From: Paul Burton <paul.burton@imgtec.com>
To: chenj <chenj@lemote.com>
Cc: <linux-mips@linux-mips.org>, <chenhc@lemote.com>,
<ralf@linux-mips.org>, <wangr@lemote.com>
Subject: Re: [PATCH] Not preempt in CP1 exception handling
Date: Fri, 11 Jul 2014 16:56:31 +0100 [thread overview]
Message-ID: <20140711155631.GE8187@pburton-laptop> (raw)
In-Reply-To: <1405048453-12633-1-git-send-email-chenj@lemote.com>
On Fri, Jul 11, 2014 at 11:14:13AM +0800, chenj wrote:
> do_ade may be invoked with preempt enabled. do_cpu will be invoked with
> preempt enabled. When it's preempted(in do_ade/do_cpu), TIF_USEDFPU will be
> cleared, when it returns to do_ade/do_cpu, the fpu is actually disabled.
>
> e.g.
> In do_ade()
> emulate_load_store_insn():
> BUG_ON(!is_fpu_owner()); <-- This assertion may be breaked.
>
> In do_cpu()
> enable_restore_fp_context():
> was_fpu_owner = is_fpu_owner();
Preemption should indeed be disabled around the assignment & use of the
was_fpu_owner variable, but note that you can only hit the problem if
using MSA. One of the MSA fixes I just submitted also fixes this along
with another instance of the problem:
http://patchwork.linux-mips.org/patch/7307/
I prefer my patch to this since it disables preemption for less time,
in addition to fixing the !used_math() case.
In emulate_load_store_insn I believe the correct fix is simply to remove
that BUG_ON. The code is about to give up FPU ownership anyway, so it's
not like there is any requirement being violated if it was already lost.
Thanks,
Paul
> This patch simply disables interrupts in related handlers, and
> disable preempt/enable interrupts in do_ade/do_cpu.
> ---
> arch/mips/kernel/genex.S | 4 ++--
> arch/mips/kernel/traps.c | 4 ++++
> 2 files changed, 6 insertions(+), 2 deletions(-)
>
> diff --git a/arch/mips/kernel/genex.S b/arch/mips/kernel/genex.S
> index ac35e12..a5c6931 100644
> --- a/arch/mips/kernel/genex.S
> +++ b/arch/mips/kernel/genex.S
> @@ -370,7 +370,7 @@ NESTED(nmi_handler, PT_SIZE, sp)
> .macro __build_clear_ade
> MFC0 t0, CP0_BADVADDR
> PTR_S t0, PT_BVADDR(sp)
> - KMODE
> + CLI
> .endm
>
> .macro __BUILD_silent exception
> @@ -422,7 +422,7 @@ NESTED(nmi_handler, PT_SIZE, sp)
> BUILD_HANDLER dbe be cli silent /* #7 */
> BUILD_HANDLER bp bp sti silent /* #9 */
> BUILD_HANDLER ri ri sti silent /* #10 */
> - BUILD_HANDLER cpu cpu sti silent /* #11 */
> + BUILD_HANDLER cpu cpu cli silent /* #11 */
> BUILD_HANDLER ov ov sti silent /* #12 */
> BUILD_HANDLER tr tr sti silent /* #13 */
> BUILD_HANDLER msa_fpe msa_fpe sti silent /* #14 */
> diff --git a/arch/mips/kernel/traps.c b/arch/mips/kernel/traps.c
> index 51706d6..0e0f7de 100644
> --- a/arch/mips/kernel/traps.c
> +++ b/arch/mips/kernel/traps.c
> @@ -1166,6 +1166,9 @@ asmlinkage void do_cpu(struct pt_regs *regs)
> int status, err;
> unsigned long __maybe_unused flags;
>
> + preempt_disable();
> + local_irq_enable();
> +
> prev_state = exception_enter();
> cpid = (regs->cp0_cause >> CAUSEB_CE) & 3;
>
> @@ -1258,6 +1261,7 @@ asmlinkage void do_cpu(struct pt_regs *regs)
>
> out:
> exception_exit(prev_state);
> + preempt_enable();
> }
>
> asmlinkage void do_msa_fpe(struct pt_regs *regs)
> --
> 1.9.0
>
>
WARNING: multiple messages have this Message-ID (diff)
From: Paul Burton <paul.burton@imgtec.com>
To: chenj <chenj@lemote.com>
Cc: linux-mips@linux-mips.org, chenhc@lemote.com,
ralf@linux-mips.org, wangr@lemote.com
Subject: Re: [PATCH] Not preempt in CP1 exception handling
Date: Fri, 11 Jul 2014 16:56:31 +0100 [thread overview]
Message-ID: <20140711155631.GE8187@pburton-laptop> (raw)
Message-ID: <20140711155631.BR3esMwwDINziwzJoNtdMBMFDAfE2naxoks1XXJbrPs@z> (raw)
In-Reply-To: <1405048453-12633-1-git-send-email-chenj@lemote.com>
On Fri, Jul 11, 2014 at 11:14:13AM +0800, chenj wrote:
> do_ade may be invoked with preempt enabled. do_cpu will be invoked with
> preempt enabled. When it's preempted(in do_ade/do_cpu), TIF_USEDFPU will be
> cleared, when it returns to do_ade/do_cpu, the fpu is actually disabled.
>
> e.g.
> In do_ade()
> emulate_load_store_insn():
> BUG_ON(!is_fpu_owner()); <-- This assertion may be breaked.
>
> In do_cpu()
> enable_restore_fp_context():
> was_fpu_owner = is_fpu_owner();
Preemption should indeed be disabled around the assignment & use of the
was_fpu_owner variable, but note that you can only hit the problem if
using MSA. One of the MSA fixes I just submitted also fixes this along
with another instance of the problem:
http://patchwork.linux-mips.org/patch/7307/
I prefer my patch to this since it disables preemption for less time,
in addition to fixing the !used_math() case.
In emulate_load_store_insn I believe the correct fix is simply to remove
that BUG_ON. The code is about to give up FPU ownership anyway, so it's
not like there is any requirement being violated if it was already lost.
Thanks,
Paul
> This patch simply disables interrupts in related handlers, and
> disable preempt/enable interrupts in do_ade/do_cpu.
> ---
> arch/mips/kernel/genex.S | 4 ++--
> arch/mips/kernel/traps.c | 4 ++++
> 2 files changed, 6 insertions(+), 2 deletions(-)
>
> diff --git a/arch/mips/kernel/genex.S b/arch/mips/kernel/genex.S
> index ac35e12..a5c6931 100644
> --- a/arch/mips/kernel/genex.S
> +++ b/arch/mips/kernel/genex.S
> @@ -370,7 +370,7 @@ NESTED(nmi_handler, PT_SIZE, sp)
> .macro __build_clear_ade
> MFC0 t0, CP0_BADVADDR
> PTR_S t0, PT_BVADDR(sp)
> - KMODE
> + CLI
> .endm
>
> .macro __BUILD_silent exception
> @@ -422,7 +422,7 @@ NESTED(nmi_handler, PT_SIZE, sp)
> BUILD_HANDLER dbe be cli silent /* #7 */
> BUILD_HANDLER bp bp sti silent /* #9 */
> BUILD_HANDLER ri ri sti silent /* #10 */
> - BUILD_HANDLER cpu cpu sti silent /* #11 */
> + BUILD_HANDLER cpu cpu cli silent /* #11 */
> BUILD_HANDLER ov ov sti silent /* #12 */
> BUILD_HANDLER tr tr sti silent /* #13 */
> BUILD_HANDLER msa_fpe msa_fpe sti silent /* #14 */
> diff --git a/arch/mips/kernel/traps.c b/arch/mips/kernel/traps.c
> index 51706d6..0e0f7de 100644
> --- a/arch/mips/kernel/traps.c
> +++ b/arch/mips/kernel/traps.c
> @@ -1166,6 +1166,9 @@ asmlinkage void do_cpu(struct pt_regs *regs)
> int status, err;
> unsigned long __maybe_unused flags;
>
> + preempt_disable();
> + local_irq_enable();
> +
> prev_state = exception_enter();
> cpid = (regs->cp0_cause >> CAUSEB_CE) & 3;
>
> @@ -1258,6 +1261,7 @@ asmlinkage void do_cpu(struct pt_regs *regs)
>
> out:
> exception_exit(prev_state);
> + preempt_enable();
> }
>
> asmlinkage void do_msa_fpe(struct pt_regs *regs)
> --
> 1.9.0
>
>
next prev parent reply other threads:[~2014-07-11 15:56 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-07-11 3:06 [PATCH] MIPS: Don't BUG_ON(!is_fpu_owner()) in do_ade() when preemptible Huacai Chen
2014-07-11 3:14 ` [PATCH] Not preempt in CP1 exception handling chenj
2014-07-11 3:13 ` Chen Jie
2014-07-11 15:56 ` Paul Burton [this message]
2014-07-11 15:56 ` Paul Burton
2014-07-11 23:28 ` Chen Jie
2014-07-12 9:10 ` Huacai Chen
2014-07-12 9:30 ` Paul Burton
2014-07-14 2:22 ` Huacai Chen
2014-08-01 16:48 ` Ralf Baechle
2014-08-19 15:56 ` Chen Jie
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20140711155631.GE8187@pburton-laptop \
--to=paul.burton@imgtec.com \
--cc=chenhc@lemote.com \
--cc=chenj@lemote.com \
--cc=linux-mips@linux-mips.org \
--cc=ralf@linux-mips.org \
--cc=wangr@lemote.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox