From: David Laight <david.laight.linux@gmail.com>
To: Mark Rutland <mark.rutland@arm.com>
Cc: vladimir.murzin@arm.com, ryan.roberts@arm.com,
peterz@infradead.org, catalin.marinas@arm.com,
ruanjinjie@huawei.com, stable@vger.kernel.org,
james.morse@arm.com, yang@os.amperecomputing.com, cl@gentwo.org,
maz@kernel.org, david@kernel.org, ljs@kernel.org,
will@kernel.org, ardb@kernel.org,
linux-arm-kernel@lists.infradead.org
Subject: Re: [PATCH v2 02/20] arm64: percpu: Fix this_cpu_and() mask generation
Date: Thu, 6 Aug 2026 09:28:15 +0100 [thread overview]
Message-ID: <20260806092815.082c6b2a@pumpkin> (raw)
In-Reply-To: <anM0S1jVmwO0mqEt@J2N7QTR9R3>
On Wed, 5 Aug 2026 14:02:03 +0100
Mark Rutland <mark.rutland@arm.com> wrote:
> On Wed, Aug 05, 2026 at 10:14:16AM +0100, David Laight wrote:
> > On Tue, 4 Aug 2026 18:04:45 +0100
> > Mark Rutland <mark.rutland@arm.com> wrote:
> >
> > > The arm64 implementation of this_cpu_and(pcp, val) is built in terms of
> > > ANDNOT operations, which requires the 'val' argument to be bitwise
> > > negated. The bitwise negation is not implemented correctly, with two
> > > bugs described below.
> > >
> > > (1) The bitwise negation is performed as '~val' rather than '~(val)'.
> > > This won't always generate the expected value when 'val' is an
> > > expression.
> > >
> > > For example, for this_cpu_and(pcp, 1 - 1):
> > >
> > > * 'val' is '1 - 1' ===> (int) 0x00000000
> > > * '~val' is '~1 - 1' ===> (int) 0xfffffffd
> > > * '~(val)' is '~(1 - 1)' ===> (int) 0xffffffff
> > >
> > > ... and thus bit[1] of 'pcp' would be preserved unexpectedly by the
> > > ANDNOT operation.
> > >
> > > (2) The bitwise negation is performed on 'val' before it has been cast
> > > to (at least) the width of 'pcp'. This won't always generate the
> > > expected value for the upper bits.
> > >
> > > For example, for this_cpu_and(pcp, zero), where 'pcp' is a u64 and
> > > 'zero' is a u32:
> > >
> > > * 'zero' ===> (u32) 0x00000000
> > > * '~(zero)' ===> (u32) 0xffffffff
> > > * '(u64)~(zero)' ===> (u64) 0x00000000ffffffff
> > > * '~((u64)(zero))' ===> (u64) 0xffffffffffffffff
> > >
> > > ... and thus bits[63:32] of 'pcp' would be preserved unexpectedly by
> > > the ANDNOT operation.
> > >
> > > Fix these issues by adding brackets around 'val', and by casting 'val'
> > > to an appropriately-sized type before bitwise negation.
...
> > > #define this_cpu_and_8(pcp, val) \
> > > - _pcp_protect(__percpu_andnot_case_64, pcp, ~val)
> > > + _pcp_protect(__percpu_andnot_case_64, pcp, ~(u64)(val))
> >
> > This one still isn't right.
> > If val is a signed int with a negative value then it is sign extended
> > before being inverted.
> > val (int)0x80000000
> > (u64)(val) 0xffffffff80000000
> > ~(u64)(val) 0x000000007fffffff
> > Something like ~(u64)((val) + 0u) will DTRT.
>
> As above, where have you got that idea from?
>
> AFAICT, a smaller signed type *should* be sign extended, and that must
> happen before bitwise negation, since that bitwise negation is to cancel
> out the NOT part of the ANDNOT operation.
>
> Think:
>
> 'pcp' is (u64) 0x0123456789abcdef
> 'val' is (int) 0x800000000
> '(u64)(val)' is (u64) 0xffffffff80000000
> 'pcp & (u64)(val)' is (u64) 0x0123456780000000
>
> '~(u64)(val)' is (u64) 0x000000007fffffff
> 'pcp ANDNOT ~(u64)(val)' is (u64) 0x0123456780000000
The problem tends to arise with (u8)128 << 24 which is signed even
though that is never intended.
To my mind sign extension prior to and/or operations is almost
certainly unexpected.
David
next prev parent reply other threads:[~2026-08-06 8:28 UTC|newest]
Thread overview: 42+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 17:04 [PATCH v2 00/20] arm64: Preemptible this_cpu_*() operations Mark Rutland
2026-08-04 17:04 ` [PATCH v2 01/20] arm64: percpu: Fix this_cpu_write() casting Mark Rutland
2026-08-05 8:37 ` David Laight
2026-08-07 4:00 ` Jinjie Ruan
2026-08-04 17:04 ` [PATCH v2 02/20] arm64: percpu: Fix this_cpu_and() mask generation Mark Rutland
2026-08-05 9:14 ` David Laight
2026-08-05 13:02 ` Mark Rutland
2026-08-06 8:28 ` David Laight [this message]
2026-08-06 10:23 ` Mark Rutland
2026-08-07 9:52 ` Jinjie Ruan
2026-08-04 17:04 ` [PATCH v2 03/20] arm64: cmpxchg: LL/SC: Avoid redundant extension Mark Rutland
2026-08-04 17:04 ` [PATCH v2 04/20] arm64: cmpxchg128: LSE: Remove redundant operands Mark Rutland
2026-08-04 17:04 ` [PATCH v2 05/20] arm64: preempt: Simplify and optimize __preempt_count_dec_and_test() Mark Rutland
2026-08-04 17:04 ` [PATCH v2 06/20] arm64: preempt: Treat should_resched() as unlikely Mark Rutland
2026-08-04 17:04 ` [PATCH v2 07/20] arm64: ptrace: Always inline pt_regs_[read,write}_reg() Mark Rutland
2026-08-04 17:04 ` [PATCH v2 08/20] arm64: percpu: Factor out percpu offset asm Mark Rutland
2026-08-04 17:04 ` [PATCH v2 09/20] arm64: gpr-num: Add wxN aliases for wN registers Mark Rutland
2026-08-04 17:04 ` [PATCH v2 10/20] arm64: gpr-num: add __GPR_NUM() helper Mark Rutland
2026-08-04 17:04 ` [PATCH v2 11/20] arm64: entry: sdei: Restore all clobberable GPRs Mark Rutland
2026-08-07 11:35 ` Mark Rutland
2026-08-04 17:04 ` [PATCH v2 12/20] arm64: entry: sdei: Make 'tsk' available Mark Rutland
2026-08-04 17:04 ` [PATCH v2 13/20] arm64: percpu: Add infrastructure for preemptible this_cpu_*() ops Mark Rutland
2026-08-04 22:45 ` Pedro Falcato
2026-08-05 10:27 ` David Laight
2026-08-05 12:50 ` Pedro Falcato
2026-08-05 6:45 ` David Hildenbrand (Arm)
2026-08-05 6:47 ` David Hildenbrand (Arm)
2026-08-06 11:21 ` Mark Rutland
2026-08-06 11:32 ` David Hildenbrand (Arm)
2026-08-06 12:02 ` Mark Rutland
2026-08-06 13:25 ` David Laight
2026-08-06 13:30 ` David Hildenbrand (Arm)
2026-08-04 17:04 ` [PATCH v2 14/20] arm64: percpu: Implement preemptible read/write ops Mark Rutland
2026-08-05 9:24 ` Ryan Roberts
2026-08-05 12:08 ` David Laight
2026-08-05 13:34 ` Mark Rutland
2026-08-04 17:04 ` [PATCH v2 15/20] arm64: percpu: Implement preemptible void RMW ops Mark Rutland
2026-08-04 17:04 ` [PATCH v2 16/20] arm64: percpu: Implement preemptible return " Mark Rutland
2026-08-04 17:05 ` [PATCH v2 17/20] arm64: percpu: Implement preemptible XCHG ops Mark Rutland
2026-08-04 17:05 ` [PATCH v2 18/20] arm64: percpu: Implement preemptible CMPXCHG ops Mark Rutland
2026-08-04 17:05 ` [PATCH v2 19/20] arm64: percpu: Implement preemptible CMPXCHG128 ops Mark Rutland
2026-08-04 17:05 ` [PATCH v2 20/20] arm64: percpu: Remove _pcp_protect*() wrappers Mark Rutland
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260806092815.082c6b2a@pumpkin \
--to=david.laight.linux@gmail.com \
--cc=ardb@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=cl@gentwo.org \
--cc=david@kernel.org \
--cc=james.morse@arm.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=ljs@kernel.org \
--cc=mark.rutland@arm.com \
--cc=maz@kernel.org \
--cc=peterz@infradead.org \
--cc=ruanjinjie@huawei.com \
--cc=ryan.roberts@arm.com \
--cc=stable@vger.kernel.org \
--cc=vladimir.murzin@arm.com \
--cc=will@kernel.org \
--cc=yang@os.amperecomputing.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.