From: syzbot <syzbot+2ad5f42cd6ca88f0107c@syzkaller.appspotmail.com>
To: linux-kernel@vger.kernel.org
Subject: Forwarded: [PATCH] wifi: cfg80211: defer self-managed regulatory processing to per-wiphy work
Date: Wed, 07 Oct 2026 18:12:03 -0700 [thread overview]
Message-ID: <6ac6ede3.a36481ec.1ba24c.0003.GAE@google.com> (raw)
In-Reply-To: <6a88eb8b.ae6ddae5.3da009.0049.GAE@google.com>
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org.
***
Subject: [PATCH] wifi: cfg80211: defer self-managed regulatory processing to per-wiphy work
Author: emmaonana18@gmail.com
#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master
reg_process_self_managed_hints() currently acquires each registered
wiphy's mutex while called with RTNL held. This can deadlock with a
concurrent path that holds a wiphy mutex and waits for RTNL.
Defer processing of individual self-managed regulatory hints to the
per-wiphy wiphy_work instead. The dispatcher, which runs with RTNL held,
only checks whether a regulatory hint is pending and queues the
corresponding work item.
The regulatory update is then processed with the wiphy mutex held and
without RTNL. This removes the RTNL -> wiphy mutex acquisition from the
synchronous regulatory-processing path.
Also start the regulatory channel-enforcement grace timer after the
self-managed regulatory update has been processed, preserving the
existing ordering between regulatory updates and channel enforcement.
Fixes: f4e72e375807 ("wifi: cfg80211: check channel list asynchronously")
Reported-by: syzbot+2ad5f42cd6ca88f0107c@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=2ad5f42cd6ca88f0107c
Signed-off-by: Omokefe Emmanuel Onanaroghene <emmaonana18@gmail.com>
---
net/wireless/core.c | 1 +
net/wireless/core.h | 1 +
net/wireless/reg.c | 37 +++++++++++++++++++++++++------------
net/wireless/reg.h | 7 +++++++
4 files changed, 34 insertions(+), 12 deletions(-)
diff --git a/net/wireless/core.c b/net/wireless/core.c
index cde3ca85494d..3dfbfb0c10f3 100644
--- a/net/wireless/core.c
+++ b/net/wireless/core.c
@@ -671,6 +671,7 @@ struct wiphy *wiphy_new_nm(const struct cfg80211_ops *ops, int sizeof_priv,
INIT_WORK(&rdev->sched_scan_res_wk, cfg80211_sched_scan_results_wk);
wiphy_work_init(&rdev->reg_check_chans_wk, reg_leave_invalid_chans_wk);
INIT_WORK(&rdev->reg_leave_nan_wk, reg_leave_invalid_nan_wk);
+ wiphy_work_init(&rdev->reg_self_managed_wk, reg_process_self_managed_hint_wk);
INIT_WORK(&rdev->propagate_radar_detect_wk,
cfg80211_propagate_radar_detect_wk);
INIT_WORK(&rdev->propagate_cac_done_wk, cfg80211_propagate_cac_done_wk);
diff --git a/net/wireless/core.h b/net/wireless/core.h
index 6138d207caf4..2b3239d0cf1f 100644
--- a/net/wireless/core.h
+++ b/net/wireless/core.h
@@ -116,6 +116,7 @@ struct cfg80211_registered_device {
struct work_struct sched_scan_res_wk;
struct wiphy_work reg_check_chans_wk;
struct work_struct reg_leave_nan_wk;
+ struct wiphy_work reg_self_managed_wk;
struct cfg80211_chan_def radar_chandef;
struct work_struct propagate_radar_detect_wk;
diff --git a/net/wireless/reg.c b/net/wireless/reg.c
index 11665e0a7efc..00244341fde1 100644
--- a/net/wireless/reg.c
+++ b/net/wireless/reg.c
@@ -3188,7 +3188,6 @@ static void reg_process_self_managed_hint(struct wiphy *wiphy)
enum nl80211_band band;
struct regulatory_request request = {};
- ASSERT_RTNL();
lockdep_assert_wiphy(wiphy);
spin_lock(®_requests_lock);
@@ -3219,6 +3218,14 @@ static void reg_process_self_managed_hint(struct wiphy *wiphy)
nl80211_send_wiphy_reg_change_event(&request);
}
+void reg_process_self_managed_hint_wk(struct wiphy *wiphy, struct wiphy_work *work)
+{
+ lockdep_assert_held(&wiphy->mtx);
+
+ reg_process_self_managed_hint(wiphy);
+ reg_check_channels();
+}
+
static void reg_process_self_managed_hints(void)
{
struct cfg80211_registered_device *rdev;
@@ -3226,12 +3233,17 @@ static void reg_process_self_managed_hints(void)
ASSERT_RTNL();
for_each_rdev(rdev) {
- guard(wiphy)(&rdev->wiphy);
+ bool has_hint;
- reg_process_self_managed_hint(&rdev->wiphy);
- }
+ spin_lock(®_requests_lock);
+ has_hint = !!rdev->requested_regd;
+ spin_unlock(®_requests_lock);
- reg_check_channels();
+ if (!has_hint)
+ continue;
+
+ wiphy_work_queue(&rdev->wiphy, &rdev->reg_self_managed_wk);
+ }
}
static void reg_todo(struct work_struct *work)
@@ -3618,15 +3630,10 @@ static void restore_regulatory_settings(bool reset_user, bool cached)
static bool is_wiphy_all_set_reg_flag(enum ieee80211_regulatory_flags flag)
{
struct cfg80211_registered_device *rdev;
- struct wireless_dev *wdev;
for_each_rdev(rdev) {
- guard(wiphy)(&rdev->wiphy);
-
- list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
- if (!(wdev->wiphy->regulatory_flags & flag))
- return false;
- }
+ if (!(rdev->wiphy.regulatory_flags & flag))
+ return false;
}
return true;
@@ -4144,9 +4151,15 @@ void wiphy_regulatory_register(struct wiphy *wiphy)
void wiphy_regulatory_deregister(struct wiphy *wiphy)
{
+ struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
struct wiphy *request_wiphy = NULL;
struct regulatory_request *lr;
+ spin_lock(®_requests_lock);
+ kfree(rdev->requested_regd);
+ rdev->requested_regd = NULL;
+ spin_unlock(®_requests_lock);
+
lr = get_last_request();
if (!reg_dev_ignore_cell_hint(wiphy))
diff --git a/net/wireless/reg.h b/net/wireless/reg.h
index c587079ead8f..4cfac05c6178 100644
--- a/net/wireless/reg.h
+++ b/net/wireless/reg.h
@@ -194,6 +194,13 @@ void reg_leave_invalid_chans_wk(struct wiphy *wiphy, struct wiphy_work *work);
*/
void reg_leave_invalid_nan_wk(struct work_struct *work);
+/**
+ * reg_process_self_managed_hint_wk - process self-managed hint for a wiphy
+ * @wiphy: the wiphy to process
+ * @work: the work struct
+ */
+void reg_process_self_managed_hint_wk(struct wiphy *wiphy, struct wiphy_work *work);
+
extern const u8 shipped_regdb_certs[];
extern unsigned int shipped_regdb_certs_len;
extern const u8 extra_regdb_certs[];
--
2.43.0
prev parent reply other threads:[~2026-10-08 1:12 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-22 0:21 [syzbot] [net?] INFO: task hung in genl_rcv_msg (5) syzbot
2026-10-08 1:12 ` syzbot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6ac6ede3.a36481ec.1ba24c.0003.GAE@google.com \
--to=syzbot+2ad5f42cd6ca88f0107c@syzkaller.appspotmail.com \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®