From da35d8eb464e58166dd19b74a4c2959e6e0b7778 Mon Sep 17 00:00:00 2001 From: Aravind Kishore Sukla Date: Mon, 6 Jun 2022 16:39:51 +0530 Subject: [PATCH 01/16] qcacld-3.0: Update wiphy max_num_akms_connect variable Update wiphy->max_num_akms_connect to wiphy->max_num_akm_suites, based on the upstream kernel change. Change-Id: I54455b1d3fc162ddea5a0f9380f66a4a06236076 CRs-Fixed: 3214543 --- core/hdd/src/wlan_hdd_cfg80211.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/core/hdd/src/wlan_hdd_cfg80211.c b/core/hdd/src/wlan_hdd_cfg80211.c index 8531cf162dc0..32ef0a23a050 100644 --- a/core/hdd/src/wlan_hdd_cfg80211.c +++ b/core/hdd/src/wlan_hdd_cfg80211.c @@ -17359,7 +17359,7 @@ wlan_hdd_update_akm_suit_info(struct wiphy *wiphy) static void wlan_hdd_update_max_connect_akm(struct wiphy *wiphy) { - wiphy->max_num_akms_connect = WLAN_CM_MAX_CONNECT_AKMS; + wiphy->max_num_akm_suites = WLAN_CM_MAX_CONNECT_AKMS; } #else static void From d4e50bce791c0384c97dfe40b0098b8d6eb0c6a3 Mon Sep 17 00:00:00 2001 From: Srikanth Marepalli Date: Sat, 4 May 2024 00:42:26 +0530 Subject: [PATCH 02/16] qcacld-3.0: Enable CFG80211_MULTI_AKM_CONNECT_SUPPORT from kernelv6.0 Current code supports CFG80211_MULTI_AKM_CONNECT_SUPPORT only for v5.15 kernel. Enable this feature support from kernelv6.0 by default. Change-Id: I6fbf83df54fd898abde0546f526b193a6d8dc620 CRs-Fixed: 3806550 --- core/hdd/src/wlan_hdd_cfg80211.h | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/core/hdd/src/wlan_hdd_cfg80211.h b/core/hdd/src/wlan_hdd_cfg80211.h index f59eccad6adf..08cdc03c2bb3 100644 --- a/core/hdd/src/wlan_hdd_cfg80211.h +++ b/core/hdd/src/wlan_hdd_cfg80211.h @@ -208,6 +208,20 @@ extern const struct nla_policy wlan_hdd_wisa_cmd_policy[ #define USE_CFG80211_DEL_STA_V2 #endif +/* + * CFG80211_MULTI_AKM_CONNECT_SUPPORT + * used to indicate the Linux kernel contains support for multi AKM connect + * support + * + * This feature was introduced in Linux Kernel 6.0 via: + * ecad3b0b99bf wifi: cfg80211: Increase akm_suites array size in + * cfg80211_crypto_settings. + */ +#if (LINUX_VERSION_CODE >= KERNEL_VERSION(6, 0, 0) || \ + (defined CFG80211_MAX_NUM_AKM_SUITES)) +#define CFG80211_MULTI_AKM_CONNECT_SUPPORT 1 +#endif + #ifdef CFG80211_MULTI_AKM_CONNECT_SUPPORT #define WLAN_CM_MAX_CONNECT_AKMS 5 #endif From c9f42e357d4163050af4996b26b08768aad76d7e Mon Sep 17 00:00:00 2001 From: Srikanth Marepalli Date: Sat, 4 May 2024 01:56:51 +0530 Subject: [PATCH 03/16] qcacld-3.0: Update connect request crypto parameters Update the connect request crypto parameters based on the new kernel changes to increase the size of the akm_suites array in connect request Change-Id: I36eb265d3dafe9d822879fdbed340ba0c6bb7225 CRs-Fixed: 3806556 --- core/hdd/src/wlan_hdd_cfg80211.c | 86 +++++++------------------------- 1 file changed, 17 insertions(+), 69 deletions(-) diff --git a/core/hdd/src/wlan_hdd_cfg80211.c b/core/hdd/src/wlan_hdd_cfg80211.c index 32ef0a23a050..76831317f09b 100644 --- a/core/hdd/src/wlan_hdd_cfg80211.c +++ b/core/hdd/src/wlan_hdd_cfg80211.c @@ -20513,7 +20513,23 @@ static bool wlan_hdd_is_akm_suite_fils(uint32_t key_mgmt) } } +static int +hdd_get_num_akm_suites(const struct cfg80211_connect_params *req) +{ + return req->crypto.n_akm_suites; +} + +static uint32_t* +hdd_get_akm_suites(const struct cfg80211_connect_params *req) +{ + return (uint32_t *)req->crypto.akm_suites; +} + #ifdef CFG80211_MULTI_AKM_CONNECT_SUPPORT +#define MAX_AKM_SUITES WLAN_CM_MAX_CONNECT_AKMS +#else +#define MAX_AKM_SUITES NL80211_MAX_NR_AKM_SUITES +#endif /** * hdd_populate_crypto_akm_type() - populate akm type for crypto * @vdev: pointed to vdev obmgr @@ -20533,64 +20549,9 @@ hdd_populate_crypto_akm_type(struct wlan_objmgr_vdev *vdev, uint32_t set_val = 0; wlan_crypto_key_mgmt akm; - if (req->crypto.n_connect_akm_suites) { - for (i = 0; i < req->crypto.n_connect_akm_suites && - i < WLAN_CM_MAX_CONNECT_AKMS; i++) { - akm = osif_nl_to_crypto_akm_type( - req->crypto.connect_akm_suites[i]); - - HDD_SET_BIT(set_val, akm); - } - - status = wlan_crypto_set_vdev_param(vdev, - WLAN_CRYPTO_PARAM_KEY_MGMT, - set_val); - if (QDF_IS_STATUS_ERROR(status)) - hdd_err("Failed to set akm type %0x to crypto", - set_val); - - status = wlan_crypto_set_vdev_param( - vdev, WLAN_CRYPTO_PARAM_ORIG_KEY_MGMT, set_val); - if (QDF_IS_STATUS_ERROR(status)) - hdd_err("Failed to set original akm type %0x to crypto", - set_val); - } else { - set_val = 0; - /* Reset to none */ - HDD_SET_BIT(set_val, WLAN_CRYPTO_KEY_MGMT_NONE); - wlan_crypto_set_vdev_param(vdev, - WLAN_CRYPTO_PARAM_KEY_MGMT, - set_val); - wlan_crypto_set_vdev_param(vdev, - WLAN_CRYPTO_PARAM_ORIG_KEY_MGMT, - set_val); - } -} - -static int -hdd_get_num_akm_suites(const struct cfg80211_connect_params *req) -{ - return req->crypto.n_connect_akm_suites; -} - -static uint32_t* -hdd_get_akm_suites(const struct cfg80211_connect_params *req) -{ - return (uint32_t *)req->crypto.connect_akm_suites; -} -#else -static void -hdd_populate_crypto_akm_type(struct wlan_objmgr_vdev *vdev, - const struct cfg80211_connect_params *req) -{ - QDF_STATUS status; - uint32_t i = 0; - uint32_t set_val = 0; - wlan_crypto_key_mgmt akm; - if (req->crypto.n_akm_suites) { for (i = 0; i < req->crypto.n_akm_suites && - i < NL80211_MAX_NR_AKM_SUITES; i++) { + i < MAX_AKM_SUITES; i++) { akm = osif_nl_to_crypto_akm_type( req->crypto.akm_suites[i]); @@ -20623,19 +20584,6 @@ hdd_populate_crypto_akm_type(struct wlan_objmgr_vdev *vdev, } } -static int -hdd_get_num_akm_suites(const struct cfg80211_connect_params *req) -{ - return req->crypto.n_akm_suites; -} - -static uint32_t* -hdd_get_akm_suites(const struct cfg80211_connect_params *req) -{ - return (uint32_t *)req->crypto.akm_suites; -} -#endif - static bool wlan_hdd_is_conn_type_fils(struct cfg80211_connect_params *req) { enum nl80211_auth_type auth_type = req->auth_type; From d4e8774068cab408d7ef6697c6ccb13d396ef303 Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Mon, 15 Jul 2024 01:08:10 -0700 Subject: [PATCH 04/16] Release 2.0.8.34T Release 2.0.8.34T Change-Id: Idacaae744b054dc32c1fc9b4874945459884a0dc CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index d750097bf8b7..ad8382fecb06 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "S" +#define QWLAN_VERSION_EXTRA "T" #define QWLAN_VERSION_BUILD 34 -#define QWLAN_VERSIONSTR "2.0.8.34S" +#define QWLAN_VERSIONSTR "2.0.8.34T" #endif /* QWLAN_VERSION_H */ From 38efdc0db2131641cc18bc8983039ed4e24acb8e Mon Sep 17 00:00:00 2001 From: Ashish Date: Mon, 6 Jun 2022 19:31:01 +0530 Subject: [PATCH 05/16] qcacld-3.0: Set sar safety req resp event before unsolited work stop Currently when sar safety unsolited timer expires, driver schedules a work to send sar safety unsolited events to user space. When driver receives sar set command from user space it tries to stop this work with delayed work stop sync. This delayed work stop sync API waits for work to get complete and then it stops the work, because of this, work runs the complete for loop and sends extra sar safety unsolicited events even after receiving sar set command. To addrerss above issue, set the sar safety request response event before delayed work stop sync to complete the work. Change-Id: I3485e4b1ea600393ff2d9512a055de92d0a3d612 CRs-Fixed: 3213334 --- core/hdd/src/wlan_hdd_sar_limits.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/core/hdd/src/wlan_hdd_sar_limits.c b/core/hdd/src/wlan_hdd_sar_limits.c index e51ae8ac56ea..15f7d5b2fd6e 100644 --- a/core/hdd/src/wlan_hdd_sar_limits.c +++ b/core/hdd/src/wlan_hdd_sar_limits.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2012-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2021 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2021, 2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1082,10 +1082,11 @@ void wlan_hdd_sar_timers_reset(struct hdd_context *hdd_ctx) if (QDF_IS_STATUS_SUCCESS(status)) hdd_nofl_debug("sar safety timer started"); + qdf_event_set(&hdd_ctx->sar_safety_req_resp_event); + qdf_delayed_work_stop_sync(&hdd_ctx->sar_safety_unsolicited_work); hdd_nofl_debug("sar safety unsolicited work stopped"); - qdf_event_set(&hdd_ctx->sar_safety_req_resp_event); } void wlan_hdd_sar_timers_init(struct hdd_context *hdd_ctx) From 18748980f7e7fe14816173e283052f5af4e2f3a6 Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Thu, 29 Aug 2024 01:17:53 -0700 Subject: [PATCH 06/16] Release 2.0.8.34U Release 2.0.8.34U Change-Id: Ie459f60663aef7745dbd9ef190691d8a405cb116 CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index ad8382fecb06..9c2757a9513a 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "T" +#define QWLAN_VERSION_EXTRA "U" #define QWLAN_VERSION_BUILD 34 -#define QWLAN_VERSIONSTR "2.0.8.34T" +#define QWLAN_VERSIONSTR "2.0.8.34U" #endif /* QWLAN_VERSION_H */ From 5d837c1b79e7761e75e1e128b189fa01ec6a1a85 Mon Sep 17 00:00:00 2001 From: Surya Prakash Sivaraj Date: Fri, 12 Jul 2024 16:07:30 +0530 Subject: [PATCH 07/16] qcacld-3.0: Enhance the RSNXE inter-op logic Some third-party APs are not able to handle more than 1 octet in the RSNXE, even though RSNXE support is present. Therefore, to prevent this interop issue, send only 1 octet of RSNXE if the AP broadcasts only 1 octet. RSNXE handling logic summary: 1. Don't modify userspace RSNXE when caps other than SAE_H2E, SAE_PK, SECURE_LTF, SECURE_RTT, PROT_RANGE_NEGOTIOATION are set. 2. AP doesn't send RSNXE For WPA2 - Strip the RSNXE completely. For WPA3 - Retain only SAE capabilities such as H2E and PK. 3. AP supports RSNXE with length 1 For WPA2 & WPA3 - Retain only the first octet in RSNXE. 4. AP supports RSNXE with multiple octet For WPA2 & WPA3 - Use the userspace assoc ie RSNXE as it is. Change-Id: I56d1d5711b067fe5e0ff19117f6a600219cb86a0 CRs-Fixed: 3490369 --- core/mac/inc/sir_mac_prot_def.h | 4 +- .../src/pe/lim/lim_process_sme_req_messages.c | 144 +++++++++++++++++- 2 files changed, 146 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/sir_mac_prot_def.h b/core/mac/inc/sir_mac_prot_def.h index 8927b19557e7..b31f399917c4 100644 --- a/core/mac/inc/sir_mac_prot_def.h +++ b/core/mac/inc/sir_mac_prot_def.h @@ -1,6 +1,6 @@ /* * Copyright (c) 2011-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022,2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1872,4 +1872,6 @@ struct he_6ghz_capability_info { #define SIR_MAC_TXSTBC 1 #define SIR_MAC_RXSTBC 1 +#define SIR_MAC_RSNX_CAP_MIN_LEN 1 +#define SIR_MAC_RSNX_CAP_MAX_LEN 16 #endif /* __MAC_PROT_DEFS_H */ diff --git a/core/mac/src/pe/lim/lim_process_sme_req_messages.c b/core/mac/src/pe/lim/lim_process_sme_req_messages.c index dd4ea287d90b..49113c9529e4 100644 --- a/core/mac/src/pe/lim/lim_process_sme_req_messages.c +++ b/core/mac/src/pe/lim/lim_process_sme_req_messages.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2012-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2021-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2021-2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -61,6 +61,7 @@ #include #include "wlan_lmac_if_def.h" #include "wlan_reg_services_api.h" +#include /* SME REQ processing function templates */ static bool __lim_process_sme_sys_ready_ind(struct mac_context *, uint32_t *); @@ -1198,6 +1199,140 @@ lim_get_vdev_rmf_capable(struct mac_context *mac, struct pe_session *session) } #endif +/* + * lim_rebuild_rsnxe_cap() - Rebuild the RSNXE CAP for STA + * + * @rsnx_ie: RSNX IE + * @length: length of extended RSN cap field + * + * This API is used to truncate/rebuild the RSNXE based on the length + * provided. This length marks the length of the extended RSN cap field. + * + * Return: Newly constructed RSNX IE + */ +static inline uint8_t *lim_rebuild_rsnxe_cap(uint8_t *rsnx_ie, uint8_t length) +{ + const uint8_t *rsnxe_cap; + uint8_t cap_len; + uint8_t *new_rsnxe = NULL; + + if (length < SIR_MAC_RSNX_CAP_MIN_LEN || + length > SIR_MAC_RSNX_CAP_MAX_LEN) { + pe_err("Invalid length %d", length); + return NULL; + } + + rsnxe_cap = wlan_crypto_parse_rsnxe_ie(rsnx_ie, &cap_len); + if (!rsnxe_cap) + return NULL; + + new_rsnxe = qdf_mem_malloc(length + 2); + if (!new_rsnxe) + return NULL; + + new_rsnxe[0] = WLAN_ELEMID_RSNXE; + new_rsnxe[1] = length; + qdf_mem_copy(&new_rsnxe[2], rsnxe_cap, length); + + /* Now update the new field length in octet 0 for the new length*/ + new_rsnxe[2] = (new_rsnxe[2] & 0xF0) | (length - 1); + + pe_debug("New RSNXE length %d", length); + QDF_TRACE_HEX_DUMP(QDF_MODULE_ID_PE, QDF_TRACE_LEVEL_DEBUG, + new_rsnxe, length + 2); + return new_rsnxe; +} + +static inline QDF_STATUS +lim_strip_rsnx_ie(struct mac_context *mac_ctx, + struct pe_session *session) +{ + int32_t akm; + uint8_t len = 0; + uint8_t *rsnxe = NULL, *new_rsnxe = NULL; + QDF_STATUS status = QDF_STATUS_SUCCESS; + uint8_t *add_ie = NULL; + uint16_t add_ie_len; + + akm = wlan_crypto_get_param(session->vdev, WLAN_CRYPTO_PARAM_KEY_MGMT); + if (akm == -1 || + !(WLAN_CRYPTO_IS_WPA_WPA2(akm) || WLAN_CRYPTO_IS_WPA3(akm))) + return status; + + add_ie = session->lim_join_req->addIEAssoc.addIEdata; + add_ie_len = session->lim_join_req->addIEAssoc.length; + + if (!wlan_get_ie_ptr_from_eid(WLAN_ELEMID_RSNXE, add_ie, add_ie_len)) + return status; + + /* + * Userspace may send RSNXE also in connect request irrespective + * of the connecting AP capabilities. This allows the driver to chose + * best candidate based on score. But the chosen candidate may + * not support the RSNXE feature and may not advertise RSNXE + * in beacon/probe response. Station is not supposed to include + * the RSNX IE in assoc request in such cases as legacy APs + * may misbahave due to the new IE. It's observed that few + * legacy APs which don't support the RSNXE reject the + * connection at EAPOL stage. + * + */ + rsnxe = qdf_mem_malloc(WLAN_MAX_IE_LEN + 2); + if (!rsnxe) + return QDF_STATUS_E_FAILURE; + + lim_strip_ie(mac_ctx, add_ie, &add_ie_len, WLAN_ELEMID_RSNXE, + ONE_BYTE, NULL, 0, rsnxe, WLAN_MAX_IE_LEN); + + session->lim_join_req->addIEAssoc.length = add_ie_len; + + if (!rsnxe[0]) + goto end; + + if (WLAN_CRYPTO_IS_WPA_WPA2(akm)) { + mlme_debug("Strip RSNXE as it is not supported by AP"); + goto end; + } + + if (WLAN_CRYPTO_IS_WPA3(akm)) { + len = 1; + goto rebuild_rsnxe; + } + + pe_err("Error in handling RSNXE. RSNXE length : %d", rsnxe[1]); + status = QDF_STATUS_E_FAILURE; + goto end; + +rebuild_rsnxe: + /* Build the new RSNXE */ + new_rsnxe = lim_rebuild_rsnxe_cap(rsnxe, len); + if (!new_rsnxe) { + status = QDF_STATUS_E_FAILURE; + goto end; + } else if (!new_rsnxe[1]) { + qdf_mem_free(new_rsnxe); + status = QDF_STATUS_E_FAILURE; + goto end; + } + + /* Append the new RSNXE to the assoc ie */ + if (add_ie_len + new_rsnxe[1] >= SIR_MAC_MAX_ADD_IE_LENGTH) { + pe_err("Cannot accomodate the new RSNX IE"); + status = QDF_STATUS_E_FAILURE; + qdf_mem_free(new_rsnxe); + goto end; + } + + qdf_mem_copy(&add_ie[add_ie_len], new_rsnxe, new_rsnxe[1] + 2); + add_ie_len += new_rsnxe[1] + 2; + session->lim_join_req->addIEAssoc.length = add_ie_len; + qdf_mem_free(new_rsnxe); + +end: + qdf_mem_free(rsnxe); + return status; +} + /** * __lim_process_sme_join_req() - process SME_JOIN_REQ message * @mac_ctx: Pointer to Global MAC structure @@ -1599,6 +1734,13 @@ __lim_process_sme_join_req(struct mac_context *mac_ctx, void *msg_buf) ret_code = eSIR_SME_INVALID_PARAMETERS; goto end; } + + status = lim_strip_rsnx_ie(mac_ctx, session); + if (QDF_IS_STATUS_ERROR(status)) { + pe_err("Error in parsing RSNX IE"); + ret_code = eSIR_SME_INVALID_PARAMETERS; + goto end; + } } mlme_obj = wlan_vdev_mlme_get_cmpt_obj(session->vdev); From b9e91d03e431fc332884d3d910ae77e2270f93e2 Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Mon, 2 Sep 2024 09:26:40 -0700 Subject: [PATCH 08/16] Release 2.0.8.34V Release 2.0.8.34V Change-Id: I6f37d9545e66ae5c2c2c57df8980e2c34d6d1abf CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index 9c2757a9513a..22bb21b22cf9 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "U" +#define QWLAN_VERSION_EXTRA "V" #define QWLAN_VERSION_BUILD 34 -#define QWLAN_VERSIONSTR "2.0.8.34U" +#define QWLAN_VERSIONSTR "2.0.8.34V" #endif /* QWLAN_VERSION_H */ From f33a4f5a7d5b0b54b72f6775a450575fc82a2fd8 Mon Sep 17 00:00:00 2001 From: Kiran Kumar Lokere Date: Mon, 9 Sep 2024 16:07:29 -0700 Subject: [PATCH 09/16] qcacld-3.0: Fix the possible OOB write in country IE unpack Fix the possible OOB write in unpacking the country IE due to the IE length check against integer division. CRs-Fixed: 3910626 Change-Id: I800290ab7285fb46ed43a46ce38967046b4881fa (cherry picked from commit 0002f9ddc9a6be3e34fe15e55f286b5794b29f08) --- core/mac/src/include/dot11f.h | 2 +- core/mac/src/sys/legacy/src/utils/src/dot11f.c | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/core/mac/src/include/dot11f.h b/core/mac/src/include/dot11f.h index 7b0afc593596..338a943facae 100644 --- a/core/mac/src/include/dot11f.h +++ b/core/mac/src/include/dot11f.h @@ -27,7 +27,7 @@ * * * This file was automatically generated by 'framesc' - * Mon May 30 20:50:39 2022 from the following file(s): + * Wed Sep 11 12:49:28 2024 from the following file(s): * * dot11f.frms * diff --git a/core/mac/src/sys/legacy/src/utils/src/dot11f.c b/core/mac/src/sys/legacy/src/utils/src/dot11f.c index ec2f7ff8be51..b44f94ea0ba8 100644 --- a/core/mac/src/sys/legacy/src/utils/src/dot11f.c +++ b/core/mac/src/sys/legacy/src/utils/src/dot11f.c @@ -25,7 +25,7 @@ * * * This file was automatically generated by 'framesc' - * Mon May 30 20:50:39 2022 from the following file(s): + * Wed Sep 11 12:49:28 2024 from the following file(s): * * dot11f.frms * @@ -134,7 +134,7 @@ typedef struct sIEDefn { #define DOT11F_PARAMETER_CHECK2(pSrc, pBuf, nBuf, pnConsumed) \ do { \ if (!pSrc || IsBadReadPtr(pSrc, 4))\ - eturn DOT11F_BAD_INPUT_BUFFER; \ + return DOT11F_BAD_INPUT_BUFFER; \ if (!pBuf || IsBadWritePtr(pBuf, nBuf))\ return DOT11F_BAD_OUTPUT_BUFFER; \ if (!nBuf)\ @@ -4131,7 +4131,7 @@ uint32_t dot11f_unpack_ie_country(tpAniSirGlobal pCtx, return 0U; } else { pDst->num_more_triplets = (uint8_t)(ielen / 3); - if (ielen / 3 > 80) { + if (ielen > 80 * 3) { pDst->present = 0; return DOT11F_SKIPPED_BAD_IE; } From 923a4325957c9c1bda483828037331defd919a0e Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Thu, 26 Sep 2024 08:29:49 -0700 Subject: [PATCH 10/16] Release 2.0.8.34W Release 2.0.8.34W Change-Id: I8b539f6198a7491667862a742c31424e84380b14 CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index 22bb21b22cf9..52ba845b0e8c 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "V" +#define QWLAN_VERSION_EXTRA "W" #define QWLAN_VERSION_BUILD 34 -#define QWLAN_VERSIONSTR "2.0.8.34V" +#define QWLAN_VERSIONSTR "2.0.8.34W" #endif /* QWLAN_VERSION_H */ From 01ae0689b195f626929893b846f53e4bc08d59db Mon Sep 17 00:00:00 2001 From: Surya Prakash Sivaraj Date: Fri, 29 Mar 2024 10:33:08 +0530 Subject: [PATCH 11/16] qcacld-3.0: Remove use-after-free of frame in tx mgmt send The tx completion handler for the frame frees the buffer. Therefore, usage of frame after tx completion causes undesired effect. Remove the dereference of tx frame buffer contents in lim_tx_mgmt_frame() after the tx completion. Change-Id: I32211e1bce4f96ba920a2212ef65aa39831666ab CRs-Fixed: 3772014 --- core/mac/src/pe/lim/lim_send_management_frames.c | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/core/mac/src/pe/lim/lim_send_management_frames.c b/core/mac/src/pe/lim/lim_send_management_frames.c index d9d92767aed6..67e12248ea2a 100644 --- a/core/mac/src/pe/lim/lim_send_management_frames.c +++ b/core/mac/src/pe/lim/lim_send_management_frames.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2011-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -5744,8 +5744,7 @@ static void lim_tx_mgmt_frame(struct mac_context *mac_ctx, uint8_t vdev_id, MTRACE(qdf_trace(QDF_MODULE_ID_PE, TRACE_CODE_TX_COMPLETE, session->peSessionId, qdf_status)); if (!QDF_IS_STATUS_SUCCESS(qdf_status)) { - pe_err("*** Could not send Auth frame (subType: %d), retCode=%X ***", - fc->subType, qdf_status); + pe_err("Could not send Auth frame, retCode=%X", qdf_status); mac_ctx->auth_ack_status = LIM_TX_FAILED; auth_ack_status = SENT_FAIL; lim_diag_event_report(mac_ctx, WLAN_PE_DIAG_AUTH_ACK_EVENT, From 507504e89d928623d1bc2a5a805eaf7fdbefd313 Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Fri, 4 Oct 2024 09:04:56 -0700 Subject: [PATCH 12/16] Release 2.0.8.34X Release 2.0.8.34X Change-Id: I236740f6ead734b72780cfa0366f0311a20a9308 CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index 52ba845b0e8c..cada8a0095ac 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "W" +#define QWLAN_VERSION_EXTRA "X" #define QWLAN_VERSION_BUILD 34 -#define QWLAN_VERSIONSTR "2.0.8.34W" +#define QWLAN_VERSIONSTR "2.0.8.34X" #endif /* QWLAN_VERSION_H */ From 685e5c9a53e754d4eb67211ed5ec7b4144bbfcd1 Mon Sep 17 00:00:00 2001 From: Dharmendra Tiwari Date: Tue, 3 Sep 2024 23:06:17 -0700 Subject: [PATCH 13/16] qcacld-3.0: Correcting the TSInfo structure size according to the Spec According to spec the TSinfo size should be 4 bytes. To fix this issue,TSInfo size is increased to 4bytes aligning with the current standard. CRs-Fixed: 3910625 Change-Id: I7979fa84af0295d21d4afe1b876af494a5b8fed8 --- core/mac/src/cfg/cfgUtil/dot11f.frms | 2 +- core/mac/src/include/dot11f.h | 4 ++-- core/mac/src/sys/legacy/src/utils/src/dot11f.c | 4 ++-- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/core/mac/src/cfg/cfgUtil/dot11f.frms b/core/mac/src/cfg/cfgUtil/dot11f.frms index a3bbbbbf6297..4cb16f7da0c1 100644 --- a/core/mac/src/cfg/cfgUtil/dot11f.frms +++ b/core/mac/src/cfg/cfgUtil/dot11f.frms @@ -370,7 +370,7 @@ FF SMPowerModeSet (1) //7.3.1.25 } } -FF TSInfo (3) // 7.3.2.30 +FF TSInfo (4) // 7.3.2.30 { { traffic_type: 1; diff --git a/core/mac/src/include/dot11f.h b/core/mac/src/include/dot11f.h index 338a943facae..216172f4c2c8 100644 --- a/core/mac/src/include/dot11f.h +++ b/core/mac/src/include/dot11f.h @@ -27,7 +27,7 @@ * * * This file was automatically generated by 'framesc' - * Wed Sep 11 12:49:28 2024 from the following file(s): + * Tue Sep 3 23:04:38 2024 from the following file(s): * * dot11f.frms * @@ -442,7 +442,7 @@ typedef struct sDot11fFfTSInfo { uint32_t unused:15; } tDot11fFfTSInfo; -#define DOT11F_FF_TSINFO_LEN (3) +#define DOT11F_FF_TSINFO_LEN (4) void dot11f_unpack_ff_ts_info(tpAniSirGlobal, uint8_t *, tDot11fFfTSInfo *); diff --git a/core/mac/src/sys/legacy/src/utils/src/dot11f.c b/core/mac/src/sys/legacy/src/utils/src/dot11f.c index b44f94ea0ba8..3e2dba18d7c4 100644 --- a/core/mac/src/sys/legacy/src/utils/src/dot11f.c +++ b/core/mac/src/sys/legacy/src/utils/src/dot11f.c @@ -25,7 +25,7 @@ * * * This file was automatically generated by 'framesc' - * Wed Sep 11 12:49:28 2024 from the following file(s): + * Tue Sep 3 23:04:38 2024 from the following file(s): * * dot11f.frms * @@ -16710,7 +16710,7 @@ uint32_t dot11f_get_packed_del_ts_size(tpAniSirGlobal pCtx, tDot11fDelTS *pFrm, uint32_t *pnNeeded) { uint32_t status = 0; - *pnNeeded = 7; + *pnNeeded = 8; status = get_packed_size_core(pCtx, (uint8_t *)pFrm, pnNeeded, IES_DelTS); return status; From 1a2fc5395ed628e0b804102bf8ef1b08390bddca Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Wed, 9 Oct 2024 03:44:50 -0700 Subject: [PATCH 14/16] Release 2.0.8.34Y Release 2.0.8.34Y Change-Id: Ifb4c818cfbb266d94f02fb887edd901c4471a707 CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index cada8a0095ac..a57de3022392 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "X" +#define QWLAN_VERSION_EXTRA "Y" #define QWLAN_VERSION_BUILD 34 -#define QWLAN_VERSIONSTR "2.0.8.34X" +#define QWLAN_VERSIONSTR "2.0.8.34Y" #endif /* QWLAN_VERSION_H */ From 8867dfaa062661e77fb65cf1e3ea72f0b50c276c Mon Sep 17 00:00:00 2001 From: Dharmendra Tiwari Date: Tue, 3 Sep 2024 23:06:17 -0700 Subject: [PATCH 15/16] qcacld-3.0: Correcting the TSInfo structure size according to the Spec According to spec the TSinfo size should be 4 bytes. To fix this issue,TSInfo size is increased to 4bytes aligning with the current standard. CRs-Fixed: 3910625 Change-Id: I7979fa84af0295d21d4afe1b876af494a5b8fed8 --- core/mac/src/cfg/cfgUtil/dot11f.frms | 2 +- core/mac/src/include/dot11f.h | 4 ++-- core/mac/src/sys/legacy/src/utils/src/dot11f.c | 4 ++-- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/core/mac/src/cfg/cfgUtil/dot11f.frms b/core/mac/src/cfg/cfgUtil/dot11f.frms index a3bbbbbf6297..4cb16f7da0c1 100644 --- a/core/mac/src/cfg/cfgUtil/dot11f.frms +++ b/core/mac/src/cfg/cfgUtil/dot11f.frms @@ -370,7 +370,7 @@ FF SMPowerModeSet (1) //7.3.1.25 } } -FF TSInfo (3) // 7.3.2.30 +FF TSInfo (4) // 7.3.2.30 { { traffic_type: 1; diff --git a/core/mac/src/include/dot11f.h b/core/mac/src/include/dot11f.h index 7b0afc593596..216172f4c2c8 100644 --- a/core/mac/src/include/dot11f.h +++ b/core/mac/src/include/dot11f.h @@ -27,7 +27,7 @@ * * * This file was automatically generated by 'framesc' - * Mon May 30 20:50:39 2022 from the following file(s): + * Tue Sep 3 23:04:38 2024 from the following file(s): * * dot11f.frms * @@ -442,7 +442,7 @@ typedef struct sDot11fFfTSInfo { uint32_t unused:15; } tDot11fFfTSInfo; -#define DOT11F_FF_TSINFO_LEN (3) +#define DOT11F_FF_TSINFO_LEN (4) void dot11f_unpack_ff_ts_info(tpAniSirGlobal, uint8_t *, tDot11fFfTSInfo *); diff --git a/core/mac/src/sys/legacy/src/utils/src/dot11f.c b/core/mac/src/sys/legacy/src/utils/src/dot11f.c index ec2f7ff8be51..9277833d8b65 100644 --- a/core/mac/src/sys/legacy/src/utils/src/dot11f.c +++ b/core/mac/src/sys/legacy/src/utils/src/dot11f.c @@ -25,7 +25,7 @@ * * * This file was automatically generated by 'framesc' - * Mon May 30 20:50:39 2022 from the following file(s): + * Tue Sep 3 23:04:38 2024 from the following file(s): * * dot11f.frms * @@ -16710,7 +16710,7 @@ uint32_t dot11f_get_packed_del_ts_size(tpAniSirGlobal pCtx, tDot11fDelTS *pFrm, uint32_t *pnNeeded) { uint32_t status = 0; - *pnNeeded = 7; + *pnNeeded = 8; status = get_packed_size_core(pCtx, (uint8_t *)pFrm, pnNeeded, IES_DelTS); return status; From ccf6a7f542b1529184942e95a173c769d86200a0 Mon Sep 17 00:00:00 2001 From: Kiran Kumar Lokere Date: Mon, 9 Sep 2024 16:07:29 -0700 Subject: [PATCH 16/16] qcacld-3.0: Fix the possible OOB write in country IE unpack Fix the possible OOB write in unpacking the country IE due to the IE length check against integer division. CRs-Fixed: 3910626 Change-Id: I800290ab7285fb46ed43a46ce38967046b4881fa (cherry picked from commit 0002f9ddc9a6be3e34fe15e55f286b5794b29f08) --- core/mac/src/include/dot11f.h | 2 +- core/mac/src/sys/legacy/src/utils/src/dot11f.c | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/core/mac/src/include/dot11f.h b/core/mac/src/include/dot11f.h index 216172f4c2c8..0e2d373a0b1f 100644 --- a/core/mac/src/include/dot11f.h +++ b/core/mac/src/include/dot11f.h @@ -27,7 +27,7 @@ * * * This file was automatically generated by 'framesc' - * Tue Sep 3 23:04:38 2024 from the following file(s): + * Wed Sep 11 12:49:28 2024 from the following file(s): * * dot11f.frms * diff --git a/core/mac/src/sys/legacy/src/utils/src/dot11f.c b/core/mac/src/sys/legacy/src/utils/src/dot11f.c index 9277833d8b65..b07b8c68f94a 100644 --- a/core/mac/src/sys/legacy/src/utils/src/dot11f.c +++ b/core/mac/src/sys/legacy/src/utils/src/dot11f.c @@ -25,7 +25,7 @@ * * * This file was automatically generated by 'framesc' - * Tue Sep 3 23:04:38 2024 from the following file(s): + * Wed Sep 11 12:49:28 2024 from the following file(s): * * dot11f.frms * @@ -134,7 +134,7 @@ typedef struct sIEDefn { #define DOT11F_PARAMETER_CHECK2(pSrc, pBuf, nBuf, pnConsumed) \ do { \ if (!pSrc || IsBadReadPtr(pSrc, 4))\ - eturn DOT11F_BAD_INPUT_BUFFER; \ + return DOT11F_BAD_INPUT_BUFFER; \ if (!pBuf || IsBadWritePtr(pBuf, nBuf))\ return DOT11F_BAD_OUTPUT_BUFFER; \ if (!nBuf)\ @@ -4131,7 +4131,7 @@ uint32_t dot11f_unpack_ie_country(tpAniSirGlobal pCtx, return 0U; } else { pDst->num_more_triplets = (uint8_t)(ielen / 3); - if (ielen / 3 > 80) { + if (ielen > 80 * 3) { pDst->present = 0; return DOT11F_SKIPPED_BAD_IE; }