openwrt / openwrt/mt76

mt76x2u: NULL pointer dereference in mt76u_tx_queue_skb() after MCU init failure on Xbox Wireless Adapter (045e:02fe)

Open
#1,121 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C
Stars
888
Forks
436
PR merge metrics
No merged PRs in 30d

Description

Summary

The Xbox Wireless Adapter is in the mt76x2u device ID table, but its MCU sometimes won't fully complete init after waking up from sleep (error: MCU resp evt:9 seq:1-0, similar failure to https://github.com/openwrt/mt76/issues/200).
Contrary to the #200 issue, this time the error is followed by a kernel panic, as the driver tries to dereference a NULL pointer.

This panic does not occur every time, but if it occurs it's almost always after waking from sleep, ~0.6s after the MCU error.

Related Mediatek hardware

  • USB device: Microsoft Xbox Wireless Adapter, USB ID [045e:02fe]

Platform on which the panic has occurred

  • OS: CachyOS
  • Kernel: 7.1.8-1-cachyos
  • CPU: Intel Core Ultra 7 265k
  • Motherboard: Gigabyte Z890 GAMING X WIFI7
  • BIOS version: F17f
  • GPU: AMD RX 9070 XT
  • RAM: 64GB DDR5

Note: the kernel is tainted G OE by vboxdrv and hid_xpadneo. Neither appears in the call trace; mt76, mt76_usb and mt76x2u are all in-tree.

Steps to reproduce

  1. Plug in the Xbox Wireless Adapter (claimed by mt76x2u via its ID table).
  2. Suspend to RAM (/sys/power/mem_sleep = deep).
  3. Resume.
  4. If it doesn't trigger a kernel panic, repeat steps 1-3 (around 10-15% success rate). Increasing the sleep time duration increases the chances. "Weird" wake up (like self-wake, ESD discharge wake or a misbehaving USB device wake) also increases the chances.

Logs

ramoops log
Oops#1 Part1
<6>[19620.286307] hid-generic 0003:3434:D028.001B: hiddev99,hidraw5: USB HID v1.10 Device [Keychron Keychron Ultra-Link 8K] on usb-0000:80:14.0-4.2/input3
<6>[19620.286536] hid-generic 0003:3434:D028.001C: hiddev100,hidraw6: USB HID v1.10 Device [Keychron Keychron Ultra-Link 8K] on usb-0000:80:14.0-4.2/input4
<6>[19620.364119] Bluetooth: hci0: Device setup in 467836 usecs
<4>[19620.364127] Bluetooth: hci0: HCI Enhanced Setup Synchronous Connection command is advertised, but not supported.
<6>[19620.448755] Bluetooth: hci0: AOSP extensions version v1.00
<6>[19620.448776] Bluetooth: hci0: AOSP quality report is supported
<6>[19620.448904] Bluetooth: MGMT ver 1.23
<6>[19620.836836] r8169 0000:82:00.0 enp130s0: Link is Down
<6>[19624.330489] r8169 0000:82:00.0 enp130s0: Link is Up - 2.5Gbps/Full - flow control off
<4>[19629.199293] [UFW BLOCK] IN=enp130s0 OUT= MAC=01:00:5e:00:00:01:a0:ad:9f:e8:52:10:08:00 SRC=0.0.0.0 DST=224.0.0.1 LEN=32 TOS=0x00 PREC=0xC0 TTL=1 ID=0 DF PROTO=2 
<4>[19631.189664] [UFW BLOCK] IN=enp130s0 OUT= MAC=01:00:5e:00:00:01:a0:ad:9f:e8:52:10:08:00 SRC=0.0.0.0 DST=224.0.0.1 LEN=32 TOS=0x00 PREC=0xC0 TTL=1 ID=0 DF PROTO=2 
<3>[19633.536445] mt76x2u 3-10:1.0: error: MCU resp evt:9 seq:1-0
<3>[19634.106839] Oops: general protection fault, kernel NULL pointer dereference 0x88: 0000 [#1] SMP NOPTI
<3>[19634.106874] CPU: 0 UID: 0 PID: 1266 Comm: mt76-tx phy1 Tainted: G           OE       7.1.8-1-cachyos #1 PREEMPT(full)  b4c0ec852ba11d95ca3c3dad93b04199835241c7
<3>[19634.106894] Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE
<3>[19634.106895] Hardware name: Gigabyte Technology Co., Ltd. Z890 GAMING X WIFI7/Z890 GAMING X WIFI7, BIOS F17f 09/09/2025
<3>[19634.106896] RIP: 0010:mt76u_tx_queue_skb+0xbe/0x1f0 [mt76_usb]
<3>[19634.106899] Code: ea 4c 89 e9 2e 2e 2e 41 ff d3 85 c0 78 68 4c 8b bc 24 00 02 00 00 48 8b 43 10 4b 8d 0c b6 4d 89 f1 4c 8b 74 c8 08 41 8b 47 70 <41> 89 86 88 00 00 00 41 80 bc 24 08 6a 00 00 00 4d 89 e5 74 3f 4d
<3>[19634.106900] RSP: 0018:ffffd185c2cb3ba8 EFLAGS: 00010246
<3>[19634.106902] RAX: 00000000000000fc RBX: ffff8f1efcccf478 RCX: 0000000000000226
<3>[19634.106902] RDX: 0000000000000005 RSI: 0000000000000000 RDI: ffff8f1ecf1de17e
<3>[19634.106903] RBP: 0000000000000000 R08: 0000000000000000 R09: 000000000000006e
<3>[19634.106904] R10: 0000000000000100 R11: ffffffffc3620a90 R12: ffff8f1f1d2e2120
<3>[19634.106904] R13: ffff8f1f29176898 R14: 0000000000000000 R15: ffff8f22369c3a00
<3>[19634.106905] FS:  0000000000000000(0000) GS:ffff8f2e7f885000(0000) knlGS:0000000000000000
<3>[19634.106906] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
<3>[19634.106906] CR2: 00007f4e4bbd2000 CR3: 0000000e16212003 CR4: 0000000008f72ef0
<3>[19634.106907] PKRU: 55555554
<3>[19634.106908] Call Trace:
<3>[19634.106909]  <TASK>
<3>[19634.106912]  mt76_txq_schedule_pending_wcid+0x207/0x2c0 [mt76 b6cf32f20df4e8016f6676bf6e69b78ba6bdd609]
<3>[19634.106918]  mt76_txq_schedule_pending+0x146/0x1c0 [mt76 b6cf32f20df4e8016f6676bf6e69b78ba6bdd609]
<3>[19634.106922]  ? mt76_txq_schedule_pending+0x4e/0x1c0 [mt76 b6cf32f20df4e8016f6676bf6e69b78ba6bdd609]
<3>[19634.106925]  mt76_tx_worker+0x27/0x180 [mt76 b6cf32f20df4e8016f6676bf6e69b78ba6bdd609]
<3>[19634.106928]  __mt76_worker_fn+0x6d/0xb0 [mt76 b6cf32f20df4e8016f6676bf6e69b78ba6bdd609]
<3>[19634.106931]  ? __pfx___mt76_worker_fn+0x10/0x10 [mt76 b6cf32f20df4e8016f6676bf6e69b78ba6bdd609]
<3>[19634.106934]  kthread+0xfb/0x120
<3>[19634.106937]  ? __pfx_kthread+0x10/0x10
<3>[19634.106938]  ret_from_fork+0xec/0x2a0
<3>[19634.106940]  ? __pfx_kthread+0x10/0x10
<3>[19634.106940]  ret_from_fork_asm+0x1a/0x30
<3>[19634.106942]  </TASK>
<3>[19634.106943] Modules linked in: xpad hid_xpadneo(OE) ff_memless uhid snd_seq_dummy snd_hrtimer rfcomm snd_seq xt_CHECKSUM xt_MASQUERADE nft_chain_nat nf_nat bridge stp llc algif_hash algif_skcipher af_alg bnep vfat fat mt76x2u mt76x2_common mt76x02_usb mt76x02_lib mt76_usb snd_sof_pci_intel_mtl snd_sof_intel_hda_generic soundwire_intel snd_hda_codec_intelhdmi snd_sof_intel_hda_sdw_bpt snd_sof_intel_hda_common snd_soc_hdac_hda snd_sof_intel_hda snd_sof_intel_hda_mlink soundwire_cadence snd_sof_pci snd_hda_codec_alc662 snd_sof_xtensa_dsp snd_hda_codec_realtek_lib snd_sof snd_hda_codec_generic snd_sof_utils snd_hda_ext_core snd_soc_acpi_intel_match snd_soc_acpi_intel_sdca_quirks soundwire_generic_allocation snd_soc_sdw_utils intel_rapl_msr snd_hda_codec_atihdmi intel_uncore_frequency snd_soc_acpi intel_uncore_frequency_common snd_hda_codec_hdmi soundwire_bus mt7925e intel_pmc_core mt7925_common snd_soc_sdca x86_pkg_temp_thermal processor_thermal_device_pci snd_hda_intel mt792x_lib intel_powerclamp snd_usb_audio coretemp
<3>[19634.106962]  processor_thermal_device snd_soc_core mt76_connac_lib snd_hda_codec processor_thermal_power_floor snd_usbmidi_lib aesni_intel mt76 snd_hda_core processor_thermal_wt_hint ac97_bus snd_ump gf128mul processor_thermal_wt_req snd_intel_dspcfg rapl r8169 snd_pcm_dmaengine snd_rawmidi processor_thermal_rfim snd_intel_sdw_acpi intel_cstate mac80211 mei_gsc_proxy realtek spd5118 snd_hwdep snd_seq_device snd_compress processor_thermal_mbox phy_package btusb platform_temperature_control intel_uncore snd_pcm processor_thermal_rapl mdio_devres btmtk int3403_thermal cfg80211 gigabyte_wmi snd_timer intel_rapl_common pcspkr spi_nor pmt_telemetry mei_me btbcm i2c_i801 hid_apple processor_thermal_soc_slider libphy libarc4 int3400_thermal pmt_discovery snd btintel wmi_bmof intel_hid thunderbolt mc i2c_smbus acpi_thermal_rel intel_pmc_ssram_telemetry crc8 int340x_thermal_zone aead pinctrl_meteorlake intel_vpu pmt_class mei cdc_acm soundcore mdio_bus sparse_keymap apple_mfi_fastcharge acpi_tad mousedev btrtl 8250_dw mtd usblp
<3>[19634.106983]  pinctrl_meteorpoint acpi_pad joydev i2c_mux bluetooth rfkill mac_hid ip6t_REJECT nf_reject_ipv6 xt_hl ip6t_rt ipt_REJECT nf_reject_ipv4 xt_LOG nf_log_syslog xt_comment xt_multiport nft_limit xt_limit xt_addrtype xt_tcpudp xt_conntrack nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 nft_compat x_tables nf_tables nfnetlink vboxnetadp(OE) vboxnetflt(OE) vboxdrv(OE) ccp kvm_intel ramoops reed_solomon kvm dm_mod irqbypass pkcs8_key_parser ntsync i2c_dev crypto_user zram 842_decompress 842_compress lz4hc_compress lz4_compress xe drm_gpuvm drm_gpusvm_helper amdgpu i915 drm_panel_backlight_quirks drm_suballoc_helper spi_pxa2xx_platform drm_exec dw_dmac gpu_sched intel_gtt spi_pxa2xx_core amdxcp drm_buddy drm_ttm_helper i2c_algo_bit nvme ttm nvme_core drm_display_helper nvme_keyring intel_lpss_pci spi_intel_pci intel_lpss nvme_auth intel_vsec video cec spi_intel idma64 wmi
<4>[19634.107006] ---[ end trace 0000000000000000 ]---

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing mt76u_tx_queue_skb() from the reported mt76_tx_worker call path, then inspect how mt76x2u handles the MCU initialization failure after resume. Reproduce with the Xbox Wireless Adapter across suspend and resume cycles, and verify that an MCU failure no longer leads to a NULL pointer dereference or kernel panic.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, linux
Domain
networking, operating-systems
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.