nvme-pci: Remap CMB SQ entries on every controller reset

"Linux Kernel Mailing List" <[email protected]> Sat, 17 Feb 2018 19:17:15 +0000 (UTC)
Newsgroups gmane.linux.kernel.commits.head
Message-ID <[email protected]>
Web:        https://git.kernel.org/torvalds/c/815c6704bf9f1c59f3a6be380a4032b9c57b12f1
Commit:     815c6704bf9f1c59f3a6be380a4032b9c57b12f1
Parent:     3fd176b754e992e1cdf1693ea8184626d1ed7671
Refname:    refs/heads/master
Author:     Keith Busch <[email protected]>
AuthorDate: Tue Feb 13 05:44:44 2018 -0700
Committer:  Keith Busch <[email protected]>
CommitDate: Tue Feb 13 17:09:50 2018 -0700

    nvme-pci: Remap CMB SQ entries on every controller reset
    
    The controller memory buffer is remapped into a kernel address on each
    reset, but the driver was setting the submission queue base address
    only on the very first queue creation. The remapped address is likely to
    change after a reset, so accessing the old address will hit a kernel bug.
    
    This patch fixes that by setting the queue's CMB base address each time
    the queue is created.
    
    Fixes: f63572dff1421 ("nvme: unmap CMB and remove sysfs file in reset path")
    Reported-by: Christian Black <[email protected]>
    Cc: Jon Derrick <[email protected]>
    Cc: <[email protected]> # 4.9+
    Signed-off-by: Keith Busch <[email protected]>
    Reviewed-by: Christoph Hellwig <[email protected]>
---
 drivers/nvme/host/pci.c | 25 ++++++++++++++-----------
 1 file changed, 14 insertions(+), 11 deletions(-)

diff --git a/drivers/nvme/host/pci.c b/drivers/nvme/host/pci.c
index ab9c19525fa8..b427157af74e 100644
--- a/drivers/nvme/host/pci.c
+++ b/drivers/nvme/host/pci.c
@@ -1364,18 +1364,14 @@ static int nvme_cmb_qdepth(struct nvme_dev *dev, int nr_io_queues,
 static int nvme_alloc_sq_cmds(struct nvme_dev *dev, struct nvme_queue *nvmeq,
 				int qid, int depth)
 {
-	if (qid && dev->cmb && use_cmb_sqes && (dev->cmbsz & NVME_CMBSZ_SQS)) {
-		unsigned offset = (qid - 1) * roundup(SQ_SIZE(depth),
-						      dev->ctrl.page_size);
-		nvmeq->sq_dma_addr = dev->cmb_bus_addr + offset;
-		nvmeq->sq_cmds_io = dev->cmb + offset;
-	} else {
-		nvmeq->sq_cmds = dma_alloc_coherent(dev->dev, SQ_SIZE(depth),
-					&nvmeq->sq_dma_addr, GFP_KERNEL);
-		if (!nvmeq->sq_cmds)
-			return -ENOMEM;
-	}
+	/* CMB SQEs will be mapped before creation */
+	if (qid && dev->cmb && use_cmb_sqes && (dev->cmbsz & NVME_CMBSZ_SQS))
+		return 0;
 
+	nvmeq->sq_cmds = dma_alloc_coherent(dev->dev, SQ_SIZE(depth),
+					    &nvmeq->sq_dma_addr, GFP_KERNEL);
+	if (!nvmeq->sq_cmds)
+		return -ENOMEM;
 	return 0;
 }
 
@@ -1449,6 +1445,13 @@ static int nvme_create_queue(struct nvme_queue *nvmeq, int qid)
 	struct nvme_dev *dev = nvmeq->dev;
 	int result;
 
+	if (dev->cmb && use_cmb_sqes && (dev->cmbsz & NVME_CMBSZ_SQS)) {
+		unsigned offset = (qid - 1) * roundup(SQ_SIZE(nvmeq->q_depth),
+						      dev->ctrl.page_size);
+		nvmeq->sq_dma_addr = dev->cmb_bus_addr + offset;
+		nvmeq->sq_cmds_io = dev->cmb + offset;
+	}
+
 	nvmeq->cq_vector = qid - 1;
 	result = adapter_alloc_cq(dev, qid, nvmeq);
 	if (result < 0)
--
To unsubscribe from this list: send the line "unsubscribe git-commits-head" in
the body of a message to [email protected]
More majordomo info at  http://vger.kernel.org/majordomo-info.html