[PATCH v2 00/14] Add clang Thread Safety Analysis (TSA) support
Anup Patel
anup at brainfault.org
Tue Sep 15 22:19:30 PDT 2026
On Wed, Sep 9, 2026 at 10:01 PM Carlos López
<carlos.lopezr4096 at gmail.com> wrote:
>
> Enable the use of clang's Thread Safety Analysis [0]. TSA is a clang
> language extension that allows detecting potential invalid locking
> patterns and race conditions at compile time, with zero runtime
> overhead. TSA relies on annotations to express the relationships between
> data and locks, and the expected state of a lock at certain points in
> the program.
>
> The first two commits introduce the basic infrastructure to use the TSA
> annotations. The last commit enables TSA by default in the Makefile.
> Commits in between add the new annotations to particular OpenSBI
> subsystems.
>
> The general pattern is:
> * Struct fields are rearranged so that locks appear before the
> field(s) they protect. This is needed for the compiler to be able to
> perform analysis. Protected fields are annotated with GUARDED_BY() /
> PT_GUARDED_BY().
> * Functions that access spinlock-protected fields are annotated wth
> MUST_HOLD().
> * Functions that acquire a spinlock, and which may plausibly be called
> with that spinlock held, are annotated with MUST_NOT_HOLD() to prevent
> potential future deadlocks.
> * Initializer functions and other special cases are excluded via
> NO_THREAD_SAFETY_ANALYSIS.
>
> This successfully results in detecting incorrect locking on clang >19.
> For example, the following change:
>
> diff --git a/lib/sbi/sbi_fifo.c b/lib/sbi/sbi_fifo.c
> index 88b8888d2e81..5348b7452f64 100644
> --- a/lib/sbi/sbi_fifo.c
> +++ b/lib/sbi/sbi_fifo.c
> @@ -37,9 +37,7 @@ u16 sbi_fifo_avail(struct sbi_fifo *fifo)
> if (!fifo)
> return 0;
>
> - spin_lock(&fifo->qlock);
> ret = fifo->avail;
> - spin_unlock(&fifo->qlock);
>
> return ret;
> }
>
> Results in a build error:
>
> lib/sbi/sbi_fifo.c:41:14: error: reading variable 'avail' requires holding spinlock '&sbi_fifo::qlock' [-Werror,-Wthread-safety-analysis]
> 41 | ret = fifo->avail;
> | ^
> 1 error generated.
>
> Tested with clang 18.1.8, 19.1.7 and 22.1.8.
>
> [0] https://clang.llvm.org/docs/ThreadSafetyAnalysis.html
>
> v2:
> - Enable TSA macros only on clang >= 19.
>
> Carlos López (14):
> include: sbi: add thread safety analysis macros
> lib: sbi_locks: annotate spinlock APIs for TSA
> lib: sbi_fifo: add TSA annotations
> lib: sbi_heap: add TSA annotations
> lib: sbi_scratch: add TSA annotations
> lib: rpmi: add TSA annotations
> lib: sbi_timer: add TSA annotations
> lib: htif: add TSA annotations
> lib: sbi_domain: add TSA annotations
> lib: sbi_sse: inline enable event locking
> lib: sbi_sse: pass SSE hart state explicitly
> lib: sbi_sse: add TSA annotations
> lib: test: disable TSA for spinlock tests
> Makefile: enable Thread Safety Analysis
>
> Makefile | 7 ++
> include/sbi/riscv_locks.h | 8 +-
> include/sbi/sbi_domain.h | 10 ++-
> include/sbi/sbi_fifo.h | 6 +-
> include/sbi/sbi_visibility.h | 17 +++++
> lib/sbi/riscv_locks.c | 4 +-
> lib/sbi/sbi_domain.c | 3 +
> lib/sbi/sbi_domain_context.c | 2 +
> lib/sbi/sbi_fifo.c | 11 ++-
> lib/sbi/sbi_heap.c | 25 +++---
> lib/sbi/sbi_scratch.c | 3 +-
> lib/sbi/sbi_sse.c | 89 ++++++++++------------
> lib/sbi/sbi_timer.c | 5 +-
> lib/sbi/tests/riscv_locks_test.c | 3 +
> lib/utils/mailbox/fdt_mailbox_rpmi_shmem.c | 14 ++--
> lib/utils/sys/htif.c | 28 ++++---
> 16 files changed, 140 insertions(+), 95 deletions(-)
>
>
> base-commit: 3593a5facc4c6938b90429a6973ba9ee21fc5899
> --
> 2.51.0
>
>
> --
> opensbi mailing list
> opensbi at lists.infradead.org
> http://lists.infradead.org/mailman/listinfo/opensbi
LGTM.
Reviewed-by: Anup Patel <anup at brainfault.org>
Applied this patch to the riscv/opensbi repo.
Thanks,
Anup
More information about the opensbi
mailing list