* [PATCH 6.12.y] wifi: ath12k: fix reusing m3 memory
@ 2026-10-10 5:11 Artem Dinaburg
0 siblings, 0 replies; only message in thread
From: Artem Dinaburg @ 2026-10-10 5:11 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, Sasha Levin, Baochen Qiang, Kalle Valo,
Jeff Johnson, Jeff Johnson, Vasanthakumar Thiagarajan, ath12k,
linux-wireless, linux-kernel
From: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
[ Upstream commit 00575bb44b2c2aa53d0a768de2b80c9c1af0174d ]
During firmware recovery or suspend/resume, m3 memory could be reused if
the size of the new m3 binary is equal to or less than that of the
existing memory. There will be issues for the latter case, since
m3_mem->size will be updated with a smaller value and this value is
eventually used in the free path, where the original total size should be
used instead.
To fix it, add a new member in m3_mem_region structure to track the original
memory size and use it in free path.
Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3
[ Backport to 6.12.y: drop the copyright-line hunks, which do not apply
to 6.12.y. The code changes are the same as upstream. ]
Fixes: 05090ae82f44 ("wifi: ath12k: check M3 buffer size as well whey trying to reuse it")
Signed-off-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Reviewed-by: Vasanthakumar Thiagarajan <vasanthakumar.thiagarajan@oss.qualcomm.com>
Link: https://patch.msgid.link/20251029-ath12k-fix-m3-reuse-v1-1-69225bacfc5d@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
---
Hi Greg, Sasha, and ath12k maintainers,
Please queue this for 6.12.y.
6.12.y has the bug this fixes. When a smaller M3 image is loaded into a
reused buffer, m3_mem->size shrinks to the new image length, and that
length is later passed to dma_free_coherent() instead of the size that
was allocated. The patch also fixes the allocation-failure message, which
reads fw->size even though fw is NULL when the M3 image comes from
firmware-N.bin.
The fix is already in 6.18.y and 7.2.y.
Testing: applies to v6.12.112 and on top of the current 6.12 stable
queue. An x86_64 allmodconfig build with CONFIG_WERROR=y is clean, and
ath12k also builds cleanly with W=1. I tested the M3 load and free
functions in userspace with firmware and DMA stubs under ASan/UBSan. I
did not test on ath12k hardware.
An LLM helped prepare, build, and test this backport. I reviewed the
results.
Thanks,
Artem Dinaburg
drivers/net/wireless/ath/ath12k/qmi.c | 9 ++++++---
drivers/net/wireless/ath/ath12k/qmi.h | 3 +++
2 files changed, 9 insertions(+), 3 deletions(-)
diff --git a/drivers/net/wireless/ath/ath12k/qmi.c b/drivers/net/wireless/ath/ath12k/qmi.c
index b93ce9f87f61..5b02d1d76a36 100644
--- a/drivers/net/wireless/ath/ath12k/qmi.c
+++ b/drivers/net/wireless/ath/ath12k/qmi.c
@@ -2724,9 +2724,10 @@ static void ath12k_qmi_m3_free(struct ath12k_base *ab)
if (!m3_mem->vaddr)
return;
- dma_free_coherent(ab->dev, m3_mem->size,
+ dma_free_coherent(ab->dev, m3_mem->total_size,
m3_mem->vaddr, m3_mem->paddr);
m3_mem->vaddr = NULL;
+ m3_mem->total_size = 0;
m3_mem->size = 0;
}
@@ -2762,7 +2763,7 @@ static int ath12k_qmi_m3_load(struct ath12k_base *ab)
/* In recovery/resume cases, M3 buffer is not freed, try to reuse that */
if (m3_mem->vaddr) {
- if (m3_mem->size >= m3_len)
+ if (m3_mem->total_size >= m3_len)
goto skip_m3_alloc;
/* Old buffer is too small, free and reallocate */
@@ -2774,11 +2775,13 @@ static int ath12k_qmi_m3_load(struct ath12k_base *ab)
GFP_KERNEL);
if (!m3_mem->vaddr) {
ath12k_err(ab, "failed to allocate memory for M3 with size %zu\n",
- fw->size);
+ m3_len);
ret = -ENOMEM;
goto out;
}
+ m3_mem->total_size = m3_len;
+
skip_m3_alloc:
memcpy(m3_mem->vaddr, m3_data, m3_len);
m3_mem->size = m3_len;
diff --git a/drivers/net/wireless/ath/ath12k/qmi.h b/drivers/net/wireless/ath/ath12k/qmi.h
index 0dfcbd8cb59b..e9eb186441cc 100644
--- a/drivers/net/wireless/ath/ath12k/qmi.h
+++ b/drivers/net/wireless/ath/ath12k/qmi.h
@@ -118,6 +118,9 @@ struct target_info {
};
struct m3_mem_region {
+ /* total memory allocated */
+ u32 total_size;
+ /* actual memory being used */
u32 size;
dma_addr_t paddr;
void *vaddr;
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-10-10 5:11 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-10 5:11 [PATCH 6.12.y] wifi: ath12k: fix reusing m3 memory Artem Dinaburg
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®