Re: [PATCH 2/2] src/station.c: fix of SEGV in station_roam_scan_notify when performing repeated roam scan at legacy roaming after ft_auth-/ft_reassoc-timeout when using mwifiex / NXP 88W9098 driver

James Prestwood <[email protected]> Tue, 14 Jul 2026 06:37:48 -0700
Newsgroups dev.linux.lists.iwd
Message-ID <[email protected]>
Hi Dierk,

On 7/13/26 4:35 AM, Dierk Modrow wrote:
> From: DEMODDIE <[email protected]>
>
> ---
>   src/station.c | 12 ++++++------
>   1 file changed, 6 insertions(+), 6 deletions(-)
>
> diff --git a/src/station.c b/src/station.c
> index 8fcf8c70..077e510e 100644
> --- a/src/station.c
> +++ b/src/station.c
> @@ -2253,7 +2253,7 @@ static bool station_can_fast_transition(struct station *station,
>   {
>          uint16_t mdid;
>
> -       if (!hs->mde)
> +       if (!hs || !hs->mde)
>                  return false;
>
>          if (ie_parse_mobility_domain_from_data(hs->mde, hs->mde[1] + 2,
> @@ -2917,7 +2917,7 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list,
>
>          orig_security = network_get_security(network);
>
> -       if (hs->mde)
> +       if (hs && hs->mde)
>                  ie_parse_mobility_domain_from_data(hs->mde, hs->mde[1] + 2,
>                                                          &mdid, NULL, NULL);
>
> @@ -2930,7 +2930,7 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list,
>          if (bss && !station->ap_directed_roaming) {
>                  double cur_bss_rank = bss->rank;
>
> -               if (hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid)
> +               if (hs && hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid)
>                          cur_bss_rank *= RANK_FT_FACTOR;
>
>                  cur_bss_group_rank = evaluate_bss_group_rank(bss->addr,
> @@ -2967,8 +2967,8 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list,
>                          goto next;
>
>                  /* Skip result if it is not part of the ESS */
> -               if (bss->ssid_len != hs->ssid_len ||
> -                               memcmp(bss->ssid, hs->ssid, hs->ssid_len))
> +               if (hs && (bss->ssid_len != hs->ssid_len ||
> +                               memcmp(bss->ssid, hs->ssid, hs->ssid_len)))
>                          goto next;
>
>                  if (scan_bss_get_security(bss, &security) < 0)
> @@ -2986,7 +2986,7 @@ static bool station_roam_scan_notify(int err, struct l_queue *bss_list,
>
>                  rank = bss->rank;
>
> -               if (hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid)
> +               if (hs && hs->mde && bss->mde_present && l_get_le16(bss->mde) == mdid)
>                          rank *= RANK_FT_FACTOR;
>
>                  group_rank = evaluate_bss_group_rank(bss->addr, bss->frequency,
> --
> 2.53.0.windows.2
>
Are you sure you're not looking in the wrong place? You mention ft_auth 
and ft_associate, but the behavior differs significantly if there's a 
timeout:

- If ft_auth times out IWD will try another BSS and the handshake is 
preserved.
- If ft_reassoc times out the kernel forces a disconnect, destroying the 
handshake

That said I'm not sure how we can get into station_roam_scan_notify 
without a handshake... If we ever disconnect the scan callback should be 
canceled, even if its still in-flight ELL will null out the callback, we 
should just never get there.

Is there a bug causing the callback to get called? (maybe?) but if so 
that's where we should fix this, not checking if the handshake exists 
when it always should. An L_WARN_ON check might be appropriate at the 
top level to both prevent a hard crash and provide a warning that there 
is a bug.


Thanks,

James