[PATCH RFC v2 06/15] hazptr: elide redundant first drain pass

From: Kunwu Chan

Date: Fri Oct 02 2026 - 13:10:26 EST


Each scan cycle drained both wildcard generations: the
unpublished "other" generation (pass 1) and the pre-flip current
generation (pass 2). Pass 1 is not needed for correctness, so
flip the wildcard first and drain only the old generation while
building the Bloom filter.

An acquire that read the old wildcard before the flip may publish
it into its slot after the drain has passed that slot. Such a
straggling acquire cannot have loaded the pre-unpublish pointer;
see the following LKMM test for the ordering argument.

Signed-off-by: Kunwu Chan <kunwu.chan@xxxxxxxxx>
---
kernel/hazptr.c | 36 +++++++++++++-----------------------
1 file changed, 13 insertions(+), 23 deletions(-)

diff --git a/kernel/hazptr.c b/kernel/hazptr.c
index 799784f698ed..86336f229f57 100644
--- a/kernel/hazptr.c
+++ b/kernel/hazptr.c
@@ -365,24 +365,19 @@ static bool hazptr_scan_walk(void *watch, struct hazptr_bloom *bloom)
}

/*
- * Wait until no per-CPU slot or overflow-list slot holds @wc.
- * Callers must ensure that the wildcard value in use by new acquires
- * differs from @wc, so that the set of slots holding @wc only
- * shrinks, which guarantees forward progress.
- */
-static void hazptr_drain_wildcard(void *wc)
-{
- while (hazptr_scan_walk(wc, NULL))
- cond_resched();
-}
-
-/*
- * Move pending waiters to ->scanning and perform a two-phase
- * wildcard scan shared by all waiters.
+ * Move pending waiters to ->scanning, flip the wildcard, then
+ * drain the old generation while collecting observed addresses
+ * into the Bloom filter. New acquires use the new generation,
+ * so old-generation slots normally only drain.
+ *
+ * An acquire that read the old wildcard before the flip may
+ * publish it after the scanner has passed its slot, but cannot
+ * have loaded the pre-unpublish pointer. See
+ * Documentation/litmus-tests/hazptr/hazptr-wildcard-flip-escape.litmus.
*/
static void hazptr_scan_do_cycle(void)
{
- void *scan_wildcard, *old_wildcard;
+ void *old_wildcard;
struct hazptr_waiter *w, *n;
LIST_HEAD(done);

@@ -397,16 +392,11 @@ static void hazptr_scan_do_cycle(void)
return;
}

- /* Pass 1: drain the unpublished wildcard. */
- scan_wildcard = flip_wildcard(READ_ONCE(hazptr_wildcard));
- hazptr_drain_wildcard(scan_wildcard);
-
- /* Flip so new acquires use the new generation. */
- WRITE_ONCE(hazptr_wildcard, scan_wildcard);
- old_wildcard = flip_wildcard(scan_wildcard);
+ old_wildcard = READ_ONCE(hazptr_wildcard);
+ WRITE_ONCE(hazptr_wildcard, flip_wildcard(old_wildcard));

/*
- * Pass 2: drain the old wildcard while collecting observed
+ * Drain the old wildcard while collecting observed
* addresses into the Bloom filter.
*/
while (hazptr_scan_walk(old_wildcard, &hazptr_scan.bloom))
--
2.43.0