Page MenuHomeFreeBSD

bnxt_en: dcb: serialize HWRM sends and avoid freeing DMA bufs on timeout
ClosedPublic

Authored by sumit.saxena_broadcom.com on Wed, Sep 30, 5:26 PM.
Tags
None
Referenced Files
F175276022: D60179.id189214.diff
Fri, Oct 9, 3:54 PM
F175273857: D60179.diff
Fri, Oct 9, 3:36 PM
F175265537: D60179.id.diff
Fri, Oct 9, 1:59 PM
F175265305: D60179.id189214.diff
Fri, Oct 9, 1:56 PM
F175265059: D60179.diff
Fri, Oct 9, 1:53 PM
F175183090: D60179.diff
Thu, Oct 8, 10:36 PM
F175165460: D60179.id188231.diff
Thu, Oct 8, 7:24 PM
Unknown Object (File)
Thu, Oct 8, 6:09 PM
Subscribers

Details

Summary

Every _hwrm_send_message() call in bnxt_dcb.c ran without BNXT_HWRM_LOCK,
unlike the rest of the driver, letting concurrent HWRM commands race on
the shared MMIO doorbell and response buffer. Route single-shot sends
through the already-locked hwrm_send_message() wrapper, and wrap the
remaining send+response-read sequences in explicit BNXT_HWRM_LOCK/UNLOCK.

Also stop freeing the transient DMA buffers used for structured-data
get/set on ETIMEDOUT: a host-side timeout doesn't guarantee firmware
actually gave up, so a late completion could still DMA into memory
that's since been freed and reused. Leak the buffer instead in that case.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable