{"id":96086,"date":"2026-08-27T12:56:33","date_gmt":"2026-08-27T04:56:33","guid":{"rendered":"https:\/\/www.wsisp.com\/helps\/96086.html"},"modified":"2026-08-27T12:56:33","modified_gmt":"2026-08-27T04:56:33","slug":"%e5%ba%96%e4%b8%81%e8%a7%a3-vmcore-%c2%b7-%e7%ac%ac%e4%b8%83%e7%af%87-%c2%b7-%e7%bb%93%e5%96%89%e4%b9%8b%e5%a4%84%ef%bc%9a%e9%94%81%e4%b8%8e%e6%ad%bb%e9%94%81%e7%9a%84%e8%a7%a3%e5%89%96","status":"publish","type":"post","link":"https:\/\/www.wsisp.com\/helps\/96086.html","title":{"rendered":"\u5e96\u4e01\u89e3 vmCore \u00b7 \u7b2c\u4e03\u7bc7 \u00b7 \u7ed3\u5589\u4e4b\u5904\uff1a\u9501\u4e0e\u6b7b\u9501\u7684\u89e3\u5256"},"content":{"rendered":"<h2>\u5e96\u4e01\u89e3 vmCore \u5341\u7bc7 \u00b7 \u7b2c\u4e03\u7bc7 \u00b7 \u7ed3\u5589\u4e4b\u5904&#xff1a;\u9501\u4e0e\u6b7b\u9501\u7684\u89e3\u5256<\/h2>\n<p>\u5e96\u4e01\u66f0&#xff1a;\u6280\u7ecf\u80af\u7dae\u4e4b\u672a\u5c1d&#xff0c;\u800c\u51b5\u5927\u8ef1\u4e4e\u3002<br \/>\n\u9501\u8005&#xff0c;\u80af\u7dae\u4e5f&#xff1b;\u6b7b\u9501\u8005&#xff0c;\u80af\u7dae\u76f8\u7f20\u800c\u5200\u4e0d\u5f97\u5165\u4e5f\u3002<br \/>\nvmcore \u8005&#xff0c;\u7f20\u7ed3\u65e2\u6210\u4e4b\u5b9a\u5f71\u2014\u2014\u4f9d\u4e4e\u5929\u7406&#xff0c;\u6279\u5927\u90e4&#xff0c;\u5bfc\u5927\u7abe\u3002<\/p>\n<hr \/>\n<h3>\u76ee\u5f55<\/h3>\n<ul>\n<li>\u4e00\u3001\u4ece call trace \u5230\u9501&#xff1a;\u672c\u7bc7\u7684\u4f4d\u7f6e\n<ul>\n<li>1.1 \u7b2c\u516d\u7bc7\u7559\u4e0b\u7684\u90a3\u4e2a\u504f\u79fb<\/li>\n<li>1.2 \u4ec0\u4e48\u6837\u7684\u73b0\u573a\u9700\u8981\u89e3\u5256\u9501<\/li>\n<li>1.3 \u6b7b\u9501\u4e0e panic&#xff1a;\u5165\u573a\u52a8\u4f5c\u7684\u5dee\u5f02<\/li>\n<li>1.4 \u627f\u4e0a&#xff1a;\u4e09\u8f74\u539f\u5219\u5728\u9501\u5206\u6790\u4e2d\u7684\u843d\u70b9<\/li>\n<\/ul>\n<\/li>\n<li>\u4e8c\u3001\u9501\u5206\u6790\u7684\u5e95\u5c42\u903b\u8f91&#xff1a;\u4e3a\u4ec0\u4e48\u53ef\u8c03\u8bd5\u6027\u5929\u5dee\u5730\u522b\n<ul>\n<li>2.1 \u4ece\u7b49\u5f85\u56fe\u5012\u63a8&#xff1a;\u5206\u6790\u5230\u5e95\u9700\u8981\u4ec0\u4e48<\/li>\n<li>2.2 \u4e3a\u4ec0\u4e48\u6309&#034;\u80fd\u5426\u7761\u7720&#034;\u5206\u7c7b<\/li>\n<li>2.3 \u4e24\u6761\u8def\u7ebf\u7684\u5206\u91ce<\/li>\n<li>2.4 \u9501\u7c7b\u578b\u901f\u67e5\u8868<\/li>\n<\/ul>\n<\/li>\n<li>\u4e09\u3001\u8def\u7ebf A&#xff1a;\u8bfb\u7ed3\u6784\u5b9a\u6301\u6709\u8005\n<ul>\n<li>3.1 owner \u7f16\u7801&#xff1a;\u4e00\u5957\u89c4\u5219&#xff0c;\u591a\u9501\u901a\u7528<\/li>\n<li>3.2 \u7b49\u5f85\u94fe\u904d\u5386&#xff1a;\u901a\u7528\u624b\u6cd5<\/li>\n<li>3.3 rw_semaphore \u7684\u4e09\u5904\u7279\u6b8a\u6027<\/li>\n<li>3.4 \u8def\u7ebf A \u4f55\u65f6\u4f1a\u5931\u7075<\/li>\n<\/ul>\n<\/li>\n<li>\u56db\u3001\u8def\u7ebf B&#xff1a;\u81ea\u65cb\u9501\u7684\u4ea4\u53c9\u63a8\u65ad\n<ul>\n<li>4.1 val \u80fd\u56de\u7b54\u4ec0\u4e48&#xff0c;\u4e0d\u80fd\u56de\u7b54\u4ec0\u4e48<\/li>\n<li>4.2 \u8def\u7ebf\u5224\u5b9a&#xff1a;\u770b\u8fd9\u628a\u9501\u7684\u7ed3\u6784\u91cc\u6709\u6ca1\u6709\u6301\u6709\u8005\u5b57\u6bb5<\/li>\n<li>4.3 MCS \u961f\u5217&#xff1a;\u5b83\u8bb0\u5f55\u7684\u4e0d\u662f task&#xff0c;\u56e0\u6b64\u5bf9\u7b49\u5f85\u56fe\u6ca1\u6709\u8d21\u732e<\/li>\n<li>4.4 \u4ea4\u53c9\u63a8\u65ad\u56db\u6b65\u6cd5<\/li>\n<li>4.5 \u67b6\u6784\u5dee\u5f02\u5982\u4f55\u6539\u53d8&#034;\u80fd\u62ff\u5230\u4ec0\u4e48\u73b0\u573a&#034;<\/li>\n<\/ul>\n<\/li>\n<li>\u4e94\u3001\u6b7b\u9501\u7c7b\u578b\u56fe\u8c31<\/li>\n<li>\u516d\u3001\u7b49\u5f85\u94fe\u91cd\u5efa&#xff1a;\u5b8c\u6574\u65b9\u6cd5\u8bba<\/li>\n<li>\u4e03\u3001\u6848\u4f8b\u4e00&#xff1a;mutex ABBA \u6b7b\u9501&#xff08;\u8def\u7ebf A \u5168\u6d41\u7a0b&#xff09;<\/li>\n<li>\u516b\u3001\u6848\u4f8b\u4e8c&#xff1a;rwsem \u6b7b\u9501&#xff08;\u4e0e\u6848\u4f8b\u4e00\u7684\u64cd\u4f5c\u5dee\u5f02&#xff09;<\/li>\n<li>\u4e5d\u3001\u6848\u4f8b\u4e09&#xff1a;\u56de\u5230 jbd2 \u73b0\u573a&#xff08;\u771f\u5b9e\u6848\u4f8b&#xff0c;\u8def\u7ebf B \u4e0e\u5931\u6548\u8fb9\u754c&#xff09;<\/li>\n<li>\u5341\u3001lockdep \u544a\u8b66\u7684\u4e8b\u540e\u89e3\u8bfb<\/li>\n<li>\u5341\u4e00\u3001D \u72b6\u6001\u6d77\u7684\u8fa8\u522b&#xff1a;\u5e76\u975e\u5168\u662f\u6b7b\u9501\n<ul>\n<li>11.1 \u6838\u5fc3\u52a8\u4f5c&#xff1a;\u627e\u5230\u7ec8\u7aef\u8282\u70b9<\/li>\n<li>11.2 \u5355\u70b9\u963b\u585e&#xff1a;\u76f4\u63a5\u578b\u4e0e\u7ecf\u9501\u578b<\/li>\n<li>11.3 RCU Stall&#xff1a;\u673a\u5236\u4e0d\u540c\u7684\u4e00\u7c7b<\/li>\n<li>11.4 seqlock \u8bfb\u8005\u7a7a\u8f6c&#xff1a;\u4e0d\u8868\u73b0\u4e3a D \u72b6\u6001<\/li>\n<li>11.5 \u8fa8\u522b\u6d41\u7a0b<\/li>\n<\/ul>\n<\/li>\n<li>\u5341\u4e8c\u3001\u5c0f\u7ed3<\/li>\n<\/ul>\n<hr \/>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260827045631-6a8fc37f5548a.png\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0\" \/><\/p>\n<hr \/>\n<h3>\u4e00\u3001\u4ece call trace \u5230\u9501&#xff1a;\u672c\u7bc7\u7684\u4f4d\u7f6e<\/h3>\n<h4>1.1 \u7b2c\u516d\u7bc7\u7559\u4e0b\u7684\u90a3\u4e2a\u504f\u79fb<\/h4>\n<p>\u7b2c\u516d\u7bc7\u7684\u7ed3\u5c3e\u505c\u5728\u4e00\u4e2a\u60ac\u800c\u672a\u51b3\u7684\u5730\u65b9\u3002\u90a3\u4efd 4.19 ARM64 \u751f\u4ea7\u73b0\u573a\u91cc&#xff0c;\u4e24\u9897 CPU \u4e0a\u7684 jbd2 \u5185\u6838\u7ebf\u7a0b\u540c\u65f6 soft lockup&#xff0c;\u4e14\u90fd\u5361\u5728\u540c\u4e00\u4e2a\u51fd\u6570\u7684\u540c\u4e00\u4e2a\u504f\u79fb&#xff1a;<\/p>\n<p>el1_irq&#043;0xb8\/0x140                          &lt;- \u4e2d\u65ad\u8fb9\u754c<br \/>\next4_process_freed_data&#043;0x258\/0x530         &lt;- \u88ab\u4e2d\u65ad\u65f6\u6b63\u5728\u6267\u884c<br \/>\next4_journal_commit_callback&#043;0x50\/0x120<br \/>\njbd2_journal_commit_transaction&#043;0x164c\/0x1a60<br \/>\nkjournald2&#043;0xd0\/0x2b8<\/p>\n<p>\u7b2c\u516d\u7bc7\u5f53\u65f6\u7ed9\u51fa\u7684\u5224\u65ad\u662f&#xff1a;\u4e24\u5757\u72ec\u7acb\u78c1\u76d8\u7684\u65e5\u5fd7\u7ebf\u7a0b\u5361\u5728\u540c\u4e00\u5904&#xff0c;\u7528\u5de7\u5408\u89e3\u91ca\u4e0d\u5408\u7406&#xff0c;\u4e00\u4e2a\u503c\u5f97\u4f18\u5148\u9a8c\u8bc1\u7684\u5047\u8bbe\u662f\u81ea\u65cb\u9501\u4e89\u62a2\u2014\u2014\u4f46\u540c\u65f6\u4e5f\u5f3a\u8c03\u4e86&#xff0c;\u8fd9\u53ea\u662f\u5047\u8bbe&#xff0c;\u70ed\u70b9\u5faa\u73af\u3001\u4e0b\u6e38\u963b\u585e\u540c\u6837\u80fd\u9020\u6210\u540c\u4e00\u73b0\u8c61&#xff0c;\u5fc5\u987b\u53cd\u6c47\u7f16\u786e\u8ba4 &#043;0x258 \u5904\u7a76\u7adf\u662f\u4ec0\u4e48&#xff0c;\u5047\u8bbe\u624d\u6210\u7acb\u3002<\/p>\n<p>\u672c\u7bc7\u7b2c\u4e5d\u7ae0\u4f1a\u628a\u8fd9\u4e2a\u9a8c\u8bc1\u8865\u4e0a\u3002\u5728\u6b64\u4e4b\u524d&#xff0c;\u9700\u8981\u5148\u5efa\u7acb\u8bfb\u9501\u7ed3\u6784\u7684\u65b9\u6cd5\u3002<\/p>\n<h4>1.2 \u4ec0\u4e48\u6837\u7684\u73b0\u573a\u9700\u8981\u89e3\u5256\u9501<\/h4>\n<p>\u7b2c\u4e94\u7bc7\u7684\u8f6c\u5411\u4fe1\u53f7\u662f&#034;call trace \u8d70\u5230\u5c3d\u5934&#xff0c;\u7b54\u6848\u5728\u5185\u5b58\u91cc&#034;&#xff1b;\u7b2c\u516d\u7bc7\u662f&#034;\u4e00\u6761 call trace \u4e0d\u591f&#xff0c;\u9700\u8981\u6a2a\u5411\u770b\u6240\u6709\u8fdb\u7a0b&#034;\u3002\u672c\u7bc7\u7684\u8f6c\u5411\u4fe1\u53f7\u66f4\u5177\u4f53&#xff1a;\u6a2a\u5411\u770b\u5b8c\u8fdb\u7a0b\u4e4b\u540e&#xff0c;\u53d1\u73b0\u591a\u4e2a\u8fdb\u7a0b\u7684\u963b\u585e\u70b9\u6536\u655b\u5230\u540c\u6b65\u539f\u8bed\u4e0a\u3002<\/p>\n<table>\n<tr>\u73b0\u573a\u7279\u5f81\u8bf4\u660e\u672c\u7bc7\u5bf9\u5e94\u7ae0\u8282<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">foreach UN bt \u4e2d\u591a\u4e2a\u8fdb\u7a0b\u505c\u5728 __mutex_lock \/ rwsem_down_*<\/td>\n<td align=\"left\">\u7761\u7720\u9501\u7ade\u4e89&#xff0c;\u6301\u6709\u8005\u53ef\u76f4\u63a5\u8bfb\u51fa<\/td>\n<td align=\"left\">\u4e09\u3001\u4e03\u3001\u516b<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">backtrace \u505c\u5728 queued_spin_lock_slowpath<\/td>\n<td align=\"left\">\u81ea\u65cb\u9501\u7ade\u4e89&#xff0c;\u65e0\u6301\u6709\u8005\u8bb0\u5f55<\/td>\n<td align=\"left\">\u56db\u3001\u4e5d<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">soft lockup \/ hard lockup&#xff0c;\u5361\u70b9\u843d\u5728\u6301\u9501\u533a\u95f4<\/td>\n<td align=\"left\">CPU \u88ab\u81ea\u65cb\u7b49\u5f85\u5360\u4f4f<\/td>\n<td align=\"left\">\u56db\u3001\u4e5d<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">dmesg \u6709 possible circular locking dependency<\/td>\n<td align=\"left\">lockdep \u5df2\u7ecf\u628a\u73af\u7b97\u51fa\u6765\u4e86<\/td>\n<td align=\"left\">\u5341<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">\u5927\u91cf D \u72b6\u6001\u4f46\u8ffd\u4e0d\u51fa\u73af<\/td>\n<td align=\"left\">\u53ef\u80fd\u6839\u672c\u4e0d\u662f\u6b7b\u9501<\/td>\n<td align=\"left\">\u5341\u4e00<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u4e0e\u524d\u4e24\u7bc7\u7684\u5206\u5de5&#xff1a; \u7b2c\u4e94\u7bc7\u56de\u7b54&#034;\u8fd9\u4e2a\u503c\u4e3a\u4ec0\u4e48\u662f\u9519\u7684&#034;&#xff0c;\u7b2c\u516d\u7bc7\u56de\u7b54&#034;\u8fd9\u4ef6\u4e8b\u8ddf\u8c01\u6709\u5173&#034;&#xff0c;\u672c\u7bc7\u56de\u7b54**\u201c\u4ed6\u4eec\u5361\u5728\u8c01\u624b\u91cc\u201d**\u3002<\/p>\n<h4>1.3 \u6b7b\u9501\u4e0e panic&#xff1a;\u5165\u573a\u52a8\u4f5c\u7684\u5dee\u5f02<\/h4>\n<p>panic \u578b vmcore \u4e0e\u6b7b\u9501\u578b vmcore \u7684\u8c03\u67e5\u65b9\u5411\u662f\u76f8\u53cd\u7684\u3002<\/p>\n<p>panic \u6709\u660e\u786e\u7684\u5d29\u6e83\u70b9&#xff0c;\u7b2c\u4e00\u52a8\u4f5c\u662f bt\u2014\u2014\u627e\u5230\u90a3\u6761\u51fa\u4e8b\u7684\u8c03\u7528\u94fe&#xff0c;\u987a\u7740\u5b83\u5f80\u56de\u8ffd\u3002\u6b7b\u9501\u6ca1\u6709\u5d29\u6e83\u70b9&#xff0c;\u7cfb\u7edf\u662f\u5728&#034;\u8fd8\u80fd\u8fd0\u884c\u4f46\u8981\u5bb3\u88ab\u5361\u4f4f&#034;\u7684\u72b6\u6001\u4e0b\u88ab\u5f3a\u884c\u53d6\u7684\u73b0\u573a&#xff0c;\u7b2c\u4e00\u52a8\u4f5c\u662f ps\u2014\u2014\u5148\u770b\u6709\u54ea\u4e9b\u4efb\u52a1\u4e0d\u52a8\u4e86&#xff0c;\u518d\u4ece\u8fd9\u6279\u9759\u6b62\u7684\u4efb\u52a1\u91cc\u627e\u5173\u7cfb\u3002<\/p>\n<p>panic vmcore    -&gt;  one crash site, follow the trace backwards<br \/>\n                    entry command: bt<\/p>\n<p>deadlock vmcore -&gt;  no crash site, many stalled tasks<br \/>\n                    entry command: ps  (then ps -m for ordering)<\/p>\n<p>\u89e6\u53d1\u6b7b\u9501\u573a\u666f vmcore \u7684\u5e38\u89c1\u9014\u5f84\u6709\u4e09\u6761&#xff0c;\u5404\u81ea\u7684\u73b0\u573a\u7279\u5f81\u4e0d\u540c&#xff1a;<\/p>\n<table>\n<tr>\u89e6\u53d1\u9014\u5f84\u5185\u6838\u53c2\u6570\u73b0\u573a\u7279\u5f81<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">hung_task \u8d85\u65f6 panic<\/td>\n<td align=\"left\">kernel.hung_task_panic&#061;1<\/td>\n<td align=\"left\">\u7761\u7720\u9501\u6b7b\u9501&#xff0c;D \u72b6\u6001\u4efb\u52a1\u7fa4<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">watchdog \u68c0\u6d4b CPU \u5361\u6b7b<\/td>\n<td align=\"left\">softlockup_panic \/ hardlockup_panic<\/td>\n<td align=\"left\">\u81ea\u65cb\u9501\u6b7b\u9501&#xff0c;CPU \u88ab\u5360\u4f4f<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">SysRq-c \u624b\u52a8\u89e6\u53d1<\/td>\n<td align=\"left\">kernel.sysrq<\/td>\n<td align=\"left\">\u8fd0\u7ef4\u4ecb\u5165&#xff0c;\u73b0\u573a\u53d6\u51b3\u4e8e\u89e6\u53d1\u65f6\u673a<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u6ce8\u610f hung_task \u7684\u53c2\u6570\u540d\u3002 \u89e6\u53d1 panic \u7684\u662f kernel.hung_task_panic&#xff0c;\u800c kernel.hung_task_timeout_secs&#xff08;\u9ed8\u8ba4 120&#xff09;\u53ea\u63a7\u5236\u4f55\u65f6\u6253\u5370\u544a\u8b66\u3002\u4e8c\u8005\u5e38\u88ab\u6df7\u79f0&#xff0c;\u5b9e\u6d4b\u4ee5 sysctl -a | grep hung_task \u4e3a\u51c6\u3002<\/p>\n<p>\u8bc6\u522b\u6b7b\u9501\u573a\u666f\u7684\u4e09\u4e2a\u4fe1\u53f7&#xff1a;<\/p>\n<p>\u4fe1\u53f7\u4e00&#xff1a;dmesg \u7684 hung_task \u6253\u5370\u3002<\/p>\n<p>INFO: task worker-thread:4821 blocked for more than 120 seconds.<br \/>\nCall Trace:<br \/>\n __schedule&#043;0x2b9\/0x860<br \/>\n __mutex_lock.isra.0&#043;0x209\/0x540<br \/>\n volume_lock_acquire&#043;0x38\/0x70 [demo_drv]<\/p>\n<p>\u4fe1\u53f7\u4e8c&#xff1a;dmesg \u7684 watchdog \u544a\u8b66\u3002<\/p>\n<p>watchdog: BUG: soft lockup &#8211; CPU#2 stuck for 22s! [kworker\/2:1:4822]<br \/>\nwatchdog: BUG: hard LOCKUP on cpu 2<\/p>\n<p>\u4fe1\u53f7\u4e09&#xff1a;crash \u4e2d\u7684 D \u72b6\u6001\u4efb\u52a1\u7fa4\u3002<\/p>\n<p>crash&gt; ps | grep &#034; UN &#034;<br \/>\n  4821  4815  0  ffff888207a3c000  UN   0.0  20480  1024  worker-thread<br \/>\n  4822  4815  1  ffff888207b48000  UN   0.0  20480  1024  worker-thread<br \/>\n  4823  4815  2  ffff888207c5a000  UN   0.0  20480  1024  worker-thread<\/p>\n<p>\u540c\u540d\u8fdb\u7a0b\u624e\u5806 D \u72b6\u6001\u662f\u4e00\u4e2a\u5f3a\u4fe1\u53f7\u2014\u2014\u5b83\u610f\u5473\u7740\u8fd9\u4e9b\u4efb\u52a1\u8d70\u7684\u662f\u540c\u4e00\u6bb5\u4ee3\u7801\u8def\u5f84&#xff0c;\u5f88\u53ef\u80fd\u5361\u5728\u540c\u4e00\u4e2a\u8d44\u6e90\u4e0a\u3002\u914d\u5408\u7b49\u5f85\u65f6\u957f&#xff1a;<\/p>\n<p>crash&gt; ps -m | grep &#034; UN &#034;<br \/>\n[0 00:05:47.882]  4821  &#8230;  UN  worker-thread<br \/>\n[0 00:05:45.201]  4822  &#8230;  UN  worker-thread<br \/>\n[0 00:05:41.094]  4823  &#8230;  UN  worker-thread<\/p>\n<p>\u6309\u7b2c\u516d\u7bc7 3.3 \u8282&#xff0c;ps -m \u7ed9\u51fa\u7684\u662f last-run \u65f6\u95f4\u5dee&#xff0c;\u5bf9\u7761\u7720\u6001\u8fd1\u4f3c\u53cd\u6620\u8fde\u7eed\u672a\u8fd0\u884c\u65f6\u957f\u3002\u6b64\u5904\u8fd1\u516d\u5206\u949f\u672a\u88ab\u8c03\u5ea6&#xff0c;\u8fdc\u8d85\u6b63\u5e38 I\/O \u7b49\u5f85\u91cf\u7ea7&#xff0c;\u503c\u5f97\u6df1\u67e5\u2014\u2014\u4f46\u8fd9\u662f\u6392\u5e8f\u7ebf\u7d22\u800c\u975e\u5224\u636e&#xff0c;\u771f\u6b63\u7684\u786e\u8ba4\u8981\u9760\u7b49\u5f85\u94fe\u8ffd\u8e2a\u3002<\/p>\n<p>\u4e0a\u8ff0\u4e09\u4e2a PID \u53ca\u540e\u6587\u51fa\u73b0\u7684 demo_drv \u76f8\u5173\u7b26\u53f7&#xff0c;\u5747\u4e3a\u7b2c\u4e03\u7ae0\u6559\u5b66\u6848\u4f8b\u7684\u9884\u6f14&#xff0c;\u975e\u771f\u5b9e\u751f\u4ea7\u6570\u636e&#xff0c;\u8be6\u89c1\u8be5\u7ae0\u5f00\u5934\u7684\u8bf4\u660e\u3002<\/p>\n<h4>1.4 \u627f\u4e0a&#xff1a;\u4e09\u8f74\u539f\u5219\u5728\u9501\u5206\u6790\u4e2d\u7684\u843d\u70b9<\/h4>\n<p>\u9501\u7684\u5b9e\u73b0\u662f\u4e09\u8f74\u4f9d\u8d56\u7684\u91cd\u707e\u533a\u3002 \u540c\u4e00\u6bb5\u5206\u6790\u65b9\u6cd5&#xff0c;\u6362\u4e2a\u67b6\u6784\u3001\u6362\u4e2a\u5185\u6838\u7248\u672c\u3001\u6362\u4e2a\u7f16\u8bd1\u914d\u7f6e&#xff0c;\u8bfb\u5230\u7684\u7ed3\u6784\u53ef\u80fd\u5b8c\u5168\u4e0d\u540c&#xff1a;<\/p>\n<table>\n<tr>\u672c\u7bc7\u77e5\u8bc6\u70b9\u53d7\u54ea\u4e00\u8f74\u7ea6\u675f\u5177\u4f53\u5206\u754c<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">spinlock \u662f qspinlock \u8fd8\u662f ticket lock<\/td>\n<td align=\"left\">\u7248\u672c &#043; \u914d\u7f6e<\/td>\n<td align=\"left\">CONFIG_QUEUED_SPINLOCKS&#xff1b;x86_64 \u81ea 4.2\u3001ARM64 \u81ea 4.19 \u8d77\u9ed8\u8ba4<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">spinlock \u662f\u5426\u8bb0\u5f55 owner<\/td>\n<td align=\"left\">\u914d\u7f6e<\/td>\n<td align=\"left\">CONFIG_DEBUG_SPINLOCK \u5f00\u542f\u65f6\u624d\u6709 owner \/ owner_cpu<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">rwsem \u7684 count \u4f4d\u57df\u5e03\u5c40<\/td>\n<td align=\"left\">\u7248\u672c<\/td>\n<td align=\"left\">5.3 \u524d\u540e\u7ecf\u5386\u91cd\u5199&#xff0c;\u4f4d\u5b9a\u4e49\u5b8c\u5168\u4e0d\u540c<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">mutex \u662f\u5426\u6709 osq \u4e50\u89c2\u81ea\u65cb<\/td>\n<td align=\"left\">\u914d\u7f6e<\/td>\n<td align=\"left\">CONFIG_MUTEX_SPIN_ON_OWNER<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">mutex \u662f\u5426\u6709 magic \u6821\u9a8c\u5b57\u6bb5<\/td>\n<td align=\"left\">\u914d\u7f6e<\/td>\n<td align=\"left\">CONFIG_DEBUG_MUTEXES<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">ARM64 \u80fd\u5426\u89e6\u53d1 hard lockup<\/td>\n<td align=\"left\">\u67b6\u6784 &#043; \u914d\u7f6e &#043; \u56fa\u4ef6<\/td>\n<td align=\"left\">\u9700 CONFIG_ARM64_PSEUDO_NMI \u4e14 GICv3 \u56fa\u4ef6\u652f\u6301<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">lockdep \u4f9d\u8d56\u56fe\u662f\u5426\u53ef\u7528<\/td>\n<td align=\"left\">\u914d\u7f6e<\/td>\n<td align=\"left\">CONFIG_PROVE_LOCKING<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u56e0\u6b64\u672c\u7bc7\u7ed9\u51fa\u7684\u6240\u6709\u4f4d\u57df\u3001\u504f\u79fb\u3001\u5e38\u91cf&#xff0c;\u90fd\u5e94\u89c6\u4e3a\u67d0\u7ec4\u4e09\u8f74\u53d6\u503c\u4e0b\u7684\u5b9e\u4f8b\u3002\u52a8\u624b\u524d\u5148\u786e\u8ba4&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> sys                        <span class=\"token comment\"># \u67b6\u6784 &#043; \u5185\u6838\u7248\u672c<\/span><br \/>\ncrash<span class=\"token operator\">&gt;<\/span> struct mutex               <span class=\"token comment\"># \u6709\u65e0 osq \/ magic \u5b57\u6bb5<\/span><br \/>\ncrash<span class=\"token operator\">&gt;<\/span> struct qspinlock           <span class=\"token comment\"># \u8be5\u5185\u6838\u7684\u5b9e\u9645\u7ed3\u6784\u5b9a\u4e49<\/span><br \/>\ncrash<span class=\"token operator\">&gt;<\/span> struct rw_semaphore        <span class=\"token comment\"># count \u4e0e owner \u7684\u5b9e\u9645\u5e03\u5c40<\/span><\/p>\n<p>struct &lt;type&gt; \u4e0d\u5e26\u5730\u5740\u5373\u53ef\u6253\u5370\u8be5\u5185\u6838\u7684\u7ed3\u6784\u5b9a\u4e49\u4e0e\u5404\u5b57\u6bb5\u504f\u79fb\u2014\u2014\u8fd9\u662f\u672c\u7bc7\u6700\u91cd\u8981\u7684\u4e00\u6761\u5b9e\u6d4b\u4e60\u60ef\u3002<\/p>\n<hr \/>\n<h3>\u4e8c\u3001\u9501\u5206\u6790\u7684\u5e95\u5c42\u903b\u8f91&#xff1a;\u4e3a\u4ec0\u4e48\u53ef\u8c03\u8bd5\u6027\u5929\u5dee\u5730\u522b<\/h3>\n<p>\u5728\u8bb2\u4efb\u4f55\u4e00\u79cd\u9501\u7684\u5b57\u6bb5\u7f16\u7801\u4e4b\u524d&#xff0c;\u5148\u8981\u56de\u7b54\u4e24\u4e2a\u95ee\u9898&#xff1a;\u6211\u4eec\u5230\u5e95\u5728\u627e\u4ec0\u4e48&#xff1f;\u4e3a\u4ec0\u4e48\u6709\u4e9b\u9501\u597d\u67e5&#xff0c;\u6709\u4e9b\u9501\u96be\u67e5&#xff1f; \u60f3\u6e05\u695a\u8fd9\u4e24\u70b9&#xff0c;\u540e\u9762\u6240\u6709\u64cd\u4f5c\u90fd\u662f\u81ea\u7136\u63a8\u8bba&#xff0c;\u4e0d\u9700\u8981\u6b7b\u8bb0\u3002<\/p>\n<h4>2.1 \u4ece\u7b49\u5f85\u56fe\u5012\u63a8&#xff1a;\u5206\u6790\u5230\u5e95\u9700\u8981\u4ec0\u4e48<\/h4>\n<p>\u6b7b\u9501\u5206\u6790\u7684\u672c\u8d28&#xff0c;\u662f\u5728\u9759\u6001\u5feb\u7167\u4e2d\u91cd\u5efa\u4e00\u5f20\u6709\u5411\u56fe\u5e76\u68c0\u6d4b\u5176\u4e2d\u7684\u73af\u3002\u8fd9\u5f20\u56fe\u53ea\u6709\u4e24\u7c7b\u8fb9&#xff1a;<\/p>\n<p>WAIT edge:  TASK  &#8212;- waits for &#8212;-&gt;  LOCK<br \/>\n            source: the task&#039;s backtrace<br \/>\n            cost:   cheap, always available<\/p>\n<p>HOLD edge:  LOCK  &#8212;- held by &#8212;&#8211;&gt;  TASK<br \/>\n            source: the lock structure itself<br \/>\n            cost:   depends entirely on the lock type<\/p>\n<p>\u4e0b\u6587\u7edf\u4e00\u79f0\u4e8c\u8005\u4e3a\u7b49\u5f85\u8fb9\u4e0e\u6301\u6709\u8fb9\u3002<\/p>\n<p>\u7b49\u5f85\u8fb9\u6c38\u8fdc\u62ff\u5f97\u5230\u3002 \u4efb\u4f55\u963b\u585e\u7684\u4efb\u52a1&#xff0c;bt \u90fd\u4f1a\u663e\u793a\u5b83\u505c\u5728\u54ea\u4e2a\u52a0\u9501\u51fd\u6570\u4e0a&#xff0c;\u5f80\u4e0a\u4e00\u5e27\u5c31\u662f\u6301\u9501\u70b9\u6240\u5728\u7684\u8c03\u7528\u8005\u3002\u8fd9\u4e00\u6b65\u4e0e\u9501\u7684\u7c7b\u578b\u65e0\u5173\u3002<\/p>\n<p>\u6301\u6709\u8fb9\u662f\u5168\u90e8\u56f0\u96be\u7684\u6240\u5728\u3002 \u4e00\u628a\u9501\u88ab\u8c01\u6301\u6709&#xff0c;\u8fd9\u4e2a\u4fe1\u606f\u4e0d\u4f1a\u5199\u5728\u7b49\u5f85\u8005\u7684\u6808\u4e0a&#xff0c;\u53ea\u53ef\u80fd\u8bb0\u5f55\u5728\u9501\u81ea\u5df1\u7684\u7ed3\u6784\u91cc\u3002\u82e5\u9501\u4e0d\u8bb0\u5f55\u6301\u6709\u8005&#xff0c;\u8fd9\u6761\u8fb9\u5c31\u65ad\u4e86\u2014\u2014\u56fe\u8fde\u4e0d\u8d77\u6765&#xff0c;\u73af\u4e5f\u5c31\u65e0\u4ece\u627e\u8d77\u3002<\/p>\n<p>\u5728\u5f80\u4e0b\u63a8\u4e4b\u524d&#xff0c;\u5148\u8ba4\u8bc6\u4e24\u4e2a\u5b57\u6bb5\u3002 \u5b83\u4eec\u662f\u540e\u6587\u53cd\u590d\u51fa\u73b0\u7684\u4e3b\u89d2&#xff0c;\u5404\u81ea\u4e00\u53e5\u8bdd\u5c31\u80fd\u8bf4\u6e05&#xff1a;<\/p>\n<p>owner  &#8212;  found in sleepable locks (mutex \/ rw_semaphore \/ rt_mutex)<br \/>\n           type: atomic_long_t<br \/>\n           value: the holder&#039;s task_struct pointer<br \/>\n                  (low bits borrowed for flags; mask them off)<br \/>\n           in one sentence:<br \/>\n                it tells you directly WHO holds this lock<\/p>\n<p>val    &#8212;  found in spinning locks (spinlock_t \/ rwlock_t)<br \/>\n           type: atomic_t, only 32 bits, the entire lock state<br \/>\n                 compressed into one word<br \/>\n           layout: locked \/ pending \/ tail sub-fields<br \/>\n           in one sentence:<br \/>\n                it tells you the lock IS taken and how many are<br \/>\n                queued &#8212; but never WHO took it<\/p>\n<p>\u4e24\u4e2a\u5b57\u6bb5\u7684\u5dee\u522b&#xff0c;\u6070\u597d\u5bf9\u5e94\u4e0a\u9762\u4e24\u7c7b\u8fb9\u7684\u5dee\u522b&#xff1a;owner \u76f4\u63a5\u7ed9\u51fa\u6301\u6709\u8fb9&#xff1b;val \u53ea\u80fd\u8bc1\u660e\u8fd9\u6761\u8fb9\u5b58\u5728&#xff0c;\u8bf4\u4e0d\u51fa\u5b83\u6307\u5411\u8c01\u3002<\/p>\n<p>\u7531\u6b64\u5f97\u51fa\u672c\u7bc7\u7684\u7b2c\u4e00\u4e2a\u6838\u5fc3\u7ed3\u8bba&#xff1a;<\/p>\n<p>owner \u5b57\u6bb5\u4e4b\u6240\u4ee5\u91cd\u8981&#xff0c;\u4e0d\u662f\u56e0\u4e3a\u5b83\u662f\u4e00\u4e2a\u5b57\u6bb5&#xff0c;\u800c\u662f\u56e0\u4e3a\u5b83\u662f\u6301\u6709\u8fb9\u7684\u552f\u4e00\u76f4\u63a5\u6765\u6e90\u3002<\/p>\n<p>\u540c\u7406&#xff0c;\u81ea\u65cb\u9501\u7684 val \u5b57\u6bb5\u4e4b\u6240\u4ee5\u8981\u9010\u4f4d\u62c6\u89e3&#xff0c;\u662f\u56e0\u4e3a\u5b83\u662f\u90a3\u4e9b\u6ca1\u6709 owner \u7684\u9501\u4e0a&#xff0c;\u552f\u4e00\u80fd\u6324\u51fa\u4fe1\u606f\u7684\u5730\u65b9\u2014\u2014\u5b83\u81f3\u5c11\u80fd\u544a\u8bc9\u4f60\u6301\u6709\u8fb9\u662f\u5426\u5b58\u5728&#xff08;\u9501\u662f\u5426\u88ab\u6301\u6709&#xff09;&#xff0c;\u54ea\u6015\u8bf4\u4e0d\u51fa&#034;\u8fb9\u6307\u5411\u8c01&#034;\u3002<\/p>\n<h4>2.2 \u4e3a\u4ec0\u4e48\u6309&#034;\u80fd\u5426\u7761\u7720&#034;\u5206\u7c7b<\/h4>\n<p>\u9501\u53ef\u4ee5\u6309\u5f88\u591a\u7ef4\u5ea6\u5206\u7c7b&#xff1a;\u6301\u6709\u65f6\u957f\u3001\u8bfb\u5199\u8bed\u4e49\u3001\u516c\u5e73\u6027\u3001\u662f\u5426\u53ef\u91cd\u5165\u3002\u672c\u7bc7\u9009\u62e9&#034;\u80fd\u5426\u7761\u7720&#034;\u8fd9\u4e2a\u7ef4\u5ea6&#xff0c;\u4e0d\u662f\u56e0\u4e3a\u5b83\u6700\u80fd\u63cf\u8ff0\u9501\u7684\u529f\u80fd&#xff0c;\u800c\u662f\u56e0\u4e3a\u5b83\u76f4\u63a5\u51b3\u5b9a vmcore \u91cc\u80fd\u8bfb\u5230\u4ec0\u4e48\u3002<\/p>\n<p>\u63a8\u5bfc\u94fe\u6761\u5982\u4e0b&#xff1a;<\/p>\n<p>CAN SLEEP<br \/>\n  -&gt; the waiter gives up the CPU and stops running entirely<br \/>\n  -&gt; it can no longer poll the lock by itself<br \/>\n  -&gt; SOMEBODY ELSE must wake it up on release<br \/>\n  -&gt; the releaser must know WHOM to wake<br \/>\n  -&gt; the lock must therefore record every waiter&#039;s task_struct<br \/>\n  -&gt; implemented as an intrusive linked list: wait_list<br \/>\n  &#061;&gt;  a complete, traversable roster in the vmcore<\/p>\n<p>  -&gt; hold time may be long; recording the owner has real value<br \/>\n     (deadlock detection; optimistic spinning needs to know<br \/>\n      whether the owner is still running)<br \/>\n  &#061;&gt;  owner field exists, HOLD edge READABLE<\/p>\n<p>CANNOT SLEEP<br \/>\n  -&gt; the waiter does NOT yield the CPU; it observes the release itself<br \/>\n     (x86_64: PAUSE busy-wait;  ARM64: WFE low-power wait, woken by SEV)<br \/>\n  -&gt; it notices the release on its own; nobody needs to wake it<br \/>\n  -&gt; no roster of waiters is required<br \/>\n  -&gt; (an MCS queue does exist, but it holds per-CPU nodes for<br \/>\n      cache-line locality &#8212; NOT task_struct pointers, see 4.2)<br \/>\n  &#061;&gt;  no waiter roster to read<\/p>\n<p>  -&gt; hold time is designed to be extremely short<br \/>\n  -&gt; recording an owner costs a store on every acquire\/release<br \/>\n     for negligible benefit  &#061;&gt;  omitted in production builds<br \/>\n  &#061;&gt;  no owner field, HOLD edge must be INFERRED<\/p>\n<p>\u63a8\u5bfc\u7684\u5173\u952e\u73af\u8282\u662f&#034;\u7761\u7740\u7684\u4eba\u65e0\u6cd5\u81ea\u5df1\u9192\u6765&#034;\u3002 \u7761\u7720\u9501\u7684\u7b49\u5f85\u8005\u4ea4\u51fa\u4e86\u6267\u884c\u6743&#xff0c;\u4e0d\u53ef\u80fd\u518d\u53bb\u67e5\u770b\u9501\u7684\u72b6\u6001&#xff0c;\u53ea\u80fd\u7531\u91ca\u653e\u65b9\u5524\u9192&#xff1b;\u800c\u5524\u9192\u5fc5\u987b\u77e5\u9053\u627e\u8c01&#xff0c;\u4e8e\u662f\u9501\u4e0d\u5f97\u4e0d\u8bb0\u4e0b\u6bcf\u4e00\u4e2a\u7b49\u5f85\u8005\u2014\u2014wait_list \u5c31\u662f\u8fd9\u4efd\u540d\u5355\u3002\u81ea\u65cb\u9501\u7684\u7b49\u5f85\u8005\u4e0d\u4ea4\u51fa\u6267\u884c\u6743&#xff0c;\u80fd\u591f\u81ea\u884c\u89c2\u5bdf\u5230\u9501\u88ab\u91ca\u653e&#xff0c;\u56e0\u6b64\u4e0d\u9700\u8981\u6709\u4eba\u6765\u53eb&#xff0c;\u4e5f\u5c31\u4e0d\u9700\u8981\u8fd9\u4efd\u540d\u5355\u3002\u5177\u4f53\u7684\u7b49\u5f85\u65b9\u5f0f\u968f\u67b6\u6784\u800c\u5f02&#xff1a;x86_64 \u4f7f\u7528 PAUSE \u5fd9\u7b49&#xff0c;\u6301\u7eed\u5360\u7528 CPU&#xff1b;ARM64 \u4f7f\u7528 WFE \u8fdb\u5165\u4f4e\u529f\u8017\u7b49\u5f85&#xff0c;\u7531\u91ca\u653e\u65b9\u7684 SEV \u5524\u9192&#xff08;\u89c1 4.5 \u8282&#xff09;\u3002\u4e24\u8005\u7684\u5171\u540c\u70b9\u5728\u4e8e\u5524\u9192\u4e0d\u4f9d\u8d56\u9501\u7ed3\u6784\u8bb0\u5f55\u7b49\u5f85\u8005\u8eab\u4efd\u2014\u2014WFE \u7531\u786c\u4ef6\u4e8b\u4ef6\u5524\u9192&#xff0c;\u91ca\u653e\u65b9\u65e0\u9700\u77e5\u9053\u5177\u4f53\u5728\u7b49\u8c01\u3002<\/p>\n<p>\u6ce8\u610f\u4e00\u5904\u5bb9\u6613\u6df7\u6dc6\u7684\u5730\u65b9&#xff1a;\u81ea\u65cb\u9501\u5e76\u975e\u6ca1\u6709\u961f\u5217\u3002 qspinlock \u6709 MCS \u961f\u5217&#xff0c;\u4f46\u5b83\u7684\u5b58\u5728\u76ee\u7684\u5b8c\u5168\u4e0d\u540c\u2014\u2014\u4e0d\u662f\u4e3a\u4e86\u5524\u9192&#xff0c;\u800c\u662f\u8ba9\u6bcf\u4e2a CPU \u81ea\u65cb\u5728\u5404\u81ea\u7684\u7f13\u5b58\u884c\u4e0a\u4ee5\u907f\u514d\u98a0\u7c38\u3002\u56e0\u6b64\u5b83\u8bb0\u5f55\u7684\u662f per-CPU \u7684 mcs_spinlock \u8282\u70b9&#xff0c;\u4e0d\u662f task_struct \u6307\u9488&#xff0c;\u5bf9\u7b49\u5f85\u56fe\u6ca1\u6709\u8d21\u732e&#xff08;\u8be6\u89c1 4.3 \u8282&#xff09;\u3002<\/p>\n<table>\n<tr>\u7761\u7720\u9501\u7684 wait_list\u81ea\u65cb\u9501\u7684 MCS \u961f\u5217<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">\u5b58\u5728\u76ee\u7684<\/td>\n<td align=\"left\">\u91ca\u653e\u65f6\u9700\u8981\u77e5\u9053\u5524\u9192\u8c01<\/td>\n<td align=\"left\">\u8ba9\u5404 CPU \u81ea\u65cb\u5728\u4e0d\u540c\u7f13\u5b58\u884c<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">\u8bb0\u5f55\u5185\u5bb9<\/td>\n<td align=\"left\">\u7b49\u5f85\u8005\u7684 task_struct<\/td>\n<td align=\"left\">per-CPU \u7684 mcs_spinlock \u8282\u70b9<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">\u5bf9\u7b49\u5f85\u56fe\u7684\u8d21\u732e<\/td>\n<td align=\"left\">\u76f4\u63a5\u7ed9\u51fa&#034;\u8c01\u5728\u7b49&#034;<\/td>\n<td align=\"left\">\u53ea\u80fd\u5f97\u5230\u961f\u5c3e\u5728\u54ea\u9897 CPU<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">\u53ef\u904d\u5386\u6027<\/td>\n<td align=\"left\">\u6807\u51c6\u94fe\u8868&#xff0c;list \u4e00\u6761\u547d\u4ee4<\/td>\n<td align=\"left\">\u9700\u89e3\u6790 per-CPU \u57fa\u5740&#xff0c;\u6210\u672c\u9ad8\u56de\u62a5\u4f4e<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u6362\u8a00\u4e4b&#xff0c;&#034;\u80fd\u5426\u7761\u7720&#034;\u8fd9\u4e2a\u5206\u7c7b\u6807\u51c6\u662f\u4ece\u53ef\u8c03\u8bd5\u6027\u5012\u63a8\u51fa\u6765\u7684\u3002 \u5b83\u4e4b\u6240\u4ee5\u6709\u6548&#xff0c;\u662f\u56e0\u4e3a\u7761\u7720\u80fd\u529b\u51b3\u5b9a\u4e86\u9501\u7684\u5b9e\u73b0\u5fc5\u987b\u63d0\u4f9b\u4ec0\u4e48\u8bbe\u65bd&#xff0c;\u800c\u8fd9\u4e9b\u8bbe\u65bd\u6070\u597d\u5c31\u662f vmcore \u5206\u6790\u6240\u4f9d\u8d56\u7684\u3002<\/p>\n<p>\u7406\u89e3\u8fd9\u6761\u63a8\u5bfc&#xff0c;\u6bd4\u8bb0\u4f4f&#034;\u54ea\u4e9b\u9501\u80fd\u7761&#034;\u66f4\u6709\u7528\u2014\u2014\u9047\u5230\u672c\u7bc7\u6ca1\u8986\u76d6\u7684\u9501\u7c7b\u578b&#xff08;\u5982\u5404\u79cd\u9a71\u52a8\u81ea\u5b9a\u4e49\u7684\u540c\u6b65\u539f\u8bed&#xff09;&#xff0c;\u540c\u6837\u53ef\u4ee5\u7528\u5b83\u6765\u5224\u65ad\u8be5\u5f80\u54ea\u4e2a\u65b9\u5411\u67e5\u3002<\/p>\n<h4>2.3 \u4e24\u6761\u8def\u7ebf\u7684\u5206\u91ce<\/h4>\n<p>\u7531 2.1 \u4e0e 2.2 \u5f97\u5230\u5168\u7bc7\u7684\u9aa8\u67b6&#xff1a;<\/p>\n<p>                    is the HOLD edge directly readable?<br \/>\n                                  |<br \/>\n              &#043;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-&#043;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-&#043;<br \/>\n              | YES                                   | NO<br \/>\n              v                                       v<br \/>\n     PATH A: read the structure            PATH B: infer from context<br \/>\n     &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;        &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\n     mutex \/ rw_semaphore \/ rt_mutex       spinlock_t \/ rwlock_t \/ raw_*<br \/>\n                                           (unless CONFIG_DEBUG_SPINLOCK)<\/p>\n<p>     owner &amp; ~0x7  -&gt;  task_struct*        val tells you &#034;held&#034;, not &#034;by whom&#034;<br \/>\n     wait_list     -&gt;  traversable         MCS queue, not a plain list<br \/>\n                                           holder inferred from per-CPU bt<\/p>\n<p>     cost: minutes                         cost: hours, and may fail entirely<\/p>\n<p>\u8fd9\u4e24\u6761\u8def\u7ebf\u5bf9\u5e94\u672c\u7bc7\u7684\u7b2c\u4e09\u3001\u56db\u7ae0\u3002 \u540e\u9762\u6240\u6709\u7684\u5b57\u6bb5\u7f16\u7801\u3001\u547d\u4ee4\u5e8f\u5217&#xff0c;\u90fd\u5f52\u5c5e\u4e8e\u5176\u4e2d\u4e00\u6761\u3002\u6848\u4f8b\u7ae0\u8282&#xff08;\u4e03\u3001\u516b\u3001\u4e5d&#xff09;\u5219\u5206\u522b\u8d70\u901a\u8fd9\u4e24\u6761\u8def\u3002<\/p>\n<p>\u4e00\u4e2a\u52a1\u5b9e\u7684\u5efa\u8bae&#xff1a;\u9047\u5230\u73b0\u573a\u5148\u5224\u65ad\u8d70\u54ea\u6761\u8def\u7ebf&#xff0c;\u518d\u51b3\u5b9a\u6295\u5165\u591a\u5c11\u65f6\u95f4\u3002 \u8def\u7ebf A \u901a\u5e38\u5341\u51e0\u5206\u949f\u80fd\u51fa\u7ed3\u8bba&#xff1b;\u8def\u7ebf B \u53ef\u80fd\u8017\u6389\u534a\u5929&#xff0c;\u4e14\u7b2c\u4e5d\u7ae0\u4f1a\u5c55\u793a\u4e00\u79cd\u8fde\u63a8\u65ad\u90fd\u65e0\u6cd5\u8fdb\u884c\u7684\u60c5\u5f62\u3002<\/p>\n<h4>2.4 \u9501\u7c7b\u578b\u901f\u67e5\u8868<\/h4>\n<p>\u628a\u6240\u6709\u5e38\u89c1\u9501\u7684\u5173\u952e\u4fe1\u606f\u96c6\u4e2d\u5728\u4e00\u5904&#xff0c;\u540e\u7eed\u7ae0\u8282\u4e0d\u518d\u9010\u4e00\u5c55\u5f00&#xff1a;<\/p>\n<table>\n<tr>\u9501\u7c7b\u578b\u8def\u5f84\u6301\u6709\u8005\u4ece\u54ea\u8bfb\u7b49\u5f85\u94fe\u5173\u952e\u5b57\u6bb5\u7f16\u7801<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">mutex<\/td>\n<td align=\"left\">A<\/td>\n<td align=\"left\">owner &amp; ~0x7<\/td>\n<td align=\"left\">mutex_waiter \u94fe\u8868<\/td>\n<td align=\"left\">bit0 WAITERS\u3001bit1 HANDOFF\u3001bit2 PICKUP<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">rw_semaphore<\/td>\n<td align=\"left\">A<\/td>\n<td align=\"left\">\u5199\u8005\u540c\u4e0a&#xff1b;\u8bfb\u8005\u4e0d\u53ef\u5f97<\/td>\n<td align=\"left\">rwsem_waiter \u94fe\u8868&#xff08;\u542b type&#xff09;<\/td>\n<td align=\"left\">count bit0 \u5199\u9501\u3001bit1 \u6709\u7b49\u5f85\u8005\u3001&gt;&gt;8 \u8bfb\u8005\u6570<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">rt_mutex<\/td>\n<td align=\"left\">A<\/td>\n<td align=\"left\">owner \u5b57\u6bb5<\/td>\n<td align=\"left\">plist \u6216\u7ea2\u9ed1\u6811&#xff08;\u968f\u7248\u672c&#xff0c;\u5b9e\u6d4b\u4e3a\u51c6&#xff09;<\/td>\n<td align=\"left\">\u652f\u6301\u4f18\u5148\u7ea7\u7ee7\u627f<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">semaphore<\/td>\n<td align=\"left\">A<\/td>\n<td align=\"left\">\u65e0<\/td>\n<td align=\"left\">wait_list \u94fe\u8868<\/td>\n<td align=\"left\">count \u4e3a\u53ef\u7528\u914d\u989d<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">spinlock_t \/ raw_spinlock_t<\/td>\n<td align=\"left\">B<\/td>\n<td align=\"left\">\u9ed8\u8ba4\u65e0&#xff1b;DEBUG \u914d\u7f6e\u4e0b\u6709 owner<\/td>\n<td align=\"left\">MCS&#xff0c;\u4e0d\u4fbf\u904d\u5386<\/td>\n<td align=\"left\">val&#xff1a;locked[7:0]\u3001pending[15:8]\u3001idx[17:16]\u3001tail_cpu[31:18]<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">rwlock_t<\/td>\n<td align=\"left\">B<\/td>\n<td align=\"left\">\u9ed8\u8ba4\u65e0<\/td>\n<td align=\"left\">MCS&#xff0c;\u4e0d\u4fbf\u904d\u5386<\/td>\n<td align=\"left\">cnts&#xff1a;wlocked \u4e3a byte 0&#xff0c;\u8bfb\u8005\u6570 &gt;&gt;8<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">seqlock_t<\/td>\n<td align=\"left\">\u2014<\/td>\n<td align=\"left\">\u5199\u4fa7\u770b\u5185\u90e8 spinlock<\/td>\n<td align=\"left\">\u4e0d\u53c2\u4e0e\u7b49\u5f85\u94fe<\/td>\n<td align=\"left\">seqcount \u5947\u6570&#061;\u5199\u8005\u6d3b\u8dc3<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">RCU<\/td>\n<td align=\"left\">\u2014<\/td>\n<td align=\"left\">\u65e0&#xff08;\u975e\u9501&#xff09;<\/td>\n<td align=\"left\">\u65e0<\/td>\n<td align=\"left\">stall \u53e6\u6709\u5224\u522b\u65b9\u5f0f&#xff0c;\u89c1\u7b2c\u5341\u4e00\u7ae0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u8868\u4e2d\u4e24\u884c\u9700\u8981\u7279\u522b\u8bf4\u660e&#xff1a;<\/p>\n<p>seqlock_t \u4e0d\u53c2\u4e0e\u7b49\u5f85\u94fe\u3002 \u5b83\u7684\u8bfb\u8005\u662f\u91cd\u8bd5\u800c\u975e\u963b\u585e&#xff0c;\u6c38\u8fdc\u4e0d\u4f1a\u51fa\u73b0\u5728 D \u72b6\u6001\u4efb\u52a1\u91cc&#xff1b;\u5199\u4fa7\u7684\u4e92\u65a5\u4f9d\u8d56\u5185\u90e8\u7684 spinlock&#xff0c;\u82e5\u5199\u8005\u5361\u4f4f&#xff0c;\u6309\u8def\u7ebf B \u5904\u7406\u5373\u53ef\u3002\u56e0\u6b64\u672c\u7bc7\u4e0d\u4e3a\u5b83\u5355\u8bbe\u7ae0\u8282\u3002\u5b83\u552f\u4e00\u503c\u5f97\u8b66\u60d5\u7684\u662f\u4e00\u79cd\u8bef\u5224\u6a21\u5f0f&#xff08;\u8bfb\u8005\u7a7a\u8f6c\u5bfc\u81f4 CPU \u9ad8\u4f46\u65e0\u8fdb\u7a0b\u963b\u585e&#xff09;&#xff0c;\u5f52\u5165\u7b2c\u5341\u4e00\u7ae0\u3002<\/p>\n<p>semaphore \u6709\u7b49\u5f85\u94fe\u4f46\u65e0 owner\u3002 \u8fd9\u662f\u4e2a\u7279\u4f8b&#xff1a;\u80fd\u7761\u7720&#xff0c;\u6240\u4ee5\u6709 wait_list \u53ef\u904d\u5386&#xff1b;\u4f46\u5b83\u662f\u8ba1\u6570\u4fe1\u53f7\u91cf&#xff0c;\u8bed\u4e49\u4e0a\u5141\u8bb8\u591a\u4e2a\u6301\u6709\u8005&#xff0c;\u56e0\u6b64\u4e0d\u8bb0\u5f55\u5355\u4e00 owner\u3002\u5206\u6790\u65f6\u53ea\u80fd\u62ff\u5230&#034;\u8c01\u5728\u7b49&#034;&#xff0c;\u62ff\u4e0d\u5230&#034;\u8c01\u6301\u6709&#034;\u3002<\/p>\n<p>rt_mutex \u7684\u7b49\u5f85\u961f\u5217\u7ed3\u6784\u968f\u5185\u6838\u7248\u672c\u53d8\u5316\u3002 \u65e9\u671f\u5b9e\u73b0\u4e3a plist_head&#xff08;\u4f18\u5148\u7ea7\u6392\u5e8f\u94fe\u8868&#xff09;&#xff0c;\u8f83\u65b0\u7248\u672c\u6539\u4e3a rb_root_cached&#xff08;\u7ea2\u9ed1\u6811&#xff09;\u3002\u904d\u5386\u524d\u987b\u7528 struct rt_mutex \u786e\u8ba4\u8be5\u5185\u6838\u7684\u5b9e\u9645\u7c7b\u578b\u2014\u2014\u4e24\u79cd\u7ed3\u6784\u7684\u904d\u5386\u547d\u4ee4\u4e0d\u540c&#xff0c;\u5957\u9519\u4f1a\u76f4\u63a5\u5931\u8d25\u3002<\/p>\n<hr \/>\n<h3>\u4e09\u3001\u8def\u7ebf A&#xff1a;\u8bfb\u7ed3\u6784\u5b9a\u6301\u6709\u8005<\/h3>\n<p>\u7761\u7720\u9501\u7684\u5206\u6790\u4e4b\u6240\u4ee5\u7b80\u5355&#xff0c;\u662f\u56e0\u4e3a\u7b2c\u4e8c\u7c7b\u8fb9\u76f4\u63a5\u5199\u5728\u7ed3\u6784\u91cc\u3002\u672c\u7ae0\u8bb2\u6e05\u4e00\u5957\u901a\u7528\u624b\u6cd5&#xff0c;\u5404\u9501\u7684\u5dee\u5f02\u53ea\u5728\u5c11\u6570\u51e0\u5904\u3002<\/p>\n<h4>3.1 owner \u7f16\u7801&#xff1a;\u4e00\u5957\u89c4\u5219&#xff0c;\u591a\u9501\u901a\u7528<\/h4>\n<p>mutex \u4e0e rw_semaphore \u7684 owner \u5b57\u6bb5\u91c7\u7528\u4f4e\u4f4d\u590d\u7528\u6807\u5fd7\u3001\u9ad8\u4f4d\u5b58\u6307\u9488\u7684\u540c\u7c7b\u601d\u8def&#xff1a;\u7c7b\u578b\u90fd\u662f atomic_long_t\u3002\u4f46\u4e8c\u8005\u7684\u6807\u5fd7\u4f4d\u6570\u91cf\u4e0e\u8bed\u4e49\u5e76\u4e0d\u76f8\u540c\u2014\u2014mutex \u7528\u4f4e 3 \u4f4d&#xff0c;rwsem \u7528\u4f4e 2 \u4f4d\u4e14\u542b\u4e49\u5b8c\u5168\u4e0d\u540c\u3002\u5171\u901a\u7684\u53ea\u662f\u63d0\u53d6\u6301\u6709\u8005\u7684\u52a8\u4f5c&#xff0c;\u63a9\u7801 ~0x7 \u5bf9\u4e24\u8005\u90fd\u9002\u7528&#xff08;\u5bf9 rwsem \u591a\u6e05\u4e86\u4e00\u4f4d\u672a\u4f7f\u7528\u7684 bit2&#xff0c;\u4e0d\u5f71\u54cd\u7ed3\u679c&#xff09;\u3002<\/p>\n<p> 63                                        3   2   1   0<br \/>\n&#043;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#043;&#8212;&#043;&#8212;&#043;&#8212;&#043;<br \/>\n|        task_struct pointer  [63:3]       | . | . | . |<br \/>\n&#043;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#043;&#8212;&#043;&#8212;&#043;&#8212;&#043;<br \/>\n                                             flag bits<\/p>\n<p>\u4f4e 3 \u4f4d\u80fd\u88ab\u590d\u7528&#xff0c;\u662f\u56e0\u4e3a task_struct \u7531 slab \u5206\u914d\u5668\u5206\u914d&#xff0c;\u5bf9\u9f50\u7c92\u5ea6\u81f3\u5c11 8 \u5b57\u8282&#xff08;\u5b9e\u9645\u901a\u5e38\u662f L1_CACHE_BYTES&#xff0c;\u5178\u578b 64 \u5b57\u8282&#xff09;&#xff0c;\u6307\u9488\u4f4e 3 \u4f4d\u5929\u7136\u4e3a\u96f6\u3002<\/p>\n<p>\u6ce8\u610f\u4e0e\u5185\u6838\u6808\u533a\u5206&#xff1a;THREAD_SIZE&#xff08;\u901a\u5e38 16KB&#xff09;\u662f\u5185\u6838\u6808\u7684\u5927\u5c0f&#xff0c;\u4e0e task_struct \u7684\u5bf9\u9f50\u7c92\u5ea6\u65e0\u5173\u3002\u4e8c\u8005\u81ea 4.9&#xff08;x86_64&#xff09;\/ 4.10&#xff08;ARM64&#xff09;\u8d77\u5df2\u5206\u79bb&#xff0c;\u89c1\u7b2c\u516d\u7bc7 4.4 \u8282\u3002<\/p>\n<p>\u901a\u7528\u63d0\u53d6\u5f0f&#xff1a;<\/p>\n<p>holder &#061; owner.counter &amp; ~0x7UL<\/p>\n<p>holder &#061;&#061; 0   -&gt;  lock is free<br \/>\nholder !&#061; 0   -&gt;  holder is a task_struct pointer<\/p>\n<p>\u5404\u9501\u7684\u6807\u5fd7\u4f4d\u542b\u4e49\u4e0d\u540c&#xff0c;\u4f46\u63d0\u53d6\u6301\u6709\u8005\u7684\u52a8\u4f5c\u5b8c\u5168\u4e00\u6837\u3002<\/p>\n<p>mutex \u7684\u4e09\u4e2a\u6807\u5fd7\u4f4d&#xff1a;<\/p>\n<table>\n<tr>\u4f4d\u5b8f\u540d\u7f6e\u4f4d\u65f6\u673a<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">bit 0<\/td>\n<td align=\"left\">MUTEX_FLAG_WAITERS<\/td>\n<td align=\"left\">wait_list \u975e\u7a7a<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">bit 1<\/td>\n<td align=\"left\">MUTEX_FLAG_HANDOFF<\/td>\n<td align=\"left\">\u6301\u6709\u8005\u6b63\u5411\u7b2c\u4e00\u7b49\u5f85\u8005\u79fb\u4ea4<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">bit 2<\/td>\n<td align=\"left\">MUTEX_FLAG_PICKUP<\/td>\n<td align=\"left\">\u79fb\u4ea4\u76ee\u6807\u5df2\u88ab\u5524\u9192&#xff0c;\u53ef\u6765\u63a5\u9501<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>MUTEX_FLAGS \u63a9\u7801\u4e3a 0x07&#xff0c;\u81ea 4.10 mutex \u91cd\u5199\u4ee5\u6765\u7a33\u5b9a\u3002\u4ecd\u5efa\u8bae p MUTEX_FLAGS \u6216\u67e5\u76ee\u6807\u5185\u6838 include\/linux\/mutex.h \u786e\u8ba4\u3002<\/p>\n<p>crash \u64cd\u4f5c&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> p\/x <span class=\"token punctuation\">((<\/span>struct mutex *<span class=\"token punctuation\">)<\/span>0xffffffffc0789040<span class=\"token punctuation\">)<\/span>&#8211;<span class=\"token operator\">&gt;<\/span>owner.counter<br \/>\n<span class=\"token variable\">$1<\/span> <span class=\"token operator\">&#061;<\/span> 0xffff888207b48001<\/p>\n<p>\u62c6\u89e3&#xff1a;holder &#061; 0xffff888207b48001 &amp; ~0x7 &#061; 0xffff888207b48000&#xff0c;bit0 &#061; 1 \u8868\u793a\u6709\u7b49\u5f85\u8005\u3002<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> task 0xffff888207b48000<br \/>\nPID: <span class=\"token number\">4822<\/span><br \/>\nCOMM: worker-thread<\/p>\n<p>counter \u663e\u793a\u4e3a\u8d1f\u6570\u662f\u6b63\u5e38\u73b0\u8c61\u2014\u2014atomic_long_t \u662f\u6709\u7b26\u53f7\u7c7b\u578b&#xff0c;\u5185\u6838\u5730\u5740\u7684\u6700\u9ad8\u4f4d\u4e3a 1&#xff0c;\u76f4\u63a5\u6253\u5370\u4f1a\u5448\u73b0\u4e3a\u5927\u8d1f\u6570\u3002\u7528 p\/x \u4ee5\u5341\u516d\u8fdb\u5236\u8bfb\u53d6\u5373\u53ef\u3002<\/p>\n<h4>3.2 \u7b49\u5f85\u94fe\u904d\u5386&#xff1a;\u901a\u7528\u624b\u6cd5<\/h4>\n<p>\u7761\u7720\u9501\u7684\u7b49\u5f85\u8005\u90fd\u4ee5\u94fe\u8868\u5f62\u5f0f\u6302\u5728\u9501\u7684 wait_list \u4e0a\u3002\u7b49\u5f85\u8005\u63cf\u8ff0\u7b26\u7684\u7b2c\u4e00\u4e2a\u6210\u5458\u90fd\u662f list_head&#xff0c;\u56e0\u6b64 wait_list.next \u7684\u503c\u540c\u65f6\u4e5f\u662f\u7b2c\u4e00\u4e2a\u7b49\u5f85\u8005\u63cf\u8ff0\u7b26\u7684\u5730\u5740\u3002<\/p>\n<p><span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">mutex_waiter<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">list_head<\/span>        list<span class=\"token punctuation\">;<\/span>    <span class=\"token comment\">\/* offset 0 *\/<\/span><br \/>\n    <span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">task_struct<\/span>     <span class=\"token operator\">*<\/span>task<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">ww_acquire_ctx<\/span>  <span class=\"token operator\">*<\/span>ww_ctx<span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>&#034;\u504f\u79fb 0&#034;\u4e0d\u662f\u8de8\u7248\u672c\u4fdd\u8bc1&#xff0c;\u7528 struct mutex_waiter -o \u786e\u8ba4\u4e00\u6b21\u6210\u672c\u6781\u4f4e\u3002<\/p>\n<p>\u901a\u7528\u904d\u5386\u547d\u4ee4&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> list <span class=\"token operator\">&lt;<\/span>waiter_type<span class=\"token operator\">&gt;<\/span>.list <span class=\"token parameter variable\">-s<\/span> <span class=\"token operator\">&lt;<\/span>waiter_type<span class=\"token operator\">&gt;<\/span>.task <span class=\"token operator\">&lt;<\/span>wait_list.next<span class=\"token operator\">&gt;<\/span><\/p>\n<p>\u5b9e\u4f8b&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> list mutex_waiter.list <span class=\"token parameter variable\">-s<\/span> mutex_waiter.task 0xffff888207b48e20<br \/>\nffff888207b48e20<br \/>\n  task <span class=\"token operator\">&#061;<\/span> 0xffff888207a3c000<br \/>\nffff888207c5adc0<br \/>\n  task <span class=\"token operator\">&#061;<\/span> 0xffff888207c5a000<\/p>\n<p>list \u7684\u53c2\u6570\u5f62\u5f0f\u968f crash \u7248\u672c\u6709\u5dee\u5f02&#xff0c;\u7528\u524d help list \u786e\u8ba4\u3002<\/p>\n<p>\u4e00\u4e2a\u6709\u7528\u7684\u4ea4\u53c9\u9a8c\u8bc1\u624b\u6bb5\u3002 mutex_waiter \u5728\u5f53\u524d\u5b9e\u73b0\u4e2d\u4e0d\u662f\u4ece slab \u5206\u914d\u7684&#xff0c;\u5b83\u662f __mutex_lock() \u7684\u5c40\u90e8\u53d8\u91cf&#xff0c;\u5b58\u6d3b\u5728\u7b49\u5f85\u8fdb\u7a0b\u81ea\u5df1\u7684\u5185\u6838\u6808\u5e27\u4e0a&#xff1a;<\/p>\n<p><span class=\"token keyword\">static<\/span> <span class=\"token keyword\">int<\/span> <span class=\"token function\">__mutex_lock<\/span><span class=\"token punctuation\">(<\/span><span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">mutex<\/span> <span class=\"token operator\">*<\/span>lock<span class=\"token punctuation\">,<\/span> <span class=\"token punctuation\">.<\/span><span class=\"token punctuation\">.<\/span><span class=\"token punctuation\">.<\/span><span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">mutex_waiter<\/span> waiter<span class=\"token punctuation\">;<\/span>               <span class=\"token comment\">\/* on the caller&#039;s kernel stack *\/<\/span><br \/>\n    <span class=\"token function\">list_add_tail<\/span><span class=\"token punctuation\">(<\/span><span class=\"token operator\">&amp;<\/span>waiter<span class=\"token punctuation\">.<\/span>list<span class=\"token punctuation\">,<\/span> <span class=\"token operator\">&amp;<\/span>lock<span class=\"token operator\">-&gt;<\/span>wait_list<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">for<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">;<\/span><span class=\"token punctuation\">;<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">mutex_try_to_acquire<\/span><span class=\"token punctuation\">(<\/span>lock<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><br \/>\n            <span class=\"token keyword\">break<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token function\">schedule<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><br \/>\n    <span class=\"token function\">list_del<\/span><span class=\"token punctuation\">(<\/span><span class=\"token operator\">&amp;<\/span>waiter<span class=\"token punctuation\">.<\/span>list<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u56e0\u6b64 wait_list \u4e2d\u6bcf\u4e2a\u8282\u70b9\u7684\u5730\u5740&#xff0c;\u5e94\u843d\u5728\u67d0\u4e2a\u7b49\u5f85\u8fdb\u7a0b\u7684\u5185\u6838\u6808\u8303\u56f4\u5185\u3002\u4e0a\u4f8b\u4e2d 0xffff888207b48e20 \u4e0e PID 4821 \u7684\u6808\u5730\u5740\u543b\u5408&#xff0c;\u8bf4\u660e\u94fe\u8868\u5b8c\u597d&#xff1b;\u5bf9\u4e0d\u4e0a\u5219\u8bf4\u660e\u94fe\u8868\u53ef\u80fd\u5df2\u88ab\u7834\u574f\u3002<\/p>\n<p>\u8fd9\u5c5e\u4e8e\u5f53\u524d\u5b9e\u73b0\u4e0b\u7684\u53ef\u7528\u624b\u6bb5&#xff0c;\u800c\u975e\u5185\u6838\u7684\u56fa\u6709\u8bbe\u8ba1\u3002ww_mutex \u7b49\u53d8\u4f53\u7684\u7b49\u5f85\u8def\u5f84\u4e0d\u5b8c\u5168\u76f8\u540c&#xff0c;\u672a\u6765\u7248\u672c\u4e5f\u53ef\u80fd\u8c03\u6574\u3002<\/p>\n<h4>3.3 rw_semaphore \u7684\u4e09\u5904\u7279\u6b8a\u6027<\/h4>\n<p>rw_semaphore \u7684\u5206\u6790\u6d41\u7a0b\u4e0e mutex \u57fa\u672c\u4e00\u81f4&#xff0c;\u53ea\u6709\u4e09\u5904\u9700\u8981\u989d\u5916\u6ce8\u610f\u3002<\/p>\n<p>\u7279\u6b8a\u6027\u4e00&#xff1a;count \u5b57\u6bb5\u627f\u8f7d\u4e86\u72b6\u6001\u4e0e\u8bfb\u8005\u8ba1\u6570\u3002<\/p>\n<p> 63                              8   7  &#8230;  3   2   1   0<br \/>\n&#043;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#043;&#8212;&#8212;&#8212;&#8212;-&#043;&#8212;&#043;&#8212;&#043;&#8212;&#043;<br \/>\n|      reader count  [63:8]       |   reserved  | H | W | L |<br \/>\n&#043;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#043;&#8212;&#8212;&#8212;&#8212;-&#043;&#8212;&#043;&#8212;&#043;&#8212;&#043;<br \/>\n                        RWSEM_FLAG_HANDOFF  &lt;&#8212;&#8211;&#043;   |   |<br \/>\n                        RWSEM_FLAG_WAITERS  &lt;&#8212;&#8212;&#8212;&#043;   |<br \/>\n                        RWSEM_WRITER_LOCKED &lt;&#8212;&#8212;&#8212;&#8212;-&#043;<\/p>\n<table>\n<tr>count \u503c\u542b\u4e49<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">0x0<\/td>\n<td align=\"left\">\u5b8c\u5168\u7a7a\u95f2<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">0x1<\/td>\n<td align=\"left\">\u5199\u8005\u6301\u6709&#xff0c;\u65e0\u7b49\u5f85\u8005<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">0x3<\/td>\n<td align=\"left\">\u5199\u8005\u6301\u6709&#xff0c;\u6709\u7b49\u5f85\u8005<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">0x100<\/td>\n<td align=\"left\">\u4e00\u4e2a\u8bfb\u8005\u6301\u6709<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">0x302<\/td>\n<td align=\"left\">\u4e09\u4e2a\u8bfb\u8005&#xff0c;\u4e14\u6709\u7b49\u5f85\u8005&#xff08;\u901a\u5e38\u662f\u7b49\u5f85\u7684\u5199\u8005&#xff09;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u8fd9\u662f\u672c\u7bc7\u7248\u672c\u8f74\u6700\u9661\u7684\u4e00\u5904\u3002 rw_semaphore \u5728 5.3 \u524d\u540e\u7ecf\u5386\u91cd\u5199&#xff1a;\u65e9\u671f\u5b9e\u73b0\u7684 count \u7528&#034;\u8d1f\u6570\u8868\u793a\u5199\u9501&#034;\u7684\u504f\u79fb\u7f16\u7801&#xff08;RWSEM_ACTIVE_WRITE_BIAS \u4e00\u7ec4\u5e38\u91cf&#xff09;&#xff0c;\u4e0e\u4e0a\u8ff0\u4f4d\u6807\u5fd7\u7f16\u7801\u5b8c\u5168\u4e0d\u540c\u3002\u5206\u6790 5.3 \u4e4b\u524d\u7684\u5185\u6838&#xff08;\u542b 4.19 LTS&#xff09;\u65f6\u4e0a\u8868\u4e0d\u9002\u7528&#xff0c;\u987b\u67e5\u8be5\u7248\u672c\u7684 rwsem.h\u3002<\/p>\n<p>\u7279\u6b8a\u6027\u4e8c&#xff1a;\u8bfb\u8005\u6301\u6709\u65f6&#xff0c;owner \u4e0d\u542b\u5177\u4f53\u8fdb\u7a0b\u3002<\/p>\n<p>\u5199\u8005\u6301\u6709\u65f6 owner \u7684\u8bfb\u6cd5\u4e0e mutex \u5b8c\u5168\u76f8\u540c&#xff1b;\u4f46\u8bfb\u8005\u6301\u6709\u65f6&#xff0c;\u8be5\u5b57\u6bb5\u7684\u884c\u4e3a\u5728\u4e0d\u540c\u5185\u6838\u7248\u672c\u95f4\u5e76\u4e0d\u4e00\u81f4\u2014\u2014\u67d0\u4e9b\u7248\u672c\u8bbe\u4e3a\u56fa\u5b9a\u6807\u8bb0&#xff08;\u5982 RWSEM_READER_OWNED&#xff09;&#xff0c;\u67d0\u4e9b\u4fdd\u7559\u6700\u540e\u4e00\u4e2a\u8bfb\u8005\u7684 task_struct \u6307\u9488&#xff0c;\u67d0\u4e9b\u5219\u7f6e\u4e3a NULL\u3002<\/p>\n<p>\u65e0\u8bba\u54ea\u79cd\u5f62\u5f0f&#xff0c;\u90fd\u4e0d\u80fd\u7528\u5b83\u8ffd\u6eaf\u8bfb\u9501\u7684\u6301\u6709\u8005&#xff1a;\u56fa\u5b9a\u6807\u8bb0\u4e0d\u542b\u8fdb\u7a0b\u4fe1\u606f&#xff1b;\u5373\u4f7f\u4fdd\u7559\u4e86\u67d0\u4e2a\u8bfb\u8005\u7684\u6307\u9488&#xff0c;\u4e5f\u65e0\u6cd5\u8bc1\u660e\u8be5\u4efb\u52a1\u5f53\u524d\u4ecd\u6301\u6709\u8bfb\u9501&#xff0c;\u66f4\u65e0\u6cd5\u7ed9\u51fa\u5b8c\u6574\u7684\u8bfb\u8005\u96c6\u5408&#xff08;\u8bfb\u9501\u53ef\u88ab\u591a\u4e2a\u4efb\u52a1\u540c\u65f6\u6301\u6709&#xff09;\u3002<\/p>\n<p>\u56e0\u6b64&#034;\u8c01\u6301\u6709\u8bfb\u9501&#034;\u5728 vmcore \u4e2d\u65e0\u6cd5\u76f4\u63a5\u8bfb\u51fa\u2014\u2014\u6301\u6709\u8fb9\u5728\u8fd9\u91cc\u53c8\u65ad\u4e86\u4e00\u6b21&#xff0c;\u552f\u4e00\u53ef\u9760\u7684\u65b9\u6cd5\u662f\u904d\u5386 backtrace&#xff0c;\u627e\u51fa\u505c\u5728\u8bfb\u4e34\u754c\u533a\u5185\u7684\u4efb\u52a1\u3002\u8fd9\u662f\u8def\u7ebf A \u4e2d\u552f\u4e00\u4f1a\u9000\u5316\u7684\u573a\u666f\u3002<\/p>\n<p>\u7279\u6b8a\u6027\u4e09&#xff1a;\u7b49\u5f85\u8005\u961f\u5217\u4e2d\u8bfb\u8005\u4e0e\u5199\u8005\u6df7\u6392&#xff0c;\u987b\u9760 type \u533a\u5206\u3002<\/p>\n<p><span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">rwsem_waiter<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">list_head<\/span>        list<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">task_struct<\/span>     <span class=\"token operator\">*<\/span>task<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">enum<\/span> <span class=\"token class-name\">rwsem_waiter_type<\/span>  type<span class=\"token punctuation\">;<\/span>   <span class=\"token comment\">\/* WAITING_FOR_WRITE \/ _FOR_READ *\/<\/span><br \/>\n    <span class=\"token keyword\">unsigned<\/span> <span class=\"token keyword\">long<\/span>           timeout<span class=\"token punctuation\">;<\/span><br \/>\n    bool                    handoff_set<span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> list rwsem_waiter.list <span class=\"token parameter variable\">-s<\/span> rwsem_waiter.task,rwsem_waiter.type <span class=\"token punctuation\">\\\\<\/span><br \/>\n       <span class=\"token punctuation\">((<\/span>struct rw_semaphore *<span class=\"token punctuation\">)<\/span>0xffffffffc0801200<span class=\"token punctuation\">)<\/span>&#8211;<span class=\"token operator\">&gt;<\/span>wait_list.next<br \/>\n  task <span class=\"token operator\">&#061;<\/span> 0xffff888209201000<br \/>\n  <span class=\"token builtin class-name\">type<\/span> <span class=\"token operator\">&#061;<\/span> <span class=\"token number\">1<\/span>                    \u2190 RWSEM_WAITING_FOR_WRITE<\/p>\n<p>mutex \u7684 wait_list \u4e2d\u6240\u6709\u7b49\u5f85\u8005\u6027\u8d28\u76f8\u540c&#xff0c;\u56e0\u800c\u65e0\u9700\u7c7b\u578b\u6807\u8bb0&#xff1b;rw_semaphore \u7684\u961f\u5217\u91cc\u8bfb\u8005\u4e0e\u5199\u8005\u5171\u5b58&#xff0c;\u4e8c\u8005\u5bf9\u5e94\u5b8c\u5168\u4e0d\u540c\u7684\u95ee\u9898\u7c7b\u578b&#xff0c;\u6545\u9700 type \u5b57\u6bb5\u52a0\u4ee5\u533a\u5206&#xff1a;<\/p>\n<table>\n<tr>type \u53d6\u503c\u7b49\u5f85\u6027\u8d28\u5bf9\u5e94\u7684\u95ee\u9898\u7c7b\u578b<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">RWSEM_WAITING_FOR_WRITE<\/td>\n<td align=\"left\">\u7b49\u5f85\u5199\u9501<\/td>\n<td align=\"left\">\u4e0e\u53e6\u4e00\u5199\u8005\u4e92\u7b49&#xff0c;\u7ecf\u5178 ABBA<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">RWSEM_WAITING_FOR_READ<\/td>\n<td align=\"left\">\u7b49\u5f85\u8bfb\u9501<\/td>\n<td align=\"left\">\u5199\u8005\u4f18\u5148\u7b56\u7565\u5bfc\u81f4\u8bfb\u8005\u6392\u961f&#xff08;\u89c1\u7b2c\u4e94\u7ae0&#xff09;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u82e5\u7701\u7565\u8be5\u5b57\u6bb5&#xff0c;rw_semaphore \u961f\u5217\u4e2d\u7684\u8fd9\u4e24\u7c7b\u7b49\u5f85\u8005\u5728\u8f93\u51fa\u4e2d\u5b8c\u5168\u76f8\u540c\u2014\u2014\u5747\u8868\u73b0\u4e3a&#034;\u67d0\u4efb\u52a1\u963b\u585e\u5728\u8be5 rw_semaphore \u4e0a&#034;&#xff0c;\u4f46\u4e8c\u8005\u7684\u6210\u56e0\u4e0e\u4fee\u590d\u65b9\u5411\u622a\u7136\u4e0d\u540c\u3002<\/p>\n<p>type \u7684\u679a\u4e3e\u503c\u4ee5\u76ee\u6807\u5185\u6838\u7684 enum rwsem_waiter_type \u4e3a\u51c6&#xff0c;\u4e0d\u540c\u7248\u672c\u6b21\u5e8f\u53ef\u80fd\u4e0d\u540c\u3002<\/p>\n<h4>3.4 \u8def\u7ebf A \u4f55\u65f6\u4f1a\u5931\u7075<\/h4>\n<p>\u5373\u4f7f\u662f\u7761\u7720\u9501&#xff0c;\u4e5f\u6709\u8bfb\u4e0d\u51fa\u6301\u6709\u8005\u7684\u60c5\u51b5&#xff1a;<\/p>\n<p>1. rwsem held by READERS       -&gt; owner has no task info (see 3.3)<br \/>\n2. semaphore                   -&gt; no owner field by design<br \/>\n3. lock structure corrupted    -&gt; owner points to garbage; validate with<br \/>\n                                  &#096;task &lt;addr&gt;&#096; before trusting it<br \/>\n4. wait_list corrupted         -&gt; &#096;list&#096; traversal loops or aborts;<br \/>\n                                  cross-check with waiter stack addresses (3.2)<\/p>\n<p>\u7b2c\u4e09\u3001\u56db\u6761\u5c24\u5176\u8981\u7559\u610f&#xff1a;\u8bfb\u51fa\u6765\u7684\u503c\u5fc5\u987b\u9a8c\u8bc1\u3002owner \u89e3\u51fa\u7684\u5730\u5740\u82e5\u4e0d\u662f\u6709\u6548\u7684 task_struct&#xff0c;task &lt;addr&gt; \u4f1a\u62a5\u9519\u2014\u2014\u8fd9\u65f6\u5019\u4e0d\u662f&#034;\u6ca1\u627e\u5230\u6301\u6709\u8005&#034;&#xff0c;\u800c\u662f&#034;\u9501\u7ed3\u6784\u672c\u8eab\u5df2\u88ab\u7834\u574f&#034;&#xff0c;\u95ee\u9898\u6027\u8d28\u4ece\u6b7b\u9501\u8f6c\u4e3a\u5185\u5b58\u635f\u574f&#xff0c;\u5e94\u8f6c\u56de\u7b2c\u4e94\u7bc7\u7684\u65b9\u6cd5\u3002<\/p>\n<hr \/>\n<h3>\u56db\u3001\u8def\u7ebf B&#xff1a;\u81ea\u65cb\u9501\u7684\u4ea4\u53c9\u63a8\u65ad<\/h3>\n<h4>4.1 val \u80fd\u56de\u7b54\u4ec0\u4e48&#xff0c;\u4e0d\u80fd\u56de\u7b54\u4ec0\u4e48<\/h4>\n<p>\u81ea\u65cb\u9501\u9ed8\u8ba4\u4e0d\u8bb0\u5f55\u6301\u6709\u8005&#xff0c;\u5168\u90e8\u4fe1\u606f\u538b\u7f29\u5728\u4e00\u4e2a 32 \u4f4d\u7684 val \u91cc\u3002\u7406\u89e3\u5b83\u7684\u4fe1\u606f\u8fb9\u754c&#xff0c;\u6bd4\u80cc\u4e0b\u4f4d\u57df\u66f4\u91cd\u8981&#xff1a;<\/p>\n<p>val CAN tell you:<br \/>\n  &#8211; is the lock held right now          (locked byte !&#061; 0)<br \/>\n  &#8211; is anyone spinning in fast path     (pending byte !&#061; 0)<br \/>\n  &#8211; is there an MCS queue, and on which CPU is its tail<br \/>\n                                        (tail field)<\/p>\n<p>val CANNOT tell you:<br \/>\n  &#8211; WHO holds it            &lt;- this is HOLD edge, and it is missing<br \/>\n  &#8211; who is in the queue (except the tail CPU)<br \/>\n  &#8211; how long it has been held<\/p>\n<p>\u8fd9\u5c31\u662f\u8def\u7ebf B \u5168\u90e8\u56f0\u96be\u7684\u6839\u6e90\u3002 val \u53ea\u80fd\u786e\u8ba4&#034;\u8fb9\u5b58\u5728&#034;&#xff0c;\u8bf4\u4e0d\u51fa&#034;\u8fb9\u6307\u5411\u8c01&#034;&#xff0c;\u56e0\u6b64\u6301\u6709\u8005\u5fc5\u987b\u4ece\u522b\u5904\u63a8\u65ad\u3002<\/p>\n<p>qspinlock \u7684\u771f\u5b9e\u4f4d\u57df\u5e03\u5c40&#xff1a;<\/p>\n<p><span class=\"token comment\">\/* include\/asm-generic\/qspinlock_types.h *\/<\/span><br \/>\n<span class=\"token keyword\">typedef<\/span> <span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">qspinlock<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token keyword\">union<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token class-name\">atomic_t<\/span> val<span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">struct<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n            u8  locked<span class=\"token punctuation\">;<\/span>          <span class=\"token comment\">\/* byte 0 *\/<\/span><br \/>\n            u8  pending<span class=\"token punctuation\">;<\/span>         <span class=\"token comment\">\/* byte 1 *\/<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">struct<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n            u16 locked_pending<span class=\"token punctuation\">;<\/span>  <span class=\"token comment\">\/* bytes 0-1 *\/<\/span><br \/>\n            u16 tail<span class=\"token punctuation\">;<\/span>            <span class=\"token comment\">\/* bytes 2-3 *\/<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span> <span class=\"token class-name\">arch_spinlock_t<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>locked \u4e0e pending \u5404\u5360\u4e00\u6574\u4e2a\u5b57\u8282&#xff0c;\u8fd9\u662f\u7406\u89e3\u4f4d\u57df\u7684\u5173\u952e&#xff1a;<\/p>\n<p> 31              18 17  16 15            8 7             0<br \/>\n&#043;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#043;&#8212;&#8212;&#043;&#8212;&#8212;&#8212;&#8212;&#8212;&#043;&#8212;&#8212;&#8212;&#8212;&#8212;&#043;<br \/>\n|     tail_cpu     | idx  |    pending    |    locked     |<br \/>\n|     [31:18]      |[17:16]|    [15:8]    |     [7:0]     |<br \/>\n&#043;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#043;&#8212;&#8212;&#043;&#8212;&#8212;&#8212;&#8212;&#8212;&#043;&#8212;&#8212;&#8212;&#8212;&#8212;&#043;<\/p>\n<table>\n<tr>\u5b57\u6bb5\u4f4d\u8303\u56f4OFFSET \u5b8f\u8bed\u4e49<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">locked<\/td>\n<td align=\"left\">[7:0]<\/td>\n<td align=\"left\">_Q_LOCKED_OFFSET &#061; 0<\/td>\n<td align=\"left\">\u975e\u96f6\u8868\u793a\u9501\u88ab\u6301\u6709<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">pending<\/td>\n<td align=\"left\">[15:8]<\/td>\n<td align=\"left\">_Q_PENDING_OFFSET &#061; 8<\/td>\n<td align=\"left\">\u5feb\u901f\u8def\u5f84\u4e0a\u7684\u7b2c\u4e8c\u4e2a\u7ade\u4e89\u8005<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">tail_idx<\/td>\n<td align=\"left\">[17:16]<\/td>\n<td align=\"left\">_Q_TAIL_IDX_OFFSET &#061; 16<\/td>\n<td align=\"left\">\u4e0a\u4e0b\u6587&#xff1a;0&#061;task 1&#061;softirq 2&#061;hardirq 3&#061;NMI<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">tail_cpu<\/td>\n<td align=\"left\">[31:18]<\/td>\n<td align=\"left\">_Q_TAIL_CPU_OFFSET &#061; 18<\/td>\n<td align=\"left\">\u961f\u5c3e CPU \u7f16\u53f7 &#043;1&#xff08;0 \u8868\u793a\u961f\u5217\u7a7a&#xff09;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>pending \u5bbd\u5ea6\u662f\u914d\u7f6e\u76f8\u5173\u7684\u3002 \u4e0a\u8868\u9002\u7528\u4e8e NR_CPUS &lt; 16K \u7684\u5e38\u89c4\u914d\u7f6e&#xff08;_Q_PENDING_BITS &#061; 8&#xff09;&#xff1b;\u8d85\u5927\u89c4\u6a21\u914d\u7f6e\u4e0b pending \u538b\u7f29\u4e3a 1 \u4f4d&#xff0c;\u5404\u5b57\u6bb5\u504f\u79fb\u968f\u4e4b\u6539\u53d8\u3002\u7528 p _Q_TAIL_CPU_OFFSET \u5b9e\u6d4b&#xff0c;\u6216\u76f4\u63a5\u770b\u8be5\u5185\u6838\u7684 qspinlock_types.h\u3002<\/p>\n<p>\u5b9e\u7528\u8bfb\u6cd5&#xff1a;\u4e0d\u5fc5\u624b\u5de5\u79fb\u4f4d&#xff0c;crash \u76f4\u63a5\u7ed9\u5b57\u8282\u89c6\u56fe\u3002<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> struct qspinlock ffffffffc0909040<br \/>\nstruct qspinlock <span class=\"token punctuation\">{<\/span><br \/>\n  <span class=\"token punctuation\">{<\/span><br \/>\n    val <span class=\"token operator\">&#061;<\/span> <span class=\"token punctuation\">{<\/span> counter <span class=\"token operator\">&#061;<\/span> <span class=\"token number\">262145<\/span> <span class=\"token punctuation\">}<\/span>,<br \/>\n    <span class=\"token punctuation\">{<\/span> locked <span class=\"token operator\">&#061;<\/span> <span class=\"token number\">1<\/span>, pending <span class=\"token operator\">&#061;<\/span> <span class=\"token number\">0<\/span> <span class=\"token punctuation\">}<\/span>,<br \/>\n    <span class=\"token punctuation\">{<\/span> locked_pending <span class=\"token operator\">&#061;<\/span> <span class=\"token number\">1<\/span>, <span class=\"token function\">tail<\/span> <span class=\"token operator\">&#061;<\/span> <span class=\"token number\">4<\/span> <span class=\"token punctuation\">}<\/span><br \/>\n  <span class=\"token punctuation\">}<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>locked &#061; 1 \u2192 \u9501\u88ab\u6301\u6709&#xff1b;tail &#061; 4&#xff0c;4 &gt;&gt; 2 &#061; 1 \u5373 tail_cpu &#061; 1&#xff0c;\u5bf9\u5e94 CPU 0 \u5728\u6392\u961f&#xff08;\u7f16\u7801\u662f CPU \u53f7 &#043;1&#xff09;\u3002<\/p>\n<p>\u9700\u8981\u624b\u5de5\u6362\u7b97\u65f6&#xff1a;<\/p>\n<p>tail_cpu_field &#061; (val &gt;&gt; 18)          -&gt; CPU number &#043; 1  (0 means empty)<br \/>\ntail_idx       &#061; (val &gt;&gt; 16) &amp; 0x3    -&gt; 0&#061;task 1&#061;softirq 2&#061;hardirq 3&#061;NMI<br \/>\npending        &#061; (val &gt;&gt; 8)  &amp; 0xFF<br \/>\nlocked         &#061;  val        &amp; 0xFF<\/p>\n<p>\u5e38\u89c1\u53d6\u503c\u901f\u67e5&#xff08;\u5747\u53ef\u7528\u4e0a\u5f0f\u590d\u6838&#xff09;&#xff1a;<\/p>\n<table>\n<tr>val\u5341\u8fdb\u5236lockedpendingtail_idxtail_cpu \u5b57\u6bb5\u72b6\u6001<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">0x00000000<\/td>\n<td align=\"left\">0<\/td>\n<td align=\"left\">0<\/td>\n<td align=\"left\">0<\/td>\n<td align=\"left\">\u2014<\/td>\n<td align=\"left\">0<\/td>\n<td align=\"left\">\u7a7a\u95f2<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">0x00000001<\/td>\n<td align=\"left\">1<\/td>\n<td align=\"left\">1<\/td>\n<td align=\"left\">0<\/td>\n<td align=\"left\">\u2014<\/td>\n<td align=\"left\">0<\/td>\n<td align=\"left\">\u5df2\u6301\u6709&#xff0c;\u65e0\u7ade\u4e89\u8005&#xff0c;\u961f\u5217\u7a7a<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">0x00000101<\/td>\n<td align=\"left\">257<\/td>\n<td align=\"left\">1<\/td>\n<td align=\"left\">1<\/td>\n<td align=\"left\">\u2014<\/td>\n<td align=\"left\">0<\/td>\n<td align=\"left\">\u5df2\u6301\u6709&#xff0c;\u4e00\u4e2a CPU \u5728\u5feb\u901f\u8def\u5f84\u81ea\u65cb<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">0x00040001<\/td>\n<td align=\"left\">262145<\/td>\n<td align=\"left\">1<\/td>\n<td align=\"left\">0<\/td>\n<td align=\"left\">0&#xff08;task&#xff09;<\/td>\n<td align=\"left\">1 \u2192 CPU 0<\/td>\n<td align=\"left\">\u5df2\u6301\u6709&#xff0c;\u961f\u5c3e\u5728 CPU 0&#xff0c;task \u4e0a\u4e0b\u6587<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">0x00080001<\/td>\n<td align=\"left\">524289<\/td>\n<td align=\"left\">1<\/td>\n<td align=\"left\">0<\/td>\n<td align=\"left\">0&#xff08;task&#xff09;<\/td>\n<td align=\"left\">2 \u2192 CPU 1<\/td>\n<td align=\"left\">\u5df2\u6301\u6709&#xff0c;\u961f\u5c3e\u5728 CPU 1&#xff0c;task \u4e0a\u4e0b\u6587<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">0x00050001<\/td>\n<td align=\"left\">327681<\/td>\n<td align=\"left\">1<\/td>\n<td align=\"left\">0<\/td>\n<td align=\"left\">1&#xff08;softirq&#xff09;<\/td>\n<td align=\"left\">1 \u2192 CPU 0<\/td>\n<td align=\"left\">\u5df2\u6301\u6709&#xff0c;\u961f\u5c3e\u5728 CPU 0&#xff0c;softirq \u4e0a\u4e0b\u6587<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u4ee5 0x00050001 \u4e3a\u4f8b\u590d\u6838&#xff1a;val &gt;&gt; 18 &#061; 1&#xff0c;tail_cpu \u5b57\u6bb5\u4e3a 1&#xff0c;\u5bf9\u5e94\u5b9e\u9645 CPU 0&#xff08;\u8be5\u5b57\u6bb5\u7f16\u7801\u4e3a CPU \u7f16\u53f7\u52a0\u4e00&#xff09;&#xff1b;(val &gt;&gt; 16) &amp; 0x3 &#061; 1&#xff0c;tail_idx \u4e3a 1&#xff0c;\u5bf9\u5e94 softirq \u4e0a\u4e0b\u6587\u3002tail_cpu \u5b57\u6bb5\u4e3a 0 \u65f6\u8868\u793a\u961f\u5217\u4e3a\u7a7a&#xff0c;\u6b64\u65f6\u4e0d\u5b58\u5728\u961f\u5c3e&#xff0c;tail_idx \u4ea6\u65e0\u610f\u4e49\u2014\u2014\u8868\u4e2d\u524d\u4e09\u884c\u7684\u8be5\u5217\u6807\u4e3a \u2014 \u5373\u56e0\u5982\u6b64\u3002<\/p>\n<p>qrwlock \u540c\u7406\u3002 rwlock_t \u5728\u542f\u7528 CONFIG_QUEUED_RWLOCKS \u65f6\u4f7f\u7528 qrwlock \u5b9e\u73b0&#xff0c;\u540c\u5c5e\u8def\u7ebf B&#xff0c;\u540c\u6837\u65e0 owner&#xff1a;<\/p>\n<p>cnts layout:<br \/>\n  byte 0        &#061; wlocked     0x00 free \/ 0x01 _QW_WAITING \/ 0xFF _QW_LOCKED<br \/>\n  bits [31:8]   &#061; reader count<\/p>\n<p>reader_count &#061; cnts &gt;&gt; 8<br \/>\n               when wlocked &#061;&#061; 0xFF (write-locked), this is always 0<br \/>\n               otherwise it reflects the actual reader count<\/p>\n<p>wlocked &#061;&#061; 0x01&#xff08;_QW_WAITING&#xff09;\u662f\u6700\u6709\u8bca\u65ad\u4ef7\u503c\u7684\u4e2d\u95f4\u6001&#xff1a;\u5199\u8005\u5df2\u5728\u6392\u961f&#xff0c;\u6b63\u7b49\u73b0\u5b58\u8bfb\u8005\u9000\u51fa\u3002\u6b64\u65f6\u8bfb\u8005\u8ba1\u6570\u4ecd\u7136\u6709\u6548&#xff0c;\u4e14\u6b63\u662f\u5199\u8005\u8981\u7b49\u7684\u5bf9\u8c61\u3002\u82e5\u8be5\u72b6\u6001\u957f\u671f\u4e0d\u53d8&#xff0c;\u8bf4\u660e\u5b58\u5728&#034;\u5199\u8005\u88ab\u8bfb\u8005\u6d41\u997f\u6b7b&#034;\u7684\u73b0\u8c61\u3002<\/p>\n<h4>4.2 \u8def\u7ebf\u5224\u5b9a&#xff1a;\u770b\u8fd9\u628a\u9501\u7684\u7ed3\u6784\u91cc\u6709\u6ca1\u6709\u6301\u6709\u8005\u5b57\u6bb5<\/h4>\n<p>\u8def\u7ebf A \u4e0e\u8def\u7ebf B \u7684\u5206\u91ce\u4e0d\u53d6\u51b3\u4e8e\u9501\u7684\u540d\u5b57&#xff0c;\u800c\u53d6\u51b3\u4e8e\u5b83\u7684\u7ed3\u6784\u91cc\u662f\u5426\u8bb0\u5f55\u4e86\u6301\u6709\u8005\u3002\u5224\u5b9a\u65b9\u5f0f\u5bf9\u4efb\u4f55\u9501\u90fd\u4e00\u6837\u2014\u2014\u7528\u9501\u7684\u5b9e\u9645\u7c7b\u578b\u540d\u67e5\u770b\u7ed3\u6784\u5b9a\u4e49&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> struct <span class=\"token operator\">&lt;<\/span>lock_type<span class=\"token operator\">&gt;<\/span><\/p>\n<p>\u8f93\u51fa\u4e2d\u51fa\u73b0 owner\u3001owner_cpu \u6216\u8bed\u4e49\u7b49\u4ef7\u7684\u5b57\u6bb5&#xff0c;\u5373\u8d70\u8def\u7ebf A&#xff08;3.1 \u8282\u7684\u63d0\u53d6\u5f0f\u901a\u7528&#xff09;&#xff1b;\u6ca1\u6709&#xff0c;\u5219\u8d70\u8def\u7ebf B\u3002<\/p>\n<table>\n<tr>\u9501\u7c7b\u578b\u9ed8\u8ba4\u7ed3\u6784\u5224\u5b9a<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">mutex \/ rw_semaphore \/ rt_mutex<\/td>\n<td align=\"left\">\u6052\u6709 owner<\/td>\n<td align=\"left\">\u8def\u7ebf A<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">raw_spinlock \/ spinlock_t<\/td>\n<td align=\"left\">\u65e0&#xff1b;CONFIG_DEBUG_SPINLOCK \u4e0b\u6709 owner\u3001owner_cpu<\/td>\n<td align=\"left\">\u89c6\u914d\u7f6e<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">qrwlock \/ rwlock_t<\/td>\n<td align=\"left\">\u65e0<\/td>\n<td align=\"left\">\u8def\u7ebf B<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">\u9a71\u52a8\u81ea\u5b9a\u4e49\u539f\u8bed<\/td>\n<td align=\"left\">\u672a\u77e5&#xff0c;\u987b\u5b9e\u6d4b<\/td>\n<td align=\"left\">\u89c6\u7ed3\u6784<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u5173\u4e8e\u6700\u540e\u4e00\u884c\u3002 \u8be5\u5224\u5b9a\u540c\u6837\u9002\u7528\u4e8e\u9a71\u52a8\u81ea\u5b9a\u4e49\u7684\u540c\u6b65\u539f\u8bed&#xff0c;\u4f46\u4e0d\u80fd\u6309\u5b57\u6bb5\u540d\u5339\u914d\u2014\u2014\u5224\u636e\u662f\u7ed3\u6784\u4e2d\u662f\u5426\u5b58\u5728\u80fd\u5b9a\u4f4d\u5230\u6301\u6709\u8005\u7684\u6210\u5458\u3002\u7b26\u5408\u8be5\u6761\u4ef6\u7684\u5b57\u6bb5\u6709\u591a\u79cd\u5f62\u5f0f&#xff1a;\u7c7b\u578b\u4e3a struct task_struct * \u7684\u6307\u9488\u3001\u8bb0\u5f55 PID \u7684\u6574\u578b\u5b57\u6bb5\u3001\u8bb0\u5f55\u6301\u6709\u8005 CPU \u7f16\u53f7\u7684\u5b57\u6bb5\u7b49&#xff1b;\u5176\u547d\u540d\u53ef\u80fd\u662f owner\u3001holder\u3001locking_task \u6216\u5176\u4ed6\u4efb\u610f\u6807\u8bc6\u7b26\u3002\u5224\u5b9a\u65f6\u5e94\u5ba1\u67e5\u5b57\u6bb5\u7684\u7c7b\u578b\u4e0e\u8bed\u4e49&#xff0c;\u800c\u975e\u540d\u79f0\u3002<\/p>\n<p>\u5224\u5b9a\u4e3a\u8def\u7ebf B \u65f6&#xff0c;\u8f6c\u5165 4.4 \u8282\u7684\u63a8\u65ad\u6d41\u7a0b\u3002<\/p>\n<h4>4.3 MCS \u961f\u5217&#xff1a;\u5b83\u8bb0\u5f55\u7684\u4e0d\u662f task&#xff0c;\u56e0\u6b64\u5bf9\u7b49\u5f85\u56fe\u6ca1\u6709\u8d21\u732e<\/h4>\n<p>\u81ea\u65cb\u9501\u7684\u7b49\u5f85\u8005\u7ec4\u7ec7\u6210 MCS \u961f\u5217\u3002\u8fd9\u4e2a\u961f\u5217\u5728\u6280\u672f\u4e0a\u53ef\u4ee5\u904d\u5386&#xff0c;\u4f46\u5b83\u8bb0\u5f55\u7684\u662f per-CPU \u7684\u8282\u70b9\u800c\u975e task_struct&#xff0c;\u56e0\u6b64\u65e0\u6cd5\u4ea7\u51fa\u7b49\u5f85\u56fe\u6240\u9700\u7684\u4efb\u4f55\u4e00\u7c7b\u8fb9\u2014\u2014\u8fd9\u662f\u672c\u8282\u7684\u6838\u5fc3\u7ed3\u8bba&#xff0c;\u673a\u5236\u7ec6\u8282\u670d\u52a1\u4e8e\u7406\u89e3\u8fd9\u4e00\u70b9\u3002<\/p>\n<p><span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">mcs_spinlock<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">mcs_spinlock<\/span> <span class=\"token operator\">*<\/span>next<span class=\"token punctuation\">;<\/span>   <span class=\"token comment\">\/* \u961f\u5217\u4e2d\u7684\u4e0b\u4e00\u4e2a\u7b49\u5f85\u8005 *\/<\/span><br \/>\n    <span class=\"token keyword\">int<\/span>                  locked<span class=\"token punctuation\">;<\/span> <span class=\"token comment\">\/* 0&#061;\u4ecd\u5728\u7b49\u5f85&#xff0c;1&#061;\u53ef\u4ee5\u5c1d\u8bd5\u83b7\u9501 *\/<\/span><br \/>\n    <span class=\"token keyword\">int<\/span>                  count<span class=\"token punctuation\">;<\/span>  <span class=\"token comment\">\/* \u5d4c\u5957\u5c42\u6570 *\/<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>\u8282\u70b9\u7684\u5b58\u653e\u4f4d\u7f6e&#xff1a;\u6bcf\u4e2a CPU \u6301\u6709\u4e00\u4e2a\u542b 4 \u4e2a\u5143\u7d20\u7684 per-CPU \u6570\u7ec4&#xff0c;\u56db\u4e2a\u5143\u7d20\u5206\u522b\u5bf9\u5e94 task \/ softirq \/ hardirq \/ NMI \u56db\u5c42\u5d4c\u5957\u4e0a\u4e0b\u6587\u3002<\/p>\n<p>val \u7684 tail \u5b57\u6bb5\u7528\u4e24\u4e2a\u5b50\u5b57\u6bb5\u5171\u540c\u5b9a\u4f4d\u961f\u5c3e\u8282\u70b9&#xff1a;<\/p>\n<p>tail_cpu [31:18]  -&gt;  which CPU        (encoded as CPU number &#043; 1)<br \/>\ntail_idx [17:16]  -&gt;  which of that CPU&#039;s 4 array slots (context level)<\/p>\n<p>\u6bcf\u4e2a\u7ade\u4e89\u8005\u628a\u81ea\u5df1\u8ffd\u52a0\u5230\u961f\u5c3e&#xff0c;\u5e76\u5728\u524d\u9a71\u8282\u70b9\u7684 locked \u5b57\u6bb5\u4e0a\u81ea\u65cb\u3002\u5404 CPU \u56e0\u6b64\u81ea\u65cb\u5728\u4e0d\u540c\u7684\u7f13\u5b58\u884c\u4e0a&#xff0c;\u8fd9\u662f MCS \u907f\u514d\u7f13\u5b58\u884c\u98a0\u7c38\u7684\u6838\u5fc3\u673a\u5236\u2014\u2014\u4e5f\u89e3\u91ca\u4e86\u4e3a\u4ec0\u4e48\u8fd9\u4e2a\u961f\u5217\u7684\u8bbe\u8ba1\u76ee\u6807\u662f\u7f13\u5b58\u5c40\u90e8\u6027&#xff0c;\u800c\u975e\u8bb0\u5f55\u7b49\u5f85\u8005\u8eab\u4efd\u3002<\/p>\n<p>\u7531\u6b64&#xff0c;\u904d\u5386 MCS \u961f\u5217\u5bf9\u5206\u6790\u7684\u5b9e\u9645\u4ef7\u503c&#xff1a;<\/p>\n<table>\n<tr>\u60f3\u77e5\u9053\u7684\u4fe1\u606fMCS \u961f\u5217\u80fd\u5426\u63d0\u4f9b<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">\u8c01\u6301\u6709\u8fd9\u628a\u9501&#xff08;\u6301\u6709\u8fb9&#xff09;<\/td>\n<td align=\"left\">\u5426\u2014\u2014\u961f\u5217\u53ea\u542b\u7b49\u5f85\u8005&#xff0c;\u6301\u6709\u8005\u4ece\u4e0d\u5165\u961f<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">\u54ea\u4e9b\u4efb\u52a1\u5728\u7b49&#xff08;\u7b49\u5f85\u8fb9&#xff09;<\/td>\n<td align=\"left\">\u5426\u2014\u2014\u8282\u70b9\u91cc\u6ca1\u6709 task_struct \u6307\u9488<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">\u961f\u5c3e\u5728\u54ea\u9897 CPU<\/td>\n<td align=\"left\">\u80fd&#xff0c;\u4e14 tail \u5b57\u6bb5\u76f4\u63a5\u7ed9\u51fa&#xff0c;\u65e0\u9700\u904d\u5386<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u4e09\u884c\u7ed3\u8bba\u4e00\u81f4&#xff1a;\u8be5\u7ed9\u7684\u4fe1\u606f tail \u5df2\u7ecf\u7ed9\u4e86&#xff0c;\u8be5\u8981\u7684\u4fe1\u606f\u961f\u5217\u91cc\u6ca1\u6709\u3002 \u56e0\u6b64\u5b9e\u6218\u4e2d\u4e0d\u89e3\u6790 MCS \u94fe&#xff0c;\u6301\u6709\u8005\u8eab\u4efd\u8d70 4.4 \u8282\u7684\u63a8\u65ad\u3002<\/p>\n<h4>4.4 \u4ea4\u53c9\u63a8\u65ad\u56db\u6b65\u6cd5<\/h4>\n<p>\u672c\u8282\u7684\u524d\u63d0\u662f\u5df2\u6309 4.2 \u8282\u7684\u8def\u7ebf\u5224\u5b9a\u786e\u8ba4\u8be5\u9501\u65e0\u6301\u6709\u8005\u5b57\u6bb5\u3002\u56db\u4e2a\u6b65\u9aa4\u5bf9\u4efb\u4f55\u65e0 owner \u7684\u9501\u90fd\u6210\u7acb&#xff0c;\u5176\u4e2d\u524d\u4e24\u6b65\u9700\u8981\u8bfb\u9501\u7684\u5177\u4f53\u5b57\u6bb5&#xff0c;\u5404\u9501\u7684\u8bfb\u6cd5\u89c1\u6b65\u9aa4\u540e\u7684\u5bf9\u7167\u8868\u3002<\/p>\n<p>STEP 1  Verify the premise: is the lock actually held?<br \/>\n        the backtrace only proves the task is INSIDE the acquire path;<br \/>\n        it does NOT prove the lock is currently taken by someone else.<br \/>\n        read the lock&#039;s state field to confirm.<\/p>\n<p>        held      -&gt; premise holds, proceed to STEP 2<br \/>\n        not held  -&gt; the premise is wrong. Check, in order:<br \/>\n                       &#8211; is the lock address correct?    (re-read dis)<br \/>\n                       &#8211; is the backtrace trustworthy?   (see 9.2)<br \/>\n                       &#8211; if both are fine, this is not a lock problem<br \/>\n                         -&gt; go to chapter 11<\/p>\n<p>STEP 2  Narrow the candidate set<br \/>\n        extract whatever locality information the lock exposes<br \/>\n        (queue tail CPU, waiter count, etc.)<br \/>\n        -&gt; this narrows WHERE to look, never WHO holds it<\/p>\n<p>STEP 3  Sweep per-CPU backtraces<br \/>\n        crash&gt; foreach bt          (or bt -c 0 .. bt -c N)<br \/>\n        look for a CPU that is NOT blocked on this lock,<br \/>\n        but whose call path has already acquired it<br \/>\n        -&gt; the ONLY step that can identify the holder<\/p>\n<p>STEP 4  Disassemble to confirm the acquisition order<br \/>\n        crash&gt; dis &lt;func&gt; &lt;n&gt;<br \/>\n        find the point where this lock is held and another is requested<\/p>\n<p>\u5173\u4e8e STEP 1\u3002 \u8d70\u5230\u8fd9\u91cc\u65f6&#xff0c;\u4f60\u5df2\u7ecf\u4ece\u67d0\u4e2a\u4efb\u52a1\u7684 backtrace \u5f97\u5230\u4e86\u4e00\u6761\u7b49\u5f85\u8fb9&#xff0c;\u4f46 backtrace \u53cd\u6620\u7684\u662f\u4efb\u52a1\u5f53\u65f6\u5728\u6267\u884c\u54ea\u6bb5\u4ee3\u7801&#xff0c;\u5b83\u4e0d\u80fd\u8bc1\u660e\u9501\u6b64\u523b\u771f\u7684\u88ab\u522b\u4eba\u62ff\u7740\u3002\u4e8c\u8005\u5bf9\u4e0d\u4e0a\u7684\u60c5\u5f62\u6709\u4e09\u79cd&#xff1a;\u9501\u521a\u88ab\u91ca\u653e\u800c\u7b49\u5f85\u8005\u5c1a\u672a\u9000\u51fa\u81ea\u65cb\u5faa\u73af&#xff1b;backtrace \u672c\u8eab\u4e0d\u53ef\u4fe1&#xff08;ARM64 \u8de8\u6808\u5931\u8d25\u6216\u6808\u5df2\u635f\u574f&#xff09;&#xff1b;\u4ece\u53cd\u6c47\u7f16\u91cc\u53d6\u9519\u4e86\u53c2\u6570&#xff0c;\u8bfb\u5230\u7684\u662f\u53e6\u4e00\u628a\u9501\u3002<\/p>\n<p>\u56e0\u6b64 STEP 1 \u7684\u804c\u8d23\u4e0d\u662f&#034;\u987a\u624b\u770b\u4e00\u773c\u72b6\u6001&#034;&#xff0c;\u800c\u662f\u5728\u6295\u5165\u9ad8\u6210\u672c\u63a8\u65ad\u4e4b\u524d\u9a8c\u8bc1\u524d\u63d0\u2014\u2014STEP 3 \u8981\u626b\u63cf\u5168\u90e8 CPU&#xff0c;\u82b1\u51e0\u79d2\u786e\u8ba4\u524d\u63d0\u6210\u7acb\u662f\u503c\u5f97\u7684\u3002\u82e5\u9501\u786e\u5b9e\u7a7a\u95f2\u3001\u5730\u5740\u65e0\u8bef\u3001backtrace \u53ef\u4fe1&#xff0c;\u90a3\u4e48&#034;\u8fd9\u662f\u4e2a\u9501\u95ee\u9898&#034;\u7684\u5b9a\u6027\u672c\u8eab\u5c31\u9519\u4e86\u3002<\/p>\n<p>\u5173\u4e8e STEP 3\u3002 \u8fd9\u662f\u552f\u4e00\u80fd\u5b9a\u51fa\u6301\u6709\u8005\u7684\u4e00\u6b65&#xff0c;\u4e5f\u662f\u6700\u8017\u65f6\u7684&#xff1a;\u8981\u627e\u7684\u4e0d\u662f&#034;\u5728\u7b49\u8fd9\u628a\u9501\u7684 CPU&#034;&#xff0c;\u800c\u662f&#034;\u5df2\u7ecf\u62ff\u5230\u8fd9\u628a\u9501\u3001\u6b63\u5728\u505a\u522b\u7684\u4e8b\u7684 CPU&#034;\u3002\u524d\u8005\u5728 queued_spin_lock_slowpath \u91cc&#xff0c;\u540e\u8005\u4e0d\u5728\u2014\u2014\u5b83\u53ef\u80fd\u6b63\u5728\u7b49\u53e6\u4e00\u628a\u9501\u3001\u7b49 I\/O&#xff0c;\u6216\u8005\u6b63\u8dd1\u5728\u4e00\u4e2a\u957f\u5faa\u73af\u91cc\u3002<\/p>\n<p>\u524d\u4e24\u6b65\u7684\u5404\u9501\u8bfb\u6cd5&#xff1a;<\/p>\n<table>\n<tr>\u9501\u7c7b\u578bSTEP 1&#xff1a;\u5224&#034;\u88ab\u6301\u6709&#034;STEP 2&#xff1a;\u53ef\u7528\u7684\u5b9a\u4f4d\u4fe1\u606f<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">qspinlock&#xff08;spinlock_t&#xff09;<\/td>\n<td align=\"left\">locked \u5b57\u8282\u975e\u96f6<\/td>\n<td align=\"left\">tail_cpu &#8211; 1 \u5f97\u961f\u5c3e CPU&#xff1b;pending \u975e\u96f6\u8868\u793a\u5feb\u901f\u8def\u5f84\u6709\u7ade\u4e89\u8005<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">qrwlock&#xff08;rwlock_t&#xff09;<\/td>\n<td align=\"left\">wlocked &#061;&#061; 0xFF \u4e3a\u5199\u9501\u6301\u6709&#xff1b;cnts &gt;&gt; 8 \u975e\u96f6\u4e3a\u8bfb\u9501\u6301\u6709<\/td>\n<td align=\"left\">wlocked &#061;&#061; 0x01 \u8868\u793a\u5199\u8005\u5df2\u5728\u6392\u961f&#xff1b;\u65e0\u961f\u5c3e CPU \u4fe1\u606f<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">ticket lock&#xff08;\u672a\u542f\u7528 QUEUED_SPINLOCKS&#xff09;<\/td>\n<td align=\"left\">owner !&#061; next<\/td>\n<td align=\"left\">\u4e8c\u8005\u4e4b\u5dee\u5373\u7b49\u5f85\u8005\u6570\u91cf&#xff1b;\u65e0 CPU \u4fe1\u606f<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">\u9a71\u52a8\u81ea\u5b9a\u4e49\u539f\u8bed<\/td>\n<td align=\"left\">\u987b\u8bfb\u8be5\u7ed3\u6784\u7684\u72b6\u6001\u5b57\u6bb5&#xff0c;\u5b9e\u6d4b\u786e\u5b9a<\/td>\n<td align=\"left\">\u89c6\u7ed3\u6784\u800c\u5b9a&#xff0c;\u53ef\u80fd\u6ca1\u6709<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u6700\u540e\u4e00\u884c\u662f\u5e38\u6001\u800c\u975e\u4f8b\u5916\u3002 \u9047\u5230\u672c\u7bc7\u672a\u8986\u76d6\u7684\u9501\u65f6&#xff0c;STEP 1 \u7684\u5224\u636e\u8981\u4ece\u5b83\u81ea\u5df1\u7684\u7ed3\u6784\u91cc\u627e&#xff08;\u901a\u5e38\u662f\u67d0\u4e2a\u8ba1\u6570\u6216\u6807\u5fd7\u5b57\u6bb5&#xff09;&#xff0c;STEP 2 \u53ef\u80fd\u5b8c\u5168\u6ca1\u6709\u53ef\u7528\u4fe1\u606f\u2014\u2014\u6b64\u65f6\u76f4\u63a5\u8df3\u5230 STEP 3&#xff0c;\u626b\u63cf\u5168\u90e8 CPU&#xff0c;\u4ee3\u4ef7\u662f\u5019\u9009\u8303\u56f4\u6ca1\u6709\u7f29\u5c0f\u3002<\/p>\n<h4>4.5 \u67b6\u6784\u5dee\u5f02\u5982\u4f55\u6539\u53d8&#034;\u80fd\u62ff\u5230\u4ec0\u4e48\u73b0\u573a&#034;<\/h4>\n<p>\u81ea\u65cb\u9501\u7684\u5206\u6790\u53d7\u67b6\u6784\u5f71\u54cd&#xff0c;\u4f46\u771f\u6b63\u9700\u8981\u5173\u5fc3\u7684\u4e0d\u662f\u6307\u4ee4\u5c42\u9762\u7684\u5dee\u5f02&#xff0c;\u800c\u662f\u54ea\u4e9b\u5dee\u5f02\u4f1a\u6539\u53d8\u6545\u969c\u80fd\u5426\u88ab\u53d1\u73b0\u3001\u73b0\u573a\u80fd\u5426\u88ab\u91c7\u96c6\u3002\u4ee5\u4e0b\u4e24\u6761\u5c5e\u4e8e\u6b64\u5217\u3002<\/p>\n<table>\n<tr>\u7ef4\u5ea6x86_64ARM64\u540e\u679c<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">\u81ea\u65cb\u7b49\u5f85\u6307\u4ee4<\/td>\n<td align=\"left\">PAUSE&#xff0c;\u6301\u7eed\u5360\u7528 CPU<\/td>\n<td align=\"left\">WFE&#xff0c;\u8fdb\u5165\u4f4e\u529f\u8017\u7b49\u5f85<\/td>\n<td align=\"left\">ARM64 \u81ea\u65cb\u4e0d\u70e7 CPU&#xff0c;\u57fa\u4e8e\u4f7f\u7528\u7387\u7684\u76d1\u63a7\u53ef\u80fd\u770b\u4e0d\u51fa\u5f02\u5e38<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">hard lockup \u68c0\u6d4b<\/td>\n<td align=\"left\">PMU \u9a71\u52a8\u7684 local APIC NMI&#xff0c;\u9ed8\u8ba4\u53ef\u7528<\/td>\n<td align=\"left\">\u9700\u4f2a NMI&#xff0c;\u6761\u4ef6\u82db\u523b&#xff08;\u89c1\u4e0b&#xff09;<\/td>\n<td align=\"left\">\u6761\u4ef6\u4e0d\u6ee1\u8db3\u65f6&#xff0c;\u5173\u4e2d\u65ad\u6b7b\u9501\u4e0d\u4ea7\u751f vmcore<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u5176\u4f59\u67b6\u6784\u5dee\u5f02&#xff08;\u5185\u5b58\u5e8f\u3001\u91ca\u653e\u65f6\u7684\u5524\u9192\u673a\u5236\u3001\u53d6\u5730\u5740\u4e0e\u8c03\u7528\u6307\u4ee4\u7684\u5199\u6cd5&#xff09;\u5c5e\u4e8e\u5b9e\u73b0\u7ec6\u8282&#xff0c;\u4e0d\u6539\u53d8\u5206\u6790\u7684\u53ef\u884c\u6027\u3002\u5176\u4e2d\u53cd\u6c47\u7f16\u76f8\u5173\u7684\u8bfb\u6cd5\u5dee\u5f02\u5728\u7b2c\u4e03\u7ae0 7.3 \u8282\u6709\u8bf4\u660e\u3002<\/p>\n<p>ARM64 \u7684 hard lockup \u68c0\u6d4b\u9700\u8981\u540c\u65f6\u6ee1\u8db3\u4e09\u4e2a\u6761\u4ef6&#xff1a;<\/p>\n<p>CONFIG_ARM64_PSEUDO_NMI&#061;y<br \/>\nGICv3 (or later) interrupt controller<br \/>\nfirmware support for interrupt priority masking<\/p>\n<p>\u4e09\u8005\u7f3a\u4e00&#xff0c;hard lockup \u68c0\u6d4b\u5373\u4e0d\u53ef\u7528\u3002\u5176\u540e\u679c\u9700\u5206\u4e24\u79cd\u60c5\u5f62\u7406\u89e3\u3002<\/p>\n<p>\u60c5\u5f62\u4e00&#xff1a;\u5361\u6b7b\u53d1\u751f\u5728\u5173\u4e2d\u65ad\u7684\u8def\u5f84\u4e0a\u3002 \u6b64\u65f6\u65e0\u4efb\u4f55\u673a\u5236\u53ef\u4ee5\u6253\u65ad\u8be5 CPU\u2014\u2014soft lockup \u4f9d\u8d56\u7684 watchdog hrtimer \u672c\u8eab\u8981\u9760\u4e2d\u65ad\u89e6\u53d1&#xff0c;\u4e2d\u65ad\u5df2\u5173\u5219\u65e0\u6cd5\u89e6\u53d1&#xff1b;\u4f2a NMI \u4e0d\u53ef\u7528&#xff0c;\u540c\u6837\u65e0\u4ece\u4ecb\u5165\u3002\u7cfb\u7edf\u9759\u9ed8\u5361\u6b7b&#xff0c;\u4e0d\u4ea7\u751f vmcore\u3002<\/p>\n<p>\u60c5\u5f62\u4e8c&#xff1a;\u5361\u6b7b\u53d1\u751f\u5728\u4e2d\u65ad\u4ecd\u5f00\u542f\u7684\u8def\u5f84\u4e0a\u3002 watchdog hrtimer \u53ef\u6b63\u5e38\u89e6\u53d1&#xff0c;soft lockup \u80fd\u591f\u6355\u83b7\u5e76\u4ea7\u751f vmcore\u3002<\/p>\n<p>\u56e0\u6b64\u8be5\u7c7b\u5e73\u53f0\u7684\u53ef\u68c0\u6d4b\u8303\u56f4\u88ab\u538b\u7f29\u4e3a\u60c5\u5f62\u4e8c&#xff1b;\u60c5\u5f62\u4e00\u5b8c\u5168\u4e0d\u53ef\u89c1&#xff0c;\u53ea\u80fd\u4f9d\u9760 SysRq \u7b49\u5916\u90e8\u624b\u6bb5\u4eba\u5de5\u53d6\u73b0\u573a\u3002<\/p>\n<p>\u5206\u6790 ARM64 vmcore \u524d\u503c\u5f97\u5148\u786e\u8ba4&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> sym gic_irq_nmi_setup      <span class=\"token comment\"># \u5b58\u5728\u8be5\u7b26\u53f7 -&gt; \u5df2\u7f16\u8bd1\u8fdb\u5185\u6838&#xff08;GICv3 \u5b9e\u73b0&#xff09;<\/span><br \/>\ncrash<span class=\"token operator\">&gt;<\/span> log <span class=\"token operator\">|<\/span> <span class=\"token function\">grep<\/span> <span class=\"token parameter variable\">-i<\/span> <span class=\"token string\">&#034;GICv3&#034;<\/span>      <span class=\"token comment\"># \u786e\u8ba4\u4e2d\u65ad\u63a7\u5236\u5668\u6ee1\u8db3\u786c\u4ef6\u6761\u4ef6<\/span><br \/>\ncrash<span class=\"token operator\">&gt;<\/span> log <span class=\"token operator\">|<\/span> <span class=\"token function\">grep<\/span> <span class=\"token parameter variable\">-i<\/span> <span class=\"token string\">&#034;pseudo-NMI&#034;<\/span> <span class=\"token comment\"># \u6709\u8f93\u51fa\u624d\u8bf4\u660e\u8fd0\u884c\u65f6\u5df2\u542f\u7528<\/span><br \/>\ncrash<span class=\"token operator\">&gt;<\/span> p saved_command_line       <span class=\"token comment\"># \u67e5 irqchip.gicv3_pseudo_nmi&#061;1 \u662f\u5426\u5b58\u5728<\/span><\/p>\n<p>\u7f16\u8bd1\u8fdb\u5185\u6838\u4e0e\u8fd0\u884c\u65f6\u542f\u7528\u662f\u4e24\u56de\u4e8b&#xff0c;\u4e24\u9879\u90fd\u8981\u67e5\u3002 \u8be5\u7279\u6027\u9ed8\u8ba4\u5173\u95ed&#xff0c;\u987b\u663e\u5f0f\u52a0\u542f\u52a8\u53c2\u6570\u624d\u751f\u6548\u3002\u53e6\u9700\u6ce8\u610f&#xff1a;irq_nmi_setup \u662f struct irq_chip \u7684\u6210\u5458\u540d\u800c\u975e\u5168\u5c40\u7b26\u53f7&#xff0c;sym irq_nmi_setup \u4f1a\u62a5 not found&#xff0c;\u5e94\u67e5\u5176 GICv3 \u5b9e\u73b0 gic_irq_nmi_setup\u3002<\/p>\n<p>\u8fd9\u6761\u786e\u8ba4\u6709\u4e2a\u76f4\u63a5\u7684\u63a8\u8bba\u4ef7\u503c&#xff1a;\u5982\u679c\u4e00\u4e2a ARM64 \u73b0\u573a\u662f soft lockup \u800c\u975e hard lockup&#xff0c;\u8bf4\u660e\u5361\u4f4f\u7684\u8def\u5f84\u4e2d\u65ad\u4ecd\u662f\u5f00\u7684\u2014\u2014\u8fd9\u5c31\u6392\u9664\u4e86 spin_lock_irqsave \u4e00\u7c7b\u5173\u4e2d\u65ad\u6301\u9501\u7684\u5acc\u7591&#xff0c;\u5acc\u7591\u8303\u56f4\u7acb\u523b\u7f29\u5c0f\u3002\u7b2c\u4e5d\u7ae0\u4f1a\u7528\u5230\u8fd9\u6761\u63a8\u7406\u3002<\/p>\n<hr \/>\n<h3>\u4e94\u3001\u6b7b\u9501\u7c7b\u578b\u56fe\u8c31<\/h3>\n<h4>ABBA \u6b7b\u9501&#xff08;\u6700\u5e38\u89c1&#xff09;<\/h4>\n<p>Task A:  holds Lock_X  &#8212;- waiting &#8212;-&gt;  Lock_Y<br \/>\nTask B:  holds Lock_Y  &#8212;- waiting &#8212;-&gt;  Lock_X<\/p>\n<p>\u7279\u5f81&#xff1a;\u4e24\u4e2a\u6216\u4ee5\u4e0a D \u72b6\u6001\u4efb\u52a1&#xff0c;\u5404\u81ea backtrace \u505c\u5728\u4e0d\u540c\u9501\u7684\u83b7\u53d6\u8def\u5f84&#xff0c;\u4ea4\u53c9\u8ffd\u8e2a owner \u5f62\u6210\u6709\u5411\u73af\u3002<\/p>\n<h4>\u81ea\u9501&#xff08;Self Deadlock&#xff09;<\/h4>\n<p>Task A:  holds Lock_X  &#8212;- (several call levels) &#8212;-&gt;  mutex_lock(Lock_X)<\/p>\n<p>mutex \u662f\u975e\u9012\u5f52\u9501&#xff0c;\u4e8c\u6b21\u52a0\u9501\u4f1a\u88ab\u81ea\u5df1\u7684 owner \u6c38\u8fdc\u963b\u585e\u3002\u8bc6\u522b\u7279\u5f81\u6781\u5176\u660e\u786e&#xff1a;\u4ece mutex.owner \u89e3\u51fa\u7684 task_struct \u5730\u5740&#xff0c;\u7b49\u4e8e\u5f53\u524d\u963b\u585e\u5728\u8be5\u9501\u4e0a\u7684\u4efb\u52a1\u5730\u5740\u2014\u2014\u81ea\u5df1\u7b49\u81ea\u5df1\u3002<\/p>\n<h4>\u4e2d\u65ad\u4e0a\u4e0b\u6587\u53c2\u4e0e\u7684\u6b7b\u9501<\/h4>\n<p>process context : spin_lock_irqsave(&amp;Lock_X)   \/* IRQ disabled *\/<br \/>\n                  wants Lock_Y<\/p>\n<p>hard IRQ        : spin_lock(&amp;Lock_Y)           \/* already holds Lock_Y *\/<br \/>\n                  wants Lock_X                 \/* held by process ctx  *\/<\/p>\n<p>\u5355 CPU \u4e0a&#xff0c;\u5173\u4e2d\u65ad\u540e\u4e2d\u65ad\u65e0\u6cd5\u62a2\u5360&#xff0c;\u6784\u6210\u672c CPU \u5185\u7684\u94fe\u8def\u6b7b\u9501&#xff1b;\u591a CPU \u4e0a\u5219\u662f\u8de8 CPU \u7684 ABBA\u3002\u7279\u5f81\u662f\u67d0 CPU \u7684\u4e2d\u65ad\u4e0a\u4e0b\u6587\u5e27&#xff08;do_IRQ \/ el1_irq&#xff09;\u4e2d\u6301\u6709 spinlock&#xff0c;\u53e6\u4e00 CPU \u7684\u8fdb\u7a0b\u8def\u5f84\u5728\u7b49\u540c\u4e00\u628a\u9501\u3002<\/p>\n<p>\u6309 4.5 \u8282\u7684\u63a8\u8bba&#xff0c;\u8fd9\u7c7b\u6b7b\u9501\u5728\u65e0\u4f2a NMI \u7684 ARM64 \u5e73\u53f0\u4e0a\u901a\u5e38\u62ff\u4e0d\u5230 vmcore\u2014\u2014\u5173\u4e2d\u65ad\u540e watchdog \u4e5f\u8fdb\u4e0d\u6765\u3002<\/p>\n<h4>\u9501\u987a\u5e8f\u4e0d\u4e00\u81f4&#xff08;\u6f5c\u5728\u6b7b\u9501&#xff09;<\/h4>\n<p>\u540c\u4e00\u5bf9\u9501\u5728\u4e0d\u540c\u4ee3\u7801\u8def\u5f84\u4e2d\u4ee5\u76f8\u53cd\u987a\u5e8f\u52a0\u9501\u3002\u5b83\u4e0d\u662f\u5fc5\u7136\u89e6\u53d1\u7684\u6b7b\u9501&#xff0c;\u4f46\u968f\u5e76\u53d1\u5ea6\u63d0\u9ad8\u8fdf\u65e9\u53d1\u751f\u3002lockdep \u5728\u7b2c\u4e00\u6b21\u8fdd\u53cd\u4f9d\u8d56\u987a\u5e8f\u65f6\u5373\u544a\u8b66&#xff0c;\u65e0\u9700\u7b49\u5230\u771f\u6b63\u6b7b\u9501\u2014\u2014\u8fd9\u662f\u7b2c\u5341\u7ae0\u7684\u4ef7\u503c\u6240\u5728\u3002<\/p>\n<h4>rwsem \u5199\u8005\u4f18\u5148\u5bfc\u81f4\u7684\u51c6\u6b7b\u9501<\/h4>\n<p>Task A (writer): holds rwsem      &#8212;- waiting &#8212;-&gt;  mutex_M<br \/>\nTask B (reader): holds mutex_M    &#8212;- waiting &#8212;-&gt;  rwsem (down_read)<\/p>\n<p>\u5199\u8005\u6301\u6709 rwsem \u7b49 mutex&#xff1b;\u8bfb\u8005\u6301\u6709 mutex \u5c1d\u8bd5 down_read\u3002\u7531\u4e8e RWSEM_FLAG_WAITERS \u5df2\u7f6e\u4f4d&#xff0c;rwsem \u5bf9\u65b0\u8bfb\u8005\u5b9e\u65bd\u5199\u8005\u4f18\u5148\u7b56\u7565&#xff0c;\u8bfb\u8005\u88ab\u6392\u961f\u800c\u975e\u76f4\u63a5\u83b7\u53d6\u2014\u2014\u4e8e\u662f\u53cc\u65b9\u4e92\u7b49\u3002\u672c\u8d28\u4ecd\u662f ABBA&#xff0c;\u53ea\u662f\u4e24\u4fa7\u9501\u7c7b\u578b\u4e0d\u540c\u3002<\/p>\n<p>\u8fd9\u7c7b\u6b7b\u9501\u5bb9\u6613\u88ab\u8bef\u5224\u4e3a&#034;\u8bfb\u9501\u600e\u4e48\u4f1a\u963b\u585e&#034;\u3002 \u5173\u952e\u5728\u4e8e\u7406\u89e3&#xff1a;\u6709\u5199\u8005\u5728\u6392\u961f\u65f6&#xff0c;\u8bfb\u8005\u4e0d\u80fd\u63d2\u961f&#xff0c;\u5426\u5219\u5199\u8005\u4f1a\u88ab\u6e90\u6e90\u4e0d\u65ad\u7684\u8bfb\u8005\u997f\u6b7b\u3002\u8fd9\u4e5f\u662f 3.3 \u8282\u5f3a\u8c03\u5fc5\u987b\u8bfb rwsem_waiter.type \u7684\u539f\u56e0\u2014\u2014\u4e0d\u8bfb type&#xff0c;\u5c31\u5206\u4e0d\u6e05\u773c\u524d\u662f&#034;\u4e24\u4e2a\u5199\u8005\u4e92\u7b49&#034;\u8fd8\u662f&#034;\u8bfb\u8005\u88ab\u6321\u5728\u95e8\u5916&#034;\u3002<\/p>\n<hr \/>\n<h3>\u516d\u3001\u7b49\u5f85\u94fe\u91cd\u5efa&#xff1a;\u5b8c\u6574\u65b9\u6cd5\u8bba<\/h3>\n<p>\u628a\u524d\u9762\u5404\u7ae0\u7684\u65b9\u6cd5\u4e32\u6210\u4e00\u6761\u5b8c\u6574\u8def\u5f84&#xff1a;<\/p>\n<p>STEP 1  Enumerate stalled tasks<br \/>\n        crash&gt; ps | grep &#034; UN &#034;<br \/>\n        crash&gt; ps -m | grep &#034; UN &#034;        (last-run delta, ordering only)<br \/>\n        record: PID  &lt;-&gt;  task_struct address<br \/>\n              |<br \/>\n              v<br \/>\nSTEP 2  Collect backtraces, extract WAIT edges<br \/>\n        crash&gt; foreach UN bt<br \/>\n        blocking point tells you the lock TYPE:<br \/>\n          __mutex_lock \/ rwsem_down_*        -&gt; PATH A  (ch.3)<br \/>\n          queued_spin_lock_slowpath          -&gt; PATH B  (ch.4)<br \/>\n        wait edge:  TASK  &#8212;- waits for &#8212;-&gt;  LOCK<br \/>\n              |<br \/>\n              v<br \/>\nSTEP 3  Locate the lock address<br \/>\n        global symbol:   sym -m &lt;module&gt; | grep -i lock<br \/>\n        embedded:        dis &lt;caller_func&gt; &lt;n&gt;, read the first argument<br \/>\n                         x86_64: lea &#8230;, %rdi     ARM64: adrp\/add -&gt; x0<br \/>\n              |<br \/>\n              v<br \/>\nSTEP 4  Read HOLD edges  (the hard part)<br \/>\n        PATH A:  struct mutex|rw_semaphore &lt;addr&gt;<br \/>\n                 p\/x owner.counter ; holder &#061; counter &amp; ~0x7<br \/>\n                 validate: task &lt;holder&gt;       &lt;- must be a valid task<br \/>\n        PATH B:  struct raw_spinlock          &lt;- DEBUG owner field?<br \/>\n                 struct qspinlock &lt;addr&gt;      &lt;- locked byte, tail<br \/>\n                 then infer via foreach bt &#043; dis<br \/>\n        hold edge:  LOCK  &#8212;- held by &#8212;-&gt;  TASK<br \/>\n              |<br \/>\n              v<br \/>\nSTEP 5  Build the graph, search for a cycle<br \/>\n        nodes: tasks and locks<br \/>\n        a cycle  &#061;&#061;  deadlock confirmed<br \/>\n        NO cycle &#061;&#061;  follow chains to their TERMINAL nodes, see ch.11<br \/>\n              |<br \/>\n              v<br \/>\nSTEP 6  Verify at source level<br \/>\n        crash&gt; dis &lt;func&gt; &lt;n&gt;<br \/>\n        confirm the two paths take the locks in opposite order<\/p>\n<p>\u7b2c\u4e94\u6b65\u662f\u5224\u5b9a\u7684\u5206\u6c34\u5cad\u3002 \u8ffd\u4e0d\u51fa\u73af\u65f6\u4e0d\u8981\u5f3a\u884c\u8ba4\u5b9a\u6b7b\u9501\u2014\u2014\u7b2c\u5341\u4e00\u7ae0\u5217\u51fa\u7684\u51e0\u7c7b\u73b0\u8c61\u90fd\u80fd\u9020\u51fa&#034;\u5927\u7247 D \u72b6\u6001&#034;\u7684\u5047\u8c61\u3002<\/p>\n<p>\u7b2c\u4e09\u6b65\u7684 dis &lt;func&gt; &lt;n&gt; \u4e2d\u7684 n \u662f\u53cd\u6c47\u7f16\u7684\u6307\u4ee4\u6761\u6570&#xff08;\u4e0d\u662f\u884c\u6570\u6216\u5b57\u8282\u6570&#xff09;\u3002\u52a0\u9501\u8c03\u7528\u901a\u5e38\u51fa\u73b0\u5728\u51fd\u6570\u5e8f\u8a00\u4e4b\u540e\u4e0d\u8fdc\u5904&#xff0c;12 \u662f\u4e2a\u591f\u7528\u7684\u8d77\u624b\u503c&#xff1b;\u82e5\u6ca1\u770b\u5230\u76ee\u6807 call \/ bl&#xff0c;\u9010\u6b65\u52a0\u5927\u5230 30\u300160\u3002<\/p>\n<hr \/>\n<h3>\u4e03\u3001\u6848\u4f8b\u4e00&#xff1a;mutex ABBA \u6b7b\u9501&#xff08;\u8def\u7ebf A \u5168\u6d41\u7a0b&#xff09;<\/h3>\n<p>\u672c\u7ae0\u4e3a\u6559\u5b66\u6784\u9020\u3002 \u6a21\u5757\u540d demo_drv\u3001\u7b26\u53f7\u540d\u3001\u5730\u5740\u4e0e PID \u5747\u4e3a\u865a\u62df&#xff0c;\u4f4d\u57df\u53d6\u503c\u6309\u771f\u5b9e\u7f16\u7801\u89c4\u5219\u751f\u6210&#xff08;owner &amp; ~0x7 \u4e0e\u5bf9\u5e94 task \u5730\u5740\u7684\u5f15\u7528\u5173\u7cfb\u81ea\u6d3d&#xff09;\u3002<\/p>\n<p>\u4e4b\u6240\u4ee5\u7528\u6784\u9020\u6848\u4f8b\u6f14\u793a\u5b8c\u6574\u6d41\u7a0b&#xff0c;\u662f\u56e0\u4e3a\u771f\u5b9e\u6b7b\u9501\u73b0\u573a\u51e0\u4e4e\u603b\u5728\u67d0\u4e00\u6b65\u5361\u4f4f\u2014\u2014ARM64 \u7684 bt \u53ef\u80fd\u8de8\u6808\u5931\u8d25&#xff0c;CPU \u505c\u673a\u5931\u8d25\u4f1a\u5bfc\u81f4\u5bc4\u5b58\u5668\u73b0\u573a\u7f3a\u5931&#xff0c;\u9501\u53ef\u80fd\u662f\u5d4c\u5957\u7ed3\u6784\u91cc\u7684\u533f\u540d\u6210\u5458\u3002\u8fd9\u4e9b\u56f0\u96be\u5bf9\u9996\u6b21\u5efa\u7acb\u6d41\u7a0b\u8ba4\u77e5\u662f\u5e72\u6270\u3002\u7b2c\u4e5d\u7ae0\u662f\u771f\u5b9e\u751f\u4ea7\u73b0\u573a&#xff0c;\u90a3\u91cc\u4f1a\u5c55\u793a\u4e0a\u8ff0\u6bcf\u4e00\u79cd\u56f0\u96be\u3002<\/p>\n<p>\u4e24\u7c7b\u6848\u4f8b\u7684\u5206\u5de5&#xff1a;\u6784\u9020\u6848\u4f8b\u6559\u65b9\u6cd5&#xff0c;\u771f\u5b9e\u6848\u4f8b\u6559\u8fb9\u754c\u3002<\/p>\n<h4>7.1 \u73b0\u573a<\/h4>\n<p>\u89e6\u53d1\u539f\u56e0&#xff1a;hung_task \u8d85\u65f6 panic\u3002dmesg \u6458\u5f55&#xff1a;<\/p>\n<p>INFO: task worker-thread:4821 blocked for more than 120 seconds.<br \/>\n __schedule&#043;0x2b9\/0x860<br \/>\n __mutex_lock.isra.0&#043;0x209\/0x540<br \/>\n volume_lock_acquire&#043;0x38\/0x70 [demo_drv]<\/p>\n<p>INFO: task worker-thread:4822 blocked for more than 120 seconds.<br \/>\n __mutex_lock.isra.0&#043;0x209\/0x540<br \/>\n io_lock_acquire&#043;0x3c\/0x80 [demo_drv]<\/p>\n<h4>7.2 STEP 1-2&#xff1a;\u679a\u4e3e\u4e0e\u53d6\u8fb9<\/h4>\n<p>crash<span class=\"token operator\">&gt;<\/span> <span class=\"token function\">ps<\/span> <span class=\"token parameter variable\">-m<\/span> <span class=\"token operator\">|<\/span> <span class=\"token function\">grep<\/span> <span class=\"token string\">&#034; UN &#034;<\/span><br \/>\n<span class=\"token punctuation\">[<\/span><span class=\"token number\">0<\/span> 00:05:47.882<span class=\"token punctuation\">]<\/span>  <span class=\"token number\">4821<\/span>  <span class=\"token number\">4815<\/span>  <span class=\"token number\">0<\/span>  ffff888207a3c000  UN  worker-thread<br \/>\n<span class=\"token punctuation\">[<\/span><span class=\"token number\">0<\/span> 00:05:45.201<span class=\"token punctuation\">]<\/span>  <span class=\"token number\">4822<\/span>  <span class=\"token number\">4815<\/span>  <span class=\"token number\">1<\/span>  ffff888207b48000  UN  worker-thread<br \/>\n<span class=\"token punctuation\">[<\/span><span class=\"token number\">0<\/span> 00:05:41.094<span class=\"token punctuation\">]<\/span>  <span class=\"token number\">4823<\/span>  <span class=\"token number\">4815<\/span>  <span class=\"token number\">2<\/span>  ffff888207c5a000  UN  worker-thread<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> bt <span class=\"token number\">4821<\/span><br \/>\n <span class=\"token comment\">#3 [ffff888207a3bd20] __mutex_lock at ffffffff81a58c30<\/span><br \/>\n <span class=\"token comment\">#5 [ffff888207a3bda0] volume_lock_acquire at ffffffffc07834a8 [demo_drv]<\/span><br \/>\n <span class=\"token comment\">#6 [ffff888207a3be20] flush_volume at ffffffffc07836c0 [demo_drv]<\/span><\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> bt <span class=\"token number\">4822<\/span><br \/>\n <span class=\"token comment\">#3 [ffff888207b48d20] __mutex_lock at ffffffff81a58c30<\/span><br \/>\n <span class=\"token comment\">#5 [ffff888207b48da0] io_lock_acquire at ffffffffc078384c [demo_drv]<\/span><br \/>\n <span class=\"token comment\">#6 [ffff888207b48e20] submit_io at ffffffffc078390a [demo_drv]<\/span><\/p>\n<p>\u8fb9&#xff08;\u7b2c\u4e00\u7c7b&#xff09;&#xff1a;<\/p>\n<p>PID 4821 (flush path)  &#8212;- waits for &#8212;-&gt;  the mutex taken in volume_lock_acquire<br \/>\nPID 4822 (submit path) &#8212;- waits for &#8212;-&gt;  the mutex taken in io_lock_acquire<\/p>\n<p>PID 4823 \u7684 bt \u663e\u793a\u5b83\u4e5f\u5728\u7b49\u7b2c\u4e00\u628a\u9501&#xff0c;\u662f\u666e\u901a\u6392\u961f\u8005&#xff0c;\u4e0d\u5728\u73af\u4e0a\u3002<\/p>\n<h4>7.3 STEP 3&#xff1a;\u5b9a\u4f4d\u9501\u5730\u5740<\/h4>\n<p>\u6a21\u5757\u7684\u5168\u5c40\u9501\u53ef\u76f4\u63a5\u67e5\u7b26\u53f7&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> sym <span class=\"token parameter variable\">-m<\/span> demo_drv <span class=\"token operator\">|<\/span> <span class=\"token function\">grep<\/span> <span class=\"token parameter variable\">-i<\/span> mutex<br \/>\nffffffffc0789040 <span class=\"token punctuation\">(<\/span>b<span class=\"token punctuation\">)<\/span> volume_mutex <span class=\"token punctuation\">[<\/span>demo_drv<span class=\"token punctuation\">]<\/span><br \/>\nffffffffc0789080 <span class=\"token punctuation\">(<\/span>b<span class=\"token punctuation\">)<\/span> io_mutex     <span class=\"token punctuation\">[<\/span>demo_drv<span class=\"token punctuation\">]<\/span><\/p>\n<p>\u82e5\u9501\u5d4c\u5728\u67d0\u4e2a\u7ed3\u6784\u4f53\u91cc\u3001\u62ff\u4e0d\u5230\u7b26\u53f7&#xff0c;\u5c31\u4ece\u8c03\u7528\u5e27\u53cd\u6c47\u7f16&#xff0c;\u8bfb\u7b2c\u4e00\u4e2a\u53c2\u6570&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> dis volume_lock_acquire <span class=\"token number\">12<\/span><br \/>\nffffffffc0783490:  push   %rbp<br \/>\nffffffffc0783491:  mov    %rsp,%rbp<br \/>\nffffffffc07834a8:  lea    0x4590<span class=\"token punctuation\">(<\/span>%rip<span class=\"token punctuation\">)<\/span>,%rdi   <span class=\"token comment\"># ffffffffc0789040 &lt;volume_mutex&gt;<\/span><br \/>\nffffffffc07834af:  call   mutex_lock_nested<\/p>\n<p>x86_64 \u4e0a\u7b2c\u4e00\u4e2a\u53c2\u6570\u5728 %rdi&#xff0c;lea \u6ce8\u91ca\u91cc\u7684 # ffffffffc0789040 \u5c31\u662f\u9501\u5730\u5740\u2014\u2014crash \u5df2\u7ecf\u628a RIP \u76f8\u5bf9\u5bfb\u5740\u7b97\u597d\u5e76\u6807\u6ce8\u4e86\u7b26\u53f7\u540d&#xff0c;\u4e0d\u9700\u8981\u624b\u5de5\u8ba1\u7b97\u3002<\/p>\n<p>bt \u8f93\u51fa\u4e2d\u5e76\u5b58\u4e09\u7c7b\u5730\u5740&#xff0c;\u987b\u52a0\u533a\u5206\u3002 \u4ee5 7.2 \u8282\u7684\u5e27\u4e3a\u4f8b&#xff1a;<\/p>\n<p>#3 [ffff888207a3bd20] __mutex_lock at ffffffff81a58c30<br \/>\n   \u2514\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518                  \u2514\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518<br \/>\n      \u6808\u5e27\u5730\u5740                          \u7b26\u53f7\u5730\u5740<\/p>\n<p>\u6808\u5e27\u5730\u5740&#xff08;ffff888207a3bd20&#xff09;\u662f\u8be5\u5e27\u5728\u5f53\u524d\u8fdb\u7a0b\u5185\u6838\u6808\u4e0a\u7684\u8d77\u59cb\u4f4d\u7f6e&#xff0c;\u5c5e\u8fd0\u884c\u65f6\u5750\u6807&#xff0c;\u968f\u6bcf\u6b21\u8c03\u7528\u800c\u53d8&#xff1b;\u7528\u9014\u662f\u914d\u5408 bt -f \u5c55\u5f00\u8be5\u5e27\u7684\u539f\u59cb\u5185\u5bb9\u3002<\/p>\n<p>\u7b26\u53f7\u5730\u5740&#xff08;ffffffff81a58c30&#xff09;\u662f\u8be5\u5e27\u6267\u884c\u5230\u7684\u6307\u4ee4\u4f4d\u7f6e&#xff0c;\u5c5e\u7f16\u8bd1\u671f\u5750\u6807&#xff0c;\u56fa\u5b9a\u4e0d\u53d8&#xff1b;\u7528\u9014\u662f dis \u53cd\u6c47\u7f16\u6216 sym \u53cd\u67e5\u3002<\/p>\n<p>\u5bf9\u8c61\u5730\u5740&#xff08;ffffffffc0789040&#xff09;\u5219\u662f volume_mutex \u8fd9\u4e2a mutex \u5b9e\u4f8b\u6240\u5728\u4f4d\u7f6e&#xff0c;\u4f4d\u4e8e\u6a21\u5757 .bss \u6bb5&#xff0c;\u662f struct mutex \u8981\u8bfb\u7684\u76ee\u6807\u3002<\/p>\n<p>\u4e09\u8005\u53ef\u7531\u524d\u7f00\u5feb\u901f\u533a\u5206&#xff08;\u53c2\u89c1\u7b2c\u4e94\u7bc7 2.2 \u8282&#xff09;&#xff1a;ffff8882&#8230; \u5c5e\u76f4\u63a5\u6620\u5c04\u533a&#xff08;\u5185\u6838\u6808&#xff09;&#xff0c;ffffffff81&#8230; \u5c5e\u5185\u6838\u955c\u50cf&#xff0c;ffffffffc0&#8230; \u5c5e\u6a21\u5757\u533a\u3002<\/p>\n<p>ARM64 \u7684\u8bfb\u6cd5\u4e0d\u540c&#xff1a; \u53d6\u5168\u5c40\u5730\u5740\u7528 adrp &#043; add \u7ec4\u5408&#xff0c;\u9996\u53c2\u5728 x0&#xff0c;\u8c03\u7528\u7528 bl&#xff1a;<\/p>\n<p>adrp   x0, ffffffc010789000       &lt;- page base<br \/>\nadd    x0, x0, #0x40              &lt;- &#043; offset<br \/>\nbl     mutex_lock_nested<\/p>\n<p>\u9501\u5730\u5740 &#061; \u9875\u57fa\u5740 &#043; \u504f\u79fb &#061; 0xffffffc010789040\u3002<\/p>\n<h4>7.4 STEP 4&#xff1a;\u8bfb\u7b2c\u4e8c\u7c7b\u8fb9<\/h4>\n<p>crash<span class=\"token operator\">&gt;<\/span> p\/x <span class=\"token punctuation\">((<\/span>struct mutex *<span class=\"token punctuation\">)<\/span>0xffffffffc0789040<span class=\"token punctuation\">)<\/span>&#8211;<span class=\"token operator\">&gt;<\/span>owner.counter<br \/>\n<span class=\"token variable\">$1<\/span> <span class=\"token operator\">&#061;<\/span> 0xffff888207b48001<\/p>\n<p>$1\u3001$2 \u662f crash \u7684\u503c\u5386\u53f2\u7f16\u53f7&#xff0c;\u6bcf\u6267\u884c\u4e00\u6b21 p \u81ea\u589e&#xff0c;\u53ef\u7528 p $1 \u56de\u770b\u4e4b\u524d\u7684\u7ed3\u679c\u3002\u5b83\u4eec\u53ea\u662f\u8f93\u51fa\u7f16\u53f7&#xff0c;\u4e0e\u6240\u8bfb\u5b57\u6bb5\u65e0\u5173\u3002<\/p>\n<p>volume_mutex \u7684\u6301\u6709\u8005 &#061; 0xffff888207b48001 &amp; ~0x7 &#061; 0xffff888207b48000\u3002\u9a8c\u8bc1\u4e00\u4e0b&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> task 0xffff888207b48000 <span class=\"token operator\">|<\/span> <span class=\"token function\">head<\/span> <span class=\"token parameter variable\">-2<\/span><br \/>\nPID: <span class=\"token number\">4822<\/span>   COMMAND: <span class=\"token string\">&#034;worker-thread&#034;<\/span><\/p>\n<p>\u8fd9\u4e00\u6b65\u9a8c\u8bc1\u4e0d\u80fd\u7701\u2014\u2014\u82e5 task \u62a5\u9519\u8bf4\u660e\u89e3\u51fa\u7684\u5730\u5740\u4e0d\u662f\u6709\u6548 task_struct&#xff0c;\u90a3\u662f\u9501\u7ed3\u6784\u635f\u574f\u800c\u975e\u6b7b\u9501&#xff08;\u89c1 3.4 \u8282&#xff09;\u3002<\/p>\n<p>\u540c\u6cd5\u8bfb\u7b2c\u4e8c\u628a&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> p\/x <span class=\"token punctuation\">((<\/span>struct mutex *<span class=\"token punctuation\">)<\/span>0xffffffffc0789080<span class=\"token punctuation\">)<\/span>&#8211;<span class=\"token operator\">&gt;<\/span>owner.counter<br \/>\n<span class=\"token variable\">$2<\/span> <span class=\"token operator\">&#061;<\/span> 0xffff888207a3c001<\/p>\n<p>io_mutex \u7684\u6301\u6709\u8005 &#061; 0xffff888207a3c000 \u2192 PID 4821\u3002<\/p>\n<h4>7.5 STEP 5&#xff1a;\u786e\u8ba4\u73af<\/h4>\n<p>PID 4821 &#8211;holds&#8211;&gt; io_mutex      &#8211;blocks&#8211;&gt; PID 4822<br \/>\n   ^                                             |<br \/>\n   |                                             |<br \/>\n   &#043;&#8211;blocked by&#8211; volume_mutex &lt;&#8211;holds&#8212;&#8212;&#8212;&#043;<\/p>\n<p>cycle confirmed  -&gt;  ABBA deadlock<\/p>\n<h4>7.6 STEP 6&#xff1a;\u53cd\u6c47\u7f16\u9a8c\u8bc1\u52a0\u9501\u987a\u5e8f<\/h4>\n<p>crash<span class=\"token operator\">&gt;<\/span> dis flush_volume <span class=\"token number\">60<\/span><br \/>\nffffffffc07836c0:  call  io_lock_acquire       <span class=\"token operator\">&lt;<\/span>&#8211; \u5148\u52a0 io_mutex<br \/>\nffffffffc07836d8:  call  volume_lock_acquire   <span class=\"token operator\">&lt;<\/span>&#8211; \u540e\u52a0 volume_mutex<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> dis submit_io <span class=\"token number\">60<\/span><br \/>\nffffffffc0783910:  call  volume_lock_acquire   <span class=\"token operator\">&lt;<\/span>&#8211; \u5148\u52a0 volume_mutex<br \/>\nffffffffc0783928:  call  io_lock_acquire       <span class=\"token operator\">&lt;<\/span>&#8211; \u540e\u52a0 io_mutex<\/p>\n<p>\u4e24\u6761\u8def\u5f84\u52a0\u9501\u987a\u5e8f\u5b8c\u5168\u76f8\u53cd&#xff0c;\u6839\u56e0\u786e\u8ba4\u3002\u4fee\u590d\u65b9\u5411&#xff1a;\u7edf\u4e00\u5168\u5c40\u52a0\u9501\u987a\u5e8f&#xff0c;\u6216\u91cd\u65b0\u8bc4\u4f30\u662f\u5426\u5fc5\u987b\u540c\u65f6\u6301\u6709\u4e24\u628a\u9501\u3002<\/p>\n<hr \/>\n<h3>\u516b\u3001\u6848\u4f8b\u4e8c&#xff1a;rwsem \u6b7b\u9501&#xff08;\u4e0e\u6848\u4f8b\u4e00\u7684\u64cd\u4f5c\u5dee\u5f02&#xff09;<\/h3>\n<p>\u672c\u7ae0\u540c\u4e3a\u6559\u5b66\u6784\u9020\u3002<\/p>\n<p>\u672c\u6848\u4f8b\u4e0e\u7b2c\u4e03\u7ae0\u540c\u5c5e\u8def\u7ebf A&#xff1a;\u540c\u6837\u662f\u4e24\u4e2a\u4efb\u52a1\u4e92\u6301\u5bf9\u65b9\u6240\u9700\u7684\u9501&#xff0c;\u540c\u6837\u6309\u7b2c\u516d\u7ae0\u7684\u516d\u6b65\u8d70\u3002\u533a\u522b\u53ea\u5728\u4e8e\u5176\u4e2d\u4e00\u628a\u9501\u662f rw_semaphore \u800c\u975e mutex&#xff0c;\u8fd9\u5bfc\u81f4 STEP 4&#xff08;\u8bfb\u6301\u6709\u8fb9&#xff09;\u7684\u64cd\u4f5c\u6709\u6240\u4e0d\u540c\u3002<\/p>\n<p>\u7b2c\u4e03\u7ae0\u5df2\u5b8c\u6574\u6f14\u793a\u8fc7\u516d\u6b65\u6d41\u7a0b&#xff0c;\u672c\u7ae0\u56e0\u6b64\u53ea\u5c55\u5f00\u53d7 rwsem \u5f71\u54cd\u7684\u6b65\u9aa4&#xff0c;\u5176\u4f59\u6b65\u9aa4&#xff08;\u679a\u4e3e\u4efb\u52a1\u3001\u53d6\u7b49\u5f85\u8fb9\u3001\u5b9a\u4f4d\u9501\u5730\u5740\u3001\u786e\u8ba4\u73af\u3001\u53cd\u6c47\u7f16\u9a8c\u8bc1&#xff09;\u4e0e\u7b2c\u4e03\u7ae0\u5b8c\u5168\u4e00\u81f4&#xff0c;\u4e0d\u518d\u91cd\u590d\u3002<\/p>\n<p>\u4ee5\u4e0b&#034;\u5dee\u5f02&#034;\u5747\u6307\u76f8\u5bf9\u4e8e\u7b2c\u4e03\u7ae0 mutex \u7684\u64cd\u4f5c\u5dee\u5f02&#xff0c;\u5176\u6839\u6e90\u662f 3.3 \u8282\u6240\u8ff0\u7684 rwsem \u4e09\u5904\u7ed3\u6784\u7279\u6b8a\u6027\u3002<\/p>\n<h4>8.1 \u73b0\u573a\u6982\u8981<\/h4>\n<ul>\n<li>PID 5100&#xff08;cache-flusher&#xff09;&#xff1a;\u6301\u6709 meta_mutex&#xff0c;\u4ee5\u5199\u8005\u8eab\u4efd\u7b49\u5f85 cache_rwsem<\/li>\n<li>PID 5101&#xff08;meta-updater&#xff09;&#xff1a;\u6301\u6709 cache_rwsem \u5199\u9501&#xff0c;\u7b49\u5f85 meta_mutex<\/li>\n<\/ul>\n<p>\u6309\u7b2c\u516d\u7ae0 STEP 1-2 \u679a\u4e3e\u4efb\u52a1\u5e76\u53d6\u7b49\u5f85\u8fb9&#xff08;\u6d41\u7a0b\u4e0e\u7b2c\u4e03\u7ae0\u76f8\u540c&#xff0c;\u5b8c\u6574 bt \u8f93\u51fa\u683c\u5f0f\u89c1 7.2 \u8282&#xff0c;\u6b64\u5904\u4e0d\u518d\u91cd\u590d&#xff09;&#xff0c;\u5f97\u5230\u4e24\u4e2a\u4efb\u52a1\u7684\u963b\u585e\u70b9&#xff1a;<\/p>\n<table>\n<tr>PIDCOMMAND\u963b\u585e\u70b9&#xff08;\u6808\u9876\u5728\u5de6&#xff09;\u7b49\u5f85\u7684\u9501<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">5100<\/td>\n<td align=\"left\">cache-flusher<\/td>\n<td align=\"left\">rwsem_down_write_slowpath \u2190 down_write \u2190 cache_flush_begin<\/td>\n<td align=\"left\">cache_rwsem&#xff08;\u5199&#xff09;<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">5101<\/td>\n<td align=\"left\">meta-updater<\/td>\n<td align=\"left\">__mutex_lock \u2190 mutex_lock_nested \u2190 meta_lock_update<\/td>\n<td align=\"left\">meta_mutex<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u4e0a\u8868\u4e3a\u6458\u8981&#xff0c;\u975e\u547d\u4ee4\u8f93\u51fa\u2014\u2014foreach UN bt \u5b9e\u9645\u4f1a\u9010\u4e2a\u4efb\u52a1\u6253\u5370\u5b8c\u6574\u5e27\u5217\u8868\u3002STEP 3&#xff08;\u5b9a\u4f4d\u9501\u5730\u5740&#xff09;\u540c\u6837\u4e0e\u7b2c\u4e03\u7ae0\u4e00\u81f4&#xff0c;\u7565\u8fc7\u3002<\/p>\n<h4>8.2 STEP 4 \u5dee\u5f02\u4e00&#xff1a;\u9700\u5148\u8bfb count \u5224\u5b9a\u9501\u7684\u6301\u6709\u5f62\u6001<\/h4>\n<p>mutex \u53ea\u9700\u8bfb owner&#xff0c;rwsem \u8981\u5148\u770b count \u624d\u77e5\u9053\u662f\u5199\u9501\u8fd8\u662f\u8bfb\u9501\u88ab\u6301\u6709&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> p\/x <span class=\"token punctuation\">((<\/span>struct rw_semaphore *<span class=\"token punctuation\">)<\/span>0xffffffffc0801200<span class=\"token punctuation\">)<\/span>&#8211;<span class=\"token operator\">&gt;<\/span>count.counter<br \/>\n<span class=\"token variable\">$1<\/span> <span class=\"token operator\">&#061;<\/span> 0x3<\/p>\n<p>bit0 &#061; 1 \u2192 \u5199\u8005\u6301\u6709&#xff1b;bit1 &#061; 1 \u2192 \u6709\u7b49\u5f85\u8005\u3002\u786e\u8ba4\u662f\u5199\u9501\u6301\u6709&#xff0c;owner \u624d\u6709\u610f\u4e49&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> p\/x <span class=\"token punctuation\">((<\/span>struct rw_semaphore *<span class=\"token punctuation\">)<\/span>0xffffffffc0801200<span class=\"token punctuation\">)<\/span>&#8211;<span class=\"token operator\">&gt;<\/span>owner.counter<br \/>\n<span class=\"token variable\">$2<\/span> <span class=\"token operator\">&#061;<\/span> 0xffff8882091a0001<\/p>\n<p>\u6301\u6709\u8005 &#061; 0xffff8882091a0000 \u2192 PID 5101\u3002<\/p>\n<p>\u82e5 count \u663e\u793a\u7684\u662f\u8bfb\u8005\u6301\u6709&#xff08;\u5982 0x300&#xff09;&#xff0c;owner \u5b57\u6bb5\u4e0d\u542b\u8fdb\u7a0b\u4fe1\u606f&#xff0c;\u53ea\u80fd\u6539\u8d70\u904d\u5386 backtrace \u7684\u8def\u5b50&#xff08;3.3 \u8282\u7279\u6b8a\u6027\u4e8c&#xff09;\u3002<\/p>\n<h4>8.3 STEP 4 \u5dee\u5f02\u4e8c&#xff1a;\u904d\u5386\u7b49\u5f85\u94fe\u65f6\u987b\u540c\u65f6\u8bfb\u51fa type<\/h4>\n<p>crash<span class=\"token operator\">&gt;<\/span> list rwsem_waiter.list <span class=\"token parameter variable\">-s<\/span> rwsem_waiter.task,rwsem_waiter.type <span class=\"token punctuation\">\\\\<\/span><br \/>\n       <span class=\"token punctuation\">((<\/span>struct rw_semaphore *<span class=\"token punctuation\">)<\/span>0xffffffffc0801200<span class=\"token punctuation\">)<\/span>&#8211;<span class=\"token operator\">&gt;<\/span>wait_list.next<br \/>\nffff888209201e40<br \/>\n  task <span class=\"token operator\">&#061;<\/span> 0xffff888209201000   \u2190 PID <span class=\"token number\">5100<\/span><br \/>\n  <span class=\"token builtin class-name\">type<\/span> <span class=\"token operator\">&#061;<\/span> <span class=\"token number\">1<\/span>                    \u2190 RWSEM_WAITING_FOR_WRITE<\/p>\n<p>\u8fd9\u4e00\u6b65\u51b3\u5b9a\u4e86\u95ee\u9898\u7684\u5b9a\u6027\u3002 type &#061; WRITE \u8bf4\u660e 5100 \u662f\u4ee5\u5199\u8005\u8eab\u4efd\u6392\u961f&#xff0c;\u4e0e 5101 \u6784\u6210\u4e24\u4e2a\u5199\u8005\u4e92\u7b49\u7684\u7ecf\u5178 ABBA&#xff1b;\u82e5 type &#061; READ&#xff0c;\u5219\u6027\u8d28\u53d8\u6210\u7b2c\u4e94\u7ae0\u8bb2\u7684&#034;\u5199\u8005\u4f18\u5148\u5bfc\u81f4\u8bfb\u8005\u6392\u961f&#034;&#xff0c;\u6210\u56e0\u4e0e\u4fee\u590d\u65b9\u5411\u90fd\u4e0d\u540c\u3002<\/p>\n<h4>8.4 STEP 5 \u5dee\u5f02\u4e09&#xff1a;\u73af\u7684\u7ed3\u6784\u76f8\u540c&#xff0c;\u4f46\u53d6\u8fb9\u52a8\u4f5c\u662f\u4e24\u6b65\u800c\u975e\u4e00\u6b65<\/h4>\n<p>PID 5100 &#8211;holds&#8211;&gt; meta_mutex   &#8211;blocks&#8211;&gt; PID 5101<br \/>\n   ^                                            |<br \/>\n   |                                            |<br \/>\n   &#043;&#8211;blocked by&#8211; cache_rwsem &lt;&#8211;holds&#8212;&#8212;&#8212;&#043;<\/p>\n<p>\u73af\u7684\u7ed3\u6784\u4e0e\u7b2c\u4e03\u7ae0\u65e0\u5f02&#xff0c;\u4f46\u53d6\u8fb9\u7684\u52a8\u4f5c\u4e0d\u540c&#xff1a;meta_mutex \u4e00\u6b65\u8bfb owner&#xff0c;cache_rwsem \u8981\u4e24\u6b65&#xff08;\u5148 count \u5b9a\u6027\u3001\u518d owner \u53d6\u503c&#xff09;\u3002\u8fd9\u5c31\u662f rwsem \u5206\u6790\u7684\u5168\u90e8\u989d\u5916\u6210\u672c\u3002<\/p>\n<hr \/>\n<h3>\u4e5d\u3001\u6848\u4f8b\u4e09&#xff1a;\u56de\u5230 jbd2 \u73b0\u573a&#xff08;\u8def\u7ebf B \u4e0e\u5931\u6548\u8fb9\u754c&#xff09;<\/h3>\n<p>\u672c\u7ae0\u4e3a\u771f\u5b9e\u751f\u4ea7\u73b0\u573a&#xff0c;\u5168\u90e8\u547d\u4ee4\u8f93\u51fa\u53d6\u81ea\u4e00\u4efd 4.19 ARM64 \u9e92\u9e9f vmcore&#xff08;96 \u6838\u30011TB \u5185\u5b58\u3001\u8fde\u7eed\u8fd0\u884c 322 \u5929&#xff09;\u3002\u4e0e\u524d\u4e24\u7ae0\u7684\u6784\u9020\u6848\u4f8b\u76f8\u6bd4&#xff0c;\u8fd9\u91cc\u7684\u8fc7\u7a0b\u8981\u66f2\u6298\u5f97\u591a\u2014\u2014\u591a\u4e2a\u6b65\u9aa4\u53d7\u963b&#xff0c;\u6070\u597d\u628a\u8def\u7ebf B \u7684\u56f0\u96be\u4e0e\u8fb9\u754c\u5b8c\u6574\u66b4\u9732\u4e86\u51fa\u6765\u3002\u540c\u65f6&#xff0c;\u7b2c\u516d\u7bc7\u7559\u4e0b\u7684\u90a3\u4e2a\u60ac\u5ff5\u5728\u672c\u7ae0\u5f97\u5230\u8bc1\u5b9e\u3002<\/p>\n<h4>9.1 \u4e09\u8f74\u786e\u8ba4<\/h4>\n<p>crash<span class=\"token operator\">&gt;<\/span> sys<br \/>\n      KERNEL: \/usr\/lib\/debug\/<span class=\"token punctuation\">..<\/span>.\/4.19.90-23.42.v2101.ky10.aarch64\/vmlinux<br \/>\n    DUMPFILE: vmcore  <span class=\"token punctuation\">[<\/span>PARTIAL DUMP<span class=\"token punctuation\">]<\/span><br \/>\n        CPUS: <span class=\"token number\">96<\/span><br \/>\n      UPTIME: <span class=\"token number\">322<\/span> days, <span class=\"token number\">17<\/span>:04:41<br \/>\n     RELEASE: <span class=\"token number\">4.19<\/span>.90-23.42.v2101.ky10.aarch64<br \/>\n     MACHINE: aarch64  <span class=\"token punctuation\">(<\/span>unknown Mhz<span class=\"token punctuation\">)<\/span><br \/>\n      MEMORY: <span class=\"token number\">1024<\/span> GB<br \/>\n       PANIC: <span class=\"token string\">&#034;Kernel panic &#8211; not syncing: softlockup: hung tasks&#034;<\/span><\/p>\n<p>\u4e09\u9879\u4fe1\u606f\u503c\u5f97\u7559\u610f&#xff1a;KERNEL \u8def\u5f84\u4f4d\u4e8e \/usr\/lib\/debug\/ \u4e0b&#xff0c;\u8bf4\u660e\u5e26 debuginfo&#xff0c;dis -l \u53ef\u8f93\u51fa\u6e90\u7801\u884c\u53f7\u2014\u2014\u8fd9\u4e00\u70b9\u5bf9\u672c\u7ae0\u7684\u7ed3\u8bba\u81f3\u5173\u91cd\u8981&#xff1b;UPTIME 322 \u5929\u8868\u660e\u7cfb\u7edf\u957f\u671f\u7a33\u5b9a\u540e\u624d\u51fa\u95ee\u9898&#xff1b;PANIC \u660e\u786e\u662f softlockup \u800c\u975e hard lockup\u3002<\/p>\n<p>\u786e\u8ba4\u9501\u7684\u5b9e\u73b0\u5f62\u6001&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> struct qspinlock<br \/>\nstruct qspinlock <span class=\"token punctuation\">{<\/span><br \/>\n    union <span class=\"token punctuation\">{<\/span><br \/>\n        atomic_t val<span class=\"token punctuation\">;<\/span><br \/>\n        struct <span class=\"token punctuation\">{<\/span><br \/>\n            u8 locked<span class=\"token punctuation\">;<\/span><br \/>\n            u8 pending<span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        struct <span class=\"token punctuation\">{<\/span><br \/>\n            u16 locked_pending<span class=\"token punctuation\">;<\/span><br \/>\n            u16 <span class=\"token function\">tail<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><br \/>\nSIZE: <span class=\"token number\">4<\/span><\/p>\n<p>\u4e0e 4.1 \u8282\u7684\u4f4d\u57df\u5e03\u5c40\u4e00\u81f4\u3002\u8be5\u673a 96 \u6838&#xff0c;\u8fdc\u4f4e\u4e8e _Q_PENDING_BITS &#061; 8 \u6240\u5bf9\u5e94\u7684\u89c4\u6a21\u4e0a\u9650&#xff0c;\u6807\u51c6\u4f4d\u57df\u8868\u9002\u7528\u3002<\/p>\n<p>\u8def\u7ebf\u5224\u5b9a&#xff08;\u6309 4.2 \u8282&#xff09;&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> struct raw_spinlock<br \/>\nstruct raw_spinlock <span class=\"token punctuation\">{<\/span><br \/>\n    arch_spinlock_t raw_lock<span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><br \/>\nSIZE: <span class=\"token number\">4<\/span><\/p>\n<p>\u7ed3\u6784\u4e2d\u53ea\u6709 raw_lock \u4e00\u4e2a\u6210\u5458&#xff0c;SIZE \u4e3a 4\u2014\u2014CONFIG_DEBUG_SPINLOCK \u672a\u5f00\u542f&#xff08;\u5f00\u542f\u65f6\u4f1a\u989d\u5916\u51fa\u73b0 magic\u3001owner_cpu\u3001owner&#xff0c;SIZE \u76f8\u5e94\u589e\u5927&#xff09;\u3002\u5224\u5b9a\u4e3a\u8def\u7ebf B\u3002<\/p>\n<h4>9.2 \u4f2a NMI&#xff1a;\u7f16\u8bd1\u4e86&#xff0c;\u4f46\u672a\u542f\u7528<\/h4>\n<p>\u6309 4.5 \u8282&#xff0c;ARM64 \u7684 hard lockup \u68c0\u6d4b\u4f9d\u8d56\u4f2a NMI\u3002\u9010\u9879\u6838\u5b9e&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> sym irq_nmi_setup<br \/>\nsymbol not found: irq_nmi_setup<br \/>\npossible alternatives:<br \/>\n  ffff3ab9a9d99778 <span class=\"token punctuation\">(<\/span>t<span class=\"token punctuation\">)<\/span> gic_irq_nmi_setup<\/p>\n<p>irq_nmi_setup \u662f struct irq_chip \u7684\u6210\u5458\u540d\u800c\u975e\u5168\u5c40\u7b26\u53f7&#xff0c;\u67e5\u4e0d\u5230\u5c5e\u6b63\u5e38\u3002crash \u63d0\u793a\u7684 gic_irq_nmi_setup \u624d\u662f\u5224\u65ad\u4f9d\u636e\u3002<\/p>\n<p>\u8be5\u7b26\u53f7\u5b58\u5728&#xff0c;\u8bf4\u660e CONFIG_ARM64_PSEUDO_NMI \u5df2\u7f16\u8bd1\u8fdb\u5185\u6838\u3002 \u786c\u4ef6\u6761\u4ef6\u4e5f\u6ee1\u8db3&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> log <span class=\"token operator\">|<\/span> <span class=\"token function\">grep<\/span> <span class=\"token parameter variable\">-i<\/span> <span class=\"token string\">&#034;GICv3&#034;<\/span><br \/>\n<span class=\"token punctuation\">[<\/span>    <span class=\"token number\">0.000000<\/span><span class=\"token punctuation\">]<\/span> GICv3: GIC: Using <span class=\"token function\">split<\/span> EOI\/Deactivate mode<br \/>\n<span class=\"token punctuation\">[<\/span>    <span class=\"token number\">0.000000<\/span><span class=\"token punctuation\">]<\/span> GICv3: Distributor has no Range Selector support<br \/>\n<span class=\"token punctuation\">[<\/span>    <span class=\"token number\">0.000000<\/span><span class=\"token punctuation\">]<\/span> GICv3: VLPI support, direct LPI support<\/p>\n<p>GICv3 \u6b63\u5e38\u521d\u59cb\u5316&#xff0c;\u4e14\u91c7\u7528 split EOI\/Deactivate \u6a21\u5f0f\u2014\u2014\u8fd9\u6b63\u662f\u4f2a NMI \u7684\u524d\u63d0\u4e4b\u4e00\u3002<\/p>\n<p>\u4f46\u8fd0\u884c\u65f6\u672a\u542f\u7528&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> log <span class=\"token operator\">|<\/span> <span class=\"token function\">grep<\/span> <span class=\"token parameter variable\">-i<\/span> <span class=\"token string\">&#034;pseudo-NMI&#034;<\/span><br \/>\n&#xff08;\u65e0\u8f93\u51fa&#xff09;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> p saved_command_line<br \/>\nsaved_command_line <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;BOOT_IMAGE&#061;\/vmlinuz-4.19.90-&#8230; root&#061;&#8230; ro rd.lvm.lv&#061;&#8230;<br \/>\n video&#061;VGA-1:640&#215;480-32&#064;60me nomodeset rhgb quiet<br \/>\n smmu.bypassdev&#061;0x1000:0x17 smmu.bypassdev&#061;0x1000:0x15 cra&#034;<\/span><span class=\"token punctuation\">..<\/span>.<\/p>\n<p>\u5185\u6838\u771f\u6b63\u542f\u7528\u4f2a NMI \u65f6\u4f1a\u6253\u5370 Pseudo-NMIs enabled&#8230;&#xff1b;\u542f\u52a8\u53c2\u6570\u4e2d\u4e5f\u6ca1\u6709 irqchip.gicv3_pseudo_nmi&#061;1\u3002\u8be5\u7279\u6027\u9ed8\u8ba4\u5173\u95ed&#xff0c;\u987b\u663e\u5f0f\u5f00\u542f\u3002<\/p>\n<p>\u7ed3\u8bba&#xff1a;\u8fd9\u53f0\u673a\u5668\u4e0d\u5177\u5907 hard lockup \u68c0\u6d4b\u80fd\u529b&#xff0c;\u539f\u56e0\u662f&#034;\u7f16\u8bd1\u4e86\u4f46\u672a\u542f\u7528&#034;\u3002 \u8fd9\u4e2a\u533a\u522b\u6709\u5b9e\u9645\u4ef7\u503c\u2014\u2014\u590d\u73b0\u65f6\u53ea\u9700\u589e\u52a0\u4e00\u4e2a\u542f\u52a8\u53c2\u6570\u5373\u53ef\u83b7\u5f97\u8be5\u80fd\u529b&#xff0c;\u65e0\u9700\u91cd\u65b0\u7f16\u8bd1\u5185\u6838\u3002<\/p>\n<p>\u7531\u6b64\u5f97\u5230\u4e00\u6761\u63a8\u8bba&#xff1a;\u672c\u4f8b\u80fd\u89e6\u53d1 soft lockup&#xff0c;\u8bf4\u660e\u5361\u4f4f\u7684\u8def\u5f84\u4e2d\u65ad\u4ecd\u662f\u5f00\u7684\u3002 \u8fd9\u4e0d\u4ec5\u6392\u9664\u4e86 spin_lock_irqsave \u4e00\u7c7b\u5173\u4e2d\u65ad\u6301\u9501\u7684\u5acc\u7591&#xff0c;\u4e5f\u89e3\u91ca\u4e86\u8fd9\u4efd vmcore \u4f55\u4ee5\u5b58\u5728\u2014\u2014\u6309 4.5 \u8282\u7684\u60c5\u5f62\u5212\u5206&#xff0c;\u82e5\u8be5\u8def\u5f84\u5173\u95ed\u4e86\u4e2d\u65ad&#xff0c;\u5728\u8fd9\u53f0\u65e0\u4f2a NMI \u7684\u673a\u5668\u4e0a\u4e0d\u4f1a\u6709\u4efb\u4f55\u68c0\u6d4b\u673a\u5236\u4ecb\u5165&#xff0c;\u4e5f\u5c31\u4e0d\u4f1a\u6709\u73b0\u573a\u53ef\u4f9b\u5206\u6790\u3002<\/p>\n<h4>9.3 \u53d6\u7b49\u5f85\u8fb9\u53d7\u963b&#xff1a;\u4e09\u79cd\u4e0d\u540c\u7684\u5931\u8d25<\/h4>\n<p>\u7b2c\u516d\u7bc7 5.6 \u8282\u5df2\u5206\u6790\u8fc7 bt \u5728\u8fd9\u4efd\u73b0\u573a\u4e0a\u7684\u56f0\u96be\u3002\u5b8c\u6574\u6838\u5b9e\u4e09\u9897 CPU&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> bt <span class=\"token parameter variable\">-c<\/span> <span class=\"token number\">79<\/span><br \/>\nPID: <span class=\"token number\">2896966<\/span>  TASK: ffff8b5408058380  CPU: <span class=\"token number\">79<\/span>  COMMAND: <span class=\"token string\">&#034;jbd2\/sdc1-8&#034;<\/span><br \/>\n <span class=\"token comment\">#0 [ffffab54bf4dfbf0] __crash_kexec at ffff3ab9a98cf8a0<\/span><br \/>\n <span class=\"token comment\">#1 [ffffab54bf4dfd60] panic at ffff3ab9a9809cc4<\/span><br \/>\n <span class=\"token comment\">#2 [ffffab54bf4dfe40] watchdog_timer_fn at ffff3ab9a9906878<\/span><br \/>\n <span class=\"token comment\">#3 [ffffab54bf4dfea0] __hrtimer_run_queues at ffff3ab9a98aa070<\/span><br \/>\n <span class=\"token comment\">#4 [ffffab54bf4dff20] hrtimer_interrupt at ffff3ab9a98aaf14<\/span><br \/>\n <span class=\"token comment\">#5 [ffffab54bf4dff90] arch_timer_handler_phys at ffff3ab9aa0eec14<\/span><br \/>\n <span class=\"token comment\">#6 [ffffab54bf4dffb0] handle_percpu_devid_irq at ffff3ab9a9889c8c<\/span><br \/>\n <span class=\"token comment\">#7 [ffffab54bf4dfff0] generic_handle_irq at ffff3ab9a98820e8<\/span><br \/>\n <span class=\"token comment\">#8 [ffffab54bf4e0010] __handle_domain_irq at ffff3ab9a9882a04<\/span><\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> bt <span class=\"token parameter variable\">-c<\/span> <span class=\"token number\">0<\/span><br \/>\nPID: <span class=\"token number\">0<\/span>      TASK: ffff3ab9aaf0f4c0  CPU: <span class=\"token number\">0<\/span>   COMMAND: <span class=\"token string\">&#034;swapper\/0&#034;<\/span><br \/>\n <span class=\"token comment\">#0 [ffff8b54fe24fe30] crash_save_cpu at ffff3ab9a98cfc44<\/span><br \/>\n <span class=\"token comment\">#1 [ffff8b54fe24ffe0] handle_IPI at ffff3ab9a97b74f0<\/span><br \/>\n <span class=\"token comment\">#2 [ffff8b54fe250050] gic_handle_irq at ffff3ab9a97a1740<\/span><\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> bt <span class=\"token parameter variable\">-c<\/span> <span class=\"token number\">95<\/span><br \/>\nPID: <span class=\"token number\">2896829<\/span>  TASK: ffff8b540805c180  CPU: <span class=\"token number\">95<\/span>  COMMAND: <span class=\"token string\">&#034;jbd2\/sdb1-8&#034;<\/span><br \/>\nbt: WARNING: cannot determine starting stack frame <span class=\"token keyword\">for<\/span> task ffff8b540805c180<\/p>\n<table>\n<tr>CPU\u5bc4\u5b58\u5668\u73b0\u573abt \u7ed3\u679c\u53d7\u963b\u539f\u56e0<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">79<\/td>\n<td align=\"left\">\u6709&#xff08;panic \u8def\u5f84&#xff09;<\/td>\n<td align=\"left\">8 \u5e27&#xff0c;\u6b62\u4e8e __handle_domain_irq<\/td>\n<td align=\"left\">unwinder \u8de8\u6808\u5931\u8d25<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">0<\/td>\n<td align=\"left\">\u6709<\/td>\n<td align=\"left\">3 \u5e27&#xff0c;\u6b62\u4e8e gic_handle_irq<\/td>\n<td align=\"left\">unwinder \u8de8\u6808\u5931\u8d25<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">95<\/td>\n<td align=\"left\">\u65e0<\/td>\n<td align=\"left\">cannot determine starting stack frame<\/td>\n<td align=\"left\">\u672a\u54cd\u5e94\u505c\u673a IPI<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>CPU 0 \u7684\u8f93\u51fa\u7ea0\u6b63\u4e86\u4e00\u4e2a\u5bb9\u6613\u8bef\u5224\u7684\u5730\u65b9\u3002 \u5b83\u7684\u6808\u9876\u662f crash_save_cpu\u2014\u2014\u8be5 CPU \u6536\u5230\u4e86\u505c\u673a IPI \u5e76\u5b8c\u6574\u6267\u884c\u4e86\u5bc4\u5b58\u5668\u4fdd\u5b58\u6d41\u7a0b&#xff0c;crash_notes \u6709\u6548\u3002\u7136\u800c dmesg \u91cc\u5199\u7740&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> log <span class=\"token operator\">|<\/span> <span class=\"token function\">grep<\/span> <span class=\"token parameter variable\">-i<\/span> <span class=\"token string\">&#034;failed to stop&#034;<\/span><br \/>\n<span class=\"token punctuation\">[<\/span><span class=\"token number\">27881836.838944<\/span><span class=\"token punctuation\">]<\/span> SMP: failed to stop secondary CPUs <span class=\"token number\">0<\/span>-78,80-95<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> log <span class=\"token operator\">|<\/span> <span class=\"token function\">grep<\/span> <span class=\"token parameter variable\">-i<\/span> <span class=\"token string\">&#034;stale\\\\|unreliable&#034;<\/span><br \/>\n<span class=\"token punctuation\">[<\/span><span class=\"token number\">27881836.848669<\/span><span class=\"token punctuation\">]<\/span> Some CPUs may be stale, kdump will be unreliable.<\/p>\n<p>CPU 0 \u660e\u660e\u5728 0-78 \u8fd9\u4e2a\u540d\u5355\u91cc\u3002\u77db\u76fe\u7684\u6839\u6e90\u5728\u4e8e\u8be5\u6d88\u606f\u7684\u6253\u5370\u65b9\u5f0f\u3002\u4ee5\u4e0b\u4e3a 4.19 \u7248\u672c arch\/arm64\/kernel\/smp.c \u7684\u5b9e\u73b0&#xff1a;<\/p>\n<p><span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">atomic_read<\/span><span class=\"token punctuation\">(<\/span><span class=\"token operator\">&amp;<\/span>waiting_for_crash_ipi<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">&gt;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span><br \/>\n    <span class=\"token function\">pr_warn<\/span><span class=\"token punctuation\">(<\/span>&#034;SMP<span class=\"token operator\">:<\/span> failed to stop secondary CPUs <span class=\"token operator\">%<\/span><span class=\"token operator\">*<\/span>pbl<br \/>\n&#034;<span class=\"token punctuation\">,<\/span><br \/>\n            <span class=\"token function\">cpumask_pr_args<\/span><span class=\"token punctuation\">(<\/span><span class=\"token operator\">&amp;<\/span>mask<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span>   <span class=\"token comment\">\/* mask &#061; \u5168\u90e8 secondary CPU *\/<\/span><\/p>\n<p>\u6253\u5370\u7684 mask \u662f&#034;\u6240\u6709\u975e\u672c\u6838 CPU&#034;&#xff0c;\u4e0d\u662f&#034;\u5b9e\u9645\u5931\u8d25\u7684 CPU&#034;\u3002 \u8ba1\u6570\u5668\u5927\u4e8e 0 \u4ec5\u8bf4\u660e\u81f3\u5c11\u6709\u4e00\u9897\u672a\u5728\u8d85\u65f6\u5185\u62a5\u5230&#xff0c;\u6d88\u606f\u5374\u628a 95 \u9897\u5168\u90e8\u5217\u51fa\u3002<\/p>\n<p>failed to stop secondary CPUs \u7ed9\u51fa\u7684\u662f\u5019\u9009\u540d\u5355&#xff0c;\u4e0d\u662f\u5931\u8d25\u540d\u5355\u3002 \u5224\u65ad\u67d0\u9897 CPU \u7684\u73b0\u573a\u662f\u5426\u53ef\u7528&#xff0c;\u987b\u9010\u4e2a bt -c N \u5b9e\u6d4b&#xff0c;\u4e0d\u80fd\u636e\u8fd9\u6761\u6d88\u606f\u63a8\u65ad\u3002<\/p>\n<p>\u8be5\u7ed3\u8bba\u57fa\u4e8e 4.19 \u7684\u5b9e\u73b0\u3002\u5176\u4ed6\u5185\u6838\u7248\u672c\u7684\u6253\u5370\u903b\u8f91\u53ef\u80fd\u4e0d\u540c&#xff08;\u8f83\u65b0\u7248\u672c\u6709\u53ef\u80fd\u6539\u4e3a\u53ea\u8f93\u51fa\u5b9e\u9645\u8d85\u65f6\u7684 CPU \u5b50\u96c6&#xff09;&#xff0c;\u9047\u5230\u6b64\u7c7b\u6d88\u606f\u65f6\u5e94\u56de\u67e5\u76ee\u6807\u5185\u6838\u5bf9\u5e94\u4f4d\u7f6e\u7684\u4ee3\u7801&#xff0c;\u6216\u76f4\u63a5\u4ee5\u9010 CPU \u5b9e\u6d4b\u4e3a\u51c6\u3002<\/p>\n<p>\u4ea4\u53c9\u63a8\u65ad\u5728\u8fd9\u4efd vmcore \u4e0a\u786e\u5b9e\u5931\u6548&#xff0c;\u4f46\u4e3b\u56e0\u662f unwinder \u800c\u975e\u5bc4\u5b58\u5668\u7f3a\u5931\u3002 \u5373\u4fbf\u5bc4\u5b58\u5668\u9f50\u5168&#xff08;\u5982 CPU 0&#xff09;&#xff0c;\u4e5f\u770b\u4e0d\u5230\u4e2d\u65ad\u4e4b\u524d\u8be5 CPU \u5728\u6267\u884c\u4ec0\u4e48\u2014\u2014\u800c\u8fd9\u6070\u6070\u662f STEP 3 \u63a8\u65ad\u6301\u6709\u8005\u6240\u9700\u7684\u4fe1\u606f\u3002\u81f3\u4e8e CPU 95&#xff0c;\u5b83\u672c\u8eab\u5c31\u662f\u53e6\u4e00\u9897 soft lockup \u7684\u6838&#xff08;jbd2\/sdb1-8&#xff09;&#xff0c;\u5361\u5728\u81ea\u65cb\u4e2d\u65e0\u6cd5\u54cd\u5e94 IPI&#xff0c;\u5c5e\u4e8e\u95ee\u9898\u7684\u75c7\u72b6\u800c\u975e\u72ec\u7acb\u6545\u969c\u3002<\/p>\n<p>\u6539\u4ece\u5185\u6838\u81ea\u8eab\u6253\u5370\u7684\u8c03\u7528\u94fe\u53d6\u7b49\u5f85\u8fb9&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> log <span class=\"token operator\">|<\/span> <span class=\"token function\">grep<\/span> <span class=\"token parameter variable\">-A20<\/span> <span class=\"token string\">&#034;Call trace&#034;<\/span><\/p>\n<p>el1_irq&#043;0xb8\/0x140<br \/>\next4_process_freed_data&#043;0x258\/0x530<br \/>\next4_journal_commit_callback&#043;0x50\/0x120<br \/>\njbd2_journal_commit_transaction&#043;0x164c\/0x1a60<br \/>\nkjournald2&#043;0xd0\/0x2b8<\/p>\n<p>ARM64 \u4e0a crash \u7684 unwinder \u8de8\u6808\u80fd\u529b\u6709\u9650&#xff0c;bt \u65ad\u5728\u4e2d\u65ad\u8def\u5f84\u65f6&#xff0c;dmesg \u4e2d\u5185\u6838\u81ea\u5df1\u6253\u5370\u7684 Call trace \u5f80\u5f80\u66f4\u5b8c\u6574\u2014\u2014\u90a3\u662f\u5185\u6838 unwinder \u7684\u8f93\u51fa&#xff0c;\u4e0e crash \u662f\u4e24\u5957\u72ec\u7acb\u5b9e\u73b0\u3002<\/p>\n<h4>9.4 \u6838\u5fc3\u9a8c\u8bc1&#xff1a;\u53cd\u6c47\u7f16 &#043;0x258<\/h4>\n<p>\u8fd9\u662f\u7b2c\u516d\u7bc7\u660e\u786e\u8981\u6c42\u8865\u4e0a\u7684\u4e00\u6b65\u3002 \u7b2c\u516d\u7bc7\u5f53\u65f6\u63d0\u51fa&#034;\u4e24\u5757\u72ec\u7acb\u78c1\u76d8\u7684 jbd2 \u5361\u5728\u540c\u4e00\u504f\u79fb&#xff0c;\u53ef\u80fd\u662f\u81ea\u65cb\u9501\u4e89\u62a2&#034;&#xff0c;\u5e76\u5f3a\u8c03\u5fc5\u987b\u53cd\u6c47\u7f16\u786e\u8ba4\u3002<\/p>\n<p>\u5148\u5b9a\u4f4d\u51fd\u6570\u57fa\u5740&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> sym ext4_process_freed_data<br \/>\nffff3ab9a9b36798 <span class=\"token punctuation\">(<\/span>T<span class=\"token punctuation\">)<\/span> ext4_process_freed_data<br \/>\n    \/usr\/src\/debug\/kernel-4.19.90\/<span class=\"token punctuation\">..<\/span>.\/fs\/ext4\/mballoc.c: <span class=\"token number\">2860<\/span><\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> whatis ext4_process_freed_data<br \/>\nvoid ext4_process_freed_data<span class=\"token punctuation\">(<\/span>struct super_block *, tid_t<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>\u76ee\u6807\u5730\u5740&#xff1a;<\/p>\n<p>base    &#061; 0xffff3ab9a9b36798<br \/>\ntarget  &#061; base &#043; 0x258 &#061; 0xffff3ab9a9b369f0<\/p>\n<p>crash \u7684 dis \u8f93\u51fa\u4e2d&#xff0c;\u7b26\u53f7\u540e\u7684\u504f\u79fb\u662f\u5341\u8fdb\u5236\u3002 &#043;0x258 \u5bf9\u5e94\u8f93\u51fa\u91cc\u7684 &#043;600&#xff0c;\u6362\u7b97\u65f6\u5bb9\u6613\u51fa\u9519&#xff0c;\u5efa\u8bae\u76f4\u63a5\u6309\u5730\u5740\u53cd\u6c47\u7f16\u3002<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> dis <span class=\"token parameter variable\">-l<\/span> 0xffff3ab9a9b369e0 <span class=\"token number\">16<\/span><\/p>\n<p>.\/arch\/arm64\/include\/asm\/atomic_lse.h: 479<br \/>\n0xffff3ab9a9b369e0 &lt;ext4_process_freed_data&#043;584&gt;:  mov    x0, x4<br \/>\n0xffff3ab9a9b369e4 &lt;ext4_process_freed_data&#043;588&gt;:  mov    x2, #0x1<br \/>\n0xffff3ab9a9b369e8 &lt;ext4_process_freed_data&#043;592&gt;:  mov    w30, w1<br \/>\n0xffff3ab9a9b369ec &lt;ext4_process_freed_data&#043;596&gt;:  .inst  0x88fe7c82 ; undefined<br \/>\n0xffff3ab9a9b369f0 &lt;ext4_process_freed_data&#043;600&gt;:  mov    w0, w30<\/p>\n<p>.\/include\/asm-generic\/qspinlock.h: 86<br \/>\n0xffff3ab9a9b369f4 &lt;ext4_process_freed_data&#043;604&gt;:  cbnz   w0, 0xffff3ab9a9b36c70<\/p>\n<p>fs\/ext4\/ext4.h: 1571<br \/>\n0xffff3ab9a9b369f8 &lt;ext4_process_freed_data&#043;608&gt;:  ldr    x1, [x19,#1032]<\/p>\n<p>fs\/ext4\/mballoc.c: 2820<br \/>\n0xffff3ab9a9b369fc &lt;ext4_process_freed_data&#043;612&gt;:  ldr    w2, [x20,#48]<br \/>\n0xffff3ab9a9b36a00 &lt;ext4_process_freed_data&#043;616&gt;:  ldr    w0, [x1,#700]<br \/>\n0xffff3ab9a9b36a04 &lt;ext4_process_freed_data&#043;620&gt;:  sub    w0, w0, w2<br \/>\n0xffff3ab9a9b36a08 &lt;ext4_process_freed_data&#043;624&gt;:  str    w0, [x1,#700]<\/p>\n<p>.\/include\/asm-generic\/qspinlock.h: 101<br \/>\n0xffff3ab9a9b36a0c &lt;ext4_process_freed_data&#043;628&gt;:  ldr    x0, [x19,#1032]<br \/>\n0xffff3ab9a9b36a10 &lt;ext4_process_freed_data&#043;632&gt;:  add    x0, x0, #0x2a0<br \/>\n0xffff3ab9a9b36a14 &lt;ext4_process_freed_data&#043;636&gt;:  stlrb  w23, [x0]<\/p>\n<p>\u6e90\u7801\u884c\u53f7\u76f4\u63a5\u7ed9\u51fa\u4e86\u7b54\u6848\u3002<\/p>\n<p>&#043;596 \u5f52\u5c5e atomic_lse.h:479&#xff08;LSE \u539f\u5b50\u64cd\u4f5c&#xff09;&#xff0c;&#043;604 \u5f52\u5c5e qspinlock.h:86\u3002\u540e\u8005\u5bf9\u5e94\u7684\u662f&#xff1a;<\/p>\n<p><span class=\"token comment\">\/* include\/asm-generic\/qspinlock.h *\/<\/span><br \/>\n<span class=\"token keyword\">static<\/span> __always_inline <span class=\"token keyword\">void<\/span> <span class=\"token function\">queued_spin_lock<\/span><span class=\"token punctuation\">(<\/span><span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">qspinlock<\/span> <span class=\"token operator\">*<\/span>lock<span class=\"token punctuation\">)<\/span><br \/>\n<span class=\"token punctuation\">{<\/span><br \/>\n    u32 val <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">atomic_cmpxchg_acquire<\/span><span class=\"token punctuation\">(<\/span><span class=\"token operator\">&amp;<\/span>lock<span class=\"token operator\">-&gt;<\/span>val<span class=\"token punctuation\">,<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">,<\/span> _Q_LOCKED_VAL<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">likely<\/span><span class=\"token punctuation\">(<\/span>val <span class=\"token operator\">&#061;&#061;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><br \/>\n        <span class=\"token keyword\">return<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">queued_spin_lock_slowpath<\/span><span class=\"token punctuation\">(<\/span>lock<span class=\"token punctuation\">,<\/span> val<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span>   <span class=\"token comment\">\/* &lt;- cbnz \u8df3\u8f6c\u76ee\u6807 *\/<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p>\u6c47\u7f16\u4e0e\u6e90\u7801\u9010\u6761\u5bf9\u5e94&#xff1a;x2 &#061; 1 \u662f _Q_LOCKED_VAL&#xff1b;.inst 0x88fe7c82 \u662f LSE \u7684\u6bd4\u8f83\u4ea4\u6362\u6307\u4ee4&#xff1b;&#043;600 \u628a\u7ed3\u679c\u642c\u56de w0&#xff1b;&#043;604 \u5224\u975e\u96f6\u5219\u8df3 slowpath\u3002<\/p>\n<p>.inst &#8230; undefined \u4e0d\u662f\u5185\u5b58\u635f\u574f\u3002 crash \u5185\u7f6e\u7684\u53cd\u6c47\u7f16\u5668\u7248\u672c\u8f83\u65e7&#xff0c;\u4e0d\u8bc6\u522b ARMv8.1 \u7684 LSE \u539f\u5b50\u6307\u4ee4&#xff08;casal\u3001ldadd \u7b49&#xff09;&#xff0c;\u56e0\u6b64\u628a\u673a\u5668\u7801\u539f\u6837\u8f93\u51fa\u3002\u9700\u8981\u89e3\u7801\u65f6\u7528 objdump -d &#8211;start-address&#061;0xffff3ab9a9b369ec vmlinux \u5373\u53ef\u3002\u9047\u5230 undefined \u5148\u8003\u8651\u53cd\u6c47\u7f16\u5668\u80fd\u529b&#xff0c;\u800c\u975e\u6570\u636e\u635f\u574f\u3002<\/p>\n<p>&#043;0x258 \u662f spin_lock() \u5185\u8054\u5c55\u5f00\u540e\u3001cmpxchg \u521a\u8fd4\u56de\u7684\u90a3\u6761\u6307\u4ee4\u3002\u7b2c\u516d\u7bc7\u7684\u5047\u8bbe\u6210\u7acb\u3002<\/p>\n<h4>9.5 \u786e\u5b9a\u662f\u54ea\u628a\u9501<\/h4>\n<p>&#043;628:  ldr    x0, [x19,#1032]     &lt;- x0 &#061; sb-&gt;s_fs_info&#xff0c;\u5373 EXT4_SB(sb)<br \/>\n&#043;632:  add    x0, x0, #0x2a0      &lt;- \u52a0\u56fa\u5b9a\u504f\u79fb&#xff0c;\u65e0\u7d22\u5f15\u8fd0\u7b97<br \/>\n&#043;636:  stlrb  w23, [x0]           &lt;- qspinlock.h:101, queued_spin_unlock()<\/p>\n<p>x19 \u662f\u51fd\u6570\u9996\u53c2 struct super_block *&#xff0c;\u504f\u79fb 1032 \u5904\u53d6\u51fa EXT4_SB(sb)&#xff0c;\u518d\u52a0\u56fa\u5b9a\u504f\u79fb 0x2a0&#xff08;\u5341\u8fdb\u5236 672&#xff09;\u5f97\u5230\u9501\u5730\u5740\u3002<\/p>\n<p>\u6ce8\u610f\u8fd9\u91cc\u662f\u7eaf\u56fa\u5b9a\u504f\u79fb&#xff0c;\u4e0d\u542b\u4efb\u4f55\u7d22\u5f15\u8ba1\u7b97\u3002 \u8fd9\u4e00\u70b9\u6392\u9664\u4e86 ext4_lock_group() \u7684\u53ef\u80fd\u2014\u2014\u540e\u8005\u5185\u90e8\u8c03\u7528 bgl_lock_ptr()&#xff0c;\u8fd4\u56de locks[group &amp; (NR_BG_LOCKS-1)]&#xff0c;\u662f\u4f9d\u8d56 group \u53c2\u6570\u7684\u52a8\u6001\u5730\u5740&#xff0c;\u7f16\u8bd1\u540e\u5fc5\u7136\u5305\u542b\u63a9\u7801\u4e0e\u7d22\u5f15\u8fd0\u7b97\u3002<\/p>\n<p>\u5b9e\u6d4b\u786e\u8ba4\u8be5\u504f\u79fb\u5bf9\u5e94\u7684\u5b57\u6bb5&#xff1a;<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> struct ext4_sb_info <span class=\"token parameter variable\">-o<\/span> <span class=\"token operator\">|<\/span> <span class=\"token function\">grep<\/span> <span class=\"token parameter variable\">-B2<\/span> <span class=\"token parameter variable\">-A2<\/span> <span class=\"token string\">&#034;672&#034;<\/span><br \/>\n   <span class=\"token punctuation\">[<\/span><span class=\"token number\">656<\/span><span class=\"token punctuation\">]<\/span> struct ext4_group_info ***s_group_info<span class=\"token punctuation\">;<\/span><br \/>\n   <span class=\"token punctuation\">[<\/span><span class=\"token number\">664<\/span><span class=\"token punctuation\">]<\/span> struct inode *s_buddy_cache<span class=\"token punctuation\">;<\/span><br \/>\n   <span class=\"token punctuation\">[<\/span><span class=\"token number\">672<\/span><span class=\"token punctuation\">]<\/span> spinlock_t s_md_lock<span class=\"token punctuation\">;<\/span><br \/>\n   <span class=\"token punctuation\">[<\/span><span class=\"token number\">680<\/span><span class=\"token punctuation\">]<\/span> unsigned short *s_mb_offsets<span class=\"token punctuation\">;<\/span><br \/>\n   <span class=\"token punctuation\">[<\/span><span class=\"token number\">688<\/span><span class=\"token punctuation\">]<\/span> unsigned int *s_mb_maxs<span class=\"token punctuation\">;<\/span><\/p>\n<p>struct &#8230; -o \u7684\u504f\u79fb\u5217\u662f\u5341\u8fdb\u5236&#xff0c;\u56e0\u6b64\u67e5 0x2a0 \u987b\u6362\u7b97\u4e3a 672 \u518d\u68c0\u7d22\u3002<\/p>\n<p>\u7ed3\u8bba&#xff1a;\u5361\u5728 ext4_sb_info-&gt;s_md_lock \u4e0a\u2014\u2014\u8fd9\u662f\u6bcf\u4e2a ext4 \u6587\u4ef6\u7cfb\u7edf\u5b9e\u4f8b\u552f\u4e00\u7684\u4e00\u628a mballoc \u6570\u636e\u4fdd\u62a4\u9501&#xff0c;\u4e0d\u662f per-block-group \u9501\u3002<\/p>\n<p>\u8fd9\u91cc\u7ea0\u6b63\u4e00\u5904\u6781\u6613\u53d1\u751f\u7684\u8bef\u5224\u3002 \u53cd\u6c47\u7f16\u4e2d &#043;608 \u5904\u5e26\u6709 fs\/ext4\/ext4.h:1571 \u7684\u884c\u53f7&#xff0c;\u8be5\u884c\u6b63\u662f ext4_lock_group() \u7684\u5b9a\u4e49\u4f4d\u7f6e&#xff0c;\u5f88\u5bb9\u6613\u636e\u6b64\u8ba4\u5b9a\u5361\u5728 group \u9501\u4e0a\u3002\u4f46\u884c\u53f7\u4fe1\u606f\u5728\u5185\u8054\u5c55\u5f00\u540e\u4f1a\u51fa\u73b0\u6620\u5c04\u504f\u5dee&#xff0c;\u4e0d\u80fd\u5355\u72ec\u4f5c\u4e3a\u9501\u8eab\u4efd\u7684\u8bc1\u636e\u3002<\/p>\n<p>\u771f\u6b63\u7684\u5224\u636e\u6709\u4e24\u6761&#xff1a;\u5176\u4e00&#xff0c;\u5bfb\u5740\u65b9\u5f0f\u662f\u56fa\u5b9a\u504f\u79fb\u800c\u975e\u52a8\u6001\u7d22\u5f15&#xff1b;\u5176\u4e8c&#xff0c;struct ext4_sb_info -o \u5b9e\u6d4b\u7ed9\u51fa\u7684\u5b57\u6bb5\u540d\u3002\u51e1\u662f\u4ece\u884c\u53f7\u63a8\u65ad\u51fa\u7684\u5bf9\u8c61\u8eab\u4efd&#xff0c;\u90fd\u5e94\u5f53\u7528\u7ed3\u6784\u4f53\u504f\u79fb\u5b9e\u6d4b\u590d\u6838\u3002<\/p>\n<p>\u800c mballoc.c:2820&#xff08;&#043;612&#xff5e;&#043;624&#xff09;\u662f\u4e34\u754c\u533a\u5185\u7684\u64cd\u4f5c\u2014\u2014\u4ece x1&#043;700 \u51cf\u53bb x20&#043;48 \u540e\u5199\u56de&#xff0c;\u5bf9\u5e94\u91ca\u653e\u5757\u65f6\u66f4\u65b0\u8ba1\u6570\u3002<\/p>\n<h4>9.6 \u5b8c\u6574\u56e0\u679c\u94fe<\/h4>\n<p>two jbd2 threads (sdb1 \/ sdc1) commit transactions<br \/>\n        |<br \/>\n        v<br \/>\njbd2_journal_commit_transaction<br \/>\n        |<br \/>\n        v<br \/>\next4_journal_commit_callback  -&gt;  ext4_process_freed_data<br \/>\n        |<br \/>\n        v<br \/>\nwalk s_freed_data_list; for each freed extent:<br \/>\n        spin_lock(&amp;sbi-&gt;s_md_lock)      &lt;- STUCK HERE (&#043;0x258)<br \/>\n        update counters                 &lt;- mballoc.c:2820<br \/>\n        spin_unlock(&amp;sbi-&gt;s_md_lock)    &lt;- &#043;636 stlrb<br \/>\n        |<br \/>\n        v<br \/>\neach filesystem has exactly ONE s_md_lock<br \/>\n-&gt; all mballoc operations on that fs serialize through it<br \/>\n        |<br \/>\n        v<br \/>\nspin exceeds watchdog threshold  -&gt;  soft lockup on both CPUs<\/p>\n<p>\u7b2c\u516d\u7bc7\u7684\u5047\u8bbe\u5f97\u5230\u8bc1\u5b9e&#xff1a;\u786e\u5b9e\u662f\u81ea\u65cb\u9501\u4e89\u62a2\u3002 \u4f46\u4e89\u62a2\u7684\u5bf9\u8c61\u4e0e\u539f\u5148\u7684\u63a8\u6d4b\u4e0d\u540c\u2014\u2014\u4e0d\u662f per-block-group \u9501&#xff0c;\u800c\u662f s_md_lock\u3002<\/p>\n<p>\u8fd9\u4e2a\u533a\u522b\u5728\u6545\u969c\u673a\u7406\u4e0a\u5f88\u5173\u952e\u3002 per-block-group \u9501\u6709 NR_BG_LOCKS&#xff08;\u901a\u5e38 128&#xff09;\u628a&#xff0c;\u6309 group \u7f16\u53f7\u6563\u5217&#xff0c;\u7ade\u4e89\u88ab\u7a00\u91ca&#xff1b;\u800c s_md_lock \u662f\u6bcf\u4e2a\u6587\u4ef6\u7cfb\u7edf\u552f\u4e00\u7684\u4e00\u628a&#xff0c;\u8be5\u6587\u4ef6\u7cfb\u7edf\u4e0a\u6240\u6709 mballoc \u76f8\u5173\u64cd\u4f5c\u90fd\u8981\u4e32\u884c\u901a\u8fc7\u5b83&#xff0c;\u4e0d\u5b58\u5728\u4efb\u4f55\u7a00\u91ca\u3002<\/p>\n<p>\u8fd8\u6709\u4e00\u70b9\u987b\u6f84\u6e05&#xff1a;sdb1 \u4e0e sdc1 \u662f\u4e24\u4e2a\u72ec\u7acb\u7684\u6587\u4ef6\u7cfb\u7edf&#xff0c;\u5404\u81ea\u62e5\u6709\u72ec\u7acb\u7684 ext4_sb_info&#xff0c;\u56e0\u800c\u5404\u81ea\u6709\u72ec\u7acb\u7684 s_md_lock\u3002\u4e24\u9897 CPU \u5e76\u975e\u5728\u4e89\u62a2\u540c\u4e00\u4e2a\u9501\u5bf9\u8c61\u3002\u5b83\u4eec\u5361\u5728\u540c\u4e00\u504f\u79fb&#xff0c;\u662f\u56e0\u4e3a\u6267\u884c\u7684\u662f\u540c\u4e00\u6bb5\u4ee3\u7801\u8def\u5f84&#xff0c;\u800c\u975e\u7ade\u4e89\u540c\u4e00\u5bf9\u8c61\u3002<\/p>\n<p>\u56e0\u6b64\u73b0\u573a\u7684\u6027\u8d28\u662f&#xff1a;\u4e24\u4e2a\u6587\u4ef6\u7cfb\u7edf\u5404\u81ea\u7684 s_md_lock \u540c\u65f6\u51fa\u73b0\u957f\u65f6\u95f4\u4e89\u62a2\u3002\u8fd9\u63d0\u793a\u538b\u529b\u6765\u81ea\u5171\u6027\u56e0\u7d20\u800c\u975e\u5355\u4e00\u78c1\u76d8\u2014\u2014\u7ed3\u5408\u8be5\u673a\u89c4\u6a21&#xff08;96 \u6838\u30011TB \u5185\u5b58\u3001\u8fde\u7eed\u8fd0\u884c 322 \u5929&#xff09;&#xff0c;\u5f85\u91ca\u653e\u7684 extent \u94fe\u8868\u53ef\u80fd\u6781\u957f&#xff0c;\u6bcf\u4e2a extent \u90fd\u8981\u53d6\u4e00\u6b21 s_md_lock&#xff0c;\u800c 96 \u6838\u7684\u5e76\u53d1\u89c4\u6a21\u4f1a\u8ba9\u8fd9\u628a\u5355\u70b9\u9501\u6210\u4e3a\u660e\u663e\u74f6\u9888\u3002<\/p>\n<p>\u8fdb\u4e00\u6b65\u7684\u6392\u67e5\u65b9\u5411&#xff1a;\u786e\u8ba4 s_freed_data_list \u7684\u5b9e\u9645\u957f\u5ea6&#xff0c;\u4ee5\u53ca\u540c\u4e00\u6587\u4ef6\u7cfb\u7edf\u4e0a\u6709\u591a\u5c11 CPU \u5728\u5e76\u53d1\u6267\u884c mballoc \u8def\u5f84\u3002<\/p>\n<h4>9.7 \u672c\u6848\u4f8b\u7684\u65b9\u6cd5\u8bba\u4ef7\u503c<\/h4>\n<p>\u5176\u4e00&#xff0c;\u884c\u53f7\u53ef\u4ee5\u63d0\u793a\u65b9\u5411&#xff0c;\u4f46\u4e0d\u80fd\u4f5c\u4e3a\u5bf9\u8c61\u8eab\u4efd\u7684\u6700\u7ec8\u5224\u636e\u3002 \u7b2c\u516d\u7bc7\u63d0\u51fa&#034;\u53ef\u80fd\u662f\u81ea\u65cb\u9501&#034;&#xff0c;\u672c\u7ae0\u901a\u8fc7 dis -l \u7684 qspinlock.h:86 \u786e\u8ba4\u4e86\u8fd9\u4e00\u70b9\u2014\u2014\u8fd9\u90e8\u5206\u884c\u53f7\u8bc1\u636e\u662f\u53ef\u9760\u7684&#xff0c;\u56e0\u4e3a\u5b83\u6807\u6ce8\u7684\u6b63\u662f &#043;604 \u90a3\u6761 cbnz \u6307\u4ee4\u672c\u8eab\u3002<\/p>\n<p>\u4f46\u7528\u884c\u53f7\u5224\u65ad\u662f\u54ea\u628a\u9501\u5219\u4e0d\u53ef\u9760&#xff1a;&#043;608 \u5904\u7684 ext4.h:1571 \u6307\u5411 ext4_lock_group()&#xff0c;\u636e\u6b64\u4f1a\u5f97\u51fa&#034;per-block-group \u9501&#034;\u7684\u7ed3\u8bba&#xff0c;\u800c struct ext4_sb_info -o \u5b9e\u6d4b\u8868\u660e\u8be5\u504f\u79fb\u662f s_md_lock\u3002\u5185\u8054\u5c55\u5f00\u4f1a\u4f7f\u884c\u53f7\u6620\u5c04\u4ea7\u751f\u504f\u5dee&#xff0c;\u51e1\u6d89\u53ca\u5bf9\u8c61\u8eab\u4efd\u7684\u7ed3\u8bba&#xff0c;\u90fd\u5e94\u4ee5\u7ed3\u6784\u4f53\u504f\u79fb\u5b9e\u6d4b\u590d\u6838\u3002<\/p>\n<p>\u672c\u4f8b\u4e2d\u771f\u6b63\u6307\u5411\u6b63\u786e\u7b54\u6848\u7684\u662f\u5bfb\u5740\u65b9\u5f0f&#xff1a;\u56fa\u5b9a\u504f\u79fb add #0x2a0 \u6392\u9664\u4e86\u9700\u8981\u7d22\u5f15\u8fd0\u7b97\u7684 bgl_lock_ptr()\u3002\u6c47\u7f16\u7684\u5bfb\u5740\u5f62\u6001\u6709\u65f6\u6bd4\u884c\u53f7\u66f4\u53ef\u4fe1\u3002 \u4e0e\u6b64\u540c\u65f6&#xff0c;\u5e26 debuginfo \u7684 vmlinux \u4ecd\u662f\u5fc5\u8981\u6761\u4ef6\u2014\u2014\u82e5\u53ea\u6709\u88f8\u7b26\u53f7&#xff0c;\u770b\u5230 .inst undefined \u4e0e\u51e0\u6761 ldr\/add&#xff0c;\u8fde&#034;\u8fd9\u662f\u52a0\u9501\u8def\u5f84&#034;\u90fd\u96be\u4ee5\u65ad\u5b9a\u3002<\/p>\n<p>\u5176\u4e8c&#xff0c;dmesg \u6d88\u606f\u7684\u63aa\u8f9e\u9700\u8981\u6838\u5b9e\u5176\u751f\u6210\u903b\u8f91\u3002 failed to stop secondary CPUs 0-78,80-95 \u770b\u4f3c\u5217\u51fa\u4e86 95 \u9897\u5931\u8d25\u7684 CPU&#xff0c;\u5b9e\u9645\u662f\u5019\u9009\u540d\u5355&#xff1b;CPU 0 \u7684 bt \u8bc1\u660e\u5b83\u4fdd\u5b58\u6210\u529f\u3002\u9047\u5230\u5173\u952e\u5224\u65ad\u4f9d\u8d56\u67d0\u6761\u5185\u6838\u6d88\u606f\u65f6&#xff0c;\u503c\u5f97\u56de\u67e5\u8be5\u6d88\u606f\u7684\u6253\u5370\u4ee3\u7801\u3002<\/p>\n<p>\u5176\u4e09&#xff0c;\u5de5\u5177\u80fd\u529b\u662f\u5206\u6790\u7684\u8fb9\u754c\u6761\u4ef6\u3002 ARM64 \u4e0a crash \u7684 unwinder \u8de8\u4e0d\u8fc7 IRQ \u6808\u8fb9\u754c&#xff0c;\u8fd9\u4e0e\u5bc4\u5b58\u5668\u662f\u5426\u53ef\u8bfb\u65e0\u5173\u3002\u6b64\u65f6\u5e94\u53ca\u65f6\u8f6c\u5411 dmesg \u7684 Call trace&#xff0c;\u800c\u975e\u5728\u5931\u6548\u7684\u547d\u4ee4\u4e0a\u53cd\u590d\u5c1d\u8bd5\u3002\u540c\u7406&#xff0c;.inst undefined \u662f\u53cd\u6c47\u7f16\u5668\u7684\u80fd\u529b\u95ee\u9898&#xff0c;\u6362\u7528 objdump \u5373\u53ef\u3002<\/p>\n<p>\u5176\u56db&#xff0c;\u5bf9\u53ef\u590d\u73b0\u7684\u95ee\u9898&#xff0c;\u5e94\u4f18\u5148\u6539\u53d8\u91c7\u96c6\u6761\u4ef6\u3002 \u8fd9\u4efd\u73b0\u573a\u82e5\u80fd\u590d\u73b0&#xff0c;\u4e24\u5904\u8c03\u6574\u53ef\u663e\u8457\u964d\u4f4e\u5206\u6790\u96be\u5ea6&#xff1a;\u5f00\u542f CONFIG_DEBUG_SPINLOCK \u4f7f raw_spinlock \u5e26\u4e0a owner \u5b57\u6bb5&#xff0c;\u5206\u6790\u8def\u5f84\u7531\u8def\u7ebf B \u8f6c\u4e3a\u8def\u7ebf A&#xff1b;\u589e\u52a0 irqchip.gicv3_pseudo_nmi&#061;1 \u542f\u52a8\u53c2\u6570\u4ee5\u83b7\u5f97 hard lockup \u68c0\u6d4b\u80fd\u529b\u3002\u4e8c\u8005\u7684\u6210\u672c\u5747\u4f4e\u4e8e\u5728\u73b0\u6709 vmcore \u4e0a\u8fdb\u884c\u4ea4\u53c9\u63a8\u65ad\u3002<\/p>\n<hr \/>\n<h3>\u5341\u3001lockdep \u544a\u8b66\u7684\u4e8b\u540e\u89e3\u8bfb<\/h3>\n<p>\u542f\u7528 CONFIG_PROVE_LOCKING \u65f6&#xff0c;\u5185\u6838\u5728\u8fd0\u884c\u65f6\u7ef4\u62a4\u5168\u5c40\u9501\u4f9d\u8d56\u56fe\u3002\u4e00\u65e6\u65b0\u7684\u52a0\u9501\u64cd\u4f5c\u4f1a\u5f62\u6210\u4f9d\u8d56\u73af&#xff0c;\u5728\u7b2c\u4e00\u6b21\u8fdd\u53cd\u65f6\u5373\u6253\u5370\u544a\u8b66\u2014\u2014\u4e0d\u9700\u8981\u6b7b\u9501\u771f\u6b63\u53d1\u751f\u3002<\/p>\n<p>\u82e5 dmesg \u4e2d\u6709 lockdep \u544a\u8b66&#xff0c;\u4f18\u5148\u8bfb\u5b83\u3002 \u5b83\u76f4\u63a5\u7ed9\u51fa\u73af\u7684\u4e24\u6761\u8fb9\u548c\u7cbe\u786e\u7684\u4ee3\u7801\u504f\u79fb&#xff0c;\u6bd4\u4ece\u9501\u7ed3\u6784\u53cd\u63a8\u5feb\u4e00\u4e2a\u6570\u91cf\u7ea7\u2014\u2014\u76f8\u5f53\u4e8e\u628a\u7b2c\u516d\u7ae0\u7684\u516d\u6b65\u5168\u90e8\u66ff\u4f60\u505a\u5b8c\u4e86\u3002<\/p>\n<p>crash<span class=\"token operator\">&gt;<\/span> log <span class=\"token operator\">|<\/span> <span class=\"token function\">grep<\/span> <span class=\"token parameter variable\">-A<\/span> <span class=\"token number\">60<\/span> <span class=\"token string\">&#034;circular locking dependency&#034;<\/span><\/p>\n<p>\u5178\u578b\u544a\u8b66\u7684\u7ed3\u6784&#xff1a;<\/p>\n<p>WARNING: possible circular locking dependency detected<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br \/>\nnet-rx-0\/5200 is trying to acquire lock:              &lt;- \u65b0\u8bf7\u6c42\u7684\u9501<br \/>\nffffffffc0909080 (&amp;drv-&gt;tx_lock){&#043;.&#043;.}-{2:2},<br \/>\n                 at: drv_process_rx&#043;0x190\/0x3a0 [netdrv]<\/p>\n<p>but task is already holding:                          &lt;- \u5f53\u524d\u5df2\u6301\u6709\u7684\u9501<br \/>\nffffffffc0909040 (&amp;drv-&gt;rx_lock){&#043;.&#043;.}-{2:2},<br \/>\n                 at: drv_process_rx&#043;0x30\/0x3a0 [netdrv]<\/p>\n<p>which lock already depends on the new lock.<\/p>\n<p>the existing dependency chain (in reverse order) is:<\/p>\n<p>-&gt; #1 (&amp;drv-&gt;tx_lock){&#043;.&#043;.}-{2:2}:<br \/>\n       _raw_spin_lock_irqsave&#043;0x48\/0x90<br \/>\n       drv_flush_tx&#043;0x30\/0x280 [netdrv]<\/p>\n<p>-&gt; #0 (&amp;drv-&gt;rx_lock){&#043;.&#043;.}-{2:2}:<br \/>\n       _raw_spin_lock_irqsave&#043;0x48\/0x90<br \/>\n       drv_flush_tx&#043;0x190\/0x280 [netdrv]<\/p>\n<p>\u8bfb\u6cd5&#xff1a; \u4e0a\u534a\u90e8\u5206\u7684 trying to acquire \u4e0e already holding \u5c31\u662f\u73af\u7684\u4e24\u6761\u8fb9&#xff1b;\u4e0b\u534a\u90e8\u5206\u7684\u4f9d\u8d56\u94fe\u7ed9\u51fa\u5bf9\u65b9\u8def\u5f84\u7684\u52a0\u9501\u4f4d\u7f6e\u3002\u56db\u4e2a &#043;0x190\/0x3a0 \u8fd9\u6837\u7684\u504f\u79fb\u53ef\u76f4\u63a5\u7528 dis \u5b9a\u4f4d\u5230\u5177\u4f53\u6307\u4ee4\u3002<\/p>\n<p>{&#043;.&#043;.} \u56db\u5b57\u7b26\u662f\u8be5\u9501\u7684\u4e2d\u65ad\u4e0a\u4e0b\u6587\u4f7f\u7528\u5386\u53f2\u3002-{2:2} \u662f lockdep \u8bb0\u5f55\u7684\u8be5\u9501\u5728 hardirq \/ softirq \u4e0a\u4e0b\u6587\u4e2d\u7684\u6700\u5927\u5d4c\u5957\u6df1\u5ea6\u2014\u2014\u6ce8\u610f\u8fd9\u662f\u5386\u53f2\u6700\u5927\u503c&#xff0c;\u4e0d\u662f\u672c\u6b21\u52a0\u9501\u5173\u4e86\u51e0\u5c42\u3002<\/p>\n<p>\u8fd9\u4e9b\u6ce8\u8bb0\u7684\u786e\u5207\u8bed\u4e49\u968f\u5185\u6838\u7248\u672c\u7565\u6709\u8c03\u6574&#xff0c;\u9047\u5230\u65f6\u4ee5\u8be5\u5185\u6838 Documentation\/locking\/lockdep-design.rst \u4e3a\u51c6&#xff0c;\u6216\u76f4\u63a5\u770b\u544a\u8b66\u4e0b\u65b9 lockdep \u81ea\u52a8\u6253\u5370\u7684\u8bf4\u660e\u6bb5\u843d\u3002\u5206\u6790\u65f6\u771f\u6b63\u5173\u952e\u7684\u662f\u4e0a\u534a\u90e8\u5206\u4e0e\u4e24\u6761\u4f9d\u8d56\u94fe\u2014\u2014\u90a3\u624d\u662f\u73af\u7684\u76f4\u63a5\u8bc1\u636e&#xff0c;\u6ce8\u8bb0\u53ea\u662f\u8865\u5145\u4fe1\u606f\u3002<\/p>\n<hr \/>\n<h3>\u5341\u4e00\u3001D \u72b6\u6001\u6d77\u7684\u8fa8\u522b&#xff1a;\u5e76\u975e\u5168\u662f\u6b7b\u9501<\/h3>\n<p>\u5927\u91cf D \u72b6\u6001\u8fdb\u7a0b\u4e0d\u7b49\u4e8e\u5b58\u5728\u73af\u8def\u6b7b\u9501\u3002\u7b2c\u516d\u7ae0 STEP 5 \u8ffd\u4e0d\u51fa\u73af\u65f6&#xff0c;\u5e94\u8f6c\u5165\u672c\u7ae0\u91cd\u65b0\u5b9a\u6027\u3002<\/p>\n<h4>11.1 \u6838\u5fc3\u52a8\u4f5c&#xff1a;\u627e\u5230\u7ec8\u7aef\u8282\u70b9<\/h4>\n<p>\u6ca1\u6709\u73af&#xff0c;\u610f\u5473\u7740\u7b49\u5f85\u94fe\u662f\u4e00\u6761\u6761\u6709\u7ec8\u70b9\u7684\u94fe\u800c\u975e\u9996\u5c3e\u76f8\u63a5\u7684\u5708\u3002\u56e0\u6b64\u8fa8\u522b\u7684\u7b2c\u4e00\u6b65\u4e0d\u662f\u7ee7\u7eed\u627e\u73af&#xff0c;\u800c\u662f\u6cbf\u6bcf\u6761\u94fe\u8d70\u5230\u5e95&#xff1a;<\/p>\n<p>terminal node &#061; the task at the end of a wait chain<br \/>\n                that is NOT waiting on any lock<\/p>\n<p>\u7ec8\u7aef\u8282\u70b9\u5728\u7b49\u4ec0\u4e48&#xff0c;\u51b3\u5b9a\u4e86\u6839\u56e0\u5f52\u5c5e\u3002 \u5b83\u4e0e\u524d\u9762\u90a3\u4e9b\u7b49\u5f85\u8005\u4e4b\u95f4\u9694\u4e86\u51e0\u628a\u9501&#xff0c;\u53ea\u5f71\u54cd\u8bca\u65ad\u6b65\u9aa4\u7684\u957f\u77ed&#xff0c;\u4e0d\u6539\u53d8\u6839\u56e0\u3002<\/p>\n<p>Follow each chain to its terminal node, then ask:<br \/>\n  what is that terminal task actually waiting on?<\/p>\n<p>  block device I\/O      -&gt;  storage subsystem<br \/>\n  network \/ RPC         -&gt;  NFS, iSCSI, remote storage<br \/>\n  completion            -&gt;  some other subsystem has not finished<br \/>\n  a long-running loop   -&gt;  not blocked at all, merely slow<br \/>\n  RCU grace period      -&gt;  different mechanism entirely, see 11.3<\/p>\n<h4>11.2 \u5355\u70b9\u963b\u585e&#xff1a;\u76f4\u63a5\u578b\u4e0e\u7ecf\u9501\u578b<\/h4>\n<p>\u7edd\u5927\u591a\u6570&#034;\u5927\u7247 D \u72b6\u6001\u4f46\u65e0\u73af&#034;\u7684\u73b0\u573a&#xff0c;\u90fd\u5c5e\u4e8e\u5355\u70b9\u963b\u585e\u2014\u2014\u6240\u6709\u7b49\u5f85\u6700\u7ec8\u6536\u655b\u5230\u540c\u4e00\u4e2a\u8d44\u6e90\u4e0a\u3002\u5b83\u6709\u4e24\u79cd\u5f62\u6001&#xff0c;\u6839\u56e0\u76f8\u540c&#xff0c;\u89c2\u5bdf\u96be\u5ea6\u4e0d\u540c\u3002<\/p>\n<p>\u76f4\u63a5\u578b&#xff1a;\u7b49\u5f85\u8005\u4e0e\u963b\u585e\u6e90\u4e4b\u95f4\u6ca1\u6709\u9501\u3002<\/p>\n<p>Task A \u2500\u2500waits\u2500\u2500&gt; I\/O<br \/>\nTask B \u2500\u2500waits\u2500\u2500&gt; I\/O<br \/>\nTask C \u2500\u2500waits\u2500\u2500&gt; I\/O<\/p>\n<p>\u6bcf\u4e2a\u4efb\u52a1\u81ea\u5df1\u7684 backtrace \u5c31\u76f4\u63a5\u663e\u793a io_schedule\u3001blk_mq_submit_bio\u3001submit_bio_noacct \u7b49\u4f4d\u7f6e&#xff0c;\u518d\u5f80\u4e0b\u662f\u9a71\u52a8\u7684\u8d85\u65f6\u7b49\u5f85\u3002\u4e00\u773c\u53ef\u89c1&#xff0c;\u65e0\u9700\u8ffd\u8e2a\u3002<\/p>\n<p>\u7ecf\u9501\u578b&#xff1a;\u7b49\u5f85\u8005\u4e0e\u963b\u585e\u6e90\u4e4b\u95f4\u9694\u7740\u4e00\u628a\u9501\u3002<\/p>\n<p>Task B \u2500\u2500waits\u2500\u2500&gt; Lock L \u2500\u2500held by\u2500\u2500&gt; Task A \u2500\u2500waits\u2500\u2500&gt; I\/O<br \/>\nTask C \u2500\u2500waits\u2500\u2500&gt; Lock L                          &#xff08;\u7ec8\u7aef\u8282\u70b9&#xff09;<br \/>\nTask D \u2500\u2500waits\u2500\u2500&gt; Lock L<\/p>\n<p>\u591a\u6570\u4efb\u52a1\u7684 backtrace \u663e\u793a __mutex_lock&#xff0c;\u770b\u8d77\u6765\u50cf\u9501\u7ade\u4e89&#xff1b;\u53ea\u6709\u7ec8\u7aef\u4efb\u52a1 A \u7684 backtrace \u624d\u663e\u793a\u771f\u6b63\u7684\u963b\u585e\u6e90\u3002\u82e5\u53ea\u770b\u524d\u51e0\u4e2a\u4efb\u52a1\u5c31\u4e0b\u7ed3\u8bba&#xff0c;\u4f1a\u8bef\u5224\u4e3a\u9501\u95ee\u9898\u3002<\/p>\n<p>\u8fd9\u4e24\u79cd\u5f62\u6001\u7684\u6839\u56e0\u662f\u540c\u4e00\u4e2a&#xff0c;\u90fd\u662f\u90a3\u4e2a\u7ec8\u7aef\u8d44\u6e90\u3002 \u5dee\u522b\u4ec5\u5728\u4e8e\u7ecf\u9501\u578b\u9700\u8981\u591a\u8d70\u4e00\u8df3&#xff1a;\u8bfb\u9501\u7684 owner&#xff0c;\u627e\u5230\u6301\u6709\u8005&#xff0c;\u518d\u770b\u6301\u6709\u8005\u5728\u7b49\u4ec0\u4e48\u3002<\/p>\n<p>\u9501\u5728\u7ecf\u9501\u578b\u4e2d\u7684\u4f5c\u7528\u662f\u653e\u5927\u5668\u3002 \u539f\u672c\u53ea\u6709\u4e00\u4e2a\u4efb\u52a1\u88ab I\/O \u5361\u4f4f&#xff0c;\u56e0\u4e3a\u5b83\u6301\u6709\u9501&#xff0c;\u51e0\u5341\u4e2a\u4efb\u52a1\u8ddf\u7740\u5361\u4f4f\u3002\u8fd9\u89e3\u91ca\u4e86&#034;\u4e00\u5757\u76d8\u53d8\u6162\u4e3a\u4f55\u4f1a\u5bfc\u81f4\u6574\u673a hang&#034;&#xff0c;\u4e5f\u63d0\u793a\u4fee\u590d\u65b9\u5411\u2014\u2014\u9664\u4e86\u5904\u7406 I\/O \u672c\u8eab&#xff0c;\u8fd8\u5e94\u8bc4\u4f30\u8be5\u9501\u7684\u6301\u6709\u8303\u56f4\u662f\u5426\u8fc7\u5bbd\u3001\u662f\u5426\u6709\u5fc5\u8981\u5728\u6301\u9501\u671f\u95f4\u6267\u884c I\/O\u3002<\/p>\n<p>\u5173\u4e8e\u80fd\u5426\u81ea\u884c\u6062\u590d\u3002 \u8fd9\u7c7b\u5f62\u6001\u4e0b\u4e0d\u5b58\u5728\u4e92\u7b49\u7684\u73af&#xff0c;\u56e0\u6b64\u4e00\u65e6\u7ec8\u7aef\u963b\u585e\u89e3\u9664&#xff0c;\u6574\u6761\u94fe\u4f1a\u81ea\u7136\u74e6\u89e3\u3002\u4f46\u7ec8\u7aef\u963b\u585e\u80fd\u5426\u89e3\u9664\u53d6\u51b3\u4e8e\u90a3\u4e2a\u5916\u90e8\u8d44\u6e90\u672c\u8eab\u2014\u2014\u5b58\u50a8\u8bbe\u5907\u5f7b\u5e95\u5931\u6548\u6216 NFS \u670d\u52a1\u7aef\u6c38\u4e45\u5931\u8054\u65f6&#xff0c;I\/O \u6c38\u4e0d\u5b8c\u6210&#xff0c;\u9501\u6c38\u4e0d\u91ca\u653e&#xff0c;\u7cfb\u7edf\u540c\u6837\u65e0\u6cd5\u6062\u590d\u3002&#034;\u65e0\u73af&#034;\u610f\u5473\u7740\u4e0d\u662f\u6b7b\u9501&#xff0c;\u4e0d\u610f\u5473\u7740\u80fd\u81ea\u6108\u3002<\/p>\n<h4>11.3 RCU Stall&#xff1a;\u673a\u5236\u4e0d\u540c\u7684\u4e00\u7c7b<\/h4>\n<p>RCU stall \u4e0e\u524d\u8ff0\u5f62\u6001\u6709\u672c\u8d28\u533a\u522b&#xff1a;\u5b83\u65e2\u4e0d\u662f\u7b49\u9501&#xff0c;\u4e5f\u4e0d\u662f\u7b49\u8bbe\u5907&#xff0c;\u800c\u662f\u5bbd\u9650\u671f\u65e0\u6cd5\u7ed3\u675f\u3002<\/p>\n<p>rcu: INFO: rcu_preempt self-detected stall on CPU<br \/>\nrcu:     Tasks blocked on rcu_node (5 tasks):<\/p>\n<p>\u67d0\u4efb\u52a1\u957f\u65f6\u95f4\u672a\u9000\u51fa rcu_read_lock() \u4e34\u754c\u533a&#xff0c;\u6216\u67d0 CPU \u957f\u671f\u4e0d\u7ecf\u8fc7\u9759\u6b62\u70b9&#xff0c;\u5bfc\u81f4\u6240\u6709\u4f9d\u8d56 synchronize_rcu \u7684\u64cd\u4f5c\u88ab\u963b\u585e\u3002<\/p>\n<p>\u5b83\u4e0d\u9002\u7528 11.1 \u7684\u7ec8\u7aef\u8282\u70b9\u5206\u6790&#xff0c;\u56e0\u4e3a&#034;\u963b\u585e\u6e90&#034;\u53ef\u80fd\u6839\u672c\u6ca1\u6709\u88ab\u963b\u585e\u2014\u2014\u5b83\u53ef\u80fd\u6b63\u5728\u957f\u5faa\u73af\u91cc\u6267\u884c&#xff0c;\u6216\u8005\u53ea\u662f\u90a3\u9897 CPU \u957f\u671f\u672a\u7ecf\u8fc7\u9759\u6b62\u70b9\u3002\u6cbf\u7b49\u5f85\u94fe\u8ffd\u8e2a\u4e0d\u4f1a\u6307\u5411\u5b83\u3002<\/p>\n<p>\u8fa8\u522b\u65b9\u6cd5&#xff1a; dmesg \u4e2d\u6709 rcu stall \u544a\u8b66&#xff1b;\u6216 backtrace \u663e\u793a\u4efb\u52a1\u5728 rcu_read_lock \u4fdd\u62a4\u533a\u5185\u6267\u884c\u4e86\u7761\u7720\u64cd\u4f5c&#xff08;schedule\u3001wait_event&#xff09;\u2014\u2014\u90a3\u662f RCU \u4f7f\u7528\u8fdd\u89c4\u3002<\/p>\n<h4>11.4 seqlock \u8bfb\u8005\u7a7a\u8f6c&#xff1a;\u4e0d\u8868\u73b0\u4e3a D \u72b6\u6001<\/h4>\n<p>\u8fd9\u662f\u672c\u7ae0\u552f\u4e00\u4e0d\u4ea7\u751f D \u72b6\u6001\u7684\u5f62\u6001&#xff0c;\u4f46\u540c\u6837\u5bb9\u6613\u88ab\u5f53\u6210&#034;\u7cfb\u7edf\u5361\u4f4f&#034;\u3002<\/p>\n<p>\u82e5\u67d0\u5199\u8005\u957f\u65f6\u95f4\u6301\u6709 seqlock&#xff08;seqcount \u505c\u5728\u5947\u6570&#xff09;&#xff0c;\u8bfb\u8005\u4f1a\u6301\u7eed\u91cd\u8bd5\u800c\u7a7a\u8f6c CPU&#xff1a;<\/p>\n<p>symptom : CPU utilization abnormally high<br \/>\n          NO blocked tasks, NO D-state pile-up<br \/>\ncause   : writer holds seqlock too long, readers keep retrying<br \/>\ncheck   : seqcount value is ODD  -&gt;  a writer is active<br \/>\n          then locate that writer via its internal spinlock (\u8def\u7ebf B)<\/p>\n<p>\u7279\u5f81\u662f&#034;CPU \u9ad8\u4f46\u65e0\u8fdb\u7a0b\u963b\u585e&#034;\u2014\u2014\u4e0e\u6b7b\u9501\u5f62\u6001\u76f8\u53cd\u3002\u6309\u6b7b\u9501\u601d\u8def\u53bb\u627e D \u72b6\u6001\u4efb\u52a1\u4f1a\u4e00\u65e0\u6240\u83b7\u3002<\/p>\n<h4>11.5 \u8fa8\u522b\u6d41\u7a0b<\/h4>\n<p>Large number of D-state tasks, but STEP 5 found no cycle<br \/>\n        |<br \/>\n        v<br \/>\nFollow each chain to its TERMINAL node<br \/>\n(the task not waiting on any lock)<br \/>\n        |<br \/>\n        &#043;&#8211; terminal waits on I\/O \/ network \/ completion?<br \/>\n        |     -&gt; single-point blocking (11.2)<br \/>\n        |        direct form : the tasks themselves show io_schedule etc.<br \/>\n        |        via-lock form: only the terminal task shows the real source<br \/>\n        |        root cause &#061; the terminal resource, NOT the lock<br \/>\n        |<br \/>\n        &#043;&#8211; terminal is in a long loop, not blocked?<br \/>\n        |     -&gt; not a deadlock; a slow path holding the lock too long<br \/>\n        |<br \/>\n        &#043;&#8211; dmesg shows rcu stall \/ task sleeps inside rcu_read_lock?<br \/>\n              -&gt; RCU stall (11.3); chain-following does not apply<\/p>\n<p>High CPU but NO blocked tasks<br \/>\n        -&gt; seqcount odd, readers retrying? (11.4)<\/p>\n<p>\u53ea\u6709&#034;\u627e\u5230\u73af&#034;\u662f\u6b7b\u9501\u7684\u80af\u5b9a\u5224\u636e\u3002 \u672c\u7ae0\u5404\u6761\u90fd\u662f\u6392\u9664\u9879\u2014\u2014\u6cbf\u94fe\u8d70\u5230\u7ec8\u7aef\u3001\u770b\u6e05\u7ec8\u7aef\u5728\u7b49\u4ec0\u4e48&#xff0c;\u82e5\u7ec8\u7aef\u7b49\u7684\u662f\u5916\u90e8\u8d44\u6e90\u800c\u975e\u53e6\u4e00\u628a\u9501&#xff0c;\u90a3\u4e48\u95ee\u9898\u4e0d\u5728\u9501&#xff0c;\u800c\u5728\u90a3\u4e2a\u8d44\u6e90\u3002<\/p>\n<hr \/>\n<h3>\u5341\u4e8c\u3001\u5c0f\u7ed3<\/h3>\n<p>\u9501\u662f\u5185\u6838\u5e76\u53d1\u7684\u54bd\u5589&#xff0c;\u6b7b\u9501\u662f\u6253\u5728\u54bd\u5589\u4e0a\u7684\u7ed3\u3002vmcore \u662f\u6253\u7ed3\u4e4b\u540e\u7684\u9759\u6b62\u753b\u9762\u2014\u2014\u8bfb\u5b83\u7684\u65b9\u6cd5\u662f\u6cbf\u7ed3\u6784\u8ffd\u94fe\u8def&#xff0c;\u4e0d\u662f\u731c\u3002<\/p>\n<p>\u5165\u53e3&#xff08;\u7b2c\u4e00\u7ae0&#xff09;&#xff1a; \u7b2c\u4e94\u7bc7\u56de\u7b54&#034;\u8fd9\u4e2a\u503c\u4e3a\u4ec0\u4e48\u662f\u9519\u7684&#034;&#xff0c;\u7b2c\u516d\u7bc7\u56de\u7b54&#034;\u8fd9\u4ef6\u4e8b\u8ddf\u8c01\u6709\u5173&#034;&#xff0c;\u672c\u7bc7\u56de\u7b54**\u201c\u4ed6\u4eec\u5361\u5728\u8c01\u624b\u91cc\u201d**\u3002\u5f53 foreach UN bt \u7684\u963b\u585e\u70b9\u6536\u655b\u5230\u540c\u6b65\u539f\u8bed\u4e0a\u65f6&#xff0c;\u8f6c\u5165\u672c\u7bc7\u3002<\/p>\n<p>\u5e95\u5c42\u903b\u8f91&#xff08;\u7b2c\u4e8c\u7ae0&#xff09;&#xff1a; \u6b7b\u9501\u5206\u6790\u7684\u672c\u8d28\u662f\u91cd\u5efa\u6709\u5411\u56fe\u5e76\u627e\u73af\u3002\u56fe\u91cc\u53ea\u6709\u4e24\u7c7b\u8fb9\u2014\u2014\u7b49\u5f85\u8fb9&#xff08;task &#8211;waits&#8211;&gt; lock&#xff09;\u4ece backtrace \u5f97\u5230&#xff0c;\u4efb\u4f55\u9501\u90fd\u4e00\u6837&#xff1b;\u6301\u6709\u8fb9&#xff08;lock &#8211;held by&#8211;&gt; task&#xff09;\u53ea\u80fd\u4ece\u9501\u7ed3\u6784\u8bfb&#xff0c;\u8fd9\u624d\u662f\u5168\u90e8\u56f0\u96be\u6240\u5728\u3002owner \u5b57\u6bb5\u4e4b\u6240\u4ee5\u91cd\u8981&#xff0c;\u6b63\u56e0\u4e3a\u5b83\u662f\u6301\u6709\u8fb9\u7684\u552f\u4e00\u76f4\u63a5\u6765\u6e90&#xff1b;val \u4e4b\u6240\u4ee5\u8981\u9010\u4f4d\u62c6&#xff0c;\u56e0\u4e3a\u5b83\u662f\u65e0 owner \u7684\u9501\u4e0a\u552f\u4e00\u80fd\u6324\u51fa\u4fe1\u606f\u7684\u5730\u65b9\u3002<\/p>\n<p>&#034;\u80fd\u5426\u7761\u7720&#034;\u8fd9\u4e2a\u5206\u7c7b\u7ef4\u5ea6\u662f\u4ece\u53ef\u8c03\u8bd5\u6027\u5012\u63a8\u51fa\u6765\u7684&#xff1a;\u80fd\u7761 \u2192 \u5fc5\u987b\u6709\u7b49\u5f85\u961f\u5217 \u2192 \u6709\u94fe\u8868\u53ef\u8bfb\u3001\u503c\u5f97\u8bb0 owner&#xff1b;\u4e0d\u80fd\u7761 \u2192 \u539f\u5730\u81ea\u65cb \u2192 \u65e0\u9700\u961f\u5217\u3001\u8bb0 owner \u4e0d\u5212\u7b97\u3002\u7406\u89e3\u8fd9\u6761\u63a8\u5bfc&#xff0c;\u9047\u5230\u672c\u7bc7\u6ca1\u8986\u76d6\u7684\u9501\u7c7b\u578b\u4e5f\u80fd\u5224\u65ad\u8be5\u5f80\u54ea\u67e5\u3002<\/p>\n<p>\u4e24\u6761\u8def\u7ebf&#xff08;\u7b2c\u4e09\u3001\u56db\u7ae0&#xff09;&#xff1a;<\/p>\n<table>\n<tr>\u8def\u7ebf\u9002\u7528\u9501\u6838\u5fc3\u52a8\u4f5c\u6210\u672c<\/tr>\n<tbody>\n<tr>\n<td align=\"left\">\u8def\u7ebf A<\/td>\n<td align=\"left\">mutex \/ rw_semaphore \/ rt_mutex<\/td>\n<td align=\"left\">owner &amp; ~0x7 \u5f97\u6301\u6709\u8005&#xff1b;list \u904d\u5386 wait_list<\/td>\n<td align=\"left\">\u5206\u949f\u7ea7<\/td>\n<\/tr>\n<tr>\n<td align=\"left\">\u8def\u7ebf B<\/td>\n<td align=\"left\">spinlock_t \/ rwlock_t<\/td>\n<td align=\"left\">val \u5224\u5b9a\u662f\u5426\u88ab\u6301\u6709&#xff1b;\u591a CPU backtrace \u63a8\u65ad\u6301\u6709\u8005<\/td>\n<td align=\"left\">\u5c0f\u65f6\u7ea7&#xff0c;\u4e14\u53ef\u80fd\u5931\u8d25<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u8def\u7ebf A \u6709\u4e09\u5904\u4f1a\u5931\u7075&#xff1a;rwsem \u88ab\u8bfb\u8005\u6301\u6709\u3001semaphore \u65e0 owner\u3001\u9501\u7ed3\u6784\u5df2\u635f\u574f\u3002\u8f6c\u5165\u8def\u7ebf B \u4e4b\u524d\u5e94\u5148\u6267\u884c\u8def\u7ebf\u5224\u5b9a\u2014\u2014struct &lt;lock_type&gt; \u770b\u7ed3\u6784\u91cc\u6709\u6ca1\u6709\u6301\u6709\u8005\u5b57\u6bb5&#xff0c;\u51e0\u79d2\u949f\u7684\u68c0\u67e5\u53ef\u80fd\u7701\u4e0b\u6570\u5c0f\u65f6&#xff1b;\u8be5\u5224\u5b9a\u540c\u6837\u9002\u7528\u4e8e\u9a71\u52a8\u81ea\u5b9a\u4e49\u539f\u8bed&#xff0c;\u5224\u636e\u4e3a\u5b57\u6bb5\u7684\u7c7b\u578b\u4e0e\u8bed\u4e49&#xff08;struct task_struct * \u6307\u9488\u3001PID \u6216 CPU \u7f16\u53f7\u7b49&#xff09;&#xff0c;\u800c\u975e\u5b57\u6bb5\u540d\u79f0\u3002<\/p>\n<p>\u4e09\u4e2a\u6848\u4f8b\u7684\u5206\u5de5&#xff1a;\u6784\u9020\u6848\u4f8b\u6559\u65b9\u6cd5&#xff0c;\u771f\u5b9e\u6848\u4f8b\u6559\u8fb9\u754c\u3002 \u7b2c\u4e03\u7ae0\u8d70\u901a\u8def\u7ebf A \u7684\u5b8c\u6574\u516d\u6b65&#xff1b;\u7b2c\u516b\u7ae0\u53ea\u5c55\u5f00 rwsem \u76f8\u5bf9\u7b2c\u4e03\u7ae0\u7684\u4e09\u5904\u64cd\u4f5c\u5dee\u5f02&#xff08;\u5148\u8bfb count \u5b9a\u6027\u3001\u904d\u5386\u65f6\u987b\u8bfb waiter type\u3001\u53d6\u6301\u6709\u8fb9\u662f\u4e24\u6b65\u800c\u975e\u4e00\u6b65&#xff09;&#xff1b;\u7b2c\u4e5d\u7ae0\u662f\u771f\u5b9e\u751f\u4ea7\u73b0\u573a&#xff0c;\u7528\u5b9e\u6d4b\u6570\u636e\u5b8c\u6210\u4e86\u7b2c\u516d\u7bc7\u7559\u4e0b\u7684\u9a8c\u8bc1\u2014\u2014dis -l \u7ed9\u51fa\u7684 qspinlock.h:86 \u786e\u8bc1\u4e86\u5361\u70b9\u4f4d\u4e8e spin_lock() \u7684\u5feb\u901f\u8def\u5f84\u4e0a&#xff1b;\u800c\u9501\u7684\u8eab\u4efd\u5219\u7531 struct ext4_sb_info -o \u5b9e\u6d4b\u786e\u5b9a\u4e3a s_md_lock\u2014\u2014\u884c\u53f7\u4fe1\u606f\u56e0\u5185\u8054\u5c55\u5f00\u5b58\u5728\u6620\u5c04\u504f\u5dee&#xff0c;\u4e00\u5ea6\u6307\u5411 ext4_lock_group()&#xff0c;\u5b9e\u6d4b\u7ea0\u6b63\u4e86\u8fd9\u4e00\u8bef\u5224\u3002<\/p>\n<p>\u7b2c\u4e5d\u7ae0\u540c\u65f6\u5c55\u793a\u4e86\u8def\u7ebf B \u7684\u4e09\u7c7b\u5931\u6548\u8fb9\u754c&#xff1a;crash \u7684 ARM64 unwinder \u8de8\u4e0d\u8fc7 IRQ \u6808\u8fb9\u754c&#xff0c;\u5373\u4f7f\u5bc4\u5b58\u5668\u9f50\u5168\u4e5f\u770b\u4e0d\u5230\u4e2d\u65ad\u524d\u7684\u6267\u884c\u8def\u5f84&#xff1b;failed to stop secondary CPUs \u6253\u5370\u7684\u662f\u5019\u9009\u540d\u5355\u800c\u975e\u5931\u8d25\u540d\u5355&#xff0c;\u636e\u5176\u63a8\u65ad\u4f1a\u8bef\u5224&#xff1b;\u53cd\u6c47\u7f16\u5668\u4e0d\u8bc6\u522b ARMv8.1 \u7684 LSE \u6307\u4ee4&#xff0c;\u8f93\u51fa .inst undefined \u6613\u88ab\u8bef\u8ba4\u4e3a\u6570\u636e\u635f\u574f\u3002\u4e09\u8005\u90fd\u4e0d\u662f\u6570\u636e\u7f3a\u5931&#xff0c;\u800c\u662f\u5de5\u5177\u80fd\u529b\u7684\u8fb9\u754c\u3002<\/p>\n<p>\u4e09\u6761\u8d2f\u7a7f\u5168\u7bc7\u7684\u9650\u5b9a&#xff1a;<\/p>\n<p>\u7b2c\u4e00&#xff0c;\u6240\u6709\u4f4d\u57df\u4e0e\u5e38\u91cf\u90fd\u662f\u67d0\u7ec4\u4e09\u8f74\u53d6\u503c\u4e0b\u7684\u5b9e\u4f8b\u3002qspinlock \u7684 pending \u5bbd\u5ea6\u968f NR_CPUS \u53d8\u3001rwsem \u7684 count \u7f16\u7801\u5728 5.3 \u524d\u540e\u5b8c\u5168\u4e0d\u540c\u3001spinlock \u6709\u65e0 owner \u53d6\u51b3\u4e8e CONFIG_DEBUG_SPINLOCK\u2014\u2014\u52a8\u624b\u524d\u5148 struct &lt;type&gt; \u5b9e\u6d4b\u3002<\/p>\n<p>\u7b2c\u4e8c&#xff0c;\u5bf9\u53ef\u590d\u73b0\u7684\u95ee\u9898&#xff0c;\u5e94\u4f18\u5148\u6539\u53d8\u91c7\u96c6\u6761\u4ef6\u800c\u975e\u5728\u73b0\u6709 vmcore \u4e0a\u5f3a\u63a8\u3002\u5f00\u542f CONFIG_DEBUG_SPINLOCK \u540e raw_spinlock \u5e26\u4e0a owner \u5b57\u6bb5&#xff0c;\u5206\u6790\u8def\u5f84\u7531\u8def\u7ebf B \u8f6c\u4e3a\u8def\u7ebf A&#xff0c;\u6570\u5c0f\u65f6\u7684\u4ea4\u53c9\u63a8\u65ad\u53d8\u4e3a\u4e00\u6b21\u76f4\u8bfb&#xff1b;ARM64 \u4e0a\u589e\u52a0 irqchip.gicv3_pseudo_nmi&#061;1 \u53ef\u83b7\u5f97 hard lockup \u68c0\u6d4b\u80fd\u529b\u3002\u4e8c\u8005\u7684\u6210\u672c\u5747\u4f4e\u4e8e\u4ea4\u53c9\u63a8\u65ad\u3002<\/p>\n<p>\u6b64\u5916&#xff0c;\u5e26 debuginfo \u7684 vmlinux \u5bf9\u9501\u5206\u6790\u4ef7\u503c\u6781\u9ad8\u3002\u7b2c\u4e5d\u7ae0\u7684\u7ed3\u8bba\u5b8c\u5168\u5efa\u7acb\u5728 dis -l \u8f93\u51fa\u7684\u6e90\u7801\u884c\u53f7\u4e0a\u2014\u2014\u82e5\u53ea\u6709\u88f8\u7b26\u53f7&#xff0c;.inst undefined \u52a0\u51e0\u6761 ldr\/add \u5f88\u96be\u88ab\u8ba4\u5b9a\u4e3a\u52a0\u9501\u8def\u5f84\u3002<\/p>\n<p>\u7b2c\u4e09&#xff0c;\u8ffd\u4e0d\u51fa\u73af\u65f6\u4e0d\u8981\u5f3a\u884c\u8ba4\u5b9a\u6b7b\u9501\u3002\u6b64\u65f6\u7684\u6b63\u786e\u52a8\u4f5c\u662f\u6cbf\u6bcf\u6761\u7b49\u5f85\u94fe\u8d70\u5230\u7ec8\u7aef\u8282\u70b9\u2014\u2014\u90a3\u4e2a\u4e0d\u518d\u7b49\u5f85\u4efb\u4f55\u9501\u7684\u4efb\u52a1\u2014\u2014\u518d\u770b\u5b83\u7a76\u7adf\u5728\u7b49\u4ec0\u4e48\u3002\u6839\u56e0\u7531\u7ec8\u7aef\u8282\u70b9\u7684\u7b49\u5f85\u5bf9\u8c61\u51b3\u5b9a&#xff1b;\u7b49\u5f85\u8005\u4e0e\u7ec8\u7aef\u4e4b\u95f4\u9694\u6ca1\u9694\u9501&#xff0c;\u53ea\u5f71\u54cd\u8bca\u65ad\u8981\u8d70\u51e0\u8df3&#xff0c;\u4e0d\u6539\u53d8\u6839\u56e0\u3002<\/p>\n<p>\u7531\u6b64&#xff0c;\u7b2c\u5341\u4e00\u7ae0\u7684\u5f62\u6001\u53ef\u5f52\u4e3a\u4e24\u7c7b&#xff1a;\u5355\u70b9\u963b\u585e&#xff08;\u7ec8\u7aef\u5728\u7b49 I\/O\u3001\u7f51\u7edc\u6216 completion&#xff0c;\u5176&#034;\u76f4\u63a5\u578b&#034;\u4e0e&#034;\u7ecf\u9501\u578b&#034;\u6839\u56e0\u76f8\u540c&#xff0c;\u9501\u5728\u7ecf\u9501\u578b\u4e2d\u53ea\u8d77\u653e\u5927\u4f5c\u7528&#xff09;&#xff0c;\u4ee5\u53ca\u673a\u5236\u72ec\u7acb\u7684\u4e24\u79cd\u2014\u2014RCU stall \u4e0d\u9002\u7528\u94fe\u6761\u8ffd\u8e2a&#xff0c;seqlock \u8bfb\u8005\u7a7a\u8f6c\u751a\u81f3\u4e0d\u8868\u73b0\u4e3a D \u72b6\u6001\u3002\u9700\u8981\u6ce8\u610f&#xff0c;\u65e0\u73af\u53ea\u8bf4\u660e\u4e0d\u662f\u6b7b\u9501&#xff0c;\u4e0d\u610f\u5473\u7740\u7cfb\u7edf\u80fd\u81ea\u6108&#xff1a;\u7ec8\u7aef\u963b\u585e\u82e5\u6765\u81ea\u6c38\u4e45\u5931\u6548\u7684\u5916\u90e8\u8d44\u6e90&#xff0c;\u94fe\u6761\u540c\u6837\u4e0d\u4f1a\u74e6\u89e3\u3002<\/p>\n<hr \/>\n<p>\u4e0b\u4e00\u7bc7\u300a\u5e96\u5203\u6240\u53ca\u300b\u8fdb\u5165\u9a71\u52a8\u4e0e\u6a21\u5757\u5d29\u6e83\u7684\u9886\u57df&#xff1a;\u5f53\u5d29\u6e83\u6839\u6e90\u4e0d\u5728\u4e3b\u7ebf\u5185\u6838&#xff0c;\u800c\u5728\u90a3\u4e9b\u672a\u5fc5\u62ff\u5f97\u5230\u6e90\u7801\u7684 .ko \u91cc\u2014\u2014\u5982\u4f55\u5728 vmcore \u4e2d\u628a\u5b83\u4eec\u62ce\u51fa\u6765&#xff0c;\u662f\u7b2c\u516b\u7bc7\u8981\u89e3\u7684\u9898\u3002<\/p>\n<hr \/>\n","protected":false},"excerpt":{"rendered":"<p>\u5e96\u4e01\u89e3 vmCore \u5341\u7bc7 \u00b7 \u7b2c\u4e03\u7bc7 \u00b7 \u7ed3\u5589\u4e4b\u5904&#xff1a;\u9501\u4e0e\u6b7b\u9501\u7684\u89e3\u5256\u5e96\u4e01\u66f0&#xff1a;\u6280\u7ecf\u80af\u7dae\u4e4b\u672a\u5c1d&#xff0c;\u800c\u51b5\u5927\u8ef1\u4e4e\u3002<br \/>\n\u9501\u8005&#xff0c;\u80af\u7dae\u4e5f&#xff1b;\u6b7b\u9501\u8005&#xff0c;\u80af\u7dae\u76f8\u7f20\u800c\u5200\u4e0d\u5f97\u5165\u4e5f\u3002<br \/>\nvmcore \u8005&#xff0c;\u7f20\u7ed3\u65e2\u6210\u4e4b\u5b9a\u5f71\u2014\u2014\u4f9d\u4e4e\u5929\u7406&#xff0c;\u6279\u5927\u90e4&#xff0c;\u5bfc\u5927\u7abe\u3002\u76ee\u5f55<br \/>\n\u4e00\u3001\u4ece call trace \u5230\u9501&#xff1a;\u672c\u7bc7\u7684\u4f4d\u7f6e<br \/>\n1.1 \u7b2c\u516d\u7bc7\u7559\u4e0b\u7684\u90a3\u4e2a\u504f\u79fb1.2 \u4ec0\u4e48\u6837\u7684\u73b0\u573a\u9700\u8981\u89e3\u5256\u95011.3 \u6b7b\u9501\u4e0e<\/p>\n","protected":false},"author":2,"featured_media":96085,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[10187,58,43,44,176],"topic":[],"class_list":["post-96086","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-server","tag-codingplan","tag-linux","tag-43","tag-44","tag-176"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u5e96\u4e01\u89e3 vmCore \u00b7 \u7b2c\u4e03\u7bc7 \u00b7 \u7ed3\u5589\u4e4b\u5904\uff1a\u9501\u4e0e\u6b7b\u9501\u7684\u89e3\u5256 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wsisp.com\/helps\/96086.html\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u5e96\u4e01\u89e3 vmCore \u00b7 \u7b2c\u4e03\u7bc7 \u00b7 \u7ed3\u5589\u4e4b\u5904\uff1a\u9501\u4e0e\u6b7b\u9501\u7684\u89e3\u5256 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"og:description\" content=\"\u5e96\u4e01\u89e3 vmCore \u5341\u7bc7 \u00b7 \u7b2c\u4e03\u7bc7 \u00b7 \u7ed3\u5589\u4e4b\u5904&#xff1a;\u9501\u4e0e\u6b7b\u9501\u7684\u89e3\u5256\u5e96\u4e01\u66f0&#xff1a;\u6280\u7ecf\u80af\u7dae\u4e4b\u672a\u5c1d&#xff0c;\u800c\u51b5\u5927\u8ef1\u4e4e\u3002 \u9501\u8005&#xff0c;\u80af\u7dae\u4e5f&#xff1b;\u6b7b\u9501\u8005&#xff0c;\u80af\u7dae\u76f8\u7f20\u800c\u5200\u4e0d\u5f97\u5165\u4e5f\u3002 vmcore \u8005&#xff0c;\u7f20\u7ed3\u65e2\u6210\u4e4b\u5b9a\u5f71\u2014\u2014\u4f9d\u4e4e\u5929\u7406&#xff0c;\u6279\u5927\u90e4&#xff0c;\u5bfc\u5927\u7abe\u3002\u76ee\u5f55 \u4e00\u3001\u4ece call trace \u5230\u9501&#xff1a;\u672c\u7bc7\u7684\u4f4d\u7f6e 1.1 \u7b2c\u516d\u7bc7\u7559\u4e0b\u7684\u90a3\u4e2a\u504f\u79fb1.2 \u4ec0\u4e48\u6837\u7684\u73b0\u573a\u9700\u8981\u89e3\u5256\u95011.3 \u6b7b\u9501\u4e0e\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wsisp.com\/helps\/96086.html\" \/>\n<meta property=\"og:site_name\" content=\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-27T04:56:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260827045631-6a8fc37f5548a.png\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"34 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/96086.html\",\"url\":\"https:\/\/www.wsisp.com\/helps\/96086.html\",\"name\":\"\u5e96\u4e01\u89e3 vmCore \u00b7 \u7b2c\u4e03\u7bc7 \u00b7 \u7ed3\u5589\u4e4b\u5904\uff1a\u9501\u4e0e\u6b7b\u9501\u7684\u89e3\u5256 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"isPartOf\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\"},\"datePublished\":\"2026-08-27T04:56:33+00:00\",\"dateModified\":\"2026-08-27T04:56:33+00:00\",\"author\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/96086.html#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.wsisp.com\/helps\/96086.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/96086.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.wsisp.com\/helps\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u5e96\u4e01\u89e3 vmCore \u00b7 \u7b2c\u4e03\u7bc7 \u00b7 \u7ed3\u5589\u4e4b\u5904\uff1a\u9501\u4e0e\u6b7b\u9501\u7684\u89e3\u5256\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\",\"url\":\"https:\/\/www.wsisp.com\/helps\/\",\"name\":\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"description\":\"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"contentUrl\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/wp.wsisp.com\"],\"url\":\"https:\/\/www.wsisp.com\/helps\/author\/admin\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u5e96\u4e01\u89e3 vmCore \u00b7 \u7b2c\u4e03\u7bc7 \u00b7 \u7ed3\u5589\u4e4b\u5904\uff1a\u9501\u4e0e\u6b7b\u9501\u7684\u89e3\u5256 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wsisp.com\/helps\/96086.html","og_locale":"zh_CN","og_type":"article","og_title":"\u5e96\u4e01\u89e3 vmCore \u00b7 \u7b2c\u4e03\u7bc7 \u00b7 \u7ed3\u5589\u4e4b\u5904\uff1a\u9501\u4e0e\u6b7b\u9501\u7684\u89e3\u5256 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","og_description":"\u5e96\u4e01\u89e3 vmCore \u5341\u7bc7 \u00b7 \u7b2c\u4e03\u7bc7 \u00b7 \u7ed3\u5589\u4e4b\u5904&#xff1a;\u9501\u4e0e\u6b7b\u9501\u7684\u89e3\u5256\u5e96\u4e01\u66f0&#xff1a;\u6280\u7ecf\u80af\u7dae\u4e4b\u672a\u5c1d&#xff0c;\u800c\u51b5\u5927\u8ef1\u4e4e\u3002 \u9501\u8005&#xff0c;\u80af\u7dae\u4e5f&#xff1b;\u6b7b\u9501\u8005&#xff0c;\u80af\u7dae\u76f8\u7f20\u800c\u5200\u4e0d\u5f97\u5165\u4e5f\u3002 vmcore \u8005&#xff0c;\u7f20\u7ed3\u65e2\u6210\u4e4b\u5b9a\u5f71\u2014\u2014\u4f9d\u4e4e\u5929\u7406&#xff0c;\u6279\u5927\u90e4&#xff0c;\u5bfc\u5927\u7abe\u3002\u76ee\u5f55 \u4e00\u3001\u4ece call trace \u5230\u9501&#xff1a;\u672c\u7bc7\u7684\u4f4d\u7f6e 1.1 \u7b2c\u516d\u7bc7\u7559\u4e0b\u7684\u90a3\u4e2a\u504f\u79fb1.2 \u4ec0\u4e48\u6837\u7684\u73b0\u573a\u9700\u8981\u89e3\u5256\u95011.3 \u6b7b\u9501\u4e0e","og_url":"https:\/\/www.wsisp.com\/helps\/96086.html","og_site_name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","article_published_time":"2026-08-27T04:56:33+00:00","og_image":[{"url":"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/08\/20260827045631-6a8fc37f5548a.png"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"admin","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"34 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wsisp.com\/helps\/96086.html","url":"https:\/\/www.wsisp.com\/helps\/96086.html","name":"\u5e96\u4e01\u89e3 vmCore \u00b7 \u7b2c\u4e03\u7bc7 \u00b7 \u7ed3\u5589\u4e4b\u5904\uff1a\u9501\u4e0e\u6b7b\u9501\u7684\u89e3\u5256 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","isPartOf":{"@id":"https:\/\/www.wsisp.com\/helps\/#website"},"datePublished":"2026-08-27T04:56:33+00:00","dateModified":"2026-08-27T04:56:33+00:00","author":{"@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41"},"breadcrumb":{"@id":"https:\/\/www.wsisp.com\/helps\/96086.html#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wsisp.com\/helps\/96086.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wsisp.com\/helps\/96086.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.wsisp.com\/helps"},{"@type":"ListItem","position":2,"name":"\u5e96\u4e01\u89e3 vmCore \u00b7 \u7b2c\u4e03\u7bc7 \u00b7 \u7ed3\u5589\u4e4b\u5904\uff1a\u9501\u4e0e\u6b7b\u9501\u7684\u89e3\u5256"}]},{"@type":"WebSite","@id":"https:\/\/www.wsisp.com\/helps\/#website","url":"https:\/\/www.wsisp.com\/helps\/","name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","description":"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41","name":"admin","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/","url":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","contentUrl":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","caption":"admin"},"sameAs":["http:\/\/wp.wsisp.com"],"url":"https:\/\/www.wsisp.com\/helps\/author\/admin"}]}},"_links":{"self":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/96086","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/comments?post=96086"}],"version-history":[{"count":0,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/96086\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media\/96085"}],"wp:attachment":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media?parent=96086"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/categories?post=96086"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/tags?post=96086"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/topic?post=96086"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}