This contains many fixes from upstream Linux.
mac80211/371-wifi-mac80211-Add-eMLSR-eMLMR-action-frame-parsing-s.patch
adapted to upstream split of include/linux/ieee80211.h
Changes:
```
$ git log --oneline v6.18.26...v6.18.39 -- drivers/net/wireless/ net/mac80211/ net/wireless/ include/linux/ieee80211*
1de92789ce31 wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
b0b07e04f0c7 wifi: iwlwifi: mld: fix race condition in PTP removal
df626f284cb9 wifi: iwlwifi: mvm: fix race condition in PTP removal
200d58c851b8 wifi: rtw88: usb: fix memory leaks on USB write failures
73d427d271f7 wifi: rtw88: increase TX report timeout to fix race condition
0aeb4d3ff6ce wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor
40aa3c2b0cb8 wifi: ath11k: fix warning when unbinding
a7cdc384c9c5 wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer
7e25b5e22c1f wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S
3c499851753a wifi: mt76: add wcid publish check in mt76_sta_add
37c059d4d92f wifi: mac80211: tests: mark HT check strict
4dac39a4db14 wifi: mac80211: skip ieee80211_verify_sta_ht_mcs_support check in non-strict mode
265c07c09c83 wifi: nl80211: reject oversized EMA RNR lists
ac2000be0cbe wifi: iwlwifi: pcie: simplify the resume flow if fast resume is not used
fb8db813eba2 wifi: fix leak if split 6 GHz scanning fails
9b40c59bab08 wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap
9dca67624721 wifi: iwlwifi: mvm: don't support the reset handshake for old firmwares
95c82d498d74 wifi: wilc1000: fix dma_buffer leak on bus acquire failure
55c479aae99b wifi: mac80211: fix MLE defragmentation
2d8379834800 wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs
926a08cf19be wifi: ath11k: fix peer resolution on rx path when peer_id=0
3a74aaad0473 wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it
9e360e610a73 wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled
e1b429d8e712 wifi: ath10k: skip WMI and beacon transmission when device is wedged
d94127d04017 wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm()
acde4692afcd wifi: ath11k: fix error path leaks in some WMI WOW calls
2dd9304727c7 wifi: mac80211: consume only present negotiated TTLM maps
6cfae4914439 wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
dc31c6947652 wifi: iwlwifi: mld: stop TX during firmware restart
6fe92651b44f wifi: iwlwifi: mvm: fix driver-set TX rates on old devices
614cacec60fe wifi: ath11k: clear shared SRNG pointer state on restart
254633506626 wifi: ath10k: fix station lookup failure during disconnect
a9937a3ac585 wifi: mac80211: handle VHT EXT NSS in ieee80211_determine_our_sta_mode()
cbea71b44803 wifi: brcmfmac: Fix error pointer dereference
6b9694702c37 wifi: rtw89: phy: fix uninitialized variable access in rtw89_phy_cfo_set_crystal_cap()
a1a8a8bdfa21 wifi: mt76: mt7996: fix RRO EMU configuration
dc34c01521bf wifi: mt76: support upgrading passive scans to active
a2cde15af378 wifi: mt76: fix multi-radio on-channel scanning
98e0118ab51c wifi: mt76: mt7996: Decrement sta counter removing the link in mt7996_mac_reset_sta_iter()
e54c6440114d wifi: mt76: mt7996: Switch to the secondary link if the default one is removed
d6f6b3a65660 wifi: mt76: mt7996: use correct link_id when filling TXD and TXP
5a3353b06387 wifi: mt76: mt7996: Remove link pointer dependency in mt7996_mac_sta_remove_links()
7da35e2d2fb7 wifi: mt76: mt7996: Add missing CHANCTX_STA_CSA property
1e0f3e5e2835 wifi: mt76: mt7921: fix 6GHz regulatory update on connection
aa4a31cd89f4 wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work()
6b7cbb13c838 wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()
419babee9b5c wifi: mt76: mt7996: fix struct mt7996_mcu_uni_event
ae94ef093a15 wifi: mt76: mt7996: fix wrong DMAD length when using MAC TXP
5fc8c5d45e44 wifi: mt76: fix deadlock in remain-on-channel
35180c772f5e wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_sync
153bcba36c87 wifi: mt76: mt7925: fix potential deadlock in mt7925_roc_abort_sync
e125def8b380 wifi: mt76: mt7925: drop puncturing handling from BSS change path
a1a59bd3cd1e wifi: mt76: mt7925: cqm rssi low/high event notify
dcbc13d19bef wifi: mt76: Fix memory leak destroying device
35835ff71e6e wifi: mt76: mt7921: Place upper limit on station AID
e00c27608536 wifi: mt76: mt7996: fix FCS error flag check in RX descriptor
815db7fd57aa wifi: mt76: mt7925: prevent NULL vif dereference in mt7925_mac_write_txwi
93d0694fb56d wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_tx_check_aggr()
b81a93dc0aed wifi: mt76: mt7915: fix use_cts_prot support
729b4adad191 wifi: mt76: mt7615: fix use_cts_prot support
9aa3b49e1c5b wifi: mt76: mt7925: Fix incorrect MLO mode in firmware control
3880639cec09 wifi: mt76: mt7921: Reset ampdu_state state in case of failure in mt76_connac2_tx_check_aggr()
1e16b0a9b988 wifi: mt76: mt7996: Reset ampdu_state state in case of failure in mt7996_tx_check_aggr()
455a48685fee wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link()
6d7f231d5fff wifi: mt76: mt7996: Reset mtxq->idx if primary link is removed in mt7996_vif_link_remove()
15205c72f1ec wifi: mt76: mt7996: Set mtxq->wcid just for primary link
900579479395 wifi: mt76: mt7996: fix iface combination for different chipsets
096b74331df2 wifi: mt76: mt7996: fix the behavior of radar detection
00c0317cebf4 wifi: libertas: don't kill URBs in interrupt context
a761a1539a55 wifi: libertas: use USB anchors for tracking in-flight URBs
0ee803fc4787 wifi: ieee80211: fix definition of EHT-MCS 15 in MRU
dd827cff429d wifi: ieee80211: split EHT definitions out
df5720d35848 wifi: ieee80211: split HE definitions out
f8d1e8038bc7 wifi: ieee80211: split VHT definitions out
4d5caab09dab wifi: ieee80211: split HT definitions out
3f459076b2d8 wifi: ieee80211: split mesh definitions out
aa10a452e348 wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet
9fe48cacab63 wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt()
658d2e46c2e9 wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task
d7029879bafd wifi: b43: enforce bounds check on firmware key index in b43_rx()
9e28654f79f4 wifi: mac80211: remove station if connection prep fails
e9f1081bc775 wifi: ath5k: do not access array OOB
7577a4b8a10f wifi: mac80211: use safe list iteration in radar detect work
4f9a4ae8d2c1 wifi: rsi: fix kthread lifetime race between self-exit and external-stop
e131562d6f2b wifi: mac80211: drop stray 'static' from fast-RX rx_result
9d1bc1558029 wifi: b43legacy: enforce bounds check on firmware key index in RX path
6d55948a62ab wifi: mt76: mt7921: fix ROC abort flow interruption in mt7921_roc_work
0aa63d33742b wifi: mt76: mt7921: fix a potential clc buffer length underflow
6fc7c8b414ce wifi: mt76: mt7925: fix incorrect length field in txpower command
5860ab3ddeaa wifi: mt76: mt7925: fix AMPDU state handling in mt7925_tx_check_aggr
8c4339dbab49 wifi: mt76: mt7925: fix incorrect TLV length in CLC command
7d7863018f40 wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling
0bc155c4ca47 wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor
69c4d137b22d wifi: rtl8xxxu: fix potential use of uninitialized value
4e179a60a60c wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup()
000134a20bbf wifi: rtw88: check for PCI upstream bridge existence
```
Link: https://github.com/openwrt/openwrt/pull/24353
Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
PKG_NAME:=mac80211
-PKG_VERSION:=6.18.26
+PKG_VERSION:=6.18.39
PKG_RELEASE:=1
PKG_LICENSE:=GPL-2.0-only
PKG_LICENSE_FILES:=COPYING
PKG_SOURCE_URL:=https://github.com/openwrt/backports/releases/download/backports-v$(PKG_VERSION)
-PKG_HASH:=2ad578c6cae22f192fefd44e1449725228d4109ee781998b41dcbae872554968
+PKG_HASH:=8951c1e270d7c311432377bd50951cd1d5dee2b5fedf33d30db41aa8e428aeb0
PKG_SOURCE:=backports-$(PKG_VERSION).tar.zst
PKG_BUILD_DIR:=$(KERNEL_BUILD_DIR)/$(if $(BUILD_VARIANT),$(PKG_NAME)-$(BUILD_VARIANT)/)backports-$(PKG_VERSION)
--- a/drivers/net/wireless/ath/ath11k/dp_rx.c
+++ b/drivers/net/wireless/ath/ath11k/dp_rx.c
-@@ -4930,8 +4930,13 @@ ath11k_dp_rx_mon_merg_msdus(struct ath11
+@@ -4929,8 +4929,13 @@ ath11k_dp_rx_mon_merg_msdus(struct ath11
}
prev_buf->next = NULL;
} else if (decap_format == DP_RX_DECAP_TYPE_NATIVE_WIFI) {
u8 qos_pkt = 0;
-@@ -4957,10 +4962,13 @@ ath11k_dp_rx_mon_merg_msdus(struct ath11
+@@ -4956,10 +4961,13 @@ ath11k_dp_rx_mon_merg_msdus(struct ath11
prev_buf = msdu;
msdu = msdu->next;
}
ath11k_dbg(ab, ATH11K_DBG_DATA,
"mpdu_buf %p mpdu_buf->len %u",
prev_buf, prev_buf->len);
-@@ -5085,12 +5093,27 @@ static int ath11k_dp_rx_mon_deliver(stru
+@@ -5084,12 +5092,27 @@ static int ath11k_dp_rx_mon_deliver(stru
header = mon_skb;
--- a/drivers/net/wireless/ath/ath12k/core.c
+++ b/drivers/net/wireless/ath/ath12k/core.c
-@@ -812,6 +812,28 @@ int ath12k_core_check_smbios(struct ath12k_base *ab)
+@@ -806,6 +806,28 @@ int ath12k_core_check_smbios(struct ath1
return 0;
}
int ret;
--- a/drivers/net/wireless/ath/ath12k/qmi.c
+++ b/drivers/net/wireless/ath/ath12k/qmi.c
-@@ -2945,6 +2945,10 @@ int ath12k_qmi_request_target_cap(struct ath12k_base *ab)
+@@ -2903,6 +2903,10 @@ int ath12k_qmi_request_target_cap(struct
if (r)
ath12k_dbg(ab, ATH12K_DBG_QMI, "SMBIOS bdf variant name not set.\n");
goto end;
--- a/drivers/net/wireless/ath/ath5k/base.c
+++ b/drivers/net/wireless/ath/ath5k/base.c
-@@ -2009,7 +2009,7 @@ ath5k_beacon_send(struct ath5k_hw *ah)
+@@ -2010,7 +2010,7 @@ ath5k_beacon_send(struct ath5k_hw *ah)
}
if ((ah->opmode == NL80211_IFTYPE_AP && ah->num_ap_vifs +
ah->opmode == NL80211_IFTYPE_MESH_POINT) {
u64 tsf = ath5k_hw_get_tsf64(ah);
u32 tsftu = TSF_TO_TU(tsf);
-@@ -2095,7 +2095,7 @@ ath5k_beacon_update_timers(struct ath5k_
+@@ -2096,7 +2096,7 @@ ath5k_beacon_update_timers(struct ath5k_
intval = ah->bintval & AR5K_BEACON_PERIOD;
if (ah->opmode == NL80211_IFTYPE_AP && ah->num_ap_vifs
intval /= ATH_BCBUF; /* staggered multi-bss beacons */
if (intval < 15)
ATH5K_WARN(ah, "intval %u is too low, min 15\n",
-@@ -2561,6 +2561,7 @@ static const struct ieee80211_iface_limi
+@@ -2562,6 +2562,7 @@ static const struct ieee80211_iface_limi
BIT(NL80211_IFTYPE_MESH_POINT) |
#endif
BIT(NL80211_IFTYPE_AP) },
return intstatus;
}
-@@ -2581,6 +2596,182 @@ static int brcmf_sdio_intr_rstatus(struc
+@@ -2582,6 +2597,182 @@ static int brcmf_sdio_intr_rstatus(struc
return ret;
}
static void brcmf_sdio_dpc(struct brcmf_sdio *bus)
{
struct brcmf_sdio_dev *sdiod = bus->sdiodev;
-@@ -2652,8 +2843,11 @@ static void brcmf_sdio_dpc(struct brcmf_
+@@ -2653,8 +2844,11 @@ static void brcmf_sdio_dpc(struct brcmf_
/* Handle host mailbox indication */
if (intstatus & I_HMB_HOST_INT) {
}
sdio_release_host(bus->sdiodev->func1);
-@@ -2698,7 +2892,7 @@ static void brcmf_sdio_dpc(struct brcmf_
+@@ -2699,7 +2893,7 @@ static void brcmf_sdio_dpc(struct brcmf_
brcmf_sdio_clrintr(bus);
if (bus->ctrl_frame_stat && (bus->clkstate == CLK_AVAIL) &&
sdio_claim_host(bus->sdiodev->func1);
if (bus->ctrl_frame_stat) {
err = brcmf_sdio_tx_ctrlframe(bus, bus->ctrl_frame_buf,
-@@ -3569,6 +3763,10 @@ static int brcmf_sdio_bus_preinit(struct
+@@ -3570,6 +3764,10 @@ static int brcmf_sdio_bus_preinit(struct
if (err < 0)
goto done;
bus->tx_hdrlen = SDPCM_HWHDR_LEN + SDPCM_SWHDR_LEN;
if (sdiodev->sg_support) {
bus->txglom = false;
-@@ -4219,7 +4417,7 @@ static void brcmf_sdio_firmware_callback
+@@ -4220,7 +4418,7 @@ static void brcmf_sdio_firmware_callback
u8 saveclk, bpreq;
u8 devctl;
if (err)
goto fail;
-@@ -4397,12 +4595,25 @@ static void brcmf_sdio_firmware_callback
+@@ -4398,12 +4596,25 @@ static void brcmf_sdio_firmware_callback
}
/* Attach to the common layer, reserve hdr space */
/* ready */
return;
-@@ -4650,3 +4861,40 @@ int brcmf_sdio_sleep(struct brcmf_sdio *
+@@ -4652,3 +4863,40 @@ int brcmf_sdio_sleep(struct brcmf_sdio *
return ret;
}
--- a/drivers/net/wireless/realtek/rtw88/usb.c
+++ b/drivers/net/wireless/realtek/rtw88/usb.c
-@@ -965,7 +965,11 @@ static int rtw_usb_init_rx(struct rtw_de
+@@ -974,7 +974,11 @@ static int rtw_usb_init_rx(struct rtw_de
struct sk_buff *rx_skb;
int i;
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
-@@ -4088,7 +4088,7 @@ struct ieee80211_txq *ieee80211_next_txq
+@@ -4090,7 +4090,7 @@ struct ieee80211_txq *ieee80211_next_txq
if (deficit < 0)
sta->airtime[txqi->txq.ac].deficit +=
if (deficit < 0 || !aql_check) {
list_move_tail(&txqi->schedule_order,
-@@ -4233,7 +4233,8 @@ bool ieee80211_txq_may_transmit(struct i
+@@ -4235,7 +4235,8 @@ bool ieee80211_txq_may_transmit(struct i
}
sta = container_of(iter->txq.sta, struct sta_info, sta);
if (ieee80211_sta_deficit(sta, ac) < 0)
list_move_tail(&iter->schedule_order, &local->active_txqs[ac]);
}
-@@ -4241,7 +4242,7 @@ bool ieee80211_txq_may_transmit(struct i
+@@ -4243,7 +4244,7 @@ bool ieee80211_txq_may_transmit(struct i
if (sta->airtime[ac].deficit >= 0)
goto out;
c->dfs_state_entered = jiffies;
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
-@@ -20967,6 +20967,9 @@ void cfg80211_ch_switch_notify(struct ne
+@@ -20970,6 +20970,9 @@ void cfg80211_ch_switch_notify(struct ne
break;
case NL80211_IFTYPE_AP:
case NL80211_IFTYPE_P2P_GO:
void cfg80211_update_last_available(struct wiphy *wiphy,
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
-@@ -6741,6 +6741,8 @@ static int nl80211_start_ap(struct sk_bu
+@@ -6744,6 +6744,8 @@ static int nl80211_start_ap(struct sk_bu
goto out;
}
atomic_add(tx_airtime,
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
-@@ -2558,7 +2558,7 @@ static u16 ieee80211_store_ack_skb(struc
+@@ -2560,7 +2560,7 @@ static u16 ieee80211_store_ack_skb(struc
spin_lock_irqsave(&local->ack_status_lock, flags);
id = idr_alloc(&local->ack_status_frames, ack_skb,
spin_unlock_irqrestore(&local->ack_status_lock, flags);
if (id >= 0) {
-@@ -3989,20 +3989,20 @@ begin:
+@@ -3991,20 +3991,20 @@ begin:
encap_out:
info->control.vif = vif;
}
return skb;
-@@ -4054,6 +4054,7 @@ struct ieee80211_txq *ieee80211_next_txq
+@@ -4056,6 +4056,7 @@ struct ieee80211_txq *ieee80211_next_txq
struct ieee80211_txq *ret = NULL;
struct txq_info *txqi = NULL, *head = NULL;
bool found_eligible_txq = false;
spin_lock_bh(&local->active_txq_lock[ac]);
-@@ -4077,26 +4078,26 @@ struct ieee80211_txq *ieee80211_next_txq
+@@ -4079,26 +4080,26 @@ struct ieee80211_txq *ieee80211_next_txq
if (!head)
head = txqi;
if (txqi->schedule_round == local->schedule_round[ac])
goto out;
-@@ -4163,7 +4164,8 @@ bool ieee80211_txq_airtime_check(struct
+@@ -4165,7 +4166,8 @@ bool ieee80211_txq_airtime_check(struct
return true;
if (!txq->sta)
if (unlikely(txq->tid == IEEE80211_NUM_TIDS))
return true;
-@@ -4212,15 +4214,15 @@ bool ieee80211_txq_may_transmit(struct i
+@@ -4214,15 +4216,15 @@ bool ieee80211_txq_may_transmit(struct i
spin_lock_bh(&local->active_txq_lock[ac]);
* @vif: virtual interface to iterate, may be %NULL for all
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
-@@ -4185,6 +4185,24 @@ bool ieee80211_txq_airtime_check(struct
+@@ -4187,6 +4187,24 @@ bool ieee80211_txq_airtime_check(struct
}
EXPORT_SYMBOL(ieee80211_txq_airtime_check);
+From 0d95280a2d54ebd3d38adc4ff67808009798978c Mon Sep 17 00:00:00 2001
From: Lorenzo Bianconi <lorenzo@kernel.org>
Date: Thu, 29 Jan 2026 14:15:46 +0100
-Subject: [PATCH] wifi: mac80211: Add eMLSR/eMLMR action frame parsing support
+Subject: wifi: mac80211: Add eMLSR/eMLMR action frame parsing support
Introduce support in AP mode for parsing of the Operating Mode Notification
frame sent by the client to enable/disable MLO eMLSR or eMLMR if supported
Link: https://patch.msgid.link/20260129-mac80211-emlsr-v4-1-14bdadf57380@kernel.org
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
---
+ include/linux/ieee80211-eht.h | 11 +++
+ include/linux/ieee80211.h | 6 ++
+ include/net/mac80211.h | 32 +++++++
+ net/mac80211/driver-ops.h | 21 ++++
+ net/mac80211/eht.c | 175 ++++++++++++++++++++++++++++++++++
+ net/mac80211/ieee80211_i.h | 2 +
+ net/mac80211/iface.c | 10 +-
+ net/mac80211/rx.c | 8 ++
+ net/mac80211/trace.h | 32 +++++++
+ 9 files changed, 296 insertions(+), 1 deletion(-)
---- a/include/linux/ieee80211.h
-+++ b/include/linux/ieee80211.h
-@@ -1612,6 +1612,12 @@ struct ieee80211_mgmt {
- u8 action_code;
- u8 variable[];
- } __packed epcs;
-+ struct {
-+ u8 action_code;
-+ u8 dialog_token;
-+ u8 control;
-+ u8 variable[];
-+ } __packed eml_omn;
- } u;
- } __packed action;
- DECLARE_FLEX_ARRAY(u8, body); /* Generic frame body */
-@@ -5462,6 +5468,17 @@ struct ieee80211_mle_tdls_common_info {
+--- a/include/linux/ieee80211-eht.h
++++ b/include/linux/ieee80211-eht.h
+@@ -558,6 +558,17 @@ struct ieee80211_mle_tdls_common_info {
- /* no fixed fields in PRIO_ACCESS */
+ #define IEEE80211_MLC_PRIO_ACCESS_PRES_AP_MLD_MAC_ADDR 0x0010
+#define IEEE80211_EML_CTRL_EMLSR_MODE BIT(0)
+#define IEEE80211_EML_CTRL_EMLMR_MODE BIT(1)
+#define IEEE80211_EML_EMLMR_RX_MCS_MAP 0xf0
+#define IEEE80211_EML_EMLMR_TX_MCS_MAP 0x0f
+
+ /* no fixed fields in PRIO_ACCESS */
+
/**
- * ieee80211_mle_common_size - check multi-link element common size
- * @data: multi-link element, must already be checked for size using
+--- a/include/linux/ieee80211.h
++++ b/include/linux/ieee80211.h
+@@ -1367,6 +1367,12 @@ struct ieee80211_mgmt {
+ u8 action_code;
+ u8 variable[];
+ } __packed epcs;
++ struct {
++ u8 action_code;
++ u8 dialog_token;
++ u8 control;
++ u8 variable[];
++ } __packed eml_omn;
+ } u;
+ } __packed action;
+ DECLARE_FLEX_ARRAY(u8, body); /* Generic frame body */
--- a/include/net/mac80211.h
+++ b/include/net/mac80211.h
@@ -1901,6 +1901,31 @@ enum ieee80211_offload_flags {
#endif /* !__MAC80211_DRIVER_TRACE || TRACE_HEADER_MULTI_READ */
#undef TRACE_INCLUDE_PATH
---- /dev/null
-+++ b/include/linux/ieee80211-eht.h
-@@ -0,0 +1 @@
-+#include <linux/ieee80211.h>