Skip to content

Commit 09cfae9

Browse files
markusboehmedavem330
authored andcommitted
ixgbe: Fix packet corruption due to missing DMA sync
When receiving a packet with multiple fragments, hardware may still touch the first fragment until the entire packet has been received. The driver therefore keeps the first fragment mapped for DMA until end of packet has been asserted, and delays its dma_sync call until then. The driver tries to fit multiple receive buffers on one page. When using 3K receive buffers (e.g. using Jumbo frames and legacy-rx is turned off/build_skb is being used) on an architecture with 4K pages, the driver allocates an order 1 compound page and uses one page per receive buffer. To determine the correct offset for a delayed DMA sync of the first fragment of a multi-fragment packet, the driver then cannot just use PAGE_MASK on the DMA address but has to construct a mask based on the actual size of the backing page. Using PAGE_MASK in the 3K RX buffer/4K page architecture configuration will always sync the first page of a compound page. With the SWIOTLB enabled this can lead to corrupted packets (zeroed out first fragment, re-used garbage from another packet) and various consequences, such as slow/stalling data transfers and connection resets. For example, testing on a link with MTU exceeding 3058 bytes on a host with SWIOTLB enabled (e.g. "iommu=soft swiotlb=262144,force") TCP transfers quickly fizzle out without this patch. Cc: [email protected] Fixes: 0c5661e ("ixgbe: fix crash in build_skb Rx code path") Signed-off-by: Markus Boehme <[email protected]> Tested-by: Tony Brelinski <[email protected]> Signed-off-by: Tony Nguyen <[email protected]> Signed-off-by: David S. Miller <[email protected]>
1 parent 91bed55 commit 09cfae9

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

drivers/net/ethernet/intel/ixgbe/ixgbe_main.c

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1825,7 +1825,8 @@ static void ixgbe_dma_sync_frag(struct ixgbe_ring *rx_ring,
18251825
struct sk_buff *skb)
18261826
{
18271827
if (ring_uses_build_skb(rx_ring)) {
1828-
unsigned long offset = (unsigned long)(skb->data) & ~PAGE_MASK;
1828+
unsigned long mask = (unsigned long)ixgbe_rx_pg_size(rx_ring) - 1;
1829+
unsigned long offset = (unsigned long)(skb->data) & mask;
18291830

18301831
dma_sync_single_range_for_cpu(rx_ring->dev,
18311832
IXGBE_CB(skb)->dma,

0 commit comments

Comments
 (0)