From: Mohit Mishra <mishraloopmohit@gmail.com>
To: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: linux-staging@lists.linux.dev, linux-kernel@vger.kernel.org,
Mohit Mishra <mishraloopmohit@gmail.com>
Subject: [PATCH] staging: rtl8723bs: fix underflow logic in swing index calculations
Date: Wed, 29 Jul 2026 22:57:07 +0530 [thread overview]
Message-ID: <20260729172707.13333-1-mishraloopmohit@gmail.com> (raw)
In ODM_TxPwrTrackSetPwr_8723B(), the baseband swing index variables
Final_OFDM_Swing_Index and Final_CCK_Swing_Index are declared as u8.
However, their calculation adds Absolute_OFDMSwingIdx, which is a signed
8-bit integer (s8) and can be negative:
Final_OFDM_Swing_Index = pDM_Odm->DefaultOfdmIndex +
pDM_Odm->Absolute_OFDMSwingIdx[RFPath];
If the resulting sum is negative, it underflows under u8 rules (e.g. -5
becomes 251). This causes the lower-limit checks (e.g. <= 0) to fail,
and in MIX_MODE causes the logic to execute the "BBSwing higher than limit"
branch instead of capping to 0.
Additionally, in BBSWING mode, the check for CCK underflow mistakenly
examines the static struct member pDM_Odm->BbSwingIdxCck instead of the
newly calculated Final_CCK_Swing_Index:
else if (pDM_Odm->BbSwingIdxCck <= 0)
Fix this by changing both swing index variable types to int to enable
signed math and correct branch selection (aligning with the TODO item to
convert remaining unusual variable types). Update the CCK check in
BBSWING mode to examine Final_CCK_Swing_Index.
Note: The fix is scoped to the calculation and branching logic. When
passed downstream to setIqkMatrix_8723B() and setCCKFilterCoefficient(),
the values are already clamped within [0, 42], fitting safely in u8.
Compile-tested only; no hardware available for testing.
Signed-off-by: Mohit Mishra <mishraloopmohit@gmail.com>
---
drivers/staging/rtl8723bs/hal/HalPhyRf_8723B.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/staging/rtl8723bs/hal/HalPhyRf_8723B.c b/drivers/staging/rtl8723bs/hal/HalPhyRf_8723B.c
index 6c5f56d5a1f4..4e89847700f3 100644
--- a/drivers/staging/rtl8723bs/hal/HalPhyRf_8723B.c
+++ b/drivers/staging/rtl8723bs/hal/HalPhyRf_8723B.c
@@ -160,8 +160,8 @@ void ODM_TxPwrTrackSetPwr_8723B(
u8 PwrTrackingLimit_OFDM = 34; /* 0dB */
u8 PwrTrackingLimit_CCK = 28; /* 2dB */
u8 TxRate = 0xFF;
- u8 Final_OFDM_Swing_Index = 0;
- u8 Final_CCK_Swing_Index = 0;
+ int Final_OFDM_Swing_Index = 0;
+ int Final_CCK_Swing_Index = 0;
{
u16 rate = *(pDM_Odm->pForcedDataRate);
@@ -217,7 +217,7 @@ void ODM_TxPwrTrackSetPwr_8723B(
if (Final_CCK_Swing_Index >= CCK_TABLE_SIZE)
Final_CCK_Swing_Index = CCK_TABLE_SIZE-1;
- else if (pDM_Odm->BbSwingIdxCck <= 0)
+ else if (Final_CCK_Swing_Index <= 0)
Final_CCK_Swing_Index = 0;
setIqkMatrix_8723B(pDM_Odm, Final_OFDM_Swing_Index, RFPath,
--
2.43.0
next reply other threads:[~2026-07-29 17:27 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 17:27 Mohit Mishra [this message]
2026-07-30 7:39 ` [PATCH] staging: rtl8723bs: fix underflow logic in swing index calculations Greg Kroah-Hartman
2026-07-30 8:50 ` Mohit Mishra
2026-07-30 9:25 ` Greg Kroah-Hartman
2026-07-30 9:45 ` Nikolay Kulikov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260729172707.13333-1-mishraloopmohit@gmail.com \
--to=mishraloopmohit@gmail.com \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-staging@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.