lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Mon, 6 Apr 2020 18:51:04 +0530 From: Sumit Garg <sumit.garg@...aro.org> To: Johannes Berg <johannes@...solutions.net>, Kalle Valo <kvalo@...eaurora.org> Cc: linux-wireless@...r.kernel.org, "David S. Miller" <davem@...emloft.net>, kuba@...nel.org, netdev@...r.kernel.org, Linux Kernel Mailing List <linux-kernel@...r.kernel.org>, Matthias-Peter Schöpfer <matthias.schoepfer@...inx.io>, "Berg Philipp (HAU-EDS)" <Philipp.Berg@...bherr.com>, "Weitner Michael (HAU-EDS)" <Michael.Weitner@...bherr.com>, Daniel Thompson <daniel.thompson@...aro.org>, Loic Poulain <loic.poulain@...aro.org>, stable@...r.kernel.org Subject: Re: [PATCH] mac80211: fix race in ieee80211_register_hw() On Mon, 6 Apr 2020 at 18:38, Johannes Berg <johannes@...solutions.net> wrote: > > On Mon, 2020-04-06 at 16:04 +0300, Kalle Valo wrote: > > Johannes Berg <johannes@...solutions.net> writes: > > > > > On Mon, 2020-04-06 at 15:52 +0300, Kalle Valo wrote: > > > > Johannes Berg <johannes@...solutions.net> writes: > > > > > > > > > On Mon, 2020-04-06 at 15:44 +0300, Kalle Valo wrote: > > > > > > > user-space ieee80211_register_hw() RX IRQ > > > > > > > +++++++++++++++++++++++++++++++++++++++++++++ > > > > > > > | | | > > > > > > > |<---wlan0---wiphy_register() | > > > > > > > |----start wlan0---->| | > > > > > > > | |<---IRQ---(RX packet) > > > > > > > | Kernel crash | > > > > > > > | due to unallocated | > > > > > > > | workqueue. | > > > > > > > > > > [snip] > > > > > > > > > > > I have understood that no frames should be received until mac80211 calls > > > > > > struct ieee80211_ops::start: > > > > > > > > > > > > * @start: Called before the first netdevice attached to the hardware > > > > > > * is enabled. This should turn on the hardware and must turn on > > > > > > * frame reception (for possibly enabled monitor interfaces.) > > > > > > > > > > True, but I think he's saying that you can actually add and configure an > > > > > interface as soon as the wiphy is registered? > > > > > > > > With '<---IRQ---(RX packet)' I assumed wcn36xx is delivering a frame to > > > > mac80211 using ieee80211_rx(), but of course I'm just guessing here. > > > > > > Yeah, but that could be legitimate? > > > > Ah, I misunderstood then. The way I have understood is that no rx frames > > should be delivered (= calling ieee80211_rx()_ before start() is called, > > but if that's not the case please ignore me :) > > No no, that _is_ the case. But I think the "start wlan0" could end up > calling it? > Sorry if I wasn't clear enough via the sequence diagram. It's a common RX packet that arrives via ieee80211_tasklet_handler() which is enabled via call to "struct ieee80211_ops::start" api. -Sumit > johannes >
Powered by blists - more mailing lists