From 8be762469ab18b40e4cea9223a1bf86fa203159d Mon Sep 17 00:00:00 2001 From: "Kaushik K.N" Date: Mon, 14 Jul 2025 21:50:31 +0530 Subject: [PATCH 1/4] qcacld-3.0: Add Validation for WMA Handle and PSOC in Wake Event Currently, the WOW wakeup event handler lacks validation for the WMA handle and the PSOC pointer within the WMA handle. This omission can lead to null pointer dereferences in the host. To address this issue, null pointer checks for both the WMA handle and the PSOC pointer have been added. CRs-Fixed: 4107000 Change-Id: Iaf22d5adc14b65b778b0e1d78108eded0cccb8c9 --- core/wma/src/wma_features.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/core/wma/src/wma_features.c b/core/wma/src/wma_features.c index 03a51f01fbd4..e5a234adc325 100644 --- a/core/wma/src/wma_features.c +++ b/core/wma/src/wma_features.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2013-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -2813,6 +2813,9 @@ int wma_wow_wakeup_host_event(void *handle, uint8_t *event, uint32_t len) WMI_WOW_WAKEUP_HOST_EVENTID_param_tlvs *event_param; WOW_EVENT_INFO_fixed_param *wake_info; + if (!wma || !wma->psoc) + return -EINVAL; + event_param = (WMI_WOW_WAKEUP_HOST_EVENTID_param_tlvs *)event; if (!event_param) { wma_err("Wake event data is null"); From 4117e36cb841c3a9e5751785cee84fd9a9933c2d Mon Sep 17 00:00:00 2001 From: Dharmendra Tiwari Date: Mon, 12 May 2025 08:00:40 -0700 Subject: [PATCH 2/4] qcacld-3.0: Fix underflow issue of beacon length A validation check has been added to ensure beacon length is not less than (bcn->noa_sub_ie_len + sizeof(struct p2p_ie)), preventing underflow issues. Change-Id: I924a3ebf4a0749d5a4c56b36878765fcf46440a4 CRs-Fixed: 4166530 --- core/wma/src/wma_power.c | 20 ++++++++++++++------ 1 file changed, 14 insertions(+), 6 deletions(-) diff --git a/core/wma/src/wma_power.c b/core/wma/src/wma_power.c index 6c8004735a15..feed5a83979d 100644 --- a/core/wma/src/wma_power.c +++ b/core/wma/src/wma_power.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2013-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1171,20 +1171,28 @@ static void wma_update_beacon_noa_ie(struct beacon_info *bcn, /* TODO: Assuming p2p noa ie is last ie in the beacon */ qdf_mem_zero(bcn->noa_ie, (bcn->noa_sub_ie_len + sizeof(struct p2p_ie))); - bcn->len -= (bcn->noa_sub_ie_len + - sizeof(struct p2p_ie)); + if (bcn->len < (bcn->noa_sub_ie_len + + sizeof(struct p2p_ie))) + bcn->len = 0; + else + bcn->len -= (bcn->noa_sub_ie_len + + sizeof(struct p2p_ie)); bcn->noa_ie = NULL; bcn->noa_sub_ie_len = 0; } - wma_debug("No need to update NoA"); return; } if (bcn->noa_sub_ie_len && bcn->noa_ie) { + if (bcn->len < (bcn->noa_sub_ie_len + sizeof(struct p2p_ie))) + bcn->len = 0; + else + bcn->len -= (bcn->noa_sub_ie_len + + sizeof(struct p2p_ie)); + /* NoA present in previous beacon, update it */ wma_debug("NoA present in previous beacon, update the NoA IE, bcn->len %u bcn->noa_sub_ie_len %u", - bcn->len, bcn->noa_sub_ie_len); - bcn->len -= (bcn->noa_sub_ie_len + sizeof(struct p2p_ie)); + bcn->len, bcn->noa_sub_ie_len); qdf_mem_zero(bcn->noa_ie, (bcn->noa_sub_ie_len + sizeof(struct p2p_ie))); } else { /* NoA is not present in previous beacon */ From 15ea8abee0fb0954361aad88d35b9e6c0319e411 Mon Sep 17 00:00:00 2001 From: Kiran Kumar Reddy A E Date: Sat, 6 Sep 2025 00:37:52 -0700 Subject: [PATCH 3/4] Release 2.0.8.35G Release 2.0.8.35G Change-Id: Iaa1e456ca143d8650d715e3bdd25e00f5281b8b4 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index 7c707bd54fb8..500f1f71f75c 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "F" +#define QWLAN_VERSION_EXTRA "G" #define QWLAN_VERSION_BUILD 35 -#define QWLAN_VERSIONSTR "2.0.8.35F" +#define QWLAN_VERSIONSTR "2.0.8.35G" #endif /* QWLAN_VERSION_H */ From 40c990ed3d9987d281009a1256c5664614ec1138 Mon Sep 17 00:00:00 2001 From: Surya Prakash Sivaraj Date: Fri, 16 May 2025 12:51:50 +0530 Subject: [PATCH 4/4] qcacld-3.0: Populate MBSSID cap in Ext CAP IE The MBSSID cap in the extended capability IE is populated properly in the Probe and Assoc request of the initial connection. But, this cap is missing in the reassoc request during roaming. Host driver fills this cap based on the service cap of MBSSID support only during the probe/assoc req generation. This cap is not passed to the firmware via SET IE or via assoc IEs in the RSO START. Since the service cap would not change in runtime, override the MBSSID cap in the assoc IEs received from the userspace itself. This sets the cap in both SET IE as well as RSO START. Change-Id: I69476e503a369df6533de9c215efc4c39d9e251c CRs-Fixed: 4117861 --- core/mac/src/pe/lim/lim_process_sme_req_messages.c | 3 +++ core/sme/src/csr/csr_api_roam.c | 12 +++++++++++- 2 files changed, 14 insertions(+), 1 deletion(-) diff --git a/core/mac/src/pe/lim/lim_process_sme_req_messages.c b/core/mac/src/pe/lim/lim_process_sme_req_messages.c index 0ac96d900386..0f57abe3c224 100644 --- a/core/mac/src/pe/lim/lim_process_sme_req_messages.c +++ b/core/mac/src/pe/lim/lim_process_sme_req_messages.c @@ -6520,6 +6520,9 @@ static void lim_process_set_ie_req(struct mac_context *mac_ctx, uint32_t *msg_bu if (p_ext_cap->interworking_service) p_ext_cap->qos_map = 1; + if (wma_is_mbssid_enabled()) + p_ext_cap->multi_bssid = 1; + extra_ext_cap.num_bytes = lim_compute_ext_cap_ie_length(&extra_ext_cap); send_ie: diff --git a/core/sme/src/csr/csr_api_roam.c b/core/sme/src/csr/csr_api_roam.c index c67bbe35827c..4484ed3c5ce8 100644 --- a/core/sme/src/csr/csr_api_roam.c +++ b/core/sme/src/csr/csr_api_roam.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2012-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2022-2025 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -17422,6 +17422,8 @@ static void csr_cm_update_driver_assoc_ies( MIN_TX_PWR_CAP, MAX_TX_PWR_CAP}; uint8_t max_tx_pwr_cap = 0; uint8_t supp_chan_ie[DOT11F_IE_SUPPCHANNELS_MAX_LEN], supp_chan_ie_len; + struct s_ext_cap *extcap; + uint8_t *ext_cap_ie; static const uint8_t qcn_ie[] = {0x8C, 0xFD, 0xF0, 0x1, QCN_IE_VERSION_SUBATTR_ID, QCN_IE_VERSION_SUBATTR_DATA_LEN, @@ -17433,6 +17435,14 @@ static void csr_cm_update_driver_assoc_ies( qdf_mem_copy(rso_mode_cfg->assoc_ie, session->pAddIEAssoc, rso_mode_cfg->assoc_ie_length); + ext_cap_ie = (uint8_t *)wlan_get_ie_ptr_from_eid(WLAN_ELEMID_XCAPS, + rso_mode_cfg->assoc_ie, + rso_mode_cfg->assoc_ie_length); + if (ext_cap_ie && wma_is_mbssid_enabled()) { + extcap = (struct s_ext_cap *)&ext_cap_ie[2]; + extcap->multi_bssid = 1; + } + if (session->pConnectBssDesc) max_tx_pwr_cap = csr_get_cfg_max_tx_power( mac_ctx,