Revert "ath10k: add sanity check to ie_len before parsing fw/board ie"

"Linux Kernel Mailing List" <[email protected]>
Newsgroups gmane.linux.kernel.commits.head
Message-ID <[email protected]>
Web:        https://git.kernel.org/torvalds/c/9ce8b24aa96e983a540bb8244298a10322881ef4
Commit:     9ce8b24aa96e983a540bb8244298a10322881ef4
Parent:     4e12d654ba068df06c5e4c8322d7dcced41e48ee
Refname:    refs/heads/master
Author:     Ryan Hsu <[email protected]>
AuthorDate: Wed Feb 7 15:51:23 2018 +0200
Committer:  Kalle Valo <[email protected]>
CommitDate: Thu Feb 8 14:34:18 2018 +0200

    Revert "ath10k: add sanity check to ie_len before parsing fw/board ie"
    
    This reverts commit 9ed4f91628737c820af6a1815b65bc06bd31518f.
    
    The commit introduced a regression that over read the ie with
    the padding.
    
    - the expected IE information
    
    ath10k_pci 0000:03:00.0: found firmware features ie (1 B)
    ath10k_pci 0000:03:00.0: Enabling feature bit: 6
    ath10k_pci 0000:03:00.0: Enabling feature bit: 7
    ath10k_pci 0000:03:00.0: features
    ath10k_pci 0000:03:00.0: 00000000: c0 00 00 00 00 00 00 00
    
    - the wrong IE with padding is read (0x77)
    
    ath10k_pci 0000:03:00.0: found firmware features ie (4 B)
    ath10k_pci 0000:03:00.0: Enabling feature bit: 6
    ath10k_pci 0000:03:00.0: Enabling feature bit: 7
    ath10k_pci 0000:03:00.0: Enabling feature bit: 8
    ath10k_pci 0000:03:00.0: Enabling feature bit: 9
    ath10k_pci 0000:03:00.0: Enabling feature bit: 10
    ath10k_pci 0000:03:00.0: Enabling feature bit: 12
    ath10k_pci 0000:03:00.0: Enabling feature bit: 13
    ath10k_pci 0000:03:00.0: Enabling feature bit: 14
    ath10k_pci 0000:03:00.0: Enabling feature bit: 16
    ath10k_pci 0000:03:00.0: Enabling feature bit: 17
    ath10k_pci 0000:03:00.0: Enabling feature bit: 18
    ath10k_pci 0000:03:00.0: features
    ath10k_pci 0000:03:00.0: 00000000: c0 77 07 00 00 00 00 00
    
    Tested-by: Mike Lothian <[email protected]>
    Signed-off-by: Ryan Hsu <[email protected]>
    Signed-off-by: Kalle Valo <[email protected]>
---
 drivers/net/wireless/ath/ath10k/core.c | 14 +++++++-------
 1 file changed, 7 insertions(+), 7 deletions(-)

diff --git a/drivers/net/wireless/ath/ath10k/core.c b/drivers/net/wireless/ath/ath10k/core.c
index 6fb282f76804..f3ec13b80b20 100644
--- a/drivers/net/wireless/ath/ath10k/core.c
+++ b/drivers/net/wireless/ath/ath10k/core.c
@@ -1305,10 +1305,7 @@ static int ath10k_core_fetch_board_data_api_n(struct ath10k *ar,
 		len -= sizeof(*hdr);
 		data = hdr->data;
 
-		/* jump over the padding */
-		ie_len = ALIGN(ie_len, 4);
-
-		if (len < ie_len) {
+		if (len < ALIGN(ie_len, 4)) {
 			ath10k_err(ar, "invalid length for board ie_id %d ie_len %zu len %zu\n",
 				   ie_id, ie_len, len);
 			ret = -EINVAL;
@@ -1347,6 +1344,9 @@ static int ath10k_core_fetch_board_data_api_n(struct ath10k *ar,
 			goto out;
 		}
 
+		/* jump over the padding */
+		ie_len = ALIGN(ie_len, 4);
+
 		len -= ie_len;
 		data += ie_len;
 	}
@@ -1477,9 +1477,6 @@ int ath10k_core_fetch_firmware_api_n(struct ath10k *ar, const char *name,
 		len -= sizeof(*hdr);
 		data += sizeof(*hdr);
 
-		/* jump over the padding */
-		ie_len = ALIGN(ie_len, 4);
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.