From nobody Fri Jul 24 22:17:34 2026 Received: from mail-pl1-f173.google.com (mail-pl1-f173.google.com [209.85.214.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 20056470EA2 for ; Thu, 23 Jul 2026 01:09:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.173 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784768966; cv=none; b=q6Lm+dqzst/HSLCJD6svF2rAHpHl2uHIueV0cAuTqxOoVgEMISAUPVqZDUgKXl7tbmsIFkoRsOk34PMR3ldnpY1qzhHYIzwelbDomjFXAjIG0ArV10M5U90qVRSO/uyj2dffQ1lGRNNOVLkyZsTHLKjJ80b9hpwI9KvztiDgFUg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784768966; c=relaxed/simple; bh=yNbi8MQpsTQ3PMK8Nhe/XHDQlPfbrrLl1OGxvluchAo=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=e87PfkwQCffFYfpR00hoBHmFG5oKsBll7k/8zaRTiwGJi5qwjMbqCyjZmHivBllr2fH3DvTcsWmnfv0OFrj8ZTg6Qr+GFccnjhWBU9vLldXCk4WndsMw5yRUYFpEp0i7e2Bjaw7L0EajOH0Nsj1BAIZMi0XAsu2Oome9umVgFpE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=c7sTaBX4; arc=none smtp.client-ip=209.85.214.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="c7sTaBX4" Received: by mail-pl1-f173.google.com with SMTP id d9443c01a7336-2ce98cb8165so711825ad.1 for ; Wed, 22 Jul 2026 18:09:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784768963; x=1785373763; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=DUKN5sPrRvuKbWGXM5C8TwKRW+R8k9MDgafaHsafP5M=; b=c7sTaBX4d+OTgGuaDsYP6zNrsmDB9IVPw81KnNd+iP0HAFvBN/KRmCeCN4A7ZPuYJT rsKN59UjYcu8F6+18CMIDvzZrlmyMX3CysPdOTWygAG1arkuH2985Z/6b1UqxGq1dTed mtPSjJyeSVKlEVlyvC60gwv5yx7gBdRFbXxStkYvWACj6qL89UQVoTpcl2ARRq3vscfZ kZBZz882NyQbcnkomv3RE663EPWx0It3MMUInouoz9GDxay/kWwd9cFnHIczmUMNd9Lb yKFI4BIkJt5jVY0w4EA8VqxUw4eTAf83U3hGfj5Sb7RurO88HL3sgPe3BjhOkAufDDwj jVVQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784768963; x=1785373763; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DUKN5sPrRvuKbWGXM5C8TwKRW+R8k9MDgafaHsafP5M=; b=ePl4efBT4qahAp28lwrCiqGtB3FBhPbWfB35hM/qMISpThM0odZMkRQcQlvxd4h1KK TCB4pLhJaIInYZHI+X7i/LHBLc3XWwivXfnEeoVE969QpBKYqBE99VLwbRrAypzxUssC NojX9Q+CO/jDcovcfp665RIdVOadYrdsR3pdJMGg3uUjiO3TiwqzLglWNaWIEOAoBxJ+ zNBS929tSLhbXSaU9n6naar02XUtPEOwmbJj7p3UINYAAgMFyAMlUTVd4fTmtvqZEl9R iN7EZs+4kV3BoDBqLkCDrptLijVyeTKIEnhfk2FteYBZwpEoWVA67G91/MMxvN0P6xu5 SJ4w== X-Forwarded-Encrypted: i=1; AHgh+RqV2ga6+FdHNquRuj3GcqTr2UPs+Al5htE3IeE0gmbxyzTxmIKey/pTDLiO458YgSg2ZusfzmuWcIZqKN4=@vger.kernel.org X-Gm-Message-State: AOJu0YxQ7sYNJcNMewAbiI6nHWQu5ddg4wsxzHsKYLZFnytYCeX16Pr+ x7NSwPBcMnnLkq2kawJm6xMRTx+rgj6RZ9tBSvU8t1f1mlW5PeJdi9kaxMFVsgfxYz0= X-Gm-Gg: AR+sD13aGyrKbC5du7sXoH/v4Fvd9tOb8s/drrBE2i/tXtRiGUq+2uXrUQiP0ArLd1M UAywT225MpO9kL/gkNLwdTmZDwP08cFbqdVGxoSdcWJVcuyqw+V9IGWhZbwlsRLb6Cyy9KESXvA ZhG/J0Hg/GCL59Jb2UMZIlLdDGjzS5JN9WDEpuQkNlon4D9u4jTAbUA56YZHgztKkRZ/6VTJDPN s4KeeBzs8is6Wn7iXx02LPgPdtTMiVX8VfEz5jcVS/drCcraRmi4L5JgiAf1G27LqgOFQP9joO9 9hfrnVBooOb/KPVIQAH5Ml0KMoSJVujGfsGycYyt5WpJsOxyosIqT1top47QqFUs96yltj3P2zP iUezTiv069jtGDzjkSp32LHEp+6YRdg4sSMOv0GR4Z8MOpWPnzrXO6kf8IUDbB12vVX4fvRevI3 jnjt8+AYhRRr/735EQj15KvN3JeUcusiJQaDKs7v+huZXZCgW7A2Y= X-Received: by 2002:a17:903:2306:b0:2c9:994c:9a5 with SMTP id d9443c01a7336-2cfa9588d7emr6808925ad.30.1784768963146; Wed, 22 Jul 2026 18:09:23 -0700 (PDT) Received: from KRHW1CJW23.bytedance.net ([203.208.189.11]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf8f350554sm22562085ad.66.2026.07.22.18.09.20 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 22 Jul 2026 18:09:22 -0700 (PDT) From: Zhao Li To: johannes@sipsolutions.net Cc: linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, Zhao Li Subject: [PATCH] wifi: cfg80211: publish PMSR request before starting the driver Date: Thu, 23 Jul 2026 09:09:16 +0800 Message-ID: <20260723010916.76433-1-enderaoelyther@gmail.com> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" nl80211_pmsr_start() assigns the request cookie, calls the driver's ->start_pmsr() callback, and only then adds the request to wdev->pmsr_list, without holding pmsr_lock for the addition. mac80211_hwsim saves the request in its start callback and returns. Since nl80211 uses parallel_ops, an immediate REPORT_PMSR can then run before nl80211_pmsr_start() reaches its post-start list_add_tail(). hwsim also dispatches reports from its virtio receive workqueue. Completion removes the request from wdev->pmsr_list under pmsr_lock and frees it. Thus completion can precede publication, race the unlocked list mutation, or free the request before nl80211_pmsr_start() reads req->cookie for the netlink reply. Add the request to wdev->pmsr_list under pmsr_lock before calling the driver, and use a cookie value saved before the call so the request is not dereferenced after a successful start. On an error return the driver has not retained or completed the request, so remove it from the list under the lock and free it. This ordering also permits a successful driver callback to complete the request synchronously. Document the resulting start_pmsr lifetime contract. Fixes: 9bb7e0f24e7e ("cfg80211: add peer measurement with FTM initiator API= ") Assisted-by: Codex:gpt-5 Assisted-by: Claude:opus-4.8 Signed-off-by: Zhao Li --- include/net/cfg80211.h | 6 +++++- include/net/mac80211.h | 6 +++++- net/wireless/pmsr.c | 21 +++++++++++++++++---- 3 files changed, 27 insertions(+), 6 deletions(-) diff --git a/include/net/cfg80211.h b/include/net/cfg80211.h index f5abf1db7558..a8ba484ecad6 100644 --- a/include/net/cfg80211.h +++ b/include/net/cfg80211.h @@ -5202,7 +5202,11 @@ struct mgmt_frame_regs { * * @get_ftm_responder_stats: Retrieve FTM responder statistics, if availab= le. * Statistics should be cumulative, currently no way to reset is provided. - * @start_pmsr: start peer measurement (e.g. FTM) + * @start_pmsr: start peer measurement (e.g. FTM). The callback may + * complete the request before returning success. After completing it, + * the driver must not access the request. If the callback returns an + * error, the driver must not retain the request or later report results + * or completion for it. * @abort_pmsr: abort peer measurement * * @update_owe_info: Provide updated OWE info to driver. Driver implementi= ng SME diff --git a/include/net/mac80211.h b/include/net/mac80211.h index 4f95da023746..64600e7bd251 100644 --- a/include/net/mac80211.h +++ b/include/net/mac80211.h @@ -4661,7 +4661,11 @@ struct ieee80211_prep_tx_info { * @get_ftm_responder_stats: Retrieve FTM responder statistics, if availab= le. * Statistics should be cumulative, currently no way to reset is provided. * - * @start_pmsr: start peer measurement (e.g. FTM) (this call can sleep) + * @start_pmsr: start peer measurement (e.g. FTM) (this call can sleep). + * The callback may complete the request before returning success. + * After completing it, the driver must not access the request. If the + * callback returns an error, the driver must not retain the request or + * later report results or completion for it. * @abort_pmsr: abort peer measurement (this call can sleep) * @set_tid_config: Apply TID specific configurations. This callback may s= leep. * @reset_tid_config: Reset TID specific configuration for the peer. diff --git a/net/wireless/pmsr.c b/net/wireless/pmsr.c index d1e2fae5bc0e..3484956ebb50 100644 --- a/net/wireless/pmsr.c +++ b/net/wireless/pmsr.c @@ -420,6 +420,7 @@ int nl80211_pmsr_start(struct sk_buff *skb, struct genl= _info *info) const struct cfg80211_pmsr_capabilities *capa; struct cfg80211_pmsr_request *req; struct nlattr *peers, *peer; + u64 cookie; =20 capa =3D rdev->wiphy.pmsr_capa; =20 @@ -521,14 +522,26 @@ int nl80211_pmsr_start(struct sk_buff *skb, struct ge= nl_info *info) } req->cookie =3D cfg80211_assign_cookie(rdev); req->nl_portid =3D info->snd_portid; + cookie =3D req->cookie; + + /* + * Publish before the driver can complete the request. Completion may free + * it before rdev_start_pmsr() returns, so use the cookie snapshot below. + */ + spin_lock_bh(&wdev->pmsr_lock); + list_add_tail(&req->list, &wdev->pmsr_list); + spin_unlock_bh(&wdev->pmsr_lock); =20 err =3D rdev_start_pmsr(rdev, wdev, req); - if (err) + if (err) { + /* An error return leaves the request owned by this path. */ + spin_lock_bh(&wdev->pmsr_lock); + list_del(&req->list); + spin_unlock_bh(&wdev->pmsr_lock); goto out_err; + } =20 - list_add_tail(&req->list, &wdev->pmsr_list); - - nl_set_extack_cookie_u64(info->extack, req->cookie); + nl_set_extack_cookie_u64(info->extack, cookie); return 0; out_err: kfree(req); --=20 2.50.1 (Apple Git-155)