mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Boqun Feng <boqun@kernel.org>
To: Thomas Gleixner <tglx@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>,
	linux-kernel@vger.kernel.org, linux-tip-commits@vger.kernel.org,
	x86@kernel.org
Subject: Re: [PATCH] locking: Revert switching guards to _irq_{disable,enable}()
Date: Tue, 1 Sep 2026 08:13:58 -0700	[thread overview]
Message-ID: <apbrtgkbxo69ZLJ2@tardis.local> (raw)
In-Reply-To: <87tso9axyk.ffs@fw13>

On Tue, Sep 01, 2026 at 03:43:47PM +0200, Thomas Gleixner wrote:
> > On Mon, Aug 31, 2026 at 12:02:50PM +0200, Thomas Gleixner wrote:
> > Right, that's why I thought fully revert on commit e901c1510e24 might
> > not be needed.
> 
> It's gone already and as I told you before the reason is that the issues
> were not restricted to the ordering parts v.s. count/hardware and the
> fallout in the softirq code. The whole issue with nested unlock/lock
> inside a guard are not solved by reordering local_interrupt_disable().
> Not to talk about the lack of proper debug features for it.
> 
> > And if PREEMPT_COUNT_IRQFLAGS=y is the future (i.e. it'll be always y),
> > then we will likely have local_interrupt_{en,dis}able() (or a different
> > name) as a general API for everyone. So the API (and its semantics) is
> > not Rust-specific considering the future direction. Hence previously I
> > said that we can move them to Rust only but seems a bit unnecessary to
> > me.
> 
> No. We need a proper strategy to pull that off and not exposing the
> functionality and the name right now outside of Rust makes that way
> simpler. Changing Rust is one thing, chasing down a pile of random use
> cases which crept in _before_ the design and strategy is settled is a
> completely different story.
> 

Fair enough.

Not trying to keep interrupt_{en,dis}able() from moving, but after some
thoughts, I think I figured out a few debugs we can add for
PREEMPT_COUNT_IRQFLAGS=n case, things we want to avoid:

*	interrupt_disable(); irq_disable(); irq_enable(); interrupt_enable();

*	interrupt_disable(); irq_enable(); irq_disable(); interrupt_enable();

*	irq_save(flags); interrupt_disable(); irq_restore(flags); interrupt_enable();

on top of your current work, we can do the following when
PREEMPT_COUNT_IRQFLAGS=n. It'll help find a few random use cases that
break. (even when interrupt_disable() are Rust-only, Rust code can still
call a function which does irq_enable(); irq_disable(); while in a
interrupt_disable() critical section, so it makes sense to catch them).

Thoughts?

Regards,
Boqun

---------------------->8
diff --git a/include/linux/irqflags.h b/include/linux/irqflags.h
index dd55786768d1..a41d188dceef 100644
--- a/include/linux/irqflags.h
+++ b/include/linux/irqflags.h
@@ -241,6 +241,14 @@ static __always_inline void raw_safe_halt(void)
 
 static __always_inline void raw_local_irq_disable(void)
 {
+	/*
+	 * Assuming local_irq_{en,dis}able() always paired, then
+	 * local_irq_disable() should not be used inside an
+	 * local_interrupt_disable() critical section. Because the paired
+	 * local_irq_enable() would enable the interrupt inside a
+	 * local_interrupt_disable() critical section.
+	 */
+	debug_assert(!(preempt_count() & HARDIRQ_DISABLE_MASK));
 	arch_local_irq_disable();
 }
 
@@ -251,6 +259,12 @@ static __always_inline void raw_force_local_irq_disable(void)
 
 static __always_inline void raw_local_irq_enable(void)
 {
+	/*
+	 * local_irq_enable() should not be called inside a
+	 * local_interrupt_disable() critical section, but it would enable the
+	 * interrupt unexpectedly.
+	 */
+	debug_assert(!(preempt_count() & HARDIRQ_DISABLE_MASK));
 	arch_local_irq_enable();
 }
 
@@ -261,6 +275,12 @@ static __always_inline unsigned long __raw_local_irq_save(void)
 
 static __always_inline void __raw_local_irq_restore(unsigned long flags)
 {
+	/*
+	 * local_irq_restore() should not enable interrupt unexpectedly inside
+	 * a local_interrupt_disable() critical section
+	 */
+	debug_assert(!(preempt_count() & HARDIRQ_DISABLE_MASK) ||
+		     arch_irqs_disabled_flags(flags));
 	arch_local_irq_restore(flags);
 }

  reply	other threads:[~2026-09-01 15:14 UTC|newest]

Thread overview: 110+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-04 16:14 [PATCH v4 00/17] Refcounted interrupt disable and SpinLockIrq for Rust Boqun Feng
2026-08-04 16:14 ` [PATCH v4 01/17] preempt: Track NMI nesting to separate per-CPU counter Boqun Feng
2026-08-08 20:48   ` [tip: locking/core] " tip-bot2 for Joel Fernandes
2026-08-04 16:14 ` [PATCH v4 02/17] preempt: Introduce HARDIRQ_DISABLE_BITS Boqun Feng
2026-08-05  6:31   ` Peter Zijlstra
2026-08-05  6:59     ` Boqun Feng
2026-08-08 20:48   ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-04 16:14 ` [PATCH v4 03/17] preempt: Introduce __preempt_count_{sub,add}_return() Boqun Feng
2026-08-08 20:48   ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-04 16:14 ` [PATCH v4 04/17] openrisc: Include <linux/cpumask.h> in smp.h Boqun Feng
2026-08-08 20:48   ` [tip: locking/core] " tip-bot2 for Lyude Paul
2026-08-04 16:14 ` [PATCH v4 05/17] irq & spin_lock: Add counted interrupt disabling/enabling Boqun Feng
2026-08-04 18:20   ` Boqun Feng
2026-08-04 18:26   ` [PATCH v4.1 " Boqun Feng
2026-08-08 20:48     ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-10  8:57     ` [tip: locking/core] irq,spin_lock: " tip-bot2 for Boqun Feng
2026-08-04 20:51   ` [PATCH v4 05/17] irq & spin_lock: " Shrikanth Hegde
2026-08-04 21:08     ` Boqun Feng
2026-08-05  6:36       ` Peter Zijlstra
2026-08-05  7:07         ` Boqun Feng
2026-08-05  7:09           ` Shrikanth Hegde
2026-08-05  7:19             ` Boqun Feng
2026-08-05 13:53               ` Boqun Feng
2026-08-05 14:10                 ` Shrikanth Hegde
2026-08-05 14:20                   ` Boqun Feng
2026-08-05 14:56                     ` Shrikanth Hegde
2026-08-05 15:11                       ` Boqun Feng
2026-08-05 16:53                         ` Shrikanth Hegde
2026-08-05 17:38                           ` Boqun Feng
2026-08-05 18:07                       ` Boqun Feng
2026-08-04 16:14 ` [PATCH v4 06/17] irq: Add KUnit test for refcounted interrupt enable/disable Boqun Feng
2026-08-08 20:48   ` [tip: locking/core] " tip-bot2 for Lyude Paul
2026-08-10  8:57   ` tip-bot2 for Lyude Paul
2026-08-04 16:14 ` [PATCH v4 07/17] locking: Switch to _irq_{disable,enable}() variants in cleanup guards Boqun Feng
2026-08-08 20:48   ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-10  8:57   ` tip-bot2 for Boqun Feng
2026-08-24 10:47     ` Peter Zijlstra
2026-08-24 10:55       ` [PATCH] locking: Revert switching guards to _irq_{disable,enable}() Peter Zijlstra
2026-08-24 11:01         ` [tip: locking/urgent] " tip-bot2 for Peter Zijlstra
2026-08-25  1:33         ` [PATCH] " Boqun Feng
2026-08-25 22:59           ` Thomas Gleixner
2026-08-25 23:28             ` Boqun Feng
2026-08-25 23:48               ` Boqun Feng
2026-08-26  1:33                 ` Boqun Feng
2026-08-27  8:30               ` Thomas Gleixner
2026-08-27 13:14                 ` Boqun Feng
2026-08-27 15:43                   ` Thomas Gleixner
2026-08-27 16:52                     ` Boqun Feng
2026-08-27 18:15                       ` Thomas Gleixner
2026-08-27 19:41                         ` Boqun Feng
2026-08-27 22:52                           ` Thomas Gleixner
2026-08-28  1:56                             ` Boqun Feng
2026-08-28  6:42                             ` Peter Zijlstra
2026-08-28 23:11                             ` Thomas Gleixner
2026-08-29  0:45                               ` Boqun Feng
2026-08-29 20:44                                 ` Thomas Gleixner
2026-08-29 20:53                                   ` Boqun Feng
2026-08-29  8:05                               ` Peter Zijlstra
2026-08-29 19:52                                 ` Thomas Gleixner
2026-08-29 23:37                               ` Boqun Feng
2026-08-30 15:18                                 ` Boqun Feng
2026-08-30 19:57                                   ` Thomas Gleixner
2026-08-30 21:23                                     ` Boqun Feng
2026-08-31 10:02                                       ` Thomas Gleixner
2026-08-31 12:41                                         ` Boqun Feng
2026-09-01 13:43                                           ` Thomas Gleixner
2026-09-01 15:13                                             ` Boqun Feng [this message]
2026-09-04 13:19                                               ` Thomas Gleixner
2026-09-04 13:14                                             ` [PATCH] irq: Move local_irq_enable/disable() into Rust, Thomas Gleixner
2026-09-04 13:26                                               ` [PATCH] irq: Move local_irq_enable/disable() into Rust Thomas Gleixner
2026-09-04 15:25                                                 ` Boqun Feng
2026-09-04 21:20                                                   ` Thomas Gleixner
2026-08-30 21:42                                     ` [PATCH] locking: Revert switching guards to _irq_{disable,enable}() Boqun Feng
2026-08-31  9:56                                       ` Thomas Gleixner
2026-08-30 20:01                                 ` Thomas Gleixner
2026-08-27 20:29                 ` Thomas Gleixner
2026-08-27 21:33                   ` Boqun Feng
2026-08-28  6:55                     ` Peter Zijlstra
2026-08-28  8:22                     ` David Laight
2026-08-28 21:26                       ` Boqun Feng
2026-08-04 16:14 ` [PATCH v4 08/17] sched: Remove the unused preempt_offset parameter of __cant_sleep() Boqun Feng
2026-08-08 20:48   ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-10  8:57   ` tip-bot2 for Boqun Feng
2026-08-04 16:14 ` [PATCH v4 09/17] sched: Avoid signed comparison of preempt_count() in __cant_migrate() Boqun Feng
2026-08-08 20:48   ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-10  8:57   ` tip-bot2 for Boqun Feng
2026-08-04 16:14 ` [PATCH v4 10/17] preempt: Introduce HAS_SEPARATE_PREEMPT_RESCHED_BITS Boqun Feng
2026-08-04 20:11   ` Shrikanth Hegde
2026-08-05  6:54     ` Boqun Feng
2026-08-05  7:15       ` Shrikanth Hegde
2026-08-05  7:27         ` Boqun Feng
2026-08-06  0:58       ` Boqun Feng
2026-08-04 21:09   ` Shrikanth Hegde
2026-08-04 23:14     ` Boqun Feng
2026-08-08 20:48   ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-10  8:57   ` tip-bot2 for Boqun Feng
2026-08-04 16:14 ` [PATCH v4 11/17] arm64: sched/preempt: Enable HAS_SEPARATE_PREEMPT_RESCHED_BITS Boqun Feng
2026-08-08 20:48   ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-10  8:57   ` tip-bot2 for Boqun Feng
2026-08-04 16:14 ` [PATCH v4 12/17] s390/preempt: " Boqun Feng
2026-08-04 20:27   ` Shrikanth Hegde
2026-08-05  9:42     ` Peter Zijlstra
2026-08-05 12:37       ` Shrikanth Hegde
2026-08-08 20:48   ` [tip: locking/core] " tip-bot2 for Heiko Carstens
2026-08-10  8:57   ` tip-bot2 for Heiko Carstens
2026-08-04 16:14 ` [PATCH v4 13/17] rust: Introduce interrupt module Boqun Feng
2026-08-04 16:14 ` [PATCH v4 14/17] rust: helper: Add spin_{un,}lock_irq_{enable,disable}() helpers Boqun Feng
2026-08-04 16:14 ` [PATCH v4 15/17] rust: sync: Use super::* in spinlock.rs Boqun Feng
2026-08-04 16:14 ` [PATCH v4 16/17] rust: sync: Add SpinLockIrq Boqun Feng
2026-08-04 16:14 ` [PATCH v4 17/17] rust: sync: Introduce SpinLockIrq::lock_with() and friends Boqun Feng

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=apbrtgkbxo69ZLJ2@tardis.local \
    --to=boqun@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-tip-commits@vger.kernel.org \
    --cc=peterz@infradead.org \
    --cc=tglx@kernel.org \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®