Re: [PATCH] hrtimer: Use the mask to clear TIF_HRTIMER_REARM from the exit work
From: Karl Mehltretter
Date: Mon Sep 28 2026 - 00:01:24 EST
On Sat, Sep 19, 2026 at 04:40:27PM +0100, Karl Mehltretter wrote:
> TIF_HRTIMER_REARM is the bit number (12), not the mask. That clears
> TIF_NOTIFY_SIGNAL (bit 2) and TIF_MEMDIE (bit 3) from the copy and
> leaves bit 12 set.
>
> So the function never returns true, and the copy handed to
> exit_to_user_mode_loop() lacks TIF_NOTIFY_SIGNAL. If that was the only
> work for the loop, the task returns to user space with the task work
> still pending. hrtimer_interrupt() sets TIF_HRTIMER_REARM every time,
> so the next tick repeats that. Task work queued with TWA_SIGNAL from a
> hrtimer callback stays pending until the task does a syscall, takes an
> interrupt without deferred rearm or has to reschedule.
>
> A task which polls the io_uring completion ring in user space sees a
> timeout completion after 30ms (median) instead of 70us. 2 CPU QEMU
> guest, HZ=1000.
>
> Use the mask.
The patch also fixes longer delays I found with NO_HZ_FULL.
Same 2-CPU x86-64 QEMU guest, nohz_full=1 rcu_nocbs=1, polling on
CPU 1. For 6,000 3 ms timeouts per kernel across three boots:
More than 50 ms late Worst delay
Unpatched 239 (4%) 991 ms
Patched 0 5.7 ms
Most callbacks run on the housekeeping CPU and avoid the bug. A
traced local expiry was followed by a 737 ms gap until a
call-function IPI.
Thanks,
Karl