diff --git a/umac/scan/dispatcher/src/wlan_scan_utils_api.c b/umac/scan/dispatcher/src/wlan_scan_utils_api.c index 4979f53f2d16..0e00c2b62f2d 100644 --- a/umac/scan/dispatcher/src/wlan_scan_utils_api.c +++ b/umac/scan/dispatcher/src/wlan_scan_utils_api.c @@ -2147,18 +2147,6 @@ util_handle_nontx_prof(uint8_t *mbssid_elem, uint8_t *subelement, uint32_t prof_len; prof_len = subelement[TAG_LEN_POS]; - /* - * if prof_residue is true, that means we are - * in the continuation of the fragmented profile part, - * present in the next MBSSD IE else this profile - * is a non fragmented non tx BSSID profile. - */ - - if (mbssid_info->prof_residue) - mbssid_info->split_prof_continue = true; - else - mbssid_info->split_prof_continue = false; - /* * If we are executing the split portion of the nontx * profile present in the subsequent MBSSID, then there @@ -2342,7 +2330,25 @@ static QDF_STATUS util_scan_parse_mbssid(struct wlan_objmgr_pdev *pdev, subelement += MIN_IE_LEN + subelement[TAG_LEN_POS]) { subie_len = subelement[TAG_LEN_POS]; + /* + * if prof_residue is true, that means we are + * in the continuation of the fragmented profile part, + * present in the next MBSSD IE else this profile + * is a non fragmented non tx BSSID profile. + */ + + if (mbssid_info.prof_residue) + mbssid_info.split_prof_continue = true; + else + mbssid_info.split_prof_continue = false; + if (subie_len > MAX_SUBELEM_LEN) { + scm_err_rl("Corrupt frame with subie_len: %d\n" + "split_prof_continue: %d\n" + "prof_residue: %d\n", + subie_len, + mbssid_info.split_prof_continue, + mbssid_info.prof_residue); if (mbssid_info.split_prof_continue) qdf_mem_free(split_prof_start); @@ -2361,6 +2367,10 @@ static QDF_STATUS util_scan_parse_mbssid(struct wlan_objmgr_pdev *pdev, bssid, new_bssid); if (retval == INVALID_SPLIT_PROF) { + scm_err_rl("Corrupt frame with ID_POS: %d\n" + "TAG_LEN_POS: %d\n", + subelement[ID_POS], + subelement[TAG_LEN_POS]); qdf_mem_free(split_prof_start); qdf_mem_free(new_ie); return QDF_STATUS_E_INVAL; @@ -2395,6 +2405,7 @@ static QDF_STATUS util_scan_parse_mbssid(struct wlan_objmgr_pdev *pdev, split_prof_start = qdf_mem_malloc(ielen); if (!split_prof_start) { + scm_err_rl("Malloc failed"); qdf_mem_free(new_ie); return QDF_STATUS_E_NOMEM; } @@ -2492,6 +2503,9 @@ static QDF_STATUS util_scan_parse_mbssid(struct wlan_objmgr_pdev *pdev, if (mbssid_info.split_prof_continue) qdf_mem_free(split_prof_start); qdf_mem_free(new_ie); + scm_err_rl("Malloc for new_frame failed"); + scm_err_rl("split_prof_continue: %d", + mbssid_info.split_prof_continue); return QDF_STATUS_E_NOMEM; } @@ -2532,6 +2546,8 @@ static QDF_STATUS util_scan_parse_mbssid(struct wlan_objmgr_pdev *pdev, } qdf_mem_free(new_frame); scm_err_rl("failed to generate a scan entry"); + scm_err_rl("split_prof_continue: %d", + mbssid_info.split_prof_continue); break; } /* scan entry makes its own copy so free the frame*/