Netdev List
 help / color / mirror / Atom feed
* Re: Vague maybe ppp-related panic report for 2.6.23-rc9
From: David Miller @ 2007-10-04 20:51 UTC (permalink / raw)
  To: rdreier; +Cc: linux-kernel, netdev, herbert
In-Reply-To: <ada4ph6da05.fsf@cisco.com>

From: Roland Dreier <rdreier@cisco.com>
Date: Thu, 04 Oct 2007 11:12:42 -0700

> Sorry for the lack of detail -- I've just switched to running in the
> console so if I can provoke the crash again I'll get a little more
> info.  I just wanted to mention this in case someone has seen
> something similar or has any good ideas about how to capture debugging
> output on a laptop (when I'm not home and have no other boxes handy).

I don't want to jump the gun on the analysis but it just might
be the packet sharing fixes Herbert put in a short time ago.

What you could do is go back to say rc2 and see if you still get
the panics, then bisect from there to narrow it down.

If rc2 still gives the panic, it's something else, perhaps device
specific.

^ permalink raw reply

* Re: Vague maybe ppp-related panic report for 2.6.23-rc9
From: Roland Dreier @ 2007-10-04 20:53 UTC (permalink / raw)
  To: David Miller; +Cc: linux-kernel, netdev, herbert
In-Reply-To: <20071004.135113.48807663.davem@davemloft.net>

 > I don't want to jump the gun on the analysis but it just might
 > be the packet sharing fixes Herbert put in a short time ago.
 > 
 > What you could do is go back to say rc2 and see if you still get
 > the panics, then bisect from there to narrow it down.
 > 
 > If rc2 still gives the panic, it's something else, perhaps device
 > specific.

OK thanks.  I'm still trying to find a good way to reproduce it, so
I'm going to try to get it to happen with -rc9 while running in the
console, and at least take a picture of the backtrace.  If I find a
good way to make it happen then I'll try rc2 and let you know.

 - R.

^ permalink raw reply

* Skb over panic on TUN device (2.6.18)
From: Max Krasnyansky @ 2007-10-04 20:58 UTC (permalink / raw)
  To: netdev

Folks,

I just got this panic report against 2.6.18 kernel and was wondering if some of you have
an idea of why this might happen.

The panic looks like this:

skb_over_panic: text:ffffffff880463db len:2840 put:1454 head:ffff81005df81000 data:ffff81005df81020
tail:ffff81005df81b38 end:ffff81005df81840 dev:tun0

skb_over_panic: text:ffffffff880463db len:1354 put:1314 head:ffff81007d77ee00 data:ffff81007d77ee20 
tail:ffff81007d77f36a end:ffff81007d77ee80 dev:tun0

Those are two are unrelated and happened at different times.

It's coming from this piece of code:
        if (!(skb = alloc_skb(len + align, GFP_KERNEL))) {
                tun->stats.rx_dropped++;
                return -ENOMEM;
        }

        if (align)
                skb_reserve(skb, align);
        if (memcpy_fromiovec(skb_put(skb, len), iv, len)) {
                tun->stats.rx_dropped++;
                kfree_skb(skb);
                return -EFAULT;
        }

As you can see there is not a whole lot that can go wrong with skb in there.
'align' is set to 0 for TUN devices.

First dumps looks as if skb already had no zero length right after allocation.
In the second dump skb is only 128 byte in size (end - head) even though 
we're clearly allocating and trying to write more than that. 

So, my conclusion at this point is that for whatever reason alloc_skb() returned 
busted SKB. Probably because something in the slab got corrupted.

Any other thoughts ?

Thanx
Max

^ permalink raw reply

* Re: [PATCH] mac80211: Fix TX after monitor interface is converted to managed
From: Michael Wu @ 2007-10-04 21:16 UTC (permalink / raw)
  To: John W. Linville
  Cc: Michael Buesch, Daniel Drake, johannes, netdev, linux-wireless
In-Reply-To: <20071004181516.GH6037@tuxdriver.com>

[-- Attachment #1: Type: text/plain, Size: 1129 bytes --]

On Thursday 04 October 2007 14:15, John W. Linville wrote:
> Falling back on bloat as an argument against a BUG_ON in a
> configuration path seems a bit weak. :-)
>
Seems strong to me. Bloat slows me down and distracts me from what code really 
needs to do. Bloat is an indication that one does not understand what the 
code really needs to do.

> Programming with assertions (and BUG_ON is a form of that) is
> generally a good practice.  Almost any book or other source on
> good programming practices will agree.  Yes, it can be overdone.
> But I don't really think that is the case here, since the check is
> relatively inexpensive and the consequence should it ever *somehow*
> happen could be a something wierd (crash, corruption, etc) w/o any
> other indication of what occured.
>
A line has to be drawn somewhere. There's about a billion places where we can 
add checks like this because if an assumption should ever break, the code 
will break into pieces. However, we don't, and there's no reason to do so 
here other than to needlessly add code just because it makes you feel safer.

-Michael Wu

[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply

* Re: [PATCH] ieee80211_if_set_type: make check for master dev more explicit
From: Michael Wu @ 2007-10-04 21:26 UTC (permalink / raw)
  To: John W. Linville
  Cc: Daniel Drake, johannes-cdvu00un1VgdHxzADdlk8Q,
	netdev-u79uwXL29TY76Z2rM5mHXA,
	linux-wireless-u79uwXL29TY76Z2rM5mHXA
In-Reply-To: <20071004180900.GG6037-2XuSBdqkA4R54TAoqtyWWQ@public.gmane.org>

[-- Attachment #1: Type: text/plain, Size: 705 bytes --]

On Thursday 04 October 2007 14:09, John W. Linville wrote:
> diff --git a/net/mac80211/ieee80211_iface.c
> b/net/mac80211/ieee80211_iface.c index be7e77f..6607b80 100644
> --- a/net/mac80211/ieee80211_iface.c
> +++ b/net/mac80211/ieee80211_iface.c
> @@ -106,7 +106,7 @@ void ieee80211_if_set_type(struct net_device *dev, int
> type) * which already has a hard_start_xmit routine assigned
>  	 * which must not be changed.
>  	 */
> -	if (!dev->hard_start_xmit)
> +	if (dev->type != ARPHRD_IEEE80211)
The standard way of checking for the master device is
dev == sdata->local->mdev

wme.c doesn't quite follow this but that code needs to die anyway.

This does look nicer than the other patch.

-Michael Wu

[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply

* Re: PROBLEM: system freezes on starting ne2k-pci + bridge
From: Stephen Hemminger @ 2007-10-04 21:27 UTC (permalink / raw)
  To: Mirko Parthey; +Cc: netdev
In-Reply-To: <20071004182738.GA4191@augustus.informatik.tu-chemnitz.de>

On Thu, 4 Oct 2007 20:27:38 +0200
mirko.parthey@informatik.tu-chemnitz.de (Mirko Parthey) wrote:

> On Tue, Oct 02, 2007 at 04:12:17PM +0200, I wrote:
> > On a machine running Debian testing, I get complete lockups
> > (Num lock LED not responding anymore)
> > 
> > Kernel versions tried (all of them show this problem):
> > - linux-image-2.6.18-5-amd64 (Debian etch)
> > - linux-image-2.6.22-2-amd64 (Debian testing)
> > - plain kernel.org 2.6.23-rc8-git4 (with allmodconfig and ATKBD=y)
> > 
> > The 2.6.18 kernel sometimes prints
> >   Losing some ticks ... checking if CPU frequency changed.
> >   Your time source seems to be instable or some driver is hogging
> >   interrupts.
> >   rip __do_softirq + 0x53/0xd5
> > before freezing.
> 
> I was able to narrow this down a bit - the problem can be reproduced with 
> the ne2k-pci driver alone, sky2 is not needed.
> Powering off isn't necessary, either.
> 
> Hardware preparation:
> - eth0: Compex ReadyLink 2000 (BNC+TP), ne2k-pci driver,
>   network cable disconnected
> 
> How to reproduce the problem:
> 
> brctl addbr br0
> brctl addif br0 eth0
> ifconfig eth0 0 up
> ifconfig br0 192.168.1.17 up
> sync
> find / >/dev/null &
> ping -b 192.168.1.255
> 
> This will lock up my system, usually within a few seconds.
> 
> Some additional information:
> - I could not reproduce the problem when using eth0 directly,
>   without a bridge.
> - Booting with "maxcpus=1" does not help, the problem remains.
>   My system doesn't boot with "nosmp", otherwise I would have
>   tried this too.
>

Yes its a bug, but the ne2k is old crufty device driver not really
suited to bridging. It lacks:
   * proper speed reporting via ethtool (not much of any ethtool support).
   * doesn't report carrier up/down status




-- 
Stephen Hemminger <shemminger@linux-foundation.org>

^ permalink raw reply

* Re: [PATCH] mac80211: Fix TX after monitor interface is converted to managed
From: Roland Dreier @ 2007-10-04 21:31 UTC (permalink / raw)
  To: John W. Linville
  Cc: Michael Wu, Michael Buesch, Daniel Drake, johannes, netdev,
	linux-wireless
In-Reply-To: <20071004181516.GH6037@tuxdriver.com>

 > Programming with assertions (and BUG_ON is a form of that) is
 > generally a good practice.  Almost any book or other source on
 > good programming practices will agree.  Yes, it can be overdone.
 > But I don't really think that is the case here, since the check is
 > relatively inexpensive and the consequence should it ever *somehow*
 > happen could be a something wierd (crash, corruption, etc) w/o any
 > other indication of what occured.

The problem with BUG_ON is that it kills the whole system.  So every
time you add a BUG_ON into code, you have to weigh whether the problem
you detected is so severe that the right response is to panic.  For
example, I can see panicking on something fundamental like corrupted
page tables.  However I would submit that the wireless stack should
*never* use BUG_ON -- printing a warning and trying to limp on seems
preferable to me.

 - R.

^ permalink raw reply

* net-2.6.24 compile breakage: error: 'ipgre_header' undeclared
From: Kok, Auke @ 2007-10-04 21:49 UTC (permalink / raw)
  To: NetDev; +Cc: David S. Miller, Stephen Hemminger

I'm getting this on net-2.6.24 today:

  CC [M]  net/ipv4/ip_gre.o
net/ipv4/ip_gre.c:1135: error: 'ipgre_header' undeclared here (not in a function)
make[2]: *** [net/ipv4/ip_gre.o] Error 1
make[1]: *** [net/ipv4] Error 2
make[1]: *** Waiting for unfinished jobs....


the git log says sch touched it last:

commit 2c1d70cafc188843ae15a1a504a0a3c9f3c0318d
Author: Stephen Hemminger <shemminger@linux-foundation.org>
Date:   Wed Sep 26 22:19:06 2007 -0700

    [NET]: Move hardware header operations out of netdevice.

    Since hardware header operations are part of the protocol class
    not the device instance, make them into a separate object and
    save memory.

    Signed-off-by: Stephen Hemminger <shemminger@linux-foundation.org>
    Signed-off-by: David S. Miller <davem@davemloft.net>


anyone seen this? let me know if you want my .config.

PS: No, I didn't touch anything besides e1000e in that tree ;)

Auke

^ permalink raw reply

* Re: [PATCH] net: fix kernel_accept() error path
From: James Morris @ 2007-10-04 21:57 UTC (permalink / raw)
  To: Tony Battersby; +Cc: netdev, davem
In-Reply-To: <47054AF5.4050409@cybernetics.com>

On Thu, 4 Oct 2007, Tony Battersby wrote:

> If accept() returns an error, kernel_accept() releases the new socket
> but passes a pointer to the released socket back to the caller.  Make it
> pass back NULL instead.
> 
> Signed-off-by: Tony Battersby <tonyb@cybernetics.com>
> ---
> --- linux-2.6.23-rc9/net/socket.c.bak	2007-10-04 15:21:17.000000000 -0400
> +++ linux-2.6.23-rc9/net/socket.c	2007-10-04 15:21:22.000000000 -0400
> @@ -2230,6 +2230,7 @@ int kernel_accept(struct socket *sock, s
>  	err = sock->ops->accept(sock, *newsock, flags);
>  	if (err < 0) {
>  		sock_release(*newsock);
> +		*newsock = NULL;
>  		goto done;
>  	}
>  

If you get an error back from kernel_accept, you should not be trying to 
use newsock.

-- 
James Morris
<jmorris@namei.org>

^ permalink raw reply

* [PATCH] e1000e: Fix ethtool register test code
From: Auke Kok @ 2007-10-04 22:00 UTC (permalink / raw)
  To: jeff; +Cc: netdev

A merge/cleanup code accidentally dropped 8254x code in and removed
8257x code here. Undo this mistake and use the pci-e relevant register
test similar as to what is in e1000.

Signed-off-by: Auke Kok <auke-jan.h.kok@intel.com>
---

 drivers/net/e1000e/ethtool.c |   14 ++++++++++----
 1 files changed, 10 insertions(+), 4 deletions(-)

diff --git a/drivers/net/e1000e/ethtool.c b/drivers/net/e1000e/ethtool.c
index 3423f33..2e8218f 100644
--- a/drivers/net/e1000e/ethtool.c
+++ b/drivers/net/e1000e/ethtool.c
@@ -784,10 +784,16 @@ static int e1000_reg_test(struct e1000_adapter *adapter, u64 *data)
 	REG_SET_AND_CHECK(E1000_RCTL, before, 0x003FFFFB);
 	REG_SET_AND_CHECK(E1000_TCTL, 0xFFFFFFFF, 0x00000000);
 
-	REG_SET_AND_CHECK(E1000_RCTL, 0xFFFFFFFF, 0x01FFFFFF);
-	REG_PATTERN_TEST(E1000_RDBAL, 0xFFFFF000, 0xFFFFFFFF);
-	REG_PATTERN_TEST(E1000_TXCW, 0x0000FFFF, 0x0000FFFF);
-	REG_PATTERN_TEST(E1000_TDBAL, 0xFFFFF000, 0xFFFFFFFF);
+	REG_SET_AND_CHECK(E1000_RCTL, before, 0xFFFFFFFF);
+	REG_PATTERN_TEST(E1000_RDBAL, 0xFFFFFFF0, 0xFFFFFFFF);
+	if ((mac->type != e1000_ich8lan) &&
+	    (mac->type != e1000_ich9lan))
+		REG_PATTERN_TEST(E1000_TXCW, 0xC000FFFF, 0x0000FFFF);
+	REG_PATTERN_TEST(E1000_TDBAL, 0xFFFFFFF0, 0xFFFFFFFF);
+	REG_PATTERN_TEST(E1000_TIDV, 0x0000FFFF, 0x0000FFFF);
+	for (i = 0; i < mac->rar_entry_count; i++)
+		REG_PATTERN_TEST_ARRAY(E1000_RA, ((i << 1) + 1),
+				       0x8003FFFF, 0xFFFFFFFF);
 
 	for (i = 0; i < mac->mta_reg_count; i++)
 		REG_PATTERN_TEST_ARRAY(E1000_MTA, i, 0xFFFFFFFF, 0xFFFFFFFF);

^ permalink raw reply related

* Re: [PATCH] net: fix kernel_accept() error path
From: David Miller @ 2007-10-04 22:08 UTC (permalink / raw)
  To: jmorris; +Cc: tonyb, netdev
In-Reply-To: <Xine.LNX.4.64.0710041456300.13076@us.intercode.com.au>

From: James Morris <jmorris@namei.org>
Date: Thu, 4 Oct 2007 14:57:33 -0700 (PDT)

> On Thu, 4 Oct 2007, Tony Battersby wrote:
> 
> > If accept() returns an error, kernel_accept() releases the new socket
> > but passes a pointer to the released socket back to the caller.  Make it
> > pass back NULL instead.
> > 
> > Signed-off-by: Tony Battersby <tonyb@cybernetics.com>
> > ---
> > --- linux-2.6.23-rc9/net/socket.c.bak	2007-10-04 15:21:17.000000000 -0400
> > +++ linux-2.6.23-rc9/net/socket.c	2007-10-04 15:21:22.000000000 -0400
> > @@ -2230,6 +2230,7 @@ int kernel_accept(struct socket *sock, s
> >  	err = sock->ops->accept(sock, *newsock, flags);
> >  	if (err < 0) {
> >  		sock_release(*newsock);
> > +		*newsock = NULL;
> >  		goto done;
> >  	}
> >  
> 
> If you get an error back from kernel_accept, you should not be trying to 
> use newsock.

Agreed, the caller should not try to deref the thing, it's
value is undefined.

^ permalink raw reply

* Re: net-2.6.24 compile breakage: error: 'ipgre_header' undeclared
From: David Miller @ 2007-10-04 22:11 UTC (permalink / raw)
  To: auke-jan.h.kok; +Cc: netdev, shemminger
In-Reply-To: <47055FD6.5070801@intel.com>

From: "Kok, Auke" <auke-jan.h.kok@intel.com>
Date: Thu, 04 Oct 2007 14:49:10 -0700

> I'm getting this on net-2.6.24 today:
> 
>   CC [M]  net/ipv4/ip_gre.o
> net/ipv4/ip_gre.c:1135: error: 'ipgre_header' undeclared here (not in a function)
> make[2]: *** [net/ipv4/ip_gre.o] Error 1
> make[1]: *** [net/ipv4] Error 2
> make[1]: *** Waiting for unfinished jobs....
> 
> 
> the git log says sch touched it last:

Please us Stephen's current email address if you really want to reach
him :) It was even mentioned in the commit sign off.  I've fixed it up
in the CC:

>     [NET]: Move hardware header operations out of netdevice.
> 
>     Since hardware header operations are part of the protocol class
>     not the device instance, make them into a separate object and
>     save memory.
> 
>     Signed-off-by: Stephen Hemminger <shemminger@linux-foundation.org>
>     Signed-off-by: David S. Miller <davem@davemloft.net>

Stephen, we need to handle the case where NET_IPGRE_BROADCAST is
not enabled.  ipgre_header() is only compiled in when that is
set, but you reference it unconditionally.

^ permalink raw reply

* Re: [PATCH] net: fix kernel_accept() error path
From: Tony Battersby @ 2007-10-04 22:12 UTC (permalink / raw)
  To: James Morris; +Cc: netdev, davem
In-Reply-To: <Xine.LNX.4.64.0710041456300.13076@us.intercode.com.au>

James Morris wrote:
> On Thu, 4 Oct 2007, Tony Battersby wrote:
>
>   
>> If accept() returns an error, kernel_accept() releases the new socket
>> but passes a pointer to the released socket back to the caller.  Make it
>> pass back NULL instead.
>>
>> Signed-off-by: Tony Battersby <tonyb@cybernetics.com>
>> ---
>> --- linux-2.6.23-rc9/net/socket.c.bak	2007-10-04 15:21:17.000000000 -0400
>> +++ linux-2.6.23-rc9/net/socket.c	2007-10-04 15:21:22.000000000 -0400
>> @@ -2230,6 +2230,7 @@ int kernel_accept(struct socket *sock, s
>>  	err = sock->ops->accept(sock, *newsock, flags);
>>  	if (err < 0) {
>>  		sock_release(*newsock);
>> +		*newsock = NULL;
>>  		goto done;
>>  	}
>>  
>>     
>
> If you get an error back from kernel_accept, you should not be trying to 
> use newsock.
>
>   

Here is an example of what I would consider "reasonable code" that would
fail:

int example()
{
    struct socket *conn_socket = NULL;
    int err;

    ...

    if ((err = kernel_accept(sock, &conn_socket, 0)) < 0)
        goto out_cleanup;

    [do whatever with conn_socket]

 out_cleanup:

    if (conn_socket != NULL)
        sock_release(&conn_socket);

    return err;
}

Without the patch, the double sock_release() will cause a BUG().

Also compare to sock_create_lite(), which sets *res to NULL on error.

Tony


^ permalink raw reply

* Re: [PATCH] mac80211: Fix TX after monitor interface is converted to managed
From: John W. Linville @ 2007-10-04 22:13 UTC (permalink / raw)
  To: Roland Dreier
  Cc: Michael Wu, Michael Buesch, Daniel Drake, johannes, netdev,
	linux-wireless
In-Reply-To: <ada4ph6bm8h.fsf@cisco.com>

On Thu, Oct 04, 2007 at 02:31:26PM -0700, Roland Dreier wrote:
>  > Programming with assertions (and BUG_ON is a form of that) is
>  > generally a good practice.  Almost any book or other source on

> The problem with BUG_ON is that it kills the whole system.  So every
> time you add a BUG_ON into code, you have to weigh whether the problem
> you detected is so severe that the right response is to panic.  For
> example, I can see panicking on something fundamental like corrupted
> page tables.  However I would submit that the wireless stack should
> *never* use BUG_ON -- printing a warning and trying to limp on seems
> preferable to me.

OK, I'll buy that as an argument to use WARN_ON instead of BUG_ON.
But it doesn't invalidate the desire to have some sort of assertion.

John
-- 
John W. Linville
linville@tuxdriver.com

^ permalink raw reply

* Re: [PATCH] ieee80211_if_set_type: make check for master dev more explicit
From: John W. Linville @ 2007-10-04 23:02 UTC (permalink / raw)
  To: Michael Wu
  Cc: Daniel Drake, johannes-cdvu00un1VgdHxzADdlk8Q,
	netdev-u79uwXL29TY76Z2rM5mHXA,
	linux-wireless-u79uwXL29TY76Z2rM5mHXA
In-Reply-To: <200710041726.11744.flamingice-R9e9/4HEdknk1uMJSBkQmQ@public.gmane.org>

On Thu, Oct 04, 2007 at 05:26:11PM -0400, Michael Wu wrote:
> On Thursday 04 October 2007 14:09, John W. Linville wrote:
> > diff --git a/net/mac80211/ieee80211_iface.c
> > b/net/mac80211/ieee80211_iface.c index be7e77f..6607b80 100644
> > --- a/net/mac80211/ieee80211_iface.c
> > +++ b/net/mac80211/ieee80211_iface.c
> > @@ -106,7 +106,7 @@ void ieee80211_if_set_type(struct net_device *dev, int
> > type) * which already has a hard_start_xmit routine assigned
> >  	 * which must not be changed.
> >  	 */
> > -	if (!dev->hard_start_xmit)
> > +	if (dev->type != ARPHRD_IEEE80211)
> The standard way of checking for the master device is
> dev == sdata->local->mdev
> 
> wme.c doesn't quite follow this but that code needs to die anyway.
> 
> This does look nicer than the other patch.

Alright...better?

---

From: John W. Linville <linville-2XuSBdqkA4R54TAoqtyWWQ@public.gmane.org>
Subject: [PATCH] ieee80211_if_set_type: make check for master dev more explicit

Problem description by Daniel Drake <dsd-aBrp7R+bbdUdnm+yROfE0A@public.gmane.org>:

"This sequence of events causes loss of connectivity:

<plug in>
<associate as normal in managed mode>
ifconfig eth7 down
iwconfig eth7 mode monitor
ifconfig eth7 up
ifconfig eth7 down
iwconfig eth7 mode managed
<associate as normal>

At this point you are associated but TX does not work. This is because
the eth7 hard_start_xmit is still ieee80211_monitor_start_xmit."

The problem is caused by ieee80211_if_set_type checking for a non-zero
hard_start_xmit pointer value in order to avoid changing that value for
master devices.  The fix is to make that check more explicitly linked to
master devices rather than simply checking if the value has been
previously set.

CC: Daniel Drake <dsd-aBrp7R+bbdUdnm+yROfE0A@public.gmane.org>
Signed-off-by: John W. Linville <linville-2XuSBdqkA4R54TAoqtyWWQ@public.gmane.org>
---
 net/mac80211/ieee80211_iface.c |    2 +-
 1 files changed, 1 insertions(+), 1 deletions(-)

diff --git a/net/mac80211/ieee80211_iface.c b/net/mac80211/ieee80211_iface.c
index be7e77f..43e505d 100644
--- a/net/mac80211/ieee80211_iface.c
+++ b/net/mac80211/ieee80211_iface.c
@@ -106,7 +106,7 @@ void ieee80211_if_set_type(struct net_device *dev, int type)
 	 * which already has a hard_start_xmit routine assigned
 	 * which must not be changed.
 	 */
-	if (!dev->hard_start_xmit)
+	if (dev != sdata->local->mdev)
 		dev->hard_start_xmit = ieee80211_subif_start_xmit;
 
 	/*
-- 
1.5.2.4


-- 
John W. Linville
linville-2XuSBdqkA4R54TAoqtyWWQ@public.gmane.org

^ permalink raw reply related

* Re: [Bugme-new] [Bug 9124] New: Netconsole race crashed the system
From: Andrew Morton @ 2007-10-04 23:43 UTC (permalink / raw)
  To: tina.yang; +Cc: bugme-daemon, netdev
In-Reply-To: <bug-9124-10286@http.bugzilla.kernel.org/>


(Please resoind by emailed reply-to-all, not via the bugzilla web interface)

On Thu,  4 Oct 2007 16:24:18 -0700 (PDT)
bugme-daemon@bugzilla.kernel.org wrote:

> http://bugzilla.kernel.org/show_bug.cgi?id=9124
> 
>            Summary: Netconsole race crashed the system
>            Product: Networking
>            Version: 2.5
>      KernelVersion: 2.6.9, 2.6.18, 2.6.23
>           Platform: All
>         OS/Version: Linux
>               Tree: Mainline
>             Status: NEW
>           Severity: high
>           Priority: P1
>          Component: Other
>         AssignedTo: acme@ghostprotocols.net
>         ReportedBy: tina.yang@oracle.com
> 
> 
> Most recent kernel where this bug did not occur:
> Think the problem has always been there.
> Distribution:
> Hardware Environment:
> DELL PowerEdge 2650 (x86)
> DELL PowerEdge 2850(x86_64)
> HP ProLiant DL380 G5 (x86_64) 
> with various NICs - e1000, tg3, bnx2
> Software Environment:
> 2.6.9, 2.6.18, 2.6.23
> Problem Description:
> On 2.6.18 found this issue on e1000 and tg3. On mainline 2.6.23-rc* found this
>  issue on e100,tgs and bnx2.  It either panicked
> at netdevice.h:890 or hung the system, and sometimes depending
> on which NIC are used, the following console message,
>  e1000:
>       "e1000: eth0: e1000_clean_tx_irq: Detected Tx Unit Hang"
>  tg3:
>       "NETDEV WATCHDOG: eth4: transmit timed out"
>       "tg3: eth4: transmit timed out, resetting"
> 
> Steps to reproduce:
> 1. On 2.6.18 (both x86_x86_64) insert netconsole module.(NIC: e1000 and tg3)
> 2. Run a moderate io load , preferably fio - one process doing async+directIO
> using libaio 
> 
> fio jobfile:
> [global]
> iodepth=1024
> iodepth_batch=60
> randrepeat=1
> size=1024m
> directory=/home/oracle
> numjobs=2
> [job1]
> bs=8k
> direct=1
> ioengine=libaio
> rw=randrw
> filename=file1:file2
> 
> 3. From second console as root do " echo t > /proc/sysrq-trigger"
> 
> Machine will instantly hang.
> 
> 
> Crash stack captured on 2.6.9
>        PANIC: "kernel BUG at include/linux/netdevice.h:888!"
> #0 [ 23c5e60] disk_dump at f9ca71a2
> #1 [ 23c5e64] printk at 21228d6
> #2 [ 23c5e70] freeze_other_cpus at f9ca6ef5
> #3 [ 23c5e80] start_disk_dump at f9ca6fa0
> #4 [ 23c5e90] try_crashdump at 2133766
> #5 [ 23c5e98] die at 2106354
> #6 [ 23c5ecc] do_invalid_op at 210672f
> #7 [ 23c5f7c] error_code (via invalid_op) at fffecede
>    EAX: 00000006  EBX: 00200202  ECX: 00000000  EDX: df287000  EBP: e05ca000
>    DS:  007b      ESI: 00000001  ES:  007b      EDI: e05ca240 
>    CS:  0060      EIP: f8c82a08  ERR: ffffffff  EFLAGS: 00210046 
> #8 [ 23c5fb8] tg3_poll at f8c82a08
> #9 [ 23c5fd0] net_rx_action at 227a8da
> #10 [ 23c5fe8] __do_softirq at 2126422
> --- <soft IRQ> ---
> #0 [25c71cac] do_softirq at 2108460
> #1 [25c71cb4] dev_queue_xmit at 227a0d2
> #2 [25c71ccc] ip_finish_output at 229288d
> #3 [25c71ce4] ip_queue_xmit at 2292fa9
> #4 [25c71dac] tcp_transmit_skb at 22a0ff7
> #5 [25c71dec] tcp_write_xmit at 22a1901
> #6 [25c71e10] tcp_sendmsg at 2297d6d
> #7 [25c71e80] sock_aio_write at 2272512
> #8 [25c71eec] do_sync_write at 215a444
> #9 [25c71f88] vfs_write at 215a53a
> #10 [25c71fa4] sys_write at 215a5f4
> #11 [25c71fc0] system_call at fffec219 
> 
> net_device in memory,
>   name = "eth0\000\000\000\000\000\000\000\000\000\000\000", 
>  ...
> 
> 
> Crash stack captured on 2.6.18
>        PANIC: "kernel BUG at include/linux/netdevice.h:890!"
>  #0 [c072ce30] crash_kexec at c044418a
>  #1 [c072ce74] die at c04054d0
>  #2 [c072cea4] do_invalid_op at c0405c20
>  #3 [c072cf54] error_code (via invalid_op) at c0404ab3
>     EAX: 00000007  EBX: 00000202  ECX: 00000000  EDX: f6d9c000  EBP: f6d9c400 
>     DS:  007b      ESI: 00000001  ES:  007b      EDI: cb02b280 
>     CS:  0060      EIP: f8927791  ERR: ffffffff  EFLAGS: 00010046 
>  #4 [c072cf88] tg3_poll at f8927791
> --- <soft IRQ> ---
>  #0 [f7e54f60] do_softirq at c0406433
>  #1 [f7e54f6c] do_IRQ at c0406425
>  #2 [f7e54fb4] cpu_idle at c0402c8e
> 
> net_device in memory,
>   name = "eth4\000\000\000\000\000\000\000\000\000\000\000", 
>   name_hlist = {
>     next = 0x0, 
>     pprev = 0xc07d0148
>   }, 
>   ...
> 

OK, but in my 2.6.18, include/linux/netdevice.h:890 is a
local_irq_restore() in netif_rx_complete().  I don't see how that can go
BUG.

Does your 2.6.18 have any patches applied?

Please tell us what is at include/linux/netdevice.h:890 in your 2.6.18
tree.


^ permalink raw reply

* Re: [PATCH] net: fix kernel_accept() error path
From: David Miller @ 2007-10-04 23:55 UTC (permalink / raw)
  To: tonyb; +Cc: jmorris, netdev
In-Reply-To: <47056565.50803@cybernetics.com>

From: Tony Battersby <tonyb@cybernetics.com>
Date: Thu, 04 Oct 2007 18:12:53 -0400

> Here is an example of what I would consider "reasonable code" that would
> fail:
> 
> int example()
> {
>     struct socket *conn_socket = NULL;
>     int err;
> 
>     ...
> 
>     if ((err = kernel_accept(sock, &conn_socket, 0)) < 0)
>         goto out_cleanup;
> 
>     [do whatever with conn_socket]
> 
>  out_cleanup:
> 
>     if (conn_socket != NULL)
>         sock_release(&conn_socket);
> 
>     return err;
> }

This is a grey area.

I'd say you shouldn't be trying to do cleanups on conn_socket unless
kernel_accept() gave you a success return.

However, kernel_accept() is guilty of leaving a stray pointer
in conn_socket, in fact a reference to freed memory.  So
from that perspective we should put your patch in.

Please resubmit, at least to me under seperate cover,thanks.

^ permalink raw reply

* Re: netconsole problems
From: Matt Mackall @ 2007-10-05  0:27 UTC (permalink / raw)
  To: Tina Yang; +Cc: netdev
In-Reply-To: <47052A0A.2080100@oracle.com>

On Thu, Oct 04, 2007 at 10:59:38AM -0700, Tina Yang wrote:
> We recently run into a few problems with netconsole
> in at least 2.6.9, 2.6.18 and 2.6.23.  It either panicked
> at netdevice.h:890 or hung the system, and sometimes depending
> on which NIC we are using, the following console message,
> e1000:
>      "e1000: eth0: e1000_clean_tx_irq: Detected Tx Unit Hang"
> tg3:
>      "NETDEV WATCHDOG: eth4: transmit timed out"
>      "tg3: eth4: transmit timed out, resetting"
> 
> The postmortem vmcore analysis indicated race between normal
> network stack (net_rx_action) and netpoll, and disabling the
> following code segment cures all the problems.

That doesn't tell us much. Can you provide any more details? Like the
call chains on both sides?
 
> netpoll.c
>    178         /* Process pending work on NIC */
>    179         np->dev->poll_controller(np->dev);
>    180         if (np->dev->poll)
>    181                 poll_napi(np);

There are a couple different places this gets called, and for
different reasons. If we have a -large- netconsole dump (like
sysrq-t), we'll swallow up all of our SKB pool and may get stuck waiting
for the NIC to send them (because it's waiting to hand packets back to
the kernel and has no free buffers for outgoing packets).

> Big or small, there seems to be several race windows in the code,
> and fixing them probably has consequence on overall system performance.

Yes, the networking layer goes to great lengths to avoid having any
locking in its fast paths and we don't want to undo any of that
effort.

> Maybe this code should only run when the machine is single-threaded ?

In the not-very-distant future, such machines will be extremely rare.

-- 
Mathematics is the supreme nostalgia of our time.

^ permalink raw reply

* [PATCH net-2.6.24] ip_gre: build fix
From: Stephen Hemminger @ 2007-10-05  0:47 UTC (permalink / raw)
  To: David Miller; +Cc: auke-jan.h.kok, netdev
In-Reply-To: <20071004.151108.82373575.davem@davemloft.net>

IPGRE only uses header_ops in the case of CONFIG_NET_IPGRE_BROADCAST.

Signed-off-by: Stephen Hemminger <shemminger@linux-foundation.org>


--- a/net/ipv4/ip_gre.c	2007-10-04 17:40:34.000000000 -0700
+++ b/net/ipv4/ip_gre.c	2007-10-04 17:41:20.000000000 -0700
@@ -1092,6 +1092,10 @@ static int ipgre_header(struct sk_buff *
 	return -t->hlen;
 }
 
+static const struct header_ops ipgre_header_ops = {
+	.create	= ipgre_header,
+};
+
 static int ipgre_open(struct net_device *dev)
 {
 	struct ip_tunnel *t = netdev_priv(dev);
@@ -1131,10 +1135,6 @@ static int ipgre_close(struct net_device
 
 #endif
 
-static const struct header_ops ipgre_header_ops = {
-	.create	= ipgre_header,
-};
-
 static void ipgre_tunnel_setup(struct net_device *dev)
 {
 	dev->uninit		= ipgre_tunnel_uninit;

^ permalink raw reply

* Re: Vague maybe ppp-related panic report for 2.6.23-rc9
From: Herbert Xu @ 2007-10-05  0:49 UTC (permalink / raw)
  To: David Miller; +Cc: rdreier, linux-kernel, netdev
In-Reply-To: <20071004.135113.48807663.davem@davemloft.net>

On Thu, Oct 04, 2007 at 01:51:13PM -0700, David Miller wrote:
> 
> I don't want to jump the gun on the analysis but it just might
> be the packet sharing fixes Herbert put in a short time ago.

I think the only change of mine that could affect ppp over a
serial line is this one.  I couldn't see anything obvious in
it but maybe someone else can.

Cheers,
-- 
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
--
2a38b775b77f99308a4e571c13d908df78ac5e57
diff --git a/drivers/net/ppp_generic.c b/drivers/net/ppp_generic.c
index 7e21342..4b49d0e 100644
--- a/drivers/net/ppp_generic.c
+++ b/drivers/net/ppp_generic.c
@@ -1525,7 +1525,7 @@ ppp_input_error(struct ppp_channel *chan, int code)
 static void
 ppp_receive_frame(struct ppp *ppp, struct sk_buff *skb, struct channel *pch)
 {
-	if (skb->len >= 2) {
+	if (pskb_may_pull(skb, 2)) {
 #ifdef CONFIG_PPP_MULTILINK
 		/* XXX do channel-level decompression here */
 		if (PPP_PROTO(skb) == PPP_MP)
@@ -1577,7 +1577,7 @@ ppp_receive_nonmp_frame(struct ppp *ppp, struct sk_buff *skb)
 		if (ppp->vj == 0 || (ppp->flags & SC_REJ_COMP_TCP))
 			goto err;
 
-		if (skb_tailroom(skb) < 124) {
+		if (skb_tailroom(skb) < 124 || skb_cloned(skb)) {
 			/* copy to a new sk_buff with more tailroom */
 			ns = dev_alloc_skb(skb->len + 128);
 			if (ns == 0) {
@@ -1648,23 +1648,29 @@ ppp_receive_nonmp_frame(struct ppp *ppp, struct sk_buff *skb)
 		/* check if the packet passes the pass and active filters */
 		/* the filter instructions are constructed assuming
 		   a four-byte PPP header on each packet */
-		*skb_push(skb, 2) = 0;
-		if (ppp->pass_filter
-		    && sk_run_filter(skb, ppp->pass_filter,
-				     ppp->pass_len) == 0) {
-			if (ppp->debug & 1)
-				printk(KERN_DEBUG "PPP: inbound frame not passed\n");
-			kfree_skb(skb);
-			return;
-		}
-		if (!(ppp->active_filter
-		      && sk_run_filter(skb, ppp->active_filter,
-				       ppp->active_len) == 0))
-			ppp->last_recv = jiffies;
-		skb_pull(skb, 2);
-#else
-		ppp->last_recv = jiffies;
+		if (ppp->pass_filter || ppp->active_filter) {
+			if (skb_cloned(skb) &&
+			    pskb_expand_head(skb, 0, 0, GFP_ATOMIC))
+				goto err;
+
+			*skb_push(skb, 2) = 0;
+			if (ppp->pass_filter
+			    && sk_run_filter(skb, ppp->pass_filter,
+					     ppp->pass_len) == 0) {
+				if (ppp->debug & 1)
+					printk(KERN_DEBUG "PPP: inbound frame "
+					       "not passed\n");
+				kfree_skb(skb);
+				return;
+			}
+			if (!(ppp->active_filter
+			      && sk_run_filter(skb, ppp->active_filter,
+					       ppp->active_len) == 0))
+				ppp->last_recv = jiffies;
+			__skb_pull(skb, 2);
+		} else
 #endif /* CONFIG_PPP_FILTER */
+			ppp->last_recv = jiffies;
 
 		if ((ppp->dev->flags & IFF_UP) == 0
 		    || ppp->npmode[npi] != NPMODE_PASS) {
@@ -1762,7 +1768,7 @@ ppp_receive_mp_frame(struct ppp *ppp, struct sk_buff *skb, struct channel *pch)
 	struct channel *ch;
 	int mphdrlen = (ppp->flags & SC_MP_SHORTSEQ)? MPHDRLEN_SSN: MPHDRLEN;
 
-	if (!pskb_may_pull(skb, mphdrlen) || ppp->mrru == 0)
+	if (!pskb_may_pull(skb, mphdrlen + 1) || ppp->mrru == 0)
 		goto err;		/* no good, throw it away */
 
 	/* Decode sequence number and begin/end bits */

^ permalink raw reply related

* Re: [PATCH net-2.6.24] ip_gre: build fix
From: David Miller @ 2007-10-05  0:54 UTC (permalink / raw)
  To: shemminger; +Cc: auke-jan.h.kok, netdev
In-Reply-To: <20071004174738.00c64226@freepuppy.rosehill>

From: Stephen Hemminger <shemminger@linux-foundation.org>
Date: Thu, 4 Oct 2007 17:47:38 -0700

> IPGRE only uses header_ops in the case of CONFIG_NET_IPGRE_BROADCAST.
> 
> Signed-off-by: Stephen Hemminger <shemminger@linux-foundation.org>

Applied, thanks Stephen.

^ permalink raw reply

* Re: netconsole problems
From: Tina Yang @ 2007-10-05  1:22 UTC (permalink / raw)
  To: Matt Mackall; +Cc: netdev
In-Reply-To: <20071005002754.GH19691@waste.org>

Matt Mackall wrote:
> On Thu, Oct 04, 2007 at 10:59:38AM -0700, Tina Yang wrote:
>   
>> We recently run into a few problems with netconsole
>> in at least 2.6.9, 2.6.18 and 2.6.23.  It either panicked
>> at netdevice.h:890 or hung the system, and sometimes depending
>> on which NIC we are using, the following console message,
>> e1000:
>>      "e1000: eth0: e1000_clean_tx_irq: Detected Tx Unit Hang"
>> tg3:
>>      "NETDEV WATCHDOG: eth4: transmit timed out"
>>      "tg3: eth4: transmit timed out, resetting"
>>
>> The postmortem vmcore analysis indicated race between normal
>> network stack (net_rx_action) and netpoll, and disabling the
>> following code segment cures all the problems.
>>     
>
> That doesn't tell us much. Can you provide any more details? Like the
> call chains on both sides?
>   
       I've filed a bug with details, 
http://bugzilla.kernel.org/show_bug.cgi?id=9124
       Basically for 2.6.9, tg3_poll from net_rx_action had panicked 
because
        __LINK_STATE_RX_SCHED is not set, and the net_device from the vmcore
       showed the device is not on any of the per_cpu poll_list at the time.
       For 2.6.18, same crash, however, the net_device showed the dev is 
on one
       poll_list.  The discrepancy between the two crashes can be 
explained as follows,
       1) netpoll on cpu0 called dev->poll(), removed the dev from the 
list and enabled the interrupt
       2) net_rx_action on cpu1 called dev->poll() again, panicked on 
removing the dev from the list
       3) interrupt delivered to, say cpu2, and scheduled the device again

       Because of the race, it could result in a condition where you 
could have more than
       one cpu deal with interrupt (hw or soft) from the same device at 
the same time ?
     
>  
>   
>> netpoll.c
>>    178         /* Process pending work on NIC */
>>    179         np->dev->poll_controller(np->dev);
>>    180         if (np->dev->poll)
>>    181                 poll_napi(np);
>>     
>
> There are a couple different places this gets called, and for
> different reasons. If we have a -large- netconsole dump (like
> sysrq-t), we'll swallow up all of our SKB pool and may get stuck waiting
> for the NIC to send them (because it's waiting to hand packets back to
> the kernel and has no free buffers for outgoing packets).
>
>   
       But the softirq will process and free them ?  The problem is the 
poll_list
       is in a per_cpu structure, shouldn't be manipulated by another 
cpu where
       netpoll is running.
>> Big or small, there seems to be several race windows in the code,
>> and fixing them probably has consequence on overall system performance.
>>     
>
> Yes, the networking layer goes to great lengths to avoid having any
> locking in its fast paths and we don't want to undo any of that
> effort.
>
>   
>> Maybe this code should only run when the machine is single-threaded ?
>>     
>
> In the not-very-distant future, such machines will be extremely rare.
>
>   
       I meant the special case such as in crash mode.


^ permalink raw reply

* Re: [Bugme-new] [Bug 9124] New: Netconsole race crashed the system
From: Tina Yang @ 2007-10-05  1:27 UTC (permalink / raw)
  To: Andrew Morton; +Cc: bugme-daemon, netdev
In-Reply-To: <20071004164343.ca01c06b.akpm@linux-foundation.org>

[-- Attachment #1: Type: text/plain, Size: 4885 bytes --]

Andrew Morton wrote:
> (Please resoind by emailed reply-to-all, not via the bugzilla web interface)
>
> On Thu,  4 Oct 2007 16:24:18 -0700 (PDT)
> bugme-daemon@bugzilla.kernel.org wrote:
>
>   
>> http://bugzilla.kernel.org/show_bug.cgi?id=9124
>>
>>            Summary: Netconsole race crashed the system
>>            Product: Networking
>>            Version: 2.5
>>      KernelVersion: 2.6.9, 2.6.18, 2.6.23
>>           Platform: All
>>         OS/Version: Linux
>>               Tree: Mainline
>>             Status: NEW
>>           Severity: high
>>           Priority: P1
>>          Component: Other
>>         AssignedTo: acme@ghostprotocols.net
>>         ReportedBy: tina.yang@oracle.com
>>
>>
>> Most recent kernel where this bug did not occur:
>> Think the problem has always been there.
>> Distribution:
>> Hardware Environment:
>> DELL PowerEdge 2650 (x86)
>> DELL PowerEdge 2850(x86_64)
>> HP ProLiant DL380 G5 (x86_64) 
>> with various NICs - e1000, tg3, bnx2
>> Software Environment:
>> 2.6.9, 2.6.18, 2.6.23
>> Problem Description:
>> On 2.6.18 found this issue on e1000 and tg3. On mainline 2.6.23-rc* found this
>>  issue on e100,tgs and bnx2.  It either panicked
>> at netdevice.h:890 or hung the system, and sometimes depending
>> on which NIC are used, the following console message,
>>  e1000:
>>       "e1000: eth0: e1000_clean_tx_irq: Detected Tx Unit Hang"
>>  tg3:
>>       "NETDEV WATCHDOG: eth4: transmit timed out"
>>       "tg3: eth4: transmit timed out, resetting"
>>
>> Steps to reproduce:
>> 1. On 2.6.18 (both x86_x86_64) insert netconsole module.(NIC: e1000 and tg3)
>> 2. Run a moderate io load , preferably fio - one process doing async+directIO
>> using libaio 
>>
>> fio jobfile:
>> [global]
>> iodepth=1024
>> iodepth_batch=60
>> randrepeat=1
>> size=1024m
>> directory=/home/oracle
>> numjobs=2
>> [job1]
>> bs=8k
>> direct=1
>> ioengine=libaio
>> rw=randrw
>> filename=file1:file2
>>
>> 3. From second console as root do " echo t > /proc/sysrq-trigger"
>>
>> Machine will instantly hang.
>>
>>
>> Crash stack captured on 2.6.9
>>        PANIC: "kernel BUG at include/linux/netdevice.h:888!"
>> #0 [ 23c5e60] disk_dump at f9ca71a2
>> #1 [ 23c5e64] printk at 21228d6
>> #2 [ 23c5e70] freeze_other_cpus at f9ca6ef5
>> #3 [ 23c5e80] start_disk_dump at f9ca6fa0
>> #4 [ 23c5e90] try_crashdump at 2133766
>> #5 [ 23c5e98] die at 2106354
>> #6 [ 23c5ecc] do_invalid_op at 210672f
>> #7 [ 23c5f7c] error_code (via invalid_op) at fffecede
>>    EAX: 00000006  EBX: 00200202  ECX: 00000000  EDX: df287000  EBP: e05ca000
>>    DS:  007b      ESI: 00000001  ES:  007b      EDI: e05ca240 
>>    CS:  0060      EIP: f8c82a08  ERR: ffffffff  EFLAGS: 00210046 
>> #8 [ 23c5fb8] tg3_poll at f8c82a08
>> #9 [ 23c5fd0] net_rx_action at 227a8da
>> #10 [ 23c5fe8] __do_softirq at 2126422
>> --- <soft IRQ> ---
>> #0 [25c71cac] do_softirq at 2108460
>> #1 [25c71cb4] dev_queue_xmit at 227a0d2
>> #2 [25c71ccc] ip_finish_output at 229288d
>> #3 [25c71ce4] ip_queue_xmit at 2292fa9
>> #4 [25c71dac] tcp_transmit_skb at 22a0ff7
>> #5 [25c71dec] tcp_write_xmit at 22a1901
>> #6 [25c71e10] tcp_sendmsg at 2297d6d
>> #7 [25c71e80] sock_aio_write at 2272512
>> #8 [25c71eec] do_sync_write at 215a444
>> #9 [25c71f88] vfs_write at 215a53a
>> #10 [25c71fa4] sys_write at 215a5f4
>> #11 [25c71fc0] system_call at fffec219 
>>
>> net_device in memory,
>>   name = "eth0\000\000\000\000\000\000\000\000\000\000\000", 
>>  ...
>>
>>
>> Crash stack captured on 2.6.18
>>        PANIC: "kernel BUG at include/linux/netdevice.h:890!"
>>  #0 [c072ce30] crash_kexec at c044418a
>>  #1 [c072ce74] die at c04054d0
>>  #2 [c072cea4] do_invalid_op at c0405c20
>>  #3 [c072cf54] error_code (via invalid_op) at c0404ab3
>>     EAX: 00000007  EBX: 00000202  ECX: 00000000  EDX: f6d9c000  EBP: f6d9c400 
>>     DS:  007b      ESI: 00000001  ES:  007b      EDI: cb02b280 
>>     CS:  0060      EIP: f8927791  ERR: ffffffff  EFLAGS: 00010046 
>>  #4 [c072cf88] tg3_poll at f8927791
>> --- <soft IRQ> ---
>>  #0 [f7e54f60] do_softirq at c0406433
>>  #1 [f7e54f6c] do_IRQ at c0406425
>>  #2 [f7e54fb4] cpu_idle at c0402c8e
>>
>> net_device in memory,
>>   name = "eth4\000\000\000\000\000\000\000\000\000\000\000", 
>>   name_hlist = {
>>     next = 0x0, 
>>     pprev = 0xc07d0148
>>   }, 
>>   ...
>>
>>     
>
> OK, but in my 2.6.18, include/linux/netdevice.h:890 is a
> local_irq_restore() in netif_rx_complete().  I don't see how that can go
> BUG.
>
> Does your 2.6.18 have any patches applied?
>
> Please tell us what is at include/linux/netdevice.h:890 in your 2.6.18
> tree.
>
> -
> To unsubscribe from this list: send the line "unsubscribe netdev" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
>   

    netdevice.h attached.
    890         BUG_ON(!test_bit(__LINK_STATE_RX_SCHED, &dev->state));
   

[-- Attachment #2: netdevice.h --]
[-- Type: text/plain, Size: 32237 bytes --]

/*
 * INET		An implementation of the TCP/IP protocol suite for the LINUX
 *		operating system.  INET is implemented using the  BSD Socket
 *		interface as the means of communication with the user level.
 *
 *		Definitions for the Interfaces handler.
 *
 * Version:	@(#)dev.h	1.0.10	08/12/93
 *
 * Authors:	Ross Biro
 *		Fred N. van Kempen, <waltje@uWalt.NL.Mugnet.ORG>
 *		Corey Minyard <wf-rch!minyard@relay.EU.net>
 *		Donald J. Becker, <becker@cesdis.gsfc.nasa.gov>
 *		Alan Cox, <Alan.Cox@linux.org>
 *		Bjorn Ekwall. <bj0rn@blox.se>
 *              Pekka Riikonen <priikone@poseidon.pspt.fi>
 *
 *		This program is free software; you can redistribute it and/or
 *		modify it under the terms of the GNU General Public License
 *		as published by the Free Software Foundation; either version
 *		2 of the License, or (at your option) any later version.
 *
 *		Moved to /usr/include/linux for NET3
 */
#ifndef _LINUX_NETDEVICE_H
#define _LINUX_NETDEVICE_H

#include <linux/if.h>
#include <linux/if_ether.h>
#include <linux/if_packet.h>

#ifdef __KERNEL__
#include <asm/atomic.h>
#include <asm/cache.h>
#include <asm/byteorder.h>

#include <linux/device.h>
#include <linux/percpu.h>
#include <linux/dmaengine.h>

struct divert_blk;
struct vlan_group;
struct ethtool_ops;
struct netpoll_info;
					/* source back-compat hooks */
#define SET_ETHTOOL_OPS(netdev,ops) \
	( (netdev)->ethtool_ops = (ops) )

#define HAVE_ALLOC_NETDEV		/* feature macro: alloc_xxxdev
					   functions are available. */
#define HAVE_FREE_NETDEV		/* free_netdev() */
#define HAVE_NETDEV_PRIV		/* netdev_priv() */

#define NET_XMIT_SUCCESS	0
#define NET_XMIT_DROP		1	/* skb dropped			*/
#define NET_XMIT_CN		2	/* congestion notification	*/
#define NET_XMIT_POLICED	3	/* skb is shot by police	*/
#define NET_XMIT_BYPASS		4	/* packet does not leave via dequeue;
					   (TC use only - dev_queue_xmit
					   returns this as NET_XMIT_SUCCESS) */

/* Backlog congestion levels */
#define NET_RX_SUCCESS		0   /* keep 'em coming, baby */
#define NET_RX_DROP		1  /* packet dropped */
#define NET_RX_CN_LOW		2   /* storm alert, just in case */
#define NET_RX_CN_MOD		3   /* Storm on its way! */
#define NET_RX_CN_HIGH		4   /* The storm is here */
#define NET_RX_BAD		5  /* packet dropped due to kernel error */

#define net_xmit_errno(e)	((e) != NET_XMIT_CN ? -ENOBUFS : 0)

#endif

#define MAX_ADDR_LEN	32		/* Largest hardware address length */

/* Driver transmit return codes */
#define NETDEV_TX_OK 0		/* driver took care of packet */
#define NETDEV_TX_BUSY 1	/* driver tx path was busy*/
#define NETDEV_TX_LOCKED -1	/* driver tx lock was already taken */

/*
 *	Compute the worst case header length according to the protocols
 *	used.
 */
 
#if !defined(CONFIG_AX25) && !defined(CONFIG_AX25_MODULE) && !defined(CONFIG_TR)
#define LL_MAX_HEADER	32
#else
#if defined(CONFIG_AX25) || defined(CONFIG_AX25_MODULE)
#define LL_MAX_HEADER	96
#else
#define LL_MAX_HEADER	48
#endif
#endif

#if !defined(CONFIG_NET_IPIP) && \
    !defined(CONFIG_IPV6) && !defined(CONFIG_IPV6_MODULE)
#define MAX_HEADER LL_MAX_HEADER
#else
#define MAX_HEADER (LL_MAX_HEADER + 48)
#endif

/*
 *	Network device statistics. Akin to the 2.0 ether stats but
 *	with byte counters.
 */
 
struct net_device_stats
{
	unsigned long	rx_packets;		/* total packets received	*/
	unsigned long	tx_packets;		/* total packets transmitted	*/
	unsigned long	rx_bytes;		/* total bytes received 	*/
	unsigned long	tx_bytes;		/* total bytes transmitted	*/
	unsigned long	rx_errors;		/* bad packets received		*/
	unsigned long	tx_errors;		/* packet transmit problems	*/
	unsigned long	rx_dropped;		/* no space in linux buffers	*/
	unsigned long	tx_dropped;		/* no space available in linux	*/
	unsigned long	multicast;		/* multicast packets received	*/
	unsigned long	collisions;

	/* detailed rx_errors: */
	unsigned long	rx_length_errors;
	unsigned long	rx_over_errors;		/* receiver ring buff overflow	*/
	unsigned long	rx_crc_errors;		/* recved pkt with crc error	*/
	unsigned long	rx_frame_errors;	/* recv'd frame alignment error */
	unsigned long	rx_fifo_errors;		/* recv'r fifo overrun		*/
	unsigned long	rx_missed_errors;	/* receiver missed packet	*/

	/* detailed tx_errors */
	unsigned long	tx_aborted_errors;
	unsigned long	tx_carrier_errors;
	unsigned long	tx_fifo_errors;
	unsigned long	tx_heartbeat_errors;
	unsigned long	tx_window_errors;
	
	/* for cslip etc */
	unsigned long	rx_compressed;
	unsigned long	tx_compressed;
};


/* Media selection options. */
enum {
        IF_PORT_UNKNOWN = 0,
        IF_PORT_10BASE2,
        IF_PORT_10BASET,
        IF_PORT_AUI,
        IF_PORT_100BASET,
        IF_PORT_100BASETX,
        IF_PORT_100BASEFX
};

#ifdef __KERNEL__

#include <linux/cache.h>
#include <linux/skbuff.h>

struct neighbour;
struct neigh_parms;
struct sk_buff;

struct netif_rx_stats
{
	unsigned total;
	unsigned dropped;
	unsigned time_squeeze;
	unsigned cpu_collision;
};

DECLARE_PER_CPU(struct netif_rx_stats, netdev_rx_stat);


/*
 *	We tag multicasts with these structures.
 */
 
struct dev_mc_list
{	
	struct dev_mc_list	*next;
	__u8			dmi_addr[MAX_ADDR_LEN];
	unsigned char		dmi_addrlen;
	int			dmi_users;
	int			dmi_gusers;
};

struct hh_cache
{
	struct hh_cache *hh_next;	/* Next entry			     */
	atomic_t	hh_refcnt;	/* number of users                   */
	unsigned short  hh_type;	/* protocol identifier, f.e ETH_P_IP
                                         *  NOTE:  For VLANs, this will be the
                                         *  encapuslated type. --BLG
                                         */
	int		hh_len;		/* length of header */
	int		(*hh_output)(struct sk_buff *skb);
	rwlock_t	hh_lock;

	/* cached hardware header; allow for machine alignment needs.        */
#define HH_DATA_MOD	16
#define HH_DATA_OFF(__len) \
	(HH_DATA_MOD - (((__len - 1) & (HH_DATA_MOD - 1)) + 1))
#define HH_DATA_ALIGN(__len) \
	(((__len)+(HH_DATA_MOD-1))&~(HH_DATA_MOD - 1))
	unsigned long	hh_data[HH_DATA_ALIGN(LL_MAX_HEADER) / sizeof(long)];
};

/* Reserve HH_DATA_MOD byte aligned hard_header_len, but at least that much.
 * Alternative is:
 *   dev->hard_header_len ? (dev->hard_header_len +
 *                           (HH_DATA_MOD - 1)) & ~(HH_DATA_MOD - 1) : 0
 *
 * We could use other alignment values, but we must maintain the
 * relationship HH alignment <= LL alignment.
 */
#define LL_RESERVED_SPACE(dev) \
	(((dev)->hard_header_len&~(HH_DATA_MOD - 1)) + HH_DATA_MOD)
#define LL_RESERVED_SPACE_EXTRA(dev,extra) \
	((((dev)->hard_header_len+extra)&~(HH_DATA_MOD - 1)) + HH_DATA_MOD)

/* These flag bits are private to the generic network queueing
 * layer, they may not be explicitly referenced by any other
 * code.
 */

enum netdev_state_t
{
	__LINK_STATE_XOFF=0,
	__LINK_STATE_START,
	__LINK_STATE_PRESENT,
	__LINK_STATE_SCHED,
	__LINK_STATE_NOCARRIER,
	__LINK_STATE_RX_SCHED,
	__LINK_STATE_LINKWATCH_PENDING,
	__LINK_STATE_DORMANT,
	__LINK_STATE_QDISC_RUNNING,
};


/*
 * This structure holds at boot time configured netdevice settings. They
 * are then used in the device probing. 
 */
struct netdev_boot_setup {
	char name[IFNAMSIZ];
	struct ifmap map;
};
#define NETDEV_BOOT_SETUP_MAX 8

extern int __init netdev_boot_setup(char *str);

/*
 *	The DEVICE structure.
 *	Actually, this whole structure is a big mistake.  It mixes I/O
 *	data with strictly "high-level" data, and it has to know about
 *	almost every data structure used in the INET module.
 *
 *	FIXME: cleanup struct net_device such that network protocol info
 *	moves out.
 */

struct net_device
{

	/*
	 * This is the first field of the "visible" part of this structure
	 * (i.e. as seen by users in the "Space.c" file).  It is the name
	 * the interface.
	 */
	char			name[IFNAMSIZ];
	/* device name hash chain */
	struct hlist_node	name_hlist;

	/*
	 *	I/O specific fields
	 *	FIXME: Merge these and struct ifmap into one
	 */
	unsigned long		mem_end;	/* shared mem end	*/
	unsigned long		mem_start;	/* shared mem start	*/
	unsigned long		base_addr;	/* device I/O address	*/
	unsigned int		irq;		/* device IRQ number	*/

	/*
	 *	Some hardware also needs these fields, but they are not
	 *	part of the usual set specified in Space.c.
	 */

	unsigned char		if_port;	/* Selectable AUI, TP,..*/
	unsigned char		dma;		/* DMA channel		*/

	unsigned long		state;

	struct net_device	*next;
	
	/* The device initialization function. Called only once. */
	int			(*init)(struct net_device *dev);

	/* ------- Fields preinitialized in Space.c finish here ------- */

	/* Net device features */
	unsigned long		features;
#define NETIF_F_SG		1	/* Scatter/gather IO. */
#define NETIF_F_IP_CSUM		2	/* Can checksum only TCP/UDP over IPv4. */
#define NETIF_F_NO_CSUM		4	/* Does not require checksum. F.e. loopack. */
#define NETIF_F_HW_CSUM		8	/* Can checksum all the packets. */
#define NETIF_F_HIGHDMA		32	/* Can DMA to high memory. */
#define NETIF_F_FRAGLIST	64	/* Scatter/gather IO. */
#define NETIF_F_HW_VLAN_TX	128	/* Transmit VLAN hw acceleration */
#define NETIF_F_HW_VLAN_RX	256	/* Receive VLAN hw acceleration */
#define NETIF_F_HW_VLAN_FILTER	512	/* Receive filtering on VLAN */
#define NETIF_F_VLAN_CHALLENGED	1024	/* Device cannot handle VLAN packets */
#define NETIF_F_GSO		2048	/* Enable software GSO. */
#define NETIF_F_LLTX		4096	/* LockLess TX */

	/* Segmentation offload features */
#define NETIF_F_GSO_SHIFT	16
#define NETIF_F_GSO_MASK	0xffff0000
#define NETIF_F_TSO		(SKB_GSO_TCPV4 << NETIF_F_GSO_SHIFT)
#define NETIF_F_UFO		(SKB_GSO_UDP << NETIF_F_GSO_SHIFT)
#define NETIF_F_GSO_ROBUST	(SKB_GSO_DODGY << NETIF_F_GSO_SHIFT)
#define NETIF_F_TSO_ECN		(SKB_GSO_TCP_ECN << NETIF_F_GSO_SHIFT)
#define NETIF_F_TSO6		(SKB_GSO_TCPV6 << NETIF_F_GSO_SHIFT)

	/* List of features with software fallbacks. */
#define NETIF_F_GSO_SOFTWARE	(NETIF_F_TSO | NETIF_F_TSO_ECN | NETIF_F_TSO6)

#define NETIF_F_GEN_CSUM	(NETIF_F_NO_CSUM | NETIF_F_HW_CSUM)
#define NETIF_F_ALL_CSUM	(NETIF_F_IP_CSUM | NETIF_F_GEN_CSUM)

	struct net_device	*next_sched;

	/* Interface index. Unique device identifier	*/
	int			ifindex;
	int			iflink;


	struct net_device_stats* (*get_stats)(struct net_device *dev);
	struct iw_statistics*	(*get_wireless_stats)(struct net_device *dev);

	/* List of functions to handle Wireless Extensions (instead of ioctl).
	 * See <net/iw_handler.h> for details. Jean II */
	const struct iw_handler_def *	wireless_handlers;
	/* Instance data managed by the core of Wireless Extensions. */
	struct iw_public_data *	wireless_data;

	/* pending config used by cfg80211/wext compat code only */
	void *cfg80211_wext_pending_config;

	struct ethtool_ops *ethtool_ops;

	/*
	 * This marks the end of the "visible" part of the structure. All
	 * fields hereafter are internal to the system, and may change at
	 * will (read: may be cleaned up at will).
	 */


	unsigned int		flags;	/* interface flags (a la BSD)	*/
	unsigned short		gflags;
        unsigned short          priv_flags; /* Like 'flags' but invisible to userspace. */
	unsigned short		padded;	/* How much padding added by alloc_netdev() */

	unsigned char		operstate; /* RFC2863 operstate */
	unsigned char		link_mode; /* mapping policy to operstate */

	unsigned		mtu;	/* interface MTU value		*/
	unsigned short		type;	/* interface hardware type	*/
	unsigned short		hard_header_len;	/* hardware hdr length	*/

	struct net_device	*master; /* Pointer to master device of a group,
					  * which this device is member of.
					  */

	/* Interface address info. */
	unsigned char		perm_addr[MAX_ADDR_LEN]; /* permanent hw address */
	unsigned char		addr_len;	/* hardware address length	*/
	unsigned short          dev_id;		/* for shared network cards */

	struct dev_mc_list	*mc_list;	/* Multicast mac addresses	*/
	int			mc_count;	/* Number of installed mcasts	*/
	int			promiscuity;
	int			allmulti;


	/* Protocol specific pointers */
	
	void 			*atalk_ptr;	/* AppleTalk link 	*/
	void			*ip_ptr;	/* IPv4 specific data	*/  
	void                    *dn_ptr;        /* DECnet specific data */
	void                    *ip6_ptr;       /* IPv6 specific data */
	void			*ec_ptr;	/* Econet specific data	*/
	void			*ax25_ptr;	/* AX.25 specific data */
	void			*ieee80211_ptr;	/* IEEE 802.11 specific data */

/*
 * Cache line mostly used on receive path (including eth_type_trans())
 */
	struct list_head	poll_list ____cacheline_aligned_in_smp;
					/* Link to poll list	*/

	int			(*poll) (struct net_device *dev, int *quota);
	int			quota;
	int			weight;
	unsigned long		last_rx;	/* Time of last Rx	*/
	/* Interface address info used in eth_type_trans() */
	unsigned char		dev_addr[MAX_ADDR_LEN];	/* hw address, (before bcast 
							because most packets are unicast) */

	unsigned char		broadcast[MAX_ADDR_LEN];	/* hw bcast add	*/

/*
 * Cache line mostly used on queue transmit path (qdisc)
 */
	/* device queue lock */
	spinlock_t		queue_lock ____cacheline_aligned_in_smp;
	struct Qdisc		*qdisc;
	struct Qdisc		*qdisc_sleeping;
	struct list_head	qdisc_list;
	unsigned long		tx_queue_len;	/* Max frames per queue allowed */

	/* Partially transmitted GSO packet. */
	struct sk_buff		*gso_skb;

	/* ingress path synchronizer */
	spinlock_t		ingress_lock;
	struct Qdisc		*qdisc_ingress;

/*
 * One part is mostly used on xmit path (device)
 */
	/* hard_start_xmit synchronizer */
	spinlock_t		_xmit_lock ____cacheline_aligned_in_smp;
	/* cpu id of processor entered to hard_start_xmit or -1,
	   if nobody entered there.
	 */
	int			xmit_lock_owner;
	void			*priv;	/* pointer to private data	*/
	int			(*hard_start_xmit) (struct sk_buff *skb,
						    struct net_device *dev);
	/* These may be needed for future network-power-down code. */
	unsigned long		trans_start;	/* Time (in jiffies) of last Tx	*/

	int			watchdog_timeo; /* used by dev_watchdog() */
	struct timer_list	watchdog_timer;

/*
 * refcnt is a very hot point, so align it on SMP
 */
	/* Number of references to this device */
	atomic_t		refcnt ____cacheline_aligned_in_smp;

	/* delayed register/unregister */
	struct list_head	todo_list;
	/* device index hash chain */
	struct hlist_node	index_hlist;

	/* register/unregister state machine */
	enum { NETREG_UNINITIALIZED=0,
	       NETREG_REGISTERED,	/* completed register_netdevice */
	       NETREG_UNREGISTERING,	/* called unregister_netdevice */
	       NETREG_UNREGISTERED,	/* completed unregister todo */
	       NETREG_RELEASED,		/* called free_netdev */
	} reg_state;

	/* Called after device is detached from network. */
	void			(*uninit)(struct net_device *dev);
	/* Called after last user reference disappears. */
	void			(*destructor)(struct net_device *dev);

	/* Pointers to interface service routines.	*/
	int			(*open)(struct net_device *dev);
	int			(*stop)(struct net_device *dev);
#define HAVE_NETDEV_POLL
	int			(*hard_header) (struct sk_buff *skb,
						struct net_device *dev,
						unsigned short type,
						void *daddr,
						void *saddr,
						unsigned len);
	int			(*rebuild_header)(struct sk_buff *skb);
#define HAVE_MULTICAST			 
	void			(*set_multicast_list)(struct net_device *dev);
#define HAVE_SET_MAC_ADDR  		 
	int			(*set_mac_address)(struct net_device *dev,
						   void *addr);
#define HAVE_PRIVATE_IOCTL
	int			(*do_ioctl)(struct net_device *dev,
					    struct ifreq *ifr, int cmd);
#define HAVE_SET_CONFIG
	int			(*set_config)(struct net_device *dev,
					      struct ifmap *map);
#define HAVE_HEADER_CACHE
	int			(*hard_header_cache)(struct neighbour *neigh,
						     struct hh_cache *hh);
	void			(*header_cache_update)(struct hh_cache *hh,
						       struct net_device *dev,
						       unsigned char *  haddr);
#define HAVE_CHANGE_MTU
	int			(*change_mtu)(struct net_device *dev, int new_mtu);

#define HAVE_TX_TIMEOUT
	void			(*tx_timeout) (struct net_device *dev);

	void			(*vlan_rx_register)(struct net_device *dev,
						    struct vlan_group *grp);
	void			(*vlan_rx_add_vid)(struct net_device *dev,
						   unsigned short vid);
	void			(*vlan_rx_kill_vid)(struct net_device *dev,
						    unsigned short vid);

	int			(*hard_header_parse)(struct sk_buff *skb,
						     unsigned char *haddr);
	int			(*neigh_setup)(struct net_device *dev, struct neigh_parms *);
#ifdef CONFIG_NETPOLL
	struct netpoll_info	*npinfo;
#endif
#ifdef CONFIG_NET_POLL_CONTROLLER
	void                    (*poll_controller)(struct net_device *dev);
#endif

	/* bridge stuff */
	struct net_bridge_port	*br_port;

#ifdef CONFIG_NET_DIVERT
	/* this will get initialized at each interface type init routine */
	struct divert_blk	*divert;
#endif /* CONFIG_NET_DIVERT */

	/* class/net/name entry */
	struct class_device	class_dev;
	/* space for optional statistics and wireless sysfs groups */
	struct attribute_group  *sysfs_groups[3];
};

#define	NETDEV_ALIGN		32
#define	NETDEV_ALIGN_CONST	(NETDEV_ALIGN - 1)

static inline void *netdev_priv(struct net_device *dev)
{
	return (char *)dev + ((sizeof(struct net_device)
					+ NETDEV_ALIGN_CONST)
				& ~NETDEV_ALIGN_CONST);
}

#define SET_MODULE_OWNER(dev) do { } while (0)
/* Set the sysfs physical device reference for the network logical device
 * if set prior to registration will cause a symlink during initialization.
 */
#define SET_NETDEV_DEV(net, pdev)	((net)->class_dev.dev = (pdev))

struct packet_type {
	__be16			type;	/* This is really htons(ether_type). */
	struct net_device	*dev;	/* NULL is wildcarded here	     */
	int			(*func) (struct sk_buff *,
					 struct net_device *,
					 struct packet_type *,
					 struct net_device *);
	struct sk_buff		*(*gso_segment)(struct sk_buff *skb,
						int features);
	int			(*gso_send_check)(struct sk_buff *skb);
	void			*af_packet_priv;
	struct list_head	list;
};

#include <linux/interrupt.h>
#include <linux/notifier.h>

extern struct net_device		loopback_dev;		/* The loopback */
extern struct net_device		*dev_base;		/* All devices */
extern rwlock_t				dev_base_lock;		/* Device list lock */

extern int 			netdev_boot_setup_check(struct net_device *dev);
extern unsigned long		netdev_boot_base(const char *prefix, int unit);
extern struct net_device    *dev_getbyhwaddr(unsigned short type, char *hwaddr);
extern struct net_device *dev_getfirstbyhwtype(unsigned short type);
extern void		dev_add_pack(struct packet_type *pt);
extern void		dev_remove_pack(struct packet_type *pt);
extern void		__dev_remove_pack(struct packet_type *pt);

extern struct net_device	*dev_get_by_flags(unsigned short flags,
						  unsigned short mask);
extern struct net_device	*dev_get_by_name(const char *name);
extern struct net_device	*__dev_get_by_name(const char *name);
extern int		dev_alloc_name(struct net_device *dev, const char *name);
extern int		dev_open(struct net_device *dev);
extern int		dev_close(struct net_device *dev);
extern int		dev_queue_xmit(struct sk_buff *skb);
extern int		register_netdevice(struct net_device *dev);
extern int		unregister_netdevice(struct net_device *dev);
extern void		free_netdev(struct net_device *dev);
extern void		synchronize_net(void);
extern int 		register_netdevice_notifier(struct notifier_block *nb);
extern int		unregister_netdevice_notifier(struct notifier_block *nb);
extern int		call_netdevice_notifiers(unsigned long val, void *v);
extern struct net_device	*dev_get_by_index(int ifindex);
extern struct net_device	*__dev_get_by_index(int ifindex);
extern int		dev_restart(struct net_device *dev);
#ifdef CONFIG_NETPOLL_TRAP
extern int		netpoll_trap(void);
#endif

typedef int gifconf_func_t(struct net_device * dev, char __user * bufptr, int len);
extern int		register_gifconf(unsigned int family, gifconf_func_t * gifconf);
static inline int unregister_gifconf(unsigned int family)
{
	return register_gifconf(family, NULL);
}

/*
 * Incoming packets are placed on per-cpu queues so that
 * no locking is needed.
 */

struct softnet_data
{
	struct net_device	*output_queue;
	struct sk_buff_head	input_pkt_queue;
	struct list_head	poll_list;
	struct sk_buff		*completion_queue;

	struct net_device	backlog_dev;	/* Sorry. 8) */
#ifdef CONFIG_NET_DMA
	struct dma_chan		*net_dma;
#endif
};

DECLARE_PER_CPU(struct softnet_data,softnet_data);

#define HAVE_NETIF_QUEUE

extern void __netif_schedule(struct net_device *dev);

static inline void netif_schedule(struct net_device *dev)
{
	if (!test_bit(__LINK_STATE_XOFF, &dev->state))
		__netif_schedule(dev);
}

static inline void netif_start_queue(struct net_device *dev)
{
	clear_bit(__LINK_STATE_XOFF, &dev->state);
}

static inline void netif_wake_queue(struct net_device *dev)
{
#ifdef CONFIG_NETPOLL_TRAP
	if (netpoll_trap())
		return;
#endif
	if (test_and_clear_bit(__LINK_STATE_XOFF, &dev->state))
		__netif_schedule(dev);
}

static inline void netif_stop_queue(struct net_device *dev)
{
#ifdef CONFIG_NETPOLL_TRAP
	if (netpoll_trap())
		return;
#endif
	set_bit(__LINK_STATE_XOFF, &dev->state);
}

static inline int netif_queue_stopped(const struct net_device *dev)
{
	return test_bit(__LINK_STATE_XOFF, &dev->state);
}

static inline int netif_running(const struct net_device *dev)
{
	return test_bit(__LINK_STATE_START, &dev->state);
}


/* Use this variant when it is known for sure that it
 * is executing from interrupt context.
 */
static inline void dev_kfree_skb_irq(struct sk_buff *skb)
{
	if (atomic_dec_and_test(&skb->users)) {
		struct softnet_data *sd;
		unsigned long flags;

		local_irq_save(flags);
		sd = &__get_cpu_var(softnet_data);
		skb->next = sd->completion_queue;
		sd->completion_queue = skb;
		raise_softirq_irqoff(NET_TX_SOFTIRQ);
		local_irq_restore(flags);
	}
}

/* Use this variant in places where it could be invoked
 * either from interrupt or non-interrupt context.
 */
extern void dev_kfree_skb_any(struct sk_buff *skb);

#define HAVE_NETIF_RX 1
extern int		netif_rx(struct sk_buff *skb);
extern int		netif_rx_ni(struct sk_buff *skb);
#define HAVE_NETIF_RECEIVE_SKB 1
extern int		netif_receive_skb(struct sk_buff *skb);
extern int		dev_valid_name(const char *name);
extern int		dev_ioctl(unsigned int cmd, void __user *);
extern int		dev_ethtool(struct ifreq *);
extern unsigned		dev_get_flags(const struct net_device *);
extern int		dev_change_flags(struct net_device *, unsigned);
extern int		dev_change_name(struct net_device *, char *);
extern int		dev_set_mtu(struct net_device *, int);
extern int		dev_set_mac_address(struct net_device *,
					    struct sockaddr *);
extern int		dev_hard_start_xmit(struct sk_buff *skb,
					    struct net_device *dev);

extern void		dev_init(void);

extern int		netdev_budget;

/* Called by rtnetlink.c:rtnl_unlock() */
extern void netdev_run_todo(void);

static inline void dev_put(struct net_device *dev)
{
	atomic_dec(&dev->refcnt);
}

static inline void dev_hold(struct net_device *dev)
{
	atomic_inc(&dev->refcnt);
}

/* Carrier loss detection, dial on demand. The functions netif_carrier_on
 * and _off may be called from IRQ context, but it is caller
 * who is responsible for serialization of these calls.
 *
 * The name carrier is inappropriate, these functions should really be
 * called netif_lowerlayer_*() because they represent the state of any
 * kind of lower layer not just hardware media.
 */

extern void linkwatch_fire_event(struct net_device *dev);

static inline int netif_carrier_ok(const struct net_device *dev)
{
	return !test_bit(__LINK_STATE_NOCARRIER, &dev->state);
}

extern void __netdev_watchdog_up(struct net_device *dev);

extern void netif_carrier_on(struct net_device *dev);

extern void netif_carrier_off(struct net_device *dev);

static inline void netif_dormant_on(struct net_device *dev)
{
	if (!test_and_set_bit(__LINK_STATE_DORMANT, &dev->state))
		linkwatch_fire_event(dev);
}

static inline void netif_dormant_off(struct net_device *dev)
{
	if (test_and_clear_bit(__LINK_STATE_DORMANT, &dev->state))
		linkwatch_fire_event(dev);
}

static inline int netif_dormant(const struct net_device *dev)
{
	return test_bit(__LINK_STATE_DORMANT, &dev->state);
}


static inline int netif_oper_up(const struct net_device *dev) {
	return (dev->operstate == IF_OPER_UP ||
		dev->operstate == IF_OPER_UNKNOWN /* backward compat */);
}

/* Hot-plugging. */
static inline int netif_device_present(struct net_device *dev)
{
	return test_bit(__LINK_STATE_PRESENT, &dev->state);
}

extern void netif_device_detach(struct net_device *dev);

extern void netif_device_attach(struct net_device *dev);

/*
 * Network interface message level settings
 */
#define HAVE_NETIF_MSG 1

enum {
	NETIF_MSG_DRV		= 0x0001,
	NETIF_MSG_PROBE		= 0x0002,
	NETIF_MSG_LINK		= 0x0004,
	NETIF_MSG_TIMER		= 0x0008,
	NETIF_MSG_IFDOWN	= 0x0010,
	NETIF_MSG_IFUP		= 0x0020,
	NETIF_MSG_RX_ERR	= 0x0040,
	NETIF_MSG_TX_ERR	= 0x0080,
	NETIF_MSG_TX_QUEUED	= 0x0100,
	NETIF_MSG_INTR		= 0x0200,
	NETIF_MSG_TX_DONE	= 0x0400,
	NETIF_MSG_RX_STATUS	= 0x0800,
	NETIF_MSG_PKTDATA	= 0x1000,
	NETIF_MSG_HW		= 0x2000,
	NETIF_MSG_WOL		= 0x4000,
};

#define netif_msg_drv(p)	((p)->msg_enable & NETIF_MSG_DRV)
#define netif_msg_probe(p)	((p)->msg_enable & NETIF_MSG_PROBE)
#define netif_msg_link(p)	((p)->msg_enable & NETIF_MSG_LINK)
#define netif_msg_timer(p)	((p)->msg_enable & NETIF_MSG_TIMER)
#define netif_msg_ifdown(p)	((p)->msg_enable & NETIF_MSG_IFDOWN)
#define netif_msg_ifup(p)	((p)->msg_enable & NETIF_MSG_IFUP)
#define netif_msg_rx_err(p)	((p)->msg_enable & NETIF_MSG_RX_ERR)
#define netif_msg_tx_err(p)	((p)->msg_enable & NETIF_MSG_TX_ERR)
#define netif_msg_tx_queued(p)	((p)->msg_enable & NETIF_MSG_TX_QUEUED)
#define netif_msg_intr(p)	((p)->msg_enable & NETIF_MSG_INTR)
#define netif_msg_tx_done(p)	((p)->msg_enable & NETIF_MSG_TX_DONE)
#define netif_msg_rx_status(p)	((p)->msg_enable & NETIF_MSG_RX_STATUS)
#define netif_msg_pktdata(p)	((p)->msg_enable & NETIF_MSG_PKTDATA)
#define netif_msg_hw(p)		((p)->msg_enable & NETIF_MSG_HW)
#define netif_msg_wol(p)	((p)->msg_enable & NETIF_MSG_WOL)

static inline u32 netif_msg_init(int debug_value, int default_msg_enable_bits)
{
	/* use default */
	if (debug_value < 0 || debug_value >= (sizeof(u32) * 8))
		return default_msg_enable_bits;
	if (debug_value == 0)	/* no output */
		return 0;
	/* set low N bits */
	return (1 << debug_value) - 1;
}

/* Test if receive needs to be scheduled */
static inline int __netif_rx_schedule_prep(struct net_device *dev)
{
	return !test_and_set_bit(__LINK_STATE_RX_SCHED, &dev->state);
}

/* Test if receive needs to be scheduled but only if up */
static inline int netif_rx_schedule_prep(struct net_device *dev)
{
	return netif_running(dev) && __netif_rx_schedule_prep(dev);
}

/* Add interface to tail of rx poll list. This assumes that _prep has
 * already been called and returned 1.
 */

extern void __netif_rx_schedule(struct net_device *dev);

/* Try to reschedule poll. Called by irq handler. */

static inline void netif_rx_schedule(struct net_device *dev)
{
	if (netif_rx_schedule_prep(dev))
		__netif_rx_schedule(dev);
}

/* Try to reschedule poll. Called by dev->poll() after netif_rx_complete().
 * Do not inline this?
 */
static inline int netif_rx_reschedule(struct net_device *dev, int undo)
{
	if (netif_rx_schedule_prep(dev)) {
		unsigned long flags;

		dev->quota += undo;

		local_irq_save(flags);
		list_add_tail(&dev->poll_list, &__get_cpu_var(softnet_data).poll_list);
		__raise_softirq_irqoff(NET_RX_SOFTIRQ);
		local_irq_restore(flags);
		return 1;
	}
	return 0;
}

/* Remove interface from poll list: it must be in the poll list
 * on current cpu. This primitive is called by dev->poll(), when
 * it completes the work. The device cannot be out of poll list at this
 * moment, it is BUG().
 */
static inline void netif_rx_complete(struct net_device *dev)
{
	unsigned long flags;

	local_irq_save(flags);
	BUG_ON(!test_bit(__LINK_STATE_RX_SCHED, &dev->state));
	list_del(&dev->poll_list);
	smp_mb__before_clear_bit();
	clear_bit(__LINK_STATE_RX_SCHED, &dev->state);
	local_irq_restore(flags);
}

static inline void netif_poll_disable(struct net_device *dev)
{
	while (test_and_set_bit(__LINK_STATE_RX_SCHED, &dev->state))
		/* No hurry. */
		schedule_timeout_interruptible(1);
}

static inline void netif_poll_enable(struct net_device *dev)
{
	clear_bit(__LINK_STATE_RX_SCHED, &dev->state);
}

/* same as netif_rx_complete, except that local_irq_save(flags)
 * has already been issued
 */
static inline void __netif_rx_complete(struct net_device *dev)
{
	BUG_ON(!test_bit(__LINK_STATE_RX_SCHED, &dev->state));
	list_del(&dev->poll_list);
	smp_mb__before_clear_bit();
	clear_bit(__LINK_STATE_RX_SCHED, &dev->state);
}

static inline void netif_tx_lock(struct net_device *dev)
{
	spin_lock(&dev->_xmit_lock);
	dev->xmit_lock_owner = smp_processor_id();
}

static inline void netif_tx_lock_bh(struct net_device *dev)
{
	spin_lock_bh(&dev->_xmit_lock);
	dev->xmit_lock_owner = smp_processor_id();
}

static inline int netif_tx_trylock(struct net_device *dev)
{
	int ok = spin_trylock(&dev->_xmit_lock);
	if (likely(ok))
		dev->xmit_lock_owner = smp_processor_id();
	return ok;
}

static inline void netif_tx_unlock(struct net_device *dev)
{
	dev->xmit_lock_owner = -1;
	spin_unlock(&dev->_xmit_lock);
}

static inline void netif_tx_unlock_bh(struct net_device *dev)
{
	dev->xmit_lock_owner = -1;
	spin_unlock_bh(&dev->_xmit_lock);
}

static inline void netif_tx_disable(struct net_device *dev)
{
	netif_tx_lock_bh(dev);
	netif_stop_queue(dev);
	netif_tx_unlock_bh(dev);
}

/* These functions live elsewhere (drivers/net/net_init.c, but related) */

extern void		ether_setup(struct net_device *dev);

/* Support for loadable net-drivers */
extern struct net_device *alloc_netdev(int sizeof_priv, const char *name,
				       void (*setup)(struct net_device *));
extern int		register_netdev(struct net_device *dev);
extern void		unregister_netdev(struct net_device *dev);
/* Functions used for multicast support */
extern void		dev_mc_upload(struct net_device *dev);
extern int 		dev_mc_delete(struct net_device *dev, void *addr, int alen, int all);
extern int		dev_mc_add(struct net_device *dev, void *addr, int alen, int newonly);
extern void		dev_mc_discard(struct net_device *dev);
extern void		dev_set_promiscuity(struct net_device *dev, int inc);
extern void		dev_set_allmulti(struct net_device *dev, int inc);
extern void		netdev_state_change(struct net_device *dev);
extern void		netdev_features_change(struct net_device *dev);
/* Load a device via the kmod */
extern void		dev_load(const char *name);
extern void		dev_mcast_init(void);
extern int		netdev_max_backlog;
extern int		weight_p;
extern int		netdev_set_master(struct net_device *dev, struct net_device *master);
extern int skb_checksum_help(struct sk_buff *skb, int inward);
extern struct sk_buff *skb_gso_segment(struct sk_buff *skb, int features);
#ifdef CONFIG_BUG
extern void netdev_rx_csum_fault(struct net_device *dev);
#else
static inline void netdev_rx_csum_fault(struct net_device *dev)
{
}
#endif
/* rx skb timestamps */
extern void		net_enable_timestamp(void);
extern void		net_disable_timestamp(void);

#ifdef CONFIG_PROC_FS
extern void *dev_seq_start(struct seq_file *seq, loff_t *pos);
extern void *dev_seq_next(struct seq_file *seq, void *v, loff_t *pos);
extern void dev_seq_stop(struct seq_file *seq, void *v);
#endif

extern void linkwatch_run_queue(void);

static inline int net_gso_ok(int features, int gso_type)
{
	int feature = gso_type << NETIF_F_GSO_SHIFT;
	return (features & feature) == feature;
}

static inline int skb_gso_ok(struct sk_buff *skb, int features)
{
	return net_gso_ok(features, skb_shinfo(skb)->gso_type);
}

static inline int netif_needs_gso(struct net_device *dev, struct sk_buff *skb)
{
	return skb_is_gso(skb) &&
	       (!skb_gso_ok(skb, dev->features) ||
		unlikely(skb->ip_summed != CHECKSUM_HW));
}

/* On bonding slaves other than the currently active slave, suppress
 * duplicates except for 802.3ad ETH_P_SLOW and alb non-mcast/bcast.
 */
static inline int skb_bond_should_drop(struct sk_buff *skb)
{
	struct net_device *dev = skb->dev;
	struct net_device *master = dev->master;

	if (master &&
	    (dev->priv_flags & IFF_SLAVE_INACTIVE)) {
		if (master->priv_flags & IFF_MASTER_ALB) {
			if (skb->pkt_type != PACKET_BROADCAST &&
			    skb->pkt_type != PACKET_MULTICAST)
				return 0;
		}
		if (master->priv_flags & IFF_MASTER_8023AD &&
		    skb->protocol == __constant_htons(ETH_P_SLOW))
			return 0;

		return 1;
	}
	return 0;
}

#endif /* __KERNEL__ */

#endif	/* _LINUX_DEV_H */

^ permalink raw reply

* Re: Vague maybe ppp-related panic report for 2.6.23-rc9
From: Roland Dreier @ 2007-10-05  1:59 UTC (permalink / raw)
  To: linux-kernel; +Cc: netdev
In-Reply-To: <ada4ph6da05.fsf@cisco.com>

Just as a quick update -- I seem to only be able to reproduce this
crash when my ppp session drops, which seems associated with marginal
signal.  And unfortunately I have great coverage at home so I haven't
been able to reproduce this again today.  Maybe on the train tomorrow
I can crash my laptop...

 - R.

^ permalink raw reply

* [PATCH net-2.6.24] fix network compile warnings
From: Stephen Hemminger @ 2007-10-05  3:10 UTC (permalink / raw)
  To: David S. Miller; +Cc: netdev

One unused variable warning, and other is failure to check result.

Signed-off-by: Stephen Hemminger <shemminger@linux-foundation.org>

--- a/drivers/infiniband/ulp/ipoib/ipoib_main.c	2007-10-04 17:40:34.000000000 -0700
+++ b/drivers/infiniband/ulp/ipoib/ipoib_main.c	2007-10-04 17:44:33.000000000 -0700
@@ -854,8 +854,8 @@ struct ipoib_neigh *ipoib_neigh_alloc(st
 
 void ipoib_neigh_free(struct net_device *dev, struct ipoib_neigh *neigh)
 {
-	struct ipoib_dev_priv *priv = netdev_priv(dev);
 	struct sk_buff *skb;
+
 	*to_ipoib_neigh(neigh->neighbour) = NULL;
 	while ((skb = __skb_dequeue(&neigh->queue))) {
 		++dev->stats.tx_dropped;
--- a/drivers/net/cxgb3/cxgb3_main.c	2007-10-04 17:40:34.000000000 -0700
+++ b/drivers/net/cxgb3/cxgb3_main.c	2007-10-04 17:45:58.000000000 -0700
@@ -933,7 +933,8 @@ static int offload_open(struct net_devic
 	init_smt(adapter);
 
 	/* Never mind if the next step fails */
-	sysfs_create_group(&tdev->lldev->dev.kobj, &offload_attr_group);
+	if (sysfs_create_group(&tdev->lldev->dev.kobj, &offload_attr_group))
+		dev_dbg(&tdev->lldev->dev, "sysfs offload attribute create failed\n");
 
 	/* Call back all registered clients */
 	cxgb3_add_clients(tdev);

^ permalink raw reply


This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox