From 3c83a1d00d47ec0e30beb514222f9af900528477 Mon Sep 17 00:00:00 2001 From: Balaji Pothunoori Date: Mon, 24 Apr 2023 22:19:54 +0530 Subject: [PATCH 1/5] qcacmn: Extract Rx data packet SGI from WMI_VDEV_SMART_MONITOR_EVENTID Due to limitation uCode always filling SGI as long for VHT mode in rx_msdu_start_tlv. This change is to extract VHT Rx data packet SGI from WMI_VDEV_SMART_MONITOR_EVENTID. Change-Id: I5fcdc463ea2a6d83253e39cc377a2471aeb4e122 CRs-Fixed: 3477303 --- wmi/src/wmi_unified_tlv.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/wmi/src/wmi_unified_tlv.c b/wmi/src/wmi_unified_tlv.c index 1776a8a1d621..2ceae231bc5d 100644 --- a/wmi/src/wmi_unified_tlv.c +++ b/wmi/src/wmi_unified_tlv.c @@ -14539,7 +14539,7 @@ extract_smart_monitor_event_tlv(void *handle, void *evt_buf, if (params->vdev_id >= WLAN_UMAC_PDEV_MAX_VDEVS) return QDF_STATUS_E_INVAL; - params->rx_avg_rssi = smu_event->avg_rssi_data_dbm; + params->rx_vht_sgi = smu_event->rx_vht_sgi; return QDF_STATUS_SUCCESS; } From 2420399667dae31d652967eaac778ee1c03a257f Mon Sep 17 00:00:00 2001 From: Venkateswara Naralasetty Date: Wed, 2 Aug 2023 16:01:01 +0530 Subject: [PATCH 2/5] qcacmn: add new counter to fisa stats Add a new counter inccorect_rdi to fisa stats to log incorrect reo destination indications in fisa processing. Change-Id: I785ad90ae1d36b2f6b9b1888373a29fcbd65348e CRs-Fixed: 3426537 --- dp/wifi3.0/dp_types.h | 1 + 1 file changed, 1 insertion(+) diff --git a/dp/wifi3.0/dp_types.h b/dp/wifi3.0/dp_types.h index ed8306bc8b3b..25ba47531cd1 100644 --- a/dp/wifi3.0/dp_types.h +++ b/dp/wifi3.0/dp_types.h @@ -3138,6 +3138,7 @@ struct dp_fisa_stats { /* flow index invalid from RX HW TLV */ uint32_t invalid_flow_index; uint32_t reo_mismatch; + uint32_t incorrect_rdi; }; enum fisa_aggr_ret { From a3fd923c0de8baa43f931459b2e3a94254cdc965 Mon Sep 17 00:00:00 2001 From: Guru Pratap Sharma Date: Fri, 11 Aug 2023 00:13:30 -0700 Subject: [PATCH 3/5] qcacmn: handle integer underflow in util_gen_new_ie Handle integer underflow for subie_len in util_gen_new_ie Change-Id: I2f73e5a7e0462100deae1e85e6a51f77bfc46b95 CRs-Fixed: 3582487 --- umac/scan/dispatcher/src/wlan_scan_utils_api.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/umac/scan/dispatcher/src/wlan_scan_utils_api.c b/umac/scan/dispatcher/src/wlan_scan_utils_api.c index c2a7c7f4acff..b6deba111005 100644 --- a/umac/scan/dispatcher/src/wlan_scan_utils_api.c +++ b/umac/scan/dispatcher/src/wlan_scan_utils_api.c @@ -2134,8 +2134,9 @@ static uint32_t util_gen_new_ie(uint8_t *ie, uint32_t ielen, * copied to new ie, skip ssid, capability, bssid-index ie */ tmp_new = sub_copy; - while (((tmp_new + tmp_new[1] + MIN_IE_LEN) - sub_copy) <= - (subie_len - 1)) { + while ((subie_len > 0) && + (((tmp_new + tmp_new[1] + MIN_IE_LEN) - sub_copy) <= + (subie_len - 1))) { if (!(tmp_new[0] == WLAN_ELEMID_NONTX_BSSID_CAP || tmp_new[0] == WLAN_ELEMID_SSID || tmp_new[0] == WLAN_ELEMID_MULTI_BSSID_IDX || From 61edca871f5d4e07b734b42526018bfc0449c9e4 Mon Sep 17 00:00:00 2001 From: Shwetha Goravanahalli Kemparaju Date: Mon, 25 Sep 2023 13:35:11 +0530 Subject: [PATCH 4/5] qcacmn: Fix OOB issue Changes to fix OOB issue seen util_scan_parse_beacon_frame. CRs-Fixed: 3582496 Change-Id: I53244be54d31e87b55d0b44ce94315c8001f417d --- .../cmn_defs/inc/wlan_cmn_ieee80211.h | 4 +++ .../scan/dispatcher/src/wlan_scan_utils_api.c | 25 +++++++++++++------ 2 files changed, 22 insertions(+), 7 deletions(-) diff --git a/umac/cmn_services/cmn_defs/inc/wlan_cmn_ieee80211.h b/umac/cmn_services/cmn_defs/inc/wlan_cmn_ieee80211.h index d519f3396ac1..f4ccb035f530 100644 --- a/umac/cmn_services/cmn_defs/inc/wlan_cmn_ieee80211.h +++ b/umac/cmn_services/cmn_defs/inc/wlan_cmn_ieee80211.h @@ -205,6 +205,10 @@ #define WLAN_MAX_HEOP_IE_LEN 16 #define WLAN_HEOP_OUI_TYPE "\x24" #define WLAN_HEOP_OUI_SIZE 1 +#define WLAN_MIN_HECAP_IE_LEN 22 +#define WLAN_MAX_HECAP_IE_LEN 55 +#define WLAN_HE_MCS_MAP_LEN 2 +#define WLAN_INVALID_RX_MCS_MAP 0xFFFF #define WLAN_HEOP_FIXED_PARAM_LENGTH 7 #define WLAN_HEOP_VHTOP_LENGTH 3 diff --git a/umac/scan/dispatcher/src/wlan_scan_utils_api.c b/umac/scan/dispatcher/src/wlan_scan_utils_api.c index b6deba111005..49be228eac36 100644 --- a/umac/scan/dispatcher/src/wlan_scan_utils_api.c +++ b/umac/scan/dispatcher/src/wlan_scan_utils_api.c @@ -789,6 +789,9 @@ util_scan_parse_extn_ie(struct scan_cache_entry *scan_params, scan_params->ie_list.srp = (uint8_t *)ie; break; case WLAN_EXTN_ELEMID_HECAP: + if ((extn_ie->ie_len < WLAN_MIN_HECAP_IE_LEN) || + (extn_ie->ie_len > WLAN_MAX_HECAP_IE_LEN)) + return QDF_STATUS_E_INVAL; scan_params->ie_list.hecap = (uint8_t *)ie; break; case WLAN_EXTN_ELEMID_HEOP: @@ -1317,28 +1320,36 @@ static int util_scan_scm_calc_nss_supported_by_ap( { struct htcap_cmn_ie *htcap; struct wlan_ie_vhtcaps *vhtcaps; - struct wlan_ie_hecaps *hecaps; + uint8_t *he_cap; + uint8_t *end_ptr = NULL; uint16_t rx_mcs_map = 0; + uint8_t *mcs_map_offset; htcap = (struct htcap_cmn_ie *) util_scan_entry_htcap(scan_params); vhtcaps = (struct wlan_ie_vhtcaps *) util_scan_entry_vhtcap(scan_params); - hecaps = (struct wlan_ie_hecaps *) - util_scan_entry_hecap(scan_params); + he_cap = util_scan_entry_hecap(scan_params); - if (hecaps) { + if (he_cap) { /* Using rx mcs map related to 80MHz or lower as in some * cases higher mcs may suuport lesser NSS than that * of lowe mcs. Thus giving max NSS capability. */ - rx_mcs_map = - qdf_cpu_to_le16(hecaps->mcs_bw_map[0].rx_mcs_map); + end_ptr = he_cap + he_cap[1] + sizeof(struct ie_header); + mcs_map_offset = (he_cap + sizeof(struct extn_ie_header) + + WLAN_HE_MACCAP_LEN + WLAN_HE_PHYCAP_LEN); + if ((mcs_map_offset + WLAN_HE_MCS_MAP_LEN) <= end_ptr) { + rx_mcs_map = *(uint16_t *)mcs_map_offset; + } else { + rx_mcs_map = WLAN_INVALID_RX_MCS_MAP; + scm_debug("mcs_map_offset exceeds he cap len"); + } } else if (vhtcaps) { rx_mcs_map = vhtcaps->rx_mcs_map; } - if (hecaps || vhtcaps) { + if (he_cap || vhtcaps) { if ((rx_mcs_map & 0xC000) != 0xC000) return 8; From c5560438fc171e684b6f6d73c1b514d851b2fc72 Mon Sep 17 00:00:00 2001 From: Ashish Date: Fri, 14 Jul 2023 12:23:03 +0530 Subject: [PATCH 5/5] qcacmn: Consider gindoor_channel_support ini to decide ap_power_type Currently driver does not consider gindoor_channel_support ini when it decides the ap power type and because of that it always decides ap power type as VLP. Driver should consider this ini value as well because this INI says that indoor channels are allowed so driver should set ap power mode as LPI to allow LPI power mode. Change-ID: Id7ad546ba23ce210497002e3083a22f1edc87185 CRs-Fixed: 3085997 --- umac/regulatory/core/src/reg_utils.c | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/umac/regulatory/core/src/reg_utils.c b/umac/regulatory/core/src/reg_utils.c index 2a162c13bd52..1438365da7d9 100644 --- a/umac/regulatory/core/src/reg_utils.c +++ b/umac/regulatory/core/src/reg_utils.c @@ -831,11 +831,18 @@ enum reg_6g_ap_type reg_decide_6g_ap_pwr_type(struct wlan_objmgr_pdev *pdev) return REG_VERY_LOW_POWER_AP; } - if (reg_is_afc_available(pdev)) + if (reg_is_afc_available(pdev)) { ap_pwr_type = REG_STANDARD_POWER_AP; - else if (pdev_priv_obj->reg_6g_superid != FCC1_6G && - pdev_priv_obj->reg_6g_superid != FCC1_6G_CL) + } else if (pdev_priv_obj->indoor_chan_enabled) { + if (pdev_priv_obj->reg_rules.num_of_6g_ap_reg_rules[REG_INDOOR_AP]) + ap_pwr_type = REG_INDOOR_AP; + else + ap_pwr_type = REG_VERY_LOW_POWER_AP; + } else if (pdev_priv_obj->reg_rules.num_of_6g_ap_reg_rules[REG_VERY_LOW_POWER_AP]) { ap_pwr_type = REG_VERY_LOW_POWER_AP; + } + reg_debug("indoor_chan_enabled %d ap_pwr_type %d", + pdev_priv_obj->indoor_chan_enabled, ap_pwr_type); reg_set_ap_pwr_and_update_chan_list(pdev, ap_pwr_type);