Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1366660

[PATCH 3.2 15/62] xen/pcifront: Fix mysterious crashes when NUMA locality information was extracted.

From Ben Hutchings <ben@decadent.org.uk>
Newsgroups linux.kernel
Subject [PATCH 3.2 15/62] xen/pcifront: Fix mysterious crashes when NUMA locality information was extracted.
Date 2016-03-29 22:20 +0200
Message-ID <ri8hl-2Tk-65@gated-at.bofh.it> (permalink)
References <ri87D-2Ps-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


3.2.79-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>

commit 4d8c8bd6f2062c9988817183a91fe2e623c8aa5e upstream.

Occasionaly PV guests would crash with:

pciback 0000:00:00.1: Xen PCI mapped GSI0 to IRQ16
BUG: unable to handle kernel paging request at 0000000d1a8c0be0
.. snip..
  <ffffffff8139ce1b>] find_next_bit+0xb/0x10
  [<ffffffff81387f22>] cpumask_next_and+0x22/0x40
  [<ffffffff813c1ef8>] pci_device_probe+0xb8/0x120
  [<ffffffff81529097>] ? driver_sysfs_add+0x77/0xa0
  [<ffffffff815293e4>] driver_probe_device+0x1a4/0x2d0
  [<ffffffff813c1ddd>] ? pci_match_device+0xdd/0x110
  [<ffffffff81529657>] __device_attach_driver+0xa7/0xb0
  [<ffffffff815295b0>] ? __driver_attach+0xa0/0xa0
  [<ffffffff81527622>] bus_for_each_drv+0x62/0x90
  [<ffffffff8152978d>] __device_attach+0xbd/0x110
  [<ffffffff815297fb>] device_attach+0xb/0x10
  [<ffffffff813b75ac>] pci_bus_add_device+0x3c/0x70
  [<ffffffff813b7618>] pci_bus_add_devices+0x38/0x80
  [<ffffffff813dc34e>] pcifront_scan_root+0x13e/0x1a0
  [<ffffffff817a0692>] pcifront_backend_changed+0x262/0x60b
  [<ffffffff814644c6>] ? xenbus_gather+0xd6/0x160
  [<ffffffff8120900f>] ? put_object+0x2f/0x50
  [<ffffffff81465c1d>] xenbus_otherend_changed+0x9d/0xa0
  [<ffffffff814678ee>] backend_changed+0xe/0x10
  [<ffffffff81463a28>] xenwatch_thread+0xc8/0x190
  [<ffffffff810f22f0>] ? woken_wake_function+0x10/0x10

which was the result of two things:

When we call pci_scan_root_bus we would pass in 'sd' (sysdata)
pointer which was an 'pcifront_sd' structure. However in the
pci_device_add it expects that the 'sd' is 'struct sysdata' and
sets the dev->node to what is in sd->node (offset 4):

set_dev_node(&dev->dev, pcibus_to_node(bus));

 __pcibus_to_node(const struct pci_bus *bus)
{
        const struct pci_sysdata *sd = bus->sysdata;

        return sd->node;
}

However our structure was pcifront_sd which had nothing at that
offset:

struct pcifront_sd {
        int                        domain;    /*     0     4 */
        /* XXX 4 bytes hole, try to pack */
        struct pcifront_device *   pdev;      /*     8     8 */
}

That is an hole - filled with garbage as we used kmalloc instead of
kzalloc (the second problem).

This patch fixes the issue by:
 1) Use kzalloc to initialize to a well known state.
 2) Put 'struct pci_sysdata' at the start of 'pcifront_sd'. That
    way access to the 'node' will access the right offset.

Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Reviewed-by: Boris Ostrovsky <boris.ostrovsky@oracle.com>
Signed-off-by: David Vrabel <david.vrabel@citrix.com>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 drivers/pci/xen-pcifront.c | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

--- a/drivers/pci/xen-pcifront.c
+++ b/drivers/pci/xen-pcifront.c
@@ -50,7 +50,7 @@ struct pcifront_device {
 };
 
 struct pcifront_sd {
-	int domain;
+	struct pci_sysdata sd;
 	struct pcifront_device *pdev;
 };
 
@@ -64,7 +64,9 @@ static inline void pcifront_init_sd(stru
 				    unsigned int domain, unsigned int bus,
 				    struct pcifront_device *pdev)
 {
-	sd->domain = domain;
+	/* Because we do not expose that information via XenBus. */
+	sd->sd.node = first_online_node;
+	sd->sd.domain = domain;
 	sd->pdev = pdev;
 }
 
@@ -461,8 +463,8 @@ static int __devinit pcifront_scan_root(
 	dev_info(&pdev->xdev->dev, "Creating PCI Frontend Bus %04x:%02x\n",
 		 domain, bus);
 
-	bus_entry = kmalloc(sizeof(*bus_entry), GFP_KERNEL);
-	sd = kmalloc(sizeof(*sd), GFP_KERNEL);
+	bus_entry = kzalloc(sizeof(*bus_entry), GFP_KERNEL);
+	sd = kzalloc(sizeof(*sd), GFP_KERNEL);
 	if (!bus_entry || !sd) {
 		err = -ENOMEM;
 		goto err_out;

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 3.2 00/62] 3.2.79-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
  [PATCH 3.2 27/62] USB: option: add support for SIM7100E Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
  [PATCH 3.2 13/62] xen/pciback: Check PF instead of VF for  PCI_COMMAND_MEMORY Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
  [PATCH 3.2 12/62] libata: fix HDIO_GET_32BIT ioctl Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
  [PATCH 3.2 52/62] ALSA: seq: oss: Don't drain at closing a client Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
  [PATCH 3.2 41/62] ipr: Fix out-of-bounds null overwrite Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
  [PATCH 3.2 20/62] af_unix: Don't set err in unix_stream_read_generic  unless there was an error Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
  [PATCH 3.2 21/62] af_unix: Guard against other == sk in  unix_dgram_sendmsg Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
  [PATCH 3.2 35/62] sunrpc/cache: fix off-by-one in qword_get() Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
  [PATCH 3.2 42/62] ipr: Fix regression when loading firmware Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
  [PATCH 3.2 15/62] xen/pcifront: Fix mysterious crashes when NUMA  locality information was extracted. Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
  [PATCH 3.2 50/62] ASoC: wm8994: Fix enum ctl accesses in a wrong type Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
  [PATCH 3.2 49/62] ASoC: wm8958: Fix enum ctl accesses in a wrong type Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:20 +0200
  [PATCH 3.2 57/62] ubi: Fix out of bounds write in volume update code Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 03/62] iommu/vt-d: Fix 64-bit accesses to 32-bit  DMAR_GSTS_REG Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 45/62] ALSA: timer: Fix broken compat timer user  status ioctl Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 05/62] cfg80211/wext: fix message ordering Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 14/62] xen/pciback: Save the number of MSI-X entries  to be copied later. Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 18/62] tracing: Fix freak link error caused by branch  tracer Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 16/62] ALSA: seq: Fix leak of pool buffer at  concurrent writes Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 62/62] HID: usbhid: fix recursive deadlock Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 08/62] drm/i915: fix error path in intel_setup_gmbus() Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 19/62] ALSA: seq: Fix double port list deletion Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 58/62] Revert "drm/radeon: call hpd_irq_event on resume" Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 10/62] s390/dasd: prevent incorrect length error under  z/VM after PAV changes Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 07/62] nfs: fix nfs_size_to_loff_t Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 04/62] wext: fix message delay/ordering Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 06/62] mac80211: fix use of uninitialised values in RX  aggregation Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 46/62] ALSA: hdspm: Fix wrong boolean ctl value accesses Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 01/62] Revert "crypto: algif_skcipher - Do not  dereference ctx without socket lock" Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  [PATCH 3.2 17/62] tracepoints: Do not trace when cpu is offline Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200
  Re: [PATCH 3.2 00/62] 3.2.79-rc1 review Guenter Roeck <linux@roeck-us.net> - 2016-03-29 22:30 +0200
    Re: [PATCH 3.2 00/62] 3.2.79-rc1 review Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 23:10 +0200
  [PATCH 3.2 02/62] crypto: {blk,giv}cipher: Set has_setkey Ben Hutchings <ben@decadent.org.uk> - 2016-03-29 22:30 +0200

csiph-web