From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.16]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4063D425879 for ; Thu, 8 Oct 2026 21:57:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.16 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791496641; cv=none; b=bJgJfGieduolXmQmDYjb69hkgup+8tpqxX5oQHcIaKM/Z7Vq1ECjUwCaLVEH2N5hJ8HThNmLEOJrRjTL+G8qxPgnVGrNtZwngdhz8swO9uGalvpQG4C/7uoCiOLh6R4crDsw0pL+Izp2HkiMCk6Qd+nKT7/bcDppJzQNw15rwkw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791496641; c=relaxed/simple; bh=lTrKTSatH6F5W7QbhomMEPf+C93N56aiNc35nCNlUy4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=cG84M8GN+2+grYVcCUMRFipHVfSE4xy4f4cuRXgbQud38GGdCsJrEcE1I4HoOtVqXL3kkSUofZWuaHan9ssIh6DdJ1nb2szlkaxgpJHjIY3EQ+SYymBm4EAD06Yghc3QKQlhimCT6zCQzkXXUz7gsHKv8iJyKBisl2mSlJnYWvU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=Nag5lFLA; arc=none smtp.client-ip=192.198.163.16 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="Nag5lFLA" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1791496641; x=1823032641; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=lTrKTSatH6F5W7QbhomMEPf+C93N56aiNc35nCNlUy4=; b=Nag5lFLAuLRp5QD/QXVkwPq/Ngcd80rIwnSAoB1s2/vBV60b3+q4Qp8J WrS1ABClzmgdeqG+01auz9aGN+vMP022MNQWUAGaNHHbF/nxdlsrhwzHi +Q5sVHm5klRrSKIJBBh5CX3ci+HAjSCQRpp835DI+74/7rTidxbEnQY1q WLv/sSrDXvyT9Ke7v9EGyTx1crff5c0IBbRwZQy4CwkIRi/ouRcIx5NEh cl6xKqUyBILn4d9/JAg7eWuZvWIG4462WUBTHJquC8OCDaXejnaGSOklb 2q+Ud/kVa32QOizPT47AnG/7n5Khe4tRYLwI1tlTwhsnhH91IpenNiHR/ g==; X-CSE-ConnectionGUID: kuyFicUTTpOO/4g2l+7OUw== X-CSE-MsgGUID: yrUCow/oR/Ss4IR4lg3bGg== X-IronPort-AV: E=McAfee;i="6800,10657,11929"; a="294638" X-IronPort-AV: E=Sophos;i="6.27,147,1787036400"; d="scan'208";a="294638" Received: from orviesa003.jf.intel.com ([10.64.159.143]) by fmvoesa110.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 08 Oct 2026 14:57:17 -0700 X-CSE-ConnectionGUID: Q+7hS1I+QmCPz/CcQV29fA== X-CSE-MsgGUID: 1aP48R++QyC6gjhu+xvwbQ== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.27,147,1787036400"; d="scan'208";a="150408" Received: from anguy11-upstream.jf.intel.com ([10.166.9.133]) by orviesa003.jf.intel.com with ESMTP; 08 Oct 2026 14:57:17 -0700 From: Tony Nguyen To: davem@davemloft.net, kuba@kernel.org, pabeni@redhat.com, edumazet@kernel.org, andrew+netdev@lunn.ch, netdev@vger.kernel.org Cc: Jacob Keller , anthony.l.nguyen@intel.com, maciej.machnikowski@intel.com, przemyslaw.korba@intel.com, grzegorz.nitka@intel.com, sergey.temerkhanov@intel.com, arkadiusz.kubalewski@intel.com, poros@redhat.com, richardcochran@gmail.com, horms@kernel.org, Alexander Nowlin Subject: [PATCH net v2 04/15] ice: set in_use only after preparing Tx timestamp index Date: Thu, 8 Oct 2026 14:56:01 -0700 Message-ID: <20261008215614.1987250-5-anthony.l.nguyen@intel.com> X-Mailer: git-send-email 2.47.1 In-Reply-To: <20261008215614.1987250-1-anthony.l.nguyen@intel.com> References: <20261008215614.1987250-1-anthony.l.nguyen@intel.com> Precedence: bulk X-Mailing-List: netdev@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Jacob Keller The ice_ptp_request_ts() function is used to request a timestamp index for use with a packet. When reserving an index, it sets the start time and saves a pointer to the skb into the appropriate index. The function marks the in_use bit first before doing any of these steps. The IRQ handler which clears the timestamps reads the in_use bits uses a lockless flow for reading the in_use bits to determine which ones are in-use. This is necessary as actually processing a complete timestamp must be able to sleep so we cannot hold the timestamp tracker lock over the entire sequence. Additionally, blocking the Tx hotpath with such a lock indefinitely would be problematic. However, the existing flow now has a very narrow window where the IRQ handler could see a timestamp as in-use but read a stale value for its "start" time. Fix this by ordering the sequence to mark the in_use bit last, and add a memory barrier to prevent re-ordering of the previous writes to setup the index. This was found and reported by Sashiko while reviewing an unrelated change. Closes: https://sashiko.dev/#/patchset/20260821-jk-e825c-minimized-fixes-v1-0-9d0731eb4858%40intel.com?part=7 Fixes: ea9b847cda64 ("ice: enable transmit timestamps for E810 devices") Signed-off-by: Jacob Keller Tested-by: Alexander Nowlin Signed-off-by: Tony Nguyen --- drivers/net/ethernet/intel/ice/ice_ptp.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/drivers/net/ethernet/intel/ice/ice_ptp.c b/drivers/net/ethernet/intel/ice/ice_ptp.c index adc5308baefc..bbb57edcec0f 100644 --- a/drivers/net/ethernet/intel/ice/ice_ptp.c +++ b/drivers/net/ethernet/intel/ice/ice_ptp.c @@ -592,6 +592,9 @@ static void ice_ptp_process_tx_tstamp(struct ice_ptp_tx *tx) bool drop_ts = !link_up; struct sk_buff *skb; + /* Prevent speculative re-ordering of start and skb */ + smp_rmb(); + /* Drop packets which have waited for more than 2 seconds */ if (time_is_before_jiffies(tx->tstamps[idx].start + 2 * HZ)) { drop_ts = true; @@ -2670,11 +2673,13 @@ s8 ice_ptp_request_ts(struct ice_ptp_tx *tx, struct sk_buff *skb) * a reference to the skb and the start time to allow discarding old * requests. */ - set_bit(idx, tx->in_use); - clear_bit(idx, tx->stale); tx->tstamps[idx].start = jiffies; tx->tstamps[idx].skb = skb_get(skb); skb_shinfo(skb)->tx_flags |= SKBTX_IN_PROGRESS; + clear_bit(idx, tx->stale); + /* Ensure index is setup before marking it as used */ + smp_mb__before_atomic(); + set_bit(idx, tx->in_use); ice_trace(tx_tstamp_request, skb, idx); } -- 2.47.1