From: Sasha Levin <Alexander.Levin@microsoft.com>
To: "stable@vger.kernel.org" <stable@vger.kernel.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>
Cc: Jakub Kicinski <jakub.kicinski@netronome.com>,
"David S . Miller" <davem@davemloft.net>,
Sasha Levin <Alexander.Levin@microsoft.com>
Subject: [PATCH AUTOSEL 4.9 33/43] nfp: avoid buffer leak when FW communication fails
Date: Fri, 7 Sep 2018 00:38:42 +0000 [thread overview]
Message-ID: <20180907003816.57852-33-alexander.levin@microsoft.com> (raw)
In-Reply-To: <20180907003816.57852-1-alexander.levin@microsoft.com>
From: Jakub Kicinski <jakub.kicinski@netronome.com>
[ Upstream commit 07300f774fec9519663a597987a4083225588be4 ]
After device is stopped we reset the rings by moving all free buffers
to positions [0, cnt - 2], and clear the position cnt - 1 in the ring.
We then proceed to clear the read/write pointers. This means that if
we try to reset the ring again the code will assume that the next to
fill buffer is at position 0 and swap it with cnt - 1. Since we
previously cleared position cnt - 1 it will lead to leaking the first
buffer and leaving ring in a bad state.
This scenario can only happen if FW communication fails, in which case
the ring will never be used again, so the fact it's in a bad state will
not be noticed. Buffer leak is the only problem. Don't try to move
buffers in the ring if the read/write pointers indicate the ring was
never used or have already been reset.
nfp_net_clear_config_and_disable() is now fully idempotent.
Found by code inspection, FW communication failures are very rare,
and reconfiguring a live device is not common either, so it's unlikely
anyone has ever noticed the leak.
Signed-off-by: Jakub Kicinski <jakub.kicinski@netronome.com>
Reviewed-by: Dirk van der Merwe <dirk.vandermerwe@netronome.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <alexander.levin@microsoft.com>
---
drivers/net/ethernet/netronome/nfp/nfp_net_common.c | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/netronome/nfp/nfp_net_common.c b/drivers/net/ethernet/netronome/nfp/nfp_net_common.c
index eee6e59e6cf3..2e8703da536d 100644
--- a/drivers/net/ethernet/netronome/nfp/nfp_net_common.c
+++ b/drivers/net/ethernet/netronome/nfp/nfp_net_common.c
@@ -990,7 +990,7 @@ static void nfp_net_tx_complete(struct nfp_net_tx_ring *tx_ring)
* @nn: NFP Net device
* @tx_ring: TX ring structure
*
- * Assumes that the device is stopped
+ * Assumes that the device is stopped, must be idempotent.
*/
static void
nfp_net_tx_ring_reset(struct nfp_net *nn, struct nfp_net_tx_ring *tx_ring)
@@ -1144,13 +1144,18 @@ static void nfp_net_rx_give_one(struct nfp_net_rx_ring *rx_ring,
* nfp_net_rx_ring_reset() - Reflect in SW state of freelist after disable
* @rx_ring: RX ring structure
*
- * Warning: Do *not* call if ring buffers were never put on the FW freelist
- * (i.e. device was not enabled)!
+ * Assumes that the device is stopped, must be idempotent.
*/
static void nfp_net_rx_ring_reset(struct nfp_net_rx_ring *rx_ring)
{
unsigned int wr_idx, last_idx;
+ /* wr_p == rd_p means ring was never fed FL bufs. RX rings are always
+ * kept at cnt - 1 FL bufs.
+ */
+ if (rx_ring->wr_p == 0 && rx_ring->rd_p == 0)
+ return;
+
/* Move the empty entry to the end of the list */
wr_idx = rx_ring->wr_p % rx_ring->cnt;
last_idx = rx_ring->cnt - 1;
@@ -1919,6 +1924,8 @@ static void nfp_net_vec_clear_ring_data(struct nfp_net *nn, unsigned int idx)
/**
* nfp_net_clear_config_and_disable() - Clear control BAR and disable NFP
* @nn: NFP Net device to reconfigure
+ *
+ * Warning: must be fully idempotent.
*/
static void nfp_net_clear_config_and_disable(struct nfp_net *nn)
{
--
2.17.1
next prev parent reply other threads:[~2018-09-07 0:41 UTC|newest]
Thread overview: 44+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-09-07 0:38 [PATCH AUTOSEL 4.9 01/43] usb: usbtest: use irqsave() in USB's complete callback Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 02/43] iommu/arm-smmu-v3: sync the OVACKFLG to PRIQ consumer register Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 04/43] ALSA: usb-audio: Fix multiple definitions in AU0828_DEVICE() macro Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 03/43] ALSA: msnd: Fix the default sample sizes Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 05/43] xfrm: fix 'passing zero to ERR_PTR()' warning Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 07/43] clk: imx6ul: fix missing of_node_put() Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 06/43] gfs2: Special-case rindex for gfs2_grow Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 09/43] kbuild: add .DELETE_ON_ERROR special target Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 08/43] clk: clk-fixed-factor: Clear OF_POPULATED flag in case of failure Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 10/43] media: tw686x: Fix oops on buffer alloc failure Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 11/43] dmaengine: pl330: fix irq race with terminate_all Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 12/43] MIPS: ath79: fix system restart Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 13/43] media: videobuf2-core: check for q->error in vb2_core_qbuf() Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 14/43] IB/rxe: Drop QP0 silently Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 15/43] mtd/maps: fix solutionengine.c printk format warnings Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 16/43] perf test: Fix subtest number when showing results Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 18/43] iio: ad9523: Fix displayed phase Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 17/43] gfs2: Don't reject a supposedly full bitmap if we have blocks reserved Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 19/43] fbdev: omapfb: off by one in omapfb_register_client() Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 20/43] video: goldfishfb: fix memory leak on driver remove Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 21/43] fbdev/via: fix defined but not used warning Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 22/43] perf powerpc: Fix callchain ip filtering when return address is in a register Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 24/43] fbdev: Distinguish between interlaced and progressive modes Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 23/43] video: fbdev: pxafb: clear allocated memory for video modes Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 25/43] ARM: exynos: Clear global variable on init error path Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 26/43] perf powerpc: Fix callchain ip filtering Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 27/43] powerpc/powernv: opal_put_chars partial write fix Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 28/43] MIPS: jz4740: Bump zload address Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 29/43] mac80211: restrict delayed tailroom needed decrement Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 30/43] Smack: Fix handling of IPv4 traffic received by PF_INET6 sockets Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 31/43] wan/fsl_ucc_hdlc: use IS_ERR_VALUE() to check return value of qe_muram_alloc Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 32/43] efi/arm: preserve early mapping of UEFI memory map longer for BGRT Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 34/43] xen-netfront: fix queue name setting Sasha Levin
2018-09-07 0:38 ` Sasha Levin [this message]
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 35/43] arm64: dts: qcom: db410c: Fix Bluetooth LED trigger Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 36/43] ARM: dts: qcom: msm8974-hammerhead: increase load on l20 for sdhci Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 37/43] s390/qeth: fix race in used-buffer accounting Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 38/43] s390/qeth: reset layer2 attribute on layer switch Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 39/43] platform/x86: toshiba_acpi: Fix defined but not used build warnings Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 40/43] KVM: arm/arm64: Fix vgic init race Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 41/43] drivers/base: stop new probing during shutdown Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 42/43] dmaengine: mv_xor_v2: kill the tasklets upon exit Sasha Levin
2018-09-07 0:38 ` [PATCH AUTOSEL 4.9 43/43] crypto: sharah - Unregister correct algorithms for SAHARA 3 Sasha Levin
2018-09-07 5:43 ` [PATCH AUTOSEL 4.9 01/43] usb: usbtest: use irqsave() in USB's complete callback Greg Kroah-Hartman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20180907003816.57852-33-alexander.levin@microsoft.com \
--to=alexander.levin@microsoft.com \
--cc=davem@davemloft.net \
--cc=jakub.kicinski@netronome.com \
--cc=linux-kernel@vger.kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome