Sebastian Huber created a merge request: 
https://gitlab.rtems.org/rtems/rtos/rtems/-/merge_requests/1485

Project:Branches: sebhub/rtems:up/timer-server-delete to rtems/rtos/rtems:main
Author: Sebastian Huber

## Summary

Issue #5741: score: A watchdog service routine can run on a freed object

Issue #5757: rtems: The delete of a timer frees an object which the server reads

Twelve commits on the branch of section 51. Six of them pre-qualify the
`<sys/lock.h>` condition variables and add the support header
`condimpl.h`, which hands a component the thread queue of a condition
variable. The timer server fix below uses it.

The first of the other six counts the tickle phases of a processor and
adds `_Watchdog_Wait_for_service_stop()`. `_Watchdog_Tick()` increments
the count at the begin of a phase and stores the next even count at the
end. An odd count therefore names a processor whose collections may run
a service routine. The wait reads that count with an acquire load and
waits out the phase which it found. The same commit takes the wait into
the free paths of the four object classes which own a watchdog: the
Classic timer, the period, the POSIX timer and the thread.

The second commit closes the other producer of a tickle. `_TOD_Set()`
tickles the realtime collection of every processor at task level, and no
count covers it. The directive obtains the object allocator mutex
instead of the TOD mutex, and every delete directive obtains that mutex
before it frees an object. The TOD mutex loses its last user. A timer
service routine of a set runs under the mutex, so it may create and
delete no object. The item of `rtems_clock_set()` says so, and two
routines of `sp11` drop the check which forbids the mutex.

Two validation tests follow, one for the window of a tickle and one for
the window of a clock set. Each arms a timer on the processor of the
runner, holds the service routine in the window, and checks that the
delete of a worker on the second processor ends after the routine
returns.

The fifth commit repairs `rtems_timer_delete()` for the Timer Server
task, which is the second issue. `_Timer_server_Body()` marks the ticker
`WATCHDOG_INACTIVE` and calls the routine outside the lock, and that
state names two other situations as well. The server gains a condition
variable and a member which states whether it runs the routines of a
phase. The thread queue lock of that condition variable is the lock of
the server, so a caller cannot separate the read of the member from its
own enqueue. The directive releases the object allocator mutex around
the wait, because a service routine of the server may obtain it. It
takes the thread life protection, because that release ends the
protection which the mutex gives. A system with no timer server and a
delete from the server itself need no wait.

The last commit adds the validation test of that requirement. The
routine of the timer blocks in the Timer Server task and lets a worker
delete the timer. Each of the three new tests fails without its fix.

The sporadic server timer of the POSIX API keeps the window.
`_POSIX_Threads_Terminate_extension()` removes it under the `Join_queue`
lock. `_POSIX_Threads_Sporadic_timer()` re-arms it under
`Wait.Lock.Default`. A wait closes that order by no means, so the first
issue stays open.

The test suite of `sparc/gr740` runs in the four configurations. The two
release configurations report no regression. The two debug
configurations report four failures which this branch does not cause.

**BSP** `sparc/gr740` in four configurations ยท **Simulator** SIS

## AI Details
<!-- Make sure you have read our statement at 
https://www.rtems.org/generative-ai/ -->

### Prompt used

None as a single prompt.  The work was done in an interactive Claude Code
session on the RTEMS tree.  The task was to run the test suites of the
simulator BSPs, diagnose every failure and fix the cause.  Each change was
directed and reviewed.

### AI model used

Claude Opus 5 (claude-opus-5), through Claude Code.

### How AI was used for the contribution

- [ ] Formatting
- [ ] Test creation.
- [x] Code comments.
- [ ] The entire contribution was generated using AI
- [ ] AI code completion such as Copilot in VSCode.

The diagnosis and the implementation were produced in that session under my
direction, and the commit messages were drafted there.

### Access

I have not used a product which claims copyright in its output, and I have
legitimate access to the one I used.

-- 
View it on GitLab: 
https://gitlab.rtems.org/rtems/rtos/rtems/-/merge_requests/1485
You're receiving this email because of your account on gitlab.rtems.org. 
Unsubscribe from this thread: 
https://gitlab.rtems.org/-/namespace/49/sent_notifications/5-77kpf1p0773svg6iajxo1hda6-1d/unsubscribe
 | Manage all notifications: https://gitlab.rtems.org/-/profile/notifications | 
Help: https://gitlab.rtems.org/help


_______________________________________________
bugs mailing list
[email protected]
http://lists.rtems.org/mailman/listinfo/bugs

Reply via email to