ed5979
From 0dd4be411e35f00d006d89a15d9161f5d8783c1d Mon Sep 17 00:00:00 2001
ed5979
From: Emanuele Giuseppe Esposito <eesposit@redhat.com>
ed5979
Date: Thu, 9 Mar 2023 08:24:36 -0500
ed5979
Subject: [PATCH 10/12] physmem: add missing memory barrier
ed5979
ed5979
RH-Author: Emanuele Giuseppe Esposito <eesposit@redhat.com>
ed5979
RH-MergeRequest: 158: qatomic: add smp_mb__before/after_rmw()
ed5979
RH-Bugzilla: 2175660
ed5979
RH-Acked-by: Paolo Bonzini <pbonzini@redhat.com>
ed5979
RH-Acked-by: Cornelia Huck <cohuck@redhat.com>
ed5979
RH-Acked-by: David Hildenbrand <david@redhat.com>
ed5979
RH-Acked-by: Eric Auger <eric.auger@redhat.com>
ed5979
RH-Commit: [7/9] ee4875cb8c564f0510e48b00a5d95c0e6ea6301b (eesposit/qemu-kvm)
ed5979
ed5979
Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=2175660
ed5979
ed5979
commit 33828ca11da08436e1b32f3e79dabce3061a0427
ed5979
Author: Paolo Bonzini <pbonzini@redhat.com>
ed5979
Date:   Fri Mar 3 14:36:32 2023 +0100
ed5979
ed5979
    physmem: add missing memory barrier
ed5979
ed5979
    Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
ed5979
    Reviewed-by: David Hildenbrand <david@redhat.com>
ed5979
    Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
ed5979
ed5979
Signed-off-by: Emanuele Giuseppe Esposito <eesposit@redhat.com>
ed5979
---
ed5979
 softmmu/physmem.c | 3 +++
ed5979
 1 file changed, 3 insertions(+)
ed5979
ed5979
diff --git a/softmmu/physmem.c b/softmmu/physmem.c
ed5979
index 1b606a3002..772c9896cd 100644
ed5979
--- a/softmmu/physmem.c
ed5979
+++ b/softmmu/physmem.c
ed5979
@@ -3117,6 +3117,8 @@ void cpu_register_map_client(QEMUBH *bh)
ed5979
     qemu_mutex_lock(&map_client_list_lock);
ed5979
     client->bh = bh;
ed5979
     QLIST_INSERT_HEAD(&map_client_list, client, link);
ed5979
+    /* Write map_client_list before reading in_use.  */
ed5979
+    smp_mb();
ed5979
     if (!qatomic_read(&bounce.in_use)) {
ed5979
         cpu_notify_map_clients_locked();
ed5979
     }
ed5979
@@ -3309,6 +3311,7 @@ void address_space_unmap(AddressSpace *as, void *buffer, hwaddr len,
ed5979
     qemu_vfree(bounce.buffer);
ed5979
     bounce.buffer = NULL;
ed5979
     memory_region_unref(bounce.mr);
ed5979
+    /* Clear in_use before reading map_client_list.  */
ed5979
     qatomic_mb_set(&bounce.in_use, false);
ed5979
     cpu_notify_map_clients();
ed5979
 }
ed5979
-- 
ed5979
2.39.1
ed5979