Commit Graph

8139 Commits

Author SHA1 Message Date
snandini
a1aa96c98a Release 5.2.0.59W
Release 5.2.0.59W

Change-Id: I51dcc05615eb205298225880f0eed3d92f9fc916
CRs-Fixed: 774533
2018-01-02 15:37:36 -08:00
Kapil Gupta
2a0781fb4c qcacld-3.0: Remove excessive logging for FILS based connection
Currently host driver is dumping all the connection related
info for FILS connection.

Add changes to remove excessive logging for FILS connection

Change-Id: Ib23a90672413e00c06ae61f01fbbb0fb51edda56
CRs-Fixed: 2077465
2018-01-02 15:37:35 -08:00
snandini
f3f65873ab Release 5.2.0.59V
Release 5.2.0.59V

Change-Id: Ib56b621a0a667e51fe54d309eb71099361792277
CRs-Fixed: 774533
2018-01-02 07:26:38 -08:00
wadesong
c46581bc1c qcacld-3.0: Fix an ACS hw mode mapping discrepancy
When ACS is started, acs_cfg.hw_mode in AP context will
be set after mapping from values defined in enum
qca_wlan_vendor_acs_hw_mode to values defined in enum
eCsrPhyMode, but when ACS scan fails due to some reason,
such as scan timeout, the code in function
sap_select_default_oper_chan is still using values
defined in enum qca_wlan_vendor_acs_hw_mode to setup
the default channel.

Change the code in function sap_select_default_oper_chan
to use the values defined in enum eCsrPhyMode when
setting up the default channel.

Change-Id: Ic0d43c43bf9b9a9a36c290d2754c30ebb40bb0e3
CRs-Fixed: 2163658
2018-01-02 07:26:38 -08:00
snandini
b2503551ac Release 5.2.0.59U
Release 5.2.0.59U

Change-Id: I80748c06b091075f7ac315f10c7275595f50e990
CRs-Fixed: 774533
2017-12-29 06:17:01 -08:00
Yeshwanth Sriram Guntuka
7cf307e148 qcacld-3.0: Save previous auth algo in pe session
DUT retries auth with open system if shared key
authentication is not supported by AP. If auth
response from AP for open system auth has same
sequence number as that of shared key response,
host drops the frame.

Fix is to drop the auth frame only if previous
sequence number and auth algo match with current
sequence number and auth algo.

Change-Id: Ia02408d72371dfb91a7cae190ae9399cdf2e2e8b
CRs-Fixed: 2163231
2017-12-29 06:17:00 -08:00
snandini
92dff40b76 Release 5.2.0.59T
Release 5.2.0.59T

Change-Id: I12c7da84ecbc22f811d05020dca2b961b1a1f3f2
CRs-Fixed: 774533
2017-12-29 05:28:42 -08:00
Himanshu Agarwal
ff399e36cb qcacld-3.0: Calculate buf_len properly for extscan hotlist event buffer
Calculate buf_len properly for extscan hotlist event buffer in
wma_extscan_hotlist_match_event_handler()

Change-Id: I923f0d86d83902539a7d3a7b8ea8322dcb83ba00
CRs-Fixed: 2161977
2017-12-29 05:28:40 -08:00
Ganesh Kondabattini
b6fdb6311f qcacld-3.0: Increase the max beacon count value to 10
Modify the upper limit of beacon count to 10.

CRs-Fixed: 2165013
Change-Id: Id6e6fb7eb2435f91e8052b6e8af10435dc25a2d2
2017-12-29 05:28:34 -08:00
Sandeep Puligilla
00d2a1f2c6 qcacld-3.0: Add HDD support to spectral scan
Add HDD support to spectral scan vendor commands

Change-Id: Ie58fabfca07077fd1b886eeb63c1a9361030035f
CRs-Fixed: 2165256
2017-12-29 05:28:28 -08:00
snandini
29751c6b69 Release 5.2.0.59S
Release 5.2.0.59S

Change-Id: I6c002b2e444d366474004b31500c650377aeaed8
CRs-Fixed: 774533
2017-12-28 21:26:32 -08:00
Vignesh Viswanathan
9dd88d39b7 qcacld-3.0: Determine transition status for BSS transition candidates
Determine bss transition status for preferrable candidates provided
by userspace based on the transition reason, rssi of connected and
candidate bssids and other parameters like whether transitiong to the
candidate will result in sub-optimal scenario. The transition status
is either accept or a reason for reject.

Change-Id: Ib83c81909f4d8e31b4125309b8ac392a26a0d6bf
CRs-Fixed: 2007107
2017-12-28 21:26:31 -08:00
snandini
b399834d69 Release 5.2.0.59R
Release 5.2.0.59R

Change-Id: Id7b118b71aaf99623855e205a26341f6d9e1d964
CRs-Fixed: 774533
2017-12-28 15:25:55 -08:00
Rajeev Kumar
6d0b2eaaf0 qcacld-3.0: Rate limit error logs in data path
Rate limit error logs in data path to avoid watch dog bark.

Change-Id: Id20f6224928c6b5e27a04daa6b9a10084ad122b9
CRs-Fixed: 2162954
2017-12-28 11:59:44 -08:00
snandini
63e72af541 Release 5.2.0.59Q
Release 5.2.0.59Q

Change-Id: I74d26e81a21794f9e7581362f697709f3d419313
CRs-Fixed: 774533
2017-12-28 05:06:53 -08:00
Jiachao Wu
d58cfc9eee qcacld-3.0: Check NULL pointer of roam_profile
__wlan_hdd_cfg80211_get_key was invoked when unloading driver.
SAP ctx had been freed at this time.wlan_sap_get_roam_profile will
return NULL.
Check NULL pointer before use roam_profile.

Change-Id: If1f11f0fb7027a6af4e3242fe9af722740d32850
CRs-Fixed: 2162395
2017-12-28 05:06:52 -08:00
Himanshu Agarwal
61990374c0 qcacld-3.0: Add data_len check to avoid OOB access
Add data_len check in wma_stats_ext_event_handler()
to avoid OOB access.

Change-Id: I756ec66fee1cf937f144441a051e973cd561909d
CRs-Fixed: 2160395
2017-12-28 05:06:50 -08:00
snandini
55424ec371 Release 5.2.0.59P
Release 5.2.0.59P

Change-Id: I83d76f13884f55c199acdc7e8ece9c116f3be41d
CRs-Fixed: 774533
2017-12-28 04:27:42 -08:00
Himanshu Agarwal
822187985e qcacld-3.0: Add num_debug_register check to avoid OOB access
Add num_debug_register check in
wma_unified_power_debug_stats_event_handler() to avoid OOB access.

Change-Id: Iae206bc467a940a8fbc1128bff498af958df1c04
CRs-Fixed: 2160403
2017-12-28 04:27:41 -08:00
Himanshu Agarwal
55e1621dd2 qcacld-3.0: Add data_len check to avoid OOB access
Add data_len check in wma_nan_rsp_event_handler()
to avoid OOB access.

Change-Id: Iff42da84567381a4b64bc07e69ff1a0cd4b5a543
CRs-Fixed: 2160375
2017-12-28 04:27:39 -08:00
snandini
a1ebf33bbb Release 5.2.0.59O
Release 5.2.0.59O

Change-Id: If873a066d582d7804f5285cc930ee263a6ae78d8
CRs-Fixed: 774533
2017-12-28 03:38:25 -08:00
Tiger Yu
6a10e3e173 qcacld-3.0: Fix potential buffer overwrite in the htt_t2h_lp_msg_handler
qcacld-2.0 to qcacld-3.0 propagation

Check for the validity of tx_desc_id when received the htt message of
HTT_T2H_MSG_TYPE_MGMT_TX_COMPL_IND from firmware to ensure the buffer
overwrite does not happen.

Change-Id: I0afc781b7fff303525352b817e7eb60b8b05e4d3
CRs-Fixed: 2164705
2017-12-28 03:38:24 -08:00
Himanshu Agarwal
1b34c1f30f qcacld-3.0: Add num_peer check to avoid OOB access
Add num_peer check in wma_ibss_peer_info_event_handler()
to avoid OOB access.

Change-Id: Id798a2143b201e60fbcc4a3881c1cda3e3376eca
CRs-Fixed: 2160461
2017-12-28 03:38:21 -08:00
Hanumanth Reddy Pothula
07e5f99716 qcacld-3.0: Remove FW memory dump feature
qcacld-2.0 to qcacld-3.0 propagation

FW memory dump feature is no longer used. Hence remove FW memory
dump feature code changes.

Change-Id: Ida655f83630c369df746e7c0c9d61a8fee2932a2
CRs-Fixed: 2140261
2017-12-28 11:54:10 +05:30
snandini
daf47342e0 Release 5.2.0.59N
Release 5.2.0.59N

Change-Id: I399dfbac843e1d69130b6cac99bbbe79ae411782
CRs-Fixed: 774533
2017-12-26 17:26:58 -08:00
snandini
f37ce13c6c Release 5.2.0.59M
Release 5.2.0.59M

Change-Id: I29df3be2b462a61b4a9567ae3b95178f89dd2b4f
CRs-Fixed: 774533
2017-12-25 23:26:38 -08:00
Dustin Brown
36e24e273b qcacld-3.0: close all adapters before module stop
Adapter resources are not being released until after stop modules. This
leads to resource leaks on PCIe targets. Move the call to close adapters
to before stop modules.

Change-Id: I18ceba26bb6aab634da91a14cc6890a7b7bd836f
CRs-Fixed: 2162868
2017-12-25 23:26:38 -08:00
Kabilan Kannan
75bd4b3310 qcacld-3.0: Rate limit TX data transmit error in HDD
TX data transmit error is flooding out the logging
system.
Rate limit the TX transmit error to avoid
log buffer overrun.

Change-Id: Ie6f857378f1d8d2ee07ba0d6e10639f6f5dcbd1c
CRs-Fixed: 2160835
2017-12-25 23:26:34 -08:00
Vignesh Viswanathan
bdfbaa9cbf qcacld-3.0: Fix buffer overwrite in lim_send_probe_rsp_template_to_hal
In function lim_send_probe_rsp_template_to_hal, memset is done for the
allocated packet for length nBytes which is calculated as size of payload +
MAC header + addn_ielen.
However, the buffer used psessionEntry->pSchProbeRspTemplate is allocated
for length 512 (SCH_MAX_PROBE_RESP_SIZE) only as part of create session.
This leads to a potential overflow of the memory if nBytes calculated is
greater than 512 leading to kernel panic while freeing the memory in
delete session.

Add sanity check to make sure we do not exceed the SCH_MAX_PROBE_RESP_SIZE
before doing a memset on the buffer.

Change-Id: I4657d34a429b1f0c11ac8ca24869727c222669b8
CRs-Fixed: 2160086
2017-12-25 23:26:31 -08:00
snandini
e6bce00c2c Release 5.2.0.59L
Release 5.2.0.59L

Change-Id: Ie3eb7e2b1ac9f163ebb5993a26b060e07eb5af52
CRs-Fixed: 774533
2017-12-25 21:26:13 -08:00
Ashish Kumar Dhanotiya
d2b9064557 qcacld-3.0: Buffer overwrite in vendor scan request on n_ssid
In function __wlan_hdd_cfg80211_vendor_scan, when SCAN_SSIDS
and QCA_WLAN_VENDOR_ATTR_SCAN_FREQUENCIES are parsed, if the
number of SSIDs or number of channels are more then 255 in
netlink message, n_ssid and n_channels will get overflow
because n_ssid and n_channels are of type uint8_t.

Add a check to validate the max number of SCAN_SSIDs against
MAX_SCAN_SSID and max number of channels against MAX_CHANNEL.

Change-Id: Ib31dcc912fee8639e26d836d2fc5a32bf81fb43d
CRs-Fixed: 2153343
2017-12-25 21:26:13 -08:00
Dustin Brown
26b3d04130 qcacld-3.0: Fix runtime leak compilation issue
HDD calls several qdf_debug_domain APIs when that feature is not
enabled. Add conditional compilation to avoid these calls when runtime
leak detection is not enabled.

Change-Id: I78775c240b5352ed63f2e15f16e25159bbde5666
CRs-Fixed: 2162989
2017-12-25 21:26:10 -08:00
snandini
9355430d8e Release 5.2.0.59K
Release 5.2.0.59K

Change-Id: I9497b81f0c16909f5f01ce8052d32811a3824c91
CRs-Fixed: 774533
2017-12-25 19:26:03 -08:00
Paul Zhang
fb02f45704 qcacld-3.0: Register hdd_netdev_notifier properly
The statement register_netdevice_notifier(&hdd_netdev_notifier)
is replaced by hdd_register_notifiers(hdd_ctx) mistakenly when
propagating from 3.1 to 3.2.

Change-Id: Iddcc2b0375c0e81b944def117b40ea3015f91e4b
CRs-Fixed: 2163113
2017-12-25 19:26:02 -08:00
snandini
64206612cb Release 5.2.0.59J
Release 5.2.0.59J

Change-Id: I56bc7e2d3f87f91c1b8a29971a6a496414c4e380
CRs-Fixed: 774533
2017-12-25 13:26:02 -08:00
Vignesh Viswanathan
59bf3d4bf0 qcacld-3.0: Fix potential OOB read in lim_parse_kde_elements
In function lim_parse_kde_elements, while parsing the KDE list from
the assoc response frame, elem_len is obtained from the frame buffer.
elem_len is then used to find the matching OUI for KDE OUI type and
then to calculate data_len based on the offset for the GTK/IGTK data
types.

If the value in elem_len field in the frame is less than the Data
Offset (which includes the OUI and data type) or the GTK/IGTK offset
then a OOB read would occur.

Add checks to validate the elem_len with Data offset and then with
the GTK/IGTK offset based on the data type.

Change-Id: I8ae31c6d6c28e88ad9bda757b3f1ff2585f8a553
CRs-Fixed: 2161920
2017-12-25 13:26:01 -08:00
snandini
9c8e7e6222 Release 5.2.0.59I
Release 5.2.0.59I

Change-Id: I2055927fba7705f2a909b6e874ed82de8bedd28b
CRs-Fixed: 774533
2017-12-22 19:26:33 -08:00
wadesong
db4d958ba4 qcacld-3.0: Refine peer object cleanup sequence
When a peer object is to be removed in WLAN HDD object manager
code, it should be logically deleted first before it's ref
count is decreased and the peer object is freed, or there will
be a potential race condition, in which a freed peer object
buffer will be accessed.

Change-Id: Ib3179e8207d1e9bbaa9c2b8450a8016e23cfc3f3
CRs-Fixed: 2161627
2017-12-22 19:26:32 -08:00
Poddar, Siddarth
3f97e3dca7 qcacld-3.0: Check for peer delete in progress before assigning to temp var
With the existing implementation of TAILQ_FOREACH_REVERSE
in ol_txrx_remove_peers_for_vdev() function, host traverses
the list, stores the peer in the var, releases the lock and
later temp var is getting deleted as part of peer unmap and
host end up in accessing the stale peer entry.

To avoid this, host should check the peer delete in progress
first before assigning it to the temp var.

Change-Id: I5b9a401ae062efc6d2fbe608b25424a27c9d9f94
CRs-Fixed: 2159446
2017-12-22 19:26:30 -08:00
Naveen Rawat
f939162569 qcacld-3.0: Avoid possible null pointer dereference
Check hdd_ctx, adapter and sta_ctx against null before dereferencing
them in wlan_hdd_nan_datapath.c

Change-Id: Ie81a359be4f03f4f7e411b56d583c12fa3bb03c0
CRs-Fixed: 2162244
2017-12-22 19:26:28 -08:00
snandini
9dae0a4488 Release 5.2.0.59H
Release 5.2.0.59H

Change-Id: If23d863e00f28d1357c3790b4b90adf9b73fe0b2
CRs-Fixed: 774533
2017-12-22 15:26:12 -08:00
Naveen Rawat
170420a953 qcacld-3.0: Change log level of debug message
Change log level of warning message to debug in functions:
__lim_process_operating_mode_action_frame
lim_is_robust_mgmt_action_frame

Change-Id: I8572dc9e6182767809df810fd6f74a307508e32a
CRs-Fixed: 2162961
2017-12-22 15:26:11 -08:00
Arif Hussain
21ad43430c qcacld-3.0: Add null pointer check and fix buffer overflow in sap
Add null pointer validation and fix possible buffer overflow issue
in sap module.

Change-Id: I314e07a31368dd3ca854b9aeab4a0bce0402a81b
CRs-Fixed: 2162246
2017-12-22 15:26:08 -08:00
Himanshu Agarwal
b956c03cb0 qcacld-3.0: Assign correct preamble type for OFDM packets
Presently, OFDM packets are assigned preamble type of
LONG_PREAMBLE when the type should be SHORT_PREAMBLE.

Assign the preamble type correctly.

Change-Id: Ie16936ba54cb8e1dfa5e96ccc52f3fc6693a5d48
CRs-Fixed: 2159511
2017-12-22 15:26:05 -08:00
snandini
61962a876c Release 5.2.0.59G
Release 5.2.0.59G

Change-Id: I36d1f4db20fb6de2ceb3fbc37582c191c5b45fb0
CRs-Fixed: 774533
2017-12-22 13:26:22 -08:00
gaurank kathpalia
90f83f081b qcacld-3.0: Change scores for QBSS/ESP load
Currently in the scoring logic the host has the same
score of 125 for the QBSS/ESP load between 50% to 75%
and 75% to 100% which sometimes may result in improper
scoring for cases where AP1 has air time fraction
127 which  convertes to 51% load and other AP2 has air
time fraction 13 which convertes to 95 % load.
But the score is same for both AP and the host selects
randomly any one of the AP instead of AP1

Fix is to change score for QBSS/ESP load to differentiate
between 50-75% and 75-100% load

Change-Id: I96d0d8a6a0a1854b2faca4435afa612336bc3caf
CRs-Fixed: 2161778
2017-12-22 13:26:22 -08:00
snandini
199108d6c8 Release 5.2.0.59F
Release 5.2.0.59F

Change-Id: I54c141604efa30591533733856dfad40bf970619
CRs-Fixed: 774533
2017-12-22 11:37:43 -08:00
Dustin Brown
db0c68806a qcacld-3.0: Remove FTM checks from memdump init/deinit
The transition to/from FTM happens after the memdump feature is
initialized. However, the memdump init/deinit functions bail out if the
driver is currently in FTM. This leads to situations were memdump is
initialized, but skips deinitialization when the driver is in FTM at the
time of unload. Since memdump is always initialized during driver probe
(the driver is never in FTM at that time), always deinitialize on driver
unload.

Change-Id: Ib3555a89f64912403d8858877086ab070ce24e35
CRs-Fixed: 2162241
2017-12-22 11:37:42 -08:00
snandini
996bb6f3cd Release 5.2.0.59E
Release 5.2.0.59E

Change-Id: I4da1e61f9937fe9f90cd6dc1b2a023f9aace0d97
CRs-Fixed: 774533
2017-12-22 09:26:09 -08:00
hqu
5e6b9866fd qcacld-3.0: Move log level to info high if tx hits invalid station id
For sns test in some scenarios when tx hits invalid station id it will
print massive log so that it will lead to WD bark issue.

Move log level to lower info high from info if tx hits invalid station
id, also align with cld3.1 code.

Change-Id: I965033fc8232c8ead15ef06d26aa0d1d2b468e8a
CRs-Fixed: 2159529
2017-12-22 09:26:09 -08:00
Vignesh Viswanathan
117c2031ee qcacld-3.0: Add suppport to forward GAS action frames to supplicant
Add changes identify and forward GAS public action frames to
supplicant in lim_process_action_frame_no_session.

Change-Id: Id872e2b0b8b7a203b472e0bd152f25f63c873b4f
CRs-Fixed: 2161785
2017-12-22 09:26:06 -08:00
snandini
4aade6ed56 Release 5.2.0.59D
Release 5.2.0.59D

Change-Id: I759824ca7c638ac3d391ca6b9d191727495a9340
CRs-Fixed: 774533
2017-12-22 01:27:30 -08:00
Vignesh Viswanathan
448573185e qcacld-3.0: Fix min IE length for FILS indication IE
FILS indication IE minimum length should be 4 bytes (2 bytes for tag and
length) + (2 bytes for realm hash). However current mininum is set to
5 bytes.
Usually AP sends cache identifier also in the FILS indication IE, which
is optional and causes the ie length to be greater than min of 5.
If the AP does not send Cache Identifier and sends only realm hash,
the IE length would be 4, which causes the IE to be skipped in parsing
thereby failing FILS connection.

Fix min IE length to 4 bytes in the frame parser for FILS Indication IE

Change-Id: I07f2b724f5840f9ba8ec663e0b303d8fc86663da
CRs-Fixed: 2161241
2017-12-22 01:27:28 -08:00
snandini
577128f1f3 Release 5.2.0.59C
Release 5.2.0.59C

Change-Id: I5177c3ddea7e1cf060496fe4ad337c657a19e455
CRs-Fixed: 774533
2017-12-21 23:37:49 -08:00
Vignesh Viswanathan
93b7f70f80 qcacld-3.0: Add WiderBWChanSwitchAnn IE to ext_chan_switch_ann action frame
Add the WiderBWChanSwitchAnn to ext_chan_switch_ann action frame
as optional IE. Currently WiderBWChanSwitchAnn is added only in
beacon frames.

Change-Id: I4f76479bdb2befa93fcb83238590007a555af210
CRs-Fixed: 2141529
2017-12-21 23:37:48 -08:00
snandini
9fb9f5cf77 Release 5.2.0.59B
Release 5.2.0.59B

Change-Id: Ifa002dd7db2347291b92cc97d6207be8ca463777
CRs-Fixed: 774533
2017-12-21 17:39:47 -08:00
Rajeev Kumar
5d17dd531f qcacld-3.0: Avoid qdf_mem_cpy when source pointer is null
During SAP SSR scan default ie data pointer is cleared and
set to null hence avoid unnecessary qdf_mem_cpy when source
pointer is null.

Change-Id: I75960c69804144abee5b1978b43002110b0d0be4
CRs-Fixed: 2161056
2017-12-21 17:39:46 -08:00
snandini
3f6a15ac26 Release 5.2.0.59A
Release 5.2.0.59A

Change-Id: I3c0375e9504555c47db5c76cfc42e39c7760eb5b
CRs-Fixed: 774533
2017-12-21 11:32:32 -08:00
Himanshu Agarwal
75c8d796d9 qcacld-3.0: Set high priority as false for stop bss sme command
When stop AP command is received from hostapd, all the stations
are deauthenticated and then stop bss is called. But stop bss is
called with high priority as true and so gets queued on the top
of the list while del sta commands are queued at the tail as high
priority is set to false for those. This leads to desynchronization
as the commands are not serialized.

Set high priority as false for stop bss sme command to serialize all
the commands.

Change-Id: I9c80032c418e05d3b5591bb3cfd70f8285f27fe8
CRs-Fixed: 2161257
2017-12-21 11:32:32 -08:00
wadesong
f13dbd60e9 qcacld-3.0: Suppress verbose WMA debug printing
The eGAP status update event handler is exhibiting a too verbose
debug printing.

Supress the eGAP status update by increasing the debug level.

Change-Id: I85e290abfe03d488ab770a3a403871d984ee8df9
CRs-Fixed: 2161713
2017-12-21 11:32:29 -08:00
snandini
e4ee084f0a Release 5.2.0.59
Release 5.2.0.59

Change-Id: I12dbca198663792d9b8dbc2340d80a30dbae52df
CRs-Fixed: 774533
2017-12-21 09:21:47 -08:00
Ashish Kumar Dhanotiya
a60c1754b3 qcacld-3.0: Possible buffer overwrite in vendor scan request
In api "__wlan_hdd_cfg80211_vendor_scan", the ssid length is u8,
when memcpy is done for ssid, the length is not validated and
nla_len(attr) is used directly in memcpy which can result in buffer
overwrite.

Add a check to validate the max length of scan ssid against
SIR_MAC_MAX_SSID_LENGTH.

Change-Id: If4c25710973ee50094c5d52410269962f552ac3f
CRs-Fixed: 2153326
2017-12-21 09:21:46 -08:00
snandini
19fd6ba846 Release 5.2.0.58Z
Release 5.2.0.58Z

Change-Id: I190092f4cfe1338458e5f3e76ae9af6120317fc9
CRs-Fixed: 774533
2017-12-21 05:26:43 -08:00
Yeshwanth Sriram Guntuka
9b9eb43d00 qcacld-3.0: Set passive dwell time
Set passive dwell time to 28msecs for active
scan when bt a2dp is enabled and hw is not dbs
capable and when sta is connected on 2G band.

Change-Id: I44f2e3d98f2d7ddc52e4902ba989131c256da4ef
CRs-Fixed: 2146311
2017-12-21 05:26:42 -08:00
snandini
8841c95cf1 Release 5.2.0.58Y
Release 5.2.0.58Y

Change-Id: Iefda078904b76b7f986dfe9effc9a71d8ee9bbfa
CRs-Fixed: 774533
2017-12-21 01:39:12 -08:00
Naveen Rawat
2f13193c4a qcacld-3.0: Fix handler for operating mode action frame
Do not drop operating mode action frame if channel bonding is disabled.
Process NSS change if requested by frame.

Change-Id: Id342c5399a70be8ea1b3d6c9878983a75ca456ad
CRs-Fixed: 2157167
2017-12-21 01:39:11 -08:00
snandini
d0f8724f02 Release 5.2.0.58X
Release 5.2.0.58X

Change-Id: I33debbe901ff3ff4b4b9a90c1ec8ae5324ca0c0f
CRs-Fixed: 774533
2017-12-20 21:27:56 -08:00
Poddar, Siddarth
61fbc93f6e qcacld-3.0: Enable pktlog after SSR/PDR if previously enabled
Implement a flag in hdd context to track the state of
pktlog events. Pktlog will be enabled/disabled after SSR/PDR,
depending upon the state of Pktlog events just before SSR/PDR
is triggered.

Change-Id: I18999d7fcf3677a86c21559d7d443ba1cd086528
CRs-Fixed: 2151296
2017-12-20 21:27:56 -08:00
snandini
3228756801 Release 5.2.0.58W
Release 5.2.0.58W

Change-Id: I21ae25f0ada369275c945cf3e0fd9f376ccc4646
CRs-Fixed: 774533
2017-12-20 19:27:31 -08:00
gaurank kathpalia
0efbb56f81 qcacld-3.0: Change default value of g_is_bssid_hint_priority to 0
Change default value of g_is_bssid_hint_priority to 0, as the driver
scoring logic will take care of the beat AP to select from the candidate
AP and the host can ignore the hint.

Change-Id: Ia372e3e0f580047eae33cc0b68b0a0d1460ebfc2
CRs-Fixed: 2160591
2017-12-20 19:27:30 -08:00
Dustin Brown
4c5b990170 qcacld-3.0: Add hdd_check_for_leaks function docs
In cases where memory allocated at runtime is release during module
unload, it is tempting to label these memory leaks as false positives.
Add documentation to hdd_check_for_leaks explaining why these are real
memory leaks. This helps reduce confusion, and helps to dissuade
developers from "fixing" the runtime memory leak logic, instead of
fixing the memory leak.

Change-Id: I2f7574e7465630d2d9f96280ecf8180a51b41e0f
CRs-Fixed: 2161394
2017-12-20 19:27:27 -08:00
Yuanyuan Liu
23a8eecd28 qcacld-3.0: remove struct sps_iovc reference
Since struct sps_iovc is obsolete in the latest kernel,
use a local macro instead of sizeof() . It should be
updated with the correct IPA size macro once it is
avaiable in the latest kernel.

CRs-Fixed: 2160658
Change-Id: Ifc2926d5182c96e07de6b4ddd50156764b7ad51e
2017-12-20 19:27:24 -08:00
gaurank kathpalia
16a721a680 qcacld-3.0: Fix memory leak issue of ch_list in sap_get_channel_list
In the api sap_get_channel_list, list is allocated memory to store the
channel list to be sent for scan request. This api is called by
sap_goto_channel_sel which initializes scan_request.ChannelInfo.ChannelList
to channel_list, without any prior NULL check of channel_list.
Also in scan callback wlansap_scan_callback, if the state machine structure
is in disconnected state , the host returns without freeing the memory
allocated to the channel list in sap_ctx .

Fix is to free the memory allocated to the channel list
and make the sap_ctx->channellist, sap_ctx->num_of_channel
as NULL and zero respectively in both the instances.

Change-Id: Ia54287d6e77e206c717bd3c205ebe57510ea801c
CRs-Fixed: 2159489
2017-12-20 19:27:21 -08:00
snandini
a3726d9963 Release 5.2.0.58V
Release 5.2.0.58V

Change-Id: Ie916f23741b2b4e4df2e72cfbbe37ff96bfb89df
CRs-Fixed: 774533
2017-12-20 15:26:55 -08:00
gaurank kathpalia
addd8a0b0d qcacld-3.0: Change default value of pcl_weightage to 0
Change default value of pcl_weightage to 0, as pcl
weightage logic need some changes in algo to be used in LFR3.

Change-Id: I21559f7aaa8a19388cf399dee684c00c7905cfae
CRs-Fixed: 2160589
2017-12-20 15:26:54 -08:00
snandini
573d5d914f Release 5.2.0.58U
Release 5.2.0.58U

Change-Id: I5fcc1557ecc1a35798e204fdb043a0c971fbfe30
CRs-Fixed: 774533
2017-12-20 14:10:32 -08:00
Naveen Rawat
a015a2f712 qcacld-3.0: Support HE dual band by default
Add support for dual band in HE caps by:
1) Setting default value of HE dual_band support to 1.
2) Checking advertised FW MAC cap for support of both bands.

Change-Id: I978e4082364b832dc3f49f13a00ef9159f269f72
CRs-Fixed: 2160792
2017-12-20 14:10:31 -08:00
psimha
deea0a130c qcacld-3.0: Add fixes to prevent NULL pdev access on module stop
- Change the order of the deinit code of pktlog
- Change the order of the deinit code of runtime pm

Change-Id: I570b20b247b7892f9bba82f3d3a58aff9af09105
CRs-Fixed: 2160794
2017-12-20 14:10:28 -08:00
snandini
dfe8f777e3 Release 5.2.0.58T
Release 5.2.0.58T

Change-Id: I2139644bedeaed60f06d34c6582871c58236057a
CRs-Fixed: 774533
2017-12-20 07:26:07 -08:00
Paul Zhang
72697bdc04 qcacld-3.0: Add ini hostscan_adaptive_dwell_mode_no_conn
This ini will set the algo used in dwell time optimization
during host scan without connection.

Change-Id: Ie81636d32b6c42651aa9b5de52889970c17f6aca
CRs-Fixed: 2159656
2017-12-20 07:26:06 -08:00
snandini
75f57b9cc4 Release 5.2.0.58S
Release 5.2.0.58S

Change-Id: I67386963967b0cffe12bb688d226bf9d16b38dca
CRs-Fixed: 774533
2017-12-20 05:38:38 -08:00
Kiran Kumar Lokere
4aa08a5c14 qcacld-3.0: Add configuration support for he dynamic fragmentation
Add user configuration for HE dynamic fragmentation capability
support

Change-Id: I94a18b5102b1ee303ccbf832e67c37930f523bec
CRs-Fixed: 2159864
2017-12-20 05:38:38 -08:00
snandini
82348f5aa4 Release 5.2.0.58R
Release 5.2.0.58R

Change-Id: Ic553857324b7ebc286135c34962b167f1d2f8cb3
CRs-Fixed: 774533
2017-12-20 02:26:58 -08:00
Amar Singhal
6c0c0d9f2b qcacld-3.0: Change the name of the sysfs path
Use string "wifi" instead of "wlan" in sysfs path for version string.
This is to avoid warning for same string name in the path.

Change-Id: Ifadabdb3e89d9a6564bbda58241f3ff38eeb4eb1
CRs-Fixed: 2153885
2017-12-20 02:26:58 -08:00
Amar Singhal
0928b19abe qcacld-3.0: Add sysfs interface for retrieving version information
User-space needs sysfs interface for retrieving version
information for both firmware and driver. Add this new
sysfs interface.

Change-Id: I666aff1868f4d1d954773fae1ae85c1ebd0fdc87
CRs-Fixed: 2153885
2017-12-20 02:26:54 -08:00
snandini
b98b8b0849 Release 5.2.0.58Q
Release 5.2.0.58Q

Change-Id: I2f472f4d401098b4e3baf37e5a3e984728763c72
CRs-Fixed: 774533
2017-12-20 01:38:52 -08:00
gaurank kathpalia
2690098b55 qcacld-3.0: Fix condition to ignore security in scan filter
In api csr_prepare_scan_filter,If bWPSAssociation is set or
bOSENAssociation is set, the security check  while filtering
scan results need to be skipped.

Fix is to check for both bWPSAssociation and bOSENAssociation
to set the ignore security flag in converged scan filter

Change-Id: I1e850581ab1cd3b313e681bfd110280765fa6a2a
CRs-Fixed: 2161103
2017-12-20 01:38:51 -08:00
Poddar, Siddarth
d021751ded qcacld-3.0: Fix to get correct 64-bit htt rx address
Fix is to get correct 64-bit htt rx in order address
when ENABLE_DEBUG_ADDRESS_MARKING is disabled.

Change-Id: I479ed4a2dd5cee3427f9a3714cda4ed50afa271a
CRs-Fixed: 2161207
2017-12-20 01:38:48 -08:00
Wu Gao
9c01ec4ae5 qcacld-3.0: Update channel width and set channel for SAP
It does not set channel width and set channel for HT40 mode SAP, which
causes SAP start at HT20 mode by default.

Change-Id: Ia29c44d897384569249149bccf8d3e0516cce0ce
CRs-Fixed: 2158079
2017-12-20 01:38:45 -08:00
snandini
fd681e44db Release 5.2.0.58P
Release 5.2.0.58P

Change-Id: I60369e0643783be1db4a47a1dfcb356341a54f82
CRs-Fixed: 774533
2017-12-20 00:07:47 -08:00
Dustin Brown
45ed4bbeaa qcacld-3.0: Print drv ops inactive thread call stack
As part of the wlan driver handlers for kernel ndo events, an inactivity
timer (effectively a watchdog timer) is started. This allows us to catch
instances where drvier operations take much longer than expected. In
cases where this inactivity timer expires, print the stack trace of the
inactive thread to expedite debugging efforts.

Change-Id: I4427207a5cd7d232486ce453555765f7e0f4fe17
CRs-Fixed: 2160837
2017-12-20 00:07:46 -08:00
snandini
4fea99d090 Release 5.2.0.58O
Release 5.2.0.58O

Change-Id: I673f57131e8243fc39ef8f11ba65093f1d633365
CRs-Fixed: 774533
2017-12-19 13:37:37 -08:00
Will Huang
9adefff55a qcacld-3.0: Use correct wmi event id when register wmi event
WMI_xxx_EVENTID must re-define as wmi_xxx_event_id, otherwise module
init will fail when check event id.

Change-Id: Icf0562ddb9c6fd90b553ce06e502575d9e69b8d3
CRs-Fixed: 2159607
2017-12-19 13:37:36 -08:00
snandini
74683f3488 Release 5.2.0.58N
Release 5.2.0.58N

Change-Id: I901ba7e84cdf56d3defc1778ac3122c1bf87b5d5
CRs-Fixed: 774533
2017-12-19 09:26:42 -08:00
Yeshwanth Sriram Guntuka
3e4d96fbfa qcacld-3.0: Add check to validate vdev id
Get ARP stats command is sent to firmware with
inactive vdev id in stats param resulting in
firmware crash.

Fix is to add check to validate vdev id before
sending get ARP stats command to firmware.

Change-Id: I1483573f4f9649c307f8d47466d9c7e234e9a78e
CRs-Fixed: 2161031
2017-12-19 09:26:41 -08:00
Poddar, Siddarth
4bbe4fc724 qcacld-3.0: Do not log pktlog event when monitor mode is ON
In case of Monitor mode, headroom of skb, which originally
contains rx_desc data, is overwritten by radio tap header.

Host pulls skb data by radio tap header and the same skb is
passed on to packet log function which expects payload to
point to skb-> data and end up in wrong access.

Moreover, pktlog is meant to log rx_desc information which is
already overwritten by radio header and hence pkt logging is
of no use in this case.

CRs-Fixed: 2159130
Change-Id: Id19c0371a0ed31c70ada788fc2b396a8b1eac1f1
2017-12-19 09:26:38 -08:00
snandini
dc84a5ca07 Release 5.2.0.58M
Release 5.2.0.58M

Change-Id: Idc8d1c8816bf84cd12cec02c4bbe21b5ef5a77a4
CRs-Fixed: 774533
2017-12-19 03:48:40 -08:00
Hanumanth Reddy Pothula
8fcade5661 qcacld-3.0: Resolve overflow while processing setHostOffload ioctl
qcacld-2.0 to qcacld-3.0 propagation

While processing setHostOffload ioctl there is a possibility of
sending invalid data to lower layers as user sent data structure
is different from local buffer structure.
To mitigate this issue, initialize local buffer to zero and then
update local buffer member by member.

Change-Id: I657d2a8c7d37435b1ad28ef6de60ea80a235ead9
CRs-Fixed: 2152143
2017-12-19 03:48:40 -08:00
snandini
05e2b52b45 Release 5.2.0.58L
Release 5.2.0.58L

Change-Id: I09d2af76a72834827e201b7aee18b62b15b19a98
CRs-Fixed: 774533
2017-12-18 21:48:34 -08:00
Rajeev Kumar
b0ef982be7 qcacld-3.0: Log critical suspend/resume log using info level
Log critical suspend/resume log using info log level such that
driver 3 stage suspend/resume state is known from available logs.

Change-Id: Id17133d406f2366058198b38445d7ff6afba3764
CRs-Fixed: 2160041
2017-12-18 21:48:33 -08:00
Lin Bai
1c67848386 qcacld-3.0: Fix FTM mode malfunction and memory leak
Current driver will create two apdaters in FTM mode, with device_mode
STA and P2P, where STA is incorrect and P2P is unnecessary.
And those types will cause memory leak in
qdf_mem_malloc()/sme_deregister_mgmt_frame(), when unloading driver.

Also, it is improper to fix the interface name to wlan0 for FTM mode,
as some platforms may use different naming rule.

Only create one adapter with FTM mode, with variable interface name.

CRs-Fixed: 2160513
Change-Id: If3bf4444e5535e6fe88c3ad2d87da217534984a0
2017-12-18 21:48:31 -08:00
Jeff Johnson
876c1a6d35 qcacld-3.0: Use enum QDF_GLOBAL_MODE
Change "qcacmn: Rename enum tQDF_GLOBAL_CON_MODE" (qca-wifi-host-cmn
Change-Id I57933a62f6ce02b6594d97198be8132e61e8d1f6) renamed enum
tQDF_GLOBAL_CON_MODE to QDF_GLOBAL_MODE. Update all references to use
the new name.

Change-Id: I0e806e87a4c4828279dee83450b1fc20a236c9d3
CRs-Fixed: 2158636
2017-12-18 21:48:28 -08:00
snandini
ea3575092b Release 5.2.0.58K
Release 5.2.0.58K

Change-Id: Icda918f25b504987a3742db1bd6f407e826ad866
CRs-Fixed: 774533
2017-12-18 18:27:43 -08:00
Kabilan Kannan
44a5837f36 qcacld-3.0: Update tdls config as per target configuration
Update the default tdls configuration based on target
configuration

Change-Id: I13335f9492c218975cbd725f3e604d396379eec3
CRs-Fixed: 2159887
2017-12-18 18:27:42 -08:00
snandini
419b5d95cc Release 5.2.0.58J
Release 5.2.0.58J

Change-Id: I4b035e766f96fadfc1e69bee80ab1c4df771f9c2
CRs-Fixed: 774533
2017-12-18 15:55:09 -08:00
Amar Singhal
f0a94adf46 qcacld-3.0: print the source of country code
Country code can be set by multiple sources. Print the source of country
code for debug purposes.

Change-Id: I54f8237de540d7a0d01671148109130a28516670
CRs-Fixed: 2149684
2017-12-18 15:55:08 -08:00
Naveen Rawat
269b4ed0a7 qcacld-3.0: Add ini to control chain mask for 2G and 5G
Add ini parameters to control chain mask in 2G and 5G band.

Change-Id: I336c4598164c55d923f20b748fb189654b713102
CRs-Fixed: 2155583
2017-12-18 10:45:05 -08:00
snandini
0a448122a4 Release 5.2.0.58I
Release 5.2.0.58I

Change-Id: I16574b10260659b00fa41483cf36371960432989
CRs-Fixed: 774533
2017-12-18 05:39:56 -08:00
Vignesh Viswanathan
9fa8fef7b7 qcacld-3.0: Avoid potential OOB read in wma_is_vdev_valid function
In function wma_is_vdev_valid, vdev_id received as argument is used
to access wma_handle->interfaces array directly without validation
of max value of vdev_id. If vdev_id is not less than max_bssid, then
an OOB read would occur in this function.

Also add free and break in wma_mc_process_msg while handling
SIR_HAL_CONFIG_GUARD_TIME message in WMA.

Change-Id: I5f4481c937d5c370b334f2a7f8a172d08140ab1d
CRs-Fixed: 2154304
2017-12-18 05:39:56 -08:00
wadesong
f9b15ed483 qcacld-3.0: Abort all scan requests before SAP is stopped
Abort all outstanding scan requests on an SAP adapter synchronously
when the SAP adapter is to be stopped, so any scan callback
functions will not access the buffers for SAP adapter, ACS config,
etc. after they're freed.

Change-Id: Idc02b140c05a5de4dc652a547cd20b8d113447b6
CRs-Fixed: 2152962
2017-12-18 05:39:53 -08:00
Hanumanth Reddy Pothula
53dec12515 qcacld-3.0: Pass valid default scan IEs to firmware
During driver re-init, host might pass invalid(NULL) default scan
IEs to FW if host won't receive same IEs from supplicant as part
of vendor event QCA_NL80211_VENDOR_SUBCMD_SET_WIFI_CONFIGURATION.

Validate driver has default scan IEs, before sending same to
firmware.

Change-Id: I333ceead0c375bfb9309466e420a6860199826dc
CRs-Fixed: 2155312
2017-12-18 05:39:51 -08:00
snandini
7224ba4039 Release 5.2.0.58H
Release 5.2.0.58H

Change-Id: I80dc4059b009577dcbbc866e07cd1317bba4d645
CRs-Fixed: 774533
2017-12-17 13:37:38 -08:00
Jeff Johnson
3b2abe930d qcacld-3.0: Validate Scan Default IEs
Currently the Scan Default IEs configured via the attribute
QCA_WLAN_VENDOR_ATTR_CONFIG_SCAN_DEFAULT_IES are not validated. As a
result a buffer overread can occur when the Scan Default IEs are later
referenced. To address this issue validate the Scan Default IEs before
storing them.

Change-Id: Ifd8739c96a9990f01ff159eb59a7e904f7b8c592
CRs-Fixed: 2154346
2017-12-17 13:37:37 -08:00
snandini
649e5047c7 Release 5.2.0.58G
Release 5.2.0.58G

Change-Id: I3c554a1f4ac2272a1a7632e53303a81f9f5432e1
CRs-Fixed: 774533
2017-12-17 09:26:14 -08:00
gaurank kathpalia
1b42e8d4cb qcacld-3.0: Fix SAP replying to BC probe request in hiddenssid
The SAP configured in hidden ssid mode sends probe response
to BC probe requests in hidden ssid mode after force SCC.
In wma_set_channel, req.ssidhidden is not set by the host
which in turn sets the param->flags last bit to 0, and
the firmware receives  these flags and sends the probe
responses.In the wma_vdev_start api, the host sets the flags
based upon the req.ssidhidden received from wma_set_channel
only in vdev start case , and not in vdev restart case.

Fix is to set the value of req.ssidhidden in wma_set_channel
and to set the hidden ssid flag in both vdev start and vdev
restart case.

Change-Id: I988d8d64b06128a37824c7d31d4407247ba46dce
CRs-Fixed: 2142430
2017-12-17 04:53:18 -08:00
snandini
3dda815399 Release 5.2.0.58F
Release 5.2.0.58F

Change-Id: I7b0434995ba2fdb84ffe4d040d4347f1282063ce
CRs-Fixed: 774533
2017-12-16 15:26:18 -08:00
Dustin Brown
04348375a0 qcacld-3.0: Free scan IEs during stop adapter
Scan IEs are allocated at adapter runtime. Thus, scan IEs should be
freed during adapter stop.

Change-Id: Idd1ee68bc57ecd3dfea77a3d882b57aae21a478f
CRs-Fixed: 2159407
2017-12-16 15:26:17 -08:00
Kabilan Kannan
f0f81ad646 qcacld-3.0: Reject scan command, when firmware is down
Scan command is entertained, when the firmware is down, and
it causes crash in the system.
Reject the scan command, when firmware is down.

Change-Id: Ib3501e14846dea9ea99f6fa13695108d4ae58bf0
CRs-Fixed: 2159449
2017-12-16 15:26:14 -08:00
Varun Reddy Yeturu
91cbd1db84 qcacld-3.0: Upon roam synch failure, send roaming stop
Currently, the host sends a roam scan mode of
WMI_ROAM_SCAN_MODE_ROAMOFFLOAD to the firmware when roam
synch fails in the host. But the firmware expects a
WMI_ROAM_SCAN_MODE_NONE in the roam synch wait state
to respond with a HO_FAIL which will evetually lead
to a disconnection and clean up.

Change-Id: I39c768881c312ecbedf6e4a1742e3eaabcea1f4d
CRs-Fixed: 2159244
2017-12-16 15:26:12 -08:00
snandini
3b1e133caa Release 5.2.0.58E
Release 5.2.0.58E

Change-Id: Idf0dd624d721c26a5f495374d75f54703fe9c7e2
CRs-Fixed: 774533
2017-12-16 14:07:59 -08:00
Paul Zhang
2f1077c10a qcacld-3.0: Support LFR2.0 with new scan module
1\ Register the lim_process_rx_scan_handler with api
   ucfg_scan_register_requester;
2\ Redefine function lim_send_preauth_scan_offload
   to use api ucfg_scan_start;

Change-Id: I43a0b28c3abcce907575717dc3a4bfb190a32ec2
CRs-Fixed: 2144630
2017-12-16 14:07:59 -08:00
snandini
96dc553e24 Release 5.2.0.58D
Release 5.2.0.58D

Change-Id: Ic4b035ed72c1ddf9038075168cfdd975fd49952b
CRs-Fixed: 774533
2017-12-16 13:27:40 -08:00
Paul Zhang
4362697ced qcacld-3.0: Fix non-scan active queue stuck issue
1\ The command content is wrongly reset and cause
   the corresponding command could not find from the
   active queue.
2\ It should release the command in time before issue
   the next command.

Change-Id: I094a6ce0e34f4698222d85a785cb6424852e25f8
CRs-Fixed: 2144630
2017-12-16 13:27:39 -08:00
snandini
f3f5b68da7 Release 5.2.0.58C
Release 5.2.0.58C

Change-Id: Ibe6cdf917107ac334c59f4ab0ca2b5daa4663396
CRs-Fixed: 774533
2017-12-16 03:26:17 -08:00
Naveen Rawat
7cc925c403 qcacld-3.0: Reject scan cmd if ie length greater than max allowed
Firmware cannot handle scan IE more than a certain size owing to memory
restrictions. Check the scan IE length before passing params to firmware.

Change-Id: I73321a9d4932f4cbb876de904dacecf15c9083ff
CRs-Fixed: 2159363
2017-12-16 03:26:16 -08:00
gaurank kathpalia
247554ce79 qcacld-3.0: Free allocated memory in wma_unified_link_radio_stats_event_handler
In the file wma_unified_radio_tx_power_level_stats_event_handler ,
the driver allocates  memory to rs_results->tx_time_per_power_level ,
also in api wma_unified_link_radio_stats_event_handler ,
rs_results->channels , without checking a previous allocated
memory for the same . Also the driver makes the pointers
rs_results->tx_time_per_power_level and rs_results->channels
as null without a prior check , which results in a memory leak.
Fix is to add a check for rs_results->channels and
rs_results->tx_time_per_power_level for NULL , and free
the already allocated memory for the same.

Change-Id: I02af53454270239bf68446a727b735c8ef10d434
CRs-Fixed: 2150714
2017-12-16 03:26:14 -08:00
Dustin Brown
550f6d2350 qcacld-3.0: Add wlan module transition logs
Add a consistent set of logs for wlan module transition changes to aid
in debugging efforts.

Change-Id: Id7f039c03f25ba46194a101b64e08f8ae3042c50
CRs-Fixed: 2159403
2017-12-16 03:26:12 -08:00
snandini
e6cc0bf4e8 Release 5.2.0.58B
Release 5.2.0.58B

Change-Id: I1653b3d2788f11f22ecfbc012f3f054531022762
CRs-Fixed: 774533
2017-12-16 01:26:56 -08:00
snandini
279c4f018b Release 5.2.0.58A
Release 5.2.0.58A

Change-Id: I30102fd00b5004777d3f6c0be67ca8df3a5e72d0
CRs-Fixed: 774533
2017-12-15 19:26:19 -08:00
Kabilan Kannan
efca122f5d qcacld-3.0: Add validity check in HDD object manager deinit
Add validity check in HDD object manager destroy function
to avoid the crash.

Change-Id: I1c3296dc2bf84fc564686aeab46c1a0b217820ce
CRs-Fixed: 2159256
2017-12-15 19:26:19 -08:00
snandini
41198157b8 Release 5.2.0.58
Release 5.2.0.58

Change-Id: I283d454ee2670fdbe0949fe9b1e7a52cefc19fcc
CRs-Fixed: 774533
2017-12-15 17:31:31 -08:00
Yun Park
a4bb37c234 qcacld-3.0: Fix IPA pipe unloading timeout during driver restart
Host driver drops incoming HDD IPA events during unloading prcess,
when IPA pipe unloading timeout occurs, and IPA offload state could
be mismatch between host driver and FW.
Fix by setting unloading complete before IPA pipe disable and putting
events into pending event queue for unloading timeout case as well.

Change-Id: If44caa07f328bf3ac2d2fc02aafb796176114678
CRs-Fixed: 2152490
2017-12-15 17:31:30 -08:00
snandini
964e0d631e Release 5.2.0.57Z
Release 5.2.0.57Z

Change-Id: I12906d3a8103c5352f91795ff04a50c140074861
CRs-Fixed: 774533
2017-12-15 13:26:26 -08:00
lifeng
70a5ee609e qcacld-3.0: Fix buffer overread in lim_process_fils_auth_frame2
qcacld-2.0 to qcacld-3.0 propagation

The return value validation is missing for dot11fUnpackIeRSN, thus
"dot11f_ie_rsn.pmkid_count" could be larger than 4. When it is larger
than 4 there will be a buffer over-read in vos_mem_compare. Add status
check of dot11fUnpackIeRSN in lim_process_fils_auth_frame2.

Change-Id: If563ddb13bbfcad5660d136c35c39846010594e1
CRs-Fixed: 2147955
2017-12-15 13:26:25 -08:00
Dustin Brown
920397d930 qcacld-3.0: Remove hdd_adapter_list_node_t
Linux convention is to embed a list node in a structure that is meant to
be a member of a list. However, hdd_adapter_list_node_t is created to
contain both the list node and the list item itself. Remove
hdd_adapter_list_node_t and embed the list node directly into
hdd_adapter instead.

Change-Id: I62888a0212d88aa212fee34b886e3d8a4875e0c7
CRs-Fixed: 2159309
2017-12-15 13:26:23 -08:00
snandini
f847c8629c Release 5.2.0.57Y
Release 5.2.0.57Y

Change-Id: I7c782e83004119854e8ae9adfdb2e9a8547bc9c0
CRs-Fixed: 774533
2017-12-15 03:42:06 -08:00
Naveen Rawat
bcd3d019d8 qcacld-3.0: Execute sme_stop and mac_stop in mc thread context
sme_stop and mac_stop are accessing share data structures which
create a race condition when it is called from rmmod context.
Change context of sme_stop and mac_stop from rmmod thread to
mc thread.

Change-Id: Ie30f99d6b0c2f7c6cf20371dd66323d156360474
CRs-Fixed: 2148771
2017-12-15 03:42:05 -08:00
snandini
ec5c565002 Release 5.2.0.57X
Release 5.2.0.57X

Change-Id: I3becda7b09ad2d603f6c3ad06769179857be3273
CRs-Fixed: 774533
2017-12-15 01:38:37 -08:00
Abhishek Singh
104a1bfccc qcacld-3.0: Enable roaming scoring logic by default
Set enable_scoring_for_roam to enable roaming scoring logic by default.

Change-Id: Ib48116142f38d3a796f0c02d0345ebc3fdd36700
CRs-Fixed: 2157478
2017-12-15 01:38:36 -08:00
snandini
4db80cade7 Release 5.2.0.57W
Release 5.2.0.57W

Change-Id: I8ca41d452d4954a447082f6354b4d17342c90556
CRs-Fixed: 774533
2017-12-14 23:27:12 -08:00
Sourav Mohapatra
804359ebc4 qcacld-3.0: Enable additional feature caps
Enable WIFI_FEATURE_CONFIG_NDO caps in __wlan_hdd_cfg80211_get_features
to help in VTS test case passing.

Change-Id: Iea56e53add127dc79a959f26e5f512662ed304cb
CRs-Fixed: 2155700
2017-12-14 23:27:11 -08:00
snandini
e975bebe13 Release 5.2.0.57V
Release 5.2.0.57V

Change-Id: If2721019679867347ed99dcf0baff14339386c42
CRs-Fixed: 774533
2017-12-14 09:25:52 -08:00
Vignesh Viswanathan
ac6f2c30ac qcacld-3.0: Fix potential OOB read in dot11f.c
In function get_container_ies_len, nBuf is passed from caller function
as length of the buffer remaining in the frame. len is calculated from
the length field present in the IE. Then find_ie_defn is called with
nBuf + len as buffer length available leading to potential OOB read
in the function find_ie_defn.
Also in function get_container_ies_len, if len is greater than nBuf,
OOB read would occur in the caller function unpack_core.

In function unpack_core, len is calculated from the length field in
the IE buffer, then the IE is parsed in one of the unpack functions
where len is decremented without any check for min value of len.
If the value of len obtained from the IE buffer is less than the
minSize of the IE, then an integer underflow would occur.

1. In function get_container_ies_len, change calling of find_ie_defn
to use nbuf - len.
2. In function get_container_ies_len, if len > nbuf, return error.
3. In function unpack_core, add sanity check to make sure len is not
less thatn IE's minSize.

Change-Id: I8e42fb7e9674845d152d2ec26a592e02a1b562ab
CRs-Fixed: 2153003
2017-12-14 09:25:51 -08:00
snandini
f72ed5e06e Release 5.2.0.57U
Release 5.2.0.57U

Change-Id: Iaeaeb23b17b2f40599b24edf2229c9c88b363400
CRs-Fixed: 774533
2017-12-13 21:38:39 -08:00
Krunal Soni
1565067857 qcacld-3.0: Remove unused structure while sending probe resp template
While sending probe response template down to firmware, driver
populates some items in data-structure which is not getting used.

Remove those unused items and send only what is needed.

CRs-Fixed: 2148056
Change-Id: I1878f523f0f88c354854dfdb75e60e66c4ecb0e8
2017-12-13 21:38:38 -08:00
snandini
ba4b582f9a Release 5.2.0.57T
Release 5.2.0.57T

Change-Id: Id47bc2feab39123b113481c5b65164da939b6d65
CRs-Fixed: 774533
2017-12-13 20:08:21 -08:00
Sandeep Puligilla
c0f7744dc3 qcacld-3.0: Add a SSID length check
Add a SSID length validation check before
copying the SSID field to scan request
structure from connect profile.

Change-Id: Ic6297a28f8852db2e5d22c5c7d5b8eab7b76dbfd
CRs-Fixed: 2145706
2017-12-13 20:08:21 -08:00
Rajeev Kumar
658e849971 qcacld-3.0: Initialize message on stack in SME get peer info request
Initialize message local variable on stack in SME get peer info request
API before posting message via scheduler API.

Change-Id: I4471f3c3eacaacfb8e9145e61dd4eb33b921936f
CRs-Fixed: 2158564
2017-12-13 20:08:17 -08:00
Naveen Rawat
436979baa9 qcacld-3.0: Avoid bit addressing for HE Caps and HE Ops
Avoid bit addressing for HE Caps and HE Ops, and use structures
to access fields within HE Caps and HE Ops.

Change-Id: I1afa1926d1f4c7da5446870a7ad3121c06762f98
CRs-Fixed: 2145511
2017-12-13 20:08:14 -08:00
snandini
90067c812d Release 5.2.0.57S
Release 5.2.0.57S

Change-Id: I6712b03c0e59f6fa539f716db42407111b57a12c
CRs-Fixed: 774533
2017-12-13 19:18:04 -08:00
Rajeev Kumar Sirasanagandla
bb03b2cd0e qcacld-3.0: Fix add interface issue for multiple softaps
Conditional check to avoid add of same softap interface again
during SSR in __wlan_hdd_add_virtual_intf() is causing
regression (Ic3cd1eebb23482e9cebf04683533face178698b4) and
not allowing to add more than one softap interface.

To fix, add check for newly requested softap interface name with
previously registered softap interfaces and add if name is different
else return the existing one.

Change-Id: I103bd577db5c38e53b1ef12278a856a39790f8f7
CRs-Fixed: 2155854
2017-12-13 19:18:03 -08:00
Arunk Khandavalli
6a22788176 qcacld-3.0: Dont set mc addr list if the modules are closed
MC addr list is a ndo operation can be invoked by the kernel even
if the driver modules are closed which can result in accessing from
freed variables.
Reject the set/reset mc addr list when the modules are closed.

Change-Id: Ief83e18e6f8e431c7d68377f803ac602178f8913
CRs-Fixed: 2153099
2017-12-13 19:18:01 -08:00
Kabilan Kannan
1622a4799d qcacld-3.0: validate the return status in TDLS peer delete
TDLS peer delete function is not validating the return
status from PE, and it causes unpredictable errors.
Verify the return status and take the corresponding
action for the error cases.

Change-Id: I55c77842560917ca766fbfcbf26762d745a1d5e5
CRs-Fixed: 2144268
2017-12-13 19:17:58 -08:00
snandini
115e5b35f4 Release 5.2.0.57R
Release 5.2.0.57R

Change-Id: I9ed5d5ba23fd1eb97884c0bec8077570060e23ed
CRs-Fixed: 774533
2017-12-13 15:38:24 -08:00
Dustin Brown
677e0866c3 qcacld-3.0: Enable MC Timer runtime leak detection
In addition to any other resource leak checks being done at runtime,
check for any leaked MC Timers as well.

Change-Id: Ic576eed3cf9b19824db6864a6b7b0466a6f03ea9
CRs-Fixed: 2125799
2017-12-13 15:38:23 -08:00
snandini
1c24403ef0 Release 5.2.0.57Q
Release 5.2.0.57Q

Change-Id: Ib231f53612bf3dcb3b7383903582891efb4c4eb2
CRs-Fixed: 774533
2017-12-13 07:26:26 -08:00
Vignesh Viswanathan
8d2d6e0e26 qcacld-3.0: Add debugs to dump Vendor IEs in the AP's beacon/probe response
Add debugs to dump all the Vendor IEs of tag type 221 to identify
the IEs sent in the AP's beacons/probe response without need to sniffer.

Change-Id: I1896adc12b49a54e4cf39794e802c04f7ad22080
CRs-Fixed: 2156913
2017-12-13 07:26:25 -08:00
snandini
e3a0acd156 Release 5.2.0.57P
Release 5.2.0.57P

Change-Id: I6c957c489d930d17127b4110f76efd6676418f99
CRs-Fixed: 774533
2017-12-13 05:40:16 -08:00
Arunk Khandavalli
a4563d206d qcacld-3.0: Increase the hdd scan timeout to double of csr scan timeout
During frequent suspend/resume there is a possibility of csr scan timer
and hdd scan timer are racing eaching other. Increase the hdd scan timer
value to double of the csr scan timer value to reduce the race allowing
hdd to abort the scan incase of timeout.

Change-Id: I03995498df692dc92dc87e8ef1fc8fd316965df0
CRs-Fixed: 2151994
2017-12-13 05:40:16 -08:00
snandini
e7f0250036 Release 5.2.0.57O
Release 5.2.0.57O

Change-Id: I2fd742d4428af9f3a1e36d225c197b2d45157812
CRs-Fixed: 774533
2017-12-12 21:27:29 -08:00
Vignesh Viswanathan
96e0e702ec qcacld-3.0: Fix potential buffer overflow in wlan_hdd_cfg80211_set_ie
In function wlan_hdd_cfg80211_set_ie, RSN IE is parsed and copied
into the buffer  for length eLen + 2.
However, the buffer WPARSNIE is allocated only for
size. If eLen + 2 is greater than MAX_WPA_RSN_IE_LEN, a buffer overflow
would occur.

Add sanity check to make sure eLen does not exceed MAX_WPA_RSN_IE_LEN - 2.
Also increase the size of  to 255 as per the spec

Change-Id: Ibf44e8dc1010e6e32b2262357d3aa180926d5c99
CRs-Fixed: 2154216
2017-12-12 21:27:28 -08:00
snandini
3b0c91e96e Release 5.2.0.57N
Release 5.2.0.57N

Change-Id: Idd09b2c5123efe7e4b764bd415ccd863a7e472af
CRs-Fixed: 774533
2017-12-12 17:57:21 -08:00
Mohit Khanna
c4c222535f qcacld-3.0: Replace cdp peer_find_by_addr by get_ref_by_addr
Change the existing cdp_peer_find_by_addr by calls to
cdp_peer_get_ref_by_addr and cdp_peer_release_ref. The new APIs
make sure that the peer is valid as long as the peer reference is not
released (call to cdp_peer_release_ref)

Change-Id: Ibde9944a9721e5dcf0f7838058c229539efae7e4
CRs-Fixed: 2139801
2017-12-12 17:57:21 -08:00
Mohit Khanna
b7bec723c3 qcacld-3.0: Add peer APIs to get and release peer ref
The existing peer API cdp_peer_find_by_add does not maintain any peer
references. So a peer which is returned by the API may get deleted in a
different context. This may lead to access to a already deleted memory.

Fix the issue by introducing new APIs "peer_get_ref" and
"peer_release_ref" which make sure the peer is valid until it is
"released" (peer_release_ref is called).

Change-Id: I60175ee1d67f01e3ee4b48cb655d1728d29d08f4
CRs-Fixed: 2139801
2017-12-12 17:57:16 -08:00
Sandeep Puligilla
63633f697f qcacld-3.0: Fix memory leak in measurement request processing
Memory leak is detected while processing the
measurement report request while another request
is under processing.

Pass an address of the pointer to the rrm beacon
request API to get the allocated memory address.

Change-Id: I83c44a6a7a4a8e1ce56e48b008e7d784cca1dc6d
CRs-Fixed: 2144031
2017-12-12 17:57:13 -08:00
snandini
89e1acbc5a Release 5.2.0.57M
Release 5.2.0.57M

Change-Id: I57c9a610c5fe4daed09903ff8c6be119c48ac2d8
CRs-Fixed: 774533
2017-12-12 15:56:41 -08:00
Arunk Khandavalli
ebd1e37e15 qcacld-3.0: Reject system suspend in monitor mode
In the monitor mode when the system is suspended
FW trying to send packet to host which is not allowed leading to this
system crash.

Acquire wakelock once the device enters monitor mode and block
the system from entering suspend.

Change-Id: I27ba2d43fd7b84bc1ae7e6046ab635065872b2d2
CRs-Fixed: 2130546
2017-12-12 15:56:41 -08:00
snandini
d43cb9804f Release 5.2.0.57L
Release 5.2.0.57L

Change-Id: I4fa06e09ee6a6ca4a914f88d5bbefccc6bd2a521
CRs-Fixed: 774533
2017-12-12 11:26:14 -08:00
Abhishek Singh
67e02bdb0b qcacld-3.0: Avoid adding duplicate qcn ie in directed probe req
If mac_ctx->roam.configParam.qcn_ie_support is enabled driver adds
qcn ie in directed probe req, even if its already present in the
additional scan IEs. Thus in probe request two qcn ie are present.

To fix this add qcn ie only if roam.configParam.qcn_ie_support is set
and qcn ie is not present in the additional scan IE.

Change-Id: I4c7ea32dc06e5c62b4043dbd3794348f8185fd9b
CRs-Fixed: 2152795
2017-12-12 03:06:29 -08:00
snandini
dc626447fa Release 5.2.0.57K
Release 5.2.0.57K

Change-Id: Idcee03310fe1deecd3d05c85d1095c58ea469c93
CRs-Fixed: 774533
2017-12-12 01:26:05 -08:00
Naveen Rawat
df221b7f73 qcacld-3.0: Avoid WMI_HE_OPS macros in lim
Avoid using WMI HE Ops macro in lim and use dot11f struct for
HE Ops instead. Keep the tranlation to FW interpratation of
HE Ops in wma layer only.

Change-Id: Ie94795541aaddb7ae291ff451b938ebb96f74dbf
CRs-Fixed: 2145510
2017-12-12 01:26:05 -08:00
gaurank kathpalia
bcbde36363 qcacld-3.0: Add check for iface in wma_setup_install_key_cmd
The host defines the iface ptr with :-
iface = &wma_handle->interfaces[key_params->vdev_id], at line 1588
and if the WLAN_FEATURE_11W, is not enabled , the host sets the
iface->is_waiting_for_key as false , without a NULL check of iface.
Fix is to add a NULL check for iface

Change-Id: I69ed8f881b678458d16f1f74e87e31959c04ec63
CRs-Fixed: 2156921
2017-12-12 01:26:01 -08:00
snandini
208f1dee58 Release 5.2.0.57J
Release 5.2.0.57J

Change-Id: I5c0e75986e328ab8f2cf5ffef80173bb583b6e7d
CRs-Fixed: 774533
2017-12-11 22:08:19 -08:00
Paul Zhang
99fe884782 qcacld-3.0: Implement interface to set WLM level
WLAN Latency module (WLM) is added by fw to gain latency
because of schedule out of service like power saving,
scanning, roaming etc. per the level set by framework.

Change-Id: Id4305e5e66dcce464447aff56296c7d027347ea2
CRs-Fixed: 2142391
2017-12-11 22:08:19 -08:00
snandini
33e8661c51 Release 5.2.0.57I
Release 5.2.0.57I

Change-Id: I163558662169c4fa5ec438185756ca8b2d08664f
CRs-Fixed: 774533
2017-12-11 21:26:02 -08:00
hqu
8925c8f767 qcacld-3.0: Move log level to info high if tx hits invalid peer state
For sns test in some scenarios when tx hits invalid peer state it will
print massive log so that it will lead to WD bark issue.

Move log level to lower info high from warn if tx hits invalid peer state.

Change-Id: I91d414e7203bf1e00094ca7b2fcebf80f4102082
CRs-Fixed: 2156472
2017-12-11 21:26:01 -08:00
Ashish Kumar Dhanotiya
7b1fe06cc7 qcacld-3.0: Add missing reg pairs in driver
Regpair for DM, DO, HN, JM, NA, PA, SN, XA are missing
which results in a crash.

Add regpair for country codes  DM, DO, HN, JM, NA, PA, SN, XA.

Change-Id: I6d29f16a549121b9588d6fb68b78e14375e8eb8e
CRs-Fixed: 2154385
2017-12-11 21:25:58 -08:00
wadesong
1ef396242d qcacld-3.0: Fix ACS scan abnormal cancellation problem
When a BSS is being started, the WLAN driver will abort all
scan requests, including the ACS scan initiated by the
secondary SAP, which will result in secondary SAP start
failure.

Use a different function to abort scans initiated by the
current session which is doing BSS starting so ACS scan
initiated by a second SAP will not be affected.

Change-Id: I442431e92e31cc8d3eb302ccca4249d0b4bedf82
CRs-Fixed: 2154230
2017-12-11 21:25:56 -08:00
snandini
15432b3e2a Release 5.2.0.57H
Release 5.2.0.57H

Change-Id: I72c0c16942ff1b34ea99105643003550e88a3a51
CRs-Fixed: 774533
2017-12-11 19:38:18 -08:00
Jingxiang Ge
df9292a6b4 qcacld-3.0: Packing cdp_vdev_detach
Packing cleanup operation following cdp_vdev_detach.

Change-Id: I39ed8cf018df756e4a66fae833debfea25003cf0
CRs-Fixed: 2154859
2017-12-11 19:38:17 -08:00
Rajeev Kumar
a57db6b0c2 qcacld-3.0: Optimize stack memory allocation in CSR msg processor
csr_roaming_state_msg_processor() is declaring roam_info on stack
which is of size 736 bytes. Kernel stack has limited size and all
big data structures should be allocated from heap to avoid stack
overflow. Hence allocate roam_info struct from heap and free it
after callback has returned.

Change-Id: I282d9baa9f3e679bfd5b628f0baaadf4beec86af
CRs-Fixed: 2143439
2017-12-11 19:38:15 -08:00
Dustin Brown
021cecdb56 qcacld-3.0: Move memdump init/deinit to avoid runtime leak
The memdump feature allocates memory after the module has started,
leading to a false positive memory leak when the module is subsequently
stopped. Move memdump init to before the module is started in
hdd_wlan_startup, and memdump deinit to after the module is stopped in
hdd_wlan_exit.

Change-Id: I8df48e55e0f1e90fb4599469ce10f7741fb7a9a0
CRs-Fixed: 2157112
2017-12-11 19:38:13 -08:00
snandini
30cfcb12c7 Release 5.2.0.57G
Release 5.2.0.57G

Change-Id: Idea4e12c55d2252620c259e3b39c7f1607bd38b0
CRs-Fixed: 774533
2017-12-11 17:38:08 -08:00
Dustin Brown
4bc0a62828 qcacld-3.0: Detect leaks on transition to driver-closed
Currently, resource leak detection happens when the driver module is
unloaded. Instead move as much leak detection as possible to when the
driver transitions back into the closed state. This better supports
load-once-never-unload and built-in driver configurations.

Change-Id: I88be641948ffa4fff397a8eae40cf3b05c543673
CRs-Fixed: 2113606
2017-12-11 17:38:07 -08:00
snandini
416d3b4c1a Release 5.2.0.57F
Release 5.2.0.57F

Change-Id: Ic86e48f176e1286afefb1edebc1b3f1c406b48b1
CRs-Fixed: 774533
2017-12-11 15:46:34 -08:00
Varun Reddy Yeturu
371404beda qcacld-3.0: Handle set key response failure
If roaming is happening and then a set key response is
generated from WMA to PE, then there is a possibility
of not finding the PE session as the roaming happened
and new session is established. In such cases, return
failure from PE to SME so that the set key command is
released and the command queue is not stuck

Change-Id: Ieba8ea76a2a53322f2e392e6b0bf30360b1e8f8a
CRs-Fixed: 2150731
2017-12-11 15:46:33 -08:00
Nachiket Kukade
08b9f2903b qcacld-3.0: Use new event infrastructure for session open/close events
With current implementation, if sme_open_session sends down a command
to the Firmware and an SSR/PDR occurs, the thread is stuck on waiting
on an event. The thread also holds the rtnl lock and will keep
blocking any other thread from acquiring it till timeout occurs. This
can result in deadlock situation with IPA driver trying to execute
driver ops during the SSR/PDR notification callback.

Use the wait_for_event_completion API for waiting on event. With this
the event will be purged when driver receives FW_DOWN indication.

Change-Id: I2920fd36c0eb5bb5994e66e584d12a2a9d8f409a
CRs-Fixed: 2120226
2017-12-11 15:46:30 -08:00
snandini
5536a99c2d Release 5.2.0.57E
Release 5.2.0.57E

Change-Id: Ib06c69d58a70f1d86319f126695bdf408904f5b0
CRs-Fixed: 774533
2017-12-11 13:56:39 -08:00
snandini
d0f7ac32a0 Release 5.2.0.57D
Release 5.2.0.57D

Change-Id: Ifafbf46eea7d0704408341b7c349a54e1ee07553
CRs-Fixed: 774533
2017-12-11 03:38:08 -08:00
Padma, Santhosh Kumar
ecbcafcb96 qcacld-3.0: Reduce the max join attempts for connection
Limit the max join attempts to two less than 1/3 of the total
command timeout value.

Change-Id: Ic52ec1cfa268a9e24e944f5d6e875e42d5a7b2be
CRs-Fixed: 2137346
2017-12-11 03:38:08 -08:00
snandini
66a74d85a5 Release 5.2.0.57C
Release 5.2.0.57C

Change-Id: I52593cc508b69ab22b5185a9cabcad0dc69d88dd
CRs-Fixed: 774533
2017-12-10 23:38:27 -08:00
Tiger Yu
6211cd7436 qcacld-3.0: Fix potential BUG_ON in the htt_rx_offload_msdu_pop_ll
qcacld-2.0 to qcacld-3.0 propagation

For HTT_T2H_MSG_TYPE_RX_OFFLOAD_DELIVER_IND, the msdu_cnt is a signed
integer coming from firmware. If set the msdu_cnt to a negative value,
or be greater than the number of current elements in the queue, the loop
will execute lots of times in ol_rx_offload_deliver_ind_handler, the
htt_rx_netbuf_pop will cause the BUG_ON issue sooner or later if it is
low latency solution.

Change the msdu_cnt type from signed to unsigned and add the validity
msdu_cnt checking will fix this issue.

Change-Id: I436557a124074f59ab11fd937dfdc975b9caebe8
CRs-Fixed: 2149461
2017-12-10 23:38:26 -08:00
snandini
ab09ed083c Release 5.2.0.57B
Release 5.2.0.57B

Change-Id: Ic09b58f837275c90ec37ce353837608d0c9f5fc2
CRs-Fixed: 774533
2017-12-10 22:16:22 -08:00
Tiger Yu
25c131e8a8 qcacld-3.0: Fix potential buffer overflow in htt_t2h_lp_msg_handler
qcacld-2.0 to qcacld-3.0 propagation

Check for the validity of peer_id when received the htt message of
HTT_T2H_MSG_TYPE_PEER_MAP or HTT_T2H_MSG_TYPE_PEER_UNMAP from firmware
to ensure the buffer overflow does not happen.

Change-Id: Ib3f92f4de0b406a78bf34d348c07cb3981277513
CRs-Fixed: 2147119
2017-12-10 22:16:21 -08:00
Tiger Yu
62ef4fb08d qcacld-3.0: Fix potential buffer overflow in ol_rx_flush_handler
qcacld-2.0 to qcacld-3.0 propagation

Check for the validity of tid when received the htt message of
HTT_T2H_MSG_TYPE_RX_FLUSH & HTT_T2H_MSG_TYPE_RX_PN_IND from firmware
to ensure the buffer overflow does not happen.

And correct the sequence number type from signed int to unsigned.

Change-Id: Ibff86e891c335bfe8c2f9db82410545036463ed3
CRs-Fixed: 2149399
2017-12-10 22:16:17 -08:00
Tiger Yu
a007b9a256 qcacld-3.0: Fix potential buffer overflow for TX_COMPL_IND
qcacld-2.0 to qcacld-3.0 propagation

Check for the validity of num_msdus when received the htt message of
HTT_T2H_MSG_TYPE_TX_COMPL_IND or HTT_T2H_MSG_TYPE_TX_INSPECT_IND from
firmware to ensure the buffer overflow does not happen.

Change-Id: Ic6ce75f34c5e2705d174eda014350e6ef0391388
CRs-Fixed: 2146869
2017-12-10 22:16:13 -08:00
snandini
99ec257084 Release 5.2.0.57A
Release 5.2.0.57A

Change-Id: If5f9c1055c259b100111da509351e055801b6836
CRs-Fixed: 774533
2017-12-10 21:26:56 -08:00
Tiger Yu
c35fbb1e72 qcacld-3.0: Fix potential integer overflow when TX_CREDIT_UPDATE
qcacld-2.0 to qcacld-3.0 propagation

Check for the validity of credits when received the htt message of
HTT_T2H_MSG_TYPE_TX_CREDIT_UPDATE_IND or HTT_T2H_MSG_TYPE_TX_COMPL_IND
from firmware to ensure the integer overflow does not happen if these
messages invoked many times.

Change-Id: I01386b88f1b677153f3e51e055b7fbac073cd6b3
CRs-Fixed: 2147127
2017-12-10 21:26:54 -08:00
snandini
8159423fff Release 5.2.0.57
Release 5.2.0.57

Change-Id: Ida6ab2930cbd104aca1fd57b17d0017eb26a35eb
CRs-Fixed: 774533
2017-12-09 23:27:10 -08:00
Venkata Sharath Chandra Manchala
1240fc7c98 qcacld-3.0: Enable Packetlog for Napier
Add ATH_PKTLOG_LITE_T2H and ATH_PKTLOG_LITE_RX
support for Napier.

Change-Id: I6e2833e2f7e1a4c68c51f7ae83d0ae76f63c9b0f
CRs-Fixed: 2133558
2017-12-09 23:27:07 -08:00