You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Items deferred out of #451 (the REG_CR 0xFF-before-LLT-init fix) and #453 (its review follow-up), all pre-existing on master or deliberately left as they are. None changes the fix itself.
Beacon lifecycle
StopBeacon result contract. It returns false both for "nothing active" (the IRadio contract) and for "a disable write was refused", so a caller cannot tell them apart. txdemo's TxBeaconGuard therefore ends its loop on any false, and a refused disable on Jaguar2 (which has no teardown power-down) can leave the beacon airing until re-enumeration. Fix shape: a distinct result from StopBeacon (tri-state or a BeaconStopResult), after which the guard retries only the refused case. Interim without an API change: after a successful StartBeacon (armed == true) both Jaguar2 and Jaguar3 return false only on a refused disable and keep _bcn_hw_touched, so if (!dev->StopBeacon() && armed) continue; in the guard's loop already gives the retry that matters.
Below 3 bulk-OUT endpoints the SetAmpduMode TID lands on data frames that ride endpoint 0: a descriptor/endpoint mismatch on the 1- and 2-endpoint shapes, deliberately kept and pinned by tests/txqueue_selftest.cpp (src/jaguar3/TxQueueMap.h). Neither the 1/2- nor the 4-endpoint shape has been measured; the DEVOURER_TX_QSEL override can produce the same mismatch on any shape.
TXDMA_STATUS decoding
Only two bits of REG_TXDMA_STATUS are decoded (IRtlRadio::GetTxDmaStatus): bit 18 BIT_TXPKTBUF_REQ_ERR, the one measured with the wedge, and bit 13 BIT_PAYLOAD_OVF_8822C, which latches under max-duty USB2 backpressure while TX continues. The 8812BU's wedge read 0x10 then 0x15, undecoded. The bit-13 latch is intermittent: seen from the first sample on an 8812CU at DEVOURER_TX_GAP_US=0 on 2026-09-26/27, and absent in 26/26 samples of an otherwise identical cold-cycled run at jaguar2/3: #451 review follow-up - TXDMA_STATUS bit semantics, send_packets drop warning, beacon-guard retry #453's head. A poller that wants a "stopped" verdict needs the remaining bits decoded against halmac_bit_8822c.h / the 8822B equivalent and each one measured.
Items deferred out of #451 (the
REG_CR0xFF-before-LLT-init fix) and #453 (its review follow-up), all pre-existing on master or deliberately left as they are. None changes the fix itself.Beacon lifecycle
StopBeaconresult contract. It returns false both for "nothing active" (theIRadiocontract) and for "a disable write was refused", so a caller cannot tell them apart. txdemo'sTxBeaconGuardtherefore ends its loop on any false, and a refused disable on Jaguar2 (which has no teardown power-down) can leave the beacon airing until re-enumeration. Fix shape: a distinct result fromStopBeacon(tri-state or aBeaconStopResult), after which the guard retries only the refused case. Interim without an API change: after a successfulStartBeacon(armed == true) both Jaguar2 and Jaguar3 return false only on a refused disable and keep_bcn_hw_touched, soif (!dev->StopBeacon() && armed) continue;in the guard's loop already gives the retry that matters.StartBeaconreturns true after a failedPinBeaconTbtt(0)re-download (jaguar2/3: enable the MAC protocol engine before the LLT init - the TX page-ring fix #451 round 7).StopBeacon: it inherits theIRadiono-op, so a Kestrel beaconing session cannot disarm mid-session (jaguar2/3: enable the MAC protocol engine before the LLT init - the TX page-ring fix #451 round 3; untestable on that PR's bench).Send path
_ampduunsynchronized on the send path (jaguar2/3: enable the MAC protocol engine before the LLT init - the TX page-ring fix #451 round 9); Jaguar3 was fixed there, the other two were not.SetAmpduModeTID lands on data frames that ride endpoint 0: a descriptor/endpoint mismatch on the 1- and 2-endpoint shapes, deliberately kept and pinned bytests/txqueue_selftest.cpp(src/jaguar3/TxQueueMap.h). Neither the 1/2- nor the 4-endpoint shape has been measured; theDEVOURER_TX_QSELoverride can produce the same mismatch on any shape.TXDMA_STATUS decoding
REG_TXDMA_STATUSare decoded (IRtlRadio::GetTxDmaStatus): bit 18BIT_TXPKTBUF_REQ_ERR, the one measured with the wedge, and bit 13BIT_PAYLOAD_OVF_8822C, which latches under max-duty USB2 backpressure while TX continues. The 8812BU's wedge read0x10then0x15, undecoded. The bit-13 latch is intermittent: seen from the first sample on an 8812CU atDEVOURER_TX_GAP_US=0on 2026-09-26/27, and absent in 26/26 samples of an otherwise identical cold-cycled run at jaguar2/3: #451 review follow-up - TXDMA_STATUS bit semantics, send_packets drop warning, beacon-guard retry #453's head. A poller that wants a "stopped" verdict needs the remaining bits decoded againsthalmac_bit_8822c.h/ the 8822B equivalent and each one measured.Bench
0bda:a81a) drops off USB about 2 s in, every build, so jaguar2/3: enable the MAC protocol engine before the LLT init - the TX page-ring fix #451 and jaguar2/3: #451 review follow-up - TXDMA_STATUS bit semantics, send_packets drop warning, beacon-guard retry #453 were validated on the 8812CU and 8812BU only. Consistent with the pre-existing 5 GHz flood NAK behaviour plus a likely supply brownout; needs a powered fixture before the EU die can be a witness for either fix.Context and measurements: #451 and #453 bodies,
docs/jaguar3-tx-ring.md,src/jaguar3/CLAUDE.md.