From: luka.gejak@linux.dev
To: Ping-Ke Shih <pkshih@realtek.com>, linux-wireless@vger.kernel.org
Cc: linux-kernel@vger.kernel.org,
Michael Straube <straube.linux@gmail.com>,
Bitterblue Smith <rtl8821cerfe2@gmail.com>,
Peter Robinson <pbrobinson@gmail.com>,
Hans de Goede <johannes.goede@oss.qualcomm.com>,
Luka Gejak <luka.gejak@linux.dev>
Subject: [PATCH v4 4/7] wifi: rtw88: fw: handle the RTL8723BS management TX reports
Date: Tue, 11 Aug 2026 09:12:00 +0000 [thread overview]
Message-ID: <20260811091203.26841-5-luka.gejak@linux.dev> (raw)
In-Reply-To: <20260811091203.26841-1-luka.gejak@linux.dev>
From: Luka Gejak <luka.gejak@linux.dev>
The vendor firmware used by the RTL8723BS does not report management
frame transmission through C2H_CCX_TX_RPT. It uses event 0x12, and
reuses 0x32 for scan probe reports, which rtw88 otherwise treats as a
WLAN_RFON event and completes the LPS leave check with.
Route both events to the existing TX report handler for this chip, and
defer 0x32 to the worker instead of consuming it in the interrupt path,
so the reports are decoded and the LPS handshake is left alone. The
payload layout is the same as C2H_CCX_TX_RPT, so no separate decode is
needed.
Without this, testers on ARM SDIO boards see "failed to get tx report
from firmware" and "firmware failed to leave lps state" once power save
engages under load.
Reported-by: Peter Robinson <pbrobinson@gmail.com>
Closes: https://lore.kernel.org/all/CALeDE9PgQmpMfDt1DgfLD4tBFGH0MZ7GncV6RUEOHhHbKF+TdQ@mail.gmail.com/
Signed-off-by: Luka Gejak <luka.gejak@linux.dev>
---
drivers/net/wireless/realtek/rtw88/fw.c | 20 ++++++++++++++++++++
drivers/net/wireless/realtek/rtw88/fw.h | 5 +++++
2 files changed, 25 insertions(+)
diff --git a/drivers/net/wireless/realtek/rtw88/fw.c b/drivers/net/wireless/realtek/rtw88/fw.c
index 945fedcd375b..c85c0e3e60a9 100644
--- a/drivers/net/wireless/realtek/rtw88/fw.c
+++ b/drivers/net/wireless/realtek/rtw88/fw.c
@@ -317,6 +317,15 @@ void rtw_fw_c2h_cmd_handle(struct rtw_dev *rtwdev, struct sk_buff *skb)
case C2H_CCX_TX_RPT:
rtw_tx_report_handle(rtwdev, skb, C2H_CCX_TX_RPT);
break;
+ case C2H_VENDOR_TX_RPT:
+ case C2H_WLAN_RFON:
+ /*
+ * The RTL8723BS firmware reports management TX through these
+ * two events instead, using the same payload layout.
+ */
+ if (rtw_is_8723bs(rtwdev))
+ rtw_tx_report_handle(rtwdev, skb, C2H_CCX_TX_RPT);
+ break;
case C2H_BT_INFO:
rtw_coex_bt_info_notify(rtwdev, c2h->payload, len);
break;
@@ -365,6 +374,17 @@ void rtw_fw_c2h_cmd_rx_irqsafe(struct rtw_dev *rtwdev, u32 pkt_offset,
rtw_coex_info_response(rtwdev, skb);
break;
case C2H_WLAN_RFON:
+ /*
+ * On 8723BS SDIO with v41 firmware, C2H 0x32 carries a scan TX
+ * report, not a WLAN_RFON event: defer it to
+ * rtw_fw_c2h_cmd_handle().
+ */
+ if (rtw_is_8723bs(rtwdev)) {
+ *((u32 *)skb->cb) = pkt_offset;
+ skb_queue_tail(&rtwdev->c2h_queue, skb);
+ ieee80211_queue_work(rtwdev->hw, &rtwdev->c2h_work);
+ break;
+ }
complete(&rtwdev->lps_leave_check);
dev_kfree_skb_any(skb);
break;
diff --git a/drivers/net/wireless/realtek/rtw88/fw.h b/drivers/net/wireless/realtek/rtw88/fw.h
index 48ad9ceab6ea..bdda78dc6462 100644
--- a/drivers/net/wireless/realtek/rtw88/fw.h
+++ b/drivers/net/wireless/realtek/rtw88/fw.h
@@ -54,6 +54,11 @@ enum rtw_c2h_cmd_id {
C2H_BT_MP_INFO = 0x0b,
C2H_BT_HID_INFO = 0x45,
C2H_RA_RPT = 0x0c,
+ /*
+ * 8723BS SDIO vendor v41 firmware management TX report (0x32 is
+ * reported as C2H_WLAN_RFON, handled per-chip in the C2H dispatch).
+ */
+ C2H_VENDOR_TX_RPT = 0x12,
C2H_HW_FEATURE_REPORT = 0x19,
C2H_WLAN_INFO = 0x27,
C2H_WLAN_RFON = 0x32,
--
2.53.0
next prev parent reply other threads:[~2026-08-11 9:13 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-11 9:11 [PATCH v4 0/7] wifi: rtw88: preparations for RTL8723B/RTL8723BS luka.gejak
2026-08-11 9:11 ` [PATCH v4 1/7] wifi: rtw88: add the RTL8723B chip type and SDIO helper luka.gejak
2026-08-11 9:11 ` [PATCH v4 2/7] wifi: rtw88: rx: mark zero length packets on RTL8723BS luka.gejak
2026-08-11 9:11 ` [PATCH v4 3/7] wifi: rtw88: tx: extend the TX report purge timeout to RTL8723BS luka.gejak
2026-08-11 9:12 ` luka.gejak [this message]
2026-08-11 11:42 ` [PATCH v4 4/7] wifi: rtw88: fw: handle the RTL8723BS management TX reports Bitterblue Smith
2026-08-11 9:12 ` [PATCH v4 5/7] wifi: rtw88: sdio: track free TX pages and OQT credits for RTL8723BS luka.gejak
2026-08-11 9:12 ` [PATCH v4 6/7] wifi: rtw88: sdio: set up RX aggregation and interrupts " luka.gejak
2026-08-11 9:12 ` [PATCH v4 7/7] wifi: rtw88: sdio: add TX back-pressure and retry on page starvation luka.gejak
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260811091203.26841-5-luka.gejak@linux.dev \
--to=luka.gejak@linux.dev \
--cc=johannes.goede@oss.qualcomm.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=pbrobinson@gmail.com \
--cc=pkshih@realtek.com \
--cc=rtl8821cerfe2@gmail.com \
--cc=straube.linux@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox