Re: [PATCH v2] wifi: rtw88: sdio: Fix unhandled RX request interrupt storm

From: Luka Gejak

Date: Wed Sep 30 2026 - 06:10:16 EST


Hi Alastair,

This breaks the drain loop on the 8051 parts. The early write clears
REG_SDIO_HISR_RX_REQUEST before rtw_sdio_rx_isr() runs, but the 8051 branch
of the loop uses that bit to decide whether another request is pending:

> + rtw_sdio_disable_interrupt(rtwdev);
> + rtw_write32(rtwdev, REG_SDIO_HISR, hisr);
> [...]
> + if (hisr & REG_SDIO_HISR_RX_REQUEST)
> rtw_sdio_rx_isr(rtwdev);

if (rtw_chip_wcpu_8051(rtwdev)) {
hisr = rtw_read32(rtwdev, REG_SDIO_HISR);
} else {
hisr = REG_SDIO_HISR_RX_REQUEST;
}
} while (total_rx_bytes < SZ_64K && hisr & REG_SDIO_HISR_RX_REQUEST);

In the v1 thread Ping-Ke relayed that the hardware clears the bit once the
RX buffer is empty, and that a software clear means no new interrupt unless
a new packet arrives. So the first re-read after the write returns 0, the
loop stops after one request, and the rest of the FIFO waits for the next
packet.

The 8821CS cannot show this, since 3081 parts never read HISR there.
RTL8723CS, RTL8723DS and the RTL8723BS once its glue lands are the 8051
SDIO parts, so please run the test on one of those, or leave RX_REQUEST out
of the early write and let the hardware drop it.

This also needs a rebase for rtw-next. The 8723BS mask sits between this
block and the old write:

if (rtw_is_8723bs(rtwdev))
hisr &= RTW_SDIO_HISR_CLEAR_MASK;

rtw_write32(rtwdev, REG_SDIO_HISR, hisr);

Moving the write up as posted puts the raw value back, undefined bits
included, which is the resume storm on 8723BS that the mask exists to
avoid.

One smaller thing, the early write also consumes anything already queued
when the handler starts, so what the 64K budget leaves behind waits for the
next packet too, on 3081 as well.

Best regards,
Luka Gejak