From: Johannes Berg <johannes@sipsolutions.net>
To: Yogesh Ashok Powar <yogeshp@marvell.com>
Cc: "John W. Linville" <linville@tuxdriver.com>,
linux-wireless <linux-wireless@vger.kernel.org>,
Nishant Sarmukadam <nishants@marvell.com>
Subject: Re: [PATCH v2] mac80211: Purge A-MPDU TX queues before station destructions
Date: Thu, 08 Dec 2011 10:30:24 +0100 [thread overview]
Message-ID: <1323336624.3332.10.camel@jlt3.sipsolutions.net> (raw)
In-Reply-To: <20111208092608.GA4981@hertz.marvell.com>
On Thu, 2011-12-08 at 14:56 +0530, Yogesh Ashok Powar wrote:
> When a station leaves suddenly while ampdu traffic to that station is still
> running, there is a possibility that the ampdu pending queues are not freed due
> to a race condition leading to memory leaks. In '__sta_info_destroy' when we
> attempt to destroy the ampdu sessions in 'ieee80211_sta_tear_down_BA_sessions',
> the driver calls 'ieee80211_stop_tx_ba_cb_irqsafe' to delete the ampdu
> structures (tid_tx) and splice the pending queues and this job gets queued in
> sdata workqueue. However, the sta entry can get destroyed before the above work
> gets scheduled and hence the race.
>
> Purging the queues and freeing the tid_tx to avoid the leak. The better solution
> would be to fix the race, but that can be taken up in a separate patch.
>
> Signed-off-by: Nishant Sarmukadam <nishants@marvell.com>
> Signed-off-by: Yogesh Ashok Powar <yogeshp@marvell.com>
>
> v2: Adding note for driver authors as suggested by Johannes.
Thanks!
> ---
> net/mac80211/agg-tx.c | 2 ++
> net/mac80211/sta_info.c | 25 +++++++++++++++++++++++++
> 2 files changed, 27 insertions(+), 0 deletions(-)
>
> diff --git a/net/mac80211/agg-tx.c b/net/mac80211/agg-tx.c
> index 7380287..4bb33b8 100644
> --- a/net/mac80211/agg-tx.c
> +++ b/net/mac80211/agg-tx.c
> @@ -55,6 +55,8 @@
> * @ampdu_action function will be called with the action
> * %IEEE80211_AMPDU_TX_STOP. In this case, the call must not fail,
> * and the driver must later call ieee80211_stop_tx_ba_cb_irqsafe().
> + * Note that the sta can get destroyed before the BA tear down is
> + * complete.
> */
>
> static void ieee80211_send_addba_request(struct ieee80211_sub_if_data *sdata,
> diff --git a/net/mac80211/sta_info.c b/net/mac80211/sta_info.c
> index f982352..c6ca9bd 100644
> --- a/net/mac80211/sta_info.c
> +++ b/net/mac80211/sta_info.c
> @@ -851,6 +851,7 @@ static int __must_check __sta_info_destroy(struct sta_info *sta)
> struct ieee80211_sub_if_data *sdata;
> unsigned long flags;
> int ret, i, ac;
> + struct tid_ampdu_tx *tid_tx;
>
> might_sleep();
>
> @@ -949,6 +950,30 @@ static int __must_check __sta_info_destroy(struct sta_info *sta)
> }
> #endif
>
> + /* There could be some memory leaks because of ampdu tx pending queue
> + * not being freed before destroying the station info.
> + *
> + * Make sure that such queues are purged before freeing the station
> + * info.
> + * TODO: We have to somehow postpone the full destruction
> + * until the aggregation stop completes. Refer
> + * http://thread.gmane.org/gmane.linux.kernel.wireless.general/81936
> + */
> + for (i = 0; i < STA_TID_NUM; i++) {
> + if (!sta->ampdu_mlme.tid_tx[i])
> + continue;
> + tid_tx = sta->ampdu_mlme.tid_tx[i];
> + if (skb_queue_len(&tid_tx->pending)) {
> +#ifdef CONFIG_MAC80211_HT_DEBUG
> + wiphy_debug(local->hw.wiphy, "TX A-MPDU purging %d "
> + "packets for tid=%d\n",
> + skb_queue_len(&tid_tx->pending), i);
> +#endif /* CONFIG_MAC80211_HT_DEBUG */
> + __skb_queue_purge(&tid_tx->pending);
> + }
> + kfree_rcu(tid_tx, rcu_head);
> + }
> +
> __sta_info_free(local, sta);
>
> return 0;
next prev parent reply other threads:[~2011-12-08 9:30 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-12-08 9:26 [PATCH v2] mac80211: Purge A-MPDU TX queues before station destructions Yogesh Ashok Powar
2011-12-08 9:30 ` Johannes Berg [this message]
2011-12-14 22:17 ` Johannes Berg
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1323336624.3332.10.camel@jlt3.sipsolutions.net \
--to=johannes@sipsolutions.net \
--cc=linux-wireless@vger.kernel.org \
--cc=linville@tuxdriver.com \
--cc=nishants@marvell.com \
--cc=yogeshp@marvell.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox