* Re: DPAA2 triggers, [PATCH] dma debug: report -EEXIST errors in add_dma_entry
[not found] ` <20210914154504.z6vqxuh3byqwgfzx@skbuf>
@ 2021-09-30 13:37 ` Karsten Graul
2021-10-01 12:52 ` Gerald Schaefer
0 siblings, 1 reply; 9+ messages in thread
From: Karsten Graul @ 2021-09-30 13:37 UTC (permalink / raw)
To: Ioana Ciornei, Jeremy Linton
Cc: Hamza Mahfooz, linux-kernel@vger.kernel.org, Christoph Hellwig,
Marek Szyprowski, Robin Murphy, iommu@lists.linux-foundation.org,
Dan Williams, netdev@vger.kernel.org, Gerald Schaefer, linux-s390
On 14/09/2021 17:45, Ioana Ciornei wrote:
> On Wed, Sep 08, 2021 at 10:33:26PM -0500, Jeremy Linton wrote:
>> +DPAA2, netdev maintainers
>> Hi,
>>
>> On 5/18/21 7:54 AM, Hamza Mahfooz wrote:
>>> Since, overlapping mappings are not supported by the DMA API we should
>>> report an error if active_cacheline_insert returns -EEXIST.
>>
>> It seems this patch found a victim. I was trying to run iperf3 on a
>> honeycomb (5.14.0, fedora 35) and the console is blasting this error message
>> at 100% cpu. So, I changed it to a WARN_ONCE() to get the call trace, which
>> is attached below.
>>
>
> These frags are allocated by the stack, transformed into a scatterlist
> by skb_to_sgvec and then DMA mapped with dma_map_sg. It was not the
> dpaa2-eth's decision to use two fragments from the same page (that will
> also end un in the same cacheline) in two different in-flight skbs.
>
> Is this behavior normal?
>
We see the same problem here and it started with 5.15-rc2 in our nightly CI runs.
The CI has panic_on_warn enabled so we see the panic every day now.
Its always the same pattern: module SMC calls dma_map_sg_attrs() which ends
up in the EEXIST warning sooner or later.
It would be better to revert this patch now and start to better understand the
checking logic for overlapping areas.
Thank you.
The call trace for reference:
[ 864.189864] DMA-API: mlx5_core 0662:00:00.0: cacheline tracking EEXIST, overlapping mappings aren't supported
[ 864.189883] WARNING: CPU: 0 PID: 33720 at kernel/dma/debug.c:570 add_dma_entry+0x208/0x2c8
...
[ 864.190747] CPU: 0 PID: 33720 Comm: smcapp Not tainted 5.15.0-20210928.rc3.git0.a59bf04db7bb.300.fc34.s390x+debug #1
[ 864.190758] Hardware name: IBM 8561 T01 701 (z/VM 7.2.0)
[ 864.190766] Krnl PSW : 0704d00180000000 00000000fa6239fc (add_dma_entry+0x20c/0x2c8)
[ 864.190783] R:0 T:1 IO:1 EX:1 Key:0 M:1 W:0 P:0 AS:3 CC:1 PM:0 RI:0 EA:3
[ 864.190795] Krnl GPRS: c0000000ffffbfff 0000000080000000 0000000000000061 0000000000000000
[ 864.190804] 0000000000000001 0000000000000001 0000000000000001 0000000000000001
[ 864.190813] 0700000000000001 000000000020ff00 00000000ffffffff 000000008137b300
[ 864.190822] 0000000020020100 0000000000000001 00000000fa6239f8 00000380074536f8
[ 864.190837] Krnl Code: 00000000fa6239ec: c020007a4964 larl %r2,00000000fb56ccb4
00000000fa6239f2: c0e5005ef2ff brasl %r14,00000000fb201ff0
#00000000fa6239f8: af000000 mc 0,0
>00000000fa6239fc: ecb60057007c cgij %r11,0,6,00000000fa623aaa
00000000fa623a02: c01000866149 larl %r1,00000000fb6efc94
00000000fa623a08: e31010000012 lt %r1,0(%r1)
00000000fa623a0e: a774ff73 brc 7,00000000fa6238f4
00000000fa623a12: c010008a9227 larl %r1,00000000fb775e60
[ 864.202949] Call Trace:
[ 864.202959] [<00000000fa6239fc>] add_dma_entry+0x20c/0x2c8
[ 864.202971] ([<00000000fa6239f8>] add_dma_entry+0x208/0x2c8)
[ 864.202981] [<00000000fa624988>] debug_dma_map_sg+0x140/0x160
[ 864.202992] [<00000000fa61eadc>] __dma_map_sg_attrs+0x9c/0xd8
[ 864.203002] [<00000000fa61eb3a>] dma_map_sg_attrs+0x22/0x40
[ 864.203012] [<000003ff80483bde>] smc_ib_buf_map_sg+0x5e/0x90 [smc]
[ 864.203036] [<000003ff80486b44>] smcr_buf_map_link.part.0+0x12c/0x1e8 [smc]
[ 864.203053] [<000003ff80486cb6>] _smcr_buf_map_lgr+0xb6/0xf8 [smc]
[ 864.203071] [<000003ff8048b91c>] smcr_buf_map_lgr+0x4c/0x90 [smc]
[ 864.211496] [<000003ff80490ac2>] smc_llc_cli_add_link+0x152/0x420 [smc]
[ 864.211522] [<000003ff8047acbc>] smcr_clnt_conf_first_link+0x124/0x1e0 [smc]
[ 864.211537] [<000003ff8047bfb2>] smc_connect_rdma+0x25a/0x2e8 [smc]
[ 864.211551] [<000003ff8047da4a>] __smc_connect+0x38a/0x650 [smc]
[ 864.211566] [<000003ff8047de70>] smc_connect+0x160/0x190 [smc]
[ 864.211580] [<00000000faf10c70>] __sys_connect+0x98/0xd0
[ 864.211592] [<00000000faf12e9a>] __do_sys_socketcall+0x16a/0x350
[ 864.211603] [<00000000fb216752>] __do_syscall+0x1c2/0x1f0
[ 864.211616] [<00000000fb229148>] system_call+0x78/0xa0
--
Karsten
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: DPAA2 triggers, [PATCH] dma debug: report -EEXIST errors in add_dma_entry
2021-09-30 13:37 ` DPAA2 triggers, [PATCH] dma debug: report -EEXIST errors in add_dma_entry Karsten Graul
@ 2021-10-01 12:52 ` Gerald Schaefer
2021-10-06 13:10 ` Gerald Schaefer
0 siblings, 1 reply; 9+ messages in thread
From: Gerald Schaefer @ 2021-10-01 12:52 UTC (permalink / raw)
To: Karsten Graul
Cc: Ioana Ciornei, Jeremy Linton, Hamza Mahfooz,
linux-kernel@vger.kernel.org, Christoph Hellwig, Marek Szyprowski,
Robin Murphy, iommu@lists.linux-foundation.org, Dan Williams,
netdev@vger.kernel.org, linux-s390, Gerald Schaefer
On Thu, 30 Sep 2021 15:37:33 +0200
Karsten Graul <kgraul@linux.ibm.com> wrote:
> On 14/09/2021 17:45, Ioana Ciornei wrote:
> > On Wed, Sep 08, 2021 at 10:33:26PM -0500, Jeremy Linton wrote:
> >> +DPAA2, netdev maintainers
> >> Hi,
> >>
> >> On 5/18/21 7:54 AM, Hamza Mahfooz wrote:
> >>> Since, overlapping mappings are not supported by the DMA API we should
> >>> report an error if active_cacheline_insert returns -EEXIST.
> >>
> >> It seems this patch found a victim. I was trying to run iperf3 on a
> >> honeycomb (5.14.0, fedora 35) and the console is blasting this error message
> >> at 100% cpu. So, I changed it to a WARN_ONCE() to get the call trace, which
> >> is attached below.
> >>
> >
> > These frags are allocated by the stack, transformed into a scatterlist
> > by skb_to_sgvec and then DMA mapped with dma_map_sg. It was not the
> > dpaa2-eth's decision to use two fragments from the same page (that will
> > also end un in the same cacheline) in two different in-flight skbs.
> >
> > Is this behavior normal?
> >
>
> We see the same problem here and it started with 5.15-rc2 in our nightly CI runs.
> The CI has panic_on_warn enabled so we see the panic every day now.
Adding a WARN for a case that be detected false-positive seems not
acceptable, exactly for this reason (kernel panic on unaffected
systems).
So I guess it boils down to the question if the behavior that Ioana
described is legit behavior, on a system that is dma coherent. We
are apparently hitting the same scenario, although it could not yet be
reproduced with debug printks for some reason.
If the answer is yes, than please remove at lease the WARN, so that
it will not make systems crash that behave valid, and have
panic_on_warn set. Even a normal printk feels wrong to me in that
case, it really sounds rather like you want to fix / better refine
the overlap check, if you want to report anything here.
BTW, there is already a WARN in the add_dma_entry() path, related
to cachlline overlap and -EEXIST:
add_dma_entry() -> active_cacheline_insert() -> -EEXIST ->
active_cacheline_inc_overlap()
That will only trigger when "overlap > ACTIVE_CACHELINE_MAX_OVERLAP".
Not familiar with that code, but it seems that there are now two
warnings for more or less the same, and the new warning is much more
prone to false-positives.
How do these 2 warnings relate, are they both really necessary?
I think the new warning was only introduced because of some old
TODO comment in add_dma_entry(), see commit 2b4bbc6231d78
("dma-debug: report -EEXIST errors in add_dma_entry").
That comment was initially added by Dan long time ago, and he
added several fix-ups for overlap detection after that, including
the "overlap > ACTIVE_CACHELINE_MAX_OVERLAP" stuff in
active_cacheline_inc_overlap(). So could it be that the TODO
comment was simply not valid any more, and better be removed
instead of adding new / double warnings, that also generate
false-positives and kernel crashes?
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: DPAA2 triggers, [PATCH] dma debug: report -EEXIST errors in add_dma_entry
2021-10-01 12:52 ` Gerald Schaefer
@ 2021-10-06 13:10 ` Gerald Schaefer
2021-10-06 13:21 ` Gerald Schaefer
2021-10-06 14:23 ` Robin Murphy
0 siblings, 2 replies; 9+ messages in thread
From: Gerald Schaefer @ 2021-10-06 13:10 UTC (permalink / raw)
To: Hamza Mahfooz, Christoph Hellwig, Dan Williams
Cc: Karsten Graul, Ioana Ciornei, Jeremy Linton,
linux-kernel@vger.kernel.org, Marek Szyprowski, Robin Murphy,
iommu@lists.linux-foundation.org, netdev@vger.kernel.org,
linux-s390
On Fri, 1 Oct 2021 14:52:56 +0200
Gerald Schaefer <gerald.schaefer@linux.ibm.com> wrote:
> On Thu, 30 Sep 2021 15:37:33 +0200
> Karsten Graul <kgraul@linux.ibm.com> wrote:
>
> > On 14/09/2021 17:45, Ioana Ciornei wrote:
> > > On Wed, Sep 08, 2021 at 10:33:26PM -0500, Jeremy Linton wrote:
> > >> +DPAA2, netdev maintainers
> > >> Hi,
> > >>
> > >> On 5/18/21 7:54 AM, Hamza Mahfooz wrote:
> > >>> Since, overlapping mappings are not supported by the DMA API we should
> > >>> report an error if active_cacheline_insert returns -EEXIST.
> > >>
> > >> It seems this patch found a victim. I was trying to run iperf3 on a
> > >> honeycomb (5.14.0, fedora 35) and the console is blasting this error message
> > >> at 100% cpu. So, I changed it to a WARN_ONCE() to get the call trace, which
> > >> is attached below.
> > >>
> > >
> > > These frags are allocated by the stack, transformed into a scatterlist
> > > by skb_to_sgvec and then DMA mapped with dma_map_sg. It was not the
> > > dpaa2-eth's decision to use two fragments from the same page (that will
> > > also end un in the same cacheline) in two different in-flight skbs.
> > >
> > > Is this behavior normal?
> > >
> >
> > We see the same problem here and it started with 5.15-rc2 in our nightly CI runs.
> > The CI has panic_on_warn enabled so we see the panic every day now.
>
> Adding a WARN for a case that be detected false-positive seems not
> acceptable, exactly for this reason (kernel panic on unaffected
> systems).
>
> So I guess it boils down to the question if the behavior that Ioana
> described is legit behavior, on a system that is dma coherent. We
> are apparently hitting the same scenario, although it could not yet be
> reproduced with debug printks for some reason.
>
> If the answer is yes, than please remove at lease the WARN, so that
> it will not make systems crash that behave valid, and have
> panic_on_warn set. Even a normal printk feels wrong to me in that
> case, it really sounds rather like you want to fix / better refine
> the overlap check, if you want to report anything here.
Dan, Christoph, any opinion?
So far it all looks a lot like a false positive, so could you please
see that those patches get reverted? I do wonder a bit why this is
not an issue for others, we surely cannot be the only ones running
CI with panic_on_warn.
We would need to disable DEBUG_DMA if this WARN stays in, which
would be a shame. Of course, in theory, this might also indicate
some real bug, but there really is no sign of that so far.
Having multiple sg elements in the same page (or cacheline) is
valid, correct? And this is also not a decision of the driver
IIUC, so if it was bug, it should be addressed in common code,
correct?
>
> BTW, there is already a WARN in the add_dma_entry() path, related
> to cachlline overlap and -EEXIST:
>
> add_dma_entry() -> active_cacheline_insert() -> -EEXIST ->
> active_cacheline_inc_overlap()
>
> That will only trigger when "overlap > ACTIVE_CACHELINE_MAX_OVERLAP".
> Not familiar with that code, but it seems that there are now two
> warnings for more or less the same, and the new warning is much more
> prone to false-positives.
>
> How do these 2 warnings relate, are they both really necessary?
> I think the new warning was only introduced because of some old
> TODO comment in add_dma_entry(), see commit 2b4bbc6231d78
> ("dma-debug: report -EEXIST errors in add_dma_entry").
>
> That comment was initially added by Dan long time ago, and he
> added several fix-ups for overlap detection after that, including
> the "overlap > ACTIVE_CACHELINE_MAX_OVERLAP" stuff in
> active_cacheline_inc_overlap(). So could it be that the TODO
> comment was simply not valid any more, and better be removed
> instead of adding new / double warnings, that also generate
> false-positives and kernel crashes?
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: DPAA2 triggers, [PATCH] dma debug: report -EEXIST errors in add_dma_entry
2021-10-06 13:10 ` Gerald Schaefer
@ 2021-10-06 13:21 ` Gerald Schaefer
2021-10-06 14:23 ` Robin Murphy
1 sibling, 0 replies; 9+ messages in thread
From: Gerald Schaefer @ 2021-10-06 13:21 UTC (permalink / raw)
To: Hamza Mahfooz, Christoph Hellwig, Dan Williams
Cc: Karsten Graul, Ioana Ciornei, Jeremy Linton,
linux-kernel@vger.kernel.org, Marek Szyprowski, Robin Murphy,
iommu@lists.linux-foundation.org, netdev@vger.kernel.org,
linux-s390
On Wed, 6 Oct 2021 15:10:43 +0200
Gerald Schaefer <gerald.schaefer@linux.ibm.com> wrote:
> On Fri, 1 Oct 2021 14:52:56 +0200
> Gerald Schaefer <gerald.schaefer@linux.ibm.com> wrote:
>
> > On Thu, 30 Sep 2021 15:37:33 +0200
> > Karsten Graul <kgraul@linux.ibm.com> wrote:
> >
> > > On 14/09/2021 17:45, Ioana Ciornei wrote:
> > > > On Wed, Sep 08, 2021 at 10:33:26PM -0500, Jeremy Linton wrote:
> > > >> +DPAA2, netdev maintainers
> > > >> Hi,
> > > >>
> > > >> On 5/18/21 7:54 AM, Hamza Mahfooz wrote:
> > > >>> Since, overlapping mappings are not supported by the DMA API we should
> > > >>> report an error if active_cacheline_insert returns -EEXIST.
> > > >>
> > > >> It seems this patch found a victim. I was trying to run iperf3 on a
> > > >> honeycomb (5.14.0, fedora 35) and the console is blasting this error message
> > > >> at 100% cpu. So, I changed it to a WARN_ONCE() to get the call trace, which
> > > >> is attached below.
> > > >>
> > > >
> > > > These frags are allocated by the stack, transformed into a scatterlist
> > > > by skb_to_sgvec and then DMA mapped with dma_map_sg. It was not the
> > > > dpaa2-eth's decision to use two fragments from the same page (that will
> > > > also end un in the same cacheline) in two different in-flight skbs.
> > > >
> > > > Is this behavior normal?
> > > >
> > >
> > > We see the same problem here and it started with 5.15-rc2 in our nightly CI runs.
> > > The CI has panic_on_warn enabled so we see the panic every day now.
> >
> > Adding a WARN for a case that be detected false-positive seems not
> > acceptable, exactly for this reason (kernel panic on unaffected
> > systems).
> >
> > So I guess it boils down to the question if the behavior that Ioana
> > described is legit behavior, on a system that is dma coherent. We
> > are apparently hitting the same scenario, although it could not yet be
> > reproduced with debug printks for some reason.
> >
> > If the answer is yes, than please remove at lease the WARN, so that
> > it will not make systems crash that behave valid, and have
> > panic_on_warn set. Even a normal printk feels wrong to me in that
> > case, it really sounds rather like you want to fix / better refine
> > the overlap check, if you want to report anything here.
>
> Dan, Christoph, any opinion?
>
> So far it all looks a lot like a false positive, so could you please
> see that those patches get reverted? I do wonder a bit why this is
> not an issue for others, we surely cannot be the only ones running
> CI with panic_on_warn.
For reference, we are talking about these commits:
2b4bbc6231d7 ("dma-debug: report -EEXIST errors in add_dma_entry")
510e1a724ab1 ("dma-debug: prevent an error message from causing runtime problems")
The latter introduced the WARN (through err_printk usage), and should
be reverted if it can be false-positive, but both seem wrong in that
case.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: DPAA2 triggers, [PATCH] dma debug: report -EEXIST errors in add_dma_entry
2021-10-06 13:10 ` Gerald Schaefer
2021-10-06 13:21 ` Gerald Schaefer
@ 2021-10-06 14:23 ` Robin Murphy
2021-10-06 15:06 ` Gerald Schaefer
2021-10-07 10:59 ` Karsten Graul
1 sibling, 2 replies; 9+ messages in thread
From: Robin Murphy @ 2021-10-06 14:23 UTC (permalink / raw)
To: Gerald Schaefer, Hamza Mahfooz, Christoph Hellwig, Dan Williams
Cc: Karsten Graul, Ioana Ciornei, Jeremy Linton,
linux-kernel@vger.kernel.org, Marek Szyprowski,
iommu@lists.linux-foundation.org, netdev@vger.kernel.org,
linux-s390
On 2021-10-06 14:10, Gerald Schaefer wrote:
> On Fri, 1 Oct 2021 14:52:56 +0200
> Gerald Schaefer <gerald.schaefer@linux.ibm.com> wrote:
>
>> On Thu, 30 Sep 2021 15:37:33 +0200
>> Karsten Graul <kgraul@linux.ibm.com> wrote:
>>
>>> On 14/09/2021 17:45, Ioana Ciornei wrote:
>>>> On Wed, Sep 08, 2021 at 10:33:26PM -0500, Jeremy Linton wrote:
>>>>> +DPAA2, netdev maintainers
>>>>> Hi,
>>>>>
>>>>> On 5/18/21 7:54 AM, Hamza Mahfooz wrote:
>>>>>> Since, overlapping mappings are not supported by the DMA API we should
>>>>>> report an error if active_cacheline_insert returns -EEXIST.
>>>>>
>>>>> It seems this patch found a victim. I was trying to run iperf3 on a
>>>>> honeycomb (5.14.0, fedora 35) and the console is blasting this error message
>>>>> at 100% cpu. So, I changed it to a WARN_ONCE() to get the call trace, which
>>>>> is attached below.
>>>>>
>>>>
>>>> These frags are allocated by the stack, transformed into a scatterlist
>>>> by skb_to_sgvec and then DMA mapped with dma_map_sg. It was not the
>>>> dpaa2-eth's decision to use two fragments from the same page (that will
>>>> also end un in the same cacheline) in two different in-flight skbs.
>>>>
>>>> Is this behavior normal?
>>>>
>>>
>>> We see the same problem here and it started with 5.15-rc2 in our nightly CI runs.
>>> The CI has panic_on_warn enabled so we see the panic every day now.
>>
>> Adding a WARN for a case that be detected false-positive seems not
>> acceptable, exactly for this reason (kernel panic on unaffected
>> systems).
>>
>> So I guess it boils down to the question if the behavior that Ioana
>> described is legit behavior, on a system that is dma coherent. We
>> are apparently hitting the same scenario, although it could not yet be
>> reproduced with debug printks for some reason.
>>
>> If the answer is yes, than please remove at lease the WARN, so that
>> it will not make systems crash that behave valid, and have
>> panic_on_warn set. Even a normal printk feels wrong to me in that
>> case, it really sounds rather like you want to fix / better refine
>> the overlap check, if you want to report anything here.
>
> Dan, Christoph, any opinion?
>
> So far it all looks a lot like a false positive, so could you please
> see that those patches get reverted? I do wonder a bit why this is
> not an issue for others, we surely cannot be the only ones running
> CI with panic_on_warn.
What convinces you it's a false-positive? I'm hardly familiar with most
of that callstack, but it appears to be related to mlx5, and I know that
exists on expansion cards which could be plugged into a system with
non-coherent PCIe where partial cacheline overlap *would* be a real
issue. Of course it's dubious that there are many real use-cases for
plugging a NIC with a 4-figure price tag into a little i.MX8 or
whatever, but the point is that it *should* still work correctly.
> We would need to disable DEBUG_DMA if this WARN stays in, which
> would be a shame. Of course, in theory, this might also indicate
> some real bug, but there really is no sign of that so far.
The whole point of DMA debug is to flag up things that you *do* get away
with on the vast majority of systems, precisely because most testing
happens on those systems rather than more esoteric embedded setups. Say
your system only uses dma-direct and a driver starts triggering the
warning for not calling dma_mapping_error(), would you argue for
removing that warning as well since dma_map_single() can't fail on your
machine so it's "not a bug"?
> Having multiple sg elements in the same page (or cacheline) is
> valid, correct? And this is also not a decision of the driver
> IIUC, so if it was bug, it should be addressed in common code,
> correct?
According to the streaming DMA API documentation, it is *not* valid:
".. warning::
Memory coherency operates at a granularity called the cache
line width. In order for memory mapped by this API to operate
correctly, the mapped region must begin exactly on a cache line
boundary and end exactly on one (to prevent two separately mapped
regions from sharing a single cache line). Since the cache line size
may not be known at compile time, the API will not enforce this
requirement. Therefore, it is recommended that driver writers who
don't take special care to determine the cache line size at run time
only map virtual regions that begin and end on page boundaries (which
are guaranteed also to be cache line boundaries)."
>> BTW, there is already a WARN in the add_dma_entry() path, related
>> to cachlline overlap and -EEXIST:
>>
>> add_dma_entry() -> active_cacheline_insert() -> -EEXIST ->
>> active_cacheline_inc_overlap()
>>
>> That will only trigger when "overlap > ACTIVE_CACHELINE_MAX_OVERLAP".
>> Not familiar with that code, but it seems that there are now two
>> warnings for more or less the same, and the new warning is much more
>> prone to false-positives.
>>
>> How do these 2 warnings relate, are they both really necessary?
>> I think the new warning was only introduced because of some old
>> TODO comment in add_dma_entry(), see commit 2b4bbc6231d78
>> ("dma-debug: report -EEXIST errors in add_dma_entry").
AFAICS they are different things. I believe the new warning is supposed
to be for the fundementally incorrect API usage (as above) of mapping
different regions overlapping within the same cacheline. The existing
one is about dma-debug losing internal consistency when tracking the
*same* region being mapped multiple times, which is a legal thing to do
- e.g. buffer sharing between devices - but if anyone's doing it to
excess that's almost certainly a bug (i.e. they probably intended to
unmap it in between but missed that out).
Robin.
>> That comment was initially added by Dan long time ago, and he
>> added several fix-ups for overlap detection after that, including
>> the "overlap > ACTIVE_CACHELINE_MAX_OVERLAP" stuff in
>> active_cacheline_inc_overlap(). So could it be that the TODO
>> comment was simply not valid any more, and better be removed
>> instead of adding new / double warnings, that also generate
>> false-positives and kernel crashes?
>
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: DPAA2 triggers, [PATCH] dma debug: report -EEXIST errors in add_dma_entry
2021-10-06 14:23 ` Robin Murphy
@ 2021-10-06 15:06 ` Gerald Schaefer
2021-10-07 10:59 ` Karsten Graul
1 sibling, 0 replies; 9+ messages in thread
From: Gerald Schaefer @ 2021-10-06 15:06 UTC (permalink / raw)
To: Robin Murphy
Cc: Hamza Mahfooz, Christoph Hellwig, Dan Williams, Karsten Graul,
Ioana Ciornei, Jeremy Linton, linux-kernel@vger.kernel.org,
Marek Szyprowski, iommu@lists.linux-foundation.org,
netdev@vger.kernel.org, linux-s390, linux-rdma
On Wed, 6 Oct 2021 15:23:36 +0100
Robin Murphy <robin.murphy@arm.com> wrote:
> On 2021-10-06 14:10, Gerald Schaefer wrote:
> > On Fri, 1 Oct 2021 14:52:56 +0200
> > Gerald Schaefer <gerald.schaefer@linux.ibm.com> wrote:
> >
> >> On Thu, 30 Sep 2021 15:37:33 +0200
> >> Karsten Graul <kgraul@linux.ibm.com> wrote:
> >>
> >>> On 14/09/2021 17:45, Ioana Ciornei wrote:
> >>>> On Wed, Sep 08, 2021 at 10:33:26PM -0500, Jeremy Linton wrote:
> >>>>> +DPAA2, netdev maintainers
> >>>>> Hi,
> >>>>>
> >>>>> On 5/18/21 7:54 AM, Hamza Mahfooz wrote:
> >>>>>> Since, overlapping mappings are not supported by the DMA API we should
> >>>>>> report an error if active_cacheline_insert returns -EEXIST.
> >>>>>
> >>>>> It seems this patch found a victim. I was trying to run iperf3 on a
> >>>>> honeycomb (5.14.0, fedora 35) and the console is blasting this error message
> >>>>> at 100% cpu. So, I changed it to a WARN_ONCE() to get the call trace, which
> >>>>> is attached below.
> >>>>>
> >>>>
> >>>> These frags are allocated by the stack, transformed into a scatterlist
> >>>> by skb_to_sgvec and then DMA mapped with dma_map_sg. It was not the
> >>>> dpaa2-eth's decision to use two fragments from the same page (that will
> >>>> also end un in the same cacheline) in two different in-flight skbs.
> >>>>
> >>>> Is this behavior normal?
> >>>>
> >>>
> >>> We see the same problem here and it started with 5.15-rc2 in our nightly CI runs.
> >>> The CI has panic_on_warn enabled so we see the panic every day now.
> >>
> >> Adding a WARN for a case that be detected false-positive seems not
> >> acceptable, exactly for this reason (kernel panic on unaffected
> >> systems).
> >>
> >> So I guess it boils down to the question if the behavior that Ioana
> >> described is legit behavior, on a system that is dma coherent. We
> >> are apparently hitting the same scenario, although it could not yet be
> >> reproduced with debug printks for some reason.
> >>
> >> If the answer is yes, than please remove at lease the WARN, so that
> >> it will not make systems crash that behave valid, and have
> >> panic_on_warn set. Even a normal printk feels wrong to me in that
> >> case, it really sounds rather like you want to fix / better refine
> >> the overlap check, if you want to report anything here.
> >
> > Dan, Christoph, any opinion?
> >
> > So far it all looks a lot like a false positive, so could you please
> > see that those patches get reverted? I do wonder a bit why this is
> > not an issue for others, we surely cannot be the only ones running
> > CI with panic_on_warn.
>
> What convinces you it's a false-positive? I'm hardly familiar with most
> of that callstack, but it appears to be related to mlx5, and I know that
> exists on expansion cards which could be plugged into a system with
> non-coherent PCIe where partial cacheline overlap *would* be a real
> issue. Of course it's dubious that there are many real use-cases for
> plugging a NIC with a 4-figure price tag into a little i.MX8 or
> whatever, but the point is that it *should* still work correctly.
I would assume that a *proper* warning would check if we see the
"non-coherent" case, e.g. by using dev_is_dma_coherent() and only
report with potentially fatal WARN on systems where it is appropriate.
However, I am certainly even less familiar with all that, and might
just have gotten the wrong impression here.
Also not sure about mlx5 relation here, it does not really show
in the call trace, only in the err_printk() output, probably
from dev_driver_string(dev) or dev_name(dev). But I do not see
where mlx5 code would be involved here.
[...]
> According to the streaming DMA API documentation, it is *not* valid:
>
> ".. warning::
>
> Memory coherency operates at a granularity called the cache
> line width. In order for memory mapped by this API to operate
> correctly, the mapped region must begin exactly on a cache line
> boundary and end exactly on one (to prevent two separately mapped
> regions from sharing a single cache line). Since the cache line size
> may not be known at compile time, the API will not enforce this
> requirement. Therefore, it is recommended that driver writers who
> don't take special care to determine the cache line size at run time
> only map virtual regions that begin and end on page boundaries (which
> are guaranteed also to be cache line boundaries)."
Thanks, but I cannot really make a lot of sense out if this. Which
driver exactly would be the one that needs to take care of the
cache line alignment for sg elements? If this WARN is really reporting
a bug, could you please help pointing to where it would need to be
addressed?
And does this really say that it is illegal to have multiple sg elements
within the same cache line, regardless of cache coherence?
Adding linux-rdma@vger.kernel.org, sorry for the noise, but maybe somebody
on that list can make more sense of this.
For reference, the link to the start of this thread:
https://lkml.kernel.org/r/fd67fbac-64bf-f0ea-01e1-5938ccfab9d0@arm.com
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: DPAA2 triggers, [PATCH] dma debug: report -EEXIST errors in add_dma_entry
2021-10-06 14:23 ` Robin Murphy
2021-10-06 15:06 ` Gerald Schaefer
@ 2021-10-07 10:59 ` Karsten Graul
2021-10-07 16:40 ` Gerald Schaefer
2021-10-11 11:47 ` Christoph Hellwig
1 sibling, 2 replies; 9+ messages in thread
From: Karsten Graul @ 2021-10-07 10:59 UTC (permalink / raw)
To: Robin Murphy, Gerald Schaefer, Hamza Mahfooz, Christoph Hellwig,
Dan Williams
Cc: Ioana Ciornei, Jeremy Linton, linux-kernel@vger.kernel.org,
Marek Szyprowski, iommu@lists.linux-foundation.org,
netdev@vger.kernel.org, linux-s390
On 06/10/2021 16:23, Robin Murphy wrote:
> On 2021-10-06 14:10, Gerald Schaefer wrote:
>> On Fri, 1 Oct 2021 14:52:56 +0200
>> Gerald Schaefer <gerald.schaefer@linux.ibm.com> wrote:
>>
>>> On Thu, 30 Sep 2021 15:37:33 +0200
>>> Karsten Graul <kgraul@linux.ibm.com> wrote:
>>>
>>>> On 14/09/2021 17:45, Ioana Ciornei wrote:
>>>>> On Wed, Sep 08, 2021 at 10:33:26PM -0500, Jeremy Linton wrote:
>>>>>> +DPAA2, netdev maintainers
>>>>>> Hi,
>>>>>>
>>>>>> On 5/18/21 7:54 AM, Hamza Mahfooz wrote:
>>>>>>> Since, overlapping mappings are not supported by the DMA API we should
>>>>>>> report an error if active_cacheline_insert returns -EEXIST.
>>>>>>
>>>>>> It seems this patch found a victim. I was trying to run iperf3 on a
>>>>>> honeycomb (5.14.0, fedora 35) and the console is blasting this error message
>>>>>> at 100% cpu. So, I changed it to a WARN_ONCE() to get the call trace, which
>>>>>> is attached below.
>>>>>>
>>>>>
>>>>> These frags are allocated by the stack, transformed into a scatterlist
>>>>> by skb_to_sgvec and then DMA mapped with dma_map_sg. It was not the
>>>>> dpaa2-eth's decision to use two fragments from the same page (that will
>>>>> also end un in the same cacheline) in two different in-flight skbs.
>>>>>
>>>>> Is this behavior normal?
>>>>>
>>>>
>>>> We see the same problem here and it started with 5.15-rc2 in our nightly CI runs.
>>>> The CI has panic_on_warn enabled so we see the panic every day now.
>>>
>>> Adding a WARN for a case that be detected false-positive seems not
>>> acceptable, exactly for this reason (kernel panic on unaffected
>>> systems).
>>>
>>> So I guess it boils down to the question if the behavior that Ioana
>>> described is legit behavior, on a system that is dma coherent. We
>>> are apparently hitting the same scenario, although it could not yet be
>>> reproduced with debug printks for some reason.
>>>
>>> If the answer is yes, than please remove at lease the WARN, so that
>>> it will not make systems crash that behave valid, and have
>>> panic_on_warn set. Even a normal printk feels wrong to me in that
>>> case, it really sounds rather like you want to fix / better refine
>>> the overlap check, if you want to report anything here.
>>
>> Dan, Christoph, any opinion?
>>
>> So far it all looks a lot like a false positive, so could you please
>> see that those patches get reverted? I do wonder a bit why this is
>> not an issue for others, we surely cannot be the only ones running
>> CI with panic_on_warn.
>
> What convinces you it's a false-positive? I'm hardly familiar with most of that callstack, but it appears to be related to mlx5, and I know that exists on expansion cards which could be plugged into a system with non-coherent PCIe where partial cacheline overlap *would* be a real issue. Of course it's dubious that there are many real use-cases for plugging a NIC with a 4-figure price tag into a little i.MX8 or whatever, but the point is that it *should* still work correctly.
>
>> We would need to disable DEBUG_DMA if this WARN stays in, which
>> would be a shame. Of course, in theory, this might also indicate
>> some real bug, but there really is no sign of that so far.
>
> The whole point of DMA debug is to flag up things that you *do* get away with on the vast majority of systems, precisely because most testing happens on those systems rather than more esoteric embedded setups. Say your system only uses dma-direct and a driver starts triggering the warning for not calling dma_mapping_error(), would you argue for removing that warning as well since dma_map_single() can't fail on your machine so it's "not a bug"?
>
>> Having multiple sg elements in the same page (or cacheline) is
>> valid, correct? And this is also not a decision of the driver
>> IIUC, so if it was bug, it should be addressed in common code,
>> correct?
>
> According to the streaming DMA API documentation, it is *not* valid:
>
> ".. warning::
>
> Memory coherency operates at a granularity called the cache
> line width. In order for memory mapped by this API to operate
> correctly, the mapped region must begin exactly on a cache line
> boundary and end exactly on one (to prevent two separately mapped
> regions from sharing a single cache line). Since the cache line size
> may not be known at compile time, the API will not enforce this
> requirement. Therefore, it is recommended that driver writers who
> don't take special care to determine the cache line size at run time
> only map virtual regions that begin and end on page boundaries (which
> are guaranteed also to be cache line boundaries)."
>
>>> BTW, there is already a WARN in the add_dma_entry() path, related
>>> to cachlline overlap and -EEXIST:
>>>
>>> add_dma_entry() -> active_cacheline_insert() -> -EEXIST ->
>>> active_cacheline_inc_overlap()
>>>
>>> That will only trigger when "overlap > ACTIVE_CACHELINE_MAX_OVERLAP".
>>> Not familiar with that code, but it seems that there are now two
>>> warnings for more or less the same, and the new warning is much more
>>> prone to false-positives.
>>>
>>> How do these 2 warnings relate, are they both really necessary?
>>> I think the new warning was only introduced because of some old
>>> TODO comment in add_dma_entry(), see commit 2b4bbc6231d78
>>> ("dma-debug: report -EEXIST errors in add_dma_entry").
>
> AFAICS they are different things. I believe the new warning is supposed to be for the fundementally incorrect API usage (as above) of mapping different regions overlapping within the same cacheline. The existing one is about dma-debug losing internal consistency when tracking the *same* region being mapped multiple times, which is a legal thing to do - e.g. buffer sharing between devices - but if anyone's doing it to excess that's almost certainly a bug (i.e. they probably intended to unmap it in between but missed that out).
Thanks for the explanation Robin.
In our case its really that a buffer is mapped twice for 2 different devices which we use in SMC to provide failover capabilities. We see that -EEXIST is returned when a buffer is mapped for the second device. Since there is a maximum of 2 parallel mappings we never see the warning shown by active_cacheline_inc_overlap() because we don't exceed ACTIVE_CACHELINE_MAX_OVERLAP.
So how to deal with this kind of "legal thing", looks like there is no way to suppress the newly introduced EEXIST warning for that case?
Karsten
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: DPAA2 triggers, [PATCH] dma debug: report -EEXIST errors in add_dma_entry
2021-10-07 10:59 ` Karsten Graul
@ 2021-10-07 16:40 ` Gerald Schaefer
2021-10-11 11:47 ` Christoph Hellwig
1 sibling, 0 replies; 9+ messages in thread
From: Gerald Schaefer @ 2021-10-07 16:40 UTC (permalink / raw)
To: Karsten Graul
Cc: Robin Murphy, Hamza Mahfooz, Christoph Hellwig, Dan Williams,
Ioana Ciornei, Jeremy Linton, linux-kernel@vger.kernel.org,
Marek Szyprowski, iommu@lists.linux-foundation.org,
netdev@vger.kernel.org, linux-s390
On Thu, 7 Oct 2021 12:59:32 +0200
Karsten Graul <kgraul@linux.ibm.com> wrote:
[...]
> >
> >>> BTW, there is already a WARN in the add_dma_entry() path, related
> >>> to cachlline overlap and -EEXIST:
> >>>
> >>> add_dma_entry() -> active_cacheline_insert() -> -EEXIST ->
> >>> active_cacheline_inc_overlap()
> >>>
> >>> That will only trigger when "overlap > ACTIVE_CACHELINE_MAX_OVERLAP".
> >>> Not familiar with that code, but it seems that there are now two
> >>> warnings for more or less the same, and the new warning is much more
> >>> prone to false-positives.
> >>>
> >>> How do these 2 warnings relate, are they both really necessary?
> >>> I think the new warning was only introduced because of some old
> >>> TODO comment in add_dma_entry(), see commit 2b4bbc6231d78
> >>> ("dma-debug: report -EEXIST errors in add_dma_entry").
> >
> > AFAICS they are different things. I believe the new warning is supposed to be for the fundementally incorrect API usage (as above) of mapping different regions overlapping within the same cacheline. The existing one is about dma-debug losing internal consistency when tracking the *same* region being mapped multiple times, which is a legal thing to do - e.g. buffer sharing between devices - but if anyone's doing it to excess that's almost certainly a bug (i.e. they probably intended to unmap it in between but missed that out).
>
> Thanks for the explanation Robin.
>
> In our case its really that a buffer is mapped twice for 2 different devices which we use in SMC to provide failover capabilities. We see that -EEXIST is returned when a buffer is mapped for the second device. Since there is a maximum of 2 parallel mappings we never see the warning shown by active_cacheline_inc_overlap() because we don't exceed ACTIVE_CACHELINE_MAX_OVERLAP.
>
> So how to deal with this kind of "legal thing", looks like there is no way to suppress the newly introduced EEXIST warning for that case?
Thanks Karsten, very interesting. We assumed so far that we hit the
same case as Ioana, i.e. having multiple sg elements in one cacheline.
With debug output it now seems that we hit a completely different
case, not at all related to any cacheline or coherency issues.
So it really seems that the new warning is basically the same
as the already present one, with the difference that it already
triggers on the first occurrence. Looking at the code again, it
also seems rather obvious now...
IIUC, from what Robin described, this means that the "legal thing
to do - e.g. buffer sharing between devices" will now immediately
trigger the new warning? Not sure if I missed something (again),
because then I would expect much more reports on this, and of
course it would then obviously be false-positive.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: DPAA2 triggers, [PATCH] dma debug: report -EEXIST errors in add_dma_entry
2021-10-07 10:59 ` Karsten Graul
2021-10-07 16:40 ` Gerald Schaefer
@ 2021-10-11 11:47 ` Christoph Hellwig
1 sibling, 0 replies; 9+ messages in thread
From: Christoph Hellwig @ 2021-10-11 11:47 UTC (permalink / raw)
To: Karsten Graul
Cc: Robin Murphy, Gerald Schaefer, Hamza Mahfooz, Christoph Hellwig,
Dan Williams, Ioana Ciornei, Jeremy Linton,
linux-kernel@vger.kernel.org, Marek Szyprowski,
iommu@lists.linux-foundation.org, netdev@vger.kernel.org,
linux-s390
On Thu, Oct 07, 2021 at 12:59:32PM +0200, Karsten Graul wrote:
> In our case its really that a buffer is mapped twice for 2 different devices which we use in SMC to provide failover capabilities. We see that -EEXIST is returned when a buffer is mapped for the second device. Since there is a maximum of 2 parallel mappings we never see the warning shown by active_cacheline_inc_overlap() because we don't exceed ACTIVE_CACHELINE_MAX_OVERLAP.
Mapping something twice is possible, but needs special care.
Basically one device always needs to do the first mapping and the other
one needs to use DMA_ATTR_SKIP_CPU_SYNC to opt out of the coherency
protocol. So we have two TODO items here: 1) the driver needs to use the
above scheme and 2) this dma-debug check needs to understand
DMA_ATTR_SKIP_CPU_SYNC. Can I trick you into doing both?
^ permalink raw reply [flat|nested] 9+ messages in thread
end of thread, other threads:[~2021-10-11 11:47 UTC | newest]
Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <20210518125443.34148-1-someguy@effective-light.com>
[not found] ` <fd67fbac-64bf-f0ea-01e1-5938ccfab9d0@arm.com>
[not found] ` <20210914154504.z6vqxuh3byqwgfzx@skbuf>
2021-09-30 13:37 ` DPAA2 triggers, [PATCH] dma debug: report -EEXIST errors in add_dma_entry Karsten Graul
2021-10-01 12:52 ` Gerald Schaefer
2021-10-06 13:10 ` Gerald Schaefer
2021-10-06 13:21 ` Gerald Schaefer
2021-10-06 14:23 ` Robin Murphy
2021-10-06 15:06 ` Gerald Schaefer
2021-10-07 10:59 ` Karsten Graul
2021-10-07 16:40 ` Gerald Schaefer
2021-10-11 11:47 ` Christoph Hellwig
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).