mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH for-rc 0/4] RDMA/hns: Bugfixes
@ 2024-12-20  5:52 Junxian Huang
  2024-12-20  5:52 ` [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer Junxian Huang
                   ` (4 more replies)
  0 siblings, 5 replies; 6+ messages in thread
From: Junxian Huang @ 2024-12-20  5:52 UTC (permalink / raw)
  To: jgg, leon
  Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang

Here are some recent bugfixes for hns.

Chengchang Tang (3):
  RDMA/hns: Fix accessing invalid dip_ctx during destroying QP
  RDMA/hns: Fix warning storm caused by invalid input in IO path
  RDMA/hns: Fix missing flush CQE for DWQE

wenglianfa (1):
  RDMA/hns: Fix mapping error of zero-hop WQE buffer

 drivers/infiniband/hw/hns/hns_roce_hem.c   | 43 +++++++++++++++-------
 drivers/infiniband/hw/hns/hns_roce_hw_v2.c | 11 +++++-
 drivers/infiniband/hw/hns/hns_roce_mr.c    |  5 ---
 3 files changed, 38 insertions(+), 21 deletions(-)

--
2.33.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer
  2024-12-20  5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang
@ 2024-12-20  5:52 ` Junxian Huang
  2024-12-20  5:52 ` [PATCH for-rc 2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP Junxian Huang
                   ` (3 subsequent siblings)
  4 siblings, 0 replies; 6+ messages in thread
From: Junxian Huang @ 2024-12-20  5:52 UTC (permalink / raw)
  To: jgg, leon
  Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang

From: wenglianfa <wenglianfa@huawei.com>

Due to HW limitation, the three region of WQE buffer must be mapped
and set to HW in a fixed order: SQ buffer, SGE buffer, and RQ buffer.

Currently when one region is zero-hop while the other two are not,
the zero-hop region will not be mapped. This violate the limitation
above and leads to address error.

Fixes: 38389eaa4db1 ("RDMA/hns: Add mtr support for mixed multihop addressing")
Signed-off-by: wenglianfa <wenglianfa@huawei.com>
Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com>
---
 drivers/infiniband/hw/hns/hns_roce_hem.c | 43 ++++++++++++++++--------
 drivers/infiniband/hw/hns/hns_roce_mr.c  |  5 ---
 2 files changed, 29 insertions(+), 19 deletions(-)

diff --git a/drivers/infiniband/hw/hns/hns_roce_hem.c b/drivers/infiniband/hw/hns/hns_roce_hem.c
index f84521be3bea..605562122ecc 100644
--- a/drivers/infiniband/hw/hns/hns_roce_hem.c
+++ b/drivers/infiniband/hw/hns/hns_roce_hem.c
@@ -931,6 +931,7 @@ struct hns_roce_hem_item {
 	size_t count; /* max ba numbers */
 	int start; /* start buf offset in this hem */
 	int end; /* end buf offset in this hem */
+	bool exist_bt;
 };
 
 /* All HEM items are linked in a tree structure */
@@ -959,6 +960,7 @@ hem_list_alloc_item(struct hns_roce_dev *hr_dev, int start, int end, int count,
 		}
 	}
 
+	hem->exist_bt = exist_bt;
 	hem->count = count;
 	hem->start = start;
 	hem->end = end;
@@ -969,22 +971,22 @@ hem_list_alloc_item(struct hns_roce_dev *hr_dev, int start, int end, int count,
 }
 
 static void hem_list_free_item(struct hns_roce_dev *hr_dev,
-			       struct hns_roce_hem_item *hem, bool exist_bt)
+			       struct hns_roce_hem_item *hem)
 {
-	if (exist_bt)
+	if (hem->exist_bt)
 		dma_free_coherent(hr_dev->dev, hem->count * BA_BYTE_LEN,
 				  hem->addr, hem->dma_addr);
 	kfree(hem);
 }
 
 static void hem_list_free_all(struct hns_roce_dev *hr_dev,
-			      struct list_head *head, bool exist_bt)
+			      struct list_head *head)
 {
 	struct hns_roce_hem_item *hem, *temp_hem;
 
 	list_for_each_entry_safe(hem, temp_hem, head, list) {
 		list_del(&hem->list);
-		hem_list_free_item(hr_dev, hem, exist_bt);
+		hem_list_free_item(hr_dev, hem);
 	}
 }
 
@@ -1084,6 +1086,10 @@ int hns_roce_hem_list_calc_root_ba(const struct hns_roce_buf_region *regions,
 
 	for (i = 0; i < region_cnt; i++) {
 		r = (struct hns_roce_buf_region *)&regions[i];
+		/* when r->hopnum = 0, the region should not occupy root_ba. */
+		if (!r->hopnum)
+			continue;
+
 		if (r->hopnum > 1) {
 			step = hem_list_calc_ba_range(r->hopnum, 1, unit);
 			if (step > 0)
@@ -1177,7 +1183,7 @@ static int hem_list_alloc_mid_bt(struct hns_roce_dev *hr_dev,
 
 err_exit:
 	for (level = 1; level < hopnum; level++)
-		hem_list_free_all(hr_dev, &temp_list[level], true);
+		hem_list_free_all(hr_dev, &temp_list[level]);
 
 	return ret;
 }
@@ -1218,16 +1224,26 @@ static int alloc_fake_root_bt(struct hns_roce_dev *hr_dev, void *cpu_base,
 {
 	struct hns_roce_hem_item *hem;
 
+	/* This is on the has_mtt branch, if r->hopnum
+	 * is 0, there is no root_ba to reuse for the
+	 * region's fake hem, so a dma_alloc request is
+	 * necessary here.
+	 */
 	hem = hem_list_alloc_item(hr_dev, r->offset, r->offset + r->count - 1,
-				  r->count, false);
+				  r->count, !r->hopnum);
 	if (!hem)
 		return -ENOMEM;
 
-	hem_list_assign_bt(hem, cpu_base, phy_base);
+	/* The root_ba can be reused only when r->hopnum > 0. */
+	if (r->hopnum)
+		hem_list_assign_bt(hem, cpu_base, phy_base);
 	list_add(&hem->list, branch_head);
 	list_add(&hem->sibling, leaf_head);
 
-	return r->count;
+	/* If r->hopnum == 0, 0 is returned,
+	 * so that the root_bt entry is not occupied.
+	 */
+	return r->hopnum ? r->count : 0;
 }
 
 static int setup_middle_bt(struct hns_roce_dev *hr_dev, void *cpu_base,
@@ -1271,7 +1287,7 @@ setup_root_hem(struct hns_roce_dev *hr_dev, struct hns_roce_hem_list *hem_list,
 		return -ENOMEM;
 
 	total = 0;
-	for (i = 0; i < region_cnt && total < max_ba_num; i++) {
+	for (i = 0; i < region_cnt && total <= max_ba_num; i++) {
 		r = &regions[i];
 		if (!r->count)
 			continue;
@@ -1337,9 +1353,9 @@ static int hem_list_alloc_root_bt(struct hns_roce_dev *hr_dev,
 			     region_cnt);
 	if (ret) {
 		for (i = 0; i < region_cnt; i++)
-			hem_list_free_all(hr_dev, &head.branch[i], false);
+			hem_list_free_all(hr_dev, &head.branch[i]);
 
-		hem_list_free_all(hr_dev, &head.root, true);
+		hem_list_free_all(hr_dev, &head.root);
 	}
 
 	return ret;
@@ -1402,10 +1418,9 @@ void hns_roce_hem_list_release(struct hns_roce_dev *hr_dev,
 
 	for (i = 0; i < HNS_ROCE_MAX_BT_REGION; i++)
 		for (j = 0; j < HNS_ROCE_MAX_BT_LEVEL; j++)
-			hem_list_free_all(hr_dev, &hem_list->mid_bt[i][j],
-					  j != 0);
+			hem_list_free_all(hr_dev, &hem_list->mid_bt[i][j]);
 
-	hem_list_free_all(hr_dev, &hem_list->root_bt, true);
+	hem_list_free_all(hr_dev, &hem_list->root_bt);
 	INIT_LIST_HEAD(&hem_list->btm_bt);
 	hem_list->root_ba = 0;
 }
diff --git a/drivers/infiniband/hw/hns/hns_roce_mr.c b/drivers/infiniband/hw/hns/hns_roce_mr.c
index bf30b3a65a9b..55b9283bfc6f 100644
--- a/drivers/infiniband/hw/hns/hns_roce_mr.c
+++ b/drivers/infiniband/hw/hns/hns_roce_mr.c
@@ -814,11 +814,6 @@ int hns_roce_mtr_map(struct hns_roce_dev *hr_dev, struct hns_roce_mtr *mtr,
 	for (i = 0, mapped_cnt = 0; i < mtr->hem_cfg.region_count &&
 	     mapped_cnt < page_cnt; i++) {
 		r = &mtr->hem_cfg.region[i];
-		/* if hopnum is 0, no need to map pages in this region */
-		if (!r->hopnum) {
-			mapped_cnt += r->count;
-			continue;
-		}
 
 		if (r->offset + r->count > page_cnt) {
 			ret = -EINVAL;
-- 
2.33.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH for-rc 2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP
  2024-12-20  5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang
  2024-12-20  5:52 ` [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer Junxian Huang
@ 2024-12-20  5:52 ` Junxian Huang
  2024-12-20  5:52 ` [PATCH for-rc 3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path Junxian Huang
                   ` (2 subsequent siblings)
  4 siblings, 0 replies; 6+ messages in thread
From: Junxian Huang @ 2024-12-20  5:52 UTC (permalink / raw)
  To: jgg, leon
  Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang

From: Chengchang Tang <tangchengchang@huawei.com>

If it fails to modify QP to RTR, dip_ctx will not be attached. And
during detroying QP, the invalid dip_ctx pointer will be accessed.

Fixes: faa62440a577 ("RDMA/hns: Fix different dgids mapping to the same dip_idx")
Signed-off-by: Chengchang Tang <tangchengchang@huawei.com>
Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com>
---
 drivers/infiniband/hw/hns/hns_roce_hw_v2.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
index 697b17cca02e..6dddadb90e02 100644
--- a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
+++ b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
@@ -5619,6 +5619,9 @@ static void put_dip_ctx_idx(struct hns_roce_dev *hr_dev,
 {
 	struct hns_roce_dip *hr_dip = hr_qp->dip;
 
+	if (!hr_dip)
+		return;
+
 	xa_lock(&hr_dev->qp_table.dip_xa);
 
 	hr_dip->qp_cnt--;
-- 
2.33.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH for-rc 3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path
  2024-12-20  5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang
  2024-12-20  5:52 ` [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer Junxian Huang
  2024-12-20  5:52 ` [PATCH for-rc 2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP Junxian Huang
@ 2024-12-20  5:52 ` Junxian Huang
  2024-12-20  5:52 ` [PATCH for-rc 4/4] RDMA/hns: Fix missing flush CQE for DWQE Junxian Huang
  2024-12-23 14:58 ` [PATCH for-rc 0/4] RDMA/hns: Bugfixes Leon Romanovsky
  4 siblings, 0 replies; 6+ messages in thread
From: Junxian Huang @ 2024-12-20  5:52 UTC (permalink / raw)
  To: jgg, leon
  Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang

From: Chengchang Tang <tangchengchang@huawei.com>

WARN_ON() is called in the IO path. And it could lead to a warning
storm. Use WARN_ON_ONCE() instead of WARN_ON().

Fixes: 12542f1de179 ("RDMA/hns: Refactor process about opcode in post_send()")
Signed-off-by: Chengchang Tang <tangchengchang@huawei.com>
Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com>
---
 drivers/infiniband/hw/hns/hns_roce_hw_v2.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
index 6dddadb90e02..d0469d27c63c 100644
--- a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
+++ b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
@@ -468,7 +468,7 @@ static inline int set_ud_wqe(struct hns_roce_qp *qp,
 	valid_num_sge = calc_wr_sge_num(wr, &msg_len);
 
 	ret = set_ud_opcode(ud_sq_wqe, wr);
-	if (WARN_ON(ret))
+	if (WARN_ON_ONCE(ret))
 		return ret;
 
 	ud_sq_wqe->msg_len = cpu_to_le32(msg_len);
@@ -572,7 +572,7 @@ static inline int set_rc_wqe(struct hns_roce_qp *qp,
 	rc_sq_wqe->msg_len = cpu_to_le32(msg_len);
 
 	ret = set_rc_opcode(hr_dev, rc_sq_wqe, wr);
-	if (WARN_ON(ret))
+	if (WARN_ON_ONCE(ret))
 		return ret;
 
 	hr_reg_write(rc_sq_wqe, RC_SEND_WQE_SO,
-- 
2.33.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH for-rc 4/4] RDMA/hns: Fix missing flush CQE for DWQE
  2024-12-20  5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang
                   ` (2 preceding siblings ...)
  2024-12-20  5:52 ` [PATCH for-rc 3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path Junxian Huang
@ 2024-12-20  5:52 ` Junxian Huang
  2024-12-23 14:58 ` [PATCH for-rc 0/4] RDMA/hns: Bugfixes Leon Romanovsky
  4 siblings, 0 replies; 6+ messages in thread
From: Junxian Huang @ 2024-12-20  5:52 UTC (permalink / raw)
  To: jgg, leon
  Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang

From: Chengchang Tang <tangchengchang@huawei.com>

Flush CQE handler has not been called if QP state gets into errored
mode in DWQE path. So, the new added outstanding WQEs will never be
flushed.

It leads to a hung task timeout when using NFS over RDMA:
    __switch_to+0x7c/0xd0
    __schedule+0x350/0x750
    schedule+0x50/0xf0
    schedule_timeout+0x2c8/0x340
    wait_for_common+0xf4/0x2b0
    wait_for_completion+0x20/0x40
    __ib_drain_sq+0x140/0x1d0 [ib_core]
    ib_drain_sq+0x98/0xb0 [ib_core]
    rpcrdma_xprt_disconnect+0x68/0x270 [rpcrdma]
    xprt_rdma_close+0x20/0x60 [rpcrdma]
    xprt_autoclose+0x64/0x1cc [sunrpc]
    process_one_work+0x1d8/0x4e0
    worker_thread+0x154/0x420
    kthread+0x108/0x150
    ret_from_fork+0x10/0x18

Fixes: 01584a5edcc4 ("RDMA/hns: Add support of direct wqe")
Signed-off-by: Chengchang Tang <tangchengchang@huawei.com>
Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com>
---
 drivers/infiniband/hw/hns/hns_roce_hw_v2.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
index d0469d27c63c..0144e7210d05 100644
--- a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
+++ b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
@@ -670,6 +670,10 @@ static void write_dwqe(struct hns_roce_dev *hr_dev, struct hns_roce_qp *qp,
 #define HNS_ROCE_SL_SHIFT 2
 	struct hns_roce_v2_rc_send_wqe *rc_sq_wqe = wqe;
 
+	if (unlikely(qp->state == IB_QPS_ERR)) {
+		flush_cqe(hr_dev, qp);
+		return;
+	}
 	/* All kinds of DirectWQE have the same header field layout */
 	hr_reg_enable(rc_sq_wqe, RC_SEND_WQE_FLAG);
 	hr_reg_write(rc_sq_wqe, RC_SEND_WQE_DB_SL_L, qp->sl);
-- 
2.33.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH for-rc 0/4] RDMA/hns: Bugfixes
  2024-12-20  5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang
                   ` (3 preceding siblings ...)
  2024-12-20  5:52 ` [PATCH for-rc 4/4] RDMA/hns: Fix missing flush CQE for DWQE Junxian Huang
@ 2024-12-23 14:58 ` Leon Romanovsky
  4 siblings, 0 replies; 6+ messages in thread
From: Leon Romanovsky @ 2024-12-23 14:58 UTC (permalink / raw)
  To: jgg, Junxian Huang; +Cc: linux-rdma, linuxarm, linux-kernel, tangchengchang


On Fri, 20 Dec 2024 13:52:45 +0800, Junxian Huang wrote:
> Here are some recent bugfixes for hns.
> 
> Chengchang Tang (3):
>   RDMA/hns: Fix accessing invalid dip_ctx during destroying QP
>   RDMA/hns: Fix warning storm caused by invalid input in IO path
>   RDMA/hns: Fix missing flush CQE for DWQE
> 
> [...]

Applied, thanks!

[1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer
      https://git.kernel.org/rdma/rdma/c/8673a6c2d9e483
[2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP
      https://git.kernel.org/rdma/rdma/c/0572eccf239ce4
[3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path
      https://git.kernel.org/rdma/rdma/c/fa5c4ba8cdbfd2
[4/4] RDMA/hns: Fix missing flush CQE for DWQE
      https://git.kernel.org/rdma/rdma/c/e3debdd48423d3

Best regards,
-- 
Leon Romanovsky <leon@kernel.org>


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2024-12-23 14:58 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-12-20  5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang
2024-12-20  5:52 ` [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer Junxian Huang
2024-12-20  5:52 ` [PATCH for-rc 2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP Junxian Huang
2024-12-20  5:52 ` [PATCH for-rc 3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path Junxian Huang
2024-12-20  5:52 ` [PATCH for-rc 4/4] RDMA/hns: Fix missing flush CQE for DWQE Junxian Huang
2024-12-23 14:58 ` [PATCH for-rc 0/4] RDMA/hns: Bugfixes Leon Romanovsky

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®