From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.8 required=3.0 tests=HEADER_FROM_DIFFERENT_DOMAINS, INCLUDES_PATCH,MAILING_LIST_MULTI,SIGNED_OFF_BY,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1BC2CC10F27 for ; Mon, 9 Mar 2020 16:40:14 +0000 (UTC) Received: from gabe.freedesktop.org (gabe.freedesktop.org [131.252.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id E6F5524655 for ; Mon, 9 Mar 2020 16:40:13 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org E6F5524655 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=linux.intel.com Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=intel-gfx-bounces@lists.freedesktop.org Received: from gabe.freedesktop.org (localhost [127.0.0.1]) by gabe.freedesktop.org (Postfix) with ESMTP id 7E1C9883C5; Mon, 9 Mar 2020 16:40:13 +0000 (UTC) Received: from mga12.intel.com (mga12.intel.com [192.55.52.136]) by gabe.freedesktop.org (Postfix) with ESMTPS id 04E96883C5 for ; Mon, 9 Mar 2020 16:40:11 +0000 (UTC) X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from fmsmga002.fm.intel.com ([10.253.24.26]) by fmsmga106.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 09 Mar 2020 09:40:11 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.70,533,1574150400"; d="scan'208";a="276583300" Received: from gaia.fi.intel.com ([10.237.72.192]) by fmsmga002.fm.intel.com with ESMTP; 09 Mar 2020 09:40:10 -0700 Received: by gaia.fi.intel.com (Postfix, from userid 1000) id 020275C1DD1; Mon, 9 Mar 2020 18:38:49 +0200 (EET) From: Mika Kuoppala To: Chris Wilson , intel-gfx@lists.freedesktop.org In-Reply-To: <158377077310.4769.2840055823228121182@build.alporthouse.com> References: <20200309112431.13903-1-chris@chris-wilson.co.uk> <87eeu135kf.fsf@gaia.fi.intel.com> <158377077310.4769.2840055823228121182@build.alporthouse.com> Date: Mon, 09 Mar 2020 18:38:49 +0200 Message-ID: <878sk932li.fsf@gaia.fi.intel.com> MIME-Version: 1.0 Subject: Re: [Intel-gfx] [PATCH] drm/i915/gt: Defend against concurrent updates to execlists->active X-BeenThere: intel-gfx@lists.freedesktop.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Intel graphics driver community testing & development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: intel-gfx-bounces@lists.freedesktop.org Sender: "Intel-gfx" Chris Wilson writes: > Quoting Mika Kuoppala (2020-03-09 15:34:40) >> Chris Wilson writes: >> >> > [ 206.875637] BUG: KCSAN: data-race in __i915_schedule+0x7fc/0x930 [i915] >> > [ 206.875654] >> > [ 206.875666] race at unknown origin, with read to 0xffff8881f7644480 of 8 bytes by task 703 on cpu 3: >> > [ 206.875901] __i915_schedule+0x7fc/0x930 [i915] >> > [ 206.876130] __bump_priority+0x63/0x80 [i915] >> > [ 206.876361] __i915_sched_node_add_dependency+0x258/0x300 [i915] >> > [ 206.876593] i915_sched_node_add_dependency+0x50/0xa0 [i915] >> > [ 206.876824] i915_request_await_dma_fence+0x1da/0x530 [i915] >> > [ 206.877057] i915_request_await_object+0x2fe/0x470 [i915] >> > [ 206.877287] i915_gem_do_execbuffer+0x45dc/0x4c20 [i915] >> > [ 206.877517] i915_gem_execbuffer2_ioctl+0x2c3/0x580 [i915] >> > [ 206.877535] drm_ioctl_kernel+0xe4/0x120 >> > [ 206.877549] drm_ioctl+0x297/0x4c7 >> > [ 206.877563] ksys_ioctl+0x89/0xb0 >> > [ 206.877577] __x64_sys_ioctl+0x42/0x60 >> > [ 206.877591] do_syscall_64+0x6e/0x2c0 >> > [ 206.877606] entry_SYSCALL_64_after_hwframe+0x44/0xa9 >> > >> > References: https://gitlab.freedesktop.org/drm/intel/issues/1318 >> > Signed-off-by: Chris Wilson >> > --- >> > drivers/gpu/drm/i915/gt/intel_engine.h | 12 +++++++++++- >> > 1 file changed, 11 insertions(+), 1 deletion(-) >> > >> > diff --git a/drivers/gpu/drm/i915/gt/intel_engine.h b/drivers/gpu/drm/i915/gt/intel_engine.h >> > index 29c8c03c5caa..f267f51c457c 100644 >> > --- a/drivers/gpu/drm/i915/gt/intel_engine.h >> > +++ b/drivers/gpu/drm/i915/gt/intel_engine.h >> > @@ -107,7 +107,17 @@ execlists_num_ports(const struct intel_engine_execlists * const execlists) >> > static inline struct i915_request * >> > execlists_active(const struct intel_engine_execlists *execlists) >> > { >> > - return *READ_ONCE(execlists->active); >> > + struct i915_request * const *cur = READ_ONCE(execlists->active); >> > + struct i915_request * const *old; >> > + struct i915_request *active; >> > + >> > + do { >> > + old = cur; >> > + active = READ_ONCE(*cur); >> > + cur = READ_ONCE(execlists->active); >> > + } while (cur != old); >> > + >> > + return active; >> >> The updated side is scary. We are updating the execlists->active >> in two phases and handling the array copying in between. >> >> as WRITE_ONCE only guarantees ordering inside one context, due to >> it is for compiler only, it makes me very suspicious about >> how the memcpy of pending->inflight might unravel between two cpus. >> >> smb_store_mb(execlists->active, execlists->pending); >> memcpy(inflight, pending) >> smb_wmb(); >> smb_store_mb(execlists->active, execlists->inflight); >> smb_store_mb(execlists->pending[0], NULL); > > Not quite. You've overkill on the mb there. > > If you want to be pedantic, > > WRITE_ONCE(active, pending); > smp_wmb(); > > memcpy(inflight, pending); > smp_wmb(); > WRITE_ONCE(active, inflight); This is the crux of it, needing rmb counterpart. -Mika > > The update of pending is not part of this sequence. > > But do we need that, and I still think we do not. > >> This in paired with: >> >> active = READ_ONCE(*cur); >> smb_rmb(); >> cur = READ_ONCE(execlists->active); >> >> With this, it should not matter at which point the execlists->active >> is sampled as the pending would be guaranteed to be >> immutable if it sampled early and inflight immutable if it >> sampled late? > > Simply because we don't care about the sampling, just that the read > dependency gives us a valid pointer. (We are not looking at a snapshot > of several reads, but a _single_ read and the data dependency from > that.) > -Chris _______________________________________________ Intel-gfx mailing list Intel-gfx@lists.freedesktop.org https://lists.freedesktop.org/mailman/listinfo/intel-gfx