* [PATCH] ibm_newemac: Fixes kernel crashes when speed of cable connected changes @ 2008-06-23 12:54 Stefan Roese 2008-06-23 23:20 ` Benjamin Herrenschmidt 0 siblings, 1 reply; 4+ messages in thread From: Stefan Roese @ 2008-06-23 12:54 UTC (permalink / raw) To: linuxppc-dev, netdev; +Cc: Sathya Narayanan From: Sathya Narayanan <sathyan@teamf1.com> The descriptor pointers were not initialized to NIL values, so it was poiniting to some random addresses which was completely invalid. This fix takes care of initializing the descriptor to NIL values and clearing the valid descriptors on clean ring operation. Signed-off-by: Sathya Narayanan <sathyan@teamf1.com> Signed-off-by: Stefan Roese <sr@denx.de> --- drivers/net/ibm_newemac/core.c | 6 +++++- 1 files changed, 5 insertions(+), 1 deletions(-) diff --git a/drivers/net/ibm_newemac/core.c b/drivers/net/ibm_newemac/core.c index 5d2108c..6dfc2c9 100644 --- a/drivers/net/ibm_newemac/core.c +++ b/drivers/net/ibm_newemac/core.c @@ -1025,7 +1025,7 @@ static void emac_clean_tx_ring(struct emac_instance *dev) int i; for (i = 0; i < NUM_TX_BUFF; ++i) { - if (dev->tx_skb[i]) { + if (dev->tx_skb[i] && dev->tx_desc[i].data_ptr) { dev_kfree_skb(dev->tx_skb[i]); dev->tx_skb[i] = NULL; if (dev->tx_desc[i].ctrl & MAL_TX_CTRL_READY) @@ -2719,6 +2719,10 @@ static int __devinit emac_probe(struct of_device *ofdev, /* Clean rings */ memset(dev->tx_desc, 0, NUM_TX_BUFF * sizeof(struct mal_descriptor)); memset(dev->rx_desc, 0, NUM_RX_BUFF * sizeof(struct mal_descriptor)); + for (i = 0; i <= NUM_TX_BUFF; i++) + dev->tx_skb[i] = NULL; + for (i = 0; i <= NUM_RX_BUFF; i++) + dev->rx_skb[i] = NULL; /* Attach to ZMII, if needed */ if (emac_has_feature(dev, EMAC_FTR_HAS_ZMII) && -- 1.5.6 ^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH] ibm_newemac: Fixes kernel crashes when speed of cable connected changes 2008-06-23 12:54 [PATCH] ibm_newemac: Fixes kernel crashes when speed of cable connected changes Stefan Roese @ 2008-06-23 23:20 ` Benjamin Herrenschmidt 2008-06-27 6:54 ` SathyaNarayanan 0 siblings, 1 reply; 4+ messages in thread From: Benjamin Herrenschmidt @ 2008-06-23 23:20 UTC (permalink / raw) To: Stefan Roese; +Cc: linuxppc-dev, Sathya Narayanan, netdev On Mon, 2008-06-23 at 14:54 +0200, Stefan Roese wrote: > From: Sathya Narayanan <sathyan@teamf1.com> > > The descriptor pointers were not initialized to NIL values, so it was > poiniting to some random addresses which was completely invalid. This > fix takes care of initializing the descriptor to NIL values and clearing > the valid descriptors on clean ring operation. > > Signed-off-by: Sathya Narayanan <sathyan@teamf1.com> > Signed-off-by: Stefan Roese <sr@denx.de> > --- > drivers/net/ibm_newemac/core.c | 6 +++++- > 1 files changed, 5 insertions(+), 1 deletions(-) > > diff --git a/drivers/net/ibm_newemac/core.c b/drivers/net/ibm_newemac/core.c > index 5d2108c..6dfc2c9 100644 > --- a/drivers/net/ibm_newemac/core.c > +++ b/drivers/net/ibm_newemac/core.c > @@ -1025,7 +1025,7 @@ static void emac_clean_tx_ring(struct emac_instance *dev) > int i; > > for (i = 0; i < NUM_TX_BUFF; ++i) { > - if (dev->tx_skb[i]) { > + if (dev->tx_skb[i] && dev->tx_desc[i].data_ptr) { Why changing the test above ? > dev_kfree_skb(dev->tx_skb[i]); > dev->tx_skb[i] = NULL; > if (dev->tx_desc[i].ctrl & MAL_TX_CTRL_READY) > @@ -2719,6 +2719,10 @@ static int __devinit emac_probe(struct of_device *ofdev, > /* Clean rings */ > memset(dev->tx_desc, 0, NUM_TX_BUFF * sizeof(struct mal_descriptor)); > memset(dev->rx_desc, 0, NUM_RX_BUFF * sizeof(struct mal_descriptor)); > + for (i = 0; i <= NUM_TX_BUFF; i++) > + dev->tx_skb[i] = NULL; > + for (i = 0; i <= NUM_RX_BUFF; i++) > + dev->rx_skb[i] = NULL; Why not use memset here too ? > /* Attach to ZMII, if needed */ > if (emac_has_feature(dev, EMAC_FTR_HAS_ZMII) && ^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] ibm_newemac: Fixes kernel crashes when speed of cable connected changes 2008-06-23 23:20 ` Benjamin Herrenschmidt @ 2008-06-27 6:54 ` SathyaNarayanan 2008-06-27 8:54 ` Benjamin Herrenschmidt 0 siblings, 1 reply; 4+ messages in thread From: SathyaNarayanan @ 2008-06-27 6:54 UTC (permalink / raw) To: benh; +Cc: linuxppc-dev, Stefan Roese, netdev [-- Attachment #1: Type: text/plain, Size: 2529 bytes --] Hi benh, Please find my comments inline. Thanks and regards, SathyaNarayanan On Tue, Jun 24, 2008 at 4:50 AM, Benjamin Herrenschmidt < benh@kernel.crashing.org> wrote: > On Mon, 2008-06-23 at 14:54 +0200, Stefan Roese wrote: > > From: Sathya Narayanan <sathyan@teamf1.com> > > > > The descriptor pointers were not initialized to NIL values, so it was > > poiniting to some random addresses which was completely invalid. This > > fix takes care of initializing the descriptor to NIL values and clearing > > the valid descriptors on clean ring operation. > > > > Signed-off-by: Sathya Narayanan <sathyan@teamf1.com> > > Signed-off-by: Stefan Roese <sr@denx.de> > > --- > > drivers/net/ibm_newemac/core.c | 6 +++++- > > 1 files changed, 5 insertions(+), 1 deletions(-) > > > > diff --git a/drivers/net/ibm_newemac/core.c > b/drivers/net/ibm_newemac/core.c > > index 5d2108c..6dfc2c9 100644 > > --- a/drivers/net/ibm_newemac/core.c > > +++ b/drivers/net/ibm_newemac/core.c > > @@ -1025,7 +1025,7 @@ static void emac_clean_tx_ring(struct emac_instance > *dev) > > int i; > > > > for (i = 0; i < NUM_TX_BUFF; ++i) { > > - if (dev->tx_skb[i]) { > > + if (dev->tx_skb[i] && dev->tx_desc[i].data_ptr) { > > Why changing the test above ? The reason for changing this condition is , In any of the case if the dev->tx_skb is not containing valid address, Then while clearing it you may be resulted in "address voilations". This additional condition ensures that we are clearing the valid skbs. Further this condition is not in general data flow, So this additional condition should not have any impact on performance. > > > > dev_kfree_skb(dev->tx_skb[i]); > > dev->tx_skb[i] = NULL; > > if (dev->tx_desc[i].ctrl & MAL_TX_CTRL_READY) > > @@ -2719,6 +2719,10 @@ static int __devinit emac_probe(struct of_device > *ofdev, > > /* Clean rings */ > > memset(dev->tx_desc, 0, NUM_TX_BUFF * sizeof(struct > mal_descriptor)); > > memset(dev->rx_desc, 0, NUM_RX_BUFF * sizeof(struct > mal_descriptor)); > > + for (i = 0; i <= NUM_TX_BUFF; i++) > > + dev->tx_skb[i] = NULL; > > + for (i = 0; i <= NUM_RX_BUFF; i++) > > + dev->rx_skb[i] = NULL; > > Why not use memset here too ? Yes, It was valid to use memset here. I can send the modified patch for it. > > > > /* Attach to ZMII, if needed */ > > if (emac_has_feature(dev, EMAC_FTR_HAS_ZMII) && > > [-- Attachment #2: Type: text/html, Size: 4135 bytes --] ^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] ibm_newemac: Fixes kernel crashes when speed of cable connected changes 2008-06-27 6:54 ` SathyaNarayanan @ 2008-06-27 8:54 ` Benjamin Herrenschmidt 0 siblings, 0 replies; 4+ messages in thread From: Benjamin Herrenschmidt @ 2008-06-27 8:54 UTC (permalink / raw) To: SathyaNarayanan; +Cc: linuxppc-dev, Stefan Roese, netdev > > > for (i = 0; i < NUM_TX_BUFF; ++i) { > > - if (dev->tx_skb[i]) { > > + if (dev->tx_skb[i] && > dev->tx_desc[i].data_ptr) { > > > Why changing the test above ? > > The reason for changing this condition is , In any of the case if > the dev->tx_skb is not containing valid address, Then while clearing > it you may be resulted in "address voilations". This additional > condition ensures that we are clearing the valid skbs. > Further this condition is not in general data flow, So this additional > condition should not have any impact on performance. Do you see -any- case where tx_skb[i] and dev->tx_desc[i].data_ptr would be out of sync ? If that's the case, shouldn't we cleanup instead of leaving some kind of stale entry in the ring ? In addition, in pure theory, data_ptr == 0 is a valid DMA address :-) So I think that part of the patch shouldn't be there. > > > dev_kfree_skb(dev->tx_skb[i]); > > dev->tx_skb[i] = NULL; > > if (dev->tx_desc[i].ctrl & > MAL_TX_CTRL_READY) > > @@ -2719,6 +2719,10 @@ static int __devinit > emac_probe(struct of_device *ofdev, > > /* Clean rings */ > > memset(dev->tx_desc, 0, NUM_TX_BUFF * sizeof(struct > mal_descriptor)); > > memset(dev->rx_desc, 0, NUM_RX_BUFF * sizeof(struct > mal_descriptor)); > > + for (i = 0; i <= NUM_TX_BUFF; i++) > > + dev->tx_skb[i] = NULL; > > + for (i = 0; i <= NUM_RX_BUFF; i++) > > + dev->rx_skb[i] = NULL; > > > Why not use memset here too ? > Yes, It was valid to use memset here. I can send the modified > patch for it. Please do, thanks. Cheers, Ben. ^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2008-06-27 8:54 UTC | newest] Thread overview: 4+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2008-06-23 12:54 [PATCH] ibm_newemac: Fixes kernel crashes when speed of cable connected changes Stefan Roese 2008-06-23 23:20 ` Benjamin Herrenschmidt 2008-06-27 6:54 ` SathyaNarayanan 2008-06-27 8:54 ` Benjamin Herrenschmidt
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox