mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] wifi: ath11k: initialize CFR locks before capability checks
@ 2026-10-09  6:03 Runyu Xiao
  2026-10-09  6:57 ` Vasanthakumar Thiagarajan
  2026-10-09 22:07 ` Jeff Johnson
  0 siblings, 2 replies; 3+ messages in thread
From: Runyu Xiao @ 2026-10-09  6:03 UTC (permalink / raw)
  To: Jeff Johnson
  Cc: linux-wireless, ath11k, linux-kernel, stable, Runyu Xiao, Jianhao Xu

ath11k_cfr_init() returns before initializing cfr->lock when CFR
capability is absent.  However, station removal still calls
ath11k_cfr_decrement_peer_count(), which unconditionally takes this
lock.  This leaves a production path using an uninitialized spinlock.

Initialize cfr->lock for every radio before the capability check.  Keep
the CFR ring and lookup-table lock initialization conditional, since
those objects are only used after CFR capability setup.

Fixes: 9b2e3b4ebec7 ("wifi: ath11k: Add initialization and deinitialization sequence for CFR module")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
---
 drivers/net/wireless/ath/ath11k/cfr.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/net/wireless/ath/ath11k/cfr.c b/drivers/net/wireless/ath/ath11k/cfr.c
index a91f25fb6..0708ca28b 100644
--- a/drivers/net/wireless/ath/ath11k/cfr.c
+++ b/drivers/net/wireless/ath/ath11k/cfr.c
@@ -956,6 +956,9 @@ int ath11k_cfr_init(struct ath11k_base *ab)
 	struct ath11k *ar;
 	int i, ret;
 
+	for (i = 0; i < ab->num_radios; i++)
+		spin_lock_init(&ab->pdevs[i].ar->cfr.lock);
+
 	if (!test_bit(WMI_TLV_SERVICE_CFR_CAPTURE_SUPPORT, ab->wmi_ab.svc_map) ||
 	    !ab->hw_params.cfr_support)
 		return 0;
@@ -971,7 +974,6 @@ int ath11k_cfr_init(struct ath11k_base *ab)
 
 		idr_init(&cfr->rx_ring.bufs_idr);
 		spin_lock_init(&cfr->rx_ring.idr_lock);
-		spin_lock_init(&cfr->lock);
 		spin_lock_init(&cfr->lut_lock);
 
 		num_lut_entries = min_t(u32, CFR_MAX_LUT_ENTRIES, db_cap.min_elem);
-- 
2.34.1

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-09 22:08 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-09  6:03 [PATCH] wifi: ath11k: initialize CFR locks before capability checks Runyu Xiao
2026-10-09  6:57 ` Vasanthakumar Thiagarajan
2026-10-09 22:07 ` Jeff Johnson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®