From: Rory Little <roryl@candelatech.com>
To: Johannes Berg <johannes@sipsolutions.net>
Cc: linux-wireless@vger.kernel.org,
Dylan Eskew <dylan.eskew@candelatech.com>
Subject: [PATCH wireless-next v2] net: cfg80211: validate monitor channel set against radio usage
Date: Mon, 21 Sep 2026 11:46:05 -0700 [thread overview]
Message-ID: <20260921184605.2699-1-roryl@candelatech.com> (raw)
In-Reply-To: <2318ac388c0da7a200c8a1aec0d0af662fdf1ba8.camel@sipsolutions.net>
Current logic only looks globally at interface counts to validate that a
monitor can have its channel configured. This works to ensure that the
wiphy is not pulled off the channel currently being used by another
active interface, but fails to allow for the case where the channels in
use on the other active interface and the desired channel for the
monitor fall on disjoint sets of radios.
Instead, search for any interface which would cause conflict, otherwise
allowing for the configuration.
Suggested-by: Dylan Eskew <dylan.eskew@candelatech.com>
Signed-off-by: Rory Little <roryl@candelatech.com>
---
v2:
- Handle error return from cfg80211_get_radio_idx_by_chan
- Fixed subject line
net/wireless/chan.c | 29 ++++++++++++++++++++++++++++-
1 file changed, 28 insertions(+), 1 deletion(-)
diff --git a/net/wireless/chan.c b/net/wireless/chan.c
index 1071e823108b..679f1152ba65 100644
--- a/net/wireless/chan.c
+++ b/net/wireless/chan.c
@@ -1810,13 +1810,40 @@ bool cfg80211_reg_check_beaconing(struct wiphy *wiphy,
}
EXPORT_SYMBOL(cfg80211_reg_check_beaconing);
+static bool cfg80211_can_set_monitor_channel(struct cfg80211_registered_device *rdev,
+ struct cfg80211_chan_def *chandef)
+{
+ struct wireless_dev *wdev;
+ int radio_idx;
+
+ lockdep_assert_held(&rdev->wiphy.mtx);
+
+ if (cfg80211_has_monitors_only(rdev))
+ return true;
+
+ radio_idx = cfg80211_get_radio_idx_by_chan(&rdev->wiphy, chandef->chan);
+ if (radio_idx < 0)
+ return false;
+
+ list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
+ if (wdev->iftype == NL80211_IFTYPE_MONITOR)
+ continue;
+ if (!wdev->netdev)
+ continue;
+ if (rdev_get_radio_mask(rdev, wdev->netdev) & BIT(radio_idx))
+ return false;
+ }
+
+ return true;
+}
+
int cfg80211_set_monitor_channel(struct cfg80211_registered_device *rdev,
struct net_device *dev,
struct cfg80211_chan_def *chandef)
{
if (!rdev->ops->set_monitor_channel)
return -EOPNOTSUPP;
- if (!cfg80211_has_monitors_only(rdev))
+ if (!cfg80211_can_set_monitor_channel(rdev, chandef))
return -EBUSY;
return rdev_set_monitor_channel(rdev, dev, chandef);
--
2.52.0
next prev parent reply other threads:[~2026-09-21 18:56 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 17:07 [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage Rory Little
2026-09-21 9:04 ` Johannes Berg
2026-09-21 18:46 ` Rory Little [this message]
2026-09-21 18:59 ` [PATCH wireless-next v2] net: cfg80211: validate " Johannes Berg
2026-09-21 20:17 ` Rory Little
2026-09-21 20:20 ` Johannes Berg
2026-09-21 20:55 ` Rory Little
2026-09-21 21:04 ` [PATCH wireless-next v3] wifi: " Rory Little
2026-09-21 18:46 ` [PATCH wireless-next] net: cfg80211: Validate " Rory Little
2026-09-21 12:04 ` [syzbot ci] " syzbot ci
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260921184605.2699-1-roryl@candelatech.com \
--to=roryl@candelatech.com \
--cc=dylan.eskew@candelatech.com \
--cc=johannes@sipsolutions.net \
--cc=linux-wireless@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox