From: Mehmet Fide <mehmet.fide@gmail.com>
To: pkshih@realtek.com
Cc: luka.gejak@linux.dev, rtl8821cerfe2@gmail.com,
linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org,
mehmet.fide@screeningeagle.com
Subject: Re: [PATCH rtw-next v4 2/2] wifi: rtw88: support channel switch in AP mode
Date: Wed, 7 Oct 2026 10:09:30 +0200 [thread overview]
Message-ID: <20261007080930.2473263-1-mehmet.fide@gmail.com> (raw)
In-Reply-To: <63ac6992e6614de1a085131964974ff1@realtek.com>
Hi Ping-Ke,
On 2026-10-07 Ping-Ke Shih wrote:
> add lockdep_assert_wiphy(wiphy) to rtw_fw_csa_{active,start,stop}?
> Since they access rtwdev->csa_vif.
Yes. Adding them showed that update_beacon_work, the TIM download,
reads csa_vif outside the wiphy lock: it is an ordinary work queued
from set_tim(). v5 makes it a wiphy work first, in a patch of its own,
the way rtw89 runs its update_beacon_work, and the three helpers then
assert the lock. The series then went through the whole AP test set
on a PROVE_LOCKING kernel (8821CU and 8822CU, including a firmware
crash during a countdown and the IPS path) without a lockdep report.
> > - rtw_fw_download_rsvd_page(rtwdev);
> > - rtw_send_rsvd_page_h2c(rtwdev);
> > + if (!rtw_fw_csa_active(rtwdev)) {
>
> Does it actually happen to AP mode?
>
> If it could happen, check the condition by conf->csa_active (like below)?
Not for the AP interface: mac80211 raises BSS_CHANGED_ASSOC for a
station interface only. The hunk is for the STA+AP combination the
driver registers for the 8822C, and it does happen there: with an AP
on an RTL8822CU counting down from channel 6 to 11, a station interface
on the same device that had a fresh scan result associated with an AP
on channel 11 while the countdown ran, so BSS_CHANGED_ASSOC arrived in
the middle of it. That download would rebuild the reserved page with a
fresh beacon. conf belongs to the station there, so conf->csa_active
would say nothing about the AP; that is why the check is on
rtwdev->csa_vif.
> > - if (rtw_get_lps_deep_mode(rtwdev) == LPS_DEEP_MODE_PG)
> > + if (rtw_get_lps_deep_mode(rtwdev) == LPS_DEEP_MODE_PG &&
> > + !rtw_fw_csa_active(rtwdev))
>
> Think of this deeper.... Is it existing race between set_key and !csa->active?
I do not see one. set_key(), the countdown work and the places that
set and clear csa_active all run under the wiphy lock, so the flag
cannot change under the check. The download set_key() skips is not
lost either: ieee80211_csa_finish() ends in ieee80211_csa_finalize(),
which assigns the next beacon with BSS_CHANGED_BEACON, and that path
rebuilds the whole page, CAM backup included, once the countdown is
over. Did you have another race in mind?
> > + rtw_fw_csa_stop(rtwdev, rtwdev->csa_vif);
>
> Since you access rtwdev->csa_vif, should this take wiphy_lock?
It is held already: cfg80211's wiphy_suspend() calls rdev_suspend()
inside scoped_guard(wiphy, ...), and drv_suspend() asserts the lock.
The assert in rtw_fw_csa_stop() will make that visible.
> > + mutex_lock(&rtwdev->mutex);
>
> guard(mutex)( &rtwdev->mutex); ?
Done in v5, which follows in a few days.
Thanks,
Mehmet
next prev parent reply other threads:[~2026-10-07 8:09 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 6:11 [PATCH rtw-next v4 0/2] wifi: rtw88: " Mehmet Fide
2026-10-07 6:11 ` [PATCH rtw-next v4 1/2] wifi: rtw88: download the beacon the reserved page was built with Mehmet Fide
2026-10-07 6:11 ` [PATCH rtw-next v4 2/2] wifi: rtw88: support channel switch in AP mode Mehmet Fide
2026-10-07 6:39 ` Ping-Ke Shih
2026-10-07 8:09 ` Mehmet Fide [this message]
2026-10-07 8:17 ` Ping-Ke Shih
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261007080930.2473263-1-mehmet.fide@gmail.com \
--to=mehmet.fide@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=luka.gejak@linux.dev \
--cc=mehmet.fide@screeningeagle.com \
--cc=pkshih@realtek.com \
--cc=rtl8821cerfe2@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®