qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Alexey Kardashevskiy <aik@ozlabs.ru>
To: qemu-devel@nongnu.org
Cc: Alexey Kardashevskiy <aik@ozlabs.ru>, Gerd Hoffmann <kraxel@redhat.com>
Subject: [Qemu-devel] [PATCH qemu] xhci: Avoid DMA when ERSTBA is set to zero
Date: Mon, 11 Sep 2017 16:56:06 +1000	[thread overview]
Message-ID: <20170911065606.40600-1-aik@ozlabs.ru> (raw)

The existing XHCI code reads the Event Ring Segment Table Base Address
Register (ERSTBA) every time when it is changed. However zero is its
default state so one would think that zero there means it is not in use.

This adds a check for ERSTBA in addition to the existing check for
the Event Ring Segment Table Size Register (ERSTSZ).

Signed-off-by: Alexey Kardashevskiy <aik@ozlabs.ru>
---

On pseries, the SLOF firmware initializes XHCI and sets non-zero value
to ERSTBA. Then, it jumps to the guest and the guest requests the SLOF
to quiesce devices, that includes XHCI. SLOF removes DMA mappings and
writes 0 to ERSTBA, writing to its high part triggers xhci_er_reset()
in QEMU which calls pci_dma_read(PCI_DEVICE(xhci), erstba,...) which
ends up in unassigned_mem_accepts as IOMMU translation entry for 0 is
missing (and it is missing always on pseries, at least in practice).

However the very same SLOF driver does not cause EEH (that would be
hardware reaction on missing IOMMU translation entry) on the real POWER8
system with "Texas Instruments TUSB73x0 SuperSpeed USB 3.0 xHCI
Host Controller" passed via VFIO which made me think that this patch is
a useful thing to have anyway as this is what the hardware does,
i.e. tolerates some misconfiguration.

And yes, we will fix SLOF to reset ERSTSZ in addition to ERSTBA anyway.

The XHCI spec, just in case:
https://www.intel.com.au/content/dam/www/public/us/en/documents/technical-specifications/extensible-host-controler-interface-usb-xhci.pdf
---
 hw/usb/hcd-xhci.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/hw/usb/hcd-xhci.c b/hw/usb/hcd-xhci.c
index 204ea69d3f..d75c085d94 100644
--- a/hw/usb/hcd-xhci.c
+++ b/hw/usb/hcd-xhci.c
@@ -811,8 +811,9 @@ static void xhci_er_reset(XHCIState *xhci, int v)
 {
     XHCIInterrupter *intr = &xhci->intr[v];
     XHCIEvRingSeg seg;
+    dma_addr_t erstba = xhci_addr64(intr->erstba_low, intr->erstba_high);
 
-    if (intr->erstsz == 0) {
+    if (intr->erstsz == 0 || erstba == 0) {
         /* disabled */
         intr->er_start = 0;
         intr->er_size = 0;
@@ -824,7 +825,6 @@ static void xhci_er_reset(XHCIState *xhci, int v)
         xhci_die(xhci);
         return;
     }
-    dma_addr_t erstba = xhci_addr64(intr->erstba_low, intr->erstba_high);
     pci_dma_read(PCI_DEVICE(xhci), erstba, &seg, sizeof(seg));
     le32_to_cpus(&seg.addr_low);
     le32_to_cpus(&seg.addr_high);
-- 
2.11.0

                 reply	other threads:[~2017-09-11  6:56 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20170911065606.40600-1-aik@ozlabs.ru \
    --to=aik@ozlabs.ru \
    --cc=kraxel@redhat.com \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).