ppp_xmit_process() already locks the xmit path. If HARD_TX_LOCK() tries
to hold the _xmit_lock we can get lock inversion.
[ 973.726130] ======================================================
[ 973.727311] [ INFO: possible circular locking dependency detected ]
[ 973.728546] 4.8.0-rc2 #1 Tainted: G O
[ 973.728986] -------------------------------------------------------
[ 973.728986] accel-pppd/1806 is trying to acquire lock:
[ 973.728986] (&qdisc_xmit_lock_key){+.-...}, at: [<
ffffffff8146f6fe>] sch_direct_xmit+0x8d/0x221
[ 973.728986]
[ 973.728986] but task is already holding lock:
[ 973.728986] (l2tp_sock){+.-...}, at: [<
ffffffffa0202c4a>] l2tp_xmit_skb+0x1e8/0x5d7 [l2tp_core]
[ 973.728986]
[ 973.728986] which lock already depends on the new lock.
[ 973.728986]
[ 973.728986]
[ 973.728986] the existing dependency chain (in reverse order) is:
[ 973.728986]
-> #3 (l2tp_sock){+.-...}:
[ 973.728986] [<
ffffffff810b3130>] lock_acquire+0x150/0x217
[ 973.728986] [<
ffffffff815752f4>] _raw_spin_lock+0x2d/0x3c
[ 973.728986] [<
ffffffffa0202c4a>] l2tp_xmit_skb+0x1e8/0x5d7 [l2tp_core]
[ 973.728986] [<
ffffffffa01b2466>] pppol2tp_xmit+0x1f2/0x25e [l2tp_ppp]
[ 973.728986] [<
ffffffffa0184f59>] ppp_channel_push+0xb5/0x14a [ppp_generic]
[ 973.728986] [<
ffffffffa01853ed>] ppp_write+0x104/0x11c [ppp_generic]
[ 973.728986] [<
ffffffff811b2ec6>] __vfs_write+0x56/0x120
[ 973.728986] [<
ffffffff811b3f4c>] vfs_write+0xbd/0x11b
[ 973.728986] [<
ffffffff811b4cb2>] SyS_write+0x5e/0x96
[ 973.728986] [<
ffffffff81575ba5>] entry_SYSCALL_64_fastpath+0x18/0xa8
[ 973.728986]
-> #2 (&(&pch->downl)->rlock){+.-...}:
[ 973.728986] [<
ffffffff810b3130>] lock_acquire+0x150/0x217
[ 973.728986] [<
ffffffff81575334>] _raw_spin_lock_bh+0x31/0x40
[ 973.728986] [<
ffffffffa01808e2>] ppp_push+0xa7/0x82d [ppp_generic]
[ 973.728986] [<
ffffffffa0184675>] __ppp_xmit_process+0x48/0x877 [ppp_generic]
[ 973.728986] [<
ffffffffa018505b>] ppp_xmit_process+0x4b/0xaf [ppp_generic]
[ 973.728986] [<
ffffffffa01853f7>] ppp_write+0x10e/0x11c [ppp_generic]
[ 973.728986] [<
ffffffff811b2ec6>] __vfs_write+0x56/0x120
[ 973.728986] [<
ffffffff811b3f4c>] vfs_write+0xbd/0x11b
[ 973.728986] [<
ffffffff811b4cb2>] SyS_write+0x5e/0x96
[ 973.728986] [<
ffffffff81575ba5>] entry_SYSCALL_64_fastpath+0x18/0xa8
[ 973.728986]
-> #1 (&(&ppp->wlock)->rlock){+.-...}:
[ 973.728986] [<
ffffffff810b3130>] lock_acquire+0x150/0x217
[ 973.728986] [<
ffffffff81575334>] _raw_spin_lock_bh+0x31/0x40
[ 973.728986] [<
ffffffffa0184654>] __ppp_xmit_process+0x27/0x877 [ppp_generic]
[ 973.728986] [<
ffffffffa018505b>] ppp_xmit_process+0x4b/0xaf [ppp_generic]
[ 973.728986] [<
ffffffffa01852da>] ppp_start_xmit+0x21b/0x22a [ppp_generic]
[ 973.728986] [<
ffffffff8143f767>] dev_hard_start_xmit+0x1a9/0x43d
[ 973.728986] [<
ffffffff8146f747>] sch_direct_xmit+0xd6/0x221
[ 973.728986] [<
ffffffff814401e4>] __dev_queue_xmit+0x62a/0x912
[ 973.728986] [<
ffffffff814404d7>] dev_queue_xmit+0xb/0xd
[ 973.728986] [<
ffffffff81449978>] neigh_direct_output+0xc/0xe
[ 973.728986] [<
ffffffff8150e62b>] ip6_finish_output2+0x5a9/0x623
[ 973.728986] [<
ffffffff81512128>] ip6_output+0x15e/0x16a
[ 973.728986] [<
ffffffff8153ef86>] dst_output+0x76/0x7f
[ 973.728986] [<
ffffffff8153f737>] mld_sendpack+0x335/0x404
[ 973.728986] [<
ffffffff81541c61>] mld_send_initial_cr.part.21+0x99/0xa2
[ 973.728986] [<
ffffffff8154441d>] ipv6_mc_dad_complete+0x42/0x71
[ 973.728986] [<
ffffffff8151c4bd>] addrconf_dad_completed+0x1cf/0x2ea
[ 973.728986] [<
ffffffff8151e4fa>] addrconf_dad_work+0x453/0x520
[ 973.728986] [<
ffffffff8107a393>] process_one_work+0x365/0x6f0
[ 973.728986] [<
ffffffff8107aecd>] worker_thread+0x2de/0x421
[ 973.728986] [<
ffffffff810816fb>] kthread+0x121/0x130
[ 973.728986] [<
ffffffff81575dbf>] ret_from_fork+0x1f/0x40
[ 973.728986]
-> #0 (&qdisc_xmit_lock_key){+.-...}:
[ 973.728986] [<
ffffffff810b28d6>] __lock_acquire+0x1118/0x1483
[ 973.728986] [<
ffffffff810b3130>] lock_acquire+0x150/0x217
[ 973.728986] [<
ffffffff815752f4>] _raw_spin_lock+0x2d/0x3c
[ 973.728986] [<
ffffffff8146f6fe>] sch_direct_xmit+0x8d/0x221
[ 973.728986] [<
ffffffff814401e4>] __dev_queue_xmit+0x62a/0x912
[ 973.728986] [<
ffffffff814404d7>] dev_queue_xmit+0xb/0xd
[ 973.728986] [<
ffffffff81449978>] neigh_direct_output+0xc/0xe
[ 973.728986] [<
ffffffff81487811>] ip_finish_output2+0x5db/0x609
[ 973.728986] [<
ffffffff81489590>] ip_finish_output+0x152/0x15e
[ 973.728986] [<
ffffffff8148a0d4>] ip_output+0x8c/0x96
[ 973.728986] [<
ffffffff81489652>] ip_local_out+0x41/0x4a
[ 973.728986] [<
ffffffff81489e7d>] ip_queue_xmit+0x5a5/0x609
[ 973.728986] [<
ffffffffa0202fe4>] l2tp_xmit_skb+0x582/0x5d7 [l2tp_core]
[ 973.728986] [<
ffffffffa01b2466>] pppol2tp_xmit+0x1f2/0x25e [l2tp_ppp]
[ 973.728986] [<
ffffffffa0184f59>] ppp_channel_push+0xb5/0x14a [ppp_generic]
[ 973.728986] [<
ffffffffa01853ed>] ppp_write+0x104/0x11c [ppp_generic]
[ 973.728986] [<
ffffffff811b2ec6>] __vfs_write+0x56/0x120
[ 973.728986] [<
ffffffff811b3f4c>] vfs_write+0xbd/0x11b
[ 973.728986] [<
ffffffff811b4cb2>] SyS_write+0x5e/0x96
[ 973.728986] [<
ffffffff81575ba5>] entry_SYSCALL_64_fastpath+0x18/0xa8
[ 973.728986]
[ 973.728986] other info that might help us debug this:
[ 973.728986]
[ 973.728986] Chain exists of:
&qdisc_xmit_lock_key --> &(&pch->downl)->rlock --> l2tp_sock
[ 973.728986] Possible unsafe locking scenario:
[ 973.728986]
[ 973.728986] CPU0 CPU1
[ 973.728986] ---- ----
[ 973.728986] lock(l2tp_sock);
[ 973.728986] lock(&(&pch->downl)->rlock);
[ 973.728986] lock(l2tp_sock);
[ 973.728986] lock(&qdisc_xmit_lock_key);
[ 973.728986]
[ 973.728986] *** DEADLOCK ***
[ 973.728986]
[ 973.728986] 6 locks held by accel-pppd/1806:
[ 973.728986] #0: (&(&pch->downl)->rlock){+.-...}, at: [<
ffffffffa0184efa>] ppp_channel_push+0x56/0x14a [ppp_generic]
[ 973.728986] #1: (l2tp_sock){+.-...}, at: [<
ffffffffa0202c4a>] l2tp_xmit_skb+0x1e8/0x5d7 [l2tp_core]
[ 973.728986] #2: (rcu_read_lock){......}, at: [<
ffffffff81486981>] rcu_lock_acquire+0x0/0x20
[ 973.728986] #3: (rcu_read_lock_bh){......}, at: [<
ffffffff81486981>] rcu_lock_acquire+0x0/0x20
[ 973.728986] #4: (rcu_read_lock_bh){......}, at: [<
ffffffff814340e3>] rcu_lock_acquire+0x0/0x20
[ 973.728986] #5: (dev->qdisc_running_key ?: &qdisc_running_key#2){+.....}, at: [<
ffffffff8144011e>] __dev_queue_xmit+0x564/0x912
[ 973.728986]
[ 973.728986] stack backtrace:
[ 973.728986] CPU: 2 PID: 1806 Comm: accel-pppd Tainted: G O 4.8.0-rc2 #1
[ 973.728986] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Debian-1.8.2-1 04/01/2014
[ 973.728986]
ffff7fffffffffff ffff88003436f850 ffffffff812a20f4 ffffffff82156e30
[ 973.728986]
ffffffff82156920 ffff88003436f890 ffffffff8115c759 ffff88003344ae00
[ 973.728986]
ffff88003344b5c0 0000000000000002 0000000000000006 ffff88003344b5e8
[ 973.728986] Call Trace:
[ 973.728986] [<
ffffffff812a20f4>] dump_stack+0x67/0x90
[ 973.728986] [<
ffffffff8115c759>] print_circular_bug+0x22e/0x23c
[ 973.728986] [<
ffffffff810b28d6>] __lock_acquire+0x1118/0x1483
[ 973.728986] [<
ffffffff810b3130>] lock_acquire+0x150/0x217
[ 973.728986] [<
ffffffff810b3130>] ? lock_acquire+0x150/0x217
[ 973.728986] [<
ffffffff8146f6fe>] ? sch_direct_xmit+0x8d/0x221
[ 973.728986] [<
ffffffff815752f4>] _raw_spin_lock+0x2d/0x3c
[ 973.728986] [<
ffffffff8146f6fe>] ? sch_direct_xmit+0x8d/0x221
[ 973.728986] [<
ffffffff8146f6fe>] sch_direct_xmit+0x8d/0x221
[ 973.728986] [<
ffffffff814401e4>] __dev_queue_xmit+0x62a/0x912
[ 973.728986] [<
ffffffff814404d7>] dev_queue_xmit+0xb/0xd
[ 973.728986] [<
ffffffff81449978>] neigh_direct_output+0xc/0xe
[ 973.728986] [<
ffffffff81487811>] ip_finish_output2+0x5db/0x609
[ 973.728986] [<
ffffffff81486853>] ? dst_mtu+0x29/0x2e
[ 973.728986] [<
ffffffff81489590>] ip_finish_output+0x152/0x15e
[ 973.728986] [<
ffffffff8148a0bc>] ? ip_output+0x74/0x96
[ 973.728986] [<
ffffffff8148a0d4>] ip_output+0x8c/0x96
[ 973.728986] [<
ffffffff81489652>] ip_local_out+0x41/0x4a
[ 973.728986] [<
ffffffff81489e7d>] ip_queue_xmit+0x5a5/0x609
[ 973.728986] [<
ffffffff814c559e>] ? udp_set_csum+0x207/0x21e
[ 973.728986] [<
ffffffffa0202fe4>] l2tp_xmit_skb+0x582/0x5d7 [l2tp_core]
[ 973.728986] [<
ffffffffa01b2466>] pppol2tp_xmit+0x1f2/0x25e [l2tp_ppp]
[ 973.728986] [<
ffffffffa0184f59>] ppp_channel_push+0xb5/0x14a [ppp_generic]
[ 973.728986] [<
ffffffffa01853ed>] ppp_write+0x104/0x11c [ppp_generic]
[ 973.728986] [<
ffffffff811b2ec6>] __vfs_write+0x56/0x120
[ 973.728986] [<
ffffffff8124c11d>] ? fsnotify_perm+0x27/0x95
[ 973.728986] [<
ffffffff8124d41d>] ? security_file_permission+0x4d/0x54
[ 973.728986] [<
ffffffff811b3f4c>] vfs_write+0xbd/0x11b
[ 973.728986] [<
ffffffff811b4cb2>] SyS_write+0x5e/0x96
[ 973.728986] [<
ffffffff81575ba5>] entry_SYSCALL_64_fastpath+0x18/0xa8
[ 973.728986] [<
ffffffff810ae0fa>] ? trace_hardirqs_off_caller+0x121/0x12f
Signed-off-by: Guillaume Nault <g.nault@alphalink.fr>
Signed-off-by: David S. Miller <davem@davemloft.net>