[PATCH] wifi: rtw88: sdio: copy RX status after updating the frequency
From: Hungyu Lin
Date: Thu Oct 08 2026 - 21:53:05 EST
rtw_sdio_rx_skb() copies rx_status to the skb before calling
rtw_update_rx_freq_for_invalid(). If the frequency is corrected, the skb
still carries the old value when it is passed to mac80211.
Move the copy after the frequency update, as the PCI and USB RX paths
already do.
Fixes: 53ed4b25a79a ("wifi: rtw88: 8822c: Parse channel from IE to correct invalid hardware reports")
Signed-off-by: Hungyu Lin <dennylin0707@xxxxxxxxx>
---
Built the rtw88 directory on arm64 with GCC 13.3.0 and W=1, with
RTW88_8723BS, RTW88_SDIO, RTW88_PCI and RTW88_USB enabled.
A userspace test of the old and new receive function, with helper calls
stubbed, confirmed that the corrected frequency reaches skb->cb.
No hardware testing.
drivers/net/wireless/realtek/rtw88/sdio.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/net/wireless/realtek/rtw88/sdio.c b/drivers/net/wireless/realtek/rtw88/sdio.c
index dc2fd0f8f9ff..7c22f0ba5329 100644
--- a/drivers/net/wireless/realtek/rtw88/sdio.c
+++ b/drivers/net/wireless/realtek/rtw88/sdio.c
@@ -1332,8 +1332,6 @@ static void rtw_sdio_rx_skb(struct rtw_dev *rtwdev, struct sk_buff *skb,
u32 pkt_offset, struct rtw_rx_pkt_stat *pkt_stat,
struct ieee80211_rx_status *rx_status)
{
- *IEEE80211_SKB_RXCB(skb) = *rx_status;
-
if (pkt_stat->is_c2h) {
skb_put(skb, pkt_stat->pkt_len + pkt_offset);
rtw_fw_c2h_cmd_rx_irqsafe(rtwdev, pkt_offset, skb);
@@ -1346,6 +1344,7 @@ static void rtw_sdio_rx_skb(struct rtw_dev *rtwdev, struct sk_buff *skb,
rtw_update_rx_freq_for_invalid(rtwdev, skb, rx_status, pkt_stat);
rtw_rx_stats(rtwdev, pkt_stat->vif, skb);
+ *IEEE80211_SKB_RXCB(skb) = *rx_status;
ieee80211_rx_irqsafe(rtwdev->hw, skb);
}
base-commit: 83de3a16c7b37064a59305040ba9b0f93b832794
--
2.43.0