[PATCH] wifi: libertas: return consistent length in lbs_add_wpa_tlv()
Dan Williams
dcbw at redhat.com
Tue Jan 3 09:47:09 PST 2023
On Mon, 2023-01-02 at 15:47 -0800, Doug Brown wrote:
> The existing code only converts the first IE to a TLV, but it returns
> a
> value that takes the length of all IEs into account. When there is
> more
> than one IE (which happens with modern wpa_supplicant versions for
> example), the returned length is too long and extra junk TLVs get
> sent
> to the firmware, resulting in an association failure.
>
> Fix this by returning a length that only factors in the single IE
> that
> was converted. The firmware doesn't seem to support the additional
> IEs,
> so there is no value in trying to convert them to additional TLVs.
>
> Fixes: e86dc1ca4676 ("Libertas: cfg80211 support")
> Signed-off-by: Doug Brown <doug at schmorgal.com>
> ---
> drivers/net/wireless/marvell/libertas/cfg.c | 7 +++----
> 1 file changed, 3 insertions(+), 4 deletions(-)
>
> diff --git a/drivers/net/wireless/marvell/libertas/cfg.c
> b/drivers/net/wireless/marvell/libertas/cfg.c
> index 3e065cbb0af9..fcc5420ec7ea 100644
> --- a/drivers/net/wireless/marvell/libertas/cfg.c
> +++ b/drivers/net/wireless/marvell/libertas/cfg.c
> @@ -432,10 +432,9 @@ static int lbs_add_wpa_tlv(u8 *tlv, const u8
> *ie, u8 ie_len)
> *tlv++ = 0;
> tlv_len = *tlv++ = *ie++;
> *tlv++ = 0;
> - while (tlv_len--)
> - *tlv++ = *ie++;
> - /* the TLV is two bytes larger than the IE */
> - return ie_len + 2;
> + memcpy(tlv, ie, tlv_len);
> + /* the TLV has a four-byte header */
> + return tlv_len + 4;
Since you're removing ie_len usage in the function, you might as well
remove it from the function's arguments.
Can you also update the comments to say something like "only copy the
first IE into the command buffer".
Lastly, should you check the IE to make sure you're copying the WPA or
WMM IE that the firmware expects? What other IEs does
wpa_supplicant/cfg80211 add these days?
Dan
> }
>
> /*
More information about the libertas-dev
mailing list