I had read somewhere on this forum that a value of 20000 was recommended for Apple devices, so that is what I had been running for a long time. I changed it to 50000 during my pursuit of trying to solve this VLAN reassignment issue and haven't set it back down lower yet. Maybe I'll do that in a few minutes...
Is this a setting on your phone/test device?
I'm not sure what to make of this yet. I'm pondering this.
For clarification sake, are you saying the FT request is triggering a restart of the AP itself?
thanks. I managed to make your patches applied but placing it on the directory you specified doesnt seem to work, at least on 24.10.1 sdk, it ignores it and the compiled version works similarly as the one from openwrt's repo and ft is broken as usual.
ive read deeper on how to apply those patches manually on a specific package (eg on wpad-mbedtls in my case) involves cding deeper inside the build_dir directory all the way to the package you want to apply the patch (which in my case hostapd-wpad-full-mbedtls), from there, I wget your patch, run quilt import, quilt push, then verify it and run quilt series, after that I compiled it using the make command, install the ipks to the APs (for some reason, I need to reboot those device just to get them installed as opkg stubbornly wants the internet version of the ipk), after installing it, reboot it another just in case and it looks like somethings working this time, tried roaming around and see if it still jumps to default network when roaming and it seems to work great now, it no longer vlan hop to default vlan now. Im going to test it further and I hope this fixes it.
hardware used: 4x Tplilnk ax-23 and 1x Zbtlink ZBT-WG3526 (32M) all of them are mt7621 based soc.
I second this, been 5 days with like 8-10 devices (mixed of laptops, smartphones and ipads roaming around) zero issues so far, everything is FT-ing without vlan hopping to default vlan. Configuration on 802.11r are all default configuration, didt even bother adjusting that reassociation value and our iphone and ipads are roaming just fine. Aside from actually me using band steering on the SSID since I dont really want to bother switching between 2.4 and 5ghz band manually all the time.
@remlei && @xize Thanks for the feedback! I’m very pleased to hear this patch has been doing its intended job, and not crashing people’s stuff while doing it
I am going to see about submitting it upstream, but I’ve got to refresh my memory on all the requirements to do so. If, by some chance, I need some help with testing confirmations and/or sign-offs, would you be willing to vouch for it?
What I was observing was a drop out from lose of power , I changed not so long ago to PoE with one AP, but everytime I used speedtest it did just enough to restart the wifi but not the router.
The patch has no issues , I gonna try to overload this unifi PoE switch so it will not happen again on the AP when testing.
I used your example to create a mixed AP setup [WPA2-EAP and WPA2-PSK] because some client devices here do not support 802.1x. Both the external RADIUS and hostapd_wpa_psk file happily coexist.
The only thing I had to look up was use of hostapd_cli. The suggested command
I have a second revision of the patch I originally posted here:
The second revision is active at that same gist URL for anyone willing to try it. My hope still is to get it upstreamed, but I want to make sure it’s good and solid first.
Thanks in advance to anyone willing to give it a go!
Hi, I have done a small test between my dumbap and back to my main router.
I know that my dumbap has a small issue getting the default gateway if interfaces restart it sometimes uses the wrong one (theres no wan, all in lan and only the lan interface having default gateway checked, but somehow doesn’t make it default route), usually it should work, but to confirm I also walked back downstairs and ensured in wifiman I changed.
Now I keep hopping to the default vlan:
Fri Aug 22 18:34:46 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: sending 1/4 msg of 4-Way Handshake
Fri Aug 22 18:34:46 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:6xx:xx:xx WPA: received EAPOL-Key frame (2/4 Pairwise)
Fri Aug 22 18:34:46 2025 daemon.notice hostapd: Assigned VLAN ID 90 from wpa_psk_file to f6:a2:10:xx:xx:xx
Fri Aug 22 18:34:46 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.11: binding station to interface 'phy1-ap0-aya'
Fri Aug 22 18:34:46 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: sending 3/4 msg of 4-Way Handshake
Fri Aug 22 18:34:46 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: received EAPOL-Key frame (4/4 Pairwise)
Fri Aug 22 18:34:46 2025 daemon.notice hostapd: phy1-ap0: AP-STA-CONNECTED f6:a2:10:xx:xx:xx auth_alg=open
Fri Aug 22 18:34:46 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.1X: authorizing port
Fri Aug 22 18:34:46 2025 daemon.info hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx RADIUS: starting accounting session 2BA883C95B561D54
Fri Aug 22 18:34:46 2025 daemon.info hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: pairwise key handshake completed (RSN)
Fri Aug 22 18:34:46 2025 daemon.notice hostapd: phy1-ap0: EAPOL-4WAY-HS-COMPLETED f6:a2:10:xx:xx:xx
Fri Aug 22 18:40:15 2025 daemon.notice hostapd: phy1-ap0: AP-STA-DISCONNECTED f6:a2:10:xx:xx:xx
Fri Aug 22 18:40:15 2025 daemon.err hostapd: phy1-ap0: nl80211: kernel reports: key addition failed
Fri Aug 22 18:40:15 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.11: binding station to interface 'phy1-ap0'
Fri Aug 22 18:40:15 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.11: authentication OK (FT)
Fri Aug 22 18:40:15 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx MLME: MLME-AUTHENTICATE.indication(f6:a2:10:xx:xx:xx, FT)
Fri Aug 22 18:40:15 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.11: association OK (aid 2)
Fri Aug 22 18:40:15 2025 daemon.info hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.11: associated (aid 2)
Fri Aug 22 18:40:15 2025 daemon.notice hostapd: phy1-ap0: AP-STA-CONNECTED f6:a2:10:xx:xx:xx auth_alg=ft
Fri Aug 22 18:40:15 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx MLME: MLME-REASSOCIATE.indication(f6:a2:10:xx:xx:xx)
Fri Aug 22 18:40:15 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.11: binding station to interface 'phy1-ap0'
Fri Aug 22 18:40:15 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: event 6 notification
Fri Aug 22 18:40:15 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: FT authentication already completed - do not start 4-way handshake
Does the patch target recent main branch commit until 3b54f82?
Oddly enough, this latest patch seems to be working perfectly for me, so I’m a bit confused as to what the difference could be between our configs/environments.
Would you mind trying this so we can get more verbosity from your log? (changed MSG_DEBUG to MSG_INFO)
I have tried it with the new patch but I don’t see anything special, just the same as my first post.
Sat Aug 23 00:14:37 2025 daemon.err hostapd: phy1-ap0: nl80211: kernel reports: key addition failed
Sat Aug 23 00:14:37 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.11: binding station to interface 'phy1-ap0'
Sat Aug 23 00:14:37 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.11: authentication OK (FT)
Sat Aug 23 00:14:37 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx MLME: MLME-AUTHENTICATE.indication(f6:a2:10:xx:xx:xx, FT)
Sat Aug 23 00:14:37 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.11: association OK (aid 1)
Sat Aug 23 00:14:37 2025 daemon.info hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.11: associated (aid 1)
Sat Aug 23 00:14:37 2025 daemon.notice hostapd: phy1-ap0: AP-STA-CONNECTED f6:a2:10:xx:xx:xx auth_alg=ft
Sat Aug 23 00:14:37 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx MLME: MLME-REASSOCIATE.indication(f6:a2:10:xx:xx:xx)
Sat Aug 23 00:14:37 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.11: binding station to interface 'phy1-ap0'
Sat Aug 23 00:14:37 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: event 6 notification
Sat Aug 23 00:14:37 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: FT authentication already completed - do not start 4-way handshake
Sat Aug 23 00:18:41 2025 authpriv.info dispatcher.uc: luci: accepted login on / for root from 10.39.95.2
Edit: and when I try to disable wifi and connect to this same ap:
Sat Aug 23 00:27:57 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx MLME: MLME-ASSOCIATE.indication(f6:a2:10:xx:xx:xx)
Sat Aug 23 00:27:57 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx MLME: MLME-DELETEKEYS.request(f6:a2:10:xx:xx:xx)
Sat Aug 23 00:27:57 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.11: binding station to interface 'phy1-ap0'
Sat Aug 23 00:27:57 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: event 1 notification
Sat Aug 23 00:27:57 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: start authentication
Sat Aug 23 00:27:57 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.1X: unauthorizing port
Sat Aug 23 00:27:57 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: sending 1/4 msg of 4-Way Handshake
Sat Aug 23 00:27:57 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: received EAPOL-Key frame (2/4 Pairwise)
Sat Aug 23 00:27:57 2025 daemon.notice hostapd: Assigned VLAN ID 90 from wpa_psk_file to f6:a2:10:xx:xx:xx
Sat Aug 23 00:27:57 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.11: binding station to interface 'phy1-ap0-aya'
Sat Aug 23 00:27:57 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: sending 3/4 msg of 4-Way Handshake
Sat Aug 23 00:27:57 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: received EAPOL-Key frame (4/4 Pairwise)
Sat Aug 23 00:27:57 2025 daemon.notice hostapd: phy1-ap0: AP-STA-CONNECTED f6:a2:10:xx:xx:xx auth_alg=open
Sat Aug 23 00:27:57 2025 daemon.debug hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx IEEE 802.1X: authorizing port
Sat Aug 23 00:27:57 2025 daemon.info hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx RADIUS: starting accounting session 139787A7FE090E33
Sat Aug 23 00:27:57 2025 daemon.info hostapd: phy1-ap0: STA f6:a2:10:xx:xx:xx WPA: pairwise key handshake completed (RSN)
Sat Aug 23 00:27:57 2025 daemon.notice hostapd: phy1-ap0: EAPOL-4WAY-HS-COMPLETED f6:a2:10:xx:xx:xx
Is there a way I can confirm the patch is applied?
Yeah, it looks to me like the patch isn’t getting built in properly. With the MSG_INFO patch I posted earlier, you should see at least a handful of messages like this:
When you build your image, do you have it output a build log? e.g. make -j$((1+nproc)) V=s 2>&1 | tee build.log | grep -i -E "^make.*(error|[12345]...Entering dir)"
If so, you can check if the patch is getting applied like so: