1 // SPDX-License-Identifier: GPL-2.0
2 /*
3 * Detect hard and soft lockups on a system
4 *
5 * started by Don Zickus, Copyright (C) 2010 Red Hat, Inc.
6 *
7 * Note: Most of this code is borrowed heavily from the original softlockup
8 * detector, so thanks to Ingo for the initial implementation.
9 * Some chunks also taken from the old x86-specific nmi watchdog code, thanks
10 * to those contributors as well.
11 */
12
13 #define pr_fmt(fmt) "watchdog: " fmt
14
15 #include <linux/cpu.h>
16 #include <linux/init.h>
17 #include <linux/irq.h>
18 #include <linux/irqdesc.h>
19 #include <linux/kernel_stat.h>
20 #include <linux/kvm_para.h>
21 #include <linux/math64.h>
22 #include <linux/mm.h>
23 #include <linux/module.h>
24 #include <linux/nmi.h>
25 #include <linux/stop_machine.h>
26 #include <linux/sysctl.h>
27 #include <linux/tick.h>
28
29 #include <linux/sched/clock.h>
30 #include <linux/sched/debug.h>
31 #include <linux/sched/isolation.h>
32
33 #include <asm/irq_regs.h>
34
35 static DEFINE_MUTEX(watchdog_mutex);
36
37 #if defined(CONFIG_HARDLOCKUP_DETECTOR) || defined(CONFIG_HARDLOCKUP_DETECTOR_SPARC64)
38 # define WATCHDOG_HARDLOCKUP_DEFAULT 1
39 #else
40 # define WATCHDOG_HARDLOCKUP_DEFAULT 0
41 #endif
42
43 #define NUM_SAMPLE_PERIODS 5
44
45 unsigned long __read_mostly watchdog_enabled;
46 int __read_mostly watchdog_user_enabled = 1;
47 static int __read_mostly watchdog_hardlockup_user_enabled = WATCHDOG_HARDLOCKUP_DEFAULT;
48 static int __read_mostly watchdog_softlockup_user_enabled = 1;
49 int __read_mostly watchdog_thresh = 10;
50 static int __read_mostly watchdog_hardlockup_available;
51
52 struct cpumask watchdog_cpumask __read_mostly;
53 unsigned long *watchdog_cpumask_bits = cpumask_bits(&watchdog_cpumask);
54
55 #ifdef CONFIG_HARDLOCKUP_DETECTOR
56
57 # ifdef CONFIG_SMP
58 int __read_mostly sysctl_hardlockup_all_cpu_backtrace;
59 # endif /* CONFIG_SMP */
60
61 /*
62 * Should we panic when a soft-lockup or hard-lockup occurs:
63 */
64 unsigned int __read_mostly hardlockup_panic =
65 IS_ENABLED(CONFIG_BOOTPARAM_HARDLOCKUP_PANIC);
66 /*
67 * We may not want to enable hard lockup detection by default in all cases,
68 * for example when running the kernel as a guest on a hypervisor. In these
69 * cases this function can be called to disable hard lockup detection. This
70 * function should only be executed once by the boot processor before the
71 * kernel command line parameters are parsed, because otherwise it is not
72 * possible to override this in hardlockup_panic_setup().
73 */
hardlockup_detector_disable(void)74 void __init hardlockup_detector_disable(void)
75 {
76 watchdog_hardlockup_user_enabled = 0;
77 }
78
hardlockup_panic_setup(char * str)79 static int __init hardlockup_panic_setup(char *str)
80 {
81 next:
82 if (!strncmp(str, "panic", 5))
83 hardlockup_panic = 1;
84 else if (!strncmp(str, "nopanic", 7))
85 hardlockup_panic = 0;
86 else if (!strncmp(str, "0", 1))
87 watchdog_hardlockup_user_enabled = 0;
88 else if (!strncmp(str, "1", 1))
89 watchdog_hardlockup_user_enabled = 1;
90 else if (!strncmp(str, "r", 1))
91 hardlockup_config_perf_event(str + 1);
92 while (*(str++)) {
93 if (*str == ',') {
94 str++;
95 goto next;
96 }
97 }
98 return 1;
99 }
100 __setup("nmi_watchdog=", hardlockup_panic_setup);
101
102 #endif /* CONFIG_HARDLOCKUP_DETECTOR */
103
104 #if defined(CONFIG_HARDLOCKUP_DETECTOR_COUNTS_HRTIMER)
105
106 static DEFINE_PER_CPU(atomic_t, hrtimer_interrupts);
107 static DEFINE_PER_CPU(int, hrtimer_interrupts_saved);
108 static DEFINE_PER_CPU(bool, watchdog_hardlockup_warned);
109 static DEFINE_PER_CPU(bool, watchdog_hardlockup_touched);
110 static unsigned long hard_lockup_nmi_warn;
111
arch_touch_nmi_watchdog(void)112 notrace void arch_touch_nmi_watchdog(void)
113 {
114 /*
115 * Using __raw here because some code paths have
116 * preemption enabled. If preemption is enabled
117 * then interrupts should be enabled too, in which
118 * case we shouldn't have to worry about the watchdog
119 * going off.
120 */
121 raw_cpu_write(watchdog_hardlockup_touched, true);
122 }
123 EXPORT_SYMBOL(arch_touch_nmi_watchdog);
124
watchdog_hardlockup_touch_cpu(unsigned int cpu)125 void watchdog_hardlockup_touch_cpu(unsigned int cpu)
126 {
127 per_cpu(watchdog_hardlockup_touched, cpu) = true;
128 }
129
is_hardlockup(unsigned int cpu)130 static bool is_hardlockup(unsigned int cpu)
131 {
132 int hrint = atomic_read(&per_cpu(hrtimer_interrupts, cpu));
133
134 if (per_cpu(hrtimer_interrupts_saved, cpu) == hrint)
135 return true;
136
137 /*
138 * NOTE: we don't need any fancy atomic_t or READ_ONCE/WRITE_ONCE
139 * for hrtimer_interrupts_saved. hrtimer_interrupts_saved is
140 * written/read by a single CPU.
141 */
142 per_cpu(hrtimer_interrupts_saved, cpu) = hrint;
143
144 return false;
145 }
146
watchdog_hardlockup_kick(void)147 static void watchdog_hardlockup_kick(void)
148 {
149 int new_interrupts;
150
151 new_interrupts = atomic_inc_return(this_cpu_ptr(&hrtimer_interrupts));
152 watchdog_buddy_check_hardlockup(new_interrupts);
153 }
154
watchdog_hardlockup_check(unsigned int cpu,struct pt_regs * regs)155 void watchdog_hardlockup_check(unsigned int cpu, struct pt_regs *regs)
156 {
157 if (per_cpu(watchdog_hardlockup_touched, cpu)) {
158 per_cpu(watchdog_hardlockup_touched, cpu) = false;
159 return;
160 }
161
162 /*
163 * Check for a hardlockup by making sure the CPU's timer
164 * interrupt is incrementing. The timer interrupt should have
165 * fired multiple times before we overflow'd. If it hasn't
166 * then this is a good indication the cpu is stuck
167 */
168 if (is_hardlockup(cpu)) {
169 unsigned int this_cpu = smp_processor_id();
170 unsigned long flags;
171
172 /* Only print hardlockups once. */
173 if (per_cpu(watchdog_hardlockup_warned, cpu))
174 return;
175
176 /*
177 * Prevent multiple hard-lockup reports if one cpu is already
178 * engaged in dumping all cpu back traces.
179 */
180 if (sysctl_hardlockup_all_cpu_backtrace) {
181 if (test_and_set_bit_lock(0, &hard_lockup_nmi_warn))
182 return;
183 }
184
185 /*
186 * NOTE: we call printk_cpu_sync_get_irqsave() after printing
187 * the lockup message. While it would be nice to serialize
188 * that printout, we really want to make sure that if some
189 * other CPU somehow locked up while holding the lock associated
190 * with printk_cpu_sync_get_irqsave() that we can still at least
191 * get the message about the lockup out.
192 */
193 pr_emerg("CPU%u: Watchdog detected hard LOCKUP on cpu %u\n", this_cpu, cpu);
194 printk_cpu_sync_get_irqsave(flags);
195
196 print_modules();
197 print_irqtrace_events(current);
198 if (cpu == this_cpu) {
199 if (regs)
200 show_regs(regs);
201 else
202 dump_stack();
203 printk_cpu_sync_put_irqrestore(flags);
204 } else {
205 printk_cpu_sync_put_irqrestore(flags);
206 trigger_single_cpu_backtrace(cpu);
207 }
208
209 if (sysctl_hardlockup_all_cpu_backtrace) {
210 trigger_allbutcpu_cpu_backtrace(cpu);
211 if (!hardlockup_panic)
212 clear_bit_unlock(0, &hard_lockup_nmi_warn);
213 }
214
215 if (hardlockup_panic)
216 nmi_panic(regs, "Hard LOCKUP");
217
218 per_cpu(watchdog_hardlockup_warned, cpu) = true;
219 } else {
220 per_cpu(watchdog_hardlockup_warned, cpu) = false;
221 }
222 }
223
224 #else /* CONFIG_HARDLOCKUP_DETECTOR_COUNTS_HRTIMER */
225
watchdog_hardlockup_kick(void)226 static inline void watchdog_hardlockup_kick(void) { }
227
228 #endif /* !CONFIG_HARDLOCKUP_DETECTOR_COUNTS_HRTIMER */
229
230 /*
231 * These functions can be overridden based on the configured hardlockdup detector.
232 *
233 * watchdog_hardlockup_enable/disable can be implemented to start and stop when
234 * softlockup watchdog start and stop. The detector must select the
235 * SOFTLOCKUP_DETECTOR Kconfig.
236 */
watchdog_hardlockup_enable(unsigned int cpu)237 void __weak watchdog_hardlockup_enable(unsigned int cpu) { }
238
watchdog_hardlockup_disable(unsigned int cpu)239 void __weak watchdog_hardlockup_disable(unsigned int cpu) { }
240
241 /*
242 * Watchdog-detector specific API.
243 *
244 * Return 0 when hardlockup watchdog is available, negative value otherwise.
245 * Note that the negative value means that a delayed probe might
246 * succeed later.
247 */
watchdog_hardlockup_probe(void)248 int __weak __init watchdog_hardlockup_probe(void)
249 {
250 return -ENODEV;
251 }
252
253 /**
254 * watchdog_hardlockup_stop - Stop the watchdog for reconfiguration
255 *
256 * The reconfiguration steps are:
257 * watchdog_hardlockup_stop();
258 * update_variables();
259 * watchdog_hardlockup_start();
260 */
watchdog_hardlockup_stop(void)261 void __weak watchdog_hardlockup_stop(void) { }
262
263 /**
264 * watchdog_hardlockup_start - Start the watchdog after reconfiguration
265 *
266 * Counterpart to watchdog_hardlockup_stop().
267 *
268 * The following variables have been updated in update_variables() and
269 * contain the currently valid configuration:
270 * - watchdog_enabled
271 * - watchdog_thresh
272 * - watchdog_cpumask
273 */
watchdog_hardlockup_start(void)274 void __weak watchdog_hardlockup_start(void) { }
275
276 /**
277 * lockup_detector_update_enable - Update the sysctl enable bit
278 *
279 * Caller needs to make sure that the hard watchdogs are off, so this
280 * can't race with watchdog_hardlockup_disable().
281 */
lockup_detector_update_enable(void)282 static void lockup_detector_update_enable(void)
283 {
284 watchdog_enabled = 0;
285 if (!watchdog_user_enabled)
286 return;
287 if (watchdog_hardlockup_available && watchdog_hardlockup_user_enabled)
288 watchdog_enabled |= WATCHDOG_HARDLOCKUP_ENABLED;
289 if (watchdog_softlockup_user_enabled)
290 watchdog_enabled |= WATCHDOG_SOFTOCKUP_ENABLED;
291 }
292
293 #ifdef CONFIG_SOFTLOCKUP_DETECTOR
294
295 /*
296 * Delay the soflockup report when running a known slow code.
297 * It does _not_ affect the timestamp of the last successdul reschedule.
298 */
299 #define SOFTLOCKUP_DELAY_REPORT ULONG_MAX
300
301 #ifdef CONFIG_SMP
302 int __read_mostly sysctl_softlockup_all_cpu_backtrace;
303 #endif
304
305 static struct cpumask watchdog_allowed_mask __read_mostly;
306
307 /* Global variables, exported for sysctl */
308 unsigned int __read_mostly softlockup_panic =
309 IS_ENABLED(CONFIG_BOOTPARAM_SOFTLOCKUP_PANIC);
310
311 static bool softlockup_initialized __read_mostly;
312 static u64 __read_mostly sample_period;
313
314 /* Timestamp taken after the last successful reschedule. */
315 static DEFINE_PER_CPU(unsigned long, watchdog_touch_ts);
316 /* Timestamp of the last softlockup report. */
317 static DEFINE_PER_CPU(unsigned long, watchdog_report_ts);
318 static DEFINE_PER_CPU(struct hrtimer, watchdog_hrtimer);
319 static DEFINE_PER_CPU(bool, softlockup_touch_sync);
320 static unsigned long soft_lockup_nmi_warn;
321
softlockup_panic_setup(char * str)322 static int __init softlockup_panic_setup(char *str)
323 {
324 softlockup_panic = simple_strtoul(str, NULL, 0);
325 return 1;
326 }
327 __setup("softlockup_panic=", softlockup_panic_setup);
328
nowatchdog_setup(char * str)329 static int __init nowatchdog_setup(char *str)
330 {
331 watchdog_user_enabled = 0;
332 return 1;
333 }
334 __setup("nowatchdog", nowatchdog_setup);
335
nosoftlockup_setup(char * str)336 static int __init nosoftlockup_setup(char *str)
337 {
338 watchdog_softlockup_user_enabled = 0;
339 return 1;
340 }
341 __setup("nosoftlockup", nosoftlockup_setup);
342
watchdog_thresh_setup(char * str)343 static int __init watchdog_thresh_setup(char *str)
344 {
345 get_option(&str, &watchdog_thresh);
346 return 1;
347 }
348 __setup("watchdog_thresh=", watchdog_thresh_setup);
349
350 #ifdef CONFIG_SOFTLOCKUP_DETECTOR_INTR_STORM
351 enum stats_per_group {
352 STATS_SYSTEM,
353 STATS_SOFTIRQ,
354 STATS_HARDIRQ,
355 STATS_IDLE,
356 NUM_STATS_PER_GROUP,
357 };
358
359 static const enum cpu_usage_stat tracked_stats[NUM_STATS_PER_GROUP] = {
360 CPUTIME_SYSTEM,
361 CPUTIME_SOFTIRQ,
362 CPUTIME_IRQ,
363 CPUTIME_IDLE,
364 };
365
366 static DEFINE_PER_CPU(u16, cpustat_old[NUM_STATS_PER_GROUP]);
367 static DEFINE_PER_CPU(u8, cpustat_util[NUM_SAMPLE_PERIODS][NUM_STATS_PER_GROUP]);
368 static DEFINE_PER_CPU(u8, cpustat_tail);
369
370 /*
371 * We don't need nanosecond resolution. A granularity of 16ms is
372 * sufficient for our precision, allowing us to use u16 to store
373 * cpustats, which will roll over roughly every ~1000 seconds.
374 * 2^24 ~= 16 * 10^6
375 */
get_16bit_precision(u64 data_ns)376 static u16 get_16bit_precision(u64 data_ns)
377 {
378 return data_ns >> 24LL; /* 2^24ns ~= 16.8ms */
379 }
380
update_cpustat(void)381 static void update_cpustat(void)
382 {
383 int i;
384 u8 util;
385 u16 old_stat, new_stat;
386 struct kernel_cpustat kcpustat;
387 u64 *cpustat = kcpustat.cpustat;
388 u8 tail = __this_cpu_read(cpustat_tail);
389 u16 sample_period_16 = get_16bit_precision(sample_period);
390
391 kcpustat_cpu_fetch(&kcpustat, smp_processor_id());
392
393 for (i = 0; i < NUM_STATS_PER_GROUP; i++) {
394 old_stat = __this_cpu_read(cpustat_old[i]);
395 new_stat = get_16bit_precision(cpustat[tracked_stats[i]]);
396 util = DIV_ROUND_UP(100 * (new_stat - old_stat), sample_period_16);
397 __this_cpu_write(cpustat_util[tail][i], util);
398 __this_cpu_write(cpustat_old[i], new_stat);
399 }
400
401 __this_cpu_write(cpustat_tail, (tail + 1) % NUM_SAMPLE_PERIODS);
402 }
403
print_cpustat(void)404 static void print_cpustat(void)
405 {
406 int i, group;
407 u8 tail = __this_cpu_read(cpustat_tail);
408 u64 sample_period_second = sample_period;
409
410 do_div(sample_period_second, NSEC_PER_SEC);
411
412 /*
413 * Outputting the "watchdog" prefix on every line is redundant and not
414 * concise, and the original alarm information is sufficient for
415 * positioning in logs, hence here printk() is used instead of pr_crit().
416 */
417 printk(KERN_CRIT "CPU#%d Utilization every %llus during lockup:\n",
418 smp_processor_id(), sample_period_second);
419
420 for (i = 0; i < NUM_SAMPLE_PERIODS; i++) {
421 group = (tail + i) % NUM_SAMPLE_PERIODS;
422 printk(KERN_CRIT "\t#%d: %3u%% system,\t%3u%% softirq,\t"
423 "%3u%% hardirq,\t%3u%% idle\n", i + 1,
424 __this_cpu_read(cpustat_util[group][STATS_SYSTEM]),
425 __this_cpu_read(cpustat_util[group][STATS_SOFTIRQ]),
426 __this_cpu_read(cpustat_util[group][STATS_HARDIRQ]),
427 __this_cpu_read(cpustat_util[group][STATS_IDLE]));
428 }
429 }
430
431 #define HARDIRQ_PERCENT_THRESH 50
432 #define NUM_HARDIRQ_REPORT 5
433 struct irq_counts {
434 int irq;
435 u32 counts;
436 };
437
438 static DEFINE_PER_CPU(bool, snapshot_taken);
439
440 /* Tabulate the most frequent interrupts. */
tabulate_irq_count(struct irq_counts * irq_counts,int irq,u32 counts,int rank)441 static void tabulate_irq_count(struct irq_counts *irq_counts, int irq, u32 counts, int rank)
442 {
443 int i;
444 struct irq_counts new_count = {irq, counts};
445
446 for (i = 0; i < rank; i++) {
447 if (counts > irq_counts[i].counts)
448 swap(new_count, irq_counts[i]);
449 }
450 }
451
452 /*
453 * If the hardirq time exceeds HARDIRQ_PERCENT_THRESH% of the sample_period,
454 * then the cause of softlockup might be interrupt storm. In this case, it
455 * would be useful to start interrupt counting.
456 */
need_counting_irqs(void)457 static bool need_counting_irqs(void)
458 {
459 u8 util;
460 int tail = __this_cpu_read(cpustat_tail);
461
462 tail = (tail + NUM_HARDIRQ_REPORT - 1) % NUM_HARDIRQ_REPORT;
463 util = __this_cpu_read(cpustat_util[tail][STATS_HARDIRQ]);
464 return util > HARDIRQ_PERCENT_THRESH;
465 }
466
start_counting_irqs(void)467 static void start_counting_irqs(void)
468 {
469 if (!__this_cpu_read(snapshot_taken)) {
470 kstat_snapshot_irqs();
471 __this_cpu_write(snapshot_taken, true);
472 }
473 }
474
stop_counting_irqs(void)475 static void stop_counting_irqs(void)
476 {
477 __this_cpu_write(snapshot_taken, false);
478 }
479
print_irq_counts(void)480 static void print_irq_counts(void)
481 {
482 unsigned int i, count;
483 struct irq_counts irq_counts_sorted[NUM_HARDIRQ_REPORT] = {
484 {-1, 0}, {-1, 0}, {-1, 0}, {-1, 0}, {-1, 0}
485 };
486
487 if (__this_cpu_read(snapshot_taken)) {
488 for_each_active_irq(i) {
489 count = kstat_get_irq_since_snapshot(i);
490 tabulate_irq_count(irq_counts_sorted, i, count, NUM_HARDIRQ_REPORT);
491 }
492
493 /*
494 * Outputting the "watchdog" prefix on every line is redundant and not
495 * concise, and the original alarm information is sufficient for
496 * positioning in logs, hence here printk() is used instead of pr_crit().
497 */
498 printk(KERN_CRIT "CPU#%d Detect HardIRQ Time exceeds %d%%. Most frequent HardIRQs:\n",
499 smp_processor_id(), HARDIRQ_PERCENT_THRESH);
500
501 for (i = 0; i < NUM_HARDIRQ_REPORT; i++) {
502 if (irq_counts_sorted[i].irq == -1)
503 break;
504
505 printk(KERN_CRIT "\t#%u: %-10u\tirq#%d\n",
506 i + 1, irq_counts_sorted[i].counts,
507 irq_counts_sorted[i].irq);
508 }
509
510 /*
511 * If the hardirq time is less than HARDIRQ_PERCENT_THRESH% in the last
512 * sample_period, then we suspect the interrupt storm might be subsiding.
513 */
514 if (!need_counting_irqs())
515 stop_counting_irqs();
516 }
517 }
518
report_cpu_status(void)519 static void report_cpu_status(void)
520 {
521 print_cpustat();
522 print_irq_counts();
523 }
524 #else
update_cpustat(void)525 static inline void update_cpustat(void) { }
report_cpu_status(void)526 static inline void report_cpu_status(void) { }
need_counting_irqs(void)527 static inline bool need_counting_irqs(void) { return false; }
start_counting_irqs(void)528 static inline void start_counting_irqs(void) { }
stop_counting_irqs(void)529 static inline void stop_counting_irqs(void) { }
530 #endif
531
532 /*
533 * Hard-lockup warnings should be triggered after just a few seconds. Soft-
534 * lockups can have false positives under extreme conditions. So we generally
535 * want a higher threshold for soft lockups than for hard lockups. So we couple
536 * the thresholds with a factor: we make the soft threshold twice the amount of
537 * time the hard threshold is.
538 */
get_softlockup_thresh(void)539 static int get_softlockup_thresh(void)
540 {
541 return watchdog_thresh * 2;
542 }
543
544 /*
545 * Returns seconds, approximately. We don't need nanosecond
546 * resolution, and we don't need to waste time with a big divide when
547 * 2^30ns == 1.074s.
548 */
get_timestamp(void)549 static unsigned long get_timestamp(void)
550 {
551 return running_clock() >> 30LL; /* 2^30 ~= 10^9 */
552 }
553
set_sample_period(void)554 static void set_sample_period(void)
555 {
556 /*
557 * convert watchdog_thresh from seconds to ns
558 * the divide by 5 is to give hrtimer several chances (two
559 * or three with the current relation between the soft
560 * and hard thresholds) to increment before the
561 * hardlockup detector generates a warning
562 */
563 sample_period = get_softlockup_thresh() * ((u64)NSEC_PER_SEC / NUM_SAMPLE_PERIODS);
564 watchdog_update_hrtimer_threshold(sample_period);
565 }
566
update_report_ts(void)567 static void update_report_ts(void)
568 {
569 __this_cpu_write(watchdog_report_ts, get_timestamp());
570 }
571
572 /* Commands for resetting the watchdog */
update_touch_ts(void)573 static void update_touch_ts(void)
574 {
575 __this_cpu_write(watchdog_touch_ts, get_timestamp());
576 update_report_ts();
577 }
578
579 /**
580 * touch_softlockup_watchdog_sched - touch watchdog on scheduler stalls
581 *
582 * Call when the scheduler may have stalled for legitimate reasons
583 * preventing the watchdog task from executing - e.g. the scheduler
584 * entering idle state. This should only be used for scheduler events.
585 * Use touch_softlockup_watchdog() for everything else.
586 */
touch_softlockup_watchdog_sched(void)587 notrace void touch_softlockup_watchdog_sched(void)
588 {
589 /*
590 * Preemption can be enabled. It doesn't matter which CPU's watchdog
591 * report period gets restarted here, so use the raw_ operation.
592 */
593 raw_cpu_write(watchdog_report_ts, SOFTLOCKUP_DELAY_REPORT);
594 }
595
touch_softlockup_watchdog(void)596 notrace void touch_softlockup_watchdog(void)
597 {
598 touch_softlockup_watchdog_sched();
599 wq_watchdog_touch(raw_smp_processor_id());
600 }
601 EXPORT_SYMBOL(touch_softlockup_watchdog);
602
touch_all_softlockup_watchdogs(void)603 void touch_all_softlockup_watchdogs(void)
604 {
605 int cpu;
606
607 /*
608 * watchdog_mutex cannpt be taken here, as this might be called
609 * from (soft)interrupt context, so the access to
610 * watchdog_allowed_cpumask might race with a concurrent update.
611 *
612 * The watchdog time stamp can race against a concurrent real
613 * update as well, the only side effect might be a cycle delay for
614 * the softlockup check.
615 */
616 for_each_cpu(cpu, &watchdog_allowed_mask) {
617 per_cpu(watchdog_report_ts, cpu) = SOFTLOCKUP_DELAY_REPORT;
618 wq_watchdog_touch(cpu);
619 }
620 }
621
touch_softlockup_watchdog_sync(void)622 void touch_softlockup_watchdog_sync(void)
623 {
624 __this_cpu_write(softlockup_touch_sync, true);
625 __this_cpu_write(watchdog_report_ts, SOFTLOCKUP_DELAY_REPORT);
626 }
627
is_softlockup(unsigned long touch_ts,unsigned long period_ts,unsigned long now)628 static int is_softlockup(unsigned long touch_ts,
629 unsigned long period_ts,
630 unsigned long now)
631 {
632 if ((watchdog_enabled & WATCHDOG_SOFTOCKUP_ENABLED) && watchdog_thresh) {
633 /*
634 * If period_ts has not been updated during a sample_period, then
635 * in the subsequent few sample_periods, period_ts might also not
636 * be updated, which could indicate a potential softlockup. In
637 * this case, if we suspect the cause of the potential softlockup
638 * might be interrupt storm, then we need to count the interrupts
639 * to find which interrupt is storming.
640 */
641 if (time_after_eq(now, period_ts + get_softlockup_thresh() / NUM_SAMPLE_PERIODS) &&
642 need_counting_irqs())
643 start_counting_irqs();
644
645 /*
646 * A poorly behaving BPF scheduler can live-lock the system into
647 * soft lockups. Tell sched_ext to try ejecting the BPF
648 * scheduler when close to a soft lockup.
649 */
650 if (time_after_eq(now, period_ts + get_softlockup_thresh() * 3 / 4))
651 scx_softlockup(now - touch_ts);
652
653 /* Warn about unreasonable delays. */
654 if (time_after(now, period_ts + get_softlockup_thresh()))
655 return now - touch_ts;
656 }
657 return 0;
658 }
659
660 /* watchdog detector functions */
661 static DEFINE_PER_CPU(struct completion, softlockup_completion);
662 static DEFINE_PER_CPU(struct cpu_stop_work, softlockup_stop_work);
663
664 /*
665 * The watchdog feed function - touches the timestamp.
666 *
667 * It only runs once every sample_period seconds (4 seconds by
668 * default) to reset the softlockup timestamp. If this gets delayed
669 * for more than 2*watchdog_thresh seconds then the debug-printout
670 * triggers in watchdog_timer_fn().
671 */
softlockup_fn(void * data)672 static int softlockup_fn(void *data)
673 {
674 update_touch_ts();
675 stop_counting_irqs();
676 complete(this_cpu_ptr(&softlockup_completion));
677
678 return 0;
679 }
680
681 /* watchdog kicker functions */
watchdog_timer_fn(struct hrtimer * hrtimer)682 static enum hrtimer_restart watchdog_timer_fn(struct hrtimer *hrtimer)
683 {
684 unsigned long touch_ts, period_ts, now;
685 struct pt_regs *regs = get_irq_regs();
686 int duration;
687 int softlockup_all_cpu_backtrace = sysctl_softlockup_all_cpu_backtrace;
688 unsigned long flags;
689
690 if (!watchdog_enabled)
691 return HRTIMER_NORESTART;
692
693 watchdog_hardlockup_kick();
694
695 /* kick the softlockup detector */
696 if (completion_done(this_cpu_ptr(&softlockup_completion))) {
697 reinit_completion(this_cpu_ptr(&softlockup_completion));
698 stop_one_cpu_nowait(smp_processor_id(),
699 softlockup_fn, NULL,
700 this_cpu_ptr(&softlockup_stop_work));
701 }
702
703 /* .. and repeat */
704 hrtimer_forward_now(hrtimer, ns_to_ktime(sample_period));
705
706 /*
707 * Read the current timestamp first. It might become invalid anytime
708 * when a virtual machine is stopped by the host or when the watchog
709 * is touched from NMI.
710 */
711 now = get_timestamp();
712 /*
713 * If a virtual machine is stopped by the host it can look to
714 * the watchdog like a soft lockup. This function touches the watchdog.
715 */
716 kvm_check_and_clear_guest_paused();
717 /*
718 * The stored timestamp is comparable with @now only when not touched.
719 * It might get touched anytime from NMI. Make sure that is_softlockup()
720 * uses the same (valid) value.
721 */
722 period_ts = READ_ONCE(*this_cpu_ptr(&watchdog_report_ts));
723
724 update_cpustat();
725
726 /* Reset the interval when touched by known problematic code. */
727 if (period_ts == SOFTLOCKUP_DELAY_REPORT) {
728 if (unlikely(__this_cpu_read(softlockup_touch_sync))) {
729 /*
730 * If the time stamp was touched atomically
731 * make sure the scheduler tick is up to date.
732 */
733 __this_cpu_write(softlockup_touch_sync, false);
734 sched_clock_tick();
735 }
736
737 update_report_ts();
738 return HRTIMER_RESTART;
739 }
740
741 /* Check for a softlockup. */
742 touch_ts = __this_cpu_read(watchdog_touch_ts);
743 duration = is_softlockup(touch_ts, period_ts, now);
744 if (unlikely(duration)) {
745 /*
746 * Prevent multiple soft-lockup reports if one cpu is already
747 * engaged in dumping all cpu back traces.
748 */
749 if (softlockup_all_cpu_backtrace) {
750 if (test_and_set_bit_lock(0, &soft_lockup_nmi_warn))
751 return HRTIMER_RESTART;
752 }
753
754 /* Start period for the next softlockup warning. */
755 update_report_ts();
756
757 printk_cpu_sync_get_irqsave(flags);
758 pr_emerg("BUG: soft lockup - CPU#%d stuck for %us! [%s:%d]\n",
759 smp_processor_id(), duration,
760 current->comm, task_pid_nr(current));
761 report_cpu_status();
762 print_modules();
763 print_irqtrace_events(current);
764 if (regs)
765 show_regs(regs);
766 else
767 dump_stack();
768 printk_cpu_sync_put_irqrestore(flags);
769
770 if (softlockup_all_cpu_backtrace) {
771 trigger_allbutcpu_cpu_backtrace(smp_processor_id());
772 if (!softlockup_panic)
773 clear_bit_unlock(0, &soft_lockup_nmi_warn);
774 }
775
776 add_taint(TAINT_SOFTLOCKUP, LOCKDEP_STILL_OK);
777 if (softlockup_panic)
778 panic("softlockup: hung tasks");
779 }
780
781 return HRTIMER_RESTART;
782 }
783
watchdog_enable(unsigned int cpu)784 static void watchdog_enable(unsigned int cpu)
785 {
786 struct hrtimer *hrtimer = this_cpu_ptr(&watchdog_hrtimer);
787 struct completion *done = this_cpu_ptr(&softlockup_completion);
788
789 WARN_ON_ONCE(cpu != smp_processor_id());
790
791 init_completion(done);
792 complete(done);
793
794 /*
795 * Start the timer first to prevent the hardlockup watchdog triggering
796 * before the timer has a chance to fire.
797 */
798 hrtimer_setup(hrtimer, watchdog_timer_fn, CLOCK_MONOTONIC, HRTIMER_MODE_REL_HARD);
799 hrtimer_start(hrtimer, ns_to_ktime(sample_period),
800 HRTIMER_MODE_REL_PINNED_HARD);
801
802 /* Initialize timestamp */
803 update_touch_ts();
804 /* Enable the hardlockup detector */
805 if (watchdog_enabled & WATCHDOG_HARDLOCKUP_ENABLED)
806 watchdog_hardlockup_enable(cpu);
807 }
808
watchdog_disable(unsigned int cpu)809 static void watchdog_disable(unsigned int cpu)
810 {
811 struct hrtimer *hrtimer = this_cpu_ptr(&watchdog_hrtimer);
812
813 WARN_ON_ONCE(cpu != smp_processor_id());
814
815 /*
816 * Disable the hardlockup detector first. That prevents that a large
817 * delay between disabling the timer and disabling the hardlockup
818 * detector causes a false positive.
819 */
820 watchdog_hardlockup_disable(cpu);
821 hrtimer_cancel(hrtimer);
822 wait_for_completion(this_cpu_ptr(&softlockup_completion));
823 }
824
softlockup_stop_fn(void * data)825 static int softlockup_stop_fn(void *data)
826 {
827 watchdog_disable(smp_processor_id());
828 return 0;
829 }
830
softlockup_stop_all(void)831 static void softlockup_stop_all(void)
832 {
833 int cpu;
834
835 if (!softlockup_initialized)
836 return;
837
838 for_each_cpu(cpu, &watchdog_allowed_mask)
839 smp_call_on_cpu(cpu, softlockup_stop_fn, NULL, false);
840
841 cpumask_clear(&watchdog_allowed_mask);
842 }
843
softlockup_start_fn(void * data)844 static int softlockup_start_fn(void *data)
845 {
846 watchdog_enable(smp_processor_id());
847 return 0;
848 }
849
softlockup_start_all(void)850 static void softlockup_start_all(void)
851 {
852 int cpu;
853
854 cpumask_copy(&watchdog_allowed_mask, &watchdog_cpumask);
855 for_each_cpu(cpu, &watchdog_allowed_mask)
856 smp_call_on_cpu(cpu, softlockup_start_fn, NULL, false);
857 }
858
lockup_detector_online_cpu(unsigned int cpu)859 int lockup_detector_online_cpu(unsigned int cpu)
860 {
861 if (cpumask_test_cpu(cpu, &watchdog_allowed_mask))
862 watchdog_enable(cpu);
863 return 0;
864 }
865
lockup_detector_offline_cpu(unsigned int cpu)866 int lockup_detector_offline_cpu(unsigned int cpu)
867 {
868 if (cpumask_test_cpu(cpu, &watchdog_allowed_mask))
869 watchdog_disable(cpu);
870 return 0;
871 }
872
__lockup_detector_reconfigure(void)873 static void __lockup_detector_reconfigure(void)
874 {
875 cpus_read_lock();
876 watchdog_hardlockup_stop();
877
878 softlockup_stop_all();
879 set_sample_period();
880 lockup_detector_update_enable();
881 if (watchdog_enabled && watchdog_thresh)
882 softlockup_start_all();
883
884 watchdog_hardlockup_start();
885 cpus_read_unlock();
886 }
887
lockup_detector_reconfigure(void)888 void lockup_detector_reconfigure(void)
889 {
890 mutex_lock(&watchdog_mutex);
891 __lockup_detector_reconfigure();
892 mutex_unlock(&watchdog_mutex);
893 }
894
895 /*
896 * Create the watchdog infrastructure and configure the detector(s).
897 */
lockup_detector_setup(void)898 static __init void lockup_detector_setup(void)
899 {
900 /*
901 * If sysctl is off and watchdog got disabled on the command line,
902 * nothing to do here.
903 */
904 lockup_detector_update_enable();
905
906 if (!IS_ENABLED(CONFIG_SYSCTL) &&
907 !(watchdog_enabled && watchdog_thresh))
908 return;
909
910 mutex_lock(&watchdog_mutex);
911 __lockup_detector_reconfigure();
912 softlockup_initialized = true;
913 mutex_unlock(&watchdog_mutex);
914 }
915
916 #else /* CONFIG_SOFTLOCKUP_DETECTOR */
__lockup_detector_reconfigure(void)917 static void __lockup_detector_reconfigure(void)
918 {
919 cpus_read_lock();
920 watchdog_hardlockup_stop();
921 lockup_detector_update_enable();
922 watchdog_hardlockup_start();
923 cpus_read_unlock();
924 }
lockup_detector_reconfigure(void)925 void lockup_detector_reconfigure(void)
926 {
927 __lockup_detector_reconfigure();
928 }
lockup_detector_setup(void)929 static inline void lockup_detector_setup(void)
930 {
931 __lockup_detector_reconfigure();
932 }
933 #endif /* !CONFIG_SOFTLOCKUP_DETECTOR */
934
935 /**
936 * lockup_detector_soft_poweroff - Interface to stop lockup detector(s)
937 *
938 * Special interface for parisc. It prevents lockup detector warnings from
939 * the default pm_poweroff() function which busy loops forever.
940 */
lockup_detector_soft_poweroff(void)941 void lockup_detector_soft_poweroff(void)
942 {
943 watchdog_enabled = 0;
944 }
945
946 #ifdef CONFIG_SYSCTL
947
948 /* Propagate any changes to the watchdog infrastructure */
proc_watchdog_update(void)949 static void proc_watchdog_update(void)
950 {
951 /* Remove impossible cpus to keep sysctl output clean. */
952 cpumask_and(&watchdog_cpumask, &watchdog_cpumask, cpu_possible_mask);
953 __lockup_detector_reconfigure();
954 }
955
956 /*
957 * common function for watchdog, nmi_watchdog and soft_watchdog parameter
958 *
959 * caller | table->data points to | 'which'
960 * -------------------|----------------------------------|-------------------------------
961 * proc_watchdog | watchdog_user_enabled | WATCHDOG_HARDLOCKUP_ENABLED |
962 * | | WATCHDOG_SOFTOCKUP_ENABLED
963 * -------------------|----------------------------------|-------------------------------
964 * proc_nmi_watchdog | watchdog_hardlockup_user_enabled | WATCHDOG_HARDLOCKUP_ENABLED
965 * -------------------|----------------------------------|-------------------------------
966 * proc_soft_watchdog | watchdog_softlockup_user_enabled | WATCHDOG_SOFTOCKUP_ENABLED
967 */
proc_watchdog_common(int which,const struct ctl_table * table,int write,void * buffer,size_t * lenp,loff_t * ppos)968 static int proc_watchdog_common(int which, const struct ctl_table *table, int write,
969 void *buffer, size_t *lenp, loff_t *ppos)
970 {
971 int err, old, *param = table->data;
972
973 mutex_lock(&watchdog_mutex);
974
975 old = *param;
976 if (!write) {
977 /*
978 * On read synchronize the userspace interface. This is a
979 * racy snapshot.
980 */
981 *param = (watchdog_enabled & which) != 0;
982 err = proc_dointvec_minmax(table, write, buffer, lenp, ppos);
983 *param = old;
984 } else {
985 err = proc_dointvec_minmax(table, write, buffer, lenp, ppos);
986 if (!err && old != READ_ONCE(*param))
987 proc_watchdog_update();
988 }
989 mutex_unlock(&watchdog_mutex);
990 return err;
991 }
992
993 /*
994 * /proc/sys/kernel/watchdog
995 */
proc_watchdog(const struct ctl_table * table,int write,void * buffer,size_t * lenp,loff_t * ppos)996 static int proc_watchdog(const struct ctl_table *table, int write,
997 void *buffer, size_t *lenp, loff_t *ppos)
998 {
999 return proc_watchdog_common(WATCHDOG_HARDLOCKUP_ENABLED |
1000 WATCHDOG_SOFTOCKUP_ENABLED,
1001 table, write, buffer, lenp, ppos);
1002 }
1003
1004 /*
1005 * /proc/sys/kernel/nmi_watchdog
1006 */
proc_nmi_watchdog(const struct ctl_table * table,int write,void * buffer,size_t * lenp,loff_t * ppos)1007 static int proc_nmi_watchdog(const struct ctl_table *table, int write,
1008 void *buffer, size_t *lenp, loff_t *ppos)
1009 {
1010 if (!watchdog_hardlockup_available && write)
1011 return -ENOTSUPP;
1012 return proc_watchdog_common(WATCHDOG_HARDLOCKUP_ENABLED,
1013 table, write, buffer, lenp, ppos);
1014 }
1015
1016 #ifdef CONFIG_SOFTLOCKUP_DETECTOR
1017 /*
1018 * /proc/sys/kernel/soft_watchdog
1019 */
proc_soft_watchdog(const struct ctl_table * table,int write,void * buffer,size_t * lenp,loff_t * ppos)1020 static int proc_soft_watchdog(const struct ctl_table *table, int write,
1021 void *buffer, size_t *lenp, loff_t *ppos)
1022 {
1023 return proc_watchdog_common(WATCHDOG_SOFTOCKUP_ENABLED,
1024 table, write, buffer, lenp, ppos);
1025 }
1026 #endif
1027
1028 /*
1029 * /proc/sys/kernel/watchdog_thresh
1030 */
proc_watchdog_thresh(const struct ctl_table * table,int write,void * buffer,size_t * lenp,loff_t * ppos)1031 static int proc_watchdog_thresh(const struct ctl_table *table, int write,
1032 void *buffer, size_t *lenp, loff_t *ppos)
1033 {
1034 int err, old;
1035
1036 mutex_lock(&watchdog_mutex);
1037
1038 old = READ_ONCE(watchdog_thresh);
1039 err = proc_dointvec_minmax(table, write, buffer, lenp, ppos);
1040
1041 if (!err && write && old != READ_ONCE(watchdog_thresh))
1042 proc_watchdog_update();
1043
1044 mutex_unlock(&watchdog_mutex);
1045 return err;
1046 }
1047
1048 /*
1049 * The cpumask is the mask of possible cpus that the watchdog can run
1050 * on, not the mask of cpus it is actually running on. This allows the
1051 * user to specify a mask that will include cpus that have not yet
1052 * been brought online, if desired.
1053 */
proc_watchdog_cpumask(const struct ctl_table * table,int write,void * buffer,size_t * lenp,loff_t * ppos)1054 static int proc_watchdog_cpumask(const struct ctl_table *table, int write,
1055 void *buffer, size_t *lenp, loff_t *ppos)
1056 {
1057 int err;
1058
1059 mutex_lock(&watchdog_mutex);
1060
1061 err = proc_do_large_bitmap(table, write, buffer, lenp, ppos);
1062 if (!err && write)
1063 proc_watchdog_update();
1064
1065 mutex_unlock(&watchdog_mutex);
1066 return err;
1067 }
1068
1069 static const int sixty = 60;
1070
1071 static const struct ctl_table watchdog_sysctls[] = {
1072 {
1073 .procname = "watchdog",
1074 .data = &watchdog_user_enabled,
1075 .maxlen = sizeof(int),
1076 .mode = 0644,
1077 .proc_handler = proc_watchdog,
1078 .extra1 = SYSCTL_ZERO,
1079 .extra2 = SYSCTL_ONE,
1080 },
1081 {
1082 .procname = "watchdog_thresh",
1083 .data = &watchdog_thresh,
1084 .maxlen = sizeof(int),
1085 .mode = 0644,
1086 .proc_handler = proc_watchdog_thresh,
1087 .extra1 = SYSCTL_ZERO,
1088 .extra2 = (void *)&sixty,
1089 },
1090 {
1091 .procname = "watchdog_cpumask",
1092 .data = &watchdog_cpumask_bits,
1093 .maxlen = NR_CPUS,
1094 .mode = 0644,
1095 .proc_handler = proc_watchdog_cpumask,
1096 },
1097 #ifdef CONFIG_SOFTLOCKUP_DETECTOR
1098 {
1099 .procname = "soft_watchdog",
1100 .data = &watchdog_softlockup_user_enabled,
1101 .maxlen = sizeof(int),
1102 .mode = 0644,
1103 .proc_handler = proc_soft_watchdog,
1104 .extra1 = SYSCTL_ZERO,
1105 .extra2 = SYSCTL_ONE,
1106 },
1107 {
1108 .procname = "softlockup_panic",
1109 .data = &softlockup_panic,
1110 .maxlen = sizeof(int),
1111 .mode = 0644,
1112 .proc_handler = proc_dointvec_minmax,
1113 .extra1 = SYSCTL_ZERO,
1114 .extra2 = SYSCTL_ONE,
1115 },
1116 #ifdef CONFIG_SMP
1117 {
1118 .procname = "softlockup_all_cpu_backtrace",
1119 .data = &sysctl_softlockup_all_cpu_backtrace,
1120 .maxlen = sizeof(int),
1121 .mode = 0644,
1122 .proc_handler = proc_dointvec_minmax,
1123 .extra1 = SYSCTL_ZERO,
1124 .extra2 = SYSCTL_ONE,
1125 },
1126 #endif /* CONFIG_SMP */
1127 #endif
1128 #ifdef CONFIG_HARDLOCKUP_DETECTOR
1129 {
1130 .procname = "hardlockup_panic",
1131 .data = &hardlockup_panic,
1132 .maxlen = sizeof(int),
1133 .mode = 0644,
1134 .proc_handler = proc_dointvec_minmax,
1135 .extra1 = SYSCTL_ZERO,
1136 .extra2 = SYSCTL_ONE,
1137 },
1138 #ifdef CONFIG_SMP
1139 {
1140 .procname = "hardlockup_all_cpu_backtrace",
1141 .data = &sysctl_hardlockup_all_cpu_backtrace,
1142 .maxlen = sizeof(int),
1143 .mode = 0644,
1144 .proc_handler = proc_dointvec_minmax,
1145 .extra1 = SYSCTL_ZERO,
1146 .extra2 = SYSCTL_ONE,
1147 },
1148 #endif /* CONFIG_SMP */
1149 #endif
1150 };
1151
1152 static struct ctl_table watchdog_hardlockup_sysctl[] = {
1153 {
1154 .procname = "nmi_watchdog",
1155 .data = &watchdog_hardlockup_user_enabled,
1156 .maxlen = sizeof(int),
1157 .mode = 0444,
1158 .proc_handler = proc_nmi_watchdog,
1159 .extra1 = SYSCTL_ZERO,
1160 .extra2 = SYSCTL_ONE,
1161 },
1162 };
1163
watchdog_sysctl_init(void)1164 static void __init watchdog_sysctl_init(void)
1165 {
1166 register_sysctl_init("kernel", watchdog_sysctls);
1167
1168 if (watchdog_hardlockup_available)
1169 watchdog_hardlockup_sysctl[0].mode = 0644;
1170 register_sysctl_init("kernel", watchdog_hardlockup_sysctl);
1171 }
1172
1173 #else
1174 #define watchdog_sysctl_init() do { } while (0)
1175 #endif /* CONFIG_SYSCTL */
1176
1177 static void __init lockup_detector_delay_init(struct work_struct *work);
1178 static bool allow_lockup_detector_init_retry __initdata;
1179
1180 static struct work_struct detector_work __initdata =
1181 __WORK_INITIALIZER(detector_work, lockup_detector_delay_init);
1182
lockup_detector_delay_init(struct work_struct * work)1183 static void __init lockup_detector_delay_init(struct work_struct *work)
1184 {
1185 int ret;
1186
1187 ret = watchdog_hardlockup_probe();
1188 if (ret) {
1189 if (ret == -ENODEV)
1190 pr_info("NMI not fully supported\n");
1191 else
1192 pr_info("Delayed init of the lockup detector failed: %d\n", ret);
1193 pr_info("Hard watchdog permanently disabled\n");
1194 return;
1195 }
1196
1197 allow_lockup_detector_init_retry = false;
1198
1199 watchdog_hardlockup_available = true;
1200 lockup_detector_setup();
1201 }
1202
1203 /*
1204 * lockup_detector_retry_init - retry init lockup detector if possible.
1205 *
1206 * Retry hardlockup detector init. It is useful when it requires some
1207 * functionality that has to be initialized later on a particular
1208 * platform.
1209 */
lockup_detector_retry_init(void)1210 void __init lockup_detector_retry_init(void)
1211 {
1212 /* Must be called before late init calls */
1213 if (!allow_lockup_detector_init_retry)
1214 return;
1215
1216 schedule_work(&detector_work);
1217 }
1218
1219 /*
1220 * Ensure that optional delayed hardlockup init is proceed before
1221 * the init code and memory is freed.
1222 */
lockup_detector_check(void)1223 static int __init lockup_detector_check(void)
1224 {
1225 /* Prevent any later retry. */
1226 allow_lockup_detector_init_retry = false;
1227
1228 /* Make sure no work is pending. */
1229 flush_work(&detector_work);
1230
1231 watchdog_sysctl_init();
1232
1233 return 0;
1234
1235 }
1236 late_initcall_sync(lockup_detector_check);
1237
lockup_detector_init(void)1238 void __init lockup_detector_init(void)
1239 {
1240 if (tick_nohz_full_enabled())
1241 pr_info("Disabling watchdog on nohz_full cores by default\n");
1242
1243 cpumask_copy(&watchdog_cpumask,
1244 housekeeping_cpumask(HK_TYPE_TIMER));
1245
1246 if (!watchdog_hardlockup_probe())
1247 watchdog_hardlockup_available = true;
1248 else
1249 allow_lockup_detector_init_retry = true;
1250
1251 lockup_detector_setup();
1252 }
1253