1. Feb 04, 2021
  2. Jan 28, 2021
    • Miaoqing Pan's avatar
      ath10k: fix wmi mgmt tx queue full due to race condition · b55379e3
      Miaoqing Pan authored
      
      
      Failed to transmit wmi management frames:
      
      [84977.840894] ath10k_snoc a000000.wifi: wmi mgmt tx queue is full
      [84977.840913] ath10k_snoc a000000.wifi: failed to transmit packet, dropping: -28
      [84977.840924] ath10k_snoc a000000.wifi: failed to submit frame: -28
      [84977.840932] ath10k_snoc a000000.wifi: failed to transmit frame: -28
      
      This issue is caused by race condition between skb_dequeue and
      __skb_queue_tail. The queue of ‘wmi_mgmt_tx_queue’ is protected by a
      different lock: ar->data_lock vs list->lock, the result is no protection.
      So when ath10k_mgmt_over_wmi_tx_work() and ath10k_mac_tx_wmi_mgmt()
      running concurrently on different CPUs, there appear to be a rare corner
      cases when the queue length is 1,
      
        CPUx (skb_deuque)			CPUy (__skb_queue_tail)
      					next=list
      					prev=list
        struct sk_buff *skb = skb_peek(list);	WRITE_ONCE(newsk->next, next);
        WRITE_ONCE(list->qlen, list->qlen - 1);WRITE_ONCE(newsk->prev, prev);
        next       = skb->next;		WRITE_ONCE(next->prev, newsk);
        prev       = skb->prev;		WRITE_ONCE(prev->next, newsk);
        skb->next  = skb->prev = NULL;	list->qlen++;
        WRITE_ONCE(next->prev, prev);
        WRITE_ONCE(prev->next, next);
      
      If the instruction ‘next = skb->next’ is executed before
      ‘WRITE_ONCE(prev->next, newsk)’, newsk will be lost, as CPUx get the
      old ‘next’ pointer, but the length is still added by one. The final
      result is the length of the queue will reach the maximum value but
      the queue is empty.
      
      So remove ar->data_lock, and use 'skb_queue_tail' instead of
      '__skb_queue_tail' to prevent the potential race condition. Also switch
      to use skb_queue_len_lockless, in case we queue a few SKBs simultaneously.
      
      Tested-on: WCN3990 hw1.0 SNOC WLAN.HL.3.1.c2-00033-QCAHLSWMTPLZ-1
      
      Signed-off-by: default avatarMiaoqing Pan <miaoqing@codeaurora.org>
      Reviewed-by: default avatarBrian Norris <briannorris@chromium.org>
      Signed-off-by: default avatarKalle Valo <kvalo@codeaurora.org>
      Link: https://lore.kernel.org/r/1608618887-8857-1-git-send-email-miaoqing@codeaurora.org
      b55379e3
    • Wen Gong's avatar
      ath10k: pass the ssid info to get the correct bss entity · 22df5e1b
      Wen Gong authored
      
      
      When connect to an AP with WPA mode, ath10k need to set need_ptk_4_way to
      firmware in WMI_PEER_ASSOC_CMD, then the data path is disallow in
      firmware, it will be allowed untill firmware finish the 4 way handshake.
      
      It failed with a test case with below steps:
      1. configure AP with WPA mode with ssid1 SimpleConnect_a_orbvt_ch1,
         bssid1 and channel 1.
      2. connect to ssid1 and ping success.
      3. wait 10 seconds which is less than
         IEEE80211_SCAN_RESULT_EXPIRE(30 seconds).
      4. configure AP with OPEN mode with ssid2 SimpleConnect_b_z3a00_ch1,
         but use same bssid1 and channel 1 of step 1.
      5. disconnect ssid1.
      6. connect to ssid2 and ping fail.
      
      Fail reason:
      When run step 6, ath10k_peer_assoc_h_crypto() called cfg80211_get_bss()
      with bssid and chan info, but ssid1 and ssid2 have the same bssid and
      channel, then there have 2 entry for ssid1 and ssid2 in cfg80211. The
      ssid1's order is before ssid2 in bss_list, and ssid1's age is less than
      the expire time which is IEEE80211_SCAN_RESULT_EXPIRE(30 seconds). Then
      ssid1's entry is selected and ath10k_peer_assoc_h_crypto() parsed it and
      get the rsnie and then need_ptk_4_way is set to firmware, so data path
      is disallowed and it will not receive 4 way handshake for OPEN mode,
      so ping fail in step 6.
      
      This patch is to pass the ssid info to cfg80211_get_bss() as same as
      cfg80211_mlme_assoc() and cfg80211_mlme_auth(), then it will find the
      correct bss entry in above test case, then case success.
      
      For AP mode, the ssid info is filled in ieee80211_start_ap(), for STATION
      mode, it is filled in ieee80211_mgd_assoc(). Tested for both AP/STATION
      mode with QCA6174 hw3.2 PCI, it is success start/connect/ping for
      WPA/OPEN mode.
      
      Tested-on: QCA6174 hw3.2 PCI WLAN.RM.4.4.1-00110-QCARMSWP-1
      
      Signed-off-by: default avatarWen Gong <wgong@codeaurora.org>
      Signed-off-by: default avatarKalle Valo <kvalo@codeaurora.org>
      Link: https://lore.kernel.org/r/1607312195-3583-3-git-send-email-wgong@codeaurora.org
      22df5e1b
    • Carl Huang's avatar
      ath10k: allow dynamic SAR power limits via common API · 442545ba
      Carl Huang authored
      
      
      ath10k assigns ath10k_mac_set_sar_specs to ath10k_ops, and
      this function is called when user space application calls
      NL80211_CMD_SET_SAR_SPECS. ath10k also registers SAR type,
      and supported frequency ranges to wiphy so user space can
      query SAR capabilities.
      
      This SAR power limitation is compared to regulatory txpower
      and selects the minimal one to set when station is connected.
      Otherwise, it delays until the station is connected. If the
      station is disconnected, it returns to regulatory txpower.
      
      This feature is controlled by hw parameter: dynamic_sar_support.
      
      Tested-on: QCA6174 hw3.2 PCI WLAN.RM.4.4.1-00110-QCARMSWP-1
      
      Signed-off-by: default avatarCarl Huang <cjhuang@codeaurora.org>
      Reviewed-by: default avatarBrian Norris <briannorris@chromium.org>
      Reviewed-by: default avatarAbhishek Kumar <kuabhs@chromium.org>
      Reported-by: default avatarkernel test robot <lkp@intel.com>
      Signed-off-by: default avatarKalle Valo <kvalo@codeaurora.org>
      Link: https://lore.kernel.org/r/20201203103728.3034-4-cjhuang@codeaurora.org
      442545ba
  3. Jan 27, 2021
    • Zheng Yongjun's avatar
      wcn36xx: Remove unnecessary memset · 337cd0d3
      Zheng Yongjun authored
      
      
      memcpy operation is next to memset code, and the size to copy is equals to the size to
      memset, so the memset operation is unnecessary, remove it.
      
      Signed-off-by: default avatarZheng Yongjun <zhengyongjun3@huawei.com>
      Signed-off-by: default avatarKalle Valo <kvalo@codeaurora.org>
      Link: https://lore.kernel.org/r/20201223012516.24286-1-zhengyongjun3@huawei.com
      337cd0d3
    • Wen Gong's avatar
      ath11k: add ieee80211_unregister_hw to avoid kernel crash caused by NULL pointer · 0d969683
      Wen Gong authored
      
      
      When function return fail to __ath11k_mac_register after success called
      ieee80211_register_hw, then it set wiphy->dev.parent to NULL by
      SET_IEEE80211_DEV(ar->hw, NULL) in end of __ath11k_mac_register, then
      cfg80211_get_drvinfo will be called by below call stack, but the
      wiphy->dev.parent is NULL, so kernel crash.
      
      Call stack to cfg80211_get_drvinfo:
      NetworkManager   826 [001]  6696.731371:    probe:cfg80211_get_drvinfo: (ffffffffc107d8f0)
              ffffffffc107d8f1 cfg80211_get_drvinfo+0x1 (/lib/modules/5.10.0-rc1-wt-ath+/kernel/net/wireless-back/cfg80211.ko)
              ffffffff9d8fc529 ethtool_get_drvinfo+0x99 (vmlinux)
              ffffffff9d90080e dev_ethtool+0x1dbe (vmlinux)
              ffffffff9d8b88f7 dev_ioctl+0xb7 (vmlinux)
              ffffffff9d8668de sock_do_ioctl+0xae (vmlinux)
              ffffffff9d866d60 sock_ioctl+0x350 (vmlinux)
              ffffffff9d2ca30e __x64_sys_ioctl+0x8e (vmlinux)
              ffffffff9da0dda3 do_syscall_64+0x33 (vmlinux)
              ffffffff9dc0008c entry_SYSCALL_64_after_hwframe+0x44 (vmlinux)
                  7feb5f673007 __GI___ioctl+0x7 (/lib/x86_64-linux-gnu/libc-2.23.so)
                             0 [unknown] ([unknown])
      
      Code of cfg80211_get_drvinfo, the pdev which is wiphy->dev.parent is
      NULL when kernel crash:
      void cfg80211_get_drvinfo(struct net_device *dev, struct ethtool_drvinfo *info)
      {
      	struct wireless_dev *wdev = dev->ieee80211_ptr;
      	struct device *pdev = wiphy_dev(wdev->wiphy);
      
      	if (pdev->driver)
      ....
      
      kernel crash log:
      [  973.619550] ath11k_pci 0000:05:00.0: failed to perform regd update : -16
      [  973.619555] ath11k_pci 0000:05:00.0: ath11k regd update failed: -16
      [  973.619566] ath11k_pci 0000:05:00.0: failed register the radio with mac80211: -16
      [  973.619618] ath11k_pci 0000:05:00.0: failed to create pdev core: -16
      [  973.636035] BUG: kernel NULL pointer dereference, address: 0000000000000068
      [  973.636046] #PF: supervisor read access in kernel mode
      [  973.636050] #PF: error_code(0x0000) - not-present page
      [  973.636054] PGD 800000012452e067 P4D 800000012452e067 PUD 12452d067 PMD 0
      [  973.636064] Oops: 0000 [#1] SMP PTI
      [  973.636072] CPU: 3 PID: 848 Comm: NetworkManager Kdump: loaded Tainted: G        W  OE     5.10.0-rc1-wt-ath+ #24
      [  973.636076] Hardware name: LENOVO 418065C/418065C, BIOS 83ET63WW (1.33 ) 07/29/2011
      [  973.636161] RIP: 0010:cfg80211_get_drvinfo+0x25/0xd0 [cfg80211]
      [  973.636169] Code: e9 c9 fe ff ff 66 66 66 66 90 55 53 ba 20 00 00 00 48 8b af 08 03 00 00 48 89 f3 48 8d 7e 04 48 8b 45 00 48 8b 80 90 01 00 00 <48> 8b 40 68 48 85 c0 0f 84 8d 00 00 00 48 8b 30 e8 a6 cc 72 c7 48
      [  973.636174] RSP: 0018:ffffaafb4040bbe0 EFLAGS: 00010286
      [  973.636180] RAX: 0000000000000000 RBX: ffffaafb4040bbfc RCX: 0000000000000000
      [  973.636184] RDX: 0000000000000020 RSI: ffffaafb4040bbfc RDI: ffffaafb4040bc00
      [  973.636188] RBP: ffff8a84c9568950 R08: 722d302e30312e35 R09: 74612d74772d3163
      [  973.636192] R10: 3163722d302e3031 R11: 2b6874612d74772d R12: ffffaafb4040bbfc
      [  973.636196] R13: 00007ffe453707c0 R14: ffff8a84c9568000 R15: 0000000000000000
      [  973.636202] FS:  00007fd3d179b940(0000) GS:ffff8a84fa2c0000(0000) knlGS:0000000000000000
      [  973.636206] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
      [  973.636211] CR2: 0000000000000068 CR3: 00000001153b6002 CR4: 00000000000606e0
      [  973.636215] Call Trace:
      [  973.636234]  ethtool_get_drvinfo+0x99/0x1f0
      [  973.636246]  dev_ethtool+0x1dbe/0x2be0
      [  973.636256]  ? mntput_no_expire+0x35/0x220
      [  973.636264]  ? inet_ioctl+0x1ce/0x200
      [  973.636274]  ? tomoyo_path_number_perm+0x68/0x1d0
      [  973.636282]  ? kmem_cache_alloc+0x3cb/0x430
      [  973.636290]  ? dev_ioctl+0xb7/0x570
      [  973.636295]  dev_ioctl+0xb7/0x570
      [  973.636307]  sock_do_ioctl+0xae/0x150
      [  973.636315]  ? sock_ioctl+0x350/0x3c0
      [  973.636319]  sock_ioctl+0x350/0x3c0
      [  973.636332]  ? __x64_sys_ioctl+0x8e/0xd0
      [  973.636339]  ? dlci_ioctl_set+0x30/0x30
      [  973.636346]  __x64_sys_ioctl+0x8e/0xd0
      [  973.636359]  do_syscall_64+0x33/0x80
      [  973.636368]  entry_SYSCALL_64_after_hwframe+0x44/0xa9
      
      Sequence of function call when wlan load for success case when function
      __ath11k_mac_register return 0:
      
      kworker/u16:3-e  2922 [001]  6696.729734:   probe:ieee80211_register_hw: (ffffffffc116ae60)
      kworker/u16:3-e  2922 [001]  6696.730210:        probe:ieee80211_if_add: (ffffffffc1185cc0)
      NetworkManager   826 [001]  6696.731345:     probe:ethtool_get_drvinfo: (ffffffff9d8fc490)
      NetworkManager   826 [001]  6696.731371:    probe:cfg80211_get_drvinfo: (ffffffffc107d8f0)
      NetworkManager   826 [001]  6696.731639:     probe:ethtool_get_drvinfo: (ffffffff9d8fc490)
      NetworkManager   826 [001]  6696.731653:    probe:cfg80211_get_drvinfo: (ffffffffc107d8f0)
      NetworkManager   826 [001]  6696.732866:     probe:ethtool_get_drvinfo: (ffffffff9d8fc490)
      NetworkManager   826 [001]  6696.732893:    probe:cfg80211_get_drvinfo: (ffffffffc107d8f0)
      systemd-udevd  3850 [003]  6696.737199:     probe:ethtool_get_drvinfo: (ffffffff9d8fc490)
      systemd-udevd  3850 [003]  6696.737226:    probe:cfg80211_get_drvinfo: (ffffffffc107d8f0)
      NetworkManager   826 [000]  6696.759950:     probe:ethtool_get_drvinfo: (ffffffff9d8fc490)
      NetworkManager   826 [000]  6696.759967:    probe:cfg80211_get_drvinfo: (ffffffffc107d8f0)
      NetworkManager   826 [000]  6696.760057:     probe:ethtool_get_drvinfo: (ffffffff9d8fc490)
      NetworkManager   826 [000]  6696.760062:    probe:cfg80211_get_drvinfo: (ffffffffc107d8f0)
      
      After apply this patch, kernel crash gone, and below is the test case's
      sequence of function call and log when wlan load with fail by function
      ath11k_regd_update, and __ath11k_mac_register return fail:
      
      kworker/u16:5-e   192 [001]   215.174388:   probe:ieee80211_register_hw: (ffffffffc1131e60)
      kworker/u16:5-e   192 [000]   215.174973:        probe:ieee80211_if_add: (ffffffffc114ccc0)
      NetworkManager   846 [001]   215.175857:     probe:ethtool_get_drvinfo: (ffffffff928fc490)
      kworker/u16:5-e   192 [000]   215.175867: probe:ieee80211_unregister_hw: (ffffffffc1131970)
      NetworkManager   846 [001]   215.175880:    probe:cfg80211_get_drvinfo: (ffffffffc107f8f0)
      NetworkManager   846 [001]   215.176105:     probe:ethtool_get_drvinfo: (ffffffff928fc490)
      NetworkManager   846 [001]   215.176118:    probe:cfg80211_get_drvinfo: (ffffffffc107f8f0)
      [  215.175859] ath11k_pci 0000:05:00.0: ath11k regd update failed: -16
      NetworkManager   846 [001]   215.196420:     probe:ethtool_get_drvinfo: (ffffffff928fc490)
      NetworkManager   846 [001]   215.196430:    probe:cfg80211_get_drvinfo: (ffffffffc107f8f0)
      [  215.258598] ath11k_pci 0000:05:00.0: failed register the radio with mac80211: -16
      [  215.258613] ath11k_pci 0000:05:00.0: failed to create pdev core: -16
      
      When ath11k_regd_update or ath11k_debugfs_register return fail, function
      ieee80211_unregister_hw of mac80211 will be called, then it will wait
      untill cfg80211_get_drvinfo finished, the wiphy->dev.parent is not NULL
      at this moment, after that, it set wiphy->dev.parent to NULL by
      SET_IEEE80211_DEV(ar->hw, NULL) in end of __ath11k_mac_register, so
      not happen kernel crash.
      
      Tested-on: QCA6390 hw2.0 PCI WLAN.HST.1.0.1-01740-QCAHSTSWPLZ_V2_TO_X86-1
      Signed-off-by: default avatarWen Gong <wgong@codeaurora.org>
      Signed-off-by: default avatarKalle Valo <kvalo@codeaurora.org>
      Link: https://lore.kernel.org/r/1608607824-16067-1-git-send-email-wgong@codeaurora.org
      0d969683
  4. Jan 19, 2021
  5. Jan 12, 2021
  6. Jan 10, 2021