Re: [PATCH] io_uring/io-wq: fix worker accounting when canceling creation callbacks

Gabriel Krisman Bertazi <[email protected]>
Newsgroups org.kernel.vger.io-uring,org.kernel.vger.linux-kernel
Organization SUSE
Message-ID <[email protected]>
Vishnu Razdan via B4 Relay <[email protected]>
writes:

> From: Vishnu Razdan <[email protected]>
>
> create_worker_cb() reserves an io-wq worker slot only after its
> task-work callback runs. If the callback is canceled before then,
> io_worker_cancel_cb() still decrements acct->nr_workers. When an
> existing worker retires with its creation callback pending, that
> worker has already decremented the same account's worker count.
>
> The resulting undercount permits worker creation beyond the account's
> configured limit. On an AST2600 OpenBMC system, an unchanged sensor
> daemon reached 4,291 threads with the original kernel. With an
> equivalent downstream fix, 25 passive samples under its normal
> workload showed 6-9 threads.
>
> Decrement nr_workers only when the canceled callback is not
> create_worker_cb(). Continuation callbacks still release their reserved
> slot, and both callback types retain the existing running-count,
> reference-count, and create-state cleanup.
>
> Fixes: 1d5f5ea7cb7d ("io-wq: remove worker to owner tw dependency")
> Cc: [email protected]
> Assisted-by: Codex:gpt-5.6-sol
> Signed-off-by: Vishnu Razdan <[email protected]>
> ---

Reviewed-by: Gabriel Krisman Bertazi <[email protected]>

> Prevent unreserved worker-creation callbacks from decrementing the worker count.
> ---
>  io_uring/io-wq.c | 9 ++++++---
>  1 file changed, 6 insertions(+), 3 deletions(-)
>
> diff --git a/io_uring/io-wq.c b/io_uring/io-wq.c
> index 2e14880ee..fa403ed24 100644
> --- a/io_uring/io-wq.c
> +++ b/io_uring/io-wq.c
> @@ -211,9 +211,12 @@ static void io_worker_cancel_cb(struct io_worker *worker)
>  	struct io_wq *wq = worker->wq;
>  
>  	atomic_dec(&acct->nr_running);
> -	raw_spin_lock(&acct->workers_lock);
> -	acct->nr_workers--;
> -	raw_spin_unlock(&acct->workers_lock);
> +	/* create_worker_cb() has not reserved a worker slot yet. */
> +	if (worker->create_work.func != create_worker_cb) {
> +		raw_spin_lock(&acct->workers_lock);
> +		acct->nr_workers--;
> +		raw_spin_unlock(&acct->workers_lock);
> +	}
>  	io_worker_ref_put(wq);
>  	clear_bit_unlock(0, &worker->create_state);
>  	io_worker_release(worker);
>
> ---
> base-commit: d58772d8520c7ef247c4b95c9bd76d3a25da9ff5
> change-id: 20260810-vrazdan-io-wq-b4-submit-9c94df145718
>
> Best regards,
> --  
> Vishnu Razdan <[email protected]>
>
>

-- 
Gabriel Krisman Bertazi
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.