mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning
The hand-rolled bit-scanning loop in the NCQ completion path has an
infinite loop bug. When tag_mask has only high bits set (e.g.
0x80000000), the inner while loop left-shifts tag_mask until it
overflows to 0. At that point !(0 & 1) is always true and 0 <<= 1
stays 0, causing an infinite loop in hardirq context with a spinlock
held.
Replace the open-coded bit-scanning with __ffs() which correctly
finds the least significant set bit and is bounded by the width of
the argument.
Fixes: 62936009f3 ("[libata] Add 460EX on-chip SATA driver, sata_dwc_460ex")
Assisted-by: opencode:big-pickle
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Signed-off-by: Damien Le Moal <dlemoal@kernel.org>
This commit is contained in:
parent
66c4e310ad
commit
c2130f6553
|
|
@ -607,14 +607,9 @@ static irqreturn_t sata_dwc_isr(int irq, void *dev_instance)
|
|||
status = ap->ops->sff_check_status(ap);
|
||||
dev_dbg(ap->dev, "%s ATA status register=0x%x\n", __func__, status);
|
||||
|
||||
tag = 0;
|
||||
while (tag_mask) {
|
||||
while (!(tag_mask & 0x00000001)) {
|
||||
tag++;
|
||||
tag_mask <<= 1;
|
||||
}
|
||||
|
||||
tag_mask &= (~0x00000001);
|
||||
tag = __ffs(tag_mask);
|
||||
tag_mask &= ~(1U << tag);
|
||||
qc = ata_qc_from_tag(ap, tag);
|
||||
if (unlikely(!qc)) {
|
||||
dev_err(ap->dev, "failed to get qc");
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user