All of lore.kernel.org
 help / color / mirror / Atom feed
From: Slawomir Stepien <sst@poczta.fm>
To: syzbot <syzbot@kernel.org>
Cc: syzkaller-upstream-moderation@googlegroups.com, syzbot@lists.linux.dev
Subject: Re: [PATCH RFC v3] wifi: mac80211: reject station association if AP is not started
Date: Wed, 22 Jul 2026 09:46:41 +0200	[thread overview]
Message-ID: <amB1YWWPFBPDzOyf@nr200> (raw)
In-Reply-To: <9524f34c-7766-4543-a49c-a9fe48fd9d1e@mail.kernel.org>

On lip 16, 2026 08:22, 'syzbot' via syzkaller-upstream-moderation wrote:
> If an interface is changed to AP mode but not started, its channel context
> configuration (chanctx_conf) remains NULL. If a station is then added to
> this interface, the kernel may automatically set the
> NL80211_STA_FLAG_ASSOCIATED flag for compatibility with older userspace
> applications.
> 
> When this flag is set, sta_apply_auth_flags() attempts to initialize rate
> control for the station by calling rate_control_rate_init_all_links(). This
> eventually leads to rate_control_rate_init(), which dereferences the NULL
> chanctx_conf, triggering a WARN_ON:
> 
> WARNING: net/mac80211/rate.c:51 at rate_control_rate_init+0x5a6/0x630
> ...
> Call Trace:
>  <TASK>
>  rate_control_rate_init_all_links+0xf4/0x190 net/mac80211/rate.c:84
>  sta_apply_auth_flags+0x1bc/0x430 net/mac80211/cfg.c:2152
>  sta_apply_parameters+0x126d/0x1b10 net/mac80211/cfg.c:2618
>  ieee80211_add_station+0x3de/0x700 net/mac80211/cfg.c:2684
>  rdev_add_station+0xfc/0x290 net/wireless/rdev-ops.h:201
>  nl80211_new_station+0x1b4e/0x1fd0 net/wireless/nl80211.c:9505
> 
> Fix this by rejecting the addition or modification of a station to the
> associated state if the AP has not been started (chanctx_conf is NULL).
> Exempt Multi-Link Operation (MLO) interfaces from this check, as they
> handle chanctx_conf per-link rather than globally on the VIF.
> 
> Fixes: 55de908ab292 ("mac80211: use channel contexts")
> Assisted-by: Gemini:gemini-3.1-pro-preview Gemini:gemini-3-flash-preview syzbot
> Reported-by: syzbot+9bdc0c5998ab45b05030@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=9bdc0c5998ab45b05030
> Link: https://syzkaller.appspot.com/ai_job?id=0c474d56-8871-480a-8ac4-9a9658930b46
> To: "Johannes Berg" <johannes@sipsolutions.net>
> To: <linux-wireless@vger.kernel.org>
> Cc: <linux-kernel@vger.kernel.org>
> 
> ---
> v3:
> - Added an empty line after the newly added code block for better readability.
> 
> v2:
> - Moved the chanctx_conf check inside the WLAN_STA_RATE_CONTROL check block.
> - Removed a phrase from the commit description as requested by reviewers.
> https://lore.kernel.org/all/79cbf145-6652-4e15-be67-f7974ebc29cb@mail.kernel.org/T/
> 
> v1:
> https://lore.kernel.org/all/8e8a5122-a09e-43b2-b42f-4c73b021b173@mail.kernel.org/T/
> ---
> diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c
> index 3b58af59f..d4331fbae 100644
> --- a/net/mac80211/cfg.c
> +++ b/net/mac80211/cfg.c
> @@ -2148,8 +2148,14 @@ static int sta_apply_auth_flags(struct ieee80211_local *local,
>  		 * well. Some drivers require rate control initialized
>  		 * before drv_sta_state() is called.
>  		 */
> -		if (!test_sta_flag(sta, WLAN_STA_RATE_CONTROL))
> +		if (!test_sta_flag(sta, WLAN_STA_RATE_CONTROL)) {
> +			if (!ieee80211_vif_is_mld(&sta->sdata->vif) &&
> +			    !rcu_access_pointer(
> +				    sta->sdata->vif.bss_conf.chanctx_conf))

Don't worry about 80 column limit (it is 100 for some time now in scripts/checkpatch.pl). Make this
a one line please: !rcu_access_pointer(sta->sdata->vif.bss_conf.chanctx_conf))

> +				return -EINVAL;
> +
>  			rate_control_rate_init_all_links(sta);
> +		}
>  
>  		ret = sta_info_move_state(sta, IEEE80211_STA_ASSOC);
>  		if (ret)
> 
> 
> base-commit: dc59e4fea9d83f03bad6bddf3fa2e52491777482

-- 
Slawomir Stepien

      reply	other threads:[~2026-07-22  7:46 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-16  8:22 [PATCH RFC v3] wifi: mac80211: reject station association if AP is not started syzbot
2026-07-22  7:46 ` Slawomir Stepien [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=amB1YWWPFBPDzOyf@nr200 \
    --to=sst@poczta.fm \
    --cc=syzbot@kernel.org \
    --cc=syzbot@lists.linux.dev \
    --cc=syzkaller-upstream-moderation@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.