* [PATCHv2 ath-next] wifi: ath9k: delete channel-context timers on deinit
@ 2026-09-11 21:31 Rosen Penev
2026-09-12 8:23 ` Toke Høiland-Jørgensen
2026-10-05 15:09 ` Jeff Johnson
0 siblings, 2 replies; 4+ messages in thread
From: Rosen Penev @ 2026-09-11 21:31 UTC (permalink / raw)
To: linux-wireless; +Cc: Toke Høiland-Jørgensen, open list
ath9k_deinit_channel_context() cancels chanctx_work but does not delete
the offchannel and sched timers set up by ath9k_init_channel_context().
If either timer fires after deinit (e.g. during driver unload or
suspend), it accesses sc->sc_ah which may already be freed by
ath9k_hw_deinit(), causing a use-after-free.
Delete both timers with timer_shutdown_sync() before cancelling the work
item.
Assisted-by: LLM
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
v2: use timer_shutdown_sync()
drivers/net/wireless/ath/ath9k/channel.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/wireless/ath/ath9k/channel.c b/drivers/net/wireless/ath/ath9k/channel.c
index 8b27d8cc086a..cfb1c90eb4b6 100644
--- a/drivers/net/wireless/ath/ath9k/channel.c
+++ b/drivers/net/wireless/ath/ath9k/channel.c
@@ -1363,6 +1363,8 @@ void ath9k_init_channel_context(struct ath_softc *sc)
void ath9k_deinit_channel_context(struct ath_softc *sc)
{
+ timer_shutdown_sync(&sc->sched.timer);
+ timer_shutdown_sync(&sc->offchannel.timer);
cancel_work_sync(&sc->chanctx_work);
}
--
2.55.0
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCHv2 ath-next] wifi: ath9k: delete channel-context timers on deinit
2026-09-11 21:31 [PATCHv2 ath-next] wifi: ath9k: delete channel-context timers on deinit Rosen Penev
@ 2026-09-12 8:23 ` Toke Høiland-Jørgensen
2026-10-04 15:17 ` Jeff Johnson
2026-10-05 15:09 ` Jeff Johnson
1 sibling, 1 reply; 4+ messages in thread
From: Toke Høiland-Jørgensen @ 2026-09-12 8:23 UTC (permalink / raw)
To: Rosen Penev, linux-wireless; +Cc: open list
Rosen Penev <rosenp@gmail.com> writes:
> ath9k_deinit_channel_context() cancels chanctx_work but does not delete
> the offchannel and sched timers set up by ath9k_init_channel_context().
> If either timer fires after deinit (e.g. during driver unload or
> suspend), it accesses sc->sc_ah which may already be freed by
> ath9k_hw_deinit(), causing a use-after-free.
>
> Delete both timers with timer_shutdown_sync() before cancelling the work
> item.
>
> Assisted-by: LLM
> Signed-off-by: Rosen Penev <rosenp@gmail.com>
Acked-by: Toke Høiland-Jørgensen <toke@toke.dk>
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCHv2 ath-next] wifi: ath9k: delete channel-context timers on deinit
2026-09-12 8:23 ` Toke Høiland-Jørgensen
@ 2026-10-04 15:17 ` Jeff Johnson
0 siblings, 0 replies; 4+ messages in thread
From: Jeff Johnson @ 2026-10-04 15:17 UTC (permalink / raw)
To: Toke Høiland-Jørgensen, Rosen Penev, linux-wireless; +Cc: open list
On 9/12/2026 1:23 AM, Toke Høiland-Jørgensen wrote:
> Rosen Penev <rosenp@gmail.com> writes:
>
>> ath9k_deinit_channel_context() cancels chanctx_work but does not delete
>> the offchannel and sched timers set up by ath9k_init_channel_context().
>> If either timer fires after deinit (e.g. during driver unload or
>> suspend), it accesses sc->sc_ah which may already be freed by
>> ath9k_hw_deinit(), causing a use-after-free.
>>
>> Delete both timers with timer_shutdown_sync() before cancelling the work
>> item.
>>
>> Assisted-by: LLM
>> Signed-off-by: Rosen Penev <rosenp@gmail.com>
>
> Acked-by: Toke Høiland-Jørgensen <toke@toke.dk>
I'm picking this up now. Will add the following suggested by my review agent:
Fixes: 705d0bf83dbe ("ath9k: Add a routine for initializing channel contexts")
Cc: stable@vger.kernel.org # v6.2+
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCHv2 ath-next] wifi: ath9k: delete channel-context timers on deinit
2026-09-11 21:31 [PATCHv2 ath-next] wifi: ath9k: delete channel-context timers on deinit Rosen Penev
2026-09-12 8:23 ` Toke Høiland-Jørgensen
@ 2026-10-05 15:09 ` Jeff Johnson
1 sibling, 0 replies; 4+ messages in thread
From: Jeff Johnson @ 2026-10-05 15:09 UTC (permalink / raw)
To: linux-wireless, Rosen Penev
Cc: Toke Høiland-Jørgensen, linux-kernel
On Fri, 11 Sep 2026 14:31:44 -0700, Rosen Penev wrote:
> ath9k_deinit_channel_context() cancels chanctx_work but does not delete
> the offchannel and sched timers set up by ath9k_init_channel_context().
> If either timer fires after deinit (e.g. during driver unload or
> suspend), it accesses sc->sc_ah which may already be freed by
> ath9k_hw_deinit(), causing a use-after-free.
>
> Delete both timers with timer_shutdown_sync() before cancelling the work
> item.
>
> [...]
Applied, thanks!
[1/1] wifi: ath9k: delete channel-context timers on deinit
commit: 81394dfb9a7905472957628b560ae894eae3a30f
Best regards,
--
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-10-05 15:09 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-11 21:31 [PATCHv2 ath-next] wifi: ath9k: delete channel-context timers on deinit Rosen Penev
2026-09-12 8:23 ` Toke Høiland-Jørgensen
2026-10-04 15:17 ` Jeff Johnson
2026-10-05 15:09 ` Jeff Johnson
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®