The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: Peter Zijlstra <peterz@infradead.org>
To: Hernan Ponce de Leon <hernan.poncedeleon@huaweicloud.com>
Cc: mingo@redhat.com, will@kernel.org, longman@redhat.com,
	boqun.feng@gmail.com, akpm@osdl.org, arjan@linux.intel.com,
	tglx@linutronix.de, joel@joelfernandes.org, paulmck@kernel.org,
	stern@rowland.harvard.edu, diogo.behrens@huawei.com,
	jonas.oberhauser@huawei.com, linux-kernel@vger.kernel.org,
	Hernan Ponce de Leon <hernanl.leon@huawei.com>,
	stable@vger.kernel.org
Subject: Re: [PATCH] Fix data race in mark_rt_mutex_waiters
Date: Fri, 20 Jan 2023 17:23:02 +0100	[thread overview]
Message-ID: <Y8q/5hgXrvOp6vku@hirez.programming.kicks-ass.net> (raw)
In-Reply-To: <20230120135525.25561-1-hernan.poncedeleon@huaweicloud.com>

On Fri, Jan 20, 2023 at 02:55:25PM +0100, Hernan Ponce de Leon wrote:
> From: Hernan Ponce de Leon <hernanl.leon@huawei.com>
> 
> Following the defition of data race in
> tools/memory-model/linux-kernel.cat the dartagnan tool
> https://github.com/hernanponcedeleon/Dat3M
> reported a race between mark_rt_mutex_waiters and rt_mutex_cmpxchg_release.
> 
> Commit 23f78d4a03c5 ("[PATCH] pi-futex: rt mutex core")
> later removed in commit d0aa7a70bf03 ("futex_requeue_pi optimization")
> and reverted in commit bd197234b0a6
> ("Revert "futex_requeue_pi optimization"")
> 
> The original commit introduced the data race.
> 
> Cc: stable@vger.kernel.org # v2.6.18.x
> Fixes: 23f78d4a03c5 ("[PATCH] pi-futex: rt mutex core")
> Signed-off-by: Hernan Ponce de Leon <hernanl.leon@huawei.com>
> ---
>  kernel/locking/rtmutex.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/kernel/locking/rtmutex.c b/kernel/locking/rtmutex.c
> index 010cf4e6d0b8..7ed9472edd48 100644
> --- a/kernel/locking/rtmutex.c
> +++ b/kernel/locking/rtmutex.c
> @@ -235,7 +235,7 @@ static __always_inline void mark_rt_mutex_waiters(struct rt_mutex_base *lock)
>  	unsigned long owner, *p = (unsigned long *) &lock->owner;
>  
>  	do {
> -		owner = *p;
> +		owner = READ_ONCE(*p);
>  	} while (cmpxchg_relaxed(p, owner,
>  				 owner | RT_MUTEX_HAS_WAITERS) != owner);
>  

Can't we replace the whole of that function with:

	set_bit(0, (unsigned long *)&lock->owner);

?

  parent reply	other threads:[~2023-01-20 16:23 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-01-20 13:55 [PATCH] Fix data race in mark_rt_mutex_waiters Hernan Ponce de Leon
2023-01-20 14:58 ` Arjan van de Ven
2023-01-20 15:54   ` Paul E. McKenney
2023-01-22 15:24     ` Hernan Ponce de Leon
2023-01-23 16:40       ` Paul E. McKenney
2023-01-23 17:34         ` Alan Stern
2023-01-23 17:48           ` Paul E. McKenney
2023-01-23 20:02           ` Jonas Oberhauser
2023-01-24 14:57         ` Hernan Ponce de Leon
2023-01-24 15:42           ` Waiman Long
2023-01-24 15:52             ` Peter Zijlstra
2023-01-24 16:04               ` Waiman Long
2023-01-26  9:42                 ` Hernan Ponce de Leon
2023-01-26 12:20                   ` Peter Zijlstra
2023-01-26 14:20                     ` Peter Zijlstra
2023-01-26 21:07                     ` Hernan Ponce de Leon
2023-01-26 22:10                       ` David Laight
2023-01-27  1:46                         ` Waiman Long
2023-03-01 16:32                           ` lock_torture results for different patches: Antonio Paolillo
2023-03-06  7:58                             ` Hernan Ponce de Leon
2023-03-10 17:11                             ` Paul E. McKenney
2023-01-24 16:12           ` [PATCH] Fix data race in mark_rt_mutex_waiters Paul E. McKenney
2023-01-20 16:23 ` Peter Zijlstra [this message]
2023-01-20 16:58   ` David Laight

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Y8q/5hgXrvOp6vku@hirez.programming.kicks-ass.net \
    --to=peterz@infradead.org \
    --cc=akpm@osdl.org \
    --cc=arjan@linux.intel.com \
    --cc=boqun.feng@gmail.com \
    --cc=diogo.behrens@huawei.com \
    --cc=hernan.poncedeleon@huaweicloud.com \
    --cc=hernanl.leon@huawei.com \
    --cc=joel@joelfernandes.org \
    --cc=jonas.oberhauser@huawei.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=longman@redhat.com \
    --cc=mingo@redhat.com \
    --cc=paulmck@kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=stern@rowland.harvard.edu \
    --cc=tglx@linutronix.de \
    --cc=will@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox