From nobody Fri Jul 24 21:53:09 2026 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BCD0741F7F2; Thu, 23 Jul 2026 10:21:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.142.43.55 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784802080; cv=none; b=IdkmlI2jW6hCioLSOtP9daPzT9ghT+q9DQ4izK/hIrzKJkSZHujF33bkc2Q8gofZfvnkxm8qxD7I8vOlY2CV4WyCMZOE6crj7p96SLhbwAfEowKAQycUQ4gl13TJ+sJYmfgEfctwIGxGc27R9nuSgsHu195QeEzT43KyOZXm0k0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784802080; c=relaxed/simple; bh=/QDtTQDp3hnMj/8QBvl0i3iDa9oKl8SajZoLsygSNh8=; h=Date:From:To:Subject:Cc:In-Reply-To:References:MIME-Version: Message-ID:Content-Type; b=m/VY8rP/T6dCN/0PLYL031dqDVazNfrO3SY4qW8QqFuZzxoIrKbNn3lDdAHMOykEzORFRf8dFJI1YuNMe7ThSDAOdnoZKVIZHbpiALsvaOE8+GWV8tkPPEcj8CE50bGCGV/RDt7m5V4EDOlK8waIKEKkJg9xDggdHhPJXAnawtE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de; spf=pass smtp.mailfrom=linutronix.de; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=h6Fxk54+; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=47NDp3nL; arc=none smtp.client-ip=193.142.43.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linutronix.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="h6Fxk54+"; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="47NDp3nL" Date: Thu, 23 Jul 2026 10:21:14 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1784802076; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=jM/9cgfxrIiH5uAP/NvPU/HethIBomjAXp3j72v/FUU=; b=h6Fxk54+iHwjW/ohw2SN8u48MtLuTFWU0P7UTJ/9Sr9NtfqBHwponPoEH7BZHElUCh5hoM Cw4jeXF+aO4CGx4FhydUwZgwftXHBa7i1LJmwD0MzjwCVJUBwq9pIYwlQQqFClyHViGMtp Vu9TjbW4fk9xVBbbFyWn1ZYfX93kC38kOSZvVadwjMgVZfHhvbOWtSOweea+lXRUhBMph2 4+hfLSXNFvPyizNFj8R70261h1zrE/wbxqlckox14+9Q05LQFaddxrSkMjbVXICeBz51kU 6JyE3WWrlHRb3cNa41dqiqqkPhXTgtyVAwHatFlZeWbScdw4L09qEawPqR/BIA== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1784802076; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=jM/9cgfxrIiH5uAP/NvPU/HethIBomjAXp3j72v/FUU=; b=47NDp3nLdY+pL95AKpXFFdtegUA4MK+2oZmQzbYZAvulQ9IfwaRov2fNClu0OZ0OsZqHrd A+xITjsDUXXhIPDg== From: "tip-bot2 for Chuyi Zhou" Sender: tip-bot2@linutronix.de Reply-to: linux-kernel@vger.kernel.org To: linux-tip-commits@vger.kernel.org Subject: [tip: smp/core] scftorture: Remove preempt_disable() in scftorture_invoke_one() Cc: Chuyi Zhou , Thomas Gleixner , "Paul E. McKenney" , Sebastian Andrzej Siewior , x86@kernel.org, linux-kernel@vger.kernel.org In-Reply-To: <20260709122933.4021501-10-zhouchuyi@bytedance.com> References: <20260709122933.4021501-10-zhouchuyi@bytedance.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-ID: <178480207447.2943223.5930234307841919600.tip-bot2@tip-bot2> Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails Precedence: bulk Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The following commit has been merged into the smp/core branch of tip: Commit-ID: 99b49e02f9488335156c896c24aab0785623eb67 Gitweb: https://git.kernel.org/tip/99b49e02f9488335156c896c24aab0785= 623eb67 Author: Chuyi Zhou AuthorDate: Thu, 09 Jul 2026 20:29:28 +08:00 Committer: Thomas Gleixner CommitterDate: Thu, 16 Jul 2026 09:24:56 +02:00 scftorture: Remove preempt_disable() in scftorture_invoke_one() The smp_call*() functions handle their required preemption and CPU pinning internally. The explicit preempt_disable() in scftorture_invoke_one() is therefore no longer required for correctness. Keeping the outer preempt_disable() would also prevent scftorture from exercising the narrowed internal preemption-disabled regions during IPI dispatch. Removing the outer preemption protection can expose a CPU hotplug race in the test validation when use_cpus_read_lock is false. For multicast operations, SCF_PRIM_MANY or SCF_PRIM_ALL, if only one CPU is online, smp_call_function_many() correctly skips sending IPIs and leaves scfc_out false. Without preemption disabled, a CPU hotplug thread can preempt the test thread, bring a second CPU online and increment num_online_cpus(). When the test thread resumes, the validation check can observe num_online_cpus() > 1 and falsely trigger the memory-ordering warning, leaking the scfcp structure. Remove the preempt_disable() and preempt_enable() pairs around the smp_call*() invocations in scftorture_invoke_one(). Restrict the num_online_cpus() > 1 validation to the use_cpus_read_lock=3Dtrue case, where the CPU count is stable during the evaluation. Signed-off-by: Chuyi Zhou Signed-off-by: Thomas Gleixner Tested-by: Paul E. McKenney Reviewed-by: Sebastian Andrzej Siewior Link: https://patch.msgid.link/20260709122933.4021501-10-zhouchuyi@bytedanc= e.com --- kernel/scftorture.c | 13 ++++--------- 1 file changed, 4 insertions(+), 9 deletions(-) diff --git a/kernel/scftorture.c b/kernel/scftorture.c index 327c315..2082f9b 100644 --- a/kernel/scftorture.c +++ b/kernel/scftorture.c @@ -348,6 +348,8 @@ static void scftorture_invoke_one(struct scf_statistics= *scfp, struct torture_ra int ret =3D 0; struct scf_check *scfcp =3D NULL; struct scf_selector *scfsp =3D scf_sel_rand(trsp); + bool is_single =3D (scfsp->scfs_prim =3D=3D SCF_PRIM_SINGLE || + scfsp->scfs_prim =3D=3D SCF_PRIM_SINGLE_RPC); =20 if (scfsp->scfs_prim =3D=3D SCF_PRIM_SINGLE || scfsp->scfs_wait) { scfcp =3D kmalloc_obj(*scfcp, GFP_ATOMIC); @@ -364,8 +366,6 @@ static void scftorture_invoke_one(struct scf_statistics= *scfp, struct torture_ra } if (use_cpus_read_lock) cpus_read_lock(); - else - preempt_disable(); switch (scfsp->scfs_prim) { case SCF_PRIM_RESCHED: if (IS_BUILTIN(CONFIG_SCF_TORTURE_TEST)) { @@ -411,13 +411,10 @@ static void scftorture_invoke_one(struct scf_statisti= cs *scfp, struct torture_ra if (!ret) { if (use_cpus_read_lock) cpus_read_unlock(); - else - preempt_enable(); + wait_for_completion(&scfcp->scfc_completion); if (use_cpus_read_lock) cpus_read_lock(); - else - preempt_disable(); } else { scfp->n_single_rpc_ofl++; scf_add_to_free_list(scfcp); @@ -452,7 +449,7 @@ static void scftorture_invoke_one(struct scf_statistics= *scfp, struct torture_ra scfcp->scfc_out =3D true; } if (scfcp && scfsp->scfs_wait) { - if (WARN_ON_ONCE((num_online_cpus() > 1 || scfsp->scfs_prim =3D=3D SCF_P= RIM_SINGLE) && + if (WARN_ON_ONCE(((use_cpus_read_lock && num_online_cpus() > 1) || is_si= ngle) && !scfcp->scfc_out)) { pr_warn("%s: Memory-ordering failure, scfs_prim: %d.\n", __func__, scfs= p->scfs_prim); atomic_inc(&n_mb_out_errs); // Leak rather than trash! @@ -463,8 +460,6 @@ static void scftorture_invoke_one(struct scf_statistics= *scfp, struct torture_ra } if (use_cpus_read_lock) cpus_read_unlock(); - else - preempt_enable(); if (allocfail) schedule_timeout_idle((1 + longwait) * HZ); // Let no-wait handlers com= plete. else if (!(torture_random(trsp) & 0xfff))