From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 From: Markus Zehnder Date: Wed, 9 Sep 2026 17:12:51 +0200 Subject: [PATCH] brcmfmac: report the join target on a failed connect profile->bssid is written only when a join succeeds (brcmf_is_linkup) or a roam completes (brcmf_bss_roaming_done), so brcmf_bss_connect_done() reports a *failed* join against the BSSID of the previous association. After a no-WOWL suspend brcmf_link_down() runs without brcmf_init_prof(), and the first failed join after the wake is therefore reported with the BSSID of the AP the device slept on. wpa_supplicant then puts that AP on its BSSID ignore list instead of the one it actually tried (Remote 3, two-AP network, 3 of 3 wakes on 2026-09-09). Once the link-down event handler has zeroed the profile, later failures are reported with 00:00:00:00:00:00, which the supplicant replaces with its own pending BSSID - so only the first reject after a suspend is misattributed, and it is misattributed every time. Keep the join target in the profile when a connect (or FT reassoc) is issued and report that on failure. A successful join still reports the BSSID the firmware associated with. An all-zero target (the supplicant left the choice to the firmware) is reported as before, so the supplicant's fallback keeps working. profile->bssid itself is untouched: the link-down handler compares it with the event address while connected, and brcmf_cfg80211_disconnect() uses it for the DISASSOC. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_016RuiYS68fr5Zq6Ji5A9YXe --- .../broadcom/brcm80211/brcmfmac/cfg80211.c | 18 +++++++++++++++++- .../broadcom/brcm80211/brcmfmac/cfg80211.h | 2 ++ 2 files changed, 19 insertions(+), 1 deletion(-) diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c index 28e7d780a..8919721f8 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c @@ -3019,6 +3019,7 @@ brcmf_cfg80211_connect(struct wiphy *wiphy, struct net_device *ndev, brcmf_dbg(CONN, "Trying to REASSOC For FT\n"); memset(&ext_roam_params, 0, sizeof(ext_roam_params)); memcpy(&ext_roam_params.bssid, sme->bssid, ETH_ALEN); + memcpy(profile->target_bssid, sme->bssid, ETH_ALEN); set_bit(BRCMF_VIF_STATUS_CONNECTING, &ifp->vif->sme_state); err = brcmf_fil_cmd_data_set(ifp, BRCMF_C_REASSOC, @@ -3058,6 +3059,15 @@ brcmf_cfg80211_connect(struct wiphy *wiphy, struct net_device *ndev, set_bit(BRCMF_VIF_STATUS_CONNECTING, &ifp->vif->sme_state); + /* Remember the join target. profile->bssid is only written by a + * successful link-up, so a failed join would otherwise be reported + * against the previous association (see brcmf_bss_connect_done). + */ + if (sme->bssid) + memcpy(profile->target_bssid, sme->bssid, ETH_ALEN); + else + eth_zero_addr(profile->target_bssid); + if (chan) { cfg->channel = ieee80211_frequency_to_channel(chan->center_freq); @@ -8071,14 +8081,20 @@ brcmf_bss_connect_done(struct brcmf_cfg80211_info *cfg, set_bit(BRCMF_VIF_STATUS_CONNECTED, &ifp->vif->sme_state); conn_params.status = WLAN_STATUS_SUCCESS; + conn_params.links[0].bssid = profile->bssid; } else { clear_bit(BRCMF_VIF_STATUS_EAP_SUCCESS, &ifp->vif->sme_state); clear_bit(BRCMF_VIF_STATUS_ASSOC_SUCCESS, &ifp->vif->sme_state); conn_params.status = WLAN_STATUS_AUTH_TIMEOUT; + /* Report the BSSID the join was issued for, not the one + * of the previous association that profile->bssid still + * holds after a suspend. An all-zero target (none given) + * makes wpa_supplicant fall back to its own pending BSSID. + */ + conn_params.links[0].bssid = profile->target_bssid; } - conn_params.links[0].bssid = profile->bssid; conn_params.req_ie = conn_info->req_ie; conn_params.req_ie_len = conn_info->req_ie_len; conn_params.resp_ie = conn_info->resp_ie; diff --git a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.h b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.h index d345df533..e98768ab7 100644 --- a/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.h +++ b/drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.h @@ -167,11 +167,13 @@ enum brcmf_profile_fwauth { * struct brcmf_cfg80211_profile - profile information. * * @bssid: bssid of joined/joining ibss. + * @target_bssid: BSSID the pending join was issued for (all-zero if none given). * @sec: security information. * @key: key information */ struct brcmf_cfg80211_profile { u8 bssid[ETH_ALEN]; + u8 target_bssid[ETH_ALEN]; struct brcmf_cfg80211_security sec; struct brcmf_wsec_key key[BRCMF_MAX_DEFAULT_KEYS]; enum brcmf_profile_fwsup use_fwsup; -- 2.39.5 (Apple Git-154)