NetBSD-Bugs archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
port-evbarm/60815: Request pull-up of Raspberry Pi 5 SDIO Wi-Fi fixes to netbsd-11
>Number: 60815
>Category: port-evbarm
>Synopsis: Request pull-up of Raspberry Pi 5 SDIO Wi-Fi fixes to netbsd-11
>Confidential: no
>Severity: serious
>Priority: medium
>Responsible: port-evbarm-maintainer
>State: open
>Class: change-request
>Submitter-Id: net
>Arrival-Date: Sun Sep 27 22:05:04 +0000 2026
>Originator: Anton Povalikhin
>Release: NetBSD 11.0
>Organization:
LLC OXTECH
>Environment:
NetBSD pi5-netbsd 11.0 NetBSD 11.0 (OXTORG64) #0: Fri Sep 25 01:31:55 UTC 2026 root@arm64:/root/build/usr/src/sys/arch/evbarm/compile/OXTORG64 evbarm
>Description:
DRAFT FACTS FOR THE SUBMITTER ? rewrite the report in your own words before submission.
On two Raspberry Pi 5 boards with BCM2712 C1 and CYW43455 Wi-Fi over SDIO, NetBSD 11.0 does not attach bwfm: the module reports product 0x4345, which the netbsd-11 if_bwfm_sdio.c match table lacks. We booted through eotics RPi5 UEFI rpi5-20260730.1 with local SDIO power fixes.
With the BCM4345 match from trunk if_bwfm_sdio.c 1.34 alone, the first SDIO CMD53 read caused a kernel fault in sdhc_start_command() on the ADMA2-capable host. The command had no DMA map; the netbsd-11 driver attempted to use the NULL c_dmamap. We observed this on 24 September 2026.
Adding the relevant DMA guard from trunk sdhc.c 1.125 allowed the module to attach and connect to WPA2 on 5 GHz with DHCP. Our test kernel also included trunk if_bwfm_sdio.c 1.33 and separate local Raspberry Pi 5, UEFI, and Wi-Fi fixes. Thus these tests do not establish that the three trunk pull-ups alone provide full stock Pi 5 Wi-Fi support. We did not observe the corrupt-frame panic addressed by 1.33; we saw one 'bwfm0: rx_glom empty packet' message.
On 25 September, a 3-hour-20-minute load run completed 49 cycles: 57-114 Mbit/s from the board, 49-61 Mbit/s to the board, with no lost pings. The full 24-hour log was not retained, so we make no overnight stability claim. Additional reboot and network-switch tests exercised local bwfm state-machine changes, which should be reported separately.
Russian-language summary of observations:
Без 1.34 Wi-Fi нет: bwfm в 11.0 не знает product 0x4345, модуль CYW43455 на Pi 5 не подключается. С 1.34, но без правки sdhc.c ядро 11.0 падает: команды SDIO CMD53 идут без карты DMA, а sdhc разыменовывает пустой указатель на первом чтении моду

83;я. С правкой sdhc.c модуль подключился, WPA2 и DHCP работали. За 3 ч 20 мин нагрузочного прогона прошло 49 кругов, ping без потерь. Полный суточный журнал не сохранился.
>How-To-Repeat:
DRAFT FACTS ? rewrite before submission.
1. Boot NetBSD 11.0 on a Raspberry Pi 5 with UEFI that powers SDIO2. The CYW43455 reports product 0x4345, but bwfm does not attach.
2. Apply only trunk if_bwfm_sdio.c revision 1.34 and reboot. The first SDIO CMD53 read reaches sdhc_start_command() with a NULL c_dmamap on an ADMA2-capable host and the kernel faults.
3. Apply the sdhc_start_command() DMA guard from trunk sdhc.c revision 1.125. The module attaches; WPA2 connection and DHCP then worked on our locally patched test image.
>Fix:
DRAFT FACTS ? rewrite the explanation in your own words before submission. The patch below consists of three existing NetBSD trunk changes for netbsd-11:
- if_bwfm_sdio.c 1.34 (44055db23a36): BCM4345 match.
- if_bwfm_sdio.c 1.33 (0bd35761fb5d): rounded RX glom frame reads. Its corrupt-frame panic was not reproduced here.
- The sdhc_start_command() hunk from sdhc.c 1.125 (a75847d5d6d7): ADMA2 setup only when the command uses DMA; assert that the DMA map exists. The rest of 1.125 is unrelated Wii U support.
The patch applied without offset or fuzz to netbsd-11 at 03d918f6d0e81fa05b8f1160eca0628ad39988a6.
--- sys/dev/sdmmc/if_bwfm_sdio.c
+++ sys/dev/sdmmc/if_bwfm_sdio.c
@@ -289,6 +289,11 @@
SDMMC_VENDOR_BROADCOM,
SDMMC_PRODUCT_BROADCOM_BCM4334,
SDMMC_CIS_BROADCOM_BCM4334
+ },
+ {
+ SDMMC_VENDOR_BROADCOM,
+ SDMMC_PRODUCT_BROADCOM_BCM4345,
+ SDMMC_CIS_BROADCOM_BCM4345
},
{
SDMMC_VENDOR_BROADCOM,
@@ -1898,7 +1903,7 @@
struct bwfm_sdio_swhdr swhdr;
struct bwfm_proto_bcdc_hdr *bcdc;
struct mbuf *m, *m0;
- size_t flen, off, hoff;
+ size_t flen, off, hoff, slen;
int i;
const size_t hdrlen = sizeof(hwhdr) + sizeof(swhdr);
@@ -1916,18 +1921,19 @@
return;
}
bwfm_qput(&m0, m);
- if (le16toh(sublen[i]) > m->m_len) {
+ slen = le16toh(sublen[i]);
+ if (roundup(slen,4) > m->m_len) {
m_freem(m0);
printf("%s: header larger than mbuf\n", DEVNAME(sc));
return;
}
if (bwfm_sdio_frame_read_write(sc, mtod(m, char *),
- le16toh(sublen[i]), 0)) {
+ roundup(slen,4), 0)) {
m_freem(m0);
printf("%s: frame I/O error\n", DEVNAME(sc));
return;
}
- m->m_len = m->m_pkthdr.len = le16toh(sublen[i]);
+ m->m_len = m->m_pkthdr.len = slen;
}
if (m0->m_len >= hdrlen) {
--- sys/dev/sdmmc/sdhc.c
+++ sys/dev/sdmmc/sdhc.c
@@ -1809,7 +1809,10 @@
}
/* Set DMA start address. */
- if (ISSET(hp->flags, SHF_USE_ADMA2_MASK) && cmd->c_data != NULL) {
+ if (ISSET(mode, SDHC_DMA_ENABLE) &&
+ ISSET(hp->flags, SHF_USE_ADMA2_MASK) &&
+ cmd->c_data != NULL) {
+ KASSERT(cmd->c_dmamap != NULL);
for (int seg = 0; seg < cmd->c_dmamap->dm_nsegs; seg++) {
bus_addr_t paddr =
cmd->c_dmamap->dm_segs[seg].ds_addr;
Home |
Main Index |
Thread Index |
Old Index