From nobody Sun Aug 24 14:38:51 2025 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4c8xPm4Hk3z65XcN; Sun, 24 Aug 2025 14:38:52 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R12" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4c8xPm2Pqbz3Wkw; Sun, 24 Aug 2025 14:38:52 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1756046332; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=skUG/MVyzRwrwhHLHTPTaZDhM6A869zofQc20jb8sAI=; b=t1irHRF+ZfyfJdQP7OIB3UHoLwwLhWC7rTSUqXEPrl4LYHajFx1pP6eABLZ8FHdW5We5sI 3oqSvUoMUfIgWL72ew8nmdWrC1YNBOgLGQ3dbFZwFSBxm7W5h6SSRa9r0pLOkkDFfgu4U8 7Z56qO58glvvr+AwntEnBNwp0xhbIrD3rDntfPfw8NFFzs4MxYzjPcynLLmbOGq25aCc34 68hzWmSbMw3wnCpxH+g8YQJ60+dFmvVNArjjZZIRGGpOHmzj4yJZbFeKP6Ao4StdcNtQVV 0VVIoW+29TqnXcBRprrb2m65/phh7G20U08U0E7apFbPgoVA+e8KhR9+l/hqKA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1756046332; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=skUG/MVyzRwrwhHLHTPTaZDhM6A869zofQc20jb8sAI=; b=xiTUYk+FTWlY2IXGuFoNpOXjy6VYewALVmS8OyqgG6aTfMkX8NBCKRy8RQumYXO7jsf26R Ul+JB3dKyDJWTw1ZfaP2CEQGzUNMPUUL78ZJiuKY1cFpl1J0lZoXhHD/pvqyEObyYH/HMt 1WRmQbAt8AYDqFEF3sbCCEObcnqall6yHbyu5XPZpyx2RN5Dd64gTnTluNnZraoq/QlH+k Nly1QbfXhVyy2RBsg0CBil3wxn+FmEH38W82ZnzvRGx3hYG6UyNwnCXHL5qajmSQZjR9RE HV1nMIE+PADizRnkWhbM6lKrTT3sr4ZyUAhikKem1jlchceUG0mw3Rlmoh/nyw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1756046332; a=rsa-sha256; cv=none; b=SkLCjXaVyh0JW8EQQ08UHQY/l4w8XFrzq6CZz9oiO54Q7mv8UPUHdO0avMPyV8l7HLqFHG NywY05sDbq6g9qwGA7Qb5ClqaOrH8M8zmyX12GRt9WFkARAeWNj7mNh1wNVIw6s4tM5qfA U+PRMniuB72/MvjEMVuzAx0mBzZ9kKeZzLc+Wq5FkLBqX1xjSy35r0Jof8GVhPInqXGWr+ f4jgJFCt0quqPMjkENLX7VJKlcde+M5OiJO5ofFFEeaV6e/AiwxuLHjvJMKGEP+jMsHpHo hHCqS1SXbr7a0IUsTiQDP8SaRgmy6rtckFh2dBlFrOIws7j/V4zePzlq/BPGLg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4c8xPl75S1z16Z8; Sun, 24 Aug 2025 14:38:51 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 57OEcpa3040470; Sun, 24 Aug 2025 14:38:51 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 57OEcprT040465; Sun, 24 Aug 2025 14:38:51 GMT (envelope-from git) Date: Sun, 24 Aug 2025 14:38:51 GMT Message-Id: <202508241438.57OEcprT040465@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: "Bjoern A. Zeeb" Subject: git: 8475942ca8e8 - main - LinuxKPI: 802.11: add guards to lkpi_ic_ampdu_rx_{start,stop} List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: bz X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 8475942ca8e887287959ec2671266a210f41ed86 Auto-Submitted: auto-generated The branch main has been updated by bz: URL: https://cgit.FreeBSD.org/src/commit/?id=8475942ca8e887287959ec2671266a210f41ed86 commit 8475942ca8e887287959ec2671266a210f41ed86 Author: Bjoern A. Zeeb AuthorDate: 2025-07-20 15:03:42 +0000 Commit: Bjoern A. Zeeb CommitDate: 2025-08-24 10:26:38 +0000 LinuxKPI: 802.11: add guards to lkpi_ic_ampdu_rx_{start,stop} After updating calls into lkpi_ic_ampdu_rx_stop() were seen along with panics. Working backwards adding checks to each level we lastly ended up fighting a lsta which is NULL. Simply return in any error cases as there is nothing we can do and just leave it to net80211. Sponsored by: The FreeBSD Foundation MFC after: 3 days --- sys/compat/linuxkpi/common/src/linux_80211.c | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/sys/compat/linuxkpi/common/src/linux_80211.c b/sys/compat/linuxkpi/common/src/linux_80211.c index 7ea7622744db..7e1430ccdbd1 100644 --- a/sys/compat/linuxkpi/common/src/linux_80211.c +++ b/sys/compat/linuxkpi/common/src/linux_80211.c @@ -5575,6 +5575,12 @@ lkpi_ic_ampdu_rx_start(struct ieee80211_node *ni, struct ieee80211_rx_ampdu *rap return (-ENXIO); } + if (lsta->state != IEEE80211_STA_AUTHORIZED) { + ic_printf(ic, "%s: lsta %p ni %p vap %p, sta %p state %d not AUTHORIZED\n", + __func__, lsta, ni, vap, sta, lsta->state); + return (-ENXIO); + } + params.sta = sta; params.action = IEEE80211_AMPDU_RX_START; params.buf_size = _IEEE80211_MASKSHIFT(le16toh(baparamset), IEEE80211_BAPS_BUFSIZ); @@ -5651,13 +5657,35 @@ lkpi_ic_ampdu_rx_stop(struct ieee80211_node *ni, struct ieee80211_rx_ampdu *rap) lvif = VAP_TO_LVIF(vap); vif = LVIF_TO_VIF(lvif); lsta = ni->ni_drv_data; + if (lsta == NULL) { + ic_printf(ic, "%s: lsta %p ni %p vap %p, lsta is NULL\n", + __func__, lsta, ni, vap); + goto net80211_only; + } sta = LSTA_TO_STA(lsta); + if (!lsta->added_to_drv) { + ic_printf(ic, "%s: lsta %p ni %p vap %p, sta %p not added to firmware\n", + __func__, lsta, ni, vap, sta); + goto net80211_only; + } + + if (lsta->state != IEEE80211_STA_AUTHORIZED) { + ic_printf(ic, "%s: lsta %p ni %p vap %p, sta %p state %d not AUTHORIZED\n", + __func__, lsta, ni, vap, sta, lsta->state); + goto net80211_only; + } + IMPROVE_HT("This really should be passed from ht_recv_action_ba_delba."); for (tid = 0; tid < WME_NUM_TID; tid++) { if (&ni->ni_rx_ampdu[tid] == rap) break; } + if (tid == WME_NUM_TID) { + ic_printf(ic, "%s: lsta %p ni %p vap %p, sta %p TID not found\n", + __func__, lsta, ni, vap, sta); + goto net80211_only; + } params.sta = sta; params.action = IEEE80211_AMPDU_RX_STOP;