From patchwork Mon Jul 6 13:21:13 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Stanley Chu X-Patchwork-Id: 11645743 Return-Path: Received: from mail.kernel.org (pdx-korg-mail-1.web.codeaurora.org [172.30.200.123]) by pdx-korg-patchwork-2.web.codeaurora.org (Postfix) with ESMTP id 7194513B4 for ; Mon, 6 Jul 2020 13:21:29 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id 5976C20715 for ; Mon, 6 Jul 2020 13:21:29 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (1024-bit key) header.d=mediatek.com header.i=@mediatek.com header.b="Z7mlhbDj" Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1729197AbgGFNVZ (ORCPT ); Mon, 6 Jul 2020 09:21:25 -0400 Received: from mailgw02.mediatek.com ([210.61.82.184]:39178 "EHLO mailgw02.mediatek.com" rhost-flags-OK-FAIL-OK-FAIL) by vger.kernel.org with ESMTP id S1729115AbgGFNVZ (ORCPT ); Mon, 6 Jul 2020 09:21:25 -0400 X-UUID: b13fd27570944096b1cf0dedc847be4b-20200706 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=mediatek.com; s=dk; h=Content-Transfer-Encoding:Content-Type:MIME-Version:Message-ID:Date:Subject:CC:To:From; bh=JEKKXzqAAcN0UvZo8mMJzoVz8sWVLl6w/CEmyd3ob10=; b=Z7mlhbDj7PETj/GJWWRzSgi0r12CgWLpcAsE1nDMfqydOA/CezKOq+YsV2A6SMjjcrfu5ob/vGcHgwn1JVG7qjCOVSfbO27EnB1fzNSP/r0E12ZzbDMlwHt3ZjqII9CZB0yMA3AKH7kk31CKUXEGvCwxsf39fHYiWJrJ5RQTmks=; X-UUID: b13fd27570944096b1cf0dedc847be4b-20200706 Received: from mtkexhb02.mediatek.inc [(172.21.101.103)] by mailgw02.mediatek.com (envelope-from ) (Cellopoint E-mail Firewall v4.1.10 Build 0809 with TLS) with ESMTP id 1590028650; Mon, 06 Jul 2020 21:21:22 +0800 Received: from MTKCAS06.mediatek.inc (172.21.101.30) by mtkmbs02n2.mediatek.inc (172.21.101.101) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 6 Jul 2020 21:21:16 +0800 Received: from mtksdccf07.mediatek.inc (172.21.84.99) by MTKCAS06.mediatek.inc (172.21.101.73) with Microsoft SMTP Server id 15.0.1497.2 via Frontend Transport; Mon, 6 Jul 2020 21:21:10 +0800 From: Stanley Chu To: , , , , , CC: , , , , , , , , , , , , , Stanley Chu Subject: [PATCH v3] scsi: ufs: Cleanup completed request without interrupt notification Date: Mon, 6 Jul 2020 21:21:13 +0800 Message-ID: <20200706132113.21096-1-stanley.chu@mediatek.com> X-Mailer: git-send-email 2.18.0 MIME-Version: 1.0 X-TM-SNTS-SMTP: ACCDC8000567A9642C17428D46DC7631AE2F5179EBF4FB271AB3B227D089DFBA2000:8 X-MTK: N Sender: linux-scsi-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-scsi@vger.kernel.org If somehow no interrupt notification is raised for a completed request and its doorbell bit is cleared by host, UFS driver needs to cleanup its outstanding bit in ufshcd_abort(). Otherwise, system may crash by below abnormal flow: After this request is requeued by SCSI layer with its outstanding bit set, the next completed request will trigger ufshcd_transfer_req_compl() to handle all "completed outstanding bits". In this time, the "abnormal outstanding bit" will be detected and the "requeued request" will be chosen to execute request post-processing flow. This is wrong and blk_finish_request() will BUG_ON because this request is still "alive". It is worth mentioning that before ufshcd_abort() cleans the timed-out request, driver need to check again if this request is really not handled by __ufshcd_transfer_req_compl() yet because it may be possible that the interrupt comes very lately before the cleaning. Signed-off-by: Stanley Chu --- drivers/scsi/ufs/ufshcd.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/drivers/scsi/ufs/ufshcd.c b/drivers/scsi/ufs/ufshcd.c index 8603b07045a6..f23fb14df9f6 100644 --- a/drivers/scsi/ufs/ufshcd.c +++ b/drivers/scsi/ufs/ufshcd.c @@ -6462,7 +6462,7 @@ static int ufshcd_abort(struct scsi_cmnd *cmd) /* command completed already */ dev_err(hba->dev, "%s: cmd at tag %d successfully cleared from DB.\n", __func__, tag); - goto out; + goto cleanup; } else { dev_err(hba->dev, "%s: no response from device. tag = %d, err %d\n", @@ -6496,9 +6496,14 @@ static int ufshcd_abort(struct scsi_cmnd *cmd) goto out; } +cleanup: + spin_lock_irqsave(host->host_lock, flags); + if (!test_bit(tag, &hba->outstanding_reqs)) { + spin_unlock_irqrestore(host->host_lock, flags); + goto out; + } scsi_dma_unmap(cmd); - spin_lock_irqsave(host->host_lock, flags); ufshcd_outstanding_req_clear(hba, tag); hba->lrb[tag].cmd = NULL; spin_unlock_irqrestore(host->host_lock, flags);