Re: Regression on linux-next (next-20260324 )

From: Borah, Chaitanya Kumar

Date: Tue Apr 21 2026 - 10:38:06 EST


Hello Peter,

On 4/20/2026 6:33 PM, Peter Zijlstra wrote:
On Mon, Mar 30, 2026 at 09:50:37PM +0200, Peter Zijlstra wrote:
On Mon, Mar 30, 2026 at 01:56:33PM +0530, Borah, Chaitanya Kumar wrote:
diff --git a/kernel/locking/ww_mutex.h b/kernel/locking/ww_mutex.h
index b1834ab7e782..bb8b410779d4 100644
--- a/kernel/locking/ww_mutex.h
+++ b/kernel/locking/ww_mutex.h
@@ -42,7 +42,7 @@ __ww_waiter_last(struct mutex *lock)
struct mutex_waiter *w = lock->first_waiter;
if (w)
- w = list_prev_entry(w, list);
+ w = __ww_waiter_prev(lock, w);
return w;
}
Thank you for the response, Peter. Unfortunately, the issue is still seen
with this change.

Bah, indeed. Looking at this after the weekend I see that it's actually
wrong.

But I haven't yet had a new idea. I don't suppose there is a relatively
easy way to reproduce this issue outside of your CI robot?

My current working thesis is that since this is graphics, this is
ww_mutex related. I'll go over this code once more...

Since you've not provided a reproducer, can I ask you to try the below?

---
diff --git a/kernel/locking/mutex.c b/kernel/locking/mutex.c
index 186b463fe326..a93e57fc53b1 100644
--- a/kernel/locking/mutex.c
+++ b/kernel/locking/mutex.c
@@ -229,10 +229,8 @@ __mutex_remove_waiter(struct mutex *lock, struct mutex_waiter *waiter)
__mutex_clear_flag(lock, MUTEX_FLAGS);
lock->first_waiter = NULL;
} else {
- if (lock->first_waiter == waiter) {
- lock->first_waiter = list_first_entry(&waiter->list,
- struct mutex_waiter, list);
- }
+ if (lock->first_waiter == waiter)
+ lock->first_waiter = list_next_entry(waiter, list);
list_del(&waiter->list);
}
diff --git a/kernel/locking/ww_mutex.h b/kernel/locking/ww_mutex.h
index 016f0db892a5..875b303511b3 100644
--- a/kernel/locking/ww_mutex.h
+++ b/kernel/locking/ww_mutex.h
@@ -6,6 +6,32 @@
#define MUTEX_WAITER mutex_waiter
#define WAIT_LOCK wait_lock
+/*
+ * +-------+
+ * | 3 | <+
+ * +-------+ |
+ * ^ |
+ * | |
+ * v |
+ * +-------+ +-------+ |
+ * | first | --> | 1 | |
+ * +-------+ +-------+ |
+ * ^ |
+ * | |
+ * v |
+ * +-------+ |
+ * | 2 | <+
+ * +-------+
+ */
+
+/*
+ * Specifically:
+ *
+ * for (cur = __ww_waiter_first(); cur; cur = __ww_waiter_next())
+ * ...
+ *
+ * should iterate like: 1 2 3
+ */
static inline struct mutex_waiter *
__ww_waiter_first(struct mutex *lock)
__must_hold(&lock->wait_lock)
@@ -18,23 +44,21 @@ __ww_waiter_next(struct mutex *lock, struct mutex_waiter *w)
__must_hold(&lock->wait_lock)
{
w = list_next_entry(w, list);
- if (lock->first_waiter == w)
- return NULL;
-
- return w;
-}
-
-static inline struct mutex_waiter *
-__ww_waiter_prev(struct mutex *lock, struct mutex_waiter *w)
- __must_hold(&lock->wait_lock)
-{
- w = list_prev_entry(w, list);
- if (lock->first_waiter == w)
+ /* We've already seen first, terminate */
+ if (w == __ww_waiter_first(lock))
return NULL;
return w;
}
+/*
+ * Specifically:
+ *
+ * for (cur = __ww_waiter_last(); cur; cur = __ww_waiter_prev())
+ * ...
+ *
+ * should iterate like: 3 2 1
+ */
static inline struct mutex_waiter *
__ww_waiter_last(struct mutex *lock)
__must_hold(&lock->wait_lock)
@@ -46,6 +70,18 @@ __ww_waiter_last(struct mutex *lock)
return w;
}
+static inline struct mutex_waiter *
+__ww_waiter_prev(struct mutex *lock, struct mutex_waiter *w)
+ __must_hold(&lock->wait_lock)
+{
+ w = list_prev_entry(w, list);
+ /* We've already seen last, terminate */
+ if (w == __ww_waiter_last(lock))
+ return NULL;
+
+ return w;
+}
+
static inline void
__ww_waiter_add(struct mutex *lock, struct mutex_waiter *waiter, struct mutex_waiter *pos)
__must_hold(&lock->wait_lock)

Thank you for the patch.
This seems to fix the issue on our CI machine. The diff turned out to be slightly different, pasting it here just in case.

diff --git a/kernel/locking/mutex.c b/kernel/locking/mutex.c
index 186b463fe326..a93e57fc53b1 100644
--- a/kernel/locking/mutex.c
+++ b/kernel/locking/mutex.c
@@ -229,10 +229,8 @@ __mutex_remove_waiter(struct mutex *lock, struct mutex_waiter *waiter)
__mutex_clear_flag(lock, MUTEX_FLAGS);
lock->first_waiter = NULL;
} else {
- if (lock->first_waiter == waiter) {
- lock->first_waiter = list_first_entry(&waiter->list,
- struct mutex_waiter, list);
- }
+ if (lock->first_waiter == waiter)
+ lock->first_waiter = list_next_entry(waiter, list);
list_del(&waiter->list);
}

diff --git a/kernel/locking/ww_mutex.h b/kernel/locking/ww_mutex.h
index 016f0db892a5..875b303511b3 100644
--- a/kernel/locking/ww_mutex.h
+++ b/kernel/locking/ww_mutex.h
@@ -6,6 +6,32 @@
#define MUTEX_WAITER mutex_waiter
#define WAIT_LOCK wait_lock

+/*
+ * +-------+
+ * | 3 | <+
+ * +-------+ |
+ * ^ |
+ * | |
+ * v |
+ * +-------+ +-------+ |
+ * | first | --> | 1 | |
+ * +-------+ +-------+ |
+ * ^ |
+ * | |
+ * v |
+ * +-------+ |
+ * | 2 | <+
+ * +-------+
+ */
+
+/*
+ * Specifically:
+ *
+ * for (cur = __ww_waiter_first(); cur; cur = __ww_waiter_next())
+ * ...
+ *
+ * should iterate like: 1 2 3
+ */
static inline struct mutex_waiter *
__ww_waiter_first(struct mutex *lock)
__must_hold(&lock->wait_lock)
@@ -18,31 +44,41 @@ __ww_waiter_next(struct mutex *lock, struct mutex_waiter *w)
__must_hold(&lock->wait_lock)
{
w = list_next_entry(w, list);
- if (lock->first_waiter == w)
+ /* We've already seen first, terminate */
+ if (w == __ww_waiter_first(lock))
return NULL;

return w;
}

+/*
+ * Specifically:
+ *
+ * for (cur = __ww_waiter_last(); cur; cur = __ww_waiter_prev())
+ * ...
+ *
+ * should iterate like: 3 2 1
+ */
static inline struct mutex_waiter *
-__ww_waiter_prev(struct mutex *lock, struct mutex_waiter *w)
+__ww_waiter_last(struct mutex *lock)
__must_hold(&lock->wait_lock)
{
- w = list_prev_entry(w, list);
- if (lock->first_waiter == w)
- return NULL;
+ struct mutex_waiter *w = lock->first_waiter;

+ if (w)
+ w = list_prev_entry(w, list);
return w;
}

static inline struct mutex_waiter *
-__ww_waiter_last(struct mutex *lock)
+__ww_waiter_prev(struct mutex *lock, struct mutex_waiter *w)
__must_hold(&lock->wait_lock)
{
- struct mutex_waiter *w = lock->first_waiter;
+ w = list_prev_entry(w, list);
+ /* We've already seen last, terminate */
+ if (w == __ww_waiter_last(lock))
+ return NULL;

- if (w)
- w = list_prev_entry(w, list);
return w;
}

==
Chaitanya