From nobody Sat Sep 26 19:33:47 2026 Received: from mta0.migadu.com (out-188.mta0.migadu.com [91.218.175.188]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4D53E39D6CA for ; Mon, 31 Aug 2026 06:12:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.188 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788156726; cv=none; b=S1WOaBzrp42Uz1iO5y0tSnTbxs7f5fK4eio/rtCpXIk4g+Xxi0SceOL3QOk2GajKk+AdBc/gW/EKna3LGdClV70WZn7b48F6B2SAY0wimd/m19u5U45Jjk0wCDnH/jwaHqHt5Ck+Ywi0a/yZN0QIcWlxtjRDEq+iagV5L/1QnUU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788156726; c=relaxed/simple; bh=vclbbxrEXBh2L03+0rbD5hWawomsUAw6S4F76/NZMP4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Jqs8SKwkO4mSyWg1q5Qj1Z0m631kyEGYnMt9VIN9aBPAE2Gh69YAu60fIFhEfcLvpI9U31k6NZgoAzdq43jrowUdqEI4zY1cEHzts3ClrrfopnLnhZsUWasKf7grfcngfpox9VuLlSPkN/UwoZdbH/+z/g/0BLDGv24cpoL/UBg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=mrEXTzAi; arc=none smtp.client-ip=91.218.175.188 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="mrEXTzAi" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=vclbbxrEXBh2L03+0rbD5hWawomsUAw6S4F76/NZMP4=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1788156720; v=1; x=1788761520; b=mrEXTzAihqwHWERl1PfC8HEjkFQjZyWbYgPYWU61uB/YfgFTelgOQ/V4gXkIN3G6l1ZPgzQ1 W+hCIzz0UzVvtnIGE6V2JHLgQLsZh6WKSyLUQe8WpfrXMAt3mfdLUeQGOfWpqF2whz/OeE7HXlg XROdE7T6gXfz5Oe1pNH8/9vU= X-Envelope-To: linux-kernel@vger.kernel.org Received: by smtp.migadu.com with ESMTPS id 92e85d5713bf910f; Mon, 31 Aug 2026 06:12:00 +0000 X-Mizu-Trace-ID: 92e85d5713bf910f X-Migadu-Flow: FLOW_OUT From: luka.gejak@linux.dev To: Ping-Ke Shih , linux-wireless@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Michael Straube , Bitterblue Smith , Peter Robinson , Hans de Goede , Luka Gejak Subject: [PATCH v9 1/6] wifi: rtw88: add the RTL8723B chip type and SDIO helper Date: Mon, 31 Aug 2026 06:11:39 +0000 Message-ID: <20260831061144.18631-2-luka.gejak@linux.dev> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260831061144.18631-1-luka.gejak@linux.dev> References: <20260831061144.18631-1-luka.gejak@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Luka Gejak The RTL8723B is a 802.11n combo chip whose SDIO variant, RTL8723BS, runs a Realtek vendor firmware that differs from the firmware used by the other rtw88 8723 family devices. Supporting it needs a number of small adjustments spread across the shared core, all of which have to be restricted to this one chip and bus combination. Add the chip type and a helper that tests for it, so the changes that follow can be gated without repeating the chip and bus comparison. Signed-off-by: Luka Gejak Acked-by: Ping-Ke Shih --- Notes: Changes in v9: none. Changes in v8: none. Changes in v7: none. Changes in v6: none. Changes in v5: none. drivers/net/wireless/realtek/rtw88/main.h | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/drivers/net/wireless/realtek/rtw88/main.h b/drivers/net/wirele= ss/realtek/rtw88/main.h index c6e981ba7986..8f86f7c12de5 100644 --- a/drivers/net/wireless/realtek/rtw88/main.h +++ b/drivers/net/wireless/realtek/rtw88/main.h @@ -194,6 +194,7 @@ enum rtw_chip_type { RTW_CHIP_TYPE_8723D, RTW_CHIP_TYPE_8821C, RTW_CHIP_TYPE_8703B, + RTW_CHIP_TYPE_8723B, RTW_CHIP_TYPE_8821A, RTW_CHIP_TYPE_8812A, RTW_CHIP_TYPE_8814A, @@ -2194,6 +2195,12 @@ static inline bool rtw_chip_has_tx_stbc(struct rtw_d= ev *rtwdev) return rtwdev->chip->tx_stbc; } =20 +static inline bool rtw_is_8723bs(struct rtw_dev *rtwdev) +{ + return rtwdev->chip->id =3D=3D RTW_CHIP_TYPE_8723B && + rtwdev->hci.type =3D=3D RTW_HCI_TYPE_SDIO; +} + static inline u8 rtw_acquire_macid(struct rtw_dev *rtwdev) { unsigned long mac_id; --=20 2.53.0 From nobody Sat Sep 26 19:33:47 2026 Received: from mta1.migadu.com (out-52.mta1.migadu.com [95.215.58.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B595A2BCF46 for ; Mon, 31 Aug 2026 06:12:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.52 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788156733; cv=none; b=YXBXmfcsF4lHoIyfXM5nOkbEwNGYNbOX7BEjEVvJhTJrQKYZOE2tGgl7hDllcoDTGbSKcTDPTwjS2IO98OK5h6Q8pzJJEE7EqxuAr5y7Sp/GvqdK8OVIpXw+6ypVj3nLfWOEC7Sjoo8tH2zS563DuW/HMp6OExk+GLoQPzAf40k= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788156733; c=relaxed/simple; bh=EzLfWy6AHQnq33EcVIOFY8v0KxYz34L3rC3KooYUqKI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=SDIEsj5TaqipG37q+QjdNfoiWSb94z67TnvjSlbMhGd3Onz5BZ+rrJqVFabUng7Q/H5QHcmPphq8Q0EUb9LDhK92O/HmSeJTuPe79SnMIVuk47f7YC4LarW/VDf1CJBKnZv0tD2TZNs95nnZkaW+KaapdiWti/Qx4F0puycPn3s= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=g5OBdhDo; arc=none smtp.client-ip=95.215.58.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="g5OBdhDo" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=EzLfWy6AHQnq33EcVIOFY8v0KxYz34L3rC3KooYUqKI=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1788156726; v=1; x=1788761526; b=g5OBdhDoDhVSdrgCIyXho3HesbuvCjgGczPnnuTBkxTBCtpua9rJ+Hx/T+4JBjOXcdeYppsz KibjfEwVG6MoxEFydU8qw4HbSmMnWCwmPhGj8WMN2KZ6LnY6C5Tk0VLiPDH3baze/gKq6NFXwYu pJIKqJgrIilbNBiB9kZVdcz4= X-Envelope-To: linux-kernel@vger.kernel.org Received: by smtp.migadu.com with ESMTPS id 192e6d74ed31113e; Mon, 31 Aug 2026 06:12:06 +0000 X-Mizu-Trace-ID: 192e6d74ed31113e X-Migadu-Flow: FLOW_OUT From: luka.gejak@linux.dev To: Ping-Ke Shih , linux-wireless@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Michael Straube , Bitterblue Smith , Peter Robinson , Hans de Goede , Luka Gejak Subject: [PATCH v9 2/6] wifi: rtw88: rx: mark zero length packets on RTL8723BS Date: Mon, 31 Aug 2026 06:11:40 +0000 Message-ID: <20260831061144.18631-3-luka.gejak@linux.dev> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260831061144.18631-1-luka.gejak@linux.dev> References: <20260831061144.18631-1-luka.gejak@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Luka Gejak Like the RTL8703B, the RTL8723BS reports receive descriptors with a zero packet length, which the vendor driver drops outright. rtw88 already flags these as having no PSDU for the RTL8703B, so extend the same handling rather than passing an empty frame up. This is gated on the SDIO interface rather than the chip id, because it has only been observed there; the USB variant is not known to do it. Co-developed-by: Michael Straube Signed-off-by: Michael Straube Signed-off-by: Luka Gejak Acked-by: Ping-Ke Shih --- Notes: Changes in v9: none. Changes in v8: none. Changes in v7: none. Changes in v6: none. Changes in v5: the zero length test now evaluates pkt_stat->pkt_len first, so the unlikely case short circuits before the chip test. drivers/net/wireless/realtek/rtw88/rx.c | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/drivers/net/wireless/realtek/rtw88/rx.c b/drivers/net/wireless= /realtek/rtw88/rx.c index 01fd299abb7f..fde21c840ac0 100644 --- a/drivers/net/wireless/realtek/rtw88/rx.c +++ b/drivers/net/wireless/realtek/rtw88/rx.c @@ -253,10 +253,12 @@ static void rtw_rx_fill_rx_status(struct rtw_dev *rtw= dev, =20 rtw_rx_addr_match(rtwdev, pkt_stat, hdr); =20 - /* Rtl8723cs driver checks for size < 14 or size > 8192 and - * simply drops the packet. + /* + * Rtl8723cs and rtl8723bs drivers check for size < 14 or size > 8192 + * and simply drop the packet. */ - if (rtwdev->chip->id =3D=3D RTW_CHIP_TYPE_8703B && pkt_stat->pkt_len =3D= =3D 0) { + if (pkt_stat->pkt_len =3D=3D 0 && + (rtwdev->chip->id =3D=3D RTW_CHIP_TYPE_8703B || rtw_is_8723bs(rtwdev)= )) { rx_status->flag |=3D RX_FLAG_NO_PSDU; rtw_dbg(rtwdev, RTW_DBG_RX, "zero length packet"); } --=20 2.53.0 From nobody Sat Sep 26 19:33:47 2026 Received: from mta0.migadu.com (out-196.mta0.migadu.com [91.218.175.196]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C277B2750E6 for ; Mon, 31 Aug 2026 06:12:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.196 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788156742; cv=none; b=Bke9OAo/fjsSPAMKR+qHzTns+FiUA+Zyr8gX3b6j4MygGm7n8vsh4QxwFctfMm0uAUQ9o/ZY2tooqhpZRflHGmqjVgUxpliCqBRwJj1y3d/417gpzwoxATlEWse+Gwm2zPm8kcjybht7hzu8YyGDbAGPiBE2StDiSIQuJH54Z3E= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788156742; c=relaxed/simple; bh=SpkPYmmmzxaUtSCKbpZnHJzxs4cuAWXkCR/cThEw114=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=aGhpo6QSbeKhjdKfw78WRSeeLIHx0evBCh0uOZuF7BR2sJIShgSLr8lfO6CTscCcAextlrNb05hZUl/9SHfifXzOAjyoQebjpDMfrpGz6KgWB3etoTnC9n/zKLMSwM3TxodWhEHqvEr6fv2fIIeYoomEFFUKLHRNARvMwniYOJI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=dAqr8QHI; arc=none smtp.client-ip=91.218.175.196 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="dAqr8QHI" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=SpkPYmmmzxaUtSCKbpZnHJzxs4cuAWXkCR/cThEw114=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1788156732; v=1; x=1788761532; b=dAqr8QHINmCjrGMncEOXZDCI+9NNUB6vhcRGEjPotK/PPzxMOAsqanG2OM0YRwm4wtm+u46N sCpNHXRF5ClEN/GyHJ/5HQdEv+NpmvbXlXEiaLISm5/684eF999J6OI2vsLownYeLBQIBpSWidJ FkGbtf34cWoyBBXtXV5WNq94= X-Envelope-To: linux-kernel@vger.kernel.org Received: by smtp.migadu.com with ESMTPS id e6f981f4fdca2c84; Mon, 31 Aug 2026 06:12:12 +0000 X-Mizu-Trace-ID: e6f981f4fdca2c84 X-Migadu-Flow: FLOW_OUT From: luka.gejak@linux.dev To: Ping-Ke Shih , linux-wireless@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Michael Straube , Bitterblue Smith , Peter Robinson , Hans de Goede , Luka Gejak Subject: [PATCH v9 3/6] wifi: rtw88: tx: extend the TX report purge timeout to RTL8723BS Date: Mon, 31 Aug 2026 06:11:41 +0000 Message-ID: <20260831061144.18631-4-luka.gejak@linux.dev> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260831061144.18631-1-luka.gejak@linux.dev> References: <20260831061144.18631-1-luka.gejak@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Luka Gejak Commit c80788f7c5ae ("wifi: rtw88: increase TX report timeout to fix race condition") raised the purge timeout to 2500 ms for the RTL8723DU, because the firmware can stay off channel during background scans for longer than the 500 ms default, which delays the TX reports and lets the purge timer drop the tracking skbs. The host stack then reads the missing status as loss and collapses TCP throughput. The RTL8723BS runs the same vendor firmware over a slower SDIO host and hits the same race. Testers on ARM SDIO boards see "failed to get tx report from firmware" under load, with the same throughput collapse. Extend the 2500 ms timeout to the RTL8723BS. Reported-by: Peter Robinson Closes: https://lore.kernel.org/all/CALeDE9PgQmpMfDt1DgfLD4tBFGH0MZ7GncV6RU= EOHhHbKF+TdQ@mail.gmail.com/ Signed-off-by: Luka Gejak Acked-by: Ping-Ke Shih --- Notes: Changes in v9: none. Changes in v8: none. Changes in v7: none. Changes in v6: none. Changes in v5: none. Restored in v4 after being dropped in v2, because testers on slower ARM SDIO hosts hit the warning that commit c80788f7c5ae already fixes for the RTL8723DU. drivers/net/wireless/realtek/rtw88/tx.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/drivers/net/wireless/realtek/rtw88/tx.c b/drivers/net/wireless= /realtek/rtw88/tx.c index 9d747a060b98..797c1e0402f2 100644 --- a/drivers/net/wireless/realtek/rtw88/tx.c +++ b/drivers/net/wireless/realtek/rtw88/tx.c @@ -208,8 +208,9 @@ void rtw_tx_report_enqueue(struct rtw_dev *rtwdev, stru= ct sk_buff *skb, u8 sn) __skb_queue_tail(&tx_report->queue, skb); spin_unlock_irqrestore(&tx_report->q_lock, flags); =20 - if (rtwdev->chip->id =3D=3D RTW_CHIP_TYPE_8723D && - rtwdev->hci.type =3D=3D RTW_HCI_TYPE_USB) + if ((rtwdev->chip->id =3D=3D RTW_CHIP_TYPE_8723D && + rtwdev->hci.type =3D=3D RTW_HCI_TYPE_USB) || + rtw_is_8723bs(rtwdev)) timeout =3D msecs_to_jiffies(2500); =20 mod_timer(&tx_report->purge_timer, jiffies + timeout); --=20 2.53.0 From nobody Sat Sep 26 19:33:47 2026 Received: from mta0.migadu.com (out-197.mta0.migadu.com [91.218.175.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6DDA83B9DAC for ; Mon, 31 Aug 2026 06:12:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.197 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788156743; cv=none; b=W7X2yyxTA/YX9wo6pJOApW7ObI3+FKhv5H14XcyPkJHGELUixCWBMtfv/ZDyI7glVWALnMG01HHwFKpoSpgAOaINuwBxnDNVYb5KlBVsHTTeyvWrU6196lrlOIhXq2Z85SWSWQS+/nSVCkz5vwh6J7EX7FGQyD8AYHifo/TKcis= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788156743; c=relaxed/simple; bh=Hu5H6vxkdaMzl5KqpQiUUiMmGrRgRQKm/enUbBKGpEk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=NyQ3Yilx69TeswfXgfUHYId/y6HMCOJZH1BV/0Q5PPSaW8KsNs8cU84BNp5lss8Xqq7qt2toZfIVVS7JeZPE9CFHuoqrFfNnIBFpFatAAngWW22Om2oWKftHvRWZ/oqV7hqjmAAt2Da7ZqUVosgjzi6WBApDLBJp4gCquhI0Wfk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=goJvKPs5; arc=none smtp.client-ip=91.218.175.197 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="goJvKPs5" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=Hu5H6vxkdaMzl5KqpQiUUiMmGrRgRQKm/enUbBKGpEk=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1788156733; v=1; x=1788761533; b=goJvKPs5QtI60sw0FypkAOLg+8U6yfaVGuL41+imH1u7/e6Q5gWJy1OMe2A5lfTlxKdOkxsH 7hWApKqYs7cHLe9fuXxn+Um5jAliLL60fzzMF4kHJ5guqNToo+0c2UYSUpZslRjyOD55y3Y8Pvm czzQb+dtTuiOPI9uNPiZiyQg= X-Envelope-To: linux-kernel@vger.kernel.org Received: by smtp.migadu.com with ESMTPS id a2768bc0192df874; Mon, 31 Aug 2026 06:12:13 +0000 X-Mizu-Trace-ID: a2768bc0192df874 X-Migadu-Flow: FLOW_OUT From: luka.gejak@linux.dev To: Ping-Ke Shih , linux-wireless@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Michael Straube , Bitterblue Smith , Peter Robinson , Hans de Goede , Luka Gejak Subject: [PATCH v9 4/6] wifi: rtw88: sdio: track free TX pages and OQT credits for RTL8723BS Date: Mon, 31 Aug 2026 06:11:42 +0000 Message-ID: <20260831061144.18631-5-luka.gejak@linux.dev> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260831061144.18631-1-luka.gejak@linux.dev> References: <20260831061144.18631-1-luka.gejak@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Luka Gejak The RTL8723BS reports free TX page counts that the generic 8051 path reads back from the chip on every transfer, which is both slow over SDIO and unreliable on this part: the register frequently reads back zero while pages are in fact available. It also gates transmission on a free count in the SDIO output queue, REG_SDIO_OQT_FREE_PG, which rtw88 does not track at all. The vendor driver calls this the OQT free space and never expands the acronym; the register holds the number of further transfers the SDIO output queue can accept, and the chip discards writes that arrive when it has run out. Mirror the vendor driver and keep the per-queue and public page counts in software, seeded at start and resynchronised from the chip only when the cached counts say there is not enough room. Wait for a free output queue entry before writing, and account for the pages consumed after a successful transfer. Transfers also have to be padded up to the SDIO block size for this chip rather than using the generic alignment, so size the write separately from the frame and zero the padding with __skb_pad(), which also reallocates a cloned skb instead of writing into a buffer a clone still shares. The check, the output queue wait and the accounting are serialised by a mutex. The TX worker and the H2C path reach this function concurrently, and two writers that both pass the checks can otherwise claim the same pages and output queue entry, after which the chip silently discards whichever transfer arrives second. The vendor driver avoids the same race by funnelling all transmission through one thread. Measured on RTL8723BS hardware against an iperf3 server one hop behind the AP, with the wlan0 byte counters as ground truth. On the generic path the association completes but no data passes at all: TCP and UDP both measure 0 bit/s in either direction. With this patch TCP is 25.3 Mbit/s up and 37.3 Mbit/s down, and UDP is 25.0 Mbit/s up at 0% loss. Signed-off-by: Luka Gejak --- Notes: Changes in v9: - rtw_sdio_write_port() is now only a dispatcher, with the two paths = in rtw_sdio_write_port_8723bs() and rtw_sdio_write_port_generic(), as you asked. The chip specific one takes the mutex with guard() directly, so the extra rtw_sdio_8723bs_write_port() layer, which on= ly existed to give the guard a scope while the generic path shared the outer function, is gone. - the unaligned SKB warning is in rtw_sdio_write_to_port() now, once, next to the transfer whose pointer it checks and after any padding. __func__ therefore reads rtw_sdio_write_to_port on every SDIO part. Changes in v8: - RTW_TX_QUEUE_VO is accounted against the normal page pool rather th= an the high one. rtw_sdio_get_tx_addr() writes it to the normal transm= it FIFO, and that is the pool the chip charges: over a saturating VO flood the high pool never lost a single page while the public pool drained. The vendor maps VO to the high queue, but it also writes VO to the high FIFO, which rtw88 does not. - the output queue entry claimed before the transfer is handed back when the transfer fails, rather than staying claimed until the cache next resyncs from the chip. - mutex_destroy() for tx_credit_lock on teardown and on the init error path, matching rtw_core_deinit(). - the comment on the cached page counters no longer explains the atomic_t by the several contexts that write them. Since v7 the transmit paths all update them under tx_credit_lock; what is left outside the lock is rtw_sdio_start() seeding them, and that is the reason they stay atomic_t. - the free page check, the output queue wait, the transfer and the accounting moved into rtw_sdio_8723bs_write_port(), which takes the lock with guard(mutex) as you suggested. The generic path is a short branch in rtw_sdio_write_port() that never touches the lock, and the transfer itself is shared as rtw_sdio_write_to_port(). - lockdep_assert_held() added to rtw_sdio_8723bs_write_port(), rtw_sdio_8723bs_wait_tx_oqt() and rtw_sdio_8723bs_consume_txpg(), and checked on a kernel built with CONFIG_PROVE_LOCKING over bidirectional traffic and three module reloads: nothing fired. - the padding uses a pad_size local and the comment is down to the one point that matters, that __skb_pad() must not free the skb. - the comment above the lock is gone; the one at the declaration of tx_credit_lock covers it. Changes in v7: - the free page check, the output queue wait and the accounting after the transfer are serialised by a mutex. The TX worker and the H2C path run concurrently, and two writers that both passed the checks could claim the same pages and output queue entry; the OQT refill could also read the register while the other writer was between its claim and its transfer. The chip silently discards the overcommitted transfer, which for H2C means a lost firmware command. - the CMD53 address is computed from skb->len again, as upstream does. Passing the aligned size changed the encoded transfer length for every other SDIO chip whenever sdio_align_size() padded; for the RTL8723BS the two encodings are the same value. - the padding is applied with __skb_pad() and only on the RTL8723BS path. The open coded version wrote into a cloned skb's shared buffer when the tailroom happened to be large enough, and it also ran on the generic path, giving other chips a new allocation and failure mode. __skb_pad() does not move skb->len, so the trim on the way out is gone too. It must not free the skb on failure, since one caller requeues it and the other frees it. =20 Changes in v6: none. Changes in v5: - the commit message now says what OQT is, as far as the vendor driver reveals it. - rtw_sdio_8723bs_sync_free_txpg() returns whether the chip reported anything and is the only caller of _store_free_txpg(), and _init_free_txpg() returns an error rather than nothing. That found a real bug: the public pool size was acq_pg_num minus the reserved queues with no check, so a chip coming up with no transmit page allocation would underflow a u16 and leave about 65000 free pages. It is now rtw_sdio_8723bs_pubq_num(), shared with the queue page allocation repair path, and it fails cleanly. - the output queue wait is bounded by a jiffies deadline rather than a loop count, so RTW_SDIO_OQT_TIMEOUT_MS is really milliseconds. - rtw_sdio_8723bs_check_rqpn() returns an error instead of silently doing nothing when the pool cannot cover the reserved queues, and rtw_sdio_start() propagates it. Both early returns are explained. drivers/net/wireless/realtek/rtw88/sdio.c | 360 +++++++++++++++++++++- drivers/net/wireless/realtek/rtw88/sdio.h | 12 + 2 files changed, 356 insertions(+), 16 deletions(-) diff --git a/drivers/net/wireless/realtek/rtw88/sdio.c b/drivers/net/wirele= ss/realtek/rtw88/sdio.c index 5b40d74b16ee..2991acc21b03 100644 --- a/drivers/net/wireless/realtek/rtw88/sdio.c +++ b/drivers/net/wireless/realtek/rtw88/sdio.c @@ -20,6 +20,7 @@ #include "tx.h" =20 #define RTW_SDIO_INDIRECT_RW_RETRIES 50 +#define RTW_SDIO_OQT_TIMEOUT_MS 1000 =20 static bool rtw_sdio_is_bus_addr(u32 addr) { @@ -548,12 +549,164 @@ static int rtw_sdio_read_port(struct rtw_dev *rtwdev= , u8 *buf, size_t count) return ret; } =20 +/* + * The cached free page counters are a fast path hint only. The transmit + * paths read and update them under tx_credit_lock; rtw_sdio_start() seeds + * them outside it, so they are atomic_t. Whenever they claim there is not + * enough room they are resynchronised from the chip before the caller giv= es + * up, which also absorbs any drift. + */ +static void rtw_sdio_8723bs_store_free_txpg(struct rtw_dev *rtwdev, + u32 free_txpg) +{ + struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; + + atomic_set(&rtwsdio->free_pg_high, + u32_get_bits(free_txpg, BIT_FREE_TXPG_HIGH)); + atomic_set(&rtwsdio->free_pg_normal, + u32_get_bits(free_txpg, BIT_FREE_TXPG_NORMAL)); + atomic_set(&rtwsdio->free_pg_low, + u32_get_bits(free_txpg, BIT_FREE_TXPG_LOW)); + atomic_set(&rtwsdio->free_pg_pub, + u32_get_bits(free_txpg, BIT_FREE_TXPG_PUB)); +} + +/* + * Refresh the cached counters from the chip. Returns false when the chip + * reports no free pages at all, which means the counts cannot be trusted + * and the caller has to decide what to do instead. + */ +static bool rtw_sdio_8723bs_sync_free_txpg(struct rtw_dev *rtwdev) +{ + u32 free_txpg =3D rtw_read32(rtwdev, REG_SDIO_FREE_TXPG); + + if (!free_txpg) + return false; + + rtw_sdio_8723bs_store_free_txpg(rtwdev, free_txpg); + + return true; +} + +/* + * Size of the public page pool: whatever the transmit page allocation has + * left once the per queue pools are taken out. Fails if the allocation + * cannot cover the reserved queues, since the remainder would underflow a= nd + * there would be no sensible pool to hand out. + */ +static int rtw_sdio_8723bs_pubq_num(struct rtw_dev *rtwdev, u16 *pubq_num) +{ + const struct rtw_page_table *pg_tbl =3D &rtwdev->chip->page_table[0]; + u16 acq_pg_num =3D rtwdev->fifo.acq_pg_num; + u16 reserved_num; + + reserved_num =3D pg_tbl->hq_num + pg_tbl->lq_num + pg_tbl->nq_num + + pg_tbl->exq_num + pg_tbl->gapq_num; + if (acq_pg_num <=3D reserved_num) { + rtw_err(rtwdev, + "no transmit pages left for the public queue: %u of %u reserved\n", + reserved_num, acq_pg_num); + return -EINVAL; + } + + *pubq_num =3D acq_pg_num - reserved_num; + + return 0; +} + +static int rtw_sdio_8723bs_init_free_txpg(struct rtw_dev *rtwdev) +{ + struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; + const struct rtw_page_table *pg_tbl; + u16 pubq_num; + int ret; + + /* Seed from the page table when the chip has nothing to report yet. */ + if (!rtw_sdio_8723bs_sync_free_txpg(rtwdev)) { + ret =3D rtw_sdio_8723bs_pubq_num(rtwdev, &pubq_num); + if (ret) + return ret; + + pg_tbl =3D &rtwdev->chip->page_table[0]; + atomic_set(&rtwsdio->free_pg_high, pg_tbl->hq_num); + atomic_set(&rtwsdio->free_pg_normal, pg_tbl->nq_num); + atomic_set(&rtwsdio->free_pg_low, pg_tbl->lq_num); + atomic_set(&rtwsdio->free_pg_pub, pubq_num); + } + + atomic_set(&rtwsdio->tx_oqt_free, + rtw_read8(rtwdev, REG_SDIO_OQT_FREE_PG)); + + return 0; +} + +/* + * Sum of the queue's dedicated counter and the public pool, clamped at ze= ro: + * a lost update between the check below and rtw_sdio_8723bs_consume_txpg() + * can briefly drive a counter negative, and letting that wrap would hide = the + * shortage instead of triggering a resync from the chip. + */ +static unsigned int rtw_sdio_8723bs_pages_free(struct rtw_dev *rtwdev, + atomic_t *dedicated) +{ + struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; + int free; + + free =3D atomic_read(dedicated) + atomic_read(&rtwsdio->free_pg_pub); + + return free > 0 ? free : 0; +} + +/* + * The pool a queue draws from follows the transmit FIFO that + * rtw_sdio_get_tx_addr() writes into, since that is the one the chip char= ges. + * RTW_TX_QUEUE_MGMT is the exception: it goes to the extra FIFO, which + * REG_SDIO_FREE_TXPG has no counter for and this chip allocates no pages = to, + * so it is accounted against the high pool and served from the public one. + */ +static atomic_t *rtw_sdio_8723bs_free_txpg(struct rtw_dev *rtwdev, u8 queu= e) +{ + struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; + + switch (queue) { + case RTW_TX_QUEUE_VI: + case RTW_TX_QUEUE_VO: + return &rtwsdio->free_pg_normal; + case RTW_TX_QUEUE_BE: + case RTW_TX_QUEUE_BK: + return &rtwsdio->free_pg_low; + case RTW_TX_QUEUE_BCN: + case RTW_TX_QUEUE_H2C: + case RTW_TX_QUEUE_HI0: + case RTW_TX_QUEUE_MGMT: + return &rtwsdio->free_pg_high; + default: + return NULL; + } +} + static int rtw_sdio_check_free_txpg(struct rtw_dev *rtwdev, u8 queue, size_t count) { unsigned int pages_free, pages_needed; =20 - if (rtw_chip_wcpu_8051(rtwdev)) { + if (rtw_is_8723bs(rtwdev)) { + atomic_t *dedicated; + + dedicated =3D rtw_sdio_8723bs_free_txpg(rtwdev, queue); + if (!dedicated) { + rtw_warn(rtwdev, "Unknown mapping for queue %u\n", queue); + return -EINVAL; + } + + pages_free =3D rtw_sdio_8723bs_pages_free(rtwdev, dedicated); + pages_needed =3D DIV_ROUND_UP(count, rtwdev->chip->page_size); + if (pages_needed <=3D pages_free) + return 0; + + rtw_sdio_8723bs_sync_free_txpg(rtwdev); + pages_free =3D rtw_sdio_8723bs_pages_free(rtwdev, dedicated); + } else if (rtw_chip_wcpu_8051(rtwdev)) { u32 free_txpg; =20 free_txpg =3D rtw_sdio_read32(rtwdev, REG_SDIO_FREE_TXPG); @@ -632,24 +785,60 @@ static int rtw_sdio_check_free_txpg(struct rtw_dev *r= twdev, u8 queue, return 0; } =20 -static int rtw_sdio_write_port(struct rtw_dev *rtwdev, struct sk_buff *skb, - enum rtw_tx_queue_type queue) +static int rtw_sdio_8723bs_wait_tx_oqt(struct rtw_dev *rtwdev) { struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; - bool bus_claim; - size_t txsize; - u32 txaddr; - int ret; + unsigned long deadline; + u8 free; =20 - txaddr =3D rtw_sdio_get_tx_addr(rtwdev, skb->len, queue); - if (!txaddr) - return -EINVAL; + lockdep_assert_held(&rtwsdio->tx_credit_lock); =20 - txsize =3D sdio_align_size(rtwsdio->sdio_func, skb->len); + if (atomic_add_unless(&rtwsdio->tx_oqt_free, -1, 0)) + return 0; =20 - ret =3D rtw_sdio_check_free_txpg(rtwdev, queue, txsize); - if (ret) - return ret; + deadline =3D jiffies + msecs_to_jiffies(RTW_SDIO_OQT_TIMEOUT_MS); + do { + free =3D rtw_read8(rtwdev, REG_SDIO_OQT_FREE_PG); + if (free) { + atomic_set(&rtwsdio->tx_oqt_free, free - 1); + return 0; + } + usleep_range(1000, 2000); + } while (time_before(jiffies, deadline)); + + return -EBUSY; +} + +static void rtw_sdio_8723bs_consume_txpg(struct rtw_dev *rtwdev, u8 queue, + unsigned int pages) +{ + struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; + atomic_t *dedicated; + unsigned int taken; + int free; + + lockdep_assert_held(&rtwsdio->tx_credit_lock); + + dedicated =3D rtw_sdio_8723bs_free_txpg(rtwdev, queue); + if (!dedicated) + return; + + free =3D atomic_read(dedicated); + taken =3D min_t(unsigned int, pages, free > 0 ? free : 0); + atomic_sub(taken, dedicated); + + pages -=3D taken; + if (pages && atomic_sub_return(pages, &rtwsdio->free_pg_pub) < 0) + atomic_set(&rtwsdio->free_pg_pub, 0); +} + +static int rtw_sdio_write_to_port(struct rtw_dev *rtwdev, struct sk_buff *= skb, + enum rtw_tx_queue_type queue, u32 txaddr, + size_t write_size) +{ + struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; + bool bus_claim; + int ret; =20 if (!IS_ALIGNED((unsigned long)skb->data, RTW_SDIO_DATA_PTR_ALIGN)) rtw_warn(rtwdev, "Got unaligned SKB in %s() for queue %u\n", @@ -660,7 +849,8 @@ static int rtw_sdio_write_port(struct rtw_dev *rtwdev, = struct sk_buff *skb, if (bus_claim) sdio_claim_host(rtwsdio->sdio_func); =20 - ret =3D sdio_memcpy_toio(rtwsdio->sdio_func, txaddr, skb->data, txsize); + ret =3D sdio_memcpy_toio(rtwsdio->sdio_func, txaddr, skb->data, + write_size); =20 if (bus_claim) sdio_release_host(rtwsdio->sdio_func); @@ -668,11 +858,101 @@ static int rtw_sdio_write_port(struct rtw_dev *rtwde= v, struct sk_buff *skb, if (ret) rtw_warn(rtwdev, "Failed to write %zu byte(s) to SDIO port 0x%08x", - txsize, txaddr); + write_size, txaddr); =20 return ret; } =20 +/* + * The free page check, the output queue wait and the accounting after the + * transfer have to be one unit, or two writers can both pass the checks a= nd + * claim the same pages and output queue entry. + */ +static int rtw_sdio_write_port_8723bs(struct rtw_dev *rtwdev, + struct sk_buff *skb, + enum rtw_tx_queue_type queue) +{ + struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; + unsigned int pages; + size_t write_size; + size_t txsize; + u32 txaddr; + int ret; + + txaddr =3D rtw_sdio_get_tx_addr(rtwdev, skb->len, queue); + if (!txaddr) + return -EINVAL; + + txsize =3D round_up(skb->len, 4); + write_size =3D txsize > RTW_SDIO_BLOCK_SIZE ? + round_up(txsize, RTW_SDIO_BLOCK_SIZE) : txsize; + + if (write_size > skb->len) { + size_t pad_size =3D write_size - skb->len; + + /* + * __skb_pad() must not free the skb on failure: both callers + * still own it, one requeues it and the other frees it. + */ + ret =3D __skb_pad(skb, pad_size, false); + if (ret) + return ret; + } + + guard(mutex)(&rtwsdio->tx_credit_lock); + + ret =3D rtw_sdio_check_free_txpg(rtwdev, queue, txsize); + if (ret) + return ret; + + ret =3D rtw_sdio_8723bs_wait_tx_oqt(rtwdev); + if (ret) + return ret; + + ret =3D rtw_sdio_write_to_port(rtwdev, skb, queue, txaddr, write_size); + if (ret) { + /* nothing was queued, so hand the output queue entry back */ + atomic_inc(&rtwsdio->tx_oqt_free); + return ret; + } + + pages =3D DIV_ROUND_UP(txsize, rtwdev->chip->page_size); + rtw_sdio_8723bs_consume_txpg(rtwdev, queue, pages); + + return 0; +} + +static int rtw_sdio_write_port_generic(struct rtw_dev *rtwdev, + struct sk_buff *skb, + enum rtw_tx_queue_type queue) +{ + struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; + size_t txsize; + u32 txaddr; + int ret; + + txaddr =3D rtw_sdio_get_tx_addr(rtwdev, skb->len, queue); + if (!txaddr) + return -EINVAL; + + txsize =3D sdio_align_size(rtwsdio->sdio_func, skb->len); + + ret =3D rtw_sdio_check_free_txpg(rtwdev, queue, txsize); + if (ret) + return ret; + + return rtw_sdio_write_to_port(rtwdev, skb, queue, txaddr, txsize); +} + +static int rtw_sdio_write_port(struct rtw_dev *rtwdev, struct sk_buff *skb, + enum rtw_tx_queue_type queue) +{ + if (rtw_is_8723bs(rtwdev)) + return rtw_sdio_write_port_8723bs(rtwdev, skb, queue); + + return rtw_sdio_write_port_generic(rtwdev, skb, queue); +} + static void rtw_sdio_init(struct rtw_dev *rtwdev) { struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; @@ -749,8 +1029,51 @@ static int rtw_sdio_setup(struct rtw_dev *rtwdev) return 0; } =20 +/* + * Reprogram the queue page allocation if the chip came up with none. This= is + * a repair path, not part of the normal start sequence: a non-zero free p= age + * count means the allocation latched during power on and must be left alo= ne, + * and without a transmit page pool there is nothing to divide up either. + */ +static int rtw_sdio_8723bs_check_rqpn(struct rtw_dev *rtwdev) +{ + const struct rtw_chip_info *chip =3D rtwdev->chip; + struct rtw_fifo_conf *fifo =3D &rtwdev->fifo; + const struct rtw_page_table *pg_tbl; + u32 free_txpg; + u16 pubq_num; + int ret; + + free_txpg =3D rtw_read32(rtwdev, REG_SDIO_FREE_TXPG); + if (free_txpg || !fifo->acq_pg_num) + return 0; + + ret =3D rtw_sdio_8723bs_pubq_num(rtwdev, &pubq_num); + if (ret) + return ret; + + pg_tbl =3D &chip->page_table[0]; + rtw_write32(rtwdev, REG_RQPN_NPQ, + BIT_RQPN_NE(pg_tbl->nq_num, pg_tbl->exq_num)); + rtw_write32(rtwdev, REG_RQPN, + BIT_RQPN_HLP(pg_tbl->hq_num, pg_tbl->lq_num, pubq_num)); + + return 0; +} + static int rtw_sdio_start(struct rtw_dev *rtwdev) { + if (rtw_is_8723bs(rtwdev)) { + int ret =3D rtw_sdio_8723bs_check_rqpn(rtwdev); + + if (ret) + return ret; + + ret =3D rtw_sdio_8723bs_init_free_txpg(rtwdev); + if (ret) + return ret; + } + rtw_sdio_enable_rx_aggregation(rtwdev); rtw_sdio_enable_interrupt(rtwdev); =20 @@ -1294,6 +1617,8 @@ static int rtw_sdio_init_tx(struct rtw_dev *rtwdev) return -ENOMEM; } =20 + mutex_init(&rtwsdio->tx_credit_lock); + for (i =3D 0; i < RTK_MAX_TX_QUEUE_NUM; i++) skb_queue_head_init(&rtwsdio->tx_queue[i]); rtwsdio->tx_handler_data =3D kmalloc_obj(*rtwsdio->tx_handler_data); @@ -1306,6 +1631,7 @@ static int rtw_sdio_init_tx(struct rtw_dev *rtwdev) return 0; =20 err_destroy_wq: + mutex_destroy(&rtwsdio->tx_credit_lock); destroy_workqueue(rtwsdio->txwq); return -ENOMEM; } @@ -1320,6 +1646,8 @@ static void rtw_sdio_deinit_tx(struct rtw_dev *rtwdev) =20 for (i =3D 0; i < RTK_MAX_TX_QUEUE_NUM; i++) ieee80211_purge_tx_queue(rtwdev->hw, &rtwsdio->tx_queue[i]); + + mutex_destroy(&rtwsdio->tx_credit_lock); } =20 int rtw_sdio_probe(struct sdio_func *sdio_func, diff --git a/drivers/net/wireless/realtek/rtw88/sdio.h b/drivers/net/wirele= ss/realtek/rtw88/sdio.h index 457e8b02380e..f43f1c6309b7 100644 --- a/drivers/net/wireless/realtek/rtw88/sdio.h +++ b/drivers/net/wireless/realtek/rtw88/sdio.h @@ -86,6 +86,10 @@ #define REG_SDIO_OQT_FREE_PG (SDIO_LOCAL_OFFSET + 0x001E) /* Free Tx Buffer Page */ #define REG_SDIO_FREE_TXPG (SDIO_LOCAL_OFFSET + 0x0020) +#define BIT_FREE_TXPG_HIGH GENMASK(7, 0) +#define BIT_FREE_TXPG_NORMAL GENMASK(15, 8) +#define BIT_FREE_TXPG_LOW GENMASK(23, 16) +#define BIT_FREE_TXPG_PUB GENMASK(31, 24) /* HCI Current Power Mode 1 */ #define REG_SDIO_HCPWM1 (SDIO_LOCAL_OFFSET + 0x0024) /* HCI Current Power Mode 2 */ @@ -159,6 +163,14 @@ struct rtw_sdio { struct workqueue_struct *txwq; struct rtw_sdio_work_data *tx_handler_data; struct sk_buff_head tx_queue[RTK_MAX_TX_QUEUE_NUM]; + + atomic_t free_pg_high; + atomic_t free_pg_normal; + atomic_t free_pg_low; + atomic_t free_pg_pub; + atomic_t tx_oqt_free; + /* one writer at a time between the credit check and the accounting */ + struct mutex tx_credit_lock; }; =20 extern const struct dev_pm_ops rtw_sdio_pm_ops; --=20 2.53.0 From nobody Sat Sep 26 19:33:47 2026 Received: from mta1.migadu.com (out-59.mta1.migadu.com [95.215.58.59]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9EDD33B14BC for ; Mon, 31 Aug 2026 06:12:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.59 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788156744; cv=none; b=fj9Vk9TUF+tDAY1FZ0Lj7VtHzeZDEL8ZuAH9Vea7NzkayyxzqHfqWHXDp+qvcPUM3s5CGfr563DYjBWZlMOsy9XBL/ZPuZbiKsk7yiDJFUe5bCgPS4pagkCmwHkCINvunYqRUqAX+HJBJi5kRenZX9o/oDKsxUBaW2z8xuSE41w= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788156744; c=relaxed/simple; bh=IHoNIXOjMwBphJx4W21chltKoGJtbTu1qug+/9UmwRY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=h6aTgLyYMQvfP92/U6VOD0Uoa+YIRQ5GnmBEmLKOfvSoPhzD3PrhsSzz/7+sOwNZen9A9zSrOVOQA/FpJdkEPpdfzqsBZEWEzd7Wca+ljZHkX8AktSMnVWwEFA52y3NLK1lbdlO6jFCl2DMp7SH0ISgpWN+8mUFwWk0CyiQOF48= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=mBhc/ZC5; arc=none smtp.client-ip=95.215.58.59 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="mBhc/ZC5" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=IHoNIXOjMwBphJx4W21chltKoGJtbTu1qug+/9UmwRY=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1788156734; v=1; x=1788761534; b=mBhc/ZC5yA++Dr4ggn2ZblNVLzqQDj69cqOjpTY6CJFOfifnHBW2wzj27zjwR6CcTeSqBRy0 C+hT6AvNdcE2g82Xo+Y5mvewvVbeBu08SoWPGjWdXgG8dZz9UZTrYGSgz97d32MK4lhWFYu3ryi KLVyYclBVDpmNICeo3G3EDfQ= X-Envelope-To: linux-kernel@vger.kernel.org Received: by smtp.migadu.com with ESMTPS id c843f02597b0cf76; Mon, 31 Aug 2026 06:12:14 +0000 X-Mizu-Trace-ID: c843f02597b0cf76 X-Migadu-Flow: FLOW_OUT From: luka.gejak@linux.dev To: Ping-Ke Shih , linux-wireless@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Michael Straube , Bitterblue Smith , Peter Robinson , Hans de Goede , Luka Gejak Subject: [PATCH v9 5/6] wifi: rtw88: sdio: set up RX aggregation and interrupts for RTL8723BS Date: Mon, 31 Aug 2026 06:11:43 +0000 Message-ID: <20260831061144.18631-6-luka.gejak@linux.dev> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260831061144.18631-1-luka.gejak@linux.dev> References: <20260831061144.18631-1-luka.gejak@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Luka Gejak Enable the existing RX aggregation setup for this chip and select the larger DMA burst count it needs. The RTL8723BS does not raise CPWM1, so leave that source out of its interrupt mask, and set the SDIO TX control bit the vendor driver uses to have transfers always recognised. The chip was also seen to keep raising the interrupt after resume when undefined status bits were written back on acknowledgment, so acknowledge only the bits this driver defines. That observation dates from bring up and I cannot re-measure it: the test machine only offers s2idle and does not reliably return from it, so the resume path is not exercised here. The change is scoped to this chip; the other SDIO parts keep writing the status word back unchanged. Signed-off-by: Luka Gejak Acked-by: Ping-Ke Shih --- Notes: Changes in v9: none. Changes in v8: none. Changes in v7: none. Changes in v6: none. Changes in v5: fixed the interrupt acknowledgment. It masked the status word with both irq_mask and RTW_SDIO_HISR_CLEAR_MASK, but for this chip irq_mask is REG_SDIO_HIMR_RX_REQUEST alone and that bit is not in the clear mask, so the two had no bits in common and the driver acknowledged nothing at all. It now masks with the defined bits only, which is what the comment described. The commit message also no longer presents the resume behaviour as re-measured, because it is not. drivers/net/wireless/realtek/rtw88/sdio.c | 28 ++++++++++++++++++++++- drivers/net/wireless/realtek/rtw88/sdio.h | 9 ++++++++ 2 files changed, 36 insertions(+), 1 deletion(-) diff --git a/drivers/net/wireless/realtek/rtw88/sdio.c b/drivers/net/wirele= ss/realtek/rtw88/sdio.c index 2991acc21b03..4e6864b4f8ea 100644 --- a/drivers/net/wireless/realtek/rtw88/sdio.c +++ b/drivers/net/wireless/realtek/rtw88/sdio.c @@ -957,7 +957,11 @@ static void rtw_sdio_init(struct rtw_dev *rtwdev) { struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; =20 - rtwsdio->irq_mask =3D REG_SDIO_HIMR_RX_REQUEST | REG_SDIO_HIMR_CPWM1; + if (rtw_is_8723bs(rtwdev)) + rtwsdio->irq_mask =3D REG_SDIO_HIMR_RX_REQUEST; + else + rtwsdio->irq_mask =3D REG_SDIO_HIMR_RX_REQUEST | + REG_SDIO_HIMR_CPWM1; } =20 static void rtw_sdio_enable_rx_aggregation(struct rtw_dev *rtwdev) @@ -965,6 +969,7 @@ static void rtw_sdio_enable_rx_aggregation(struct rtw_d= ev *rtwdev) u8 size, timeout; =20 switch (rtwdev->chip->id) { + case RTW_CHIP_TYPE_8723B: case RTW_CHIP_TYPE_8703B: case RTW_CHIP_TYPE_8821A: case RTW_CHIP_TYPE_8812A: @@ -992,6 +997,8 @@ static void rtw_sdio_enable_rx_aggregation(struct rtw_d= ev *rtwdev) FIELD_PREP(BIT_DMA_AGG_TO_V1, timeout)); =20 rtw_write8_set(rtwdev, REG_RXDMA_MODE, BIT_DMA_MODE); + if (rtw_is_8723bs(rtwdev)) + rtw_write8_mask(rtwdev, REG_RXDMA_MODE, BIT_DMA_BURST_CNT, 0x3); } =20 static void rtw_sdio_enable_interrupt(struct rtw_dev *rtwdev) @@ -1063,6 +1070,8 @@ static int rtw_sdio_8723bs_check_rqpn(struct rtw_dev = *rtwdev) =20 static int rtw_sdio_start(struct rtw_dev *rtwdev) { + u32 clear; + if (rtw_is_8723bs(rtwdev)) { int ret =3D rtw_sdio_8723bs_check_rqpn(rtwdev); =20 @@ -1075,6 +1084,13 @@ static int rtw_sdio_start(struct rtw_dev *rtwdev) } =20 rtw_sdio_enable_rx_aggregation(rtwdev); + + if (rtw_is_8723bs(rtwdev)) { + clear =3D rtw_read32(rtwdev, REG_SDIO_HISR) & RTW_SDIO_HISR_CLEAR_MASK; + if (clear) + rtw_write32(rtwdev, REG_SDIO_HISR, clear); + } + rtw_sdio_enable_interrupt(rtwdev); =20 return 0; @@ -1154,6 +1170,8 @@ static void rtw_sdio_interface_cfg(struct rtw_dev *rt= wdev) =20 val =3D rtw_read32(rtwdev, REG_SDIO_TX_CTRL); val &=3D 0xfff8; + if (rtw_is_8723bs(rtwdev)) + val |=3D BIT_SDIO_TX_CTRL_ALWAYS_RECOGNIZE; rtw_write32(rtwdev, REG_SDIO_TX_CTRL, val); } =20 @@ -1418,6 +1436,14 @@ static void rtw_sdio_handle_interrupt(struct sdio_fu= nc *sdio_func) rtw_sdio_rx_isr(rtwdev); } =20 + /* + * RTL8723BS keeps raising the interrupt after resume if undefined + * status bits are written back, so acknowledge only the bits this + * driver defines. Other chips keep the existing behaviour. + */ + if (rtw_is_8723bs(rtwdev)) + hisr &=3D RTW_SDIO_HISR_CLEAR_MASK; + rtw_write32(rtwdev, REG_SDIO_HISR, hisr); =20 rtwsdio->irq_thread =3D NULL; diff --git a/drivers/net/wireless/realtek/rtw88/sdio.h b/drivers/net/wirele= ss/realtek/rtw88/sdio.h index f43f1c6309b7..634c0b1339bb 100644 --- a/drivers/net/wireless/realtek/rtw88/sdio.h +++ b/drivers/net/wireless/realtek/rtw88/sdio.h @@ -22,6 +22,7 @@ =20 /* SDIO Tx Control */ #define REG_SDIO_TX_CTRL (SDIO_LOCAL_OFFSET + 0x0000) +#define BIT_SDIO_TX_CTRL_ALWAYS_RECOGNIZE BIT(4) =20 /*SDIO status timeout*/ #define REG_SDIO_TIMEOUT (SDIO_LOCAL_OFFSET + 0x0002) @@ -77,6 +78,14 @@ /* the following two are RTL8188 SDIO Specific */ #define REG_SDIO_HISR_MCU_ERR BIT(28) #define REG_SDIO_HISR_TSF_BIT32_TOGGLE BIT(29) +#define RTW_SDIO_HISR_CLEAR_MASK \ + (REG_SDIO_HISR_TXERR | REG_SDIO_HISR_RXERR | \ + REG_SDIO_HISR_TXFOVW | REG_SDIO_HISR_RXFOVW | \ + REG_SDIO_HISR_TXBCNOK | REG_SDIO_HISR_TXBCNERR | \ + REG_SDIO_HISR_C2HCMD | REG_SDIO_HISR_CPWM1 | \ + REG_SDIO_HISR_CPWM2 | REG_SDIO_HISR_HSISR_IND | \ + REG_SDIO_HISR_GTINT3_IND | REG_SDIO_HISR_GTINT4_IND | \ + REG_SDIO_HISR_PSTIMEOUT | REG_SDIO_HISR_OCPINT) =20 /* HCI Current Power Mode */ #define REG_SDIO_HCPWM (SDIO_LOCAL_OFFSET + 0x0019) --=20 2.53.0 From nobody Sat Sep 26 19:33:47 2026 Received: from mta1.migadu.com (out-62.mta1.migadu.com [95.215.58.62]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 277053B47C4 for ; Mon, 31 Aug 2026 06:12:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.62 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788156750; cv=none; b=djvcyqzO57d8xHN5x8V1b3vq5wtcbTknqRK/ybPwCL2X1AFQtlH1sxfUSzXp4OVh7nqEHxERtyE1pxr3eqrw64bsbJPLmx6h+zxRjEgkh8E2MgVfPhPJfoflEZBfhy7vkYD5zbhPWCeRE6xUlbij5OPKQTsS5tBD4oCTiFKUm8Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788156750; c=relaxed/simple; bh=FyqvdUVio19e6fB6OmJXLKmzP0jHqX6/aY8fv9FJReY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=bJRMICe4DVDOdpVcmFZM5vVCwd7/gRgZDN8NOIBu4s+t3XC0Gx64JjRfmE7en6R1eUasW69YiUsVOguaDg7U5snYAOfQ5dTjKPNnZOjOqR6/dpVHnzOCcZ8efBuolzM0IoMeYEw/WKYMaDSHIuIihNzQwEqJkQKnLYthbp+MP8k= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=fLh1+eNI; arc=none smtp.client-ip=95.215.58.62 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="fLh1+eNI" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=FyqvdUVio19e6fB6OmJXLKmzP0jHqX6/aY8fv9FJReY=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1788156739; v=1; x=1788761539; b=fLh1+eNISEkeHL89/4tP9pz+JosCdTfUYX4SLVy0mytb6FeBL/Orfs/bKMXSgIfrjPVnc2HS DipmRewGj3A0K7A9EA0bsj6syrQfnPnINeFFZ/3Df1wIeoV4aeRxPyXjM4MI1j4GQH87oNl0K9T fPwuMpVugCu43XhIoBSq+vpE= X-Envelope-To: linux-kernel@vger.kernel.org Received: by smtp.migadu.com with ESMTPS id e318c50f092400b6; Mon, 31 Aug 2026 06:12:19 +0000 X-Mizu-Trace-ID: e318c50f092400b6 X-Migadu-Flow: FLOW_OUT From: luka.gejak@linux.dev To: Ping-Ke Shih , linux-wireless@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Michael Straube , Bitterblue Smith , Peter Robinson , Hans de Goede , Luka Gejak Subject: [PATCH v9 6/6] wifi: rtw88: sdio: add TX back-pressure and retry on page starvation Date: Mon, 31 Aug 2026 06:11:44 +0000 Message-ID: <20260831061144.18631-7-luka.gejak@linux.dev> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260831061144.18631-1-luka.gejak@linux.dev> References: <20260831061144.18631-1-luka.gejak@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Luka Gejak Two problems show up on RTL8723BS uplink. The per-AC software FIFO is unbounded, so mac80211 keeps handing frames down until latency collapses under load. And when a transfer cannot be completed the queue is simply abandoned for that pass, which stalls the AC until something else kicks the worker. Stop the mac80211 queue once a data AC fills past a high watermark and wake it from the drain path when it falls back to a low one. Both sides take the TX queue lock across the length check and the flag update, the way rtw_pci_tx_write() and rtw_pci_tx_isr() use irq_lock. Without it the producer could stop a queue on a length the drain path had already emptied, having seen the flag still clear and so skipped the wake, and the AC would have stayed stopped with nothing left to wake it. Convert the TX work item to a delayed work and re-arm it when a transfer fails for a reason that can clear on its own, so it is retried rather than the AC abandoned, and cancel the work on teardown. Retrying matters once the queue can be stopped. A stopped queue is handed no further frames, so nothing else would kick the worker, and the AC would stay stopped for good with the link still up and receive unaffected. The two retried cases, a transmit page or output queue shortage and a failed skb expansion, are also the two that fail silently; the rest are logged where they happen, so they are visible rather than an unexplained hang, and they keep the existing behaviour rather than being retried indefinitely. Measured on RTL8723BS hardware, uplink goes from 11.9 Mbit/s with 204 TCP retransmits to 20.1 Mbit/s with 2. Signed-off-by: Luka Gejak Acked-by: Ping-Ke Shih --- Notes: Changes in v9: none, beyond recording your Acked-by. Changes in v8: - the stop and the wake take the TX queue lock with guard(spinlock_irqsave) across the length check and the flag update, following pci.c, which holds irq_lock on both sides and needs no barrier because of it. The smp_mb() pair, the READ_ONCE and WRITE_ONCE accessors and the re-check that undid a stop all went with it. - q_map is read later, just before the call that uses it. It cannot m= ove past rtw_sdio_indicate_tx_status(), which consumes the skb, so that= is as far down as it goes. Changes in v7: - the mac80211 queue index is read before skb_queue_tail() publishes the skb to the TX worker, which may process and free it immediately; reading it afterwards was a use after free. - the stop path re-checks the FIFO after setting the stopped flag and undoes the stop if the worker drained it meanwhile. In that window the drain side still saw the flag clear, so neither side would have woken the queue and the AC stayed stopped for good. The flag is accessed with READ_ONCE/WRITE_ONCE and the re-check is ordered against the drain path with a barrier pair. =20 Changes in v6: - dropped rtw_sdio_reschedule_tx_work(). It was a thin wrapper around queue_delayed_work() and hid the kernel API for no gain. - the reschedule conditions moved into rtw_sdio_8723bs_reschedule_tx(= ), so rtw_sdio_tx_handler() no longer explains any chip specific condition in the common flow. - dropped the unconditional break on a failed transfer. v4 and v5 had it, and it quietly changed the other SDIO parts: upstream requeues the frame and the loop retries, and breaking gave up after the first failure. The two errors this chip needs to retry are handled in the helper above, so the rest can keep the existing behaviour and the other parts are untouched again. Changes in v5: - the back-pressure and wake conditions moved into rtw_sdio_8723bs_stop_tx_queue() and _wake_tx_queue(). - rtw_sdio_process_tx_queue() returns 0 on success and 1 for the empty queue case, rather than the other way round. - queue_stopped[] renamed to tx_queue_stopped[]. - fixed a transmit stall: the work item was only re-armed on a page shortage, so on any other failure a stopped access category would stay stopped for good. It now also re-arms on a failed skb expansion, which with the page shortage covers both failures that produce no log message. - RTW_SDIO_TX_RETRY_DELAY is left as msecs_to_jiffies(1): it does not become 0 for HZ < 1000, since msecs_to_jiffies() rounds up. drivers/net/wireless/realtek/rtw88/sdio.c | 153 ++++++++++++++++++++-- drivers/net/wireless/realtek/rtw88/sdio.h | 3 +- 2 files changed, 145 insertions(+), 11 deletions(-) diff --git a/drivers/net/wireless/realtek/rtw88/sdio.c b/drivers/net/wirele= ss/realtek/rtw88/sdio.c index 4e6864b4f8ea..b281e111502c 100644 --- a/drivers/net/wireless/realtek/rtw88/sdio.c +++ b/drivers/net/wireless/realtek/rtw88/sdio.c @@ -22,6 +22,16 @@ #define RTW_SDIO_INDIRECT_RW_RETRIES 50 #define RTW_SDIO_OQT_TIMEOUT_MS 1000 =20 +/* + * 8723BS SDIO TX FIFO back-pressure watermarks: stop the mac80211 queue o= nce + * the per-AC software FIFO fills past the high watermark, and wake it fro= m the + * TX drain path once it falls back to the low one. Bounds the queueing la= tency + * that otherwise causes uplink bufferbloat / congestion collapse. + */ +#define RTW_SDIO_TX_FIFO_HIWATER 16 +#define RTW_SDIO_TX_FIFO_LOWATER 8 +#define RTW_SDIO_TX_RETRY_DELAY msecs_to_jiffies(1) + static bool rtw_sdio_is_bus_addr(u32 addr) { return !!(addr & RTW_SDIO_BUS_MSK); @@ -1154,7 +1164,11 @@ static void rtw_sdio_tx_kick_off(struct rtw_dev *rtw= dev) { struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; =20 - queue_work(rtwsdio->txwq, &rtwsdio->tx_handler_data->work); + /* + * A retry may already be pending with a delay; re-arm it so a newly + * queued frame is not held back by it. + */ + mod_delayed_work(rtwsdio->txwq, &rtwsdio->tx_handler_data->work, 0); } =20 static void rtw_sdio_link_ps(struct rtw_dev *rtwdev, bool enter) @@ -1263,12 +1277,65 @@ static int rtw_sdio_write_data_h2c(struct rtw_dev *= rtwdev, u8 *buf, u32 size) return rtw_sdio_write_data(rtwdev, &pkt_info, skb, RTW_TX_QUEUE_H2C); } =20 +/* + * Back-pressure on the data ACs (BK/BE/VI/VO): once the software FIFO fil= ls + * past the high watermark, stop the corresponding mac80211 queue so it st= ops + * handing frames down, which bounds the queueing latency. The queue is wo= ken + * again from the TX drain path once the FIFO falls back to the low waterm= ark. + * + * Both sides hold the TX queue lock across the length check and the flag + * update, so a queue is only ever stopped while it really is above the + * watermark, and the drain path always sees the flag the producer set. + */ +static void rtw_sdio_8723bs_stop_tx_queue(struct rtw_dev *rtwdev, + enum rtw_tx_queue_type queue, + u16 q_map) +{ + struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; + + if (!rtw_is_8723bs(rtwdev) || queue >=3D RTW_TX_QUEUE_BCN) + return; + + guard(spinlock_irqsave)(&rtwsdio->tx_queue[queue].lock); + + if (rtwsdio->tx_queue_stopped[queue]) + return; + + if (skb_queue_len(&rtwsdio->tx_queue[queue]) < RTW_SDIO_TX_FIFO_HIWATER) + return; + + rtwsdio->tx_queue_stopped[queue] =3D true; + ieee80211_stop_queue(rtwdev->hw, q_map); +} + +static void rtw_sdio_8723bs_wake_tx_queue(struct rtw_dev *rtwdev, + enum rtw_tx_queue_type queue, + u16 q_map) +{ + struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; + + if (!rtw_is_8723bs(rtwdev) || queue >=3D RTW_TX_QUEUE_BCN) + return; + + guard(spinlock_irqsave)(&rtwsdio->tx_queue[queue].lock); + + if (!rtwsdio->tx_queue_stopped[queue]) + return; + + if (skb_queue_len(&rtwsdio->tx_queue[queue]) > RTW_SDIO_TX_FIFO_LOWATER) + return; + + rtwsdio->tx_queue_stopped[queue] =3D false; + ieee80211_wake_queue(rtwdev->hw, q_map); +} + static int rtw_sdio_tx_write(struct rtw_dev *rtwdev, struct rtw_tx_pkt_info *pkt_info, struct sk_buff *skb) { struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; enum rtw_tx_queue_type queue =3D rtw_tx_queue_mapping(skb); + u16 q_map =3D skb_get_queue_mapping(skb); struct rtw_sdio_tx_data *tx_data; =20 rtw_sdio_tx_skb_prepare(rtwdev, pkt_info, skb, queue); @@ -1276,8 +1343,15 @@ static int rtw_sdio_tx_write(struct rtw_dev *rtwdev, tx_data =3D rtw_sdio_get_tx_data(skb); tx_data->sn =3D pkt_info->sn; =20 + /* + * skb_queue_tail() publishes the skb to the TX worker, which may + * process and free it immediately, so nothing may touch the skb + * past this point. + */ skb_queue_tail(&rtwsdio->tx_queue[queue], skb); =20 + rtw_sdio_8723bs_stop_tx_queue(rtwdev, queue, q_map); + return 0; } =20 @@ -1580,33 +1654,83 @@ static void rtw_sdio_indicate_tx_status(struct rtw_= dev *rtwdev, ieee80211_tx_status_irqsafe(hw, skb); } =20 -static void rtw_sdio_process_tx_queue(struct rtw_dev *rtwdev, - enum rtw_tx_queue_type queue) +/* + * Send one frame from @queue. Returns 0 when a frame was written, 1 when = the + * queue was empty and a negative errno when the write failed, in which ca= se + * the frame is put back at the head of the queue. + */ +static int rtw_sdio_process_tx_queue(struct rtw_dev *rtwdev, + enum rtw_tx_queue_type queue) { struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; struct sk_buff *skb; + u16 q_map; int ret; =20 skb =3D skb_dequeue(&rtwsdio->tx_queue[queue]); if (!skb) - return; + return 1; =20 ret =3D rtw_sdio_write_port(rtwdev, skb, queue); if (ret) { skb_queue_head(&rtwsdio->tx_queue[queue], skb); - return; + return ret; } =20 + /* rtw_sdio_indicate_tx_status() consumes the skb, so read this first */ + q_map =3D skb_get_queue_mapping(skb); + rtw_sdio_indicate_tx_status(rtwdev, skb); + + rtw_sdio_8723bs_wake_tx_queue(rtwdev, queue, q_map); + + return 0; +} + +/* + * Decide whether the RTL8723BS wants the TX work to run again, and if so + * arrange it and tell the caller to stop draining. Two cases need it. + * + * A transmit page or output queue shortage and a failed skb expansion are + * transient and leave the frame queued, so come back for it shortly. That + * matters once the mac80211 queue can be stopped: a stopped queue is hand= ed + * no further frames, so nothing else would kick this work item and the ac= cess + * category would stay stopped for good. The remaining errors are logged w= here + * they happen and are not retried. + * + * After a management frame, restart from the highest priority queue so the + * join sequence is not held up behind a data backlog. + */ +static bool rtw_sdio_8723bs_reschedule_tx(struct rtw_dev *rtwdev, + struct rtw_sdio_work_data *work_data, + enum rtw_tx_queue_type queue, int ret) +{ + struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; + unsigned long delay; + + if (!rtw_is_8723bs(rtwdev)) + return false; + + if (ret =3D=3D -EBUSY || ret =3D=3D -ENOMEM) + delay =3D RTW_SDIO_TX_RETRY_DELAY; + else if (ret =3D=3D 0 && queue =3D=3D RTW_TX_QUEUE_MGMT) + delay =3D 0; + else + return false; + + queue_delayed_work(rtwsdio->txwq, &work_data->work, delay); + + return true; } =20 static void rtw_sdio_tx_handler(struct work_struct *work) { struct rtw_sdio_work_data *work_data =3D - container_of(work, struct rtw_sdio_work_data, work); + container_of(to_delayed_work(work), struct rtw_sdio_work_data, + work); struct rtw_sdio *rtwsdio; struct rtw_dev *rtwdev; - int limit, queue; + int limit, queue, ret; =20 rtwdev =3D work_data->rtwdev; rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; @@ -1616,7 +1740,13 @@ static void rtw_sdio_tx_handler(struct work_struct *= work) =20 for (queue =3D RTK_MAX_TX_QUEUE_NUM - 1; queue >=3D 0; queue--) { for (limit =3D 0; limit < 1000; limit++) { - rtw_sdio_process_tx_queue(rtwdev, queue); + ret =3D rtw_sdio_process_tx_queue(rtwdev, queue); + if (ret > 0) + break; + + if (rtw_sdio_8723bs_reschedule_tx(rtwdev, work_data, + queue, ret)) + return; =20 if (skb_queue_empty(&rtwsdio->tx_queue[queue])) break; @@ -1645,14 +1775,16 @@ static int rtw_sdio_init_tx(struct rtw_dev *rtwdev) =20 mutex_init(&rtwsdio->tx_credit_lock); =20 - for (i =3D 0; i < RTK_MAX_TX_QUEUE_NUM; i++) + for (i =3D 0; i < RTK_MAX_TX_QUEUE_NUM; i++) { skb_queue_head_init(&rtwsdio->tx_queue[i]); + rtwsdio->tx_queue_stopped[i] =3D false; + } rtwsdio->tx_handler_data =3D kmalloc_obj(*rtwsdio->tx_handler_data); if (!rtwsdio->tx_handler_data) goto err_destroy_wq; =20 rtwsdio->tx_handler_data->rtwdev =3D rtwdev; - INIT_WORK(&rtwsdio->tx_handler_data->work, rtw_sdio_tx_handler); + INIT_DELAYED_WORK(&rtwsdio->tx_handler_data->work, rtw_sdio_tx_handler); =20 return 0; =20 @@ -1667,6 +1799,7 @@ static void rtw_sdio_deinit_tx(struct rtw_dev *rtwdev) struct rtw_sdio *rtwsdio =3D (struct rtw_sdio *)rtwdev->priv; int i; =20 + cancel_delayed_work_sync(&rtwsdio->tx_handler_data->work); destroy_workqueue(rtwsdio->txwq); kfree(rtwsdio->tx_handler_data); =20 diff --git a/drivers/net/wireless/realtek/rtw88/sdio.h b/drivers/net/wirele= ss/realtek/rtw88/sdio.h index 634c0b1339bb..6e7e6009744b 100644 --- a/drivers/net/wireless/realtek/rtw88/sdio.h +++ b/drivers/net/wireless/realtek/rtw88/sdio.h @@ -156,7 +156,7 @@ struct rtw_sdio_tx_data { }; =20 struct rtw_sdio_work_data { - struct work_struct work; + struct delayed_work work; struct rtw_dev *rtwdev; }; =20 @@ -172,6 +172,7 @@ struct rtw_sdio { struct workqueue_struct *txwq; struct rtw_sdio_work_data *tx_handler_data; struct sk_buff_head tx_queue[RTK_MAX_TX_QUEUE_NUM]; + bool tx_queue_stopped[RTK_MAX_TX_QUEUE_NUM]; =20 atomic_t free_pg_high; atomic_t free_pg_normal; --=20 2.53.0