Commit eb6cdc53 authored by JaeMan Park's avatar JaeMan Park Committed by Zheng Zengkai
Browse files

mac80211_hwsim: initialize ieee80211_tx_info at hw_scan_work

stable inclusion
from stable-v5.10.104
commit 13f0ea8d11934a017f5c353fa049a09de3c37ec0
bugzilla: https://gitee.com/openeuler/kernel/issues/I56XAC

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=13f0ea8d11934a017f5c353fa049a09de3c37ec0



--------------------------------

[ Upstream commit cacfddf8 ]

In mac80211_hwsim, the probe_req frame is created and sent while
scanning. It is sent with ieee80211_tx_info which is not initialized.
Uninitialized ieee80211_tx_info can cause problems when using
mac80211_hwsim with wmediumd. wmediumd checks the tx_rates field of
ieee80211_tx_info and doesn't relay probe_req frame to other clients
even if it is a broadcasting message.

Call ieee80211_tx_prepare_skb() to initialize ieee80211_tx_info for
the probe_req that is created by hw_scan_work in mac80211_hwsim.

Signed-off-by: default avatarJaeMan Park <jaeman@google.com>
Link: https://lore.kernel.org/r/20220113060235.546107-1-jaeman@google.com


[fix memory leak]
Signed-off-by: default avatarJohannes Berg <johannes.berg@intel.com>
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>
Signed-off-by: default avatarYu Liao <liaoyu15@huawei.com>
Reviewed-by: default avatarWei Li <liwei391@huawei.com>
Signed-off-by: default avatarZheng Zengkai <zhengzengkai@huawei.com>
parent 965eb9e6
Loading
Loading
Loading
Loading
+9 −0
Original line number Original line Diff line number Diff line
@@ -2264,6 +2264,15 @@ static void hw_scan_work(struct work_struct *work)
			if (req->ie_len)
			if (req->ie_len)
				skb_put_data(probe, req->ie, req->ie_len);
				skb_put_data(probe, req->ie, req->ie_len);


			if (!ieee80211_tx_prepare_skb(hwsim->hw,
						      hwsim->hw_scan_vif,
						      probe,
						      hwsim->tmp_chan->band,
						      NULL)) {
				kfree_skb(probe);
				continue;
			}

			local_bh_disable();
			local_bh_disable();
			mac80211_hwsim_tx_frame(hwsim->hw, probe,
			mac80211_hwsim_tx_frame(hwsim->hw, probe,
						hwsim->tmp_chan);
						hwsim->tmp_chan);