Commit fd4f84fa authored by Linus Torvalds's avatar Linus Torvalds

Merge tag 'staging-4.18-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/staging

Pull staging driver fixes from Greg KH:
 "Here are three small staging driver fixes for 4.18-rc7.

  One is a revert of an earlier patch that turned out to be incorrect,
  one is a fix for the speakup drivers, and the last a fix for the
  ks7010 driver to resolve a regression.

  All of these have been in linux-next for a while with no reported
  issues"

* tag 'staging-4.18-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/gregkh/staging:
  staging: speakup: fix wraparound in uaccess length check
  staging: ks7010: call 'hostif_mib_set_request_int' instead of 'hostif_mib_set_request_bool'
  Revert "staging:r8188eu: Use lib80211 to support TKIP"
parents a5f9e5da b96fba8d
...@@ -1842,14 +1842,14 @@ void hostif_sme_multicast_set(struct ks_wlan_private *priv) ...@@ -1842,14 +1842,14 @@ void hostif_sme_multicast_set(struct ks_wlan_private *priv)
memset(set_address, 0, NIC_MAX_MCAST_LIST * ETH_ALEN); memset(set_address, 0, NIC_MAX_MCAST_LIST * ETH_ALEN);
if (dev->flags & IFF_PROMISC) { if (dev->flags & IFF_PROMISC) {
hostif_mib_set_request_bool(priv, LOCAL_MULTICAST_FILTER, hostif_mib_set_request_int(priv, LOCAL_MULTICAST_FILTER,
MCAST_FILTER_PROMISC); MCAST_FILTER_PROMISC);
goto spin_unlock; goto spin_unlock;
} }
if ((netdev_mc_count(dev) > NIC_MAX_MCAST_LIST) || if ((netdev_mc_count(dev) > NIC_MAX_MCAST_LIST) ||
(dev->flags & IFF_ALLMULTI)) { (dev->flags & IFF_ALLMULTI)) {
hostif_mib_set_request_bool(priv, LOCAL_MULTICAST_FILTER, hostif_mib_set_request_int(priv, LOCAL_MULTICAST_FILTER,
MCAST_FILTER_MCASTALL); MCAST_FILTER_MCASTALL);
goto spin_unlock; goto spin_unlock;
} }
...@@ -1866,7 +1866,7 @@ void hostif_sme_multicast_set(struct ks_wlan_private *priv) ...@@ -1866,7 +1866,7 @@ void hostif_sme_multicast_set(struct ks_wlan_private *priv)
ETH_ALEN * mc_count); ETH_ALEN * mc_count);
} else { } else {
priv->sme_i.sme_flag |= SME_MULTICAST; priv->sme_i.sme_flag |= SME_MULTICAST;
hostif_mib_set_request_bool(priv, LOCAL_MULTICAST_FILTER, hostif_mib_set_request_int(priv, LOCAL_MULTICAST_FILTER,
MCAST_FILTER_MCAST); MCAST_FILTER_MCAST);
} }
......
...@@ -7,7 +7,6 @@ config R8188EU ...@@ -7,7 +7,6 @@ config R8188EU
select LIB80211 select LIB80211
select LIB80211_CRYPT_WEP select LIB80211_CRYPT_WEP
select LIB80211_CRYPT_CCMP select LIB80211_CRYPT_CCMP
select LIB80211_CRYPT_TKIP
---help--- ---help---
This option adds the Realtek RTL8188EU USB device such as TP-Link TL-WN725N. This option adds the Realtek RTL8188EU USB device such as TP-Link TL-WN725N.
If built as a module, it will be called r8188eu. If built as a module, it will be called r8188eu.
......
...@@ -23,7 +23,6 @@ ...@@ -23,7 +23,6 @@
#include <mon.h> #include <mon.h>
#include <wifi.h> #include <wifi.h>
#include <linux/vmalloc.h> #include <linux/vmalloc.h>
#include <net/lib80211.h>
#define ETHERNET_HEADER_SIZE 14 /* Ethernet Header Length */ #define ETHERNET_HEADER_SIZE 14 /* Ethernet Header Length */
#define LLC_HEADER_SIZE 6 /* LLC Header Length */ #define LLC_HEADER_SIZE 6 /* LLC Header Length */
...@@ -221,20 +220,31 @@ u32 rtw_free_uc_swdec_pending_queue(struct adapter *adapter) ...@@ -221,20 +220,31 @@ u32 rtw_free_uc_swdec_pending_queue(struct adapter *adapter)
static int recvframe_chkmic(struct adapter *adapter, static int recvframe_chkmic(struct adapter *adapter,
struct recv_frame *precvframe) struct recv_frame *precvframe)
{ {
int res = _SUCCESS; int i, res = _SUCCESS;
u32 datalen;
u8 miccode[8];
u8 bmic_err = false, brpt_micerror = true;
u8 *pframe, *payload, *pframemic;
u8 *mickey;
struct sta_info *stainfo;
struct rx_pkt_attrib *prxattrib = &precvframe->attrib; struct rx_pkt_attrib *prxattrib = &precvframe->attrib;
struct sta_info *stainfo = rtw_get_stainfo(&adapter->stapriv, prxattrib->ta); struct security_priv *psecuritypriv = &adapter->securitypriv;
struct mlme_ext_priv *pmlmeext = &adapter->mlmeextpriv;
struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
stainfo = rtw_get_stainfo(&adapter->stapriv, &prxattrib->ta[0]);
if (prxattrib->encrypt == _TKIP_) { if (prxattrib->encrypt == _TKIP_) {
if (stainfo) { RT_TRACE(_module_rtl871x_recv_c_, _drv_info_,
int key_idx; ("\n %s: prxattrib->encrypt==_TKIP_\n", __func__));
const int iv_len = 8, icv_len = 4, key_length = 32; RT_TRACE(_module_rtl871x_recv_c_, _drv_info_,
struct sk_buff *skb = precvframe->pkt; ("\n %s: da=0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x\n",
u8 key[32], iv[8], icv[4], *pframe = skb->data; __func__, prxattrib->ra[0], prxattrib->ra[1], prxattrib->ra[2],
void *crypto_private = NULL; prxattrib->ra[3], prxattrib->ra[4], prxattrib->ra[5]));
struct lib80211_crypto_ops *crypto_ops = try_then_request_module(lib80211_get_crypto_ops("TKIP"), "lib80211_crypt_tkip");
struct security_priv *psecuritypriv = &adapter->securitypriv;
/* calculate mic code */
if (stainfo) {
if (IS_MCAST(prxattrib->ra)) { if (IS_MCAST(prxattrib->ra)) {
if (!psecuritypriv) { if (!psecuritypriv) {
res = _FAIL; res = _FAIL;
...@@ -243,58 +253,115 @@ static int recvframe_chkmic(struct adapter *adapter, ...@@ -243,58 +253,115 @@ static int recvframe_chkmic(struct adapter *adapter,
DBG_88E("\n %s: didn't install group key!!!!!!!!!!\n", __func__); DBG_88E("\n %s: didn't install group key!!!!!!!!!!\n", __func__);
goto exit; goto exit;
} }
key_idx = prxattrib->key_index; mickey = &psecuritypriv->dot118021XGrprxmickey[prxattrib->key_index].skey[0];
memcpy(key, psecuritypriv->dot118021XGrpKey[key_idx].skey, 16);
memcpy(key + 16, psecuritypriv->dot118021XGrprxmickey[key_idx].skey, 16); RT_TRACE(_module_rtl871x_recv_c_, _drv_info_,
("\n %s: bcmc key\n", __func__));
} else { } else {
key_idx = 0; mickey = &stainfo->dot11tkiprxmickey.skey[0];
memcpy(key, stainfo->dot118021x_UncstKey.skey, 16); RT_TRACE(_module_rtl871x_recv_c_, _drv_err_,
memcpy(key + 16, stainfo->dot11tkiprxmickey.skey, 16); ("\n %s: unicast key\n", __func__));
} }
if (!crypto_ops) { /* icv_len included the mic code */
res = _FAIL; datalen = precvframe->pkt->len-prxattrib->hdrlen -
goto exit_lib80211_tkip; prxattrib->iv_len-prxattrib->icv_len-8;
} pframe = precvframe->pkt->data;
payload = pframe+prxattrib->hdrlen+prxattrib->iv_len;
memcpy(iv, pframe + prxattrib->hdrlen, iv_len); RT_TRACE(_module_rtl871x_recv_c_, _drv_info_, ("\n prxattrib->iv_len=%d prxattrib->icv_len=%d\n", prxattrib->iv_len, prxattrib->icv_len));
memcpy(icv, pframe + skb->len - icv_len, icv_len); rtw_seccalctkipmic(mickey, pframe, payload, datalen, &miccode[0],
memmove(pframe + iv_len, pframe, prxattrib->hdrlen); (unsigned char)prxattrib->priority); /* care the length of the data */
skb_pull(skb, iv_len); pframemic = payload+datalen;
skb_trim(skb, skb->len - icv_len);
crypto_private = crypto_ops->init(key_idx); bmic_err = false;
if (!crypto_private) {
res = _FAIL; for (i = 0; i < 8; i++) {
goto exit_lib80211_tkip; if (miccode[i] != *(pframemic+i)) {
} RT_TRACE(_module_rtl871x_recv_c_, _drv_err_,
if (crypto_ops->set_key(key, key_length, NULL, crypto_private) < 0) { ("%s: miccode[%d](%02x)!=*(pframemic+%d)(%02x) ",
res = _FAIL; __func__, i, miccode[i], i, *(pframemic + i)));
goto exit_lib80211_tkip; bmic_err = true;
} }
if (crypto_ops->decrypt_msdu(skb, key_idx, prxattrib->hdrlen, crypto_private)) {
res = _FAIL;
goto exit_lib80211_tkip;
} }
memmove(pframe, pframe + iv_len, prxattrib->hdrlen); if (bmic_err) {
skb_push(skb, iv_len); RT_TRACE(_module_rtl871x_recv_c_, _drv_err_,
skb_put(skb, icv_len); ("\n *(pframemic-8)-*(pframemic-1)=0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x\n",
*(pframemic-8), *(pframemic-7), *(pframemic-6),
*(pframemic-5), *(pframemic-4), *(pframemic-3),
*(pframemic-2), *(pframemic-1)));
RT_TRACE(_module_rtl871x_recv_c_, _drv_err_,
("\n *(pframemic-16)-*(pframemic-9)=0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x\n",
*(pframemic-16), *(pframemic-15), *(pframemic-14),
*(pframemic-13), *(pframemic-12), *(pframemic-11),
*(pframemic-10), *(pframemic-9)));
{
uint i;
memcpy(pframe + prxattrib->hdrlen, iv, iv_len); RT_TRACE(_module_rtl871x_recv_c_, _drv_err_,
memcpy(pframe + skb->len - icv_len, icv, icv_len); ("\n ======demp packet (len=%d)======\n",
precvframe->pkt->len));
for (i = 0; i < precvframe->pkt->len; i += 8) {
RT_TRACE(_module_rtl871x_recv_c_,
_drv_err_,
("0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x:0x%02x",
*(precvframe->pkt->data+i),
*(precvframe->pkt->data+i+1),
*(precvframe->pkt->data+i+2),
*(precvframe->pkt->data+i+3),
*(precvframe->pkt->data+i+4),
*(precvframe->pkt->data+i+5),
*(precvframe->pkt->data+i+6),
*(precvframe->pkt->data+i+7)));
}
RT_TRACE(_module_rtl871x_recv_c_,
_drv_err_,
("\n ====== demp packet end [len=%d]======\n",
precvframe->pkt->len));
RT_TRACE(_module_rtl871x_recv_c_,
_drv_err_,
("\n hrdlen=%d,\n",
prxattrib->hdrlen));
}
exit_lib80211_tkip: RT_TRACE(_module_rtl871x_recv_c_, _drv_err_,
if (crypto_ops && crypto_private) ("ra=0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x 0x%.2x psecuritypriv->binstallGrpkey=%d ",
crypto_ops->deinit(crypto_private); prxattrib->ra[0], prxattrib->ra[1], prxattrib->ra[2],
prxattrib->ra[3], prxattrib->ra[4], prxattrib->ra[5], psecuritypriv->binstallGrpkey));
/* double check key_index for some timing issue , */
/* cannot compare with psecuritypriv->dot118021XGrpKeyid also cause timing issue */
if ((IS_MCAST(prxattrib->ra) == true) && (prxattrib->key_index != pmlmeinfo->key_index))
brpt_micerror = false;
if ((prxattrib->bdecrypted) && (brpt_micerror)) {
rtw_handle_tkip_mic_err(adapter, (u8)IS_MCAST(prxattrib->ra));
RT_TRACE(_module_rtl871x_recv_c_, _drv_err_, (" mic error :prxattrib->bdecrypted=%d ", prxattrib->bdecrypted));
DBG_88E(" mic error :prxattrib->bdecrypted=%d\n", prxattrib->bdecrypted);
} else {
RT_TRACE(_module_rtl871x_recv_c_, _drv_err_, (" mic error :prxattrib->bdecrypted=%d ", prxattrib->bdecrypted));
DBG_88E(" mic error :prxattrib->bdecrypted=%d\n", prxattrib->bdecrypted);
}
res = _FAIL;
} else {
/* mic checked ok */
if ((!psecuritypriv->bcheck_grpkey) && (IS_MCAST(prxattrib->ra))) {
psecuritypriv->bcheck_grpkey = true;
RT_TRACE(_module_rtl871x_recv_c_, _drv_err_, ("psecuritypriv->bcheck_grpkey = true"));
}
}
} else { } else {
RT_TRACE(_module_rtl871x_recv_c_, _drv_err_, RT_TRACE(_module_rtl871x_recv_c_, _drv_err_,
("%s: rtw_get_stainfo==NULL!!!\n", __func__)); ("%s: rtw_get_stainfo==NULL!!!\n", __func__));
} }
skb_trim(precvframe->pkt, precvframe->pkt->len - 8);
} }
exit: exit:
return res; return res;
} }
......
...@@ -650,71 +650,71 @@ u32 rtw_tkip_encrypt(struct adapter *padapter, u8 *pxmitframe) ...@@ -650,71 +650,71 @@ u32 rtw_tkip_encrypt(struct adapter *padapter, u8 *pxmitframe)
return res; return res;
} }
/* The hlen isn't include the IV */
u32 rtw_tkip_decrypt(struct adapter *padapter, u8 *precvframe) u32 rtw_tkip_decrypt(struct adapter *padapter, u8 *precvframe)
{ { /* exclude ICV */
u16 pnl;
u32 pnh;
u8 rc4key[16];
u8 ttkey[16];
u8 crc[4];
struct arc4context mycontext;
int length;
u8 *pframe, *payload, *iv, *prwskey;
union pn48 dot11txpn;
struct sta_info *stainfo;
struct rx_pkt_attrib *prxattrib = &((struct recv_frame *)precvframe)->attrib; struct rx_pkt_attrib *prxattrib = &((struct recv_frame *)precvframe)->attrib;
struct security_priv *psecuritypriv = &padapter->securitypriv;
u32 res = _SUCCESS; u32 res = _SUCCESS;
pframe = (unsigned char *)((struct recv_frame *)precvframe)->pkt->data;
/* 4 start to decrypt recvframe */ /* 4 start to decrypt recvframe */
if (prxattrib->encrypt == _TKIP_) { if (prxattrib->encrypt == _TKIP_) {
struct sta_info *stainfo = rtw_get_stainfo(&padapter->stapriv, prxattrib->ta); stainfo = rtw_get_stainfo(&padapter->stapriv, &prxattrib->ta[0]);
if (stainfo) { if (stainfo) {
int key_idx;
const int iv_len = 8, icv_len = 4, key_length = 32;
void *crypto_private = NULL;
struct sk_buff *skb = ((struct recv_frame *)precvframe)->pkt;
u8 key[32], iv[8], icv[4], *pframe = skb->data;
struct lib80211_crypto_ops *crypto_ops = try_then_request_module(lib80211_get_crypto_ops("TKIP"), "lib80211_crypt_tkip");
struct security_priv *psecuritypriv = &padapter->securitypriv;
if (IS_MCAST(prxattrib->ra)) { if (IS_MCAST(prxattrib->ra)) {
if (!psecuritypriv->binstallGrpkey) { if (!psecuritypriv->binstallGrpkey) {
res = _FAIL; res = _FAIL;
DBG_88E("%s:rx bc/mc packets, but didn't install group key!!!!!!!!!!\n", __func__); DBG_88E("%s:rx bc/mc packets, but didn't install group key!!!!!!!!!!\n", __func__);
goto exit; goto exit;
} }
key_idx = prxattrib->key_index; prwskey = psecuritypriv->dot118021XGrpKey[prxattrib->key_index].skey;
memcpy(key, psecuritypriv->dot118021XGrpKey[key_idx].skey, 16);
memcpy(key + 16, psecuritypriv->dot118021XGrprxmickey[key_idx].skey, 16);
} else { } else {
key_idx = 0; RT_TRACE(_module_rtl871x_security_c_, _drv_err_, ("%s: stainfo!= NULL!!!\n", __func__));
memcpy(key, stainfo->dot118021x_UncstKey.skey, 16); prwskey = &stainfo->dot118021x_UncstKey.skey[0];
memcpy(key + 16, stainfo->dot11tkiprxmickey.skey, 16);
} }
if (!crypto_ops) { iv = pframe+prxattrib->hdrlen;
res = _FAIL; payload = pframe+prxattrib->iv_len+prxattrib->hdrlen;
goto exit_lib80211_tkip; length = ((struct recv_frame *)precvframe)->pkt->len-prxattrib->hdrlen-prxattrib->iv_len;
}
memcpy(iv, pframe + prxattrib->hdrlen, iv_len); GET_TKIP_PN(iv, dot11txpn);
memcpy(icv, pframe + skb->len - icv_len, icv_len);
crypto_private = crypto_ops->init(key_idx); pnl = (u16)(dot11txpn.val);
if (!crypto_private) { pnh = (u32)(dot11txpn.val>>16);
res = _FAIL;
goto exit_lib80211_tkip;
}
if (crypto_ops->set_key(key, key_length, NULL, crypto_private) < 0) {
res = _FAIL;
goto exit_lib80211_tkip;
}
if (crypto_ops->decrypt_mpdu(skb, prxattrib->hdrlen, crypto_private)) {
res = _FAIL;
goto exit_lib80211_tkip;
}
memmove(pframe, pframe + iv_len, prxattrib->hdrlen); phase1((u16 *)&ttkey[0], prwskey, &prxattrib->ta[0], pnh);
skb_push(skb, iv_len); phase2(&rc4key[0], prwskey, (unsigned short *)&ttkey[0], pnl);
skb_put(skb, icv_len);
memcpy(pframe + prxattrib->hdrlen, iv, iv_len); /* 4 decrypt payload include icv */
memcpy(pframe + skb->len - icv_len, icv, icv_len);
exit_lib80211_tkip: arcfour_init(&mycontext, rc4key, 16);
if (crypto_ops && crypto_private) arcfour_encrypt(&mycontext, payload, payload, length);
crypto_ops->deinit(crypto_private);
*((__le32 *)crc) = getcrc32(payload, length-4);
if (crc[3] != payload[length-1] ||
crc[2] != payload[length-2] ||
crc[1] != payload[length-3] ||
crc[0] != payload[length-4]) {
RT_TRACE(_module_rtl871x_security_c_, _drv_err_,
("rtw_wep_decrypt:icv error crc (%4ph)!=payload (%4ph)\n",
&crc, &payload[length-4]));
res = _FAIL;
}
} else { } else {
RT_TRACE(_module_rtl871x_security_c_, _drv_err_, ("rtw_tkip_decrypt: stainfo==NULL!!!\n")); RT_TRACE(_module_rtl871x_security_c_, _drv_err_, ("rtw_tkip_decrypt: stainfo==NULL!!!\n"));
res = _FAIL; res = _FAIL;
......
...@@ -198,11 +198,15 @@ static ssize_t softsynthx_read(struct file *fp, char __user *buf, size_t count, ...@@ -198,11 +198,15 @@ static ssize_t softsynthx_read(struct file *fp, char __user *buf, size_t count,
int chars_sent = 0; int chars_sent = 0;
char __user *cp; char __user *cp;
char *init; char *init;
size_t bytes_per_ch = unicode ? 3 : 1;
u16 ch; u16 ch;
int empty; int empty;
unsigned long flags; unsigned long flags;
DEFINE_WAIT(wait); DEFINE_WAIT(wait);
if (count < bytes_per_ch)
return -EINVAL;
spin_lock_irqsave(&speakup_info.spinlock, flags); spin_lock_irqsave(&speakup_info.spinlock, flags);
while (1) { while (1) {
prepare_to_wait(&speakup_event, &wait, TASK_INTERRUPTIBLE); prepare_to_wait(&speakup_event, &wait, TASK_INTERRUPTIBLE);
...@@ -228,7 +232,7 @@ static ssize_t softsynthx_read(struct file *fp, char __user *buf, size_t count, ...@@ -228,7 +232,7 @@ static ssize_t softsynthx_read(struct file *fp, char __user *buf, size_t count,
init = get_initstring(); init = get_initstring();
/* Keep 3 bytes available for a 16bit UTF-8-encoded character */ /* Keep 3 bytes available for a 16bit UTF-8-encoded character */
while (chars_sent <= count - 3) { while (chars_sent <= count - bytes_per_ch) {
if (speakup_info.flushing) { if (speakup_info.flushing) {
speakup_info.flushing = 0; speakup_info.flushing = 0;
ch = '\x18'; ch = '\x18';
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment