Page MenuHomeFreeBSD

powerpc: keep FP, VMX and VSX ownership changes atomic with preemption
Needs ReviewPublic

Authored by pkubaj on Sun, Sep 27, 8:54 AM.
Tags
None
Referenced Files
F173723793: D60054.id187794.diff
Sun, Sep 27, 11:18 PM
F173723194: D60054.diff
Sun, Sep 27, 11:13 PM
F173720511: D60054.id187794.diff
Sun, Sep 27, 10:49 PM
F173719568: D60054.diff
Sun, Sep 27, 10:41 PM
F173708269: D60054.id.diff
Sun, Sep 27, 9:03 PM
F173703295: D60054.diff
Sun, Sep 27, 8:23 PM
F173651597: D60054.id187794.diff
Sun, Sep 27, 11:40 AM
Subscribers

Details

Reviewers
None
Group Reviewers
PowerPC
Summary

trap() and set_mcontext() change the FP/VMX/VSX ownership state in
several steps with preemption enabled. A context switch in between
leaves the thread computing with another thread's register contents:

  • enable_fpu()/enable_vec() set PCB_FPU/PCB_VEC before loading the registers, so a switch mid-load saves a half-loaded unit over the PCB.
  • set_mcontext() clears the frame's MSR bits and then the PCB flags; a switch in between re-enables the unit, and the thread returns to user space with it enabled but not owned, so it is neither saved nor restored until the next signal.

Both paths run after every sigreturn(2), setcontext(2) and
swapcontext(3). A POWER9 test that keeps f14-f31 live across a signal,
with other threads using the FPU on the same CPU, saw 283 corrupted
round trips out of 882000; none after this change.

Hold a critical section around both, as amd64 and arm64 do.

MFC after: 1 week

Test Plan

POWER9 pseries guest (powerpc64le, 96 vCPUs). The test loads f14-f31,
raises a signal and re-reads them after sigreturn, while helper threads
pinned to the same CPU keep other values in the FPU and are woken from
another CPU.

kernelcorrupted round trips
stock283 of 882000
trap() fix only23 of 2030000
this change0 over several million

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 77379
Build 74262: arc lint + arc unit