From patchwork Mon Aug 27 11:35:14 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siva Rebbagondla X-Patchwork-Id: 10577019 X-Patchwork-Delegate: kvalo@adurom.com Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork-2.web.codeaurora.org (Postfix) with ESMTP id 4512617DB for ; Mon, 27 Aug 2018 11:31:27 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 34953298A5 for ; Mon, 27 Aug 2018 11:31:27 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 2756D298CF; Mon, 27 Aug 2018 11:31:27 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-8.0 required=2.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FROM,MAILING_LIST_MULTI,RCVD_IN_DNSWL_HI autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 9C51D298A5 for ; Mon, 27 Aug 2018 11:31:26 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726947AbeH0PRm (ORCPT ); Mon, 27 Aug 2018 11:17:42 -0400 Received: from mail-pf1-f196.google.com ([209.85.210.196]:39700 "EHLO mail-pf1-f196.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726825AbeH0PRl (ORCPT ); Mon, 27 Aug 2018 11:17:41 -0400 Received: by mail-pf1-f196.google.com with SMTP id j8-v6so7616345pff.6 for ; Mon, 27 Aug 2018 04:31:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id; bh=pWMhg35VRq0IMzGGu8tXGIgFNvf+CI5MEmxZXP0q+g8=; b=AnC9ZqouO1B7gAsklYF0YhUY5e9X5eanPYRPtSDw0EKUFkM2oa3tfNLBU2FK3qHI0/ hiH1ekVt6AU8wFc0J5nzFUzkNaPMtuwjK4pBC4iSX05iqoMXC0OK23pqCfGEVwvXbb8d ZB7Va4ARddwH679TM6W2jBwRQelAQtyx9K0gN1htekpq+7l7OvxSjtv1UKZ0xefrq7en voawDXV7UhPqLJSjaW8YTPpcXhV0G/lnaHe614AI6iPXmosZ44PvR9LX+ATiOT3RBLMH ShVztIlZL4j27AepqGzfoOSMgH5YY0xuPeLA++tvL4W9NTb/aq4bROqyC9jU10ugmYeq cisw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=pWMhg35VRq0IMzGGu8tXGIgFNvf+CI5MEmxZXP0q+g8=; b=cEaH3/QAVO9Y3eMqJg0tB2cGiFrqHLFxzxn61UIzuSuxz0zQHBKtLy9nHlbKRBOHjd hglNRpxxbK9v2cd/tsNHlrXC0gkpNOVVtSc8cogZgWgpBNulSIQcoa2y65lY6wGVCndE D9/+8OxSUehQY850Rgys377ao/vy/ke/iphMsW4w/UzZ5HxjvtSLSJeivpRQL08u1nEL QHXksAKE1fxFRg4DElVR6xcJDLk1hegl3Y3sCYrByFBkGsebBN5euNj3UiSciasuuvQj ryQe2DBcp95zJ7KTpb9OkZp2Cjf21HZKgtXpcM0KffnMWgtrDE2P2fYeK2b0HlDwUR1g xTJw== X-Gm-Message-State: APzg51D4NaBwexWGQC2hrgIzB7Xve9kRrClM7aZtm7qRJrfLaSYh2IKe i7XlE71r3hn2R3zlybi2kAs= X-Google-Smtp-Source: ANB0VdZjfgCWepsDFmxRrlGSNIrmHk2mqnf5qW3FvBootD1YAZ7AfjqbKItwcODZ1dhiWiSuMHRDlg== X-Received: by 2002:a63:4f64:: with SMTP id p36-v6mr3221721pgl.210.1535369484526; Mon, 27 Aug 2018 04:31:24 -0700 (PDT) Received: from cpu459.localdomain ([27.59.166.244]) by smtp.gmail.com with ESMTPSA id e202-v6sm23696375pfh.16.2018.08.27.04.31.21 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 27 Aug 2018 04:31:23 -0700 (PDT) From: Siva Rebbagondla To: Kalle Valo Cc: linux-wireless@vger.kernel.org, Sasidhar Mudigonda , Siva Rebbagondla , Sanjay Konduri Subject: [PATCH 1/2] rsi: fix memory alignment issue in ARM32 platforms Date: Mon, 27 Aug 2018 17:05:14 +0530 Message-Id: <1535369715-14254-1-git-send-email-siva8118@gmail.com> X-Mailer: git-send-email 2.5.5 Sender: linux-wireless-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP From: Siva Rebbagondla During testing in ARM32 platforms, observed below kernel panic, as driver accessing data beyond the allocated memory while submitting URB to USB. Fix: Resolved this by specifying correct length by considering 64 bit alignment. so that, USB bus driver will access only allocated memory. Unit-test: Tested and confirm that driver bring up and scanning, connection and data transfer works fine with this fix. ...skipping... [ 25.389450] Unable to handle kernel paging request at virtual address 5aa11422 [ 25.403078] Internal error: Oops: 5 [#1] SMP ARM [ 25.407703] Modules linked in: rsi_usb [ 25.411473] CPU: 1 PID: 317 Comm: RX-Thread Not tainted 4.18.0-rc7 #1 [ 25.419221] Hardware name: Freescale i.MX6 Quad/DualLite (Device Tree) [ 25.425764] PC is at skb_release_data+0x90/0x168 [ 25.430393] LR is at skb_release_all+0x28/0x2c [ 25.434842] pc : [<807435b0>] lr : [<80742ba0>] psr: 200e0013 5aa1141e [ 25.464633] Flags: nzCv IRQs on FIQs on Mode SVC_32 ISA ARM Segment none [ 25.477524] Process RX-Thread (pid: 317, stack limit = 0x(ptrval)) [ 25.483709] Stack: (0xedf69ed8 to 0xedf6a000) [ 25.569907] Backtrace: [ 25.572368] [<80743520>] (skb_release_data) from [<80742ba0>] (skb_release_all+0x28/0x2c) [ 25.580555] r9:7f00258c r8:00000001 r7:ee355000 r6:eddab0d0 r5:eddab000 r4:eddbb840 [ 25.588308] [<80742b78>] (skb_release_all) from [<807432cc>] (consume_skb+0x30/0x50) [ 25.596055] r5:eddab000 r4:eddbb840 [ 25.599648] [<8074329c>] (consume_skb) from [<7f00117c>] (rsi_usb_rx_thread+0x64/0x12c [rsi_usb]) [ 25.608524] r5:eddab000 r4:eddbb840 [ 25.612116] [<7f001118>] (rsi_usb_rx_thread [rsi_usb]) from [<80142750>] (kthread+0x11c/0x15c) [ 25.620735] r10:ee9ff9e0 r9:edcde3b8 r8:ee355000 r7:edf68000 r6:edd3a780 r5:00000000 [ 25.628567] r4:edcde380 [ 25.631110] [<80142634>] (kthread) from [<801010e8>] (ret_from_fork+0x14/0x2c) [ 25.638336] Exception stack(0xedf69fb0 to 0xedf69ff8) [ 25.682929] ---[ end trace 8236a5496f5b5d3b ]--- Signed-off-by: Siva Rebbagondla --- drivers/net/wireless/rsi/rsi_91x_usb.c | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/drivers/net/wireless/rsi/rsi_91x_usb.c b/drivers/net/wireless/rsi/rsi_91x_usb.c index c0a163e..f360690 100644 --- a/drivers/net/wireless/rsi/rsi_91x_usb.c +++ b/drivers/net/wireless/rsi/rsi_91x_usb.c @@ -266,15 +266,17 @@ static void rsi_rx_done_handler(struct urb *urb) if (urb->status) goto out; - if (urb->actual_length <= 0) { - rsi_dbg(INFO_ZONE, "%s: Zero length packet\n", __func__); + if (urb->actual_length <= 0 || + urb->actual_length > rx_cb->rx_skb->len) { + rsi_dbg(INFO_ZONE, "%s: Invalid packet length = %d\n", + __func__, urb->actual_length); goto out; } if (skb_queue_len(&dev->rx_q) >= RSI_MAX_RX_PKTS) { rsi_dbg(INFO_ZONE, "Max RX packets reached\n"); goto out; } - skb_put(rx_cb->rx_skb, urb->actual_length); + skb_trim(rx_cb->rx_skb, urb->actual_length); skb_queue_tail(&dev->rx_q, rx_cb->rx_skb); rsi_set_event(&dev->rx_thread.event); @@ -308,6 +310,7 @@ static int rsi_rx_urb_submit(struct rsi_hw *adapter, u8 ep_num) if (!skb) return -ENOMEM; skb_reserve(skb, MAX_DWORD_ALIGN_BYTES); + skb_put(skb, RSI_MAX_RX_USB_PKT_SIZE - MAX_DWORD_ALIGN_BYTES); dword_align_bytes = (unsigned long)skb->data & 0x3f; if (dword_align_bytes > 0) skb_push(skb, dword_align_bytes); @@ -319,7 +322,7 @@ static int rsi_rx_urb_submit(struct rsi_hw *adapter, u8 ep_num) usb_rcvbulkpipe(dev->usbdev, dev->bulkin_endpoint_addr[ep_num - 1]), urb->transfer_buffer, - RSI_MAX_RX_USB_PKT_SIZE, + skb->len, rsi_rx_done_handler, rx_cb); From patchwork Mon Aug 27 11:35:15 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Siva Rebbagondla X-Patchwork-Id: 10577021 X-Patchwork-Delegate: kvalo@adurom.com Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork-2.web.codeaurora.org (Postfix) with ESMTP id 82B4F17DB for ; Mon, 27 Aug 2018 11:31:29 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 72577298A5 for ; Mon, 27 Aug 2018 11:31:29 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 6678E298D0; Mon, 27 Aug 2018 11:31:29 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-8.0 required=2.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FROM,MAILING_LIST_MULTI,RCVD_IN_DNSWL_HI autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 1056F298A5 for ; Mon, 27 Aug 2018 11:31:29 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727110AbeH0PRo (ORCPT ); Mon, 27 Aug 2018 11:17:44 -0400 Received: from mail-pl1-f195.google.com ([209.85.214.195]:39841 "EHLO mail-pl1-f195.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726825AbeH0PRo (ORCPT ); Mon, 27 Aug 2018 11:17:44 -0400 Received: by mail-pl1-f195.google.com with SMTP id w14-v6so4049947plp.6 for ; Mon, 27 Aug 2018 04:31:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=or105kDghBMNMv0ANo1Lh6Z+eLJbql5/VC4E/NXgYJA=; b=cpzmnPIZFDvF1MuzossYTo9UfPkYOkmEtCPvqDtpUZrV4pqxAR7pfHsdUhWDB3VTx5 +h6JdGvzyM3M5NoZSMZzfGpf5nLC68VQOzfU1Pg3z9udvKhrZz54puKuNQKryVyQBAxb 0xdOJqmDg5+c8z8yh4UxV/j1o3KCfGctq3/F8rzLpwAoJjqSUHKjS3c4smno2/+Ut/qu MqQNxxz2GZIm44Es0vzLmFrVAJwbkDUvZ51Tdz58cExPX8nSmtfDWz52GkQlCsYFjEJl 38c7U03O0eVgjG0gCcmqRqz0cpzRpXV80qniMvGFSwhKf6uuItb5OfVTyMOntJjwApUg ERNg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=or105kDghBMNMv0ANo1Lh6Z+eLJbql5/VC4E/NXgYJA=; b=RW39OXNMMDQ/Y1fVAHq+8LG8UbQauQ5Wcn9lQIecbwBKPxWOEq6zDkWOz1nShGWTAV yvqaBCI3yFOVFAxgaKBhID+yeJ2Eeq3bIhS9QPPxruoI/RdFEv3bvqhhALY4Xk89YzS9 +ysytXgqzqq+0uDV5YyOYAxc1pdx8AidAjeqCbttwNJ4y2KMGybVg0qwSHfZKrHcEWIf 59AX5ndBXX9ICP6eg9KE9iL5ZOXc/2+DWeUd2/ODPZnEn+rWna4+XBMd1NbCzo6B80+J qy5OocuhdYk5kXefwe8Uhnkqd0cVm4nqmMFn0dmBMcWN8AuHNMkMjTOKrtfo6acyTEJ7 osUA== X-Gm-Message-State: APzg51Bh0fXnEagzU7c/qO30AhubOhp22c95g3cnnYxtoyLYJAZC+MrA G+ZF111du+yHwOusgjmeLqE/uHmK X-Google-Smtp-Source: ANB0VdbzYY1nheIxDRFEJUpPhUzl9w/xaVmeTLE/+gD+UPZZfBPMv4Iha51XRKucjRr4WPlElkkQdQ== X-Received: by 2002:a17:902:7798:: with SMTP id o24-v6mr429160pll.93.1535369487403; Mon, 27 Aug 2018 04:31:27 -0700 (PDT) Received: from cpu459.localdomain ([27.59.166.244]) by smtp.gmail.com with ESMTPSA id e202-v6sm23696375pfh.16.2018.08.27.04.31.24 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 27 Aug 2018 04:31:26 -0700 (PDT) From: Siva Rebbagondla To: Kalle Valo Cc: linux-wireless@vger.kernel.org, Sasidhar Mudigonda , Siva Rebbagondla , Sanjay Konduri Subject: [PATCH 2/2] rsi: improve kernel thread handling to fix kernel panic Date: Mon, 27 Aug 2018 17:05:15 +0530 Message-Id: <1535369715-14254-2-git-send-email-siva8118@gmail.com> X-Mailer: git-send-email 2.5.5 In-Reply-To: <1535369715-14254-1-git-send-email-siva8118@gmail.com> References: <1535369715-14254-1-git-send-email-siva8118@gmail.com> Sender: linux-wireless-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP From: Siva Rebbagondla While running regressions, observed below kernel panic when sdio disconnect called. This is because of, kthread_stop() is taking care of wait_for_completion() by default. When wait_for_completion triggered in kthread_stop and as it was done already, giving kernel panic. Hence, removing redundant wait_for_completion() from rsi_kill_thread(). ... skipping ... BUG: unable to handle kernel NULL pointer dereference at (null) IP: [] exit_creds+0x1f/0x50 PGD 0 Oops: 0002 [#1] SMP CPU: 0 PID: 6502 Comm: rmmod Tainted: G OE 4.15.9-Generic #154-Ubuntu Hardware name: Dell Inc. Edge Gateway 3003/ , BIOS 01.00.00 04/17/2017 Stack: ffff88007392e600 ffff880075847dc0 ffffffff8108160a 0000000000000000 ffff88007392e600 ffff880075847de8 ffffffff810a484b ffff880076127000 ffff88003cd3a800 ffff880074f12a00 ffff880075847e28 ffffffffc09bed15 Call Trace: [] __put_task_struct+0x5a/0x140 [] kthread_stop+0x10b/0x110 [] rsi_disconnect+0x2f5/0x300 [ven_rsi_sdio] [] ? __pm_runtime_resume+0x5b/0x80 [] sdio_bus_remove+0x38/0x100 [] __device_release_driver+0xa4/0x150 [] driver_detach+0xb5/0xc0 [] bus_remove_driver+0x55/0xd0 [] driver_unregister+0x2c/0x50 [] sdio_unregister_driver+0x1a/0x20 [] rsi_module_exit+0x15/0x30 [ven_rsi_sdio] [] SyS_delete_module+0x1b8/0x210 [] entry_SYSCALL_64_fastpath+0x1c/0xbb Signed-off-by: Siva Rebbagondla --- drivers/net/wireless/rsi/rsi_common.h | 1 - 1 file changed, 1 deletion(-) diff --git a/drivers/net/wireless/rsi/rsi_common.h b/drivers/net/wireless/rsi/rsi_common.h index d9ff3b8..60f1f28 100644 --- a/drivers/net/wireless/rsi/rsi_common.h +++ b/drivers/net/wireless/rsi/rsi_common.h @@ -75,7 +75,6 @@ static inline int rsi_kill_thread(struct rsi_thread *handle) atomic_inc(&handle->thread_done); rsi_set_event(&handle->event); - wait_for_completion(&handle->completion); return kthread_stop(handle->task); }