Bug 296953 - iwlwifi crashed at RX BA restart
Summary: iwlwifi crashed at RX BA restart
Status: New
Alias: None
Product: Base System
Classification: Unclassified
Component: wireless (show other bugs)
Version: 16.0-CURRENT
Hardware: amd64 Any
: --- Affects Many People
Assignee: freebsd-wireless (Nobody)
URL:
Keywords:
Depends on:
Blocks: iwlwifi
  Show dependency treegraph
 
Reported: 2026-07-21 11:20 UTC by slw
Modified: 2026-08-05 12:34 UTC (History)
1 user (show)

See Also:


Attachments
fix RX BA crash (1.74 KB, patch)
2026-07-21 11:20 UTC, slw
no flags Details | Diff
fix RX BA crash (1.58 KB, patch)
2026-08-05 12:34 UTC, Mark Linimon
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description slw 2026-07-21 11:20:05 UTC
Created attachment 273049 [details]
fix RX BA crash

iwlwifi(4)/AX211: reproducible fw crash ADVANCED_SYSASSERT 0x2010350B in RX_BAID_ALLOCATION_CONFIG_CMD on ADDBA (hw_crypto=1)

After enabling compat.linuxkpi.80211.hw_crypto=1 I am getting reproducible
firmware crashes on an AX211, always with the same signature: the crash
happens the moment the AP sends an ADDBA request and net80211 accepts the
A-MPDU RX session.  6 crashes within ~6 hours of normal use, all identical.

iwlwifi0: UMAC CURRENT PC: 0x80284cac
iwlwifi0: LMAC1 CURRENT PC: 0xd0
iwlwifi0: FW error in SYNC CMD UNKNOWN
#0 0xffffffff80e6d17b at linux_dump_stack+0x1b
#1 0xffffffff84eef096 at iwl_trans_pcie_send_hcmd+0x406
#2 0xffffffff84ecbd9a at iwl_trans_send_cmd+0x6a
#3 0xffffffff84f3414c at iwl_mvm_send_cmd_status+0x2c
#4 0xffffffff84f25eb5 at iwl_mvm_sta_rx_agg+0x285
#5 0xffffffff84efb3a8 at iwl_mvm_mac_ampdu_action+0x238
#6 0xffffffff80e5c3da at lkpi_ic_ampdu_rx_start+0x13a
#7 0xffffffff80d6561d at ht_recv_action_ba_addba_request+0x13d
#8 0xffffffff80e64599 at lkpi_iv_sta_recv_mgmt+0x19
#9 0xffffffff80d9042b at sta_input+0xc8b
#10 0xffffffff80d69a50 at ieee80211_input_mimo+0x1f0
#11 0xffffffff80e56d98 at lkpi_80211_lhw_rxq_task+0x148
#12 0xffffffff80c38d7e at taskqueue_run_locked+0x18e
#13 0xffffffff80c39f42 at taskqueue_thread_loop+0xc2
#14 0xffffffff80b843db at fork_exit+0x7b
#15 0xffffffff810d9b4e at fork_trampoline+0xe
iwlwifi0: lkpi_ic_ampdu_rx_start: mo_ampdu_action returned -5. ni 0xfffffe0199012000 rap 0xfffffe0199012d58
iwlwifi0: WRT: Collecting data: ini trigger 4 fired (delay=0ms).
iwlwifi0: Device error - SW reset


Claude code do next analyze:

====
net80211 does not tear down a running RX BA session before accepting a
new ADDBA request on the same TID.  ht_recv_action_ba_addba_request()
(sys/net80211/ieee80211_ht.c) unconditionally calls ic_ampdu_rx_start()
and net80211's own software handler ampdu_rx_start() copes with the
restart by just purging and re-initializing the reorder queue (see the
IEEE80211_AGGR_RUNNING check around ieee80211_ht.c:697-708).

LinuxKPI forwards this as a second IEEE80211_AMPDU_RX_START to the
driver without an intervening RX_STOP.  mac80211 guarantees drivers a
stop of the running session before the next start on the same TID
(net/mac80211/agg-rx.c tears the old session down first), so iwlwifi
does not handle the duplicate: iwl_mvm_sta_rx_agg() sends a second
RX_BAID_ALLOCATION_CONFIG_CMD/ADD for the same (sta, tid) and the
firmware asserts (ADVANCED_SYSASSERT 0x2010350B).

That matches the observed trigger: the peer re-sends an ADDBA request
after a timeout or a lost ADDBA response (this link runs at low MCS, so
that happens regularly).

Note lkpi_ic_ampdu_rx_stop() already guards the mirror case ("we should
not call into mac80211 ops with AMPDU_RX_STOP if we did not START",
with the same IEEE80211_AGGR_RUNNING check); the START side was simply
missing the equivalent handling.

Patch below: emulate the mac80211 semantics in lkpi_ic_ampdu_rx_start()
by sending RX_STOP for the running session first.
===

Result on my system (AX211, fw 89, hw_crypto=1): with this patch the
box went from 6 identical firmware crashes in ~6 hours to zero crashes
since (A-MPDU RX active, >12h uptime including bulk traffic).
Comment 1 Bjoern A. Zeeb freebsd_committer freebsd_triage 2026-07-21 15:25:00 UTC
Please show the *all* lines of the iwlwifi firmware crash.
Comment 2 slw 2026-07-21 15:35:09 UTC
(In reply to Bjoern A. Zeeb from comment #1)
iwlwifi0: Microcode SW error detected. Restarting 0x0.
iwlwifi0: Start IWL Error Log Dump:
iwlwifi0: Transport status: 0x0000004B, valid: 6
iwlwifi0: Loaded firmware version: 89.735b75a4.0 ma-b0-gf-a0-89.ucode
iwlwifi0: 0x00000071 | NMI_INTERRUPT_UMAC_FATAL
iwlwifi0: 0x10A08200 | trm_hw_status0
iwlwifi0: 0x00000000 | trm_hw_status1
iwlwifi0: 0x002DDF4E | branchlink2
iwlwifi0: 0x00008320 | interruptlink1
iwlwifi0: 0x00008320 | interruptlink2
iwlwifi0: 0x00015828 | data1
iwlwifi0: 0x00000010 | data2
iwlwifi0: 0x00000000 | data3
iwlwifi0: 0x4580DD60 | beacon time
iwlwifi0: 0x8608029E | tsf low
iwlwifi0: 0x00000013 | tsf hi
iwlwifi0: 0x00000000 | time gp1
iwlwifi0: 0x2DA66250 | time gp2
iwlwifi0: 0x00000001 | uCode revision type
iwlwifi0: 0x00000059 | uCode version major
iwlwifi0: 0x735B75A4 | uCode version minor
iwlwifi0: 0x00000441 | hw version
iwlwifi0: 0x18C80002 | board version
iwlwifi0: 0x031C001C | hcmd
iwlwifi0: 0xE7B61000 | isr0
iwlwifi0: 0x01440000 | isr1
iwlwifi0: 0x48F0001A | isr2
iwlwifi0: 0x00C10008 | isr3
iwlwifi0: 0x00200000 | isr4
iwlwifi0: 0x031C001C | last cmd Id
iwlwifi0: 0x00015828 | wait_event
iwlwifi0: 0x00004288 | l2p_control
iwlwifi0: 0x00019434 | l2p_duration
iwlwifi0: 0x000003BF | l2p_mhvalid
iwlwifi0: 0x00E700D8 | l2p_addr_match
iwlwifi0: 0x00000009 | lmpm_pmg_sel
iwlwifi0: 0x00000000 | timestamp
iwlwifi0: 0x0000C8A8 | flow_handler
iwlwifi0: Start IWL Error Log Dump:
iwlwifi0: Transport status: 0x0000004B, valid: 7
iwlwifi0: 0x2010350B | ADVANCED_SYSASSERT
iwlwifi0: 0x00000000 | umac branchlink1
iwlwifi0: 0x802602B6 | umac branchlink2
iwlwifi0: 0x80263B14 | umac interruptlink1
iwlwifi0: 0x00000000 | umac interruptlink2
iwlwifi0: 0x00000000 | umac data1
iwlwifi0: 0x00000001 | umac data2
iwlwifi0: 0xDEADBEEF | umac data3
iwlwifi0: 0x00000059 | umac major
iwlwifi0: 0x735B75A4 | umac minor
iwlwifi0: 0x2DA6624C | frame pointer
iwlwifi0: 0xC0886BDC | stack pointer
iwlwifi0: 0x00A60516 | last host cmd
iwlwifi0: 0x00000000 | isr status reg
iwlwifi0: IML/ROM dump:
iwlwifi0: 0x00000B03 | IML/ROM error/state
iwlwifi0: 0x00008435 | IML/ROM data1
iwlwifi0: 0x00000080 | IML/ROM WFPM_AUTH_KEY_0
iwlwifi0: Fseq Registers:
iwlwifi0: 0x65B00000 | FSEQ_ERROR_CODE
iwlwifi0: 0x80840003 | FSEQ_TOP_INIT_VERSION
iwlwifi0: 0x003B0000 | FSEQ_CNVIO_INIT_VERSION
iwlwifi0: 0x0000A652 | FSEQ_OTP_VERSION
iwlwifi0: 0x00000003 | FSEQ_TOP_CONTENT_VERSION
iwlwifi0: 0x4552414E | FSEQ_ALIVE_TOKEN
iwlwifi0: 0x01080800 | FSEQ_CNVI_ID
iwlwifi0: 0x00400410 | FSEQ_CNVR_ID
iwlwifi0: 0x01080800 | CNVI_AUX_MISC_CHIP
iwlwifi0: 0x00400410 | CNVR_AUX_MISC_CHIP
iwlwifi0: 0x00009061 | CNVR_SCU_SD_REGS_SD_REG_DIG_DCDC_VTRIM
iwlwifi0: 0x00000061 | CNVR_SCU_SD_REGS_SD_REG_ACTIVE_VDIG_MIRROR
iwlwifi0: 0x003B0000 | FSEQ_PREV_CNVIO_INIT_VERSION
iwlwifi0: 0x00840003 | FSEQ_WIFI_FSEQ_VERSION
iwlwifi0: 0x00840003 | FSEQ_BT_FSEQ_VERSION
iwlwifi0: 0x000000E6 | FSEQ_CLASS_TP_VERSION
iwlwifi0: UMAC CURRENT PC: 0x80284cac
iwlwifi0: LMAC1 CURRENT PC: 0xd0
iwlwifi0: FW error in SYNC CMD UNKNOWN
#0 0xffffffff80e6d17b at linux_dump_stack+0x1b
#1 0xffffffff84eef096 at iwl_trans_pcie_send_hcmd+0x406
#2 0xffffffff84ecbd9a at iwl_trans_send_cmd+0x6a
#3 0xffffffff84f3414c at iwl_mvm_send_cmd_status+0x2c
#4 0xffffffff84f25eb5 at iwl_mvm_sta_rx_agg+0x285
#5 0xffffffff84efb3a8 at iwl_mvm_mac_ampdu_action+0x238
#6 0xffffffff80e5c3da at lkpi_ic_ampdu_rx_start+0x13a
#7 0xffffffff80d6561d at ht_recv_action_ba_addba_request+0x13d
#8 0xffffffff80e64599 at lkpi_iv_sta_recv_mgmt+0x19
#9 0xffffffff80d9042b at sta_input+0xc8b
#10 0xffffffff80d69a50 at ieee80211_input_mimo+0x1f0
#11 0xffffffff80e56d98 at lkpi_80211_lhw_rxq_task+0x148
#12 0xffffffff80c38d7e at taskqueue_run_locked+0x18e
#13 0xffffffff80c39f42 at taskqueue_thread_loop+0xc2
#14 0xffffffff80b843db at fork_exit+0x7b
#15 0xffffffff810d9b4e at fork_trampoline+0xe
iwlwifi0: lkpi_ic_ampdu_rx_start: mo_ampdu_action returned -5. ni 0xfffffe0199012000 rap 0xfffffe0199012d58
iwlwifi0: WRT: Collecting data: ini trigger 4 fired (delay=0ms).
iwlwifi0: Device error - SW reset
Comment 3 Mark Linimon freebsd_committer freebsd_triage 2026-08-05 12:34:57 UTC
Created attachment 273482 [details]
fix RX BA crash

^Triage: attempt to rebase patch that previously did not apply.