From: Dan Magenheimer <dan.magenheimer@oracle.com>
To: Andrea Righi <andrea@betterlinux.com>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: "Seth Jennings" <sjenning@linux.vnet.ibm.com>,
devel@driverdev.osuosl.org, linux-kernel@vger.kernel.org,
stable@kernel.org,
"Alex Villacís Lasso" <a_villacis@palosanto.com>,
"Konrad Wilk" <konrad.wilk@oracle.com>,
"Alex Villacís Lasso" <a_villacis@palosanto.com>
Subject: RE: [PATCH] zcache: avoid AB-BA deadlock condition
Date: Mon, 27 Feb 2012 09:23:24 -0800 (PST) [thread overview]
Message-ID: <e60d5136-c2d2-45a4-97f4-5d8e58b12000@default> (raw)
In-Reply-To: <<1329739909-3174-1-git-send-email-andrea@betterlinux.com>>
> From: Andrea Righi [mailto:andrea@betterlinux.com]
> Sent: Monday, February 20, 2012 5:12 AM
> To: Greg Kroah-Hartman
> Cc: Dan Magenheimer; Seth Jennings; devel@driverdev.osuosl.org; linux-kernel@vger.kernel.org;
> stable@kernel.org
> Subject: [PATCH] zcache: avoid AB-BA deadlock condition
>
> Commit 9256a47 fixed a deadlock condition, being sure that the buddy
> list spinlock is always taken before the page spinlock.
>
> However in zbud_free_and_delist() locking order is the opposite
> (page lock -> list lock).
>
> Possible unsafe locking scenario (reported by lockdep):
>
> CPU0 CPU1
> ---- ----
> lock(&(&zbpg->lock)->rlock);
> lock(zbud_budlists_spinlock);
> lock(&(&zbpg->lock)->rlock);
> lock(zbud_budlists_spinlock);
>
> Fix by grabbing the locks in opposite order in zbud_free_and_delist().
>
> Signed-off-by: Andrea Righi <andrea@betterlinux.com>
Acked-by: Dan Magenheimer <dan.magenheimer@oracle.com>
Thanks for catching this Andrea! (And thanks also to
Alex Vallacis-Lasso for independently reporting and testing:
http://permalink.gmane.org/gmane.linux.kernel/1257214 )
Greg, this patch could be targeted for 3.3-rc6 and 3.2-stable.
AFAIK, nobody has actually experienced a deadlock from this so
if Linus has the screws down tight for -rc6, it could wait
until the 3.4 window.
> ---
> drivers/staging/zcache/zcache-main.c | 4 ++--
> 1 files changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/staging/zcache/zcache-main.c b/drivers/staging/zcache/zcache-main.c
> index ef7c52b..dce04be 100644
> --- a/drivers/staging/zcache/zcache-main.c
> +++ b/drivers/staging/zcache/zcache-main.c
> @@ -299,10 +299,12 @@ static void zbud_free_and_delist(struct zbud_hdr *zh)
> struct zbud_page *zbpg =
> container_of(zh, struct zbud_page, buddy[budnum]);
>
> + spin_lock(&zbud_budlists_spinlock);
> spin_lock(&zbpg->lock);
> if (list_empty(&zbpg->bud_list)) {
> /* ignore zombie page... see zbud_evict_pages() */
> spin_unlock(&zbpg->lock);
> + spin_unlock(&zbud_budlists_spinlock);
> return;
> }
> size = zbud_free(zh);
> @@ -310,7 +312,6 @@ static void zbud_free_and_delist(struct zbud_hdr *zh)
> zh_other = &zbpg->buddy[(budnum == 0) ? 1 : 0];
> if (zh_other->size == 0) { /* was unbuddied: unlist and free */
> chunks = zbud_size_to_chunks(size) ;
> - spin_lock(&zbud_budlists_spinlock);
> BUG_ON(list_empty(&zbud_unbuddied[chunks].list));
> list_del_init(&zbpg->bud_list);
> zbud_unbuddied[chunks].count--;
> @@ -318,7 +319,6 @@ static void zbud_free_and_delist(struct zbud_hdr *zh)
> zbud_free_raw_page(zbpg);
> } else { /* was buddied: move remaining buddy to unbuddied list */
> chunks = zbud_size_to_chunks(zh_other->size) ;
> - spin_lock(&zbud_budlists_spinlock);
> list_del_init(&zbpg->bud_list);
> zcache_zbud_buddied_count--;
> list_add_tail(&zbpg->bud_list, &zbud_unbuddied[chunks].list);
> --
> 1.7.5.4
next parent reply other threads:[~2012-02-27 17:24 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <<1329739909-3174-1-git-send-email-andrea@betterlinux.com>
2012-02-27 17:23 ` Dan Magenheimer [this message]
2012-02-27 17:29 ` Andrea Righi
2012-02-20 12:11 Andrea Righi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e60d5136-c2d2-45a4-97f4-5d8e58b12000@default \
--to=dan.magenheimer@oracle.com \
--cc=a_villacis@palosanto.com \
--cc=andrea@betterlinux.com \
--cc=devel@driverdev.osuosl.org \
--cc=gregkh@linuxfoundation.org \
--cc=konrad.wilk@oracle.com \
--cc=linux-kernel@vger.kernel.org \
--cc=sjenning@linux.vnet.ibm.com \
--cc=stable@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®