From: Boqun Feng <boqun@kernel.org>
To: Thomas Gleixner <tglx@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>,
linux-kernel@vger.kernel.org, linux-tip-commits@vger.kernel.org,
x86@kernel.org
Subject: Re: [PATCH] locking: Revert switching guards to _irq_{disable,enable}()
Date: Tue, 1 Sep 2026 08:13:58 -0700 [thread overview]
Message-ID: <apbrtgkbxo69ZLJ2@tardis.local> (raw)
In-Reply-To: <87tso9axyk.ffs@fw13>
On Tue, Sep 01, 2026 at 03:43:47PM +0200, Thomas Gleixner wrote:
> > On Mon, Aug 31, 2026 at 12:02:50PM +0200, Thomas Gleixner wrote:
> > Right, that's why I thought fully revert on commit e901c1510e24 might
> > not be needed.
>
> It's gone already and as I told you before the reason is that the issues
> were not restricted to the ordering parts v.s. count/hardware and the
> fallout in the softirq code. The whole issue with nested unlock/lock
> inside a guard are not solved by reordering local_interrupt_disable().
> Not to talk about the lack of proper debug features for it.
>
> > And if PREEMPT_COUNT_IRQFLAGS=y is the future (i.e. it'll be always y),
> > then we will likely have local_interrupt_{en,dis}able() (or a different
> > name) as a general API for everyone. So the API (and its semantics) is
> > not Rust-specific considering the future direction. Hence previously I
> > said that we can move them to Rust only but seems a bit unnecessary to
> > me.
>
> No. We need a proper strategy to pull that off and not exposing the
> functionality and the name right now outside of Rust makes that way
> simpler. Changing Rust is one thing, chasing down a pile of random use
> cases which crept in _before_ the design and strategy is settled is a
> completely different story.
>
Fair enough.
Not trying to keep interrupt_{en,dis}able() from moving, but after some
thoughts, I think I figured out a few debugs we can add for
PREEMPT_COUNT_IRQFLAGS=n case, things we want to avoid:
* interrupt_disable(); irq_disable(); irq_enable(); interrupt_enable();
* interrupt_disable(); irq_enable(); irq_disable(); interrupt_enable();
* irq_save(flags); interrupt_disable(); irq_restore(flags); interrupt_enable();
on top of your current work, we can do the following when
PREEMPT_COUNT_IRQFLAGS=n. It'll help find a few random use cases that
break. (even when interrupt_disable() are Rust-only, Rust code can still
call a function which does irq_enable(); irq_disable(); while in a
interrupt_disable() critical section, so it makes sense to catch them).
Thoughts?
Regards,
Boqun
---------------------->8
diff --git a/include/linux/irqflags.h b/include/linux/irqflags.h
index dd55786768d1..a41d188dceef 100644
--- a/include/linux/irqflags.h
+++ b/include/linux/irqflags.h
@@ -241,6 +241,14 @@ static __always_inline void raw_safe_halt(void)
static __always_inline void raw_local_irq_disable(void)
{
+ /*
+ * Assuming local_irq_{en,dis}able() always paired, then
+ * local_irq_disable() should not be used inside an
+ * local_interrupt_disable() critical section. Because the paired
+ * local_irq_enable() would enable the interrupt inside a
+ * local_interrupt_disable() critical section.
+ */
+ debug_assert(!(preempt_count() & HARDIRQ_DISABLE_MASK));
arch_local_irq_disable();
}
@@ -251,6 +259,12 @@ static __always_inline void raw_force_local_irq_disable(void)
static __always_inline void raw_local_irq_enable(void)
{
+ /*
+ * local_irq_enable() should not be called inside a
+ * local_interrupt_disable() critical section, but it would enable the
+ * interrupt unexpectedly.
+ */
+ debug_assert(!(preempt_count() & HARDIRQ_DISABLE_MASK));
arch_local_irq_enable();
}
@@ -261,6 +275,12 @@ static __always_inline unsigned long __raw_local_irq_save(void)
static __always_inline void __raw_local_irq_restore(unsigned long flags)
{
+ /*
+ * local_irq_restore() should not enable interrupt unexpectedly inside
+ * a local_interrupt_disable() critical section
+ */
+ debug_assert(!(preempt_count() & HARDIRQ_DISABLE_MASK) ||
+ arch_irqs_disabled_flags(flags));
arch_local_irq_restore(flags);
}
next prev parent reply other threads:[~2026-09-01 15:14 UTC|newest]
Thread overview: 110+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 16:14 [PATCH v4 00/17] Refcounted interrupt disable and SpinLockIrq for Rust Boqun Feng
2026-08-04 16:14 ` [PATCH v4 01/17] preempt: Track NMI nesting to separate per-CPU counter Boqun Feng
2026-08-08 20:48 ` [tip: locking/core] " tip-bot2 for Joel Fernandes
2026-08-04 16:14 ` [PATCH v4 02/17] preempt: Introduce HARDIRQ_DISABLE_BITS Boqun Feng
2026-08-05 6:31 ` Peter Zijlstra
2026-08-05 6:59 ` Boqun Feng
2026-08-08 20:48 ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-04 16:14 ` [PATCH v4 03/17] preempt: Introduce __preempt_count_{sub,add}_return() Boqun Feng
2026-08-08 20:48 ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-04 16:14 ` [PATCH v4 04/17] openrisc: Include <linux/cpumask.h> in smp.h Boqun Feng
2026-08-08 20:48 ` [tip: locking/core] " tip-bot2 for Lyude Paul
2026-08-04 16:14 ` [PATCH v4 05/17] irq & spin_lock: Add counted interrupt disabling/enabling Boqun Feng
2026-08-04 18:20 ` Boqun Feng
2026-08-04 18:26 ` [PATCH v4.1 " Boqun Feng
2026-08-08 20:48 ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-10 8:57 ` [tip: locking/core] irq,spin_lock: " tip-bot2 for Boqun Feng
2026-08-04 20:51 ` [PATCH v4 05/17] irq & spin_lock: " Shrikanth Hegde
2026-08-04 21:08 ` Boqun Feng
2026-08-05 6:36 ` Peter Zijlstra
2026-08-05 7:07 ` Boqun Feng
2026-08-05 7:09 ` Shrikanth Hegde
2026-08-05 7:19 ` Boqun Feng
2026-08-05 13:53 ` Boqun Feng
2026-08-05 14:10 ` Shrikanth Hegde
2026-08-05 14:20 ` Boqun Feng
2026-08-05 14:56 ` Shrikanth Hegde
2026-08-05 15:11 ` Boqun Feng
2026-08-05 16:53 ` Shrikanth Hegde
2026-08-05 17:38 ` Boqun Feng
2026-08-05 18:07 ` Boqun Feng
2026-08-04 16:14 ` [PATCH v4 06/17] irq: Add KUnit test for refcounted interrupt enable/disable Boqun Feng
2026-08-08 20:48 ` [tip: locking/core] " tip-bot2 for Lyude Paul
2026-08-10 8:57 ` tip-bot2 for Lyude Paul
2026-08-04 16:14 ` [PATCH v4 07/17] locking: Switch to _irq_{disable,enable}() variants in cleanup guards Boqun Feng
2026-08-08 20:48 ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-10 8:57 ` tip-bot2 for Boqun Feng
2026-08-24 10:47 ` Peter Zijlstra
2026-08-24 10:55 ` [PATCH] locking: Revert switching guards to _irq_{disable,enable}() Peter Zijlstra
2026-08-24 11:01 ` [tip: locking/urgent] " tip-bot2 for Peter Zijlstra
2026-08-25 1:33 ` [PATCH] " Boqun Feng
2026-08-25 22:59 ` Thomas Gleixner
2026-08-25 23:28 ` Boqun Feng
2026-08-25 23:48 ` Boqun Feng
2026-08-26 1:33 ` Boqun Feng
2026-08-27 8:30 ` Thomas Gleixner
2026-08-27 13:14 ` Boqun Feng
2026-08-27 15:43 ` Thomas Gleixner
2026-08-27 16:52 ` Boqun Feng
2026-08-27 18:15 ` Thomas Gleixner
2026-08-27 19:41 ` Boqun Feng
2026-08-27 22:52 ` Thomas Gleixner
2026-08-28 1:56 ` Boqun Feng
2026-08-28 6:42 ` Peter Zijlstra
2026-08-28 23:11 ` Thomas Gleixner
2026-08-29 0:45 ` Boqun Feng
2026-08-29 20:44 ` Thomas Gleixner
2026-08-29 20:53 ` Boqun Feng
2026-08-29 8:05 ` Peter Zijlstra
2026-08-29 19:52 ` Thomas Gleixner
2026-08-29 23:37 ` Boqun Feng
2026-08-30 15:18 ` Boqun Feng
2026-08-30 19:57 ` Thomas Gleixner
2026-08-30 21:23 ` Boqun Feng
2026-08-31 10:02 ` Thomas Gleixner
2026-08-31 12:41 ` Boqun Feng
2026-09-01 13:43 ` Thomas Gleixner
2026-09-01 15:13 ` Boqun Feng [this message]
2026-09-04 13:19 ` Thomas Gleixner
2026-09-04 13:14 ` [PATCH] irq: Move local_irq_enable/disable() into Rust, Thomas Gleixner
2026-09-04 13:26 ` [PATCH] irq: Move local_irq_enable/disable() into Rust Thomas Gleixner
2026-09-04 15:25 ` Boqun Feng
2026-09-04 21:20 ` Thomas Gleixner
2026-08-30 21:42 ` [PATCH] locking: Revert switching guards to _irq_{disable,enable}() Boqun Feng
2026-08-31 9:56 ` Thomas Gleixner
2026-08-30 20:01 ` Thomas Gleixner
2026-08-27 20:29 ` Thomas Gleixner
2026-08-27 21:33 ` Boqun Feng
2026-08-28 6:55 ` Peter Zijlstra
2026-08-28 8:22 ` David Laight
2026-08-28 21:26 ` Boqun Feng
2026-08-04 16:14 ` [PATCH v4 08/17] sched: Remove the unused preempt_offset parameter of __cant_sleep() Boqun Feng
2026-08-08 20:48 ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-10 8:57 ` tip-bot2 for Boqun Feng
2026-08-04 16:14 ` [PATCH v4 09/17] sched: Avoid signed comparison of preempt_count() in __cant_migrate() Boqun Feng
2026-08-08 20:48 ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-10 8:57 ` tip-bot2 for Boqun Feng
2026-08-04 16:14 ` [PATCH v4 10/17] preempt: Introduce HAS_SEPARATE_PREEMPT_RESCHED_BITS Boqun Feng
2026-08-04 20:11 ` Shrikanth Hegde
2026-08-05 6:54 ` Boqun Feng
2026-08-05 7:15 ` Shrikanth Hegde
2026-08-05 7:27 ` Boqun Feng
2026-08-06 0:58 ` Boqun Feng
2026-08-04 21:09 ` Shrikanth Hegde
2026-08-04 23:14 ` Boqun Feng
2026-08-08 20:48 ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-10 8:57 ` tip-bot2 for Boqun Feng
2026-08-04 16:14 ` [PATCH v4 11/17] arm64: sched/preempt: Enable HAS_SEPARATE_PREEMPT_RESCHED_BITS Boqun Feng
2026-08-08 20:48 ` [tip: locking/core] " tip-bot2 for Boqun Feng
2026-08-10 8:57 ` tip-bot2 for Boqun Feng
2026-08-04 16:14 ` [PATCH v4 12/17] s390/preempt: " Boqun Feng
2026-08-04 20:27 ` Shrikanth Hegde
2026-08-05 9:42 ` Peter Zijlstra
2026-08-05 12:37 ` Shrikanth Hegde
2026-08-08 20:48 ` [tip: locking/core] " tip-bot2 for Heiko Carstens
2026-08-10 8:57 ` tip-bot2 for Heiko Carstens
2026-08-04 16:14 ` [PATCH v4 13/17] rust: Introduce interrupt module Boqun Feng
2026-08-04 16:14 ` [PATCH v4 14/17] rust: helper: Add spin_{un,}lock_irq_{enable,disable}() helpers Boqun Feng
2026-08-04 16:14 ` [PATCH v4 15/17] rust: sync: Use super::* in spinlock.rs Boqun Feng
2026-08-04 16:14 ` [PATCH v4 16/17] rust: sync: Add SpinLockIrq Boqun Feng
2026-08-04 16:14 ` [PATCH v4 17/17] rust: sync: Introduce SpinLockIrq::lock_with() and friends Boqun Feng
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=apbrtgkbxo69ZLJ2@tardis.local \
--to=boqun@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-tip-commits@vger.kernel.org \
--cc=peterz@infradead.org \
--cc=tglx@kernel.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®