nuttx/sched/wqueue/kwork_cancel.c
raiden00pl 5a209a853e
Some checks are pending
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
sched/wqueue: restore -ENOENT from work_cancel() for unqueued work
work_cancel() used to return -ENOENT when the work structure was not
in the queue, and callers depend on that: aio_cancel() tears down the
AIO container (file_put() + aioc_free()) only when work_cancel()
reports success, because a work item that is not queued may already be
executing on a worker thread (see the comment in fs/aio/aio_cancel.c).

Since commit 6f72f5481d ("sched/wqueue: Refactor delayed and periodical
workqueue") work_cancel() returns OK unconditionally, and commit
d2e01b9055 ("sched/wqueue: harden custom queue lifecycle") kept that
behaviour and dropped -ENOENT from the function documentation.  Under
SMP the LTP aio_cancel tests then free the aio container and its file
while the lpwork thread is still executing aio_write_worker() on it,
which ends in a page fault in file_write() (f_inode == NULL) and a
panic.

Return -ENOENT again when the work is not queued, and document it.
For the synchronous variant "not queued" alone does not tell whether
the callback is running: the worker scan does, so report OK when a
running callback was found and waited for, and -ENOENT only when the
work was neither queued nor running.

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-13 11:31:41 +08:00

194 lines
6.1 KiB
C

/****************************************************************************
* sched/wqueue/kwork_cancel.c
*
* SPDX-License-Identifier: Apache-2.0
*
* Licensed to the Apache Software Foundation (ASF) under one or more
* contributor license agreements. See the NOTICE file distributed with
* this work for additional information regarding copyright ownership. The
* ASF licenses this file to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance with the
* License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
* WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
* License for the specific language governing permissions and limitations
* under the License.
*
****************************************************************************/
/****************************************************************************
* Included Files
****************************************************************************/
#include <nuttx/config.h>
#include <assert.h>
#include <errno.h>
#include <nuttx/irq.h>
#include <nuttx/arch.h>
#include <nuttx/list.h>
#include <nuttx/sched.h>
#include <nuttx/wqueue.h>
#include "wqueue/wqueue.h"
#ifdef CONFIG_SCHED_WORKQUEUE
/****************************************************************************
* Private Functions
****************************************************************************/
static int work_qcancel(FAR struct kwork_wqueue_s *wqueue, bool sync,
FAR struct work_s *work)
{
irqstate_t flags;
pid_t self = sync ? nxsched_gettid() : INVALID_PROCESS_ID;
int ret = -ENOENT;
if (wqueue == NULL || work == NULL)
{
return -EINVAL;
}
/* A work structure becomes available for requeue after it is dequeued,
* before its callback returns. Multiple workers can therefore execute
* callbacks using the same work structure. Find one such worker and
* repeat after it finishes until no callback remains. Exclude the
* calling worker to avoid self-deadlock.
*/
for (; ; )
{
FAR struct kworker_s *worker = wq_get_worker(wqueue);
FAR sem_t *sync_wait = NULL;
int wndx;
/* Cancelling the work is simply a matter of removing the work
* structure from the work queue. This must be done with interrupts
* disabled because new work is typically added from interrupt
* handlers.
*/
flags = spin_lock_irqsave(&wqueue->lock);
if (!work_available(work))
{
/* If the head of the pending queue has changed, reset the timer. */
if (work_remove(wqueue, work))
{
work_timer_reset(wqueue);
}
ret = OK;
}
/* Otherwise the work is not queued: either it was never queued or a
* worker has already dequeued it and may be executing its callback
* right now. Only the scan below can tell. Report -ENOENT if the
* work is neither queued nor running, so that callers (e.g.
* aio_cancel()) do not free resources that the callback is still
* using.
*/
if (sync)
{
for (wndx = 0; wndx < wqueue->nthreads; wndx++)
{
if (worker[wndx].work == work && worker[wndx].pid != self)
{
worker[wndx].wait_count++;
sync_wait = &worker[wndx].wait;
ret = OK;
break;
}
}
}
spin_unlock_irqrestore(&wqueue->lock, flags);
if (sync_wait == NULL)
{
return ret;
}
nxsem_wait_uninterruptible(sync_wait);
}
}
/****************************************************************************
* Public Functions
****************************************************************************/
/****************************************************************************
* Name: work_cancel/work_cancel_wq
*
* Description:
* Cancel previously queued work. This removes work from the work queue.
* After work has been cancelled, it may be requeued by calling
* work_queue() again.
*
* Input Parameters:
* qid - The work queue ID (must be HPWORK or LPWORK)
* wqueue - The work queue handle
* work - The previously queued work structure to cancel
*
* Returned Value:
* Zero on success, a negated errno on failure
*
* -EINVAL - An invalid work queue was specified
* -ENOENT - The work is not queued (and, for the sync variant, not
* running either)
*
****************************************************************************/
int work_cancel(int qid, FAR struct work_s *work)
{
return work_qcancel(work_qid2wq(qid), false, work);
}
int work_cancel_wq(FAR struct kwork_wqueue_s *wqueue,
FAR struct work_s *work)
{
return work_qcancel(wqueue, false, work);
}
/****************************************************************************
* Name: work_cancel_sync/work_cancel_sync_wq
*
* Description:
* Synchronously cancel previously queued work. This removes work from
* the work queue and waits for callbacks that are already running. After
* work has been cancelled, it may be requeued by calling work_queue()
* again.
*
* Input Parameters:
* qid - The work queue ID (must be HPWORK or LPWORK)
* wqueue - The work queue handle
* work - The previously queued work structure to cancel
*
* Returned Value:
* Zero means the work was successfully cancelled.
* A negated errno value is returned on any failure:
*
* -EINVAL - An invalid work queue was specified
*
****************************************************************************/
int work_cancel_sync(int qid, FAR struct work_s *work)
{
return work_qcancel(work_qid2wq(qid), true, work);
}
int work_cancel_sync_wq(FAR struct kwork_wqueue_s *wqueue,
FAR struct work_s *work)
{
return work_qcancel(wqueue, true, work);
}
#endif /* CONFIG_SCHED_WORKQUEUE */