]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/blob - releases/4.19.35/ibmvnic-fix-completion-structure-initialization.patch
Linux 4.14.112
[thirdparty/kernel/stable-queue.git] / releases / 4.19.35 / ibmvnic-fix-completion-structure-initialization.patch
1 From 83f76c00bf340cc258c8a70a8696778980399b0b Mon Sep 17 00:00:00 2001
2 From: Thomas Falcon <tlfalcon@linux.ibm.com>
3 Date: Thu, 4 Apr 2019 18:58:26 -0500
4 Subject: ibmvnic: Fix completion structure initialization
5
6 [ Upstream commit bbd669a868bba591ffd38b7bc75a7b361bb54b04 ]
7
8 Fix device initialization completion handling for vNIC adapters.
9 Initialize the completion structure on probe and reinitialize when needed.
10 This also fixes a race condition during kdump where the driver can attempt
11 to access the completion struct before it is initialized:
12
13 Unable to handle kernel paging request for data at address 0x00000000
14 Faulting instruction address: 0xc0000000081acbe0
15 Oops: Kernel access of bad area, sig: 11 [#1]
16 LE SMP NR_CPUS=2048 NUMA pSeries
17 Modules linked in: ibmvnic(+) ibmveth sunrpc overlay squashfs loop
18 CPU: 19 PID: 301 Comm: systemd-udevd Not tainted 4.18.0-64.el8.ppc64le #1
19 NIP: c0000000081acbe0 LR: c0000000081ad964 CTR: c0000000081ad900
20 REGS: c000000027f3f990 TRAP: 0300 Not tainted (4.18.0-64.el8.ppc64le)
21 MSR: 800000010280b033 <SF,VEC,VSX,EE,FP,ME,IR,DR,RI,LE,TM[E]> CR: 28228288 XER: 00000006
22 CFAR: c000000008008934 DAR: 0000000000000000 DSISR: 40000000 IRQMASK: 1
23 GPR00: c0000000081ad964 c000000027f3fc10 c0000000095b5800 c0000000221b4e58
24 GPR04: 0000000000000003 0000000000000001 000049a086918581 00000000000000d4
25 GPR08: 0000000000000007 0000000000000000 ffffffffffffffe8 d0000000014dde28
26 GPR12: c0000000081ad900 c000000009a00c00 0000000000000001 0000000000000100
27 GPR16: 0000000000000038 0000000000000007 c0000000095e2230 0000000000000006
28 GPR20: 0000000000400140 0000000000000001 c00000000910c880 0000000000000000
29 GPR24: 0000000000000000 0000000000000006 0000000000000000 0000000000000003
30 GPR28: 0000000000000001 0000000000000001 c0000000221b4e60 c0000000221b4e58
31 NIP [c0000000081acbe0] __wake_up_locked+0x50/0x100
32 LR [c0000000081ad964] complete+0x64/0xa0
33 Call Trace:
34 [c000000027f3fc10] [c000000027f3fc60] 0xc000000027f3fc60 (unreliable)
35 [c000000027f3fc60] [c0000000081ad964] complete+0x64/0xa0
36 [c000000027f3fca0] [d0000000014dad58] ibmvnic_handle_crq+0xce0/0x1160 [ibmvnic]
37 [c000000027f3fd50] [d0000000014db270] ibmvnic_tasklet+0x98/0x130 [ibmvnic]
38 [c000000027f3fda0] [c00000000813f334] tasklet_action_common.isra.3+0xc4/0x1a0
39 [c000000027f3fe00] [c000000008cd13f4] __do_softirq+0x164/0x400
40 [c000000027f3fef0] [c00000000813ed64] irq_exit+0x184/0x1c0
41 [c000000027f3ff20] [c0000000080188e8] __do_irq+0xb8/0x210
42 [c000000027f3ff90] [c00000000802d0a4] call_do_irq+0x14/0x24
43 [c000000026a5b010] [c000000008018adc] do_IRQ+0x9c/0x130
44 [c000000026a5b060] [c000000008008ce4] hardware_interrupt_common+0x114/0x120
45
46 Signed-off-by: Thomas Falcon <tlfalcon@linux.ibm.com>
47 Signed-off-by: David S. Miller <davem@davemloft.net>
48 Signed-off-by: Sasha Levin <sashal@kernel.org>
49 ---
50 drivers/net/ethernet/ibm/ibmvnic.c | 5 +++--
51 1 file changed, 3 insertions(+), 2 deletions(-)
52
53 diff --git a/drivers/net/ethernet/ibm/ibmvnic.c b/drivers/net/ethernet/ibm/ibmvnic.c
54 index c8704b1690eb..a475f36ddf8c 100644
55 --- a/drivers/net/ethernet/ibm/ibmvnic.c
56 +++ b/drivers/net/ethernet/ibm/ibmvnic.c
57 @@ -1888,6 +1888,7 @@ static int do_hard_reset(struct ibmvnic_adapter *adapter,
58 */
59 adapter->state = VNIC_PROBED;
60
61 + reinit_completion(&adapter->init_done);
62 rc = init_crq_queue(adapter);
63 if (rc) {
64 netdev_err(adapter->netdev,
65 @@ -4569,7 +4570,7 @@ static int ibmvnic_reset_init(struct ibmvnic_adapter *adapter)
66 old_num_rx_queues = adapter->req_rx_queues;
67 old_num_tx_queues = adapter->req_tx_queues;
68
69 - init_completion(&adapter->init_done);
70 + reinit_completion(&adapter->init_done);
71 adapter->init_done_rc = 0;
72 ibmvnic_send_crq_init(adapter);
73 if (!wait_for_completion_timeout(&adapter->init_done, timeout)) {
74 @@ -4624,7 +4625,6 @@ static int ibmvnic_init(struct ibmvnic_adapter *adapter)
75
76 adapter->from_passive_init = false;
77
78 - init_completion(&adapter->init_done);
79 adapter->init_done_rc = 0;
80 ibmvnic_send_crq_init(adapter);
81 if (!wait_for_completion_timeout(&adapter->init_done, timeout)) {
82 @@ -4703,6 +4703,7 @@ static int ibmvnic_probe(struct vio_dev *dev, const struct vio_device_id *id)
83 INIT_WORK(&adapter->ibmvnic_reset, __ibmvnic_reset);
84 INIT_LIST_HEAD(&adapter->rwi_list);
85 spin_lock_init(&adapter->rwi_lock);
86 + init_completion(&adapter->init_done);
87 adapter->resetting = false;
88
89 adapter->mac_change_pending = false;
90 --
91 2.19.1
92