<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Fault-Tolerance on tzimmermann dot org</title>
    <link>https://tzimmermann.org/tags/fault-tolerance/</link>
    <description>Recent content in Fault-Tolerance on tzimmermann dot org</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <managingEditor>blog@tzimmermann.org (Thomas Zimmermann)</managingEditor>
    <webMaster>blog@tzimmermann.org (Thomas Zimmermann)</webMaster>
    <lastBuildDate>Fri, 21 Jul 2017 11:00:00 +0200</lastBuildDate>
    
	<atom:link href="https://tzimmermann.org/tags/fault-tolerance/index.xml" rel="self" type="application/rss+xml" />
    
    
    
    <item>
      <title>Switching to Hugo</title>
      <link>https://tzimmermann.org/2026/09/30/switching-to-hugo/</link>
      <pubDate>Wed, 30 Sep 2026 18:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2026/09/30/switching-to-hugo/</guid>
      <description>&lt;p&gt;This blog has been dormant since I joined SUSE 8 years ago, although I
wanted to get back to blogging for quite some time. After changing jobs,
at first I simply had too much other tasks to take care of. Later when
things settled down a bit, my Jekyll installation was obsolete to a point
that it wasn&amp;rsquo;t usable any longer.&lt;/p&gt;
&lt;p&gt;Jekyll has always been a bit of pain to work with. Any updates to the
Ruby installation risked breaking some of Jekyll&amp;rsquo;s dependencies. Any updates
to the system risked breaking Ruby itself. Whenever I tried to come back
to writing, I found something was not working in my Jekyll installation.
Most recently, Ruby&amp;rsquo;s Bundler installer either failed to set up a user-local
installation or wanted to mess around with my Linux&amp;rsquo; system libraries.
Building Ruby&amp;rsquo;s BigDecimal module didn&amp;rsquo;t work at all. So it appeared as if
I&amp;rsquo;d have to move up from mere user to Ruby developer to keep using Jekyll.&lt;/p&gt;
&lt;p&gt;As this was not an option, I decided to convert the site to another
generator. &lt;a href=&#34;https://jamstack.org/generators/&#34;&gt;There are plenty&lt;/a&gt; to choose from and
&lt;a href=&#34;https://gohugo.io/&#34;&gt;Hugo&lt;/a&gt; seemed like a good choice. It is light-weight and supports
Markdown for writing. In contrast to Jekyll, it appears to be a single
core program with less fragile dependencies.&lt;/p&gt;
&lt;p&gt;The conversion still was painful. Hugo&amp;rsquo;s documentation is there; to put
it in friendly terms. I found it, however, insufficient for beginners.
It took me literally hours to figure how to make links work correctly or
how to get data onto the final website. (Data goes into static/, not assets/.)
I found the book &lt;a href=&#34;https://pkg.yihui.org/blogdown/&#34;&gt;blogdown&lt;/a&gt; by Xie, Thomas and Hill really
helpful. The authors seem to considers it out-of-date, but it was still
the best guide I could find. When setting up the site&amp;rsquo;s Atom feed, I loosely
followed the description at &lt;a href=&#34;https://dmvrtx.me/2023/06/hugo-atom-feed/&#34;&gt;dmvrtx.me&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;After getting through the initial learning curve, things got better. I
had to fix up the permalinks, adapt some of the syntax and do little changes
here and there. It was also a good opportunity to weed out the last remaining
JS scripts and external resources. The website should now be self-contained.&lt;/p&gt;
&lt;p&gt;For the theme, I forked from &lt;a href=&#34;https://github.com/LukasJoswiak/etch/tree/b304186c260f574d281a495f5ceb4d8ac382cbe5&#34;&gt;Etch&lt;/a&gt; by Lukas Joswiak and
applied significant modifications to page layout, fonts and page features.
The original Etch is available under MIT license.&lt;/p&gt;
&lt;p&gt;With everything in place, the resulting website is quite nice, I think. Hopefully
I get back to blogging more often.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Safe Integer Conversion in C</title>
      <link>https://tzimmermann.org/2018/04/20/safe-integer-conversion-in-c/</link>
      <pubDate>Fri, 20 Apr 2018 15:30:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2018/04/20/safe-integer-conversion-in-c/</guid>
      <description>&lt;p&gt;Integer conversion is tricky and error prone. When converting from a larger
type to a smaller type, overflows and underflows can happen. For conversion
of signed values, the rules are often obscure and the compiler seems to
perform some &lt;em&gt;dark magic&lt;/em&gt; in the background.&lt;/p&gt;
&lt;p&gt;In this post, we&amp;rsquo;ll looks at the situation in C and develop a general
function to cover all the corner cases. The type-conversion feature is
part of &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt; 0.11 and later, which also covers integration
with larger software applications.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;There are two central problems in integer type conversion. The first are
conversions from types with wider range (i.e., more bits) to types with
smaller range (i.e., less bits). Here we have to be careful to not overflow
or underflow the result type.&lt;/p&gt;
&lt;p&gt;The second problem is the conversion from signed values (i.e., negative
numbers) to unsigned types, which cannot represent signs. To compare signed
and unsigned types, the C compiler performs some &lt;em&gt;interpretation&lt;/em&gt; of the
values, which can lead to surprising results.&lt;/p&gt;
&lt;h4 id=&#34;case-1-unsigned-to-unsigned&#34;&gt;Case 1: Unsigned to Unsigned&lt;/h4&gt;
&lt;p&gt;Let&amp;rsquo;s start with something simple. Let&amp;rsquo;s cast a value of type
&lt;code&gt;unsigned short&lt;/code&gt; to &lt;code&gt;unsigned char&lt;/code&gt;. In our example, the former type contains
16 bit, the latter contains 8 bit.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;short&lt;/span&gt; val_u16 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; val_u8 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;)val_u16;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;With a value of &lt;em&gt;1,&lt;/em&gt; this works well. Let&amp;rsquo;s try with a different number.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;short&lt;/span&gt; val_u16 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;456&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; val_u8 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;)val_u16;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;As &lt;code&gt;unsigned char&lt;/code&gt; can only represent values ranging from 0 to 255,
the casting operation cannot give a correct result. Thus we test this case
and report an error accordingly.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;short&lt;/span&gt; val_u16 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;456&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; val_u8;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (val_u16 &lt;span style=&#34;color:#f92672&#34;&gt;&amp;gt;&lt;/span&gt; UCHAR_MAX) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;report_error_and_abort&lt;/span&gt;(EDOM);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    val_u8 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;)val_u16;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Our test checks the value stored in &lt;code&gt;val_u16&lt;/code&gt; against the constant
&lt;code&gt;UCHAR_MAX&lt;/code&gt;, which represents the maximum value that a variable of
type &lt;code&gt;unsigned char&lt;/code&gt; can store. If the test fails, we stop and report
a domain error with the errno code of &lt;code&gt;EDOM&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The function &lt;code&gt;report_error_and_abort()&lt;/code&gt; is provided by the application.
&lt;code&gt;EDOM&lt;/code&gt; is defined in the C standard header &lt;code&gt;&amp;lt;errno.h&amp;gt;&lt;/code&gt;, &lt;code&gt;UCHAR_MAX&lt;/code&gt; is
defined in &lt;code&gt;&amp;lt;limits.h&amp;gt;&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;All our unsigned-to-unsigned conversions can be performed this way:
test against the upper limit of the result type and abort if the
test fails.&lt;/p&gt;
&lt;h5 id=&#34;conversion-ranks&#34;&gt;Conversion Ranks&lt;/h5&gt;
&lt;p&gt;There&amp;rsquo;s one question though: why does this test work? In
&lt;code&gt;val_u16 &amp;gt; UCHAR_MAX&lt;/code&gt;, we compare the value of a 16-bit type and the
value of an 8-bit type. Why does the compiler know how to perform the
comparision?&lt;/p&gt;
&lt;p&gt;To perform the &lt;em&gt;greater-than&lt;/em&gt; operation in the test, the compiler has
to convert both operands to the same type. This controlled by the
types&amp;rsquo; conversion ranks. The &lt;em&gt;conversion rank&lt;/em&gt; is a property
of each type in C. It specifies the implicit conversions during
operations, such as the &lt;em&gt;&amp;gt;&lt;/em&gt; in our test.&lt;/p&gt;
&lt;p&gt;Each type has it&amp;rsquo;s own rank, which it only shares with its corresponding
signed or unsigned type. The ranks are ordered in the following way:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;_Bool&lt;/code&gt; &amp;lt; &lt;code&gt;unsigned char&lt;/code&gt; &amp;lt; &lt;code&gt;unsigned short&lt;/code&gt; &amp;lt; &lt;code&gt;unsigned int&lt;/code&gt; &amp;lt; &lt;code&gt;unsigned long&lt;/code&gt; &amp;lt; &lt;code&gt;unsigned long long&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;If an operation receives two operands with different conversion ranks,
the compiler first generates code to that converts the operand with
the lesser rank to the type with the higher rank. The resulting temporary
value is then used for the operation.&lt;/p&gt;
&lt;p&gt;This implicit conversion works because of the way the C types are defined.
Larger types always cover the complete range of smaller types:
&lt;code&gt;unsigned short&lt;/code&gt; covers the complete range of &lt;code&gt;unsigned char&lt;/code&gt;,
&lt;code&gt;unsigned int&lt;/code&gt; covers the complete range of &lt;code&gt;unsigned short&lt;/code&gt;, and so on.
Converting from a lower-rank type to a higher-rank type is therefore safe.&lt;/p&gt;
&lt;p&gt;Coming back to our example, the C compiler first converts the value
of &lt;code&gt;UCHAR_MAX&lt;/code&gt; from &lt;code&gt;unsigned char&lt;/code&gt; to &lt;code&gt;unsigned short&lt;/code&gt;, and then
performs the test with the intermediate value.&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;h4 id=&#34;case-2-signed-to-signed&#34;&gt;Case 2: Signed to Signed&lt;/h4&gt;
&lt;p&gt;Conversions among unsigned types are simple. Luckily, the same rules
apply to &lt;em&gt;signed&lt;/em&gt; types as well. Conversion ranks among signed types are the
same as for their unsigned counterparts. This means, we can do the same
test for the upper limit of the result type as in the case of &lt;em&gt;unsigned.&lt;/em&gt;&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;short&lt;/span&gt; val_s16 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;456&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;signed&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; val_s8;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (val_s16 &lt;span style=&#34;color:#f92672&#34;&gt;&amp;gt;&lt;/span&gt; SCHAR_MAX) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;report_error_and_abort&lt;/span&gt;(EDOM);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    val_s8 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;signed&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;)val_s16;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The constant &lt;code&gt;SCHAR_MAX&lt;/code&gt; holds the maximum value of &lt;code&gt;signed char&lt;/code&gt;. For
historical reasons, the type &lt;code&gt;char&lt;/code&gt; can be signed or unsigned; so it&amp;rsquo;s
best to avoid it here in favor of an explicit &lt;code&gt;signed char&lt;/code&gt; or
&lt;code&gt;unsigned char&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;With signed types, we can have negative numbers. The minimum value of
a signed type is stored in a constant named something like &lt;code&gt;&amp;lt;type&amp;gt;_MIN&lt;/code&gt;.
For &lt;code&gt;signed char&lt;/code&gt; this is &lt;code&gt;SCHAR_MIN&lt;/code&gt;. To cover cases where a value is
too low for the result type, we have to extend our test a bit.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;short&lt;/span&gt; val_s16 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;456&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;signed&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; val_s8;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (val_s16 &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; SCHAR_MIN) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;report_error_and_abort&lt;/span&gt;(EDOM);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (val_s16 &lt;span style=&#34;color:#f92672&#34;&gt;&amp;gt;&lt;/span&gt; SCHAR_MAX) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;report_error_and_abort&lt;/span&gt;(EDOM);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    val_s8 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;signed&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;)val_s16;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We&amp;rsquo;re now also testing against &lt;code&gt;SCHAR_MIN&lt;/code&gt;, but the overall logic remains
the same.&lt;/p&gt;
&lt;h4 id=&#34;case-3-unsigned-to-signed&#34;&gt;Case 3: Unsigned to Signed&lt;/h4&gt;
&lt;p&gt;In the case of an converting a value from an unsigned type to a signed
type, we have to make sure that the result is not larger than the maximum
value of the signed type. Our previous code already covers these cases.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;short&lt;/span&gt; val_u16 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;456&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;signed&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; val_s8;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (val_u16 &lt;span style=&#34;color:#f92672&#34;&gt;&amp;gt;&lt;/span&gt; SCHAR_MAX) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;report_error_and_abort&lt;/span&gt;(EDOM);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    val_s8 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;signed&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;)val_u16;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;There&amp;rsquo;s really not much difference to the unsigned-to-unsigned case. The
C compiler converts the constant &lt;code&gt;SCHAR_MAX&lt;/code&gt; to &lt;code&gt;unsigned short&lt;/code&gt; for
comparing it to &lt;code&gt;val_u16&lt;/code&gt;. Because &lt;em&gt;chars&lt;/em&gt; are never larger than &lt;em&gt;shorts&lt;/em&gt;
the temporary value is always representable by &lt;code&gt;unsigned short&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;However, if we compile such code, we might get a compiler warning about
mixing signed and unsigned values in the test&amp;rsquo;s condition. This requires
a closer look at how signed and unsigned types are compared.&lt;/p&gt;
&lt;h3 id=&#34;case-4-signed-to-unsigned&#34;&gt;Case 4: Signed to Unsigned&lt;/h3&gt;
&lt;p&gt;Comparing signed and unsigned values is tricky, because unsigned types
cannot represent negative values. Let&amp;rsquo;s take the following example.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;short&lt;/span&gt; val_s16 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; val_u8;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (val_s16 &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0ull&lt;/span&gt;) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;report_error_and_abort&lt;/span&gt;(EDOM);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (val_s16 &lt;span style=&#34;color:#f92672&#34;&gt;&amp;gt;&lt;/span&gt; UCHAR_MAX) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;report_error_and_abort&lt;/span&gt;(EDOM);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    val_u8 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;)val_s16;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Here we compare a signed 16-bit value against &lt;em&gt;0ull&lt;/em&gt; and &lt;code&gt;UCHAR_MAX&lt;/code&gt;,
which are both unsigned. If we&amp;rsquo;d compile and run this code, we&amp;rsquo;d be
surprised by the fact that both tests succeed and that the result
value of &lt;code&gt;val_u8&lt;/code&gt; is &lt;em&gt;255.&lt;/em&gt; We would have expected the first test
to fail.&lt;/p&gt;
&lt;p&gt;The exact rules for comparing signed and unsigned types in C are
complex, but generally speaking, the compiler picks the operand type
with the highest rank, converts both operands to the unsigned
version of this type, and finally compares these intermediate unsigned
operands.&lt;/p&gt;
&lt;p&gt;In the first test, &lt;em&gt;0ull&lt;/em&gt; is of type &lt;code&gt;unsigned long long&lt;/code&gt;, which has
a higher rank than &lt;code&gt;short&lt;/code&gt;. So the compiler converts the value of
&lt;code&gt;val_s16&lt;/code&gt; to &lt;code&gt;long long&lt;/code&gt; &lt;em&gt;and&lt;/em&gt; interprets the resulting bits as
&lt;code&gt;unsigned long long&lt;/code&gt;. When stored as &lt;code&gt;long long&lt;/code&gt;, the bit pattern of &lt;em&gt;-1&lt;/em&gt; is
&lt;em&gt;11111111 11111111 11111111 11111111 11111111 11111111 11111111 11111111,&lt;/em&gt;
assuming 64-bit &lt;code&gt;long long&lt;/code&gt; values. Interpreting this bit pattern as
unsigned gives a value of &lt;em&gt;2&lt;sup&gt;64&lt;/sup&gt;-1.&lt;/em&gt; And suddenly &lt;em&gt;-1&lt;/em&gt; is larger
than &lt;em&gt;0.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;We can fix this problem by comparing against &lt;em&gt;0ll&lt;/em&gt;, a signed zero,
in the first test.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;short&lt;/span&gt; val_s16 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; val_u8;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (val_s16 &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0ll&lt;/span&gt;) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;report_error_and_abort&lt;/span&gt;(EDOM);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (val_s16 &lt;span style=&#34;color:#f92672&#34;&gt;&amp;gt;&lt;/span&gt; UCHAR_MAX) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;report_error_and_abort&lt;/span&gt;(EDOM);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    val_u8 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;)val_s16;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The first test is now a signed-to-signed conversion, which is always
safe to perform. The second test is also safe to perform, as the
range of &lt;code&gt;short&lt;/code&gt; can represent &lt;code&gt;UCHAR_MAX&lt;/code&gt;.&lt;/p&gt;
&lt;h4 id=&#34;putting-it-all-together&#34;&gt;Putting It All Together&lt;/h4&gt;
&lt;p&gt;Ideally, we&amp;rsquo;d have a single function for each conversion, something like
&lt;code&gt;cast_int_to_ushort()&lt;/code&gt;, &lt;code&gt;cast_char_to_int()&lt;/code&gt;, &lt;code&gt;cast_long_to_bool()&lt;/code&gt; and so
on. Even better, if we could have a generator macro that creates these
functions for us.&lt;/p&gt;
&lt;p&gt;The blog post is getting rather long already, so please forgive that I&amp;rsquo;m
not going to explain all the details of how to do this. Rather, I&amp;rsquo;d like
to point you to the &lt;a href=&#34;http://github.com/picotm/picotm/blob/master/modules/cast/include/picotm/picotm-cast.h#L66&#34;&gt;picotm source code&lt;/a&gt;, which
contains exactly this.&lt;/p&gt;
&lt;p&gt;The C pre-processor macro &lt;code&gt;PICOTM_CAST_TX()&lt;/code&gt; generates conversion functions
from one C type to another C type. For example, running&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;PICOTM_CAST_TX&lt;/span&gt;(uint, &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;, &lt;span style=&#34;color:#66d9ef&#34;&gt;short&lt;/span&gt;, &lt;span style=&#34;color:#66d9ef&#34;&gt;short&lt;/span&gt;, SHRT_MAX, SHORT_MIN)
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;produces&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;inline&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;short&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;cast_uint_to_short_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; value);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;which safely casts any value of type &lt;code&gt;unsigned int&lt;/code&gt; to type &lt;code&gt;short&lt;/code&gt;. The
function detects the signess of the input and result types, makes sure that
it&amp;rsquo;s not comparing values of signed and unsigned types in the wrong places,
and reports errors.&lt;/p&gt;
&lt;p&gt;A lot of the analysis depends on the involved types and can be done by
the C compiler while building the program. An optimizing compiler can easily
eliminate most of the cases. For example, if both types have the same
signess, all the cases for handling differences in signess are removed.&lt;/p&gt;
&lt;p&gt;As picotm provides system-level transactions for safe and reliable
programming, errors are reported to the picotm transaction manager, which
will roll-back the transaction and run the error-recovery code. But this is
entirely separated and unrelated to the type conversion.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we&amp;rsquo;ve looked at the different cases of converting
integer types among each other. This includes&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;unsigned to unsigned,&lt;/li&gt;
&lt;li&gt;signed to signed,&lt;/li&gt;
&lt;li&gt;unsigned to signed, and&lt;/li&gt;
&lt;li&gt;signed to unsigned.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There are a lot of corner cases and the blog post covers all of the tricky
parts. Finally, we&amp;rsquo;ve seen a generator macro that creates conversion
functions during the C compiler&amp;rsquo;s pre-processing stage. Using such a macro,
a large number of safe type-casting functions can be created easily.&lt;/p&gt;
&lt;p&gt;If you like this blog post, please subscribe to the RSS feed, follow on
Twitter or share on social networks.&lt;/p&gt;
&lt;h4 id=&#34;footnotes&#34;&gt;Footnotes&lt;/h4&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;C compilers don&amp;rsquo;t have to follow this procedure step-by-step. A
compiler is allowed to optimize the code as long as the result is
the same as in the non-optimized variant.&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</description>
    </item>
    
    
    
    <item>
      <title>System-Level Transactions with picotm</title>
      <link>https://tzimmermann.org/2018/02/12/system-level-transactions-with-picotm/</link>
      <pubDate>Mon, 12 Feb 2018 11:00:00 +0100</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2018/02/12/system-level-transactions-with-picotm/</guid>
      <description>&lt;p&gt;I&amp;rsquo;ll speak about &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt; at this year&amp;rsquo;s
&lt;a href=&#34;https://chemnitzer.linux-tage.de/2018/de/programm/beitrag/203&#34;&gt;Chemnitzer Linux-Tage&lt;/a&gt;. The conference committee asks
each presenter to submit a shortpaper containing an overview of the
presentation&amp;rsquo;s content. Now that I have this nice single-page overview
of picotm, I decided to post a cleaned-up version here in my blog. A
&lt;a href=&#34;https://tzimmermann.org/pubs/picotm-shortpaper20180212.pdf&#34;&gt;PDF&lt;/a&gt; of the text is also available.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;h4 id=&#34;the-problems-with-traditional-code&#34;&gt;The Problems with Traditional Code&lt;/h4&gt;
&lt;p&gt;Our goal is to write software that works reliably under all circumstances.
Besides correctness at the algorithmic level, this requires
correct handling of concurrency and run-time errors. Both are notoriously
hard to test and implement.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd0, fd1; &lt;span style=&#34;color:#75715e&#34;&gt;/* file descriptors */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; obuf[&lt;span style=&#34;color:#ae81ff&#34;&gt;100&lt;/span&gt;]; &lt;span style=&#34;color:#75715e&#34;&gt;/* output buffer */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;write&lt;/span&gt;(fd0, obuf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(obuf));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;write&lt;/span&gt;(fd1, obuf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(obuf));
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This example program writes an output buffer to two files. If the first
&lt;code&gt;write()&lt;/code&gt; operation succeeds but the second fails, only one file will
be updated and the program will enter an inconsistent, and probably erroneous,
state. Correctly returning to the previous consistent state will become
impossible at this point. If there&amp;rsquo;s concurrent access to the files, the
program&amp;rsquo;s result will become unpredictable. Similar examples can be
constructed for memory access, data structures, or any other non-constant
resource.&lt;/p&gt;
&lt;h4 id=&#34;transactional-execution&#34;&gt;Transactional Execution&lt;/h4&gt;
&lt;p&gt;A &lt;em&gt;transaction&lt;/em&gt; is a transition from one consistent state to another
consistent state; without the intermediate steps being visible outside of the
transaction&amp;rsquo;s context. This is known as the ACID properties &lt;em&gt;atomicity,&lt;/em&gt;
&lt;em&gt;consistency,&lt;/em&gt; &lt;em&gt;isolation&lt;/em&gt; and &lt;em&gt;durability.&lt;/em&gt; To achieve ACID
properties, a transaction has to handle run-time errors and concurrency of
its contained operations; exactly those pieces of the software that we just
identified as being problematic.&lt;/p&gt;
&lt;h4 id=&#34;phases-of-each-operation&#34;&gt;Phases of each Operation&lt;/h4&gt;
&lt;p&gt;Most operations, such as &lt;code&gt;write()&lt;/code&gt;, can be split into different
phases. We call them &lt;em&gt;execute,&lt;/em&gt; &lt;em&gt;apply&lt;/em&gt; and &lt;em&gt;undo.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;When first called, an operation enters the execute phase, where it allocates
resources, acquires locks and checks for potential run-time errors. If
successful, the operation will enter the apply phase where its effects become
globally visible. If unsuccessful, the operation will enter the undo phase,
where all setup from the execute phase is reverted.&lt;/p&gt;
&lt;p&gt;For &lt;em&gt;n&lt;/em&gt; operations in a row, phases can be rearranged. First we
perform all execute phases &lt;em&gt;e_1,&lt;/em&gt; &lt;em&gt;e_2,&lt;/em&gt; &amp;hellip; &lt;em&gt;e_n.&lt;/em&gt; If successful, we will
perform all apply phases &lt;em&gt;a_1,&lt;/em&gt; &lt;em&gt;a_2,&lt;/em&gt; &amp;hellip; &lt;em&gt;a_n.&lt;/em&gt; In unsuccessful, we will
revert execution with the undo phases &lt;em&gt;u_n,&lt;/em&gt; &amp;hellip; &lt;em&gt;u_2,&lt;/em&gt; &lt;em&gt;u_1.&lt;/em&gt; This scheme
allows us to compose transactions from arbitrary operations.&lt;/p&gt;
&lt;h4 id=&#34;system-level-transactions-with-picotm&#34;&gt;System-Level Transactions with picotm&lt;/h4&gt;
&lt;p&gt;&lt;em&gt;picotm&lt;/em&gt; is a system-level transaction manager implemented in highly
portable C. It provides a generic framework to formalize the
execute-apply-undo scheme and to integrate a large number of different modules
and interfaces. All concurrency control and error detection is performed
internally, users only have to implement application-specific algorithms
and error recovery.&lt;/p&gt;
&lt;p&gt;Re-implementing the example program puts all execute phases between
&lt;code&gt;picotm_begin&lt;/code&gt; and &lt;code&gt;picotm_commit&lt;/code&gt;. Note each operation&amp;rsquo;s
&lt;code&gt;_tx&lt;/code&gt; suffix.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  &lt;span style=&#34;color:#75715e&#34;&gt;/* execution phase */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  &lt;span style=&#34;color:#a6e22e&#34;&gt;write_tx&lt;/span&gt;(fd0, obuf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(obuf));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  &lt;span style=&#34;color:#a6e22e&#34;&gt;write_tx&lt;/span&gt;(fd1, obuf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(obuf));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;picotm_commit &lt;span style=&#34;color:#75715e&#34;&gt;/* apply during commit */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  &lt;span style=&#34;color:#75715e&#34;&gt;/* recovery phase */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  &lt;span style=&#34;color:#a6e22e&#34;&gt;put_error_recovery_here&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;  &lt;span style=&#34;color:#a6e22e&#34;&gt;picotm_restart&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Execute phases perform concurrency control and error detection
internally. Each operation&amp;rsquo;s apply phase is performed by
&lt;code&gt;picotm_commit&lt;/code&gt;. Until commit, all changes are local and can be
reverted via the corresponding undo phase. After reverting from a detected
error, the transaction enters the recovery phase where the application
can attempt to repair the error and restart the transaction.&lt;/p&gt;
&lt;h4 id=&#34;picotm-modules&#34;&gt;picotm Modules&lt;/h4&gt;
&lt;p&gt;The picotm core library provides the building blocks for generic error
handing and concurrency control. On top of these primitives, users can
implement modules for their specific use case and application.
Out of the box, picotm comes with a large set of available modules, such as&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Software Transactional Memory: Transactional access to shared memory&lt;/li&gt;
&lt;li&gt;Data structures: Implements transactional lists, queues, multisets, stacks&lt;/li&gt;
&lt;li&gt;Memory management: Provides transaction-safe C memory allocation with
&lt;code&gt;malloc()&lt;/code&gt;, &lt;code&gt;free()&lt;/code&gt;, et al.&lt;/li&gt;
&lt;li&gt;C string and memory operations: Provides C Standard Library functions that
operate on transactional memory, such as &lt;code&gt;memset()&lt;/code&gt;, &lt;code&gt;strcpy()&lt;/code&gt;, et al.&lt;/li&gt;
&lt;li&gt;File-descriptor I/O: Offers transaction-safe access to files and file-like
structures on P&lt;small&gt;OSIX&lt;/small&gt; systems, with functions such as
&lt;code&gt;open()&lt;/code&gt;, &lt;code&gt;close()&lt;/code&gt;, &lt;code&gt;read()&lt;/code&gt;, &lt;code&gt;write()&lt;/code&gt;, et al.&lt;/li&gt;
&lt;li&gt;C math functions: Transactional &lt;code&gt;tan()&lt;/code&gt;, &lt;code&gt;sqrt()&lt;/code&gt;, et al.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;All available modules co-operate and can be mixed freely. More modules are
planned and will be added over time.&lt;/p&gt;
&lt;h4 id=&#34;obtaining-picotm&#34;&gt;Obtaining picotm&lt;/h4&gt;
&lt;p&gt;picotm is available at &lt;a href=&#34;http://picotm.org/&#34;&gt;http://picotm.org&lt;/a&gt;. It&amp;rsquo;s
implemented in plain C and currently supports Linux, MacOS X, Windows
(Cygwin) and FreeBSD. More systems are planned. The source code is
distributed under the terms of the &lt;a href=&#34;http://opensource.org/licenses/MIT&#34;&gt;MIT license&lt;/a&gt;.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>A picotm Demo Application</title>
      <link>https://tzimmermann.org/2018/01/12/a-picotm-demo-application/</link>
      <pubDate>Fri, 12 Jan 2018 10:00:00 +0100</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2018/01/12/a-picotm-demo-application/</guid>
      <description>&lt;p&gt;Happy new near to you! I spent the first week of 2018 on writing a &lt;a href=&#34;http://github.com/picotm/picotm-demo&#34;&gt;demo
application&lt;/a&gt; for &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt;. The intention is to show
what picotm has to offer and how system-level transactions work in a real
program. In this blog post we&amp;rsquo;ll go through it and see what it does.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;The demo application reads random data from Linux, puts it into several
memory buffers, and visualizes the buffers&amp;rsquo; content on screen. This is
split among multiple threads, which segment the application into three major
parts: an input thread, a number of processing threads, and a (text-mode)
visualization thread.&lt;/p&gt;
&lt;p&gt;As much as possible, this functionality is implemented using picotm
transactions. All the shown transaction functionality is part of picotm and
ready to use out-of-the-box.&lt;/p&gt;
&lt;p&gt;But let&amp;rsquo;s start with a screen shot. At first, all buffers are empty.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;demo1.png&#34; alt=&#34;All application buffers are empty at first.&#34;&gt;&lt;/p&gt;
&lt;h4 id=&#34;the-input-thread&#34;&gt;The Input Thread&lt;/h4&gt;
&lt;p&gt;First of all there&amp;rsquo;s an input thread that periodically reads data from
the operating system. It does so by opening &lt;code&gt;/dev/urandom&lt;/code&gt; and calling
&lt;code&gt;read()&lt;/code&gt; on it once per second.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s the opening code. It imports the filename into the transaction,
opens the file and exports a file descriptor from the transaction to
main memory.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;open_input_file&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; filename)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// Privatize the memory of the argument and filename
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;privatize_c_tx&lt;/span&gt;(filename, &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#39;\0&amp;#39;&lt;/span&gt;, PICOTM_TM_PRIVATIZE_LOAD);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// Open input file
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; tx_fd &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;open_tx&lt;/span&gt;(filename, O_RDONLY);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// Export the file descriptor from the transaction
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;fd, tx_fd);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; res &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;recover_from_tx_error&lt;/span&gt;(__FILE__, __LINE__);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;picotm_restart&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; fd;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Remember that we don&amp;rsquo;t require error detection in transactional code. This
is done fully automatically by the transaction framework. If anything goes
wrong, the framework rolls back the transaction and jumps to the recovery
code that sits between the commit and end statements. From there, we can try
to repair the error and restart the transaction.&lt;/p&gt;
&lt;p&gt;Next is the reading code. Again it&amp;rsquo;s implemented as a transaction.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; queue_entry {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txqueue_entry entry;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; hdr msg;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;};
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; queue_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;read_file&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; queue_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; entry;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; queue_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; tx_entry &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;entry));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// Read message header from input stream. The value of `fd` is a
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// constant on the stack; no need to load or privatize. The first
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// 4 byte are considered meta data.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;read_tx&lt;/span&gt;(fd, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;tx_entry&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;msg, &lt;span style=&#34;color:#ae81ff&#34;&gt;4&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// Read data into buffer. With `read_tx()` the buffer `msg.buf` is
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// automatically privatized by the TM module.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;read_tx&lt;/span&gt;(fd, tx_entry&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;msg.buf, tx_entry&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;msg.len);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// Export message from transaction context.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;store_ptr_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;entry, tx_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; res &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;recover_from_tx_error&lt;/span&gt;(__FILE__, __LINE__);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; NULL;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;picotm_restart&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; entry;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Not trying to bore you with details, this transaction allocates a message
structure named &lt;code&gt;queue&lt;/code&gt;, reads the random data into the structure, and exports
it from the transactional context. Again, if anything goes wrong, the
transaction framework detects the error for us and goes to recovery. Because
transactions cleanly separate the error detection from the recovery, we
can re-use the &lt;em&gt;exact&lt;/em&gt; recovery code from the opening transaction.&lt;/p&gt;
&lt;p&gt;We now have a packet containing random data. Each data packet is forwarded
to one of multiple processing threads. The forwarding transaction is
trivial (as it should be).&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txqueue&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; queue &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txqueue_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;q&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;queue);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;txqueue_push_tx&lt;/span&gt;(queue, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;entry&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; res &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;recover_from_tx_error&lt;/span&gt;(__FILE__, __LINE__);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; out;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;picotm_restart&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The variable named &lt;code&gt;entry&lt;/code&gt; is the data packet we just created, the variable
named &lt;code&gt;queue&lt;/code&gt; is a transactional queue that connects the input thread with a
processing thread.&lt;/p&gt;
&lt;h4 id=&#34;the-processing-threads&#34;&gt;The Processing Threads&lt;/h4&gt;
&lt;p&gt;Processing threads receive data from the input thread for further
processing. Each maintains an in-memory buffer, where it stores the
received data.&lt;/p&gt;
&lt;p&gt;The following code removes the input thread&amp;rsquo;s data packet from the
transactional queue. This is the ownership hand-over step of the data and the
memory accociated with it. Once the processing thread reads the packet,
it owns it.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; continue_loop;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;do&lt;/span&gt; {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    continue_loop &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// Acquire transactional queue for queue state and get
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// next message from queue.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;//
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txqueue&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; queue &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txqueue_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;q&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;queue);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#a6e22e&#34;&gt;txqueue_empty_tx&lt;/span&gt;(queue)) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; commit;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; queue_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; entry &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;queue_entry_of_txqueue_entry_tx&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;txqueue_front_tx&lt;/span&gt;(queue));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// Copy message buffer into correct field and fill trailing
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// bytes with 0.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;//
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; field &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; buf&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;field[entry&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;msg.off];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;memcpy_tx&lt;/span&gt;(field, entry&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;msg.buf, entry&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;msg.len);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;memset_tx&lt;/span&gt;(field &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; entry&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;msg.len, &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;256&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-&lt;/span&gt; entry&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;msg.len);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// Remove message from queue and free memory.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;//
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txqueue_pop_tx&lt;/span&gt;(queue);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;free_tx&lt;/span&gt;(entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// Continue loop until queue runs empty
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;store__Bool_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;continue_loop, true);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    commit:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; res &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;recover_from_tx_error&lt;/span&gt;(__FILE__, __LINE__);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;picotm_restart&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;} &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (continue_loop);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The data is then copied into the memory buffer &lt;code&gt;buf-&amp;gt;field&lt;/code&gt;. The processing
thread doesn&amp;rsquo;t really do much processing, but could in a real-world
application. The transaction applies Transactional Memory for the copy
operation (i.e., &lt;code&gt;memcpy_tx()&lt;/code&gt; and &lt;code&gt;memset_tx()&lt;/code&gt;). Our output thread
will therefore be able to read the buffer content without interfering
with the processing.&lt;/p&gt;
&lt;p&gt;In the final step, the transaction removes the data packet from the
transactional queue and frees its memory.&lt;/p&gt;
&lt;p&gt;Again, you can see how we reuse the error recovery. Recovery strategies
hardly change within an application, so the recovery code should be
separate from the error detection.&lt;/p&gt;
&lt;p&gt;At this point, we have received data from an input source forwarded it
to another thread, processed it, and stored the results in main memory. A
fairly common pattern in most applications.&lt;/p&gt;
&lt;h4 id=&#34;the-output-thread&#34;&gt;The Output Thread&lt;/h4&gt;
&lt;p&gt;The output thread, actually the application&amp;rsquo;s main thread, visualizes the
buffer content. It periodically reads from each buffer and reduces the
buffer&amp;rsquo;s content to a string of hexadecimal numbers. These strings are then
displayed on the screen.&lt;/p&gt;
&lt;p&gt;Just as in the case of the processing thread, access to each buffer is
performed using Transactional Memory. Conflicts among output and processing
threads are resolved automatically. Over time each buffer fills with content;
a process that the user can follow by watching the screen. After a while the
application buffers contain data.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;demo2.png&#34; alt=&#34;After a while the application buffers contain data.&#34;&gt;&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we&amp;rsquo;ve looked picotm&amp;rsquo;s demo application.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The demo application reads random data into memory buffers and
visualizes the buffers&amp;rsquo; content on the screen.&lt;/li&gt;
&lt;li&gt;Input, processing and visualization is performed on different
threads.&lt;/li&gt;
&lt;li&gt;Transactional code is employed for communication among threads
and detecting errors.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The full source code for the demo is available in a
&lt;a href=&#34;http://github.com/picotm/picotm-demo&#34;&gt;git repository&lt;/a&gt; on GitHub.&lt;/p&gt;
&lt;p&gt;If you like this blog post, please subscribe to the RSS feed, follow on
Twitter or share on social networks.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Porting picotm to Mac OS, Windows and FreeBSD</title>
      <link>https://tzimmermann.org/2017/12/15/porting-picotm-to-mac-os-windows-and-freebsd/</link>
      <pubDate>Fri, 15 Dec 2017 12:30:00 +0100</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/12/15/porting-picotm-to-mac-os-windows-and-freebsd/</guid>
      <description>&lt;p&gt;I spent the previous weeks on porting &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt; from Linux to a
number of other operating systems. Ports to Mac OS X, Windows and
FreeBSD will be available in picotm&amp;rsquo;s next release. in this blog post
we go through them one by one and look at the major points and pitfalls.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;In it&amp;rsquo;s current release, picotm, the system-level transaction manager,
only runs on Linux systems. Supporting more operating systems was high
on my &lt;em&gt;TODO&lt;/em&gt; list for quite a while. During the previous weeks I finally
got to work on ports to Mac OS, Windows and FreeBSD.&lt;/p&gt;
&lt;p&gt;Picotm provides transactional semantics (i.e., automatic locking and
error handling) for a large set of low-level functionality, such as&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;memory operations (transactional memory),&lt;/li&gt;
&lt;li&gt;C memory and string functions (concurrent &lt;code&gt;mem*()&lt;/code&gt; and &lt;code&gt;str*()&lt;/code&gt; calls
on shared memory),&lt;/li&gt;
&lt;li&gt;memory allocation (&lt;code&gt;malloc()&lt;/code&gt; and &lt;code&gt;free()&lt;/code&gt; on shared memory),&lt;/li&gt;
&lt;li&gt;file-descriptor I/O (concurrent reading and writing within the same file),&lt;/li&gt;
&lt;li&gt;process working directory,&lt;/li&gt;
&lt;li&gt;C math functions, and&lt;/li&gt;
&lt;li&gt;transactional data structures (shared lists, multisets, etc).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;All this functionality is implemented as a set of shared libraries, built
on top of a single core library that manages all transactions in the
application. It&amp;rsquo;s all C code.&lt;/p&gt;
&lt;p&gt;The goal for each new port is to get the core transaction manager running
on the new system and then get (most of) the actual functionality working.&lt;/p&gt;
&lt;h4 id=&#34;freebsd&#34;&gt;FreeBSD&lt;/h4&gt;
&lt;p&gt;The first port was from Linux to &lt;a href=&#34;http://www.freebsd.org/&#34;&gt;FreeBSD&lt;/a&gt;. In terms of systems
programming, FreeBSD is very similar to Linux. It has the same or similar
tools and compilers. It&amp;rsquo;s a &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/&#34;&gt;POSIX&lt;/a&gt;-compatible system and supports
most of the same programming interfaces that Linux uses. For interfaces
that are missing, there&amp;rsquo;s usually a replacement with equivalent
functionality.&lt;/p&gt;
&lt;p&gt;Getting FreeBSD was really easy. The FreeBSD project even provides a complete
pre-configured disk image for virtual machines.&lt;/p&gt;
&lt;p&gt;The first thing to port was the build system. Picotm uses GNU autotools,
which are designed for portability among Unix systems. Many people love to
hate the autotools, but they are actually quite good. I resolved an
additional dependency on the &lt;code&gt;realpath&lt;/code&gt; tool by changing the affected
build scripts to work without any additional tool, so this change benefits
the original Linux build scripts as well.&lt;/p&gt;
&lt;p&gt;Next after the build system was the core transaction manager. This library
is written in C11 with dependencies on the operating system&amp;rsquo;s mutexes,
condition variables and time sources. FreeBSD comes with a recent version
of clang, which provides a good C11 compiler. As a POSIX system, FreeBSD
provides all of the required mutex, condition variables and time interfaces.
So no problems here.&lt;/p&gt;
&lt;p&gt;One major difficulty in porting picotm is the difference in supported
interfaces on each operating system. If a system provides a specific
interface, picotm tries to offer a transactional variant. If an interface
is &lt;em&gt;not&lt;/em&gt; available, picotm does to &lt;em&gt;not&lt;/em&gt; offer it. For example, on Linux
the GNU libc provides the non-standard function
&lt;a href=&#34;http://www.gnu.org/software/libc/manual/html_node/Search-Functions.html#index-rawmemchr&#34;&gt;&lt;code&gt;rawmemchr()&lt;/code&gt;&lt;/a&gt; for searching a character within a memory
buffer. Therefore picotm provides &lt;code&gt;rawmemchr_tx()&lt;/code&gt;, a transactional
variant. The C standard library on FreeBSD does not provide &lt;code&gt;rawmemchr()&lt;/code&gt;,
so picotm doesn&amp;rsquo;t provide &lt;code&gt;rawmemchr_tx()&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Supporting system-specific interfaces is easy with the GNU autotools. With
autoconf, the macro &lt;code&gt;AC_CHECK_DECL&lt;/code&gt; adds a test for the declaration of a
specific function or macro in a specific header file. In the source code
one can test for the result and change the program&amp;rsquo;s behaviour accordingly.&lt;/p&gt;
&lt;p&gt;For example, the package configuration scripts contain the following
test for &lt;code&gt;rawmemchr()&lt;/code&gt;.&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;AC_CHECK_DECL([rawmemchr],
              [AC_DEFINE([PICOTM_LIBC_HAVE_RAWMEMCHR],
                         [1],
                         [Define to one of you have rawmemchr.])],
              [],
              [@%:@include &amp;lt;string.h&amp;gt;])
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;This test searches for a declaration of &lt;code&gt;rawmemchr()&lt;/code&gt; in the header file
&lt;code&gt;&amp;lt;string.h&amp;gt;&lt;/code&gt;. If it find the declaration, it defines the C pre-processor
token &lt;code&gt;PICOTM_LIBC_HAVE_RAWMEMCHR&lt;/code&gt; to &lt;code&gt;1&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;In the picotm source code, we can do a test and only provide a transactional
implementation if &lt;code&gt;PICOTM_LIBC_HAVE_RAWMEMCHR&lt;/code&gt; is defined to &lt;code&gt;1&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#if defined(PICOTM_LIBC_HAVE_RAWMEMCHR) &amp;amp;&amp;amp; PICOTM_HAVE_RAWMEMCHR
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;rawmemchar_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;s, &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; c)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* transactional variant of rawmemchr() */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#endif
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This works fairly well and I use this scheme for &lt;em&gt;all&lt;/em&gt; supported system
interfaces of the C standard and math libraries, and the POSIX thread
library. It&amp;rsquo;s not complicated, just very tedious to do this for the several
hundred interfaces that are supported by picotm.&lt;/p&gt;
&lt;p&gt;I had to add a few minor changes throughout picotm&amp;rsquo;s source code to turn
non-portable C code into portable one, and that&amp;rsquo;s it! After this, the test
cases succeeded on FreeBSD and I consider it supported.&lt;/p&gt;
&lt;h4 id=&#34;mac-os&#34;&gt;Mac OS&lt;/h4&gt;
&lt;p&gt;The next system to support was Mac OS X. Like Linux and FreeBSD, it&amp;rsquo;s a
Unix system and mostly compatible with the POSIX standard.&lt;/p&gt;
&lt;p&gt;Because Mac OS only runs on Apply hardware, I bought an old Mac mini on Ebay.
Setting up the system for the first time was a bit frustrating. The problem
was that it&amp;rsquo;s a model from 2007 and has long been discontinued. The final
version of Mac OS X that run on the device is 10.6.8, with development tools
being out of date and compilers not supporting C11.&lt;/p&gt;
&lt;p&gt;Thanks to the excellent work of the &lt;a href=&#34;http://www.macports.org/&#34;&gt;MacPorts&lt;/a&gt; project, a lot of the
current Unix software is available on Mac OS X. So I was able to install
recent releases of gcc and build tools even on this old Mac mini.&lt;/p&gt;
&lt;p&gt;Even though Mac OS X is a POSIX system, it is more different from Linux than
FreeBSD, and required another set of changes and fixes.&lt;/p&gt;
&lt;p&gt;For example, C11 provides static assertions that are evaluated at compile
time. Doing something like&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;static_assert&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;) &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;4&lt;/span&gt;, &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Values of type &amp;#39;int&amp;#39; are not 4 bytes wide.&amp;#34;&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;tests if the size of an integer is 4 bytes. If the assertion evaluates to
&lt;code&gt;false&lt;/code&gt;, the compiler stops the build.&lt;/p&gt;
&lt;p&gt;The C standard library of the Mac OS&amp;rsquo;s SDK (i.e., Xcode 3.6) does not support
static compile-time assertions. In this and other cases of missing functions,
I reimplemented the minimum functionality within picotm. The system&amp;rsquo;s
implementation is prefered, but picotm can fall back to it&amp;rsquo;s internal code
if necessary. For the missing &lt;code&gt;static_assert()&lt;/code&gt; macro, there&amp;rsquo;s now a macro of
the same name which looks like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define __PICOTM_LIBC_STATIC_ASSERT(expr, stmt)                          \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    (__extension__({                                                     \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;        int assertion_holds[1-(2*!(expr))] __attribute__((__unused__));  \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;     }))
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#ifndef static_assert
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define static_assert   __PICOTM_LIBC_STATIC_ASSERT
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#endif
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Note that the actual implementation is in &lt;code&gt;__PICOTM_LIBC_STATIC_ASSERT&lt;/code&gt;. The
code only defines &lt;code&gt;static_assert&lt;/code&gt; if it&amp;rsquo;s not already defined by the system.&lt;/p&gt;
&lt;p&gt;A similar problem happend with Pthread barriers. A
&lt;a href=&#34;http://en.wikipedia.org/wiki/Barrier_(computer_science)&#34;&gt;barrier&lt;/a&gt; is a data structure for synchronizing the
execution of multiple threads. It waits to be acquired by a specific number
of threads until the acquiring threads can pass. In picotm, it&amp;rsquo;s used to
synchronize the threads of each test case.&lt;/p&gt;
&lt;p&gt;The implementation of a barrier is a combination of a mutex and a condition
variable. All of them; mutices, condition variables and barriers; are provided
by POSIX threads, but barriers are optional. While the implementation of a
barrier is trivial, it&amp;rsquo;s missing at least on this old version of the Mac OS
SDK. I had to implement the POSIX barrier interface within picotm, using the
system&amp;rsquo;s POSIX mutices and condition variables.&lt;/p&gt;
&lt;p&gt;Finally there was one major problem with time and clock interfaces. The POSIX
standard defines the function &lt;code&gt;clock_gettime()&lt;/code&gt;, which retrieves a time stamp
from one of the system clocks. This interface is missing on Mac OS. I didn&amp;rsquo;t
write a portable implementation within picotm, but instead changed the
function that acquired the time stamp in the first place. On Mac OS X, it
reads time stamps from non-portable interfaces, on all other systems it
reads time stamps using &lt;code&gt;clock_gettime&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Because of the use of system-dependent interfaces for reading time stamps,
I had extend the error-handling interface as well. The Mac OS kernel returns
low-level error codes in the type &lt;code&gt;kern_return_t&lt;/code&gt;. If a time stamp could not
be acquired from the system, this error code is now reported to the
transaction&amp;rsquo;s error recovery phase, so that applications can act upon it.&lt;/p&gt;
&lt;p&gt;With these changes and some additional minor fixes, the test cases
completed successfully on Mac OS. Another system supported!&lt;/p&gt;
&lt;h4 id=&#34;windows&#34;&gt;Windows&lt;/h4&gt;
&lt;p&gt;Windows is &lt;em&gt;not&lt;/em&gt; Unix, so any Unix-specific interface is not natively
supported. Fortunately, there is &lt;a href=&#34;http://www.cygwin.com/&#34;&gt;Cygwin&lt;/a&gt; a POSIX interface
implemented on top of the Windows API.&lt;/p&gt;
&lt;p&gt;This means that the Windows port does currently not support Windows&amp;rsquo; native
interfaces. For example, it&amp;rsquo;s not possible to perform a transaction write
operation to a file using &lt;a href=&#34;http://msdn.microsoft.com/en-us/library/windows/desktop/aa365747(v=vs.85).aspx&#34;&gt;&lt;code&gt;WriteFile_tx()&lt;/code&gt;&lt;/a&gt;. But using
Cygwin, it is possible to achieve the same result with
&lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/write.html&#34;&gt;&lt;code&gt;write_tx()&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;With Cygwin and all the previous fixes for FreeeBSD and Mac OS, the port
itself was straight-forward. I only had to fix a few minor issues and the
test cases completed successfully within a few hours of work. I&amp;rsquo;m happy
to have Windows support on the feature list.&lt;/p&gt;
&lt;p&gt;A few issues remain though. I would be interested in supporting Windows&#39;
native interfaces, but it&amp;rsquo;s a lot of work. At this point it doesn&amp;rsquo;t make
sense for me to spend time on this unless there is real demand for these
interfaces.&lt;/p&gt;
&lt;p&gt;The other issue is with dynamic linking support. Picotm comes as package of
multiple libraries that depend on each other. Linking a DLL requires all its
dependencies  (i.e., other DLLs) to be already installed. This makes linking
picotm libraries as DLLs complicated. It&amp;rsquo;s not hard to fix, but the result is
rather ugly and therefore left-out; and dynamic linking on Windows
is disabled for now. Statically linking against picotm&amp;rsquo;s libraries is no
problem.&lt;/p&gt;
&lt;h4 id=&#34;next-steps&#34;&gt;Next Steps&lt;/h4&gt;
&lt;p&gt;The current ports lay the ground work for supporting even more operating
systems. Coming from FreeBSD and Mac OS, possible next targets are other
Unix operating systems, such as Android and OpenBSD.&lt;/p&gt;
&lt;p&gt;A very interesting target is &lt;a href=&#34;http://www.freertos.org/&#34;&gt;FreeRTOS&lt;/a&gt;, an operating system for
low-power, single-board computers and the IoT. Running code transactionally
has the potential of significantly increasing the reliability of these
devices.&lt;/p&gt;
&lt;p&gt;Then there are the more obscure targets, such as &lt;a href=&#34;http://www.freedos.org/&#34;&gt;FreeDOS&lt;/a&gt; or
&lt;a href=&#34;http://en.wikipedia.org/wiki/AmigaOS&#34;&gt;AmigaOS&lt;/a&gt;. And of course, maybe one day I can port
picotm to &lt;a href=&#34;http://github.com/tdz/opsys&#34;&gt;opsys&lt;/a&gt;, my own little operating-system project.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we&amp;rsquo;ve looked at the different ports that are supported
by the next release of picotm.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;picotm is developed mainly on Linux, but supposed to be portable to
a wide range of different operating systems.&lt;/li&gt;
&lt;li&gt;FreeBSD is very similar to Linux, so mostly minor changes were required
for a port.&lt;/li&gt;
&lt;li&gt;Mac OS X is a Unix system like Linux and FreeBSD. It required the
reimplementation of a few interfaces, but it&amp;rsquo;s still mostly compatible.&lt;/li&gt;
&lt;li&gt;Windows uses a different interface than Linux or any other Unix system.
While the native interfaces require a significant amount of work to
be supported, all of the actual functonality is supported by using
the Cygwin compatibility layer.&lt;/li&gt;
&lt;li&gt;With these operating systems supported, more can be added easily.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you like this blog post, please subscribe to the RSS feed, follow on
Twitter or share on social networks.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Transactional Multisets</title>
      <link>https://tzimmermann.org/2017/11/24/transactional-multisets/</link>
      <pubDate>Fri, 24 Nov 2017 12:00:00 +0100</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/11/24/transactional-multisets/</guid>
      <description>&lt;p&gt;Besides &lt;a href=&#34;https://tzimmermann.org/2017/11/07/transactional-linked-lists/&#34;&gt;lists&lt;/a&gt;, &lt;a href=&#34;https://tzimmermann.org/2017/11/17/transactional-queues-and-stacks/&#34;&gt;queues and stacks&lt;/a&gt;
&lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt; 0.8 will feature a forth transactional data structures:
&lt;a href=&#34;http://github.com/picotm/picotm/pull/167&#34;&gt;multisets&lt;/a&gt;. A multiset is a sorted set that can contain
the same entry multiple times. In this blog post, we&amp;rsquo;ll go through the
interface and how to use multisets from within transactions.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;The &lt;code&gt;struct txmultiset&lt;/code&gt; data structure represents a transactional multiset
(i.e., a set that can hold the same value multiple times). As all the other
transactional data structures it implements concurrency control and error
deteciton in order to provide &lt;a href=&#34;http://en.wikipedia.org/wiki/ACID&#34;&gt;ACID&lt;/a&gt; properties for the
multiset.&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; The multiset interface resembles C++&amp;rsquo;s Standard Template
Library. If you know C++ multisets, you&amp;rsquo;ll find many similarities.&lt;/p&gt;
&lt;h4 id=&#34;multiset-entries&#34;&gt;Multiset Entries&lt;/h4&gt;
&lt;p&gt;To create a multiset, we first need multiset entries. These are represented
by &lt;code&gt;struct txmultiset_entry&lt;/code&gt;. It works the same way as for lists, queues
and stacks. We can add an instance of this data structure to any data
value to turn it into a multiset entry. Here&amp;rsquo;s an example for multisets
of values of type &lt;code&gt;unsigned long&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset_entry multiset_entry;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    };
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_init&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; item, &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; value)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_entry_init&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;multiset_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;value &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item item;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_init&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item, &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This code initializes the multiset entry using &lt;code&gt;txmultiset_entry_init()&lt;/code&gt;. The
macro &lt;code&gt;TXMULTISET_ENTRY_INITIALIZER&lt;/code&gt; initializes static or stack-allocated
multiset entries. The example below illustrates this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset_entry multiset_entry;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    };
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;#define ULONG_ITEM_INITIALIZER(_value)  \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    {                                       \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;        TXMULTISET_ENTRY_INITIALIZER,       \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;        (_value)                            \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item item &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;ULONG_ITEM_INITIALIZER&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;When both, macro and function initialization, is possible, the macro
form is prefered. Multiset entries are uninitialized with
&lt;code&gt;txmultiset_entry_uninit()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_uninit&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; item)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_entry_uninit&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;multiset_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_uninit&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;multiset-states&#34;&gt;Multiset States&lt;/h4&gt;
&lt;p&gt;To store the multiset entries, we need a non-transactional multiset state,
which represents the shared state of a multiset. It&amp;rsquo;s implemented by
&lt;code&gt;struct txmultiset_state&lt;/code&gt;. We can define and initialize a multiset state
as illustrated in the example below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_of_entry&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; entry)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;picotm_containerof&lt;/span&gt;(entry, &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item, multiset_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_key&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; item)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_compare&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; lhs, &lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; rhs)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;rhs &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;lhs) &lt;span style=&#34;color:#f92672&#34;&gt;-&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;lhs &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;rhs);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;key_cb&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; entry)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_key&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_of_entry&lt;/span&gt;(entry));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;compare_cb&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; lhs, &lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; rhs)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_compare&lt;/span&gt;(lhs, rhs);;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset_state multiset_state;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_state_init&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;multiset_state, key_cb, compare_cb);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The example shows the first major difference to the other data structures.
The initializer function takes the multiset state and two additional
call-back functions, which are required for sorting the multiset&amp;rsquo;s
entries. The &lt;code&gt;key_cb()&lt;/code&gt; call-back function returns a pointer to the key
for a given entry. In the example above, it&amp;rsquo;s the value itself. The
&lt;code&gt;compare_cb()&lt;/code&gt; call-back function compares two keys. It returns a value
less than, equal to, or greater than zero if the left-hand-side value is
less than, equal to, or greater than the right-hand-side value. Entries in
a multiset are sorted by their key in ascending order. These call-back
functions provide the key and the compare operation.&lt;/p&gt;
&lt;p&gt;The code uses the initializer function &lt;code&gt;txmultiset_state_init()&lt;/code&gt;. For
static or stack-allocated multiset states, there&amp;rsquo;s the initializer macro
&lt;code&gt;TXMULTISET_STATE_INITIALIZER()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset_state multiset_state &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;TXMULTISET_STATE_INITIALIZER&lt;/span&gt;(multiset_state, key_cb, compare_cb);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;When both forms are possible, the initializer macro is prefered.&lt;/p&gt;
&lt;p&gt;Multiset-state clean-up is performed by &lt;code&gt;txmultiset_state_uninit()&lt;/code&gt;. The
multiset state may not contain entries when the clean-up happens. This
means that entries have to be removed from within a transaction.&lt;/p&gt;
&lt;p&gt;For many uses this requirement just imposes unnecessary overhead. A call
to &lt;code&gt;txmultiset_state_clear_and_uninit_entries()&lt;/code&gt; provies a non-transactional
way of clearing the multiset from its entries. It erases each element from
the multiset and calls a clean-up function on it. The example below shows
the clean-up code for a multiset of &lt;code&gt;struct ulong_item&lt;/code&gt; entries.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_uninit_cb&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; entry, &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; data)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_uninit&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_of_entry&lt;/span&gt;(entry));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// call free() if item was malloc()&amp;#39;ed
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_state_clear_and_uninit_entries&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;multiset_state, ulong_item_uninit_cb, NULL);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_state_uninit&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;multiset_state);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;acquiring-a-multiset&#34;&gt;Acquiring a Multiset&lt;/h4&gt;
&lt;p&gt;At this point we have a multiset state and multiset entries to add to the state.
So far all code was non-transactional. Actual multiset access and manipulation
is performed by transactional code.&lt;/p&gt;
&lt;p&gt;To perform multiset operations within a transaction, we first need a multiset
data structure for our transaction. It&amp;rsquo;s represented by &lt;code&gt;struct txmultiset&lt;/code&gt;.
A call to &lt;code&gt;txmultiset_of_state_tx()&lt;/code&gt; returns an instance.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; multiset &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;multiset_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Calling &lt;code&gt;txmultiset_of_state_tx()&lt;/code&gt; multiple times for the same multiset
state &lt;em&gt;within the same transaction&lt;/em&gt; returns the same multiset. Multisets
are undefined after their transaction committed or aborted, or within
other, concurrent transactions.&lt;/p&gt;
&lt;h4 id=&#34;inserting-entries&#34;&gt;Inserting Entries&lt;/h4&gt;
&lt;p&gt;With the multiset, we can now insert entries into the multiset state using
&lt;code&gt;txmultiset_insert_tx()&lt;/code&gt;. The example below illustrates this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; multiset &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;multiset_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_insert_tx&lt;/span&gt;(multiset, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;multiset_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// more transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;After this transaction committed, the ulong data item &lt;code&gt;item&lt;/code&gt; will be
the in &lt;code&gt;multiset_state&lt;/code&gt;. If the transactions has to abort after
the call to &lt;code&gt;txmultiset_insert_tx()&lt;/code&gt;, the transaction framework will
automatically remove the entry during the rollback; thus restoring the
original state.&lt;/p&gt;
&lt;p&gt;The inserted entry will be sorted in ascending order into the multiset,
using the key the compare call-back functions. The insert function compares
the key of the new entry to the keys of existing entries to determines the
new entry&amp;rsquo;s position. The set is implemented as a tree, so inserting requires
a compare operation with only a small fraction of existing items.&lt;/p&gt;
&lt;h4 id=&#34;removing-entries&#34;&gt;Removing Entries&lt;/h4&gt;
&lt;p&gt;To remove an entry from the multiset, we can call &lt;code&gt;txmultiset_erase_tx()&lt;/code&gt;, as
illustated in the example below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; multiset &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;multiset_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// The multiset state already contains the entry.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_erase_tx&lt;/span&gt;(multiset, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;multiset_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// more transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Removing an entry keeps the entries sorted. The multiset&amp;rsquo;s implementation
re-arranges the entries automatically with very little overhead. As usual,
all errors are detected and handled by the transaction framework. The
benefits of transactional code show when we move entries between multisets.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; src_multiset &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;src_multiset_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; dst_multiset &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;dst_multiset_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// The multiset state already contains the entry.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_erase_tx&lt;/span&gt;(src_multiset, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;multiset_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_insert_tx&lt;/span&gt;(dst_multiset, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;multiset_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// more transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In this example, we removed an entry from a source multiset and inserted it
into a destination multiset. The transaction framework automatically isolates
these operations from concurrent transactions until the transaction commits.
So concurrent transactions see the entry in &lt;em&gt;either&lt;/em&gt; the source multiset
&lt;em&gt;or&lt;/em&gt; the destination multiset, but never in both. If the transaction has to
roll back after the insert operation, the transaction framework
automatically removes the multiset entry from the destination multiset and
returns it to its old position in the source multiset.&lt;/p&gt;
&lt;h4 id=&#34;multiset-size-and-emptieness&#34;&gt;Multiset Size and Emptieness&lt;/h4&gt;
&lt;p&gt;A call to &lt;code&gt;txmultiset_size_tx()&lt;/code&gt; returns the number of multiset entries, a
call to &lt;code&gt;txmultiset_empty_tx()&lt;/code&gt; returns &lt;code&gt;true&lt;/code&gt; if a multiset is empty. The
former function might have linear complexity, the later function always has
constant complexity. It&amp;rsquo;s therefore better to use &lt;code&gt;txmultiset_empty_tx()&lt;/code&gt;
if it&amp;rsquo;s only relevant whether there are entries.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; multiset &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;multiset_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; is_empty &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_empty_tx&lt;/span&gt;(multiset);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; size &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_size_tx&lt;/span&gt;(multiset);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// more transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;iterating-over-the-multisets-entries&#34;&gt;Iterating over the Multiset&amp;rsquo;s Entries&lt;/h4&gt;
&lt;p&gt;We can iterate over the entries of a multiset. The first entry of the
multiset is returned by &lt;code&gt;txmultiset_begin_tx()&lt;/code&gt;. The terminator entry
&lt;em&gt;after&lt;/em&gt; the final entry is returned by &lt;code&gt;txmultiset_end_tx()&lt;/code&gt;. The
terminator entry is not a real entry and should not be dereferenced. Calls
to &lt;code&gt;txmultiset_entry_next_tx()&lt;/code&gt; and &lt;code&gt;txmultiset_entry_prev_tx()&lt;/code&gt; return an
entry&amp;rsquo;s successor or predecessor. Here&amp;rsquo;s an example that iterates over a
multiset of values of type &lt;code&gt;unsigned long&lt;/code&gt; and sums up the individual
values.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; g_sum; &lt;span style=&#34;color:#75715e&#34;&gt;// global variable containg sum of multiset entries
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; multiset &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;multiset_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; sum &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_begin_tx&lt;/span&gt;(multiset);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; end &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_end_tx&lt;/span&gt;(multiset);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (beg &lt;span style=&#34;color:#f92672&#34;&gt;!=&lt;/span&gt; end) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; item &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_of_entry&lt;/span&gt;(beg);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            sum &lt;span style=&#34;color:#f92672&#34;&gt;+=&lt;/span&gt; item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_entry_next_tx&lt;/span&gt;(beg);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// more transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// Picotm&amp;#39;s modules collaborate! The value stored in
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// `sum` is exported from the transaction state using
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// `store_ulong_tx()` from the Transactional Memory
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// module.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;store_ulong_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_sum, sum);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;searching-entries-and-ranges&#34;&gt;Searching Entries and Ranges&lt;/h4&gt;
&lt;p&gt;Being a sorted data structure, multisets offer efficient search operations.
A call to &lt;code&gt;txmultiset_find_tx()&lt;/code&gt; looks-up an entry by a key. A multiset
can contain multiple entries with the same key. In this case
&lt;code&gt;txmultiset_find_tx()&lt;/code&gt; returns one of them. The exact entry can vary
among calls.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; multiset &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;multiset_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; key &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; entry &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_size_tx&lt;/span&gt;(multiset, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;key);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// more transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The beginning and end of a range of entries with the same key is be
obtained by &lt;code&gt;txmultiset_lower_bound_tx()&lt;/code&gt; and
&lt;code&gt;txmultiset_upper_bound_tx()&lt;/code&gt;. The former returns the first entry with the
specified key; the latter returns the entry after the final entry with the
specified key. By iterating over the range, all entries with the key can
be obtained.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; multiset &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;multiset_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; key_count &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; key &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_lower_bound_tx&lt;/span&gt;(multiset, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;key);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; end &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_upper_bound_tx&lt;/span&gt;(multiset, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;key);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (beg &lt;span style=&#34;color:#f92672&#34;&gt;!=&lt;/span&gt; end) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;key_count;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_entry_next_tx&lt;/span&gt;(beg);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// ... more transactional code ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The above example counts the number of entries for the given key. The
function &lt;code&gt;txmultiset_count_tx()&lt;/code&gt; performs this operation more efficiently.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; multiset &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;multiset_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; key &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; key_count &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_count_tx&lt;/span&gt;(multiset, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;key);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;multiset-clean-up&#34;&gt;Multiset Clean-up&lt;/h4&gt;
&lt;p&gt;Finally, to clear the whole multiset at once, there&amp;rsquo;s
&lt;code&gt;txmultiset_clear_tx()&lt;/code&gt;. It&amp;rsquo;s equivalent to a continuous erase operation,
but prefered for its reduced overhead.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txmultiset&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; multiset &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;multiset_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txmultiset_clear_tx&lt;/span&gt;(multiset);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// more transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we&amp;rsquo;ve looked at transactional multisets.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Multisets are sorted sets that can contain the same entry multiple
times.&lt;/li&gt;
&lt;li&gt;Like transactional lists, queues and stacks, multisets provide
concurrency control and error detection to implement the ACID
properties.&lt;/li&gt;
&lt;li&gt;A C++-like interface offers access to the multiset&amp;rsquo;s state and allows
for inserting, removing, iterating and conting the contained entries.&lt;/li&gt;
&lt;li&gt;Multiset access can be filtered by key, such that only relevant entries
are processed by a transaction.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you like this blog post, please subscribe to the RSS feed, follow on
Twitter or share on social networks.&lt;/p&gt;
&lt;h4 id=&#34;footnotes&#34;&gt;Footnotes&lt;/h4&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;If you&amp;rsquo;re interested in the detail of the transaction manager&amp;rsquo;s
&lt;a href=&#34;https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/&#34;&gt;internals&lt;/a&gt;,
&lt;a href=&#34;https://tzimmermann.org/2017/05/09/transactional-semantics-in-theory-and-practice/&#34;&gt;you&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/12/transaction-roll-back-and-serializability/&#34;&gt;should&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/&#34;&gt;go&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/26/transactional-access-to-arbitrary-memory-locations/&#34;&gt;back&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/01/transactional-memcpy-and-resource-privatization/&#34;&gt;and&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/09/more-on-resource-privatization/&#34;&gt;read&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/16/transaction-logs/&#34;&gt;the&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/23/transactional-malloc-and-free/&#34;&gt;installments&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/30/everything-about-errno-plus-transactions/&#34;&gt;about&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/07/07/types-of-transactional-operations/&#34;&gt;the&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/07/14/building-fault-tolerant-software-with-transactions/&#34;&gt;&lt;em&gt;simpletm&lt;/em&gt;&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/07/21/implementing-fault-tolerant-software-with-transactions/&#34;&gt;toy transaction manager&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Transactional Queues and Stacks</title>
      <link>https://tzimmermann.org/2017/11/17/transactional-queues-and-stacks/</link>
      <pubDate>Fri, 17 Nov 2017 12:00:00 +0100</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/11/17/transactional-queues-and-stacks/</guid>
      <description>&lt;p&gt;In &lt;a href=&#34;https://tzimmermann.org/2017/11/07/transactional-linked-lists/&#34;&gt;last week&amp;rsquo;s blog post&lt;/a&gt;, we&amp;rsquo;ve examined transactional
linked lists, a new feature coming in &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt; 0.8. In this
blog post, we are going to talk about transactional &lt;a href=&#34;http://github.com/picotm/picotm/pull/162&#34;&gt;queues&lt;/a&gt; and
&lt;a href=&#34;http://github.com/picotm/picotm/pull/163&#34;&gt;stacks&lt;/a&gt;. Like lists, both data structures will be available in
picotm at the end of November.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;h4 id=&#34;a-brief-recap-of-transactional-lists&#34;&gt;A Brief Recap of Transactional Lists&lt;/h4&gt;
&lt;p&gt;Like traditional linked lists, a transactional linked list is a data
structure for storing data elements. In contrast to the traditional
list, a transactional list can be shared by multiple threads
safely and handles internal errors automatically. As the name suggests,
programs use transactional lists from within a transaction, where they
provide transactional &lt;a href=&#34;http://en.wikipedia.org/wiki/ACID&#34;&gt;ACID&lt;/a&gt; properties for all their
operation.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s an example program that uses a transactional list to store
values of type &lt;code&gt;unsigned long&lt;/code&gt;. There&amp;rsquo;s a full explanation of this code
in the &lt;a href=&#34;https://tzimmermann.org/2017/11/07/transactional-linked-lists/&#34;&gt;previous blog post&lt;/a&gt;,&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; so let&amp;rsquo;s just go through
the most important points. If you are familiar with the interface of
C++&amp;rsquo;s Standard Template Library, you&amp;rsquo;ll find many similarities.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist_entry list_entry;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    };
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item item &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;ULONG_ITEM_INITIALIZER&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist_state list_state &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;TXLIST_STATE_INITIALIZER&lt;/span&gt;(list_state);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The variable &lt;code&gt;item&lt;/code&gt; is a list entry that holds a value of type
&lt;code&gt;unsigned long&lt;/code&gt;. The value is initialized to &lt;code&gt;0&lt;/code&gt; by the initializer macro.
The variable &lt;code&gt;list_state&lt;/code&gt; is the global state of a transactional linked
list. It stores all entries for this list. All actual list access is
performed from within a transaction.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// Inserting transaction
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;//
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; list &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;list_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_push_back_tx&lt;/span&gt;(list, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;list_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// ... more transactional code ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// ... more non-transactional code ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The example&amp;rsquo;s first transaction inserts the entry &lt;code&gt;item&lt;/code&gt; at the end of
the transactional list. It first acquires an actual list from the list
state by calling &lt;code&gt;txlist_of_state_tx()&lt;/code&gt;. The returned &lt;code&gt;txlist&lt;/code&gt; structure
&lt;code&gt;list&lt;/code&gt; provides the interface for operating on the list state, and it
also holds the transaction-local state of the list. With the transactional
list, the first transaction appends the entry to the list state by calling
&lt;code&gt;txlist_push_back_tx()&lt;/code&gt;. If other transactions access the list state
concurrently, the list&amp;rsquo;s implementation detects and resolves all resulting
conflicts automatically. When the transction commits, the list entry becomes
part of the shared list state.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// Iterating transaction
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;//
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; list &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;list_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_begin_tx&lt;/span&gt;(list);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; end &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_end_tx&lt;/span&gt;(list);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (beg &lt;span style=&#34;color:#f92672&#34;&gt;!=&lt;/span&gt; end) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; item &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_of_entry&lt;/span&gt;(beg);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#75715e&#34;&gt;// ... do something with local item ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_entry_next_tx&lt;/span&gt;(beg);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// ... more transactional code ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// ... more non-transactional code ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The example&amp;rsquo;s second transaction iterates over the elements of a
transactional list. Like the first transaction, it acquires a transactional
list from the list state. It then gets the list&amp;rsquo;s beginning and end entries,
which it uses to traverse the whole list from the first to the final entry.
If other transactions try to modify the list state concurrently, the list
detects and resolves any resulting conflicts automatically.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// Removing transaction
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;//
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; list &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;list_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// The list state already contains the entry.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_erase_tx&lt;/span&gt;(list, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;list_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// ... more transactional code ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Finally, the example&amp;rsquo;s third transaction removes our list entry. It
acquires a list from the list state and calls &lt;code&gt;txlist_erase_tx()&lt;/code&gt; to
remove the entry. As before, conflicts are detected and resolved
automatically.&lt;/p&gt;
&lt;h4 id=&#34;transactional-queues&#34;&gt;Transactional Queues&lt;/h4&gt;
&lt;p&gt;The list is a very generic data structure that serves a wide range of use
cases. If all we want is to insert entries at one end and later retrieve
them in the same order at the other end, we can use a transactional queue
instead. The semantics of a queue allows for more concurrency and can thus
improve performance in some situation. But first, an example.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txqueue_entry queue_entry;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    };
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item item &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;ULONG_ITEM_INITIALIZER&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txqueue_state queue_state &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;TXQUEUE_STATE_INITIALIZER&lt;/span&gt;(queue_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// Inserting transaction
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;//
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txqueue&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; queue &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txqueue_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;queue_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txqueue_push_tx&lt;/span&gt;(queue, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;queue_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// ... more transactional code ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// ... more non-transactional code ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;As with lists, there are queue entries and shared queue states. In the
example&amp;rsquo;s first transaction, we acquire a queue for the declared
queue-state variable. And as with lists, the queue is the transactional
interface for modifying the shared queue state. With a call to
&lt;code&gt;txqueue_push_tx()&lt;/code&gt;, we insert an entry into the queue. When the
transaction commits, the entry becomes part of the shared queue state. As
lists, queues detect and resolve conflicts with concurrent transactions
automatically.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// Removing transaction
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;//
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txqueue&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; queue &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txqueue_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;queue_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txqueue_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; item &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txqueue_front_tx&lt;/span&gt;(queue);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txqueue_pop_tx&lt;/span&gt;(queue);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// ... do something with item ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// ... more transactional code ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The second transaction in the example removes the entry from the queue.
It reads the next queue entry by calling &lt;code&gt;txqueue_front_tx()&lt;/code&gt;. This is the
entry we pushed into the queue in the first transaction. Then the second
transaction removes the entry with a call to &lt;code&gt;txqueue_pop_tx()&lt;/code&gt;. After
the pop operation, the entry itself is still valid, so the transaction can
use it&amp;rsquo;s stored value for further computation. After the successful commit
of the second transaction, the entry is not part of the shared queue
state any longer.&lt;/p&gt;
&lt;p&gt;In contrast to lists, entries in a queue cannot be iterated over. Only the
first or final entry can be retrieved. Furthermore, entries can only be
inserted at one end and removed at the other end. These semantics allow for
more concurrency an some situations.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txqueue&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; queue &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txqueue_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;queue_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txqueue_push_tx&lt;/span&gt;(queue, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;queue_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// ... more transactional code ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In this example we push an item into the queue. This is a local operation
and because queues don&amp;rsquo;t allow for iteration, there&amp;rsquo;s no reason to integrate
it into the global state just yet. An optimzation applied by picotm is to
keep the push operation in the transaction-local state and only integrate
it into the shared state during a commit. The transaction does not acquire
a reader lock for the queue until it actually commits. Hence concurrent
transactions can retrieve or even remove entries on the queue without being
affected by our uncommitted push.&lt;/p&gt;
&lt;h4 id=&#34;transactional-stacks&#34;&gt;Transactional Stacks&lt;/h4&gt;
&lt;p&gt;Like queues, stacks have certain properties we can use for reducing conflicts
and increasing concurrency among transactions. But let&amp;rsquo;s look at some code
first. Here&amp;rsquo;s the queue example, modified for stacks.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txstack_entry stack_entry;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    };
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item item &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;ULONG_ITEM_INITIALIZER&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txstack_state stack_state &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;TXSTACK_STATE_INITIALIZER&lt;/span&gt;(stack_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// Inserting transaction
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;//
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txstack&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; stack &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txstack_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;stack_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txstack_push_tx&lt;/span&gt;(stack, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;stack_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// ... more transactional code ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// ... more non-transactional code ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// Removing transaction
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;//
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txstack&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; stack &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txstack_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;stack_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txstack_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; item &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txstack_top_tx&lt;/span&gt;(stack);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txstack_pop_tx&lt;/span&gt;(stack);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// ... do something with item ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// ... more transactional code ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Again we have entries and shared stack state. The stack is acquired with
&lt;code&gt;txstack_of_stack_tx()&lt;/code&gt; within each transaction. The first transaction in
the example pushes an entry onto the stack, the second transaction retrieves
the stack&amp;rsquo;s top-most entry and removes it. The interfaces are very similar
to those of transactional lists and queues. Of course, each interface detects
and resolves conflicts among transactions automatically.&lt;/p&gt;
&lt;p&gt;Similar to queues, the stack allows us to reduce transaction conflicts
and increase concurrency.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txstack&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; stack &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txstack_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;stack_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txstack_push_tx&lt;/span&gt;(stack, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;stack_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// ... more transactional code ...
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txstack_pop_tx&lt;/span&gt;(stack);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In this example, the transaction pushes an entry onto the stack. As with
queues, this operation is entirely local at this point. There&amp;rsquo;s no reason
to acquire a writer lock on the stack state before the transaction actually
commits the change. Concurrent transactions can read the stack state
meanwhile.&lt;/p&gt;
&lt;p&gt;Even more concurrency can be achieved within the pop operation. Like a push,
a pop operation modifies the stack&amp;rsquo;s top. In the example above, we push
an entry onto the transaction&amp;rsquo;s local stack top. When we later pop the
entry, we again operate on the local stack top. So unless we pop an entry
from the shared stack state, we don&amp;rsquo;t require any writer locks. If a
transaction performs a number of push operations and afterwards an equal
number of pop operations, effectively no change to the shared state
was performed. In this case, the transaction can commit without acquiring
a lock on the stack state at all.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we&amp;rsquo;ve looked at transactional queues and stacks.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Like transactional lists, transactional queues and stacks provide
concurrency control and error detection to implement the ACID
properties.&lt;/li&gt;
&lt;li&gt;The semantics of queues and stack can be used to reduce conflicts
and increase concurrency among transactions.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you like this blog post, please subscribe to the RSS feed, follow on
Twitter or share on social networks.&lt;/p&gt;
&lt;h4 id=&#34;footnotes&#34;&gt;Footnotes&lt;/h4&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;If you are curious what this is all about and what transactions
can do for your
&lt;a href=&#34;https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/&#34;&gt;software&lt;/a&gt;,
&lt;a href=&#34;https://tzimmermann.org/2017/05/09/transactional-semantics-in-theory-and-practice/&#34;&gt;you&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/12/transaction-roll-back-and-serializability/&#34;&gt;should&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/&#34;&gt;go&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/26/transactional-access-to-arbitrary-memory-locations/&#34;&gt;back&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/01/transactional-memcpy-and-resource-privatization/&#34;&gt;and&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/09/more-on-resource-privatization/&#34;&gt;read&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/16/transaction-logs/&#34;&gt;the&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/23/transactional-malloc-and-free/&#34;&gt;installments&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/30/everything-about-errno-plus-transactions/&#34;&gt;about&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/07/07/types-of-transactional-operations/&#34;&gt;the&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/07/14/building-fault-tolerant-software-with-transactions/&#34;&gt;&lt;em&gt;simpletm&lt;/em&gt;&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/07/21/implementing-fault-tolerant-software-with-transactions/&#34;&gt;toy transaction manager&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Transactional Linked Lists</title>
      <link>https://tzimmermann.org/2017/11/07/transactional-linked-lists/</link>
      <pubDate>Tue, 07 Nov 2017 10:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/11/07/transactional-linked-lists/</guid>
      <description>&lt;p&gt;The November release of &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt; will feature
&lt;a href=&#34;http://github.com/picotm/picotm/pull/159&#34;&gt;transactional lists&lt;/a&gt;.
These lists can be accessed and modified concurrently by multiple
transactions while respecting the transaction&amp;rsquo;s ACID properties. In this
blog posts, we&amp;rsquo;re going to look at the lists&amp;rsquo; features and interface.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;h4 id=&#34;the-transaction-interface&#34;&gt;The Transaction Interface&lt;/h4&gt;
&lt;p&gt;Transactional code runs isolated from other transactions in the system. All
concurrency and errors are handled by a transaction manager. If anything
fails the transaction framework rolls the transaction back into the original
state and either retries or invokes error recovery. To the transaction it
looks as if it had the whole system for itself and errors never happen. This
is generally known as the &lt;a href=&#34;http://en.wikipedia.org/wiki/ACID&#34;&gt;ACID properties&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;We can build this easily with picotm, a transaction manager for C applications
and system software. Without going into details, a picotm transaction looks as
shown in the example below. The transactional code is located between
&lt;code&gt;picotm_begin&lt;/code&gt; and &lt;code&gt;picotm_commit&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// Transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// Error-recovery code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Earlier in this blog we had a series of articles about constructing a
transaction manager in C. If you want to know how all this works at the
fundamental level, you
&lt;a href=&#34;https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/&#34;&gt;might&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/09/transactional-semantics-in-theory-and-practice/&#34;&gt;want&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/12/transaction-roll-back-and-serializability/&#34;&gt;to&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/&#34;&gt;go&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/26/transactional-access-to-arbitrary-memory-locations/&#34;&gt;back&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/01/transactional-memcpy-and-resource-privatization/&#34;&gt;and&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/09/more-on-resource-privatization/&#34;&gt;read&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/16/transaction-logs/&#34;&gt;the&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/23/transactional-malloc-and-free/&#34;&gt;installments&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/30/everything-about-errno-plus-transactions/&#34;&gt;about&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/07/07/types-of-transactional-operations/&#34;&gt;the&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/07/14/building-fault-tolerant-software-with-transactions/&#34;&gt;&lt;em&gt;simpletm&lt;/em&gt;&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/07/21/implementing-fault-tolerant-software-with-transactions/&#34;&gt;toy transaction manager&lt;/a&gt;.&lt;/p&gt;
&lt;h4 id=&#34;why-do-we-want-lists&#34;&gt;Why Do We Want Lists?&lt;/h4&gt;
&lt;p&gt;The code in a transactions runs in its own, isolated space. To interact with
the outside world (i.e., the rest of the program) it has to perform
operations on shared data structurs. Such a data structure could be a
double-linked list.&lt;/p&gt;
&lt;p&gt;For an example, imagine one transaction generates list entries with
values received over the network from another computer or read from a file.
It enqueues the entries into a globally shared list where they are picked
up by other transactions for further processing of the contained data.&lt;/p&gt;
&lt;p&gt;The list has to be transactional to make this work. Therefore it must
automatically handle concurrency among transactions and detect internal
errors. On any error it has to be able to go back into its original state.
In the rest of this blog article well examine how to do this in practice
with the new transactional lists in picotm.&lt;/p&gt;
&lt;p&gt;The interfaces are similar to the lists of C++ by design. You&amp;rsquo;ll probably
recogonize some if you have experience with C++&amp;rsquo; Standard Template Library.&lt;/p&gt;
&lt;h4 id=&#34;list-entries&#34;&gt;List Entries&lt;/h4&gt;
&lt;p&gt;To create a list, we first need list entries. These are represented by
&lt;code&gt;struct txlist_entry&lt;/code&gt;. We can add an instance of this data structure to any
data value to turn it into a list entry. Here&amp;rsquo;s an example for lists of
values of type &lt;code&gt;unsigned long&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist_entry list_entry;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    };
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_init&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; item, &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; value)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_entry_init&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;list_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;value &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item item;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_init&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item, &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This code initializes the list entry using &lt;code&gt;txlist_entry_init()&lt;/code&gt;. There&amp;rsquo;s
also an initializer macro. &lt;code&gt;TXLIST_ENTRY_INITIALIZER&lt;/code&gt; initializes static
or stack-allocated list entries. The example below illustrates this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist_entry list_entry;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    };
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;#define ULONG_ITEM_INITIALIZER(_value)  \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    {                                       \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;        TXLIST_ENTRY_INITIALIZER,           \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;        (_value)                            \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item item &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;ULONG_ITEM_INITIALIZER&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;When both, macro and function initialization, is possible, the macro
form is prefered. List entries are uninitialized with
&lt;code&gt;txlist_entry_uninit()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_uninit&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; item)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_entry_uninit&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;list_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_uninit&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;the-shared-list-state&#34;&gt;The Shared List State&lt;/h4&gt;
&lt;p&gt;To store the list entries we need non-transactional list state, which
represents the shared state of a double-linked list. It&amp;rsquo;s implemented
by &lt;code&gt;struct txlist_state&lt;/code&gt;. We can define and initialize a list state
as illustrated in the example below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist_state list_state;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_state_init&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;list_state);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This code uses the initializer function &lt;code&gt;txlist_state_init()&lt;/code&gt;. For
static or stack-allocated list states, there&amp;rsquo;s the initializer macro
&lt;code&gt;TXLIST_STATE_INITIALIZER()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist_state list_state &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;TXLIST_STATE_INITIALIZER&lt;/span&gt;(list_state);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;When both forms are possible, the initializer macro is the prefered form.&lt;/p&gt;
&lt;p&gt;List-state clean up is performed by &lt;code&gt;txlist_state_uninit()&lt;/code&gt;. The list
state may not contain entries when the clean-up happens. This means that
entries have to be cleaned up from within a transaction.&lt;/p&gt;
&lt;p&gt;For many uses this requirement just imposes unnecessary overhead. A call to
&lt;code&gt;txlist_state_clear_and_uninit_entries()&lt;/code&gt; provies a non-transactional
way of clearing the list from its entries. It erases each element from
the list and calls a clean-up function on it. The example below shows
the clean-up code for a list of &lt;code&gt;struct ulong_item&lt;/code&gt; entries.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_of_entry&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; entry)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;picotm_containerof&lt;/span&gt;(entry, &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item, list_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_uninit_cb&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; entry, &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; data)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_uninit&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_of_entry&lt;/span&gt;(entry));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// call free() if item was malloc()&amp;#39;ed
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_state_clear_and_uninit_entries&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;list_state, ulong_item_uninit_cb, NULL);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_state_uninit&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;list_state);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;At this point we have a list state and list entries to add to the state.
So far all code was non-transactional. Actual list access and manipulation
is performed by transactional code.&lt;/p&gt;
&lt;h4 id=&#34;finally-lists&#34;&gt;Finally, Lists!&lt;/h4&gt;
&lt;p&gt;To perform list operations within a transaction, we first need a list
data structure for our transaction. It&amp;rsquo;s represented by &lt;code&gt;struct txlist&lt;/code&gt;.
A call to &lt;code&gt;txlist_of_state_tx()&lt;/code&gt; returns an instance.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; list &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;list_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Calling &lt;code&gt;txlist_of_state_tx()&lt;/code&gt; multiple times for the same list state
&lt;em&gt;within the same transaction&lt;/em&gt; returns the same list. Lists are undefined
after their transaction committed or aborted, or within other, concurrent
transactions.&lt;/p&gt;
&lt;h4 id=&#34;adding-and-removing-list-entries&#34;&gt;Adding And Removing List Entries&lt;/h4&gt;
&lt;p&gt;With the list, we can now append or prepend entries to the list state
using &lt;code&gt;txlist_push_back_tx()&lt;/code&gt; and &lt;code&gt;txlist_push_front_tx()&lt;/code&gt;. The example
below illustrates the use of &lt;code&gt;txlist_push_back_tx()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; list &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;list_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_push_back_tx&lt;/span&gt;(list, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;list_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// more transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;After this transaction committed, the ulong data item &lt;code&gt;item&lt;/code&gt; will be
the final entry in &lt;code&gt;list_state&lt;/code&gt;. If the transactions has to abort after
the call to &lt;code&gt;txlist_push_back_tx()&lt;/code&gt;, the transaction framework will
automatically remove the appended entry during the rollback; thus
restoring the original state.&lt;/p&gt;
&lt;p&gt;To remove an entry from the list, we can call &lt;code&gt;txlist_erase_tx()&lt;/code&gt;,
illustated in the example below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; list &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;list_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// The list state already contains the entry.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_erase_tx&lt;/span&gt;(list, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;list_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// more transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;As usual, all errors are detected and handled by the transaction
framework. The benefits of transactional code show when we move
entries between lists.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; src_list &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;src_list_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; dst_list &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;dst_list_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// The list state already contains the entry.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_erase_tx&lt;/span&gt;(src_list, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;list_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_push_back_tx&lt;/span&gt;(dst_list, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;list_entry);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// more transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In this example, we remove an entry from a source list and append it to
a destination list. The transaction framework automatically isolates these
operations from concurrent transactions until the transaction commits. So
concurrent transactions see the entry in &lt;em&gt;either&lt;/em&gt; the source list &lt;em&gt;or&lt;/em&gt; the
destination list, but never in both. If the transaction has to roll back
after the append operation, the transaction framework automatically removes
the list entry from the destination list and returns it to its old position
in the source list.&lt;/p&gt;
&lt;h4 id=&#34;list-capacity&#34;&gt;List Capacity&lt;/h4&gt;
&lt;p&gt;A call to &lt;code&gt;txlist_size_tx()&lt;/code&gt; returns the number of list entries, a call to
&lt;code&gt;txlist_empty_tx()&lt;/code&gt; returns &lt;code&gt;true&lt;/code&gt; if a list is empty. The former function
might have linear complexity, the later function always has constant
complexity. It&amp;rsquo;s therefore better to use &lt;code&gt;txlist_empty_tx()&lt;/code&gt; if it&amp;rsquo;s only
relevant whether there are entries.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; list &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;list_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; is_empty &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_empty_tx&lt;/span&gt;(list);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; size &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_size_tx&lt;/span&gt;(list);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// more transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;iterating-over-list-entries&#34;&gt;Iterating Over List Entries&lt;/h4&gt;
&lt;p&gt;We can also iterate over the entries of a list. The first entry of the list
is returned by &lt;code&gt;txlist_begin_tx()&lt;/code&gt;. The terminator entry &lt;em&gt;after&lt;/em&gt; the final
entry is returned by &lt;code&gt;txlist_end_tx()&lt;/code&gt;. The terminator entry is not a real
entry and should not be dereferenced. Calls to &lt;code&gt;txlist_entry_next_tx()&lt;/code&gt; and
&lt;code&gt;txlist_entry_prev_tx()&lt;/code&gt; return an entry&amp;rsquo;s successor or predecessor. Here&amp;rsquo;s
and example that iterates over a list of values of type &lt;code&gt;unsigned long&lt;/code&gt; and
sums up the individual values.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; g_sum; &lt;span style=&#34;color:#75715e&#34;&gt;// global variable containg sum of list entries
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; list &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;list_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; sum &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_begin_tx&lt;/span&gt;(list);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; end &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_end_tx&lt;/span&gt;(list);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (beg &lt;span style=&#34;color:#f92672&#34;&gt;!=&lt;/span&gt; end) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; ulong_item&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; item &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;ulong_item_of_entry&lt;/span&gt;(beg);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            sum &lt;span style=&#34;color:#f92672&#34;&gt;+=&lt;/span&gt; item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_entry_next_tx&lt;/span&gt;(beg);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// more transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// Picotm&amp;#39;s modules collaborate! The value stored in
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// `sum` is exported from the transaction state using
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// `store_ulong_tx()` from the Transactional Memory
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// module.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;store_ulong_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_sum, sum);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;If we have an entry in a list, we can insert another entry &lt;em&gt;before&lt;/em&gt;
the existing one with &lt;code&gt;txlist_insert_tx()&lt;/code&gt;. In the example below, we
insert before the terminator entry, which is equivalent to an append
operation.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; list &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;list_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_insert_tx&lt;/span&gt;(list, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;item&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;list_entry, &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_end_tx&lt;/span&gt;(list));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// more transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;To append or prepend entries to a list, it&amp;rsquo;s better use the appropriate
push functions, though. The transaction framework might be able to optimize
concurrency control for each. Also, inserting or removing from a list
can make iteration loops invalid. It&amp;rsquo;s therefore better to separate these
operations cleanly.&lt;/p&gt;
&lt;h4 id=&#34;clearing-the-list&#34;&gt;Clearing The List&lt;/h4&gt;
&lt;p&gt;Finally, to clear the whole list at once there&amp;rsquo;s &lt;code&gt;txlist_clear_tx()&lt;/code&gt;.
It&amp;rsquo;s equivalent to a continuous erase operation, but prefered for its
reduced overhead.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// init and ulong code here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; txlist&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; list &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_of_state_tx&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;list_state);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;txlist_clear_tx&lt;/span&gt;(list);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// more transactional code
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    picotm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;next-steps&#34;&gt;Next Steps&lt;/h4&gt;
&lt;p&gt;The current transactional lists already provide everything we need. But
of course, there&amp;rsquo;s always room for optimizations.&lt;/p&gt;
&lt;p&gt;One possible next step is the introduction of an iterator data type that
abstracts access to list entries. Such an abstraction would allow
for more concurrency when operating on lists, as the order of list entries
would be determined by the iterator and not the actual list order.&lt;/p&gt;
&lt;p&gt;With iterators in place, appending and prepending to a list is another
possible area of optimization. Each operation means &lt;em&gt;modify the entry at
either end of the list,&lt;/em&gt; but neither depends on where the actual end is.
Each transaction can have its own local beginning and end of the list.
Only during a commit would this local state become part of the global list
state.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we&amp;rsquo;ve looked at transactional lists and how to use them.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Transactional lists provide concurrency control and error detection to
implement the ACID properties.&lt;/li&gt;
&lt;li&gt;Non-transactional list state and entries are separate from the
transactional list.&lt;/li&gt;
&lt;li&gt;All list access and modification is performed by transactions.&lt;/li&gt;
&lt;li&gt;A transaction creates a list by acquiring global list state.&lt;/li&gt;
&lt;li&gt;Transactions can add and remove entries in a list, retrieve the number
of entries in a list, and iterate over a list&amp;rsquo;s entries.&lt;/li&gt;
&lt;li&gt;Sophisticated list implementations can optimize concurrency control
depending on each list operation&amp;rsquo;s semantics.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you like this blog post, please subscribe to the RSS feed, follow on
Twitter or share on social networks.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Scaling Lock Performance</title>
      <link>https://tzimmermann.org/2017/10/20/scaling-lock-performance/</link>
      <pubDate>Fri, 20 Oct 2017 19:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/10/20/scaling-lock-performance/</guid>
      <description>&lt;p&gt;Release 0.7 of &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt; will feature several major improvements of
the locking code. In this blog post, we&amp;rsquo;re going to look at each change and
how it impacts performance and scalability. We&amp;rsquo;ll go from exclusive locks to
reader/writer locks to exclusive mode to a dedicated lock manager.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;h4 id=&#34;the-test-setup&#34;&gt;The Test Setup&lt;/h4&gt;
&lt;p&gt;&lt;a href=&#34;http://picotm.org/&#34;&gt;Picotm&lt;/a&gt; is a transaction manager for system-level software. For
example, we can write transactions that concurrently perform operations on
file descriptors and file buffers, and picotm will detect reader/writer
conflicts and errors for us. In the case of a conflict, one of the
conflicting transactions has to roll back into its original state and retry.
In the case of an error, picotm executes application-specific error handling
code.&lt;/p&gt;
&lt;p&gt;Our tools for measuring the performance is
&lt;a href=&#34;http://github.com/picotm/picotm-perf&#34;&gt;&lt;code&gt;picotm-perf&lt;/code&gt;&lt;/a&gt;. It&amp;rsquo;s a
&lt;a href=&#34;https://tzimmermann.org/2017/09/27/benchmark-visualization-with-latex-and-gnuplot/&#34;&gt;simple test tool and comes with a benchmark script&lt;/a&gt;
for running a large set of tests.&lt;/p&gt;
&lt;p&gt;Tests within &lt;code&gt;picotm-perf&lt;/code&gt; operate on transactional memory. Each test&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;begins a transaction,&lt;/li&gt;
&lt;li&gt;performs a number of load operations from shared memory,&lt;/li&gt;
&lt;li&gt;performs a number of store operations into shared memory, and&lt;/li&gt;
&lt;li&gt;commits the transactions.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;All load and store locations are randomized. The shared memory is a memory
buffer that is used for all transactions&amp;rsquo; loads and stores. With only 1024
bytes it&amp;rsquo;s fairly small, so conflicts are more or less guaranteed.&lt;/p&gt;
&lt;p&gt;Picotm-perf is a synthetic benchmark; all results are only meaningful
relative to each other, but they probably don&amp;rsquo;t represent real-world
performance in any way. Change any parameter and the results could be
entirely different.&lt;/p&gt;
&lt;p&gt;The test environment is outlined in the PDF files with the results. Note
that the test machine has 4 logical processor cores, but only 2 physical
cores. The performance won&amp;rsquo;t scale linearly with the number of cores on
such a system.&lt;/p&gt;
&lt;h4 id=&#34;the-original-code-of-picotm-06&#34;&gt;The Original Code of picotm 0.6&lt;/h4&gt;
&lt;p&gt;Let&amp;rsquo;s start with the original implementation that shipped with picotm&amp;rsquo;s
previous release 0.6. It divides the shared memory buffer into small records
of 8 bytes and locks each record with an exclusive lock. This means that two
transactions observe a conflict when both access the same record concurrently;
whether it&amp;rsquo;s a load or a store operation does not matter.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&#34;results-v0.6.pdf&#34;&gt;benchmark results&lt;/a&gt; (pg. 3-8) for random memory
access reflect this. Independently from the number of loads and stores, all
graphs look the same. Here&amp;rsquo;s an example of a transaction with 50 loads and
50 stores.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;results-v0.6.png&#34; alt=&#34;picotm v0.6, I/O pattern random, 50 loads, 50 stores&#34;&gt;&lt;/p&gt;
&lt;p&gt;The blue bars and the scale on the left show the number of committed
transactions per second; the red bars and the right scale show the number
of restarts per second.&lt;/p&gt;
&lt;p&gt;We already mentioned the effect of exclusive locks on concurrency. For a
single transaction we start with around 50,000 commits per seconds, but go
down as we add concurrent transactions ot the test. And that&amp;rsquo;s even the case
if we only run transactions with load operations, which don&amp;rsquo;t require
exclusive locks.&lt;/p&gt;
&lt;p&gt;Another problem that becomes obvious from the test results is the extremely
high number of restarts. There are up to 4 million restarts per second!&lt;/p&gt;
&lt;p&gt;These results gives us our first targets for improvement: enable concurrent
access to memory records for transactions that only perform load operations,
and reduce the number of restarts.&lt;/p&gt;
&lt;h4 id=&#34;adding-readerwriter-locks&#34;&gt;Adding Reader/Writer Locks&lt;/h4&gt;
&lt;p&gt;&lt;a href=&#34;http://github.com/picotm/picotm/pull/140&#34;&gt;Pull request #140&lt;/a&gt; on GitHub converts the transactional-memory
module to use reader/writer locks. These locks are already provided by picotm
and used throughout the file-I/O code to protect concurrent access to files
and file buffers.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s an example from the &lt;a href=&#34;results-limit-nretries.pdf&#34;&gt;test results&lt;/a&gt;
for reader/writer locks. The transaction again consists of 50 load and 50
store operations.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;results-tm-rwlocks.png&#34; alt=&#34;With R/W locks, I/O pattern random, 50 loads, 50 stores&#34;&gt;&lt;/p&gt;
&lt;p&gt;The results are two-fold. We have reduced the number of restarts by a factor
of 10 to 15 to something in the 200 thousands. Unfortunately, this didn&amp;rsquo;t
increase the number of commits per seconds. Quite the opposite actually. With
more than one transaction present, the result drops to a few 1.000 commits
per second.&lt;/p&gt;
&lt;p&gt;An exception is the case of the load-only transactions, shown on page 8 of
the &lt;a href=&#34;results-limit-nretries.pdf&#34;&gt;PDF file&lt;/a&gt;. With the new reader/writer
locks, reader transactions finally start scaling.&lt;/p&gt;
&lt;p&gt;At this point it&amp;rsquo;s worth remembering that our shared memory buffer is only
1 KiB in size. With a buffer size that small, as soon as we have write
operations in our transaction, conflicting access among transactions are
likely.&lt;/p&gt;
&lt;p&gt;The low number of concurrent commits is the result of the small buffer
size and the interactions between concurrent transactions, competing for
locks. We have hit a pathological corner case. If we could &lt;em&gt;guarantee&lt;/em&gt;
progress to some transactions, things might improve. One simple way of
doing this is a limit on the number of restarts per transaction.&lt;/p&gt;
&lt;h4 id=&#34;adding-exclusive-mode&#34;&gt;Adding Exclusive Mode&lt;/h4&gt;
&lt;p&gt;Exclusive mode is a variant of irrevocability. In exclusive mode, we
run one single transaction exclusively. All other transactions are
blocked and consequently conflicts among transcations cannot occur.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;http://github.com/picotm/picotm/pull/141&#34;&gt;Pull request #141&lt;/a&gt; on GitHub enables exclusive mode on top
of the reader/writer patch set. After a transaction has reached 10 retries,
picotm stops all other transactions, which now have to wait until completion
of the exclusive one. The limit has been choosen arbitrarily and its optimum
depends on the workload and access patterns.&lt;/p&gt;
&lt;p&gt;The complete results are in &lt;a href=&#34;results-tm-rwlocks.pdf&#34;&gt;this PDF file&lt;/a&gt;.
Here&amp;rsquo;s an example.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;results-limit-nretries.png&#34; alt=&#34;With exclusive mode, I/O pattern random, 50 loads, 50 stores&#34;&gt;&lt;/p&gt;
&lt;p&gt;The results look really promising. By limiting the number of restarts per
transaction, we have reduced the overall number of restarts by factor 10
to 100,000 to 140,000 restarts per second. At the same time we increased
the number of concurrent commits by a factor of 10 to up to 20,000.&lt;/p&gt;
&lt;p&gt;On top of the scalability improvements, exclusive mode offers another
important feature: transactions are now guaranteed to commit and our
overall system will make progress in any case. Imagine a scenario where
transactions constantly conflict with each other, restart, and conflict
again without ever getting out of this pattern. This is called a &lt;em&gt;livelock.&lt;/em&gt;
With the previous implementation this was very much possible; with the
new implementation not so. With this patch set, we did not just improve
scalability, we resolved a whole class of concurrency problems.&lt;/p&gt;
&lt;p&gt;Even with our current patch set we still observe 100,000 to 140,000 restarts
per second. These restarts are required to avoid cyclic dependencies among
transactions, as all locks held by a transaction are released if the
transaction restarts. By simply never waiting, no cyclic dependencies, and
therefore no deadlocks, can occur.&lt;/p&gt;
&lt;p&gt;Our next improvement will try to reduce the number of restarts by not
restarting after all. That&amp;rsquo;s what a lock manager does.&lt;/p&gt;
&lt;h4 id=&#34;adding-a-lock-manager&#34;&gt;Adding a Lock Manager&lt;/h4&gt;
&lt;p&gt;The lock manager is a software component within picotm that&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;maintains lists of transactions waiting for each reader/writer lock, and&lt;/li&gt;
&lt;li&gt;schedules waiting transactions when a lock becomes available.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The &lt;a href=&#34;http://github.com/picotm/picotm/pull/142&#34;&gt;actual implemenation&lt;/a&gt; is quite complex and worth a
separate blog post. The overall algorithm can be summarized like this&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;A transaction tries to acquire a reader/writer lock.&lt;/li&gt;
&lt;li&gt;If the transaction fails to acquire the lock, it instructs the lock
manager to make it wait for the lock to become available.&lt;/li&gt;
&lt;li&gt;The lock manager inserts the transaction into a waiting queue for
the lock.&lt;/li&gt;
&lt;li&gt;When the lock becomes available, the unlocking transaction instructs
the lock manager to select one or more of the waiting transactions
and wake them up.&lt;/li&gt;
&lt;li&gt;In the waiters
&lt;ol&gt;
&lt;li&gt;the woken-up transactions try again to acquire the lock.&lt;/li&gt;
&lt;li&gt;If a transaction has not been woken up after a certain timeout, it
wakes up automatically and a tries to acquire the lock.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;Only if a transaction fails a second time to acquire the lock, it
restarts; otherwise it continues as if lock acquisition had been
successful on the first try.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Point 5.2 is required to avoid cyclic dependencies, and therefore deadlocks,
among waiting transactions. If the waiting time has an upper bound, cyclic
dependencies will be resolved as soon as the timeout has been reached and
one of the transactions restarts.&lt;/p&gt;
&lt;p&gt;Lock management gives us a new quality of locking: we now know which
transaction waits for which lock, we can keep statistics about each
transaction&amp;rsquo;s locking patterns, and we have a central place that coordinates
locks among transactions.&lt;/p&gt;
&lt;p&gt;At the moment &lt;a href=&#34;results-lock-manager.pdf&#34;&gt;the results&lt;/a&gt; are again
two-fold. Here&amp;rsquo;s our example result.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;results-lock-manager.png&#34; alt=&#34;With lock management, I/O pattern random, 50 loads, 50 stores&#34;&gt;&lt;/p&gt;
&lt;p&gt;Compared to the previous patch set, we have reduced the number of restarts
by another factor of 8 to 14.000 to 16.000 restarts per second. Compared to
the 4 million restarts per second with picotm 0.6 that&amp;rsquo;s an overall
improvement by factor 250. Amazing!&lt;/p&gt;
&lt;p&gt;Unfortunately, lock management actually decreased the number of
commits per second significantly. The reason is in the high overhead
of maintaining the waiter lists and suspending the waiting transactions,
which involves a number of system calls. That&amp;rsquo;s significant compared to
the fast load and store operations that are required for simply restarting.&lt;/p&gt;
&lt;h4 id=&#34;where-to-go-from-here&#34;&gt;Where To Go From Here?&lt;/h4&gt;
&lt;p&gt;picotm 0.7 will feature all of the improvements we discussed in this blog
post. Reader/writer locks and the exclusive mode are definitely useful
changes.&lt;/p&gt;
&lt;p&gt;The lock manager will be available, but probably not be used for the
most part. For these memory-only transactions of our test program, maintaining
waiter lists and suspending transactions makes no sense, because simply
restarting conflicting transactions in exclusive mode gives much better
results.&lt;/p&gt;
&lt;p&gt;The situation changes with longer transactions that may even have a higher
system-wide overhead. For example, file I/O requires system calls for
reading and writing data in the file buffer. The longer such a transaction
runs, the more likely it is that it reaches a tiping point where waiting
is the better option over restarting immediately.&lt;/p&gt;
&lt;p&gt;Our current lock manager&amp;rsquo;s transaction scheduler always wakes up the longest
waiting transaction when the lock becomes available. That&amp;rsquo;s probably not
optimal in most situation. By maintaining better locking statistics for
each transaction, we can make better decisions about which transaction to
wake up. There are zillions of strategies and tuning parameters to explore!&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we&amp;rsquo;ve looked at the impact of different locking patch sets
to the scalability and performance of picotm&amp;rsquo;s transactions.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Exclusive locks don&amp;rsquo;t scale well, lead to a large number of conflict
restarts, and don&amp;rsquo;t allow for concurrent readers.&lt;/li&gt;
&lt;li&gt;Reader/writer locks improve concurrency in setups with many reader
transactions and only few conflicts. They are not that helpful if
conflicts with writer transactions are likely.&lt;/li&gt;
&lt;li&gt;Switching transactions to an exclusive mode after they reached a limited
number of restarts further improves scalability and prevents livelocks.&lt;/li&gt;
&lt;li&gt;Lock management can significantly reduce the number of restarts, but
imposes overhead on the transactions.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you like this blog post, please subscribe to the RSS feed, follow on
Twitter or share on social networks.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>When realloc() Doesn&#39;t Allocate</title>
      <link>https://tzimmermann.org/2017/10/06/when-realloc-doesnt-allocate/</link>
      <pubDate>Fri, 06 Oct 2017 08:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/10/06/when-realloc-doesnt-allocate/</guid>
      <description>&lt;p&gt;I recently wrote about &lt;a href=&#34;https://tzimmermann.org/2017/09/08/mallocs-tricky-error-reporting/&#34;&gt;correct error handling for &lt;code&gt;malloc()&lt;/code&gt;&lt;/a&gt;.
Coincidently I came across an older &lt;a href=&#34;http://www.open-std.org/jtc1/sc22/wg14/www/docs/n2109.htm#dr_400&#34;&gt;defect report&lt;/a&gt; on the
behavior of C&amp;rsquo;s &lt;a href=&#34;http://man7.org/linux/man-pages/man3/realloc.3.html&#34;&gt;&lt;code&gt;realloc()&lt;/code&gt;&lt;/a&gt; function just a few days ago. In
this blog post, we&amp;rsquo;re going to look at &lt;code&gt;realloc()&lt;/code&gt;&amp;rsquo;s behavior if it&amp;rsquo;s out
of memory or if the requested size is zero.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;h4 id=&#34;a-simple-realloc&#34;&gt;A Simple &lt;code&gt;realloc()&lt;/code&gt;&lt;/h4&gt;
&lt;p&gt;In C11, new memory blocks are dynamically allocated using one of
&lt;a href=&#34;http://man7.org/linux/man-pages/man3/malloc.3.html&#34;&gt;&lt;code&gt;malloc()&lt;/code&gt;&lt;/a&gt;, &lt;a href=&#34;http://man7.org/linux/man-pages/man3/calloc.3.html&#34;&gt;&lt;code&gt;calloc()&lt;/code&gt;&lt;/a&gt;, or
&lt;a href=&#34;http://man7.org/linux/man-pages/man3/aligned_alloc.3.html&#34;&gt;&lt;code&gt;aligned_alloc()&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you read this blog post, you&amp;rsquo;ve probably seen calls to these functions
frequently, including calls to &lt;a href=&#34;http://man7.org/linux/man-pages/man3/realloc.3.html&#34;&gt;&lt;code&gt;realloc()&lt;/code&gt;&lt;/a&gt;. A call to
&lt;code&gt;realloc()&lt;/code&gt; changes the size of a memory block while preserving the block&amp;rsquo;s
existing content. Here&amp;rsquo;s a naive implementation.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;realloc&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; old_mem, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; new_size)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;old_mem) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(new_size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;new_size) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; old_mem;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; new_mem &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(new_size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;new_mem) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; NULL;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; old_size &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; ; &lt;span style=&#34;color:#75715e&#34;&gt;// non-portable: get size of &amp;#39;old_mem&amp;#39; from allocator
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;memcpy&lt;/span&gt;(new_mem, old_mem, old_size &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; new_size &lt;span style=&#34;color:#f92672&#34;&gt;?&lt;/span&gt; old_size : new_size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;free&lt;/span&gt;(old_mem);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; new_mem;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;What does it do? First of all, we get two corner cases out of the way. If
no old memory buffer is specified, &lt;code&gt;realloc()&lt;/code&gt; shall behave like &lt;code&gt;malloc()&lt;/code&gt;.
Our first condition handles this. Then we test if the new size is not zero. If
it is zero, we return the old memory. &lt;a href=&#34;http://www.open-std.org/jtc1/sc22/wg14/www/docs/n2109.htm#dr_400&#34;&gt;C11 with DR 400&lt;/a&gt; say that
successful zero-size allocations shall behave &lt;em&gt;as if the size were some nonzero
value [&amp;hellip;].&lt;/em&gt; We already know that &lt;code&gt;old_mem&lt;/code&gt; contains a non-&lt;code&gt;NULL&lt;/code&gt; value, so we
return this. It&amp;rsquo;s not supposed to be dereferenced after this point, though.&lt;/p&gt;
&lt;p&gt;With the corner cases handled, we can perform the &lt;em&gt;real&lt;/em&gt; &lt;code&gt;realloc()&lt;/code&gt;, which is
&lt;code&gt;malloc()&lt;/code&gt;-&lt;code&gt;memcpy()&lt;/code&gt;-&lt;code&gt;free()&lt;/code&gt; semantically. And finally we return the new
buffer, which contains the content of the old buffer.&lt;/p&gt;
&lt;p&gt;For the &lt;code&gt;memcpy()&lt;/code&gt; operation, we need the size of the old buffer. There&amp;rsquo;s no
such functionality standardized by ISO C or POSIX, but most allocators provide
an interface for this: &lt;a href=&#34;http://man7.org/linux/man-pages/man3/malloc_usable_size.3.html&#34;&gt;&lt;code&gt;malloc_usable_size()&lt;/code&gt;&lt;/a&gt; in the
GNU libc, BSD and Bionic, &lt;a href=&#34;http://msdn.microsoft.com/en-us/library/z2s077bc(v=vs.140).aspx&#34;&gt;&lt;code&gt;_msize()&lt;/code&gt;&lt;/a&gt; on Windows, or
&lt;a href=&#34;http://www.unix.com/man-page/osx/3/malloc_size/&#34;&gt;&lt;code&gt;malloc_size()&lt;/code&gt;&lt;/a&gt; on MacOS.&lt;/p&gt;
&lt;h4 id=&#34;handling-the-returned-value&#34;&gt;Handling the Returned Value&lt;/h4&gt;
&lt;p&gt;Let&amp;rsquo;s now call &lt;code&gt;realloc()&lt;/code&gt; and see what it does. One common programming
mistake is illustrated below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; mem &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;10&lt;/span&gt;); &lt;span style=&#34;color:#75715e&#34;&gt;/* non-zero allocation */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;...
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;mem &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;realloc&lt;/span&gt;(mem, &lt;span style=&#34;color:#ae81ff&#34;&gt;20&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;mem) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* handle allocation failure */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This pattern can often be found, although it is incorrect. What happens if
the re-allocation fails? Of course, &lt;code&gt;NULL&lt;/code&gt; is returned. If we immediately
store &lt;code&gt;realloc()&lt;/code&gt;&amp;rsquo;s returned value in &lt;code&gt;mem&lt;/code&gt;, the old &lt;code&gt;mem&lt;/code&gt; buffer leaks if
&lt;code&gt;realloc()&lt;/code&gt; fails. The correct code looks like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; mem &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;10&lt;/span&gt;); &lt;span style=&#34;color:#75715e&#34;&gt;// non-zero allocation
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;...
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; tmp &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;realloc&lt;/span&gt;(mem, &lt;span style=&#34;color:#ae81ff&#34;&gt;20&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;tmp) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* handle allocation failure */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;mem &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; tmp; &lt;span style=&#34;color:#75715e&#34;&gt;/* Only update &amp;#39;mem&amp;#39; is it&amp;#39;s safe to do so */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Even if &lt;code&gt;realloc()&lt;/code&gt; failed to allocate a new buffer, we still have our
pointer to the old buffer and can free the old buffer later on.&lt;/p&gt;
&lt;p&gt;Another, although less common, mistake is to access memory out-of-bounds
after shrinking a buffer. Here&amp;rsquo;s an example.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; mem &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;10&lt;/span&gt;); &lt;span style=&#34;color:#75715e&#34;&gt;/* non-zero allocation */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;...
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; tmp &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;realloc&lt;/span&gt;(mem, &lt;span style=&#34;color:#ae81ff&#34;&gt;5&lt;/span&gt;); &lt;span style=&#34;color:#75715e&#34;&gt;/* shrink buffer */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;tmp) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* handle allocation failure */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;mem &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; tmp;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;mem[&lt;span style=&#34;color:#ae81ff&#34;&gt;7&lt;/span&gt;] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;; &lt;span style=&#34;color:#75715e&#34;&gt;/* This memory location is now outside the allocated buffer! */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Remember that semantically &lt;code&gt;realloc()&lt;/code&gt; allocates a new buffer, copies the
old buffer into the new buffer, and then frees the old buffer. Depending on
the requested buffer size, the actual buffer size can also shrink. Accessing
memory that was allocated with the old buffer, but not with the new buffer is
therefore undefined behavior.&lt;/p&gt;
&lt;p&gt;Finally, let&amp;rsquo;s see what happens if the requested new size is zero. Quoting
&lt;a href=&#34;http://www.open-std.org/jtc1/sc22/wg14/www/docs/n2109.htm#dr_400&#34;&gt;DR 400&lt;/a&gt; again:&lt;/p&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;&lt;/th&gt;
					&lt;th&gt;&lt;code&gt;realloc(NULL, 0)&lt;/code&gt;&lt;/th&gt;
					&lt;th&gt;&lt;code&gt;realloc(non-NULL ptr, 0)&lt;/code&gt;&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;AIX&lt;/td&gt;
					&lt;td&gt;always returns &lt;code&gt;NULL&lt;/code&gt;, errno is &lt;code&gt;EINVAL&lt;/code&gt;&lt;/td&gt;
					&lt;td&gt;always returns &lt;code&gt;NULL&lt;/code&gt;, frees &lt;code&gt;ptr&lt;/code&gt;, errno is &lt;code&gt;EINVAL&lt;/code&gt;&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;BSD&lt;/td&gt;
					&lt;td&gt;returns &lt;code&gt;NULL&lt;/code&gt; on error, errno is &lt;code&gt;ENOMEM&lt;/code&gt;&lt;/td&gt;
					&lt;td&gt;returns NULL on error, &lt;code&gt;ptr&lt;/code&gt; unchanged, errno is &lt;code&gt;ENOMEM&lt;/code&gt;&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;glibc&lt;/td&gt;
					&lt;td&gt;returns &lt;code&gt;NULL&lt;/code&gt; on error, errno is &lt;code&gt;ENOMEM&lt;/code&gt;&lt;/td&gt;
					&lt;td&gt;always returns &lt;code&gt;NULL&lt;/code&gt;, &lt;code&gt;ptr&lt;/code&gt; freed, errno unchanged&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;This is very inconsistent among older C implementations before C11.
Every implementation behaves in a different way. I can&amp;rsquo;t bring myself
to even try to write error-checking code that works correctly with all
these variants. If you do, please &lt;a href=&#34;mailto:blog@tzimmermann.org&#34;&gt;send me some example code&lt;/a&gt;
and I&amp;rsquo;ll post it here.&lt;/p&gt;
&lt;p&gt;If we&amp;rsquo;re on C11, we&amp;rsquo;re lucky. For zero-size reallocations, DR 400
specifies that &lt;code&gt;realloc()&lt;/code&gt; shall either return a &lt;code&gt;NULL&lt;/code&gt; pointer to indicate
an error, or that the old buffer remains in place. For all pre-C11 code that
requires portability between different implementations, it&amp;rsquo;s best to
write a wrapper around &lt;code&gt;realloc()&lt;/code&gt; that handles the corner cases specifically.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;portable_realloc&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; mem, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; siz)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;mem) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(siz);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;siz) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; mem;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;realloc&lt;/span&gt;(mem, siz);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post we looked at the corner cases of &lt;code&gt;realloc()&lt;/code&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;If the old memory buffer is &lt;code&gt;NULL&lt;/code&gt;, &lt;code&gt;realloc()&lt;/code&gt; behaves like &lt;code&gt;malloc()&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;If the requested size is zero, behavior is implementation defined.&lt;/li&gt;
&lt;li&gt;On allocation errors, pre-C11 implementations of &lt;code&gt;realloc()&lt;/code&gt; handle
&lt;code&gt;errno&lt;/code&gt;, the old memory buffer and their return value in different ways.&lt;/li&gt;
&lt;li&gt;Portable code should either switch to C11, or wrap &lt;code&gt;realloc()&lt;/code&gt; in a
function that handles the corner cases in a portable way.&lt;/li&gt;
&lt;li&gt;Callers must hold a pointer to the old buffer until they tested for
the success of &lt;code&gt;realloc()&lt;/code&gt;. Otherwise the application leaks the old
memory buffer on allocation failures.&lt;/li&gt;
&lt;li&gt;Calls to &lt;code&gt;realloc&lt;/code&gt; may shrink memory buffers. Memory that was present
in the old buffer, may not be available in the new shrinked memory buffer.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you like this blog post about memory allocation, please subscribe to
the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Benchmark Visualization with LaTeX and gnuplot</title>
      <link>https://tzimmermann.org/2017/09/27/benchmark-visualization-with-latex-and-gnuplot/</link>
      <pubDate>Wed, 27 Sep 2017 18:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/09/27/benchmark-visualization-with-latex-and-gnuplot/</guid>
      <description>&lt;p&gt;Visualizing benchmark results is an important step in performance testing.
In this blog post, we&amp;rsquo;re going to use &lt;a href=&#34;http://www.latex-project.org/&#34;&gt;LaTeX&lt;/a&gt;, &lt;a href=&#34;http://www.gnuplot.info/&#34;&gt;gnuplot&lt;/a&gt;
and &lt;a href=&#34;http://www.perl.org/&#34;&gt;Perl&lt;/a&gt; to convert raw performance data into a nice-looking PDF
document.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;We&amp;rsquo;re going to produce a script named &lt;code&gt;run_benchmark.pl&lt;/code&gt;, which executes
a set of tests and produces a PDF document with a set of nicely formated
diagrams that illustrate the test results. Of course we cannot go through
the script line-by-line, we all the major points are explained.&lt;/p&gt;
&lt;p&gt;The produced PDF looks like in &lt;a href=&#34;results.pdf&#34;&gt;this example&lt;/a&gt;. The full
source code is available in picotm&amp;rsquo;s &lt;a href=&#34;http://github.com/picotm/picotm-perf&#34;&gt;picotm-perf&lt;/a&gt;
repository.&lt;/p&gt;
&lt;h4 id=&#34;turning-raw-numbers-into-actionable-data&#34;&gt;Turning Raw Numbers into Actionable Data&lt;/h4&gt;
&lt;p&gt;During September your author was busy with the implementation of a new testing
infrastructure for &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt;&amp;rsquo;s unit tests and continuous integration.&lt;/p&gt;
&lt;p&gt;Part of this infrastructure is a set of performance tests. Each test run a
predefined workloads and generate a test result that gives information about
the performance of the system. Picotm is a manager for system-level
transactions, which means that the most interesting performance information
is the number of transactions it&amp;rsquo;s able to perform per unit of time.&lt;/p&gt;
&lt;p&gt;The first interesting information is the number of completed transactions
per time unit. Our test constantly begins and commits transactions for
a certain amount of time and measures the number of successfully committed
transactions. This is the &lt;em&gt;throughput&lt;/em&gt; measured in &lt;em&gt;commits per second.&lt;/em&gt;
The single-thread throughput mostly depends on the transaction manager&amp;rsquo;s
overhead, so this information is relevant during optimization.&lt;/p&gt;
&lt;p&gt;Occationally (or maybe frequently) the transaction manager stops, rolls
back and restarts a transaction. This happens for error handling and
conflict resolution. Restarting transactions can have quite a bit of
overhead and minimizing the number of restarts will improve the system&amp;rsquo;s
performance. Therefore the second interesting information is the number
of restarted transactions per time, measured in &lt;em&gt;restarts per second.&lt;/em&gt;
Minimizing the number of restarts should have positive impact on
throughput.&lt;/p&gt;
&lt;p&gt;Our test program &lt;code&gt;picotm-perf&lt;/code&gt; executes a number of load and store
transactions in the main memory. The resulting output on the console
looks like this:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;0 60000 10000 0
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;These numbers are&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;the thread id. &lt;em&gt;0&lt;/em&gt; as there&amp;rsquo;s only one thread in this example.&lt;/li&gt;
&lt;li&gt;The number of milliseconds that the test ran. The equivalent of 60
seconds in this case.&lt;/li&gt;
&lt;li&gt;The number of commited transactions on this thread. 10000.&lt;/li&gt;
&lt;li&gt;And finally the number of restarts. There are no restarts because a
single transaction cannot conflict.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This test program can be executed for various combinations of load and
store operations and I/O patterns. This only depends on the command-line
parameters.&lt;/p&gt;
&lt;p&gt;Running all these combinations result is an endless list of such single-line
performance results. This is unintuitive, so we have to feed the data into
further processing stages.&lt;/p&gt;
&lt;p&gt;The tools your author has picked are&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Perl for processing the test-program&amp;rsquo;s information,&lt;/li&gt;
&lt;li&gt;gnuplot for converting raw data into diagrams, and&lt;/li&gt;
&lt;li&gt;LaTeX for assembling the individual graphs into a PDF document.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;You can find the source code of the script in the
&lt;a href=&#34;http://github.com/picotm/picotm-perf&#34;&gt;picotm-perf&lt;/a&gt; repository. If you want to use it for
other performance visualization, all you have to replace is the test
program, and adopt the data parser in the Perl script and the gnuplot
instructions. The rest should be independent from the actual performance
tests.&lt;/p&gt;
&lt;h4 id=&#34;generating-the-raw-data&#34;&gt;Generating the Raw Data&lt;/h4&gt;
&lt;p&gt;As mentioned before, test results are generated by &lt;code&gt;picotm-perf&lt;/code&gt;. To
generate larger amounts of test data, the benchmark script
&lt;code&gt;run_bechmark.pl&lt;/code&gt; calls &lt;code&gt;picotm-perf&lt;/code&gt; with different combinations of
parameters for the number of concurrent transactions, the number of
load operations per transaction, the number of store operations per
transaction, and the I/O pattern. It&amp;rsquo;s a set of nested loops in Perl.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-perl&#34; data-lang=&#34;perl&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;foreach&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;my&lt;/span&gt; $pattern (&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#39;random&amp;#39;&lt;/span&gt;, &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#39;sequential&amp;#39;&lt;/span&gt;) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;foreach&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;my&lt;/span&gt; $nloads (&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;10&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;20&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;30&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;40&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;50&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;60&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;70&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;80&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;90&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;100&lt;/span&gt;) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;my&lt;/span&gt; $nstores &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;100&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-&lt;/span&gt; $nloads;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;foreach&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;my&lt;/span&gt; $ncores (&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;..&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;4&lt;/span&gt;) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            run_picotm_perf($pattern, $nloads, $nstores, $ncores);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;sub&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;run_picotm_perf&lt;/span&gt;() {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;my&lt;/span&gt; ($pattern, $nloads, $nstores, $ncores) &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; @_;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;`picotm-perf -T 60000 -P $pattern -L $nloads -S $nstores -t $ncores`&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The example code is mostly self-explaining. It executes the function
&lt;code&gt;run_picotm_perf()&lt;/code&gt; for all different combinations of I/O patterns, numbers
of loads and stores, and number of concurrent transactions / processor
cores.&lt;/p&gt;
&lt;p&gt;The function &lt;code&gt;run_picotm_perf()&lt;/code&gt; simply runs the external test program
with the given parameters and returns the resulting output string of
the format we&amp;rsquo;ve seen before.&lt;/p&gt;
&lt;h4 id=&#34;generating-the-diagram-data&#34;&gt;Generating the Diagram Data&lt;/h4&gt;
&lt;p&gt;With the raw data at hand, we can now generate the information required
by gnuplot to create the diagrams. The question is what our diagrams shall
tell us.&lt;/p&gt;
&lt;p&gt;We are interested in the number of commits and restarts per second for
each combination of I/O pattern and loads and stores. For each of these
combinations, we&amp;rsquo;re also interested in how the values change if we add
or remove concurrent transactions in the workload.&lt;/p&gt;
&lt;p&gt;So we want a single diagram for each combination of I/O pattern, loads
and stores, and have the number of transactions change along each
diagram&amp;rsquo;s x axis. The y axis&amp;rsquo; display the result.&lt;/p&gt;
&lt;p&gt;We can build this by replacing the inner-most loop of the previous
example by the function &lt;code&gt;generate_dat()&lt;/code&gt;, which is shown below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-perl&#34; data-lang=&#34;perl&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;sub&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;generate_dat&lt;/span&gt; {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;my&lt;/span&gt; ($pattern, $nloads, $nstores) &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; @_;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;foreach&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;my&lt;/span&gt; $ncores (&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;..&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;4&lt;/span&gt;) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;my&lt;/span&gt; $result_string &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; run_picotm_perf($pattern, $nloads, $nstores, $ncores);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;my&lt;/span&gt; dat_string
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;my&lt;/span&gt; $ncommits &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;my&lt;/span&gt; $nretries &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;my&lt;/span&gt; @lines &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; split &lt;span style=&#34;color:#e6db74&#34;&gt;/\n/&lt;/span&gt;, $result_string;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;foreach&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;my&lt;/span&gt; $line (@lines) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#75715e&#34;&gt;# &amp;lt;thread id&amp;gt; &amp;lt;nmsecs&amp;gt; &amp;lt;ncommits&amp;gt; &amp;lt;nretries&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            $line &lt;span style=&#34;color:#f92672&#34;&gt;=~&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;m/^(\d+)\s+(\d+)\s+(\d+)\s+(\d+)\s*$/&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;or&lt;/span&gt; die;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#75715e&#34;&gt;# Sum up normalized results&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            $ncommits &lt;span style=&#34;color:#f92672&#34;&gt;+=&lt;/span&gt; $3 &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1000&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;/&lt;/span&gt; $2;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            $nretries &lt;span style=&#34;color:#f92672&#34;&gt;+=&lt;/span&gt; $4 &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1000&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;/&lt;/span&gt; $2;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        dat_string &lt;span style=&#34;color:#f92672&#34;&gt;.=&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;\n&amp;#34;&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;.&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;$ncores $ncommits $nretries&amp;#34;&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; dat_string;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This code produces the data for a single diagram, but it&amp;rsquo;s probably
non-obvious what happens.&lt;/p&gt;
&lt;p&gt;First of all the function runs the test program 4 times: with 1, 2, 3, or
4 concurrent  transactions. Each run produces a result that is stored in
&lt;code&gt;result_string&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;For each test run, the result string is parsed line by line for the number
of seconds that the test ran, the number of committed transactions and the
number of restarted transactions. The result numbers are normalized by time
and added up. The result is appended to the string &lt;code&gt;dat_string&lt;/code&gt; in the
following format.&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;1 123400 0
2 12300  100
3 1200   1200
4 100    12300
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Each line in &lt;code&gt;dat_string&lt;/code&gt; now contains the number of concurrent transactions,
the number of committed transactions per second, and the number of restarted
transactions per second. This is what we want to display in each diagram
and it&amp;rsquo;s in a format that gnuplot understands.&lt;/p&gt;
&lt;h4 id=&#34;generating-a-latex-document&#34;&gt;Generating a LaTeX document&lt;/h4&gt;
&lt;p&gt;At this point we have performed a large number of tests for different
combinations of I/O patterns, loads and stores, &lt;em&gt;and&lt;/em&gt; for each combination
we know how the results change when the number of concurrent transactions
increases.&lt;/p&gt;
&lt;p&gt;In principle the hardest work is done and all that&amp;rsquo;s left to do is to put
the data into a nice format.&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; As mentioned before, we use LaTeX and
gnuplot for the data visualization. It&amp;rsquo;s fair to say that both programs
are fantastic in terms of features, but less than optimal in terms of
usability. Both have a file format that is rather inelegant and breaks
easily. It&amp;rsquo;s something most people write and debug once, and then try to
leave alone.&lt;/p&gt;
&lt;p&gt;The input for gnuplot is a format that describes the resulting diagram. It
allows to connect the input data, which we generated in the previous step,
to the individual axes, and allows for configuring colors and style of the
graph. The x axis on each of our diagrams shows the number of concurrent
transactions. The y axis on the left shows the number of commits per second;
the y axis on the right shows the number of restarts per second. Running
&lt;code&gt;gnuplot&lt;/code&gt; on each set of input data produces the corresponding image of
the diagram.&lt;/p&gt;
&lt;p&gt;We won&amp;rsquo;t go through the details of the LaTeX document source code here,
but your author likes to highlight the use of LaTeX&amp;rsquo; gnuplot package. The
gnuplot tool typically gets it input from an external file. One can run
gnuplot to generate an image file from such an external file and then
reference the image&amp;rsquo;s filename in the LaTeX source code.&lt;/p&gt;
&lt;p&gt;The gnuplot package for LaTeX simplifies this significantly. It allows for
storing the gnuplot diagram description directly within the LaTeX document.
The gnuplot tool is run automatically by the package while processing the
LaTeX document and the resulting image is included where the description
was located before. This does away with all the file-name juggling. Your
author appreciated the gnuplot package a lot while working on the benchmark
script.&lt;/p&gt;
&lt;p&gt;The rest of the LaTeX document is set in the standard format, which is
widely documented on the web. The end result is a file named &lt;code&gt;results.tex&lt;/code&gt;,
which can be converted into a PDF document.&lt;/p&gt;
&lt;h4 id=&#34;generating-a-pdf-document&#34;&gt;Generating a PDF Document&lt;/h4&gt;
&lt;p&gt;The PDF output is produced by the LaTeX tool &lt;code&gt;pdflatex&lt;/code&gt;. Running LaTeX
tools seems just as arkward as writing LaTeX documents. We have to run
&lt;code&gt;pfdlatex&lt;/code&gt; 3 times on &lt;code&gt;results.tex&lt;/code&gt; to get a correct PDF document. The
benchmark script does this internally.&lt;/p&gt;
&lt;h4 id=&#34;ideas-for-future-improvements&#34;&gt;Ideas for Future Improvements&lt;/h4&gt;
&lt;p&gt;Finally we have a [PDF document][site:results_pdf] named &lt;code&gt;results.pdf&lt;/code&gt;. With
picotm&amp;rsquo;s current implementation the performance numbers don&amp;rsquo;t have much
meaning yet, but from here we can easily change and optimize and compare
different versions against each other.&lt;/p&gt;
&lt;p&gt;For the benchmark script itself, your author has a number of ideas.&lt;/p&gt;
&lt;p&gt;Of course, more combinations of our test parameters are always possible.
Adding these is a low-hanging fruit.&lt;/p&gt;
&lt;p&gt;Since we already have a lot of performance data, we could archive it for
future use. Then a user could point the script to a certain directory with
test results and have it generate performance diagrams from these.&lt;/p&gt;
&lt;p&gt;With the old results stored away, the script could also compute the
differences between different test runs, visualize them, and automatically
warn about performance regressions above a certain threshold.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we&amp;rsquo;ve developed a script for creating and visualizing
performance data.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The actual test utility is an external program that generates performance
data for different simulated workloads.&lt;/li&gt;
&lt;li&gt;The test result is returned in the test utility&amp;rsquo;s output.&lt;/li&gt;
&lt;li&gt;The benchmark script is written in Perl, which is well-suited for
text processing.&lt;/li&gt;
&lt;li&gt;The benchmark script runs the test program with various combinations
of workload parameters and converts the resulting performance data
to a format that is compatible with gnuplot.&lt;/li&gt;
&lt;li&gt;The gnuplot tool generates images of diagrams from raw data.&lt;/li&gt;
&lt;li&gt;The benchmark script assembles all gnuplot-generated diagrams into
a LaTeX source file.&lt;/li&gt;
&lt;li&gt;The LaTeX tool &lt;code&gt;pdflatex&lt;/code&gt; generates the final PDF document from the
LaTeX sources.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you like this blog post, please subscribe to the RSS feed, follow on
Twitter or share on social networks.&lt;/p&gt;
&lt;h4 id=&#34;footnotes&#34;&gt;Footnotes&lt;/h4&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;One could argue that collecting the data is easy, but writing
LaTeX source files is hard. :p&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</description>
    </item>
    
    
    
    <item>
      <title>malloc()&#39;s Tricky Error Reporting</title>
      <link>https://tzimmermann.org/2017/09/08/mallocs-tricky-error-reporting/</link>
      <pubDate>Fri, 08 Sep 2017 12:30:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/09/08/mallocs-tricky-error-reporting/</guid>
      <description>&lt;p&gt;Most error checks for &lt;code&gt;malloc()&lt;/code&gt; are incorrect. In this blog post, we&amp;rsquo;re
going to look at the details of &lt;code&gt;malloc()&lt;/code&gt;&amp;rsquo;s error reporting semantics and
how to test if a call to &lt;code&gt;malloc()&lt;/code&gt; succeeded.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;h4 id=&#34;the-semantics-of-malloc&#34;&gt;The Semantics of &lt;code&gt;malloc()&lt;/code&gt;&lt;/h4&gt;
&lt;p&gt;If you have seen at least a few lines of C code, you&amp;rsquo;ve probably come
across &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/malloc.html&#34;&gt;&lt;code&gt;malloc()&lt;/code&gt;&lt;/a&gt;, the interface for allocating memory
from the operating system at runtime.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; size &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;calc_amount_of_bytes&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In this example, the function &lt;code&gt;calc_amount_of_bytes()&lt;/code&gt; is a placeholder
that returns the number of bytes to be allocated. This memory size is given
to &lt;code&gt;malloc()&lt;/code&gt;, which then acquires a large-enough memory buffer from the
operating system. Finally, &lt;code&gt;malloc()&lt;/code&gt; returns a pointer to the beginning
of the buffer.&lt;/p&gt;
&lt;h4 id=&#34;first-try-testing-the-returned-value&#34;&gt;First Try: Testing the Returned Value&lt;/h4&gt;
&lt;p&gt;In the case that &lt;code&gt;malloc()&lt;/code&gt; failed to allocate the requested amount
of memory, it returns a &lt;code&gt;NULL&lt;/code&gt; pointer. Quoting
&lt;a href=&#34;http://man7.org/linux/man-pages/man3/malloc.3.html&#34;&gt;&lt;code&gt;malloc()&lt;/code&gt;&amp;rsquo;s man page&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The  malloc()  and  calloc()  functions return a pointer to the
allocated memory, which is suitably aligned for any built-in type.
On error, these functions return NULL.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Similar descriptions can be found in the ISO C Standard, the POSIX
Standard and the &lt;code&gt;malloc()&lt;/code&gt; page on MSDN.&lt;/p&gt;
&lt;p&gt;The usual, almost ideomatic way of testing for allocation errors therefore
looks like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; size &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;calc_amount_of_bytes&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;ptr) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// allocation error detected!
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;And this code is&amp;hellip; &lt;strong&gt;wrong.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Again, here&amp;rsquo;s what &lt;code&gt;malloc()&lt;/code&gt;&amp;rsquo;s man page says. Note the additional sentence.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The  malloc()  and  calloc()  functions return a pointer to the allocated
memory, which is suitably aligned for any built-in type.  On error, these
functions return NULL.  NULL may also be returned by a successful call to
malloc() with a size of zero [&amp;hellip;].&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;So if the allocation size is &lt;em&gt;0,&lt;/em&gt; &lt;code&gt;malloc()&lt;/code&gt; is allowed to return &lt;code&gt;NULL&lt;/code&gt; even
though it actually succeeded. For some reason, everyone seems to ignore this
additional sentence. I admit that I&amp;rsquo;m guilty of this as well.&lt;/p&gt;
&lt;h4 id=&#34;second-try-testing-errno&#34;&gt;Second Try: Testing &lt;code&gt;errno&lt;/code&gt;&lt;/h4&gt;
&lt;p&gt;Just testing the returned pointer for &lt;code&gt;NULL&lt;/code&gt; doesn&amp;rsquo;t work. My solution to
this problem was to test the value of &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/errno.html&#34;&gt;&lt;code&gt;errno&lt;/code&gt;&lt;/a&gt; instead. If
the allocation fails, &lt;code&gt;malloc()&lt;/code&gt; sets the value of &lt;code&gt;errno&lt;/code&gt; to &lt;code&gt;ENOMEM&lt;/code&gt;
before it returns &lt;code&gt;NULL&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The pattern for testing &lt;code&gt;malloc()&lt;/code&gt; errors via &lt;code&gt;errno&lt;/code&gt; looks like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; size &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;calc_amount_of_bytes&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;errno &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (errno) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// allocation error detected!
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Here, we clear &lt;code&gt;errno&lt;/code&gt; to a neutral value before calling &lt;code&gt;malloc()&lt;/code&gt;. If
&lt;code&gt;errno&lt;/code&gt; is set afterwards, an allocation error has accured.&lt;/p&gt;
&lt;p&gt;Unfortunately, it&amp;rsquo;s not a correct solution either. The pattern worked
very well on all kinds of Linux systems until I came across a &lt;code&gt;malloc()&lt;/code&gt;
implementation on one of Sony&amp;rsquo;s Android phones.&lt;/p&gt;
&lt;p&gt;On Firefox OS, we used to have a number of system daemons for running the
Android drivers separately from the main system. When reviewing patches to
these daemons, I asked patch authors to use the &lt;code&gt;errno&lt;/code&gt; pattern and avoid
the test for the &lt;code&gt;NULL&lt;/code&gt; pointer.&lt;/p&gt;
&lt;p&gt;On Sony&amp;rsquo;s Android phone, this didn&amp;rsquo;t work. We had this pattern in our
Bluetooth daemon, but Sony&amp;rsquo;s implementation of &lt;code&gt;malloc()&lt;/code&gt; sets &lt;code&gt;errno&lt;/code&gt; even
if the allocation succeeds. The Bluetooth daemon incorrectly interpreted
this as an error.&lt;/p&gt;
&lt;p&gt;I don&amp;rsquo;t blame Sony for this problem. It was a mistake on my side, as the
POSIX standard says the following about &lt;code&gt;errno&lt;/code&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;No function in this volume of POSIX.1-2008 shall set errno to 0. The
setting of errno after a successful call to a function is unspecified
unless the description of that function specifies that errno shall not
be modified.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;In other words, even in the case of success, &lt;code&gt;malloc()&lt;/code&gt; is allowed to modify
the value of &lt;code&gt;errno&lt;/code&gt;. It&amp;rsquo;s just not allowed to set it to &lt;em&gt;0.&lt;/em&gt;&lt;/p&gt;
&lt;h4 id=&#34;third-try-testing-the-allocation-size-and-the-returned-pointer&#34;&gt;Third Try: Testing the Allocation Size and the Returned Pointer&lt;/h4&gt;
&lt;p&gt;This brings us back to testing the returned pointer. Since it&amp;rsquo;s only
allowed to be legally &lt;code&gt;NULL&lt;/code&gt; if the requested size is zero, we have to
test specifically for this combination. This pattern looks as shown below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; size &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;calc_amount_of_bytes&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (size &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;ptr) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// allocation error detected!
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;And this is the solution to the problem. The pointer test is only allowed
if we requested a memory buffer with a size greater than zero. And only then
it&amp;rsquo;s an error. Allocations of zero-size buffers always succeed.&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s important to note that the behavior for zero-size allocations is
completely up to the implementation. It&amp;rsquo;s also legal that &lt;code&gt;malloc()&lt;/code&gt; returns
a pointer different from &lt;code&gt;NULL&lt;/code&gt;. It could even set &lt;code&gt;errno&lt;/code&gt; in this case. Our
current pattern handles these implementations as well.&lt;/p&gt;
&lt;p&gt;A nice detail about releasing the allocated memory with
&lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/free.html&#34;&gt;&lt;code&gt;free()&lt;/code&gt;&lt;/a&gt; is, that &lt;code&gt;free()&lt;/code&gt; accepts &lt;code&gt;NULL&lt;/code&gt; as a valid argument.
So it&amp;rsquo;s always possible to use a code pattern like the one shown below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; size &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;calc_amount_of_bytes&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (size &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;ptr) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// allocation error detected!
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;free&lt;/span&gt;(ptr);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;If you know a recent system where this code fails for allocation of zero
size, I&amp;rsquo;d like to &lt;a href=&#34;mailto:blog@tzimmermann.org&#34;&gt;hear about&lt;/a&gt; it.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we investigated different patterns for testing
for failed allocations.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;malloc()&lt;/code&gt; returns &lt;code&gt;NULL&lt;/code&gt; on errors.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;malloc()&lt;/code&gt; may return &lt;code&gt;NULL&lt;/code&gt; for zero-size allocations.&lt;/li&gt;
&lt;li&gt;Testing the returned value does not work reliably with zero-size
allocations.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;malloc()&lt;/code&gt; is allowed to modify &lt;code&gt;errno&lt;/code&gt; during successful allocations.&lt;/li&gt;
&lt;li&gt;Testing the returned error code does not work reliably.&lt;/li&gt;
&lt;li&gt;Testing the returned value iff the allocation size is larger than zero
works reliably on modern systems.&lt;/li&gt;
&lt;li&gt;A &lt;code&gt;NULL&lt;/code&gt; pointer returned by a zero-size allocation is accepted by
&lt;code&gt;free()&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;errata&#34;&gt;Errata&lt;/h4&gt;
&lt;p&gt;&lt;em&gt;2017-10-06: C11 defect report &lt;a href=&#34;http://www.open-std.org/jtc1/sc22/wg14/www/docs/n2109.htm#dr_400&#34;&gt;DR 400&lt;/a&gt; changes the specification
for zero-size allocations to return NULL to indicate an error, or behave as
if a non-zero value had been requested. So iff you&amp;rsquo;re using a conforming
implementation of C11, only testing for NULL should work in all situatons.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;If you like this blog post about memory allocation, please subscribe to
the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>The Internals of Unix Pipes and FIFOs</title>
      <link>https://tzimmermann.org/2017/09/01/the-internals-of-unix-pipes-and-fifos/</link>
      <pubDate>Fri, 01 Sep 2017 14:30:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/09/01/the-internals-of-unix-pipes-and-fifos/</guid>
      <description>&lt;p&gt;There is a series of blog posts examining the details of files and
file descriptors, etc on Linux and Unix. This installment continues with the
details of Unix FIFOs, how they work internally, and how they are used for
communicating between processes.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;h4 id=&#34;first-in-first-out&#34;&gt;First-In First-Out&lt;/h4&gt;
&lt;p&gt;A recent &lt;a href=&#34;https://tzimmermann.org/2017/07/28/data-structures-of-unix-file-io/&#34;&gt;series&lt;/a&gt; &lt;a href=&#34;https://tzimmermann.org/2017/08/04/unix-hard-links-soft-links-and-files/&#34;&gt;of&lt;/a&gt; &lt;a href=&#34;https://tzimmermann.org/2017/08/17/file-descriptors-during-fork-and-exec/&#34;&gt;posts&lt;/a&gt;
on this blog describes the data structures surrounding Unix file I/O, such
as file buffers, open file descriptions, and file descriptors; how they work
together and interact with the file system. In these entries we mostly
focused on regular files, which have a representation in the file system
and a data buffer that is stored on a disk.&lt;/p&gt;
&lt;p&gt;From the previous blog entries, remember how we opened a file twice
and got a number of unique and shared data structures.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;open&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_file.txt&amp;#34;&lt;/span&gt;, O_RDWR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;O_CREAT, S_IRUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IWUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IRGRP);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;open&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_file.txt&amp;#34;&lt;/span&gt;, O_RDWR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;O_CREAT, S_IRUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IWUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IRGRP);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;img src=&#34;https://tzimmermann.org/2017/07/28/data-structures-of-unix-file-io/unix2.png&#34; alt=&#34;Data structures after opening /home/joe_user/my_file.txt twice.&#34;&gt;&lt;/p&gt;
&lt;p&gt;In this example we opened the file &lt;code&gt;/home/joe_user/my_file.txt&lt;/code&gt; twice
and got two file descriptors, each refering to its own open file
description. Both open file descriptions refer to the same file buffer,
which holds the file&amp;rsquo;s content. Using a FIFO is similar to this example,
but the involved buffer data structure is very different.&lt;/p&gt;
&lt;p&gt;A &lt;em&gt;FIFO (first-in first-out)&lt;/em&gt; is a data buffer with a write end and a read
end. Data is written on one end of the data buffer, and read from the other
end.&lt;/p&gt;
&lt;p&gt;FIFOs were invented in the early 1970s by Douglas McIlroy. They were first
included in Unix Version 5, released in 1974. As we&amp;rsquo;ll see below, FIFOs allow
for connecting the output of one program to the input of another program.
This makes them one of the building blocks of what is considered to be Unix.&lt;/p&gt;
&lt;h4 id=&#34;using-and-creating-fifos&#34;&gt;Using and Creating FIFOs&lt;/h4&gt;
&lt;p&gt;Let&amp;rsquo;s first create a FIFO and see what happens. FIFOs are also called
pipes, so the Unix function to create a pipe is called &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/pipe.html&#34;&gt;&lt;code&gt;pipe()&lt;/code&gt;&lt;/a&gt;
as well.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; pipefd[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;pipe&lt;/span&gt;(pipe[fd]);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;A call to &lt;code&gt;pipe()&lt;/code&gt; creates two file descriptors, which are returned
in the array that &lt;code&gt;pipe()&lt;/code&gt; takes as its argument. In the example, the file
descriptor for reading is stored in &lt;code&gt;pipefd[0]&lt;/code&gt; and the file descriptor
for writing is stored in &lt;code&gt;pipefd[1]&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;After calling &lt;code&gt;pipe()&lt;/code&gt;, the data structures look very similar to the
case where we opened a file twice. For the purpose of illustration,
process-local data structures are shown in light-blue color.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;pipe1.png&#34; alt=&#34;Data structures after creating a pipe.&#34;&gt;&lt;/p&gt;
&lt;p&gt;As mentioned we have created two new file descriptors. Each refers to an
open file description. Each open file description of the FIFO stores whether
it&amp;rsquo;s on the read end or the write end. Both open file descriptions refer to
the same FIFO buffer, which the kernel just created.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s write to our new pipe. The interface for writing and reading is the
same as for files. Each end of a FIFO is represented by a file descriptor.
A call to &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/write.html&#34;&gt;&lt;code&gt;write()&lt;/code&gt;&lt;/a&gt; writes to the write end, a call to
&lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/read.html&#34;&gt;&lt;code&gt;read()&lt;/code&gt;&lt;/a&gt; read from the read end.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; string[] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Hello world!&amp;#34;&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;write&lt;/span&gt;(pipefd[&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;], string, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(string));
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The FIFO buffer now contains the string &lt;em&gt;Hello world!&lt;/em&gt;. We can read it
using the other file descriptor.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; buf[&lt;span style=&#34;color:#ae81ff&#34;&gt;13&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;read&lt;/span&gt;(pipefd[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;], buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(buf));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;// buf now contains `Hello world!`
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Reading transfers the content of the FIFO buffer into the read buffer and
removes the read data from the FIFO buffer.&lt;/p&gt;
&lt;p&gt;Although the FIFO buffer might look similar to a file buffer at first, it
works in a different way.&lt;/p&gt;
&lt;p&gt;First of all, there is no actual buffer on the disk drive. A FIFO buffer is
only contained in memory. So when the system shuts down, its content is gone.&lt;/p&gt;
&lt;p&gt;A FIFO is a channel with a single direction and the order of data is
preserved. So when we write &lt;code&gt;Hello world!&lt;/code&gt; on the write end, we will later
read &lt;code&gt;Hello world!&lt;/code&gt; on the read end; but never &lt;code&gt;world! Hello&lt;/code&gt; or
&lt;code&gt;Ehlol Rwold!&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;When accessing a file buffer, we can select the location of where the read
or write operation takes place. Because there is only a write end and a read
end for a FIFO, it&amp;rsquo;s not possible to select the location. If we wrote
&lt;em&gt;Hello world!&lt;/em&gt; in the example, there&amp;rsquo;s no way to only read &lt;em&gt;world!&lt;/em&gt; without
reading &lt;em&gt;Hello&lt;/em&gt; first.&lt;/p&gt;
&lt;h4 id=&#34;duplicating-and-closing-fifos&#34;&gt;Duplicating and Closing FIFOs&lt;/h4&gt;
&lt;p&gt;A file can be duplicated by simply copying it to a new location in the file
system. For FIFO buffers it&amp;rsquo;s not possible to duplicate them in any similar
way. All we can do is to duplicate the file descriptor using
&lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/dup.html&#34;&gt;&lt;code&gt;dup()&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;read_fd &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;dup&lt;/span&gt;(pipefd[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;]);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;write_fd &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;dup&lt;/span&gt;(pipefd[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;]);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;These duplicated file descriptors work exactly the way that the original
file descriptors worked.&lt;/p&gt;
&lt;p&gt;As with all file descriptors, the read and write ends of a pipe are closed
using &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/close.html&#34;&gt;&lt;code&gt;close()&lt;/code&gt;&lt;/a&gt;. The kernel releases the FIFO buffer after
all its file descriptors have been closed.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;close&lt;/span&gt;(read_fd);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;close&lt;/span&gt;(write_fd);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;inter-process-communication-using-fifos&#34;&gt;Inter-Process Communication using FIFOs&lt;/h4&gt;
&lt;p&gt;Now that we&amp;rsquo;ve looked at the interface, let&amp;rsquo;s see what FIFOs are actually
used for. By far the most common usage of FIFOs is to communicate between
processes.&lt;/p&gt;
&lt;p&gt;In the previous example, we already created a FIFO with a call to &lt;code&gt;pipe()&lt;/code&gt;.
Let&amp;rsquo;s now duplicate the process using &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/fork.html&#34;&gt;&lt;code&gt;fork()&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; pipefd[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;pipe&lt;/span&gt;(pipefd);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;fork&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;As we have seen in previous blog entries, a call to &lt;code&gt;fork()&lt;/code&gt; only copies the
process-local file descriptors, but the underlying buffers an open file
descriptions are shared by the old and the new process. So our data
structures now look like this.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;pipe2.png&#34; alt=&#34;Data structures after creating a pipe.&#34;&gt;&lt;/p&gt;
&lt;p&gt;It might seem confusing at first, but what this diagram shows is a FIFO
with read and write end, and two processes that each have a file descriptor
refering to either end of the FIFO. The old process&amp;rsquo; data structures are
again shown in light-blue color, the new process&amp;rsquo; data structures are shown
in orange color.&lt;/p&gt;
&lt;p&gt;We can now communicate between processes using &lt;code&gt;read()&lt;/code&gt; and &lt;code&gt;write()&lt;/code&gt; as in
the examples above. If we write to the FIFO in the old process&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; string[] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Hello world!&amp;#34;&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;write&lt;/span&gt;(pipefd[&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;], string, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(string));
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;the new process can read the data from the FIFO.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; buf[&lt;span style=&#34;color:#ae81ff&#34;&gt;13&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;read&lt;/span&gt;(pipefd[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;], buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(buf));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;// buf now contains `Hello world!`
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Currently both processes can access both ends of the FIFO buffer. In
practice each process would close one end of the FIFO, such that there
is one writer and one reader. For bi-directional communication, there would
be a second FIFO and processes would act in opposite roles.&lt;/p&gt;
&lt;h4 id=&#34;an-excursus-on-the-shell&#34;&gt;An Excursus on the Shell&lt;/h4&gt;
&lt;p&gt;Using FIFOs, a Unix terminal allows us connect the input and output of
different programs.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-sh&#34; data-lang=&#34;sh&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;cat /home/joe_user/my_file.txt | less
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This command starts two programs &lt;code&gt;cat&lt;/code&gt; and &lt;code&gt;less&lt;/code&gt;. The call to &lt;code&gt;cat&lt;/code&gt; reads
the content of the file &lt;code&gt;/home/joe_user/my_file.txt&lt;/code&gt; and writes it to its
standard output. The call to &lt;code&gt;less&lt;/code&gt; reads text from its standard input and
display it to the user.&lt;/p&gt;
&lt;p&gt;There&amp;rsquo;s also a pipe symbol &lt;code&gt;|&lt;/code&gt; between them. This instructs the Unix shell
to connect both programs using a FIFO. The shell creates a pipe, creates the
two processes and makes the FIFO&amp;rsquo;s write end the standard output of &lt;code&gt;cat&lt;/code&gt;.
The FIFO&amp;rsquo;s read end becomes the standard input of &lt;code&gt;less&lt;/code&gt;. After that, each
process executes either the &lt;code&gt;cat&lt;/code&gt; or the &lt;code&gt;less&lt;/code&gt; program. Anything written
by &lt;code&gt;cat&lt;/code&gt; goes into the FIFO, and anything read by &lt;code&gt;less&lt;/code&gt; comes out of the
FIFO.&lt;/p&gt;
&lt;h4 id=&#34;named-pipes&#34;&gt;Named Pipes&lt;/h4&gt;
&lt;p&gt;With the pipes that we&amp;rsquo;ve seen so far, there has to be some kind of
relationship between communicating processes. One must be a copy of the
other, or both must have the same parent process. Otherwise it would not
be possible for them to refer the same FIFO buffer. So if we have two
unrelated processes, they cannot communicate this way.&lt;/p&gt;
&lt;p&gt;The solution to this problem are named pipes. A &lt;em&gt;named pipe&lt;/em&gt; is a special
kind of file that has a name in the file system, but refers to a FIFO
buffer.&lt;/p&gt;
&lt;p&gt;We can create a named pipe with a call to &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/mkfifo.html&#34;&gt;&lt;code&gt;mkfifo()&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;mkfifo&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_fifo&amp;#34;&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Here we create a named pipe with the name &lt;code&gt;/home/joe_user/my_fifo&lt;/code&gt; and the
default file-mode flags. It&amp;rsquo;s path is now present in the file system.&lt;/p&gt;
&lt;p&gt;And just like with a regular file, a process opens a named pipe with a call
to &lt;code&gt;open()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;open&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_fifo&amp;#34;&lt;/span&gt;, O_RDONLY);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;open&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_fifo&amp;#34;&lt;/span&gt;, O_WRONLY);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;After opening the named pipe at least once for reading and at least once for
writing, it is usable. Because these calls to &lt;code&gt;open()&lt;/code&gt; can happen in any
process with permission to access the file path, arbitrary programs can
communicate using a named pipe.&lt;/p&gt;
&lt;p&gt;The big difference to regular files is that the name pipe refers to a FIFO
buffer. There is still no file buffer on the disk and as soon as the system
shuts down, any un-read content of the named pipe is lost.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we discussed usage and data structures of FIFOs on
Unix systems.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;FIFOs, also known as pipes, are data buffers with a write end and a
read end.&lt;/li&gt;
&lt;li&gt;Data written to a FIFOs write end is read from the read end in the
same order.&lt;/li&gt;
&lt;li&gt;A pipe is created using the &lt;code&gt;pipe()&lt;/code&gt; function.&lt;/li&gt;
&lt;li&gt;Reading and writing on a FIFO is performed with &lt;code&gt;read()&lt;/code&gt; and &lt;code&gt;write()&lt;/code&gt;
in the same way as with regular files.&lt;/li&gt;
&lt;li&gt;It is not possible to skip or ignore data while reading.&lt;/li&gt;
&lt;li&gt;Pipes are used for communication between related programs.&lt;/li&gt;
&lt;li&gt;A named pipe is a FIFO with a representation in the file system.&lt;/li&gt;
&lt;li&gt;Names pipes can be opened by arbitrary processes and allow unrelated
programs to communicate with each other.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you like this blog post about the basics of Unix file I/O, please
subscribe to the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>The Strange strerror_r() of Dr POSIX and Mr GNU</title>
      <link>https://tzimmermann.org/2017/08/25/the-strange_strerror_r_of_dr_posix_and_mr_gnu/</link>
      <pubDate>Fri, 25 Aug 2017 10:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/08/25/the-strange_strerror_r_of_dr_posix_and_mr_gnu/</guid>
      <description>&lt;p&gt;There are several variants of the C function
&lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/strerror_r.html&#34;&gt;&lt;code&gt;strerror_r()&lt;/code&gt;&lt;/a&gt; that differ in their return value and
error handling. This blog post describes how to support all of them in a
transactional interface, while still being compatible with either internal
implementation. As such, &lt;code&gt;strerror_r()&lt;/code&gt; serves as a case study for
transactional interfaces with multiple or variable semantics.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;This blog post builds on previous entries about transactional C code and
system-level transactions. If you missed earlier entries in the
&lt;a href=&#34;https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/&#34;&gt;series&lt;/a&gt;,
&lt;a href=&#34;https://tzimmermann.org/2017/05/09/transactional-semantics-in-theory-and-practice/&#34;&gt;you&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/12/transaction-roll-back-and-serializability/&#34;&gt;might&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/&#34;&gt;want&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/26/transactional-access-to-arbitrary-memory-locations/&#34;&gt;to&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/01/transactional-memcpy-and-resource-privatization/&#34;&gt;go&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/09/more-on-resource-privatization/&#34;&gt;back&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/16/transaction-logs/&#34;&gt;and&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/23/transactional-malloc-and-free/&#34;&gt;read&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/30/everything-about-errno-plus-transactions/&#34;&gt;the&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/07/07/types-of-transactional-operations/&#34;&gt;installments&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/07/14/building-fault-tolerant-software-with-transactions/&#34;&gt;so&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/07/21/implementing-fault-tolerant-software-with-transactions/&#34;&gt;far&lt;/a&gt;.&lt;/p&gt;
&lt;h4 id=&#34;the-old-single-threaded-times&#34;&gt;The Old, Single-threaded Times&lt;/h4&gt;
&lt;p&gt;The original C &lt;code&gt;strerror()&lt;/code&gt; function returns a descriptive string for
each &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/errno.html&#34;&gt;&lt;code&gt;errno&lt;/code&gt;&lt;/a&gt; constant, as shown below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; str &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strerror&lt;/span&gt;(ENOMEM);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;%s&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, str); &lt;span style=&#34;color:#75715e&#34;&gt;// prints &amp;#34;Out of memory&amp;#34;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The example retrieves and prints a description of the errno code &lt;code&gt;ENOMEM&lt;/code&gt;,
which results in an output like &lt;code&gt;Out of memory&lt;/code&gt; or a similar text.&lt;/p&gt;
&lt;p&gt;This works well in a single-threaded program, but fails in multi-threaded
software. &lt;code&gt;strerror()&lt;/code&gt; is allowed to use an internal buffer for constructing
and storing the returned string. The buffer is shared among all threads, so
if multiple threads execute the function at the same time, they overwrite
each other&amp;rsquo;s error strings.&lt;/p&gt;
&lt;h4 id=&#34;the-multi-threaded-interface&#34;&gt;The Multi-threaded Interface&lt;/h4&gt;
&lt;p&gt;The function &lt;code&gt;strerror_r()&lt;/code&gt; is a variant of &lt;code&gt;strerror&lt;/code&gt; that is suitable for
multi-threaded environments. As typical for thread-safe interfaces of the C
standard library, &lt;code&gt;strerror_r()&lt;/code&gt; takes an additional argument that provides
thread-local memory for its internal operations. In this case it&amp;rsquo;s a string
buffer and the buffer length.&lt;/p&gt;
&lt;p&gt;Rewriting our previous example with &lt;code&gt;strerror_r()&lt;/code&gt; we get the following
code.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; buf[&lt;span style=&#34;color:#ae81ff&#34;&gt;256&lt;/span&gt;]; &lt;span style=&#34;color:#75715e&#34;&gt;// large-enough string buffer
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; str &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strerror_r&lt;/span&gt;(ENOMEM, buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(buf));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;%s&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, str); &lt;span style=&#34;color:#75715e&#34;&gt;// prints &amp;#34;Out of memory&amp;#34;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Any temporary error string is stored in the supplied memory of &lt;code&gt;buf&lt;/code&gt;, which
is owned by the current thread.&lt;/p&gt;
&lt;h4 id=&#34;the-gnu-interface&#34;&gt;The GNU Interface&lt;/h4&gt;
&lt;p&gt;The function &lt;code&gt;strerror_r()&lt;/code&gt; in the example returns a pointer to the error
string, which is possibly stored in the memory of &lt;code&gt;buf&lt;/code&gt;. This is the &lt;a href=&#34;https://www.gnu.org/software/libc/manual/html_node/Error-Messages.html#index-strerror_005fr&#34;&gt;GNU
definition of &lt;code&gt;strerror_r()&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The GNU variant returns an internal string for known errors, or copies
something like &lt;code&gt;Unknown error code&lt;/code&gt; into the provided buffer and returns
the buffer&amp;rsquo;s address. In any case no error is returned.&lt;/p&gt;
&lt;h4 id=&#34;the-posix-interface&#34;&gt;The POSIX Interface&lt;/h4&gt;
&lt;p&gt;The GNU interface probably existed before &lt;code&gt;strerror_r()&lt;/code&gt; was standardized
by POSIX in 2001. Unfortunately the POSIX interface works differently. Here
again our example.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; buf[&lt;span style=&#34;color:#ae81ff&#34;&gt;256&lt;/span&gt;]; &lt;span style=&#34;color:#75715e&#34;&gt;// large-enough string buffer
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; err &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strerror_r&lt;/span&gt;(ENOMEM, buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(buf));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (err) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// handle error stored in err
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;%s&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, buf); &lt;span style=&#34;color:#75715e&#34;&gt;// prints &amp;#34;Out of memory&amp;#34;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The variant of &lt;code&gt;strerror_r()&lt;/code&gt; as standardized by POSIX returns an integer
value that signals the success or failure of the operation. If &lt;code&gt;strerror_r()&lt;/code&gt;
succeeds, it returns a value of &lt;em&gt;0.&lt;/em&gt; The provided buffer now contains the
error string. If it returns the constant &lt;code&gt;EINVAL&lt;/code&gt;, the provided &lt;code&gt;errno&lt;/code&gt;
constant is unknown and the buffer is still empty. If &lt;code&gt;strerror_r()&lt;/code&gt; returns
the constant &lt;code&gt;ERANGE&lt;/code&gt;, the provided buffer space is too small to store the
error string and the caller is supposed to provide a larger buffer.&lt;/p&gt;
&lt;h4 id=&#34;the-semi-posix-interface-in-older-glibc&#34;&gt;The Semi-POSIX Interface in Older glibc&lt;/h4&gt;
&lt;p&gt;In the GNU C library before release 2.13, there exists yet another variant
of &lt;code&gt;strerror_r()&lt;/code&gt;. It&amp;rsquo;s similar to the POSIX variant, but returns &lt;code&gt;-1&lt;/code&gt; on
errors and stores the error code in &lt;code&gt;errno&lt;/code&gt;. Using that variant, our example
looks like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; buf[&lt;span style=&#34;color:#ae81ff&#34;&gt;256&lt;/span&gt;]; &lt;span style=&#34;color:#75715e&#34;&gt;// large-enough string buffer
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; res &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strerror_r&lt;/span&gt;(ENOMEM, buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(buf));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// handle error stored in errno
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;%s&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, buf); &lt;span style=&#34;color:#75715e&#34;&gt;// prints &amp;#34;Out of memory&amp;#34;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;I tried to find out more about the origins of this variant, but was not
successful so far. I guess that the use of different semantics were either
an oversite, or it was part of some other standard or system that pre-dates
POSIX 2001.&lt;/p&gt;
&lt;h4 id=&#34;the-transactional-interface&#34;&gt;The Transactional Interface&lt;/h4&gt;
&lt;p&gt;For using &lt;code&gt;strerror_r()&lt;/code&gt; from within transactions, we have to provide a
transaction-safe wrapper function. This function has to protect all
input parameters from concurrent access and handle returned errors by
starting the transaction&amp;rsquo;s recovery code.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s start with providing a transactional interface that users can call. In
the GNU C library, which we&amp;rsquo;ll use for the rest of this discussion, all
variants of &lt;code&gt;strerror_r()&lt;/code&gt; exist in one way or the other. To make them work,
we create two internal interfaces; one for GNU and one for POSIX.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;__strerror_r_gnu_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; errnum, &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; buflen);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;__strerror_r_posix_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; errnum, &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; buflen);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Which one is used by the caller depends on the compile-time flags of the
caller&amp;rsquo;s program. The POSIX declararion is provided by defining
&lt;code&gt;_POSIX_C_SOURCE &amp;gt;= 200112L)&lt;/code&gt; and undefining &lt;code&gt;_GNU_SOURCE&lt;/code&gt; in the
C preprocessor. This means that if we follow POSIX &lt;em&gt;and&lt;/em&gt; disallow GNU
extenions, we get the POSIX variant, otherwise we get the GNU variant.&lt;/p&gt;
&lt;p&gt;Our transactional &lt;code&gt;strerror_r()&lt;/code&gt; is called &lt;code&gt;strerror_r_tx()&lt;/code&gt;. We provide it
as a C pre-processor macro that switches between the variants.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#if (_POSIX_C_SOURCE &amp;gt;= 200112L) &amp;amp;&amp;amp; !_GNU_SOURCE
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define strerror_r_tx   __strerror_r_posix_tx
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#else
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define strerror_r_tx   __strerror_r_gnu_tx
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#endif
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This was easy. If we follow POSIX strictly, a call to &lt;code&gt;strerror_r_tx()&lt;/code&gt;
will result in invoking &lt;code&gt;__strerror_r_posix_tx()&lt;/code&gt;, otherwise
&lt;code&gt;__strerror_r_gnu_tx()&lt;/code&gt;.&lt;/p&gt;
&lt;h4 id=&#34;the-transactional-gnu-implementation&#34;&gt;The Transactional GNU Implementation&lt;/h4&gt;
&lt;p&gt;We implement the transactional GNU and POSIX interfaces with either
&lt;code&gt;__strerror_r_posix_tx()&lt;/code&gt; or &lt;code&gt;__strerror_r_gnu_tx()&lt;/code&gt;. These functions are
part of the transaction system and we always have to provide both because
we don&amp;rsquo;t know if the caller&amp;rsquo;s program is build against one or the other.
Depending on the transaction system&amp;rsquo;s compile-time flags, either function&amp;rsquo;s
implementation could in turn use the GNU or the POSIX implementation
internally.&lt;/p&gt;
&lt;p&gt;For simplicity, let&amp;rsquo;s strip down the example code to the minimum. Here&amp;rsquo;s the
transactional GNU implementation.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;__strerror_r_gnu_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; errnum, &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; buflen);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// protect buf from concurrent access here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// save errno here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; str;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#if (_POSIX_C_SOURCE &amp;gt;= 200112L) &amp;amp;&amp;amp; !_GNU_SOURCE
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// POSIX
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; tmpbuf[&lt;span style=&#34;color:#ae81ff&#34;&gt;256&lt;/span&gt;]; &lt;span style=&#34;color:#75715e&#34;&gt;// large-enough buffer for all error strings
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; res &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strerror_r&lt;/span&gt;(errnum, tmpbuf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(tmpbuf));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// TODO: error handling
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (buflen) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; tmplen &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strlen&lt;/span&gt;(tmpbuf);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        str &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;memcpy&lt;/span&gt;(buf, tmpbuf, &lt;span style=&#34;color:#a6e22e&#34;&gt;MIN&lt;/span&gt;(tmplen &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, buflen));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        str[&lt;span style=&#34;color:#a6e22e&#34;&gt;MIN&lt;/span&gt;(tmplen, buflen &lt;span style=&#34;color:#f92672&#34;&gt;-&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;)] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#39;\0&amp;#39;&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#else
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// GNU
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    str &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strerror_r&lt;/span&gt;(errnum, buf, buflen);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#endif
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; str;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In the example, we first protect the input buffer against concurrent access
and save the state of &lt;code&gt;errno&lt;/code&gt;. Other modules of the transactional system do
this for us, so it&amp;rsquo;s left out here. If you&amp;rsquo;re curious, previous entries in
this blog explain how it works.&lt;/p&gt;
&lt;p&gt;If we implement &lt;code&gt;__strerror_r_gnu_tx&lt;/code&gt; with the GNU variant, there&amp;rsquo;s nothing
we have to do. Just wrap the function.&lt;/p&gt;
&lt;p&gt;If we implement &lt;code&gt;__strerror_r_gnu_tx&lt;/code&gt; with the POSIX variant, we execute it
with the temporary buffer &lt;code&gt;tmpbuf&lt;/code&gt; and copy the result into the
caller-provided buffer. The point of using a temporary buffer is to avoid
&lt;code&gt;strerror_r()&lt;/code&gt; return the error code &lt;code&gt;ERANGE&lt;/code&gt;. For this reason the memory
in &lt;code&gt;tmpbuf&lt;/code&gt; must be large enough to hold &lt;em&gt;any&lt;/em&gt; string returned by POSIX&#39;
&lt;code&gt;strerror_r()&lt;/code&gt;. When we later copy the temporary buffer to the output buffer,
we can cut-off any trailing bytes that do not fit into the output buffer.&lt;/p&gt;
&lt;p&gt;There&amp;rsquo;s one TODO comment left in the example. It&amp;rsquo;s the error handling for
&lt;code&gt;strerror_r()&lt;/code&gt;. Let&amp;rsquo;s add this.&lt;/p&gt;
&lt;p&gt;First of all, there are three cases to handle here. A return value of &lt;em&gt;0&lt;/em&gt;
always signals success. A negative return value signals an error with glibc
before 2.13 and the error is stored in &lt;code&gt;errno&lt;/code&gt;. A positive return value
signals an error with glibc 2.13 and later, and the error is the returned
value itself.&lt;/p&gt;
&lt;p&gt;Second, we can handle the error code of &lt;code&gt;EINVAL&lt;/code&gt;, which signals an unknown
error code, by manually creating an appropriate string. The error code
&lt;code&gt;ERANGE&lt;/code&gt;, which signals that the provided buffer is too small, is avoided
by choosing the size of &lt;code&gt;tmpbuf&lt;/code&gt; accordingly. If we see any other error,
we have to run the transaction&amp;rsquo;s error recovery, as required by transactional
semantics.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s fill in the error handling.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;handle_errnum&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; errnum, &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (errnum &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; EINVAL) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;memcpy&lt;/span&gt;(buf, &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Unknown error code&amp;#34;&lt;/span&gt;, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Unknown error code&amp;#34;&lt;/span&gt;));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// invoke transactional error recovery here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;__strerror_r_gnu_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; errnum, &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; buflen)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// protect buf from concurrent access here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// save errno here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; str;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#if (_POSIX_C_SOURCE &amp;gt;= 200112L) &amp;amp;&amp;amp; !_GNU_SOURCE
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// POSIX
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; tmpbuf[&lt;span style=&#34;color:#ae81ff&#34;&gt;256&lt;/span&gt;]; &lt;span style=&#34;color:#75715e&#34;&gt;// large-enough buffer for all error strings
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; res &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strerror_r&lt;/span&gt;(errnum, tmpbuf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(tmpbuf));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;) { &lt;span style=&#34;color:#75715e&#34;&gt;// glibc &amp;lt; 2.13
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;handle_errnum&lt;/span&gt;(errno, tmpbuf);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res) { &lt;span style=&#34;color:#75715e&#34;&gt;// glibc &amp;gt;= 2.13
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;handle_errnum&lt;/span&gt;(res, tmpbuf);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (buflen) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; tmplen &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strlen&lt;/span&gt;(tmpbuf);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        str &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;memcpy&lt;/span&gt;(buf, tmpbuf, &lt;span style=&#34;color:#a6e22e&#34;&gt;MIN&lt;/span&gt;(tmplen &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, buflen));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        str[&lt;span style=&#34;color:#a6e22e&#34;&gt;MIN&lt;/span&gt;(tmplen, buflen &lt;span style=&#34;color:#f92672&#34;&gt;-&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;)] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#39;\0&amp;#39;&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        str &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; buf;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#else
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// GNU
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    str &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strerror_r&lt;/span&gt;(errnum, buf, buflen);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#endif
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; str;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;the-transactional-posix-implementation&#34;&gt;The Transactional POSIX Implementation&lt;/h4&gt;
&lt;p&gt;After building the transactional GNU implementation, we need a similar
implementation for the POSIX variant &lt;code&gt;__strerror_r_posix_tx&lt;/code&gt;. This time we
implement the POSIX declaration with either the GNU implementation or the
POSIX implementation itself. Therefore we have to return an integer value.&lt;/p&gt;
&lt;p&gt;There&amp;rsquo;s one interesting corner case here. While &lt;code&gt;ERANGE&lt;/code&gt;, the buffer-too-small
signal, is technically an error, it&amp;rsquo;s not actually used as such. A transaction
might want to call the function with an initial buffer, check for &lt;code&gt;ERANGE&lt;/code&gt;, and
grow the buffer until the error string fits in. So &lt;code&gt;ERANGE&lt;/code&gt; is not an error,
but a status code. That&amp;rsquo;s a valid pattern and our transactional implementation
should be able to support it.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;__strerror_r_posix_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; errnum, &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; buflen)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// protect buf from concurrent access here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// save errno here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#if (_POSIX_C_SOURCE &amp;gt;= 200112L) &amp;amp;&amp;amp; !_GNU_SOURCE
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// POSIX
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; res &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strerror_r&lt;/span&gt;(errnum, buf, buflen);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;) { &lt;span style=&#34;color:#75715e&#34;&gt;// glibc &amp;lt; 2.13
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (errno &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; ERANGE) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; res;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#75715e&#34;&gt;// invoke transactional error recovery here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res) { &lt;span style=&#34;color:#75715e&#34;&gt;// glibc &amp;gt;= 2.13
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; ERANGE) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; res;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#75715e&#34;&gt;// invoke transactional error recovery here
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#else
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;// GNU
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt; tmpbuf[&lt;span style=&#34;color:#ae81ff&#34;&gt;256&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; str &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strerror_r&lt;/span&gt;(errnum, tmpbuf, tmplen);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (str &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; tmpbuf) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;// invoke transactional error recovery for EINVAL
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#a6e22e&#34;&gt;strlen&lt;/span&gt;(str) &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;&amp;gt;&lt;/span&gt; buflen) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (glibc version &lt;span style=&#34;color:#f92672&#34;&gt;&amp;gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;2.13&lt;/span&gt;) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; ERANGE;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            errno &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; ERANGE;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;-&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;mempcy&lt;/span&gt;(buf, str, &lt;span style=&#34;color:#a6e22e&#34;&gt;strlen&lt;/span&gt;(str) &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#endif
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;As before, we first protect the input input buffer against concurrent access
and save the value of errno.&lt;/p&gt;
&lt;p&gt;If the first case, where we use the POSIX implementation of &lt;code&gt;strerror_r()&lt;/code&gt;,
we check the return value for possible errors. As before, we have to handle
different versions of the glibc differently. If we see an error of type
&lt;code&gt;ERANGE&lt;/code&gt;, we return it to the calling transaction. That&amp;rsquo;s the case were the
error is actually a status code. The other possible error, &lt;code&gt;EINVAL&lt;/code&gt;, is
actually an error and triggers transactional error recovery.&lt;/p&gt;
&lt;p&gt;In the second case, we use the GNU implementation of &lt;code&gt;strerror_r()&lt;/code&gt;. As
mentioned before, the GNU code does not return errors at all. To detect
&lt;code&gt;ERANGE&lt;/code&gt; and &lt;code&gt;EINVAL&lt;/code&gt;, we need other means.&lt;/p&gt;
&lt;p&gt;The GNU implementation has an interesting property that we can use to our
advantage: it only uses the provided buffer for unknown error codes. For every
known error code it returns a pointer to an internal static string. In our
example we call the GNU implementation with a temporary buffer. If the
returned string pointer has the same address as the temporary buffer, GNU&amp;rsquo;s
&lt;code&gt;strerror_r()&lt;/code&gt; generated an &lt;code&gt;Unknown error code&lt;/code&gt; message. In this case we
invoke the transaction&amp;rsquo;s recovery code as if we had seen &lt;code&gt;EINVAL&lt;/code&gt;. If the
addresses differ, we got an internal static string, so the error code is a
known one.&lt;/p&gt;
&lt;p&gt;The other error, &lt;code&gt;ERANGE&lt;/code&gt;, is detected by comparing the size of the provided
buffer with the length of the error string. If the error string does not fit
into the buffer, we return &lt;code&gt;ERANGE&lt;/code&gt; to the calling transaction. The
transaction can now resize the buffer and try again.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In blog post, we examined the details of implementing a transactional variant
of &lt;code&gt;strerror_r()&lt;/code&gt;, a C function with varying interfaces and semantics.&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; It
serves as a case study for code with similar properties.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;strerror_r()&lt;/code&gt; generates an error string for a given &lt;code&gt;errno&lt;/code&gt; node. It
possibly stores the string in a caller-provided output buffer.&lt;/li&gt;
&lt;li&gt;The GNU implementation returns a pointer to the error string.&lt;/li&gt;
&lt;li&gt;The POSIX implementation return an integer signalling errors and stores
the string in the provided buffer.&lt;/li&gt;
&lt;li&gt;The semi-POSIX impementation returns an integer signalling success or
failure and stores the error code in &lt;code&gt;errno&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Depending on their compile-time flags, users may call the GNU or POSIX
variant. Therefore we have to provide a transactional implementation for
each.&lt;/li&gt;
&lt;li&gt;The transactional implementations have to ensure compatiblity with the
semantics of the non-transactional implementations.&lt;/li&gt;
&lt;li&gt;Some error codes, such as ERANGE, might not be errors, but allow for
specific programming patterns. The transactional implementations have
to support these corner cases.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you like this series about writing a transaction manager in C, please
subscribe to the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
&lt;h4 id=&#34;footnotes&#34;&gt;Footnotes&lt;/h4&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;To add a personal opinion here, the only useful variant of these
interfaces is the one specified by GNU. When we call &lt;code&gt;strerror_r()&lt;/code&gt;
we&amp;rsquo;re probably already in the middle of handling an error. The last
thing we want is to deal with additional errors coming from the
error-reporting code. To me, returning a static error string or
whatever fits into the provided output buffer is acceptable and
sane semantics for &lt;code&gt;strerror_r()&lt;/code&gt;.&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</description>
    </item>
    
    
    
    <item>
      <title>File Descriptors During fork() and exec()</title>
      <link>https://tzimmermann.org/2017/08/17/file-descriptors-during-fork-and-exec/</link>
      <pubDate>Thu, 17 Aug 2017 16:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/08/17/file-descriptors-during-fork-and-exec/</guid>
      <description>&lt;p&gt;In the previous blog posts, we examined the relationship between files,
file names, file descriptors, and open file descriptions. This time we look
at what happens to file descriptors when we start a new program by calling
&lt;code&gt;fork()&lt;/code&gt; and &lt;code&gt;exec()&lt;/code&gt;.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;h4 id=&#34;opening-a-file&#34;&gt;Opening a File&lt;/h4&gt;
&lt;p&gt;As in previous examples, let&amp;rsquo;s &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html&#34;&gt;open&lt;/a&gt; a file on the file system.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;open&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_file.txt&amp;#34;&lt;/span&gt;, O_RDWR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;O_CREAT, S_IRUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IWUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IRGRP);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This creates a file descriptor, an open file description, and a file buffer.
The following graph illustrates this, highlighting the per-process structures
in light blue color. A &lt;a href=&#34;https://tzimmermann.org/2017/07/28/data-structures-of-unix-file-io/&#34;&gt;previous blog post&lt;/a&gt; describes the
open procedure in detail.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;unix6.png&#34; alt=&#34;Data structures after opening /home/joe_user/my_file.txt once.&#34;&gt;&lt;/p&gt;
&lt;h4 id=&#34;file-descriptors-and-process-creation&#34;&gt;File Descriptors and Process Creation&lt;/h4&gt;
&lt;p&gt;Right now there&amp;rsquo;s only one Unix process in our example. New processes are
created by a call to &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/fork.html&#34;&gt;&lt;code&gt;fork()&lt;/code&gt;&lt;/a&gt;. Invoking &lt;code&gt;fork()&lt;/code&gt; duplicates
the calling process, such that the new process is a copy of the caller.&lt;/p&gt;
&lt;p&gt;What happens to the file descriptors during a fork? They are part of the
process, so they are copied for the new process. So is the file-descriptor
table.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s call &lt;code&gt;fork()&lt;/code&gt; in our example process.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;fork&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We now have two processes and each has its own file descriptors and
file-descriptor table.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;unix7.png&#34; alt=&#34;Data structures after calling fork().&#34;&gt;&lt;/p&gt;
&lt;p&gt;The process-specific data structures of the original process are still
displayed in a light blue color. The new process&amp;rsquo; data structures are
displayed in orange color. The file descriptor has been duplicated and
refers to the new process&amp;rsquo; file-descriptor table. The file descriptor
table itself is part of the pre-process state and has also been copied
by the call to &lt;code&gt;fork()&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;An important detail of the design of Unix is that the open file
description and the file buffer are are kernel data structures. Therefore
they are not duplicate by &lt;code&gt;fork()&lt;/code&gt;. Consequently, whenever one of the
processes reads from or writes to it&amp;rsquo;s local file descriptor, the effects
in the open file description and file buffer are seen by the other
process.&lt;/p&gt;
&lt;p&gt;On the other hand, operations that work solely on file descriptors, such
as &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/close.html&#34;&gt;&lt;code&gt;close()&lt;/code&gt;&lt;/a&gt; or &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/dup.html&#34;&gt;&lt;code&gt;dup()&lt;/code&gt;&lt;/a&gt; don&amp;rsquo;t effect the other
process. So if either process closes its file descriptor, the other
process doesn&amp;rsquo;t notice.&lt;/p&gt;
&lt;h4 id=&#34;executing-a-different-program&#34;&gt;Executing a Different Program&lt;/h4&gt;
&lt;p&gt;After a call to &lt;code&gt;fork()&lt;/code&gt;, both the original and the new process continue
execution at the next instruction after &lt;code&gt;fork()&lt;/code&gt;. To really execute a
different program, a process invokes &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/execl.html&#34;&gt;&lt;code&gt;execl()&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The &lt;code&gt;execl()&lt;/code&gt; system call instructs the kernel to replace the user-space
program of a process with the program stored in an executable file. A
call to &lt;code&gt;execl()&lt;/code&gt; takes the path of the executable file and a list of
command-line arguments for the new program.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s call &lt;code&gt;execl()&lt;/code&gt; in the new process that we just created with &lt;code&gt;fork()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;execl&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/bin/my_executable&amp;#34;&lt;/span&gt;, NULL);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Our new process will now abandon the original program and execute the
program stored in &lt;code&gt;/bin/my_executable&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;What does this mean for the process&amp;rsquo; file descriptors and
file-descriptor table? Nothing! They are still in place and working as
before. Remember that the user-space file descriptor is really just an
integer index into the file-descriptor table. If the new program reads and
writes using the existing file-descriptor value, it reads and writes the
file opened by the old program. So even after executing a new program,
our diagram looks as before.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;unix7.png&#34; alt=&#34;Data structures after calling fork().&#34;&gt;&lt;/p&gt;
&lt;p&gt;The good thing about this is that it&amp;rsquo;s a nice, generic way of
communicating between programs. For example, when starting a new program
from the Unix terminal, the terminal sets up the program&amp;rsquo;s default input
and output file descriptors to refer to what the terminal itself uses;
let&amp;rsquo;s say keyboard and text screen. If instead the terminal uses a serial
port for input and output, a new program started from the terminal also
uses the serial port. This way the new program inherits these settings
from the terminal. And likewise, as a user we can direct a program&amp;rsquo;s default
input and output file descriptors to anything that looks like a file, such
as pipes, sockets or regular files.&lt;/p&gt;
&lt;p&gt;Unfortuantely, there is also one major drawback of this whole design.
It&amp;rsquo;s too easy to leak file descriptors into a newly executed program. That&amp;rsquo;s
what happened &lt;a href=&#34;http://medium.com/@fun_cuddles/opening-files-in-node-js-considered-harmful-d7de566d499f&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The only standardized file descriptors are those for default input and
output, and the one for error reporting. They are the file descriptors
&lt;em&gt;0,&lt;/em&gt; &lt;em&gt;1&lt;/em&gt; and &lt;em&gt;2&lt;/em&gt; respectively. The newly executed program does not know
about any other file descriptors opened by the process&amp;rsquo; old program.&lt;/p&gt;
&lt;p&gt;This is bad for two reasons. First of all it unnecessarily consumes
resources. The maximum number of file descriptors per process is limited;
typically to &lt;em&gt;1024.&lt;/em&gt; A program can run out of available file descriptors
quickly if it doesn&amp;rsquo;t close file descriptors after their final use.&lt;/p&gt;
&lt;p&gt;An even more sever problem is that the old program can leak information
into the new program that the new program is not supposed to see. A file
descriptor might refer to a file with sensitive data that only the original
program was supposed to access. After the call to &lt;code&gt;execl()&lt;/code&gt; the new program
would be able to read this data as well.&lt;/p&gt;
&lt;p&gt;To prevent this, file descriptors have to be closed &lt;em&gt;before&lt;/em&gt; the new program
gets loaded by the kernel. Fortunately, there&amp;rsquo;s a simple way of ensuring
this constraint: the &lt;code&gt;O_CLOEXEC&lt;/code&gt; flag.&lt;/p&gt;
&lt;p&gt;At the very beginning of this blog entry, we opened a file with the following
code fragment.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;open&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_file.txt&amp;#34;&lt;/span&gt;, O_RDWR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;O_CREAT, S_IRUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IWUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IRGRP);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;By or-ing &lt;code&gt;O_CLOEXEC&lt;/code&gt; into the flags argument, the returned file descriptor
will be closed before the process, or any forked process, starts executing a
new program.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;open&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_file.txt&amp;#34;&lt;/span&gt;, O_RDWR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;O_CREAT&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;O_CLOEXEC, S_IRUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IWUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IRGRP);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;How would our example look if we opened the file like this? During the fork
the file descriptor and file-descriptor table are copied into the new
process. The file descriptor carries the &lt;code&gt;O_CLOEXEC&lt;/code&gt; flag in its entry in the
file-descriptor table, but nothing else changed.&lt;/p&gt;
&lt;p&gt;The big change comes when the new process executes &lt;code&gt;execl()&lt;/code&gt;. Before loading
the new program into the process, the kernel goes through the process&#39;
file-descriptor table and closes all file descriptors that have the
&lt;code&gt;O_CLOEXEC&lt;/code&gt; flag set. Afterwards the resulting file data structures look
like this.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;unix8.png&#34; alt=&#34;Data structures after calling execl() with O_CLOEXEC set.&#34;&gt;&lt;/p&gt;
&lt;p&gt;The &lt;code&gt;O_CLOEXEC&lt;/code&gt; flag can also be set and cleared with a call to
&lt;del&gt;fstat()&lt;/del&gt; &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/fcntl.html&#34;&gt;&lt;code&gt;fcntl()&lt;/code&gt;&lt;/a&gt;&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; after the file
descriptor has been created. But setting it later creates the possibility
of meanwhile calling &lt;code&gt;execl()&lt;/code&gt; and leaking file descriptors.&lt;/p&gt;
&lt;p&gt;In practice, the safest strategy is to &lt;em&gt;always&lt;/em&gt; set &lt;code&gt;O_CLOEXEC&lt;/code&gt; when a new
file descriptor gets created; and explictly clear the flag right before the
call to &lt;code&gt;execl()&lt;/code&gt; for those file descriptors that are supposed to be handed
over to the new program.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we examined the behavior of Unix file-I/O data structures
during &lt;code&gt;fork()&lt;/code&gt; and &lt;code&gt;execl()&lt;/code&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A call to &lt;code&gt;fork()&lt;/code&gt; duplicates the calling porcess.&lt;/li&gt;
&lt;li&gt;During the fork operation, the kernel copies the process&amp;rsquo; file descriptors
and file-descriptor table, but not the underlying open file descriptions
and file buffers.&lt;/li&gt;
&lt;li&gt;Processes can communicate with each other by using the shared open file
descriptions and file buffers.&lt;/li&gt;
&lt;li&gt;A call to &lt;code&gt;execl()&lt;/code&gt; starts a new program within the calling process.&lt;/li&gt;
&lt;li&gt;By default, executing a new program has no effect on file-I/O data
structures. The new program will have access to all file descriptors,
open file descriptions and file buffers left open by the old program.&lt;/li&gt;
&lt;li&gt;Leaving file descriptors open before executing a new program can leak
resources and/or sensitive information to the new program.&lt;/li&gt;
&lt;li&gt;Creating a file descriptor with the flag &lt;code&gt;O_CLOEXEC&lt;/code&gt; marks the file
descriptor to be closed when a new program gets executed. This
automatically prevents file-descriptor leaks.&lt;/li&gt;
&lt;li&gt;File descriptors should always be created with &lt;code&gt;O_CLOEXEC&lt;/code&gt; and the flag
should be cleared explictly before executing a new program if required.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you like this blog post about the basics of Unix file I/O, please
subscribe to the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
&lt;h4 id=&#34;footnotes&#34;&gt;Footnotes&lt;/h4&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;Edit: The text originally said that &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/fstat.html&#34;&gt;&lt;code&gt;fstat()&lt;/code&gt;&lt;/a&gt; updates
a file descriptor&amp;rsquo;s &lt;code&gt;O_CLOEXEC&lt;/code&gt; flag. The correct function is
&lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/fcntl.html&#34;&gt;&lt;code&gt;fcntl()&lt;/code&gt;&lt;/a&gt;. The command parameter is named
&lt;code&gt;FD_CLOEXEC&lt;/code&gt;.&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</description>
    </item>
    
    
    
    <item>
      <title>picotm at FrOSCon 2017</title>
      <link>https://tzimmermann.org/2017/08/09/picotm-at-froscon-2017/</link>
      <pubDate>Wed, 09 Aug 2017 15:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/08/09/picotm-at-froscon-2017/</guid>
      <description>&lt;p&gt;I&amp;rsquo;m very excited to speak about &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt; at this year&amp;rsquo;s
&lt;a href=&#34;https://www.froscon.de/&#34;&gt;FroSCon&lt;/a&gt; conference! &lt;a href=&#34;https://programm.froscon.de/2017/events/1959.html&#34;&gt;The presentation&lt;/a&gt; is on
August 19, 2pm. I&amp;rsquo;ll cover the use cases of picotm, some programming,
and some internals. I look forward to see you there!&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Unix Hard Links, Soft Links, and Files</title>
      <link>https://tzimmermann.org/2017/08/04/unix-hard-links-soft-links-and-files/</link>
      <pubDate>Fri, 04 Aug 2017 10:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/08/04/unix-hard-links-soft-links-and-files/</guid>
      <description>&lt;p&gt;This blog post describes the relation ship between file names and files on
Unix file systems. We&amp;rsquo;ll also look at soft links and how all this interacts
with file descriptors.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;h4 id=&#34;creating-a-new-file&#34;&gt;Creating a New File&lt;/h4&gt;
&lt;p&gt;Let&amp;rsquo;s create a new file &lt;code&gt;my_file.txt&lt;/code&gt; our application. We do this by
calling &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html&#34;&gt;&lt;code&gt;open()&lt;/code&gt;&lt;/a&gt; with the file&amp;rsquo;s name.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;open&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_file.txt&amp;#34;&lt;/span&gt;, O_RDWR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;O_CREAT, S_IRUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IWUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IRGRP);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;As we&amp;rsquo;ve seen in the previous &lt;a href=&#34;https://tzimmermann.org/2017/07/28/data-structures-of-unix-file-io/&#34;&gt;blog post&lt;/a&gt; this creates a file
descriptor, an open file description, and a file buffer. You should read that
entry if you are interested in the relationship among file descriptors, open
file descriptions and file buffers.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://tzimmermann.org/2017/07/28/data-structures-of-unix-file-io/unix1.png&#34; alt=&#34;Data structures after opening /home/joe_user/my_file.txt once.&#34;&gt;&lt;/p&gt;
&lt;p&gt;In the file system, there&amp;rsquo;s now a file name that refers to the file buffer
we just opened.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;vfs1.png&#34; alt=&#34;File system after opening /home/joe_user/my_file.txt.&#34;&gt;&lt;/p&gt;
&lt;p&gt;A file name that refers to a file buffer is also called &lt;em&gt;hard link.&lt;/em&gt; There
can be multiple links to the same file buffer. Or in other words, the same
file buffer can be made available under different names.&lt;/p&gt;
&lt;h4 id=&#34;adding-hard-links&#34;&gt;Adding Hard Links&lt;/h4&gt;
&lt;p&gt;An additional name for a file is created with the command
&lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/link.html&#34;&gt;&lt;code&gt;link()&lt;/code&gt;&lt;/a&gt;. The function takes an existing file name and a new
file name. If successful, the new name refers to the existing file name&amp;rsquo;s
buffer.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s create an additional hard link of the name
&lt;code&gt;/home/joe_user/my_hard_link.txt&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;link&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_file.txt&amp;#34;&lt;/span&gt;, &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_hard_link.txt&amp;#34;&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Our file system now looks like this.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;vfs2.png&#34; alt=&#34;File system after creating /home/joe_user/my_hard_link.txt.&#34;&gt;&lt;/p&gt;
&lt;p&gt;What happens if we open the new file name from within our application?&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;open&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_hard_link.txt&amp;#34;&lt;/span&gt;, O_RDWR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;O_CREAT, S_IRUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IWUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IRGRP);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;It&amp;rsquo;s the same file buffer as before, so the result is the same as if
we&amp;rsquo;d opened the file by the original name.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://tzimmermann.org/2017/07/28/data-structures-of-unix-file-io/unix2.png&#34; alt=&#34;Data structures after opening /home/joe_user/my_hard_link.txt once.&#34;&gt;&lt;/p&gt;
&lt;p&gt;The application has opened two file descriptors, two open file descriptions,
and they both refer to the same file buffer.&lt;/p&gt;
&lt;p&gt;This is also the reason why we cannot go through all files on a file
system to sum up how much space they consume on the disk. Since multiple
file names can refer to the same file buffer, we could calculate a cumulative
size that might be larger than the actually consumed size; maybe even
larger than the maximum size of the disk.&lt;/p&gt;
&lt;h4 id=&#34;unlinking-closing-and-the-removal-of-file-buffers&#34;&gt;Unlinking, Closing, and the Removal of File Buffers&lt;/h4&gt;
&lt;p&gt;A call to &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/unlink.html&#34;&gt;&lt;code&gt;unlink()&lt;/code&gt;&lt;/a&gt; removes a file name from the file
system. Let&amp;rsquo;s call &lt;code&gt;unlink()&lt;/code&gt; on both file names and the file system will
be empty.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;unlink&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_file.txt&amp;#34;&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;unlink&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_hard_link.txt&amp;#34;&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Once the final link is gone, there&amp;rsquo;s no way to create a new link to the
file buffer. But the application still has these files open! How does that
work?&lt;/p&gt;
&lt;p&gt;For each file buffer, Unix maintains two counters: the link counter and
the open counter.&lt;/p&gt;
&lt;p&gt;The &lt;em&gt;link counter&lt;/em&gt; contains the number of links refering to a file buffer.
After being created, each file starts with a link count of &lt;em&gt;1.&lt;/em&gt; When we
added a hard link with &lt;code&gt;link()&lt;/code&gt; the counter went up by one. When we
removed a hard link with &lt;code&gt;unlink()&lt;/code&gt; the counter went down by one.&lt;/p&gt;
&lt;p&gt;The &lt;em&gt;open counter&lt;/em&gt; countains the number of times the file buffer was opened,
or more specifically the number of open file descriptions refering to the
file buffer. When a file buffer is not opened, the open counter is &lt;em&gt;0.&lt;/em&gt;
Each time we opened a file buffer with &lt;code&gt;open()&lt;/code&gt; that counter went up by one.
Only when we later close the file descriptors and the open file
descriptions get removed, the counter goes down.&lt;/p&gt;
&lt;p&gt;When both, link counter and open counter, reach zero at the same time
Unix removes the file buffer from the disk.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s close both file descriptors to remove the file buffer from the
disk.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;close&lt;/span&gt;(fd0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;close&lt;/span&gt;(fd1);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;soft-links&#34;&gt;Soft Links&lt;/h4&gt;
&lt;p&gt;Hard links have one major drawback, which is that they only work on the
file system that also maintains the buffer. So if you have one partition
for your computer&amp;rsquo;s operating system, an another partition for your personal
data, it&amp;rsquo;s not possible to create a hard link from one file system to the
other.&lt;/p&gt;
&lt;p&gt;Unix file systems provide a solution called soft links, also called
symbolic links or symlinks. Although it has a file name, a soft link is
not a regular file, but a special file that stores a full file path.
When an application opens the soft links, it actually opens the file at
the path that is stored in the soft link. Because a file path is stored
(instead of a reference to a file buffer), it&amp;rsquo;s independent from the
underlying file system.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s go back to the example of &lt;code&gt;/home/joe_user/my_file.txt&lt;/code&gt;. We can create
a soft link with a call to &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/symlink.html&#34;&gt;&lt;code&gt;symlink()&lt;/code&gt;&lt;/a&gt;. Like &lt;code&gt;link()&lt;/code&gt; before,
it takes the original file&amp;rsquo;s path and the path of the symlink.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;symlink&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_file.txt&amp;#34;&lt;/span&gt;, &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_soft_link.txt&amp;#34;&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;With the soft link in place, the file system looks like this.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;vfs3.png&#34; alt=&#34;File system after creating /home/joe_user/my_soft_link.txt.&#34;&gt;&lt;/p&gt;
&lt;p&gt;We have a file name &lt;code&gt;my_file.txt&lt;/code&gt;, which refers to a file buffer. And we
have a file name &lt;code&gt;my_soft_link.txt&lt;/code&gt;, which refers to the soft-link file,
which in turn refers to the original file name.&lt;/p&gt;
&lt;p&gt;The existance of a soft link does not have any impact on the actual file,
or that file buffers&amp;rsquo;s link counter. So a file can be removed, even if it
is the target of a soft link. If this happens, the soft link goes stale
and trying to open it returns an error.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we went through a tour of how hard links and soft links
work on Unix, and how they affect the life time of file buffers.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Initially each file buffer is referenced by a file name.&lt;/li&gt;
&lt;li&gt;The file name is called &lt;em&gt;hard link.&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;There can be multiple hard links ot the same file buffer.&lt;/li&gt;
&lt;li&gt;Opening any of a file buffer&amp;rsquo;s hard links opens the file buffer.&lt;/li&gt;
&lt;li&gt;A file buffer can not be opened any longer after all hard links have been
removed.&lt;/li&gt;
&lt;li&gt;A file buffer is removed from the disk after all hard links have been
removed and the file buffer is not opened by any application.&lt;/li&gt;
&lt;li&gt;Hard links don&amp;rsquo;t work across file-system boundaries.&lt;/li&gt;
&lt;li&gt;Soft links are a special type of file that reference other files by
their path names.&lt;/li&gt;
&lt;li&gt;Opening a soft link opens the referenced file.&lt;/li&gt;
&lt;li&gt;Soft links can reference files on other file systems.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you like this blog post about the basics of Unix File I/O, please
subscribe to the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
&lt;h4 id=&#34;footnotes&#34;&gt;Footnotes&lt;/h4&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Data Structures of Unix File I/O</title>
      <link>https://tzimmermann.org/2017/07/28/data-structures-of-unix-file-io/</link>
      <pubDate>Fri, 28 Jul 2017 10:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/07/28/data-structures-of-unix-file-io/</guid>
      <description>&lt;p&gt;This blog post describes the basic data structures involved in file I/O on
Unix and Linux. We&amp;rsquo;ll go through file descriptors, open file descriptions and
file buffers, and see how they relate to each other.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;Over the last few weeks I&amp;rsquo;ve been reworking and cleaning up the transactional
file I/O in &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt;&amp;rsquo;s libc component. It occures to me that while
Unix systems dominate the operating-system landscape, many details of how
they actually work are not widely documented&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; and consequently not widely
understood. With programmers coming from backgrounds other than C and Unix we
now get to hear stories like &lt;a href=&#34;http://medium.com/@fun_cuddles/opening-files-in-node-js-considered-harmful-d7de566d499f&#34;&gt;this one&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In this blog post, we&amp;rsquo;ll look at what happens when an application opens and
closes file descriptors on a Unix system. Whether it calls from C source code,
&lt;a href=&#34;http://nodejs.org/en/&#34;&gt;Node.js&lt;/a&gt;, or any other Unix-like interface is not really important.&lt;/p&gt;
&lt;h4 id=&#34;file-descriptors-open-file-descriptions-and-regular-files&#34;&gt;File Descriptors, Open File Descriptions, and Regular Files&lt;/h4&gt;
&lt;p&gt;On Unix systems, such as Linux, the BSDs, or MacOS, there are three major
data structures that are relevant to file I/O. These are file descriptors,
open file descriptions, and the file buffers themselves.&lt;/p&gt;
&lt;p&gt;A call to &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/open.html&#34;&gt;&lt;code&gt;open()&lt;/code&gt;&lt;/a&gt; takes the name of the file and the
file-access flags that describe whether the file should be opened for
reading or writing, etc. If a new file might be created, an optional third
argument specifies the new file buffer&amp;rsquo;s file mode.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s look at an example by calling&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;open&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_file.txt&amp;#34;&lt;/span&gt;, O_RDWR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;O_CREAT, S_IRUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IWUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IRGRP);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We open the file buffer associated with the filename
&lt;code&gt;/home/joe_user/my_file.txt&lt;/code&gt; for reading and writing (i.e., &lt;code&gt;O_RDWR&lt;/code&gt;). If
no file buffer with this name exists, the kernel creates a new one (i.e.,
&lt;code&gt;O_CREAT&lt;/code&gt;). The new file is readable by the process&amp;rsquo; user and group, and
writable only by the process&amp;rsquo; user (i.e., &lt;code&gt;S_IRUSR|S_IWUSR|S_IRGRP&lt;/code&gt;).&lt;/p&gt;
&lt;p&gt;If we assume that a process has no files open yet, calling &lt;code&gt;open()&lt;/code&gt; on
&lt;code&gt;/home/joe_user/my_file.txt&lt;/code&gt; creates the following hierarchy of these data
stuctures.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;unix1.png&#34; alt=&#34;Data structures after opening /home/joe_user/my_file.txt once.&#34;&gt;&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s start with the file buffer. The file buffer is represented by
&lt;em&gt;File buffer no. 0&lt;/em&gt; in our example. It&amp;rsquo;s the raw data stored in the regular
file.&lt;/p&gt;
&lt;p&gt;From now on we&amp;rsquo;ll also refer to file buffers as regular files. The term
&lt;em&gt;regular file&lt;/em&gt; is Unix-speak for a data buffer that is located on a file
system and represented by a name in the file-system tree. The byte offset
for reading from and writing to a regular file is freely choosable.
Unix file I/O also knowns about multiple types of special files, directories,
sockets, multiple types of memory objects, and more. A regular file is what
we&amp;rsquo;d commonly expect to be a file.&lt;/p&gt;
&lt;p&gt;Next, the kernel creates a new open file description, labeled &lt;em&gt;Open file
description no. 0.&lt;/em&gt; in the example. &lt;em&gt;The open file description&lt;/em&gt; stores all
state related to the opened file. That is the file-access flags supplied
with &lt;code&gt;open()&lt;/code&gt; and the byte offset where the next read or write operation takes
place. In our example, the file-access mode is set to &lt;em&gt;readable/writable&lt;/em&gt; and
the initial byte offset is &lt;em&gt;0.&lt;/em&gt; The open file description refers to the file
buffer we just retrieved from the file system.&lt;/p&gt;
&lt;p&gt;The file buffer and the open file description are system-wide resources. Given
the correct sequence of operations, multiple processes can get a hold on
either of them and share their state.&lt;/p&gt;
&lt;p&gt;To do so, each process maintains a so-called &lt;em&gt;file-descriptor table.&lt;/em&gt; As the
name suggests, it&amp;rsquo;s a table of all file descriptors of the process. &lt;em&gt;A file
descriptor&lt;/em&gt; is a process&amp;rsquo; means of refering to an open file description. Each
file descriptor refers to an open file description, which in turn refers to a
file buffer.&lt;/p&gt;
&lt;p&gt;The kernel always allocates the lowest available entry in the file-descriptor
table and associates it with the open file description it just created.
In the case of our invocation of &lt;code&gt;open()&lt;/code&gt; this is entry &lt;em&gt;0.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Finally, &lt;code&gt;open()&lt;/code&gt; returns the table index of the allocated file descriptor to
the process&amp;rsquo;s user-space application. Using the returned index, the application
can access the regular file via &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/read.html&#34;&gt;&lt;code&gt;read()&lt;/code&gt;&lt;/a&gt; or
&lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/write.html&#34;&gt;&lt;code&gt;write()&lt;/code&gt;&lt;/a&gt;, etc. So if we now do&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;write&lt;/span&gt;(fd0, &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Hello world!&amp;#34;&lt;/span&gt;, &lt;span style=&#34;color:#a6e22e&#34;&gt;strlen&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Hello world!&amp;#34;&lt;/span&gt;)); &lt;span style=&#34;color:#75715e&#34;&gt;// write 12 byte
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;we write &lt;em&gt;Hello world!&lt;/em&gt; to the beginning of &lt;em&gt;File buffer no. 0&lt;/em&gt; and
increment the byte offset of &lt;em&gt;Open file description no. 0&lt;/em&gt; by 12 byte.&lt;/p&gt;
&lt;p&gt;There&amp;rsquo;s a bit of confusing terminology here. When talking about the user-space
integer value, one usually speaks of a file descriptor. But the actual file
descriptor is in the process&amp;rsquo; file-descriptor table in the kernel. The
user-space value is just an index into this table.&lt;/p&gt;
&lt;h4 id=&#34;opening-the-same-file-multiple-times&#34;&gt;Opening The Same File Multiple Times&lt;/h4&gt;
&lt;p&gt;Let&amp;rsquo;s open the file a second time.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;open&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;/home/joe_user/my_file.txt&amp;#34;&lt;/span&gt;, O_RDWR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;O_CREAT, S_IRUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IWUSR&lt;span style=&#34;color:#f92672&#34;&gt;|&lt;/span&gt;S_IRGRP);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Our hierarchy of data structures now looks like this.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;unix2.png&#34; alt=&#34;Data structures after opening /home/joe_user/my_file.txt twice.&#34;&gt;&lt;/p&gt;
&lt;p&gt;We already have a file buffer for the regular file with the name
of the user&amp;rsquo;s &lt;code&gt;my_file.txt&lt;/code&gt; file. The Unix kernel uses this buffer for the
second call to &lt;code&gt;open()&lt;/code&gt;. The &lt;code&gt;O_CREAT&lt;/code&gt; flag is only relevant if the
regular file does not yet exist.&lt;/p&gt;
&lt;p&gt;Every call to &lt;code&gt;open()&lt;/code&gt; creates a new open file description. It&amp;rsquo;s labeled
&lt;em&gt;Open file description no. 1&lt;/em&gt; in our example. As before it&amp;rsquo;s initialized
with a byte offset of &lt;em&gt;0&lt;/em&gt; and the file-access flags are taken from &lt;code&gt;open()&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;For the new open file description, a new entry in the file-descriptor table
is allocated and its index is returned to the user-space application. It&amp;rsquo;s
called &lt;em&gt;File descriptor no. 1&lt;/em&gt; in our example.&lt;/p&gt;
&lt;p&gt;Our application now has two file descriptors that refer to the same file
buffer, but these file descriptors don&amp;rsquo;t share any state besides the file
buffer&amp;rsquo;s content. So writing with &lt;code&gt;fd1&lt;/code&gt; starts at byte offset 0! Doing&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;write&lt;/span&gt;(fd1, &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Salut monde!&amp;#34;&lt;/span&gt;, &lt;span style=&#34;color:#a6e22e&#34;&gt;strlen&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Salut monde!&amp;#34;&lt;/span&gt;));
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;effectively overwrites the output we already wrote using &lt;code&gt;fd0&lt;/code&gt;. The file
buffer now contains &lt;em&gt;Salut monde!&lt;/em&gt; and the byte offset of
&lt;em&gt;Open file description no. 1&lt;/em&gt; is at position 12.&lt;/p&gt;
&lt;h4 id=&#34;duplicating-file-descriptors&#34;&gt;Duplicating File Descriptors&lt;/h4&gt;
&lt;p&gt;We can also have file descriptors that share their open file descriptions.
For this we use &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/dup.html&#34;&gt;&lt;code&gt;dup()&lt;/code&gt;&lt;/a&gt;. A call to &lt;code&gt;dup()&lt;/code&gt; &lt;em&gt;duplicates&lt;/em&gt; a file
descriptor, but reuses the open file description.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s duplicate &lt;code&gt;fd1&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; fd2 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;dup&lt;/span&gt;(fd1);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This will setup our data structures as shown below.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;unix3.png&#34; alt=&#34;Data structures after duplicating fd1.&#34;&gt;&lt;/p&gt;
&lt;p&gt;The call to &lt;code&gt;dup()&lt;/code&gt; allocates a new entry in the process&amp;rsquo; file-descriptor
table and copies &lt;em&gt;File descriptor no. 1&lt;/em&gt; to the new entry. The result is
the new &lt;em&gt;File descriptor no. 2&lt;/em&gt;. Its table index is returned to the process&#39;
user-space application.&lt;/p&gt;
&lt;p&gt;In contrast to the previous example of opening a file twice, this time
both file descriptors refer to the same open file description, which is
&lt;em&gt;Open file description no. 1.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s write using both, &lt;code&gt;fd1&lt;/code&gt; and &lt;code&gt;fd2&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;write&lt;/span&gt;(fd2, &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34; Ca&amp;#34;&lt;/span&gt;, &lt;span style=&#34;color:#a6e22e&#34;&gt;strlen&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34; Ca&amp;#34;&lt;/span&gt;)); &lt;span style=&#34;color:#75715e&#34;&gt;// write 3 byte
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;write&lt;/span&gt;(fd1, &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34; va?&amp;#34;&lt;/span&gt;, &lt;span style=&#34;color:#a6e22e&#34;&gt;strlen&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34; va?&amp;#34;&lt;/span&gt;)); &lt;span style=&#34;color:#75715e&#34;&gt;// write another 4 byte
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Both file descriptors share the same open file description, writing with
either therefore modifies the same byte offset. From the previous write
operation, the byte offset is already at position 12. We write another 3 byte
using &amp;lsquo;fd2&amp;rsquo; and yet another 4 byte using &lt;code&gt;fd1&lt;/code&gt;. Our file buffer now contains
the output &lt;em&gt;Salut monde! Ca va?&lt;/em&gt; and the byte offset in &lt;em&gt;Open file description
no. 1&lt;/em&gt; is at position 19.&lt;/p&gt;
&lt;p&gt;For a final exampleon writing, let&amp;rsquo;s again write using &lt;code&gt;fd0&lt;/code&gt;.
&lt;em&gt;File descriptor no. 0&lt;/em&gt; refers to &lt;em&gt;Open file description no. 0.&lt;/em&gt; Last time
we used it for writing &lt;em&gt;Hello world!&lt;/em&gt; and the open file description&amp;rsquo;s byte
offset is still at position 12. That&amp;rsquo;s where the next &lt;code&gt;write()&lt;/code&gt; operation
starts&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;write&lt;/span&gt;(fd0, &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34; How&amp;#39;s it going?&amp;#34;&lt;/span&gt;, &lt;span style=&#34;color:#a6e22e&#34;&gt;strlen&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34; How&amp;#39;s it going?&amp;#34;&lt;/span&gt;)); &lt;span style=&#34;color:#75715e&#34;&gt;// write 16 byte
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This command writes 16 byte at the offset of 12, effectively overwriting
the previous output at this location. Our file buffer now contains the
output &lt;em&gt;Salut monde! How&amp;rsquo;s it going?&lt;/em&gt;.&lt;/p&gt;
&lt;h4 id=&#34;closing-file-descriptors&#34;&gt;Closing File Descriptors&lt;/h4&gt;
&lt;p&gt;Our process has created 3 file descriptors. Let us close &lt;code&gt;fd1&lt;/code&gt;. Closing
is performed by calling &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/close.html&#34;&gt;&lt;code&gt;close()&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;close&lt;/span&gt;(fd1);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Here&amp;rsquo;s how our hierarchy of data structures looks now.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;unix4.png&#34; alt=&#34;Data structures after closing fd1.&#34;&gt;&lt;/p&gt;
&lt;p&gt;We can see that &lt;em&gt;File descriptor no. 1&lt;/em&gt; is not available to the
application code any longer and the entry has been removed from the
file-descriptor table.&lt;/p&gt;
&lt;p&gt;We always close file descriptors, not open file descriptions or file
buffers. Therefore the open file descriptions and the file buffer are still
there! Each is still referenced and available for use with
&lt;em&gt;File descriptor no. 0&lt;/em&gt; or &lt;em&gt;File descriptor no. 2&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;Now let&amp;rsquo;s close &lt;code&gt;fd0&lt;/code&gt; as well.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;close&lt;/span&gt;(fd0);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;img src=&#34;unix5.png&#34; alt=&#34;Data structures after closing fd0.&#34;&gt;&lt;/p&gt;
&lt;p&gt;As with the previous close operation, the file descriptor and the entry in
the file-descriptor table are gone. And because no other file descriptor
references &lt;em&gt;Open file description no. 0&lt;/em&gt;, the kernel deletes this open file
description and releases the memory. The file buffer &lt;em&gt;File buffer no. 0&lt;/em&gt;
is still there, as it&amp;rsquo;s still referenced by &lt;em&gt;Open file description no. 2.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;If we would close the final file descriptor &lt;em&gt;File descriptor no. 2&lt;/em&gt; as well,
the kernel would release all remaining data structures including
&lt;em&gt;File buffer no. 0.&lt;/em&gt;&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;This blog post describes the basic data structures of Unix file I/O.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The content of regular files is stored in file buffers.&lt;/li&gt;
&lt;li&gt;Opening a regular file opens or creates the file&amp;rsquo;s file buffer.&lt;/li&gt;
&lt;li&gt;Each call to &lt;code&gt;open()&lt;/code&gt; creates a new open file description that stores
the file-access flags and the byte offset for the next read or
write operation.&lt;/li&gt;
&lt;li&gt;Each open file description refers to a file buffer.&lt;/li&gt;
&lt;li&gt;Processes interact with open file descriptions and file buffers by
using file descriptors.&lt;/li&gt;
&lt;li&gt;Each process contains its own table of file descriptors.&lt;/li&gt;
&lt;li&gt;File descriptors are duplicated using &lt;code&gt;dup()&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Duplicated file descriptors share the same open file description.&lt;/li&gt;
&lt;li&gt;File descriptors are closed using &lt;code&gt;close()&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The kernel releases the open file descriptions and file buffers
automatically when they are not longer needed.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you like this blog post about the basics of Unix File I/O, please
subscribe to the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
&lt;p&gt;Maybe I turn this into a little series of blog posts. There&amp;rsquo;s interesting
stuff happening during process forks; when using sockets; or in other
interfaces that look like files, but aren&amp;rsquo;t.&lt;/p&gt;
&lt;h4 id=&#34;footnotes&#34;&gt;Footnotes&lt;/h4&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;There are a number of good books on Linux and Unix programming. If
you&amp;rsquo;re interested in Linux system programming I&amp;rsquo;d recommend Michael
Kerrisk&amp;rsquo;s &lt;a href=&#34;http://man7.org/tlpi/&#34;&gt;The Linux Programming Interface&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Implementing Fault-Tolerant Software With Transactions</title>
      <link>https://tzimmermann.org/2017/07/21/implementing-fault-tolerant-software-with-transactions/</link>
      <pubDate>Fri, 21 Jul 2017 11:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/07/21/implementing-fault-tolerant-software-with-transactions/</guid>
      <description>&lt;p&gt;This is a series of blog posts to build a transaction manager in C. Last time,
we looked at fault tolerance, and how to build fail-safe transactional
software. In this installment, we&amp;rsquo;re going to implement support for error
detection and recovery in our transaction manager &lt;em&gt;simpletm.&lt;/em&gt; As usual, the
complete example code for this blog post
&lt;a href=&#34;http://github.com/tdz/blog_examples/tree/master/2017-07-21&#34;&gt;is available on GitHub&lt;/a&gt;.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;If you missed earlier entries in the series, you
&lt;a href=&#34;https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/&#34;&gt;might&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/09/transactional-semantics-in-theory-and-practice/&#34;&gt;want&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/12/transaction-roll-back-and-serializability/&#34;&gt;to&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/&#34;&gt;go&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/26/transactional-access-to-arbitrary-memory-locations/&#34;&gt;back&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/01/transactional-memcpy-and-resource-privatization/&#34;&gt;and&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/09/more-on-resource-privatization/&#34;&gt;read&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/16/transaction-logs/&#34;&gt;the&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/23/transactional-malloc-and-free/&#34;&gt;installments&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/30/everything-about-errno-plus-transactions/&#34;&gt;so&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/07/07/types-of-transactional-operations/&#34;&gt;far&lt;/a&gt;. You might especially want to read the
&lt;a href=&#34;https://tzimmermann.org/2017/07/14/building-fault-tolerant-software-with-transactions/&#34;&gt;previous installment&lt;/a&gt;, which in detail lays the foundation
for transactional error handling.&lt;/p&gt;
&lt;h4 id=&#34;a-brief-recap&#34;&gt;A Brief Recap&lt;/h4&gt;
&lt;p&gt;Here&amp;rsquo;s a very brief recap of the &lt;a href=&#34;https://tzimmermann.org/2017/07/14/building-fault-tolerant-software-with-transactions/&#34;&gt;previous blog post&lt;/a&gt;. In this
installment, we had the following example program written in C.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;enum&lt;/span&gt; result {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    failure,
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    success
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;};
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;enum&lt;/span&gt; result
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;func&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#a6e22e&#34;&gt;call_1&lt;/span&gt;() &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; failure) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; err_call_1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#a6e22e&#34;&gt;call_2&lt;/span&gt;() &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; failure) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; err_call_2;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#a6e22e&#34;&gt;call_3&lt;/span&gt;() &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; failure) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; err_call_3;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; success;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;err_call_3:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;revert_call_2&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;err_call_2:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;revert_call_1&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;err_call_1:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; failure;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;repair_func&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* repair errors of func() */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;main&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; argc, &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; argv[])
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;try_func:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#a6e22e&#34;&gt;func&lt;/span&gt;() &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; failure) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;repair_func&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; try_func;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; EXIT_SUCCESS;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The function &lt;code&gt;main()&lt;/code&gt; calls &lt;code&gt;func()&lt;/code&gt; until &lt;code&gt;func()&lt;/code&gt; signals success.
In &lt;code&gt;func()&lt;/code&gt; itself, there are 3 calls to the functions named &lt;code&gt;call_1()&lt;/code&gt;,
&lt;code&gt;call_2()&lt;/code&gt; and &lt;code&gt;call_3()&lt;/code&gt;. If all invocations succeed, &lt;code&gt;func()&lt;/code&gt; signals
success; if either invocation fails, &lt;code&gt;func()&lt;/code&gt; reverts the already completed
calls and signals failure. In case of a failure, &lt;code&gt;main()&lt;/code&gt; tries to repair
the error by calling &lt;code&gt;repair_func()&lt;/code&gt;. After completing the repair, &lt;code&gt;main()&lt;/code&gt;
restarts &lt;code&gt;func()&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The revert-repair-and-retry scheme is a typical pattern in C software. It
resembles the rollback-and-retry pattern found in transactions. If we add
the repair functionality to the transaction manager, we can write the code
as a transaction.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;repair_func&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* repair errors of func() */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;main&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; argc, &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; argv[])
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;/* execution phase */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;call_1_tx&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;call_2_tx&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;call_3_tx&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;/* recovery phase */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;repair_func&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;tm_restart&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tm_end
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; EXIT_SUCCESS;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The functions &lt;code&gt;call_1_tx()&lt;/code&gt;, &lt;code&gt;call_2_tx()&lt;/code&gt; and &lt;code&gt;call_3_tx()&lt;/code&gt; are now invoked
during the transaction&amp;rsquo;s &lt;em&gt;execution phase.&lt;/em&gt; They internally test for errors
and roll back the transaction if they detect one. This functionality is
implemented by the transaction manager, so there&amp;rsquo;s nothing that the
application programmer has to add.&lt;/p&gt;
&lt;p&gt;After an error has been detected and the transaction manager performed the
rollback, it restarts the transaction in the &lt;em&gt;recovery phase&lt;/em&gt;. During
recovery, the application can try to repair the error and then restart the
transaction&amp;rsquo;s execution phase.&lt;/p&gt;
&lt;p&gt;You can already see how much cleaner the transactional implementation is.
Everything that can be automated is handled by the transaction manager&amp;rsquo;s
framework. The only code that has to be written by the application programmer
is the recovery phase, as it&amp;rsquo;s specific to the application and use case.&lt;/p&gt;
&lt;h4 id=&#34;additional-interfaces-for-recovery&#34;&gt;Additional Interfaces for Recovery&lt;/h4&gt;
&lt;p&gt;For the implementation, we&amp;rsquo;re going to modify our standard example of
producer and a consumer transactions. Let&amp;rsquo;s start with the transaction
manager&amp;rsquo;s public interfaces.&lt;/p&gt;
&lt;p&gt;So far, our transactions have been contained by &lt;code&gt;tm_begin&lt;/code&gt; and &lt;code&gt;tm_commit&lt;/code&gt;&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define tm_begin                            \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    _tm_begin(setjmp(_tm_get_tx()-&amp;gt;env));   \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define tm_commit                           \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;        _tm_commit();                       \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;When used in application code and expanded by the C preprocessor, they
form a block that looks this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_begin&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;setjmp&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_get_tx&lt;/span&gt;()&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;env));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* execution phase */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_commit&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The code for our new recovery phase is located between &lt;code&gt;tm_commit&lt;/code&gt; and the
new &lt;code&gt;tm_end&lt;/code&gt; macro. To run either the execution phase or the recovery, we
implement the &lt;code&gt;tm_begin&lt;/code&gt;-&lt;code&gt;tm_commit&lt;/code&gt;-&lt;code&gt;tm_end&lt;/code&gt; combo as if-else branch.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define tm_begin                                \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    if (_tm_begin(setjmp(_tm_get_tx()-&amp;gt;env)))   \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define tm_commit                           \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;        _tm_commit();                       \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    } else {
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define tm_end  \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Expanded by the C preprocessor, the code looks like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_begin&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;setjmp&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_get_tx&lt;/span&gt;()&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;env)))
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* execution phase */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_commit&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;} &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* recovery phase */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Whether the transaction enters execution or recovery depends on the value
returned by &lt;code&gt;_tm_begin()&lt;/code&gt;. And this value is controlled by the transaction
manager. If we start the transaction for the first time or rolled back because
of a conflict, the returned value is &lt;em&gt;true&lt;/em&gt; and we enter the execution phase.
After we rolled back because of an error, the returned value is &lt;em&gt;false&lt;/em&gt; and we
enter the recovery phase.&lt;/p&gt;
&lt;p&gt;At the end of the recovery phase, the transaction defaults to ending without
retrying execution. To restart we also need a new public interface. It&amp;rsquo;s
called &lt;code&gt;tm_restart()&lt;/code&gt; and invokes the transaction&amp;rsquo;s execution phase.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;tm_restart&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;error-detection&#34;&gt;Error Detection&lt;/h4&gt;
&lt;p&gt;Our transaction manager contains the function &lt;code&gt;malloc_tx()&lt;/code&gt;, a transactional
implementation of &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/malloc.html&#34;&gt;&lt;code&gt;malloc()&lt;/code&gt;&lt;/a&gt;. Here&amp;rsquo;s the implementation.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;undo_malloc_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; data)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;)data;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;free&lt;/span&gt;(ptr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;malloc_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; size)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;save_errno&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;append_to_log&lt;/span&gt;(NULL, undo_malloc_tx, (&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)ptr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; ptr;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Since &lt;code&gt;malloc()&lt;/code&gt; fails if no memory is available for allocation, &lt;code&gt;malloc_tx()&lt;/code&gt;
should detect the error and invoke recovery.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;undo_malloc_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; data)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;)data;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;free&lt;/span&gt;(ptr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;malloc_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; size)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;save_errno&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;ptr) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;tm_recover&lt;/span&gt;(errno); &lt;span style=&#34;color:#75715e&#34;&gt;/* does not return */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;append_to_log&lt;/span&gt;(NULL, undo_malloc_tx, (&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)ptr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; ptr;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This implementation of &lt;code&gt;malloc_tx()&lt;/code&gt; tests the returned pointer and
invokes &lt;code&gt;tm_recover()&lt;/code&gt; if no memory could be allocated. To understand
&lt;code&gt;tm_recover()&lt;/code&gt;, let&amp;rsquo;s look at the restart-and-recovery machinery as a
whole.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_begin&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; value)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; value &lt;span style=&#34;color:#f92672&#34;&gt;!=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;rollback_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_tx&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; tx, &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; value)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;release_resources&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;arraybeg&lt;/span&gt;(g_resource),
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                      &lt;span style=&#34;color:#a6e22e&#34;&gt;arrayend&lt;/span&gt;(g_resource), false);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* Revert logged operations */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;undo_log&lt;/span&gt;(tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log, tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log_length);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log_length &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* Restore errno */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;errno_saved) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        errno &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;errno_value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;errno_saved &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* Jump to the beginning of the transaction */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;longjmp&lt;/span&gt;(tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;env, value);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;tm_restart&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;rollback_tx&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_get_tx&lt;/span&gt;(), &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;tm_recover&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; errno_code)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_tx&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; tx &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_get_tx&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;recovery_errno_code &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; errno_code;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;rollback_tx&lt;/span&gt;(tx, &lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The roll back is performed by the internal function &lt;code&gt;rollback_tx()&lt;/code&gt;. Its
implementation is mostly uninteresting here, but it&amp;rsquo;s important to note that
the second parameter &lt;code&gt;value&lt;/code&gt; contains the value that is passed to &lt;code&gt;_tm_begin()&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;If the transaction manager detects a conflict it rolls back the transaction
with a call to &lt;code&gt;tm_restart()&lt;/code&gt;. This function is also the one to call at the
end of the recovery phase. It uses a value of &lt;em&gt;1,&lt;/em&gt; which means something like
&lt;em&gt;regular restart.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;If a transactional function detects an error it invokes &lt;code&gt;tm_recover()&lt;/code&gt;. This
function saves the errno code and restarts the transaction with a value of
&lt;em&gt;2.&lt;/em&gt; This value signals the request for error recovery.&lt;/p&gt;
&lt;p&gt;An invocation of &lt;code&gt;_tm_begin()&lt;/code&gt; can now receive three possible values. A value
of &lt;em&gt;0&lt;/em&gt; signals the initial execution of the transaction. This is the default
value returned by &lt;code&gt;setjmp()&lt;/code&gt;. A value of &lt;em&gt;1&lt;/em&gt; signals a restart into the
execution phase and a value of &lt;em&gt;2&lt;/em&gt; signals a restart into the recovery phase.
&lt;code&gt;_tm_begin()&lt;/code&gt; tests the value and returns &lt;em&gt;true&lt;/em&gt; or &lt;em&gt;false&lt;/em&gt; accordingly.&lt;/p&gt;
&lt;p&gt;in addition to the public interfaces, we also add the function
&lt;code&gt;tm_recovery_errno()&lt;/code&gt;. It returns the stored errno code, so that the
recovery phase can query information about the failure.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;tm_recovery_errno&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_tx&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; tx &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_get_tx&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;recovery_errno_code;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;a-producer-consumer-example&#34;&gt;A Producer-Consumer Example&lt;/h4&gt;
&lt;p&gt;In previous blog posts we used an example with a producer transaction and
a consumer transaction. The producer looked something like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; seed &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tm_save &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i[&lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; {&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;};
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (true) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;sleep&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;i[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        i[&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;rand_r&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;seed);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Storing i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;], i[&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;]);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; NULL;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;load&lt;/span&gt;((&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_i, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(g_i));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;buf) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                buf &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc_tx&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;buf));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                buf[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; i[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                buf[&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; i[&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#a6e22e&#34;&gt;store&lt;/span&gt;((&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_i, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(g_i));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;It produces a pseudo-random value and hands it over to the consumer. The
memory is allocated dynamically using &lt;code&gt;malloc_tx()&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s extend this example with the new functionality. We can add error
recovery by appending only 3 lines of code to the transaction.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;recover_from_errno&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; errno_code)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;fprintf&lt;/span&gt;(stderr, &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Recovering from error %d (%s)&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, errno_code,
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;strerror&lt;/span&gt;(errno_code));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; seed &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tm_save &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i[&lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; {&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;};
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (true) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;sleep&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;i[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        i[&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;rand_r&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;seed);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Storing i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;], i[&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;]);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; NULL;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;load&lt;/span&gt;((&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_i, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(g_i));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;buf) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                buf &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc_tx&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;buf));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                buf[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; i[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                buf[&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; i[&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#a6e22e&#34;&gt;store&lt;/span&gt;((&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_i, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(g_i));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;recover_from_errno&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;tm_recovery_errno&lt;/span&gt;());
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;tm_restart&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_end
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The new function &lt;code&gt;recover_from_errno()&lt;/code&gt; is specific to the application. In
a real-world scenario it could try to free some memory, for example by
flushing caches or running a garbage collector. In the example, it simply
prints a message.&lt;/p&gt;
&lt;p&gt;To test the code, we can instrument the implementation of &lt;code&gt;malloc_tx()&lt;/code&gt; to
fail spuriously, just as if the application was low on memory.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;malloc_with_low_mem&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; size)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* simulate spurious allocation failures */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;clock_t&lt;/span&gt; cputime &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;clock&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;(cputime &lt;span style=&#34;color:#f92672&#34;&gt;%&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;3&lt;/span&gt;)) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        errno &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; ENOMEM;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; NULL;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;malloc_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; size)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;save_errno&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc_with_low_mem&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;ptr) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;tm_recover&lt;/span&gt;(errno); &lt;span style=&#34;color:#75715e&#34;&gt;/* does not return */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;append_to_log&lt;/span&gt;(NULL, undo_malloc_tx, (&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)ptr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; ptr;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The full example code &lt;a href=&#34;http://github.com/tdz/blog_examples/tree/master/2017-07-21&#34;&gt;is available on GitHub&lt;/a&gt;. If you
run it, it should output something like this to the terminal.&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;Storing i0=1, i1=476707713
Loaded i0=0, i1=0
Storing i0=2, i1=1186278907
Loaded i0=1, i1=476707713
Storing i0=3, i1=505671508
Loaded i0=2, i1=1186278907
Storing i0=4, i1=2137716191
Loaded i0=3, i1=505671508
Storing i0=5, i1=936145377
Loaded i0=4, i1=2137716191
Storing i0=6, i1=1215825599
Loaded i0=5, i1=936145377
Recovering from error 12 (Cannot allocate memory)
Recovering from error 12 (Cannot allocate memory)
Loaded i0=6, i1=1215825599
Storing i0=7, i1=589265238
Recovering from error 12 (Cannot allocate memory)
Loaded i0=7, i1=589265238
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;This is the output of the values stored and loaded by the producer and
consumer transactions. Occationally the producer&amp;rsquo;s memory allocation failed
and triggered the recovery phase.&lt;/p&gt;
&lt;p&gt;The final three lines illustrate this nicely. The producer transaction intended
to store value no. 7, but had to recover. The error message tells that memory
allocation failed (as expected). After completing recovery the producer
restarted execution and successfully stored the 7th value. The consumer
transaction then loaded the value correctly, as signalled by the final line of
the output.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we&amp;rsquo;ve added support for error detection and recovery
to our &lt;em&gt;simpletm&lt;/em&gt; transaction manager.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Error detection and rollback is provided by the transaction manager&amp;rsquo;s
framework.&lt;/li&gt;
&lt;li&gt;Only the error recovery is application-specific and has to be provided
by the application developer.&lt;/li&gt;
&lt;li&gt;Transactional functions, such as &lt;code&gt;malloc_tx&lt;/code&gt;, detect errors and invoke
recovery.&lt;/li&gt;
&lt;li&gt;The transaction either restarts into the execution phase or the
recovery phase.&lt;/li&gt;
&lt;li&gt;The code of the recovery phase is located between &lt;code&gt;tm_commit&lt;/code&gt; and
the new token &lt;code&gt;tm_end&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As usual, the complete example code for this blog post &lt;a href=&#34;http://github.com/tdz/blog_examples/tree/master/2017-07-21&#34;&gt;is available on
GitHub&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you like this series about writing a transaction manager in C, please
subscribe to the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Building Fault-Tolerant Software With Transactions</title>
      <link>https://tzimmermann.org/2017/07/14/building-fault-tolerant-software-with-transactions/</link>
      <pubDate>Fri, 14 Jul 2017 11:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/07/14/building-fault-tolerant-software-with-transactions/</guid>
      <description>&lt;p&gt;This is a series of blog posts to build a transaction manager in C. Having
implemented thread isolation, we will now look at error handling. Our goal
is to automate error handling as much as possible and make building
fault-tolerant software easy.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;If you missed earlier entries in the series, you
&lt;a href=&#34;https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/&#34;&gt;might&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/09/transactional-semantics-in-theory-and-practice/&#34;&gt;want&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/12/transaction-roll-back-and-serializability/&#34;&gt;to&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/&#34;&gt;go&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/26/transactional-access-to-arbitrary-memory-locations/&#34;&gt;back&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/01/transactional-memcpy-and-resource-privatization/&#34;&gt;and&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/09/more-on-resource-privatization/&#34;&gt;read&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/16/transaction-logs/&#34;&gt;the&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/23/transactional-malloc-and-free/&#34;&gt;installments&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/30/everything-about-errno-plus-transactions/&#34;&gt;so&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/07/07/types-of-transactional-operations/&#34;&gt;far&lt;/a&gt;.&lt;/p&gt;
&lt;h4 id=&#34;overview&#34;&gt;Overview&lt;/h4&gt;
&lt;p&gt;In the very first installment of the series, I claimed that the
transaction manager provides thread isolation and error handling
to its transactions; with a clear implication that transactional
code would do better than its traditional counter part.  But so
far we&amp;rsquo;ve only looked at thread isolation. We have built a basic
implementation of Software Transactional Memory and added support
for a few C functions on top.&lt;/p&gt;
&lt;p&gt;In this and the next blog post, we&amp;rsquo;re going to discuss error handling
and automate it as much as possible. This time we cover the theory, and
next time we add an implementation to our &lt;em&gt;simpletm&lt;/em&gt; transaction
manager. In the end, we&amp;rsquo;ll have infrastructure that allows for easy
creation of fault-tolerant software.&lt;/p&gt;
&lt;h4 id=&#34;the-tradional-approach&#34;&gt;The Tradional Approach&lt;/h4&gt;
&lt;p&gt;A typical pattern of C code looks like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;enum&lt;/span&gt; result {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    failure,
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    success
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;};
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;enum&lt;/span&gt; result
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;func&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#a6e22e&#34;&gt;call_1&lt;/span&gt;() &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; failure) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; err_call_1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#a6e22e&#34;&gt;call_2&lt;/span&gt;() &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; failure) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; err_call_2;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#a6e22e&#34;&gt;call_3&lt;/span&gt;() &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; failure) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; err_call_3;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; success;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;err_call_3:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;revert_call_2&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;err_call_2:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;revert_call_1&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;err_call_1:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; failure;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The function &lt;code&gt;func()&lt;/code&gt; invokes 3 other functions named &lt;code&gt;call_1()&lt;/code&gt;, &lt;code&gt;call_2()&lt;/code&gt;,
and &lt;code&gt;call_3()&lt;/code&gt;. If either fails, the execution moves to the end of &lt;code&gt;func()&lt;/code&gt;
and executes a block of clean-up code to revert the effects of the already
completed functions.&lt;/p&gt;
&lt;p&gt;Although hard coded, these goto statements and labels act like an undo log
in a transaction: all the executed operations are un-done and the system
moves back into its previous state.&lt;/p&gt;
&lt;p&gt;When &lt;code&gt;func()&lt;/code&gt; returns &lt;code&gt;failure&lt;/code&gt;, the calling code could try to repair the
problem and retry the invocation.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;repair_func&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* repair errors of func() */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;main&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; argc, &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; argv[])
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;try_func:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#a6e22e&#34;&gt;func&lt;/span&gt;() &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; failure) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;repair_func&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; try_func;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; EXIT_SUCCESS;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Here, the &lt;code&gt;main()&lt;/code&gt; function invokes &lt;code&gt;func()&lt;/code&gt; and tries to repair any errors
that might happen. Erroneous invocations are re-started after the repair.&lt;/p&gt;
&lt;p&gt;This pattern works very well in traditional C programs, but has a few
drawbacks.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The error handling interleaves with the application code. The application
logic, the error detection and the error recovery is all mixed in the
same location.&lt;/li&gt;
&lt;li&gt;The error handling is hard coded and cannot be re-used easily. Similar
code requires similar error handling, which has to be re-written. Any
changes later on have to be applied to all error-handling code.&lt;/li&gt;
&lt;li&gt;The code is not well structured. There are quite a few goto statements
and labels. In more complex programs, it&amp;rsquo;s not always easy to follow
these jumps.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;the-transactional-approach&#34;&gt;The Transactional Approach&lt;/h4&gt;
&lt;p&gt;Transactions can help to solve these problems. As with thread isolation,
application logic is separate from the error detection. The former is
given by the application programmer, the latter is entirely implemented
within the transaction framework. Error recovery also is provided by
the application programmer, but separated from the application logic.&lt;/p&gt;
&lt;p&gt;To implement error handling, let us first extend our transaction manager&amp;rsquo;s
interface a bit. So far, a transaction is only confined by &lt;code&gt;tm_begin&lt;/code&gt; and
&lt;code&gt;tm_commit&lt;/code&gt;. All transactional application logic is listed between these
two statements. This is called &lt;em&gt;execution phase&lt;/em&gt;. Once the transaction
reached &lt;code&gt;tm_commit&lt;/code&gt;, it entered the &lt;em&gt;commit phase.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;We now extend this interface with a new statement called &lt;code&gt;tm_end&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* execution phase */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_commit   &lt;span style=&#34;color:#75715e&#34;&gt;/* commit phase */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* recovery phase */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_end
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;code&gt;tm_end&lt;/code&gt; follows after &lt;code&gt;tm_commit&lt;/code&gt; and marks the end of the transaction.
The code between &lt;code&gt;tm_commit&lt;/code&gt; and &lt;code&gt;tm_end&lt;/code&gt; is provided by the application
programmer to repair possible errors. We call this the &lt;em&gt;recovery phase.&lt;/em&gt;
The transaction framework only invokes recovery if it detects an error.&lt;/p&gt;
&lt;p&gt;An error-free transaction still looks like before.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Perform &lt;code&gt;tm_begin&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Perform the execution phase.&lt;/li&gt;
&lt;li&gt;Perform &lt;code&gt;tm_commit&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Leave the transaction by executing the next instruction after &lt;code&gt;tm_end&lt;/code&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;An erroneous transaction instead runs the recovery phase.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Perform &lt;code&gt;tm_begin&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Perform the execution phase up to the point were the error happens. The
error is detected within the framework. All transactional operations;
such as &lt;code&gt;load()&lt;/code&gt;, &lt;code&gt;store()&lt;/code&gt;, &lt;code&gt;malloc_tx()&lt;/code&gt; or &lt;code&gt;free_tx()&lt;/code&gt;; are provided
by the transaction manager. Their implementation detects the error
internally. The transactional application logic does not have to do
error detection.&lt;/li&gt;
&lt;li&gt;Roll-back the transaction log. In traditional code, an equivalent
operation is performed by the clean-up code at the end of &lt;code&gt;func()&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Perform the recovery phase. The recovery code is application specific
and has to be provided by the application programmer.&lt;/li&gt;
&lt;li&gt;After successful recovery, restart the transaction&amp;rsquo;s execution phase.&lt;/li&gt;
&lt;li&gt;Perform &lt;code&gt;tm_commit&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Leave the transaction by executing the next instruction after &lt;code&gt;tm_end&lt;/code&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If done correctly, there is no difference between the result of an error-free
run, and the result of an erroneous run with successful recovery.&lt;/p&gt;
&lt;p&gt;Although rather abstract, let&amp;rsquo;s re-write the original example as transactional
code.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;repair_func&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* repair errors of func() */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;main&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; argc, &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; argv[])
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;call_1_tx&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;call_2_tx&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;call_3_tx&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;repair_func&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;tm_restart&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tm_end
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; EXIT_SUCCESS;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We&amp;rsquo;ve replaced the function &lt;code&gt;func()&lt;/code&gt; with a transaction. During the
execution phase, the transaction invokes &lt;code&gt;call_1_tx()&lt;/code&gt; to &lt;code&gt;call_3_tx()&lt;/code&gt;
These operations run the respective &lt;code&gt;call_?()&lt;/code&gt; function and append
them to the transaction log, together with an undo function. We&amp;rsquo;ve seen
how this works in detail in the
&lt;a href=&#34;https://tzimmermann.org/2017/06/23/transactional-malloc-and-free/&#34;&gt;blog post on transactional &lt;code&gt;malloc()&lt;/code&gt;&lt;/a&gt;. Shown below is
a pseudo implementation of &lt;code&gt;call_1_tx()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;undo_call_1_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; data)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;revert_call_1&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;call_1_tx&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#a6e22e&#34;&gt;call_1&lt;/span&gt;() &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; success) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;append_to_log&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;append_to_log&lt;/span&gt;(NULL, undo_call_1_tx, &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;tm_recover&lt;/span&gt;(); &lt;span style=&#34;color:#75715e&#34;&gt;/* does not return */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The functions &lt;code&gt;call_1_tx()&lt;/code&gt; to &lt;code&gt;call_3_tx()&lt;/code&gt; also perform error detection
internally. If either function fails, it instructs the transaction manager
to perform a rollback and invoke the recovery phase.&lt;/p&gt;
&lt;p&gt;The recovery phase starts with a call to &lt;code&gt;repair_func()&lt;/code&gt;. What exactly it
does is dependent on the application; maybe it runs the garbage collector to
free memory, or cleans up files to free disk space. In any case it can at
least send an email to the administrator and shut down the software
gracefully, so even sever errors don&amp;rsquo;t go unnoticed.&lt;/p&gt;
&lt;p&gt;After a successful repair, the recovery code invokes &lt;code&gt;tm_restart()&lt;/code&gt;, which
restarts the transaction&amp;rsquo;s execution phase. It now either succeeds by
committing the transaction or detects another error and re-runs the
recovery phase.&lt;/p&gt;
&lt;p&gt;You can see from this abstract example, how we&amp;rsquo;ve solved the traditional
code&amp;rsquo;s problems with error handling.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;We cleanly separated application logic from error handling. For the
error handling, we further separated error detection (i.e., done within
the framework) from error recovery (i.e., done during the recovery phase).&lt;/li&gt;
&lt;li&gt;Error detection is implemented once by each transactional operation. The
detection code is re-used for each transaction and freely combined with
other operation&amp;rsquo;s error detection.&lt;/li&gt;
&lt;li&gt;Error recovery has to be implemented only once by the application
programmer. The code in &lt;code&gt;repair_func()&lt;/code&gt; could repair all kinds of errors,
not just those specific to our example.&lt;/li&gt;
&lt;li&gt;All goto statements and labels are gone, making the transactional code
much more readable.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we&amp;rsquo;ve discussed the problems of error handling, and looked
at the solution the transaction&amp;rsquo;s provide.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Traditional code interleaves application logic, error detection and
error recovery; making the result hard to read and maintain.&lt;/li&gt;
&lt;li&gt;Transactional code detects errors within the transaction manager&amp;rsquo;s
framework.&lt;/li&gt;
&lt;li&gt;Each transaction contains a specific &lt;em&gt;recovery phase&lt;/em&gt; that implements
recovery strategies for specific errors.&lt;/li&gt;
&lt;li&gt;If the transaction framework detects an error, it rolls back the
transaction&amp;rsquo;s execution and runs the recovery code.&lt;/li&gt;
&lt;li&gt;After a successful recovery, the transction can be re-executed.&lt;/li&gt;
&lt;li&gt;Transactional code cleanly separates application logic, error detection
and error recovery.&lt;/li&gt;
&lt;li&gt;The result of an erroneous transaction with successful recovery is the
same as the result of the same transasction after and an error-free run.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This blog post was fairly high-level and abstract. In the next installment,
we&amp;rsquo;ll add an implementation to our &lt;em&gt;simpletm&lt;/em&gt; toy transaction manager. All
this (and more) is already provided by &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt;, the system-level
transaction manger.&lt;/p&gt;
&lt;p&gt;If you like this series about writing a transaction manager in C, please
subscribe to the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Types of Transactional Operations</title>
      <link>https://tzimmermann.org/2017/07/07/types-of-transactional-operations/</link>
      <pubDate>Fri, 07 Jul 2017 10:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/07/07/types-of-transactional-operations/</guid>
      <description>&lt;p&gt;This is a series of blog posts to build a transaction manager in C. In this
installment, we&amp;rsquo;re going to take a closer look at the different types of
functions that exist and what we have to do to handle them in a transaction.&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;ve already implemented support for several interfaces from the C Standard
Library in our transaction manager. We&amp;rsquo;re now going to sort and formalize
this a bit.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;If you missed earlier entries in the series, you might
&lt;a href=&#34;https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/&#34;&gt;want&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/09/transactional-semantics-in-theory-and-practice/&#34;&gt;to&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/12/transaction-roll-back-and-serializability/&#34;&gt;go&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/&#34;&gt;back&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/26/transactional-access-to-arbitrary-memory-locations/&#34;&gt;and&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/01/transactional-memcpy-and-resource-privatization/&#34;&gt;read&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/09/more-on-resource-privatization/&#34;&gt;the&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/16/transaction-logs/&#34;&gt;installments&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/23/transactional-malloc-and-free/&#34;&gt;so&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/30/everything-about-errno-plus-transactions/&#34;&gt;far&lt;/a&gt;.&lt;/p&gt;
&lt;h4 id=&#34;overview&#34;&gt;Overview&lt;/h4&gt;
&lt;p&gt;Initially we only had support for memory operations in our transaction
manager. On top of that, we added memory and string helper functions, such
as &lt;code&gt;memcpy()&lt;/code&gt;. With the introduction of the transaction log, we have also
added support for &lt;code&gt;malloc()&lt;/code&gt; and &lt;code&gt;free()&lt;/code&gt;, which required either reversal
during roll back or delay to commit.&lt;/p&gt;
&lt;p&gt;We can distiguish 4 different classes of transactional functions. A
transactional function is either&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;pure,&lt;/li&gt;
&lt;li&gt;deferable,&lt;/li&gt;
&lt;li&gt;revocable, or&lt;/li&gt;
&lt;li&gt;irrevocable.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Sorted roughly by their impact on the transaction system, these classes
differ in the kind of support they require from the transaction manager
and consequently the amount of work they require for an implementation.&lt;/p&gt;
&lt;h4 id=&#34;pure-functions&#34;&gt;Pure Functions&lt;/h4&gt;
&lt;p&gt;&lt;em&gt;Pure functions&lt;/em&gt; don&amp;rsquo;t have any dependencies or side effects that interfere
with the transaction.&lt;/p&gt;
&lt;p&gt;One example on Linux systems is &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/pthread_self.html&#34;&gt;&lt;code&gt;pthread_self()&lt;/code&gt;&lt;/a&gt;,
which returns the calling thread&amp;rsquo;s id. The function doesn&amp;rsquo;t depend on any
parameters or mutable state. The returned id is constant for each thread.
In a transaction, we can call &lt;code&gt;pthread_self()&lt;/code&gt; without further considerations.&lt;/p&gt;
&lt;p&gt;Another example is &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/fmin.html&#34;&gt;&lt;code&gt;fmin()&lt;/code&gt;&lt;/a&gt;, a function that returns the
smaller of two values of type &lt;code&gt;double&lt;/code&gt;. The parameters it receives are the
two values to compare. Again, no pointers or mutable state that this function
depends on. A call to &lt;code&gt;fmin&lt;/code&gt; doesn&amp;rsquo;t even generate errors. There&amp;rsquo;s a result
for all possible input values, even &lt;em&gt;NaN.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;A &lt;code&gt;load()&lt;/code&gt; operation on transactional memory is also pure. While its result
depends on the memory&amp;rsquo;s content, &lt;code&gt;load()&lt;/code&gt; doesn&amp;rsquo;t change non-transactional
mutable state.&lt;/p&gt;
&lt;p&gt;Handling pure functions is easy. We can call them directly from within the
transaction.&lt;/p&gt;
&lt;h4 id=&#34;deferable-functions&#34;&gt;Deferable Functions&lt;/h4&gt;
&lt;p&gt;The next class after pure functions are deferable functions. A &lt;em&gt;deferable
function&lt;/em&gt; does not have an immediate effect on the transaction and can be
defered until commit time.&lt;/p&gt;
&lt;p&gt;A common deferable function that we&amp;rsquo;ve already seen is &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/free.html&#34;&gt;&lt;code&gt;free()&lt;/code&gt;&lt;/a&gt;.
Free releases a block of dynamically allocated memory. It accepts a pointer
to the memory block as its only argument. After &lt;code&gt;free()&lt;/code&gt; returns, the
content of the memory block is invalid and accessing it is an undefined
operation.&lt;/p&gt;
&lt;p&gt;If we&amp;rsquo;d free the memory during the transaction&amp;rsquo;s execution, there&amp;rsquo;d be no
way of rolling back the transaction later, as free operations cannot be
reverted.&lt;/p&gt;
&lt;p&gt;However, there&amp;rsquo;s no need to actually free the memory at this point. Instead
we defer the free operation until commit time. In the case of a roll back
of the transaction, we simply ignore the call to &lt;code&gt;free()&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Another example of a deferable function is the &lt;code&gt;store()&lt;/code&gt; operation we
implemented for transactional memory. Stores in write-back mode buffer
the written data and defer it until commit time.&lt;/p&gt;
&lt;p&gt;The main criteria for a deferable function is that it has an effect on
non-transactional mutable state, but the effect is either not immeditely
visible, or can be simulated within the transaction.&lt;/p&gt;
&lt;h4 id=&#34;revocable-functions&#34;&gt;Revocable Functions&lt;/h4&gt;
&lt;p&gt;In some way, a revocable function is the opposite of a deferable function.
A &lt;em&gt;revocable function&lt;/em&gt; is executed during the transaction, but it&amp;rsquo;s effects
are revoked (or reverted) during the transaction&amp;rsquo;s roll back.&lt;/p&gt;
&lt;p&gt;In our case, we&amp;rsquo;ve already seen &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/malloc.html&#34;&gt;&lt;code&gt;malloc()&lt;/code&gt;&lt;/a&gt; as an example of
a revokable function. A call to &lt;code&gt;malloc()&lt;/code&gt; returns a dynamically allocated
block of memory. This operation has to be executed immediately during the
transaction as the memory might be required during subsequent operations
within the transaction.&lt;/p&gt;
&lt;p&gt;To support &lt;code&gt;malloc()&lt;/code&gt;, the transaction executes the operation immediately
and returns the allocated memory block. If it rolls back the transaction
later, the transaction manager frees the allocated block automatically.&lt;/p&gt;
&lt;p&gt;Another example is a &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/read.html&#34;&gt;&lt;code&gt;read()&lt;/code&gt;&lt;/a&gt; operation on a file. Whatever
gets read might have an effect on the transaction, so the data returned by
the read operation is immediately required. But reading has no side-effects
on the data itself. It mostly changes the file offset at which the next read
operation takes place. The change to the offset can be revoked by restoring
the old offset during a roll back. So reading from a file is a revocable
operation.&lt;/p&gt;
&lt;p&gt;As a third example, again &lt;code&gt;store()&lt;/code&gt; can act like a revocable function. When
executed in write-through mode, &lt;code&gt;store()&lt;/code&gt; immediately writes the data to
memory. It keeps a copy of the old data, which is restored during a roll
back.&lt;/p&gt;
&lt;p&gt;Revocable functions have an effect on the transaction&amp;rsquo;s execution and
therefore have to be performed immediately. The effects on non-transactional
mutable state can be revoked during a roll back.&lt;/p&gt;
&lt;h4 id=&#34;irrevocable-functions&#34;&gt;Irrevocable Functions&lt;/h4&gt;
&lt;p&gt;Finally we have irrevocable functions. The result of an &lt;em&gt;irrevocable
function&lt;/em&gt; is immeditely required, but there&amp;rsquo;s no way of revoking it&amp;rsquo;s effects
on non-transactional mutable state.&lt;/p&gt;
&lt;p&gt;An example of an irrevocable function is a &lt;code&gt;read()&lt;/code&gt; operation on a Unix pipe,
which is often used to transfer data from one program to another program.
Similar to a file, invoking &lt;code&gt;read()&lt;/code&gt; on a pipe returns the next block of
data. Unlike a file, a pipe doesn&amp;rsquo;t provide any means of reverting the effect
of the read operation. Once it has read data from the pipe, the transaction
has no way of putting back the data into a pipe during a roll back. The
effect of calling &lt;code&gt;read()&lt;/code&gt; on a pipe is therefore not revocable. The function
is thus irrevocable.&lt;/p&gt;
&lt;p&gt;The only way to support irrevocable functions is to guarantee that a
transaction is not rolled back after it executed an irrevocable function. This
has a number of consequences for the transactional system as a whole.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;A transaction has to explicitly request irrevocability from the
transaction manager. This requires support by the transaction manager.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Once it a transaction is irrevocable, it wins any conflict with
concurrent transactions.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;At any time, there can only be one irrevocable transaction. Imagine
there were two irrevocable transactions at the same time. If there&amp;rsquo;s
a conflict between these two transactions, it would not be possible
to pick a loser without violating irrevocability.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The easiest way of supporting irrevocability is to run the irrevocable
transaction exclusively. When a transaction requests irrevocability, all
other transactions are stopped, rolled back, and suspended until the
irrevocable transaction committed. So there are either multiple revocable
transactions running, or at most one irrevocable transaction. This is the
same semantics as for reader/writer lock and that&amp;rsquo;s how it&amp;rsquo;s implemented.&lt;/p&gt;
&lt;p&gt;A more elaborated implementation would use a lock manager. This component
of the transaction manager observes the state of resource locks, and resolves
conflicts between transactions. When it has to resolve a conflict between the
irrevocable transaction and a revocable transaction, it would always pick the
irrevocable transaction as winner.&lt;/p&gt;
&lt;p&gt;To summarize, irrevocable functions have an effect on the transaction&amp;rsquo;s
execution and therefore have to be performed immeditely. The effects on
non-transactional mutable state cannot be revoked during a roll back, so
the transaction may not perform a roll back at all.&lt;/p&gt;
&lt;h4 id=&#34;special-cases&#34;&gt;Special Cases&lt;/h4&gt;
&lt;p&gt;Aside from the 4 basic types, there are a number of special cases.&lt;/p&gt;
&lt;p&gt;First of all, there are functions that are both deferable and recovable. One
such function is &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/realloc.html&#34;&gt;&lt;code&gt;realloc()&lt;/code&gt;&lt;/a&gt;, which changes the size of an
already allocated block of memory. A call to &lt;code&gt;realloc()&lt;/code&gt; has to be performed
immediately as the allocated memory has to be returned into the transaction.
This memory has to be released during a roll back. The memory block of the
old size also has to be released, but only at commit time. An implementing
of a transactional &lt;code&gt;realloc()&lt;/code&gt; is a combination of &lt;code&gt;malloc()&lt;/code&gt; and &lt;code&gt;free()&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Another special case happens when functions change their type depending
on some internal state. We&amp;rsquo;ve already seen &lt;code&gt;store()&lt;/code&gt; and &lt;code&gt;read()&lt;/code&gt;. These
functions&amp;rsquo; type depends on parameters and internal state.&lt;/p&gt;
&lt;p&gt;Finally, there are operations that simple don&amp;rsquo;t make sense in the context
of a transaction. These usually concern program state as a whole. Calling
functions like &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/exit.html&#34;&gt;&lt;code&gt;exit()&lt;/code&gt;&lt;/a&gt;, &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/exec.html&#34;&gt;&lt;code&gt;exec()&lt;/code&gt;&lt;/a&gt;, or
&lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/abort.html&#34;&gt;&lt;code&gt;abort()&lt;/code&gt;&lt;/a&gt; will end the current program in some way. Calling
them within a transaction would probably lead to an inconsistent state of
the system.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we&amp;rsquo;ve discussed the different types of transactional
functions.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Pure functions have no effect on non-transactional state.&lt;/li&gt;
&lt;li&gt;Deferable functions are defered until commit time. Their effects on
non-transactional state are simulated to the transaction.&lt;/li&gt;
&lt;li&gt;Revocable functions are executed immediately during the transaction,
but their effects on non-tranactional state are reverted during a
roll back.&lt;/li&gt;
&lt;li&gt;Irrevocable functions are executed immediately, but their effects on
non-transactional state cannot be reverted. A transaction may not
have to roll back after executing an irrevocable function.&lt;/li&gt;
&lt;li&gt;Functions can change their type, depending on the parameters or the
transaction&amp;rsquo;s state.&lt;/li&gt;
&lt;li&gt;Some functions have no meaningful semantics in the context of
transactions.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you like this series about writing a transaction manager in C, please
subscribe to the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Everything About errno; plus Transactions</title>
      <link>https://tzimmermann.org/2017/06/30/everything-about-errno-plus-transactions/</link>
      <pubDate>Fri, 30 Jun 2017 10:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/06/30/everything-about-errno-plus-transactions/</guid>
      <description>&lt;p&gt;This is a series of blog posts to build a transaction manager in C. In this
entry, we&amp;rsquo;r going to take a look at &lt;code&gt;errno&lt;/code&gt; and how it works behind the
scenes. Afterwards we&amp;rsquo;re going to add support for &lt;code&gt;errno&lt;/code&gt; to our transaction
manager &lt;em&gt;simpletm&lt;/em&gt;.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;If you missed earlier entries in the series, you might want
&lt;a href=&#34;https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/&#34;&gt;to&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/09/transactional-semantics-in-theory-and-practice/&#34;&gt;go&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/12/transaction-roll-back-and-serializability/&#34;&gt;back&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/&#34;&gt;and&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/26/transactional-access-to-arbitrary-memory-locations/&#34;&gt;read&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/01/transactional-memcpy-and-resource-privatization/&#34;&gt;the&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/09/more-on-resource-privatization/&#34;&gt;installments&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/16/transaction-logs/&#34;&gt;so&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/23/transactional-malloc-and-free/&#34;&gt;far&lt;/a&gt;. Entries are self-contained as much as possible, but
knowning the big picture might by helpful in some cases.&lt;/p&gt;
&lt;h4 id=&#34;communicating-problems&#34;&gt;Communicating Problems&lt;/h4&gt;
&lt;p&gt;The C and POSIX standards specify a multitude of ways for reporting errors
to a program.&lt;/p&gt;
&lt;p&gt;If you do something critical, such as accessing unmapped memory regions,
you&amp;rsquo;ll get a signal distributed from the operating system; for example
SIGSEGV in the case of unmapped memory. Usually these critical signals
cannot be ignored. You have to handle them, or the operating system will
abort the program.&lt;/p&gt;
&lt;p&gt;But signals are rather uncommon. Most interfaces in C or POSIX return the
integer value of &lt;em&gt;-1&lt;/em&gt; on errors and provide an additional way of retreiving
information about the actual error.&lt;/p&gt;
&lt;p&gt;For floating-point operations, there are floating-point exceptions. These
can be queries with &lt;code&gt;fgetexceptflag()&lt;/code&gt;. Divide by zero and you&amp;rsquo;ll get
&lt;code&gt;FE_DIVBYZERO&lt;/code&gt;, for example.&lt;/p&gt;
&lt;p&gt;One of the oldest methods for communicating errors is by setting an error
code. Traditional error codes in C are provided in the header file
&lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/basedefs/errno.h.html&#34;&gt;&lt;em&gt;errno.h&lt;/em&gt;&lt;/a&gt;. There you&amp;rsquo;ll find short identifier for all kinds
of possible errors: &lt;code&gt;ENOMEM&lt;/code&gt; for out-of-memory situations, &lt;code&gt;EACCES&lt;/code&gt; when
file access has been denied, or &lt;code&gt;EINVAL&lt;/code&gt; if an incorrect argument was given
to a function. Each identifier maps to a positiv integer value, but the
actual value is system-dependent.&lt;/p&gt;
&lt;p&gt;Some more-recent interfaces, such as POSIX threads, return error codes
directly, but most POSIX interfaces store them in the variable named &lt;code&gt;errno&lt;/code&gt;.&lt;/p&gt;
&lt;h4 id=&#34;the-history-of-errno&#34;&gt;The History of errno&lt;/h4&gt;
&lt;p&gt;The variable &lt;code&gt;errno&lt;/code&gt; is quite old. I searched through the source code of
&lt;a href=&#34;http://www.tuhs.org/&#34;&gt;The Unix Heritage Society&lt;/a&gt; and found its first in-code appearance in
&lt;a href=&#34;http://github.com/dspinellis/unix-history-repo/blob/Research-V5-Snapshot-Development/usr/source/s4/perror.c#L1&#34;&gt;Unix Release V5&lt;/a&gt;. According to the git history, the commit
was made on Nov 27 1974! Back then, there was no file named &lt;em&gt;errno.h.&lt;/em&gt;
Instead &lt;code&gt;errno&lt;/code&gt; was implemented as part of &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/perror.html&#34;&gt;&lt;code&gt;perror()&lt;/code&gt;&lt;/a&gt;,
a function that outputs a descriptive string for each error code.&lt;/p&gt;
&lt;p&gt;The error codes are even older than &lt;code&gt;errno&lt;/code&gt;. The earliest error codes I
could find were in the source code of &lt;a href=&#34;http://github.com/dspinellis/unix-history-repo/blob/Research-V4-Snapshot-Development/sys/user.h#L39&#34;&gt;Unix Release V4&lt;/a&gt;.
This file dates back to Aug 31 1973. The error codes were stored in the
field &lt;code&gt;u_error&lt;/code&gt; of &lt;code&gt;struct user&lt;/code&gt;. Even though the &lt;code&gt;errno&lt;/code&gt; variable was
not present in the source code of V4, it&amp;rsquo;s already mentioned on the
&lt;a href=&#34;http://github.com/dspinellis/unix-history-repo/blob/Research-V4-Snapshot-Development/man/man3/perror.3#L28&#34;&gt;man page for &lt;code&gt;perror()&lt;/code&gt;&lt;/a&gt;. This file dates back to
Nov 6 1973, so &lt;code&gt;errno&lt;/code&gt; must have been introduced at some point between
Aug 31 and Nov 6 of 1973.&lt;/p&gt;
&lt;p&gt;If you compare these old error codes to what is present on today&amp;rsquo;s
Unix-like system, you&amp;rsquo;ll find that they are mostly the same. In fact all of
the old error codes are still present. New releases and standards only added
more error codes when required.&lt;/p&gt;
&lt;p&gt;So back in Unix Release V5, &lt;code&gt;errno&lt;/code&gt; was an integer value. Error codes were
still returned in the field &lt;code&gt;u_error&lt;/code&gt; of &lt;code&gt;struct user&lt;/code&gt;, but automatically
copied to &lt;code&gt;errno&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;C was first standardized in the late 1980s and &lt;code&gt;errno&lt;/code&gt; was part of this
standard. It was specified to be &lt;em&gt;a modifiable lvalue of type &lt;code&gt;int&lt;/code&gt;,&lt;/em&gt; just as
it was in Unix.&lt;/p&gt;
&lt;p&gt;Compared to its prominent place in Unix, in the C Standard &lt;code&gt;errno&lt;/code&gt; feels as
if it is either under-used or out of place. Only 3 error codes are part of
the C standard: &lt;code&gt;EDOM&lt;/code&gt;, &lt;code&gt;EILSEQ&lt;/code&gt; and &lt;code&gt;ERANGE&lt;/code&gt;. Many traditional Unix
functions don&amp;rsquo;t have error codes specified. For example, even though
&lt;code&gt;malloc()&lt;/code&gt; is part of the C Standard Library, its error code &lt;code&gt;ENOMEM&lt;/code&gt; is
not.&lt;/p&gt;
&lt;p&gt;The implementation of &lt;code&gt;errno&lt;/code&gt; remained of type &lt;code&gt;int&lt;/code&gt; for roughly 22
years, and then&amp;hellip; multithreading happend.&lt;/p&gt;
&lt;p&gt;In a multithreaded program, having a global variable that signals the error
code is obviously a problem. In the time between one thread observing an
error (i.e., &lt;em&gt;-1&lt;/em&gt; being returned from a function call) and reading the
error code from &lt;code&gt;errno&lt;/code&gt;, an error on another thread could change the value
of &lt;code&gt;errno&lt;/code&gt;. A global &lt;code&gt;errno&lt;/code&gt; variable of type &lt;code&gt;int&lt;/code&gt; is basically useless in
this environment.&lt;/p&gt;
&lt;p&gt;The solution to this problem is illustrated in the example code shown below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#ifdef	_THREAD_SAFE
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;extern&lt;/span&gt;	&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;		&lt;span style=&#34;color:#a6e22e&#34;&gt;__error&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define	errno		(* __error())
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#else
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;extern&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; errno;			&lt;span style=&#34;color:#75715e&#34;&gt;/* global error number */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#endif
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In a thread-safe program, &lt;code&gt;errno&lt;/code&gt; is defined as macro that resolves to a
function call. The function returns a pointer to a thread-local copy of
the error variable and the &lt;code&gt;errno&lt;/code&gt; macro internally dereference the pointer.
This way, accessing &lt;code&gt;errno&lt;/code&gt; returns a thread-local error code.&lt;/p&gt;
&lt;p&gt;The code snipped above has been
&lt;a href=&#34;https://github.com/dspinellis/unix-history-repo/commit/4a81bbc3e8796e1f18f1a5e8ba62836ad71025c2#diff-4c402341f93d93b29dc0f6eb539600f5R46&#34;&gt;taken from a rather confusing commit&lt;/a&gt;
to FreeBSD. The commit was made on Jan 22 1996 and first shipped in FreeBSD
2.2.0.&lt;/p&gt;
&lt;p&gt;Other systems, such as GNU or Linux, traditionally used different
implementations of POSIX and the C Standard Library, but have gone through
a similar transition.&lt;/p&gt;
&lt;h4 id=&#34;transactional-errno&#34;&gt;Transactional errno&lt;/h4&gt;
&lt;p&gt;After this long excurse into history, let&amp;rsquo;s get back to transactions. For
&lt;code&gt;errno&lt;/code&gt; to be transaction-safe, all we have to do is to save its value
before it&amp;rsquo;s being changed by any function. If a transaction aborts, we
reset &lt;code&gt;errno&lt;/code&gt; to its original value, so the transactions always restarts
with the same error code. As the variable itself is already thread-local,
no concurrency control is required.&lt;/p&gt;
&lt;p&gt;Building upon &lt;code&gt;malloc()&lt;/code&gt; and &lt;code&gt;free()&lt;/code&gt; support from the
&lt;a href=&#34;https://tzimmermann.org/2017/06/23/transactional-malloc-and-free/&#34;&gt;previous blog entry&lt;/a&gt;, let us first add an interface to safe
&lt;code&gt;errno&lt;/code&gt; during the transaction.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;save_errno&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Too easy.&lt;/p&gt;
&lt;p&gt;For the implementation, we add an errno value to the transaction context
as well as a flag showing the value&amp;rsquo;s validity.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_tx {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    jmp_buf env;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt;        log_length;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_log_entry log[&lt;span style=&#34;color:#ae81ff&#34;&gt;256&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; errno_saved;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; errno_value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;};
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We further have to save &lt;code&gt;errno&lt;/code&gt; and restore its value during a rollback.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;save_errno&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_tx&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; tx &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_get_tx&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;errno_saved) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;errno_value &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; errno;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;errno_saved &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; true;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;tm_restart&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;release_resources&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;arraybeg&lt;/span&gt;(g_resource),
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                      &lt;span style=&#34;color:#a6e22e&#34;&gt;arrayend&lt;/span&gt;(g_resource), false);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_tx&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; tx &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_get_tx&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* Revert logged operations */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;undo_log&lt;/span&gt;(tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log, tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log_length);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log_length &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* Restore errno */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;errno_saved) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        errno &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;errno_value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;errno_saved &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* Jump to the beginning of the transaction */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;longjmp&lt;/span&gt;(tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;env, &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We only save &lt;code&gt;errno&lt;/code&gt; on the first time that &lt;code&gt;save_error()&lt;/code&gt; gets called
in a transaction. That&amp;rsquo;s the error code we&amp;rsquo;re interested in. Later
invocations may not replace is. During a transaction&amp;rsquo;s roll-back and
restart, we check if we saved &lt;code&gt;errno&lt;/code&gt; and possibly restore it to its
original value.&lt;/p&gt;
&lt;p&gt;So far, our transaction manager only supports one function that could
potentially modify &lt;code&gt;errno&lt;/code&gt;, which is &lt;code&gt;malloc_tx()&lt;/code&gt;. Modifying &lt;code&gt;malloc_tx()&lt;/code&gt;
to save &lt;code&gt;errno&lt;/code&gt; is trivial.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;malloc_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; size)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;save_errno&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;append_to_log&lt;/span&gt;(NULL, undo_malloc_tx, (&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)ptr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; ptr;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;That&amp;rsquo;s the same implementation as in the previous blog post, extended by
a call to &lt;code&gt;save_errno()&lt;/code&gt;.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;We&amp;rsquo;ve looked at &lt;code&gt;errno&lt;/code&gt; and how to support it in a system transaction.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;errno&lt;/code&gt; has a long history, dating back to the earliest Unix releases.&lt;/li&gt;
&lt;li&gt;Today, &lt;code&gt;errno&lt;/code&gt; is implemented as a thread-local variable.&lt;/li&gt;
&lt;li&gt;Before executing an operation that modifies the value of &lt;code&gt;errno&lt;/code&gt;,
the original value has to be saved in the transaction context.&lt;/li&gt;
&lt;li&gt;During a roll-back of the transaction, &lt;code&gt;errno&lt;/code&gt; is restored to its
original value.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As usually, you can find the full source code for this blog post
&lt;a href=&#34;http://github.com/tdz/blog_examples/tree/master/2017-06-30&#34;&gt;on GitHub&lt;/a&gt;. If you&amp;rsquo;re interested in a more sophisticated C
transaction manager, take a look at &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you like this series about writing a transaction manager in C, please
subscribe to the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Transactional malloc() and free()</title>
      <link>https://tzimmermann.org/2017/06/23/transactional-malloc-and-free/</link>
      <pubDate>Fri, 23 Jun 2017 12:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/06/23/transactional-malloc-and-free/</guid>
      <description>&lt;p&gt;This is a series of blog posts to build a transaction manager in C. In
this installment we&amp;rsquo;re going to implement support for
&lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/malloc.html&#34;&gt;&lt;code&gt;malloc()&lt;/code&gt;&lt;/a&gt; and &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/free.html&#34;&gt;&lt;code&gt;free()&lt;/code&gt;&lt;/a&gt;. With these functions
we can allocate and free blocks of memory, and automatically garbage-collect
allocated blocks if an error or conflict occures during the transaction.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;If you missed earlier entries in the series, you might want to go
&lt;a href=&#34;https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/&#34;&gt;back&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/09/transactional-semantics-in-theory-and-practice/&#34;&gt;and&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/12/transaction-roll-back-and-serializability/&#34;&gt;read&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/&#34;&gt;the&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/26/transactional-access-to-arbitrary-memory-locations/&#34;&gt;installments&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/01/transactional-memcpy-and-resource-privatization/&#34;&gt;so&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/09/more-on-resource-privatization/&#34;&gt;far&lt;/a&gt;.
You should especially read &lt;a href=&#34;https://tzimmermann.org/2017/06/16/transaction-logs/&#34;&gt;last week&amp;rsquo;s entry&lt;/a&gt;, which
introduces transaction logs and gives some information about use cases and
scenarios.&lt;/p&gt;
&lt;h4 id=&#34;the-problems-of-malloc-and-free&#34;&gt;The Problems of malloc() and free()&lt;/h4&gt;
&lt;p&gt;One of last week&amp;rsquo;s example transactions looked like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;load&lt;/span&gt;(...);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;store&lt;/span&gt;(...);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;There&amp;rsquo;s an invocation to &lt;code&gt;malloc()&lt;/code&gt; near the beginning of the transaction,
and several &lt;code&gt;load()&lt;/code&gt; and &lt;code&gt;store()&lt;/code&gt; operations later in the transaction. If
the transaction has to roll back and restart, the malloc&amp;rsquo;ed memory buffer
would leak. We therefore need a way of freeing the memory during the rollback.&lt;/p&gt;
&lt;p&gt;Another example illustrated the problem with &lt;code&gt;free()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;load&lt;/span&gt;(...);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;free&lt;/span&gt;(buf);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;store&lt;/span&gt;(...);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Here we free a memory buffer that was allocated outside the transaction. If
the transaction has to roll back afterwards, there&amp;rsquo;s no way to un-do the
effects of the &lt;code&gt;free()&lt;/code&gt; operation. Hence, we&amp;rsquo;d work on invalid data after a
restart. We can only release memory if we know that the transaction commits.&lt;/p&gt;
&lt;p&gt;The solution that we saw in the previous blog post was to keep a log of
operations that either require rollback, or have to be delayed until commit.&lt;/p&gt;
&lt;h4 id=&#34;extending-the-transaction-manager&#34;&gt;Extending the Transaction Manager&lt;/h4&gt;
&lt;p&gt;To extend our transaction manager with a log, we first have to know how
the log entry has to look like. We require a function to apply an operation
during commit, un-do an operation during rollback, and we need some
additional user data for each operation.&lt;/p&gt;
&lt;p&gt;So the log entry might look like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_log_entry {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;        (&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;apply)(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; data);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;        (&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;undo)(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; data);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;    data;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;};
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We add an array of these structures to our transaction&amp;rsquo;s internal data
structure.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_tx {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    jmp_buf env;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt;        log_length;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_log_entry log[&lt;span style=&#34;color:#ae81ff&#34;&gt;256&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;};
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The log&amp;rsquo;s initial length at the start of the transaction is 0. Using a
static array limits our number of log entries to a certain maximum,
256 in this case, but that&amp;rsquo;s OK for an example. The log in &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt;
can grow until it reaches system limits.&lt;/p&gt;
&lt;p&gt;How do we append to this log? We have to add a new public interface to the
transaction manager.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;append_to_log&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;apply)(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;),
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;              &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;undo)(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;), &lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; data)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_tx&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; tx &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_get_tx&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;assert&lt;/span&gt;(tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log_length &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;arraylen&lt;/span&gt;(tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_log_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; entry &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log_length;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    entry&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;apply &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; apply;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    entry&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;undo  &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; undo;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    entry&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;data  &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; data;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log_length;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The implementation of &lt;code&gt;append_to_log()&lt;/code&gt; is fairly trivial. It acquires the
next available element of the log array and fills it with the arguments it
got from the caller. These are the &lt;code&gt;apply()&lt;/code&gt; and &lt;code&gt;undo()&lt;/code&gt; functions, and
some user data.&lt;/p&gt;
&lt;p&gt;Finally what we need is some extra code to execute these &lt;code&gt;apply()&lt;/code&gt; and
&lt;code&gt;undo()&lt;/code&gt; functions. Here&amp;rsquo;s the apply code.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;apply_log&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_log_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; beg, &lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_log_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; end)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (beg &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; end) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (beg&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;apply) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            beg&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;apply&lt;/span&gt;(beg&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;data);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;beg;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_commit&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;release_resources&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;arraybeg&lt;/span&gt;(g_resource),
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                      &lt;span style=&#34;color:#a6e22e&#34;&gt;arrayend&lt;/span&gt;(g_resource), true);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_tx&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; tx &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_get_tx&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* Perform logged operations */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;apply_log&lt;/span&gt;(tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log, tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log_length);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log_length &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The function &lt;code&gt;apply_log()&lt;/code&gt; is called by the transaction manager&amp;rsquo;s main commit
function(). It walks over the entries in the log and applys them one by one.
Afterwards the log length is set to 0 again.&lt;/p&gt;
&lt;p&gt;The undo code is similar.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;undo_log&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_log_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; beg, &lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_log_entry&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; end)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (end &lt;span style=&#34;color:#f92672&#34;&gt;&amp;gt;&lt;/span&gt; beg) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;--&lt;/span&gt;end;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (end&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;undo) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            end&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;undo&lt;/span&gt;(end&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;data);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;tm_restart&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;release_resources&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;arraybeg&lt;/span&gt;(g_resource),
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                      &lt;span style=&#34;color:#a6e22e&#34;&gt;arrayend&lt;/span&gt;(g_resource), false);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_tx&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; tx &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_get_tx&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* Revert logged operations */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;undo_log&lt;/span&gt;(tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log, tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log_length);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;log_length &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* Jump to the beginning of the transaction */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;longjmp&lt;/span&gt;(tx&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;env, &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The function &lt;code&gt;undo_log()&lt;/code&gt; walks backwards over the log and un-does each
log entry&amp;rsquo;s effects. It&amp;rsquo;s invoked from the transaction manager&amp;rsquo;s main restart
function. Afterwards the log length is set to 0 again. That&amp;rsquo;s all fairly
trivial, isn&amp;rsquo;t it?&lt;/p&gt;
&lt;p&gt;There&amp;rsquo;s one small caveat that we have to watch out for. It&amp;rsquo;s important
that we first apply all operations on memory resources and then apply the
logged operations. Otherwise it could happen that a transaction first frees
a block of memory and then performs store operations on the just free&amp;rsquo;d
memory. The operation would be undefined.&lt;/p&gt;
&lt;h4 id=&#34;transactional-malloc&#34;&gt;Transactional malloc()&lt;/h4&gt;
&lt;p&gt;Here&amp;rsquo;s the implementation of our transactional malloc function &lt;code&gt;malloc_tx()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;undo_malloc_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; data)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;)data;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;free&lt;/span&gt;(ptr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;malloc_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; size)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;append_to_log&lt;/span&gt;(NULL, undo_malloc_tx, (&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)ptr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; ptr;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;A call to &lt;code&gt;malloc_tx()&lt;/code&gt; allocates memory using standard &lt;code&gt;malloc()&lt;/code&gt;. It
then puts an entry into the log. That entry contains a pointer to the
un-do function and a pointer to the allocated memory. The undo function
&lt;code&gt;undo_malloc_tx()&lt;/code&gt; simply frees the allocated memory buffer.&lt;/p&gt;
&lt;p&gt;Using &lt;code&gt;malloc_tx()&lt;/code&gt; we can rewrite our first example transaction.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc_tx&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;load&lt;/span&gt;(...);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;store&lt;/span&gt;(...);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Any roll-back of this transaction will un-do the effects of &lt;code&gt;malloc_tx()&lt;/code&gt;
by freeing the allocated memory.&lt;/p&gt;
&lt;h4 id=&#34;transactional-free&#34;&gt;Transactional free()&lt;/h4&gt;
&lt;p&gt;The transactional free function &lt;code&gt;free_tx()&lt;/code&gt; looks like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;apply_free_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; data)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;)data;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;free&lt;/span&gt;(ptr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;free_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;append_to_log&lt;/span&gt;(apply_free_tx, NULL, (&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)ptr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;It puts an entry into the log, containing a pointer to the apply function
&lt;code&gt;apply_free_tx()&lt;/code&gt; and a pointer to the buffer that is to be free&amp;rsquo;d. The
apply function later executes the free operation during commit.&lt;/p&gt;
&lt;p&gt;And our second example using &lt;code&gt;free_tx()&lt;/code&gt; looks like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;load&lt;/span&gt;(...);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;free_tx&lt;/span&gt;(buf);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;store&lt;/span&gt;(...);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This transaction can roll back at any time. The memory buffer would
only be free&amp;rsquo;d during commit.&lt;/p&gt;
&lt;h4 id=&#34;freeing-buffers-that-are-in-use&#34;&gt;Freeing Buffers That Are In Use&lt;/h4&gt;
&lt;p&gt;There&amp;rsquo;s one possible scenario that we haven&amp;rsquo;t covered yet. What happens
if the free&amp;rsquo;d buffer is in use by a concurrent transaction?&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s say we free a buffer in one transaction&amp;rsquo;s commit, but another
transaction concurrently performs a store operation on the buffer&amp;rsquo;s memory.
The buffer is gone so the store operation should observe a conflict. The
current implementation wouldn&amp;rsquo;t detect this.&lt;/p&gt;
&lt;p&gt;This problem can be solved fairly easy with memory privatizations. In
&lt;code&gt;free_tx()&lt;/code&gt; we write-privatize the buffer. This will show up any conflict
between the freeing transaction and any transaction that uses the buffer
concurrently.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;free_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; ptr)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; siz &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc_usable_size&lt;/span&gt;(ptr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;privatize&lt;/span&gt;((&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)ptr, siz, false, true);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;append_to_log&lt;/span&gt;(apply_free_tx, NULL, (&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)ptr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The function &lt;a href=&#34;http://man7.org/linux/man-pages/man3/malloc_usable_size.3.html&#34;&gt;&lt;code&gt;malloc_usable_size()&lt;/code&gt;&lt;/a&gt; is provided
by the GNU C Library. For a given allocated buffer, it returns the size of
the allocation. Most allocators provide an interface like this, but it&amp;rsquo;s
unfortunately not standardized.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this block post, we&amp;rsquo;ve implemented support for transactional &lt;code&gt;malloc()&lt;/code&gt;
and &lt;code&gt;free()&lt;/code&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Allocated memory has to be released during rollbacks.&lt;/li&gt;
&lt;li&gt;Freeing memory cannot be undone, so this operation has to be delayed
until commit.&lt;/li&gt;
&lt;li&gt;Invoked operations add themselves to the transaction log.&lt;/li&gt;
&lt;li&gt;The transaction manager uses the log to un-do &lt;code&gt;malloc()&lt;/code&gt; operations.&lt;/li&gt;
&lt;li&gt;The transaction manager uses the log to apply &lt;code&gt;free()&lt;/code&gt; operations.&lt;/li&gt;
&lt;li&gt;Conflicts between a freeing transaction and users of the free&amp;rsquo;d buffer
can be detected by write-privatizing the buffer before performing the
free.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As usually, you can find the full source code for this blog post
&lt;a href=&#34;http://github.com/tdz/blog_examples/tree/master/2017-06-23&#34;&gt;on GitHub&lt;/a&gt;. If you&amp;rsquo;re interested in a more sophisticated C
transaction manager, take a look at &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you like this series about writing a transaction manager in C, please
subscribe to the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Transaction Logs</title>
      <link>https://tzimmermann.org/2017/06/16/transaction-logs/</link>
      <pubDate>Fri, 16 Jun 2017 11:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/06/16/transaction-logs/</guid>
      <description>&lt;p&gt;This is series of blog posts to build a transaction manager in C. We
have already implemented support for transactional memory and simple functions
that operate only on memory, such as &lt;code&gt;memcpy()&lt;/code&gt;. In this installment we&amp;rsquo;re
going to look at logs, transactional logging and transactional memory
allocation.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;If you missed earlier entries in the series, you might want to go
&lt;a href=&#34;https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/&#34;&gt;back&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/09/transactional-semantics-in-theory-and-practice/&#34;&gt;and&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/12/transaction-roll-back-and-serializability/&#34;&gt;read&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/&#34;&gt;the&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/05/26/transactional-access-to-arbitrary-memory-locations/&#34;&gt;installments&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/01/transactional-memcpy-and-resource-privatization/&#34;&gt;so&lt;/a&gt;
&lt;a href=&#34;https://tzimmermann.org/2017/06/09/more-on-resource-privatization/&#34;&gt;far&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This is the first part of a two-part mini-series on transaction logs. In
this entry we&amp;rsquo;re going to examine the uses for transaction logs and how
they work in theory. In the next entry, we&amp;rsquo;ll implement a log for our
transaction manager &lt;em&gt;simpletm.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;If you&amp;rsquo;ve been following this series over the course of the last weeks,
you might have noticed how we&amp;rsquo;re going from more specific use cases to
more broad scenarios, and how we&amp;rsquo;re going from memory operations to
arbitrary functions.&lt;/p&gt;
&lt;p&gt;When we added memory privatization to our transaction manager, we layed the
foundation for calling C functions directly from within a transaction. C
functions often take pointers as their arguments, and memory privatization
is required allow this in a transaction-safe manner.&lt;/p&gt;
&lt;p&gt;In this blog post, we&amp;rsquo;ll do the next step towards support for arbitrary
functions. We&amp;rsquo;ll look at transaction logs and functions that require some
form of transactional log.&lt;/p&gt;
&lt;h4 id=&#34;operations-that-have-to-be-undone&#34;&gt;Operations That Have To Be Undone&lt;/h4&gt;
&lt;p&gt;Let&amp;rsquo;s take a look at the following code fragment.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;load&lt;/span&gt;(...);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;store&lt;/span&gt;(...);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Like many C programs, this transaction allocates memory using &lt;code&gt;malloc()&lt;/code&gt;. This
memory could be a temporary buffer required for an algorithm executed by the
transaction. The transaction further performs several load and store
operations. It could be a producer transaction that creates data for a
consumer.&lt;/p&gt;
&lt;p&gt;Looks good so far, however there&amp;rsquo;s a problem lurking.&lt;/p&gt;
&lt;p&gt;Imaging a conflict happens during one of the load or store operations. If the
transaction tries to acquire a memory location that is owned by a concurrent
transaction, the transaction manager will resolve the conflict usually by
rolling back the transaction that came last.&lt;/p&gt;
&lt;p&gt;This rollback is a problem because of the memory buffer we allocated. Simply
reverting all load and stores and restarting the transaction will leak the
allocated memory.&lt;/p&gt;
&lt;p&gt;To free allocated memory during a rollback, we have to inform the transaction
manager about every allocation we performed during the transaction. This
information is stored in the transaction log.&lt;/p&gt;
&lt;h4 id=&#34;operations-that-have-to-be-delayed&#34;&gt;Operations That Have To Be Delayed&lt;/h4&gt;
&lt;p&gt;Let&amp;rsquo;s further take a look at another example.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;malloc&lt;/span&gt;(size);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;load&lt;/span&gt;(...);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;free&lt;/span&gt;(buf);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;store&lt;/span&gt;(...);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In this program, memory is allocated outside of the transaction using
&lt;code&gt;malloc()&lt;/code&gt;. After the transaction started, it loads several memory
locations and performs computations. As part of the transaction the
allocated memory buffer is released using &lt;code&gt;free()&lt;/code&gt;, and finally some
stores are performed to save the transaction&amp;rsquo;s results. This transaction
could be the consumer to our producer from the previous example.&lt;/p&gt;
&lt;p&gt;This example illustrates another problem. Imaging the transaction frees
the buffer and then one of the store operations observes a conflict. The
transaction would have to rollback and restart. The &lt;code&gt;free()&lt;/code&gt; operation,
however, cannot be rolled back. It has already been performed and the
memory might have already been allocated by another part of the program.&lt;/p&gt;
&lt;p&gt;To allow the rollback of a free operation, we have to delay the invocation
of &lt;code&gt;free()&lt;/code&gt; until the commit happens. This information is also stored in
the transaction log.&lt;/p&gt;
&lt;h4 id=&#34;undo-and-redo&#34;&gt;Undo and Redo&lt;/h4&gt;
&lt;p&gt;The examples above illustrate the two use case that require a log: some
operations require to be reverted during a rollback, some operations
require to be delayed until commit time.&lt;/p&gt;
&lt;p&gt;One can distiguish between undo and redo logs, although implementaions might
not be so strict.&lt;/p&gt;
&lt;p&gt;An &lt;em&gt;undo log&lt;/em&gt; is a log that for each operation stores the old value &lt;em&gt;before&lt;/em&gt;
that operation. It is useful for reverting operations. In the case of
&lt;code&gt;malloc()&lt;/code&gt; it would store a pointer to the allocated memory, so that the
transaction manager knows that &lt;em&gt;before&lt;/em&gt; this invocation of &lt;code&gt;malloc()&lt;/code&gt;,
the memory had not been allocated.&lt;/p&gt;
&lt;p&gt;A &lt;em&gt;redo log&lt;/em&gt; stores the changes for each operation that affects the state
of the transaction. In the case of &lt;code&gt;free()&lt;/code&gt; it stores the pointer that
needs to be freed during commit. With this type of log it&amp;rsquo;s possible to
&lt;em&gt;re-do&lt;/em&gt; the transaction step by step.&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;ve already seen something like these logs before. Let&amp;rsquo;s for a moment
remember the write-back and write-through semantics that we used for store
operations on transactional memory. For each memory resource, we had a
transaction-local buffer that either stored the original value or the
transaction&amp;rsquo;s modified copy.&lt;/p&gt;
&lt;p&gt;In write-back mode the transaction performed all changes in its local buffer,
which was synchronized with the shared global buffer during commit. So the
local buffer acted like a redo log, although it merges all store operations
into one.&lt;/p&gt;
&lt;p&gt;A similar thing is true for write-through mode. For a store, the transaction
first copys the shared global value into its local buffer as a backup. Then
it performed modifications directly on the global buffer. During a rollback
the global buffer is reverted to its original state from the content of the
local buffer. So the local buffer acts like an undo log.&lt;/p&gt;
&lt;h4 id=&#34;implementation-outline&#34;&gt;Implementation Outline&lt;/h4&gt;
&lt;p&gt;A database usually has an abstract interface to the stored data and the
implemented algorithms. Because access happens though abstract languages
such as SQL, the database&amp;rsquo;s implementation might be able to only go with
an undo or redo log only.&lt;/p&gt;
&lt;p&gt;But as mentioned before, an implementation might not be too strict about
distiguishing between undo and redo logs. In our case, we&amp;rsquo;ve already seen
that we require both semantics: the undo semantics for &lt;code&gt;malloc()&lt;/code&gt; and the
redo semantics for &lt;code&gt;free()&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Generally speaking, we can say that we require&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;undo semantics for all operations that allocate resources, and&lt;/li&gt;
&lt;li&gt;redo semantics for all operaionss that release resources.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;An operation that allocates a resource can also be a call to &lt;code&gt;open()&lt;/code&gt; for
opening a file. An operation for releasing a resource can also be a call
to &lt;code&gt;close()&lt;/code&gt; for closing a file descriptor.&lt;/p&gt;
&lt;p&gt;We can simply combine both types of logs into the same data structure. For
each allocating operation we have to&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;perform the operation, because the result is required immediately by
the transaction, and&lt;/li&gt;
&lt;li&gt;put an entry into the log.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;For each releasing operation we have to&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;put and entry into the log, and&lt;/li&gt;
&lt;li&gt;&lt;em&gt;don&amp;rsquo;t&lt;/em&gt; do anything else; especially no the operation itself.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;During a commit we can be sure that the transaction is about to complete. So
we go through the log entries one-by-one and&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;ignore the entry if it refers to an allocating operation. We already
performed these during the transaction&amp;rsquo;s execution phase.&lt;/li&gt;
&lt;li&gt;Apply the entry if it is a releasing operation.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;During a rollback we go backwards through the log entries one-by-one and&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;undo the entry&amp;rsquo;s effects if it refers to an allocating operation, or&lt;/li&gt;
&lt;li&gt;ignore the entry if it refers to a releasing operation. We&amp;rsquo;ll certainly
require the released resource during after the transaction&amp;rsquo;s restart.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As system transactions are about concurrency control and error handling,
each transaction can get by with its own private log. If we have multiple
transactions running concurrently, they won&amp;rsquo;t have to content for access
to a global log. Databases have different use cases and stricter requirements
for their transaction&amp;rsquo;s durability. Therefore they often require logs that
are either shared globally among transactions, or allow for restoring a
global history from the individual transaction&amp;rsquo;s logs. Fortunately none of
this is required in our case.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this block post, we&amp;rsquo;ve investigated the use of logs in our transaction
manager.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Resource-allocating operations have to be undone when the transaction
rolls back.&lt;/li&gt;
&lt;li&gt;Resource-releasing operations have to be delayed when the transaction
commits.&lt;/li&gt;
&lt;li&gt;A transaction log keeps track of all changes performed by a transaction.&lt;/li&gt;
&lt;li&gt;An undo log stores the state &lt;em&gt;before&lt;/em&gt; performing an operation.&lt;/li&gt;
&lt;li&gt;A redo log stores the state change peformed by an operation.&lt;/li&gt;
&lt;li&gt;Both types of logs can be combined into a single data structure.&lt;/li&gt;
&lt;li&gt;Each executed operations puts an entry into the transaction&amp;rsquo;s log.&lt;/li&gt;
&lt;li&gt;During commit the transaction applys all defered operations.&lt;/li&gt;
&lt;li&gt;During rollback the transaction reverts all performed operations.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;So far we only covered some theory and concepts. In the next installment of
this series of blog posts, we will implement a simple transactional log and
implement transactional &lt;code&gt;malloc()&lt;/code&gt; and &lt;code&gt;free()&lt;/code&gt; on top of it.&lt;/p&gt;
&lt;p&gt;If you like this series about writing a transaction manager in C, please
subscribe to the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>picotm at Tübix 2017</title>
      <link>https://tzimmermann.org/2017/06/13/picotm-at-tuebix-2017/</link>
      <pubDate>Tue, 13 Jun 2017 16:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/06/13/picotm-at-tuebix-2017/</guid>
      <description>&lt;p&gt;On June 24, I&amp;rsquo;ll be at &lt;a href=&#34;http://www.tuebix.org/&#34;&gt;Tübix 2017&lt;/a&gt;. I&amp;rsquo;ll do a
&lt;a href=&#34;http://www.tuebix.org/2017/programm/thomas-zimmermann-system-transaktionen-mit-picotm/&#34;&gt;presentation&lt;/a&gt; on &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt; and
system-level transactions. Hope to see you there!&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>More on Resource Privatization</title>
      <link>https://tzimmermann.org/2017/06/09/more-on-resource-privatization/</link>
      <pubDate>Fri, 09 Jun 2017 11:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/06/09/more-on-resource-privatization/</guid>
      <description>&lt;p&gt;This is a follow-up post to &lt;a href=&#34;https://tzimmermann.org/2017/06/01/transactional-memcpy-and-resource-privatization/&#34;&gt;last week&amp;rsquo;s piece&lt;/a&gt; on resource
privatization for transactional memory. We&amp;rsquo;re going to support C strings and
look at combining load and store operations with privatization.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;h4 id=&#34;privatizing-c-strings&#34;&gt;Privatizing C Strings&lt;/h4&gt;
&lt;p&gt;Privatazion provides a way of directly accessing a resource from within
a transaction. For memory this means direct access to the memory region,
instead of working on a transaction-local copy.&lt;/p&gt;
&lt;p&gt;The interface for privatizing regions of memory looks like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;privatize&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; addr, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; siz, &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; load, &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; store);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This function takes the address of the first byte of the memory region to
be privatized, the number bytes in the region, and two booleans enabling
load and store access. If it succeeds, the memory region is owned by the
transaction and can be accessed directly.&lt;/p&gt;
&lt;p&gt;The interface is fine for memory regions of known size. In last week&amp;rsquo;s
example code we implemented a transactional &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/memcpy.html&#34;&gt;&lt;code&gt;memcpy()&lt;/code&gt;&lt;/a&gt;; and
anything that is typically accessed with &lt;code&gt;memcpy()&lt;/code&gt; by be privatized this
way.&lt;/p&gt;
&lt;p&gt;There is one noteable exception: C strings. Strings in C have their length
implicitly signalled with a trailing &lt;em&gt;\0&lt;/em&gt; character. The get a string&amp;rsquo;s
length a call to &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/strlen.html&#34;&gt;&lt;code&gt;strlen()&lt;/code&gt;&lt;/a&gt; is required.&lt;/p&gt;
&lt;p&gt;A first attempt to privatize a C string will fail quickly.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; str &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Hello World!&amp;#34;&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;privatize&lt;/span&gt;(str, &lt;span style=&#34;color:#f92672&#34;&gt;???&lt;/span&gt;, true, false);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;When using the current interface, we don&amp;rsquo;t know of which length the string
is. Maybe using &lt;code&gt;strlen()&lt;/code&gt; could help.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; str &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Hello World!&amp;#34;&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; siz &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strlen&lt;/span&gt;(str);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;privatize&lt;/span&gt;(str, siz, true, false);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We now have all parameters required by &lt;code&gt;privatize()&lt;/code&gt; but the call to
&lt;code&gt;strlen()&lt;/code&gt; does not protect against concurrent access to &lt;code&gt;str&lt;/code&gt;. Another
transaction can modify the content of &lt;code&gt;str&lt;/code&gt; concurrently, which would
make the returned length incorrect. Maybe we can solve this problem by
providing a transactional implementation of &lt;code&gt;strlen()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;strlen_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; str)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;privatize&lt;/span&gt;(str, &lt;span style=&#34;color:#f92672&#34;&gt;???&lt;/span&gt;, true, false);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strlen&lt;/span&gt;(str);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; str &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Hello World!&amp;#34;&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; siz &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;strlen_tx&lt;/span&gt;(str);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;privatize&lt;/span&gt;(str, siz, true, false);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This approach creates a chicken-and-egg problem. Our transactional
implementation of &lt;code&gt;strlen()&lt;/code&gt; requires &lt;code&gt;privatize()&lt;/code&gt; to protect the
string against concurrent modification. But &lt;code&gt;privatize()&lt;/code&gt; is what we&amp;rsquo;re
trying to support in the first place.&lt;/p&gt;
&lt;p&gt;Clearly a different approach is required.&lt;/p&gt;
&lt;p&gt;The solution implemented by &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt; is to have a privatize function
that stops at a caller-specified terminating character. For a C string the
terminating character would be &lt;em&gt;\0.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Our function is called &lt;code&gt;privatize_c()&lt;/code&gt; with &lt;code&gt;c&lt;/code&gt; for character. The interface
is similar to the regular &lt;code&gt;privatize()&lt;/code&gt;, but it receives a character instead
of the length.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;privatize_c&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; addr, &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; chr, &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; load, &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; store);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; found_chr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; false
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;found_chr) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;acquire_resource&lt;/span&gt;(addr &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; BASE_BITMASK);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;res) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;tm_restart&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; index &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; addr &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; RESOURCE_BITMASK;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; bits &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1ul&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&amp;lt;&lt;/span&gt; index;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;arraybeg&lt;/span&gt;(res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_value) &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; index;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; end &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;arrayend&lt;/span&gt;(res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_value);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;found_chr &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; (beg &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; end)) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#75715e&#34;&gt;/* If we&amp;#39;re about to store, we first have to
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;             * save the old value for possible rollbacks. */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (store &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;(res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_bits &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; bits) ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;((&lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;)addr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            bits &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&amp;lt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;--&lt;/span&gt;siz;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;addr;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;beg;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            found_chr &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;beg &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; chr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (store) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;flags &lt;span style=&#34;color:#f92672&#34;&gt;|=&lt;/span&gt; RESOURCE_FLAG_WRITE_THROUGH;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The code is again very similar to the implementation of the original
&lt;code&gt;privatize()&lt;/code&gt;, but instead of testing for the size of the supplied memory
region, it tests for the existence of the terminating character. Once the
memory location containing the character has been privatized, &lt;code&gt;privatize_c()&lt;/code&gt;
returns.&lt;/p&gt;
&lt;p&gt;Our original example now becomes trivial to implement.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;char&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; str &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Hello World!&amp;#34;&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;privatize_c&lt;/span&gt;(str, &lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#39;\0&amp;#39;&lt;/span&gt;, true, false);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;loading-and-storing-privatized-memory&#34;&gt;Loading and Storing Privatized Memory&lt;/h4&gt;
&lt;p&gt;Remember that load and store operations used a transaction-local buffer
to work on. We called this &lt;em&gt;write-back,&lt;/em&gt; as the buffer is only written back
to the shared memory resource during a commit. Privatization instead required
&lt;em&gt;write-through&lt;/em&gt; semantics, where transactions operate directly on the shared
resource.&lt;/p&gt;
&lt;p&gt;Because of this difference, our implementation of &lt;code&gt;privatize()&lt;/code&gt; can not be
combined with &lt;code&gt;load()&lt;/code&gt; and &lt;code&gt;store()&lt;/code&gt; calls on the same memory regions. Here&amp;rsquo;s
an example transaction.&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; value &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;privatize&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;value, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(value), true, true);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    value &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;value); &lt;span style=&#34;color:#75715e&#34;&gt;/* returns 0 */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This transaction privatizes an integer variable and stores &lt;em&gt;1.&lt;/em&gt; It then
transactionally loads the variable, but this gives an incorrect result of
&lt;em&gt;0.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Loads and stores currently use a write-back scheme. When acquiring a
resource, they operate on a transaction-local buffer. Only at commit
time this buffer is written back to the shared value. The call to
&lt;code&gt;privatize()&lt;/code&gt; initializes the transaction-local buffer with the original
value of &lt;em&gt;0,&lt;/em&gt; so this is what &lt;code&gt;load_int()&lt;/code&gt; returns.&lt;/p&gt;
&lt;p&gt;The solution to this problem is to support write-through mode for load
and store operation. Without going into details, an implementation would have
to provide the following semantics.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;For initial loads and stores, acquire the resource and use write-back.&lt;/li&gt;
&lt;li&gt;For initial privatize, acquire the resource and use write-through.&lt;/li&gt;
&lt;li&gt;For load and stores on an already-privatized resource, operate on the
shared buffer, instead of the transaction-local buffer.&lt;/li&gt;
&lt;li&gt;For privatizing an already-loaded or already-stored resource, swap the
content of transaction-local and shared buffer, and set write-through
mode for the resource.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This behavior is implemented in &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt;, but probably not worth
the effort for our &lt;em&gt;simpletm&lt;/em&gt; transaction manager.&lt;/p&gt;
&lt;p&gt;A further optimization would be the use of write-through mode for all load
operations until the transaction executed a store operation on the resource.
This would spare reader transactions from the overhead of filling
transaction-local buffers that they are never going to modify.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this block post, we looked at two corner cases of memory privatization.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Memory regions with terminating character, such as C strings, can be
privatized by stopping privatization at the specific character.&lt;/li&gt;
&lt;li&gt;Load and store operations can be combined with privatization by supporting
write-through semantics when loading and storing shared resources.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you like this series about writing a transaction manager in C, please
subscribe to the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
&lt;h4 id=&#34;footnotes&#34;&gt;Footnotes&lt;/h4&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;There might be other limitations in our current implementation
that prevent this example from working. One is that acquiring the
same resource multiple times from within the same transaction is
currently not supported.&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Transactional memcpy() and Resource Privatization</title>
      <link>https://tzimmermann.org/2017/06/01/transactional-memcpy-and-resource-privatization/</link>
      <pubDate>Thu, 01 Jun 2017 11:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/06/01/transactional-memcpy-and-resource-privatization/</guid>
      <description>&lt;p&gt;So far we have &lt;a href=&#34;https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/&#34;&gt;implemented a simple transaction manager&lt;/a&gt;
that &lt;a href=&#34;https://tzimmermann.org/2017/05/26/transactional-access-to-arbitrary-memory-locations/&#34;&gt;loads and stores values in shared memory locations&lt;/a&gt;.
These load and store operations copy values in and out of the transactional
context. In this blog post we&amp;rsquo;re going to implement direct access to the
shared memory. We also lay the foundation for operations besides memory
access, such as function calls.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;For our transaction manager, we created an implementation that loads and
stores values by copying them in and out of the transaction context. The
interface is shown below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;load&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; addr, &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; siz);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;store&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; addr, &lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; siz);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The function &lt;code&gt;load()&lt;/code&gt; takes an address in main memory and copies &lt;code&gt;siz&lt;/code&gt;
bytes into a transaction-local buffer. The function &lt;code&gt;store()&lt;/code&gt; does a
similar thing by copying &lt;code&gt;siz&lt;/code&gt; bytes from the transactional buffer to
an arbitrary address in memory.&lt;/p&gt;
&lt;p&gt;This interface is good for most use cases, but sometimes we need access
to the &lt;em&gt;actual&lt;/em&gt; shared resource. When we acquire a resource for direct
access, it becomes part of the transaction&amp;rsquo;s private context. We call this
&lt;em&gt;privatization.&lt;/em&gt;&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;h4 id=&#34;why-privatize-resources&#34;&gt;Why Privatize Resources?&lt;/h4&gt;
&lt;p&gt;Imaging we have a non-transactional function that takes a memory location
for it&amp;rsquo;s arguments, let&amp;rsquo;s say &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/memcpy.html&#34;&gt;&lt;code&gt;memcpy()&lt;/code&gt;&lt;/a&gt;. If we what to call
&lt;code&gt;memcpy()&lt;/code&gt; from within a transaction, we require an implementation that can
handle transactional memory.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s a very simple implementation based on the load and store primitives
we&amp;rsquo;ve developed so far.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;memcpy_tx&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; dst, &lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; src, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; siz)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; dst8 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; dst;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; src8 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; src;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (siz) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;load&lt;/span&gt;(src8, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;value, &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;store&lt;/span&gt;(dst8, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;value, &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;src8;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;dst8;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;--&lt;/span&gt;siz;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; dst;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This function transactionally loads a byte from the source memory, and
transactionally stores it in the destination memory. We could optimize
the implementation by loading and storing memory words instead of bytes,
but the fundamental problem is that the intermediate value exists in the
first place.&lt;/p&gt;
&lt;p&gt;To get around this limitation we have to add privatization to our transaction
manager.&lt;/p&gt;
&lt;h4 id=&#34;privatizing-memory&#34;&gt;Privatizing Memory&lt;/h4&gt;
&lt;p&gt;In these blog posts, we usually start with the implementation of a new
feature and then work our way &lt;em&gt;outwards&lt;/em&gt; to the interface. This time
let&amp;rsquo;s start with the interface and look at the implementation afterwards.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;privatize&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; addr, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; siz, &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; load, &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt;, store);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This looks similar to the &lt;code&gt;load()&lt;/code&gt; and &lt;code&gt;store()&lt;/code&gt; function we already have,
doesn&amp;rsquo;t it? The &lt;code&gt;privatize()&lt;/code&gt; function takes the first address of a memory
buffer and the buffer&amp;rsquo;s length. This is the memory that will be privatized.
The &lt;code&gt;load&lt;/code&gt; and &lt;code&gt;store&lt;/code&gt; arguments tell the transaction manager whether we
want to load or store or both.&lt;/p&gt;
&lt;p&gt;Using this interface, we can re-implement &lt;code&gt;memcpy_tx()&lt;/code&gt;.&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;void*
memcpy_tx(void* dst, const void* src, size_t siz)
{
    privatize(dst, siz, false, true);
    privatize(src, siz, true, false);

    return memcpy(dst, src, siz);
}
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Here we first privatize &lt;code&gt;dst&lt;/code&gt; for storing, then privatize &lt;code&gt;src&lt;/code&gt; for loading.
At this point the transaction owns both buffers. Finally we execute a plain
&lt;code&gt;memcpy()&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Not only does the new implementation look much nicer, it has a number of
advantages.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Single calls to privatize() have less overhead than repeated calls to
&lt;code&gt;load()&lt;/code&gt; or &lt;code&gt;store()&lt;/code&gt;; simply by the fact that there are less function
invocations.&lt;/li&gt;
&lt;li&gt;We got rid of the intermediate value and instead copy directly from
&lt;code&gt;src&lt;/code&gt; to &lt;code&gt;dst&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;We use the system&amp;rsquo;s &lt;code&gt;memcpy()&lt;/code&gt; operation. C compilers or standard
libraries often replace memory and string functions by highly optimized
implementations or even single assembly instructions. Using the native
implementation of &lt;code&gt;memcpy()&lt;/code&gt; allows these optimization to take place.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;implementing-memory-privatization&#34;&gt;Implementing Memory Privatization&lt;/h4&gt;
&lt;p&gt;Let&amp;rsquo;s take a look at the implementation of &lt;code&gt;privatize()&lt;/code&gt;, especially how
we provide direct access to memory. Let&amp;rsquo;s first add a &lt;code&gt;flags&lt;/code&gt; field back
to the resource structure.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; resource {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;       base;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;         local_value[RESOURCE_NBYTES];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;         local_bits;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;         flags;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_t&lt;/span&gt;       owner;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_mutex_t&lt;/span&gt; lock;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;};
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Loading is the same as it was before. When we privatize for loading the
transaction acquires the memory resource. The &lt;code&gt;load()&lt;/code&gt; function would return
a copy of the value, but after privatizing we can just read it directly.&lt;/p&gt;
&lt;p&gt;Storing is different than before. So far storing worked by storing to a
transaction-local buffer and later copying the content of this buffer to the
shared memory during a commit. We can call this a &lt;em&gt;write-back scheme&lt;/em&gt;,
because we first keep a local copy and later &lt;em&gt;write its content back&lt;/em&gt; to the
global memory location.&lt;/p&gt;
&lt;p&gt;When privatizing for store operations the transaction also acquires the
memory. The difference to regular &lt;code&gt;store()&lt;/code&gt; calls is that for privatizations,
we require what we can call a &lt;em&gt;write-through scheme.&lt;/em&gt; During the transaction&amp;rsquo;s
execution, we directly &lt;em&gt;write through&lt;/em&gt; to the shared memory.&lt;/p&gt;
&lt;p&gt;This means that when the transaction commits, the shared values are already
updated. For a rollback we have to restore the old value. Here&amp;rsquo;s an
implementation of &lt;code&gt;privatize()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;privatize&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; addr, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; siz, &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; load, &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; store)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (siz) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;acquire_resource&lt;/span&gt;(addr &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; BASE_BITMASK);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;res) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;tm_restart&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; index &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; addr &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; RESOURCE_BITMASK;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; bits &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1ul&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&amp;lt;&lt;/span&gt; index;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;arraybeg&lt;/span&gt;(res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_value) &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; index;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; end &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;arrayend&lt;/span&gt;(res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_value);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (siz &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; (beg &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; end)) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#75715e&#34;&gt;/* If we&amp;#39;re about to store, we first have to
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;             * save the old value for possible rollbacks. */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (store &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;(res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_bits &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; bits) ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;((&lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;)addr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            bits &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&amp;lt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;--&lt;/span&gt;siz;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;addr;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;beg;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (store) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;flags &lt;span style=&#34;color:#f92672&#34;&gt;|=&lt;/span&gt; RESOURCE_FLAG_WRITE_THROUGH;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;It&amp;rsquo;s very similar to the load and store functions we developed so far.
The main difference is that for store privatizations, we save the shared
value in the transaction-local buffer in the inner while loop. We will
use this buffer for restoring previous values during a rollback.&lt;/p&gt;
&lt;p&gt;For each store-privatized resource, we also set &lt;code&gt;RESOURCE_FLAG_WRITE_THROUGH&lt;/code&gt;,
which modifies the commit and rollback behavior. Commit and rollback is both
implemented in the same function &lt;code&gt;release_resource()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;release_resource&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res, &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; commit)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_t&lt;/span&gt; self &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_self&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;lock);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;owner &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;owner &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; self) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_bits) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#75715e&#34;&gt;/* We have to store if we either commit in write-back
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;             * mode, or revert in write-through mode.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;             */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; store_local_bits &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; commit &lt;span style=&#34;color:#f92672&#34;&gt;!=&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;!!&lt;/span&gt;(res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;flags &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; RESOURCE_FLAG_WRITE_THROUGH);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (store_local_bits) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; bit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1ul&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; mem &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;)res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;base;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;arraybeg&lt;/span&gt;(res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_value);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; end &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;arrayend&lt;/span&gt;(res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_value);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (beg &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; end) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_bits &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; bit) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                        &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;mem &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;beg;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                    bit &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&amp;lt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                    &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;mem;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                    &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;beg;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_bits &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;flags &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;owner &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_unlock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;lock);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Here we modified the &amp;lsquo;write condition.&amp;rsquo; Before, we only used
write-back mode and unconditionally stored all updates. Now we have to
distinguish between write-back and write-through mode. We have to write
the transaction-local buffer to the shared memory, if&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;we commit in write-back mode (stores), or if&lt;/li&gt;
&lt;li&gt;we revert in write-through mode (privatizations).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;With these modifications we&amp;rsquo;ve implemented basic memory privatization. It
should be noted that in the current implementation a transaction can
either load and store &lt;em&gt;or&lt;/em&gt; privatize a memory resource. The real-world
implementation in &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt; handles all combinations of operations
automatically.&lt;/p&gt;
&lt;h4 id=&#34;producer-consumer-transactions-with-privatizations&#34;&gt;Producer-Consumer Transactions with Privatizations&lt;/h4&gt;
&lt;p&gt;What&amp;rsquo;s missing is an update to our example program to use the new
functionality. Here&amp;rsquo;s how the producer looked until now with stores.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; seed &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tm_save &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (true) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;sleep&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;rand_r&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;seed);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Storing i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_i0, i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_i1, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We replace the invocations of &lt;code&gt;store_int()&lt;/code&gt; with &lt;code&gt;privatize()&lt;/code&gt; and
&lt;code&gt;memcpy()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; seed &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tm_save &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i[&lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; {&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;};
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (true) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;sleep&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;i[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        i[&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;] &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;rand_r&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;seed);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Storing i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;], i[&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;]);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;privatize&lt;/span&gt;((&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)g_i, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(g_i), false, true);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;memcpy&lt;/span&gt;(g_i, (&lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;)i, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(g_i));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The transaction privatizes the globally shared memory in &lt;code&gt;g_i&lt;/code&gt; with a
store privatization and copies the updated values there.&lt;/p&gt;
&lt;p&gt;The consumer looks similar, but copies &lt;em&gt;out&lt;/em&gt; of the shared memory.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;consumer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (true) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;sleep&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i[&lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;privatize&lt;/span&gt;((&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)g_i, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(g_i), true, false);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;memcpy&lt;/span&gt;(i, g_i, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(i));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;verify_load&lt;/span&gt;(i[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;], i[&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;]);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Loaded i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i[&lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;], i[&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;]);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h4 id=&#34;when-not-to-privatize&#34;&gt;When not to Privatize?&lt;/h4&gt;
&lt;p&gt;In theory one could replace all loads and stores with privatizations,
although that&amp;rsquo;s usually not a good idea.&lt;/p&gt;
&lt;p&gt;Our implementation of privatization requires a transaction-local backup of
the shared memory&amp;rsquo;s value. For workloads with mostly loads and a low number
of conflicts, these copies could add a non-trivial overhead.&lt;/p&gt;
&lt;p&gt;For storing, only &lt;em&gt;one&lt;/em&gt; transaction can own the privatized shared resource.
With workloads with many store operations to the same memory location, this
could create unnecessary contention. For write-back stores, such overhead
can be reduced by limiting the time stored memory is owned to each
transaction&amp;rsquo;s commit phase.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;With this blog post we add memory privatizations to our transaction
manager.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Privatizations give transactions direct access to shared resources.&lt;/li&gt;
&lt;li&gt;This can reduce overhead when wrapping non-transactional code. We used
&lt;code&gt;memcpy()&lt;/code&gt; as an example.&lt;/li&gt;
&lt;li&gt;Memory resources can be privatized by providing a write-through mode
for store operations.&lt;/li&gt;
&lt;li&gt;A resource&amp;rsquo;s previous state has to be restored during a rollback
in write-through mode.&lt;/li&gt;
&lt;li&gt;Depending on the workload, privatization might have undesirable
overhead.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;You&amp;rsquo;ll find the full source code for this blog post
&lt;a href=&#34;http://github.com/tdz/blog_examples/tree/master/2017-06-01&#34;&gt;on GitHub&lt;/a&gt;. If you&amp;rsquo;re interested in a more sophisticated C
transaction manager, take a look at &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you like this series about writing a transaction manager in C, please
subscribe to the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
&lt;h4 id=&#34;footnotes&#34;&gt;Footnotes&lt;/h4&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;Wikipedia describes a slightly different meaning of
&lt;a href=&#34;http://en.wikipedia.org/wiki/Privatization_(computer_programming)&#34;&gt;privatization&lt;/a&gt; in a slightly different
context.&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</description>
    </item>
    
    
    
    <item>
      <title>picotm 0.2.0 released</title>
      <link>https://tzimmermann.org/2017/05/31/picotm-0.2.0-released/</link>
      <pubDate>Wed, 31 May 2017 15:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/05/31/picotm-0.2.0-released/</guid>
      <description>&lt;p&gt;Today I released version 0.2.0 of &lt;a href=&#34;http://picotm.org&#34;&gt;picotm&lt;/a&gt;, the system-level
transaction manager. Feature highlights of the new release are consistent
error reporting and much improved documentation with tutorials and interface
references.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;You can find the full announcement on the
&lt;a href=&#34;http://picotm.org/2017/05/31/picotm-0.2.0-released.html&#34;&gt;picotm homepage&lt;/a&gt;.
The software is available for download from the GitHub
&lt;a href=&#34;http://github.com/picotm/picotm/releases/tag/v0.2.0&#34;&gt;release page&lt;/a&gt;.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Transactional Access to Arbitrary Memory Locations</title>
      <link>https://tzimmermann.org/2017/05/26/transactional-access-to-arbitrary-memory-locations/</link>
      <pubDate>Fri, 26 May 2017 09:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/05/26/transactional-access-to-arbitrary-memory-locations/</guid>
      <description>&lt;p&gt;In this blog post we are going to implement transactional semantics for
arbitrary locations in main memory. So far our &lt;em&gt;simpletm&lt;/em&gt; transaction manager
can only handle integer values that we store in a dedicated data structure.
At the end of this installment, we&amp;rsquo;ll be able to work with values of arbitrary
types that are located (almost) anywhere in memory.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;In the &lt;a href=&#34;https://tzimmermann.org/2017/05/12/transaction-roll-back-and-serializability/&#34;&gt;previous&lt;/a&gt; &lt;a href=&#34;https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/&#34;&gt;installments&lt;/a&gt; we finished our
transaction manager &lt;em&gt;simpletm&lt;/em&gt; to contain miminal functionality for detecting
and resolving conflicts among transactions, and we separated the transaction
manager from the application logic by creating a generic C interface.&lt;/p&gt;
&lt;h4 id=&#34;loads-and-stores-for-integer-resources&#34;&gt;Loads and Stores for Integer Resources&lt;/h4&gt;
&lt;p&gt;For transactional memory access, our example program executes load and store
operations on dedicted data structures of type &lt;code&gt;struct int_resource&lt;/code&gt;, which
is shown below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;             value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;             local_value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt;   flags;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_t&lt;/span&gt;       owner;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_mutex_t&lt;/span&gt; lock;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;};
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The shared integer value is stored in the field &lt;code&gt;value&lt;/code&gt;. Each instance of the
structure is owned by a single transaction that stores in the field
&lt;code&gt;local_value&lt;/code&gt; and loads from either &lt;code&gt;value&lt;/code&gt; or &lt;code&gt;local_value&lt;/code&gt;, depending
whether a local value is present. The &lt;code&gt;flags&lt;/code&gt; field tells us about this.
During the owning transaction&amp;rsquo;s commit the local value is copied to the actual
value, on rollback the local value is discarded.&lt;/p&gt;
&lt;p&gt;The corresponding load/store interface for an application looks like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res, &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; value);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res, &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; value);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;It&amp;rsquo;s specific to integer values and the application has to know about the
&lt;code&gt;struct int_resource&lt;/code&gt; data structure. Instead we should prefer an interface
that can store a value of any type at any location in memory.&lt;/p&gt;
&lt;h4 id=&#34;working-with-arbitrary-types&#34;&gt;Working With Arbitrary Types&lt;/h4&gt;
&lt;p&gt;To support arbitrary types, let us rework &lt;code&gt;struct int_resource&lt;/code&gt; a bit. We
call this new structure &lt;code&gt;struct resource&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define RESOURCE_BITSHIFT   (3)
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define RESOURCE_NBYTES     (1ul &amp;lt;&amp;lt; RESOURCE_BITSHIFT)
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;/**
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt; * An integer value with an associated owner.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt; */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; resource {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;       base;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;         local_value[RESOURCE_NBYTES];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;uint16_t&lt;/span&gt;        local_bits;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_t&lt;/span&gt;       owner;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_mutex_t&lt;/span&gt; lock;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;};
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;First of all, we remove the field &lt;code&gt;value&lt;/code&gt;. Instead the &lt;code&gt;base&lt;/code&gt; field tells us
where in memory the resource is located. The value in &lt;code&gt;base&lt;/code&gt; is the address
of the first byte of a transactional value.&lt;/p&gt;
&lt;p&gt;The field &lt;code&gt;local_value&lt;/code&gt; is now a fixed-size byte array. It still stores
the local value, but it&amp;rsquo;s not any longer type specific. In our case the array
is 8 byte in size, so we can operate on values up to 8 bytes. Further below we
will see how to arrange the resources such that values of arbitrary size can
be supported.&lt;/p&gt;
&lt;p&gt;Finally we replaced the &lt;code&gt;flags&lt;/code&gt; field by &lt;code&gt;local_bits&lt;/code&gt;. The latter is a bit
field, where each bit signals the present of a transaction-local value in
&lt;code&gt;local_value&lt;/code&gt;.  So if bit 0 is set &lt;code&gt;local_value[0]&lt;/code&gt; contains a local value,
if bit 1 is set &lt;code&gt;local_value[1]&lt;/code&gt; contains a local value, and so on.&lt;/p&gt;
&lt;h4 id=&#34;working-with-arbitrary-memory-locations&#34;&gt;Working With Arbitrary Memory Locations&lt;/h4&gt;
&lt;p&gt;Our &lt;code&gt;local_value&lt;/code&gt; stores 8 bytes and &lt;code&gt;base&lt;/code&gt; could be any address. If we align
&lt;code&gt;base&lt;/code&gt; such that it always contains an address at an 8-byte boundary, its
lowest three bytes will always be zero. For a memory address, these bits
contain the index into &lt;code&gt;local_value&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Here are the bits of a 32-bit memory address with their meaning for access
to &lt;code&gt;struct resource&lt;/code&gt;.&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;    | 31 .. 13  12 11 10  9  8  7  6  5  4  3 |  2  1  0 |
    |                  Base                   |   Index  |
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;For mapping a memory address to a byte in a resource structure, first we
have to make sure that the base values of address and resource are the same,
then use the address&amp;rsquo; lowest three bits as index into &lt;code&gt;local_value&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;So far we&amp;rsquo;ve had two values of type &lt;code&gt;struct int_resource&lt;/code&gt;. If we had a single
&lt;code&gt;resource&lt;/code&gt; structure in our transaction manager, we could load and store 8
consecutive bytes for the transactions. To load and store more memory, we
have to add more instances; let&amp;rsquo;s say 1024.&lt;/p&gt;
&lt;p&gt;The code fragment below creates an array of 1024 resource structures.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define NRESOURCES_BITSHIFT (10)
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define NRESOURCES          (1ul &amp;lt;&amp;lt; NRESOURCES_BITSHIFT)
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; resource g_resource[NRESOURCES];
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We could assign a base address to each array element and search in the
array whenever we want to map an address to a resource with corresponding
base address. While this would work, there&amp;rsquo;s an easy way to compute the
correct element directly.&lt;/p&gt;
&lt;p&gt;Storing the position of element of the array requires exactly 10 bit. These
10 bit are located in the memory address directly before the index; or in
other words, they are the next higher bits above the index.&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;    | 31 .. 13 | 12 11 10  9  8  7  6  5  4  3 |  2  1  0 |
    |          |             Element           |          |
    |                   Base                   |   Index  |
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;For mapping a memory address to a byte in a resource structure, we can
extract the element position (bits 3 to 12), get the element from the
element array we declared, make sure that the base values of address and
resource are the same, and then use the address&amp;rsquo; lowest three bits as index
into &lt;code&gt;local_value&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;This look-up scheme is very fast and ensures that resources are consecutive
in memory as well as the bytes of each resource. It is therefore possible to
operate on values that are larger than 8 bytes. For example, if we load or
store a value of 16 bytes, we first operate on the resource structure covering
the value&amp;rsquo;s first bytes, then operate on the resource structure covering the
next bytes, and so on.&lt;/p&gt;
&lt;h4 id=&#34;loading-and-storing&#34;&gt;Loading and Storing&lt;/h4&gt;
&lt;p&gt;Before we go into the details of the load and store functions, let us look
at the new interfaces. Because we don&amp;rsquo;t use &lt;code&gt;int&lt;/code&gt; directly any more, the
new interfaces take memory addresses and buffers.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;load&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; addr, &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; siz);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;store&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; addr, &lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; siz)
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The value &lt;code&gt;addr&lt;/code&gt; is the address of the shared value. The application logic
is not required to know about the resource any more. The transaction manager
maintains these internally. The values &lt;code&gt;buf&lt;/code&gt; and &lt;code&gt;siz&lt;/code&gt; give a
transaction-local buffer and the number of bytes in the buffer.&lt;/p&gt;
&lt;p&gt;The complexity is now in the implementation of the load and store function.
Here is &lt;code&gt;store()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;store&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; addr, &lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; siz)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; mem &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;)buf;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (siz) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;acquire_resource&lt;/span&gt;(addr &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; BASE_BITMASK);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;res) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;tm_restart&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; index &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; addr &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; RESOURCE_BITMASK;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; bits &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1ul&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&amp;lt;&lt;/span&gt; index;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;arraybeg&lt;/span&gt;(res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_value) &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; index;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; end &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;arrayend&lt;/span&gt;(res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_value);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (siz &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; (beg &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; end)) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;mem;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_bits &lt;span style=&#34;color:#f92672&#34;&gt;|=&lt;/span&gt; bits;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            bits &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&amp;lt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;--&lt;/span&gt;siz;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;addr;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;mem;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;beg;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;code&gt;store()&lt;/code&gt; transactionally stores all bytes in &lt;code&gt;buf&lt;/code&gt; to the resources that cover
&lt;code&gt;addr&lt;/code&gt; and successiv memory locations. The function call to
&lt;code&gt;acquire_resource()&lt;/code&gt; acquires the resource for a specific base address and
returns the resource&amp;rsquo;s data structure. If the resource cannot be acquired,
the transaction is in conflict, &lt;code&gt;NULL&lt;/code&gt; is returned and the transaction aborts.&lt;/p&gt;
&lt;p&gt;Once we have the resource, we start filling its &lt;code&gt;local_value&lt;/code&gt; field with the
contents of &lt;code&gt;buf&lt;/code&gt;. For each byte we copy, we set the corresponding bit in
&lt;code&gt;local_bits&lt;/code&gt;. We do this until we reach the end of either &lt;code&gt;buf&lt;/code&gt; or
&lt;code&gt;local_value&lt;/code&gt;. If we reached the end of &lt;code&gt;local_value&lt;/code&gt; and there are still
bytes left in &lt;code&gt;buf&lt;/code&gt; we continue the outer while loop with the next resource.&lt;/p&gt;
&lt;p&gt;The load function is identical, except for the actual copy operation.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;load&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt; addr, &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; buf, &lt;span style=&#34;color:#66d9ef&#34;&gt;size_t&lt;/span&gt; siz)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; mem &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; (&lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;)buf;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (siz) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;acquire_resource&lt;/span&gt;(addr &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; BASE_BITMASK);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;res) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;tm_restart&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; index &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; addr &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; RESOURCE_BITMASK;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt; bits &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1ul&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&amp;lt;&lt;/span&gt; index;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; beg &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;arraybeg&lt;/span&gt;(res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_value) &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; index;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; end &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;arrayend&lt;/span&gt;(res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_value);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (siz &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; (beg &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; end)) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_bits &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; bits) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;mem &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;beg;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;mem &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;((&lt;span style=&#34;color:#66d9ef&#34;&gt;uint8_t&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;)addr);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            bits &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&amp;lt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;--&lt;/span&gt;siz;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;addr;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;mem;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;beg;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Here we walk over the local values of the involved resources and copy &lt;em&gt;into&lt;/em&gt;
&lt;code&gt;buf&lt;/code&gt;. In the inner while loop, we check if there&amp;rsquo;s a local value and either
copy this or the globally shared value.&lt;/p&gt;
&lt;p&gt;Our current setup can support 8192 bytes of transactional memory. If this
limit is reached or if multiple memory locations map to the same resource,
the transaction manager aborts the process. This would be detected by
&lt;code&gt;acquire_resource()&lt;/code&gt;. As a workaround to this limit the size of the resource
array can be doubled until all variables are covered. A real-world
implementation could also replace the array by a sparse look-up tree. That&amp;rsquo;s
how it&amp;rsquo;s done in &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For convenience, we can keep the &lt;code&gt;load_int()&lt;/code&gt; and &lt;code&gt;store_int()&lt;/code&gt; functions
around. They are now mere wrappers around &lt;code&gt;load()&lt;/code&gt; and &lt;code&gt;store()&lt;/code&gt;.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; addr)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;load&lt;/span&gt;((&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)addr, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;value, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(value));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; addr, &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; value)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;store&lt;/span&gt;((&lt;span style=&#34;color:#66d9ef&#34;&gt;uintptr_t&lt;/span&gt;)addr, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;value, &lt;span style=&#34;color:#66d9ef&#34;&gt;sizeof&lt;/span&gt;(value));
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;With helpers as simple as these, there can be plenty of type-specific
functions that load and store &lt;code&gt;float&lt;/code&gt;, &lt;code&gt;long&lt;/code&gt;, &lt;code&gt;complex double&lt;/code&gt;, or any
other type.&lt;/p&gt;
&lt;h4 id=&#34;converting-the-application&#34;&gt;Converting the Application&lt;/h4&gt;
&lt;p&gt;The old producer code looked like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource g_int_resource[&lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; seed &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tm_save &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (true) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;sleep&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;rand_r&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;seed);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Storing i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This translates into the following code.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; g_i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; g_i1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; seed &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tm_save &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (true) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;sleep&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;rand_r&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;seed);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Storing i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_i0, i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_i1, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The global values of type &lt;code&gt;struct int_resource&lt;/code&gt; are gone. Instead we work
directly on integer types.&lt;/p&gt;
&lt;p&gt;The consumer side looks similar.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;consumer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (true) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;sleep&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0, i1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            i1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            i0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;verify_load&lt;/span&gt;(i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Loaded i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;As in the &lt;a href=&#34;https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/&#34;&gt;previous post&lt;/a&gt;, we added a certain complexity to
the transaction manager, but the application logic got a lot simpler.
And just as before, we had to implement the transaction manager exactly
once. Further application-specific changes are not required.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we removed the dedicated resource data structures from
the interface of &lt;em&gt;simpletm.&lt;/em&gt; The new interface loads and stores at arbitrary
memory locations and all resource management is done internally.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;We can load and store arbitrary types.&lt;/li&gt;
&lt;li&gt;We can protect concurrent access to arbitrary memory locations.&lt;/li&gt;
&lt;li&gt;Applications don&amp;rsquo;t have to know about dedicated data structures for
resource management. The interface for transactional memory access
uses memory addresses of the involved variables.&lt;/li&gt;
&lt;li&gt;We can further optimize transactional memory access without interfering
with application logic.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;You&amp;rsquo;ll find the full source code for this blog post
&lt;a href=&#34;http://github.com/tdz/blog_examples/tree/master/2017-05-26&#34;&gt;on GitHub&lt;/a&gt;. If you&amp;rsquo;re interested in a more sophisticated C
transaction manager, take a look at &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you like this series about writing a transaction manager in C, please
subscribe to the RSS feed, follow on Twitter or share on social networks.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Writing the Beginning and End of a Transaction</title>
      <link>https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/</link>
      <pubDate>Fri, 19 May 2017 09:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/05/19/writing-the-beginning-and-end-of-a-transaction/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://tzimmermann.org/2017/05/12/transaction-roll-back-and-serializability/&#34;&gt;Last time&lt;/a&gt; we finished our transaction manager and example
program &lt;em&gt;simpletm&lt;/em&gt; to contain the minimum functionality for conflict detection
and transaction rollback. In this blog post we are going to separate
application logic and transaction logic from each other. We will move the
latter into a distinct module with a generic C interface for beginning and
committing transactions.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;h4 id=&#34;towards-a-generic-transaction-interface&#34;&gt;Towards a Generic Transaction Interface&lt;/h4&gt;
&lt;p&gt;&lt;em&gt;Simpletm&lt;/em&gt; has two threads. A producer thread generates pairs of integer
values and stores them in two globally shared variables. The consumer thread
loads the stored values from the shared variables. All load and store
operations are performed transactionally.&lt;/p&gt;
&lt;p&gt;We ended the previous blog post with a producer function that looked like the
code shown below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; seed &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (true) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;sleep&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;rand_r&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;seed);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Storing i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;commit) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; release;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; release;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; true;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        release:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, commit);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, commit);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;While this code works correctly, it&amp;rsquo;s poorly designed and not generally
re-useable in other software.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The inner while loop serves as transaction control block. This
is not obvious. We should prefer clear statements that indicate when we
begin and commit a transaction.&lt;/li&gt;
&lt;li&gt;We explicitly test the return value of each call to &lt;code&gt;store_int()&lt;/code&gt; and
abort if necessary. This is error prone and obfuscates the appliction
logic. It would be preferable if &lt;code&gt;store_int()&lt;/code&gt; could do this automatically
for us.&lt;/li&gt;
&lt;li&gt;We maintain the variable &lt;code&gt;commit&lt;/code&gt; by hand. That is also error prone. If we
forget to set &lt;code&gt;commit&lt;/code&gt; to &lt;code&gt;true&lt;/code&gt;, we end up in an end-less loop. If we
set it too early (i.e., before all loads and stores have been executed),
we might commit a conflicting transaction.&lt;/li&gt;
&lt;li&gt;We track which resources the transaction uses and release them explicitly
at the end of the transaction. It would be better if this could be done
once for all transactions.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The consumer has similar problems. If we can move all this behind a
common interface, we can reduce the overall code to the pure application
logic.&lt;/p&gt;
&lt;h4 id=&#34;the-interface&#34;&gt;The Interface&lt;/h4&gt;
&lt;p&gt;First of all we have to mark the beginning of a transactional block. Once
a transaction has began, there are currently two cases we must handle: either
our transaction commits and leaves the transaction, or the transaction aborts
at some point and returns to the beginning of the transaction block. In both
cases we have to release the transaction&amp;rsquo;s acquired resources.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s start with implementing two statements. We call them &lt;code&gt;tm_begin&lt;/code&gt; and
&lt;code&gt;tm_commit&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;As the name indicates, &lt;code&gt;tm_begin&lt;/code&gt; is where the transaction starts. Here&amp;rsquo;s
the code.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_begin&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* Nothing to do */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define tm_begin    \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    _tm_begin();    \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The function &lt;code&gt;_tm_begin()&lt;/code&gt; is the place where we can put any set-up code that
we might require. It&amp;rsquo;s currently empty.&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; The function is not supposed to
be called directly. Instead there&amp;rsquo;s &lt;code&gt;tm_begin&lt;/code&gt;. It&amp;rsquo;s a macro that calls
&lt;code&gt;_tm_begin()&lt;/code&gt; and then begins a new C code block. Note that &lt;code&gt;tm_begin&lt;/code&gt;
intentionally has no round brackets. It&amp;rsquo;s not a function call. It&amp;rsquo;s an
element of code structuring.&lt;/p&gt;
&lt;p&gt;The code for &lt;code&gt;tm_commit&lt;/code&gt; is where we update and release the shared resources
acquired by the transaction.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define arraylen(_array)    \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    ( sizeof(_array) / sizeof(*(_array)) )
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define arraybeg(_array)    \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    ( _array )
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define arrayend(_array)    \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    ( arraybeg(_array) + arraylen(_array) )
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resources&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; beg,
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;const&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; end, &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; commit)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (beg &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; end) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(beg, commit);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;beg;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_commit&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resources&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;arraybeg&lt;/span&gt;(g_int_resource),
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                          &lt;span style=&#34;color:#a6e22e&#34;&gt;arrayend&lt;/span&gt;(g_int_resources), true);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define tm_commit       \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;        _tm_commit();   \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;If &lt;code&gt;tm_begin&lt;/code&gt; marks the beginning of our transactional code, &lt;code&gt;tm_commit&lt;/code&gt;
marks the end. It&amp;rsquo;s again a macro. It calls the function &lt;code&gt;_tm_commit()&lt;/code&gt;
and ends the C code block that was started by &lt;code&gt;tm_begin&lt;/code&gt;. The intended
side effect of this block is that all variables declared in the
transactional code are transaction-local by default.&lt;/p&gt;
&lt;p&gt;The commit operation&amp;rsquo;s implementation is in &lt;code&gt;_tm_commit()&lt;/code&gt;. This function
releases all shared integer resources. Then we have completed the
transaction. The rest of the shown code is simply helpers.&lt;/p&gt;
&lt;p&gt;The primitives shown so far is all we need for beginning and committing
transactions. But what about conflict handling?&lt;/p&gt;
&lt;h4 id=&#34;non-local-gotos-in-c&#34;&gt;Non-Local Gotos in C&lt;/h4&gt;
&lt;p&gt;When a transaction observes a conflict during resource access, we want it
to release the resources it acquired so far and restart from the beginning.&lt;/p&gt;
&lt;p&gt;Conflicts are detected within &lt;code&gt;store_int()&lt;/code&gt;, or &lt;code&gt;load_int()&lt;/code&gt; for the
consumer transaction. To restart from there we have to implement a non-local
goto that jumps from &lt;code&gt;store_int()&lt;/code&gt; to where we called &lt;code&gt;tm_begin&lt;/code&gt;. It&amp;rsquo;s called
&lt;em&gt;non-local goto&lt;/em&gt; because we&amp;rsquo;re doing a goto operation over function-call
boundaries.&lt;/p&gt;
&lt;p&gt;Non-local gotos in C are implemented with the functions
&lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/setjmp.html&#34;&gt;setjmp()&lt;/a&gt; and &lt;a href=&#34;http://pubs.opengroup.org/onlinepubs/9699919799/functions/longjmp.html&#34;&gt;longjmp()&lt;/a&gt;.&lt;sup id=&#34;fnref:2&#34;&gt;&lt;a href=&#34;#fn:2&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;2&lt;/a&gt;&lt;/sup&gt; A call to
&lt;code&gt;setjmp()&lt;/code&gt; stores the processors current instruction counter and stack pointer
for this thread. A later call to &lt;code&gt;longjmp()&lt;/code&gt; restores these values, effectivly
transfering program control back to the point where &lt;code&gt;setjmp()&lt;/code&gt; had been called.
The state values are stored in a &lt;em&gt;jump buffer&lt;/em&gt; of type &lt;code&gt;jmp_buf&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s how the code looks like. First we need a thread-local jump buffer.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_tx {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    jmp_buf env;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;};
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_tx&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_get_tx&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* Thread-local transaction structure */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; __thread &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; _tm_tx t_tm_tx;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;t_tm_tx;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We put the jump buffer into &lt;code&gt;struct _tm_tx&lt;/code&gt;. The function &lt;code&gt;_tm_get_tx()&lt;/code&gt;
simply returns a thread-local instance of this structure.&lt;/p&gt;
&lt;p&gt;To save the thread state in the jump buffer upon entering the transaction,
we have to call &lt;code&gt;setjmp()&lt;/code&gt; at the right time. Therefore we modify &lt;code&gt;tm_begin&lt;/code&gt;
as shown below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_begin&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; value)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* Nothing to do */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define tm_begin                            \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    _tm_begin(setjmp(_tm_get_tx()-&amp;gt;env));   \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The call to &lt;code&gt;setjmp()&lt;/code&gt; is now done at the very beginning. It saves the
instruction counter and stack pointer in the thread-local jump buffer
and returns a value. When we later call &lt;code&gt;longjmp()&lt;/code&gt; with the saved jump
buffer, the transaction performs the non-local goto and &lt;code&gt;setjmp()&lt;/code&gt; will
return &lt;em&gt;again.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Upon entering the transaction for the first time, &lt;code&gt;setjmp()&lt;/code&gt; returns 0. At
the time we call &lt;code&gt;longjmp()&lt;/code&gt; we have the option of passing a different value,
which &lt;code&gt;setjmp()&lt;/code&gt; will return. Its return value is passed as an argument to
&lt;code&gt;_tm_begin()&lt;/code&gt;. This way we can distinguish between a new transaction and
a restarted transaction in &lt;code&gt;_tm_begin()&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;What we finally need is the restart function that is executed by &lt;code&gt;store_int()&lt;/code&gt;
upon detected conflicts.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;tm_restart&lt;/span&gt;()
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resources&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;arraybeg&lt;/span&gt;(g_int_resource),
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                          &lt;span style=&#34;color:#a6e22e&#34;&gt;arrayend&lt;/span&gt;(g_int_resource), false);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* Jump to the beginning of the transaction */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;longjmp&lt;/span&gt;(&lt;span style=&#34;color:#a6e22e&#34;&gt;_tm_get_tx&lt;/span&gt;()&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;env, &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res, &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; value)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;acquire_int_resource&lt;/span&gt;(res);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;tm_restart&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_value &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;flags &lt;span style=&#34;color:#f92672&#34;&gt;|=&lt;/span&gt; RESOURCE_HAS_LOCAL_VALUE;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Like &lt;code&gt;_tm_commit()&lt;/code&gt; the function &lt;code&gt;tm_restart()&lt;/code&gt; releases the transaction&amp;rsquo;s
resources, but of course without updating the global values. Instead of
returning, &lt;code&gt;tm_restart()&lt;/code&gt; invokes &lt;code&gt;longjmp()&lt;/code&gt; with the saved jump buffer and
an additional value. This transfers program control back to the transaction&amp;rsquo;s
beginning where &lt;code&gt;setjmp()&lt;/code&gt; saved the jump buffer. This time, &lt;code&gt;setjmp()&lt;/code&gt;
returns the second argument to &lt;code&gt;longjmp()&lt;/code&gt;. In our case this is 1.&lt;/p&gt;
&lt;p&gt;In &lt;code&gt;store_int()&lt;/code&gt;, we now call &lt;code&gt;tm_restart()&lt;/code&gt; upon detected conflicts. Notice
that a call to &lt;code&gt;store_int()&lt;/code&gt; cannot fail anymore. If it returns it has been
successful, otherwise it automatically restarts the transaction.&lt;/p&gt;
&lt;h4 id=&#34;putting-it-all-together&#34;&gt;Putting It All Together&lt;/h4&gt;
&lt;p&gt;While the details of &lt;code&gt;setjmp()&lt;/code&gt; and &lt;code&gt;longjmp()&lt;/code&gt; are certainly more complex
than the while loop, it&amp;rsquo;s all contained in the transaction manager. And we&amp;rsquo;re
effectivly done with this problem. There&amp;rsquo;s hardly any reason to ever change
the code.&lt;/p&gt;
&lt;p&gt;The application logic, however, looks &lt;em&gt;much&lt;/em&gt; clear than before. Let&amp;rsquo;s put
everything together. Here&amp;rsquo;s our new producer.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; seed &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (true) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;sleep&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;rand_r&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;seed);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Storing i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We were able to condense the whole inner while loop into four statements
were each statement is relevant to the application! Gone are the while loop,
the explicit tests for successful stores, the &lt;code&gt;commit&lt;/code&gt; variable, and the
explicit releases at the end of the transaction.&lt;/p&gt;
&lt;p&gt;After applying similar changes to the consumer, the new consumer looks like
this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;consumer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (true) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;sleep&lt;/span&gt;(&lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0, i1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_begin
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;verify_load&lt;/span&gt;(i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        tm_commit
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Loaded i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Again, we were able to remove all the transactional book keeping and reduce
the code to the application logic!&lt;/p&gt;
&lt;h4 id=&#34;optimizing-for-optimizers&#34;&gt;Optimizing for Optimizers&lt;/h4&gt;
&lt;p&gt;There&amp;rsquo;s one final point about non-local gotos that we have to take care of.
Remember that &lt;code&gt;setjmp()&lt;/code&gt; only saves the processor&amp;rsquo;s instruction counter and
stack pointer. It &lt;em&gt;does not&lt;/em&gt; save any program variable&amp;rsquo;s value.&lt;/p&gt;
&lt;p&gt;Program variables are subject to opimizations by the compiler. They can even
be removed entirely and the value can be hold in a processor register. If we
compile the &lt;em&gt;simpletm&lt;/em&gt; binary with the gcc flags &amp;lsquo;-O2 -Wclobbered&amp;rsquo;, we might
get a warning like the one shown below.&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;main.c: In function ‘producer_func’
main.c:33:9: warning: variable ‘i0’ might be clobbered by ‘longjmp’ or ‘vfork’ [-Wclobbered]
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;This means that the compiler&amp;rsquo;s optimizer moves around access to &lt;code&gt;i0&lt;/code&gt; or
maybe even removes the variable. Such optimizations depend on the function&amp;rsquo;s
structure and code. The information about how the &lt;code&gt;longjmp()&lt;/code&gt; happens
is simply not available to the optimizer because the call to &lt;code&gt;longjmp()&lt;/code&gt;
happens in a different function. After a &lt;code&gt;longjmp()&lt;/code&gt; the value of &lt;code&gt;i0&lt;/code&gt;
is undefined.&lt;/p&gt;
&lt;p&gt;We can prevent this from happening by declaring the &lt;code&gt;i0&lt;/code&gt; as &lt;code&gt;volatile&lt;/code&gt;, or
as we call it &lt;code&gt;tm_save&lt;/code&gt;. The &lt;code&gt;volatile&lt;/code&gt; keyword prevents the compiler from
optimizing the variable.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define tm_save volatile
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; seed &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    tm_save &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    [...]
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;From now on, we will compile transactional code with &amp;lsquo;-Wclobbered&amp;rsquo; to make the
compiler warn about this problem, and we will add &lt;code&gt;tm_save&lt;/code&gt; where necessary.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this blog post, we created a clean interface that let&amp;rsquo;s us separate our
transaction manager from the application logic and keep both in separate
modules.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;We begin a transaction with &lt;code&gt;tm_begin&lt;/code&gt; and commit with &lt;code&gt;tm_commit&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Both statements are implemented by the transaction manager.&lt;/li&gt;
&lt;li&gt;A call to &lt;code&gt;tm_begin&lt;/code&gt; saves the instruction counter and stack pointer using
&lt;code&gt;setjmp()&lt;/code&gt;. For aborting we execute &lt;code&gt;longjmp()&lt;/code&gt; to return to the beginning
of the transaction.&lt;/li&gt;
&lt;li&gt;Transaction aborts are performed internally by the transaction manager.&lt;/li&gt;
&lt;li&gt;Resources are released automatically by the transaction manager during
commits and aborts. No support from the application is required.&lt;/li&gt;
&lt;li&gt;The application code is reduced to the actual application logic.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As always, the full source code for this blog post is
&lt;a href=&#34;http://github.com/tdz/blog_examples/tree/master/2017-05-19&#34;&gt;available on GitHub&lt;/a&gt;. If you&amp;rsquo;re interested in a more
sophisticated C transaction manager, take a look at &lt;a href=&#34;http://picotm.org/&#34;&gt;picotm&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you like this series about writing a transaction manager in C, please
subscribe to the RSS feed, follow on Twitter or share on social networks.
In the next installment, we will probably replace &lt;code&gt;struct int_resource&lt;/code&gt; with
support for arbitrary memory locations.&lt;/p&gt;
&lt;h4 id=&#34;footnotes&#34;&gt;Footnotes&lt;/h4&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;We will fill &lt;code&gt;_tm_begin()&lt;/code&gt; with code when we get to error recovery
in a later blog post.&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:2&#34;&gt;
&lt;p&gt;As word of warning, try to avoid using &lt;code&gt;setjmp()&lt;/code&gt; and &lt;code&gt;longjmp()&lt;/code&gt; in
your software. It&amp;rsquo;s perfect for our transactions, but in general it
often does more harm than good to program design.&amp;#160;&lt;a href=&#34;#fnref:2&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Transaction Roll-Back and Serializability</title>
      <link>https://tzimmermann.org/2017/05/12/transaction-roll-back-and-serializability/</link>
      <pubDate>Fri, 12 May 2017 09:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/05/12/transaction-roll-back-and-serializability/</guid>
      <description>&lt;p&gt;In this blog post we&amp;rsquo;ll explore transaction roll-back code and briefly cover
serializability. We&amp;rsquo;ll build upon our
&lt;a href=&#34;https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/&#34;&gt;simple transaction manager&lt;/a&gt; and the
&lt;a href=&#34;https://tzimmermann.org/2017/05/09/transactional-semantics-in-theory-and-practice/&#34;&gt;theoretical foundation&lt;/a&gt; we&amp;rsquo;ve discussed last time. At the end
of this post, we&amp;rsquo;ll have a simple, but correct transaction manager that can
be adapted to arbitrary work loads.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;h4 id=&#34;a-closer-look-at-simpletm&#34;&gt;A Closer Look at &lt;em&gt;simpletm&lt;/em&gt;&lt;/h4&gt;
&lt;p&gt;Let&amp;rsquo;s take a closer look at &lt;em&gt;simpletm,&lt;/em&gt; the transaction manager that we
made before. Specifically let&amp;rsquo;s look at the producer and consumer code.
Here&amp;rsquo;s the producer again.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* produce i0 and i1 */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    i1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;rand&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;print&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Storing i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;commit) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; release;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; release;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; true;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    release:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;It creates two values, &lt;code&gt;i0&lt;/code&gt; and &lt;code&gt;i1&lt;/code&gt;, and stores them in shared resources;
acquiring these resources along the way. If it can not acquire a resource,
the producer releases all its resources and restarts.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s the consumer.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;consumer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0, i1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;commit) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; release;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; release;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; true;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    release:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* consume i0 and i1 */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;print&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Loaded i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Similar to the producer, the consumer loads two values from shared resources
and acquires these resources along the way. If it fails to acquire a resource
the consumer releases all its other resources and restarts.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s further condense both code blocks to the load, store, and release
functions that operate on shared resources. A transaction won&amp;rsquo;t see conflicts
when accessing its private resources. So for our analysis, it&amp;rsquo;s only
important how transactions interact with shared resources.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;consumer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Producer and consumer run concurrently, so invocations of the load, store,
and release functions can interleave in any way. Let&amp;rsquo;s reorder the
individual calls&amp;hellip; and a problem will appear.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i0);         &lt;span style=&#34;color:#75715e&#34;&gt;/* producer acquires resource 0 and performs store */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;/* context switch */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i1);          &lt;span style=&#34;color:#75715e&#34;&gt;/* consumer acquires resource 1 and performs load */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;/* context switch */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i1);         &lt;span style=&#34;color:#75715e&#34;&gt;/* producer fails to acquire resource 1 */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);   &lt;span style=&#34;color:#75715e&#34;&gt;/* producer releases resource 0 */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;/* context switch */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i0);          &lt;span style=&#34;color:#75715e&#34;&gt;/* consumer acquires resource 0 and performs load */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;/* THE CONSUMER JUST LOADED THE VALUE PREVIOUSLY STORED BY THE ABORTED PRODUCER! */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Oh! If we only execute the first store and the first load, and then abort
the producer, the consumer will load the value that has just been stored by
the producer.&lt;/p&gt;
&lt;p&gt;Is this actually correct? Before, we could only have guessed, but in the
previous blog post, we established a theoretical foundation and talked about
the ACID properties.&lt;/p&gt;
&lt;p&gt;Our property of atomicity required transactions to be either executed
completely, or not at all. In the example at hand we only executed half of
the producer&amp;rsquo;s transaction, namely the first store; therefore violating
the atomicity principle.&lt;/p&gt;
&lt;p&gt;Consequently we also violated the isolation property, as we leaked internal
changes of the producer into the global state.&lt;/p&gt;
&lt;p&gt;We specified early int the original blog post that we want to update either both
resources or none. So we also violated our established notion of consistency.&lt;/p&gt;
&lt;p&gt;Clearly, the current behavior is not correct.&lt;/p&gt;
&lt;h4 id=&#34;test-it-for-yourself&#34;&gt;Test it for Yourself&lt;/h4&gt;
&lt;p&gt;Usually you won&amp;rsquo;t see this problem, because the &lt;code&gt;sleep()&lt;/code&gt; and &lt;code&gt;printf()&lt;/code&gt;
statements slow down thread execution considerably. If you want to trigger
the bug, take the &lt;a href=&#34;https://github.com/tdz/blog_examples/tree/master/2017-05-05&#34;&gt;original code of the simpletm&lt;/a&gt; and
replace &lt;code&gt;producer_func()&lt;/code&gt; and &lt;code&gt;consumer_func()&lt;/code&gt; with the code shown below.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; seed &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (true) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;rand_r&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;seed);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;commit) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; release;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; release;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; true;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        release:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;verify_load&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0, &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i1)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; seed &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; value &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;for&lt;/span&gt; (i &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;; i &lt;span style=&#34;color:#f92672&#34;&gt;&amp;lt;&lt;/span&gt; i0; &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;i) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        value &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;rand_r&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;seed);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (value &lt;span style=&#34;color:#f92672&#34;&gt;!=&lt;/span&gt; i1) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;printf&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Incorrect value pair (%d,%d), should be (%d,%d)&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;               i0, i1, i, value);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;consumer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (true) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0, i1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;commit) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; release;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; release;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;verify_load&lt;/span&gt;(i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; true;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        release:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The replacement code has the invocations of &lt;code&gt;sleep()&lt;/code&gt; and &lt;code&gt;printf()&lt;/code&gt; removed
and verifies the loaded values. When you run it, you should see plenty of
statements like the ones below on the terminal.&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;Incorrect value pair (17103,1980393415), should be (17103,507428599)
Incorrect value pair (17104,507428599), should be (17104,1058612930)
Incorrect value pair (17111,1861807294), should be (17111,2062867441)
Incorrect value pair (17112,2062867441), should be (17112,1510167188)
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;This comes from the consumer thread, which failed to verify the correctness
of the loaded values.&lt;/p&gt;
&lt;p&gt;Notice that if &lt;code&gt;i0&lt;/code&gt; is 17103 the consumer expects &lt;code&gt;i1&lt;/code&gt; to be 507428599, but
this value is only loaded later when &lt;code&gt;i0&lt;/code&gt; is 17104. This is because the
producer stored 17104 for &lt;code&gt;i0&lt;/code&gt; and then aborted, keeping &lt;code&gt;i1&lt;/code&gt; at the old
value. The same happens for 17111 and 17112.&lt;/p&gt;
&lt;h4 id=&#34;introducing-serializability&#34;&gt;Introducing Serializability&lt;/h4&gt;
&lt;p&gt;Remember from the previous post that the cumulative effects of a set of
transactions shall look as if the transactions had been executed one by
one. This is called serializability.&lt;/p&gt;
&lt;p&gt;A specific execution of a set of transactions is called a &lt;em&gt;history.&lt;/em&gt; For
example, the execution near the beginning of this post, the one that
showed up the problem, is a history.&lt;/p&gt;
&lt;p&gt;In our code we have two transactions that we execute concurrently. If we
execute all operations of one transaction strictly before or after all
operations of the other transaction, we have a &lt;em&gt;serial history.&lt;/em&gt; This
generalizes to histories containing any number of transactions.&lt;/p&gt;
&lt;p&gt;A history is &lt;em&gt;serializable&lt;/em&gt; if the effects of history&amp;rsquo;s committed
transactions are equivalent to an actual serial history. This means that
if we execute and commit all our transactions concurrently, the result must
be the same as if we had executed and committed the transactions one by one.
The exact order of the transactions doesn&amp;rsquo;t matter.&lt;/p&gt;
&lt;p&gt;To make a history look like a serial one, we have ensure is that each
transaction always sees the shared state as if no other transaction was
present. If a transaction detects a conflict, it has to revert its own
changes as if they never happened.&lt;/p&gt;
&lt;h4 id=&#34;fixing-the-code&#34;&gt;Fixing the Code&lt;/h4&gt;
&lt;p&gt;Our transaction manager already detects conflicts among transactions that
access the same resource concurrently. This means that we have already
implemented half of the requirements for serializability. What the
transaction manager is still missing is a way of reverting a transaction&amp;rsquo;s
changes when the transaction aborts.&lt;/p&gt;
&lt;p&gt;We implement this by introducing transaction-local state for each resources.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#75715e&#34;&gt;#define RESOURCE_HAS_LOCAL_VALUE    (1ul &amp;lt;&amp;lt; 0)
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;             value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;             local_value;    &lt;span style=&#34;color:#75715e&#34;&gt;/* the transaction-local state */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;unsigned&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;long&lt;/span&gt;   flags;          &lt;span style=&#34;color:#75715e&#34;&gt;/* flag set if local state present. */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_t&lt;/span&gt;       owner;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_mutex_t&lt;/span&gt; lock;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;};
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The owner of the resource always stores only to the local state; and it
always loads from the local state if that is present.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res, &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; value)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;acquire_int_resource&lt;/span&gt;(res);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* only store to local state */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_value &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;flags &lt;span style=&#34;color:#f92672&#34;&gt;|=&lt;/span&gt; RESOURCE_HAS_LOCAL_VALUE;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; true;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res, &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; value)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;acquire_int_resource&lt;/span&gt;(res);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#75715e&#34;&gt;/* return the local state if we have executed a store() before */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;flags &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; RESOURCE_HAS_LOCAL_VALUE) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;value &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;value &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; true;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The local state becomes globally visible if, and only if, (!) the transaction commits.
This happens just before releasing the resource.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res, &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; commit)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_t&lt;/span&gt; self &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_self&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;lock);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;owner &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;owner &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; self) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;/* if we commit, copy the local state to the global state */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;flags &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt; RESOURCE_HAS_LOCAL_VALUE) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (commit) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;value &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;local_value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;flags &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;=&lt;/span&gt; &lt;span style=&#34;color:#f92672&#34;&gt;~&lt;/span&gt;RESOURCE_HAS_LOCAL_VALUE;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;owner &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_unlock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;lock);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Every time we call &lt;code&gt;release_int_resource()&lt;/code&gt;, we now have to tell it whether
we&amp;rsquo;re comitting or not.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;{
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    [...]
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; true;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        release:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, commit);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, commit);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;If we commit a transaction, its local effects become globally visible. If we
abort, the transaction&amp;rsquo;s effects are thrown away.&lt;/p&gt;
&lt;p&gt;These fairly small changes fix the incorrect state that the consumer was
observing. If you run this code, even with &lt;code&gt;sleep()&lt;/code&gt; and &lt;code&gt;printf()&lt;/code&gt; removed,
you won&amp;rsquo;t see any warnings about incorrect value pairs.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;In this post, we looked at serializability and how to implemenent it in our
transaction manager.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A &lt;em&gt;serial&lt;/em&gt; history is a set of transactions that are executed one by one.&lt;/li&gt;
&lt;li&gt;We want concurrent executions of a history to have the same result as
a serial one. This is called &lt;em&gt;serializability.&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;We have to revert a transaction&amp;rsquo;s changes when the transaction aborts.&lt;/li&gt;
&lt;li&gt;We introduced transaction-local state for each resource. The local state
becomes globally visible &lt;em&gt;iff&lt;/em&gt; the transaction commits.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As before, the full source code for this blog post is
&lt;a href=&#34;https://github.com/tdz/blog_examples/tree/master/2017-05-12&#34;&gt;available on GitHub&lt;/a&gt;. The code should now be complete enough
to be useful for an arbitrary amount of producers and consumers, or threads
that perform both.&lt;/p&gt;
&lt;p&gt;In the next installment, we&amp;rsquo;ll replace the while loop in the producer and
consumer functions with something nicer. The result will be a cleaner and
more maintainable code base.&lt;/p&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Transactional Semantics in Theory and Practice</title>
      <link>https://tzimmermann.org/2017/05/09/transactional-semantics-in-theory-and-practice/</link>
      <pubDate>Tue, 09 May 2017 18:00:00 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/05/09/transactional-semantics-in-theory-and-practice/</guid>
      <description>&lt;p&gt;In the &lt;a href=&#34;https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/&#34;&gt;previous installment&lt;/a&gt;, we implemented a simple transaction
manager, but we didn&amp;rsquo;t really say what it means to run code as a transaction,
which features are considered &lt;em&gt;transactional&lt;/em&gt; and which aren&amp;rsquo;t.&lt;/p&gt;
&lt;p&gt;In this blog post, we&amp;rsquo;re first going to examine the theoretical priciples of
transactional semantics, and afterwards look at how to put them into practice.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;h4 id=&#34;why-bother&#34;&gt;Why Bother?&lt;/h4&gt;
&lt;p&gt;It&amp;rsquo;s certainly fair to ask why we should bother.&lt;/p&gt;
&lt;p&gt;Image a software program of your choice. If we take a step backwards from the
actual code, we can describe the software as a &lt;a href=&#34;https://en.wikipedia.org/wiki/Finite-state_machine&#34;&gt;state machine&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;As the name implies, the state machine is always in a &lt;em&gt;state.&lt;/em&gt; What the state
consists of depends on the software. For example, a chess game might be in a
state where it waits for the player&amp;rsquo;s next move. While it does this, it
doesn&amp;rsquo;t change. At the software level, think of state as a combination of the
values of all data structures.&lt;/p&gt;
&lt;p&gt;Now something happens. Maybe the user pressed a key, or a hardware sensor
fired, or a new packet arrived on the network. Our state machine responds
according to which state it is in. When it does so, it performs a specific
action and moves into a new state. This movement from one state to the next
while performing an action in between is called a &lt;em&gt;transition.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;In a real-world program, the action is implemented by software. When the state
is in data structures, the action is in algorithms.&lt;/p&gt;
&lt;p&gt;When the software is in a specific state, a specific input triggers a specific
action, which transitions the software into a new state. Normally all states
should be well-defined and transitions should always move the state machine
from one well-defined state to another well-defined state.&lt;/p&gt;
&lt;p&gt;So far, so good. But back in the real world, not all state can handle all
input; and if it can, the associated action can be faulty. When this happens,
the state machine goes from a well-defined state into an undefined state.
What happens next is not specified.&lt;/p&gt;
&lt;p&gt;We call this a software bug.&lt;/p&gt;
&lt;p&gt;If we could implement our transition such that it detects incorrect input or
internal problems automatically, and has the option of going back to the old,
well-defined state; we&amp;rsquo;d be able to rule-out a large number of incorrect
transitions into undefined states.&lt;/p&gt;
&lt;p&gt;This is were the transaction concept comes in handy.&lt;/p&gt;
&lt;h4 id=&#34;the-acid-properties&#34;&gt;The ACID Properties&lt;/h4&gt;
&lt;p&gt;Transactional semantics are defined by four properties, which the transaction
manager guarantees to its transactions. Those are called the ACID properties,
from their initial letters. If you had at least a minimal exposure to database
theory, you have already seen them before.&lt;/p&gt;
&lt;p&gt;The ACID properties are&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Atomicity,&lt;/li&gt;
&lt;li&gt;Consistency,&lt;/li&gt;
&lt;li&gt;Isolation, and&lt;/li&gt;
&lt;li&gt;Durability.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Let&amp;rsquo;s go through them one by one. Consistency directly follows from our
previous discussion of states and transations, so let&amp;rsquo;s start with this.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Consistency&lt;/em&gt; describes a requirement to move from one well-defined state
to another. For example, the HTML documents of a website refer to each other
via hyper links. If one of the document&amp;rsquo;s files gets renamed, the consistency
constraints could require that all links in all documents refering to the
renamed file should be updated to the new filename.&lt;/p&gt;
&lt;p&gt;What is considered well-defined depends on the software at hand; therefore
guarantee-ing consistency always requires some help from the application. The
transaction system can only help with implementing this. In our example, if
the rename-and-update transaction simple ignores some of the HTML documents
for an update, the result is probably inconsistent.&lt;/p&gt;
&lt;p&gt;To guarantee consistency, it&amp;rsquo;s obvious that we have to guarantee
atomicity as well. &lt;em&gt;Atomicity&lt;/em&gt; specifies that we either do all of
the operations contained in a transaction, or none. That&amp;rsquo;s something, the
transaction system can help a lot with. In the example with the HTML
documents, the transaction system would ensure that all documents are updated,
or, if updating is not possible, revert to the old state before the rename.&lt;/p&gt;
&lt;p&gt;So far we&amp;rsquo;ve only considered a single transaction. Now let&amp;rsquo;s add another,
concurent transaction into the mix. This brings us to isolation. The
&lt;em&gt;isolation&lt;/em&gt; requirement specifies that the effects of a transaction shall
not interfere with the effects of another, concurrent transaction.&lt;/p&gt;
&lt;p&gt;To give an example of &lt;em&gt;isolation&lt;/em&gt;, if both of our transactions rename
filenames of HTML documents and update the references, they should not
overwrite each others changes. In most cases the cumulative effect of
both transactions should look as if the transactions had been executed
one-after-the-other.&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;
&lt;p&gt;Finally, we have durability. &lt;em&gt;Durability,&lt;/em&gt; also known as persistence,
specifies that effects of a transaction persist, once the transaction
committed the effects. A later transaction will always see these changes and
not a previous state missing them. For our HTML example this means that once
a document has been successfully renamed, a later transaction will not see
the old filename.&lt;/p&gt;
&lt;p&gt;Durability is often not achievable by the transactional system alone. It
requires an environment that ensures certain constaints.
For example, if an HTML document gets renamed and suddenly the disk drive
fails, the rename can get lost. The environment must apply sophisticated
back-up and replication strategies to avoid this.&lt;/p&gt;
&lt;h4 id=&#34;putting-theory-into-practice&#34;&gt;Putting Theory into Practice&lt;/h4&gt;
&lt;p&gt;The ACID properties are most of all requirements, but not practical
solutions. This is the job of the transaction manager.&lt;/p&gt;
&lt;p&gt;The transaction manager provides the transactions with a number of
operations. For each operation it implements two features. These
are&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;error handling, and&lt;/li&gt;
&lt;li&gt;concurrency control.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Who really cares about handling all errors correctly? Handling means
&lt;em&gt;detecting&lt;/em&gt; every error and always being able to move back into a previous
consistent state. The latter is called &lt;em&gt;recovery.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Common sense says that error handling is the worst part of each software.
Errors are hard to test for and rarely happen. The error handling is
therefore the code that gets executed the least. Recovery is often complicated
as it requires significant effort to being able to back in state. In
traditional software, this is almost impossible.&lt;/p&gt;
&lt;p&gt;Transaction managers implement all logic required to detect every possible
error for each of its operations, and contain the logic for going back into
a previous state; therefore recovering from the detected error.&lt;/p&gt;
&lt;p&gt;This provides a significant benefit over traditional approaches where
application logic and error handling are written side by side. Because the
transaction manager implements error handling once, all transactions
automatically employ it. Therefore all transactional application logic
automatically employs it as well. This gives us the atomicity and consistency
requirements from the ACID properties.&lt;/p&gt;
&lt;p&gt;With a good transaction manager, all the error handling that&amp;rsquo;s left for the
application is the pathological cases, when the software reaches hardware
limits or sees hardware failure. Even in these cases, error detection is still
provided by the transaction manager and the application at least gets a
chance of reporting the error to an administrator and shutting down safely.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Concurrency control&lt;/em&gt; describes the logic that controls resource access and
protects resources against concurrent access from multiple transactions. A
resource can be any data structure that transactions might want to use, maybe
a file or shared memory.&lt;/p&gt;
&lt;p&gt;There&amp;rsquo;s a lot to concurrency control, but you can think of it as locking.
Locking happens to be the most common implementation.&lt;/p&gt;
&lt;p&gt;Controlling resource access gives us the atomicity, consistency and isolation
requirements of the ACID properties. Without concurrency control, transactions
would constantly overwrite each others effects and operate on inconsistent,
half-committed state changes made by other transactions.&lt;/p&gt;
&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;There was quite of theory on this blog post. We first&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;looked at software as a set of states that are connected by transitions.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We can make these transitions far less error prone by guarantee-ing the
properties of&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;atomicity,&lt;/li&gt;
&lt;li&gt;consistensy,&lt;/li&gt;
&lt;li&gt;isolation, and&lt;/li&gt;
&lt;li&gt;durability.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This is called a transaction. A transaction manager helps with implementing
these guarantees by providing&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;error handling, and&lt;/li&gt;
&lt;li&gt;concurrency control.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Next time, we&amp;rsquo;ll get back to &lt;a href=&#34;https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/&#34;&gt;simpletm&lt;/a&gt;, our toy transaction
manager. If you&amp;rsquo;re interested in a complete transaction manager, take a
look at &lt;a href=&#34;https://picotm.github.io/&#34;&gt;picotm&lt;/a&gt;.&lt;/p&gt;
&lt;h4 id=&#34;footnotes&#34;&gt;Footnotes&lt;/h4&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;This &lt;em&gt;one-after-the-other&lt;/em&gt; requirement is called serializability.
We&amp;rsquo;ll examine this in a later post.&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Implementing a Simple Transaction Manager in C</title>
      <link>https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/</link>
      <pubDate>Fri, 05 May 2017 10:05:01 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/05/05/implementing-a-simple-transaction-manager-in-c/</guid>
      <description>&lt;p&gt;In this blog post, we&amp;rsquo;re going to write a simple transaction manager
in C. It will load and store integer variables in memory, while handling
locks automatically. The full source code is available on &lt;a href=&#34;https://github.com/tdz/blog_examples/tree/master/2017-05-05&#34;&gt;GitHub&lt;/a&gt;.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;A transaction manager provides two important guarantees to each
transaction. These are isolation from the effects of concurrent
transactions, and error handling.&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; For now we only go for isolation.
Error handling requires a more elaborated software design than what is
possible in a single blog post.&lt;/p&gt;
&lt;p&gt;Before writing a transaction manager, the first thing to do is to look at the
involved resources. In our case these are two global integer values.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; g_i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; g_i1;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;These values are stored in memory. Transaction systems for memory are called
&lt;a href=&#34;https://en.wikipedia.org/wiki/Software_transactional_memory&#34;&gt;Software Transactional Memory&lt;/a&gt;. In principle, we could use arbitrary
types of resources or even combine resources of different types in a single
transaction. For simplicity, we stick with memory.&lt;/p&gt;
&lt;p&gt;So what do we do with these two values? For our example, we use two threads
in a producer-consumer scenario. The producer thread stores a value in
each of &lt;code&gt;g_i0&lt;/code&gt; and &lt;code&gt;g_i1&lt;/code&gt;, the consumer thread reads them.&lt;/p&gt;
&lt;p&gt;An important constraint is that the values in these variables are dependent
on each other: either both change or neither changes. We achieve this by
acquiring a lock while accessing &lt;code&gt;g_i0&lt;/code&gt; or &lt;code&gt;g_i1&lt;/code&gt;.&lt;/p&gt;
&lt;h4 id=&#34;a-non-transactional-example&#34;&gt;A non-transactional Example&amp;hellip;&lt;/h4&gt;
&lt;p&gt;Let&amp;rsquo;s take a look at some, still non-transactional, example code. Our producer
looks like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; g_i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; g_i1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_mutex_t&lt;/span&gt; g_lock0; &lt;span style=&#34;color:#75715e&#34;&gt;/* Lock for g_i0 */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_mutex_t&lt;/span&gt; g_lock1; &lt;span style=&#34;color:#75715e&#34;&gt;/* Lock for g_i1 */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;/* produce i0 and i1 */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        i1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;rand&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;print&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Storing i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        g_i0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        g_i1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; i1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_unlock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_unlock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The producer generates two values &lt;code&gt;i0&lt;/code&gt; and &lt;code&gt;i1&lt;/code&gt;. The value of &lt;code&gt;i0&lt;/code&gt; increases
monotonically. It might be a timestamp. The value of &lt;code&gt;i1&lt;/code&gt; changes arbitrarily;
maybe it&amp;rsquo;s the output of a hardware sensor. By acquiring locks &lt;code&gt;g_lock0&lt;/code&gt; and
&lt;code&gt;g_lock1&lt;/code&gt;, the producer enters a critical section where it updates the
global values.&lt;/p&gt;
&lt;p&gt;Our consumer looks like this.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;consumer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        i0 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; g_i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        i1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; g_i1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_unlock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_unlock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;/* consume i0 and i1 */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;print&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Loaded i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Again we have two local values &lt;code&gt;i0&lt;/code&gt; and &lt;code&gt;i1&lt;/code&gt;. This time they are not
generated, but updated from their global counterparts. Like the producer,
the consumer enters a critical section by acquiring the two locks. It
copies the values and prints them to the terminal.&lt;/p&gt;
&lt;h4 id=&#34;-with-a-problem&#34;&gt;&amp;hellip; with a Problem.&lt;/h4&gt;
&lt;p&gt;This is all nice and good&amp;hellip; except it isn&amp;rsquo;t. You&amp;rsquo;ve probably spotted
the problem already. Our producer excecutes&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock1);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;while our consumer concurrently executes&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock0);
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;If they interleave, we get&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock0); &lt;span style=&#34;color:#75715e&#34;&gt;/* producer */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock1); &lt;span style=&#34;color:#75715e&#34;&gt;/* consumer */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock1); &lt;span style=&#34;color:#75715e&#34;&gt;/* producer */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;g_lock0); &lt;span style=&#34;color:#75715e&#34;&gt;/* consumer */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This is the classical ABBA deadlock. The only way to resolve it is to
detect it beforehand and have one thread release its lock, so that the
other thread can make progress.&lt;/p&gt;
&lt;p&gt;Our transaction manager does this for us!&lt;/p&gt;
&lt;h4 id=&#34;rewriting-as-transactions&#34;&gt;Rewriting as Transactions&lt;/h4&gt;
&lt;p&gt;In a transactional code, each resource is somehow owned by the
transactions that use it. All this is really not the problem of the
transactions themselves, but the transaction manager that controls the
transactions. Each transaction tells the transaction manager what
resources it requires and which operations it performs on them. The
transaction manager handles the details of resource ownership.&lt;/p&gt;
&lt;p&gt;As a first step, let us wrap shared integer resources and information
about their current owner in a data structure. This simplifies the later
steps by a large amount.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;             value;  &lt;span style=&#34;color:#75715e&#34;&gt;/* only accessed by owner */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_t&lt;/span&gt;       owner;  &lt;span style=&#34;color:#75715e&#34;&gt;/* protected by lock */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_mutex_t&lt;/span&gt; lock;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    };
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This structure has three fields. The &lt;code&gt;value&lt;/code&gt; field is the value as before.
The &lt;code&gt;owner&lt;/code&gt; field is the thread of the transaction that currently owns the
resource. A transaction has to acquire ownership from the
transaction manager before it can access the &lt;code&gt;value&lt;/code&gt; field. Finally, the
field &lt;code&gt;lock&lt;/code&gt; protects the owner field.&lt;/p&gt;
&lt;p&gt;In the next step, we introduce the functions for acquiring and releasing
ownership of a resource.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;acquire_int_resource&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_t&lt;/span&gt; self &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_self&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;lock);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;owner &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;owner &lt;span style=&#34;color:#f92672&#34;&gt;!=&lt;/span&gt; self) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#75715e&#34;&gt;/* Owned by another thread. */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; err_has_owner;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        } &lt;span style=&#34;color:#66d9ef&#34;&gt;else&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;owner) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#75715e&#34;&gt;/* Now owned by us. */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;owner &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; self;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_unlock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;lock);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; true;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    err_has_owner:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_unlock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;lock);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The acquire function &lt;code&gt;acquire_int_resource()&lt;/code&gt; locks the owner field and checks its
value. If someone else is the owner, it reports failure by returning &lt;code&gt;false&lt;/code&gt;. This
will later lead to an abort of the transaction. If the resource currently has no
owner, &lt;code&gt;acquire_int_resource()&lt;/code&gt; sets the transaction&amp;rsquo;s thread as the owner and
reports success by returning &lt;code&gt;true&lt;/code&gt;. If the transaction already owns the resource,
it also reports success.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;pthread_t&lt;/span&gt; self &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_self&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_lock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;lock);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;owner &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;owner &lt;span style=&#34;color:#f92672&#34;&gt;==&lt;/span&gt; self) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#75715e&#34;&gt;/* Release the resource */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;owner &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;pthread_mutex_unlock&lt;/span&gt;(&lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;lock);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The release function &lt;code&gt;release_int_resource()&lt;/code&gt; only has to check if the transaction
is the current owner of the resource. If so, it clears the &lt;code&gt;owner&lt;/code&gt; field. If not,
it returns silently.&lt;/p&gt;
&lt;p&gt;You probably noticed that there&amp;rsquo;s not yet a single integer involved here. We could
move this code into a separate module and re-use it for any kind of resource.&lt;/p&gt;
&lt;p&gt;The integer values are introduced now. We do this by wrapping the load and store
operations in two functions &lt;code&gt;load_int()&lt;/code&gt; and &lt;code&gt;store_int()&lt;/code&gt;. These functions will do
all the work required for accessing shared integer resources.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; integer_res&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res, &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt;&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; value)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;acquire_int_res&lt;/span&gt;(res);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt;value &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; true;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; integer_res&lt;span style=&#34;color:#f92672&#34;&gt;*&lt;/span&gt; res, &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; value)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;acquire_int_res&lt;/span&gt;(res);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        res&lt;span style=&#34;color:#f92672&#34;&gt;-&amp;gt;&lt;/span&gt;value &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; value;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;return&lt;/span&gt; true;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Both functions first try to acquire the resource by calling
&lt;code&gt;acquire_int_res()&lt;/code&gt;. If successful they perform their respective operation
by either loading or storing a value. Like the acquire function, they
return true or false, depending on whether or not the resource could be
acquired in the first place.&lt;/p&gt;
&lt;h4 id=&#34;transactional-producers-and-consumers&#34;&gt;Transactional Producers and Consumers&lt;/h4&gt;
&lt;p&gt;Phew! I hope you&amp;rsquo;re still with me.&lt;/p&gt;
&lt;p&gt;What we&amp;rsquo;ve done so far is to write a producer-consumer scenario using locks,
only to discover that our code is prone to deadlocks.&lt;/p&gt;
&lt;p&gt;From their we went towards implementing transaction support. We first wrapped
our resource in a data structure, so that is can be maintained by the
transaction manager, then we created interfaces for accessing and releasing
the resource.&lt;/p&gt;
&lt;p&gt;Now you might wonder where that transaction manager actually is. Well, in
some way it&amp;rsquo;s already there. The core of our transaction manager is in the
acquire and release functions and in the resource structure. This code does
provide us with everything we need to ensure isolation among transactions.&lt;/p&gt;
&lt;p&gt;The only thing missing are the producer and consumer threads that
use our &lt;em&gt;wanna-be&lt;/em&gt; transaction manager. Let&amp;rsquo;s take a look at the producer.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;struct&lt;/span&gt; int_resource g_int_resource[&lt;span style=&#34;color:#ae81ff&#34;&gt;2&lt;/span&gt;];
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The global values are now stored in the instances of &lt;code&gt;struct int_resource&lt;/code&gt;
in &lt;code&gt;g_int_resource&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Like before the producer creates two values and prints them to the terminal.
Unlike before, there are no locks anymore. In fact, the whole critical
section has been replaced by a while loop.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;producer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;static&lt;/span&gt; &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;/* produce i0 and i1 */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#f92672&#34;&gt;++&lt;/span&gt;i0;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        i1 &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;rand&lt;/span&gt;();
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;print&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Storing i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;commit) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; release;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;store_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; release;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; true;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        release:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;You probably remember that the transaction might not be able to acquire
ownership of a resource. In this case, it has to release its locks and
restart from the beginning. That&amp;rsquo;s how we prevent the ABBA deadlock scenario
that our original code couldn&amp;rsquo;t handle.&lt;/p&gt;
&lt;p&gt;The transaction starts with &lt;code&gt;commit&lt;/code&gt; set to &lt;code&gt;false&lt;/code&gt;. If any invocation of
&lt;code&gt;store_int()&lt;/code&gt; returns &lt;code&gt;false&lt;/code&gt;, it was not able to acquire ownership of the
resource. The transaction jumps to &lt;code&gt;release&lt;/code&gt; where it releases all its
resources. These resources are now available for being acquired by a
concurrent transaction. Since &lt;code&gt;commit&lt;/code&gt; is still &lt;code&gt;false&lt;/code&gt;, the while loop
continues and the transaction starts anew.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Be warned that the producer code doesn&amp;rsquo;t yet roll-back correctly. We&amp;rsquo;ll
fix this in one of the next installments, but don&amp;rsquo;t put this example into
practice as it is.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;If all invocations of &lt;code&gt;store_int()&lt;/code&gt; succeed, the transaction eventually
sets &lt;code&gt;commit&lt;/code&gt; to &lt;code&gt;true&lt;/code&gt;. It will then also release its resources, but now
the while loop breaks. The transaction has committed its results.&lt;/p&gt;
&lt;p&gt;The while loop is good for educational purposes, not an optimal software
design, and not what you&amp;rsquo;d use in a real-world transaction manager. We&amp;rsquo;ll
build something better in a later blog post.&lt;/p&gt;
&lt;p&gt;Now that we have a producer, let&amp;rsquo;s also look at the consumer side.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-c&#34; data-lang=&#34;c&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    &lt;span style=&#34;color:#a6e22e&#34;&gt;consumer_func&lt;/span&gt;(&lt;span style=&#34;color:#66d9ef&#34;&gt;void&lt;/span&gt;)
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;int&lt;/span&gt; i0, i1;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; false;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#66d9ef&#34;&gt;while&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;commit) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;bool&lt;/span&gt; succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; release;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            succ &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; &lt;span style=&#34;color:#a6e22e&#34;&gt;load_int&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;, &lt;span style=&#34;color:#f92672&#34;&gt;&amp;amp;&lt;/span&gt;i0);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#66d9ef&#34;&gt;if&lt;/span&gt; (&lt;span style=&#34;color:#f92672&#34;&gt;!&lt;/span&gt;succ) {
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;                &lt;span style=&#34;color:#66d9ef&#34;&gt;goto&lt;/span&gt; release;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            commit &lt;span style=&#34;color:#f92672&#34;&gt;=&lt;/span&gt; true;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        release:
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;0&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;            &lt;span style=&#34;color:#a6e22e&#34;&gt;release_int_resource&lt;/span&gt;(g_int_resource &lt;span style=&#34;color:#f92672&#34;&gt;+&lt;/span&gt; &lt;span style=&#34;color:#ae81ff&#34;&gt;1&lt;/span&gt;);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        }
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#75715e&#34;&gt;/* consume i0 and i1 */&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;        &lt;span style=&#34;color:#a6e22e&#34;&gt;print&lt;/span&gt;(&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;Loaded i0=%d, i1=%d&lt;/span&gt;&lt;span style=&#34;color:#ae81ff&#34;&gt;\n&lt;/span&gt;&lt;span style=&#34;color:#e6db74&#34;&gt;&amp;#34;&lt;/span&gt;, i0, i1);
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;    }
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Again we replaced the critical section by a while loop. The principles of
aborting and committing the transaction are the same here as in the producer,
just that this transaction calls the &lt;code&gt;load_int()&lt;/code&gt; function.&lt;/p&gt;
&lt;p&gt;If you run this example, it should display something like the output below
on the terminal.&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;    Loaded i0=0, i1=0
    Storing i0=1, i1=1804289383
    Loaded i0=1, i1=1804289383
    Storing i0=2, i1=846930886
    Storing i0=3, i1=1681692777
    Loaded i0=3, i1=1681692777
&lt;/code&gt;&lt;/pre&gt;&lt;h4 id=&#34;summary&#34;&gt;Summary&lt;/h4&gt;
&lt;p&gt;I hope you enjoyed the quick tour through a very simple transaction manager.
While the presented code is simple, it already contains many of the basic
building blocks of a complete implementation.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The transaction manager provides isolation and error handling to its
transactions.&lt;/li&gt;
&lt;li&gt;Transactions interact with transactional resources by invoking
transactional interfaces.&lt;/li&gt;
&lt;li&gt;Non-transactional code is prone to deadlocks, transactional code
isn&amp;rsquo;t.&lt;sup id=&#34;fnref:2&#34;&gt;&lt;a href=&#34;#fn:2&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;2&lt;/a&gt;&lt;/sup&gt;&lt;/li&gt;
&lt;li&gt;Conflicting access is resolved by the transaction manager. This can
lead to an abort and restart of the involved transactions.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The full source code for this blog post is &lt;a href=&#34;https://github.com/tdz/blog_examples/tree/master/2017-05-05&#34;&gt;available on GitHub&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;There are more blog posts to come that talk about all kinds of topics around
transactions. If you&amp;rsquo;re interested in a complete transaction manager take a
look at &lt;a href=&#34;https://picotm.github.io/&#34;&gt;picotm&lt;/a&gt;.&lt;/p&gt;
&lt;h4 id=&#34;footnotes&#34;&gt;Footnotes&lt;/h4&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;In database context, these guarantees are known as the &lt;a href=&#34;https://en.wikipedia.org/wiki/ACID&#34;&gt;ACID&lt;/a&gt;
properties.&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:2&#34;&gt;
&lt;p&gt;We&amp;rsquo;ll talk about livelocks in a later blog post.&amp;#160;&lt;a href=&#34;#fnref:2&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</description>
    </item>
    
    
    
    <item>
      <title>Thank you, Jekyll!</title>
      <link>https://tzimmermann.org/2017/05/02/thank-you-jekyll/</link>
      <pubDate>Tue, 02 May 2017 15:05:01 +0200</pubDate>
      <author>blog@tzimmermann.org (Thomas Zimmermann)</author>
      <guid>https://tzimmermann.org/2017/05/02/thank-you-jekyll/</guid>
      <description>&lt;p&gt;Just a quick &lt;em&gt;Thank you&lt;/em&gt; to everyone involved with Jekyll.&lt;/p&gt;
&lt;!-- excerpt --&gt;
&lt;p&gt;Before I get to my own topics, I think it&amp;rsquo;s appropriate that I thank everyone
who is involved with &lt;a href=&#34;https://jekyllrb.com/&#34;&gt;Jekyll&lt;/a&gt; for their work. Jekyll is the CMS
software I&amp;rsquo;m using, and I could not have made this website and blog without
it.&lt;/p&gt;
&lt;p&gt;A special &lt;em&gt;Thank you&lt;/em&gt; goes out to &lt;a href=&#34;https://github.com/steinvc/&#34;&gt;Stijn&lt;/a&gt;, who&amp;rsquo;s Jekyll theme
&lt;a href=&#34;https://steinvc.github.io/holo-alfa/&#34;&gt;Holo Alfa&lt;/a&gt; I&amp;rsquo;m using.&lt;/p&gt;
</description>
    </item>
    
    
    
    
    
    
    
    
  </channel>
</rss>
