[PATCH v2 5/5] wifi: iwlwifi: reduce encryption error message to debug level in FIPS mode

From: Jose Ignacio Tornos Martinez

Date: Wed Sep 30 2026 - 08:15:09 EST


In FIPS mode, the firmware may report
RX_MPDU_RES_STATUS_SEC_ENC_ERR (0x707) for frames received
before keys are installed. This triggers the warning:
"iwlwifi: Unhandled alg: 0x707"

This is expected behavior — mac80211 software crypto handles
decryption on the host CPU. Reduce the message from IWL_WARN to
IWL_DEBUG_RX in FIPS mode to avoid false-positive warnings
during normal operation, while preserving warnings for actual
unexpected conditions.

Signed-off-by: Jose Ignacio Tornos Martinez <jtornosm@xxxxxxxxxx>
---
v2: No modification
v1: https://lore.kernel.org/all/20260629121213.597038-3-jtornosm@xxxxxxxxxx/

drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c | 9 +++++++++
1 file changed, 9 insertions(+)

diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c b/drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c
index 7f0b4f5daa21..6d223ef75bb4 100644
--- a/drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c
+++ b/drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c
@@ -6,6 +6,7 @@
*/
#include <linux/etherdevice.h>
#include <linux/skbuff.h>
+#include <linux/fips.h>
#include "iwl-trans.h"
#include "mvm.h"
#include "fw-api.h"
@@ -494,6 +495,14 @@ static int iwl_mvm_rx_crypto(struct iwl_mvm *mvm, struct ieee80211_sta *sta,
return 0;
case RX_MPDU_RES_STATUS_SEC_CMAC_GMAC_ENC:
break;
+ case RX_MPDU_RES_STATUS_SEC_ENC_ERR:
+ if (fips_enabled) {
+ IWL_DEBUG_RX(mvm,
+ "FIPS mode: firmware cannot decrypt, status: 0x%x\n",
+ status);
+ break;
+ }
+ fallthrough;
default:
/*
* Sometimes we can get frames that were not decrypted
--
2.55.0