From: Stanley Jhu <stanleyjhu@google.com>
To: "Martin K . Petersen" <martin.petersen@oracle.com>,
Bean Huo <beanhuo@micron.com>,
Bart Van Assche <bvanassche@acm.org>
Cc: Alim Akhtar <alim.akhtar@samsung.com>,
Avri Altman <avri.altman@wdc.com>,
"James E . J . Bottomley"
<James.Bottomley@HansenPartnership.com>,
Manivannan Sadhasivam <mani@kernel.org>,
Peter Wang <peter.wang@mediatek.com>,
linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org,
Stanley Jhu <stanleyjhu@google.com>
Subject: [PATCH v3 0/2] scsi: ufs: core: Fix unsafe MMIO reads and redundant CQ sweeps in MCQ reset
Date: Mon, 28 Sep 2026 11:58:14 +0800 [thread overview]
Message-ID: <20260928035816.1294326-1-stanleyjhu@google.com> (raw)
During Multi-Circular Queue (MCQ) error recovery and host reset,
ufshcd_mcq_compl_pending_transfer() sweeps or polls completion queues to
reap pending transfers. Two bugs exist in this path:
1. Unsafe MMIO read and spurious errors while HCE = 0 (Patch 1/2):
ufshcd_host_reset_and_restore() stops the controller (HCE = 0) before
calling ufshcd_mcq_compl_all_cqes_lock(). Calling
ufshcd_mcq_update_cq_tail_slot() at the end of the sweep reads CQTPy
over MMIO while HCE = 0, directly contradicting the function's own
documented contract that reading host controller registers may not be
safe when the controller is disabled. In addition, passing expected
empty slots during a full-ring sweep into ufshcd_mcq_process_cqe()
prints spurious "Abnormal CQ entry!" errors.
2. Redundant per-request CQ sweeps and polls (Patch 2/2):
ufshcd_mcq_compl_pending_transfer() runs hardware queue completion
sweeps (force_compl == true) or CQTPy polls (force_compl == false)
inside blk_mq_tagset_busy_iter() callbacks, repeating whole-queue
operations once per busy request instead of once per hardware queue.
Patch 1/2 removes the unsafe ufshcd_mcq_update_cq_tail_slot() call and
redundant slot assignment in ufshcd_mcq_compl_all_cqes_lock(), and
extracts ufshcd_mcq_compl_cqe() so full-ring sweeps skip empty slots
silently. Patch 2/2 sweeps or polls each hardware queue once before
iterating residual requests and removes ufshcd_mcq_compl_one().
Differences from v2:
- Fix the grammar of the CQE comment in ufshcd_mcq_compl_cqe() (Bart).
- Drop the redundant cq_tail_slot assignment in
ufshcd_mcq_compl_all_cqes_lock() (Bart).
- Add Reviewed-by tags from Peter and Bart.
Differences from v1:
- Split into a two-patch series separating ring sweep safety from
per-request tagset iteration.
- Extract ufshcd_mcq_compl_cqe() to skip empty slots without double CQE
checks.
- Decouple hardware queue polling/sweeping for both force_compl paths
and remove ufshcd_mcq_compl_one().
Tested: QEMU ARM64 MCQ/SDB host reset and I/O without CQE error logs.
Link: https://lore.kernel.org/r/CAE14pdek6ynze+muDZrK+yNX-3ioe3vprxOA4W22qokg352tJQ@mail.gmail.com
Link: https://lore.kernel.org/r/20260918143809.3034592-1-stanleyjhu@google.com
Stanley Jhu (2):
scsi: ufs: core: Avoid unsafe MMIO reads in
ufshcd_mcq_compl_all_cqes_lock()
scsi: ufs: core: Decouple CQ sweep from request iterator in MCQ
drivers/ufs/core/ufs-mcq.c | 30 +++++++++++++++++-------------
drivers/ufs/core/ufshcd.c | 31 ++++++++++++-------------------
2 files changed, 29 insertions(+), 32 deletions(-)
base-commit: f09d2c7485b32adb82336d0d748935c8237a649e
--
2.56.0.rc1.315.gc6ed9934b7-goog
next reply other threads:[~2026-09-28 3:58 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 3:58 Stanley Jhu [this message]
2026-09-28 3:58 ` [PATCH v3 1/2] scsi: ufs: core: Avoid unsafe MMIO reads in ufshcd_mcq_compl_all_cqes_lock() Stanley Jhu
2026-09-28 17:45 ` Bart Van Assche
2026-09-28 3:58 ` [PATCH v3 2/2] scsi: ufs: core: Decouple CQ sweep from request iterator in MCQ Stanley Jhu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928035816.1294326-1-stanleyjhu@google.com \
--to=stanleyjhu@google.com \
--cc=James.Bottomley@HansenPartnership.com \
--cc=alim.akhtar@samsung.com \
--cc=avri.altman@wdc.com \
--cc=beanhuo@micron.com \
--cc=bvanassche@acm.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=mani@kernel.org \
--cc=martin.petersen@oracle.com \
--cc=peter.wang@mediatek.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®