git: f616f8a83ba1 - main - iwx: fix kernel panic on module unload with assertions enabled

From: Adrian Chadd <adrian_at_FreeBSD.org>
Date: Sun, 13 Sep 2026 02:57:27 UTC
The branch main has been updated by adrian:

URL: https://cgit.FreeBSD.org/src/commit/?id=f616f8a83ba1bf8aa41003837c11a0f0955efed8

commit f616f8a83ba1bf8aa41003837c11a0f0955efed8
Author:     Andriy Voskoboinyk <avos@FreeBSD.org>
AuthorDate: 2026-09-13 02:26:53 +0000
Commit:     Adrian Chadd <adrian@FreeBSD.org>
CommitDate: 2026-09-13 02:26:53 +0000

    iwx: fix kernel panic on module unload with assertions enabled
    
    When interface is up and running 'kldunload if_iwx' stops the device and executes RUN -> INIT state transition.
    Since the device is already stopped iwx_run_stop fails to stop the device again and returns non-zero exit code from iv_newstate callback which triggers 'INIT state change failed' assertion.
    
    I reused IWX_FLAG_SHUTDOWN flag to:
    a) set it in iwx_detach
    b) check it in iwx_newstate_sub - when it is set all custom state transition logic is skipped
    
    Accidentally found while experimenting with iwlwifi / iwx drivers
    
    Reviewed by:    adrian
    Differential Revision:  https://reviews.freebsd.org/D59624
---
 sys/dev/iwx/if_iwx.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/sys/dev/iwx/if_iwx.c b/sys/dev/iwx/if_iwx.c
index 372fa440466c..ee12e330de92 100644
--- a/sys/dev/iwx/if_iwx.c
+++ b/sys/dev/iwx/if_iwx.c
@@ -8085,6 +8085,9 @@ iwx_newstate_sub(struct ieee80211vap *vap, enum ieee80211_state nstate)
 	int err = 0;
 
 	IWX_LOCK(sc);
+	if (sc->sc_flags & IWX_FLAG_SHUTDOWN) {
+		goto out;
+	}
 
 	if (nstate <= ostate || nstate > IEEE80211_S_RUN) {
 		switch (ostate) {
@@ -10679,6 +10682,7 @@ iwx_detach(device_t dev)
 	int txq_i;
 
 	iwx_stop_device(sc);
+	sc->sc_flags |= IWX_FLAG_SHUTDOWN;
 
 	taskqueue_drain_all(sc->sc_tq);
 	taskqueue_free(sc->sc_tq);