mirror of
https://github.com/torvalds/linux.git
synced 2026-10-10 04:18:03 +02:00
Merge branch 'net-atl1c-atl1e-atl1-fix-soft-lockup-on-out-of-range-tx-consumer-index'
says:
====================
net: atl1c/atl1e/atl1: fix soft lockup on out-of-range tx consumer index
atl1c_clean_tx() reads a hardware-maintained tx consumer index and
walks a software index towards it:
while (next_to_clean != hw_next_to_clean) {
...
if (++next_to_clean == tpd_ring->count)
next_to_clean = 0;
}
next_to_clean only ever takes values in [0, tpd_ring->count). If the
hardware read returns a value outside that range - seen as 0xffff
while the PCIe link/MAC is resetting, e.g. during a neighboring
device's reboot - the loop condition can never become false, and the
NAPI thread spins forever. This produced a real soft lockup on
current hardware:
watchdog: BUG: soft lockup - CPU#12 stuck for 354s! [napi/eth%d-0]
RIP: 0010:atl1c_clean_tx+0x142/0x2d0 [atl1c]
Patch 1 fixes this in atl1c. atl1e and atl1 (atlx) share the exact
same loop shape, reading their own hardware-maintained consumer index
with no bounds check either, and are just as reachable from the same
kind of PCIe link event. Patches 2 and 3 apply the same guard to each.
====================
Link: https://patch.msgid.link/20260921091334.3571525-1-tamas@rimpianto.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
This commit is contained in:
commit
3cd204d4c6
|
|
@ -1602,6 +1602,9 @@ static int atl1c_clean_tx(struct napi_struct *napi, int budget)
|
|||
AT_READ_REGW(&adapter->hw, atl1c_qregs[tpd_ring->num].tpd_cons,
|
||||
&hw_next_to_clean);
|
||||
|
||||
if (unlikely(hw_next_to_clean >= tpd_ring->count))
|
||||
hw_next_to_clean = next_to_clean;
|
||||
|
||||
while (next_to_clean != hw_next_to_clean) {
|
||||
buffer_info = &tpd_ring->buffer_info[next_to_clean];
|
||||
if (buffer_info->skb) {
|
||||
|
|
|
|||
|
|
@ -1234,6 +1234,9 @@ static bool atl1e_clean_tx_irq(struct atl1e_adapter *adapter)
|
|||
u16 hw_next_to_clean = AT_READ_REGW(&adapter->hw, REG_TPD_CONS_IDX);
|
||||
u16 next_to_clean = atomic_read(&tx_ring->next_to_clean);
|
||||
|
||||
if (unlikely(hw_next_to_clean >= tx_ring->count))
|
||||
hw_next_to_clean = next_to_clean;
|
||||
|
||||
while (next_to_clean != hw_next_to_clean) {
|
||||
tx_buffer = &tx_ring->tx_buffer[next_to_clean];
|
||||
if (tx_buffer->dma) {
|
||||
|
|
|
|||
|
|
@ -2066,6 +2066,9 @@ static int atl1_intr_tx(struct atl1_adapter *adapter)
|
|||
sw_tpd_next_to_clean = atomic_read(&tpd_ring->next_to_clean);
|
||||
cmb_tpd_next_to_clean = le16_to_cpu(adapter->cmb.cmb->tpd_cons_idx);
|
||||
|
||||
if (unlikely(cmb_tpd_next_to_clean >= tpd_ring->count))
|
||||
cmb_tpd_next_to_clean = sw_tpd_next_to_clean;
|
||||
|
||||
while (cmb_tpd_next_to_clean != sw_tpd_next_to_clean) {
|
||||
buffer_info = &tpd_ring->buffer_info[sw_tpd_next_to_clean];
|
||||
if (buffer_info->dma) {
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user