From: Raghavendra K T <raghavendra.kt@linux.vnet.ibm.com>
To: Oleg Nesterov <oleg@redhat.com>
Cc: jeremy@goop.org, kvm@vger.kernel.org, peterz@infradead.org,
virtualization@lists.linux-foundation.org,
paul.gortmaker@windriver.com, hpa@zytor.com, ak@linux.intel.com,
a.ryabinin@samsung.com, x86@kernel.org, borntraeger@de.ibm.com,
mingo@redhat.com, xen-devel@lists.xenproject.org,
paulmck@linux.vnet.ibm.com, riel@redhat.com,
konrad.wilk@oracle.com, dave@stgolabs.net,
sasha.levin@oracle.com, davej@redhat.com, tglx@linutronix.de,
waiman.long@hp.com, linux-kernel@vger.kernel.org,
pbonzini@redhat.com, akpm@linux-foundation.org,
torvalds@linux-foundation.org
Subject: Re: [PATCH V3] x86 spinlock: Fix memory corruption on completing completions
Date: Thu, 12 Feb 2015 19:53:29 +0530 [thread overview]
Message-ID: <54DCB761.4050504@linux.vnet.ibm.com> (raw)
In-Reply-To: <20150212135056.GA10646@redhat.com>
On 02/12/2015 07:20 PM, Oleg Nesterov wrote:
> On 02/12, Raghavendra K T wrote:
>>
>> @@ -191,8 +189,7 @@ static inline void arch_spin_unlock_wait(arch_spinlock_t *lock)
>> * We need to check "unlocked" in a loop, tmp.head == head
>> * can be false positive because of overflow.
>> */
>> - if (tmp.head == (tmp.tail & ~TICKET_SLOWPATH_FLAG) ||
>> - tmp.head != head)
>> + if (__tickets_equal(tmp.head, tmp.tail) || tmp.head != head)
>> break;
>
> Ah, it seems that "tmp.head != head" should be turned into
> !__tickets_equal(), no?
>
> Suppose that TICKET_SLOWPATH_FLAG is set after the first ACCESS_ONCE(head),
> then tmp.head != head will be true before the first unlock we are waiting
> for.
Good catch. othewise we would wrongly break out even when somebody
does halt wait.
>
> And perhaps you can turn these ACCESS_ONCE into READ_ONCE as well.
Yes again :)
WARNING: multiple messages have this Message-ID (diff)
From: Raghavendra K T <raghavendra.kt@linux.vnet.ibm.com>
To: Oleg Nesterov <oleg@redhat.com>
Cc: tglx@linutronix.de, mingo@redhat.com, hpa@zytor.com,
peterz@infradead.org, torvalds@linux-foundation.org,
konrad.wilk@oracle.com, pbonzini@redhat.com,
paulmck@linux.vnet.ibm.com, waiman.long@hp.com, davej@redhat.com,
x86@kernel.org, jeremy@goop.org, paul.gortmaker@windriver.com,
ak@linux.intel.com, jasowang@redhat.com,
linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
virtualization@lists.linux-foundation.org,
xen-devel@lists.xenproject.org, riel@redhat.com,
borntraeger@de.ibm.com, akpm@linux-foundation.org,
a.ryabinin@samsung.com, sasha.levin@oracle.com,
dave@stgolabs.net
Subject: Re: [PATCH V3] x86 spinlock: Fix memory corruption on completing completions
Date: Thu, 12 Feb 2015 19:53:29 +0530 [thread overview]
Message-ID: <54DCB761.4050504@linux.vnet.ibm.com> (raw)
In-Reply-To: <20150212135056.GA10646@redhat.com>
On 02/12/2015 07:20 PM, Oleg Nesterov wrote:
> On 02/12, Raghavendra K T wrote:
>>
>> @@ -191,8 +189,7 @@ static inline void arch_spin_unlock_wait(arch_spinlock_t *lock)
>> * We need to check "unlocked" in a loop, tmp.head == head
>> * can be false positive because of overflow.
>> */
>> - if (tmp.head == (tmp.tail & ~TICKET_SLOWPATH_FLAG) ||
>> - tmp.head != head)
>> + if (__tickets_equal(tmp.head, tmp.tail) || tmp.head != head)
>> break;
>
> Ah, it seems that "tmp.head != head" should be turned into
> !__tickets_equal(), no?
>
> Suppose that TICKET_SLOWPATH_FLAG is set after the first ACCESS_ONCE(head),
> then tmp.head != head will be true before the first unlock we are waiting
> for.
Good catch. othewise we would wrongly break out even when somebody
does halt wait.
>
> And perhaps you can turn these ACCESS_ONCE into READ_ONCE as well.
Yes again :)
next prev parent reply other threads:[~2015-02-12 14:23 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-02-12 11:47 [PATCH V3] x86 spinlock: Fix memory corruption on completing completions Raghavendra K T
2015-02-12 11:47 ` Raghavendra K T
2015-02-12 11:47 ` Raghavendra K T
2015-02-12 13:37 ` Oleg Nesterov
2015-02-12 13:37 ` Oleg Nesterov
2015-02-12 13:37 ` Oleg Nesterov
2015-02-12 14:21 ` Raghavendra K T
2015-02-12 14:21 ` Raghavendra K T
2015-02-12 14:21 ` Raghavendra K T
2015-02-12 13:50 ` Oleg Nesterov
2015-02-12 13:50 ` Oleg Nesterov
2015-02-12 14:23 ` Raghavendra K T
2015-02-12 14:23 ` Raghavendra K T [this message]
2015-02-12 14:23 ` Raghavendra K T
2015-02-12 13:50 ` Oleg Nesterov
2015-02-12 14:02 ` Oleg Nesterov
2015-02-12 14:02 ` Oleg Nesterov
2015-02-12 14:02 ` Oleg Nesterov
2015-02-12 14:25 ` Raghavendra K T
2015-02-12 14:25 ` Raghavendra K T
2015-02-12 14:25 ` Raghavendra K T
2015-02-12 15:00 ` Peter Zijlstra
2015-02-12 15:00 ` Peter Zijlstra
2015-02-12 15:00 ` Peter Zijlstra
2015-02-12 15:28 ` Raghavendra K T
2015-02-12 15:28 ` Raghavendra K T
2015-02-12 15:28 ` Raghavendra K T
-- strict thread matches above, loose matches on Subject: below --
2015-02-12 11:47 Raghavendra K T
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=54DCB761.4050504@linux.vnet.ibm.com \
--to=raghavendra.kt@linux.vnet.ibm.com \
--cc=a.ryabinin@samsung.com \
--cc=ak@linux.intel.com \
--cc=akpm@linux-foundation.org \
--cc=borntraeger@de.ibm.com \
--cc=dave@stgolabs.net \
--cc=davej@redhat.com \
--cc=hpa@zytor.com \
--cc=jeremy@goop.org \
--cc=konrad.wilk@oracle.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=oleg@redhat.com \
--cc=paul.gortmaker@windriver.com \
--cc=paulmck@linux.vnet.ibm.com \
--cc=pbonzini@redhat.com \
--cc=peterz@infradead.org \
--cc=riel@redhat.com \
--cc=sasha.levin@oracle.com \
--cc=tglx@linutronix.de \
--cc=torvalds@linux-foundation.org \
--cc=virtualization@lists.linux-foundation.org \
--cc=waiman.long@hp.com \
--cc=x86@kernel.org \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.