[PATCH rtw-next v4 0/4] wifi: rtw88: sdio: Fix unhandled RX request interrupt storm

From: Alastair D'Silva

Date: Mon Oct 05 2026 - 04:49:11 EST


On 3081-based SDIO chips (e.g. RTL8821CS, RTL8822CS), hardware does not
automatically clear the REG_SDIO_HISR_RX_REQUEST status bit when the RX
FIFO is empty. Masking this bit out in software before writing back to
HISR prevented it from ever being acknowledged in hardware, trapping the
CPU core in an infinite interrupt storm that locked up the system upon
receiving network traffic.

This series fixes the interrupt storm on 3081 chips and addresses
related SDIO lifecycle and error handling issues:

- Patch 1 returns error codes from rtw_sdio_rxfifo_recv() on allocation
or read failures so the caller stops immediately instead of burning
through the loop budget.
- Patch 2 tracks operational state via rtwsdio->running and cancels
the TX worker synchronously on stop, preventing work items from
accessing powered-down hardware.
- Patch 3 fixes the interrupt storm by splitting
rtw_sdio_handle_interrupt() into 8051 and 3081 paths. On 3081,
interrupts are masked via HIMR, acknowledged via W1C writeback,
serviced, and re-enabled.
- Patch 4 refactors rtw_sdio_rx_isr() into separate 8051 and 3081 variants
to clarify the differences in register width and HISR handling without
any logic changes.

Hardware Validation:
Validated on an Allwinner H618 board (Mellow Fly-C5) with RTL8821CS SDIO:
- Bidirectional TCP throughput: 36.5 Mbps RX / 36.4 Mbps TX (over wlan0).
- Repeated interface down/up cycles verified clean with zero storms or
hangs.

Differences in v4:
- Split pre-existing lifecycle and error handling issues into separate
patches (Patches 1 and 2) prior to the storm fix (per Luka Gejak).
- Guard HIMR re-enabling with rtwsdio->running in the 3081 handler.
- Significantly reduced and streamlined commit messages across the series
(per Ping-Ke Shih).
- Clarified in Patch 4 that it is a refactoring without logic changes,
highlighting register width and HISR behavior (per Ping-Ke Shih).
- Tagged with rtw-next in subject prefix for NIPA testing.

Alastair D'Silva (4):
wifi: rtw88: sdio: Handle allocation and read errors in
rtw_sdio_rxfifo_recv
wifi: rtw88: sdio: Track running state and cancel TX worker on stop
wifi: rtw88: sdio: Fix unhandled RX request interrupt storm
wifi: rtw88: sdio: Split rtw_sdio_rx_isr into 8051 and 3081 variants

drivers/net/wireless/realtek/rtw88/sdio.c | 128 +++++++++++++++-------
drivers/net/wireless/realtek/rtw88/sdio.h | 1 +
2 files changed, 91 insertions(+), 38 deletions(-)

--
2.53.0