* [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage
@ 2026-09-17 22:12 Rory Little
2026-09-20 10:49 ` [syzbot ci] " syzbot ci
0 siblings, 1 reply; 5+ messages in thread
From: Rory Little @ 2026-09-17 22:12 UTC (permalink / raw)
To: Johannes Berg; +Cc: linux-wireless, Dylan Eskew
Current logic only looks globally at interface counts to validate that a
monitor can have its channel configured. This works to ensure that the
wiphy is not pulled off the channel currently being used by another
active interface, but fails to allow for the case where the channels in
use on the other active interface and the desired channel for the
monitor fall on disjoint sets of radios.
Instead, search for any interface which would cause conflict, otherwise
allowing for the configuration.
Suggested-by: Dylan Eskew <dylan.eskew@candelatech.com>
Signed-off-by: Rory Little <roryl@candelatech.com>
---
net/wireless/chan.c | 27 ++++++++++++++++++++++++++-
1 file changed, 26 insertions(+), 1 deletion(-)
diff --git a/net/wireless/chan.c b/net/wireless/chan.c
index 1071e823108b..e417649a543a 100644
--- a/net/wireless/chan.c
+++ b/net/wireless/chan.c
@@ -1810,13 +1810,38 @@ bool cfg80211_reg_check_beaconing(struct wiphy *wiphy,
}
EXPORT_SYMBOL(cfg80211_reg_check_beaconing);
+static bool cfg80211_can_set_monitor_channel(struct cfg80211_registered_device *rdev,
+ struct cfg80211_chan_def *chandef)
+{
+ struct wireless_dev *wdev;
+ int radio_idx;
+
+ lockdep_assert_held(&rdev->wiphy.mtx);
+
+ if (cfg80211_has_monitors_only(rdev))
+ return true;
+
+ radio_idx = cfg80211_get_radio_idx_by_chan(&rdev->wiphy, chandef->chan);
+
+ list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
+ if (wdev->iftype == NL80211_IFTYPE_MONITOR)
+ continue;
+ if (!wdev->netdev)
+ continue;
+ if (rdev_get_radio_mask(rdev, wdev->netdev) & BIT(radio_idx))
+ return false;
+ }
+
+ return true;
+}
+
int cfg80211_set_monitor_channel(struct cfg80211_registered_device *rdev,
struct net_device *dev,
struct cfg80211_chan_def *chandef)
{
if (!rdev->ops->set_monitor_channel)
return -EOPNOTSUPP;
- if (!cfg80211_has_monitors_only(rdev))
+ if (!cfg80211_can_set_monitor_channel(rdev, chandef))
return -EBUSY;
return rdev_set_monitor_channel(rdev, dev, chandef);
--
2.52.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage
@ 2026-09-18 17:07 Rory Little
2026-09-21 9:04 ` Johannes Berg
0 siblings, 1 reply; 5+ messages in thread
From: Rory Little @ 2026-09-18 17:07 UTC (permalink / raw)
To: Johannes Berg; +Cc: linux-wireless, Dylan Eskew
Current logic only looks globally at interface counts to validate that a
monitor can have its channel configured. This works to ensure that the
wiphy is not pulled off the channel currently being used by another
active interface, but fails to allow for the case where the channels in
use on the other active interface and the desired channel for the
monitor fall on disjoint sets of radios.
Instead, search for any interface which would cause conflict, otherwise
allowing for the configuration.
Suggested-by: Dylan Eskew <dylan.eskew@candelatech.com>
Signed-off-by: Rory Little <roryl@candelatech.com>
---
net/wireless/chan.c | 27 ++++++++++++++++++++++++++-
1 file changed, 26 insertions(+), 1 deletion(-)
diff --git a/net/wireless/chan.c b/net/wireless/chan.c
index 1071e823108b..e417649a543a 100644
--- a/net/wireless/chan.c
+++ b/net/wireless/chan.c
@@ -1810,13 +1810,38 @@ bool cfg80211_reg_check_beaconing(struct wiphy *wiphy,
}
EXPORT_SYMBOL(cfg80211_reg_check_beaconing);
+static bool cfg80211_can_set_monitor_channel(struct cfg80211_registered_device *rdev,
+ struct cfg80211_chan_def *chandef)
+{
+ struct wireless_dev *wdev;
+ int radio_idx;
+
+ lockdep_assert_held(&rdev->wiphy.mtx);
+
+ if (cfg80211_has_monitors_only(rdev))
+ return true;
+
+ radio_idx = cfg80211_get_radio_idx_by_chan(&rdev->wiphy, chandef->chan);
+
+ list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
+ if (wdev->iftype == NL80211_IFTYPE_MONITOR)
+ continue;
+ if (!wdev->netdev)
+ continue;
+ if (rdev_get_radio_mask(rdev, wdev->netdev) & BIT(radio_idx))
+ return false;
+ }
+
+ return true;
+}
+
int cfg80211_set_monitor_channel(struct cfg80211_registered_device *rdev,
struct net_device *dev,
struct cfg80211_chan_def *chandef)
{
if (!rdev->ops->set_monitor_channel)
return -EOPNOTSUPP;
- if (!cfg80211_has_monitors_only(rdev))
+ if (!cfg80211_can_set_monitor_channel(rdev, chandef))
return -EBUSY;
return rdev_set_monitor_channel(rdev, dev, chandef);
--
2.52.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [syzbot ci] Re: net: cfg80211: Validate monitor channel set against radio usage
2026-09-17 22:12 [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage Rory Little
@ 2026-09-20 10:49 ` syzbot ci
0 siblings, 0 replies; 5+ messages in thread
From: syzbot ci @ 2026-09-20 10:49 UTC (permalink / raw)
To: dylan.eskew, johannes, linux-wireless, roryl; +Cc: syzbot, syzkaller-bugs
syzbot ci has tested the following series
[v1] net: cfg80211: Validate monitor channel set against radio usage
https://lore.kernel.org/all/20260917221205.3214125-1-roryl@candelatech.com
* [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage
and found the following issue:
UBSAN: shift-out-of-bounds in cfg80211_set_monitor_channel
Full report is available here:
https://ci.syzbot.org/series/096ed229-0401-4402-9865-92c5b6d81b57
***
UBSAN: shift-out-of-bounds in cfg80211_set_monitor_channel
tree: wireless-next
URL: https://kernel.googlesource.com/pub/scm/linux/kernel/git/wireless/wireless-next.git
base: 3b35f726c20d138fafa154182ee926a419306269
arch: amd64
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
config: https://ci.syzbot.org/builds/7147a923-683e-41dc-b623-05cfe4ac2a30/config
syz repro: https://ci.syzbot.org/findings/525583ec-5ed7-4adc-aeab-6eb3b293f9ee/syz_repro
------------[ cut here ]------------
UBSAN: shift-out-of-bounds in net/wireless/chan.c:1831:49
shift exponent -22 is negative
CPU: 1 UID: 0 PID: 5855 Comm: syz.1.18 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
Call Trace:
<TASK>
dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
ubsan_epilogue+0xa/0x30 lib/ubsan.c:233
__ubsan_handle_shift_out_of_bounds+0x36d/0x400 lib/ubsan.c:494
cfg80211_can_set_monitor_channel net/wireless/chan.c:1831 [inline]
cfg80211_set_monitor_channel+0x38a/0x8d0 net/wireless/chan.c:1844
__nl80211_set_channel+0x340/0x990 net/wireless/nl80211.c:4203
nl80211_set_wiphy+0x127c/0x3050 net/wireless/nl80211.c:-1
genl_family_rcv_msg_doit+0x233/0x340 net/netlink/genetlink.c:1114
genl_family_rcv_msg net/netlink/genetlink.c:1194 [inline]
genl_rcv_msg+0x614/0x7a0 net/netlink/genetlink.c:1209
netlink_rcv_skb+0x226/0x4a0 net/netlink/af_netlink.c:2556
genl_rcv+0x28/0x40 net/netlink/genetlink.c:1218
netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline]
netlink_unicast+0x7bd/0x940 net/netlink/af_netlink.c:1345
netlink_sendmsg+0x813/0xb40 net/netlink/af_netlink.c:1900
sock_sendmsg_nosec+0x13a/0x180 net/socket.c:800
__sock_sendmsg net/socket.c:815 [inline]
____sys_sendmsg+0x54e/0x850 net/socket.c:2713
___sys_sendmsg+0x2a5/0x360 net/socket.c:2767
__sys_sendmsg net/socket.c:2799 [inline]
__do_sys_sendmsg net/socket.c:2804 [inline]
__se_sys_sendmsg net/socket.c:2802 [inline]
__x64_sys_sendmsg+0x1b1/0x290 net/socket.c:2802
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f7e3a59e159
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f7e3b3d5028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007f7e3a825fa0 RCX: 00007f7e3a59e159
RDX: 0000000004040000 RSI: 0000200000000040 RDI: 0000000000000003
RBP: 00007f7e3a63506b R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f7e3a826038 R14: 00007f7e3a825fa0 R15: 00007ffd12ef16a8
</TASK>
---[ end trace ]---
***
If these findings have caused you to resend the series or submit a
separate fix, please add the following tag to your commit message:
Tested-by: syzbot@syzkaller.appspotmail.com
---
This report is generated by a bot. It may contain errors.
syzbot ci engineers can be reached at syzkaller@googlegroups.com.
To test a fix for this bug, please reply with `#syz test`
(on a separate line) and attach the patch to the email.
Notes:
- The patch will be applied on top of the tested series (as an
incremental fix).
- To test a new version of the whole series, please send it directly
to syzbot@lists.linux.dev.
- Arguments like custom git repos and branches are not supported.
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage
2026-09-18 17:07 [PATCH wireless-next] " Rory Little
@ 2026-09-21 9:04 ` Johannes Berg
2026-09-21 18:46 ` Rory Little
0 siblings, 1 reply; 5+ messages in thread
From: Johannes Berg @ 2026-09-21 9:04 UTC (permalink / raw)
To: Rory Little; +Cc: linux-wireless, Dylan Eskew
You didn't really have to send it twice :)
Please fix the subject and the syzbot reported issue.
johannes
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage
2026-09-21 9:04 ` Johannes Berg
@ 2026-09-21 18:46 ` Rory Little
0 siblings, 0 replies; 5+ messages in thread
From: Rory Little @ 2026-09-21 18:46 UTC (permalink / raw)
To: Johannes Berg; +Cc: linux-wireless, Dylan Eskew
> You didn't really have to send it twice 🙂
Sorry about that!
> Please fix the subject and the syzbot reported issue.
Will do.
- Rory
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-21 18:46 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-17 22:12 [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage Rory Little
2026-09-20 10:49 ` [syzbot ci] " syzbot ci
-- strict thread matches above, loose matches on Subject: below --
2026-09-18 17:07 [PATCH wireless-next] " Rory Little
2026-09-21 9:04 ` Johannes Berg
2026-09-21 18:46 ` Rory Little
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox