Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "George Moussalem" <george.moussalem@outlook.com>
Cc: robh@kernel.org, conor+dt@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH ath-next 03/16] wifi: ath11k: Register root PD rproc notifier
Date: Wed, 23 Sep 2026 12:17:26 +0000	[thread overview]
Message-ID: <20260923121726.97C951F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260923-ipq5018-qcn6122-mpd-v1-3-86729521a75c@outlook.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] ath11k: firmware reset and recovery broken for non-MPD targets
- [High] ath11k: NULL pointer dereference in root PD notifier debug log
--

commit cebde61194c39a9cdbfb9178d0b280c99923a9c0
Author: George Moussalem <george.moussalem@outlook.com>

wifi: ath11k: Register root PD rproc notifier

This commit prepares for multi-PD support by registering the rproc notifier
for the Q6 rootPD. It handles booting the root PD and waiting for power-up
notification before proceeding, adding driver-level locking to avoid races.

> diff --git a/drivers/net/wireless/ath/ath11k/ahb.c b/drivers/net/wireless/ath/ath11k/ahb.c
> index 27d01411b6e9c..86723a2eb3d26 100644
> --- a/drivers/net/wireless/ath/ath11k/ahb.c
> +++ b/drivers/net/wireless/ath/ath11k/ahb.c

[ ... ]

> @@ -408,21 +415,12 @@ static void ath11k_ahb_stop(struct ath11k_base *ab)
>  
>  static int ath11k_ahb_power_up(struct ath11k_base *ab)
>  {
> -	struct ath11k_ahb *ab_ahb = ath11k_ahb_priv(ab);
> -	int ret;
> -
> -	ret = rproc_boot(ab_ahb->tgt_rproc);
> -	if (ret)
> -		ath11k_err(ab, "failed to boot the remote processor Q6\n");
> -
> -	return ret;
> +	return 0;
>  }
>  
>  static void ath11k_ahb_power_down(struct ath11k_base *ab, bool is_suspend)
>  {
> -	struct ath11k_ahb *ab_ahb = ath11k_ahb_priv(ab);
> -
> -	rproc_shutdown(ab_ahb->tgt_rproc);
> +	return;
>  }

[Severity: High]
Does making ath11k_ahb_power_up() and ath11k_ahb_power_down() empty stubs
break the firmware recovery mechanisms for non-MPD targets like IPQ8074?

When ath11k_qmi_fwreset_from_cold_boot() or ath11k_core_reset() are called,
they invoke ath11k_hif_power_down() and ath11k_hif_power_up(). If these
hardware operations do nothing, wouldn't the hardware fail to restart
during firmware crash recovery or cold boot calibration, leaving the WiFi
subsystem broken?

[ ... ]

> @@ -832,24 +830,200 @@ static const struct ath11k_hif_ops ath11k_ahb_hif_ops_wcn6750 = {
>  	.ce_irq_disable = ath11k_pci_disable_ce_irqs_except_wake_irq,
>  };
>  
> +static int ath11k_ahb_root_pd_state_notifier(struct notifier_block *nb,
> +					     const unsigned long event, void *data)
> +{
> +	struct ath11k_ahb_rproc_info *rproc_info =
> +		container_of(nb, struct ath11k_ahb_rproc_info, root_pd_nb);
> +
> +	if (event == ATH11K_RPROC_AFTER_POWERUP) {
> +		ath11k_dbg(NULL, ATH11K_DBG_AHB, "Root PD is UP\n");

[Severity: High]
Will passing a NULL pointer as the struct ath11k_base *ab argument to
ath11k_dbg() cause a kernel panic?

If debug logging or tracepoints are enabled, it looks like __ath11k_dbg()
will unconditionally dereference ab->dev, which would be triggered
automatically when the root PD powers up.

> +		complete(&rproc_info->rootpd_ready);
> +	}
> +
> +	return 0;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260923-ipq5018-qcn6122-mpd-v1-0-86729521a75c@outlook.com?part=3

  reply	other threads:[~2026-09-23 12:17 UTC|newest]

Thread overview: 31+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23 12:05 [PATCH ath-next 00/16] wifi: ath11k: add MultiPD support for AHB platforms George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 01/16] dt-bindings: net: wireless: ath11k: Sort compatible names alphabetically George Moussalem via B4 Relay
2026-09-28 10:45   ` Krzysztof Kozlowski
2026-09-23 12:05 ` [PATCH ath-next 02/16] dt-bindings: net: wireless: ath11k: Add bindings for IPQ5018 George Moussalem via B4 Relay
2026-09-23 12:14   ` sashiko-bot
2026-09-28 10:45   ` Krzysztof Kozlowski
2026-09-29 10:03     ` George Moussalem
2026-09-23 12:05 ` [PATCH ath-next 03/16] wifi: ath11k: Register root PD rproc notifier George Moussalem via B4 Relay
2026-09-23 12:17   ` sashiko-bot [this message]
2026-09-23 12:05 ` [PATCH ath-next 04/16] wifi: ath11k: Add support for loading m3 mbn firmware George Moussalem via B4 Relay
2026-09-23 12:15   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 05/16] wifi: ath11k: Add ability to set BDF and M3 dump memory addresses George Moussalem via B4 Relay
2026-09-23 12:18   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 06/16] firmware: qcom: scm: Add support for setting internal WiFi power mode George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 07/16] wifi: ath11k: Register userPD interrupts and SMEM entries George Moussalem via B4 Relay
2026-09-23 12:19   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 08/16] wifi: ath11k: Power up userPD George Moussalem via B4 Relay
2026-09-23 12:17   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 09/16] wifi: ath11k: Power down userPD George Moussalem via B4 Relay
2026-09-23 12:15   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 10/16] dt-bindings: net: wireless: ath11k: Add bindings for QCN6122 George Moussalem via B4 Relay
2026-09-23 12:17   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 11/16] wifi: ath11k: add hw params " George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 12/16] wifi: ath11k: add hal regs " George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 13/16] wifi: ath11k: add hw ring mask " George Moussalem via B4 Relay
2026-09-23 12:29   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 14/16] wifi: ath11k: update hif and pci ops " George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 15/16] wifi: ath11k: define userPDs " George Moussalem via B4 Relay
2026-09-23 12:28   ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 16/16] wifi: ath11k: add QCN6122 device support George Moussalem via B4 Relay
2026-09-23 12:25   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923121726.97C951F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=george.moussalem@outlook.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox