* [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage
@ 2026-09-17 22:12 Rory Little
0 siblings, 0 replies; 11+ messages in thread
From: Rory Little @ 2026-09-17 22:12 UTC (permalink / raw)
To: Johannes Berg; +Cc: linux-wireless, Dylan Eskew
Current logic only looks globally at interface counts to validate that a
monitor can have its channel configured. This works to ensure that the
wiphy is not pulled off the channel currently being used by another
active interface, but fails to allow for the case where the channels in
use on the other active interface and the desired channel for the
monitor fall on disjoint sets of radios.
Instead, search for any interface which would cause conflict, otherwise
allowing for the configuration.
Suggested-by: Dylan Eskew <dylan.eskew@candelatech.com>
Signed-off-by: Rory Little <roryl@candelatech.com>
---
net/wireless/chan.c | 27 ++++++++++++++++++++++++++-
1 file changed, 26 insertions(+), 1 deletion(-)
diff --git a/net/wireless/chan.c b/net/wireless/chan.c
index 1071e823108b..e417649a543a 100644
--- a/net/wireless/chan.c
+++ b/net/wireless/chan.c
@@ -1810,13 +1810,38 @@ bool cfg80211_reg_check_beaconing(struct wiphy *wiphy,
}
EXPORT_SYMBOL(cfg80211_reg_check_beaconing);
+static bool cfg80211_can_set_monitor_channel(struct cfg80211_registered_device *rdev,
+ struct cfg80211_chan_def *chandef)
+{
+ struct wireless_dev *wdev;
+ int radio_idx;
+
+ lockdep_assert_held(&rdev->wiphy.mtx);
+
+ if (cfg80211_has_monitors_only(rdev))
+ return true;
+
+ radio_idx = cfg80211_get_radio_idx_by_chan(&rdev->wiphy, chandef->chan);
+
+ list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
+ if (wdev->iftype == NL80211_IFTYPE_MONITOR)
+ continue;
+ if (!wdev->netdev)
+ continue;
+ if (rdev_get_radio_mask(rdev, wdev->netdev) & BIT(radio_idx))
+ return false;
+ }
+
+ return true;
+}
+
int cfg80211_set_monitor_channel(struct cfg80211_registered_device *rdev,
struct net_device *dev,
struct cfg80211_chan_def *chandef)
{
if (!rdev->ops->set_monitor_channel)
return -EOPNOTSUPP;
- if (!cfg80211_has_monitors_only(rdev))
+ if (!cfg80211_can_set_monitor_channel(rdev, chandef))
return -EBUSY;
return rdev_set_monitor_channel(rdev, dev, chandef);
--
2.52.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage
@ 2026-09-18 17:07 Rory Little
2026-09-21 9:04 ` Johannes Berg
2026-09-21 12:04 ` [syzbot ci] " syzbot ci
0 siblings, 2 replies; 11+ messages in thread
From: Rory Little @ 2026-09-18 17:07 UTC (permalink / raw)
To: Johannes Berg; +Cc: linux-wireless, Dylan Eskew
Current logic only looks globally at interface counts to validate that a
monitor can have its channel configured. This works to ensure that the
wiphy is not pulled off the channel currently being used by another
active interface, but fails to allow for the case where the channels in
use on the other active interface and the desired channel for the
monitor fall on disjoint sets of radios.
Instead, search for any interface which would cause conflict, otherwise
allowing for the configuration.
Suggested-by: Dylan Eskew <dylan.eskew@candelatech.com>
Signed-off-by: Rory Little <roryl@candelatech.com>
---
net/wireless/chan.c | 27 ++++++++++++++++++++++++++-
1 file changed, 26 insertions(+), 1 deletion(-)
diff --git a/net/wireless/chan.c b/net/wireless/chan.c
index 1071e823108b..e417649a543a 100644
--- a/net/wireless/chan.c
+++ b/net/wireless/chan.c
@@ -1810,13 +1810,38 @@ bool cfg80211_reg_check_beaconing(struct wiphy *wiphy,
}
EXPORT_SYMBOL(cfg80211_reg_check_beaconing);
+static bool cfg80211_can_set_monitor_channel(struct cfg80211_registered_device *rdev,
+ struct cfg80211_chan_def *chandef)
+{
+ struct wireless_dev *wdev;
+ int radio_idx;
+
+ lockdep_assert_held(&rdev->wiphy.mtx);
+
+ if (cfg80211_has_monitors_only(rdev))
+ return true;
+
+ radio_idx = cfg80211_get_radio_idx_by_chan(&rdev->wiphy, chandef->chan);
+
+ list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
+ if (wdev->iftype == NL80211_IFTYPE_MONITOR)
+ continue;
+ if (!wdev->netdev)
+ continue;
+ if (rdev_get_radio_mask(rdev, wdev->netdev) & BIT(radio_idx))
+ return false;
+ }
+
+ return true;
+}
+
int cfg80211_set_monitor_channel(struct cfg80211_registered_device *rdev,
struct net_device *dev,
struct cfg80211_chan_def *chandef)
{
if (!rdev->ops->set_monitor_channel)
return -EOPNOTSUPP;
- if (!cfg80211_has_monitors_only(rdev))
+ if (!cfg80211_can_set_monitor_channel(rdev, chandef))
return -EBUSY;
return rdev_set_monitor_channel(rdev, dev, chandef);
--
2.52.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* Re: [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage
2026-09-18 17:07 [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage Rory Little
@ 2026-09-21 9:04 ` Johannes Berg
2026-09-21 18:46 ` [PATCH wireless-next v2] net: cfg80211: validate " Rory Little
2026-09-21 18:46 ` [PATCH wireless-next] net: cfg80211: Validate " Rory Little
2026-09-21 12:04 ` [syzbot ci] " syzbot ci
1 sibling, 2 replies; 11+ messages in thread
From: Johannes Berg @ 2026-09-21 9:04 UTC (permalink / raw)
To: Rory Little; +Cc: linux-wireless, Dylan Eskew
You didn't really have to send it twice :)
Please fix the subject and the syzbot reported issue.
johannes
^ permalink raw reply [flat|nested] 11+ messages in thread
* [syzbot ci] Re: net: cfg80211: Validate monitor channel set against radio usage
2026-09-18 17:07 [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage Rory Little
2026-09-21 9:04 ` Johannes Berg
@ 2026-09-21 12:04 ` syzbot ci
1 sibling, 0 replies; 11+ messages in thread
From: syzbot ci @ 2026-09-21 12:04 UTC (permalink / raw)
To: dylan.eskew, johannes, linux-wireless, roryl; +Cc: syzbot, syzkaller-bugs
syzbot ci has tested the following series
[v1] net: cfg80211: Validate monitor channel set against radio usage
https://lore.kernel.org/all/20260918170746.3824-1-roryl@candelatech.com
* [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage
and found the following issues:
* UBSAN: shift-out-of-bounds in cfg80211_set_monitor_channel
* UBSAN: shift-out-of-bounds in corrupted
Full report is available here:
https://ci.syzbot.org/series/8cc9e8b7-7ee7-4960-86f8-d3d32e74b751
***
UBSAN: shift-out-of-bounds in cfg80211_set_monitor_channel
tree: wireless-next
URL: https://kernel.googlesource.com/pub/scm/linux/kernel/git/wireless/wireless-next.git
base: 3b35f726c20d138fafa154182ee926a419306269
arch: amd64
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
config: https://ci.syzbot.org/builds/007f6283-0b6e-4ff9-84e0-69128d745e0c/config
syz repro: https://ci.syzbot.org/findings/ba5a8e20-28a0-4771-b097-95a9703e3244/syz_repro
UBSAN: shift-out-of-bounds in net/wireless/chan.c:1831:49
shift exponent -22 is negative
CPU: 0 UID: 0 PID: 5850 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
Call Trace:
<TASK>
dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
ubsan_epilogue+0xa/0x30 lib/ubsan.c:233
__ubsan_handle_shift_out_of_bounds+0x36d/0x400 lib/ubsan.c:494
cfg80211_can_set_monitor_channel net/wireless/chan.c:1831 [inline]
cfg80211_set_monitor_channel+0x38a/0x8d0 net/wireless/chan.c:1844
__nl80211_set_channel+0x340/0x990 net/wireless/nl80211.c:4203
nl80211_set_wiphy+0x127c/0x3050 net/wireless/nl80211.c:-1
genl_family_rcv_msg_doit+0x233/0x340 net/netlink/genetlink.c:1114
genl_family_rcv_msg net/netlink/genetlink.c:1194 [inline]
genl_rcv_msg+0x614/0x7a0 net/netlink/genetlink.c:1209
netlink_rcv_skb+0x226/0x4a0 net/netlink/af_netlink.c:2556
genl_rcv+0x28/0x40 net/netlink/genetlink.c:1218
netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline]
netlink_unicast+0x7bd/0x940 net/netlink/af_netlink.c:1345
netlink_sendmsg+0x813/0xb40 net/netlink/af_netlink.c:1900
sock_sendmsg_nosec+0x13a/0x180 net/socket.c:800
__sock_sendmsg net/socket.c:815 [inline]
____sys_sendmsg+0x54e/0x850 net/socket.c:2713
___sys_sendmsg+0x2a5/0x360 net/socket.c:2767
__sys_sendmsg net/socket.c:2799 [inline]
__do_sys_sendmsg net/socket.c:2804 [inline]
__se_sys_sendmsg net/socket.c:2802 [inline]
__x64_sys_sendmsg+0x1b1/0x290 net/socket.c:2802
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fc73059e159
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fc731480028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007fc730825fa0 RCX: 00007fc73059e159
RDX: 0000000004040000 RSI: 0000200000000040 RDI: 0000000000000003
RBP: 00007fc73063506b R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fc730826038 R14: 00007fc730825fa0 R15: 00007ffd4fd500b8
</TASK>
---[ end trace ]---
***
UBSAN: shift-out-of-bounds in corrupted
tree: wireless-next
URL: https://kernel.googlesource.com/pub/scm/linux/kernel/git/wireless/wireless-next.git
base: 3b35f726c20d138fafa154182ee926a419306269
arch: amd64
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
config: https://ci.syzbot.org/builds/007f6283-0b6e-4ff9-84e0-69128d745e0c/config
------------[ cut here ]------------
UBSAN: shift-out-of-bounds in net/wireless/chan.c:1831:49
shift exponent -22 is negative
CPU: 0 UID: 0 PID: 6635 Comm: syz.3.380 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
Call Trace:
Call Trace:
<TASK>
dump_stack_lvl+0xe8/0x150
ubsan_epilogue+0xa/0x30
__ubsan_handle_shift_out_of_bounds+0x36d/0x400
cfg80211_set_monitor_channel+0x38a/0x8d0
__nl80211_set_channel+0x340/0x990
nl80211_set_wiphy+0x127c/0x3050
genl_family_rcv_msg_doit+0x233/0x340
genl_rcv_msg+0x614/0x7a0
netlink_rcv_skb+0x226/0x4a0
genl_rcv+0x28/0x40
netlink_unicast+0x7bd/0x940
netlink_sendmsg+0x813/0xb40
sock_sendmsg_nosec+0x13a/0x180
____sys_sendmsg+0x54e/0x850
___sys_sendmsg+0x2a5/0x360
__x64_sys_sendmsg+0x1b1/0x290
do_syscall_64+0x166/0x520
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7fbeb4b9e159
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fbeb5aef028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e
RAX: ffffffffffffffda RBX: 00007fbeb4e25fa0 RCX: 00007fbeb4b9e159
RDX: 0000000004040000 RSI: 0000200000000040 RDI: 0000000000000003
RBP: 00007fbeb4c3506b R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007fbeb4e26038 R14: 00007fbeb4e25fa0 R15: 00007ffe46366df8
</TASK>
---[ end trace ]---
***
If these findings have caused you to resend the series or submit a
separate fix, please add the following tag to your commit message:
Tested-by: syzbot@syzkaller.appspotmail.com
---
This report is generated by a bot. It may contain errors.
syzbot ci engineers can be reached at syzkaller@googlegroups.com.
To test a fix for this bug, please reply with `#syz test`
(on a separate line) and attach the patch to the email.
Notes:
- The patch will be applied on top of the tested series (as an
incremental fix).
- To test a new version of the whole series, please send it directly
to syzbot@lists.linux.dev.
- Arguments like custom git repos and branches are not supported.
^ permalink raw reply [flat|nested] 11+ messages in thread
* [PATCH wireless-next v2] net: cfg80211: validate monitor channel set against radio usage
2026-09-21 9:04 ` Johannes Berg
@ 2026-09-21 18:46 ` Rory Little
2026-09-21 18:59 ` Johannes Berg
2026-09-21 21:04 ` [PATCH wireless-next v3] wifi: " Rory Little
2026-09-21 18:46 ` [PATCH wireless-next] net: cfg80211: Validate " Rory Little
1 sibling, 2 replies; 11+ messages in thread
From: Rory Little @ 2026-09-21 18:46 UTC (permalink / raw)
To: Johannes Berg; +Cc: linux-wireless, Dylan Eskew
Current logic only looks globally at interface counts to validate that a
monitor can have its channel configured. This works to ensure that the
wiphy is not pulled off the channel currently being used by another
active interface, but fails to allow for the case where the channels in
use on the other active interface and the desired channel for the
monitor fall on disjoint sets of radios.
Instead, search for any interface which would cause conflict, otherwise
allowing for the configuration.
Suggested-by: Dylan Eskew <dylan.eskew@candelatech.com>
Signed-off-by: Rory Little <roryl@candelatech.com>
---
v2:
- Handle error return from cfg80211_get_radio_idx_by_chan
- Fixed subject line
net/wireless/chan.c | 29 ++++++++++++++++++++++++++++-
1 file changed, 28 insertions(+), 1 deletion(-)
diff --git a/net/wireless/chan.c b/net/wireless/chan.c
index 1071e823108b..679f1152ba65 100644
--- a/net/wireless/chan.c
+++ b/net/wireless/chan.c
@@ -1810,13 +1810,40 @@ bool cfg80211_reg_check_beaconing(struct wiphy *wiphy,
}
EXPORT_SYMBOL(cfg80211_reg_check_beaconing);
+static bool cfg80211_can_set_monitor_channel(struct cfg80211_registered_device *rdev,
+ struct cfg80211_chan_def *chandef)
+{
+ struct wireless_dev *wdev;
+ int radio_idx;
+
+ lockdep_assert_held(&rdev->wiphy.mtx);
+
+ if (cfg80211_has_monitors_only(rdev))
+ return true;
+
+ radio_idx = cfg80211_get_radio_idx_by_chan(&rdev->wiphy, chandef->chan);
+ if (radio_idx < 0)
+ return false;
+
+ list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
+ if (wdev->iftype == NL80211_IFTYPE_MONITOR)
+ continue;
+ if (!wdev->netdev)
+ continue;
+ if (rdev_get_radio_mask(rdev, wdev->netdev) & BIT(radio_idx))
+ return false;
+ }
+
+ return true;
+}
+
int cfg80211_set_monitor_channel(struct cfg80211_registered_device *rdev,
struct net_device *dev,
struct cfg80211_chan_def *chandef)
{
if (!rdev->ops->set_monitor_channel)
return -EOPNOTSUPP;
- if (!cfg80211_has_monitors_only(rdev))
+ if (!cfg80211_can_set_monitor_channel(rdev, chandef))
return -EBUSY;
return rdev_set_monitor_channel(rdev, dev, chandef);
--
2.52.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
* Re: [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage
2026-09-21 9:04 ` Johannes Berg
2026-09-21 18:46 ` [PATCH wireless-next v2] net: cfg80211: validate " Rory Little
@ 2026-09-21 18:46 ` Rory Little
1 sibling, 0 replies; 11+ messages in thread
From: Rory Little @ 2026-09-21 18:46 UTC (permalink / raw)
To: Johannes Berg; +Cc: linux-wireless, Dylan Eskew
> You didn't really have to send it twice 🙂
Sorry about that!
> Please fix the subject and the syzbot reported issue.
Will do.
- Rory
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: [PATCH wireless-next v2] net: cfg80211: validate monitor channel set against radio usage
2026-09-21 18:46 ` [PATCH wireless-next v2] net: cfg80211: validate " Rory Little
@ 2026-09-21 18:59 ` Johannes Berg
2026-09-21 20:17 ` Rory Little
2026-09-21 21:04 ` [PATCH wireless-next v3] wifi: " Rory Little
1 sibling, 1 reply; 11+ messages in thread
From: Johannes Berg @ 2026-09-21 18:59 UTC (permalink / raw)
To: Rory Little; +Cc: linux-wireless, Dylan Eskew
On Mon, 2026-09-21 at 11:46 -0700, Rory Little wrote:
>
> - Handle error return from cfg80211_get_radio_idx_by_chan
Yes, but did you do it correctly? I don't think so?
> - Fixed subject line
No? "wifi:" instead of "net:"
johannes
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: [PATCH wireless-next v2] net: cfg80211: validate monitor channel set against radio usage
2026-09-21 18:59 ` Johannes Berg
@ 2026-09-21 20:17 ` Rory Little
2026-09-21 20:20 ` Johannes Berg
0 siblings, 1 reply; 11+ messages in thread
From: Rory Little @ 2026-09-21 20:17 UTC (permalink / raw)
To: Johannes Berg; +Cc: linux-wireless, Dylan Eskew
>> - Handle error return from cfg80211_get_radio_idx_by_chan
> Yes, but did you do it correctly? I don't think so?
You mean propagating -EINVAL out to the caller, right? I'd need to
handle the n_radio == 0 case to keep the -EBUSY behavior consistent.
>> - Fixed subject line
> No? "wifi:" instead of "net:"
Oops, I read that as a casing comment. Will fix in v3.
- Rory
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: [PATCH wireless-next v2] net: cfg80211: validate monitor channel set against radio usage
2026-09-21 20:17 ` Rory Little
@ 2026-09-21 20:20 ` Johannes Berg
2026-09-21 20:55 ` Rory Little
0 siblings, 1 reply; 11+ messages in thread
From: Johannes Berg @ 2026-09-21 20:20 UTC (permalink / raw)
To: Rory Little; +Cc: linux-wireless, Dylan Eskew
On Mon, 2026-09-21 at 13:17 -0700, Rory Little wrote:
> > > - Handle error return from cfg80211_get_radio_idx_by_chan
> > Yes, but did you do it correctly? I don't think so?
>
> You mean propagating -EINVAL out to the caller, right? I'd need to
> handle the n_radio == 0 case to keep the -EBUSY behavior consistent.
Yeah, I get that, but it seemed tgo me it should return true (accepting
the channel change) - but then again maybe not, since it already accepts
"only have monitors", and then getting there means there's something
else ... sorry.
johannes
^ permalink raw reply [flat|nested] 11+ messages in thread
* Re: [PATCH wireless-next v2] net: cfg80211: validate monitor channel set against radio usage
2026-09-21 20:20 ` Johannes Berg
@ 2026-09-21 20:55 ` Rory Little
0 siblings, 0 replies; 11+ messages in thread
From: Rory Little @ 2026-09-21 20:55 UTC (permalink / raw)
To: Johannes Berg; +Cc: linux-wireless, Dylan Eskew
On 9/21/26 13:20, Johannes Berg wrote:
> On Mon, 2026-09-21 at 13:17 -0700, Rory Little wrote:
>>>> - Handle error return from cfg80211_get_radio_idx_by_chan
>>> Yes, but did you do it correctly? I don't think so?
>> You mean propagating -EINVAL out to the caller, right? I'd need to
>> handle the n_radio == 0 case to keep the -EBUSY behavior consistent.
> Yeah, I get that, but it seemed tgo me it should return true (accepting
> the channel change) - but then again maybe not, since it already accepts
> "only have monitors", and then getting there means there's something
> else ... sorry.
Yeah, if we are there then there are other interfaces up, so rejecting
at that point keeps the existing behavior. I'll add a comment clarifying
that.
On a different note, I also noticed that this introduced an issue -
cfg80211_has_monitors_only also verifies that there is at least one
active interface. This patch loses that verification for multi-radio
wiphys. I will fix this in v3.
- Rory
^ permalink raw reply [flat|nested] 11+ messages in thread
* [PATCH wireless-next v3] wifi: cfg80211: validate monitor channel set against radio usage
2026-09-21 18:46 ` [PATCH wireless-next v2] net: cfg80211: validate " Rory Little
2026-09-21 18:59 ` Johannes Berg
@ 2026-09-21 21:04 ` Rory Little
1 sibling, 0 replies; 11+ messages in thread
From: Rory Little @ 2026-09-21 21:04 UTC (permalink / raw)
To: Johannes Berg; +Cc: linux-wireless, Dylan Eskew
Current logic only looks globally at interface counts to validate that a
monitor can have its channel configured. This works to ensure that the
wiphy is not pulled off the channel currently being used by another
active interface, but fails to allow for the case where the channels in
use on the other active interface and the desired channel for the
monitor fall on disjoint sets of radios.
Instead, search for any interface which would cause conflict, otherwise
allowing for the configuration.
Suggested-by: Dylan Eskew <dylan.eskew@candelatech.com>
Signed-off-by: Rory Little <roryl@candelatech.com>
---
v3:
- Reject case where no monitors are running
- Add clarifying comment for radio_idx error path
- Actually fixed subject line
v2:
- Handle error return from cfg80211_get_radio_idx_by_chan
- Fixed subject line
net/wireless/chan.c | 33 ++++++++++++++++++++++++++++++++-
1 file changed, 32 insertions(+), 1 deletion(-)
diff --git a/net/wireless/chan.c b/net/wireless/chan.c
index 1071e823108b..c743b6fb7e30 100644
--- a/net/wireless/chan.c
+++ b/net/wireless/chan.c
@@ -1810,13 +1810,44 @@ bool cfg80211_reg_check_beaconing(struct wiphy *wiphy,
}
EXPORT_SYMBOL(cfg80211_reg_check_beaconing);
+static bool cfg80211_can_set_monitor_channel(struct cfg80211_registered_device *rdev,
+ struct cfg80211_chan_def *chandef)
+{
+ struct wireless_dev *wdev;
+ int radio_idx;
+
+ lockdep_assert_held(&rdev->wiphy.mtx);
+
+ if (rdev->num_running_monitor_ifaces < 1)
+ return false;
+
+ if (cfg80211_has_monitors_only(rdev))
+ return true;
+
+ radio_idx = cfg80211_get_radio_idx_by_chan(&rdev->wiphy, chandef->chan);
+ /* No defined radio covers this channel. Fall back on global behavior */
+ if (radio_idx < 0)
+ return false;
+
+ list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
+ if (wdev->iftype == NL80211_IFTYPE_MONITOR)
+ continue;
+ if (!wdev->netdev)
+ continue;
+ if (rdev_get_radio_mask(rdev, wdev->netdev) & BIT(radio_idx))
+ return false;
+ }
+
+ return true;
+}
+
int cfg80211_set_monitor_channel(struct cfg80211_registered_device *rdev,
struct net_device *dev,
struct cfg80211_chan_def *chandef)
{
if (!rdev->ops->set_monitor_channel)
return -EOPNOTSUPP;
- if (!cfg80211_has_monitors_only(rdev))
+ if (!cfg80211_can_set_monitor_channel(rdev, chandef))
return -EBUSY;
return rdev_set_monitor_channel(rdev, dev, chandef);
--
2.52.0
^ permalink raw reply related [flat|nested] 11+ messages in thread
end of thread, other threads:[~2026-09-21 21:15 UTC | newest]
Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-18 17:07 [PATCH wireless-next] net: cfg80211: Validate monitor channel set against radio usage Rory Little
2026-09-21 9:04 ` Johannes Berg
2026-09-21 18:46 ` [PATCH wireless-next v2] net: cfg80211: validate " Rory Little
2026-09-21 18:59 ` Johannes Berg
2026-09-21 20:17 ` Rory Little
2026-09-21 20:20 ` Johannes Berg
2026-09-21 20:55 ` Rory Little
2026-09-21 21:04 ` [PATCH wireless-next v3] wifi: " Rory Little
2026-09-21 18:46 ` [PATCH wireless-next] net: cfg80211: Validate " Rory Little
2026-09-21 12:04 ` [syzbot ci] " syzbot ci
-- strict thread matches above, loose matches on Subject: below --
2026-09-17 22:12 [PATCH wireless-next] " Rory Little
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox