From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ej1-f49.google.com (mail-ej1-f49.google.com [209.85.218.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6928F3DF003 for ; Sun, 26 Jul 2026 22:19:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785104387; cv=none; b=ST59H3OqmJOvKSBKXnX9T7SkLfb/SmfAIAsyZmICl3UnXlNkbKqEQPJWhrdGEPA3jnbK6J6QYE0zY1Ur/Gaz4w4lhweC1DlIeHsV8GkTt7k0Z2R+pVBWjPZKto6izpL0W1+yTt8dwsFd/q83JCRe0iC7CQFkGT5uCbJUG5wiAeo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785104387; c=relaxed/simple; bh=5z6xCM330x0gV6OWXp701jrk3HyaNz82AbVh+/w8o0w=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gcx4bugF7xx6mGirdsiTs5PAwS1CmLu+B2bHUuQNzNYkeBZYNwBvq1geMn8PvvhUbknWcxNzEpSjcawPepkATzI6voNbLCAjq0/mnvbJqF6eK4gndtw0Jx2UjZMX4PjHuytef6wp5MrdyC42A6s2/58yn1QRNTK072c+Y3ub3+A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bairaktaris.de; spf=pass smtp.mailfrom=bairaktaris.de; dkim=pass (2048-bit key) header.d=bairaktaris.de header.i=@bairaktaris.de header.b=CCkQlXDn; arc=none smtp.client-ip=209.85.218.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=bairaktaris.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=bairaktaris.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=bairaktaris.de header.i=@bairaktaris.de header.b="CCkQlXDn" Received: by mail-ej1-f49.google.com with SMTP id a640c23a62f3a-c15e03c2763so400488266b.0 for ; Sun, 26 Jul 2026 15:19:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bairaktaris.de; s=google; t=1785104385; x=1785709185; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=K9fcVVwyHbUhNRIUxOg0dRn9BUzSneLTHuKU2xQuQd4=; b=CCkQlXDn6Tc0Xe+D2FJ5oFrnaPtcOafp+06e+VkbKYeGEeK8q5PpVtXVlDsHK+LHFh AZSX+OL23TpmUfue52ZyX7pF2MG+ahxO8lzX3TsdKcHnwDDUqBRPUYaxwmAJQBo6rtpp DvEjRX5CUFEid799DgJAD15PkfX1NvdD52fZ57Ewuvu4tgLh7GNGZAQBLL1/vT3f2Vfi z+kiNs93pXR+BKRNOvoMoQhRG4fj4jjqZT35zngEOwDfkruQIhCpn8aTFd/e6WJXCvyA GXHiFhoA2F1YP057LqMQ0I4YFiBQ25u1lZNC/jiJ3Kcm9WVy2HDzAIHZN7PFXhvVZplA ODPg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785104385; x=1785709185; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=K9fcVVwyHbUhNRIUxOg0dRn9BUzSneLTHuKU2xQuQd4=; b=XLft2X1zSqCal/WuCWLSFEwpz5nzZviZgaqUPHTTQw9H8PkC5Z5S+OVqwkkkdMqdMO MFESfW+ANrbdu4mt4sh3gJetcTEjgtg1yc99c7JkD6SRVTkTR8CCFkTSw/aL0GI56i2q zg1XD/0nh53qQiBp/lZ89sPKNetdfKn5qO/5jYK0pTBIQXE0b3Wz/GWmiDbtv96T1B3Q YFxqEdX0q9Wmpx2lTQy4gCRCKiWjjWvL2xNFhPnudK8zE20acH1wZZsQii57XLTusOAM 0rviUrhj+Iln7b90eYaOr6VescppYYPWg8CiRm35LKCSqcin15KuPiQzGqxTo4gRbQgn 5ilQ== X-Forwarded-Encrypted: i=1; AHgh+Rp/OOzykQbOlrCzETL0+w3H02nd6xoK4ytz6vkaLLPwBgA5dSvQwgoaJmA8YyKxXkLqYbghMdHCI0mW0l4=@vger.kernel.org X-Gm-Message-State: AOJu0YzwiUC0OaQSoZpwldm7mPlXkElH91niJf6k5RC+4JPSFL1dVFK7 8ErgBQ7W7Gv3krwc5QlGKFrbHEB2LxVlWWxDe//iQOkK8A2xzI+WVEREl6FTecqaCA== X-Gm-Gg: AR+sD119bYceD/PPWb0INsX5P1gvTD+7A6us9j8/Gw48Cf5dRBfkECoH24DaCGVEmiS usqXAJ10fS5HjK2bSH6gG7oXnyVLodEQUYqhJee31pDJYPeyVkme357zdXUCLe0T4z21W8pdjS/ juGRK26dXmd0oG+qneNIE/OX62sP7cqrDo+Q3gEUcPzkY+3Ju8cLPYT71J/cSPF9128bqtIMsnU RTQuULYvlQUHVrMxtkSuGLFEXGv7MYdNpq5JcWfhrWwcMrgCCK+7sOqtA+4q6uV8qwXMvLg5obL ZghYjSK/HqerNfzqXpbx4azX28X+tp9nZA4AjDKwJwq0kP7B5s/hpofcnKeU4Z7asRKRAwN1Toy Lkz5KfO+sRwWl3EmIwU/SUJOjZJuPACM9TdLn4OoE+UyavolrYIhSkXaMIkV+s+8LQ0x3dTmQqS hQSe9WbfqR7hQQ3IxI+4dcujEBTnX8uxJikUw90oiHqFmIddNwNo5GI/GVQo5nFiVZK70juODr7 ME6z9Uh9Yj88JebI3bsmoNeMPKwdaOy6XGFEcdiVc9dLUxKl7jEIM3r5xHfH3O2nIAhGRlpgLSD kut+C217F2y+1iM4lkQw7GygAiFUMrHJNM4kfjYtJlJD0c/X74KN91JMj9dS/6IUd/nRrUHUF1o FDUytwkJoxmDX9LpKZX0azrRXiFLzxvc= X-Received: by 2002:a17:907:9286:b0:c1c:1fbf:5d18 with SMTP id a640c23a62f3a-c1f13388df1mr379927666b.3.1785104384611; Sun, 26 Jul 2026 15:19:44 -0700 (PDT) Received: from Desktop (p54affe4b.dip0.t-ipconnect.de. [84.175.254.75]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c1c32a76fecsm561599466b.8.2026.07.26.15.19.43 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 15:19:43 -0700 (PDT) From: Julius Bairaktaris To: jjohnson@kernel.org Cc: ath11k@lists.infradead.org, linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, baochen.qiang@oss.qualcomm.com, vasanthakumar.thiagarajan@oss.qualcomm.com, rameshkumar.sundaram@oss.qualcomm.com Subject: [PATCH ath-next v2 2/2] wifi: ath11k: disable interrupts during firmware crash recovery Date: Mon, 27 Jul 2026 00:19:08 +0200 Message-ID: <20260726221908.104873-3-julius@bairaktaris.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260726221908.104873-1-julius@bairaktaris.de> References: <20260726221908.104873-1-julius@bairaktaris.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit On IPQ8074 a firmware assert reboots the SoC: Unable to handle kernel read from unreadable memory at virtual address 0 pc : ath11k_hal_srng_access_begin+0xc/0x60 [ath11k] lr : ath11k_dp_rx_process_mon_status+0x15c/0xd84 [ath11k] Call trace: ath11k_hal_srng_access_begin+0xc/0x60 [ath11k] ath11k_dp_rx_process_mon_rings+0xa0/0x5d4 [ath11k] ath11k_dp_service_srng+0x1f4/0x348 [ath11k] ath11k_ahb_ext_grp_napi_poll+0x34/0xd4 [ath11k_ahb] __napi_poll+0x38/0x188 net_rx_action+0x120/0x2c0 ath11k_core_reconfigure_on_crash() tears the data path down with ath11k_dp_pdev_free(), ath11k_dp_free() and ath11k_hal_srng_clear(), which memsets the ring list. The DP NAPI is still running while that happens, so it services a ring whose address pointer has just been cleared. That function used to disable the interrupts first, until commit d455e805de70 ("wifi: ath11k: rearrange IRQ enable/disable in reset path") moved the disable into ath11k_core_reset(). reset_work is only queued from mhi.c and from the debugfs hw-restart handler, so AHB parts never run it on a real firmware crash. Their recovery goes QMI server exit -> restart_work -> ath11k_core_reconfigure_on_crash() -> ath11k_core_qmi_firmware_ready(), and nothing disables the interrupts anywhere along it. Disable them again on the crash path. The reset path has already done so by the time it gets here, hence the ab->is_reset check. This is also why the debugfs hw-restart trigger never showed the problem: it goes through ath11k_core_reset(), the one path that still had the disable. Tested-on: IPQ8074 hw2.0 AHB WLAN.HK.2.12-01460-QCAHKSWPL_SILICONZ-1 Fixes: d455e805de70 ("wifi: ath11k: rearrange IRQ enable/disable in reset path") Assisted-by: Claude:claude-opus-5 Signed-off-by: Julius Bairaktaris --- drivers/net/wireless/ath/ath11k/core.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/drivers/net/wireless/ath/ath11k/core.c b/drivers/net/wireless/ath/ath11k/core.c index 8039124e7832..d2ed6a0ea7e3 100644 --- a/drivers/net/wireless/ath/ath11k/core.c +++ b/drivers/net/wireless/ath/ath11k/core.c @@ -2334,6 +2334,16 @@ static int ath11k_core_reconfigure_on_crash(struct ath11k_base *ab) mutex_lock(&ab->core_lock); ath11k_thermal_unregister(ab); + + /* + * ath11k_core_reset() already disabled the interrupts on the reset + * path; only the firmware crash path reaches here with them live. + */ + if (!ab->is_reset) { + ath11k_hif_irq_disable(ab); + ath11k_hif_ce_irq_disable(ab); + } + ath11k_dp_pdev_free(ab); ath11k_cfr_deinit(ab); ath11k_spectral_deinit(ab); -- 2.53.0