Issue created by Sebastian Huber: 
https://gitlab.rtems.org/rtems/rtos/rtems/-/work_items/5761



`_Regulator_Free_helper()` reads `delivery_thread_has_exited` and then
calls `rtems_task_delete()` on `delivery_thread_id`. Nothing holds the
instance between the read and the call. An output thread which reaches
`rtems_task_exit()` in that span leaves an identifier which names no
task. `rtems_task_delete()` answers `RTEMS_INVALID_ID` and a debug build
ends with a failed assertion.

Two orders reach the state which the read accepts. A second
`rtems_regulator_delete()` after an `RTEMS_TIMEOUT` finds
`delivery_thread_is_running` false and `delivery_thread_has_exited`
still false, because the first call set `delivery_thread_request_exit`
and the output thread runs its exit path. A `rtems_regulator_delete()`
which runs while the output thread fails its
`rtems_rate_monotonic_create()` finds the same pair.

Both orders need a second processor. A uniprocessor build reaches
neither, because the helper runs only where the output thread does not,
and the exit path of the output thread holds no block point.

The repair belongs to the instance. The helper needs a field which the
output thread and the helper both write under a lock. A thread which is
about to exit can also signal the helper before it calls
`rtems_task_exit()`.

Merge request !1479 widens the span, because it puts a directive call
between the two stores of the exit path. The branch
`up/libmisc-regulator` has the race as well, on the `ticks == 0` path
where the outer test reads no flag. Found in the review of that merge
request. This description was created with Claude Code assistance.

-- 
View it on GitLab: https://gitlab.rtems.org/rtems/rtos/rtems/-/work_items/5761
You're receiving this email because of your account on gitlab.rtems.org. 
Unsubscribe from this thread: 
https://gitlab.rtems.org/-/sent_notifications/5-553mv3w32n1l4lpcibttfz3tt-1d/unsubscribe
 | Manage all notifications: https://gitlab.rtems.org/-/profile/notifications | 
Help: https://gitlab.rtems.org/help


_______________________________________________
bugs mailing list
[email protected]
http://lists.rtems.org/mailman/listinfo/bugs

Reply via email to