From: "xuqiang (M)" <xuqiang36@huawei.com>
To: Marc Zyngier <maz@kernel.org>
Cc: <tglx@linutronix.de>, <jason@lakedaemon.net>,
<linux-kernel@vger.kernel.org>, <rui.xiang@huawei.com>
Subject: Re: [PATCH -next] irq-chip/gic-v3-its: Fixed an issue where the ITS executes the residual commands in the queue again when the ITS wakes up from sleep mode.
Date: Thu, 5 Nov 2020 19:54:50 +0800 [thread overview]
Message-ID: <8395dfbb-a90e-6903-abe9-cd6f7c48f441@huawei.com> (raw)
In-Reply-To: <87imamtiav.wl-maz@kernel.org>
The kernel sends three commands in the following sequence:
1.mapd(deviceA, ITT_addr1, valid:1)
2.mapti(deviceA):ITS write ITT_addr1 memory;
3.mapd(deviceA, ITT_addr1, valid:0) and kfree(ITT_addr1);
4.mapd(deviceA, ITT_addr2, valid:1);
5.mapti(deviceA):ITS write ITT_addr2 memory;
In this case, the processor enters the sleep mode. After the kernel
performs the suspend operation, the firmware performs the store
operation and saves GITS_CBASER and GITS_CWRITER registers.
Then, the processor is woken up, and the firmware restores GITS_CBASER
and GITS_CWRITER registers. Because GITS_CWRITER register is not 0, ITS
will read the above command sequence execution from the command queue,
causing ITT_addr1 memory to be trampled.
Thanks,
Xu
在 2020/11/4 2:19, Marc Zyngier 写道:
> On Tue, 03 Nov 2020 08:11:23 +0000,
> Xu Qiang <xuqiang36@huawei.com> wrote:
>> During wakeup, the ATF restore interface restores the values of
>> the cbaser and cwriter registers. As a result, the ITS executes
>> the residual commands in the queue, which may cause memory corruption.
>>
>> To solve this problem, clear all data in the command queue
>> in the suspend interface of the ITS driver.
>>
>> Signed-off-by: Xu Qiang <xuqiang36@huawei.com>
>> ---
>> drivers/irqchip/irq-gic-v3-its.c | 8 ++++++++
>> 1 file changed, 8 insertions(+)
>>
>> diff --git a/drivers/irqchip/irq-gic-v3-its.c b/drivers/irqchip/irq-gic-v3-its.c
>> index 0fec31931e11..b8487f78ac21 100644
>> --- a/drivers/irqchip/irq-gic-v3-its.c
>> +++ b/drivers/irqchip/irq-gic-v3-its.c
>> @@ -4741,6 +4741,14 @@ static int its_save_disable(void)
>> list_for_each_entry(its, &its_nodes, entry) {
>> void __iomem *base;
>>
>> + /*
>> + * Clear the command queue so that the ITS will not re-execute
>> + * the remaining commands in the command queue when
>> + * the cwriter and cbaser registers are restored
>> + * in the restore interface of the firmware.
>> + */
>> + memset(its->cmd_base, 0, ITS_CMD_QUEUE_SZ);
>> +
>> if (!(its->flags & ITS_FLAGS_SAVE_SUSPEND_STATE))
>> continue;
> You are wiping the ITS queue before even stopping the ITS. How well is
> that going to work? What if there is something in flight?
>
> I don't understand what you are trying to do here, nor how ATF is
> involved. So please describe the whole sequence of events, and we'll
> decide whether that's something we need to fix.
>
> Thanks,
>
> M.
>
next prev parent reply other threads:[~2020-11-05 11:55 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-11-03 8:11 Xu Qiang
2020-11-03 18:19 ` Marc Zyngier
2020-11-05 11:54 ` xuqiang (M) [this message]
2020-11-05 13:12 ` Marc Zyngier
2020-11-05 14:06 ` xuqiang (M)
2020-11-05 14:24 ` Marc Zyngier
2020-11-06 10:05 ` xuqiang (M)
2020-11-07 10:42 Xu Qiang
2020-11-07 16:54 ` Marc Zyngier
2020-11-09 3:05 ` xuqiang (M)
2020-11-09 10:43 ` Marc Zyngier
2020-11-10 9:09 ` xuqiang (M)
2020-11-17 13:37 ` xuqiang (M)
2020-11-22 12:47 ` Marc Zyngier
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8395dfbb-a90e-6903-abe9-cd6f7c48f441@huawei.com \
--to=xuqiang36@huawei.com \
--cc=jason@lakedaemon.net \
--cc=linux-kernel@vger.kernel.org \
--cc=maz@kernel.org \
--cc=rui.xiang@huawei.com \
--cc=tglx@linutronix.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®