From: Alan Huang <mmpgouride@gmail.com>
To: paulmck@kernel.org, frederic@kernel.org,
quic_neeraju@quicinc.com, joel@joelfernandes.org,
josh@joshtriplett.org, boqun.feng@gmail.com, corbet@lwn.net
Cc: rcu@vger.kernel.org, linux-doc@vger.kernel.org,
Alan Huang <mmpgouride@gmail.com>
Subject: [PATCH 2/2] docs/RCU: Bring back smp_wmb()
Date: Thu, 6 Jul 2023 10:28:49 +0000 [thread overview]
Message-ID: <20230706102849.437687-3-mmpgouride@gmail.com> (raw)
In-Reply-To: <20230706102849.437687-1-mmpgouride@gmail.com>
The objects are allocated with SLAB_TYPESAFE_BY_RCU, and there is
n->next = first within hlist_add_head_rcu() before rcu_assign_pointer(),
which modifies obj->obj_node.next. There may be readers holding the
reference of obj in lockless_lookup, and when updater modifies ->next,
readers can see the change immediately because of SLAB_TYPESAFE_BY_RCU.
There are two memory ordering required in the insertion algorithm,
we need to make sure obj->key is updated before obj->obj_node.next
and obj->refcnt, atomic_set_release is not enough to provide the
required memory barrier.
Signed-off-by: Alan Huang <mmpgouride@gmail.com>
---
Documentation/RCU/rculist_nulls.rst | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/Documentation/RCU/rculist_nulls.rst b/Documentation/RCU/rculist_nulls.rst
index 21e40fcc08de..fa3729dc7e74 100644
--- a/Documentation/RCU/rculist_nulls.rst
+++ b/Documentation/RCU/rculist_nulls.rst
@@ -64,7 +64,7 @@ but a version with an additional memory barrier (smp_rmb())
{
struct hlist_node *node, *next;
for (pos = rcu_dereference((head)->first);
- pos && ({ next = pos->next; smp_rmb(); prefetch(next); 1; }) &&
+ pos && ({ next = READ_ONCE(pos->next); smp_rmb(); prefetch(next); 1; }) &&
({ obj = hlist_entry(pos, typeof(*obj), obj_node); 1; });
pos = rcu_dereference(next))
if (obj->key == key)
@@ -112,7 +112,12 @@ detect the fact that it missed following items in original chain.
obj = kmem_cache_alloc(...);
lock_chain(); // typically a spin_lock()
obj->key = key;
- atomic_set_release(&obj->refcnt, 1); // key before refcnt
+ /*
+ * We need to make sure obj->key is updated before obj->obj_node.next
+ * and obj->refcnt.
+ */
+ smp_wmb();
+ atomic_set(&obj->refcnt, 1);
hlist_add_head_rcu(&obj->obj_node, list);
unlock_chain(); // typically a spin_unlock()
--
2.34.1
next prev parent reply other threads:[~2023-07-06 10:29 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-07-06 10:28 [PATCH 0/2] rcu: Fix rculist_nulls and doc Alan Huang
2023-07-06 10:28 ` [PATCH 1/2] rcu: Use WRITE_ONCE() for assignments to ->next for rculist_nulls Alan Huang
2023-07-10 19:08 ` Paul E. McKenney
2023-07-10 20:01 ` Joel Fernandes
2023-07-10 20:30 ` Paul E. McKenney
2023-07-11 14:56 ` Alan Huang
2023-07-11 16:45 ` Paul E. McKenney
2023-07-11 14:51 ` Alan Huang
2023-07-06 10:28 ` Alan Huang [this message]
2023-07-10 19:11 ` [PATCH 2/2] docs/RCU: Bring back smp_wmb() Paul E. McKenney
2023-07-11 14:50 ` Alan Huang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20230706102849.437687-3-mmpgouride@gmail.com \
--to=mmpgouride@gmail.com \
--cc=boqun.feng@gmail.com \
--cc=corbet@lwn.net \
--cc=frederic@kernel.org \
--cc=joel@joelfernandes.org \
--cc=josh@joshtriplett.org \
--cc=linux-doc@vger.kernel.org \
--cc=paulmck@kernel.org \
--cc=quic_neeraju@quicinc.com \
--cc=rcu@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox