From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 920B9146588 for ; Mon, 15 Jun 2026 10:12:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781518355; cv=none; b=u5vy7/N3iQkH0byMo8LaHMeoHr7nHsP6uflWj5YHNQ2qUU5xOjKzX2VNPW7AyIY8dr5s1abW4okmpN/CQ7v7wE/f5dyx2LJ0tW+vTl21w4q/OJzqiv6xihg9gtgXIk5gD8lIQUMvQDxtMJ2vGJOMrFO9Lj8ZOqVLCK+lxdd3fqM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781518355; c=relaxed/simple; bh=IbwmXwIcDH9ohSAtSW80tfvssE++Y7xx7QhTi72YQZE=; h=Message-ID:Subject:From:To:Cc:Date:In-Reply-To:References: Content-Type:MIME-Version; b=cS5qijhFmdZVa5froyj5XM0IFUBia9qlZ6H+71n2jtWW5ppqc/Dm3gk1ZBVc5mqJuuVRf/fOpuizeiA5lwnWwScoN8Ckgin/LPXfNr1Wx9LF+QL8DhbqL+XLmJyMaGf+8lMe1D00xjttKGzxECSGbQuGM7sIV6yC+4J8w4LzAHA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=bqsPyXbT; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=MjnhNYtI; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="bqsPyXbT"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="MjnhNYtI" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1781518353; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=J5KDtylEulH4nzlQDklazM4BcDULe+/NGudq0xGCiOA=; b=bqsPyXbTyA7upuMd4hN5S2DI6g3hV6Qebvv8Tvp2jFBzJIZVNDTMF79SG9Kp+riCIfG/qD F6EF4V0g9/Vv5M37cfGZ0KYz6EkhjqCh8htaz+LjWyY61tciO0BvuwhBtnonnCBdQUzU1T wOjEwvgT9RjTy772vBMIiDuQaga8ESY= Received: from mail-wr1-f69.google.com (mail-wr1-f69.google.com [209.85.221.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-256-WrSTCstBMAyVIC2ulQdPjA-1; Mon, 15 Jun 2026 06:12:29 -0400 X-MC-Unique: WrSTCstBMAyVIC2ulQdPjA-1 X-Mimecast-MFC-AGG-ID: WrSTCstBMAyVIC2ulQdPjA_1781518348 Received: by mail-wr1-f69.google.com with SMTP id ffacd0b85a97d-4600c8cb13aso2258300f8f.1 for ; Mon, 15 Jun 2026 03:12:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1781518348; x=1782123148; darn=vger.kernel.org; h=mime-version:user-agent:content-transfer-encoding:references :in-reply-to:date:cc:to:from:subject:message-id:from:to:cc:subject :date:message-id:reply-to; bh=J5KDtylEulH4nzlQDklazM4BcDULe+/NGudq0xGCiOA=; b=MjnhNYtIdjLho4fGlyZfPFR/SgUeOEyhBSUp0QsYfOrLtYeCZjIvVBCIy0tiRUzt7+ hX5BrlkZi4cJqMAnMfYZWwUccCTQPqI/mdF7xgPnBP+H2lJzV9Tw2cDO1d+DERutvF+M o7hij11wKTBlRCNOSkL6/sZ/aJwHA/1csBtHTp0x0PTQC+YbtZR2SdvMeCeOVQSGjbFA EG2DdcpK5rhqWZ0+7zBBSwQY+9YPW2L4L6lpYnJLstrQgHWjcoTC7vu2pgQ7HIQ5nk0M ZH0rQQrzea3ytPU3N5aoGwP+sOgrfWH4cr714H/gXO1pwIgpxHmuFrGW616cMbW/8NMx sfJA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781518348; x=1782123148; h=mime-version:user-agent:content-transfer-encoding:references :in-reply-to:date:cc:to:from:subject:message-id:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=J5KDtylEulH4nzlQDklazM4BcDULe+/NGudq0xGCiOA=; b=Whjgm/UbNonadLnZMJp5tNJVpm/ajoNrE6MnAc4wxKTsxfCrGfhSx5LNBU+IM/8InU svV7jfHUr5v3FJhKz8aiUIpfgMIjLaw7hVELexK0OqIq7TGimS2XrUwiF83LYrbv0UrB 8TE35DjkfTjmONwAACQCTYAr1dTqfk54u4M4mtDG7UQ4g9mJ1Sh0/IJJz6vOXhht7jxo VI5+WHPIOJVTFwTz1/vv/BsZoK5SBiVbyKY5hQyofq+GwIGMolftn0ImNd3smmFR7/w9 u53CEo/+oqfEtq9uzlvQlVCKuZNo1DnW2+Jh9j0iJI0ERM6fpauA3CNjQRuL7aAzABHf H3pw== X-Forwarded-Encrypted: i=1; AFNElJ+ZWjelylyeoGU+24SsRVUTc5C4LDQ+Db/65A02PoqunEOHYjTp+G9EJuNC+UjPYA39ITo+ZrMJ9d+EY7Y=@vger.kernel.org X-Gm-Message-State: AOJu0YwfmF7xuK+KAjLjLIZ+8x0iKShhQrA7rT5ExBQ4x5ve8jI9KXWS EzXvQ5V4GT1AMAbYAbkaxJPeHDs2pZfFSMUBa0EsmXlvo0I1ppTwhiHrV5IABuG3S45jufarAGB vFX2pMu60zRE6YT1+XGKWaeplu5tefBfHDKAUvBRSu/4+qMHucbzu7+tVeoceTiu779wUvpo24Q == X-Gm-Gg: Acq92OE5ElXKxitwUNkjskfTtEZUkeJ8vGqUmyjmhsRFOl1dYXGGeB3hFpZ294xkCTj F9mVz2Dt4mMMXDEvrkrAPbtbBfvcFuXbsnDYuPtlYST6IoWzzYQQcGe3tqwvFVJrG0oMi0WLj11 txaFYjVmyp/8a+xPZW/azrw3dNlQi/5A8ScQdNiXHXKrOoruSfG28o14cUMtwSaJEGoNvKPJDUI 9HhudrR/Xk6RBSWNUjDV7HPGRlKLIeFJCyKQJjYFDJZJRi0SpbNVQzSLkAcE1sTsOz396kWNBt1 3lwAgBnulfMtmUIT7V7t40J0SXpZ+M0yoSxfgjo3VBtrXSQjV5Oq8mtw8wfj4P54iqd7aN7RBgm 5QMugVyX87K8vizxqURQTjzmzYg== X-Received: by 2002:a05:6000:41fe:b0:460:67b7:54f1 with SMTP id ffacd0b85a97d-4606dbbcc38mr19632473f8f.42.1781518347907; Mon, 15 Jun 2026 03:12:27 -0700 (PDT) X-Received: by 2002:a05:6000:41fe:b0:460:67b7:54f1 with SMTP id ffacd0b85a97d-4606dbbcc38mr19632415f8f.42.1781518347348; Mon, 15 Jun 2026 03:12:27 -0700 (PDT) Received: from [192.168.1.167] ([185.168.96.228]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4606f2d933esm31425885f8f.33.2026.06.15.03.12.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 15 Jun 2026 03:12:26 -0700 (PDT) Message-ID: <4442008c90e6957d9d6916a3b30afd1401b2f760.camel@redhat.com> Subject: Re: [PATCH v3 4/9] rv/ha: fix ha_invariant_passed_ns silent bypass of invariant check From: Gabriele Monaco To: wen.yang@linux.dev Cc: Steven Rostedt , linux-trace-kernel@vger.kernel.org, linux-kernel@vger.kernel.org Date: Mon, 15 Jun 2026 12:12:26 +0200 In-Reply-To: <812b7b8e8979b4ab00ac7727e3fea578799f2a8b.1780847473.git.wen.yang@linux.dev> References: <812b7b8e8979b4ab00ac7727e3fea578799f2a8b.1780847473.git.wen.yang@linux.dev> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.60.2 (3.60.2-1.fc44) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 On Mon, 2026-06-08 at 00:13 +0800, wen.yang@linux.dev wrote: > From: Wen Yang >=20 > The function is documented as "prepare the invariant and return the > time > since reset", but on the first call (env_store =3D=3D U64_MAX) it exits > early without calling ha_set_invariant_ns(): >=20 > =C2=A0 if (ha_monitor_env_invalid(ha_mon, env))=C2=A0 /* env_store =3D=3D= U64_MAX > */ > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 return 0;=C2=A0=C2=A0 /* ha_set_invariant_= ns skipped, env_store stays > U64_MAX */ > =C2=A0 ... > =C2=A0 ha_set_invariant_ns(ha_mon, env, expire - passed, time_ns); >=20 > This leaves env_store =3D=3D U64_MAX, so ha_check_invariant_ns() always > passes on the first activation regardless of elapsed time: >=20 > =C2=A0 return READ_ONCE(ha_mon->env_store[env]) >=3D time_ns;=C2=A0 /* U6= 4_MAX >=3D > any */ >=20 > Fix: establish the guard before converting to the invariant: >=20 > =C2=A0 if (ha_monitor_env_invalid(ha_mon, env)) > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 ha_reset_clk_ns(ha_mon, env, time_ns); /* = guard: env_store =3D > time_ns */ > =C2=A0 passed =3D ha_get_env(ha_mon, env, time_ns); > =C2=A0 ha_set_invariant_ns(ha_mon, env, expire - passed, time_ns); > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 /* invariant: env_store =3D t= ime_ns + > expire */ >=20 > Apply the same fix to ha_invariant_passed_jiffy(). >=20 > Signed-off-by: Wen Yang This is neat and probably works just fine in your case. Anyway I'm planning on a more seamless solution not involving invalid states at all. Initialisation would include a reset, which should work better on monitors doing da_handle_start(), so not running the first event. That's, by the way, pretty much what you wanted by doing reset() on the (virtual) init transition. We first needs Nam's simplification though [1]. We can synchronise during this development cycle, you probably won't really need to bother for now. Thanks, Gabriele [1] - https://lore.kernel.org/lkml/08188c28f274da63a3f8549add3086a92aef45e5.17809= 08661.git.namcao@linutronix.de > --- > =C2=A0include/rv/ha_monitor.h | 17 +++++++++++++---- > =C2=A01 file changed, 13 insertions(+), 4 deletions(-) >=20 > diff --git a/include/rv/ha_monitor.h b/include/rv/ha_monitor.h > index 28d3c74cabfc..e5860900a337 100644 > --- a/include/rv/ha_monitor.h > +++ b/include/rv/ha_monitor.h > @@ -365,16 +365,22 @@ static inline bool ha_check_invariant_ns(struct > ha_monitor *ha_mon, > =C2=A0} > =C2=A0/* > =C2=A0 * ha_invariant_passed_ns - prepare the invariant and return the > time since reset > + * > + * If the env has not been initialised yet (first entry into a state > with an > + * invariant), anchor the guard clock at the current time so that > the full > + * budget is available from this point.=C2=A0 This preserves the > documented > + * guard=E2=86=92invariant ordering: ha_set_invariant_ns() is always > preceded by a > + * valid guard representation in env_store. > =C2=A0 */ > =C2=A0static inline u64 ha_invariant_passed_ns(struct ha_monitor *ha_mon, > enum envs env, > =C2=A0 =C2=A0=C2=A0 u64 expire, u64 time_ns) > =C2=A0{ > - u64 passed =3D 0; > + u64 passed; > =C2=A0 > =C2=A0 if (env < 0 || env >=3D ENV_MAX_STORED) > =C2=A0 return 0; > =C2=A0 if (ha_monitor_env_invalid(ha_mon, env)) > - return 0; > + ha_reset_clk_ns(ha_mon, env, time_ns); > =C2=A0 passed =3D ha_get_env(ha_mon, env, time_ns); > =C2=A0 ha_set_invariant_ns(ha_mon, env, expire - passed, time_ns); > =C2=A0 return passed; > @@ -404,16 +410,19 @@ static inline bool > ha_check_invariant_jiffy(struct ha_monitor *ha_mon, > =C2=A0} > =C2=A0/* > =C2=A0 * ha_invariant_passed_jiffy - prepare the invariant and return the > time since reset > + * > + * Same first-use semantics as ha_invariant_passed_ns(): anchor the > guard clock > + * now if the env has not been initialised. > =C2=A0 */ > =C2=A0static inline u64 ha_invariant_passed_jiffy(struct ha_monitor > *ha_mon, enum envs env, > =C2=A0 =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 u64 expire, u64 time_ns) > =C2=A0{ > - u64 passed =3D 0; > + u64 passed; > =C2=A0 > =C2=A0 if (env < 0 || env >=3D ENV_MAX_STORED) > =C2=A0 return 0; > =C2=A0 if (ha_monitor_env_invalid(ha_mon, env)) > - return 0; > + ha_reset_clk_jiffy(ha_mon, env); > =C2=A0 passed =3D ha_get_env(ha_mon, env, time_ns); > =C2=A0 ha_set_invariant_jiffy(ha_mon, env, expire - passed); > =C2=A0 return passed;