[PATCH wireless 0/2] wifi: mt76: fix the dev->mutex / iflist_mtx inversion in .config
Devin Wittmayer <[email protected]>
| Newsgroups | org.kernel.vger.linux-wireless,org.infradead.lists.linux-mediatek |
|---|---|
| Message-ID | <[email protected]> |
mt7921_config() and mt7925_config() hold dev->mutex across ieee80211_iterate_active_interfaces(), which takes local->iflist_mtx. mac80211 goes the other way round: it calls drv_unassign_vif_chanctx() with iflist_mtx held, and mt792x_unassign_vif_chanctx() takes dev->mutex. Deleting a monitor interface that has a channel assigned hits it. On an MT7922 with lockdep: ip link set wlp4s0 down iw phy phy0 interface add mon0 type monitor ip link set mon0 up iw dev mon0 set freq 5180 iw dev mon0 del The splat comes on the last line and nowhere earlier. I reported it in July and had no reply: https://lore.kernel.org/linux-wireless/[email protected]/ Both ops are reached only from drv_config(), which asserts the wiphy mutex, so ieee80211_iterate_active_interfaces_mtx() applies and never takes iflist_mtx. Reproduced and fixed on an MT7922 and an MT7925: splat before, none after, monitor mode configured and capturing on either arm. Its kerneldoc says the iterator cannot sleep and these two do, since they send MCU commands. That line is identical to the _atomic variant's directly above it, and no version of the helper has taken RCU, a spinlock or disabled preemption. I can send a doc fix separately if you want one. The other sites from that report are follow-ups. Devin Wittmayer (2): wifi: mt76: mt7921: fix lock inversion between dev->mutex and iflist_mtx wifi: mt76: mt7925: fix lock inversion between dev->mutex and iflist_mtx drivers/net/wireless/mediatek/mt76/mt7921/main.c | 6 +++--- drivers/net/wireless/mediatek/mt76/mt7925/main.c | 6 +++--- 2 files changed, 6 insertions(+), 6 deletions(-) -- 2.55.0