Linux wireless drivers development
 help / color / mirror / Atom feed
From: Johannes Berg <johannes@sipsolutions.net>
To: Tomas Winkler <tomas.winkler@intel.com>
Cc: linville@tuxdriver.com, yi.zhu@intel.com,
	linux-wireless@vger.kernel.org,
	Ron Rindjunsky <ron.rindjunsky@intel.com>
Subject: Re: [PATCH 1/1] mac80211: fix deadlock in sta->lock
Date: Mon, 26 May 2008 16:19:14 +0200	[thread overview]
Message-ID: <1211811554.4843.4.camel@johannes.berg> (raw)
In-Reply-To: <1211810958-23095-1-git-send-email-tomas.winkler@intel.com>

[-- Attachment #1: Type: text/plain, Size: 2433 bytes --]

On Mon, 2008-05-26 at 17:09 +0300, Tomas Winkler wrote:
> From: Ron Rindjunsky <ron.rindjunsky@intel.com>
> 
> This patch fixes a deadlock of sta->lock use, occuring while changing
> tx aggregation states, as dev_queue_xmit end up in new function
> test_and_clear_sta_flags that uses that lock thus leading to deadlock

Oh, good catch, thanks. Reminds me to debug the other deadlock I saw
(not mac80211 related though)

> Signed-off-by: Ron Rindjunsky <ron.rindjunsky@intel.com>
> Signed-off-by: Tomas Winkler <tomas.winkler@intel.com>

Acked-by: Johannes Berg <johannes@sipsolutions.net>

> ---
>  net/mac80211/main.c |   10 +++++++---
>  1 files changed, 7 insertions(+), 3 deletions(-)
> 
> diff --git a/net/mac80211/main.c b/net/mac80211/main.c
> index b0fddb7..5a9030c 100644
> --- a/net/mac80211/main.c
> +++ b/net/mac80211/main.c
> @@ -662,6 +662,8 @@ int ieee80211_start_tx_ba_session(struct ieee80211_hw *hw, u8 *ra, u16 tid)
>  		goto start_ba_err;
>  	}
>  
> +	spin_unlock_bh(&sta->lock);
> +
>  	/* Will put all the packets in the new SW queue */
>  	ieee80211_requeue(local, ieee802_1d_to_ac[tid]);
>  	spin_unlock_bh(&local->mdev->queue_lock);
> @@ -688,9 +690,9 @@ start_ba_err:
>  	kfree(sta->ampdu_mlme.tid_tx[tid]);
>  	sta->ampdu_mlme.tid_tx[tid] = NULL;
>  	spin_unlock_bh(&local->mdev->queue_lock);
> +	spin_unlock_bh(&sta->lock);
>  	ret = -EBUSY;
>  start_ba_exit:
> -	spin_unlock_bh(&sta->lock);
>  	rcu_read_unlock();
>  	return ret;
>  }
> @@ -829,10 +831,11 @@ void ieee80211_stop_tx_ba_cb(struct ieee80211_hw *hw, u8 *ra, u8 tid)
>  	}
>  	state = &sta->ampdu_mlme.tid_state_tx[tid];
>  
> -	spin_lock_bh(&sta->lock);
> +	/* no need to use sta->lock in this state check, as
> +	 * ieee80211_stop_tx_ba_session will let only
> +	 * one stop call to pass through per sta/tid */
>  	if ((*state & HT_AGG_STATE_REQ_STOP_BA_MSK) == 0) {
>  		printk(KERN_DEBUG "unexpected callback to A-MPDU stop\n");
> -		spin_unlock_bh(&sta->lock);
>  		rcu_read_unlock();
>  		return;
>  	}
> @@ -855,6 +858,7 @@ void ieee80211_stop_tx_ba_cb(struct ieee80211_hw *hw, u8 *ra, u8 tid)
>  	 * ieee80211_wake_queue is not used here as this queue is not
>  	 * necessarily stopped */
>  	netif_schedule(local->mdev);
> +	spin_lock_bh(&sta->lock);
>  	*state = HT_AGG_STATE_IDLE;
>  	sta->ampdu_mlme.addba_req_num[tid] = 0;
>  	kfree(sta->ampdu_mlme.tid_tx[tid]);

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 828 bytes --]

  reply	other threads:[~2008-05-26 14:20 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-05-26 14:09 [PATCH 1/1] mac80211: fix deadlock in sta->lock Tomas Winkler
2008-05-26 14:19 ` Johannes Berg [this message]
2008-05-26 14:32   ` Tomas Winkler
2008-05-26 14:40     ` Johannes Berg
2008-05-26 14:48       ` Tomas Winkler
2008-05-27  5:23   ` Tomas Winkler
2008-05-27  7:42     ` Ron Rindjunsky

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1211811554.4843.4.camel@johannes.berg \
    --to=johannes@sipsolutions.net \
    --cc=linux-wireless@vger.kernel.org \
    --cc=linville@tuxdriver.com \
    --cc=ron.rindjunsky@intel.com \
    --cc=tomas.winkler@intel.com \
    --cc=yi.zhu@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox