From: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
To: Marek Szyprowski <m.szyprowski@samsung.com>,
Julius Bairaktaris <julius@bairaktaris.de>,
jjohnson@kernel.org
Cc: ath11k@lists.infradead.org, linux-wireless@vger.kernel.org,
linux-kernel@vger.kernel.org,
vasanthakumar.thiagarajan@oss.qualcomm.com,
rameshkumar.sundaram@oss.qualcomm.com
Subject: Re: [PATCH ath-next v2 2/2] wifi: ath11k: disable interrupts during firmware crash recovery
Date: Mon, 14 Sep 2026 14:32:37 +0800 [thread overview]
Message-ID: <dd342f3d-36d3-4a85-95ca-6cacb7b834ad@oss.qualcomm.com> (raw)
In-Reply-To: <a068a857-a549-4cc2-ae0f-3ef119d3a859@samsung.com>
On 9/11/2026 3:53 PM, Marek Szyprowski wrote:
> On 27.07.2026 00:19, Julius Bairaktaris wrote:
>> On IPQ8074 a firmware assert reboots the SoC:
>>
>> Unable to handle kernel read from unreadable memory at virtual address 0
>> pc : ath11k_hal_srng_access_begin+0xc/0x60 [ath11k]
>> lr : ath11k_dp_rx_process_mon_status+0x15c/0xd84 [ath11k]
>> Call trace:
>> ath11k_hal_srng_access_begin+0xc/0x60 [ath11k]
>> ath11k_dp_rx_process_mon_rings+0xa0/0x5d4 [ath11k]
>> ath11k_dp_service_srng+0x1f4/0x348 [ath11k]
>> ath11k_ahb_ext_grp_napi_poll+0x34/0xd4 [ath11k_ahb]
>> __napi_poll+0x38/0x188
>> net_rx_action+0x120/0x2c0
>>
>> ath11k_core_reconfigure_on_crash() tears the data path down with
>> ath11k_dp_pdev_free(), ath11k_dp_free() and ath11k_hal_srng_clear(),
>> which memsets the ring list. The DP NAPI is still running while that
>> happens, so it services a ring whose address pointer has just been
>> cleared.
>>
>> That function used to disable the interrupts first, until
>> commit d455e805de70 ("wifi: ath11k: rearrange IRQ enable/disable in reset path")
>> moved the disable into ath11k_core_reset(). reset_work is only queued
>> from mhi.c and from the debugfs hw-restart handler, so AHB parts never
>> run it on a real firmware crash. Their recovery goes QMI server exit ->
>> restart_work -> ath11k_core_reconfigure_on_crash() ->
>> ath11k_core_qmi_firmware_ready(), and nothing disables the interrupts
>> anywhere along it.
>>
>> Disable them again on the crash path. The reset path has already done
>> so by the time it gets here, hence the ab->is_reset check.
>>
>> This is also why the debugfs hw-restart trigger never showed the
>> problem: it goes through ath11k_core_reset(), the one path that still
>> had the disable.
>>
>> Tested-on: IPQ8074 hw2.0 AHB WLAN.HK.2.12-01460-QCAHKSWPL_SILICONZ-1
>>
>> Fixes: d455e805de70 ("wifi: ath11k: rearrange IRQ enable/disable in reset path")
>> Assisted-by: Claude:claude-opus-5
>> Signed-off-by: Julius Bairaktaris <julius@bairaktaris.de>
>
>
> This patch landed recently in linux-next as commit f7a74e131d3f ("wifi: ath11k:
> disable interrupts during firmware crash recovery"). In my tests I found that it
> causes a regression on QCOM RB5 board during system suspend/resume cycle
> (s2idle):
Hi @Marek, can you please try if below diff can fix this regression? Also, @Julis, can you
please also confirm if it can address your original issue as well?
diff --git a/drivers/net/wireless/ath/ath11k/core.c b/drivers/net/wireless/ath/ath11k/core.c
index d2ed6a0ea7e3..1ad0a47653de 100644
--- a/drivers/net/wireless/ath/ath11k/core.c
+++ b/drivers/net/wireless/ath/ath11k/core.c
@@ -1275,9 +1275,6 @@ int ath11k_core_suspend_late(struct ath11k_base *ab)
if (ab->actual_pm_policy == ATH11K_PM_WOW)
return 0;
- ath11k_hif_irq_disable(ab);
- ath11k_hif_ce_irq_disable(ab);
-
ath11k_hif_power_down(ab, true);
return 0;
@@ -2333,17 +2330,9 @@ static int ath11k_core_reconfigure_on_crash(struct ath11k_base *ab)
int ret;
mutex_lock(&ab->core_lock);
+ ath11k_hif_irq_disable(ab);
+ ath11k_hif_ce_irq_disable(ab);
ath11k_thermal_unregister(ab);
-
- /*
- * ath11k_core_reset() already disabled the interrupts on the reset
- * path; only the firmware crash path reaches here with them live.
- */
- if (!ab->is_reset) {
- ath11k_hif_irq_disable(ab);
- ath11k_hif_ce_irq_disable(ab);
- }
-
ath11k_dp_pdev_free(ab);
ath11k_cfr_deinit(ab);
ath11k_spectral_deinit(ab);
@@ -2605,9 +2594,6 @@ static void ath11k_core_reset(struct work_struct *work)
time_left = wait_for_completion_timeout(&ab->recovery_start,
ATH11K_RECOVER_START_TIMEOUT_HZ);
- ath11k_hif_irq_disable(ab);
- ath11k_hif_ce_irq_disable(ab);
-
ath11k_hif_power_down(ab, false);
ath11k_hif_power_up(ab);
--
2.34.1
next prev parent reply other threads:[~2026-09-14 6:32 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-26 22:19 [PATCH ath-next v2 0/2] wifi: ath11k: fix SoC reboot on firmware crash on AHB Julius Bairaktaris
2026-07-26 22:19 ` [PATCH ath-next v2 1/2] wifi: ath11k: implement CE interrupt enable/disable for AHB Julius Bairaktaris
2026-07-26 22:19 ` [PATCH ath-next v2 2/2] wifi: ath11k: disable interrupts during firmware crash recovery Julius Bairaktaris
[not found] ` <CGME20260911075315eucas1p1b4ffb1f57ef187e0a055072ccc0983e3@eucas1p1.samsung.com>
2026-09-11 7:53 ` Marek Szyprowski
2026-09-11 16:54 ` Jeff Johnson
2026-09-14 6:32 ` Baochen Qiang [this message]
2026-09-14 6:47 ` Julius Bairaktaris
2026-09-14 7:22 ` Marek Szyprowski
2026-09-20 16:42 ` Julius Bairaktaris
2026-09-21 3:17 ` Baochen Qiang
2026-09-21 6:32 ` Julius Bairaktaris
2026-07-31 3:07 ` [PATCH ath-next v2 0/2] wifi: ath11k: fix SoC reboot on firmware crash on AHB Baochen Qiang
2026-08-05 10:48 ` Julius Bairaktaris
2026-08-05 11:13 ` Rameshkumar Sundaram
2026-09-03 19:02 ` Jeff Johnson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=dd342f3d-36d3-4a85-95ca-6cacb7b834ad@oss.qualcomm.com \
--to=baochen.qiang@oss.qualcomm.com \
--cc=ath11k@lists.infradead.org \
--cc=jjohnson@kernel.org \
--cc=julius@bairaktaris.de \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=m.szyprowski@samsung.com \
--cc=rameshkumar.sundaram@oss.qualcomm.com \
--cc=vasanthakumar.thiagarajan@oss.qualcomm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®