[BUG] wifi: mt76: mt7925: hw_scan drops common_ies, P2P probe requests lack P2P/WPS/WFD IEs (regression since v6.16)

Sven Besser sven.besser at sql-ag.de
Wed Oct 7 02:08:00 PDT 2026


Hi,

since commit 9f8f4a51f3c1 ("wifi: mt76: mt7925: fix incorrect scan probe
IE handling for hw_scan", v6.16), Wi-Fi Direct device discovery with
mt7925 no longer finds P2P devices that are in Listen state (e.g.
Miracast sinks). As far as I can tell, the P2P probe requests are sent
without the P2P, WPS and WFD IEs that wpa_supplicant supplies, so
compliant P2P devices do not answer them.

Cause (from the source)
-----------------------
mt7925_mcu_build_scan_ie_tlv() only copies scan_ies->ies[band] into the
UNI_SCAN_IE TLVs. It never uses scan_ies->common_ies.

mac80211 (ieee80211_put_preq_ies(), net/mac80211/util.c) only moves the
user IEs listed in the before_extrates/before_ht/before_vht/before_he
arrays into the per-band part. All remaining user IEs, which includes
every vendor-specific IE (WPS 00:50:f2:04, P2P 50:6f:9a:09,
WFD 50:6f:9a:0a), go into common_ies ("add any remaining custom IEs").

Before 9f8f4a51f3c1 (v6.15), mt7925_mcu_hw_scan() and
mt7925_mcu_sched_scan_req() copied sreq->ie, i.e. the complete user IEs.
mt7921 (mt76_connac_mcu_hw_scan()) still does that. In v7.0 and in
current master, mt7925 drops common_ies in both hw_scan and sched_scan.

Observed behaviour
------------------
Hardware: Lenovo ThinkPad T14 Gen 7 AMD, MEDIATEK MT7925 [14c3:7925]
          (mt7925e), firmware build 20260605184651a / WM 20260605184805
Software: Ubuntu 26.04.1, kernel 7.0.0-38-generic, wpa_supplicant 2.11,
          NetworkManager 1.54.3, gnome-network-displays 0.99.0
Sink:     Microsoft Wireless Display Adapter, model 1733, firmware
          2.0.8442 (found immediately by Windows and by an Android phone)

1. The P2P search itself runs. "iw event" during p2p_find shows the
   expected pattern on the P2P device wdev:
     scan finished: 2412 2437 2462, "DIRECT-"
     remain on freq 2437 (102-307ms)
   repeating, plus the initial full 2.4/5 GHz sweep.

2. No Listen-state device ever answers. wpa_supplicant reports no
   P2P-DEVICE-FOUND for the sink, with the station connected (channel 9)
   or disconnected, with default ("start_with_full") and "progressive"
   discovery, and with WFD IEs set early via the D-Bus WFDIEs property.

3. Devices that search themselves are still found: an Android phone in
   its Wi-Fi Direct screen shows up as P2P-DEVICE-FOUND, because this
   laptop receives the phone's own P2P probe requests while it is in
   Listen state. That matches the theory that only our *transmitted*
   probe requests are affected.

4. Monitor-mode captures (second vif on the same phy, radiotap,
   filter on probe request/response and action frames):

   a) Laptop silent, monitor hopping 1/6/11, phone searching for 75 s:
      - phone P2P probe requests on 2412/2437/2462 (42/46/42 frames),
        SSID "DIRECT-", with P2P IE (capability, listen channel),
        WPS IE (request type, device type, name), WFD IE
        (00 0006 0010 1c44 0032) and HT/VHT/HE capabilities
      - sink probe responses on 2462 to the phone: 45 frames
        (P2P IE with device info, WPS IE, WFD IE)

   b) Laptop running a normal 60 s P2P find (station associated on
      2452), monitor on the same phy:
      - probe responses and action frames addressed to the laptop's
        station address (from APs, responses to station scans)
      - zero frames addressed to the laptop's P2P device address,
        on any channel; no frame from the sink at all

   Limitation: the monitor vif does not show this radio's own
   transmissions, so I could not capture the laptop's P2P probe request
   itself. A capture with an external sniffer should confirm quickly
   whether the P2P/WPS/WFD IEs are missing.

Suggested fix direction (UNTESTED, not compile-tested)
------------------------------------------------------
Append common_ies to each per-band IE TLV, so that the firmware gets the
complete IE set again. The buffer sizing (MT76_CONNAC_SCAN_IE_LEN for
all bands together) may need adjusting once common_ies is duplicated per
band; you will know better whether the firmware expects a separate TLV
instead.

--- a/drivers/net/wireless/mediatek/mt76/mt7925/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/mcu.c
@@ -2904,7 +2904,7 @@
 	enum nl80211_band i;
 	struct tlv *tlv;
 	const u8 *ies;
-	u16 ies_len;
+	u16 ies_len, total_len;

 	for (i = 0; i <= NL80211_BAND_6GHZ; i++) {
 		if (i == NL80211_BAND_60GHZ)
@@ -2916,15 +2916,23 @@
 		if (!ies || !ies_len)
 			continue;

-		if (ies_len > max_len)
+		/* common_ies carries the remaining user IEs (e.g. the P2P,
+		 * WPS and WFD IEs added by wpa_supplicant); append them to
+		 * every band, otherwise P2P probe requests lack the P2P IE.
+		 */
+		total_len = ies_len + scan_ies->common_ie_len;
+		if (total_len > max_len)
 			return;

 		tlv = mt76_connac_mcu_add_tlv(skb, UNI_SCAN_IE,
-					      sizeof(*ie) + ies_len);
+					      sizeof(*ie) + total_len);
 		ie = (struct scan_ie_tlv *)tlv;

 		memcpy(ie->ies, ies, ies_len);
-		ie->ies_len = cpu_to_le16(ies_len);
+		if (scan_ies->common_ie_len)
+			memcpy(ie->ies + ies_len, scan_ies->common_ies,
+			       scan_ies->common_ie_len);
+		ie->ies_len = cpu_to_le16(total_len);

 		switch (i) {
 		case NL80211_BAND_2GHZ:
@@ -2938,7 +2946,7 @@
 			break;
 		}

-		max_len -= (sizeof(*ie) + ies_len);
+		max_len -= (sizeof(*ie) + total_len);
 	}
 }

I can test a fix once it is available in a (signed) Ubuntu kernel, and
can provide the captures on request.

Thanks in advance and

-- 
Kind regards

Sven Besser
Head of IT and Operations


SQL Projekt AG
Franklin Road 25 a
01069 Dresden - GERMANY

Fone:	+49 351 87619-0
Fax:	+49 351 87619-99
eMail:	sven.besser at sql-ag.de
Web:	www.sql-ag.de 
--------------------------
Aufsichtsratsvorsitzender: Jürgen Bittner
Vorstand: Jens Gärtner (Sprecher), Stefan Ehrlich
Handelsregister: HRB 38924 Amtsgericht Dresden

This e-mail may contain confidential and/or privileged information.
If you are not the intended recipient (or have received this e-mail in error) please notify the sender immediately and destroy this e-mail. Any unauthorized copying, disclosure or distribution oft he material in this e-mail is strictly forbidden.



--

Mit freundlichen Grüßen
 
Sven Besser
Head of IT and Operations
 
 
SQL Projekt AG
Franklinstraße 25 a
01069 Dresden
 
Telefon:  +49 351 87619-0
Fax:        +49 351 87619-99
eMail:     sven.besser at sql-ag.de
Web:      www.sql-ag.de

--------------------------
Aufsichtsratsvorsitzender: Jürgen Bittner
Vorstand: Jens Gärtner (Sprecher), Stefan Ehrlich
Handelsregister: HRB 38924 Amtsgericht Dresden
 
 
 
Die Zertifizierungsstelle der TÜV SÜD Management Service GmbH bescheinigt, dass die SQL Projekt AG für den Geltungsbereich "Entwicklung

und Vertrieb von Datenbank- und Integrationslösungen sowie Beratung, Training und Support auf dem Gebiet datenbankgestützter

Softwareprodukte" ein Qualitätsmanagementsystem eingeführt hat und anwendet.
 
 
Diese E-Mail enthält vertrauliche und/oder rechtlich geschützte Informationen.

Wenn Sie nicht der richtige Adressat sind oder diese E-Mail irrtümlich erhalten haben, informieren Sie bitte sofort den Absender und vernichten Sie diese Mail. Das unerlaubte
 Kopieren sowie die unbefugte Weitergabe dieser Mail oder Inhalte ist nicht gestattet.

 


More information about the Linux-mediatek mailing list