From: Robin Murphy <robin.murphy@arm.com>
To: Harsh Jain <Harsh@chelsio.com>, Casey Leedom <leedom@chelsio.com>,
"Raj, Ashok" <ashok.raj@intel.com>
Cc: Herbert Xu <herbert@gondor.apana.org.au>,
David Woodhouse <David.Woodhouse@intel.com>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"iommu@lists.linux-foundation.org"
<iommu@lists.linux-foundation.org>,
"linux-crypto@vger.kernel.org" <linux-crypto@vger.kernel.org>,
Dan Williams <dan.j.williams@intel.com>,
"dwmw2@infradead.org" <dwmw2@infradead.org>
Subject: Re: DMA error when sg->offset value is greater than PAGE_SIZE in Intel IOMMU
Date: Tue, 26 Sep 2017 15:22:47 +0100 [thread overview]
Message-ID: <437a9bd8-d4d6-22ca-1a64-1a3e73f1101a@arm.com> (raw)
In-Reply-To: <6d2af675-7b97-6eaf-4daa-d7bf80a05923@chelsio.com>
On 26/09/17 13:21, Harsh Jain wrote:
> Find attached new set of log. After repeated tries it panics.
Thanks, that makes things a bit clearer - looks like fixing the physical
address/pteval calculation to not be off by a page in one direction wasn't
helping much because the returned DMA address is actually also off by a
page in the other direction, and thus overflowing past the allocated IOVA
into whoever else's mapping happened to be there; complete carnage ensues.
After another look through the intel_map_sg() path, here's my second (still
completely untested) guess at a possible fix.
Robin.
----->8-----
diff --git a/drivers/iommu/intel-iommu.c b/drivers/iommu/intel-iommu.c
index 6784a05dd6b2..d7f7def81613 100644
--- a/drivers/iommu/intel-iommu.c
+++ b/drivers/iommu/intel-iommu.c
@@ -2254,10 +2254,12 @@ static int __domain_mapping(struct dmar_domain *domain, unsigned long iov_pfn,
uint64_t tmp;
if (!sg_res) {
+ size_t off = sg->offset & ~PAGE_MASK;
+
sg_res = aligned_nrpages(sg->offset, sg->length);
- sg->dma_address = ((dma_addr_t)iov_pfn << VTD_PAGE_SHIFT) + sg->offset;
+ sg->dma_address = ((dma_addr_t)iov_pfn << VTD_PAGE_SHIFT) + off;
sg->dma_length = sg->length;
- pteval = page_to_phys(sg_page(sg)) | prot;
+ pteval = (page_to_phys(sg_page(sg)) + sg->offset - off) | prot;
phys_pfn = pteval >> VTD_PAGE_SHIFT;
}
>
>
> On 26-09-2017 09:16, Harsh Jain wrote:
>> On 26-09-2017 00:16, Casey Leedom wrote:
>>> | From: Raj, Ashok <ashok.raj@intel.com>
>>> | Sent: Monday, September 25, 2017 8:54 AM
>>> |
>>> | Not sure how the page->offset would end up being greater than page-size?
>> Refer below
>>> |
>>> | If you have additional traces, please send them by.
>>> |
>>> | Is this a new driver? wondering how we didn't run into this?
>>>
>>> According to Herbert Xu and one of our own engineers, it's actually legal
>>> for Scatter/Gather Lists to have this. This isn't my area of expertise
>>> though so I'm just passing that on.
>>>
>>> I've asked our team to produce a detailed trace of the exact
>>> Scatter/Gather Lists they're seeing and what ends up coming out of the DMA
>>> Mappings, etc. They're in India, so I expect that they'll have this for you
>>> by tomorrow morning.
>> Below mentioned log was already there in 1st mail. Copied here for easy reference. Let me know if you need
>> additional traces.
>>
>> 1) IN esp_output() "__skb_to_sgvec()" convert skb frags to scatter gather list.
>> At that moment sg->offset was 4094.
>> 2) From esp_output control reaches to "crypto_authenc_encrypt()". Here in
>> "scatterwalk_ffwd()" sg->offset become 4110.
>> 3) Same sg list received by chelsio crypto driver(chcr). When chcr try to do
>> DMA mapping it starts giving DMA errors.
>>
>> Following error observed. first two prints are added for debugging in chcr.
>> Kernel version used to reproduce is 4.9.28 on x86_64 with Page size 4K.
>>
>> Sep 15 12:40:52 heptagon kernel: process_cipher req src ffff8803cb41f0a8
>> Sep 15 12:40:52 heptagon kernel: ========= issue hit offset:4110 =======
>> dma_addr f24b000e ==> DMA mapped address returned by dma_map_sg()
>>
>> Sep 15 12:40:52 heptagon kernel: DMAR: DRHD: handling fault status reg 2
>> Sep 15 12:40:52 heptagon kernel: DMAR: [DMA Write] Request device [02:00.4]
>> fault addr f24b0000 [fault reason 05] PTE Write access is not set
>>
>>> Casey
>
next prev parent reply other threads:[~2017-09-26 14:22 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-09-16 6:11 Harsh Jain
2017-09-20 8:01 ` Herbert Xu
2017-09-20 10:12 ` Robin Murphy
2017-09-20 11:20 ` Harsh Jain
2017-09-25 17:46 ` Casey Leedom
2017-09-25 15:54 ` Raj, Ashok
2017-09-25 18:46 ` Casey Leedom
2017-09-26 3:46 ` Harsh Jain
2017-09-26 12:21 ` Harsh Jain
2017-09-26 14:22 ` Robin Murphy [this message]
2017-09-26 14:34 ` Raj, Ashok
2017-09-26 14:40 ` Raj, Ashok
2017-09-26 20:50 ` Casey Leedom
2017-09-26 18:15 ` Robin Murphy
[not found] ` <MWHPR12MB1600694D099E1CFAD6849A68C87B0@MWHPR12MB1600.namprd12.prod.outlook.com>
2017-09-26 16:10 ` Dan Williams
2017-09-27 16:31 ` Casey Leedom
2017-09-27 17:13 ` Dan Williams
2017-10-01 8:59 ` Christoph Hellwig
2017-09-27 17:18 ` Robin Murphy
2017-09-27 14:48 ` Raj, Ashok
2017-09-27 21:29 ` Casey Leedom
2017-09-27 19:07 ` Raj, Ashok
2017-09-27 22:13 ` Casey Leedom
2017-09-28 5:01 ` Harsh Jain
2017-09-28 10:33 ` Herbert Xu
2017-09-28 13:38 ` Harsh Jain
2017-09-28 13:05 ` Raj, Ashok
2017-09-29 5:37 ` Harsh Jain
2017-09-27 17:30 ` Casey Leedom
2017-09-26 17:30 ` Casey Leedom
2017-09-25 19:31 ` Dan Williams
2017-09-25 20:05 ` Casey Leedom
2017-09-25 20:11 ` Dan Williams
2017-09-25 19:03 ` Raj, Ashok
2017-09-25 23:41 ` Casey Leedom
2017-09-26 13:04 ` Harsh Jain
2017-09-20 11:30 ` Harsh Jain
2017-09-25 18:45 ` David Woodhouse
2017-09-25 20:19 ` Casey Leedom
2017-09-26 11:17 ` Harsh Jain
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=437a9bd8-d4d6-22ca-1a64-1a3e73f1101a@arm.com \
--to=robin.murphy@arm.com \
--cc=David.Woodhouse@intel.com \
--cc=Harsh@chelsio.com \
--cc=ashok.raj@intel.com \
--cc=dan.j.williams@intel.com \
--cc=dwmw2@infradead.org \
--cc=herbert@gondor.apana.org.au \
--cc=iommu@lists.linux-foundation.org \
--cc=leedom@chelsio.com \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®