From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:37419) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bL9jk-0000sW-T0 for qemu-devel@nongnu.org; Thu, 07 Jul 2016 09:53:06 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bL9je-0002vR-DT for qemu-devel@nongnu.org; Thu, 07 Jul 2016 09:53:03 -0400 Received: from mail-lf0-x241.google.com ([2a00:1450:4010:c07::241]:34368) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bL9je-0002vN-0d for qemu-devel@nongnu.org; Thu, 07 Jul 2016 09:52:58 -0400 Received: by mail-lf0-x241.google.com with SMTP id z185so1512297lfd.1 for ; Thu, 07 Jul 2016 06:52:57 -0700 (PDT) References: <1467735496-16256-1-git-send-email-alex.bennee@linaro.org> <1467735496-16256-2-git-send-email-alex.bennee@linaro.org> From: Sergey Fedorov Message-ID: <577E5EB6.9060509@gmail.com> Date: Thu, 7 Jul 2016 16:52:54 +0300 MIME-Version: 1.0 In-Reply-To: <1467735496-16256-2-git-send-email-alex.bennee@linaro.org> Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit Subject: Re: [Qemu-devel] [PATCH v2 1/6] tcg: Ensure safe tb_jmp_cache lookup out of 'tb_lock' List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: =?UTF-8?Q?Alex_Benn=c3=a9e?= , mttcg@listserver.greensocs.com, qemu-devel@nongnu.org, fred.konrad@greensocs.com, a.rigo@virtualopensystems.com, cota@braap.org, bobby.prani@gmail.com, rth@twiddle.net Cc: mark.burton@greensocs.com, pbonzini@redhat.com, jan.kiszka@siemens.com, peter.maydell@linaro.org, claudio.fontana@huawei.com, Sergey Fedorov , Peter Crosthwaite I was not sure if the language I used in the source code comments is 100% correct. So it would be fine if someone could check if it is easy to understand ;) Thanks, Sergey On 05/07/16 19:18, Alex Bennée wrote: > From: Sergey Fedorov > > First, ensure atomicity of CPU's 'tb_jmp_cache' access by: > * using atomic_read() to look up a TB when not holding 'tb_lock'; > * using atomic_write() to remove a TB from each CPU's local cache on > TB invalidation. > > Second, add some memory barriers to ensure we don't put the TB being > invalidated back to CPU's 'tb_jmp_cache'. If we fail to look up a TB in > CPU's local cache because it is being invalidated by some other thread > then it must not be found in the shared TB hash table. Otherwise we'd > put it back to CPU's local cache. > > Note that this patch does *not* make CPU's TLB invalidation safe if it > is done from some other thread while the CPU is in its execution loop. > > Signed-off-by: Sergey Fedorov > Signed-off-by: Sergey Fedorov > [AJB: fixed missing atomic set, tweak title] > Signed-off-by: Alex Bennée > Reviewed-by: Richard Henderson > Reviewed-by: Emilio G. Cota > > --- > v1 (AJB): > - tweak title > - fixed missing set of tb_jmp_cache > v2 > - fix spelling s/con't/can't/ > - add atomic_read while clearing tb_jmp_cache > - add r-b tags > --- > cpu-exec.c | 9 +++++++-- > translate-all.c | 9 +++++++-- > 2 files changed, 14 insertions(+), 4 deletions(-) > > diff --git a/cpu-exec.c b/cpu-exec.c > index b840e1d..10ce1cb 100644 > --- a/cpu-exec.c > +++ b/cpu-exec.c > @@ -285,6 +285,11 @@ static TranslationBlock *tb_find_slow(CPUState *cpu, > { > TranslationBlock *tb; > > + /* Ensure that we won't find a TB in the shared hash table > + * if it is being invalidated by some other thread. > + * Otherwise we'd put it back to CPU's local cache. > + * Pairs with smp_wmb() in tb_phys_invalidate(). */ > + smp_rmb(); > tb = tb_find_physical(cpu, pc, cs_base, flags); > if (tb) { > goto found; > @@ -315,7 +320,7 @@ static TranslationBlock *tb_find_slow(CPUState *cpu, > > found: > /* we add the TB in the virtual pc hash table */ > - cpu->tb_jmp_cache[tb_jmp_cache_hash_func(pc)] = tb; > + atomic_set(&cpu->tb_jmp_cache[tb_jmp_cache_hash_func(pc)], tb); > return tb; > } > > @@ -333,7 +338,7 @@ static inline TranslationBlock *tb_find_fast(CPUState *cpu, > is executed. */ > cpu_get_tb_cpu_state(env, &pc, &cs_base, &flags); > tb_lock(); > - tb = cpu->tb_jmp_cache[tb_jmp_cache_hash_func(pc)]; > + tb = atomic_read(&cpu->tb_jmp_cache[tb_jmp_cache_hash_func(pc)]); > if (unlikely(!tb || tb->pc != pc || tb->cs_base != cs_base || > tb->flags != flags)) { > tb = tb_find_slow(cpu, pc, cs_base, flags); > diff --git a/translate-all.c b/translate-all.c > index eaa95e4..96efe48 100644 > --- a/translate-all.c > +++ b/translate-all.c > @@ -1004,11 +1004,16 @@ void tb_phys_invalidate(TranslationBlock *tb, tb_page_addr_t page_addr) > invalidate_page_bitmap(p); > } > > + /* Ensure that we won't find the TB in the shared hash table > + * if we can't see it in CPU's local cache. > + * Pairs with smp_rmb() in tb_find_slow(). */ > + smp_wmb(); > + > /* remove the TB from the hash list */ > h = tb_jmp_cache_hash_func(tb->pc); > CPU_FOREACH(cpu) { > - if (cpu->tb_jmp_cache[h] == tb) { > - cpu->tb_jmp_cache[h] = NULL; > + if (atomic_read(&cpu->tb_jmp_cache[h]) == tb) { > + atomic_set(&cpu->tb_jmp_cache[h], NULL); > } > } >