From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from YT6PR01CU002.outbound.protection.outlook.com (mail-canadacentralazon11022138.outbound.protection.outlook.com [40.107.193.138]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 474313254A9 for ; Mon, 16 Mar 2026 19:36:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=40.107.193.138 ARC-Seal:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773689806; cv=fail; b=NPJoS/4yJLyeWaMc9ehTpjbeW519r5WxuQxEwt/P5Q+PlEHTB83XflhCWp7rlYc5rHT+jN58CADcYVNgviVjNU0iE/EXfPV9JqrzwC0cWyBlIbHNP8EigEhm8ABxnDmAHFQE8nyloj/R7ewRuCFiDBBmf2DJD+eWdU+PlFMXiso= ARC-Message-Signature:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1773689806; c=relaxed/simple; bh=wkvNaBb3K4nRBXXgyFk/O8sInJWpiABCu6Pdj2EiNhw=; h=Message-ID:Date:Subject:To:Cc:References:From:In-Reply-To: Content-Type:MIME-Version; b=lrGYR3nab37Az1G410vvbFqngDogmtCb7O4nWIhQiRfaBtrF2Fnx7pvQKjsMEkWqD01Hxwg/DZitVaH23VqN26sjuts8VvB/nhOeeqDndctIQ2yuJs4oAIae0DTDd3DcI++lCv0Hcmv/Rrl9wLSoL9Iwf17Lwm6h9gdpqyLjDfM= ARC-Authentication-Results:i=2; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=efficios.com; spf=pass smtp.mailfrom=efficios.com; dkim=pass (2048-bit key) header.d=efficios.com header.i=@efficios.com header.b=QxMrh9++; arc=fail smtp.client-ip=40.107.193.138 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=efficios.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=efficios.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=efficios.com header.i=@efficios.com header.b="QxMrh9++" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=g4+fHKC9k59Q+/beeAkvCy2J4BKwkz7m2gENeHhzho0XyKnf759dFB/ccDOmHfodSlJA7PgRwrUbQPETCos50G8xAClWI3PLKPU2GTsvyyYZShJL+UqMqzbgmsc/d/pp5ylT3aDncaJGLFPVPartb1OyPbZITULRyyKXid2i6jOmav4mpg72wFbRxFz/d3W6mymwDwekySTmB9opOKaiDW9QOitgSWIGK1yB1C5y6KpHH2cQPCravoB7igH1Bny50Qu88OJRz8a/cK1dBY2m6l4k5+0tHyTM/SHDk8dQsVVD4caZSsiKpVqupQGdo51B8g0dzP+R6r4a3siuR/Y15w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=wkxaTXkzFh15Sr/qcc28Acc3FRTgjrUc46Ac4rtSkkY=; b=tmRyPozdQI4bHbsfK6MJw3Pk2yL5MADvUUWXiapSXRC8O0fm6jz1DolGpdPVX5cUn90QHHo7HgLG0P011/kZhm9M+2hVGhY3uZO35v8LTYIi4Bu5aQJTEKZpMSbskLVc2HQlm2Mglh4iJn8UwEqh2k+1QFgbRLZby7ozAQGxT/jDJ8BSYC+skgy0nlLipkU6SekAFfYufrGSyQAhHbQfqgSR39yWWr3O7qIbXGHENmWYW2o5bd92t5SnjkMeLZQcBDaYc0cAkFsrbO7cnBryL6cD2Mwq1hQObBR/BOvyRbFfiFaYiA1MvIWJv3o61m3QNnNWGSgXQRf1tEIQui8cmg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=efficios.com; dmarc=pass action=none header.from=efficios.com; dkim=pass header.d=efficios.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=efficios.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=wkxaTXkzFh15Sr/qcc28Acc3FRTgjrUc46Ac4rtSkkY=; b=QxMrh9++e3ItN1BD4LzhU4yY0E0MC9zqsIQFg+o6RN+QzjWPxK8o3MvOHe4G7iPvhggs5BE26Za1DZmzRYhCtvQs/nL34rjJo/M6HFJFtBDN4lssU5TgBd1o50dT2xezQT+lwg3eHVMDmpz81wf74riudhHFtF3+DPfBP97DkXEOqhyYWX8FgXRSCEwTOSyTMJWvkwsQzYhkSMVsD2FkOhM79xmtqqPHER5Wts4k2ncFf4K9AV+BDywQspceHgkLUw4PqxmFNiVC2a48GcLu1fLxufiaH4GvHtGJckOWRgU3KHcDIy4f5XNpWIi+a0J6lvXQvyMY/XiWJMdA67Cm2g== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=efficios.com; Received: from YT2PR01MB9175.CANPRD01.PROD.OUTLOOK.COM (2603:10b6:b01:be::5) by YT4PR01MB10773.CANPRD01.PROD.OUTLOOK.COM (2603:10b6:b01:105::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9700.25; Mon, 16 Mar 2026 19:36:41 +0000 Received: from YT2PR01MB9175.CANPRD01.PROD.OUTLOOK.COM ([fe80::6004:a862:d45d:90c1]) by YT2PR01MB9175.CANPRD01.PROD.OUTLOOK.COM ([fe80::6004:a862:d45d:90c1%3]) with mapi id 15.20.9700.024; Mon, 16 Mar 2026 19:36:38 +0000 Message-ID: Date: Mon, 16 Mar 2026 15:36:36 -0400 User-Agent: Mozilla Thunderbird Subject: Re: [RFC PATCH] futex: Introduce __vdso_robust_futex_unlock To: Thomas Gleixner , =?UTF-8?Q?Andr=C3=A9_Almeida?= Cc: linux-kernel@vger.kernel.org, Carlos O'Donell , Sebastian Andrzej Siewior , Peter Zijlstra , Florian Weimer , Rich Felker , Torvald Riegel , Darren Hart , Ingo Molnar , Davidlohr Bueso , Arnd Bergmann , "Liam R . Howlett" References: <20260311185409.1988269-1-mathieu.desnoyers@efficios.com> <87eclopu0j.ffs@tglx> <874imfpukd.ffs@tglx> From: Mathieu Desnoyers Content-Language: en-US In-Reply-To: <874imfpukd.ffs@tglx> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-ClientProxiedBy: YT4PR01CA0398.CANPRD01.PROD.OUTLOOK.COM (2603:10b6:b01:108::19) To YT2PR01MB9175.CANPRD01.PROD.OUTLOOK.COM (2603:10b6:b01:be::5) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: YT2PR01MB9175:EE_|YT4PR01MB10773:EE_ X-MS-Office365-Filtering-Correlation-Id: 624be789-c00b-4c79-66a8-08de83935793 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|7416014|376014|366016|1800799024|22082099003|18002099003|56012099003; X-Microsoft-Antispam-Message-Info: 4f87dX/9fYI7+gUevW/vEbvAjs9UxqmxnzZLbRyBZoIoEAK0bJ5omCcLLO+FoIPEvpUrKgmWTwBn7O0nczhqwQmU6Pw6oC6lnQhWROMeMk/1N2bHan4qWm5Eu8MFYPpXXazDfRj4RG0hA0I3k9rtCtK4QnVtzZTnv2mpDlcVQcM4EFn/lkNphk8VCgShneeNXcJhajrvkIlmGV4de+ePaorJsPivLGmYWcVbXMmZ5XEJl+Rj12XV+wKCwcTZYZqJ1trM2qCj2yF7iDXbRJtEV6QgFJf8yI732tYno0Z/ueisfC4EDB8brxV/XhUI4gf4Z00PQb2B1uyyQNRfonF1SMtzOos3PEZMtwgojlgvrb8nwHz174QU7EprtXhLD9MsincPO+aBPmaXoOVzyf0s0mieckCc0T88n41FzVozp2xQqEpVUIjCvBeODk0L+z815CmmH95a9z2+XN5UZ5JQ0imd0HzuDHrigjBp77a2ggNMusyEw2KVnHNrHDwuv6Qep+CLDWr5kwgfMo/YMZa20eMQqTfvpVBxVoUHVYRJIrI2maInlSpCjAreMStOmdTTcl5eVYqL6WlN+vooI1kJJGHDSXmoAVzMTqRen3RJ7SWjwOFMcDr+mcWdGs/ASZbRVIJPXY1HAbrTTpiYvcdg44HejJosNqKZU26+pjT8mgYn9PCFQI0UKFZFutHXjE/E X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:YT2PR01MB9175.CANPRD01.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(7416014)(376014)(366016)(1800799024)(22082099003)(18002099003)(56012099003);DIR:OUT;SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?utf-8?B?eVVnV2dQeHhWZXkxNlE1bGFYRnRIR2ZOeUtjUUNHOFF6VlFCcGYvU0pzd0tD?= =?utf-8?B?eEFKQ3ZTNjhLR3Z0MDdZSUREaEE0eW5EUm1MNVhIbnY4bXZMaTFYMlhHRzI5?= =?utf-8?B?bnhPN1RIbmNEUnJLelFwUmk3WExBN0pXNTc2MEo2bHhSc2t4eEZCdnFWd0dY?= =?utf-8?B?N0l5b1ZiN2ZmRTJCS3hOR282NnBsa1R1ZFRPellaY1V3V01XVnNCSjVvbC9G?= =?utf-8?B?ZXVMWGFUTDJrL1BMK0FlZlJ5S1Q1WVBLNVBlL0ZTczV1SWQ1NFJOVGo3Wm56?= =?utf-8?B?ZHhxbzU0S0I0SFhNM0QrUVhsVHFORFJocjBOUjFQUGQrNGRqUXJtWUY0REMw?= =?utf-8?B?S2l0WlJIeTJMVERGbHRkVWp5S0hMS01XcGQrNXNqd3Fpbm9qMmZ0blZqNnBk?= =?utf-8?B?Y3hUcnRaaGh2TExEc2pTSXpaNzR2TUNKQ3NCU3RpZERoVWNVbk00WVcrbDNo?= =?utf-8?B?YzVMS2xNclJodTBmVVNaTDhwOEI2NEJtcnFURlZjbGJnSmpDdTZURndEZ0Fp?= =?utf-8?B?RVVseHNneVpPUU8wY2RMTlVSNzA4UXM5OEZMUGUvN2tJSXlwTytNa216MGdu?= =?utf-8?B?NVNSMnY0eWsxWkVIME9MdVZTYjFMOUt1ejNSWXJIWkRIaWJ0Y2x2aVF4UnpZ?= =?utf-8?B?dURyYTNoNWM5bnhmQm5jLy82WXQ1TWtaUXEraWF2d2xzZHlYZ0JOejNLdGdx?= =?utf-8?B?VXZoQ0lWVkxIUGMzUkpmNG9rNVYzRTViM1VjNnB4clFNV3RVdDZHeStPb25X?= =?utf-8?B?NEgzMm9nanFNWGxmVStyNm9rNEdwWFRFUHBGbUxqcWJpbHQrQjhObU5GNHlE?= =?utf-8?B?c0szemdNOWQxYnI5VEMvWmR0eVJXTGd0UGMwWWRXMEpCbmdqM2wvREtuZUta?= =?utf-8?B?MHQ5WmwwV05qSG5oN3BYU3hPSGdRTVBzaVFIR2REZ05rUGdMaUx2Z3ExSjhN?= =?utf-8?B?MGNlQk96Yk5rOXVrdCtBQ3FTbk1FUjNrVWl2TGZobi8zMWVYMGJleHVkMTdw?= =?utf-8?B?ODVodFB6ZzdISXJjaCtOQXpPMXNsaUgzSFVxU055VzFucERYWVB2MTVWSGZC?= =?utf-8?B?cW80QlNuVmQ3Nk5vUCtWK1ZML3o0cjB5Q2lGMWpHR1ZrQXRmTkZiOENTK2FS?= =?utf-8?B?WEhjSHFoS1I3dUlyUExKWXBnalg5ZkppTk0yaTRnaWY5MU44UDhMWmI0UGhP?= =?utf-8?B?aHdiQ3Q4N0Y1Z3Zwd2xpSnVxTzM0MDM2U3VTNDVib0djZDFJbzZTeEE0TzlL?= =?utf-8?B?ZVdIV1NQbjhUWmRoYVZRb2FKTnJDY0RRMDNWTTFHeU5jRHYwMU55Rm1oekxO?= =?utf-8?B?RCtPVDlIREp5eTJNMGFZa3dPNEg2U1NOYysvc1gxQm9mVmtHVTR4b01Ya2Vq?= =?utf-8?B?aElQdldXTlJOSVNON1BSMXRxcGxaOWxZVDh2TXhMMDNwTVU5SzdMVU5WaGtk?= =?utf-8?B?L3Y0QS9sbnUweFdPVGhjSktJQWp1M0xRUXpNcEc4ZHh2L2doTzJFQUV6MURU?= =?utf-8?B?L2MrcTZUL3VGMzZJL0NsT0F1QXo0WjFtTU1rVVFJclpQcGY4aVVCRU9ETzhG?= =?utf-8?B?Qko1OU5XKzhFZ1Qyc2ZTeW43ZGdKWkJpd3NYUXZpd3ZQK1ZTSVRvVzRRZlRL?= =?utf-8?B?RGwwQVppbDFpdllRM2FudTF2VE1xRXRURGRJRkVBQklaWmlLZC9TYXB2d2Ju?= =?utf-8?B?WklQaWNRUmlBMFlTSm9ibXBoVk9idDZzbjhWL2t5Y1Y2VVA1S0lYSG80M1B6?= =?utf-8?B?VjAra3V4Z0J6NkoxY1B4Z0EwcGxjamdGMXpaTkE2dlNaZ2orUUN3cEdUZE5j?= =?utf-8?B?K2hZTEdBTzlWY3pFbGltMUxFMFl4U1hsdHI0RUlqQUw3ZDFSTmNNTEhnSDh0?= =?utf-8?B?LzUwUDhnVHRib0J1TlBHQUFqdjR4SFhPUDZ0NWtDK08vMThIYVJyRTN0eGVk?= =?utf-8?B?OW9XUi9HL0ZtcXFJSkVIRWpWUnhyMFFKVkFFYUhqU2ZDUlpVTzZ5VjFnSHJl?= =?utf-8?B?elZOeEIxSU01dXg3WWNaTTlXdDFaTEdDK29Ld1VnSjcveUp0WldNLy9FR2l2?= =?utf-8?B?V3VQVk5uUDF6OU8zUEcvS0V2U3JoelF2cVBic25lRnFyZnNvYk9BODNhdTBs?= =?utf-8?B?YnNXQjdCdC83ZThpODdjM1d6WGxkUEM2RUNoU05BcllTbXozTzZZdWVTT0xl?= =?utf-8?B?eTQ2Y0trZ3FnckwzYUpZKzRuQVRzQVNDVHNYZU5yUmtGRlRCUGREQlZsN3k0?= =?utf-8?B?WDMzM3dSV28ycXVRTzRRSENSUVhmdnFyZFlSa1M2NXBWSG1oTnJLekRDT2p1?= =?utf-8?B?MCsrOEh1M2dPOEFBRE5MMy8rYkRwWisyZWtiaHFMTmlsNCtmVVQ4SW1UUHpm?= =?utf-8?Q?ewV94BfRrxEebY6KdDesu/5ZIsmq+dfSWHYHu?= X-OriginatorOrg: efficios.com X-MS-Exchange-CrossTenant-Network-Message-Id: 624be789-c00b-4c79-66a8-08de83935793 X-MS-Exchange-CrossTenant-AuthSource: YT2PR01MB9175.CANPRD01.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 16 Mar 2026 19:36:38.6862 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 4f278736-4ab6-415c-957e-1f55336bd31e X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: gt+NktBMn9bEYrK184AIbIKRvwY4DFLE3GPHlW6LZs1+6uvjfikr9lsFKFQ/WNBPBkNKAN+pHnLyePmnJYfF1z7Ar4EBITpJPMr/o75eZNQ= X-MS-Exchange-Transport-CrossTenantHeadersStamped: YT4PR01MB10773 On 2026-03-16 13:12, Thomas Gleixner wrote: > On Thu, Mar 12 2026 at 18:52, Mathieu Desnoyers wrote: [...] > To fix this for correctness sake it needs more than a hack in the kernel > without even looking at the overall larger picture. If my POC helped move the discussion forward, then it has achieved its purpose. :) > I sat down and did a > full analysis and here are the most important questions: > > Q: Have non-PI and PI to be treated differently? > > A: No. > > That's just historical evolution. While PI can't use XCHG because that > would create inconsistent state, there is absolutely no reason why > non-PI can't use try_cmpxchg(). Agreed. > > > Q: Is it required to unlock in user space first and then go into the kernel > to wake up waiters? > > A: No. > > That's again a historical leftover from the 1st generation futexes which > preceeded both robust and PI. There is no technical reason to keep it > this way. > > So both can do: > > if (cmpxchg(lock, tid, 0) != tid) > sys_futex(UNLOCK,....); > > which then allows for both non-PI and PI to hand the pending op pointer > into the syscall and let the kernel deal with the unlock, the op pointer > and the wake up in one go. Yes, that's a nice simplification. > > That reduces the problem space to take care of the non-contended unlock > case, where the pending op is cleared after the cmpxchg() succeeded. > > And yes, that part can be done in the VDSO and a fixup mechanism in the > kernel. Yes. > > > Q: Are robust list pointers guaranteed to be 64-bit when running as a > 64-bit task? > > A: No. > > The gaming emulators use both the native 64-bit robust list and the > 32-bit robust list from the same 64-bit application to make the > emulation work. > > So both the UNLOCK syscall and the fixup need to have means to figure > out the to be cleared size for that pointer. > > Sure, this can be done with a boat load of different functions and flags > and whatever, but that makes the actual fixup handling in the kernel > more complicated than necessary. Good point, this is a requirement I did not know about. I notice you are dealing with it in your series. > > > Q: Have regular signal delivery and process exit in case of crash or being > killed by a external signal to be treated differently? > > A: No. > > A task always goes through the same signal code path for both cases so > all of this can be handled in _one_ place without even touching the > robust list cleanup code. So far, yes. > > sys_exit() is different because there a task voluntarily exits and if > it does so between the unlock and the clearing of the op pointer, > then so be it. That'd be wilfull ignorance or malice and not any > different from the task doing the corruption itself in user space > right away. I'm not sure about this one. How about the two following scenario: A concurrent thread calls sys_exit concurrently with the vdso. Is this something we should handle or consider it "wilfull ignorance/malice" ? > Q: Are exception tables a good idea? > > A: No. > > This is not an exception handling case. It's a fixup similar to RSEQ > critical section fixups and so it has to be handled with dedicated > mechanisms which are performant and not glued onto something which has a > completely different purpose. I agree with your kernel-level approach. I've proposed a few changes to the vdso itself and vdso2c script to increase robustness in my review. Thanks, Mathieu -- Mathieu Desnoyers EfficiOS Inc. https://www.efficios.com