nuttx/include
hujun5 b7c8430de6
Some checks are pending
Build Documentation / build-html (push) Waiting to run
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
spinlock: fix ticket lock corruption in trylock and unlock
Two defects in the CONFIG_TICKET_SPINLOCK paths of spinlock.h:

1. spin_trylock_notrace() passed &lock->owner as the "expected" pointer
   of atomic_cmpxchg().  A failed compare-exchange writes the current
   value of the target object back through that pointer, so a losing
   trylock stores lock->next into lock->owner.  owner then equals next,
   which is the unlocked state: a lock still held by another CPU reports
   itself as free, spin_is_locked() returns false and the lock can be
   taken again.  Every later unlock keeps incrementing owner past next,
   so the ticket of a real waiter never matches and the lock stays
   locked forever.  Keep the expected value in a local variable.

2. spin_unlock() was wrapped in #ifdef __SP_UNLOCK_FUNCTION, a macro
   that is never defined anywhere in the tree.  The function body was
   therefore dead code and spin_unlock() always expanded to
   "do { *(l) = SP_UNLOCKED; } while (0)", which zeroes both ticket
   counters instead of releasing one ticket with
   atomic_fetch_add(&lock->owner, 1).  That drops queued waiters, lets a
   newcomer draw ticket 0 and enter the critical section, and also skips
   the UP_DMB/UP_DSB/UP_SEV release barriers and the
   sched_note_spinlock_unlock() note.  Drop the dead #ifdef so
   spin_unlock() is always the function.

Both were reproduced on qemu-armv7a:smp (cortex-a7 x4) with
CONFIG_TICKET_SPINLOCK=y, where the compare-exchange lowers to native
ldrex/strex.  This confirms the root cause is the C-level aliasing of
the expected pointer, not the atomic implementation.

Refs: https://github.com/apache/nuttx/issues/19808

Signed-off-by: hujun5 <hujun5@xiaomi.com>
2026-08-18 10:21:51 +08:00
..
android
arpa
crypto crypto: add CRYPTO_AES_CTR_SSH variant (128-bit big-endian counter) 2026-07-16 15:42:10 +08:00
cxx include/cxx/ctime: Add localtime to std namespace. 2026-06-09 11:33:40 -03:00
net
netinet
netpacket
nuttx spinlock: fix ticket lock corruption in trylock and unlock 2026-08-18 10:21:51 +08:00
ssp
sys libc: add wait4() 2026-08-14 10:20:52 +08:00
.gitignore ci: add stdbit.h test 2026-06-29 14:44:17 +02:00
aio.h
alloca.h
assert.h
byteswap.h
ctype.h
debug.h style: fix checkpatch issues after debug.h move 2026-04-07 07:50:06 -03:00
dirent.h fs/dirent: add d_ino member to struct dirent 2026-06-26 10:45:33 -04:00
dlfcn.h
dsp.h libs/libdsp: Add Matrix operations 2026-07-11 14:55:59 -03:00
dspb16.h
elf.h
elf32.h
elf64.h
endian.h
err.h
errno.h include/errno.h: skip set_errno in interrupt context 2026-05-03 17:23:40 -03:00
execinfo.h
fcntl.h !include/fcntl.h: align open flags with Linux values 2026-06-30 13:43:44 +08:00
fixedmath.h !compiler: drop CONFIG_HAVE_LONG_LONG and require long long support 2026-05-19 16:21:28 +08:00
fnmatch.h
ftw.h
gcov.h
getopt.h
glob.h
grp.h libc/grp: add getgrouplist() 2026-06-23 23:09:22 +08:00
hex2bin.h
iconv.h
ifaddrs.h
imx_container.h
inttypes.h !sched/clock: remove CONFIG_SYSTEM_TIME64 and always use 64-bit time 2026-05-19 16:21:28 +08:00
iso646.h
langinfo.h
libgen.h
libintl.h
limits.h sched: add supplementary group IDs (setgroups/getgroups/initgroups) 2026-08-12 16:06:03 -03:00
locale.h
lzf.h lzf: prevent lzf header struct optimization 2026-02-13 11:58:50 +01:00
malloc.h
mqueue.h
netdb.h
nl_types.h
nxflat.h !arch/arm: Use r9 as the PIC base register. 2026-08-06 01:38:23 +08:00
obstack.h
poll.h
pthread.h include/pthread : initialize wait_count in PTHREAD_COND_INITIALIZER 2026-06-16 19:12:30 -03:00
pty.h
pwd.h
regex.h
resolv.h
sched.h
search.h
semaphore.h
shadow.h
signal.h
spawn.h
stdbool.h
stddef.h !compiler: drop CONFIG_HAVE_LONG_LONG and require long long support 2026-05-19 16:21:28 +08:00
stdint.h
stdio.h
stdlib.h fs/binfmt: close symlink TOCTOU and harden setuid/setgid exec hygiene 2026-08-01 15:32:03 -03:00
stdnoreturn.h
string.h include/string.h: mark memset and memcpy as used_code 2026-02-12 13:19:06 -05:00
strings.h !compiler: drop CONFIG_HAVE_LONG_LONG and require long long support 2026-05-19 16:21:28 +08:00
syscall.h
syslog.h
termios.h
threads.h
time.h
ulimit.h
unistd.h sched: add supplementary group IDs (setgroups/getgroups/initgroups) 2026-08-12 16:06:03 -03:00
utime.h
uuid.h
wait.h
wchar.h
wctype.h