Commit 7825de3f75d1 for kernel

commit 7825de3f75d184612d77655669a04ea0da252c17
Author: Devin Wittmayer <lucid_duck@justthetip.ca>
Date:   Tue Aug 25 11:17:12 2026 -0700

    wifi: mt76: mt792x: fix NULL dereference in ACPI SAR init during probe

    Some laptops carry a MediaTek power table in their firmware, and the
    driver reads it to set a transmit limit for each frequency range.  It
    only fills in the ranges themselves when it registers the device.

    The startup step that does this existed already, but it never programmed
    anything.  Two recent commits made it run a regulatory update instead,
    which sets the limits on the way through, long before registration.

    As a result, on a machine that has the table the driver reads through an
    empty pointer and the interface never appears:

      BUG: kernel NULL pointer dereference, address: 0000000000000004
      RIP: 0010:mt792x_init_acpi_sar_power
      Call Trace:
       mt7921_set_tx_sar_pwr
       mt7921_mcu_regd_update
       mt7921_regd_update
       mt7921_run_firmware
       mt7921e_mcu_init
       mt7921_init_work

    Skip it when the ranges are missing. They are applied again once the
    device is up, which is where they came from before.

    Reported-by: Klara Modin <klarasmodin@gmail.com>
    Closes: https://lore.kernel.org/linux-wireless/aoyxqHYvSuaBeubf@soda.int.kasm.eu/
    Fixes: 9b80bd9cab40 ("wifi: mt76: mt7921: add regulatory wiphy self manager support")
    Fixes: e9f3f1cc133f ("wifi: mt76: mt7925: add regulatory wiphy self manager support")
    Signed-off-by: Devin Wittmayer <lucid_duck@justthetip.ca>
    Tested-by: David Gow <david@davidgow.net>
    Tested-by: Klara Modin <klarasmodin@gmail.com>
    Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>

diff --git a/drivers/net/wireless/mediatek/mt76/mt792x_acpi_sar.c b/drivers/net/wireless/mediatek/mt76/mt792x_acpi_sar.c
index 946dd7956e4a..b468051fbe68 100644
--- a/drivers/net/wireless/mediatek/mt76/mt792x_acpi_sar.c
+++ b/drivers/net/wireless/mediatek/mt76/mt792x_acpi_sar.c
@@ -323,7 +323,8 @@ int mt792x_init_acpi_sar_power(struct mt792x_phy *phy, bool set_default)
 	const struct cfg80211_sar_capa *capa = phy->mt76->hw->wiphy->sar_capa;
 	int i;

-	if (!phy->acpisar || !((struct mt792x_acpi_sar *)phy->acpisar)->dyn)
+	if (!capa || !phy->acpisar ||
+	    !((struct mt792x_acpi_sar *)phy->acpisar)->dyn)
 		return 0;

 	/* When ACPI SAR enabled in HW, we should apply rules for .frp