@@ -739,53 +739,53 @@ int rndis_filter_open(struct hv_device *dev)intrndis_filter_close(structhv_device*dev){-structnetvsc_device*netDevice=hv_get_drvdata(dev);+structnetvsc_device*nvdev=hv_get_drvdata(dev);-if(!netDevice)+if(!nvdev)return-EINVAL;-returnrndis_filter_close_device(netDevice->extension);+returnrndis_filter_close_device(nvdev->extension);}intrndis_filter_send(structhv_device*dev,structhv_netvsc_packet*pkt){intret;-structrndis_filter_packet*filterPacket;-structrndis_message*rndisMessage;-structrndis_packet*rndisPacket;-u32rndisMessageSize;+structrndis_filter_packet*filter_pkt;+structrndis_message*rndis_msg;+structrndis_packet*rndis_pkt;+u32rndis_msg_size;/* Add the rndis header */-filterPacket=(structrndis_filter_packet*)pkt->extension;+filter_pkt=(structrndis_filter_packet*)pkt->extension;-memset(filterPacket,0,sizeof(structrndis_filter_packet));+memset(filter_pkt,0,sizeof(structrndis_filter_packet));-rndisMessage=&filterPacket->msg;-rndisMessageSize=RNDIS_MESSAGE_SIZE(structrndis_packet);+rndis_msg=&filter_pkt->msg;+rndis_msg_size=RNDIS_MESSAGE_SIZE(structrndis_packet);-rndisMessage->ndis_msg_type=REMOTE_NDIS_PACKET_MSG;-rndisMessage->msg_len=pkt->total_data_buflen+-rndisMessageSize;+rndis_msg->ndis_msg_type=REMOTE_NDIS_PACKET_MSG;+rndis_msg->msg_len=pkt->total_data_buflen++rndis_msg_size;-rndisPacket=&rndisMessage->msg.pkt;-rndisPacket->data_offset=sizeof(structrndis_packet);-rndisPacket->data_len=pkt->total_data_buflen;+rndis_pkt=&rndis_msg->msg.pkt;+rndis_pkt->data_offset=sizeof(structrndis_packet);+rndis_pkt->data_len=pkt->total_data_buflen;pkt->is_data_pkt=true;-pkt->page_buf[0].pfn=virt_to_phys(rndisMessage)>>PAGE_SHIFT;+pkt->page_buf[0].pfn=virt_to_phys(rndis_msg)>>PAGE_SHIFT;pkt->page_buf[0].offset=-(unsignedlong)rndisMessage&(PAGE_SIZE-1);-pkt->page_buf[0].len=rndisMessageSize;+(unsignedlong)rndis_msg&(PAGE_SIZE-1);+pkt->page_buf[0].len=rndis_msg_size;/* Save the packet send completion and context */-filterPacket->completion=pkt->completion.send.send_completion;-filterPacket->completion_ctx=+filter_pkt->completion=pkt->completion.send.send_completion;+filter_pkt->completion_ctx=pkt->completion.send.send_completion_ctx;/* Use ours */pkt->completion.send.send_completion=rndis_filter_send_completion;-pkt->completion.send.send_completion_ctx=filterPacket;+pkt->completion.send.send_completion_ctx=filter_pkt;ret=netvsc_send(dev,pkt);if(ret!=0){
@@ -794,9 +794,9 @@ int rndis_filter_send(struct hv_device *dev,*above*/pkt->completion.send.send_completion=-filterPacket->completion;+filter_pkt->completion;pkt->completion.send.send_completion_ctx=-filterPacket->completion_ctx;+filter_pkt->completion_ctx;}returnret;
@@ -804,10 +804,10 @@ int rndis_filter_send(struct hv_device *dev,staticvoidrndis_filter_send_completion(void*ctx){-structrndis_filter_packet*filterPacket=ctx;+structrndis_filter_packet*filter_pkt=ctx;/* Pass it back to the original handler */-filterPacket->completion(filterPacket->completion_ctx);+filter_pkt->completion(filter_pkt->completion_ctx);}
The memory has been allocated by kzalloc, so it's unnecessary to memset
again.
Signed-off-by: Haiyang Zhang <haiyangz@microsoft.com>
Signed-off-by: K. Y. Srinivasan <kys@microsoft.com>
---
drivers/net/hyperv/rndis_filter.c | 2 --
1 files changed, 0 insertions(+), 2 deletions(-)
There is a possible data corruption if an RNDIS message goes beyond page
boundary in the sending code path. This patch fixes the problem.
Signed-off-by: Haiyang Zhang <haiyangz@microsoft.com>
Signed-off-by: K. Y. Srinivasan <kys@microsoft.com>
---
drivers/net/hyperv/netvsc_drv.c | 8 ++++----
drivers/net/hyperv/rndis_filter.c | 13 +++++++++++++
2 files changed, 17 insertions(+), 4 deletions(-)
@@ -151,10 +151,10 @@ static int netvsc_start_xmit(struct sk_buff *skb, struct net_device *net)intret;unsignedinti,num_pages,npg_data;-/* Add multipage for skb->data and additional one for RNDIS */+/* Add multipages for skb->data and additional 2 for RNDIS */npg_data=(((unsignedlong)skb->data+skb_headlen(skb)-1)>>PAGE_SHIFT)-((unsignedlong)skb->data>>PAGE_SHIFT)+1;-num_pages=skb_shinfo(skb)->nr_frags+npg_data+1;+num_pages=skb_shinfo(skb)->nr_frags+npg_data+2;/* Allocate a netvsc packet based on # of frags. */packet=kzalloc(sizeof(structhv_netvsc_packet)+
@@ -173,8 +173,8 @@ static int netvsc_start_xmit(struct sk_buff *skb, struct net_device *net)sizeof(structhv_netvsc_packet)+(num_pages*sizeof(structhv_page_buffer));-/* Setup the rndis header */-packet->page_buf_cnt=num_pages;+/* If the rndis msg goes beyond 1 page, we will add 1 later */+packet->page_buf_cnt=num_pages-1;/* Initialize it from the skb */packet->total_data_buflen=skb->len;
@@ -776,6 +776,19 @@ int rndis_filter_send(struct hv_device *dev,(unsignedlong)rndis_msg&(PAGE_SIZE-1);pkt->page_buf[0].len=rndis_msg_size;+/* Add one page_buf if the rndis msg goes beyond page boundary */+if(pkt->page_buf[0].offset+rndis_msg_size>PAGE_SIZE){+inti;+for(i=pkt->page_buf_cnt;i>1;i--)+pkt->page_buf[i]=pkt->page_buf[i-1];+pkt->page_buf_cnt++;+pkt->page_buf[0].len=PAGE_SIZE-pkt->page_buf[0].offset;+pkt->page_buf[1].pfn=virt_to_phys((void*)((ulong)rndis_msg++pkt->page_buf[0].len))>>PAGE_SHIFT;+pkt->page_buf[1].offset=0;+pkt->page_buf[1].len=rndis_msg_size-pkt->page_buf[0].len;+}+/* Save the packet send completion and context */filter_pkt->completion=pkt->completion.send.send_completion;filter_pkt->completion_ctx=
For code path not on the xmit, use netif_tx_disable() instead of
netif_stop_queue() to ensure other CPUs are not doing xmit.
Signed-off-by: Haiyang Zhang <haiyangz@microsoft.com>
Signed-off-by: K. Y. Srinivasan <kys@microsoft.com>
---
drivers/net/hyperv/netvsc_drv.c | 8 ++++----
1 files changed, 4 insertions(+), 4 deletions(-)
The first assignment to variable "net" is wrong, but overridden by the
latter assignments. So the bug isn't manifested.
Signed-off-by: Haiyang Zhang <haiyangz@microsoft.com>
Signed-off-by: K. Y. Srinivasan <kys@microsoft.com>
---
drivers/net/hyperv/netvsc_drv.c | 7 ++-----
1 files changed, 2 insertions(+), 5 deletions(-)
From: David Miller <davem@davemloft.net> Date: 2012-02-01 19:37:01
Please do not mix cleanups with real bug fixes.
Patches #4 and #5 in this series fix real bugs, so you should submit them
seperately for inclusion to my 'net' tree.
Once those fixes have propagated to my 'net-next' tree, you can then submit
the cleanups.
-----Original Message-----
From: David Miller [mailto:davem@davemloft.net]
Sent: Wednesday, February 01, 2012 2:37 PM
To: Haiyang Zhang
Cc: KY Srinivasan; netdev@vger.kernel.org; linux-kernel@vger.kernel.org
Subject: Re: [PATCH 1/5] net/hyperv: Convert camel cased variables in
rndis_filter.c to lower cases
Please do not mix cleanups with real bug fixes.
Patches #4 and #5 in this series fix real bugs, so you should submit them
seperately for inclusion to my 'net' tree.
Once those fixes have propagated to my 'net-next' tree, you can then
submit
the cleanups.