From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755185AbbFLMls (ORCPT ); Fri, 12 Jun 2015 08:41:48 -0400 Received: from sci-ig2.spreadtrum.com ([222.66.158.135]:61220 "EHLO SHSQR01.spreadtrum.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1753458AbbFLMlp (ORCPT ); Fri, 12 Jun 2015 08:41:45 -0400 From: =?utf-8?B?SnVzdGluIFdhbmcgKOeOi+S4gSk=?= To: "'ulf.hansson@linaro.org'" , "'kuninori.morimoto.gx@renesas.com'" , "'jh80.chung@samsung.com'" , "'akpm@linux-foundation.org'" , "'JBottomley@Odin.com'" , "'ben@decadent.org.uk'" , "'chuanxiao.dong@intel.com'" CC: "'linux-mmc@vger.kernel.org'" , "'linux-kernel@vger.kernel.org'" Subject: [PATCH v2] mmc: card: Fixup request missing in mmc_blk_issue_rw_rq Thread-Topic: [PATCH v2] mmc: card: Fixup request missing in mmc_blk_issue_rw_rq Thread-Index: AQHQpQy1Y/9PMwvqfkyt14jMUR02rA== Date: Fri, 12 Jun 2015 12:38:39 +0000 Message-ID: References: In-Reply-To: Accept-Language: zh-CN, en-US Content-Language: zh-CN X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [10.0.1.200] Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 X-MAIL: SHSQR01.spreadtrum.com t5CCcKBP004861 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Transfer-Encoding: 8bit X-MIME-Autoconverted: from base64 to 8bit by nfs id t5CCfrCA017526 >>From 0e01e7546745f39843d54810f74c198e01cb8226 Mon Sep 17 00:00:00 2001 From: justin.wang Date: Mon, 18 May 2015 20:14:15 +0800 Subject: [PATCH v2] mmc: card: Fixup request missing in mmc_blk_issue_rw_rq The current handler of MMC_BLK_CMD_ERR in mmc_blk_issue_rw_rq function may cause new coming request permanent missing when the ongoing request (previoulsy started) complete end. The problem scenario is as follows: (1) Request A is ongoing; (2) Request B arrived, and finally mmc_blk_issue_rw_rq() is called; (3) Request A encounters the MMC_BLK_CMD_ERR error; (4) In the error handling of MMC_BLK_CMD_ERR, suppose mmc_blk_cmd_err() end request A completed and return zero. Continue the error handling, suppose mmc_blk_reset() reset device success; (5) Continue the execution, while loop completed because variable ret is zero now; (6) Finally, mmc_blk_issue_rw_rq() return without processing request B. The process related to the missing request may wait that IO request complete forever, possibly crashing the application or hanging the system. Fix this issue by starting new request when reset success. Signed-off-by: Ding Wang --- drivers/mmc/card/block.c | 8 +++++--- 1 files changed, 5 insertions(+), 3 deletions(-) diff --git a/drivers/mmc/card/block.c b/drivers/mmc/card/block.c index 60f7141..f05cd1f 100644 --- a/drivers/mmc/card/block.c +++ b/drivers/mmc/card/block.c @@ -1910,9 +1910,11 @@ static int mmc_blk_issue_rw_rq(struct mmc_queue *mq, struct request *rqc) break; case MMC_BLK_CMD_ERR: ret = mmc_blk_cmd_err(md, card, brq, req, ret); - if (!mmc_blk_reset(md, card->host, type)) - break; - goto cmd_abort; + if (mmc_blk_reset(md, card->host, type)) + goto cmd_abort; + if (!ret) + goto start_new_req; + break; case MMC_BLK_RETRY: if (retry++ < 5) break; -- 1.7.4.1 ÿôèº{.nÇ+‰·Ÿ®‰­†+%ŠËÿ±éݶ¥Šwÿº{.nÇ+‰·¥Š{±þG«éÿŠ{ayºʇڙë,j­¢f£¢·hšïêÿ‘êçz_è®(­éšŽŠÝ¢j"ú¶m§ÿÿ¾«þG«éÿ¢¸?™¨è­Ú&£ø§~á¶iO•æ¬z·švØ^¶m§ÿÿà ÿ¶ìÿ¢¸?–I¥