From: Akira Yokosawa <akiyks@gmail.com>
To: Kunwu Chan <kunwu.chan@gmail.com>
Cc: linux-doc@vger.kernel.org, lkmm@lists.linux.dev,
linux-arch@vger.kernel.org, linux-kernel@vger.kernel.org,
rdunlap@infradead.org, skhan@linuxfoundation.org,
paulmck@kernel.org, dlustig@nvidia.com, joelagnelf@nvidia.com,
corbet@lwn.net, luc.maranget@inria.fr, j.alglave@ucl.ac.uk,
dhowells@redhat.com, npiggin@gmail.com, boqun@kernel.org,
peterz@infradead.org, will@kernel.org, parri.andrea@gmail.com,
stern@rowland.harvard.edu
Subject: Re: [PATCH v2 1/2] Documentation/litmus-tests: Add SRCU fastpath anchor-before-scan test
Date: Sun, 13 Sep 2026 18:48:18 +0900 [thread overview]
Message-ID: <892d82bf-aff4-4b0c-9585-8438280b45b1@gmail.com> (raw)
In-Reply-To: <20260912024225.2872265-2-kunwu.chan@gmail.com>
Hi,
This is more of a knee-jerk reaction, but
On Sat, 12 Sep 2026 10:42:24 +0800, Kunwu Chan wrote:
> synchronize_srcu_atomic() may end its grace period immediately when
> its scan of the per-CPU lock counters finds no readers. Correctness
> requires the grace-period anchor written by srcu_gp_start() to precede
> the smp_mb() ordering the lock scan. This ordering ensures that any
> reader whose lock increment is missed by the scan cannot have
> incremented its lock counter before the grace-period anchor, and
> therefore cannot be a pre-existing reader of this grace period.
>
> This litmus test models the key ordering between the grace-period
> anchor and the lock counter scan, where "seq" models the
> grace-period anchor in ->srcu_gp_seq and "ctr" models the per-CPU
> ->srcu_ctrs[].srcu_locks counter. P0 writes the anchor before the
> smp_mb() and the lock scan. P1 models the reader-side counter
> increment, with the smp_mb() of __srcu_read_lock() following the
> increment. P2 models an observer that sees the reader's increment
> before seeing the anchor.
>
> The outcome is forbidden by LKMM, and herd7 reports "Never". See
> SRCU-fastpath-scan-before-anchor.litmus for the reversed ordering,
> which permits this outcome.
>
> Tested with herd7 7.58 using linux-kernel.cfg.
>
> Signed-off-by: Kunwu Chan <kunwu.chan@gmail.com>
> ---
> .../SRCU-fastpath-anchor-before-scan.litmus | 57 +++++++++++++++++++
> 1 file changed, 57 insertions(+)
> create mode 100644 Documentation/litmus-tests/srcu/SRCU-fastpath-anchor-before-scan.litmus
>
> diff --git a/Documentation/litmus-tests/srcu/SRCU-fastpath-anchor-before-scan.litmus b/Documentation/litmus-tests/srcu/SRCU-fastpath-anchor-before-scan.litmus
> new file mode 100644
> index 000000000000..efa9c0c4e047
> --- /dev/null
> +++ b/Documentation/litmus-tests/srcu/SRCU-fastpath-anchor-before-scan.litmus
> @@ -0,0 +1,57 @@
> +C SRCU-fastpath-anchor-before-scan
> +
> +(*
> + * Result: Never
> + *
> + * The synchronize_srcu_atomic() fastpath may end its grace period
> + * immediately when its scan of the per-CPU lock counters finds no
> + * readers. Correctness requires the grace-period anchor written by
> + * srcu_gp_start() to precede the smp_mb() ordering the lock scan.
> + * This ordering ensures that any reader whose lock increment is missed
> + * by the scan cannot have incremented its lock counter before the
> + * grace-period anchor, and therefore cannot be a pre-existing reader
> + * of this grace period.
> + *
> + * This litmus test models the key ordering between the grace-period
> + * anchor and the lock counter scan, where "seq" models the
> + * grace-period anchor in ->srcu_gp_seq and "ctr" models the per-CPU
> + * ->srcu_ctrs[].srcu_locks counter. P0 writes the anchor before the
> + * smp_mb() and the lock scan. P1 models the reader-side counter
> + * increment, with the smp_mb() of __srcu_read_lock() following the
> + * increment. P2 models an observer that sees the reader's increment
> + * before seeing the anchor.
> + *
> + * The outcome is forbidden by LKMM, and herd7 reports "Never". See
> + * SRCU-fastpath-scan-before-anchor.litmus for the reversed ordering,
> + * which permits this outcome.
> + *)
> +
> +{}
> +
> +P0(int *seq, int *ctr)
> +{
> + int r2;
> +
> + WRITE_ONCE(*seq, 1);
> + smp_mb();
> + r2 = READ_ONCE(*ctr);
> +}
> +
> +P1(int *ctr)
> +{
> + WRITE_ONCE(*ctr, 1);
> + smp_mb();
> +}
As P1() has a single memory access, this smp_mb() can't have any
effect on the outcome.
The one you see in "__srcu_read_lock() following the increment" is
there for other ordering requirements, I guess.
Ditto smp_mb() in P1() of 2/2.
Thanks, Akira
> +
> +P2(int *seq, int *ctr)
> +{
> + int r3;
> + int r4;
> +
> + r3 = READ_ONCE(*ctr);
> + smp_mb();
> + r4 = READ_ONCE(*seq);
> +}
> +
> +filter (0:r2 = 0)
> +exists (2:r3 = 1 /\ 2:r4 = 0)
> --
> 2.43.0
next prev parent reply other threads:[~2026-09-13 9:48 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-12 2:42 [PATCH v2 0/2] Documentation/litmus-tests: Add SRCU fastpath litmus tests Kunwu Chan
2026-09-12 2:42 ` [PATCH v2 1/2] Documentation/litmus-tests: Add SRCU fastpath anchor-before-scan test Kunwu Chan
2026-09-13 9:48 ` Akira Yokosawa [this message]
2026-09-12 2:42 ` [PATCH v2 2/2] Documentation/litmus-tests: Add SRCU fastpath scan-before-anchor test Kunwu Chan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=892d82bf-aff4-4b0c-9585-8438280b45b1@gmail.com \
--to=akiyks@gmail.com \
--cc=boqun@kernel.org \
--cc=corbet@lwn.net \
--cc=dhowells@redhat.com \
--cc=dlustig@nvidia.com \
--cc=j.alglave@ucl.ac.uk \
--cc=joelagnelf@nvidia.com \
--cc=kunwu.chan@gmail.com \
--cc=linux-arch@vger.kernel.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lkmm@lists.linux.dev \
--cc=luc.maranget@inria.fr \
--cc=npiggin@gmail.com \
--cc=parri.andrea@gmail.com \
--cc=paulmck@kernel.org \
--cc=peterz@infradead.org \
--cc=rdunlap@infradead.org \
--cc=skhan@linuxfoundation.org \
--cc=stern@rowland.harvard.edu \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.