Linux MIPS Architecture development
 help / color / mirror / Atom feed
From: Paul Burton <paul.burton@imgtec.com>
To: chenj <chenj@lemote.com>
Cc: <linux-mips@linux-mips.org>, <chenhc@lemote.com>,
	<ralf@linux-mips.org>, <wangr@lemote.com>
Subject: Re: [PATCH] Not preempt in CP1 exception handling
Date: Fri, 11 Jul 2014 16:56:31 +0100	[thread overview]
Message-ID: <20140711155631.GE8187@pburton-laptop> (raw)
In-Reply-To: <1405048453-12633-1-git-send-email-chenj@lemote.com>

On Fri, Jul 11, 2014 at 11:14:13AM +0800, chenj wrote:
> do_ade may be invoked with preempt enabled. do_cpu will be invoked with
> preempt enabled. When it's preempted(in do_ade/do_cpu), TIF_USEDFPU will be
> cleared, when it returns to do_ade/do_cpu, the fpu is actually disabled.
> 
> e.g.
> In do_ade()
>   emulate_load_store_insn():
>     BUG_ON(!is_fpu_owner()); <-- This assertion may be breaked.
> 
> In do_cpu()
>   enable_restore_fp_context():
>     was_fpu_owner = is_fpu_owner();

Preemption should indeed be disabled around the assignment & use of the
was_fpu_owner variable, but note that you can only hit the problem if
using MSA. One of the MSA fixes I just submitted also fixes this along
with another instance of the problem:

  http://patchwork.linux-mips.org/patch/7307/

I prefer my patch to this since it disables preemption for less time,
in addition to fixing the !used_math() case.

In emulate_load_store_insn I believe the correct fix is simply to remove
that BUG_ON. The code is about to give up FPU ownership anyway, so it's
not like there is any requirement being violated if it was already lost.

Thanks,
    Paul

> This patch simply disables interrupts in related handlers, and
> disable preempt/enable interrupts in do_ade/do_cpu.
> ---
>  arch/mips/kernel/genex.S | 4 ++--
>  arch/mips/kernel/traps.c | 4 ++++
>  2 files changed, 6 insertions(+), 2 deletions(-)
> 
> diff --git a/arch/mips/kernel/genex.S b/arch/mips/kernel/genex.S
> index ac35e12..a5c6931 100644
> --- a/arch/mips/kernel/genex.S
> +++ b/arch/mips/kernel/genex.S
> @@ -370,7 +370,7 @@ NESTED(nmi_handler, PT_SIZE, sp)
>  	.macro	__build_clear_ade
>  	MFC0	t0, CP0_BADVADDR
>  	PTR_S	t0, PT_BVADDR(sp)
> -	KMODE
> +	CLI
>  	.endm
>  
>  	.macro	__BUILD_silent exception
> @@ -422,7 +422,7 @@ NESTED(nmi_handler, PT_SIZE, sp)
>  	BUILD_HANDLER dbe be cli silent			/* #7  */
>  	BUILD_HANDLER bp bp sti silent			/* #9  */
>  	BUILD_HANDLER ri ri sti silent			/* #10 */
> -	BUILD_HANDLER cpu cpu sti silent		/* #11 */
> +	BUILD_HANDLER cpu cpu cli silent		/* #11 */
>  	BUILD_HANDLER ov ov sti silent			/* #12 */
>  	BUILD_HANDLER tr tr sti silent			/* #13 */
>  	BUILD_HANDLER msa_fpe msa_fpe sti silent	/* #14 */
> diff --git a/arch/mips/kernel/traps.c b/arch/mips/kernel/traps.c
> index 51706d6..0e0f7de 100644
> --- a/arch/mips/kernel/traps.c
> +++ b/arch/mips/kernel/traps.c
> @@ -1166,6 +1166,9 @@ asmlinkage void do_cpu(struct pt_regs *regs)
>  	int status, err;
>  	unsigned long __maybe_unused flags;
>  
> +	preempt_disable();
> +	local_irq_enable();
> +
>  	prev_state = exception_enter();
>  	cpid = (regs->cp0_cause >> CAUSEB_CE) & 3;
>  
> @@ -1258,6 +1261,7 @@ asmlinkage void do_cpu(struct pt_regs *regs)
>  
>  out:
>  	exception_exit(prev_state);
> +	preempt_enable();
>  }
>  
>  asmlinkage void do_msa_fpe(struct pt_regs *regs)
> -- 
> 1.9.0
> 
> 

WARNING: multiple messages have this Message-ID (diff)
From: Paul Burton <paul.burton@imgtec.com>
To: chenj <chenj@lemote.com>
Cc: linux-mips@linux-mips.org, chenhc@lemote.com,
	ralf@linux-mips.org, wangr@lemote.com
Subject: Re: [PATCH] Not preempt in CP1 exception handling
Date: Fri, 11 Jul 2014 16:56:31 +0100	[thread overview]
Message-ID: <20140711155631.GE8187@pburton-laptop> (raw)
Message-ID: <20140711155631.BR3esMwwDINziwzJoNtdMBMFDAfE2naxoks1XXJbrPs@z> (raw)
In-Reply-To: <1405048453-12633-1-git-send-email-chenj@lemote.com>

On Fri, Jul 11, 2014 at 11:14:13AM +0800, chenj wrote:
> do_ade may be invoked with preempt enabled. do_cpu will be invoked with
> preempt enabled. When it's preempted(in do_ade/do_cpu), TIF_USEDFPU will be
> cleared, when it returns to do_ade/do_cpu, the fpu is actually disabled.
> 
> e.g.
> In do_ade()
>   emulate_load_store_insn():
>     BUG_ON(!is_fpu_owner()); <-- This assertion may be breaked.
> 
> In do_cpu()
>   enable_restore_fp_context():
>     was_fpu_owner = is_fpu_owner();

Preemption should indeed be disabled around the assignment & use of the
was_fpu_owner variable, but note that you can only hit the problem if
using MSA. One of the MSA fixes I just submitted also fixes this along
with another instance of the problem:

  http://patchwork.linux-mips.org/patch/7307/

I prefer my patch to this since it disables preemption for less time,
in addition to fixing the !used_math() case.

In emulate_load_store_insn I believe the correct fix is simply to remove
that BUG_ON. The code is about to give up FPU ownership anyway, so it's
not like there is any requirement being violated if it was already lost.

Thanks,
    Paul

> This patch simply disables interrupts in related handlers, and
> disable preempt/enable interrupts in do_ade/do_cpu.
> ---
>  arch/mips/kernel/genex.S | 4 ++--
>  arch/mips/kernel/traps.c | 4 ++++
>  2 files changed, 6 insertions(+), 2 deletions(-)
> 
> diff --git a/arch/mips/kernel/genex.S b/arch/mips/kernel/genex.S
> index ac35e12..a5c6931 100644
> --- a/arch/mips/kernel/genex.S
> +++ b/arch/mips/kernel/genex.S
> @@ -370,7 +370,7 @@ NESTED(nmi_handler, PT_SIZE, sp)
>  	.macro	__build_clear_ade
>  	MFC0	t0, CP0_BADVADDR
>  	PTR_S	t0, PT_BVADDR(sp)
> -	KMODE
> +	CLI
>  	.endm
>  
>  	.macro	__BUILD_silent exception
> @@ -422,7 +422,7 @@ NESTED(nmi_handler, PT_SIZE, sp)
>  	BUILD_HANDLER dbe be cli silent			/* #7  */
>  	BUILD_HANDLER bp bp sti silent			/* #9  */
>  	BUILD_HANDLER ri ri sti silent			/* #10 */
> -	BUILD_HANDLER cpu cpu sti silent		/* #11 */
> +	BUILD_HANDLER cpu cpu cli silent		/* #11 */
>  	BUILD_HANDLER ov ov sti silent			/* #12 */
>  	BUILD_HANDLER tr tr sti silent			/* #13 */
>  	BUILD_HANDLER msa_fpe msa_fpe sti silent	/* #14 */
> diff --git a/arch/mips/kernel/traps.c b/arch/mips/kernel/traps.c
> index 51706d6..0e0f7de 100644
> --- a/arch/mips/kernel/traps.c
> +++ b/arch/mips/kernel/traps.c
> @@ -1166,6 +1166,9 @@ asmlinkage void do_cpu(struct pt_regs *regs)
>  	int status, err;
>  	unsigned long __maybe_unused flags;
>  
> +	preempt_disable();
> +	local_irq_enable();
> +
>  	prev_state = exception_enter();
>  	cpid = (regs->cp0_cause >> CAUSEB_CE) & 3;
>  
> @@ -1258,6 +1261,7 @@ asmlinkage void do_cpu(struct pt_regs *regs)
>  
>  out:
>  	exception_exit(prev_state);
> +	preempt_enable();
>  }
>  
>  asmlinkage void do_msa_fpe(struct pt_regs *regs)
> -- 
> 1.9.0
> 
> 

  parent reply	other threads:[~2014-07-11 15:56 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-07-11  3:06 [PATCH] MIPS: Don't BUG_ON(!is_fpu_owner()) in do_ade() when preemptible Huacai Chen
2014-07-11  3:14 ` [PATCH] Not preempt in CP1 exception handling chenj
2014-07-11  3:13   ` Chen Jie
2014-07-11 15:56   ` Paul Burton [this message]
2014-07-11 15:56     ` Paul Burton
2014-07-11 23:28     ` Chen Jie
2014-07-12  9:10       ` Huacai Chen
2014-07-12  9:30         ` Paul Burton
2014-07-14  2:22           ` Huacai Chen
2014-08-01 16:48             ` Ralf Baechle
2014-08-19 15:56               ` Chen Jie

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20140711155631.GE8187@pburton-laptop \
    --to=paul.burton@imgtec.com \
    --cc=chenhc@lemote.com \
    --cc=chenj@lemote.com \
    --cc=linux-mips@linux-mips.org \
    --cc=ralf@linux-mips.org \
    --cc=wangr@lemote.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox