[PATCH] net: cadence: Fix a sleep-in-atomic-context bug in macb_halt_tx()

Subsystems: atmel macb ethernet driver, networking drivers, the rest

STALE2910d

2 messages, 2 authors, 2018-09-02 · open the first message on its own page

[PATCH] net: cadence: Fix a sleep-in-atomic-context bug in macb_halt_tx()

From: Jia-Ju Bai <hidden>
Date: 2018-09-01 12:11:15

The kernel module may sleep with holding a spinlock.

The function call paths (from bottom to top) in Linux-4.16 are:

[FUNC] usleep_range
drivers/net/ethernet/cadence/macb_main.c, 648: 
	usleep_range in macb_halt_tx
drivers/net/ethernet/cadence/macb_main.c, 730: 
	macb_halt_tx in macb_tx_error_task
drivers/net/ethernet/cadence/macb_main.c, 721: 
	_raw_spin_lock_irqsave in macb_tx_error_task

To fix this bug, usleep_range() is replaced with udelay().

This bug is found by my static analysis tool DSAC.

Signed-off-by: Jia-Ju Bai <redacted>
---
 drivers/net/ethernet/cadence/macb_main.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/cadence/macb_main.c b/drivers/net/ethernet/cadence/macb_main.c
index a6c911bb5ce2..3dcc31cd4261 100644
--- a/drivers/net/ethernet/cadence/macb_main.c
+++ b/drivers/net/ethernet/cadence/macb_main.c
@@ -641,7 +641,7 @@ static int macb_halt_tx(struct macb *bp)
 		if (!(status & MACB_BIT(TGO)))
 			return 0;
 
-		usleep_range(10, 250);
+		udelay(250);
 	} while (time_before(halt_time, timeout));
 
 	return -ETIMEDOUT;
-- 
2.17.0

Re: [PATCH] net: cadence: Fix a sleep-in-atomic-context bug in macb_halt_tx()

From: David Miller <davem@davemloft.net>
Date: 2018-09-02 23:05:42

From: Jia-Ju Bai <redacted>
Date: Sat,  1 Sep 2018 20:11:05 +0800
The kernel module may sleep with holding a spinlock.

The function call paths (from bottom to top) in Linux-4.16 are:

[FUNC] usleep_range
drivers/net/ethernet/cadence/macb_main.c, 648: 
	usleep_range in macb_halt_tx
drivers/net/ethernet/cadence/macb_main.c, 730: 
	macb_halt_tx in macb_tx_error_task
drivers/net/ethernet/cadence/macb_main.c, 721: 
	_raw_spin_lock_irqsave in macb_tx_error_task

To fix this bug, usleep_range() is replaced with udelay().

This bug is found by my static analysis tool DSAC.

Signed-off-by: Jia-Ju Bai <redacted>
Applied, thanks.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help