All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
To: Benjamin Berg <benjamin@sipsolutions.net>,
	linux-wireless@vger.kernel.org
Cc: Jeff Johnson <jjohnson@kernel.org>,
	Miri Korenblit <miriam.rachel.korenblit@intel.com>,
	Felix Fietkau <nbd@nbd.name>,
	Lorenzo Bianconi <lorenzo@kernel.org>,
	Ryder Lee <ryder.lee@mediatek.com>,
	Ping-Ke Shih <pkshih@realtek.com>,
	Johannes Berg <johannes@sipsolutions.net>,
	ath11k@lists.infradead.org, ath12k@lists.infradead.org,
	Benjamin Berg <benjamin.berg@intel.com>
Subject: Re: [PATCH wireless-next v3 2/8] wifi: mac80211: change public RX API to use link stations
Date: Thu, 20 Aug 2026 10:56:14 -0700	[thread overview]
Message-ID: <1bdf4b7d-2f05-4ae3-8304-60697d2c849d@oss.qualcomm.com> (raw)
In-Reply-To: <20260819155703.af6d319e6b61.I4a2d45609e94b52654b10ec572e59a45d09c41f4@changeid>

On 8/19/2026 6:57 AM, Benjamin Berg wrote:
> diff --git a/drivers/net/wireless/mediatek/mt76/mac80211.c b/drivers/net/wireless/mediatek/mt76/mac80211.c
> index abbe65cbcd89..3da06a55913e 100644
> --- a/drivers/net/wireless/mediatek/mt76/mac80211.c
> +++ b/drivers/net/wireless/mediatek/mt76/mac80211.c
> @@ -1255,7 +1255,7 @@ EXPORT_SYMBOL(mt76_rx_signal);
>  static void
>  mt76_rx_convert(struct mt76_dev *dev, struct sk_buff *skb,
>  		struct ieee80211_hw **hw,
> -		struct ieee80211_sta **sta)
> +		struct ieee80211_link_sta **link_sta)
>  {
>  	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
>  	struct ieee80211_hdr *hdr = mt76_skb_get_hdr(skb);
> @@ -1302,11 +1302,15 @@ mt76_rx_convert(struct mt76_dev *dev, struct sk_buff *skb,
>  	       sizeof(mstat.chain_signal));
>  
>  	if (mstat.wcid) {
> -		status->link_valid = mstat.wcid->link_valid;
> -		status->link_id = mstat.wcid->link_id;
> +		struct ieee80211_sta *sta = wcid_to_sta(mstat.wcid);
> +
> +		if (mstat.wcid->link_valid)
> +			*link_sta =
> +				rcu_dereference(sta->link[mstat.wcid->link_id]);
> +		else
> +			*link_sta = &sta->deflink;
>  	}
>  
> -	*sta = wcid_to_sta(mstat.wcid);
>  	*hw = mt76_phy_hw(dev, mstat.phy_idx);
>  }
>  
> @@ -1530,7 +1534,7 @@ mt76_check_sta(struct mt76_dev *dev, struct sk_buff *skb)
>  void mt76_rx_complete(struct mt76_dev *dev, struct sk_buff_head *frames,
>  		      struct napi_struct *napi)
>  {
> -	struct ieee80211_sta *sta;
> +	struct ieee80211_link_sta *link_sta;

My review agent says:
**Issue 1 — mt76: uninitialized `link_sta` pointer on the no-wcid path.**

In `mt76_rx_complete()`, `link_sta` is declared but not initialized to NULL.

Then `mt76_rx_convert()` is called, which only sets `*link_sta` when
`mstat.wcid != NULL`. If `mstat.wcid` is NULL, `link_sta` remains
uninitialized and is then passed to `ieee80211_rx_list()`. This is a use of
an uninitialized pointer. The fix is trivially `= NULL`.

>  	struct ieee80211_hw *hw;
>  	struct sk_buff *skb, *tmp;
>  	LIST_HEAD(list);
> @@ -1541,8 +1545,8 @@ void mt76_rx_complete(struct mt76_dev *dev, struct sk_buff_head *frames,
>  
>  		mt76_check_ccmp_pn(skb);
>  		skb_shinfo(skb)->frag_list = NULL;
> -		mt76_rx_convert(dev, skb, &hw, &sta);
> -		ieee80211_rx_list(hw, sta, skb, &list);
> +		mt76_rx_convert(dev, skb, &hw, &link_sta);
> +		ieee80211_rx_list(hw, link_sta, skb, &list);
>  
>  		/* subsequent amsdu frames */
>  		while (nskb) {
> @@ -1550,8 +1554,8 @@ void mt76_rx_complete(struct mt76_dev *dev, struct sk_buff_head *frames,
>  			nskb = nskb->next;
>  			skb->next = NULL;
>  
> -			mt76_rx_convert(dev, skb, &hw, &sta);
> -			ieee80211_rx_list(hw, sta, skb, &list);
> +			mt76_rx_convert(dev, skb, &hw, &link_sta);
> +			ieee80211_rx_list(hw, link_sta, skb, &list);
>  		}
>  	}
>  	spin_unlock(&dev->rx_lock);


  parent reply	other threads:[~2026-08-20 17:56 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-19 13:57 [PATCH wireless-next v3 0/8] Adding NO_STA flag and reworking RX link resolution Benjamin Berg
2026-08-19 13:57 ` [PATCH wireless-next v3 1/8] wifi: iwlwifi: use link_sta internally to the driver Benjamin Berg
2026-08-19 13:57 ` [PATCH wireless-next v3 2/8] wifi: mac80211: change public RX API to use link stations Benjamin Berg
2026-08-20 16:12   ` Devin Wittmayer
2026-08-20 17:56   ` Jeff Johnson [this message]
2026-08-20 23:15     ` Devin Wittmayer
2026-08-19 13:57 ` [PATCH wireless-next v3 3/8] wifi: mac80211: refactor RX link_id and station handling Benjamin Berg
2026-08-19 13:57 ` [PATCH wireless-next v3 4/8] wifi: mac80211: rework RX packet handling Benjamin Berg
2026-08-19 13:57 ` [PATCH wireless-next v3 5/8] wifi: cfg80211: add attribute for TX/RX denoting there is no station Benjamin Berg
2026-08-20 18:12   ` Jeff Johnson
2026-08-19 13:57 ` [PATCH wireless-next v3 6/8] wifi: mac80211: report to cfg80211 when no STA is known for a frame Benjamin Berg
2026-08-19 13:57 ` [PATCH wireless-next v3 7/8] wifi: mac80211: pass station to ieee80211_tx_skb_tid Benjamin Berg
2026-08-19 13:57 ` [PATCH wireless-next v3 8/8] uwifi: mac80211: pass error station if non-STA transmit was requested Benjamin Berg
2026-08-20 17:40   ` Jeff Johnson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1bdf4b7d-2f05-4ae3-8304-60697d2c849d@oss.qualcomm.com \
    --to=jeff.johnson@oss.qualcomm.com \
    --cc=ath11k@lists.infradead.org \
    --cc=ath12k@lists.infradead.org \
    --cc=benjamin.berg@intel.com \
    --cc=benjamin@sipsolutions.net \
    --cc=jjohnson@kernel.org \
    --cc=johannes@sipsolutions.net \
    --cc=linux-wireless@vger.kernel.org \
    --cc=lorenzo@kernel.org \
    --cc=miriam.rachel.korenblit@intel.com \
    --cc=nbd@nbd.name \
    --cc=pkshih@realtek.com \
    --cc=ryder.lee@mediatek.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.