From 149e4a4f326ea1ea4b92cfc1599d1da616b7d4f6 Mon Sep 17 00:00:00 2001 From: Krupali Dhanvijay Date: Tue, 27 Dec 2022 22:55:23 +0530 Subject: [PATCH 1/5] qcacmn: Send driver disconnect internal reason code to user space Send the driver disconnect internal reason code as an event to user space using QCA_NL80211_VENDOR_SUBCMD_DRIVER_DISCONNECT_REASON vendor command. Change-Id: I0027675b809b94628b6c0c4b8e8286e38fa9f47d CRs-Fixed: 3371398 --- os_if/linux/wlan_cfg80211.h | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/os_if/linux/wlan_cfg80211.h b/os_if/linux/wlan_cfg80211.h index ea022611eb04..dfcdc412b1e5 100644 --- a/os_if/linux/wlan_cfg80211.h +++ b/os_if/linux/wlan_cfg80211.h @@ -1,5 +1,6 @@ /* * Copyright (c) 2016-2020 The Linux Foundation. All rights reserved. + * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -140,6 +141,8 @@ * MBSSID TX VDEV status index * @QCA_NL80211_VENDOR_SUBCMD_CONFIG_TWT_INDEX: TWT config index * @QCA_NL80211_VENDOR_SUBCMD_PEER_CFR_CAPTURE_CFG_INDEX: CFR data event index + * @QCA_NL80211_VENDOR_SUBCMD_DRIVER_DISCONNECT_REASON_INDEX: + * Driver disconnect reason index */ enum qca_nl80211_vendor_subcmds_index { @@ -232,6 +235,7 @@ enum qca_nl80211_vendor_subcmds_index { QCA_NL80211_VENDOR_SUBCMD_UPDATE_SSID_INDEX, QCA_NL80211_VENDOR_SUBCMD_WIFI_FW_STATS_INDEX, QCA_NL80211_VENDOR_SUBCMD_MBSSID_TX_VDEV_STATUS_INDEX, + QCA_NL80211_VENDOR_SUBCMD_DRIVER_DISCONNECT_REASON_INDEX, #ifdef WLAN_SUPPORT_TWT QCA_NL80211_VENDOR_SUBCMD_CONFIG_TWT_INDEX, #endif From 1ff1a00b32f052b8ae4116493d6f15206260766b Mon Sep 17 00:00:00 2001 From: Surabhi Vishnoi Date: Fri, 2 Dec 2022 16:04:56 +0530 Subject: [PATCH 2/5] qcacmn: Fix 6 GHz bss HE capable beamformee score Currently, BSS beamformee score is calculated from vht_cap or eht caps, so for 6 GHz HE capable BSS it will calculated to zero. Due to this 5 GHz will always get selected compared to 6 GHz BSS with all other capabilities and conditions same in both BSS as 5 GHz will have more total candidate score. Fix this issue by correct calculation of AP beamformer capability in case of 6 GHz HE BSS. Change-Id: I0f3285ce1c5c1aeeba624c5371ff0f884ae78c58 CRs-Fixed: 3351991 --- umac/cmn_services/cmn_defs/inc/wlan_cmn_ieee80211.h | 7 ++++++- .../connection_mgr/core/src/wlan_cm_bss_scoring.c | 13 ++++++++++++- 2 files changed, 18 insertions(+), 2 deletions(-) diff --git a/umac/cmn_services/cmn_defs/inc/wlan_cmn_ieee80211.h b/umac/cmn_services/cmn_defs/inc/wlan_cmn_ieee80211.h index e0c794255ee6..d519f3396ac1 100644 --- a/umac/cmn_services/cmn_defs/inc/wlan_cmn_ieee80211.h +++ b/umac/cmn_services/cmn_defs/inc/wlan_cmn_ieee80211.h @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1400,11 +1400,16 @@ struct wlan_ie_vhtop { uint16_t vhtop_basic_mcs_set; } qdf_packed; +#define WLAN_HE_PHYCAP_SU_BFER_OFFSET 3 +#define WLAN_HE_PHYCAP_SU_BFER_IDX 7 +#define WLAN_HE_PHYCAP_SU_BFER_BITS 1 + #define WLAN_HE_PHYCAP_160_SUPPORT BIT(2) #define WLAN_HE_PHYCAP_80_80_SUPPORT BIT(3) #define WLAN_HE_MACCAP_LEN 6 #define WLAN_HE_PHYCAP_LEN 11 #define WLAN_HE_MAX_MCS_MAPS 3 + /** * struct wlan_ie_hecaps - HT capabilities * @elem_id: HE caps IE diff --git a/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c b/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c index 6329c0a90ef1..27d70b49ec1f 100644 --- a/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c +++ b/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c @@ -1,5 +1,6 @@ /* * Copyright (c) 2017-2021, The Linux Foundation. All rights reserved. + * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for any * purpose with or without fee is hereby granted, provided that the above @@ -1416,6 +1417,7 @@ static int cm_calculate_bss_score(struct wlan_objmgr_psoc *psoc, bool same_bucket = false; bool ap_su_beam_former = false; struct wlan_ie_vhtcaps *vht_cap; + struct wlan_ie_hecaps *he_cap; struct scoring_cfg *score_config; struct weight_cfg *weight_config; uint32_t sta_nss; @@ -1504,8 +1506,17 @@ static int cm_calculate_bss_score(struct wlan_objmgr_psoc *psoc, score_config->rssi_score.bad_rssi_bucket_size); vht_cap = (struct wlan_ie_vhtcaps *)util_scan_entry_vhtcap(entry); - if (vht_cap && vht_cap->su_beam_former) + he_cap = (struct wlan_ie_hecaps *)util_scan_entry_hecap(entry); + + if (vht_cap && vht_cap->su_beam_former) { ap_su_beam_former = true; + + } else if (he_cap && QDF_GET_BITS(*(he_cap->he_phy_cap.phy_cap_bytes + + WLAN_HE_PHYCAP_SU_BFER_OFFSET), WLAN_HE_PHYCAP_SU_BFER_IDX, + WLAN_HE_PHYCAP_SU_BFER_BITS)) { + ap_su_beam_former = true; + } + if (phy_config->beamformee_cap && is_vht && ap_su_beam_former && (entry->rssi_raw > rssi_pref_5g_rssi_thresh) && !same_bucket) From 074d28559711535252db6397b2f915c9c2976c46 Mon Sep 17 00:00:00 2001 From: Vinod Kumar Myadam Date: Thu, 16 Feb 2023 18:09:50 +0530 Subject: [PATCH 3/5] qcacmn: Fix out-of-bounds of src_freq When handling WMI_ROAM_SCAN_STATS_EVENTID, the number of channels scanned for each roam trigger is fetched from wmi_roam_scan_info TLV (wmi_roam_scan_info->roam_scan_channel_count), The total number of channels for all the roam triggers is fetched from param_buf->num_roam_scan_chan_info. chan_idx is the index used to fetch the current channel info TLV to be read. So if wmi_roam_scan_info->roam_scan_channel_count provided by firmware exceeds the total param_buf->num_roam_scan_chan_info starting from given chan_idx then OOB access of event buffer can happen. To avoid this, validate the sum of the current chan_idx and src_data->roam_scan_channel_count against evt_buf->num_roam_scan_chan_info. Change-Id: Ied94464d1f12690cf8832962b94595c2e00c33f8 CRs-Fixed: 3357714 --- wmi/src/wmi_unified_tlv.c | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/wmi/src/wmi_unified_tlv.c b/wmi/src/wmi_unified_tlv.c index 3819c3ba6454..1776a8a1d621 100644 --- a/wmi/src/wmi_unified_tlv.c +++ b/wmi/src/wmi_unified_tlv.c @@ -14279,6 +14279,15 @@ extract_roam_scan_stats_tlv(wmi_unified_t wmi_handle, void *evt_buf, dst->num_chan = MAX_ROAM_SCAN_CHAN; src_chan = ¶m_buf->roam_scan_chan_info[chan_idx]; + + if ((dst->num_chan + chan_idx) > + param_buf->num_roam_scan_chan_info) { + wmi_err("Invalid TLV. num_chan %d chan_idx %d num_roam_scan_chan_info %d", + dst->num_chan, chan_idx, + param_buf->num_roam_scan_chan_info); + return QDF_STATUS_SUCCESS; + } + for (i = 0; i < dst->num_chan; i++) { dst->chan_freq[i] = src_chan->channel; src_chan++; @@ -14387,6 +14396,14 @@ extract_roam_11kv_stats_tlv(wmi_unified_t wmi_handle, void *evt_buf, if (dst->num_freq > MAX_ROAM_SCAN_CHAN) dst->num_freq = MAX_ROAM_SCAN_CHAN; + if ((dst->num_freq + rpt_idx) > + param_buf->num_roam_neighbor_report_chan_info) { + wmi_err("Invalid TLV. num_freq %d rpt_idx %d num_roam_neighbor_report_chan_info %d", + dst->num_freq, rpt_idx, + param_buf->num_roam_scan_chan_info); + return QDF_STATUS_SUCCESS; + } + for (i = 0; i < dst->num_freq; i++) { dst->freq[i] = src_freq->channel; src_freq++; From d7687fb293475708f664828d58d83742c3d6366e Mon Sep 17 00:00:00 2001 From: Vinod Kumar Myadam Date: Fri, 3 Mar 2023 12:17:49 +0530 Subject: [PATCH 4/5] qcacmn: Fix OOB in util_gen_new_ie For example, If tmp_new[1] = 3, subie_len=160, tmp_new + tmp_new[1] + MIN_IE_LEN) - sub_copy will be 159. In this scenario, while condition gets true (159 <= 160) In if condition (159 >= 160), we are not breaking the loop in if. tmp_new will get incremented, tmp_new will point at 159, tmp_new[1] will point at 160, tmp_new[2] point at 161. So, we are accessing one byte out-of-bound value. To fix accessing out-of-bound value subtract one from the subie_len in while and if condition to avoid this scenario. Change-Id: I624585323963b6d79acf9ff0f96ec17e0b415c2d CRs-Fixed: 3358833 --- umac/scan/dispatcher/src/wlan_scan_utils_api.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/umac/scan/dispatcher/src/wlan_scan_utils_api.c b/umac/scan/dispatcher/src/wlan_scan_utils_api.c index 66a4555e03aa..c2a7c7f4acff 100644 --- a/umac/scan/dispatcher/src/wlan_scan_utils_api.c +++ b/umac/scan/dispatcher/src/wlan_scan_utils_api.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2021-2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2021-2023 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -2135,7 +2135,7 @@ static uint32_t util_gen_new_ie(uint8_t *ie, uint32_t ielen, */ tmp_new = sub_copy; while (((tmp_new + tmp_new[1] + MIN_IE_LEN) - sub_copy) <= - subie_len) { + (subie_len - 1)) { if (!(tmp_new[0] == WLAN_ELEMID_NONTX_BSSID_CAP || tmp_new[0] == WLAN_ELEMID_SSID || tmp_new[0] == WLAN_ELEMID_MULTI_BSSID_IDX || @@ -2149,7 +2149,7 @@ static uint32_t util_gen_new_ie(uint8_t *ie, uint32_t ielen, } } if (((tmp_new + tmp_new[1] + MIN_IE_LEN) - sub_copy) >= - subie_len) + (subie_len - 1)) break; tmp_new += tmp_new[1] + MIN_IE_LEN; } From c786671eaac52da0f906ac4f6ca24c21afd56424 Mon Sep 17 00:00:00 2001 From: Asutosh Mohapatra Date: Wed, 4 Jan 2023 15:08:17 +0530 Subject: [PATCH 5/5] qcacmn: Add new INI to separate scan policy for rest of world users Currently host drops an AP from scan list if host country is set to US and AP country is non-US. This implementation violates our standard regulatory scan policy. To address this issue, introduce a new INI to differentiate between our standard regulatory policy with others. Change-Id: Id72f871653e31969c4d1b147cb3c557f90a6c8f6 CRs-Fixed: 3361720 --- .../core/src/wlan_cm_bss_scoring.c | 24 +++++++++++++++++ .../dispatcher/inc/wlan_cm_bss_score_param.h | 27 +++++++++++++++++++ umac/scan/core/src/wlan_scan_cache_db.c | 5 ++-- 3 files changed, 54 insertions(+), 2 deletions(-) diff --git a/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c b/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c index 27d70b49ec1f..10b0805bbae6 100644 --- a/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c +++ b/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c @@ -1908,6 +1908,30 @@ bool wlan_cm_get_check_6ghz_security(struct wlan_objmgr_psoc *psoc) return mlme_psoc_obj->psoc_cfg.score_config.check_6ghz_security; } +void wlan_cm_set_standard_6ghz_conn_policy(struct wlan_objmgr_psoc *psoc, + bool value) +{ + struct psoc_mlme_obj *mlme_psoc_obj; + + mlme_psoc_obj = wlan_psoc_mlme_get_cmpt_obj(psoc); + if (!mlme_psoc_obj) + return; + + mlme_debug("6ghz standard connection policy val %x", value); + mlme_psoc_obj->psoc_cfg.score_config.standard_6ghz_conn_policy = value; +} + +bool wlan_cm_get_standard_6ghz_conn_policy(struct wlan_objmgr_psoc *psoc) +{ + struct psoc_mlme_obj *mlme_psoc_obj; + + mlme_psoc_obj = wlan_psoc_mlme_get_cmpt_obj(psoc); + if (!mlme_psoc_obj) + return false; + + return mlme_psoc_obj->psoc_cfg.score_config.standard_6ghz_conn_policy; +} + void wlan_cm_set_6ghz_key_mgmt_mask(struct wlan_objmgr_psoc *psoc, uint32_t value) { diff --git a/umac/mlme/connection_mgr/dispatcher/inc/wlan_cm_bss_score_param.h b/umac/mlme/connection_mgr/dispatcher/inc/wlan_cm_bss_score_param.h index 75d53a564b4e..55388bd0b9d1 100644 --- a/umac/mlme/connection_mgr/dispatcher/inc/wlan_cm_bss_score_param.h +++ b/umac/mlme/connection_mgr/dispatcher/inc/wlan_cm_bss_score_param.h @@ -1,5 +1,6 @@ /* * Copyright (c) 2017-2020, The Linux Foundation. All rights reserved. + * Copyright (c) 2023 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for any * purpose with or without fee is hereby granted, provided that the above @@ -129,6 +130,7 @@ struct per_slot_score { * @check_assoc_disallowed: Should assoc be disallowed if MBO OCE IE indicate so * @vendor_roam_score_algorithm: Preferred ETP vendor roam score algorithm * @check_6ghz_security: check security for 6Ghz candidate + * @standard_6ghz_conn_policy: check for 6 GHz standard connection policy * @key_mgmt_mask_6ghz: user configurable mask for 6ghz AKM */ struct scoring_cfg { @@ -143,6 +145,7 @@ struct scoring_cfg { bool check_assoc_disallowed; bool vendor_roam_score_algorithm; uint8_t check_6ghz_security; + uint8_t standard_6ghz_conn_policy:1; uint32_t key_mgmt_mask_6ghz; }; @@ -291,6 +294,18 @@ void wlan_cm_set_6ghz_key_mgmt_mask(struct wlan_objmgr_psoc *psoc, */ uint32_t wlan_cm_get_6ghz_key_mgmt_mask(struct wlan_objmgr_psoc *psoc); +void wlan_cm_set_standard_6ghz_conn_policy(struct wlan_objmgr_psoc *psoc, + bool value); + +/** + * wlan_cm_get_standard_6ghz_conn_policy() - Get 6Ghz standard connection + * policy + * @psoc: pointer to psoc object + * + * Return: value + */ +bool wlan_cm_get_standard_6ghz_conn_policy(struct wlan_objmgr_psoc *psoc); + #else static inline bool wlan_cm_6ghz_allowed_for_akm(struct wlan_objmgr_psoc *psoc, @@ -314,6 +329,18 @@ bool wlan_cm_get_check_6ghz_security(struct wlan_objmgr_psoc *psoc) return false; } +static inline +void wlan_cm_set_standard_6ghz_conn_policy(struct wlan_objmgr_psoc *psoc, + uint32_t value) +{ +} + +static inline +bool wlan_cm_get_standard_6ghz_conn_policy(struct wlan_objmgr_psoc *psoc) +{ + return false; +} + static inline void wlan_cm_set_6ghz_key_mgmt_mask(struct wlan_objmgr_psoc *psoc, uint32_t value) {} diff --git a/umac/scan/core/src/wlan_scan_cache_db.c b/umac/scan/core/src/wlan_scan_cache_db.c index 229ed22f98f9..8aa4f17942ab 100644 --- a/umac/scan/core/src/wlan_scan_cache_db.c +++ b/umac/scan/core/src/wlan_scan_cache_db.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1166,7 +1166,8 @@ QDF_STATUS __scm_handle_bcn_probe(struct scan_bcn_probe_event *bcn) * enabled. wlan_cm_get_check_6ghz_security API returns true if * neither Safe mode nor RF test mode are enabled. */ - if (!scm_is_bss_allowed_for_country(psoc, scan_entry) && + if (!wlan_cm_get_standard_6ghz_conn_policy(psoc) && + !scm_is_bss_allowed_for_country(psoc, scan_entry) && wlan_cm_get_check_6ghz_security(psoc)) { scm_info_rl( "Drop frame from "QDF_MAC_ADDR_FMT