All of lore.kernel.org
 help / color / mirror / Atom feed
From: Magnus Lindholm <linmag7@gmail.com>
To: richard.henderson@linaro.org, mattst88@gmail.com,
	linux-kernel@vger.kernel.org, linux-alpha@vger.kernel.org
Cc: glaubitz@physik.fu-berlin.de, mcree@orcon.net.nz,
	ink@unseen.parts, macro@orcam.me.uk,
	Magnus Lindholm <linmag7@gmail.com>
Subject: [PATCH 3/6] alpha: fix the local TLB invalidate in flush_tlb_page()
Date: Sun,  9 Aug 2026 10:49:35 +0200	[thread overview]
Message-ID: <20260809085208.3262799-4-linmag7@gmail.com> (raw)
In-Reply-To: <20260809085208.3262799-1-linmag7@gmail.com>

flush_tlb_page() invalidates the calling CPU itself before asking the
others, and gates that on current->active_mm. For a non-executable vma
that means a targeted tbi(2, addr), which acts on the context currently
loaded, so as in the IPI handler it reaches nothing when only active_mm
names the mm, and nothing forces the old ASN to be retired afterwards.

Test current->mm instead. When no thread of the mm is current, clear
mm->context[cpu] so a fresh ASN is taken at the next switch. That also
covers the case where the mm is not this CPU's active_mm at all: the CPU
may still hold translations for it, and smp_call_function() does not call
back into the caller.

Reached in practice by folio_mkclean() from the writeback flusher
kworker, which has no mm of its own: about half the calls during
writeback of a shared mapping, and none at all on anonymous memory.

flush_tlb_mm() does not need the same active_mm to current->mm change,
because its active_mm path loads a new context rather than issuing a
targeted tbi(). It does have the separate caller-CPU omission when the
target mm is not active_mm; that is fixed in the following patch.

Signed-off-by: Magnus Lindholm <linmag7@gmail.com>
---
 arch/alpha/kernel/smp.c | 12 +++++++++++-
 1 file changed, 11 insertions(+), 1 deletion(-)

diff --git a/arch/alpha/kernel/smp.c b/arch/alpha/kernel/smp.c
index 0dfe29b59039..d167b3ba1303 100644
--- a/arch/alpha/kernel/smp.c
+++ b/arch/alpha/kernel/smp.c
@@ -696,7 +696,15 @@ flush_tlb_page(struct vm_area_struct *vma, unsigned long addr)
 
 	preempt_disable();
 
-	if (mm == current->active_mm) {
+	/*
+	 * As in ipi_flush_tlb_page(): the targeted tbi() reaches MM's
+	 * translations only when a thread of MM is current, so test
+	 * current->mm.  Otherwise - lazily borrowing MM, or not running it
+	 * at all - clear mm->context[cpu] so a fresh ASN is taken at the
+	 * next switch.  smp_call_function() below does not call back into
+	 * this CPU, so this is the only chance to retire what it holds.
+	 */
+	if (mm == current->mm) {
 		flush_tlb_current_page(mm, vma, addr);
 		if (atomic_read(&mm->mm_users) <= 1) {
 			int cpu, this_cpu = smp_processor_id();
@@ -709,6 +717,8 @@ flush_tlb_page(struct vm_area_struct *vma, unsigned long addr)
 			preempt_enable();
 			return;
 		}
+	} else {
+		flush_tlb_other(mm);
 	}
 
 	data.vma = vma;
-- 
2.53.0


  parent reply	other threads:[~2026-08-09  8:55 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-09  8:49 [PATCH 0/6] alpha: fix stale TLB translations breaking copy-on-write and writeback Magnus Lindholm
2026-08-09  8:49 ` [PATCH 1/6] alpha: run check_mmu_context() from finish_arch_post_lock_switch() Magnus Lindholm
2026-08-09  8:49 ` [PATCH 2/6] alpha: only use a targeted tbi() when the target mm is really current Magnus Lindholm
2026-08-09  8:49 ` Magnus Lindholm [this message]
2026-08-09  8:49 ` [PATCH 4/6] alpha: only use a targeted tbi() when the target mm is really current (UP) Magnus Lindholm
2026-08-09  8:49 ` [PATCH 5/6] alpha: invalidate the local context in flush_tlb_mm() Magnus Lindholm
2026-08-09  8:49 ` [PATCH 6/6] alpha: invalidate the local context in flush_icache_user_page() Magnus Lindholm

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260809085208.3262799-4-linmag7@gmail.com \
    --to=linmag7@gmail.com \
    --cc=glaubitz@physik.fu-berlin.de \
    --cc=ink@unseen.parts \
    --cc=linux-alpha@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=macro@orcam.me.uk \
    --cc=mattst88@gmail.com \
    --cc=mcree@orcon.net.nz \
    --cc=richard.henderson@linaro.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.