From: linux@arm.linux.org.uk (Russell King - ARM Linux)
To: linux-arm-kernel@lists.infradead.org
Subject: CAS implementation may be broken
Date: Mon, 23 Nov 2009 15:08:42 +0000 [thread overview]
Message-ID: <20091123150842.GD18142@n2100.arm.linux.org.uk> (raw)
In-Reply-To: <4B08055C.3000408@45mercystreet.com>
On Sat, Nov 21, 2009 at 04:21:00PM +0100, Toby Douglass wrote:
> 382 do {
> 383 asm volatile("@ __cmpxchg4\n"
> 384 " ldrex %1, [%2]\n"
> 385 " mov %0, #0\n"
> 386 " teq %1, %3\n"
> 387 " strexeq %0, %4, [%2]\n"
> 388 : "=&r" (res), "=&r" (oldval)
> 389 : "r" (ptr), "Ir" (old), "r" (new)
> 390 : "memory", "cc");
> 391 } while (res);
>
> The problem is *we then come round in the do-while loop again*. We have
> *not* updated our exchange value. So THIS second time around, we
> *repeat* our strex and we DO swap - and we just swapped in completely
> the wrong next pointer, from way back before the stack was totally
> changed by all the other threads popping and pushing.
First time around the loop, lets say %3 = 1 *(u32 *)%2 = 1.
ldrex %1, [%2]
%1 = *(u32 *)%2 (= 1)
mov %0, #0
%0 = 0
teq %1, %3
%3 == %1? (yes)
strexeq %0, %4, [%2]
executed but because of the other access,
exclusivity fails. *(u32 *)%2 not written
and %0 = 1
So, res = 1, and we go around the loop again. Lets say that *(u32 *)%2 = 2
now.
ldrex %1, [%2]
%1 = *(u32 *)%2 (= 2)
mov %0, #0
%0 = 0
teq %1, %3
%3 == %1? (no)
strexeq %0, %4, [%2]
not executed at all, %0 and *(u32 *)%2 untouched
So, res = 0 and we do _not_ repeat the loop and return "cmpxchg" failure.
I haven't had time to read all your email properly (due to the need to
get on a conference call), but please tell me where the problem is above
(using a similar worked example).
Thanks.
next prev parent reply other threads:[~2009-11-23 15:08 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-11-04 18:09 GCC built-in atomic operations and memory barriers Toby Douglass
2009-11-04 19:05 ` Russell King - ARM Linux
2009-11-04 20:12 ` Toby Douglass
2009-11-04 21:03 ` Russell King - ARM Linux
2009-11-06 19:10 ` Toby Douglass
2009-11-04 22:09 ` Gilles Chanteperdrix
2009-11-06 19:17 ` Toby Douglass
2009-11-21 15:21 ` CAS implementation may be broken Toby Douglass
2009-11-23 15:08 ` Russell King - ARM Linux [this message]
2009-11-23 19:10 ` Toby Douglass
2009-11-23 20:06 ` Russell King - ARM Linux
2009-11-23 20:34 ` Toby Douglass
2009-11-23 15:13 ` Catalin Marinas
2009-11-24 15:15 ` Toby Douglass
2009-11-24 15:36 ` Russell King - ARM Linux
2009-11-24 16:20 ` Toby Douglass
2009-11-24 16:27 ` Catalin Marinas
2009-11-24 17:14 ` Toby Douglass
2009-11-25 1:24 ` Jamie Lokier
2009-11-26 16:14 ` Toby Douglass
2009-11-27 1:37 ` Jamie Lokier
2009-11-24 15:33 ` Toby Douglass
2009-11-23 15:34 ` Catalin Marinas
2009-11-23 16:40 ` Toby Douglass
2009-11-23 22:28 ` Jamie Lokier
2009-11-23 23:13 ` Russell King - ARM Linux
2009-11-24 1:32 ` Jamie Lokier
2009-11-24 11:19 ` Catalin Marinas
2009-11-24 22:24 ` Toby Douglass
2009-11-25 11:11 ` Catalin Marinas
2009-11-25 18:57 ` Toby Douglass
2009-11-24 22:34 ` Toby Douglass
2009-11-24 22:56 ` Russell King - ARM Linux
2009-11-25 0:34 ` Toby Douglass
2009-11-24 9:38 ` Toby Douglass
2009-11-24 15:59 ` Catalin Marinas
2009-11-24 16:34 ` Toby Douglass
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20091123150842.GD18142@n2100.arm.linux.org.uk \
--to=linux@arm.linux.org.uk \
--cc=linux-arm-kernel@lists.infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).