From nobody Mon Sep 28 10:01:07 2026 Received: from mta0.migadu.com (out-193.mta0.migadu.com [91.218.175.193]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0868B17B418 for ; Mon, 24 Aug 2026 00:37:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.193 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787531837; cv=none; b=iHf3+2u2Sf2WkBCqmxQoTxE2b66i+Erjz4TvbJLxhGfVj4PGqHqwU8ewLnVT2JMhFVZbadQBK4BHRCphqnztYR+uHosEnT4waIFVc++IcY1whYexRmRRYcH5I9dqpd7HongFYReGtKIwURrEuw/+xFB1VajSmdmVtlObWWgk8Ng= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787531837; c=relaxed/simple; bh=uoWdwa3RpAwzJqIgRTFihUod/33vvbItb8N4Mvr8jJg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=ehdo+DK8+lhvdQIfLHvM6e6+Fi9GbvIo9daSVsbQV75FD74JpAoe7AwF4255HqltLFwzGMBvCHReSQQd7KyYImDt/VzMC5OBgNhzDHO/A2noiVhEiivJx5sYdxvCV0Ae7G1k4Bmqi3UOJJFVpq10ALGjrXAdW41mjFaBEbcm4gQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=justthetip.ca; spf=pass smtp.mailfrom=justthetip.ca; dkim=pass (2048-bit key) header.d=justthetip.ca header.i=@justthetip.ca header.b=ZK5ylNIm; arc=none smtp.client-ip=91.218.175.193 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=justthetip.ca Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=justthetip.ca Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=justthetip.ca header.i=@justthetip.ca header.b="ZK5ylNIm" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=uoWdwa3RpAwzJqIgRTFihUod/33vvbItb8N4Mvr8jJg=; c=simple/simple; d=justthetip.ca; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787531832; v=1; x=1788136632; b=ZK5ylNIm2u1iwKBTmHIAUY6uz6H4yzks0Fv0cyUGl4z6v/GurtV8FZsIbUGkHFwb8JTxHkB3 yi4MaKki8zF8XKpTq6sIE+mIXnwFquLZM2mi6PQFA3wzyECU9cROuE04FSjp+XPLj/8lw4TtgOI oHNXCjAaTOxK5Sx9fSzp4xo8MLwhtp972foFR04lT1OhE1nIDYhvUBADX6fjHp3rq+lkupEmq13 jXqR4oYkqm+sUzdEgOQlIYCQotktJn3n3YlwsazpweWmqlzNk2ewxLHo4la7ctUZNF4VBfZhsly jYcIxKTZGQXVuDCie9dugrKfuCVWV2xXgwm5SxhVkXdrg== X-Envelope-To: linux-kernel@vger.kernel.org Received: from fedora (2001:569:be59:c500:b340:3f2c:4486:21c1) by smtp.migadu.com with ESMTPS id 63ef895034ec1925; Mon, 24 Aug 2026 00:37:02 +0000 X-Mizu-Trace-ID: 63ef895034ec1925 X-Migadu-Flow: FLOW_OUT From: Devin Wittmayer To: Johannes Berg Cc: Felix Fietkau , linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH wireless] wifi: mac80211: refuse to make a monitor active when it has no queue Date: Sun, 23 Aug 2026 17:36:56 -0700 Message-ID: <20260824003656.27049-1-lucid_duck@justthetip.ca> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" commit 8105f9b8a887 ("mac80211: allocate TXQs for active monitor interfaces") reserved a TXQ for active monitors, because drivers using TXQ expect every interface handed to them to have one. It covers only interfaces created active: vif.txq is assigned in ieee80211_txq_init() from ieee80211_if_add(), and cannot be added later. MONITOR_FLAG_ACTIVE can still be set afterwards. ieee80211_set_mon_options() refuses that while the interface is up, but while it is down it just stores the flag. Such an interface then reaches the driver with vif->txq NULL, and ath9k resolves its multicast node's tids through that pointer unchecked: BUG: kernel NULL pointer dereference, address: 0000000000000066 RIP: 0010:ath_tx_node_init+0x49/0x170 [ath9k] ath9k_add_interface+0x10c/0x140 [ath9k] drv_add_interface+0x54/0x250 [mac80211] ieee80211_do_open+0x32f/0x800 [mac80211] Two commands from a user with CAP_NET_ADMIN reach it: iw dev set monitor active ip link set up The fault happens with RTNL held, so it is never released and all later netlink operations block. Refuse the promotion when there is no queue to give. Fixes: 79af1f866193 ("mac80211: avoid allocating TXQs that won't be used") Cc: stable@vger.kernel.org Signed-off-by: Devin Wittmayer --- Reproduces on mac80211_hwsim, no hardware needed: create a monitor, take it down, make it active and bring it up, and the driver gets a NULL vif->txq. One created with flags active gets a real one. With the patch the first is refused, the second still works, and an interface created active, set to none and back to active, is still accepted. Same on an MT7922. Only drivers advertising NL80211_FEATURE_ACTIVE_MONITOR reach this, since cfg80211 refuses the flag otherwise. ath9k, mt7603 and mt76x02 deref vif->txq unchecked. mt7615, mt7915, mt7921, mt7925 and mt7996 test it first. Where it faults today, refusing costs nothing. On the drivers that check, I could not test whether a promoted interface actually works, so that is where a regression would show. Reserving a queue for every monitor instead would make the promotion work rather than refuse it, and would also cover a passive monitor reaching the driver under NO_VIRTUAL_MONITOR. That undoes 79af1f866193 deliberately, so I did not assume it. Happy to write it if you prefer. net/mac80211/cfg.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/net/mac80211/cfg.c b/net/mac80211/cfg.c index b6163dcc7e92..523cef0a5526 100644 --- a/net/mac80211/cfg.c +++ b/net/mac80211/cfg.c @@ -115,6 +115,15 @@ static int ieee80211_set_mon_options(struct ieee80211_= sub_if_data *sdata, return -EBUSY; } =20 + /* + * An active monitor is passed to the driver and needs a TXQ, which is + * reserved with the netdev in ieee80211_if_add() and cannot be added + * later. An interface created without the flag has none, so refuse to + * set it rather than hand the driver a NULL vif->txq. + */ + if ((params->flags & MONITOR_FLAG_ACTIVE) && !sdata->vif.txq) + return -EOPNOTSUPP; + /* validate whether MU-MIMO can be configured */ if (!ieee80211_hw_check(&local->hw, WANT_MONITOR_VIF) && !ieee80211_hw_check(&local->hw, NO_VIRTUAL_MONITOR) && --=20 2.55.0