Skip to content

ieee80211: enforce complete TXOP exchange duration - #1273

Open
mgonzalezlopezudc wants to merge 9 commits into
inet-framework:masterfrom
mgonzalezlopezudc:feat/ieee80211-txop-duration
Open

mgonzalezlopezudc wants to merge 9 commits into
inet-framework:masterfrom
mgonzalezlopezudc:feat/ieee80211-txop-duration

Conversation

@mgonzalezlopezudc

@mgonzalezlopezudc mgonzalezlopezudc commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

A data frame can fit a transmission opportunity (TXOP) while its required acknowledgment (ACK) exceeds the TXOP limit.
The hybrid coordination function (HCF) now checks complete exchanges when isBlockAckSupported=false.
The check includes protection, response airtime, and each required short interframe space (SIFS).
HCF transmits the same frames, physical layer (PHY) modes, ACK policy, and protection choices that passed the check.

The exchange regression checks a 350 µs limit and requires bursts of two frames and one frame.
HCF retains a refused continuation for later channel access.
The medium access control (MAC) module resets active requests and exchange state on stop and crash.
HCF restores Block Ack inactivity deadlines after restart and rejects Block Ack data without an active agreement.
External implementations of the changed MAC contracts require source changes and a rebuild.

This PR depends on radio command PR #1280.
The first commit provides the radio deferral that the TXOP changes require.

Commit order

Read these eight TXOP commits after the radio prerequisite:

Commit Purpose
52900c674a Record the implementation plan, scope, and contracts.
54820a11b5 Remove extra final blank lines.
0878804865 Identify Tx requests and protect sequence state across callbacks.
ecd8743e3a Reset lifecycle state, restore deadlines, and retire Block Ack agreements safely.
3b489d5472 Retain frames and expose read-only ACK state.
4ad589e1b3 Prepare frame sequences with fixed choices.
0522440474 Add complete duration admission, transmitted reservation checks, and Duration/ID calculation.
c8ea3b7b15 Enable prepared HCF execution and update its fingerprint baselines.

Sequence preparation and duration admission precede production activation.
Request identity, lifecycle reset, and frame retention also change behavior before activation.

Scope and interfaces

Preparation predicts exchange completion without changes to real ACK state, retries, sequence numbers, or queue order.
Admission includes the SIFS before each continuation.
Actual transmission history determines zero-limit allowances and supported overrun exceptions.
A separate check enforces the reservation from this station's transmitted Duration/ID values.
HCF rechecks state and complete exchange cost before transmission; frame removal or a mode set change invalidates the prepared exchange.

Tx request identities contain a lifecycle epoch and a serial.
Interframe space (IFS) is a required interval between specified frame transmissions.
Tx rechecks the identity after callbacks, even on the zero-IFS path.
Cancellation removes only the delayed transmission with that identity.
Callback guards and frame retention keep borrowed objects valid until callbacks return.

Coordination functions release exchange contexts before child frame stores die.
Lifecycle reset preserves the distinction between Normal Ack, No Ack, group transmissions, and Block Ack.

Downtime counts toward finite Block Ack deadlines; timeout zero disables inactivity expiry.
Restart retires overdue agreements in both roles before queued management traffic requests channel access.
Recipient retirement clears only the retired peer and traffic identifier (TID)'s reorder buffer before the deletion notification.
Each actual retirement emits one deletion notification; duplicate DELBA frames emit none.
DELBA is the Action frame that ends a Block Ack agreement.
Completion of timeout or UNKNOWN_BA DELBA preserves a replacement agreement for the same peer and TID.

The changed contracts cover Tx, sequence handlers, prepared records, ACK snapshots, timeout policies, frame stores, agreement handlers, and recipient data services.
Agreement handlers supply absolute deadlines and return timeout DELBA frames to HCF after retirement.
Deletion callbacks borrow an agreement only until the callback returns.

qosFrameReceived() adds an IProcedureCallback * argument and returns false for Block Ack data when the agreement is absent or overdue.
For overdue state, the handler requests expiry before it returns false.
For absent state, it queues UNKNOWN_BA DELBA through the procedure callback, which takes ownership of the management frame.
HCF discards the data frame on a false result.
The migration guide lists the required contract changes.

The duration guarantee assumes zero propagation delay, nominal SIFS, and response modes and complete frame lengths that match the predictions.
An oversized initial exchange without a supported exception raises a model-limit error before transmission.
Automatic fragmentation to an airtime budget remains unsupported.
An aggregate MAC protocol data unit (A-MPDU) combines multiple frames in one physical transmission.
The prepared path supports no A-MPDU exchange.

The distributed coordination function (DCF) and HCF with Block Ack support use their current paths without the new duration guarantee.
TXOP duration statistics report actual elapsed time.
Duration/ID content changes; frame formats, module definitions, and configuration parameters remain unchanged.

The duration checks use IEEE Std 802.11-2024, clauses 10.23.2.8, 10.23.2.9, and 9.2.5.2.
Agreement inactivity behavior uses clause 11.5.4.

Validation

At c8ea3b7b15, debug and release builds pass.
Five unit targets, eight module targets, and five Wi-Fi protocol targets pass in debug mode.
The tests cover prepared admission, fixed choices, frame retention, cancellation, retry modes, teardown, and Block Ack lifecycle behavior.
The protocol targets cover legacy data/ACK, RTS/CTS, fragmentation, TXOP bursts, and Block Ack.
The module targets also check inactivity expiry, buffer isolation, replacement agreements, and delayed DELBA completion.

The checks run from the repository root:

source ./setenv -q
make MODE=debug -j6
make MODE=release -j6
inet_run_unit_tests -m debug --no-concurrent -f '(FrameSequence_1|Ieee80211TxopProcedure_1|Ieee80211TxopDuration_1|Ieee80211PreparedOriginatorPolicy_1|Ieee80211BlockAckInactivity_1)\.test$'
inet_run_module_tests -m debug --no-concurrent -f 'Ieee80211(ExchangeTeardown|TxopExchange|PreparedCancellation|RetryMode|LifecycleGroup|BlockAckRetirement|BlockAckRestart|BlockAckLifecycle)_1\.test$'
inet_run_protocol_tests -m debug --no-concurrent -w '^tests/protocol/wifi$' -f '/(Legacy_DataAck|Legacy_RtsCts|Legacy_Fragmentation|N_TxopBurst|N_BlockAck)\.test$'
doc/project/enforcement/check-commits.sh 03e927c18a..c8ea3b7b15
doc/project/enforcement/check-classification.sh 03e927c18a..c8ea3b7b15
doc/project/enforcement/check-source-seals.sh --base origin/master
doc/project/enforcement/check-architecture.sh
doc/project/enforcement/check-naming.sh --base origin/master
doc/project/enforcement/check-interfaces.sh
git diff --check

Commit, classification, source seal, and whitespace checks pass.
Global architecture, naming, and interface checks report the same findings as the PR base, 03e927c18a.
The comparison finds 25 architecture candidates, 23 naming candidates, and 15 interface violations on both trees.
CI validation for this head has no recorded result at this update.

Baseline changes and limits

The radio commit updates 30 rows: thirteen examples, thirteen showcases, and four tutorials.
Those rows change only tplx because radio commands wait until accepted responses complete, which changes event order.
The HCF activation commit updates eleven rows: seven examples and four showcases.
All three fingerprints change because prepared admission controls frame choices, transmission time, and Duration/ID content.
Four rows receive both changes, so the PR changes 37 distinct rows against 03e927c18a.
Each source commit contains the baseline rows that it causes.

Per-commit runtime verification of the complete series, statistical impact, graphical fingerprints, additional seeds, and release-mode unit/module/protocol tests remain unverified.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

@mgonzalezlopezudc
mgonzalezlopezudc force-pushed the feat/ieee80211-txop-duration branch 4 times, most recently from 56829e1 to eea6e43 Compare October 4, 2026 20:37
@mgonzalezlopezudc
mgonzalezlopezudc force-pushed the feat/ieee80211-txop-duration branch 6 times, most recently from e8907fa to 23ed984 Compare October 5, 2026 16:52
@mgonzalezlopezudc
mgonzalezlopezudc force-pushed the feat/ieee80211-txop-duration branch from cb3fda0 to 7404029 Compare October 5, 2026 19:29
A radio command can reach the radio during short interframe space
(SIFS), before an accepted recipient response reaches the medium.
The medium access control (MAC) module checks medium state, but that
state does not identify the accepted response. Keep the command until
the transmission module (Tx) releases its accepted transmission.

The hybrid coordination function (HCF) and distributed coordination
function (DCF) release the command after the response completes.
Custom Tx modules must implement ITx::hasTransmission(). This query
returns true from acceptance through the SIFS wait and transmission.
It returns false after Tx releases the request.

To reproduce, submit a radio command after HCF accepts an
acknowledgment (ACK) frame for SIFS transmission. The old MAC sends
the command immediately when the medium is free. The focused module
test requires the command to wait until the ACK completes.

The command follows the accepted response, which changes event order.
The 30 affected fingerprint rows change only their event fingerprints.
Their numerical fingerprints retain their base values.

Change: src.ieee80211.mac | behavior.change.fix | test whatsnew migration fingerprint | radio-command-deferral
The transmission opportunity (TXOP) change needs one durable
description of its scope and contracts. A TXOP gives a quality of
service (QoS) station time to start frame exchange sequences.
Record the supported hybrid coordination function (HCF) path in
the implementation plan. Explain complete duration checks,
cancellation, frame ownership, and direct verification there.

Plan: plan/pending/ieee80211-txop-duration.md
Change: plan | behavior.add | - | txop-duration
Extra blank lines follow the final declarations in these MAC files.
Remove those lines separately so that the functional diffs show only
their source changes. The compiler sees the same source tokens.

Plan: plan/pending/ieee80211-txop-duration.md
Change: src.ieee80211.mac | format | - | txop-duration
A synchronous callback can cancel a delayed frame or start another
sequence. An old callback must not advance the replacement sequence.
Give each request to the transmission module (Tx) an identity before
submission. Check that identity after each permission callback.
The check also applies when the interframe space (IFS) is zero.

Protect borrowed sequence objects until all nested callbacks return.
Detach the contention callback before the channel grant notification.
This lets synchronous cancellation request channel access again.
Preserve response timeout order relative to equal-time network
allocation vector (NAV) events. The NAV records the medium
reservation from protocol duration information.
External Tx modules and handlers require the new request callbacks.

The request identity contract changes Tx and each callback consumer
together. A partial migration cannot compile against the new callbacks
or preserve cancellation across synchronous calls. The callback guards
belong to that contract, so this commit cannot divide safely.

Plan: plan/pending/ieee80211-txop-duration.md
Change: src.ieee80211.mac | behavior.add+change | test whatsnew migration | txop-duration
Stop and crash can leave a delayed or on-air request alive in the
medium access control (MAC) transmission module (Tx).
The hybrid coordination function (HCF) can also retain Block Ack
agreements without an inactivity timer after resume. Block Ack reports
reception status for multiple frames. An expired recipient agreement
can leave an old reorder buffer or admit late Block Ack data.

MAC resets Tx before the coordination functions retire their exchanges.
A new lifecycle epoch rejects old requests. Group, Block Ack, and
No Ack transmissions do not enter Normal Ack failure processing.
Normal Ack uses an acknowledgment (ACK) frame for each required response.

HCF retains each agreement's absolute deadline across downtime.
Resume retires overdue agreements before channel access.
Each handler detaches expired state before deletion callbacks.
Recipient retirement clears only the corresponding peer and traffic
identifier (TID)'s buffer. HCF discards late Block Ack data and queues
a delete block acknowledgment (DELBA) frame. Delayed timeout or
UNKNOWN_BA completion preserves a replacement agreement.

For example, an agreement starts at sequence 19 and buffers sequence 20.
After expiry, replacement add block acknowledgment (ADDBA) starts at
sequence 100. The cleared buffer lets HCF deliver sequence 100.
Late Block Ack data without an agreement instead causes discard
and UNKNOWN_BA DELBA.

The reset, deadline, buffer, and deletion contracts form one lifecycle
change. Their callers require the same interfaces before stop or resume
can use them. External Tx modules, handlers, ACK owners, agreement
handlers, callbacks, and recipient data services require source changes.
The module tests cover both expiry event orders, stop/crash restart,
zero timeout, buffer isolation, and replacement preservation.
IEEE Std 802.11-2024, 11.5.4 defines expiry and late-data discard.
Table 9-79 defines the DELBA reason codes.

Plan: plan/pending/ieee80211-txop-duration.md
Change: src.ieee80211.mac | behavior.add+change.fix | test whatsnew migration | txop-duration
Exchange preparation needs frame identity and acknowledgment (ACK)
state without protocol progress. Expose read-only ACK snapshots and
staged views. Keep extraction and fragment transmission history in
the frame store. Retain original frames while a context borrows them.
Notify the typed removal callback before a referenced frame leaves
the store.

The distributed coordination function (DCF) and hybrid coordination
function (HCF) release contexts in preDelete(), before child stores die.
The teardown regression checks this order for DCF and legacy HCF.
Custom ACK owners require snapshotFrameState(), the read-only state query.

Plan: plan/pending/ieee80211-txop-duration.md
Change: src.ieee80211.mac | behavior.add | test whatsnew migration | txop-duration
Admission must use the duration of the exchange that execution selects.
Let the current constructor tree record each selected branch, frame,
mode, protection choice, and response before execution.
A private context projects completion without an acknowledgment (ACK)
state change. Timeout queries use the supplied response mode and
keep overrides. Unsupported primitives report unsupported preparation
explicitly.

The hybrid coordination function (HCF) still uses the legacy production
path in this commit. External sequence, step, and timeout policy
implementations require the new methods and a rebuild.

The preparation contract changes the constructor tree, primitive steps,
context, and timeout queries together. Each constructor must forward
the same prepared records that each primitive produces. A partial
migration cannot compile or retain those choices, so this commit
cannot divide safely. Production admission remains a later commit.

Plan: plan/pending/ieee80211-txop-duration.md
Change: src.ieee80211.mac | behavior.add+change | test whatsnew migration | txop-duration
…ions

A data frame can fit a transmission opportunity (TXOP) while its
required response does not. Add admission for the complete prepared
exchange, with interframe space (IFS) and response airtime.
Use actual transmission history for permitted overruns and zero-limit
fragment units under IEEE Std 802.11-2024, 10.23.2.9.

Check the transmitted reservation separately under 10.23.2.8.
Derive the Duration/ID header field from accepted plans under 9.2.5.2.
Hybrid coordination function (HCF) preparation remains disabled in
the production context.

Plan: plan/pending/ieee80211-txop-duration.md
Change: src.ieee80211.mac | behavior.add+change | test whatsnew migration | txop-duration
The hybrid coordination function (HCF) previously admitted a continuation whenever
positive transmission opportunity (TXOP) time remains.
That check can accept a data frame whose required response exceeds
the limit. Enable complete exchange preparation when
isBlockAckSupported is false. HCF executes the exchange that passed
complete duration admission.

Transmission uses the accepted frames, modes, acknowledgment (ACK)
policy, and protection values. Mode-set changes and retained frame
removal invalidate stale plans. Commit actual transmission history
before completion selects another exchange. Keep cancellation in
the HCF module context.

For example, the exchange test's 350-microsecond limit admits two
data/ACK exchanges. HCF refuses the third complete exchange and ends
the TXOP. The third frame waits for a new channel grant without
retry progress.

The distributed coordination function (DCF) and HCF with Block Ack
support retain their legacy paths. Block Ack reports reception status
for multiple frames. The duration guarantee assumes zero propagation
delay and nominal short interframe space (SIFS).
An oversized initial exchange without a supported exception reports
a model-limit error. Automatic fragmentation to an airtime budget
is unsupported.

The accepted exchange now controls frame choices and transmission time.
This changes eleven fingerprint rows for tplx, ~tNl, and ~tND.
Of the 30 rows that the radio deferral changes, 26 retain those values.
Four rows receive the combined effect of radio deferral and prepared
HCF execution.

Plan: plan/pending/ieee80211-txop-duration.md
Change: src.ieee80211.mac | behavior.add+change.fix | test whatsnew migration fingerprint | txop-duration
@mgonzalezlopezudc
mgonzalezlopezudc force-pushed the feat/ieee80211-txop-duration branch 2 times, most recently from 1ef1f17 to c8ea3b7 Compare October 5, 2026 22:56

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant