mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Stanislaw Gruszka <stf_xl@wp.pl>
To: Runyu Xiao <runyu.xiao@seu.edu.cn>
Cc: Julia Lawall <Julia.Lawall@lip6.fr>,
	Kalle Valo <kvalo@kernel.org>,
	linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org,
	stable@vger.kernel.org, Jianhao Xu <jianhao.xu@seu.edu.cn>
Subject: Re: [PATCH] wifi: iwlegacy: serialize watchdog updates with device teardown
Date: Tue, 6 Oct 2026 10:40:23 +0200	[thread overview]
Message-ID: <20261006084023.GA28327@wp.pl> (raw)
In-Reply-To: <20261004114519.1233305-1-runyu.xiao@seu.edu.cn>

On Sun, Oct 04, 2026 at 07:45:19PM +0800, Runyu Xiao wrote:
> The writable wd_timeout debugfs file changes il->cfg->wd_timeout, but the
> iwl3945 configuration is shared and const. The handler also rearms the
The cfg in il_priv is not const. What would possibly make sense is
take _all_ modified fields out, and make it const then.

> watchdog without taking il->mutex. The down paths hold this mutex, delete
> the timer, and then free the TX queues, so an unlocked debugfs write can
> rearm the timer after deletion. The callback can then access the queues
> after they have been freed.
> 
> Store wd_timeout in per-device state. Serialize the debugfs update with
> the down paths and only arm the watchdog while TX queues exist. Use
> READ_ONCE() and WRITE_ONCE() for accesses that do not hold il->mutex.
> 
> Fixes: 1dc80798a8ca ("iwlegacy: constify local structures")
This is wrong tag. At least for watchdog stop races.

> --- a/drivers/net/wireless/intel/iwlegacy/debug.c
> +++ b/drivers/net/wireless/intel/iwlegacy/debug.c
> @@ -1284,8 +1284,12 @@ il_dbgfs_wd_timeout_write(struct file *file, const char __user *user_buf,
>  	if (timeout < 0 || timeout > IL_MAX_WD_TIMEOUT)
>  		timeout = IL_DEF_WD_TIMEOUT;
>  
> -	il->cfg->wd_timeout = timeout;
> -	il_setup_watchdog(il);
> +	mutex_lock(&il->mutex);
> +	WRITE_ONCE(il->wd_timeout, timeout);
> +	if (il->txq)
> +		il_setup_watchdog(il);
This will not work for 4965. Possibly il->is_open could be used as
check. But maybe we should just remove possibility of setting
wd_timeout, I need to think about it.

Regards
Stanislaw
> +	mutex_unlock(&il->mutex);
> +
>  	return count;
>  }
>  
> -- 
> 2.34.1

      parent reply	other threads:[~2026-10-06  8:40 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-04 11:45 Runyu Xiao
2026-10-05 13:23 ` Johannes Berg
2026-10-06  8:40 ` Stanislaw Gruszka [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261006084023.GA28327@wp.pl \
    --to=stf_xl@wp.pl \
    --cc=Julia.Lawall@lip6.fr \
    --cc=jianhao.xu@seu.edu.cn \
    --cc=kvalo@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-wireless@vger.kernel.org \
    --cc=runyu.xiao@seu.edu.cn \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®