From: Andre Przywara <andre.przywara@linaro.org>
To: Jan Beulich <JBeulich@suse.com>, xen-devel@lists.xen.org
Cc: Stefano Stabellini <sstabellini@kernel.org>,
Wei Liu <wei.liu2@citrix.com>,
George Dunlap <George.Dunlap@eu.citrix.com>,
Andrew Cooper <andrew.cooper3@citrix.com>,
Ian Jackson <Ian.Jackson@eu.citrix.com>, Tim Deegan <tim@xen.org>,
Julien Grall <julien.grall@arm.com>
Subject: Re: [PATCH 2/2] gnttab: improve GNTTABOP_cache_flush locking
Date: Fri, 1 Dec 2017 15:31:45 +0000 [thread overview]
Message-ID: <ebefbc11-f6c1-8fb5-33c3-b80588addcbe@linaro.org> (raw)
In-Reply-To: <5A20247B020000780019390F@prv-mh.provo.novell.com>
Hi,
On 30/11/17 14:32, Jan Beulich wrote:
> Dropping the lock before returning from grant_map_exists() means handing
> possibly stale information back to the caller. Return back the pointer
> to the active entry instead, for the caller to release the lock once
> done.
I don't know enough about grant tables to reason about the deeper
meaning of this patch, but at least I can confirm that the amended
locking scheme seems to be correct (now).
I just wonder if it's worthwhile to add a comment that the function
takes a lock, but leaves it up to the caller to drop it. Since there is
only one caller, this might be overkill, though.
> Signed-off-by: Jan Beulich <jbeulich@suse.com>
Reviewed-by: Andre Przywara <andre.przywara@linaro.org>
Cheers,
Andre.
>
> --- a/xen/common/grant_table.c
> +++ b/xen/common/grant_table.c
> @@ -786,10 +786,10 @@ static int _set_status(unsigned gt_versi
> return _set_status_v2(domid, readonly, mapflag, shah, act, status);
> }
>
> -static int grant_map_exists(const struct domain *ld,
> - struct grant_table *rgt,
> - unsigned long mfn,
> - grant_ref_t *cur_ref)
> +static struct active_grant_entry *grant_map_exists(const struct domain *ld,
> + struct grant_table *rgt,
> + unsigned long mfn,
> + grant_ref_t *cur_ref)
> {
> grant_ref_t ref, max_iter;
>
> @@ -805,28 +805,20 @@ static int grant_map_exists(const struct
> nr_grant_entries(rgt));
> for ( ref = *cur_ref; ref < max_iter; ref++ )
> {
> - struct active_grant_entry *act;
> - bool_t exists;
> -
> - act = active_entry_acquire(rgt, ref);
> -
> - exists = act->pin
> - && act->domid == ld->domain_id
> - && act->frame == mfn;
> + struct active_grant_entry *act = active_entry_acquire(rgt, ref);
>
> + if ( act->pin && act->domid == ld->domain_id && act->frame == mfn )
> + return act;
> active_entry_release(act);
> -
> - if ( exists )
> - return 0;
> }
>
> if ( ref < nr_grant_entries(rgt) )
> {
> *cur_ref = ref;
> - return 1;
> + return NULL;
> }
>
> - return -EINVAL;
> + return ERR_PTR(-EINVAL);
> }
>
> #define MAPKIND_READ 1
> @@ -3213,6 +3205,7 @@ static int cache_flush(const gnttab_cach
> struct domain *d, *owner;
> struct page_info *page;
> unsigned long mfn;
> + struct active_grant_entry *act = NULL;
> void *v;
> int ret;
>
> @@ -3250,13 +3243,13 @@ static int cache_flush(const gnttab_cach
> {
> grant_read_lock(owner->grant_table);
>
> - ret = grant_map_exists(d, owner->grant_table, mfn, cur_ref);
> - if ( ret != 0 )
> + act = grant_map_exists(d, owner->grant_table, mfn, cur_ref);
> + if ( IS_ERR_OR_NULL(act) )
> {
> grant_read_unlock(owner->grant_table);
> rcu_unlock_domain(d);
> put_page(page);
> - return ret;
> + return act ? PTR_ERR(act) : 1;
> }
> }
>
> @@ -3273,7 +3266,11 @@ static int cache_flush(const gnttab_cach
> ret = 0;
>
> if ( d != owner )
> + {
> + active_entry_release(act);
> grant_read_unlock(owner->grant_table);
> + }
> +
> unmap_domain_page(v);
> put_page(page);
>
_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xenproject.org
https://lists.xenproject.org/mailman/listinfo/xen-devel
next prev parent reply other threads:[~2017-12-01 15:31 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-11-28 20:07 [BUG] assertion failure in do_grant_table_op() Jann Horn
2017-11-30 14:26 ` [PATCH 0/2] gnttab: improve GNTTABOP_cache_flush handling Jan Beulich
2017-11-30 14:31 ` [PATCH 1/2] gnttab: correct GNTTABOP_cache_flush empty batch handling Jan Beulich
2017-12-01 15:31 ` Andre Przywara
2017-12-04 9:00 ` Jan Beulich
2017-12-04 17:13 ` Andre Przywara
2017-12-01 21:38 ` Stefano Stabellini
2017-12-04 10:08 ` Jan Beulich
2017-12-05 18:42 ` Stefano Stabellini
2017-12-04 11:12 ` George Dunlap
2017-12-04 11:19 ` Jan Beulich
2017-11-30 14:32 ` [PATCH 2/2] gnttab: improve GNTTABOP_cache_flush locking Jan Beulich
2017-12-01 15:31 ` Andre Przywara [this message]
2017-12-04 9:02 ` Jan Beulich
2017-12-04 11:31 ` George Dunlap
2017-12-04 11:36 ` Jan Beulich
2017-12-01 21:45 ` Stefano Stabellini
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ebefbc11-f6c1-8fb5-33c3-b80588addcbe@linaro.org \
--to=andre.przywara@linaro.org \
--cc=George.Dunlap@eu.citrix.com \
--cc=Ian.Jackson@eu.citrix.com \
--cc=JBeulich@suse.com \
--cc=andrew.cooper3@citrix.com \
--cc=julien.grall@arm.com \
--cc=sstabellini@kernel.org \
--cc=tim@xen.org \
--cc=wei.liu2@citrix.com \
--cc=xen-devel@lists.xen.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).