mirror of
https://github.com/apache/nuttx.git
synced 2026-08-18 20:18:17 +00:00
|
Some checks are pending
Build Documentation / build-html (push) Waiting to run
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
Two defects in the CONFIG_TICKET_SPINLOCK paths of spinlock.h:
1. spin_trylock_notrace() passed &lock->owner as the "expected" pointer
of atomic_cmpxchg(). A failed compare-exchange writes the current
value of the target object back through that pointer, so a losing
trylock stores lock->next into lock->owner. owner then equals next,
which is the unlocked state: a lock still held by another CPU reports
itself as free, spin_is_locked() returns false and the lock can be
taken again. Every later unlock keeps incrementing owner past next,
so the ticket of a real waiter never matches and the lock stays
locked forever. Keep the expected value in a local variable.
2. spin_unlock() was wrapped in #ifdef __SP_UNLOCK_FUNCTION, a macro
that is never defined anywhere in the tree. The function body was
therefore dead code and spin_unlock() always expanded to
"do { *(l) = SP_UNLOCKED; } while (0)", which zeroes both ticket
counters instead of releasing one ticket with
atomic_fetch_add(&lock->owner, 1). That drops queued waiters, lets a
newcomer draw ticket 0 and enter the critical section, and also skips
the UP_DMB/UP_DSB/UP_SEV release barriers and the
sched_note_spinlock_unlock() note. Drop the dead #ifdef so
spin_unlock() is always the function.
Both were reproduced on qemu-armv7a:smp (cortex-a7 x4) with
CONFIG_TICKET_SPINLOCK=y, where the compare-exchange lowers to native
ldrex/strex. This confirms the root cause is the C-level aliasing of
the expected pointer, not the atomic implementation.
Refs: https://github.com/apache/nuttx/issues/19808
Signed-off-by: hujun5 <hujun5@xiaomi.com>
|
||
|---|---|---|
| .. | ||
| android | ||
| arpa | ||
| crypto | ||
| cxx | ||
| net | ||
| netinet | ||
| netpacket | ||
| nuttx | ||
| ssp | ||
| sys | ||
| .gitignore | ||
| aio.h | ||
| alloca.h | ||
| assert.h | ||
| byteswap.h | ||
| ctype.h | ||
| debug.h | ||
| dirent.h | ||
| dlfcn.h | ||
| dsp.h | ||
| dspb16.h | ||
| elf.h | ||
| elf32.h | ||
| elf64.h | ||
| endian.h | ||
| err.h | ||
| errno.h | ||
| execinfo.h | ||
| fcntl.h | ||
| fixedmath.h | ||
| fnmatch.h | ||
| ftw.h | ||
| gcov.h | ||
| getopt.h | ||
| glob.h | ||
| grp.h | ||
| hex2bin.h | ||
| iconv.h | ||
| ifaddrs.h | ||
| imx_container.h | ||
| inttypes.h | ||
| iso646.h | ||
| langinfo.h | ||
| libgen.h | ||
| libintl.h | ||
| limits.h | ||
| locale.h | ||
| lzf.h | ||
| malloc.h | ||
| mqueue.h | ||
| netdb.h | ||
| nl_types.h | ||
| nxflat.h | ||
| obstack.h | ||
| poll.h | ||
| pthread.h | ||
| pty.h | ||
| pwd.h | ||
| regex.h | ||
| resolv.h | ||
| sched.h | ||
| search.h | ||
| semaphore.h | ||
| shadow.h | ||
| signal.h | ||
| spawn.h | ||
| stdbool.h | ||
| stddef.h | ||
| stdint.h | ||
| stdio.h | ||
| stdlib.h | ||
| stdnoreturn.h | ||
| string.h | ||
| strings.h | ||
| syscall.h | ||
| syslog.h | ||
| termios.h | ||
| threads.h | ||
| time.h | ||
| ulimit.h | ||
| unistd.h | ||
| utime.h | ||
| uuid.h | ||
| wait.h | ||
| wchar.h | ||
| wctype.h | ||