diff --git a/drivers/staging/qca-wifi-host-cmn/qdf/linux/src/qdf_trace.c b/drivers/staging/qca-wifi-host-cmn/qdf/linux/src/qdf_trace.c index 0b3e2dbd150d..30815cb19d89 100644 --- a/drivers/staging/qca-wifi-host-cmn/qdf/linux/src/qdf_trace.c +++ b/drivers/staging/qca-wifi-host-cmn/qdf/linux/src/qdf_trace.c @@ -411,10 +411,19 @@ void qdf_mtrace_log(QDF_MODULE_ID src_module, QDF_MODULE_ID dst_module, uint16_t message_id, uint8_t vdev_id) { uint32_t trace_log, payload; - static uint16_t counter; + static __qdf_atomic_t counter; + static bool initialized = false; + + // Initialize counter only once + if (!initialized) { + qdf_atomic_init(&counter); + initialized = true; + } trace_log = (src_module << 23) | (dst_module << 15) | message_id; - payload = (vdev_id << 16) | counter++; + + qdf_atomic_add(1, &counter); + payload = ((uint32_t)vdev_id << 16) | (qdf_atomic_read(&counter) & 0xFFFF); QDF_TRACE(src_module, QDF_TRACE_LEVEL_TRACE, "%x %x", trace_log, payload); diff --git a/drivers/staging/qca-wifi-host-cmn/umac/regulatory/core/src/reg_build_chan_list.c b/drivers/staging/qca-wifi-host-cmn/umac/regulatory/core/src/reg_build_chan_list.c index 6059b406d57b..40959dbe6df2 100644 --- a/drivers/staging/qca-wifi-host-cmn/umac/regulatory/core/src/reg_build_chan_list.c +++ b/drivers/staging/qca-wifi-host-cmn/umac/regulatory/core/src/reg_build_chan_list.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2014-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2023, 2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -2089,6 +2089,11 @@ QDF_STATUS reg_process_master_chan_list_ext( reg_store_regulatory_ext_info_to_socpriv(soc_reg, regulat_info, phy_id); + if (this_mchan_params->client_type >= REG_MAX_CLIENT_TYPE) { + reg_err("6 GHz reg client type invalid"); + return QDF_STATUS_E_FAILURE; + } + status = reg_fill_master_channels(regulat_info, &this_mchan_params->reg_rules, this_mchan_params->client_type, diff --git a/drivers/staging/qca-wifi-host-cmn/umac/regulatory/core/src/reg_services_common.c b/drivers/staging/qca-wifi-host-cmn/umac/regulatory/core/src/reg_services_common.c index 7732e35b5ee4..328a4898dcd1 100644 --- a/drivers/staging/qca-wifi-host-cmn/umac/regulatory/core/src/reg_services_common.c +++ b/drivers/staging/qca-wifi-host-cmn/umac/regulatory/core/src/reg_services_common.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2014-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2022,2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -5113,7 +5113,7 @@ QDF_STATUS reg_get_6g_chan_ap_power(struct wlan_objmgr_pdev *pdev, QDF_STATUS reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev, enum reg_6g_ap_type ap_type, qdf_freq_t chan_freq, - bool *is_psd, + bool is_psd, uint16_t *tx_power, uint16_t *eirp_psd_power) { @@ -5136,8 +5136,7 @@ QDF_STATUS reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev, reg_find_txpower_from_6g_list(chan_freq, master_chan_list, tx_power); - *is_psd = reg_is_6g_psd_power(pdev); - if (*is_psd) + if (is_psd) status = reg_get_6g_chan_psd_eirp_power(chan_freq, master_chan_list, eirp_psd_power); diff --git a/drivers/staging/qca-wifi-host-cmn/umac/regulatory/core/src/reg_services_common.h b/drivers/staging/qca-wifi-host-cmn/umac/regulatory/core/src/reg_services_common.h index c0d478ea1887..3a94a215298a 100644 --- a/drivers/staging/qca-wifi-host-cmn/umac/regulatory/core/src/reg_services_common.h +++ b/drivers/staging/qca-wifi-host-cmn/umac/regulatory/core/src/reg_services_common.h @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * * Permission to use, copy, modify, and/or distribute this software for @@ -1484,7 +1484,7 @@ QDF_STATUS reg_get_6g_chan_ap_power(struct wlan_objmgr_pdev *pdev, * * This function is meant to be called to find the channel frequency power * information for a client when the device is operating as a client. It will - * fill in the parameter is_psd, tx_power, and eirp_psd_power. eirp_psd_power + * fill in the parameters tx_power and eirp_psd_power. eirp_psd_power * will only be filled if the channel is PSD. * * Return: QDF_STATUS @@ -1492,7 +1492,7 @@ QDF_STATUS reg_get_6g_chan_ap_power(struct wlan_objmgr_pdev *pdev, QDF_STATUS reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev, enum reg_6g_ap_type ap_type, qdf_freq_t chan_freq, - bool *is_psd, + bool is_psd, uint16_t *tx_power, uint16_t *eirp_psd_power); @@ -1582,11 +1582,10 @@ static inline QDF_STATUS reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev, enum reg_6g_ap_type ap_type, qdf_freq_t chan_freq, - bool *is_psd, + bool is_psd, uint16_t *tx_power, uint16_t *eirp_psd_power) { - *is_psd = false; *tx_power = 0; *eirp_psd_power = 0; return QDF_STATUS_E_NOSUPPORT; diff --git a/drivers/staging/qca-wifi-host-cmn/umac/regulatory/dispatcher/inc/wlan_reg_services_api.h b/drivers/staging/qca-wifi-host-cmn/umac/regulatory/dispatcher/inc/wlan_reg_services_api.h index d8c7ad95a133..c380a077abe5 100644 --- a/drivers/staging/qca-wifi-host-cmn/umac/regulatory/dispatcher/inc/wlan_reg_services_api.h +++ b/drivers/staging/qca-wifi-host-cmn/umac/regulatory/dispatcher/inc/wlan_reg_services_api.h @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2021-2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1869,8 +1869,8 @@ QDF_STATUS wlan_reg_get_6g_chan_ap_power(struct wlan_objmgr_pdev *pdev, * * This function is meant to be called to find the channel frequency power * information for a client when the device is operating as a client. It will - * fill in the parameter is_psd, tx_power, and eirp_psd_power. eirp_psd_power - * will only be filled if the channel is PSD. + * fill in the parameters tx_power and eirp_psd_power. eirp_psd_power will + * only be filled if the channel is PSD. * * Return: QDF_STATUS */ @@ -1878,7 +1878,7 @@ QDF_STATUS wlan_reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev, enum reg_6g_ap_type ap_type, qdf_freq_t chan_freq, - bool *is_psd, uint16_t *tx_power, + bool is_psd, uint16_t *tx_power, uint16_t *eirp_psd_power); /** @@ -1985,10 +1985,9 @@ static inline QDF_STATUS wlan_reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev, enum reg_6g_ap_type ap_type, qdf_freq_t chan_freq, - bool *is_psd, uint16_t *tx_power, + bool is_psd, uint16_t *tx_power, uint16_t *eirp_psd_power) { - *is_psd = false; *tx_power = 0; *eirp_psd_power = 0; return QDF_STATUS_E_NOSUPPORT; diff --git a/drivers/staging/qca-wifi-host-cmn/umac/regulatory/dispatcher/src/wlan_reg_services_api.c b/drivers/staging/qca-wifi-host-cmn/umac/regulatory/dispatcher/src/wlan_reg_services_api.c index 2b720dee6ca6..7d458f0421fc 100644 --- a/drivers/staging/qca-wifi-host-cmn/umac/regulatory/dispatcher/src/wlan_reg_services_api.c +++ b/drivers/staging/qca-wifi-host-cmn/umac/regulatory/dispatcher/src/wlan_reg_services_api.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2021-2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * * Permission to use, copy, modify, and/or distribute this software for @@ -1443,7 +1443,7 @@ QDF_STATUS wlan_reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev, enum reg_6g_ap_type ap_type, qdf_freq_t chan_freq, - bool *is_psd, uint16_t *tx_power, + bool is_psd, uint16_t *tx_power, uint16_t *eirp_psd_power) { return reg_get_client_power_for_connecting_ap(pdev, ap_type, chan_freq, diff --git a/drivers/staging/qca-wifi-host-cmn/wmi/src/wmi_unified_tlv.c b/drivers/staging/qca-wifi-host-cmn/wmi/src/wmi_unified_tlv.c index cd998b35ca7e..b9359e099ce6 100644 --- a/drivers/staging/qca-wifi-host-cmn/wmi/src/wmi_unified_tlv.c +++ b/drivers/staging/qca-wifi-host-cmn/wmi/src/wmi_unified_tlv.c @@ -14208,9 +14208,14 @@ extract_roam_scan_ap_stats_tlv(wmi_unified_t wmi_handle, void *evt_buf, return QDF_STATUS_E_FAILURE; } - if (ap_idx >= param_buf->num_roam_ap_info) { - wmi_err("Invalid roam scan AP tlv ap_idx:%d total_ap:%d", - ap_idx, param_buf->num_roam_ap_info); + /* + * Check to validate that the requested number of APs do not exceed the + * remaining APs in param_buf after ap_idx to prevent out of bounds + * access. + */ + if ((ap_idx + num_cand) > param_buf->num_roam_ap_info) { + wmi_err("Invalid roam scan AP tlv ap_idx:%d, num_cand:%d, total_ap:%d", + ap_idx, num_cand, param_buf->num_roam_ap_info); return QDF_STATUS_E_FAILURE; } @@ -14724,6 +14729,12 @@ static QDF_STATUS extract_pdev_csa_switch_count_status_tlv( wmi_handle, csa_status->pdev_id); param->current_switch_count = csa_status->current_switch_count; + + if (param_buf->num_vdev_ids != csa_status->num_vdevs) { + wmi_err("Invalid number of vdevs: received = %d, expected = %d", + csa_status->num_vdevs, param_buf->num_vdev_ids); + return QDF_STATUS_E_INVAL; + } param->num_vdevs = csa_status->num_vdevs; param->vdev_ids = param_buf->vdev_ids;