From: Ping-Ke Shih <pkshih@realtek.com>
To: <linux-wireless@vger.kernel.org>
Cc: <dian_syuan0116@realtek.com>, <echuang@realtek.com>,
<phhuang@realtek.com>, <kevin_yang@realtek.com>
Subject: [PATCH rtw-next 07/15] wifi: rtw89: fw: cmd_ofld_flush always reset counter
Date: Wed, 9 Sep 2026 14:59:56 +0800 [thread overview]
Message-ID: <20260909070004.35353-8-pkshih@realtek.com> (raw)
In-Reply-To: <20260909070004.35353-1-pkshih@realtek.com>
From: Zong-Zhe Yang <kevin_yang@realtek.com>
Callers expect cmd offload counter is reset after flushing, and then
use counter++ with array index. Previously, it might cause OOB since
cmd_ofld_flush gets an error, e.g out of memory, and does not reset
the cmd offload counter. Fix cmd_ofld_flush to always reset it.
Resolve OVERRUN (Out-of-bounds write) reported by Coverity.
Pass info to cmd_ofld_flush to make Coverity aware the changes on
cmd offload counter.
Signed-off-by: Zong-Zhe Yang <kevin_yang@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
---
drivers/net/wireless/realtek/rtw89/fw.c | 13 +++++++------
1 file changed, 7 insertions(+), 6 deletions(-)
diff --git a/drivers/net/wireless/realtek/rtw89/fw.c b/drivers/net/wireless/realtek/rtw89/fw.c
index a16127b2c317..dcbdf4b5e4b2 100644
--- a/drivers/net/wireless/realtek/rtw89/fw.c
+++ b/drivers/net/wireless/realtek/rtw89/fw.c
@@ -12643,9 +12643,9 @@ static int rtw89_fw_cmd_ofld_pack(struct rtw89_dev *rtwdev)
return 0;
}
-static void rtw89_fw_cmd_ofld_flush(struct rtw89_dev *rtwdev)
+static void rtw89_fw_cmd_ofld_flush(struct rtw89_dev *rtwdev,
+ struct rtw89_fw_cmd_ofld_info *info)
{
- struct rtw89_fw_cmd_ofld_info *info = rtwdev->fw_cmd_ofld_info;
struct sk_buff *skb;
int ret;
u32 len;
@@ -12654,7 +12654,7 @@ static void rtw89_fw_cmd_ofld_flush(struct rtw89_dev *rtwdev)
skb = rtw89_fw_h2c_alloc_skb_with_hdr(rtwdev, len);
if (!skb) {
rtw89_err(rtwdev, "alloc skb fail\n");
- return;
+ goto out;
}
skb_put_data(skb, info->cmds, len);
@@ -12669,12 +12669,13 @@ static void rtw89_fw_cmd_ofld_flush(struct rtw89_dev *rtwdev)
if (ret) {
rtw89_err(rtwdev, "failed to send cmd ofld\n");
dev_kfree_skb_any(skb);
- return;
+ goto out;
}
if (info->accu_delay)
fsleep(info->accu_delay);
+out:
info->cnt = 0;
info->accu_delay = 0;
}
@@ -12694,7 +12695,7 @@ static int rtw89_fw_cmd_ofld_unpack(struct rtw89_dev *rtwdev)
if (info->cnt == 0)
return 0;
- rtw89_fw_cmd_ofld_flush(rtwdev);
+ rtw89_fw_cmd_ofld_flush(rtwdev, info);
return 0;
}
@@ -12721,7 +12722,7 @@ static int rtw89_fw_cmd_ofld_enqueue(struct rtw89_dev *rtwdev,
return -EFAULT;
if (info->cnt >= ARRAY_SIZE(info->cmds))
- rtw89_fw_cmd_ofld_flush(rtwdev);
+ rtw89_fw_cmd_ofld_flush(rtwdev, info);
h2c = &info->cmds[info->cnt++];
--
2.25.1
next prev parent reply other threads:[~2026-09-09 7:01 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 6:59 [PATCH rtw-next 00/15] wifi: rtw89: correct MLO behavior, fix Coverity issues, and update hardware settings Ping-Ke Shih
2026-09-09 6:59 ` [PATCH rtw-next 01/15] wifi: rtw89: consider sta maximum AMSDU subframes number to decide TX work waiting Ping-Ke Shih
2026-09-09 6:59 ` [PATCH rtw-next 02/15] wifi: rtw89: mlo: update link id to FW upon connection Ping-Ke Shih
2026-09-09 6:59 ` [PATCH rtw-next 03/15] Revert "wifi: rtw89: fix unable to receive probe responses under MLO connection" Ping-Ke Shih
2026-09-09 6:59 ` [PATCH rtw-next 04/15] wifi: rtw89: modify active scan rule for 6GHz band Ping-Ke Shih
2026-09-09 6:59 ` [PATCH rtw-next 05/15] wifi: rtw89: fix ctrl_sco_cck for Wi-Fi 7 Ping-Ke Shih
2026-09-09 6:59 ` [PATCH rtw-next 06/15] wifi: rtw89: 8852a: prevent potential OOB in ctrl_sco_cck Ping-Ke Shih
2026-09-09 6:59 ` Ping-Ke Shih [this message]
2026-09-09 6:59 ` [PATCH rtw-next 08/15] wifi: rtw89: explicitly declare TX queue flags by DECLARE_BITMAP() Ping-Ke Shih
2026-09-09 6:59 ` [PATCH rtw-next 09/15] wifi: rtw89: 8922d: add extra data to PS H2C Ping-Ke Shih
2026-09-09 6:59 ` [PATCH rtw-next 10/15] wifi: rtw89: mac: change beamformee CSI direct forward to CMAC_TXDMA Ping-Ke Shih
2026-09-09 7:00 ` [PATCH rtw-next 11/15] wifi: rtw89: fw: extend ch_info format of hw_scan to v2 Ping-Ke Shih
2026-09-09 7:00 ` [PATCH rtw-next 12/15] wifi: rtw89: 8922d: update BA cam format to G7 Ping-Ke Shih
2026-09-09 7:00 ` [PATCH rtw-next 13/15] wifi: rtw89: 8851b: rfk: set DCK start and delay time Ping-Ke Shih
2026-09-09 7:00 ` [PATCH rtw-next 14/15] wifi: rtw89: 8852b: update default value for ANA SWR Ping-Ke Shih
2026-09-09 7:00 ` [PATCH rtw-next 15/15] wifi: rtw89: phy: correct PHY-1 EDCCA report register access Ping-Ke Shih
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909070004.35353-8-pkshih@realtek.com \
--to=pkshih@realtek.com \
--cc=dian_syuan0116@realtek.com \
--cc=echuang@realtek.com \
--cc=kevin_yang@realtek.com \
--cc=linux-wireless@vger.kernel.org \
--cc=phhuang@realtek.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.