From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
Milton Miller <miltonm@bga.com>,
Benjamin Herrenschmidt <benh@kernel.crashing.org>
Subject: [06/35] powerpc: rtas_flash needs to use rtas_data_buf
Date: Fri, 25 Mar 2011 17:03:38 -0700 [thread overview]
Message-ID: <20110326000456.446632198@clark.kroah.org> (raw)
In-Reply-To: <20110326000509.GA29736@kroah.com>
2.6.33-longterm review patch. If anyone has any objections, please let us know.
------------------
From: Milton Miller <miltonm@us.ibm.com>
commit bd2b64a12bf55bec0d1b949e3dca3f8863409646 upstream.
When trying to flash a machine via the update_flash command, Anton received the
following error:
Restarting system.
FLASH: kernel bug...flash list header addr above 4GB
The code in question has a comment that the flash list should be in
the kernel data and therefore under 4GB:
/* NOTE: the "first" block list is a global var with no data
* blocks in the kernel data segment. We do this because
* we want to ensure this block_list addr is under 4GB.
*/
Unfortunately the Kconfig option is marked tristate which means the variable
may not be in the kernel data and could be above 4GB.
Instead of relying on the data segment being below 4GB, use the static
data buffer allocated by the kernel for use by rtas. Since we don't
use the header struct directly anymore, convert it to a simple pointer.
Reported-By: Anton Blanchard <anton@samba.org>
Signed-Off-By: Milton Miller <miltonm@bga.com>
Tested-By: Anton Blanchard <anton@samba.org>
Signed-off-by: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
---
arch/powerpc/kernel/rtas_flash.c | 39 +++++++++++++++++++++------------------
1 file changed, 21 insertions(+), 18 deletions(-)
--- a/arch/powerpc/kernel/rtas_flash.c
+++ b/arch/powerpc/kernel/rtas_flash.c
@@ -93,12 +93,8 @@ struct flash_block_list {
struct flash_block_list *next;
struct flash_block blocks[FLASH_BLOCKS_PER_NODE];
};
-struct flash_block_list_header { /* just the header of flash_block_list */
- unsigned long num_blocks;
- struct flash_block_list *next;
-};
-static struct flash_block_list_header rtas_firmware_flash_list = {0, NULL};
+static struct flash_block_list *rtas_firmware_flash_list;
/* Use slab cache to guarantee 4k alignment */
static struct kmem_cache *flash_block_cache = NULL;
@@ -107,13 +103,14 @@ static struct kmem_cache *flash_block_ca
/* Local copy of the flash block list.
* We only allow one open of the flash proc file and create this
- * list as we go. This list will be put in the
- * rtas_firmware_flash_list var once it is fully read.
+ * list as we go. The rtas_firmware_flash_list varable will be
+ * set once the data is fully read.
*
* For convenience as we build the list we use virtual addrs,
* we do not fill in the version number, and the length field
* is treated as the number of entries currently in the block
- * (i.e. not a byte count). This is all fixed on release.
+ * (i.e. not a byte count). This is all fixed when calling
+ * the flash routine.
*/
/* Status int must be first member of struct */
@@ -200,16 +197,16 @@ static int rtas_flash_release(struct ino
if (uf->flist) {
/* File was opened in write mode for a new flash attempt */
/* Clear saved list */
- if (rtas_firmware_flash_list.next) {
- free_flash_list(rtas_firmware_flash_list.next);
- rtas_firmware_flash_list.next = NULL;
+ if (rtas_firmware_flash_list) {
+ free_flash_list(rtas_firmware_flash_list);
+ rtas_firmware_flash_list = NULL;
}
if (uf->status != FLASH_AUTH)
uf->status = flash_list_valid(uf->flist);
if (uf->status == FLASH_IMG_READY)
- rtas_firmware_flash_list.next = uf->flist;
+ rtas_firmware_flash_list = uf->flist;
else
free_flash_list(uf->flist);
@@ -592,7 +589,7 @@ static void rtas_flash_firmware(int rebo
unsigned long rtas_block_list;
int i, status, update_token;
- if (rtas_firmware_flash_list.next == NULL)
+ if (rtas_firmware_flash_list == NULL)
return; /* nothing to do */
if (reboot_type != SYS_RESTART) {
@@ -609,20 +606,25 @@ static void rtas_flash_firmware(int rebo
return;
}
- /* NOTE: the "first" block list is a global var with no data
- * blocks in the kernel data segment. We do this because
- * we want to ensure this block_list addr is under 4GB.
+ /*
+ * NOTE: the "first" block must be under 4GB, so we create
+ * an entry with no data blocks in the reserved buffer in
+ * the kernel data segment.
*/
- rtas_firmware_flash_list.num_blocks = 0;
- flist = (struct flash_block_list *)&rtas_firmware_flash_list;
+ spin_lock(&rtas_data_buf_lock);
+ flist = (struct flash_block_list *)&rtas_data_buf[0];
+ flist->num_blocks = 0;
+ flist->next = rtas_firmware_flash_list;
rtas_block_list = virt_to_abs(flist);
if (rtas_block_list >= 4UL*1024*1024*1024) {
printk(KERN_ALERT "FLASH: kernel bug...flash list header addr above 4GB\n");
+ spin_unlock(&rtas_data_buf_lock);
return;
}
printk(KERN_ALERT "FLASH: preparing saved firmware image for flash\n");
/* Update the block_list in place. */
+ rtas_firmware_flash_list = NULL; /* too hard to backout on error */
image_size = 0;
for (f = flist; f; f = next) {
/* Translate data addrs to absolute */
@@ -663,6 +665,7 @@ static void rtas_flash_firmware(int rebo
printk(KERN_ALERT "FLASH: unknown flash return code %d\n", status);
break;
}
+ spin_unlock(&rtas_data_buf_lock);
}
static void remove_flash_pde(struct proc_dir_entry *dp)
next prev parent reply other threads:[~2011-03-26 0:06 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-03-26 0:05 [00/35] 2.6.33.9-longterm review Greg KH
2011-03-26 0:03 ` [01/35] smp_call_function_many: handle concurrent clearing of mask Greg KH
2011-03-26 0:03 ` [02/35] [PARISC] fix per-cpu flag problem in the cpu affinity checkers Greg KH
2011-03-26 0:03 ` [03/35] i2c: Fix typo in instantiating-devices document Greg KH
2011-03-26 0:03 ` [04/35] mmc: sdio: remember new card RCA when redetecting card Greg KH
2011-03-26 0:03 ` [05/35] powerpc/kdump: Fix race in kdump shutdown Greg KH
2011-03-30 23:27 ` Paul Gortmaker
2011-04-11 22:57 ` [stable] " Greg KH
2011-03-26 0:03 ` Greg KH [this message]
2011-03-26 0:03 ` [07/35] x86, binutils, xen: Fix another wrong size directive Greg KH
2011-03-26 0:03 ` [08/35] hwmon: (sht15) Fix integer overflow in humidity calculation Greg KH
2011-03-26 0:03 ` [09/35] ALSA: hda - VIA: Fix stereo mixer recording no sound issue Greg KH
2011-03-26 0:03 ` [10/35] ALSA: hda - VIA: Add missing support for VT1718S in A-A path Greg KH
2011-03-26 0:03 ` [11/35] aio: wake all waiters when destroying ctx Greg KH
2011-03-26 0:03 ` [12/35] shmem: let shared anonymous be nonlinear again Greg KH
2011-03-26 0:03 ` [13/35] PCI hotplug: acpiphp: set current_state to D0 in register_slot Greg KH
2011-03-26 0:03 ` [14/35] xen: set max_pfn_mapped to the last pfn mapped Greg KH
2011-03-26 0:03 ` [15/35] PCI: return correct value when writing to the "reset" attribute Greg KH
2011-03-26 0:03 ` [16/35] [PATCH] Revert "intel_idle: PCI quirk to prevent Lenovo Ideapad s10-3 boot hang" Greg KH
2011-03-26 0:03 ` [17/35] Prevent rt_sigqueueinfo and rt_tgsigqueueinfo from spoofing the signal code Greg KH
2011-03-26 0:03 ` [18/35] ext3: skip orphan cleanup on rocompat fs Greg KH
2011-03-26 0:03 ` [19/35] procfs: fix /proc/<pid>/maps heap check Greg KH
2011-03-26 0:03 ` [20/35] proc: protect mm start_code/end_code in /proc/pid/stat Greg KH
2011-03-26 0:03 ` [21/35] fbcon: Bugfix soft cursor detection in Tile Blitting Greg KH
2011-03-26 0:03 ` [22/35] nfsd41: modify the members value of nfsd4_op_flags Greg KH
2011-03-26 0:03 ` [23/35] nfsd: wrong index used in inner loop Greg KH
2011-03-26 0:03 ` [24/35] [media] uvcvideo: Fix uvc_fixup_video_ctrl() format search Greg KH
2011-03-26 0:03 ` [25/35] [media] uvcvideo: Fix descriptor parsing for video output devices Greg KH
2011-03-26 0:03 ` [26/35] ehci-hcd: Bug fix: dont set a QHs Halt bit Greg KH
2011-03-26 0:03 ` [27/35] USB: uss720 fixup refcount position Greg KH
2011-03-26 0:04 ` [28/35] USB: cdc-acm: fix memory corruption / panic Greg KH
2011-03-26 0:04 ` [29/35] USB: cdc-acm: fix potential null-pointer dereference Greg KH
2011-03-26 0:04 ` [30/35] USB: cdc-acm: fix potential null-pointer dereference on disconnect Greg KH
2011-03-26 0:04 ` [31/35] Input: xen-kbdfront - advertise either absolute or relative coordinates Greg KH
2011-03-26 0:04 ` [32/35] x86: Cleanup highmap after brk is concluded Greg KH
2011-03-26 0:04 ` [33/35] SUNRPC: Never reuse the socket port after an xs_close() Greg KH
2011-03-26 0:04 ` [34/35] fs: call security_d_instantiate in d_obtain_alias V2 Greg KH
2011-03-26 0:24 ` Casey Schaufler
2011-03-26 16:11 ` Josef Bacik
2011-03-26 0:04 ` [35/35] dcdbas: force SMI to happen when expected Greg KH
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20110326000456.446632198@clark.kroah.org \
--to=gregkh@suse.de \
--cc=akpm@linux-foundation.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=benh@kernel.crashing.org \
--cc=linux-kernel@vger.kernel.org \
--cc=miltonm@bga.com \
--cc=stable-review@kernel.org \
--cc=stable@kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®