RCU Archive on lore.kernel.org
 help / color / Atom feed
* re: rcu/nocb: Add bypass callback queueing, bug report
@ 2019-08-13 12:34 Colin Ian King
  2019-08-13 15:23 ` Paul E. McKenney
  0 siblings, 1 reply; 2+ messages in thread
From: Colin Ian King @ 2019-08-13 12:34 UTC (permalink / raw)
  To: Paul E. McKenney, Josh Triplett, Steven Rostedt,
	Mathieu Desnoyers, Lai Jiangshan, Joel Fernandes, rcu
  Cc: linux-kernel

Hi,

Static analysis on linux-next today found an issue in the following commit:

commit 1afc4b18724f8f7b7a21fdf66cd43cc4a932812d
Author: Paul E. McKenney <paulmck@linux.ibm.com>
Date:   Tue Jul 2 16:03:33 2019 -0700

    rcu/nocb: Add bypass callback queueing


The coverity report is as follows:

1783        // If we have advanced to a new jiffy, reset counts to allow
1784        // moving back from ->nocb_bypass to ->cblist.
1785        if (j == rdp->nocb_nobypass_last) {
1786                c = rdp->nocb_nobypass_count + 1;
1787        } else {
1788                WRITE_ONCE(rdp->nocb_nobypass_last, j);
1789                c = rdp->nocb_nobypass_count -
nocb_nobypass_lim_per_jiffy;
1790                if (c > nocb_nobypass_lim_per_jiffy)
1791                        c = nocb_nobypass_lim_per_jiffy;

CID 85141 (#1 of 1): Unsigned compared against 0
unsigned_compare: This less-than-zero comparison of an unsigned value is
never true. c < 0UL.

1792                else if (c < 0)
1793                        c = 0;

Variable c is an unsigned long so the c < 0 check is never true. I'm not
sure what the ramifications are if c is made a signed long instead, so
I'm not fixing this and reporting this issue.

Regards,

Colin

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: rcu/nocb: Add bypass callback queueing, bug report
  2019-08-13 12:34 rcu/nocb: Add bypass callback queueing, bug report Colin Ian King
@ 2019-08-13 15:23 ` Paul E. McKenney
  0 siblings, 0 replies; 2+ messages in thread
From: Paul E. McKenney @ 2019-08-13 15:23 UTC (permalink / raw)
  To: Colin Ian King
  Cc: Josh Triplett, Steven Rostedt, Mathieu Desnoyers, Lai Jiangshan,
	Joel Fernandes, rcu, linux-kernel

On Tue, Aug 13, 2019 at 01:34:02PM +0100, Colin Ian King wrote:
> Hi,
> 
> Static analysis on linux-next today found an issue in the following commit:
> 
> commit 1afc4b18724f8f7b7a21fdf66cd43cc4a932812d
> Author: Paul E. McKenney <paulmck@linux.ibm.com>
> Date:   Tue Jul 2 16:03:33 2019 -0700
> 
>     rcu/nocb: Add bypass callback queueing
> 
> 
> The coverity report is as follows:
> 
> 1783        // If we have advanced to a new jiffy, reset counts to allow
> 1784        // moving back from ->nocb_bypass to ->cblist.
> 1785        if (j == rdp->nocb_nobypass_last) {
> 1786                c = rdp->nocb_nobypass_count + 1;
> 1787        } else {
> 1788                WRITE_ONCE(rdp->nocb_nobypass_last, j);
> 1789                c = rdp->nocb_nobypass_count -
> nocb_nobypass_lim_per_jiffy;
> 1790                if (c > nocb_nobypass_lim_per_jiffy)
> 1791                        c = nocb_nobypass_lim_per_jiffy;
> 
> CID 85141 (#1 of 1): Unsigned compared against 0
> unsigned_compare: This less-than-zero comparison of an unsigned value is
> never true. c < 0UL.
> 
> 1792                else if (c < 0)
> 1793                        c = 0;
> 
> Variable c is an unsigned long so the c < 0 check is never true. I'm not
> sure what the ramifications are if c is made a signed long instead, so
> I'm not fixing this and reporting this issue.

Good catch!!!

How about the alleged fix shown below?

							Thanx, Paul

------------------------------------------------------------------------

diff --git a/kernel/rcu/tree_plugin.h b/kernel/rcu/tree_plugin.h
index 91cefa3bf943..2defc7fe74c3 100644
--- a/kernel/rcu/tree_plugin.h
+++ b/kernel/rcu/tree_plugin.h
@@ -1787,10 +1787,11 @@ static bool rcu_nocb_try_bypass(struct rcu_data *rdp, struct rcu_head *rhp,
 	} else {
 		WRITE_ONCE(rdp->nocb_nobypass_last, j);
 		c = rdp->nocb_nobypass_count - nocb_nobypass_lim_per_jiffy;
-		if (c > nocb_nobypass_lim_per_jiffy)
-			c = nocb_nobypass_lim_per_jiffy;
-		else if (c < 0)
+		if (ULONG_CMP_LT(rdp->nocb_nobypass_count,
+				 nocb_nobypass_lim_per_jiffy))
 			c = 0;
+		else if (c > nocb_nobypass_lim_per_jiffy)
+			c = nocb_nobypass_lim_per_jiffy;
 	}
 	WRITE_ONCE(rdp->nocb_nobypass_count, c);
 

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, back to index

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-08-13 12:34 rcu/nocb: Add bypass callback queueing, bug report Colin Ian King
2019-08-13 15:23 ` Paul E. McKenney

RCU Archive on lore.kernel.org

Archives are clonable:
	git clone --mirror https://lore.kernel.org/rcu/0 rcu/git/0.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 rcu rcu/ https://lore.kernel.org/rcu \
		rcu@vger.kernel.org rcu@archiver.kernel.org
	public-inbox-index rcu


Newsgroup available over NNTP:
	nntp://nntp.lore.kernel.org/org.kernel.vger.rcu


AGPL code for this site: git clone https://public-inbox.org/ public-inbox