Netdev List
 help / color / mirror / Atom feed
* Kernel panic from tg3 net driver
@ 2011-10-15  7:50 Ari Savolainen
  2011-10-20 19:30 ` Ari Savolainen
  0 siblings, 1 reply; 14+ messages in thread
From: Ari Savolainen @ 2011-10-15  7:50 UTC (permalink / raw)
  To: David S. Miller, netdev, linux-kernel

Hi,

I get this panic when I try to print from a virtual machine:

https://docs.google.com/leaf?id=0B7LPWLwa6EUaODIxYTY2YmQtNWJlZS00M2ViLTk5ZmEtNDM2ZTZmNzE2MDEz&hl=fi

I tried to bisect it, but couldn't finish, because after the last step
the boot process got stuck right after selecting the kernel in grub
and I ran out of time:

git bisect start
# bad: [322a8b034003c0d46d39af85bf24fee27b902f48] Linux 3.1-rc1
git bisect bad 322a8b034003c0d46d39af85bf24fee27b902f48
# good: [02f8c6aee8df3cdc935e9bdd4f2d020306035dbe] Linux 3.0
git bisect good 02f8c6aee8df3cdc935e9bdd4f2d020306035dbe
# bad: [0003230e8200699860f0b10af524dc47bf8aecad] Merge branch
'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/viro/vfs-2.6
git bisect bad 0003230e8200699860f0b10af524dc47bf8aecad
# bad: [72f96e0e38d7e29ba16dcfd824ecaebe38b8293e] Merge branch
'for-linus-core' of
git://git.kernel.org/pub/scm/linux/kernel/git/nab/target-pending
git bisect bad 72f96e0e38d7e29ba16dcfd824ecaebe38b8293e
# good: [204d1641d200709c759d8c269458cbc7de378c40] Merge branch
'master' of git://git.kernel.org/pub/scm/linux/kernel/git/linville/wireless-next-2.6
into for-davem
git bisect good 204d1641d200709c759d8c269458cbc7de378c40
# bad: [415b3334a21aa67806c52d1acf4e72e14f7f402f] icmp: Fix regression
in nexthop resolution during replies.
git bisect bad 415b3334a21aa67806c52d1acf4e72e14f7f402f
# bad: [95a943c162d74b20d869917bdf5df11293c35b63] Merge branch
'master' of git://git.kernel.org/pub/scm/linux/kernel/git/linville/wireless-next-2.6
into for-davem
git bisect bad 95a943c162d74b20d869917bdf5df11293c35b63

In the first bad kernel (3.1-rc1) there was this in the log:

[  105.612095]
[  105.612096] ===================================================
[  105.612100] [ INFO: suspicious rcu_dereference_check() usage. ]
[  105.612101] ---------------------------------------------------
[  105.612103] include/net/dst.h:91 invoked rcu_dereference_check()
without protection!
[  105.612105]
[  105.612106] other info that might help us debug this:
[  105.612106]
[  105.612108]
[  105.612108] rcu_scheduler_active = 1, debug_locks = 0
[  105.612110] 1 lock held by dnsmasq/2618:
[  105.612111]  #0:  (rtnl_mutex){+.+.+.}, at: [<ffffffff815df8c7>]
rtnl_lock+0x17/0x20
[  105.612120]
[  105.612121] stack backtrace:
[  105.612123] Pid: 2618, comm: dnsmasq Not tainted 3.1.0-rc1 #41
[  105.612125] Call Trace:
[  105.612129]  [<ffffffff810ccdcb>] lockdep_rcu_dereference+0xbb/0xc0
[  105.612132]  [<ffffffff815dc5a9>] neigh_update+0x4f9/0x5f0
[  105.612135]  [<ffffffff815da001>] ? neigh_lookup+0xe1/0x220
[  105.612139]  [<ffffffff81639298>] arp_req_set+0xb8/0x230
[  105.612142]  [<ffffffff8163a59f>] arp_ioctl+0x1bf/0x310
[  105.612146]  [<ffffffff810baa40>] ? lock_hrtimer_base.isra.26+0x30/0x60
[  105.612150]  [<ffffffff8163fb75>] inet_ioctl+0x85/0x90
[  105.612154]  [<ffffffff815b5520>] sock_do_ioctl+0x30/0x70
[  105.612157]  [<ffffffff815b55d3>] sock_ioctl+0x73/0x280
[  105.612162]  [<ffffffff811b7698>] do_vfs_ioctl+0x98/0x570
[  105.612165]  [<ffffffff811a5c40>] ? fget_light+0x340/0x3a0
[  105.612168]  [<ffffffff811b7bbf>] sys_ioctl+0x4f/0x80
[  105.612172]  [<ffffffff816fdcab>] system_call_fastpath+0x16/0x1b

^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: Kernel panic from tg3 net driver
  2011-10-15  7:50 Kernel panic from tg3 net driver Ari Savolainen
@ 2011-10-20 19:30 ` Ari Savolainen
  2011-10-20 19:56   ` David Miller
  0 siblings, 1 reply; 14+ messages in thread
From: Ari Savolainen @ 2011-10-20 19:30 UTC (permalink / raw)
  To: David S. Miller, Richard Cochran, netdev, linux-kernel

I finally got time to continue bisecting. The commit that causes the
kernel panic is:  2669069aacc9 "tg3: enable transmit time stamping."

Ari

2011/10/15 Ari Savolainen <ari.m.savolainen@gmail.com>:
> Hi,
>
> I get this panic when I try to print from a virtual machine:
>
> https://docs.google.com/leaf?id=0B7LPWLwa6EUaODIxYTY2YmQtNWJlZS00M2ViLTk5ZmEtNDM2ZTZmNzE2MDEz&hl=fi
>
> I tried to bisect it, but couldn't finish, because after the last step
> the boot process got stuck right after selecting the kernel in grub
> and I ran out of time:
>
> git bisect start
> # bad: [322a8b034003c0d46d39af85bf24fee27b902f48] Linux 3.1-rc1
> git bisect bad 322a8b034003c0d46d39af85bf24fee27b902f48
> # good: [02f8c6aee8df3cdc935e9bdd4f2d020306035dbe] Linux 3.0
> git bisect good 02f8c6aee8df3cdc935e9bdd4f2d020306035dbe
> # bad: [0003230e8200699860f0b10af524dc47bf8aecad] Merge branch
> 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/viro/vfs-2.6
> git bisect bad 0003230e8200699860f0b10af524dc47bf8aecad
> # bad: [72f96e0e38d7e29ba16dcfd824ecaebe38b8293e] Merge branch
> 'for-linus-core' of
> git://git.kernel.org/pub/scm/linux/kernel/git/nab/target-pending
> git bisect bad 72f96e0e38d7e29ba16dcfd824ecaebe38b8293e
> # good: [204d1641d200709c759d8c269458cbc7de378c40] Merge branch
> 'master' of git://git.kernel.org/pub/scm/linux/kernel/git/linville/wireless-next-2.6
> into for-davem
> git bisect good 204d1641d200709c759d8c269458cbc7de378c40
> # bad: [415b3334a21aa67806c52d1acf4e72e14f7f402f] icmp: Fix regression
> in nexthop resolution during replies.
> git bisect bad 415b3334a21aa67806c52d1acf4e72e14f7f402f
> # bad: [95a943c162d74b20d869917bdf5df11293c35b63] Merge branch
> 'master' of git://git.kernel.org/pub/scm/linux/kernel/git/linville/wireless-next-2.6
> into for-davem
> git bisect bad 95a943c162d74b20d869917bdf5df11293c35b63
>
> In the first bad kernel (3.1-rc1) there was this in the log:
>
> [  105.612095]
> [  105.612096] ===================================================
> [  105.612100] [ INFO: suspicious rcu_dereference_check() usage. ]
> [  105.612101] ---------------------------------------------------
> [  105.612103] include/net/dst.h:91 invoked rcu_dereference_check()
> without protection!
> [  105.612105]
> [  105.612106] other info that might help us debug this:
> [  105.612106]
> [  105.612108]
> [  105.612108] rcu_scheduler_active = 1, debug_locks = 0
> [  105.612110] 1 lock held by dnsmasq/2618:
> [  105.612111]  #0:  (rtnl_mutex){+.+.+.}, at: [<ffffffff815df8c7>]
> rtnl_lock+0x17/0x20
> [  105.612120]
> [  105.612121] stack backtrace:
> [  105.612123] Pid: 2618, comm: dnsmasq Not tainted 3.1.0-rc1 #41
> [  105.612125] Call Trace:
> [  105.612129]  [<ffffffff810ccdcb>] lockdep_rcu_dereference+0xbb/0xc0
> [  105.612132]  [<ffffffff815dc5a9>] neigh_update+0x4f9/0x5f0
> [  105.612135]  [<ffffffff815da001>] ? neigh_lookup+0xe1/0x220
> [  105.612139]  [<ffffffff81639298>] arp_req_set+0xb8/0x230
> [  105.612142]  [<ffffffff8163a59f>] arp_ioctl+0x1bf/0x310
> [  105.612146]  [<ffffffff810baa40>] ? lock_hrtimer_base.isra.26+0x30/0x60
> [  105.612150]  [<ffffffff8163fb75>] inet_ioctl+0x85/0x90
> [  105.612154]  [<ffffffff815b5520>] sock_do_ioctl+0x30/0x70
> [  105.612157]  [<ffffffff815b55d3>] sock_ioctl+0x73/0x280
> [  105.612162]  [<ffffffff811b7698>] do_vfs_ioctl+0x98/0x570
> [  105.612165]  [<ffffffff811a5c40>] ? fget_light+0x340/0x3a0
> [  105.612168]  [<ffffffff811b7bbf>] sys_ioctl+0x4f/0x80
> [  105.612172]  [<ffffffff816fdcab>] system_call_fastpath+0x16/0x1b
>

^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: Kernel panic from tg3 net driver
  2011-10-20 19:30 ` Ari Savolainen
@ 2011-10-20 19:56   ` David Miller
  2011-10-20 20:05     ` Eric Dumazet
  0 siblings, 1 reply; 14+ messages in thread
From: David Miller @ 2011-10-20 19:56 UTC (permalink / raw)
  To: ari.m.savolainen; +Cc: richardcochran, netdev, linux-kernel

From: Ari Savolainen <ari.m.savolainen@gmail.com>
Date: Thu, 20 Oct 2011 22:30:44 +0300

> I finally got time to continue bisecting. The commit that causes the
> kernel panic is:  2669069aacc9 "tg3: enable transmit time stamping."

I thought initially that the issue might be that we have to do the
skb_tx_timestamp() call before we advance the mailbox transmit
descriptor pointer.

But that shouldn't matter, we run with a lock held, and TX reclaim takes
that same lock.

So I'm sort of stumped at the moment.

^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: Kernel panic from tg3 net driver
  2011-10-20 19:56   ` David Miller
@ 2011-10-20 20:05     ` Eric Dumazet
  2011-10-20 20:11       ` David Miller
  0 siblings, 1 reply; 14+ messages in thread
From: Eric Dumazet @ 2011-10-20 20:05 UTC (permalink / raw)
  To: David Miller; +Cc: ari.m.savolainen, richardcochran, netdev, linux-kernel

Le jeudi 20 octobre 2011 à 15:56 -0400, David Miller a écrit :
> From: Ari Savolainen <ari.m.savolainen@gmail.com>
> Date: Thu, 20 Oct 2011 22:30:44 +0300
> 
> > I finally got time to continue bisecting. The commit that causes the
> > kernel panic is:  2669069aacc9 "tg3: enable transmit time stamping."
> 
> I thought initially that the issue might be that we have to do the
> skb_tx_timestamp() call before we advance the mailbox transmit
> descriptor pointer.
> 
> But that shouldn't matter, we run with a lock held, and TX reclaim takes
> that same lock.
> 
> So I'm sort of stumped at the moment.

But its not a panic, its a RCU splat ?

> [  105.612129]  [<ffffffff810ccdcb>] lockdep_rcu_dereference+0xbb/0xc0
> [  105.612132]  [<ffffffff815dc5a9>] neigh_update+0x4f9/0x5f0
> [  105.612135]  [<ffffffff815da001>] ? neigh_lookup+0xe1/0x220
> [  105.612139]  [<ffffffff81639298>] arp_req_set+0xb8/0x230
> [  105.612142]  [<ffffffff8163a59f>] arp_ioctl+0x1bf/0x310
> [  105.612146]  [<ffffffff810baa40>] ? lock_hrtimer_base.isra.26+0x30/0x60
> [  105.612150]  [<ffffffff8163fb75>] inet_ioctl+0x85/0x90
> [  105.612154]  [<ffffffff815b5520>] sock_do_ioctl+0x30/0x70
> [  105.612157]  [<ffffffff815b55d3>] sock_ioctl+0x73/0x280
> [  105.612162]  [<ffffffff811b7698>] do_vfs_ioctl+0x98/0x570
> [  105.612165]  [<ffffffff811a5c40>] ? fget_light+0x340/0x3a0
> [  105.612168]  [<ffffffff811b7bbf>] sys_ioctl+0x4f/0x80
> [  105.612172]  [<ffffffff816fdcab>] system_call_fastpath+0x16/0x1b

And I think this was fixed yesterday ?

De: 	roy.qing.li@gmail.com
À: 	ari.m.savolainen@gmail.com, netdev@vger.kernel.org
Sujet: 	[PATCH net-next] neigh: fix rcu splat in neigh_update()
Date: 	Tue, 18 Oct 2011 16:32:42 +0800 (18/10/2011 10:32:42)

^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: Kernel panic from tg3 net driver
  2011-10-20 20:05     ` Eric Dumazet
@ 2011-10-20 20:11       ` David Miller
  2011-10-20 20:17         ` Eric Dumazet
  0 siblings, 1 reply; 14+ messages in thread
From: David Miller @ 2011-10-20 20:11 UTC (permalink / raw)
  To: eric.dumazet; +Cc: ari.m.savolainen, richardcochran, netdev, linux-kernel

From: Eric Dumazet <eric.dumazet@gmail.com>
Date: Thu, 20 Oct 2011 22:05:25 +0200

> And I think this was fixed yesterday ?
> 
> De: 	roy.qing.li@gmail.com
> À: 	ari.m.savolainen@gmail.com, netdev@vger.kernel.org
> Sujet: 	[PATCH net-next] neigh: fix rcu splat in neigh_update()
> Date: 	Tue, 18 Oct 2011 16:32:42 +0800 (18/10/2011 10:32:42)
> 

Good catch, it seems to be this bug.

^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: Kernel panic from tg3 net driver
  2011-10-20 20:11       ` David Miller
@ 2011-10-20 20:17         ` Eric Dumazet
  2011-10-20 20:37           ` Ari Savolainen
  0 siblings, 1 reply; 14+ messages in thread
From: Eric Dumazet @ 2011-10-20 20:17 UTC (permalink / raw)
  To: David Miller; +Cc: ari.m.savolainen, richardcochran, netdev, linux-kernel

Le jeudi 20 octobre 2011 à 16:11 -0400, David Miller a écrit :
> From: Eric Dumazet <eric.dumazet@gmail.com>
> Date: Thu, 20 Oct 2011 22:05:25 +0200
> 
> > And I think this was fixed yesterday ?
> > 
> > De: 	roy.qing.li@gmail.com
> > À: 	ari.m.savolainen@gmail.com, netdev@vger.kernel.org
> > Sujet: 	[PATCH net-next] neigh: fix rcu splat in neigh_update()
> > Date: 	Tue, 18 Oct 2011 16:32:42 +0800 (18/10/2011 10:32:42)
> > 
> 
> Good catch, it seems to be this bug.

Oh well, sorry, it seems it was one bug hit during bisection, but maybe
its completely unrelated to the real problem.

^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: Kernel panic from tg3 net driver
  2011-10-20 20:17         ` Eric Dumazet
@ 2011-10-20 20:37           ` Ari Savolainen
  2011-10-21 10:48             ` RongQing Li
  0 siblings, 1 reply; 14+ messages in thread
From: Ari Savolainen @ 2011-10-20 20:37 UTC (permalink / raw)
  To: Eric Dumazet; +Cc: David Miller, richardcochran, netdev, linux-kernel

That's right. I tried the patch and it didn't help.

Ari

2011/10/20 Eric Dumazet <eric.dumazet@gmail.com>:
> Le jeudi 20 octobre 2011 à 16:11 -0400, David Miller a écrit :
>> From: Eric Dumazet <eric.dumazet@gmail.com>
>> Date: Thu, 20 Oct 2011 22:05:25 +0200
>>
>> > And I think this was fixed yesterday ?
>> >
>> > De:         roy.qing.li@gmail.com
>> > À:  ari.m.savolainen@gmail.com, netdev@vger.kernel.org
>> > Sujet:      [PATCH net-next] neigh: fix rcu splat in neigh_update()
>> > Date:       Tue, 18 Oct 2011 16:32:42 +0800 (18/10/2011 10:32:42)
>> >
>>
>> Good catch, it seems to be this bug.
>
> Oh well, sorry, it seems it was one bug hit during bisection, but maybe
> its completely unrelated to the real problem.
>
>
>
>

^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: Kernel panic from tg3 net driver
  2011-10-20 20:37           ` Ari Savolainen
@ 2011-10-21 10:48             ` RongQing Li
  2011-10-22  6:12               ` Ari Savolainen
  0 siblings, 1 reply; 14+ messages in thread
From: RongQing Li @ 2011-10-21 10:48 UTC (permalink / raw)
  To: Ari Savolainen
  Cc: Eric Dumazet, David Miller, richardcochran, netdev, linux-kernel

Hi Ari:

Are you sure the patch is applied correctly and the log is same?
If the log is not same, could you paste it again.

Thanks

BR

2011/10/21 Ari Savolainen <ari.m.savolainen@gmail.com>:
> That's right. I tried the patch and it didn't help.
>
> Ari
>
> 2011/10/20 Eric Dumazet <eric.dumazet@gmail.com>:
>> Le jeudi 20 octobre 2011 à 16:11 -0400, David Miller a écrit :
>>> From: Eric Dumazet <eric.dumazet@gmail.com>
>>> Date: Thu, 20 Oct 2011 22:05:25 +0200
>>>
>>> > And I think this was fixed yesterday ?
>>> >
>>> > De:         roy.qing.li@gmail.com
>>> > À:  ari.m.savolainen@gmail.com, netdev@vger.kernel.org
>>> > Sujet:      [PATCH net-next] neigh: fix rcu splat in neigh_update()
>>> > Date:       Tue, 18 Oct 2011 16:32:42 +0800 (18/10/2011 10:32:42)
>>> >
>>>
>>> Good catch, it seems to be this bug.
>>
>> Oh well, sorry, it seems it was one bug hit during bisection, but maybe
>> its completely unrelated to the real problem.
>>
>>
>>
>>
> --
> To unsubscribe from this list: send the line "unsubscribe netdev" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
>

^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: Kernel panic from tg3 net driver
  2011-10-21 10:48             ` RongQing Li
@ 2011-10-22  6:12               ` Ari Savolainen
  2011-10-22  6:37                 ` Eric Dumazet
  0 siblings, 1 reply; 14+ messages in thread
From: Ari Savolainen @ 2011-10-22  6:12 UTC (permalink / raw)
  To: RongQing Li
  Cc: Eric Dumazet, David Miller, richardcochran, netdev, linux-kernel

2011/10/21 RongQing Li <roy.qing.li@gmail.com>:
> Hi Ari:
>
> Are you sure the patch is applied correctly and the log is same?
> If the log is not same, could you paste it again.
>
> Thanks

Yes, I'm sure. The panic and the rcu splat are unrelated. The panic
occurs when skb_tx_timestamp is being called after skb having been
freed by tigon3_dma_hwbug_workaround.

Ari

^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: Kernel panic from tg3 net driver
  2011-10-22  6:12               ` Ari Savolainen
@ 2011-10-22  6:37                 ` Eric Dumazet
  2011-10-22  7:25                   ` [PATCH] tg3: fix tigon3_dma_hwbug_workaround() Eric Dumazet
  0 siblings, 1 reply; 14+ messages in thread
From: Eric Dumazet @ 2011-10-22  6:37 UTC (permalink / raw)
  To: Ari Savolainen
  Cc: RongQing Li, David Miller, richardcochran, netdev, linux-kernel

Le samedi 22 octobre 2011 à 09:12 +0300, Ari Savolainen a écrit :
> 2011/10/21 RongQing Li <roy.qing.li@gmail.com>:
> > Hi Ari:
> >
> > Are you sure the patch is applied correctly and the log is same?
> > If the log is not same, could you paste it again.
> >
> > Thanks
> 
> Yes, I'm sure. The panic and the rcu splat are unrelated. The panic
> occurs when skb_tx_timestamp is being called after skb having been
> freed by tigon3_dma_hwbug_workaround.

OK that makes sense, thanks !

Do you plan to submit a patch, now you found the bug ?

^ permalink raw reply	[flat|nested] 14+ messages in thread

* [PATCH] tg3: fix tigon3_dma_hwbug_workaround()
  2011-10-22  6:37                 ` Eric Dumazet
@ 2011-10-22  7:25                   ` Eric Dumazet
  2011-10-22  7:30                     ` David Miller
  2011-10-22  7:54                     ` Ari Savolainen
  0 siblings, 2 replies; 14+ messages in thread
From: Eric Dumazet @ 2011-10-22  7:25 UTC (permalink / raw)
  To: Ari Savolainen
  Cc: RongQing Li, David Miller, richardcochran, netdev, linux-kernel

Ari got kernel panics using tg3 NIC, and bisected to 2669069aacc9 "tg3:
enable transmit time stamping."

This is because tigon3_dma_hwbug_workaround() might alloc a new skb and
free the original. We panic when skb_tx_timestamp() is called on freed
skb.

Reported-by: Ari Savolainen <ari.m.savolainen@gmail.com>
Signed-off-by: Eric Dumazet <eric.dumazet@gmail.com>
---
 drivers/net/tg3.c |    8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/net/tg3.c b/drivers/net/tg3.c
index 4a1374d..6149dc5 100644
--- a/drivers/net/tg3.c
+++ b/drivers/net/tg3.c
@@ -6029,12 +6029,12 @@ static void tg3_tx_skb_unmap(struct tg3_napi *tnapi, u32 entry, int last)
 
 /* Workaround 4GB and 40-bit hardware DMA bugs. */
 static int tigon3_dma_hwbug_workaround(struct tg3_napi *tnapi,
-				       struct sk_buff *skb,
+				       struct sk_buff **pskb,
 				       u32 *entry, u32 *budget,
 				       u32 base_flags, u32 mss, u32 vlan)
 {
 	struct tg3 *tp = tnapi->tp;
-	struct sk_buff *new_skb;
+	struct sk_buff *new_skb, *skb = *pskb;
 	dma_addr_t new_addr = 0;
 	int ret = 0;
 
@@ -6076,7 +6076,7 @@ static int tigon3_dma_hwbug_workaround(struct tg3_napi *tnapi,
 	}
 
 	dev_kfree_skb(skb);
-
+	*pskb = new_skb;
 	return ret;
 }
 
@@ -6305,7 +6305,7 @@ static netdev_tx_t tg3_start_xmit(struct sk_buff *skb, struct net_device *dev)
 		 */
 		entry = tnapi->tx_prod;
 		budget = tg3_tx_avail(tnapi);
-		if (tigon3_dma_hwbug_workaround(tnapi, skb, &entry, &budget,
+		if (tigon3_dma_hwbug_workaround(tnapi, &skb, &entry, &budget,
 						base_flags, mss, vlan))
 			goto out_unlock;
 	}

^ permalink raw reply related	[flat|nested] 14+ messages in thread

* Re: [PATCH] tg3: fix tigon3_dma_hwbug_workaround()
  2011-10-22  7:25                   ` [PATCH] tg3: fix tigon3_dma_hwbug_workaround() Eric Dumazet
@ 2011-10-22  7:30                     ` David Miller
  2011-10-22  7:54                     ` Ari Savolainen
  1 sibling, 0 replies; 14+ messages in thread
From: David Miller @ 2011-10-22  7:30 UTC (permalink / raw)
  To: eric.dumazet
  Cc: ari.m.savolainen, roy.qing.li, richardcochran, netdev,
	linux-kernel

From: Eric Dumazet <eric.dumazet@gmail.com>
Date: Sat, 22 Oct 2011 09:25:38 +0200

> Ari got kernel panics using tg3 NIC, and bisected to 2669069aacc9 "tg3:
> enable transmit time stamping."
> 
> This is because tigon3_dma_hwbug_workaround() might alloc a new skb and
> free the original. We panic when skb_tx_timestamp() is called on freed
> skb.
> 
> Reported-by: Ari Savolainen <ari.m.savolainen@gmail.com>
> Signed-off-by: Eric Dumazet <eric.dumazet@gmail.com>

Applied, thanks Eric.

^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: [PATCH] tg3: fix tigon3_dma_hwbug_workaround()
  2011-10-22  7:25                   ` [PATCH] tg3: fix tigon3_dma_hwbug_workaround() Eric Dumazet
  2011-10-22  7:30                     ` David Miller
@ 2011-10-22  7:54                     ` Ari Savolainen
  2011-10-22 13:30                       ` Ari Savolainen
  1 sibling, 1 reply; 14+ messages in thread
From: Ari Savolainen @ 2011-10-22  7:54 UTC (permalink / raw)
  To: Eric Dumazet
  Cc: RongQing Li, David Miller, richardcochran, netdev, linux-kernel

I tried a similar patch earlier and got another panic with that. I was
quite tired at that time and may have made a mistake. I'll test Eric's
patch either later today or tomorrow.

Ari

2011/10/22 Eric Dumazet <eric.dumazet@gmail.com>:
> Ari got kernel panics using tg3 NIC, and bisected to 2669069aacc9 "tg3:
> enable transmit time stamping."
>
> This is because tigon3_dma_hwbug_workaround() might alloc a new skb and
> free the original. We panic when skb_tx_timestamp() is called on freed
> skb.
>
> Reported-by: Ari Savolainen <ari.m.savolainen@gmail.com>
> Signed-off-by: Eric Dumazet <eric.dumazet@gmail.com>
> ---
>  drivers/net/tg3.c |    8 ++++----
>  1 file changed, 4 insertions(+), 4 deletions(-)
>
> diff --git a/drivers/net/tg3.c b/drivers/net/tg3.c
> index 4a1374d..6149dc5 100644
> --- a/drivers/net/tg3.c
> +++ b/drivers/net/tg3.c
> @@ -6029,12 +6029,12 @@ static void tg3_tx_skb_unmap(struct tg3_napi *tnapi, u32 entry, int last)
>
>  /* Workaround 4GB and 40-bit hardware DMA bugs. */
>  static int tigon3_dma_hwbug_workaround(struct tg3_napi *tnapi,
> -                                      struct sk_buff *skb,
> +                                      struct sk_buff **pskb,
>                                       u32 *entry, u32 *budget,
>                                       u32 base_flags, u32 mss, u32 vlan)
>  {
>        struct tg3 *tp = tnapi->tp;
> -       struct sk_buff *new_skb;
> +       struct sk_buff *new_skb, *skb = *pskb;
>        dma_addr_t new_addr = 0;
>        int ret = 0;
>
> @@ -6076,7 +6076,7 @@ static int tigon3_dma_hwbug_workaround(struct tg3_napi *tnapi,
>        }
>
>        dev_kfree_skb(skb);
> -
> +       *pskb = new_skb;
>        return ret;
>  }
>
> @@ -6305,7 +6305,7 @@ static netdev_tx_t tg3_start_xmit(struct sk_buff *skb, struct net_device *dev)
>                 */
>                entry = tnapi->tx_prod;
>                budget = tg3_tx_avail(tnapi);
> -               if (tigon3_dma_hwbug_workaround(tnapi, skb, &entry, &budget,
> +               if (tigon3_dma_hwbug_workaround(tnapi, &skb, &entry, &budget,
>                                                base_flags, mss, vlan))
>                        goto out_unlock;
>        }
>
>
>

^ permalink raw reply	[flat|nested] 14+ messages in thread

* Re: [PATCH] tg3: fix tigon3_dma_hwbug_workaround()
  2011-10-22  7:54                     ` Ari Savolainen
@ 2011-10-22 13:30                       ` Ari Savolainen
  0 siblings, 0 replies; 14+ messages in thread
From: Ari Savolainen @ 2011-10-22 13:30 UTC (permalink / raw)
  To: Eric Dumazet
  Cc: RongQing Li, David Miller, richardcochran, netdev, linux-kernel

I tested the patch. It works. The panics are gone.

Thanks,
Ari

2011/10/22 Ari Savolainen <ari.m.savolainen@gmail.com>:
> I tried a similar patch earlier and got another panic with that. I was
> quite tired at that time and may have made a mistake. I'll test Eric's
> patch either later today or tomorrow.
>
> Ari
>
> 2011/10/22 Eric Dumazet <eric.dumazet@gmail.com>:
>> Ari got kernel panics using tg3 NIC, and bisected to 2669069aacc9 "tg3:
>> enable transmit time stamping."
>>
>> This is because tigon3_dma_hwbug_workaround() might alloc a new skb and
>> free the original. We panic when skb_tx_timestamp() is called on freed
>> skb.
>>
>> Reported-by: Ari Savolainen <ari.m.savolainen@gmail.com>
>> Signed-off-by: Eric Dumazet <eric.dumazet@gmail.com>
>> ---
>>  drivers/net/tg3.c |    8 ++++----
>>  1 file changed, 4 insertions(+), 4 deletions(-)
>>
>> diff --git a/drivers/net/tg3.c b/drivers/net/tg3.c
>> index 4a1374d..6149dc5 100644
>> --- a/drivers/net/tg3.c
>> +++ b/drivers/net/tg3.c
>> @@ -6029,12 +6029,12 @@ static void tg3_tx_skb_unmap(struct tg3_napi *tnapi, u32 entry, int last)
>>
>>  /* Workaround 4GB and 40-bit hardware DMA bugs. */
>>  static int tigon3_dma_hwbug_workaround(struct tg3_napi *tnapi,
>> -                                      struct sk_buff *skb,
>> +                                      struct sk_buff **pskb,
>>                                       u32 *entry, u32 *budget,
>>                                       u32 base_flags, u32 mss, u32 vlan)
>>  {
>>        struct tg3 *tp = tnapi->tp;
>> -       struct sk_buff *new_skb;
>> +       struct sk_buff *new_skb, *skb = *pskb;
>>        dma_addr_t new_addr = 0;
>>        int ret = 0;
>>
>> @@ -6076,7 +6076,7 @@ static int tigon3_dma_hwbug_workaround(struct tg3_napi *tnapi,
>>        }
>>
>>        dev_kfree_skb(skb);
>> -
>> +       *pskb = new_skb;
>>        return ret;
>>  }
>>
>> @@ -6305,7 +6305,7 @@ static netdev_tx_t tg3_start_xmit(struct sk_buff *skb, struct net_device *dev)
>>                 */
>>                entry = tnapi->tx_prod;
>>                budget = tg3_tx_avail(tnapi);
>> -               if (tigon3_dma_hwbug_workaround(tnapi, skb, &entry, &budget,
>> +               if (tigon3_dma_hwbug_workaround(tnapi, &skb, &entry, &budget,
>>                                                base_flags, mss, vlan))
>>                        goto out_unlock;
>>        }
>>
>>
>>
>

^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2011-10-22 13:30 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-10-15  7:50 Kernel panic from tg3 net driver Ari Savolainen
2011-10-20 19:30 ` Ari Savolainen
2011-10-20 19:56   ` David Miller
2011-10-20 20:05     ` Eric Dumazet
2011-10-20 20:11       ` David Miller
2011-10-20 20:17         ` Eric Dumazet
2011-10-20 20:37           ` Ari Savolainen
2011-10-21 10:48             ` RongQing Li
2011-10-22  6:12               ` Ari Savolainen
2011-10-22  6:37                 ` Eric Dumazet
2011-10-22  7:25                   ` [PATCH] tg3: fix tigon3_dma_hwbug_workaround() Eric Dumazet
2011-10-22  7:30                     ` David Miller
2011-10-22  7:54                     ` Ari Savolainen
2011-10-22 13:30                       ` Ari Savolainen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox