Compare commits
3 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| c4797b1dbf | |||
| 90f50b375f | |||
| f2cf586f89 |
@@ -511,6 +511,9 @@ struct bes2600_common {
|
||||
struct list_head coex_event_list;
|
||||
spinlock_t coex_event_lock;
|
||||
|
||||
/* Connection-loss-storm fast-recover (Trigger A). See sta.c. */
|
||||
struct work_struct connection_loss_storm_recover_work;
|
||||
|
||||
/* member for low power */
|
||||
struct bes2600_pwr_t bes_power;
|
||||
|
||||
@@ -627,6 +630,10 @@ struct bes2600_vif {
|
||||
/* CQM Implementation */
|
||||
struct delayed_work bss_loss_work;
|
||||
struct delayed_work connection_loss_work;
|
||||
/* Connection-loss-storm fast-recover (Trigger A). See sta.c. */
|
||||
unsigned long connection_loss_storm_window_start;
|
||||
unsigned int connection_loss_storm_count;
|
||||
unsigned int connection_loss_storm_recoveries;
|
||||
struct work_struct tx_failure_work;
|
||||
int delayed_link_loss;
|
||||
spinlock_t bss_loss_lock;
|
||||
@@ -865,4 +872,9 @@ void bes2600_btusb_uninit(struct usb_interface *interface);
|
||||
void bes2600_decrypt_storm_init(struct bes2600_vif *priv);
|
||||
void bes2600_decrypt_storm_account(struct bes2600_vif *priv);
|
||||
|
||||
/* Connection-loss-storm fast-recover helpers — see sta.c. */
|
||||
void bes2600_connection_loss_storm_init(struct bes2600_vif *priv);
|
||||
bool bes2600_connection_loss_storm_account(struct bes2600_vif *priv);
|
||||
void bes2600_connection_loss_storm_recover(struct work_struct *work);
|
||||
|
||||
#endif /* BES2600_H */
|
||||
|
||||
+28
-9
@@ -29,6 +29,7 @@
|
||||
#include <linux/of_gpio.h>
|
||||
|
||||
#include "bes2600.h"
|
||||
#include "bh.h"
|
||||
#include "sbus.h"
|
||||
#include "bes2600_plat.h"
|
||||
#include "bes2600_factory.h"
|
||||
@@ -812,10 +813,23 @@ static int bes2600_sdio_extract_packets(struct sbus_priv *self, u32 ctrl_reg, u8
|
||||
skb_put(skb, packet_len);
|
||||
memcpy(skb->data, &data[pos], packet_len);
|
||||
bes_devel("%s, %d,%d\n", __func__, packet_len, pos);
|
||||
spin_lock(&self->rx_queue_lock);
|
||||
skb_queue_tail(&self->rx_queue, skb);
|
||||
self->rx_data_cnt++;
|
||||
spin_unlock(&self->rx_queue_lock);
|
||||
/*
|
||||
* Patch C: deliver SKB directly into the WSM/mac80211 stack
|
||||
* instead of skb_queue_tail-ing onto self->rx_queue for later
|
||||
* pickup by the bh thread. Removes two spinlock acquires
|
||||
* (rx_queue->lock at queue-tail + at dequeue) per RX frame
|
||||
* and one bh wait-queue wake-up per IRQ batch.
|
||||
*
|
||||
* bes2600_bh_handle_rx_skb owns the SKB on every path.
|
||||
* Contract: process context, sleepable, caller holds no
|
||||
* bes2600 spinlock. See bh.c for the contract block.
|
||||
*
|
||||
* Pre-condition satisfied here: bes2600_sdio_unlock(self)
|
||||
* was called at the bottom of the SDIO read sequence in
|
||||
* sdio_rx_work, so we hold no bes2600 mutex either.
|
||||
*/
|
||||
bes2600_bh_handle_rx_skb(self->core, skb);
|
||||
packet_len = (packet_len + 3) & (~0x3);
|
||||
pos += packet_len;
|
||||
#ifdef BES_SDIO_OPTIMIZED_LEN
|
||||
@@ -898,12 +912,17 @@ static void sdio_rx_work(struct work_struct *work)
|
||||
|
||||
ctrl_reg = 0;
|
||||
|
||||
if (likely(self->irq_handler)) {
|
||||
self->irq_handler(self->irq_priv);
|
||||
} else {
|
||||
bes_err("%s,%d\n", __func__, __LINE__);
|
||||
goto failed;
|
||||
}
|
||||
/*
|
||||
* Patch C: with direct delivery in extract_packets, the bh
|
||||
* thread no longer drives RX consumption — there is no
|
||||
* rx_queue to drain. Calling self->irq_handler() here would
|
||||
* wake the bh thread for nothing on every IRQ batch. TX
|
||||
* wakes still flow through bes2600_bh_wakeup() from TX
|
||||
* submitters and from bes2600_bh_handle_rx_skb when a
|
||||
* confirm releases a TX buffer; early-boot IRQs (before
|
||||
* fw_started) still go through self->irq_handler from the
|
||||
* GPIO IRQ handler's fallback branch.
|
||||
*/
|
||||
|
||||
} while (again);
|
||||
|
||||
|
||||
@@ -484,6 +484,18 @@ int bes2600_chrdev_do_bus_reset(const struct sbus_ops *sbus_ops, struct sbus_pri
|
||||
return 0;
|
||||
}
|
||||
|
||||
/*
|
||||
* Trigger bes2600_chrdev_do_bus_reset() against the file-global
|
||||
* bes2600_cdev. Used by host-side recovery paths outside this
|
||||
* compilation unit (e.g. sta.c connection-loss-storm fast-recover) so
|
||||
* those callers do not need to reach the static bes2600_cdev directly.
|
||||
*/
|
||||
int bes2600_chrdev_trigger_bus_reset(void)
|
||||
{
|
||||
return bes2600_chrdev_do_bus_reset(bes2600_cdev.sbus_ops,
|
||||
bes2600_cdev.sbus_priv);
|
||||
}
|
||||
|
||||
bool bes2600_chrdev_is_wifi_opened(void)
|
||||
{
|
||||
bool wifi_opened = false;
|
||||
|
||||
@@ -61,6 +61,7 @@ struct sbus_priv *bes2600_chrdev_get_sbus_priv_data(void);
|
||||
int bes2600_chrdev_check_system_close(void);
|
||||
int bes2600_chrdev_do_system_close(const struct sbus_ops *sbus_ops, struct sbus_priv *priv);
|
||||
int bes2600_chrdev_do_bus_reset(const struct sbus_ops *sbus_ops, struct sbus_priv *priv);
|
||||
int bes2600_chrdev_trigger_bus_reset(void);
|
||||
void bes2600_chrdev_wakeup_bt(void);
|
||||
void bes2600_chrdev_wifi_force_close(struct bes2600_common *hw_priv, bool halt_dev);
|
||||
void bes2600_chrdev_usb_remove(struct bes2600_common *hw_priv);
|
||||
|
||||
+109
@@ -958,6 +958,115 @@ static void bes2600_bh_parse_wakeup_event(struct bes2600_common *hw_priv, struct
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
* Direct-deliver an RX SKB into the WSM/mac80211 stack.
|
||||
*
|
||||
* Patch C (sdio_rx_work direct delivery): this function does the
|
||||
* per-SKB bookkeeping (sequence-number check, exception handling,
|
||||
* tx-confirm accounting, mac80211 hand-off via wsm_handle_rx) that
|
||||
* previously ran inside bes2600_bh_rx_helper after pipe_read dequeued
|
||||
* an SKB from sbus_priv->rx_queue. It is now called inline from
|
||||
* bes2600_sdio_extract_packets, eliminating the queue + bh-wakeup
|
||||
* relay (one wait-queue wake-up + two rx_queue->lock acquires per
|
||||
* RX frame).
|
||||
*
|
||||
* Contract:
|
||||
* - process context, sleepable. wsm_handle_rx (wsm.c:2211, exported
|
||||
* at wsm.c:2463) acquires wsm_cmd.lock, may call into mac80211
|
||||
* and may sleep on wait_event_timeout (wsm.c:2036, 2091).
|
||||
* - caller MUST hold no bes2600 spinlock. Reference precedent:
|
||||
* bes2600_bh_rx_helper (this file) called from the bh thread.
|
||||
* The SDIO mutex is released at bes2600_sdio.c before
|
||||
* extract_packets is called, so this is satisfied.
|
||||
* - SKB ownership: function frees on every path (success and error).
|
||||
* - Returns 0 on success, negative on error. When the SKB carries
|
||||
* a confirm that releases a TX buffer, the function asynchronously
|
||||
* wakes the bh thread to drain TX (matches the in-bh tx=1
|
||||
* signaling that bh_rx_helper used).
|
||||
*/
|
||||
int bes2600_bh_handle_rx_skb(struct bes2600_common *priv, struct sk_buff *skb)
|
||||
{
|
||||
struct wsm_hdr *wsm;
|
||||
size_t wsm_len;
|
||||
u16 wsm_id;
|
||||
u8 wsm_seq;
|
||||
int tx = 0;
|
||||
u32 confirm_label = 0x0;
|
||||
|
||||
if (!skb)
|
||||
return 0;
|
||||
|
||||
wsm = (struct wsm_hdr *)skb->data;
|
||||
wsm_len = __le16_to_cpu(wsm->len);
|
||||
if (WARN_ON(wsm_len > skb->len)) {
|
||||
bes_err("wsm_len err %d %d\n", (int)wsm_len, (int)skb->len);
|
||||
dev_kfree_skb(skb);
|
||||
return -1;
|
||||
}
|
||||
|
||||
if (priv->wsm_enable_wsm_dumps)
|
||||
print_hex_dump(KERN_DEBUG, "<-- ", DUMP_PREFIX_NONE, 16, 1,
|
||||
skb->data, wsm_len, false);
|
||||
|
||||
wsm_id = __le16_to_cpu(wsm->id) & 0xFFF;
|
||||
wsm_seq = (__le16_to_cpu(wsm->id) >> 13) & 7;
|
||||
bes_devel("bes2600_bh_handle_rx_skb wsm_id:0x%04x seq:%d\n",
|
||||
wsm_id, wsm_seq);
|
||||
|
||||
skb_trim(skb, wsm_len);
|
||||
|
||||
if (wsm_id == 0x0800) {
|
||||
wsm_handle_exception(priv,
|
||||
&skb->data[sizeof(*wsm)],
|
||||
wsm_len - sizeof(*wsm));
|
||||
bes_err("wsm exception\n");
|
||||
dev_kfree_skb(skb);
|
||||
return -1;
|
||||
} else if ((wsm_seq != priv->wsm_rx_seq[WSM_TXRX_SEQ_IDX(wsm_id)])) {
|
||||
bes_err("seq error! %u. %u. 0x%x.", wsm_seq,
|
||||
priv->wsm_rx_seq[WSM_TXRX_SEQ_IDX(wsm_id)], wsm_id);
|
||||
dev_kfree_skb(skb);
|
||||
return -1;
|
||||
}
|
||||
|
||||
bes2600_bh_parse_wakeup_event(priv, skb);
|
||||
|
||||
priv->wsm_rx_seq[WSM_TXRX_SEQ_IDX(wsm_id)] = (wsm_seq + 1) & 7;
|
||||
|
||||
if (IS_DRIVER_TO_MCU_CMD(wsm_id))
|
||||
confirm_label = __le32_to_cpu(((struct wsm_mcu_hdr *)wsm)->handle_label);
|
||||
|
||||
if (WSM_CONFIRM_CONDITION(wsm_id, confirm_label)) {
|
||||
int rc = wsm_release_tx_buffer(priv, 1);
|
||||
bes2600_bh_dec_pending_count(priv, WSM_TXRX_SEQ_IDX(wsm->id));
|
||||
|
||||
if (rc < 0) {
|
||||
bes_err("wsm_release_tx_buffer failed: %d\n", rc);
|
||||
dev_kfree_skb(skb);
|
||||
return rc;
|
||||
} else if (rc > 0) {
|
||||
tx = 1;
|
||||
}
|
||||
}
|
||||
|
||||
/* wsm_handle_rx takes care of SKB lifetime: zeroes *skb_p if consumed. */
|
||||
if (wsm_handle_rx(priv, wsm_id, wsm, &skb)) {
|
||||
bes_err("wsm_handle_rx failed (id=0x%04x)\n", wsm_id);
|
||||
if (skb)
|
||||
dev_kfree_skb(skb);
|
||||
return -1;
|
||||
}
|
||||
|
||||
if (skb)
|
||||
dev_kfree_skb(skb);
|
||||
|
||||
if (tx)
|
||||
bes2600_bh_wakeup(priv);
|
||||
|
||||
return 0;
|
||||
}
|
||||
EXPORT_SYMBOL(bes2600_bh_handle_rx_skb);
|
||||
|
||||
static int bes2600_bh_rx_helper(struct bes2600_common *priv, int *tx)
|
||||
{
|
||||
struct sk_buff *skb = NULL;
|
||||
|
||||
@@ -36,6 +36,13 @@ void bes2600_enable_powersave(struct bes2600_vif *priv,
|
||||
int wsm_release_tx_buffer(struct bes2600_common *hw_priv, int count);
|
||||
int wsm_release_vif_tx_buffer(struct bes2600_common *hw_priv, int if_id,
|
||||
int count);
|
||||
/*
|
||||
* Direct-deliver an RX SKB into the WSM/mac80211 stack.
|
||||
* Process context, sleepable, caller holds no bes2600 spinlock.
|
||||
* Function frees skb on every path. See bh.c for full contract.
|
||||
*/
|
||||
int bes2600_bh_handle_rx_skb(struct bes2600_common *hw_priv,
|
||||
struct sk_buff *skb);
|
||||
int bes2600_bh_sw_process(struct bes2600_common *hw_priv,
|
||||
struct wsm_tx_confirm *tx_confirm);
|
||||
|
||||
|
||||
@@ -544,6 +544,8 @@ static int bes2600_status_show_priv(struct seq_file *seq, void *v)
|
||||
bes2600_debug_join_status[priv->join_status]);
|
||||
seq_printf(seq, "DecryptStormRecoveries: %u\n",
|
||||
priv->decrypt_storm_recoveries);
|
||||
seq_printf(seq, "ConnectionLossStormRecoveries: %u\n",
|
||||
priv->connection_loss_storm_recoveries);
|
||||
if (priv->rx_filter.promiscuous)
|
||||
seq_puts(seq, "Filter: promisc\n");
|
||||
else if (priv->rx_filter.fcs)
|
||||
|
||||
@@ -484,6 +484,8 @@ static struct ieee80211_hw *bes2600_init_common(size_t hw_priv_data_len)
|
||||
spin_lock_init(&hw_priv->rtsvalue_lock);
|
||||
INIT_WORK(&hw_priv->dynamic_opt_txrx_work, bes2600_dynamic_opt_txrx_work);
|
||||
INIT_WORK(&hw_priv->tx_policy_upload_work, tx_policy_upload_work);
|
||||
INIT_WORK(&hw_priv->connection_loss_storm_recover_work,
|
||||
bes2600_connection_loss_storm_recover);
|
||||
spin_lock_init(&hw_priv->event_queue_lock);
|
||||
INIT_LIST_HEAD(&hw_priv->event_queue);
|
||||
INIT_WORK(&hw_priv->event_handler, bes2600_event_handler);
|
||||
|
||||
+80
-2
@@ -266,6 +266,7 @@ void bes2600_stop(struct ieee80211_hw *dev, bool suspend)
|
||||
cancel_work_sync(&hw_priv->coex_work);
|
||||
coex_stop(hw_priv);
|
||||
#endif
|
||||
cancel_work_sync(&hw_priv->connection_loss_storm_recover_work);
|
||||
|
||||
bes2600_wifi_stop(hw_priv);
|
||||
|
||||
@@ -1659,6 +1660,70 @@ report:
|
||||
spin_unlock(&priv->bss_loss_lock);
|
||||
}
|
||||
|
||||
/*
|
||||
* Connection-loss-storm fast-recover (Trigger A).
|
||||
*
|
||||
* bes2600_connection_loss_work below is the driver's own decision-point
|
||||
* to give up on a BSS (after bss-loss detection accumulates beyond
|
||||
* tolerance) and tell mac80211 via ieee80211_connection_loss(). On the
|
||||
* deployed pinetab2 stack a single ieee80211_connection_loss() event
|
||||
* sometimes triggers a userspace reauth blackhole (assoc-comeback
|
||||
* timeouts followed by AP unprotected-deauth-reason-6) that ends only
|
||||
* via cross-channel/cross-SSID fallback and can take 80+ s. Receipts at
|
||||
* https://git.reauktion.de/marfrit/besser, notes/phase4-2026-05-07.md.
|
||||
*
|
||||
* When N connection-loss decisions land within WINDOW on the same vif,
|
||||
* skip the ieee80211_connection_loss() path and trigger a chip-level
|
||||
* bus_reset (the c5.2-introduced bes2600_chrdev_do_bus_reset). The chip
|
||||
* is removed and re-probed; userspace re-associates from a fresh state,
|
||||
* dodging the assoc-comeback loop.
|
||||
*
|
||||
* Threshold (3 / 60 s) is chosen well above the steady-state per-vif
|
||||
* connection-loss rate observed in the patch-A Phase-7 rep
|
||||
* (0.86/h under sustained load), so a true storm is required.
|
||||
*
|
||||
* The recover work_struct lives on bes2600_common (hw_priv) so that
|
||||
* scheduling it does not race with vif teardown after bus_reset frees
|
||||
* the per-vif state.
|
||||
*/
|
||||
#define BES2600_CONNECTION_LOSS_STORM_THRESHOLD 3
|
||||
#define BES2600_CONNECTION_LOSS_STORM_WINDOW_MS 60000
|
||||
|
||||
void bes2600_connection_loss_storm_recover(struct work_struct *work)
|
||||
{
|
||||
bes_warn("[bes2600] connection-loss-storm fast-recover: bus_reset\n");
|
||||
bes2600_chrdev_trigger_bus_reset();
|
||||
/*
|
||||
* After bes2600_chrdev_do_bus_reset() returns, the SDIO core has
|
||||
* scheduled a remove + rescan; per-vif state may already be gone.
|
||||
* Do not dereference any per-vif pointer here.
|
||||
*/
|
||||
}
|
||||
|
||||
void bes2600_connection_loss_storm_init(struct bes2600_vif *priv)
|
||||
{
|
||||
priv->connection_loss_storm_window_start = 0;
|
||||
priv->connection_loss_storm_count = 0;
|
||||
priv->connection_loss_storm_recoveries = 0;
|
||||
}
|
||||
|
||||
bool bes2600_connection_loss_storm_account(struct bes2600_vif *priv)
|
||||
{
|
||||
unsigned long now = jiffies;
|
||||
unsigned long window =
|
||||
msecs_to_jiffies(BES2600_CONNECTION_LOSS_STORM_WINDOW_MS);
|
||||
|
||||
if (priv->connection_loss_storm_window_start == 0 ||
|
||||
time_after(now, priv->connection_loss_storm_window_start + window)) {
|
||||
priv->connection_loss_storm_window_start = now;
|
||||
priv->connection_loss_storm_count = 1;
|
||||
return false;
|
||||
}
|
||||
|
||||
return ++priv->connection_loss_storm_count >=
|
||||
BES2600_CONNECTION_LOSS_STORM_THRESHOLD;
|
||||
}
|
||||
|
||||
void bes2600_connection_loss_work(struct work_struct *work)
|
||||
{
|
||||
struct bes2600_vif *priv =
|
||||
@@ -1668,9 +1733,21 @@ void bes2600_connection_loss_work(struct work_struct *work)
|
||||
|
||||
bes_devel("[CQM] Reporting connection loss.\n");
|
||||
bes2600_pwr_clear_busy_event(priv->hw_priv, BES_PWR_LOCK_ON_BSS_LOST);
|
||||
if(bes2600_suspend_status_get(hw_priv)) {
|
||||
|
||||
if (bes2600_connection_loss_storm_account(priv)) {
|
||||
bes_warn("[bes2600] connection-loss storm: %u in %u s, scheduling bus reset\n",
|
||||
priv->connection_loss_storm_count,
|
||||
BES2600_CONNECTION_LOSS_STORM_WINDOW_MS / 1000);
|
||||
priv->connection_loss_storm_count = 0;
|
||||
priv->connection_loss_storm_recoveries++;
|
||||
schedule_work(&hw_priv->connection_loss_storm_recover_work);
|
||||
/* bus_reset will tear the chip down; skip the mac80211 path. */
|
||||
return;
|
||||
}
|
||||
|
||||
if (bes2600_suspend_status_get(hw_priv))
|
||||
bes2600_pending_unjoin_set(hw_priv, priv->if_id);
|
||||
} else
|
||||
else
|
||||
ieee80211_connection_loss(priv->vif);
|
||||
#ifdef WIFI_BT_COEXIST_EPTA_ENABLE
|
||||
// set disconnected in BSS_CHANGED_ASSOC
|
||||
@@ -2621,6 +2698,7 @@ int bes2600_vif_setup(struct bes2600_vif *priv)
|
||||
/* Setup per vif workitems and locks */
|
||||
spin_lock_init(&priv->vif_lock);
|
||||
bes2600_decrypt_storm_init(priv);
|
||||
bes2600_connection_loss_storm_init(priv);
|
||||
INIT_WORK(&priv->join_work, bes2600_join_work);
|
||||
INIT_DELAYED_WORK(&priv->join_timeout, bes2600_join_timeout);
|
||||
INIT_WORK(&priv->unjoin_work, bes2600_unjoin_work);
|
||||
|
||||
Reference in New Issue
Block a user