mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-11 07:03:09 -04:00
qcacmn: Fix OOB issue
Changes to fix OOB issue seen util_scan_parse_beacon_frame. CRs-Fixed: 3582496 Change-Id: I53244be54d31e87b55d0b44ce94315c8001f417d
This commit is contained in:
parent
a3fd923c0d
commit
61edca871f
2 changed files with 22 additions and 7 deletions
|
|
@ -205,6 +205,10 @@
|
|||
#define WLAN_MAX_HEOP_IE_LEN 16
|
||||
#define WLAN_HEOP_OUI_TYPE "\x24"
|
||||
#define WLAN_HEOP_OUI_SIZE 1
|
||||
#define WLAN_MIN_HECAP_IE_LEN 22
|
||||
#define WLAN_MAX_HECAP_IE_LEN 55
|
||||
#define WLAN_HE_MCS_MAP_LEN 2
|
||||
#define WLAN_INVALID_RX_MCS_MAP 0xFFFF
|
||||
|
||||
#define WLAN_HEOP_FIXED_PARAM_LENGTH 7
|
||||
#define WLAN_HEOP_VHTOP_LENGTH 3
|
||||
|
|
|
|||
|
|
@ -789,6 +789,9 @@ util_scan_parse_extn_ie(struct scan_cache_entry *scan_params,
|
|||
scan_params->ie_list.srp = (uint8_t *)ie;
|
||||
break;
|
||||
case WLAN_EXTN_ELEMID_HECAP:
|
||||
if ((extn_ie->ie_len < WLAN_MIN_HECAP_IE_LEN) ||
|
||||
(extn_ie->ie_len > WLAN_MAX_HECAP_IE_LEN))
|
||||
return QDF_STATUS_E_INVAL;
|
||||
scan_params->ie_list.hecap = (uint8_t *)ie;
|
||||
break;
|
||||
case WLAN_EXTN_ELEMID_HEOP:
|
||||
|
|
@ -1317,28 +1320,36 @@ static int util_scan_scm_calc_nss_supported_by_ap(
|
|||
{
|
||||
struct htcap_cmn_ie *htcap;
|
||||
struct wlan_ie_vhtcaps *vhtcaps;
|
||||
struct wlan_ie_hecaps *hecaps;
|
||||
uint8_t *he_cap;
|
||||
uint8_t *end_ptr = NULL;
|
||||
uint16_t rx_mcs_map = 0;
|
||||
uint8_t *mcs_map_offset;
|
||||
|
||||
htcap = (struct htcap_cmn_ie *)
|
||||
util_scan_entry_htcap(scan_params);
|
||||
vhtcaps = (struct wlan_ie_vhtcaps *)
|
||||
util_scan_entry_vhtcap(scan_params);
|
||||
hecaps = (struct wlan_ie_hecaps *)
|
||||
util_scan_entry_hecap(scan_params);
|
||||
he_cap = util_scan_entry_hecap(scan_params);
|
||||
|
||||
if (hecaps) {
|
||||
if (he_cap) {
|
||||
/* Using rx mcs map related to 80MHz or lower as in some
|
||||
* cases higher mcs may suuport lesser NSS than that
|
||||
* of lowe mcs. Thus giving max NSS capability.
|
||||
*/
|
||||
rx_mcs_map =
|
||||
qdf_cpu_to_le16(hecaps->mcs_bw_map[0].rx_mcs_map);
|
||||
end_ptr = he_cap + he_cap[1] + sizeof(struct ie_header);
|
||||
mcs_map_offset = (he_cap + sizeof(struct extn_ie_header) +
|
||||
WLAN_HE_MACCAP_LEN + WLAN_HE_PHYCAP_LEN);
|
||||
if ((mcs_map_offset + WLAN_HE_MCS_MAP_LEN) <= end_ptr) {
|
||||
rx_mcs_map = *(uint16_t *)mcs_map_offset;
|
||||
} else {
|
||||
rx_mcs_map = WLAN_INVALID_RX_MCS_MAP;
|
||||
scm_debug("mcs_map_offset exceeds he cap len");
|
||||
}
|
||||
} else if (vhtcaps) {
|
||||
rx_mcs_map = vhtcaps->rx_mcs_map;
|
||||
}
|
||||
|
||||
if (hecaps || vhtcaps) {
|
||||
if (he_cap || vhtcaps) {
|
||||
if ((rx_mcs_map & 0xC000) != 0xC000)
|
||||
return 8;
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue