From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6F2F13603DB for ; Mon, 3 Aug 2026 07:07:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785740870; cv=none; b=afvGcTXrkFCnXnZE2+cDJQVN2Kts8Q5ROovRwF/zpuKDCPVYBMBykGCPnhsNl1zHoMoK3sRXsx2lg+O1ZIXQxt/bAX0vNAGNrV5wZypsbnc2bcxqdgtZxWwvqPnV7OdgaFWw6+mHXnVqOVU2khZr1KKc8tJJ4g3ZZfczjq2LGbk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785740870; c=relaxed/simple; bh=gLP8V6map0eSHPOl64cKbGyO29l5VAbii39xtqvgRWI=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=gCh5cHoiD5D8O8SAduONiC5DXxmeHB04knz6op1PK6698RPbjg5Bf7Vgr3/3I8N4Ma6/58H/Fm1ONqTWlewVQThNQeIdsDadKNGAWVtOqkGF0rcBfBhjdWEjuNTVvzLW1s9gXVAPJRNJdMzlKdwEUO32jzy3uyH7CmECmUybVPo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=JC2q4HjE; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=NYNvOxBv; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="JC2q4HjE"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="NYNvOxBv" Received: from pps.filterd (m0279865.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6736SLdK250882 for ; Mon, 3 Aug 2026 07:07:46 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= Uylxz9VVZchrtEvgB/E7O4hO2qJgkiTSZerKRLMUiYw=; b=JC2q4HjEabbStTrn IbeO1rcatNdDLZK+K/2ZPAmcKzeLjvZ7bVGTobWVJZFTvw67sRaDvIxNGK8QZQRO v6BDYP4GkmpqNXjeicHw7sdH52EjhEtrB6pRf3pR3uQG8HRpJVwB2OqMeUD9QF1/ 0Bvkg/t+sR+GtmY0imDQi0kKb5uO5m0e3KDkSf01vBSY7uQbZBgrvfi3pNq3ptQq RYLSycilFKCEJahIvk246zk+Czo22f5ERC3me8lVPOp2DhAqVjTW0Ff9lkYMDQdq w40mZ/jhEHjeFzYdhr+u8gakNf5ixZsPVRpcWRSmQ5xXQCnVCC/E7ko3e8xRqN0z gxCc6g== Received: from mail-pl1-f200.google.com (mail-pl1-f200.google.com [209.85.214.200]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4ftnrd84w5-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Mon, 03 Aug 2026 07:07:46 +0000 (GMT) Received: by mail-pl1-f200.google.com with SMTP id d9443c01a7336-2d004f13426so41838015ad.3 for ; Mon, 03 Aug 2026 00:07:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1785740866; x=1786345666; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Uylxz9VVZchrtEvgB/E7O4hO2qJgkiTSZerKRLMUiYw=; b=NYNvOxBviOvYXXfDYKRmoZYkWWmG+CSy8V0hSGWms37OwPzMLyu1GG5Ye2iQ+rmGca NCVG+cU7ShBqZq1sFAnAMwboJJZjylY0S9uG0zRTkVcyARbQrqGGoOQ5J9WvCPpVUXVJ r93x7DvLJdkLPF/CYZ2eDyWnbUcL2rWUd2JnDlx1WqqSuURNReC7ufeKlrYBy/DVsbSQ UO1hLbz1+jlLV2X0XcDkzvUrbOA1xNFzmIeXaWPm1yvwtYNN02LOEZ+plKXG47qA99WK 8wOpK3sUyahfGC/CFnwjainKXqvy1jsTYcpErCD/SudryfjY6U1fR3RnHI3sm35Yv1mN l8Ew== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785740866; x=1786345666; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Uylxz9VVZchrtEvgB/E7O4hO2qJgkiTSZerKRLMUiYw=; b=SktOE7Yg8mtJDF7YP/zJMe3af4OuaGjrNRrNaECwIHG5oxEVfMgG/VHQ7rOTtWTdC7 Ycjuz/jKHSTujNGCNN05PFoIoE1nA4Rj8GeNMPEWyPT416n8H+25qlcJB4Yz0s2IIt1X M+fA5LDibAJ5E8tyiMPR0xqXj+YM9cfUEp82LWMtBXorT9dL/CCTqfKbqLXROyCZnlSQ QgHOpcoUxYzg3t5DM+1CsAnxlYjQfWAWLsbb0pcVWTjjF7QZDj+ZsdrvrS+cDgmSS8MP p3W06AtbG7b8ZjwwXOcMPqNEFcMXDW59qTE69jzYmnBGX6cNDZm+rekxExDZUBmOnHSE Ia9w== X-Forwarded-Encrypted: i=1; AHgh+RoTQzkjFzdWGooUlVxjpAE08eVGdyeTuJ2HmegHzg8xUyQPBHGCdiDQThX5mSRQ/1H2wTYt2KycyJihz9I=@vger.kernel.org X-Gm-Message-State: AOJu0YwK++C9Q89e/AueAiD6gouxmQn1yrCwXRbpXH6IflQ7Zu4sx82t vlCi1L7+lWNqvZLVmVgOxwlHK5kON70VptVoQEjr8zq0V08nkJdkHqPT9gzYQCR4U7M7sCvkRwh EEPYU7FwP3Qzr9Bw88G8k9RsFg03a2jd58mUuwnEKfBPJ0fY9x3BHvrPNeYoJo6nT+Og= X-Gm-Gg: AR+sD10oEIyRCbkDkX7zy4Bu5aoDqJvBNS55xuo3+beUfC+f1sK7AUkg7uzgYhskahD X0JnrtWtgJlLyGepBatD75eV326CyX/1IOwQUmDCZepRY3CbbqEFwXrsX7Rgw5KW1ya6HuJfEDv mcGC3WyPF7qeVs6R5W1zzsPyLzIrPbZbH2UDqVOISgOEaLo2v9p5GkUpgZeB+0zRIhf9nQENKAT TXJ3xtlvZEGAigt71+d8ZeSPpExpQwy5AOyAgmVbPy6FFrUfXDlRnMKxeRPA/ZsNu+bVjFF101W Qwse3uWDJKktw1AeiHIx3895BJ5KOCUIE1Hgi5fIIhwu3BfBPncaJDhAu2CMtgX+HDwSMrh+Hbe vnMozn0ZIy5ZWxsVe7a/cCKpN8cacF3BmZzziRMjzhVGpPSSsXnqg7sEttP56MLKZs5HxGQg= X-Received: by 2002:a17:903:3883:b0:2c9:b396:1a55 with SMTP id d9443c01a7336-2d0522023b7mr86121815ad.12.1785740865967; Mon, 03 Aug 2026 00:07:45 -0700 (PDT) X-Received: by 2002:a17:903:3883:b0:2c9:b396:1a55 with SMTP id d9443c01a7336-2d0522023b7mr86121465ad.12.1785740865561; Mon, 03 Aug 2026 00:07:45 -0700 (PDT) Received: from [10.133.33.22] (tpe-colo-wan-fw-bordernet.qualcomm.com. [103.229.16.4]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d04ae19411sm33697225ad.8.2026.08.03.00.07.43 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 03 Aug 2026 00:07:44 -0700 (PDT) Message-ID: <58cd73d5-d7b2-4259-9936-9c6a55492d53@oss.qualcomm.com> Date: Mon, 3 Aug 2026 15:07:42 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [RESEND PATCH ath-current 3/3] wifi: ath11k: unregister PM notifier on QMI init failure path To: Jeff Johnson , jjohnson@kernel.org Cc: ath11k@lists.infradead.org, linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org References: <20260730030948.147892-1-miaoqing.pan@oss.qualcomm.com> <20260730030948.147892-4-miaoqing.pan@oss.qualcomm.com> Content-Language: en-US From: Miaoqing Pan In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Proofpoint-Spam-Info: AW1haW4tMjYwODAzMDA2MSBTYWx0ZWRfX8h2YbR3/3Bvy /k78T1HQX652EjE9I6f2N+4aav0vvXAOeZFCXneEL+CUFIrGYwGijEv0S4LeT9/B2svfVG06VHh FlEZFBdrm9/0EAKdZMoxmN+a0NnG96A= X-Authority-Analysis: v=2.4 cv=f/94wuyM c=1 sm=1 tr=0 ts=6a703e42 cx=c_pps a=IZJwPbhc+fLeJZngyXXI0A==:117 a=nuhDOHQX5FNHPW3J6Bj6AA==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=Um2Pa8k9VHT-vaBCBUpS:22 a=EUspDBNiAAAA:8 a=JNLNxjGKG8KZZL2vac8A:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 a=uG9DUKGECoFWVXl0Dc02:22 X-Proofpoint-GUID: hbfk22U8eWnqO5VLBTigecd6OhM2OpLl X-Proofpoint-ORIG-GUID: hbfk22U8eWnqO5VLBTigecd6OhM2OpLl X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODAzMDA2MSBTYWx0ZWRfX2BsXmaPEkdCB Dn31TR8ylTK0xDIPw6NK5Ajo5ZVuXojagPfcunZmd+KZVepTqW+A+ruUkeDQonrixCWTpzn4U1K KsBejdKhLDnBarI7dVzBFotazbwJ9ho6U5MRPUYEQWcXIx5be/GmIdsiuDfYaFGQLoEvUTCXT+v 90+2gYy/G+GoWOEdVzfZoKMANCEQn0fsC/q6vey5P8lCFaSe6Fc2W3dF6qTp3moAS1FsC9H/JQJ Lomwlnp+EI1FK/QaZhZMW+SxGZQF0ktBKr7eMvxgodDwkKZEzLTiV6zZKcz/vhHcGRKmvPjbxa7 UBnJB7zFOt4EDSLTaIkUovuaYdCu5guBIgdQhJaw4HXcfzaisdYXFQCmlYrmw7tIrfgeUTPPIvq om52hfIJ9Ps/T3Agzrb1BIJI8KjCbYgHy5vWe17ho7thl4i4OmsVNRzg0AvddXB7HHrkvECWdex Xd8ZJYVYIv5E04+nvkg== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-02_06,2026-07-30_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 lowpriorityscore=0 adultscore=0 priorityscore=1501 malwarescore=0 spamscore=0 bulkscore=0 impostorscore=0 suspectscore=0 clxscore=1015 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608030061 On 8/1/2026 7:06 AM, Jeff Johnson wrote: > On 7/29/2026 8:09 PM, Miaoqing Pan wrote: >> ath11k_core_init() registers a PM notifier before the QMI server >> becomes available. If the QMI server never arrives, the device remove() >> path can take the early-exit path introduced for QMI initialization >> failures, skipping ath11k_core_deinit(). > > This patch felt wrong to me, so I spent some time with my buddy Claude. > > I asked Claude: in the last patch the commit text says "If the QMI server > never arrives, the device remove() path can take the early-exit path > introduced for QMI initialization failures". where is this device remove() > path code? I'm trying to understand why there needs to be a call to > ath11k_core_pm_notifier_unregister() in ath11k_ahb_remove() as well as in > ath11k_core_deinit(). since ath11k_core_pm_notifier_register() is only called > from one place it is logical that ath11k_core_pm_notifier_unregister() should > also be called in one place that is symmetrical. the proposed patch breaks the > init/deinit symmetry. > > Claude said: > The symmetry argument is well-founded. Here's the actual structure: > > ath11k_core_init() registers the notifier. ath11k_core_deinit() is its > symmetric counterpart and unregisters it. That is the intended 1:1 pairing. > > The problem is that both ath11k_ahb_remove() and ath11k_pci_remove() have an > early-exit path for QMI_FAIL that bypasses ath11k_core_deinit() — but still > need to undo what ath11k_core_init() did. So they replicate the unregister > call directly. This is an existing pattern: pci.c:1188 already had > ath11k_core_pm_notifier_unregister() in its QMI_FAIL early-exit before this > patch series. > > Patch 3 simply extends that same pattern to ahb.c's early-exit path, which was > missing it. > > The symmetry break isn't introduced by this patch — it was already present for > PCI. The fix for the symmetry issue would be to restructure so the early-exit > paths all go through ath11k_core_deinit() (or a new partial-deinit function), > but that's a larger refactor. This patch's approach matches the existing > convention in the tree. > > The commit message claim about "the early-exit path introduced for QMI > initialization failures" refers to the QMI_FAIL branch at ahb.c:1301 — the > goto qmi_fail block that skips ath11k_core_deinit(). > > Thank you, Claude. > > So I guess this patch is OK since it is replicating the PCI pattern, but is > there any way to have ath11k_core_deinit() called in those early exit paths so > that we can keep the init/deinit symmetry? It just seems wrong that if > ath11k_core_init() did not return an error that we would have deinit logic > that would skip calling ath11k_core_deinit() > The init/deinit symmetry issue is a pre-existing concern and not trivial to solve. We can address it separately in a future cleanup/refactoring patch. >> >> As a result, the PM notifier remains registered after the ath11k base >> object has been freed. A subsequent suspend or resume event may invoke >> the stale notifier and trigger a use-after-free. >> >> Fix this by explicitly unregistering the PM notifier in the QMI failure >> cleanup path before releasing ath11k resources. >> >> Tested-on: WCN6750 hw1.0 AHB WLAN.MSL.2.0.c2-00204-QCAMSLSWPLZ-1 >> >> Fixes: 32d93b51bc7e ("wifi: ath11k: choose default PM policy for hibernation") >> Signed-off-by: Miaoqing Pan >> --- >> drivers/net/wireless/ath/ath11k/ahb.c | 1 + >> 1 file changed, 1 insertion(+) >> >> diff --git a/drivers/net/wireless/ath/ath11k/ahb.c b/drivers/net/wireless/ath/ath11k/ahb.c >> index 7f5f5c8d7c56..bdb8c99f10fa 100644 >> --- a/drivers/net/wireless/ath/ath11k/ahb.c >> +++ b/drivers/net/wireless/ath/ath11k/ahb.c >> @@ -1272,6 +1272,7 @@ static void ath11k_ahb_remove(struct platform_device *pdev) >> ath11k_ahb_power_down(ab, false); >> ath11k_debugfs_soc_destroy(ab); >> ath11k_qmi_deinit_service(ab); >> + ath11k_core_pm_notifier_unregister(ab); >> goto qmi_fail; >> } >> >