From b3be3854eac954ee1a805652337aa142275b8b3b Mon Sep 17 00:00:00 2001 From: Aravind Kishore Sukla Date: Mon, 6 Jun 2022 16:39:51 +0530 Subject: [PATCH 01/27] qcacld-3.0: Update wiphy max_num_akms_connect variable Update wiphy->max_num_akms_connect to wiphy->max_num_akm_suites, based on the upstream kernel change. Change-Id: I54455b1d3fc162ddea5a0f9380f66a4a06236076 CRs-Fixed: 3214543 --- core/hdd/src/wlan_hdd_cfg80211.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/core/hdd/src/wlan_hdd_cfg80211.c b/core/hdd/src/wlan_hdd_cfg80211.c index 8531cf162dc0..32ef0a23a050 100644 --- a/core/hdd/src/wlan_hdd_cfg80211.c +++ b/core/hdd/src/wlan_hdd_cfg80211.c @@ -17359,7 +17359,7 @@ wlan_hdd_update_akm_suit_info(struct wiphy *wiphy) static void wlan_hdd_update_max_connect_akm(struct wiphy *wiphy) { - wiphy->max_num_akms_connect = WLAN_CM_MAX_CONNECT_AKMS; + wiphy->max_num_akm_suites = WLAN_CM_MAX_CONNECT_AKMS; } #else static void From c6f2b88a05148d7561ef45a20f6ab5ce96f41c8d Mon Sep 17 00:00:00 2001 From: Srikanth Marepalli Date: Sat, 4 May 2024 00:42:26 +0530 Subject: [PATCH 02/27] qcacld-3.0: Enable CFG80211_MULTI_AKM_CONNECT_SUPPORT from kernelv6.0 Current code supports CFG80211_MULTI_AKM_CONNECT_SUPPORT only for v5.15 kernel. Enable this feature support from kernelv6.0 by default. Change-Id: I6fbf83df54fd898abde0546f526b193a6d8dc620 CRs-Fixed: 3806550 --- core/hdd/src/wlan_hdd_cfg80211.h | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/core/hdd/src/wlan_hdd_cfg80211.h b/core/hdd/src/wlan_hdd_cfg80211.h index f59eccad6adf..08cdc03c2bb3 100644 --- a/core/hdd/src/wlan_hdd_cfg80211.h +++ b/core/hdd/src/wlan_hdd_cfg80211.h @@ -208,6 +208,20 @@ extern const struct nla_policy wlan_hdd_wisa_cmd_policy[ #define USE_CFG80211_DEL_STA_V2 #endif +/* + * CFG80211_MULTI_AKM_CONNECT_SUPPORT + * used to indicate the Linux kernel contains support for multi AKM connect + * support + * + * This feature was introduced in Linux Kernel 6.0 via: + * ecad3b0b99bf wifi: cfg80211: Increase akm_suites array size in + * cfg80211_crypto_settings. + */ +#if (LINUX_VERSION_CODE >= KERNEL_VERSION(6, 0, 0) || \ + (defined CFG80211_MAX_NUM_AKM_SUITES)) +#define CFG80211_MULTI_AKM_CONNECT_SUPPORT 1 +#endif + #ifdef CFG80211_MULTI_AKM_CONNECT_SUPPORT #define WLAN_CM_MAX_CONNECT_AKMS 5 #endif From b9ce37bdc0e9fc4c9d8425606278bfbeb6d56465 Mon Sep 17 00:00:00 2001 From: Srikanth Marepalli Date: Sat, 4 May 2024 01:56:51 +0530 Subject: [PATCH 03/27] qcacld-3.0: Update connect request crypto parameters Update the connect request crypto parameters based on the new kernel changes to increase the size of the akm_suites array in connect request Change-Id: I36eb265d3dafe9d822879fdbed340ba0c6bb7225 CRs-Fixed: 3806556 --- core/hdd/src/wlan_hdd_cfg80211.c | 86 +++++++------------------------- 1 file changed, 17 insertions(+), 69 deletions(-) diff --git a/core/hdd/src/wlan_hdd_cfg80211.c b/core/hdd/src/wlan_hdd_cfg80211.c index 8531cf162dc0..dce428a053ef 100644 --- a/core/hdd/src/wlan_hdd_cfg80211.c +++ b/core/hdd/src/wlan_hdd_cfg80211.c @@ -20513,7 +20513,23 @@ static bool wlan_hdd_is_akm_suite_fils(uint32_t key_mgmt) } } +static int +hdd_get_num_akm_suites(const struct cfg80211_connect_params *req) +{ + return req->crypto.n_akm_suites; +} + +static uint32_t* +hdd_get_akm_suites(const struct cfg80211_connect_params *req) +{ + return (uint32_t *)req->crypto.akm_suites; +} + #ifdef CFG80211_MULTI_AKM_CONNECT_SUPPORT +#define MAX_AKM_SUITES WLAN_CM_MAX_CONNECT_AKMS +#else +#define MAX_AKM_SUITES NL80211_MAX_NR_AKM_SUITES +#endif /** * hdd_populate_crypto_akm_type() - populate akm type for crypto * @vdev: pointed to vdev obmgr @@ -20533,64 +20549,9 @@ hdd_populate_crypto_akm_type(struct wlan_objmgr_vdev *vdev, uint32_t set_val = 0; wlan_crypto_key_mgmt akm; - if (req->crypto.n_connect_akm_suites) { - for (i = 0; i < req->crypto.n_connect_akm_suites && - i < WLAN_CM_MAX_CONNECT_AKMS; i++) { - akm = osif_nl_to_crypto_akm_type( - req->crypto.connect_akm_suites[i]); - - HDD_SET_BIT(set_val, akm); - } - - status = wlan_crypto_set_vdev_param(vdev, - WLAN_CRYPTO_PARAM_KEY_MGMT, - set_val); - if (QDF_IS_STATUS_ERROR(status)) - hdd_err("Failed to set akm type %0x to crypto", - set_val); - - status = wlan_crypto_set_vdev_param( - vdev, WLAN_CRYPTO_PARAM_ORIG_KEY_MGMT, set_val); - if (QDF_IS_STATUS_ERROR(status)) - hdd_err("Failed to set original akm type %0x to crypto", - set_val); - } else { - set_val = 0; - /* Reset to none */ - HDD_SET_BIT(set_val, WLAN_CRYPTO_KEY_MGMT_NONE); - wlan_crypto_set_vdev_param(vdev, - WLAN_CRYPTO_PARAM_KEY_MGMT, - set_val); - wlan_crypto_set_vdev_param(vdev, - WLAN_CRYPTO_PARAM_ORIG_KEY_MGMT, - set_val); - } -} - -static int -hdd_get_num_akm_suites(const struct cfg80211_connect_params *req) -{ - return req->crypto.n_connect_akm_suites; -} - -static uint32_t* -hdd_get_akm_suites(const struct cfg80211_connect_params *req) -{ - return (uint32_t *)req->crypto.connect_akm_suites; -} -#else -static void -hdd_populate_crypto_akm_type(struct wlan_objmgr_vdev *vdev, - const struct cfg80211_connect_params *req) -{ - QDF_STATUS status; - uint32_t i = 0; - uint32_t set_val = 0; - wlan_crypto_key_mgmt akm; - if (req->crypto.n_akm_suites) { for (i = 0; i < req->crypto.n_akm_suites && - i < NL80211_MAX_NR_AKM_SUITES; i++) { + i < MAX_AKM_SUITES; i++) { akm = osif_nl_to_crypto_akm_type( req->crypto.akm_suites[i]); @@ -20623,19 +20584,6 @@ hdd_populate_crypto_akm_type(struct wlan_objmgr_vdev *vdev, } } -static int -hdd_get_num_akm_suites(const struct cfg80211_connect_params *req) -{ - return req->crypto.n_akm_suites; -} - -static uint32_t* -hdd_get_akm_suites(const struct cfg80211_connect_params *req) -{ - return (uint32_t *)req->crypto.akm_suites; -} -#endif - static bool wlan_hdd_is_conn_type_fils(struct cfg80211_connect_params *req) { enum nl80211_auth_type auth_type = req->auth_type; From 0c185589bc7c4659bdcd17e060a546733eaf7b7c Mon Sep 17 00:00:00 2001 From: Srikanth Marepalli Date: Wed, 3 Jul 2024 01:47:40 +0530 Subject: [PATCH 04/27] qcacld-3.0: Fix the AKM precedence order for RSN IE When the AP is configured with multiple AKMs for eg. SuiteB and FT-SuiteB then Supplicant selects the FT-SuiteB based on its precedence order but driver was selecting SuiteB due to its incorrect AKM precedence. Due to this the RSN IE in assoc-request was filled with SuiteB AKM but all other IEs were used of FT-SuiteB as sent by the Supplicant. And this is resulting in association failure. Fix the AKM precedence in the order of more secure AKM. Change-Id: I96ff786924778d336507e3bca4a38de4d7c07ffc CRs-Fixed: 3861554 (cherry picked from commit 97b3d0426579237de9c02fdf349f781514e85e2b) --- core/sme/src/csr/csr_util.c | 76 ++++++++++++++++++------------------- 1 file changed, 38 insertions(+), 38 deletions(-) diff --git a/core/sme/src/csr/csr_util.c b/core/sme/src/csr/csr_util.c index 0343476c116a..f8c2f48b711c 100644 --- a/core/sme/src/csr/csr_util.c +++ b/core/sme/src/csr/csr_util.c @@ -2451,6 +2451,7 @@ static void csr_update_key_mgmt_crypto_param(struct wlan_objmgr_vdev *vdev, { int32_t key_mgmt = 0; int32_t neg_akm; + uint8_t i; neg_akm = wlan_crypto_get_param(vdev, WLAN_CRYPTO_PARAM_KEY_MGMT); if (neg_akm < 0) { @@ -2458,69 +2459,66 @@ static void csr_update_key_mgmt_crypto_param(struct wlan_objmgr_vdev *vdev, return; } - SET_PARAM(neg_akm, - wlan_crypto_rsn_suite_to_keymgmt(ap_rsn.akm_suite[0])); + for (i = 0; i < ap_rsn.akm_suite_cnt; i++) + SET_PARAM(neg_akm, + wlan_crypto_rsn_suite_to_keymgmt(ap_rsn.akm_suite[i])); /* * As there can be multiple AKM present select the most secured AKM * present */ - if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_SAE)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_SAE); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_SAE)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_SAE); + if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B_192)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B_192); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B); - else if (HAS_PARAM(neg_akm, - WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B_192)) - SET_PARAM(key_mgmt, - WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B_192); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FILS_SHA256)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FILS_SHA256); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA384)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA384); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FILS_SHA384)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FILS_SHA384); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA256)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA256); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA384)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA384); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_OWE)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_OWE); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_DPP)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_DPP); - else if (HAS_PARAM(neg_akm, - WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384)) - SET_PARAM(key_mgmt, - WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_PSK)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_PSK); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FILS_SHA256)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FILS_SHA256); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_PSK)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_PSK); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SHA256)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SHA256); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_PSK_SHA256)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_PSK_SHA256); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_DPP)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_DPP); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_SAE)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_SAE); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_SAE)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_SAE); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_PSK_SHA384)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_PSK_SHA384); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_PSK)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_PSK); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SHA256)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SHA256); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_PSK_SHA384)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_PSK_SHA384); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_PSK_SHA256)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_PSK_SHA256); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_IEEE8021X); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_PSK)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_PSK); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_WPA_NONE)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_WPA_NONE); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_OSEN)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_OSEN); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_OWE)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_OWE); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_WAPI_PSK)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_WAPI_PSK); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_WAPI_CERT)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_WAPI_CERT); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_CCKM)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_CCKM); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_OSEN)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_OSEN); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_WPS)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_WPS); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_IEEE8021X); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_NO_WPA)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_NO_WPA); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_WPA_NONE)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_WPA_NONE); else /* use original if no akm match */ key_mgmt = neg_akm; @@ -2533,6 +2531,7 @@ static void csr_update_ucast_cipher_crypto_param(struct wlan_objmgr_vdev *vdev, { int32_t ucastcipherset = 0; int32_t neg_ucastcipher; + uint8_t i; neg_ucastcipher = wlan_crypto_get_param(vdev, WLAN_CRYPTO_PARAM_UCAST_CIPHER); @@ -2541,8 +2540,9 @@ static void csr_update_ucast_cipher_crypto_param(struct wlan_objmgr_vdev *vdev, return; } - SET_PARAM(neg_ucastcipher, - wlan_crypto_rsn_suite_to_cipher(ap_rsn.pwise_cipher_suites[0])); + for (i = 0; i < ap_rsn.pwise_cipher_suite_count; i++) + SET_PARAM(neg_ucastcipher, + wlan_crypto_rsn_suite_to_cipher(ap_rsn.pwise_cipher_suites[i])); /* * As there can be multiple ucastcipher present select the most secured From 0f39a68508e25531405b18f1ebc848459d9187e6 Mon Sep 17 00:00:00 2001 From: Surya Prakash Sivaraj Date: Fri, 12 Jul 2024 16:07:30 +0530 Subject: [PATCH 05/27] qcacld-3.0: Enhance the RSNXE inter-op logic Some third-party APs are not able to handle more than 1 octet in the RSNXE, even though RSNXE support is present. Therefore, to prevent this interop issue, send only 1 octet of RSNXE if the AP broadcasts only 1 octet. RSNXE handling logic summary: 1. Don't modify userspace RSNXE when caps other than SAE_H2E, SAE_PK, SECURE_LTF, SECURE_RTT, PROT_RANGE_NEGOTIOATION are set. 2. AP doesn't send RSNXE For WPA2 - Strip the RSNXE completely. For WPA3 - Retain only SAE capabilities such as H2E and PK. 3. AP supports RSNXE with length 1 For WPA2 & WPA3 - Retain only the first octet in RSNXE. 4. AP supports RSNXE with multiple octet For WPA2 & WPA3 - Use the userspace assoc ie RSNXE as it is. Change-Id: I56d1d5711b067fe5e0ff19117f6a600219cb86a0 CRs-Fixed: 3490369 (cherry picked from commit 5d837c1b79e7761e75e1e128b189fa01ec6a1a85) --- core/mac/inc/sir_mac_prot_def.h | 4 +- .../src/pe/lim/lim_process_sme_req_messages.c | 144 +++++++++++++++++- 2 files changed, 146 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/sir_mac_prot_def.h b/core/mac/inc/sir_mac_prot_def.h index 8927b19557e7..b31f399917c4 100644 --- a/core/mac/inc/sir_mac_prot_def.h +++ b/core/mac/inc/sir_mac_prot_def.h @@ -1,6 +1,6 @@ /* * Copyright (c) 2011-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022,2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1872,4 +1872,6 @@ struct he_6ghz_capability_info { #define SIR_MAC_TXSTBC 1 #define SIR_MAC_RXSTBC 1 +#define SIR_MAC_RSNX_CAP_MIN_LEN 1 +#define SIR_MAC_RSNX_CAP_MAX_LEN 16 #endif /* __MAC_PROT_DEFS_H */ diff --git a/core/mac/src/pe/lim/lim_process_sme_req_messages.c b/core/mac/src/pe/lim/lim_process_sme_req_messages.c index dd4ea287d90b..49113c9529e4 100644 --- a/core/mac/src/pe/lim/lim_process_sme_req_messages.c +++ b/core/mac/src/pe/lim/lim_process_sme_req_messages.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2012-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2021-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2021-2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -61,6 +61,7 @@ #include #include "wlan_lmac_if_def.h" #include "wlan_reg_services_api.h" +#include /* SME REQ processing function templates */ static bool __lim_process_sme_sys_ready_ind(struct mac_context *, uint32_t *); @@ -1198,6 +1199,140 @@ lim_get_vdev_rmf_capable(struct mac_context *mac, struct pe_session *session) } #endif +/* + * lim_rebuild_rsnxe_cap() - Rebuild the RSNXE CAP for STA + * + * @rsnx_ie: RSNX IE + * @length: length of extended RSN cap field + * + * This API is used to truncate/rebuild the RSNXE based on the length + * provided. This length marks the length of the extended RSN cap field. + * + * Return: Newly constructed RSNX IE + */ +static inline uint8_t *lim_rebuild_rsnxe_cap(uint8_t *rsnx_ie, uint8_t length) +{ + const uint8_t *rsnxe_cap; + uint8_t cap_len; + uint8_t *new_rsnxe = NULL; + + if (length < SIR_MAC_RSNX_CAP_MIN_LEN || + length > SIR_MAC_RSNX_CAP_MAX_LEN) { + pe_err("Invalid length %d", length); + return NULL; + } + + rsnxe_cap = wlan_crypto_parse_rsnxe_ie(rsnx_ie, &cap_len); + if (!rsnxe_cap) + return NULL; + + new_rsnxe = qdf_mem_malloc(length + 2); + if (!new_rsnxe) + return NULL; + + new_rsnxe[0] = WLAN_ELEMID_RSNXE; + new_rsnxe[1] = length; + qdf_mem_copy(&new_rsnxe[2], rsnxe_cap, length); + + /* Now update the new field length in octet 0 for the new length*/ + new_rsnxe[2] = (new_rsnxe[2] & 0xF0) | (length - 1); + + pe_debug("New RSNXE length %d", length); + QDF_TRACE_HEX_DUMP(QDF_MODULE_ID_PE, QDF_TRACE_LEVEL_DEBUG, + new_rsnxe, length + 2); + return new_rsnxe; +} + +static inline QDF_STATUS +lim_strip_rsnx_ie(struct mac_context *mac_ctx, + struct pe_session *session) +{ + int32_t akm; + uint8_t len = 0; + uint8_t *rsnxe = NULL, *new_rsnxe = NULL; + QDF_STATUS status = QDF_STATUS_SUCCESS; + uint8_t *add_ie = NULL; + uint16_t add_ie_len; + + akm = wlan_crypto_get_param(session->vdev, WLAN_CRYPTO_PARAM_KEY_MGMT); + if (akm == -1 || + !(WLAN_CRYPTO_IS_WPA_WPA2(akm) || WLAN_CRYPTO_IS_WPA3(akm))) + return status; + + add_ie = session->lim_join_req->addIEAssoc.addIEdata; + add_ie_len = session->lim_join_req->addIEAssoc.length; + + if (!wlan_get_ie_ptr_from_eid(WLAN_ELEMID_RSNXE, add_ie, add_ie_len)) + return status; + + /* + * Userspace may send RSNXE also in connect request irrespective + * of the connecting AP capabilities. This allows the driver to chose + * best candidate based on score. But the chosen candidate may + * not support the RSNXE feature and may not advertise RSNXE + * in beacon/probe response. Station is not supposed to include + * the RSNX IE in assoc request in such cases as legacy APs + * may misbahave due to the new IE. It's observed that few + * legacy APs which don't support the RSNXE reject the + * connection at EAPOL stage. + * + */ + rsnxe = qdf_mem_malloc(WLAN_MAX_IE_LEN + 2); + if (!rsnxe) + return QDF_STATUS_E_FAILURE; + + lim_strip_ie(mac_ctx, add_ie, &add_ie_len, WLAN_ELEMID_RSNXE, + ONE_BYTE, NULL, 0, rsnxe, WLAN_MAX_IE_LEN); + + session->lim_join_req->addIEAssoc.length = add_ie_len; + + if (!rsnxe[0]) + goto end; + + if (WLAN_CRYPTO_IS_WPA_WPA2(akm)) { + mlme_debug("Strip RSNXE as it is not supported by AP"); + goto end; + } + + if (WLAN_CRYPTO_IS_WPA3(akm)) { + len = 1; + goto rebuild_rsnxe; + } + + pe_err("Error in handling RSNXE. RSNXE length : %d", rsnxe[1]); + status = QDF_STATUS_E_FAILURE; + goto end; + +rebuild_rsnxe: + /* Build the new RSNXE */ + new_rsnxe = lim_rebuild_rsnxe_cap(rsnxe, len); + if (!new_rsnxe) { + status = QDF_STATUS_E_FAILURE; + goto end; + } else if (!new_rsnxe[1]) { + qdf_mem_free(new_rsnxe); + status = QDF_STATUS_E_FAILURE; + goto end; + } + + /* Append the new RSNXE to the assoc ie */ + if (add_ie_len + new_rsnxe[1] >= SIR_MAC_MAX_ADD_IE_LENGTH) { + pe_err("Cannot accomodate the new RSNX IE"); + status = QDF_STATUS_E_FAILURE; + qdf_mem_free(new_rsnxe); + goto end; + } + + qdf_mem_copy(&add_ie[add_ie_len], new_rsnxe, new_rsnxe[1] + 2); + add_ie_len += new_rsnxe[1] + 2; + session->lim_join_req->addIEAssoc.length = add_ie_len; + qdf_mem_free(new_rsnxe); + +end: + qdf_mem_free(rsnxe); + return status; +} + /** * __lim_process_sme_join_req() - process SME_JOIN_REQ message * @mac_ctx: Pointer to Global MAC structure @@ -1599,6 +1734,13 @@ __lim_process_sme_join_req(struct mac_context *mac_ctx, void *msg_buf) ret_code = eSIR_SME_INVALID_PARAMETERS; goto end; } + + status = lim_strip_rsnx_ie(mac_ctx, session); + if (QDF_IS_STATUS_ERROR(status)) { + pe_err("Error in parsing RSNX IE"); + ret_code = eSIR_SME_INVALID_PARAMETERS; + goto end; + } } mlme_obj = wlan_vdev_mlme_get_cmpt_obj(session->vdev); From 5a034779fd85f258de87cad9c60421bcb680dcda Mon Sep 17 00:00:00 2001 From: Kiran Kumar Lokere Date: Mon, 9 Sep 2024 16:07:29 -0700 Subject: [PATCH 06/27] qcacld-3.0: Fix the possible OOB write in country IE unpack Fix the possible OOB write in unpacking the country IE due to the IE length check against integer division. CRs-Fixed: 3910626 Change-Id: I800290ab7285fb46ed43a46ce38967046b4881fa (cherry picked from commit 0002f9ddc9a6be3e34fe15e55f286b5794b29f08) (cherry picked from commit f33a4f5a7d5b0b54b72f6775a450575fc82a2fd8) --- core/mac/src/include/dot11f.h | 2 +- core/mac/src/sys/legacy/src/utils/src/dot11f.c | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/core/mac/src/include/dot11f.h b/core/mac/src/include/dot11f.h index 7b0afc593596..338a943facae 100644 --- a/core/mac/src/include/dot11f.h +++ b/core/mac/src/include/dot11f.h @@ -27,7 +27,7 @@ * * * This file was automatically generated by 'framesc' - * Mon May 30 20:50:39 2022 from the following file(s): + * Wed Sep 11 12:49:28 2024 from the following file(s): * * dot11f.frms * diff --git a/core/mac/src/sys/legacy/src/utils/src/dot11f.c b/core/mac/src/sys/legacy/src/utils/src/dot11f.c index ec2f7ff8be51..b44f94ea0ba8 100644 --- a/core/mac/src/sys/legacy/src/utils/src/dot11f.c +++ b/core/mac/src/sys/legacy/src/utils/src/dot11f.c @@ -25,7 +25,7 @@ * * * This file was automatically generated by 'framesc' - * Mon May 30 20:50:39 2022 from the following file(s): + * Wed Sep 11 12:49:28 2024 from the following file(s): * * dot11f.frms * @@ -134,7 +134,7 @@ typedef struct sIEDefn { #define DOT11F_PARAMETER_CHECK2(pSrc, pBuf, nBuf, pnConsumed) \ do { \ if (!pSrc || IsBadReadPtr(pSrc, 4))\ - eturn DOT11F_BAD_INPUT_BUFFER; \ + return DOT11F_BAD_INPUT_BUFFER; \ if (!pBuf || IsBadWritePtr(pBuf, nBuf))\ return DOT11F_BAD_OUTPUT_BUFFER; \ if (!nBuf)\ @@ -4131,7 +4131,7 @@ uint32_t dot11f_unpack_ie_country(tpAniSirGlobal pCtx, return 0U; } else { pDst->num_more_triplets = (uint8_t)(ielen / 3); - if (ielen / 3 > 80) { + if (ielen > 80 * 3) { pDst->present = 0; return DOT11F_SKIPPED_BAD_IE; } From 2aed6fe57ad5b2d180c3ec8cc1fc56e82ae53a5d Mon Sep 17 00:00:00 2001 From: Dharmendra Tiwari Date: Tue, 3 Sep 2024 23:06:17 -0700 Subject: [PATCH 07/27] qcacld-3.0: Correcting the TSInfo structure size according to the Spec According to spec the TSinfo size should be 4 bytes. To fix this issue,TSInfo size is increased to 4bytes aligning with the current standard. CRs-Fixed: 3910625 Change-Id: I7979fa84af0295d21d4afe1b876af494a5b8fed8 (cherry picked from commit 685e5c9a53e754d4eb67211ed5ec7b4144bbfcd1) --- core/mac/src/cfg/cfgUtil/dot11f.frms | 2 +- core/mac/src/include/dot11f.h | 2 +- core/mac/src/sys/legacy/src/utils/src/dot11f.c | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/core/mac/src/cfg/cfgUtil/dot11f.frms b/core/mac/src/cfg/cfgUtil/dot11f.frms index a3bbbbbf6297..4cb16f7da0c1 100644 --- a/core/mac/src/cfg/cfgUtil/dot11f.frms +++ b/core/mac/src/cfg/cfgUtil/dot11f.frms @@ -370,7 +370,7 @@ FF SMPowerModeSet (1) //7.3.1.25 } } -FF TSInfo (3) // 7.3.2.30 +FF TSInfo (4) // 7.3.2.30 { { traffic_type: 1; diff --git a/core/mac/src/include/dot11f.h b/core/mac/src/include/dot11f.h index 338a943facae..0e2d373a0b1f 100644 --- a/core/mac/src/include/dot11f.h +++ b/core/mac/src/include/dot11f.h @@ -442,7 +442,7 @@ typedef struct sDot11fFfTSInfo { uint32_t unused:15; } tDot11fFfTSInfo; -#define DOT11F_FF_TSINFO_LEN (3) +#define DOT11F_FF_TSINFO_LEN (4) void dot11f_unpack_ff_ts_info(tpAniSirGlobal, uint8_t *, tDot11fFfTSInfo *); diff --git a/core/mac/src/sys/legacy/src/utils/src/dot11f.c b/core/mac/src/sys/legacy/src/utils/src/dot11f.c index b44f94ea0ba8..b07b8c68f94a 100644 --- a/core/mac/src/sys/legacy/src/utils/src/dot11f.c +++ b/core/mac/src/sys/legacy/src/utils/src/dot11f.c @@ -16710,7 +16710,7 @@ uint32_t dot11f_get_packed_del_ts_size(tpAniSirGlobal pCtx, tDot11fDelTS *pFrm, uint32_t *pnNeeded) { uint32_t status = 0; - *pnNeeded = 7; + *pnNeeded = 8; status = get_packed_size_core(pCtx, (uint8_t *)pFrm, pnNeeded, IES_DelTS); return status; From 6bebc81e607bfa2f80969c13613b1a8940665be3 Mon Sep 17 00:00:00 2001 From: Krupali Dhanvijay Date: Fri, 21 Feb 2025 17:43:55 +0530 Subject: [PATCH 08/27] qcacld-3.0: Recalculate TX power post CSA Currently, host doesn't recalculate TX power post CSA if no change in power constraint or TPE IE, this can cause issue if local regulatory power is different for new CSA frequency. To address this issue, add support to recalculate TX power for first beacon received post CSA. Change-Id: I91f4609c552d579c24e781d382e647b6617e9315 CRs-Fixed: 3809724 --- core/mac/src/pe/include/lim_session.h | 4 +++- core/mac/src/pe/lim/lim_send_sme_rsp_messages.c | 2 ++ core/mac/src/pe/sch/sch_beacon_process.c | 5 +++-- 3 files changed, 8 insertions(+), 3 deletions(-) diff --git a/core/mac/src/pe/include/lim_session.h b/core/mac/src/pe/include/lim_session.h index 5488a180a145..25f2f90143c5 100644 --- a/core/mac/src/pe/include/lim_session.h +++ b/core/mac/src/pe/include/lim_session.h @@ -1,6 +1,6 @@ /* * Copyright (c) 2012-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2024-2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -140,6 +140,7 @@ struct obss_detection_cfg { * @prev_auth_seq_num: Sequence number of previously received auth frame to * detect duplicate frames. * @prev_auth_mac_addr: mac_addr of the sta correspond to @prev_auth_seq_num + * @cal_tpc_post_csa: Recalculate tx power power csa */ struct pe_session { /* To check session table is in use or free */ @@ -580,6 +581,7 @@ struct pe_session { uint32_t dfs_regdomain; uint8_t ap_defined_power_type_6g; uint8_t best_6g_power_type; + bool cal_tpc_post_csa; }; /*------------------------------------------------------------------------- diff --git a/core/mac/src/pe/lim/lim_send_sme_rsp_messages.c b/core/mac/src/pe/lim/lim_send_sme_rsp_messages.c index 8b6a073ea59e..639fac0c3c4f 100644 --- a/core/mac/src/pe/lim/lim_send_sme_rsp_messages.c +++ b/core/mac/src/pe/lim/lim_send_sme_rsp_messages.c @@ -1,5 +1,6 @@ /* * Copyright (c) 2012-2020 The Linux Foundation. All rights reserved. + * Copyright (c) 2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1884,6 +1885,7 @@ void lim_handle_csa_offload_msg(struct mac_context *mac_ctx, err: qdf_mem_free(csa_params); + session_entry->cal_tpc_post_csa = true; } /*-------------------------------------------------------------------------- diff --git a/core/mac/src/pe/sch/sch_beacon_process.c b/core/mac/src/pe/sch/sch_beacon_process.c index 3c0914e6c71a..8ffa424d5962 100644 --- a/core/mac/src/pe/sch/sch_beacon_process.c +++ b/core/mac/src/pe/sch/sch_beacon_process.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2012-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2021-2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2021-2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -704,8 +704,9 @@ static void __sch_beacon_process_for_session(struct mac_context *mac_ctx, } if ((ap_constraint_change && local_constraint) || - (tpe_change && !skip_tpe)) { + (tpe_change && !skip_tpe) || session->cal_tpc_post_csa) { lim_calculate_tpc(mac_ctx, session); + session->cal_tpc_post_csa = false; if (tx_ops->set_tpc_power) tx_ops->set_tpc_power(mac_ctx->psoc, From ee56b3c1d79f335ad58c714546c6330688a0963e Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Tue, 4 Mar 2025 01:20:54 -0800 Subject: [PATCH 09/27] Release 2.0.8.35 Release 2.0.8.35 Change-Id: I2ce9028c33f0161e85772f0a7996cad2a515726a CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index c8f76c9a8572..3b4e0d649715 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "Z" -#define QWLAN_VERSION_BUILD 34 +#define QWLAN_VERSION_EXTRA "" +#define QWLAN_VERSION_BUILD 35 -#define QWLAN_VERSIONSTR "2.0.8.34Z" +#define QWLAN_VERSIONSTR "2.0.8.35" #endif /* QWLAN_VERSION_H */ From c69a241cd99da17fe666564deaaebe07bf40fefc Mon Sep 17 00:00:00 2001 From: Aditya Kodukula Date: Wed, 8 Jan 2025 11:55:23 -0800 Subject: [PATCH 10/27] qcacld-3.0: Fix potential OOB memory access Currently in the wma_stats_ext_event_handler(), the buf_ptr is not pointing correctly to the event data received from FW. This is leading to an OOB memory access during qdf_mem_copy(). So, to avoid this issue correctly point the buf_ptr to the event data sent by the FW in the TLV. Change-Id: Iffa3e96a6a36eff5899a7a9a7febe0ebb9d7878f CRs-Fixed: 4011656 --- core/wma/src/wma_utils.c | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/core/wma/src/wma_utils.c b/core/wma/src/wma_utils.c index e8f10039e0ad..3f34979096b8 100644 --- a/core/wma/src/wma_utils.c +++ b/core/wma/src/wma_utils.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2013-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2021-2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2021-2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -708,7 +708,6 @@ int wma_stats_ext_event_handler(void *handle, uint8_t *event_buf, } stats_ext_info = param_buf->fixed_param; - buf_ptr = (uint8_t *)stats_ext_info; alloc_len = sizeof(tSirStatsExtEvent); alloc_len += stats_ext_info->data_len; @@ -725,7 +724,7 @@ int wma_stats_ext_event_handler(void *handle, uint8_t *event_buf, if (!stats_ext_event) return -ENOMEM; - buf_ptr += sizeof(wmi_stats_ext_event_fixed_param) + WMI_TLV_HDR_SIZE; + buf_ptr = (uint8_t *)param_buf->data; stats_ext_event->vdev_id = stats_ext_info->vdev_id; stats_ext_event->event_data_len = stats_ext_info->data_len; @@ -775,7 +774,6 @@ int wma_stats_ext_event_handler(void *handle, uint8_t *event_buf, } stats_ext_info = param_buf->fixed_param; - buf_ptr = (uint8_t *)stats_ext_info; alloc_len = sizeof(tSirStatsExtEvent); alloc_len += stats_ext_info->data_len; @@ -791,7 +789,7 @@ int wma_stats_ext_event_handler(void *handle, uint8_t *event_buf, if (!stats_ext_event) return -ENOMEM; - buf_ptr += sizeof(wmi_stats_ext_event_fixed_param) + WMI_TLV_HDR_SIZE; + buf_ptr = (uint8_t *)param_buf->data; stats_ext_event->vdev_id = stats_ext_info->vdev_id; stats_ext_event->event_data_len = stats_ext_info->data_len; From b6c8048d829e93b8b045ee0cb64c8257c766c31a Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Thu, 27 Mar 2025 11:15:32 -0700 Subject: [PATCH 11/27] Release 2.0.8.35A Release 2.0.8.35A Change-Id: Ib7f525b0dbae414daa80b9e2d204943d6827aae4 CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index 3b4e0d649715..5a0f26d5d2fc 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "" +#define QWLAN_VERSION_EXTRA "A" #define QWLAN_VERSION_BUILD 35 -#define QWLAN_VERSIONSTR "2.0.8.35" +#define QWLAN_VERSIONSTR "2.0.8.35A" #endif /* QWLAN_VERSION_H */ From 10e437e63d4d0d0caadd46ea6bf412dafcd068e8 Mon Sep 17 00:00:00 2001 From: Will Huang Date: Mon, 6 Sep 2021 17:07:50 +0800 Subject: [PATCH 12/27] qcacld-3.0: Fix mgmt tx from supplicant failed on 6 GHz chan Currently wlan_hdd_mgmt_tx path is still using legacy API to convert channel frequency to number, it is not applicable for 6 GHz channel if convert it back from number to frequency. Fix it by replace all places where using legacy API to convert channel and use channel frequency from supplicant directly. It can fix mgmt tx from supplicant on 6 GHz channel. Change-Id: I60fe37d7d716eeaceaa00f3fb59c77b629ebacac CRs-Fixed: 3024898 --- components/p2p/core/src/wlan_p2p_off_chan_tx.c | 5 +++-- components/p2p/core/src/wlan_p2p_off_chan_tx.h | 4 ++-- components/p2p/core/src/wlan_p2p_roc.c | 4 ++-- components/p2p/core/src/wlan_p2p_roc.h | 4 ++-- .../p2p/dispatcher/inc/wlan_p2p_public_struct.h | 5 +++-- core/hdd/src/wlan_hdd_p2p.c | 11 ++++++----- os_if/p2p/src/wlan_cfg80211_p2p.c | 17 ++++++++--------- 7 files changed, 26 insertions(+), 24 deletions(-) diff --git a/components/p2p/core/src/wlan_p2p_off_chan_tx.c b/components/p2p/core/src/wlan_p2p_off_chan_tx.c index 1478df85dce7..2d1417271ddf 100644 --- a/components/p2p/core/src/wlan_p2p_off_chan_tx.c +++ b/components/p2p/core/src/wlan_p2p_off_chan_tx.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022, 2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1076,7 +1076,8 @@ static QDF_STATUS p2p_mgmt_tx(struct tx_action_context *tx_ctx, mgmt_param.vdev_id = tx_ctx->vdev_id; mgmt_param.pdata = frame; if (tx_ctx->chan) - chanfreq = (uint16_t)wlan_chan_to_freq(tx_ctx->chan); + chanfreq = tx_ctx->chan; + mgmt_param.chanfreq = chanfreq; mgmt_param.qdf_ctx = wlan_psoc_get_qdf_dev(psoc); diff --git a/components/p2p/core/src/wlan_p2p_off_chan_tx.h b/components/p2p/core/src/wlan_p2p_off_chan_tx.h index 46e80fca5a33..00a7929c6484 100644 --- a/components/p2p/core/src/wlan_p2p_off_chan_tx.h +++ b/components/p2p/core/src/wlan_p2p_off_chan_tx.h @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2019 The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022, 2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -174,7 +174,7 @@ struct tx_action_context { int scan_id; uint64_t roc_cookie; int32_t id; - uint8_t chan; + qdf_freq_t chan; uint8_t *buf; int buf_len; bool off_chan; diff --git a/components/p2p/core/src/wlan_p2p_roc.c b/components/p2p/core/src/wlan_p2p_roc.c index 7146367eae62..f0c9881f3ff2 100644 --- a/components/p2p/core/src/wlan_p2p_roc.c +++ b/components/p2p/core/src/wlan_p2p_roc.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2023, 2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -114,7 +114,7 @@ static QDF_STATUS p2p_scan_start(struct p2p_roc_context *roc_ctx) req->scan_req.scan_type = SCAN_TYPE_P2P_LISTEN; req->scan_req.scan_req_id = p2p_soc_obj->scan_req_id; req->scan_req.chan_list.num_chan = 1; - req->scan_req.chan_list.chan[0].freq = wlan_chan_to_freq(roc_ctx->chan); + req->scan_req.chan_list.chan[0].freq = roc_ctx->chan; req->scan_req.dwell_time_passive = roc_ctx->duration; req->scan_req.dwell_time_active = 0; req->scan_req.scan_priority = SCAN_PRIORITY_HIGH; diff --git a/components/p2p/core/src/wlan_p2p_roc.h b/components/p2p/core/src/wlan_p2p_roc.h index 143e01726a8f..f1f27364ac7b 100644 --- a/components/p2p/core/src/wlan_p2p_roc.h +++ b/components/p2p/core/src/wlan_p2p_roc.h @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2019 The Linux Foundation. All rights reserved. - * Copyright (c) 2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2023, 2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -95,7 +95,7 @@ struct p2p_roc_context { uint32_t vdev_id; uint32_t scan_id; void *tx_ctx; - uint8_t chan; + qdf_freq_t chan; uint8_t phy_mode; uint32_t duration; enum roc_type roc_type; diff --git a/components/p2p/dispatcher/inc/wlan_p2p_public_struct.h b/components/p2p/dispatcher/inc/wlan_p2p_public_struct.h index 33fd71c70b40..1f09757a868b 100644 --- a/components/p2p/dispatcher/inc/wlan_p2p_public_struct.h +++ b/components/p2p/dispatcher/inc/wlan_p2p_public_struct.h @@ -1,5 +1,6 @@ /* * Copyright (c) 2017-2019 The Linux Foundation. All rights reserved. + * Copyright (c) 2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -67,7 +68,7 @@ struct p2p_ps_params { */ struct p2p_roc_req { uint32_t vdev_id; - uint32_t chan; + qdf_freq_t chan; uint32_t phy_mode; uint32_t duration; }; @@ -96,7 +97,7 @@ struct p2p_event { uint32_t vdev_id; enum p2p_roc_event roc_event; uint64_t cookie; - uint32_t chan; + qdf_freq_t chan; uint32_t duration; }; diff --git a/core/hdd/src/wlan_hdd_p2p.c b/core/hdd/src/wlan_hdd_p2p.c index 4743ce81ba2a..d8aee3c9ee21 100644 --- a/core/hdd/src/wlan_hdd_p2p.c +++ b/core/hdd/src/wlan_hdd_p2p.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2012-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2023, 2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -286,15 +286,16 @@ wlan_hdd_validate_and_override_offchan(struct hdd_adapter *adapter, struct ieee80211_channel *chan, bool *offchan) { - uint8_t home_ch; + qdf_freq_t home_ch_freq; if (!offchan || !chan || !(*offchan)) return; - home_ch = hdd_get_adapter_home_channel(adapter); + home_ch_freq = hdd_get_adapter_home_channel(adapter); - if (ieee80211_frequency_to_channel(chan->center_freq) == home_ch) { - hdd_debug("override offchan to 0 at home channel %d", home_ch); + if (chan->center_freq == home_ch_freq) { + hdd_debug("override offchan to 0 at home channel %d", + home_ch_freq); *offchan = false; } } diff --git a/os_if/p2p/src/wlan_cfg80211_p2p.c b/os_if/p2p/src/wlan_cfg80211_p2p.c index ddeba7bf0d51..4db1500f65fa 100644 --- a/os_if/p2p/src/wlan_cfg80211_p2p.c +++ b/os_if/p2p/src/wlan_cfg80211_p2p.c @@ -1,5 +1,6 @@ /* * Copyright (c) 2017-2020 The Linux Foundation. All rights reserved. + * Copyright (c) 2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -281,8 +282,7 @@ static void wlan_p2p_event_callback(void *user_data, goto fail; } - chan = ieee80211_get_channel(wdev->wiphy, - wlan_chan_to_freq(p2p_event->chan)); + chan = ieee80211_get_channel(wdev->wiphy, p2p_event->chan); if (!chan) { osif_err("channel conversion failed"); goto fail; @@ -360,7 +360,7 @@ int wlan_cfg80211_roc(struct wlan_objmgr_vdev *vdev, return -EINVAL; } - roc_req.chan = (uint32_t)wlan_freq_to_chan(chan->center_freq); + roc_req.chan = chan->center_freq; roc_req.duration = duration; roc_req.vdev_id = (uint32_t)vdev_id; @@ -409,7 +409,7 @@ int wlan_cfg80211_mgmt_tx(struct wlan_objmgr_vdev *vdev, struct p2p_mgmt_tx mgmt_tx = {0}; struct wlan_objmgr_psoc *psoc; uint8_t vdev_id; - uint32_t channel = 0; + qdf_freq_t chan_freq = 0; if (!vdev) { osif_err("invalid vdev object"); @@ -417,7 +417,7 @@ int wlan_cfg80211_mgmt_tx(struct wlan_objmgr_vdev *vdev, } if (chan) - channel = (uint32_t)wlan_freq_to_chan(chan->center_freq); + chan_freq = chan->center_freq; else osif_debug("NULL chan, set channel to 0"); @@ -436,8 +436,7 @@ int wlan_cfg80211_mgmt_tx(struct wlan_objmgr_vdev *vdev, int ret; bool ok; - ret = policy_mgr_is_chan_ok_for_dnbs( - psoc, wlan_chan_to_freq(channel), &ok); + ret = policy_mgr_is_chan_ok_for_dnbs(psoc, chan_freq, &ok); if (QDF_IS_STATUS_ERROR(ret)) { osif_err("policy_mgr_is_chan_ok_for_dnbs():ret:%d", ret); @@ -445,13 +444,13 @@ int wlan_cfg80211_mgmt_tx(struct wlan_objmgr_vdev *vdev, } if (!ok) { osif_err("Rejecting mgmt_tx for channel:%d as DNSC is set", - channel); + chan_freq); return -EINVAL; } } mgmt_tx.vdev_id = (uint32_t)vdev_id; - mgmt_tx.chan = channel; + mgmt_tx.chan = chan_freq; mgmt_tx.wait = wait; mgmt_tx.len = len; mgmt_tx.no_cck = (uint32_t)no_cck; From fda10761df20c96ac7540fcd21f49eefeca24798 Mon Sep 17 00:00:00 2001 From: Will Huang Date: Fri, 10 Sep 2021 10:40:22 +0800 Subject: [PATCH 13/27] qcacld-3.0: Rename variables name chan to chan_freq of wlan_hdd_mgmt_tx We have fixed using channel number as internal parameter instead of chan frequency with change I60fe37d7d716eeaceaa00f3fb59c77b629ebacac, but variables name are still chan which might cause confused to reader. Rename all places where "chan" to "chan_freq", which actually channel frequency used. And alter miss APIs which still expect channel number. Change-Id: I948cbad133a17093f49384b563966d2c53b51707 CRs-Fixed: 3033951 --- .../p2p/core/src/wlan_p2p_off_chan_tx.c | 77 ++++++++-------- .../p2p/core/src/wlan_p2p_off_chan_tx.h | 4 +- components/p2p/core/src/wlan_p2p_roc.c | 88 +++++++++++-------- components/p2p/core/src/wlan_p2p_roc.h | 12 +-- .../dispatcher/inc/wlan_p2p_public_struct.h | 12 +-- .../p2p/dispatcher/src/wlan_p2p_ucfg_api.c | 20 +++-- os_if/p2p/src/wlan_cfg80211_p2p.c | 8 +- 7 files changed, 120 insertions(+), 101 deletions(-) diff --git a/components/p2p/core/src/wlan_p2p_off_chan_tx.c b/components/p2p/core/src/wlan_p2p_off_chan_tx.c index 2d1417271ddf..857e619900a8 100644 --- a/components/p2p/core/src/wlan_p2p_off_chan_tx.c +++ b/components/p2p/core/src/wlan_p2p_off_chan_tx.c @@ -211,7 +211,7 @@ static QDF_STATUS p2p_check_and_update_channel(struct tx_action_context *tx_ctx) struct p2p_soc_priv_obj *p2p_soc_obj; struct p2p_roc_context *curr_roc_ctx; - if (!tx_ctx || tx_ctx->chan) { + if (!tx_ctx || tx_ctx->chan_freq) { p2p_err("NULL tx ctx or channel valid"); return QDF_STATUS_E_INVAL; } @@ -232,7 +232,7 @@ static QDF_STATUS p2p_check_and_update_channel(struct tx_action_context *tx_ctx) (mode == QDF_P2P_DEVICE_MODE || mode == QDF_P2P_CLIENT_MODE || mode == QDF_P2P_GO_MODE)) - tx_ctx->chan = curr_roc_ctx->chan; + tx_ctx->chan_freq = curr_roc_ctx->chan_freq; wlan_objmgr_vdev_release_ref(vdev, WLAN_P2P_ID); @@ -1068,17 +1068,13 @@ static QDF_STATUS p2p_mgmt_tx(struct tx_action_context *tx_ctx, void *mac_addr; uint8_t pdev_id; struct wlan_objmgr_vdev *vdev; - uint16_t chanfreq = 0; psoc = tx_ctx->p2p_soc_obj->soc; mgmt_param.tx_frame = packet; mgmt_param.frm_len = buf_len; mgmt_param.vdev_id = tx_ctx->vdev_id; mgmt_param.pdata = frame; - if (tx_ctx->chan) - chanfreq = tx_ctx->chan; - - mgmt_param.chanfreq = chanfreq; + mgmt_param.chanfreq = tx_ctx->chan_freq; mgmt_param.qdf_ctx = wlan_psoc_get_qdf_dev(psoc); if (!(mgmt_param.qdf_ctx)) { @@ -1162,7 +1158,7 @@ static QDF_STATUS p2p_roc_req_for_tx_action( p2p_soc_obj = tx_ctx->p2p_soc_obj; roc_ctx->p2p_soc_obj = p2p_soc_obj; roc_ctx->vdev_id = tx_ctx->vdev_id; - roc_ctx->chan = tx_ctx->chan; + roc_ctx->chan_freq = tx_ctx->chan_freq; roc_ctx->duration = tx_ctx->duration; roc_ctx->roc_state = ROC_STATE_IDLE; roc_ctx->roc_type = OFF_CHANNEL_TX; @@ -1805,13 +1801,15 @@ void p2p_dump_tx_queue(struct p2p_soc_priv_obj *p2p_soc_obj) while (QDF_IS_STATUS_SUCCESS(status)) { tx_ctx = qdf_container_of(p_node, struct tx_action_context, node); - p2p_debug("p2p soc object:%pK, tx ctx:%pK, vdev_id:%d, scan_id:%d, roc_cookie:%llx, chan:%d, buf:%pK, len:%d, off_chan:%d, cck:%d, ack:%d, duration:%d", - p2p_soc_obj, tx_ctx, - tx_ctx->vdev_id, tx_ctx->scan_id, - tx_ctx->roc_cookie, tx_ctx->chan, - tx_ctx->buf, tx_ctx->buf_len, - tx_ctx->off_chan, tx_ctx->no_cck, - tx_ctx->no_ack, tx_ctx->duration); + p2p_debug("p2p soc object:%pK, tx ctx:%pK, vdev_id:%d, " + "scan_id:%d, roc_cookie:%llx, freq:%d, buf:%pK, " + "len:%d, off_chan:%d, cck:%d, ack:%d, duration:%d", + p2p_soc_obj, tx_ctx, + tx_ctx->vdev_id, tx_ctx->scan_id, + tx_ctx->roc_cookie, tx_ctx->chan_freq, + tx_ctx->buf, tx_ctx->buf_len, + tx_ctx->off_chan, tx_ctx->no_cck, + tx_ctx->no_ack, tx_ctx->duration); status = qdf_list_peek_next(&p2p_soc_obj->tx_q_roc, p_node, &p_node); @@ -1823,13 +1821,15 @@ void p2p_dump_tx_queue(struct p2p_soc_priv_obj *p2p_soc_obj) while (QDF_IS_STATUS_SUCCESS(status)) { tx_ctx = qdf_container_of(p_node, struct tx_action_context, node); - p2p_debug("p2p soc object:%pK, tx_ctx:%pK, vdev_id:%d, scan_id:%d, roc_cookie:%llx, chan:%d, buf:%pK, len:%d, off_chan:%d, cck:%d, ack:%d, duration:%d", - p2p_soc_obj, tx_ctx, - tx_ctx->vdev_id, tx_ctx->scan_id, - tx_ctx->roc_cookie, tx_ctx->chan, - tx_ctx->buf, tx_ctx->buf_len, - tx_ctx->off_chan, tx_ctx->no_cck, - tx_ctx->no_ack, tx_ctx->duration); + p2p_debug("p2p soc object:%pK, tx_ctx:%pK, vdev_id:%d, " + "scan_id:%d, roc_cookie:%llx, freq:%d, buf:%pK, " + "len:%d, off_chan:%d, cck:%d, ack:%d, duration:%d", + p2p_soc_obj, tx_ctx, + tx_ctx->vdev_id, tx_ctx->scan_id, + tx_ctx->roc_cookie, tx_ctx->chan_freq, + tx_ctx->buf, tx_ctx->buf_len, + tx_ctx->off_chan, tx_ctx->no_cck, + tx_ctx->no_ack, tx_ctx->duration); status = qdf_list_peek_next(&p2p_soc_obj->tx_q_ack, p_node, &p_node); @@ -2919,17 +2919,17 @@ void p2p_rand_mac_tx(struct tx_action_context *tx_action) return; soc = tx_action->p2p_soc_obj->soc; - if (!tx_action->no_ack && tx_action->chan && + if (!tx_action->no_ack && tx_action->chan_freq && tx_action->buf_len > MIN_MAC_HEADER_LEN && p2p_is_vdev_support_rand_mac_by_id(soc, tx_action->vdev_id) && p2p_is_random_mac(soc, tx_action->vdev_id, &tx_action->buf[SRC_MAC_ADDR_OFFSET])) { status = p2p_request_random_mac( - soc, tx_action->vdev_id, - &tx_action->buf[SRC_MAC_ADDR_OFFSET], - wlan_chan_to_freq(tx_action->chan), - tx_action->id, - tx_action->duration); + soc, tx_action->vdev_id, + &tx_action->buf[SRC_MAC_ADDR_OFFSET], + tx_action->chan_freq, + tx_action->id, + tx_action->duration); if (status == QDF_STATUS_SUCCESS) tx_action->rand_mac_tx = true; else @@ -2999,11 +2999,13 @@ QDF_STATUS p2p_process_mgmt_tx(struct tx_action_context *tx_ctx) p2p_soc_obj = tx_ctx->p2p_soc_obj; - p2p_debug("soc:%pK, tx_ctx:%pK, vdev_id:%d, scan_id:%d, roc_cookie:%llx, chan:%d, buf:%pK, len:%d, off_chan:%d, cck:%d, ack:%d, duration:%d", - p2p_soc_obj->soc, tx_ctx, tx_ctx->vdev_id, - tx_ctx->scan_id, tx_ctx->roc_cookie, tx_ctx->chan, - tx_ctx->buf, tx_ctx->buf_len, tx_ctx->off_chan, - tx_ctx->no_cck, tx_ctx->no_ack, tx_ctx->duration); + p2p_debug("soc:%pK, tx_ctx:%pK, vdev_id:%d, scan_id:%d, " + "roc_cookie:%llx, freq:%d, buf:%pK, len:%d, " + "off_chan:%d, cck:%d, ack:%d, duration:%d", + p2p_soc_obj->soc, tx_ctx, tx_ctx->vdev_id, + tx_ctx->scan_id, tx_ctx->roc_cookie, tx_ctx->chan_freq, + tx_ctx->buf, tx_ctx->buf_len, tx_ctx->off_chan, + tx_ctx->no_cck, tx_ctx->no_ack, tx_ctx->duration); status = p2p_get_frame_info(tx_ctx->buf, tx_ctx->buf_len, &(tx_ctx->frame_info)); @@ -3032,8 +3034,8 @@ QDF_STATUS p2p_process_mgmt_tx(struct tx_action_context *tx_ctx) tx_ctx->no_ack = 1; } - if (!tx_ctx->off_chan || !tx_ctx->chan) { - if (!tx_ctx->chan) + if (!tx_ctx->off_chan || !tx_ctx->chan_freq) { + if (!tx_ctx->chan_freq) p2p_check_and_update_channel(tx_ctx); status = p2p_execute_tx_action_frame(tx_ctx); if (status != QDF_STATUS_SUCCESS) { @@ -3045,7 +3047,7 @@ QDF_STATUS p2p_process_mgmt_tx(struct tx_action_context *tx_ctx) /* For off channel tx case */ curr_roc_ctx = p2p_find_current_roc_ctx(p2p_soc_obj); - if (curr_roc_ctx && (curr_roc_ctx->chan == tx_ctx->chan)) { + if (curr_roc_ctx && (curr_roc_ctx->chan_freq == tx_ctx->chan_freq)) { if ((curr_roc_ctx->roc_state == ROC_STATE_REQUESTED) || (curr_roc_ctx->roc_state == ROC_STATE_STARTED)) { tx_ctx->roc_cookie = (uintptr_t)curr_roc_ctx; @@ -3076,7 +3078,8 @@ QDF_STATUS p2p_process_mgmt_tx(struct tx_action_context *tx_ctx) } } - curr_roc_ctx = p2p_find_roc_by_chan(p2p_soc_obj, tx_ctx->chan); + curr_roc_ctx = p2p_find_roc_by_chan_freq(p2p_soc_obj, + tx_ctx->chan_freq); if (curr_roc_ctx && (curr_roc_ctx->roc_state == ROC_STATE_IDLE)) { tx_ctx->roc_cookie = (uintptr_t)curr_roc_ctx; status = qdf_list_insert_back( diff --git a/components/p2p/core/src/wlan_p2p_off_chan_tx.h b/components/p2p/core/src/wlan_p2p_off_chan_tx.h index 00a7929c6484..5b98ccbc7066 100644 --- a/components/p2p/core/src/wlan_p2p_off_chan_tx.h +++ b/components/p2p/core/src/wlan_p2p_off_chan_tx.h @@ -157,7 +157,7 @@ struct p2p_frame_info { * @scan_id: Scan id given by scan component for this roc req * @roc_cookie: Cookie for remain on channel request * @id: Identifier of this tx context - * @chan: Chan for which this tx has been requested + * @chan_freq: Chan frequency for which this tx has been requested * @buf: tx buffer * @buf_len: Length of tx buffer * @off_chan: Is this off channel tx @@ -174,7 +174,7 @@ struct tx_action_context { int scan_id; uint64_t roc_cookie; int32_t id; - qdf_freq_t chan; + qdf_freq_t chan_freq; uint8_t *buf; int buf_len; bool off_chan; diff --git a/components/p2p/core/src/wlan_p2p_roc.c b/components/p2p/core/src/wlan_p2p_roc.c index f0c9881f3ff2..643d54a1a428 100644 --- a/components/p2p/core/src/wlan_p2p_roc.c +++ b/components/p2p/core/src/wlan_p2p_roc.c @@ -114,7 +114,7 @@ static QDF_STATUS p2p_scan_start(struct p2p_roc_context *roc_ctx) req->scan_req.scan_type = SCAN_TYPE_P2P_LISTEN; req->scan_req.scan_req_id = p2p_soc_obj->scan_req_id; req->scan_req.chan_list.num_chan = 1; - req->scan_req.chan_list.chan[0].freq = roc_ctx->chan; + req->scan_req.chan_list.chan[0].freq = roc_ctx->chan_freq; req->scan_req.dwell_time_passive = roc_ctx->duration; req->scan_req.dwell_time_active = 0; req->scan_req.scan_priority = SCAN_PRIORITY_HIGH; @@ -278,7 +278,7 @@ static QDF_STATUS p2p_send_roc_event( p2p_evt.vdev_id = roc_ctx->vdev_id; p2p_evt.roc_event = evt; p2p_evt.cookie = (uint64_t)roc_ctx->id; - p2p_evt.chan = roc_ctx->chan; + p2p_evt.chan_freq = roc_ctx->chan_freq; p2p_evt.duration = roc_ctx->duration; p2p_debug("roc_event: %d, cookie:%llx", p2p_evt.roc_event, @@ -305,9 +305,10 @@ static QDF_STATUS p2p_destroy_roc_ctx(struct p2p_roc_context *roc_ctx, QDF_STATUS status = QDF_STATUS_SUCCESS; struct p2p_soc_priv_obj *p2p_soc_obj = roc_ctx->p2p_soc_obj; - p2p_debug("p2p_soc_obj:%pK, roc_ctx:%pK, up_layer_event:%d, in_roc_queue:%d vdev_id:%d chan:%d duration:%d", - p2p_soc_obj, roc_ctx, up_layer_event, in_roc_queue, - roc_ctx->vdev_id, roc_ctx->chan, roc_ctx->duration); + p2p_debug("p2p_soc_obj:%pK, roc_ctx:%pK, up_layer_event:%d," + " in_roc_queue:%d vdev_id:%d freq:%d duration:%d", + p2p_soc_obj, roc_ctx, up_layer_event, in_roc_queue, + roc_ctx->vdev_id, roc_ctx->chan_freq, roc_ctx->duration); if (up_layer_event) { if (roc_ctx->roc_state < ROC_STATE_ON_CHAN) @@ -391,11 +392,13 @@ static void p2p_roc_timeout(void *pdata) return; } - p2p_debug("p2p soc obj:%pK, roc ctx:%pK, vdev_id:%d, scan_id:%d, tx ctx:%pK, chan:%d, phy_mode:%d, duration:%d, roc_type:%d, roc_state:%d", - roc_ctx->p2p_soc_obj, roc_ctx, roc_ctx->vdev_id, - roc_ctx->scan_id, roc_ctx->tx_ctx, roc_ctx->chan, - roc_ctx->phy_mode, roc_ctx->duration, - roc_ctx->roc_type, roc_ctx->roc_state); + p2p_debug("p2p soc obj:%pK, roc ctx:%pK, vdev_id:%d, scan_id:%d," + " tx ctx:%pK, freq:%d, phy_mode:%d, duration:%d," + " roc_type:%d, roc_state:%d", + roc_ctx->p2p_soc_obj, roc_ctx, roc_ctx->vdev_id, + roc_ctx->scan_id, roc_ctx->tx_ctx, roc_ctx->chan_freq, + roc_ctx->phy_mode, roc_ctx->duration, + roc_ctx->roc_type, roc_ctx->roc_state); if (roc_ctx->roc_state == ROC_STATE_CANCEL_IN_PROG) { p2p_err("Cancellation already in progress"); @@ -418,11 +421,13 @@ static QDF_STATUS p2p_execute_roc_req(struct p2p_roc_context *roc_ctx) QDF_STATUS status; struct p2p_soc_priv_obj *p2p_soc_obj = roc_ctx->p2p_soc_obj; - p2p_debug("p2p soc obj:%pK, roc ctx:%pK, vdev_id:%d, scan_id:%d, tx ctx:%pK, chan:%d, phy_mode:%d, duration:%d, roc_type:%d, roc_state:%d", - p2p_soc_obj, roc_ctx, roc_ctx->vdev_id, - roc_ctx->scan_id, roc_ctx->tx_ctx, roc_ctx->chan, - roc_ctx->phy_mode, roc_ctx->duration, - roc_ctx->roc_type, roc_ctx->roc_state); + p2p_debug("p2p soc obj:%pK, roc ctx:%pK, vdev_id:%d, scan_id:%d," + " tx ctx:%pK, freq:%d, phy_mode:%d, duration:%d," + " roc_type:%d, roc_state:%d", + p2p_soc_obj, roc_ctx, roc_ctx->vdev_id, + roc_ctx->scan_id, roc_ctx->tx_ctx, roc_ctx->chan_freq, + roc_ctx->phy_mode, roc_ctx->duration, + roc_ctx->roc_type, roc_ctx->roc_state); /* prevent runtime suspend */ qdf_runtime_pm_prevent_suspend(&p2p_soc_obj->roc_runtime_lock); @@ -645,14 +650,14 @@ struct p2p_roc_context *p2p_find_current_roc_ctx( struct p2p_roc_context, node); if (roc_ctx->roc_state != ROC_STATE_IDLE) { p2p_debug("p2p soc obj:%pK, roc ctx:%pK, vdev_id" - ":%d, scan_id:%d, tx ctx:%pK, chan:" - "%d, phy_mode:%d, duration:%d, " - "roc_type:%d, roc_state:%d", - roc_ctx->p2p_soc_obj, roc_ctx, - roc_ctx->vdev_id, roc_ctx->scan_id, - roc_ctx->tx_ctx, roc_ctx->chan, - roc_ctx->phy_mode, roc_ctx->duration, - roc_ctx->roc_type, roc_ctx->roc_state); + ":%d, scan_id:%d, tx ctx:%pK, freq:" + "%d, phy_mode:%d, duration:%d, " + "roc_type:%d, roc_state:%d", + roc_ctx->p2p_soc_obj, roc_ctx, + roc_ctx->vdev_id, roc_ctx->scan_id, + roc_ctx->tx_ctx, roc_ctx->chan_freq, + roc_ctx->phy_mode, roc_ctx->duration, + roc_ctx->roc_type, roc_ctx->roc_state); return roc_ctx; } @@ -685,8 +690,8 @@ struct p2p_roc_context *p2p_find_roc_by_tx_ctx( return NULL; } -struct p2p_roc_context *p2p_find_roc_by_chan( - struct p2p_soc_priv_obj *p2p_soc_obj, uint8_t chan) +struct p2p_roc_context *p2p_find_roc_by_chan_freq( + struct p2p_soc_priv_obj *p2p_soc_obj, qdf_freq_t chan_freq) { struct p2p_roc_context *roc_ctx; qdf_list_node_t *p_node; @@ -697,11 +702,14 @@ struct p2p_roc_context *p2p_find_roc_by_chan( roc_ctx = qdf_container_of(p_node, struct p2p_roc_context, node); - if (roc_ctx->chan == chan) { - p2p_debug("p2p soc obj:%pK, roc ctx:%pK, vdev_id:%d, scan_id:%d, tx ctx:%pK, chan:%d, phy_mode:%d, duration:%d, roc_type:%d, roc_state:%d", + if (roc_ctx->chan_freq == chan_freq) { + p2p_debug("p2p soc obj:%pK, roc ctx:%pK, vdev_id:%d," + " scan_id:%d, tx ctx:%pK, freq:%d," + " phy_mode:%d, duration:%d," + " roc_type:%d, roc_state:%d", roc_ctx->p2p_soc_obj, roc_ctx, roc_ctx->vdev_id, roc_ctx->scan_id, - roc_ctx->tx_ctx, roc_ctx->chan, + roc_ctx->tx_ctx, roc_ctx->chan_freq, roc_ctx->phy_mode, roc_ctx->duration, roc_ctx->roc_type, roc_ctx->roc_state); @@ -808,10 +816,12 @@ QDF_STATUS p2p_process_cleanup_roc_queue( roc_ctx = qdf_container_of(p_node, struct p2p_roc_context, node); - p2p_debug("p2p soc obj:%pK, roc ctx:%pK, vdev_id:%d, scan_id:%d, tx ctx:%pK, chan:%d, phy_mode:%d, duration:%d, roc_type:%d, roc_state:%d", + p2p_debug("p2p soc obj:%pK, roc ctx:%pK, vdev_id:%d, " + "scan_id:%d, tx ctx:%pK, freq:%d, phy_mode:%d, " + "duration:%d, roc_type:%d, roc_state:%d", roc_ctx->p2p_soc_obj, roc_ctx, roc_ctx->vdev_id, roc_ctx->scan_id, - roc_ctx->tx_ctx, roc_ctx->chan, + roc_ctx->tx_ctx, roc_ctx->chan_freq, roc_ctx->phy_mode, roc_ctx->duration, roc_ctx->roc_type, roc_ctx->roc_state); status = qdf_list_peek_next(&p2p_soc_obj->roc_q, @@ -836,9 +846,11 @@ QDF_STATUS p2p_process_cleanup_roc_queue( roc_ctx = qdf_container_of(p_node, struct p2p_roc_context, node); - p2p_debug("p2p soc obj:%pK, roc ctx:%pK, vdev_id:%d, scan_id:%d, tx ctx:%pK, chan:%d, phy_mode:%d, duration:%d, roc_type:%d, roc_state:%d", + p2p_debug("p2p soc obj:%pK, roc ctx:%pK, vdev_id:%d, " + "scan_id:%d, tx ctx:%pK, freq:%d, phy_mode:%d, " + "duration:%d, roc_type:%d, roc_state:%d", roc_ctx->p2p_soc_obj, roc_ctx, roc_ctx->vdev_id, - roc_ctx->scan_id, roc_ctx->tx_ctx, roc_ctx->chan, + roc_ctx->scan_id, roc_ctx->tx_ctx, roc_ctx->chan_freq, roc_ctx->phy_mode, roc_ctx->duration, roc_ctx->roc_type, roc_ctx->roc_state); @@ -871,11 +883,13 @@ QDF_STATUS p2p_process_roc_req(struct p2p_roc_context *roc_ctx) p2p_soc_obj = roc_ctx->p2p_soc_obj; - p2p_debug("p2p soc obj:%pK, roc ctx:%pK, vdev_id:%d, scan_id:%d, tx_ctx:%pK, chan:%d, phy_mode:%d, duration:%d, roc_type:%d, roc_state:%d", - p2p_soc_obj, roc_ctx, roc_ctx->vdev_id, - roc_ctx->scan_id, roc_ctx->tx_ctx, roc_ctx->chan, - roc_ctx->phy_mode, roc_ctx->duration, - roc_ctx->roc_type, roc_ctx->roc_state); + p2p_debug("p2p soc obj:%pK, roc ctx:%pK, vdev_id:%d, scan_id:%d, " + "tx_ctx:%pK, freq:%d, phy_mode:%d, duration:%d, " + "roc_type:%d, roc_state:%d", + p2p_soc_obj, roc_ctx, roc_ctx->vdev_id, + roc_ctx->scan_id, roc_ctx->tx_ctx, roc_ctx->chan_freq, + roc_ctx->phy_mode, roc_ctx->duration, + roc_ctx->roc_type, roc_ctx->roc_state); status = qdf_list_insert_back(&p2p_soc_obj->roc_q, &roc_ctx->node); diff --git a/components/p2p/core/src/wlan_p2p_roc.h b/components/p2p/core/src/wlan_p2p_roc.h index f1f27364ac7b..b800b20174b4 100644 --- a/components/p2p/core/src/wlan_p2p_roc.h +++ b/components/p2p/core/src/wlan_p2p_roc.h @@ -81,7 +81,7 @@ enum roc_state { * @vdev_id: Vdev id on which this request has come * @scan_id: Scan id given by scan component for this roc req * @tx_ctx: TX context if this ROC is for tx MGMT - * @chan: Chan for which this RoC has been requested + * @chan_freq: Chan frequency for which this RoC has been requested * @phy_mode: PHY mode * @duration: Duration for the RoC * @roc_type: RoC type User requested or internal @@ -95,7 +95,7 @@ struct p2p_roc_context { uint32_t vdev_id; uint32_t scan_id; void *tx_ctx; - qdf_freq_t chan; + qdf_freq_t chan_freq; uint8_t phy_mode; uint32_t duration; enum roc_type roc_type; @@ -165,9 +165,9 @@ struct p2p_roc_context *p2p_find_roc_by_tx_ctx( struct p2p_soc_priv_obj *p2p_soc_obj, uint64_t cookie); /** - * p2p_find_roc_by_chan() - Find out roc context by channel + * p2p_find_roc_by_chan_freq() - Find out roc context by channel * @p2p_soc_obj: p2p psoc private object - * @chan: channel of the ROC + * @chan_freq: channel frequency of the ROC * * This function finds out roc context by channel from p2p psoc * private object @@ -175,8 +175,8 @@ struct p2p_roc_context *p2p_find_roc_by_tx_ctx( * Return: Pointer to roc context - success * NULL - failure */ -struct p2p_roc_context *p2p_find_roc_by_chan( - struct p2p_soc_priv_obj *p2p_soc_obj, uint8_t chan); +struct p2p_roc_context *p2p_find_roc_by_chan_freq( + struct p2p_soc_priv_obj *p2p_soc_obj, qdf_freq_t chan_freq); /** * p2p_restart_roc_timer() - Restarts roc timer diff --git a/components/p2p/dispatcher/inc/wlan_p2p_public_struct.h b/components/p2p/dispatcher/inc/wlan_p2p_public_struct.h index 1f09757a868b..060f0df3ba8b 100644 --- a/components/p2p/dispatcher/inc/wlan_p2p_public_struct.h +++ b/components/p2p/dispatcher/inc/wlan_p2p_public_struct.h @@ -62,13 +62,13 @@ struct p2p_ps_params { /** * struct p2p_roc_req - P2P roc request * @vdev_id: Vdev id on which this request has come - * @chan: Chan for which this RoC has been requested + * @chan_freq: Chan frequency for which this RoC has been requested * @phy_mode: PHY mode * @duration: Duration for the RoC */ struct p2p_roc_req { uint32_t vdev_id; - qdf_freq_t chan; + qdf_freq_t chan_freq; uint32_t phy_mode; uint32_t duration; }; @@ -90,14 +90,14 @@ enum p2p_roc_event { * @vdev_id: Vdev id * @roc_event: RoC event * @cookie: Cookie which is given to supplicant for this roc req - * @chan: Chan for which this RoC has been requested + * @chan_freq: Chan frequency for which this RoC has been requested * @duration: Duration for the RoC */ struct p2p_event { uint32_t vdev_id; enum p2p_roc_event roc_event; uint64_t cookie; - qdf_freq_t chan; + qdf_freq_t chan_freq; uint32_t duration; }; @@ -138,7 +138,7 @@ struct p2p_tx_cnf { /** * struct p2p_mgmt_tx - p2p mgmt tx structure * @vdev_id: Vdev id - * @chan: Chan for which this RoC has been requested + * @chan_freq: Chan frequency for which this RoC has been requested * @wait: Duration for the RoC * @len: Length of tx buffer * @no_cck: Required cck or not @@ -148,7 +148,7 @@ struct p2p_tx_cnf { */ struct p2p_mgmt_tx { uint32_t vdev_id; - uint32_t chan; + qdf_freq_t chan_freq; uint32_t wait; uint32_t len; uint32_t no_cck; diff --git a/components/p2p/dispatcher/src/wlan_p2p_ucfg_api.c b/components/p2p/dispatcher/src/wlan_p2p_ucfg_api.c index 50444dc6d8e4..3b862f62d3de 100644 --- a/components/p2p/dispatcher/src/wlan_p2p_ucfg_api.c +++ b/components/p2p/dispatcher/src/wlan_p2p_ucfg_api.c @@ -1,5 +1,6 @@ /* * Copyright (c) 2017-2020 The Linux Foundation. All rights reserved. + * Copyright (c) 2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -118,9 +119,9 @@ QDF_STATUS ucfg_p2p_roc_req(struct wlan_objmgr_psoc *soc, QDF_STATUS status; int32_t id; - p2p_debug("soc:%pK, vdev_id:%d, chan:%d, phy_mode:%d, duration:%d", - soc, roc_req->vdev_id, roc_req->chan, - roc_req->phy_mode, roc_req->duration); + p2p_debug("soc:%pK, vdev_id:%d, chanfreq:%d, phy_mode:%d, duration:%d", + soc, roc_req->vdev_id, roc_req->chan_freq, + roc_req->phy_mode, roc_req->duration); if (!soc) { p2p_err("psoc context passed is NULL"); @@ -148,7 +149,7 @@ QDF_STATUS ucfg_p2p_roc_req(struct wlan_objmgr_psoc *soc, *cookie = (uint64_t)id; roc_ctx->p2p_soc_obj = p2p_soc_obj; roc_ctx->vdev_id = roc_req->vdev_id; - roc_ctx->chan = roc_req->chan; + roc_ctx->chan_freq = roc_req->chan_freq; roc_ctx->phy_mode = roc_req->phy_mode; roc_ctx->duration = roc_req->duration; roc_ctx->roc_state = ROC_STATE_IDLE; @@ -324,10 +325,11 @@ QDF_STATUS ucfg_p2p_mgmt_tx(struct wlan_objmgr_psoc *soc, QDF_STATUS status; int32_t id; - p2p_debug("soc:%pK, vdev_id:%d, chan:%d, wait:%d, buf_len:%d, cck:%d, no ack:%d, off chan:%d", - soc, mgmt_frm->vdev_id, mgmt_frm->chan, - mgmt_frm->wait, mgmt_frm->len, mgmt_frm->no_cck, - mgmt_frm->dont_wait_for_ack, mgmt_frm->off_chan); + p2p_debug("soc:%pK, vdev_id:%d, freq:%d, wait:%d, buf_len:%d," + " cck:%d, no ack:%d, off chan:%d", + soc, mgmt_frm->vdev_id, mgmt_frm->chan_freq, + mgmt_frm->wait, mgmt_frm->len, mgmt_frm->no_cck, + mgmt_frm->dont_wait_for_ack, mgmt_frm->off_chan); if (!soc) { p2p_err("psoc context passed is NULL"); @@ -361,7 +363,7 @@ QDF_STATUS ucfg_p2p_mgmt_tx(struct wlan_objmgr_psoc *soc, *cookie = (uint64_t)id; tx_action->p2p_soc_obj = p2p_soc_obj; tx_action->vdev_id = mgmt_frm->vdev_id; - tx_action->chan = mgmt_frm->chan; + tx_action->chan_freq = mgmt_frm->chan_freq; tx_action->duration = mgmt_frm->wait; tx_action->buf_len = mgmt_frm->len; tx_action->no_cck = mgmt_frm->no_cck; diff --git a/os_if/p2p/src/wlan_cfg80211_p2p.c b/os_if/p2p/src/wlan_cfg80211_p2p.c index 4db1500f65fa..8363fbe52a80 100644 --- a/os_if/p2p/src/wlan_cfg80211_p2p.c +++ b/os_if/p2p/src/wlan_cfg80211_p2p.c @@ -282,7 +282,7 @@ static void wlan_p2p_event_callback(void *user_data, goto fail; } - chan = ieee80211_get_channel(wdev->wiphy, p2p_event->chan); + chan = ieee80211_get_channel(wdev->wiphy, p2p_event->chan_freq); if (!chan) { osif_err("channel conversion failed"); goto fail; @@ -360,7 +360,7 @@ int wlan_cfg80211_roc(struct wlan_objmgr_vdev *vdev, return -EINVAL; } - roc_req.chan = chan->center_freq; + roc_req.chan_freq = chan->center_freq; roc_req.duration = duration; roc_req.vdev_id = (uint32_t)vdev_id; @@ -372,7 +372,7 @@ int wlan_cfg80211_roc(struct wlan_objmgr_vdev *vdev, } if (!ok) { - osif_err("channel%d not OK for DNBS", roc_req.chan); + osif_err("channel%d not OK for DNBS", roc_req.chan_freq); return -EINVAL; } @@ -450,7 +450,7 @@ int wlan_cfg80211_mgmt_tx(struct wlan_objmgr_vdev *vdev, } mgmt_tx.vdev_id = (uint32_t)vdev_id; - mgmt_tx.chan = chan_freq; + mgmt_tx.chan_freq = chan_freq; mgmt_tx.wait = wait; mgmt_tx.len = len; mgmt_tx.no_cck = (uint32_t)no_cck; From d6e1ed30e5bd70090f15ccd40fcfa26e8dbb9914 Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Thu, 10 Apr 2025 01:07:24 -0700 Subject: [PATCH 14/27] Release 2.0.8.35B Release 2.0.8.35B Change-Id: Id320fd9d156ae0f075b050ba530da1bce5bb2a69 CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index 5a0f26d5d2fc..d27763477199 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "A" +#define QWLAN_VERSION_EXTRA "B" #define QWLAN_VERSION_BUILD 35 -#define QWLAN_VERSIONSTR "2.0.8.35A" +#define QWLAN_VERSIONSTR "2.0.8.35B" #endif /* QWLAN_VERSION_H */ From 251ec89b59f1760acaf71e256895f8804a922c95 Mon Sep 17 00:00:00 2001 From: Krupali Dhanvijay Date: Wed, 19 Mar 2025 14:41:55 +0530 Subject: [PATCH 15/27] qcacld-3.0: Update PMK from firmware for FT-SAE AKM also When roaming happens with full SAE for FT-SAE AKMs host doesn't update the PMK received from firmware into its global cache. This causes stale PMK to be sent to firmware when full SAE happens when roaming to below AKM's: WLAN_CRYPTO_KEY_MGMT_FT_SAE WLAN_CRYPTO_KEY_MGMT_FT_SAE_EXT_KEY So update the PMK sent from firmware for above AKM's when auth status is connected (full SAE happens at host). CRs-Fixed: 3807689 Change-Id: I25d1a253de37481952c41f54697521285a0ccf92 --- core/sme/src/csr/csr_api_roam.c | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/core/sme/src/csr/csr_api_roam.c b/core/sme/src/csr/csr_api_roam.c index 262b4f292c30..c67bbe35827c 100644 --- a/core/sme/src/csr/csr_api_roam.c +++ b/core/sme/src/csr/csr_api_roam.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2012-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2022-2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -21586,11 +21586,12 @@ csr_process_roam_sync_callback(struct mac_context *mac_ctx, * eapol. So the session->psk_pmk will be stale in PMKSA cached * SAE/OWE roaming case. */ + akm_type = session->connectedProfile.AuthType; + if (roam_synch_data->authStatus == CSR_ROAM_AUTH_STATUS_AUTHENTICATED || - session->pCurRoamProfile->negotiatedAuthType == - eCSR_AUTH_TYPE_SAE || - session->pCurRoamProfile->negotiatedAuthType == - eCSR_AUTH_TYPE_OWE) { + akm_type == eCSR_AUTH_TYPE_SAE || + akm_type == eCSR_AUTH_TYPE_FT_SAE || + akm_type == eCSR_AUTH_TYPE_OWE) { csr_roam_substate_change(mac_ctx, eCSR_ROAM_SUBSTATE_NONE, session_id); /* @@ -21615,8 +21616,7 @@ csr_process_roam_sync_callback(struct mac_context *mac_ctx, &session->connectedProfile.bssid); sme_debug("Trying to find PMKID for " QDF_MAC_ADDR_FMT " AKM Type:%d", QDF_MAC_ADDR_REF(pmkid_cache->BSSID.bytes), - session->pCurRoamProfile->negotiatedAuthType); - akm_type = session->connectedProfile.AuthType; + akm_type); mdie_present = session->connectedProfile.mdid.mdie_present; if (csr_lookup_pmkid_using_bssid(mac_ctx, session, @@ -21696,6 +21696,8 @@ csr_process_roam_sync_callback(struct mac_context *mac_ctx, qdf_mem_zero(pmksa, sizeof(*pmksa)); qdf_mem_free(pmksa); } + } else { + sme_debug("PMK not received from fw"); } sme_debug("pmkid found for " QDF_MAC_ADDR_FMT " len %d", QDF_MAC_ADDR_REF(pmkid_cache->BSSID.bytes), From 2db179ead0b8274d64f36ef05d0e14748fe657d5 Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Thu, 29 May 2025 01:11:39 -0700 Subject: [PATCH 16/27] Release 2.0.8.35C Release 2.0.8.35C Change-Id: I6d812e6d4eadfd09a9c6f39761446e73bf207c7f CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index d27763477199..8b118e5e2c21 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "B" +#define QWLAN_VERSION_EXTRA "C" #define QWLAN_VERSION_BUILD 35 -#define QWLAN_VERSIONSTR "2.0.8.35B" +#define QWLAN_VERSIONSTR "2.0.8.35C" #endif /* QWLAN_VERSION_H */ From 1879db349b12c562330bd695942a1bb713d60135 Mon Sep 17 00:00:00 2001 From: Eswar Kesavalu Date: Fri, 2 May 2025 15:56:44 +0530 Subject: [PATCH 17/27] qcacld-3.0: Add ini to apply RSSI delta for 6 GHz roam Introduce a new ini parameter, to apply an RSSI penalty to non-6 GHz candidate APs during roaming from 6 GHz AP. This ensures roaming to non-6 GHz AP occurs only if it offers significantly better signal quality. Change-Id: I02482c37c56c44d3d1804282abd09deaefb8eed3 CRs-Fixed: 4141300 --- components/mlme/core/src/wlan_mlme_main.c | 3 ++ components/mlme/dispatcher/inc/cfg_mlme_lfr.h | 34 +++++++++++++ .../dispatcher/inc/wlan_mlme_public_struct.h | 8 ++- .../src/target_if_cm_roam_offload.c | 50 +++++++++++++++++++ .../core/src/wlan_cm_roam_offload.c | 8 +++ .../inc/wlan_cm_roam_public_struct.h | 12 +++++ .../dispatcher/src/wlan_cm_roam_api.c | 9 ++++ core/sme/src/csr/csr_neighbor_roam.c | 3 ++ 8 files changed, 125 insertions(+), 2 deletions(-) diff --git a/components/mlme/core/src/wlan_mlme_main.c b/components/mlme/core/src/wlan_mlme_main.c index 66f4ef140432..131518cc5cd9 100644 --- a/components/mlme/core/src/wlan_mlme_main.c +++ b/components/mlme/core/src/wlan_mlme_main.c @@ -1,6 +1,7 @@ /* * Copyright (c) 2018-2020 The Linux Foundation. All rights reserved. * Copyright (c) 2021-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1846,6 +1847,8 @@ static void mlme_init_lfr_cfg(struct wlan_objmgr_psoc *psoc, cfg_get(psoc, CFG_LFR3_ROAM_PREAUTH_RETRY_COUNT); lfr->roam_rssi_diff = cfg_get(psoc, CFG_LFR_ROAM_RSSI_DIFF); lfr->roam_rssi_diff_6ghz = cfg_get(psoc, CFG_LFR_ROAM_RSSI_DIFF_6GHZ); + lfr->roam_rssi_delta_6ghz_to_non_6ghz = + cfg_get(psoc, CFG_LFR_ROAM_RSSI_DELTA_6GHZ_TO_NON_6GHZ); lfr->bg_rssi_threshold = cfg_get(psoc, CFG_LFR_ROAM_BG_RSSI_TH); lfr->roam_scan_offload_enabled = cfg_get(psoc, CFG_LFR_ROAM_SCAN_OFFLOAD_ENABLED); diff --git a/components/mlme/dispatcher/inc/cfg_mlme_lfr.h b/components/mlme/dispatcher/inc/cfg_mlme_lfr.h index 6ad5d7011e58..135eb7597a3c 100644 --- a/components/mlme/dispatcher/inc/cfg_mlme_lfr.h +++ b/components/mlme/dispatcher/inc/cfg_mlme_lfr.h @@ -1,6 +1,7 @@ /* * Copyright (c) 2012-2020 The Linux Foundation. All rights reserved. * Copyright (c) 2021-2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1280,6 +1281,38 @@ CFG_VALUE_OR_DEFAULT, \ "Enable 6 GHz roam based on rssi") +/* + * + * roam_rssi_delta_from_6ghz_to_non_6ghz - Enable roam to Non 6 GHz AP based + * on rssi + * @Min: 0 + * @Max: 100 + * @Default: 0 + * + * This INI is used to decide whether to roam to Non 6 GHz AP or not based on + * RSSI. AP1 is the currently associated AP(6 GHz) and AP2(2.4 GHz / 5 GHz) is + * chosen for roaming. The Roaming will happen only if AP2 has better Signal + * Quality and it has a RSSI better than AP1. + * roam_rssi_delta_from_6ghz_to_non_6ghz is the number of dB units AP2 is + * better than AP1. + * + * + * Related: None + * + * Supported Feature: Roaming + * + * Usage: External + * + * + */ +#define CFG_LFR_ROAM_RSSI_DELTA_6GHZ_TO_NON_6GHZ CFG_INI_UINT( \ + "roam_rssi_delta_from_6ghz_to_non_6ghz", \ + 0, \ + 100, \ + 0, \ + CFG_VALUE_OR_DEFAULT, \ + "Enable 6 GHz to non 6 GHz roam based on rssi") + /* * * bg_rssi_threshold - To set RSSI Threshold for BG scan roaming @@ -2930,6 +2963,7 @@ CFG(CFG_LFR_FAST_TRANSITION_ENABLED) \ CFG(CFG_LFR_ROAM_RSSI_DIFF) \ CFG(CFG_LFR_ROAM_RSSI_DIFF_6GHZ) \ + CFG(CFG_LFR_ROAM_RSSI_DELTA_6GHZ_TO_NON_6GHZ) \ CFG(CFG_LFR_ROAM_BG_RSSI_TH) \ CFG(CFG_LFR_ENABLE_WES_MODE) \ CFG(CFG_LFR_ROAM_SCAN_OFFLOAD_ENABLED) \ diff --git a/components/mlme/dispatcher/inc/wlan_mlme_public_struct.h b/components/mlme/dispatcher/inc/wlan_mlme_public_struct.h index ad48cd35c0cd..9ca94e78d468 100644 --- a/components/mlme/dispatcher/inc/wlan_mlme_public_struct.h +++ b/components/mlme/dispatcher/inc/wlan_mlme_public_struct.h @@ -1,6 +1,7 @@ /* * Copyright (c) 2018-2020 The Linux Foundation. All rights reserved. * Copyright (c) 2021-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1680,8 +1681,10 @@ struct fw_scan_channels { * @roam_preauth_no_ack_timeout: Configure the no ack timeout period * @roam_rssi_diff: Enable roam based on rssi * @roam_rssi_diff_6ghz: RSSI diff value to be used for roaming to 6 GHz AP. - * @roam_scan_offload_enabled: Enable Roam Scan Offload - * @neighbor_scan_timer_period: Neighbor scan timer period + * @roam_rssi_delta_6ghz_to_non_6ghz: RSSI diff value to be used for + * roaming from 6 GHz to Non 6GHz AP. + * @roam_scan_offload_enabled: Enable Roam Scan Offload + * @neighbor_scan_timer_period: Neighbor scan timer period * @neighbor_scan_min_timer_period: Min neighbor scan timer period * @neighbor_lookup_rssi_threshold: Neighbor lookup rssi threshold * @opportunistic_scan_threshold_diff: Set oppurtunistic threshold diff @@ -1804,6 +1807,7 @@ struct wlan_mlme_lfr_cfg { uint32_t roam_preauth_no_ack_timeout; uint8_t roam_rssi_diff; uint8_t roam_rssi_diff_6ghz; + uint8_t roam_rssi_delta_6ghz_to_non_6ghz; uint8_t bg_rssi_threshold; bool roam_scan_offload_enabled; uint32_t neighbor_scan_timer_period; diff --git a/components/target_if/connection_mgr/src/target_if_cm_roam_offload.c b/components/target_if/connection_mgr/src/target_if_cm_roam_offload.c index 46e1cab26484..970d0429f1b7 100644 --- a/components/target_if/connection_mgr/src/target_if_cm_roam_offload.c +++ b/components/target_if/connection_mgr/src/target_if_cm_roam_offload.c @@ -1,6 +1,7 @@ /* * Copyright (c) 2020, The Linux Foundation. All rights reserved. * Copyright (c) 2021-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for any * purpose with or without fee is hereby granted, provided that the above @@ -264,6 +265,41 @@ target_if_cm_roam_rssi_diff_6ghz(struct wlan_objmgr_vdev *vdev, return status; } +/** + * target_if_cm_roam_rssi_delta_6ghz_to_non_6ghz() - Sends the roam RSSI + * diff value to the FW. This value is used to determine how much better + * the RSSI of the new/roamable non-6 GHz AP must be for roaming. + * + * @vdev: vdev object + * @roam_rssi_delta_6ghz_to_non_6ghz: RSSI diff value to be used for roaming to + * Non 6 GHz AP + * + * Return: QDF_STATUS + */ +static QDF_STATUS +target_if_cm_roam_rssi_delta_6ghz_to_non_6ghz(struct wlan_objmgr_vdev *vdev, + uint8_t roam_rssi_delta_6ghz_to_non_6ghz) +{ + QDF_STATUS status = QDF_STATUS_E_FAILURE; + uint8_t vdev_id; + wmi_unified_t wmi_handle; + + wmi_handle = target_if_cm_roam_get_wmi_handle_from_vdev(vdev); + if (!wmi_handle) + return status; + + vdev_id = wlan_vdev_get_id(vdev); + status = target_if_roam_set_param( + wmi_handle, vdev_id, + WMI_ROAM_PARAM_ROAM_RSSI_PENALTY_FOR_NON_6GHZ_CAND_AP, + roam_rssi_delta_6ghz_to_non_6ghz); + + if (QDF_IS_STATUS_ERROR(status)) + target_if_err("Failed to set WMI_ROAM_PARAM_ROAM_RSSI_PENALTY_FOR_NON_6GHZ_CAND_AP"); + + return status; +} + static QDF_STATUS target_if_cm_roam_scan_offload_rssi_thresh( wmi_unified_t wmi_handle, @@ -367,6 +403,13 @@ target_if_cm_roam_rssi_diff_6ghz(struct wlan_objmgr_vdev *vdev, return QDF_STATUS_E_NOSUPPORT; } +static QDF_STATUS +target_if_cm_roam_rssi_delta_6ghz_to_non_6ghz(struct wlan_objmgr_vdev *vdev, + uint8_t roam_rssi_diff_6ghz) +{ + return QDF_STATUS_E_NOSUPPORT; +} + static inline void target_if_check_hi_rssi_5ghz_support( wmi_unified_t wmi_handle, @@ -1276,6 +1319,9 @@ target_if_cm_roam_send_start(struct wlan_objmgr_vdev *vdev, if (req->wlan_roam_rssi_diff_6ghz) target_if_cm_roam_rssi_diff_6ghz(vdev, req->wlan_roam_rssi_diff_6ghz); + if (req->wlan_roam_rssi_delta_6ghz_to_non_6ghz) + target_if_cm_roam_rssi_delta_6ghz_to_non_6ghz( + vdev, req->wlan_roam_rssi_delta_6ghz_to_non_6ghz); /* add other wmi commands */ end: @@ -1516,6 +1562,10 @@ target_if_cm_roam_send_update_config(struct wlan_objmgr_vdev *vdev, if (req->wlan_roam_rssi_diff_6ghz) target_if_cm_roam_rssi_diff_6ghz( vdev, req->wlan_roam_rssi_diff_6ghz); + + if (req->wlan_roam_rssi_delta_6ghz_to_non_6ghz) + target_if_cm_roam_rssi_delta_6ghz_to_non_6ghz( + vdev, req->wlan_roam_rssi_delta_6ghz_to_non_6ghz); } end: return status; diff --git a/components/umac/mlme/connection_mgr/core/src/wlan_cm_roam_offload.c b/components/umac/mlme/connection_mgr/core/src/wlan_cm_roam_offload.c index 647f5e0229b2..8f5e5272d77c 100644 --- a/components/umac/mlme/connection_mgr/core/src/wlan_cm_roam_offload.c +++ b/components/umac/mlme/connection_mgr/core/src/wlan_cm_roam_offload.c @@ -629,6 +629,10 @@ cm_roam_start_req(struct wlan_objmgr_psoc *psoc, uint8_t vdev_id, wlan_cm_roam_cfg_get_value(psoc, vdev_id, ROAM_RSSI_DIFF_6GHZ, &temp); start_req->wlan_roam_rssi_diff_6ghz = temp.uint_value; + wlan_cm_roam_cfg_get_value(psoc, vdev_id, + ROAM_RSSI_DELTA_6GHZ_TO_NON_6GHZ, &temp); + start_req->wlan_roam_rssi_delta_6ghz_to_non_6ghz = temp.uint_value; + status = wlan_cm_tgt_send_roam_start_req(psoc, vdev_id, start_req); if (QDF_IS_STATUS_ERROR(status)) mlme_debug("fail to send roam start"); @@ -691,6 +695,10 @@ cm_roam_update_config_req(struct wlan_objmgr_psoc *psoc, uint8_t vdev_id, wlan_cm_roam_cfg_get_value(psoc, vdev_id, ROAM_RSSI_DIFF_6GHZ, &temp); update_req->wlan_roam_rssi_diff_6ghz = temp.uint_value; + wlan_cm_roam_cfg_get_value(psoc, vdev_id, + ROAM_RSSI_DELTA_6GHZ_TO_NON_6GHZ, &temp); + update_req->wlan_roam_rssi_delta_6ghz_to_non_6ghz = temp.uint_value; + status = wlan_cm_tgt_send_roam_update_req(psoc, vdev_id, update_req); if (QDF_IS_STATUS_ERROR(status)) mlme_debug("fail to send update config"); diff --git a/components/umac/mlme/connection_mgr/dispatcher/inc/wlan_cm_roam_public_struct.h b/components/umac/mlme/connection_mgr/dispatcher/inc/wlan_cm_roam_public_struct.h index 9a027bc6a11f..b4d17e9c04fe 100644 --- a/components/umac/mlme/connection_mgr/dispatcher/inc/wlan_cm_roam_public_struct.h +++ b/components/umac/mlme/connection_mgr/dispatcher/inc/wlan_cm_roam_public_struct.h @@ -1,6 +1,7 @@ /* * Copyright (c) 2020-2021, The Linux Foundation. All rights reserved. * Copyright (c) 2022-2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for any * purpose with or without fee is hereby granted, provided that the above @@ -120,12 +121,14 @@ * @BEACON_RSSI_WEIGHT: Beacon Rssi weight parameter * @HI_RSSI_DELAY_BTW_SCANS: High Rssi delay between scans * @ROAM_RSSI_DIFF_6GHZ: roam rssi diff for 6 GHz AP + * @ROAM_RSSI_DELTA_6GHZ_TO_NON_6GHZ: roam rssi diff for Non 6 GHz AP */ enum roam_cfg_param { RSSI_CHANGE_THRESHOLD, BEACON_RSSI_WEIGHT, HI_RSSI_DELAY_BTW_SCANS, ROAM_RSSI_DIFF_6GHZ, + ROAM_RSSI_DELTA_6GHZ_TO_NON_6GHZ, }; /** @@ -1206,6 +1209,8 @@ enum roam_rt_stats_params { * scan only on prior discovery of any 6 GHz support in the environment. * @wlan_roam_rssi_diff_6ghz: This value is used as to how better the RSSI of * the new/roamable 6GHz AP should be for roaming. + * @wlan_roam_rssi_delta_6ghz_to_non_6ghz: This value is used as to how better + * the RSSI of the new/roamable non 6GHz AP should be for roaming. */ struct wlan_roam_start_config { struct wlan_roam_offload_scan_rssi_params rssi_params; @@ -1229,6 +1234,7 @@ struct wlan_roam_start_config { uint8_t wlan_exclude_rm_partial_scan_freq; uint8_t wlan_roam_full_scan_6ghz_on_disc; uint8_t wlan_roam_rssi_diff_6ghz; + uint8_t wlan_roam_rssi_delta_6ghz_to_non_6ghz; /* other wmi cmd structures */ }; @@ -1281,6 +1287,8 @@ struct wlan_roam_stop_config { * scan only on prior discovery of any 6 GHz support in the environment. * @wlan_roam_rssi_diff_6ghz: This value is used as to how better the RSSI of * the new/roamable 6GHz AP should be for roaming. + * @wlan_roam_rssi_delta_6ghz_to_non_6ghz: This value is used as to how better + * the RSSI of the new/roamable non 6GHz AP should be for roaming. */ struct wlan_roam_update_config { struct wlan_roam_beacon_miss_cnt beacon_miss_cnt; @@ -1299,6 +1307,7 @@ struct wlan_roam_update_config { uint8_t wlan_exclude_rm_partial_scan_freq; uint8_t wlan_roam_full_scan_6ghz_on_disc; uint8_t wlan_roam_rssi_diff_6ghz; + uint8_t wlan_roam_rssi_delta_6ghz_to_non_6ghz; }; #if defined(WLAN_FEATURE_HOST_ROAM) || defined(WLAN_FEATURE_ROAM_OFFLOAD) @@ -1522,6 +1531,8 @@ enum roam_fail_params { * @roam_invoke_fail_reason: One of reason id from enum * wmi_roam_invoke_status_error in case of forced roam * @roam_rssi_diff_6ghz: roam rssi diff for 6 GHz AP + * @roam_rssi_delta_6ghz_to_non_6ghz: RSSI Delta value to be used for roaming + * from 6 GHz to Non 6GHz AP. */ struct wlan_cm_rso_configs { uint8_t rescan_rssi_delta; @@ -1532,6 +1543,7 @@ struct wlan_cm_rso_configs { uint32_t roam_trigger_reason; uint32_t roam_invoke_fail_reason; uint8_t roam_rssi_diff_6ghz; + uint8_t roam_rssi_delta_6ghz_to_non_6ghz; }; /** diff --git a/components/umac/mlme/connection_mgr/dispatcher/src/wlan_cm_roam_api.c b/components/umac/mlme/connection_mgr/dispatcher/src/wlan_cm_roam_api.c index 53fce94e29c3..8ad4cef25e38 100644 --- a/components/umac/mlme/connection_mgr/dispatcher/src/wlan_cm_roam_api.c +++ b/components/umac/mlme/connection_mgr/dispatcher/src/wlan_cm_roam_api.c @@ -1,6 +1,7 @@ /* * Copyright (c) 2020, The Linux Foundation. All rights reserved. * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for any * purpose with or without fee is hereby granted, provided that the above @@ -519,6 +520,10 @@ QDF_STATUS wlan_cm_roam_cfg_get_value(struct wlan_objmgr_psoc *psoc, case ROAM_RSSI_DIFF_6GHZ: dst_config->uint_value = src_config->roam_rssi_diff_6ghz; break; + case ROAM_RSSI_DELTA_6GHZ_TO_NON_6GHZ: + dst_config->uint_value = + src_config->roam_rssi_delta_6ghz_to_non_6ghz; + break; default: mlme_err("Invalid roam config requested:%d", roam_cfg_type); status = QDF_STATUS_E_FAILURE; @@ -568,6 +573,10 @@ wlan_cm_roam_cfg_set_value(struct wlan_objmgr_psoc *psoc, uint8_t vdev_id, case ROAM_RSSI_DIFF_6GHZ: dst_config->roam_rssi_diff_6ghz = src_config->uint_value; break; + case ROAM_RSSI_DELTA_6GHZ_TO_NON_6GHZ: + dst_config->roam_rssi_delta_6ghz_to_non_6ghz = + src_config->uint_value; + break; default: mlme_err("Invalid roam config requested:%d", roam_cfg_type); status = QDF_STATUS_E_FAILURE; diff --git a/core/sme/src/csr/csr_neighbor_roam.c b/core/sme/src/csr/csr_neighbor_roam.c index df8c0cfabee5..199c4352952f 100644 --- a/core/sme/src/csr/csr_neighbor_roam.c +++ b/core/sme/src/csr/csr_neighbor_roam.c @@ -848,6 +848,9 @@ static void csr_neighbor_roam_info_ctx_init(struct mac_context *mac, wlan_cm_roam_cfg_set_value(mac->psoc, session_id, ROAM_RSSI_DIFF_6GHZ, &src_cfg); + src_cfg.uint_value = mac->mlme_cfg->lfr.roam_rssi_delta_6ghz_to_non_6ghz; + wlan_cm_roam_cfg_set_value(mac->psoc, session_id, + ROAM_RSSI_DELTA_6GHZ_TO_NON_6GHZ, &src_cfg); /* * Now we can clear the preauthDone that * was saved as we are connected afresh From f3f95c51abbe5f02fa34e64cf96d2a79ede7dcb2 Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Thu, 5 Jun 2025 01:33:58 -0700 Subject: [PATCH 18/27] Release 2.0.8.35D Release 2.0.8.35D Change-Id: I3b0c1f0536f0ef1278181c95747928037ea12311 CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index 8b118e5e2c21..0e3eaa97f81d 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "C" +#define QWLAN_VERSION_EXTRA "D" #define QWLAN_VERSION_BUILD 35 -#define QWLAN_VERSIONSTR "2.0.8.35C" +#define QWLAN_VERSIONSTR "2.0.8.35D" #endif /* QWLAN_VERSION_H */ From 8be762469ab18b40e4cea9223a1bf86fa203159d Mon Sep 17 00:00:00 2001 From: "Kaushik K.N" Date: Mon, 14 Jul 2025 21:50:31 +0530 Subject: [PATCH 19/27] qcacld-3.0: Add Validation for WMA Handle and PSOC in Wake Event Currently, the WOW wakeup event handler lacks validation for the WMA handle and the PSOC pointer within the WMA handle. This omission can lead to null pointer dereferences in the host. To address this issue, null pointer checks for both the WMA handle and the PSOC pointer have been added. CRs-Fixed: 4107000 Change-Id: Iaf22d5adc14b65b778b0e1d78108eded0cccb8c9 --- core/wma/src/wma_features.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/core/wma/src/wma_features.c b/core/wma/src/wma_features.c index 03a51f01fbd4..e5a234adc325 100644 --- a/core/wma/src/wma_features.c +++ b/core/wma/src/wma_features.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2013-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -2813,6 +2813,9 @@ int wma_wow_wakeup_host_event(void *handle, uint8_t *event, uint32_t len) WMI_WOW_WAKEUP_HOST_EVENTID_param_tlvs *event_param; WOW_EVENT_INFO_fixed_param *wake_info; + if (!wma || !wma->psoc) + return -EINVAL; + event_param = (WMI_WOW_WAKEUP_HOST_EVENTID_param_tlvs *)event; if (!event_param) { wma_err("Wake event data is null"); From fed91e16d8019d54b98c0b999126456d2d172ef8 Mon Sep 17 00:00:00 2001 From: Surya Prakash Sivaraj Date: Thu, 28 Apr 2022 15:25:15 +0530 Subject: [PATCH 20/27] qcacld-3.0: Validate bw in lim calculate tpc Currently host driver does not validate bw in lim calculate tpc api before is it gets next higher bw, there is a possiblity that this bw becomes invalid and driver ends up with out of bound access for get higher bw array. In current scenario when host driver tries to start vdev on frequency 2472 for country IN and executes this API for frequency 2472, at the same time country is changed to US and this frequency becomes invalid. so in the execution of this API host driver gets invalid bw from reg set param and ends up with out of bound access for get higher bw array. TO address above issue, add a check to validate bw before driver acceses get higher bw array. Change-Id: Ibd6a2ff44a7928bb2fd461e6c49d4e306e4de7f7 CRs-Fixed: 3186084 --- core/mac/src/pe/lim/lim_process_sme_req_messages.c | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/core/mac/src/pe/lim/lim_process_sme_req_messages.c b/core/mac/src/pe/lim/lim_process_sme_req_messages.c index 49113c9529e4..41842fe17ead 100644 --- a/core/mac/src/pe/lim/lim_process_sme_req_messages.c +++ b/core/mac/src/pe/lim/lim_process_sme_req_messages.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2012-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2021-2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -2223,7 +2223,9 @@ void lim_calculate_tpc(struct mac_context *mac, ch_params.ch_width = CH_WIDTH_20MHZ; - for (i = 0; i < num_pwr_levels; i++) { + for (i = 0; + i < num_pwr_levels && (ch_params.ch_width != CH_WIDTH_INVALID); + i++) { if (is_tpe_present) { if (is_6ghz_freq) { wlan_reg_get_client_power_for_connecting_ap( @@ -2241,8 +2243,9 @@ void lim_calculate_tpc(struct mac_context *mac, mac->pdev, oper_freq, 0, &ch_params); mlme_obj->reg_tpc_obj.frequency[i] = ch_params.mhz_freq_seg0; - ch_params.ch_width = - get_next_higher_bw[ch_params.ch_width]; + if (ch_params.ch_width != CH_WIDTH_INVALID) + ch_params.ch_width = + get_next_higher_bw[ch_params.ch_width]; } if (is_6ghz_freq) { if (LIM_IS_STA_ROLE(session)) { From ad3eca7060b622d9985ccff785d776f2883fc3c9 Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Tue, 22 Jul 2025 12:55:06 -0700 Subject: [PATCH 21/27] Release 2.0.8.35E Release 2.0.8.35E Change-Id: I831554185675089d3055c9e071c39944fe5c8f68 CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index 0e3eaa97f81d..212336852d5f 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "D" +#define QWLAN_VERSION_EXTRA "E" #define QWLAN_VERSION_BUILD 35 -#define QWLAN_VERSIONSTR "2.0.8.35D" +#define QWLAN_VERSIONSTR "2.0.8.35E" #endif /* QWLAN_VERSION_H */ From 1c5657681bfefeb006bc92b9b55aad16249218a6 Mon Sep 17 00:00:00 2001 From: Surya Prakash Sivaraj Date: Wed, 18 Jun 2025 12:17:24 +0530 Subject: [PATCH 22/27] qcacld-3.0: Add TPE IE EIRP power support for 6 GHz band Add TPE IE EIRP power parsing support for 6 GHz channels. 1) Currently, is_psd_power flag is derived from current channel list chan flag which returns true if corresponding channel supports PSD power. Normally, all 6 GHz channels support PSD, so this flag is usually set to 1. But, AP can transmit EIRP power in TPE IE for 6 GHz channels, thus derive this flag based on tx_power interpretation field in TPE IE for accurate value. 2) The calculated center freq is passed as argument to retrieve regulatory power from reg channel list but this logic works only for PSD. E.g. In case of EIRP, center freq can be 6125 MHz for oper freq 6115 and BW 40 MHz, and causing reg APIs to return reg power as 0. Thus, pass operating freq as argument in case of EIRP. Change-Id: If1ad3870a866592d970adad218e507c9c756f615 CRs-Fixed: 3266393 --- .../src/pe/lim/lim_process_sme_req_messages.c | 23 +++++++++++-------- 1 file changed, 14 insertions(+), 9 deletions(-) diff --git a/core/mac/src/pe/lim/lim_process_sme_req_messages.c b/core/mac/src/pe/lim/lim_process_sme_req_messages.c index 41842fe17ead..a48c6c707fa7 100644 --- a/core/mac/src/pe/lim/lim_process_sme_req_messages.c +++ b/core/mac/src/pe/lim/lim_process_sme_req_messages.c @@ -2059,6 +2059,7 @@ void lim_parse_tpe_ie(struct mac_context *mac, struct pe_session *session, single_tpe = tpe_ies[non_psd_index]; vdev_mlme->reg_tpc_obj.eirp_power = single_tpe.tx_power[single_tpe.max_tx_pwr_count]; + vdev_mlme->reg_tpc_obj.is_psd_power = false; } } @@ -2202,7 +2203,6 @@ void lim_calculate_tpc(struct mac_context *mac, skip_tpe = wlan_mlme_skip_tpe(mac->psoc); } else { is_6ghz_freq = true; - is_psd_power = wlan_reg_is_6g_psd_power(mac->pdev); if (LIM_IS_STA_ROLE(session)) ap_power_type_6g = session->best_6g_power_type; } @@ -2210,6 +2210,7 @@ void lim_calculate_tpc(struct mac_context *mac, if (mlme_obj->reg_tpc_obj.num_pwr_levels) { is_tpe_present = true; num_pwr_levels = mlme_obj->reg_tpc_obj.num_pwr_levels; + is_psd_power = mlme_obj->reg_tpc_obj.is_psd_power; } else { num_pwr_levels = lim_get_num_pwr_levels(is_psd_power, session->ch_width); @@ -2228,10 +2229,16 @@ void lim_calculate_tpc(struct mac_context *mac, i++) { if (is_tpe_present) { if (is_6ghz_freq) { - wlan_reg_get_client_power_for_connecting_ap( - mac->pdev, ap_power_type_6g, - mlme_obj->reg_tpc_obj.frequency[i], - &is_psd_power, ®_max, &psd_power); + if (is_psd_power) { + wlan_reg_get_client_power_for_connecting_ap( + mac->pdev, ap_power_type_6g, + mlme_obj->reg_tpc_obj.frequency[i], + is_psd_power, ®_max, &psd_power); + } else { + wlan_reg_get_client_power_for_connecting_ap( + mac->pdev, ap_power_type_6g, oper_freq, + is_psd_power, ®_max, &psd_power); + } } } else { /* center frequency calculation */ @@ -2252,10 +2259,9 @@ void lim_calculate_tpc(struct mac_context *mac, wlan_reg_get_client_power_for_connecting_ap (mac->pdev, ap_power_type_6g, mlme_obj->reg_tpc_obj.frequency[i], - &is_psd_power, ®_max, &psd_power); + is_psd_power, ®_max, &psd_power); } else { - ap_power_type_6g = - wlan_reg_get_cur_6g_ap_pwr_type( + wlan_reg_get_cur_6g_ap_pwr_type( mac->pdev, &ap_power_type_6g); wlan_reg_get_6g_chan_ap_power( @@ -2321,7 +2327,6 @@ void lim_calculate_tpc(struct mac_context *mac, } mlme_obj->reg_tpc_obj.num_pwr_levels = num_pwr_levels; - mlme_obj->reg_tpc_obj.is_psd_power = is_psd_power; mlme_obj->reg_tpc_obj.eirp_power = reg_max; mlme_obj->reg_tpc_obj.power_type_6g = ap_power_type_6g; From 1eea4bab119a5e3bbb078ba4bf9d1f3a6b37a6ab Mon Sep 17 00:00:00 2001 From: Surya Prakash Sivaraj Date: Wed, 18 Jun 2025 12:23:26 +0530 Subject: [PATCH 23/27] qcacld-3.0: don't overwrite psd_power flag if psd_set is true When both EIRP and PSD TPE IEs are advertised by 6 GHz AP, we need to use PSD power. We need to keep the psd_power true if psd_set is true (means PSD TPE IE present) when driver processes the EIRP TPE IE. If reg rules don't support psd power, ignore PSD TPE IE. Change-Id: I96cf8f08ffd0aa143f0f0f453eed3c8b8e5d2382 CRs-Fixed: 3693350 --- .../src/pe/lim/lim_process_sme_req_messages.c | 25 ++++++++++++++++++- 1 file changed, 24 insertions(+), 1 deletion(-) diff --git a/core/mac/src/pe/lim/lim_process_sme_req_messages.c b/core/mac/src/pe/lim/lim_process_sme_req_messages.c index a48c6c707fa7..0ac96d900386 100644 --- a/core/mac/src/pe/lim/lim_process_sme_req_messages.c +++ b/core/mac/src/pe/lim/lim_process_sme_req_messages.c @@ -1903,6 +1903,8 @@ void lim_parse_tpe_ie(struct mac_context *mac, struct pe_session *session, uint16_t bw_val, ch_width; qdf_freq_t curr_op_freq, curr_freq; enum reg_6g_client_type client_mobility_type; + enum reg_6g_ap_type ap_power_type_6g; + uint16_t reg_max = 0, psd_power = 0; struct ch_params ch_params = {0}; tDot11fIEtransmit_power_env single_tpe; /* @@ -1979,6 +1981,25 @@ void lim_parse_tpe_ie(struct mac_context *mac, struct pe_session *session, curr_op_freq = session->curr_op_freq; bw_val = wlan_reg_get_bw_value(session->ch_width); + if (psd_set) { + if (wlan_reg_is_6ghz_chan_freq(curr_op_freq)) { + ap_power_type_6g = session->best_6g_power_type; + + wlan_reg_get_client_power_for_connecting_ap( + mac->pdev, ap_power_type_6g, + curr_op_freq, true, ®_max, &psd_power); + + /* If reg rules don't support psd power, ignore PSD + * TPE IE + */ + if (!psd_power) { + pe_debug_rl("reg rule doesn't support psd for %d ap type %d", + curr_op_freq, ap_power_type_6g); + psd_set = false; + } + } + } + if (non_psd_set && !psd_set) { single_tpe = tpe_ies[non_psd_index]; vdev_mlme->reg_tpc_obj.is_psd_power = false; @@ -2059,7 +2080,9 @@ void lim_parse_tpe_ie(struct mac_context *mac, struct pe_session *session, single_tpe = tpe_ies[non_psd_index]; vdev_mlme->reg_tpc_obj.eirp_power = single_tpe.tx_power[single_tpe.max_tx_pwr_count]; - vdev_mlme->reg_tpc_obj.is_psd_power = false; + pe_debug("eirp_power %d", vdev_mlme->reg_tpc_obj.eirp_power); + if (!psd_set) + vdev_mlme->reg_tpc_obj.is_psd_power = false; } } From 7604d08f894532472b9dce5ecca083eb57b69594 Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Tue, 22 Jul 2025 15:20:49 -0700 Subject: [PATCH 24/27] Release 2.0.8.35F Release 2.0.8.35F Change-Id: I8d4a6dabef540cd4594e32e3131bd508b4dd7ea9 CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index 212336852d5f..7c707bd54fb8 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "E" +#define QWLAN_VERSION_EXTRA "F" #define QWLAN_VERSION_BUILD 35 -#define QWLAN_VERSIONSTR "2.0.8.35E" +#define QWLAN_VERSIONSTR "2.0.8.35F" #endif /* QWLAN_VERSION_H */ From 4117e36cb841c3a9e5751785cee84fd9a9933c2d Mon Sep 17 00:00:00 2001 From: Dharmendra Tiwari Date: Mon, 12 May 2025 08:00:40 -0700 Subject: [PATCH 25/27] qcacld-3.0: Fix underflow issue of beacon length A validation check has been added to ensure beacon length is not less than (bcn->noa_sub_ie_len + sizeof(struct p2p_ie)), preventing underflow issues. Change-Id: I924a3ebf4a0749d5a4c56b36878765fcf46440a4 CRs-Fixed: 4166530 --- core/wma/src/wma_power.c | 20 ++++++++++++++------ 1 file changed, 14 insertions(+), 6 deletions(-) diff --git a/core/wma/src/wma_power.c b/core/wma/src/wma_power.c index 6c8004735a15..feed5a83979d 100644 --- a/core/wma/src/wma_power.c +++ b/core/wma/src/wma_power.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2013-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1171,20 +1171,28 @@ static void wma_update_beacon_noa_ie(struct beacon_info *bcn, /* TODO: Assuming p2p noa ie is last ie in the beacon */ qdf_mem_zero(bcn->noa_ie, (bcn->noa_sub_ie_len + sizeof(struct p2p_ie))); - bcn->len -= (bcn->noa_sub_ie_len + - sizeof(struct p2p_ie)); + if (bcn->len < (bcn->noa_sub_ie_len + + sizeof(struct p2p_ie))) + bcn->len = 0; + else + bcn->len -= (bcn->noa_sub_ie_len + + sizeof(struct p2p_ie)); bcn->noa_ie = NULL; bcn->noa_sub_ie_len = 0; } - wma_debug("No need to update NoA"); return; } if (bcn->noa_sub_ie_len && bcn->noa_ie) { + if (bcn->len < (bcn->noa_sub_ie_len + sizeof(struct p2p_ie))) + bcn->len = 0; + else + bcn->len -= (bcn->noa_sub_ie_len + + sizeof(struct p2p_ie)); + /* NoA present in previous beacon, update it */ wma_debug("NoA present in previous beacon, update the NoA IE, bcn->len %u bcn->noa_sub_ie_len %u", - bcn->len, bcn->noa_sub_ie_len); - bcn->len -= (bcn->noa_sub_ie_len + sizeof(struct p2p_ie)); + bcn->len, bcn->noa_sub_ie_len); qdf_mem_zero(bcn->noa_ie, (bcn->noa_sub_ie_len + sizeof(struct p2p_ie))); } else { /* NoA is not present in previous beacon */ From 15ea8abee0fb0954361aad88d35b9e6c0319e411 Mon Sep 17 00:00:00 2001 From: Kiran Kumar Reddy A E Date: Sat, 6 Sep 2025 00:37:52 -0700 Subject: [PATCH 26/27] Release 2.0.8.35G Release 2.0.8.35G Change-Id: Iaa1e456ca143d8650d715e3bdd25e00f5281b8b4 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index 7c707bd54fb8..500f1f71f75c 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "F" +#define QWLAN_VERSION_EXTRA "G" #define QWLAN_VERSION_BUILD 35 -#define QWLAN_VERSIONSTR "2.0.8.35F" +#define QWLAN_VERSIONSTR "2.0.8.35G" #endif /* QWLAN_VERSION_H */ From 40c990ed3d9987d281009a1256c5664614ec1138 Mon Sep 17 00:00:00 2001 From: Surya Prakash Sivaraj Date: Fri, 16 May 2025 12:51:50 +0530 Subject: [PATCH 27/27] qcacld-3.0: Populate MBSSID cap in Ext CAP IE The MBSSID cap in the extended capability IE is populated properly in the Probe and Assoc request of the initial connection. But, this cap is missing in the reassoc request during roaming. Host driver fills this cap based on the service cap of MBSSID support only during the probe/assoc req generation. This cap is not passed to the firmware via SET IE or via assoc IEs in the RSO START. Since the service cap would not change in runtime, override the MBSSID cap in the assoc IEs received from the userspace itself. This sets the cap in both SET IE as well as RSO START. Change-Id: I69476e503a369df6533de9c215efc4c39d9e251c CRs-Fixed: 4117861 --- core/mac/src/pe/lim/lim_process_sme_req_messages.c | 3 +++ core/sme/src/csr/csr_api_roam.c | 12 +++++++++++- 2 files changed, 14 insertions(+), 1 deletion(-) diff --git a/core/mac/src/pe/lim/lim_process_sme_req_messages.c b/core/mac/src/pe/lim/lim_process_sme_req_messages.c index 0ac96d900386..0f57abe3c224 100644 --- a/core/mac/src/pe/lim/lim_process_sme_req_messages.c +++ b/core/mac/src/pe/lim/lim_process_sme_req_messages.c @@ -6520,6 +6520,9 @@ static void lim_process_set_ie_req(struct mac_context *mac_ctx, uint32_t *msg_bu if (p_ext_cap->interworking_service) p_ext_cap->qos_map = 1; + if (wma_is_mbssid_enabled()) + p_ext_cap->multi_bssid = 1; + extra_ext_cap.num_bytes = lim_compute_ext_cap_ie_length(&extra_ext_cap); send_ie: diff --git a/core/sme/src/csr/csr_api_roam.c b/core/sme/src/csr/csr_api_roam.c index c67bbe35827c..4484ed3c5ce8 100644 --- a/core/sme/src/csr/csr_api_roam.c +++ b/core/sme/src/csr/csr_api_roam.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2012-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2022-2025 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -17422,6 +17422,8 @@ static void csr_cm_update_driver_assoc_ies( MIN_TX_PWR_CAP, MAX_TX_PWR_CAP}; uint8_t max_tx_pwr_cap = 0; uint8_t supp_chan_ie[DOT11F_IE_SUPPCHANNELS_MAX_LEN], supp_chan_ie_len; + struct s_ext_cap *extcap; + uint8_t *ext_cap_ie; static const uint8_t qcn_ie[] = {0x8C, 0xFD, 0xF0, 0x1, QCN_IE_VERSION_SUBATTR_ID, QCN_IE_VERSION_SUBATTR_DATA_LEN, @@ -17433,6 +17435,14 @@ static void csr_cm_update_driver_assoc_ies( qdf_mem_copy(rso_mode_cfg->assoc_ie, session->pAddIEAssoc, rso_mode_cfg->assoc_ie_length); + ext_cap_ie = (uint8_t *)wlan_get_ie_ptr_from_eid(WLAN_ELEMID_XCAPS, + rso_mode_cfg->assoc_ie, + rso_mode_cfg->assoc_ie_length); + if (ext_cap_ie && wma_is_mbssid_enabled()) { + extcap = (struct s_ext_cap *)&ext_cap_ie[2]; + extcap->multi_bssid = 1; + } + if (session->pConnectBssDesc) max_tx_pwr_cap = csr_get_cfg_max_tx_power( mac_ctx,