Merge branch 'net-atl1c-atl1e-atl1-fix-soft-lockup-on-out-of-range-tx-consumer-index'

says:

====================
net: atl1c/atl1e/atl1: fix soft lockup on out-of-range tx consumer index

atl1c_clean_tx() reads a hardware-maintained tx consumer index and
walks a software index towards it:

    while (next_to_clean != hw_next_to_clean) {
            ...
            if (++next_to_clean == tpd_ring->count)
                    next_to_clean = 0;
    }

next_to_clean only ever takes values in [0, tpd_ring->count). If the
hardware read returns a value outside that range - seen as 0xffff
while the PCIe link/MAC is resetting, e.g. during a neighboring
device's reboot - the loop condition can never become false, and the
NAPI thread spins forever. This produced a real soft lockup on
current hardware:

    watchdog: BUG: soft lockup - CPU#12 stuck for 354s! [napi/eth%d-0]
    RIP: 0010:atl1c_clean_tx+0x142/0x2d0 [atl1c]

Patch 1 fixes this in atl1c. atl1e and atl1 (atlx) share the exact
same loop shape, reading their own hardware-maintained consumer index
with no bounds check either, and are just as reachable from the same
kind of PCIe link event. Patches 2 and 3 apply the same guard to each.
====================

Link: https://patch.msgid.link/20260921091334.3571525-1-tamas@rimpianto.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
This commit is contained in:
Paolo Abeni 2026-09-24 12:41:12 +02:00
commit 3cd204d4c6
3 changed files with 9 additions and 0 deletions

View File

@ -1602,6 +1602,9 @@ static int atl1c_clean_tx(struct napi_struct *napi, int budget)
AT_READ_REGW(&adapter->hw, atl1c_qregs[tpd_ring->num].tpd_cons,
&hw_next_to_clean);
if (unlikely(hw_next_to_clean >= tpd_ring->count))
hw_next_to_clean = next_to_clean;
while (next_to_clean != hw_next_to_clean) {
buffer_info = &tpd_ring->buffer_info[next_to_clean];
if (buffer_info->skb) {

View File

@ -1234,6 +1234,9 @@ static bool atl1e_clean_tx_irq(struct atl1e_adapter *adapter)
u16 hw_next_to_clean = AT_READ_REGW(&adapter->hw, REG_TPD_CONS_IDX);
u16 next_to_clean = atomic_read(&tx_ring->next_to_clean);
if (unlikely(hw_next_to_clean >= tx_ring->count))
hw_next_to_clean = next_to_clean;
while (next_to_clean != hw_next_to_clean) {
tx_buffer = &tx_ring->tx_buffer[next_to_clean];
if (tx_buffer->dma) {

View File

@ -2066,6 +2066,9 @@ static int atl1_intr_tx(struct atl1_adapter *adapter)
sw_tpd_next_to_clean = atomic_read(&tpd_ring->next_to_clean);
cmb_tpd_next_to_clean = le16_to_cpu(adapter->cmb.cmb->tpd_cons_idx);
if (unlikely(cmb_tpd_next_to_clean >= tpd_ring->count))
cmb_tpd_next_to_clean = sw_tpd_next_to_clean;
while (cmb_tpd_next_to_clean != sw_tpd_next_to_clean) {
buffer_info = &tpd_ring->buffer_info[sw_tpd_next_to_clean];
if (buffer_info->dma) {