Fix release fence ordering in inner_enqueue() to prevent size_approx() race on AArch64 - #172
Open
cppmage wants to merge 1 commit into
Open
Fix release fence ordering in inner_enqueue() to prevent size_approx() race on AArch64#172cppmage wants to merge 1 commit into
cppmage wants to merge 1 commit into
Conversation
Move fence(memory_order_release) before both writes that publish a newly allocated block (tailBlock_->next and tailBlock), not just the second one. size_approx() reaches blocks via the next-chain and never reads tailBlock, so it wasn't covered by the existing fence placement. Fixes cameron314#171
cameron314
reviewed
Aug 23, 2026
cameron314
left a comment
Owner
There was a problem hiding this comment.
Thanks for looking into this. It does seem like a real bug.
Comment on lines
631
to
636
| @@ -627,7 +634,6 @@ class MOODYCAMEL_MAYBE_ALIGN_TO_CACHELINE ReaderWriterQueue | |||
| // case where it could try to read the next is if it's already at the tailBlock, | |||
| // and it won't advance past tailBlock in any circumstance). | |||
|
|
|||
Owner
There was a problem hiding this comment.
I think this comment was to justify the previous placement of the fence, and can be removed, since it clearly missed a case in its reasoning :)
| // and it won't advance past tailBlock in any circumstance). | ||
|
|
||
| fence(memory_order_release); | ||
| tailBlock = newBlock; |
Owner
There was a problem hiding this comment.
I think we still need a release fence before setting tailBlock itself? Otherwise anything reading tailBlock might not see the latest value of tailBlock->next, which would be the opposite bug.
Owner
|
Note that at the time this code was written, TSan generated false positives with lock-free data structures, which is why it wasn't used. I should probably try running under TSan again at some point, it's come a long way since then. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #171
What changed
Move
fence(memory_order_release)ininner_enqueue()'sCanAllocbranch so it precedes both writes that publish a newly allocated block
(
tailBlock_->next = newBlockandtailBlock = newBlock), instead ofonly the second one. See #171 for the full root-cause
analysis and repro.
Also expanded the comment at that call site to note that
size_approx()(and any otherBlock::next-chain traversal) dependson this ordering too, not just
try_dequeue().Testing
size_approxstress test run in a loop (1000 iterations).same loop (1000 iterations).
size_approxstress test has other pre-existingassertion failures, unrelated to this change and not addressed here.