* [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse
@ 2026-07-29 1:05 Jeff Johnson
2026-07-29 1:05 ` [PATCH ath-next 1/2] wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() Jeff Johnson
` (4 more replies)
0 siblings, 5 replies; 8+ messages in thread
From: Jeff Johnson @ 2026-07-29 1:05 UTC (permalink / raw)
To: Jeff Johnson; +Cc: ath11k, ath12k, linux-wireless, linux-kernel, Jeff Johnson
Both ath11k and ath12k have the same issue.
---
Jeff Johnson (2):
wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()
wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()
drivers/net/wireless/ath/ath11k/wmi.c | 8 +++++---
drivers/net/wireless/ath/ath12k/wmi.c | 8 +++++---
2 files changed, 10 insertions(+), 6 deletions(-)
---
base-commit: 189721a4afa1804315e7dcfca9ca0539c7b1d7af
change-id: 20260720-mac_phy_caps_parse-stride-mismatch-e7292580f072
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH ath-next 1/2] wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()
2026-07-29 1:05 [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse Jeff Johnson
@ 2026-07-29 1:05 ` Jeff Johnson
2026-07-29 1:05 ` [PATCH ath-next 2/2] wifi: ath11k: " Jeff Johnson
` (3 subsequent siblings)
4 siblings, 0 replies; 8+ messages in thread
From: Jeff Johnson @ 2026-07-29 1:05 UTC (permalink / raw)
To: Jeff Johnson; +Cc: ath11k, ath12k, linux-wireless, linux-kernel, Jeff Johnson
Currently, in ath12k_wmi_mac_phy_caps_parse(), kzalloc() sizes the
mac_phy_caps buffer as tot_phy_id * len, where len is clamped to
min(firmware_len, sizeof(struct ath12k_wmi_mac_phy_caps_params)). The
subsequent memcpy() destination advances by sizeof(full struct) per slot
via C pointer arithmetic, not by the clamped len. When firmware sends
short TLVs, the second and later slots are written past the end of the
allocation.
The reader in ath12k_pull_mac_phy_cap_svc_ready_ext() also indexes the
buffer with full-struct pointer arithmetic, so the allocation must match
that stride.
Fix by using kzalloc_objs(), which derives the element size from the
pointer type, making allocation size and pointer stride provably
consistent regardless of what len the firmware provides.
Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Fixes: d889913205cf ("wifi: ath12k: driver for Qualcomm Wi-Fi 7 devices")
Assisted-by: Claude:claude-sonnet-4-6
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
---
drivers/net/wireless/ath/ath12k/wmi.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/drivers/net/wireless/ath/ath12k/wmi.c b/drivers/net/wireless/ath/ath12k/wmi.c
index 672eae237ac6..d466baf5e90a 100644
--- a/drivers/net/wireless/ath/ath12k/wmi.c
+++ b/drivers/net/wireless/ath/ath12k/wmi.c
@@ -4765,14 +4765,16 @@ static int ath12k_wmi_mac_phy_caps_parse(struct ath12k_base *soc,
if (svc_rdy_ext->n_mac_phy_caps >= svc_rdy_ext->tot_phy_id)
return -ENOBUFS;
- len = min_t(u16, len, sizeof(struct ath12k_wmi_mac_phy_caps_params));
if (!svc_rdy_ext->n_mac_phy_caps) {
- svc_rdy_ext->mac_phy_caps = kzalloc((svc_rdy_ext->tot_phy_id) * len,
- GFP_ATOMIC);
+ svc_rdy_ext->mac_phy_caps =
+ kzalloc_objs(*svc_rdy_ext->mac_phy_caps,
+ svc_rdy_ext->tot_phy_id,
+ GFP_ATOMIC);
if (!svc_rdy_ext->mac_phy_caps)
return -ENOMEM;
}
+ len = min_t(u16, len, sizeof(struct ath12k_wmi_mac_phy_caps_params));
memcpy(svc_rdy_ext->mac_phy_caps + svc_rdy_ext->n_mac_phy_caps, ptr, len);
svc_rdy_ext->n_mac_phy_caps++;
return 0;
--
2.43.0
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH ath-next 2/2] wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()
2026-07-29 1:05 [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse Jeff Johnson
2026-07-29 1:05 ` [PATCH ath-next 1/2] wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() Jeff Johnson
@ 2026-07-29 1:05 ` Jeff Johnson
2026-07-29 3:57 ` [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse Rameshkumar Sundaram
` (2 subsequent siblings)
4 siblings, 0 replies; 8+ messages in thread
From: Jeff Johnson @ 2026-07-29 1:05 UTC (permalink / raw)
To: Jeff Johnson; +Cc: ath11k, ath12k, linux-wireless, linux-kernel, Jeff Johnson
Currently, in ath11k_wmi_tlv_mac_phy_caps_parse(), kcalloc() sizes the
mac_phy_caps buffer as tot_phy_id * len, where len is clamped to
min(firmware_len, sizeof(struct wmi_mac_phy_capabilities)). The subsequent
memcpy() destination advances by sizeof(full struct) per slot via C
pointer arithmetic, not by the clamped len. When firmware sends short
TLVs, the second and later slots are written past the end of the
allocation.
The reader in ath11k_pull_mac_phy_cap_svc_ready_ext() also indexes the
buffer with full-struct pointer arithmetic, so the allocation must match
that stride.
Fix by using kzalloc_objs(), which derives the element size from the
pointer type, making allocation size and pointer stride provably
consistent regardless of what len the firmware provides.
Compile tested only.
Fixes: 5b90fc760db5 ("ath11k: fix wmi service ready ext tlv parsing")
Assisted-by: Claude:claude-sonnet-4-6
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
---
drivers/net/wireless/ath/ath11k/wmi.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/drivers/net/wireless/ath/ath11k/wmi.c b/drivers/net/wireless/ath/ath11k/wmi.c
index 2d2c6d7a4a3b..f80e9b4a8a39 100644
--- a/drivers/net/wireless/ath/ath11k/wmi.c
+++ b/drivers/net/wireless/ath/ath11k/wmi.c
@@ -4800,14 +4800,16 @@ static int ath11k_wmi_tlv_mac_phy_caps_parse(struct ath11k_base *soc,
if (svc_rdy_ext->n_mac_phy_caps >= svc_rdy_ext->tot_phy_id)
return -ENOBUFS;
- len = min_t(u16, len, sizeof(struct wmi_mac_phy_capabilities));
if (!svc_rdy_ext->n_mac_phy_caps) {
- svc_rdy_ext->mac_phy_caps = kcalloc(svc_rdy_ext->tot_phy_id,
- len, GFP_ATOMIC);
+ svc_rdy_ext->mac_phy_caps =
+ kzalloc_objs(*svc_rdy_ext->mac_phy_caps,
+ svc_rdy_ext->tot_phy_id,
+ GFP_ATOMIC);
if (!svc_rdy_ext->mac_phy_caps)
return -ENOMEM;
}
+ len = min_t(u16, len, sizeof(struct wmi_mac_phy_capabilities));
memcpy(svc_rdy_ext->mac_phy_caps + svc_rdy_ext->n_mac_phy_caps, ptr, len);
svc_rdy_ext->n_mac_phy_caps++;
return 0;
--
2.43.0
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse
2026-07-29 1:05 [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse Jeff Johnson
2026-07-29 1:05 ` [PATCH ath-next 1/2] wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() Jeff Johnson
2026-07-29 1:05 ` [PATCH ath-next 2/2] wifi: ath11k: " Jeff Johnson
@ 2026-07-29 3:57 ` Rameshkumar Sundaram
2026-07-29 9:00 ` Baochen Qiang
2026-07-30 15:10 ` Jeff Johnson
4 siblings, 0 replies; 8+ messages in thread
From: Rameshkumar Sundaram @ 2026-07-29 3:57 UTC (permalink / raw)
To: Jeff Johnson, Jeff Johnson; +Cc: ath11k, ath12k, linux-wireless, linux-kernel
On 7/29/2026 6:35 AM, Jeff Johnson wrote:
> Both ath11k and ath12k have the same issue.
>
> ---
> Jeff Johnson (2):
> wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()
> wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()
>
> drivers/net/wireless/ath/ath11k/wmi.c | 8 +++++---
> drivers/net/wireless/ath/ath12k/wmi.c | 8 +++++---
> 2 files changed, 10 insertions(+), 6 deletions(-)
> ---
> base-commit: 189721a4afa1804315e7dcfca9ca0539c7b1d7af
> change-id: 20260720-mac_phy_caps_parse-stride-mismatch-e7292580f072
>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse
2026-07-29 1:05 [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse Jeff Johnson
` (2 preceding siblings ...)
2026-07-29 3:57 ` [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse Rameshkumar Sundaram
@ 2026-07-29 9:00 ` Baochen Qiang
2026-07-30 15:10 ` Jeff Johnson
4 siblings, 0 replies; 8+ messages in thread
From: Baochen Qiang @ 2026-07-29 9:00 UTC (permalink / raw)
To: Jeff Johnson, Jeff Johnson; +Cc: ath11k, ath12k, linux-wireless, linux-kernel
On 7/29/2026 9:05 AM, Jeff Johnson wrote:
> Both ath11k and ath12k have the same issue.
>
> ---
> Jeff Johnson (2):
> wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()
> wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()
>
> drivers/net/wireless/ath/ath11k/wmi.c | 8 +++++---
> drivers/net/wireless/ath/ath12k/wmi.c | 8 +++++---
> 2 files changed, 10 insertions(+), 6 deletions(-)
> ---
> base-commit: 189721a4afa1804315e7dcfca9ca0539c7b1d7af
> change-id: 20260720-mac_phy_caps_parse-stride-mismatch-e7292580f072
>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
>
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse
2026-07-29 1:05 [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse Jeff Johnson
` (3 preceding siblings ...)
2026-07-29 9:00 ` Baochen Qiang
@ 2026-07-30 15:10 ` Jeff Johnson
4 siblings, 0 replies; 8+ messages in thread
From: Jeff Johnson @ 2026-07-30 15:10 UTC (permalink / raw)
To: Jeff Johnson, Jeff Johnson; +Cc: ath11k, ath12k, linux-wireless, linux-kernel
On Tue, 28 Jul 2026 18:05:27 -0700, Jeff Johnson wrote:
> Both ath11k and ath12k have the same issue.
>
Applied, thanks!
[1/2] wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()
commit: 4c6eb712a91fa079be6f9f1419c96e0ad2227081
[2/2] wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()
commit: 7a246c72132eb943b5844ba79dad597b47429dba
Best regards,
--
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse
2026-07-29 15:26 Jeff Johnson
@ 2026-07-29 15:29 ` Jeff Johnson
0 siblings, 0 replies; 8+ messages in thread
From: Jeff Johnson @ 2026-07-29 15:29 UTC (permalink / raw)
To: Jeff Johnson; +Cc: ath11k, ath12k, linux-wireless, linux-kernel
On 7/29/2026 8:26 AM, Jeff Johnson wrote:
> Both ath11k and ath12k have the same issue.
>
> ---
> Jeff Johnson (2):
> wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()
> wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()
>
> drivers/net/wireless/ath/ath11k/wmi.c | 8 +++++---
> drivers/net/wireless/ath/ath12k/wmi.c | 8 +++++---
> 2 files changed, 10 insertions(+), 6 deletions(-)
> ---
> base-commit: 189721a4afa1804315e7dcfca9ca0539c7b1d7af
> change-id: 20260720-mac_phy_caps_parse-stride-mismatch-e7292580f072
>
<sigh> ignore this repost. invoked the wrong maintainer script...
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse
@ 2026-07-29 15:26 Jeff Johnson
2026-07-29 15:29 ` Jeff Johnson
0 siblings, 1 reply; 8+ messages in thread
From: Jeff Johnson @ 2026-07-29 15:26 UTC (permalink / raw)
To: Jeff Johnson; +Cc: ath11k, ath12k, linux-wireless, linux-kernel, Jeff Johnson
Both ath11k and ath12k have the same issue.
---
Jeff Johnson (2):
wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()
wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()
drivers/net/wireless/ath/ath11k/wmi.c | 8 +++++---
drivers/net/wireless/ath/ath12k/wmi.c | 8 +++++---
2 files changed, 10 insertions(+), 6 deletions(-)
---
base-commit: 189721a4afa1804315e7dcfca9ca0539c7b1d7af
change-id: 20260720-mac_phy_caps_parse-stride-mismatch-e7292580f072
^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-07-30 15:11 UTC | newest]
Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-29 1:05 [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse Jeff Johnson
2026-07-29 1:05 ` [PATCH ath-next 1/2] wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() Jeff Johnson
2026-07-29 1:05 ` [PATCH ath-next 2/2] wifi: ath11k: " Jeff Johnson
2026-07-29 3:57 ` [PATCH ath-next 0/2] wifi: ath: fix stride mismatch in mac_phy_caps_parse Rameshkumar Sundaram
2026-07-29 9:00 ` Baochen Qiang
2026-07-30 15:10 ` Jeff Johnson
2026-07-29 15:26 Jeff Johnson
2026-07-29 15:29 ` Jeff Johnson
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®