From: Felix Fietkau Date: Sat, 14 Jan 2017 17:02:54 +0000 (+0100) Subject: mac80211: backport a fix for a tx related race condition X-Git-Url: http://demsky.eecs.uci.edu/git/?a=commitdiff_plain;h=e7e91e62bb68d907b6d7f7d95c8e6c076fda985e;p=lede.git mac80211: backport a fix for a tx related race condition Signed-off-by: Felix Fietkau --- diff --git a/package/kernel/mac80211/patches/352-mac80211-prevent-skb-txq-mismatch.patch b/package/kernel/mac80211/patches/352-mac80211-prevent-skb-txq-mismatch.patch new file mode 100644 index 0000000000..3822026352 --- /dev/null +++ b/package/kernel/mac80211/patches/352-mac80211-prevent-skb-txq-mismatch.patch @@ -0,0 +1,107 @@ +From: Michal Kazior +Date: Fri, 13 Jan 2017 13:32:51 +0100 +Subject: [PATCH] mac80211: prevent skb/txq mismatch + +Station structure is considered as not uploaded +(to driver) until drv_sta_state() finishes. This +call is however done after the structure is +attached to mac80211 internal lists and hashes. +This means mac80211 can lookup (and use) station +structure before it is uploaded to a driver. + +If this happens (structure exists, but +sta->uploaded is false) fast_tx path can still be +taken. Deep in the fastpath call the sta->uploaded +is checked against to derive "pubsta" argument for +ieee80211_get_txq(). If sta->uploaded is false +(and sta is actually non-NULL) ieee80211_get_txq() +effectively downgraded to vif->txq. + +At first glance this may look innocent but coerces +mac80211 into a state that is almost guaranteed +(codel may drop offending skb) to crash because a +station-oriented skb gets queued up on +vif-oriented txq. The ieee80211_tx_dequeue() ends +up looking at info->control.flags and tries to use +txq->sta which in the fail case is NULL. + +It's probably pointless to pretend one can +downgrade skb from sta-txq to vif-txq. + +Since downgrading unicast traffic to vif->txq must +not be done there's no txq to put a frame on if +sta->uploaded is false. Therefore the code is made +to fall back to regular tx() op path if the +described condition is hit. + +Only drivers using wake_tx_queue were affected. + +Example crash dump before fix: + + Unable to handle kernel paging request at virtual address ffffe26c + PC is at ieee80211_tx_dequeue+0x204/0x690 [mac80211] + [] (ieee80211_tx_dequeue [mac80211]) from + [] (ath10k_mac_tx_push_txq+0x54/0x1c0 [ath10k_core]) + [] (ath10k_mac_tx_push_txq [ath10k_core]) from + [] (ath10k_htt_txrx_compl_task+0xd78/0x11d0 [ath10k_core]) + [] (ath10k_htt_txrx_compl_task [ath10k_core]) + [] (ath10k_pci_napi_poll+0x54/0xe8 [ath10k_pci]) + [] (ath10k_pci_napi_poll [ath10k_pci]) from + [] (net_rx_action+0xac/0x160) + +Reported-by: Mohammed Shafi Shajakhan +Signed-off-by: Michal Kazior +--- + +--- a/net/mac80211/tx.c ++++ b/net/mac80211/tx.c +@@ -798,7 +798,7 @@ static __le16 ieee80211_tx_next_seq(stru + + static struct txq_info *ieee80211_get_txq(struct ieee80211_local *local, + struct ieee80211_vif *vif, +- struct ieee80211_sta *pubsta, ++ struct sta_info *sta, + struct sk_buff *skb) + { + struct ieee80211_hdr *hdr = (struct ieee80211_hdr *) skb->data; +@@ -812,10 +812,13 @@ static struct txq_info *ieee80211_get_tx + if (!ieee80211_is_data(hdr->frame_control)) + return NULL; + +- if (pubsta) { ++ if (sta) { + u8 tid = skb->priority & IEEE80211_QOS_CTL_TID_MASK; + +- txq = pubsta->txq[tid]; ++ if (!sta->uploaded) ++ return NULL; ++ ++ txq = sta->sta.txq[tid]; + } else if (vif) { + txq = vif->txq; + } +@@ -1503,23 +1506,17 @@ static bool ieee80211_queue_skb(struct i + struct fq *fq = &local->fq; + struct ieee80211_vif *vif; + struct txq_info *txqi; +- struct ieee80211_sta *pubsta; + + if (!local->ops->wake_tx_queue || + sdata->vif.type == NL80211_IFTYPE_MONITOR) + return false; + +- if (sta && sta->uploaded) +- pubsta = &sta->sta; +- else +- pubsta = NULL; +- + if (sdata->vif.type == NL80211_IFTYPE_AP_VLAN) + sdata = container_of(sdata->bss, + struct ieee80211_sub_if_data, u.ap); + + vif = &sdata->vif; +- txqi = ieee80211_get_txq(local, vif, pubsta, skb); ++ txqi = ieee80211_get_txq(local, vif, sta, skb); + + if (!txqi) + return false;