public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: "Paul E. McKenney" <paulmck@kernel.org>
To: rcu@vger.kernel.org
Cc: linux-kernel@vger.kernel.org, kernel-team@meta.com,
	rostedt@goodmis.org, Ankur Arora <ankur.a.arora@oracle.com>,
	Frederic Weisbecker <frederic@kernel.org>,
	"Paul E . McKenney" <paulmck@kernel.org>
Subject: [PATCH rcu v2] 4/9] rcu: handle unstable rdp in rcu_read_unlock_strict()
Date: Thu, 30 Jan 2025 10:55:17 -0800	[thread overview]
Message-ID: <20250130185522.1652093-4-paulmck@kernel.org> (raw)
In-Reply-To: <9bc6e5fe-d49f-495a-9f55-537ed97a3615@paulmck-laptop>

From: Ankur Arora <ankur.a.arora@oracle.com>

rcu_read_unlock_strict() can be called with preemption enabled
which can make for an unstable rdp and a racy norm value.

Fix this by dropping the preempt-count in __rcu_read_unlock()
after the call to rcu_read_unlock_strict(), adjusting the
preempt-count check appropriately.

Suggested-by: Frederic Weisbecker <frederic@kernel.org>
Signed-off-by: Ankur Arora <ankur.a.arora@oracle.com>
Reviewed-by: Frederic Weisbecker <frederic@kernel.org>
Signed-off-by: Paul E. McKenney <paulmck@kernel.org>
---
 include/linux/rcupdate.h |  2 +-
 kernel/rcu/tree_plugin.h | 11 ++++++++++-
 2 files changed, 11 insertions(+), 2 deletions(-)

diff --git a/include/linux/rcupdate.h b/include/linux/rcupdate.h
index c6c4aee47df2..9b05db8ff061 100644
--- a/include/linux/rcupdate.h
+++ b/include/linux/rcupdate.h
@@ -95,9 +95,9 @@ static inline void __rcu_read_lock(void)
 
 static inline void __rcu_read_unlock(void)
 {
-	preempt_enable();
 	if (IS_ENABLED(CONFIG_RCU_STRICT_GRACE_PERIOD))
 		rcu_read_unlock_strict();
+	preempt_enable();
 }
 
 static inline int rcu_preempt_depth(void)
diff --git a/kernel/rcu/tree_plugin.h b/kernel/rcu/tree_plugin.h
index bb7ca6eb9ef0..b025e95ede05 100644
--- a/kernel/rcu/tree_plugin.h
+++ b/kernel/rcu/tree_plugin.h
@@ -833,8 +833,17 @@ void rcu_read_unlock_strict(void)
 {
 	struct rcu_data *rdp;
 
-	if (irqs_disabled() || preempt_count() || !rcu_state.gp_kthread)
+	if (irqs_disabled() || in_atomic_preempt_off() || !rcu_state.gp_kthread)
 		return;
+
+	/*
+	 * rcu_report_qs_rdp() can only be invoked with a stable rdp and
+	 * from the local CPU.
+	 *
+	 * The in_atomic_preempt_off() check ensures that we come here holding
+	 * the last preempt_count (which will get dropped once we return to
+	 * __rcu_read_unlock().
+	 */
 	rdp = this_cpu_ptr(&rcu_data);
 	rdp->cpu_no_qs.b.norm = false;
 	rcu_report_qs_rdp(rdp);
-- 
2.40.1


  parent reply	other threads:[~2025-01-30 18:55 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-01-16 20:13 [PATCH rcu 0/9] Lazy-preemption-related updates Paul E. McKenney
2025-01-16 20:13 ` [PATCH rcu 1/9] rcu: fix header guard for rcu_all_qs() Paul E. McKenney
2025-01-16 20:13 ` [PATCH rcu 2/9] rcu: rename PREEMPT_AUTO to PREEMPT_LAZY Paul E. McKenney
2025-01-16 20:13 ` [PATCH rcu 3/9] sched: update __cond_resched comment about RCU quiescent states Paul E. McKenney
2025-01-16 20:13 ` [PATCH rcu 4/9] rcu: handle unstable rdp in rcu_read_unlock_strict() Paul E. McKenney
2025-01-16 20:13 ` [PATCH rcu 5/9] rcu: handle quiescent states for PREEMPT_RCU=n, PREEMPT_COUNT=y Paul E. McKenney
2025-01-16 20:13 ` [PATCH rcu 6/9] osnoise: provide quiescent states Paul E. McKenney
2025-01-16 20:13 ` [PATCH rcu 7/9] rcu: limit PREEMPT_RCU configurations Paul E. McKenney
2025-01-16 20:13 ` [PATCH rcu 8/9] rcutorture: Make scenario TREE10 build CONFIG_PREEMPT_LAZY=y Paul E. McKenney
2025-01-16 20:13 ` [PATCH rcu 9/9] rcutorture: Make scenario TREE07 " Paul E. McKenney
2025-01-30 18:55 ` [PATCH rcu 0/9] Lazy-preemption-related updates Paul E. McKenney
2025-01-30 18:55   ` [PATCH rcu v2] 1/9] rcu: fix header guard for rcu_all_qs() Paul E. McKenney
2025-01-30 18:55   ` [PATCH rcu v2] 2/9] rcu: rename PREEMPT_AUTO to PREEMPT_LAZY Paul E. McKenney
2025-01-30 18:55   ` [PATCH rcu v2] 3/9] sched: update __cond_resched comment about RCU quiescent states Paul E. McKenney
2025-01-30 18:55   ` Paul E. McKenney [this message]
2025-01-30 18:55   ` [PATCH rcu v2] 5/9] rcu: handle quiescent states for PREEMPT_RCU=n, PREEMPT_COUNT=y Paul E. McKenney
2025-01-30 18:55   ` [PATCH rcu v2] 6/9] osnoise: provide quiescent states Paul E. McKenney
2025-01-30 18:55   ` [PATCH rcu v2] 7/9] rcu: limit PREEMPT_RCU configurations Paul E. McKenney
2025-01-30 18:55   ` [PATCH rcu v2] 8/9] rcutorture: Make scenario TREE10 build CONFIG_PREEMPT_LAZY=y Paul E. McKenney
2025-01-30 18:55   ` [PATCH rcu v2] 9/9] rcutorture: Make scenario TREE07 " Paul E. McKenney

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250130185522.1652093-4-paulmck@kernel.org \
    --to=paulmck@kernel.org \
    --cc=ankur.a.arora@oracle.com \
    --cc=frederic@kernel.org \
    --cc=kernel-team@meta.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=rcu@vger.kernel.org \
    --cc=rostedt@goodmis.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox