From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mta0.migadu.com (out-47.mta0.migadu.com [91.218.175.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A4B76385D68 for ; Thu, 10 Sep 2026 03:11:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.47 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789009879; cv=none; b=kv2vGTfL0wtjt+fJGSDN3yO4wHXPD0IG3kMW4rd5sa7PrvUBVF1iycnepP+iLep8mt7+PtcWmp4dWecANb8ddCuaVCcGpWATdWOs06uMCXnBYhXRf6FaoX+w68vhUI2g+Qe2L2GXyr4Wlhh6yF7RG4iXJYOodr9heyv8WBFZiUM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789009879; c=relaxed/simple; bh=eT6Rs+Bqe2GzErT0DYERaLhJHKGVCA/meei3BWCpq7M=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=fg74mgc9p8YrYKdnYQHyn5cKQhf+eiTgQFixPRXE8Q96d8ts4fiP3SMs/HYEvqADMyt+Ch/lGkLAqNTLXiEcSc1nO3Jj+jW3uF9ISz2pASB6aSi07IW/2Y463/V2qS0Hc9oFSPQAtY415nei3pMWjIynLWq31t2TJ25DxDlJMTw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=justthetip.ca; spf=pass smtp.mailfrom=justthetip.ca; dkim=pass (2048-bit key) header.d=justthetip.ca header.i=@justthetip.ca header.b=T2+0YKee; arc=none smtp.client-ip=91.218.175.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=justthetip.ca Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=justthetip.ca Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=justthetip.ca header.i=@justthetip.ca header.b="T2+0YKee" X-Envelope-To: linux-wireless@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=eT6Rs+Bqe2GzErT0DYERaLhJHKGVCA/meei3BWCpq7M=; c=simple/simple; d=justthetip.ca; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1789009872; v=1; x=1789614672; b=T2+0YKee/0G/0/oKfvw9Li3cgqLsRnUt+j4BwZa3nroakf5CRejD8CYgaJBg8dJKxBCnhI/d 1aNivRu8zMdWhnfn1tmjBiJbNrwF0qBbLSJNX3uP7U8dOB7LFnAPEb1QSlGE8Wr4iK5/VNGnptf lOSW4XwaL1m6LuwAei7Z13hqZgB1fuegw4rpEezlLjDlX12GDn1BiOlDJT2p7qv4Bo5VLzNME5f qm/i5LB/eM9NLQ9y6w5ALrx+3eTJ5ToL+6JvIOwouBbw6Xmouk7o/4sYzQ4TX9qS6SseNel5Go1 rs9Bmom1iF9tmSeI2PoOHRJ3+r0/qHAlE7v7fV/y65png== X-Envelope-To: linux-wireless@vger.kernel.org Received: by smtp.migadu.com with ESMTPS id 6bba01725542afbb; Thu, 10 Sep 2026 03:11:12 +0000 X-Mizu-Trace-ID: 6bba01725542afbb X-Migadu-Flow: FLOW_OUT From: Devin Wittmayer To: stable@vger.kernel.org Cc: Felix Fietkau , Wentao Guan , linux-wireless@vger.kernel.org Subject: [PATCH 6.18.y 2/2] wifi: mt76: mt7925: cancel pending mlo_pm_work Date: Wed, 9 Sep 2026 20:11:02 -0700 Message-ID: <20260910031106.25906-3-lucid_duck@justthetip.ca> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260910031106.25906-1-lucid_duck@justthetip.ca> References: <20260910031106.25906-1-lucid_duck@justthetip.ca> Precedence: bulk X-Mailing-List: linux-wireless@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Wentao Guan commit 2889e84282dda147f10b10d94cf0efd90a349c53 upstream. If the device is reset, suspended or unregistered within that window, the pending work can still run and access vif/bss data that may already be freed, or send MCU commands while the firmware is not available. Add cancel_delayed_work_sync(&dev->mlo_pm_work) in all relevant teardown and suspend paths: - mt7925_mac_reset_work() (chip reset recovery) - mt7925e_unregister_device() (PCIe unbind) - mt7925_pci_suspend() (PCIe bus suspend) - mt7925_suspend() (mac80211 suspend) - mt7925u_suspend() (USB bus / runtime suspend) This ensures the work is stopped before the device state becomes invalid. Assisted-by: kimi-cli:kimi-k2.7 code Assisted-by: atomcode:glm-5.2 #Reported-by Fixes: 276a568832577 ("wifi: mt76: mt7925: update the power-saving flow") Cc: stable@vger.kernel.org Signed-off-by: Wentao Guan Signed-off-by: Devin Wittmayer --- diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/mac.c b/drivers/net/wireless/mediatek/mt76/mt7925/mac.c index 18f99d6..f9980b5 100644 --- a/drivers/net/wireless/mediatek/mt76/mt7925/mac.c +++ b/drivers/net/wireless/mediatek/mt76/mt7925/mac.c @@ -1312,6 +1312,7 @@ void mt7925_mac_reset_work(struct work_struct *work) cancel_delayed_work_sync(&dev->mphy.mac_work); cancel_delayed_work_sync(&pm->ps_work); + cancel_delayed_work_sync(&dev->mlo_pm_work); cancel_work_sync(&pm->wake_work); for (i = 0; i < 10; i++) { diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/main.c b/drivers/net/wireless/mediatek/mt76/mt7925/main.c index d22e25b..8ef0d98 100644 --- a/drivers/net/wireless/mediatek/mt76/mt7925/main.c +++ b/drivers/net/wireless/mediatek/mt76/mt7925/main.c @@ -1502,6 +1502,7 @@ static int mt7925_suspend(struct ieee80211_hw *hw, cancel_delayed_work_sync(&phy->mt76->mac_work); cancel_delayed_work_sync(&dev->pm.ps_work); + cancel_delayed_work_sync(&dev->mlo_pm_work); mt76_connac_free_pending_tx_skbs(&dev->pm, NULL); mt792x_mutex_acquire(dev); diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/pci.c b/drivers/net/wireless/mediatek/mt76/mt7925/pci.c index d6732f5..7972111 100644 --- a/drivers/net/wireless/mediatek/mt76/mt7925/pci.c +++ b/drivers/net/wireless/mediatek/mt76/mt7925/pci.c @@ -41,6 +41,7 @@ static void mt7925e_unregister_device(struct mt792x_dev *dev) mt76_for_each_q_rx(&dev->mt76, i) napi_disable(&dev->mt76.napi[i]); cancel_delayed_work_sync(&pm->ps_work); + cancel_delayed_work_sync(&dev->mlo_pm_work); cancel_work_sync(&pm->wake_work); cancel_work_sync(&dev->reset_work); @@ -454,6 +455,7 @@ static int mt7925_pci_suspend(struct device *device) dev->hif_resumed = false; flush_work(&dev->reset_work); cancel_delayed_work_sync(&pm->ps_work); + cancel_delayed_work_sync(&dev->mlo_pm_work); cancel_work_sync(&pm->wake_work); mt7925_roc_abort_sync(dev); diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/usb.c b/drivers/net/wireless/mediatek/mt76/mt7925/usb.c index bf040f3..16ab139 100644 --- a/drivers/net/wireless/mediatek/mt76/mt7925/usb.c +++ b/drivers/net/wireless/mediatek/mt76/mt7925/usb.c @@ -251,6 +251,7 @@ static int mt7925u_suspend(struct usb_interface *intf, pm_message_t state) pm->suspended = true; dev->hif_resumed = false; flush_work(&dev->reset_work); + cancel_delayed_work_sync(&dev->mlo_pm_work); mt76_connac_mcu_set_hif_suspend(&dev->mt76, true, false); ret = wait_event_timeout(dev->wait,