Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qca-wifi-host-cmn into android13-5.4-lahaina

LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0

* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qca-wifi-host-cmn:
  qcacmn: Validate vdev count before pdev CSA switch count update
  qcacmn: Fix out of bounds read in extract_roam_scan_ap_stats_tlv
  qcacmn: Update is_psd_power logic in reg get client pwr API
  qcacmn: Keep counter atomicity while logging
  qcacmn: Avoid OOB read in reg fill master channel API
  qcacmn: Add macro to determine WPA3 AKM
  qcacmn: Correct RSNXE capability indexes

Change-Id: I99ee7720aa22bc6dcfe52505d883498d767c7f09
This commit is contained in:
Michael Bestas 2026-04-30 21:11:29 +03:00
commit a2d66d3891
No known key found for this signature in database
GPG key ID: CC95044519BE6669
7 changed files with 45 additions and 23 deletions

View file

@ -411,10 +411,19 @@ void qdf_mtrace_log(QDF_MODULE_ID src_module, QDF_MODULE_ID dst_module,
uint16_t message_id, uint8_t vdev_id)
{
uint32_t trace_log, payload;
static uint16_t counter;
static __qdf_atomic_t counter;
static bool initialized = false;
// Initialize counter only once
if (!initialized) {
qdf_atomic_init(&counter);
initialized = true;
}
trace_log = (src_module << 23) | (dst_module << 15) | message_id;
payload = (vdev_id << 16) | counter++;
qdf_atomic_add(1, &counter);
payload = ((uint32_t)vdev_id << 16) | (qdf_atomic_read(&counter) & 0xFFFF);
QDF_TRACE(src_module, QDF_TRACE_LEVEL_TRACE, "%x %x",
trace_log, payload);

View file

@ -1,6 +1,6 @@
/*
* Copyright (c) 2014-2021 The Linux Foundation. All rights reserved.
* Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved.
* Copyright (c) 2022-2023, 2025 Qualcomm Innovation Center, Inc. All rights reserved.
*
* Permission to use, copy, modify, and/or distribute this software for
* any purpose with or without fee is hereby granted, provided that the
@ -2089,6 +2089,11 @@ QDF_STATUS reg_process_master_chan_list_ext(
reg_store_regulatory_ext_info_to_socpriv(soc_reg, regulat_info, phy_id);
if (this_mchan_params->client_type >= REG_MAX_CLIENT_TYPE) {
reg_err("6 GHz reg client type invalid");
return QDF_STATUS_E_FAILURE;
}
status = reg_fill_master_channels(regulat_info,
&this_mchan_params->reg_rules,
this_mchan_params->client_type,

View file

@ -1,6 +1,6 @@
/*
* Copyright (c) 2014-2021 The Linux Foundation. All rights reserved.
* Copyright (c) 2022,2024 Qualcomm Innovation Center, Inc. All rights reserved.
* Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries.
*
* Permission to use, copy, modify, and/or distribute this software for
* any purpose with or without fee is hereby granted, provided that the
@ -5113,7 +5113,7 @@ QDF_STATUS reg_get_6g_chan_ap_power(struct wlan_objmgr_pdev *pdev,
QDF_STATUS reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev,
enum reg_6g_ap_type ap_type,
qdf_freq_t chan_freq,
bool *is_psd,
bool is_psd,
uint16_t *tx_power,
uint16_t *eirp_psd_power)
{
@ -5136,8 +5136,7 @@ QDF_STATUS reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev,
reg_find_txpower_from_6g_list(chan_freq, master_chan_list,
tx_power);
*is_psd = reg_is_6g_psd_power(pdev);
if (*is_psd)
if (is_psd)
status = reg_get_6g_chan_psd_eirp_power(chan_freq,
master_chan_list,
eirp_psd_power);

View file

@ -1,6 +1,6 @@
/*
* Copyright (c) 2017-2021 The Linux Foundation. All rights reserved.
* Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved.
* Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries.
*
*
* Permission to use, copy, modify, and/or distribute this software for
@ -1484,7 +1484,7 @@ QDF_STATUS reg_get_6g_chan_ap_power(struct wlan_objmgr_pdev *pdev,
*
* This function is meant to be called to find the channel frequency power
* information for a client when the device is operating as a client. It will
* fill in the parameter is_psd, tx_power, and eirp_psd_power. eirp_psd_power
* fill in the parameters tx_power and eirp_psd_power. eirp_psd_power
* will only be filled if the channel is PSD.
*
* Return: QDF_STATUS
@ -1492,7 +1492,7 @@ QDF_STATUS reg_get_6g_chan_ap_power(struct wlan_objmgr_pdev *pdev,
QDF_STATUS reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev,
enum reg_6g_ap_type ap_type,
qdf_freq_t chan_freq,
bool *is_psd,
bool is_psd,
uint16_t *tx_power,
uint16_t *eirp_psd_power);
@ -1582,11 +1582,10 @@ static inline
QDF_STATUS reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev,
enum reg_6g_ap_type ap_type,
qdf_freq_t chan_freq,
bool *is_psd,
bool is_psd,
uint16_t *tx_power,
uint16_t *eirp_psd_power)
{
*is_psd = false;
*tx_power = 0;
*eirp_psd_power = 0;
return QDF_STATUS_E_NOSUPPORT;

View file

@ -1,6 +1,6 @@
/*
* Copyright (c) 2017-2021 The Linux Foundation. All rights reserved.
* Copyright (c) 2021-2024 Qualcomm Innovation Center, Inc. All rights reserved.
* Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries.
*
* Permission to use, copy, modify, and/or distribute this software for
* any purpose with or without fee is hereby granted, provided that the
@ -1869,8 +1869,8 @@ QDF_STATUS wlan_reg_get_6g_chan_ap_power(struct wlan_objmgr_pdev *pdev,
*
* This function is meant to be called to find the channel frequency power
* information for a client when the device is operating as a client. It will
* fill in the parameter is_psd, tx_power, and eirp_psd_power. eirp_psd_power
* will only be filled if the channel is PSD.
* fill in the parameters tx_power and eirp_psd_power. eirp_psd_power will
* only be filled if the channel is PSD.
*
* Return: QDF_STATUS
*/
@ -1878,7 +1878,7 @@ QDF_STATUS
wlan_reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev,
enum reg_6g_ap_type ap_type,
qdf_freq_t chan_freq,
bool *is_psd, uint16_t *tx_power,
bool is_psd, uint16_t *tx_power,
uint16_t *eirp_psd_power);
/**
@ -1985,10 +1985,9 @@ static inline QDF_STATUS
wlan_reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev,
enum reg_6g_ap_type ap_type,
qdf_freq_t chan_freq,
bool *is_psd, uint16_t *tx_power,
bool is_psd, uint16_t *tx_power,
uint16_t *eirp_psd_power)
{
*is_psd = false;
*tx_power = 0;
*eirp_psd_power = 0;
return QDF_STATUS_E_NOSUPPORT;

View file

@ -1,6 +1,6 @@
/*
* Copyright (c) 2017-2021 The Linux Foundation. All rights reserved.
* Copyright (c) 2021-2024 Qualcomm Innovation Center, Inc. All rights reserved.
* Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries.
*
*
* Permission to use, copy, modify, and/or distribute this software for
@ -1443,7 +1443,7 @@ QDF_STATUS
wlan_reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev,
enum reg_6g_ap_type ap_type,
qdf_freq_t chan_freq,
bool *is_psd, uint16_t *tx_power,
bool is_psd, uint16_t *tx_power,
uint16_t *eirp_psd_power)
{
return reg_get_client_power_for_connecting_ap(pdev, ap_type, chan_freq,

View file

@ -14208,9 +14208,14 @@ extract_roam_scan_ap_stats_tlv(wmi_unified_t wmi_handle, void *evt_buf,
return QDF_STATUS_E_FAILURE;
}
if (ap_idx >= param_buf->num_roam_ap_info) {
wmi_err("Invalid roam scan AP tlv ap_idx:%d total_ap:%d",
ap_idx, param_buf->num_roam_ap_info);
/*
* Check to validate that the requested number of APs do not exceed the
* remaining APs in param_buf after ap_idx to prevent out of bounds
* access.
*/
if ((ap_idx + num_cand) > param_buf->num_roam_ap_info) {
wmi_err("Invalid roam scan AP tlv ap_idx:%d, num_cand:%d, total_ap:%d",
ap_idx, num_cand, param_buf->num_roam_ap_info);
return QDF_STATUS_E_FAILURE;
}
@ -14724,6 +14729,12 @@ static QDF_STATUS extract_pdev_csa_switch_count_status_tlv(
wmi_handle,
csa_status->pdev_id);
param->current_switch_count = csa_status->current_switch_count;
if (param_buf->num_vdev_ids != csa_status->num_vdevs) {
wmi_err("Invalid number of vdevs: received = %d, expected = %d",
csa_status->num_vdevs, param_buf->num_vdev_ids);
return QDF_STATUS_E_INVAL;
}
param->num_vdevs = csa_status->num_vdevs;
param->vdev_ids = param_buf->vdev_ids;