From: Bradley Morgan <brads@mainlining.org>
To: ruanjinjie@huawei.com
Cc: adilger.kernel@dilger.ca, akpm@linux-foundation.org,
andriy.shevchenko@linux.intel.com, bcrl@kvack.org,
brauner@kernel.org, jack@suse.cz, kees@kernel.org,
libaokun@linux.alibaba.com, linux-aio@kvack.org,
linux-ext4@vger.kernel.org, linux-fsdevel@vger.kernel.org,
linux-kernel@vger.kernel.org, linux@rasmusvillemoes.dk,
ojaswin@linux.ibm.com, pmladek@suse.com, ritesh.list@gmail.com,
rostedt@goodmis.org, senozhatsky@chromium.org,
sforshee@kernel.org, tglx@kernel.org, tytso@mit.edu,
viro@zeniv.linux.org.uk, yi.zhang@huawei.com
Subject: Re: [PATCH v3 1/8] user_namespace: Use acquire/release for nr_extents synchronization
Date: Wed, 02 Sep 2026 11:09:15 +0100 [thread overview]
Message-ID: <0303FE1D-8F56-4C18-87DA-9C3BBF2D43AE@mainlining.org> (raw)
In-Reply-To: <20260902074805.398540-2-ruanjinjie@huawei.com>
On 2 September 2026 08:47:58 BST, Jinjie Ruan <ruanjinjie@huawei.com>
wrote:
>Replace smp_wmb()/smp_rmb() with smp_store_release()/smp_load_acquire()
>when publishing and consuming `nr_extents`. This expresses the
>publish/subscribe pattern more clearly and allows architectures with
>native acquire/release instructions (e.g. arm64's STLR/LDAR) to avoid
>the cost of full one-way barriers (DMB ISHST/ISHLD).
>
>No functional change intended.
>
>Cc: Alexander Viro <viro@zeniv.linux.org.uk>
>Cc: Christian Brauner <brauner@kernel.org>
>Cc: Jan Kara <jack@suse.cz>
>Cc: Seth Forshee <sforshee@kernel.org>
>Cc: Kees Cook <kees@kernel.org>
>Cc: Aleksa Sarai <cyphar@cyphar.com>
>Assisted-by: DeepSeek:DeepSeek-V3
LGTM, thanks
Reviewed-by: Bradley Morgan <brads@mainlining.org>
>Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com>
>---
>v2:
>- Add missing load replace in copy_mnt_idmap()
>---
> fs/mnt_idmapping.c | 5 ++---
> kernel/user_namespace.c | 24 +++++++++++++-----------
> 2 files changed, 15 insertions(+), 14 deletions(-)
>
>diff --git a/fs/mnt_idmapping.c b/fs/mnt_idmapping.c
>index cb61fbdb52e9..612b266ab3da 100644
>--- a/fs/mnt_idmapping.c
>+++ b/fs/mnt_idmapping.c
>@@ -219,10 +219,9 @@ EXPORT_SYMBOL_GPL(vfsgid_in_group_p);
> static int copy_mnt_idmap(struct uid_gid_map *map_from,
> struct uid_gid_map *map_to)
> {
>+ /* Pairs with smp_store_release() in map_write(). */
>+ u32 nr_extents = smp_load_acquire(&map_from->nr_extents);
> struct uid_gid_extent *forward, *reverse;
>- u32 nr_extents = READ_ONCE(map_from->nr_extents);
>- /* Pairs with smp_wmb() when writing the idmapping. */
>- smp_rmb();
>
> /*
> * Don't blindly copy @map_to into @map_from if nr_extents is
>diff --git a/kernel/user_namespace.c b/kernel/user_namespace.c
>index 0bed462e9b2a..576b667a8813 100644
>--- a/kernel/user_namespace.c
>+++ b/kernel/user_namespace.c
>@@ -317,9 +317,9 @@ map_id_range_down_base(unsigned extents, struct uid_gid_map *map, u32 id, u32 co
>
> static u32 map_id_range_down(struct uid_gid_map *map, u32 id, u32 count)
> {
>+ /* Pairs with smp_store_release() in map_write(). */
>+ unsigned int extents = smp_load_acquire(&map->nr_extents);
> struct uid_gid_extent *extent;
>- unsigned extents = map->nr_extents;
>- smp_rmb();
>
> if (extents <= UID_GID_MAP_MAX_BASE_EXTENTS)
> extent = map_id_range_down_base(extents, map, id, count);
>@@ -383,9 +383,9 @@ map_id_range_up_max(unsigned extents, struct uid_gid_map *map, u32 id, u32 count
>
> u32 map_id_range_up(struct uid_gid_map *map, u32 id, u32 count)
> {
>+ /* Pairs with smp_store_release() in map_write(). */
>+ unsigned int extents = smp_load_acquire(&map->nr_extents);
> struct uid_gid_extent *extent;
>- unsigned extents = map->nr_extents;
>- smp_rmb();
>
> if (extents <= UID_GID_MAP_MAX_BASE_EXTENTS)
> extent = map_id_range_up_base(extents, map, id, count);
>@@ -676,9 +676,9 @@ static int projid_m_show(struct seq_file *seq, void *v)
> static void *m_start(struct seq_file *seq, loff_t *ppos,
> struct uid_gid_map *map)
> {
>+ /* Pairs with smp_store_release() in map_write(). */
>+ unsigned int extents = smp_load_acquire(&map->nr_extents);
> loff_t pos = *ppos;
>- unsigned extents = map->nr_extents;
>- smp_rmb();
>
> if (pos >= extents)
> return NULL;
>@@ -967,9 +967,11 @@ static ssize_t map_write(struct file *file, const char __user *buf,
> * desired behavior is to see the values of the extents that
> * were written before the count of the extents.
> *
>- * To achieve this smp_wmb() is used on guarantee the write
>- * order and smp_rmb() is guaranteed that we don't have crazy
>- * architectures returning stale data.
>+ * The nr_extents field is the publish point for the extent
>+ * data. Writers use smp_store_release() to ensure all extent
>+ * data is visible before nr_extents is updated. Readers use
>+ * smp_load_acquire() to ensure they see a consistent view of
>+ * the extent data when reading nr_extents.
> */
> mutex_lock(&userns_state_mutex);
>
>@@ -1098,8 +1100,8 @@ static ssize_t map_write(struct file *file, const char __user *buf,
> map->forward = new_map.forward;
> map->reverse = new_map.reverse;
> }
>- smp_wmb();
>- map->nr_extents = new_map.nr_extents;
>+ /* Pairs with smp_load_acquire() in map_id_range_{up,down}() and m_start(). */
>+ smp_store_release(&map->nr_extents, new_map.nr_extents);
>
> *ppos = count;
> ret = count;
>
--- Thanks!
https://lore.kernel.org/all/EE579805-42F2-4C58-B752-F28779EEB717@grrlz.net/
next prev parent reply other threads:[~2026-09-02 10:10 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 7:47 [PATCH v3 0/8] Convert barrier pairs to acquire/release for better performance Jinjie Ruan
2026-09-02 7:47 ` [PATCH v3 1/8] user_namespace: Use acquire/release for nr_extents synchronization Jinjie Ruan
2026-09-02 7:53 ` sashiko-bot
2026-09-02 10:09 ` Bradley Morgan [this message]
2026-09-02 7:47 ` [PATCH v3 2/8] lib/vsprintf: Use acquire/release for ptr_key publication Jinjie Ruan
2026-09-02 7:52 ` sashiko-bot
2026-09-02 7:48 ` [PATCH v3 3/8] fs: aio: Use acquire/release for ring->tail publication Jinjie Ruan
2026-09-02 7:57 ` sashiko-bot
2026-09-02 7:48 ` [PATCH v3 4/8] fs: Use acquire/release for fdtable resize synchronization Jinjie Ruan
2026-09-02 7:53 ` sashiko-bot
2026-09-02 7:48 ` [PATCH v3 5/8] pidfs: Use test_bit_acquire() for attr flag tests Jinjie Ruan
2026-09-02 7:55 ` sashiko-bot
2026-09-02 7:48 ` [PATCH v3 6/8] super: Use acquire for SB_BORN check in super_cache_count() Jinjie Ruan
2026-09-02 7:58 ` sashiko-bot
2026-09-02 7:48 ` [PATCH v3 7/8] ext4: Fix out-of-bounds read in ext4_get_group_info() Jinjie Ruan
2026-09-02 8:01 ` sashiko-bot
2026-09-02 7:48 ` [PATCH v3 8/8] ext4: Convert group-count barrier protocol to acquire/release Jinjie Ruan
2026-09-02 7:58 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=0303FE1D-8F56-4C18-87DA-9C3BBF2D43AE@mainlining.org \
--to=brads@mainlining.org \
--cc=adilger.kernel@dilger.ca \
--cc=akpm@linux-foundation.org \
--cc=andriy.shevchenko@linux.intel.com \
--cc=bcrl@kvack.org \
--cc=brauner@kernel.org \
--cc=jack@suse.cz \
--cc=kees@kernel.org \
--cc=libaokun@linux.alibaba.com \
--cc=linux-aio@kvack.org \
--cc=linux-ext4@vger.kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@rasmusvillemoes.dk \
--cc=ojaswin@linux.ibm.com \
--cc=pmladek@suse.com \
--cc=ritesh.list@gmail.com \
--cc=rostedt@goodmis.org \
--cc=ruanjinjie@huawei.com \
--cc=senozhatsky@chromium.org \
--cc=sforshee@kernel.org \
--cc=tglx@kernel.org \
--cc=tytso@mit.edu \
--cc=viro@zeniv.linux.org.uk \
--cc=yi.zhang@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox