Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1242908
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 3.2 068/107] powerpc/MSI: Fix race condition in tearing down MSI interrupts |
| Date | 2015-10-09 02:40 +0200 |
| Message-ID | <qhtT5-2Qh-45@gated-at.bofh.it> (permalink) |
| References | <qhtzH-2tg-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
3.2.72-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Paul Mackerras <paulus@ozlabs.org>
commit e297c939b745e420ef0b9dc989cb87bda617b399 upstream.
This fixes a race which can result in the same virtual IRQ number
being assigned to two different MSI interrupts. The most visible
consequence of that is usually a warning and stack trace from the
sysfs code about an attempt to create a duplicate entry in sysfs.
The race happens when one CPU (say CPU 0) is disposing of an MSI
while another CPU (say CPU 1) is setting up an MSI. CPU 0 calls
(for example) pnv_teardown_msi_irqs(), which calls
msi_bitmap_free_hwirqs() to indicate that the MSI (i.e. its
hardware IRQ number) is no longer in use. Then, before CPU 0 gets
to calling irq_dispose_mapping() to free up the virtal IRQ number,
CPU 1 comes in and calls msi_bitmap_alloc_hwirqs() to allocate an
MSI, and gets the same hardware IRQ number that CPU 0 just freed.
CPU 1 then calls irq_create_mapping() to get a virtual IRQ number,
which sees that there is currently a mapping for that hardware IRQ
number and returns the corresponding virtual IRQ number (which is
the same virtual IRQ number that CPU 0 was using). CPU 0 then
calls irq_dispose_mapping() and frees that virtual IRQ number.
Now, if another CPU comes along and calls irq_create_mapping(), it
is likely to get the virtual IRQ number that was just freed,
resulting in the same virtual IRQ number apparently being used for
two different hardware interrupts.
To fix this race, we just move the call to msi_bitmap_free_hwirqs()
to after the call to irq_dispose_mapping(). Since virq_to_hw()
doesn't work for the virtual IRQ number after irq_dispose_mapping()
has been called, we need to call it before irq_dispose_mapping() and
remember the result for the msi_bitmap_free_hwirqs() call.
The pattern of calling msi_bitmap_free_hwirqs() before
irq_dispose_mapping() appears in 5 places under arch/powerpc, and
appears to have originated in commit 05af7bd2d75e ("[POWERPC] MPIC
U3/U4 MSI backend") from 2007.
Fixes: 05af7bd2d75e ("[POWERPC] MPIC U3/U4 MSI backend")
Reported-by: Alexey Kardashevskiy <aik@ozlabs.ru>
Signed-off-by: Paul Mackerras <paulus@samba.org>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
[bwh: Backported to 3.2:
- powernv uses a private functions instead of msi_bitmap_free_hwirqs()
- Adjust filename, context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
arch/powerpc/platforms/powernv/pci.c | 5 +++--
arch/powerpc/sysdev/fsl_msi.c | 5 +++--
arch/powerpc/sysdev/mpic_pasemi_msi.c | 5 +++--
arch/powerpc/sysdev/mpic_u3msi.c | 5 +++--
arch/powerpc/sysdev/ppc4xx_msi.c | 5 +++--
5 files changed, 15 insertions(+), 10 deletions(-)
--- a/arch/powerpc/platforms/powernv/pci.c
+++ b/arch/powerpc/platforms/powernv/pci.c
@@ -130,6 +130,7 @@ static void pnv_teardown_msi_irqs(struct
struct pci_controller *hose = pci_bus_to_host(pdev->bus);
struct pnv_phb *phb = hose->private_data;
struct msi_desc *entry;
+ irq_hw_number_t hwirq;
if (WARN_ON(!phb))
return;
@@ -137,9 +138,10 @@ static void pnv_teardown_msi_irqs(struct
list_for_each_entry(entry, &pdev->msi_list, list) {
if (entry->irq == NO_IRQ)
continue;
+ hwirq = virq_to_hw(entry->irq);
irq_set_msi_desc(entry->irq, NULL);
- pnv_put_msi(phb, virq_to_hw(entry->irq));
irq_dispose_mapping(entry->irq);
+ pnv_put_msi(phb, hwirq);
}
}
#endif /* CONFIG_PCI_MSI */
--- a/arch/powerpc/sysdev/fsl_msi.c
+++ b/arch/powerpc/sysdev/fsl_msi.c
@@ -106,15 +106,16 @@ static void fsl_teardown_msi_irqs(struct
{
struct msi_desc *entry;
struct fsl_msi *msi_data;
+ irq_hw_number_t hwirq;
list_for_each_entry(entry, &pdev->msi_list, list) {
if (entry->irq == NO_IRQ)
continue;
+ hwirq = virq_to_hw(entry->irq);
msi_data = irq_get_chip_data(entry->irq);
irq_set_msi_desc(entry->irq, NULL);
- msi_bitmap_free_hwirqs(&msi_data->bitmap,
- virq_to_hw(entry->irq), 1);
irq_dispose_mapping(entry->irq);
+ msi_bitmap_free_hwirqs(&msi_data->bitmap, hwirq, 1);
}
return;
--- a/arch/powerpc/sysdev/mpic_pasemi_msi.c
+++ b/arch/powerpc/sysdev/mpic_pasemi_msi.c
@@ -74,6 +74,7 @@ static int pasemi_msi_check_device(struc
static void pasemi_msi_teardown_msi_irqs(struct pci_dev *pdev)
{
struct msi_desc *entry;
+ irq_hw_number_t hwirq;
pr_debug("pasemi_msi_teardown_msi_irqs, pdev %p\n", pdev);
@@ -81,10 +82,10 @@ static void pasemi_msi_teardown_msi_irqs
if (entry->irq == NO_IRQ)
continue;
+ hwirq = virq_to_hw(entry->irq);
irq_set_msi_desc(entry->irq, NULL);
- msi_bitmap_free_hwirqs(&msi_mpic->msi_bitmap,
- virq_to_hw(entry->irq), ALLOC_CHUNK);
irq_dispose_mapping(entry->irq);
+ msi_bitmap_free_hwirqs(&msi_mpic->msi_bitmap, hwirq, ALLOC_CHUNK);
}
return;
--- a/arch/powerpc/sysdev/mpic_u3msi.c
+++ b/arch/powerpc/sysdev/mpic_u3msi.c
@@ -124,15 +124,16 @@ static int u3msi_msi_check_device(struct
static void u3msi_teardown_msi_irqs(struct pci_dev *pdev)
{
struct msi_desc *entry;
+ irq_hw_number_t hwirq;
list_for_each_entry(entry, &pdev->msi_list, list) {
if (entry->irq == NO_IRQ)
continue;
+ hwirq = virq_to_hw(entry->irq);
irq_set_msi_desc(entry->irq, NULL);
- msi_bitmap_free_hwirqs(&msi_mpic->msi_bitmap,
- virq_to_hw(entry->irq), 1);
irq_dispose_mapping(entry->irq);
+ msi_bitmap_free_hwirqs(&msi_mpic->msi_bitmap, hwirq, 1);
}
return;
--- a/arch/powerpc/sysdev/ppc4xx_msi.c
+++ b/arch/powerpc/sysdev/ppc4xx_msi.c
@@ -114,16 +114,17 @@ void ppc4xx_teardown_msi_irqs(struct pci
{
struct msi_desc *entry;
struct ppc4xx_msi *msi_data = &ppc4xx_msi;
+ irq_hw_number_t hwirq;
dev_dbg(&dev->dev, "PCIE-MSI: tearing down msi irqs\n");
list_for_each_entry(entry, &dev->msi_list, list) {
if (entry->irq == NO_IRQ)
continue;
+ hwirq = virq_to_hw(entry->irq);
irq_set_msi_desc(entry->irq, NULL);
- msi_bitmap_free_hwirqs(&msi_data->bitmap,
- virq_to_hw(entry->irq), 1);
irq_dispose_mapping(entry->irq);
+ msi_bitmap_free_hwirqs(&msi_data->bitmap, hwirq, 1);
}
}
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 3.2 000/107] 3.2.72-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
[PATCH 3.2 072/107] USB: option: add ZTE PIDs Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
[PATCH 3.2 069/107] hfs,hfsplus: cache pages correctly between bnode_create and bnode_free Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
[PATCH 3.2 015/107] ocfs2: fix BUG in ocfs2_downconvert_thread_do_work() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
[PATCH 3.2 049/107] DRM - radeon: Don't link train DisplayPort on HPD until we get the dpcd Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
[PATCH 3.2 098/107] ipv6: lock socket in ip6_datagram_connect() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
[PATCH 3.2 024/107] libfc: Fix fc_fcp_cleanup_each_cmd() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:30 +0200
[PATCH 3.2 094/107] Initialize msg/shm IPC objects before doing ipc_addid() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 060/107] drm/i915: Always mark the object as dirty when used by the GPU Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 047/107] eCryptfs: Invalidate dcache entries when lower i_nlink is zero Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 009/107] target: REPORT LUNS should return LUN 0 even for dynamic ACLs Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 095/107] net/tipc: initialize security state for new connection socket Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 018/107] x86/ldt: Make modify_ldt synchronous Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 036/107] PCI: Add VPD function 0 quirk for Intel Ethernet devices Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 016/107] net: Clone skb before setting peeked flag Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 026/107] x86/ldt: Further fix FPU emulation Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 029/107] sparc64: Fix userspace FPU register corruptions. Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 023/107] libiscsi: Fix host busy blocking during connection teardown Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 019/107] x86/ldt: Correct LDT access in single stepping logic Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 017/107] net: Fix skb_set_peeked use-after-free bug Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 005/107] crypto: ixp4xx - Remove bogus BUG_ON on scattered dst buffer Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 033/107] PCI: Fix TI816X class code quirk Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 051/107] rtlwifi: rtl8192cu: Add new device ID Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 032/107] [media] rc-core: fix remove uevent generation Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 068/107] powerpc/MSI: Fix race condition in tearing down MSI interrupts Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 037/107] usb: gadget: m66592-udc: forever loop in set_feature() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 054/107] xfs: return errors from partial I/O failures to files Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 103/107] ipv6: prevent fib6_run_gc() contention Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 044/107] serial: 8250: bind to ALi Fast Infrared Controller (ALI5123) Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 070/107] hfs: fix B-tree corruption after insertion at position 0 Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 050/107] rtlwifi: rtl8192cu: Add new device ID Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 048/107] xfs: Fix xfs_attr_leafblock definition Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 025/107] ipc,sem: fix use after free on IPC_RMID after a task using same semaphore set exits Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 007/107] target/iscsi: Fix double free of a TUR followed by a solicited NOPOUT Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:40 +0200
[PATCH 3.2 081/107] usb: Use the USB_SS_MULT() macro to get the burst multiplier. Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 079/107] s390/compat: correct uc_sigmask of the compat signal frame Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 091/107] virtio-net: drop NETIF_F_FRAGLIST Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 053/107] drivercore: Fix unregistration path of platform devices Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 006/107] USB: sierra: add 1199:68AB device ID Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 059/107] spi: spi-pxa2xx: Check status register to determine if SSSR_TINT is disabled Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 002/107] pktgen: Require CONFIG_INET due to use of IPv4 checksum function Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 085/107] cifs: use server timestamp for ntlmv2 authentication Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 066/107] ARM: 8429/1: disable GCC SRA optimization Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 061/107] Add radeon suspend/resume quirk for HP Compaq dc5750. Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 046/107] USB: ftdi_sio: Added custom PID for CustomWare products Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 013/107] perf: Fix fasync handling on inherited events Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 074/107] btrfs: skip waiting on ordered range for special files Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 052/107] of/address: Don't loop forever in of_find_matching_node_by_address(). Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 042/107] NFSv4: don't set SETATTR for O_RDONLY|O_EXCL Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 093/107] ipc/sem.c: fully initialize sem_array before making it visible Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 039/107] auxdisplay: ks0108: fix refcount Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 083/107] usb: xhci: Clear XHCI_STATE_DYING on start Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 062/107] IB/uverbs: reject invalid or unknown opcodes Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 058/107] IB/uverbs: Fix race between ib_uverbs_open and remove_one Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 102/107] perf tools: Fix build with perl 5.18 Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 075/107] ARM: 7880/1: Clear the IT state independent of the Thumb-2 mode Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 105/107] parisc: Filter out spurious interrupts in PA-RISC irq handler Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 100/107] net/ipv6: Correct PIM6 mrt_lock handling Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 030/107] dcache: Handle escaped paths in prepend_path Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 041/107] windfarm: decrement client count when unregistering Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 076/107] ARM: fix Thumb2 signal handling when ARMv6 is enabled Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 057/107] IB/mlx4: Use correct SL on AH query under RoCE Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 090/107] ipv6: addrconf: validate new MTU before applying it Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 010/107] MIPS: Fix sched_getaffinity with MT FPAFF enabled Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 02:50 +0200
[PATCH 3.2 063/107] Input: evdev - do not report errors form flush() Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
[PATCH 3.2 078/107] ASoC: fix broken pxa SoC support Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
[PATCH 3.2 064/107] crypto: ghash-clmulni: specify context size for ghash async algorithm Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
[PATCH 3.2 065/107] fs: create and use seq_show_option for escaping Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
[PATCH 3.2 084/107] xhci: change xhci 1.0 only restrictions to support xhci 1.1 Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
[PATCH 3.2 071/107] perf header: Fixup reading of HEADER_NRCPUS feature Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
[PATCH 3.2 104/107] ipv6: update ip6_rt_last_gc every time GC is run Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
[PATCH 3.2 055/107] IB/qib: Change lkey table allocation to support more MRs Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
[PATCH 3.2 073/107] Btrfs: fix read corruption of compressed and shared extents Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
Re: [PATCH 3.2 000/107] 3.2.72-rc1 review Guenter Roeck <linux@roeck-us.net> - 2015-10-09 03:00 +0200
Re: [PATCH 3.2 000/107] 3.2.72-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:20 +0200
[PATCH 3.2 077/107] x86/platform: Fix Geode LX timekeeping in the generic x86 build Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
[PATCH 3.2 087/107] ocfs2/dlm: fix deadlock when dispatch assert master Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
[PATCH 3.2 056/107] SUNRPC: xs_reset_transport must mark the connection as disconnected Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
[PATCH 3.2 082/107] xhci: give command abortion one more chance before killing xhci Ben Hutchings <ben@decadent.org.uk> - 2015-10-09 03:00 +0200
csiph-web