From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753182AbcLGKDh (ORCPT ); Wed, 7 Dec 2016 05:03:37 -0500 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]:45099 "EHLO mx0a-001b2d01.pphosted.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1751798AbcLGKDg (ORCPT ); Wed, 7 Dec 2016 05:03:36 -0500 Subject: Re: [RFC PATCH v3] mm: use READ_ONCE in page_cpupid_xchg_last() To: Michal Hocko References: <584523E4.9030600@huawei.com> <58461A0A.3070504@huawei.com> <20161207084305.GA20350@dhcp22.suse.cz> <7b74a021-e472-a21e-7936-6741e07906b5@suse.cz> <20161207085809.GD17136@dhcp22.suse.cz> <20161207095943.GF17136@dhcp22.suse.cz> Cc: Vlastimil Babka , Xishi Qiu , Andrew Morton , Mel Gorman , Yaowei Bai , Linux MM , LKML , Yisheng Xie From: Christian Borntraeger Date: Wed, 7 Dec 2016 11:03:29 +0100 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.4.0 MIME-Version: 1.0 In-Reply-To: <20161207095943.GF17136@dhcp22.suse.cz> Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: 7bit X-TM-AS-GCONF: 00 X-Content-Scanned: Fidelis XPS MAILER x-cbid: 16120710-0024-0000-0000-00001536D1A9 X-IBM-SpamModules-Scores: X-IBM-SpamModules-Versions: BY=3.00006208; HX=3.00000240; KW=3.00000007; PH=3.00000004; SC=3.00000194; SDB=6.00790469; UDB=6.00382811; IPR=6.00568208; BA=6.00004950; NDR=6.00000001; ZLA=6.00000005; ZF=6.00000009; ZB=6.00000000; ZP=6.00000000; ZH=6.00000000; ZU=6.00000002; MB=3.00013563; XFM=3.00000011; UTC=2016-12-07 10:03:34 X-IBM-AV-DETECTION: SAVI=unused REMOTE=unused XFE=unused x-cbparentid: 16120710-0025-0000-0000-000046C29D5E Message-Id: <5d4accd3-e26b-d23f-5417-debe9ad7148a@de.ibm.com> X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10432:,, definitions=2016-12-07_03:,, signatures=0 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 suspectscore=0 malwarescore=0 phishscore=0 adultscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1609300000 definitions=main-1612070173 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 12/07/2016 10:59 AM, Michal Hocko wrote: > On Wed 07-12-16 10:40:47, Christian Borntraeger wrote: >> On 12/07/2016 10:29 AM, Vlastimil Babka wrote: >>> On 12/07/2016 09:58 AM, Michal Hocko wrote: >>>> On Wed 07-12-16 09:48:52, Vlastimil Babka wrote: >>>>> On 12/07/2016 09:43 AM, Michal Hocko wrote: >>>>>> On Tue 06-12-16 09:53:14, Xishi Qiu wrote: >>>>>>> A compiler could re-read "old_flags" from the memory location after reading >>>>>>> and calculation "flags" and passes a newer value into the cmpxchg making >>>>>>> the comparison succeed while it should actually fail. >>>>>>> >>>>>>> Signed-off-by: Xishi Qiu >>>>>>> Suggested-by: Christian Borntraeger >>>>>>> --- >>>>>>> mm/mmzone.c | 2 +- >>>>>>> 1 file changed, 1 insertion(+), 1 deletion(-) >>>>>>> >>>>>>> diff --git a/mm/mmzone.c b/mm/mmzone.c >>>>>>> index 5652be8..e0b698e 100644 >>>>>>> --- a/mm/mmzone.c >>>>>>> +++ b/mm/mmzone.c >>>>>>> @@ -102,7 +102,7 @@ int page_cpupid_xchg_last(struct page *page, int cpupid) >>>>>>> int last_cpupid; >>>>>>> >>>>>>> do { >>>>>>> - old_flags = flags = page->flags; >>>>>>> + old_flags = flags = READ_ONCE(page->flags); >>>>>>> last_cpupid = page_cpupid_last(page); >>>>>> >>>>>> what prevents compiler from doing? >>>>>> old_flags = READ_ONCE(page->flags); >>>>>> flags = READ_ONCE(page->flags); >>>>> >>>>> AFAIK, READ_ONCE tells the compiler that page->flags is volatile. It >>>>> can't read from volatile location more times than being told? >>>> >>>> But those are two different variables which we assign to so what >>>> prevents the compiler from applying READ_ONCE on each of them >>>> separately? >>> >>> I would naively expect that it's assigned to flags first, and then from >>> flags to old_flags. But I don't know exactly the C standard evaluation >>> rules that apply here. >>> >>>> Anyway, this could be addressed easily by >>> >>> Yes, that way there should be no doubt. >> >> That change would make it clearer, but the code is correct anyway, >> as assignments in C are done from right to left, so >> old_flags = flags = READ_ONCE(page->flags); >> >> is equivalent to >> >> flags = READ_ONCE(page->flags); >> old_flags = flags; > > OK, I guess you are right. For some reason I thought that the compiler > is free to bypass flags and split an assignment > a = b = c; into b = c; a = c > which would still follow from right to left rule. I guess I am over > speculating here though, so sorry for the noise. Hmmm, just rereading C, I am no longer sure... I cannot find anything right now, that adds a sequence point in here. Still looking...