* [PATCH] wifi: rtw88: pci: preserve the RX ring DMA address on cleanup
@ 2026-10-09 3:23 Hungyu Lin
2026-10-09 11:50 ` Luka Gejak
0 siblings, 1 reply; 2+ messages in thread
From: Hungyu Lin @ 2026-10-09 3:23 UTC (permalink / raw)
To: pkshih
Cc: linux-wireless, linux-kernel, pchelkin, mihaildimoski, tristan,
rtl8821cerfe2, dawei.feng, learn.rahul.rai, branislav.klocok,
timlee, kvalo, briannorris, yhchuang, sgruszka, Hungyu Lin
rtw_pci_init_rx_ring() stores the coherent ring DMA address in dma, but
reuses it for RX buffer DMA addresses during error cleanup. If
initialization fails after at least one buffer has been mapped,
dma_free_coherent() receives the last buffer's DMA address instead of
the ring's.
Use a separate variable for the buffer DMA addresses so the ring is
freed with the address returned by dma_alloc_coherent().
Fixes: e3037485c68e ("rtw88: new Realtek 802.11ac driver")
Signed-off-by: Hungyu Lin <dennylin0707@gmail.com>
---
drivers/net/wireless/realtek/rtw88/pci.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/realtek/rtw88/pci.c b/drivers/net/wireless/realtek/rtw88/pci.c
index 66d2e5f51444..10147375f3b2 100644
--- a/drivers/net/wireless/realtek/rtw88/pci.c
+++ b/drivers/net/wireless/realtek/rtw88/pci.c
@@ -298,11 +298,13 @@ static int rtw_pci_init_rx_ring(struct rtw_dev *rtwdev,
err_out:
for (i = 0; i < allocated; i++) {
+ dma_addr_t buf_dma;
+
skb = rx_ring->buf[i];
if (!skb)
continue;
- dma = *((dma_addr_t *)skb->cb);
- dma_unmap_single(&pdev->dev, dma, buf_sz, DMA_FROM_DEVICE);
+ buf_dma = *((dma_addr_t *)skb->cb);
+ dma_unmap_single(&pdev->dev, buf_dma, buf_sz, DMA_FROM_DEVICE);
dev_kfree_skb_any(skb);
rx_ring->buf[i] = NULL;
}
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] wifi: rtw88: pci: preserve the RX ring DMA address on cleanup
2026-10-09 3:23 [PATCH] wifi: rtw88: pci: preserve the RX ring DMA address on cleanup Hungyu Lin
@ 2026-10-09 11:50 ` Luka Gejak
0 siblings, 0 replies; 2+ messages in thread
From: Luka Gejak @ 2026-10-09 11:50 UTC (permalink / raw)
To: Hungyu Lin, pkshih
Cc: linux-wireless, linux-kernel, pchelkin, mihaildimoski, tristan,
rtl8821cerfe2, dawei.feng, learn.rahul.rai, branislav.klocok,
timlee, kvalo, briannorris, yhchuang, sgruszka
On Fri Oct 9, 2026 at 5:23 AM CEST, Hungyu Lin wrote:
> rtw_pci_init_rx_ring() stores the coherent ring DMA address in dma, but
> reuses it for RX buffer DMA addresses during error cleanup. If
> initialization fails after at least one buffer has been mapped,
> dma_free_coherent() receives the last buffer's DMA address instead of
> the ring's.
>
> Use a separate variable for the buffer DMA addresses so the ring is
> freed with the address returned by dma_alloc_coherent().
>
> Fixes: e3037485c68e ("rtw88: new Realtek 802.11ac driver")
> Signed-off-by: Hungyu Lin <dennylin0707@gmail.com>
> ---
> drivers/net/wireless/realtek/rtw88/pci.c | 6 ++++--
> 1 file changed, 4 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/net/wireless/realtek/rtw88/pci.c b/drivers/net/wireless/realtek/rtw88/pci.c
> index 66d2e5f51444..10147375f3b2 100644
> --- a/drivers/net/wireless/realtek/rtw88/pci.c
> +++ b/drivers/net/wireless/realtek/rtw88/pci.c
> @@ -298,11 +298,13 @@ static int rtw_pci_init_rx_ring(struct rtw_dev *rtwdev,
>
> err_out:
> for (i = 0; i < allocated; i++) {
> + dma_addr_t buf_dma;
> +
> skb = rx_ring->buf[i];
> if (!skb)
> continue;
> - dma = *((dma_addr_t *)skb->cb);
> - dma_unmap_single(&pdev->dev, dma, buf_sz, DMA_FROM_DEVICE);
> + buf_dma = *((dma_addr_t *)skb->cb);
> + dma_unmap_single(&pdev->dev, buf_dma, buf_sz, DMA_FROM_DEVICE);
> dev_kfree_skb_any(skb);
> rx_ring->buf[i] = NULL;
> }
This patch should cc stable so it gets backported. Besides that it
looks good to me. Ping-Ke maybe you can add Cc: stable@vger.kernel.org
when applying to your tree?
Reviewed-by: Luka Gejak <luka.gejak@linux.dev>
Best regards,
Luka Gejak
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-09 11:51 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-09 3:23 [PATCH] wifi: rtw88: pci: preserve the RX ring DMA address on cleanup Hungyu Lin
2026-10-09 11:50 ` Luka Gejak
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®