xen-devel.lists.xenproject.org archive mirror
 help / color / mirror / Atom feed
From: Andre Przywara <andre.przywara@linaro.org>
To: Jan Beulich <JBeulich@suse.com>, xen-devel@lists.xen.org
Cc: Stefano Stabellini <sstabellini@kernel.org>,
	Wei Liu <wei.liu2@citrix.com>,
	George Dunlap <George.Dunlap@eu.citrix.com>,
	Andrew Cooper <andrew.cooper3@citrix.com>,
	Ian Jackson <Ian.Jackson@eu.citrix.com>, Tim Deegan <tim@xen.org>,
	Julien Grall <julien.grall@arm.com>
Subject: Re: [PATCH 2/2] gnttab: improve GNTTABOP_cache_flush locking
Date: Fri, 1 Dec 2017 15:31:45 +0000	[thread overview]
Message-ID: <ebefbc11-f6c1-8fb5-33c3-b80588addcbe@linaro.org> (raw)
In-Reply-To: <5A20247B020000780019390F@prv-mh.provo.novell.com>

Hi,

On 30/11/17 14:32, Jan Beulich wrote:
> Dropping the lock before returning from grant_map_exists() means handing
> possibly stale information back to the caller. Return back the pointer
> to the active entry instead, for the caller to release the lock once
> done.

I don't know enough about grant tables to reason about the deeper
meaning of this patch, but at least I can confirm that the amended
locking scheme seems to be correct (now).
I just wonder if it's worthwhile to add a comment that the function
takes a lock, but leaves it up to the caller to drop it. Since there is
only one caller, this might be overkill, though.

> Signed-off-by: Jan Beulich <jbeulich@suse.com>

Reviewed-by: Andre Przywara <andre.przywara@linaro.org>

Cheers,
Andre.

> 
> --- a/xen/common/grant_table.c
> +++ b/xen/common/grant_table.c
> @@ -786,10 +786,10 @@ static int _set_status(unsigned gt_versi
>          return _set_status_v2(domid, readonly, mapflag, shah, act, status);
>  }
>  
> -static int grant_map_exists(const struct domain *ld,
> -                            struct grant_table *rgt,
> -                            unsigned long mfn,
> -                            grant_ref_t *cur_ref)
> +static struct active_grant_entry *grant_map_exists(const struct domain *ld,
> +                                                   struct grant_table *rgt,
> +                                                   unsigned long mfn,
> +                                                   grant_ref_t *cur_ref)
>  {
>      grant_ref_t ref, max_iter;
>  
> @@ -805,28 +805,20 @@ static int grant_map_exists(const struct
>                     nr_grant_entries(rgt));
>      for ( ref = *cur_ref; ref < max_iter; ref++ )
>      {
> -        struct active_grant_entry *act;
> -        bool_t exists;
> -
> -        act = active_entry_acquire(rgt, ref);
> -
> -        exists = act->pin
> -            && act->domid == ld->domain_id
> -            && act->frame == mfn;
> +        struct active_grant_entry *act = active_entry_acquire(rgt, ref);
>  
> +        if ( act->pin && act->domid == ld->domain_id && act->frame == mfn )
> +            return act;
>          active_entry_release(act);
> -
> -        if ( exists )
> -            return 0;
>      }
>  
>      if ( ref < nr_grant_entries(rgt) )
>      {
>          *cur_ref = ref;
> -        return 1;
> +        return NULL;
>      }
>  
> -    return -EINVAL;
> +    return ERR_PTR(-EINVAL);
>  }
>  
>  #define MAPKIND_READ 1
> @@ -3213,6 +3205,7 @@ static int cache_flush(const gnttab_cach
>      struct domain *d, *owner;
>      struct page_info *page;
>      unsigned long mfn;
> +    struct active_grant_entry *act = NULL;
>      void *v;
>      int ret;
>  
> @@ -3250,13 +3243,13 @@ static int cache_flush(const gnttab_cach
>      {
>          grant_read_lock(owner->grant_table);
>  
> -        ret = grant_map_exists(d, owner->grant_table, mfn, cur_ref);
> -        if ( ret != 0 )
> +        act = grant_map_exists(d, owner->grant_table, mfn, cur_ref);
> +        if ( IS_ERR_OR_NULL(act) )
>          {
>              grant_read_unlock(owner->grant_table);
>              rcu_unlock_domain(d);
>              put_page(page);
> -            return ret;
> +            return act ? PTR_ERR(act) : 1;
>          }
>      }
>  
> @@ -3273,7 +3266,11 @@ static int cache_flush(const gnttab_cach
>          ret = 0;
>  
>      if ( d != owner )
> +    {
> +        active_entry_release(act);
>          grant_read_unlock(owner->grant_table);
> +    }
> +
>      unmap_domain_page(v);
>      put_page(page);
>  

_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xenproject.org
https://lists.xenproject.org/mailman/listinfo/xen-devel

  reply	other threads:[~2017-12-01 15:31 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-11-28 20:07 [BUG] assertion failure in do_grant_table_op() Jann Horn
2017-11-30 14:26 ` [PATCH 0/2] gnttab: improve GNTTABOP_cache_flush handling Jan Beulich
2017-11-30 14:31   ` [PATCH 1/2] gnttab: correct GNTTABOP_cache_flush empty batch handling Jan Beulich
2017-12-01 15:31     ` Andre Przywara
2017-12-04  9:00       ` Jan Beulich
2017-12-04 17:13         ` Andre Przywara
2017-12-01 21:38     ` Stefano Stabellini
2017-12-04 10:08       ` Jan Beulich
2017-12-05 18:42         ` Stefano Stabellini
2017-12-04 11:12     ` George Dunlap
2017-12-04 11:19       ` Jan Beulich
2017-11-30 14:32   ` [PATCH 2/2] gnttab: improve GNTTABOP_cache_flush locking Jan Beulich
2017-12-01 15:31     ` Andre Przywara [this message]
2017-12-04  9:02       ` Jan Beulich
2017-12-04 11:31         ` George Dunlap
2017-12-04 11:36           ` Jan Beulich
2017-12-01 21:45     ` Stefano Stabellini

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ebefbc11-f6c1-8fb5-33c3-b80588addcbe@linaro.org \
    --to=andre.przywara@linaro.org \
    --cc=George.Dunlap@eu.citrix.com \
    --cc=Ian.Jackson@eu.citrix.com \
    --cc=JBeulich@suse.com \
    --cc=andrew.cooper3@citrix.com \
    --cc=julien.grall@arm.com \
    --cc=sstabellini@kernel.org \
    --cc=tim@xen.org \
    --cc=wei.liu2@citrix.com \
    --cc=xen-devel@lists.xen.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).