Commit Graph

1464105 Commits

Author SHA1 Message Date
Laxman Acharya Padhya
9417c5818a wifi: mt76: mt7921: validate CLC firmware records
The CLC region is supplied by firmware, but the loader trusts the
region count and each record length. A malformed image can make the
region table pointer precede the firmware buffer, make the record loop
fail to advance, or index phy->clc past its end. Validate the table and
record bounds before dereferencing or copying.

Fixes: 23bdc5d8ca ("wifi: mt76: mt7921: introduce Country Location Control support")
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Link: https://patch.msgid.link/CAMyXUJmh=WfwC4_KHupNxYR5e2Gy5QhBDL5TSG6XEW-XLa+X4Q@mail.gmail.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:38 +00:00
Sean Wang
7910bd565d wifi: mt76: mt792x: quiesce USB paths on disconnect
USB disconnect can leave reset/init work, TX worker, and MCU waiters active
while the device is being removed. Stop those paths before unregistering
the device to avoid teardown waiting on firmware or queue activity after
disconnect.

Run WFSYS reset after USB queue deinit so removal does not issue the reset
while USB traffic may still be queued.

Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260613224131.2396026-7-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:38 +00:00
Sean Wang
b994cb409f wifi: mt76: mt792x: enable USB UDMA TX timeout
Configure the USB UDMA TX timeout limit and enable timeout detection
during DMA initialization, matching the vendor driver setup. Use a
longer timeout to avoid false alarms.

Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260613224131.2396026-6-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:38 +00:00
Sean Wang
a4803d1801 wifi: mt76: mt792x: drain USB UDMA before WFSYS reset
Stop USB UDMA RX/TX and wait for idle before WFSYS reset.
Warn if the engine remains busy.

Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260613224131.2396026-5-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:38 +00:00
Sean Wang
e137e5fd24 wifi: mt76: mt792x: stop USB register access after bus hang
Mark the mt792x USB bus hung on the first control timeout and switch
register access to no-op bus ops. Each failed vendor request may spend
up to MT_VEND_REQ_MAX_RETRY * MT_VEND_REQ_TOUT_MS, about 3 seconds, and
teardown/reset paths can keep issuing such requests after the device has
stopped responding.

Also skip the USB WFSYS reset path after bus_hung is set, since it uses
UHW vendor requests as well.

mt7925u 1-2:1.3: vendor request req:63 off:0018 failed:-110
mt7925u 1-2:1.3: vendor request req:63 off:0018 failed:-110
mt7925u 1-2:1.3: vendor request req:63 off:0018 failed:-110
mt7925u 1-2:1.3: vendor request req:63 off:0018 failed:-110
mt7925u 1-2:1.3: vendor request req:63 off:0018 failed:-110

Avoid repeating those register reads after the bus is known to be hung by
switching register access to no-op handlers.

Fixes: 0d2afe09fa ("mt76: mt7921: add mt7921u driver")
Fixes: c948b5da6b ("wifi: mt76: mt7925: add Mediatek Wi-Fi7 driver for mt7925 chips")
Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260613224131.2396026-4-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:38 +00:00
Sean Wang
c781b74c3f wifi: mt76: mt7925: skip reset work on hung bus
Skip mt7925 reset handling once the bus is marked hung.

A hung bus cannot be recovered by issuing another device reset. Continuing
the reset path may only send more failing MCU or register accesses and
delay teardown. Return early from reset work and the USB reset path so the
failed device can be torn down quickly.

Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260613224131.2396026-3-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:38 +00:00
Sean Wang
7e87dc3b21 wifi: mt76: mt7925: stop init retries on hung bus
Stop retrying hardware init once the bus is marked hung.

The control path is no longer usable at that point, so more retries only
issue failing device accesses, including MCU commands or register
operations, and delay teardown. Exit early and let the failed device be
torn down quickly.

Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260613224131.2396026-2-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Shayne Chen
70869cc429 wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()
When performing channel switches on different radios within a short
timeframe, channel contexts with different bands can be carried for
each struct ieee80211_vif_chanctx_switch.

Rework mt76_switch_vif_chanctx() to properly handle this scenario.

Fixes: 82334623af ("wifi: mt76: add chanctx functions for multi-channel phy support")
Co-developed-by: Rex Lu <rex.lu@mediatek.com>
Signed-off-by: Rex Lu <rex.lu@mediatek.com>
Signed-off-by: Shayne Chen <shayne.chen@mediatek.com>
Link: https://patch.msgid.link/20260720090102.190729-1-shayne.chen@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
David Bauer
965cbdbdfb wifi: mt76: mt7603: free beacon SKB on error
The SKB containing the generated beacon is not freed when the beacon
queue is deected stuck and scheduled for recovery.

Fixes potential memory leaks in case the beacon queue is detected stuck.

Signed-off-by: David Bauer <mail@david-bauer.net>
Link: https://patch.msgid.link/20260611215658.259324-1-mail@david-bauer.net
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Ethan Nelson-Moore
429e516d4f wifi: mt76: mt7996: remove code guarded by nonexistent config option
A small piece of code in mt7996.h depends on CONFIG_MTK_DEBUG, which
has never been defined in the kernel. Remove this dead code.

Discovered while searching for CONFIG_* symbols referenced in code but
not defined in any Kconfig file.

Signed-off-by: Ethan Nelson-Moore <enelsonmoore@gmail.com>
Reviewed-by: Matthias Brugger <matthias.bgg@gmail.com>
Link: https://patch.msgid.link/20260610041050.206950-1-enelsonmoore@gmail.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Ethan Nelson-Moore
31beda21fb wifi: mt76: mt7925: remove code guarded by nonexistent config option
A small piece of code in mt7925/regs.h depends on CONFIG_MT76_DEV, which
has never been defined in the kernel. Remove this dead code.

Discovered while searching for CONFIG_* symbols referenced in code but
not defined in any Kconfig file.

Signed-off-by: Ethan Nelson-Moore <enelsonmoore@gmail.com>
Reviewed-by: Matthias Brugger <matthias.bgg@gmail.com>
Link: https://patch.msgid.link/20260610042429.222717-1-enelsonmoore@gmail.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Devin Wittmayer
ddae0bcb01 wifi: mt76: mt76x02: report rx FCS errors to mac80211
When the fcsfail filter is enabled the hardware passes frames with a bad
FCS up to the driver, but mt76x02_mac_process_rx() never checks
MT_RXINFO_CRCERR and hands them to mac80211 without
RX_FLAG_FAILED_FCS_CRC. In monitor mode the radiotap flags byte then
never gets IEEE80211_RADIOTAP_F_BADFCS set and corrupted frames cannot be
told apart from clean ones.

Set RX_FLAG_FAILED_FCS_CRC from the descriptor CRC error bit, matching
mt7603, mt7615, mt7915, mt7921, mt7925 and mt7996.

Reported-by: 0072a70 <90307219+0072a70@users.noreply.github.com>
Closes: https://github.com/morrownr/mt76/issues/38
Tested-by: 0072a70 <90307219+0072a70@users.noreply.github.com>
Signed-off-by: Devin Wittmayer <lucid_duck@justthetip.ca>
Link: https://patch.msgid.link/20260613002544.27750-3-lucid_duck@justthetip.ca
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Devin Wittmayer
81497634d9 wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length
The MPDU length in the rx descriptor comes from the hardware. In
monitor mode with the fcsfail filter enabled, the hardware passes up
corrupted frames, and a corrupted frame can report a length larger
than the received buffer. The bounds check correctly discards such
frames, but its WARN_ON_ONCE wrapper means any over-the-air garbage
frame taints the kernel, and panics it on the first such frame when
panic_on_warn is set.

Drop the WARN and discard the frame silently, matching what
commit c2d4c8723d ("mt76x2: remove some harmless WARN_ONs in tx
status and rx path") did for the neighboring rx and tx status paths.

Observed immediately on rx with an MT7612U in fcsfail monitor mode
on a busy channel.

Fixes: 7bc04215a6 ("mt76: add driver code for MT76x2e")
Signed-off-by: Devin Wittmayer <lucid_duck@justthetip.ca>
Link: https://patch.msgid.link/20260613002544.27750-2-lucid_duck@justthetip.ca
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Sean Wang
420e0bbd52 wifi: mt76: mt792x: advertise NAN data support
Advertise NAN and NAN data support when firmware exposes NAN
capability.

Add NAN interface combinations on top of the dynamic combination
framework, advertise 2.4 GHz and 5 GHz NAN bands, and enable secure
NAN.

Keep the base interface combinations unchanged when NAN is unavailable
so existing STA/AP/P2P modes keep the same limits.

Co-developed-by: Stella Liu <yu-ching.liu@mediatek.com>
Signed-off-by: Stella Liu <yu-ching.liu@mediatek.com>
Co-developed-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260625001834.475094-10-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Sean Wang
9bb39d09ab wifi: mt76: mt792x: build iface combinations dynamically
Move mt792x interface combination selection into a helper and store the
selected table in mt792x device state.

This keeps the existing non-CNM and CNM combinations unchanged while
making later firmware-gated extensions add combinations without touching
the common wiphy setup path.

Co-developed-by: Stella Liu <yu-ching.liu@mediatek.com>
Signed-off-by: Stella Liu <yu-ching.liu@mediatek.com>
Co-developed-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260625001834.475094-9-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Sean Wang
0f3605e4f8 wifi: mt76: mt7925: wire up NAN operations
Wire mac80211 NAN start, stop and change_conf callbacks to the mt7925 NAN
MCU helpers. Track the active NAN vif and notify mac80211 on cluster join
events.

Initialize NAN PHY capabilities after the supported bands are ready.

Co-developed-by: Stella Liu <yu-ching.liu@mediatek.com>
Signed-off-by: Stella Liu <yu-ching.liu@mediatek.com>
Co-developed-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260625001834.475094-8-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Sean Wang
4ee3d2a5f2 wifi: mt76: add init_wiphy callback
Add an optional callback for drivers to finalize wiphy state after mt76
has initialized the supported bands and before registration.

Co-developed-by: Stella Liu <yu-ching.liu@mediatek.com>
Signed-off-by: Stella Liu <yu-ching.liu@mediatek.com>
Co-developed-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260625001834.475094-7-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Sean Wang
9824fb4edb wifi: mt76: mt7925: add NAN MCU handling
Route NAN MCU responses and unsolicited events through the mt7925 MCU
path, and handle NAN-specific BSS and station TLVs.

Co-developed-by: Stella Liu <yu-ching.liu@mediatek.com>
Signed-off-by: Stella Liu <yu-ching.liu@mediatek.com>
Co-developed-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260625001834.475094-6-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Sean Wang
a5487a6824 wifi: mt76: mt7925: add NAN MCU helpers
Add the mt7925 NAN MCU ABI and helpers for enable, disable, configuration
updates, availability updates and peer schedule commands.

Upper-layer integration is added by later patches.

Co-developed-by: Stella Liu <yu-ching.liu@mediatek.com>
Signed-off-by: Stella Liu <yu-ching.liu@mediatek.com>
Co-developed-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260625001834.475094-5-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Sean Wang
b7ab9f780d wifi: mt76: connac: add NAN connection type
Introduce a dedicated NAN connection type for connac firmware and use it
for NAN interface device, BSS and station records.

Add the common NAN MCU command and event IDs used by mt7925.

Co-developed-by: Stella Liu <yu-ching.liu@mediatek.com>
Signed-off-by: Stella Liu <yu-ching.liu@mediatek.com>
Co-developed-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260625001834.475094-4-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Sean Wang
9080164f3b wifi: mt76: mt7925: guard BSS capability lookups
mt7925 BSS setup may dereference missing channel data or query HE 6 GHz
capabilities for an iftype without HE support.

Guard both lookups before adding NAN paths that can use partially
configured BSS state.

Co-developed-by: Stella Liu <yu-ching.liu@mediatek.com>
Signed-off-by: Stella Liu <yu-ching.liu@mediatek.com>
Co-developed-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260625001834.475094-3-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Sean Wang
a7c71a3465 wifi: mt76: mt792x: advertise mgmt frame registration
Advertise multicast management frame registration support so userspace
can subscribe to multicast management and action frames.

This capability is required for NAN discovery and related operations.

Co-developed-by: Stella Liu <yu-ching.liu@mediatek.com>
Signed-off-by: Stella Liu <yu-ching.liu@mediatek.com>
Co-developed-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Jeremy Yu <chengwei.yu@mediatek.com>
Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Link: https://patch.msgid.link/20260625001834.475094-2-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Filip Bakreski
5323d3e50c wifi: mt76: mt76u: use a threaded NAPI for the RX path
The USB RX path delivers frames to the stack via mt76_rx_complete() with
a NULL napi pointer, taking the netif_receive_skb_list() path, so it never
benefits from GRO -- unlike the DMA-based mt76 drivers, which pass a real
napi and use napi_gro_receive(). For bulk TCP traffic this is costly, as
every segment traverses the stack individually.

Service the MT_RXQ_MAIN queue from a threaded NAPI, reusing mt76_dev's
existing napi_dev and napi[] rather than adding new fields. The URB
completion handler schedules the napi; its poll drains the URBs, builds
the skbs, resubmits and delivers them through napi_gro_receive(). The MCU
queue stays on the existing RX worker. This enables GRO and moves RX
processing into its own kernel thread, parallelising the datapath.

On mt7921u at HE-MCS 11 (2x2, 80 MHz; fast.com, multiple streams) this
averages ~588 Mbit/s, versus ~424 Mbit/s when the same napi is instead
driven manually from the RX worker, and ~380 Mbit/s for the unmodified
driver.

Suggested-by: Lorenzo Bianconi <lorenzo@kernel.org>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Filip Bakreski <phial@phiality.com>
Acked-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/20260609105301.196302-1-phial@phiality.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
David Bauer
a92cd5dd79 wifi: mt76: mt7915: configure noise floor reporting on reset
When performing a full system recovery of the MCU on a dual-phy
platform, band 0 (usually 2.4GHz) stops reading correct noise floor
data.

This is due to noise floor reporting only being configured correctly
for the second device PHY.

Configure the respective registers correctly after restarting the MCU
firmware to fix reported noise-floor values.

Signed-off-by: David Bauer <mail@david-bauer.net>
Link: https://patch.msgid.link/20260516144944.2574053-1-mail@david-bauer.net
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Emery Hsin
e65b4ca339 wifi: mt76: mt7925: add MT7928 PCIe support
Register MT7928 (0x7928, 0x7935) in the PCI device table and
declare MODULE_FIRMWARE for all four MT7928 firmware blobs.

Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075339.2578327-5-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Emery Hsin
8905038d58 wifi: mt76: mt7925: add MT7928 per-chip PCIe register definitions
MT7928 maps PCIe MAC registers through base 0x74040000. Add
MT7928_PCIE_MAC_{INT_ENABLE,PM} macros and override dev->pcie_reg
at probe time for MT7928 hardware.

Signed-off-by: Xiong <xiong.huang@mediatek.com>
Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075339.2578327-4-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Emery Hsin
f26fda0c6a wifi: mt76: mt7925: align scan IE and EFUSE TLV lengths to 4 bytes for MT7928
MT7928 firmware requires 4-byte aligned TLV payloads. Round up
UNI_SCAN_IE allocation with ALIGN(..., 4) and track padded length.

Signed-off-by: Xiong <xiong.huang@mediatek.com>
Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075339.2578327-3-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:37 +00:00
Emery Hsin
d93e31ba9f wifi: mt76: mt7925: add MMIO register remapping table for MT7928
MT7928 has a different physical address layout. Add a dedicated
mt7928_fixed_map[] remapping table and select it at runtime. Set
mdev->rev early in probe for correct chip revision detection.

Signed-off-by: Leon Yen <leon.yen@mediatek.com>
Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075339.2578327-2-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
5e738c59e0 wifi: mt76: mt7925: add MT7928 TXD/TXS/TX_DONE support
Add MT7928 TXD v2 fields, per-chip WTBL register addresses, UNI
TxDone event parsing, and TXS format acceptance for MPDU/PPDU.
Suppress HW AMSDU on management frames for MT7928.

Signed-off-by: Xiong <xiong.huang@mediatek.com>
Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075339.2578327-1-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
a01a222ab4 wifi: mt76: mt7925: add MT7928 DMA configuration
Add MT7928 DMA queue layout, DMASHDL configuration, prefetch ring
setup, and WFDMA interrupt priority initialization. Select the
MT7928-specific layout and GLO_CFG path in mt7925_dma_init().

Signed-off-by: FC Wei <fc.wei@mediatek.com>
Signed-off-by: Xiong <xiong.huang@mediatek.com>
Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075313.2578154-5-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
d92d0b0c06 wifi: mt76: mt7925: add MT7928 irq_map with chip-specific rx masks
MT7928 uses different RX interrupt bit assignments (RX_DONE_DATA on
ENA0, RX_DONE_WM on ENA3). Add MT7928-specific irq_map and select
it at probe time based on PCI device ID.

Signed-off-by: FC Wei <fc.wei@mediatek.com>
Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075313.2578154-4-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
4f8ded4d5f wifi: mt76: mt7925: add MT7928 FWDL support
Add CBMCU and PHY RAM firmware download flow for MT7928. The CBMCU
firmware is loaded in sections before the main WM firmware. Register
MT7928 firmware file names and is_mt7928() chip check.

Signed-off-by: FC Wei <fc.wei@mediatek.com>
Signed-off-by: Xiong <xiong.huang@mediatek.com>
Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075313.2578154-3-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
e34e157e6e wifi: mt76: mt7925: fix MMIO dynamic remap window size
Fix the 0x7c500000 remap entry window size from 0x2000000 (32MB) to
0x200000 (2MB) to match the actual addressable range.

This is a preparation patch before enabling MT7928 PCIe support.

Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075313.2578154-2-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
e058739cbf wifi: mt76: connac3: update basic rate table starting index
Change MT792x_BASIC_RATES_TBL index from 11 to 14 to match the latest
connac3 firmware rate table layout.

This is a preparation patch before enabling MT7928 PCIe support.

Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075313.2578154-1-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
78ff45f849 wifi: mt76: mt792x: add tx_done ring to common DMA queue allocation
Add a tx_done field to mt792x_dma_layout and extend
mt792x_dma_alloc_queues() to allocate the MT_RXQ_MCU_WA queue when
tx_done.ring_base is configured.

This is a preparation patch before enabling MT7928 PCIe support.

Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075136.2577553-5-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
3422e61141 wifi: mt76: mt7925: rename WTBL registers to chip-specific format
Rename MT_WTBLON_TOP_WDUCR and MT_WTBL_UPDATE to MT7925-prefixed
versions since MT7928 uses different WTBL register offsets.

This is a preparation patch before enabling MT7928 PCIe support.

Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075136.2577553-4-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
50a16805a9 wifi: mt76: mt792x: rename WFDMA DMASHDL enable bit to follow the convention
Rename MT_WFDMA0_CSR_TX_DMASHDL_ENABLE to
MT_WFDMA0_GLO_CFG_EXT0_CSR_TX_DMASHDL_EN to follow the register
naming convention (parent register name as prefix).

This is a preparation patch before enabling MT7928 PCIe support.

Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075136.2577553-3-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
d63b19ece3 wifi: mt76: mt792x: replace shared PCIe MAC macros with per-chip struct
Update mt792x_wpdma_reinit_cond() to use dev->pcie_reg and remove the
now unused MT_PCIE_MAC_INT_ENABLE and MT_PCIE_MAC_PM macros from
mt792x_regs.h.

This is a preparation patch before enabling MT7928 PCIe support.

Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075042.2577193-5-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
0d0205dbf3 wifi: mt76: mt7925: add per-chip PCIe register definitions
Add MT7925_PCIE_MAC_{INT_ENABLE,PM} macros and mt7925_pcie_reg
struct. Update all PCIe register accesses in pci.c, pci_mac.c, and
pci_mcu.c to use dev->pcie_reg->{imask,pm}.

This is a preparation patch before enabling MT7928 PCIe support.

Signed-off-by: Xiong <xiong.huang@mediatek.com>
Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075136.2577553-2-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
7e8c44d06a wifi: mt76: connac2: add per-chip PCIe register definitions
Add MT_PCIE_MAC_{INT_ENABLE,PM} definitions to mt7921/regs.h and
wire up mt7921_pcie_reg in mt7921_pci_probe() to provide connac2
series chips with their own PCIe register definitions.

This is a preparation patch before enabling MT7928 PCIe support.

Signed-off-by: Xiong <xiong.huang@mediatek.com>
Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075136.2577553-1-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
9ad48ff235 wifi: mt76: mt792x: add per-chip PCIe register struct
Add a mt792x_pcie_reg struct and a pcie_reg pointer in mt792x_dev, so
that each chip can supply its own PCIe register offsets. Users are
converted in the following patches.

This is a preparation patch before enabling MT7928 PCIe support.

Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075042.2577193-5-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
4590ceed74 wifi: mt76: mt7925: add MT7927 per-chip rx irq definitions
Add MT7927_INT_RX_DONE_{DATA,WM,WM2,ALL} macros and populate
all_complete_mask in mt7927_irq_map. MT7927 maps RX_DONE_DATA to
ENA4 and RX_DONE_WM to ENA6, differing from MT7925.

This is a preparation patch before enabling MT7928 PCIe support.

Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075042.2577193-4-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
c4edf9e3e0 wifi: mt76: mt7925: replace shared rx irq masks with per-chip definitions
Replace shared MT_INT_RX_DONE_* macros with chip-specific
MT7925_INT_RX_DONE_{DATA,WM,WM2,ALL} and populate all_complete_mask
in mt7925_irq_map. Update resume and mac_reset paths accordingly.

This is a preparation patch before enabling MT7928 PCIe support.

Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075042.2577193-3-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
83c65e82e5 wifi: mt76: connac2: apply new rx all_complete_mask
Populate all_complete_mask in MT7921 irq_map and update pci_resume()
and mac_reset() to use irq_map->rx.all_complete_mask instead of the
hardcoded MT_INT_RX_DONE_ALL macro.

This is a preparation patch before enabling MT7928 PCIe support.

Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075042.2577193-2-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Emery Hsin
047dc4dc58 wifi: mt76: mt792x: consolidate rx interrupt masks into all_complete_mask
Add all_complete_mask to irq_map rx sub-struct and use it in
mt792x_irq_tasklet() and mt792x_dma_enable() to replace individual
per-ring mask OR expressions.

This is a preparation patch before enabling MT7928 PCIe support.

Signed-off-by: Emery Hsin <emery.hsin@mediatek.com>
Link: https://patch.msgid.link/20260612075042.2577193-1-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Runyu Xiao
bda8324270 wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex
mt7615_suspend() acquired the mt76 mutex and then called
cancel_delayed_work_sync() on mac_work.  mt7615_mac_work() acquires the
same mutex via mt7615_mutex_acquire() at the top of the worker, so if
mac_work is already running and blocked on the mutex, the suspend path
deadlocks waiting for the work it holds the mutex against.

Flush scan_work and mac_work before taking the mutex, matching the
suspend paths in mt7921 and mt7925.  scan_work only takes the mt76
spinlock, but moving it keeps the sequence consistent.  This also keeps
mac_work from running over an already suspended HIF, which the previous
split (async cancel under the lock, sync cancel after release) would
have allowed.

Fixes: c6bf20109a ("mt76: mt7615: add WoW support")
Cc: stable@vger.kernel.org
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Link: https://patch.msgid.link/20260612041331.2596331-1-runyu.xiao@seu.edu.cn
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Dmitry Gomzyakov
574bd79955 wifi: mt76: connac: add MT7991A (0x7991) to is_mt7996()
The MT7991A chipset uses PCI device ID 0x7991 (MT7996_DEVICE_ID_2),
but is_mt7996() only checks for 0x7990. This causes MT7991A devices
to use incorrect chip-specific settings, such as:
- MSDU_CNT_V2 instead of MSDU_CNT in TX descriptors
- Wrong WTBL BMC size (32 instead of 64)
- Incorrect prefetch depth for MCU queues

Fixes: 7014fe5358 ("wifi: mt76: mt7996: add macros for pci device ids")
Signed-off-by: Dmitry Gomzyakov <nicerok11@gmail.com>
Link: https://patch.msgid.link/20260510102911.1883849-2-kyoto1337@protonmail.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
2026-07-31 12:25:36 +00:00
Zhao Li
4a0bd262df wifi: mac80211: fix per-STA profile length in cross-link CSA parsing
ieee80211_mgd_check_cross_link_csa() starts parsing elements after the
fixed per-STA profile header and the STA Info field, but subtracts only
the STA Info length from the profile length. As a result,
ieee802_11_parse_elems() is given sizeof(*prof) == 3 bytes beyond the
current profile's element area, and data following the profile may be
interpreted as belonging to it.

Subtract the fixed profile header as well. The preceding
ieee80211_mle_basic_sta_prof_size_ok() check guarantees that the
corrected calculation cannot underflow, and
ieee80211_rx_uhr_link_reconfig_req() uses the same calculation.

The call site currently states that cross-link CSA parsing has no effect
because the broader parsing is still incorrect. This patch does not
address that broader problem; it only makes the per-STA profile parser
stop at the end of that profile. No production allocation over-read or
user-visible failure has been demonstrated.

Fixes: 7ef8f6821d ("wifi: mac80211: mlme: handle cross-link CSA")
Assisted-by: Codex:gpt-5.6-sol
Assisted-by: Kimi:K3
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260728111326.63087-1-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-07-28 16:04:16 +02:00
Dmitry Antipov
7d86b0a8ac wifi: mac80211: simplify airtime_flags_write()
Use 'kstrtou16_from_user()' to simplify 'airtime_flags_write()'.

Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru>
Link: https://patch.msgid.link/20260727095714.347039-1-dmantipov@yandex.ru
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-07-28 16:03:49 +02:00
Fabio Estevam
058d979d4f wifi: mwifiex: Remove WQ_HIGHPRI from main workqueue
The MWIFIEX_WORK_QUEUE handles command and event processing, including
the commands used for scheduled scans.

Running this work on the high-priority worker pool can interfere with
latency-sensitive workloads. On an i.MX8MP-based audio system using an
88W8997, background scheduled scans caused audible glitches in USB
audio playback.

Remove WQ_HIGHPRI from the main workqueue so that command and scan
processing use the normal-priority worker pool.

Leave the RX and host MLME workqueues unchanged.

Signed-off-by: Fabio Estevam <festevam@nabladev.com>
Link: https://patch.msgid.link/20260724203320.78793-2-festevam@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
2026-07-28 16:02:38 +02:00