[PATCH 2/4] wifi: mt76: mt7925: unwind link BSS add failures
From: Jiale Yao
Date: Thu Sep 24 2026 - 09:26:30 EST
mac80211 does not call remove_interface() after add_interface() fails, so
the driver must undo any state it published before returning an error.
mt7925_mac_link_bss_add() reserves vif and OMAC bits and publishes the
station WCID before asking the firmware to add the device. If that command
fails, the function currently returns with those resources still installed.
The WCID pointer then refers into vif private data that mac80211 can free,
and the mask bits remain permanently allocated.
Use the existing link BSS removal helper to undo the published WCID, mask
bits, and WCID resources when the firmware add command fails.
Commit 2fb6480c52f6 ("wifi: mt76: mt7915: unwind state on add_interface
failure") fixed the same failure-unwind issue in mt7915.
Fixes: c948b5da6bbe ("wifi: mt76: mt7925: add Mediatek Wi-Fi7 driver for mt7925 chips")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>
---
drivers/net/wireless/mediatek/mt76/mt7925/main.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/main.c b/drivers/net/wireless/mediatek/mt76/mt7925/main.c
index 5993b31e1aae..25ad3bbdcd2c 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7925/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/main.c
@@ -439,8 +439,10 @@ static int mt7925_mac_link_bss_add(struct mt792x_dev *dev,
ret = mt76_connac_mcu_uni_add_dev(&dev->mphy, link_conf, &mconf->mt76,
&mlink->wcid, true);
- if (ret)
+ if (ret) {
+ mt792x_mac_link_bss_remove(dev, mconf, mlink);
goto out;
+ }
if (vif->txq) {
mtxq = (struct mt76_txq *)vif->txq->drv_priv;
--
2.34.1