Re: [PATCH rtw-next 1/2] wifi: rtw88: download the beacon the reserved page was built with

From: Luka Gejak

Date: Tue Sep 29 2026 - 15:15:35 EST


On Tue, 29 Sep 2026, Mehmet Fide wrote:

> Besides the extra work, every beacon fetch advances the DTIM count and,
> while a channel switch is announced, the CSA countdown; doing it twice
> per update lets a countdown that starts at 2 reach 0, which mac80211
> warns about. Keep the beacon skb from the page build and download that.
[...]
> @@ -1744,25 +1745,25 @@ static int rtw_download_beacon(struct rtw_dev *rtwdev)
> return -EINVAL;
> }
>
> - skb = rtw_get_rsvd_page_skb(hw, rsvd_pkt);
> + /* the beacon kept by rtw_build_rsvd_page() */
> + skb = rsvd_pkt->skb;
> if (!skb) {
> rtw_err(rtwdev, "failed to get beacon skb\n");
> - return -ENOMEM;
> + return -ENOENT;
> }
>
> ret = rtw_download_drv_rsvd_page(rtwdev, skb->data, skb->len);
> if (ret)
> rtw_err(rtwdev, "failed to download drv rsvd page\n");
>
> - dev_kfree_skb(skb);
> -
> return ret;
> }
>
[...]
> @@ -1791,6 +1792,12 @@ int rtw_fw_download_rsvd_page(struct rtw_dev *rtwdev)
> free:
> kfree(buf);
>
> + /* free the beacon kept by rtw_build_rsvd_page() */
> + rsvd_pkt = list_first_entry(&rtwdev->rsvd_page_list,
> + struct rtw_rsvd_page, build_list);
> + kfree_skb(rsvd_pkt->skb);
> + rsvd_pkt->skb = NULL;
> +
> return ret;
> }

This breaks hardware scan offload while an AP is active.

rtw_download_beacon() no longer fetches a beacon of its own. It reads
rsvd_pkt->skb, and rtw_fw_download_rsvd_page() clears that skb right
before it returns:

if (rtwdev->ap_active) {
ret = rtw_download_beacon(rtwdev);
if (ret)
rtw_err(rtwdev, "HW scan download beacon failed\n");
}

rtw_hw_scan_offload() takes that branch without building a reserved page
first, so nothing repopulates the skb. Since the store has already run from
BSS_CHANGED_BEACON when the AP started, rsvd_pkt->skb is NULL by the time a
scan begins and rtw_download_beacon() returns -ENOENT:

skb = rsvd_pkt->skb;
if (!skb) {
rtw_err(rtwdev, "failed to get beacon skb\n");
return -ENOENT;
}

rtw_ops_hw_scan() then treats the error as a failed scan and aborts it.

Before this patch the scan path worked because rtw_download_beacon() called
rtw_get_rsvd_page_skb() itself.

Could the scan path fetch its own beacon, or could the retained skb be
released only after the standalone download, with care taken to not
advance the CSA countdown twice?

Best regards,
Luka Gejak