* - If 0, the page_pool has been destroyed
* - if negative, we will never recover
* in both cases no reschedule is necessary.
*/
if (inflight <= 0)
return;

/* Periodic warning */
Expand Down

0 comments on commit 91522ab

Please sign in to comment.