Skip to content

Commit 7245012

Browse files
committed
wifi: iwlwifi: mvm: fix 6 GHz scan construction
If more than 255 colocated APs exist for the set of all APs found during 2.4/5 GHz scanning, then the 6 GHz scan construction will loop forever since the loop variable has type u8, which can never reach the number found when that's bigger than 255, and is stored in a u32 variable. Also move it into the loops to have a smaller scope. Using a u32 there is fine, we limit the number of APs in the scan list and each has a limit on the number of RNR entries due to the frame size. With a limit of 1000 scan results, a frame size upper bound of 4096 (really it's more like ~2300) and a TBTT entry size of at least 11, we get an upper bound for the number of ~372k, well in the bounds of a u32. Cc: [email protected] Fixes: eae94cf ("iwlwifi: mvm: add support for 6GHz") Closes: https://bugzilla.kernel.org/show_bug.cgi?id=219375 Link: https://patch.msgid.link/20241023091744.f4baed5c08a1.I8b417148bbc8c5d11c101e1b8f5bf372e17bf2a7@changeid Signed-off-by: Johannes Berg <[email protected]>
1 parent d5fee26 commit 7245012

File tree

1 file changed

+3
-3
lines changed
  • drivers/net/wireless/intel/iwlwifi/mvm

1 file changed

+3
-3
lines changed

drivers/net/wireless/intel/iwlwifi/mvm/scan.c

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1774,7 +1774,7 @@ iwl_mvm_umac_scan_cfg_channels_v7_6g(struct iwl_mvm *mvm,
17741774
&cp->channel_config[ch_cnt];
17751775

17761776
u32 s_ssid_bitmap = 0, bssid_bitmap = 0, flags = 0;
1777-
u8 j, k, n_s_ssids = 0, n_bssids = 0;
1777+
u8 k, n_s_ssids = 0, n_bssids = 0;
17781778
u8 max_s_ssids, max_bssids;
17791779
bool force_passive = false, found = false, allow_passive = true,
17801780
unsolicited_probe_on_chan = false, psc_no_listen = false;
@@ -1799,7 +1799,7 @@ iwl_mvm_umac_scan_cfg_channels_v7_6g(struct iwl_mvm *mvm,
17991799
cfg->v5.iter_count = 1;
18001800
cfg->v5.iter_interval = 0;
18011801

1802-
for (j = 0; j < params->n_6ghz_params; j++) {
1802+
for (u32 j = 0; j < params->n_6ghz_params; j++) {
18031803
s8 tmp_psd_20;
18041804

18051805
if (!(scan_6ghz_params[j].channel_idx == i))
@@ -1873,7 +1873,7 @@ iwl_mvm_umac_scan_cfg_channels_v7_6g(struct iwl_mvm *mvm,
18731873
* SSID.
18741874
* TODO: improve this logic
18751875
*/
1876-
for (j = 0; j < params->n_6ghz_params; j++) {
1876+
for (u32 j = 0; j < params->n_6ghz_params; j++) {
18771877
if (!(scan_6ghz_params[j].channel_idx == i))
18781878
continue;
18791879

0 commit comments

Comments
 (0)