Re: [PATCH v3] wifi: ath9k_htc: bound TX aggregation to MAX_TX_BUF_SIZE
From: Toke Høiland-Jørgensen
Date: Fri Sep 11 2026 - 06:45:02 EST
Georgios Karantzas <gck.kara@xxxxxxxxx> writes:
> __hif_usb_tx() dequeues up to MAX_TX_AGGR_NUM (20) frames into a
> single tx_buf of MAX_TX_BUF_SIZE (32768) bytes, limiting the batch
> by record count but never by cumulative byte length.
>
> With large frames (MTU 2304), 20 aggregated frames of 2292 bytes
> each exceed the allocation (20 * 2296 = 45920 bytes), so the
> memcpy() in the loop writes up to 13152 bytes past tx_buf->buf
> before usb_submit_urb().
>
> Peek the queue head and stop before copying any record that would
> cross MAX_TX_BUF_SIZE, then dispatch the current batch. Leftover
> skbs remain queued and are drained on the next URB completion.
>
> The byte bound changes the loop's exit semantics: it can now exit
> before i == tx_skb_cnt - 1. Stock only finalized tx_buf->len on
> that last index (len += offset), so an early break would submit a
> URB holding only the last record's length while every dequeued skb
> is freed on completion, silently dropping frames. Make tx_buf->len
> a running total and advance tx_buf->offset per record instead; the
> stride round_up(nskb->len + 4, 4) is identical to the stock stride
> when the loop runs to completion.
>
> Tested on hardware with an MTU 2304 flood: the loop stops at
> record 15 (len = 32144, offset = 32144, within 32768), no
> oversized URB is submitted, and MTU 1500 pings pass 20/20.
>
> Fixes: fb9987d0f748c983 ("ath9k_htc: Support for AR9271 chipset.")
> Signed-off-by: Georgios Karantzas <gck.kara@xxxxxxxxx>
Looks good now, thanks!
Acked-by: Toke Høiland-Jørgensen <toke@xxxxxxx>