On Fri, Sep 11, 2026 at 11:51 PM Paul E. McKenney <[email protected]> wrote:
>
> On Wed, Sep 09, 2026 at 11:02:51AM +0800, Kunwu Chan wrote:
> > On Tue, 8 Sep 2026 16:58:31 -0700 "Paul E. McKenney" <[email protected]> 
> > wrote:
> >
> > > On Mon, Sep 07, 2026 at 03:58:17PM +0800, Kunwu Chan wrote:
> > > > From: Kunwu Chan <[email protected]>
> > > >
> > > > synchronize_srcu_atomic() may end its grace period immediately when
> > > > its scan of the per-CPU lock counters finds no readers.  Correctness
> > > > requires the grace-period anchor written by srcu_gp_start() to precede
> > > > the smp_mb() ordering the lock scan.  This ordering ensures that any
> > > > reader whose lock increment is missed by the scan cannot have
> > > > incremented its lock counter before the grace-period anchor, and
> > > > therefore cannot be a pre-existing reader of this grace period.
> > > >
> > > > This litmus test models the key ordering between the grace-period
> > > > anchor and the lock counter scan, where "seq" models the
> > > > grace-period anchor in ->srcu_gp_seq and "ctr" models the per-CPU
> > > > ->srcu_ctrs[].srcu_locks counter.  P0 writes the anchor before the
> > > > smp_mb() and the lock scan.  P1 models the reader-side counter
> > > > increment, with the smp_mb() of __srcu_read_lock() following the
> > > > increment.  P2 models an observer that sees the reader's increment
> > > > before seeing the anchor.
> > > >
> > > > The outcome is forbidden by LKMM, and herd7 reports "Never".  See
> > > > SRCU-fastpath-scan-before-anchor.litmus for the reversed ordering,
> > > > which permits this outcome.
> > > >
> > > > Tested with herd7 7.58 using linux-kernel.cfg.
> > > >
> > > > Signed-off-by: Kunwu Chan <[email protected]>
> > >
> > > Litmus tests!  Very nice!!!
> > >
> > > Could you please put both of these in Documentation/litmus-tests, in a
> > > new "srcu" subdirectory?
> > >
> > > One thing for your consideration is use of the "filter" clause for the
> > > first term of your "exists" clause.  Not a big deal at all for this small
> > > of a litmus test, but the idea is that this litmus test only cares about
> > > the 0:r2=0 case:  If that condition does not hold, then P0() and P1()
> > > aren't the beginning and end of a valid SRCU read-side critical section.
> > >
> > > Use of the "filter" allows herd7 to abandon a given execution early,
> > > so it is a big deal for larger litmus tests.
> > >
> > > Again, what you have is fine (or will be when moved to the other
> > > directory), just pointing out the additional feature.
> > >
> > > If you would like to see a use case, please see:
> > >
> > > Documentation/litmus-tests/locking/RM-fixed.litmus
> >
> > Thanks, Paul.
> > I’ll move both tests to Documentation/litmus-tests/srcu/ and use a "filter"
> > clause for the first test as suggested.
> >
> > I’ll send the two litmus tests as a separate follow-up series, so this won’t
> > hold up the current atomic SRCU series.
>
> That sounds good, thank you!
>
> > I’d also like to continue maintaining the SRCU litmus tests as they evolve.
> > If you think a MAINTAINERS entry for the SRCU litmus tests would be 
> > appropriate,
> > I’d be happy to prepare that as well.
>
> Why don't we take a longer-term approach and work to get you up to speed
> for maintainership of SRCU, rather than just for a couple of litmus tests?
>

Thanks, Paul. I really appreciate the support.

I agree that taking a longer-term approach toward SRCU maintainership
makes much more sense. I’d be glad to work toward that and take on
more SRCU development, review, testing, and LKMM work as I get up to
speed.
I’ll keep building on the atomic SRCU work and look for opportunities
to contribute more broadly to SRCU.

Thanks for the guidance.

Thanks,
KunWu

>                                                         Thanx, Paul
>
> > Thanks,
> > KunWu
> >
> > >
> > >                                                     Thanx, Paul
> > >
> > > > ---
> > > >  .../SRCU-fastpath-anchor-before-scan.litmus   | 56 +++++++++++++++++++
> > > >  1 file changed, 56 insertions(+)
> > > >  create mode 100644 
> > > > tools/memory-model/litmus-tests/SRCU-fastpath-anchor-before-scan.litmus
> > > >
> > > > diff --git 
> > > > a/tools/memory-model/litmus-tests/SRCU-fastpath-anchor-before-scan.litmus
> > > >  
> > > > b/tools/memory-model/litmus-tests/SRCU-fastpath-anchor-before-scan.litmus
> > > > new file mode 100644
> > > > index 000000000000..8200a75e15ef
> > > > --- /dev/null
> > > > +++ 
> > > > b/tools/memory-model/litmus-tests/SRCU-fastpath-anchor-before-scan.litmus
> > > > @@ -0,0 +1,56 @@
> > > > +C SRCU-fastpath-anchor-before-scan
> > > > +
> > > > +(*
> > > > + * Result: Never
> > > > + *
> > > > + * The synchronize_srcu_atomic() fastpath may end its grace period
> > > > + * immediately when its scan of the per-CPU lock counters finds no
> > > > + * readers.  Correctness requires the grace-period anchor written by
> > > > + * srcu_gp_start() to precede the smp_mb() ordering the lock scan.
> > > > + * This ordering ensures that any reader whose lock increment is missed
> > > > + * by the scan cannot have incremented its lock counter before the
> > > > + * grace-period anchor, and therefore cannot be a pre-existing reader
> > > > + * of this grace period.
> > > > + *
> > > > + * This litmus test models the key ordering between the grace-period
> > > > + * anchor and the lock counter scan, where "seq" models the
> > > > + * grace-period anchor in ->srcu_gp_seq and "ctr" models the per-CPU
> > > > + * ->srcu_ctrs[].srcu_locks counter.  P0 writes the anchor before the
> > > > + * smp_mb() and the lock scan.  P1 models the reader-side counter
> > > > + * increment, with the smp_mb() of __srcu_read_lock() following the
> > > > + * increment.  P2 models an observer that sees the reader's increment
> > > > + * before seeing the anchor.
> > > > + *
> > > > + * The outcome is forbidden by LKMM, and herd7 reports "Never".  See
> > > > + * SRCU-fastpath-scan-before-anchor.litmus for the reversed ordering,
> > > > + * which permits this outcome.
> > > > + *)
> > > > +
> > > > +{}
> > > > +
> > > > +P0(int *seq, int *ctr)
> > > > +{
> > > > + int r2;
> > > > +
> > > > + WRITE_ONCE(*seq, 1);
> > > > + smp_mb();
> > > > + r2 = READ_ONCE(*ctr);
> > > > +}
> > > > +
> > > > +P1(int *ctr)
> > > > +{
> > > > + WRITE_ONCE(*ctr, 1);
> > > > + smp_mb();
> > > > +}
> > > > +
> > > > +P2(int *seq, int *ctr)
> > > > +{
> > > > + int r3;
> > > > + int r4;
> > > > +
> > > > + r3 = READ_ONCE(*ctr);
> > > > + smp_mb();
> > > > + r4 = READ_ONCE(*seq);
> > > > +}
> > > > +
> > > > +exists (0:r2 = 0 /\ 2:r3 = 1 /\ 2:r4 = 0)
> > > > --
> > > > 2.43.0
> > > >
> > >
> >
> > Sent using hkml (https://github.com/sjp38/hackermail)

Reply via email to