xref: /linux/kernel/watchdog.c (revision 62e7ca5280fd8cbf523970757e13f0324ce0daa0)
1 /*
2  * Detect hard and soft lockups on a system
3  *
4  * started by Don Zickus, Copyright (C) 2010 Red Hat, Inc.
5  *
6  * Note: Most of this code is borrowed heavily from the original softlockup
7  * detector, so thanks to Ingo for the initial implementation.
8  * Some chunks also taken from the old x86-specific nmi watchdog code, thanks
9  * to those contributors as well.
10  */
11 
12 #define pr_fmt(fmt) "NMI watchdog: " fmt
13 
14 #include <linux/mm.h>
15 #include <linux/cpu.h>
16 #include <linux/nmi.h>
17 #include <linux/init.h>
18 #include <linux/delay.h>
19 #include <linux/freezer.h>
20 #include <linux/kthread.h>
21 #include <linux/lockdep.h>
22 #include <linux/notifier.h>
23 #include <linux/module.h>
24 #include <linux/sysctl.h>
25 #include <linux/smpboot.h>
26 #include <linux/sched/rt.h>
27 
28 #include <asm/irq_regs.h>
29 #include <linux/kvm_para.h>
30 #include <linux/perf_event.h>
31 
32 int watchdog_user_enabled = 1;
33 int __read_mostly watchdog_thresh = 10;
34 #ifdef CONFIG_SMP
35 int __read_mostly sysctl_softlockup_all_cpu_backtrace;
36 #else
37 #define sysctl_softlockup_all_cpu_backtrace 0
38 #endif
39 
40 static int __read_mostly watchdog_running;
41 static u64 __read_mostly sample_period;
42 
43 static DEFINE_PER_CPU(unsigned long, watchdog_touch_ts);
44 static DEFINE_PER_CPU(struct task_struct *, softlockup_watchdog);
45 static DEFINE_PER_CPU(struct hrtimer, watchdog_hrtimer);
46 static DEFINE_PER_CPU(bool, softlockup_touch_sync);
47 static DEFINE_PER_CPU(bool, soft_watchdog_warn);
48 static DEFINE_PER_CPU(unsigned long, hrtimer_interrupts);
49 static DEFINE_PER_CPU(unsigned long, soft_lockup_hrtimer_cnt);
50 #ifdef CONFIG_HARDLOCKUP_DETECTOR
51 static DEFINE_PER_CPU(bool, hard_watchdog_warn);
52 static DEFINE_PER_CPU(bool, watchdog_nmi_touch);
53 static DEFINE_PER_CPU(unsigned long, hrtimer_interrupts_saved);
54 static DEFINE_PER_CPU(struct perf_event *, watchdog_ev);
55 #endif
56 static unsigned long soft_lockup_nmi_warn;
57 
58 /* boot commands */
59 /*
60  * Should we panic when a soft-lockup or hard-lockup occurs:
61  */
62 #ifdef CONFIG_HARDLOCKUP_DETECTOR
63 static int hardlockup_panic =
64 			CONFIG_BOOTPARAM_HARDLOCKUP_PANIC_VALUE;
65 
66 static int __init hardlockup_panic_setup(char *str)
67 {
68 	if (!strncmp(str, "panic", 5))
69 		hardlockup_panic = 1;
70 	else if (!strncmp(str, "nopanic", 7))
71 		hardlockup_panic = 0;
72 	else if (!strncmp(str, "0", 1))
73 		watchdog_user_enabled = 0;
74 	return 1;
75 }
76 __setup("nmi_watchdog=", hardlockup_panic_setup);
77 #endif
78 
79 unsigned int __read_mostly softlockup_panic =
80 			CONFIG_BOOTPARAM_SOFTLOCKUP_PANIC_VALUE;
81 
82 static int __init softlockup_panic_setup(char *str)
83 {
84 	softlockup_panic = simple_strtoul(str, NULL, 0);
85 
86 	return 1;
87 }
88 __setup("softlockup_panic=", softlockup_panic_setup);
89 
90 static int __init nowatchdog_setup(char *str)
91 {
92 	watchdog_user_enabled = 0;
93 	return 1;
94 }
95 __setup("nowatchdog", nowatchdog_setup);
96 
97 /* deprecated */
98 static int __init nosoftlockup_setup(char *str)
99 {
100 	watchdog_user_enabled = 0;
101 	return 1;
102 }
103 __setup("nosoftlockup", nosoftlockup_setup);
104 /*  */
105 #ifdef CONFIG_SMP
106 static int __init softlockup_all_cpu_backtrace_setup(char *str)
107 {
108 	sysctl_softlockup_all_cpu_backtrace =
109 		!!simple_strtol(str, NULL, 0);
110 	return 1;
111 }
112 __setup("softlockup_all_cpu_backtrace=", softlockup_all_cpu_backtrace_setup);
113 #endif
114 
115 /*
116  * Hard-lockup warnings should be triggered after just a few seconds. Soft-
117  * lockups can have false positives under extreme conditions. So we generally
118  * want a higher threshold for soft lockups than for hard lockups. So we couple
119  * the thresholds with a factor: we make the soft threshold twice the amount of
120  * time the hard threshold is.
121  */
122 static int get_softlockup_thresh(void)
123 {
124 	return watchdog_thresh * 2;
125 }
126 
127 /*
128  * Returns seconds, approximately.  We don't need nanosecond
129  * resolution, and we don't need to waste time with a big divide when
130  * 2^30ns == 1.074s.
131  */
132 static unsigned long get_timestamp(void)
133 {
134 	return local_clock() >> 30LL;  /* 2^30 ~= 10^9 */
135 }
136 
137 static void set_sample_period(void)
138 {
139 	/*
140 	 * convert watchdog_thresh from seconds to ns
141 	 * the divide by 5 is to give hrtimer several chances (two
142 	 * or three with the current relation between the soft
143 	 * and hard thresholds) to increment before the
144 	 * hardlockup detector generates a warning
145 	 */
146 	sample_period = get_softlockup_thresh() * ((u64)NSEC_PER_SEC / 5);
147 }
148 
149 /* Commands for resetting the watchdog */
150 static void __touch_watchdog(void)
151 {
152 	__this_cpu_write(watchdog_touch_ts, get_timestamp());
153 }
154 
155 void touch_softlockup_watchdog(void)
156 {
157 	/*
158 	 * Preemption can be enabled.  It doesn't matter which CPU's timestamp
159 	 * gets zeroed here, so use the raw_ operation.
160 	 */
161 	raw_cpu_write(watchdog_touch_ts, 0);
162 }
163 EXPORT_SYMBOL(touch_softlockup_watchdog);
164 
165 void touch_all_softlockup_watchdogs(void)
166 {
167 	int cpu;
168 
169 	/*
170 	 * this is done lockless
171 	 * do we care if a 0 races with a timestamp?
172 	 * all it means is the softlock check starts one cycle later
173 	 */
174 	for_each_online_cpu(cpu)
175 		per_cpu(watchdog_touch_ts, cpu) = 0;
176 }
177 
178 #ifdef CONFIG_HARDLOCKUP_DETECTOR
179 void touch_nmi_watchdog(void)
180 {
181 	/*
182 	 * Using __raw here because some code paths have
183 	 * preemption enabled.  If preemption is enabled
184 	 * then interrupts should be enabled too, in which
185 	 * case we shouldn't have to worry about the watchdog
186 	 * going off.
187 	 */
188 	__raw_get_cpu_var(watchdog_nmi_touch) = true;
189 	touch_softlockup_watchdog();
190 }
191 EXPORT_SYMBOL(touch_nmi_watchdog);
192 
193 #endif
194 
195 void touch_softlockup_watchdog_sync(void)
196 {
197 	__raw_get_cpu_var(softlockup_touch_sync) = true;
198 	__raw_get_cpu_var(watchdog_touch_ts) = 0;
199 }
200 
201 #ifdef CONFIG_HARDLOCKUP_DETECTOR
202 /* watchdog detector functions */
203 static int is_hardlockup(void)
204 {
205 	unsigned long hrint = __this_cpu_read(hrtimer_interrupts);
206 
207 	if (__this_cpu_read(hrtimer_interrupts_saved) == hrint)
208 		return 1;
209 
210 	__this_cpu_write(hrtimer_interrupts_saved, hrint);
211 	return 0;
212 }
213 #endif
214 
215 static int is_softlockup(unsigned long touch_ts)
216 {
217 	unsigned long now = get_timestamp();
218 
219 	/* Warn about unreasonable delays: */
220 	if (time_after(now, touch_ts + get_softlockup_thresh()))
221 		return now - touch_ts;
222 
223 	return 0;
224 }
225 
226 #ifdef CONFIG_HARDLOCKUP_DETECTOR
227 
228 static struct perf_event_attr wd_hw_attr = {
229 	.type		= PERF_TYPE_HARDWARE,
230 	.config		= PERF_COUNT_HW_CPU_CYCLES,
231 	.size		= sizeof(struct perf_event_attr),
232 	.pinned		= 1,
233 	.disabled	= 1,
234 };
235 
236 /* Callback function for perf event subsystem */
237 static void watchdog_overflow_callback(struct perf_event *event,
238 		 struct perf_sample_data *data,
239 		 struct pt_regs *regs)
240 {
241 	/* Ensure the watchdog never gets throttled */
242 	event->hw.interrupts = 0;
243 
244 	if (__this_cpu_read(watchdog_nmi_touch) == true) {
245 		__this_cpu_write(watchdog_nmi_touch, false);
246 		return;
247 	}
248 
249 	/* check for a hardlockup
250 	 * This is done by making sure our timer interrupt
251 	 * is incrementing.  The timer interrupt should have
252 	 * fired multiple times before we overflow'd.  If it hasn't
253 	 * then this is a good indication the cpu is stuck
254 	 */
255 	if (is_hardlockup()) {
256 		int this_cpu = smp_processor_id();
257 
258 		/* only print hardlockups once */
259 		if (__this_cpu_read(hard_watchdog_warn) == true)
260 			return;
261 
262 		if (hardlockup_panic)
263 			panic("Watchdog detected hard LOCKUP on cpu %d",
264 			      this_cpu);
265 		else
266 			WARN(1, "Watchdog detected hard LOCKUP on cpu %d",
267 			     this_cpu);
268 
269 		__this_cpu_write(hard_watchdog_warn, true);
270 		return;
271 	}
272 
273 	__this_cpu_write(hard_watchdog_warn, false);
274 	return;
275 }
276 #endif /* CONFIG_HARDLOCKUP_DETECTOR */
277 
278 static void watchdog_interrupt_count(void)
279 {
280 	__this_cpu_inc(hrtimer_interrupts);
281 }
282 
283 static int watchdog_nmi_enable(unsigned int cpu);
284 static void watchdog_nmi_disable(unsigned int cpu);
285 
286 /* watchdog kicker functions */
287 static enum hrtimer_restart watchdog_timer_fn(struct hrtimer *hrtimer)
288 {
289 	unsigned long touch_ts = __this_cpu_read(watchdog_touch_ts);
290 	struct pt_regs *regs = get_irq_regs();
291 	int duration;
292 	int softlockup_all_cpu_backtrace = sysctl_softlockup_all_cpu_backtrace;
293 
294 	/* kick the hardlockup detector */
295 	watchdog_interrupt_count();
296 
297 	/* kick the softlockup detector */
298 	wake_up_process(__this_cpu_read(softlockup_watchdog));
299 
300 	/* .. and repeat */
301 	hrtimer_forward_now(hrtimer, ns_to_ktime(sample_period));
302 
303 	if (touch_ts == 0) {
304 		if (unlikely(__this_cpu_read(softlockup_touch_sync))) {
305 			/*
306 			 * If the time stamp was touched atomically
307 			 * make sure the scheduler tick is up to date.
308 			 */
309 			__this_cpu_write(softlockup_touch_sync, false);
310 			sched_clock_tick();
311 		}
312 
313 		/* Clear the guest paused flag on watchdog reset */
314 		kvm_check_and_clear_guest_paused();
315 		__touch_watchdog();
316 		return HRTIMER_RESTART;
317 	}
318 
319 	/* check for a softlockup
320 	 * This is done by making sure a high priority task is
321 	 * being scheduled.  The task touches the watchdog to
322 	 * indicate it is getting cpu time.  If it hasn't then
323 	 * this is a good indication some task is hogging the cpu
324 	 */
325 	duration = is_softlockup(touch_ts);
326 	if (unlikely(duration)) {
327 		/*
328 		 * If a virtual machine is stopped by the host it can look to
329 		 * the watchdog like a soft lockup, check to see if the host
330 		 * stopped the vm before we issue the warning
331 		 */
332 		if (kvm_check_and_clear_guest_paused())
333 			return HRTIMER_RESTART;
334 
335 		/* only warn once */
336 		if (__this_cpu_read(soft_watchdog_warn) == true)
337 			return HRTIMER_RESTART;
338 
339 		if (softlockup_all_cpu_backtrace) {
340 			/* Prevent multiple soft-lockup reports if one cpu is already
341 			 * engaged in dumping cpu back traces
342 			 */
343 			if (test_and_set_bit(0, &soft_lockup_nmi_warn)) {
344 				/* Someone else will report us. Let's give up */
345 				__this_cpu_write(soft_watchdog_warn, true);
346 				return HRTIMER_RESTART;
347 			}
348 		}
349 
350 		pr_emerg("BUG: soft lockup - CPU#%d stuck for %us! [%s:%d]\n",
351 			smp_processor_id(), duration,
352 			current->comm, task_pid_nr(current));
353 		print_modules();
354 		print_irqtrace_events(current);
355 		if (regs)
356 			show_regs(regs);
357 		else
358 			dump_stack();
359 
360 		if (softlockup_all_cpu_backtrace) {
361 			/* Avoid generating two back traces for current
362 			 * given that one is already made above
363 			 */
364 			trigger_allbutself_cpu_backtrace();
365 
366 			clear_bit(0, &soft_lockup_nmi_warn);
367 			/* Barrier to sync with other cpus */
368 			smp_mb__after_atomic();
369 		}
370 
371 		if (softlockup_panic)
372 			panic("softlockup: hung tasks");
373 		__this_cpu_write(soft_watchdog_warn, true);
374 	} else
375 		__this_cpu_write(soft_watchdog_warn, false);
376 
377 	return HRTIMER_RESTART;
378 }
379 
380 static void watchdog_set_prio(unsigned int policy, unsigned int prio)
381 {
382 	struct sched_param param = { .sched_priority = prio };
383 
384 	sched_setscheduler(current, policy, &param);
385 }
386 
387 static void watchdog_enable(unsigned int cpu)
388 {
389 	struct hrtimer *hrtimer = &__raw_get_cpu_var(watchdog_hrtimer);
390 
391 	/* kick off the timer for the hardlockup detector */
392 	hrtimer_init(hrtimer, CLOCK_MONOTONIC, HRTIMER_MODE_REL);
393 	hrtimer->function = watchdog_timer_fn;
394 
395 	/* Enable the perf event */
396 	watchdog_nmi_enable(cpu);
397 
398 	/* done here because hrtimer_start can only pin to smp_processor_id() */
399 	hrtimer_start(hrtimer, ns_to_ktime(sample_period),
400 		      HRTIMER_MODE_REL_PINNED);
401 
402 	/* initialize timestamp */
403 	watchdog_set_prio(SCHED_FIFO, MAX_RT_PRIO - 1);
404 	__touch_watchdog();
405 }
406 
407 static void watchdog_disable(unsigned int cpu)
408 {
409 	struct hrtimer *hrtimer = &__raw_get_cpu_var(watchdog_hrtimer);
410 
411 	watchdog_set_prio(SCHED_NORMAL, 0);
412 	hrtimer_cancel(hrtimer);
413 	/* disable the perf event */
414 	watchdog_nmi_disable(cpu);
415 }
416 
417 static void watchdog_cleanup(unsigned int cpu, bool online)
418 {
419 	watchdog_disable(cpu);
420 }
421 
422 static int watchdog_should_run(unsigned int cpu)
423 {
424 	return __this_cpu_read(hrtimer_interrupts) !=
425 		__this_cpu_read(soft_lockup_hrtimer_cnt);
426 }
427 
428 /*
429  * The watchdog thread function - touches the timestamp.
430  *
431  * It only runs once every sample_period seconds (4 seconds by
432  * default) to reset the softlockup timestamp. If this gets delayed
433  * for more than 2*watchdog_thresh seconds then the debug-printout
434  * triggers in watchdog_timer_fn().
435  */
436 static void watchdog(unsigned int cpu)
437 {
438 	__this_cpu_write(soft_lockup_hrtimer_cnt,
439 			 __this_cpu_read(hrtimer_interrupts));
440 	__touch_watchdog();
441 }
442 
443 #ifdef CONFIG_HARDLOCKUP_DETECTOR
444 /*
445  * People like the simple clean cpu node info on boot.
446  * Reduce the watchdog noise by only printing messages
447  * that are different from what cpu0 displayed.
448  */
449 static unsigned long cpu0_err;
450 
451 static int watchdog_nmi_enable(unsigned int cpu)
452 {
453 	struct perf_event_attr *wd_attr;
454 	struct perf_event *event = per_cpu(watchdog_ev, cpu);
455 
456 	/* is it already setup and enabled? */
457 	if (event && event->state > PERF_EVENT_STATE_OFF)
458 		goto out;
459 
460 	/* it is setup but not enabled */
461 	if (event != NULL)
462 		goto out_enable;
463 
464 	wd_attr = &wd_hw_attr;
465 	wd_attr->sample_period = hw_nmi_get_sample_period(watchdog_thresh);
466 
467 	/* Try to register using hardware perf events */
468 	event = perf_event_create_kernel_counter(wd_attr, cpu, NULL, watchdog_overflow_callback, NULL);
469 
470 	/* save cpu0 error for future comparision */
471 	if (cpu == 0 && IS_ERR(event))
472 		cpu0_err = PTR_ERR(event);
473 
474 	if (!IS_ERR(event)) {
475 		/* only print for cpu0 or different than cpu0 */
476 		if (cpu == 0 || cpu0_err)
477 			pr_info("enabled on all CPUs, permanently consumes one hw-PMU counter.\n");
478 		goto out_save;
479 	}
480 
481 	/* skip displaying the same error again */
482 	if (cpu > 0 && (PTR_ERR(event) == cpu0_err))
483 		return PTR_ERR(event);
484 
485 	/* vary the KERN level based on the returned errno */
486 	if (PTR_ERR(event) == -EOPNOTSUPP)
487 		pr_info("disabled (cpu%i): not supported (no LAPIC?)\n", cpu);
488 	else if (PTR_ERR(event) == -ENOENT)
489 		pr_warn("disabled (cpu%i): hardware events not enabled\n",
490 			 cpu);
491 	else
492 		pr_err("disabled (cpu%i): unable to create perf event: %ld\n",
493 			cpu, PTR_ERR(event));
494 	return PTR_ERR(event);
495 
496 	/* success path */
497 out_save:
498 	per_cpu(watchdog_ev, cpu) = event;
499 out_enable:
500 	perf_event_enable(per_cpu(watchdog_ev, cpu));
501 out:
502 	return 0;
503 }
504 
505 static void watchdog_nmi_disable(unsigned int cpu)
506 {
507 	struct perf_event *event = per_cpu(watchdog_ev, cpu);
508 
509 	if (event) {
510 		perf_event_disable(event);
511 		per_cpu(watchdog_ev, cpu) = NULL;
512 
513 		/* should be in cleanup, but blocks oprofile */
514 		perf_event_release_kernel(event);
515 	}
516 	return;
517 }
518 #else
519 static int watchdog_nmi_enable(unsigned int cpu) { return 0; }
520 static void watchdog_nmi_disable(unsigned int cpu) { return; }
521 #endif /* CONFIG_HARDLOCKUP_DETECTOR */
522 
523 static struct smp_hotplug_thread watchdog_threads = {
524 	.store			= &softlockup_watchdog,
525 	.thread_should_run	= watchdog_should_run,
526 	.thread_fn		= watchdog,
527 	.thread_comm		= "watchdog/%u",
528 	.setup			= watchdog_enable,
529 	.cleanup		= watchdog_cleanup,
530 	.park			= watchdog_disable,
531 	.unpark			= watchdog_enable,
532 };
533 
534 static void restart_watchdog_hrtimer(void *info)
535 {
536 	struct hrtimer *hrtimer = &__raw_get_cpu_var(watchdog_hrtimer);
537 	int ret;
538 
539 	/*
540 	 * No need to cancel and restart hrtimer if it is currently executing
541 	 * because it will reprogram itself with the new period now.
542 	 * We should never see it unqueued here because we are running per-cpu
543 	 * with interrupts disabled.
544 	 */
545 	ret = hrtimer_try_to_cancel(hrtimer);
546 	if (ret == 1)
547 		hrtimer_start(hrtimer, ns_to_ktime(sample_period),
548 				HRTIMER_MODE_REL_PINNED);
549 }
550 
551 static void update_timers(int cpu)
552 {
553 	/*
554 	 * Make sure that perf event counter will adopt to a new
555 	 * sampling period. Updating the sampling period directly would
556 	 * be much nicer but we do not have an API for that now so
557 	 * let's use a big hammer.
558 	 * Hrtimer will adopt the new period on the next tick but this
559 	 * might be late already so we have to restart the timer as well.
560 	 */
561 	watchdog_nmi_disable(cpu);
562 	smp_call_function_single(cpu, restart_watchdog_hrtimer, NULL, 1);
563 	watchdog_nmi_enable(cpu);
564 }
565 
566 static void update_timers_all_cpus(void)
567 {
568 	int cpu;
569 
570 	get_online_cpus();
571 	for_each_online_cpu(cpu)
572 		update_timers(cpu);
573 	put_online_cpus();
574 }
575 
576 static int watchdog_enable_all_cpus(bool sample_period_changed)
577 {
578 	int err = 0;
579 
580 	if (!watchdog_running) {
581 		err = smpboot_register_percpu_thread(&watchdog_threads);
582 		if (err)
583 			pr_err("Failed to create watchdog threads, disabled\n");
584 		else
585 			watchdog_running = 1;
586 	} else if (sample_period_changed) {
587 		update_timers_all_cpus();
588 	}
589 
590 	return err;
591 }
592 
593 /* prepare/enable/disable routines */
594 /* sysctl functions */
595 #ifdef CONFIG_SYSCTL
596 static void watchdog_disable_all_cpus(void)
597 {
598 	if (watchdog_running) {
599 		watchdog_running = 0;
600 		smpboot_unregister_percpu_thread(&watchdog_threads);
601 	}
602 }
603 
604 /*
605  * proc handler for /proc/sys/kernel/nmi_watchdog,watchdog_thresh
606  */
607 
608 int proc_dowatchdog(struct ctl_table *table, int write,
609 		    void __user *buffer, size_t *lenp, loff_t *ppos)
610 {
611 	int err, old_thresh, old_enabled;
612 	static DEFINE_MUTEX(watchdog_proc_mutex);
613 
614 	mutex_lock(&watchdog_proc_mutex);
615 	old_thresh = ACCESS_ONCE(watchdog_thresh);
616 	old_enabled = ACCESS_ONCE(watchdog_user_enabled);
617 
618 	err = proc_dointvec_minmax(table, write, buffer, lenp, ppos);
619 	if (err || !write)
620 		goto out;
621 
622 	set_sample_period();
623 	/*
624 	 * Watchdog threads shouldn't be enabled if they are
625 	 * disabled. The 'watchdog_running' variable check in
626 	 * watchdog_*_all_cpus() function takes care of this.
627 	 */
628 	if (watchdog_user_enabled && watchdog_thresh)
629 		err = watchdog_enable_all_cpus(old_thresh != watchdog_thresh);
630 	else
631 		watchdog_disable_all_cpus();
632 
633 	/* Restore old values on failure */
634 	if (err) {
635 		watchdog_thresh = old_thresh;
636 		watchdog_user_enabled = old_enabled;
637 	}
638 out:
639 	mutex_unlock(&watchdog_proc_mutex);
640 	return err;
641 }
642 #endif /* CONFIG_SYSCTL */
643 
644 void __init lockup_detector_init(void)
645 {
646 	set_sample_period();
647 
648 	if (watchdog_user_enabled)
649 		watchdog_enable_all_cpus(false);
650 }
651