[PATCH ath-next v4 2/8] wifi: ath9k_htc: fix the byte count of a full RMW buffer flush
From: Nerijus Bendžiūnas
Date: Wed Sep 16 2026 - 13:42:35 EST
ath9k_reg_rmw_buffer() sizes a full-buffer flush with
sizeof(struct register_write), 8 bytes, instead of
sizeof(struct register_rmw), 12 bytes. ar9271_hw_pa_cal() queues
exactly 15 read-modify-writes, so the AR9271 PA calibration has been
losing its last five writes since the buffer was added.
The corrected command is 192 bytes, three full 64-byte USB packets,
and the firmware ends a command only on a short packet, so the device
stops answering WMI on the first interface open. Send the whole buffer
on a full flush and cap it at 14 entries; 15 is the only count within
the buffer's reach that fills whole packets.
Fixes: 8badb50cfab6 ("ath9k_htc: add new WMI_REG_RMW_CMDID command")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Nerijus Bendžiūnas <nerijus.bendziunas@xxxxxxxxx>
---
drivers/net/wireless/ath/ath9k/htc_drv_init.c | 2 +-
drivers/net/wireless/ath/ath9k/wmi.h | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/ath/ath9k/htc_drv_init.c b/drivers/net/wireless/ath/ath9k/htc_drv_init.c
index 3798d3375158..2d9c14006972 100644
--- a/drivers/net/wireless/ath/ath9k/htc_drv_init.c
+++ b/drivers/net/wireless/ath/ath9k/htc_drv_init.c
@@ -408,7 +408,7 @@ static void ath9k_reg_rmw_buffer(void *hw_priv,
if (priv->wmi->multi_rmw_idx == MAX_RMW_CMD_NUMBER) {
r = ath9k_wmi_cmd(priv->wmi, WMI_REG_RMW_CMDID,
(u8 *) &priv->wmi->multi_rmw,
- sizeof(struct register_write) * priv->wmi->multi_rmw_idx,
+ sizeof(priv->wmi->multi_rmw),
(u8 *) &rsp_status, sizeof(rsp_status),
100);
if (unlikely(r)) {
diff --git a/drivers/net/wireless/ath/ath9k/wmi.h b/drivers/net/wireless/ath/ath9k/wmi.h
index 5c3b710b8f31..f9c0fe54a884 100644
--- a/drivers/net/wireless/ath/ath9k/wmi.h
+++ b/drivers/net/wireless/ath/ath9k/wmi.h
@@ -126,7 +126,7 @@ enum wmi_event_id {
};
#define MAX_CMD_NUMBER 62
-#define MAX_RMW_CMD_NUMBER 15
+#define MAX_RMW_CMD_NUMBER 14
struct register_write {
__be32 reg;
--
2.55.0