Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1242908

[PATCH 3.2 068/107] powerpc/MSI: Fix race condition in tearing down MSI interrupts

From Ben Hutchings <ben@decadent.org.uk>
Newsgroups linux.kernel
Subject [PATCH 3.2 068/107] powerpc/MSI: Fix race condition in tearing down MSI interrupts
Date 2015-10-09 02:40 +0200
Message-ID <qhtT5-2Qh-45@gated-at.bofh.it> (permalink)
References <qhtzH-2tg-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


3.2.72-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Paul Mackerras <paulus@ozlabs.org>

commit e297c939b745e420ef0b9dc989cb87bda617b399 upstream.

This fixes a race which can result in the same virtual IRQ number
being assigned to two different MSI interrupts.  The most visible
consequence of that is usually a warning and stack trace from the
sysfs code about an attempt to create a duplicate entry in sysfs.

The race happens when one CPU (say CPU 0) is disposing of an MSI
while another CPU (say CPU 1) is setting up an MSI.  CPU 0 calls
(for example) pnv_teardown_msi_irqs(), which calls
msi_bitmap_free_hwirqs() to indicate that the MSI (i.e. its
hardware IRQ number) is no longer in use.  Then, before CPU 0 gets
to calling irq_dispose_mapping() to free up the virtal IRQ number,
CPU 1 comes in and calls msi_bitmap_alloc_hwirqs() to allocate an
MSI, and gets the same hardware IRQ number that CPU 0 just freed.
CPU 1 then calls irq_create_mapping() to get a virtual IRQ number,
which sees that there is currently a mapping for that hardware IRQ
number and returns the corresponding virtual IRQ number (which is
the same virtual IRQ number that CPU 0 was using).  CPU 0 then
calls irq_dispose_mapping() and frees that virtual IRQ number.
Now, if another CPU comes along and calls irq_create_mapping(), it
is likely to get the virtual IRQ number that was just freed,
resulting in the same virtual IRQ number apparently being used for
two different hardware interrupts.

To fix this race, we just move the call to msi_bitmap_free_hwirqs()
to after the call to irq_dispose_mapping().  Since virq_to_hw()
doesn't work for the virtual IRQ number after irq_dispose_mapping()
has been called, we need to call it before irq_dispose_mapping() and
remember the result for the msi_bitmap_free_hwirqs() call.

The pattern of calling msi_bitmap_free_hwirqs() before
irq_dispose_mapping() appears in 5 places under arch/powerpc, and
appears to have originated in commit 05af7bd2d75e ("[POWERPC] MPIC
U3/U4 MSI backend") from 2007.

Fixes: 05af7bd2d75e ("[POWERPC] MPIC U3/U4 MSI backend")
Reported-by: Alexey Kardashevskiy <aik@ozlabs.ru>
Signed-off-by: Paul Mackerras <paulus@samba.org>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
[bwh: Backported to 3.2:
 - powernv uses a private functions instead of msi_bitmap_free_hwirqs()
 - Adjust filename, context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 arch/powerpc/platforms/powernv/pci.c  | 5 +++--
 arch/powerpc/sysdev/fsl_msi.c         | 5 +++--
 arch/powerpc/sysdev/mpic_pasemi_msi.c | 5 +++--
 arch/powerpc/sysdev/mpic_u3msi.c      | 5 +++--
 arch/powerpc/sysdev/ppc4xx_msi.c      | 5 +++--
 5 files changed, 15 insertions(+), 10 deletions(-)

--- a/arch/powerpc/platforms/powernv/pci.c
+++ b/arch/powerpc/platforms/powernv/pci.c
@@ -130,6 +130,7 @@ static void pnv_teardown_msi_irqs(struct
 	struct pci_controller *hose = pci_bus_to_host(pdev->bus);
 	struct pnv_phb *phb = hose->private_data;
 	struct msi_desc *entry;
+	irq_hw_number_t hwirq;
 
 	if (WARN_ON(!phb))
 		return;
@@ -137,9 +138,10 @@ static void pnv_teardown_msi_irqs(struct
 	list_for_each_entry(entry, &pdev->msi_list, list) {
 		if (entry->irq == NO_IRQ)
 			continue;
+		hwirq = virq_to_hw(entry->irq);
 		irq_set_msi_desc(entry->irq, NULL);
-		pnv_put_msi(phb, virq_to_hw(entry->irq));
 		irq_dispose_mapping(entry->irq);
+		pnv_put_msi(phb, hwirq);
 	}
 }
 #endif /* CONFIG_PCI_MSI */
--- a/arch/powerpc/sysdev/fsl_msi.c
+++ b/arch/powerpc/sysdev/fsl_msi.c
@@ -106,15 +106,16 @@ static void fsl_teardown_msi_irqs(struct
 {
 	struct msi_desc *entry;
 	struct fsl_msi *msi_data;
+	irq_hw_number_t hwirq;
 
 	list_for_each_entry(entry, &pdev->msi_list, list) {
 		if (entry->irq == NO_IRQ)
 			continue;
+		hwirq = virq_to_hw(entry->irq);
 		msi_data = irq_get_chip_data(entry->irq);
 		irq_set_msi_desc(entry->irq, NULL);
-		msi_bitmap_free_hwirqs(&msi_data->bitmap,
-				       virq_to_hw(entry->irq), 1);
 		irq_dispose_mapping(entry->irq);
+		msi_bitmap_free_hwirqs(&msi_data->bitmap, hwirq, 1);
 	}
 
 	return;
--- a/arch/powerpc/sysdev/mpic_pasemi_msi.c
+++ b/arch/powerpc/sysdev/mpic_pasemi_msi.c
@@ -74,6 +74,7 @@ static int pasemi_msi_check_device(struc
 static void pasemi_msi_teardown_msi_irqs(struct pci_dev *pdev)
 {
 	struct msi_desc *entry;
+	irq_hw_number_t hwirq;
 
 	pr_debug("pasemi_msi_teardown_msi_irqs, pdev %p\n", pdev);
 
@@ -81,10 +82,10 @@ static void pasemi_msi_teardown_msi_irqs
 		if (entry->irq == NO_IRQ)
 			continue;
 
+		hwirq = virq_to_hw(entry->irq);
 		irq_set_msi_desc(entry->irq, NULL);
-		msi_bitmap_free_hwirqs(&msi_mpic->msi_bitmap,
-				       virq_to_hw(entry->irq), ALLOC_CHUNK);
 		irq_dispose_mapping(entry->irq);
+		msi_bitmap_free_hwirqs(&msi_mpic->msi_bitmap, hwirq, ALLOC_CHUNK);
 	}
 
 	return;
--- a/arch/powerpc/sysdev/mpic_u3msi.c
+++ b/arch/powerpc/sysdev/mpic_u3msi.c
@@ -124,15 +124,16 @@ static int u3msi_msi_check_device(struct
 static void u3msi_teardown_msi_irqs(struct pci_dev *pdev)
 {
 	struct msi_desc *entry;
+	irq_hw_number_t hwirq;
 
         list_for_each_entry(entry, &pdev->msi_list, list) {
 		if (entry->irq == NO_IRQ)
 			continue;
 
+		hwirq = virq_to_hw(entry->irq);
 		irq_set_msi_desc(entry->irq, NULL);
-		msi_bitmap_free_hwirqs(&msi_mpic->msi_bitmap,
-				       virq_to_hw(entry->irq), 1);
 		irq_dispose_mapping(entry->irq);
+		msi_bitmap_free_hwirqs(&msi_mpic->msi_bitmap, hwirq, 1);
 	}
 
 	return;
--- a/arch/powerpc/sysdev/ppc4xx_msi.c
+++ b/arch/powerpc/sysdev/ppc4xx_msi.c
@@ -114,16 +114,17 @@ void ppc4xx_teardown_msi_irqs(struct pci
 {
 	struct msi_desc *entry;
 	struct ppc4xx_msi *msi_data = &ppc4xx_msi;
+	irq_hw_number_t hwirq;
 
 	dev_dbg(&dev->dev, "PCIE-MSI: tearing down msi irqs\n");
 
 	list_for_each_entry(entry, &dev->msi_list, list) {
 		if (entry->irq == NO_IRQ)
 			continue;
+		hwirq = virq_to_hw(entry->irq);
 		irq_set_msi_desc(entry->irq, NULL);
-		msi_bitmap_free_hwirqs(&msi_data->bitmap,
-				virq_to_hw(entry->irq), 1);
 		irq_dispose_mapping(entry->irq);
+		msi_bitmap_free_hwirqs(&msi_data->bitmap, hwirq, 1);
 	}
 }
 

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 3.2 000/107] 3.2.72-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
  [PATCH 3.2 072/107] USB: option: add ZTE PIDs Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
  [PATCH 3.2 069/107] hfs,hfsplus: cache pages correctly between  bnode_create and bnode_free Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
  [PATCH 3.2 015/107] ocfs2: fix BUG in ocfs2_downconvert_thread_do_work() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
  [PATCH 3.2 049/107] DRM - radeon: Don't link train DisplayPort on  HPD until we get the dpcd Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
  [PATCH 3.2 098/107] ipv6: lock socket in ip6_datagram_connect() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
  [PATCH 3.2 024/107] libfc: Fix fc_fcp_cleanup_each_cmd() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
  [PATCH 3.2 094/107] Initialize msg/shm IPC objects before doing  ipc_addid() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 060/107] drm/i915: Always mark the object as dirty  when used by the GPU Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 047/107] eCryptfs: Invalidate dcache entries when  lower i_nlink is zero Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 009/107] target: REPORT LUNS should return LUN 0 even  for dynamic ACLs Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 095/107] net/tipc: initialize security state for new  connection  socket Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 018/107] x86/ldt: Make modify_ldt synchronous Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 036/107] PCI: Add VPD function 0 quirk for Intel  Ethernet devices Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 016/107] net: Clone skb before setting peeked flag Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 026/107] x86/ldt: Further fix FPU emulation Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 029/107] sparc64: Fix userspace FPU register corruptions. Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 023/107] libiscsi: Fix host busy blocking during  connection teardown Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 019/107] x86/ldt: Correct LDT access in single  stepping logic Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 017/107] net: Fix skb_set_peeked use-after-free bug Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 005/107] crypto: ixp4xx - Remove bogus BUG_ON on  scattered dst buffer Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 033/107] PCI: Fix TI816X class code quirk Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 051/107] rtlwifi: rtl8192cu: Add new device ID Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 032/107] [media] rc-core: fix remove uevent generation Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 068/107] powerpc/MSI: Fix race condition in tearing  down MSI interrupts Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 037/107] usb: gadget: m66592-udc: forever loop in  set_feature() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 054/107] xfs: return errors from partial I/O failures  to files Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 103/107] ipv6: prevent fib6_run_gc() contention Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 044/107] serial: 8250: bind to ALi Fast Infrared  Controller (ALI5123) Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 070/107] hfs: fix B-tree corruption after insertion at  position 0 Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 050/107] rtlwifi: rtl8192cu: Add new device ID Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 048/107] xfs: Fix xfs_attr_leafblock definition Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 025/107] ipc,sem: fix use after free on IPC_RMID after  a task using same semaphore set exits Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 007/107] target/iscsi: Fix double free of a TUR  followed by a solicited NOPOUT Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
  [PATCH 3.2 081/107] usb: Use the USB_SS_MULT() macro to get the  burst multiplier. Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 079/107] s390/compat: correct uc_sigmask of the compat  signal frame Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 091/107] virtio-net: drop NETIF_F_FRAGLIST Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 053/107] drivercore: Fix unregistration path of  platform devices Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 006/107] USB: sierra: add 1199:68AB device ID Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 059/107] spi: spi-pxa2xx: Check status register to  determine if SSSR_TINT is disabled Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 002/107] pktgen: Require CONFIG_INET due to use of  IPv4 checksum function Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 085/107] cifs: use server timestamp for ntlmv2  authentication Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 066/107] ARM: 8429/1: disable GCC SRA optimization Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 061/107] Add radeon suspend/resume quirk for HP Compaq  dc5750. Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 046/107] USB: ftdi_sio: Added custom PID for  CustomWare products Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 013/107] perf: Fix fasync handling on inherited events Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 074/107] btrfs: skip waiting on ordered range for  special files Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 052/107] of/address: Don't loop forever in  of_find_matching_node_by_address(). Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 042/107] NFSv4: don't set SETATTR for O_RDONLY|O_EXCL Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 093/107] ipc/sem.c: fully initialize sem_array before  making it visible Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 039/107] auxdisplay: ks0108: fix refcount Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 083/107] usb: xhci: Clear XHCI_STATE_DYING on start Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 062/107] IB/uverbs: reject invalid or unknown opcodes Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 058/107] IB/uverbs: Fix race between ib_uverbs_open  and remove_one Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 102/107] perf tools: Fix build with perl 5.18 Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 075/107] ARM: 7880/1: Clear the IT state independent  of the Thumb-2 mode Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 105/107] parisc: Filter out spurious interrupts in  PA-RISC irq handler Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 100/107] net/ipv6: Correct PIM6 mrt_lock handling Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 030/107] dcache: Handle escaped paths in prepend_path Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 041/107] windfarm: decrement client count when  unregistering Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 076/107] ARM: fix Thumb2 signal handling when ARMv6 is  enabled Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 057/107] IB/mlx4: Use correct SL on AH query under RoCE Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 090/107] ipv6: addrconf: validate new MTU before  applying it Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 010/107] MIPS: Fix sched_getaffinity with MT FPAFF enabled Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
  [PATCH 3.2 063/107] Input: evdev - do not report errors form flush() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
  [PATCH 3.2 078/107] ASoC: fix broken pxa SoC support Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
  [PATCH 3.2 064/107] crypto: ghash-clmulni: specify context size  for ghash async algorithm Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
  [PATCH 3.2 065/107] fs: create and use seq_show_option for escaping Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
  [PATCH 3.2 084/107] xhci: change xhci 1.0 only restrictions to  support xhci 1.1 Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
  [PATCH 3.2 071/107] perf header: Fixup reading of HEADER_NRCPUS  feature Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
  [PATCH 3.2 104/107] ipv6: update ip6_rt_last_gc every time GC is run Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
  [PATCH 3.2 055/107] IB/qib: Change lkey table allocation to  support more MRs Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
  [PATCH 3.2 073/107] Btrfs: fix read corruption of compressed and  shared extents Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
  Re: [PATCH 3.2 000/107] 3.2.72-rc1 review Guenter Roeck <linux@roeck-us.net> - 2015-10-09 03:00 +0200
    Re: [PATCH 3.2 000/107] 3.2.72-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:20 +0200
  [PATCH 3.2 077/107] x86/platform: Fix Geode LX timekeeping in the  generic x86 build Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
  [PATCH 3.2 087/107] ocfs2/dlm: fix deadlock when dispatch assert  master Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
  [PATCH 3.2 056/107] SUNRPC: xs_reset_transport must mark the  connection as disconnected Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
  [PATCH 3.2 082/107] xhci: give command abortion one more chance  before killing xhci Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200

csiph-web