* [PATCH for-rc 0/4] RDMA/hns: Bugfixes
@ 2024-12-20 5:52 Junxian Huang
2024-12-20 5:52 ` [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer Junxian Huang
` (4 more replies)
0 siblings, 5 replies; 6+ messages in thread
From: Junxian Huang @ 2024-12-20 5:52 UTC (permalink / raw)
To: jgg, leon
Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang
Here are some recent bugfixes for hns.
Chengchang Tang (3):
RDMA/hns: Fix accessing invalid dip_ctx during destroying QP
RDMA/hns: Fix warning storm caused by invalid input in IO path
RDMA/hns: Fix missing flush CQE for DWQE
wenglianfa (1):
RDMA/hns: Fix mapping error of zero-hop WQE buffer
drivers/infiniband/hw/hns/hns_roce_hem.c | 43 +++++++++++++++-------
drivers/infiniband/hw/hns/hns_roce_hw_v2.c | 11 +++++-
drivers/infiniband/hw/hns/hns_roce_mr.c | 5 ---
3 files changed, 38 insertions(+), 21 deletions(-)
--
2.33.0
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer
2024-12-20 5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang
@ 2024-12-20 5:52 ` Junxian Huang
2024-12-20 5:52 ` [PATCH for-rc 2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP Junxian Huang
` (3 subsequent siblings)
4 siblings, 0 replies; 6+ messages in thread
From: Junxian Huang @ 2024-12-20 5:52 UTC (permalink / raw)
To: jgg, leon
Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang
From: wenglianfa <wenglianfa@huawei.com>
Due to HW limitation, the three region of WQE buffer must be mapped
and set to HW in a fixed order: SQ buffer, SGE buffer, and RQ buffer.
Currently when one region is zero-hop while the other two are not,
the zero-hop region will not be mapped. This violate the limitation
above and leads to address error.
Fixes: 38389eaa4db1 ("RDMA/hns: Add mtr support for mixed multihop addressing")
Signed-off-by: wenglianfa <wenglianfa@huawei.com>
Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com>
---
drivers/infiniband/hw/hns/hns_roce_hem.c | 43 ++++++++++++++++--------
drivers/infiniband/hw/hns/hns_roce_mr.c | 5 ---
2 files changed, 29 insertions(+), 19 deletions(-)
diff --git a/drivers/infiniband/hw/hns/hns_roce_hem.c b/drivers/infiniband/hw/hns/hns_roce_hem.c
index f84521be3bea..605562122ecc 100644
--- a/drivers/infiniband/hw/hns/hns_roce_hem.c
+++ b/drivers/infiniband/hw/hns/hns_roce_hem.c
@@ -931,6 +931,7 @@ struct hns_roce_hem_item {
size_t count; /* max ba numbers */
int start; /* start buf offset in this hem */
int end; /* end buf offset in this hem */
+ bool exist_bt;
};
/* All HEM items are linked in a tree structure */
@@ -959,6 +960,7 @@ hem_list_alloc_item(struct hns_roce_dev *hr_dev, int start, int end, int count,
}
}
+ hem->exist_bt = exist_bt;
hem->count = count;
hem->start = start;
hem->end = end;
@@ -969,22 +971,22 @@ hem_list_alloc_item(struct hns_roce_dev *hr_dev, int start, int end, int count,
}
static void hem_list_free_item(struct hns_roce_dev *hr_dev,
- struct hns_roce_hem_item *hem, bool exist_bt)
+ struct hns_roce_hem_item *hem)
{
- if (exist_bt)
+ if (hem->exist_bt)
dma_free_coherent(hr_dev->dev, hem->count * BA_BYTE_LEN,
hem->addr, hem->dma_addr);
kfree(hem);
}
static void hem_list_free_all(struct hns_roce_dev *hr_dev,
- struct list_head *head, bool exist_bt)
+ struct list_head *head)
{
struct hns_roce_hem_item *hem, *temp_hem;
list_for_each_entry_safe(hem, temp_hem, head, list) {
list_del(&hem->list);
- hem_list_free_item(hr_dev, hem, exist_bt);
+ hem_list_free_item(hr_dev, hem);
}
}
@@ -1084,6 +1086,10 @@ int hns_roce_hem_list_calc_root_ba(const struct hns_roce_buf_region *regions,
for (i = 0; i < region_cnt; i++) {
r = (struct hns_roce_buf_region *)®ions[i];
+ /* when r->hopnum = 0, the region should not occupy root_ba. */
+ if (!r->hopnum)
+ continue;
+
if (r->hopnum > 1) {
step = hem_list_calc_ba_range(r->hopnum, 1, unit);
if (step > 0)
@@ -1177,7 +1183,7 @@ static int hem_list_alloc_mid_bt(struct hns_roce_dev *hr_dev,
err_exit:
for (level = 1; level < hopnum; level++)
- hem_list_free_all(hr_dev, &temp_list[level], true);
+ hem_list_free_all(hr_dev, &temp_list[level]);
return ret;
}
@@ -1218,16 +1224,26 @@ static int alloc_fake_root_bt(struct hns_roce_dev *hr_dev, void *cpu_base,
{
struct hns_roce_hem_item *hem;
+ /* This is on the has_mtt branch, if r->hopnum
+ * is 0, there is no root_ba to reuse for the
+ * region's fake hem, so a dma_alloc request is
+ * necessary here.
+ */
hem = hem_list_alloc_item(hr_dev, r->offset, r->offset + r->count - 1,
- r->count, false);
+ r->count, !r->hopnum);
if (!hem)
return -ENOMEM;
- hem_list_assign_bt(hem, cpu_base, phy_base);
+ /* The root_ba can be reused only when r->hopnum > 0. */
+ if (r->hopnum)
+ hem_list_assign_bt(hem, cpu_base, phy_base);
list_add(&hem->list, branch_head);
list_add(&hem->sibling, leaf_head);
- return r->count;
+ /* If r->hopnum == 0, 0 is returned,
+ * so that the root_bt entry is not occupied.
+ */
+ return r->hopnum ? r->count : 0;
}
static int setup_middle_bt(struct hns_roce_dev *hr_dev, void *cpu_base,
@@ -1271,7 +1287,7 @@ setup_root_hem(struct hns_roce_dev *hr_dev, struct hns_roce_hem_list *hem_list,
return -ENOMEM;
total = 0;
- for (i = 0; i < region_cnt && total < max_ba_num; i++) {
+ for (i = 0; i < region_cnt && total <= max_ba_num; i++) {
r = ®ions[i];
if (!r->count)
continue;
@@ -1337,9 +1353,9 @@ static int hem_list_alloc_root_bt(struct hns_roce_dev *hr_dev,
region_cnt);
if (ret) {
for (i = 0; i < region_cnt; i++)
- hem_list_free_all(hr_dev, &head.branch[i], false);
+ hem_list_free_all(hr_dev, &head.branch[i]);
- hem_list_free_all(hr_dev, &head.root, true);
+ hem_list_free_all(hr_dev, &head.root);
}
return ret;
@@ -1402,10 +1418,9 @@ void hns_roce_hem_list_release(struct hns_roce_dev *hr_dev,
for (i = 0; i < HNS_ROCE_MAX_BT_REGION; i++)
for (j = 0; j < HNS_ROCE_MAX_BT_LEVEL; j++)
- hem_list_free_all(hr_dev, &hem_list->mid_bt[i][j],
- j != 0);
+ hem_list_free_all(hr_dev, &hem_list->mid_bt[i][j]);
- hem_list_free_all(hr_dev, &hem_list->root_bt, true);
+ hem_list_free_all(hr_dev, &hem_list->root_bt);
INIT_LIST_HEAD(&hem_list->btm_bt);
hem_list->root_ba = 0;
}
diff --git a/drivers/infiniband/hw/hns/hns_roce_mr.c b/drivers/infiniband/hw/hns/hns_roce_mr.c
index bf30b3a65a9b..55b9283bfc6f 100644
--- a/drivers/infiniband/hw/hns/hns_roce_mr.c
+++ b/drivers/infiniband/hw/hns/hns_roce_mr.c
@@ -814,11 +814,6 @@ int hns_roce_mtr_map(struct hns_roce_dev *hr_dev, struct hns_roce_mtr *mtr,
for (i = 0, mapped_cnt = 0; i < mtr->hem_cfg.region_count &&
mapped_cnt < page_cnt; i++) {
r = &mtr->hem_cfg.region[i];
- /* if hopnum is 0, no need to map pages in this region */
- if (!r->hopnum) {
- mapped_cnt += r->count;
- continue;
- }
if (r->offset + r->count > page_cnt) {
ret = -EINVAL;
--
2.33.0
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH for-rc 2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP
2024-12-20 5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang
2024-12-20 5:52 ` [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer Junxian Huang
@ 2024-12-20 5:52 ` Junxian Huang
2024-12-20 5:52 ` [PATCH for-rc 3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path Junxian Huang
` (2 subsequent siblings)
4 siblings, 0 replies; 6+ messages in thread
From: Junxian Huang @ 2024-12-20 5:52 UTC (permalink / raw)
To: jgg, leon
Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang
From: Chengchang Tang <tangchengchang@huawei.com>
If it fails to modify QP to RTR, dip_ctx will not be attached. And
during detroying QP, the invalid dip_ctx pointer will be accessed.
Fixes: faa62440a577 ("RDMA/hns: Fix different dgids mapping to the same dip_idx")
Signed-off-by: Chengchang Tang <tangchengchang@huawei.com>
Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com>
---
drivers/infiniband/hw/hns/hns_roce_hw_v2.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
index 697b17cca02e..6dddadb90e02 100644
--- a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
+++ b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
@@ -5619,6 +5619,9 @@ static void put_dip_ctx_idx(struct hns_roce_dev *hr_dev,
{
struct hns_roce_dip *hr_dip = hr_qp->dip;
+ if (!hr_dip)
+ return;
+
xa_lock(&hr_dev->qp_table.dip_xa);
hr_dip->qp_cnt--;
--
2.33.0
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH for-rc 3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path
2024-12-20 5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang
2024-12-20 5:52 ` [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer Junxian Huang
2024-12-20 5:52 ` [PATCH for-rc 2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP Junxian Huang
@ 2024-12-20 5:52 ` Junxian Huang
2024-12-20 5:52 ` [PATCH for-rc 4/4] RDMA/hns: Fix missing flush CQE for DWQE Junxian Huang
2024-12-23 14:58 ` [PATCH for-rc 0/4] RDMA/hns: Bugfixes Leon Romanovsky
4 siblings, 0 replies; 6+ messages in thread
From: Junxian Huang @ 2024-12-20 5:52 UTC (permalink / raw)
To: jgg, leon
Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang
From: Chengchang Tang <tangchengchang@huawei.com>
WARN_ON() is called in the IO path. And it could lead to a warning
storm. Use WARN_ON_ONCE() instead of WARN_ON().
Fixes: 12542f1de179 ("RDMA/hns: Refactor process about opcode in post_send()")
Signed-off-by: Chengchang Tang <tangchengchang@huawei.com>
Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com>
---
drivers/infiniband/hw/hns/hns_roce_hw_v2.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
index 6dddadb90e02..d0469d27c63c 100644
--- a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
+++ b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
@@ -468,7 +468,7 @@ static inline int set_ud_wqe(struct hns_roce_qp *qp,
valid_num_sge = calc_wr_sge_num(wr, &msg_len);
ret = set_ud_opcode(ud_sq_wqe, wr);
- if (WARN_ON(ret))
+ if (WARN_ON_ONCE(ret))
return ret;
ud_sq_wqe->msg_len = cpu_to_le32(msg_len);
@@ -572,7 +572,7 @@ static inline int set_rc_wqe(struct hns_roce_qp *qp,
rc_sq_wqe->msg_len = cpu_to_le32(msg_len);
ret = set_rc_opcode(hr_dev, rc_sq_wqe, wr);
- if (WARN_ON(ret))
+ if (WARN_ON_ONCE(ret))
return ret;
hr_reg_write(rc_sq_wqe, RC_SEND_WQE_SO,
--
2.33.0
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH for-rc 4/4] RDMA/hns: Fix missing flush CQE for DWQE
2024-12-20 5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang
` (2 preceding siblings ...)
2024-12-20 5:52 ` [PATCH for-rc 3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path Junxian Huang
@ 2024-12-20 5:52 ` Junxian Huang
2024-12-23 14:58 ` [PATCH for-rc 0/4] RDMA/hns: Bugfixes Leon Romanovsky
4 siblings, 0 replies; 6+ messages in thread
From: Junxian Huang @ 2024-12-20 5:52 UTC (permalink / raw)
To: jgg, leon
Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang
From: Chengchang Tang <tangchengchang@huawei.com>
Flush CQE handler has not been called if QP state gets into errored
mode in DWQE path. So, the new added outstanding WQEs will never be
flushed.
It leads to a hung task timeout when using NFS over RDMA:
__switch_to+0x7c/0xd0
__schedule+0x350/0x750
schedule+0x50/0xf0
schedule_timeout+0x2c8/0x340
wait_for_common+0xf4/0x2b0
wait_for_completion+0x20/0x40
__ib_drain_sq+0x140/0x1d0 [ib_core]
ib_drain_sq+0x98/0xb0 [ib_core]
rpcrdma_xprt_disconnect+0x68/0x270 [rpcrdma]
xprt_rdma_close+0x20/0x60 [rpcrdma]
xprt_autoclose+0x64/0x1cc [sunrpc]
process_one_work+0x1d8/0x4e0
worker_thread+0x154/0x420
kthread+0x108/0x150
ret_from_fork+0x10/0x18
Fixes: 01584a5edcc4 ("RDMA/hns: Add support of direct wqe")
Signed-off-by: Chengchang Tang <tangchengchang@huawei.com>
Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com>
---
drivers/infiniband/hw/hns/hns_roce_hw_v2.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
index d0469d27c63c..0144e7210d05 100644
--- a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
+++ b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c
@@ -670,6 +670,10 @@ static void write_dwqe(struct hns_roce_dev *hr_dev, struct hns_roce_qp *qp,
#define HNS_ROCE_SL_SHIFT 2
struct hns_roce_v2_rc_send_wqe *rc_sq_wqe = wqe;
+ if (unlikely(qp->state == IB_QPS_ERR)) {
+ flush_cqe(hr_dev, qp);
+ return;
+ }
/* All kinds of DirectWQE have the same header field layout */
hr_reg_enable(rc_sq_wqe, RC_SEND_WQE_FLAG);
hr_reg_write(rc_sq_wqe, RC_SEND_WQE_DB_SL_L, qp->sl);
--
2.33.0
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH for-rc 0/4] RDMA/hns: Bugfixes
2024-12-20 5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang
` (3 preceding siblings ...)
2024-12-20 5:52 ` [PATCH for-rc 4/4] RDMA/hns: Fix missing flush CQE for DWQE Junxian Huang
@ 2024-12-23 14:58 ` Leon Romanovsky
4 siblings, 0 replies; 6+ messages in thread
From: Leon Romanovsky @ 2024-12-23 14:58 UTC (permalink / raw)
To: jgg, Junxian Huang; +Cc: linux-rdma, linuxarm, linux-kernel, tangchengchang
On Fri, 20 Dec 2024 13:52:45 +0800, Junxian Huang wrote:
> Here are some recent bugfixes for hns.
>
> Chengchang Tang (3):
> RDMA/hns: Fix accessing invalid dip_ctx during destroying QP
> RDMA/hns: Fix warning storm caused by invalid input in IO path
> RDMA/hns: Fix missing flush CQE for DWQE
>
> [...]
Applied, thanks!
[1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer
https://git.kernel.org/rdma/rdma/c/8673a6c2d9e483
[2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP
https://git.kernel.org/rdma/rdma/c/0572eccf239ce4
[3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path
https://git.kernel.org/rdma/rdma/c/fa5c4ba8cdbfd2
[4/4] RDMA/hns: Fix missing flush CQE for DWQE
https://git.kernel.org/rdma/rdma/c/e3debdd48423d3
Best regards,
--
Leon Romanovsky <leon@kernel.org>
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2024-12-23 14:58 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-12-20 5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang
2024-12-20 5:52 ` [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer Junxian Huang
2024-12-20 5:52 ` [PATCH for-rc 2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP Junxian Huang
2024-12-20 5:52 ` [PATCH for-rc 3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path Junxian Huang
2024-12-20 5:52 ` [PATCH for-rc 4/4] RDMA/hns: Fix missing flush CQE for DWQE Junxian Huang
2024-12-23 14:58 ` [PATCH for-rc 0/4] RDMA/hns: Bugfixes Leon Romanovsky
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®