@@ -5,7 +5,7 @@ # # Architecture requirements #-# * arm/arm64+# * arm/arm64/powerpc # # Rely on implicit context synchronization as a result of exception return # when returning from IPI handler, and when returning to user-space.
@@ -45,7 +45,7 @@ | nios2: | TODO | | openrisc: | TODO | | parisc: | TODO |- | powerpc: | TODO |+ | powerpc: | ok | | riscv: | TODO | | s390: | TODO | | sh: | TODO |
@@ -5,7 +5,7 @@ # # Architecture requirements #-# * arm/arm64+# * arm/arm64/powerpc # # Rely on implicit context synchronization as a result of exception return # when returning from IPI handler, and when returning to user-space.
@@ -45,7 +45,7 @@ | nios2: | TODO | | openrisc: | TODO | | parisc: | TODO |- | powerpc: | TODO |+ | powerpc: | ok | | riscv: | TODO | | s390: | TODO | | sh: | TODO |
This file is dedicated to BOOK3S/64. What about other ones ?
On 32 bits, this is also valid as 'rfi' is also context synchronising,
but then why just add some comment in exception-64s.h and only there ?
This file is dedicated to BOOK3S/64. What about other ones ?
On 32 bits, this is also valid as 'rfi' is also context synchronising,
but then why just add some comment in exception-64s.h and only there ?
Yeah you're right, I basically wanted to keep a note there just in case,
because it's possible we would get a less synchronising return (maybe
unlikely with meltdown) or even return from a kernel interrupt using a
something faster (e.g., bctar if we don't use tar register in the kernel
anywhere).
So I wonder where to add the note, entry_32.S and 64e.h as well?
I should actually change the comment for 64-bit because soft masked
interrupt replay is an interesting case. I thought it was okay (because
the IPI would cause a hard interrupt which does do the rfi) but that
should at least be written. The context synchronisation happens before
the Linux IPI function is called, but for the purpose of membarrier I
think that is okay (the membarrier just needs to have caused a memory
barrier + context synchronistaion by the time it has done).
Thanks,
Nick
This file is dedicated to BOOK3S/64. What about other ones ?
On 32 bits, this is also valid as 'rfi' is also context synchronising,
but then why just add some comment in exception-64s.h and only there ?
Yeah you're right, I basically wanted to keep a note there just in case,
because it's possible we would get a less synchronising return (maybe
unlikely with meltdown) or even return from a kernel interrupt using a
something faster (e.g., bctar if we don't use tar register in the kernel
anywhere).
So I wonder where to add the note, entry_32.S and 64e.h as well?
For 64-bit powerpc, I would be tempted to either place the comment in the header
implementing the RFI_TO_USER and RFI_TO_USER_OR_KERNEL macros or the .S files
using them, e.g. either:
arch/powerpc/include/asm/exception-64e.h
arch/powerpc/include/asm/exception-64s.h
or
arch/powerpc/kernel/exceptions-64s.S
arch/powerpc/kernel/entry_64.S
And for 32-bit powerpc, AFAIU
arch/powerpc/kernel/entry_32.S
uses SYNC + RFI to return to user-space. RFI is defined in
arch/powerpc/include/asm/ppc_asm.h
So a comment either near the RFI define and its uses should work.
I should actually change the comment for 64-bit because soft masked
interrupt replay is an interesting case. I thought it was okay (because
the IPI would cause a hard interrupt which does do the rfi) but that
should at least be written.
Yes.
The context synchronisation happens before
the Linux IPI function is called, but for the purpose of membarrier I
think that is okay (the membarrier just needs to have caused a memory
barrier + context synchronistaion by the time it has done).
Can you point me to the code implementing this logic ?
Thanks,
Mathieu
This file is dedicated to BOOK3S/64. What about other ones ?
On 32 bits, this is also valid as 'rfi' is also context synchronising,
but then why just add some comment in exception-64s.h and only there ?
Yeah you're right, I basically wanted to keep a note there just in case,
because it's possible we would get a less synchronising return (maybe
unlikely with meltdown) or even return from a kernel interrupt using a
something faster (e.g., bctar if we don't use tar register in the kernel
anywhere).
So I wonder where to add the note, entry_32.S and 64e.h as well?
For 64-bit powerpc, I would be tempted to either place the comment in the header
implementing the RFI_TO_USER and RFI_TO_USER_OR_KERNEL macros or the .S files
using them, e.g. either:
arch/powerpc/include/asm/exception-64e.h
arch/powerpc/include/asm/exception-64s.h
or
arch/powerpc/kernel/exceptions-64s.S
arch/powerpc/kernel/entry_64.S
And for 32-bit powerpc, AFAIU
arch/powerpc/kernel/entry_32.S
uses SYNC + RFI to return to user-space. RFI is defined in
arch/powerpc/include/asm/ppc_asm.h
So a comment either near the RFI define and its uses should work.
For 32-bit, RFI is likely to go away the day 40x goes away, so I
wouldn't put it there.
Places like head_8xx.S use rfi not RFI.
And the SYNC is about to go when we decide to retire 601 SYNC FIX.
So it would be probably better to put it somewhere in entry_32.S
Christophe
This file is dedicated to BOOK3S/64. What about other ones ?
On 32 bits, this is also valid as 'rfi' is also context synchronising,
but then why just add some comment in exception-64s.h and only there ?
Yeah you're right, I basically wanted to keep a note there just in case,
because it's possible we would get a less synchronising return (maybe
unlikely with meltdown) or even return from a kernel interrupt using a
something faster (e.g., bctar if we don't use tar register in the kernel
anywhere).
So I wonder where to add the note, entry_32.S and 64e.h as well?
For 64-bit powerpc, I would be tempted to either place the comment in the header
implementing the RFI_TO_USER and RFI_TO_USER_OR_KERNEL macros or the .S files
using them, e.g. either:
arch/powerpc/include/asm/exception-64e.h
arch/powerpc/include/asm/exception-64s.h
or
arch/powerpc/kernel/exceptions-64s.S
arch/powerpc/kernel/entry_64.S
And for 32-bit powerpc, AFAIU
arch/powerpc/kernel/entry_32.S
uses SYNC + RFI to return to user-space. RFI is defined in
arch/powerpc/include/asm/ppc_asm.h
So a comment either near the RFI define and its uses should work.
quoted
I should actually change the comment for 64-bit because soft masked
interrupt replay is an interesting case. I thought it was okay (because
the IPI would cause a hard interrupt which does do the rfi) but that
should at least be written.
Yes.
quoted
The context synchronisation happens before
the Linux IPI function is called, but for the purpose of membarrier I
think that is okay (the membarrier just needs to have caused a memory
barrier + context synchronistaion by the time it has done).
Can you point me to the code implementing this logic ?
It's mostly in arch/powerpc/kernel/exception-64s.S and
powerpc/kernel/irq.c, but a lot of asm so easier to explain.
When any Linux code does local_irq_disable(), we set interrupts as
software-masked in a per-cpu flag. When interrupts (including IPIs) come
in, the first thing we do is check that flag and if we are masked, then
record that the interrupt needs to be "replayed" in another per-cpu
flag. The interrupt handler then exits back using RFI (which is context
synchronising the CPU). Later, when the kernel code does
local_irq_enable(), it checks the replay flag to see if anything needs
to be done. At that point we basically just call the interrupt handler
code like a normal function, and when that returns there is no context
synchronising instruction.
So membarrier IPI will always cause target CPUs to perform a context
synchronising instruction, but sometimes it happens before the IPI
handler function runs.
Thanks,
Nick
----- On Jul 8, 2020, at 1:17 AM, Nicholas Piggin npiggin@gmail.com wrote:
Excerpts from Mathieu Desnoyers's message of July 7, 2020 9:25 pm:
quoted
----- On Jul 7, 2020, at 1:50 AM, Nicholas Piggin npiggin@gmail.com wrote:
[...]
quoted
quoted
I should actually change the comment for 64-bit because soft masked
interrupt replay is an interesting case. I thought it was okay (because
the IPI would cause a hard interrupt which does do the rfi) but that
should at least be written.
Yes.
quoted
The context synchronisation happens before
the Linux IPI function is called, but for the purpose of membarrier I
think that is okay (the membarrier just needs to have caused a memory
barrier + context synchronistaion by the time it has done).
Can you point me to the code implementing this logic ?
It's mostly in arch/powerpc/kernel/exception-64s.S and
powerpc/kernel/irq.c, but a lot of asm so easier to explain.
When any Linux code does local_irq_disable(), we set interrupts as
software-masked in a per-cpu flag. When interrupts (including IPIs) come
in, the first thing we do is check that flag and if we are masked, then
record that the interrupt needs to be "replayed" in another per-cpu
flag. The interrupt handler then exits back using RFI (which is context
synchronising the CPU). Later, when the kernel code does
local_irq_enable(), it checks the replay flag to see if anything needs
to be done. At that point we basically just call the interrupt handler
code like a normal function, and when that returns there is no context
synchronising instruction.
AFAIU this can only happen for interrupts nesting over irqoff sections,
therefore over kernel code, never userspace, right ?
So membarrier IPI will always cause target CPUs to perform a context
synchronising instruction, but sometimes it happens before the IPI
handler function runs.
If my understanding is correct, the replayed interrupt handler logic
only nests over kernel code, which will eventually need to issue a
context synchronizing instruction before returning to user-space.
All we care about is that starting from the membarrier, each core
either:
- interrupt user-space to issue the context synchronizing instruction if
they were running userspace, or
- _eventually_ issue a context synchronizing instruction before returning
to user-space if they were running kernel code.
So your earlier statement "the membarrier just needs to have caused a memory
barrier + context synchronistaion by the time it has done" is not strictly
correct: the context synchronizing instruction does not strictly need to
happen on each core before membarrier returns. A similar line of thoughts
can be followed for memory barriers.
Thanks,
Mathieu
--
Mathieu Desnoyers
EfficiOS Inc.
http://www.efficios.com
From: Nicholas Piggin <npiggin@gmail.com> Date: 2020-07-09 10:27:21
Excerpts from Mathieu Desnoyers's message of July 9, 2020 12:12 am:
----- On Jul 8, 2020, at 1:17 AM, Nicholas Piggin npiggin@gmail.com wrote:
quoted
Excerpts from Mathieu Desnoyers's message of July 7, 2020 9:25 pm:
quoted
----- On Jul 7, 2020, at 1:50 AM, Nicholas Piggin npiggin@gmail.com wrote:
[...]
quoted
quoted
quoted
I should actually change the comment for 64-bit because soft masked
interrupt replay is an interesting case. I thought it was okay (because
the IPI would cause a hard interrupt which does do the rfi) but that
should at least be written.
Yes.
quoted
The context synchronisation happens before
the Linux IPI function is called, but for the purpose of membarrier I
think that is okay (the membarrier just needs to have caused a memory
barrier + context synchronistaion by the time it has done).
Can you point me to the code implementing this logic ?
It's mostly in arch/powerpc/kernel/exception-64s.S and
powerpc/kernel/irq.c, but a lot of asm so easier to explain.
When any Linux code does local_irq_disable(), we set interrupts as
software-masked in a per-cpu flag. When interrupts (including IPIs) come
in, the first thing we do is check that flag and if we are masked, then
record that the interrupt needs to be "replayed" in another per-cpu
flag. The interrupt handler then exits back using RFI (which is context
synchronising the CPU). Later, when the kernel code does
local_irq_enable(), it checks the replay flag to see if anything needs
to be done. At that point we basically just call the interrupt handler
code like a normal function, and when that returns there is no context
synchronising instruction.
AFAIU this can only happen for interrupts nesting over irqoff sections,
therefore over kernel code, never userspace, right ?
Right.
quoted
So membarrier IPI will always cause target CPUs to perform a context
synchronising instruction, but sometimes it happens before the IPI
handler function runs.
If my understanding is correct, the replayed interrupt handler logic
only nests over kernel code, which will eventually need to issue a
context synchronizing instruction before returning to user-space.
Yes.
All we care about is that starting from the membarrier, each core
either:
- interrupt user-space to issue the context synchronizing instruction if
they were running userspace, or
- _eventually_ issue a context synchronizing instruction before returning
to user-space if they were running kernel code.
So your earlier statement "the membarrier just needs to have caused a memory
barrier + context synchronistaion by the time it has done" is not strictly
correct: the context synchronizing instruction does not strictly need to
happen on each core before membarrier returns. A similar line of thoughts
can be followed for memory barriers.
Ah okay that makes it simpler, then no such speical comment is required
for the powerpc specific interrupt handling.
Thanks,
Nick