Forwarded: [PATCH] wifi: cfg80211: defer self-managed regulatory processing to per-wiphy work

From: syzbot

Date: Wed Oct 07 2026 - 21:12:13 EST


For archival purposes, forwarding an incoming command email to
linux-kernel@xxxxxxxxxxxxxxx.

***

Subject: [PATCH] wifi: cfg80211: defer self-managed regulatory processing to per-wiphy work
Author: emmaonana18@xxxxxxxxx

#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master

reg_process_self_managed_hints() currently acquires each registered
wiphy's mutex while called with RTNL held. This can deadlock with a
concurrent path that holds a wiphy mutex and waits for RTNL.

Defer processing of individual self-managed regulatory hints to the
per-wiphy wiphy_work instead. The dispatcher, which runs with RTNL held,
only checks whether a regulatory hint is pending and queues the
corresponding work item.

The regulatory update is then processed with the wiphy mutex held and
without RTNL. This removes the RTNL -> wiphy mutex acquisition from the
synchronous regulatory-processing path.

Also start the regulatory channel-enforcement grace timer after the
self-managed regulatory update has been processed, preserving the
existing ordering between regulatory updates and channel enforcement.

Fixes: f4e72e375807 ("wifi: cfg80211: check channel list asynchronously")
Reported-by: syzbot+2ad5f42cd6ca88f0107c@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=2ad5f42cd6ca88f0107c
Signed-off-by: Omokefe Emmanuel Onanaroghene <emmaonana18@xxxxxxxxx>
---
net/wireless/core.c | 1 +
net/wireless/core.h | 1 +
net/wireless/reg.c | 37 +++++++++++++++++++++++++------------
net/wireless/reg.h | 7 +++++++
4 files changed, 34 insertions(+), 12 deletions(-)

diff --git a/net/wireless/core.c b/net/wireless/core.c
index cde3ca85494d..3dfbfb0c10f3 100644
--- a/net/wireless/core.c
+++ b/net/wireless/core.c
@@ -671,6 +671,7 @@ struct wiphy *wiphy_new_nm(const struct cfg80211_ops *ops, int sizeof_priv,
INIT_WORK(&rdev->sched_scan_res_wk, cfg80211_sched_scan_results_wk);
wiphy_work_init(&rdev->reg_check_chans_wk, reg_leave_invalid_chans_wk);
INIT_WORK(&rdev->reg_leave_nan_wk, reg_leave_invalid_nan_wk);
+ wiphy_work_init(&rdev->reg_self_managed_wk, reg_process_self_managed_hint_wk);
INIT_WORK(&rdev->propagate_radar_detect_wk,
cfg80211_propagate_radar_detect_wk);
INIT_WORK(&rdev->propagate_cac_done_wk, cfg80211_propagate_cac_done_wk);
diff --git a/net/wireless/core.h b/net/wireless/core.h
index 6138d207caf4..2b3239d0cf1f 100644
--- a/net/wireless/core.h
+++ b/net/wireless/core.h
@@ -116,6 +116,7 @@ struct cfg80211_registered_device {
struct work_struct sched_scan_res_wk;
struct wiphy_work reg_check_chans_wk;
struct work_struct reg_leave_nan_wk;
+ struct wiphy_work reg_self_managed_wk;

struct cfg80211_chan_def radar_chandef;
struct work_struct propagate_radar_detect_wk;
diff --git a/net/wireless/reg.c b/net/wireless/reg.c
index 11665e0a7efc..00244341fde1 100644
--- a/net/wireless/reg.c
+++ b/net/wireless/reg.c
@@ -3188,7 +3188,6 @@ static void reg_process_self_managed_hint(struct wiphy *wiphy)
enum nl80211_band band;
struct regulatory_request request = {};

- ASSERT_RTNL();
lockdep_assert_wiphy(wiphy);

spin_lock(&reg_requests_lock);
@@ -3219,6 +3218,14 @@ static void reg_process_self_managed_hint(struct wiphy *wiphy)
nl80211_send_wiphy_reg_change_event(&request);
}

+void reg_process_self_managed_hint_wk(struct wiphy *wiphy, struct wiphy_work *work)
+{
+ lockdep_assert_held(&wiphy->mtx);
+
+ reg_process_self_managed_hint(wiphy);
+ reg_check_channels();
+}
+
static void reg_process_self_managed_hints(void)
{
struct cfg80211_registered_device *rdev;
@@ -3226,12 +3233,17 @@ static void reg_process_self_managed_hints(void)
ASSERT_RTNL();

for_each_rdev(rdev) {
- guard(wiphy)(&rdev->wiphy);
+ bool has_hint;

- reg_process_self_managed_hint(&rdev->wiphy);
- }
+ spin_lock(&reg_requests_lock);
+ has_hint = !!rdev->requested_regd;
+ spin_unlock(&reg_requests_lock);

- reg_check_channels();
+ if (!has_hint)
+ continue;
+
+ wiphy_work_queue(&rdev->wiphy, &rdev->reg_self_managed_wk);
+ }
}

static void reg_todo(struct work_struct *work)
@@ -3618,15 +3630,10 @@ static void restore_regulatory_settings(bool reset_user, bool cached)
static bool is_wiphy_all_set_reg_flag(enum ieee80211_regulatory_flags flag)
{
struct cfg80211_registered_device *rdev;
- struct wireless_dev *wdev;

for_each_rdev(rdev) {
- guard(wiphy)(&rdev->wiphy);
-
- list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
- if (!(wdev->wiphy->regulatory_flags & flag))
- return false;
- }
+ if (!(rdev->wiphy.regulatory_flags & flag))
+ return false;
}

return true;
@@ -4144,9 +4151,15 @@ void wiphy_regulatory_register(struct wiphy *wiphy)

void wiphy_regulatory_deregister(struct wiphy *wiphy)
{
+ struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
struct wiphy *request_wiphy = NULL;
struct regulatory_request *lr;

+ spin_lock(&reg_requests_lock);
+ kfree(rdev->requested_regd);
+ rdev->requested_regd = NULL;
+ spin_unlock(&reg_requests_lock);
+
lr = get_last_request();

if (!reg_dev_ignore_cell_hint(wiphy))
diff --git a/net/wireless/reg.h b/net/wireless/reg.h
index c587079ead8f..4cfac05c6178 100644
--- a/net/wireless/reg.h
+++ b/net/wireless/reg.h
@@ -194,6 +194,13 @@ void reg_leave_invalid_chans_wk(struct wiphy *wiphy, struct wiphy_work *work);
*/
void reg_leave_invalid_nan_wk(struct work_struct *work);

+/**
+ * reg_process_self_managed_hint_wk - process self-managed hint for a wiphy
+ * @wiphy: the wiphy to process
+ * @work: the work struct
+ */
+void reg_process_self_managed_hint_wk(struct wiphy *wiphy, struct wiphy_work *work);
+
extern const u8 shipped_regdb_certs[];
extern unsigned int shipped_regdb_certs_len;
extern const u8 extra_regdb_certs[];
--
2.43.0