From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B6A4D2877F7 for ; Wed, 3 Jun 2026 06:09:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780466942; cv=none; b=cMe3Zs16qGClMca6j3y6WJA0qpA1oRuTqFejoJSHobd0Pis08rFySDhWw60kvTPHUZ+peY0CQPPq0G3p3IW/2rgnql9JhsTvtubmUPf0xvAFLVoZnrAxoX3JUFamQ2Wt0SOs45rjiW8cGl/Fhdi5JvieT41m216STZLJzNPHHz0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780466942; c=relaxed/simple; bh=rplsugD9qrD95irhZtPaL813UPk7/qFJJ4ATEKHAYU4=; h=Message-ID:Subject:From:To:Cc:Date:In-Reply-To:References: Content-Type:MIME-Version; b=mzLl44euDf2C8YPRADHaU3yv0gZ0ckoFgyrl8Ur1FqBtSYUC5xJ5C8EyZZXzlCoEy7W+GndPItof8UnQ5MD+B4d8X41hV7WibzinIx7auQCFDHcJjVMZRvCQLbvrwIvuRyZlCgJr3xYfQ7n60ARNMRsNGv9yQ88lrR2CIGIyZFg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=M308w3x6; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="M308w3x6" Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 652No0OE2403880; Wed, 3 Jun 2026 06:08:53 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=pp1; bh=95WJe2 ld0amV14OU1UZb8DE77vln26nKbfGACzakO+8=; b=M308w3x6pCxlU1vnqw36Sz Kn+n2X4eJvJx0muktbU8qJirdct2nJ/zM54Y5V44imj79DnIdpE62fX1bwt7V8hF xQfIEKI9yxpGevE4uG47wOCQAgPFLExIkNUn+MmBgNsFv9BaphFu1SawkLUGOSXQ ZFvz2I4GPEyDFHPK+1gjRZk5mnJ1OIR9jtEHV4gVW6m1WUXxRfYq+MXglz6dJatE 2vZ8lxjvjYnVhZJKGRBzt/MziAEgphK+STmLQrcUIxYQm6wcWZvQl/tXLu9zhdaB r6vtujQKNpXGGIP2CFSI9xP6TqxixY3sy0oFug9zrMhpShRslUlT9Lz/cmhjdqIg == Received: from ppma12.dal12v.mail.ibm.com (dc.9e.1632.ip4.static.sl-reverse.com [50.22.158.220]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4efpae902a-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 03 Jun 2026 06:08:53 +0000 (GMT) Received: from pps.filterd (ppma12.dal12v.mail.ibm.com [127.0.0.1]) by ppma12.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 6535s8gb019598; Wed, 3 Jun 2026 06:08:52 GMT Received: from smtprelay05.fra02v.mail.ibm.com ([9.218.2.225]) by ppma12.dal12v.mail.ibm.com (PPS) with ESMTPS id 4ega7qf0p5-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Wed, 03 Jun 2026 06:08:52 +0000 (GMT) Received: from smtpav04.fra02v.mail.ibm.com (smtpav04.fra02v.mail.ibm.com [10.20.54.103]) by smtprelay05.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 65368mrF46727546 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 3 Jun 2026 06:08:48 GMT Received: from smtpav04.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id D32292004B; Wed, 3 Jun 2026 06:08:48 +0000 (GMT) Received: from smtpav04.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 31DAE20040; Wed, 3 Jun 2026 06:08:46 +0000 (GMT) Received: from aboo.ibm.com (unknown [9.39.24.39]) by smtpav04.fra02v.mail.ibm.com (Postfix) with ESMTP; Wed, 3 Jun 2026 06:08:45 +0000 (GMT) Message-ID: <953a5a29dc71c5f3067f977b48c6da1ba36d58ac.camel@linux.ibm.com> Subject: Re: [PATCH 2/3] powerpc/powernv: fix preempt count leak in pnv_kexec_wait_secondaries_down From: Aboorva Devarajan To: Shrikanth Hegde , Madhavan Srinivasan , linuxppc-dev@lists.ozlabs.org Cc: Athira Rajeev , Christophe Leroy , linux-kernel@vger.kernel.org, Sourabh Jain , Ritesh Harjani Date: Wed, 03 Jun 2026 11:38:44 +0530 In-Reply-To: <99da8dfa-2624-44fb-96c5-ff7eddf717ac@linux.ibm.com> References: <20260518050855.1147242-1-aboorvad@linux.ibm.com> <20260518050855.1147242-3-aboorvad@linux.ibm.com> <99da8dfa-2624-44fb-96c5-ff7eddf717ac@linux.ibm.com> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.60.1 (3.60.1-1.fc44) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Authority-Analysis: v=2.4 cv=Zt3d7d7G c=1 sm=1 tr=0 ts=6a1fc4f5 cx=c_pps a=bLidbwmWQ0KltjZqbj+ezA==:117 a=bLidbwmWQ0KltjZqbj+ezA==:17 a=IkcTkHD0fZMA:10 a=FelO9ux0wxsA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=V8glGbnc2Ofi9Qvn3v5h:22 a=VnNF1IyMAAAA:8 a=KmrhXWUz77OnfvDMe7QA:9 a=QEXdDO2ut3YA:10 a=O8hF6Hzn-FEA:10 X-Proofpoint-GUID: 4RQ4VT8YlK4uol0qKNA4J5m6lchyvP_d X-Proofpoint-ORIG-GUID: w-b4aFE-RxnaFyZMJG8cXNvHvPeezooP X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNjAzMDA1NiBTYWx0ZWRfX59v9j55MSimh IkWA1fQUmzglCvpyvjvA3lZ8qdM2wc3FPWB9/xKp+pDL7WEWGcStbtryMe7rRsxMVG7fV5RYzEq gnHb5tOxPzR3c+92I1MoF1ONEo4Sjz3zjtXy4FQnasrnI5/mppN3lLtnFdoVQhqtKQvf8zUKkLL cg+uxYSdiESKITeM9MBtNVqXtEXmDQsf3CzOjl+3MlHq4I7q4qbOSMoKntfu3L3uljtJBrBTkWl XuEZDmzWhQ6mOiYU5esnuBDJNlI6pxIMfIrzTv2eeeB5DkUnHQi8tv+8Z0a3g0wHHC8KzSybV9j 5xL7aJFQCC9oYmbMvkP9GXRe4X8RcJy0Bk+XeghAGONjguDMZDaiI+yqXRllGpUFAzzN7g31P8Z XmcekolAvkyNJJy37n1hMj8gA1wlcBl4wVHOLjVRNRA0KbJEtkfiVw0q+uj+7dOyFW0vVhZEgTj Asv9/5SgHX15cdtTPiQ== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-06-03_02,2026-05-28_03,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 suspectscore=0 priorityscore=1501 bulkscore=0 clxscore=1015 phishscore=0 spamscore=0 malwarescore=0 adultscore=0 lowpriorityscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2605210000 definitions=main-2606030056 On Mon, 2026-05-18 at 13:26 +0530, Shrikanth Hegde wrote: >=20 > Hi Aboorva. >=20 > On 5/18/26 10:38 AM, Aboorva Devarajan wrote: > > pnv_kexec_wait_secondaries_down() calls get_cpu() to obtain the current > > CPU id but never calls the matching put_cpu(), leaking one > > preempt_disable() nesting level on every invocation. > >=20 > > In practice the imbalance does not trigger a visible splat because the > > kexec teardown path is a one-way trip: IRQs are already disabled, no > > schedule() occurs after the leak, and default_machine_kexec() overwrite= s > > preempt_count with HARDIRQ_OFFSET before jumping into kexec_sequence() > > which never returns. However the bookkeeping is still wrong. > >=20 > > In the kexec teardown path IRQs are already disabled and the CPU is > > pinned, so get_cpu()'s preempt_disable() side-effect is unnecessary. > > Replace get_cpu() with raw_smp_processor_id() which returns the CPU id > > without touching preempt_count. > >=20 > > Fixes: 298b34d7d578 ("powerpc/powernv: Fix kexec races going back to OP= AL") > > Signed-off-by: Aboorva Devarajan > > --- > > =C2=A0 arch/powerpc/platforms/powernv/setup.c | 2 +- > > =C2=A0 1 file changed, 1 insertion(+), 1 deletion(-) > >=20 > > diff --git a/arch/powerpc/platforms/powernv/setup.c b/arch/powerpc/plat= forms/powernv/setup.c > > index 4dbb47ddbdcc4..177da0defcb36 100644 > > --- a/arch/powerpc/platforms/powernv/setup.c > > +++ b/arch/powerpc/platforms/powernv/setup.c > > @@ -396,7 +396,7 @@ static void pnv_kexec_wait_secondaries_down(void) > > =C2=A0 { > > =C2=A0=C2=A0 int my_cpu, i, notified =3D -1; > > =C2=A0=20 > > - my_cpu =3D get_cpu(); > > + my_cpu =3D raw_smp_processor_id(); > > =C2=A0=20 >=20 > Is it always with irq-disabled? > How about !CONFIG_SMP and in kexec_prepare_cpus. I see it disables interr= upt later. > (though it is a less common config) >=20 IIUC, PPC_POWERNV does 'select FORCE_SMP' (-> selects SMP), so there is no !CONFIG_SMP powernv build. The !SMP kexec_prepare_cpus() variant in arch/powerpc/kexec/core_64.c, the one you spotted that calls ppc_md.kexec_cpu_down() before local_irq_disable() is therefore never compiled with powernv, so pnv_kexec_cpu_down() -> pnv_kexec_wait_secondaries_down() can't be reached through it. so, IRQs are disabled in every case that reaches this function. > So use smp_processor_id()?? One could compile with CONFIG_DEBUG_PREEMPT= =3Dy and > see any reports. >=20 > > =C2=A0=C2=A0 for_each_online_cpu(i) { > > =C2=A0=C2=A0 uint8_t status; sure, I'll switch to smp_processor_id() in v2 rather than raw_smp_processor= _id(). It returns the cpu id without touching preempt_count (so the leak is gone), and unlike the raw variant it keeps the CONFIG_DEBUG_PREEMPT check which is a no-op here since IRQs are off, but will flag any future caller that reaches this path while preemptible instead of silently hiding it. Thanks, Aboorva