* [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing
@ 2026-09-28 12:43 Johannes Berg
2026-09-28 12:43 ` [PATCH wireless-next 2/2] wifi: cfg80211: type-check (extended) element search functions Johannes Berg
2026-09-28 16:15 ` [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing Johannes Berg
0 siblings, 2 replies; 3+ messages in thread
From: Johannes Berg @ 2026-09-28 12:43 UTC (permalink / raw)
To: linux-wireless; +Cc: Johannes Berg
From: Johannes Berg <johannes.berg@intel.com>
WLAN_EID_TX_POWER_ENVELOPE is a regular (non-extended) element,
but I accidentally used find_ext_elem() for it. Fix this.
Fixes: 4540568136fe ("wifi: mac80211: handle TPE element during CSA")
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
---
net/mac80211/parse.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/mac80211/parse.c b/net/mac80211/parse.c
index 3b66ca7d7a5c..4ff726eef453 100644
--- a/net/mac80211/parse.c
+++ b/net/mac80211/parse.c
@@ -692,8 +692,8 @@ _ieee802_11_parse_elems_full(struct ieee80211_elems_parse_params *params,
IEEE80211_PARSE_ERR_BAD_ELEM_SIZE;
}
- subelem = cfg80211_find_ext_elem(WLAN_EID_TX_POWER_ENVELOPE,
- pos, elen);
+ subelem = cfg80211_find_elem(WLAN_EID_TX_POWER_ENVELOPE,
+ pos, elen);
if (subelem)
ieee80211_parse_tpe(&elems->csa_tpe,
subelem->data + 1,
--
2.55.0
^ permalink raw reply related [flat|nested] 3+ messages in thread* [PATCH wireless-next 2/2] wifi: cfg80211: type-check (extended) element search functions 2026-09-28 12:43 [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing Johannes Berg @ 2026-09-28 12:43 ` Johannes Berg 2026-09-28 16:15 ` [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing Johannes Berg 1 sibling, 0 replies; 3+ messages in thread From: Johannes Berg @ 2026-09-28 12:43 UTC (permalink / raw) To: linux-wireless; +Cc: Johannes Berg From: Johannes Berg <johannes.berg@intel.com> When constants are given as the first argument for the element or extended element ID, make sure they're from the right enum by tagging the argument accordingly. Signed-off-by: Johannes Berg <johannes.berg@intel.com> --- include/net/cfg80211.h | 17 +++++++++++------ net/wireless/scan.c | 3 ++- 2 files changed, 13 insertions(+), 7 deletions(-) diff --git a/include/net/cfg80211.h b/include/net/cfg80211.h index b603f1804cc2..2e3dfee85019 100644 --- a/include/net/cfg80211.h +++ b/include/net/cfg80211.h @@ -7858,7 +7858,8 @@ unsigned int cfg80211_classify8021d(struct sk_buff *skb, * byte array to match. */ const struct element * -cfg80211_find_elem_match(u8 eid, const u8 *ies, unsigned int len, +cfg80211_find_elem_match(enum ieee80211_eid eid, + const u8 *ies, unsigned int len, const u8 *match, unsigned int match_len, unsigned int match_offset); @@ -7887,7 +7888,7 @@ cfg80211_find_elem_match(u8 eid, const u8 *ies, unsigned int len, * byte array to match. */ static inline const u8 * -cfg80211_find_ie_match(u8 eid, const u8 *ies, unsigned int len, +cfg80211_find_ie_match(enum ieee80211_eid eid, const u8 *ies, unsigned int len, const u8 *match, unsigned int match_len, unsigned int match_offset) { @@ -7920,7 +7921,7 @@ cfg80211_find_ie_match(u8 eid, const u8 *ies, unsigned int len, * having to fit into the given data. */ static inline const struct element * -cfg80211_find_elem(u8 eid, const u8 *ies, int len) +cfg80211_find_elem(enum ieee80211_eid eid, const u8 *ies, int len) { return cfg80211_find_elem_match(eid, ies, len, NULL, 0, 0); } @@ -7940,7 +7941,8 @@ cfg80211_find_elem(u8 eid, const u8 *ies, int len) * Note: There are no checks on the element length other than * having to fit into the given data. */ -static inline const u8 *cfg80211_find_ie(u8 eid, const u8 *ies, int len) +static inline const u8 *cfg80211_find_ie(enum ieee80211_eid eid, + const u8 *ies, int len) { return cfg80211_find_ie_match(eid, ies, len, NULL, 0, 0); } @@ -7961,10 +7963,13 @@ static inline const u8 *cfg80211_find_ie(u8 eid, const u8 *ies, int len) * having to fit into the given data. */ static inline const struct element * -cfg80211_find_ext_elem(u8 ext_eid, const u8 *ies, int len) +cfg80211_find_ext_elem(enum ieee80211_eid_ext ext_eid, + const u8 *ies, int len) { + u8 _ext_eid = ext_eid; + return cfg80211_find_elem_match(WLAN_EID_EXTENSION, ies, len, - &ext_eid, 1, 0); + &_ext_eid, 1, 0); } /** diff --git a/net/wireless/scan.c b/net/wireless/scan.c index caa9c6495f20..8fedfaeba4e0 100644 --- a/net/wireless/scan.c +++ b/net/wireless/scan.c @@ -1436,7 +1436,8 @@ void cfg80211_bss_flush(struct wiphy *wiphy) EXPORT_SYMBOL(cfg80211_bss_flush); const struct element * -cfg80211_find_elem_match(u8 eid, const u8 *ies, unsigned int len, +cfg80211_find_elem_match(enum ieee80211_eid eid, + const u8 *ies, unsigned int len, const u8 *match, unsigned int match_len, unsigned int match_offset) { -- 2.55.0 ^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing 2026-09-28 12:43 [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing Johannes Berg 2026-09-28 12:43 ` [PATCH wireless-next 2/2] wifi: cfg80211: type-check (extended) element search functions Johannes Berg @ 2026-09-28 16:15 ` Johannes Berg 1 sibling, 0 replies; 3+ messages in thread From: Johannes Berg @ 2026-09-28 16:15 UTC (permalink / raw) To: linux-wireless On Mon, 2026-09-28 at 14:43 +0200, Johannes Berg wrote: > From: Johannes Berg <johannes.berg@intel.com> > > WLAN_EID_TX_POWER_ENVELOPE is a regular (non-extended) element, > but I accidentally used find_ext_elem() for it. Fix this. > > Fixes: 4540568136fe ("wifi: mac80211: handle TPE element during CSA") > Signed-off-by: Johannes Berg <johannes.berg@intel.com> > --- > net/mac80211/parse.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/net/mac80211/parse.c b/net/mac80211/parse.c > index 3b66ca7d7a5c..4ff726eef453 100644 > --- a/net/mac80211/parse.c > +++ b/net/mac80211/parse.c > @@ -692,8 +692,8 @@ _ieee802_11_parse_elems_full(struct ieee80211_elems_parse_params *params, > IEEE80211_PARSE_ERR_BAD_ELEM_SIZE; > } > > - subelem = cfg80211_find_ext_elem(WLAN_EID_TX_POWER_ENVELOPE, > - pos, elen); > + subelem = cfg80211_find_elem(WLAN_EID_TX_POWER_ENVELOPE, > + pos, elen); Actually, this should also be a loop. johannes ^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-28 16:15 UTC | newest] Thread overview: 3+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-09-28 12:43 [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing Johannes Berg 2026-09-28 12:43 ` [PATCH wireless-next 2/2] wifi: cfg80211: type-check (extended) element search functions Johannes Berg 2026-09-28 16:15 ` [PATCH wireless-next 1/2] wifi: mac80211: fix TPE in channel switch wrapper parsing Johannes Berg
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox