Re: [PATCH] io_uring/io-wq: fix worker accounting when canceling creation callbacks
From: Gabriel Krisman Bertazi
Date: Tue Aug 11 2026 - 13:03:37 EST
Vishnu Razdan via B4 Relay <devnull+vrazdan.openai.com@xxxxxxxxxx>
writes:
> From: Vishnu Razdan <vrazdan@xxxxxxxxxx>
>
> create_worker_cb() reserves an io-wq worker slot only after its
> task-work callback runs. If the callback is canceled before then,
> io_worker_cancel_cb() still decrements acct->nr_workers. When an
> existing worker retires with its creation callback pending, that
> worker has already decremented the same account's worker count.
>
> The resulting undercount permits worker creation beyond the account's
> configured limit. On an AST2600 OpenBMC system, an unchanged sensor
> daemon reached 4,291 threads with the original kernel. With an
> equivalent downstream fix, 25 passive samples under its normal
> workload showed 6-9 threads.
>
> Decrement nr_workers only when the canceled callback is not
> create_worker_cb(). Continuation callbacks still release their reserved
> slot, and both callback types retain the existing running-count,
> reference-count, and create-state cleanup.
>
> Fixes: 1d5f5ea7cb7d ("io-wq: remove worker to owner tw dependency")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: Codex:gpt-5.6-sol
> Signed-off-by: Vishnu Razdan <vrazdan@xxxxxxxxxx>
> ---
Reviewed-by: Gabriel Krisman Bertazi <krisman@xxxxxxx>
> Prevent unreserved worker-creation callbacks from decrementing the worker count.
> ---
> io_uring/io-wq.c | 9 ++++++---
> 1 file changed, 6 insertions(+), 3 deletions(-)
>
> diff --git a/io_uring/io-wq.c b/io_uring/io-wq.c
> index 2e14880ee..fa403ed24 100644
> --- a/io_uring/io-wq.c
> +++ b/io_uring/io-wq.c
> @@ -211,9 +211,12 @@ static void io_worker_cancel_cb(struct io_worker *worker)
> struct io_wq *wq = worker->wq;
>
> atomic_dec(&acct->nr_running);
> - raw_spin_lock(&acct->workers_lock);
> - acct->nr_workers--;
> - raw_spin_unlock(&acct->workers_lock);
> + /* create_worker_cb() has not reserved a worker slot yet. */
> + if (worker->create_work.func != create_worker_cb) {
> + raw_spin_lock(&acct->workers_lock);
> + acct->nr_workers--;
> + raw_spin_unlock(&acct->workers_lock);
> + }
> io_worker_ref_put(wq);
> clear_bit_unlock(0, &worker->create_state);
> io_worker_release(worker);
>
> ---
> base-commit: d58772d8520c7ef247c4b95c9bd76d3a25da9ff5
> change-id: 20260810-vrazdan-io-wq-b4-submit-9c94df145718
>
> Best regards,
> --
> Vishnu Razdan <vrazdan@xxxxxxxxxx>
>
>
--
Gabriel Krisman Bertazi