Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

net: amd: lance: don't call dev_kfree_skb() under spin_lock_irqsave()

It is not allowed to call kfree_skb() or consume_skb() from hardware
interrupt context or with hardware interrupts being disabled.

It should use dev_kfree_skb_irq() or dev_consume_skb_irq() instead.
The difference between them is free reason, dev_kfree_skb_irq() means
the SKB is dropped in error and dev_consume_skb_irq() means the SKB
is consumed in normal.

In these two cases, dev_kfree_skb() is called consume the xmited SKB,
so replace it with dev_consume_skb_irq().

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Yang Yingliang <yangyingliang@huawei.com>
Signed-off-by: David S. Miller <davem@davemloft.net>

authored by

Yang Yingliang and committed by
David S. Miller
6151d105 3727f742

+2 -2
+1 -1
drivers/net/ethernet/amd/atarilance.c
··· 824 824 lp->memcpy_f( PKTBUF_ADDR(head), (void *)skb->data, skb->len ); 825 825 head->flag = TMD1_OWN_CHIP | TMD1_ENP | TMD1_STP; 826 826 dev->stats.tx_bytes += skb->len; 827 - dev_kfree_skb( skb ); 827 + dev_consume_skb_irq(skb); 828 828 lp->cur_tx++; 829 829 while( lp->cur_tx >= TX_RING_SIZE && lp->dirty_tx >= TX_RING_SIZE ) { 830 830 lp->cur_tx -= TX_RING_SIZE;
+1 -1
drivers/net/ethernet/amd/lance.c
··· 1001 1001 skb_copy_from_linear_data(skb, &lp->tx_bounce_buffs[entry], skb->len); 1002 1002 lp->tx_ring[entry].base = 1003 1003 ((u32)isa_virt_to_bus((lp->tx_bounce_buffs + entry)) & 0xffffff) | 0x83000000; 1004 - dev_kfree_skb(skb); 1004 + dev_consume_skb_irq(skb); 1005 1005 } else { 1006 1006 lp->tx_skbuff[entry] = skb; 1007 1007 lp->tx_ring[entry].base = ((u32)isa_virt_to_bus(skb->data) & 0xffffff) | 0x83000000;