NetBSD-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

port-evbarm/60815: Request pull-up of Raspberry Pi 5 SDIO Wi-Fi fixes to netbsd-11



>Number:         60815
>Category:       port-evbarm
>Synopsis:       Request pull-up of Raspberry Pi 5 SDIO Wi-Fi fixes to netbsd-11
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    port-evbarm-maintainer
>State:          open
>Class:          change-request
>Submitter-Id:   net
>Arrival-Date:   Sun Sep 27 22:05:04 +0000 2026
>Originator:     Anton Povalikhin
>Release:        NetBSD 11.0
>Organization:
LLC OXTECH
>Environment:
NetBSD pi5-netbsd 11.0 NetBSD 11.0 (OXTORG64) #0: Fri Sep 25 01:31:55 UTC 2026  root@arm64:/root/build/usr/src/sys/arch/evbarm/compile/OXTORG64 evbarm
>Description:
DRAFT FACTS FOR THE SUBMITTER ? rewrite the report in your own words before submission.

On two Raspberry Pi 5 boards with BCM2712 C1 and CYW43455 Wi-Fi over SDIO, NetBSD 11.0 does not attach bwfm: the module reports product 0x4345, which the netbsd-11 if_bwfm_sdio.c match table lacks. We booted through eotics RPi5 UEFI rpi5-20260730.1 with local SDIO power fixes.

With the BCM4345 match from trunk if_bwfm_sdio.c 1.34 alone, the first SDIO CMD53 read caused a kernel fault in sdhc_start_command() on the ADMA2-capable host. The command had no DMA map; the netbsd-11 driver attempted to use the NULL c_dmamap. We observed this on 24 September 2026.

Adding the relevant DMA guard from trunk sdhc.c 1.125 allowed the module to attach and connect to WPA2 on 5 GHz with DHCP. Our test kernel also included trunk if_bwfm_sdio.c 1.33 and separate local Raspberry Pi 5, UEFI, and Wi-Fi fixes. Thus these tests do not establish that the three trunk pull-ups alone provide full stock Pi 5 Wi-Fi support. We did not observe the corrupt-frame panic addressed by 1.33; we saw one 'bwfm0: rx_glom empty packet' message.

On 25 September, a 3-hour-20-minute load run completed 49 cycles: 57-114 Mbit/s from the board, 49-61 Mbit/s to the board, with no lost pings. The full 24-hour log was not retained, so we make no overnight stability claim. Additional reboot and network-switch tests exercised local bwfm state-machine changes, which should be reported separately.

Russian-language summary of observations:
Без 1.34 Wi-Fi нет: bwfm в 11.0 не знает product 0x4345, модуль CYW43455 на Pi 5 не подключается. С 1.34, но без правки sdhc.c ядро 11.0 падает: команды SDIO CMD53 идут без карты DMA, а sdhc разыменовывает пустой указатель на первом чтении моду&#10
 83;я. С правкой sdhc.c модуль подключился, WPA2 и DHCP работали. За 3 ч 20 мин нагрузочного прогона прошло 49 кругов, ping без потерь. Полный суточный журнал не сохранился.
>How-To-Repeat:
DRAFT FACTS ? rewrite before submission.
1. Boot NetBSD 11.0 on a Raspberry Pi 5 with UEFI that powers SDIO2. The CYW43455 reports product 0x4345, but bwfm does not attach.
2. Apply only trunk if_bwfm_sdio.c revision 1.34 and reboot. The first SDIO CMD53 read reaches sdhc_start_command() with a NULL c_dmamap on an ADMA2-capable host and the kernel faults.
3. Apply the sdhc_start_command() DMA guard from trunk sdhc.c revision 1.125. The module attaches; WPA2 connection and DHCP then worked on our locally patched test image.
>Fix:
DRAFT FACTS ? rewrite the explanation in your own words before submission. The patch below consists of three existing NetBSD trunk changes for netbsd-11:
- if_bwfm_sdio.c 1.34 (44055db23a36): BCM4345 match.
- if_bwfm_sdio.c 1.33 (0bd35761fb5d): rounded RX glom frame reads. Its corrupt-frame panic was not reproduced here.
- The sdhc_start_command() hunk from sdhc.c 1.125 (a75847d5d6d7): ADMA2 setup only when the command uses DMA; assert that the DMA map exists. The rest of 1.125 is unrelated Wii U support.

The patch applied without offset or fuzz to netbsd-11 at 03d918f6d0e81fa05b8f1160eca0628ad39988a6.

--- sys/dev/sdmmc/if_bwfm_sdio.c
+++ sys/dev/sdmmc/if_bwfm_sdio.c
@@ -289,6 +289,11 @@
 		SDMMC_VENDOR_BROADCOM,
 		SDMMC_PRODUCT_BROADCOM_BCM4334,
 		SDMMC_CIS_BROADCOM_BCM4334
+	},
+	{
+		SDMMC_VENDOR_BROADCOM,
+		SDMMC_PRODUCT_BROADCOM_BCM4345,
+		SDMMC_CIS_BROADCOM_BCM4345
 	},
 	{
 		SDMMC_VENDOR_BROADCOM,
@@ -1898,7 +1903,7 @@
 	struct bwfm_sdio_swhdr swhdr;
 	struct bwfm_proto_bcdc_hdr *bcdc;
 	struct mbuf *m, *m0;
-	size_t flen, off, hoff;
+	size_t flen, off, hoff, slen;
 	int i;
 	const size_t hdrlen = sizeof(hwhdr) + sizeof(swhdr);
 
@@ -1916,18 +1921,19 @@
 			return;
 		}
 		bwfm_qput(&m0, m);
-		if (le16toh(sublen[i]) > m->m_len) {
+		slen = le16toh(sublen[i]);
+		if (roundup(slen,4) > m->m_len) {
 			m_freem(m0);
 			printf("%s: header larger than mbuf\n", DEVNAME(sc));
 			return;
 		}
 		if (bwfm_sdio_frame_read_write(sc, mtod(m, char *),
-		    le16toh(sublen[i]), 0)) {
+		    roundup(slen,4), 0)) {
 			m_freem(m0);
 			printf("%s: frame I/O error\n", DEVNAME(sc));
 			return;
 		}
-		m->m_len = m->m_pkthdr.len = le16toh(sublen[i]);
+		m->m_len = m->m_pkthdr.len = slen;
 	}
 
 	if (m0->m_len >= hdrlen) {
--- sys/dev/sdmmc/sdhc.c
+++ sys/dev/sdmmc/sdhc.c
@@ -1809,7 +1809,10 @@
 	}
 
 	/* Set DMA start address. */
-	if (ISSET(hp->flags, SHF_USE_ADMA2_MASK) && cmd->c_data != NULL) {
+	if (ISSET(mode, SDHC_DMA_ENABLE) &&
+	    ISSET(hp->flags, SHF_USE_ADMA2_MASK) &&
+	    cmd->c_data != NULL) {
+		KASSERT(cmd->c_dmamap != NULL);
 		for (int seg = 0; seg < cmd->c_dmamap->dm_nsegs; seg++) {
 			bus_addr_t paddr =
 			    cmd->c_dmamap->dm_segs[seg].ds_addr;




Home | Main Index | Thread Index | Old Index