<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<html lang="en" style="--code-editor-font: var(--default-mono-font, "GitLab Mono"), JetBrains Mono, Menlo, DejaVu Sans Mono, Liberation Mono, Consolas, Ubuntu Mono, Courier New, andale mono, lucida console, monospace;">
<head>
<meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
<title>
GitLab
</title>
<style data-premailer="ignore" type="text/css">
a { color: #1068bf; }
</style>
<style>img {
max-width: 100%; height: auto;
}
body {
font-size: .875rem;
}
body {
-webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px;
}
body {
font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji"; font-size: inherit;
}
</style>
</head>
<body style="font-size: inherit; -webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px; font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji";">
<div class="content">
<p class="details" style="font-style: italic; color: #626168;">
Issue created by <a href="https://gitlab.rtems.org/sebhub">Sebastian Huber</a>: <a href="https://gitlab.rtems.org/rtems/rtos/rtems/-/work_items/5733">#5733</a>
</p>
<p>
Assignee: Sebastian Huber
</p>
<div class="md" style="position: relative; z-index: 1; color: #3a383f; word-wrap: break-word;">
<h2 id="user-content-summary" dir="auto" style="margin-top: 0px; margin-bottom: 10px;" align="initial">Summary<a href="#summary" aria-label="Link to heading 'Summary'" data-heading-content="Summary" class="anchor" style="margin-top: 0px;"></a>
</h2>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">This is a severe bug which should be fixed in all production systems.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">A thread timeout can cancel a wait which the thread started after that timeout
expired. The score has no way to name the wait which a timeout belongs to.
The thread then gets a wrong <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">STATUS_TIMEOUT</code> for an unrelated wait, or the
watchdog tree of a processor becomes corrupt and a later clock tick stops every
processor.</p>
<h2 id="user-content-the-mechanism" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">The mechanism<a href="#the-mechanism" aria-label="Link to heading 'The mechanism'" data-heading-content="The mechanism" class="anchor" style="margin-top: 0px;"></a>
</h2>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial"><code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">_Watchdog_Do_tickle()</code> extracts the node from the tree, sets it inactive and
releases the lock of the header. It calls the service routine after that. It
never acquires the <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">Timer.Lock</code> of the thread, which is the lock the arm and
the removal of a thread timer use.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">For a thread timer the routine is <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">_Thread_Timeout()</code>. That routine calls
<code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">_Thread_Continue()</code> with <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">STATUS_TIMEOUT</code>.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">Between the release of the header lock and the call, another party can satisfy
the wait. The <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">_Thread_Timer_remove()</code> of that party finds an inactive node
and reports success, although the routine is still in flight. The score has no
cancel and drain for a thread timer. The thread leaves its wait, continues,
and enters a new wait.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial"><code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">_Thread_Continue()</code> then acquires the wait lock of the new wait. It tests
<code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">wait_flags != THREAD_WAIT_STATE_READY</code> and derives the wait class from the
value it reads. Both tests pass for any wait, so it cancels the new one.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">The thread wait flags cannot separate one wait of a thread from the next. The
state runs <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">READY</code>, <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">INTEND_TO_BLOCK</code>, <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">BLOCKED</code>, <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">READY</code> and starts again. It
is a generation counter of three values which resets at every wait.</p>
<h2 id="user-content-what-the-cancel-leaves-behind" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">What the cancel leaves behind<a href="#what-the-cancel-leaves-behind" aria-label="Link to heading 'What the cancel leaves behind'" data-heading-content="What the cancel leaves behind" class="anchor" style="margin-top: 0px;"></a>
</h2>
<table dir="auto" style="border-spacing: 0; text-align: initial; color: #3a383f; width: auto; border-collapse: collapse; margin: 16px 0; border-width: 0;">
<thead style="margin-top: 0px;">
<tr style="margin-top: 0px;">
<th style="line-height: 1.25rem; color: #18171d; margin-top: 0px; padding: 10px 16px; border-color: #dcdcde; border-style: solid; border-width: 1px 1px 0;" valign="top">The new wait of the thread</th>
<th style="line-height: 1.25rem; color: #18171d; padding: 10px 16px; border-color: #dcdcde; border-style: solid; border-width: 1px 1px 0;" valign="top">Result</th>
</tr>
</thead>
<tbody>
<tr style="margin-top: 0px;">
<td style="line-height: 1.25rem; margin-top: 0px; padding: 10px 16px; border: 1px solid #dcdcde;" valign="top">carries a timeout</td>
<td style="line-height: 1.25rem; padding: 10px 16px; border: 1px solid #dcdcde;" valign="top">the watchdog it armed, still scheduled</td>
</tr>
<tr>
<td style="line-height: 1.25rem; margin-top: 0px; padding: 10px 16px; border: 1px solid #dcdcde;" valign="top">carries no timeout</td>
<td style="line-height: 1.25rem; padding: 10px 16px; border: 1px solid #dcdcde;" valign="top">a report of a timeout which never ran</td>
</tr>
</tbody>
</table>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">A leaked watchdog stays in the tree of a processor. The next timed wait of
that thread inserts the same node a second time. The red-black tree of that
processor is then corrupt. A later clock tick either traps in
<code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">_RBTree_Extract()</code> or turns in an endless loop with the lock of the tree held.
The second case stops every processor.</p>
<h2 id="user-content-exposure" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">Exposure<a href="#exposure" aria-label="Link to heading 'Exposure'" data-heading-content="Exposure" class="anchor" style="margin-top: 0px;"></a>
</h2>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">Every wait which <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">_Thread_Continue()</code> ends is exposed. That covers each call
which blocks on a thread queue, <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">rtems_event_receive()</code>,
<code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">rtems_task_wake_after()</code>, <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">rtems_task_wake_when()</code> and the POSIX counterparts
of these calls.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">On an SMP configuration the party which satisfies the wait is an interrupt
handler or a thread on another processor. The window is open on every timed
wait.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">On a uniprocessor configuration the window opens through <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">_TOD_Set()</code>. That
routine tickles the realtime header of each processor in task context.
<code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">rtems_clock_set()</code> holds a mutex and an ISR lock, and <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">_Timecounter_Set_clock()</code>
releases that ISR lock before the loop. Interrupts and thread dispatch are both
enabled while the loop calls <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">_Thread_Timeout()</code>.</p>
<h2 id="user-content-affected-versions" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">Affected versions<a href="#affected-versions" aria-label="Link to heading 'Affected versions'" data-heading-content="Affected versions" class="anchor" style="margin-top: 0px;"></a>
</h2>
<table dir="auto" style="border-spacing: 0; text-align: initial; color: #3a383f; width: auto; border-collapse: collapse; margin: 16px 0; border-width: 0;">
<thead style="margin-top: 0px;">
<tr style="margin-top: 0px;">
<th style="line-height: 1.25rem; color: #18171d; margin-top: 0px; padding: 10px 16px; border-color: #dcdcde; border-style: solid; border-width: 1px 1px 0;" valign="top">Change</th>
<th style="line-height: 1.25rem; color: #18171d; padding: 10px 16px; border-color: #dcdcde; border-style: solid; border-width: 1px 1px 0;" valign="top">Date</th>
<th style="line-height: 1.25rem; color: #18171d; padding: 10px 16px; border-color: #dcdcde; border-style: solid; border-width: 1px 1px 0;" valign="top">Releases</th>
</tr>
</thead>
<tbody>
<tr style="margin-top: 0px;">
<td style="line-height: 1.25rem; margin-top: 0px; padding: 10px 16px; border: 1px solid #dcdcde;" valign="top"><code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; white-space: pre-wrap; overflow-wrap: break-word; word-break: keep-all; padding: 0.125rem 0.25rem;">score: Add thread wait flags</code></td>
<td style="line-height: 1.25rem; padding: 10px 16px; border: 1px solid #dcdcde;" valign="top">2015-03-04</td>
<td style="line-height: 1.25rem; padding: 10px 16px; border: 1px solid #dcdcde;" valign="top">4.11 and later</td>
</tr>
<tr>
<td style="line-height: 1.25rem; margin-top: 0px; padding: 10px 16px; border: 1px solid #dcdcde;" valign="top"><code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; white-space: pre-wrap; overflow-wrap: break-word; word-break: keep-all; padding: 0.125rem 0.25rem;">score: Replace watchdog handler implementation</code></td>
<td style="line-height: 1.25rem; padding: 10px 16px; border: 1px solid #dcdcde;" valign="top">2016-02-18</td>
<td style="line-height: 1.25rem; padding: 10px 16px; border: 1px solid #dcdcde;" valign="top">5.1 and later</td>
</tr>
<tr>
<td style="line-height: 1.25rem; margin-top: 0px; padding: 10px 16px; border: 1px solid #dcdcde;" valign="top"><code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; white-space: pre-wrap; overflow-wrap: break-word; word-break: keep-all; padding: 0.125rem 0.25rem;">score: Add _Thread_Continue()</code></td>
<td style="line-height: 1.25rem; padding: 10px 16px; border: 1px solid #dcdcde;" valign="top">2017-10-19</td>
<td style="line-height: 1.25rem; padding: 10px 16px; border: 1px solid #dcdcde;" valign="top">5.1 and later</td>
</tr>
</tbody>
</table>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">The mechanism above is present in 5.1, 5.2, 5.3, 6.1, 6.2 and the development
head. Release 4.11 carries the thread wait flags but a different watchdog
handler. Nobody checked 4.11 against this defect.</p>
<h2 id="user-content-how-to-construct-the-defect-without-a-race" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">How to construct the defect without a race<a href="#how-to-construct-the-defect-without-a-race" aria-label="Link to heading 'How to construct the defect without a race'" data-heading-content="How to construct the defect without a race" class="anchor" style="margin-top: 0px;"></a>
</h2>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">The <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">_TOD_Set()</code> path makes the window deterministic on a single processor.</p>
<ol dir="auto" style="text-align: initial; margin: 0px 0px 1rem; padding: 0;">
<li style="margin-top: 0px; line-height: 1.6em; margin-left: 25px; padding-left: 3px;">A high priority task blocks on a semaphore with an absolute realtime
timeout.</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">A low priority task calls <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; white-space: pre-wrap; overflow-wrap: break-word; word-break: keep-all; padding: 0.125rem 0.25rem;">rtems_clock_set()</code> with a time past that expiry.</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">
<code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; white-space: pre-wrap; overflow-wrap: break-word; word-break: keep-all; padding: 0.125rem 0.25rem;">_TOD_Set()</code> extracts the watchdog, releases the header lock and calls
<code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; white-space: pre-wrap; overflow-wrap: break-word; word-break: keep-all; padding: 0.125rem 0.25rem;">_Thread_Timeout()</code>.</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">An interrupt releases the semaphore inside that window.</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">The high priority task preempts, returns from the wait and enters a second
wait.</li>
<li style="line-height: 1.6em; margin-left: 25px; padding-left: 3px;">The low priority task resumes and cancels the second wait.</li>
</ol>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">Without the defect the second wait stays intact. With the defect it reports a
timeout, and it leaks its watchdog when it carries one.</p>
<h2 id="user-content-the-repair" dir="auto" style="margin-top: 20px; margin-bottom: 10px;" align="initial">The repair<a href="#the-repair" aria-label="Link to heading 'The repair'" data-heading-content="The repair" class="anchor" style="margin-top: 0px;"></a>
</h2>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial">The thread wait flags word is an <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">unsigned int</code> and uses bits 0 to 15 only.
Bits 16 to 31 hold a generation which steps at every wait start. The watchdog
carries the generation which the arm wrote. <code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">_Watchdog_Do_tickle()</code> reads that
value under the header lock and passes it to the service routine. This is the
only transport which survives a second arm of the same node, because the arm of
the next wait overwrites every field of the node.</p>
<p dir="auto" style="color: #3a383f; margin: 0px 0px 1rem;" align="initial"><code style="font-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; font-weight: inherit; overflow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem 0.25rem;">_Thread_Timeout()</code> compares the value against the current generation under the
wait lock. On a mismatch it returns and touches nothing.</p>
<p dir="auto" style="color: #3a383f; margin: 0px;" align="initial">The bug report was created using Claude Code.</p>
</div>
</div>
<div class="footer" style="margin-top: 10px;">
<p style="font-size: small; color: #626168;">
—
<br>
<a href="https://gitlab.rtems.org/rtems/rtos/rtems/-/work_items/5733">View it on GitLab</a>.
<br>
You're receiving this email because of your account on <a target="_blank" rel="noopener noreferrer" href="https://gitlab.rtems.org">gitlab.rtems.org</a>. <a href="https://gitlab.rtems.org/-/sent_notifications/5-87dswag3ss2c6tl7w2xqxeg92-1d/unsubscribe" target="_blank" rel="noopener noreferrer">Unsubscribe</a> from this thread · <a href="https://gitlab.rtems.org/-/profile/notifications" target="_blank" rel="noopener noreferrer" class="mng-notif-link">Manage all notifications</a> · <a href="https://gitlab.rtems.org/help" target="_blank" rel="noopener noreferrer" class="help-link">Help</a>
<span style="color: transparent; font-size: 0; display: none; overflow: hidden; opacity: 0; width: 0; height: 0; max-width: 0; max-height: 0;">
Notification message regarding https://gitlab.rtems.org/rtems/rtos/rtems/-/work_items/5733 at 1788143830
</span>
<script type="application/ld+json">{"@context":"http://schema.org","@type":"EmailMessage","action":{"@type":"ViewAction","name":"View Work item","url":"https://gitlab.rtems.org/rtems/rtos/rtems/-/work_items/5733"}}</script>
</p>
</div>
</body>
</html>