From: Kang Yang <kang.yang@oss.qualcomm.com>
To: ath12k@lists.infradead.org, kang.yang@oss.qualcomm.com
Cc: linux-wireless@vger.kernel.org
Subject: [PATCH ath-next 2/6] wifi: ath12k: free pending MSDUs on duplicate mon link descriptor
Date: Wed, 16 Sep 2026 14:03:21 +0800 [thread overview]
Message-ID: <20260916060325.854-3-kang.yang@oss.qualcomm.com> (raw)
In-Reply-To: <20260916060325.854-1-kang.yang@oss.qualcomm.com>
ath12k_wifi7_dp_rx_mon_mpdu_pop() aborts processing when a duplicate
monitor link descriptor is detected.
Previous iterations may already have linked MSDUs onto *head_msdu
and detached the corresponding RX buffers from their descriptors.
Returning without completing or freeing the chain leaves those
skbs orphaned, resulting in a memory leak.
kmemleak reports these skbs in field testing:
kmemleak_alloc()
__netdev_alloc_skb()
ath12k_dp_rx_bufs_replenish()
ath12k_wifi7_dp_rx_mon_dest_process()
Free the accumulated MSDU chain before returning and clear
*head_msdu so callers observe a consistent state.
Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Fixes: 72bfbf19b7da ("wifi: ath12k: add support to reap and process mon dest ring")
Signed-off-by: Kang Yang <kang.yang@oss.qualcomm.com>
---
drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c b/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
index ed6686746605..08f2fba3e680 100644
--- a/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
+++ b/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
@@ -2675,6 +2675,8 @@ ath12k_wifi7_dp_rx_mon_mpdu_pop(struct ath12k *ar, int mac_id,
if (pmon->mon_last_linkdesc_paddr == paddr) {
pmon->rx_mon_stats.dup_mon_linkdesc_cnt++;
spin_unlock_bh(&pmon->mon_lock);
+ kfree_skb_list(*head_msdu);
+ *head_msdu = NULL;
return rx_bufs_used;
}
--
2.34.1
next prev parent reply other threads:[~2026-09-16 6:04 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 6:03 [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 1/6] wifi: ath12k: fix skb leak on paddr mismatch in wifi7 mon RX pop Kang Yang
2026-09-16 6:03 ` Kang Yang [this message]
2026-09-16 6:03 ` [PATCH ath-next 3/6] wifi: ath12k: fix stale tail_msdu pointer returned from mpdu_pop Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 4/6] wifi: ath12k: place dp_mon_mpdu on stack in mon dst reap loop Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 5/6] wifi: ath12k: fix skb leak on monitor PPDU ID wraparound Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 6/6] wifi: ath12k: avoid double DMA unmap of held monitor RX buffers Kang Yang
2026-09-17 10:44 ` [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Vasanthakumar Thiagarajan
2026-09-18 1:37 ` Baochen Qiang
2026-09-24 7:48 ` Kang Yang
2026-09-24 14:35 ` Jeff Johnson
2026-09-25 15:26 ` Jeff Johnson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916060325.854-3-kang.yang@oss.qualcomm.com \
--to=kang.yang@oss.qualcomm.com \
--cc=ath12k@lists.infradead.org \
--cc=linux-wireless@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox