blob: 1b266d5862bb051838d96e731724c33644f474a3 [file] [log] [blame]
From 210567ce3c35210762840b3d672a76291561fb4c Mon Sep 17 00:00:00 2001
From: Fredrik Olofsson <>
Date: Tue, 19 Nov 2019 14:34:51 +0100
Subject: [PATCH] mac80211: fix TID field in monitor mode transmit
commit 753ffad3d6243303994227854d951ff5c70fa9e0 upstream.
Fix overwriting of the qos_ctrl.tid field for encrypted frames injected on
a monitor interface. While qos_ctrl.tid is not encrypted, it's used as an
input into the encryption algorithm so it's protected, and thus cannot be
modified after encryption. For injected frames, the encryption may already
have been done in userspace, so we cannot change any fields.
Before passing the frame to the driver, the qos_ctrl.tid field is updated
from skb->priority. Prior to dbd50a851c50 skb->priority was updated in
ieee80211_select_queue_80211(), but this function is no longer always
Update skb->priority in ieee80211_monitor_start_xmit() so that the value
is stored, and when later code 'modifies' the TID it really sets it to
the same value as before, preserving the encryption.
Fixes: dbd50a851c50 ("mac80211: only allocate one queue when using iTXQs")
Signed-off-by: Fredrik Olofsson <>
[rewrite commit message based on our discussion]
Signed-off-by: Johannes Berg <>
Signed-off-by: Paul Gortmaker <>
diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
index f13eb2f61ccf..d7619afc5725 100644
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
@@ -2262,6 +2262,15 @@ netdev_tx_t ieee80211_monitor_start_xmit(struct sk_buff *skb,
+ /*
+ * Initialize skb->priority for QoS frames. This is put in the TID field
+ * of the frame before passing it to the driver.
+ */
+ if (ieee80211_is_data_qos(hdr->frame_control)) {
+ u8 *p = ieee80211_get_qos_ctl(hdr);
+ skb->priority = *p & IEEE80211_QOS_CTL_TAG1D_MASK;
+ }
memset(info, 0, sizeof(*info));
info->flags = IEEE80211_TX_CTL_REQ_TX_STATUS |