* [PATCH] ibm_newemac: Fixes kernel crashes when speed of cable connected changes
@ 2008-06-23 12:54 Stefan Roese
2008-06-23 23:20 ` Benjamin Herrenschmidt
0 siblings, 1 reply; 4+ messages in thread
From: Stefan Roese @ 2008-06-23 12:54 UTC (permalink / raw)
To: linuxppc-dev, netdev; +Cc: Sathya Narayanan
From: Sathya Narayanan <sathyan@teamf1.com>
The descriptor pointers were not initialized to NIL values, so it was
poiniting to some random addresses which was completely invalid. This
fix takes care of initializing the descriptor to NIL values and clearing
the valid descriptors on clean ring operation.
Signed-off-by: Sathya Narayanan <sathyan@teamf1.com>
Signed-off-by: Stefan Roese <sr@denx.de>
---
drivers/net/ibm_newemac/core.c | 6 +++++-
1 files changed, 5 insertions(+), 1 deletions(-)
diff --git a/drivers/net/ibm_newemac/core.c b/drivers/net/ibm_newemac/core.c
index 5d2108c..6dfc2c9 100644
--- a/drivers/net/ibm_newemac/core.c
+++ b/drivers/net/ibm_newemac/core.c
@@ -1025,7 +1025,7 @@ static void emac_clean_tx_ring(struct emac_instance *dev)
int i;
for (i = 0; i < NUM_TX_BUFF; ++i) {
- if (dev->tx_skb[i]) {
+ if (dev->tx_skb[i] && dev->tx_desc[i].data_ptr) {
dev_kfree_skb(dev->tx_skb[i]);
dev->tx_skb[i] = NULL;
if (dev->tx_desc[i].ctrl & MAL_TX_CTRL_READY)
@@ -2719,6 +2719,10 @@ static int __devinit emac_probe(struct of_device *ofdev,
/* Clean rings */
memset(dev->tx_desc, 0, NUM_TX_BUFF * sizeof(struct mal_descriptor));
memset(dev->rx_desc, 0, NUM_RX_BUFF * sizeof(struct mal_descriptor));
+ for (i = 0; i <= NUM_TX_BUFF; i++)
+ dev->tx_skb[i] = NULL;
+ for (i = 0; i <= NUM_RX_BUFF; i++)
+ dev->rx_skb[i] = NULL;
/* Attach to ZMII, if needed */
if (emac_has_feature(dev, EMAC_FTR_HAS_ZMII) &&
--
1.5.6
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH] ibm_newemac: Fixes kernel crashes when speed of cable connected changes
2008-06-23 12:54 [PATCH] ibm_newemac: Fixes kernel crashes when speed of cable connected changes Stefan Roese
@ 2008-06-23 23:20 ` Benjamin Herrenschmidt
2008-06-27 6:54 ` SathyaNarayanan
0 siblings, 1 reply; 4+ messages in thread
From: Benjamin Herrenschmidt @ 2008-06-23 23:20 UTC (permalink / raw)
To: Stefan Roese; +Cc: linuxppc-dev, Sathya Narayanan, netdev
On Mon, 2008-06-23 at 14:54 +0200, Stefan Roese wrote:
> From: Sathya Narayanan <sathyan@teamf1.com>
>
> The descriptor pointers were not initialized to NIL values, so it was
> poiniting to some random addresses which was completely invalid. This
> fix takes care of initializing the descriptor to NIL values and clearing
> the valid descriptors on clean ring operation.
>
> Signed-off-by: Sathya Narayanan <sathyan@teamf1.com>
> Signed-off-by: Stefan Roese <sr@denx.de>
> ---
> drivers/net/ibm_newemac/core.c | 6 +++++-
> 1 files changed, 5 insertions(+), 1 deletions(-)
>
> diff --git a/drivers/net/ibm_newemac/core.c b/drivers/net/ibm_newemac/core.c
> index 5d2108c..6dfc2c9 100644
> --- a/drivers/net/ibm_newemac/core.c
> +++ b/drivers/net/ibm_newemac/core.c
> @@ -1025,7 +1025,7 @@ static void emac_clean_tx_ring(struct emac_instance *dev)
> int i;
>
> for (i = 0; i < NUM_TX_BUFF; ++i) {
> - if (dev->tx_skb[i]) {
> + if (dev->tx_skb[i] && dev->tx_desc[i].data_ptr) {
Why changing the test above ?
> dev_kfree_skb(dev->tx_skb[i]);
> dev->tx_skb[i] = NULL;
> if (dev->tx_desc[i].ctrl & MAL_TX_CTRL_READY)
> @@ -2719,6 +2719,10 @@ static int __devinit emac_probe(struct of_device *ofdev,
> /* Clean rings */
> memset(dev->tx_desc, 0, NUM_TX_BUFF * sizeof(struct mal_descriptor));
> memset(dev->rx_desc, 0, NUM_RX_BUFF * sizeof(struct mal_descriptor));
> + for (i = 0; i <= NUM_TX_BUFF; i++)
> + dev->tx_skb[i] = NULL;
> + for (i = 0; i <= NUM_RX_BUFF; i++)
> + dev->rx_skb[i] = NULL;
Why not use memset here too ?
> /* Attach to ZMII, if needed */
> if (emac_has_feature(dev, EMAC_FTR_HAS_ZMII) &&
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] ibm_newemac: Fixes kernel crashes when speed of cable connected changes
2008-06-23 23:20 ` Benjamin Herrenschmidt
@ 2008-06-27 6:54 ` SathyaNarayanan
2008-06-27 8:54 ` Benjamin Herrenschmidt
0 siblings, 1 reply; 4+ messages in thread
From: SathyaNarayanan @ 2008-06-27 6:54 UTC (permalink / raw)
To: benh; +Cc: linuxppc-dev, Stefan Roese, netdev
[-- Attachment #1: Type: text/plain, Size: 2529 bytes --]
Hi benh,
Please find my comments inline.
Thanks and regards,
SathyaNarayanan
On Tue, Jun 24, 2008 at 4:50 AM, Benjamin Herrenschmidt <
benh@kernel.crashing.org> wrote:
> On Mon, 2008-06-23 at 14:54 +0200, Stefan Roese wrote:
> > From: Sathya Narayanan <sathyan@teamf1.com>
> >
> > The descriptor pointers were not initialized to NIL values, so it was
> > poiniting to some random addresses which was completely invalid. This
> > fix takes care of initializing the descriptor to NIL values and clearing
> > the valid descriptors on clean ring operation.
> >
> > Signed-off-by: Sathya Narayanan <sathyan@teamf1.com>
> > Signed-off-by: Stefan Roese <sr@denx.de>
> > ---
> > drivers/net/ibm_newemac/core.c | 6 +++++-
> > 1 files changed, 5 insertions(+), 1 deletions(-)
> >
> > diff --git a/drivers/net/ibm_newemac/core.c
> b/drivers/net/ibm_newemac/core.c
> > index 5d2108c..6dfc2c9 100644
> > --- a/drivers/net/ibm_newemac/core.c
> > +++ b/drivers/net/ibm_newemac/core.c
> > @@ -1025,7 +1025,7 @@ static void emac_clean_tx_ring(struct emac_instance
> *dev)
> > int i;
> >
> > for (i = 0; i < NUM_TX_BUFF; ++i) {
> > - if (dev->tx_skb[i]) {
> > + if (dev->tx_skb[i] && dev->tx_desc[i].data_ptr) {
>
> Why changing the test above ?
The reason for changing this condition is , In any of the case if the
dev->tx_skb is not containing valid address, Then while clearing it you may
be resulted in "address voilations". This additional condition ensures that
we are clearing the valid skbs.
Further this condition is not in general data flow, So this additional
condition should not have any impact on performance.
>
>
> > dev_kfree_skb(dev->tx_skb[i]);
> > dev->tx_skb[i] = NULL;
> > if (dev->tx_desc[i].ctrl & MAL_TX_CTRL_READY)
> > @@ -2719,6 +2719,10 @@ static int __devinit emac_probe(struct of_device
> *ofdev,
> > /* Clean rings */
> > memset(dev->tx_desc, 0, NUM_TX_BUFF * sizeof(struct
> mal_descriptor));
> > memset(dev->rx_desc, 0, NUM_RX_BUFF * sizeof(struct
> mal_descriptor));
> > + for (i = 0; i <= NUM_TX_BUFF; i++)
> > + dev->tx_skb[i] = NULL;
> > + for (i = 0; i <= NUM_RX_BUFF; i++)
> > + dev->rx_skb[i] = NULL;
>
> Why not use memset here too ?
Yes, It was valid to use memset here. I can send the modified patch for
it.
>
>
> > /* Attach to ZMII, if needed */
> > if (emac_has_feature(dev, EMAC_FTR_HAS_ZMII) &&
>
>
[-- Attachment #2: Type: text/html, Size: 4135 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] ibm_newemac: Fixes kernel crashes when speed of cable connected changes
2008-06-27 6:54 ` SathyaNarayanan
@ 2008-06-27 8:54 ` Benjamin Herrenschmidt
0 siblings, 0 replies; 4+ messages in thread
From: Benjamin Herrenschmidt @ 2008-06-27 8:54 UTC (permalink / raw)
To: SathyaNarayanan; +Cc: linuxppc-dev, Stefan Roese, netdev
>
> > for (i = 0; i < NUM_TX_BUFF; ++i) {
> > - if (dev->tx_skb[i]) {
> > + if (dev->tx_skb[i] &&
> dev->tx_desc[i].data_ptr) {
>
>
> Why changing the test above ?
>
> The reason for changing this condition is , In any of the case if
> the dev->tx_skb is not containing valid address, Then while clearing
> it you may be resulted in "address voilations". This additional
> condition ensures that we are clearing the valid skbs.
> Further this condition is not in general data flow, So this additional
> condition should not have any impact on performance.
Do you see -any- case where tx_skb[i] and dev->tx_desc[i].data_ptr would
be out of sync ? If that's the case, shouldn't we cleanup instead of
leaving some kind of stale entry in the ring ?
In addition, in pure theory, data_ptr == 0 is a valid DMA address :-) So
I think that part of the patch shouldn't be there.
>
> > dev_kfree_skb(dev->tx_skb[i]);
> > dev->tx_skb[i] = NULL;
> > if (dev->tx_desc[i].ctrl &
> MAL_TX_CTRL_READY)
> > @@ -2719,6 +2719,10 @@ static int __devinit
> emac_probe(struct of_device *ofdev,
> > /* Clean rings */
> > memset(dev->tx_desc, 0, NUM_TX_BUFF * sizeof(struct
> mal_descriptor));
> > memset(dev->rx_desc, 0, NUM_RX_BUFF * sizeof(struct
> mal_descriptor));
> > + for (i = 0; i <= NUM_TX_BUFF; i++)
> > + dev->tx_skb[i] = NULL;
> > + for (i = 0; i <= NUM_RX_BUFF; i++)
> > + dev->rx_skb[i] = NULL;
>
>
> Why not use memset here too ?
> Yes, It was valid to use memset here. I can send the modified
> patch for it.
Please do, thanks.
Cheers,
Ben.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2008-06-27 8:54 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-06-23 12:54 [PATCH] ibm_newemac: Fixes kernel crashes when speed of cable connected changes Stefan Roese
2008-06-23 23:20 ` Benjamin Herrenschmidt
2008-06-27 6:54 ` SathyaNarayanan
2008-06-27 8:54 ` Benjamin Herrenschmidt
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).