Linux-mediatek Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Eason Lai <eason.lai@mediatek.com>
To: <nbd@nbd.name>, <lorenzo@kernel.org>
Cc: <linux-wireless@vger.kernel.org>,
	<linux-mediatek@lists.infradead.org>, <kun.wu@mediatek.com>,
	<deren.wu@mediatek.com>, <sean.wang@mediatek.com>,
	<quan.zhou@mediatek.com>, <ryder.lee@mediatek.com>,
	<leon.yen@mediatek.com>, <litien.chang@mediatek.com>,
	<jb.tsai@mediatek.com>, <jeff.hsu@mediatek.com>,
	<eason.lai@mediatek.com>, Jeff Hsu <Jeff.Hsu@mediatek.com>
Subject: [PATCH] wifi: mt76: mt7925: Fixes: Fix SER will panic when connect to AP
Date: Thu, 8 Oct 2026 13:24:53 +0800	[thread overview]
Message-ID: <20261008052453.3977058-1-eason.lai@mediatek.com> (raw)

From: Jeff Hsu <Jeff.Hsu@mediatek.com>

MAC reset(mt7925e_mac_reset) not check all the RX Q and stop napi
it will result racing then happen panic

kernel: wlp1s0: associated
kernel: wlp1s0: Limiting TX power to 30 (30 - 0) dBm as advertised by 02:0c:43:36:60:c8
kernel: ------------[ cut here ]------------
kernel: kernel BUG at net/core/dev.c:7436!
kernel: Oops: invalid opcode: 0000 [#1] SMP NOPTI
kernel: CPU: 1 UID: 0 PID: 459 Comm: kworker/u48:8 Tainted: G S         OE       6.17.0-061700-generic #202509282239 PREEMPT(voluntary)
kernel: Tainted: [S]=CPU_OUT_OF_SPEC, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE
kernel: Hardware name: HP HP ProDesk 600 G6 Microtower PC/8712, BIOS S02 Ver. 02.05.01 01/05/2021
kernel: Workqueue: mt76 mt7925_mac_reset_work [mt7925_common]
kernel: RIP: 0010:napi_enable_locked+0x1cb/0x220
kernel: Code: 48 c7 c7 10 2c 1e 87 e8 93 c4 2f 00 4c 8b 6d e0 e9 e9 fe ff ff e8 75 31 ff ff 48 8b 45 e0 48 8d 53 10 a8 01 0f 85 02 ff ff ff <0f> 0b 8b bb a0 01 00 00 48 83 c6 18 e8 04 59 20 ff 48 8b b3 e8 01
kernel: RSP: 0018:ffffd1e8418afd48 EFLAGS: 00010246
kernel: RAX: 0000000000000110 RBX: ffff8a2921952cf8 RCX: 0000000000000000
kernel: RDX: ffff8a2921952d08 RSI: 0000000000000000 RDI: 0000000000000000
kernel: RBP: ffffd1e8418afd68 R08: 0000000000000000 R09: 0000000000000000
kernel: R10: 0000000000000000 R11: 0000000000000000 R12: ffff8a2921955658
kernel: R13: 0000000000000110 R14: ffff8a2921952918 R15: ffff8a2921955758
kernel: FS:  0000000000000000(0000) GS:ffff8a3088300000(0000) knlGS:0000000000000000
kernel: CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
kernel: CR2: 0000561733e012d8 CR3: 000000011aa40005 CR4: 00000000003726f0
kernel: Call Trace:
kernel:  <TASK>
kernel:  napi_enable+0x25/0x50
kernel:  mt7925e_mac_reset+0x1a9/0x480 [mt7925e]
kernel:  mt7925_mac_reset_work+0x9a/0x1a0 [mt7925_common]
kernel:  ? __schedule+0x2f6/0x7c0
kernel:  process_one_work+0x18d/0x370
kernel:  worker_thread+0x33a/0x480
kernel:  ? _raw_spin_lock_irqsave+0xe/0x20
kernel:  ? __pfx_worker_thread+0x10/0x10
kernel:  kthread+0x108/0x220
kernel:  ? __pfx_kthread+0x10/0x10
kernel:  ret_from_fork+0x124/0x140
kernel:  ? __pfx_kthread+0x10/0x10
kernel:  ret_from_fork_asm+0x1a/0x30

Fixes: c4edf9e3e0e5 ("wifi: mt76: mt7925: replace shared rx irq masks with per-chip definitions")
Signed-off-by: Jeff Hsu <Jeff.Hsu@mediatek.com>
---
 .../net/wireless/mediatek/mt76/mt7925/pci_mac.c   | 15 +++++----------
 1 file changed, 5 insertions(+), 10 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/pci_mac.c b/drivers/net/wireless/mediatek/mt76/mt7925/pci_mac.c
index 2549d4e9e3a4..c3db814b2788 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7925/pci_mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/pci_mac.c
@@ -90,16 +90,11 @@ int mt7925e_mac_reset(struct mt792x_dev *dev)
 	mt76_txq_schedule_all(&dev->mphy);
 
 	mt76_worker_disable(&dev->mt76.tx_worker);
-	if (irq_map->rx.data_complete_mask)
-		napi_disable(&dev->mt76.napi[MT_RXQ_MAIN]);
-	if (irq_map->rx.wm_complete_mask)
-		napi_disable(&dev->mt76.napi[MT_RXQ_MCU]);
-	if (irq_map->rx.wm2_complete_mask)
-		napi_disable(&dev->mt76.napi[MT_RXQ_MCU_WA]);
-	if (is_mt7928(&dev->mt76) && (irq_map->rx.wm4_complete_mask))
-		napi_disable(&dev->mt76.napi[MT_RXQ_ICS]);
-	if (irq_map->tx.all_complete_mask)
-		napi_disable(&dev->mt76.tx_napi);
+
+	mt76_for_each_q_rx(&dev->mt76, i)
+		napi_disable(&dev->mt76.napi[i]);
+
+	napi_disable(&dev->mt76.tx_napi);
 
 	mt7925_tx_token_put(dev);
 	idr_init(&dev->mt76.token);
-- 
2.45.2



                 reply	other threads:[~2026-10-08  5:25 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261008052453.3977058-1-eason.lai@mediatek.com \
    --to=eason.lai@mediatek.com \
    --cc=deren.wu@mediatek.com \
    --cc=jb.tsai@mediatek.com \
    --cc=jeff.hsu@mediatek.com \
    --cc=kun.wu@mediatek.com \
    --cc=leon.yen@mediatek.com \
    --cc=linux-mediatek@lists.infradead.org \
    --cc=linux-wireless@vger.kernel.org \
    --cc=litien.chang@mediatek.com \
    --cc=lorenzo@kernel.org \
    --cc=nbd@nbd.name \
    --cc=quan.zhou@mediatek.com \
    --cc=ryder.lee@mediatek.com \
    --cc=sean.wang@mediatek.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox