summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorFan Ye <fy15309206903@gmail.com>2026-08-10 12:14:13 +0000
committerMika Westerberg <mika.westerberg@linux.intel.com>2026-08-11 05:57:59 +0200
commit86feaba911f2f1a540a7695c8f4a98fd0fd60ac4 (patch)
treeae97c0ecfe3da5f257a2b4bb14b62603d4ee1957
parente8158c8a6a232a70ae70c5acfaf7008a99b716c1 (diff)
downloadlinux-stable-86feaba911f2f1a540a7695c8f4a98fd0fd60ac4.tar.gz
linux-stable-86feaba911f2f1a540a7695c8f4a98fd0fd60ac4.zip
thunderbolt: Clamp DMA tunnel credits to what a hop register can hold
struct tb_regs_hop::initial_credits is 7 bits wide, but neither of the values tb_tunnel_alloc_dma() picks from is bounded by that: the dma_credits module parameter has no upper limit, and neither does the host router's baMaxHI. A larger count survives until tb_path_activate() copies it into the register and keeps the low bits, leaving the path on a credit count nobody asked for. Clamp it in tb_tunnel_alloc_dma(), the only entry point for DMA tunnels; every step below it can only lower the value further. Carry the count in an unsigned int while at it. Assisted-by: Claude:claude-opus-5 Signed-off-by: Fan Ye <fy15309206903@gmail.com> Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
-rw-r--r--drivers/thunderbolt/tunnel.c10
1 files changed, 9 insertions, 1 deletions
diff --git a/drivers/thunderbolt/tunnel.c b/drivers/thunderbolt/tunnel.c
index e9214de5f3b7..7e8284575dff 100644
--- a/drivers/thunderbolt/tunnel.c
+++ b/drivers/thunderbolt/tunnel.c
@@ -48,6 +48,9 @@
#define TB_DP_AUX_PRIORITY 2
#define TB_DP_AUX_WEIGHT 1
+/* struct tb_regs_hop::initial_credits is 7 bits wide */
+#define TB_MAX_CREDITS 127
+
/* Minimum number of credits needed for PCIe path */
#define TB_MIN_PCIE_CREDITS 6U
/*
@@ -1907,7 +1910,7 @@ struct tb_tunnel *tb_tunnel_alloc_dma(struct tb *tb, struct tb_port *nhi,
struct tb_tunnel *tunnel;
size_t npaths = 0, i = 0;
struct tb_path *path;
- int credits;
+ unsigned int credits;
/* Ring 0 is reserved for control channel */
if (WARN_ON(!receive_ring || !transmit_ring))
@@ -1930,6 +1933,11 @@ struct tb_tunnel *tb_tunnel_alloc_dma(struct tb *tb, struct tb_port *nhi,
tunnel->destroy = tb_dma_destroy;
credits = min_not_zero(dma_credits, nhi->sw->max_dma_credits);
+ if (credits > TB_MAX_CREDITS) {
+ tb_tunnel_dbg(tunnel, "%u credits do not fit a hop, using %u\n",
+ credits, TB_MAX_CREDITS);
+ credits = TB_MAX_CREDITS;
+ }
if (receive_ring > 0) {
path = tb_path_alloc(tb, dst, receive_path, nhi, receive_ring, 0,