Commit 7e9b1879 authored by Litao Jiao's avatar Litao Jiao
Browse files

net/smc: replace mutex rmbs_lock and sndbufs_lock with rw_semaphore

mainline inclusion
from mainline-v6.3-rc1
commit aff7bfed
category: bugfix
bugzilla: https://gitee.com/openeuler/kernel/issues/I7809T
CVE: NA

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/smc?id=aff7bfed9097435ea38de919befbe2d7771a3e87



--------------------------------

It's clear that rmbs_lock and sndbufs_lock are aims to protect the
rmbs list or the sndbufs list.

During connection establieshment, smc_buf_get_slot() will always
be invoked, and it only performs read semantics in rmbs list and
sndbufs list.

Based on the above considerations, we replace mutex with rw_semaphore.
Only smc_buf_get_slot() use down_read() to allow smc_buf_get_slot()
run concurrently, other part use down_write() to keep exclusive
semantics.

Signed-off-by: default avatarD. Wythe <alibuda@linux.alibaba.com>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
Signed-off-by: default avatarLitao Jiao <jiaolitao@sangfor.com.cn>
parent c87e42bb
Loading
Loading
Loading
Loading
+22 −22
Original line number Diff line number Diff line
@@ -398,8 +398,8 @@ static int smc_lgr_create(struct smc_sock *smc, struct smc_init_info *ini)
	lgr->terminating = 0;
	lgr->freeing = 0;
	lgr->vlan_id = ini->vlan_id;
	mutex_init(&lgr->sndbufs_lock);
	mutex_init(&lgr->rmbs_lock);
	init_rwsem(&lgr->sndbufs_lock);
	init_rwsem(&lgr->rmbs_lock);
	rwlock_init(&lgr->conns_lock);
	for (i = 0; i < SMC_RMBE_SIZES; i++) {
		INIT_LIST_HEAD(&lgr->sndbufs[i]);
@@ -624,9 +624,9 @@ static void smcr_buf_unuse(struct smc_buf_desc *rmb_desc,

	if (rmb_desc->is_reg_err) {
		/* buf registration failed, reuse not possible */
		mutex_lock(&lgr->rmbs_lock);
		down_write(&lgr->rmbs_lock);
		list_del(&rmb_desc->list);
		mutex_unlock(&lgr->rmbs_lock);
		up_write(&lgr->rmbs_lock);

		smc_buf_free(lgr, true, rmb_desc);
	} else {
@@ -700,15 +700,15 @@ static void smcr_buf_unmap_lgr(struct smc_link *lnk)
	int i;

	for (i = 0; i < SMC_RMBE_SIZES; i++) {
		mutex_lock(&lgr->rmbs_lock);
		down_write(&lgr->rmbs_lock);
		list_for_each_entry_safe(buf_desc, bf, &lgr->rmbs[i], list)
			smcr_buf_unmap_link(buf_desc, true, lnk);
		mutex_unlock(&lgr->rmbs_lock);
		mutex_lock(&lgr->sndbufs_lock);
		up_write(&lgr->rmbs_lock);
		down_write(&lgr->sndbufs_lock);
		list_for_each_entry_safe(buf_desc, bf, &lgr->sndbufs[i],
					 list)
			smcr_buf_unmap_link(buf_desc, false, lnk);
		mutex_unlock(&lgr->sndbufs_lock);
		up_write(&lgr->sndbufs_lock);
	}
}

@@ -1404,19 +1404,19 @@ int smc_uncompress_bufsize(u8 compressed)
 * buffer size; if not available, return NULL
 */
static struct smc_buf_desc *smc_buf_get_slot(int compressed_bufsize,
					     struct mutex *lock,
					     struct rw_semaphore *lock,
					     struct list_head *buf_list)
{
	struct smc_buf_desc *buf_slot;

	mutex_lock(lock);
	down_read(lock);
	list_for_each_entry(buf_slot, buf_list, list) {
		if (cmpxchg(&buf_slot->used, 0, 1) == 0) {
			mutex_unlock(lock);
			up_read(lock);
			return buf_slot;
		}
	}
	mutex_unlock(lock);
	up_read(lock);
	return NULL;
}

@@ -1492,13 +1492,13 @@ int smcr_link_reg_rmb(struct smc_link *link, struct smc_buf_desc *rmb_desc)
	return 0;
}

static int _smcr_buf_map_lgr(struct smc_link *lnk, struct mutex *lock,
static int _smcr_buf_map_lgr(struct smc_link *lnk, struct rw_semaphore *lock,
			     struct list_head *lst, bool is_rmb)
{
	struct smc_buf_desc *buf_desc, *bf;
	int rc = 0;

	mutex_lock(lock);
	down_write(lock);
	list_for_each_entry_safe(buf_desc, bf, lst, list) {
		if (!buf_desc->used)
			continue;
@@ -1507,7 +1507,7 @@ static int _smcr_buf_map_lgr(struct smc_link *lnk, struct mutex *lock,
			goto out;
	}
out:
	mutex_unlock(lock);
	up_write(lock);
	return rc;
}

@@ -1539,7 +1539,7 @@ int smcr_buf_reg_lgr(struct smc_link *lnk)
	struct smc_buf_desc *buf_desc, *bf;
	int i, rc = 0;

	mutex_lock(&lgr->rmbs_lock);
	down_write(&lgr->rmbs_lock);
	for (i = 0; i < SMC_RMBE_SIZES; i++) {
		list_for_each_entry_safe(buf_desc, bf, &lgr->rmbs[i], list) {
			if (!buf_desc->used)
@@ -1550,7 +1550,7 @@ int smcr_buf_reg_lgr(struct smc_link *lnk)
		}
	}
out:
	mutex_unlock(&lgr->rmbs_lock);
	up_write(&lgr->rmbs_lock);
	return rc;
}

@@ -1654,7 +1654,7 @@ static int __smc_buf_create(struct smc_sock *smc, bool is_smcd, bool is_rmb)
	struct smc_link_group *lgr = conn->lgr;
	struct list_head *buf_list;
	int bufsize, bufsize_short;
	struct mutex *lock;	/* lock buffer list */
	struct rw_semaphore *lock;	/* lock buffer list */
	int sk_buf_size;

	if (is_rmb)
@@ -1696,9 +1696,9 @@ static int __smc_buf_create(struct smc_sock *smc, bool is_smcd, bool is_rmb)
			continue;

		buf_desc->used = 1;
		mutex_lock(lock);
		down_write(lock);
		list_add(&buf_desc->list, buf_list);
		mutex_unlock(lock);
		up_write(lock);
		break; /* found */
	}

@@ -1788,9 +1788,9 @@ int smc_buf_create(struct smc_sock *smc, bool is_smcd)
	/* create rmb */
	rc = __smc_buf_create(smc, is_smcd, true);
	if (rc) {
		mutex_lock(&smc->conn.lgr->sndbufs_lock);
		down_write(&smc->conn.lgr->sndbufs_lock);
		list_del(&smc->conn.sndbuf_desc->list);
		mutex_unlock(&smc->conn.lgr->sndbufs_lock);
		up_write(&smc->conn.lgr->sndbufs_lock);
		smc_buf_free(smc->conn.lgr, false, smc->conn.sndbuf_desc);
		smc->conn.sndbuf_desc = NULL;
	}
+2 −2
Original line number Diff line number Diff line
@@ -220,9 +220,9 @@ struct smc_link_group {
	unsigned short		vlan_id;	/* vlan id of link group */

	struct list_head	sndbufs[SMC_RMBE_SIZES];/* tx buffers */
	struct mutex		sndbufs_lock;	/* protects tx buffers */
	struct rw_semaphore	sndbufs_lock;	/* protects tx buffers */
	struct list_head	rmbs[SMC_RMBE_SIZES];	/* rx buffers */
	struct mutex		rmbs_lock;	/* protects rx buffers */
	struct rw_semaphore	rmbs_lock;	/* protects rx buffers */

	u8			id[SMC_LGR_ID_SIZE];	/* unique lgr id */
	struct delayed_work	free_work;	/* delayed freeing of an lgr */
+4 −4
Original line number Diff line number Diff line
@@ -756,7 +756,7 @@ static int smc_llc_cli_rkey_exchange(struct smc_link *link,
	int rc = 0;
	int i;

	mutex_lock(&lgr->rmbs_lock);
	down_write(&lgr->rmbs_lock);
	num_rkeys_send = lgr->conns_num;
	buf_pos = smc_llc_get_first_rmb(lgr, &buf_lst);
	do {
@@ -783,7 +783,7 @@ static int smc_llc_cli_rkey_exchange(struct smc_link *link,
			break;
	} while (num_rkeys_send || num_rkeys_recv);

	mutex_unlock(&lgr->rmbs_lock);
	up_write(&lgr->rmbs_lock);
	return rc;
}

@@ -1089,7 +1089,7 @@ static int smc_llc_srv_rkey_exchange(struct smc_link *link,
	int rc = 0;
	int i;

	mutex_lock(&lgr->rmbs_lock);
	down_write(&lgr->rmbs_lock);
	num_rkeys_send = lgr->conns_num;
	buf_pos = smc_llc_get_first_rmb(lgr, &buf_lst);
	do {
@@ -1114,7 +1114,7 @@ static int smc_llc_srv_rkey_exchange(struct smc_link *link,
		smc_llc_flow_qentry_del(&lgr->llc_flow_lcl);
	} while (num_rkeys_send || num_rkeys_recv);
out:
	mutex_unlock(&lgr->rmbs_lock);
	up_write(&lgr->rmbs_lock);
	return rc;
}