]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
wifi: cfg80211: publish PMSR request before starting the driver
authorZhao Li <enderaoelyther@gmail.com>
Thu, 23 Jul 2026 20:22:23 +0000 (04:22 +0800)
committerJohannes Berg <johannes.berg@intel.com>
Tue, 28 Jul 2026 13:08:57 +0000 (15:08 +0200)
nl80211_pmsr_start() assigns the request cookie, calls the driver's
->start_pmsr() callback, and only then adds the request to
wdev->pmsr_list, without holding pmsr_lock for the addition.

mac80211_hwsim saves the request in its start callback and returns. Since
nl80211 uses parallel_ops, an immediate REPORT_PMSR can then run before
nl80211_pmsr_start() reaches its post-start list_add_tail(). hwsim also
dispatches reports from its virtio receive workqueue. Completion removes
the request from wdev->pmsr_list under pmsr_lock and frees it.

Thus completion can precede publication, race the unlocked list mutation,
or free the request before nl80211_pmsr_start() reads req->cookie for the
netlink reply.

Add the request to wdev->pmsr_list under pmsr_lock before calling the
driver, and use a cookie value saved before the call so the request is not
dereferenced after a successful start. On an error return the driver has
not retained or completed the request, so remove it from the list under the
lock and free it.

Fixes: 9bb7e0f24e7e ("cfg80211: add peer measurement with FTM initiator API")
Link: https://lore.kernel.org/all/20260723010916.76433-1-enderaoelyther@gmail.com/
Assisted-by: Codex:gpt-5
Assisted-by: Claude:opus-4.8
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260723202223.99661-1-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
net/wireless/pmsr.c

index d1e2fae5bc0e58a4454f8236c0aef089111a32c2..97449bcb9a2257ef0738375e30fda239e3b36890 100644 (file)
@@ -420,6 +420,7 @@ int nl80211_pmsr_start(struct sk_buff *skb, struct genl_info *info)
        const struct cfg80211_pmsr_capabilities *capa;
        struct cfg80211_pmsr_request *req;
        struct nlattr *peers, *peer;
+       u64 cookie;
 
        capa = rdev->wiphy.pmsr_capa;
 
@@ -521,14 +522,27 @@ int nl80211_pmsr_start(struct sk_buff *skb, struct genl_info *info)
        }
        req->cookie = cfg80211_assign_cookie(rdev);
        req->nl_portid = info->snd_portid;
+       cookie = req->cookie;
+
+       /*
+        * Add to the list before the driver call; under races or broken
+        * drivers, completion may free the request before rdev_start_pmsr()
+        * returns. Use the saved cookie below.
+        */
+       spin_lock_bh(&wdev->pmsr_lock);
+       list_add_tail(&req->list, &wdev->pmsr_list);
+       spin_unlock_bh(&wdev->pmsr_lock);
 
        err = rdev_start_pmsr(rdev, wdev, req);
-       if (err)
+       if (err) {
+               /* An error return leaves the request owned by this path. */
+               spin_lock_bh(&wdev->pmsr_lock);
+               list_del(&req->list);
+               spin_unlock_bh(&wdev->pmsr_lock);
                goto out_err;
+       }
 
-       list_add_tail(&req->list, &wdev->pmsr_list);
-
-       nl_set_extack_cookie_u64(info->extack, req->cookie);
+       nl_set_extack_cookie_u64(info->extack, cookie);
        return 0;
 out_err:
        kfree(req);