olga / rpms / glibc

Forked from rpms/glibc 5 years ago
Clone

Blame SOURCES/glibc-rh1672773.patch

077c9d
commit 823624bdc47f1f80109c9c52dee7939b9386d708
077c9d
Author: Stefan Liebler <stli@linux.ibm.com>
077c9d
Date:   Thu Feb 7 15:18:36 2019 +0100
077c9d
077c9d
    Add compiler barriers around modifications of the robust mutex list for pthread_mutex_trylock. [BZ #24180]
077c9d
    
077c9d
    While debugging a kernel warning, Thomas Gleixner, Sebastian Sewior and
077c9d
    Heiko Carstens found a bug in pthread_mutex_trylock due to misordered
077c9d
    instructions:
077c9d
    140:   a5 1b 00 01             oill    %r1,1
077c9d
    144:   e5 48 a0 f0 00 00       mvghi   240(%r10),0   <--- THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending, NULL);
077c9d
    14a:   e3 10 a0 e0 00 24       stg     %r1,224(%r10) <--- last THREAD_SETMEM of ENQUEUE_MUTEX_PI
077c9d
    
077c9d
    vs (with compiler barriers):
077c9d
    140:   a5 1b 00 01             oill    %r1,1
077c9d
    144:   e3 10 a0 e0 00 24       stg     %r1,224(%r10)
077c9d
    14a:   e5 48 a0 f0 00 00       mvghi   240(%r10),0
077c9d
    
077c9d
    Please have a look at the discussion:
077c9d
    "Re: WARN_ON_ONCE(!new_owner) within wake_futex_pi() triggerede"
077c9d
    (https://lore.kernel.org/lkml/20190202112006.GB3381@osiris/)
077c9d
    
077c9d
    This patch is introducing the same compiler barriers and comments
077c9d
    for pthread_mutex_trylock as introduced for pthread_mutex_lock and
077c9d
    pthread_mutex_timedlock by commit 8f9450a0b7a9e78267e8ae1ab1000ebca08e473e
077c9d
    "Add compiler barriers around modifications of the robust mutex list."
077c9d
    
077c9d
    ChangeLog:
077c9d
    
077c9d
            [BZ #24180]
077c9d
            * nptl/pthread_mutex_trylock.c (__pthread_mutex_trylock):
077c9d
077c9d
diff --git a/nptl/pthread_mutex_trylock.c b/nptl/pthread_mutex_trylock.c
077c9d
index 8fe43b8f0f..bf2869eca2 100644
077c9d
--- a/nptl/pthread_mutex_trylock.c
077c9d
+++ b/nptl/pthread_mutex_trylock.c
077c9d
@@ -94,6 +94,9 @@ __pthread_mutex_trylock (pthread_mutex_t *mutex)
077c9d
     case PTHREAD_MUTEX_ROBUST_ADAPTIVE_NP:
077c9d
       THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending,
077c9d
 		     &mutex->__data.__list.__next);
077c9d
+      /* We need to set op_pending before starting the operation.  Also
077c9d
+	 see comments at ENQUEUE_MUTEX.  */
077c9d
+      __asm ("" ::: "memory");
077c9d
 
077c9d
       oldval = mutex->__data.__lock;
077c9d
       do
077c9d
@@ -119,7 +122,12 @@ __pthread_mutex_trylock (pthread_mutex_t *mutex)
077c9d
 	      /* But it is inconsistent unless marked otherwise.  */
077c9d
 	      mutex->__data.__owner = PTHREAD_MUTEX_INCONSISTENT;
077c9d
 
077c9d
+	      /* We must not enqueue the mutex before we have acquired it.
077c9d
+		 Also see comments at ENQUEUE_MUTEX.  */
077c9d
+	      __asm ("" ::: "memory");
077c9d
 	      ENQUEUE_MUTEX (mutex);
077c9d
+	      /* We need to clear op_pending after we enqueue the mutex.  */
077c9d
+	      __asm ("" ::: "memory");
077c9d
 	      THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending, NULL);
077c9d
 
077c9d
 	      /* Note that we deliberately exist here.  If we fall
077c9d
@@ -135,6 +143,8 @@ __pthread_mutex_trylock (pthread_mutex_t *mutex)
077c9d
 	      int kind = PTHREAD_MUTEX_TYPE (mutex);
077c9d
 	      if (kind == PTHREAD_MUTEX_ROBUST_ERRORCHECK_NP)
077c9d
 		{
077c9d
+		  /* We do not need to ensure ordering wrt another memory
077c9d
+		     access.  Also see comments at ENQUEUE_MUTEX. */
077c9d
 		  THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending,
077c9d
 				 NULL);
077c9d
 		  return EDEADLK;
077c9d
@@ -142,6 +152,8 @@ __pthread_mutex_trylock (pthread_mutex_t *mutex)
077c9d
 
077c9d
 	      if (kind == PTHREAD_MUTEX_ROBUST_RECURSIVE_NP)
077c9d
 		{
077c9d
+		  /* We do not need to ensure ordering wrt another memory
077c9d
+		     access.  */
077c9d
 		  THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending,
077c9d
 				 NULL);
077c9d
 
077c9d
@@ -160,6 +172,9 @@ __pthread_mutex_trylock (pthread_mutex_t *mutex)
077c9d
 							id, 0);
077c9d
 	  if (oldval != 0 && (oldval & FUTEX_OWNER_DIED) == 0)
077c9d
 	    {
077c9d
+	      /* We haven't acquired the lock as it is already acquired by
077c9d
+		 another owner.  We do not need to ensure ordering wrt another
077c9d
+		 memory access.  */
077c9d
 	      THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending, NULL);
077c9d
 
077c9d
 	      return EBUSY;
077c9d
@@ -173,13 +188,20 @@ __pthread_mutex_trylock (pthread_mutex_t *mutex)
077c9d
 	      if (oldval == id)
077c9d
 		lll_unlock (mutex->__data.__lock,
077c9d
 			    PTHREAD_ROBUST_MUTEX_PSHARED (mutex));
077c9d
+	      /* FIXME This violates the mutex destruction requirements.  See
077c9d
+		 __pthread_mutex_unlock_full.  */
077c9d
 	      THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending, NULL);
077c9d
 	      return ENOTRECOVERABLE;
077c9d
 	    }
077c9d
 	}
077c9d
       while ((oldval & FUTEX_OWNER_DIED) != 0);
077c9d
 
077c9d
+      /* We must not enqueue the mutex before we have acquired it.
077c9d
+	 Also see comments at ENQUEUE_MUTEX.  */
077c9d
+      __asm ("" ::: "memory");
077c9d
       ENQUEUE_MUTEX (mutex);
077c9d
+      /* We need to clear op_pending after we enqueue the mutex.  */
077c9d
+      __asm ("" ::: "memory");
077c9d
       THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending, NULL);
077c9d
 
077c9d
       mutex->__data.__owner = id;
077c9d
@@ -211,10 +233,15 @@ __pthread_mutex_trylock (pthread_mutex_t *mutex)
077c9d
 	}
077c9d
 
077c9d
 	if (robust)
077c9d
-	  /* Note: robust PI futexes are signaled by setting bit 0.  */
077c9d
-	  THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending,
077c9d
-			 (void *) (((uintptr_t) &mutex->__data.__list.__next)
077c9d
-				   | 1));
077c9d
+	  {
077c9d
+	    /* Note: robust PI futexes are signaled by setting bit 0.  */
077c9d
+	    THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending,
077c9d
+			   (void *) (((uintptr_t) &mutex->__data.__list.__next)
077c9d
+				     | 1));
077c9d
+	    /* We need to set op_pending before starting the operation.  Also
077c9d
+	       see comments at ENQUEUE_MUTEX.  */
077c9d
+	    __asm ("" ::: "memory");
077c9d
+	  }
077c9d
 
077c9d
 	oldval = mutex->__data.__lock;
077c9d
 
077c9d
@@ -223,12 +250,16 @@ __pthread_mutex_trylock (pthread_mutex_t *mutex)
077c9d
 	  {
077c9d
 	    if (kind == PTHREAD_MUTEX_ERRORCHECK_NP)
077c9d
 	      {
077c9d
+		/* We do not need to ensure ordering wrt another memory
077c9d
+		   access.  */
077c9d
 		THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending, NULL);
077c9d
 		return EDEADLK;
077c9d
 	      }
077c9d
 
077c9d
 	    if (kind == PTHREAD_MUTEX_RECURSIVE_NP)
077c9d
 	      {
077c9d
+		/* We do not need to ensure ordering wrt another memory
077c9d
+		   access.  */
077c9d
 		THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending, NULL);
077c9d
 
077c9d
 		/* Just bump the counter.  */
077c9d
@@ -250,6 +281,9 @@ __pthread_mutex_trylock (pthread_mutex_t *mutex)
077c9d
 	  {
077c9d
 	    if ((oldval & FUTEX_OWNER_DIED) == 0)
077c9d
 	      {
077c9d
+		/* We haven't acquired the lock as it is already acquired by
077c9d
+		   another owner.  We do not need to ensure ordering wrt another
077c9d
+		   memory access.  */
077c9d
 		THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending, NULL);
077c9d
 
077c9d
 		return EBUSY;
077c9d
@@ -270,6 +304,9 @@ __pthread_mutex_trylock (pthread_mutex_t *mutex)
077c9d
 	    if (INTERNAL_SYSCALL_ERROR_P (e, __err)
077c9d
 		&& INTERNAL_SYSCALL_ERRNO (e, __err) == EWOULDBLOCK)
077c9d
 	      {
077c9d
+		/* The kernel has not yet finished the mutex owner death.
077c9d
+		   We do not need to ensure ordering wrt another memory
077c9d
+		   access.  */
077c9d
 		THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending, NULL);
077c9d
 
077c9d
 		return EBUSY;
077c9d
@@ -287,7 +324,12 @@ __pthread_mutex_trylock (pthread_mutex_t *mutex)
077c9d
 	    /* But it is inconsistent unless marked otherwise.  */
077c9d
 	    mutex->__data.__owner = PTHREAD_MUTEX_INCONSISTENT;
077c9d
 
077c9d
+	    /* We must not enqueue the mutex before we have acquired it.
077c9d
+	       Also see comments at ENQUEUE_MUTEX.  */
077c9d
+	    __asm ("" ::: "memory");
077c9d
 	    ENQUEUE_MUTEX (mutex);
077c9d
+	    /* We need to clear op_pending after we enqueue the mutex.  */
077c9d
+	    __asm ("" ::: "memory");
077c9d
 	    THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending, NULL);
077c9d
 
077c9d
 	    /* Note that we deliberately exit here.  If we fall
077c9d
@@ -310,13 +352,20 @@ __pthread_mutex_trylock (pthread_mutex_t *mutex)
077c9d
 						  PTHREAD_ROBUST_MUTEX_PSHARED (mutex)),
077c9d
 			      0, 0);
077c9d
 
077c9d
+	    /* To the kernel, this will be visible after the kernel has
077c9d
+	       acquired the mutex in the syscall.  */
077c9d
 	    THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending, NULL);
077c9d
 	    return ENOTRECOVERABLE;
077c9d
 	  }
077c9d
 
077c9d
 	if (robust)
077c9d
 	  {
077c9d
+	    /* We must not enqueue the mutex before we have acquired it.
077c9d
+	       Also see comments at ENQUEUE_MUTEX.  */
077c9d
+	    __asm ("" ::: "memory");
077c9d
 	    ENQUEUE_MUTEX_PI (mutex);
077c9d
+	    /* We need to clear op_pending after we enqueue the mutex.  */
077c9d
+	    __asm ("" ::: "memory");
077c9d
 	    THREAD_SETMEM (THREAD_SELF, robust_head.list_op_pending, NULL);
077c9d
 	  }
077c9d