From 9567459a4e79f22953dbebe2c62cf54c9383d309 Mon Sep 17 00:00:00 2001 From: Surya Prakash Sivaraj Date: Tue, 19 Mar 2024 15:55:28 +0530 Subject: [PATCH 1/7] qcacmn: Correct RSNXE capability indexes Currently, RSNXE capability indexes are defined incorrect. It seems BIT index is misinterpreted. Correct the same as defined below in spec(IEEE Std 802.11-2020, 9.4.2.241, Table 9-780). The Extended RSN Capabilities field, except its first 4 bits, is a bit field indicating the extended RSN capabilities being advertised by the STA transmitting the element. The length of the Extended RSN Capabilities field is a variable n, in octets, as indicated by the first 4 bits in the field. Also, add a macro to check if the given akm is WPA/WPA2 i.e. legacy than WPA3. Change-Id: I3d8eee15f6734b2364628f699b7829a1edb246f0 CRs-Fixed: 3257715 (cherry picked from commit ab3c4a8142a555742094118d49c29285d80b18b5) --- .../crypto/inc/wlan_crypto_global_def.h | 20 +++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h b/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h index d5f386bef272..0ba235650b4d 100644 --- a/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h +++ b/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h @@ -493,4 +493,24 @@ struct wlan_lmac_if_crypto_rx_ops { #define WLAN_CRYPTO_RX_OPS_SET_PEER_WEP_KEYS(crypto_rx_ops) \ (crypto_rx_ops->set_peer_wep_keys) +#define WLAN_CRYPTO_IS_WPA_WPA2(akm) \ + (QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_PSK) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_PSK) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SHA256) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_PSK_SHA256) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_WPS) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_WAPI_PSK) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_WAPI_CERT) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_CCKM) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_OSEN) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FILS_SHA256) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FILS_SHA384) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA256) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA384) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_PSK_SHA384) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_PSK_SHA384)) + #endif /* end of _WLAN_CRYPTO_GLOBAL_DEF_H_ */ From 2c029ff90739a5a301203088f3110efd61072356 Mon Sep 17 00:00:00 2001 From: Surya Prakash Sivaraj Date: Tue, 19 Mar 2024 15:56:34 +0530 Subject: [PATCH 2/7] qcacmn: Add macro to determine WPA3 AKM Add a macro to determine if a particular AKM is WPA3-based AKM. Change-Id: I9b3f546e2e0f69281305ca9052dc109fb6812e21 CRs-Fixed: 3418837 (cherry picked from commit 389a047ba7c9e4c0f57cfd52f41fcbcf37fe85a6) --- umac/cmn_services/crypto/inc/wlan_crypto_global_def.h | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h b/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h index 0ba235650b4d..74d047350ac6 100644 --- a/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h +++ b/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h @@ -513,4 +513,11 @@ struct wlan_lmac_if_crypto_rx_ops { QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_PSK_SHA384) || \ QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_PSK_SHA384)) +#define WLAN_CRYPTO_IS_WPA3(akm) \ + (QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_SAE) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_SAE) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B_192) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_OWE) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_DPP) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384)) #endif /* end of _WLAN_CRYPTO_GLOBAL_DEF_H_ */ From c0dcb8d4a30318c67f716adac73fa6f9b0cd36d1 Mon Sep 17 00:00:00 2001 From: Gururaj Pandurangi Date: Thu, 6 Feb 2025 18:27:21 -0800 Subject: [PATCH 3/7] qcacmn: Avoid OOB read in reg fill master channel API Avoid OOB read by adding sanity check for 6 GHz regulatory client type before invoking reg_fill_master_channels API. CRs-Fixed: 4046668 Change-Id: Ief959940e3470b5341d3188ac558475dc8d7fee1 --- umac/regulatory/core/src/reg_build_chan_list.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/umac/regulatory/core/src/reg_build_chan_list.c b/umac/regulatory/core/src/reg_build_chan_list.c index 6059b406d57b..40959dbe6df2 100644 --- a/umac/regulatory/core/src/reg_build_chan_list.c +++ b/umac/regulatory/core/src/reg_build_chan_list.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2014-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2023, 2025 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -2089,6 +2089,11 @@ QDF_STATUS reg_process_master_chan_list_ext( reg_store_regulatory_ext_info_to_socpriv(soc_reg, regulat_info, phy_id); + if (this_mchan_params->client_type >= REG_MAX_CLIENT_TYPE) { + reg_err("6 GHz reg client type invalid"); + return QDF_STATUS_E_FAILURE; + } + status = reg_fill_master_channels(regulat_info, &this_mchan_params->reg_rules, this_mchan_params->client_type, From 312ae55c1fe5ae849f1bdab8050dad30e08885ca Mon Sep 17 00:00:00 2001 From: Sheenam Monga Date: Wed, 21 May 2025 13:26:16 +0530 Subject: [PATCH 4/7] qcacmn: Keep counter atomicity while logging Currently, there might be a case logging counter is incremented by one thread and used by another thread which can cause issue because payload is fetched from counter. To avoid above issue keep atomicity while incrementing the counter. CRs-Fixed: 4153670 Change-Id: I417b63df8da72918a830a1f8fe7a574bab549ea8 (cherry picked from commit 0ace5b3611f7b164f61c355909a165bf716440b7) --- qdf/linux/src/qdf_trace.c | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/qdf/linux/src/qdf_trace.c b/qdf/linux/src/qdf_trace.c index 0b3e2dbd150d..30815cb19d89 100644 --- a/qdf/linux/src/qdf_trace.c +++ b/qdf/linux/src/qdf_trace.c @@ -411,10 +411,19 @@ void qdf_mtrace_log(QDF_MODULE_ID src_module, QDF_MODULE_ID dst_module, uint16_t message_id, uint8_t vdev_id) { uint32_t trace_log, payload; - static uint16_t counter; + static __qdf_atomic_t counter; + static bool initialized = false; + + // Initialize counter only once + if (!initialized) { + qdf_atomic_init(&counter); + initialized = true; + } trace_log = (src_module << 23) | (dst_module << 15) | message_id; - payload = (vdev_id << 16) | counter++; + + qdf_atomic_add(1, &counter); + payload = ((uint32_t)vdev_id << 16) | (qdf_atomic_read(&counter) & 0xFFFF); QDF_TRACE(src_module, QDF_TRACE_LEVEL_TRACE, "%x %x", trace_log, payload); From 7a8fb28e048a0b781fbaa02207977901c83676db Mon Sep 17 00:00:00 2001 From: Surya Prakash Sivaraj Date: Mon, 15 Aug 2022 17:47:09 -0700 Subject: [PATCH 5/7] qcacmn: Update is_psd_power logic in reg get client pwr API Currently, the reg_get_client_power_for_connecting_ap() API populates is_psd_power flag within the function and uses it as a check to further populate EIRP power. The is_psd_power flag is derived from current channel list chan flag which returns true if corresponding channel supports PSD power. Normally, all 6 GHz channels support PSD, so this flag is usually set to 1. But, AP can transmit EIRP power in TPE IE for 6 GHz channels, thus for MCC specific cases, derive this flag based on tx_power interpretation field in TPE IE for accurate value. WIN Host can still use reg_is_6g_psd_power() to retrieve the flag in the caller APIs. Hence, derive is_psd_power flag from TPE IE interpretation value beforehand and pass it as an argument to reg_get_client_power_for_connecting_ap() API. Change-Id: Iabbcbd003f441151643a087ad4908bcdaed753a5 CRs-Fixed: 3268118 --- umac/regulatory/core/src/reg_services_common.c | 7 +++---- umac/regulatory/core/src/reg_services_common.h | 9 ++++----- .../regulatory/dispatcher/inc/wlan_reg_services_api.h | 11 +++++------ .../regulatory/dispatcher/src/wlan_reg_services_api.c | 4 ++-- 4 files changed, 14 insertions(+), 17 deletions(-) diff --git a/umac/regulatory/core/src/reg_services_common.c b/umac/regulatory/core/src/reg_services_common.c index 4678269ed294..877d31d91142 100644 --- a/umac/regulatory/core/src/reg_services_common.c +++ b/umac/regulatory/core/src/reg_services_common.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2014-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2022,2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -5112,7 +5112,7 @@ QDF_STATUS reg_get_6g_chan_ap_power(struct wlan_objmgr_pdev *pdev, QDF_STATUS reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev, enum reg_6g_ap_type ap_type, qdf_freq_t chan_freq, - bool *is_psd, + bool is_psd, uint16_t *tx_power, uint16_t *eirp_psd_power) { @@ -5135,8 +5135,7 @@ QDF_STATUS reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev, reg_find_txpower_from_6g_list(chan_freq, master_chan_list, tx_power); - *is_psd = reg_is_6g_psd_power(pdev); - if (*is_psd) + if (is_psd) status = reg_get_6g_chan_psd_eirp_power(chan_freq, master_chan_list, eirp_psd_power); diff --git a/umac/regulatory/core/src/reg_services_common.h b/umac/regulatory/core/src/reg_services_common.h index c0d478ea1887..3a94a215298a 100644 --- a/umac/regulatory/core/src/reg_services_common.h +++ b/umac/regulatory/core/src/reg_services_common.h @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * * Permission to use, copy, modify, and/or distribute this software for @@ -1484,7 +1484,7 @@ QDF_STATUS reg_get_6g_chan_ap_power(struct wlan_objmgr_pdev *pdev, * * This function is meant to be called to find the channel frequency power * information for a client when the device is operating as a client. It will - * fill in the parameter is_psd, tx_power, and eirp_psd_power. eirp_psd_power + * fill in the parameters tx_power and eirp_psd_power. eirp_psd_power * will only be filled if the channel is PSD. * * Return: QDF_STATUS @@ -1492,7 +1492,7 @@ QDF_STATUS reg_get_6g_chan_ap_power(struct wlan_objmgr_pdev *pdev, QDF_STATUS reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev, enum reg_6g_ap_type ap_type, qdf_freq_t chan_freq, - bool *is_psd, + bool is_psd, uint16_t *tx_power, uint16_t *eirp_psd_power); @@ -1582,11 +1582,10 @@ static inline QDF_STATUS reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev, enum reg_6g_ap_type ap_type, qdf_freq_t chan_freq, - bool *is_psd, + bool is_psd, uint16_t *tx_power, uint16_t *eirp_psd_power) { - *is_psd = false; *tx_power = 0; *eirp_psd_power = 0; return QDF_STATUS_E_NOSUPPORT; diff --git a/umac/regulatory/dispatcher/inc/wlan_reg_services_api.h b/umac/regulatory/dispatcher/inc/wlan_reg_services_api.h index d8c7ad95a133..c380a077abe5 100644 --- a/umac/regulatory/dispatcher/inc/wlan_reg_services_api.h +++ b/umac/regulatory/dispatcher/inc/wlan_reg_services_api.h @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2021-2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1869,8 +1869,8 @@ QDF_STATUS wlan_reg_get_6g_chan_ap_power(struct wlan_objmgr_pdev *pdev, * * This function is meant to be called to find the channel frequency power * information for a client when the device is operating as a client. It will - * fill in the parameter is_psd, tx_power, and eirp_psd_power. eirp_psd_power - * will only be filled if the channel is PSD. + * fill in the parameters tx_power and eirp_psd_power. eirp_psd_power will + * only be filled if the channel is PSD. * * Return: QDF_STATUS */ @@ -1878,7 +1878,7 @@ QDF_STATUS wlan_reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev, enum reg_6g_ap_type ap_type, qdf_freq_t chan_freq, - bool *is_psd, uint16_t *tx_power, + bool is_psd, uint16_t *tx_power, uint16_t *eirp_psd_power); /** @@ -1985,10 +1985,9 @@ static inline QDF_STATUS wlan_reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev, enum reg_6g_ap_type ap_type, qdf_freq_t chan_freq, - bool *is_psd, uint16_t *tx_power, + bool is_psd, uint16_t *tx_power, uint16_t *eirp_psd_power) { - *is_psd = false; *tx_power = 0; *eirp_psd_power = 0; return QDF_STATUS_E_NOSUPPORT; diff --git a/umac/regulatory/dispatcher/src/wlan_reg_services_api.c b/umac/regulatory/dispatcher/src/wlan_reg_services_api.c index 2b720dee6ca6..7d458f0421fc 100644 --- a/umac/regulatory/dispatcher/src/wlan_reg_services_api.c +++ b/umac/regulatory/dispatcher/src/wlan_reg_services_api.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2021-2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * * * Permission to use, copy, modify, and/or distribute this software for @@ -1443,7 +1443,7 @@ QDF_STATUS wlan_reg_get_client_power_for_connecting_ap(struct wlan_objmgr_pdev *pdev, enum reg_6g_ap_type ap_type, qdf_freq_t chan_freq, - bool *is_psd, uint16_t *tx_power, + bool is_psd, uint16_t *tx_power, uint16_t *eirp_psd_power) { return reg_get_client_power_for_connecting_ap(pdev, ap_type, chan_freq, From a676bd5e81d78c678a77f4933d82ab095cf51aab Mon Sep 17 00:00:00 2001 From: Akshay Mohite Date: Mon, 21 Jul 2025 20:11:04 +0530 Subject: [PATCH 6/7] qcacmn: Fix out of bounds read in extract_roam_scan_ap_stats_tlv In API extract_roam_scan_ap_stats_tlv(), for loop is implemented to extract AP info from a param_buf structure and store it in a dst buffer starting from index value ap_idx. The loop iterates num_cand times, where num_cand is the number of candidate APs to be extracted. However, the issue arises when the num_cand value exceeds the remaining number of APs in the param_buf structure, starting from the ap_idx index. This can cause the loop to access memory outside the bounds of the param_buf structure. To fix this, add a check before the for loop to ensure that the num_cand value does not exceed the remaining number of APs in the param_buf structure,starting from the ap_idx index. CRs-Fixed: 4218517 Change-Id: I46504dfd17da652fddd0bcea2f3f062420b3a9ff --- wmi/src/wmi_unified_tlv.c | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/wmi/src/wmi_unified_tlv.c b/wmi/src/wmi_unified_tlv.c index cd998b35ca7e..269c45b65a74 100644 --- a/wmi/src/wmi_unified_tlv.c +++ b/wmi/src/wmi_unified_tlv.c @@ -14208,9 +14208,14 @@ extract_roam_scan_ap_stats_tlv(wmi_unified_t wmi_handle, void *evt_buf, return QDF_STATUS_E_FAILURE; } - if (ap_idx >= param_buf->num_roam_ap_info) { - wmi_err("Invalid roam scan AP tlv ap_idx:%d total_ap:%d", - ap_idx, param_buf->num_roam_ap_info); + /* + * Check to validate that the requested number of APs do not exceed the + * remaining APs in param_buf after ap_idx to prevent out of bounds + * access. + */ + if ((ap_idx + num_cand) > param_buf->num_roam_ap_info) { + wmi_err("Invalid roam scan AP tlv ap_idx:%d, num_cand:%d, total_ap:%d", + ap_idx, num_cand, param_buf->num_roam_ap_info); return QDF_STATUS_E_FAILURE; } From 47c8aa7cad489faf1bdb65fe878a31384a0d017a Mon Sep 17 00:00:00 2001 From: amaindol Date: Tue, 22 Jul 2025 15:51:46 +0530 Subject: [PATCH 7/7] qcacmn: Validate vdev count before pdev CSA switch count update The num of vdevs parameter of the pdev csa switch count TLV is a tainted value and is not checked before use. Invalid values can cause a slab out of bound error, which results in a crash. Add a check for the num of vdevs while extracting pdev csa switch count TLV. Compare the number of vdevs with the num of vdev ids parameter of the csa switch count firmware event. Drop the event if the check fails. CRs-Fixed: 4217096 Change-Id: I88401984437186a1a6e077c274d0011fa93e8704 --- wmi/src/wmi_unified_tlv.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/wmi/src/wmi_unified_tlv.c b/wmi/src/wmi_unified_tlv.c index 269c45b65a74..b9359e099ce6 100644 --- a/wmi/src/wmi_unified_tlv.c +++ b/wmi/src/wmi_unified_tlv.c @@ -14729,6 +14729,12 @@ static QDF_STATUS extract_pdev_csa_switch_count_status_tlv( wmi_handle, csa_status->pdev_id); param->current_switch_count = csa_status->current_switch_count; + + if (param_buf->num_vdev_ids != csa_status->num_vdevs) { + wmi_err("Invalid number of vdevs: received = %d, expected = %d", + csa_status->num_vdevs, param_buf->num_vdev_ids); + return QDF_STATUS_E_INVAL; + } param->num_vdevs = csa_status->num_vdevs; param->vdev_ids = param_buf->vdev_ids;