* [PATCH net v4 1/3] net: ethernet: mtk_wed: skip ring reset in wdma_tx_ring_setup for WED v3
@ 2026-09-17 14:43 Zhi-Jun You
2026-09-17 14:43 ` [PATCH net v4 2/3] net: ethernet: mtk_wed: fix reset condition for rx wdma Zhi-Jun You
2026-09-17 14:43 ` [PATCH net v4 3/3] net: ethernet: mtk_wed: setup WDMA_RING_TX(0) for non-DBDC MT7986 Zhi-Jun You
0 siblings, 2 replies; 5+ messages in thread
From: Zhi-Jun You @ 2026-09-17 14:43 UTC (permalink / raw)
To: Felix Fietkau, Lorenzo Bianconi
Cc: Andrew Lunn, David S . Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Matthias Brugger, AngeloGioacchino Del Regno,
Sujuan Chen, Rex.Lu, netdev, linux-kernel, linux-arm-kernel,
linux-mediatek, Zhi-Jun You
Currently WED v3 tx wdma ring, ring reset happens in a separate code
block unconditionally.
Moreover, v3 has double the size of wdma_desc and has different init
values. mtk_wed_ring_reset doens't deal with that and would corrupt the
wdma_desc.
Fix this by skipping mtk_wed_ring_reset in mtk_wdma_tx_ring_setup for
WED v3.
Fixes: e2f64db13aa1 ("net: ethernet: mtk_wed: introduce WED support for MT7988")
Signed-off-by: Zhi-Jun You <hujy652@gmail.com>
---
Changes in v4:
- no change
- Link to v3: https://lore.kernel.org/all/20260724172040.1653-1-hujy652@gmail.com/
Changes in v3:
- new patch addressing WED v3 ring reset issue raised by Sashiko
- Link to the review: https://lore.kernel.org/netdev/20260630144831.1109-1-hujy652@gmail.com/
---
drivers/net/ethernet/mediatek/mtk_wed.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/mediatek/mtk_wed.c b/drivers/net/ethernet/mediatek/mtk_wed.c
index 53d3b7e00e1c..d55042ccaff1 100644
--- a/drivers/net/ethernet/mediatek/mtk_wed.c
+++ b/drivers/net/ethernet/mediatek/mtk_wed.c
@@ -1938,7 +1938,7 @@ mtk_wed_wdma_tx_ring_setup(struct mtk_wed_device *dev, int idx, int size,
wdma_w32(dev, MTK_WDMA_RING_TX(idx) + MTK_WED_RING_OFS_CPU_IDX, 0);
wdma_w32(dev, MTK_WDMA_RING_TX(idx) + MTK_WED_RING_OFS_DMA_IDX, 0);
- if (reset)
+ if (!mtk_wed_is_v3_or_greater(dev->hw) && reset)
mtk_wed_ring_reset(wdma, MTK_WED_WDMA_RING_SIZE, true);
if (!idx) {
--
2.47.3
^ permalink raw reply [flat|nested] 5+ messages in thread* [PATCH net v4 2/3] net: ethernet: mtk_wed: fix reset condition for rx wdma 2026-09-17 14:43 [PATCH net v4 1/3] net: ethernet: mtk_wed: skip ring reset in wdma_tx_ring_setup for WED v3 Zhi-Jun You @ 2026-09-17 14:43 ` Zhi-Jun You 2026-09-17 14:43 ` [PATCH net v4 3/3] net: ethernet: mtk_wed: setup WDMA_RING_TX(0) for non-DBDC MT7986 Zhi-Jun You 1 sibling, 0 replies; 5+ messages in thread From: Zhi-Jun You @ 2026-09-17 14:43 UTC (permalink / raw) To: Felix Fietkau, Lorenzo Bianconi Cc: Andrew Lunn, David S . Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni, Matthias Brugger, AngeloGioacchino Del Regno, Sujuan Chen, Rex.Lu, netdev, linux-kernel, linux-arm-kernel, linux-mediatek, Zhi-Jun You In mtk_wdma_rx_reset, only the wdma rings that weren't allocated are reset which is wrong. Fix this by inverting the reset condition so allocated rings will be reset. Fixes: 4c5de09eb0d0 ("net: ethernet: mtk_wed: add configure wed wo support") Signed-off-by: Zhi-Jun You <hujy652@gmail.com> --- Changes in v4: - Patch added for issue raised by Sashiko - Link to Sashiko review: https://sashiko.dev/#/patchset/20260724172040.1653-1-hujy652%40gmail.com --- drivers/net/ethernet/mediatek/mtk_wed.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/net/ethernet/mediatek/mtk_wed.c b/drivers/net/ethernet/mediatek/mtk_wed.c index d55042ccaff1..3f0be70c3f14 100644 --- a/drivers/net/ethernet/mediatek/mtk_wed.c +++ b/drivers/net/ethernet/mediatek/mtk_wed.c @@ -257,7 +257,7 @@ mtk_wdma_rx_reset(struct mtk_wed_device *dev) wdma_w32(dev, MTK_WDMA_RESET_IDX, 0); for (i = 0; i < ARRAY_SIZE(dev->rx_wdma); i++) { - if (dev->rx_wdma[i].desc) + if (!dev->rx_wdma[i].desc) continue; wdma_w32(dev, -- 2.47.3 ^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH net v4 3/3] net: ethernet: mtk_wed: setup WDMA_RING_TX(0) for non-DBDC MT7986 2026-09-17 14:43 [PATCH net v4 1/3] net: ethernet: mtk_wed: skip ring reset in wdma_tx_ring_setup for WED v3 Zhi-Jun You 2026-09-17 14:43 ` [PATCH net v4 2/3] net: ethernet: mtk_wed: fix reset condition for rx wdma Zhi-Jun You @ 2026-09-17 14:43 ` Zhi-Jun You 2026-09-21 16:10 ` netdev-bot+sashiko 1 sibling, 1 reply; 5+ messages in thread From: Zhi-Jun You @ 2026-09-17 14:43 UTC (permalink / raw) To: Felix Fietkau, Lorenzo Bianconi Cc: Andrew Lunn, David S . Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni, Matthias Brugger, AngeloGioacchino Del Regno, Sujuan Chen, Rex.Lu, netdev, linux-kernel, linux-arm-kernel, linux-mediatek, Zhi-Jun You WDMA_RING_TX(0) is required to set MTK_WED_WDMA_RING_TX for WED RX but on a non-DBDC MT7986 it is never setup because idx is 1. Setting MTK_WED_WDMA_RING_TX with WDMA_RING_TX(1) is not feasible because WED still tries to send through WDMA_RING_TX(0). This is verified with register dump. Fix this by calling mtk_wed_wdma_tx_ring_setup if wed is v2 and rx_ring[0] is not allocated and reset tx_wdma[0] if it's already allocated. Fixes: 4c5de09eb0d0 ("net: ethernet: mtk_wed: add configure wed wo support") Signed-off-by: Zhi-Jun You <hujy652@gmail.com> --- Changes in v4: - no change - Link to v3: https://lore.kernel.org/all/20260724172040.1653-2-hujy652@gmail.com/ - Still waiting for comment from maintainers for the return value concern raised by Sashiko and it would be a much bigger change because it involves mt7915 and mt7996. Changes in v3: - no change - Link to v2: https://lore.kernel.org/r/20260711112128.971-1-hujy652@gmail.com Changes in v2: - Address warm reset concern raised by AI review. - Return value concern is skipped until further comment from reviewers. - Added a comment to explain this special case. - Link to v1: https://lore.kernel.org/r/20260630144831.1109-1-hujy652@gmail.com --- drivers/net/ethernet/mediatek/mtk_wed.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/drivers/net/ethernet/mediatek/mtk_wed.c b/drivers/net/ethernet/mediatek/mtk_wed.c index 3f0be70c3f14..3800e602d3c4 100644 --- a/drivers/net/ethernet/mediatek/mtk_wed.c +++ b/drivers/net/ethernet/mediatek/mtk_wed.c @@ -2339,6 +2339,13 @@ mtk_wed_start(struct mtk_wed_device *dev, u32 irq_mask) if (!dev->rx_wdma[i].desc) mtk_wed_wdma_rx_ring_setup(dev, i, 16, false); + /* + * non-DBDC MT7986 allocates only rx_ring[1] and tx_wdma[1] during setup + * but tx_wdma[0] is also needed for WED to function. + */ + if (mtk_wed_is_v2(dev->hw) && !dev->rx_ring[0].desc) + mtk_wed_wdma_tx_ring_setup(dev, 0, MTK_WED_WDMA_RING_SIZE, !!dev->tx_wdma[0].desc); + if (dev->wlan.hw_rro) { for (i = 0; i < MTK_WED_RX_PAGE_QUEUES; i++) { u32 addr = MTK_WED_RRO_MSDU_PG_CTRL0(i) + -- 2.47.3 ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH net v4 3/3] net: ethernet: mtk_wed: setup WDMA_RING_TX(0) for non-DBDC MT7986 2026-09-17 14:43 ` [PATCH net v4 3/3] net: ethernet: mtk_wed: setup WDMA_RING_TX(0) for non-DBDC MT7986 Zhi-Jun You @ 2026-09-21 16:10 ` netdev-bot+sashiko 2026-09-22 13:46 ` Zhi-Jun You 0 siblings, 1 reply; 5+ messages in thread From: netdev-bot+sashiko @ 2026-09-21 16:10 UTC (permalink / raw) To: hujy652 Cc: nbd, lorenzo, andrew+netdev, davem, edumazet, kuba, pabeni, matthias.bgg, angelogioacchino.delregno, sujuan.chen, Rex.Lu, netdev, linux-kernel, linux-arm-kernel, linux-mediatek Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider. Critical: 0 · High: 0 · Medium: 1 (1) · Low: 0 If you believe none of the issues are legitimate, please reply to each issue of Medium severity or higher and explain why the AI is wrong. If any of them are legitimate and you plan to respin, please let patchwork know by including "pw-bot: cr" as a separate line at the end of your reply (one such reply per series is enough). - [Medium] In mtk_wed_start() (drivers/net/ethernet/mediatek/mtk_wed.c:2346-2347) the newly added… Pre-existing issues: - [Medium] This problem wasn't introduced by this patch, but the patch widens it: dev->tx_wdma[] descriptor rings are allocated with… -- net: ethernet: mtk_wed: setup WDMA_RING_TX(0) for non-DBDC MT7986 On a non-DBDC MT7986 only rx_ring[1]/tx_wdma[1] get set up, so WDMA_RING_TX(0) is never programmed even though WED needs it for RX offload. The patch adds a call to mtk_wed_wdma_tx_ring_setup() for ring 0 from mtk_wed_start() when the device is WED v2 and rx_ring[0] was not allocated, passing reset=true when tx_wdma[0] already exists. > diff --git a/drivers/net/ethernet/mediatek/mtk_wed.c b/drivers/net/ethernet/mediatek/mtk_wed.c > index 3f0be70c3f145..3800e602d3c48 100644 > --- a/drivers/net/ethernet/mediatek/mtk_wed.c > +++ b/drivers/net/ethernet/mediatek/mtk_wed.c > @@ -2339,6 +2339,13 @@ mtk_wed_start(struct mtk_wed_device *dev, u32 irq_mask) > if (!dev->rx_wdma[i].desc) > mtk_wed_wdma_rx_ring_setup(dev, i, 16, false); > > + /* > + * non-DBDC MT7986 allocates only rx_ring[1] and tx_wdma[1] during setup > + * but tx_wdma[0] is also needed for WED to function. > + */ > + if (mtk_wed_is_v2(dev->hw) && !dev->rx_ring[0].desc) > + mtk_wed_wdma_tx_ring_setup(dev, 0, MTK_WED_WDMA_RING_SIZE, !!dev->tx_wdma[0].desc); [Severity: Medium] Should the return value of mtk_wed_wdma_tx_ring_setup() be checked here? On the first start of a non-DBDC v2 device dev->tx_wdma[0].desc is NULL, so reset is false and the helper takes the allocation path: drivers/net/ethernet/mediatek/mtk_wed.c:mtk_wed_wdma_tx_ring_setup() { wdma = &dev->tx_wdma[idx]; if (!reset && mtk_wed_ring_alloc(dev, wdma, MTK_WED_WDMA_RING_SIZE, dev->hw->soc->wdma_desc_size, true)) return -ENOMEM; ... } mtk_wed_ring_alloc() does a dma_alloc_coherent() of MTK_WED_WDMA_RING_SIZE * wdma_desc_size (32 KiB on MT7986), and on failure the helper returns before writing MTK_WDMA_RING_TX(0) BASE/COUNT/CPU_IDX/ DMA_IDX and before the "if (!idx)" block that programs the WED side MTK_WED_WDMA_RING_TX window. Since the status is dropped, mtk_wed_start() keeps going through mtk_wed_hw_init(), mtk_wed_configure_irq() and mtk_wed_dma_enable(), which arms MTK_WDMA_GLO_CFG_TX_DMA_EN and, for rx-capable v2, MTK_WED_WDMA_GLO_CFG_TX_DRV_EN | MTK_WED_WDMA_GLO_CFG_TX_DDONE_CHK, and then sets dev->running = true. Can the hardware then fetch descriptors from a ring whose base register was left at 0 by the preceding mtk_wdma_tx_reset()/mtk_wed_reset(), leaving the WED offload silently non-functional with no message? The other caller of the same helper propagates the failure: drivers/net/ethernet/mediatek/mtk_wed.c:mtk_wed_rx_ring_setup() { if (mtk_wed_wdma_tx_ring_setup(dev, idx, MTK_WED_WDMA_RING_SIZE, reset)) return -ENOMEM; ... } and mtk_wed_start() itself already bails out on mtk_wed_rx_buffer_alloc() and mtk_wed_rro_cfg() failures. Since mtk_wed_ops.start is void and mt7915_dma_start() cannot observe the error, would it make sense to abort the start sequence locally here (skipping mtk_wed_dma_enable() and dev->running = true) and log the failure? [Severity: Medium] This isn't a problem introduced by this patch, but does this new call add another leak of dev->tx_wdma[0]? dev->tx_wdma[] rings are allocated by mtk_wed_ring_alloc() via mtk_wed_wdma_tx_ring_setup(), but the ring-release helpers never free that array: drivers/net/ethernet/mediatek/mtk_wed.c:mtk_wed_free_tx_rings() { for (i = 0; i < ARRAY_SIZE(dev->tx_ring); i++) mtk_wed_free_ring(dev, &dev->tx_ring[i]); for (i = 0; i < ARRAY_SIZE(dev->rx_wdma); i++) mtk_wed_free_ring(dev, &dev->rx_wdma[i]); } drivers/net/ethernet/mediatek/mtk_wed.c:mtk_wed_free_rx_rings() { mtk_wed_free_rx_buffer(dev); mtk_wed_free_ring(dev, &dev->rro.ring); } __mtk_wed_detach() calls those helpers and then does memset(dev, 0, sizeof(*dev)), so tx_wdma[].desc/desc_phys are discarded and the 32 KiB coherent allocation can no longer be released. The existing allocation site is mtk_wed_rx_ring_setup(), so the omission predates this change, but non-DBDC MT7986/MT7981 previously never allocated tx_wdma[0] at all, and now every attach/start/detach cycle would leak one more ring. Would adding dev->tx_wdma[] to mtk_wed_free_tx_rings() be the right way to restore alloc/free symmetry? -- Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260917144335.19466-1-hujy652%40gmail.com ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH net v4 3/3] net: ethernet: mtk_wed: setup WDMA_RING_TX(0) for non-DBDC MT7986 2026-09-21 16:10 ` netdev-bot+sashiko @ 2026-09-22 13:46 ` Zhi-Jun You 0 siblings, 0 replies; 5+ messages in thread From: Zhi-Jun You @ 2026-09-22 13:46 UTC (permalink / raw) To: netdev-bot+sashiko Cc: Rex.Lu, andrew+netdev, angelogioacchino.delregno, davem, edumazet, hujy652, kuba, linux-arm-kernel, linux-kernel, linux-mediatek, lorenzo, matthias.bgg, nbd, netdev, pabeni, sujuan.chen [-- Attachment #1: v4reply --] [-- Type: text/plain, Size: 5688 bytes --] On Mon, Sep 21, 2026 at 04:10:00PM +0000, netdev-bot+sashiko@kernel.org wrote: > Thank you for your contribution! Sashiko AI review found 1 potential > issue(s) to consider. > > Critical: 0 · High: 0 · Medium: 1 (1) · Low: 0 > > If you believe none of the issues are legitimate, please reply to each > issue of Medium severity or higher and explain why the AI is wrong. > If any of them are legitimate and you plan to respin, please let patchwork > know by including "pw-bot: cr" as a separate line at the end of your reply > (one such reply per series is enough). > > - [Medium] In mtk_wed_start() > (drivers/net/ethernet/mediatek/mtk_wed.c:2346-2347) the newly added… > > Pre-existing issues: > - [Medium] This problem wasn't introduced by this patch, but the patch > widens it: dev->tx_wdma[] descriptor rings are allocated with… > > -- > > net: ethernet: mtk_wed: setup WDMA_RING_TX(0) for non-DBDC MT7986 > > On a non-DBDC MT7986 only rx_ring[1]/tx_wdma[1] get set up, so > WDMA_RING_TX(0) is never programmed even though WED needs it for RX > offload. The patch adds a call to mtk_wed_wdma_tx_ring_setup() for ring 0 > from mtk_wed_start() when the device is WED v2 and rx_ring[0] was not > allocated, passing reset=true when tx_wdma[0] already exists. > > > diff --git a/drivers/net/ethernet/mediatek/mtk_wed.c b/drivers/net/ethernet/mediatek/mtk_wed.c > > index 3f0be70c3f145..3800e602d3c48 100644 > > --- a/drivers/net/ethernet/mediatek/mtk_wed.c > > +++ b/drivers/net/ethernet/mediatek/mtk_wed.c > > @@ -2339,6 +2339,13 @@ mtk_wed_start(struct mtk_wed_device *dev, u32 irq_mask) > > if (!dev->rx_wdma[i].desc) > > mtk_wed_wdma_rx_ring_setup(dev, i, 16, false); > > > > + /* > > + * non-DBDC MT7986 allocates only rx_ring[1] and tx_wdma[1] during setup > > + * but tx_wdma[0] is also needed for WED to function. > > + */ > > + if (mtk_wed_is_v2(dev->hw) && !dev->rx_ring[0].desc) > > + mtk_wed_wdma_tx_ring_setup(dev, 0, MTK_WED_WDMA_RING_SIZE, !!dev->tx_wdma[0].desc); > > [Severity: Medium] > Should the return value of mtk_wed_wdma_tx_ring_setup() be checked here? > > On the first start of a non-DBDC v2 device dev->tx_wdma[0].desc is NULL, so > reset is false and the helper takes the allocation path: > > drivers/net/ethernet/mediatek/mtk_wed.c:mtk_wed_wdma_tx_ring_setup() { > wdma = &dev->tx_wdma[idx]; > if (!reset && mtk_wed_ring_alloc(dev, wdma, MTK_WED_WDMA_RING_SIZE, > dev->hw->soc->wdma_desc_size, true)) > return -ENOMEM; > ... > } > > mtk_wed_ring_alloc() does a dma_alloc_coherent() of > MTK_WED_WDMA_RING_SIZE * wdma_desc_size (32 KiB on MT7986), and on failure > the helper returns before writing MTK_WDMA_RING_TX(0) BASE/COUNT/CPU_IDX/ > DMA_IDX and before the "if (!idx)" block that programs the WED side > MTK_WED_WDMA_RING_TX window. > > Since the status is dropped, mtk_wed_start() keeps going through > mtk_wed_hw_init(), mtk_wed_configure_irq() and mtk_wed_dma_enable(), which > arms MTK_WDMA_GLO_CFG_TX_DMA_EN and, for rx-capable v2, > MTK_WED_WDMA_GLO_CFG_TX_DRV_EN | MTK_WED_WDMA_GLO_CFG_TX_DDONE_CHK, and > then sets dev->running = true. Can the hardware then fetch descriptors > from a ring whose base register was left at 0 by the preceding > mtk_wdma_tx_reset()/mtk_wed_reset(), leaving the WED offload silently > non-functional with no message? > > The other caller of the same helper propagates the failure: > > drivers/net/ethernet/mediatek/mtk_wed.c:mtk_wed_rx_ring_setup() { > if (mtk_wed_wdma_tx_ring_setup(dev, idx, MTK_WED_WDMA_RING_SIZE, > reset)) > return -ENOMEM; > ... > } > > and mtk_wed_start() itself already bails out on mtk_wed_rx_buffer_alloc() > and mtk_wed_rro_cfg() failures. Since mtk_wed_ops.start is void and > mt7915_dma_start() cannot observe the error, would it make sense to abort > the start sequence locally here (skipping mtk_wed_dma_enable() and > dev->running = true) and log the failure? ACK I will add error messages and return when there's an error. > > [Severity: Medium] > This isn't a problem introduced by this patch, but does this new call add > another leak of dev->tx_wdma[0]? > > dev->tx_wdma[] rings are allocated by mtk_wed_ring_alloc() via > mtk_wed_wdma_tx_ring_setup(), but the ring-release helpers never free that > array: > > drivers/net/ethernet/mediatek/mtk_wed.c:mtk_wed_free_tx_rings() { > for (i = 0; i < ARRAY_SIZE(dev->tx_ring); i++) > mtk_wed_free_ring(dev, &dev->tx_ring[i]); > for (i = 0; i < ARRAY_SIZE(dev->rx_wdma); i++) > mtk_wed_free_ring(dev, &dev->rx_wdma[i]); > } > > drivers/net/ethernet/mediatek/mtk_wed.c:mtk_wed_free_rx_rings() { > mtk_wed_free_rx_buffer(dev); > mtk_wed_free_ring(dev, &dev->rro.ring); > } > > __mtk_wed_detach() calls those helpers and then does > memset(dev, 0, sizeof(*dev)), so tx_wdma[].desc/desc_phys are discarded and > the 32 KiB coherent allocation can no longer be released. > > The existing allocation site is mtk_wed_rx_ring_setup(), so the omission > predates this change, but non-DBDC MT7986/MT7981 previously never allocated > tx_wdma[0] at all, and now every attach/start/detach cycle would leak one > more ring. Would adding dev->tx_wdma[] to mtk_wed_free_tx_rings() be the > right way to restore alloc/free symmetry? > There is a patch in MediaTek SDK fixing this exact issue. I will pull the patch from there. Link:https://github.com/mediatek/mtk-openwrt-feeds/blob/main/25.12/files/target/linux/mediatek/patches-6.12/999-wed-04-Fix-reinsert-wifi-module-cause-memory-leak-issue.patch Best regards, Zhi-Jun pw-bot: cr > -- > Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260917144335.19466-1-hujy652%40gmail.com > ^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-22 13:47 UTC | newest] Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- 2026-09-17 14:43 [PATCH net v4 1/3] net: ethernet: mtk_wed: skip ring reset in wdma_tx_ring_setup for WED v3 Zhi-Jun You 2026-09-17 14:43 ` [PATCH net v4 2/3] net: ethernet: mtk_wed: fix reset condition for rx wdma Zhi-Jun You 2026-09-17 14:43 ` [PATCH net v4 3/3] net: ethernet: mtk_wed: setup WDMA_RING_TX(0) for non-DBDC MT7986 Zhi-Jun You 2026-09-21 16:10 ` netdev-bot+sashiko 2026-09-22 13:46 ` Zhi-Jun You
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®