* Re: [PATCH 1/2] Update woken requeued futex_q lock_ptr
2009-08-05 22:02 ` [PATCH 1/2] Update woken requeued futex_q lock_ptr Darren Hart
@ 2009-08-06 5:15 ` Darren Hart
2009-08-07 0:24 ` Darren Hart
2009-08-08 15:27 ` [tip:core/urgent] futex: " tip-bot for Darren Hart
2009-08-09 20:24 ` tip-bot for Darren Hart
2 siblings, 1 reply; 10+ messages in thread
From: Darren Hart @ 2009-08-06 5:15 UTC (permalink / raw)
To: linux-rt-users, linux-kernel
Cc: tglx, peterz, rostedt, mingo, dino, johnstul, John Kacur
Darren Hart wrote:
> futex_requeue() can acquire the lock on behalf of a waiter during the
> requeue
> loop in the event of a lock steal or owner died. futex_wait_requeue_pi()
> cleans
> up the pi_state owner, using the lock_ptr to protect against concurrent
> access
> to the pi_state. The pi_state is found on the requeue target futex hash
> bucket
> so the lock_ptr needs to be updated accordingly. The problem manifested by
> triggering the WARN_ON in lookup_pi_state() about the pid !=
> pi_state->owner
> pid.
> The astute reviewer will note that still exists a race between the time
> futex_requeue() releases hb2->lock() and the time when
> futex_wait_requeue_pi()
> acquires it. During this time the pi_state and the futex uaddr are not
> in sync
> with the rt_mutex ownership. This patch closes the window to the point
> where
> my tests now pass, but we still need to address it.
>
> Note: Please apply to mainline and rt
>
> static inline
> -void requeue_pi_wake_futex(struct futex_q *q, union futex_key *key)
> +void requeue_pi_wake_futex(struct futex_q *q, union futex_key *key,
> + struct futex_hash_bucket *hb)
> {
> drop_futex_key_refs(&q->key);
> get_futex_key_refs(key);
> q->key = *key;
> + q->lock_ptr = &hb->lock;
Hrm... turns out changing this breaks the
handle_early_requeue_pi_wakeup() logic. I'll have to respin this patch
to account for that as well. Please hold off on this patch.
--
Darren Hart
IBM Linux Technology Center
Real-Time Linux Team
^ permalink raw reply [flat|nested] 10+ messages in thread* Re: [PATCH 1/2] Update woken requeued futex_q lock_ptr
2009-08-06 5:15 ` Darren Hart
@ 2009-08-07 0:24 ` Darren Hart
0 siblings, 0 replies; 10+ messages in thread
From: Darren Hart @ 2009-08-07 0:24 UTC (permalink / raw)
To: linux-rt-users, linux-kernel
Cc: tglx, peterz, rostedt, mingo, dino, johnstul, John Kacur
Darren Hart wrote:
> Darren Hart wrote:
>> futex_requeue() can acquire the lock on behalf of a waiter during the
>> requeue
>> loop in the event of a lock steal or owner died.
>> futex_wait_requeue_pi() cleans
>> up the pi_state owner, using the lock_ptr to protect against
>> concurrent access
>> to the pi_state. The pi_state is found on the requeue target futex
>> hash bucket
>> so the lock_ptr needs to be updated accordingly. The problem
>> manifested by
>> triggering the WARN_ON in lookup_pi_state() about the pid !=
>> pi_state->owner
>> pid.
>> The astute reviewer will note that still exists a race between the time
>> futex_requeue() releases hb2->lock() and the time when
>> futex_wait_requeue_pi()
>> acquires it. During this time the pi_state and the futex uaddr are
>> not in sync
>> with the rt_mutex ownership. This patch closes the window to the
>> point where
>> my tests now pass, but we still need to address it.
>>
>> Note: Please apply to mainline and rt
>>
>
>
>> static inline
>> -void requeue_pi_wake_futex(struct futex_q *q, union futex_key *key)
>> +void requeue_pi_wake_futex(struct futex_q *q, union futex_key *key,
>> + struct futex_hash_bucket *hb)
>> {
>> drop_futex_key_refs(&q->key);
>> get_futex_key_refs(key);
>> q->key = *key;
>> + q->lock_ptr = &hb->lock;
>
> Hrm... turns out changing this breaks the
> handle_early_requeue_pi_wakeup() logic. I'll have to respin this patch
> to account for that as well. Please hold off on this patch.
In fact, this doesn't affect the handle_early_requeue_pi_wakeup() code
in the slightest. It only needs to hold a hb->lock (either one is
adequate) to ensure the requeue routine has completed. By changing the
q->lock_ptr of the waiter to hb2->lock we ensure the pi_state is
protected from concurrent access by futex_wait_requeue_pi() and new
contending threads.
Ingo, please apply to tip/urgent.
Thanks,
--
Darren Hart
IBM Linux Technology Center
Real-Time Linux Team
^ permalink raw reply [flat|nested] 10+ messages in thread
* [tip:core/urgent] futex: Update woken requeued futex_q lock_ptr
2009-08-05 22:02 ` [PATCH 1/2] Update woken requeued futex_q lock_ptr Darren Hart
2009-08-06 5:15 ` Darren Hart
@ 2009-08-08 15:27 ` tip-bot for Darren Hart
2009-08-09 20:24 ` tip-bot for Darren Hart
2 siblings, 0 replies; 10+ messages in thread
From: tip-bot for Darren Hart @ 2009-08-08 15:27 UTC (permalink / raw)
To: linux-tip-commits
Cc: linux-kernel, dvhltc, hpa, mingo, jkacur, johnstul, peterz, dino,
rostedt, stable, tglx, mingo
Commit-ID: 00235fe25eba6d3a13f3349b2e3a2d94b699a414
Gitweb: http://git.kernel.org/tip/00235fe25eba6d3a13f3349b2e3a2d94b699a414
Author: Darren Hart <dvhltc@us.ibm.com>
AuthorDate: Wed, 5 Aug 2009 15:02:20 -0700
Committer: Ingo Molnar <mingo@elte.hu>
CommitDate: Sat, 8 Aug 2009 17:21:49 +0200
futex: Update woken requeued futex_q lock_ptr
futex_requeue() can acquire the lock on behalf of a waiter
during the requeue loop in the event of a lock steal or owner
died. futex_wait_requeue_pi() cleans up the pi_state owner,
using the lock_ptr to protect against concurrent access to the
pi_state. The pi_state is found on the requeue target futex
hash bucket so the lock_ptr needs to be updated accordingly.
The problem manifested by triggering the WARN_ON in
lookup_pi_state() about the pid != pi_state->owner pid.
The astute reviewer will note that still exists a race between
the time futex_requeue() releases hb2->lock() and the time when
futex_wait_requeue_pi() acquires it. During this time the
pi_state and the futex uaddr are not in sync with the rt_mutex
ownership. This patch closes the window to the point where my
tests now pass, but we still need to address it.
Signed-off-by: Darren Hart <dvhltc@us.ibm.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Dinakar Guniguntala <dino@in.ibm.com>
Cc: John Stultz <johnstul@us.ibm.com>
Cc: John Kacur <jkacur@redhat.com>
Cc: <stable@kernel.org>
LKML-Reference: <4A7A016C.1090002@us.ibm.com>
Signed-off-by: Ingo Molnar <mingo@elte.hu>
---
kernel/futex.c | 13 +++++++++----
1 files changed, 9 insertions(+), 4 deletions(-)
diff --git a/kernel/futex.c b/kernel/futex.c
index 0672ff8..57f5a80 100644
--- a/kernel/futex.c
+++ b/kernel/futex.c
@@ -1010,19 +1010,24 @@ void requeue_futex(struct futex_q *q, struct futex_hash_bucket *hb1,
* requeue_pi_wake_futex() - Wake a task that acquired the lock during requeue
* q: the futex_q
* key: the key of the requeue target futex
+ * hb: the hash_bucket of the requeue target futex
*
* During futex_requeue, with requeue_pi=1, it is possible to acquire the
* target futex if it is uncontended or via a lock steal. Set the futex_q key
* to the requeue target futex so the waiter can detect the wakeup on the right
* futex, but remove it from the hb and NULL the rt_waiter so it can detect
- * atomic lock acquisition. Must be called with the q->lock_ptr held.
+ * atomic lock acquisition. Set the q->lock_ptr to the requeue target hb->lock
+ * to protect access to the pi_state to fixup the owner later. Must be called
+ * with the q->lock_ptr held.
*/
static inline
-void requeue_pi_wake_futex(struct futex_q *q, union futex_key *key)
+void requeue_pi_wake_futex(struct futex_q *q, union futex_key *key,
+ struct futex_hash_bucket *hb)
{
drop_futex_key_refs(&q->key);
get_futex_key_refs(key);
q->key = *key;
+ q->lock_ptr = &hb->lock;
WARN_ON(plist_node_empty(&q->list));
plist_del(&q->list, &q->list.plist);
@@ -1088,7 +1093,7 @@ static int futex_proxy_trylock_atomic(u32 __user *pifutex,
ret = futex_lock_pi_atomic(pifutex, hb2, key2, ps, top_waiter->task,
set_waiters);
if (ret == 1)
- requeue_pi_wake_futex(top_waiter, key2);
+ requeue_pi_wake_futex(top_waiter, key2, hb2);
return ret;
}
@@ -1273,7 +1278,7 @@ retry_private:
this->task, 1);
if (ret == 1) {
/* We got the lock. */
- requeue_pi_wake_futex(this, &key2);
+ requeue_pi_wake_futex(this, &key2, hb2);
continue;
} else if (ret) {
/* -EDEADLK */
^ permalink raw reply related [flat|nested] 10+ messages in thread* [tip:core/urgent] futex: Update woken requeued futex_q lock_ptr
2009-08-05 22:02 ` [PATCH 1/2] Update woken requeued futex_q lock_ptr Darren Hart
2009-08-06 5:15 ` Darren Hart
2009-08-08 15:27 ` [tip:core/urgent] futex: " tip-bot for Darren Hart
@ 2009-08-09 20:24 ` tip-bot for Darren Hart
2009-08-09 20:56 ` Ingo Molnar
2 siblings, 1 reply; 10+ messages in thread
From: tip-bot for Darren Hart @ 2009-08-09 20:24 UTC (permalink / raw)
To: linux-tip-commits
Cc: linux-kernel, dvhltc, hpa, mingo, jkacur, johnstul, peterz, dino,
rostedt, stable, tglx, mingo
Commit-ID: 4047446de8fa83d8d5922e9448eb0cbb7ac3f475
Gitweb: http://git.kernel.org/tip/4047446de8fa83d8d5922e9448eb0cbb7ac3f475
Author: Darren Hart <dvhltc@us.ibm.com>
AuthorDate: Wed, 5 Aug 2009 15:02:20 -0700
Committer: Ingo Molnar <mingo@elte.hu>
CommitDate: Sun, 9 Aug 2009 22:20:07 +0200
futex: Update woken requeued futex_q lock_ptr
futex_requeue() can acquire the lock on behalf of a waiter early on
or during the requeue loop if it is uncontended or in the event of a
lock steal or owner died. On wakeup, the waiter (in
futex_wait_requeue_pi()) cleans up the pi_state owner using the
lock_ptr to protect against concurrent access to the pi_state. The
pi_state is hung off futex_q's on the requeue target futex hash
bucket so the lock_ptr needs to be updated accordingly.
The problem manifested by triggering the WARN_ON in
lookup_pi_state() about the pid != pi_state->owner->pid. With this
patch, the pi_state is properly guarded against concurrent access
via the requeue target hb lock.
The astute reviewer may notice that there is a window of time
between when futex_requeue() unlocks the hb locks and when
futex_wait_requeue_pi() will acquire hb2->lock. During this time
the pi_state and uval are not in sync with the underlying rtmutex
owner (but the uval does indicate there are waiters, so no atomic
changes will occur in userspace). However, this is not a problem.
Should a contending thread enter lookup_pi_state() and acquire
hb2->lock before the ownership is fixed up, it will find the
pi_state hung off a waiter's (possibly the pending owner's) futex_q
and block on the rtmutex. Once futex_wait_requeue_pi() fixes up the
owner, it will also move the pi_state from the old owner's
task->pi_state_list to its own.
Signed-off-by: Darren Hart <dvhltc@us.ibm.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Dinakar Guniguntala <dino@in.ibm.com>
Cc: John Stultz <johnstul@us.ibm.com>
Cc: John Kacur <jkacur@redhat.com>
Cc: <stable@kernel.org>
LKML-Reference: <4A7A016C.1090002@us.ibm.com>
Signed-off-by: Ingo Molnar <mingo@elte.hu>
---
kernel/futex.c | 17 +++++++++++++----
1 files changed, 13 insertions(+), 4 deletions(-)
diff --git a/kernel/futex.c b/kernel/futex.c
index 0672ff8..ca99305 100644
--- a/kernel/futex.c
+++ b/kernel/futex.c
@@ -1010,15 +1010,19 @@ void requeue_futex(struct futex_q *q, struct futex_hash_bucket *hb1,
* requeue_pi_wake_futex() - Wake a task that acquired the lock during requeue
* q: the futex_q
* key: the key of the requeue target futex
+ * hb: the hash_bucket of the requeue target futex
*
* During futex_requeue, with requeue_pi=1, it is possible to acquire the
* target futex if it is uncontended or via a lock steal. Set the futex_q key
* to the requeue target futex so the waiter can detect the wakeup on the right
* futex, but remove it from the hb and NULL the rt_waiter so it can detect
- * atomic lock acquisition. Must be called with the q->lock_ptr held.
+ * atomic lock acquisition. Set the q->lock_ptr to the requeue target hb->lock
+ * to protect access to the pi_state to fixup the owner later. Must be called
+ * with both q->lock_ptr and hb->lock held.
*/
static inline
-void requeue_pi_wake_futex(struct futex_q *q, union futex_key *key)
+void requeue_pi_wake_futex(struct futex_q *q, union futex_key *key,
+ struct futex_hash_bucket *hb)
{
drop_futex_key_refs(&q->key);
get_futex_key_refs(key);
@@ -1030,6 +1034,11 @@ void requeue_pi_wake_futex(struct futex_q *q, union futex_key *key)
WARN_ON(!q->rt_waiter);
q->rt_waiter = NULL;
+ q->lock_ptr = &hb->lock;
+#ifdef CONFIG_DEBUG_PI_LIST
+ q->list.plist.slock = &hb->lock;
+#endif
+
wake_up_state(q->task, TASK_NORMAL);
}
@@ -1088,7 +1097,7 @@ static int futex_proxy_trylock_atomic(u32 __user *pifutex,
ret = futex_lock_pi_atomic(pifutex, hb2, key2, ps, top_waiter->task,
set_waiters);
if (ret == 1)
- requeue_pi_wake_futex(top_waiter, key2);
+ requeue_pi_wake_futex(top_waiter, key2, hb2);
return ret;
}
@@ -1273,7 +1282,7 @@ retry_private:
this->task, 1);
if (ret == 1) {
/* We got the lock. */
- requeue_pi_wake_futex(this, &key2);
+ requeue_pi_wake_futex(this, &key2, hb2);
continue;
} else if (ret) {
/* -EDEADLK */
^ permalink raw reply related [flat|nested] 10+ messages in thread* Re: [tip:core/urgent] futex: Update woken requeued futex_q lock_ptr
2009-08-09 20:24 ` tip-bot for Darren Hart
@ 2009-08-09 20:56 ` Ingo Molnar
2009-08-09 22:03 ` Darren Hart
2009-08-09 22:18 ` Darren Hart
0 siblings, 2 replies; 10+ messages in thread
From: Ingo Molnar @ 2009-08-09 20:56 UTC (permalink / raw)
To: mingo, hpa, dvhltc, linux-kernel, jkacur, johnstul, peterz, dino,
rostedt, stable, tglx
Cc: linux-tip-commits
* tip-bot for Darren Hart <dvhltc@us.ibm.com> wrote:
> @@ -1030,6 +1034,11 @@ void requeue_pi_wake_futex(struct futex_q *q, union futex_key *key)
> WARN_ON(!q->rt_waiter);
> q->rt_waiter = NULL;
>
> + q->lock_ptr = &hb->lock;
> +#ifdef CONFIG_DEBUG_PI_LIST
> + q->list.plist.slock = &hb->lock;
> +#endif
> +
> wake_up_state(q->task, TASK_NORMAL);
> }
>
-tip testing found a build error with v2 of the patch:
kernel/futex.c: In function ‘requeue_pi_wake_futex’:
kernel/futex.c:1039: error: ‘struct plist_head’ has no member named ‘slock’
Ingo
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [tip:core/urgent] futex: Update woken requeued futex_q lock_ptr
2009-08-09 20:56 ` Ingo Molnar
@ 2009-08-09 22:03 ` Darren Hart
2009-08-09 22:18 ` Darren Hart
1 sibling, 0 replies; 10+ messages in thread
From: Darren Hart @ 2009-08-09 22:03 UTC (permalink / raw)
To: Ingo Molnar
Cc: mingo, hpa, linux-kernel, jkacur, johnstul, peterz, dino, rostedt,
stable, tglx, linux-tip-commits
Ingo Molnar wrote:
> * tip-bot for Darren Hart <dvhltc@us.ibm.com> wrote:
>
>> @@ -1030,6 +1034,11 @@ void requeue_pi_wake_futex(struct futex_q *q, union futex_key *key)
>> WARN_ON(!q->rt_waiter);
>> q->rt_waiter = NULL;
>>
>> + q->lock_ptr = &hb->lock;
>> +#ifdef CONFIG_DEBUG_PI_LIST
>> + q->list.plist.slock = &hb->lock;
>> +#endif
>> +
>> wake_up_state(q->task, TASK_NORMAL);
>> }
>>
>
> -tip testing found a build error with v2 of the patch:
>
> kernel/futex.c: In function ‘requeue_pi_wake_futex’:
> kernel/futex.c:1039: error: ‘struct plist_head’ has no member named ‘slock’
I've been developing on -rt, and the plist implementation changed with:
34ca9f9b spinlocks: Create atomic_spinlock and convert rq->lock
Apologies for not catching that. I'll send out V3 of this patch, one
for mainline, and one for -rt. Is prefacing the patch with [RT] the
preferred way to distinguish mainline and -rt patches?
Thanks,
--
Darren Hart
IBM Linux Technology Center
Real-Time Linux Team
^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [tip:core/urgent] futex: Update woken requeued futex_q lock_ptr
2009-08-09 20:56 ` Ingo Molnar
2009-08-09 22:03 ` Darren Hart
@ 2009-08-09 22:18 ` Darren Hart
1 sibling, 0 replies; 10+ messages in thread
From: Darren Hart @ 2009-08-09 22:18 UTC (permalink / raw)
To: Ingo Molnar
Cc: mingo, hpa, linux-kernel, jkacur, johnstul, peterz, dino, rostedt,
stable, tglx
Ingo Molnar wrote:
> * tip-bot for Darren Hart <dvhltc@us.ibm.com> wrote:
>
>> @@ -1030,6 +1034,11 @@ void requeue_pi_wake_futex(struct futex_q *q, union futex_key *key)
>> WARN_ON(!q->rt_waiter);
>> q->rt_waiter = NULL;
>>
>> + q->lock_ptr = &hb->lock;
>> +#ifdef CONFIG_DEBUG_PI_LIST
>> + q->list.plist.slock = &hb->lock;
>> +#endif
>> +
>> wake_up_state(q->task, TASK_NORMAL);
>> }
>>
>
> -tip testing found a build error with v2 of the patch:
>
> kernel/futex.c: In function ‘requeue_pi_wake_futex’:
> kernel/futex.c:1039: error: ‘struct plist_head’ has no member named ‘slock’
Ingo,
I'm finding myself confused by the tip branches. I was going to prepare
you a "mainline" version of this patch, but tip/core-for-linus-2 doesn't
have the original requeue_pi support in futex.c, while tag v2.6.31-rc5
does have that support.
I'll prepare a patch against v2.6.31-rc5, but can you explain how you
would prefer for people to send patches that are needed in both mainline
and rt, but have slightly different implementations?
--
Darren Hart
IBM Linux Technology Center
Real-Time Linux Team
^ permalink raw reply [flat|nested] 10+ messages in thread