Created attachment 273049 [details] fix RX BA crash iwlwifi(4)/AX211: reproducible fw crash ADVANCED_SYSASSERT 0x2010350B in RX_BAID_ALLOCATION_CONFIG_CMD on ADDBA (hw_crypto=1) After enabling compat.linuxkpi.80211.hw_crypto=1 I am getting reproducible firmware crashes on an AX211, always with the same signature: the crash happens the moment the AP sends an ADDBA request and net80211 accepts the A-MPDU RX session. 6 crashes within ~6 hours of normal use, all identical. iwlwifi0: UMAC CURRENT PC: 0x80284cac iwlwifi0: LMAC1 CURRENT PC: 0xd0 iwlwifi0: FW error in SYNC CMD UNKNOWN #0 0xffffffff80e6d17b at linux_dump_stack+0x1b #1 0xffffffff84eef096 at iwl_trans_pcie_send_hcmd+0x406 #2 0xffffffff84ecbd9a at iwl_trans_send_cmd+0x6a #3 0xffffffff84f3414c at iwl_mvm_send_cmd_status+0x2c #4 0xffffffff84f25eb5 at iwl_mvm_sta_rx_agg+0x285 #5 0xffffffff84efb3a8 at iwl_mvm_mac_ampdu_action+0x238 #6 0xffffffff80e5c3da at lkpi_ic_ampdu_rx_start+0x13a #7 0xffffffff80d6561d at ht_recv_action_ba_addba_request+0x13d #8 0xffffffff80e64599 at lkpi_iv_sta_recv_mgmt+0x19 #9 0xffffffff80d9042b at sta_input+0xc8b #10 0xffffffff80d69a50 at ieee80211_input_mimo+0x1f0 #11 0xffffffff80e56d98 at lkpi_80211_lhw_rxq_task+0x148 #12 0xffffffff80c38d7e at taskqueue_run_locked+0x18e #13 0xffffffff80c39f42 at taskqueue_thread_loop+0xc2 #14 0xffffffff80b843db at fork_exit+0x7b #15 0xffffffff810d9b4e at fork_trampoline+0xe iwlwifi0: lkpi_ic_ampdu_rx_start: mo_ampdu_action returned -5. ni 0xfffffe0199012000 rap 0xfffffe0199012d58 iwlwifi0: WRT: Collecting data: ini trigger 4 fired (delay=0ms). iwlwifi0: Device error - SW reset Claude code do next analyze: ==== net80211 does not tear down a running RX BA session before accepting a new ADDBA request on the same TID. ht_recv_action_ba_addba_request() (sys/net80211/ieee80211_ht.c) unconditionally calls ic_ampdu_rx_start() and net80211's own software handler ampdu_rx_start() copes with the restart by just purging and re-initializing the reorder queue (see the IEEE80211_AGGR_RUNNING check around ieee80211_ht.c:697-708). LinuxKPI forwards this as a second IEEE80211_AMPDU_RX_START to the driver without an intervening RX_STOP. mac80211 guarantees drivers a stop of the running session before the next start on the same TID (net/mac80211/agg-rx.c tears the old session down first), so iwlwifi does not handle the duplicate: iwl_mvm_sta_rx_agg() sends a second RX_BAID_ALLOCATION_CONFIG_CMD/ADD for the same (sta, tid) and the firmware asserts (ADVANCED_SYSASSERT 0x2010350B). That matches the observed trigger: the peer re-sends an ADDBA request after a timeout or a lost ADDBA response (this link runs at low MCS, so that happens regularly). Note lkpi_ic_ampdu_rx_stop() already guards the mirror case ("we should not call into mac80211 ops with AMPDU_RX_STOP if we did not START", with the same IEEE80211_AGGR_RUNNING check); the START side was simply missing the equivalent handling. Patch below: emulate the mac80211 semantics in lkpi_ic_ampdu_rx_start() by sending RX_STOP for the running session first. === Result on my system (AX211, fw 89, hw_crypto=1): with this patch the box went from 6 identical firmware crashes in ~6 hours to zero crashes since (A-MPDU RX active, >12h uptime including bulk traffic).
Please show the *all* lines of the iwlwifi firmware crash.
(In reply to Bjoern A. Zeeb from comment #1) iwlwifi0: Microcode SW error detected. Restarting 0x0. iwlwifi0: Start IWL Error Log Dump: iwlwifi0: Transport status: 0x0000004B, valid: 6 iwlwifi0: Loaded firmware version: 89.735b75a4.0 ma-b0-gf-a0-89.ucode iwlwifi0: 0x00000071 | NMI_INTERRUPT_UMAC_FATAL iwlwifi0: 0x10A08200 | trm_hw_status0 iwlwifi0: 0x00000000 | trm_hw_status1 iwlwifi0: 0x002DDF4E | branchlink2 iwlwifi0: 0x00008320 | interruptlink1 iwlwifi0: 0x00008320 | interruptlink2 iwlwifi0: 0x00015828 | data1 iwlwifi0: 0x00000010 | data2 iwlwifi0: 0x00000000 | data3 iwlwifi0: 0x4580DD60 | beacon time iwlwifi0: 0x8608029E | tsf low iwlwifi0: 0x00000013 | tsf hi iwlwifi0: 0x00000000 | time gp1 iwlwifi0: 0x2DA66250 | time gp2 iwlwifi0: 0x00000001 | uCode revision type iwlwifi0: 0x00000059 | uCode version major iwlwifi0: 0x735B75A4 | uCode version minor iwlwifi0: 0x00000441 | hw version iwlwifi0: 0x18C80002 | board version iwlwifi0: 0x031C001C | hcmd iwlwifi0: 0xE7B61000 | isr0 iwlwifi0: 0x01440000 | isr1 iwlwifi0: 0x48F0001A | isr2 iwlwifi0: 0x00C10008 | isr3 iwlwifi0: 0x00200000 | isr4 iwlwifi0: 0x031C001C | last cmd Id iwlwifi0: 0x00015828 | wait_event iwlwifi0: 0x00004288 | l2p_control iwlwifi0: 0x00019434 | l2p_duration iwlwifi0: 0x000003BF | l2p_mhvalid iwlwifi0: 0x00E700D8 | l2p_addr_match iwlwifi0: 0x00000009 | lmpm_pmg_sel iwlwifi0: 0x00000000 | timestamp iwlwifi0: 0x0000C8A8 | flow_handler iwlwifi0: Start IWL Error Log Dump: iwlwifi0: Transport status: 0x0000004B, valid: 7 iwlwifi0: 0x2010350B | ADVANCED_SYSASSERT iwlwifi0: 0x00000000 | umac branchlink1 iwlwifi0: 0x802602B6 | umac branchlink2 iwlwifi0: 0x80263B14 | umac interruptlink1 iwlwifi0: 0x00000000 | umac interruptlink2 iwlwifi0: 0x00000000 | umac data1 iwlwifi0: 0x00000001 | umac data2 iwlwifi0: 0xDEADBEEF | umac data3 iwlwifi0: 0x00000059 | umac major iwlwifi0: 0x735B75A4 | umac minor iwlwifi0: 0x2DA6624C | frame pointer iwlwifi0: 0xC0886BDC | stack pointer iwlwifi0: 0x00A60516 | last host cmd iwlwifi0: 0x00000000 | isr status reg iwlwifi0: IML/ROM dump: iwlwifi0: 0x00000B03 | IML/ROM error/state iwlwifi0: 0x00008435 | IML/ROM data1 iwlwifi0: 0x00000080 | IML/ROM WFPM_AUTH_KEY_0 iwlwifi0: Fseq Registers: iwlwifi0: 0x65B00000 | FSEQ_ERROR_CODE iwlwifi0: 0x80840003 | FSEQ_TOP_INIT_VERSION iwlwifi0: 0x003B0000 | FSEQ_CNVIO_INIT_VERSION iwlwifi0: 0x0000A652 | FSEQ_OTP_VERSION iwlwifi0: 0x00000003 | FSEQ_TOP_CONTENT_VERSION iwlwifi0: 0x4552414E | FSEQ_ALIVE_TOKEN iwlwifi0: 0x01080800 | FSEQ_CNVI_ID iwlwifi0: 0x00400410 | FSEQ_CNVR_ID iwlwifi0: 0x01080800 | CNVI_AUX_MISC_CHIP iwlwifi0: 0x00400410 | CNVR_AUX_MISC_CHIP iwlwifi0: 0x00009061 | CNVR_SCU_SD_REGS_SD_REG_DIG_DCDC_VTRIM iwlwifi0: 0x00000061 | CNVR_SCU_SD_REGS_SD_REG_ACTIVE_VDIG_MIRROR iwlwifi0: 0x003B0000 | FSEQ_PREV_CNVIO_INIT_VERSION iwlwifi0: 0x00840003 | FSEQ_WIFI_FSEQ_VERSION iwlwifi0: 0x00840003 | FSEQ_BT_FSEQ_VERSION iwlwifi0: 0x000000E6 | FSEQ_CLASS_TP_VERSION iwlwifi0: UMAC CURRENT PC: 0x80284cac iwlwifi0: LMAC1 CURRENT PC: 0xd0 iwlwifi0: FW error in SYNC CMD UNKNOWN #0 0xffffffff80e6d17b at linux_dump_stack+0x1b #1 0xffffffff84eef096 at iwl_trans_pcie_send_hcmd+0x406 #2 0xffffffff84ecbd9a at iwl_trans_send_cmd+0x6a #3 0xffffffff84f3414c at iwl_mvm_send_cmd_status+0x2c #4 0xffffffff84f25eb5 at iwl_mvm_sta_rx_agg+0x285 #5 0xffffffff84efb3a8 at iwl_mvm_mac_ampdu_action+0x238 #6 0xffffffff80e5c3da at lkpi_ic_ampdu_rx_start+0x13a #7 0xffffffff80d6561d at ht_recv_action_ba_addba_request+0x13d #8 0xffffffff80e64599 at lkpi_iv_sta_recv_mgmt+0x19 #9 0xffffffff80d9042b at sta_input+0xc8b #10 0xffffffff80d69a50 at ieee80211_input_mimo+0x1f0 #11 0xffffffff80e56d98 at lkpi_80211_lhw_rxq_task+0x148 #12 0xffffffff80c38d7e at taskqueue_run_locked+0x18e #13 0xffffffff80c39f42 at taskqueue_thread_loop+0xc2 #14 0xffffffff80b843db at fork_exit+0x7b #15 0xffffffff810d9b4e at fork_trampoline+0xe iwlwifi0: lkpi_ic_ampdu_rx_start: mo_ampdu_action returned -5. ni 0xfffffe0199012000 rap 0xfffffe0199012d58 iwlwifi0: WRT: Collecting data: ini trigger 4 fired (delay=0ms). iwlwifi0: Device error - SW reset
Created attachment 273482 [details] fix RX BA crash ^Triage: attempt to rebase patch that previously did not apply.