Repository navigation
ieee80211: publish management rate contexts - #1276
mgonzalezlopezudc wants to merge 15 commits into
Conversation
There was a problem hiding this comment.
Devin Review found 3 potential issues.
3 flags not posted on this PR by your GitHub settings — view them in Devin Review. (Configure)
| if (txop->admitExchange(nextPlan->duration, *candidate, simTime()) == TxopProcedure::Admission::REFUSED || | ||
| !txop->fitsTxnav(nextPlan->remainingDuration(0, true), simTime())) |
There was a problem hiding this comment.
🔴 Protected continuations lose their TXOP
For an RTS-protected continuation, fitsTxnav compares the full exchange against a reservation covering only its RTS/CTS handshake. The valid continuation gets refused and must contend for another channel grant.
Learn more
A prepared continuation can contain RTS, CTS, data, and ACK. The preceding transmitted frame reserves the current exchange and only the first protected interval of the continuation in computePreparedDurationField. The current TXNAV therefore ends after CTS, not after the continuation's ACK. Comparing its remaining reservation with the whole continuation cost refuses a valid protected exchange even when the TXOP limit has room. Its RTS will establish a new reservation for the remaining data exchange.
Example: A frame reserves its own ACK, then SIFS + RTS + SIFS + CTS for the next frame. Once its ACK arrives, the TXNAV has enough time for RTS/CTS, but not for RTS/CTS + data + ACK. The continuation is refused despite enough TXOP airtime for all four steps.
Recommended fix: Compare the available TXNAV only with the interval that the preceding frame reserves for the next exchange. Keep admitExchange() responsible for checking the complete continuation against the TXOP limit. Test an RTS-protected continuation that fits both limits but whose full exchange extends beyond the previous reservation.
Was this helpful? React with 👍 or 👎 to provide feedback.
| if (pendingRadioConfigMsg != nullptr && !tx->hasTransmission()) { | ||
| auto message = pendingRadioConfigMsg; | ||
| pendingRadioConfigMsg = nullptr; | ||
| sendDown(message); |
There was a problem hiding this comment.
🟡 Shutdown sends queued radio configuration
When a MAC stops with a queued radio command, sendDownPendingRadioConfigMsg sends it during sequence cleanup. Tx has already reset, so its transmission guard no longer protects the stopped radio.
Learn more
A radio configuration command is queued when the medium is busy or Tx has a transmission. On MAC shutdown, handleStopOperation first resets Tx, then resets HCF or DCF. Their frameSequenceFinished callbacks flush the pending command. Tx now reports no transmission, so this method sends the command while the MAC is stopping.
Example: Queue a channel-change command during an HCF exchange, then stop the interface before transmission finishes. Sequence cleanup sends the channel change to the radio during shutdown instead of keeping the radio stopped.
Recommended fix: Separate normal exchange completion from lifecycle cleanup when flushing pending radio commands. Clear or defer the pending command on stop according to the intended restart policy; only send it while the MAC is operational.
Was this helpful? React with 👍 or 👎 to provide feedback.
| if (binding != incomingRateContexts.end() && | ||
| (binding->second.size() != 1 || binding->second.front() != ref)) | ||
| return result; | ||
| if (ref.kind == BssRateContextRef::TARGET) { | ||
| useTarget(ref); | ||
| return result; | ||
| } | ||
| if (ref != activeRateContext) | ||
| return result; |
There was a problem hiding this comment.
🟡 Old active reference overrides pending target
During same-AP reassociation, snapshotRateContext accepts an explicit active reference for the outgoing request subtype. incomingRateContexts binds only the response subtype, so the conflicting pending target is missed and active rates are returned.
Learn more
A rate context reference identifies the BSS whose rate facts a queued management frame uses. A station binds a new association target to its incoming response subtype in startReassociation. The target lookup already recognizes an outgoing request and its corresponding response subtype in useTarget. The explicit-active path instead checks only the exact subtype's binding, then returns active facts when that binding does not exist.
Example: A station reassociates with its current AP. The new target is bound to ST_REASSOCIATIONRESPONSE, but querying ST_REASSOCIATIONREQUEST with an old active reference returns the active rate set instead of an unknown conflicting context.
Recommended fix: Apply the same corresponding-subtype binding check to explicit active references before returning active facts. Preserve the existing distinction between an absent target and a target bound to a different peer.
Was this helpful? React with 👍 or 👎 to provide feedback.
b01a6a7 to
83b5a11
Compare
The TXOP change needs one durable description of its scope and contracts. Record the supported HCF path, complete duration checks, cancellation, frame ownership, and direct verification in the implementation plan. Plan: plan/pending/ieee80211-txop-duration.md Change: plan | behavior.add | - | ieee80211-txop-duration
Extra blank lines follow the final declarations in these MAC files. Remove those lines separately so that the functional diffs show only their source changes. The compiler sees the same source tokens. Plan: plan/pending/ieee80211-txop-duration.md Change: src.ieee80211.mac | format | - | ieee80211-txop-duration
A radio command can arrive during SIFS before an accepted response reaches the medium. Medium state alone does not identify that response. Keep the command until Tx releases its accepted transmission. HCF and DCF release pending commands after a recipient response. Custom Tx modules must implement hasTransmission(). The isolated fix reproduces the final tplx values in all 26 event-only baseline rows. The other eleven HCF rows retain all three base values. The command follows the accepted response, which changes event order. Numerical fingerprints remain unchanged in all 37 affected cases. Plan: plan/pending/ieee80211-txop-duration.md Change: src.ieee80211.mac | behavior.change.fix | test whatsnew migration fingerprint | ieee80211-txop-duration
A synchronous callback can cancel a delayed frame or start another sequence. An old callback must not advance the replacement sequence. Give each Tx request an identity before submission. Check that identity after each permission callback, including the zero-IFS path. Protect borrowed sequence objects until all nested callbacks return. Detach the contention callback before the channel grant notification. This lets synchronous cancellation request channel access again. Preserve response timeout order relative to equal-time NAV events. External Tx modules and handlers require the new request callbacks. The request identity contract changes Tx and each callback consumer together. A partial migration cannot compile against the new callbacks or preserve cancellation across synchronous calls. The callback guards belong to that contract, so this commit cannot divide safely. Plan: plan/pending/ieee80211-txop-duration.md Change: src.ieee80211.mac | behavior.add+change | test whatsnew migration | ieee80211-txop-duration
MAC stop and crash can leave a delayed or on-air request in Tx. Reset Tx before the coordination functions retire their exchanges. Advance the lifecycle epoch so that an old request cannot resume. Clear frame registrations and restart channel access after resume. Group, Block Ack, and No Ack transmissions require no Normal ACK failure transition when lifecycle reset interrupts them. External Tx modules, handlers, and ACK owners require reset support. Plan: plan/pending/ieee80211-txop-duration.md Change: src.ieee80211.mac | behavior.add+change.fix | test whatsnew migration | ieee80211-txop-duration
Exchange preparation needs frame identity and ACK state without protocol progress. Expose read-only ACK snapshots and staged views. Keep extraction and fragment transmission history in the frame store. Retain original frames while a context borrows them. Notify the typed removal callback before a referenced frame leaves the store. Release HCF and DCF contexts in preDelete(), before child stores die. The teardown regression checks this order for DCF and legacy HCF. Custom ACK owners require snapshotFrameState(). Plan: plan/pending/ieee80211-txop-duration.md Change: src.ieee80211.mac | behavior.add | test whatsnew migration | ieee80211-txop-duration
Admission must use the duration of the exchange that execution selects. Let the existing constructor tree record each selected branch, frame, mode, protection choice, and response before execution. A private context projects completion without an ACK state change. Timeout queries use the supplied response mode and keep overrides. Unsupported primitives report unsupported preparation explicitly. HCF still uses the legacy production path in this commit. External sequence, step, and timeout policy implementations require the new methods and a rebuild. The preparation contract changes the constructor tree, primitive steps, context, and timeout queries together. Each constructor must forward the same prepared records that each primitive produces. A partial migration cannot compile or retain those choices, so this commit cannot divide safely. Production admission remains a later commit. Plan: plan/pending/ieee80211-txop-duration.md Change: src.ieee80211.mac | behavior.add+change | test whatsnew migration | ieee80211-txop-duration
…ions A data frame can fit a TXOP while its required response does not. Add admission for the complete prepared exchange, including IFS and response airtime. Use actual transmission history for permitted overruns and zero-limit fragment units under 802.11-2024 10.23.2.9. Check the transmitted reservation separately under 10.23.2.8. Derive Duration/ID from accepted plans under 9.2.5.2. HCF preparation remains disabled in the production context. Plan: plan/pending/ieee80211-txop-duration.md Change: src.ieee80211.mac | behavior.add+change | test whatsnew migration | ieee80211-txop-duration
HCF must execute the exchange that passed complete duration admission. Enable preparation when isBlockAckSupported is false. Use the accepted frames, modes, ACK policy, and protection values for transmission. Reject stale plans after a mode-set change or retained frame removal. Commit actual transmission history before completion selects another exchange. Keep cancellation in the HCF module context. DCF and HCF with Block Ack support retain their legacy paths. The duration guarantee assumes zero propagation delay and nominal SIFS. An oversized initial exchange without a supported exception reports a model-limit error. Airtime-driven fragmentation is unsupported. Prepared HCF execution changes the remaining eleven baseline rows. Those rows now match the topic for tplx, ~tNl, and ~tND. The earlier 26 event-only rows retain their values from the radio fix. The accepted exchange now controls frame choices and transmission time. Plan: plan/pending/ieee80211-txop-duration.md Change: src.ieee80211.mac | behavior.add+change.fix | test whatsnew migration fingerprint | ieee80211-txop-duration
Stop or crash cancels HCF inactivity while finite agreements survive. Restart must restore their absolute deadlines without new peer activity. HCF reads both agreement directions and schedules their earliest deadline. Elapsed deadlines expire at restart. Timeout zero retains no timer. Recipient Block Ack data refreshes its own peer and TID deadline. Each handler retires expired state before it queues timeout DELBA. This prevents repeated expiry and stale state if stop cancels DELBA. Delayed timeout DELBA completion preserves a replacement agreement. The timer uses absolute deadlines under IEEE 802.11-2024, 11.5.4. External agreement handlers and timer callbacks require source changes. Ieee80211BlockAckRestart_1 reproduces stop and crash after real ADDBA. It checks both roles, short and expired downtime, and timeout zero. Ieee80211BlockAckInactivity_1 checks retirement before callback re-entry and preservation of replacement state after delayed DELBA completion. Plan: plan/pending/ieee80211-txop-duration.md Change: src.ieee80211.mac | behavior.change.fix | test whatsnew migration | ieee80211-txop-duration
83b5a11 to
5d15895
Compare
Overdue Block Ack agreements can survive restart if traffic renews the deadline before the restored inactivity event executes. Recipient retirement also leaves an old reorder buffer. Local expiry sends no deletion notification. HCF retires both directions before timeout DELBA requests channel access. Receive handlers check the absolute deadline before renewal. The recipient data service releases only the retired peer and TID's buffer. HCF emits one deletion notification after the state transition. Delayed timeout DELBA completion preserves replacement agreements. The retirement contract and all callers form one change. Buffer cleanup and deletion notification must complete before DELBA can request channel access. The tests cover deadline boundaries, stop/crash restart, buffer isolation, replacement ADDBA, and duplicate retirement. To reproduce the buffer defect, establish ADDBA at sequence 19. Retain sequence 20. Expire the agreement. Establish replacement ADDBA at sequence 100. The old reorder window discards the first new frame. IEEE Std 802.11-2024, 11.5.4 defines inactivity expiry and late data discard. Plan: plan/pending/ieee80211-txop-duration.md Change: src.ieee80211.mac | behavior.change.fix | test whatsnew migration | ieee80211-txop-duration
Rate consumers need rate facts with a complete relationship identity. The MIB now returns owned snapshots for active and target relationships. It rejects stale references, conflicting identities, and ambiguous bindings. The MIB assigns generations to committed references. Related updates use RateUpdate so one notification follows the complete transition. Target removal also removes its bindings. Direct probes cover empty and unknown facts, both association directions, ambiguous bindings, stale references, and owned snapshots. Existing MIB teardown and Supported Rates tests retain their expected results. Include the unchanged implementation plan for the series references. The release notes and migration guide describe the query contract. No recorded expectation changes belong to this commit. Plan: plan/pending/ieee80211-rate-context.md Change: src.ieee80211 | behavior.add+change | test whatsnew migration | ieee80211-rate-context
Management owns the advertisements that describe accepted rate facts. Rate consumers previously needed those facts without production publishers. Decode both legacy rate elements before a cache or MIB update. Publish local, independent-BSS, discovery, and associated-Beacon facts. Simplified management publishes its configured association in both station and AP records. Existing HT inputs supply HT MCS facts. Discovery cleanup preserves the active peer. Relationship and lifecycle cleanup remove matching rate records before the final notification. The staged module case checks publication, malformed advertisements, discovery cleanup, simplified association, and the MIB query contract. The Beacon fixture represents a valid advertisement with an unsupported basic HT MCS. The primitive-dispatch fixture now supplies a real MIB. No recorded expectation changes belong to this commit. Plan: plan/pending/ieee80211-rate-context.md Change: src.ieee80211 | behavior.add+change | test whatsnew migration | ieee80211-rate-context
A queued management frame must retain the BSS selected by its transaction. The active association alone cannot identify that BSS during reassociation. Install a target and its expected incoming binding before queue entry. Carry the reference through packet copies, fragmentation, and RTS creation. The MAC uses the reference for the management BSSID. Reception removes the sender-local tag so each receiver resolves its own relationship. Full STA management commits accepted response rates with association state. The STA retains basic HT MCS facts from the target snapshot. AP management commits saved peer rates after an acknowledged successful response. Reject requests that omit required basic legacy rates. Fixture updates supply valid advertisements without a change to their expected outcomes. Failure, cancellation, replacement, disassociation, stop, and crash retire targets and bindings for that transaction. Transaction identifiers survive restart. Tests cover same-AP and different-AP targets, copies, refusal, lifecycle cleanup, and publication through the existing HT radio exchange. The STA MAC now puts the selected BSSID in management Address 3. The earlier path left this field unspecified. The new bytes identify the BSS selected by the transaction, including a reassociation target. This changes 30 ~tND fingerprints, all with run 0 and seed 0. Their tplx and ~tNl values stay the same. WHATSNEW explains this effect. The 13 examples.csv rows use WirelessDHCP, Wireless2DHCP, MIPv6 Handover, RouteOptimizationTwoCNs, MIPv6 Roaming, PMIPv6 General, wireless Handover, all five wireless/qos configurations, and wiredandwirelesshostswithap. The 13 showcases.csv rows use all four canvas/ieee80211 configurations, interfacetable AdvancedFeatures, networkpathactivity ChangingPaths, packetdrop QueueOverflow, physicallinkactivity Filtering, styling Annotation, wireless Handover, Multiradio, and both wireless/qos cases. Each row carries full STA management frames with the selected BSSID. The four tutorials.csv rows use configurator Step8A, Step8B, Step9, and Step12. Their full STA management frames carry the same byte change. Plan: plan/pending/ieee80211-rate-context.md Change: src.ieee80211 | behavior.add+change | test whatsnew migration fingerprint | ieee80211-rate-context
Start authentication with an AP that is not yet authenticated. Receive deauthentication before its authentication response. The STA previously ignored this frame, so the agent received no immediate completion. Accept deauthentication when authentication remains pending. The STA cancels its timeout and target. The STA sends one refusal to the agent. A duplicate frame causes no second completion. The agent resumes its scan after the refusal. The production management regression uses the real agent response path. It checks one refusal, one scan request, duplicate handling, and absence of a later timeout completion. No recorded expectation changes belong to this commit. Plan: plan/pending/ieee80211-rate-context.md Change: src.ieee80211 | behavior.change.fix | test | ieee80211-rate-context
5d15895 to
b9134c3
Compare
|
Superseded by PR #1301 |
Management frames need the rate facts for the BSS selected by their transaction.
The active association alone cannot identify that BSS during reassociation.
Management publishes accepted facts through the MIB, which returns copied snapshots with complete relationship identities.
A rate context identifies a relationship and its rate facts.
A target identifies the BSS selected by an authentication, association, or reassociation transaction.
A station retains AP A's active rates while it prepares association with AP B.
Queued frames for B retain B's target reference.
Failure removes B's target while A's active relationship remains intact.
An unknown target does not use A's rates.
The snapshots supply facts without a change to rate-selection policy.
An invalid reference makes the query return unknown context.
It does not cancel a queued originator transmission.
Custom management must publish facts at the actual relationship commit points.
Dependency and commit order
This branch includes the TXOP prerequisite from PR #1273.
Its prerequisite source tree matches
cb3fda07885379d75a5f83de5afec02a34cc3eb2exactly.The included prerequisite tip is
189f489f98.Its commit messages use the plan name
ieee80211-txop-durationas their group label.PR #1273 retains its own commit identities.
The prerequisite restores Block Ack inactivity deadlines after stop or crash.
HCF retires overdue agreements before channel access resumes.
Recipient retirement clears the peer and TID's reorder buffer.
Timeout zero retains no inactivity event.
Review the prerequisite first.
GitHub compares this PR against
master, so its displayed diff includes the prerequisite.Read the four rate-context commits in this order:
3930423ccbc777523db8543b33097cb9134c399bEach topic commit references
plan/pending/ieee80211-rate-context.md.Each topic group label is
ieee80211-rate-context.The first topic commit includes that plan.
The full series contains 15 commits on base
d9e14c5af24741e5c4b52d4cdcded7119f3fc2da.Architecture and behavior
Management owns accepted advertisements and transaction state.
The MIB owns rate records, generations, incoming bindings, and snapshot queries.
snapshotRateContext()takes the peer, frame subtype, optional BSSID, and optional context reference.It returns copied facts and identities.
References contain the BSSID, transaction identifier, and relationship generation.
Snapshots also contain the MIB generation.
A generation identifies a committed version of a relationship.
Queries reject stale references, conflicting identities, and ambiguous relationships.
Unknown facts remain distinct from known empty sets.
Full and simplified management publish local facts, discovery facts, accepted Beacon updates, and association facts.
Management validates legacy rate advertisements before publication.
APs reject association requests that omit required basic legacy rates.
Ieee80211Mib::RateUpdategroups related changes so listeners receive one notification after the complete state transition.Management installs a target before its first frame enters the queue.
It binds the expected incoming subtype and peer to the transaction.
References survive queues, Packet copies, fragmentation, and RTS creation.
The MAC puts the selected BSSID in Address 3 of management frames.
The previous STA path leaves that field unspecified.
Reception removes the sender-local tag so each receiver resolves its own relationship.
Failure, cancellation, replacement, disassociation, stop, and crash remove the affected targets and incoming bindings.
Transaction identifiers remain unique across restart.
Deauthentication during pending authentication cancels the timeout and target.
The STA sends one refusal to the agent, which resumes its scan.
A duplicate frame causes no second completion.
Ieee80211RateContextTagcontains local metadata without rate values or a new wire format.Ieee80211MgmtTransactionTagretains its role for association-response outcomes.The migration guide describes custom management publication and the prerequisite's external API changes.
WHATSNEWexplains the user effects.The four topic commits change no NED parameters or feature descriptors.
They touch no sealed source path.
They introduce no architecture or naming exception.
Control-rate selection, PHY response timing, TXOP admission policy, Block Ack wire formats, and A-MPDU integration remain outside the rate-context topic.
Validation
The current head is
b9134c399b0eec6c63ae22f9a6fb28f367e53c0c.Every corrected commit retains exactly the source tree of its corresponding commit before the label correction.
The final tree equals the tested rebase head
92dbb610c0e53d90619b1257237e229956f0495d.Only the group labels and resulting commit identities differ.
The correction changes no source, test, configuration, or fingerprint value.
All 15 corrected commits build in debug mode and pass their nonempty focused tests.
The final head also builds in release mode.
The final union passes 26 module targets and seven unit targets.
All 48 selected fingerprint cases pass for
tplx,~tNl, and~tND, with run 0 and seed 0.3930423ccbc777523db8543b33097cb9134c399bThe commit, classification, source-seal, and committed whitespace checks pass across all 15 commits.
The scoped Wi-Fi architecture and naming checks pass.
All group labels match their Plan file stems.
The project-wide gates still report 36 architecture findings, 23 naming findings, and 15 interface findings.
A fresh control at the common base reports the same findings.
The candidate adds or removes none of those findings.
These project-wide gates remain nonzero.
The local evidence resides in
audit/pull-request/pr1276-label-fix-20261005.It records every commit, source tree, selector, command, exit status, and normalized verification result.
Each commit uses a fresh incremental debug build from the repository root:
The release build uses the same command with
MODE=release.The module and unit verification uses the installed
opp_replinterface:Each invocation sets
PR1276_LABEL_STAGEto its position from 1 through 15.The final union uses
final.The local evidence script records the exact selectors and rejects an empty selection or a failed result.
It adds
tests/moduleto the test include paths.Each selected fixture starts from its committed test input.
The final module selector covers these targets:
Ieee80211TargetRateContext_1,Ieee80211MgmtStaSimplifiedInitialization_1,Ieee80211MgmtApReassociationSnapshot_1, andIeee80211MgmtStaLifecycle_1.Ieee80211HtAssociation_1,Ieee80211MgmtStaBeaconUpdate_1,Ieee80211MgmtStaDeauthentication_1, andIeee80211MgmtStaDisassociation_1.Ieee80211AgentStaReassociation_1,Ieee80211MgmtStaDiscovery_1,Ieee80211MgmtApTimeout_1, andIeee80211MgmtApHcfRtsTimeout_1.Ieee80211MgmtApQueueDrop_1,Ieee80211MgmtApLifecycle_1,Ieee80211MgmtApChannelChange_1, andIeee80211MgmtApHcfQueueDrop_1.Ieee80211MgmtApMalformedHtCap_1,Ieee80211HcfManagementRecovery_1,Ieee80211BlockAckLifecycle_1, andIeee80211PreparedCancellation_1.Ieee80211RetryMode_1,Ieee80211ExchangeTeardown_1,Ieee80211BlockAckRestart_1, andIeee80211BlockAckRetirement_1.Ieee80211LifecycleGroup_1andIeee80211TxopExchange_1.The final unit selector covers these targets:
Ieee80211SupportedRates_1,Ieee80211MibPeerTeardown_1, andIeee80211MgmtStaPrimitiveDispatch_1.Ieee80211PreparedOriginatorPolicy_1andIeee80211TxopDuration_1.FrameSequence_1andIeee80211BlockAckInactivity_1.The target regression checks identity, unknown and empty facts, both association directions, same-AP targets, stale references, copies, publication, and lifecycle cleanup.
Its authentication case uses the real agent response path.
The restart target covers stop, crash, both roles, short and expired downtime, and timeout zero.
The retirement target checks deletion notifications, recipient buffers, replacement agreements, and late activity.
Fingerprint provenance
The selected BSSID changes serialized management frame bytes.
The transaction commit records 30 changed
~tNDvalues with run 0 and seed 0.Their
tplxand~tNlvalues remain the same.The correction changes no stored expectation.
The 13 affected
examples.csvrows cover these groups:The 13 affected
showcases.csvrows cover these groups:The four affected
tutorials.csvrows cover configurator Step8A, Step8B, Step9, and Step12.Every affected configuration uses full STA management.
The transaction message declares this cause and its fingerprint obligation.
The prerequisite also contains its 37 previously approved fingerprint row updates.
The final fingerprint check uses this selector from
tests/fingerprint:The selected simulation time limits remain unchanged.
The check excludes
tyf.Fresh local execution does not cover the complete fingerprint suite, statistical baselines, or release-mode behavior tests.
Per-commit CI and fingerprints at each intermediate baseline commit remain unverified.