From: Chris Metcalf <hidden> Date: 2016-03-02 20:10:47
Currently ret_fast_syscall, work_pending, and ret_to_user form an ad-hoc
state machine that can be difficult to reason about due to duplicated
code and a large number of branch targets.
This patch factors the common logic out into the existing
do_notify_resume function, converting the code to C in the process,
making the code more legible.
This patch tries to closely mirror the existing behaviour while using
the usual C control flow primitives. As local_irq_{disable,enable} may
be instrumented, we balance exception entry (where we will almost most
likely enable IRQs) with a call to trace_hardirqs_on just before the
return to userspace.
Signed-off-by: Chris Metcalf <redacted>
---
arch/arm64/kernel/entry.S | 12 ++++--------
arch/arm64/kernel/signal.c | 30 ++++++++++++++++++++++--------
2 files changed, 26 insertions(+), 16 deletions(-)
From: Will Deacon <hidden> Date: 2016-03-04 16:38:17
Hi Chris,
On Wed, Mar 02, 2016 at 03:09:35PM -0500, Chris Metcalf wrote:
Currently ret_fast_syscall, work_pending, and ret_to_user form an ad-hoc
state machine that can be difficult to reason about due to duplicated
code and a large number of branch targets.
This patch factors the common logic out into the existing
do_notify_resume function, converting the code to C in the process,
making the code more legible.
This patch tries to closely mirror the existing behaviour while using
the usual C control flow primitives. As local_irq_{disable,enable} may
be instrumented, we balance exception entry (where we will almost most
likely enable IRQs) with a call to trace_hardirqs_on just before the
return to userspace.
This doesn't look right to me. We only get here after running
do_notify_resume, which returns with interrupts disabled.
Do we not instead need to inform the tracing code that interrupts are
disabled prior to calling do_notify_resume?
From: Chris Metcalf <hidden> Date: 2016-03-04 20:03:12
On 03/04/2016 11:38 AM, Will Deacon wrote:
Hi Chris,
On Wed, Mar 02, 2016 at 03:09:35PM -0500, Chris Metcalf wrote:
quoted
Currently ret_fast_syscall, work_pending, and ret_to_user form an ad-hoc
state machine that can be difficult to reason about due to duplicated
code and a large number of branch targets.
This patch factors the common logic out into the existing
do_notify_resume function, converting the code to C in the process,
making the code more legible.
This patch tries to closely mirror the existing behaviour while using
the usual C control flow primitives. As local_irq_{disable,enable} may
be instrumented, we balance exception entry (where we will almost most
likely enable IRQs) with a call to trace_hardirqs_on just before the
return to userspace.
This doesn't look right to me. We only get here after running
do_notify_resume, which returns with interrupts disabled.
Do we not instead need to inform the tracing code that interrupts are
disabled prior to calling do_notify_resume?
I think you are right about the trace_hardirqs_off prior to
calling into do_notify_resume, given Catalin's recent commit to
add it. I dropped it since I was moving schedule() into C code,
but I suspect we'll see the same problem that Catalin saw with
CONFIG_TRACE_IRQFLAGS without it. I'll copy the arch/arm approach
and add a trace_hardirqs_off() at the top of do_notify_resume().
The trace_hardirqs_on I was copying from Mark Rutland's earlier patch:
http://permalink.gmane.org/gmane.linux.ports.arm.kernel/467781
I don't know if it's necessary to flag that interrupts are enabled
prior to returning to userspace; it may well not be. Mark, can you
comment on what led you to add that trace_hardirqs_on?
For now I've left both of them in there.
This might be easier to read as a do { ... } while.
Yes, and in fact that's how I did it for arch/tile, as the maintainer.
I picked up the arch/x86 version as more canonical to copy. But I'm
more than happy to do it the other way :-). Fixed.
--
Chris Metcalf, EZChip Semiconductor
http://www.ezchip.com
From: Mark Rutland <mark.rutland@arm.com> Date: 2016-03-14 10:29:48
Hi,
On Fri, Mar 04, 2016 at 03:02:47PM -0500, Chris Metcalf wrote:
On 03/04/2016 11:38 AM, Will Deacon wrote:
quoted
Hi Chris,
On Wed, Mar 02, 2016 at 03:09:35PM -0500, Chris Metcalf wrote:
quoted
Currently ret_fast_syscall, work_pending, and ret_to_user form an ad-hoc
state machine that can be difficult to reason about due to duplicated
code and a large number of branch targets.
This patch factors the common logic out into the existing
do_notify_resume function, converting the code to C in the process,
making the code more legible.
This patch tries to closely mirror the existing behaviour while using
the usual C control flow primitives. As local_irq_{disable,enable} may
be instrumented, we balance exception entry (where we will almost most
likely enable IRQs) with a call to trace_hardirqs_on just before the
return to userspace.
This doesn't look right to me. We only get here after running
do_notify_resume, which returns with interrupts disabled.
Do we not instead need to inform the tracing code that interrupts are
disabled prior to calling do_notify_resume?
I think you are right about the trace_hardirqs_off prior to
calling into do_notify_resume, given Catalin's recent commit to
add it. I dropped it since I was moving schedule() into C code,
but I suspect we'll see the same problem that Catalin saw with
CONFIG_TRACE_IRQFLAGS without it. I'll copy the arch/arm approach
and add a trace_hardirqs_off() at the top of do_notify_resume().
The trace_hardirqs_on I was copying from Mark Rutland's earlier patch:
http://permalink.gmane.org/gmane.linux.ports.arm.kernel/467781
I don't know if it's necessary to flag that interrupts are enabled
prior to returning to userspace; it may well not be. Mark, can you
comment on what led you to add that trace_hardirqs_on?
From what I recall, we didn't properly trace enabling IRQs in all the
asm entry paths from userspace, and doing this made things appear
balanced to the tracing code (as the existing behaviour of masking IRQs
in assembly did).
It was more expedient / simpler than fixing all the entry assembly to
update the IRQ tracing state correctly, which I had expected to rework
if/when moving the rest to C.
Thanks,
Mark.