Fix release fence ordering in inner_enqueue() to prevent size_approx() race on AArch64 - #172
Fix release fence ordering in inner_enqueue() to prevent size_approx() race on AArch64#172cppmage wants to merge 2 commits into
Conversation
Move fence(memory_order_release) before both writes that publish a newly allocated block (tailBlock_->next and tailBlock), not just the second one. size_approx() reaches blocks via the next-chain and never reads tailBlock, so it wasn't covered by the existing fence placement. Fixes cameron314#171
cameron314
left a comment
There was a problem hiding this comment.
Thanks for looking into this. It does seem like a real bug.
| @@ -627,7 +634,6 @@ class MOODYCAMEL_MAYBE_ALIGN_TO_CACHELINE ReaderWriterQueue | |||
| // case where it could try to read the next is if it's already at the tailBlock, | |||
| // and it won't advance past tailBlock in any circumstance). | |||
|
|
|||
There was a problem hiding this comment.
I think this comment was to justify the previous placement of the fence, and can be removed, since it clearly missed a case in its reasoning :)
| // and it won't advance past tailBlock in any circumstance). | ||
|
|
||
| fence(memory_order_release); | ||
| tailBlock = newBlock; |
There was a problem hiding this comment.
I think we still need a release fence before setting tailBlock itself? Otherwise anything reading tailBlock might not see the latest value of tailBlock->next, which would be the opposite bug.
There was a problem hiding this comment.
I think we still need a release fence before setting
tailBlockitself? Otherwise anything readingtailBlockmight not see the latest value oftailBlock->next, which would be the opposite bug.
Yeap, that is right. We need to guarantee that tailBlock's data was prepared before changing it.
I'll restore the second fence and clarify the comment accordingly.
|
Note that at the time this code was written, TSan generated false positives with lock-free data structures, which is why it wasn't used. I should probably try running under TSan again at some point, it's come a long way since then. |
Launched with clang thread sanitize, everything seems normal for me. |
Added second fence and changed comments
Fixes #171
What changed
Move
fence(memory_order_release)ininner_enqueue()'sCanAllocbranch so it precedes both writes that publish a newly allocated block
(
tailBlock_->next = newBlockandtailBlock = newBlock), instead ofonly the second one. See #171 for the full root-cause
analysis and repro.
Also expanded the comment at that call site to note that
size_approx()(and any otherBlock::next-chain traversal) dependson this ordering too, not just
try_dequeue().Testing
size_approxstress test run in a loop (1000 iterations).same loop (1000 iterations).
size_approxstress test has other pre-existingassertion failures, unrelated to this change and not addressed here.