mail archive of the barebox mailing list
 help / color / mirror / Atom feed
From: "Daniel Glöckner" <dg@emlix.com>
To: Sascha Hauer <s.hauer@pengutronix.de>,
	Barebox List <barebox@lists.infradead.org>
Cc: Edmund Henniges <eh@emlix.com>
Subject: Re: [PATCH 17/21] fastboot net: implement fastboot over UDP
Date: Mon, 29 Jun 2020 21:50:51 +0200	[thread overview]
Message-ID: <70810c58-b4f1-945d-fffa-c79083a03c48@emlix.com> (raw)
In-Reply-To: <20200619074427.17289-18-s.hauer@pengutronix.de>

Hello Sascha,

Am 19.06.20 um 09:44 schrieb Sascha Hauer:
> +struct fastboot_net {
> +	struct fastboot fastboot;
> +
> +	struct net_connection *net_con;
> +	struct fastboot_header response_header;
> +	struct poller_struct poller;
> +	struct work_queue wq;
> +	u64 host_waits_since;
> +	u64 last_download_pkt;
> +	bool sequence_number_seen;
> +	bool active_download;
> +	bool reinit;
> +	bool send_keep_alive;
> +	enum may_send may_send;
> +
> +	IPaddr_t host_addr;
> +	u16 host_port;
> +	u8 host_mac[ETH_ALEN];
> +	u16 sequence_number;
> +	u16 last_payload_len;
> +	uchar last_payload[FASTBOOT_MAX_CMD_LEN + sizeof(struct fastboot_header)];

This is not FASTBOOT_MAX_CMD_LEN. It's the 64 that is strewn around in
fastboot_tx_print. Adding a new constant FASTBOOT_MAX_MSG_LEN would be
correct.

[...]

> +static int fastboot_write_net(struct fastboot *fb, const char *buf,
> +			      unsigned int n)
> +{
> +	struct fastboot_net *fbn = container_of(fb, struct fastboot_net,
> +						fastboot);
> +	struct fastboot_header response_header;
> +	uchar *packet;
> +	uchar *packet_base;
> +	int ret;
> +
> +	if (fbn->reinit)
> +		return 0;
> +
> +	/*
> +	 * This function is either called in command context, in which
> +	 * case we may wait, or from the keepalive poller which explicitly
> +	 * only calls us when we don't have to wait here.
> +	 */
> +	ret = fastboot_net_wait_may_send(fbn);
> +	if (ret) {
> +		fastboot_net_abort(fbn);
> +		return ret;
> +	}
> +
> +	if (n && fbn->may_send == MAY_SEND_ACK) {
> +		fastboot_send(fbn, fbn->response_header,
> +				"Have message but only ACK allowed");
> +		return -EPROTO;
> +	} else if (!n && fbn->may_send == MAY_SEND_MESSAGE) {
> +		fastboot_send(fbn, fbn->response_header,
> +				"Want to send ACK but message expected");
> +		return -EPROTO;
> +	}
> +
> +	response_header = fbn->response_header;
> +	response_header.flags = 0;
> +	response_header.seq = htons(fbn->sequence_number);
> +	++fbn->sequence_number;
> +	fbn->sequence_number_seen = false;
> +
> +	packet = net_udp_get_payload(fbn->net_con);
> +	packet_base = packet;
> +
> +	/* Write headers */
> +	memcpy(packet, &response_header, sizeof(response_header));
> +	packet += sizeof(response_header);
> +	/* Write response */
> +	memcpy(packet, buf, n);
> +	packet += n;
> +
> +	/* Save packet for retransmitting */
> +	fbn->last_payload_len = packet - packet_base;
> +	memcpy(fbn->last_payload, packet_base, fbn->last_payload_len);
> +
> +	memcpy(fbn->net_con->et->et_dest, fbn->host_mac, ETH_ALEN);
> +	net_write_ip(&fbn->net_con->ip->daddr, fbn->host_addr);
> +	fbn->net_con->udp->uh_dport = fbn->host_port;
> +	net_udp_send(fbn->net_con, fbn->last_payload_len);
> +
> +	fbn->may_send = MAY_NOT_SEND;

You moved that line below net_udp_send. Is there any risk that

1. our work queue executes a command which calls fastboot_tx_print
2. the net_udp_send caused by that fastboot_tx_print sleeps
3. our poller is executed and decides to send a message because
   may_send is still MAY_SEND_MESSAGE

?

[...]

> +static void fastboot_start_download_net(struct fastboot *fb)
> +{
> +	struct fastboot_net *fbn = container_of(fb, struct fastboot_net,
> +						fastboot);
> +
> +	fastboot_start_download_generic(fb);
> +	fbn->active_download = true;
> +	fbn->last_download_pkt = get_time_ns();
> +}

Although you added that last_download_pkt timeout check to the poller,
there is still the risk that we will never close download_fd if
fastboot_net_abort is called (f.ex. by the first fastboot_tx_print
inside cb_download) before we open download_fd. In that case there
is no poller to check for the timeout.

[...]

> +static void fastboot_handle_type_fastboot(struct fastboot_net *fbn,
> +					  struct fastboot_header header,
> +					  char *fastboot_data,
> +					  unsigned int fastboot_data_len)
> +{
> +	struct fastboot_work *w;
> +
> +	fbn->response_header = header;
> +	fbn->host_waits_since = get_time_ns();
> +	fbn->may_send = fastboot_data_len ? MAY_SEND_ACK : MAY_SEND_MESSAGE;
> +
> +	if (fbn->active_download) {
> +		fbn->last_download_pkt = get_time_ns();
> +
> +		if (!fastboot_data_len && fbn->fastboot.download_bytes
> +					   == fbn->fastboot.download_size) {
> +
> +			fbn->active_download = false;
> +
> +			w = xzalloc(sizeof(*w));
> +			w->fbn = fbn;
> +			w->download_finished = true;
> +
> +			wq_queue_work(&fbn->wq, &w->work);
> +		} else {
> +			fastboot_data_download(fbn, fastboot_data,
> +					       fastboot_data_len);
> +		}
> +		return;
> +	}
> +
> +	if (fastboot_data_len >= FASTBOOT_MAX_CMD_LEN) {

Still off-by-one. Replace >= with >

[...]

> +	case FASTBOOT_INIT:
> +		if (ntohs(header.seq) != fbn->sequence_number) {
> +			fastboot_check_retransmit(fbn, header);
> +			break;
> +		}
> +		fbn->host_addr = net_read_ip(&ip_header->saddr);
> +		fbn->host_port = udp_header->uh_sport;
> +		memcpy(fbn->host_mac, eth_header->et_src, ETH_ALEN);
> +		fastboot_net_abort(fbn);
> +		ret = poller_register(&fbn->poller, "fastboot");
> +		if (ret) {
> +			pr_err("Cannot register poller: %s\n", strerror(-ret));
> +			return;

It is not obvious that a second FASTBOOT_INIT will _not_ cause this
error because fastboot_net_abort unregistered the previous poller.
I would at least add a comment to the fastboot_net_abort(fbn) line.

[...]

> +static void fastboot_poll(struct poller_struct *poller)
> +{
> +	struct fastboot_net *fbn = container_of(poller, struct fastboot_net,
> +					       poller);
> +
> +	if (fbn->active_download && is_timeout(fbn->last_download_pkt, 5 * SECOND)) {

Should pollers prefer is_timeout_non_interruptible over is_timeout?

I can make a new patch set where all issues are fixed, if you don't insist
on doing it yourself.

Best regards,

  Daniel


-- 
Dipl.-Math. Daniel Glöckner, emlix GmbH, http://www.emlix.com
Fon +49 551 30664-0, Fax +49 551 30664-11,
Gothaer Platz 3, 37083 Göttingen, Germany
Sitz der Gesellschaft: Göttingen, Amtsgericht Göttingen HR B 3160
Geschäftsführung: Heike Jordan, Dr. Uwe Kracke
Ust-IdNr.: DE 205 198 055

emlix - your embedded linux partner

_______________________________________________
barebox mailing list
barebox@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/barebox

  reply	other threads:[~2020-06-29 19:51 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-06-19  7:44 [PATCH v5 00/21] Slices and " Sascha Hauer
2020-06-19  7:44 ` [PATCH 01/21] Introduce slices Sascha Hauer
2020-06-19  7:44 ` [PATCH 02/21] Add workqueues Sascha Hauer
2020-06-19  7:44 ` [PATCH 03/21] ratp: Switch to workqueues Sascha Hauer
2020-06-19  7:44 ` [PATCH 04/21] net: Add a slice to struct eth_device Sascha Hauer
2020-06-19  7:44 ` [PATCH 05/21] net: mdiobus: Add slice Sascha Hauer
2020-06-19  7:44 ` [PATCH 06/21] usb: Add a slice to usb host controllers Sascha Hauer
2020-06-19  7:44 ` [PATCH 07/21] usbnet: Add slice Sascha Hauer
2020-06-19  7:44 ` [PATCH 08/21] net: Call net_poll() in a poller Sascha Hauer
2020-06-19  7:44 ` [PATCH 09/21] net: reply to ping requests Sascha Hauer
2020-06-19  7:44 ` [PATCH 10/21] usbnet: Be more friendly in the receive path Sascha Hauer
2020-06-19  7:44 ` [PATCH 11/21] defconfigs: update renamed fastboot options Sascha Hauer
2020-06-19  7:44 ` [PATCH 12/21] globalvar: Add helper for deprecated variable names Sascha Hauer
2020-06-19  7:44 ` [PATCH 13/21] fastboot: rename usbgadget.fastboot_* variables to fastboot.* Sascha Hauer
2020-06-19  7:44 ` [PATCH 14/21] fastboot: Warn when cb_download is called with file still open Sascha Hauer
2020-06-19  7:44 ` [PATCH 15/21] fastboot: Add fastboot_abort() Sascha Hauer
2020-06-19  7:44 ` [PATCH 16/21] fastboot: init list head in common Sascha Hauer
2020-06-19  7:44 ` [PATCH 17/21] fastboot net: implement fastboot over UDP Sascha Hauer
2020-06-29 19:50   ` Daniel Glöckner [this message]
2020-07-11  4:48     ` Sascha Hauer
2020-08-13 10:38     ` Sascha Hauer
2020-06-19  7:44 ` [PATCH 18/21] usb: fastboot: execute commands in command context Sascha Hauer
2020-06-19  7:44 ` [PATCH 19/21] Add WARN_ONCE() macro Sascha Hauer
2020-06-19  7:44 ` [PATCH 20/21] fs: Warn when filesystem operations are called from a poller Sascha Hauer
2020-06-19  7:44 ` [PATCH 21/21] Documentation: Add document for parallel execution in barebox Sascha Hauer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=70810c58-b4f1-945d-fffa-c79083a03c48@emlix.com \
    --to=dg@emlix.com \
    --cc=barebox@lists.infradead.org \
    --cc=eh@emlix.com \
    --cc=s.hauer@pengutronix.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox