All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH for v5.16] iwlwifi: mvm: don't crash on invalid rate w/o STA
@ 2021-12-03 12:04 Luca Coelho
  2021-12-03 12:05 ` Luca Coelho
  2021-12-08 18:15 ` Kalle Valo
  0 siblings, 2 replies; 4+ messages in thread
From: Luca Coelho @ 2021-12-03 12:04 UTC (permalink / raw)
  To: kvalo; +Cc: luca, linux-wireless

From: Johannes Berg <johannes.berg@intel.com>

If we get to the WARN_ONCE(..., "Got a HT rate (...)", ...)
here with a NULL sta, then we crash because mvmsta is bad
and we try to dereference it. Fix that by printing -1 as the
state if no station was given.

Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Fixes: 6761a718263a ("iwlwifi: mvm: add explicit check for non-data frames in get Tx rate")
Signed-off-by: Luca Coelho <luciano.coelho@intel.com>
---
 drivers/net/wireless/intel/iwlwifi/mvm/tx.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/tx.c b/drivers/net/wireless/intel/iwlwifi/mvm/tx.c
index bdd4ee432548..76e0b7b45980 100644
--- a/drivers/net/wireless/intel/iwlwifi/mvm/tx.c
+++ b/drivers/net/wireless/intel/iwlwifi/mvm/tx.c
@@ -269,17 +269,18 @@ static u32 iwl_mvm_get_tx_rate(struct iwl_mvm *mvm,
 	u8 rate_plcp;
 	u32 rate_flags = 0;
 	bool is_cck;
-	struct iwl_mvm_sta *mvmsta = iwl_mvm_sta_from_mac80211(sta);
 
 	/* info->control is only relevant for non HW rate control */
 	if (!ieee80211_hw_check(mvm->hw, HAS_RATE_CONTROL)) {
+		struct iwl_mvm_sta *mvmsta = iwl_mvm_sta_from_mac80211(sta);
+
 		/* HT rate doesn't make sense for a non data frame */
 		WARN_ONCE(info->control.rates[0].flags & IEEE80211_TX_RC_MCS &&
 			  !ieee80211_is_data(fc),
 			  "Got a HT rate (flags:0x%x/mcs:%d/fc:0x%x/state:%d) for a non data frame\n",
 			  info->control.rates[0].flags,
 			  info->control.rates[0].idx,
-			  le16_to_cpu(fc), mvmsta->sta_state);
+			  le16_to_cpu(fc), sta ? mvmsta->sta_state : -1);
 
 		rate_idx = info->control.rates[0].idx;
 	}
-- 
2.33.1


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH for v5.16] iwlwifi: mvm: don't crash on invalid rate w/o STA
  2021-12-03 12:04 [PATCH for v5.16] iwlwifi: mvm: don't crash on invalid rate w/o STA Luca Coelho
@ 2021-12-03 12:05 ` Luca Coelho
  2021-12-03 12:26   ` Kalle Valo
  2021-12-08 18:15 ` Kalle Valo
  1 sibling, 1 reply; 4+ messages in thread
From: Luca Coelho @ 2021-12-03 12:05 UTC (permalink / raw)
  To: kvalo; +Cc: linux-wireless

On Fri, 2021-12-03 at 14:04 +0200, Luca Coelho wrote:
> From: Johannes Berg <johannes.berg@intel.com>
> 
> If we get to the WARN_ONCE(..., "Got a HT rate (...)", ...)
> here with a NULL sta, then we crash because mvmsta is bad
> and we try to dereference it. Fix that by printing -1 as the
> state if no station was given.
> 
> Signed-off-by: Johannes Berg <johannes.berg@intel.com>
> Fixes: 6761a718263a ("iwlwifi: mvm: add explicit check for non-data frames in get Tx rate")
> Signed-off-by: Luca Coelho <luciano.coelho@intel.com>
> ---

Kalle,

Can you take this one directly to wireless-drivers? This fixes a kernel
crash in some situations.

--
Cheers,
Luca.

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH for v5.16] iwlwifi: mvm: don't crash on invalid rate w/o STA
  2021-12-03 12:05 ` Luca Coelho
@ 2021-12-03 12:26   ` Kalle Valo
  0 siblings, 0 replies; 4+ messages in thread
From: Kalle Valo @ 2021-12-03 12:26 UTC (permalink / raw)
  To: Luca Coelho; +Cc: linux-wireless

Luca Coelho <luca@coelho.fi> writes:

> On Fri, 2021-12-03 at 14:04 +0200, Luca Coelho wrote:
>> From: Johannes Berg <johannes.berg@intel.com>
>> 
>> If we get to the WARN_ONCE(..., "Got a HT rate (...)", ...)
>> here with a NULL sta, then we crash because mvmsta is bad
>> and we try to dereference it. Fix that by printing -1 as the
>> state if no station was given.
>> 
>> Signed-off-by: Johannes Berg <johannes.berg@intel.com>
>> Fixes: 6761a718263a ("iwlwifi: mvm: add explicit check for non-data
>> frames in get Tx rate")
>> Signed-off-by: Luca Coelho <luciano.coelho@intel.com>
>> ---
>
> Kalle,
>
> Can you take this one directly to wireless-drivers? This fixes a kernel
> crash in some situations.

Ok, I took the patch in patchwork.

-- 
https://patchwork.kernel.org/project/linux-wireless/list/

https://wireless.wiki.kernel.org/en/developers/documentation/submittingpatches

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH for v5.16] iwlwifi: mvm: don't crash on invalid rate w/o STA
  2021-12-03 12:04 [PATCH for v5.16] iwlwifi: mvm: don't crash on invalid rate w/o STA Luca Coelho
  2021-12-03 12:05 ` Luca Coelho
@ 2021-12-08 18:15 ` Kalle Valo
  1 sibling, 0 replies; 4+ messages in thread
From: Kalle Valo @ 2021-12-08 18:15 UTC (permalink / raw)
  To: Luca Coelho; +Cc: kvalo, luca, linux-wireless

Luca Coelho <luca@coelho.fi> wrote:

> From: Johannes Berg <johannes.berg@intel.com>
> 
> If we get to the WARN_ONCE(..., "Got a HT rate (...)", ...)
> here with a NULL sta, then we crash because mvmsta is bad
> and we try to dereference it. Fix that by printing -1 as the
> state if no station was given.
> 
> Signed-off-by: Johannes Berg <johannes.berg@intel.com>
> Fixes: 6761a718263a ("iwlwifi: mvm: add explicit check for non-data frames in get Tx rate")
> Signed-off-by: Luca Coelho <luciano.coelho@intel.com>

Patch applied to wireless-drivers.git, thanks.

d599f714b73e iwlwifi: mvm: don't crash on invalid rate w/o STA

-- 
https://patchwork.kernel.org/project/linux-wireless/patch/iwlwifi.20211203140410.1a1541d7dcb5.I606c746e11447fe168cf046376b70b04e278c3b4@changeid/

https://wireless.wiki.kernel.org/en/developers/documentation/submittingpatches


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2021-12-08 18:15 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2021-12-03 12:04 [PATCH for v5.16] iwlwifi: mvm: don't crash on invalid rate w/o STA Luca Coelho
2021-12-03 12:05 ` Luca Coelho
2021-12-03 12:26   ` Kalle Valo
2021-12-08 18:15 ` Kalle Valo

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.