From: Magnus Lindholm <linmag7@gmail.com>
To: richard.henderson@linaro.org, mattst88@gmail.com,
linux-kernel@vger.kernel.org, linux-alpha@vger.kernel.org
Cc: linmag7@gmail.com
Subject: [PATCH v4 0/8] alpha: fix stale TLB translations breaking copy-on-write and writeback
Date: Fri, 9 Oct 2026 23:03:45 +0200 [thread overview]
Message-ID: <20261009210449.971057-1-linmag7@gmail.com> (raw)
On Alpha, stale TLB translations can break copy-on-write and shared-mapping
writeback: a multi-threaded process can lose its own stores, read data
belonging to its child, or lose writes through a shared file mapping. The
copy-on-write failures need more than one CPU; the writeback failure also
happens on a uniprocessor.
This is the first of two series, based on for-next at 33465f6ab697
("alpha: support the remaining kernel compression formats"). Apply all
eight patches here, then the two patches in "alpha: complete the direct-mm
shootdown fixes" v3. There is no interleaving or external prerequisite for
this first series.
Patch 1 moves here from v2 of the direct-switch series:
https://lore.kernel.org/linux-alpha/20261008195608.965266-2-linmag7@gmail.com/
It loads the context when switch_mm() is called directly for current,
before kthread_use_mm() can reach the hook added by patch 2. This closes
the dependency that previously required applying one patch from the other
series first. Its code and Matt's review and test tags are unchanged.
Patch 2 completes the deferred-ASN handshake from
finish_arch_post_lock_switch(), including the first switch to a newly
created task. Its old location after alpha_switch_to() was bypassed when
a new task reached schedule_tail(), leaving asn_lock set.
The hook runs after interrupts are enabled. Set need_new_asn whether
switch_mm() reused or allocated an ASN, so a deferred IPI cannot leave
a live hardware context with a zero slot. This is also required before
the second series uses those slots to decide whether to skip shootdowns.
Drop the preemptible() guard: Alpha has no kernel preemption and the
direct-switch callers do not sleep before the hook, including when
RCU_STRICT_GRACE_PERIOD enables PREEMPT_COUNT.
Patches 3, 5 and 6 test current->mm before issuing targeted tbi(), since
a lazy active_mm does not establish which ASN is actually loaded. Patches
4, 7 and 8 retire the calling CPU's context when the local current-context
test fails; smp_call_function() only visits the other CPUs.
Patch 4 deliberately precedes patch 5. The missing else branch must be
present before lazy callers are routed to it, so no intermediate commit
loses their local invalidate. This matters on EV7 where a foreign-context
tbi() appeared to work. The full-mm and icache callers retain their
active_mm tests because those paths load a new context instead of using
a targeted tbi(). The second series separately changes their IPI handlers
to retire slots on lazy CPUs rather than keeping those slots visible.
Testing
Cross-build validation for this revision covers arch/alpha/kernel/,
arch/alpha/mm/, kernel/sched/core.o and kernel/kthread.o with GCC 15.0.1:
ALPHA_GENERIC SMP and UP with COMPACTION=n, and SMP with COMPACTION=y,
RCU_STRICT_GRACE_PERIOD=y, PREEMPT_COUNT=y and NR_CPUS=4. These are compile
checks; all three passed. All ten patches pass checkpatch without warnings,
and sequential application reproduces the committed trees at both series
boundaries. No new boot or hardware runtime results are claimed.
Historical results from the earlier stale-TLB series, on an ES40,
EV68AL (21264C) Tsunami with three CPUs, v7.2-rc2 and v7.2-rc6:
before after
smoke test, stale-read check 7 of 9 rounds 0 of 9
lost stores 11 of 40 0 of 400
writeback (mkclean4), SMP [*] 10 of 10 0 of 10
writeback (mkclean4), UP [*] every round 0 of 8
tst-malloc-fork-deadlock-
malloc-check 8 of 10 fail 25/25 pass
[*] CONFIG_COMPACTION=n.
alpha-cow-smoketest.c uses pthreads and forked children. Each thread owns
its slot, and the main thread reads only after joining. Slots are 128
bytes apart so threads share a page; writing once and reading repeatedly
avoids hiding stale translations with another faulting write. It does
not fail when restricted to one CPU.
mkclean4.c exercises patches 4 and 5 together on SMP, and patch 6 on UP.
It compares a small MAP_SHARED mapping with its backing file after
background writeback, with the writer and flusher pinned to the same CPU
on SMP. It needs root and COMPACTION=n. With COMPACTION=y, Alpha overrides
ptep_clear_flush() to use migrate_flush_tlb_page(), so folio_mkclean() does
not exercise flush_tlb_page(). Earlier unpatched COMPACTION=y runs passed
103 rounds; separate regression runs under continuous compaction migrated
368522 folios without failures.
Matt's earlier ES47 (EV7) testing on v7.3-rc1 with one CPU online found no
regressions in fork/COW, writeback and gdb breakpoint tests on SMP and UP
builds. He could not reproduce the unpatched writeback failure despite
counters showing foreign-context targeted invalidates. The fix rests on
the tbi() contract, not on every implementation exhibiting the failure.
Patches 7 and 8 still have no isolated reproducer. A gdb breakpoint
exerciser covered patch 8's path for regressions. Matt suggested
move_pages() on another process's hugetlb mapping, with the caller pinned
to the CPU the target last ran on, as a possible reproducer for patch 7.
That is unverified; the proposed hugetlb support is not in this base.
Changes since v3:
- Move patch 1 of the v2 "alpha: load the MMU context on a direct mm
switch" series here as patch 1, so the stale-TLB series can be
applied first, followed by the remaining MMU fixes.
- Drop the post-switch hook's preemptible() guard.
- Set need_new_asn on both reused and newly allocated ASN paths.
- Put the missing local flush_tlb_page() else branch before changing
the current->mm test, as requested by Matt.
- Rebase on for-next and update numbering and dependency descriptions.
- Mention the proposed hugetlb caller without claiming a new reproducer.
- Drop the old review tag from the materially changed hook patch;
retain tags on the other patches.
Thanks to Matt Turner for the review and EV7 testing.
v3: https://lore.kernel.org/linux-alpha/20260923074903.862898-1-linmag7@gmail.com/
Magnus Lindholm (8):
alpha: load the MMU context when switch_mm() switches the current task
alpha: run check_mmu_context() from finish_arch_post_lock_switch()
alpha: only use a targeted tbi() when the target mm is really current
alpha: invalidate the local context in flush_tlb_page()
alpha: fix the local TLB invalidate in flush_tlb_page()
alpha: fix the local TLB invalidate in the UP flush_tlb_page()
alpha: invalidate the local context in flush_tlb_mm()
alpha: invalidate the local context in flush_icache_user_page()
arch/alpha/include/asm/mmu_context.h | 23 ++++++++++++++++++++---
arch/alpha/include/asm/switch_to.h | 1 -
arch/alpha/include/asm/tlbflush.h | 3 ++-
arch/alpha/kernel/smp.c | 15 +++++++++++++--
4 files changed, 35 insertions(+), 7 deletions(-)
base-commit: 33465f6ab697abceafd9a340067a544d551c4412
--
2.43.0
next reply other threads:[~2026-10-09 21:05 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-09 21:03 Magnus Lindholm [this message]
2026-10-09 21:03 ` [PATCH v4 1/8] alpha: load the MMU context when switch_mm() switches the current task Magnus Lindholm
2026-10-10 1:42 ` Matt Turner
2026-10-09 21:03 ` [PATCH v4 2/8] alpha: run check_mmu_context() from finish_arch_post_lock_switch() Magnus Lindholm
2026-10-10 1:42 ` Matt Turner
2026-10-09 21:03 ` [PATCH v4 3/8] alpha: only use a targeted tbi() when the target mm is really current Magnus Lindholm
2026-10-09 21:03 ` [PATCH v4 4/8] alpha: invalidate the local context in flush_tlb_page() Magnus Lindholm
2026-10-10 1:44 ` Matt Turner
2026-10-09 21:03 ` [PATCH v4 5/8] alpha: fix the local TLB invalidate " Magnus Lindholm
2026-10-09 21:03 ` [PATCH v4 6/8] alpha: fix the local TLB invalidate in the UP flush_tlb_page() Magnus Lindholm
2026-10-09 21:03 ` [PATCH v4 7/8] alpha: invalidate the local context in flush_tlb_mm() Magnus Lindholm
2026-10-09 21:03 ` [PATCH v4 8/8] alpha: invalidate the local context in flush_icache_user_page() Magnus Lindholm
2026-10-10 1:42 ` [PATCH v4 0/8] alpha: fix stale TLB translations breaking copy-on-write and writeback Matt Turner
2026-10-10 1:45 ` Matt Turner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261009210449.971057-1-linmag7@gmail.com \
--to=linmag7@gmail.com \
--cc=linux-alpha@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mattst88@gmail.com \
--cc=richard.henderson@linaro.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®