[PATCH 1/3] wifi: cfg80211: do not support direct add of station to AP_VLAN interfaces

0 views
Skip to first unread message

Slawomir Stepien

unread,
5:04 AM (1 hour ago) 5:04 AM
to syzkall...@googlegroups.com, joha...@sipsolutions.net, linux-w...@vger.kernel.org, linux-...@vger.kernel.org, syz...@lists.linux.dev, s...@poczta.fm, syzbot+9bdc0c...@syzkaller.appspotmail.com
Prevent userspace from adding stations directly to AP_VLAN type
interfaces. Userspace should first add the station to the base interface
(AP type) and then can use CMD_SET_STATION to move it to AP_VLAN.

Without this path, we cannot check if the AP has been started before
adding the station - wdev for AP_VLAN does not store information about
the base AP interface.

Signed-off-by: Slawomir Stepien <s...@poczta.fm>
---
net/wireless/nl80211.c | 1 -
1 file changed, 1 deletion(-)

diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index 5adcb6bd0fc5..0c4e6bd6a44c 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -9402,7 +9402,6 @@ static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)

switch (wdev->iftype) {
case NL80211_IFTYPE_AP:
- case NL80211_IFTYPE_AP_VLAN:
case NL80211_IFTYPE_P2P_GO:
/* ignore WME attributes if iface/sta is not capable */
if (!(rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) ||
--
2.55.0

Slawomir Stepien

unread,
5:04 AM (1 hour ago) 5:04 AM
to syzkall...@googlegroups.com, joha...@sipsolutions.net, linux-w...@vger.kernel.org, linux-...@vger.kernel.org, syz...@lists.linux.dev, s...@poczta.fm, syzbot+9bdc0c...@syzkaller.appspotmail.com
I do not see a reason why this check is so low in the function. Move it
up right next to param fetch.

This new position is more beneficial for AP/Link state check that will
be added in upcoming commit.

Signed-off-by: Slawomir Stepien <s...@poczta.fm>
---
net/wireless/nl80211.c | 27 ++++++++++-----------------
1 file changed, 10 insertions(+), 17 deletions(-)

diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index 0c4e6bd6a44c..ebde52655904 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -9222,6 +9222,16 @@ static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
params.link_sta_params.link_id =
nl80211_link_id_or_invalid(info->attrs);

+ if (wdev->valid_links) {
+ if (params.link_sta_params.link_id < 0)
+ return -EINVAL;
+ if (!(wdev->valid_links & BIT(params.link_sta_params.link_id)))
+ return -ENOLINK;
+ } else {
+ if (params.link_sta_params.link_id >= 0)
+ return -EINVAL;
+ }
+
if (info->attrs[NL80211_ATTR_MLD_ADDR]) {
mac_addr = nla_data(info->attrs[NL80211_ATTR_MLD_ADDR]);
params.link_sta_params.mld_mac = mac_addr;
@@ -9494,27 +9504,10 @@ static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)

/* be aware of params.vlan when changing code here */

- if (wdev->valid_links) {
- if (params.link_sta_params.link_id < 0) {
- err = -EINVAL;
- goto out;
- }
- if (!(wdev->valid_links & BIT(params.link_sta_params.link_id))) {
- err = -ENOLINK;
- goto out;
- }
- } else {
- if (params.link_sta_params.link_id >= 0) {
- err = -EINVAL;
- goto out;
- }
- }
-
params.epp_peer =
nla_get_flag(info->attrs[NL80211_ATTR_EPP_PEER]);

err = rdev_add_station(rdev, wdev, mac_addr, &params);
-out:
dev_put(params.vlan);
return err;
}
--
2.55.0

Slawomir Stepien

unread,
5:04 AM (1 hour ago) 5:04 AM
to syzkall...@googlegroups.com, joha...@sipsolutions.net, linux-w...@vger.kernel.org, linux-...@vger.kernel.org, syz...@lists.linux.dev, s...@poczta.fm, syzbot+9bdc0c...@syzkaller.appspotmail.com
Adding a new station to AP makes only sense when the AP has been started
beforehand (nl80211_start_ap()). Check if AP is up and beaconing on the
link when adding new station. Return error if this isn't the case.

Reported-by: syzbot+9bdc0c...@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=9bdc0c5998ab45b05030
Signed-off-by: Slawomir Stepien <s...@poczta.fm>
---
net/wireless/nl80211.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index ebde52655904..75bbd78f91ba 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -9174,7 +9174,7 @@ static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
{
struct cfg80211_registered_device *rdev = info->user_ptr[0];
- int err;
+ int err, link_id;
struct wireless_dev *wdev = info->user_ptr[1];
struct net_device *dev = wdev->netdev;
struct station_parameters params;
@@ -9413,6 +9413,11 @@ static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
switch (wdev->iftype) {
case NL80211_IFTYPE_AP:
case NL80211_IFTYPE_P2P_GO:
+ /* Add a new station only after the AP and link has been started */
+ link_id = wdev->valid_links ? params.link_sta_params.link_id : 0;
+ if (!wdev->links[link_id].ap.beacon_interval)
+ return -ENETDOWN;
+
/* ignore WME attributes if iface/sta is not capable */
if (!(rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) ||
!(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)))
--
2.55.0

Reply all
Reply to author
Forward
0 new messages