[source] mac80211: backport a fix for a tx related race condition

LEDE Commits lede-commits at lists.infradead.org
Sat Jan 14 09:29:39 PST 2017


nbd pushed a commit to source.git, branch master:
https://git.lede-project.org/e7e91e62bb68d907b6d7f7d95c8e6c076fda985e

commit e7e91e62bb68d907b6d7f7d95c8e6c076fda985e
Author: Felix Fietkau <nbd at nbd.name>
AuthorDate: Sat Jan 14 18:02:54 2017 +0100

    mac80211: backport a fix for a tx related race condition
    
    Signed-off-by: Felix Fietkau <nbd at nbd.name>
---
 .../352-mac80211-prevent-skb-txq-mismatch.patch    | 107 +++++++++++++++++++++
 1 file changed, 107 insertions(+)

diff --git a/package/kernel/mac80211/patches/352-mac80211-prevent-skb-txq-mismatch.patch b/package/kernel/mac80211/patches/352-mac80211-prevent-skb-txq-mismatch.patch
new file mode 100644
index 0000000..3822026
--- /dev/null
+++ b/package/kernel/mac80211/patches/352-mac80211-prevent-skb-txq-mismatch.patch
@@ -0,0 +1,107 @@
+From: Michal Kazior <michal.kazior at tieto.com>
+Date: Fri, 13 Jan 2017 13:32:51 +0100
+Subject: [PATCH] mac80211: prevent skb/txq mismatch
+
+Station structure is considered as not uploaded
+(to driver) until drv_sta_state() finishes. This
+call is however done after the structure is
+attached to mac80211 internal lists and hashes.
+This means mac80211 can lookup (and use) station
+structure before it is uploaded to a driver.
+
+If this happens (structure exists, but
+sta->uploaded is false) fast_tx path can still be
+taken. Deep in the fastpath call the sta->uploaded
+is checked against to derive "pubsta" argument for
+ieee80211_get_txq(). If sta->uploaded is false
+(and sta is actually non-NULL) ieee80211_get_txq()
+effectively downgraded to vif->txq.
+
+At first glance this may look innocent but coerces
+mac80211 into a state that is almost guaranteed
+(codel may drop offending skb) to crash because a
+station-oriented skb gets queued up on
+vif-oriented txq. The ieee80211_tx_dequeue() ends
+up looking at info->control.flags and tries to use
+txq->sta which in the fail case is NULL.
+
+It's probably pointless to pretend one can
+downgrade skb from sta-txq to vif-txq.
+
+Since downgrading unicast traffic to vif->txq must
+not be done there's no txq to put a frame on if
+sta->uploaded is false. Therefore the code is made
+to fall back to regular tx() op path if the
+described condition is hit.
+
+Only drivers using wake_tx_queue were affected.
+
+Example crash dump before fix:
+
+ Unable to handle kernel paging request at virtual address ffffe26c
+ PC is at ieee80211_tx_dequeue+0x204/0x690 [mac80211]
+ [<bf4252a4>] (ieee80211_tx_dequeue [mac80211]) from
+ [<bf4b1388>] (ath10k_mac_tx_push_txq+0x54/0x1c0 [ath10k_core])
+ [<bf4b1388>] (ath10k_mac_tx_push_txq [ath10k_core]) from
+ [<bf4bdfbc>] (ath10k_htt_txrx_compl_task+0xd78/0x11d0 [ath10k_core])
+ [<bf4bdfbc>] (ath10k_htt_txrx_compl_task [ath10k_core])
+ [<bf51c5a4>] (ath10k_pci_napi_poll+0x54/0xe8 [ath10k_pci])
+ [<bf51c5a4>] (ath10k_pci_napi_poll [ath10k_pci]) from
+ [<c0572e90>] (net_rx_action+0xac/0x160)
+
+Reported-by: Mohammed Shafi Shajakhan <mohammed at qti.qualcomm.com>
+Signed-off-by: Michal Kazior <michal.kazior at tieto.com>
+---
+
+--- a/net/mac80211/tx.c
++++ b/net/mac80211/tx.c
+@@ -798,7 +798,7 @@ static __le16 ieee80211_tx_next_seq(stru
+ 
+ static struct txq_info *ieee80211_get_txq(struct ieee80211_local *local,
+ 					  struct ieee80211_vif *vif,
+-					  struct ieee80211_sta *pubsta,
++					  struct sta_info *sta,
+ 					  struct sk_buff *skb)
+ {
+ 	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *) skb->data;
+@@ -812,10 +812,13 @@ static struct txq_info *ieee80211_get_tx
+ 	if (!ieee80211_is_data(hdr->frame_control))
+ 		return NULL;
+ 
+-	if (pubsta) {
++	if (sta) {
+ 		u8 tid = skb->priority & IEEE80211_QOS_CTL_TID_MASK;
+ 
+-		txq = pubsta->txq[tid];
++		if (!sta->uploaded)
++			return NULL;
++
++		txq = sta->sta.txq[tid];
+ 	} else if (vif) {
+ 		txq = vif->txq;
+ 	}
+@@ -1503,23 +1506,17 @@ static bool ieee80211_queue_skb(struct i
+ 	struct fq *fq = &local->fq;
+ 	struct ieee80211_vif *vif;
+ 	struct txq_info *txqi;
+-	struct ieee80211_sta *pubsta;
+ 
+ 	if (!local->ops->wake_tx_queue ||
+ 	    sdata->vif.type == NL80211_IFTYPE_MONITOR)
+ 		return false;
+ 
+-	if (sta && sta->uploaded)
+-		pubsta = &sta->sta;
+-	else
+-		pubsta = NULL;
+-
+ 	if (sdata->vif.type == NL80211_IFTYPE_AP_VLAN)
+ 		sdata = container_of(sdata->bss,
+ 				     struct ieee80211_sub_if_data, u.ap);
+ 
+ 	vif = &sdata->vif;
+-	txqi = ieee80211_get_txq(local, vif, pubsta, skb);
++	txqi = ieee80211_get_txq(local, vif, sta, skb);
+ 
+ 	if (!txqi)
+ 		return false;



More information about the lede-commits mailing list