| From 3cc89c31a5d0751c479aaa4e9120f98ee6c3a18a Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Thu, 13 Jan 2022 15:02:35 +0900 |
| Subject: mac80211_hwsim: initialize ieee80211_tx_info at hw_scan_work |
| |
| From: JaeMan Park <jaeman@google.com> |
| |
| [ Upstream commit cacfddf82baf1470e5741edeecb187260868f195 ] |
| |
| In mac80211_hwsim, the probe_req frame is created and sent while |
| scanning. It is sent with ieee80211_tx_info which is not initialized. |
| Uninitialized ieee80211_tx_info can cause problems when using |
| mac80211_hwsim with wmediumd. wmediumd checks the tx_rates field of |
| ieee80211_tx_info and doesn't relay probe_req frame to other clients |
| even if it is a broadcasting message. |
| |
| Call ieee80211_tx_prepare_skb() to initialize ieee80211_tx_info for |
| the probe_req that is created by hw_scan_work in mac80211_hwsim. |
| |
| Signed-off-by: JaeMan Park <jaeman@google.com> |
| Link: https://lore.kernel.org/r/20220113060235.546107-1-jaeman@google.com |
| [fix memory leak] |
| Signed-off-by: Johannes Berg <johannes.berg@intel.com> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| drivers/net/wireless/mac80211_hwsim.c | 9 +++++++++ |
| 1 file changed, 9 insertions(+) |
| |
| diff --git a/drivers/net/wireless/mac80211_hwsim.c b/drivers/net/wireless/mac80211_hwsim.c |
| index cfd97fe92d468..6e1721d533846 100644 |
| --- a/drivers/net/wireless/mac80211_hwsim.c |
| +++ b/drivers/net/wireless/mac80211_hwsim.c |
| @@ -2062,6 +2062,15 @@ static void hw_scan_work(struct work_struct *work) |
| if (req->ie_len) |
| skb_put_data(probe, req->ie, req->ie_len); |
| |
| + if (!ieee80211_tx_prepare_skb(hwsim->hw, |
| + hwsim->hw_scan_vif, |
| + probe, |
| + hwsim->tmp_chan->band, |
| + NULL)) { |
| + kfree_skb(probe); |
| + continue; |
| + } |
| + |
| local_bh_disable(); |
| mac80211_hwsim_tx_frame(hwsim->hw, probe, |
| hwsim->tmp_chan); |
| -- |
| 2.34.1 |
| |