rust: sync: Introduce SpinLockIrq::lock_with() and friends

`SpinLockIrq` and `SpinLock` use the exact same underlying C structure,
with the only real difference being that the former uses the
irq_disable() and irq_enable() variants for locking/unlocking. These
variants can introduce some minor overhead in contexts where we already
know that local processor interrupts are disabled, and as such we want a
way to be able to skip modifying processor interrupt state in said
contexts in order to avoid some overhead - just like the current C API
allows us to do.

In order to do this, we add some special functions for SpinLockIrq:
lock_with() and try_lock_with(), which allow acquiring the lock without
changing the interrupt state - as long as the caller can provide a
LocalInterruptDisabled reference to prove that local processor
interrupts have been disabled.

In some hacked-together benchmarks we ran, most of the time this did
actually seem to lead to a noticeable difference in overhead:

  From an aarch64 VM running on a MacBook M4:
    lock() when irq is disabled, 100 times cost Delta { nanos: 500 }
    lock_with() when irq is disabled, 100 times cost Delta { nanos: 292 }
    lock() when irq is enabled, 100 times cost Delta { nanos: 834 }

    lock() when irq is disabled, 100 times cost Delta { nanos: 459 }
    lock_with() when irq is disabled, 100 times cost Delta { nanos: 291 }
    lock() when irq is enabled, 100 times cost Delta { nanos: 709 }

  From an x86_64 VM (qemu/kvm) running on a i7-13700H
    lock() when irq is disabled, 100 times cost Delta { nanos: 1002 }
    lock_with() when irq is disabled, 100 times cost Delta { nanos: 729 }
    lock() when irq is enabled, 100 times cost Delta { nanos: 1516 }

    lock() when irq is disabled, 100 times cost Delta { nanos: 754 }
    lock_with() when irq is disabled, 100 times cost Delta { nanos: 966 }
    lock() when irq is enabled, 100 times cost Delta { nanos: 1227 }

    (note that there were some runs on x86_64 where lock() on irq
    disabled vs. lock_with() on irq disabled had equivalent benchmarks,
    but it very much appeared to be a minority of test runs.)

While it's not clear how this affects real-world workloads yet, let's
add this for the time being so we can find out.

This makes it so that a `SpinLockIrq` will work like a `SpinLock` if
interrupts are disabled. So a function:

        (&'a SpinLockIrq, &'a LocalInterruptDisabled) -> Guard<'a, .., SpinLockBackend>

makes sense. Note that due to `Guard` and `LocalInterruptDisabled`
having the same lifetime, interrupts cannot be enabled while the Guard
exists.

Signed-off-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Boqun Feng <boqun@kernel.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Gary Guo <gary@garyguo.net>
Link: https://patch.msgid.link/20260807070218.27144-19-boqun@kernel.org
This commit is contained in:
Lyude Paul
2026-08-07 00:02:15 -07:00
committed by Peter Zijlstra
parent 5967f4df55
commit ec4fad7c2b

View File

@@ -4,7 +4,10 @@
//!
//! This module allows Rust code to use the kernel's `spinlock_t`.
use super::*;
use crate::prelude::*;
use crate::{
interrupt::LocalInterruptDisabled,
prelude::*, //
};
/// Creates a [`SpinLock`] initialiser with the given name and a newly-created lock class.
///
@@ -160,6 +163,16 @@ macro_rules! new_spinlock_irq {
/// A variant of `SpinLock` that ensures interrupts are disabled in the critical section.
///
/// This lock can be acquired in two ways:
///
/// - Using [`lock()`] like any other type of lock, in which case the bindings will modify the
/// interrupt state to ensure that local processor interrupts remain disabled for at least as
/// long as the [`SpinLockIrqGuard`] exists.
/// - Using [`lock_with()`] in contexts where a [`LocalInterruptDisabled`] token is present and
/// local processor interrupts are already known to be disabled, in which case the local
/// interrupt state will not be touched. This method should be preferred if a
/// [`LocalInterruptDisabled`] token is present in the scope.
///
/// For more info on spinlocks, see [`SpinLock`]. For more information on interrupts,
/// [see the interrupt module](kernel::interrupt).
///
@@ -213,7 +226,47 @@ macro_rules! new_spinlock_irq {
/// # Ok::<(), Error>(())
/// ```
///
/// The next example demonstrates locking a [`SpinLockIrq`] using [`lock_with()`] in a function
/// which can only be called when local processor interrupts are already disabled.
///
/// ```
/// use kernel::sync::{new_spinlock_irq, SpinLockIrq};
/// use kernel::interrupt::*;
///
/// struct Inner {
/// a: u32,
/// }
///
/// #[pin_data]
/// struct Example {
/// #[pin]
/// inner: SpinLockIrq<Inner>,
/// }
///
/// impl Example {
/// fn new() -> impl PinInit<Self> {
/// pin_init!(Self {
/// inner <- new_spinlock_irq!(Inner { a: 20 }),
/// })
/// }
/// }
///
/// // Accessing an `Example` from a function that can only be called in no-interrupt contexts.
/// fn noirq_work(e: &Example, interrupt_disabled: &LocalInterruptDisabled) {
/// // Because we know interrupts are disabled from interrupt_disable, we can skip toggling
/// // interrupt state using lock_with() and the provided token
/// assert_eq!(e.inner.lock_with(interrupt_disabled).a, 20);
/// }
///
/// # let e = KBox::pin_init(Example::new(), GFP_KERNEL)?;
/// # let interrupt_guard = local_interrupt_disable();
/// # noirq_work(&e, &interrupt_guard);
/// #
/// # Ok::<(), Error>(())
/// ```
///
/// [`lock()`]: SpinLockIrq::lock
/// [`lock_with()`]: SpinLockIrq::lock_with
pub type SpinLockIrq<T> = super::Lock<T, SpinLockIrqBackend>;
/// A kernel `spinlock_t` lock backend that can only be acquired in interrupt disabled contexts.
@@ -278,6 +331,43 @@ unsafe fn assert_is_held(ptr: *mut Self::State) {
}
}
impl<T: ?Sized> Lock<T, SpinLockIrqBackend> {
/// Casts the lock as a `Lock<T, SpinLockBackend>`.
#[inline]
fn as_lock_in_interrupt<'a>(&'a self, _context: &'a LocalInterruptDisabled) -> &'a SpinLock<T> {
// SAFETY:
// - `Lock<T, SpinLockBackend>` and `Lock<T, SpinLockIrqBackend>` both have identical data
// layouts.
// - As long as local interrupts are disabled (which is proven to be true by _context), it
// is safe to treat a lock with SpinLockIrqBackend as a SpinLockBackend lock.
unsafe { core::mem::transmute(self) }
}
/// Acquires the lock without modifying local interrupt state.
///
/// This function should be used in place of the more expensive [`Lock::lock()`] function when
/// possible for [`SpinLockIrq`] locks.
#[inline]
pub fn lock_with<'a>(&'a self, context: &'a LocalInterruptDisabled) -> SpinLockGuard<'a, T> {
self.as_lock_in_interrupt(context).lock()
}
/// Tries to acquire the lock without modifying local interrupt state.
///
/// This function should be used in place of the more expensive [`Lock::try_lock()`] function
/// when possible for [`SpinLockIrq`] locks.
///
/// Returns a guard that can be used to access the data protected by the lock if successful.
#[must_use = "if unused, the lock will be immediately unlocked"]
#[inline]
pub fn try_lock_with<'a>(
&'a self,
context: &'a LocalInterruptDisabled,
) -> Option<SpinLockGuard<'a, T>> {
self.as_lock_in_interrupt(context).try_lock()
}
}
#[kunit_tests(rust_spinlock_irq_condvar)]
mod tests {
use super::*;