]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
wifi: mwifiex: replace one-element arrays with flexible array members
authorGeorgi Valkov <gvalkov@gmail.com>
Thu, 16 Jul 2026 00:17:28 +0000 (03:17 +0300)
committerJohannes Berg <johannes.berg@intel.com>
Tue, 21 Jul 2026 11:29:30 +0000 (13:29 +0200)
Replace deprecated one-element arrays with flexible array members.
CONFIG_FORTIFY_SOURCE reports the following warning when
one-element arrays are used as variable-length buffers:

sta_cmd.c:1033 mwifiex_sta_prepare_cmd
memcpy: detected field-spanning write (size 84) of single field
"domain->triplet" at .../marvell/mwifiex/sta_cmd.c:1033 (size 3)

Convert affected structs to use flexible array members.
- Preserve existing wire layouts.
- Use DECLARE_FLEX_ARRAY() for structs inside affected unions.

Tested-on: WRT3200ACM, OpenWrt
Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
Reviewed-by: Francesco Dolcini <francesco.dolcini@toradex.com>
Link: https://patch.msgid.link/20260716001728.57799-1-gvalkov@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
drivers/net/wireless/marvell/mwifiex/fw.h
drivers/net/wireless/marvell/mwifiex/join.c
drivers/net/wireless/marvell/mwifiex/sta_cmd.c

index e9e8966069121b647bfd2b96878ee80959f6f7b6..93561116959ac3321f8a057268385cf00011560f 100644 (file)
@@ -823,7 +823,7 @@ struct chan_band_param_set {
 
 struct mwifiex_ie_types_chan_band_list_param_set {
        struct mwifiex_ie_types_header header;
-       struct chan_band_param_set chan_band_param[1];
+       struct chan_band_param_set chan_band_param[];
 } __packed;
 
 struct mwifiex_ie_types_rates_param_set {
@@ -886,7 +886,7 @@ struct mwifiex_ie_types_wildcard_ssid_params {
 #define TSF_DATA_SIZE            8
 struct mwifiex_ie_types_tsf_timestamp {
        struct mwifiex_ie_types_header header;
-       u8 tsf_data[1];
+       u8 tsf_data[];
 } __packed;
 
 struct mwifiex_cf_param_set {
@@ -903,8 +903,8 @@ struct mwifiex_ibss_param_set {
 struct mwifiex_ie_types_ss_param_set {
        struct mwifiex_ie_types_header header;
        union {
-               struct mwifiex_cf_param_set cf_param_set[1];
-               struct mwifiex_ibss_param_set ibss_param_set[1];
+               DECLARE_FLEX_ARRAY(struct mwifiex_cf_param_set, cf_param_set);
+               DECLARE_FLEX_ARRAY(struct mwifiex_ibss_param_set, ibss_param_set);
        } cf_ibss;
 } __packed;
 
@@ -922,8 +922,8 @@ struct mwifiex_ds_param_set {
 struct mwifiex_ie_types_phy_param_set {
        struct mwifiex_ie_types_header header;
        union {
-               struct mwifiex_fh_param_set fh_param_set[1];
-               struct mwifiex_ds_param_set ds_param_set[1];
+               DECLARE_FLEX_ARRAY(struct mwifiex_fh_param_set, fh_param_set);
+               DECLARE_FLEX_ARRAY(struct mwifiex_ds_param_set, ds_param_set);
        } fh_ds;
 } __packed;
 
@@ -1383,7 +1383,7 @@ struct host_cmd_ds_802_11_snmp_mib {
        __le16 query_type;
        __le16 oid;
        __le16 buf_size;
-       u8 value[1];
+       u8 value[];
 } __packed;
 
 struct mwifiex_rate_scope {
@@ -1551,7 +1551,7 @@ struct mwifiex_scan_cmd_config {
         *  TLV_TYPE_CHANLIST, mwifiex_ie_types_chan_list_param_set
         *  WLAN_EID_SSID, mwifiex_ie_types_ssid_param_set
         */
-       u8 tlv_buf[1];  /* SSID TLV(s) and ChanList TLVs are stored
+       u8 tlv_buf[];   /* SSID TLV(s) and ChanList TLVs are stored
                                   here */
 } __packed;
 
@@ -1683,7 +1683,7 @@ struct host_cmd_ds_802_11_bg_scan_query_rsp {
 struct mwifiex_ietypes_domain_param_set {
        struct mwifiex_ie_types_header header;
        u8 country_code[IEEE80211_COUNTRY_STRING_LEN];
-       struct ieee80211_country_ie_triplet triplet[1];
+       struct ieee80211_country_ie_triplet triplet[];
 } __packed;
 
 struct host_cmd_ds_802_11d_domain_info {
index b48f7febaf03fd55b401a634f280a3123afd193a..259140395d35327e7157a457ab16a3709c18b569 100644 (file)
@@ -421,15 +421,15 @@ int mwifiex_cmd_802_11_associate(struct mwifiex_private *priv,
 
        phy_tlv = (struct mwifiex_ie_types_phy_param_set *) pos;
        phy_tlv->header.type = cpu_to_le16(WLAN_EID_DS_PARAMS);
-       phy_tlv->header.len = cpu_to_le16(sizeof(phy_tlv->fh_ds.ds_param_set));
-       memcpy(&phy_tlv->fh_ds.ds_param_set,
+       phy_tlv->header.len = cpu_to_le16(sizeof(*phy_tlv->fh_ds.ds_param_set));
+       memcpy(phy_tlv->fh_ds.ds_param_set,
               &bss_desc->phy_param_set.ds_param_set.current_chan,
-              sizeof(phy_tlv->fh_ds.ds_param_set));
+              sizeof(*phy_tlv->fh_ds.ds_param_set));
        pos += sizeof(phy_tlv->header) + le16_to_cpu(phy_tlv->header.len);
 
        ss_tlv = (struct mwifiex_ie_types_ss_param_set *) pos;
        ss_tlv->header.type = cpu_to_le16(WLAN_EID_CF_PARAMS);
-       ss_tlv->header.len = cpu_to_le16(sizeof(ss_tlv->cf_ibss.cf_param_set));
+       ss_tlv->header.len = cpu_to_le16(sizeof(*ss_tlv->cf_ibss.cf_param_set));
        pos += sizeof(ss_tlv->header) + le16_to_cpu(ss_tlv->header.len);
 
        /* Get the common rates supported between the driver and the BSS Desc */
index 623ddde8c8e59003b3dda66e300f61587249b0f5..071f7cb305e1b71166e397c1377a9c3deef4ed03 100644 (file)
@@ -108,7 +108,7 @@ static int mwifiex_cmd_802_11_snmp_mib(struct mwifiex_private *priv,
                    "cmd: SNMP_CMD: cmd_oid = 0x%x\n", cmd_oid);
        cmd->command = cpu_to_le16(HostCmd_CMD_802_11_SNMP_MIB);
        cmd->size = cpu_to_le16(sizeof(struct host_cmd_ds_802_11_snmp_mib)
-                               - 1 + S_DS_GEN);
+                               + S_DS_GEN);
 
        snmp_mib->oid = cpu_to_le16((u16)cmd_oid);
        if (cmd_action == HostCmd_ACT_GEN_GET) {