1 // SPDX-License-Identifier: GPL-2.0
2 /*
3 * Detect hard and soft lockups on a system
4 *
5 * started by Don Zickus, Copyright (C) 2010 Red Hat, Inc.
6 *
7 * Note: Most of this code is borrowed heavily from the original softlockup
8 * detector, so thanks to Ingo for the initial implementation.
9 * Some chunks also taken from the old x86-specific nmi watchdog code, thanks
10 * to those contributors as well.
11 */
12
13 #define pr_fmt(fmt) "watchdog: " fmt
14
15 #include <linux/cpu.h>
16 #include <linux/init.h>
17 #include <linux/irq.h>
18 #include <linux/irqdesc.h>
19 #include <linux/kernel_stat.h>
20 #include <linux/kvm_para.h>
21 #include <linux/math64.h>
22 #include <linux/mm.h>
23 #include <linux/module.h>
24 #include <linux/nmi.h>
25 #include <linux/stop_machine.h>
26 #include <linux/sysctl.h>
27 #include <linux/tick.h>
28
29 #include <linux/sched/clock.h>
30 #include <linux/sched/debug.h>
31 #include <linux/sched/isolation.h>
32
33 #include <asm/irq_regs.h>
34
35 static DEFINE_MUTEX(watchdog_mutex);
36
37 #if defined(CONFIG_HARDLOCKUP_DETECTOR) || defined(CONFIG_HARDLOCKUP_DETECTOR_SPARC64)
38 # define WATCHDOG_HARDLOCKUP_DEFAULT 1
39 #else
40 # define WATCHDOG_HARDLOCKUP_DEFAULT 0
41 #endif
42
43 #define NUM_SAMPLE_PERIODS 5
44
45 unsigned long __read_mostly watchdog_enabled;
46 int __read_mostly watchdog_user_enabled = 1;
47 static int __read_mostly watchdog_hardlockup_user_enabled = WATCHDOG_HARDLOCKUP_DEFAULT;
48 static int __read_mostly watchdog_softlockup_user_enabled = 1;
49 int __read_mostly watchdog_thresh = 10;
50 static int __read_mostly watchdog_hardlockup_available;
51
52 struct cpumask watchdog_cpumask __read_mostly;
53 unsigned long *watchdog_cpumask_bits = cpumask_bits(&watchdog_cpumask);
54
55 #ifdef CONFIG_HARDLOCKUP_DETECTOR
56
57 # ifdef CONFIG_SMP
58 int __read_mostly sysctl_hardlockup_all_cpu_backtrace;
59 # endif /* CONFIG_SMP */
60
61 /*
62 * Should we panic when a soft-lockup or hard-lockup occurs:
63 */
64 unsigned int __read_mostly hardlockup_panic =
65 IS_ENABLED(CONFIG_BOOTPARAM_HARDLOCKUP_PANIC);
66 /*
67 * We may not want to enable hard lockup detection by default in all cases,
68 * for example when running the kernel as a guest on a hypervisor. In these
69 * cases this function can be called to disable hard lockup detection. This
70 * function should only be executed once by the boot processor before the
71 * kernel command line parameters are parsed, because otherwise it is not
72 * possible to override this in hardlockup_panic_setup().
73 */
hardlockup_detector_disable(void)74 void __init hardlockup_detector_disable(void)
75 {
76 watchdog_hardlockup_user_enabled = 0;
77 }
78
hardlockup_panic_setup(char * str)79 static int __init hardlockup_panic_setup(char *str)
80 {
81 next:
82 if (!strncmp(str, "panic", 5))
83 hardlockup_panic = 1;
84 else if (!strncmp(str, "nopanic", 7))
85 hardlockup_panic = 0;
86 else if (!strncmp(str, "0", 1))
87 watchdog_hardlockup_user_enabled = 0;
88 else if (!strncmp(str, "1", 1))
89 watchdog_hardlockup_user_enabled = 1;
90 else if (!strncmp(str, "r", 1))
91 hardlockup_config_perf_event(str + 1);
92 while (*(str++)) {
93 if (*str == ',') {
94 str++;
95 goto next;
96 }
97 }
98 return 1;
99 }
100 __setup("nmi_watchdog=", hardlockup_panic_setup);
101
102 #endif /* CONFIG_HARDLOCKUP_DETECTOR */
103
104 #if defined(CONFIG_HARDLOCKUP_DETECTOR_COUNTS_HRTIMER)
105
106 static DEFINE_PER_CPU(atomic_t, hrtimer_interrupts);
107 static DEFINE_PER_CPU(int, hrtimer_interrupts_saved);
108 static DEFINE_PER_CPU(bool, watchdog_hardlockup_warned);
109 static DEFINE_PER_CPU(bool, watchdog_hardlockup_touched);
110 static unsigned long hard_lockup_nmi_warn;
111
arch_touch_nmi_watchdog(void)112 notrace void arch_touch_nmi_watchdog(void)
113 {
114 /*
115 * Using __raw here because some code paths have
116 * preemption enabled. If preemption is enabled
117 * then interrupts should be enabled too, in which
118 * case we shouldn't have to worry about the watchdog
119 * going off.
120 */
121 raw_cpu_write(watchdog_hardlockup_touched, true);
122 }
123 EXPORT_SYMBOL(arch_touch_nmi_watchdog);
124
watchdog_hardlockup_touch_cpu(unsigned int cpu)125 void watchdog_hardlockup_touch_cpu(unsigned int cpu)
126 {
127 per_cpu(watchdog_hardlockup_touched, cpu) = true;
128 }
129
is_hardlockup(unsigned int cpu)130 static bool is_hardlockup(unsigned int cpu)
131 {
132 int hrint = atomic_read(&per_cpu(hrtimer_interrupts, cpu));
133
134 if (per_cpu(hrtimer_interrupts_saved, cpu) == hrint)
135 return true;
136
137 /*
138 * NOTE: we don't need any fancy atomic_t or READ_ONCE/WRITE_ONCE
139 * for hrtimer_interrupts_saved. hrtimer_interrupts_saved is
140 * written/read by a single CPU.
141 */
142 per_cpu(hrtimer_interrupts_saved, cpu) = hrint;
143
144 return false;
145 }
146
watchdog_hardlockup_kick(void)147 static void watchdog_hardlockup_kick(void)
148 {
149 int new_interrupts;
150
151 new_interrupts = atomic_inc_return(this_cpu_ptr(&hrtimer_interrupts));
152 watchdog_buddy_check_hardlockup(new_interrupts);
153 }
154
watchdog_hardlockup_check(unsigned int cpu,struct pt_regs * regs)155 void watchdog_hardlockup_check(unsigned int cpu, struct pt_regs *regs)
156 {
157 if (per_cpu(watchdog_hardlockup_touched, cpu)) {
158 per_cpu(watchdog_hardlockup_touched, cpu) = false;
159 return;
160 }
161
162 /*
163 * Check for a hardlockup by making sure the CPU's timer
164 * interrupt is incrementing. The timer interrupt should have
165 * fired multiple times before we overflow'd. If it hasn't
166 * then this is a good indication the cpu is stuck
167 */
168 if (is_hardlockup(cpu)) {
169 unsigned int this_cpu = smp_processor_id();
170 unsigned long flags;
171
172 /* Only print hardlockups once. */
173 if (per_cpu(watchdog_hardlockup_warned, cpu))
174 return;
175
176 /*
177 * Prevent multiple hard-lockup reports if one cpu is already
178 * engaged in dumping all cpu back traces.
179 */
180 if (sysctl_hardlockup_all_cpu_backtrace) {
181 if (test_and_set_bit_lock(0, &hard_lockup_nmi_warn))
182 return;
183 }
184
185 /*
186 * NOTE: we call printk_cpu_sync_get_irqsave() after printing
187 * the lockup message. While it would be nice to serialize
188 * that printout, we really want to make sure that if some
189 * other CPU somehow locked up while holding the lock associated
190 * with printk_cpu_sync_get_irqsave() that we can still at least
191 * get the message about the lockup out.
192 */
193 pr_emerg("CPU%u: Watchdog detected hard LOCKUP on cpu %u\n", this_cpu, cpu);
194 printk_cpu_sync_get_irqsave(flags);
195
196 print_modules();
197 print_irqtrace_events(current);
198 if (cpu == this_cpu) {
199 if (regs)
200 show_regs(regs);
201 else
202 dump_stack();
203 printk_cpu_sync_put_irqrestore(flags);
204 } else {
205 printk_cpu_sync_put_irqrestore(flags);
206 trigger_single_cpu_backtrace(cpu);
207 }
208
209 if (sysctl_hardlockup_all_cpu_backtrace) {
210 trigger_allbutcpu_cpu_backtrace(cpu);
211 if (!hardlockup_panic)
212 clear_bit_unlock(0, &hard_lockup_nmi_warn);
213 }
214
215 if (hardlockup_panic)
216 nmi_panic(regs, "Hard LOCKUP");
217
218 per_cpu(watchdog_hardlockup_warned, cpu) = true;
219 } else {
220 per_cpu(watchdog_hardlockup_warned, cpu) = false;
221 }
222 }
223
224 #else /* CONFIG_HARDLOCKUP_DETECTOR_COUNTS_HRTIMER */
225
watchdog_hardlockup_kick(void)226 static inline void watchdog_hardlockup_kick(void) { }
227
228 #endif /* !CONFIG_HARDLOCKUP_DETECTOR_COUNTS_HRTIMER */
229
230 /*
231 * These functions can be overridden based on the configured hardlockdup detector.
232 *
233 * watchdog_hardlockup_enable/disable can be implemented to start and stop when
234 * softlockup watchdog start and stop. The detector must select the
235 * SOFTLOCKUP_DETECTOR Kconfig.
236 */
watchdog_hardlockup_enable(unsigned int cpu)237 void __weak watchdog_hardlockup_enable(unsigned int cpu) { }
238
watchdog_hardlockup_disable(unsigned int cpu)239 void __weak watchdog_hardlockup_disable(unsigned int cpu) { }
240
241 /*
242 * Watchdog-detector specific API.
243 *
244 * Return 0 when hardlockup watchdog is available, negative value otherwise.
245 * Note that the negative value means that a delayed probe might
246 * succeed later.
247 */
watchdog_hardlockup_probe(void)248 int __weak __init watchdog_hardlockup_probe(void)
249 {
250 return -ENODEV;
251 }
252
253 /**
254 * watchdog_hardlockup_stop - Stop the watchdog for reconfiguration
255 *
256 * The reconfiguration steps are:
257 * watchdog_hardlockup_stop();
258 * update_variables();
259 * watchdog_hardlockup_start();
260 */
watchdog_hardlockup_stop(void)261 void __weak watchdog_hardlockup_stop(void) { }
262
263 /**
264 * watchdog_hardlockup_start - Start the watchdog after reconfiguration
265 *
266 * Counterpart to watchdog_hardlockup_stop().
267 *
268 * The following variables have been updated in update_variables() and
269 * contain the currently valid configuration:
270 * - watchdog_enabled
271 * - watchdog_thresh
272 * - watchdog_cpumask
273 */
watchdog_hardlockup_start(void)274 void __weak watchdog_hardlockup_start(void) { }
275
276 /**
277 * lockup_detector_update_enable - Update the sysctl enable bit
278 *
279 * Caller needs to make sure that the hard watchdogs are off, so this
280 * can't race with watchdog_hardlockup_disable().
281 */
lockup_detector_update_enable(void)282 static void lockup_detector_update_enable(void)
283 {
284 watchdog_enabled = 0;
285 if (!watchdog_user_enabled)
286 return;
287 if (watchdog_hardlockup_available && watchdog_hardlockup_user_enabled)
288 watchdog_enabled |= WATCHDOG_HARDLOCKUP_ENABLED;
289 if (watchdog_softlockup_user_enabled)
290 watchdog_enabled |= WATCHDOG_SOFTOCKUP_ENABLED;
291 }
292
293 #ifdef CONFIG_SOFTLOCKUP_DETECTOR
294
295 /*
296 * Delay the soflockup report when running a known slow code.
297 * It does _not_ affect the timestamp of the last successdul reschedule.
298 */
299 #define SOFTLOCKUP_DELAY_REPORT ULONG_MAX
300
301 #ifdef CONFIG_SMP
302 int __read_mostly sysctl_softlockup_all_cpu_backtrace;
303 #endif
304
305 static struct cpumask watchdog_allowed_mask __read_mostly;
306
307 /* Global variables, exported for sysctl */
308 unsigned int __read_mostly softlockup_panic =
309 IS_ENABLED(CONFIG_BOOTPARAM_SOFTLOCKUP_PANIC);
310
311 static bool softlockup_initialized __read_mostly;
312 static u64 __read_mostly sample_period;
313
314 /* Timestamp taken after the last successful reschedule. */
315 static DEFINE_PER_CPU(unsigned long, watchdog_touch_ts);
316 /* Timestamp of the last softlockup report. */
317 static DEFINE_PER_CPU(unsigned long, watchdog_report_ts);
318 static DEFINE_PER_CPU(struct hrtimer, watchdog_hrtimer);
319 static DEFINE_PER_CPU(bool, softlockup_touch_sync);
320 static unsigned long soft_lockup_nmi_warn;
321
softlockup_panic_setup(char * str)322 static int __init softlockup_panic_setup(char *str)
323 {
324 softlockup_panic = simple_strtoul(str, NULL, 0);
325 return 1;
326 }
327 __setup("softlockup_panic=", softlockup_panic_setup);
328
nowatchdog_setup(char * str)329 static int __init nowatchdog_setup(char *str)
330 {
331 watchdog_user_enabled = 0;
332 return 1;
333 }
334 __setup("nowatchdog", nowatchdog_setup);
335
nosoftlockup_setup(char * str)336 static int __init nosoftlockup_setup(char *str)
337 {
338 watchdog_softlockup_user_enabled = 0;
339 return 1;
340 }
341 __setup("nosoftlockup", nosoftlockup_setup);
342
watchdog_thresh_setup(char * str)343 static int __init watchdog_thresh_setup(char *str)
344 {
345 get_option(&str, &watchdog_thresh);
346 return 1;
347 }
348 __setup("watchdog_thresh=", watchdog_thresh_setup);
349
350 #ifdef CONFIG_SOFTLOCKUP_DETECTOR_INTR_STORM
351 enum stats_per_group {
352 STATS_SYSTEM,
353 STATS_SOFTIRQ,
354 STATS_HARDIRQ,
355 STATS_IDLE,
356 NUM_STATS_PER_GROUP,
357 };
358
359 static const enum cpu_usage_stat tracked_stats[NUM_STATS_PER_GROUP] = {
360 CPUTIME_SYSTEM,
361 CPUTIME_SOFTIRQ,
362 CPUTIME_IRQ,
363 CPUTIME_IDLE,
364 };
365
366 static DEFINE_PER_CPU(u16, cpustat_old[NUM_STATS_PER_GROUP]);
367 static DEFINE_PER_CPU(u8, cpustat_util[NUM_SAMPLE_PERIODS][NUM_STATS_PER_GROUP]);
368 static DEFINE_PER_CPU(u8, cpustat_tail);
369
370 /*
371 * We don't need nanosecond resolution. A granularity of 16ms is
372 * sufficient for our precision, allowing us to use u16 to store
373 * cpustats, which will roll over roughly every ~1000 seconds.
374 * 2^24 ~= 16 * 10^6
375 */
get_16bit_precision(u64 data_ns)376 static u16 get_16bit_precision(u64 data_ns)
377 {
378 return data_ns >> 24LL; /* 2^24ns ~= 16.8ms */
379 }
380
update_cpustat(void)381 static void update_cpustat(void)
382 {
383 int i;
384 u8 util;
385 u16 old_stat, new_stat;
386 struct kernel_cpustat kcpustat;
387 u64 *cpustat = kcpustat.cpustat;
388 u8 tail = __this_cpu_read(cpustat_tail);
389 u16 sample_period_16 = get_16bit_precision(sample_period);
390
391 kcpustat_cpu_fetch(&kcpustat, smp_processor_id());
392
393 for (i = 0; i < NUM_STATS_PER_GROUP; i++) {
394 old_stat = __this_cpu_read(cpustat_old[i]);
395 new_stat = get_16bit_precision(cpustat[tracked_stats[i]]);
396 util = DIV_ROUND_UP(100 * (new_stat - old_stat), sample_period_16);
397 __this_cpu_write(cpustat_util[tail][i], util);
398 __this_cpu_write(cpustat_old[i], new_stat);
399 }
400
401 __this_cpu_write(cpustat_tail, (tail + 1) % NUM_SAMPLE_PERIODS);
402 }
403
print_cpustat(void)404 static void print_cpustat(void)
405 {
406 int i, group;
407 u8 tail = __this_cpu_read(cpustat_tail);
408 u64 sample_period_second = sample_period;
409
410 do_div(sample_period_second, NSEC_PER_SEC);
411
412 /*
413 * Outputting the "watchdog" prefix on every line is redundant and not
414 * concise, and the original alarm information is sufficient for
415 * positioning in logs, hence here printk() is used instead of pr_crit().
416 */
417 printk(KERN_CRIT "CPU#%d Utilization every %llus during lockup:\n",
418 smp_processor_id(), sample_period_second);
419
420 for (i = 0; i < NUM_SAMPLE_PERIODS; i++) {
421 group = (tail + i) % NUM_SAMPLE_PERIODS;
422 printk(KERN_CRIT "\t#%d: %3u%% system,\t%3u%% softirq,\t"
423 "%3u%% hardirq,\t%3u%% idle\n", i + 1,
424 __this_cpu_read(cpustat_util[group][STATS_SYSTEM]),
425 __this_cpu_read(cpustat_util[group][STATS_SOFTIRQ]),
426 __this_cpu_read(cpustat_util[group][STATS_HARDIRQ]),
427 __this_cpu_read(cpustat_util[group][STATS_IDLE]));
428 }
429 }
430
431 #define HARDIRQ_PERCENT_THRESH 50
432 #define NUM_HARDIRQ_REPORT 5
433 struct irq_counts {
434 int irq;
435 u32 counts;
436 };
437
438 static DEFINE_PER_CPU(bool, snapshot_taken);
439
440 /* Tabulate the most frequent interrupts. */
tabulate_irq_count(struct irq_counts * irq_counts,int irq,u32 counts,int rank)441 static void tabulate_irq_count(struct irq_counts *irq_counts, int irq, u32 counts, int rank)
442 {
443 int i;
444 struct irq_counts new_count = {irq, counts};
445
446 for (i = 0; i < rank; i++) {
447 if (counts > irq_counts[i].counts)
448 swap(new_count, irq_counts[i]);
449 }
450 }
451
452 /*
453 * If the hardirq time exceeds HARDIRQ_PERCENT_THRESH% of the sample_period,
454 * then the cause of softlockup might be interrupt storm. In this case, it
455 * would be useful to start interrupt counting.
456 */
need_counting_irqs(void)457 static bool need_counting_irqs(void)
458 {
459 u8 util;
460 int tail = __this_cpu_read(cpustat_tail);
461
462 tail = (tail + NUM_HARDIRQ_REPORT - 1) % NUM_HARDIRQ_REPORT;
463 util = __this_cpu_read(cpustat_util[tail][STATS_HARDIRQ]);
464 return util > HARDIRQ_PERCENT_THRESH;
465 }
466
start_counting_irqs(void)467 static void start_counting_irqs(void)
468 {
469 if (!__this_cpu_read(snapshot_taken)) {
470 kstat_snapshot_irqs();
471 __this_cpu_write(snapshot_taken, true);
472 }
473 }
474
stop_counting_irqs(void)475 static void stop_counting_irqs(void)
476 {
477 __this_cpu_write(snapshot_taken, false);
478 }
479
print_irq_counts(void)480 static void print_irq_counts(void)
481 {
482 unsigned int i, count;
483 struct irq_counts irq_counts_sorted[NUM_HARDIRQ_REPORT] = {
484 {-1, 0}, {-1, 0}, {-1, 0}, {-1, 0}, {-1, 0}
485 };
486
487 if (__this_cpu_read(snapshot_taken)) {
488 for_each_active_irq(i) {
489 count = kstat_get_irq_since_snapshot(i);
490 tabulate_irq_count(irq_counts_sorted, i, count, NUM_HARDIRQ_REPORT);
491 }
492
493 /*
494 * Outputting the "watchdog" prefix on every line is redundant and not
495 * concise, and the original alarm information is sufficient for
496 * positioning in logs, hence here printk() is used instead of pr_crit().
497 */
498 printk(KERN_CRIT "CPU#%d Detect HardIRQ Time exceeds %d%%. Most frequent HardIRQs:\n",
499 smp_processor_id(), HARDIRQ_PERCENT_THRESH);
500
501 for (i = 0; i < NUM_HARDIRQ_REPORT; i++) {
502 if (irq_counts_sorted[i].irq == -1)
503 break;
504
505 printk(KERN_CRIT "\t#%u: %-10u\tirq#%d\n",
506 i + 1, irq_counts_sorted[i].counts,
507 irq_counts_sorted[i].irq);
508 }
509
510 /*
511 * If the hardirq time is less than HARDIRQ_PERCENT_THRESH% in the last
512 * sample_period, then we suspect the interrupt storm might be subsiding.
513 */
514 if (!need_counting_irqs())
515 stop_counting_irqs();
516 }
517 }
518
report_cpu_status(void)519 static void report_cpu_status(void)
520 {
521 print_cpustat();
522 print_irq_counts();
523 }
524 #else
update_cpustat(void)525 static inline void update_cpustat(void) { }
report_cpu_status(void)526 static inline void report_cpu_status(void) { }
need_counting_irqs(void)527 static inline bool need_counting_irqs(void) { return false; }
start_counting_irqs(void)528 static inline void start_counting_irqs(void) { }
stop_counting_irqs(void)529 static inline void stop_counting_irqs(void) { }
530 #endif
531
532 /*
533 * Hard-lockup warnings should be triggered after just a few seconds. Soft-
534 * lockups can have false positives under extreme conditions. So we generally
535 * want a higher threshold for soft lockups than for hard lockups. So we couple
536 * the thresholds with a factor: we make the soft threshold twice the amount of
537 * time the hard threshold is.
538 */
get_softlockup_thresh(void)539 static int get_softlockup_thresh(void)
540 {
541 return watchdog_thresh * 2;
542 }
543
544 /*
545 * Returns seconds, approximately. We don't need nanosecond
546 * resolution, and we don't need to waste time with a big divide when
547 * 2^30ns == 1.074s.
548 */
get_timestamp(void)549 static unsigned long get_timestamp(void)
550 {
551 return running_clock() >> 30LL; /* 2^30 ~= 10^9 */
552 }
553
set_sample_period(void)554 static void set_sample_period(void)
555 {
556 /*
557 * convert watchdog_thresh from seconds to ns
558 * the divide by 5 is to give hrtimer several chances (two
559 * or three with the current relation between the soft
560 * and hard thresholds) to increment before the
561 * hardlockup detector generates a warning
562 */
563 sample_period = get_softlockup_thresh() * ((u64)NSEC_PER_SEC / NUM_SAMPLE_PERIODS);
564 watchdog_update_hrtimer_threshold(sample_period);
565 }
566
update_report_ts(void)567 static void update_report_ts(void)
568 {
569 __this_cpu_write(watchdog_report_ts, get_timestamp());
570 }
571
572 /* Commands for resetting the watchdog */
update_touch_ts(void)573 static void update_touch_ts(void)
574 {
575 __this_cpu_write(watchdog_touch_ts, get_timestamp());
576 update_report_ts();
577 }
578
579 /**
580 * touch_softlockup_watchdog_sched - touch watchdog on scheduler stalls
581 *
582 * Call when the scheduler may have stalled for legitimate reasons
583 * preventing the watchdog task from executing - e.g. the scheduler
584 * entering idle state. This should only be used for scheduler events.
585 * Use touch_softlockup_watchdog() for everything else.
586 */
touch_softlockup_watchdog_sched(void)587 notrace void touch_softlockup_watchdog_sched(void)
588 {
589 /*
590 * Preemption can be enabled. It doesn't matter which CPU's watchdog
591 * report period gets restarted here, so use the raw_ operation.
592 */
593 raw_cpu_write(watchdog_report_ts, SOFTLOCKUP_DELAY_REPORT);
594 }
595
touch_softlockup_watchdog(void)596 notrace void touch_softlockup_watchdog(void)
597 {
598 touch_softlockup_watchdog_sched();
599 wq_watchdog_touch(raw_smp_processor_id());
600 }
601 EXPORT_SYMBOL(touch_softlockup_watchdog);
602
touch_all_softlockup_watchdogs(void)603 void touch_all_softlockup_watchdogs(void)
604 {
605 int cpu;
606
607 /*
608 * watchdog_mutex cannpt be taken here, as this might be called
609 * from (soft)interrupt context, so the access to
610 * watchdog_allowed_cpumask might race with a concurrent update.
611 *
612 * The watchdog time stamp can race against a concurrent real
613 * update as well, the only side effect might be a cycle delay for
614 * the softlockup check.
615 */
616 for_each_cpu(cpu, &watchdog_allowed_mask) {
617 per_cpu(watchdog_report_ts, cpu) = SOFTLOCKUP_DELAY_REPORT;
618 wq_watchdog_touch(cpu);
619 }
620 }
621
touch_softlockup_watchdog_sync(void)622 void touch_softlockup_watchdog_sync(void)
623 {
624 __this_cpu_write(softlockup_touch_sync, true);
625 __this_cpu_write(watchdog_report_ts, SOFTLOCKUP_DELAY_REPORT);
626 }
627
is_softlockup(unsigned long touch_ts,unsigned long period_ts,unsigned long now)628 static int is_softlockup(unsigned long touch_ts,
629 unsigned long period_ts,
630 unsigned long now)
631 {
632 if ((watchdog_enabled & WATCHDOG_SOFTOCKUP_ENABLED) && watchdog_thresh) {
633 /*
634 * If period_ts has not been updated during a sample_period, then
635 * in the subsequent few sample_periods, period_ts might also not
636 * be updated, which could indicate a potential softlockup. In
637 * this case, if we suspect the cause of the potential softlockup
638 * might be interrupt storm, then we need to count the interrupts
639 * to find which interrupt is storming.
640 */
641 if (time_after_eq(now, period_ts + get_softlockup_thresh() / NUM_SAMPLE_PERIODS) &&
642 need_counting_irqs())
643 start_counting_irqs();
644
645 /*
646 * A poorly behaving BPF scheduler can live-lock the system into
647 * soft lockups. Tell sched_ext to try ejecting the BPF
648 * scheduler when close to a soft lockup.
649 */
650 if (time_after_eq(now, period_ts + get_softlockup_thresh() * 3 / 4))
651 scx_softlockup(now - touch_ts);
652
653 /* Warn about unreasonable delays. */
654 if (time_after(now, period_ts + get_softlockup_thresh()))
655 return now - touch_ts;
656 }
657 return 0;
658 }
659
660 /* watchdog detector functions */
661 static DEFINE_PER_CPU(struct completion, softlockup_completion);
662 static DEFINE_PER_CPU(struct cpu_stop_work, softlockup_stop_work);
663
664 /*
665 * The watchdog feed function - touches the timestamp.
666 *
667 * It only runs once every sample_period seconds (4 seconds by
668 * default) to reset the softlockup timestamp. If this gets delayed
669 * for more than 2*watchdog_thresh seconds then the debug-printout
670 * triggers in watchdog_timer_fn().
671 */
softlockup_fn(void * data)672 static int softlockup_fn(void *data)
673 {
674 update_touch_ts();
675 stop_counting_irqs();
676 complete(this_cpu_ptr(&softlockup_completion));
677
678 return 0;
679 }
680
681 /* watchdog kicker functions */
watchdog_timer_fn(struct hrtimer * hrtimer)682 static enum hrtimer_restart watchdog_timer_fn(struct hrtimer *hrtimer)
683 {
684 unsigned long touch_ts, period_ts, now;
685 struct pt_regs *regs = get_irq_regs();
686 int duration;
687 int softlockup_all_cpu_backtrace = sysctl_softlockup_all_cpu_backtrace;
688 unsigned long flags;
689
690 if (!watchdog_enabled)
691 return HRTIMER_NORESTART;
692
693 watchdog_hardlockup_kick();
694
695 /* kick the softlockup detector */
696 if (completion_done(this_cpu_ptr(&softlockup_completion))) {
697 reinit_completion(this_cpu_ptr(&softlockup_completion));
698 stop_one_cpu_nowait(smp_processor_id(),
699 softlockup_fn, NULL,
700 this_cpu_ptr(&softlockup_stop_work));
701 }
702
703 /* .. and repeat */
704 hrtimer_forward_now(hrtimer, ns_to_ktime(sample_period));
705
706 /*
707 * Read the current timestamp first. It might become invalid anytime
708 * when a virtual machine is stopped by the host or when the watchog
709 * is touched from NMI.
710 */
711 now = get_timestamp();
712 /*
713 * If a virtual machine is stopped by the host it can look to
714 * the watchdog like a soft lockup. This function touches the watchdog.
715 */
716 kvm_check_and_clear_guest_paused();
717 /*
718 * The stored timestamp is comparable with @now only when not touched.
719 * It might get touched anytime from NMI. Make sure that is_softlockup()
720 * uses the same (valid) value.
721 */
722 period_ts = READ_ONCE(*this_cpu_ptr(&watchdog_report_ts));
723
724 update_cpustat();
725
726 /* Reset the interval when touched by known problematic code. */
727 if (period_ts == SOFTLOCKUP_DELAY_REPORT) {
728 if (unlikely(__this_cpu_read(softlockup_touch_sync))) {
729 /*
730 * If the time stamp was touched atomically
731 * make sure the scheduler tick is up to date.
732 */
733 __this_cpu_write(softlockup_touch_sync, false);
734 sched_clock_tick();
735 }
736
737 update_report_ts();
738 return HRTIMER_RESTART;
739 }
740
741 /* Check for a softlockup. */
742 touch_ts = __this_cpu_read(watchdog_touch_ts);
743 duration = is_softlockup(touch_ts, period_ts, now);
744 if (unlikely(duration)) {
745 /*
746 * Prevent multiple soft-lockup reports if one cpu is already
747 * engaged in dumping all cpu back traces.
748 */
749 if (softlockup_all_cpu_backtrace) {
750 if (test_and_set_bit_lock(0, &soft_lockup_nmi_warn))
751 return HRTIMER_RESTART;
752 }
753
754 /* Start period for the next softlockup warning. */
755 update_report_ts();
756
757 printk_cpu_sync_get_irqsave(flags);
758 pr_emerg("BUG: soft lockup - CPU#%d stuck for %us! [%s:%d]\n",
759 smp_processor_id(), duration,
760 current->comm, task_pid_nr(current));
761 report_cpu_status();
762 print_modules();
763 print_irqtrace_events(current);
764 if (regs)
765 show_regs(regs);
766 else
767 dump_stack();
768 printk_cpu_sync_put_irqrestore(flags);
769
770 if (softlockup_all_cpu_backtrace) {
771 trigger_allbutcpu_cpu_backtrace(smp_processor_id());
772 if (!softlockup_panic)
773 clear_bit_unlock(0, &soft_lockup_nmi_warn);
774 }
775
776 add_taint(TAINT_SOFTLOCKUP, LOCKDEP_STILL_OK);
777 if (softlockup_panic)
778 panic("softlockup: hung tasks");
779 }
780
781 return HRTIMER_RESTART;
782 }
783
watchdog_enable(unsigned int cpu)784 static void watchdog_enable(unsigned int cpu)
785 {
786 struct hrtimer *hrtimer = this_cpu_ptr(&watchdog_hrtimer);
787 struct completion *done = this_cpu_ptr(&softlockup_completion);
788
789 WARN_ON_ONCE(cpu != smp_processor_id());
790
791 init_completion(done);
792 complete(done);
793
794 /*
795 * Start the timer first to prevent the hardlockup watchdog triggering
796 * before the timer has a chance to fire.
797 */
798 hrtimer_init(hrtimer, CLOCK_MONOTONIC, HRTIMER_MODE_REL_HARD);
799 hrtimer->function = watchdog_timer_fn;
800 hrtimer_start(hrtimer, ns_to_ktime(sample_period),
801 HRTIMER_MODE_REL_PINNED_HARD);
802
803 /* Initialize timestamp */
804 update_touch_ts();
805 /* Enable the hardlockup detector */
806 if (watchdog_enabled & WATCHDOG_HARDLOCKUP_ENABLED)
807 watchdog_hardlockup_enable(cpu);
808 }
809
watchdog_disable(unsigned int cpu)810 static void watchdog_disable(unsigned int cpu)
811 {
812 struct hrtimer *hrtimer = this_cpu_ptr(&watchdog_hrtimer);
813
814 WARN_ON_ONCE(cpu != smp_processor_id());
815
816 /*
817 * Disable the hardlockup detector first. That prevents that a large
818 * delay between disabling the timer and disabling the hardlockup
819 * detector causes a false positive.
820 */
821 watchdog_hardlockup_disable(cpu);
822 hrtimer_cancel(hrtimer);
823 wait_for_completion(this_cpu_ptr(&softlockup_completion));
824 }
825
softlockup_stop_fn(void * data)826 static int softlockup_stop_fn(void *data)
827 {
828 watchdog_disable(smp_processor_id());
829 return 0;
830 }
831
softlockup_stop_all(void)832 static void softlockup_stop_all(void)
833 {
834 int cpu;
835
836 if (!softlockup_initialized)
837 return;
838
839 for_each_cpu(cpu, &watchdog_allowed_mask)
840 smp_call_on_cpu(cpu, softlockup_stop_fn, NULL, false);
841
842 cpumask_clear(&watchdog_allowed_mask);
843 }
844
softlockup_start_fn(void * data)845 static int softlockup_start_fn(void *data)
846 {
847 watchdog_enable(smp_processor_id());
848 return 0;
849 }
850
softlockup_start_all(void)851 static void softlockup_start_all(void)
852 {
853 int cpu;
854
855 cpumask_copy(&watchdog_allowed_mask, &watchdog_cpumask);
856 for_each_cpu(cpu, &watchdog_allowed_mask)
857 smp_call_on_cpu(cpu, softlockup_start_fn, NULL, false);
858 }
859
lockup_detector_online_cpu(unsigned int cpu)860 int lockup_detector_online_cpu(unsigned int cpu)
861 {
862 if (cpumask_test_cpu(cpu, &watchdog_allowed_mask))
863 watchdog_enable(cpu);
864 return 0;
865 }
866
lockup_detector_offline_cpu(unsigned int cpu)867 int lockup_detector_offline_cpu(unsigned int cpu)
868 {
869 if (cpumask_test_cpu(cpu, &watchdog_allowed_mask))
870 watchdog_disable(cpu);
871 return 0;
872 }
873
__lockup_detector_reconfigure(void)874 static void __lockup_detector_reconfigure(void)
875 {
876 cpus_read_lock();
877 watchdog_hardlockup_stop();
878
879 softlockup_stop_all();
880 set_sample_period();
881 lockup_detector_update_enable();
882 if (watchdog_enabled && watchdog_thresh)
883 softlockup_start_all();
884
885 watchdog_hardlockup_start();
886 cpus_read_unlock();
887 }
888
lockup_detector_reconfigure(void)889 void lockup_detector_reconfigure(void)
890 {
891 mutex_lock(&watchdog_mutex);
892 __lockup_detector_reconfigure();
893 mutex_unlock(&watchdog_mutex);
894 }
895
896 /*
897 * Create the watchdog infrastructure and configure the detector(s).
898 */
lockup_detector_setup(void)899 static __init void lockup_detector_setup(void)
900 {
901 /*
902 * If sysctl is off and watchdog got disabled on the command line,
903 * nothing to do here.
904 */
905 lockup_detector_update_enable();
906
907 if (!IS_ENABLED(CONFIG_SYSCTL) &&
908 !(watchdog_enabled && watchdog_thresh))
909 return;
910
911 mutex_lock(&watchdog_mutex);
912 __lockup_detector_reconfigure();
913 softlockup_initialized = true;
914 mutex_unlock(&watchdog_mutex);
915 }
916
917 #else /* CONFIG_SOFTLOCKUP_DETECTOR */
__lockup_detector_reconfigure(void)918 static void __lockup_detector_reconfigure(void)
919 {
920 cpus_read_lock();
921 watchdog_hardlockup_stop();
922 lockup_detector_update_enable();
923 watchdog_hardlockup_start();
924 cpus_read_unlock();
925 }
lockup_detector_reconfigure(void)926 void lockup_detector_reconfigure(void)
927 {
928 __lockup_detector_reconfigure();
929 }
lockup_detector_setup(void)930 static inline void lockup_detector_setup(void)
931 {
932 __lockup_detector_reconfigure();
933 }
934 #endif /* !CONFIG_SOFTLOCKUP_DETECTOR */
935
936 /**
937 * lockup_detector_soft_poweroff - Interface to stop lockup detector(s)
938 *
939 * Special interface for parisc. It prevents lockup detector warnings from
940 * the default pm_poweroff() function which busy loops forever.
941 */
lockup_detector_soft_poweroff(void)942 void lockup_detector_soft_poweroff(void)
943 {
944 watchdog_enabled = 0;
945 }
946
947 #ifdef CONFIG_SYSCTL
948
949 /* Propagate any changes to the watchdog infrastructure */
proc_watchdog_update(void)950 static void proc_watchdog_update(void)
951 {
952 /* Remove impossible cpus to keep sysctl output clean. */
953 cpumask_and(&watchdog_cpumask, &watchdog_cpumask, cpu_possible_mask);
954 __lockup_detector_reconfigure();
955 }
956
957 /*
958 * common function for watchdog, nmi_watchdog and soft_watchdog parameter
959 *
960 * caller | table->data points to | 'which'
961 * -------------------|----------------------------------|-------------------------------
962 * proc_watchdog | watchdog_user_enabled | WATCHDOG_HARDLOCKUP_ENABLED |
963 * | | WATCHDOG_SOFTOCKUP_ENABLED
964 * -------------------|----------------------------------|-------------------------------
965 * proc_nmi_watchdog | watchdog_hardlockup_user_enabled | WATCHDOG_HARDLOCKUP_ENABLED
966 * -------------------|----------------------------------|-------------------------------
967 * proc_soft_watchdog | watchdog_softlockup_user_enabled | WATCHDOG_SOFTOCKUP_ENABLED
968 */
proc_watchdog_common(int which,const struct ctl_table * table,int write,void * buffer,size_t * lenp,loff_t * ppos)969 static int proc_watchdog_common(int which, const struct ctl_table *table, int write,
970 void *buffer, size_t *lenp, loff_t *ppos)
971 {
972 int err, old, *param = table->data;
973
974 mutex_lock(&watchdog_mutex);
975
976 old = *param;
977 if (!write) {
978 /*
979 * On read synchronize the userspace interface. This is a
980 * racy snapshot.
981 */
982 *param = (watchdog_enabled & which) != 0;
983 err = proc_dointvec_minmax(table, write, buffer, lenp, ppos);
984 *param = old;
985 } else {
986 err = proc_dointvec_minmax(table, write, buffer, lenp, ppos);
987 if (!err && old != READ_ONCE(*param))
988 proc_watchdog_update();
989 }
990 mutex_unlock(&watchdog_mutex);
991 return err;
992 }
993
994 /*
995 * /proc/sys/kernel/watchdog
996 */
proc_watchdog(const struct ctl_table * table,int write,void * buffer,size_t * lenp,loff_t * ppos)997 static int proc_watchdog(const struct ctl_table *table, int write,
998 void *buffer, size_t *lenp, loff_t *ppos)
999 {
1000 return proc_watchdog_common(WATCHDOG_HARDLOCKUP_ENABLED |
1001 WATCHDOG_SOFTOCKUP_ENABLED,
1002 table, write, buffer, lenp, ppos);
1003 }
1004
1005 /*
1006 * /proc/sys/kernel/nmi_watchdog
1007 */
proc_nmi_watchdog(const struct ctl_table * table,int write,void * buffer,size_t * lenp,loff_t * ppos)1008 static int proc_nmi_watchdog(const struct ctl_table *table, int write,
1009 void *buffer, size_t *lenp, loff_t *ppos)
1010 {
1011 if (!watchdog_hardlockup_available && write)
1012 return -ENOTSUPP;
1013 return proc_watchdog_common(WATCHDOG_HARDLOCKUP_ENABLED,
1014 table, write, buffer, lenp, ppos);
1015 }
1016
1017 #ifdef CONFIG_SOFTLOCKUP_DETECTOR
1018 /*
1019 * /proc/sys/kernel/soft_watchdog
1020 */
proc_soft_watchdog(const struct ctl_table * table,int write,void * buffer,size_t * lenp,loff_t * ppos)1021 static int proc_soft_watchdog(const struct ctl_table *table, int write,
1022 void *buffer, size_t *lenp, loff_t *ppos)
1023 {
1024 return proc_watchdog_common(WATCHDOG_SOFTOCKUP_ENABLED,
1025 table, write, buffer, lenp, ppos);
1026 }
1027 #endif
1028
1029 /*
1030 * /proc/sys/kernel/watchdog_thresh
1031 */
proc_watchdog_thresh(const struct ctl_table * table,int write,void * buffer,size_t * lenp,loff_t * ppos)1032 static int proc_watchdog_thresh(const struct ctl_table *table, int write,
1033 void *buffer, size_t *lenp, loff_t *ppos)
1034 {
1035 int err, old;
1036
1037 mutex_lock(&watchdog_mutex);
1038
1039 old = READ_ONCE(watchdog_thresh);
1040 err = proc_dointvec_minmax(table, write, buffer, lenp, ppos);
1041
1042 if (!err && write && old != READ_ONCE(watchdog_thresh))
1043 proc_watchdog_update();
1044
1045 mutex_unlock(&watchdog_mutex);
1046 return err;
1047 }
1048
1049 /*
1050 * The cpumask is the mask of possible cpus that the watchdog can run
1051 * on, not the mask of cpus it is actually running on. This allows the
1052 * user to specify a mask that will include cpus that have not yet
1053 * been brought online, if desired.
1054 */
proc_watchdog_cpumask(const struct ctl_table * table,int write,void * buffer,size_t * lenp,loff_t * ppos)1055 static int proc_watchdog_cpumask(const struct ctl_table *table, int write,
1056 void *buffer, size_t *lenp, loff_t *ppos)
1057 {
1058 int err;
1059
1060 mutex_lock(&watchdog_mutex);
1061
1062 err = proc_do_large_bitmap(table, write, buffer, lenp, ppos);
1063 if (!err && write)
1064 proc_watchdog_update();
1065
1066 mutex_unlock(&watchdog_mutex);
1067 return err;
1068 }
1069
1070 static const int sixty = 60;
1071
1072 static const struct ctl_table watchdog_sysctls[] = {
1073 {
1074 .procname = "watchdog",
1075 .data = &watchdog_user_enabled,
1076 .maxlen = sizeof(int),
1077 .mode = 0644,
1078 .proc_handler = proc_watchdog,
1079 .extra1 = SYSCTL_ZERO,
1080 .extra2 = SYSCTL_ONE,
1081 },
1082 {
1083 .procname = "watchdog_thresh",
1084 .data = &watchdog_thresh,
1085 .maxlen = sizeof(int),
1086 .mode = 0644,
1087 .proc_handler = proc_watchdog_thresh,
1088 .extra1 = SYSCTL_ZERO,
1089 .extra2 = (void *)&sixty,
1090 },
1091 {
1092 .procname = "watchdog_cpumask",
1093 .data = &watchdog_cpumask_bits,
1094 .maxlen = NR_CPUS,
1095 .mode = 0644,
1096 .proc_handler = proc_watchdog_cpumask,
1097 },
1098 #ifdef CONFIG_SOFTLOCKUP_DETECTOR
1099 {
1100 .procname = "soft_watchdog",
1101 .data = &watchdog_softlockup_user_enabled,
1102 .maxlen = sizeof(int),
1103 .mode = 0644,
1104 .proc_handler = proc_soft_watchdog,
1105 .extra1 = SYSCTL_ZERO,
1106 .extra2 = SYSCTL_ONE,
1107 },
1108 {
1109 .procname = "softlockup_panic",
1110 .data = &softlockup_panic,
1111 .maxlen = sizeof(int),
1112 .mode = 0644,
1113 .proc_handler = proc_dointvec_minmax,
1114 .extra1 = SYSCTL_ZERO,
1115 .extra2 = SYSCTL_ONE,
1116 },
1117 #ifdef CONFIG_SMP
1118 {
1119 .procname = "softlockup_all_cpu_backtrace",
1120 .data = &sysctl_softlockup_all_cpu_backtrace,
1121 .maxlen = sizeof(int),
1122 .mode = 0644,
1123 .proc_handler = proc_dointvec_minmax,
1124 .extra1 = SYSCTL_ZERO,
1125 .extra2 = SYSCTL_ONE,
1126 },
1127 #endif /* CONFIG_SMP */
1128 #endif
1129 #ifdef CONFIG_HARDLOCKUP_DETECTOR
1130 {
1131 .procname = "hardlockup_panic",
1132 .data = &hardlockup_panic,
1133 .maxlen = sizeof(int),
1134 .mode = 0644,
1135 .proc_handler = proc_dointvec_minmax,
1136 .extra1 = SYSCTL_ZERO,
1137 .extra2 = SYSCTL_ONE,
1138 },
1139 #ifdef CONFIG_SMP
1140 {
1141 .procname = "hardlockup_all_cpu_backtrace",
1142 .data = &sysctl_hardlockup_all_cpu_backtrace,
1143 .maxlen = sizeof(int),
1144 .mode = 0644,
1145 .proc_handler = proc_dointvec_minmax,
1146 .extra1 = SYSCTL_ZERO,
1147 .extra2 = SYSCTL_ONE,
1148 },
1149 #endif /* CONFIG_SMP */
1150 #endif
1151 };
1152
1153 static struct ctl_table watchdog_hardlockup_sysctl[] = {
1154 {
1155 .procname = "nmi_watchdog",
1156 .data = &watchdog_hardlockup_user_enabled,
1157 .maxlen = sizeof(int),
1158 .mode = 0444,
1159 .proc_handler = proc_nmi_watchdog,
1160 .extra1 = SYSCTL_ZERO,
1161 .extra2 = SYSCTL_ONE,
1162 },
1163 };
1164
watchdog_sysctl_init(void)1165 static void __init watchdog_sysctl_init(void)
1166 {
1167 register_sysctl_init("kernel", watchdog_sysctls);
1168
1169 if (watchdog_hardlockup_available)
1170 watchdog_hardlockup_sysctl[0].mode = 0644;
1171 register_sysctl_init("kernel", watchdog_hardlockup_sysctl);
1172 }
1173
1174 #else
1175 #define watchdog_sysctl_init() do { } while (0)
1176 #endif /* CONFIG_SYSCTL */
1177
1178 static void __init lockup_detector_delay_init(struct work_struct *work);
1179 static bool allow_lockup_detector_init_retry __initdata;
1180
1181 static struct work_struct detector_work __initdata =
1182 __WORK_INITIALIZER(detector_work, lockup_detector_delay_init);
1183
lockup_detector_delay_init(struct work_struct * work)1184 static void __init lockup_detector_delay_init(struct work_struct *work)
1185 {
1186 int ret;
1187
1188 ret = watchdog_hardlockup_probe();
1189 if (ret) {
1190 if (ret == -ENODEV)
1191 pr_info("NMI not fully supported\n");
1192 else
1193 pr_info("Delayed init of the lockup detector failed: %d\n", ret);
1194 pr_info("Hard watchdog permanently disabled\n");
1195 return;
1196 }
1197
1198 allow_lockup_detector_init_retry = false;
1199
1200 watchdog_hardlockup_available = true;
1201 lockup_detector_setup();
1202 }
1203
1204 /*
1205 * lockup_detector_retry_init - retry init lockup detector if possible.
1206 *
1207 * Retry hardlockup detector init. It is useful when it requires some
1208 * functionality that has to be initialized later on a particular
1209 * platform.
1210 */
lockup_detector_retry_init(void)1211 void __init lockup_detector_retry_init(void)
1212 {
1213 /* Must be called before late init calls */
1214 if (!allow_lockup_detector_init_retry)
1215 return;
1216
1217 schedule_work(&detector_work);
1218 }
1219
1220 /*
1221 * Ensure that optional delayed hardlockup init is proceed before
1222 * the init code and memory is freed.
1223 */
lockup_detector_check(void)1224 static int __init lockup_detector_check(void)
1225 {
1226 /* Prevent any later retry. */
1227 allow_lockup_detector_init_retry = false;
1228
1229 /* Make sure no work is pending. */
1230 flush_work(&detector_work);
1231
1232 watchdog_sysctl_init();
1233
1234 return 0;
1235
1236 }
1237 late_initcall_sync(lockup_detector_check);
1238
lockup_detector_init(void)1239 void __init lockup_detector_init(void)
1240 {
1241 if (tick_nohz_full_enabled())
1242 pr_info("Disabling watchdog on nohz_full cores by default\n");
1243
1244 cpumask_copy(&watchdog_cpumask,
1245 housekeeping_cpumask(HK_TYPE_TIMER));
1246
1247 if (!watchdog_hardlockup_probe())
1248 watchdog_hardlockup_available = true;
1249 else
1250 allow_lockup_detector_init_retry = true;
1251
1252 lockup_detector_setup();
1253 }
1254