From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DD7FF3A1A27 for ; Sun, 5 Jul 2026 19:15:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783278914; cv=none; b=nRnRNwQm7E4pMuyTqNSbhqJeL3D/NYW5kBJoQ7/oNJVMttZ+2ACbYCVWHHrh5Qw+l5ystoEmM5H9XIJRlffG2hfehdFAWpUIbZ1OOQA2wFgGzOXgLJpB3+FJmFhEi5AVOovthFkPIwHUgmGOgAhIv/JEJmrqW8QYBxWcz7SBKnM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783278914; c=relaxed/simple; bh=44lM3DRPYiy11Cw67gCIsslslOmao7q+J1d0JTufAW8=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=c1aQBq1l4lZdsIPTz355cCZKNHOwpPoLJ/DCRgon1tdHFPcKV9Ik3SpxuUzSyJWDhwNTnDdQm3bFcMobCfoChFWv8ugy+stLHAMO87sP3I0udcp11MA4BDGEXuPYdH/houyTFL9Sf+eZf10V2yZgtePvkPmr+XHpS4NV9a/nwLg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=RYYoPstc; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=KLMxYOTS; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="RYYoPstc"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="KLMxYOTS" Received: from pps.filterd (m0279862.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 665HiJeZ2201193 for ; Sun, 5 Jul 2026 19:15:12 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= JzHURdlTBy4HGtMk9pPhO21TM4DbHArmKo3PXiJCc4k=; b=RYYoPstc/ElDH0lQ +9fg1uQrsS0yv/soaDeKupGZTFCQ4bqXSRUZbtYo1LjUlL/9osR7Y08YMWl8BYyF 4GZCWEd/IeHOKcrAfTOHWuiP6SQn3l4LcVpsS8T2yT5mCAmHn9tVP4azsSQAhFV6 Tu0AgiRGkle6VATOVPsBbNUInpeUP8Zg1P9QHRt+plhYFTAQLVHZENXC4Yc7QKhB Oot0k/6BeP7Opqy9XxUjQnkLDK9rnlZhXlWrOG0XFRnJz5hmma14wKXFWSstn/jl kgBkKXAOMVT7RLlymwWiZ1dviuUQbl3coHy5nZUp6fjVLC1UPB274OnQHGQQLQ36 9tOkkg== Received: from mail-pl1-f197.google.com (mail-pl1-f197.google.com [209.85.214.197]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4f6txek600-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Sun, 05 Jul 2026 19:15:11 +0000 (GMT) Received: by mail-pl1-f197.google.com with SMTP id d9443c01a7336-2cc73f47bdcso20995395ad.3 for ; Sun, 05 Jul 2026 12:15:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1783278911; x=1783883711; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:content-language:from :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=JzHURdlTBy4HGtMk9pPhO21TM4DbHArmKo3PXiJCc4k=; b=KLMxYOTSFh44OyRyzZo7IJvu45c/gNgXjKSHDJAOGM6h0EQzdgonygcOHBa3p+fpKI 4w7CMCIbR0CxXJiYtwEAyiVddi2fMoGyOvU/dNc/3m0ctB2Hip8HYMSQz3iSw0qO22sk h8F9jHKUB4qVYA90iHtKlvQ5L3swcNGW5XcPc4OwduOrFrbwNhOhlDMa9Ytr2acC6x65 PmsdAPX5cSg4o4bnnOaV1cLr4CZ3KvOVUQVGroIhvteuPpA0Mc9BvKPTnowfaeCfv2Ze bj57iBIO5/D6doJIgH5EtgxWMfItWArTeoP0lP5krb4mkLqoeyGnCgYJpx/AZpu/yRcd Y8aA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783278911; x=1783883711; h=content-transfer-encoding:in-reply-to:content-language:from :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=JzHURdlTBy4HGtMk9pPhO21TM4DbHArmKo3PXiJCc4k=; b=cne64CJSVEjftNdNZSxoCSwSVfqZLlvFoVZ98uNm0UdRF4rNFObXf5SMwego2r2eSf nm8MblIdBob+ys6CR/lnIWnsn3L2M958skWbYUG5OMIphDbOwShR6GGoWk/rUiPPXkqJ uGj4Yj7CsR4yMdHCHvnqx+CL613t3WQ4BFQgZc3d26mj2Tuq0vmcZzXhNTupSylZZN+w Yf1R+a4xXfOj6rVwXDbvOd+RMMaT9ScgCYyWZ8egWa4/9fG8121GmxEvYn1YoG3oGHLI Kt8ommlbn7VuetYBKrZKPynk1E/OB8qPVRGovMXkT30VwQ6BHxG4cFrZhZUD1fBCcL+y X7Jw== X-Forwarded-Encrypted: i=1; AHgh+RpAShdXPQCNSGpTeNq1WpdhPRv7nNXgnwcVJj73IRpe8PlJGwg2zyJOHylo22ie3BOzsnhWS2mHUbMuX68=@vger.kernel.org X-Gm-Message-State: AOJu0Yyf6YGI+OOCYe+8KeueWmAHsulsRSyTsolbuK+IRIc1R9eiLW+T mXkh4XmDpBOQl55rz8EBHlele6TaEZ8NzgIVFz0tbQmFH4V4CkGpvo6TycquBJwl81Qd+CahXAM lofO4K/VlGXBrT51JcexFB/CdYg5tdAffxYTgwTfhAXujXkYaXHkJoLfCEEmczQUnI8s= X-Gm-Gg: AfdE7cknjV+gWKRFPbrDaoV1JnR238ZWj5UXb1H4pD1Np2BWTx1aNrIF7FZZ4utltig 1ko3fVAWXi295O7Z2XJL2blN6420sBUqblQit24zIYHAwAVogVF2dTzZcPhaMbKgbBOuNWG/Oh/ DyZ/RugjfbSvCu0wyJloBoPGa5GDZMTiqChnwug5hRY/UEr1MDyakAs11w0KL7oSqNFVnjtHj0Y VmEAg8ArPkLKnL8a5gYrHxIuJ42acswHrCYkaiUuUukNp8ohwnnxMIRVef9zXVWtN+2/wmx5Zrs WkhtvQ3emq0bBOGtFE9QfCPAA/5hw/gJ3rgOL2XysHMvLeta8B7Q//yLOcME3K8s6gCgEEZk9Gj 32qYIBHFwumfrsEJdm01pB/TzlsFYFcCGLQrdOwcpHQWTkKvVTZ0v5HPP+r+S2+eefrhj X-Received: by 2002:a17:903:3202:b0:2ca:d151:382d with SMTP id d9443c01a7336-2cbb9e38d1cmr78131155ad.14.1783278910876; Sun, 05 Jul 2026 12:15:10 -0700 (PDT) X-Received: by 2002:a17:903:3202:b0:2ca:d151:382d with SMTP id d9443c01a7336-2cbb9e38d1cmr78130605ad.14.1783278909958; Sun, 05 Jul 2026 12:15:09 -0700 (PDT) Received: from [192.168.1.11] (222.sub-97-215-84.myvzw.com. [97.215.84.222]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13b492a088fsm31335582c88.15.2026.07.05.12.15.08 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sun, 05 Jul 2026 12:15:09 -0700 (PDT) Message-ID: Date: Sun, 5 Jul 2026 12:15:07 -0700 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v2] ath12k: fix NULL pointer dereference in rhash table destroy To: Vasanthakumar Thiagarajan , Jose Ignacio Tornos Martinez , jjohnson@kernel.org Cc: linux-wireless@vger.kernel.org, ath12k@lists.infradead.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org References: <20260615112103.601982-1-jtornosm@redhat.com> From: Jeff Johnson Content-Language: en-US In-Reply-To: Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Proofpoint-Spam-Info: AW1haW4tMjYwNzA1MDIwOCBTYWx0ZWRfX811P2yvOIDWx VIs3fXUr2sqegRIDjO3hADtDvMjX25D3Dg2NwjDfkB1ytj+mhOJoO6PNQR6rjccNFI/7UWuBryv oihovQp+sjEytRRCINwT9gfE9tT+qss= X-Proofpoint-GUID: Y4ZHy71j29u0JUuR9GstdKzIOLCz12TV X-Proofpoint-ORIG-GUID: Y4ZHy71j29u0JUuR9GstdKzIOLCz12TV X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNzA1MDIwOCBTYWx0ZWRfX/ZnG325wRbjY m9hCyZaFQNV8241ejynpbZOqx5CenYcsVickYPe5kxCxSDGt8Zj6gTdHx5cK8d5PZe/ifn9vq4q N4X8/FDK4UKOlmzH4VkyC3vhr4tcFzm8OwBEst3IqzcmSIy1pkUCMJzqfvhnJpa1bGDrn3OfIgm eCWAkHkRZpc1c2my0VY7arpWWHJmup1tJBiDUuclmaOkwCdHJpfuRcsrvoGezD4HT4OUC+GBppd 5J+YKTlqPgm5Yc+H3KRT+9wYlo2KUTXyJy18mAnhekFr9lyNg0OZ7H4KX73o3Hrx8kLxUjCXEez AfeSNWGZ43rKHcPWNDZ+YqwL8FiJAbKa0XzOEg/z+Ztycmo67pydoqpd9yYL3oDbIsEx2ywIQ2c X0ZDaKQP0wiAmvDd45tnrpTMJhw+Y6yah6fdl4QuvaO30ATpET6rGfY4U7AZ59XrGVj5jMhqKni FKdRiAGbEMDAwNSFB8A== X-Authority-Analysis: v=2.4 cv=HLLz0Itv c=1 sm=1 tr=0 ts=6a4aad3f cx=c_pps a=cmESyDAEBpBGqyK7t0alAg==:117 a=i4k25I72rCCN9bAAQd7+Jg==:17 a=IkcTkHD0fZMA:10 a=RAioF0-LDSMA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=_K5XuSEh1TEqbUxoQ0s3:22 a=VwQbUJbxAAAA:8 a=20KFwNOVAAAA:8 a=EUspDBNiAAAA:8 a=TRTaysboXGgomUBcWKUA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 a=1OuFwYUASf3TG4hYMiVC:22 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-07-05_01,2026-07-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 priorityscore=1501 clxscore=1015 suspectscore=0 impostorscore=0 phishscore=0 adultscore=0 malwarescore=0 lowpriorityscore=0 spamscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2607050208 On 7/5/2026 10:27 AM, Vasanthakumar Thiagarajan wrote: > > > On 7/5/2026 10:53 PM, Vasanthakumar Thiagarajan wrote: >> >> >> On 6/15/2026 4:51 PM, Jose Ignacio Tornos Martinez wrote: >>> When unbinding the ath12k driver, kernel NULL pointer dereferences >>> occur in irq_work_sync() called from rhashtable_destroy(). >>> >>> Two hash tables are affected: >>> 1. ath12k_link_sta hash table in ath12k_base >>> 2. ath12k_dp_link_peer hash table in ath12k_dp >>> >>> The issue happens because the destroy functions are called unconditionally >>> in cleanup paths, but the hash tables are only initialized late in their >>> respective init functions. If the device was never fully started or if the >>> init functions failed before initializing the hash tables, the pointers >>> will be NULL. The issues are always reproducible from a VM because the MSI >>> addressing initialization is failing. >>> >>> Call trace for ath12k_link_sta_rhash_tbl_destroy: >>>   RIP: irq_work_sync+0x1e/0x70 >>>   rhashtable_destroy+0x12/0x60 >>>   ath12k_link_sta_rhash_tbl_destroy+0x19/0x40 [ath12k] >>>   ath12k_core_stop+0xe/0x80 [ath12k] >>>   ath12k_core_hw_group_cleanup+0x6b/0xb0 [ath12k] >>>   ath12k_pci_remove+0x60/0x110 [ath12k] >>> >>> Call trace for ath12k_dp_link_peer_rhash_tbl_destroy: >>>   RIP: irq_work_sync+0x1e/0x70 >>>   rhashtable_destroy+0x12/0x60 >>>   ath12k_dp_link_peer_rhash_tbl_destroy+0x29/0x50 [ath12k] >>>   ath12k_dp_cmn_device_deinit+0x21/0x140 [ath12k] >>>   ath12k_core_hw_group_cleanup+0x6b/0xb0 [ath12k] >>>   ath12k_pci_remove+0x60/0x110 [ath12k] >>> >>> Fix this by adding NULL checks before calling rhashtable_destroy() in >>> both destroy functions. >>> >>> The NULL check approach was chosen because the rhashtable pointer >>> serves as the initialization state indicator. The init can fail at >>> various points, leaving some components uninitialized. Checking the >>> pointer directly is simpler than adding separate state flags that >>> would need synchronization. >>> >>> Fixes: 57ccca410237 ("wifi: ath12k: Add hash table for ath12k_link_sta in ath12k_base") >>> Fixes: a88cf5f71adf ("wifi: ath12k: Add hash table for ath12k_dp_link_peer") >>> Cc: stable@vger.kernel.org >>> Signed-off-by: Jose Ignacio Tornos Martinez >> >> Reviewed-by: Vasanthakumar Thiagarajan > > Missed to mention that pls add wifi prefix to the patch title. I'll fix this in my pending branch. /jeff