From: Luka Gejak <luka.gejak@linux.dev>
To: Mehmet Fide <mehmet.fide@gmail.com>
Cc: Ping-Ke Shih <pkshih@realtek.com>,
Bitterblue Smith <rtl8821cerfe2@gmail.com>,
mehmet.fide@screeningeagle.com, linux-wireless@vger.kernel.org,
linux-kernel@vger.kernel.org, Luka Gejak <luka.gejak@linux.dev>
Subject: Re: [PATCH v2 1/2] wifi: rtw88: download the beacon the reserved page was built with
Date: Thu, 1 Oct 2026 07:16:56 +0000 [thread overview]
Message-ID: <20261001071656.16499-1-luka.gejak@linux.dev> (raw)
In-Reply-To: <20260930074444.1991223-2-mehmet.fide@gmail.com>
On Wed, 30 Sep 2026, Mehmet Fide wrote:
> - if (page == 0)
> + if (page == 0) {
> page += rtw_len_to_page(rsvd_pkt->skb->len +
> tx_desc_sz, page_size);
> + /* the caller downloads it once more on its own */
> + *beacon = rsvd_pkt->skb;
> + } else {
[...]
> free:
> + dev_kfree_skb(beacon);
> kfree(buf);
beacon is written in that branch only, and the caller declares it without an
initialiser while the free at the end frees whatever it holds. The first page
always takes that branch today, but the caller cannot see that, so a later
change in the build would free a stack value. Would you mind initialising it to
NULL?
> @@ -2345,7 +2353,7 @@ int rtw_hw_scan_offload(struct rtw_dev *rtwdev, struct ieee80211_vif *vif,
> out:
> if (rtwdev->ap_active) {
> - ret = rtw_download_beacon(rtwdev);
> + ret = rtw_download_beacon(rtwdev, NULL);
> if (ret)
> rtw_err(rtwdev, "HW scan download beacon failed\n");
The cover says this path is compile tested only. The feature comes from the
firmware header rather than from the chip:
fw->feature = feature & FW_FEATURE_SIG ? feature : 0;
so another firmware for the same hardware can reach it, and this is the path
that v1 got wrong. Can it be run once on a device whose firmware has scan
offload?
Best regards,
Luka Gejak
next prev parent reply other threads:[~2026-10-01 7:17 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 7:44 [PATCH rtw-next v2 0/2] wifi: rtw88: channel switch in AP mode Mehmet Fide
2026-09-30 7:44 ` [PATCH rtw-next v2 1/2] wifi: rtw88: download the beacon the reserved page was built with Mehmet Fide
2026-10-01 7:16 ` Luka Gejak [this message]
2026-10-01 11:54 ` Mehmet Fide
2026-09-30 7:44 ` [PATCH rtw-next v2 2/2] wifi: rtw88: support channel switch in AP mode Mehmet Fide
2026-10-01 7:18 ` [PATCH " Luka Gejak
2026-10-01 11:54 ` [PATCH rtw-next " Mehmet Fide
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001071656.16499-1-luka.gejak@linux.dev \
--to=luka.gejak@linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=mehmet.fide@gmail.com \
--cc=mehmet.fide@screeningeagle.com \
--cc=pkshih@realtek.com \
--cc=rtl8821cerfe2@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®