[net] net: airoha: enable RX_DONE interrupt for RX queue 31

netdev-bot+sashiko at kernel.org netdev-bot+sashiko at kernel.org
Wed Sep 2 08:29:31 PDT 2026


Thank you for your contribution! Sashiko AI review found 1 potential
issue(s) to consider:

Critical: 0 · High: 1 · Medium: 0 · Low: 0

- [High] Incomplete fix: the patch only adds BIT(31) to
  RX_IRQ1_BANK_PIN_MASK, so the exact defect the commit message…

--

net: airoha: enable RX_DONE interrupt for RX queue 31

This adds BIT(31) to RX_IRQ1_BANK_PIN_MASK so that RX queue 31's RX_DONE
interrupt is routed to IRQ bank 1.  The stated goal is that the queue gets
drained and its buffers returned to the page pool.

> diff --git a/drivers/net/ethernet/airoha/airoha_eth.h b/drivers/net/ethernet/airoha/airoha_eth.h
> index fa9a8edce22f..8277c1c87bb3 100644
> --- a/drivers/net/ethernet/airoha/airoha_eth.h
> +++ b/drivers/net/ethernet/airoha/airoha_eth.h
> @@ -538,7 +538,7 @@ struct airoha_wdma_info {
>  
>  /* RX queue to IRQ mapping: BIT(q) in IRQ(n) */
>  #define RX_IRQ0_BANK_PIN_MASK			0x839f
> -#define RX_IRQ1_BANK_PIN_MASK			0x7fe00000
> +#define RX_IRQ1_BANK_PIN_MASK			0xffe00000
>  #define RX_IRQ2_BANK_PIN_MASK			0x20
>  #define RX_IRQ3_BANK_PIN_MASK			0x40

[Severity: High]
Does this leave the same problem in place for the other RX rings?  After the
change the union of the four bank masks is:

  0x839f | 0xffe00000 | 0x20 | 0x40 = 0xffe083ff

so rings 0-9, 15 and 21-31 are covered, but bits 10-14 and 16-20 are still
clear in every bank mask.

Those rings are still allocated and filled, because airoha_qdma_init_rx() in
drivers/net/ethernet/airoha/airoha_eth.c gates only on RX_DONE_INT_MASK:

	if (!(RX_DONE_INT_MASK & BIT(i))) {
		/* rx-queue not binded to irq */
		continue;
	}

	err = airoha_qdma_init_rx_queue(&qdma->q_rx[i], qdma,
					RX_DSCP_NUM(i));

and in drivers/net/ethernet/airoha/airoha_regs.h RX_DONE_INT_MASK expands to
0xffffffff:

	#define RX_DONE_HIGH_OFFSET	fls(RX_DONE_HIGH_INT_MASK)
	#define RX_DONE_INT_MASK	\
		((RX_DONE_HIGH_INT_MASK << RX_DONE_HIGH_OFFSET) | RX_DONE_LOW_INT_MASK)

with RX_DONE_HIGH_INT_MASK and RX_DONE_LOW_INT_MASK both 0xffff.  So the
"rx-queue not binded to irq" comment filters nothing and all 32 rings get
programmed into hardware and filled from the page pool.

Meanwhile airoha_qdma_hw_init() only unmasks RX_DONE according to the pin
masks:

	airoha_qdma_irq_enable(&qdma->irq_banks[i], QDMA_INT_REG_IDX1,
			       INT_RX1_MASK(RX_IRQ_BANK_PIN_MASK(i)));
	airoha_qdma_irq_enable(&qdma->irq_banks[i], QDMA_INT_REG_IDX2,
			       INT_RX2_MASK(RX_IRQ_BANK_PIN_MASK(i)));

and airoha_qdma_rx_napi_poll() re-arms through the same mask:

	for (i = 0; i < ARRAY_SIZE(qdma->irq_banks); i++) {
		if (!(BIT(qid) & RX_IRQ_BANK_PIN_MASK(i)))
			continue;

Since rx_intr_mask in airoha_irq_handler() comes from the per-bank irqmask,
rings 10-14 and 16-20 are never passed to napi_schedule(), so
airoha_qdma_rx_process() never runs for them and their buffers stay pinned
from probe until airoha_qdma_cleanup_rx_queue().  Is that not exactly the
behaviour the commit message describes as a bug for ring 31?

Ring 11 stands out here, since RX_DSCP_NUM() gives it 128 descriptors, the
same as rings 2 and 15 which are mapped to bank 0:

	#define RX_DSCP_NUM(_n)			\
		((_n) ==  2 ? 128 :		\
		 (_n) == 11 ? 128 :		\
		 (_n) == 15 ? 128 :		\
		 (_n) ==  0 ? 1024 : 16)

while BIT(11) is absent from all pin masks, and the ring this patch enables
(31) uses the default 16 descriptors.

Would it make sense to give airoha_qdma_init_rx() and the pin masks a single
source of truth, either by having the masks cover every ring init_rx arms, or
by having init_rx key off RX_IRQ_BANK_PIN_MASK()?

Alternatively, if the sparse mapping is deliberate and those rings are simply
unused by the hardware configuration, does the justification given for
BIT(31) still hold?

-- 
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260830-airoha-rxdone-rxq31-v1-1-830a91503f2f%40kernel.org



More information about the linux-arm-kernel mailing list