From patchwork Mon Sep 11 06:56:06 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Alexey Kardashevskiy X-Patchwork-Id: 812230 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (mailfrom) smtp.mailfrom=nongnu.org (client-ip=2001:4830:134:3::11; helo=lists.gnu.org; envelope-from=qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org; receiver=) Received: from lists.gnu.org (lists.gnu.org [IPv6:2001:4830:134:3::11]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 3xrJdS39JPz9s2G for ; Mon, 11 Sep 2017 16:57:15 +1000 (AEST) Received: from localhost ([::1]:55738 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1drIec-0006WG-LU for incoming@patchwork.ozlabs.org; Mon, 11 Sep 2017 02:57:10 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:60628) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1drIeE-0006Vv-0n for qemu-devel@nongnu.org; Mon, 11 Sep 2017 02:56:47 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1drIeA-0007Ds-1o for qemu-devel@nongnu.org; Mon, 11 Sep 2017 02:56:46 -0400 Received: from ozlabs.ru ([107.173.13.209]:46606) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1drIe9-0007Dg-Rr for qemu-devel@nongnu.org; Mon, 11 Sep 2017 02:56:41 -0400 Received: from vpl1.ozlabs.ibm.com (localhost [IPv6:::1]) by ozlabs.ru (Postfix) with ESMTP id 1E1EA3A60001; Mon, 11 Sep 2017 02:57:21 -0400 (EDT) From: Alexey Kardashevskiy To: qemu-devel@nongnu.org Date: Mon, 11 Sep 2017 16:56:06 +1000 Message-Id: <20170911065606.40600-1-aik@ozlabs.ru> X-Mailer: git-send-email 2.11.0 X-detected-operating-system: by eggs.gnu.org: GNU/Linux 3.x [fuzzy] X-Received-From: 107.173.13.209 Subject: [Qemu-devel] [PATCH qemu] xhci: Avoid DMA when ERSTBA is set to zero X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Alexey Kardashevskiy , Gerd Hoffmann Errors-To: qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org Sender: "Qemu-devel" The existing XHCI code reads the Event Ring Segment Table Base Address Register (ERSTBA) every time when it is changed. However zero is its default state so one would think that zero there means it is not in use. This adds a check for ERSTBA in addition to the existing check for the Event Ring Segment Table Size Register (ERSTSZ). Signed-off-by: Alexey Kardashevskiy --- On pseries, the SLOF firmware initializes XHCI and sets non-zero value to ERSTBA. Then, it jumps to the guest and the guest requests the SLOF to quiesce devices, that includes XHCI. SLOF removes DMA mappings and writes 0 to ERSTBA, writing to its high part triggers xhci_er_reset() in QEMU which calls pci_dma_read(PCI_DEVICE(xhci), erstba,...) which ends up in unassigned_mem_accepts as IOMMU translation entry for 0 is missing (and it is missing always on pseries, at least in practice). However the very same SLOF driver does not cause EEH (that would be hardware reaction on missing IOMMU translation entry) on the real POWER8 system with "Texas Instruments TUSB73x0 SuperSpeed USB 3.0 xHCI Host Controller" passed via VFIO which made me think that this patch is a useful thing to have anyway as this is what the hardware does, i.e. tolerates some misconfiguration. And yes, we will fix SLOF to reset ERSTSZ in addition to ERSTBA anyway. The XHCI spec, just in case: https://www.intel.com.au/content/dam/www/public/us/en/documents/technical-specifications/extensible-host-controler-interface-usb-xhci.pdf --- hw/usb/hcd-xhci.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/hw/usb/hcd-xhci.c b/hw/usb/hcd-xhci.c index 204ea69d3f..d75c085d94 100644 --- a/hw/usb/hcd-xhci.c +++ b/hw/usb/hcd-xhci.c @@ -811,8 +811,9 @@ static void xhci_er_reset(XHCIState *xhci, int v) { XHCIInterrupter *intr = &xhci->intr[v]; XHCIEvRingSeg seg; + dma_addr_t erstba = xhci_addr64(intr->erstba_low, intr->erstba_high); - if (intr->erstsz == 0) { + if (intr->erstsz == 0 || erstba == 0) { /* disabled */ intr->er_start = 0; intr->er_size = 0; @@ -824,7 +825,6 @@ static void xhci_er_reset(XHCIState *xhci, int v) xhci_die(xhci); return; } - dma_addr_t erstba = xhci_addr64(intr->erstba_low, intr->erstba_high); pci_dma_read(PCI_DEVICE(xhci), erstba, &seg, sizeof(seg)); le32_to_cpus(&seg.addr_low); le32_to_cpus(&seg.addr_high);