* [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues
@ 2026-09-16 6:03 Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 1/6] wifi: ath12k: fix skb leak on paddr mismatch in wifi7 mon RX pop Kang Yang
` (9 more replies)
0 siblings, 10 replies; 12+ messages in thread
From: Kang Yang @ 2026-09-16 6:03 UTC (permalink / raw)
To: ath12k, kang.yang; +Cc: linux-wireless
This series fixes several monitor RX buffer management bugs in the
monitor destination path.
The fixes address leaked skb buffers, stale monitor descriptor state,
object lifetime issues, and incorrect DMA unmap handling observed in
various error and corner cases.
Kang Yang (6):
wifi: ath12k: fix skb leak on paddr mismatch in wifi7 mon RX pop
wifi: ath12k: free pending MSDUs on duplicate mon link descriptor
wifi: ath12k: fix stale tail_msdu pointer returned from mpdu_pop
wifi: ath12k: place dp_mon_mpdu on stack in mon dst reap loop
wifi: ath12k: fix skb leak on monitor PPDU ID wraparound
wifi: ath12k: avoid double DMA unmap of held monitor RX buffers
drivers/net/wireless/ath/ath12k/dp.c | 9 +++----
drivers/net/wireless/ath/ath12k/dp_mon.c | 15 ++++++------
drivers/net/wireless/ath/ath12k/dp_mon.h | 2 +-
.../net/wireless/ath/ath12k/wifi7/dp_mon.c | 24 +++++++++----------
4 files changed, 24 insertions(+), 26 deletions(-)
base-commit: c3bace8584ca707e34ba837f65c2e9d566af4c2c
--
2.34.1
^ permalink raw reply [flat|nested] 12+ messages in thread
* [PATCH ath-next 1/6] wifi: ath12k: fix skb leak on paddr mismatch in wifi7 mon RX pop
2026-09-16 6:03 [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Kang Yang
@ 2026-09-16 6:03 ` Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 2/6] wifi: ath12k: free pending MSDUs on duplicate mon link descriptor Kang Yang
` (8 subsequent siblings)
9 siblings, 0 replies; 12+ messages in thread
From: Kang Yang @ 2026-09-16 6:03 UTC (permalink / raw)
To: ath12k, kang.yang; +Cc: linux-wireless
When rxcb->paddr does not match the MSDU-list paddr reported by
the link descriptor, ath12k_wifi7_dp_rx_mon_mpdu_pop() sets
drop_mpdu = true and continues to the next MSDU. At that point
the skb is still attached to the descriptor via desc_info->skb;
the local msdu variable only holds a copy of that pointer. The
continue skips the rest of the loop body, which would normally
DMA-unmap the buffer, free the skb, clear desc_info->skb, and
append the descriptor to used_list in the next_msdu block.
The descriptor therefore stays in_use with the skb attached
forever. The skb is never DMA-unmapped, delivered, freed or
replaced, and HW does not write into it either because the
descriptor is no longer posted to any SRNG. The descriptor is
also never returned to used_list, so
ath12k_dp_rx_bufs_replenish() cannot allocate a fresh buffer
for it and the RX refill ring gradually drains.
The skb is still reachable via dp->rxbaddr[][].skb and is
reclaimed at teardown by ath12k_dp_cc_cleanup(), so this is not
a kmemleak-style unreachable leak. Nevertheless, both the
descriptor slot and the skb memory are wasted for the module
lifetime, and under sustained mismatches monitor RX stalls.
Remove the continue so drop_mpdu remains true, execution reaches
the DMA unmap and dev_kfree_skb_any() below, and the descriptor
is returned to used_list via the next_msdu block for replenish.
Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Fixes: 72bfbf19b7da ("wifi: ath12k: add support to reap and process mon dest ring")
Signed-off-by: Kang Yang <kang.yang@oss.qualcomm.com>
---
drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c b/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
index ded7d56cd79b..ed6686746605 100644
--- a/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
+++ b/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
@@ -2718,7 +2718,6 @@ ath12k_wifi7_dp_rx_mon_mpdu_pop(struct ath12k *ar, int mac_id,
i, (unsigned long)rxcb->paddr,
(unsigned long)msdu_list.paddr[i]);
drop_mpdu = true;
- continue;
}
if (!rxcb->unmapped) {
dma_unmap_single(ar->ab->dev, rxcb->paddr,
--
2.34.1
^ permalink raw reply related [flat|nested] 12+ messages in thread
* [PATCH ath-next 2/6] wifi: ath12k: free pending MSDUs on duplicate mon link descriptor
2026-09-16 6:03 [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 1/6] wifi: ath12k: fix skb leak on paddr mismatch in wifi7 mon RX pop Kang Yang
@ 2026-09-16 6:03 ` Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 3/6] wifi: ath12k: fix stale tail_msdu pointer returned from mpdu_pop Kang Yang
` (7 subsequent siblings)
9 siblings, 0 replies; 12+ messages in thread
From: Kang Yang @ 2026-09-16 6:03 UTC (permalink / raw)
To: ath12k, kang.yang; +Cc: linux-wireless
ath12k_wifi7_dp_rx_mon_mpdu_pop() aborts processing when a duplicate
monitor link descriptor is detected.
Previous iterations may already have linked MSDUs onto *head_msdu
and detached the corresponding RX buffers from their descriptors.
Returning without completing or freeing the chain leaves those
skbs orphaned, resulting in a memory leak.
kmemleak reports these skbs in field testing:
kmemleak_alloc()
__netdev_alloc_skb()
ath12k_dp_rx_bufs_replenish()
ath12k_wifi7_dp_rx_mon_dest_process()
Free the accumulated MSDU chain before returning and clear
*head_msdu so callers observe a consistent state.
Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Fixes: 72bfbf19b7da ("wifi: ath12k: add support to reap and process mon dest ring")
Signed-off-by: Kang Yang <kang.yang@oss.qualcomm.com>
---
drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c b/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
index ed6686746605..08f2fba3e680 100644
--- a/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
+++ b/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
@@ -2675,6 +2675,8 @@ ath12k_wifi7_dp_rx_mon_mpdu_pop(struct ath12k *ar, int mac_id,
if (pmon->mon_last_linkdesc_paddr == paddr) {
pmon->rx_mon_stats.dup_mon_linkdesc_cnt++;
spin_unlock_bh(&pmon->mon_lock);
+ kfree_skb_list(*head_msdu);
+ *head_msdu = NULL;
return rx_bufs_used;
}
--
2.34.1
^ permalink raw reply related [flat|nested] 12+ messages in thread
* [PATCH ath-next 3/6] wifi: ath12k: fix stale tail_msdu pointer returned from mpdu_pop
2026-09-16 6:03 [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 1/6] wifi: ath12k: fix skb leak on paddr mismatch in wifi7 mon RX pop Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 2/6] wifi: ath12k: free pending MSDUs on duplicate mon link descriptor Kang Yang
@ 2026-09-16 6:03 ` Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 4/6] wifi: ath12k: place dp_mon_mpdu on stack in mon dst reap loop Kang Yang
` (6 subsequent siblings)
9 siblings, 0 replies; 12+ messages in thread
From: Kang Yang @ 2026-09-16 6:03 UTC (permalink / raw)
To: ath12k, kang.yang; +Cc: linux-wireless
ath12k_wifi7_dp_rx_mon_mpdu_pop() assigns *tail_msdu from the loop
cursor msdu at function exit. That cursor reflects the state of the
last msdu_list entry processed, not the end of the accumulated MSDU
chain: on next_msdu paths (invalid skb, drop_mpdu, first-MSDU rx_desc
invalid) it is set to NULL, and on the set_pktlen failure path it
becomes a dangling pointer to a freed skb. When these occur on the
final iteration, callers see head_msdu populated with a valid chain
while tail_msdu is NULL or points to freed memory.
The chain end is already tracked by the local variable last, which is
updated only after each MSDU has been validated and linked. Use it as
the source for tail_msdu so head_msdu and tail_msdu are either both
NULL or both point into the same live chain.
Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Fixes: 72bfbf19b7da ("wifi: ath12k: add support to reap and process mon dest ring")
Signed-off-by: Kang Yang <kang.yang@oss.qualcomm.com>
---
drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c b/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
index 08f2fba3e680..8fca777041d1 100644
--- a/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
+++ b/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
@@ -2802,7 +2802,7 @@ ath12k_wifi7_dp_rx_mon_mpdu_pop(struct ath12k *ar, int mac_id,
if (last)
last->next = NULL;
- *tail_msdu = msdu;
+ *tail_msdu = last;
if (msdu_cnt == 0)
*npackets = 1;
--
2.34.1
^ permalink raw reply related [flat|nested] 12+ messages in thread
* [PATCH ath-next 4/6] wifi: ath12k: place dp_mon_mpdu on stack in mon dst reap loop
2026-09-16 6:03 [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Kang Yang
` (2 preceding siblings ...)
2026-09-16 6:03 ` [PATCH ath-next 3/6] wifi: ath12k: fix stale tail_msdu pointer returned from mpdu_pop Kang Yang
@ 2026-09-16 6:03 ` Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 5/6] wifi: ath12k: fix skb leak on monitor PPDU ID wraparound Kang Yang
` (5 subsequent siblings)
9 siblings, 0 replies; 12+ messages in thread
From: Kang Yang @ 2026-09-16 6:03 UTC (permalink / raw)
To: ath12k, kang.yang; +Cc: linux-wireless
ath12k_wifi7_dp_rx_mon_dest_process() allocates a dp_mon_mpdu with
kzalloc(GFP_ATOMIC) for each delivered MPDU. On allocation failure
it breaks out of the reap loop without calling
ath12k_hal_srng_dst_get_next_entry(), leaving the destination ring
tail pointer parked on the current entry -- the same entry will
be peek()ed on every subsequent NAPI schedule, stalling monitor
RX until the mon_dest_ring_stuck_cnt recovery path resyncs the
PPDU ID. The head_msdu chain accumulated for this iteration is
also orphaned since the break bypasses both the delivery and
the cleanup paths.
kmemleak reports these skbs in field testing:
kmemleak_alloc()
__netdev_alloc_skb()
ath12k_dp_rx_bufs_replenish()
ath12k_wifi7_dp_rx_mon_dest_process()
dp_mon_mpdu is used only within a single reap loop iteration and
is passed synchronously to ath12k_wifi7_dp_mon_rx_deliver(); the
callee does not retain the pointer. Place it on the stack instead
of using kzalloc(GFP_ATOMIC). This eliminates the allocation
failure path (and the ring stall it caused) and saves a
kzalloc/kfree pair per delivered MPDU.
Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Fixes: 72bfbf19b7da ("wifi: ath12k: add support to reap and process mon dest ring")
Signed-off-by: Kang Yang <kang.yang@oss.qualcomm.com>
---
.../net/wireless/ath/ath12k/wifi7/dp_mon.c | 19 ++++++++-----------
1 file changed, 8 insertions(+), 11 deletions(-)
diff --git a/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c b/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
index 8fca777041d1..1e29c13ad66d 100644
--- a/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
+++ b/drivers/net/wireless/ath/ath12k/wifi7/dp_mon.c
@@ -2827,7 +2827,6 @@ ath12k_wifi7_dp_rx_mon_dest_process(struct ath12k *ar, int mac_id,
struct ath12k_base *ab = ar->ab;
struct ath12k_dp *dp = ath12k_ab_to_dp(ab);
void *ring_entry, *mon_dst_srng;
- struct dp_mon_mpdu *tmp_mpdu;
LIST_HEAD(rx_desc_used_list);
struct hal_srng *srng;
@@ -2893,18 +2892,16 @@ ath12k_wifi7_dp_rx_mon_dest_process(struct ath12k *ar, int mac_id,
}
if (head_msdu && tail_msdu) {
- tmp_mpdu = kzalloc_obj(*tmp_mpdu, GFP_ATOMIC);
- if (!tmp_mpdu)
- break;
-
- tmp_mpdu->head = head_msdu;
- tmp_mpdu->tail = tail_msdu;
- tmp_mpdu->err_bitmap = pmon->err_bitmap;
- tmp_mpdu->decap_format = pmon->decap_format;
- ath12k_wifi7_dp_mon_rx_deliver(&ar->dp, tmp_mpdu,
+ struct dp_mon_mpdu tmp_mpdu = {
+ .head = head_msdu,
+ .tail = tail_msdu,
+ .err_bitmap = pmon->err_bitmap,
+ .decap_format = pmon->decap_format,
+ };
+
+ ath12k_wifi7_dp_mon_rx_deliver(&ar->dp, &tmp_mpdu,
&pmon->mon_ppdu_info, napi);
rx_mon_stats->dest_mpdu_done++;
- kfree(tmp_mpdu);
}
ring_entry = ath12k_hal_srng_dst_get_next_entry(ar->ab,
--
2.34.1
^ permalink raw reply related [flat|nested] 12+ messages in thread
* [PATCH ath-next 5/6] wifi: ath12k: fix skb leak on monitor PPDU ID wraparound
2026-09-16 6:03 [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Kang Yang
` (3 preceding siblings ...)
2026-09-16 6:03 ` [PATCH ath-next 4/6] wifi: ath12k: place dp_mon_mpdu on stack in mon dst reap loop Kang Yang
@ 2026-09-16 6:03 ` Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 6/6] wifi: ath12k: avoid double DMA unmap of held monitor RX buffers Kang Yang
` (4 subsequent siblings)
9 siblings, 0 replies; 12+ messages in thread
From: Kang Yang @ 2026-09-16 6:03 UTC (permalink / raw)
To: ath12k, kang.yang; +Cc: linux-wireless
ath12k_dp_mon_comp_ppduid() updates *ppdu_id and returns
msdu_ppdu_id to indicate that a PPDU transition was detected.
When PPDU IDs wrap around, msdu_ppdu_id can be 0. In that case
the function updates *ppdu_id but returns 0, causing
ath12k_wifi7_dp_rx_mon_mpdu_pop() to interpret the result as
"no PPDU update" and continue processing the MPDU.
The MSDUs are then linked into head_msdu while their RX
descriptors have already been detached. Later,
ath12k_wifi7_dp_rx_mon_dest_process() detects the PPDU
mismatch and exits with the partially built MSDU chain,
leaking the SKBs.
kmemleak reports the leak through:
kmemleak_alloc()
__netdev_alloc_skb()
ath12k_dp_rx_bufs_replenish()
ath12k_wifi7_dp_rx_mon_dest_process()
Fix this by returning a boolean value from
ath12k_dp_mon_comp_ppduid() so the update notification is
independent of the actual PPDU ID value.
Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Fixes: 72bfbf19b7da ("wifi: ath12k: add support to reap and process mon dest ring")
Signed-off-by: Kang Yang <kang.yang@oss.qualcomm.com>
---
drivers/net/wireless/ath/ath12k/dp_mon.c | 15 +++++++--------
drivers/net/wireless/ath/ath12k/dp_mon.h | 2 +-
2 files changed, 8 insertions(+), 9 deletions(-)
diff --git a/drivers/net/wireless/ath/ath12k/dp_mon.c b/drivers/net/wireless/ath/ath12k/dp_mon.c
index 7d5be77b081f..db20d27b6333 100644
--- a/drivers/net/wireless/ath/ath12k/dp_mon.c
+++ b/drivers/net/wireless/ath/ath12k/dp_mon.c
@@ -81,24 +81,23 @@ struct sk_buff
}
EXPORT_SYMBOL(ath12k_dp_rx_alloc_mon_status_buf);
-u32 ath12k_dp_mon_comp_ppduid(u32 msdu_ppdu_id, u32 *ppdu_id)
+bool ath12k_dp_mon_comp_ppduid(u32 msdu_ppdu_id, u32 *ppdu_id)
{
- u32 ret = 0;
-
if ((*ppdu_id < msdu_ppdu_id) &&
((msdu_ppdu_id - *ppdu_id) < DP_NOT_PPDU_ID_WRAP_AROUND)) {
/* Hold on mon dest ring, and reap mon status ring. */
*ppdu_id = msdu_ppdu_id;
- ret = msdu_ppdu_id;
- } else if ((*ppdu_id > msdu_ppdu_id) &&
- ((*ppdu_id - msdu_ppdu_id) > DP_NOT_PPDU_ID_WRAP_AROUND)) {
+ return true;
+ }
+ if ((*ppdu_id > msdu_ppdu_id) &&
+ ((*ppdu_id - msdu_ppdu_id) > DP_NOT_PPDU_ID_WRAP_AROUND)) {
/* PPDU ID has exceeded the maximum value and will
* restart from 0.
*/
*ppdu_id = msdu_ppdu_id;
- ret = msdu_ppdu_id;
+ return true;
}
- return ret;
+ return false;
}
EXPORT_SYMBOL(ath12k_dp_mon_comp_ppduid);
diff --git a/drivers/net/wireless/ath/ath12k/dp_mon.h b/drivers/net/wireless/ath/ath12k/dp_mon.h
index 162cdcaa57a7..f352655eae9d 100644
--- a/drivers/net/wireless/ath/ath12k/dp_mon.h
+++ b/drivers/net/wireless/ath/ath12k/dp_mon.h
@@ -100,7 +100,7 @@ struct sk_buff
*ath12k_dp_rx_alloc_mon_status_buf(struct ath12k_base *ab,
struct dp_rxdma_mon_ring *rx_ring,
int *buf_id);
-u32 ath12k_dp_mon_comp_ppduid(u32 msdu_ppdu_id, u32 *ppdu_id);
+bool ath12k_dp_mon_comp_ppduid(u32 msdu_ppdu_id, u32 *ppdu_id);
int
ath12k_dp_mon_parse_status_buf(struct ath12k_pdev_dp *dp_pdev,
struct ath12k_mon_data *pmon,
--
2.34.1
^ permalink raw reply related [flat|nested] 12+ messages in thread
* [PATCH ath-next 6/6] wifi: ath12k: avoid double DMA unmap of held monitor RX buffers
2026-09-16 6:03 [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Kang Yang
` (4 preceding siblings ...)
2026-09-16 6:03 ` [PATCH ath-next 5/6] wifi: ath12k: fix skb leak on monitor PPDU ID wraparound Kang Yang
@ 2026-09-16 6:03 ` Kang Yang
2026-09-17 10:44 ` [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Vasanthakumar Thiagarajan
` (3 subsequent siblings)
9 siblings, 0 replies; 12+ messages in thread
From: Kang Yang @ 2026-09-16 6:03 UTC (permalink / raw)
To: ath12k, kang.yang; +Cc: linux-wireless
ath12k_dp_cc_cleanup() assumes that every rx_desc_info entry with a
non-NULL skb still has an active DMA mapping and therefore always
calls dma_unmap_single() before freeing the skb.
This assumption is not true for the monitor RX path.
ath12k_wifi7_dp_rx_mon_mpdu_pop() may DMA-unmap a buffer and mark
rxcb->unmapped before returning early to hold the MSDU for later
reprocessing. In that state desc_info->skb remains populated, so
module removal can trigger a second dma_unmap_single() from
ath12k_dp_cc_cleanup().
IOMMU reports the issue as:
dma_unmap_phys()
dma_unmap_page_attrs()
ath12k_dp_cc_cleanup()
ath12k_dp_cmn_device_deinit()
ath12k_core_stop()
Skip dma_unmap_single() when rxcb->unmapped is already set and free
the skb directly.
Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Fixes: 72bfbf19b7da ("wifi: ath12k: add support to reap and process mon dest ring")
Signed-off-by: Kang Yang <kang.yang@oss.qualcomm.com>
---
drivers/net/wireless/ath/ath12k/dp.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/net/wireless/ath/ath12k/dp.c b/drivers/net/wireless/ath/ath12k/dp.c
index ef9601152f81..92278ac8f633 100644
--- a/drivers/net/wireless/ath/ath12k/dp.c
+++ b/drivers/net/wireless/ath/ath12k/dp.c
@@ -998,10 +998,11 @@ static void ath12k_dp_cc_cleanup(struct ath12k_base *ab)
if (!skb)
continue;
- dma_unmap_single(ab->dev,
- ATH12K_SKB_RXCB(skb)->paddr,
- skb->len + skb_tailroom(skb),
- DMA_FROM_DEVICE);
+ if (!ATH12K_SKB_RXCB(skb)->unmapped)
+ dma_unmap_single(ab->dev,
+ ATH12K_SKB_RXCB(skb)->paddr,
+ skb->len + skb_tailroom(skb),
+ DMA_FROM_DEVICE);
dev_kfree_skb_any(skb);
}
--
2.34.1
^ permalink raw reply related [flat|nested] 12+ messages in thread
* Re: [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues
2026-09-16 6:03 [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Kang Yang
` (5 preceding siblings ...)
2026-09-16 6:03 ` [PATCH ath-next 6/6] wifi: ath12k: avoid double DMA unmap of held monitor RX buffers Kang Yang
@ 2026-09-17 10:44 ` Vasanthakumar Thiagarajan
2026-09-18 1:37 ` Baochen Qiang
` (2 subsequent siblings)
9 siblings, 0 replies; 12+ messages in thread
From: Vasanthakumar Thiagarajan @ 2026-09-17 10:44 UTC (permalink / raw)
To: Kang Yang, ath12k; +Cc: linux-wireless
On 9/16/2026 11:33 AM, Kang Yang wrote:
> This series fixes several monitor RX buffer management bugs in the
> monitor destination path.
>
> The fixes address leaked skb buffers, stale monitor descriptor state,
> object lifetime issues, and incorrect DMA unmap handling observed in
> various error and corner cases.
>
> Kang Yang (6):
> wifi: ath12k: fix skb leak on paddr mismatch in wifi7 mon RX pop
> wifi: ath12k: free pending MSDUs on duplicate mon link descriptor
> wifi: ath12k: fix stale tail_msdu pointer returned from mpdu_pop
> wifi: ath12k: place dp_mon_mpdu on stack in mon dst reap loop
> wifi: ath12k: fix skb leak on monitor PPDU ID wraparound
> wifi: ath12k: avoid double DMA unmap of held monitor RX buffers
>
> drivers/net/wireless/ath/ath12k/dp.c | 9 +++----
> drivers/net/wireless/ath/ath12k/dp_mon.c | 15 ++++++------
> drivers/net/wireless/ath/ath12k/dp_mon.h | 2 +-
> .../net/wireless/ath/ath12k/wifi7/dp_mon.c | 24 +++++++++----------
> 4 files changed, 24 insertions(+), 26 deletions(-)
>
>
Reviewed-by: Vasanthakumar Thiagarajan <vasanthakumar.thiagarajan@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues
2026-09-16 6:03 [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Kang Yang
` (6 preceding siblings ...)
2026-09-17 10:44 ` [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Vasanthakumar Thiagarajan
@ 2026-09-18 1:37 ` Baochen Qiang
2026-09-24 7:48 ` Kang Yang
2026-09-25 15:26 ` Jeff Johnson
9 siblings, 0 replies; 12+ messages in thread
From: Baochen Qiang @ 2026-09-18 1:37 UTC (permalink / raw)
To: Kang Yang, ath12k; +Cc: linux-wireless
On 9/16/2026 2:03 PM, Kang Yang wrote:
> This series fixes several monitor RX buffer management bugs in the
> monitor destination path.
>
> The fixes address leaked skb buffers, stale monitor descriptor state,
> object lifetime issues, and incorrect DMA unmap handling observed in
> various error and corner cases.
>
> Kang Yang (6):
> wifi: ath12k: fix skb leak on paddr mismatch in wifi7 mon RX pop
> wifi: ath12k: free pending MSDUs on duplicate mon link descriptor
> wifi: ath12k: fix stale tail_msdu pointer returned from mpdu_pop
> wifi: ath12k: place dp_mon_mpdu on stack in mon dst reap loop
> wifi: ath12k: fix skb leak on monitor PPDU ID wraparound
> wifi: ath12k: avoid double DMA unmap of held monitor RX buffers
>
> drivers/net/wireless/ath/ath12k/dp.c | 9 +++----
> drivers/net/wireless/ath/ath12k/dp_mon.c | 15 ++++++------
> drivers/net/wireless/ath/ath12k/dp_mon.h | 2 +-
> .../net/wireless/ath/ath12k/wifi7/dp_mon.c | 24 +++++++++----------
> 4 files changed, 24 insertions(+), 26 deletions(-)
>
>
> base-commit: c3bace8584ca707e34ba837f65c2e9d566af4c2c
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues
2026-09-16 6:03 [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Kang Yang
` (7 preceding siblings ...)
2026-09-18 1:37 ` Baochen Qiang
@ 2026-09-24 7:48 ` Kang Yang
2026-09-24 14:35 ` Jeff Johnson
2026-09-25 15:26 ` Jeff Johnson
9 siblings, 1 reply; 12+ messages in thread
From: Kang Yang @ 2026-09-24 7:48 UTC (permalink / raw)
To: ath12k; +Cc: linux-wireless
On 9/16/2026 2:03 PM, Kang Yang wrote:
> This series fixes several monitor RX buffer management bugs in the
> monitor destination path.
>
> The fixes address leaked skb buffers, stale monitor descriptor state,
> object lifetime issues, and incorrect DMA unmap handling observed in
> various error and corner cases.
>
> Kang Yang (6):
> wifi: ath12k: fix skb leak on paddr mismatch in wifi7 mon RX pop
> wifi: ath12k: free pending MSDUs on duplicate mon link descriptor
> wifi: ath12k: fix stale tail_msdu pointer returned from mpdu_pop
> wifi: ath12k: place dp_mon_mpdu on stack in mon dst reap loop
> wifi: ath12k: fix skb leak on monitor PPDU ID wraparound
> wifi: ath12k: avoid double DMA unmap of held monitor RX buffers
>
> drivers/net/wireless/ath/ath12k/dp.c | 9 +++----
> drivers/net/wireless/ath/ath12k/dp_mon.c | 15 ++++++------
> drivers/net/wireless/ath/ath12k/dp_mon.h | 2 +-
> .../net/wireless/ath/ath12k/wifi7/dp_mon.c | 24 +++++++++----------
> 4 files changed, 24 insertions(+), 26 deletions(-)
>
>
> base-commit: c3bace8584ca707e34ba837f65c2e9d566af4c2c
Hi,jeff, do you have any comments? 😀
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues
2026-09-24 7:48 ` Kang Yang
@ 2026-09-24 14:35 ` Jeff Johnson
0 siblings, 0 replies; 12+ messages in thread
From: Jeff Johnson @ 2026-09-24 14:35 UTC (permalink / raw)
To: Kang Yang, ath12k; +Cc: linux-wireless
On 9/24/2026 12:48 AM, Kang Yang wrote:
>
>
> On 9/16/2026 2:03 PM, Kang Yang wrote:
>> This series fixes several monitor RX buffer management bugs in the
>> monitor destination path.
>>
>> The fixes address leaked skb buffers, stale monitor descriptor state,
>> object lifetime issues, and incorrect DMA unmap handling observed in
>> various error and corner cases.
>>
>> Kang Yang (6):
>> wifi: ath12k: fix skb leak on paddr mismatch in wifi7 mon RX pop
>> wifi: ath12k: free pending MSDUs on duplicate mon link descriptor
>> wifi: ath12k: fix stale tail_msdu pointer returned from mpdu_pop
>> wifi: ath12k: place dp_mon_mpdu on stack in mon dst reap loop
>> wifi: ath12k: fix skb leak on monitor PPDU ID wraparound
>> wifi: ath12k: avoid double DMA unmap of held monitor RX buffers
>>
>> drivers/net/wireless/ath/ath12k/dp.c | 9 +++----
>> drivers/net/wireless/ath/ath12k/dp_mon.c | 15 ++++++------
>> drivers/net/wireless/ath/ath12k/dp_mon.h | 2 +-
>> .../net/wireless/ath/ath12k/wifi7/dp_mon.c | 24 +++++++++----------
>> 4 files changed, 24 insertions(+), 26 deletions(-)
>>
>>
>> base-commit: c3bace8584ca707e34ba837f65c2e9d566af4c2c
>
>
>
> Hi,jeff, do you have any comments? 😀
If you check patchwork using the Message-id of the individual patches (not the
cover letter) you'll see the status is Under Review which means it is under
active review. For example:
https://patchwork.kernel.org/project/linux-wireless/patch/20260916060325.854-2-kang.yang@oss.qualcomm.com/
Patches transition to that state when they are placed in my pending branch.
For best results when using patchwork you'll need to create an account and log
in since anonymous access has been severely restricted due to abuse by LLM
scraping robots.
/jeff
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues
2026-09-16 6:03 [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Kang Yang
` (8 preceding siblings ...)
2026-09-24 7:48 ` Kang Yang
@ 2026-09-25 15:26 ` Jeff Johnson
9 siblings, 0 replies; 12+ messages in thread
From: Jeff Johnson @ 2026-09-25 15:26 UTC (permalink / raw)
To: ath12k, Kang Yang; +Cc: linux-wireless
On Wed, 16 Sep 2026 14:03:19 +0800, Kang Yang wrote:
> This series fixes several monitor RX buffer management bugs in the
> monitor destination path.
>
> The fixes address leaked skb buffers, stale monitor descriptor state,
> object lifetime issues, and incorrect DMA unmap handling observed in
> various error and corner cases.
>
> [...]
Applied, thanks!
[1/6] wifi: ath12k: fix skb leak on paddr mismatch in wifi7 mon RX pop
commit: 4dfe8e3ac731c3372b5c1f1f73b0676c301c3916
[2/6] wifi: ath12k: free pending MSDUs on duplicate mon link descriptor
commit: d8e8eac3fcffc114a79f7d07d7cb73cc16645381
[3/6] wifi: ath12k: fix stale tail_msdu pointer returned from mpdu_pop
commit: 1a10a558555072dba8510ded23a9174b2a00d079
[4/6] wifi: ath12k: place dp_mon_mpdu on stack in mon dst reap loop
commit: 8b1d2f4c3805b9f1bddd5dc3bd241edd1f9ab2d9
[5/6] wifi: ath12k: fix skb leak on monitor PPDU ID wraparound
commit: 97b144b82e2388efef1f78269626d61de0480feb
[6/6] wifi: ath12k: avoid double DMA unmap of held monitor RX buffers
commit: febe1f8cbccc3434790bfc4d94d40c9dbd803065
Best regards,
--
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 12+ messages in thread
end of thread, other threads:[~2026-09-25 15:27 UTC | newest]
Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-16 6:03 [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 1/6] wifi: ath12k: fix skb leak on paddr mismatch in wifi7 mon RX pop Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 2/6] wifi: ath12k: free pending MSDUs on duplicate mon link descriptor Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 3/6] wifi: ath12k: fix stale tail_msdu pointer returned from mpdu_pop Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 4/6] wifi: ath12k: place dp_mon_mpdu on stack in mon dst reap loop Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 5/6] wifi: ath12k: fix skb leak on monitor PPDU ID wraparound Kang Yang
2026-09-16 6:03 ` [PATCH ath-next 6/6] wifi: ath12k: avoid double DMA unmap of held monitor RX buffers Kang Yang
2026-09-17 10:44 ` [PATCH ath-next 0/6] wifi: ath12k: fix monitor RX buffer lifecycle issues Vasanthakumar Thiagarajan
2026-09-18 1:37 ` Baochen Qiang
2026-09-24 7:48 ` Kang Yang
2026-09-24 14:35 ` Jeff Johnson
2026-09-25 15:26 ` Jeff Johnson
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox