From nobody Mon Feb 9 08:28:38 2026 Received: from mail-dy1-f176.google.com (mail-dy1-f176.google.com [74.125.82.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 240F832863E for ; Fri, 16 Jan 2026 01:05:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768525560; cv=none; b=iqrRMUmtDXXgPbLM62FdXA5pADIP/7CPYaJDkId2qRKBWrw6fcKdeQRCtngiBncwDPybLwMZ/71yPY9e6ryFL6hpbTfS7qFHMAVVP74176IHhPYVs6eVD0BaZxKDqec3jfT64TkjC5SGL4K9GAsOd/xjS8kOO2PFeXCPfEIlNeA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768525560; c=relaxed/simple; bh=ncrRr8O6tigVgbV546c9oteIZcBP9anuVJ5asckXJHA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=l/xXjP3Pp2qo4G6k4m5CALNHEvExaW7KobsF3dJ0aYAeQiJnRfsbGPYFT6wvgc/VKcJKAl0gwEPv4Z5dex3jIDlFPtfXa8rm0sbMP02bLKeOgzVhPBxtcFEIUxMSKCgTzYMoeTJJujw8RGrYFS0yNW4D4XkPl5WjavLSss9MWjs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=zacbowling.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=R6uFt4MI; arc=none smtp.client-ip=74.125.82.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=zacbowling.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="R6uFt4MI" Received: by mail-dy1-f176.google.com with SMTP id 5a478bee46e88-2ae2eb49b4bso3305612eec.0 for ; Thu, 15 Jan 2026 17:05:56 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1768525553; x=1769130353; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:sender:from:to:cc:subject:date :message-id:reply-to; bh=ewdMOqZu09vzVANg46kFx4cCu4Abbaa2QyPG4SOmwEs=; b=R6uFt4MIpXQzjITdhe4T8i7pgnRrnXPLdhehQ2ROl4lJgM8hKzgyudsIRzsFhg/Wnr G0p5Ip99dE1W7+vpHuXy5ojEO3FtyEucpSFE7udlOhj1y4zsBHKjmfqtQBmhF8APmY4K l9pNhF5NbNYx9NmInZj5G+5fFVwP+rErPhJgTYYOCttoATd42qgJ1GtAKQGRs2euq7HA 1uUTOo9gw95XufRdMxidzoP4kev7lhX+ybvvKmjnqTE0SKVlRDPYJ2uU5gg8/ZPOeyfU gSgEewsgFzzetUFbwhjMHAFD45EuzPaEXTN0THLdUNJoMxokjMip7oEcSZ0ytzTZyV8/ UsXw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1768525553; x=1769130353; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:sender:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=ewdMOqZu09vzVANg46kFx4cCu4Abbaa2QyPG4SOmwEs=; b=ibSz0j/MefLwAYv5kgBkksiwDvi3OIbKcl2wgEmEkEWu7WHqJaZLgZiWD30aIbEKRb iE/S8X1gzjQgDF7G5biKnFoSo80VylZb33Ez7s/9a5SjvgtWBduLGpqhwD0xeF+mcmkU aQpRIwZcXxCrMvaKDb9mNNrsF5u7r6CQmpFqGPoGFILbHPvFInYKbcJXhmpzD0bRi/xX btKNqvDiGDOlpaFJZZnpNudY13Diu04RIndsBHQQe/SXbMRgXNK+94Bz3/PljCceZ8Yl Fiag1656Q/7kELTZZXZ8G9YnWinP4p+b7nBiqDyHu/BfRHo7IfFhidtsE2RCulFfmEJ9 JUag== X-Forwarded-Encrypted: i=1; AJvYcCVYRkFxszlyi+DY79xkLdtIicnpkju/5WcHEhCubI65dPEb4hVZE3qusqKnpDx0z7YpP8RMVUpxWUMd7TI=@vger.kernel.org X-Gm-Message-State: AOJu0YxxqJ+P+WAuR7iVqrPPQPOqxiMAUTiyH740fRpk5roGNkTld7mX G8fLnCWD/xUKZ9sc+8CpUrVD+J7n4PThzZQ0Xr7vOTycjCE044bcDPpR X-Gm-Gg: AY/fxX6mJtV0odRNqhfeEbqYJN5AoS7oLBle/OnF3MY3pJ0UAdqK81i46QeMpKGLJde ls6oJjiO8E0FiPem+vN1iaEuY+JHdK93f98v0o6h+AGQ46uMzn6bL13GSTux/mzifrvP/YpST4X WG6Qdzm4hco53VaQ4bXfjyFE2m120Z23vSNTsyfcJFl0VHWUYkNSMYE7wJwXM77RhnlUdK0Haie 3xS4Oxk8F8CMU7Yggzn9EzMKzZsawCpNT8TpC7f6I5s7ppMCIf52RXLQ2vaOoA7HvhK3qMvX74p o7ArFPEsTmrhmMGfTPBvwiRAFP+fLr04qVcN+7Ur6SWmvilNKtPyoBL1IhsUq8uLNoWkA+kruY0 Ej/MlO7byoNI09FrkDjFtONBvVUBycDvFxp5r95TLc6inwrE4IcUqYeZTX6oolcPADYKil5EZOd kvYg5xnAxWbTF563eDIFV7/cruNoSNEqmwzFdHo+fK8xbw4bcPrZu4eGw6eYFnJOcRcWZ/lVMY X-Received: by 2002:a05:7301:1e90:b0:2ae:5020:afe1 with SMTP id 5a478bee46e88-2b6b402c47amr1281429eec.14.1768525552939; Thu, 15 Jan 2026 17:05:52 -0800 (PST) Received: from zcache.home.zacbowling.com ([2001:5a8:60d:bc9:f1d2:502c:a6ff:5556]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-2b6b367cbc9sm1019884eec.32.2026.01.15.17.05.51 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 15 Jan 2026 17:05:52 -0800 (PST) Sender: Zac Bowling From: Zac To: sean.wang@kernel.org Cc: deren.wu@mediatek.com, kvalo@kernel.org, linux-kernel@vger.kernel.org, linux-mediatek@lists.infradead.org, linux-wireless@vger.kernel.org, lorenzo@kernel.org, nbd@nbd.name, linux@frame.work, ryder.lee@mediatek.com, sean.wang@mediatek.com, Zac , Zac Bowling Subject: [PATCH v4 20/21] wifi: mt76: fix list corruption in mt76_wcid_cleanup Date: Thu, 15 Jan 2026 17:05:18 -0800 Message-ID: <20260116010519.37001-21-zac@zacbowling.com> X-Mailer: git-send-email 2.52.0 In-Reply-To: <20260116010519.37001-1-zac@zacbowling.com> References: <20260116010519.37001-1-zac@zacbowling.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" mt76_wcid_cleanup() was not removing wcid entries from sta_poll_list before mt76_reset_device() reinitializes the master list. This leaves stale pointers in wcid->poll_list, causing list corruption when mt76_wcid_add_poll() later checks list_empty() and tries to add the entry back. The fix adds proper cleanup of poll_list in mt76_wcid_cleanup(), matching how tx_list is already handled. This is similar to what mt7996_mac_sta_deinit_link() already does correctly. Fixes list corruption warnings like: list_add corruption. prev->next should be next (ffffffff...) Signed-off-by: Zac Bowling --- drivers/net/wireless/mediatek/mt76/mac80211.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/drivers/net/wireless/mediatek/mt76/mac80211.c b/drivers/net/wi= reless/mediatek/mt76/mac80211.c index 75772979f4..d0c522909e 100644 --- a/drivers/net/wireless/mediatek/mt76/mac80211.c +++ b/drivers/net/wireless/mediatek/mt76/mac80211.c @@ -1716,6 +1716,16 @@ void mt76_wcid_cleanup(struct mt76_dev *dev, struct = mt76_wcid *wcid) =20 idr_destroy(&wcid->pktid); =20 + /* Remove from sta_poll_list to prevent list corruption after reset. + * Without this, mt76_reset_device() reinitializes sta_poll_list but + * leaves wcid->poll_list with stale pointers, causing list corruption + * when mt76_wcid_add_poll() checks list_empty(). + */ + spin_lock_bh(&dev->sta_poll_lock); + if (!list_empty(&wcid->poll_list)) + list_del_init(&wcid->poll_list); + spin_unlock_bh(&dev->sta_poll_lock); + spin_lock_bh(&phy->tx_lock); =20 if (!list_empty(&wcid->tx_list)) --=20 2.52.0