Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1545388

Re: nfc: trf7970a: Prevent repeated polling from crashing the kernel

Path csiph.com!1.us.feeder.erje.net!2.us.feeder.erje.net!feeder.erje.net!1.eu.feeder.erje.net!news.unit0.net!news.panservice.it!bofh.it!news.nic.it!robomod
From Justin Bronder <justin@kuvee.com>
Newsgroups linux.kernel
Subject Re: nfc: trf7970a: Prevent repeated polling from crashing the kernel
Date Tue, 20 Dec 2016 20:20:01 +0100
Message-ID <sQy77-1ef-29@gated-at.bofh.it> (permalink)
References <sQviW-7Qa-41@gated-at.bofh.it> <sQviW-7Qa-39@gated-at.bofh.it> <sQxXs-18O-23@gated-at.bofh.it>
X-Original-To Mark Greer <mgreer@animalcreek.com>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=kuvee-com.20150623.gappssmtp.com; s=20150623; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=d6rWgWo5kHbCsfNgJN+uWJ4n1CFPIjCtmaLtniFt65o=; b=iYxjd1gOTU72hZsbFM03oyoAegeLNHPqtx8UFw1Vr9kUjeqmvvEAgzx5QkNkxrc4U8 yhof4eLxdImAqgHqUtMGY0NXkbyT0qxy+jHwU8lfl2r7A9/cOp8dyhKWpWf5bZKEPg4+ 5TFr0/Q46/wg+DIo9kt50w856VNe2cXHPWKd8S+wG0Ooo/h73WglUrojryQgAxD52EPN DLRgbMxX1M7fdzufI+JbsVK0ra31YjtdotiU0NKPdSDBHScZLJFPbeS76cTuRz7Fxm7N zRyoiuGb8IiOlo0n3uf4TZAehDyKSf5yh2L0oo3hwXHiNrcbFkKdeZbQLptkv6MZASN3 p2WA==
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=d6rWgWo5kHbCsfNgJN+uWJ4n1CFPIjCtmaLtniFt65o=; b=t8m9W7qCEuaJTwjDb85vFE2J8QyO6PDE4juNKVRMzbvZ+NUMzaVuwVVBn90gmbgiiY mwwuvcvuCxLo/BIiLkARnwb13hS0bdP91J4xbHza9GZ+I5f9EARLno3M+/gUeWt9aB+S HlFiePmGoh8LOGO9ojcOV+KiYt6i9bZjJA9M51Jk4O2kcN/vO+z3ybjWBpYyZjXqr/pQ 0yqyVHd0ldiOyrteUkqUc+upbKtcE4Xs+zhZmZ44uVOG8r+y3W1nzASPaQILz/h534tp YBgPKUcLNWkeMPHOhUBD+m0vFY8BCQ0KdId0OZuKgh3nsIjRFgkimktnf/QE8XFU71dt UyYA==
X-Gm-Message-State AIkVDXKdQGVavEg2a73OaS36RI8D5ttjgMdLHr+H7jmDrXFvP/aGaXLJf1iWRJsoqHVmbA==
X-Received by 10.37.176.165 with SMTP id f37mr646732ybj.79.1482261233370; Tue, 20 Dec 2016 11:13:53 -0800 (PST)
MIME-Version 1.0
Content-Type text/plain; charset=us-ascii
Content-Disposition inline
User-Agent Mutt/1.5.24 (2015-08-30)
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 54
Organization linux.* mail to news gateway
X-Original-Cc Geoff Lansberry <geoff@kuvee.com>, linux-wireless@vger.kernel.org, lauro.venancio@openbossa.org, aloisio.almeida@openbossa.org, sameo@linux.intel.com, robh+dt@kernel.org, mark.rutland@arm.com, netdev@vger.kernel.org, devicetree@vger.kernel.org, linux-kernel@vger.kernel.org, Jaret Cantu <jaret.cantu@timesys.com>
X-Original-Date Tue, 20 Dec 2016 14:13:52 -0500
X-Original-Message-ID <20161220191352.GB23496@lasswell.members.linode.com>
X-Original-References <1482250592-4268-1-git-send-email-glansberry@gmail.com> <1482250592-4268-3-git-send-email-glansberry@gmail.com> <20161220185905.GA5867@animalcreek.com>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1545388

Show key headers only | View raw


On 20/12/16 11:59 -0700, Mark Greer wrote:
> On Tue, Dec 20, 2016 at 11:16:32AM -0500, Geoff Lansberry wrote:
> > From: Jaret Cantu <jaret.cantu@timesys.com>
> > 
> > Repeated polling attempts cause a NULL dereference error to occur.
> > This is because the state of the trf7970a is currently reading but
> > another request has been made to send a command before it has finished.
> 
> How is this happening?  Was trf7970a_abort_cmd() called and it didn't
> work right?  Was it not called at all and there is a bug in the digital
> layer?  More details please.
> 
> > The solution is to properly kill the waiting reading (workqueue)
> > before failing on the send.
> 
> If the bug is in the calling code, then that is what should get fixed.
> This seems to be a hack to work-around a digital layer bug.

One of our uses of NFC is to begin polling to read a tag and then stop polling
(in order to save power) until we know via user interaction that we need to poll
again.  This is typically many minutes later so the power saving is pretty
significant.  However, it's possible that a user will remove the tag before
reading has completed.  We also detect this case and stop polling.  I can go
more into this if necessary but that is what exposed a panic.

You can reproduce using neard and python, in our testing it was very likely to
occur in 10-100 iterations of the following.:

    #!/usr/bin/python
    import time

    import dbus

    bus = dbus.SystemBus()
    nfc0 = bus.get_object('org.neard', '/org/neard/nfc0')
    props = dbus.Interface(nfc0, 'org.freedesktop.DBus.Properties')

    try:
        props.Set('org.neard.Adapter', 'Powered', dbus.Boolean(1))
    except:
        pass

    adapter = dbus.Interface(nfc0, 'org.neard.Adapter')

    for i in range(1000):
        adapter.StartPollLoop('Initiator')
        time.sleep(0.1)
        adapter.StopPollLoop()
        print(i)

I believe the last time we tested this was around the 4.1 release.

-- 
Justin Bronder

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 3/3] nfc: trf7970a: Prevent repeated polling from crashing the kernel Geoff Lansberry <geoff@kuvee.com> - 2016-12-20 17:20 +0100
  Re: [PATCH 3/3] nfc: trf7970a: Prevent repeated polling from  crashing the kernel Mark Greer <mgreer@animalcreek.com> - 2016-12-20 20:10 +0100
    Re: nfc: trf7970a: Prevent repeated polling from crashing the kernel Justin Bronder <justin@kuvee.com> - 2016-12-20 20:20 +0100
      Re: nfc: trf7970a: Prevent repeated polling from crashing the kernel Mark Greer <mgreer@animalcreek.com> - 2016-12-20 21:00 +0100

csiph-web