Skip to content

brcmfmac crashes after failed OWE-TM association on HES-GUEST (scan error -12 / commonring failures) #491

Description

@flowride

Summary

Connecting to HES-GUEST (OWE/OWE-TM) on Fedora Asahi reliably puts the Broadcom Wi-Fi stack (brcmfmac) into a broken state.
After the failed association, scans and normal Wi-Fi operations degrade or stop until the driver is reloaded.

This looks like a driver/firmware crash path triggered by this network/AP profile.

Environment

  • Device: Apple Silicon machine (Asahi platform)
  • OS: Fedora Asahi Remix (fc44)
  • Kernel: 6.19.13-400.asahi ... +16k
  • Network stack:
    • NetworkManager-1.56.0-1.fc44
    • wpa_supplicant-2.11-9.fc44
    • linux-firmware-20260410-1.fc44
    • brcmfmac-firmware-20260410-1.fc44
  • Driver modules loaded:
    • brcmfmac_wcc
    • brcmfmac
    • brcmutil
    • cfg80211

Reproduction steps

  1. Start from a healthy state where Wi-Fi works on other SSIDs.
  2. Attempt to connect to HES-GUEST (seen as OWE-TM).
  3. Wait for association/activation failure.
  4. Retry scan/connect to any SSID.

Expected behavior

  • Either connect successfully, or fail cleanly.
  • Wi-Fi scanning and subsequent connections should remain functional.

Actual behavior

  • HES-GUEST association times out/fails.
  • Then Wi-Fi becomes unstable or unusable:
    • scan results become empty/intermittent
    • connection attempts fail unexpectedly
  • Recovery often requires reloading brcmfmac modules.

Key logs observed

NetworkManager

  • Activation: (wifi) association took too long
  • state change: config -> failed (reason 'ssid-not-found')
  • Activation: failed for connection 'HES-GUEST'
  • set-hw-addr: failed to set MAC address ... (NME_UNSPEC)
  • also seen:
    • ignore error changing the MAC address to globally configured value "stable-ssid", the device does not support it

Kernel / brcmfmac

  • brcmf_msgbuf_query_dcmd: Timeout on response for query command
  • brcmf_cfg80211_scan: scan error (-5)
  • brcmf_cfg80211_scan: scan error (-12)
  • brcmf_msgbuf_tx_ioctl: Failed to reserve space in commonring
  • repeated failures after the first failed association

Workaround

Reloading Wi-Fi modules restores functionality temporarily:

sudo nmcli radio wifi off
sudo modprobe -r brcmfmac_wcc brcmfmac brcmutil
sudo modprobe brcmfmac
nmcli radio wifi on

[bug_wifi.zip](https://github.com/user-attachments/files/27244243/bug_wifi.zip)

Activity

  1. gx089 commented on May 18, 2026

    @gx089

    This might not solve your problem, but give it a try. After making this change, my Wi‑Fi seems smoother — it may be a placebo effect.

    cat /etc/modprobe.d/brcmfmac.conf
    options brcmfmac roamoff=1
  2. pjjjv commented on May 31, 2026

    @pjjjv

    I had trouble with NetworkManager trying to set a randomized mac adress all the time. I had exactly the same errors/logs from NetworkManager.

    I contained that by turning that off:

    Create /etc/NetworkManager/conf.d/99-permanent-mac-address.conf:
    `[device]
    wifi.scan-rand-mac-address=no

    [connection]
    wifi.cloned-mac-address=permanent
    `

    I also had troubles with OWE.

    https://discussion.fedoraproject.org/t/brcmfmac-wifi-not-supporting-randomized-mac-addresses/192811

  3. rryan commented on Sep 23, 2026

    @rryan

    I see a very similar failure on an Apple Mac14,6 (BCM4388 PCIe, 14e4:4434) running Omarchy Mac / Arch Linux ARM with the Asahi kernel. A failed connection to an OWE guest network appears to leave brcmfmac unable to scan or connect to otherwise working networks.

    Environment:

    • Kernel: 7.1.13-3-2-ARCH (linux-asahi 7.1.13.asahi3-2)
    • NetworkManager: 1.58.1-1
    • wpa_supplicant: 2:2.12-1
    • linux-firmware-broadcom: 20260916-1
    • Driver: brcmfmac; BCM4388/4 firmware version 23.20.95.0.40.50.92, FWID 01-ec505a98
    • The failing guest profile uses 802-11-wireless-security.key-mgmt=owe. Wi-Fi power saving is disabled by the installed NetworkManager configuration.

    WPA-PSK works fine. After attempting a connection to the OWE network, the driver becomes unresponsive.

    • 09:06:54 wpa_supplicant: Trying to associate with SSID 'XYZ'
    • 09:07:04 wpa_supplicant: Authentication with [AP BSSID] timed out.
    • 09:07:06 kernel: brcmf_msgbuf_query_dcmd: Timeout on response for query command
    • 09:07:14 NetworkManager: Activation: (wifi) association took too long
    • 09:07:40 NetworkManager: Activation: failed for connection 'XYZ'
    • Subsequent kernel logs: repeated brcmf_cfg80211_scan: scan error (-5), then brcmf_msgbuf_tx_ioctl: Failed to reserve space in commonring and brcmf_cfg80211_scan: scan error (-12) (common-ring failures visible by 09:09:14).

    Afterward, multiple attempts to reconnect to the previously working WPA-PSK network failed with association timeouts / ssid-not-found; an attempt to join an open legacy guest network failed similarly. Rebooting restored operation: the WPA-PSK network connected at 09:16:04, and the open legacy guest network connected at 09:17:20 and obtained an IPv4 lease. The OWE network has not successfully connected.

  4. epascal commented on Sep 23, 2026

    @epascal

    I still have the same issue, I made a simple script to avoid rebooting :

    modprobe -r brcmfmac_wcc
    modprobe brcmfmac

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions