From: Jeff Garzik <jeff@garzik.org>
To: Alexander Sabourenkov <screwdriver@lxnt.info>
Cc: Alan Cox <alan@lxorguk.ukuu.org.uk>,
linux-ide@vger.kernel.org, Tejun Heo <htejun@gmail.com>,
MisterE <MisterE2002@zonnet.nl>,
benh@kernel.crashing.org, jgarzik@pobox.com
Subject: Re: [PATCH-RFC] Promise TX4 implement hw-bug workaround
Date: Sun, 28 Oct 2007 04:21:11 -0400 [thread overview]
Message-ID: <47244677.6030909@garzik.org> (raw)
In-Reply-To: <47238104.4000601@lxnt.info>
Alexander Sabourenkov wrote:
> Alan Cox wrote:
>>> I can't think of a way to avoid second pass over scatterlist without
>>> duplicating code (ata_qc_prep() and ata_fill_sg() from libata-core.c).
>> This appears to be incomplete:
>>
>
> [...]
>
>> What guarantees you have enough PRD entries to do this without changing
>> the limit in the structures ?
>>
>> Otherwise looks good
>
> PRD entries count is 256
> include/linux/ata.h:
> ATA_MAX_PRD = 256,
> ATA_PRD_TBL_SZ = (ATA_MAX_PRD * ATA_PRD_SZ),
>
> drivers/ata/libata-core.c:
> ap->prd = dmam_alloc_coherent(dev, ATA_PRD_TBL_SZ, &ap->prd_dma,
>
> sata_promise Scsi_Host declares support for half of that:
>
> include/linux/libata.h:
> LIBATA_MAX_PRD = ATA_MAX_PRD / 2,
>
> drivers/ata/sata_promise.c
> .sg_tablesize = LIBATA_MAX_PRD,
Alan's point was that the existing code will give you up to
LIBATA_MAX_PRD entries. After the post-virtual-merge splitting code in
ata_fill_sg() executes, the worst case result is ATA_MAX_PRD entries.
Thus, since your code has the potential to increase the number of s/g
entries above that, it can potentially corrupt memory, lock up the
machine, all the wonderful things that can happen when you run off the
end of the s/g list.
The fix is to decrease .sg_tablesize (LIBATA_MAX_PRD - 2 perhaps?) so
that you guarantee this worst case never occurs, by guaranteeing that
the system never sends you enough s/g entries to cause your code to go
out of bounds.
Jeff
next prev parent reply other threads:[~2007-10-28 8:21 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-10-03 7:26 Re[2]: Sata Sil3512 bug? Mikael Pettersson
2007-10-03 8:31 ` Alexander Sabourenkov
2007-10-03 14:45 ` Re[2]: " MisterE
2007-10-03 14:50 ` Alan Cox
2007-10-14 12:07 ` Re[2]: " MisterE
2007-10-15 8:44 ` Alexander Sabourenkov
2007-10-17 12:39 ` Re[2]: Sata Sil3512 bug?; Promise SATA300 TX4 MisterE
2007-10-17 12:54 ` Alexander Sabourenkov
2007-10-17 15:04 ` Re[2]: " MisterE
2007-10-17 19:21 ` Peter Favrholdt
2007-10-19 12:02 ` Re[2]: " MisterE
2007-10-18 21:07 ` Alexander Sabourenkov
2007-10-19 1:26 ` Tejun Heo
2007-10-19 21:06 ` Alexander Sabourenkov
2007-10-19 22:58 ` Re[2]: " MisterE
2007-10-19 23:58 ` Tejun Heo
2007-10-20 21:50 ` Alexander Sabourenkov
2007-10-27 13:24 ` [PATCH-RFC] (was: Re: Sata Sil3512 bug?; Promise SATA300 TX4) Alexander Sabourenkov
2007-10-27 13:44 ` [PATCH-RFC] Alexander Sabourenkov
2007-10-27 14:08 ` Re[2]: [PATCH-RFC] MisterE
2007-10-27 15:09 ` [PATCH-RFC] Alexander Sabourenkov
2007-10-27 15:16 ` [PATCH-RFC] Promise TX4 implement hw-bug workaround Alexander Sabourenkov
2007-10-27 18:09 ` Alan Cox
2007-10-27 18:18 ` Alexander Sabourenkov
2007-10-27 18:37 ` Alexander Sabourenkov
2007-10-28 8:21 ` Jeff Garzik [this message]
2007-10-28 20:03 ` Alexander Sabourenkov
2007-10-28 10:29 ` Jeff Garzik
2007-10-28 11:52 ` Alexander Sabourenkov
2007-10-28 11:10 ` Jeff Garzik
-- strict thread matches above, loose matches on Subject: below --
2007-10-28 11:03 Mikael Pettersson
2007-10-28 16:32 Mikael Pettersson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=47244677.6030909@garzik.org \
--to=jeff@garzik.org \
--cc=MisterE2002@zonnet.nl \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=benh@kernel.crashing.org \
--cc=htejun@gmail.com \
--cc=jgarzik@pobox.com \
--cc=linux-ide@vger.kernel.org \
--cc=screwdriver@lxnt.info \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.