From: David Laight <David.Laight@ACULAB.COM>
To: 'Andy Lutomirski' <luto@kernel.org>, "Luck, Tony" <tony.luck@intel.com>
Cc: Peter Zijlstra <peterz@infradead.org>,
"Yu, Fenghua" <fenghua.yu@intel.com>,
Ingo Molnar <mingo@kernel.org>,
Thomas Gleixner <tglx@linutronix.de>,
Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
H Peter Anvin <hpa@zytor.com>, "Raj, Ashok" <ashok.raj@intel.com>,
"Shankar, Ravi V" <ravi.v.shankar@intel.com>,
linux-kernel <linux-kernel@vger.kernel.org>, x86 <x86@kernel.org>
Subject: RE: [PATCH v10 6/6] x86/split_lock: Enable split lock detection by kernel parameter
Date: Mon, 16 Dec 2019 16:21:46 +0000 [thread overview]
Message-ID: <5c492fa2d2fd47fcaa2c38a812a3d572@AcuMS.aculab.com> (raw)
In-Reply-To: <CALCETrX6Riy8vHkWcYOt-Vt0xD2JGgua4o-8F6KatUsXH9iEUQ@mail.gmail.com>
From: Andy Lutomirski
> Sent: 12 December 2019 20:01
> On Thu, Dec 12, 2019 at 11:46 AM Luck, Tony <tony.luck@intel.com> wrote:
> >
> > >> If anything we could switch the entire bitmap interface to unsigned int,
> > >> but I'm not sure that'd actually help much.
That would break all the code that assumes it is 'unsigned long'.
At best it could be changed to a structure with an integral member.
That would make it a little harder for code to 'peek inside' the abstraction.
> > > As we've been looking for potential split lock issues in kernel code, most of
> > > the ones we found relate to callers who have <=32 bits and thus stick:
> > >
> > > u32 flags;
> > >
> > > in their structure. So it would solve those places, and fix any future code
> > > where someone does the same thing.
And break all the places that use 'unsigned long' - especially on BE.
> > If different architectures can do better with 8-bit/16-bit/32-bit/64-bit instructions
> > to manipulate bitmaps, then perhaps this is justification to make all the
> > functions operate on "bitmap_t" and have each architecture provide the
> > typedef for their favorite width.
typedef struct { u8/u32/u64 bitmap_val } bitmap_t;
> Hmm. IMO there are really two different types of uses of the API.
>
> 1 There's a field somewhere and I want to atomically set a bit. Something like:
>
> struct whatever {
> ...
> whatever_t field;
> ...
> };
>
> struct whatever *w;
> set_bit(3, &w->field);
>
> If whatever_t is architecture-dependent, then it's really awkward to
> use more than 32 bits, since some architectures won't have more than
> 32-bits.
You could implement that using multiple functions and 'sizeof'.
At the moment that code is broken on BE systems unless whatever_t is
the same size as 'unsigned long'.
> 2. DECLARE_BITMAP(), etc. That is, someone wants a biggish bitmap
> with a certain number of bits.
>
> Here the type doesn't really matter.
Except some code uses its own 'unsigned long[]' instead of DECALRE_BITMAP.
The low level x86 code actually passes 'unsigned int[]' knowing that
the cast happened to be ok.
> On an architecture with genuinely atomic bit operations (i.e. no
> hashed spinlocks involved), the width really shouldn't matter.
> set_bit() should promise to be atomic on that bit, to be a full
> barrier, and to not modify adjacent bits. I don't see why the width
> would matter for most use cases. If we're concerned, the
> implementation could actually use the largest atomic operation and
> just suitably align it. IOW, on x86, LOCK BTSQ *where we manually
> align the pointer to 8 bytes and adjust the bit number accordingly*
> should cover every possible case even of PeterZ's concerns are
> correct.
A properly abstracted BITMAP library should be allowed to permute
the bit number using a run-time initialised map.
(eg xor with any value less than the number of bits in 'unsigned long'.)
Otherwise you'll always allow the user to 'peek inside'.
There is also:
1a) I've a field I need to set a bit in.
There must be a function to do that (I like functions).
Ah yes:
set_bit(3, &s->m);
Bugger doesn't compile, try:
set_bit(3, (void *)&s->m);
That must be how I should do it.
ISTR at least one driver does that when writing ring buffer entries.
2b) I've a 'u32[]', if I cast it to 'unsigned long' I can use the 'bit' functions on it.
The data never changes (after initialisation), but I've use the atomic operations
anyway.
> For the "I have a field in a struct and I just want an atomic RMW that
> changes one bit*, an API that matches the rest of the atomic API seems
> nice: just act on atomic_t and atomic64_t.
>
> The current "unsigned long" thing basically can't be used on a 64-bit
> big-endian architecture with a 32-bit field without gross hackery.
Well, you can xor the bit number with 63 on BE systems.
Then 8/16/32 sized field members work fine - provided you don't
care what values are actually used.
> And sometimes we actually want a 32-bit field.
>
> Or am I missing some annoying subtlely here?
Some code has assumed DECLARE_BITFIELD() uses 'unsigned long'.
David
-
Registered Address Lakeside, Bramley Road, Mount Farm, Milton Keynes, MK1 1PT, UK
Registration No: 1397386 (Wales)
next prev parent reply other threads:[~2019-12-16 16:21 UTC|newest]
Thread overview: 145+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-11-21 0:53 [PATCH v10 0/6] Enable split lock detection for real time and debug Fenghua Yu
2019-11-21 0:53 ` [PATCH v10 1/6] x86/msr-index: Add two new MSRs Fenghua Yu
2019-11-21 0:53 ` [PATCH v10 2/6] x86/cpufeatures: Enumerate the IA32_CORE_CAPABILITIES MSR Fenghua Yu
2019-11-21 0:53 ` [PATCH v10 3/6] x86/split_lock: Enumerate split lock detection by " Fenghua Yu
2019-11-21 0:53 ` [PATCH v10 4/6] x86/split_lock: Enumerate split lock detection if the IA32_CORE_CAPABILITIES MSR is not supported Fenghua Yu
2019-11-21 22:07 ` Andy Lutomirski
2019-11-22 0:37 ` Fenghua Yu
2019-11-22 2:13 ` Andy Lutomirski
2019-11-22 9:46 ` Peter Zijlstra
2019-11-21 0:53 ` [PATCH v10 5/6] x86/split_lock: Handle #AC exception for split lock Fenghua Yu
2019-11-21 22:10 ` Andy Lutomirski
2019-11-21 23:14 ` Fenghua Yu
2019-11-21 23:12 ` Andy Lutomirski
2019-11-21 0:53 ` [PATCH v10 6/6] x86/split_lock: Enable split lock detection by kernel parameter Fenghua Yu
2019-11-21 6:04 ` Ingo Molnar
2019-11-21 13:01 ` Peter Zijlstra
2019-11-21 13:15 ` Peter Zijlstra
2019-11-21 21:51 ` Luck, Tony
2019-11-21 22:24 ` Andy Lutomirski
2019-11-21 22:29 ` Luck, Tony
2019-11-21 23:18 ` Andy Lutomirski
2019-11-21 23:53 ` Fenghua Yu
2019-11-22 1:52 ` Sean Christopherson
2019-11-22 2:21 ` Andy Lutomirski
2019-11-22 2:39 ` Xiaoyao Li
2019-11-22 2:57 ` Andy Lutomirski
2019-11-21 23:55 ` Luck, Tony
2019-11-22 0:55 ` Luck, Tony
2019-11-22 10:08 ` Peter Zijlstra
2019-11-21 16:14 ` Fenghua Yu
2019-11-21 17:14 ` Ingo Molnar
2019-11-21 17:35 ` Peter Zijlstra
2019-11-21 17:12 ` Ingo Molnar
2019-11-21 17:34 ` Luck, Tony
2019-11-22 10:51 ` Peter Zijlstra
2019-11-22 15:27 ` Peter Zijlstra
2019-11-22 17:22 ` Luck, Tony
2019-11-22 20:23 ` Peter Zijlstra
2019-11-22 18:02 ` Luck, Tony
2019-11-22 20:23 ` Peter Zijlstra
2019-11-22 20:42 ` Fenghua Yu
2019-11-22 21:25 ` Andy Lutomirski
2019-12-12 8:57 ` Peter Zijlstra
2019-12-12 18:52 ` Luck, Tony
2019-12-12 19:46 ` Luck, Tony
2019-12-12 20:01 ` Andy Lutomirski
2019-12-16 16:21 ` David Laight [this message]
2019-11-22 18:44 ` Sean Christopherson
2019-11-22 20:30 ` Peter Zijlstra
2019-11-23 0:30 ` Luck, Tony
2019-11-25 16:13 ` Sean Christopherson
2019-12-02 18:20 ` Luck, Tony
2019-12-12 8:59 ` Peter Zijlstra
2020-01-10 19:24 ` [PATCH v11] x86/split_lock: Enable split lock detection by kernel Luck, Tony
2020-01-14 5:55 ` Sean Christopherson
2020-01-15 22:27 ` Luck, Tony
2020-01-15 22:57 ` Sean Christopherson
2020-01-15 23:48 ` Luck, Tony
2020-01-22 18:55 ` [PATCH v12] " Luck, Tony
2020-01-22 19:04 ` Borislav Petkov
2020-01-22 20:03 ` Luck, Tony
2020-01-22 20:55 ` Borislav Petkov
2020-01-22 22:42 ` Arvind Sankar
2020-01-22 22:52 ` Arvind Sankar
2020-01-22 23:24 ` Luck, Tony
2020-01-23 0:45 ` Arvind Sankar
2020-01-23 1:23 ` Luck, Tony
2020-01-23 4:21 ` Arvind Sankar
2020-01-23 17:15 ` Luck, Tony
2020-01-23 3:53 ` [PATCH v13] " Luck, Tony
2020-01-23 4:45 ` Arvind Sankar
2020-01-23 23:16 ` [PATCH v14] " Luck, Tony
2020-01-24 21:36 ` Thomas Gleixner
2020-01-25 2:47 ` [PATCH v15] " Luck, Tony
2020-01-25 10:44 ` Borislav Petkov
2020-01-25 19:55 ` Luck, Tony
2020-01-25 20:12 ` Peter Zijlstra
2020-01-25 20:33 ` Borislav Petkov
2020-01-25 21:42 ` Luck, Tony
2020-01-25 22:17 ` Borislav Petkov
2020-01-25 20:29 ` Borislav Petkov
2020-01-25 13:41 ` Thomas Gleixner
2020-01-25 22:07 ` [PATCH v16] " Luck, Tony
2020-01-25 22:43 ` Mark D Rustad
2020-01-25 23:10 ` Luck, Tony
2020-01-26 17:27 ` Mark D Rustad
2020-01-26 20:05 ` [PATCH v17] " Luck, Tony
2020-01-29 12:31 ` Thomas Gleixner
2020-01-29 15:24 ` [tip: x86/cpu] " tip-bot2 for Peter Zijlstra (Intel)
2020-02-03 20:41 ` [PATCH v17] " Sean Christopherson
2020-02-06 0:49 ` [PATCH] x86/split_lock: Avoid runtime reads of the TEST_CTRL MSR Luck, Tony
2020-02-06 1:18 ` Andy Lutomirski
2020-02-06 16:46 ` Luck, Tony
2020-02-06 19:37 ` Andy Lutomirski
2020-03-03 19:22 ` Sean Christopherson
2020-02-04 0:04 ` [PATCH v17] x86/split_lock: Enable split lock detection by kernel Sean Christopherson
2020-02-04 12:52 ` Thomas Gleixner
2020-01-26 0:34 ` [PATCH v16] " Andy Lutomirski
2020-01-26 20:01 ` Luck, Tony
2020-01-25 21:25 ` [PATCH v15] " Arvind Sankar
2020-01-25 21:50 ` Luck, Tony
2020-01-25 23:51 ` Arvind Sankar
2020-01-26 2:52 ` Luck, Tony
2020-01-27 2:05 ` Tony Luck
2020-01-27 8:04 ` Peter Zijlstra
2020-01-27 8:36 ` Peter Zijlstra
2020-01-27 17:35 ` Luck, Tony
2020-01-27 8:02 ` Peter Zijlstra
2019-12-13 0:09 ` [PATCH v11] x86/split_lock: Enable split lock detection by kernel parameter Tony Luck
2019-12-13 0:16 ` Luck, Tony
2019-11-21 17:43 ` [PATCH v10 6/6] " David Laight
2019-11-21 17:51 ` Andy Lutomirski
2019-11-21 18:53 ` Fenghua Yu
2019-11-21 19:01 ` Andy Lutomirski
2019-11-21 20:25 ` Fenghua Yu
2019-11-21 20:19 ` Peter Zijlstra
2019-11-21 19:46 ` Peter Zijlstra
2019-11-21 20:25 ` Peter Zijlstra
2019-11-21 21:22 ` Andy Lutomirski
2019-11-22 9:25 ` Peter Zijlstra
2019-11-22 17:48 ` Luck, Tony
2019-11-22 20:31 ` Peter Zijlstra
2019-11-22 21:23 ` Andy Lutomirski
2019-12-11 17:52 ` Peter Zijlstra
2019-12-11 18:12 ` Andy Lutomirski
2019-12-11 22:34 ` Peter Zijlstra
2019-12-12 19:40 ` Andy Lutomirski
2019-12-16 9:59 ` David Laight
2019-12-16 17:22 ` Andy Lutomirski
2019-12-16 17:45 ` David Laight
2019-12-16 18:06 ` Andy Lutomirski
2019-12-17 10:03 ` David Laight
2019-12-11 18:44 ` Luck, Tony
2019-12-11 22:39 ` Peter Zijlstra
2019-12-12 10:36 ` David Laight
2019-12-12 13:04 ` Peter Zijlstra
2019-12-12 16:02 ` Andy Lutomirski
2019-12-12 16:23 ` David Laight
2019-12-12 16:29 ` David Laight
2019-11-21 19:56 ` Peter Zijlstra
2019-11-21 21:01 ` Andy Lutomirski
2019-11-22 9:36 ` Peter Zijlstra
2019-11-22 9:46 ` David Laight
2019-11-22 20:32 ` Peter Zijlstra
2019-11-21 8:00 ` Peter Zijlstra
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5c492fa2d2fd47fcaa2c38a812a3d572@AcuMS.aculab.com \
--to=david.laight@aculab.com \
--cc=ashok.raj@intel.com \
--cc=bp@alien8.de \
--cc=fenghua.yu@intel.com \
--cc=hpa@zytor.com \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@kernel.org \
--cc=mingo@kernel.org \
--cc=mingo@redhat.com \
--cc=peterz@infradead.org \
--cc=ravi.v.shankar@intel.com \
--cc=tglx@linutronix.de \
--cc=tony.luck@intel.com \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome