summaryrefslogtreecommitdiff
path: root/drivers/net/wireless/ath
AgeCommit message (Collapse)Author
2 daysMerge branch 'for-next' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/ath/ath.git
2 daysMerge branch 'for-next' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless-next.git
2 daysMerge branch 'main' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next.git
2 daysMerge branch 'next' of ↵Mark Brown
https://git.kernel.org/pub/scm/linux/kernel/git/pci/pci.git
2 dayswifi: cfg80211: regulatory: stop using RTNLJohannes Berg
Now we have cfg80211_mutex everywhere along with wiphy mutex for per-device bits, so don't need RTNL any more. Remove it from the regulatory code. Also, wiphy_apply_custom_regulatory() no longer needs the RTNL, and get_wiphy_regdom() can no longer rely on it. Link: https://patch.msgid.link/20261006120655.df1d3d28cfa2.I637dbd328886b52bed511fb798172a2d57521263@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2 dayswifi: ath12k: read wiphy regd under RCUJohannes Berg
Part of the RTNL removal here means the notifier will no longer hold the RTNL, so rcu_dereference_rtnl() can't be used any more. Use an RCU critical section which works either way, we don't have access to the cfg80211_mutex in the drivers. Link: https://patch.msgid.link/20261006120655.b59589afb302.Ieeec0e112066ccefeac6b746fdfd268611c2cc65@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2 dayswifi: ath11k: read wiphy regd under RCUJohannes Berg
Part of the RTNL removal here means the notifier will no longer hold the RTNL, so rcu_dereference_rtnl() can't be used any more. Use an RCU critical section which works either way, we don't have access to the cfg80211_mutex in the drivers. Link: https://patch.msgid.link/20261006120655.2959e1a05eb0.I92dbc5e611309de4ea3bc11fefea609a5f2d0af4@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2 dayswifi: ath: use freq_reg_info() under RCUJohannes Berg
This will soon be required, because there won't be the RTNL to protect everything. Use RCU for freq_reg_info(). Link: https://patch.msgid.link/20261006120655.b619ce4ac9a8.I44fbb6c36186a6b14a68d6f8f1010c30c69441bd@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2 dayswifi: ath6kl: don't take RTNL in del_virtual_intfJohannes Berg
cfg80211 already holds the RTNL here, so this will just deadlock. Remove the extra RTNL acquisition. Oddly enough this was all true even back when the locking here was added, so this is just a revert of a broken ~13 year old commit. Fixes: bc52aab380c7 ("ath6kl: Protect ath6kl_cfg80211_vif_cleanup using rtnl_locks") Signed-off-by: Johannes Berg <johannes.berg@intel.com> Link: https://patch.msgid.link/20261008165646.48866f0521af.I1c166be830384473f67677eeb187afa7e54106ea@changeid Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2 dayswifi: ath12k: validate MAC/PHY capability count before savingJiale Yao
Firmware supplies the hardware mode count and the PHY bitmap for each mode in the service-ready-ext event. ath12k_wmi_save_all_mac_phy_info() uses those bitmaps to populate svc_ext_info->mac_phy_info, but the destination is a fixed array of ATH12K_MAX_MAC_PHY_CAP elements. If the total number of advertised PHY entries exceeds that limit, the loop writes beyond mac_phy_info and corrupts adjacent memory. ath12k_wmi_mac_phy_caps_parse() allocates the source array for tot_phy_id entries and rejects excess capability TLVs. However, if the event contains fewer capability TLVs than advertised, the remaining allocated entries stay zeroed and are saved as invalid PHY information. After parsing the MAC/PHY capability TLVs, validate the destination capacity and reject an incomplete capability list before saving any entries. Fixes: 062ade23991e ("wifi: ath12k: parse and save hardware mode info from WMI_SERVICE_READY_EXT_EVENTID event for later use") Cc: stable@vger.kernel.org Signed-off-by: Jiale Yao <yaojiale02@163.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Link: https://patch.msgid.link/20261003101944.596546-1-yaojiale02@163.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2 dayswifi: ath12k: advertise interface MAC address poolVitor Soares
ath12k supports creating vdevs with addresses provided by mac80211. Userspace can already make concurrent interfaces work by explicitly assigning different locally administered addresses. However, ath12k does not advertise an address list, so when a second interface is created without an explicit address, mac80211 has nothing to pick from and falls back to the permanent address. If the first interface is already running with that address, bringing up the second one fails with -ENOTUNIQ. As in ath11k, provide a list of usable addresses so ieee80211_assign_perm_addr() can hand each new interface an unused one. Keep the first entry as the wiphy's permanent MAC address. Generate the remaining entries as locally administered variants by changing only the upper nibble of the first octet, which naturally limits the pool to 16 unique addresses. The cfg80211 definition of wiphy->addresses does not specify where the addresses must come from. Some ath12k platforms use it as an interface MAC address pool, while others use it for firmware-provided per-radio addresses. Gate the generated address pool behind advertise_iface_mac_pool and enable it for WCN7850 and QCC2072. The flag is read from the first radio, as all radios behind a wiphy are expected to have the same setting. Other platforms keep the existing behavior. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3 Tested-on: QCC2072 hw1.0 PCI WLAN.COL.1.0.c2-00074-QCACOLSWPL_V1_TO_SILICONZ-1 Assisted-by: LLM Signed-off-by: Vitor Soares <vitor.soares@toradex.com> Tested-by: Kang Yang <kang.yang@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Link: https://patch.msgid.link/20260922200643.1133491-2-ivitro@gmail.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
3 daysMerge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski
Cross-merge networking fixes after downstream PR (net-7.3-rc7). Conflicts: include/net/strparser.h 0984ebc631792 ("strparser: make sure __strp_recv isn't running before tearing down the parser") 02fd0a2111374 ("net: strparser: removed the aborted bit and aborts counter") https://lore.kernel.org/asYfmLsfy-SCxXjr@sirena.co.uk Adjacent changes: Documentation/networking/strparser.rst 5f193cdabf25 ("docs: networking: strparser: remove general mode") 0984ebc63179 ("strparser: make sure __strp_recv isn't running before tearing down the parser") Signed-off-by: Jakub Kicinski <kuba@kernel.org>
5 daysRevert "wifi: ath12k: add panic handler"Yingying Tang
ath12k_core_panic_handler() is invoked via atomic_notifier_call_chain(), which runs inside an RCU read-side critical section. The current code calls ath12k_pci_sw_reset() synchronously from this context, which eventually reaches mhi_device_get_sync() and schedule_timeout(), triggering a voluntary context switch within RCU. Call trace: rcu_note_context_switch+0x4c4/0x508 (P) __schedule+0xbc/0x1204 schedule+0x34/0x110 schedule_timeout+0x84/0x11c __mhi_device_get_sync+0x164/0x228 [mhi] mhi_device_get_sync+0x1c/0x3c [mhi] ath12k_wifi7_pci_bus_wake_up+0x20/0x2c [ath12k_wifi7] ath12k_pci_read32+0x58/0x350 [ath12k] ath12k_pci_clear_dbg_registers+0x28/0xb8 [ath12k] ath12k_pci_panic_handler+0x20/0x44 [ath12k] ath12k_core_panic_handler+0x28/0x3c [ath12k] notifier_call_chain+0x78/0x1c0 atomic_notifier_call_chain+0x3c/0x5c Revert change "wifi: ath12k: add panic handler" to avoid this issue. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3 Signed-off-by: Yingying Tang <yingying.tang@oss.qualcomm.com> Tested-by: Joonhoe Kim <26rote@gmail.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Fixes: 809055628bce ("wifi: ath12k: add panic handler") Link: https://patch.msgid.link/20260612032332.2278338-1-yingying.tang@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
6 dayswifi: ath10k: clear QMI if failed during initAlbert Esteve
A failed ath10k_qmi_init() leaves a dangling pointer (ar_snoc->qmi) in the cleanup path. Clear the pointer on the way out for hygiene and consistency with deinit(). Signed-off-by: Albert Esteve <aesteve@redhat.com> Reviewed-by: Brian Norris <briannorris@chromium.org> Link: https://patch.msgid.link/20260914-fix-ath10k-dangling-v1-1-15c5089682b1@redhat.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
6 dayswifi: ath9k: refuse spectral scan control while the hardware is disabledNerijus Bendžiūnas
The spectral_scan_ctl debugfs file drives PHY register writes, and nothing checks whether the hardware is up. While the interface is down the chip is asleep, and on the AR9271 those writes go over WMI to a sleeping target and hang the firmware until the device is re-enumerated. Refuse the write with -EBUSY while ATH_OP_INVALID is set. The reset control already refuses on the same flag. Assisted-by: LLM Signed-off-by: Nerijus Bendžiūnas <nerijus.bendziunas@gmail.com> Acked-by: Toke Høiland-Jørgensen <toke@toke.dk> Link: https://patch.msgid.link/20260908180308.788642-1-nerijus.bendziunas@gmail.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
6 dayswifi: ath9k: delete channel-context timers on deinitRosen Penev
ath9k_deinit_channel_context() cancels chanctx_work but does not delete the offchannel and sched timers set up by ath9k_init_channel_context(). If either timer fires after deinit (e.g. during driver unload or suspend), it accesses sc->sc_ah which may already be freed by ath9k_hw_deinit(), causing a use-after-free. Delete both timers with timer_shutdown_sync() before cancelling the work item. Assisted-by: LLM Signed-off-by: Rosen Penev <rosenp@gmail.com> Acked-by: Toke Høiland-Jørgensen <toke@toke.dk> Cc: stable@vger.kernel.org # v6.2+ Fixes: 705d0bf83dbe ("ath9k: Add a routine for initializing channel contexts") Link: https://patch.msgid.link/20260911213144.130192-1-rosenp@gmail.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
6 dayswifi: ath12k: Reserve space for a string terminatorJiale Yao
ath12k_write_htt_stats_type() accepts count == size, which fills the zero-initialized buffer without a terminating NUL. sscanf() then reads beyond the buffer. Reject input that leaves no room for the trailing NUL. Fixes: 8c7a5031a6b0 ("wifi: ath12k: Fix buffer overflow in debugfs") Reviewed-by: Dan Carpenter <error27@gmail.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Signed-off-by: Jiale Yao <yaojiale02@163.com> Link: https://patch.msgid.link/20261003095913.575108-1-yaojiale02@163.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
6 dayswifi: ath11k: fix unbalanced IRQ enable/disable during suspend/resumeBaochen Qiang
Commit f7a74e131d3f ("wifi: ath11k: disable interrupts during firmware crash recovery") added an unconditional ath11k_hif_irq_disable()/ ath11k_hif_ce_irq_disable() pair inside ath11k_core_reconfigure_on_crash(), guarded by "if (!ab->is_reset)", to stop the DP NAPI from touching rings that have just been torn down. That fixes AHB device recovery, but breaks PCI device suspend/resume. During suspend, IRQs are disabled once in ath11k_core_suspend_late(). Then during resume, ath11k_core_reconfigure_on_crash() sees ab->is_reset clear and disables them a second time. Those IRQs are enabled only once during the following reinitialization, leaving the IRQ lines masked. As a result, HTC control responses never arrive, and resume fails: failed to receive control response completion, polling.. failed to connect to HTT: -110 failed to reconfigure driver on crash recovery failed to resume core: -110 Fix this by disabling the IRQs unconditionally at the top of ath11k_core_reconfigure_on_crash(), and instead drop the disable calls from the two places that already disable IRQs before this function can run: ath11k_core_suspend_late() and ath11k_core_reset(). This keeps a single disable per recovery/suspend cycle regardless of which path (recovery or suspend) triggers it, so the refcount on PCI parts stays balanced while AHB parts keep getting the disable that the original commit needed. Fixes: f7a74e131d3f ("wifi: ath11k: disable interrupts during firmware crash recovery") Reported-by: Marek Szyprowski <m.szyprowski@samsung.com> Closes: https://lore.kernel.org/linux-wireless/a068a857-a549-4cc2-ae0f-3ef119d3a859@samsung.com/ Tested-by: Marek Szyprowski <m.szyprowski@samsung.com> Tested-by: Julius Bairaktaris <julius@bairaktaris.de> Signed-off-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Link: https://patch.msgid.link/20260928-ath11k-unbalanced-irq-enable-disable-v1-1-75166f534763@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
6 dayswifi: carl9170: NUL terminate string in debugfsDan Carpenter
The "buf" buffer comes from the user. We use it to store a number or two so it doesn't need to be large. It gets passed to sscanf() in the write functions such as carl9170_debugfs_erp_write(). Ensure that buffer is NUL terminated. This is debugfs so it's root only. Fixes: 00c4da27a421 ("carl9170: firmware parser and debugfs code") Signed-off-by: Dan Carpenter <error27@gmail.com> Acked-by: Christian Lamparter <chunkeey@gmail.com> Acked-by: Jeff Johnson <jjohnson@kernel.org> Link: https://patch.msgid.link/674270ab4aeefa1982362c0ea4132427e14f15eb.1790839793.git.error27@gmail.com Signed-off-by: Johannes Berg <johannes.berg@intel.com>
10 daysMerge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski
Cross-merge networking fixes after downstream PR (net-7.3-rc6). Conflicts: net/mac80211/tx.c net/mac80211/ieee80211_i.h 8effab902fa34 ("wifi: mac80211: prevent AP VLAN tx from other interfaces") 78b843974fb83 ("wifi: mac80211: report multicast transmission from lookup_ra_sta()") https://lore.kernel.org/arJmcuhpJ69wAvYK@sirena.co.uk drivers/net/ethernet/realtek/r8169_main.c 3cdeaef1754ab ("r8169: disable EEE on RTL8168h/8111h") 8a3c76523e449 ("r8169: add support for phylink") https://lore.kernel.org/ar5vAxEqS8tO8aVT@sirena.org.uk Adjacent changes: rust/kernel/net/netlink.rs 5e5916923759 ("rust: net: netlink: Migrate to zerocopy's IntoBytes") 0923198be4ae ("rust: net: netlink: validate attribute length before casting to `c_int`") Signed-off-by: Jakub Kicinski <kuba@kernel.org>
13 daysMerge tag 'ath-next-20260927' of ↵Johannes Berg
git://git.kernel.org/pub/scm/linux/kernel/git/ath/ath Jeff Johnson says: ================== ath.git patches for v7.4 (PR #2) For ath10k, document NVMEM device tree bindings. For ath11k, fix an error path resource leak. For ath12k, fix monitor RX buffer lifecycle issues, properly align QMI memory to meet firmware requirements, extend datapath device stats coverage, and a few other cleanups. ================== Signed-off-by: Johannes Berg <johannes.berg@intel.com>
14 dayswifi: cfg80211: add Control Integrity Protocol (CIP) APIsBenjamin Berg
The Control Integrity Protocol consists of a set of capabilities for the MIC padding as well as a new CIGTK that can be installed. The CIGTK uses a fixed GMAC-256 cipher for which no RSN extension is defined as it is bound to the pairwise cipher being GCMP-256. The CIGTK uses the key index 0 and 1, making it necessary to add a new key type for it. Add a new CIP feature flag and attributes for CIP Capabilities and enabling the feature for stations and the association. Also extend the cfg80211 API to pass the key type rather than a single pairwise boolean. Signed-off-by: Benjamin Berg <benjamin.berg@intel.com> Link: https://patch.msgid.link/20260921144048.aa7939493375.I49c0be0a1b05d625cc307e9bdd13c32a6c18667f@changeid Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-09-25wifi: ath12k: add WBM SW desc fallback counterAniruddha Mishra
When HW CC is not done, the WBM RX error path falls back to cookie-based descriptor retrieval via ath12k_dp_get_rx_desc(). This fallback path is taken before knowing whether the retrieval will succeed, so it is not a drop event and should not be counted in the drop[] array. Add a dedicated sw_desc_fallback counter in ath12k_device_dp_rx_wbm_err_stats to track how often the HW CC fallback path is taken, distinct from actual packet drops. Expose the counter in the device_dp_stats debugfs file as a separate line. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6.r1-00402-QCAHKSWPL_SILICONZ-1 Signed-off-by: Aniruddha Mishra <aniruddha.mishra@oss.qualcomm.com> Co-developed-by: Pardeep Kaur <pardeep.kaur@oss.qualcomm.com> Signed-off-by: Pardeep Kaur <pardeep.kaur@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Link: https://patch.msgid.link/20260819053247.1420393-9-pardeep.kaur@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: fix 1-based ring index in REO Rx Received debugfs outputPardeep Kaur
The REO Rx Received section in device_dp_stats debugfs uses a 1-based ring index ("Ring1:", "Ring2:", ...) which is inconsistent with the rest of ath12k where rings are indexed from 0. Fix it to use 0-based indexing and lowercase "ring%d:" to match the style used by all other ring counters in the same function. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6.r1-00402-QCAHKSWPL_SILICONZ-1 Signed-off-by: Pardeep Kaur <pardeep.kaur@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Link: https://patch.msgid.link/20260819053247.1420393-8-pardeep.kaur@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: track per-ring RX sent-to-stack countHariharan Ramanathan
The device DP stats provide visibility into RX errors and drops but lack a counter for successfully delivered packets. Without this, it is difficult to correlate REO ring activity with actual stack delivery during debugging or performance analysis. Add sent_to_stack[DP_REO_DST_RING_MAX][ATH12K_MAX_DEVICES] to ath12k_device_dp_stats to track successful deliveries per REO ring per device. The counter is attributed to the ring owner's dp and indexed by partner_dp->device_id, keeping it in the same debugfs file as reo_rx[] for direct comparison in MLO configurations. Increment the counter just before each MSDU is handed off to the stack via ath12k_dp_rx_deliver_msdu(). Add a likely()/WARN_ON_ONCE() bounds check on ring_id before indexing sent_to_stack[], consistent with all other new stat arrays in this series. Expose the per-ring per-device counts in the device_dp_stats debugfs file under a new 'REO sent to stack:' section. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6.r1-00402-QCAHKSWPL_SILICONZ-1 Signed-off-by: Hariharan Ramanathan <hariharan.ramanathan@oss.qualcomm.com> Co-developed-by: Pardeep Kaur <pardeep.kaur@oss.qualcomm.com> Signed-off-by: Pardeep Kaur <pardeep.kaur@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Link: https://patch.msgid.link/20260819053247.1420393-7-pardeep.kaur@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: add WBM RX error drop statisticsAniruddha Mishra
Without fine-grained drop counters, diagnosing RX failures in the WBM error path requires intrusive debugging. Introduce per-drop-reason counters to track exactly where and why packets are dropped during WBM RX error handling. Introduce a new dp_stats.h header and define ath12k_wbm_err_drop_reason enum there covering all drop points in the WBM RX error path: descriptor parse failures, SW descriptor retrieval errors, null partner DP, invalid HW link ID, null pdev/ar, CAC running, scatter-gather drops, and invalid NWifi header length. The new header is included by dp.h which is already included by all consumers. Add ath12k_device_dp_rx_wbm_err_stats struct grouping rxdma_error[], reo_error[], and the new drop[] counters, replacing the flat arrays previously in ath12k_device_dp_stats. Add bounds checks before indexing rxdma_error[] and reo_error[] with hardware-supplied err_code values to prevent out-of-bounds writes, using the same likely/WARN_ON_ONCE pattern as the TX stats bounds fixes. Add ath12k_wifi7_dp_rx_wbm_err_free_skb() helper to combine drop stat increment and skb free at each drop site, reducing repetition. Define the helper at the top of dp_rx.c before its first use. Increment WBM_ERR_DROP_RXDMA_GENERIC only inside rxdma_err()'s default: branch so it counts only unhandled RXDMA errors, not every RXDMA drop - consistent with how WBM_ERR_DROP_REO_GENERIC is counted. Expose WBM RX drop counts in the device_dp_stats debugfs file under a new 'WBM Rx Drop Count' section. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6.r1-00402-QCAHKSWPL_SILICONZ-1 Signed-off-by: Aniruddha Mishra <aniruddha.mishra@oss.qualcomm.com> Co-developed-by: Pardeep Kaur <pardeep.kaur@oss.qualcomm.com> Signed-off-by: Pardeep Kaur <pardeep.kaur@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Link: https://patch.msgid.link/20260819053247.1420393-6-pardeep.kaur@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: add device DP stats reset support via debugfsHariharan Ramanathan
There is no way to reset device DP stats counters without reloading the driver, making it difficult to isolate issues to a specific time window during debugging. Add a write handler to the device_dp_stats debugfs file so that writing 'reset' clears all device DP stats counters. Change the file mode from 0400 to 0600 to allow write access. Use simple_write_to_buffer() to correctly handle partial writes and non-zero ppos, consistent with ath12k_write_simulate_fw_crash(). No lock is taken around the memset since the counters are updated locklessly in the datapath; taking dp_lock would be misleading as it does not protect device_stats updates. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6.r1-00402-QCAHKSWPL_SILICONZ-1 Signed-off-by: Hariharan Ramanathan <hariharan.ramanathan@oss.qualcomm.com> Co-developed-by: Pardeep Kaur <pardeep.kaur@oss.qualcomm.com> Signed-off-by: Pardeep Kaur <pardeep.kaur@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Link: https://patch.msgid.link/20260819053247.1420393-5-pardeep.kaur@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: add TCL ring TX buffer allocation failure counterHariharan Ramanathan
When ath12k_dp_tx_assign_buffer() fails, the TX path returns -ENOMEM silently with no visibility into which traffic class is affected. Without a counter, TX descriptor pool exhaustion is invisible during debugging. Add txbuf_na[] indexed by pool_id to ath12k_device_dp_tx_err_stats to track TX descriptor pool allocation failures per traffic class and increment it on assign failure in the TX path. Expose the per-pool counts in debugfs under a new 'TX Descriptor Pool Alloc Failures' section. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6.r1-00402-QCAHKSWPL_SILICONZ-1 Signed-off-by: Hariharan Ramanathan <hariharan.ramanathan@oss.qualcomm.com> Co-developed-by: Pardeep Kaur <pardeep.kaur@oss.qualcomm.com> Signed-off-by: Pardeep Kaur <pardeep.kaur@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Link: https://patch.msgid.link/20260819053247.1420393-4-pardeep.kaur@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: rename wbm_status to htt_status in HTT TX completionHariharan Ramanathan
The variable wbm_status in ath12k_dp_tx_process_htt_tx_complete() holds a value from the HTT TX WBM completion status field, not a generic WBM status. Rename it to htt_status to accurately reflect the field origin and improve code clarity. Also fix ts.acked assignment inside the HAL_WBM_REL_HTT_TX_COMP_STATUS_OK case to use true directly since the condition is always true within that case branch. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6.r1-00402-QCAHKSWPL_SILICONZ-1 Signed-off-by: Hariharan Ramanathan <hariharan.ramanathan@oss.qualcomm.com> Co-developed-by: Pardeep Kaur <pardeep.kaur@oss.qualcomm.com> Signed-off-by: Pardeep Kaur <pardeep.kaur@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Link: https://patch.msgid.link/20260819053247.1420393-3-pardeep.kaur@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: fix out-of-bounds access on TX stats arraysPardeep Kaur
The fw_tx_status[], tx_wbm_rel_source[], and tqm_rel_reason[] arrays are indexed directly by values read from hardware without bounds checks. Values at or beyond MAX_FW_TX_STATUS, HAL_WBM_REL_SRC_MODULE_MAX, or MAX_TQM_RELEASE_REASON respectively would write past the end of the arrays causing memory corruption. Add likely() bounds checks before incrementing each counter. For tx_wbm_rel_source[] and tqm_rel_reason[], add WARN_ON_ONCE() on the out-of-bounds else branch. For fw_tx_status[], no WARN_ON_ONCE is added since the switch statement that follows already calls ath12k_warn() in its default: branch for unknown values, avoiding a double-warn. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6.r1-00402-QCAHKSWPL_SILICONZ-1 Fixes: c5c62287e690 ("wifi: ath12k: Add device dp stats support") Signed-off-by: Pardeep Kaur <pardeep.kaur@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Link: https://patch.msgid.link/20260819053247.1420393-2-pardeep.kaur@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: remove unused ath12k_dp_rx_h_find_link_peer()Miaoqing Pan
ath12k_dp_rx_h_find_link_peer() is no longer referenced anywhere, remove the unused helper and its declaration to avoid dead code. Tested-on: QCC2072 hw1.0 PCI CI_WLAN.COL.1.0.c2-00229.1-QCACOLSWPL_V1_TO_SILICON-1 Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3 Signed-off-by: Miaoqing Pan <miaoqing.pan@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Link: https://patch.msgid.link/20260803010532.302038-1-miaoqing.pan@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath11k: fix reg_info_store leak in ath11k_service_ready_ext_event()Jeff Johnson
Currently, while processing the WMI Service Ready Ext event, the iterator in ath11k_service_ready_ext_event() can dispatch the HAL Regulatory Capabilities handler ath11k_wmi_tlv_ext_soc_hal_reg_caps_parse() which can allocate ab->reg_info_store. If a subsequent failure occurs during iteration, the ab->reg_info_store allocation is leaked. Directly free and clear the pointer on the error path. Note that the normal cleanup function ath11k_reg_free() cannot be used since other regulatory-related fields are not yet populated at this point. Compile tested only. Fixes: 7004bdceef60 ("wifi: ath11k: store cur_regulatory_info for each radio") Assisted-by: Claude:claude-sonnet-4-6 Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Link: https://patch.msgid.link/20260817-reg_info_store-leak-v1-1-77025a99b074@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: align QMI target memory to 64 KBBaochen Qiang
ath12k_qmi_alloc_chunk() allocates the target memory chunks the firmware requests via dma_alloc_coherent() and hands the resulting physical addresses to the firmware. The firmware does not require every chunk to be aligned, but each unaligned chunk consumes extra TLB entries when the firmware maps it, and too many unaligned chunks exhaust the TLB and make the firmware crash. The firmware team recommends aligning the chunks to 64 KB so that the TLB stays within budget. dma_alloc_coherent() only guarantees page alignment, so a chunk can end up unaligned. Align the physical address handed to the firmware to 64 KB. A natural allocation is often already 64 KB aligned, so try the exact size first and keep it when it happens to be aligned; only when it is not, free it and over-allocate by SZ_64K - PAGE_SIZE and round the base up. Since the DMA allocator already guarantees page alignment, that padding is enough to reach the next 64 KB boundary. Record the raw allocation in paddr_unaligned/vaddr_unaligned/total_size so the chunk can still be freed correctly. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3 Tested-on: QCC2072 hw1.0 PCI WLAN.COL.1.0.c2-00074-QCACOLSWPL_V1_TO_SILICONZ-1 Signed-off-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Link: https://patch.msgid.link/20260730-ath12k-align-qmi-memory-v1-3-0fef98dda614@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: clear chunk paddr and size in ath12k_qmi_free_target_mem_chunk()Baochen Qiang
paddr and size of a chunk are not cleared after the chunk is freed, which is safe now since the code checks vaddr only and it is properly cleared on free. However, leaving stale values can mislead diagnostics and future maintenance. Clear both to reduce such risk, this also aligns with ath12k_qmi_free_mlo_mem_chunk(). Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3 Tested-on: QCC2072 hw1.0 PCI WLAN.COL.1.0.c2-00074-QCACOLSWPL_V1_TO_SILICONZ-1 Signed-off-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Link: https://patch.msgid.link/20260730-ath12k-align-qmi-memory-v1-2-0fef98dda614@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: use per-device max QMI chunk sizeBaochen Qiang
When a target memory chunk fails to allocate, ath12k_qmi_alloc_chunk() compares the requested chunk size against ATH12K_QMI_MAX_CHUNK_SIZE to decide whether to ask the firmware to retry with smaller chunks (-EAGAIN) or to give up (-ENOMEM). This threshold is the boundary that tells a first (big) request apart from a retry (small) request, so it has to match the size the firmware actually falls back to on retry. That fallback size is not the same across all firmware, though. On WCN7850 and QCC2072 the firmware splits the request into 512 KB chunks on retry, whereas on QCN9274, IPQ5332 and IPQ5424 the firmware retries with larger 2 MB segments instead of 512 KB. A single hardcoded 2 MB threshold is therefore wrong for the former, and a hardcoded 512 KB threshold would be wrong for the latter. Replace the hardcoded ATH12K_QMI_MAX_CHUNK_SIZE with a per-device qmi_max_chunk_size parameter: SZ_512K for WCN7850 and QCC2072, SZ_2M for QCN9274, IPQ5332 and IPQ5424. No functional change for the latter (the value stays 2 MB); the former now use the correct 512 KB boundary. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3 Tested-on: QCC2072 hw1.0 PCI WLAN.COL.1.0.c2-00074-QCACOLSWPL_V1_TO_SILICONZ-1 Signed-off-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Link: https://patch.msgid.link/20260730-ath12k-align-qmi-memory-v1-1-0fef98dda614@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: avoid double DMA unmap of held monitor RX buffersKang Yang
ath12k_dp_cc_cleanup() assumes that every rx_desc_info entry with a non-NULL skb still has an active DMA mapping and therefore always calls dma_unmap_single() before freeing the skb. This assumption is not true for the monitor RX path. ath12k_wifi7_dp_rx_mon_mpdu_pop() may DMA-unmap a buffer and mark rxcb->unmapped before returning early to hold the MSDU for later reprocessing. In that state desc_info->skb remains populated, so module removal can trigger a second dma_unmap_single() from ath12k_dp_cc_cleanup(). IOMMU reports the issue as: dma_unmap_phys() dma_unmap_page_attrs() ath12k_dp_cc_cleanup() ath12k_dp_cmn_device_deinit() ath12k_core_stop() Skip dma_unmap_single() when rxcb->unmapped is already set and free the skb directly. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3 Fixes: 72bfbf19b7da ("wifi: ath12k: add support to reap and process mon dest ring") Signed-off-by: Kang Yang <kang.yang@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Vasanthakumar Thiagarajan <vasanthakumar.thiagarajan@oss.qualcomm.com> Link: https://patch.msgid.link/20260916060325.854-7-kang.yang@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: fix skb leak on monitor PPDU ID wraparoundKang Yang
ath12k_dp_mon_comp_ppduid() updates *ppdu_id and returns msdu_ppdu_id to indicate that a PPDU transition was detected. When PPDU IDs wrap around, msdu_ppdu_id can be 0. In that case the function updates *ppdu_id but returns 0, causing ath12k_wifi7_dp_rx_mon_mpdu_pop() to interpret the result as "no PPDU update" and continue processing the MPDU. The MSDUs are then linked into head_msdu while their RX descriptors have already been detached. Later, ath12k_wifi7_dp_rx_mon_dest_process() detects the PPDU mismatch and exits with the partially built MSDU chain, leaking the SKBs. kmemleak reports the leak through: kmemleak_alloc() __netdev_alloc_skb() ath12k_dp_rx_bufs_replenish() ath12k_wifi7_dp_rx_mon_dest_process() Fix this by returning a boolean value from ath12k_dp_mon_comp_ppduid() so the update notification is independent of the actual PPDU ID value. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3 Fixes: 72bfbf19b7da ("wifi: ath12k: add support to reap and process mon dest ring") Signed-off-by: Kang Yang <kang.yang@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Vasanthakumar Thiagarajan <vasanthakumar.thiagarajan@oss.qualcomm.com> Link: https://patch.msgid.link/20260916060325.854-6-kang.yang@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: place dp_mon_mpdu on stack in mon dst reap loopKang Yang
ath12k_wifi7_dp_rx_mon_dest_process() allocates a dp_mon_mpdu with kzalloc(GFP_ATOMIC) for each delivered MPDU. On allocation failure it breaks out of the reap loop without calling ath12k_hal_srng_dst_get_next_entry(), leaving the destination ring tail pointer parked on the current entry -- the same entry will be peek()ed on every subsequent NAPI schedule, stalling monitor RX until the mon_dest_ring_stuck_cnt recovery path resyncs the PPDU ID. The head_msdu chain accumulated for this iteration is also orphaned since the break bypasses both the delivery and the cleanup paths. kmemleak reports these skbs in field testing: kmemleak_alloc() __netdev_alloc_skb() ath12k_dp_rx_bufs_replenish() ath12k_wifi7_dp_rx_mon_dest_process() dp_mon_mpdu is used only within a single reap loop iteration and is passed synchronously to ath12k_wifi7_dp_mon_rx_deliver(); the callee does not retain the pointer. Place it on the stack instead of using kzalloc(GFP_ATOMIC). This eliminates the allocation failure path (and the ring stall it caused) and saves a kzalloc/kfree pair per delivered MPDU. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3 Fixes: 72bfbf19b7da ("wifi: ath12k: add support to reap and process mon dest ring") Signed-off-by: Kang Yang <kang.yang@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Vasanthakumar Thiagarajan <vasanthakumar.thiagarajan@oss.qualcomm.com> Link: https://patch.msgid.link/20260916060325.854-5-kang.yang@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: fix stale tail_msdu pointer returned from mpdu_popKang Yang
ath12k_wifi7_dp_rx_mon_mpdu_pop() assigns *tail_msdu from the loop cursor msdu at function exit. That cursor reflects the state of the last msdu_list entry processed, not the end of the accumulated MSDU chain: on next_msdu paths (invalid skb, drop_mpdu, first-MSDU rx_desc invalid) it is set to NULL, and on the set_pktlen failure path it becomes a dangling pointer to a freed skb. When these occur on the final iteration, callers see head_msdu populated with a valid chain while tail_msdu is NULL or points to freed memory. The chain end is already tracked by the local variable last, which is updated only after each MSDU has been validated and linked. Use it as the source for tail_msdu so head_msdu and tail_msdu are either both NULL or both point into the same live chain. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3 Fixes: 72bfbf19b7da ("wifi: ath12k: add support to reap and process mon dest ring") Signed-off-by: Kang Yang <kang.yang@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Vasanthakumar Thiagarajan <vasanthakumar.thiagarajan@oss.qualcomm.com> Link: https://patch.msgid.link/20260916060325.854-4-kang.yang@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: free pending MSDUs on duplicate mon link descriptorKang Yang
ath12k_wifi7_dp_rx_mon_mpdu_pop() aborts processing when a duplicate monitor link descriptor is detected. Previous iterations may already have linked MSDUs onto *head_msdu and detached the corresponding RX buffers from their descriptors. Returning without completing or freeing the chain leaves those skbs orphaned, resulting in a memory leak. kmemleak reports these skbs in field testing: kmemleak_alloc() __netdev_alloc_skb() ath12k_dp_rx_bufs_replenish() ath12k_wifi7_dp_rx_mon_dest_process() Free the accumulated MSDU chain before returning and clear *head_msdu so callers observe a consistent state. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3 Fixes: 72bfbf19b7da ("wifi: ath12k: add support to reap and process mon dest ring") Signed-off-by: Kang Yang <kang.yang@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Vasanthakumar Thiagarajan <vasanthakumar.thiagarajan@oss.qualcomm.com> Link: https://patch.msgid.link/20260916060325.854-3-kang.yang@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: fix skb leak on paddr mismatch in wifi7 mon RX popKang Yang
When rxcb->paddr does not match the MSDU-list paddr reported by the link descriptor, ath12k_wifi7_dp_rx_mon_mpdu_pop() sets drop_mpdu = true and continues to the next MSDU. At that point the skb is still attached to the descriptor via desc_info->skb; the local msdu variable only holds a copy of that pointer. The continue skips the rest of the loop body, which would normally DMA-unmap the buffer, free the skb, clear desc_info->skb, and append the descriptor to used_list in the next_msdu block. The descriptor therefore stays in_use with the skb attached forever. The skb is never DMA-unmapped, delivered, freed or replaced, and HW does not write into it either because the descriptor is no longer posted to any SRNG. The descriptor is also never returned to used_list, so ath12k_dp_rx_bufs_replenish() cannot allocate a fresh buffer for it and the RX refill ring gradually drains. The skb is still reachable via dp->rxbaddr[][].skb and is reclaimed at teardown by ath12k_dp_cc_cleanup(), so this is not a kmemleak-style unreachable leak. Nevertheless, both the descriptor slot and the skb memory are wasted for the module lifetime, and under sustained mismatches monitor RX stalls. Remove the continue so drop_mpdu remains true, execution reaches the DMA unmap and dev_kfree_skb_any() below, and the descriptor is returned to used_list via the next_msdu block for replenish. Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3 Fixes: 72bfbf19b7da ("wifi: ath12k: add support to reap and process mon dest ring") Signed-off-by: Kang Yang <kang.yang@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Vasanthakumar Thiagarajan <vasanthakumar.thiagarajan@oss.qualcomm.com> Link: https://patch.msgid.link/20260916060325.854-2-kang.yang@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: convert DP_RX_RELEASE_RING_SIZE to inline helperAaradhana Sahu
Replace DP_RX_RELEASE_RING_SIZE macro with ath12k_dp_rx_release_ring_size() static inline helper. Pass the DP profile parameters explicitly to improve type safety and make the interface explicit. No functional change intended. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6-01243-QCAHKSWPL_SILICONZ-1 Signed-off-by: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Link: https://patch.msgid.link/20260820054804.3222296-8-aaradhana.sahu@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: convert ATH12K_RX_DESC_COUNT to inline helperAaradhana Sahu
Replace ATH12K_RX_DESC_COUNT with ath12k_dp_rx_desc_count() static inline helper, also replace ATH12K_NUM_RX_SPT_PAGES which is calculated from ATH12K_RX_DESC_COUNT into static inline helper functions and pass the DP profile parameters explicitly to improve type safety and make the interface explicit. Also remove the unused ATH12K_NUM_TX_SPT_PAGE_START macro. No functional change intended. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6-01243-QCAHKSWPL_SILICONZ-1 Signed-off-by: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Link: https://patch.msgid.link/20260820054804.3222296-7-aaradhana.sahu@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: convert ATH12K_NUM_POOL_TX_DESC to inline helperAaradhana Sahu
Replace ATH12K_NUM_POOL_TX_DESC with the ath12k_dp_num_pool_tx_desc() static inline helper. Also replace ATH12K_TX_SPT_PAGES_PER_POOL, ATH12K_NUM_TX_SPT_PAGES, and ATH12K_RX_SPT_PAGE_OFFSET, which are derived from ATH12K_NUM_POOL_TX_DESC, with static inline helper functions. Pass the DP profile parameters explicitly to improve type safety and make the interface more explicit. No functional change intended. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6-01243-QCAHKSWPL_SILICONZ-1 Signed-off-by: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Link: https://patch.msgid.link/20260820054804.3222296-6-aaradhana.sahu@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: convert DP_RXDMA_MONITOR_DST_RING_SIZE to inline helperAaradhana Sahu
Replace DP_RXDMA_MONITOR_DST_RING_SIZE macro with ath12k_dp_rxdma_monitor_dst_ring_size() static inline helper. Pass the DP profile parameters explicitly to improve type safety and make the interface explicit. No functional change intended. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6-01243-QCAHKSWPL_SILICONZ-1 Signed-off-by: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Link: https://patch.msgid.link/20260820054804.3222296-5-aaradhana.sahu@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: convert DP_RXDMA_MONITOR_BUF_RING_SIZE to inline helperAaradhana Sahu
Replace DP_RXDMA_MONITOR_BUF_RING_SIZE macro with ath12k_dp_rxdma_monitor_buf_ring_size() static inline helper. Pass the DP profile parameters explicitly to improve type safety and make the interface explicit. No functional change intended. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6-01243-QCAHKSWPL_SILICONZ-1 Signed-off-by: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Link: https://patch.msgid.link/20260820054804.3222296-4-aaradhana.sahu@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: convert DP_TX_COMP_RING_SIZE to inline helperAaradhana Sahu
Replace DP_TX_COMP_RING_SIZE macro with ath12k_dp_tx_comp_ring_size() static inline helper. Pass the DP profile parameters explicitly to improve type safety and make the interface explicit. Update code using ATH12K_TX_COMPL_NEXT to pass ring size directly rather than deriving it from the ath12k_base structure. Also remove the unused DP_TX_IDR_SIZE macro. No functional change intended. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6-01243-QCAHKSWPL_SILICONZ-1 Signed-off-by: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Link: https://patch.msgid.link/20260820054804.3222296-3-aaradhana.sahu@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-25wifi: ath12k: move dp_profile_params to dp.hAaradhana Sahu
Move struct ath12k_dp_profile_params from core.h to dp.h as it is specifically used for Data Path operations. This improves code organization by keeping DP-related structures in the DP header. No functional change intended. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6-01243-QCAHKSWPL_SILICONZ-1 Signed-off-by: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com> Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com> Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com> Link: https://patch.msgid.link/20260820054804.3222296-2-aaradhana.sahu@oss.qualcomm.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
2026-09-21Merge tag 'wireless-next-2026-09-21' of ↵Jakub Kicinski
https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless-next Johannes Berg says: ==================== More changes, including drivers: - brcmfmac: FT/OKC roaming offload - ath12k: IPQ5332 platform infrastructure - cfg80211/mac80211: non-STA TX/RX infrastructure for MLO to fix address translation bugs - the rest is mostly minor cleanups etc. * tag 'wireless-next-2026-09-21' of https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless-next: (101 commits) dt-bindings: net: wireless: Convert WL1251 to DT schema libertas: mesh: remove unused and undocumented sysfs attribute groups wifi: mac80211: fix multi-link UHR association wifi: nl80211: rename no-ACK bitmap to TID bitmap wifi: radiotap: correct EHT TB U-SIG 1 B20:25 wifi: ieee80211: fix FTM bufferable check wifi: mac80211: allow advertising 20 MHz-only non-AP STA wifi: mac80211: WARN on 40 MHz HT/HE mismatch wifi: mac80211: tests: fix memory leak wifi: mac80211: use assign_bit() where applicable wifi: mac80211: pass error station if non-STA transmit was requested wifi: mac80211: pass station to ieee80211_tx_skb_tid wifi: mac80211: report to cfg80211 when no STA is known for a frame wifi: cfg80211: add attribute for TX/RX denoting there is no station wifi: mac80211: rework RX packet handling wifi: mac80211: refactor RX link_id and station handling wifi: mac80211: change public RX API to use link stations wifi: iwlwifi: use link_sta internally to the driver MAINTAINERS: Replace wireless.wiki.kernel.org links wifi: brcmfmac: log the firmware status when a connect fails ... ==================== Link: https://patch.msgid.link/20260921121635.195723-3-johannes@sipsolutions.net Signed-off-by: Jakub Kicinski <kuba@kernel.org>
2026-09-21wifi: ath9k_htc: bound TX aggregation to MAX_TX_BUF_SIZEGeorgios Karantzas
__hif_usb_tx() dequeues up to MAX_TX_AGGR_NUM (20) frames into a single tx_buf of MAX_TX_BUF_SIZE (32768) bytes, limiting the batch by record count but never by cumulative byte length. With large frames (MTU 2304), 20 aggregated frames of 2292 bytes each exceed the allocation (20 * 2296 = 45920 bytes), so the memcpy() in the loop writes up to 13152 bytes past tx_buf->buf before usb_submit_urb(). Peek the queue head and stop before copying any record that would cross MAX_TX_BUF_SIZE, then dispatch the current batch. Leftover skbs remain queued and are drained on the next URB completion. The byte bound changes the loop's exit semantics: it can now exit before i == tx_skb_cnt - 1. Stock only finalized tx_buf->len on that last index (len += offset), so an early break would submit a URB holding only the last record's length while every dequeued skb is freed on completion, silently dropping frames. Make tx_buf->len a running total and advance tx_buf->offset per record instead; the stride round_up(nskb->len + 4, 4) is identical to the stock stride when the loop runs to completion. Tested on hardware with an MTU 2304 flood: the loop stops at record 15 (len = 32144, offset = 32144, within 32768), no oversized URB is submitted, and MTU 1500 pings pass 20/20. Fixes: fb9987d0f748 ("ath9k_htc: Support for AR9271 chipset.") Signed-off-by: Georgios Karantzas <gck.kara@gmail.com> Acked-by: Toke Høiland-Jørgensen <toke@toke.dk> Link: https://patch.msgid.link/20260911001143.4507-1-gck.kara@gmail.com Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>