From nobody Fri Jul 24 21:52:34 2026 Received: from mail-pg1-f176.google.com (mail-pg1-f176.google.com [209.85.215.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0B37241A51B for ; Thu, 23 Jul 2026 20:22:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784838158; cv=none; b=nLOVSHIwosc79bdr6Z3SjnJ5fdOaGg214tInzazoO6Fy6AzFNKGZw9u0XeraLGpoUk4m3rFxFiZkXsbL1rwil9adBOa65uO61pfnEnPxHsNndwnIrLvyLmsF/BJBkii2CPuezkMfLEJTerdCBuyRpSQJ61OhwlPBO+6D71mKtzs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784838158; c=relaxed/simple; bh=KWcKP2geASN3jo8/dE06oUF8rjQfnBcpV2Gx2J0AGTM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=mDDsvT5jiDRPiRcVcJdBWwAVtSsN8g8U4pIJgGWbOVM+GClRqHjanr3wqMdku2go5XTm8KTRN1f8d/mI89UY7jyZJQpEJMK+RAe2sfdkmixmK/4btRdsiSY6P3FgSZ7yx00jpBk2nXk9kIkueg2q5o2/V+yrf1ru6ueJnyDgIjs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ks9YL6b2; arc=none smtp.client-ip=209.85.215.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ks9YL6b2" Received: by mail-pg1-f176.google.com with SMTP id 41be03b00d2f7-caf45fc5202so1056405a12.1 for ; Thu, 23 Jul 2026 13:22:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784838153; x=1785442953; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=1uRexGHLvlqsOKL6vO2NQvFV//36xeGbmQtRnRdGXPo=; b=ks9YL6b2wcV1Z/EO0atHpiS9aGR2S+qXRKLk2aMi5D2CBigRX4GBNyU81EFroI3jlA oU2Xdrr2Iopizqg30NeKoGCMklLp8nSKrjrt++D9FHw3pPHfN9jh/JE2nsH0geAJhkQc icd9vAWOBEuTu+AIBrurXJnUD+ExCRXx6YkNFz7vOzVofevRh/nvw3ZUTzQBQYC0Gsz3 Ib1xSgaRK8lRdrH/jFt9r59wIwbr8fC0TQLEqM4/36qQmZO8Bo4Dsgx3lNhD6KuTQINT vIR6gEjM4RyW9F8H4HiY5gbMBEN3/WQwbQ5Lj3+j2Ws+T8j9IrRIiqPG+8gGpirxWFhy nDtA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784838153; x=1785442953; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=1uRexGHLvlqsOKL6vO2NQvFV//36xeGbmQtRnRdGXPo=; b=Kx+C70DcpEFUk4YzEu53YfHjVdnwdZYkOsG+u4+EFjscP1c3C4LTs4e/17NIkAm2wr VnvWpaY4RlovtPkwDAJkS5XO+EpUtMyHmG2fvp3enKH7cHH4VrxJlotdMqbXaKaU2Zar agAX+tFtSRwdS/gSNLsUNGQg2b4kTIsBVOyoafhWSKxAfgUWyJ1/gr4NEg1xFgUvHse0 kF65FQ3DsYbdHqZq/67EmOrx/ymdVLamiouEDZ3xcIqwkaePAx1QCIDoKDkYgOJ6CAR0 bk7Eu2DLiuXnL9ZJIvGnpqxQaE4JAGQiJd+xuSVcsgDtHT4gWeMng1+f5F8ZK66v78zI UPcQ== X-Forwarded-Encrypted: i=1; AHgh+RpK/9T6z5whZeqof/JmzohOHZuJ5FkQtak1OEpwYjEWYj00l0uKYZvageJPqCx7mQOCaweJFnlP9h0RI7U=@vger.kernel.org X-Gm-Message-State: AOJu0YxBpUoLebFDmPh3hF1gt11IYkNdvXT8/n3PBnUyyo7569CJMjQW 2Ar775FULeNqfvoyB/0U288GAIbH5p7BS4t6Q8nWCeiVDgvIlkv9GLOe X-Gm-Gg: AR+sD13bxt5w6Qdok3zI0n/fpCuEk587cSb+xmLujGYLfWTL5Yoe/HJmA1rU4g2RB0E ceUuEggYaxFR2maquyzRkz5XqeKBdM7qdiuQ/20isOFKooG2dE0mQHPB3gCYkCDJtaRpPoVoLuS O2T9GW/XSfgkw6qgCBH2+PQpTnN5ugtbIfA/LUwLxaz3c2aLC4V07okIDMZjIH1Yk5zyE+reiVX bTkPBMIeNzSyt+D0Z38/hmzt9v/+5PXzB/y3nVy2LU2zKGfM5PRkLR3e6jIEDuAcjheHXqIMZFo 46Rw9SESAS02J4OvCkZgjsH8D8fK5cY6YFWPIc6uoakk6MD67QTbFf5IsF5n2Ctehuyjt0uYw67 jrzPa4Qw7yq7HdJsvp9EfphfJXMX1VmGmgUZ4TTLEqDwdf0ObLCowUJS1eq/d2KmHaHFa/EiOa8 DUXCKaylWSuP5R3oHK3onm47gmVEqnKR4fleH+tvJa X-Received: by 2002:a05:6a20:9c8c:b0:3bf:6c08:4ebb with SMTP id adf61e73a8af0-3c44b18ac6cmr5289759637.48.1784838153196; Thu, 23 Jul 2026 13:22:33 -0700 (PDT) Received: from KRHW1CJW23.bytedance.net ([58.250.106.104]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cbb8f0ebfcesm3364119a12.11.2026.07.23.13.22.29 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Thu, 23 Jul 2026 13:22:32 -0700 (PDT) From: Zhao Li To: linux-wireless@vger.kernel.org Cc: johannes@sipsolutions.net, linux-kernel@vger.kernel.org, Zhao Li Subject: [PATCH v2] wifi: cfg80211: publish PMSR request before starting the driver Date: Fri, 24 Jul 2026 04:22:23 +0800 Message-ID: <20260723202223.99661-1-enderaoelyther@gmail.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260723010916.76433-1-enderaoelyther@gmail.com> References: <20260723010916.76433-1-enderaoelyther@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" nl80211_pmsr_start() assigns the request cookie, calls the driver's ->start_pmsr() callback, and only then adds the request to wdev->pmsr_list, without holding pmsr_lock for the addition. mac80211_hwsim saves the request in its start callback and returns. Since nl80211 uses parallel_ops, an immediate REPORT_PMSR can then run before nl80211_pmsr_start() reaches its post-start list_add_tail(). hwsim also dispatches reports from its virtio receive workqueue. Completion removes the request from wdev->pmsr_list under pmsr_lock and frees it. Thus completion can precede publication, race the unlocked list mutation, or free the request before nl80211_pmsr_start() reads req->cookie for the netlink reply. Add the request to wdev->pmsr_list under pmsr_lock before calling the driver, and use a cookie value saved before the call so the request is not dereferenced after a successful start. On an error return the driver has not retained or completed the request, so remove it from the list under the lock and free it. Fixes: 9bb7e0f24e7e ("cfg80211: add peer measurement with FTM initiator API= ") Link: https://lore.kernel.org/all/20260723010916.76433-1-enderaoelyther@gma= il.com/ Assisted-by: Codex:gpt-5 Assisted-by: Claude:opus-4.8 Signed-off-by: Zhao Li --- Changes in v2: - Drop callback documentation that implied synchronous completion was supported. - Reword the local comment as defensive handling for races or broken drivers that complete the request before ->start_pmsr() returns. --- net/wireless/pmsr.c | 22 ++++++++++++++++++---- 1 file changed, 18 insertions(+), 4 deletions(-) diff --git a/net/wireless/pmsr.c b/net/wireless/pmsr.c index d1e2fae5bc0e..97449bcb9a22 100644 --- a/net/wireless/pmsr.c +++ b/net/wireless/pmsr.c @@ -420,6 +420,7 @@ int nl80211_pmsr_start(struct sk_buff *skb, struct genl= _info *info) const struct cfg80211_pmsr_capabilities *capa; struct cfg80211_pmsr_request *req; struct nlattr *peers, *peer; + u64 cookie; =20 capa =3D rdev->wiphy.pmsr_capa; =20 @@ -521,14 +522,27 @@ int nl80211_pmsr_start(struct sk_buff *skb, struct ge= nl_info *info) } req->cookie =3D cfg80211_assign_cookie(rdev); req->nl_portid =3D info->snd_portid; + cookie =3D req->cookie; + + /* + * Add to the list before the driver call; under races or broken + * drivers, completion may free the request before rdev_start_pmsr() + * returns. Use the saved cookie below. + */ + spin_lock_bh(&wdev->pmsr_lock); + list_add_tail(&req->list, &wdev->pmsr_list); + spin_unlock_bh(&wdev->pmsr_lock); =20 err =3D rdev_start_pmsr(rdev, wdev, req); - if (err) + if (err) { + /* An error return leaves the request owned by this path. */ + spin_lock_bh(&wdev->pmsr_lock); + list_del(&req->list); + spin_unlock_bh(&wdev->pmsr_lock); goto out_err; + } =20 - list_add_tail(&req->list, &wdev->pmsr_list); - - nl_set_extack_cookie_u64(info->extack, req->cookie); + nl_set_extack_cookie_u64(info->extack, cookie); return 0; out_err: kfree(req); --=20 2.50.1 (Apple Git-155)