[PATCH] wifi: rtw89: debug: fix off-by-one in rtw89_ppdu_str()

Linkai Gong posted 1 patch 1 month, 1 week ago
drivers/net/wireless/realtek/rtw89/debug.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
[PATCH] wifi: rtw89: debug: fix off-by-one in rtw89_ppdu_str()
Posted by Linkai Gong 1 month, 1 week ago
rtw89_ppdu_str() uses type > ARRAY_SIZE(), so type == ARRAY_SIZE() still
indexes one past rtw89_ppdu_infos[]. Compare with >=, like
rtw89_txcmd_str().

Fixes: 419ed7f4a053 ("wifi: rtw89: debug: extend bb_info with TX status and PER")
Cc: stable@vger.kernel.org
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
---
 drivers/net/wireless/realtek/rtw89/debug.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/realtek/rtw89/debug.c b/drivers/net/wireless/realtek/rtw89/debug.c
index 8f5af873e09f..5786120602ab 100644
--- a/drivers/net/wireless/realtek/rtw89/debug.c
+++ b/drivers/net/wireless/realtek/rtw89/debug.c
@@ -4348,7 +4348,7 @@ static const char *rtw89_ppdu_str(struct rtw89_dev *rtwdev, u8 type, u8 subtype)
 	const struct rtw89_chip_info *chip = rtwdev->chip;
 	const struct rtw89_ppdu_info *ppdu_info;
 
-	if (type > ARRAY_SIZE(rtw89_ppdu_infos))
+	if (type >= ARRAY_SIZE(rtw89_ppdu_infos))
 		return "RSVD";
 
 	ppdu_info = &rtw89_ppdu_infos[type];
-- 
2.25.1
RE: [PATCH] wifi: rtw89: debug: fix off-by-one in rtw89_ppdu_str()
Posted by Ping-Ke Shih 1 month, 1 week ago
Linkai Gong <gonglinkai@kylinos.cn> wrote:
> rtw89_ppdu_str() uses type > ARRAY_SIZE(), so type == ARRAY_SIZE() still
> indexes one past rtw89_ppdu_infos[]. Compare with >=, like
> rtw89_txcmd_str().
> 
> Fixes: 419ed7f4a053 ("wifi: rtw89: debug: extend bb_info with TX status and PER")
> Cc: stable@vger.kernel.org
> Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>

The same patch [1] was applied. 

[1] https://lore.kernel.org/linux-wireless/aia25i0ds3B6QF6c@stanley.mountain/#t