Linux wireless drivers development
 help / color / mirror / Atom feed
* [PATCH 0/4] wifi: brcmfmac: Fix bugs when the device is removed before firmware is loaded
@ 2026-09-21 21:18 Sean Anderson
  2026-09-21 21:18 ` [PATCH 1/4] wifi: brcmfmac: Fix canceling uninitialized datawork Sean Anderson
                   ` (3 more replies)
  0 siblings, 4 replies; 6+ messages in thread
From: Sean Anderson @ 2026-09-21 21:18 UTC (permalink / raw)
  To: Arend van Spriel, linux-wireless
  Cc: Johannes Berg, brcm80211, linux-kernel, brcm80211-dev-list.pdl,
	Sean Anderson, Cássio Gabriel, Danilo Krummrich, Fan Wu,
	Franky Lin, Greg Kroah-Hartman, John W. Linville,
	Luis Chamberlain, Rafael J. Wysocki, Takashi Iwai, driver-core

I was working on a different bug, and I noticed that brcmfmac tends to
crash quite spectacularly when the device gets removed before the
firmware request completes. This is because brcmfmac does quite a lot of
initialization that would be normally be done in probe() only when the
firmware is loaded. I found two general classes of bugs:

- Some of the remove paths try to clean up things that the firmware
  request callback sets up, which doesn't work too well if the firmware
  isn't loaded (patches 1 and 2).
- The firmware request callback generally assumes that the driver is
  still alive and kicking. So if it runs after the driver is removed it
  will procede to access all sorts of memory after it's been free'd.

A fairly-reliable way to trigger these bugs is to edit really_probe in
drivers/base/dd.c and replace

    IS_ENABLED(CONFIG_DEBUG_TEST_DRIVER_REMOVE)

with

    !strcmp("brcmfmac", drv->name)

Alternatively, you can use the name of the bus's driver.

I have only tested these fixes on SDIO. I would really appreciate if
someone could test this series on PCIe with the above snippet in their
kernel (preferably with KASAN).

Right now if the firmware cannot be loaded for whatever reason then the
firmware request callback will unbind the driver. This is incompatible
with canceling the firmware request and waiting for it to complete in
the driver's remove() callback. As such, I removed this behavior so the
device now sticks around even if we can't load the firmware. If this
behavior is really, truly desired then we can drop device_lock while
waiting for the firmware request to complete and attempt to recover from
the consequences.


Sean Anderson (4):
  wifi: brcmfmac: Fix canceling uninitialized datawork
  wifi: brcmfmac: Fix brcmf_pno_detach NULL-pointer deference
  firmware_loader: Return status from request_firmware_nowait_cancel
  wifi: brcmfmac: Fix firmware requests racing against SDIO removal

 drivers/base/firmware_loader/main.c           | 11 +++++---
 .../broadcom/brcm80211/brcmfmac/bcmsdh.c      |  7 ++++-
 .../broadcom/brcm80211/brcmfmac/bus.h         |  2 ++
 .../broadcom/brcm80211/brcmfmac/core.c        |  3 +--
 .../broadcom/brcm80211/brcmfmac/firmware.c    | 26 ++++++++++++++++---
 .../broadcom/brcm80211/brcmfmac/firmware.h    | 16 +++++++++++-
 .../broadcom/brcm80211/brcmfmac/pcie.c        | 11 +++++---
 .../broadcom/brcm80211/brcmfmac/pno.c         |  2 ++
 .../broadcom/brcm80211/brcmfmac/sdio.c        |  8 +++---
 .../broadcom/brcm80211/brcmfmac/usb.c         |  6 +++--
 include/linux/firmware.h                      |  2 +-
 11 files changed, 75 insertions(+), 19 deletions(-)

---
base-commit: 587858367581b9c55c3690f4e63382ad622719d4
branch: brcmfmac_firmware_cancel

-- 
2.53.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-22 13:34 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-21 21:18 [PATCH 0/4] wifi: brcmfmac: Fix bugs when the device is removed before firmware is loaded Sean Anderson
2026-09-21 21:18 ` [PATCH 1/4] wifi: brcmfmac: Fix canceling uninitialized datawork Sean Anderson
2026-09-21 21:18 ` [PATCH 2/4] wifi: brcmfmac: Fix brcmf_pno_detach NULL-pointer deference Sean Anderson
2026-09-21 21:18 ` [PATCH 3/4] firmware_loader: Return status from request_firmware_nowait_cancel Sean Anderson
2026-09-21 21:18 ` [PATCH 4/4] wifi: brcmfmac: Fix firmware requests racing against SDIO removal Sean Anderson
2026-09-22 13:33   ` Sean Anderson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox