Re: [PATCH] Three bugfixes for iwd SEGVs at receipt of EAPOL M1 msg with legacy roaming and repeated roam scan after ft_auth-/ft_reassoc-timeout occurred:

Paul Menzel <[email protected]> Wed, 8 Jul 2026 10:12:09 +0200
Newsgroups dev.linux.lists.iwd
Message-ID <[email protected]>
Dear Dierk,


Thank you for your patch.

Am 08.07.26 um 08:16 schrieb [email protected]:
> From: DEMODDIE <[email protected]>

DEMODDIE doesn’t look right. `git config --global user.name "Dierk 
Modrow"` and `git commit --amend --author="Dierk Modrow 
<[email protected]>" should help.

>    src/eapol.c: next try for a fix of SEGV fault at eapol_rx_packets when using mwifiex / NXP 88W9098 driver
>    src/station.c: potential bugfix in station_roam_scan_notify to avoid NULL-Ptr access to var hs
>    src/station.c: next try to fix a SEGV after auth timeout at FT roaming

It’d be great if you could make one commit for each bug.

> ---
>   src/eapol.c   |  4 ++++
>   src/station.c | 12 ++++++------
>   2 files changed, 10 insertions(+), 6 deletions(-)
> 
> diff --git a/src/eapol.c b/src/eapol.c
> index 372549c6..c2dc4e4c 100644
> --- a/src/eapol.c
> +++ b/src/eapol.c
> @@ -2824,6 +2824,10 @@ void eapol_register(struct eapol_sm *sm)
>   
>   	l_queue_push_head(state_machines, sm);
>   
> +	/* workaround against SEGV on fct. eapol_rx_packet by avoiding for two different eapol_frame_watches with different ids, but same eapol_sm ptr */
> +	if ((sm->watch_id > 0) && eapol_frame_watch_remove(sm->watch_id)) {
> +		l_debug("existing frame_watch for sm=%p with id=%u successfully removed", sm, sm->watch_id);
> +	}
>   	sm->watch_id = eapol_frame_watch_add(sm->handshake->ifindex,
>   						rx_handler, sm);
>   	sm->protocol_version = sm->handshake->proto_version;
> diff --git a/src/station.c b/src/station.c
> index 8fcf8c70..077e510e 100644
> --- a/src/station.c
> +++ b/src/station.c
> @@ -2253,7 +2253,7 @@ static bool station_can_fast_transition(struct station *station,
>   {
>   	uint16_t mdid;
>   
> -	if (!hs->mde)
> +	if (!hs || !hs->mde)
>   		return false;
>   
>   	if (ie_parse_mobility_domain_from_data(hs->mde, hs->mde[1] + 2,
> @@ -2917,7 +2917,7 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list,
>   
>   	orig_security = network_get_security(network);
>   
> -	if (hs->mde)
> +	if (hs && hs->mde)
>   		ie_parse_mobility_domain_from_data(hs->mde, hs->mde[1] + 2,
>   							&mdid, NULL, NULL);
>   
> @@ -2930,7 +2930,7 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list,
>   	if (bss && !station->ap_directed_roaming) {
>   		double cur_bss_rank = bss->rank;
>   
> -		if (hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid)
> +		if (hs && hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid)
>   			cur_bss_rank *= RANK_FT_FACTOR;
>   
>   		cur_bss_group_rank = evaluate_bss_group_rank(bss->addr,
> @@ -2967,8 +2967,8 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list,
>   			goto next;
>   
>   		/* Skip result if it is not part of the ESS */
> -		if (bss->ssid_len != hs->ssid_len ||
> -				memcmp(bss->ssid, hs->ssid, hs->ssid_len))
> +		if (hs && (bss->ssid_len != hs->ssid_len ||
> +				memcmp(bss->ssid, hs->ssid, hs->ssid_len)))
>   			goto next;
>   
>   		if (scan_bss_get_security(bss, &security) < 0)
> @@ -2986,7 +2986,7 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list,
>   
>   		rank = bss->rank;
>   
> -		if (hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid)
> +		if (hs && hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid)
>   			rank *= RANK_FT_FACTOR;
>   
>   		group_rank = evaluate_bss_group_rank(bss->addr, bss->frequency,


Kind regards,

Paul