From: Johannes Berg <johannes@sipsolutions.net>
To: Arnav Kapoor <kapoorarnav43@gmail.com>
Cc: linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org,
syzbot+15f88dfa580000@syzkaller.appspotmail.com,
Arnav Rawat <arnavrawat2000@gmail.com>
Subject: Re: [PATCH] mac80211: Fix WARNING in drv_get_tsf debugfs access
Date: Mon, 19 Jan 2026 14:20:18 +0100 [thread overview]
Message-ID: <7d2a4fa708a6681fb5c17ae8420ccf762b3e83bb.camel@sipsolutions.net> (raw)
In-Reply-To: <20260118213328.74309-1-kapoorarnav43@gmail.com> (sfid-20260118_223538_198382_44DD933E)
On Mon, 2026-01-19 at 03:03 +0530, Arnav Kapoor wrote:
> The debugfs tsf read function was calling drv_get_tsf() even when the
> interface was not registered with the driver, causing a WARN_ON to be
> triggered. This is inappropriate for debugfs access.
>
> Fix this by checking the IEEE80211_SDATA_IN_DRIVER flag in the debugfs
> read function and returning -1ULL directly when the interface is not
> in the driver, avoiding the warning.
>
> Reported-by: syzbot+15f88dfa580000@syzkaller.appspotmail.com
> Signed-off-by: Arnav Rawat <arnavrawat2000@gmail.com>
> ---
> net/mac80211/debugfs_netdev.c | 5 ++++-
> 1 file changed, 4 insertions(+), 1 deletion(-)
>
> diff --git a/net/mac80211/debugfs_netdev.c b/net/mac80211/debugfs_netdev.c
> index 30a5a978a..669e7c519 100644
> --- a/net/mac80211/debugfs_netdev.c
> +++ b/net/mac80211/debugfs_netdev.c
> @@ -656,7 +656,10 @@ static ssize_t ieee80211_if_fmt_tsf(
> struct ieee80211_local *local = sdata->local;
> u64 tsf;
>
> - tsf = drv_get_tsf(local, (struct ieee80211_sub_if_data *)sdata);
> + if (!(sdata->flags & IEEE80211_SDATA_IN_DRIVER))
> + tsf = -1ULL;
> + else
> + tsf = drv_get_tsf(local, (struct ieee80211_sub_if_data *)sdata);
Seems like we could get rid of the pointless cast, while changing it
anyway.
Also seems we should do it for all the debugfs files?
johannes
next parent reply other threads:[~2026-01-19 13:20 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20260118213328.74309-1-kapoorarnav43@gmail.com>
2026-01-19 13:20 ` Johannes Berg [this message]
2026-01-19 13:20 ` syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=7d2a4fa708a6681fb5c17ae8420ccf762b3e83bb.camel@sipsolutions.net \
--to=johannes@sipsolutions.net \
--cc=arnavrawat2000@gmail.com \
--cc=kapoorarnav43@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=syzbot+15f88dfa580000@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®