From owner-svn-src-head@FreeBSD.ORG Tue Nov 4 09:21:45 2014 Return-Path: Delivered-To: svn-src-head@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 86940840; Tue, 4 Nov 2014 09:21:45 +0000 (UTC) Received: from kib.kiev.ua (kib.kiev.ua [IPv6:2001:470:d5e7:1::1]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 0E699EAC; Tue, 4 Nov 2014 09:21:44 +0000 (UTC) Received: from tom.home (kostik@localhost [127.0.0.1]) by kib.kiev.ua (8.14.9/8.14.9) with ESMTP id sA49LdZl065470 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 4 Nov 2014 11:21:39 +0200 (EET) (envelope-from kostikbel@gmail.com) DKIM-Filter: OpenDKIM Filter v2.9.2 kib.kiev.ua sA49LdZl065470 Received: (from kostik@localhost) by tom.home (8.14.9/8.14.9/Submit) id sA49LcnY065469; Tue, 4 Nov 2014 11:21:38 +0200 (EET) (envelope-from kostikbel@gmail.com) X-Authentication-Warning: tom.home: kostik set sender to kostikbel@gmail.com using -f Date: Tue, 4 Nov 2014 11:21:38 +0200 From: Konstantin Belousov To: Bruce Evans Subject: Re: svn commit: r273958 - head/sys/dev/random Message-ID: <20141104092138.GO53947@kib.kiev.ua> References: <29A795E1-19E2-49E4-9653-143D3F6F3F12@grondar.org> <20141102194625.GC53947@kib.kiev.ua> <751CD860-95B9-4F68-AE69-976B42823AD0@grondar.org> <54568E41.8030305@delphij.net> <20141102201331.GE53947@kib.kiev.ua> <545693B4.8030602@delphij.net> <1414961583.1200.27.camel@revolution.hippie.lan> <20141103113629.I3149@besplex.bde.org> <20141103091954.GJ53947@kib.kiev.ua> <20141104024151.M1038@besplex.bde.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20141104024151.M1038@besplex.bde.org> User-Agent: Mutt/1.5.23 (2014-03-12) X-Spam-Status: No, score=-2.0 required=5.0 tests=ALL_TRUSTED,BAYES_00, DKIM_ADSP_CUSTOM_MED,FREEMAIL_FROM,NML_ADSP_CUSTOM_MED autolearn=no autolearn_force=no version=3.4.0 X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on tom.home Cc: "src-committers@freebsd.org" , d@delphij.net, Ian Lepore , "svn-src-all@freebsd.org" , Mark R V Murray , "svn-src-head@freebsd.org" X-BeenThere: svn-src-head@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: SVN commit messages for the src tree for head/-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 04 Nov 2014 09:21:45 -0000 On Tue, Nov 04, 2014 at 02:59:17AM +1100, Bruce Evans wrote: > On Mon, 3 Nov 2014, Konstantin Belousov wrote: > > > On Mon, Nov 03, 2014 at 11:53:26AM +1100, Bruce Evans wrote: > >> On Sun, 2 Nov 2014, Ian Lepore wrote: > >> > >>> On Sun, 2014-11-02 at 12:27 -0800, Xin Li wrote: > >>>> -----BEGIN PGP SIGNED MESSAGE----- > >>>> Hash: SHA512 > >>>> > >>>> Hi, Mark, > >>>> > >>>> I'd like to propose the attached patch for review. It replaces > >>>> tsleep's with sx_sleep's, then checks the return value and quit the loop. > >>> > >>> It still doesn't handle the partial read/write case Kostik mentioned, > >>> but there are plenty of other drivers that don't get that right. > >> > >> Returning an error for a partial read is good enough for random devices, > >> since there is no problem with discarding the input. Upper layers are > >> still broken, so this (discarding the input is what happens automatically > >> except for ERESTART, EINTR and EWOULDBLOCK. > > But usermode buffer is already partially accessed and modified. > > Yes, I am picky about it after vn_io_fault() work. > > Urk. For some reason I was thinking that the uio modifications were > in a kernel buffer, so they could be backed out of easily. > > But surely the user buffer is indeterminate after a read error? Even > after success, the region beyond the part read should be specified as > indeterminate. I do not agree with this statement. > Consider an implementation that asks the hardware to > DMA into part of the read buffer beyond a (possibly null) region already > successfully read. If the DMA fails, you might not know how far it > got. The best you can do to recover is to back out of the failed part > of the read only. Possibly zero the part that failed for security. > For further complications, consider a similar implementations but > with multiple DMA channels writing in indeterminate order. This is theoretical. I am not aware of such driver. > > If (part of) the buffer is not allowed to be indeterminate after a > success or failure, then both the success and the failure cases are > broken in the FreeBSD implementation (apart from not handling short > I/O's correctly). In the failure case, not backing out of partial > I/O's leaves a trashed buffer. In the success case, if it is > implemented by a partial backout, the part not backed out of is still > trashed. I am not sure I follow. There are two aspects of the buffer validity issue. One is the correctness of the file pointer (in other words, the report of number of bytes read or written). This includes the correct return of the short i/o count instead of error. Another is the guarantee of the state of the buffer part after the file pointer. I do not believe there is any statement about this in POSIX, nor most applications depend on the state, but some are. E.g., cyclic buffer used by sound or video recording functioning might depend on such guarantees. Overall, both issues determine the quality of implementation, and I prefer to implement them if not too costly. For the /dev/random, which does byte-streaming using uiomove(9), both are trivially implementable, so there is no reason not to do everything correctly.