From nobody Mon Sep 28 14:48:01 2026 Received: from mail-4319.protonmail.ch (mail-4319.protonmail.ch [185.70.43.19]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 87C6D4446F3; Thu, 20 Aug 2026 12:50:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=185.70.43.19 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787230210; cv=none; b=nHdTq3qZYkvvjI5EP4+mc4djJeMf2WCA6E3nWTJDY0hxiyAzHW31O5GtZgVCRgV4wWIn6MGdP3SOQlFY5gDSVysrK3EoU5agnb2odYQlJqLbhwTOEk6mERpb+vQ4Oa/MRvgdZvhN5iuRMTX54gZxPfOcgfYoNrf4Xl982QQtj3M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787230210; c=relaxed/simple; bh=MluMhfnxSFFI8oqFjDLQfkIsKgi0izjj8u1gxqAmbmI=; h=Date:To:From:Cc:Subject:Message-ID:MIME-Version:Content-Type; b=nH3rjGZ1J8j3cWGDtkppZ2V9HmIllMSHZWtBLNqvMonaDF7bc+3+OXslLI0SC0hNSzBtRpldFGG2iMqoHRpgNAgYLPiBlTW15x/N21Pmj2LTtGmPobxCaz2YNGHshD+9MlmjMuH8HcLLtoB6zTsZAUyV1epMbckuAnql2maqT9Q= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=protonmail.com; spf=pass smtp.mailfrom=protonmail.com; dkim=pass (2048-bit key) header.d=protonmail.com header.i=@protonmail.com header.b=IzoqAMrm; arc=none smtp.client-ip=185.70.43.19 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=protonmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=protonmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=protonmail.com header.i=@protonmail.com header.b="IzoqAMrm" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=protonmail.com; s=protonmail3; t=1787230200; x=1787489400; bh=MluMhfnxSFFI8oqFjDLQfkIsKgi0izjj8u1gxqAmbmI=; h=Date:To:From:Cc:Subject:Message-ID:Feedback-ID:From:To:Cc:Date: Subject:Reply-To:Feedback-ID:Message-ID:BIMI-Selector; b=IzoqAMrm8M+cJ281Qv1SirZK3czDeEDD0DdBx1yNlB66htP7fAZZouXnMJjFK5rNo 6UboIPbLcRQwc2PI7rbJtX1xh7pEzPr79ljP1YWgVvUWwSvr/pfBVn1GXuhC2t3Bha sWaXuvhlsARAvZDZju4/p7g/lz6PkdAS2jhOzQ4GTzDQae1VOzuZMKDWPFKs3lQCTb 30fbbe77hwK1T6ImRjHwEoPIE4FwS8yhV5wSy5/5M7LGNW5F56fGIh44lM36QpPh3a eF14pvc52Yd2sqZtcn6Z/Zbtw4qrbuO9EoSHlbZfFmNj6hPBnVt6rbCAM7MWT4hicZ toFmBjktedplg== Date: Thu, 20 Aug 2026 12:49:55 +0000 To: Felix Fietkau , Lorenzo Bianconi , Ryder Lee , Shayne Chen , Sean Wang , Matthias Brugger , AngeloGioacchino Del Regno , Peter Chiu From: Ryan Leung Cc: linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-mediatek@lists.infradead.org, Ryan Leung Subject: [PATCH mt76] wifi: mt76: mt7915: publish wcid before MCU add commands Message-ID: <20260820-mt7915-wcid-publish-order-v1-1-79d2bc981d8b@protonmail.com> Feedback-ID: 184418679:user:proton X-Pm-Message-ID: 0e088586e06f860360d23c1e030fb46a5057ac8c Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" mt7915_add_interface() enables the BSS/STA in firmware via mt7915_mcu_add_bss_info() and mt7915_mcu_add_sta() before publishing dev->mt76.wcid[idx] with rcu_assign_pointer(). Firmware can start generating tx-status/tx-free events referencing that wcid as soon as it processes those MCU commands, but mt76's rx/tx-free handlers (e.g. mt7915_mac_tx_free()) look up dev->mt76.wcid[idx] to service them, and won't find it published yet. This can lead to memory corruption and kernel crashes shortly after an AP interface is brought up. This ordering was introduced by commit 8e3e7567b8c1 ("mt76: mt7915: add sta_rec with EXTRA_INFO_NEW for the first time only"): mt7915_mcu_add_sta() derived its "newly added" flag from !rcu_access_pointer(dev->mt76.wcid[idx]), so the publish had to happen after that call. Commit 33eb14f10290 ("wifi: mt76: mt7915: use mac80211 .sta_state op") later replaced that flag with a caller-supplied `newly` argument to mt7915_mcu_add_sta(), now simply hardcoded to true, so the ordering is no longer required. Move the rcu_assign_pointer() before the MCU add_bss_info/add_sta calls, so that the wcid is visible to lookups before firmware is told it's live. This mirrors mt7915_remove_interface(), which already clears the pointer before the corresponding MCU disable calls. Closes: https://github.com/openwrt/openwrt/issues/24594 Fixes: 8e3e7567b8c1 ("mt76: mt7915: add sta_rec with EXTRA_INFO_NEW for the= first time only") Signed-off-by: Ryan Leung --- drivers/net/wireless/mediatek/mt76/mt7915/main.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/main.c b/drivers/net= /wireless/mediatek/mt76/mt7915/main.c index a8286f8becf9..9c6c339f1b38 100644 --- a/drivers/net/wireless/mediatek/mt76/mt7915/main.c +++ b/drivers/net/wireless/mediatek/mt76/mt7915/main.c @@ -273,9 +273,9 @@ static int mt7915_add_interface(struct ieee80211_hw *hw, mt7915_init_bitrate_mask(vif); memset(&mvif->cap, -1, sizeof(mvif->cap)); =20 + rcu_assign_pointer(dev->mt76.wcid[idx], &mvif->sta.wcid); mt7915_mcu_add_bss_info(phy, vif, true); mt7915_mcu_add_sta(dev, vif, NULL, CONN_STATE_PORT_SECURE, true); - rcu_assign_pointer(dev->mt76.wcid[idx], &mvif->sta.wcid); =20 mutex_unlock(&dev->mt76.mutex); =20 --- base-commit: ca800a9302764c445de0da0e84d2252400a770ee change-id: 20260820-mt7915-wcid-publish-order-bebef551330c Best regards, -- =20 Ryan Leung