aircrack-ng / rtl8814au

Realtek rtl8814au driver
Other
425 stars 130 forks source link

Possible rtl8814au driver sniffing bug. #43

Open terrysimons opened 3 years ago

terrysimons commented 3 years ago

It looks like there's a driver bug in the rtl8814au driver related to the chip switching channels, and then coming back to the original channel. It seems to be the case that wpa_supplicant is possibly causing the channel switching, as I can't reproduce the problem with wpa_supplicant removed from the system, but the real issue is that the driver starts losing certain types of frames once it re-settles back to its original sniffing channel.

When sniffing, I noticed that initially, data frames would be coming in, but then after a while (~1-2 minutes) I no longer see data frames. I thought at first that it was possibly a bug where data frames were getting dropped, but it looks like the radio is changing channels on me and then switching back, and when it switches back I only see Action frames, Probe Requests, and a few other types of management frames.

I can consistently reproduce this, and once the driver gets in this state, any subsequent tcpdump (or wireshark) sniff attempts fail to produce data frames (and possibly others?)

I thought I had disabled wpa_supplicant with /etc/dhcpcd.conf using:

interface wlan1
  nohook wpa_supplicant

But at least on Ubuntu 20.10 it seems like removing wpa_supplicant with sudo dpkg -r --force-depends wpasupplicant is necessary, so I'll have to play with this a bit and see if there's a different way to do per-interface disablement of wpa_supplicant on Ubuntu 20.10.

Any idea what might be causing the driver/wpa_supplicant to go do some scans on other channels and come back? Is there a way to disable this behavior?

I'm running Ubuntu 20.10 64-bit on a Raspberry Pi 4 8GB configuration.

This is 100% reproducible for me on Ubuntu 20.10 64-bit using commit hash:

commit 27d2344264f774dd2add19d4139dfc07985d6ada (HEAD -> v5.8.5.1, origin/v5.8.5.1, origin/HEAD)

I'm building the driver with:

$ sudo apt install aircrack-ng bc build-essential dkms git tcpdump

$ sed -i 's/CONFIG_PLATFORM_I386_PC = y/CONFIG_PLATFORM_I386_PC = n/g' Makefile

$ sed -i 's/CONFIG_PLATFORM_ARM64 = n/CONFIG_PLATFORM_ARM64 = y/g' Makefile

As mentioned above, removing wpa_supplicant from the system seems to fix this, but the sniffing behavior seems like a bug in the driver to me, which just happens to be tickled by whatever wpa_supplicant is doing.

Here's an example of me sniffing along merrily on freq 5785 @ 80MHz, with data frames coming in, and then the radio does some sort of hopscotch around on some other channels, and then comes back to 5785, but now I'm no longer receiving data frames.

Notice how at 15:28:16.763574, the radio jumps over to 2412 MHz, then a bunch of other 2.4Ghz channels, then a bunch of other 5GHz channels before landing on 5785 again, but when it comes back to 5785, I'm no longer seeing data frames.

5:28:16.679125 6.0 Mb/s 5785 MHz 11a -75dBm signal antenna 0 Beacon (Gigashit) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 149, PRIVACY
15:28:16.679717 5785 MHz -42dBm signal antenna 0 User 2 MCS 8 BCC FEC 80 MHz long GI Data IV:92a7 Pad 20 KeyID 0
15:28:16.679730 5785 MHz 0dBm signal antenna 0 User 2 MCS 8 BCC FEC 20 MHz long GI Data IV:92a8 Pad 20 KeyID 0
15:28:16.680661 5785 MHz -39dBm signal antenna 0 User 2 MCS 9 BCC FEC 80 MHz long GI Data IV:b944 Pad 20 KeyID 0
15:28:16.681943 5785 MHz -42dBm signal antenna 0 User 2 MCS 8 BCC FEC 80 MHz long GI Data IV:92a9 Pad 20 KeyID 0
15:28:16.683060 5785 MHz -39dBm signal antenna 0 User 2 MCS 9 BCC FEC 80 MHz long GI Data IV:b945 Pad 20 KeyID 0
15:28:16.687457 5785 MHz -42dBm signal antenna 0 User 2 MCS 8 BCC FEC 80 MHz long GI Data IV:92aa Pad 20 KeyID 0
15:28:16.689466 5785 MHz -39dBm signal antenna 0 User 2 MCS 9 BCC FEC 80 MHz long GI Data IV:b946 Pad 20 KeyID 0
15:28:16.691558 5785 MHz -43dBm signal antenna 0 User 2 MCS 8 BCC FEC 80 MHz long GI Data IV:92ab Pad 20 KeyID 0
15:28:16.692333 5785 MHz -39dBm signal antenna 0 User 2 MCS 9 BCC FEC 80 MHz long GI Data IV:b947 Pad 20 KeyID 0
15:28:16.697966 5785 MHz -42dBm signal antenna 0 User 2 MCS 8 BCC FEC 80 MHz long GI Data IV:92ac Pad 20 KeyID 0
15:28:16.697979 5785 MHz -43dBm signal antenna 0 User 2 MCS 8 BCC FEC 80 MHz long GI Data IV:92ad Pad 20 KeyID 0
15:28:16.698683 5785 MHz -39dBm signal antenna 0 User 2 MCS 9 BCC FEC 80 MHz long GI Data IV:b948 Pad 20 KeyID 0
15:28:16.699201 5785 MHz -39dBm signal antenna 0 User 2 MCS 9 BCC FEC 80 MHz long GI Data IV:b949 Pad 20 KeyID 0
15:28:16.702964 5785 MHz 11n -66dBm signal antenna 0 58.5 Mb/s MCS 6 20 MHz long GI RX-STBC0 Data IV:7656 Pad 20 KeyID 0
15:28:16.705452 5785 MHz -42dBm signal antenna 0 User 2 MCS 8 BCC FEC 80 MHz long GI Data IV:92ae Pad 20 KeyID 0
15:28:16.706260 5785 MHz -39dBm signal antenna 0 User 2 MCS 9 BCC FEC 80 MHz long GI Data IV:b94a Pad 20 KeyID 0
15:28:16.715009 5785 MHz -42dBm signal antenna 0 User 2 MCS 8 BCC FEC 80 MHz long GI Data IV:92af Pad 20 KeyID 0
15:28:16.715807 5785 MHz -39dBm signal antenna 0 User 2 MCS 9 BCC FEC 80 MHz long GI Data IV:b94b Pad 20 KeyID 0
15:28:16.725687 5785 MHz -42dBm signal antenna 0 User 2 MCS 8 BCC FEC 80 MHz long GI Data IV:92b0 Pad 20 KeyID 0
15:28:16.726761 5785 MHz -39dBm signal antenna 0 User 2 MCS 9 BCC FEC 80 MHz long GI Data IV:b94c Pad 20 KeyID 0
15:28:16.730196 5785 MHz -42dBm signal antenna 0 User 2 MCS 8 BCC FEC 80 MHz long GI Data IV:92b1 Pad 20 KeyID 0
15:28:16.735051 5785 MHz -43dBm signal antenna 0 User 2 MCS 8 BCC FEC 80 MHz long GI Data IV:92b2 Pad 20 KeyID 0
15:28:16.735917 5785 MHz -39dBm signal antenna 0 User 2 MCS 9 BCC FEC 80 MHz long GI Data IV:b94d Pad 20 KeyID 0
15:28:16.738568 5785 MHz -39dBm signal antenna 0 User 2 MCS 9 BCC FEC 80 MHz long GI Data IV:b94e Pad 20 KeyID 0
15:28:16.742061 5785 MHz -42dBm signal antenna 0 User 2 MCS 8 BCC FEC 80 MHz long GI Data IV:92b3 Pad 20 KeyID 0
15:28:16.743024 5785 MHz -39dBm signal antenna 0 User 2 MCS 9 BCC FEC 80 MHz long GI Data IV:b94f Pad 20 KeyID 0
15:28:16.763574 11.0 Mb/s 2412 MHz 11b -33dBm signal antenna 0 Probe Response (Licorice Snap) [1.0* 2.0* 5.5* 11.0* 6.0 9.0 12.0 18.0 Mbit] CH: 1, PRIVACY
15:28:16.767402 11.0 Mb/s 2412 MHz 11b -33dBm signal antenna 0 Beacon () [1.0* 2.0* 5.5* 11.0* 6.0* 9.0 12.0* 18.0 Mbit] IBSS CH: 1, PRIVACY
15:28:16.767784 11.0 Mb/s 2412 MHz 11b -33dBm signal antenna 0 Beacon () [1.0* 2.0* 5.5* 11.0* 6.0 9.0 12.0 18.0 Mbit] ESS CH: 1
15:28:16.768197 11.0 Mb/s 2412 MHz 11b -33dBm signal antenna 0 Beacon (Licorice Snap) [1.0* 2.0* 5.5* 11.0* 6.0 9.0 12.0 18.0 Mbit] ESS CH: 1, PRIVACY
15:28:17.228825 1.0 Mb/s 2432 MHz 11b -50dBm signal antenna 0 Beacon (HAE_Wireless) [1.0* 2.0* 5.5 11.0 18.0 24.0 36.0 54.0 Mbit] ESS CH: 6, PRIVACY
15:28:17.321150 1.0 Mb/s 2437 MHz 11b -50dBm signal antenna 0 Probe Response (HAE_Wireless) [1.0* 2.0* 5.5 11.0 18.0 24.0 36.0 54.0 Mbit] CH: 6, PRIVACY
15:28:17.330942 1.0 Mb/s 2437 MHz 11b -56dBm signal antenna 0 Probe Response (Gigashit) [1.0* 2.0* 5.5* 11.0* 6.0 9.0 12.0 18.0 Mbit] CH: 6, PRIVACY
15:28:17.336189 1.0 Mb/s 2437 MHz 11b -58dBm signal antenna 0 Beacon (HAE_Wireless) [1.0* 2.0* 5.5 11.0 18.0 24.0 36.0 54.0 Mbit] ESS CH: 6, PRIVACY
15:28:17.341334 1.0 Mb/s 2437 MHz 11b -58dBm signal antenna 0 Probe Response (HAE_Wireless) [1.0* 2.0* 5.5 11.0 18.0 24.0 36.0 54.0 Mbit] CH: 6, PRIVACY
15:28:17.346346 1.0 Mb/s 2437 MHz 11b -56dBm signal antenna 0 Probe Response (Gigashit) [1.0* 2.0* 5.5* 11.0* 6.0 9.0 12.0 18.0 Mbit] CH: 6, PRIVACY
15:28:17.349376 1.0 Mb/s 2437 MHz 11b -54dBm signal antenna 0 Probe Response (Gigashit) [1.0* 2.0* 5.5* 11.0* 6.0 9.0 12.0 18.0 Mbit] CH: 6, PRIVACY
15:28:17.351683 1.0 Mb/s 2437 MHz 11b -54dBm signal antenna 0 Beacon (Gigashit) [1.0* 2.0* 5.5* 11.0* 6.0 9.0 12.0 18.0 Mbit] ESS CH: 6, PRIVACY
15:28:17.364234 1.0 Mb/s 2437 MHz 11b -58dBm signal antenna 0 Probe Response (Gigashit) [1.0* 2.0* 5.5* 11.0* 6.0 9.0 12.0 18.0 Mbit] CH: 6, PRIVACY
15:28:17.368792 1.0 Mb/s 2437 MHz 11b -56dBm signal antenna 0 Probe Response (Gigashit) [1.0* 2.0* 5.5* 11.0* 6.0 9.0 12.0 18.0 Mbit] CH: 6, PRIVACY
15:28:17.375346 1.0 Mb/s 2437 MHz 11b -56dBm signal antenna 0 Beacon (Gigashit) [1.0* 2.0* 5.5* 11.0* 6.0 9.0 12.0 18.0 Mbit] ESS CH: 6, PRIVACY
15:28:17.531814 1.0 Mb/s 2447 MHz 11b -54dBm signal antenna 0 Beacon (HAE_Wireless) [1.0* 2.0* 5.5 11.0 18.0 24.0 36.0 54.0 Mbit] ESS CH: 6, PRIVACY
15:28:17.545381 1.0 Mb/s 2447 MHz 11b -52dBm signal antenna 0 Probe Response (HAE_Wireless) [1.0* 2.0* 5.5 11.0 18.0 24.0 36.0 54.0 Mbit] CH: 6, PRIVACY
15:28:18.220550 6.0 Mb/s 5180 MHz 11a -46dBm signal antenna 0 Probe Response (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 36, PRIVACY
15:28:18.221359 6.0 Mb/s 5180 MHz 11a -46dBm signal antenna 0 Probe Response (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 36, PRIVACY
15:28:18.221895 6.0 Mb/s 5180 MHz 11a -74dBm signal antenna 0 Probe Response (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 36, PRIVACY
15:28:18.222480 6.0 Mb/s 5180 MHz 11a -90dBm signal antenna 0 Probe Response (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 36, PRIVACY
15:28:18.222918 6.0 Mb/s 5180 MHz 11a -74dBm signal antenna 0 Probe Response (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 36, PRIVACY
15:28:18.284117 6.0 Mb/s 5180 MHz 11a -91dBm signal antenna 0 unknown 802.11 ctrl frame subtype (5)
15:28:18.285290 6.0 Mb/s 5180 MHz 11a -92dBm signal antenna 0 unknown 802.11 ctrl frame subtype (5)
15:28:18.298863 6.0 Mb/s 5180 MHz 11a -90dBm signal antenna 0 Beacon () [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] IBSS CH: 36, PRIVACY
15:28:18.299701 6.0 Mb/s 5180 MHz 11a -90dBm signal antenna 0 Beacon (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 36, PRIVACY
15:28:18.300002 6.0 Mb/s 5180 MHz 11a -73dBm signal antenna 0 Beacon () [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] IBSS CH: 36, PRIVACY
15:28:18.300421 6.0 Mb/s 5180 MHz 11a -74dBm signal antenna 0 Beacon () [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 36
15:28:18.300834 6.0 Mb/s 5180 MHz 11a -73dBm signal antenna 0 Beacon (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 36, PRIVACY
15:28:18.303272 6.0 Mb/s 5180 MHz 11a -46dBm signal antenna 0 Beacon () [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] IBSS CH: 36, PRIVACY
15:28:18.303650 6.0 Mb/s 5180 MHz 11a -45dBm signal antenna 0 Beacon () [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 36
15:28:18.304070 6.0 Mb/s 5180 MHz 11a -46dBm signal antenna 0 Beacon (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 36, PRIVACY
15:28:18.543980 6.0 Mb/s 5240 MHz 11a -90dBm signal antenna 0 Probe Response (CBCI-CB18-5) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 48, PRIVACY
15:28:18.544450 6.0 Mb/s 5240 MHz 11a -91dBm signal antenna 0 Probe Response (xfinitywifi) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 48
15:28:18.544919 6.0 Mb/s 5240 MHz 11a -91dBm signal antenna 0 Probe Response (XFINITY) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 48, PRIVACY
15:28:18.545596 6.0 Mb/s 5240 MHz 11a -91dBm signal antenna 0 Probe Response (CBCI-CB18-5) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 48, PRIVACY
15:28:18.546654 6.0 Mb/s 5240 MHz 11a -89dBm signal antenna 0 Beacon (CBCI-CB18-5) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 48, PRIVACY
15:28:18.547068 6.0 Mb/s 5240 MHz 11a -90dBm signal antenna 0 Probe Response (XFINITY) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 48, PRIVACY
15:28:18.547543 6.0 Mb/s 5240 MHz 11a -90dBm signal antenna 0 Probe Response (xfinitywifi) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 48
15:28:18.580733 6.0 Mb/s 5240 MHz 11a -91dBm signal antenna 0 Beacon (xfinitywifi) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 48
15:28:18.640816 6.0 Mb/s 5240 MHz 11a -90dBm signal antenna 0 Beacon (Downtown Abbey II) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 48, PRIVACY
15:28:20.271862 6.0 Mb/s 5745 MHz 11a -71dBm signal antenna 0 Probe Response (Gigashit) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 149, PRIVACY
15:28:20.272312 6.0 Mb/s 5745 MHz 11a -76dBm signal antenna 0 Probe Response (Gigashit) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 149, PRIVACY
15:28:20.279928 12.0 Mb/s 5745 MHz 11a -44dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:20.333834 6.0 Mb/s 5745 MHz 11a -72dBm signal antenna 0 Beacon (Gigashit) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 149, PRIVACY
15:28:20.346744 6.0 Mb/s 5745 MHz 11a -77dBm signal antenna 0 Beacon (Gigashit) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 149, PRIVACY
15:28:20.365941 6.0 Mb/s 5745 MHz 11a -72dBm signal antenna 0 Beacon (Gigashit) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 149, PRIVACY
15:28:20.489684 6.0 Mb/s 5785 MHz 11a -36dBm signal antenna 0 Probe Response (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 157, PRIVACY
15:28:20.490219 6.0 Mb/s 5785 MHz 11a -64dBm signal antenna 0 Probe Response (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 157, PRIVACY
15:28:20.490664 6.0 Mb/s 5785 MHz 11a -35dBm signal antenna 0 Probe Response (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 157, PRIVACY
15:28:20.491180 6.0 Mb/s 5785 MHz 11a -64dBm signal antenna 0 Probe Response (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] CH: 157, PRIVACY
15:28:20.514933 12.0 Mb/s 5785 MHz 11a -45dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:20.541272 24.0 Mb/s 5785 MHz 11a -45dBm signal antenna 0 
15:28:20.552270 6.0 Mb/s 5785 MHz 11a -80dBm signal antenna 0 Beacon () [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 157
15:28:20.552656 6.0 Mb/s 5785 MHz 11a -81dBm signal antenna 0 Beacon (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 157, PRIVACY
15:28:20.553004 6.0 Mb/s 5785 MHz 11a -61dBm signal antenna 0 Beacon () [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] IBSS CH: 157, PRIVACY
15:28:20.553382 6.0 Mb/s 5785 MHz 11a -64dBm signal antenna 0 Beacon () [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 157
15:28:20.553800 6.0 Mb/s 5785 MHz 11a -63dBm signal antenna 0 Beacon (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 157, PRIVACY
15:28:20.556263 6.0 Mb/s 5785 MHz 11a -36dBm signal antenna 0 Beacon () [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] IBSS CH: 157, PRIVACY
15:28:20.556698 6.0 Mb/s 5785 MHz 11a -36dBm signal antenna 0 Beacon () [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 157
15:28:20.557061 6.0 Mb/s 5785 MHz 11a -35dBm signal antenna 0 Beacon (Licorice Snap) [6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0 Mbit] ESS CH: 157, PRIVACY
15:28:20.829951 24.0 Mb/s 5785 MHz 11a -48dBm signal antenna 0 
15:28:20.846157 12.0 Mb/s 5785 MHz 11a -46dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:20.963695 6.0 Mb/s 5785 MHz 11a -38dBm signal antenna 0 Action IV:8a39 Pad 20 KeyID 1
15:28:20.974108 12.0 Mb/s 5785 MHz 11a -45dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.039227 12.0 Mb/s 5785 MHz 11a -45dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.075749 12.0 Mb/s 5785 MHz 11a -44dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.104977 12.0 Mb/s 5785 MHz 11a -45dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.184247 12.0 Mb/s 5785 MHz 11a -45dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.213844 6.0 Mb/s 5785 MHz 11a -48dBm signal antenna 0 Probe Request () [6.0 9.0 12.0 18.0 24.0 36.0 48.0 54.0 Mbit]
15:28:21.226158 6.0 Mb/s 5785 MHz 11a -48dBm signal antenna 0 Probe Request () [6.0 9.0 12.0 18.0 24.0 36.0 48.0 54.0 Mbit]
15:28:21.279345 6.0 Mb/s 5785 MHz 11a -48dBm signal antenna 0 Probe Request () [6.0 9.0 12.0 18.0 24.0 36.0 48.0 54.0 Mbit]
15:28:21.286707 6.0 Mb/s 5785 MHz 11a -48dBm signal antenna 0 Probe Request () [6.0 9.0 12.0 18.0 24.0 36.0 48.0 54.0 Mbit]
15:28:21.297396 12.0 Mb/s 5785 MHz 11a -45dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.352037 6.0 Mb/s 5785 MHz 11a -73dBm signal antenna 0 Action IV:48cb Pad 20 KeyID 1
15:28:21.352342 6.0 Mb/s 5785 MHz 11a -74dBm signal antenna 0 Action IV:2ffc Pad 20 KeyID 0
15:28:21.352659 6.0 Mb/s 5785 MHz 11a -73dBm signal antenna 0 Action IV:a234 Pad 20 KeyID 1
15:28:21.353851 6.0 Mb/s 5785 MHz 11a -76dBm signal antenna 0 Action IV:3b0f Pad 20 KeyID 1
15:28:21.353866 6.0 Mb/s 5785 MHz 11a -78dBm signal antenna 0 Action IV:a380 Pad 20 KeyID 1
15:28:21.358323 6.0 Mb/s 5785 MHz 11a -77dBm signal antenna 0 Action IV:fe02 Pad 20 KeyID 0
15:28:21.410711 12.0 Mb/s 5785 MHz 11a -44dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.498983 12.0 Mb/s 5785 MHz 11a -45dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.564372 12.0 Mb/s 5785 MHz 11a -45dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.573074 5785 MHz 11n -73dBm signal antenna 0 26.0 Mb/s MCS 3 20 MHz long GI RX-STBC0 Probe Request (Sonos_O1v02CKSOMAvtzxtEgSkhUxZn0)
15:28:21.605081 12.0 Mb/s 5785 MHz 11a -45dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.635151 12.0 Mb/s 5785 MHz 11a -44dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.696706 12.0 Mb/s 5785 MHz 11a -45dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.748483 12.0 Mb/s 5785 MHz 11a -46dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.760173 12.0 Mb/s 5785 MHz 11a -47dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.862491 12.0 Mb/s 5785 MHz 11a -46dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:21.975544 12.0 Mb/s 5785 MHz 11a -45dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
15:28:22.022936 12.0 Mb/s 5785 MHz 11a -45dBm signal antenna 0 Action (e6:58:27:86:90:24 (oui Unknown)): Vendor Act#0
terrysimons commented 3 years ago

As a datapoint, it's possible to "unstick" this behavior, by re-issuing:

$ sudo iw dev wlan1 set monitor none

Then after starting tcpdump again with sudo tcpdump -i wlan1, the issue will occur again once the channel hop happens.

Rinse and repeat these two commands to see the failure reproduce.

terrysimons commented 3 years ago

The two sed lines I used were updated. I fixed the original post to include CONFIG_PLATFORM_ARM64 = y as the correct way to build the driver on Ubuntu 20.10.

terrysimons commented 3 years ago

Oops, accidentally clicked "Close with comment". This issue is still valid.