* [PATCH] mtd: nand: fix bug writing 1 byte less than page size
@ 2016-07-18 8:39 Hector Palacios
2016-07-18 9:04 ` Boris Brezillon
0 siblings, 1 reply; 5+ messages in thread
From: Hector Palacios @ 2016-07-18 8:39 UTC (permalink / raw)
To: linux-mtd, linux-kernel
Cc: boris.brezillon, richard, oss, stable, hector.palacios
nand_do_write_ops() determines if it is writing a partial page with the
formula:
part_pagewr = (column || writelen < (mtd->writesize - 1))
When 'writelen' is exactly 1 byte less than the NAND page size the formula
equates to zero, so the code doesn't process it as a partial write,
although it should.
As a consequence the function remains in the while(1) loop with 'writelen'
becoming 0xffffffff and iterating endlessly.
The bug may not be easy to reproduce in Linux since user space tools
usually force the padding or round-up the write size to a page-size
multiple.
This was discovered in U-Boot where the issue can be reproduced by
writing any size that is 1 byte less than a page-size multiple.
For example, on a NAND with 2K page (0x800):
=> nand erase.part <partition>
=> nand write $loadaddr <partition> 7ff
Signed-off-by: Hector Palacios <hector.palacios@digi.com>
---
drivers/mtd/nand/nand_base.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/mtd/nand/nand_base.c b/drivers/mtd/nand/nand_base.c
index 0b0dc29d2af7..77533f7f2429 100644
--- a/drivers/mtd/nand/nand_base.c
+++ b/drivers/mtd/nand/nand_base.c
@@ -2610,7 +2610,7 @@ static int nand_do_write_ops(struct mtd_info *mtd, loff_t to,
int cached = writelen > bytes && page != blockmask;
uint8_t *wbuf = buf;
int use_bufpoi;
- int part_pagewr = (column || writelen < (mtd->writesize - 1));
+ int part_pagewr = (column || writelen < mtd->writesize);
if (part_pagewr)
use_bufpoi = 1;
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH] mtd: nand: fix bug writing 1 byte less than page size
2016-07-18 8:39 [PATCH] mtd: nand: fix bug writing 1 byte less than page size Hector Palacios
@ 2016-07-18 9:04 ` Boris Brezillon
2016-07-18 17:18 ` Brian Norris
2016-07-18 22:37 ` Scott Wood
0 siblings, 2 replies; 5+ messages in thread
From: Boris Brezillon @ 2016-07-18 9:04 UTC (permalink / raw)
To: Hector Palacios
Cc: linux-mtd, linux-kernel, richard, oss, stable, Brian Norris
On Mon, 18 Jul 2016 10:39:18 +0200
Hector Palacios <hector.palacios@digi.com> wrote:
> nand_do_write_ops() determines if it is writing a partial page with the
> formula:
> part_pagewr = (column || writelen < (mtd->writesize - 1))
>
> When 'writelen' is exactly 1 byte less than the NAND page size the formula
> equates to zero, so the code doesn't process it as a partial write,
> although it should.
> As a consequence the function remains in the while(1) loop with 'writelen'
> becoming 0xffffffff and iterating endlessly.
>
> The bug may not be easy to reproduce in Linux since user space tools
> usually force the padding or round-up the write size to a page-size
> multiple.
> This was discovered in U-Boot where the issue can be reproduced by
> writing any size that is 1 byte less than a page-size multiple.
> For example, on a NAND with 2K page (0x800):
> => nand erase.part <partition>
> => nand write $loadaddr <partition> 7ff
>
> Signed-off-by: Hector Palacios <hector.palacios@digi.com>
Acked-by: Boris Brezillon <boris.brezillon@free-electrons.com>
Brian, can you take this patch in your tree.
As usual, I'm unsure whether we should Cc stable or not, but we
should at least add
Fixes: 66507c7bc8895 ("mtd: nand: Add support to use nand_base poi databuf as bounce buffer")
> ---
> drivers/mtd/nand/nand_base.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/mtd/nand/nand_base.c b/drivers/mtd/nand/nand_base.c
> index 0b0dc29d2af7..77533f7f2429 100644
> --- a/drivers/mtd/nand/nand_base.c
> +++ b/drivers/mtd/nand/nand_base.c
> @@ -2610,7 +2610,7 @@ static int nand_do_write_ops(struct mtd_info *mtd, loff_t to,
> int cached = writelen > bytes && page != blockmask;
> uint8_t *wbuf = buf;
> int use_bufpoi;
> - int part_pagewr = (column || writelen < (mtd->writesize - 1));
> + int part_pagewr = (column || writelen < mtd->writesize);
>
> if (part_pagewr)
> use_bufpoi = 1;
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] mtd: nand: fix bug writing 1 byte less than page size
2016-07-18 9:04 ` Boris Brezillon
@ 2016-07-18 17:18 ` Brian Norris
2016-07-18 22:37 ` Scott Wood
1 sibling, 0 replies; 5+ messages in thread
From: Brian Norris @ 2016-07-18 17:18 UTC (permalink / raw)
To: Boris Brezillon
Cc: Hector Palacios, linux-mtd, linux-kernel, richard, oss, stable,
Kamal Dasu
+ Kamal, FYI
On Mon, Jul 18, 2016 at 11:04:32AM +0200, Boris Brezillon wrote:
> On Mon, 18 Jul 2016 10:39:18 +0200
> Hector Palacios <hector.palacios@digi.com> wrote:
>
> > nand_do_write_ops() determines if it is writing a partial page with the
> > formula:
> > part_pagewr = (column || writelen < (mtd->writesize - 1))
> >
> > When 'writelen' is exactly 1 byte less than the NAND page size the formula
> > equates to zero, so the code doesn't process it as a partial write,
> > although it should.
> > As a consequence the function remains in the while(1) loop with 'writelen'
> > becoming 0xffffffff and iterating endlessly.
> >
> > The bug may not be easy to reproduce in Linux since user space tools
> > usually force the padding or round-up the write size to a page-size
> > multiple.
> > This was discovered in U-Boot where the issue can be reproduced by
> > writing any size that is 1 byte less than a page-size multiple.
> > For example, on a NAND with 2K page (0x800):
> > => nand erase.part <partition>
> > => nand write $loadaddr <partition> 7ff
> >
> > Signed-off-by: Hector Palacios <hector.palacios@digi.com>
>
> Acked-by: Boris Brezillon <boris.brezillon@free-electrons.com>
>
> Brian, can you take this patch in your tree.
>
> As usual, I'm unsure whether we should Cc stable or not, but we
> should at least add
>
> Fixes: 66507c7bc8895 ("mtd: nand: Add support to use nand_base poi databuf as bounce buffer")
Applied to l2-mtd.git with Fixes and stable tags. Thanks!
> > ---
> > drivers/mtd/nand/nand_base.c | 2 +-
> > 1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/drivers/mtd/nand/nand_base.c b/drivers/mtd/nand/nand_base.c
> > index 0b0dc29d2af7..77533f7f2429 100644
> > --- a/drivers/mtd/nand/nand_base.c
> > +++ b/drivers/mtd/nand/nand_base.c
> > @@ -2610,7 +2610,7 @@ static int nand_do_write_ops(struct mtd_info *mtd, loff_t to,
> > int cached = writelen > bytes && page != blockmask;
> > uint8_t *wbuf = buf;
> > int use_bufpoi;
> > - int part_pagewr = (column || writelen < (mtd->writesize - 1));
> > + int part_pagewr = (column || writelen < mtd->writesize);
> >
> > if (part_pagewr)
> > use_bufpoi = 1;
>
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] mtd: nand: fix bug writing 1 byte less than page size
2016-07-18 9:04 ` Boris Brezillon
2016-07-18 17:18 ` Brian Norris
@ 2016-07-18 22:37 ` Scott Wood
2016-07-19 19:56 ` Brian Norris
1 sibling, 1 reply; 5+ messages in thread
From: Scott Wood @ 2016-07-18 22:37 UTC (permalink / raw)
To: Boris Brezillon, Hector Palacios
Cc: linux-mtd, linux-kernel, richard, stable, Brian Norris
On Mon, 2016-07-18 at 11:04 +0200, Boris Brezillon wrote:
> On Mon, 18 Jul 2016 10:39:18 +0200
> Hector Palacios <hector.palacios@digi.com> wrote:
>
> >
> > nand_do_write_ops() determines if it is writing a partial page with the
> > formula:
> > part_pagewr = (column || writelen < (mtd->writesize - 1))
> >
> > When 'writelen' is exactly 1 byte less than the NAND page size the formula
> > equates to zero, so the code doesn't process it as a partial write,
> > although it should.
> > As a consequence the function remains in the while(1) loop with 'writelen'
> > becoming 0xffffffff and iterating endlessly.
> >
> > The bug may not be easy to reproduce in Linux since user space tools
> > usually force the padding or round-up the write size to a page-size
> > multiple.
> > This was discovered in U-Boot where the issue can be reproduced by
> > writing any size that is 1 byte less than a page-size multiple.
> > For example, on a NAND with 2K page (0x800):
> > => nand erase.part <partition>
> > => nand write $loadaddr <partition> 7ff
> >
> > Signed-off-by: Hector Palacios <hector.palacios@digi.com>
> Acked-by: Boris Brezillon <boris.brezillon@free-electrons.com>
>
> Brian, can you take this patch in your tree.
>
> As usual, I'm unsure whether we should Cc stable or not, but we
> should at least add
>
> Fixes: 66507c7bc8895 ("mtd: nand: Add support to use nand_base poi databuf
> as bounce buffer")
That commit just moved the bad test; it was introduced in 29072b96078ffde3
("[MTD] NAND: add subpage write support").
-Scott
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] mtd: nand: fix bug writing 1 byte less than page size
2016-07-18 22:37 ` Scott Wood
@ 2016-07-19 19:56 ` Brian Norris
0 siblings, 0 replies; 5+ messages in thread
From: Brian Norris @ 2016-07-19 19:56 UTC (permalink / raw)
To: Scott Wood
Cc: Boris Brezillon, Hector Palacios, linux-mtd, linux-kernel,
richard, stable
On Mon, Jul 18, 2016 at 05:37:22PM -0500, Scott Wood wrote:
> On Mon, 2016-07-18 at 11:04 +0200, Boris Brezillon wrote:
> > On Mon, 18 Jul 2016 10:39:18 +0200
> > Hector Palacios <hector.palacios@digi.com> wrote:
> >
> > >
> > > nand_do_write_ops() determines if it is writing a partial page with the
> > > formula:
> > > part_pagewr = (column || writelen < (mtd->writesize - 1))
> > >
> > > When 'writelen' is exactly 1 byte less than the NAND page size the formula
> > > equates to zero, so the code doesn't process it as a partial write,
> > > although it should.
> > > As a consequence the function remains in the while(1) loop with 'writelen'
> > > becoming 0xffffffff and iterating endlessly.
> > >
> > > The bug may not be easy to reproduce in Linux since user space tools
> > > usually force the padding or round-up the write size to a page-size
> > > multiple.
> > > This was discovered in U-Boot where the issue can be reproduced by
> > > writing any size that is 1 byte less than a page-size multiple.
> > > For example, on a NAND with 2K page (0x800):
> > > => nand erase.part <partition>
> > > => nand write $loadaddr <partition> 7ff
> > >
> > > Signed-off-by: Hector Palacios <hector.palacios@digi.com>
> > Acked-by: Boris Brezillon <boris.brezillon@free-electrons.com>
> >
> > Brian, can you take this patch in your tree.
> >
> > As usual, I'm unsure whether we should Cc stable or not, but we
> > should at least add
> >
> > Fixes: 66507c7bc8895 ("mtd: nand: Add support to use nand_base poi databuf
> > as bounce buffer")
>
> That commit just moved the bad test; it was introduced in 29072b96078ffde3
> ("[MTD] NAND: add subpage write support").
Indeed. I've update the Fixes tag and added an additional comment in the
commit message.
Thanks,
Brian
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2016-07-19 19:56 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-07-18 8:39 [PATCH] mtd: nand: fix bug writing 1 byte less than page size Hector Palacios
2016-07-18 9:04 ` Boris Brezillon
2016-07-18 17:18 ` Brian Norris
2016-07-18 22:37 ` Scott Wood
2016-07-19 19:56 ` Brian Norris
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).