From: Johannes Berg <johannes@sipsolutions.net>
To: linux-wireless <linux-wireless@vger.kernel.org>
Cc: "John W. Linville" <linville@tuxdriver.com>,
Michael Wu <flamingice@sourmilk.net>,
Kalle Valo <Kalle.Valo@nokia.com>
Subject: [PATCH v2] mac80211: don't send invalid QoS frames
Date: Fri, 31 Aug 2007 13:37:13 +0200 [thread overview]
Message-ID: <1188560233.7585.37.camel@johannes.berg> (raw)
In-Reply-To: <1188483732.3978.13.camel@johannes.berg>
Subject: [PATCH] mac80211: don't send invalid QoS frames
Kalle Valo noticed that QoS frames are sent with an invalid QoS control
field; this is because we increase the header length but neither
initialise the space nor actually have enough space in the header
structure for the QoS control field.
This patch fixes it by treating the QoS field specially and appending it
explicitly, initialising it to zero.
Signed-off-by: Johannes Berg <johannes@sipsolutions.net>
---
Kalle, please check if this fixes the weird frames you saw. I think it
will but would like to be sure. If it does, please say so and then we
should merge this patch to 2.6.24 and wireless-dev and I may make one
for -stable as well.
I think this is nicer than my previous patch because it explicitly
appends the QoS field and gives us a place to modify it should we ever
want.
net/mac80211/tx.c | 15 ++++++++++++++-
1 file changed, 14 insertions(+), 1 deletion(-)
--- wireless-dev.orig/net/mac80211/tx.c 2007-08-31 04:20:21.982792130 +0200
+++ wireless-dev/net/mac80211/tx.c 2007-08-31 13:26:22.252784387 +0200
@@ -1493,7 +1493,20 @@ int ieee80211_subif_start_xmit(struct sk
nh_pos += encaps_len;
h_pos += encaps_len;
}
- memcpy(skb_push(skb, hdrlen), &hdr, hdrlen);
+
+ if (fc & IEEE80211_STYPE_QOS_DATA) {
+ __le16 *qos_control;
+
+ qos_control = (__le16*) skb_push(skb, 2);
+ memcpy(skb_push(skb, hdrlen - 2), &hdr, hdrlen - 2);
+ /*
+ * Maybe we could actually set some fields here, for now just
+ * initialise to zero to indicate no special operation.
+ */
+ *qos_control = 0;
+ } else
+ memcpy(skb_push(skb, hdrlen), &hdr, hdrlen);
+
nh_pos += hdrlen;
h_pos += hdrlen;
prev parent reply other threads:[~2007-08-31 21:51 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-08-30 14:22 [PATCH] mac80211: don't send invalid QoS frames Johannes Berg
2007-08-31 8:43 ` Kalle Valo
2007-08-31 10:12 ` Johannes Berg
2007-08-31 11:25 ` Johannes Berg
2007-08-31 11:37 ` Johannes Berg [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1188560233.7585.37.camel@johannes.berg \
--to=johannes@sipsolutions.net \
--cc=Kalle.Valo@nokia.com \
--cc=flamingice@sourmilk.net \
--cc=linux-wireless@vger.kernel.org \
--cc=linville@tuxdriver.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox