From: sashiko-bot@kernel.org
To: "George Moussalem" <george.moussalem@outlook.com>
Cc: robh@kernel.org, conor+dt@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH ath-next 03/16] wifi: ath11k: Register root PD rproc notifier
Date: Wed, 23 Sep 2026 12:17:26 +0000 [thread overview]
Message-ID: <20260923121726.97C951F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260923-ipq5018-qcn6122-mpd-v1-3-86729521a75c@outlook.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] ath11k: firmware reset and recovery broken for non-MPD targets
- [High] ath11k: NULL pointer dereference in root PD notifier debug log
--
commit cebde61194c39a9cdbfb9178d0b280c99923a9c0
Author: George Moussalem <george.moussalem@outlook.com>
wifi: ath11k: Register root PD rproc notifier
This commit prepares for multi-PD support by registering the rproc notifier
for the Q6 rootPD. It handles booting the root PD and waiting for power-up
notification before proceeding, adding driver-level locking to avoid races.
> diff --git a/drivers/net/wireless/ath/ath11k/ahb.c b/drivers/net/wireless/ath/ath11k/ahb.c
> index 27d01411b6e9c..86723a2eb3d26 100644
> --- a/drivers/net/wireless/ath/ath11k/ahb.c
> +++ b/drivers/net/wireless/ath/ath11k/ahb.c
[ ... ]
> @@ -408,21 +415,12 @@ static void ath11k_ahb_stop(struct ath11k_base *ab)
>
> static int ath11k_ahb_power_up(struct ath11k_base *ab)
> {
> - struct ath11k_ahb *ab_ahb = ath11k_ahb_priv(ab);
> - int ret;
> -
> - ret = rproc_boot(ab_ahb->tgt_rproc);
> - if (ret)
> - ath11k_err(ab, "failed to boot the remote processor Q6\n");
> -
> - return ret;
> + return 0;
> }
>
> static void ath11k_ahb_power_down(struct ath11k_base *ab, bool is_suspend)
> {
> - struct ath11k_ahb *ab_ahb = ath11k_ahb_priv(ab);
> -
> - rproc_shutdown(ab_ahb->tgt_rproc);
> + return;
> }
[Severity: High]
Does making ath11k_ahb_power_up() and ath11k_ahb_power_down() empty stubs
break the firmware recovery mechanisms for non-MPD targets like IPQ8074?
When ath11k_qmi_fwreset_from_cold_boot() or ath11k_core_reset() are called,
they invoke ath11k_hif_power_down() and ath11k_hif_power_up(). If these
hardware operations do nothing, wouldn't the hardware fail to restart
during firmware crash recovery or cold boot calibration, leaving the WiFi
subsystem broken?
[ ... ]
> @@ -832,24 +830,200 @@ static const struct ath11k_hif_ops ath11k_ahb_hif_ops_wcn6750 = {
> .ce_irq_disable = ath11k_pci_disable_ce_irqs_except_wake_irq,
> };
>
> +static int ath11k_ahb_root_pd_state_notifier(struct notifier_block *nb,
> + const unsigned long event, void *data)
> +{
> + struct ath11k_ahb_rproc_info *rproc_info =
> + container_of(nb, struct ath11k_ahb_rproc_info, root_pd_nb);
> +
> + if (event == ATH11K_RPROC_AFTER_POWERUP) {
> + ath11k_dbg(NULL, ATH11K_DBG_AHB, "Root PD is UP\n");
[Severity: High]
Will passing a NULL pointer as the struct ath11k_base *ab argument to
ath11k_dbg() cause a kernel panic?
If debug logging or tracepoints are enabled, it looks like __ath11k_dbg()
will unconditionally dereference ab->dev, which would be triggered
automatically when the root PD powers up.
> + complete(&rproc_info->rootpd_ready);
> + }
> +
> + return 0;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260923-ipq5018-qcn6122-mpd-v1-0-86729521a75c@outlook.com?part=3
next prev parent reply other threads:[~2026-09-23 12:17 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 12:05 [PATCH ath-next 00/16] wifi: ath11k: add MultiPD support for AHB platforms George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 01/16] dt-bindings: net: wireless: ath11k: Sort compatible names alphabetically George Moussalem via B4 Relay
2026-09-28 10:45 ` Krzysztof Kozlowski
2026-09-23 12:05 ` [PATCH ath-next 02/16] dt-bindings: net: wireless: ath11k: Add bindings for IPQ5018 George Moussalem via B4 Relay
2026-09-23 12:14 ` sashiko-bot
2026-09-28 10:45 ` Krzysztof Kozlowski
2026-09-29 10:03 ` George Moussalem
2026-09-23 12:05 ` [PATCH ath-next 03/16] wifi: ath11k: Register root PD rproc notifier George Moussalem via B4 Relay
2026-09-23 12:17 ` sashiko-bot [this message]
2026-09-23 12:05 ` [PATCH ath-next 04/16] wifi: ath11k: Add support for loading m3 mbn firmware George Moussalem via B4 Relay
2026-09-23 12:15 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 05/16] wifi: ath11k: Add ability to set BDF and M3 dump memory addresses George Moussalem via B4 Relay
2026-09-23 12:18 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 06/16] firmware: qcom: scm: Add support for setting internal WiFi power mode George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 07/16] wifi: ath11k: Register userPD interrupts and SMEM entries George Moussalem via B4 Relay
2026-09-23 12:19 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 08/16] wifi: ath11k: Power up userPD George Moussalem via B4 Relay
2026-09-23 12:17 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 09/16] wifi: ath11k: Power down userPD George Moussalem via B4 Relay
2026-09-23 12:15 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 10/16] dt-bindings: net: wireless: ath11k: Add bindings for QCN6122 George Moussalem via B4 Relay
2026-09-23 12:17 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 11/16] wifi: ath11k: add hw params " George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 12/16] wifi: ath11k: add hal regs " George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 13/16] wifi: ath11k: add hw ring mask " George Moussalem via B4 Relay
2026-09-23 12:29 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 14/16] wifi: ath11k: update hif and pci ops " George Moussalem via B4 Relay
2026-09-23 12:05 ` [PATCH ath-next 15/16] wifi: ath11k: define userPDs " George Moussalem via B4 Relay
2026-09-23 12:28 ` sashiko-bot
2026-09-23 12:05 ` [PATCH ath-next 16/16] wifi: ath11k: add QCN6122 device support George Moussalem via B4 Relay
2026-09-23 12:25 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923121726.97C951F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=george.moussalem@outlook.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox