summaryrefslogtreecommitdiff
path: root/drivers
diff options
context:
space:
mode:
authorAaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>2026-06-30 11:50:48 +0530
committerJeff Johnson <jeff.johnson@oss.qualcomm.com>2026-07-22 09:02:19 -0700
commit42399be44b13eafb45c56b1c7d7c92107e50c289 (patch)
tree88aac0f89638e3e49dd98d1ce81039bb6d0c2e13 /drivers
parentecb517f97e629d3b8c360cbb5db3fed4d599ea2e (diff)
downloadlinux-next-42399be44b13eafb45c56b1c7d7c92107e50c289.tar.gz
linux-next-42399be44b13eafb45c56b1c7d7c92107e50c289.zip
wifi: ath12k: allocate HOST_DDR and BDF regions after Q6 RO region
Currently, the Q6 region contains a read-only firmware region along with the BDF_MEM_REGION_TYPE and HOST_DDR_REGION_TYPE memory areas. The firmware expects these writable memory regions to be assigned after the Q6 read-only section. However, the ath12k driver currently allocates the HOST_DDR_REGION_TYPE starting from the base of the Q6 region, which includes the read-only firmware area. As a result, the allocated memory regions overlap with the read-only section, causing the firmware to assert during QMI memory allocation. The Q6 memory region layout is as follows: Q6 Reserved Memory +--------------------------------------+ | | | Read-only Firmware Region | | (Q6 RO Region) | | | +--------------------------------------+ <--- bdf_addr_offset | Writable Memory Region | | (BDF + HOST_DDR allocations) | | | +--------------------------------------+ Fix this by allocating the required memory regions only after the end of the read-only region in the Q6 address space. The bdf_addr_offset parameter indicates where the writable region starts. Both HOST_DDR and BDF regions are allocated sequentially after this offset, with each region placed immediately after the previous one to avoid gaps and overlaps. Tested-on: IPQ5332 hw1.0 AHB WLAN.WBE.1.6-01275-QCAHKSWPL_SILICONZ-1 Fixes: 6757079c5890 ("wifi: ath12k: add support for fixed QMI firmware memory") Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Signed-off-by: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com> Link: https://patch.msgid.link/20260630062048.1615178-4-aaradhana.sahu@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Diffstat (limited to 'drivers')
-rw-r--r--drivers/net/wireless/ath/ath12k/qmi.c19
1 files changed, 15 insertions, 4 deletions
diff --git a/drivers/net/wireless/ath/ath12k/qmi.c b/drivers/net/wireless/ath/ath12k/qmi.c
index 4636aef29300..bb61c78e5c29 100644
--- a/drivers/net/wireless/ath/ath12k/qmi.c
+++ b/drivers/net/wireless/ath/ath12k/qmi.c
@@ -2797,8 +2797,8 @@ static const char *ath12k_qmi_get_mem_reg_name(int mem_type)
static int ath12k_qmi_assign_target_mem_chunk(struct ath12k_base *ab)
{
struct device_node *np = ab->dev->of_node;
+ size_t avail_rmem_size, offset = 0;
struct target_mem_chunk *chunk;
- size_t avail_rmem_size;
struct resource res;
const char *rname;
int i, idx, ret;
@@ -2832,9 +2832,20 @@ static int ath12k_qmi_assign_target_mem_chunk(struct ath12k_base *ab)
goto out;
avail_rmem_size = resource_size(&res);
- if (chunk->type == BDF_MEM_REGION_TYPE) {
- avail_rmem_size -= ab->hw_params->bdf_addr_offset;
- res.start += ab->hw_params->bdf_addr_offset;
+ if (chunk->type == BDF_MEM_REGION_TYPE ||
+ chunk->type == HOST_DDR_REGION_TYPE) {
+ if (ab->hw_params->bdf_addr_offset > avail_rmem_size ||
+ offset > avail_rmem_size - ab->hw_params->bdf_addr_offset) {
+ ath12k_err(ab, "qmi mem offset overflow: bdf_offset=%u offset=%zu size=%zu\n",
+ ab->hw_params->bdf_addr_offset, offset,
+ avail_rmem_size);
+ ret = -EINVAL;
+ goto out;
+ }
+
+ avail_rmem_size -= ab->hw_params->bdf_addr_offset + offset;
+ res.start += ab->hw_params->bdf_addr_offset + offset;
+ offset += chunk->size;
}
if (avail_rmem_size < chunk->size) {