From: Sean Wang <sean.wang@kernel.org>
To: nbd@nbd.name
Cc: linux-wireless@vger.kernel.org,
linux-mediatek@lists.infradead.org, yu-ching.liu@mediatek.com,
jenhao.yang@mediatek.com, posh.sun@mediatek.com,
Jacobs Wu <jacobs.wu@mediatek.com>,
Sean Wang <sean.wang@mediatek.com>
Subject: [PATCH 19/23] wifi: mt76: mt7925: steer NAN handshake frames by committed-bitmap state
Date: Sun, 27 Sep 2026 16:03:01 -0500 [thread overview]
Message-ID: <20260927210306.737669-20-sean.wang@kernel.org> (raw)
In-Reply-To: <20260927210306.737669-1-sean.wang@kernel.org>
From: Jacobs Wu <jacobs.wu@mediatek.com>
Unencrypted unicast NAN management is held to the discovery window on the
DW-WTBL, because a peer whose NDL is not yet confirmed is only reliably
awake there. That is the right call while nothing is known about the
peer, but it stays in force for the whole session, and the DW is a narrow
place to live: it opens for 16 ms every 512 ms and is shared with the
discovery queue, so roughly four transmit opportunities exist inside the
two seconds a Data Path Response has to complete. Under load the
handshake loses that race. Routing the same frames through the peer STA
WTBL was what made NDP setup reliable with a partial availability bitmap
in the first place, since the firmware then paces them by the committed
window instead of bursting blindly.
Neither placement is right on its own: the peer WTBL is only usable once
the firmware actually holds that peer's committed bitmap. A peer station
existing in mac80211 does not imply that - until the CRB download lands,
the peer's availability gate has no slots to open and a frame steered
there parks behind the pause until the session is torn down.
Track the committed state per peer. mt7925_nan_fill_crb_committed()
returns the number of committed slots it programmed, and
mt7925_nan_update_crb_tlv() latches whether that count was non-zero into
nan_sched.has_commit; the allocation rollback in
mt792x_nan_set_peer_schedule() and the peer record removal in
mt792x_nan_set_peer_rec() clear it again. Frames to a peer holding a
committed bitmap keep that peer's WTBL and are served in the slots it
has promised to be awake for; frames to a peer without one, and frames
with no station resolved, keep riding the DW-WTBL. Secured frames are
untouched and keep their own WTBL and key.
Co-developed-by: Sean Wang <sean.wang@mediatek.com>
Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Signed-off-by: Jacobs Wu <jacobs.wu@mediatek.com>
---
.../net/wireless/mediatek/mt76/mt7925/nan.c | 30 +++++++++++----
.../wireless/mediatek/mt76/mt7925/pci_mac.c | 37 +++++++------------
drivers/net/wireless/mediatek/mt76/mt792x.h | 1 +
3 files changed, 38 insertions(+), 30 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/nan.c b/drivers/net/wireless/mediatek/mt76/mt7925/nan.c
index 7aacfd6527e4..77a91a9ee4d4 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7925/nan.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/nan.c
@@ -1446,14 +1446,14 @@ static int mt7925_nan_peer_cap_tlv(struct sk_buff *skb,
return 0;
}
-static void
+static u32
mt7925_nan_fill_crb_committed(struct mt7925_nan_sched_update_crb_tlv *crb_tlv,
struct ieee80211_nan_peer_sched *sched)
{
- u32 m, slot;
+ u32 m, slot, total = 0;
if (!sched)
- return;
+ return 0;
for (m = 0; m < CFG80211_NAN_MAX_PEER_MAPS &&
m < NAN_TIMELINE_MGMT_SIZE; m++) {
@@ -1479,10 +1479,14 @@ mt7925_nan_fill_crb_committed(struct mt7925_nan_sched_update_crb_tlv *crb_tlv,
if (!ch || !ch->chanctx_conf)
continue;
+ total++;
+
for (dw = 0; dw < NAN_TOTAL_DW; dw++)
tl->avail_map[dw] |= cpu_to_le32(BIT(slot));
}
}
+
+ return total;
}
static int mt7925_nan_update_crb_tlv(struct sk_buff *skb,
@@ -1507,9 +1511,10 @@ static int mt7925_nan_update_crb_tlv(struct sk_buff *skb,
crb_tlv->is_use_ranging = false;
crb_tlv->comm_ndc_ctrl.is_valid = false;
- mt7925_nan_fill_crb_committed(crb_tlv, sta->nan_sched);
-
- return 0;
+ /* Returns the number of committed slots programmed; the caller latches
+ * has_commit only once the command has actually reached firmware.
+ */
+ return mt7925_nan_fill_crb_committed(crb_tlv, sta->nan_sched);
}
static int
@@ -1552,6 +1557,7 @@ int mt792x_nan_set_peer_schedule(struct mt792x_dev *dev,
struct mt792x_nan *nan;
struct mt76_dev *mdev;
struct sk_buff *skb;
+ int committed;
int ret;
if (!dev || !sta)
@@ -1590,7 +1596,8 @@ int mt792x_nan_set_peer_schedule(struct mt792x_dev *dev,
}
}
- if (mt7925_nan_update_crb_tlv(skb, sta, msta)) {
+ committed = mt7925_nan_update_crb_tlv(skb, sta, msta);
+ if (committed < 0) {
ret = -ENOMEM;
goto free_skb;
}
@@ -1603,6 +1610,13 @@ int mt792x_nan_set_peer_schedule(struct mt792x_dev *dev,
if (ret && idx_allocated)
goto clear_idx;
+ /* Latch only now: firmware holds this peer's committed bitmap, so its
+ * availability gate has slots to open and unencrypted NAF may be
+ * steered at the peer WTBL. Cleared when the CRB is torn down.
+ */
+ if (!ret)
+ msta->nan_sched.has_commit = committed > 0;
+
return ret;
free_skb:
@@ -1613,6 +1627,7 @@ int mt792x_nan_set_peer_schedule(struct mt792x_dev *dev,
clear_idx:
clear_bit(msta->nan_sched.sch_idx, &nan->conn_bitmap);
msta->nan_sched.idx_assigned = false;
+ msta->nan_sched.has_commit = false;
return ret;
}
@@ -1676,6 +1691,7 @@ int mt792x_nan_set_peer_rec(struct mt76_dev *mdev,
clear_bit(msta->nan_sched.sch_idx, &nan->conn_bitmap);
msta->nan_sched.idx_assigned = false;
+ msta->nan_sched.has_commit = false;
return 0;
}
diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/pci_mac.c b/drivers/net/wireless/mediatek/mt76/mt7925/pci_mac.c
index 5bdf3ebe6aef..6e9daf96da88 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7925/pci_mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/pci_mac.c
@@ -33,16 +33,15 @@ int mt7925e_tx_prepare_skb(struct mt76_dev *mdev, void *txwi_ptr,
* full retry budget on an unACKable multicast RA, so one frame eats a
* whole DW window and the publish SDF queue backlogs.
*
- * Unencrypted unicast to a peer we have no station for is first
- * contact (SDF, NDP request): the DW is the only rendezvous, so it
- * goes on the DW-WTBL and waits for it.
- *
- * Once its schedule is known - the peer station exists, which is also
- * when firmware holds its committed bitmap - the frame belongs on that
- * station instead. Firmware then airs it inside the peer's own
- * committed slots, where the peer is awake and the medium is not the
- * DW pile-up, and follows the FAW onto whatever channel the window
- * actually uses rather than being pinned to the DW channel.
+ * Unencrypted unicast is handshake traffic (SDF follow-up, NDP
+ * request/response, pairing bootstrap). Until firmware holds the
+ * peer's committed bitmap its availability gate has nothing to open,
+ * so a frame steered at the peer WTBL would park behind the BY_NAN
+ * pause; such frames ride the DW-WTBL, which firmware unpauses every
+ * DW - the one rendezvous both peers must be awake for. Once the CRB
+ * download latches has_commit, the frame keeps the peer's own WTBL
+ * and firmware serves it in the committed slots, which a 2-second
+ * handshake deadline needs (the DW alone offers only ~4 shots).
*
* Secured frames belong to an established peer and keep its own WTBL
* and key.
@@ -52,24 +51,16 @@ int mt7925e_tx_prepare_skb(struct mt76_dev *mdev, void *txwi_ptr,
struct mt792x_vif *mvif = (void *)vif->drv_priv;
bool mcast = is_multicast_ether_addr(hdr->addr1);
+ struct mt792x_sta *peer = (!mcast && sta) ?
+ (struct mt792x_sta *)sta->drv_priv : NULL;
+
if (mcast && wcid == &mvif->nan_dw_wcid) {
wcid = &mvif->sta.deflink.wcid;
} else if (!mcast && !key &&
+ !(peer && peer->nan_sched.has_commit) &&
mvif->nan_dw_wcid.idx &&
mvif->nan_dw_wcid.idx < MT792x_WTBL_STA) {
- struct ieee80211_sta *psta;
- struct mt792x_sta *pmsta;
-
- rcu_read_lock();
- psta = ieee80211_find_sta(vif, hdr->addr1);
- pmsta = psta ? (struct mt792x_sta *)psta->drv_priv :
- NULL;
-
- if (pmsta && pmsta->deflink.wcid.idx)
- wcid = &pmsta->deflink.wcid;
- else
- wcid = &mvif->nan_dw_wcid;
- rcu_read_unlock();
+ wcid = &mvif->nan_dw_wcid;
}
}
diff --git a/drivers/net/wireless/mediatek/mt76/mt792x.h b/drivers/net/wireless/mediatek/mt76/mt792x.h
index 8e1588970ac1..6ed0282775ba 100644
--- a/drivers/net/wireless/mediatek/mt76/mt792x.h
+++ b/drivers/net/wireless/mediatek/mt76/mt792x.h
@@ -133,6 +133,7 @@ struct mt792x_sta_nan_sched {
u16 committed_dw;
u32 sch_idx;
bool idx_assigned;
+ bool has_commit; /* last CRB carried a non-empty committed map */
unsigned long ndp_ctx_bitmap;
bool ndp_ctx_assigned;
u8 ndp_ctx_id; /* assigned NDP context ID (for NDI sta) */
--
2.43.0
next prev parent reply other threads:[~2026-09-27 21:10 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-27 21:02 [PATCH 00/23] wifi: mt76: mt7925: add NAN security and improve NDP reliability (part 2) Sean Wang
2026-09-27 21:02 ` [PATCH 01/23] wifi: mt76: mt7925: make NMI address TLV tail padding explicit Sean Wang
2026-09-27 21:02 ` [PATCH 02/23] wifi: mt76: mt7925: add NMI/NDI MAC address setter helpers Sean Wang
2026-10-06 9:25 ` Felix Fietkau
2026-09-27 21:02 ` [PATCH 03/23] wifi: mt76: mt7925: implement NAN MAC address randomization Sean Wang
2026-10-06 9:18 ` Felix Fietkau
2026-09-27 21:02 ` [PATCH 04/23] wifi: mt76: mt7925: wire up NAN MAC randomization lifecycle Sean Wang
2026-09-27 21:02 ` [PATCH 05/23] wifi: mt76: mt7925: add NAN low power event control on suspend/resume Sean Wang
2026-09-27 21:02 ` [PATCH 06/23] wifi: mt76: mt7925: implement NAN key management MCU command Sean Wang
2026-09-27 21:02 ` [PATCH 07/23] wifi: mt76: mt7925: add per-peer RX IGTK/BIGTK and RX GTK WTBLs Sean Wang
2026-09-27 21:02 ` [PATCH 08/23] wifi: mt76: mt7925: add NDC-aware TX GTK table for NAN_DATA Sean Wang
2026-10-06 9:20 ` Felix Fietkau
2026-09-27 21:02 ` [PATCH 09/23] wifi: mt76: mt7925: implement mt7925_nan_set_key for NAN security Sean Wang
2026-09-27 21:02 ` [PATCH 10/23] wifi: mt76: mt7925: install NAN BIP keys standalone in sta_key_tlv Sean Wang
2026-09-27 21:02 ` [PATCH 11/23] wifi: mt76: mt7925: do not disable RX NAPI twice on unload Sean Wang
2026-09-27 21:02 ` [PATCH 12/23] wifi: mt76: mt7925: assign the interface WTBL to the NAN management TXQ Sean Wang
2026-09-27 21:02 ` [PATCH 13/23] wifi: mt76: mt7925: do not deactivate shared NAN BSS on peer STA removal Sean Wang
2026-09-27 21:02 ` [PATCH 14/23] wifi: mt76: gate NAN unicast mgmt by peer availability via STA queues Sean Wang
2026-09-27 21:02 ` [PATCH 15/23] wifi: mt76: mt7925: hold NAN mgmt TX to the discovery window Sean Wang
2026-09-27 21:02 ` [PATCH 16/23] wifi: mt76: mt7925: double the retry budget for NAN unicast management Sean Wang
2026-09-27 21:02 ` [PATCH 17/23] wifi: mt76: mt7925: let TX status of DW-held NAN frames outlive the DW period Sean Wang
2026-09-27 21:03 ` [PATCH 18/23] wifi: mt76: mt7925: defer the NAN joined-cluster event out of NAN_START Sean Wang
2026-09-27 21:03 ` Sean Wang [this message]
2026-09-27 21:03 ` [PATCH 20/23] wifi: mt76: mt7925: disable only the RX NAPI instances that exist Sean Wang
2026-09-27 21:03 ` [PATCH 21/23] wifi: mt76: mt7925: stop queueing resets once the device is being removed Sean Wang
2026-09-27 21:03 ` [PATCH 22/23] wifi: mt76: mt7925: bound the lifetime of NAN unicast management frames Sean Wang
2026-09-27 21:03 ` [PATCH 23/23] wifi: mt76: mt7925: always deliver the joined-cluster event through the deferred work Sean Wang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260927210306.737669-20-sean.wang@kernel.org \
--to=sean.wang@kernel.org \
--cc=jacobs.wu@mediatek.com \
--cc=jenhao.yang@mediatek.com \
--cc=linux-mediatek@lists.infradead.org \
--cc=linux-wireless@vger.kernel.org \
--cc=nbd@nbd.name \
--cc=posh.sun@mediatek.com \
--cc=sean.wang@mediatek.com \
--cc=yu-ching.liu@mediatek.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox