From: Georgi Valkov Date: Thu, 16 Jul 2026 09:28:00 +0000 (+0300) Subject: mac80211: mwifiex: replace one-element arrays with flexible array members X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=refs%2Fpull%2F24451%2Fhead;p=thirdparty%2Fopenwrt.git mac80211: mwifiex: replace one-element arrays with flexible array members Replace deprecated one-element arrays with flexible array members. CONFIG_FORTIFY_SOURCE reports the following warning when one-element arrays are used as variable-length buffers: sta_cmd.c:1033 mwifiex_sta_prepare_cmd memcpy: detected field-spanning write (size 84) of single field "domain->triplet" at .../marvell/mwifiex/sta_cmd.c:1033 (size 3) Convert affected structs to use flexible array members. - Preserve existing wire layouts. - Use DECLARE_FLEX_ARRAY() for structs inside affected unions. This fix has been accepted upstream: https://github.com/torvalds/linux/commit/1cb5845a58d8e1f85d5766c6fbcbfddf96c212a1 Tested-on: WRT3200ACM Signed-off-by: Georgi Valkov Link: https://github.com/openwrt/openwrt/pull/24451 Signed-off-by: Jonas Jelonek --- diff --git a/package/kernel/mac80211/Makefile b/package/kernel/mac80211/Makefile index f96317a9d5a..61943b4a089 100644 --- a/package/kernel/mac80211/Makefile +++ b/package/kernel/mac80211/Makefile @@ -11,7 +11,7 @@ include $(INCLUDE_DIR)/kernel.mk PKG_NAME:=mac80211 PKG_VERSION:=6.18.39 -PKG_RELEASE:=2 +PKG_RELEASE:=3 PKG_LICENSE:=GPL-2.0-only PKG_LICENSE_FILES:=COPYING diff --git a/package/kernel/mac80211/patches/mwl/111-wifi-mwifiex-replace-one-element-arrays-with-flexibl.patch b/package/kernel/mac80211/patches/mwl/111-wifi-mwifiex-replace-one-element-arrays-with-flexibl.patch new file mode 100644 index 00000000000..62c38d7c020 --- /dev/null +++ b/package/kernel/mac80211/patches/mwl/111-wifi-mwifiex-replace-one-element-arrays-with-flexibl.patch @@ -0,0 +1,131 @@ +From 1cb5845a58d8e1f85d5766c6fbcbfddf96c212a1 Mon Sep 17 00:00:00 2001 +From: Georgi Valkov +Date: Thu, 16 Jul 2026 03:17:28 +0300 +Subject: [PATCH] wifi: mwifiex: replace one-element arrays with flexible array + members + +Replace deprecated one-element arrays with flexible array members. +CONFIG_FORTIFY_SOURCE reports the following warning when +one-element arrays are used as variable-length buffers: + +sta_cmd.c:1033 mwifiex_sta_prepare_cmd +memcpy: detected field-spanning write (size 84) of single field +"domain->triplet" at .../marvell/mwifiex/sta_cmd.c:1033 (size 3) + +Convert affected structs to use flexible array members. +- Preserve existing wire layouts. +- Use DECLARE_FLEX_ARRAY() for structs inside affected unions. + +Tested-on: WRT3200ACM, OpenWrt +Signed-off-by: Georgi Valkov +Reviewed-by: Francesco Dolcini +Link: https://patch.msgid.link/20260716001728.57799-1-gvalkov@gmail.com +Signed-off-by: Johannes Berg +--- + drivers/net/wireless/marvell/mwifiex/fw.h | 18 +++++++++--------- + drivers/net/wireless/marvell/mwifiex/join.c | 8 ++++---- + drivers/net/wireless/marvell/mwifiex/sta_cmd.c | 2 +- + 3 files changed, 14 insertions(+), 14 deletions(-) + +--- a/drivers/net/wireless/marvell/mwifiex/fw.h ++++ b/drivers/net/wireless/marvell/mwifiex/fw.h +@@ -823,7 +823,7 @@ struct chan_band_param_set { + + struct mwifiex_ie_types_chan_band_list_param_set { + struct mwifiex_ie_types_header header; +- struct chan_band_param_set chan_band_param[1]; ++ struct chan_band_param_set chan_band_param[]; + } __packed; + + struct mwifiex_ie_types_rates_param_set { +@@ -886,7 +886,7 @@ struct mwifiex_ie_types_wildcard_ssid_pa + #define TSF_DATA_SIZE 8 + struct mwifiex_ie_types_tsf_timestamp { + struct mwifiex_ie_types_header header; +- u8 tsf_data[1]; ++ u8 tsf_data[]; + } __packed; + + struct mwifiex_cf_param_set { +@@ -903,8 +903,8 @@ struct mwifiex_ibss_param_set { + struct mwifiex_ie_types_ss_param_set { + struct mwifiex_ie_types_header header; + union { +- struct mwifiex_cf_param_set cf_param_set[1]; +- struct mwifiex_ibss_param_set ibss_param_set[1]; ++ DECLARE_FLEX_ARRAY(struct mwifiex_cf_param_set, cf_param_set); ++ DECLARE_FLEX_ARRAY(struct mwifiex_ibss_param_set, ibss_param_set); + } cf_ibss; + } __packed; + +@@ -922,8 +922,8 @@ struct mwifiex_ds_param_set { + struct mwifiex_ie_types_phy_param_set { + struct mwifiex_ie_types_header header; + union { +- struct mwifiex_fh_param_set fh_param_set[1]; +- struct mwifiex_ds_param_set ds_param_set[1]; ++ DECLARE_FLEX_ARRAY(struct mwifiex_fh_param_set, fh_param_set); ++ DECLARE_FLEX_ARRAY(struct mwifiex_ds_param_set, ds_param_set); + } fh_ds; + } __packed; + +@@ -1383,7 +1383,7 @@ struct host_cmd_ds_802_11_snmp_mib { + __le16 query_type; + __le16 oid; + __le16 buf_size; +- u8 value[1]; ++ u8 value[]; + } __packed; + + struct mwifiex_rate_scope { +@@ -1551,7 +1551,7 @@ struct mwifiex_scan_cmd_config { + * TLV_TYPE_CHANLIST, mwifiex_ie_types_chan_list_param_set + * WLAN_EID_SSID, mwifiex_ie_types_ssid_param_set + */ +- u8 tlv_buf[1]; /* SSID TLV(s) and ChanList TLVs are stored ++ u8 tlv_buf[]; /* SSID TLV(s) and ChanList TLVs are stored + here */ + } __packed; + +@@ -1683,7 +1683,7 @@ struct host_cmd_ds_802_11_bg_scan_query_ + struct mwifiex_ietypes_domain_param_set { + struct mwifiex_ie_types_header header; + u8 country_code[IEEE80211_COUNTRY_STRING_LEN]; +- struct ieee80211_country_ie_triplet triplet[1]; ++ struct ieee80211_country_ie_triplet triplet[]; + } __packed; + + struct host_cmd_ds_802_11d_domain_info { +--- a/drivers/net/wireless/marvell/mwifiex/join.c ++++ b/drivers/net/wireless/marvell/mwifiex/join.c +@@ -421,15 +421,15 @@ int mwifiex_cmd_802_11_associate(struct + + phy_tlv = (struct mwifiex_ie_types_phy_param_set *) pos; + phy_tlv->header.type = cpu_to_le16(WLAN_EID_DS_PARAMS); +- phy_tlv->header.len = cpu_to_le16(sizeof(phy_tlv->fh_ds.ds_param_set)); +- memcpy(&phy_tlv->fh_ds.ds_param_set, ++ phy_tlv->header.len = cpu_to_le16(sizeof(*phy_tlv->fh_ds.ds_param_set)); ++ memcpy(phy_tlv->fh_ds.ds_param_set, + &bss_desc->phy_param_set.ds_param_set.current_chan, +- sizeof(phy_tlv->fh_ds.ds_param_set)); ++ sizeof(*phy_tlv->fh_ds.ds_param_set)); + pos += sizeof(phy_tlv->header) + le16_to_cpu(phy_tlv->header.len); + + ss_tlv = (struct mwifiex_ie_types_ss_param_set *) pos; + ss_tlv->header.type = cpu_to_le16(WLAN_EID_CF_PARAMS); +- ss_tlv->header.len = cpu_to_le16(sizeof(ss_tlv->cf_ibss.cf_param_set)); ++ ss_tlv->header.len = cpu_to_le16(sizeof(*ss_tlv->cf_ibss.cf_param_set)); + pos += sizeof(ss_tlv->header) + le16_to_cpu(ss_tlv->header.len); + + /* Get the common rates supported between the driver and the BSS Desc */ +--- a/drivers/net/wireless/marvell/mwifiex/sta_cmd.c ++++ b/drivers/net/wireless/marvell/mwifiex/sta_cmd.c +@@ -108,7 +108,7 @@ static int mwifiex_cmd_802_11_snmp_mib(s + "cmd: SNMP_CMD: cmd_oid = 0x%x\n", cmd_oid); + cmd->command = cpu_to_le16(HostCmd_CMD_802_11_SNMP_MIB); + cmd->size = cpu_to_le16(sizeof(struct host_cmd_ds_802_11_snmp_mib) +- - 1 + S_DS_GEN); ++ + S_DS_GEN); + + snmp_mib->oid = cpu_to_le16((u16)cmd_oid); + if (cmd_action == HostCmd_ACT_GEN_GET) {