* [PATCH 0/2] wifi: iwlwifi: fix legacy-rate injection outside 2.4 GHz
@ 2026-10-10 2:42 benthecarman via B4 Relay
2026-10-10 2:42 ` [PATCH 1/2] wifi: iwlwifi: mvm: Fix injected 5 GHz legacy rate benthecarman via B4 Relay
2026-10-10 2:42 ` [PATCH 2/2] wifi: iwlwifi: mld: " benthecarman via B4 Relay
0 siblings, 2 replies; 3+ messages in thread
From: benthecarman via B4 Relay @ 2026-10-10 2:42 UTC (permalink / raw)
To: Miri Korenblit; +Cc: Johannes Berg, linux-wireless, linux-kernel, benthecarman
Both op modes pass mac80211's legacy rate index for an injected frame
to the driver's rate conversion unchanged. Outside 2.4 GHz that index
points into a bitrate table starting at 6 Mbps, so every injected
legacy rate is shifted down by the four CCK rates: 12 Mbps on 5 GHz
goes out as 5.5 Mbps CCK, which nothing on that band can receive.
I found this bringing up userspace AWDL (OWL) on an AX211: the peer
heard none of our data frames until the rate was remapped. Patch 1
(mvm) was tested on that hardware; patch 2 (mld) is the same fix and
build-tested only, as I have no iwlmld device.
Testing: patch 1 was tested on an Intel AX211 (iwlmvm, firmware
89.123cf747.0) with the same change applied to Ubuntu's 7.0.0-38
kernel, injecting AWDL frames at a radiotap rate of 12 Mbps on channel
44 (5220 MHz). Before, the TX response showed status 0x83 (long retry
limit) and rate_n_flags 0x8002; after, status 0x1, no retries,
rate_n_flags 0x8102, and the peer ACKed every frame. Against
iwlwifi-next both mvm/tx.c and mld/tx.c build without warnings at W=1,
but I could not boot an iwlwifi-next kernel, and patch 2 is untested
at runtime.
The bug was found, and the patches written, with help from an AI
assistant (Claude) during that debugging session; I reviewed and
tested them as described above.
Signed-off-by: benthecarman <benthecarman@live.com>
---
benthecarman (2):
wifi: iwlwifi: mvm: Fix injected 5 GHz legacy rate
wifi: iwlwifi: mld: Fix injected 5 GHz legacy rate
drivers/net/wireless/intel/iwlwifi/mld/tx.c | 11 ++++++++++-
drivers/net/wireless/intel/iwlwifi/mvm/tx.c | 8 ++++++++
2 files changed, 18 insertions(+), 1 deletion(-)
---
base-commit: 5d017b30f502e20bfb96ba534b1c36f060a06e98
change-id: 20261009-next-da884048e667
Best regards,
--
benthecarman <benthecarman1@gmail.com>
^ permalink raw reply [flat|nested] 3+ messages in thread* [PATCH 1/2] wifi: iwlwifi: mvm: Fix injected 5 GHz legacy rate
2026-10-10 2:42 [PATCH 0/2] wifi: iwlwifi: fix legacy-rate injection outside 2.4 GHz benthecarman via B4 Relay
@ 2026-10-10 2:42 ` benthecarman via B4 Relay
2026-10-10 2:42 ` [PATCH 2/2] wifi: iwlwifi: mld: " benthecarman via B4 Relay
1 sibling, 0 replies; 3+ messages in thread
From: benthecarman via B4 Relay @ 2026-10-10 2:42 UTC (permalink / raw)
To: Miri Korenblit; +Cc: Johannes Berg, linux-wireless, linux-kernel, benthecarman
From: benthecarman <benthecarman@live.com>
iwl_mvm_get_inject_tx_rate() passes the legacy rate index from
mac80211 straight to iwl_mvm_convert_rate_idx(). That index points
into the band's own bitrate table, which outside 2.4 GHz starts at
6 Mbps (iwl_cfg80211_rates[RATES_52_OFFS]), while the driver's indices
start with the four CCK rates. A frame injected at 12 Mbps on 5 or
6 GHz, index 2, therefore goes out as 5.5 Mbps CCK, which no receiver
on those bands can decode.
The non-injected path, iwl_mvm_get_tx_rate(), already adds
IWL_FIRST_OFDM_RATE outside 2.4 GHz. Do the same for injection.
Seen on an AX211 injecting data frames at 12 Mbps on channel 44: the
TX response showed rate_n_flags 0x8002 (CCK) and the peer never ACKed.
With this change it shows 0x8102 (12 Mbps OFDM) and every unicast
frame is ACKed on the first attempt.
Fixes: b99c4607973a ("wifi: iwlwifi: mvm: refactor TX rate handling")
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: benthecarman <benthecarman@live.com>
---
drivers/net/wireless/intel/iwlwifi/mvm/tx.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/tx.c b/drivers/net/wireless/intel/iwlwifi/mvm/tx.c
index d3c2fe830..fb7e48aa3 100644
--- a/drivers/net/wireless/intel/iwlwifi/mvm/tx.c
+++ b/drivers/net/wireless/intel/iwlwifi/mvm/tx.c
@@ -331,6 +331,14 @@ static u32 iwl_mvm_get_inject_tx_rate(struct iwl_mvm *mvm,
} else {
int rate_idx = info->control.rates[0].idx;
+ /*
+ * mac80211 indexes the band's bitrates, which start at
+ * 6 Mbps outside 2.4 GHz; remap to our rate indices as
+ * iwl_mvm_get_tx_rate() does.
+ */
+ if (info->band != NL80211_BAND_2GHZ)
+ rate_idx += IWL_FIRST_OFDM_RATE;
+
result = iwl_mvm_convert_rate_idx(mvm, info, rate_idx);
}
--
2.55.0
^ permalink raw reply [flat|nested] 3+ messages in thread* [PATCH 2/2] wifi: iwlwifi: mld: Fix injected 5 GHz legacy rate
2026-10-10 2:42 [PATCH 0/2] wifi: iwlwifi: fix legacy-rate injection outside 2.4 GHz benthecarman via B4 Relay
2026-10-10 2:42 ` [PATCH 1/2] wifi: iwlwifi: mvm: Fix injected 5 GHz legacy rate benthecarman via B4 Relay
@ 2026-10-10 2:42 ` benthecarman via B4 Relay
1 sibling, 0 replies; 3+ messages in thread
From: benthecarman via B4 Relay @ 2026-10-10 2:42 UTC (permalink / raw)
To: Miri Korenblit; +Cc: Johannes Berg, linux-wireless, linux-kernel, benthecarman
From: benthecarman <benthecarman@live.com>
iwl_mld_get_inject_tx_rate() hands the legacy rate index from mac80211
to iwl_mld_mac80211_rate_idx_to_fw(), which expects the driver's rate
indices. Outside 2.4 GHz the mac80211 index points into a bitrate
table that starts at 6 Mbps, so a 12 Mbps injection on 5 or 6 GHz goes
out as 5.5 Mbps CCK.
Add IWL_FIRST_OFDM_RATE outside 2.4 GHz, as mvm does for frames that
are not injected.
Fixes: d1e879ec600f ("wifi: iwlwifi: add iwlmld sub-driver")
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: benthecarman <benthecarman@live.com>
---
drivers/net/wireless/intel/iwlwifi/mld/tx.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/intel/iwlwifi/mld/tx.c b/drivers/net/wireless/intel/iwlwifi/mld/tx.c
index fc501ac0c..317573b5e 100644
--- a/drivers/net/wireless/intel/iwlwifi/mld/tx.c
+++ b/drivers/net/wireless/intel/iwlwifi/mld/tx.c
@@ -599,7 +599,16 @@ static u32 iwl_mld_get_inject_tx_rate(struct iwl_mld *mld,
if (u32_get_bits(info->flags, IEEE80211_TX_CTL_STBC))
result |= RATE_MCS_STBC_MSK;
} else {
- result = iwl_mld_mac80211_rate_idx_to_fw(mld, info, rate->idx);
+ int rate_idx = rate->idx;
+
+ /*
+ * mac80211 indexes the band's bitrates, which start at
+ * 6 Mbps outside 2.4 GHz; remap to our rate indices.
+ */
+ if (info->band != NL80211_BAND_2GHZ)
+ rate_idx += IWL_FIRST_OFDM_RATE;
+
+ result = iwl_mld_mac80211_rate_idx_to_fw(mld, info, rate_idx);
}
if (info->control.antennas)
--
2.55.0
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-10 2:42 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-10 2:42 [PATCH 0/2] wifi: iwlwifi: fix legacy-rate injection outside 2.4 GHz benthecarman via B4 Relay
2026-10-10 2:42 ` [PATCH 1/2] wifi: iwlwifi: mvm: Fix injected 5 GHz legacy rate benthecarman via B4 Relay
2026-10-10 2:42 ` [PATCH 2/2] wifi: iwlwifi: mld: " benthecarman via B4 Relay
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®