[PATCH 1/1] wifi: mac80211: ignore PM bit in non-bufferable MMPDUs for PS start

From: Lee Jones

Date: Mon Sep 28 2026 - 06:05:26 EST


Per IEEE 802.11, the Power Management subfield in the Frame Control
field is reserved in non-bufferable management frames (such as
Authentication, Association Request, and Reassociation Request) and a
station remains in Active mode during authentication and association.

When commit 9fef65443388 ("mac80211: always update the PM state of a
peer on MGMT / DATA frames") allowed non-bufferable management frames
to update peer power-save state so that re-authenticating stations
could transition from doze to awake (sta_ps_end()), it also allowed
non-bufferable management frames with the Power Management bit set to
transition an awake station into power-save mode (sta_ps_start()).

Restrict wake-to-doze transitions (sta_ps_start()) in
ieee80211_rx_h_sta_process() to data, action, disassociation, and
deauthentication frames using hdr->frame_control (avoiding inspecting
encrypted action frame payloads prior to ieee80211_rx_h_decrypt()) while
preserving doze-to-wake transitions (sta_ps_end()).

Fixes: 9fef65443388 ("mac80211: always update the PM state of a peer on MGMT / DATA frames")
Signed-off-by: Lee Jones <lee@xxxxxxxxxx>
---
net/mac80211/rx.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/net/mac80211/rx.c b/net/mac80211/rx.c
index f5893f9c07c6..8e90d0d7b87f 100644
--- a/net/mac80211/rx.c
+++ b/net/mac80211/rx.c
@@ -1924,7 +1924,11 @@ ieee80211_rx_h_sta_process(struct ieee80211_rx_data *rx)
if (!ieee80211_has_pm(hdr->frame_control))
sta_ps_end(sta);
} else {
- if (ieee80211_has_pm(hdr->frame_control))
+ if (ieee80211_has_pm(hdr->frame_control) &&
+ (ieee80211_is_data(hdr->frame_control) ||
+ ieee80211_is_action(hdr->frame_control) ||
+ ieee80211_is_disassoc(hdr->frame_control) ||
+ ieee80211_is_deauth(hdr->frame_control)))
sta_ps_start(sta);
}
}
--
2.56.0.rc1.315.gc6ed9934b7-goog