All of lore.kernel.org
 help / color / mirror / Atom feed
From: Lorenzo Bianconi <lorenzo@kernel.org>
To: ZeroBeat <ZeroBeat@gmx.de>
Cc: Johannes Berg <johannes@sipsolutions.net>,
	Linux regressions mailing list <regressions@lists.linux.dev>,
	Felix Fietkau <nbd@nbd.name>, Ryder Lee <ryder.lee@mediatek.com>,
	"linux-wireless@vger.kernel.org" <linux-wireless@vger.kernel.org>,
	LKML <linux-kernel@vger.kernel.org>,
	Kalle Valo <kvalo@kernel.org>
Subject: Re: [regression] mt76x2u: NULL pointer dereference since recent change to fix chanctx emulation for monitor mode
Date: Thu, 25 Jul 2024 17:57:05 +0200	[thread overview]
Message-ID: <ZqJ10ZKHPGM6LbsM@lore-desk> (raw)
In-Reply-To: <231c6ea5-b8a3-4500-b994-46a45b6ab515@gmx.de>

[-- Attachment #1: Type: text/plain, Size: 3428 bytes --]

> Just to mention it here. The regression has now reached the longterm kernel:
> affected devices: mt76 series (not affected mt7601u)
> 
> 
> before update:
> $ uname -r
> 6.6.40-2-lts
> 
> $ sudo hcxdumptool -i wlp5s0f4u2 --rcascan=active
> ^C
> 38 Packet(s) captured by kernel
> 0 Packet(s) dropped by kernel
> 14 PROBERESPONSE(s) captured
> 
> exit on sigterm
> 
> 
> 
> after update:
> $ uname -r
> 6.6.41-1-lts
> 
> $ sudo hcxdumptool -i wlp48s0f4u2u1 --rcascan=active
> ^C
> 0 Packet(s) captured by kernel
> 0 Packet(s) dropped by kernel
> Warning: too less packets received (monitor mode may not work as expected)
> Possible reasons:
>  no transmitter in range
>  frames are filtered out by BPF
>  driver is broken
> Warning: no PROBERESPONSES received (frame injection may not work as expected)
> Possible reasons:
>  no AP in range
>  frames are filtered out by BPF
>  driver is broken
>  driver does not support frame injection
> 
> exit on sigterm
> 
> 
> Best regards
> Mike

Hi,

I am looking into it. I will get back to you.

Regards,
Lorenzo

> 
> 
> 
> 
> 
> 
> Am 24.07.24 um 10:47 schrieb Johannes Berg:
> > On Wed, 2024-07-24 at 09:58 +0200, Linux regression tracking (Thorsten
> > Leemhuis) wrote:
> > > Hi, Thorsten here, the Linux kernel's regression tracker.
> > > 
> > > Johannes, Felix, Lorenzo, Ryder, I noticed a report about a regression
> > > in bugzilla.kernel.org that (for my untrained eyes) appears to be a bug
> > > in some code paths of mt76x2u that was exposed by 0d9c2beed116e6 ("wifi:
> > > mac80211: fix monitor channel with chanctx emulation") [v6.10-rc5,
> > > v6.9.7] from Johannes.
> > > 
> > > As many (most?) kernel developers don't keep an eye on the bug tracker,
> > > I decided to write this mail. To quote from
> > > https://bugzilla.kernel.org/show_bug.cgi?id=219086 :
> > > 
> > > >   Michael 2024-07-23 15:38:43 UTC
> > > > 
> > > > After a user opened this discussion:
> > > > https://github.com/ZerBea/hcxdumptool/discussions/465
> > > > 
> > > > Jul 21 05:40:39 rpi4b-aarch kernel: mt76x2u 2-2:1.0 wlan1: entered promiscuous mode
> > > > Jul 21 05:40:45 rpi4b-aarch kernel: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000
> > > > Jul 21 05:40:45 rpi4b-aarch kernel: Mem abort info:
> > > > Jul 21 05:40:45 rpi4b-aarch kernel:   ESR = 0x0000000096000044
> > > > Jul 21 05:40:45 rpi4b-aarch kernel:   EC = 0x25: DABT (current EL), IL = 32 bits
> > > > Jul 21 05:40:45 rpi4b-aarch kernel:   SET = 0, FnV = 0
> > > > Jul 21 05:40:45 rpi4b-aarch kernel:   EA = 0, S1PTW = 0
> > > > Jul 21 05:40:45 rpi4b-aarch kernel:   FSC = 0x04: level 0 translation fault
> > > > Jul 21 05:40:45 rpi4b-aarch kernel: Data abort info:
> > > > Jul 21 05:40:45 rpi4b-aarch kernel:   ISV = 0, ISS = 0x00000044, ISS2 = 0x00000000
> > > > Jul 21 05:40:45 rpi4b-aarch kernel:   CM = 0, WnR = 1, TnD = 0, TagAccess = 0
> > > > Jul 21 05:40:45 rpi4b-aarch kernel:   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0
> > > > Jul 21 05:40:45 rpi4b-aarch kernel: user pgtable: 4k pages, 48-bit VAs, pgdp=0000000041300000
> > > > 
> > 
> > Not too well-versed with ARM, does that tel me anything about where in
> > the code the crash was? Without any further information I don't think I
> > can see anything here, and I don't have an affected device.
> > 
> > johannes






[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

  reply	other threads:[~2024-07-25 15:57 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-07-24  7:58 [regression] mt76x2u: NULL pointer dereference since recent change to fix chanctx emulation for monitor mode Linux regression tracking (Thorsten Leemhuis)
2024-07-24  8:47 ` Johannes Berg
2024-07-24 16:12   ` ZeroBeat
2024-07-25 15:54   ` ZeroBeat
2024-07-25 15:57     ` Lorenzo Bianconi [this message]
2024-07-25 16:00       ` ZeroBeat

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ZqJ10ZKHPGM6LbsM@lore-desk \
    --to=lorenzo@kernel.org \
    --cc=ZeroBeat@gmx.de \
    --cc=johannes@sipsolutions.net \
    --cc=kvalo@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-wireless@vger.kernel.org \
    --cc=nbd@nbd.name \
    --cc=regressions@lists.linux.dev \
    --cc=ryder.lee@mediatek.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.