[PATCH net] hinic: fix rewaking txq after netif_tx_disable

Subsystems: huawei ethernet driver, networking drivers, the rest

STALE2156d

3 messages, 2 authors, 2020-09-08 · open the first message on its own page

[PATCH net] hinic: fix rewaking txq after netif_tx_disable

From: Luo bin <hidden>
Date: 2020-09-07 17:14:46

When calling hinic_close in hinic_set_channels, all queues are
stopped after netif_tx_disable, but some queue may be rewaken in
free_tx_poll by mistake while drv is handling tx irq. If one queue
is rewaken core may call hinic_xmit_frame to send pkt after
netif_tx_disable within a short time which may results in accessing
memory that has been already freed in hinic_close. So we judge
whether the netdev is in down state before waking txq in free_tx_poll
to fix this bug.

Signed-off-by: Luo bin <redacted>
---
 drivers/net/ethernet/huawei/hinic/hinic_tx.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/huawei/hinic/hinic_tx.c b/drivers/net/ethernet/huawei/hinic/hinic_tx.c
index a97498ee6914..6eac6bdf164e 100644
--- a/drivers/net/ethernet/huawei/hinic/hinic_tx.c
+++ b/drivers/net/ethernet/huawei/hinic/hinic_tx.c
@@ -718,7 +718,8 @@ static int free_tx_poll(struct napi_struct *napi, int budget)
 
 		__netif_tx_lock(netdev_txq, smp_processor_id());
 
-		netif_wake_subqueue(nic_dev->netdev, qp->q_id);
+		if (nic_dev->flags & HINIC_INTF_UP)
+			netif_wake_subqueue(nic_dev->netdev, qp->q_id);
 
 		__netif_tx_unlock(netdev_txq);
 
-- 
2.17.1

Re: [PATCH net] hinic: fix rewaking txq after netif_tx_disable

From: Jakub Kicinski <kuba@kernel.org>
Date: 2020-09-07 21:28:56

On Mon, 7 Sep 2020 22:15:16 +0800 Luo bin wrote:
When calling hinic_close in hinic_set_channels, all queues are
stopped after netif_tx_disable, but some queue may be rewaken in
free_tx_poll by mistake while drv is handling tx irq. If one queue
is rewaken core may call hinic_xmit_frame to send pkt after
netif_tx_disable within a short time which may results in accessing
memory that has been already freed in hinic_close. So we judge
whether the netdev is in down state before waking txq in free_tx_poll
to fix this bug.
The right fix is to call napi_disable() _before_ you call
netif_tx_disable(), not after, like hinic_close() does.

Re: [PATCH net] hinic: fix rewaking txq after netif_tx_disable

From: luobin (L) <hidden>
Date: 2020-09-08 17:26:19

On 2020/9/8 5:28, Jakub Kicinski wrote:
On Mon, 7 Sep 2020 22:15:16 +0800 Luo bin wrote:
quoted
When calling hinic_close in hinic_set_channels, all queues are
stopped after netif_tx_disable, but some queue may be rewaken in
free_tx_poll by mistake while drv is handling tx irq. If one queue
is rewaken core may call hinic_xmit_frame to send pkt after
netif_tx_disable within a short time which may results in accessing
memory that has been already freed in hinic_close. So we judge
whether the netdev is in down state before waking txq in free_tx_poll
to fix this bug.
The right fix is to call napi_disable() _before_ you call
netif_tx_disable(), not after, like hinic_close() does.
.
Will fix. Thanks for your review.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help