[PATCH v2 0/3] wifi: ath12k: fixes to improve MLO station stability
Jose Ignacio Tornos Martinez <[email protected]> Tue, 4 Aug 2026 19:49:58 +0200
| Newsgroups | org.kernel.vger.linux-wireless,org.infradead.lists.ath11k,org.infradead.lists.ath12k,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
This series improves firmware crash recovery and connection stability
for MLO (Wi-Fi 7) stations on ath12k. Both work correctly for non-MLO
(Wi-Fi 6) stations, where the driver handles the full teardown and
reconnect cycle without issues and maintains stable connections. This
series brings MLO to the same level.
Without these fixes, a firmware crash during an active MLO connection
results in kernel warnings, NULL pointer dereferences, 20+ second
recovery delays, and periodic disconnections both after recovery and
during normal operation under heavy traffic.
Patches 1-2 fix firmware crash recovery:
Patch 1 moves the RECOVERY flag clear to reconfig_complete and adds
CRASH_FLUSH guards to prevent operations on dead firmware.
Patch 2 prevents scans during recovery to avoid NULL dereferences.
Patch 3 fixes MLO beacon miss handling:
Patch 3 skips connection_loss_work for MLO entirely, since its
cancellation mechanism is unreliable and the mac80211 probe
triggered by ieee80211_beacon_loss() is sufficient to detect
real AP unreachability, as done by other MLO-capable drivers
such as mt76 and rtw89.
Tested on WCN7850 with MLO (Wi-Fi 7).
Firmware crashes were observed to occur spontaneously during normal
MLO operation with intense traffic testing, though rarely.
The debugfs simulate_fw_crash interface was used for systematic testing
and reproduction during active MLO connections with traffic.
Note: I will have limited availability from mid-August to
mid-September. I will address any review feedback before then
or promptly after returning.
v2:
- Rebased on ath/main (requested by Jeff Johnson).
- Patch 1: rebase and address comments from Baochen Qiang:
- Remove CRASH_FLUSH guards from HAL srng source ring helpers
(ath12k_hal_srng_src_num_free, ath12k_hal_srng_src_get_next_entry,
ath12k_hal_srng_access_end). They were a layering violation — the
HAL should not know about device crash semantics. They were added
as a precautionary measure to abort as soon as possible, but
ath12k_wifi7_dp_tx() already has a CRASH_FLUSH check before any
HAL call.
- Fix radio[0] usage in change_vif_links, sta_state, and
peer_mlo_link_peers_delete to use per-radio ab.
- Patch 2: fix radio[0] usage
- Drop v1 patch 3 (fix MLO dp_peer ID desync with firmware):
already fixed by Baochen Qiang's ML peer ID series in ath.git
- Drop v1 patch 4 (fix MLO beacon handling using per-link
addressing): patch 3 (v1 patch 5) skips connection_loss_work for
MLO entirely, making the per-link beacon matching and cancellation
in v1 patch 4 unreachable (Baochen Qiang comment).
- No modification for v1 patch 5, now v2 patch 3.
v1: https://lore.kernel.org/all/[email protected]/
Jose Ignacio Tornos Martinez (3):
wifi: ath12k: fix MLO station firmware crash recovery
wifi: ath12k: prevent scan during firmware recovery
wifi: ath12k: skip connection_loss_work for MLO beacon miss