Find a file
Louis Kotze f74b5809a1
supplicant: dedupe MLO per-link BSSIDs in bgscan multi-AP heuristic
nm_supplicant_config_add_bgscan() picks "simple:30:-65:300" for any
profile that has been seen on more than one BSSID, on the
assumption that this is a multi-AP ESS where periodic roam-candidate
scanning is desirable. Each scan blocks the data path on the radio
for the full scan duration (5-7 s on rtw89 USB at MCS 13), causing
audible/visible stalls in real-time UDP applications such as Teams
and Discord every 5 minutes.

For single-AP Wi-Fi 7 MLO, this heuristic misfires: the AP
advertises one BSSID per link, so a 2-link or 3-link MLD looks
like a 2-3 AP ESS to the seen-bssids count. Verified locally on
RTL8922AU + Bazzite Linux 6.19.11 against TP-Link Deco BE63 mesh;
the connection's seen-bssids list contains only the per-link
BSSIDs of the single physical AP it has been associated with
(Link 1 and Link 2 of the MLD), but bgscan flips to the multi-AP
value with the user-visible stall pattern.

Add a conservative heuristic to detect MLO per-link BSSIDs and
exempt them from the multi-AP path. The detection requires ALL of:

  - 2 to 3 seen BSSIDs (802.11be defines tri-link 2.4 + 5 + 6 GHz
    as the maximum)
  - every BSSID has the locally-administered bit set (vendors use
    LAA-flagged virtual MACs for per-link addresses; verified on
    TP-Link Deco BE63: Link 1 f6:75:0c:74:4b:75 and Link 2
    ca:75:0c:74:4b:70 both have bit 1 set)
  - every BSSID shares octets 1-4 with the others (per-link MACs
    derived from a common base, varying only the first and last
    octets)

Real multi-AP ESSes (mesh, enterprise) typically use vendor-assigned
MACs (LAA bit unset) and unrelated address blocks per AP, so the
heuristic should not false-positive on legitimate multi-AP networks.
The connection's seen-bssids list is bounded at 30 entries (LRU) per
NM_SETTINGS_CONNECTION_SEEN_BSSIDS_MAX; the strv passed in from
build_supplicant_config() is the daemon-managed authoritative copy
loaded from /var/lib/NetworkManager/seen-bssids, not the unreliable
NMSettingWireless property.

Extend nm_supplicant_config_add_bgscan() to take the BSSID strv as
a parameter alongside the existing num_seen_bssids count (mirroring
the 2023 fix in commit 07c6f933d1 ('wifi: fix aggressively
roaming (background Wi-Fi scanning) based on seen-bssids') for
num_seen_bssids), so the heuristic can inspect actual addresses
rather than only the count.

Add a regression test test_wifi_bgscan_mlo_dedup() in
test-supplicant-config.c covering four cases: 2-link MLO BSSIDs
(LAA + shared octets 1-4) producing the long-interval bgscan;
tri-link MLO BSSIDs (3-BSSID variant matching 802.11be's tri-link
maximum) also producing the long-interval bgscan; real multi-AP
BSSIDs (UAA, unrelated blocks) producing the short interval; and
all-LAA BSSIDs with unrelated octets 1-4 still producing the short
interval (no false-positive on LAA alone).

Empirical A/B on the local rig (2026-04-29):
  - With this dedup applied: bgscan = "simple:30:-70:86400";
    0 scans observed in 18-min capture; 0 audio/video stalls in
    a 30-min Discord call
  - Without (stock 1.54): bgscan = "simple:30:-65:300";
    6 full-band scans at exactly 305 s cadence; 4 stall bursts
    coinciding with scan windows in 30 min

Heuristic was calibrated against TP-Link Deco BE63; non-Deco MLO
hardware was not available for testing. The conservative
all-of-three-conditions check should reject most non-MLO traffic,
but vendor diversity in MLO per-link MAC derivation has not been
characterised. Testers with non-Deco MLO hardware welcome.

Signed-off-by: Louis Kotze <loukot@gmail.com>
2026-05-06 14:37:22 +02:00
.gitlab gitlab: improve the merge request template 2026-02-27 11:59:16 +01:00
.gitlab-ci ci: fix pages job 2025-10-24 12:48:20 +02:00
contrib spec: fix scriptlet dependencies 2026-04-09 13:33:32 +00:00
data data/NetworkManager.service: restrict the unit some more 2026-02-27 08:44:10 +00:00
docs docs/libnm: fix typo in libnm.svg 2026-04-08 10:19:23 +00:00
examples core: rename NM_STATE_ASLEEP to NM_STATE_DISABLED 2025-09-23 09:17:03 +02:00
introspection core: device: allow to reset the managed property 2026-03-06 11:21:50 +01:00
man cloud-setup/man: fix typo in man nm-cloud-setup 2026-04-08 10:19:23 +00:00
po po: Update Serbian Latin translation 2026-04-08 13:05:36 +00:00
src supplicant: dedupe MLO per-link BSSIDs in bgscan multi-AP heuristic 2026-05-06 14:37:22 +02:00
tools nmcli: show the CLAT state 2026-02-06 10:38:04 +01:00
vapi geneve: added GENEVE device support 2026-02-17 15:21:03 -05:00
.clang-format glib-aux/prioq: rename NM_PRIOQ_FOREACH_ITEM() to nm_prioq_for_each() 2023-03-21 15:58:39 +01:00
.dir-locals.el misc: add toplevel .dir-locals file that tells Emacs to show trailing whitespace 2013-03-08 15:15:28 +01:00
.git-blame-ignore-revs format: add reformatting commit to ".git-blame-ignore-revs" 2023-12-07 13:03:36 +01:00
.gitignore polkit: remove the modify_system build option 2025-12-12 12:38:48 +01:00
.gitlab-ci.yml bpf: clat: rework to avoid pointer arithmetic 2026-01-24 09:42:33 +01:00
.mailmap mailmap: update Jordi's identity 2023-06-28 13:50:25 +02:00
.triage-policies.yml triage: fix typo atention -> attention 2024-09-26 11:04:51 +02:00
AUTHORS docs: fix typo in docs for upstream mailing list 2022-11-07 17:50:29 +01:00
ChangeLog Changelog: update references to "main" branch 2021-04-01 22:30:20 +02:00
config-extra.h.meson build: remove duplicate and unused RUNDIR define 2019-05-17 21:24:18 +02:00
config.h.meson Add CLAT BPF program and build machinery 2026-01-24 09:40:47 +01:00
CONTRIBUTING.md CONTRIBUTING: fix typo 2024-12-20 16:26:00 +01:00
COPYING COPYING: make sure we ship the relevant license texts 2019-09-10 11:10:52 +02:00
COPYING.GFDL COPYING: make sure we ship the relevant license texts 2019-09-10 11:10:52 +02:00
COPYING.LGPL COPYING: make sure we ship the relevant license texts 2019-09-10 11:10:52 +02:00
linker-script-binary.ver iface-helper/build: add linker version script 2016-10-13 21:33:33 +02:00
linker-script-devices.ver devices/build: use one linker-script-devices.ver for all device plugins 2016-10-13 21:36:06 +02:00
linker-script-settings.ver settings/build: add linker version script for settings plugins 2016-10-13 21:33:33 +02:00
lsan.suppressions tests/sanitizer: suppress leak in openssl 2020-05-14 12:03:24 +02:00
MAINTAINERS misc: update maintainers and authors 2016-04-21 13:39:03 -05:00
MAINTAINERS.md doc: update the process to release a VPN plugin 2025-08-25 13:34:54 +00:00
meson.build meson: fix cross-compilation issues 2026-04-08 10:11:13 +00:00
meson_options.txt Add CLAT BPF program and build machinery 2026-01-24 09:40:47 +01:00
NEWS nmtui/bond: introduce "other options" list 2026-04-09 11:33:20 +02:00
README.md README: document the required kernel version 2025-04-17 08:10:54 +02:00
RELICENSE.md docs: fix typo in docs for upstream mailing list 2022-11-07 17:50:29 +01:00
TODO core/trivial: rename NM_SHUTDOWN_TIMEOUT_MS to NM_SHUTDOWN_TIMEOUT_MAX_MSEC 2022-02-24 09:38:52 +01:00
valgrind.suppressions build: remove autotools leftovers 2025-09-08 10:46:44 +00:00

NetworkManager

Networking that Just Works

NetworkManager attempts to keep an active network connection available at all times. The point of NetworkManager is to make networking configuration and setup as painless and automatic as possible. NetworkManager is intended to replace default route, replace other routes, set IP addresses, and in general configure networking as NM sees fit (with the possibility of manual override as necessary). In effect, the goal of NetworkManager is to make networking Just Work with a minimum of user hassle, but still allow customization and a high level of manual network control. If you have special needs, we'd like to hear about them, but understand that NetworkManager is not intended for every use-case.

NetworkManager will attempt to keep every network device in the system up and active, as long as the device is available for use (has a cable plugged in, the killswitch isn't turned on, etc). Network connections can be set to 'autoconnect', meaning that NetworkManager will make that connection active whenever it and the hardware is available.

"Settings services" store lists of user- or administrator-defined "connections", which contain all the settings and parameters required to connect to a specific network. NetworkManager will never activate a connection that is not in this list, or that the user has not directed NetworkManager to connect to.

How it works

The NetworkManager daemon runs as a privileged service (since it must access and control hardware), but provides a D-Bus interface on the system bus to allow for fine-grained control of networking. NetworkManager does not store connections or settings, it is only the mechanism by which those connections are selected and activated.

To store pre-defined network connections, two separate services, the "system settings service" and the "user settings service" store connection information and provide these to NetworkManager, also via D-Bus. Each settings service can determine how and where it persistently stores the connection information; for example, the GNOME applet stores its configuration in GConf, and the system settings service stores its config in distro-specific formats, or in a distro- agnostic format, depending on user/administrator preference.

A variety of other system services are used by NetworkManager to provide network functionality: wpa_supplicant for wireless connections and 802.1x wired connections, pppd for PPP and mobile broadband connections, DHCP clients for dynamic IP addressing, dnsmasq for proxy nameserver and DHCP server functionality for internet connection sharing, and avahi-autoipd for IPv4 link-local addresses. Most communication with these daemons occurs, again, via D-Bus.

How to use it

Install NetworkManager with your distribution's package manager.

As NetworkManager is actually a daemon that runs in the background, you need to use one of the many existing client programs to interact with it.

Terminal clients:

  • nmcli: advanced command line client that gives you full control over all the aspects of NetworkManager, developed as part of the NetworkManager project.
  • nmtui: text-based user interface (TUI) client. Also for the terminal, but interactive and more user friendly, also part of the NetworkManager project.
  • nmstate: declarative network API and command line tool that uses NetworkManager as backend.
  • Ansible: use the network-role in your playbooks

GUI clients

  • nm-connection-editor and nm-applet: basic GUI interfaces developed by the NetworkManager project.
  • GNOME shell: interacts with NetworkManager via its default settings panel gnome-control-center
  • KDE Plasma: interacts with NetworkManager via its default settings panel and plasma-nm

Why doesn't my network Just Work?

Driver problems are the #1 cause of why NetworkManager sometimes fails to connect to wireless networks. Often, the driver simply doesn't behave in a consistent manner, or is just plain buggy. NetworkManager supports only those drivers that are shipped with the upstream Linux kernel, because only those drivers can be easily fixed and debugged. ndiswrapper, vendor binary drivers, or other out-of-tree drivers may or may not work well with NetworkManager, precisely because they have not been vetted and improved by the open-source community, and because problems in these drivers usually cannot be fixed.

Sometimes, command-line tools like 'iwconfig' will work, but NetworkManager will fail. This is again often due to buggy drivers, because these drivers simply aren't expecting the dynamic requests that NetworkManager and wpa_supplicant make. Driver bugs should be filed in the bug tracker of the distribution being run, since often distributions customize their kernel and drivers.

Sometimes, it really is NetworkManager's fault. If you think that's the case, please file a bug at:

https://gitlab.freedesktop.org/NetworkManager/NetworkManager/issues

Attaching NetworkManager debug logs from the journal (or wherever your distribution directs syslog's 'daemon' facility output, as /var/log/messages or /var/log/daemon.log) is often very helpful, and (if you can get) a working wpa_supplicant config file helps enormously. See the logging section of file contrib/fedora/rpm/NetworkManager.conf for how to enable debug logging in NetworkManager.

Requirements

NetworkManager requires:

  • Linux kernel >= 5.6 for some ethtool options (pause, eee, ring)

Documentation

Updated documentation can be found at https://networkmanager.dev/docs

Users can consult the man pages. Most relevant pages for normal users are:

Get in touch

To connect with the community, get help or get involved see the available communication channels at https://networkmanager.dev/community/

Report bugs or feature request in our issue tracker. See Report issues for details about how to do it.

Contribute

To get involved, see CONTRIBUTING.md to find different ways to contribute.

License

NetworkManager is free software under GPL-2.0-or-later and LGPL-2.1-or-later. See CONTRIBUTING.md#legal and RELICENSE.md for details.