From: benthecarman via B4 Relay <devnull+benthecarman1.gmail.com@kernel.org>
To: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Cc: Johannes Berg <johannes@sipsolutions.net>,
linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org,
benthecarman <benthecarman@live.com>
Subject: [PATCH 0/2] wifi: iwlwifi: fix legacy-rate injection outside 2.4 GHz
Date: Fri, 09 Oct 2026 21:42:21 -0500 [thread overview]
Message-ID: <20261009-next-v1-0-b370f5302d27@gmail.com> (raw)
Both op modes pass mac80211's legacy rate index for an injected frame
to the driver's rate conversion unchanged. Outside 2.4 GHz that index
points into a bitrate table starting at 6 Mbps, so every injected
legacy rate is shifted down by the four CCK rates: 12 Mbps on 5 GHz
goes out as 5.5 Mbps CCK, which nothing on that band can receive.
I found this bringing up userspace AWDL (OWL) on an AX211: the peer
heard none of our data frames until the rate was remapped. Patch 1
(mvm) was tested on that hardware; patch 2 (mld) is the same fix and
build-tested only, as I have no iwlmld device.
Testing: patch 1 was tested on an Intel AX211 (iwlmvm, firmware
89.123cf747.0) with the same change applied to Ubuntu's 7.0.0-38
kernel, injecting AWDL frames at a radiotap rate of 12 Mbps on channel
44 (5220 MHz). Before, the TX response showed status 0x83 (long retry
limit) and rate_n_flags 0x8002; after, status 0x1, no retries,
rate_n_flags 0x8102, and the peer ACKed every frame. Against
iwlwifi-next both mvm/tx.c and mld/tx.c build without warnings at W=1,
but I could not boot an iwlwifi-next kernel, and patch 2 is untested
at runtime.
The bug was found, and the patches written, with help from an AI
assistant (Claude) during that debugging session; I reviewed and
tested them as described above.
Signed-off-by: benthecarman <benthecarman@live.com>
---
benthecarman (2):
wifi: iwlwifi: mvm: Fix injected 5 GHz legacy rate
wifi: iwlwifi: mld: Fix injected 5 GHz legacy rate
drivers/net/wireless/intel/iwlwifi/mld/tx.c | 11 ++++++++++-
drivers/net/wireless/intel/iwlwifi/mvm/tx.c | 8 ++++++++
2 files changed, 18 insertions(+), 1 deletion(-)
---
base-commit: 5d017b30f502e20bfb96ba534b1c36f060a06e98
change-id: 20261009-next-da884048e667
Best regards,
--
benthecarman <benthecarman1@gmail.com>
next reply other threads:[~2026-10-10 2:42 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-10 2:42 benthecarman via B4 Relay [this message]
2026-10-10 2:42 ` [PATCH 1/2] wifi: iwlwifi: mvm: Fix injected 5 GHz legacy rate benthecarman via B4 Relay
2026-10-10 2:42 ` [PATCH 2/2] wifi: iwlwifi: mld: " benthecarman via B4 Relay
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261009-next-v1-0-b370f5302d27@gmail.com \
--to=devnull+benthecarman1.gmail.com@kernel.org \
--cc=benthecarman1@gmail.com \
--cc=benthecarman@live.com \
--cc=johannes@sipsolutions.net \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=miriam.rachel.korenblit@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®