From: Marcelo Tosatti <marcelo@conectiva.com.br>
To: Hugh Dickins <hugh@veritas.com>
Cc: Linus Torvalds <torvalds@transmeta.com>,
Rik van Riel <riel@conectiva.com.br>,
lkml <linux-kernel@vger.kernel.org>
Subject: Re: 2.4.10pre VM changes: Potential race condition on swap code
Date: Fri, 14 Sep 2001 15:05:36 -0300 (BRT) [thread overview]
Message-ID: <Pine.LNX.4.21.0109141456410.4708-100000@freak.distro.conectiva> (raw)
In-Reply-To: <Pine.LNX.4.21.0109141229190.1372-100000@localhost.localdomain>
On Fri, 14 Sep 2001, Hugh Dickins wrote:
> On Thu, 13 Sep 2001, Marcelo Tosatti wrote:
> > > >
> > > > CPU0 CPU1 CPU2
> > > > do_swap_page() try_to_swap_out() swapin_readahead()
> .....
> > > > BOOM.
> > > >
> > > > Now, if we get additional references at valid_swaphandles() the above race
> > > > is NOT possible: we're guaranteed that any get_swap_page() will not find
> > >
> > > Err I mean _will_ find the swap map entry used and not use it, then.
> > >
> > > > the swap map entry used. See?
>
> Yes, I see it now: had trouble with the line wrap!
>
> Sure, that's one of the scenarios we were talking about, and getting
> additional references in valid_swaphandles will stop that particular
> race.
>
> It won't stop the race with "bare" read_swap_cache_async (which can
> happen with swapoff, or with vm_swap_full deletion if multithreaded),
Could you please make a diagram of such a race ?
> and won't stop the race when valid_swaphandles->swap_duplicate comes
> all between try_to_swap_out's get_swap_page and add_to_swap_cache.
Oh I see:
CPU0 CPU1
try_to_swap_out() swapin readahead
get_swap_page()
valid_swaphandles()
swapduplicate()
add_to_swap_cache()
add_to_swap_cache()
BOOM.
Is that what you mean ?
> The first of those is significantly less likely than swapin_readahead
> instance. The second requires interrupt at the wrong moment: can
> certainly happen, but again less likely.
>
> Adding back reference bumping in valid_swaphandles would reduce the
> likelihood of malign read_swap_cache_async/try_to_swap_out races,
> but please don't imagine it's the final fix.
Right. Now I see that the diagram I just wrote (thanks for making me
understand it :)) has been there forever. Ugh.
next prev parent reply other threads:[~2001-09-14 19:30 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2001-09-11 22:40 2.4.10pre VM changes: Potential race condition on swap code Marcelo Tosatti
2001-09-11 0:14 ` Hugh Dickins
2001-09-13 1:35 ` Marcelo Tosatti
2001-09-13 7:15 ` Hugh Dickins
2001-09-13 19:34 ` Marcelo Tosatti
2001-09-13 20:31 ` Marcelo Tosatti
2001-09-13 20:36 ` Marcelo Tosatti
2001-09-13 22:04 ` Marcelo Tosatti
2001-09-13 22:29 ` Marcelo Tosatti
2001-09-14 13:14 ` Hugh Dickins
2001-09-14 11:45 ` Hugh Dickins
2001-09-14 18:05 ` Marcelo Tosatti [this message]
2001-09-14 19:44 ` Marcelo Tosatti
2001-09-14 21:55 ` Hugh Dickins
2001-09-14 21:10 ` Marcelo Tosatti
2001-09-15 0:12 ` Hugh Dickins
2001-09-15 6:29 ` Hugh Dickins
2001-09-15 11:39 ` [PATCH] Re: 2.4.10pre VM changes: Potential race Hugh Dickins
2001-09-17 18:49 ` Marcelo Tosatti
2001-09-18 4:00 ` Marcelo Tosatti
2001-09-22 9:19 ` 2.4.10pre VM changes: Potential race condition on swap code Andrea Arcangeli
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Pine.LNX.4.21.0109141456410.4708-100000@freak.distro.conectiva \
--to=marcelo@conectiva.com.br \
--cc=hugh@veritas.com \
--cc=linux-kernel@vger.kernel.org \
--cc=riel@conectiva.com.br \
--cc=torvalds@transmeta.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).