* [PATCH rtw-next 1/3] wifi: rtw89: ser: reset map of associated links when L2 SER
2026-09-23 7:27 [PATCH rtw-next 0/3] wifi: rtw89: add out-of-bound checking and reset map for hw_reconfig flow Ping-Ke Shih
@ 2026-09-23 7:27 ` Ping-Ke Shih
2026-09-30 2:17 ` Ping-Ke Shih
2026-09-23 7:27 ` [PATCH rtw-next 2/3] wifi: rtw89: wow: check AOAC report C2H event length Ping-Ke Shih
2026-09-23 7:27 ` [PATCH rtw-next 3/3] wifi: rtw89: wow: check AOAC report key index Ping-Ke Shih
2 siblings, 1 reply; 5+ messages in thread
From: Ping-Ke Shih @ 2026-09-23 7:27 UTC (permalink / raw)
To: linux-wireless; +Cc: gary.chang, kevin_yang
From: Zong-Zhe Yang <kevin_yang@realtek.com>
There is a map used to record the associated links by MAC ID, but L2 SER
(system error recovery) will invoke ieee80211_restart_hw to reset things.
After ieee80211_restart_hw, the associated links will re-configure, but
each associated link might not use the same MAC ID as the original one.
If an associated link doesn't and the old MAC ID is not re-used, the map
keeps the old pair of old MAC ID and it. And then, if somehow HW fills a
wrong MAC ID, e.g. the old MAC ID above, in RX, SW will still obtain the
associated link. Once the one is really disconnected, the memory will be
freed and this case will cause problems.
So, reset entire map of associated links before ieee80211_restart_hw call.
Signed-off-by: Zong-Zhe Yang <kevin_yang@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
---
drivers/net/wireless/realtek/rtw89/ser.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/drivers/net/wireless/realtek/rtw89/ser.c b/drivers/net/wireless/realtek/rtw89/ser.c
index 701440bd7be1..045dac0bd1db 100644
--- a/drivers/net/wireless/realtek/rtw89/ser.c
+++ b/drivers/net/wireless/realtek/rtw89/ser.c
@@ -354,6 +354,14 @@ static void ser_deinit_cam(struct rtw89_dev *rtwdev, struct rtw89_vif *rtwvif)
bitmap_zero(rtwdev->cam_info.ba_cam_map, RTW89_MAX_BA_CAM_NUM);
}
+static void ser_reset_assoc_links(struct rtw89_dev *rtwdev)
+{
+ for (int i = 0; i < RTW89_MAX_MAC_ID_NUM; i++)
+ rcu_assign_pointer(rtwdev->assoc_link_on_macid[i], NULL);
+
+ synchronize_rcu();
+}
+
static void ser_reset_mac_binding(struct rtw89_dev *rtwdev)
{
struct rtw89_vif *rtwvif;
@@ -362,6 +370,7 @@ static void ser_reset_mac_binding(struct rtw89_dev *rtwdev)
rtw89_for_each_rtwvif(rtwdev, rtwvif)
ser_deinit_cam(rtwdev, rtwvif);
+ ser_reset_assoc_links(rtwdev);
rtw89_core_release_all_bits_map(rtwdev->mac_id_map, RTW89_MAX_MAC_ID_NUM);
rtw89_for_each_rtwvif(rtwdev, rtwvif)
ser_reset_vif(rtwdev, rtwvif);
--
2.25.1
^ permalink raw reply related [flat|nested] 5+ messages in thread* Re: [PATCH rtw-next 1/3] wifi: rtw89: ser: reset map of associated links when L2 SER
2026-09-23 7:27 ` [PATCH rtw-next 1/3] wifi: rtw89: ser: reset map of associated links when L2 SER Ping-Ke Shih
@ 2026-09-30 2:17 ` Ping-Ke Shih
0 siblings, 0 replies; 5+ messages in thread
From: Ping-Ke Shih @ 2026-09-30 2:17 UTC (permalink / raw)
To: Ping-Ke Shih, linux-wireless; +Cc: gary.chang, kevin_yang
Ping-Ke Shih <pkshih@realtek.com> wrote:
> From: Zong-Zhe Yang <kevin_yang@realtek.com>
>
> There is a map used to record the associated links by MAC ID, but L2 SER
> (system error recovery) will invoke ieee80211_restart_hw to reset things.
> After ieee80211_restart_hw, the associated links will re-configure, but
> each associated link might not use the same MAC ID as the original one.
> If an associated link doesn't and the old MAC ID is not re-used, the map
> keeps the old pair of old MAC ID and it. And then, if somehow HW fills a
> wrong MAC ID, e.g. the old MAC ID above, in RX, SW will still obtain the
> associated link. Once the one is really disconnected, the memory will be
> freed and this case will cause problems.
>
> So, reset entire map of associated links before ieee80211_restart_hw call.
>
> Signed-off-by: Zong-Zhe Yang <kevin_yang@realtek.com>
> Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
3 patch(es) applied to rtw-next branch of rtw.git, thanks.
533c404af22c wifi: rtw89: ser: reset map of associated links when L2 SER
39884f761fe6 wifi: rtw89: wow: check AOAC report C2H event length
cab0aec92072 wifi: rtw89: wow: check AOAC report key index
---
https://github.com/pkshih/rtw.git
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH rtw-next 2/3] wifi: rtw89: wow: check AOAC report C2H event length
2026-09-23 7:27 [PATCH rtw-next 0/3] wifi: rtw89: add out-of-bound checking and reset map for hw_reconfig flow Ping-Ke Shih
2026-09-23 7:27 ` [PATCH rtw-next 1/3] wifi: rtw89: ser: reset map of associated links when L2 SER Ping-Ke Shih
@ 2026-09-23 7:27 ` Ping-Ke Shih
2026-09-23 7:27 ` [PATCH rtw-next 3/3] wifi: rtw89: wow: check AOAC report key index Ping-Ke Shih
2 siblings, 0 replies; 5+ messages in thread
From: Ping-Ke Shih @ 2026-09-23 7:27 UTC (permalink / raw)
To: linux-wireless; +Cc: gary.chang, kevin_yang
From: Chih-Kang Chang <gary.chang@realtek.com>
The AOAC report C2H event contains fixed-size fields including GTK
and IGTK. The received C2H skb may contain less data than the expected
AOAC report size.
Check the skb length before processing the AOAC report to ensure the
complete report is available.
Signed-off-by: Chih-Kang Chang <gary.chang@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
---
drivers/net/wireless/realtek/rtw89/mac.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/net/wireless/realtek/rtw89/mac.c b/drivers/net/wireless/realtek/rtw89/mac.c
index 093291e8854d..ad849e4b4a50 100644
--- a/drivers/net/wireless/realtek/rtw89/mac.c
+++ b/drivers/net/wireless/realtek/rtw89/mac.c
@@ -5897,6 +5897,13 @@ rtw89_mac_c2h_wow_aoac_rpt(struct rtw89_dev *rtwdev, struct sk_buff *skb, u32 le
(const struct rtw89_c2h_wow_aoac_report *)skb->data;
struct rtw89_completion_data data = {};
+ if (skb->len < sizeof(*c2h)) {
+ rtw89_warn(rtwdev, "wow: aoac rpt skb len %u is too short\n",
+ skb->len);
+ data.err = true;
+ goto out;
+ }
+
aoac_rpt->rpt_ver = c2h->rpt_ver;
aoac_rpt->sec_type = c2h->sec_type;
aoac_rpt->key_idx = c2h->key_idx;
@@ -5913,6 +5920,7 @@ rtw89_mac_c2h_wow_aoac_rpt(struct rtw89_dev *rtwdev, struct sk_buff *skb, u32 le
aoac_rpt->igtk_ipn = le64_to_cpu(c2h->igtk_ipn);
memcpy(aoac_rpt->igtk, c2h->igtk, sizeof(aoac_rpt->igtk));
+out:
rtw89_complete_cond(wait, RTW89_WOW_WAIT_COND_AOAC, &data);
}
--
2.25.1
^ permalink raw reply related [flat|nested] 5+ messages in thread* [PATCH rtw-next 3/3] wifi: rtw89: wow: check AOAC report key index
2026-09-23 7:27 [PATCH rtw-next 0/3] wifi: rtw89: add out-of-bound checking and reset map for hw_reconfig flow Ping-Ke Shih
2026-09-23 7:27 ` [PATCH rtw-next 1/3] wifi: rtw89: ser: reset map of associated links when L2 SER Ping-Ke Shih
2026-09-23 7:27 ` [PATCH rtw-next 2/3] wifi: rtw89: wow: check AOAC report C2H event length Ping-Ke Shih
@ 2026-09-23 7:27 ` Ping-Ke Shih
2 siblings, 0 replies; 5+ messages in thread
From: Ping-Ke Shih @ 2026-09-23 7:27 UTC (permalink / raw)
To: linux-wireless; +Cc: gary.chang, kevin_yang
From: Chih-Kang Chang <gary.chang@realtek.com>
Check the key index reported by firmware before updating the GTK RX IV
information in the AOAC report.
The key index is obtained from the firmware C2H register and is used
to select the GTK RX IV entry. Make sure the reported index is within
the available GTK RX IV entries before processing the report.
Signed-off-by: Chih-Kang Chang <gary.chang@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
---
drivers/net/wireless/realtek/rtw89/wow.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/realtek/rtw89/wow.c b/drivers/net/wireless/realtek/rtw89/wow.c
index 0bf34692c7ce..7a2d6904951f 100644
--- a/drivers/net/wireless/realtek/rtw89/wow.c
+++ b/drivers/net/wireless/realtek/rtw89/wow.c
@@ -546,6 +546,9 @@ static int rtw89_wow_get_aoac_rpt_reg(struct rtw89_dev *rtwdev)
aoac_rpt->key_idx =
u32_get_bits(c2h_info.u.c2hreg[0], RTW89_C2HREG_AOAC_RPT_1_W0_KEY_IDX);
key_idx = aoac_rpt->key_idx;
+ if (key_idx >= ARRAY_SIZE(aoac_rpt->gtk_rx_iv))
+ return -EINVAL;
+
aoac_rpt->gtk_rx_iv[key_idx][0] =
u32_get_bits(c2h_info.u.c2hreg[1], RTW89_C2HREG_AOAC_RPT_1_W1_IV_0);
aoac_rpt->gtk_rx_iv[key_idx][1] =
--
2.25.1
^ permalink raw reply related [flat|nested] 5+ messages in thread