]> git.ipfire.org Git - thirdparty/openwrt.git/commitdiff
mac80211: mwifiex: replace one-element arrays with flexible array members 24451/head
authorGeorgi Valkov <gvalkov@gmail.com>
Thu, 16 Jul 2026 09:28:00 +0000 (12:28 +0300)
committerJonas Jelonek <jelonek.jonas@gmail.com>
Tue, 28 Jul 2026 18:21:31 +0000 (20:21 +0200)
Replace deprecated one-element arrays with flexible array members.
CONFIG_FORTIFY_SOURCE reports the following warning when
one-element arrays are used as variable-length buffers:

sta_cmd.c:1033 mwifiex_sta_prepare_cmd
memcpy: detected field-spanning write (size 84) of single field
"domain->triplet" at .../marvell/mwifiex/sta_cmd.c:1033 (size 3)

Convert affected structs to use flexible array members.
- Preserve existing wire layouts.
- Use DECLARE_FLEX_ARRAY() for structs inside affected unions.

This fix has been accepted upstream:
https://github.com/torvalds/linux/commit/1cb5845a58d8e1f85d5766c6fbcbfddf96c212a1

Tested-on: WRT3200ACM
Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
Link: https://github.com/openwrt/openwrt/pull/24451
Signed-off-by: Jonas Jelonek <jelonek.jonas@gmail.com>
package/kernel/mac80211/Makefile
package/kernel/mac80211/patches/mwl/111-wifi-mwifiex-replace-one-element-arrays-with-flexibl.patch [new file with mode: 0644]

index f96317a9d5a465cbd405b9f6ab5e04a2a933255a..61943b4a0899f61a9228abe8054a68680e5b03c7 100644 (file)
@@ -11,7 +11,7 @@ include $(INCLUDE_DIR)/kernel.mk
 PKG_NAME:=mac80211
 
 PKG_VERSION:=6.18.39
-PKG_RELEASE:=2
+PKG_RELEASE:=3
 PKG_LICENSE:=GPL-2.0-only
 PKG_LICENSE_FILES:=COPYING
 
diff --git a/package/kernel/mac80211/patches/mwl/111-wifi-mwifiex-replace-one-element-arrays-with-flexibl.patch b/package/kernel/mac80211/patches/mwl/111-wifi-mwifiex-replace-one-element-arrays-with-flexibl.patch
new file mode 100644 (file)
index 0000000..62c38d7
--- /dev/null
@@ -0,0 +1,131 @@
+From 1cb5845a58d8e1f85d5766c6fbcbfddf96c212a1 Mon Sep 17 00:00:00 2001
+From: Georgi Valkov <gvalkov@gmail.com>
+Date: Thu, 16 Jul 2026 03:17:28 +0300
+Subject: [PATCH] wifi: mwifiex: replace one-element arrays with flexible array
+ members
+
+Replace deprecated one-element arrays with flexible array members.
+CONFIG_FORTIFY_SOURCE reports the following warning when
+one-element arrays are used as variable-length buffers:
+
+sta_cmd.c:1033 mwifiex_sta_prepare_cmd
+memcpy: detected field-spanning write (size 84) of single field
+"domain->triplet" at .../marvell/mwifiex/sta_cmd.c:1033 (size 3)
+
+Convert affected structs to use flexible array members.
+- Preserve existing wire layouts.
+- Use DECLARE_FLEX_ARRAY() for structs inside affected unions.
+
+Tested-on: WRT3200ACM, OpenWrt
+Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
+Reviewed-by: Francesco Dolcini <francesco.dolcini@toradex.com>
+Link: https://patch.msgid.link/20260716001728.57799-1-gvalkov@gmail.com
+Signed-off-by: Johannes Berg <johannes.berg@intel.com>
+---
+ drivers/net/wireless/marvell/mwifiex/fw.h      | 18 +++++++++---------
+ drivers/net/wireless/marvell/mwifiex/join.c    |  8 ++++----
+ drivers/net/wireless/marvell/mwifiex/sta_cmd.c |  2 +-
+ 3 files changed, 14 insertions(+), 14 deletions(-)
+
+--- a/drivers/net/wireless/marvell/mwifiex/fw.h
++++ b/drivers/net/wireless/marvell/mwifiex/fw.h
+@@ -823,7 +823,7 @@ struct chan_band_param_set {
+ struct mwifiex_ie_types_chan_band_list_param_set {
+       struct mwifiex_ie_types_header header;
+-      struct chan_band_param_set chan_band_param[1];
++      struct chan_band_param_set chan_band_param[];
+ } __packed;
+ struct mwifiex_ie_types_rates_param_set {
+@@ -886,7 +886,7 @@ struct mwifiex_ie_types_wildcard_ssid_pa
+ #define TSF_DATA_SIZE            8
+ struct mwifiex_ie_types_tsf_timestamp {
+       struct mwifiex_ie_types_header header;
+-      u8 tsf_data[1];
++      u8 tsf_data[];
+ } __packed;
+ struct mwifiex_cf_param_set {
+@@ -903,8 +903,8 @@ struct mwifiex_ibss_param_set {
+ struct mwifiex_ie_types_ss_param_set {
+       struct mwifiex_ie_types_header header;
+       union {
+-              struct mwifiex_cf_param_set cf_param_set[1];
+-              struct mwifiex_ibss_param_set ibss_param_set[1];
++              DECLARE_FLEX_ARRAY(struct mwifiex_cf_param_set, cf_param_set);
++              DECLARE_FLEX_ARRAY(struct mwifiex_ibss_param_set, ibss_param_set);
+       } cf_ibss;
+ } __packed;
+@@ -922,8 +922,8 @@ struct mwifiex_ds_param_set {
+ struct mwifiex_ie_types_phy_param_set {
+       struct mwifiex_ie_types_header header;
+       union {
+-              struct mwifiex_fh_param_set fh_param_set[1];
+-              struct mwifiex_ds_param_set ds_param_set[1];
++              DECLARE_FLEX_ARRAY(struct mwifiex_fh_param_set, fh_param_set);
++              DECLARE_FLEX_ARRAY(struct mwifiex_ds_param_set, ds_param_set);
+       } fh_ds;
+ } __packed;
+@@ -1383,7 +1383,7 @@ struct host_cmd_ds_802_11_snmp_mib {
+       __le16 query_type;
+       __le16 oid;
+       __le16 buf_size;
+-      u8 value[1];
++      u8 value[];
+ } __packed;
+ struct mwifiex_rate_scope {
+@@ -1551,7 +1551,7 @@ struct mwifiex_scan_cmd_config {
+        *  TLV_TYPE_CHANLIST, mwifiex_ie_types_chan_list_param_set
+        *  WLAN_EID_SSID, mwifiex_ie_types_ssid_param_set
+        */
+-      u8 tlv_buf[1];  /* SSID TLV(s) and ChanList TLVs are stored
++      u8 tlv_buf[];   /* SSID TLV(s) and ChanList TLVs are stored
+                                  here */
+ } __packed;
+@@ -1683,7 +1683,7 @@ struct host_cmd_ds_802_11_bg_scan_query_
+ struct mwifiex_ietypes_domain_param_set {
+       struct mwifiex_ie_types_header header;
+       u8 country_code[IEEE80211_COUNTRY_STRING_LEN];
+-      struct ieee80211_country_ie_triplet triplet[1];
++      struct ieee80211_country_ie_triplet triplet[];
+ } __packed;
+ struct host_cmd_ds_802_11d_domain_info {
+--- a/drivers/net/wireless/marvell/mwifiex/join.c
++++ b/drivers/net/wireless/marvell/mwifiex/join.c
+@@ -421,15 +421,15 @@ int mwifiex_cmd_802_11_associate(struct
+       phy_tlv = (struct mwifiex_ie_types_phy_param_set *) pos;
+       phy_tlv->header.type = cpu_to_le16(WLAN_EID_DS_PARAMS);
+-      phy_tlv->header.len = cpu_to_le16(sizeof(phy_tlv->fh_ds.ds_param_set));
+-      memcpy(&phy_tlv->fh_ds.ds_param_set,
++      phy_tlv->header.len = cpu_to_le16(sizeof(*phy_tlv->fh_ds.ds_param_set));
++      memcpy(phy_tlv->fh_ds.ds_param_set,
+              &bss_desc->phy_param_set.ds_param_set.current_chan,
+-             sizeof(phy_tlv->fh_ds.ds_param_set));
++             sizeof(*phy_tlv->fh_ds.ds_param_set));
+       pos += sizeof(phy_tlv->header) + le16_to_cpu(phy_tlv->header.len);
+       ss_tlv = (struct mwifiex_ie_types_ss_param_set *) pos;
+       ss_tlv->header.type = cpu_to_le16(WLAN_EID_CF_PARAMS);
+-      ss_tlv->header.len = cpu_to_le16(sizeof(ss_tlv->cf_ibss.cf_param_set));
++      ss_tlv->header.len = cpu_to_le16(sizeof(*ss_tlv->cf_ibss.cf_param_set));
+       pos += sizeof(ss_tlv->header) + le16_to_cpu(ss_tlv->header.len);
+       /* Get the common rates supported between the driver and the BSS Desc */
+--- a/drivers/net/wireless/marvell/mwifiex/sta_cmd.c
++++ b/drivers/net/wireless/marvell/mwifiex/sta_cmd.c
+@@ -108,7 +108,7 @@ static int mwifiex_cmd_802_11_snmp_mib(s
+                   "cmd: SNMP_CMD: cmd_oid = 0x%x\n", cmd_oid);
+       cmd->command = cpu_to_le16(HostCmd_CMD_802_11_SNMP_MIB);
+       cmd->size = cpu_to_le16(sizeof(struct host_cmd_ds_802_11_snmp_mib)
+-                              - 1 + S_DS_GEN);
++                              + S_DS_GEN);
+       snmp_mib->oid = cpu_to_le16((u16)cmd_oid);
+       if (cmd_action == HostCmd_ACT_GEN_GET) {