On Sep 30 2026, at 12:41 pm, Frank Li <[email protected]> wrote:

> On Tue, Sep 29, 2026 at 03:43:39PM -0400,
> [email protected] wrote:
>> [You don't often get email from [email protected]. Learn
>> why this is important at
>> https://aka.ms/LearnAboutSenderIdentification ]
>> 
>> From: Jeff Barnes <[email protected]>
>> 
>> The Layerscape PCIe driver programs PCIE_ABSERR to forward errors from
>> outbound non-posted requests to the internal AXI interface.
>> 
>> A PCI configuration access can race with the link going down after
>> dw_pcie_other_conf_map_bus() checks the link but before the MMIO access
>> is performed. When the resulting Completion Timeout is forwarded to
>> AXI, it causes an asynchronous SError and kernel panic.
>> 
>> For example:
>> 
>>   Kernel panic - not syncing: Asynchronous SError Interrupt
>>   ...
>>   Call trace:
>>    arm64_serror_panic+0x78/0x90
>>    do_serror+0x84/0x90
>>    el1h_64_error_handler+0x30/0x40
>>    el1h_64_error+0x68/0x70
>>    pci_generic_config_read+0x64/0xb0
>>    dw_pcie_rd_other_conf+0x1c/0x68
>>    pci_bus_read_config_word+0x68/0x118
>>    pcie_capability_read_word+0xa8/0xd8
>>    find_device_iter+0x8c/0x160
>>    pci_walk_bus+0x60/0xb8
>>    find_source_device+0x78/0xb0
>>    aer_isr+0x1dc/0x230
>> 
>> Restore the controller's default error response behavior instead of
>> forwarding these errors to AXI.
>> 
>> Reproduce the race by instrumenting dw_pcie_rd_other_conf() to call
>> map_bus() while the link is up, then schedule a worker on another CPU
>> to set PCI_EXP_LNKCTL_LD. Synchronize the CPUs immediately before the
>> Link Disable DBI write, then perform readl() using the address returned
>> by map_bus() concurrently with the link transition.
>> 
>> Without this change, the overlapping configuration read results in an
>> asynchronous SError and kernel panic. With this change, the same test
>> returns 0xffffffff from the configuration read. In this test, AER
>> reports a non-fatal Completion Timeout, and no SError or kernel panic
>> occurs.
>> 
>> This effectively reverts the error response behavior introduced by
>> commit 84d897d69938
>> ("PCI: layerscape: Change default error response behavior").
> 
> Subject should be revert ...
> 
> I am not sure what's expect behavior by other dwc PCI controller. returns
> 0xfffffffff or report bus error.
> 
> Frank


Thanks, Frank.

Agreed on the subject. This is mechanically a revert of 84d897d69938, so
I'll change the subject to:
Revert "PCI: layerscape: Change default error response behavior"

Regarding the expected behavior on other DWC controllers, I don't have
hardware available to test those implementations, so I don't want to speculate.

What I have verified on Layerscape is that with PCIE_ABSERR programmed,
the failed configuration access is forwarded to AXI and results in an
asynchronous SError and kernel panic. With the controller's default
response, the identical injected race returns 0xffffffff and the kernel 
survives.

Please let me know if you think the behavior of other DWC
implementations needs to be established before proceeding with this revert.

Thanks, Jeff

> 
>> 
>> Fixes: 84d897d69938 ("PCI: layerscape: Change default error response 
>> behavior")
>> Cc: [email protected]
>> Signed-off-by: Jeff Barnes <[email protected]>
>> ---
>>  drivers/pci/controller/dwc/pci-layerscape.c | 12 ------------
>>  1 file changed, 12 deletions(-)
>> 
>> diff --git a/drivers/pci/controller/dwc/pci-layerscape.c 
>> b/drivers/pci/controller/dwc/pci-layerscape.c
>> index 14d6ac4fc53f..d333f1ae8a41 100644
>> --- a/drivers/pci/controller/dwc/pci-layerscape.c
>> +++ b/drivers/pci/controller/dwc/pci-layerscape.c
>> @@ -28,8 +28,6 @@
>> 
>>  /* PEX Internal Configuration Registers */
>>  #define PCIE_STRFMR1           0x71c /* Symbol Timer & Filter Mask
>> Register1 */
>> -#define PCIE_ABSERR            0x8d0 /* Bridge Slave Error Response
>> Register */
>> -#define PCIE_ABSERR_SETTING    0x9401 /* Forward error of non-posted
>> request */
>> 
>>  /* PF Message Command Register */
>>  #define LS_PCIE_PF_MCR         0x2c
>> @@ -103,14 +101,6 @@ static void ls_pcie_drop_msg_tlp(struct ls_pcie *pcie)
>>         iowrite32(val, pci->dbi_base + PCIE_STRFMR1);
>>  }
>> 
>> -/* Forward error response of outbound non-posted requests */
>> -static void ls_pcie_fix_error_response(struct ls_pcie *pcie)
>> -{
>> -       struct dw_pcie *pci = pcie->pci;
>> -
>> -       iowrite32(PCIE_ABSERR_SETTING, pci->dbi_base + PCIE_ABSERR);
>> -}
>> -
>>  static u32 ls_pcie_pf_lut_readl(struct ls_pcie *pcie, u32 off)
>>  {
>>         if (pcie->big_endian)
>> @@ -180,8 +170,6 @@ static int ls_pcie_host_init(struct dw_pcie_rp *pp)
>>         struct dw_pcie *pci = to_dw_pcie_from_pp(pp);
>>         struct ls_pcie *pcie = to_ls_pcie(pci);
>> 
>> -       ls_pcie_fix_error_response(pcie);
>> -
>>         dw_pcie_dbi_ro_wr_en(pci);
>>         ls_pcie_clear_multifunction(pcie);
>>         dw_pcie_dbi_ro_wr_dis(pci);
>> --
>> 2.43.0
>> 
>> 
> 

Reply via email to