[PATCH v3 3/4] wifi: iwlwifi: fix RX AMPDU and A-MSDU in FIPS mode
From: Jose Ignacio Tornos Martinez
Date: Fri Oct 09 2026 - 02:54:59 EST
In FIPS mode with the WiFi MFP exception active, firmware has no
encryption keys installed (mac80211 handles all crypto in software).
This causes two RX-path issues that severely limit downlink
throughput:
1) Firmware reports SEC_UNKNOWN for all received data frames because
it has no keys to decrypt them. iwl_mvm_rx_crypto() drops these
frames when they arrive inside an AMPDU, mistaking them for a
security error. In FIPS SW-crypto mode this is expected -- the
frames are encrypted and will be decrypted by mac80211. Skip
the drop when the FIPS exception is active, same as already done
for monitor mode.
2) Firmware clears the A-MSDU present bit in the QoS header for
frames it processes. When firmware has no keys, it still strips
this bit even though it cannot de-aggregate the A-MSDU. mac80211
then treats the A-MSDU as a regular MSDU, delivering a malformed
frame. Preserve the A-MSDU bit when the FIPS exception is active
so mac80211 can properly de-aggregate after SW decryption.
Without these fixes (in my scenario), RX throughput is limited to
non-aggregated rates (~25 Mbps). With both fixes, RX AMPDU works
normally and throughput reaches ~450 Mbps.
Signed-off-by: Jose Ignacio Tornos Martinez <jtornosm@xxxxxxxxxx>
---
v3: new
v2: https://lore.kernel.org/all/20260930120829.383408-1-jtornosm@xxxxxxxxxx/
drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c b/drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c
index 7f0b4f5daa21..1ebca0323a89 100644
--- a/drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c
+++ b/drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c
@@ -5,6 +5,7 @@
* Copyright (C) 2015-2017 Intel Deutschland GmbH
*/
#include <linux/etherdevice.h>
+#include <linux/fips.h>
#include <linux/skbuff.h>
#include "iwl-trans.h"
#include "mvm.h"
@@ -421,14 +422,15 @@ static int iwl_mvm_rx_crypto(struct iwl_mvm *mvm, struct ieee80211_sta *sta,
/*
* Drop UNKNOWN frames in aggregation, unless in monitor mode
- * (where we don't have the keys).
+ * (where we don't have the keys) or FIPS SW-crypto mode.
* We limit this to aggregation because in TKIP this is a valid
* scenario, since we may not have the (correct) TTAK (phase 1
* key) in the firmware.
*/
if (phy_info & IWL_RX_MPDU_PHY_AMPDU &&
(status & IWL_RX_MPDU_STATUS_SEC_MASK) ==
- IWL_RX_MPDU_STATUS_SEC_UNKNOWN && !mvm->monitor_on) {
+ IWL_RX_MPDU_STATUS_SEC_UNKNOWN && !mvm->monitor_on &&
+ !fips_allows_exception(FIPS_EXCEPTION_WIFI_MFP)) {
IWL_DEBUG_DROP(mvm, "Dropping packets, bad enc status\n");
return -1;
}
@@ -2357,7 +2359,8 @@ void iwl_mvm_rx_mpdu_mq(struct iwl_mvm *mvm, struct napi_struct *napi,
!WARN_ON(!ieee80211_is_data_qos(hdr->frame_control))) {
u8 *qc = ieee80211_get_qos_ctl(hdr);
- *qc &= ~IEEE80211_QOS_CTL_A_MSDU_PRESENT;
+ if (!fips_allows_exception(FIPS_EXCEPTION_WIFI_MFP))
+ *qc &= ~IEEE80211_QOS_CTL_A_MSDU_PRESENT;
if (mvm->trans->mac_cfg->device_family ==
IWL_DEVICE_FAMILY_9000) {
--
2.55.0