• Paul Zhang's avatar
    wifi: cfg80211: Fix bitrates overflow issue · 18429c51
    Paul Zhang authored
    When invoking function cfg80211_calculate_bitrate_eht about
    (320 MHz, EHT-MCS 13, EHT-NSS 2, EHT-GI 0), which means the
    parameters as flags: 0x80, bw: 7, mcs: 13, eht_gi: 0, nss: 2,
    this formula (result * rate->nss) will overflow and causes
    the returned bitrate to be 3959 when it should be 57646.
    
    Here is the explanation:
     u64 tmp;
     u32 result;
     …
     /* tmp = result = 4 * rates_996[0]
      *     = 4 * 480388888 = 0x72889c60
      */
     tmp = result;
    
     /* tmp = 0x72889c60 * 6144 = 0xabccea90000 */
     tmp *= SCALE;
    
     /* tmp = 0xabccea90000 / mcs_divisors[13]
      *     = 0xabccea90000 / 5120 = 0x8970bba6
      */
     do_div(tmp, mcs_divisors[rate->mcs]);
    
     /* result = 0x8970bba6 */
     result = tmp;
    
     /* normally (result * rate->nss) = 0x8970bba6 * 2 = 0x112e1774c,
      * but since result is u32, (result * rate->nss) = 0x12e1774c,
      * overflow happens and it loses the highest bit.
      * Then result =  0x12e1774c / 8 = 39595753,
      */
     result = (result * rate->nss) / 8;
    Signed-off-by: default avatarPaul Zhang <quic_paulz@quicinc.com>
    Signed-off-by: default avatarJohannes Berg <johannes.berg@intel.com>
    18429c51
util.c 60.7 KB