Issue created by Chris Johns: 
https://gitlab.rtems.org/rtems/rtos/rtems/-/work_items/5763

Assignee: Sebastian Huber

`_Watchdog_Do_tickle()` takes the ticker of a task based timer out of the
collection and marks it `WATCHDOG_INACTIVE`. It calls
`_Timer_server_Routine_adaptor()` outside the lock of the collection. The
adaptor marks the ticker `WATCHDOG_PENDING` and puts it on the chain of
the timer server. The server takes it off that chain, marks it
`WATCHDOG_INACTIVE` again and calls the routine of the timer.

`rtems_timer_delete()` closes the object, cancels the timer and frees the
object. `_Timer_Cancel()` takes the ticker out of the collection when the
ticker is scheduled. It takes the ticker off the chain of the timer
server when the state is `WATCHDOG_PENDING`. It does nothing when the
state is `WATCHDOG_INACTIVE`.

`WATCHDOG_INACTIVE` names three situations. The timer was never armed. A
tickle phase holds the ticker and the adaptor did not run yet. The timer
server holds the ticker and the routine did not run yet. The delete tells
them apart by no means, so it frees the object in the second case and in
the third case.

In the second case the adaptor writes to the memory which the allocator
gave away. It puts that memory on the chain of the timer server. The
server reads the routine, the identifier and the user data out of it and
calls the routine.

A wait for the end of the tickle phase closes this by no means. The
reader of the third case is a task. A delete which waits for a task holds
the object allocator lock while it waits, so a caller of a higher
priority stops the system.

A wait for the timer server has to tell the third case from the first
one, and the delete has to take the ticker off the chain of the server
where the adaptor puts it during that wait. `timer_delete()` of the
POSIX API has the same shape, because `_POSIX_Timer_TSR()` schedules the
watchdog of an interval timer again. This issue leaves it alone.

Found in the review of the wait for the watchdog tickle. This description
was created with Claude Code assistance.

-- 
View it on GitLab: https://gitlab.rtems.org/rtems/rtos/rtems/-/work_items/5763
You're receiving this email because of your account on gitlab.rtems.org. 
Unsubscribe from this thread: 
https://gitlab.rtems.org/-/sent_notifications/5-9zxcgzvj86a6fvn0qjfzl99qs-1d/unsubscribe
 | Manage all notifications: https://gitlab.rtems.org/-/profile/notifications | 
Help: https://gitlab.rtems.org/help


_______________________________________________
bugs mailing list
[email protected]
http://lists.rtems.org/mailman/listinfo/bugs

Reply via email to