Commit 28a1bcdb authored by Johannes Berg's avatar Johannes Berg Committed by John W. Linville
Browse files

mac80211: fix offchannel TX cookie matching



When I introduced in-kernel off-channel TX I
introduced a bug -- the work can't be canceled
again because the code clear the skb pointer.
Fix this by keeping track separately of whether
TX status has already been reported.

Cc: stable@kernel.org [2.6.38+]
Reported-by: default avatarJouni Malinen <j@w1.fi>
Tested-by: default avatarJouni Malinen <j@w1.fi>
Signed-off-by: default avatarJohannes Berg <johannes.berg@intel.com>
Signed-off-by: default avatarJohn W. Linville <linville@tuxdriver.com>
parent af4dc88c
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -1886,7 +1886,7 @@ ieee80211_offchan_tx_done(struct ieee80211_work *wk, struct sk_buff *skb)
	 * so in that case userspace will have to deal with it.
	 */

	if (wk->offchan_tx.wait && wk->offchan_tx.frame)
	if (wk->offchan_tx.wait && !wk->offchan_tx.status)
		cfg80211_mgmt_tx_status(wk->sdata->dev,
					(unsigned long) wk->offchan_tx.frame,
					wk->ie, wk->ie_len, false, GFP_KERNEL);
+1 −0
Original line number Diff line number Diff line
@@ -346,6 +346,7 @@ struct ieee80211_work {
		struct {
			struct sk_buff *frame;
			u32 wait;
			bool status;
		} offchan_tx;
	};

+1 −1
Original line number Diff line number Diff line
@@ -429,7 +429,7 @@ void ieee80211_tx_status(struct ieee80211_hw *hw, struct sk_buff *skb)
				continue;
			if (wk->offchan_tx.frame != skb)
				continue;
			wk->offchan_tx.frame = NULL;
			wk->offchan_tx.status = true;
			break;
		}
		rcu_read_unlock();
+1 −1
Original line number Diff line number Diff line
@@ -577,7 +577,7 @@ ieee80211_offchannel_tx(struct ieee80211_work *wk)
		/*
		 * After this, offchan_tx.frame remains but now is no
		 * longer a valid pointer -- we still need it as the
		 * cookie for canceling this work.
		 * cookie for canceling this work/status matching.
		 */
		ieee80211_tx_skb(wk->sdata, wk->offchan_tx.frame);