From patchwork Sun Dec 20 13:20:40 2015 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Fengwei Yin X-Patchwork-Id: 7892171 X-Patchwork-Delegate: kvalo@adurom.com Return-Path: X-Original-To: patchwork-linux-wireless@patchwork.kernel.org Delivered-To: patchwork-parsemail@patchwork2.web.kernel.org Received: from mail.kernel.org (mail.kernel.org [198.145.29.136]) by patchwork2.web.kernel.org (Postfix) with ESMTP id E79A7BEEE5 for ; Sun, 20 Dec 2015 13:25:56 +0000 (UTC) Received: from mail.kernel.org (localhost [127.0.0.1]) by mail.kernel.org (Postfix) with ESMTP id 107CC20481 for ; Sun, 20 Dec 2015 13:25:56 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id 1F09C2047D for ; Sun, 20 Dec 2015 13:25:55 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S932563AbbLTNZx (ORCPT ); Sun, 20 Dec 2015 08:25:53 -0500 Received: from mail-pa0-f44.google.com ([209.85.220.44]:34599 "EHLO mail-pa0-f44.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S932352AbbLTNZw (ORCPT ); Sun, 20 Dec 2015 08:25:52 -0500 Received: by mail-pa0-f44.google.com with SMTP id wq6so85376720pac.1 for ; Sun, 20 Dec 2015 05:25:52 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=6AaBctq4CDswOHSS54sFEidotrU4AsIP6Gwph4irA+k=; b=chHpB+dtZGYsEdy0kxpAj3JKrD87/t9T0Nekv0l1ZkoK6ddL/mgaJ0flWT03/lvmu9 9fBdl+hLEcSPF12j93fzf3ZHjiyIRgKRsI8cUoyDDYSiMPR6rO8yKvagwTwSNk9lXeiY 00wZ8EsrNe5w1kxeLW2YB8LrNFM/D9gdxBZcg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=6AaBctq4CDswOHSS54sFEidotrU4AsIP6Gwph4irA+k=; b=ThuoHOyQJYdPHtWy6oA2S2+2iIeLaERnwJ4wF1yl9TYHyTWSimv6MR/EBOHX/pAvNz P3Hkt2iRuhWJiZH2crwNwrOrls4Qth9ZTPZ8jJI3GyPDOchphTa2UminhzHiKOa+OWAB cFdg309A8e2NuWkbqBoHLnV5D+1pmrJgu9mC6jdCC7RZNDBKSP3Tm1l4RjeC0169R0JV aBgEnIUUhQ4DanVx1dkoqz4BjG1MF+cHRYb/hVSCTqAxb7WNVoqlH6rwwSGp2DkTKBla vw+EH6n6gN6gjdgctfJ4wS7M6dbIXrpogfqBaloFSD6fux8jFBcz0+/e72Hh65dpcHju MFOQ== X-Gm-Message-State: ALoCoQnNKQXFaW/JYFxQu7bU9vixfrIgT1QXkde0DXI0DbYILiE+VrNfdKXaXp8J58SzyISCG8XxMZd7358n4Cxh2MlriPs55g== X-Received: by 10.66.190.98 with SMTP id gp2mr19579966pac.64.1450617952362; Sun, 20 Dec 2015 05:25:52 -0800 (PST) Received: from localhost.localdomain ([45.116.12.36]) by smtp.googlemail.com with ESMTPSA id q193sm13489151pfq.28.2015.12.20.05.25.49 (version=TLSv1/SSLv3 cipher=OTHER); Sun, 20 Dec 2015 05:25:51 -0800 (PST) From: Fengwei Yin To: julian.calaby@gmail.com, linux-wireless@vger.kernel.org, wcn36xx@lists.infradead.org, me@bobcopeland.com, k.eugene.e@gmail.com, bjorn.andersson@sonymobile.com Cc: fengwei.yin@linaro.org, lking@qti.qualcomm.com Subject: [PATCH v3 1/2] wcn36xx: handle rx skb allocation failure to avoid system crash Date: Sun, 20 Dec 2015 21:20:40 +0800 Message-Id: <1450617641-29531-2-git-send-email-fengwei.yin@linaro.org> X-Mailer: git-send-email 2.1.4 In-Reply-To: <1450617641-29531-1-git-send-email-fengwei.yin@linaro.org> References: <1450617641-29531-1-git-send-email-fengwei.yin@linaro.org> Sender: linux-wireless-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org X-Spam-Status: No, score=-6.8 required=5.0 tests=BAYES_00,DKIM_SIGNED, RCVD_IN_DNSWL_HI,RP_MATCHES_RCVD,T_DKIM_INVALID,UNPARSEABLE_RELAY autolearn=ham version=3.3.1 X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on mail.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP Lawrence reported that git clone could make system crash on a Qualcomm ARM soc based device (DragonBoard, 1G memory without swap) running 64bit Debian. It's turned out the crash is related with rx skb allocation failure. git could consume more than 600MB anonymous memory. And system is in extremely memory shortage case. But driver didn't handle the rx allocation failure case. This patch doesn't submit skb to upper layer if rx skb allocation fails. Instead, it reuse the old skb for rx DMA again. It's more like drop the packets if system is in memory shortage case. With this change, git clone is OOMed instead of system crash. Reported-by: King, Lawrence Signed-off-by: Fengwei Yin --- drivers/net/wireless/ath/wcn36xx/dxe.c | 43 +++++++++++++++++----------------- 1 file changed, 22 insertions(+), 21 deletions(-) diff --git a/drivers/net/wireless/ath/wcn36xx/dxe.c b/drivers/net/wireless/ath/wcn36xx/dxe.c index f8dfa05..473381f 100644 --- a/drivers/net/wireless/ath/wcn36xx/dxe.c +++ b/drivers/net/wireless/ath/wcn36xx/dxe.c @@ -474,36 +474,37 @@ static int wcn36xx_rx_handle_packets(struct wcn36xx *wcn, struct wcn36xx_dxe_desc *dxe = ctl->desc; dma_addr_t dma_addr; struct sk_buff *skb; + int ret = 0, int_mask; + u32 value; + + if (ch->ch_type == WCN36XX_DXE_CH_RX_L) { + value = WCN36XX_DXE_CTRL_RX_L; + int_mask = WCN36XX_DXE_INT_CH1_MASK; + } else { + value = WCN36XX_DXE_CTRL_RX_H; + int_mask = WCN36XX_DXE_INT_CH3_MASK; + } while (!(dxe->ctrl & WCN36XX_DXE_CTRL_VALID_MASK)) { skb = ctl->skb; dma_addr = dxe->dst_addr_l; - wcn36xx_dxe_fill_skb(wcn->dev, ctl); - - switch (ch->ch_type) { - case WCN36XX_DXE_CH_RX_L: - dxe->ctrl = WCN36XX_DXE_CTRL_RX_L; - wcn36xx_dxe_write_register(wcn, WCN36XX_DXE_ENCH_ADDR, - WCN36XX_DXE_INT_CH1_MASK); - break; - case WCN36XX_DXE_CH_RX_H: - dxe->ctrl = WCN36XX_DXE_CTRL_RX_H; - wcn36xx_dxe_write_register(wcn, WCN36XX_DXE_ENCH_ADDR, - WCN36XX_DXE_INT_CH3_MASK); - break; - default: - wcn36xx_warn("Unknown channel\n"); - } - - dma_unmap_single(wcn->dev, dma_addr, WCN36XX_PKT_SIZE, - DMA_FROM_DEVICE); - wcn36xx_rx_skb(wcn, skb); + ret = wcn36xx_dxe_fill_skb(wcn->dev, ctl); + if (0 == ret) { + /* new skb allocation ok. Use the new one and queue + * the old one to network system. + */ + dma_unmap_single(wcn->dev, dma_addr, WCN36XX_PKT_SIZE, + DMA_FROM_DEVICE); + wcn36xx_rx_skb(wcn, skb); + } /* else keep old skb not submitted and use it for rx DMA */ + + wcn36xx_dxe_write_register(wcn, WCN36XX_DXE_ENCH_ADDR, int_mask); + dxe->ctrl = value; ctl = ctl->next; dxe = ctl->desc; } ch->head_blk_ctl = ctl; - return 0; }