From nobody Fri Oct 2 08:28:23 2026 Received: from smtp-relay-internal-0.canonical.com (smtp-relay-internal-0.canonical.com [185.125.188.122]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3309840B11C for ; Mon, 3 Aug 2026 15:29:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=185.125.188.122 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785770986; cv=none; b=j6cP5nJcYdiu1+KHBB0kwmp53qIkeT9woVEqww01l0vBHzhI/a2ggJpl5YvfZ/8GwgdOxiIhwNNX4JZfuIKcnlEhFM7/AhK6/lqgoEX8jSTwClBUn3cLHazvoYdBT+/SBJ9wRmcZTjDI3QYpmWaWiPrSnryyF47EfQMroIGC6gE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785770986; c=relaxed/simple; bh=4hrz0/APa3JBtVoKpaRyKHP4waUwTsL85ZWg+fWw8Tw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=I7w00BSPcAs/uf1gnPoKQZHj5VQ1/NcUxbt6G8gXmJ+yPJpJGeuwZpQRYSu3An1IQw+9ULlpe0Tm6jEEyebm5xitwJPzpL512tSevyzEqGkS/rWupt9vTHBqghayCwx2kaP8jYwsjXFq8i0z3Mn1fgNXkMc43hmFQD7Ucdpaej0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=canonical.com; spf=pass smtp.mailfrom=canonical.com; dkim=pass (4096-bit key) header.d=canonical.com header.i=@canonical.com header.b=ZGd5peLd; arc=none smtp.client-ip=185.125.188.122 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=canonical.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=canonical.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (4096-bit key) header.d=canonical.com header.i=@canonical.com header.b="ZGd5peLd" Received: from mail-qt1-f200.google.com (mail-qt1-f200.google.com [209.85.160.200]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by smtp-relay-internal-0.canonical.com (Postfix) with ESMTPS id 637D13F167 for ; Mon, 3 Aug 2026 15:29:35 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=canonical.com; s=20251003; t=1785770975; bh=1wA9zD8wavSvGOW0aSs81qe/j2d+7UbxR14kkq6ItL8=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=ZGd5peLdWm0e9u16tXHtV8FtoeAAYqEvWzGCQ9ghITeJ777HLBTb7/j4KJqkiNZND zAiqad6FVW5ERulAFxx59/F72nMp5MC6oKRmuUD+Qc+5AdDm8m9lz1ZyOJuvn011uv +JabZH9qi38Y5DdgK4xWrbamSipv8vNLuADrzL6BERnTZOT0pGiYHAy31wgo20LYHm AxaEjlaA1chHP2z4kU7d9pErJCEC9XSMfATB3G0l/KnhjcB7r7sXJcyYkWG9eYBEFH xZnd5LnV/fNPBw6Yny9bcvlcVlVmZKs5wQvrEr/+YR+PCAG6P4ciH0JlKoo45Mv9uQ K5vSUcndaz3yU8Ewoe75G+9cm4bKcaU1eq/WCqWLZGkyMnOGJ7Uw+6lcEUClYOE3o+ 3Z/k3oj/iC7tnOceilYRQucmt8wwzAIhlTkvRyMbA3D3CZMTfjzBwMX6R5Ww9qhFix NiIchs7pKGIbGZ/BSa1OuQcrvgg4fen5v6OKQERr55WkXjA7vcLIyCpvTDjzT3s97y RbZnGTNqF1imWbSc+DX5Knjf6IDvhN7V9SbdQPd+bXbafvJJH6gqyol5Zs8hdGVquI WL/hqJrSd66WqyrVDJCSMgtZ5TaD39iSnEzHwnkiNjuOADWd4uzMDHBhAiekFGMXi+ FVTnzINLqqKiSagrd1hk3BKk= Received: by mail-qt1-f200.google.com with SMTP id d75a77b69052e-51c083f1818so34995351cf.0 for ; Mon, 03 Aug 2026 08:29:35 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785770974; x=1786375774; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=1wA9zD8wavSvGOW0aSs81qe/j2d+7UbxR14kkq6ItL8=; b=mhbSb4ZGcolgYNpOIkyOZ59JZWSLZ6fiS7Vrv5y6v5ETZwCGBM8/of6wIPmgbAio7K yuX3B//hsoT7IDTmt56IqiIhNKmTkYzt5sZJzF0kI4+qO7KnicNXzh6ErVJKiZeY5OW6 TnL+s3QWEUx3Z7mwq9+uPoJuticwlRr+hleFwSqB9wSgXz3551lJfqNS3RAORFPXl7WG mvlihD/Si3sUqjcnVQoiC5Rdkw0x2ufT+H1DVsjTSl1UARPDaxfaAITw8mADhSTto2lv jmf8e7LnME1bEjOR9p7ZY9a3FmXrbuzd59bNiAdMXkM9oEHGbdxvImg0l+Et5ZUSz4wj J33Q== X-Forwarded-Encrypted: i=1; AHgh+RpQlE02yBZfF0gGn91VTL9A9SxDVvJ1VKfUgWaHP21v319O5e3gLz3FblqQYCve1zn9CsfakEqCxE68fTo=@vger.kernel.org X-Gm-Message-State: AOJu0YzNab3z3/vN4VWfk/FcwegtuvlR2nasDoRsnJl1nNb4rM7N45rO FxzJl5IR2DV9WhYQdyeR368JEV8bURS8tjR8YilAaCr4ZXwHASX1WWw1Hfi7iRmbwJoCPMPhjtW WZpCLlPTMmWS+0EhUldXCYzSRhkUPKkUAVaY0rG+S7lfHykgxFKnO0+u+triv+Dv0OXTzeWEAHM 1fRrggzw== X-Gm-Gg: AR+sD13jaGwcvz49ZtVxhGgqHGFN6V6mbpLQyhFE0I3eSwxxOvj/bAPpflaRfa3lF17 R2xlqbscoLN9EYm78Jvrch0YU9lLP72keeW0xDXheJ9Xnji5Q1usOGFYUua97p466MoEW1wkTMI eot0h3p5s1yMzy7fl1R/DWeCi1O6crgsr/Dnu5bO7sl5OONYedMz2gAc3XbdWqkwwJFugovGC4u c59vmyxIX4oHrxDmkRZ1DLE9SvfreRZuy3lQJIRU2TAVP/eB/CKQKdxSwqUQCRGHBOSR0vUQIWB hi7Ua2IXS1I4XiC1K3S/tWiKrPBv5VDAeUTTe4WWChXFBeOIdbXOmON1Fs4PKdLOFL7g4ViLH3J dxhMr7UaR X-Received: by 2002:ac8:5941:0:b0:516:d812:c35e with SMTP id d75a77b69052e-52b56752f32mr189669091cf.21.1785770974150; Mon, 03 Aug 2026 08:29:34 -0700 (PDT) X-Received: by 2002:ac8:5941:0:b0:516:d812:c35e with SMTP id d75a77b69052e-52b56752f32mr189668341cf.21.1785770973581; Mon, 03 Aug 2026 08:29:33 -0700 (PDT) Received: from atlas ([142.112.164.247]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52b4e7ee283sm63597211cf.6.2026.08.03.08.29.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 08:29:33 -0700 (PDT) From: Bryan Fraschetti To: Tony Nguyen , Przemek Kitszel , Andrew Lunn , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Alice Michael , Paul Greenwalt , Maciej Fijalkowski , Aleksandr Loktionov Cc: Bryan Fraschetti , intel-wired-lan@lists.osuosl.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH iwl] ice: Restore Ordered MMIO Writes for Tx Doorbells Date: Mon, 3 Aug 2026 11:28:52 -0400 Message-ID: <20260803152854.305298-1-bryan.fraschetti@canonical.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The DQL accounting state which tracks the number of bytes queued for the NIC to transmit, namely dql->num_queued, is updated by the ICE driver when it invokes __netdev_tx_sent_queue(). Subsequently the driver updates the hardware queue tail allowing the NIC to begin processing the work queue. The queue accounting update should be ordered before the NIC begins transmitting descriptors. The transmit path currently updates the hardware doorbell using writel_relaxed(), which (on arm64) does not provide the same ordering guarantees between writes to normal memory and writes to MMIO registers that writel() does. This introduces a potential race where the NIC begins transmitting descriptors before the dql->num_queued update is globally visible. If the NIC finishes before the update is observed by dql_completed(), it detects an invalid state where more bytes have been completed than have been queued. When this happens the following BUG_ON is triggered. BUG_ON(count > num_queued - dql->num_completed); This has been observed and manifests as the following crash (note that the trace has been trimmed) in an environment with sustained network load that uses an Intel Corporation Ethernet Controller E810-XXV for SFP (rev 02) on an arm64 machine. Replacing writel_relaxed() with writel() in a test kernel eliminated the crash in the user's workload, which previously reproduced the issue reliably. kernel BUG at lib/dynamic_queue_limits.c:99 Internal error: Oops - BUG: 00000000f2000800 [#1] SMP pc : dql_completed+0x268/0x2a0 lr : ice_clean_tx_irq+0x1d4/0x620 [ice] Call trace: dql_completed+0x268/0x2a0 (P) ice_napi_poll+0x94/0x520 [ice] __napi_poll+0x48/0x3f0 net_rx_action+0x194/0x420 This restores the behaviour prior to commit ccde82e90946 ("ice: add E830 Earliest TxTime First Offload support"), which changed the notification mechanism from writel() to writel_relaxed(). Link: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2161572 Fixes: ccde82e90946 ("ice: add E830 Earliest TxTime First Offload support") Signed-off-by: Bryan Fraschetti Tested-by: Alexander Nowlin --- drivers/net/ethernet/intel/ice/ice_txrx.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/net/ethernet/intel/ice/ice_txrx.c b/drivers/net/ethern= et/intel/ice/ice_txrx.c index c04c5856dad6..4e26ace793ec 100644 --- a/drivers/net/ethernet/intel/ice/ice_txrx.c +++ b/drivers/net/ethernet/intel/ice/ice_txrx.c @@ -1561,10 +1561,10 @@ ice_tx_map(struct ice_tx_ring *tx_ring, struct ice_= tx_buf *first, } } tstamp_ring->next_to_use =3D j; - writel_relaxed(j, tstamp_ring->tail); + writel(j, tstamp_ring->tail); } else { ring_kick: - writel_relaxed(i, tx_ring->tail); + writel(i, tx_ring->tail); } return; =20 --=20 2.53.0