* [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing
@ 2026-09-28 12:43 Johannes Berg
2026-09-28 12:43 ` [PATCH wireless-next 2/2] wifi: cfg80211: type-check (extended) element search functions Johannes Berg
2026-09-28 16:15 ` [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing Johannes Berg
0 siblings, 2 replies; 3+ messages in thread
From: Johannes Berg @ 2026-09-28 12:43 UTC (permalink / raw)
To: linux-wireless; +Cc: Johannes Berg
From: Johannes Berg <johannes.berg@intel.com>
WLAN_EID_TX_POWER_ENVELOPE is a regular (non-extended) element,
but I accidentally used find_ext_elem() for it. Fix this.
Fixes: 4540568136fe ("wifi: mac80211: handle TPE element during CSA")
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
---
net/mac80211/parse.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/mac80211/parse.c b/net/mac80211/parse.c
index 3b66ca7d7a5c..4ff726eef453 100644
--- a/net/mac80211/parse.c
+++ b/net/mac80211/parse.c
@@ -692,8 +692,8 @@ _ieee802_11_parse_elems_full(struct ieee80211_elems_parse_params *params,
IEEE80211_PARSE_ERR_BAD_ELEM_SIZE;
}
- subelem = cfg80211_find_ext_elem(WLAN_EID_TX_POWER_ENVELOPE,
- pos, elen);
+ subelem = cfg80211_find_elem(WLAN_EID_TX_POWER_ENVELOPE,
+ pos, elen);
if (subelem)
ieee80211_parse_tpe(&elems->csa_tpe,
subelem->data + 1,
--
2.55.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* [PATCH wireless-next 2/2] wifi: cfg80211: type-check (extended) element search functions
2026-09-28 12:43 [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing Johannes Berg
@ 2026-09-28 12:43 ` Johannes Berg
2026-09-28 16:15 ` [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing Johannes Berg
1 sibling, 0 replies; 3+ messages in thread
From: Johannes Berg @ 2026-09-28 12:43 UTC (permalink / raw)
To: linux-wireless; +Cc: Johannes Berg
From: Johannes Berg <johannes.berg@intel.com>
When constants are given as the first argument for the element
or extended element ID, make sure they're from the right enum
by tagging the argument accordingly.
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
---
include/net/cfg80211.h | 17 +++++++++++------
net/wireless/scan.c | 3 ++-
2 files changed, 13 insertions(+), 7 deletions(-)
diff --git a/include/net/cfg80211.h b/include/net/cfg80211.h
index b603f1804cc2..2e3dfee85019 100644
--- a/include/net/cfg80211.h
+++ b/include/net/cfg80211.h
@@ -7858,7 +7858,8 @@ unsigned int cfg80211_classify8021d(struct sk_buff *skb,
* byte array to match.
*/
const struct element *
-cfg80211_find_elem_match(u8 eid, const u8 *ies, unsigned int len,
+cfg80211_find_elem_match(enum ieee80211_eid eid,
+ const u8 *ies, unsigned int len,
const u8 *match, unsigned int match_len,
unsigned int match_offset);
@@ -7887,7 +7888,7 @@ cfg80211_find_elem_match(u8 eid, const u8 *ies, unsigned int len,
* byte array to match.
*/
static inline const u8 *
-cfg80211_find_ie_match(u8 eid, const u8 *ies, unsigned int len,
+cfg80211_find_ie_match(enum ieee80211_eid eid, const u8 *ies, unsigned int len,
const u8 *match, unsigned int match_len,
unsigned int match_offset)
{
@@ -7920,7 +7921,7 @@ cfg80211_find_ie_match(u8 eid, const u8 *ies, unsigned int len,
* having to fit into the given data.
*/
static inline const struct element *
-cfg80211_find_elem(u8 eid, const u8 *ies, int len)
+cfg80211_find_elem(enum ieee80211_eid eid, const u8 *ies, int len)
{
return cfg80211_find_elem_match(eid, ies, len, NULL, 0, 0);
}
@@ -7940,7 +7941,8 @@ cfg80211_find_elem(u8 eid, const u8 *ies, int len)
* Note: There are no checks on the element length other than
* having to fit into the given data.
*/
-static inline const u8 *cfg80211_find_ie(u8 eid, const u8 *ies, int len)
+static inline const u8 *cfg80211_find_ie(enum ieee80211_eid eid,
+ const u8 *ies, int len)
{
return cfg80211_find_ie_match(eid, ies, len, NULL, 0, 0);
}
@@ -7961,10 +7963,13 @@ static inline const u8 *cfg80211_find_ie(u8 eid, const u8 *ies, int len)
* having to fit into the given data.
*/
static inline const struct element *
-cfg80211_find_ext_elem(u8 ext_eid, const u8 *ies, int len)
+cfg80211_find_ext_elem(enum ieee80211_eid_ext ext_eid,
+ const u8 *ies, int len)
{
+ u8 _ext_eid = ext_eid;
+
return cfg80211_find_elem_match(WLAN_EID_EXTENSION, ies, len,
- &ext_eid, 1, 0);
+ &_ext_eid, 1, 0);
}
/**
diff --git a/net/wireless/scan.c b/net/wireless/scan.c
index caa9c6495f20..8fedfaeba4e0 100644
--- a/net/wireless/scan.c
+++ b/net/wireless/scan.c
@@ -1436,7 +1436,8 @@ void cfg80211_bss_flush(struct wiphy *wiphy)
EXPORT_SYMBOL(cfg80211_bss_flush);
const struct element *
-cfg80211_find_elem_match(u8 eid, const u8 *ies, unsigned int len,
+cfg80211_find_elem_match(enum ieee80211_eid eid,
+ const u8 *ies, unsigned int len,
const u8 *match, unsigned int match_len,
unsigned int match_offset)
{
--
2.55.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing
2026-09-28 12:43 [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing Johannes Berg
2026-09-28 12:43 ` [PATCH wireless-next 2/2] wifi: cfg80211: type-check (extended) element search functions Johannes Berg
@ 2026-09-28 16:15 ` Johannes Berg
1 sibling, 0 replies; 3+ messages in thread
From: Johannes Berg @ 2026-09-28 16:15 UTC (permalink / raw)
To: linux-wireless
On Mon, 2026-09-28 at 14:43 +0200, Johannes Berg wrote:
> From: Johannes Berg <johannes.berg@intel.com>
>
> WLAN_EID_TX_POWER_ENVELOPE is a regular (non-extended) element,
> but I accidentally used find_ext_elem() for it. Fix this.
>
> Fixes: 4540568136fe ("wifi: mac80211: handle TPE element during CSA")
> Signed-off-by: Johannes Berg <johannes.berg@intel.com>
> ---
> net/mac80211/parse.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/net/mac80211/parse.c b/net/mac80211/parse.c
> index 3b66ca7d7a5c..4ff726eef453 100644
> --- a/net/mac80211/parse.c
> +++ b/net/mac80211/parse.c
> @@ -692,8 +692,8 @@ _ieee802_11_parse_elems_full(struct ieee80211_elems_parse_params *params,
> IEEE80211_PARSE_ERR_BAD_ELEM_SIZE;
> }
>
> - subelem = cfg80211_find_ext_elem(WLAN_EID_TX_POWER_ENVELOPE,
> - pos, elen);
> + subelem = cfg80211_find_elem(WLAN_EID_TX_POWER_ENVELOPE,
> + pos, elen);
Actually, this should also be a loop.
johannes
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-28 16:15 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-28 12:43 [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing Johannes Berg
2026-09-28 12:43 ` [PATCH wireless-next 2/2] wifi: cfg80211: type-check (extended) element search functions Johannes Berg
2026-09-28 16:15 ` [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing Johannes Berg
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox