|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Xen-devel] [PATCH v8 02/27] ARM: VGIC: move irq_to_pending() calls under the VGIC VCPU lock
On 12/04/17 11:13, Julien Grall wrote: Hi Andre, On 12/04/17 01:44, Andre Przywara wrote:So far irq_to_pending() is just a convenience function to lookup in statically allocated arrays. This will change with LPIs, which are more dynamic. So move the irq_to_pending() call under the VGIC VCPU lock, so we only use this pointer while holding the lock.That's a call for an ASSERT in irq_to_pending. And you would have notice that not all irq_to_pending will then be protected by the vGIC lock (see vgic_migrate_irq for instance). Also, please explain why the vgic lock as technically irq_to_pending is lock agnostic... And LPI structure will be per domain. So how do you expect the locking to work? I thought a bit more about this and I think vgic_vcpu_inject_irq will not be protected correctly for LPI. Unlike SPIs, LPIs don't have active state in the GIC so theoretically a new interrupt can come up right after handling the first one. Although, it might have been possible that the vLPI was moved from vCPU A to vCPU B and still in the LRs (not yet handled by the guest or not yet cleaned). So there is a race between gic_update_one_lr and vgic_vcpu_inject, both will take a different lock (resp. old and new) which may lead to a list corruption. I am not sure how to protect this case as this could happen because of a "DISCARD -> MAPTI", "MOVI", "MOVALL"
-- Julien Grall _______________________________________________ Xen-devel mailing list Xen-devel@xxxxxxxxxxxxx https://lists.xen.org/xen-devel
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |