Commit graph

23,231 commits

Author SHA1 Message Date
Abinandhu M
1b0f7e3489 qcacld-3.0: Disable SAP bringup in DFS when DFSmastercap
is disabled

Issue Scenario:
1) INI gEnableDFSMasterCap is set to 0
2) User tries to force start SAP on 160 MHz.
3) SAP starts on 160 MHz which contains DFS channels.

This is a violation since the DUT does not support DFS
master capability.

To fix this, stop the SAP bringup if atleast one of the
bonded channels is DFS.

CRs-Fixed: 4516874
Change-Id: Iaeb77d52059505bafb8a0d38386cb1790432b498
2026-05-10 22:52:01 +05:30
Deeksha Gupta
221de7eef1 qcacld-3.0: Set “WIPHY_FLAG_DFS_OFFLOAD” always in wiphy flag
Ensure the "WIPHY_FLAG_DFS_OFFLOAD" flag is always set in
wiphy flag, regardless of DFS master capability ini.
This changes eliminates the need for supplicant to check
DFS flags for the SAP channel, as the DFS logic is
consistently offloaded to the driver.

CRs-Fixed: 3716167
Change-Id: I571f1cf15d268b85ad4de4d2f2a93d39f59b1231
2026-05-10 22:20:34 +05:30
Pragaspathi Thilagaraj
e7116cb9e9 qcacld-3.0: Add A_INT64 typedef
Add A_INT64 as a signed 64-bit integer type in uapi/linux/a_types.h.
This complements the existing A_UINT64 definition and provides a
consistent signed 64-bit typedef for consumers of this UAPI header.

CRs-Fixed: 4492650
Change-Id: Ie7f5fb55ba291273ecf35920a217fc65dfa3f661
2026-05-08 23:05:46 +05:30
QCTECMDR Service
23e53b8260 Merge "qcacld-3.0: Self rsn cap intersect with AP rsn cap" 2026-04-28 23:25:04 -07:00
Abinandhu M
78e07c9a01 qcacld-3.0: Use orig_key_mgmt vdev param for AKM negotiation
Currently, the driver overwrites the supplicant
configured connect request AKMs with that of the
candidate's AKM. Due to this, the STA attempts
connection via an AKM which is not present in the
original connect request.

To fix this, use the intersection of original AKM
list and the candidate supported AKMs to derive the
connection AKM.

Change-Id: I700630fda91b4b3ff73e50a38e3c0386ede85e42
CRs-Fixed: 4490428
2026-04-07 13:20:50 +05:30
Surya Prakash Sivaraj
7b381e0bec qcacld-3.0: Reset SPMK cache before every connection
SPMK global cache in the vdev private is persistent
across connections. Therefore, in cross-ssid roaming
cases with different AKMs, SPMK in the global cache
will always be sent to the firmware in RSO start, even
for non-SAE connections. This causes roam failure.

Reset the spmk global cache for every new connection.

Change-Id: I03deefe16242ef79d0985a8c05881914e6f7af01
CRs-Fixed: 3310182
2026-03-18 15:20:46 +05:30
Ajit Vaishya
083fef0100 qcacld-3.0: Self rsn cap intersect with AP rsn cap
currently self rsn cap intersect with AP rsn cap IE
which is filed in bss desc, but while reading rsn cap
IE from bss desc is getting all Zero's, due to which
self cap also become Zero's.
Fix is read AP rsn cap from negotiated rsn cap of bss
desc which is populate properly and self rsn cap is
filled correctly.

Change-Id: Ia1d9c27e1f3a7528636ab78ebe973090a9ae6f1d
CRs-Fixed: 4423830
2026-02-18 06:13:49 -08:00
Surya Prakash Sivaraj
3a3ead7c31 qcacld-3.0: Prevent ping loss due to runtime suspend
Scenario:
1) FW sends roam start to the host, and host disables the netif
queues. Therefore, the ping from the stack does not reach the
driver.
3) The driver goes into runtime suspend, and the firmware aborts
roaming due to pmf assoc retry.
4) After assoc comeback timeout, the firmware successfully roams.
However, both roam abort and roam sync are not wakeable events.
5) Therefore, the host stays in runtime suspend until the timeout
as part of the serialization command queued during roam start.
6) Netif queues are enabled back after roam start timeout and ping
resumes.

This results in a data loss for a longer time, eventhough the
firmware has aborted the roaming. Currently, the host driver prevents
runtime suspend only from roam sync event until roam sync completion.

To fix this issue, prevent the runtime suspend from the roam start
until roam sync completion/roam abort/roam ho-failure.

Change-Id: I9d63dd6af09d17e90d7d2d6a63a8aaa59297a047
CRs-Fixed: 4413987
2026-01-29 13:14:11 +05:30
Surya Prakash Sivaraj
f955beb16c qcacld-3.0: Add runtime pm lock during roaming
Acquire the runtime pm lock when roam sync event is received
and release after roam sync complete is sent.

Change-Id: Ic56d353dd343f5fcbc228a8d7251e047177b9a9b
CRs-Fixed: 3238723
2026-01-29 13:13:07 +05:30
Sanskar Jain
1474e19497 qcacld-3.0: Add buffer overflow check in wma_fill_rx_stats function
The wma_fill_rx_stats function accesses wmi_rx array using index
wmi_rx[i * WLAN_MAX_AC + k] without validating that wmi_rx buffer
has sufficient elements. This can lead to buffer overflow when
num_peer_ac_rx_stats * WLAN_MAX_AC exceeds the available num_rx_stats.

Add validation check to ensure wmi_rx does not reach out of bound
before accessing the array.

CRs-Fixed: 4315163
Change-Id: I91cf41d8f931aef7d5666b2744fc5d8a167d43f3
2026-01-12 21:50:13 -08:00
jinbao liu
b4d8fce29f qcacld-3.0: Validate fse metadata before aggregation of FISA flow
When aggregation of a flow is in progress, there can be case
when the HW flow table entry match may fail for few packets.
Such packets, even though belong to a flow already present in
flow table, are routed independently to any RX ring.

When software checks this rx ring ID, from the independently routed
packet and compares the ring ID against the one which is assigned
for the flow, there will be a mismatch leading to unwanted behaviour.

Hence, always validate the fse_metadata before taking any
action on the basis of rx ring ID mismatch. The non-matching
packets, with invalid fse metadata can be submitted to network
stack independently.

Change-Id: Ia95f20ef1050bc981b2d22571b612fd2af6f6a65
CRs-Fixed: 3272353
2025-12-15 15:47:16 +08:00
Krupali Dhanvijay
594c30b7ec qcacld-3.0: Consider intersected AKM for association
Currently host overwrites crypto AKM with candidate AP’s AKM.
To choose the most secure AKM, host do sort of AKMs properly
based on security to use for association and can choose the
AKM which station do not advertise and results in Assoc failure.

To fix this, consider intersection of crypto and candidate AP’s
AKM for association instead of AKMs directly from AP config.

CRs-Fixed: 4320132
Change-Id: Id1813fc9f7fe76ff5ae9daf4da051067bddfdce1
2025-11-19 19:14:25 +05:30
Surya Prakash Sivaraj
40c990ed3d qcacld-3.0: Populate MBSSID cap in Ext CAP IE
The MBSSID cap in the extended capability IE is
populated properly in the Probe and Assoc request
of the initial connection. But, this cap is missing
in the reassoc request during roaming.

Host driver fills this cap based on the service cap
of MBSSID support only during the probe/assoc req
generation. This cap is not passed to the firmware
via SET IE or via assoc IEs in the RSO START.

Since the service cap would not change in runtime,
override the MBSSID cap in the assoc IEs received
from the userspace itself. This sets the cap in both
SET IE as well as RSO START.

Change-Id: I69476e503a369df6533de9c215efc4c39d9e251c
CRs-Fixed: 4117861
2025-10-29 16:35:11 +05:30
QCTECMDR Service
71d11eb799 Merge "Release 2.0.8.35G" 2025-09-06 03:38:26 -07:00
QCTECMDR Service
43bab0792b Merge "qcacld-3.0: Fix underflow issue of beacon length" 2025-09-06 01:02:37 -07:00
Kiran Kumar Reddy A E
15ea8abee0 Release 2.0.8.35G
Release 2.0.8.35G

Change-Id: Iaa1e456ca143d8650d715e3bdd25e00f5281b8b4
2025-09-06 00:37:52 -07:00
QCTECMDR Service
c69d2d15a7 Merge "qcacld-3.0: Add Validation for WMA Handle and PSOC in Wake Event" 2025-09-01 04:26:13 -07:00
Dharmendra Tiwari
4117e36cb8 qcacld-3.0: Fix underflow issue of beacon length
A validation check has been added to ensure
beacon length is not less than
(bcn->noa_sub_ie_len + sizeof(struct p2p_ie)),
preventing underflow issues.

Change-Id: I924a3ebf4a0749d5a4c56b36878765fcf46440a4
CRs-Fixed: 4166530
2025-08-28 09:26:47 +05:30
Ravindra Konda
7604d08f89 Release 2.0.8.35F
Release 2.0.8.35F

Change-Id: I8d4a6dabef540cd4594e32e3131bd508b4dd7ea9
CRs-Fixed: 774533
2025-07-22 15:20:49 -07:00
Surya Prakash Sivaraj
1eea4bab11 qcacld-3.0: don't overwrite psd_power flag if psd_set is true
When both EIRP and PSD TPE IEs are advertised by 6 GHz AP, we need
to use PSD power. We need to keep the psd_power true if psd_set
is true (means PSD TPE IE present) when driver processes the EIRP
TPE IE.
If reg rules don't support psd power, ignore PSD TPE IE.

Change-Id: I96cf8f08ffd0aa143f0f0f453eed3c8b8e5d2382
CRs-Fixed: 3693350
2025-07-22 15:20:48 -07:00
Surya Prakash Sivaraj
1c5657681b qcacld-3.0: Add TPE IE EIRP power support for 6 GHz band
Add TPE IE EIRP power parsing support for 6 GHz channels.
1) Currently, is_psd_power flag is derived from current
channel list chan flag which returns true if corresponding
channel supports PSD power. Normally, all 6 GHz channels
support PSD, so this flag is usually set to 1. But, AP
can transmit EIRP power in TPE IE for 6 GHz channels,
thus derive this flag based on tx_power interpretation
field in TPE IE for accurate value.
2) The calculated center freq is passed as argument to
retrieve regulatory power from reg channel list
but this logic works only for PSD. E.g. In case of EIRP,
center freq can be 6125 MHz for oper freq 6115 and BW
40 MHz, and causing reg APIs to return reg power as 0.
Thus, pass operating freq as argument in case of EIRP.

Change-Id: If1ad3870a866592d970adad218e507c9c756f615
CRs-Fixed: 3266393
2025-07-22 15:20:43 -07:00
Ravindra Konda
ad3eca7060 Release 2.0.8.35E
Release 2.0.8.35E

Change-Id: I831554185675089d3055c9e071c39944fe5c8f68
CRs-Fixed: 774533
2025-07-22 12:55:06 -07:00
Surya Prakash Sivaraj
fed91e16d8 qcacld-3.0: Validate bw in lim calculate tpc
Currently host driver does not validate bw in lim calculate
tpc api before is it gets next higher bw, there is a possiblity
that this bw becomes invalid and driver ends up with out of bound
access for get higher bw array.

In current scenario when host driver tries to start vdev on
frequency 2472 for country IN and executes this API for frequency
2472, at the same time country is changed to US and this frequency
becomes invalid. so in the execution of this API host driver gets
invalid bw from reg set param and ends up with out of bound access
for get higher bw array.

TO address above issue, add a check to validate bw before driver
acceses get higher bw array.

Change-Id: Ibd6a2ff44a7928bb2fd461e6c49d4e306e4de7f7
CRs-Fixed: 3186084
2025-07-22 12:55:06 -07:00
Kaushik K.N
8be762469a qcacld-3.0: Add Validation for WMA Handle and PSOC in Wake Event
Currently, the WOW wakeup event handler lacks validation for the
WMA handle and the PSOC pointer within the WMA handle. This omission
can lead to null pointer dereferences in the host.

To address this issue, null pointer checks for both the WMA handle
and the PSOC pointer have been added.

CRs-Fixed: 4107000
Change-Id: Iaf22d5adc14b65b778b0e1d78108eded0cccb8c9
2025-07-15 12:01:14 +05:30
Ravindra Konda
f3f95c51ab Release 2.0.8.35D
Release 2.0.8.35D

Change-Id: I3b0c1f0536f0ef1278181c95747928037ea12311
CRs-Fixed: 774533
2025-06-05 01:33:58 -07:00
Eswar Kesavalu
1879db349b qcacld-3.0: Add ini to apply RSSI delta for 6 GHz roam
Introduce a new ini parameter, to apply an RSSI penalty
to non-6 GHz candidate APs during roaming from 6 GHz AP.
This ensures roaming to non-6 GHz AP occurs only if it
offers significantly better signal quality.

Change-Id: I02482c37c56c44d3d1804282abd09deaefb8eed3
CRs-Fixed: 4141300
2025-06-05 01:33:57 -07:00
Ravindra Konda
2db179ead0 Release 2.0.8.35C
Release 2.0.8.35C

Change-Id: I6d812e6d4eadfd09a9c6f39761446e73bf207c7f
CRs-Fixed: 774533
2025-05-29 01:11:39 -07:00
Krupali Dhanvijay
251ec89b59 qcacld-3.0: Update PMK from firmware for FT-SAE AKM also
When roaming happens with full SAE for FT-SAE AKMs host doesn't
update the PMK received from firmware into its global cache.
This causes stale PMK to be sent to firmware when full SAE
happens when roaming to below AKM's:
WLAN_CRYPTO_KEY_MGMT_FT_SAE
WLAN_CRYPTO_KEY_MGMT_FT_SAE_EXT_KEY

So update the PMK sent from firmware for above AKM's when
auth status is connected (full SAE happens at host).

CRs-Fixed: 3807689
Change-Id: I25d1a253de37481952c41f54697521285a0ccf92
2025-05-29 01:11:38 -07:00
Ravindra Konda
d6e1ed30e5 Release 2.0.8.35B
Release 2.0.8.35B

Change-Id: Id320fd9d156ae0f075b050ba530da1bce5bb2a69
CRs-Fixed: 774533
2025-04-10 01:07:24 -07:00
Will Huang
fda10761df qcacld-3.0: Rename variables name chan to chan_freq of wlan_hdd_mgmt_tx
We have fixed using channel number as internal parameter instead of
chan frequency with change I60fe37d7d716eeaceaa00f3fb59c77b629ebacac,
but variables name are still chan which might cause confused to reader.

Rename all places where "chan" to "chan_freq", which actually channel
frequency used. And alter miss APIs which still expect channel number.

Change-Id: I948cbad133a17093f49384b563966d2c53b51707
CRs-Fixed: 3033951
2025-04-10 01:07:23 -07:00
Will Huang
10e437e63d qcacld-3.0: Fix mgmt tx from supplicant failed on 6 GHz chan
Currently wlan_hdd_mgmt_tx path is still using legacy API to convert
channel frequency to number, it is not applicable for 6 GHz channel if
convert it back from number to frequency.

Fix it by replace all places where using legacy API to convert channel
and use channel frequency from supplicant directly. It can fix mgmt tx
from supplicant on 6 GHz channel.

Change-Id: I60fe37d7d716eeaceaa00f3fb59c77b629ebacac
CRs-Fixed: 3024898
2025-04-10 01:07:18 -07:00
Ravindra Konda
b6c8048d82 Release 2.0.8.35A
Release 2.0.8.35A

Change-Id: Ib7f525b0dbae414daa80b9e2d204943d6827aae4
CRs-Fixed: 774533
2025-03-27 11:15:32 -07:00
Aditya Kodukula
c69a241cd9 qcacld-3.0: Fix potential OOB memory access
Currently in the wma_stats_ext_event_handler(), the buf_ptr
is not pointing correctly to the event data received from FW.
This is leading to an OOB memory access during qdf_mem_copy().

So, to avoid this issue correctly point the buf_ptr to the event
data sent by the FW in the TLV.

Change-Id: Iffa3e96a6a36eff5899a7a9a7febe0ebb9d7878f
CRs-Fixed: 4011656
2025-03-27 11:15:31 -07:00
Ravindra Konda
ee56b3c1d7 Release 2.0.8.35
Release 2.0.8.35

Change-Id: I2ce9028c33f0161e85772f0a7996cad2a515726a
CRs-Fixed: 774533
2025-03-04 01:20:55 -08:00
Krupali Dhanvijay
6bebc81e60 qcacld-3.0: Recalculate TX power post CSA
Currently, host doesn't recalculate TX power post CSA if
no change in power constraint or TPE IE, this can cause
issue if local regulatory power is different for new CSA
frequency.
To address this issue, add support to recalculate TX power
for first beacon received post CSA.

Change-Id: I91f4609c552d579c24e781d382e647b6617e9315
CRs-Fixed: 3809724
2025-03-04 01:20:54 -08:00
Ravindra Konda
8cd10f873d Release 2.0.8.34Z
Release 2.0.8.34Z

Change-Id: I1699d8e33c61adc77a6fc10efdd00dc1dd38428b
CRs-Fixed: 774533
2024-11-12 01:10:17 -08:00
Krupali Dhanvijay
6fe3981e40 qcacld-3.0: Update key management in original auth mode for WAPI
Currently for WAPI connection auth mode is updated only
in key management, but on connect request for validating
auth mode, it compared with original key management and
failing to connect because of mismatch in auth and cipher suits.

To fix this, update auth mode in original key management as well
in crypto for WAPI connection.

CRs-Fixed: 3901275
Change-Id: I942fbbc68c18d7c8137053b5fc9cb0260109fdcd
2024-11-12 01:10:16 -08:00
Ravindra Konda
1a2fc5395e Release 2.0.8.34Y
Release 2.0.8.34Y

Change-Id: Ifb4c818cfbb266d94f02fb887edd901c4471a707
CRs-Fixed: 774533
2024-10-09 03:44:51 -07:00
Dharmendra Tiwari
685e5c9a53 qcacld-3.0: Correcting the TSInfo structure size according to the Spec
According to spec the TSinfo size should be 4 bytes.

To fix this issue,TSInfo size is increased to 4bytes aligning with the
current standard.

CRs-Fixed: 3910625
Change-Id: I7979fa84af0295d21d4afe1b876af494a5b8fed8
2024-10-09 03:44:50 -07:00
Ravindra Konda
507504e89d Release 2.0.8.34X
Release 2.0.8.34X

Change-Id: I236740f6ead734b72780cfa0366f0311a20a9308
CRs-Fixed: 774533
2024-10-04 09:04:57 -07:00
Surya Prakash Sivaraj
01ae0689b1 qcacld-3.0: Remove use-after-free of frame in tx mgmt send
The tx completion handler for the frame frees the buffer.
Therefore, usage of frame after tx completion causes undesired
effect.

Remove the dereference of tx frame buffer contents in
lim_tx_mgmt_frame() after the tx completion.

Change-Id: I32211e1bce4f96ba920a2212ef65aa39831666ab
CRs-Fixed: 3772014
2024-10-04 09:04:56 -07:00
Ravindra Konda
923a432595 Release 2.0.8.34W
Release 2.0.8.34W

Change-Id: I8b539f6198a7491667862a742c31424e84380b14
CRs-Fixed: 774533
2024-09-26 08:29:50 -07:00
Kiran Kumar Lokere
f33a4f5a7d qcacld-3.0: Fix the possible OOB write in country IE unpack
Fix the possible OOB write in unpacking the country IE due to
the IE length check against integer division.

CRs-Fixed: 3910626
Change-Id: I800290ab7285fb46ed43a46ce38967046b4881fa
(cherry picked from commit 0002f9ddc9a6be3e34fe15e55f286b5794b29f08)
2024-09-26 08:29:49 -07:00
Ravindra Konda
b9e91d03e4 Release 2.0.8.34V
Release 2.0.8.34V

Change-Id: I6f37d9545e66ae5c2c2c57df8980e2c34d6d1abf
CRs-Fixed: 774533
2024-09-02 09:26:41 -07:00
Surya Prakash Sivaraj
5d837c1b79 qcacld-3.0: Enhance the RSNXE inter-op logic
Some third-party APs are not able to handle more than 1 octet
in the RSNXE, even though RSNXE support is present.

Therefore, to prevent this interop issue, send only 1 octet of
RSNXE if the AP broadcasts only 1 octet.

RSNXE handling logic summary:
1. Don't modify userspace RSNXE when caps other than
   SAE_H2E, SAE_PK, SECURE_LTF, SECURE_RTT,
   PROT_RANGE_NEGOTIOATION are set.
2. AP doesn't send RSNXE
   For WPA2 - Strip the RSNXE completely.
   For WPA3 - Retain only SAE capabilities such as H2E and PK.
3. AP supports RSNXE with length 1
   For WPA2 & WPA3 - Retain only the first octet in RSNXE.
4. AP supports RSNXE with multiple octet
   For WPA2 & WPA3 - Use the userspace assoc ie RSNXE as it is.

Change-Id: I56d1d5711b067fe5e0ff19117f6a600219cb86a0
CRs-Fixed: 3490369
2024-09-02 09:26:40 -07:00
Ravindra Konda
18748980f7 Release 2.0.8.34U
Release 2.0.8.34U

Change-Id: Ie459f60663aef7745dbd9ef190691d8a405cb116
CRs-Fixed: 774533
2024-08-29 01:17:54 -07:00
Ashish
38efdc0db2 qcacld-3.0: Set sar safety req resp event before unsolited work stop
Currently when sar safety unsolited timer expires, driver schedules
a work to send sar safety unsolited events to user space. When driver
receives sar set command from user space it tries to stop this work
with delayed work stop sync. This delayed work stop sync API waits for
work to get complete and then it stops the work, because of this,
work runs the complete for loop and sends extra sar safety unsolicited
events even after receiving sar set command.

To addrerss above issue, set the sar safety request response event
before delayed work stop sync to complete the work.

Change-Id: I3485e4b1ea600393ff2d9512a055de92d0a3d612
CRs-Fixed: 3213334
2024-08-29 01:17:53 -07:00
Ravindra Konda
d4e8774068 Release 2.0.8.34T
Release 2.0.8.34T

Change-Id: Idacaae744b054dc32c1fc9b4874945459884a0dc
CRs-Fixed: 774533
2024-07-15 01:08:10 -07:00
Srikanth Marepalli
c9f42e357d qcacld-3.0: Update connect request crypto parameters
Update the connect request crypto parameters based
on the new kernel changes to increase the size of the
akm_suites array in connect request

Change-Id: I36eb265d3dafe9d822879fdbed340ba0c6bb7225
CRs-Fixed: 3806556
2024-07-15 01:08:09 -07:00
Srikanth Marepalli
d4e50bce79 qcacld-3.0: Enable CFG80211_MULTI_AKM_CONNECT_SUPPORT from kernelv6.0
Current code supports CFG80211_MULTI_AKM_CONNECT_SUPPORT only for
v5.15 kernel.

Enable this feature support from kernelv6.0 by default.

Change-Id: I6fbf83df54fd898abde0546f526b193a6d8dc620
CRs-Fixed: 3806550
2024-07-15 01:08:04 -07:00