From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-9.8 required=3.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS,INCLUDES_PATCH, MAILING_LIST_MULTI,SIGNED_OFF_BY,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0D11BC4363A for ; Mon, 5 Oct 2020 14:44:27 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id B837D2085B for ; Mon, 5 Oct 2020 14:44:26 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (1024-bit key) header.d=joelfernandes.org header.i=@joelfernandes.org header.b="cDltzreS" Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726337AbgJEOoZ (ORCPT ); Mon, 5 Oct 2020 10:44:25 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:41738 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725911AbgJEOoZ (ORCPT ); Mon, 5 Oct 2020 10:44:25 -0400 Received: from mail-qt1-x82f.google.com (mail-qt1-x82f.google.com [IPv6:2607:f8b0:4864:20::82f]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id D7641C0613CE for ; Mon, 5 Oct 2020 07:44:24 -0700 (PDT) Received: by mail-qt1-x82f.google.com with SMTP id r8so9700697qtp.13 for ; Mon, 05 Oct 2020 07:44:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=joelfernandes.org; s=google; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to; bh=NIPvw8e1heuwMKuiOcUyxto/CHGsF04EOz1itR69nNQ=; b=cDltzreSvmKHasVP3qz8D7gEjIMIpYVbydvudTIc7UnmM2uZZIQmxeyIDV13AHU20b lejw9pOPvN5XSioyhdXPD3md7iOgNH/8YNGOFiMEPr5aqtFf/NVAJxc/RWyprr5CY57D 9FYIwELFv5jEd5B5gc6CepLCU7943Sdj1RT3I= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to; bh=NIPvw8e1heuwMKuiOcUyxto/CHGsF04EOz1itR69nNQ=; b=tcdfdTfNTv9xVKPgYHCpjuwEnjqGMXV/CjLfRQDxn6Kz4CqWRP4+IZXje1TufvdFHl Nq+p0btzp6LS6J+ZAqWAkMab6OI09W/fHuSjNxa6jmbAI84iHTNzN7/65wbKZENGMIwG GqiNPed99jwd2ua1SYPknu4183/csp8BMS0x81jS/JFXb8t8Nc6veuevrlQfeAUfKgvi 6y+b+E131jEo7+dwnVflET94DhgffeUR+QX67UcGuxqCqkxpOH79CFvHjNIbq1PODFu9 lF9NmkRXubA381deaI3K5tZf3+WCcqbPTvjqIlB9RNFEV8miJ7HpnKtw7m5hrBDoRDZQ hbvQ== X-Gm-Message-State: AOAM532PooXMPibQjzoB/KDOvL8u5IUEctT0sotdL/u7CiPN1lPYhC8H 62bT7BUcMulW78g7TXDA7roU+A== X-Google-Smtp-Source: ABdhPJxTF+6qQlaN6mNtASaz9cwRdEycr27ZrgJNp2KPaVaehyLs5/DnPs64AVUOGl/HF6q0dD0YUw== X-Received: by 2002:ac8:760f:: with SMTP id t15mr158142qtq.35.1601909063978; Mon, 05 Oct 2020 07:44:23 -0700 (PDT) Received: from localhost ([2620:15c:6:12:cad3:ffff:feb3:bd59]) by smtp.gmail.com with ESMTPSA id k22sm190690qkk.13.2020.10.05.07.44.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 05 Oct 2020 07:44:23 -0700 (PDT) Date: Mon, 5 Oct 2020 10:44:22 -0400 From: joel@joelfernandes.org To: "Paul E. McKenney" Cc: Alan Stern , parri.andrea@gmail.com, will@kernel.org, peterz@infradead.org, boqun.feng@gmail.com, npiggin@gmail.com, dhowells@redhat.com, j.alglave@ucl.ac.uk, luc.maranget@inria.fr, akiyks@gmail.com, dlustig@nvidia.com, viro@zeniv.linux.org.uk, linux-kernel@vger.kernel.org, linux-arch@vger.kernel.org Subject: Re: Litmus test for question from Al Viro Message-ID: <20201005144422.GB524504@google.com> References: <20201001045116.GA5014@paulmck-ThinkPad-P72> <20201001161529.GA251468@rowland.harvard.edu> <20201001213048.GF29330@paulmck-ThinkPad-P72> <20201003132212.GB318272@rowland.harvard.edu> <20201004233146.GP29330@paulmck-ThinkPad-P72> <20201005023846.GA359428@rowland.harvard.edu> <20201005140353.GW29330@paulmck-ThinkPad-P72> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20201005140353.GW29330@paulmck-ThinkPad-P72> Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Mon, Oct 05, 2020 at 07:03:53AM -0700, Paul E. McKenney wrote: > On Sun, Oct 04, 2020 at 10:38:46PM -0400, Alan Stern wrote: > > On Sun, Oct 04, 2020 at 04:31:46PM -0700, Paul E. McKenney wrote: > > > Nice simple example! How about like this? > > > > > > Thanx, Paul > > > > > > ------------------------------------------------------------------------ > > > > > > commit c964f404eabe4d8ce294e59dda713d8c19d340cf > > > Author: Alan Stern > > > Date: Sun Oct 4 16:27:03 2020 -0700 > > > > > > manual/kernel: Add a litmus test with a hidden dependency > > > > > > This commit adds a litmus test that has a data dependency that can be > > > hidden by control flow. In this test, both the taken and the not-taken > > > branches of an "if" statement must be accounted for in order to properly > > > analyze the litmus test. But herd7 looks only at individual executions > > > in isolation, so fails to see the dependency. > > > > > > Signed-off-by: Alan Stern > > > Signed-off-by: Paul E. McKenney > > > > > > diff --git a/manual/kernel/crypto-control-data.litmus b/manual/kernel/crypto-control-data.litmus > > > new file mode 100644 > > > index 0000000..6baecf9 > > > --- /dev/null > > > +++ b/manual/kernel/crypto-control-data.litmus > > > @@ -0,0 +1,31 @@ > > > +C crypto-control-data > > > +(* > > > + * LB plus crypto-control-data plus data > > > + * > > > + * Result: Sometimes > > > + * > > > + * This is an example of OOTA and we would like it to be forbidden. > > > + * The WRITE_ONCE in P0 is both data-dependent and (at the hardware level) > > > + * control-dependent on the preceding READ_ONCE. But the dependencies are > > > + * hidden by the form of the conditional control construct, hence the > > > + * name "crypto-control-data". The memory model doesn't recognize them. > > > + *) > > > + > > > +{} > > > + > > > +P0(int *x, int *y) > > > +{ > > > + int r1; > > > + > > > + r1 = 1; > > > + if (READ_ONCE(*x) == 0) > > > + r1 = 0; > > > + WRITE_ONCE(*y, r1); > > > +} > > > + > > > +P1(int *x, int *y) > > > +{ > > > + WRITE_ONCE(*x, READ_ONCE(*y)); > > > +} > > > + > > > +exists (0:r1=1) > > > > Considering the bug in herd7 pointed out by Akira, we should rewrite P1 as: > > > > P1(int *x, int *y) > > { > > int r2; > > > > r = READ_ONCE(*y); > > WRITE_ONCE(*x, r2); > > } > > > > Other than that, this is fine. > > Updated as suggested by Will, like this? LGTM as well, FWIW: Reviewed-by: Joel Fernandes (Google) thanks, - Joel > > Thanx, Paul > > ------------------------------------------------------------------------ > > commit adf43667b702582331d68acdf3732a6a017a182c > Author: Alan Stern > Date: Sun Oct 4 16:27:03 2020 -0700 > > manual/kernel: Add a litmus test with a hidden dependency > > This commit adds a litmus test that has a data dependency that can be > hidden by control flow. In this test, both the taken and the not-taken > branches of an "if" statement must be accounted for in order to properly > analyze the litmus test. But herd7 looks only at individual executions > in isolation, so fails to see the dependency. > > Signed-off-by: Alan Stern > Signed-off-by: Paul E. McKenney > > diff --git a/manual/kernel/crypto-control-data.litmus b/manual/kernel/crypto-control-data.litmus > new file mode 100644 > index 0000000..cdcdec9 > --- /dev/null > +++ b/manual/kernel/crypto-control-data.litmus > @@ -0,0 +1,34 @@ > +C crypto-control-data > +(* > + * LB plus crypto-control-data plus data > + * > + * Result: Sometimes > + * > + * This is an example of OOTA and we would like it to be forbidden. > + * The WRITE_ONCE in P0 is both data-dependent and (at the hardware level) > + * control-dependent on the preceding READ_ONCE. But the dependencies are > + * hidden by the form of the conditional control construct, hence the > + * name "crypto-control-data". The memory model doesn't recognize them. > + *) > + > +{} > + > +P0(int *x, int *y) > +{ > + int r1; > + > + r1 = 1; > + if (READ_ONCE(*x) == 0) > + r1 = 0; > + WRITE_ONCE(*y, r1); > +} > + > +P1(int *x, int *y) > +{ > + int r2; > + > + r2 = READ_ONCE(*y); > + WRITE_ONCE(*x, r2); > +} > + > +exists (0:r1=1)