From: Greg Kroah-Hartman <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org,
stable-review@kernel.org
Cc: torvalds@linux-foundation.org, akpm@linux-foundation.org,
alan@lxorguk.ukuu.org.uk,
FUJITA Tomonori <fujita.tomonori@lab.ntt.co.jp>,
James Bottomley <James.Bottomley@suse.de>,
Greg Kroah-Hartman <gregkh@suse.de>
Subject: [PATCH 03/97] SCSI: st: fix mdata->page_order handling
Date: Mon, 4 Jan 2010 16:32:16 -0800 [thread overview]
Message-ID: <1262651630-7354-3-git-send-email-gregkh@suse.de> (raw)
In-Reply-To: <20100105003133.GA7199@kroah.com>
From: FUJITA Tomonori <fujita.tomonori@lab.ntt.co.jp>
commit c982c368bb90adbd312faa05d0cfd842e9ab45a7 upstream.
dio transfer always resets mdata->page_order to zero. It breaks
high-order pages previously allocated for non-dio transfer.
This patches adds reserved_page_order to st_buffer structure to save
page order for non-dio transfer.
http://bugzilla.kernel.org/show_bug.cgi?id=14563
When enlarge_buffer() allocates 524288 from 0, st uses six-order page
allocation. So mdata->page_order is 6 and frp_seg is 2.
After that, if st uses dio, sgl_map_user_pages() sets
mdata->page_order to 0 for st_do_scsi(). After that, when we call
normalize_buffer(), it frees only free frp_seg * PAGE_SIZE (2 * 4096)
though we should free frp_seg * PAGE_SIZE << 6 (2 * 4096 << 6). So we
see buffer_size is set to 516096 (524288 - 8192).
Reported-by: Joachim Breuer <linux-kernel@jmbreuer.net>
Tested-by: Joachim Breuer <linux-kernel@jmbreuer.net>
Acked-by: Kai Makisara <kai.makisara@kolumbus.fi>
Signed-off-by: FUJITA Tomonori <fujita.tomonori@lab.ntt.co.jp>
Signed-off-by: James Bottomley <James.Bottomley@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
---
drivers/scsi/st.c | 23 ++++++++++++-----------
drivers/scsi/st.h | 1 +
2 files changed, 13 insertions(+), 11 deletions(-)
diff --git a/drivers/scsi/st.c b/drivers/scsi/st.c
index 12d58a7..5081f97 100644
--- a/drivers/scsi/st.c
+++ b/drivers/scsi/st.c
@@ -552,13 +552,15 @@ st_do_scsi(struct st_request * SRpnt, struct scsi_tape * STp, unsigned char *cmd
SRpnt->waiting = waiting;
if (STp->buffer->do_dio) {
+ mdata->page_order = 0;
mdata->nr_entries = STp->buffer->sg_segs;
mdata->pages = STp->buffer->mapped_pages;
} else {
+ mdata->page_order = STp->buffer->reserved_page_order;
mdata->nr_entries =
DIV_ROUND_UP(bytes, PAGE_SIZE << mdata->page_order);
- STp->buffer->map_data.pages = STp->buffer->reserved_pages;
- STp->buffer->map_data.offset = 0;
+ mdata->pages = STp->buffer->reserved_pages;
+ mdata->offset = 0;
}
memcpy(SRpnt->cmd, cmd, sizeof(SRpnt->cmd));
@@ -3718,7 +3720,7 @@ static int enlarge_buffer(struct st_buffer * STbuffer, int new_size, int need_dm
priority |= __GFP_ZERO;
if (STbuffer->frp_segs) {
- order = STbuffer->map_data.page_order;
+ order = STbuffer->reserved_page_order;
b_size = PAGE_SIZE << order;
} else {
for (b_size = PAGE_SIZE, order = 0;
@@ -3751,7 +3753,7 @@ static int enlarge_buffer(struct st_buffer * STbuffer, int new_size, int need_dm
segs++;
}
STbuffer->b_data = page_address(STbuffer->reserved_pages[0]);
- STbuffer->map_data.page_order = order;
+ STbuffer->reserved_page_order = order;
return 1;
}
@@ -3764,7 +3766,7 @@ static void clear_buffer(struct st_buffer * st_bp)
for (i=0; i < st_bp->frp_segs; i++)
memset(page_address(st_bp->reserved_pages[i]), 0,
- PAGE_SIZE << st_bp->map_data.page_order);
+ PAGE_SIZE << st_bp->reserved_page_order);
st_bp->cleared = 1;
}
@@ -3772,7 +3774,7 @@ static void clear_buffer(struct st_buffer * st_bp)
/* Release the extra buffer */
static void normalize_buffer(struct st_buffer * STbuffer)
{
- int i, order = STbuffer->map_data.page_order;
+ int i, order = STbuffer->reserved_page_order;
for (i = 0; i < STbuffer->frp_segs; i++) {
__free_pages(STbuffer->reserved_pages[i], order);
@@ -3780,7 +3782,7 @@ static void normalize_buffer(struct st_buffer * STbuffer)
}
STbuffer->frp_segs = 0;
STbuffer->sg_segs = 0;
- STbuffer->map_data.page_order = 0;
+ STbuffer->reserved_page_order = 0;
STbuffer->map_data.offset = 0;
}
@@ -3790,7 +3792,7 @@ static void normalize_buffer(struct st_buffer * STbuffer)
static int append_to_buffer(const char __user *ubp, struct st_buffer * st_bp, int do_count)
{
int i, cnt, res, offset;
- int length = PAGE_SIZE << st_bp->map_data.page_order;
+ int length = PAGE_SIZE << st_bp->reserved_page_order;
for (i = 0, offset = st_bp->buffer_bytes;
i < st_bp->frp_segs && offset >= length; i++)
@@ -3822,7 +3824,7 @@ static int append_to_buffer(const char __user *ubp, struct st_buffer * st_bp, in
static int from_buffer(struct st_buffer * st_bp, char __user *ubp, int do_count)
{
int i, cnt, res, offset;
- int length = PAGE_SIZE << st_bp->map_data.page_order;
+ int length = PAGE_SIZE << st_bp->reserved_page_order;
for (i = 0, offset = st_bp->read_pointer;
i < st_bp->frp_segs && offset >= length; i++)
@@ -3855,7 +3857,7 @@ static void move_buffer_data(struct st_buffer * st_bp, int offset)
{
int src_seg, dst_seg, src_offset = 0, dst_offset;
int count, total;
- int length = PAGE_SIZE << st_bp->map_data.page_order;
+ int length = PAGE_SIZE << st_bp->reserved_page_order;
if (offset == 0)
return;
@@ -4577,7 +4579,6 @@ static int sgl_map_user_pages(struct st_buffer *STbp,
}
mdata->offset = uaddr & ~PAGE_MASK;
- mdata->page_order = 0;
STbp->mapped_pages = pages;
return nr_pages;
diff --git a/drivers/scsi/st.h b/drivers/scsi/st.h
index 544dc6b..f91a67c 100644
--- a/drivers/scsi/st.h
+++ b/drivers/scsi/st.h
@@ -46,6 +46,7 @@ struct st_buffer {
struct st_request *last_SRpnt;
struct st_cmdstatus cmdstat;
struct page **reserved_pages;
+ int reserved_page_order;
struct page **mapped_pages;
struct rq_map_data map_data;
unsigned char *b_data;
--
1.6.6
next prev parent reply other threads:[~2010-01-05 0:57 UTC|newest]
Thread overview: 123+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-01-05 0:31 [00/97] 2.6.32.3 stable review Greg KH
2010-01-05 0:32 ` [PATCH 01/97] SCSI: ipr: fix EEH recovery Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 02/97] SCSI: qla2xxx: dpc thread can execute before scsi host has been added Greg Kroah-Hartman
2010-01-05 0:32 ` Greg Kroah-Hartman [this message]
2010-01-05 0:32 ` [PATCH 04/97] SCSI: fc class: fix fc_transport_init error handling Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 05/97] sched: Fix task_hot() test order Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 06/97] x86, cpuid: Add "volatile" to asm in native_cpuid() Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 07/97] sched: Select_task_rq_fair() must honour SD_LOAD_BALANCE Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 08/97] clockevents: Prevent clockevent_devices list corruption on cpu hotplug Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 09/97] pata_hpt3x2n: fix clock turnaround Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 10/97] pata_cmd64x: fix overclocking of UDMA0-2 modes Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 11/97] ASoC: wm8974: fix a wrong bit definition Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 12/97] sound: sgio2audio/pdaudiocf/usb-audio: initialize PCM buffer Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 13/97] ALSA: hda - Fix missing capsrc_nids for ALC88x Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 14/97] acerhdf: limit modalias matching to supported Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 15/97] ACPI: EC: Fix MSI DMI detection Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 16/97] ACPI: Use the return result of ACPI lid notifier chain correctly Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 17/97] powerpc: Handle VSX alignment faults correctly in little-endian mode Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 18/97] ASoC: Do not write to invalid registers on the wm9712 Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 19/97] drm/radeon: fix build on 64-bit with some compilers Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 20/97] USB: emi62: fix crash when trying to load EMI 6|2 firmware Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 21/97] USB: option: support hi speed for modem Haier CE100 Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 22/97] USB: Fix a bug on appledisplay.c regarding signedness Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 23/97] USB: musb: gadget_ep0: avoid SetupEnd interrupt Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 24/97] Bluetooth: Prevent ill-timed autosuspend in USB driver Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 25/97] USB: rename usb_configure_device Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 26/97] USB: fix bugs in usb_(de)authorize_device Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 27/97] drivers/net/usb: Correct code taking the size of a pointer Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 28/97] x86: SGI UV: Fix writes to led registers on remote uv hubs Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 29/97] md: Fix unfortunate interaction with evms Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 30/97] dma: at_hdmac: correct incompatible type for argument 1 of 'spin_lock_bh' Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 31/97] dma-debug: Do not add notifier when dma debugging is disabled Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 32/97] dma-debug: Fix bug causing build warning Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 33/97] cifs: NULL out tcon, pSesInfo, and srvTcp pointers when chasing DFS referrals Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 34/97] x86/amd-iommu: Fix initialization failure panic Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 35/97] ioat3: fix p-disabled q-continuation Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 36/97] ioat2,3: put channel hardware in known state at init Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 37/97] KVM: MMU: remove prefault from invlpg handler Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 38/97] KVM: LAPIC: make sure IRR bitmap is scanned after vm load Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 39/97] Libertas: fix buffer overflow in lbs_get_essid() Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 40/97] iwmc3200wifi: fix array out-of-boundary access Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 41/97] mac80211: fix propagation of failed hardware reconfigurations Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 42/97] mac80211: fix WMM AP settings application Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 43/97] mac80211: Fix IBSS merge Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 44/97] cfg80211: fix race between deauth and assoc response Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 45/97] ath5k: fix SWI calibration interrupt storm Greg Kroah-Hartman
2010-01-05 0:32 ` [PATCH 46/97] ath9k: wake hardware for interface IBSS/AP/Mesh removal Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 47/97] ath9k: Fix TX queue draining Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 48/97] ath9k: fix missed error codes in the tx status check Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 49/97] ath9k: wake hardware during AMPDU TX actions Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 50/97] ath9k: fix suspend by waking device prior to stop Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 51/97] ath9k_hw: Fix possible OOB array indexing in gen_timer_index[] on 64-bit Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 52/97] ath9k_hw: Fix AR_GPIO_INPUT_EN_VAL_BT_PRIORITY_BB and its shift value in 0x4054 Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 53/97] iwl3945: disable power save Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 54/97] iwl3945: fix panic in iwl3945 driver Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 55/97] iwlwifi: fix EEPROM/OTP reading endian annotations and a bug Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 56/97] iwlwifi: fix more eeprom endian bugs Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 57/97] iwlwifi: fix 40MHz operation setting on cards that do not allow it Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 58/97] mac80211: fix race with suspend and dynamic_ps_disable_work Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 59/97] NOMMU: Optimise away the {dac_,}mmap_min_addr tests Greg Kroah-Hartman
2010-01-07 2:03 ` Mike Frysinger
2010-01-07 17:58 ` Greg KH
2010-01-08 5:40 ` [PATCH] kernel/sysctl.c: fix stable merge error in NOMMU mmap_min_addr Mike Frysinger
2010-01-05 0:33 ` [PATCH 60/97] 'sysctl_max_map_count' should be non-negative Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 61/97] kernel/sysctl.c: fix the incomplete part of sysctl_max_map_count-should-be-non-negative.patch Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 62/97] V4L/DVB (13596): ov511.c typo: lock => unlock Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 63/97] x86/ptrace: make genregs[32]_get/set more robust Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 64/97] memcg: avoid oom-killing innocent task in case of use_hierarchy Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 65/97] e100: Fix broken cbs accounting due to missing memset Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 66/97] ipv6: reassembly: use seperate reassembly queues for conntrack and local delivery Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 67/97] netfilter: fix crashes in bridge netfilter caused by fragment jumps Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 68/97] hwmon: (sht15) Off-by-one error in array index + incorrect constants Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 69/97] b43: avoid PPC fault during resume Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 70/97] Keys: KEYCTL_SESSION_TO_PARENT needs TIF_NOTIFY_RESUME architecture support Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 71/97] sched: Fix balance vs hotplug race Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 72/97] drm/radeon/kms: fix crtc vblank update for r600 Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 73/97] drm: disable all the possible outputs/crtcs before entering KMS mode Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 74/97] S390: dasd: support DIAG access for read-only devices Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 75/97] xen: fix is_disconnected_device/exists_disconnected_device Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 76/97] xen: improvement to wait_for_devices() Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 77/97] xen: wait up to 5 minutes for device connetion Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 78/97] orinoco: fix GFP_KERNEL in orinoco_set_key with interrupts disabled Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 79/97] udf: Try harder when looking for VAT inode Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 80/97] Add unlocked version of inode_add_bytes() function Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 81/97] quota: decouple fs reserved space from quota reservation Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 82/97] ext4: Convert to generic reserved quota's space management Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 83/97] ext4: Fix potential quota deadlock Greg Kroah-Hartman
2010-01-05 0:47 ` Jan Kara
2010-01-05 18:56 ` Greg KH
2010-01-05 21:39 ` Jan Kara
2010-01-05 23:16 ` Greg KH
2010-01-06 5:20 ` tytso
2010-01-06 10:43 ` Jan Kara
2010-01-06 18:27 ` [stable] " Greg KH
2010-01-06 19:55 ` Jan Kara
2010-01-05 0:33 ` [PATCH 84/97] ext4: fix sleep inside spinlock issue with quota and dealloc (#14739) Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 85/97] x86, msr: Unify rdmsr_on_cpus/wrmsr_on_cpus Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 86/97] cpumask: use modern cpumask style in drivers/edac/amd64_edac.c Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 87/97] amd64_edac: unify MCGCTL ECC switching Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 88/97] x86, msr: Add support for non-contiguous cpumasks Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 89/97] x86, msr: msrs_alloc/free for CONFIG_SMP=n Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 90/97] amd64_edac: fix driver instance freeing Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 91/97] amd64_edac: make driver loading more robust Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 92/97] amd64_edac: fix forcing module load/unload Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 93/97] sched: Sched_rt_periodic_timer vs cpu hotplug Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 94/97] ext4: Update documentation to correct the inode_readahead_blks option name Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 95/97] lguest: fix bug in setting guest GDT entry Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 96/97] vmscan: do not evict inactive pages when skipping an active list scan Greg Kroah-Hartman
2010-01-05 0:33 ` [PATCH 97/97] Linux 2.6.32.3-rc1 Greg Kroah-Hartman
2010-01-05 1:13 ` [Stable-review] " Jake Edge
2010-01-05 14:58 ` Greg KH
2010-01-05 15:10 ` Jake Edge
2010-01-05 15:26 ` Greg KH
2010-01-05 0:55 ` [Stable-review] [00/97] 2.6.32.3 stable review Luis R. Rodriguez
2010-01-05 18:56 ` Greg KH
2010-01-05 10:26 ` Hugh Dickins
2010-01-05 18:53 ` Greg KH
2010-01-05 19:20 ` Greg KH
2010-01-05 19:21 ` [PATCH 098/101] ksm: fix mlockfreed to munlocked Greg Kroah-Hartman
2010-01-05 19:21 ` [PATCH 099/101] rt2x00: Disable powersaving for rt61pci and rt2800pci Greg Kroah-Hartman
2010-01-05 19:21 ` [PATCH 100/101] generic_permission: MAY_OPEN is not write access Greg Kroah-Hartman
2010-01-05 19:21 ` [PATCH 101/101] Linux 2.6.32.3-rc2 Greg Kroah-Hartman
2010-01-05 20:54 ` [PATCH 099/101] rt2x00: Disable powersaving for rt61pci and rt2800pci Gertjan van Wingerde
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1262651630-7354-3-git-send-email-gregkh@suse.de \
--to=gregkh@suse.de \
--cc=James.Bottomley@suse.de \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=fujita.tomonori@lab.ntt.co.jp \
--cc=linux-kernel@vger.kernel.org \
--cc=stable-review@kernel.org \
--cc=stable@kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome