From nobody Fri Oct 2 12:19:52 2026 Received: from mail-pg1-f177.google.com (mail-pg1-f177.google.com [209.85.215.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9989F446821 for ; Fri, 31 Jul 2026 16:06:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.177 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514017; cv=none; b=IyHsB9rtjrWXXWfIvEsdUTeXLh2JJLVL8YhelGdaAyUwa1ODY5PC44aoRsApb/Xc3X32KipprR/oDby54w1BX0GTUl1cjskEbhgOynIN9y5tnC7tx8f4cec+xSpCAzHYcFlPOR0wgQmHP0YppfXqXB4rG9Lq/jmDnumtkn7o8xw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514017; c=relaxed/simple; bh=YJBvBZWvNxs18TqfUfA1hwadJeuDBfwNuagruUWmko0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=GhhFGr9b1Nw0xi8mmlEcEu9HiHQIaG1DFcyOUr4qFD96f9/gysI+lRvzrILf5ntUKG5i1V8O4zUNJusBc8rdJYkIkeMDHr2wsu2OUIVPshcwXvq4ExdnvpZjgtzHe+Rp1zA4oOVlabt69Cp45EaV7xvtscj3DrcfHG8Rb/20DWk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=LKmEUAN7; arc=none smtp.client-ip=209.85.215.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="LKmEUAN7" Received: by mail-pg1-f177.google.com with SMTP id 41be03b00d2f7-ca132e9c54aso94047a12.3 for ; Fri, 31 Jul 2026 09:06:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785514015; x=1786118815; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=V+7zRa7zBwj/Mp97JNRaCsdKi8S7AHJm5zHHTJ/ZjEk=; b=LKmEUAN7WM2pOPs0/S9s2K6fX1k1hDzorSiPG/YYGoI3fwUAUxz/XaRHSRbpD9uFye A723mjHIUrRd5BoBaw7E2qKB7WFGV0IsswW7JJbzogxmD62eXeo1AVEj4481MywMyySW XaH2RoL2AhGcruek92M6oAgMq+urZ1J/uYZqkpXq8bnbgl94OMY2HlnkQ7akCX4vezYN ajl5eUYqI1b+UlqwqVThx51jIyX2Yrji7gwa7FGpIl0S/tghqDK1N9WlF7v7uFz+1fbJ hqJLOWE/3Ni5B5gYBeiWV6p4QKctm8Pt7ezUBM96dHQ2uAFGbPFLFebww/J2Bprq1ndw 8/rQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785514015; x=1786118815; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=V+7zRa7zBwj/Mp97JNRaCsdKi8S7AHJm5zHHTJ/ZjEk=; b=B5SZkh0evU07doTMGiJugsRiMMYnxmvLdfUHOadnYmuZSvHCx+QXQNtBzd3/6E0TSH /65bpstTdMTNicKJXvlLR5nwqVO5ZE1ly1ADYmmtfr8okAqS8MfkJrHvYKwQTuoSdnUZ fomRObGV3I8Dy33hPCj8unrxP8jClBYAv3IHyhqQIntn63rwLCyr0TkQ9veuZXQSnuJx JV6kGLBqEae2g6sGMORV5gPDTJUdZ3FIhTwOldPgtT0n0mcEXPl/Hy4jwvefTgqF0vdY Kxr9GG3E5U3sOIn4aGEynO+84cdSq9QScjSxFSiRZ9xuR+/HiEMdCJd31zfS3rYWPmyt bT/A== X-Forwarded-Encrypted: i=1; AHgh+RrTiua9UHIYLhpF2kTE1qZtl0GV8xsEhT2gPyKfrQoU1oyQiOifSl6npd1meg6u2NAneKTWKzBmC/emo9c=@vger.kernel.org X-Gm-Message-State: AOJu0YysZxHsH694VbfErO6Hbvi2OygrhG+0mLwM+b3fTBmcBwVZHUKb 7UdVMdcQDigFPBK5jOVNAHSsKveygs06hjpB0uxwahzYO4RCcDu6xnes X-Gm-Gg: AR+sD109nzg//6j0iDyvGTriahp+wQnL53nni4s3XmNmQkovGBFL7aS3b0loKAfZMkd qKEoMGZ1gfSBpYeiM6eJSfhe7FJ+pbFCE57xKNJ4RE8IyyWM645kU3SYVxKjPkSuK5woiskCmQK El0DqCERWI7zb/PjXuWHm/NwfQT6CI5TABKkycP8FG10r36o4UHg0enQeM1oGllWel4Dk5wmCrG Yr9ubnPtm+qbJMbSRvb7GbXAYEh0/DZTRlImrSgnQmmRcR/gJG+ePFY5Ds77E9U2qbm+IeoYZox X0GYfXL34lpTh51f/QByY6xm+B0I+dMVjjdAMpbFlytU7tm1dQ7efqjboN+5Y1J2F+xBCuw/W+g /gs1g3WpeRV9gDe80MUCkPSLWuwif+aykumLP4LB6vgK+EChJPuCsJm1J8sQc7ZYLVxadCVBF/X 0hgDo3I5weF8DPDYtRYne0lOE2SzewO7MkbaU1MdCihEXVjeJmeU2LOhCyVTY3dLrl+rvkk6h/D WqwRbte X-Received: by 2002:a17:90b:5408:b0:38e:c140:2a0b with SMTP id 98e67ed59e1d1-38fbc4c8183mr624796a91.3.1785514014834; Fri, 31 Jul 2026 09:06:54 -0700 (PDT) Received: from Potato.tail66a299.ts.net ([171.76.83.76]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3153dd9c93dsm7881425eec.8.2026.07.31.09.06.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Jul 2026 09:06:54 -0700 (PDT) From: Shivesh To: arend.vanspriel@broadcom.com Cc: linux-wireless@vger.kernel.org, brcm80211@lists.linux.dev, brcm80211-dev-list.pdl@broadcom.com, linux-kernel@vger.kernel.org, Shivesh Subject: [PATCH v4 1/8] wifi: brcmfmac: flowring: replace O(N) blocked-ring scan with atomic counter Date: Fri, 31 Jul 2026 16:06:18 +0000 Message-ID: <20260731160646.3812-2-chanelshivesh@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260731160646.3812-1-chanelshivesh@gmail.com> References: <20260731160646.3812-1-chanelshivesh@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable brcmf_flowring_block() previously determined whether any sibling ring was already blocked by walking all nrofrings entries under block_lock. This O(N) scan is both slow and incomplete: a ring that transitions from RING_OPEN to RING_CLOSING while blocked causes the unblock path to skip the decrement (because ring->status is no longer RING_OPEN), leaking the implicit "someone is blocked" state and permanently stopping the netif queue for that interface. Replace the per-call O(N) walk with a per-interface atomic counter if_blocked_cnt[BRCMF_MAX_IFS]. Introduce a per-ring boolean counted_in_blocked that records whether the ring has been added to the counter, so the matching decrement is always applied regardless of the ring status at unblock time. The decision to stop or wake the netif queue is now a simple atomic_read() check, still performed under block_lock to prevent races between concurrent brcmf_flowring_block() callers. Signed-off-by: Shivesh --- .../broadcom/brcm80211/brcmfmac/flowring.c | 65 ++++++++++++++----- .../broadcom/brcm80211/brcmfmac/flowring.h | 18 +++++ 2 files changed, 66 insertions(+), 17 deletions(-) diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/flowring.c b/= drivers/net/wireless/broadcom/brcm80211/brcmfmac/flowring.c index 35cbcea0abc9..b9c518939f50 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/flowring.c +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/flowring.c @@ -182,10 +182,8 @@ static void brcmf_flowring_block(struct brcmf_flowring= *flow, u16 flowid, struct brcmf_bus *bus_if; struct brcmf_pub *drvr; struct brcmf_if *ifp; - bool currently_blocked; - int i; - u8 ifidx; unsigned long flags; + u8 ifidx; =20 spin_lock_irqsave(&flow->block_lock, flags); =20 @@ -194,23 +192,54 @@ static void brcmf_flowring_block(struct brcmf_flowrin= g *flow, u16 flowid, spin_unlock_irqrestore(&flow->block_lock, flags); return; } - ifidx =3D brcmf_flowring_ifidx_get(flow, flowid); =20 - currently_blocked =3D false; - for (i =3D 0; i < flow->nrofrings; i++) { - if ((flow->rings[i]) && (i !=3D flowid)) { - ring =3D flow->rings[i]; - if ((ring->status =3D=3D RING_OPEN) && - (brcmf_flowring_ifidx_get(flow, i) =3D=3D ifidx)) { - if (ring->blocked) { - currently_blocked =3D true; - break; - } - } + ifidx =3D brcmf_flowring_ifidx_get(flow, flowid); + ring->blocked =3D blocked; + + /* + * Maintain the per-interface blocked-ring counter. + * + * We use ring->counted_in_blocked rather than checking + * ring->status here. A ring that became blocked while + * RING_OPEN has already been counted (counted_in_blocked=3Dtrue). + * By the time we unblock it during teardown its status may have + * advanced to RING_CLOSING, so testing RING_OPEN would wrongly + * skip the atomic_dec and permanently leak the counter, leaving + * the netif queue stopped forever. + * + * Rule: + * block transition (unblocked=E2=86=92blocked): count only if RING_OP= EN, + * set counted_in_blocked. + * unblock transition (blocked=E2=86=92unblocked): decrement only if we + * previously counted it, + * clear counted_in_blocked. + */ + if (blocked) { + if (ring->status =3D=3D RING_OPEN) { + atomic_inc(&flow->if_blocked_cnt[ifidx]); + ring->counted_in_blocked =3D true; } + } else { + if (ring->counted_in_blocked) { + atomic_dec(&flow->if_blocked_cnt[ifidx]); + ring->counted_in_blocked =3D false; + } + } + + /* + * Only propagate a netif queue-stop/wake when the interface + * transitions between fully-clear and at-least-one-blocked. + * Reading the atomic is safe here: we hold block_lock, so no + * concurrent brcmf_flowring_block() call can race the update + * we just made above. + */ + if (blocked && atomic_read(&flow->if_blocked_cnt[ifidx]) !=3D 1) { + /* Another ring was already blocked; no new queue-stop needed. */ + spin_unlock_irqrestore(&flow->block_lock, flags); + return; } - flow->rings[flowid]->blocked =3D blocked; - if (currently_blocked) { + if (!blocked && atomic_read(&flow->if_blocked_cnt[ifidx]) !=3D 0) { + /* More rings still blocked; do not wake the queue yet. */ spin_unlock_irqrestore(&flow->block_lock, flags); return; } @@ -367,6 +396,8 @@ struct brcmf_flowring *brcmf_flowring_attach(struct dev= ice *dev, u16 nrofrings) spin_lock_init(&flow->block_lock); for (i =3D 0; i < ARRAY_SIZE(flow->addr_mode); i++) flow->addr_mode[i] =3D ADDR_INDIRECT; + for (i =3D 0; i < ARRAY_SIZE(flow->if_blocked_cnt); i++) + atomic_set(&flow->if_blocked_cnt[i], 0); for (i =3D 0; i < ARRAY_SIZE(flow->hash); i++) flow->hash[i].ifidx =3D BRCMF_FLOWRING_INVALID_IFIDX; } diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/flowring.h b/= drivers/net/wireless/broadcom/brcm80211/brcmfmac/flowring.h index f3d511f9a3c9..afdea8b3f8aa 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/flowring.h +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/flowring.h @@ -5,6 +5,8 @@ #ifndef BRCMFMAC_FLOWRING_H #define BRCMFMAC_FLOWRING_H =20 +#include + =20 #define BRCMF_FLOWRING_HASHSIZE 512 /* has to be 2^x */ #define BRCMF_FLOWRING_INVALID_ID 0xFFFFFFFF @@ -26,6 +28,16 @@ enum ring_status { struct brcmf_flowring_ring { u16 hash_id; bool blocked; + /* + * True when this ring has been counted in the per-interface + * if_blocked_cnt[]. Set to true whenever the ring transitions + * unblocked=E2=86=92blocked while RING_OPEN; cleared on the matching + * blocked=E2=86=92unblocked transition. Needed so that a ring that + * becomes blocked while RING_OPEN and is later moved to + * RING_CLOSING still correctly decrements the counter at + * teardown, even though its status is no longer RING_OPEN. + */ + bool counted_in_blocked; enum ring_status status; struct sk_buff_head skblist; }; @@ -40,6 +52,12 @@ struct brcmf_flowring { struct brcmf_flowring_hash hash[BRCMF_FLOWRING_HASHSIZE]; spinlock_t block_lock; enum proto_addr_mode addr_mode[BRCMF_MAX_IFS]; + /* Per-interface count of currently blocked open rings. + * Maintained atomically so brcmf_flowring_block() can check + * whether any sibling ring is already blocked in O(1) without + * holding block_lock across an O(nrofrings) walk. + */ + atomic_t if_blocked_cnt[BRCMF_MAX_IFS]; u16 nrofrings; bool tdls_active; struct brcmf_flowring_tdls_entry *tdls_entry; --=20 2.53.0 From nobody Fri Oct 2 12:19:52 2026 Received: from mail-pf1-f175.google.com (mail-pf1-f175.google.com [209.85.210.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D67F844682F for ; Fri, 31 Jul 2026 16:06:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.175 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514020; cv=none; b=WIPhBKUTW1xeSiEgQRUq7C30tqS2oSjRpzAdc2jVruk169Q2RWq1wXg2KafSxY4tV2IlZz7wCGNEFelWKurXrz5/tTy6izr9mS7O7Lfp4+Ec8s4vGSoc7VdCTsAkAaIq5+ccQZl5UJZ26V2VjsrVl9LJZh8beUkMy8uvFGifpFU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514020; c=relaxed/simple; bh=4FmlVouAtetaruhEeiTx3rFln8aYqYjfQLfKSbIJZ0U=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=OXFcJlIHYVP/c0zQY0U3YTWiza78hZj0qv1MO4W9WC2yEiismLoUc/E/3n4EiFi6MyeCc4zsp9v8UkWiFchruvrU6gfrXRbnY+QdOqkSpFNpqpC2Vz7gpNXWOeOeyX4tx9onmVZHu8/jRvXAEuEXOXkr7N+ZmZOXfXEhqdc5k0c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=WiqA4vVN; arc=none smtp.client-ip=209.85.210.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="WiqA4vVN" Received: by mail-pf1-f175.google.com with SMTP id d2e1a72fcca58-84a6f026675so197728b3a.0 for ; Fri, 31 Jul 2026 09:06:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785514018; x=1786118818; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=n3oPX3E5KdsQaVYxU5lL3g8H/Q6QDbI99g6kazkV/Ds=; b=WiqA4vVNqe2GY9QYH0zJGVeTsOQ+yjEs7w87vp6h8mAW+PUvW9bG8cYJ3nUZ7QltNA 28RK2rHWwpcuggGRA4ALFXsPoKPaJubH2hDxAbsqVAEmGuEYU8ziYwRAnXis+B4hJgWk I2qfgLbxN03MFjIkMP4BZr89rj2N1kNTqCovvVKVFG2cPFY3Y7BlCw/OPFeEnuxPN+m2 gFhBcA7aZWOhsU91WT9b7LNRO684QoM2XJR/IwafuAe7I9lyK4j+wpTetqrisU6IAp3v 0bqIoluUQeCiFriM7FHubUf8Ycr9XOxs2mAlGM3uKr4XyvV+nGLrzaXLJTgkYyvbIEYp Kzrw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785514018; x=1786118818; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=n3oPX3E5KdsQaVYxU5lL3g8H/Q6QDbI99g6kazkV/Ds=; b=expveIqC/7nFNDk95+WH+K708vv2i30kbfia8oFjsfT7VUyZM/58xQiEl/tzzygVWH Xl7uXWWUpf70M7Y6qyOLMxUUFdds6Uh0zZkygWy8iz7r+kuHX30J77lCzA7TFCqhLgx7 OEVmE4om9a7q4o4E62/2CH1Yu7VK4R/U6iRFFNqYWClIWafpKZo0XzAvVvoSFmyP0e6N AFBXjlthJIDLXf3EnosSFtGI/csr8y9gabkjDM+14eHRKA1yNromGZvEdBFBC9nsKnY3 bsrQ0hXICCs5QP9sstiLdA2FcwveIU6BBiiI4Xe0NbDnElhjdODcSYFuSYXeTeQYt1MV d6Xg== X-Forwarded-Encrypted: i=1; AHgh+RpxAuwaJycC/QA9qKLpNmQdUPEGmRGhHt//GCxNVPBzIePqQNOLq+4/uxXNHLAGK68vpjPu9zbipRsTuNA=@vger.kernel.org X-Gm-Message-State: AOJu0YxA5oTSjoDJMqCLLCmZ5ltOFxlSrf3xtnGsfbnCSNJttnas9g84 FYyo6qb4XGCefQu/KdanI/gc5j2/12xNAj2rcmHul3pRutvn+d10G1TJ X-Gm-Gg: AR+sD11kV2LlACp+g950vAtIr/Y6keQmH7oknv8566qJSTeK8rcKYhHeSkH/8il0c34 omxjIrhOLd+HNLxup16SZppvuNkqppeOu9tlnY/5ZTmgi2sryWrlFZNWf6/jvSslC1I21rxVEsn sKho0+CrqLZRvNrlusq81UaUEr+wXFOaEIuZ9H+REhEBsURlpeyhz39sF8BDXA8RmEAPk13aSR7 IhV/U3Jfi/qOV0fy6X9F8DFiq8Z93XzqErRhrjCaIBiYuvzbBqiz08g33+woTbntdJusRNY3oaB 8kW3rhQxXuu8d6Yb6KwLLSIApVLMjPyLVL4nVCDGdOYYQ743ajqNCMLV7y6xqYhgnm6sqcMhGfD sjt6BDngGtC+EDp0C2nvM7O4I3M0sxYRWxV6DgF/yeX6kDC1HJl8niSzUaSyOThkGjO+N0+KZIa UqX4DoQQ2++ITxnXiaFIWusgY7++XJME25eqK/KxeE/svNXJfL65FcJF0mb1IHCowbz9f5uYDhS zvJNmYa X-Received: by 2002:a17:903:3c23:b0:2d0:2741:f31b with SMTP id d9443c01a7336-2d0523fc4ecmr8448685ad.4.1785514017961; Fri, 31 Jul 2026 09:06:57 -0700 (PDT) Received: from Potato.tail66a299.ts.net ([171.76.83.76]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3153dd9c93dsm7881425eec.8.2026.07.31.09.06.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Jul 2026 09:06:57 -0700 (PDT) From: Shivesh To: arend.vanspriel@broadcom.com Cc: linux-wireless@vger.kernel.org, brcm80211@lists.linux.dev, brcm80211-dev-list.pdl@broadcom.com, linux-kernel@vger.kernel.org, Shivesh Subject: [PATCH v4 2/8] wifi: brcmfmac: sdio: coalesce sdio_claim_host calls in rxglom path Date: Fri, 31 Jul 2026 16:06:19 +0000 Message-ID: <20260731160646.3812-3-chanelshivesh@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260731160646.3812-1-chanelshivesh@gmail.com> References: <20260731160646.3812-1-chanelshivesh@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable brcmf_sdio_rxglom() performs one sdio_claim_host()/sdio_release_host() pair for the superframe header parse and then one additional pair for every subframe header parse. For a superframe containing N subframes this means N+1 mutex lock/unlock round-trips on the hot RX path. Group all header parse calls =E2=80=94 superframe and all subframes =E2=80= =94 under a single claim/release pair. The host is still released before the subsequent pure host-memory processing (skb_pull, len_nxtfrm update), keeping the hold time as short as possible. The error path (rxfail) also executes while the host is claimed, which is required because brcmf_sdio_rxfail() writes SDIO Func1 registers. Signed-off-by: Shivesh --- .../broadcom/brcm80211/brcmfmac/sdio.c | 62 ++++++++++++------- 1 file changed, 38 insertions(+), 24 deletions(-) diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c b/driv= ers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c index b725c64e5b5c..4e414403d747 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/sdio.c @@ -1645,37 +1645,43 @@ static u8 brcmf_sdio_rxglom(struct brcmf_sdio *bus,= u8 rxseq) =20 rd_new.seq_num =3D rxseq; rd_new.len =3D dlen; + + /* + * Claim the host once for the entire header-parsing phase. + * + * brcmf_sdio_hdparse() operates on data already in host + * memory, but may call brcmf_sdio_rxfail() on error, which + * writes SDIO Func1 registers and therefore requires the + * host to be claimed. + * + * skb_pull() and the num counter are pure host-memory + * operations; keep them outside the lock to minimise the + * hold time. Both hdparse calls (superframe header and + * each subframe header) are grouped under a single claim/ + * release, replacing the original N+1 separate pairs. + */ sdio_claim_host(bus->sdiodev->func1); errcode =3D brcmf_sdio_hdparse(bus, pfirst->data, &rd_new, BRCMF_SDIO_FT_SUPER); - sdio_release_host(bus->sdiodev->func1); - bus->cur_read.len =3D rd_new.len_nxtfrm << 4; - - /* Remove superframe header, remember offset */ - skb_pull(pfirst, rd_new.dat_offset); - num =3D 0; - - /* Validate all the subframe headers */ - skb_queue_walk(&bus->glom, pnext) { - /* leave when invalid subframe is found */ - if (errcode) - break; =20 - rd_new.len =3D pnext->len; - rd_new.seq_num =3D rxseq++; - sdio_claim_host(bus->sdiodev->func1); - errcode =3D brcmf_sdio_hdparse(bus, pnext->data, &rd_new, - BRCMF_SDIO_FT_SUB); - sdio_release_host(bus->sdiodev->func1); - brcmf_dbg_hex_dump(BRCMF_GLOM_ON(), - pnext->data, 32, "subframe:\n"); - - num++; + /* Validate all the subframe headers while host is claimed */ + if (!errcode) { + skb_queue_walk(&bus->glom, pnext) { + rd_new.len =3D pnext->len; + rd_new.seq_num =3D rxseq++; + errcode =3D brcmf_sdio_hdparse(bus, pnext->data, + &rd_new, + BRCMF_SDIO_FT_SUB); + brcmf_dbg_hex_dump(BRCMF_GLOM_ON(), + pnext->data, 32, + "subframe:\n"); + if (errcode) + break; + } } =20 if (errcode) { - /* Terminate frame on error */ - sdio_claim_host(bus->sdiodev->func1); + /* Terminate frame on error, still holding the host */ brcmf_sdio_rxfail(bus, true, false); bus->sdcnt.rxglomfail++; brcmf_sdio_free_glom(bus); @@ -1683,6 +1689,14 @@ static u8 brcmf_sdio_rxglom(struct brcmf_sdio *bus, = u8 rxseq) bus->cur_read.len =3D 0; return 0; } + sdio_release_host(bus->sdiodev->func1); + + /* Host released; now do the pure-memory bookkeeping */ + bus->cur_read.len =3D rd_new.len_nxtfrm << 4; + + /* Remove superframe header, remember offset */ + skb_pull(pfirst, rd_new.dat_offset); + num =3D 0; =20 /* Basic SD framing looks ok - process each packet (header) */ =20 --=20 2.53.0 From nobody Fri Oct 2 12:19:52 2026 Received: from mail-pg1-f178.google.com (mail-pg1-f178.google.com [209.85.215.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 07B80443E24 for ; Fri, 31 Jul 2026 16:07:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.178 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514023; cv=none; b=L8T2PRTVxZ5LIfNOYJCDUFDTJMnJi7z5aPQPCFTZykIe5r73yNmE2/P3zQraWHGURxcz65nBGRGG2MXJfze5ik27gKXOMRpCn/Fspm0eBFns63/lkSwJh3rBeRr10MV0kFIHd8OikWb8i76IVPA93Of7U0tFgIj44IXz7GcU0AY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514023; c=relaxed/simple; bh=Jty8yO41/NAzwBTRC93gt7XYppm8tipeHN673R2Ik08=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=S4/q+585hWm8eygjhMdjnu+GCPO54wKC0+Mytn0Qj85f0eRo98RdxmLvRY/Sw53q2/9+h+L/lumCql7NbK1tt4CX8VRZXIu8WVcn1SPXeOfDqRm7Rbg+7lIxu7jYI+DUrbX0T9guKybyEEW2YhO4qVS/qtAldtSSf9r0AMyONCc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=cyhYsIhM; arc=none smtp.client-ip=209.85.215.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="cyhYsIhM" Received: by mail-pg1-f178.google.com with SMTP id 41be03b00d2f7-c96d7933910so107131a12.0 for ; Fri, 31 Jul 2026 09:07:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785514021; x=1786118821; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=XauinKQI6tu5wjHWqSFKKt7ebLbypRasR58eoZCbIfk=; b=cyhYsIhMz535yydF38+h0IbaWx+KZkCeutI27LzpL1EIMe275B6KbPUC9Vuj+5Zt07 3iLIGK0jLHjuBlcn/PVPP0Nh2K2iMBLiX/RIcVC52iPiUZrqXpJbzqyGo1imYTt1B094 Ymk2OfYiAqT5q+oaSEDX/fa3CIWI+5n/ZVsZGKtMlxHrFosJZa9+iR18UWoBbZuQJqnQ YNARRcm4KBaSX+8Zw5x2J9mllKm1bVN1Ae002YSsNvUMhJW1epv2bE9VYnU07utbQifs yW7DDLZUUwbvYa4c6JLRsmZoCMeGy/SLM/B+XxCEk2CJgXddY4UHf6ImwBCmmE9h/+EA aGng== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785514021; x=1786118821; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=XauinKQI6tu5wjHWqSFKKt7ebLbypRasR58eoZCbIfk=; b=oQZNuKa8sdwEdCtGGJgSwM8UIuzQU0MnbafmG0CUapXBpdn6FfOJOOdfLyb3fmJAGx BYorZe57PNPfWDJoXiwobUIfM4fi9X5dlRmhFo3Bjpu0XVWZxBvCiUEStBD7JCtoe/Y4 5I5f5sLWgMucIsZSkIsVcGeplUAfrMQr4DN+kEq7HSabSv2DvJ3Q2BXDG0+uHkRJOxAd MpvceumLwnrC59eh5vTY19rhl0XmgsFa7cAJHrVMYPiXn01HmMjHtbbDAbYSbUxT3osl 6dC+TpuVuxmyejzOoE9KEd79g/wO8gheM/Vl8ekQJu3GDZvPN0au8kgfv28c9b4R3Fm6 smxA== X-Forwarded-Encrypted: i=1; AHgh+RpIUL6a9yP9bBRS7XisR7tYdvgyplvr7jzPte0acBZl6glNIud2vX01HtaSSAvcfgLzSfKzdSUzOGy/eEo=@vger.kernel.org X-Gm-Message-State: AOJu0Yza5bdzQihDzEsQu5//p43qb3Mwawnd5eFZNjcTjzUaoG5/LczI F9VGJEv4u1fIzXT2N1/TWpRE4hTEsJjm+5N0d+4tUZCPmR9zokucWA3U X-Gm-Gg: AR+sD10T60VX/XI6ejBqRE/kNHu4Bpo1fUf8W4YsCW0nLg98fKwMGRWFUvVYoAytrLT FAlhi95bKfYuA6FS/LIHWbYkfRO9AoEAja3W9Z4r9zuTVjMNPzVdETQs2uyLZ14uFDGkvpm1UR1 j5+S4sxdZScjldwjeprXzjLGNZrVf8fmQ1rBiHz1nhnjcLU9ONl+DzttGbfBD3VyusjTboltICL WQdTln5vVfLYPnaPxEdySfsIkGL38dZXa1l/gZIwJALknRU16WoijS5f+cC2YPC3QkxqaOPdAdE BrOozzwzR82IgxVVOJkVIwo+DB19Ri6PTPcIF52nSfsM1fBeeN35w9wd2EhMIeoAlmt7az4/wY2 EF92PhUOG6OC30vvZYGvF2oPmQcuOTW2W/nLZYbogS+uExFiQ/+yVBMG5EpNYm0gfQnWxn1YHTE pYLYCRI6ofLEVX56yrye3faHBW+A5XQKMfrneZaX0o7utKlT4pQwztKz8vEiKw/oNdmEJz0gqtb 6zCiZBt X-Received: by 2002:a17:902:f607:b0:2ca:de3:15eb with SMTP id d9443c01a7336-2d05209f863mr7797915ad.0.1785514021222; Fri, 31 Jul 2026 09:07:01 -0700 (PDT) Received: from Potato.tail66a299.ts.net ([171.76.83.76]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3153dd9c93dsm7881425eec.8.2026.07.31.09.06.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Jul 2026 09:07:00 -0700 (PDT) From: Shivesh To: arend.vanspriel@broadcom.com Cc: linux-wireless@vger.kernel.org, brcm80211@lists.linux.dev, brcm80211-dev-list.pdl@broadcom.com, linux-kernel@vger.kernel.org, Shivesh Subject: [PATCH v4 3/8] wifi: brcmfmac: core: fix missing headroom check and populate radiotap RSSI Date: Fri, 31 Jul 2026 16:06:20 +0000 Message-ID: <20260731160646.3812-4-chanelshivesh@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260731160646.3812-1-chanelshivesh@gmail.com> References: <20260731160646.3812-1-chanelshivesh@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Two problems exist in brcmf_netif_mon_rx(): 1. skb_push() is called without first verifying that the skb has sufficient headroom. If the skb arrives with zero headroom the kernel will panic. Use skb_cow_head() before each skb_push() and free the skb on allocation failure. 2. When the firmware provides a hardware RX header (BRCMF_FEAT_MONITOR_FMT_HW_RX_HDR), the driver strips it and inserts a blank ieee80211_radiotap_header with no signal data. Monitor-mode packet captures therefore show no signal strength, making tools like Wireshark and iw unable to report RSSI. Define struct brcmf_radiotap_info that embeds the standard radiotap header followed by a dbm_antsignal field. Extract the rssi value from wlc_d11rxhdr and populate it_present with IEEE80211_RADIOTAP_DBM_ANTSIGNAL so userspace tools can read signal strength from monitor-mode frames. Also replace the open-coded "skb->len -=3D 4" with skb_trim(), which is the correct API for shortening a linear skb. Fixes: e665988be29c ("brcmfmac: support monitor frames with the hardware/uc= ode header") Signed-off-by: Shivesh --- .../broadcom/brcm80211/brcmfmac/core.c | 44 ++++++++++++------- 1 file changed, 29 insertions(+), 15 deletions(-) diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c b/driv= ers/net/wireless/broadcom/brcm80211/brcmfmac/core.c index ec170647800d..eefc437dd055 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/core.c @@ -431,45 +431,55 @@ void brcmf_netif_rx(struct brcmf_if *ifp, struct sk_b= uff *skb) netif_rx(skb); } =20 +struct brcmf_radiotap_info { + struct ieee80211_radiotap_header hdr; + s8 dbm_antsignal; +} __packed; + void brcmf_netif_mon_rx(struct brcmf_if *ifp, struct sk_buff *skb) { if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_MONITOR_FMT_RADIOTAP)) { - /* Do nothing */ + /* Firmware already provided a full radiotap header; do nothing */ } else if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_MONITOR_FMT_HW_RX_HDR)) { struct wlc_d11rxhdr *wlc_rxhdr =3D (struct wlc_d11rxhdr *)skb->data; - struct ieee80211_radiotap_header *radiotap; + struct brcmf_radiotap_info *rtap; unsigned int offset; u16 RxStatus1; + s8 rssi; =20 RxStatus1 =3D le16_to_cpu(wlc_rxhdr->rxhdr.RxStatus1); + rssi =3D wlc_rxhdr->rssi; =20 offset =3D sizeof(struct wlc_d11rxhdr); - /* MAC inserts 2 pad bytes for a4 headers or QoS or A-MSDU - * subframes - */ + /* MAC inserts 2 pad bytes for a4 headers or QoS or A-MSDU subframes */ if (RxStatus1 & RXS_PBPRES) offset +=3D 2; offset +=3D D11_PHY_HDR_LEN; =20 skb_pull(skb, offset); =20 - /* TODO: use RX header to fill some radiotap data */ - radiotap =3D skb_push(skb, sizeof(*radiotap)); - memset(radiotap, 0, sizeof(*radiotap)); - radiotap->it_len =3D cpu_to_le16(sizeof(*radiotap)); - - /* TODO: 4 bytes with receive status? */ - skb->len -=3D 4; + /* Insert our radiotap header with RSSI data */ + if (skb_cow_head(skb, sizeof(*rtap))) + goto drop; + rtap =3D skb_push(skb, sizeof(*rtap)); + memset(rtap, 0, sizeof(*rtap)); + rtap->hdr.it_len =3D cpu_to_le16(sizeof(*rtap)); + rtap->hdr.it_present =3D cpu_to_le32(1 << IEEE80211_RADIOTAP_DBM_ANTSIGN= AL); + rtap->dbm_antsignal =3D rssi; + + /* Strip the 4-byte receive status / FCS tail */ + skb_trim(skb, skb->len - 4); } else { struct ieee80211_radiotap_header *radiotap; =20 - /* TODO: use RX status to fill some radiotap data */ + if (skb_cow_head(skb, sizeof(*radiotap))) + goto drop; radiotap =3D skb_push(skb, sizeof(*radiotap)); memset(radiotap, 0, sizeof(*radiotap)); radiotap->it_len =3D cpu_to_le16(sizeof(*radiotap)); =20 - /* TODO: 4 bytes with receive status? */ - skb->len -=3D 4; + /* Strip the 4-byte receive status / FCS tail */ + skb_trim(skb, skb->len - 4); } =20 skb->dev =3D ifp->ndev; @@ -478,6 +488,10 @@ void brcmf_netif_mon_rx(struct brcmf_if *ifp, struct s= k_buff *skb) skb->protocol =3D htons(ETH_P_802_2); =20 brcmf_netif_rx(ifp, skb); + return; + +drop: + brcmu_pkt_buf_free_skb(skb); } =20 static int brcmf_rx_hdrpull(struct brcmf_pub *drvr, struct sk_buff *skb, --=20 2.53.0 From nobody Fri Oct 2 12:19:52 2026 Received: from mail-pg1-f171.google.com (mail-pg1-f171.google.com [209.85.215.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 332E644AB8D for ; Fri, 31 Jul 2026 16:07:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.171 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514026; cv=none; b=PzYTDFRUWEAwTy8UPQPLgF7JN6sll08f/VE+/la6kXcemWZpS8aA0kneZGxlpyE1B73etVuxcHLLXPP8QGeHQFXyq5CaPgNyOzQU9/vDq7okclyUM9BIiJtcOP/6hko3vy51Hu3dk326i9hUG0v2FuhAeGfnZsvf9MqSVbRVUuo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514026; c=relaxed/simple; bh=yt5tJ1FY92EBJqC4N6WpXN19nC5QZxle3Ke9UJYoQV4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=L9KGfB6sBQj96W7N1Aevn97r6rO7nWe68KPXU2FO5yw2eq0jCugViZCe2gz7OtFgZ0iKF9g4RdEPmAXdqQntp85SDCKLE6N3KcTru5UMfd4caiuvF22bXk+ly+zx8AjONIjyG7ZMvLOX9y3ellVjjwX1XSCYOW/GgqfdFXkaWVI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=V130nf0Z; arc=none smtp.client-ip=209.85.215.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="V130nf0Z" Received: by mail-pg1-f171.google.com with SMTP id 41be03b00d2f7-ca957338f14so67034a12.1 for ; Fri, 31 Jul 2026 09:07:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785514024; x=1786118824; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=4c7Zng1vNMrE5OjddEOF9zhiKxLLsxB841dV4ylJ/sE=; b=V130nf0Z+TdS5jbXhhgv7sXPjrv8aLj3jwU+IssoFI3DeAjD4pdVkxHME8wl5Pxua5 i52hwF/d1VdMD4ndiVQaCzfhSodvseceUV4o7LfTSya5YsrGEZaqx5rNqVpkx1cSjPKg nlb/GSpKt1wVTkMqBT4SevQ0jLwSUgNRKOiyLMGpBPcgSzqeyvKq/G/D01NovovL9AtV DN22LVePgLVs+dJTytVWVD3DhT3lDs8VpiYVopB0AKdDXLd0/ugq863hjt8529BrHTWL DYkz03bvWzzshsX78FFCogLOth64vOPQ5/KYwqLQCnVqvUZ1zrg2SG3icu/vTJ/5SEdQ N/Vg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785514024; x=1786118824; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=4c7Zng1vNMrE5OjddEOF9zhiKxLLsxB841dV4ylJ/sE=; b=aJnsqLKJ6/WL/QAwq77VERYN097ZDCnynIBQNUfZIYKHhUxJHbokQd6YwOdyWGgQyU 9v9IJTd3psJ12YFJu7+2V2mtHp/sdVsLMq1+l5YzL+oBrpdVEFakfR7wwJYwQjJw6VYI mcPrCUnxQ94L+ahRnarHfPCfxvTtb//gqvICSeYFPCWGWZCdEe2tuTkg289jh4yYjU7C Xp7xX8GfS77Qh0207k/PMfRSQ4ahIA9AEa/R3ne55+gpmJcCqNaXtkr9WLEqD+zIpu/j pMm8Cd8Qw9Cubtn8Ltq4BWyvnUKUwv2N9WTfwWzO3I9BSezxkitcWGlAAlXP56gPLZfZ iRUw== X-Forwarded-Encrypted: i=1; AHgh+RrbiaXmQ7Z/IzdkaU4uklPciDydFxL2Q+OoLJ1WANogIkUHZ9wLG5Sp34d4hjTnxIVe4uTvOz46ZLCrY7Q=@vger.kernel.org X-Gm-Message-State: AOJu0YzeiC057KSgCsZM37HhporLFFNx38OHPn/xU2cb8owlfKvaYFTF mNnD7M+x/s2p3Zluq4eRCnG4wQhb24vm2TYCEBwZxi+hJvtRPQ9lFZ3X X-Gm-Gg: AR+sD12di230JAbxN+ZUismN5dJI7jTKt+LAN5wkdORlWUQmKgrTfqJCEOkFlJgE81n 2WQ93tBsj0hs1s0GshOTt4AkAm9tRHuTN+eMmGo8y2RZyGVZlm6B/jm6IiZi/a52DIJfifzAL6h sEnnUysRiWqCwvSeecZXtBw7dK6fRT/Biii/UB1WDHAMX7dGTeVq0C7XQ4/m3dXU9Cxj4gNDDl9 LwzUA6WUhCZr3LB5KidR7TU4k93IBjfIMpndkX7ZR61dbJbdCBxr7WJcjqNkP6ytFX/cAr0LZLX LityBiuVG2u8hKnkBtHxA609Gna1A+hPQPP+g0mO55QBiBmj5AEIn1mRlKQpu18IHact61Vth7h Y7co5jGXOjTYPneCsi3+PP1j5tN0Uw+f/WUi4GJnd6bJsMbv05ltzifYpkGJhDDVD7P3qi7Vggm 8R6FsMuF5Sr84bOiP17mxHJDePF404+vkchHs/bbWi06/j5xlXOYs87qzCDA/Vqm8U6VUYRyJhz pQ9hImD X-Received: by 2002:a17:903:1a24:b0:2ca:ecf6:9105 with SMTP id d9443c01a7336-2d0521bd8a0mr7853625ad.1.1785514024258; Fri, 31 Jul 2026 09:07:04 -0700 (PDT) Received: from Potato.tail66a299.ts.net ([171.76.83.76]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3153dd9c93dsm7881425eec.8.2026.07.31.09.07.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Jul 2026 09:07:03 -0700 (PDT) From: Shivesh To: arend.vanspriel@broadcom.com Cc: linux-wireless@vger.kernel.org, brcm80211@lists.linux.dev, brcm80211-dev-list.pdl@broadcom.com, linux-kernel@vger.kernel.org, Shivesh Subject: [PATCH v4 4/8] wifi: brcmfmac: cfg80211: implement PMKID_V2 and fix brcmf_delay busy-wait Date: Fri, 31 Jul 2026 16:06:21 +0000 Message-ID: <20260731160646.3812-5-chanelshivesh@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260731160646.3812-1-chanelshivesh@gmail.com> References: <20260731160646.3812-1-chanelshivesh@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Two independent fixes: 1. PMKID_V2 implementation Firmware revision 12 introduced a versioned PMKID list (V2) with FILS-specific fields: raw PMK material, SSID, and fils_cache_id. The set/del/flush callbacks all contained "TODO: implement PMKID_V2" placeholders and fell through to the V1 path, breaking FILS fast-roaming on devices with V2-capable firmware. Add brcmf_pmksa_v2_op() which maintains a shadow brcmf_pmk_list_v2_le in cfg80211_info and pushes the full updated list to firmware via the pmkid_info iovar on every set/del/flush. The shadow counter is kept in list->length between calls; the wire-format byte-length is computed only at send time to avoid corrupting the shadow on the next call. Dispatch V2 between the existing V3 and V1 paths. 2. brcmf_delay() busy-wait When ms < (1000/HZ), brcmf_delay() called mdelay(), which is a CPU busy-wait loop. Since the function is always called in a sleepable context (it falls back to msleep() for larger values), the busy-wait is unnecessary and wastes CPU cycles. Replace with usleep_range() for values <=3D 20ms. Signed-off-by: Shivesh --- .../broadcom/brcm80211/brcmfmac/cfg80211.c | 123 ++++++++++++++++-- .../broadcom/brcm80211/brcmfmac/cfg80211.h | 4 +- 2 files changed, 115 insertions(+), 12 deletions(-) diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c b/= drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c index 0b55d445895f..2375c2f9d97a 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c @@ -3989,12 +3989,10 @@ static int brcmf_cfg80211_sched_scan_stop(struct wi= phy *wiphy, =20 static __always_inline void brcmf_delay(u32 ms) { - if (ms < 1000 / HZ) { - cond_resched(); - mdelay(ms); - } else { + if (ms <=3D 20) + usleep_range(ms * 1000, ms * 1000 + 1000); + else msleep(ms); - } } =20 static s32 brcmf_config_wowl_pattern(struct brcmf_if *ifp, u8 cmd[4], @@ -4364,6 +4362,109 @@ brcmf_pmksa_v3_op(struct brcmf_if *ifp, struct cfg8= 0211_pmksa *pmksa, return ret; } =20 +/** + * brcmf_pmksa_v2_op - update firmware PMKSA cache using the V2 list inter= face. + * + * V2 firmware (revision 12) uses a versioned flat list structure + * (brcmf_pmk_list_v2_le) rather than the per-entry operation model of V3. + * Each entry carries FILS-specific fields (raw PMK material, SSID, and + * fils_cache_id) in addition to the basic BSSID + PMKID pair, enabling + * FILS fast-roaming on devices that do not support V3. + * + * @cfg: driver config structure holding the shadow V2 PMKSA list + * @ifp: interface pointer + * @pmksa: the PMKSA to add/remove, or NULL for a flush + * @alive: true =3D add (set time_left to no-expiry), false =3D remove/flu= sh + */ +static s32 +brcmf_pmksa_v2_op(struct brcmf_cfg80211_info *cfg, struct brcmf_if *ifp, + struct cfg80211_pmksa *pmksa, bool alive) +{ + struct brcmf_pub *drvr =3D cfg->pub; + struct brcmf_pmk_list_v2_le *list =3D &cfg->pmk_list_v2; + struct brcmf_pmksa_v2 *pmk =3D list->pmk; + u32 npmk =3D le16_to_cpu(list->length); + u32 i; + + /* npmk here stores the count of valid entries, repurposing the + * length field of the shadow list as a counter. We convert to + * the wire format (byte length) when sending to firmware. + */ + if (!pmksa) { + /* Flush: zero the shadow list and push an empty V2 list. */ + memset(list, 0, sizeof(*list)); + goto send; + } + + if (alive) { + /* Set: search for existing BSSID match first. */ + for (i =3D 0; i < npmk; i++) + if (!memcmp(pmksa->bssid, pmk[i].bssid, ETH_ALEN)) + break; + + if (i >=3D BRCMF_MAXPMKID) { + bphy_err(drvr, "V2 PMKSA cache full (%d entries)\n", + npmk); + return -EINVAL; + } + + memset(&pmk[i], 0, sizeof(pmk[i])); + pmk[i].length =3D cpu_to_le16(sizeof(struct brcmf_pmksa_v2)); + if (pmksa->bssid) + memcpy(pmk[i].bssid, pmksa->bssid, ETH_ALEN); + if (pmksa->pmkid) + memcpy(pmk[i].pmkid, pmksa->pmkid, WLAN_PMKID_LEN); + if (pmksa->pmk && pmksa->pmk_len && + pmksa->pmk_len <=3D WLAN_PMK_LEN_SUITE_B_192) { + memcpy(pmk[i].pmk, pmksa->pmk, pmksa->pmk_len); + pmk[i].pmk_len =3D cpu_to_le16(pmksa->pmk_len); + } + if (pmksa->ssid && pmksa->ssid_len) { + memcpy(pmk[i].ssid.SSID, pmksa->ssid, pmksa->ssid_len); + pmk[i].ssid.SSID_len =3D pmksa->ssid_len; + } + if (pmksa->fils_cache_id) + pmk[i].fils_cache_id =3D *pmksa->fils_cache_id; + + if (i =3D=3D npmk) + npmk++; + } else { + /* Delete: find by BSSID and compact the list. */ + for (i =3D 0; i < npmk; i++) + if (!memcmp(pmksa->bssid, pmk[i].bssid, ETH_ALEN)) + break; + + if (i >=3D npmk) { + bphy_err(drvr, "V2 PMKSA entry not found\n"); + return -EINVAL; + } + + for (; i < npmk - 1; i++) + memcpy(&pmk[i], &pmk[i + 1], sizeof(pmk[i])); + memset(&pmk[npmk - 1], 0, sizeof(pmk[npmk - 1])); + npmk--; + } + + /* Write the updated entry count back to shadow BEFORE we overwrite + * list->length with the wire-format byte length at send:. If we + * don't do this here, the next call will read a byte-length back + * as an entry count and silently corrupt the list. + */ + list->length =3D cpu_to_le16(npmk); + +send: + /* Build the wire-format byte length and send the full list to firmware. + * Read npmk back from the shadow (handles the flush path where npmk=3D0). + */ + npmk =3D le16_to_cpu(list->length); + list->version =3D cpu_to_le16(BRCMF_PMKSA_VER_2); + list->length =3D cpu_to_le16(offsetof(struct brcmf_pmk_list_v2_le, pmk) + + npmk * sizeof(struct brcmf_pmksa_v2)); + + return brcmf_fil_iovar_data_set(ifp, "pmkid_info", list, sizeof(*list)); +} + + static __used s32 brcmf_update_pmklist(struct brcmf_cfg80211_info *cfg, struct brcmf_if *ifp) { @@ -4402,8 +4503,8 @@ brcmf_cfg80211_set_pmksa(struct wiphy *wiphy, struct = net_device *ndev, =20 if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_PMKID_V3)) return brcmf_pmksa_v3_op(ifp, pmksa, true); - - /* TODO: implement PMKID_V2 */ + if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_PMKID_V2)) + return brcmf_pmksa_v2_op(cfg, ifp, pmksa, true); =20 npmk =3D le32_to_cpu(cfg->pmk_list.npmk); for (i =3D 0; i < npmk; i++) @@ -4446,8 +4547,8 @@ brcmf_cfg80211_del_pmksa(struct wiphy *wiphy, struct = net_device *ndev, =20 if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_PMKID_V3)) return brcmf_pmksa_v3_op(ifp, pmksa, false); - - /* TODO: implement PMKID_V2 */ + if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_PMKID_V2)) + return brcmf_pmksa_v2_op(cfg, ifp, pmksa, false); =20 npmk =3D le32_to_cpu(cfg->pmk_list.npmk); for (i =3D 0; i < npmk; i++) @@ -4487,8 +4588,8 @@ brcmf_cfg80211_flush_pmksa(struct wiphy *wiphy, struc= t net_device *ndev) =20 if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_PMKID_V3)) return brcmf_pmksa_v3_op(ifp, NULL, false); - - /* TODO: implement PMKID_V2 */ + if (brcmf_feat_is_enabled(ifp, BRCMF_FEAT_PMKID_V2)) + return brcmf_pmksa_v2_op(cfg, ifp, NULL, false); =20 memset(&cfg->pmk_list, 0, sizeof(cfg->pmk_list)); err =3D brcmf_update_pmklist(cfg, ifp); diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.h b/= drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.h index 6ceb30142905..57167fde5ba1 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.h +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.h @@ -344,7 +344,8 @@ struct brcmf_cfg80211_wowl { * @bss_list: bss_list holding scanned ap information. * @bss_info: bss information for cfg80211 layer. * @conn_info: association info. - * @pmk_list: wpa2 pmk list. + * @pmk_list: wpa2 pmk list (V1 firmware). + * @pmk_list_v2: wpa2 pmk list for V2 firmware (FILS-capable, firmware rev= 12). * @scan_status: scan activity on the dongle. * @pub: common driver information. * @channel: current channel. @@ -376,6 +377,7 @@ struct brcmf_cfg80211_info { struct wl_cfg80211_bss_info *bss_info; struct brcmf_cfg80211_connect_info conn_info; struct brcmf_pmk_list_le pmk_list; + struct brcmf_pmk_list_v2_le pmk_list_v2; unsigned long scan_status; struct brcmf_pub *pub; u32 channel; --=20 2.53.0 From nobody Fri Oct 2 12:19:52 2026 Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3969444C50E for ; Fri, 31 Jul 2026 16:07:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.50 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514029; cv=none; b=Nv986PAfPSX+B6y5Etd3IFcOhDKpIHM/niT6erxot9RgTNvB9LpyJDpfoxj+/bT1zHRKCmjQvoh1E2xNkjgBxF3Yh+q8jqdoP6UE8V9HJdWW3D4J1nvnowzUXSbd49hk5tL447sprifk9hyu2ktf+NiiHtkQPoSB47tllsvfl3U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514029; c=relaxed/simple; bh=rAnNEed0QyosxM1+/rEkio2/Gl92Wp46IZzRHEGrWcg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=P7O/nd0vsPIpwydJ2IG+Yt10AJ3Hn4iv2siBiMNXA89a96Z/1yyS65PAdqR9LVZD+vvpG6RyNanGQS06ne05J1eoG7PLYE/L1HwIV0HoxrcakxbGnK4INE7POTKtpccNxP2vDu+nFFODIK60VzNlfiUkk3Iyx1PKb51aM5RJMq4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=O32pOZb8; arc=none smtp.client-ip=209.85.216.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="O32pOZb8" Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-38f0f3c8da5so137028a91.3 for ; Fri, 31 Jul 2026 09:07:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785514027; x=1786118827; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=SgtLwC7ZO4crIImA5wZcdV4RpLWyizWcscAs4EEf7Ps=; b=O32pOZb8KLYjG5KwYyWumx5tGuJYd+Ekt8+2FNolV9GxzEhQvpFMUPZkRPnXLfO+zo Hd/gNZJbRUK8PuZCvunE/vBwP4MZjw0VC/SWynpKOEf9BjWg84+pwl7hSK1Ndt5SKIyE envbM8kcqcHOF+BiUnHnIwz7RGY7AD02P7Oonf0iN8o9mJAJNrgJuwt2+sacP1RRBztf NSgpO96gqNO6bHTa+82rPjXJpZY5rN67FrOmCwyOWaQyJuidxUREDGZK1fv+BO72OtMw 0+ZDG3I6y/XJuKLLby/9PRKY78k55iNcjXWVaDuRX26lUUeESo+GOJr0AId5LAE8nmgp ezvw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785514027; x=1786118827; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=SgtLwC7ZO4crIImA5wZcdV4RpLWyizWcscAs4EEf7Ps=; b=QfzZrKFXWS5ZTEoeU+/oxUgIXiDTVEKAuAu/C6IVbnL0G8sfhhhT5VcXSDVR8if/4y RQlV2s0WHSTjuPRlSBuo9z7JtbXEGCer+IxX/Z4ltg/+uKW76mfpEjeAoKFqMsiut4Sp o+wDg1XGWmaYKjXbtHKw3dyiz8qexwEgHueoZIFw7BBGOmqkHqvsWhOIEnlGOFlAekB3 BXMpHr//B1ZBCshIa504no3WqwzHt1NS6hKyignN3JaV1kKIQwyBGF8TTvuHc1tzna0b QZ8UqnzHo4lwOPPZe6SGzb92bjX1lGMTtLiPxMYR19VeLbzn+Cjo9ebwVvU3vqK9Hnwq mTrg== X-Forwarded-Encrypted: i=1; AHgh+RrGHCnm3woKE76nzyHRXb2cmh7/vUd7/KUAmxeVNAjwDyYhewIbF2mxyDpjyyydtR1lzfTt2fHc+ByF32o=@vger.kernel.org X-Gm-Message-State: AOJu0YzkBUY8Zljy3C+R0xpWqoYFmuppF/R0QpjIc152vTtK23uw8Hx5 RkuF68Vw/7AlKFShlwEhCd7Fbv8yx+wj4zffn47eM3pIWOW+xfnLJE4COfQDv64qS4o= X-Gm-Gg: AR+sD13lLLCCxdACJhqO3jUofLjWeF1ggWkEmcBeXuh5Ar+KCxmX64yhfRQmYJntqPa qefQ7uyTZYzIolXNX7EG04dVsQIIWcHBm/wX8g3NPQSSR6zAyyeLJzJn8GwX2BQBDM1238km6sO 0gZesyRW+NdCdXjYKOizDbiLtVTiOs74KqIOgaOShiwZyWtBH+B6UjLfmKspyAk3AxQPY4VfvpL PEXKFDdRkJc62McBhXe2Mc1lBcUwaf+WpcDRvZr94FyiQP+3lh2TLT2JGnRP95WCqDE0hdSKACq HTIA1NvcJBRHiIsXQ2KORGwITvl4p+eIriBDCDIo9Sn+64li4sgI86nSVNXnn8tx+7w7GPu5n/7 4g3gD1/UENKCixutIz2WhD9XoQPEe6QN8b1DyFjVcRlqfZO+jVZgupKXD3Foe1/tC28KDII0Nth zphelDWUwA4N6GFrfGtesWkvAjjVEg3yf9V1H9iOrkdkFmN4cMGeNTRUYaBIZjIMIPu9JsHsf9+ kWmPIlI X-Received: by 2002:a17:90b:3c50:b0:381:2788:a437 with SMTP id 98e67ed59e1d1-38fbc3ffa28mr645926a91.1.1785514027354; Fri, 31 Jul 2026 09:07:07 -0700 (PDT) Received: from Potato.tail66a299.ts.net ([171.76.83.76]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3153dd9c93dsm7881425eec.8.2026.07.31.09.07.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Jul 2026 09:07:07 -0700 (PDT) From: Shivesh To: arend.vanspriel@broadcom.com Cc: linux-wireless@vger.kernel.org, brcm80211@lists.linux.dev, brcm80211-dev-list.pdl@broadcom.com, linux-kernel@vger.kernel.org, Shivesh Subject: [PATCH v4 5/8] wifi: brcmfmac: msgbuf: fix TX stall and tune buffer/threshold constants Date: Fri, 31 Jul 2026 16:06:22 +0000 Message-ID: <20260731160646.3812-6-chanelshivesh@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260731160646.3812-1-chanelshivesh@gmail.com> References: <20260731160646.3812-1-chanelshivesh@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Three related changes: 1. Fix silent TX stall under high load brcmf_msgbuf_schedule_txdata() used set_bit() followed by a conditional queue_work(). When outstanding_tx >=3D DELAY_TXWORKER_THRS and the flow_map bit was already set by a previous call, no new work item was queued. If the existing worker had already run and cleared its flow_map bits, the freshly enqueued frame would sit unsent until an unrelated event woke the workqueue. Replace set_bit() with test_and_set_bit(). If the bit was clear, a worker must be scheduled unconditionally. If the bit was already set, the existing coalescing heuristic applies. 2. Increase NR_TX_PKTIDS from 2048 to 4096 The 2048-entry TX packet-ID pool exhausts under >=3D 4 concurrent iperf3 streams on Wi-Fi 5/6 devices, causing "No PKTID available" drops and TCP retransmits. 4096 provides headroom for high- aggregation workloads (~48 KB of additional host memory). 3. Raise TX flush thresholds from 32/96 to 64/128 Doubling CNT1 and CNT2 halves the PCIe doorbell rate on sustained TX workloads. Latency impact on low-rate flows is negligible because TRICKLE_TXWORKER_THRS (32) still causes a schedule before 64 frames accumulate. 4. Replace msleep(10) with usleep_range() in init buffer fill loop The post-attach RX buffer fill loop slept for at least 10ms per iteration (often 20ms+ due to jiffy granularity). Convert to usleep_range(1000, 2000) and increase the retry limit from 10 to 100 to preserve the same 100ms total budget with much lower latency on fast hardware. Signed-off-by: Shivesh --- .../broadcom/brcm80211/brcmfmac/msgbuf.c | 69 ++++++++++++++++--- 1 file changed, 61 insertions(+), 8 deletions(-) diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/msgbuf.c b/dr= ivers/net/wireless/broadcom/brcm80211/brcmfmac/msgbuf.c index ba1ce1552e0f..8db6167072da 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/msgbuf.c +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/msgbuf.c @@ -48,7 +48,19 @@ #define MSGBUF_TYPE_LPBK_DMAXFER 0x13 #define MSGBUF_TYPE_LPBK_DMAXFER_CMPLT 0x14 =20 -#define NR_TX_PKTIDS 2048 +/* + * NR_TX_PKTIDS: number of simultaneously in-flight TX packet IDs. + * Each outstanding TX frame consumes one ID until the dongle returns + * a TX-status completion. The original 2048-entry pool exhausted under + * =E2=89=A54 concurrent iperf3 streams on Wi-Fi 5/6 (802.11ac/ax) devices, + * causing "No PKTID available" drops and TCP retransmits. 4096 gives + * headroom for high-aggregation scenarios while still fitting in a + * modest amount of host memory (~48 KB for the pktid table entries). + * + * NR_RX_PKTIDS: RX post buffers pre-allocated to the dongle. 1024 is + * sufficient for current hardware RX ring depths; leave unchanged. + */ +#define NR_TX_PKTIDS 4096 #define NR_RX_PKTIDS 1024 =20 #define BRCMF_IOCTL_REQ_PKTID 0xFFFE @@ -64,8 +76,29 @@ #define BRCMF_MSGBUF_PKT_FLAGS_FRAME_MASK 0x07 #define BRCMF_MSGBUF_PKT_FLAGS_PRIO_SHIFT 5 =20 -#define BRCMF_MSGBUF_TX_FLUSH_CNT1 32 -#define BRCMF_MSGBUF_TX_FLUSH_CNT2 96 +/* + * TX flush / doorbell-ring thresholds. + * + * CNT1 is the minimum number of frames to accumulate in the commonring + * before the first intermediate write_complete() (doorbell ring) is + * issued mid-batch. CNT2 is the hard flush interval: after this many + * frames have been written since the last flush, we unconditionally + * ring the bell and reset the counter. + * + * Raising both from the original 32/96 to 64/128 doubles the average + * number of TX descriptors committed per MMIO write, halving the PCIe + * doorbell rate on sustained throughput workloads. The tradeoff is a + * marginally higher worst-case latency for the last frames in a burst, + * which in practice is hidden by the time the dongle DMA engine drains + * the previous batch. + * + * TRICKLE_TXWORKER_THRS governs how often brcmf_msgbuf_tx_queue_data() + * forces a workqueue schedule when the queue depth is not a multiple of + * this value. Keeping it at half of CNT1 (32) preserves responsiveness + * for low-rate flows (e.g. VoIP, ICMP) that never accumulate 64 frames. + */ +#define BRCMF_MSGBUF_TX_FLUSH_CNT1 64 +#define BRCMF_MSGBUF_TX_FLUSH_CNT2 128 =20 #define BRCMF_MSGBUF_DELAY_TXWORKER_THRS 96 #define BRCMF_MSGBUF_TRICKLE_TXWORKER_THRS 32 @@ -787,10 +820,30 @@ static int brcmf_msgbuf_schedule_txdata(struct brcmf_= msgbuf *msgbuf, u32 flowid, { struct brcmf_commonring *commonring; =20 - set_bit(flowid, msgbuf->flow_map); + /* + * If the bit was already set, a txflow_work item is already + * queued or running for this ring. In that case the existing + * worker will drain our freshly enqueued frame when it runs, + * so we only need to schedule another work item when the + * force flag is set or the ring is below the delay threshold. + * + * If the bit was NOT set (test_and_set_bit returns false), no + * worker is pending for this ring at all. We MUST schedule + * one unconditionally, otherwise the frame we just enqueued + * will sit in the flowring unsent until some unrelated event + * triggers the workqueue =E2=80=94 causing silent TX stalls under + * high load when outstanding_tx >=3D DELAY_TXWORKER_THRS. + */ + if (!test_and_set_bit(flowid, msgbuf->flow_map)) { + /* Bit was clear: no worker pending, always schedule. */ + queue_work(msgbuf->txflow_wq, &msgbuf->txflow_work); + return 0; + } + + /* Bit was already set: worker pending, apply coalescing heuristic. */ commonring =3D msgbuf->flowrings[flowid]; - if ((force) || (atomic_read(&commonring->outstanding_tx) < - BRCMF_MSGBUF_DELAY_TXWORKER_THRS)) + if (force || (atomic_read(&commonring->outstanding_tx) < + BRCMF_MSGBUF_DELAY_TXWORKER_THRS)) queue_work(msgbuf->txflow_wq, &msgbuf->txflow_work); =20 return 0; @@ -1621,11 +1674,11 @@ int brcmf_proto_msgbuf_attach(struct brcmf_pub *drv= r) do { brcmf_msgbuf_rxbuf_data_fill(msgbuf); if (msgbuf->max_rxbufpost !=3D msgbuf->rxbufpost) - msleep(10); + usleep_range(1000, 2000); else break; count++; - } while (count < 10); + } while (count < 100); brcmf_msgbuf_rxbuf_event_post(msgbuf); brcmf_msgbuf_rxbuf_ioctlresp_post(msgbuf); =20 --=20 2.53.0 From nobody Fri Oct 2 12:19:52 2026 Received: from mail-pj1-f44.google.com (mail-pj1-f44.google.com [209.85.216.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3BC3A44AB8D for ; Fri, 31 Jul 2026 16:07:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.44 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514032; cv=none; b=ManeITnUgWE1mp4kajCt6I7wXwFqKk19GOnBiL3oWJgGBOt727QH0ngik5PBEZ65lV4lNFFImWjKN/SdndJHMrH4HIYXyhpTu+APEbMUrzL/6qD4imUYxd1yD/hbxhLH4zajfUm+WN4e8tCqtJHEpnbgp2W5icKbCjqP12PTRHg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514032; c=relaxed/simple; bh=+EEZHSVtxvI8sBTxmE1ATnsB2rk61KuaQLlBtFDwhfY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=CrtN+yBvLNS3qnBXHw4VWl2iwIT8MM78fXRtRb1R4sURboF2Gb8Zfuj0daEZweMLVze/sa4ugQVbfoqOyogeSu0FUnQFEUdT1k1BQC6h1Ajg5tTDOa/N/HpuyTFEqDgAvOGLIErwPcWoNBrfVNc0WGxg9gZ47MLmofl5T85YEWk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=hHH51q6d; arc=none smtp.client-ip=209.85.216.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="hHH51q6d" Received: by mail-pj1-f44.google.com with SMTP id 98e67ed59e1d1-38115bbb83dso50037a91.3 for ; Fri, 31 Jul 2026 09:07:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785514030; x=1786118830; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=sR/djYwS2eYkXntdPLamATqE5su3p7aKJoAI8mED+Wg=; b=hHH51q6dPQyu1u8+v6B05L7GJvezelvOdsHQMsxP/07QTiTBJFvMzUmwzozcZBQ1Xd F0vgFb4BuGQcJrjUemcmpJbeNy1x5r4s5NQCLMnMaNJQmQb51gz+gBaI4M86Om5/Ev3x oZgCZGOmXiTJoNm6fgg0jxOiPAoRIAIGJHNUq0u4iRPRs6RSFT0YBCa01/jkJklZxZkq TtCe58HX5OsZIrnhE+N+iQLzRZZZxC4XqysyGu0894t/C+Chqnv62jK8IjGCht4IyWNK SKtQDq77TE9HF/54Zj3Tdlobxl4oZJ71yQtpJ7TxbxloniZknupY3gixfYeYe3JdwqHX EuBQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785514030; x=1786118830; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=sR/djYwS2eYkXntdPLamATqE5su3p7aKJoAI8mED+Wg=; b=VOag2HHjkti6FpA8xTAlJY1o+5e2KSXllDtGhzQC3OzHhaTffBykGm9KoaLZL3tutK GqcswfWnaAdJLpJt2lu2gZwFekfTZvpRKp3SJdROpM5O+m3Pd5nfCbnSVBEHAwbuh8wz Xzlg++6RD5QaIy5YI21wyK4OQbDQS0BWaooD2CJbgpGWIwOLeMGNO7llQwMOK93q7QB8 6TitBZUE5dsjg6FlLyThw8VY945J6i7WDoW3o3W4f2NLPhGb/nEHaj77oXtZtAx7twTQ /yenCD4iCnG3mRm+EaIlDABWnfroep+4YHHlXwIksF5XCRSQNE8IP33BmDMFAlAed1Jq tPtw== X-Forwarded-Encrypted: i=1; AHgh+RqF2q3gnSCQIftonmqiHvXTqaaym3yV9gmz7D2JMLiamqxwjImjMuu8AN97pEF1psHfBcqQOsPQdXh+CUo=@vger.kernel.org X-Gm-Message-State: AOJu0Yw0fQswrbSiBg0Nx/yhxvSgvZT7Z6l9WloKayUHOtRyrg7x+V6g jVk05yVLD1x6czRE3ZmuGD69bcLmcaqQ4YUJdznmTKSil7bSvN6Du4UX X-Gm-Gg: AR+sD12KO7N4qos3DVfv/fxnQ2BdSHXOcAVVt4V25mnO2juHlij1dfPhVj4wATViNNd t9vCbWoqaj/cKTeDjEGMMZ7tLB/phxBf3YcF08BOg7a3nNcRqntRgYy5I0W4ZsAGQhnP/a+/KgI lgg9zceJli0gDHOqzpXIQ/Q7v7xbsR8B9Rw4ofiZfnn/CKla55nVfR7HG4vKJres2ipSmkdXe1q +rAgeq58I8q23+fOSnwZKcVBcHsb7NsfDclG/xGJFtWX9IAFTusx23OLD9LlVL7g1QY6maU3Vai 5NbSocqGby5ru/XHYc0d9OepY4cYZDg6EQ+gl1jOEYnlMfA/FI2DmCV44TN84tA6SZad5ad+PJV dkQf53cPpNvZrMe2Xclt2lutQ0ncOkPS9YqFtbZMPk+jau/L0frGw525hBCK0D7vdUod/rGgS0K 286XQZS/LPAKjq49uaalHRXD+G5n5K1KXFo7XIU95mcJHYLAVdw5vsQox4PN907ys/SwLXEKRvu V4Zg6bokEUQTfqCWiY= X-Received: by 2002:a17:90b:520c:b0:38f:aa76:88b with SMTP id 98e67ed59e1d1-38fbc506f17mr600038a91.4.1785514030468; Fri, 31 Jul 2026 09:07:10 -0700 (PDT) Received: from Potato.tail66a299.ts.net ([171.76.83.76]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3153dd9c93dsm7881425eec.8.2026.07.31.09.07.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Jul 2026 09:07:10 -0700 (PDT) From: Shivesh To: arend.vanspriel@broadcom.com Cc: linux-wireless@vger.kernel.org, brcm80211@lists.linux.dev, brcm80211-dev-list.pdl@broadcom.com, linux-kernel@vger.kernel.org, Shivesh Subject: [PATCH v4 6/8] wifi: brcmfmac: pcie: replace msleep polling with usleep_range and backoff Date: Fri, 31 Jul 2026 16:06:23 +0000 Message-ID: <20260731160646.3812-7-chanelshivesh@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260731160646.3812-1-chanelshivesh@gmail.com> References: <20260731160646.3812-1-chanelshivesh@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Two latency improvements: 1. H2D mailbox polling brcmf_pcie_send_mb_data() polled for the dongle to consume the previous H2D mailbox message with msleep(10) per iteration. As the dongle typically clears the register within a few hundred microseconds, each call incurred at least 10ms of unnecessary latency (often 20ms+ due to jiffy rounding). Replace with usleep_range() using exponential backoff: start at ~50us and double each iteration up to 5ms, with a 1-second absolute timeout matching the original budget. Add an early-exit check for BRCMFMAC_PCIE_STATE_DOWN so a dead dongle does not hold the caller for a full second. 2. IRQ teardown polling brcmf_pcie_release_irq() waited for in_irq to clear using msleep(50) in a 20-iteration loop (up to 1 second). Replace with usleep_range(1000, 2000) in a 1000-iteration loop, preserving the same ~1 second maximum while allowing the function to return in microseconds when the IRQ handler finishes quickly. Fixes: 9e37f045d5e7 ("brcmfmac: Adding PCIe bus layer support.") Signed-off-by: Shivesh --- .../broadcom/brcm80211/brcmfmac/pcie.c | 66 ++++++++++++++++--- 1 file changed, 58 insertions(+), 8 deletions(-) diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c b/driv= ers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c index 13662aa4b4ea..9338a5faa260 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/pcie.c @@ -268,6 +268,27 @@ static const struct brcmf_firmware_mapping brcmf_pcie_= fwnames[] =3D { =20 #define BRCMF_PCIE_MBDATA_TIMEOUT msecs_to_jiffies(2000) =20 +/* + * H2D mailbox poll timing parameters. + * + * The dongle typically clears the H2D mailbox register within a few + * hundred microseconds after the doorbell interrupt fires. The + * original code used msleep(10) * 100 iterations, meaning the + * minimum observable latency was 10ms even when the dongle was fast. + * + * We instead start with a short sleep and double it each iteration + * (exponential backoff) up to BRCMF_PCIE_MB_POLL_MAX_US, staying + * within the same 1-second absolute timeout. + * + * MIN_US / INITIAL_MAX_US : usleep_range bounds for the first iteration. + * MAX_US : cap on the per-iteration sleep (=C2=B5s). + * TIMEOUT_US : total budget before giving up (1 second). + */ +#define BRCMF_PCIE_MB_POLL_MIN_US 40 +#define BRCMF_PCIE_MB_POLL_INITIAL_MAX_US 50 +#define BRCMF_PCIE_MB_POLL_MAX_US 5000 +#define BRCMF_PCIE_MB_POLL_TIMEOUT_US 1000000 + #define BRCMF_PCIE_CFGREG_STATUS_CMD 0x4 #define BRCMF_PCIE_CFGREG_PM_CSR 0x4C #define BRCMF_PCIE_CFGREG_MSI_CAP 0x58 @@ -766,7 +787,8 @@ brcmf_pcie_send_mb_data(struct brcmf_pciedev_info *devi= nfo, u32 htod_mb_data) struct brcmf_core *core; u32 addr; u32 cur_htod_mb_data; - u32 i; + u32 elapsed_us =3D 0; + u32 sleep_us =3D BRCMF_PCIE_MB_POLL_INITIAL_MAX_US; =20 shared =3D &devinfo->shared; addr =3D shared->htod_mb_data_addr; @@ -776,12 +798,40 @@ brcmf_pcie_send_mb_data(struct brcmf_pciedev_info *de= vinfo, u32 htod_mb_data) brcmf_dbg(PCIE, "MB transaction is already pending 0x%04x\n", cur_htod_mb_data); =20 - i =3D 0; + /* + * Wait for the dongle to consume the previous H2D mailbox message. + * + * There is no interrupt that signals when the dongle clears this + * register, so polling is unavoidable. The original code used + * msleep(10) per iteration, incurring at least 10ms of latency + * even when the dongle responded in microseconds. + * + * We use usleep_range() with exponential backoff instead: + * - First iteration sleeps ~50=C2=B5s (fast path for responsive dongle= ). + * - Each subsequent iteration doubles the sleep, capped at 5ms, + * so long waits still yield the CPU without busy-spinning. + * - Total timeout matches the original 1-second limit. + * - We bail early if the device has gone down so that a dead + * dongle does not hold the caller for a full second. + */ while (cur_htod_mb_data !=3D 0) { - msleep(10); - i++; - if (i > 100) + if (devinfo->state =3D=3D BRCMFMAC_PCIE_STATE_DOWN) { + brcmf_dbg(PCIE, "Device down, aborting MB send\n"); return -EIO; + } + + if (elapsed_us >=3D BRCMF_PCIE_MB_POLL_TIMEOUT_US) { + brcmf_err("Timeout waiting for H2D MB slot after %u us\n", + elapsed_us); + return -EIO; + } + + usleep_range(BRCMF_PCIE_MB_POLL_MIN_US, sleep_us); + elapsed_us +=3D sleep_us; + + /* Exponential backoff, capped at BRCMF_PCIE_MB_POLL_MAX_US */ + sleep_us =3D min(sleep_us * 2, (u32)BRCMF_PCIE_MB_POLL_MAX_US); + cur_htod_mb_data =3D brcmf_pcie_read_tcm32(devinfo, addr); } =20 @@ -1001,10 +1051,10 @@ static void brcmf_pcie_release_irq(struct brcmf_pci= edev_info *devinfo) free_irq(pdev->irq, devinfo); pci_disable_msi(pdev); =20 - msleep(50); + usleep_range(1000, 2000); count =3D 0; - while ((devinfo->in_irq) && (count < 20)) { - msleep(50); + while ((devinfo->in_irq) && (count < 1000)) { + usleep_range(1000, 2000); count++; } if (devinfo->in_irq) --=20 2.53.0 From nobody Fri Oct 2 12:19:52 2026 Received: from mail-pj1-f44.google.com (mail-pj1-f44.google.com [209.85.216.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AC9FC44781A for ; Fri, 31 Jul 2026 16:07:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.44 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514036; cv=none; b=rHtmjW77PbmL/KEIrCdW8lb8yyDfZkLALQClHSS7KCL7V/JH7Gz6vGYiC8egkqFVNS8O0bSoebEQbTIJa93wEUE9I1lw/oAwe0ll0gxJUve5DuAkWNS4ut6+s7z4y3sTxY12pNCUf7l/SZJwhm2fS5dFxHW8h8CT2n/xoQwO7vM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514036; c=relaxed/simple; bh=X64FuFu6MQR0e9YLwzcqtBlBGkOJCZbkezV6SD9jPJQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=E7yzJn68I1wIci2uoL4tx8/SjIA6/4Vr0qAKeySbl3cGAIUcmTpmGnjoZSd2j4TWRqjwkzbBACmJ16PKbsNFRAaymjCOaxgwrDPV/dlgI8nfWj2Q//vaG+h+08sVNYzwA3lk0inqyAaN1iKgSAwYG/6bvUCbpwQi8P518q/sYZ0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=nnzfgbrs; arc=none smtp.client-ip=209.85.216.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="nnzfgbrs" Received: by mail-pj1-f44.google.com with SMTP id 98e67ed59e1d1-384422b05b5so154017a91.2 for ; Fri, 31 Jul 2026 09:07:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785514033; x=1786118833; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=CVffTg0thpytBoHWaWeNh2vyHkkqNffHnf4NKS93HWw=; b=nnzfgbrsDHEjTm+KtOiHlc2oaDafOoXy76kkLEj+D9Q0vLeqlOTAbjvT1gx1sXV1t2 4a/zD4kNhMVhsHUVyDgWaDPeucuwleym4rPhC7F+9dwSdeYIemLV+TrILBJHqSash00b a6VoC6TBCWNEqSptqhI8u/2kxsO4t0Cph98xXZCn6w3cMuR8QGUQKJcTkkdZGEqasHSm q9RW5JwW9x3fxX46lRrJLHwZt57iZVqPvBXi+wwkt5L9OOPRhIeJ9OOZb/EC/2LFE7I+ TKK1j907e0tUCKF/kdUOt6i9WcWi4dtXDT6qIykoIRn0SX8PTM2OFmdo+ZXycBZ1sS6I 3cTQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785514033; x=1786118833; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=CVffTg0thpytBoHWaWeNh2vyHkkqNffHnf4NKS93HWw=; b=SdesUH9wt8Twqow8fhQciOsT31CZMF84+oHlNG+fOIZKqfNlxMQSw+s3MZWAi3751+ O6LP2iHBTF9ygXq2dtiNcryCwtwwD4fr0Gp75vd4k1SwWHDQTej0GoA0u2PIwKfsjPPk 5711apD5mRwtGhME3Ao+HgGccm8kngorhYaHuS+3FqjtXQS7sP9oRtp5ScbFUfCTA/sr kCXLwTHM8JreOhWDcueqf4/BYNRVNWKnzuzjCQgosC7TftilW4F4TPwZdHpIU+DgFOpv h7IY9vzuVWaaJSLcgYNjBjgM8bul4LY3dRre536h5X3KCq5c0u2toix3Ks91PN/VsnwC Yzsw== X-Forwarded-Encrypted: i=1; AHgh+Ro9W0YNh9akKRRbRt5xJ/6IN6VbJKL7h3GpQDuteZSdo2qpWwRt3TXN7JOHref7UVTjacWSPBC43lmHm9w=@vger.kernel.org X-Gm-Message-State: AOJu0Yy7ZTMxduqrmx8IGN8k+AdqiziCndXb7d/V8DYpzudUMs0HWdGx YJ88XSm0EyQvXYK5nPI0KLDe3Q4kk/WTPx9fbY1OgGrYEM5dCXdr7jXe X-Gm-Gg: AR+sD11R7TRcPtTboH+INpbt/9VeZ7jZmxyFriVD4HpcWK/0Jaoq3DgY9eIsYmrpNdp FXb6Rnkiotgv72GFdjRhVD78V6QvTdgh82ZYSIJIZz7aGq8Lc7tnQlkndV/Flu51OTkU4fVvoP0 3fvb8iyJdRPsU4USZtVROI0ZwaN0uIDNrQp6qHItvGRz9TCdSVTtWfNBrRKGSW8A5XwGi3rRnvT 8DzqzEC/HAxQIl8Rl9GEMPQp0lv2RREp7TJ67xObVHBbu0YIp+N/o4BOYQFYSr5/XpvX0vDHMXT Xg8e2P0fFjY+al9XkAIoasiVtCDK70khyZh4/8KIBoW1M2Y704PZvIdklRpaeYwBUWcaQAS0WPt SSr1hkyXqxfE/7o7MDNaNCvJIS/pYkwe2VC6Ileu5dmVxD39UkCXJU6WS3t9NEj9Dlh3Befaoxw UgHt/a9xeca6wyhZigm/ptdbH4JL7ZmK3ZwoEFpDYU31TzxmbvEN9nabK9VtgBiFj2Zc41yFSqk K/jDw/6 X-Received: by 2002:a17:90b:51c3:b0:38e:6a7c:abbc with SMTP id 98e67ed59e1d1-38fbc5482f1mr684483a91.3.1785514033358; Fri, 31 Jul 2026 09:07:13 -0700 (PDT) Received: from Potato.tail66a299.ts.net ([171.76.83.76]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3153dd9c93dsm7881425eec.8.2026.07.31.09.07.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Jul 2026 09:07:13 -0700 (PDT) From: Shivesh To: arend.vanspriel@broadcom.com Cc: linux-wireless@vger.kernel.org, brcm80211@lists.linux.dev, brcm80211-dev-list.pdl@broadcom.com, linux-kernel@vger.kernel.org, Shivesh Subject: [PATCH v4 7/8] wifi: brcmfmac: fwsignal: document safe no-op for duplicate MAC handle ADD Date: Fri, 31 Jul 2026 16:06:24 +0000 Message-ID: <20260731160646.3812-8-chanelshivesh@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260731160646.3812-1-chanelshivesh@gmail.com> References: <20260731160646.3812-1-chanelshivesh@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When the firmware sends a MACDESC_ADD event for a MAC address that is already registered to the same slot (same mac_handle), the driver hit a TODO comment with no documented rationale. Per the firmware protocol, retransmitting an ADD for an existing handle is idempotent; overwriting the entry or reinitialising it would drop in-flight traffic queued in the per-descriptor psq. Replace the TODO with an explanatory comment so the intent is clear to future readers and static analysis tools do not flag the empty branch as dead code. Signed-off-by: Shivesh --- drivers/net/wireless/broadcom/brcm80211/brcmfmac/fwsignal.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/fwsignal.c b/= drivers/net/wireless/broadcom/brcm80211/brcmfmac/fwsignal.c index a43f1a38b0e3..3c1ca355e8ee 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/fwsignal.c +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/fwsignal.c @@ -1037,7 +1037,9 @@ int brcmf_fws_macdesc_indicate(struct brcmf_fws_info = *fws, u8 type, u8 *data) } else { brcmf_dbg(TRACE, "use existing\n"); WARN_ON(entry->mac_handle !=3D mac_handle); - /* TODO: what should we do here: continue, reinit, .. */ + /* Firmware re-sent ADD for the same MAC handle. + * No action required; it is a safe no-op. + */ } } return 0; --=20 2.53.0 From nobody Fri Oct 2 12:19:52 2026 Received: from mail-pl1-f173.google.com (mail-pl1-f173.google.com [209.85.214.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6506844E64F for ; Fri, 31 Jul 2026 16:07:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.173 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514040; cv=none; b=GTJLHn5E/Lci8nP7MdmOWmcNkemWLyKvBqNtv/g3Yow3t6OYL/lM3qKX4PD+C0fDr0NauRMbgHdzh27rfb+G1suNs9BTsLxovq6Br+p1iVbv6C+B5Nmh3WiodLUMehIHCktOKbeI1NR1I4BfktP2ItCk/MUSFfyz9548CgVLgXo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785514040; c=relaxed/simple; bh=DmsA+3I5O345ejfdJMX1ludXGRJbR24/40vzzaBvEHs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=X7dPePy1VRVl7EJkRX7vWVCLunmw/biAUGSqUJrRz7TSDc2X0ei1d3VMgZJipLxrPvVfpRSKifFn6Rnsll6RRXpv3BRbPTbe4m33qRc1sj7ziyCrMk0zwRx4l7+pxICg1BgloTwRFdxL/zoq9qCGZK5wci1o1xtsBCudj8FN3JA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=TQm0uBGj; arc=none smtp.client-ip=209.85.214.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="TQm0uBGj" Received: by mail-pl1-f173.google.com with SMTP id d9443c01a7336-2d027b7c8easo1889945ad.3 for ; Fri, 31 Jul 2026 09:07:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785514036; x=1786118836; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Ha6wWqh8e5w28XKTvBv40AUTfoBMdtclGObPHlJlp0Y=; b=TQm0uBGjkzoIJ4u/c3kQhaHzOl4KyGxbxI2/VgOO5innIdJkWL/NRbGaLNjxOR+gwW iL6qXprxYJzsVNv3UNEHHI6ZHb28CC9K4QYytSVEok8mkeRC5kVsQZ4YUxk3p+6bz8si 2QAQII+P1iWD4Xf6b1RFwDVwk2ye/MmLIkNo7MxFcnER+r5BtJBv+BS+uATGlr4Yvy+l BqD5izNqwXMQoi3P584MlihjK+UTypuyEq6V/zTlIQk+/tbsscxscQdm33acMEzZNz4e ezgk/YamTVK4bOMt/o0iMIXi+fBQwt8JPjsu4Amssrk6EtBzHyyOR5SLRGiiPZWDvf2p X65w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785514036; x=1786118836; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Ha6wWqh8e5w28XKTvBv40AUTfoBMdtclGObPHlJlp0Y=; b=s9SZJCoVgzgWV3kVpH/XoUJCqU4nUvXJ3lMI+kMwwDuWSTzCV3om4MMxuWCk72BpTY t+M2UxQP2tQ7F2efKXc5T29gf6Nns8MGB5qPKbTViEIE5tnltOUV/ZG4qwm6DXLMFqL4 N6Dfsx5SCSa3v0xA0As7IJTxRtHWof0mWoXwslRtNKhiH8QC47NS1fUCCVbAIpt2HeUs +OByJV8VBzwq/NZP+qK1p93wlgx1iBwHscI/fJDs65gcmQdGkF1Mww+B1PQW5ssklTvu 4G9uRsIwnNynMv5slIlKtMnHrZkgP1J+z/jeSTFRrTy9/OpvPEK84Yo40PjqG8VCnoXc mQ+w== X-Forwarded-Encrypted: i=1; AHgh+RqUiHTVEXehvxNu96Wgg6uLq13QQq0EMxa4/XYJn6DaOUJz0t3YeA46XTLfZ32hB/xT2FDZMNMZi8PrdNA=@vger.kernel.org X-Gm-Message-State: AOJu0YyITsA7AC5xBR2+fM+HTCxKXdo5fghaxvWKHbYc+rvJNtAwoh0P HjIlzwFCu1LP/FXacO9eylzcPPf9yjOLRaBYlFsbBfbRZZRNoEqeI9oN X-Gm-Gg: AR+sD11f4NBQP//yNFJ5KcSReN4yFxZJ9aFuAQj9Qs/vtRFM6zZ+ymEdfKPCvYnClPp cCSYN5DV3yNcyX3c9DZMwzlxw9TpzgO1AkiVzA55aGFYNsMxcrL5bXgXbZfSQxMU2kMVyvd7OYj dGDxU1suibuFVGXB6XXmByi8Fewy+lwW1P59mcyZ7+8WZSaBZQmvKK/tQJYxgEUe9m6AiGm1Tat TifQVZTRMUQ/BVTHIF7Ijy56XNFEmKExakWBo6MZp9oS7IWLxq/lr6ZYgty4hu8je8khRnEFhZd JUY12/FfPurJMKQA9QZg47xRCFjjjwTw9+pg3jkbG2odTSP8r8UFYYs5yhe7xA7ivdY8fv8bT8k HzDTE6DH7TDT0GaXCvYQKoWLEaoy3YSwxLgCbH2h9AN9Mo/pX7HfkuGR0XSs/+g7FCW+qKwA+nQ Z5nvKydrTcFrWt1/7cO2AVRWgVJXP0VG4iYQ7F0HW0fqPV4xyqGNFxs4MLV7bCVbxv5ShgQ6Oxj mtY6Hbvnw== X-Received: by 2002:a17:903:1450:b0:2c9:d298:6c0a with SMTP id d9443c01a7336-2d05246fbb8mr8606555ad.2.1785514036370; Fri, 31 Jul 2026 09:07:16 -0700 (PDT) Received: from Potato.tail66a299.ts.net ([171.76.83.76]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3153dd9c93dsm7881425eec.8.2026.07.31.09.07.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Jul 2026 09:07:15 -0700 (PDT) From: Shivesh To: arend.vanspriel@broadcom.com Cc: linux-wireless@vger.kernel.org, brcm80211@lists.linux.dev, brcm80211-dev-list.pdl@broadcom.com, linux-kernel@vger.kernel.org, Shivesh Subject: [PATCH v4 8/8] wifi: brcmsmac: ampdu: document IEEE 802.11n TID requirement Date: Fri, 31 Jul 2026 16:06:25 +0000 Message-ID: <20260731160646.3812-9-chanelshivesh@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260731160646.3812-1-chanelshivesh@gmail.com> References: <20260731160646.3812-1-chanelshivesh@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" An XXX comment in brcmsmac_ampdu_tx_add() questioned whether it is necessary to reject frames whose QoS priority differs from the current A-MPDU session. IEEE 802.11n (IEEE Std 802.11-2012, section 9.10.1) requires that all MPDUs within an A-MPDU carry the same TID; mixing TIDs would violate the Block ACK agreement and cause receiver-side reassembly failures. The existing behaviour of returning -ENOSPC to close the current aggregate and start a new one is therefore required by the standard. Replace the questioning XXX with a comment referencing the standard. Signed-off-by: Shivesh --- .../wireless/broadcom/brcm80211/brcmfmac/cfg80211.c | 1 - .../net/wireless/broadcom/brcm80211/brcmsmac/ampdu.c | 11 +++++------ 2 files changed, 5 insertions(+), 7 deletions(-) diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c b/= drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c index 2375c2f9d97a..dc4228fb31c1 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c @@ -4464,7 +4464,6 @@ brcmf_pmksa_v2_op(struct brcmf_cfg80211_info *cfg, st= ruct brcmf_if *ifp, return brcmf_fil_iovar_data_set(ifp, "pmkid_info", list, sizeof(*list)); } =20 - static __used s32 brcmf_update_pmklist(struct brcmf_cfg80211_info *cfg, struct brcmf_if *ifp) { diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmsmac/ampdu.c b/dri= vers/net/wireless/broadcom/brcm80211/brcmsmac/ampdu.c index fc7a5dd2e5d8..3fd8bdbd35e5 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmsmac/ampdu.c +++ b/drivers/net/wireless/broadcom/brcm80211/brcmsmac/ampdu.c @@ -516,12 +516,11 @@ int brcms_c_ampdu_add_frame(struct brcms_ampdu_sessio= n *session, return -ENOSPC; =20 /* - * We aren't really out of space if the new frame is of - * a different priority, but we want the same behaviour - * so return -ENOSPC anyway. - * - * XXX: The old AMPDU code did this, but is it really - * necessary? + * IEEE 802.11n standard requires that all MPDUs within an + * A-MPDU belong to the same TID (Traffic Identifier). + * Since priority maps to TID, a different priority means + * we must close the current aggregate and start a new one, + * so we return -ENOSPC here. */ first =3D skb_peek(&session->skb_list); if (p->priority !=3D first->priority) --=20 2.53.0