py/scheduler: Fix race in checking scheduler pending state.
Because the atomic section starts after checking whether the scheduler state is pending, it's possible it can become a different state by the time the atomic section starts. This is especially likely on ports where MICROPY_BEGIN_ATOMIC_SECTION is implemented with a mutex (i.e. it might block), but the race exists regardless, i.e. if a context switch occurs between those two lines.
This commit is contained in:
parent
c2cfbcc8d4
commit
243805d776
|
@ -60,6 +60,8 @@ static inline bool mp_sched_empty(void) {
|
||||||
void mp_handle_pending(bool raise_exc) {
|
void mp_handle_pending(bool raise_exc) {
|
||||||
if (MP_STATE_VM(sched_state) == MP_SCHED_PENDING) {
|
if (MP_STATE_VM(sched_state) == MP_SCHED_PENDING) {
|
||||||
mp_uint_t atomic_state = MICROPY_BEGIN_ATOMIC_SECTION();
|
mp_uint_t atomic_state = MICROPY_BEGIN_ATOMIC_SECTION();
|
||||||
|
// Re-check state is still pending now that we're in the atomic section.
|
||||||
|
if (MP_STATE_VM(sched_state) == MP_SCHED_PENDING) {
|
||||||
mp_obj_t obj = MP_STATE_VM(mp_pending_exception);
|
mp_obj_t obj = MP_STATE_VM(mp_pending_exception);
|
||||||
if (obj != MP_OBJ_NULL) {
|
if (obj != MP_OBJ_NULL) {
|
||||||
MP_STATE_VM(mp_pending_exception) = MP_OBJ_NULL;
|
MP_STATE_VM(mp_pending_exception) = MP_OBJ_NULL;
|
||||||
|
@ -72,10 +74,13 @@ void mp_handle_pending(bool raise_exc) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
mp_handle_pending_tail(atomic_state);
|
mp_handle_pending_tail(atomic_state);
|
||||||
|
} else {
|
||||||
|
MICROPY_END_ATOMIC_SECTION(atomic_state);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// This function should only be called be mp_sched_handle_pending,
|
// This function should only be called by mp_handle_pending,
|
||||||
// or by the VM's inlined version of that function.
|
// or by the VM's inlined version of that function.
|
||||||
void mp_handle_pending_tail(mp_uint_t atomic_state) {
|
void mp_handle_pending_tail(mp_uint_t atomic_state) {
|
||||||
MP_STATE_VM(sched_state) = MP_SCHED_LOCKED;
|
MP_STATE_VM(sched_state) = MP_SCHED_LOCKED;
|
||||||
|
|
7
py/vm.c
7
py/vm.c
|
@ -1366,8 +1366,10 @@ pending_exception_check:
|
||||||
#if MICROPY_ENABLE_SCHEDULER
|
#if MICROPY_ENABLE_SCHEDULER
|
||||||
// This is an inlined variant of mp_handle_pending
|
// This is an inlined variant of mp_handle_pending
|
||||||
if (MP_STATE_VM(sched_state) == MP_SCHED_PENDING) {
|
if (MP_STATE_VM(sched_state) == MP_SCHED_PENDING) {
|
||||||
MARK_EXC_IP_SELECTIVE();
|
|
||||||
mp_uint_t atomic_state = MICROPY_BEGIN_ATOMIC_SECTION();
|
mp_uint_t atomic_state = MICROPY_BEGIN_ATOMIC_SECTION();
|
||||||
|
// Re-check state is still pending now that we're in the atomic section.
|
||||||
|
if (MP_STATE_VM(sched_state) == MP_SCHED_PENDING) {
|
||||||
|
MARK_EXC_IP_SELECTIVE();
|
||||||
mp_obj_t obj = MP_STATE_VM(mp_pending_exception);
|
mp_obj_t obj = MP_STATE_VM(mp_pending_exception);
|
||||||
if (obj != MP_OBJ_NULL) {
|
if (obj != MP_OBJ_NULL) {
|
||||||
MP_STATE_VM(mp_pending_exception) = MP_OBJ_NULL;
|
MP_STATE_VM(mp_pending_exception) = MP_OBJ_NULL;
|
||||||
|
@ -1378,6 +1380,9 @@ pending_exception_check:
|
||||||
RAISE(obj);
|
RAISE(obj);
|
||||||
}
|
}
|
||||||
mp_handle_pending_tail(atomic_state);
|
mp_handle_pending_tail(atomic_state);
|
||||||
|
} else {
|
||||||
|
MICROPY_END_ATOMIC_SECTION(atomic_state);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
#else
|
#else
|
||||||
// This is an inlined variant of mp_handle_pending
|
// This is an inlined variant of mp_handle_pending
|
||||||
|
|
Loading…
Reference in New Issue