From: Devin Wittmayer <lucid_duck@justthetip.ca>
To: Klara Modin <klarasmodin@gmail.com>
Cc: linux-wireless@vger.kernel.org,
linux-mediatek@lists.infradead.org, nbd@nbd.name,
lorenzo@kernel.org, regressions@lists.linux.dev
Subject: Re: [PATCH wireless] wifi: mt76: mt792x: fix NULL dereference in ACPI SAR init during probe
Date: Thu, 27 Aug 2026 18:17:37 -0700 [thread overview]
Message-ID: <20260828011737.22809-1-lucid_duck@justthetip.ca> (raw)
In-Reply-To: <ao3dyqWJ3nf3rMMW@soda.int.kasm.eu>
Thank you for the Tested-by, and for bisecting it in the first place. The
report arrived with the commit named and a revert confirmed, which is most of
the work already done.
Something odd, since we are on the same laptop. Mine is a Framework 13 that
shipped with an MT7922, and it has no MediaTek power tables at all. I checked
every ACPI table on the machine rather than only the main one, and there is
nothing there for any vendor. So your oops cannot fire here on the same model
with the same card, which is why I had to inject tables to reproduce it.
Which means the difference is somewhere in the firmware, and I can only see my
side of it. Mine is an Intel 11th generation board on BIOS 3.17, dated October
2022. What are you on? Whether these tables came with a later release or only
ever appeared on certain boards decides whether anyone else is about to walk
into this.
While you are in there, does your geo table carry 0xff in the unused slots?
Someone turned up on the list yesterday with an ASUS padded that way, which
the driver takes as roughly -1 dBm and clamps every rate down to it. Whether
that is one vendor's habit or common changes what the right fix looks like.
Devin
On 2026-08-25 11:27:15 +0000, Klara Modin wrote:
> On 2026-08-25 11:17:12 -0700, Devin Wittmayer wrote:
> > Some laptops carry a MediaTek power table in their firmware, and the
> > driver reads it to set a transmit limit for each frequency range. It
> > only fills in the ranges themselves when it registers the device.
> >
> > The startup step that does this existed already, but it never programmed
> > anything. These two commits made it run a regulatory update instead,
> > which sets the limits on the way through, long before registration. So on
> > a machine that has the table the driver reads through an empty pointer
> > and the interface never appears:
> >
> > BUG: kernel NULL pointer dereference, address: 0000000000000004
> > RIP: 0010:mt792x_init_acpi_sar_power
> > Call Trace:
> > mt7921_set_tx_sar_pwr
> > mt7921_mcu_regd_update
> > mt7921_regd_update
> > mt7921_run_firmware
> > mt7921e_mcu_init
> > mt7921_init_work
> >
> > Skip it when the ranges are missing. They are applied again once the
> > device is up, which is where they came from before.
> >
> > Reported-by: Klara Modin <klarasmodin@gmail.com>
> > Closes: https://lore.kernel.org/linux-wireless/aoyxqHYvSuaBeubf@soda.int.kasm.eu/
> > Fixes: 9b80bd9cab40 ("wifi: mt76: mt7921: add regulatory wiphy self manager support")
> > Fixes: e9f3f1cc133f ("wifi: mt76: mt7925: add regulatory wiphy self manager support")
> > Signed-off-by: Devin Wittmayer <lucid_duck@justthetip.ca>
> > ---
> >
> > Reproduced on both chips before sending, an MT7922 and an MT7925, and the
> > fix clears both. Neither machine here ships a vendor power table, so I
> > supplied one through an ACPI override in the initrd. It also wants recent
> > firmware. The June builds do not turn on self-managed regulatory and
> > nothing happens; the builds now in linux-firmware do, and then it dies
> > exactly as reported with no interface at all. Patched, both come up and
> > scan normally, and the injected limits still show through in the power
> > table afterwards, so the skip does not lose them.
> >
> > With that table still in place and the fix absent, backing out the mt7921
> > commit on its own also boots clean, so the table is not what causes this.
> >
>
> Thanks for the quick fix!
>
> Regards,
> Tested-by: Klara Modin <klarasmodin@gmail.com>
>
> > drivers/net/wireless/mediatek/mt76/mt792x_acpi_sar.c | 3 ++-
> > 1 file changed, 2 insertions(+), 1 deletion(-)
> >
> > diff --git a/drivers/net/wireless/mediatek/mt76/mt792x_acpi_sar.c b/drivers/net/wireless/mediatek/mt76/mt792x_acpi_sar.c
> > index 946dd7956e4a..b468051fbe68 100644
> > --- a/drivers/net/wireless/mediatek/mt76/mt792x_acpi_sar.c
> > +++ b/drivers/net/wireless/mediatek/mt76/mt792x_acpi_sar.c
> > @@ -323,7 +323,8 @@ int mt792x_init_acpi_sar_power(struct mt792x_phy *phy, bool set_default)
> > const struct cfg80211_sar_capa *capa = phy->mt76->hw->wiphy->sar_capa;
> > int i;
> >
> > - if (!phy->acpisar || !((struct mt792x_acpi_sar *)phy->acpisar)->dyn)
> > + if (!capa || !phy->acpisar ||
> > + !((struct mt792x_acpi_sar *)phy->acpisar)->dyn)
> > return 0;
> >
> > /* When ACPI SAR enabled in HW, we should apply rules for .frp
> > --
> > 2.55.0
> >
next prev parent reply other threads:[~2026-08-28 1:17 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-25 18:17 [PATCH wireless] wifi: mt76: mt792x: fix NULL dereference in ACPI SAR init during probe Devin Wittmayer
2026-08-25 18:27 ` Klara Modin
2026-08-28 1:17 ` Devin Wittmayer [this message]
2026-08-28 15:27 ` Klara Modin
2026-08-28 17:18 ` Devin Wittmayer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260828011737.22809-1-lucid_duck@justthetip.ca \
--to=lucid_duck@justthetip.ca \
--cc=klarasmodin@gmail.com \
--cc=linux-mediatek@lists.infradead.org \
--cc=linux-wireless@vger.kernel.org \
--cc=lorenzo@kernel.org \
--cc=nbd@nbd.name \
--cc=regressions@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox