From: Dave Jiang <dave.jiang@intel.com>
To: Reinette Chatre <reinette.chatre@intel.com>,
fenghua.yu@intel.com, vkoul@kernel.org,
dmaengine@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Subject: Re: [PATCH 3/3] dmaengine: idxd: Do not call DMX TX callbacks during workqueue disable
Date: Fri, 2 Dec 2022 11:45:38 -0700 [thread overview]
Message-ID: <044897a1-e6e1-b80a-e4cb-6b87423680fe@intel.com> (raw)
In-Reply-To: <93b5d144bfc16e0c0f640d5f7cfaeda6bf08753f.1670005163.git.reinette.chatre@intel.com>
On 12/2/2022 11:25 AM, Reinette Chatre wrote:
> On driver unload any pending descriptors are flushed and pending
> DMA descriptors are explicitly completed:
> idxd_dmaengine_drv_remove() ->
> drv_disable_wq() ->
> idxd_wq_free_irq() ->
> idxd_flush_pending_descs() ->
> idxd_dma_complete_txd()
>
> With this done during driver unload any remaining descriptor is
> likely stuck and can be dropped. Even so, the descriptor may still
> have a callback set that could no longer be accessible. An
> example of such a problem is when the dmatest fails and the dmatest
> module is unloaded. The failure of dmatest leaves descriptors with
> dma_async_tx_descriptor::callback pointing to code that no longer
> exist. This causes a page fault as below at the time the IDXD driver
> is unloaded when it attempts to run the callback:
> BUG: unable to handle page fault for address: ffffffffc0665190
> #PF: supervisor instruction fetch in kernel mode
> #PF: error_code(0x0010) - not-present page
>
> Fix this by clearing the callback pointers on the transmit
> descriptors only when workqueue is disabled.
>
> Signed-off-by: Reinette Chatre <reinette.chatre@intel.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
> ---
>
> History of refactoring made the Fixes: hard to identify by me.
>
> drivers/dma/idxd/device.c | 10 ++++++++++
> 1 file changed, 10 insertions(+)
>
> diff --git a/drivers/dma/idxd/device.c b/drivers/dma/idxd/device.c
> index b4d7bb923a40..2ac71a34fa34 100644
> --- a/drivers/dma/idxd/device.c
> +++ b/drivers/dma/idxd/device.c
> @@ -1156,6 +1156,7 @@ int idxd_device_load_config(struct idxd_device *idxd)
>
> static void idxd_flush_pending_descs(struct idxd_irq_entry *ie)
> {
> + struct dma_async_tx_descriptor *tx;
> struct idxd_desc *desc, *itr;
> struct llist_node *head;
> LIST_HEAD(flist);
> @@ -1175,6 +1176,15 @@ static void idxd_flush_pending_descs(struct idxd_irq_entry *ie)
> list_for_each_entry_safe(desc, itr, &flist, list) {
> list_del(&desc->list);
> ctype = desc->completion->status ? IDXD_COMPLETE_NORMAL : IDXD_COMPLETE_ABORT;
> + /*
> + * wq is being disabled. Any remaining descriptors are
> + * likely to be stuck and can be dropped. callback could
> + * point to code that is no longer accessible, for example
> + * if dmatest module has been unloaded.
> + */
> + tx = &desc->txd;
> + tx->callback = NULL;
> + tx->callback_result = NULL;
> idxd_dma_complete_txd(desc, ctype, true);
> }
> }
next prev parent reply other threads:[~2022-12-02 18:46 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-12-02 18:25 [PATCH 0/3] dmaengine: idxd: Error path fixes Reinette Chatre
2022-12-02 18:25 ` [PATCH 1/3] dmaengine: idxd: Let probe fail when workqueue cannot be enabled Reinette Chatre
2022-12-02 18:44 ` Dave Jiang
2022-12-02 18:52 ` Yu, Fenghua
2022-12-02 18:25 ` [PATCH 2/3] dmaengine: idxd: Prevent use after free on completion memory Reinette Chatre
2022-12-02 18:44 ` Dave Jiang
2022-12-02 19:45 ` Yu, Fenghua
2022-12-02 18:25 ` [PATCH 3/3] dmaengine: idxd: Do not call DMX TX callbacks during workqueue disable Reinette Chatre
2022-12-02 18:45 ` Dave Jiang [this message]
2022-12-02 21:12 ` Yu, Fenghua
2022-12-02 21:51 ` Reinette Chatre
2022-12-02 21:32 ` [PATCH 0/3] dmaengine: idxd: Error path fixes Yu, Fenghua
2022-12-02 21:53 ` Reinette Chatre
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=044897a1-e6e1-b80a-e4cb-6b87423680fe@intel.com \
--to=dave.jiang@intel.com \
--cc=dmaengine@vger.kernel.org \
--cc=fenghua.yu@intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=reinette.chatre@intel.com \
--cc=vkoul@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox