Commit 57b9df6f authored by Ryder Lee's avatar Ryder Lee Committed by Felix Fietkau
Browse files

mt76: mt7915: fix possible deadlock in mt7915_stop



make mac_work per phy instead of per device and fix a possible deadlock
in mt7915_stop since mt7915_mac_work runs holding mt76 mutex

Signed-off-by: default avatarRyder Lee <ryder.lee@mediatek.com>
Signed-off-by: default avatarFelix Fietkau <nbd@nbd.name>
parent 3e68af62
Loading
Loading
Loading
Loading
+2 −1
Original line number Diff line number Diff line
@@ -592,6 +592,7 @@ int mt7915_register_ext_phy(struct mt7915_dev *dev)
	if (phy)
		return 0;

	INIT_DELAYED_WORK(&phy->mac_work, mt7915_mac_work);
	mt7915_cap_dbdc_enable(dev);
	mphy = mt76_alloc_phy(&dev->mt76, sizeof(*phy), &mt7915_ops);
	if (!mphy)
@@ -642,7 +643,7 @@ int mt7915_register_device(struct mt7915_dev *dev)
	dev->phy.dev = dev;
	dev->phy.mt76 = &dev->mt76.phy;
	dev->mt76.phy.priv = &dev->phy;
	INIT_DELAYED_WORK(&dev->mt76.mac_work, mt7915_mac_work);
	INIT_DELAYED_WORK(&dev->phy.mac_work, mt7915_mac_work);
	INIT_LIST_HEAD(&dev->sta_poll_list);
	spin_lock_init(&dev->sta_poll_lock);

+29 −20
Original line number Diff line number Diff line
@@ -1156,26 +1156,32 @@ mt7915_dma_reset(struct mt7915_dev *dev)
/* system error recovery */
void mt7915_mac_reset_work(struct work_struct *work)
{
	struct mt7915_phy *phy2;
	struct mt76_phy *ext_phy;
	struct mt7915_dev *dev;

	dev = container_of(work, struct mt7915_dev, reset_work);
	ext_phy = dev->mt76.phy2;
	phy2 = ext_phy ? ext_phy->priv : NULL;

	if (!(READ_ONCE(dev->reset_state) & MT_MCU_CMD_STOP_DMA))
		return;

	ieee80211_stop_queues(mt76_hw(dev));
	if (dev->mt76.phy2)
		ieee80211_stop_queues(dev->mt76.phy2->hw);
	if (ext_phy)
		ieee80211_stop_queues(ext_phy->hw);

	set_bit(MT76_RESET, &dev->mphy.state);
	set_bit(MT76_MCU_RESET, &dev->mphy.state);
	wake_up(&dev->mt76.mcu.wait);
	cancel_delayed_work_sync(&dev->mt76.mac_work);
	cancel_delayed_work_sync(&dev->phy.mac_work);
	if (phy2)
		cancel_delayed_work_sync(&phy2->mac_work);

	/* lock/unlock all queues to ensure that no tx is pending */
	mt76_txq_schedule_all(&dev->mphy);
	if (dev->mt76.phy2)
		mt76_txq_schedule_all(dev->mt76.phy2);
	if (ext_phy)
		mt76_txq_schedule_all(ext_phy);

	tasklet_disable(&dev->mt76.tx_tasklet);
	napi_disable(&dev->mt76.napi[0]);
@@ -1211,8 +1217,8 @@ void mt7915_mac_reset_work(struct work_struct *work)
	napi_schedule(&dev->mt76.napi[2]);

	ieee80211_wake_queues(mt76_hw(dev));
	if (dev->mt76.phy2)
		ieee80211_wake_queues(dev->mt76.phy2->hw);
	if (ext_phy)
		ieee80211_wake_queues(ext_phy->hw);

	mt76_wr(dev, MT_MCU_INT_EVENT, MT_MCU_INT_EVENT_RESET_DONE);
	mt7915_wait_reset_state(dev, MT_MCU_CMD_NORMAL_STATE);
@@ -1221,7 +1227,10 @@ void mt7915_mac_reset_work(struct work_struct *work)

	mt7915_update_beacons(dev);

	ieee80211_queue_delayed_work(mt76_hw(dev), &dev->mt76.mac_work,
	ieee80211_queue_delayed_work(mt76_hw(dev), &dev->phy.mac_work,
				     MT7915_WATCHDOG_TIME);
	if (phy2)
		ieee80211_queue_delayed_work(ext_phy->hw, &phy2->mac_work,
					     MT7915_WATCHDOG_TIME);
}

@@ -1307,25 +1316,25 @@ void mt7915_mac_sta_stats_work(struct work_struct *work)

void mt7915_mac_work(struct work_struct *work)
{
	struct mt7915_dev *dev;
	struct mt7915_phy *phy;
	struct mt76_dev *mdev;

	dev = (struct mt7915_dev *)container_of(work, struct mt76_dev,
	phy = (struct mt7915_phy *)container_of(work, struct mt7915_phy,
						mac_work.work);
	mdev = &phy->dev->mt76;

	mutex_lock(&dev->mt76.mutex);
	mt76_update_survey(&dev->mt76);
	if (++dev->mac_work_count == 5) {
		struct mt7915_phy *ext_phy = mt7915_ext_phy(dev);
	mutex_lock(&mdev->mutex);

		mt7915_mac_update_mib_stats(&dev->phy);
		if (ext_phy)
			mt7915_mac_update_mib_stats(ext_phy);
	mt76_update_survey(mdev);
	if (++phy->mac_work_count == 5) {
		phy->mac_work_count = 0;

		dev->mac_work_count = 0;
		mt7915_mac_update_mib_stats(phy);
	}
	mutex_unlock(&dev->mt76.mutex);

	ieee80211_queue_delayed_work(mt76_hw(dev), &dev->mt76.mac_work,
	mutex_unlock(&mdev->mutex);

	ieee80211_queue_delayed_work(phy->mt76->hw, &phy->mac_work,
				     MT7915_WATCHDOG_TIME);
}

+8 −10
Original line number Diff line number Diff line
@@ -47,14 +47,12 @@ static int mt7915_start(struct ieee80211_hw *hw)

	set_bit(MT76_STATE_RUNNING, &phy->mt76->state);

	if (running)
		goto out;
	ieee80211_queue_delayed_work(hw, &phy->mac_work,
				     MT7915_WATCHDOG_TIME);

	if (!running)
		mt7915_mac_reset_counters(phy);

	ieee80211_queue_delayed_work(mt76_hw(dev), &dev->mt76.mac_work,
				     MT7915_WATCHDOG_TIME);
out:
	mutex_unlock(&dev->mt76.mutex);

	return 0;
@@ -65,6 +63,8 @@ static void mt7915_stop(struct ieee80211_hw *hw)
	struct mt7915_dev *dev = mt7915_hw_dev(hw);
	struct mt7915_phy *phy = mt7915_hw_phy(hw);

	cancel_delayed_work_sync(&phy->mac_work);

	mutex_lock(&dev->mt76.mutex);

	clear_bit(MT76_STATE_RUNNING, &phy->mt76->state);
@@ -75,8 +75,6 @@ static void mt7915_stop(struct ieee80211_hw *hw)
	}

	if (!mt7915_dev_running(dev)) {
		cancel_delayed_work_sync(&dev->mt76.mac_work);

		mt7915_mcu_set_pm(dev, 0, 1);
		mt7915_mcu_set_mac(dev, 0, false, false);
	}
@@ -230,7 +228,7 @@ static int mt7915_set_channel(struct mt7915_phy *phy)
	struct mt7915_dev *dev = phy->dev;
	int ret;

	cancel_delayed_work_sync(&dev->mt76.mac_work);
	cancel_delayed_work_sync(&phy->mac_work);

	mutex_lock(&dev->mt76.mutex);
	set_bit(MT76_RESET, &phy->mt76->state);
@@ -254,7 +252,7 @@ static int mt7915_set_channel(struct mt7915_phy *phy)
	mutex_unlock(&dev->mt76.mutex);

	mt76_txq_schedule_all(phy->mt76);
	ieee80211_queue_delayed_work(mt76_hw(dev), &dev->mt76.mac_work,
	ieee80211_queue_delayed_work(phy->mt76->hw, &phy->mac_work,
				     MT7915_WATCHDOG_TIME);

	return ret;
+3 −1
Original line number Diff line number Diff line
@@ -141,6 +141,9 @@ struct mt7915_phy {
	u32 ampdu_ref;

	struct mib_stats mib;

	struct delayed_work mac_work;
	u8 mac_work_count;
};

struct mt7915_dev {
@@ -168,7 +171,6 @@ struct mt7915_dev {

	s8 **rate_power; /* TODO: use mt76_rate_power */

	u8 mac_work_count;
	bool fw_debug;
};