* [PATCH for-rc 0/4] RDMA/hns: Bugfixes
@ 2024-12-20 5:52 Junxian Huang
2024-12-20 5:52 ` [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer Junxian Huang
` (4 more replies)
0 siblings, 5 replies; 6+ messages in thread
From: Junxian Huang @ 2024-12-20 5:52 UTC (permalink / raw)
To: jgg, leon
Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang
Here are some recent bugfixes for hns.
Chengchang Tang (3):
RDMA/hns: Fix accessing invalid dip_ctx during destroying QP
RDMA/hns: Fix warning storm caused by invalid input in IO path
RDMA/hns: Fix missing flush CQE for DWQE
wenglianfa (1):
RDMA/hns: Fix mapping error of zero-hop WQE buffer
drivers/infiniband/hw/hns/hns_roce_hem.c | 43 +++++++++++++++-------
drivers/infiniband/hw/hns/hns_roce_hw_v2.c | 11 +++++-
drivers/infiniband/hw/hns/hns_roce_mr.c | 5 ---
3 files changed, 38 insertions(+), 21 deletions(-)
--
2.33.0
^ permalink raw reply [flat|nested] 6+ messages in thread* [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer 2024-12-20 5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang @ 2024-12-20 5:52 ` Junxian Huang 2024-12-20 5:52 ` [PATCH for-rc 2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP Junxian Huang ` (3 subsequent siblings) 4 siblings, 0 replies; 6+ messages in thread From: Junxian Huang @ 2024-12-20 5:52 UTC (permalink / raw) To: jgg, leon Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang From: wenglianfa <wenglianfa@huawei.com> Due to HW limitation, the three region of WQE buffer must be mapped and set to HW in a fixed order: SQ buffer, SGE buffer, and RQ buffer. Currently when one region is zero-hop while the other two are not, the zero-hop region will not be mapped. This violate the limitation above and leads to address error. Fixes: 38389eaa4db1 ("RDMA/hns: Add mtr support for mixed multihop addressing") Signed-off-by: wenglianfa <wenglianfa@huawei.com> Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com> --- drivers/infiniband/hw/hns/hns_roce_hem.c | 43 ++++++++++++++++-------- drivers/infiniband/hw/hns/hns_roce_mr.c | 5 --- 2 files changed, 29 insertions(+), 19 deletions(-) diff --git a/drivers/infiniband/hw/hns/hns_roce_hem.c b/drivers/infiniband/hw/hns/hns_roce_hem.c index f84521be3bea..605562122ecc 100644 --- a/drivers/infiniband/hw/hns/hns_roce_hem.c +++ b/drivers/infiniband/hw/hns/hns_roce_hem.c @@ -931,6 +931,7 @@ struct hns_roce_hem_item { size_t count; /* max ba numbers */ int start; /* start buf offset in this hem */ int end; /* end buf offset in this hem */ + bool exist_bt; }; /* All HEM items are linked in a tree structure */ @@ -959,6 +960,7 @@ hem_list_alloc_item(struct hns_roce_dev *hr_dev, int start, int end, int count, } } + hem->exist_bt = exist_bt; hem->count = count; hem->start = start; hem->end = end; @@ -969,22 +971,22 @@ hem_list_alloc_item(struct hns_roce_dev *hr_dev, int start, int end, int count, } static void hem_list_free_item(struct hns_roce_dev *hr_dev, - struct hns_roce_hem_item *hem, bool exist_bt) + struct hns_roce_hem_item *hem) { - if (exist_bt) + if (hem->exist_bt) dma_free_coherent(hr_dev->dev, hem->count * BA_BYTE_LEN, hem->addr, hem->dma_addr); kfree(hem); } static void hem_list_free_all(struct hns_roce_dev *hr_dev, - struct list_head *head, bool exist_bt) + struct list_head *head) { struct hns_roce_hem_item *hem, *temp_hem; list_for_each_entry_safe(hem, temp_hem, head, list) { list_del(&hem->list); - hem_list_free_item(hr_dev, hem, exist_bt); + hem_list_free_item(hr_dev, hem); } } @@ -1084,6 +1086,10 @@ int hns_roce_hem_list_calc_root_ba(const struct hns_roce_buf_region *regions, for (i = 0; i < region_cnt; i++) { r = (struct hns_roce_buf_region *)®ions[i]; + /* when r->hopnum = 0, the region should not occupy root_ba. */ + if (!r->hopnum) + continue; + if (r->hopnum > 1) { step = hem_list_calc_ba_range(r->hopnum, 1, unit); if (step > 0) @@ -1177,7 +1183,7 @@ static int hem_list_alloc_mid_bt(struct hns_roce_dev *hr_dev, err_exit: for (level = 1; level < hopnum; level++) - hem_list_free_all(hr_dev, &temp_list[level], true); + hem_list_free_all(hr_dev, &temp_list[level]); return ret; } @@ -1218,16 +1224,26 @@ static int alloc_fake_root_bt(struct hns_roce_dev *hr_dev, void *cpu_base, { struct hns_roce_hem_item *hem; + /* This is on the has_mtt branch, if r->hopnum + * is 0, there is no root_ba to reuse for the + * region's fake hem, so a dma_alloc request is + * necessary here. + */ hem = hem_list_alloc_item(hr_dev, r->offset, r->offset + r->count - 1, - r->count, false); + r->count, !r->hopnum); if (!hem) return -ENOMEM; - hem_list_assign_bt(hem, cpu_base, phy_base); + /* The root_ba can be reused only when r->hopnum > 0. */ + if (r->hopnum) + hem_list_assign_bt(hem, cpu_base, phy_base); list_add(&hem->list, branch_head); list_add(&hem->sibling, leaf_head); - return r->count; + /* If r->hopnum == 0, 0 is returned, + * so that the root_bt entry is not occupied. + */ + return r->hopnum ? r->count : 0; } static int setup_middle_bt(struct hns_roce_dev *hr_dev, void *cpu_base, @@ -1271,7 +1287,7 @@ setup_root_hem(struct hns_roce_dev *hr_dev, struct hns_roce_hem_list *hem_list, return -ENOMEM; total = 0; - for (i = 0; i < region_cnt && total < max_ba_num; i++) { + for (i = 0; i < region_cnt && total <= max_ba_num; i++) { r = ®ions[i]; if (!r->count) continue; @@ -1337,9 +1353,9 @@ static int hem_list_alloc_root_bt(struct hns_roce_dev *hr_dev, region_cnt); if (ret) { for (i = 0; i < region_cnt; i++) - hem_list_free_all(hr_dev, &head.branch[i], false); + hem_list_free_all(hr_dev, &head.branch[i]); - hem_list_free_all(hr_dev, &head.root, true); + hem_list_free_all(hr_dev, &head.root); } return ret; @@ -1402,10 +1418,9 @@ void hns_roce_hem_list_release(struct hns_roce_dev *hr_dev, for (i = 0; i < HNS_ROCE_MAX_BT_REGION; i++) for (j = 0; j < HNS_ROCE_MAX_BT_LEVEL; j++) - hem_list_free_all(hr_dev, &hem_list->mid_bt[i][j], - j != 0); + hem_list_free_all(hr_dev, &hem_list->mid_bt[i][j]); - hem_list_free_all(hr_dev, &hem_list->root_bt, true); + hem_list_free_all(hr_dev, &hem_list->root_bt); INIT_LIST_HEAD(&hem_list->btm_bt); hem_list->root_ba = 0; } diff --git a/drivers/infiniband/hw/hns/hns_roce_mr.c b/drivers/infiniband/hw/hns/hns_roce_mr.c index bf30b3a65a9b..55b9283bfc6f 100644 --- a/drivers/infiniband/hw/hns/hns_roce_mr.c +++ b/drivers/infiniband/hw/hns/hns_roce_mr.c @@ -814,11 +814,6 @@ int hns_roce_mtr_map(struct hns_roce_dev *hr_dev, struct hns_roce_mtr *mtr, for (i = 0, mapped_cnt = 0; i < mtr->hem_cfg.region_count && mapped_cnt < page_cnt; i++) { r = &mtr->hem_cfg.region[i]; - /* if hopnum is 0, no need to map pages in this region */ - if (!r->hopnum) { - mapped_cnt += r->count; - continue; - } if (r->offset + r->count > page_cnt) { ret = -EINVAL; -- 2.33.0 ^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH for-rc 2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP 2024-12-20 5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang 2024-12-20 5:52 ` [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer Junxian Huang @ 2024-12-20 5:52 ` Junxian Huang 2024-12-20 5:52 ` [PATCH for-rc 3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path Junxian Huang ` (2 subsequent siblings) 4 siblings, 0 replies; 6+ messages in thread From: Junxian Huang @ 2024-12-20 5:52 UTC (permalink / raw) To: jgg, leon Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang From: Chengchang Tang <tangchengchang@huawei.com> If it fails to modify QP to RTR, dip_ctx will not be attached. And during detroying QP, the invalid dip_ctx pointer will be accessed. Fixes: faa62440a577 ("RDMA/hns: Fix different dgids mapping to the same dip_idx") Signed-off-by: Chengchang Tang <tangchengchang@huawei.com> Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com> --- drivers/infiniband/hw/hns/hns_roce_hw_v2.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c index 697b17cca02e..6dddadb90e02 100644 --- a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c +++ b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c @@ -5619,6 +5619,9 @@ static void put_dip_ctx_idx(struct hns_roce_dev *hr_dev, { struct hns_roce_dip *hr_dip = hr_qp->dip; + if (!hr_dip) + return; + xa_lock(&hr_dev->qp_table.dip_xa); hr_dip->qp_cnt--; -- 2.33.0 ^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH for-rc 3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path 2024-12-20 5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang 2024-12-20 5:52 ` [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer Junxian Huang 2024-12-20 5:52 ` [PATCH for-rc 2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP Junxian Huang @ 2024-12-20 5:52 ` Junxian Huang 2024-12-20 5:52 ` [PATCH for-rc 4/4] RDMA/hns: Fix missing flush CQE for DWQE Junxian Huang 2024-12-23 14:58 ` [PATCH for-rc 0/4] RDMA/hns: Bugfixes Leon Romanovsky 4 siblings, 0 replies; 6+ messages in thread From: Junxian Huang @ 2024-12-20 5:52 UTC (permalink / raw) To: jgg, leon Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang From: Chengchang Tang <tangchengchang@huawei.com> WARN_ON() is called in the IO path. And it could lead to a warning storm. Use WARN_ON_ONCE() instead of WARN_ON(). Fixes: 12542f1de179 ("RDMA/hns: Refactor process about opcode in post_send()") Signed-off-by: Chengchang Tang <tangchengchang@huawei.com> Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com> --- drivers/infiniband/hw/hns/hns_roce_hw_v2.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c index 6dddadb90e02..d0469d27c63c 100644 --- a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c +++ b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c @@ -468,7 +468,7 @@ static inline int set_ud_wqe(struct hns_roce_qp *qp, valid_num_sge = calc_wr_sge_num(wr, &msg_len); ret = set_ud_opcode(ud_sq_wqe, wr); - if (WARN_ON(ret)) + if (WARN_ON_ONCE(ret)) return ret; ud_sq_wqe->msg_len = cpu_to_le32(msg_len); @@ -572,7 +572,7 @@ static inline int set_rc_wqe(struct hns_roce_qp *qp, rc_sq_wqe->msg_len = cpu_to_le32(msg_len); ret = set_rc_opcode(hr_dev, rc_sq_wqe, wr); - if (WARN_ON(ret)) + if (WARN_ON_ONCE(ret)) return ret; hr_reg_write(rc_sq_wqe, RC_SEND_WQE_SO, -- 2.33.0 ^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH for-rc 4/4] RDMA/hns: Fix missing flush CQE for DWQE 2024-12-20 5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang ` (2 preceding siblings ...) 2024-12-20 5:52 ` [PATCH for-rc 3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path Junxian Huang @ 2024-12-20 5:52 ` Junxian Huang 2024-12-23 14:58 ` [PATCH for-rc 0/4] RDMA/hns: Bugfixes Leon Romanovsky 4 siblings, 0 replies; 6+ messages in thread From: Junxian Huang @ 2024-12-20 5:52 UTC (permalink / raw) To: jgg, leon Cc: linux-rdma, linuxarm, linux-kernel, huangjunxian6, tangchengchang From: Chengchang Tang <tangchengchang@huawei.com> Flush CQE handler has not been called if QP state gets into errored mode in DWQE path. So, the new added outstanding WQEs will never be flushed. It leads to a hung task timeout when using NFS over RDMA: __switch_to+0x7c/0xd0 __schedule+0x350/0x750 schedule+0x50/0xf0 schedule_timeout+0x2c8/0x340 wait_for_common+0xf4/0x2b0 wait_for_completion+0x20/0x40 __ib_drain_sq+0x140/0x1d0 [ib_core] ib_drain_sq+0x98/0xb0 [ib_core] rpcrdma_xprt_disconnect+0x68/0x270 [rpcrdma] xprt_rdma_close+0x20/0x60 [rpcrdma] xprt_autoclose+0x64/0x1cc [sunrpc] process_one_work+0x1d8/0x4e0 worker_thread+0x154/0x420 kthread+0x108/0x150 ret_from_fork+0x10/0x18 Fixes: 01584a5edcc4 ("RDMA/hns: Add support of direct wqe") Signed-off-by: Chengchang Tang <tangchengchang@huawei.com> Signed-off-by: Junxian Huang <huangjunxian6@hisilicon.com> --- drivers/infiniband/hw/hns/hns_roce_hw_v2.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c index d0469d27c63c..0144e7210d05 100644 --- a/drivers/infiniband/hw/hns/hns_roce_hw_v2.c +++ b/drivers/infiniband/hw/hns/hns_roce_hw_v2.c @@ -670,6 +670,10 @@ static void write_dwqe(struct hns_roce_dev *hr_dev, struct hns_roce_qp *qp, #define HNS_ROCE_SL_SHIFT 2 struct hns_roce_v2_rc_send_wqe *rc_sq_wqe = wqe; + if (unlikely(qp->state == IB_QPS_ERR)) { + flush_cqe(hr_dev, qp); + return; + } /* All kinds of DirectWQE have the same header field layout */ hr_reg_enable(rc_sq_wqe, RC_SEND_WQE_FLAG); hr_reg_write(rc_sq_wqe, RC_SEND_WQE_DB_SL_L, qp->sl); -- 2.33.0 ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH for-rc 0/4] RDMA/hns: Bugfixes 2024-12-20 5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang ` (3 preceding siblings ...) 2024-12-20 5:52 ` [PATCH for-rc 4/4] RDMA/hns: Fix missing flush CQE for DWQE Junxian Huang @ 2024-12-23 14:58 ` Leon Romanovsky 4 siblings, 0 replies; 6+ messages in thread From: Leon Romanovsky @ 2024-12-23 14:58 UTC (permalink / raw) To: jgg, Junxian Huang; +Cc: linux-rdma, linuxarm, linux-kernel, tangchengchang On Fri, 20 Dec 2024 13:52:45 +0800, Junxian Huang wrote: > Here are some recent bugfixes for hns. > > Chengchang Tang (3): > RDMA/hns: Fix accessing invalid dip_ctx during destroying QP > RDMA/hns: Fix warning storm caused by invalid input in IO path > RDMA/hns: Fix missing flush CQE for DWQE > > [...] Applied, thanks! [1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer https://git.kernel.org/rdma/rdma/c/8673a6c2d9e483 [2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP https://git.kernel.org/rdma/rdma/c/0572eccf239ce4 [3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path https://git.kernel.org/rdma/rdma/c/fa5c4ba8cdbfd2 [4/4] RDMA/hns: Fix missing flush CQE for DWQE https://git.kernel.org/rdma/rdma/c/e3debdd48423d3 Best regards, -- Leon Romanovsky <leon@kernel.org> ^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2024-12-23 14:58 UTC | newest] Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- 2024-12-20 5:52 [PATCH for-rc 0/4] RDMA/hns: Bugfixes Junxian Huang 2024-12-20 5:52 ` [PATCH for-rc 1/4] RDMA/hns: Fix mapping error of zero-hop WQE buffer Junxian Huang 2024-12-20 5:52 ` [PATCH for-rc 2/4] RDMA/hns: Fix accessing invalid dip_ctx during destroying QP Junxian Huang 2024-12-20 5:52 ` [PATCH for-rc 3/4] RDMA/hns: Fix warning storm caused by invalid input in IO path Junxian Huang 2024-12-20 5:52 ` [PATCH for-rc 4/4] RDMA/hns: Fix missing flush CQE for DWQE Junxian Huang 2024-12-23 14:58 ` [PATCH for-rc 0/4] RDMA/hns: Bugfixes Leon Romanovsky
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®