From: Will Deacon <will@kernel.org>
To: Peter Zijlstra <peterz@infradead.org>
Cc: pengyu <pengyu@kylinos.cn>,
mingo@redhat.com, boqun.feng@gmail.com, longman@redhat.com,
linux-kernel@vger.kernel.org, Mark Rutland <mark.rutland@arm.com>,
t.haas@tu-bs.de, parri.andrea@gmail.com, j.alglave@ucl.ac.uk,
luc.maranget@inria.fr, paulmck@kernel.org,
jonas.oberhauser@huaweicloud.com, r.maseli@tu-bs.de,
lkmm@lists.linux.dev, stern@rowland.harvard.edu
Subject: Re: [PATCH] locking/qspinlock: use xchg with _mb in slowpath for arm64
Date: Tue, 16 Sep 2025 17:00:22 +0100 [thread overview]
Message-ID: <aMmJlv8JrzyHRCxR@willie-the-truck> (raw)
In-Reply-To: <20250916141032.GJ3245006@noisy.programming.kicks-ass.net>
On Tue, Sep 16, 2025 at 04:10:32PM +0200, Peter Zijlstra wrote:
> On Tue, Sep 16, 2025 at 11:39:03AM +0800, pengyu wrote:
> > From: Yu Peng <pengyu@kylinos.cn>
> >
> > A hardlock detected on arm64: rq->lock was released, but a CPU
> > blocked at mcs_node->locked and timed out.
> >
> > We found xchg_tail and atomic_try_cmpxchg_relaxed used _relaxed
> > versions without memory barriers. Suspected insufficient coherence
> > guarantees on some arm64 microarchitectures, potentially leading to
> > the following issues occurred:
> >
> > CPU0: CPU1:
> > // Set tail to CPU0
> > old = xchg_tail(lock, tail);
> >
> > //CPU0 read tail is itself
> > if ((val & _Q_TAIL_MASK) == tail)
> > // CPU1 exchanges the tail
> > old = xchg_tail(lock, tail)
> > //assuming CPU0 not see tail change
> > atomic_try_cmpxchg_relaxed(
> > &lock->val, &val, _Q_LOCKED_VAL)
> > //released without notifying CPU1
> > goto release;
> > //hardlock detected
> > arch_mcs_spin_lock_contended(
> > &node->locked)
> >
> > Therefore, xchg_tail and atomic_try_cmpxchg using _mb to replace _relaxed.
>
> Yeah, no. We do not apply patches based on suspicion. And we most
> certainly do not sprinkle #ifdef ARM64 in generic code.
Absolutely.
> There is this thread:
>
> https://lkml.kernel.org/r/cb83e3e4-9e22-4457-bf61-5614cc4396ad@tu-bs.de
>
> Which is also concerned with xchg_tail(). Reading back, I'm not sure
> we've ever heard back from ARM on whether that extra ;si was correct or
> not, Will?
It's still under discussion with the Arm architects but it was _very_
close to concluding last time we met and I wouldn't worry about it for
the purposes of this report.
> Anyway, as Waiman already asked, please state your exact ARM64
> microarch.
>
> Barring the ;si, the above thread suggests that they can prove the code
> correct with the below change, does that resolve your problem?
>
> Other than that, I'm going to have to leave this to Will and co.
I'll take a look but it's light on details.
Will
next prev parent reply other threads:[~2025-09-16 16:00 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20250916033903.3374794-1-pengyu@kylinos.cn>
2025-09-16 14:10 ` [PATCH] locking/qspinlock: use xchg with _mb in slowpath for arm64 Peter Zijlstra
2025-09-16 16:00 ` Will Deacon [this message]
2025-09-17 10:51 ` pengyu
2025-09-17 11:37 ` Will Deacon
2025-09-19 10:22 ` pengyu
2025-09-16 16:58 ` Waiman Long
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aMmJlv8JrzyHRCxR@willie-the-truck \
--to=will@kernel.org \
--cc=boqun.feng@gmail.com \
--cc=j.alglave@ucl.ac.uk \
--cc=jonas.oberhauser@huaweicloud.com \
--cc=linux-kernel@vger.kernel.org \
--cc=lkmm@lists.linux.dev \
--cc=longman@redhat.com \
--cc=luc.maranget@inria.fr \
--cc=mark.rutland@arm.com \
--cc=mingo@redhat.com \
--cc=parri.andrea@gmail.com \
--cc=paulmck@kernel.org \
--cc=pengyu@kylinos.cn \
--cc=peterz@infradead.org \
--cc=r.maseli@tu-bs.de \
--cc=stern@rowland.harvard.edu \
--cc=t.haas@tu-bs.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).