[PATCH v2 00/13] make signal handlers async-signal-safe
Stephen Hemminger
stephen at networkplumber.org
Mon Sep 7 19:03:18 CEST 2026
Signal handlers may only call the functions listed in signal-safety(7).
Many DPDK examples ignored this and did printf() a "preparing to exit"
message before setting the quit flag. A signal during another printf
call can deadlock. And some of the programs did even more
unsafe things.
GCC 14 -fanalyzer reports these:
warning: call to 'printf' from within signal handler [CWE-479]
[-Wanalyzer-unsafe-call-within-signal-handler]
The fix is the same throughout: the handler only sets the existing
volatile flag, and any real work moves to the main loop or to main()
after the lcores are joined. The message is dropped; the user pressed ^C
and knows a signal was sent.
Patches 1-2 only delete the printf(). Patches 3-13 also relocate work
that was being done in the handler.
Behaviour changes worth review:
- examples/ntb: SIGINT used to printf(), restore SIG_DFL and re-raise,
killing the process without stopping the forwarding lcores or closing
the devices. It now sets the per-lcore stopped flag, so SIGINT stops
forwarding and returns to the ntb> prompt; quit does the teardown.
- examples/vdpa: the teardown moved to main() now also closes the vDPA
devices when leaving interactive mode, which was missing before.
- examples/eventdev_pipeline: the second-signal escape hatch becomes
_exit() instead of rte_exit(), the --dump-dev exit dump moves to
main() (and uses the real dev_id rather than a hardcoded 0), and
SIGTSTP now sets cdata.dump_dev_signal, which schedule_devices()
already drained but nothing ever set. The SIGTSTP dump therefore
requires a scheduler lcore.
Only examples/ethtool and examples/vmdq_dcb carry a Fixes: tag; the rest
remove an unsafe call that has not been seen to deadlock in practice and
are cleanups rather than backport material.
Applications outside the analyzer's reach likely have the same pattern;
this covers what GCC flagged, plus eventdev_pipeline found by inspection.
Build tested with GCC 14 -fanalyzer; the warnings are gone for the files
touched.
v2 -- needed more work, the Claude version of examples_pipeline
was over complex and had build errors.
Stephen Hemminger (13):
graph: do not call printf in signal
examples: remove printf from signal handler
examples/vmdq: do not print from signal handler
examples/symmetric_mp: do not print or exit in handler
examples/vdpa: make signal handler safe
examples/vhost: make signal handler safe
examples/vhost_blk: do not tear down from signal handler
examples/ntb: do not print and re-raise from signal handler
examples/ipsecgw: do not print from signal handler
examples/l2fwd-macsec: remove print in signal handler
examples/ethtool: fix exit flag and unchecked cmdline
examples/vmdq_dcb: allow exit on signal
examples/eventdev_pipeline: make signal handler safe
app/graph/main.c | 4 +-
examples/distributor/main.c | 3 +-
examples/dma/dmafwd.c | 2 -
examples/ethtool/ethtool-app/ethapp.c | 5 +++
examples/ethtool/ethtool-app/main.c | 2 +-
examples/eventdev_pipeline/main.c | 41 ++++++++++++--------
examples/eventdev_pipeline/pipeline_common.h | 13 ++++---
examples/flow_filtering/main.c | 5 +--
examples/ipsec-secgw/ipsec-secgw.c | 5 +--
examples/l2fwd-event/main.c | 5 +--
examples/l2fwd-macsec/main.c | 5 +--
examples/l2fwd/main.c | 5 +--
examples/l3fwd-graph/main.c | 5 +--
examples/multi_process/symmetric_mp/main.c | 26 +++++++++----
examples/ntb/ntb_fwd.c | 16 +++++---
examples/vdpa/main.c | 16 ++++----
examples/vhost/main.c | 14 ++++---
examples/vhost_blk/vhost_blk.c | 26 +++++++------
examples/vmdq/main.c | 20 ++++++++--
examples/vmdq_dcb/main.c | 20 +++++++++-
20 files changed, 140 insertions(+), 98 deletions(-)
--
2.53.0
More information about the dev
mailing list