Message ID | iwlwifi.20211203140410.1a1541d7dcb5.I606c746e11447fe168cf046376b70b04e278c3b4@changeid (mailing list archive) |
---|---|
State | Accepted |
Commit | d599f714b73e4177dfdfe64fce09175568288ee9 |
Delegated to: | Kalle Valo |
Headers | show |
Series | [for,v5.16] iwlwifi: mvm: don't crash on invalid rate w/o STA | expand |
On Fri, 2021-12-03 at 14:04 +0200, Luca Coelho wrote: > From: Johannes Berg <johannes.berg@intel.com> > > If we get to the WARN_ONCE(..., "Got a HT rate (...)", ...) > here with a NULL sta, then we crash because mvmsta is bad > and we try to dereference it. Fix that by printing -1 as the > state if no station was given. > > Signed-off-by: Johannes Berg <johannes.berg@intel.com> > Fixes: 6761a718263a ("iwlwifi: mvm: add explicit check for non-data frames in get Tx rate") > Signed-off-by: Luca Coelho <luciano.coelho@intel.com> > --- Kalle, Can you take this one directly to wireless-drivers? This fixes a kernel crash in some situations. -- Cheers, Luca.
Luca Coelho <luca@coelho.fi> writes: > On Fri, 2021-12-03 at 14:04 +0200, Luca Coelho wrote: >> From: Johannes Berg <johannes.berg@intel.com> >> >> If we get to the WARN_ONCE(..., "Got a HT rate (...)", ...) >> here with a NULL sta, then we crash because mvmsta is bad >> and we try to dereference it. Fix that by printing -1 as the >> state if no station was given. >> >> Signed-off-by: Johannes Berg <johannes.berg@intel.com> >> Fixes: 6761a718263a ("iwlwifi: mvm: add explicit check for non-data >> frames in get Tx rate") >> Signed-off-by: Luca Coelho <luciano.coelho@intel.com> >> --- > > Kalle, > > Can you take this one directly to wireless-drivers? This fixes a kernel > crash in some situations. Ok, I took the patch in patchwork.
Luca Coelho <luca@coelho.fi> wrote: > From: Johannes Berg <johannes.berg@intel.com> > > If we get to the WARN_ONCE(..., "Got a HT rate (...)", ...) > here with a NULL sta, then we crash because mvmsta is bad > and we try to dereference it. Fix that by printing -1 as the > state if no station was given. > > Signed-off-by: Johannes Berg <johannes.berg@intel.com> > Fixes: 6761a718263a ("iwlwifi: mvm: add explicit check for non-data frames in get Tx rate") > Signed-off-by: Luca Coelho <luciano.coelho@intel.com> Patch applied to wireless-drivers.git, thanks. d599f714b73e iwlwifi: mvm: don't crash on invalid rate w/o STA
diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/tx.c b/drivers/net/wireless/intel/iwlwifi/mvm/tx.c index bdd4ee432548..76e0b7b45980 100644 --- a/drivers/net/wireless/intel/iwlwifi/mvm/tx.c +++ b/drivers/net/wireless/intel/iwlwifi/mvm/tx.c @@ -269,17 +269,18 @@ static u32 iwl_mvm_get_tx_rate(struct iwl_mvm *mvm, u8 rate_plcp; u32 rate_flags = 0; bool is_cck; - struct iwl_mvm_sta *mvmsta = iwl_mvm_sta_from_mac80211(sta); /* info->control is only relevant for non HW rate control */ if (!ieee80211_hw_check(mvm->hw, HAS_RATE_CONTROL)) { + struct iwl_mvm_sta *mvmsta = iwl_mvm_sta_from_mac80211(sta); + /* HT rate doesn't make sense for a non data frame */ WARN_ONCE(info->control.rates[0].flags & IEEE80211_TX_RC_MCS && !ieee80211_is_data(fc), "Got a HT rate (flags:0x%x/mcs:%d/fc:0x%x/state:%d) for a non data frame\n", info->control.rates[0].flags, info->control.rates[0].idx, - le16_to_cpu(fc), mvmsta->sta_state); + le16_to_cpu(fc), sta ? mvmsta->sta_state : -1); rate_idx = info->control.rates[0].idx; }