Commit 4641f8a0 authored by Johannes Berg's avatar Johannes Berg Committed by Greg Kroah-Hartman

mac80211: fix offchannel TX cookie matching

commit 28a1bcdb upstream.

When I introduced in-kernel off-channel TX I
introduced a bug -- the work can't be canceled
again because the code clear the skb pointer.
Fix this by keeping track separately of whether
TX status has already been reported.
Reported-by: default avatarJouni Malinen <j@w1.fi>
Tested-by: default avatarJouni Malinen <j@w1.fi>
Signed-off-by: default avatarJohannes Berg <johannes.berg@intel.com>
Signed-off-by: default avatarJohn W. Linville <linville@tuxdriver.com>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@suse.de>
parent 806aeb92
...@@ -1798,7 +1798,7 @@ ieee80211_offchan_tx_done(struct ieee80211_work *wk, struct sk_buff *skb) ...@@ -1798,7 +1798,7 @@ ieee80211_offchan_tx_done(struct ieee80211_work *wk, struct sk_buff *skb)
* so in that case userspace will have to deal with it. * so in that case userspace will have to deal with it.
*/ */
if (wk->offchan_tx.wait && wk->offchan_tx.frame) if (wk->offchan_tx.wait && !wk->offchan_tx.status)
cfg80211_mgmt_tx_status(wk->sdata->dev, cfg80211_mgmt_tx_status(wk->sdata->dev,
(unsigned long) wk->offchan_tx.frame, (unsigned long) wk->offchan_tx.frame,
wk->ie, wk->ie_len, false, GFP_KERNEL); wk->ie, wk->ie_len, false, GFP_KERNEL);
......
...@@ -328,6 +328,7 @@ struct ieee80211_work { ...@@ -328,6 +328,7 @@ struct ieee80211_work {
struct { struct {
struct sk_buff *frame; struct sk_buff *frame;
u32 wait; u32 wait;
bool status;
} offchan_tx; } offchan_tx;
}; };
......
...@@ -336,7 +336,7 @@ void ieee80211_tx_status(struct ieee80211_hw *hw, struct sk_buff *skb) ...@@ -336,7 +336,7 @@ void ieee80211_tx_status(struct ieee80211_hw *hw, struct sk_buff *skb)
continue; continue;
if (wk->offchan_tx.frame != skb) if (wk->offchan_tx.frame != skb)
continue; continue;
wk->offchan_tx.frame = NULL; wk->offchan_tx.status = true;
break; break;
} }
rcu_read_unlock(); rcu_read_unlock();
......
...@@ -553,7 +553,7 @@ ieee80211_offchannel_tx(struct ieee80211_work *wk) ...@@ -553,7 +553,7 @@ ieee80211_offchannel_tx(struct ieee80211_work *wk)
/* /*
* After this, offchan_tx.frame remains but now is no * After this, offchan_tx.frame remains but now is no
* longer a valid pointer -- we still need it as the * longer a valid pointer -- we still need it as the
* cookie for canceling this work. * cookie for canceling this work/status matching.
*/ */
ieee80211_tx_skb(wk->sdata, wk->offchan_tx.frame); ieee80211_tx_skb(wk->sdata, wk->offchan_tx.frame);
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment