Skip to content

Commit 9f1a002

Browse files
P Praneeshgregkh
authored andcommitted
wifi: ath11k: fix RCU stall while reaping monitor destination ring
[ Upstream commit 16c6c35 ] While processing the monitor destination ring, MSDUs are reaped from the link descriptor based on the corresponding buf_id. However, sometimes the driver cannot obtain a valid buffer corresponding to the buf_id received from the hardware. This causes an infinite loop in the destination processing, resulting in a kernel crash. kernel log: ath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309 ath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed ath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309 ath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed Fix this by skipping the problematic buf_id and reaping the next entry, replacing the break with the next MSDU processing. Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30 Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1 Fixes: d5c6515 ("ath11k: driver for Qualcomm IEEE 802.11ax devices") Signed-off-by: P Praneesh <quic_ppranees@quicinc.com> Signed-off-by: Kang Yang <quic_kangyang@quicinc.com> Acked-by: Kalle Valo <kvalo@kernel.org> Acked-by: Jeff Johnson <quic_jjohnson@quicinc.com> Link: https://patch.msgid.link/20241219110531.2096-2-quic_kangyang@quicinc.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com> Signed-off-by: Li hongliang <1468888505@139.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent db4ae18 commit 9f1a002

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

  • drivers/net/wireless/ath/ath11k

drivers/net/wireless/ath/ath11k/dp_rx.c

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4777,7 +4777,7 @@ ath11k_dp_rx_mon_mpdu_pop(struct ath11k *ar, int mac_id,
47774777
if (!msdu) {
47784778
ath11k_dbg(ar->ab, ATH11K_DBG_DATA,
47794779
"msdu_pop: invalid buf_id %d\n", buf_id);
4780-
break;
4780+
goto next_msdu;
47814781
}
47824782
rxcb = ATH11K_SKB_RXCB(msdu);
47834783
if (!rxcb->unmapped) {
@@ -5404,7 +5404,7 @@ ath11k_dp_rx_full_mon_mpdu_pop(struct ath11k *ar,
54045404
"full mon msdu_pop: invalid buf_id %d\n",
54055405
buf_id);
54065406
spin_unlock_bh(&rx_ring->idr_lock);
5407-
break;
5407+
goto next_msdu;
54085408
}
54095409
idr_remove(&rx_ring->bufs_idr, buf_id);
54105410
spin_unlock_bh(&rx_ring->idr_lock);

0 commit comments

Comments
 (0)