From: Ding Hui <dinghui1111@163.com>
To: netdev-bot+sinfo@kernel.org
Cc: alexandre.torgue@foss.st.com, andrew+netdev@lunn.ch,
davem@davemloft.net, dinghui1111@163.com, dinghui@lixiang.com,
edumazet@google.com, kuba@kernel.org,
linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org,
linux-stm32@st-md-mailman.stormreply.com, liuxuanjun@lixiang.com,
maxime.chevallier@bootlin.com, mcoquelin.stm32@gmail.com,
netdev-bot+sashiko@kernel.org, netdev@vger.kernel.org,
pabeni@redhat.com, xiasanbo@lixiang.com, yangchen11@lixiang.com
Subject: Re:Re: [PATCH net v4] net: stmmac: fix error path cleanup in DMA descriptor ring allocation
Date: Thu, 1 Oct 2026 22:06:00 +0800 [thread overview]
Message-ID: <20261001140600.1013202-1-dinghui1111@163.com> (raw)
In-Reply-To: <179082713968.31693.13138874201716710221@kernel.org>
At 2026-10-01 11:58:59, netdev-bot+sinfo@kernel.org wrote:
>Hi!
>
>This is an automated message. This series looks like a fix, but its
>commit messages seem to be missing some information:
>
> - How the issue was discovered, e.g. hit in production, hit during
> development, syzbot report, manual code inspection, LLM or static
> analysis tool scan.
This issue was discovered during a stress testing scenario in the development process.
>
> - Whether the issue was actually triggered, or is only theoretical
> (e.g. found by code inspection). If it was triggered please include
> the symptoms, like the stack trace or error messages.
>
The specific scenario triggering this issue involves performing `ifconfig down/up` operations
on a network device during an OOM (Out of Memory) condition. The call stack at the time of the
failure may like this:
[540776.647689] Call trace:
[540776.647691] dump_backtrace+0x98/0xf8
[540776.647701] show_stack+0x20/0x38
[540776.647704] dump_stack_lvl+0xbc/0xd0
[540776.647719] dump_stack+0x18/0x28
[540776.647723] warn_alloc+0x138/0x1d0
[540776.647731] __alloc_pages_noprof+0x4e8/0xfd0
[540776.647735] ___kmalloc_large_node+0xb8/0x1a8
[540776.647740] __kmalloc_large_node_noprof+0x34/0x118
[540776.647743] __kmalloc_noprof+0x2d4/0x378
[540776.647747] __alloc_dma_tx_desc_resources+0x4c/0x118
[540776.647753] alloc_dma_desc_resources+0xd8/0x150
[540776.647756] stmmac_setup_dma_desc+0x118/0x270
[540776.647759] stmmac_open+0x30/0xe8
[540776.647762] __dev_open+0x108/0x1f8
[540776.647767] __dev_change_flags+0x1d4/0x268
[540776.647770] dev_change_flags+0x2c/0x80
[540776.647773] devinet_ioctl+0x2dc/0x618
[540776.647778] inet_ioctl+0x1d4/0x1f0
[540776.647781] sock_do_ioctl+0x68/0x130
[540776.647786] sock_ioctl+0x288/0x398
[540776.647788] __arm64_sys_ioctl+0xb0/0x100
[540776.647795] invoke_syscall+0x84/0x108
[540776.647801] el0_svc_common.constprop.0+0xc8/0xf0
[540776.647805] do_el0_svc+0x24/0x38
[540776.647808] el0_svc+0x38/0x120
[540776.647813] el0t_64_sync_handler+0x120/0x130
[540776.647816] el0t_64_sync+0x190/0x198
[540776.648028] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000
[540776.648031] Mem abort info:
[540776.648033] ESR = 0x0000000096000006
[540776.648035] EC = 0x25: DABT (current EL), IL = 32 bits
[540776.648038] SET = 0, FnV = 0
[540776.648039] EA = 0, S1PTW = 0
[540776.648041] FSC = 0x06: level 2 translation fault
[540776.648043] Data abort info:
[540776.648045] ISV = 0, ISS = 0x00000006, ISS2 = 0x00000000
[540776.648047] CM = 0, WnR = 0, TnD = 0, TagAccess = 0
[540776.648049] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0
[540776.648051] user pgtable: 4k pages, 39-bit VAs, pgdp=00000013c6eed000
[540776.648053] [0000000000000000] pgd=08000013b0800003, p4d=08000013b0800003, pud=08000013b0800003, pmd=0000000000000000
[540776.648063] Internal error: Oops: 0000000096000006 [#1] PREEMPT_RT SMP
[540776.648145] pstate: 20401005 (nzCv daif +PAN -UAO -TCO -DIT +SSBS BTYPE=--)
[540776.648147] pc : dma_free_tx_skbufs+0x108/0x1b8
[540776.648151] lr : __free_dma_tx_desc_resources+0x2c/0xb8
[540776.648154] sp : ffffffc0bc5f3610
[540776.648156] x29: ffffffc0bc5f3610 x28: ffffff83e4a2c600 x27: ffffff87de595a00
[540776.648162] x26: ffffff87de8a8000 x25: 0000000000001003 x24: ffffff83dcc26000
[540776.648168] x23: 0000000000000000 x22: ffffff87de8a8a00 x21: 0000000000000000
[540776.648174] x20: 0000000000000000 x19: ffffff83dcc26100 x18: ffffffc0bc5f2f20
[540776.648179] x17: 0000000000000000 x16: 0000000000000000 x15: ffffffe62e994454
[540776.648185] x14: ffffffe62e994440 x13: 0a64656e6f73696f x12: 7077682073656761
[540776.648190] x11: 0000000000000000 x10: 0000000000000000 x9 : ffffffe62d20dc4c
[540776.648196] x8 : ffffffc0bc5f34c8 x7 : 0000000000000000 x6 : 0000000000000001
[540776.648201] x5 : ffffffe62e41c000 x4 : ffffffe62e41c600 x3 : 0000000000000000
[540776.648207] x2 : 0000000000000000 x1 : ffffff83dcc26000 x0 : 0000000000001000
[540776.648213] Call trace:
[540776.648215] dma_free_tx_skbufs+0x108/0x1b8
[540776.648217] __free_dma_tx_desc_resources+0x2c/0xb8
[540776.648219] alloc_dma_desc_resources+0x104/0x150
[540776.648222] stmmac_setup_dma_desc+0x118/0x270
[540776.648225] stmmac_open+0x30/0xe8
[540776.648228] __dev_open+0x108/0x1f8
[540776.648231] __dev_change_flags+0x1d4/0x268
[540776.648234] dev_change_flags+0x2c/0x80
[540776.648236] devinet_ioctl+0x2dc/0x618
[540776.648240] inet_ioctl+0x1d4/0x1f0
[540776.648243] sock_do_ioctl+0x68/0x130
[540776.648246] sock_ioctl+0x288/0x398
[540776.648248] __arm64_sys_ioctl+0xb0/0x100
[540776.648252] invoke_syscall+0x84/0x108
[540776.648256] el0_svc_common.constprop.0+0xc8/0xf0
[540776.648260] do_el0_svc+0x24/0x38
[540776.648263] el0_svc+0x38/0x120
[540776.648267] el0t_64_sync_handler+0x120/0x130
[540776.648270] el0t_64_sync+0x190/0x198
[540776.648274] Code: 54000389 f9449262 93797eb4 937d7eb7 (f8746843)
[540776.648277] ---[ end trace 0000000000000000 ]---
[540776.681767] Kernel panic - not syncing: Oops: Fatal exception
Alternatively, a simpler method to reproduce the issue is by injecting a fault
through stubbing `alloc_dma_tx_desc_resources`.
> - What hardware the change was tested on. For driver fixes please
> mention the device (and if relevant firmware version) used for
> testing, or say that the change was not tested on real hardware.
>
This modification was tested and verified on an in-house developed SoC
platform (featuring Synopsys XGMAC).
>Please do not repost the series just to address the above. Instead,
>reply to this email with the missing information, so that reviewers
>can take it into account. If the series needs another revision for
>other reasons, please include the information in the commit messages
>then.
>
>The evaluation is done by an LLM so it may be wrong, if you think
>that is the case please reply and explain.
prev parent reply other threads:[~2026-10-01 14:08 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 3:50 Ding Hui
2026-10-01 3:58 ` netdev-bot+sinfo
2026-10-01 14:06 ` Ding Hui [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001140600.1013202-1-dinghui1111@163.com \
--to=dinghui1111@163.com \
--cc=alexandre.torgue@foss.st.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=dinghui@lixiang.com \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-stm32@st-md-mailman.stormreply.com \
--cc=liuxuanjun@lixiang.com \
--cc=maxime.chevallier@bootlin.com \
--cc=mcoquelin.stm32@gmail.com \
--cc=netdev-bot+sashiko@kernel.org \
--cc=netdev-bot+sinfo@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=xiasanbo@lixiang.com \
--cc=yangchen11@lixiang.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®