From nobody Sat Jul 25 16:53:11 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=kernel.org ARC-Seal: i=1; a=rsa-sha256; t=1784148532; cv=none; d=zohomail.com; s=zohoarc; b=Xj4c5T+y06H9Ma5cHgsu0x/pDvgXIrM8k/7u+I2NxNkXn7XhUTTm/gwHqF0uMGZr7//qi7CTFIkApdmr+fc3q96AGF4MTzd8FdcmWsrbaZZ0bLp+qWO7lOSXWX+ibjaDV4DVU1Rdi/qA1RiHUPYSqls1a0jKe7KcL4OOGh1upGY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784148532; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:Reply-To:Sender:Subject:Subject:To:To:Message-Id; bh=ZfXnIz5LW8U2ZHPNDEMZdyv8TkFp3UpRFP6ECWtUFSE=; b=KBM02GEeDOPoz5Kop0g63sukQDs1G4tEHlIlXA8EGoxOD+OJnRvjXDFp8PLoRpW7AH2QJ8tVEeT7AP4PV3+650duCuZT0ztNjbQHwVP9Zsnv5rgMak2ZFwvLll92sLsKDbwEfE3r1GsT1IA2Vk9lB4eu1/ELN3x7uW1PAfoqy9I= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784148532366627.5339372233; Wed, 15 Jul 2026 13:48:52 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wk6X1-0005P8-If; Wed, 15 Jul 2026 16:48:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wk6Wz-0005OS-Ro for qemu-devel@nongnu.org; Wed, 15 Jul 2026 16:48:37 -0400 Received: from sea.source.kernel.org ([2600:3c0a:e001:78e:0:1991:8:25]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wk6Ww-0006RY-RM for qemu-devel@nongnu.org; Wed, 15 Jul 2026 16:48:37 -0400 Received: from smtp.kernel.org (transwarp.subspace.kernel.org [100.75.92.58]) by sea.source.kernel.org (Postfix) with ESMTP id 20A2240A4A; Wed, 15 Jul 2026 20:48:25 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPS id 021A2C19425; Wed, 15 Jul 2026 20:48:24 +0000 (UTC) Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D2B35C44501; Wed, 15 Jul 2026 20:48:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1784148505; bh=HmWJ5bg/EFj3jiUQvQ9KXN51k9IZlCSeyVFRrklvRh0=; h=From:Date:Subject:To:Cc:Reply-To:From; b=j9+HmgVB4VEsbcv60Rjb4/oRfIlOI1NQjtNkiYk4+eARJoNhAVnT3EkNNYYgB3y6D BdwdXaLvnsm5gern0UQ6tw0KuPoh8g5szSkPa0PARsoqaUPA0RpjrqaSyKe1Ue1vOq 6cV9S+aJNq5ce5FeAbj08u3+katXCBGeZHTyLyrDkV1yRdbkBDFxVBCQNL8LdKm6mW kHhbT1zj4OAq+JGNgHP6bDssVtP2b2ALer8JTDH9irewBALo8749rfIy6uYBkFjBG6 eNNqTx71xQsXh1i5EryiEXmoyD2m67wYXknplZ0wW1YFD0ohhEVT0aLf1IYVfP3EKf fjITzn1QFG50g== From: Miao Wang via B4 Relay Date: Thu, 16 Jul 2026 04:48:05 +0800 Subject: [PATCH v2] target/loongarch: fix data race in CSR_ESTAT MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260716-loong-race-v2-1-01e68e4b850f@gmail.com> X-B4-Tracking: v=1; b=H4sIAATyV2oC/03MQQ6CMBCF4auQWVvDlBbElfcwLGqdwiRATWsaD endrcSFy/8l79sgUmCKcK42CJQ4sl9LyEMFdjLrSILvpUHWsq27uhOz9+sogrEk2qZtejo5bdw NyuERyPFrx65D6Ynj04f3bif8rj8G1T+TUKDQChG16m2v6TIuhuej9QsMOecPjYuMfaQAAAA= X-Change-ID: 20260707-loong-race-63639e8f5afb To: qemu-devel@nongnu.org Cc: Song Gao <17746591750@163.com>, Bibo Mao , Xianglai Li , Jiaxun Yang , Xi Ruoyao , b4-sent@kernel.org, Miao Wang X-Mailer: b4 0.14.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=4086; i=shankerwangmiao@gmail.com; s=20250715; h=from:subject:message-id; bh=edg9pf2Pmubk/4PhluZxd33NpdiSu3MmmgovyJZQJuU=; b=owEBbQKS/ZANAwAKAbAx48p7/tluAcsmYgBqV/IJbR8n0CrMNRPbuKl/2rBv/0MyeZ3ok5dCH p/vWxytlPiJAjMEAAEKAB0WIQREqPWPgPJBxluezBOwMePKe/7ZbgUCalfyCQAKCRCwMePKe/7Z bu6gEADK+gjwYNjxuXGQ5z9OOZTfQpCBhKqx7AMHTZ0RzlW5ZYw0Zrr3gxiwE4h3ge6AD6fao9Q gzng8IrvTdiYZQhnue6T8qhps1PLrYY+FX6tvlE68aeuu0SzqCuDVZFptTsZl6/FH125/mUm8LC 8/UxQjogjIBHruDKQsGY9aO54jU+ZW6em05LIBvd89bZfBI7R2f1yiWBfdXcX/ehH7YhRm8/bAH Gk33b0KRKh/G219cFLSxTdRJfL1i8tHm917MOu76mfB1DvM5ui1aeft2lLKWDt5Boej6yEGrM+L A1bOp+0P9QIjZ+0HA9UX5A2+LaD/L75bXgb3f1fwhEkLM7sDPC4GCGhgwaKYifpbpUNBJIvC928 SLukdmFk8NXjtAWZZREd2+2FT9zBxr8Gb5nvTmCXPk3lwPbedTnVfS2MZbv/jeqnLypf4Kwx6kw gHX+cihPuK3C4TbCTeJ4xcb77ebl61kI1noE5IMyjuzvmwYReqnROhhQvSVI9xYDSpGhmgFlcoQ vDfuR0/33zm93Cel/aGQ6bifVCAj0pW5vgfuvU5mfb6+zeW4FpTCRZ+/qw57ou4jIdG5gG0EDPS OwgCsDatYz6/jXBfGfgBrWnfqqCdHUAHzJIvuP/975XVtB8aM/VaLR8siUQ87k6jrRvpDoH1v4S mZAxhdNy01fYerw== X-Developer-Key: i=shankerwangmiao@gmail.com; a=openpgp; fpr=6FAEFF06B7D212A774C60BFDFA0D166D6632EF4A X-Endpoint-Received: by B4 Relay for shankerwangmiao@gmail.com/20250715 with auth_id=462 X-Original-From: Miao Wang Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2600:3c0a:e001:78e:0:1991:8:25; envelope-from=devnull+shankerwangmiao.gmail.com@kernel.org; helo=sea.source.kernel.org X-Spam_score_int: 0 X-Spam_score: -0.0 X-Spam_bar: / X-Spam_report: (-0.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FORGED_REPLYTO=2.095, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: shankerwangmiao@gmail.com Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @kernel.org) X-ZM-MESSAGEID: 1784148533481158500 From: Miao Wang The CSR_ESTAT register of a CPU can be read and written by both the CPU thread and other threads (e.g., the interrupt controller thread). Currently the possible readers and writers of CSR_ESTAT are: - Readers - tcg generated by trans_csrrd(, CSR_ESTAT) - loongarch_cpu_has_work() - Writers - tcg generated by trans_csrxchg(, CSR_ESTAT) - helper_csrwr_estat() - helper_csrrd_msgir() - loongarch_cpu_set_irq() - loongarch_cpu_do_interrupt() - loongarch_cpu_exec_interrupt() The access from the CPU thread is not synchronized with the access from other threads, which may lead to data races. The above readers and writers shall all run on the corresponding CPU thread except for loongarch_cpu_set_irq(). To fix this, the access to CSR_ESTAT in loongarch_cpu_set_irq() is moved to the CPU thread by using async_run_on_cpu(). The data race has been identified while running the test cases from dracut, which is using QEMU to boot a LoongArch guest. By running the tests repeatedly (about 30 times) in the following conditions, the guest will hang in the middle of booting: - Host architecture: LoongArch64 or Aarch64 - Guest kernel: 7.1.3+deb14-loong64 - Number of vCPUs: 1 or 2 - CPU Features: max, la464,msgint=3Doff,ptw=3Doff, or la464,msgint=3Doff,pt= w=3Don - Accelerator: tcg When the guest hangs, the guest kernel log shows various errors related to RCU stalls or other Soft Lockup or Hard Lockup issues. When running with 1 vCPU and the guest hangs, the guest kernel directly hangs without any messages and stucks at idle_exit. With this patch, the guest can boot successfully without any hangs during repeated runs of the test cases. Signed-off-by: Miao Wang --- Changes in v2: - Simplify the changes to move the access to CSR_ESTAT from the only unsynchronized loongarch_cpu_set_irq() to the CPU thread using async_run_on_cpu() to avoid the race condition. - Link to v1: https://lore.kernel.org/qemu-devel/20260714-loong-race-v1-1-5= 4111549c95e@gmail.com --- target/loongarch/cpu.c | 27 +++++++++++++++++++-------- 1 file changed, 19 insertions(+), 8 deletions(-) diff --git a/target/loongarch/cpu.c b/target/loongarch/cpu.c index fb03424ffa8cd5e5d250531cc2a36fa789fc25a9..126c3ad276cc44311942542e086= bcabe41d91b63 100644 --- a/target/loongarch/cpu.c +++ b/target/loongarch/cpu.c @@ -57,12 +57,27 @@ static vaddr loongarch_cpu_get_pc(CPUState *cs) #ifndef CONFIG_USER_ONLY #include "hw/loongarch/virt.h" =20 +static void do_set_cpu_estat(CPUState *cs, run_on_cpu_data data) +{ + CPULoongArchState *env =3D cpu_env(cs); + CPUSysState *sys =3D env_sys(env); + + int irq =3D data.host_int; + int level =3D irq >=3D 0 ? 1 : 0; + irq =3D level ? irq : -irq; + + sys->CSR_ESTAT =3D deposit64(sys->CSR_ESTAT, irq, 1, level !=3D 0); + if (FIELD_EX64(sys->CSR_ESTAT, CSR_ESTAT, IS)) { + cpu_interrupt(cs, CPU_INTERRUPT_HARD); + } else { + cpu_reset_interrupt(cs, CPU_INTERRUPT_HARD); + } +} + void loongarch_cpu_set_irq(void *opaque, int irq, int level) { LoongArchCPU *cpu =3D opaque; - CPULoongArchState *env =3D &cpu->env; CPUState *cs =3D CPU(cpu); - CPUSysState *sys =3D env_sys(env); =20 if (irq < 0 || irq >=3D N_IRQS) { return; @@ -71,12 +86,8 @@ void loongarch_cpu_set_irq(void *opaque, int irq, int le= vel) if (kvm_enabled()) { kvm_loongarch_set_interrupt(cpu, irq, level); } else if (tcg_enabled()) { - sys->CSR_ESTAT =3D deposit64(sys->CSR_ESTAT, irq, 1, level !=3D 0); - if (FIELD_EX64(sys->CSR_ESTAT, CSR_ESTAT, IS)) { - cpu_interrupt(cs, CPU_INTERRUPT_HARD); - } else { - cpu_reset_interrupt(cs, CPU_INTERRUPT_HARD); - } + async_run_on_cpu(cs, do_set_cpu_estat, + RUN_ON_CPU_HOST_INT(level ? irq : -irq)); } } =20 --- base-commit: 499039798cdad7d86b787fec0eaf1da4151c0f05 change-id: 20260707-loong-race-63639e8f5afb Best regards, --=20 Miao Wang