Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux
1
fork

Configure Feed

Select the types of activity you want to include in your feed.

powerpc/4xx: Fix error return path in ppc4xx_msi_probe()

An arbitrary error in ppc4xx_msi_probe() quite likely results in a
crash similar to the following, seen after dma_alloc_coherent()
returned an error.

Unable to handle kernel paging request for data at address 0x00000000
Faulting instruction address: 0xc001bff0
Oops: Kernel access of bad area, sig: 11 [#1]
BE Canyonlands
Modules linked in:
CPU: 0 PID: 1 Comm: swapper Tainted: G W
4.18.0-rc6-00010-gff33d1030a6c #1
NIP: c001bff0 LR: c001c418 CTR: c01faa7c
REGS: cf82db40 TRAP: 0300 Tainted: G W
(4.18.0-rc6-00010-gff33d1030a6c)
MSR: 00029000 <CE,EE,ME> CR: 28002024 XER: 00000000
DEAR: 00000000 ESR: 00000000
GPR00: c001c418 cf82dbf0 cf828000 cf8de400 00000000 00000000 000000c4 000000c4
GPR08: c0481ea4 00000000 00000000 000000c4 22002024 00000000 c00025e8 00000000
GPR16: 00000000 00000000 00000000 00000000 00000000 00000000 c0492380 0000004a
GPR24: 00029000 0000000c 00000000 cf8de410 c0494d60 c0494d60 cf8bebc0 00000001
NIP [c001bff0] ppc4xx_of_msi_remove+0x48/0xa0
LR [c001c418] ppc4xx_msi_probe+0x294/0x3b8
Call Trace:
[cf82dbf0] [00029000] 0x29000 (unreliable)
[cf82dc10] [c001c418] ppc4xx_msi_probe+0x294/0x3b8
[cf82dc70] [c0209fbc] platform_drv_probe+0x40/0x9c
[cf82dc90] [c0208240] driver_probe_device+0x2a8/0x350
[cf82dcc0] [c0206204] bus_for_each_drv+0x60/0xac
[cf82dcf0] [c0207e88] __device_attach+0xe8/0x160
[cf82dd20] [c02071e0] bus_probe_device+0xa0/0xbc
[cf82dd40] [c02050c8] device_add+0x404/0x5c4
[cf82dd90] [c0288978] of_platform_device_create_pdata+0x88/0xd8
[cf82ddb0] [c0288b70] of_platform_bus_create+0x134/0x220
[cf82de10] [c0288bcc] of_platform_bus_create+0x190/0x220
[cf82de70] [c0288cf4] of_platform_bus_probe+0x98/0xec
[cf82de90] [c0449650] __machine_initcall_canyonlands_ppc460ex_device_probe+0x38/0x54
[cf82dea0] [c0002404] do_one_initcall+0x40/0x188
[cf82df00] [c043daec] kernel_init_freeable+0x130/0x1d0
[cf82df30] [c0002600] kernel_init+0x18/0x104
[cf82df40] [c000c23c] ret_from_kernel_thread+0x14/0x1c
Instruction dump:
90010024 813d0024 2f890000 83c30058 41bd0014 48000038 813d0024 7f89f800
409d002c 813e000c 57ea103a 3bff0001 <7c69502e> 2f830000 419effe0 4803b26d
---[ end trace 8cf551077ecfc42a ]---

Fix it up. Specifically,

- Return valid error codes from ppc4xx_setup_pcieh_hw(), have it clean
up after itself, and only access hardware after all possible error
conditions have been handled.
- Use devm_kzalloc() instead of kzalloc() in ppc4xx_msi_probe()

Signed-off-by: Guenter Roeck <linux@roeck-us.net>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>

authored by

Guenter Roeck and committed by
Michael Ellerman
6e0495c2 3127692d

+30 -21
+30 -21
arch/powerpc/platforms/4xx/msi.c
··· 146 146 const u32 *sdr_addr; 147 147 dma_addr_t msi_phys; 148 148 void *msi_virt; 149 + int err; 149 150 150 151 sdr_addr = of_get_property(dev->dev.of_node, "sdr-base", NULL); 151 152 if (!sdr_addr) 152 - return -1; 153 + return -EINVAL; 153 154 154 - mtdcri(SDR0, *sdr_addr, upper_32_bits(res.start)); /*HIGH addr */ 155 - mtdcri(SDR0, *sdr_addr + 1, lower_32_bits(res.start)); /* Low addr */ 155 + msi_data = of_get_property(dev->dev.of_node, "msi-data", NULL); 156 + if (!msi_data) 157 + return -EINVAL; 158 + 159 + msi_mask = of_get_property(dev->dev.of_node, "msi-mask", NULL); 160 + if (!msi_mask) 161 + return -EINVAL; 156 162 157 163 msi->msi_dev = of_find_node_by_name(NULL, "ppc4xx-msi"); 158 164 if (!msi->msi_dev) ··· 166 160 167 161 msi->msi_regs = of_iomap(msi->msi_dev, 0); 168 162 if (!msi->msi_regs) { 169 - dev_err(&dev->dev, "of_iomap problem failed\n"); 170 - return -ENOMEM; 163 + dev_err(&dev->dev, "of_iomap failed\n"); 164 + err = -ENOMEM; 165 + goto node_put; 171 166 } 172 167 dev_dbg(&dev->dev, "PCIE-MSI: msi register mapped 0x%x 0x%x\n", 173 168 (u32) (msi->msi_regs + PEIH_TERMADH), (u32) (msi->msi_regs)); 174 169 175 170 msi_virt = dma_alloc_coherent(&dev->dev, 64, &msi_phys, GFP_KERNEL); 176 - if (!msi_virt) 177 - return -ENOMEM; 171 + if (!msi_virt) { 172 + err = -ENOMEM; 173 + goto iounmap; 174 + } 178 175 msi->msi_addr_hi = upper_32_bits(msi_phys); 179 176 msi->msi_addr_lo = lower_32_bits(msi_phys & 0xffffffff); 180 177 dev_dbg(&dev->dev, "PCIE-MSI: msi address high 0x%x, low 0x%x\n", 181 178 msi->msi_addr_hi, msi->msi_addr_lo); 182 179 180 + mtdcri(SDR0, *sdr_addr, upper_32_bits(res.start)); /*HIGH addr */ 181 + mtdcri(SDR0, *sdr_addr + 1, lower_32_bits(res.start)); /* Low addr */ 182 + 183 183 /* Progam the Interrupt handler Termination addr registers */ 184 184 out_be32(msi->msi_regs + PEIH_TERMADH, msi->msi_addr_hi); 185 185 out_be32(msi->msi_regs + PEIH_TERMADL, msi->msi_addr_lo); 186 186 187 - msi_data = of_get_property(dev->dev.of_node, "msi-data", NULL); 188 - if (!msi_data) 189 - return -1; 190 - msi_mask = of_get_property(dev->dev.of_node, "msi-mask", NULL); 191 - if (!msi_mask) 192 - return -1; 193 187 /* Program MSI Expected data and Mask bits */ 194 188 out_be32(msi->msi_regs + PEIH_MSIED, *msi_data); 195 189 out_be32(msi->msi_regs + PEIH_MSIMK, *msi_mask); ··· 197 191 dma_free_coherent(&dev->dev, 64, msi_virt, msi_phys); 198 192 199 193 return 0; 194 + 195 + iounmap: 196 + iounmap(msi->msi_regs); 197 + node_put: 198 + of_node_put(msi->msi_dev); 199 + return err; 200 200 } 201 201 202 202 static int ppc4xx_of_msi_remove(struct platform_device *dev) ··· 221 209 msi_bitmap_free(&msi->bitmap); 222 210 iounmap(msi->msi_regs); 223 211 of_node_put(msi->msi_dev); 224 - kfree(msi); 225 212 226 213 return 0; 227 214 } ··· 234 223 235 224 dev_dbg(&dev->dev, "PCIE-MSI: Setting up MSI support...\n"); 236 225 237 - msi = kzalloc(sizeof(*msi), GFP_KERNEL); 238 - if (!msi) { 239 - dev_err(&dev->dev, "No memory for MSI structure\n"); 226 + msi = devm_kzalloc(&dev->dev, sizeof(*msi), GFP_KERNEL); 227 + if (!msi) 240 228 return -ENOMEM; 241 - } 242 229 dev->dev.platform_data = msi; 243 230 244 231 /* Get MSI ranges */ 245 232 err = of_address_to_resource(dev->dev.of_node, 0, &res); 246 233 if (err) { 247 234 dev_err(&dev->dev, "%pOF resource error!\n", dev->dev.of_node); 248 - goto error_out; 235 + return err; 249 236 } 250 237 251 238 msi_irqs = of_irq_count(dev->dev.of_node); ··· 252 243 253 244 err = ppc4xx_setup_pcieh_hw(dev, res, msi); 254 245 if (err) 255 - goto error_out; 246 + return err; 256 247 257 248 err = ppc4xx_msi_init_allocator(dev, msi); 258 249 if (err) { ··· 265 256 phb->controller_ops.setup_msi_irqs = ppc4xx_setup_msi_irqs; 266 257 phb->controller_ops.teardown_msi_irqs = ppc4xx_teardown_msi_irqs; 267 258 } 268 - return err; 259 + return 0; 269 260 270 261 error_out: 271 262 ppc4xx_of_msi_remove(dev);