From: Zhu Yi <yi.zhu@intel.com>
To: linville@tuxdriver.com
Cc: linux-wireless@vger.kernel.org,
Tomas Winkler <tomas.winkler@intel.com>,
Ron Rindjunsky <ron.rindjunsky@intel.com>
Subject: [PATCH 36/43] mac80211: fix deadlock in sta->lock
Date: Thu, 29 May 2008 16:35:21 +0800 [thread overview]
Message-ID: <1212050128-17132-37-git-send-email-yi.zhu@intel.com> (raw)
In-Reply-To: <1212050128-17132-36-git-send-email-yi.zhu@intel.com>
From: Tomas Winkler <tomas.winkler@intel.com>
This patch fixes a deadlock of sta->lock use, occurring while changing
tx aggregation states, as dev_queue_xmit end up in new function
test_and_clear_sta_flags that uses that lock thus leading to deadlock.
Signed-off-by: Tomas Winkler <tomas.winkler@intel.com>
Signed-off-by: Ron Rindjunsky <ron.rindjunsky@intel.com>
---
net/mac80211/main.c | 30 +++++++++++++++++-------------
1 files changed, 17 insertions(+), 13 deletions(-)
diff --git a/net/mac80211/main.c b/net/mac80211/main.c
index e5e4a1d..4b57de4 100644
--- a/net/mac80211/main.c
+++ b/net/mac80211/main.c
@@ -589,8 +589,8 @@ int ieee80211_start_tx_ba_session(struct ieee80211_hw *hw, u8 *ra, u16 tid)
sta = sta_info_get(local, ra);
if (!sta) {
printk(KERN_DEBUG "Could not find the station\n");
- rcu_read_unlock();
- return -ENOENT;
+ ret = -ENOENT;
+ goto exit;
}
spin_lock_bh(&sta->lock);
@@ -598,7 +598,7 @@ int ieee80211_start_tx_ba_session(struct ieee80211_hw *hw, u8 *ra, u16 tid)
/* we have tried too many times, receiver does not want A-MPDU */
if (sta->ampdu_mlme.addba_req_num[tid] > HT_AGG_MAX_RETRIES) {
ret = -EBUSY;
- goto start_ba_exit;
+ goto err_unlock_sta;
}
state = &sta->ampdu_mlme.tid_state_tx[tid];
@@ -609,7 +609,7 @@ int ieee80211_start_tx_ba_session(struct ieee80211_hw *hw, u8 *ra, u16 tid)
"idle on tid %u\n", tid);
#endif /* CONFIG_MAC80211_HT_DEBUG */
ret = -EAGAIN;
- goto start_ba_exit;
+ goto err_unlock_sta;
}
/* prepare A-MPDU MLME for Tx aggregation */
@@ -620,7 +620,7 @@ int ieee80211_start_tx_ba_session(struct ieee80211_hw *hw, u8 *ra, u16 tid)
printk(KERN_ERR "allocate tx mlme to tid %d failed\n",
tid);
ret = -ENOMEM;
- goto start_ba_exit;
+ goto err_unlock_sta;
}
/* Tx timer */
sta->ampdu_mlme.tid_tx[tid]->addba_resp_timer.function =
@@ -643,7 +643,7 @@ int ieee80211_start_tx_ba_session(struct ieee80211_hw *hw, u8 *ra, u16 tid)
printk(KERN_DEBUG "BA request denied - queue unavailable for"
" tid %d\n", tid);
#endif /* CONFIG_MAC80211_HT_DEBUG */
- goto start_ba_err;
+ goto err_unlock_queue;
}
sdata = sta->sdata;
@@ -665,12 +665,13 @@ int ieee80211_start_tx_ba_session(struct ieee80211_hw *hw, u8 *ra, u16 tid)
" tid %d\n", tid);
#endif /* CONFIG_MAC80211_HT_DEBUG */
*state = HT_AGG_STATE_IDLE;
- goto start_ba_err;
+ goto err_unlock_queue;
}
/* Will put all the packets in the new SW queue */
ieee80211_requeue(local, ieee802_1d_to_ac[tid]);
spin_unlock_bh(&local->mdev->queue_lock);
+ spin_unlock_bh(&sta->lock);
/* send an addBA request */
sta->ampdu_mlme.dialog_token_allocator++;
@@ -678,25 +679,26 @@ int ieee80211_start_tx_ba_session(struct ieee80211_hw *hw, u8 *ra, u16 tid)
sta->ampdu_mlme.dialog_token_allocator;
sta->ampdu_mlme.tid_tx[tid]->ssn = start_seq_num;
+
ieee80211_send_addba_request(sta->sdata->dev, ra, tid,
sta->ampdu_mlme.tid_tx[tid]->dialog_token,
sta->ampdu_mlme.tid_tx[tid]->ssn,
0x40, 5000);
-
/* activate the timer for the recipient's addBA response */
sta->ampdu_mlme.tid_tx[tid]->addba_resp_timer.expires =
jiffies + ADDBA_RESP_INTERVAL;
add_timer(&sta->ampdu_mlme.tid_tx[tid]->addba_resp_timer);
printk(KERN_DEBUG "activated addBA response timer on tid %d\n", tid);
- goto start_ba_exit;
+ goto exit;
-start_ba_err:
+err_unlock_queue:
kfree(sta->ampdu_mlme.tid_tx[tid]);
sta->ampdu_mlme.tid_tx[tid] = NULL;
spin_unlock_bh(&local->mdev->queue_lock);
ret = -EBUSY;
-start_ba_exit:
+err_unlock_sta:
spin_unlock_bh(&sta->lock);
+exit:
rcu_read_unlock();
return ret;
}
@@ -835,10 +837,11 @@ void ieee80211_stop_tx_ba_cb(struct ieee80211_hw *hw, u8 *ra, u8 tid)
}
state = &sta->ampdu_mlme.tid_state_tx[tid];
- spin_lock_bh(&sta->lock);
+ /* NOTE: no need to use sta->lock in this state check, as
+ * ieee80211_stop_tx_ba_session will let only
+ * one stop call to pass through per sta/tid */
if ((*state & HT_AGG_STATE_REQ_STOP_BA_MSK) == 0) {
printk(KERN_DEBUG "unexpected callback to A-MPDU stop\n");
- spin_unlock_bh(&sta->lock);
rcu_read_unlock();
return;
}
@@ -861,6 +864,7 @@ void ieee80211_stop_tx_ba_cb(struct ieee80211_hw *hw, u8 *ra, u8 tid)
* ieee80211_wake_queue is not used here as this queue is not
* necessarily stopped */
netif_schedule(local->mdev);
+ spin_lock_bh(&sta->lock);
*state = HT_AGG_STATE_IDLE;
sta->ampdu_mlme.addba_req_num[tid] = 0;
kfree(sta->ampdu_mlme.tid_tx[tid]);
--
1.5.3.6
next prev parent reply other threads:[~2008-05-29 8:37 UTC|newest]
Thread overview: 50+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-05-29 8:34 [PATCH 00/43] iwlwifi driver 05/29 updates Zhu Yi
2008-05-29 8:34 ` [PATCH 01/43] iwlwifi: move iwl_dump_nic_error_log to iwlcore module Zhu Yi
2008-05-29 8:34 ` [PATCH 02/43] iwlwifi: add RTC data address for iwl5000 Zhu Yi
2008-05-29 8:34 ` [PATCH 03/43] iwlwifi: use uCode error and event tables pointer w.r.t loaded image Zhu Yi
2008-05-29 8:34 ` [PATCH 04/43] iwlwifi: increase max payload of iwl_cmd Zhu Yi
2008-05-29 8:34 ` [PATCH 05/43] iwlwifi: create drivers debugfs dir under wiphy->debugfsdir Zhu Yi
2008-05-29 8:34 ` [PATCH 06/43] iwlwifi: mark 4965 ucode types Zhu Yi
2008-05-29 8:34 ` [PATCH 07/43] iwlwifi: remove unused variable form __iwl4965_down Zhu Yi
2008-05-29 8:34 ` [PATCH 08/43] iwlwifi: remove notif_missed_beacons variable Zhu Yi
2008-05-29 8:34 ` [PATCH 09/43] iwlwifi: clean up alive_start routine Zhu Yi
2008-05-29 8:34 ` [PATCH 10/43] iwlwifi: remove 4965 from alive_resp structures Zhu Yi
2008-05-29 8:34 ` [PATCH 11/43] iwlwifi: setup correctly L1 L0S pi link values Zhu Yi
2008-05-29 8:34 ` [PATCH 12/43] iwlwifi: implement apm reset flow Zhu Yi
2008-05-29 8:34 ` [PATCH 13/43] iwlwifi: implement apm stop function Zhu Yi
2008-05-29 8:34 ` [PATCH 14/43] iwlwifi: refactor stop master function Zhu Yi
2008-05-29 8:35 ` [PATCH 15/43] iwlwifi: move txq_ctx_stop into iwl-tx.c Zhu Yi
2008-05-29 8:35 ` [PATCH 16/43] iwlwifi: move iwl_rxq_stop into iwl-rx.c Zhu Yi
2008-05-29 8:35 ` [PATCH 17/43] iwlwifi: add remove station functionality Zhu Yi
2008-05-29 8:35 ` [PATCH 18/43] iwlwifi: move add sta handler to iwl-sta.c Zhu Yi
2008-05-29 8:35 ` [PATCH 19/43] iwlwifi: move iwl_rx_missed_beacon_notif to iwl-rx.c Zhu Yi
2008-05-29 8:35 ` [PATCH 20/43] iwlwifi-5000: implement initial calibration for 5000 Zhu Yi
2008-05-29 8:35 ` [PATCH 21/43] iwlwifi: activate status ready timeout only for run time ucode Zhu Yi
2008-05-29 8:35 ` [PATCH 22/43] iwlwifi: add iwl5000_tx_response structure Zhu Yi
2008-05-29 8:35 ` [PATCH 23/43] iwlwifi: move tx response common handlers to iwlcore Zhu Yi
2008-05-29 8:35 ` [PATCH 24/43] iwlwlifi: impelemnt 5000 tx response path Zhu Yi
2008-05-29 8:35 ` [PATCH 25/43] iwlwifi: move 4965 tx response into iwl-4965.c Zhu Yi
2008-05-29 8:35 ` [PATCH 26/43] iwlwifi: fix in-column rate scaling Zhu Yi
2008-05-29 8:35 ` [PATCH 27/43] iwlwifi: move tx reclaim flow into iwl-tx Zhu Yi
2008-05-29 8:35 ` [PATCH 28/43] iwlwifi: implement txq invalidate byte count table Zhu Yi
2008-05-29 8:35 ` [PATCH 29/43] iwlwifi: iwl-5000 add rxon_assoc Zhu Yi
2008-05-29 8:35 ` [PATCH 30/43] iwlwifi: move iwl_sta_modify_enable_tid_tx to iwl-sta.c Zhu Yi
2008-05-29 8:35 ` [PATCH 31/43] iwlwifi: move aggregation code to iwl-tx.c Zhu Yi
2008-05-29 8:35 ` [PATCH 32/43] iwlwifi: add frame count limit to link quality command Zhu Yi
2008-05-29 8:35 ` [PATCH 33/43] iwlwifi: Rx handlers common use for 4965 and 5000 Zhu Yi
2008-05-29 8:35 ` [PATCH 34/43] iwlwifi: move iwl_get_hw_mode to iwl-core.h Zhu Yi
2008-05-29 8:35 ` [PATCH 35/43] mac80211: fix ieee80211_get_buffered_bc Zhu Yi
2008-05-29 8:35 ` Zhu Yi [this message]
2008-05-29 8:35 ` [PATCH 37/43] mac80211: sends HT IE to user level through wext Zhu Yi
2008-05-29 8:35 ` [PATCH 38/43] mac80211: allow disable FAT in specific configurations Zhu Yi
2008-05-29 8:35 ` [PATCH 39/43] iwlwifi: disable FAT channel when not permitted Zhu Yi
2008-05-29 8:35 ` [PATCH 40/43] iwlwifi: fix a memory leak in scan Zhu Yi
2008-05-29 8:35 ` [PATCH 41/43] iwlwifi: remove debugfs entries before cfg80211 Zhu Yi
2008-05-29 8:35 ` [PATCH 42/43] iwlwifi: send calibration results as HUGE commands Zhu Yi
2008-05-29 8:35 ` [PATCH 43/43] iwlwifi: clean iwl4965_mac_config Zhu Yi
2008-05-30 11:47 ` [PATCH 40/43] iwlwifi: fix a memory leak in scan Tomas Winkler
2008-05-29 9:37 ` [PATCH 38/43] mac80211: allow disable FAT in specific configurations Johannes Berg
2008-05-29 9:58 ` Tomas Winkler
2008-05-29 10:12 ` Johannes Berg
2008-05-29 10:39 ` Tomas Winkler
2008-05-29 10:49 ` Johannes Berg
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1212050128-17132-37-git-send-email-yi.zhu@intel.com \
--to=yi.zhu@intel.com \
--cc=linux-wireless@vger.kernel.org \
--cc=linville@tuxdriver.com \
--cc=ron.rindjunsky@intel.com \
--cc=tomas.winkler@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.