]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
wifi: ath11k: fix source ring-buffer corruption
authorJohan Hovold <johan+linaro@kernel.org>
Wed, 4 Jun 2025 14:34:56 +0000 (16:34 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 28 Aug 2025 14:22:49 +0000 (16:22 +0200)
commit 6efa0df54022c6c9fd4d294b87622c7fcdc418c8 upstream.

Add the missing memory barrier to make sure that LMAC source ring
descriptors are written before updating the head pointer to avoid
passing stale data to the firmware on weakly ordered architectures like
aarch64.

Note that non-LMAC rings use MMIO write accessors which have the
required write memory barrier.

Tested-on: WCN6855 hw2.1 WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41

Fixes: d5c65159f289 ("ath11k: driver for Qualcomm IEEE 802.11ax devices")
Cc: stable@vger.kernel.org # 5.6
Signed-off-by: Johan Hovold <johan+linaro@kernel.org>
Reviewed-by: Baochen Qiang <quic_bqiang@quicinc.com>
Link: https://patch.msgid.link/20250604143457.26032-5-johan+linaro@kernel.org
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/net/wireless/ath/ath11k/hal.c

index 33dfc9970bea28c06bea1c1ae75533f8d2cba4da..75e83548466930c56a4411a092f52e707fa3c306 100644 (file)
@@ -841,7 +841,11 @@ void ath11k_hal_srng_access_end(struct ath11k_base *ab, struct hal_srng *srng)
                if (srng->ring_dir == HAL_SRNG_DIR_SRC) {
                        srng->u.src_ring.last_tp =
                                *(volatile u32 *)srng->u.src_ring.tp_addr;
-                       *srng->u.src_ring.hp_addr = srng->u.src_ring.hp;
+                       /* Make sure descriptor is written before updating the
+                        * head pointer.
+                        */
+                       dma_wmb();
+                       WRITE_ONCE(*srng->u.src_ring.hp_addr, srng->u.src_ring.hp);
                } else {
                        srng->u.dst_ring.last_hp = *srng->u.dst_ring.hp_addr;
                        *srng->u.dst_ring.tp_addr = srng->u.dst_ring.tp;
@@ -850,6 +854,10 @@ void ath11k_hal_srng_access_end(struct ath11k_base *ab, struct hal_srng *srng)
                if (srng->ring_dir == HAL_SRNG_DIR_SRC) {
                        srng->u.src_ring.last_tp =
                                *(volatile u32 *)srng->u.src_ring.tp_addr;
+                       /* Assume implementation use an MMIO write accessor
+                        * which has the required wmb() so that the descriptor
+                        * is written before the updating the head pointer.
+                        */
                        ath11k_hif_write32(ab,
                                           (unsigned long)srng->u.src_ring.hp_addr -
                                           (unsigned long)ab->mem,