This patch fixes below kernel crash on memory registration for rxe and other transport drivers which has dma_ops extension. IB/core invokes ib_map_sg_attrs() in generic manner with dma attributes which is used by mlx5 and mthca adapters. However in doing so it ignored honoring dma_ops extension of software based transports for sg map/unmap operation. This results in calling dma_map_sg_attrs of hardware virtual device resulting in crash for null reference. We extend the core to support sg_map/unmap_attrs and transport drivers to implement those dma_ops callback functions. Verified usign perftest applications. BUG: unable to handle kernel NULL pointer dereference at (null) IP: [<ffffffff81032a75>] check_addr+0x35/0x60 ... Call Trace: [<ffffffff81032b39>] ? nommu_map_sg+0x99/0xd0 [<ffffffffa02b31c6>] ib_umem_get+0x3d6/0x470 [ib_core] [<ffffffffa01cc329>] rxe_mem_init_user+0x49/0x270 [rdma_rxe] [<ffffffffa01c793a>] ? rxe_add_index+0xca/0x100 [rdma_rxe] [<ffffffffa01c995f>] rxe_reg_user_mr+0x9f/0x130 [rdma_rxe] [<ffffffffa00419fe>] ib_uverbs_reg_mr+0x14e/0x2c0 [ib_uverbs] [<ffffffffa003d3ab>] ib_uverbs_write+0x15b/0x3b0 [ib_uverbs] [<ffffffff811e92a6>] ? mem_cgroup_commit_charge+0x76/0xe0 [<ffffffff811af0a9>] ? page_add_new_anon_rmap+0x89/0xc0 [<ffffffff8117e6c9>] ? lru_cache_add_active_or_unevictable+0x39/0xc0 [<ffffffff811f0da8>] __vfs_write+0x28/0x120 [<ffffffff811f1239>] ? rw_verify_area+0x49/0xb0 [<ffffffff811f1492>] vfs_write+0xb2/0x1b0 [<ffffffff811f27d6>] SyS_write+0x46/0xa0 [<ffffffff814f7d32>] entry_SYSCALL_64_fastpath+0x1a/0xa4 Signed-off-by: Parav Pandit <pandit.parav@gmail.com> Signed-off-by: Doug Ledford <dledford@redhat.com>
202 lines
5.9 KiB
C
202 lines
5.9 KiB
C
/*
|
|
* Copyright(c) 2016 Intel Corporation.
|
|
*
|
|
* This file is provided under a dual BSD/GPLv2 license. When using or
|
|
* redistributing this file, you may do so under either license.
|
|
*
|
|
* GPL LICENSE SUMMARY
|
|
*
|
|
* This program is free software; you can redistribute it and/or modify
|
|
* it under the terms of version 2 of the GNU General Public License as
|
|
* published by the Free Software Foundation.
|
|
*
|
|
* This program is distributed in the hope that it will be useful, but
|
|
* WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
* General Public License for more details.
|
|
*
|
|
* BSD LICENSE
|
|
*
|
|
* Redistribution and use in source and binary forms, with or without
|
|
* modification, are permitted provided that the following conditions
|
|
* are met:
|
|
*
|
|
* - Redistributions of source code must retain the above copyright
|
|
* notice, this list of conditions and the following disclaimer.
|
|
* - Redistributions in binary form must reproduce the above copyright
|
|
* notice, this list of conditions and the following disclaimer in
|
|
* the documentation and/or other materials provided with the
|
|
* distribution.
|
|
* - Neither the name of Intel Corporation nor the names of its
|
|
* contributors may be used to endorse or promote products derived
|
|
* from this software without specific prior written permission.
|
|
*
|
|
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
|
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
|
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
|
|
* A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
|
|
* OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
|
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
|
|
* LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
|
|
* DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
|
|
* THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
|
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
|
|
* OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|
*
|
|
*/
|
|
#include <linux/types.h>
|
|
#include <linux/scatterlist.h>
|
|
#include <rdma/ib_verbs.h>
|
|
|
|
#include "dma.h"
|
|
|
|
#define BAD_DMA_ADDRESS ((u64)0)
|
|
|
|
/*
|
|
* The following functions implement driver specific replacements
|
|
* for the ib_dma_*() functions.
|
|
*
|
|
* These functions return kernel virtual addresses instead of
|
|
* device bus addresses since the driver uses the CPU to copy
|
|
* data instead of using hardware DMA.
|
|
*/
|
|
|
|
static int rvt_mapping_error(struct ib_device *dev, u64 dma_addr)
|
|
{
|
|
return dma_addr == BAD_DMA_ADDRESS;
|
|
}
|
|
|
|
static u64 rvt_dma_map_single(struct ib_device *dev, void *cpu_addr,
|
|
size_t size, enum dma_data_direction direction)
|
|
{
|
|
if (WARN_ON(!valid_dma_direction(direction)))
|
|
return BAD_DMA_ADDRESS;
|
|
|
|
return (u64)cpu_addr;
|
|
}
|
|
|
|
static void rvt_dma_unmap_single(struct ib_device *dev, u64 addr, size_t size,
|
|
enum dma_data_direction direction)
|
|
{
|
|
/* This is a stub, nothing to be done here */
|
|
}
|
|
|
|
static u64 rvt_dma_map_page(struct ib_device *dev, struct page *page,
|
|
unsigned long offset, size_t size,
|
|
enum dma_data_direction direction)
|
|
{
|
|
u64 addr;
|
|
|
|
if (WARN_ON(!valid_dma_direction(direction)))
|
|
return BAD_DMA_ADDRESS;
|
|
|
|
if (offset + size > PAGE_SIZE)
|
|
return BAD_DMA_ADDRESS;
|
|
|
|
addr = (u64)page_address(page);
|
|
if (addr)
|
|
addr += offset;
|
|
|
|
return addr;
|
|
}
|
|
|
|
static void rvt_dma_unmap_page(struct ib_device *dev, u64 addr, size_t size,
|
|
enum dma_data_direction direction)
|
|
{
|
|
/* This is a stub, nothing to be done here */
|
|
}
|
|
|
|
static int rvt_map_sg(struct ib_device *dev, struct scatterlist *sgl,
|
|
int nents, enum dma_data_direction direction)
|
|
{
|
|
struct scatterlist *sg;
|
|
u64 addr;
|
|
int i;
|
|
int ret = nents;
|
|
|
|
if (WARN_ON(!valid_dma_direction(direction)))
|
|
return 0;
|
|
|
|
for_each_sg(sgl, sg, nents, i) {
|
|
addr = (u64)page_address(sg_page(sg));
|
|
if (!addr) {
|
|
ret = 0;
|
|
break;
|
|
}
|
|
sg->dma_address = addr + sg->offset;
|
|
#ifdef CONFIG_NEED_SG_DMA_LENGTH
|
|
sg->dma_length = sg->length;
|
|
#endif
|
|
}
|
|
return ret;
|
|
}
|
|
|
|
static void rvt_unmap_sg(struct ib_device *dev,
|
|
struct scatterlist *sg, int nents,
|
|
enum dma_data_direction direction)
|
|
{
|
|
/* This is a stub, nothing to be done here */
|
|
}
|
|
|
|
static int rvt_map_sg_attrs(struct ib_device *dev, struct scatterlist *sgl,
|
|
int nents, enum dma_data_direction direction,
|
|
unsigned long attrs)
|
|
{
|
|
return rvt_map_sg(dev, sgl, nents, direction);
|
|
}
|
|
|
|
static void rvt_unmap_sg_attrs(struct ib_device *dev,
|
|
struct scatterlist *sg, int nents,
|
|
enum dma_data_direction direction,
|
|
unsigned long attrs)
|
|
{
|
|
return rvt_unmap_sg(dev, sg, nents, direction);
|
|
}
|
|
|
|
static void rvt_sync_single_for_cpu(struct ib_device *dev, u64 addr,
|
|
size_t size, enum dma_data_direction dir)
|
|
{
|
|
}
|
|
|
|
static void rvt_sync_single_for_device(struct ib_device *dev, u64 addr,
|
|
size_t size,
|
|
enum dma_data_direction dir)
|
|
{
|
|
}
|
|
|
|
static void *rvt_dma_alloc_coherent(struct ib_device *dev, size_t size,
|
|
u64 *dma_handle, gfp_t flag)
|
|
{
|
|
struct page *p;
|
|
void *addr = NULL;
|
|
|
|
p = alloc_pages(flag, get_order(size));
|
|
if (p)
|
|
addr = page_address(p);
|
|
if (dma_handle)
|
|
*dma_handle = (u64)addr;
|
|
return addr;
|
|
}
|
|
|
|
static void rvt_dma_free_coherent(struct ib_device *dev, size_t size,
|
|
void *cpu_addr, u64 dma_handle)
|
|
{
|
|
free_pages((unsigned long)cpu_addr, get_order(size));
|
|
}
|
|
|
|
struct ib_dma_mapping_ops rvt_default_dma_mapping_ops = {
|
|
.mapping_error = rvt_mapping_error,
|
|
.map_single = rvt_dma_map_single,
|
|
.unmap_single = rvt_dma_unmap_single,
|
|
.map_page = rvt_dma_map_page,
|
|
.unmap_page = rvt_dma_unmap_page,
|
|
.map_sg = rvt_map_sg,
|
|
.unmap_sg = rvt_unmap_sg,
|
|
.map_sg_attrs = rvt_map_sg_attrs,
|
|
.unmap_sg_attrs = rvt_unmap_sg_attrs,
|
|
.sync_single_for_cpu = rvt_sync_single_for_cpu,
|
|
.sync_single_for_device = rvt_sync_single_for_device,
|
|
.alloc_coherent = rvt_dma_alloc_coherent,
|
|
.free_coherent = rvt_dma_free_coherent
|
|
};
|