summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorVishnu Razdan <vrazdan@openai.com>2026-08-11 00:01:27 -0700
committerJens Axboe <axboe@kernel.dk>2026-08-15 17:29:22 -0600
commit297b5ccea4acacaa47c150f043bce695202afbf1 (patch)
tree8c27e475701aa609aefbb4bdeb238e2e6ba19995
parentb76d6b068e693a1bea1df9cc5af16893c39b5bd5 (diff)
io_uring/io-wq: fix worker accounting when canceling creation callbacks
create_worker_cb() reserves an io-wq worker slot only after its task-work callback runs. If the callback is canceled before then, io_worker_cancel_cb() still decrements acct->nr_workers. When an existing worker retires with its creation callback pending, that worker has already decremented the same account's worker count. The resulting undercount permits worker creation beyond the account's configured limit. On an AST2600 OpenBMC system, an unchanged sensor daemon reached 4,291 threads with the original kernel. With an equivalent downstream fix, 25 passive samples under its normal workload showed 6-9 threads. Decrement nr_workers only when the canceled callback is not create_worker_cb(). Continuation callbacks still release their reserved slot, and both callback types retain the existing running-count, reference-count, and create-state cleanup. Fixes: 1d5f5ea7cb7d ("io-wq: remove worker to owner tw dependency") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5.6-sol Signed-off-by: Vishnu Razdan <vrazdan@openai.com> Reviewed-by: Gabriel Krisman Bertazi <krisman@suse.de> Link: https://patch.msgid.link/20260811-vrazdan-io-wq-b4-submit-v1-1-719ced16c921@openai.com Signed-off-by: Jens Axboe <axboe@kernel.dk>
-rw-r--r--io_uring/io-wq.c9
1 files changed, 6 insertions, 3 deletions
diff --git a/io_uring/io-wq.c b/io_uring/io-wq.c
index be8d75731d24..2ca223e47d41 100644
--- a/io_uring/io-wq.c
+++ b/io_uring/io-wq.c
@@ -212,9 +212,12 @@ static void io_worker_cancel_cb(struct io_worker *worker)
struct io_wq *wq = worker->wq;
atomic_dec(&acct->nr_running);
- raw_spin_lock(&acct->workers_lock);
- acct->nr_workers--;
- raw_spin_unlock(&acct->workers_lock);
+ /* create_worker_cb() has not reserved a worker slot yet. */
+ if (worker->create_work.func != create_worker_cb) {
+ raw_spin_lock(&acct->workers_lock);
+ acct->nr_workers--;
+ raw_spin_unlock(&acct->workers_lock);
+ }
io_worker_ref_put(wq);
clear_bit_unlock(0, &worker->create_state);
io_worker_release(worker);