From: Ivan Mikhaylov <hidden> Date: 2017-05-15 13:08:10
Prevent a kernel panic caused by unintentionally clearing TCR
watchdog bits. At this point in the kernel boot, the watchdog has
already been enabled by u-boot. The original code's attempt to
write to the TCR register results in an inadvertent clearing of the
watchdog configuration bits, causing the 476 to reset.
Panic happens in case of error as silently reboot without any outputs
on serial.
Signed-off-by: Ivan Mikhaylov <redacted>
---
arch/powerpc/kernel/time.c | 16 ++++++++++++++++
1 files changed, 16 insertions(+), 0 deletions(-)
From: Michael Ellerman <mpe@ellerman.id.au> Date: 2017-05-19 10:24:48
Hi Ivan,
Ivan Mikhaylov [off-list ref] writes:
Prevent a kernel panic caused by unintentionally clearing TCR
watchdog bits. At this point in the kernel boot, the watchdog has
already been enabled by u-boot. The original code's attempt to
write to the TCR register results in an inadvertent clearing of the
watchdog configuration bits, causing the 476 to reset.
Panic happens in case of error as silently reboot without any outputs
on serial.
@@ -738,12 +738,28 @@ static int __init get_freq(char *name, int cells, u=
nsigned long *val)
=20=20
static void start_cpu_decrementer(void)
{
+ unsigned int tcr;
#if defined(CONFIG_BOOKE) || defined(CONFIG_40x)
/* Clear any pending timer interrupts */
mtspr(SPRN_TSR, TSR_ENW | TSR_WIS | TSR_DIS | TSR_FIS);
=20=20
+#ifdef CONFIG_FSP2
+ /*
+ * Prevent a kernel panic caused by unintentionally clearing TCR
+ * watchdog bits. At this point in the kernel boot, the watchdog has
+ * already been enabled by u-boot. The original code's attempt to
Don't refer to "the original code", as it doesn't exist anymore now that
we've patched it. Just say something like ".. so we must not clear the
watchdog configuration bits".
+ * write to the TCR register results in an inadvertent clearing of the
+ * watchdog configuration bits, causing the 440 to reset.
+ */
+ tcr =3D mfspr(SPRN_TCR);
+ tcr &=3D TCR_WP_MASK; /* clear all bits except for TCR[WP] */
+ tcr |=3D TCR_DIE; /* enable decrementer */
+ mtspr(SPRN_TCR, tcr);
+#else
/* Enable decrementer interrupt */
mtspr(SPRN_TCR, TCR_DIE);
+#endif
+
#endif /* defined(CONFIG_BOOKE) || defined(CONFIG_40x) */
That breaks the build for other platforms:
arch/powerpc/kernel/time.c: In function =E2=80=98start_cpu_decrementer=E2=
=80=99:
arch/powerpc/kernel/time.c:741:15: error: unused variable =E2=80=98tcr=E2=
=80=99 [-Werror=3Dunused-variable]
You can just do something like:
#if defined(CONFIG_BOOKE) || defined(CONFIG_40x)
unsigned int tcr;
#ifdef CONFIG_FSP2
tcr =3D mfspr(SPRN_TCR);
tcr &=3D TCR_WP_MASK; /* clear all bits except for TCR[WP] */
#else
tcr =3D 0;
#endif
tcr |=3D TCR_DIE; /* enable decrementer */
mtspr(SPRN_TCR, TCR_DIE);
#endif /* defined(CONFIG_BOOKE) || defined(CONFIG_40x) */
Or you could possibly just always leave TCR[WP], is there any case where
it would be correct to clear that?
cheers
From: Benjamin Herrenschmidt <benh@kernel.crashing.org> Date: 2017-05-19 10:31:01
On Mon, 2017-05-15 at 16:07 +0300, Ivan Mikhaylov wrote:
+#ifdef CONFIG_FSP2
+ /*
+ * Prevent a kernel panic caused by unintentionally clearing TCR
+ * watchdog bits. At this point in the kernel boot, the watchdog has
+ * already been enabled by u-boot. The original code's attempt to
+ * write to the TCR register results in an inadvertent clearing of the
+ * watchdog configuration bits, causing the 440 to reset.
+ */
+ tcr = mfspr(SPRN_TCR);
+ tcr &= TCR_WP_MASK; /* clear all bits except for TCR[WP] */
+ tcr |= TCR_DIE; /* enable decrementer */
+ mtspr(SPRN_TCR, tcr);
+#else
This should be a runtime test, not a compile time option.
Cheers,
Ben.
@@ -738,12 +738,28 @@ static int =5F=5Finit get=5Ffreq(char *name, int c=
ells, unsigned long *val)
quoted
=20
static void start=5Fcpu=5Fdecrementer(void)
{
+ unsigned int tcr;
#if defined(CONFIG=5FBOOKE) || defined(CONFIG=5F40x)
/* Clear any pending timer interrupts */
mtspr(SPRN=5FTSR, TSR=5FENW | TSR=5FWIS | TSR=5FDIS | TSR=5FFIS);
=20
+#ifdef CONFIG=5FFSP2
+ /*
+ * Prevent a kernel panic caused by unintentionally clearing TCR
+ * watchdog bits. At this point in the kernel boot, the watchdog has
+ * already been enabled by u-boot. The original code's attempt to
Don't refer to "the original code", as it doesn't exist anymore now that
we've patched it. Just say something like ".. so we must not clear the
watchdog configuration bits".
Ok, got it.
That breaks the build for other platforms:
arch/powerpc/kernel/time.c: In function =E2=80=98start=5Fcpu=5Fdecremente=
Or you could possibly just always leave TCR[WP], is there any case where
it would be correct to clear that?
cheers
From my point of view it's possible. I've checked docu and on idea
it should be possible cause WP is only affecting watchdog ping time.
Which in case of '00' is very small, around ~5 ms.=20
Ben also in next message said about get rid of ifdef for FSP2.
And now patch looks like this, What do you think Michael, Ben?
arch/powerpc/kernel/time.c | 15 +++++++++++++--
1 files changed, 13 insertions(+), 2 deletions(-)
@@ -718,11 +718,22 @@ static int =5F=5Finit get=5Ffreq(char *name, int cell=
s, unsigned long *val)
static void start=5Fcpu=5Fdecrementer(void)
{
#if defined(CONFIG=5FBOOKE) || defined(CONFIG=5F40x)
+ unsigned int tcr;
/* Clear any pending timer interrupts */
mtspr(SPRN=5FTSR, TSR=5FENW | TSR=5FWIS | TSR=5FDIS | TSR=5FFIS);
=20
- /* Enable decrementer interrupt */
- mtspr(SPRN=5FTCR, TCR=5FDIE);
+ tcr =3D mfspr(SPRN=5FTCR);
+ /*
+ * At this point in the kernel boot, the watchdog has already
+ * been enabled by u-boot. If we set it this to '00' it may
+ * trigger watchdog earlier than needed which will cause
+ * inattentional kernel panic. In this case we leaving TCR[WP]
+ * bit setting from uboot/bootstrap.
+ */
+ tcr &=3D TCR=5FWP=5FMASK; /* clear all bits except for TCR[WP] */
+ tcr |=3D TCR=5FDIE; /* enable decrementer */
+ mtspr(SPRN=5FTCR, tcr);
+
#endif /* defined(CONFIG=5FBOOKE) || defined(CONFIG=5F40x) */
}
=20
--=20
1.7.1
From: Michael Ellerman <mpe@ellerman.id.au> Date: 2017-05-23 04:09:57
Ivan Mikhaylov [off-list ref] writes:
From my point of view it's possible. I've checked docu and on idea
it should be possible cause WP is only affecting watchdog ping time.
The question is, is there any chance that leaving those bits set on
another platform will cause a problem?
ie. on existing machines we always clear those bits, is it OK that we
will now start leaving those bits with whatever value they had.
cheers
From: Michael Ellerman <mpe@ellerman.id.au> Date: 2017-05-26 10:37:30
Michael Ellerman [off-list ref] writes:
Ivan Mikhaylov [off-list ref] writes:
quoted
From my point of view it's possible. I've checked docu and on idea
it should be possible cause WP is only affecting watchdog ping time.
The question is, is there any chance that leaving those bits set on
another platform will cause a problem?
ie. on existing machines we always clear those bits, is it OK that we
will now start leaving those bits with whatever value they had.
I came up with the patch below (more or less your v2), if it breaks
something we can always fix it.
cheers
commit c80409358a9c91e1f6b18353dad939b851bb3522
Author: Ivan Mikhaylov [off-list ref]
Date: Fri May 19 18:47:05 2017 +0300
powerpc/[booke|4xx]: Don't clobber TCR[WP] when setting TCR[DIE]
Prevent a kernel panic caused by unintentionally clearing TCR watchdog
bits. At this point in the kernel boot, the watchdog may have already
been enabled by u-boot. The original code's attempt to write to the TCR
register results in an inadvertent clearing of the watchdog
configuration bits, causing the 476 to reset.
Signed-off-by: Ivan Mikhaylov [off-list ref]
Signed-off-by: Michael Ellerman [off-list ref]
@@ -738,12 +738,28 @@ static int __init get_freq(char *name, int cells, unsigned long *val)staticvoidstart_cpu_decrementer(void){+unsignedinttcr;#if defined(CONFIG_BOOKE) || defined(CONFIG_40x)/* Clear any pending timer interrupts */mtspr(SPRN_TSR,TSR_ENW|TSR_WIS|TSR_DIS|TSR_FIS);+#ifdef CONFIG_FSP2+/*+*PreventakernelpaniccausedbyunintentionallyclearingTCR+*watchdogbits.Atthispointinthekernelboot,thewatchdoghas+*alreadybeenenabledbyu-boot.Theoriginalcode'sattemptto
Don't refer to "the original code", as it doesn't exist anymore now that
we've patched it. Just say something like ".. so we must not clear the
watchdog configuration bits".
Ok, got it.
quoted
That breaks the build for other platforms:
arch/powerpc/kernel/time.c: In function ���start_cpu_decrementer���:
arch/powerpc/kernel/time.c:741:15: error: unused variable ���tcr��� [-Werror=unused-variable]
Oops, didn't notice, my fault.
quoted
Or you could possibly just always leave TCR[WP], is there any case where
it would be correct to clear that?
cheers
quoted
From my point of view it's possible. I've checked docu and on idea
it should be possible cause WP is only affecting watchdog ping time.
Which in case of '00' is very small, around ~5 ms.
Ben also in next message said about get rid of ifdef for FSP2.
And now patch looks like this, What do you think Michael, Ben?
arch/powerpc/kernel/time.c | 15 +++++++++++++--
1 files changed, 13 insertions(+), 2 deletions(-)