From: Dario Faggioli <dfaggioli@suse.com>
To: "julien@xen.org" <julien@xen.org>,
"ahmeddan@amazon.co.uk" <ahmeddan@amazon.co.uk>,
"xen-devel@lists.xenproject.org" <xen-devel@lists.xenproject.org>
Cc: "sstabellini@kernel.org" <sstabellini@kernel.org>,
"mpohlack@amazon.de" <mpohlack@amazon.de>,
"jgrall@amazon.co.uk" <jgrall@amazon.co.uk>,
"doebel@amazon.de" <doebel@amazon.de>
Subject: Re: NULL scheduler DoS
Date: Wed, 11 Aug 2021 09:59:48 +0000 [thread overview]
Message-ID: <a354a8ebb5fd780177024f870807f9b9b7d02f42.camel@suse.com> (raw)
In-Reply-To: <8193a685-3ab1-9407-75f3-e335ea4406e4@xen.org>
[-- Attachment #1: Type: text/plain, Size: 2642 bytes --]
On Mon, 2021-08-09 at 18:35 +0100, Julien Grall wrote:
> On 09/08/2021 17:19, Ahmed, Daniele wrote:
> > Hi all,
>
> Hi Daniele,
>
Hello everyone from me as well,
> Thank you for the report!
>
Indeed. :-)
>
> The ASSERT() is triggered because the pCPU was already assigned to
> one
> of the dom0 vCPU. This problem is happening regardless whether there
> is
> free pCPU.
>
Right. Can we raise the appropriate log level, so that we can see these
messages:
dprintk(XENLOG_G_INFO, "%d <-- %pdv%d\n", cpu, unit->domain, unit->unit_id);
(and then see a full `xl dmesg`, or even better, a serial console dump,
since we crash! :-P)
> I have added some debugging in sched_set_res():
>
> diff --git a/xen/common/sched/private.h b/xen/common/sched/private.h
> index a870320146ef..2355f531dc13 100644
> --- a/xen/common/sched/private.h
> +++ b/xen/common/sched/private.h
> @@ -150,6 +150,10 @@ static inline void sched_set_res(struct
> sched_unit
> *unit,
> unsigned int cpu = cpumask_first(res->cpus);
> struct vcpu *v;
>
> + printk("%s: res->master_cpu %u unit %p %pd %pv\n", __func__,
> + res->master_cpu, unit, unit->domain, unit->vcpu_list);
> + WARN();
> +
> for_each_sched_unit_vcpu ( unit, v )
> {
> ASSERT(cpu < nr_cpu_ids);
>
> This traced the problem to null_unit_migrate():
>
> (XEN) sched_set_res: res->master_cpu 0 unit ffff830200887f00 d1 d1v0
> (XEN) Xen WARN at private.h:155
> (XEN) ----[ Xen-4.16-unstable x86_64 debug=y Tainted: C ]----
> (XEN) CPU: 1
> (XEN) RIP: e008:[<ffff82d04023fd9f>]
> core.c#sched_set_res+0x5b/0xc6
> [...]
> (XEN) Xen call trace:
> (XEN) [<ffff82d04023fd9f>] R core.c#sched_set_res+0x5b/0xc6
> (XEN) [<ffff82d040241614>] F sched_init_vcpu+0x3dc/0x5d7
> (XEN) [<ffff82d04020527d>] F vcpu_create+0xfb/0x37a
> (XEN) [<ffff82d040238dd9>] F do_domctl+0xac0/0x184a
> (XEN) [<ffff82d04030d8bc>] F pv_hypercall+0x10d/0x2b8
> (XEN) [<ffff82d04038829d>] F lstar_enter+0x12d/0x140
> (XEN)
>
So, it's entirely possible that I'm missing something obvious here, but
what it is that is making you think that we're in null_unit_migrate() ?
Does that come from a different instance of this WARN() ?
Regards
--
Dario Faggioli, Ph.D
http://about.me/dario.faggioli
Virtualization Software Engineer
SUSE Labs, SUSE https://www.suse.com/
-------------------------------------------------------------------
<<This happens because _I_ choose it to happen!>> (Raistlin Majere)
[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 833 bytes --]
prev parent reply other threads:[~2021-08-11 10:00 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-08-09 16:19 NULL scheduler DoS Ahmed, Daniele
2021-08-09 16:47 ` Ahmed, Daniele
2021-08-09 17:35 ` Julien Grall
2021-08-09 20:38 ` Julien Grall
2021-08-11 10:09 ` Dario Faggioli
2021-09-08 8:01 ` Ahmed, Daniele
2021-12-17 15:03 ` Ahmed, Daniele
2021-08-11 9:59 ` Dario Faggioli [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a354a8ebb5fd780177024f870807f9b9b7d02f42.camel@suse.com \
--to=dfaggioli@suse.com \
--cc=ahmeddan@amazon.co.uk \
--cc=doebel@amazon.de \
--cc=jgrall@amazon.co.uk \
--cc=julien@xen.org \
--cc=mpohlack@amazon.de \
--cc=sstabellini@kernel.org \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).