108 lines
		
	
	
		
			3.5 KiB
		
	
	
	
		
			Diff
		
	
	
	
	
	
			
		
		
	
	
			108 lines
		
	
	
		
			3.5 KiB
		
	
	
	
		
			Diff
		
	
	
	
	
	
From: Michal Kazior <michal.kazior@tieto.com>
 | 
						|
Date: Fri, 13 Jan 2017 13:32:51 +0100
 | 
						|
Subject: [PATCH] mac80211: prevent skb/txq mismatch
 | 
						|
 | 
						|
Station structure is considered as not uploaded
 | 
						|
(to driver) until drv_sta_state() finishes. This
 | 
						|
call is however done after the structure is
 | 
						|
attached to mac80211 internal lists and hashes.
 | 
						|
This means mac80211 can lookup (and use) station
 | 
						|
structure before it is uploaded to a driver.
 | 
						|
 | 
						|
If this happens (structure exists, but
 | 
						|
sta->uploaded is false) fast_tx path can still be
 | 
						|
taken. Deep in the fastpath call the sta->uploaded
 | 
						|
is checked against to derive "pubsta" argument for
 | 
						|
ieee80211_get_txq(). If sta->uploaded is false
 | 
						|
(and sta is actually non-NULL) ieee80211_get_txq()
 | 
						|
effectively downgraded to vif->txq.
 | 
						|
 | 
						|
At first glance this may look innocent but coerces
 | 
						|
mac80211 into a state that is almost guaranteed
 | 
						|
(codel may drop offending skb) to crash because a
 | 
						|
station-oriented skb gets queued up on
 | 
						|
vif-oriented txq. The ieee80211_tx_dequeue() ends
 | 
						|
up looking at info->control.flags and tries to use
 | 
						|
txq->sta which in the fail case is NULL.
 | 
						|
 | 
						|
It's probably pointless to pretend one can
 | 
						|
downgrade skb from sta-txq to vif-txq.
 | 
						|
 | 
						|
Since downgrading unicast traffic to vif->txq must
 | 
						|
not be done there's no txq to put a frame on if
 | 
						|
sta->uploaded is false. Therefore the code is made
 | 
						|
to fall back to regular tx() op path if the
 | 
						|
described condition is hit.
 | 
						|
 | 
						|
Only drivers using wake_tx_queue were affected.
 | 
						|
 | 
						|
Example crash dump before fix:
 | 
						|
 | 
						|
 Unable to handle kernel paging request at virtual address ffffe26c
 | 
						|
 PC is at ieee80211_tx_dequeue+0x204/0x690 [mac80211]
 | 
						|
 [<bf4252a4>] (ieee80211_tx_dequeue [mac80211]) from
 | 
						|
 [<bf4b1388>] (ath10k_mac_tx_push_txq+0x54/0x1c0 [ath10k_core])
 | 
						|
 [<bf4b1388>] (ath10k_mac_tx_push_txq [ath10k_core]) from
 | 
						|
 [<bf4bdfbc>] (ath10k_htt_txrx_compl_task+0xd78/0x11d0 [ath10k_core])
 | 
						|
 [<bf4bdfbc>] (ath10k_htt_txrx_compl_task [ath10k_core])
 | 
						|
 [<bf51c5a4>] (ath10k_pci_napi_poll+0x54/0xe8 [ath10k_pci])
 | 
						|
 [<bf51c5a4>] (ath10k_pci_napi_poll [ath10k_pci]) from
 | 
						|
 [<c0572e90>] (net_rx_action+0xac/0x160)
 | 
						|
 | 
						|
Reported-by: Mohammed Shafi Shajakhan <mohammed@qti.qualcomm.com>
 | 
						|
Signed-off-by: Michal Kazior <michal.kazior@tieto.com>
 | 
						|
---
 | 
						|
 | 
						|
--- a/net/mac80211/tx.c
 | 
						|
+++ b/net/mac80211/tx.c
 | 
						|
@@ -798,7 +798,7 @@ static __le16 ieee80211_tx_next_seq(stru
 | 
						|
 
 | 
						|
 static struct txq_info *ieee80211_get_txq(struct ieee80211_local *local,
 | 
						|
 					  struct ieee80211_vif *vif,
 | 
						|
-					  struct ieee80211_sta *pubsta,
 | 
						|
+					  struct sta_info *sta,
 | 
						|
 					  struct sk_buff *skb)
 | 
						|
 {
 | 
						|
 	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *) skb->data;
 | 
						|
@@ -812,10 +812,13 @@ static struct txq_info *ieee80211_get_tx
 | 
						|
 	if (!ieee80211_is_data(hdr->frame_control))
 | 
						|
 		return NULL;
 | 
						|
 
 | 
						|
-	if (pubsta) {
 | 
						|
+	if (sta) {
 | 
						|
 		u8 tid = skb->priority & IEEE80211_QOS_CTL_TID_MASK;
 | 
						|
 
 | 
						|
-		txq = pubsta->txq[tid];
 | 
						|
+		if (!sta->uploaded)
 | 
						|
+			return NULL;
 | 
						|
+
 | 
						|
+		txq = sta->sta.txq[tid];
 | 
						|
 	} else if (vif) {
 | 
						|
 		txq = vif->txq;
 | 
						|
 	}
 | 
						|
@@ -1503,23 +1506,17 @@ static bool ieee80211_queue_skb(struct i
 | 
						|
 	struct fq *fq = &local->fq;
 | 
						|
 	struct ieee80211_vif *vif;
 | 
						|
 	struct txq_info *txqi;
 | 
						|
-	struct ieee80211_sta *pubsta;
 | 
						|
 
 | 
						|
 	if (!local->ops->wake_tx_queue ||
 | 
						|
 	    sdata->vif.type == NL80211_IFTYPE_MONITOR)
 | 
						|
 		return false;
 | 
						|
 
 | 
						|
-	if (sta && sta->uploaded)
 | 
						|
-		pubsta = &sta->sta;
 | 
						|
-	else
 | 
						|
-		pubsta = NULL;
 | 
						|
-
 | 
						|
 	if (sdata->vif.type == NL80211_IFTYPE_AP_VLAN)
 | 
						|
 		sdata = container_of(sdata->bss,
 | 
						|
 				     struct ieee80211_sub_if_data, u.ap);
 | 
						|
 
 | 
						|
 	vif = &sdata->vif;
 | 
						|
-	txqi = ieee80211_get_txq(local, vif, pubsta, skb);
 | 
						|
+	txqi = ieee80211_get_txq(local, vif, sta, skb);
 | 
						|
 
 | 
						|
 	if (!txqi)
 | 
						|
 		return false;
 |