From: Jinjie Ruan <ruanjinjie@huawei.com>
To: Oliver Hartkopp <socketcan@hartkopp.net>,
<viro@zeniv.linux.org.uk>, <brauner@kernel.org>, <jack@suse.cz>,
<bcrl@kvack.org>, <tytso@mit.edu>, <adilger.kernel@dilger.ca>,
<libaokun@linux.alibaba.com>, <ojaswin@linux.ibm.com>,
<ritesh.list@gmail.com>, <yi.zhang@huawei.com>,
<pmladek@suse.com>, <rostedt@goodmis.org>,
<andriy.shevchenko@linux.intel.com>, <linux@rasmusvillemoes.dk>,
<senozhatsky@chromium.org>, <akpm@linux-foundation.org>,
<davem@davemloft.net>, <edumazet@google.com>, <kuba@kernel.org>,
<pabeni@redhat.com>, <horms@kernel.org>, <mkl@pengutronix.de>,
<kuniyu@google.com>, <willemb@google.com>, <jhs@mojatatu.com>,
<jiri@resnulli.us>, <kees@kernel.org>, <cyphar@cyphar.com>,
<tglx@kernel.org>, <liuhangbin@gmail.com>, <sdf@fomichev.me>,
<nb@tipi-net.de>, <linux-fsdevel@vger.kernel.org>,
<linux-aio@kvack.org>, <linux-kernel@vger.kernel.org>,
<linux-ext4@vger.kernel.org>, <netdev@vger.kernel.org>,
<linux-can@vger.kernel.org>
Subject: Re: [PATCH 11/11] can: isotp: publish tx.state with smp_store_release()
Date: Wed, 26 Aug 2026 11:33:05 +0800 [thread overview]
Message-ID: <bc9a3081-a567-4e2a-8847-c60fd0e3dc89@huawei.com> (raw)
In-Reply-To: <d23aaeb2-1ed4-4b83-befb-996c569da27f@hartkopp.net>
在 2026/8/25 19:46, Oliver Hartkopp 写道:
>
>
> On 25.08.26 11:54, Jinjie Ruan wrote:
>> The writer already pairs with the smp_load_acquire() readers
>> in isotp_tx_timeout()/isotp_tx_gen_done(); convert
>> the smp_wmb() + WRITE_ONCE() into a release store.
>>
>> Assisted-by: DeepSeek:DeepSeek-V3
>> Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com>
>> ---
>> net/can/isotp.c | 4 ++--
>> 1 file changed, 2 insertions(+), 2 deletions(-)
>>
>> diff --git a/net/can/isotp.c b/net/can/isotp.c
>> index 155530aedce2..11b653ba7c10 100644
>> --- a/net/can/isotp.c
>> +++ b/net/can/isotp.c
>> @@ -1156,8 +1156,8 @@ static int isotp_sendmsg(struct socket *sock,
>> struct msghdr *msg, size_t size)
>> my_gen = isotp_inc_tx_gen(READ_ONCE(so->tx_gen));
>> isotp_set_tx_result(so, my_gen, ECOMM); /* prevent stale slot
>> matching */
>> WRITE_ONCE(so->tx_gen, my_gen);
>> - smp_wmb(); /* see smp_load_acquire() in isotp_tx_[timeout|
>> gen_done] */
>> - WRITE_ONCE(so->tx.state, ISOTP_SENDING);
>> + /* Pairs with smp_load_acquire() in isotp_tx_[timeout|gen_done] */
>> + smp_store_release(&so->tx.state, ISOTP_SENDING);
>> WRITE_ONCE(so->cfecho, 0);
>> spin_unlock_bh(&so->rx_lock);
>>
>
> Hi Jinjie,
>
Hi Oliver,
> thank you for the patch, but I think this breaks the barrier logic.
> The original smp_wmb() ensures that so->tx_gen is visible before both
> subsequent writes (so->tx.state and so->cfecho).
Right!
>
> By converting only the first write into smp_store_release(), the
> WRITE_ONCE(so->cfecho, 0) is no longer protected. The compiler or CPU
> could reorder and execute the cfecho write before the release store of
Indeed, that's true.
> so->tx.state, introducing a race condition with the concurrent readers.
My rough understanding is as follows:
All lock-free readers fall into two disjoint sets:
- `isotp_tx_timeout()` and `isotp_tx_gen_done()`: read only `tx.state`
(acquire) and `tx_gen`
- `isotp_txfr_timer_handler()` the timer path of `isotp_send_cframe()`,
and the post-claim path of `isotp_sendmsg()` touch `cfecho` but never
`tx_gen`.
So no lock-free reader observes both `tx_gen` and `cfecho`.
`isotp_rcv_echo()` is the only function reading both, and it runs under
`so->rx_lock`, which serializes it with the claim.
So the ordering the `smp_wmb()` provided on top of the new release store
`tx_gen` before `cfecho` — is unobservable to every reader.
Moreover, `tx.state` and `cfecho` were never ordered against each other
by the original barrier: both followed the `smp_wmb()`, so the `(state,
cfecho)` visibility seen by the lock-free timer readers is bit-for-bit
identical before and after this change.
So the release store preserves the one ordering that matters: a reader
observing `ISOTP_SENDING` sees the new `tx_gen`.
Best regards,
Jinjie
>
> Best regards,
> Oliver
>
>
next prev parent reply other threads:[~2026-08-26 3:33 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-25 9:54 [PATCH 00/11] Convert barrier pairs to acquire/release for better performance Jinjie Ruan
2026-08-25 9:54 ` [PATCH 01/11] user_namespace: Use acquire/release for nr_extents synchronization Jinjie Ruan
2026-08-25 9:54 ` [PATCH 02/11] lib/vsprintf: Use acquire/release for ptr_key publication Jinjie Ruan
2026-08-25 9:54 ` [PATCH 03/11] fs: aio: Use acquire/release for ring->tail publication Jinjie Ruan
2026-08-25 9:54 ` [PATCH 04/11] fs: Use acquire/release for fdtable resize synchronization Jinjie Ruan
2026-08-25 9:54 ` [PATCH 05/11] pidfs: Use test_bit_acquire() for attr flag tests Jinjie Ruan
2026-08-25 9:54 ` [PATCH 06/11] super: Use acquire for SB_BORN check in super_cache_count() Jinjie Ruan
2026-08-25 9:54 ` [PATCH 07/11] ext4: Convert group-count barrier protocol to acquire/release Jinjie Ruan
2026-08-25 9:54 ` [PATCH 08/11] soreuseport: publish num_socks with acquire/release Jinjie Ruan
2026-08-25 9:54 ` [PATCH 09/11] net: sched: act_gact: use acquire/release for tcfg_ptype Jinjie Ruan
2026-08-25 9:54 ` [PATCH 10/11] 8021q: publish vlan_devices_arrays entries with acquire/release Jinjie Ruan
2026-08-25 9:54 ` [PATCH 11/11] can: isotp: publish tx.state with smp_store_release() Jinjie Ruan
2026-08-25 11:46 ` Oliver Hartkopp
2026-08-26 3:33 ` Jinjie Ruan [this message]
2026-08-26 8:04 ` Oliver Hartkopp
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=bc9a3081-a567-4e2a-8847-c60fd0e3dc89@huawei.com \
--to=ruanjinjie@huawei.com \
--cc=adilger.kernel@dilger.ca \
--cc=akpm@linux-foundation.org \
--cc=andriy.shevchenko@linux.intel.com \
--cc=bcrl@kvack.org \
--cc=brauner@kernel.org \
--cc=cyphar@cyphar.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=jack@suse.cz \
--cc=jhs@mojatatu.com \
--cc=jiri@resnulli.us \
--cc=kees@kernel.org \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=libaokun@linux.alibaba.com \
--cc=linux-aio@kvack.org \
--cc=linux-can@vger.kernel.org \
--cc=linux-ext4@vger.kernel.org \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@rasmusvillemoes.dk \
--cc=liuhangbin@gmail.com \
--cc=mkl@pengutronix.de \
--cc=nb@tipi-net.de \
--cc=netdev@vger.kernel.org \
--cc=ojaswin@linux.ibm.com \
--cc=pabeni@redhat.com \
--cc=pmladek@suse.com \
--cc=ritesh.list@gmail.com \
--cc=rostedt@goodmis.org \
--cc=sdf@fomichev.me \
--cc=senozhatsky@chromium.org \
--cc=socketcan@hartkopp.net \
--cc=tglx@kernel.org \
--cc=tytso@mit.edu \
--cc=viro@zeniv.linux.org.uk \
--cc=willemb@google.com \
--cc=yi.zhang@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox