openwrt / openwrt/mt76

mt7996: Cannot send off-channel action frames on unassociated station interface

Open
#992 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C
Stars
888
Forks
436
PR merge metrics
No merged PRs in 30d

Description

When attempting to send Vendor Specific Action Frames off channel from an unassociated station interface on the mt7996 chip (Banana Pi R4), I am seeing that the kernel will report that they succeeded (for specific frequencies) but they are not actually sent (cannot be observed on a packet capture or received by the supposed recipient). This issue is present in OpenWRT and at least version 6.12 mainline linux.

Below is some additional debug info including the output of iw dev, iw phy, logread, ftrace snippits, and a wireshark capture of the stations traffic.

iw dev

root@OpenWrt:~# iw dev wifi1.1 info
Interface wifi1.1
	ifindex 50
	wdev 0x25
	addr be:dc:29:0f:8f:3a
	type managed
	wiphy 0
	txpower 27.00 dBm
	multicast TXQ:
		qsz-byt	qsz-pkt	flows	drops	marks	overlmt	hashcol	tx-bytes	tx-packets
		0	0	0	0	0	0	0	0		0
	4addr: on
	Radios: 0 1 2
root@OpenWrt:~# iw dev
phy#0
	Interface wifi2
		ifindex 28
		wdev 0x13
		addr 4a:2c:cc:42:5f:fa
		ssid BPI-AP16
		type AP
		channel 5 (5975 MHz), width: 160 MHz, center1: 6025 MHz
		txpower 12.00 dBm
		multicast TXQ:
			qsz-byt	qsz-pkt	flows	drops	marks	overlmt	hashcol	tx-bytes	tx-packets
			0	0	0	0	0	0	0	0		0
		Radios: 0 1 2
	Interface wifi1.2
		ifindex 27
		wdev 0x12
		addr 4a:2c:cc:42:5f:f9
		ssid BPI-AP13
		type AP
		channel 36 (5180 MHz), width: 80 MHz, center1: 5210 MHz
		txpower 23.00 dBm
		multicast TXQ:
			qsz-byt	qsz-pkt	flows	drops	marks	overlmt	hashcol	tx-bytes	tx-packets
			0	0	0	0	0	0	0	0		0
		Radios: 0 1 2
	Interface wifi1.1
		ifindex 26
		wdev 0x11
		addr 4a:2c:cc:42:5f:f8
		type managed
		txpower 23.00 dBm
		multicast TXQ:
			qsz-byt	qsz-pkt	flows	drops	marks	overlmt	hashcol	tx-bytes	tx-packets
			0	0	0	0	0	0	0	0		0
		4addr: on
		Radios: 0 1 2
	Interface wifi1
		ifindex 25
		wdev 0x10
		addr 4a:2c:cc:42:5f:f7
		ssid BPI-AP1
		type AP
		channel 36 (5180 MHz), width: 80 MHz, center1: 5210 MHz
		txpower 23.00 dBm
		multicast TXQ:
			qsz-byt	qsz-pkt	flows	drops	marks	overlmt	hashcol	tx-bytes	tx-packets
			0	0	0	0	0	0	0	0		0
		Radios: 0 1 2
	Interface wifi0
		ifindex 24
		wdev 0xf
		addr 4a:2c:cc:42:5f:f6
		ssid BPI-AP0
		type AP
		channel 6 (2437 MHz), width: 20 MHz, center1: 2437 MHz
		txpower 27.00 dBm
		multicast TXQ:
			qsz-byt	qsz-pkt	flows	drops	marks	overlmt	hashcol	tx-bytes	tx-packets
			0	0	0	0	0	0	0	0		0
		Radios: 0 1 2

The issue also occurs when the APs are not setup for BSSs:

root@OpenWrt:~# iw dev
phy#0
	Interface wifi2
		ifindex 47
		wdev 0x22
		addr 4a:2c:cc:42:5f:fa
		type AP
		txpower 0.00 dBm
		multicast TXQ:
			qsz-byt	qsz-pkt	flows	drops	marks	overlmt	hashcol	tx-bytes	tx-packets
			0	0	0	0	0	0	0	0		0
		Radios: 0 1 2
	Interface wifi1.2
		ifindex 46
		wdev 0x21
		addr 4a:2c:cc:42:5f:f9
		type AP
		multicast TXQ:
			qsz-byt	qsz-pkt	flows	drops	marks	overlmt	hashcol	tx-bytes	tx-packets
			0	0	0	0	0	0	0	0		0
		Radios: 0 1 2
	Interface wifi1.1
		ifindex 45
		wdev 0x20
		addr 4a:2c:cc:42:5f:f8
		type managed
		txpower 23.00 dBm
		multicast TXQ:
			qsz-byt	qsz-pkt	flows	drops	marks	overlmt	hashcol	tx-bytes	tx-packets
			0	0	0	0	0	0	0	0		0
		4addr: on
		Radios: 0 1 2
	Interface wifi1
		ifindex 44
		wdev 0x1f
		addr 4a:2c:cc:42:5f:f7
		type AP
		txpower 0.00 dBm
		multicast TXQ:
			qsz-byt	qsz-pkt	flows	drops	marks	overlmt	hashcol	tx-bytes	tx-packets
			0	0	0	0	0	0	0	0		0
		Radios: 0 1 2
	Interface wifi0
		ifindex 43
		wdev 0x1e
		addr 4a:2c:cc:42:5f:f6
		type AP
		txpower 0.00 dBm
		multicast TXQ:
			qsz-byt	qsz-pkt	flows	drops	marks	overlmt	hashcol	tx-bytes	tx-packets
			0	0	0	0	0	0	0	0		0
		Radios: 0 1 2

logread

Based on this, they really should be sending, but they are not.

Tue Jul 29 03:09:33 2025 kern.info kernel: [39916.372903] ieee80211 phy0: start roc work on freq=5180
Tue Jul 29 03:09:35 2025 kern.info kernel: [39918.429397] ieee80211 phy0: finish roc work, go back to freq=5180
Tue Jul 29 03:09:37 2025 kern.info kernel: [39920.376957] ieee80211 phy0: start roc work on freq=5220
Tue Jul 29 03:09:39 2025 kern.info kernel: [39922.621514] ieee80211 phy0: finish roc work, go back to freq=5220
Tue Jul 29 03:10:15 2025 kern.info kernel: [39958.404741] ieee80211 phy0: start roc work on freq=5180
Tue Jul 29 03:10:19 2025 kern.info kernel: [39962.878620] ieee80211 phy0: finish roc work, go back to freq=5180

ftrace

Off Channel, Some will return 0 and "succeed", some will return -EINVAL and fail, but a monitor mode capture will never show packets being sent on any of the frequencies that "succeed"

OneWifi-25037   [003] ....  7486.635536: rdev_mgmt_tx: phy0, wdev(37), band: 1, freq: 5180.000, offchan: true, wait: 2000, no cck: false, dont wait for ack: true
OneWifi-25037   [003] ....  7486.635554: drv_remain_on_channel: phy0 vif:wifi1.1(2) freq:5180.000MHz duration:10ms type=1
OneWifi-25037   [003] ....  7486.661202: api_ready_on_channel: phy0
OneWifi-25037   [003] ....  7486.661206: wiphy_work_queue: phy0 instance=0000000086aabb7b func=ieee80211_hw_roc_start+0x0/0x70 [mac80211]
OneWifi-25037   [003] ....  7486.661209: drv_return_int: phy0 - 0
OneWifi-25037   [003] ....  7486.661213: rdev_return_int_cookie: phy0, returned 0, cookie: 4294967295


OneWifi-25037   [000] ....  7488.638440: rdev_mgmt_tx: phy0, wdev(37), band: 0, freq: 2437.000, offchan: true, wait: 2000, no cck: false, dont wait for ack: true
OneWifi-25037   [000] ....  7488.638453: drv_remain_on_channel: phy0 vif:wifi1.1(2) freq:2437.000MHz duration:10ms type=1
OneWifi-25037   [000] ....  7488.638458: drv_return_int: phy0 - -22
OneWifi-25037   [000] ....  7488.638462: rdev_return_int_cookie: phy0, returned -22, cookie: 4294967295


OneWifi-25037   [000] ....  7494.646006: rdev_mgmt_tx: phy0, wdev(37), band: 1, freq: 5220.000, offchan: true, wait: 2000, no cck: false, dont wait for ack: true
OneWifi-25037   [000] ....  7494.646024: drv_remain_on_channel: phy0 vif:wifi1.1(2) freq:5220.000MHz duration:10ms type=1
OneWifi-25037   [003] ....  7494.671173: api_ready_on_channel: phy0
OneWifi-25037   [003] ....  7494.671175: wiphy_work_queue: phy0 instance=0000000086aabb7b func=ieee80211_hw_roc_start+0x0/0x70 [mac80211]
OneWifi-25037   [003] ....  7494.671178: drv_return_int: phy0 - 0
OneWifi-25037   [003] ....  7494.671180: rdev_return_int_cookie: phy0, returned 0, cookie: 4294967295


OneWifi-25037   [003] ....  7496.648897: rdev_mgmt_tx: phy0, wdev(37), band: 1, freq: 5745.000, offchan: true, wait: 2000, no cck: false, dont wait for ack: true
OneWifi-25037   [003] ....  7496.648913: drv_remain_on_channel: phy0 vif:wifi1.1(2) freq:5745.000MHz duration:10ms type=1
OneWifi-25037   [003] ....  7496.674631: api_ready_on_channel: phy0
OneWifi-25037   [003] ....  7496.674635: wiphy_work_queue: phy0 instance=0000000086aabb7b func=ieee80211_hw_roc_start+0x0/0x70 [mac80211]
OneWifi-25037   [003] ....  7496.674638: drv_return_int: phy0 - 0
OneWifi-25037   [003] ....  7496.674641: rdev_return_int_cookie: phy0, returned 0, cookie: 4294967295

On Channel, (Expectedly) Failing

OneWifi-21785   [002] ....  3022.486447: rdev_mgmt_tx: phy0, wdev(37), band: 0, freq: 2437.000, offchan: false, wait: 0, no cck: false, dont wait for ack: true
OneWifi-21785   [002] ....  3022.486459: rdev_return_int_cookie: phy0, returned -16, cookie: 18446743799228676416


OneWifi-21785   [001] ....  3030.496919: rdev_mgmt_tx: phy0, wdev(37), band: 1, freq: 5745.000, offchan: false, wait: 0, no cck: false, dont wait for ack: true
OneWifi-21785   [001] ....  3030.496931: rdev_return_int_cookie: phy0, returned -16, cookie: 18446743799228676416

iw phy

Wiphy phy0
	wiphy index: 0
	max # scan SSIDs: 4
	max scan IEs length: 2131 bytes
	max # sched scan SSIDs: 0
	max # match sets: 0
	Retry short limit: 7
	Retry long limit: 4
	Coverage class: 0 (up to 0m)
	Device supports RSN-IBSS.
	Device supports AP-side u-APSD.
	Device supports T-DLS.
	Supported Ciphers:
		* WEP40 (00-0f-ac:1)
		* WEP104 (00-0f-ac:5)
		* TKIP (00-0f-ac:2)
		* CCMP-128 (00-0f-ac:4)
		* CCMP-256 (00-0f-ac:10)
		* GCMP-128 (00-0f-ac:8)
		* GCMP-256 (00-0f-ac:9)
		* CMAC (00-0f-ac:6)
		* CMAC-256 (00-0f-ac:13)
		* GMAC-128 (00-0f-ac:11)
		* GMAC-256 (00-0f-ac:12)
	Available Antennas: TX 0xff RX 0xff
	Configured Antennas: TX 0xff RX 0xff
	Supported interface modes:
		 * IBSS
		 * managed
		 * AP
		 * AP/VLAN
		 * monitor
		 * mesh point
		 * P2P-client
		 * P2P-GO
	Band 1:
		Capabilities: 0x9ff
			RX LDPC
			HT20/HT40
			SM Power Save disabled
			RX Greenfield
			RX HT20 SGI
			RX HT40 SGI
			TX STBC
			RX STBC 1-stream
			Max AMSDU length: 7935 bytes
			No DSSS/CCK HT40
		Maximum RX AMPDU length 65535 bytes (exponent: 0x003)
		Minimum RX AMPDU time spacing: 2 usec (0x04)
		HT TX/RX MCS rate indexes supported: 0-15
		HE Iftypes: managed
			HE MAC Capabilities (0x08011a000040):
				+HTC HE Supported
				Trigger Frame MAC Padding Duration: 2
				OM Control
				Maximum A-MPDU Length Exponent: 3
				A-MSDU in A-MPDU
			HE PHY Capabilities: (0x2270ce920d01f30e4e3f00):
				HE40/2.4GHz
				242 tone RUs/2.4GHz
				Device Class: 1
				LDPC Coding in Payload
				HE SU PPDU with 1x HE-LTF and 0.8us GI
				NDP with 4x HE-LTF and 3.2us GI
				STBC Tx <= 80MHz
				STBC Rx <= 80MHz
				Full Bandwidth UL MU-MIMO
				Partial Bandwidth UL MU-MIMO
				DCM Max Constellation: 2
				DCM Max Constellation Rx: 2
				SU Beamformer
				SU Beamformee
				Beamformee STS <= 80Mhz: 3
				Sounding Dimensions <= 80Mhz: 1
				Codebook Size SU Feedback
				Codebook Size MU Feedback
				Triggered CQI Feedback
				Partial Bandwidth Extended Range
				Partial Bandwidth DL MU-MIMO
				PPE Threshold Present
				Power Boost Factor ar
				HE SU PPDU & HE PPDU 4x HE-LTF 0.8us GI
				Max NC: 1
				20MHz in 40MHz HE PPDU 2.4GHz
				20MHz in 160/80+80MHz HE PPDU
				80MHz in 160/80+80MHz HE PPDU
				DCM Max BW: 1
				Longer Than 16HE SIG-B OFDM Symbols
				Non-Triggered CQI Feedback
				TX 1024-QAM
				RX 1024-QAM
				RX Full BW SU Using HE MU PPDU with Compression SIGB
				RX Full BW SU Using HE MU PPDU with Non-Compression SIGB
			HE RX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: not supported
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: not supported
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			PPE Threshold 0x19 0x1c 0xc7 0x71
		EHT Iftypes: managed
			EHT MAC Capabilities (0x8201):
				EHT OM Control Supported
			EHT PHY Capabilities: (0xe801011e18600800):
				NDP With  EHT-LTF And 3.2 µs GI
				SU Beamformer
				SU Beamformee
				Beamformee SS (80MHz): 3
				Number Of Sounding Dimensions (80MHz): 1
				Ng = 16 SU Feedback
				Ng = 16 MU Feedback
				Codebook size (4, 2) SU Feedback
				Codebook size (7, 5) MU Feedback
				EHT MU PPDU With 4 EHT-LTF And 0.8 µs GI
				Max Nc: 1
				Common Nominal Packet Padding: 2
				Maximum Number Of Supported EHT-LTFs: 1
				Support of MCS 15: 1
			EHT MCS/NSS: (0x22222200000000000000000000):
			EHT bw=20 MHz, max NSS for MCS 0-7: Rx=2, Tx=2
			EHT bw=20 MHz, max NSS for MCS 8-9: Rx=2, Tx=2
			EHT bw=20 MHz, max NSS for MCS 10-11: Rx=2, Tx=2
			EHT bw=20 MHz, max NSS for MCS 12-13: Rx=0, Tx=0
		HE Iftypes: AP
			HE MAC Capabilities (0x00051a081044):
				+HTC HE Supported
				TWT Responder
				BSR
				OM Control
				Maximum A-MPDU Length Exponent: 3
				BQR
				A-MSDU in A-MPDU
				OM Control UL MU Data Disable RX
			HE PHY Capabilities: (0x0220ce920f01af0c000c00):
				HE40/2.4GHz
				LDPC Coding in Payload
				NDP with 4x HE-LTF and 3.2us GI
				STBC Tx <= 80MHz
				STBC Rx <= 80MHz
				Full Bandwidth UL MU-MIMO
				Partial Bandwidth UL MU-MIMO
				DCM Max Constellation: 2
				DCM Max Constellation Rx: 2
				SU Beamformer
				SU Beamformee
				MU Beamformer
				Beamformee STS <= 80Mhz: 3
				Sounding Dimensions <= 80Mhz: 1
				Codebook Size SU Feedback
				Codebook Size MU Feedback
				Triggered SU Beamforming Feedback
				Triggered MU Beamforming Feedback
				Partial Bandwidth Extended Range
				PPE Threshold Present
				HE SU PPDU & HE PPDU 4x HE-LTF 0.8us GI
				Max NC: 1
				TX 1024-QAM
				RX 1024-QAM
			HE RX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: not supported
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: not supported
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			PPE Threshold 0x19 0x1c 0xc7 0x71
		EHT Iftypes: AP
			EHT MAC Capabilities (0xa201):
				EHT OM Control Supported
			EHT PHY Capabilities: (0xe801017e18600812):
				NDP With  EHT-LTF And 3.2 µs GI
				SU Beamformer
				SU Beamformee
				Beamformee SS (80MHz): 3
				Number Of Sounding Dimensions (80MHz): 1
				Ng = 16 SU Feedback
				Ng = 16 MU Feedback
				Codebook size (4, 2) SU Feedback
				Codebook size (7, 5) MU Feedback
				Triggered SU Beamforming Feedback
				Triggered MU Beamforming Partial BW Feedback
				EHT MU PPDU With 4 EHT-LTF And 0.8 µs GI
				Max Nc: 1
				Common Nominal Packet Padding: 2
				Maximum Number Of Supported EHT-LTFs: 1
				Support of MCS 15: 1
				Non-OFDMA UL MU-MIMO (80MHz)
				MU Beamformer (80MHz)
			EHT MCS/NSS: (0x22222200000000000000000000):
			EHT bw=20 MHz, max NSS for MCS 0-7: Rx=2, Tx=2
			EHT bw=20 MHz, max NSS for MCS 8-9: Rx=2, Tx=2
			EHT bw=20 MHz, max NSS for MCS 10-11: Rx=2, Tx=2
			EHT bw=20 MHz, max NSS for MCS 12-13: Rx=0, Tx=0
		HE Iftypes: mesh point
			HE MAC Capabilities (0x00011a000040):
				+HTC HE Supported
				OM Control
				Maximum A-MPDU Length Exponent: 3
				A-MSDU in A-MPDU
			HE PHY Capabilities: (0x02200c0000000004008000):
				HE40/2.4GHz
				LDPC Coding in Payload
				STBC Tx <= 80MHz
				STBC Rx <= 80MHz
				HE SU PPDU & HE PPDU 4x HE-LTF 0.8us GI
			HE RX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: not supported
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: not supported
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
		EHT Iftypes: mesh point
			EHT MAC Capabilities (0x8201):
				EHT OM Control Supported
			EHT PHY Capabilities: (0xe801011e18600800):
				NDP With  EHT-LTF And 3.2 µs GI
				SU Beamformer
				SU Beamformee
				Beamformee SS (80MHz): 3
				Number Of Sounding Dimensions (80MHz): 1
				Ng = 16 SU Feedback
				Ng = 16 MU Feedback
				Codebook size (4, 2) SU Feedback
				Codebook size (7, 5) MU Feedback
				EHT MU PPDU With 4 EHT-LTF And 0.8 µs GI
				Max Nc: 1
				Common Nominal Packet Padding: 2
				Maximum Number Of Supported EHT-LTFs: 1
				Support of MCS 15: 1
			EHT MCS/NSS: (0x22222200000000000000000000):
			EHT bw=20 MHz, max NSS for MCS 0-7: Rx=2, Tx=2
			EHT bw=20 MHz, max NSS for MCS 8-9: Rx=2, Tx=2
			EHT bw=20 MHz, max NSS for MCS 10-11: Rx=2, Tx=2
			EHT bw=20 MHz, max NSS for MCS 12-13: Rx=0, Tx=0
		Bitrates (non-HT):
			* 1.0 Mbps (short preamble supported)
			* 2.0 Mbps (short preamble supported)
			* 5.5 Mbps (short preamble supported)
			* 11.0 Mbps (short preamble supported)
			* 6.0 Mbps
			* 9.0 Mbps
			* 12.0 Mbps
			* 18.0 Mbps
			* 24.0 Mbps
			* 36.0 Mbps
			* 48.0 Mbps
			* 54.0 Mbps
		Frequencies:
			* 2412.0 MHz [1] (27.0 dBm)
			* 2417.0 MHz [2] (27.0 dBm)
			* 2422.0 MHz [3] (27.0 dBm)
			* 2427.0 MHz [4] (27.0 dBm)
			* 2432.0 MHz [5] (27.0 dBm)
			* 2437.0 MHz [6] (27.0 dBm)
			* 2442.0 MHz [7] (27.0 dBm)
			* 2447.0 MHz [8] (27.0 dBm)
			* 2452.0 MHz [9] (27.0 dBm)
			* 2457.0 MHz [10] (27.0 dBm)
			* 2462.0 MHz [11] (27.0 dBm)
			* 2467.0 MHz [12] (disabled)
			* 2472.0 MHz [13] (disabled)
			* 2484.0 MHz [14] (disabled)
	Band 2:
		Capabilities: 0x9ff
			RX LDPC
			HT20/HT40
			SM Power Save disabled
			RX Greenfield
			RX HT20 SGI
			RX HT40 SGI
			TX STBC
			RX STBC 1-stream
			Max AMSDU length: 7935 bytes
			No DSSS/CCK HT40
		Maximum RX AMPDU length 65535 bytes (exponent: 0x003)
		Minimum RX AMPDU time spacing: 1 usec (0x03)
		HT TX/RX MCS rate indexes supported: 0-23
		VHT Capabilities (0x339a79f6):
			Max MPDU length: 11454
			Supported Channel Width: 160 MHz
			RX LDPC
			short GI (80 MHz)
			short GI (160/80+80 MHz)
			TX STBC
			SU Beamformer
			SU Beamformee
			MU Beamformer
			MU Beamformee
			RX antenna pattern consistency
			TX antenna pattern consistency
		VHT RX MCS set:
			1 streams: MCS 0-9
			2 streams: MCS 0-9
			3 streams: MCS 0-9
			4 streams: not supported
			5 streams: not supported
			6 streams: not supported
			7 streams: not supported
			8 streams: not supported
		VHT RX highest supported: 0 Mbps
		VHT TX MCS set:
			1 streams: MCS 0-9
			2 streams: MCS 0-9
			3 streams: MCS 0-9
			4 streams: not supported
			5 streams: not supported
			6 streams: not supported
			7 streams: not supported
			8 streams: not supported
		VHT TX highest supported: 0 Mbps
		VHT extended NSS: supported
		HE Iftypes: managed
			HE MAC Capabilities (0x08011a000040):
				+HTC HE Supported
				Trigger Frame MAC Padding Duration: 2
				OM Control
				Maximum A-MPDU Length Exponent: 3
				A-MSDU in A-MPDU
			HE PHY Capabilities: (0x4c70ce926d12f3164e3f00):
				HE40/HE80/5GHz
				HE160/5GHz
				242 tone RUs/5GHz
				Device Class: 1
				LDPC Coding in Payload
				HE SU PPDU with 1x HE-LTF and 0.8us GI
				NDP with 4x HE-LTF and 3.2us GI
				STBC Tx <= 80MHz
				STBC Rx <= 80MHz
				Full Bandwidth UL MU-MIMO
				Partial Bandwidth UL MU-MIMO
				DCM Max Constellation: 2
				DCM Max Constellation Rx: 2
				SU Beamformer
				SU Beamformee
				Beamformee STS <= 80Mhz: 3
				Beamformee STS > 80Mhz: 3
				Sounding Dimensions <= 80Mhz: 2
				Sounding Dimensions > 80Mhz: 2
				Codebook Size SU Feedback
				Codebook Size MU Feedback
				Triggered CQI Feedback
				Partial Bandwidth Extended Range
				Partial Bandwidth DL MU-MIMO
				PPE Threshold Present
				Power Boost Factor ar
				HE SU PPDU & HE PPDU 4x HE-LTF 0.8us GI
				Max NC: 2
				20MHz in 40MHz HE PPDU 2.4GHz
				20MHz in 160/80+80MHz HE PPDU
				80MHz in 160/80+80MHz HE PPDU
				DCM Max BW: 1
				Longer Than 16HE SIG-B OFDM Symbols
				Non-Triggered CQI Feedback
				TX 1024-QAM
				RX 1024-QAM
				RX Full BW SU Using HE MU PPDU with Compression SIGB
				RX Full BW SU Using HE MU PPDU with Non-Compression SIGB
			HE RX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE RX MCS and NSS set 160 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set 160 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			PPE Threshold 0x7a 0x1c 0xc7 0x71 0x1c 0xc7 0x71 0x1c 0xc7 0x71
		EHT Iftypes: managed
			EHT MAC Capabilities (0x8201):
				EHT OM Control Supported
			EHT PHY Capabilities: (0xe80d121e28600800):
				NDP With  EHT-LTF And 3.2 µs GI
				SU Beamformer
				SU Beamformee
				Beamformee SS (80MHz): 3
				Beamformee SS (160MHz): 3
				Number Of Sounding Dimensions (80MHz): 2
				Number Of Sounding Dimensions (160MHz): 2
				Ng = 16 SU Feedback
				Ng = 16 MU Feedback
				Codebook size (4, 2) SU Feedback
				Codebook size (7, 5) MU Feedback
				EHT MU PPDU With 4 EHT-LTF And 0.8 µs GI
				Max Nc: 2
				Common Nominal Packet Padding: 2
				Maximum Number Of Supported EHT-LTFs: 1
				Support of MCS 15: 1
			EHT MCS/NSS: (0x33333333333300000000000000):
			EHT bw <= 80 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw <= 80 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw <= 80 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
		HE Iftypes: AP
			HE MAC Capabilities (0x00051a081044):
				+HTC HE Supported
				TWT Responder
				BSR
				OM Control
				Maximum A-MPDU Length Exponent: 3
				BQR
				A-MSDU in A-MPDU
				OM Control UL MU Data Disable RX
			HE PHY Capabilities: (0x0c20ce926f12afd4000c00):
				HE40/HE80/5GHz
				HE160/5GHz
				LDPC Coding in Payload
				NDP with 4x HE-LTF and 3.2us GI
				STBC Tx <= 80MHz
				STBC Rx <= 80MHz
				Full Bandwidth UL MU-MIMO
				Partial Bandwidth UL MU-MIMO
				DCM Max Constellation: 2
				DCM Max Constellation Rx: 2
				SU Beamformer
				SU Beamformee
				MU Beamformer
				Beamformee STS <= 80Mhz: 3
				Beamformee STS > 80Mhz: 3
				Sounding Dimensions <= 80Mhz: 2
				Sounding Dimensions > 80Mhz: 2
				Codebook Size SU Feedback
				Codebook Size MU Feedback
				Triggered SU Beamforming Feedback
				Triggered MU Beamforming Feedback
				Partial Bandwidth Extended Range
				PPE Threshold Present
				HE SU PPDU & HE PPDU 4x HE-LTF 0.8us GI
				Max NC: 2
				STBC Tx > 80MHz
				STBC Rx > 80MHz
				TX 1024-QAM
				RX 1024-QAM
			HE RX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE RX MCS and NSS set 160 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set 160 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			PPE Threshold 0x7a 0x1c 0xc7 0x71 0x1c 0xc7 0x71 0x1c 0xc7 0x71
		EHT Iftypes: AP
			EHT MAC Capabilities (0xa201):
				EHT OM Control Supported
			EHT PHY Capabilities: (0xe80d127e28600836):
				NDP With  EHT-LTF And 3.2 µs GI
				SU Beamformer
				SU Beamformee
				Beamformee SS (80MHz): 3
				Beamformee SS (160MHz): 3
				Number Of Sounding Dimensions (80MHz): 2
				Number Of Sounding Dimensions (160MHz): 2
				Ng = 16 SU Feedback
				Ng = 16 MU Feedback
				Codebook size (4, 2) SU Feedback
				Codebook size (7, 5) MU Feedback
				Triggered SU Beamforming Feedback
				Triggered MU Beamforming Partial BW Feedback
				EHT MU PPDU With 4 EHT-LTF And 0.8 µs GI
				Max Nc: 2
				Common Nominal Packet Padding: 2
				Maximum Number Of Supported EHT-LTFs: 1
				Support of MCS 15: 1
				Non-OFDMA UL MU-MIMO (80MHz)
				Non-OFDMA UL MU-MIMO (160MHz)
				MU Beamformer (80MHz)
				MU Beamformer (160MHz)
			EHT MCS/NSS: (0x33333333333300000000000000):
			EHT bw <= 80 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw <= 80 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw <= 80 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
		HE Iftypes: mesh point
			HE MAC Capabilities (0x00011a000040):
				+HTC HE Supported
				OM Control
				Maximum A-MPDU Length Exponent: 3
				A-MSDU in A-MPDU
			HE PHY Capabilities: (0x0c200c0000000004008000):
				HE40/HE80/5GHz
				HE160/5GHz
				LDPC Coding in Payload
				STBC Tx <= 80MHz
				STBC Rx <= 80MHz
				HE SU PPDU & HE PPDU 4x HE-LTF 0.8us GI
			HE RX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE RX MCS and NSS set 160 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set 160 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
		EHT Iftypes: mesh point
			EHT MAC Capabilities (0x8201):
				EHT OM Control Supported
			EHT PHY Capabilities: (0xe80d121e28600800):
				NDP With  EHT-LTF And 3.2 µs GI
				SU Beamformer
				SU Beamformee
				Beamformee SS (80MHz): 3
				Beamformee SS (160MHz): 3
				Number Of Sounding Dimensions (80MHz): 2
				Number Of Sounding Dimensions (160MHz): 2
				Ng = 16 SU Feedback
				Ng = 16 MU Feedback
				Codebook size (4, 2) SU Feedback
				Codebook size (7, 5) MU Feedback
				EHT MU PPDU With 4 EHT-LTF And 0.8 µs GI
				Max Nc: 2
				Common Nominal Packet Padding: 2
				Maximum Number Of Supported EHT-LTFs: 1
				Support of MCS 15: 1
			EHT MCS/NSS: (0x33333333333300000000000000):
			EHT bw <= 80 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw <= 80 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw <= 80 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
		Bitrates (non-HT):
			* 6.0 Mbps
			* 9.0 Mbps
			* 12.0 Mbps
			* 18.0 Mbps
			* 24.0 Mbps
			* 36.0 Mbps
			* 48.0 Mbps
			* 54.0 Mbps
		Frequencies:
			* 5180.0 MHz [36] (23.0 dBm)
			* 5200.0 MHz [40] (23.0 dBm)
			* 5220.0 MHz [44] (23.0 dBm)
			* 5240.0 MHz [48] (23.0 dBm)
			* 5260.0 MHz [52] (24.0 dBm) (radar detection)
			* 5280.0 MHz [56] (24.0 dBm) (radar detection)
			* 5300.0 MHz [60] (24.0 dBm) (radar detection)
			* 5320.0 MHz [64] (24.0 dBm) (radar detection)
			* 5340.0 MHz [68] (24.0 dBm) (radar detection)
			* 5360.0 MHz [72] (disabled)
			* 5380.0 MHz [76] (disabled)
			* 5400.0 MHz [80] (disabled)
			* 5420.0 MHz [84] (disabled)
			* 5440.0 MHz [88] (disabled)
			* 5460.0 MHz [92] (disabled)
			* 5480.0 MHz [96] (24.0 dBm) (radar detection)
			* 5500.0 MHz [100] (24.0 dBm) (radar detection)
			* 5520.0 MHz [104] (24.0 dBm) (radar detection)
			* 5540.0 MHz [108] (24.0 dBm) (radar detection)
			* 5560.0 MHz [112] (24.0 dBm) (radar detection)
			* 5580.0 MHz [116] (24.0 dBm) (radar detection)
			* 5600.0 MHz [120] (24.0 dBm) (radar detection)
			* 5620.0 MHz [124] (24.0 dBm) (radar detection)
			* 5640.0 MHz [128] (24.0 dBm) (radar detection)
			* 5660.0 MHz [132] (24.0 dBm) (radar detection)
			* 5680.0 MHz [136] (24.0 dBm) (radar detection)
			* 5700.0 MHz [140] (24.0 dBm) (radar detection)
			* 5720.0 MHz [144] (24.0 dBm) (radar detection)
			* 5745.0 MHz [149] (26.0 dBm)
			* 5765.0 MHz [153] (26.0 dBm)
			* 5785.0 MHz [157] (26.0 dBm)
			* 5805.0 MHz [161] (26.0 dBm)
			* 5825.0 MHz [165] (26.0 dBm)
			* 5845.0 MHz [169] (26.0 dBm)
			* 5865.0 MHz [173] (26.0 dBm)
			* 5885.0 MHz [177] (26.0 dBm)
	Band 4:
		HE Iftypes: managed
			HE MAC Capabilities (0x08011a000040):
				+HTC HE Supported
				Trigger Frame MAC Padding Duration: 2
				OM Control
				Maximum A-MPDU Length Exponent: 3
				A-MSDU in A-MPDU
			HE PHY Capabilities: (0x4c70ce926d12f3164e3f00):
				HE40/HE80/5GHz
				HE160/5GHz
				242 tone RUs/5GHz
				Device Class: 1
				LDPC Coding in Payload
				HE SU PPDU with 1x HE-LTF and 0.8us GI
				NDP with 4x HE-LTF and 3.2us GI
				STBC Tx <= 80MHz
				STBC Rx <= 80MHz
				Full Bandwidth UL MU-MIMO
				Partial Bandwidth UL MU-MIMO
				DCM Max Constellation: 2
				DCM Max Constellation Rx: 2
				SU Beamformer
				SU Beamformee
				Beamformee STS <= 80Mhz: 3
				Beamformee STS > 80Mhz: 3
				Sounding Dimensions <= 80Mhz: 2
				Sounding Dimensions > 80Mhz: 2
				Codebook Size SU Feedback
				Codebook Size MU Feedback
				Triggered CQI Feedback
				Partial Bandwidth Extended Range
				Partial Bandwidth DL MU-MIMO
				PPE Threshold Present
				Power Boost Factor ar
				HE SU PPDU & HE PPDU 4x HE-LTF 0.8us GI
				Max NC: 2
				20MHz in 40MHz HE PPDU 2.4GHz
				20MHz in 160/80+80MHz HE PPDU
				80MHz in 160/80+80MHz HE PPDU
				DCM Max BW: 1
				Longer Than 16HE SIG-B OFDM Symbols
				Non-Triggered CQI Feedback
				TX 1024-QAM
				RX 1024-QAM
				RX Full BW SU Using HE MU PPDU with Compression SIGB
				RX Full BW SU Using HE MU PPDU with Non-Compression SIGB
			HE RX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE RX MCS and NSS set 160 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set 160 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			PPE Threshold 0x7a 0x1c 0xc7 0x71 0x1c 0xc7 0x71 0x1c 0xc7 0x71
		EHT Iftypes: managed
			EHT MAC Capabilities (0x8201):
				EHT OM Control Supported
			EHT PHY Capabilities: (0xea6d921e28600800):
				320MHz in 6GHz Supported
				NDP With  EHT-LTF And 3.2 µs GI
				SU Beamformer
				SU Beamformee
				Beamformee SS (80MHz): 3
				Beamformee SS (160MHz): 3
				Beamformee SS (320MHz): 3
				Number Of Sounding Dimensions (80MHz): 2
				Number Of Sounding Dimensions (160MHz): 2
				Number Of Sounding Dimensions (320MHz): 2
				Ng = 16 SU Feedback
				Ng = 16 MU Feedback
				Codebook size (4, 2) SU Feedback
				Codebook size (7, 5) MU Feedback
				EHT MU PPDU With 4 EHT-LTF And 0.8 µs GI
				Max Nc: 2
				Common Nominal Packet Padding: 2
				Maximum Number Of Supported EHT-LTFs: 1
				Support of MCS 15: 1
			EHT MCS/NSS: (0x33333333333333333300000000):
			EHT bw <= 80 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw <= 80 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw <= 80 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
			EHT bw=320 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw=320 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw=320 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
		HE Iftypes: AP
			HE MAC Capabilities (0x00051a081044):
				+HTC HE Supported
				TWT Responder
				BSR
				OM Control
				Maximum A-MPDU Length Exponent: 3
				BQR
				A-MSDU in A-MPDU
				OM Control UL MU Data Disable RX
			HE PHY Capabilities: (0x0c20ce926f12afd4000c00):
				HE40/HE80/5GHz
				HE160/5GHz
				LDPC Coding in Payload
				NDP with 4x HE-LTF and 3.2us GI
				STBC Tx <= 80MHz
				STBC Rx <= 80MHz
				Full Bandwidth UL MU-MIMO
				Partial Bandwidth UL MU-MIMO
				DCM Max Constellation: 2
				DCM Max Constellation Rx: 2
				SU Beamformer
				SU Beamformee
				MU Beamformer
				Beamformee STS <= 80Mhz: 3
				Beamformee STS > 80Mhz: 3
				Sounding Dimensions <= 80Mhz: 2
				Sounding Dimensions > 80Mhz: 2
				Codebook Size SU Feedback
				Codebook Size MU Feedback
				Triggered SU Beamforming Feedback
				Triggered MU Beamforming Feedback
				Partial Bandwidth Extended Range
				PPE Threshold Present
				HE SU PPDU & HE PPDU 4x HE-LTF 0.8us GI
				Max NC: 2
				STBC Tx > 80MHz
				STBC Rx > 80MHz
				TX 1024-QAM
				RX 1024-QAM
			HE RX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE RX MCS and NSS set 160 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set 160 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			PPE Threshold 0x7a 0x1c 0xc7 0x71 0x1c 0xc7 0x71 0x1c 0xc7 0x71
		EHT Iftypes: AP
			EHT MAC Capabilities (0xa201):
				EHT OM Control Supported
			EHT PHY Capabilities: (0xea6d927e2860087e):
				320MHz in 6GHz Supported
				NDP With  EHT-LTF And 3.2 µs GI
				SU Beamformer
				SU Beamformee
				Beamformee SS (80MHz): 3
				Beamformee SS (160MHz): 3
				Beamformee SS (320MHz): 3
				Number Of Sounding Dimensions (80MHz): 2
				Number Of Sounding Dimensions (160MHz): 2
				Number Of Sounding Dimensions (320MHz): 2
				Ng = 16 SU Feedback
				Ng = 16 MU Feedback
				Codebook size (4, 2) SU Feedback
				Codebook size (7, 5) MU Feedback
				Triggered SU Beamforming Feedback
				Triggered MU Beamforming Partial BW Feedback
				EHT MU PPDU With 4 EHT-LTF And 0.8 µs GI
				Max Nc: 2
				Common Nominal Packet Padding: 2
				Maximum Number Of Supported EHT-LTFs: 1
				Support of MCS 15: 1
				Non-OFDMA UL MU-MIMO (80MHz)
				Non-OFDMA UL MU-MIMO (160MHz)
				Non-OFDMA UL MU-MIMO (320MHz)
				MU Beamformer (80MHz)
				MU Beamformer (160MHz)
				MU Beamformer (320MHz)
			EHT MCS/NSS: (0x33333333333333333300000000):
			EHT bw <= 80 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw <= 80 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw <= 80 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
			EHT bw=320 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw=320 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw=320 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
		HE Iftypes: mesh point
			HE MAC Capabilities (0x00011a000040):
				+HTC HE Supported
				OM Control
				Maximum A-MPDU Length Exponent: 3
				A-MSDU in A-MPDU
			HE PHY Capabilities: (0x0c200c0000000004008000):
				HE40/HE80/5GHz
				HE160/5GHz
				LDPC Coding in Payload
				STBC Tx <= 80MHz
				STBC Rx <= 80MHz
				HE SU PPDU & HE PPDU 4x HE-LTF 0.8us GI
			HE RX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set <= 80 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE RX MCS and NSS set 160 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
			HE TX MCS and NSS set 160 MHz
				1 streams: MCS 0-11
				2 streams: MCS 0-11
				3 streams: MCS 0-11
				4 streams: not supported
				5 streams: not supported
				6 streams: not supported
				7 streams: not supported
				8 streams: not supported
		EHT Iftypes: mesh point
			EHT MAC Capabilities (0x8201):
				EHT OM Control Supported
			EHT PHY Capabilities: (0xea6d921e28600800):
				320MHz in 6GHz Supported
				NDP With  EHT-LTF And 3.2 µs GI
				SU Beamformer
				SU Beamformee
				Beamformee SS (80MHz): 3
				Beamformee SS (160MHz): 3
				Beamformee SS (320MHz): 3
				Number Of Sounding Dimensions (80MHz): 2
				Number Of Sounding Dimensions (160MHz): 2
				Number Of Sounding Dimensions (320MHz): 2
				Ng = 16 SU Feedback
				Ng = 16 MU Feedback
				Codebook size (4, 2) SU Feedback
				Codebook size (7, 5) MU Feedback
				EHT MU PPDU With 4 EHT-LTF And 0.8 µs GI
				Max Nc: 2
				Common Nominal Packet Padding: 2
				Maximum Number Of Supported EHT-LTFs: 1
				Support of MCS 15: 1
			EHT MCS/NSS: (0x33333333333333333300000000):
			EHT bw <= 80 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw <= 80 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw <= 80 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw=160 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
			EHT bw=320 MHz, max NSS for MCS 8-9: Rx=3, Tx=3
			EHT bw=320 MHz, max NSS for MCS 10-11: Rx=3, Tx=3
			EHT bw=320 MHz, max NSS for MCS 12-13: Rx=3, Tx=3
		Bitrates (non-HT):
			* 6.0 Mbps
			* 9.0 Mbps
			* 12.0 Mbps
			* 18.0 Mbps
			* 24.0 Mbps
			* 36.0 Mbps
			* 48.0 Mbps
			* 54.0 Mbps
		Frequencies:
			* 5955.0 MHz [1] (12.0 dBm)
			* 5975.0 MHz [5] (12.0 dBm)
			* 5995.0 MHz [9] (12.0 dBm)
			* 6015.0 MHz [13] (12.0 dBm)
			* 6035.0 MHz [17] (12.0 dBm)
			* 6055.0 MHz [21] (12.0 dBm)
			* 6075.0 MHz [25] (12.0 dBm)
			* 6095.0 MHz [29] (12.0 dBm)
			* 6115.0 MHz [33] (12.0 dBm)
			* 6135.0 MHz [37] (12.0 dBm)
			* 6155.0 MHz [41] (12.0 dBm)
			* 6175.0 MHz [45] (12.0 dBm)
			* 6195.0 MHz [49] (12.0 dBm)
			* 6215.0 MHz [53] (12.0 dBm)
			* 6235.0 MHz [57] (12.0 dBm)
			* 6255.0 MHz [61] (12.0 dBm)
			* 6275.0 MHz [65] (12.0 dBm)
			* 6295.0 MHz [69] (12.0 dBm)
			* 6315.0 MHz [73] (12.0 dBm)
			* 6335.0 MHz [77] (12.0 dBm)
			* 6355.0 MHz [81] (12.0 dBm)
			* 6375.0 MHz [85] (12.0 dBm)
			* 6395.0 MHz [89] (12.0 dBm)
			* 6415.0 MHz [93] (12.0 dBm)
			* 6435.0 MHz [97] (12.0 dBm)
			* 6455.0 MHz [101] (12.0 dBm)
			* 6475.0 MHz [105] (12.0 dBm)
			* 6495.0 MHz [109] (12.0 dBm)
			* 6515.0 MHz [113] (12.0 dBm)
			* 6535.0 MHz [117] (12.0 dBm)
			* 6555.0 MHz [121] (12.0 dBm)
			* 6575.0 MHz [125] (12.0 dBm)
			* 6595.0 MHz [129] (12.0 dBm)
			* 6615.0 MHz [133] (12.0 dBm)
			* 6635.0 MHz [137] (12.0 dBm)
			* 6655.0 MHz [141] (12.0 dBm)
			* 6675.0 MHz [145] (12.0 dBm)
			* 6695.0 MHz [149] (12.0 dBm)
			* 6715.0 MHz [153] (12.0 dBm)
			* 6735.0 MHz [157] (12.0 dBm)
			* 6755.0 MHz [161] (12.0 dBm)
			* 6775.0 MHz [165] (12.0 dBm)
			* 6795.0 MHz [169] (12.0 dBm)
			* 6815.0 MHz [173] (12.0 dBm)
			* 6835.0 MHz [177] (12.0 dBm)
			* 6855.0 MHz [181] (12.0 dBm)
			* 6875.0 MHz [185] (12.0 dBm)
			* 6895.0 MHz [189] (12.0 dBm)
			* 6915.0 MHz [193] (12.0 dBm)
			* 6935.0 MHz [197] (12.0 dBm)
			* 6955.0 MHz [201] (12.0 dBm)
			* 6975.0 MHz [205] (12.0 dBm)
			* 6995.0 MHz [209] (12.0 dBm)
			* 7015.0 MHz [213] (12.0 dBm)
			* 7035.0 MHz [217] (12.0 dBm)
			* 7055.0 MHz [221] (12.0 dBm)
			* 7075.0 MHz [225] (12.0 dBm)
			* 7095.0 MHz [229] (12.0 dBm)
			* 7115.0 MHz [233] (12.0 dBm)
	Supported commands:
		 * new_interface
		 * set_interface
		 * new_key
		 * start_ap
		 * new_station
		 * new_mpath
		 * set_mesh_config
		 * set_bss
		 * authenticate
		 * associate
		 * deauthenticate
		 * disassociate
		 * join_ibss
		 * join_mesh
		 * remain_on_channel
		 * set_tx_bitrate_mask
		 * frame
		 * frame_wait_cancel
		 * set_wiphy_netns
		 * set_channel
		 * tdls_mgmt
		 * tdls_oper
		 * probe_client
		 * set_noack_map
		 * register_beacons
		 * start_p2p_device
		 * set_mcast_rate
		 * testmode
		 * connect
		 * disconnect
		 * channel_switch
		 * set_qos_map
		 * set_multicast_to_unicast
		 * set_sar_specs
	software interface modes (can always be added):
		 * AP/VLAN
		 * monitor
	valid interface combinations:
		 * #{ AP, mesh point } <= 16, #{ managed } <= 19,
		   total <= 19, #channels <= 1, STA/AP BI must match, radar detect widths: { 20 MHz (no HT), 20 MHz, 40 MHz, 80 MHz, 160 MHz }

	HT Capability overrides:
		 * MCS: ff ff ff ff ff ff ff ff ff ff
		 * maximum A-MSDU length
		 * supported channel width
		 * short GI for 40 MHz
		 * max A-MPDU length exponent
		 * min MPDU start spacing
	Device supports TX status socket option.
	Device supports HT-IBSS.
	Device supports SAE with AUTHENTICATE command
	Device supports scan flush.
	Device supports per-vif TX power setting
	Driver supports full state transitions for AP/GO clients
	Driver supports a userspace MPM
	Device supports active monitor (which will ACK incoming frames)
	Driver/device bandwidth changes during BSS lifetime (AP/GO mode)
	Device supports configuring vdev MAC-addr on create.
	max # scan plans: 1
	max scan plan interval: -1
	max scan plan iterations: 0
	Supported TX frame types:
		 * IBSS: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
		 * managed: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
		 * AP: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
		 * AP/VLAN: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
		 * mesh point: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
		 * P2P-client: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
		 * P2P-GO: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
		 * P2P-device: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
	Supported RX frame types:
		 * IBSS: 0x40 0xb0 0xc0 0xd0
		 * managed: 0x40 0xb0 0xd0
		 * AP: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
		 * AP/VLAN: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
		 * mesh point: 0xb0 0xc0 0xd0
		 * P2P-client: 0x40 0xd0
		 * P2P-GO: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
		 * P2P-device: 0x40 0xd0
	Supported extended features:
		* [ VHT_IBSS ]: VHT-IBSS
		* [ RRM ]: RRM
		* [ MU_MIMO_AIR_SNIFFER ]: MU-MIMO sniffer
		* [ BEACON_RATE_LEGACY ]: legacy beacon rate setting
		* [ BEACON_RATE_HT ]: HT beacon rate setting
		* [ BEACON_RATE_VHT ]: VHT beacon rate setting
		* [ FILS_STA ]: STA FILS (Fast Initial Link Setup)
		* [ CQM_RSSI_LIST ]: multiple CQM_RSSI_THOLD records
		* [ CONTROL_PORT_OVER_NL80211 ]: control port over nl80211
		* [ ACK_SIGNAL_SUPPORT ]: ack signal level support
		* [ TXQS ]: FQ-CoDel-enabled intermediate TXQs
		* [ CAN_REPLACE_PTK0 ]: can safely replace PTK 0 when rekeying
		* [ AIRTIME_FAIRNESS ]: airtime fairness scheduling
		* [ AQL ]: Airtime Queue Limits (AQL)
		* [ BEACON_PROTECTION ]: beacon protection support
		* [ CONTROL_PORT_NO_PREAUTH ]: disable pre-auth over nl80211 control port support
		* [ DEL_IBSS_STA ]: deletion of IBSS station support
		* [ SCAN_FREQ_KHZ ]: scan on kHz frequency support
		* [ CONTROL_PORT_OVER_NL80211_TX_STATUS ]: tx status for nl80211 control port support
		* [ OPERATING_CHANNEL_VALIDATION ]: Operating Channel Validation (OCV) support
		* [ FILS_DISCOVERY ]: FILS discovery frame transmission support
		* [ UNSOL_BCAST_PROBE_RESP ]: unsolicated broadcast probe response transmission support
		* [ BEACON_RATE_HE ]: HE beacon rate support (AP/mesh)
		* [ BSS_COLOR ]: BSS coloring support
		* [ POWERED_ADDR_CHANGE ]: can change MAC address while up
		* [ PUNCT ]: preamble puncturing in AP mode
	Supported wiphy radios:
		* Idx 0:
			antenna_mask: 0x00000003
			Frequency Range: 2400 MHz - 2500 MHz
			Radio's valid interface combinations:
				 * #{ AP, mesh point } <= 16, #{ managed } <= 19,
				   total <= 19, #channels <= 1, STA/AP BI must match, radar detect widths: { 20 MHz (no HT), 20 MHz, 40 MHz, 80 MHz, 160 MHz }

		* Idx 1:
			antenna_mask: 0x0000001c
			Frequency Range: 5000 MHz - 5900 MHz
			Radio's valid interface combinations:
				 * #{ AP, mesh point } <= 16, #{ managed } <= 19,
				   total <= 19, #channels <= 1, STA/AP BI must match, radar detect widths: { 20 MHz (no HT), 20 MHz, 40 MHz, 80 MHz, 160 MHz }

		* Idx 2:
			antenna_mask: 0x000000e0
			Frequency Range: 5925 MHz - 7200 MHz
			Radio's valid interface combinations:
				 * #{ AP, mesh point } <= 16, #{ managed } <= 19,
				   total <= 19, #channels <= 1, STA/AP BI must match, radar detect widths: { 20 MHz (no HT), 20 MHz, 40 MHz, 80 MHz, 160 MHz }

	Globally valid interface combinations:
		 * #{ IBSS, managed, AP, mesh point } <= 57,
		   total <= 57, #channels <= 3, radar detect widths: { 20 MHz (no HT), 20 MHz, 40 MHz, 80 MHz, 160 MHz }

Wireshark Capture, filtered by the address of the station:

wlan.addr == 4A:2C:CC:42:5F:F8

The station performs scans before sending VS action frames which is the only traffic visible.

station_packets.pcapng.gz

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing off-channel management transmission with the documented iw commands and compare the rdev_mgmt_tx and remain-on-channel ftrace events with a monitor-mode capture. Investigate the mt7996 off-channel action-frame path; done means supported frequencies transmit frames that are observable by the recipient and unsupported or failed transmissions report accurately.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, linux
Domain
networking, operating-systems
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.