From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yx1-f43.google.com (mail-yx1-f43.google.com [74.125.224.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4C0B5449EDD for ; Fri, 27 Feb 2026 15:55:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.224.43 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772207763; cv=none; b=En6A9UR+wOq9bhwsXbtvdssRWKeUowBWRsnTugvDfxs/W+Ni1rOGtYARSPmi9NYPpCPPYvk3rmaEsReNG7jCwXlseekNBAFmAAk2J3BcxB5o9n2+9owwCxZjKZSwOuhMOnyDbmSrRNp1WUDSQ/5gTJC4K+m/jRxhfuAs7ZAnCl0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772207763; c=relaxed/simple; bh=m4HHYEoegrmceXAFNgfEuq74TcPKLbfaBUhmSQ+0Cxg=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=GUY41y15z8KJdZQmi3Gf/ZOaz+bd4s1BIaCOqhoGOm67mtMm7uOcrFFR7UZaM0+IhxR6y9CsL7Wp7igqUALV3GEl4sY9nEjIikwTvrbsCW4K7jZtBepe/2na1nbMVohd5VA7RiBcdOBBJ9x4+4kmx0CqcxsG2HPJcYOt9KqeAvg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=PZ0tOmBQ; arc=none smtp.client-ip=74.125.224.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="PZ0tOmBQ" Received: by mail-yx1-f43.google.com with SMTP id 956f58d0204a3-64ae2ce2fe1so1805357d50.1 for ; Fri, 27 Feb 2026 07:55:58 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1772207758; x=1772812558; darn=vger.kernel.org; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:from:to :cc:subject:date:message-id:reply-to; bh=ADjfSCeCS9i/E1+pRoJw2Du6HOXpGomBi+es/5I2vPI=; b=PZ0tOmBQHMv1CcCOl3F1Vfzu4MshMiYVwI4ejuymk7sgHZyMqr6CSdykTZa+C4xKJq upO9WHjtjAVPMCMGN2J2yszI8yg+rehrJRERVTc3XwhsIfO9XE09AmGApA+mCJvtk2ZK gAcGXbI1G/ZyMV3otPdM0WVbl4I9IZUZCS1zY3yoX1uFRavZ3q5cbVV7by315tCmSsXf MxNDgP8ZnYAmwiuv4WcGatSyUnnRUnjQa0GNhXMO003ZYYuOSVLR00NOkLhBYe+nLsWT wYtBIVsc0dKLNhMT17RaeeAx3fxLZIy9gZo6fkLLy6UKtfTgGC8O5C+YUOJkfH/plt3J 8h+g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1772207758; x=1772812558; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=ADjfSCeCS9i/E1+pRoJw2Du6HOXpGomBi+es/5I2vPI=; b=McD2oGx7aXtWYI3GJT1ERjzFn2KGvi+rBYHIFQUvJ9XEwEfvVKtDKMIzIF4Nrx6Eoe 4p/nanAty5j9c2genYYRP8RXe/gCGJYGirp6dWyCR5DGTVCBN+tH7ZsT/6E1o8d4mcT5 F64+a1zxOA2gBL1kXOE3F+5UIRxQq8Ub/HMC4hR9UYM2Jf4e5Y7DoJ2A5fCKXwFaUF57 mFKqNJaSkkdgrcQcx1CE3vMUqZxhEdkxKRAv8Ix5z4+i+FyX+zpWSughgyRyNEfsswPv OAcuSBCGB8TmD3GV9v9zygHMvVROB06BNSdj6LU1Zxc+cbxKsx8uBJ44LrHTCbjzi2eZ WbWg== X-Forwarded-Encrypted: i=1; AJvYcCUgyDxna3xwFklxSp1cxOw6jfiO5twMYJaB4MZaodbKFIZWQhE8zifjUNjdjf7E+1f1z7azrNAu+ZExgYg=@vger.kernel.org X-Gm-Message-State: AOJu0YxRE15gYaRX3EUNzVAn/k/I9kZxh9UOIY/wbitPAluXr4b+b4OC MjoIhx73hKPLhcbRt0kceAt2cabB/zxo8sYQKmow2wIw6GvEb0T/ehgO X-Gm-Gg: ATEYQzwPj53OaQt4EXXqJqXoN3HynwxSrmSqBnUlDn5yi2fXDL319f8qlXdwu7vtdbL kF/u3HWvTjYzkr2uZP518BTWzI3S6mBH3+gdddn7v6WgyS1IhiWyvT8Px5wxIvkr+HuivhNl+bT DfPGM3pvZKHjWqPoPZ4q8U9fKWQSwjT2pA+9QA7AqNLhioJm9pMQCqbUpFv9nfJkpfKgjJ9jgqy K1hJta8O60mxo/kQx0pfV/TjbSsAJqsbdYgjyMShZMsQH6WBwvSp8fzNqIiZJFTa2qV6pklw5UE ltcW01UrtLwzQBWxjIgQedX9TtTV1i/UtFme7nc/8KnhWFwjG/cblUCjsloVWaszuTuNKOQJZsY Yr6vbhaUpwY3IeGWgWuXGeMzWfcUd6KBa5+8EBcdhHlZ/qQRn0NTUrgHuMczfWKXBvzdx1hQzdx FfOhDyJpqS4gDpCNOMHGw+7oLZ77ig7AYhWai/WDyWSJjFBIQ= X-Received: by 2002:a53:b1d3:0:b0:649:6581:a683 with SMTP id 956f58d0204a3-64cc202dc40mr2350443d50.12.1772207757906; Fri, 27 Feb 2026 07:55:57 -0800 (PST) Received: from devvm11784.nha0.facebook.com ([2a03:2880:25ff:70::]) by smtp.gmail.com with ESMTPSA id 956f58d0204a3-64cb75a1157sm2569498d50.6.2026.02.27.07.55.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 27 Feb 2026 07:55:57 -0800 (PST) Date: Fri, 27 Feb 2026 07:55:53 -0800 From: Bobby Eshleman To: Mina Almasry Cc: Stanislav Fomichev , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Kaiyuan Zhang , Stanislav Fomichev , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Bobby Eshleman Subject: Re: [PATCH net] net: devmem: use READ_ONCE/WRITE_ONCE on binding->dev Message-ID: References: <20260223-devmem-membar-fix-v1-1-37dcae1e49f8@meta.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: On Wed, Feb 25, 2026 at 11:49:31AM -0800, Bobby Eshleman wrote: > On Wed, Feb 25, 2026 at 09:31:48AM -0800, Mina Almasry wrote: > > On Wed, Feb 25, 2026 at 7:14 AM Bobby Eshleman wrote: > > > > > > On Tue, Feb 24, 2026 at 05:49:42PM -0800, Stanislav Fomichev wrote: > > > > On 02/23, Bobby Eshleman wrote: > > > > > From: Bobby Eshleman > > > > > > > > > > binding->dev is protected on the write-side in > > > > > mp_dmabuf_devmem_uninstall() against concurrent writes, but due to the > > > > > concurrent bare read in net_devmem_get_binding() it should be wrapped in > > > > > a READ_ONCE/WRITE_ONCE pair to make sure no compiler optimizations play > > > > > with the underlying register in unforeseen ways. > > > > > > > > > > Fixes: bd61848900bf ("net: devmem: Implement TX path") > > > > > Signed-off-by: Bobby Eshleman > > > > Looks correct to me, and AFAIU Stan is right, we might as well > > annotate all the reads of ->dev as technically there could be a dmabuf > > uninstall happing concurrently on another CPU. I also think it's > > probably good to annotate potential races. > > > > The ->dev write in dmabuf binding doesn't need WRITE_ONCE annotation I > > guess because it's initialization, it can't race with any reads. > > > > This makes me wonder what other fields in dmabuf need annotations. I > > hope I didn't miss many more. > > > > I would add this is really not a critical bug because > > net_devmem_get_binding() is in TX path, and it is more than fine here > > if we fail this check if there is an unbind happening in paraller with > > sendmsg(), but it's probably good to annotate potential races anyway. > > > > Sounds good. I'll take a look at some of the other fields while my mind > is in this space. I looked through the other fields of binding and binding->dev is the only one that wants READ_ONCE/WRITE_ONCE AFAICT. Most of them are only modified after the refcount hits zero (dmabuf, tx_vec, chunk_pool, attachment, etc..) and I think binding->list is protected by the netlink priv->lock.