mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Patrick Lawler <patricktlawler@gmail.com>
To: Jeff Johnson <jjohnson@kernel.org>
Cc: linux-wireless@vger.kernel.org, ath11k@lists.infradead.org,
	linux-kernel@vger.kernel.org,
	Patrick Lawler <patricktlawler@gmail.com>,
	stable@vger.kernel.org
Subject: [PATCH ath-next] wifi: ath11k: require unique station addresses per radio
Date: Thu,  1 Oct 2026 12:41:39 -0400	[thread overview]
Message-ID: <20261001164139.370144-1-patricktlawler@gmail.com> (raw)

Commit 1e744bf218b5 ("ath11k: fix duplication peer create on same
radio") made ath11k_peer_create() refuse a peer whose address already
exists on the same radio, because the firmware asserts when asked to
create it. Commit d673cb6fe6c0 ("wifi: ath11k: fix peer
addition/deletion error on sta band migration") reduced that check to
the same vdev, so a second peer with the same address on another vdev
of the same radio is sent to the firmware again.

This happens with several BSSes on one radio: hostapd adds a station
to the driver when it receives an Authentication frame and only
removes it from the other BSSes once it associates. On an IPQ9574 with
four BSSes on the 2.4 GHz radio, Tuya Wi-Fi devices trigger it while
they are being set up: the firmware asserts, ath11k logs "failed to
find peer ... after creation" and every following WMI command fails
with -ESHUTDOWN. Any station in range can do the same with
Authentication frames from one address to two BSSes of the radio.

ath11k registers one ieee80211_hw per radio, so set
IEEE80211_HW_NEEDS_UNIQUE_STA_ADDR: mac80211 then refuses the second
station with -ENOTUNIQ before the driver or the firmware is involved,
and hostapd rejects that authentication. A client moving between BSSes
of the same radio has to leave the first one before it can join the
second, as before d673cb6fe6c0 and as with ath12k. Stations on another
radio, the case d673cb6fe6c0 was about, are not affected.

Tested-on: IPQ9574 hw1.0 AHB WLAN.HK.2.9.0.1-01977-QCAHKSWPL_SILICONZ-1

Fixes: d673cb6fe6c0 ("wifi: ath11k: fix peer addition/deletion error on sta band migration")
Cc: stable@vger.kernel.org
Signed-off-by: Patrick Lawler <patricktlawler@gmail.com>
---
IPQ9574 support is not in mainline ath11k yet; this was tested with
OpenWrt's ath11k (backports 7.2) plus its out-of-tree IPQ9574 patches.
With the patch, re-adding the device that had crashed the radio gave
29 refused authentications and no firmware assert, and the device
joined its intended BSS 39 s later. The cross-radio case from
d673cb6fe6c0 could not be tested here: IPQ9574 has one ath11k radio.

I used the mac80211 flag rather than restoring the driver check from
1e744bf218b5 because it refuses the station before any driver or
firmware state is touched. I can send the driver check instead, or as
well, if that is preferred.

 drivers/net/wireless/ath/ath11k/mac.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/net/wireless/ath/ath11k/mac.c b/drivers/net/wireless/ath/ath11k/mac.c
index ae91b57c8..a7574803e 100644
--- a/drivers/net/wireless/ath/ath11k/mac.c
+++ b/drivers/net/wireless/ath/ath11k/mac.c
@@ -10518,6 +10518,7 @@ static int __ath11k_mac_register(struct ath11k *ar)
 	ieee80211_hw_set(ar->hw, QUEUE_CONTROL);
 	ieee80211_hw_set(ar->hw, SUPPORTS_TX_FRAG);
 	ieee80211_hw_set(ar->hw, REPORTS_LOW_ACK);
+	ieee80211_hw_set(ar->hw, NEEDS_UNIQUE_STA_ADDR);
 
 	if (ath11k_frame_mode == ATH11K_HW_TXRX_ETHERNET) {
 		ieee80211_hw_set(ar->hw, SUPPORTS_TX_ENCAP_OFFLOAD);
-- 
2.55.0


                 reply	other threads:[~2026-10-01 16:42 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261001164139.370144-1-patricktlawler@gmail.com \
    --to=patricktlawler@gmail.com \
    --cc=ath11k@lists.infradead.org \
    --cc=jjohnson@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-wireless@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®