Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 0/2] wifi: mt76: fix USB copy source overreads
@ 2026-09-25 15:05 Jiale Yao
  2026-09-25 15:05 ` [PATCH 1/2] wifi: mt76: usb: fix source overread in mt76u_copy Jiale Yao
  2026-09-25 15:05 ` [PATCH 2/2] wifi: mt76: mt7615: usb: fix source overread in mt7663u_copy Jiale Yao
  0 siblings, 2 replies; 3+ messages in thread
From: Jiale Yao @ 2026-09-25 15:05 UTC (permalink / raw)
  To: Felix Fietkau, Lorenzo Bianconi, Ryder Lee, Shayne Chen,
	Sean Wang, Matthias Brugger, AngeloGioacchino Del Regno,
	Johan Hovold, Markus Theil, linux-wireless, linux-kernel,
	linux-arm-kernel, linux-mediatek
  Cc: Jiale Yao

The USB copy helpers round up the caller's length to four bytes and
then use the rounded length as the bound for memcpy() from the source
buffer. If the caller supplies a length that is not a multiple of four,
the final transfer reads one to three bytes past the source buffer.
The beacon write path can pass such an unaligned length.

The MMIO copy helpers already handle their unaligned tail through a
four-byte bounce buffer. Apply the same principle to the USB helpers:
keep the original length as the source-copy bound and zero the unused
bytes in the transmit buffer so that the register access width remains
four-byte aligned.

The two patches are independent and both apply to the same baseline:

  wifi: mt76: usb: fix source overread in mt76u_copy
  wifi: mt76: mt7615: usb: fix source overread in mt7663u_copy

Jiale Yao (2):
  wifi: mt76: usb: fix source overread in mt76u_copy
  wifi: mt76: mt7615: usb: fix source overread in mt7663u_copy

 drivers/net/wireless/mediatek/mt76/mt7615/usb.c | 17 ++++++++++++-----
 drivers/net/wireless/mediatek/mt76/usb.c        | 16 +++++++++++-----
 2 files changed, 23 insertions(+), 10 deletions(-)

-- 
2.34.1



^ permalink raw reply	[flat|nested] 3+ messages in thread

* [PATCH 1/2] wifi: mt76: usb: fix source overread in mt76u_copy
  2026-09-25 15:05 [PATCH 0/2] wifi: mt76: fix USB copy source overreads Jiale Yao
@ 2026-09-25 15:05 ` Jiale Yao
  2026-09-25 15:05 ` [PATCH 2/2] wifi: mt76: mt7615: usb: fix source overread in mt7663u_copy Jiale Yao
  1 sibling, 0 replies; 3+ messages in thread
From: Jiale Yao @ 2026-09-25 15:05 UTC (permalink / raw)
  To: Felix Fietkau, Lorenzo Bianconi, Ryder Lee, Shayne Chen,
	Sean Wang, Matthias Brugger, AngeloGioacchino Del Regno,
	Markus Theil, linux-wireless, linux-kernel, linux-arm-kernel,
	linux-mediatek
  Cc: Jiale Yao

mt76u_copy() rounds up len to a multiple of four and uses the rounded
length as the bound for memcpy() from the source buffer. When the
caller's length is not four-byte aligned, the final copy reads up to
three bytes past the source buffer.

Keep the original length for the source copy and zero the remaining
bytes in the transmit buffer so that the hardware access width remains
four-byte aligned.

Fixes: 9446248669968 ("mt76: speed up usb bulk copy")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/net/wireless/mediatek/mt76/usb.c | 16 +++++++++++-----
 1 file changed, 11 insertions(+), 5 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/usb.c b/drivers/net/wireless/mediatek/mt76/usb.c
index a9af3aa6b80a..a42a33f4e907 100644
--- a/drivers/net/wireless/mediatek/mt76/usb.c
+++ b/drivers/net/wireless/mediatek/mt76/usb.c
@@ -171,8 +171,10 @@ static void mt76u_copy(struct mt76_dev *dev, u32 offset,
 {
 	struct mt76_usb *usb = &dev->usb;
 	const u8 *val = data;
-	int ret;
 	int current_batch_size;
+	int len_aligned;
+	int copy_len;
+	int ret;
 	int i = 0;
 
 	/* Assure that always a multiple of 4 bytes are copied,
@@ -180,12 +182,16 @@ static void mt76u_copy(struct mt76_dev *dev, u32 offset,
 	 * See: "mt76: round up length on mt76_wr_copy"
 	 * Commit 850e8f6fbd5d0003b0
 	 */
-	len = round_up(len, 4);
+	len_aligned = round_up(len, 4);
 
 	mutex_lock(&usb->usb_ctrl_mtx);
-	while (i < len) {
-		current_batch_size = min_t(int, usb->data_len, len - i);
-		memcpy(usb->data, val + i, current_batch_size);
+	while (i < len_aligned) {
+		current_batch_size = min_t(int, usb->data_len, len_aligned - i);
+		copy_len = min_t(int, current_batch_size, len - i);
+		memcpy(usb->data, val + i, copy_len);
+		if (copy_len < current_batch_size)
+			memset(usb->data + copy_len, 0,
+			       current_batch_size - copy_len);
 		ret = __mt76u_vendor_request(dev, MT_VEND_MULTI_WRITE,
 					     USB_DIR_OUT | USB_TYPE_VENDOR,
 					     0, offset + i, usb->data,
-- 
2.34.1



^ permalink raw reply related	[flat|nested] 3+ messages in thread

* [PATCH 2/2] wifi: mt76: mt7615: usb: fix source overread in mt7663u_copy
  2026-09-25 15:05 [PATCH 0/2] wifi: mt76: fix USB copy source overreads Jiale Yao
  2026-09-25 15:05 ` [PATCH 1/2] wifi: mt76: usb: fix source overread in mt76u_copy Jiale Yao
@ 2026-09-25 15:05 ` Jiale Yao
  1 sibling, 0 replies; 3+ messages in thread
From: Jiale Yao @ 2026-09-25 15:05 UTC (permalink / raw)
  To: Felix Fietkau, Lorenzo Bianconi, Ryder Lee, Shayne Chen,
	Sean Wang, Matthias Brugger, AngeloGioacchino Del Regno,
	Johan Hovold, linux-wireless, linux-kernel, linux-arm-kernel,
	linux-mediatek
  Cc: Jiale Yao

mt7663u_copy() rounds up len to a multiple of four and uses the rounded
length as the bound for memcpy() from the source buffer. When the
caller's length is not four-byte aligned, the final copy reads up to
three bytes past the source buffer.

Keep the original length for the source copy and zero the remaining
bytes in the transmit buffer so that the hardware access width remains
four-byte aligned.

Fixes: 6cb596ba84e3 ("mt76: usb: introduce __mt76u_init utility routine")
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
 drivers/net/wireless/mediatek/mt76/mt7615/usb.c | 17 ++++++++++++-----
 1 file changed, 12 insertions(+), 5 deletions(-)

diff --git a/drivers/net/wireless/mediatek/mt76/mt7615/usb.c b/drivers/net/wireless/mediatek/mt76/mt7615/usb.c
index bab7b91f14be..3629e3d9bf47 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7615/usb.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7615/usb.c
@@ -58,15 +58,22 @@ static void mt7663u_copy(struct mt76_dev *dev, u32 offset,
 			 const void *data, int len)
 {
 	struct mt76_usb *usb = &dev->usb;
-	int ret, i = 0, batch_len;
 	const u8 *val = data;
+	int len_aligned;
+	int batch_len;
+	int copy_len;
+	int ret;
+	int i = 0;
 
-	len = round_up(len, 4);
+	len_aligned = round_up(len, 4);
 
 	mutex_lock(&usb->usb_ctrl_mtx);
-	while (i < len) {
-		batch_len = min_t(int, usb->data_len, len - i);
-		memcpy(usb->data, val + i, batch_len);
+	while (i < len_aligned) {
+		batch_len = min_t(int, usb->data_len, len_aligned - i);
+		copy_len = min_t(int, batch_len, len - i);
+		memcpy(usb->data, val + i, copy_len);
+		if (copy_len < batch_len)
+			memset(usb->data + copy_len, 0, batch_len - copy_len);
 		ret = __mt76u_vendor_request(dev, MT_VEND_WRITE_EXT,
 					     USB_DIR_OUT | USB_TYPE_VENDOR,
 					     (offset + i) >> 16, offset + i,
-- 
2.34.1



^ permalink raw reply related	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-25 15:06 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-25 15:05 [PATCH 0/2] wifi: mt76: fix USB copy source overreads Jiale Yao
2026-09-25 15:05 ` [PATCH 1/2] wifi: mt76: usb: fix source overread in mt76u_copy Jiale Yao
2026-09-25 15:05 ` [PATCH 2/2] wifi: mt76: mt7615: usb: fix source overread in mt7663u_copy Jiale Yao

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox