16e939c6e4
* refs/heads/tmp-b9d179c: UPSTREAM: driver core: Fix possible memory leak in device_link_add() UPSTREAM: blk-mq: fix kernel panic during iterating over flush request UPSTREAM: net: xfrm: fix memory leak in xfrm_user_rcv_msg UPSTREAM: binder: fix the missing BR_FROZEN_REPLY in binder_return_strings ANDROID: incremental-fs: fix mount_fs issue UPSTREAM: vfs: fs_context: fix up param length parsing in legacy_parse_param ANDROID: GKI: disable CONFIG_FORTIFY_SOURCE Linux 5.4.161 erofs: fix unsafe pagevec reuse of hooked pclusters erofs: remove the occupied parameter from z_erofs_pagevec_enqueue() PCI: Add MSI masking quirk for Nvidia ION AHCI PCI/MSI: Deal with devices lying about their MSI mask capability PCI/MSI: Destroy sysfs before freeing entries parisc/entry: fix trace test in syscall exit path fortify: Explicitly disable Clang support scsi: ufs: Fix tm request when non-fatal error happens ext4: fix lazy initialization next schedule time computation in more granular unit MIPS: Fix assembly error from MIPSr2 code used within MIPS_ISA_ARCH_LEVEL scsi: ufs: Fix interrupt error message for shared interrupts soc/tegra: pmc: Fix imbalanced clock disabling in error code path Revert "net: sched: update default qdisc visibility after Tx queue cnt changes" Revert "serial: core: Fix initializing and restoring termios speed" Linux 5.4.160 selftests/bpf: Fix also no-alu32 strobemeta selftest ath10k: fix invalid dma_addr_t token assignment SUNRPC: Partial revert of commit 6f9f17287e78 PCI: Add PCI_EXP_DEVCTL_PAYLOAD_* macros powerpc/powernv/prd: Unregister OPAL_MSG_PRD2 notifier during module unload s390/cio: make ccw_device_dma_* more robust s390/tape: fix timer initialization in tape_std_assign() s390/cio: check the subchannel validity for dev_busid video: backlight: Drop maximum brightness override for brightness zero mm, oom: do not trigger out_of_memory from the #PF mm, oom: pagefault_out_of_memory: don't force global OOM for dying tasks powerpc/bpf: Emit stf barrier instruction sequences for BPF_NOSPEC powerpc/security: Add a helper to query stf_barrier type powerpc/bpf: Fix BPF_SUB when imm == 0x80000000 powerpc/bpf: Validate branch ranges powerpc/lib: Add helper to check if offset is within conditional branch range ovl: fix deadlock in splice write 9p/net: fix missing error check in p9_check_errors net, neigh: Enable state migration between NUD_PERMANENT and NTF_USE f2fs: should use GFP_NOFS for directory inodes irqchip/sifive-plic: Fixup EOI failed when masked parisc: Fix set_fixmap() on PA1.x CPUs parisc: Fix backtrace to always include init funtion names ARM: 9156/1: drop cc-option fallbacks for architecture selection ARM: 9155/1: fix early early_iounmap() selftests/net: udpgso_bench_rx: fix port argument cxgb4: fix eeprom len when diagnostics not implemented net/smc: fix sk_refcnt underflow on linkdown and fallback vsock: prevent unnecessary refcnt inc for nonblocking connect net: hns3: allow configure ETS bandwidth of all TCs net/sched: sch_taprio: fix undefined behavior in ktime_mono_to_any bpf: sockmap, strparser, and tls are reusing qdisc_skb_cb and colliding arm64: pgtable: make __pte_to_phys/__phys_to_pte_val inline functions nfc: pn533: Fix double free when pn533_fill_fragment_skbs() fails llc: fix out-of-bound array index in llc_sk_dev_hash() perf bpf: Add missing free to bpf_event__print_bpf_prog_info() zram: off by one in read_block_state() mm/zsmalloc.c: close race window between zs_pool_dec_isolated() and zs_unregister_migration() bonding: Fix a use-after-free problem when bond_sysfs_slave_add() failed ACPI: PMIC: Fix intel_pmic_regs_handler() read accesses net: vlan: fix a UAF in vlan_dev_real_dev() net: davinci_emac: Fix interrupt pacing disable xen-pciback: Fix return in pm_ctrl_init() i2c: xlr: Fix a resource leak in the error handling path of 'xlr_i2c_probe()' NFSv4: Fix a regression in nfs_set_open_stateid_locked() scsi: qla2xxx: Turn off target reset during issue_lip scsi: qla2xxx: Fix gnl list corruption ar7: fix kernel builds for compiler test watchdog: f71808e_wdt: fix inaccurate report in WDIOC_GETTIMEOUT m68k: set a default value for MEMORY_RESERVE signal/sh: Use force_sig(SIGKILL) instead of do_group_exit(SIGKILL) dmaengine: dmaengine_desc_callback_valid(): Check for `callback_result` netfilter: nfnetlink_queue: fix OOB when mac header was cleared soc: fsl: dpaa2-console: free buffer before returning from dpaa2_console_read auxdisplay: ht16k33: Fix frame buffer device blanking auxdisplay: ht16k33: Connect backlight to fbdev auxdisplay: img-ascii-lcd: Fix lock-up when displaying empty string dmaengine: at_xdmac: fix AT_XDMAC_CC_PERID() macro mtd: core: don't remove debugfs directory if device is in use mtd: spi-nor: hisi-sfc: Remove excessive clk_disable_unprepare() fs: orangefs: fix error return code of orangefs_revalidate_lookup() NFS: Fix deadlocks in nfs_scan_commit_list() opp: Fix return in _opp_add_static_v2() PCI: aardvark: Fix preserving PCI_EXP_RTCTL_CRSSVE flag on emulated bridge PCI: aardvark: Don't spam about PIO Response Status drm/plane-helper: fix uninitialized variable reference pnfs/flexfiles: Fix misplaced barrier in nfs4_ff_layout_prepare_ds rpmsg: Fix rpmsg_create_ept return when RPMSG config is not defined apparmor: fix error check power: supply: bq27xxx: Fix kernel crash on IRQ handler register error mips: cm: Convert to bitfield API to fix out-of-bounds access powerpc/44x/fsp2: add missing of_node_put HID: u2fzero: properly handle timeouts in usb_submit_urb HID: u2fzero: clarify error check and length calculations serial: xilinx_uartps: Fix race condition causing stuck TX phy: qcom-qusb2: Fix a memory leak on probe ASoC: cs42l42: Defer probe if request_threaded_irq() returns EPROBE_DEFER ASoC: cs42l42: Correct some register default values ARM: dts: stm32: fix SAI sub nodes register range staging: ks7010: select CRYPTO_HASH/CRYPTO_MICHAEL_MIC RDMA/mlx4: Return missed an error if device doesn't support steering scsi: csiostor: Uninitialized data in csio_ln_vnp_read_cbfn() power: supply: rt5033_battery: Change voltage values to µV usb: gadget: hid: fix error code in do_config() serial: 8250_dw: Drop wrong use of ACPI_PTR() video: fbdev: chipsfb: use memset_io() instead of memset() clk: at91: check pmc node status before registering syscore ops memory: fsl_ifc: fix leak of irq and nand_irq in fsl_ifc_ctrl_probe soc/tegra: Fix an error handling path in tegra_powergate_power_up() arm: dts: omap3-gta04a4: accelerometer irq fix ALSA: hda: Reduce udelay() at SKL+ position reporting JFS: fix memleak in jfs_mount MIPS: loongson64: make CPU_LOONGSON64 depends on MIPS_FP_SUPPORT scsi: dc395: Fix error case unwinding ARM: dts: at91: tse850: the emac<->phy interface is rmii arm64: dts: meson-g12a: Fix the pwm regulator supply properties RDMA/bnxt_re: Fix query SRQ failure ARM: dts: qcom: msm8974: Add xo_board reference clock to DSI0 PHY arm64: dts: rockchip: Fix GPU register width for RK3328 ARM: s3c: irq-s3c24xx: Fix return value check for s3c24xx_init_intc() clk: mvebu: ap-cpu-clk: Fix a memory leak in error handling paths RDMA/rxe: Fix wrong port_cap_flags ibmvnic: Process crqs after enabling interrupts ibmvnic: don't stop queue in xmit udp6: allow SO_MARK ctrl msg to affect routing selftests/bpf: Fix fclose/pclose mismatch in test_progs crypto: pcrypt - Delay write to padata->info net: phylink: avoid mvneta warning when setting pause parameters net: amd-xgbe: Toggle PLL settings during rate change drm/amdgpu/gmc6: fix DMA mask from 44 to 40 bits wcn36xx: add proper DMA memory barriers in rx path libertas: Fix possible memory leak in probe and disconnect libertas_tf: Fix possible memory leak in probe and disconnect KVM: s390: Fix handle_sske page fault handling samples/kretprobes: Fix return value if register_kretprobe() failed tcp: don't free a FIN sk_buff in tcp_remove_empty_skb() irq: mips: avoid nested irq_enter() s390/gmap: don't unconditionally call pte_unmap_unlock() in __gmap_zap() libbpf: Fix BTF data layout checks and allow empty BTF smackfs: use netlbl_cfg_cipsov4_del() for deleting cipso_v4_doi drm/msm: Fix potential NULL dereference in DPU SSPP clocksource/drivers/timer-ti-dm: Select TIMER_OF PM: hibernate: fix sparse warnings nvme-rdma: fix error code in nvme_rdma_setup_ctrl phy: micrel: ksz8041nl: do not use power down mode mwifiex: Send DELBA requests according to spec rsi: stop thread firstly in rsi_91x_init() error handling mt76: mt76x02: fix endianness warnings in mt76x02_mac.c platform/x86: thinkpad_acpi: Fix bitwise vs. logical warning block: ataflop: fix breakage introduced at blk-mq refactoring mmc: mxs-mmc: disable regulator on error and in the remove function net: stream: don't purge sk_error_queue in sk_stream_kill_queues() drm/msm: uninitialized variable in msm_gem_import() ath10k: fix max antenna gain unit hwmon: (pmbus/lm25066) Let compiler determine outer dimension of lm25066_coeff hwmon: Fix possible memleak in __hwmon_device_register() net, neigh: Fix NTF_EXT_LEARNED in combination with NTF_USE memstick: jmb38x_ms: use appropriate free function in jmb38x_ms_alloc_host() memstick: avoid out-of-range warning mmc: sdhci-omap: Fix NULL pointer exception if regulator is not configured b43: fix a lower bounds test b43legacy: fix a lower bounds test hwrng: mtk - Force runtime pm ops for sleep ops crypto: qat - disregard spurious PFVF interrupts crypto: qat - detect PFVF collision after ACK media: dvb-frontends: mn88443x: Handle errors of clk_prepare_enable() netfilter: nft_dynset: relax superfluous check on set updates EDAC/amd64: Handle three rank interleaving mode ath9k: Fix potential interrupt storm on queue reset media: em28xx: Don't use ops->suspend if it is NULL cpuidle: Fix kobject memory leaks in error paths crypto: ecc - fix CRYPTO_DEFAULT_RNG dependency kprobes: Do not use local variable when creating debugfs file media: cx23885: Fix snd_card_free call on null card pointer media: tm6000: Avoid card name truncation media: si470x: Avoid card name truncation media: radio-wl1273: Avoid card name truncation media: mtk-vpu: Fix a resource leak in the error handling path of 'mtk_vpu_probe()' media: TDA1997x: handle short reads of hdmi info frame. media: dvb-usb: fix ununit-value in az6027_rc_query media: cxd2880-spi: Fix a null pointer dereference on error handling path media: em28xx: add missing em28xx_close_extension drm/amdgpu: fix warning for overflow check ath10k: Fix missing frame timestamp for beacon/probe-resp net: dsa: rtl8366rb: Fix off-by-one bug rxrpc: Fix _usecs_to_jiffies() by using usecs_to_jiffies() crypto: caam - disable pkc for non-E SoCs Bluetooth: btmtkuart: fix a memleak in mtk_hci_wmt_sync wilc1000: fix possible memory leak in cfg_scan_result() cgroup: Make rebind_subsystems() disable v2 controllers all at once net: net_namespace: Fix undefined member in key_remove_domain() virtio-gpu: fix possible memory allocation failure drm/v3d: fix wait for TMU write combiner flush rcu: Fix existing exp request check in sync_sched_exp_online_cleanup() Bluetooth: fix init and cleanup of sco_conn.timeout_work selftests/bpf: Fix strobemeta selftest regression netfilter: conntrack: set on IPS_ASSURED if flows enters internal stream state parisc/kgdb: add kgdb_roundup() to make kgdb work with idle polling parisc/unwind: fix unwinder when CONFIG_64BIT is enabled task_stack: Fix end_of_stack() for architectures with upwards-growing stack parisc: fix warning in flush_tlb_all x86/hyperv: Protect set_hv_tscchange_cb() against getting preempted spi: bcm-qspi: Fix missing clk_disable_unprepare() on error in bcm_qspi_probe() btrfs: do not take the uuid_mutex in btrfs_rm_device net: annotate data-race in neigh_output() vrf: run conntrack only in context of lower/physdev for locally generated packets ARM: 9136/1: ARMv7-M uses BE-8, not BE-32 gre/sit: Don't generate link-local addr if addr_gen_mode is IN6_ADDR_GEN_MODE_NONE ARM: clang: Do not rely on lr register for stacktrace smackfs: use __GFP_NOFAIL for smk_cipso_doi() iwlwifi: mvm: disable RX-diversity in powersave selftests: kvm: fix mismatched fclose() after popen() PM: hibernate: Get block device exclusively in swsusp_check() nvme: drop scan_lock and always kick requeue list when removing namespaces nvmet-tcp: fix use-after-free when a port is removed nvmet: fix use-after-free when a port is removed block: remove inaccurate requeue check mwl8k: Fix use-after-free in mwl8k_fw_state_machine() tracing/cfi: Fix cmp_entries_* functions signature mismatch workqueue: make sysfs of unbound kworker cpumask more clever lib/xz: Validate the value before assigning it to an enum variable lib/xz: Avoid overlapping memcpy() with invalid input with in-place decompression memstick: r592: Fix a UAF bug when removing the driver leaking_addresses: Always print a trailing newline ACPI: battery: Accept charges over the design capacity as full iov_iter: Fix iov_iter_get_pages{,_alloc} page fault return value ath: dfs_pattern_detector: Fix possible null-pointer dereference in channel_detector_create() tracefs: Have tracefs directories not set OTH permission bits by default net-sysfs: try not to restart the syscall if it will fail eventually media: usb: dvd-usb: fix uninit-value bug in dibusb_read_eeprom_byte() media: ipu3-imgu: VIDIOC_QUERYCAP: Fix bus_info media: ipu3-imgu: imgu_fmt: Handle properly try ACPICA: Avoid evaluating methods too early during system resume ipmi: Disable some operations during a panic media: rcar-csi2: Add checking to rcsi2_start_receiver() brcmfmac: Add DMI nvram filename quirk for Cyberbook T116 tablet ia64: don't do IA64_CMPXCHG_DEBUG without CONFIG_PRINTK media: mceusb: return without resubmitting URB in case of -EPROTO error. media: imx: set a media_device bus_info string media: s5p-mfc: Add checking to s5p_mfc_probe(). media: s5p-mfc: fix possible null-pointer dereference in s5p_mfc_probe() media: uvcvideo: Set unique vdev name based in type media: uvcvideo: Return -EIO for control errors media: uvcvideo: Set capability in s_param media: stm32: Potential NULL pointer dereference in dcmi_irq_thread() media: netup_unidvb: handle interrupt properly according to the firmware media: mt9p031: Fix corrupted frame after restarting stream ath10k: high latency fixes for beacon buffer mwifiex: Properly initialize private structure on interface type changes mwifiex: Run SET_BSS_MODE when changing from P2P to STATION vif-type x86: Increase exception stack sizes smackfs: Fix use-after-free in netlbl_catmap_walk() net: sched: update default qdisc visibility after Tx queue cnt changes locking/lockdep: Avoid RCU-induced noinstr fail MIPS: lantiq: dma: reset correct number of channel MIPS: lantiq: dma: add small delay after reset platform/x86: wmi: do not fail if disabling fails drm/panel-orientation-quirks: add Valve Steam Deck Bluetooth: fix use-after-free error in lock_sock_nested() Bluetooth: sco: Fix lock_sock() blockage by memcpy_from_msg() drm: panel-orientation-quirks: Add quirk for the Samsung Galaxy Book 10.6 drm: panel-orientation-quirks: Add quirk for KD Kurio Smart C15200 2-in-1 drm: panel-orientation-quirks: Update the Lenovo Ideapad D330 quirk (v2) dma-buf: WARN on dmabuf release with pending attachments USB: chipidea: fix interrupt deadlock USB: iowarrior: fix control-message timeouts USB: serial: keyspan: fix memleak on probe errors iio: dac: ad5446: Fix ad5622_write() return value pinctrl: core: fix possible memory leak in pinctrl_enable() quota: correct error number in free_dqentry() quota: check block number when reading the block in quota file PCI: aardvark: Read all 16-bits from PCIE_MSI_PAYLOAD_REG PCI: aardvark: Fix return value of MSI domain .alloc() method PCI: aardvark: Fix reporting Data Link Layer Link Active PCI: aardvark: Do not unmask unused interrupts PCI: aardvark: Fix checking for link up via LTSSM state PCI: aardvark: Do not clear status bits of masked interrupts PCI: pci-bridge-emul: Fix emulation of W1C bits xen/balloon: add late_initcall_sync() for initial ballooning done ALSA: mixer: fix deadlock in snd_mixer_oss_set_volume ALSA: mixer: oss: Fix racy access to slots serial: core: Fix initializing and restoring termios speed powerpc/85xx: Fix oops when mpc85xx_smp_guts_ids node cannot be found can: j1939: j1939_can_recv(): ignore messages with invalid source address can: j1939: j1939_tp_cmd_recv(): ignore abort message in the BAM transport KVM: nVMX: Query current VMCS when determining if MSR bitmaps are in use power: supply: max17042_battery: use VFSOC for capacity when no rsns power: supply: max17042_battery: Prevent int underflow in set_soc_threshold signal/mips: Update (_save|_restore)_fp_context to fail with -EFAULT signal: Remove the bogus sigkill_pending in ptrace_stop RDMA/qedr: Fix NULL deref for query_qp on the GSI QP rsi: Fix module dev_oper_mode parameter description rsi: fix rate mask set leading to P2P failure rsi: fix key enabled check causing unwanted encryption for vap_id > 0 rsi: fix occasional initialisation failure with BT coex wcn36xx: handle connection loss indication libata: fix checking of DMA state mwifiex: Read a PCI register after writing the TX ring write pointer wcn36xx: Fix HT40 capability for 2Ghz band evm: mark evm_fixmode as __ro_after_init rtl8187: fix control-message timeouts PCI: Mark Atheros QCA6174 to avoid bus reset ath10k: fix division by zero in send path ath10k: fix control-message timeout ath6kl: fix control-message timeout ath6kl: fix division by zero in send path mwifiex: fix division by zero in fw download path EDAC/sb_edac: Fix top-of-high-memory value for Broadwell/Haswell regulator: dt-bindings: samsung,s5m8767: correct s5m8767,pmic-buck-default-dvs-idx property regulator: s5m8767: do not use reset value as DVS voltage if GPIO DVS is disabled hwmon: (pmbus/lm25066) Add offset coefficients ia64: kprobes: Fix to pass correct trampoline address to the handler btrfs: call btrfs_check_rw_degradable only if there is a missing device btrfs: fix lost error handling when replaying directory deletes btrfs: clear MISSING device status bit in btrfs_close_one_device net/smc: Correct spelling mistake to TCPF_SYN_RECV nfp: bpf: relax prog rejection for mtu check through max_pkt_offset vmxnet3: do not stop tx queues after netif_device_detach() r8169: Add device 10ec:8162 to driver r8169 nvmet-tcp: fix header digest verification drm: panel-orientation-quirks: Add quirk for GPD Win3 watchdog: Fix OMAP watchdog early handling net: multicast: calculate csum of looped-back and forwarded packets spi: spl022: fix Microwire full duplex mode nvmet-tcp: fix a memory leak when releasing a queue xen/netfront: stop tx queues during live migration bpf: Prevent increasing bpf_jit_limit above max bpf: Define bpf_jit_alloc_exec_limit for arm64 JIT drm: panel-orientation-quirks: Add quirk for Aya Neo 2021 mmc: winbond: don't build on M68K reset: socfpga: add empty driver allowing consumers to probe ARM: dts: sun7i: A20-olinuxino-lime2: Fix ethernet phy-mode hyperv/vmbus: include linux/bitops.h sfc: Don't use netif_info before net_device setup cavium: Fix return values of the probe function scsi: qla2xxx: Fix unmap of already freed sgl scsi: qla2xxx: Return -ENOMEM if kzalloc() fails cavium: Return negative value when pci_alloc_irq_vectors() fails x86/irq: Ensure PI wakeup handler is unregistered before module unload x86/cpu: Fix migration safety with X86_BUG_NULL_SEL x86/sme: Use #define USE_EARLY_PGTABLE_L5 in mem_encrypt_identity.c fuse: fix page stealing ALSA: timer: Unconditionally unlink slave instances, too ALSA: timer: Fix use-after-free problem ALSA: synth: missing check for possible NULL after the call to kstrdup ALSA: usb-audio: Add registration quirk for JBL Quantum 400 ALSA: line6: fix control and interrupt message timeouts ALSA: 6fire: fix control and bulk message timeouts ALSA: ua101: fix division by zero at probe ALSA: hda/realtek: Add quirk for HP EliteBook 840 G7 mute LED ALSA: hda/realtek: Add quirk for ASUS UX550VE ALSA: hda/realtek: Add a quirk for Acer Spin SP513-54N ALSA: hda/realtek: Add quirk for Clevo PC70HS media: v4l2-ioctl: Fix check_ext_ctrls media: ir-kbd-i2c: improve responsiveness of hauppauge zilog receivers media: ite-cir: IR receiver stop working after receive overflow crypto: s5p-sss - Add error handling in s5p_aes_probe() firmware/psci: fix application of sizeof to pointer tpm: Check for integer overflow in tpm2_map_response_body() parisc: Fix ptrace check on syscall return mmc: dw_mmc: Dont wait for DRTO on Write RSP error scsi: qla2xxx: Fix use after free in eh_abort path scsi: qla2xxx: Fix kernel crash when accessing port_speed sysfs file ocfs2: fix data corruption on truncate libata: fix read log timeout value Input: i8042 - Add quirk for Fujitsu Lifebook T725 Input: elantench - fix misreporting trackpoint coordinates Input: iforce - fix control-message timeout binder: use cred instead of task for getsecid binder: use cred instead of task for selinux checks binder: use euid from cred instead of using task usb: xhci: Enable runtime-pm by default on AMD Yellow Carp platform xhci: Fix USB 3.1 enumeration issues by increasing roothub power-on-good delay Linux 5.4.159 rsi: fix control-message timeout media: staging/intel-ipu3: css: Fix wrong size comparison imgu_css_fw_init staging: rtl8192u: fix control-message timeouts staging: r8712u: fix control-message timeout comedi: vmk80xx: fix bulk and interrupt message timeouts comedi: vmk80xx: fix bulk-buffer overflow comedi: vmk80xx: fix transfer-buffer overflows comedi: ni_usb6501: fix NULL-deref in command paths comedi: dt9812: fix DMA buffers on stack isofs: Fix out of bound access for corrupted isofs image printk/console: Allow to disable console output by using console="" or console=null binder: don't detect sender/target during buffer cleanup usb-storage: Add compatibility quirk flags for iODD 2531/2541 usb: musb: Balance list entry in musb_gadget_queue usb: gadget: Mark USB_FSL_QE broken on 64-bit usb: ehci: handshake CMD_RUN instead of STS_HALT Revert "x86/kvm: fix vcpu-id indexed array sizes" Linux 5.4.158 ARM: 9120/1: Revert "amba: make use of -1 IRQs warn" Revert "drm/ttm: fix memleak in ttm_transfered_destroy" sfc: Fix reading non-legacy supported link modes Revert "usb: core: hcd: Add support for deferring roothub registration" Revert "xhci: Set HCD flag to defer primary roothub registration" media: firewire: firedtv-avc: fix a buffer overflow in avc_ca_pmt() net: ethernet: microchip: lan743x: Fix skb allocation failure vrf: Revert "Reset skb conntrack connection..." scsi: core: Put LLD module refcnt after SCSI device is released Linux 5.4.157 perf script: Check session->header.env.arch before using it KVM: s390: preserve deliverable_mask in __airqs_kick_single_vcpu KVM: s390: clear kicked_mask before sleeping again cfg80211: correct bridge/4addr mode check net: use netif_is_bridge_port() to check for IFF_BRIDGE_PORT sctp: add vtag check in sctp_sf_ootb sctp: add vtag check in sctp_sf_do_8_5_1_E_sa sctp: add vtag check in sctp_sf_violation sctp: fix the processing for COOKIE_ECHO chunk sctp: fix the processing for INIT_ACK chunk sctp: use init_tag from inithdr for ABORT chunk phy: phy_start_aneg: Add an unlocked version phy: phy_ethtool_ksettings_get: Lock the phy for consistency net/tls: Fix flipped sign in async_wait.err assignment net: nxp: lpc_eth.c: avoid hang when bringing interface down net: ethernet: microchip: lan743x: Fix dma allocation failure by using dma_set_mask_and_coherent net: ethernet: microchip: lan743x: Fix driver crash when lan743x_pm_resume fails nios2: Make NIOS2_DTB_SOURCE_BOOL depend on !COMPILE_TEST RDMA/sa_query: Use strscpy_pad instead of memcpy to copy a string net: Prevent infinite while loop in skb_tx_hash() net: batman-adv: fix error handling regmap: Fix possible double-free in regcache_rbtree_exit() arm64: dts: allwinner: h5: NanoPI Neo 2: Fix ethernet node RDMA/mlx5: Set user priority for DCT nvme-tcp: fix data digest pointer calculation nvmet-tcp: fix data digest pointer calculation IB/hfi1: Fix abba locking issue with sc_disable() IB/qib: Protect from buffer overflow in struct qib_user_sdma_pkt fields tcp_bpf: Fix one concurrency problem in the tcp_bpf_send_verdict function drm/ttm: fix memleak in ttm_transfered_destroy net: lan78xx: fix division by zero in send path cfg80211: scan: fix RCU in cfg80211_add_nontrans_list() mmc: sdhci-esdhc-imx: clear the buffer_read_ready to reset standard tuning circuit mmc: sdhci: Map more voltage level to SDHCI_POWER_330 mmc: dw_mmc: exynos: fix the finding clock sample value mmc: cqhci: clear HALT state after CQE enable mmc: vub300: fix control-message timeouts net/tls: Fix flipped sign in tls_err_abort() calls Revert "net: mdiobus: Fix memory leak in __mdiobus_register" nfc: port100: fix using -ERRNO as command type mask ata: sata_mv: Fix the error handling of mv_chip_id() Revert "pinctrl: bcm: ns: support updated DT binding as syscon subnode" usbnet: fix error return code in usbnet_probe() usbnet: sanity check for maxpacket ipv4: use siphash instead of Jenkins in fnhe_hashfun() ipv6: use siphash in rt6_exception_hash() powerpc/bpf: Fix BPF_MOD when imm == 1 ARM: 9141/1: only warn about XIP address when not compile testing ARM: 9139/1: kprobes: fix arch_init_kprobes() prototype ARM: 9134/1: remove duplicate memcpy() definition ARM: 9133/1: mm: proc-macros: ensure *_tlb_fns are 4B aligned Linux 5.4.156 pinctrl: stm32: use valid pin identifier in stm32_pinctrl_resume() ARM: 9122/1: select HAVE_FUTEX_CMPXCHG tracing: Have all levels of checks prevent recursion net: mdiobus: Fix memory leak in __mdiobus_register scsi: core: Fix shost->cmd_per_lun calculation in scsi_add_host_with_dma() Input: snvs_pwrkey - add clk handling ALSA: hda: avoid write to STATESTS if controller is in reset platform/x86: intel_scu_ipc: Update timeout value in comment isdn: mISDN: Fix sleeping function called from invalid context ARM: dts: spear3xx: Fix gmac node net: stmmac: add support for dwmac 3.40a btrfs: deal with errors when checking if a dir entry exists during log replay gcc-plugins/structleak: add makefile var for disabling structleak selftests: netfilter: remove stray bash debug line netfilter: Kconfig: use 'default y' instead of 'm' for bool config option isdn: cpai: check ctr->cnr to avoid array index out of bound nfc: nci: fix the UAF of rf_conn_info object mm, slub: fix potential memoryleak in kmem_cache_open() mm, slub: fix mismatch between reconstructed freelist depth and cnt powerpc/idle: Don't corrupt back chain when going idle KVM: PPC: Book3S HV: Make idle_kvm_start_guest() return 0 if it went to guest KVM: PPC: Book3S HV: Fix stack handling in idle_kvm_start_guest() powerpc64/idle: Fix SP offsets when saving GPRs audit: fix possible null-pointer dereference in audit_filter_rules ASoC: DAPM: Fix missing kctl change notifications ALSA: hda/realtek: Add quirk for Clevo PC50HS ALSA: usb-audio: Provide quirk for Sennheiser GSP670 Headset vfs: check fd has read access in kernel_read_file_from_fd() elfcore: correct reference to CONFIG_UML ocfs2: mount fails with buffer overflow in strlen ocfs2: fix data corruption after conversion from inline format ceph: fix handling of "meta" errors can: j1939: j1939_xtp_rx_rts_session_new(): abort TP less than 9 bytes can: j1939: j1939_xtp_rx_dat_one(): cancel session if receive TP.DT with error length can: j1939: j1939_netdev_start(): fix UAF for rx_kref of j1939_priv can: j1939: j1939_tp_rxtimer(): fix errant alert in j1939_tp_rxtimer can: peak_pci: peak_pci_remove(): fix UAF can: peak_usb: pcan_usb_fd_decode_status(): fix back to ERROR_ACTIVE state notification can: rcar_can: fix suspend/resume net: enetc: fix ethtool counter name for PM0_TERR net: stmmac: Fix E2E delay mechanism net: hns3: disable sriov before unload hclge layer net: hns3: add limit ets dwrr bandwidth cannot be 0 net: hns3: reset DWRR of unused tc to zero NIOS2: irqflags: rename a redefined register name net: dsa: lantiq_gswip: fix register definition lan78xx: select CRC32 netfilter: ipvs: make global sysctl readonly in non-init netns ASoC: wm8960: Fix clock configuration on slave mode dma-debug: fix sg checks in debug_dma_map_sg() NFSD: Keep existing listeners on portlist error xtensa: xtfpga: Try software restart before simulating CPU reset xtensa: xtfpga: use CONFIG_USE_OF instead of CONFIG_OF ARM: dts: at91: sama5d2_som1_ek: disable ISC node by default tee: optee: Fix missing devices unregister during optee_remove net: switchdev: do not propagate bridge updates across bridges parisc: math-emu: Fix fall-through warnings Linux 5.4.155 ionic: don't remove netdev->dev_addr when syncing uc list r8152: select CRC32 and CRYPTO/CRYPTO_HASH/CRYPTO_SHA256 qed: Fix missing error code in qed_slowpath_start() mqprio: Correct stats in mqprio_dump_class_stats(). acpi/arm64: fix next_platform_timer() section mismatch error drm/msm/dsi: fix off by one in dsi_bus_clk_enable error handling drm/msm/dsi: Fix an error code in msm_dsi_modeset_init() drm/msm: Fix null pointer dereference on pointer edp drm/panel: olimex-lcd-olinuxino: select CRC32 platform/mellanox: mlxreg-io: Fix argument base in kstrtou32() call mlxsw: thermal: Fix out-of-bounds memory accesses ata: ahci_platform: fix null-ptr-deref in ahci_platform_enable_regulators() pata_legacy: fix a couple uninitialized variable bugs NFC: digital: fix possible memory leak in digital_in_send_sdd_req() NFC: digital: fix possible memory leak in digital_tg_listen_mdaa() nfc: fix error handling of nfc_proto_register() ethernet: s2io: fix setting mac address during resume net: encx24j600: check error in devm_regmap_init_encx24j600 net: stmmac: fix get_hw_feature() on old hardware net/mlx5e: Mutually exclude RX-FCS and RX-port-timestamp net: korina: select CRC32 net: arc: select CRC32 gpio: pca953x: Improve bias setting sctp: account stream padding length for reconf chunk iio: dac: ti-dac5571: fix an error code in probe() iio: ssp_sensors: fix error code in ssp_print_mcu_debug() iio: ssp_sensors: add more range checking in ssp_parse_dataframe() iio: light: opt3001: Fixed timeout error when 0 lux iio: mtk-auxadc: fix case IIO_CHAN_INFO_PROCESSED iio: adc128s052: Fix the error handling path of 'adc128_probe()' iio: adc: aspeed: set driver data when adc probe. powerpc/xive: Discard disabled interrupts in get_irqchip_state() x86/Kconfig: Do not enable AMD_MEM_ENCRYPT_ACTIVE_BY_DEFAULT automatically nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells EDAC/armada-xp: Fix output of uncorrectable error counter virtio: write back F_VERSION_1 before validate USB: serial: option: add prod. id for Quectel EG91 USB: serial: option: add Telit LE910Cx composition 0x1204 USB: serial: option: add Quectel EC200S-CN module support USB: serial: qcserial: add EM9191 QDL support Input: xpad - add support for another USB ID of Nacon GC-100 usb: musb: dsps: Fix the probe error path efi: Change down_interruptible() in virt_efi_reset_system() to down_trylock() efi/cper: use stack buffer for error record decoding cb710: avoid NULL pointer subtraction xhci: Enable trust tx length quirk for Fresco FL11 USB controller xhci: Fix command ring pointer corruption while aborting a command xhci: guard accesses to ep_state in xhci_endpoint_reset() mei: me: add Ice Lake-N device id. x86/resctrl: Free the ctrlval arrays when domain_setup_mon_state() fails watchdog: orion: use 0 for unset heartbeat btrfs: check for error when looking up inode during dir entry replay btrfs: deal with errors when adding inode reference during log replay btrfs: deal with errors when replaying dir entry during log replay btrfs: unlock newly allocated extent buffer after error csky: Fixup regs.sr broken in ptrace csky: don't let sigreturn play with priveleged bits of status register s390: fix strrchr() implementation nds32/ftrace: Fix Error: invalid operands (*UND* and *UND* sections) for `^' ALSA: hda/realtek: Fix the mic type detection issue for ASUS G551JW ALSA: hda/realtek - ALC236 headset MIC recording issue ALSA: hda/realtek: Add quirk for Clevo X170KM-G ALSA: hda/realtek: Complete partial device name to avoid ambiguity ALSA: seq: Fix a potential UAF by wrong private_free call order ALSA: usb-audio: Add quirk for VF0770 ovl: simplify file splice Linux 5.4.154 sched: Always inline is_percpu_thread() scsi: virtio_scsi: Fix spelling mistake "Unsupport" -> "Unsupported" scsi: ses: Fix unsigned comparison with less than zero drm/amdgpu: fix gart.bo pin_count leak net: sun: SUNVNET_COMMON should depend on INET mac80211: check return value of rhashtable_init net: prevent user from passing illegal stab size m68k: Handle arrivals of multiple signals correctly mac80211: Drop frames from invalid MAC address in ad-hoc mode netfilter: nf_nat_masquerade: defer conntrack walk to work queue netfilter: nf_nat_masquerade: make async masq_inet6_event handling generic HID: wacom: Add new Intuos BT (CTL-4100WL/CTL-6100WL) device IDs netfilter: ip6_tables: zero-initialize fragment offset HID: apple: Fix logical maximum and usage maximum of Magic Keyboard JIS ext4: correct the error path of ext4_write_inline_data_end() net: phy: bcm7xxx: Fixed indirect MMD operations UPSTREAM: ovl: simplify file splice Linux 5.4.153 x86/Kconfig: Correct reference to MWINCHIP3D x86/hpet: Use another crystalball to evaluate HPET usability x86/platform/olpc: Correct ifdef symbol to intended CONFIG_OLPC_XO15_SCI RISC-V: Include clone3() on rv32 bpf, s390: Fix potential memory leak about jit_data i2c: acpi: fix resource leak in reconfiguration device addition net: prefer socket bound to interface when not in VRF i40e: Fix freeing of uninitialized misc IRQ vector i40e: fix endless loop under rtnl gve: fix gve_get_stats() rtnetlink: fix if_nlmsg_stats_size() under estimation gve: Correct available tx qpl check drm/nouveau/debugfs: fix file release memory leak video: fbdev: gbefb: Only instantiate device when built for IP32 bus: ti-sysc: Use CLKDM_NOAUTO for dra7 dcan1 for errata i893 netlink: annotate data races around nlk->bound net: sfp: Fix typo in state machine debug string net/sched: sch_taprio: properly cancel timer from taprio_destroy() net: bridge: use nla_total_size_64bit() in br_get_linkxstats_size() ARM: imx6: disable the GIC CPU interface before calling stby-poweroff sequence arm64: dts: ls1028a: add missing CAN nodes arm64: dts: freescale: Fix SP805 clock-names ptp_pch: Load module automatically if ID matches powerpc/fsl/dts: Fix phy-connection-type for fm1mac3 net_sched: fix NULL deref in fifo_set_limit() phy: mdio: fix memory leak bpf: Fix integer overflow in prealloc_elems_and_freelist() bpf, arm: Fix register clobbering in div/mod implementation xtensa: call irqchip_init only when CONFIG_USE_OF is selected xtensa: use CONFIG_USE_OF instead of CONFIG_OF xtensa: move XCHAL_KIO_* definitions to kmem_layout.h arm64: dts: qcom: pm8150: use qcom,pm8998-pon binding ARM: dts: imx: Fix USB host power regulator polarity on M53Menlo ARM: dts: imx: Add missing pinctrl-names for panel on M53Menlo soc: qcom: mdt_loader: Drop PT_LOAD check on hash segment ARM: dts: qcom: apq8064: Use 27MHz PXO clock as DSI PLL reference soc: qcom: socinfo: Fixed argument passed to platform_set_data() bpf, mips: Validate conditional branch offsets MIPS: BPF: Restore MIPS32 cBPF JIT ARM: dts: qcom: apq8064: use compatible which contains chipid ARM: dts: omap3430-sdp: Fix NAND device node xen/balloon: fix cancelled balloon action nfsd4: Handle the NFSv4 READDIR 'dircount' hint being zero nfsd: fix error handling of register_pernet_subsys() in init_nfsd() ovl: fix missing negative dentry check in ovl_rename() mmc: meson-gx: do not use memcpy_to/fromio for dram-access-quirk xen/privcmd: fix error handling in mmap-resource processing usb: typec: tcpm: handle SRC_STARTUP state if cc changes USB: cdc-acm: fix break reporting USB: cdc-acm: fix racy tty buffer accesses Partially revert "usb: Kconfig: using select for USB_COMMON dependency" ANDROID: Different fix for KABI breakage in 5.4.151 in struct sock Linux 5.4.152 libata: Add ATA_HORKAGE_NO_NCQ_ON_ATI for Samsung 860 and 870 SSD. silence nfscache allocation warnings with kvzalloc perf/x86: Reset destroy callback on event init failure kvm: x86: Add AMD PMU MSRs to msrs_to_save_all[] KVM: do not shrink halt_poll_ns below grow_start tools/vm/page-types: remove dependency on opt_file for idle page tracking scsi: ses: Retry failed Send/Receive Diagnostic commands selftests:kvm: fix get_warnings_count() ignoring fscanf() return warn selftests: be sure to make khdr before other targets usb: dwc2: check return value after calling platform_get_resource() usb: testusb: Fix for showing the connection speed scsi: sd: Free scsi_disk device via put_device() ext2: fix sleeping in atomic bugs on error sparc64: fix pci_iounmap() when CONFIG_PCI is not set xen-netback: correct success/error reporting for the SKB-with-fraglist case net: mdio: introduce a shutdown method to mdio device drivers ANDROID: Fix up KABI breakage in 5.4.151 in struct sock Linux 5.4.151 HID: usbhid: free raw_report buffers in usbhid_stop netfilter: ipset: Fix oversized kvmalloc() calls HID: betop: fix slab-out-of-bounds Write in betop_probe crypto: ccp - fix resource leaks in ccp_run_aes_gcm_cmd() usb: hso: remove the bailout parameter usb: hso: fix error handling code of hso_create_net_device hso: fix bailout in error case of probe libnvdimm/pmem: Fix crash triggered when I/O in-flight during unbind PCI: Fix pci_host_bridge struct device release/free handling net: stmmac: don't attach interface until resume finishes net: udp: annotate data race around udp_sk(sk)->corkflag HID: u2fzero: ignore incomplete packets without data ext4: fix potential infinite loop in ext4_dx_readdir() ext4: fix reserved space counter leakage ext4: fix loff_t overflow in ext4_max_bitmap_size() ipack: ipoctal: fix module reference leak ipack: ipoctal: fix missing allocation-failure check ipack: ipoctal: fix tty-registration error handling ipack: ipoctal: fix tty registration race ipack: ipoctal: fix stack information leak debugfs: debugfs_create_file_size(): use IS_ERR to check for error elf: don't use MAP_FIXED_NOREPLACE for elf interpreter mappings perf/x86/intel: Update event constraints for ICX af_unix: fix races in sk_peer_pid and sk_peer_cred accesses net: sched: flower: protect fl_walk() with rcu net: hns3: do not allow call hns3_nic_net_open repeatedly scsi: csiostor: Add module softdep on cxgb4 Revert "block, bfq: honor already-setup queue merges" selftests, bpf: test_lwt_ip_encap: Really disable rp_filter e100: fix buffer overrun in e100_get_regs e100: fix length calculation in e100_get_regs_len net: ipv4: Fix rtnexthop len when RTA_FLOW is present hwmon: (tmp421) fix rounding for negative values hwmon: (tmp421) report /PVLD condition as fault sctp: break out if skb_header_pointer returns NULL in sctp_rcv_ootb mac80211-hwsim: fix late beacon hrtimer handling mac80211: mesh: fix potentially unaligned access mac80211: limit injected vht mcs/nss in ieee80211_parse_tx_radiotap mac80211: Fix ieee80211_amsdu_aggregate frag_tail bug hwmon: (mlxreg-fan) Return non-zero value when fan current state is enforced from sysfs ipvs: check that ip_vs_conn_tab_bits is between 8 and 20 drm/amd/display: Pass PCI deviceid into DC x86/kvmclock: Move this_cpu_pvti into kvmclock.h mac80211: fix use-after-free in CCMP/GCMP RX scsi: ufs: Fix illegal offset in UPIU event trace hwmon: (w83791d) Fix NULL pointer dereference by removing unnecessary structure field hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field hwmon: (w83793) Fix NULL pointer dereference by removing unnecessary structure field fs-verity: fix signed integer overflow with i_size near S64_MAX usb: cdns3: fix race condition before setting doorbell cpufreq: schedutil: Destroy mutex before kobject_put() frees the memory cpufreq: schedutil: Use kobject release() method to free sugov_tunables tty: Fix out-of-bound vmalloc access in imageblit Revert "crypto: public_key: fix overflow during implicit conversion" Linux 5.4.150 qnx4: work around gcc false positive warning bug xen/balloon: fix balloon kthread freezing arm64: dts: marvell: armada-37xx: Extend PCIe MEM space thermal/drivers/int340x: Do not set a wrong tcc offset on resume EDAC/synopsys: Fix wrong value type assignment for edac_mode spi: Fix tegra20 build with CONFIG_PM=n net: 6pack: Fix tx timeout and slot time alpha: Declare virt_to_phys and virt_to_bus parameter as pointer to volatile arm64: Mark __stack_chk_guard as __ro_after_init parisc: Use absolute_pointer() to define PAGE0 qnx4: avoid stringop-overread errors sparc: avoid stringop-overread errors net: i825xx: Use absolute_pointer for memcpy from fixed memory location compiler.h: Introduce absolute_pointer macro blk-cgroup: fix UAF by grabbing blkcg lock before destroying blkg pd sparc32: page align size in arch_dma_alloc nvme-multipath: fix ANA state updates when a namespace is not present xen/balloon: use a kernel thread instead a workqueue bpf: Add oversize check before call kvcalloc() ipv6: delay fib6_sernum increase in fib6_add m68k: Double cast io functions to unsigned long net: stmmac: allow CSR clock of 300MHz net: macb: fix use after free on rmmod blktrace: Fix uaf in blk_trace access after removing by sysfs md: fix a lock order reversal in md_alloc irqchip/gic-v3-its: Fix potential VPE leak on error irqchip/goldfish-pic: Select GENERIC_IRQ_CHIP to fix build scsi: lpfc: Use correct scnprintf() limit scsi: qla2xxx: Restore initiator in dual mode cifs: fix a sign extension bug thermal/core: Potential buffer overflow in thermal_build_list_of_policies() fpga: machxo2-spi: Fix missing error code in machxo2_write_complete() fpga: machxo2-spi: Return an error on failure tty: synclink_gt: rename a conflicting function name tty: synclink_gt, drop unneeded forward declarations scsi: iscsi: Adjust iface sysfs attr detection net/mlx4_en: Don't allow aRFS for encapsulated packets qed: rdma - don't wait for resources under hw error recovery flow gpio: uniphier: Fix void functions to remove return value net/smc: add missing error check in smc_clc_prfx_set() bnxt_en: Fix TX timeout when TX ring size is set to the smallest enetc: Fix illegal access when reading affinity_hint platform/x86/intel: punit_ipc: Drop wrong use of ACPI_PTR() afs: Fix incorrect triggering of sillyrename on 3rd-party invalidation net: hso: fix muxed tty registration serial: mvebu-uart: fix driver's tx_empty callback xhci: Set HCD flag to defer primary roothub registration btrfs: prevent __btrfs_dump_space_info() to underflow its free space erofs: fix up erofs_lookup tracepoint mcb: fix error handling in mcb_alloc_bus() USB: serial: option: add device id for Foxconn T99W265 USB: serial: option: remove duplicate USB device ID USB: serial: option: add Telit LN920 compositions USB: serial: mos7840: remove duplicated 0xac24 device ID usb: core: hcd: Add support for deferring roothub registration Re-enable UAS for LaCie Rugged USB3-FW with fk quirk staging: greybus: uart: fix tty use after free binder: make sure fd closes complete USB: cdc-acm: fix minor-number release USB: serial: cp210x: add ID for GW Instek GDM-834x Digital Multimeter usb-storage: Add quirk for ScanLogic SL11R-IDE older than 2.6c xen/x86: fix PV trap handling on secondary processors cifs: fix incorrect check for null pointer in header_assemble usb: musb: tusb6010: uninitialized data in tusb_fifo_write_unaligned() usb: dwc2: gadget: Fix ISOC transfer complete handling for DDMA usb: dwc2: gadget: Fix ISOC flow for BDMA and Slave usb: gadget: r8a66597: fix a loop in set_feature() ocfs2: drop acl cache for directories too Linux 5.4.149 drm/nouveau/nvkm: Replace -ENOSYS with -ENODEV rtc: rx8010: select REGMAP_I2C blk-throttle: fix UAF by deleteing timer in blk_throtl_exit() pwm: stm32-lp: Don't modify HW state in .remove() callback pwm: rockchip: Don't modify HW state in .remove() callback pwm: img: Don't modify HW state in .remove() callback nilfs2: fix memory leak in nilfs_sysfs_delete_snapshot_group nilfs2: fix memory leak in nilfs_sysfs_create_snapshot_group nilfs2: fix memory leak in nilfs_sysfs_delete_##name##_group nilfs2: fix memory leak in nilfs_sysfs_create_##name##_group nilfs2: fix NULL pointer in nilfs_##name##_attr_release nilfs2: fix memory leak in nilfs_sysfs_create_device_group btrfs: fix lockdep warning while mounting sprout fs ceph: lockdep annotations for try_nonblocking_invalidate ceph: request Fw caps before updating the mtime in ceph_write_iter dmaengine: xilinx_dma: Set DMA mask for coherent APIs dmaengine: ioat: depends on !UML dmaengine: sprd: Add missing MODULE_DEVICE_TABLE parisc: Move pci_dev_is_behind_card_dino to where it is used drivers: base: cacheinfo: Get rid of DEFINE_SMP_CALL_CACHE_FUNCTION() thermal/core: Fix thermal_cooling_device_register() prototype Kconfig.debug: drop selecting non-existing HARDLOCKUP_DETECTOR_ARCH net: stmmac: reset Tx desc base address before restarting Tx phy: avoid unnecessary link-up delay in polling mode pwm: lpc32xx: Don't modify HW state in .probe() after the PWM chip was registered profiling: fix shift-out-of-bounds bugs nilfs2: use refcount_dec_and_lock() to fix potential UAF prctl: allow to setup brk for et_dyn executables 9p/trans_virtio: Remove sysfs file on probe failure thermal/drivers/exynos: Fix an error code in exynos_tmu_probe() dmaengine: acpi: Avoid comparison GSI with Linux vIRQ um: virtio_uml: fix memory leak on init failures staging: rtl8192u: Fix bitwise vs logical operator in TranslateRxSignalStuff819xUsb() sctp: add param size validation for SCTP_PARAM_SET_PRIMARY sctp: validate chunk size in __rcv_asconf_lookup ARM: 9098/1: ftrace: MODULE_PLT: Fix build problem without DYNAMIC_FTRACE ARM: 9079/1: ftrace: Add MODULE_PLTS support ARM: 9078/1: Add warn suppress parameter to arm_gen_branch_link() ARM: 9077/1: PLT: Move struct plt_entries definition to header apparmor: remove duplicate macro list_entry_is_head() ARM: Qualify enabling of swiotlb_init() s390/pci_mmio: fully validate the VMA before calling follow_pte() console: consume APC, DM, DCS KVM: remember position in kvm->vcpus array PCI/ACPI: Add Ampere Altra SOC MCFG quirk PCI: aardvark: Fix reporting CRS value PCI: pci-bridge-emul: Add PCIe Root Capabilities Register PCI: aardvark: Indicate error in 'val' when config read fails PCI: pci-bridge-emul: Fix big-endian support Linux 5.4.148 s390/bpf: Fix 64-bit subtraction of the -0x80000000 constant s390/bpf: Fix optimizing out zero-extensions net: renesas: sh_eth: Fix freeing wrong tx descriptor ip_gre: validate csum_start only on pull qlcnic: Remove redundant unlock in qlcnic_pinit_from_rom fq_codel: reject silly quantum parameters netfilter: socket: icmp6: fix use-after-scope net: dsa: b53: Fix calculating number of switch ports perf unwind: Do not overwrite FEATURE_CHECK_LDFLAGS-libunwind-{x86,aarch64} ARC: export clear_user_page() for modules mtd: rawnand: cafe: Fix a resource leak in the error handling path of 'cafe_nand_probe()' PCI: Sync __pci_register_driver() stub for CONFIG_PCI=n KVM: arm64: Handle PSCI resets before userspace touches vCPU state mfd: tqmx86: Clear GPIO IRQ resource when no IRQ is set PCI: Fix pci_dev_str_match_path() alloc while atomic bug mfd: axp20x: Update AXP288 volatile ranges NTB: perf: Fix an error code in perf_setup_inbuf() NTB: Fix an error code in ntb_msit_probe() ethtool: Fix an error code in cxgb2.c PCI: ibmphp: Fix double unmap of io_mem block, bfq: honor already-setup queue merges net: usb: cdc_mbim: avoid altsetting toggling for Telit LN920 Set fc_nlinfo in nh_create_ipv4, nh_create_ipv6 PCI: Add ACS quirks for Cavium multi-function devices tracing/probes: Reject events which have the same name of existing one mfd: Don't use irq_create_mapping() to resolve a mapping fuse: fix use after free in fuse_read_interrupt() PCI: Add ACS quirks for NXP LX2xx0 and LX2xx2 platforms mfd: db8500-prcmu: Adjust map to reality dt-bindings: mtd: gpmc: Fix the ECC bytes vs. OOB bytes equation mm/memory_hotplug: use "unsigned long" for PFN in zone_for_pfn_range() net: hns3: fix the timing issue of VF clearing interrupt sources net: hns3: disable mac in flr process net: hns3: change affinity_mask to numa node range net: hns3: pad the short tunnel frame before sending to hardware KVM: PPC: Book3S HV: Tolerate treclaim. in fake-suspend mode changing registers ibmvnic: check failover_pending in login response dt-bindings: arm: Fix Toradex compatible typo qed: Handle management FW error tcp: fix tp->undo_retrans accounting in tcp_sacktag_one() net: dsa: destroy the phylink instance on any error in dsa_slave_phy_setup net/af_unix: fix a data-race in unix_dgram_poll vhost_net: fix OoB on sendmsg() failure. events: Reuse value read using READ_ONCE instead of re-reading it net/mlx5: Fix potential sleeping in atomic context net/mlx5: FWTrace, cancel work on alloc pd error flow perf machine: Initialize srcline string member in add_location struct tipc: increase timeout in tipc_sk_enqueue() r6040: Restore MDIO clock frequency after MAC reset net/l2tp: Fix reference count leak in l2tp_udp_recv_core dccp: don't duplicate ccid when cloning dccp sock ptp: dp83640: don't define PAGE0 net-caif: avoid user-triggerable WARN_ON(1) tipc: fix an use-after-free issue in tipc_recvmsg x86/mm: Fix kern_addr_valid() to cope with existing but not present entries s390/sclp: fix Secure-IPL facility detection drm/etnaviv: add missing MMU context put when reaping MMU mapping drm/etnaviv: reference MMU context when setting up hardware state drm/etnaviv: fix MMU context leak on GPU reset drm/etnaviv: exec and MMU state is lost when resetting the GPU drm/etnaviv: keep MMU context across runtime suspend/resume drm/etnaviv: stop abusing mmu_context as FE running marker drm/etnaviv: put submit prev MMU context when it exists drm/etnaviv: return context from etnaviv_iommu_context_get drm/amd/amdgpu: Increase HWIP_MAX_INSTANCE to 10 PCI: Add AMD GPU multi-function power dependencies PM: base: power: don't try to use non-existing RTC for storing data arm64/sve: Use correct size when reinitialising SVE state bnx2x: Fix enabling network interfaces without VFs xen: reset legacy rtc flag for PV domU btrfs: fix upper limit for max_inline for page size 64K drm/panfrost: Clamp lock region to Bifrost minimum drm/panfrost: Use u64 for size in lock_region drm/panfrost: Simplify lock_region calculation drm/amdgpu: Fix BUG_ON assert drm/msi/mdp4: populate priv->kms in mdp4_kms_init net: dsa: lantiq_gswip: fix maximum frame length lib/test_stackinit: Fix static initializer test platform/chrome: cros_ec_proto: Send command again when timeout occurs memcg: enable accounting for pids in nested pid namespaces mm,vmscan: fix divide by zero in get_scan_count mm/hugetlb: initialize hugetlb_usage in mm_init s390/pv: fix the forcing of the swiotlb cpufreq: powernv: Fix init_chip_info initialization in numa=off scsi: qla2xxx: Sync queue idx with queue_pair_map idx scsi: qla2xxx: Changes to support kdump kernel scsi: BusLogic: Fix missing pr_cont() use ovl: fix BUG_ON() in may_delete() when called from ovl_cleanup() parisc: fix crash with signals and alloca net: w5100: check return value after calling platform_get_resource() fix array-index-out-of-bounds in taprio_change net: fix NULL pointer reference in cipso_v4_doi_free ath9k: fix sleeping in atomic context ath9k: fix OOB read ar9300_eeprom_restore_internal parport: remove non-zero check on count net/mlx5: DR, Enable QP retransmission iwlwifi: mvm: fix access to BSS elements iwlwifi: mvm: avoid static queue number aliasing iwlwifi: mvm: fix a memory leak in iwl_mvm_mac_ctxt_beacon_changed drm/amdkfd: Account for SH/SE count when setting up cu masks. ASoC: rockchip: i2s: Fixup config for DAIFMT_DSP_A/B ASoC: rockchip: i2s: Fix regmap_ops hang usbip:vhci_hcd USB port can get stuck in the disabled state usbip: give back URBs for unsent unlink requests during cleanup usb: musb: musb_dsps: request_irq() after initializing musb Revert "USB: xhci: fix U1/U2 handling for hardware with XHCI_INTEL_HOST quirk set" cifs: fix wrong release in sess_alloc_buffer() failed path mmc: core: Return correct emmc response in case of ioctl error selftests/bpf: Enlarge select() timeout for test_maps mmc: rtsx_pci: Fix long reads when clock is prescaled mmc: sdhci-of-arasan: Check return value of non-void funtions of: Don't allow __of_attached_node_sysfs() without CONFIG_SYSFS ASoC: Intel: Skylake: Fix passing loadable flag for module ASoC: Intel: Skylake: Fix module configuration for KPB and MIXER btrfs: tree-log: check btrfs_lookup_data_extent return value m68knommu: only set CONFIG_ISA_DMA_API for ColdFire sub-arch drm/exynos: Always initialize mapping in exynos_drm_register_dma() lockd: lockd server-side shouldn't set fl_ops usb: chipidea: host: fix port index underflow and UBSAN complains gfs2: Don't call dlm after protocol is unmounted staging: rts5208: Fix get_ms_information() heap buffer size rpc: fix gss_svc_init cleanup on failure tcp: enable data-less, empty-cookie SYN with TFO_SERVER_COOKIE_NOT_REQD serial: sh-sci: fix break handling for sysrq opp: Don't print an error if required-opps is missing Bluetooth: Fix handling of LE Enhanced Connection Complete nvme-tcp: don't check blk_mq_tag_to_rq when receiving pdu data arm64: dts: ls1046a: fix eeprom entries arm64: tegra: Fix compatible string for Tegra132 CPUs ARM: tegra: tamonten: Fix UART pad setting mac80211: Fix monitor MTU limit so that A-MSDUs get through drm/display: fix possible null-pointer dereference in dcn10_set_clock() gpu: drm: amd: amdgpu: amdgpu_i2c: fix possible uninitialized-variable access in amdgpu_i2c_router_select_ddc_port() net/mlx5: Fix variable type to match 64bit Bluetooth: avoid circular locks in sco_sock_connect Bluetooth: schedule SCO timeouts with delayed_work selftests/bpf: Fix xdp_tx.c prog section name drm/msm: mdp4: drop vblank get/put from prepare/complete_commit net: ethernet: stmmac: Do not use unreachable() in ipq806x_gmac_probe() arm64: dts: qcom: sdm660: use reg value for memory node ARM: dts: imx53-ppd: Fix ACHC entry media: tegra-cec: Handle errors of clk_prepare_enable() media: TDA1997x: fix tda1997x_query_dv_timings() return value media: v4l2-dv-timings.c: fix wrong condition in two for-loops media: imx258: Limit the max analogue gain to 480 media: imx258: Rectify mismatch of VTS value ASoC: Intel: bytcr_rt5640: Move "Platform Clock" routes to the maps for the matching in-/output arm64: tegra: Fix Tegra194 PCIe EP compatible string bonding: 3ad: fix the concurrency between __bond_release_one() and bond_3ad_state_machine_handler() workqueue: Fix possible memory leaks in wq_numa_init() Bluetooth: skip invalid hci_sync_conn_complete_evt ata: sata_dwc_460ex: No need to call phy_exit() befre phy_init() samples: bpf: Fix tracex7 error raised on the missing argument staging: ks7010: Fix the initialization of the 'sleep_status' structure serial: 8250_pci: make setup_port() parameters explicitly unsigned hvsi: don't panic on tty_register_driver failure xtensa: ISS: don't panic in rs_init serial: 8250: Define RX trigger levels for OxSemi 950 devices s390: make PCI mio support a machine flag s390/jump_label: print real address in a case of a jump label bug flow_dissector: Fix out-of-bounds warnings ipv4: ip_output.c: Fix out-of-bounds warning in ip_copy_addrs() video: fbdev: riva: Error out if 'pixclock' equals zero video: fbdev: kyro: Error out if 'pixclock' equals zero video: fbdev: asiliantfb: Error out if 'pixclock' equals zero bpf/tests: Do not PASS tests without actually testing the result bpf/tests: Fix copy-and-paste error in double word test drm/amd/amdgpu: Update debugfs link_settings output link_rate field in hex drm/amd/display: Fix timer_per_pixel unit error tty: serial: jsm: hold port lock when reporting modem line changes staging: board: Fix uninitialized spinlock when attaching genpd usb: gadget: composite: Allow bMaxPower=0 if self-powered USB: EHCI: ehci-mv: improve error handling in mv_ehci_enable() usb: gadget: u_ether: fix a potential null pointer dereference usb: host: fotg210: fix the actual_length of an iso packet usb: host: fotg210: fix the endpoint's transactional opportunities calculation igc: Check if num of q_vectors is smaller than max before array access drm: avoid blocking in drm_clients_info's rcu section Smack: Fix wrong semantics in smk_access_entry() netlink: Deal with ESRCH error in nlmsg_notify() video: fbdev: kyro: fix a DoS bug by restricting user input ARM: dts: qcom: apq8064: correct clock names iavf: fix locking of critical sections iavf: do not override the adapter state in the watchdog task iio: dac: ad5624r: Fix incorrect handling of an optional regulator. tipc: keep the skb in rcv queue until the whole data is read PCI: Use pci_update_current_state() in pci_enable_device_flags() crypto: mxs-dcp - Use sg_mapping_iter to copy data media: dib8000: rewrite the init prbs logic ASoC: atmel: ATMEL drivers don't need HAS_DMA drm/amdgpu: Fix amdgpu_ras_eeprom_init() userfaultfd: prevent concurrent API initialization kbuild: Fix 'no symbols' warning when CONFIG_TRIM_UNUSD_KSYMS=y MIPS: Malta: fix alignment of the devicetree buffer f2fs: fix to unmap pages from userspace process in punch_hole() f2fs: fix unexpected ENOENT comes from f2fs_map_blocks() f2fs: fix to account missing .skipped_gc_rwsem KVM: PPC: Fix clearing never mapped TCEs in realmode clk: at91: clk-generated: Limit the requested rate to our range clk: at91: clk-generated: pass the id of changeable parent at registration clk: at91: sam9x60: Don't use audio PLL fscache: Fix cookie key hashing platform/x86: dell-smbios-wmi: Add missing kfree in error-exit from run_smbios_call KVM: PPC: Book3S HV Nested: Reflect guest PMU in-use to L0 when guest SPRs are live HID: i2c-hid: Fix Elan touchpad regression scsi: target: avoid per-loop XCOPY buffer allocations powerpc/config: Renable MTD_PHYSMAP_OF scsi: qedf: Fix error codes in qedf_alloc_global_queues() scsi: qedi: Fix error codes in qedi_alloc_global_queues() scsi: smartpqi: Fix an error code in pqi_get_raid_map() pinctrl: single: Fix error return code in pcs_parse_bits_in_pinctrl_entry() scsi: fdomain: Fix error return code in fdomain_probe() SUNRPC: Fix potential memory corruption dma-debug: fix debugfs initialization order openrisc: don't printk() unconditionally f2fs: reduce the scope of setting fsck tag when de->name_len is zero f2fs: show f2fs instance in printk_ratelimited RDMA/efa: Remove double QP type assignment powerpc/stacktrace: Include linux/delay.h vfio: Use config not menuconfig for VFIO_NOIOMMU pinctrl: samsung: Fix pinctrl bank pin count docs: Fix infiniband uverbs minor number RDMA/iwcm: Release resources if iw_cm module initialization fails IB/hfi1: Adjust pkey entry in index 0 scsi: bsg: Remove support for SCSI_IOCTL_SEND_COMMAND f2fs: quota: fix potential deadlock HID: input: do not report stylus battery state as "full" PCI: aardvark: Fix masking and unmasking legacy INTx interrupts PCI: aardvark: Increase polling delay to 1.5s while waiting for PIO response PCI: aardvark: Fix checking for PIO status PCI: xilinx-nwl: Enable the clock through CCF PCI: Return ~0 data on pciconfig_read() CAP_SYS_ADMIN failure PCI: Restrict ASMedia ASM1062 SATA Max Payload Size Supported PCI/portdrv: Enable Bandwidth Notification only if port supports it ARM: 9105/1: atags_to_fdt: don't warn about stack size libata: add ATA_HORKAGE_NO_NCQ_TRIM for Samsung 860 and 870 SSDs dmaengine: imx-sdma: remove duplicated sdma_load_context Revert "dmaengine: imx-sdma: refine to load context only once" media: rc-loopback: return number of emitters rather than error media: uvc: don't do DMA on stack VMCI: fix NULL pointer dereference when unmapping queue pair dm crypt: Avoid percpu_counter spinlock contention in crypt_page_alloc() power: supply: max17042: handle fails of reading status register block: bfq: fix bfq_set_next_ioprio_data() crypto: public_key: fix overflow during implicit conversion arm64: head: avoid over-mapping in map_memory soc: aspeed: p2a-ctrl: Fix boundary check for mmap soc: aspeed: lpc-ctrl: Fix boundary check for mmap soc: qcom: aoss: Fix the out of bound usage of cooling_devs pinctrl: ingenic: Fix incorrect pull up/down info pinctrl: stmfx: Fix hazardous u8[] to unsigned long cast tools/thermal/tmon: Add cross compiling support 9p/xen: Fix end of loop tests for list_for_each_entry include/linux/list.h: add a macro to test if entry is pointing to the head xen: fix setting of max_pfn in shared_info powerpc/perf/hv-gpci: Fix counter value parsing PCI/MSI: Skip masking MSI-X on Xen PV blk-zoned: allow BLKREPORTZONE without CAP_SYS_ADMIN blk-zoned: allow zone management send operations without CAP_SYS_ADMIN btrfs: reset replace target device to allocation state on close btrfs: wake up async_delalloc_pages waiters after submit rtc: tps65910: Correct driver module alias Conflicts: Documentation/devicetree/bindings Documentation/devicetree/bindings/arm/tegra.yaml Documentation/devicetree/bindings/mtd/gpmc-nand.txt Documentation/devicetree/bindings/regulator/samsung,s5m8767.txt kernel/sched/cpufreq_schedutil.c Change-Id: Id17c4366cdc6854cd23fba0f41d335b09fc6100e Signed-off-by: Srinivasarao Pathipati <quic_spathi@quicinc.com>
1281 lines
32 KiB
C
1281 lines
32 KiB
C
// SPDX-License-Identifier: GPL-2.0-only
|
|
/*
|
|
* Copyright 2002-2004, Instant802 Networks, Inc.
|
|
* Copyright 2008, Jouni Malinen <j@w1.fi>
|
|
* Copyright (C) 2016-2017 Intel Deutschland GmbH
|
|
* Copyright (C) 2020-2021 Intel Corporation
|
|
*/
|
|
|
|
#include <linux/netdevice.h>
|
|
#include <linux/types.h>
|
|
#include <linux/skbuff.h>
|
|
#include <linux/compiler.h>
|
|
#include <linux/ieee80211.h>
|
|
#include <linux/gfp.h>
|
|
#include <asm/unaligned.h>
|
|
#include <net/mac80211.h>
|
|
#include <crypto/aes.h>
|
|
#include <crypto/algapi.h>
|
|
|
|
#include "ieee80211_i.h"
|
|
#include "michael.h"
|
|
#include "tkip.h"
|
|
#include "aes_ccm.h"
|
|
#include "aes_cmac.h"
|
|
#include "aes_gmac.h"
|
|
#include "aes_gcm.h"
|
|
#include "wpa.h"
|
|
|
|
ieee80211_tx_result
|
|
ieee80211_tx_h_michael_mic_add(struct ieee80211_tx_data *tx)
|
|
{
|
|
u8 *data, *key, *mic;
|
|
size_t data_len;
|
|
unsigned int hdrlen;
|
|
struct ieee80211_hdr *hdr;
|
|
struct sk_buff *skb = tx->skb;
|
|
struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb);
|
|
int tail;
|
|
|
|
hdr = (struct ieee80211_hdr *)skb->data;
|
|
if (!tx->key || tx->key->conf.cipher != WLAN_CIPHER_SUITE_TKIP ||
|
|
skb->len < 24 || !ieee80211_is_data_present(hdr->frame_control))
|
|
return TX_CONTINUE;
|
|
|
|
hdrlen = ieee80211_hdrlen(hdr->frame_control);
|
|
if (skb->len < hdrlen)
|
|
return TX_DROP;
|
|
|
|
data = skb->data + hdrlen;
|
|
data_len = skb->len - hdrlen;
|
|
|
|
if (unlikely(info->flags & IEEE80211_TX_INTFL_TKIP_MIC_FAILURE)) {
|
|
/* Need to use software crypto for the test */
|
|
info->control.hw_key = NULL;
|
|
}
|
|
|
|
if (info->control.hw_key &&
|
|
(info->flags & IEEE80211_TX_CTL_DONTFRAG ||
|
|
ieee80211_hw_check(&tx->local->hw, SUPPORTS_TX_FRAG)) &&
|
|
!(tx->key->conf.flags & (IEEE80211_KEY_FLAG_GENERATE_MMIC |
|
|
IEEE80211_KEY_FLAG_PUT_MIC_SPACE))) {
|
|
/* hwaccel - with no need for SW-generated MMIC or MIC space */
|
|
return TX_CONTINUE;
|
|
}
|
|
|
|
tail = MICHAEL_MIC_LEN;
|
|
if (!info->control.hw_key)
|
|
tail += IEEE80211_TKIP_ICV_LEN;
|
|
|
|
if (WARN(skb_tailroom(skb) < tail ||
|
|
skb_headroom(skb) < IEEE80211_TKIP_IV_LEN,
|
|
"mmic: not enough head/tail (%d/%d,%d/%d)\n",
|
|
skb_headroom(skb), IEEE80211_TKIP_IV_LEN,
|
|
skb_tailroom(skb), tail))
|
|
return TX_DROP;
|
|
|
|
mic = skb_put(skb, MICHAEL_MIC_LEN);
|
|
|
|
if (tx->key->conf.flags & IEEE80211_KEY_FLAG_PUT_MIC_SPACE) {
|
|
/* Zeroed MIC can help with debug */
|
|
memset(mic, 0, MICHAEL_MIC_LEN);
|
|
return TX_CONTINUE;
|
|
}
|
|
|
|
key = &tx->key->conf.key[NL80211_TKIP_DATA_OFFSET_TX_MIC_KEY];
|
|
michael_mic(key, hdr, data, data_len, mic);
|
|
if (unlikely(info->flags & IEEE80211_TX_INTFL_TKIP_MIC_FAILURE))
|
|
mic[0]++;
|
|
|
|
return TX_CONTINUE;
|
|
}
|
|
|
|
|
|
ieee80211_rx_result
|
|
ieee80211_rx_h_michael_mic_verify(struct ieee80211_rx_data *rx)
|
|
{
|
|
u8 *data, *key = NULL;
|
|
size_t data_len;
|
|
unsigned int hdrlen;
|
|
u8 mic[MICHAEL_MIC_LEN];
|
|
struct sk_buff *skb = rx->skb;
|
|
struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
|
|
|
|
/*
|
|
* it makes no sense to check for MIC errors on anything other
|
|
* than data frames.
|
|
*/
|
|
if (!ieee80211_is_data_present(hdr->frame_control))
|
|
return RX_CONTINUE;
|
|
|
|
/*
|
|
* No way to verify the MIC if the hardware stripped it or
|
|
* the IV with the key index. In this case we have solely rely
|
|
* on the driver to set RX_FLAG_MMIC_ERROR in the event of a
|
|
* MIC failure report.
|
|
*/
|
|
if (status->flag & (RX_FLAG_MMIC_STRIPPED | RX_FLAG_IV_STRIPPED)) {
|
|
if (status->flag & RX_FLAG_MMIC_ERROR)
|
|
goto mic_fail_no_key;
|
|
|
|
if (!(status->flag & RX_FLAG_IV_STRIPPED) && rx->key &&
|
|
rx->key->conf.cipher == WLAN_CIPHER_SUITE_TKIP)
|
|
goto update_iv;
|
|
|
|
return RX_CONTINUE;
|
|
}
|
|
|
|
/*
|
|
* Some hardware seems to generate Michael MIC failure reports; even
|
|
* though, the frame was not encrypted with TKIP and therefore has no
|
|
* MIC. Ignore the flag them to avoid triggering countermeasures.
|
|
*/
|
|
if (!rx->key || rx->key->conf.cipher != WLAN_CIPHER_SUITE_TKIP ||
|
|
!(status->flag & RX_FLAG_DECRYPTED))
|
|
return RX_CONTINUE;
|
|
|
|
if (rx->sdata->vif.type == NL80211_IFTYPE_AP && rx->key->conf.keyidx) {
|
|
/*
|
|
* APs with pairwise keys should never receive Michael MIC
|
|
* errors for non-zero keyidx because these are reserved for
|
|
* group keys and only the AP is sending real multicast
|
|
* frames in the BSS.
|
|
*/
|
|
return RX_DROP_UNUSABLE;
|
|
}
|
|
|
|
if (status->flag & RX_FLAG_MMIC_ERROR)
|
|
goto mic_fail;
|
|
|
|
hdrlen = ieee80211_hdrlen(hdr->frame_control);
|
|
if (skb->len < hdrlen + MICHAEL_MIC_LEN)
|
|
return RX_DROP_UNUSABLE;
|
|
|
|
if (skb_linearize(rx->skb))
|
|
return RX_DROP_UNUSABLE;
|
|
hdr = (void *)skb->data;
|
|
|
|
data = skb->data + hdrlen;
|
|
data_len = skb->len - hdrlen - MICHAEL_MIC_LEN;
|
|
key = &rx->key->conf.key[NL80211_TKIP_DATA_OFFSET_RX_MIC_KEY];
|
|
michael_mic(key, hdr, data, data_len, mic);
|
|
if (crypto_memneq(mic, data + data_len, MICHAEL_MIC_LEN))
|
|
goto mic_fail;
|
|
|
|
/* remove Michael MIC from payload */
|
|
skb_trim(skb, skb->len - MICHAEL_MIC_LEN);
|
|
|
|
update_iv:
|
|
/* update IV in key information to be able to detect replays */
|
|
rx->key->u.tkip.rx[rx->security_idx].iv32 = rx->tkip.iv32;
|
|
rx->key->u.tkip.rx[rx->security_idx].iv16 = rx->tkip.iv16;
|
|
|
|
return RX_CONTINUE;
|
|
|
|
mic_fail:
|
|
rx->key->u.tkip.mic_failures++;
|
|
|
|
mic_fail_no_key:
|
|
/*
|
|
* In some cases the key can be unset - e.g. a multicast packet, in
|
|
* a driver that supports HW encryption. Send up the key idx only if
|
|
* the key is set.
|
|
*/
|
|
cfg80211_michael_mic_failure(rx->sdata->dev, hdr->addr2,
|
|
is_multicast_ether_addr(hdr->addr1) ?
|
|
NL80211_KEYTYPE_GROUP :
|
|
NL80211_KEYTYPE_PAIRWISE,
|
|
rx->key ? rx->key->conf.keyidx : -1,
|
|
NULL, GFP_ATOMIC);
|
|
return RX_DROP_UNUSABLE;
|
|
}
|
|
|
|
static int tkip_encrypt_skb(struct ieee80211_tx_data *tx, struct sk_buff *skb)
|
|
{
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *) skb->data;
|
|
struct ieee80211_key *key = tx->key;
|
|
struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb);
|
|
unsigned int hdrlen;
|
|
int len, tail;
|
|
u64 pn;
|
|
u8 *pos;
|
|
|
|
if (info->control.hw_key &&
|
|
!(info->control.hw_key->flags & IEEE80211_KEY_FLAG_GENERATE_IV) &&
|
|
!(info->control.hw_key->flags & IEEE80211_KEY_FLAG_PUT_IV_SPACE)) {
|
|
/* hwaccel - with no need for software-generated IV */
|
|
return 0;
|
|
}
|
|
|
|
hdrlen = ieee80211_hdrlen(hdr->frame_control);
|
|
len = skb->len - hdrlen;
|
|
|
|
if (info->control.hw_key)
|
|
tail = 0;
|
|
else
|
|
tail = IEEE80211_TKIP_ICV_LEN;
|
|
|
|
if (WARN_ON(skb_tailroom(skb) < tail ||
|
|
skb_headroom(skb) < IEEE80211_TKIP_IV_LEN))
|
|
return -1;
|
|
|
|
pos = skb_push(skb, IEEE80211_TKIP_IV_LEN);
|
|
memmove(pos, pos + IEEE80211_TKIP_IV_LEN, hdrlen);
|
|
pos += hdrlen;
|
|
|
|
/* the HW only needs room for the IV, but not the actual IV */
|
|
if (info->control.hw_key &&
|
|
(info->control.hw_key->flags & IEEE80211_KEY_FLAG_PUT_IV_SPACE))
|
|
return 0;
|
|
|
|
/* Increase IV for the frame */
|
|
pn = atomic64_inc_return(&key->conf.tx_pn);
|
|
pos = ieee80211_tkip_add_iv(pos, &key->conf, pn);
|
|
|
|
/* hwaccel - with software IV */
|
|
if (info->control.hw_key)
|
|
return 0;
|
|
|
|
/* Add room for ICV */
|
|
skb_put(skb, IEEE80211_TKIP_ICV_LEN);
|
|
|
|
return ieee80211_tkip_encrypt_data(&tx->local->wep_tx_ctx,
|
|
key, skb, pos, len);
|
|
}
|
|
|
|
|
|
ieee80211_tx_result
|
|
ieee80211_crypto_tkip_encrypt(struct ieee80211_tx_data *tx)
|
|
{
|
|
struct sk_buff *skb;
|
|
|
|
ieee80211_tx_set_protected(tx);
|
|
|
|
skb_queue_walk(&tx->skbs, skb) {
|
|
if (tkip_encrypt_skb(tx, skb) < 0)
|
|
return TX_DROP;
|
|
}
|
|
|
|
return TX_CONTINUE;
|
|
}
|
|
|
|
|
|
ieee80211_rx_result
|
|
ieee80211_crypto_tkip_decrypt(struct ieee80211_rx_data *rx)
|
|
{
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *) rx->skb->data;
|
|
int hdrlen, res, hwaccel = 0;
|
|
struct ieee80211_key *key = rx->key;
|
|
struct sk_buff *skb = rx->skb;
|
|
struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
|
|
|
|
hdrlen = ieee80211_hdrlen(hdr->frame_control);
|
|
|
|
if (!ieee80211_is_data(hdr->frame_control))
|
|
return RX_CONTINUE;
|
|
|
|
if (!rx->sta || skb->len - hdrlen < 12)
|
|
return RX_DROP_UNUSABLE;
|
|
|
|
/* it may be possible to optimize this a bit more */
|
|
if (skb_linearize(rx->skb))
|
|
return RX_DROP_UNUSABLE;
|
|
hdr = (void *)skb->data;
|
|
|
|
/*
|
|
* Let TKIP code verify IV, but skip decryption.
|
|
* In the case where hardware checks the IV as well,
|
|
* we don't even get here, see ieee80211_rx_h_decrypt()
|
|
*/
|
|
if (status->flag & RX_FLAG_DECRYPTED)
|
|
hwaccel = 1;
|
|
|
|
res = ieee80211_tkip_decrypt_data(&rx->local->wep_rx_ctx,
|
|
key, skb->data + hdrlen,
|
|
skb->len - hdrlen, rx->sta->sta.addr,
|
|
hdr->addr1, hwaccel, rx->security_idx,
|
|
&rx->tkip.iv32,
|
|
&rx->tkip.iv16);
|
|
if (res != TKIP_DECRYPT_OK)
|
|
return RX_DROP_UNUSABLE;
|
|
|
|
/* Trim ICV */
|
|
if (!(status->flag & RX_FLAG_ICV_STRIPPED))
|
|
skb_trim(skb, skb->len - IEEE80211_TKIP_ICV_LEN);
|
|
|
|
/* Remove IV */
|
|
memmove(skb->data + IEEE80211_TKIP_IV_LEN, skb->data, hdrlen);
|
|
skb_pull(skb, IEEE80211_TKIP_IV_LEN);
|
|
|
|
return RX_CONTINUE;
|
|
}
|
|
|
|
|
|
static void ccmp_special_blocks(struct sk_buff *skb, u8 *pn, u8 *b_0, u8 *aad)
|
|
{
|
|
__le16 mask_fc;
|
|
int a4_included, mgmt;
|
|
u8 qos_tid;
|
|
u16 len_a;
|
|
unsigned int hdrlen;
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
|
|
|
|
/*
|
|
* Mask FC: zero subtype b4 b5 b6 (if not mgmt)
|
|
* Retry, PwrMgt, MoreData; set Protected
|
|
*/
|
|
mgmt = ieee80211_is_mgmt(hdr->frame_control);
|
|
mask_fc = hdr->frame_control;
|
|
mask_fc &= ~cpu_to_le16(IEEE80211_FCTL_RETRY |
|
|
IEEE80211_FCTL_PM | IEEE80211_FCTL_MOREDATA);
|
|
if (!mgmt)
|
|
mask_fc &= ~cpu_to_le16(0x0070);
|
|
mask_fc |= cpu_to_le16(IEEE80211_FCTL_PROTECTED);
|
|
|
|
hdrlen = ieee80211_hdrlen(hdr->frame_control);
|
|
len_a = hdrlen - 2;
|
|
a4_included = ieee80211_has_a4(hdr->frame_control);
|
|
|
|
if (ieee80211_is_data_qos(hdr->frame_control))
|
|
qos_tid = ieee80211_get_tid(hdr);
|
|
else
|
|
qos_tid = 0;
|
|
|
|
/* In CCM, the initial vectors (IV) used for CTR mode encryption and CBC
|
|
* mode authentication are not allowed to collide, yet both are derived
|
|
* from this vector b_0. We only set L := 1 here to indicate that the
|
|
* data size can be represented in (L+1) bytes. The CCM layer will take
|
|
* care of storing the data length in the top (L+1) bytes and setting
|
|
* and clearing the other bits as is required to derive the two IVs.
|
|
*/
|
|
b_0[0] = 0x1;
|
|
|
|
/* Nonce: Nonce Flags | A2 | PN
|
|
* Nonce Flags: Priority (b0..b3) | Management (b4) | Reserved (b5..b7)
|
|
*/
|
|
b_0[1] = qos_tid | (mgmt << 4);
|
|
memcpy(&b_0[2], hdr->addr2, ETH_ALEN);
|
|
memcpy(&b_0[8], pn, IEEE80211_CCMP_PN_LEN);
|
|
|
|
/* AAD (extra authenticate-only data) / masked 802.11 header
|
|
* FC | A1 | A2 | A3 | SC | [A4] | [QC] */
|
|
put_unaligned_be16(len_a, &aad[0]);
|
|
put_unaligned(mask_fc, (__le16 *)&aad[2]);
|
|
memcpy(&aad[4], &hdr->addr1, 3 * ETH_ALEN);
|
|
|
|
/* Mask Seq#, leave Frag# */
|
|
aad[22] = *((u8 *) &hdr->seq_ctrl) & 0x0f;
|
|
aad[23] = 0;
|
|
|
|
if (a4_included) {
|
|
memcpy(&aad[24], hdr->addr4, ETH_ALEN);
|
|
aad[30] = qos_tid;
|
|
aad[31] = 0;
|
|
} else {
|
|
memset(&aad[24], 0, ETH_ALEN + IEEE80211_QOS_CTL_LEN);
|
|
aad[24] = qos_tid;
|
|
}
|
|
}
|
|
|
|
|
|
static inline void ccmp_pn2hdr(u8 *hdr, u8 *pn, int key_id)
|
|
{
|
|
hdr[0] = pn[5];
|
|
hdr[1] = pn[4];
|
|
hdr[2] = 0;
|
|
hdr[3] = 0x20 | (key_id << 6);
|
|
hdr[4] = pn[3];
|
|
hdr[5] = pn[2];
|
|
hdr[6] = pn[1];
|
|
hdr[7] = pn[0];
|
|
}
|
|
|
|
|
|
static inline void ccmp_hdr2pn(u8 *pn, u8 *hdr)
|
|
{
|
|
pn[0] = hdr[7];
|
|
pn[1] = hdr[6];
|
|
pn[2] = hdr[5];
|
|
pn[3] = hdr[4];
|
|
pn[4] = hdr[1];
|
|
pn[5] = hdr[0];
|
|
}
|
|
|
|
|
|
static int ccmp_encrypt_skb(struct ieee80211_tx_data *tx, struct sk_buff *skb,
|
|
unsigned int mic_len)
|
|
{
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *) skb->data;
|
|
struct ieee80211_key *key = tx->key;
|
|
struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb);
|
|
int hdrlen, len, tail;
|
|
u8 *pos;
|
|
u8 pn[6];
|
|
u64 pn64;
|
|
u8 aad[CCM_AAD_LEN];
|
|
u8 b_0[AES_BLOCK_SIZE];
|
|
|
|
if (info->control.hw_key &&
|
|
!(info->control.hw_key->flags & IEEE80211_KEY_FLAG_GENERATE_IV) &&
|
|
!(info->control.hw_key->flags & IEEE80211_KEY_FLAG_PUT_IV_SPACE) &&
|
|
!((info->control.hw_key->flags &
|
|
IEEE80211_KEY_FLAG_GENERATE_IV_MGMT) &&
|
|
ieee80211_is_mgmt(hdr->frame_control))) {
|
|
/*
|
|
* hwaccel has no need for preallocated room for CCMP
|
|
* header or MIC fields
|
|
*/
|
|
return 0;
|
|
}
|
|
|
|
hdrlen = ieee80211_hdrlen(hdr->frame_control);
|
|
len = skb->len - hdrlen;
|
|
|
|
if (info->control.hw_key)
|
|
tail = 0;
|
|
else
|
|
tail = mic_len;
|
|
|
|
if (WARN_ON(skb_tailroom(skb) < tail ||
|
|
skb_headroom(skb) < IEEE80211_CCMP_HDR_LEN))
|
|
return -1;
|
|
|
|
pos = skb_push(skb, IEEE80211_CCMP_HDR_LEN);
|
|
memmove(pos, pos + IEEE80211_CCMP_HDR_LEN, hdrlen);
|
|
|
|
/* the HW only needs room for the IV, but not the actual IV */
|
|
if (info->control.hw_key &&
|
|
(info->control.hw_key->flags & IEEE80211_KEY_FLAG_PUT_IV_SPACE))
|
|
return 0;
|
|
|
|
hdr = (struct ieee80211_hdr *) pos;
|
|
pos += hdrlen;
|
|
|
|
pn64 = atomic64_inc_return(&key->conf.tx_pn);
|
|
|
|
pn[5] = pn64;
|
|
pn[4] = pn64 >> 8;
|
|
pn[3] = pn64 >> 16;
|
|
pn[2] = pn64 >> 24;
|
|
pn[1] = pn64 >> 32;
|
|
pn[0] = pn64 >> 40;
|
|
|
|
ccmp_pn2hdr(pos, pn, key->conf.keyidx);
|
|
|
|
/* hwaccel - with software CCMP header */
|
|
if (info->control.hw_key)
|
|
return 0;
|
|
|
|
pos += IEEE80211_CCMP_HDR_LEN;
|
|
ccmp_special_blocks(skb, pn, b_0, aad);
|
|
return ieee80211_aes_ccm_encrypt(key->u.ccmp.tfm, b_0, aad, pos, len,
|
|
skb_put(skb, mic_len));
|
|
}
|
|
|
|
|
|
ieee80211_tx_result
|
|
ieee80211_crypto_ccmp_encrypt(struct ieee80211_tx_data *tx,
|
|
unsigned int mic_len)
|
|
{
|
|
struct sk_buff *skb;
|
|
|
|
ieee80211_tx_set_protected(tx);
|
|
|
|
skb_queue_walk(&tx->skbs, skb) {
|
|
if (ccmp_encrypt_skb(tx, skb, mic_len) < 0)
|
|
return TX_DROP;
|
|
}
|
|
|
|
return TX_CONTINUE;
|
|
}
|
|
|
|
|
|
ieee80211_rx_result
|
|
ieee80211_crypto_ccmp_decrypt(struct ieee80211_rx_data *rx,
|
|
unsigned int mic_len)
|
|
{
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)rx->skb->data;
|
|
int hdrlen;
|
|
struct ieee80211_key *key = rx->key;
|
|
struct sk_buff *skb = rx->skb;
|
|
struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
|
|
u8 pn[IEEE80211_CCMP_PN_LEN];
|
|
int data_len;
|
|
int queue;
|
|
|
|
hdrlen = ieee80211_hdrlen(hdr->frame_control);
|
|
|
|
if (!ieee80211_is_data(hdr->frame_control) &&
|
|
!ieee80211_is_robust_mgmt_frame(skb))
|
|
return RX_CONTINUE;
|
|
|
|
if (status->flag & RX_FLAG_DECRYPTED) {
|
|
if (!pskb_may_pull(rx->skb, hdrlen + IEEE80211_CCMP_HDR_LEN))
|
|
return RX_DROP_UNUSABLE;
|
|
if (status->flag & RX_FLAG_MIC_STRIPPED)
|
|
mic_len = 0;
|
|
} else {
|
|
if (skb_linearize(rx->skb))
|
|
return RX_DROP_UNUSABLE;
|
|
}
|
|
|
|
/* reload hdr - skb might have been reallocated */
|
|
hdr = (void *)rx->skb->data;
|
|
|
|
data_len = skb->len - hdrlen - IEEE80211_CCMP_HDR_LEN - mic_len;
|
|
if (!rx->sta || data_len < 0)
|
|
return RX_DROP_UNUSABLE;
|
|
|
|
if (!(status->flag & RX_FLAG_PN_VALIDATED)) {
|
|
int res;
|
|
|
|
ccmp_hdr2pn(pn, skb->data + hdrlen);
|
|
|
|
queue = rx->security_idx;
|
|
|
|
res = memcmp(pn, key->u.ccmp.rx_pn[queue],
|
|
IEEE80211_CCMP_PN_LEN);
|
|
if (res < 0 ||
|
|
(!res && !(status->flag & RX_FLAG_ALLOW_SAME_PN))) {
|
|
key->u.ccmp.replays++;
|
|
return RX_DROP_UNUSABLE;
|
|
}
|
|
|
|
if (!(status->flag & RX_FLAG_DECRYPTED)) {
|
|
u8 aad[2 * AES_BLOCK_SIZE];
|
|
u8 b_0[AES_BLOCK_SIZE];
|
|
/* hardware didn't decrypt/verify MIC */
|
|
ccmp_special_blocks(skb, pn, b_0, aad);
|
|
|
|
if (ieee80211_aes_ccm_decrypt(
|
|
key->u.ccmp.tfm, b_0, aad,
|
|
skb->data + hdrlen + IEEE80211_CCMP_HDR_LEN,
|
|
data_len,
|
|
skb->data + skb->len - mic_len))
|
|
return RX_DROP_UNUSABLE;
|
|
}
|
|
|
|
memcpy(key->u.ccmp.rx_pn[queue], pn, IEEE80211_CCMP_PN_LEN);
|
|
if (unlikely(ieee80211_is_frag(hdr)))
|
|
memcpy(rx->ccm_gcm.pn, pn, IEEE80211_CCMP_PN_LEN);
|
|
}
|
|
|
|
/* Remove CCMP header and MIC */
|
|
if (pskb_trim(skb, skb->len - mic_len))
|
|
return RX_DROP_UNUSABLE;
|
|
memmove(skb->data + IEEE80211_CCMP_HDR_LEN, skb->data, hdrlen);
|
|
skb_pull(skb, IEEE80211_CCMP_HDR_LEN);
|
|
|
|
return RX_CONTINUE;
|
|
}
|
|
|
|
static void gcmp_special_blocks(struct sk_buff *skb, u8 *pn, u8 *j_0, u8 *aad)
|
|
{
|
|
__le16 mask_fc;
|
|
u8 qos_tid;
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
|
|
|
|
memcpy(j_0, hdr->addr2, ETH_ALEN);
|
|
memcpy(&j_0[ETH_ALEN], pn, IEEE80211_GCMP_PN_LEN);
|
|
j_0[13] = 0;
|
|
j_0[14] = 0;
|
|
j_0[AES_BLOCK_SIZE - 1] = 0x01;
|
|
|
|
/* AAD (extra authenticate-only data) / masked 802.11 header
|
|
* FC | A1 | A2 | A3 | SC | [A4] | [QC]
|
|
*/
|
|
put_unaligned_be16(ieee80211_hdrlen(hdr->frame_control) - 2, &aad[0]);
|
|
/* Mask FC: zero subtype b4 b5 b6 (if not mgmt)
|
|
* Retry, PwrMgt, MoreData; set Protected
|
|
*/
|
|
mask_fc = hdr->frame_control;
|
|
mask_fc &= ~cpu_to_le16(IEEE80211_FCTL_RETRY |
|
|
IEEE80211_FCTL_PM | IEEE80211_FCTL_MOREDATA);
|
|
if (!ieee80211_is_mgmt(hdr->frame_control))
|
|
mask_fc &= ~cpu_to_le16(0x0070);
|
|
mask_fc |= cpu_to_le16(IEEE80211_FCTL_PROTECTED);
|
|
|
|
put_unaligned(mask_fc, (__le16 *)&aad[2]);
|
|
memcpy(&aad[4], &hdr->addr1, 3 * ETH_ALEN);
|
|
|
|
/* Mask Seq#, leave Frag# */
|
|
aad[22] = *((u8 *)&hdr->seq_ctrl) & 0x0f;
|
|
aad[23] = 0;
|
|
|
|
if (ieee80211_is_data_qos(hdr->frame_control))
|
|
qos_tid = ieee80211_get_tid(hdr);
|
|
else
|
|
qos_tid = 0;
|
|
|
|
if (ieee80211_has_a4(hdr->frame_control)) {
|
|
memcpy(&aad[24], hdr->addr4, ETH_ALEN);
|
|
aad[30] = qos_tid;
|
|
aad[31] = 0;
|
|
} else {
|
|
memset(&aad[24], 0, ETH_ALEN + IEEE80211_QOS_CTL_LEN);
|
|
aad[24] = qos_tid;
|
|
}
|
|
}
|
|
|
|
static inline void gcmp_pn2hdr(u8 *hdr, const u8 *pn, int key_id)
|
|
{
|
|
hdr[0] = pn[5];
|
|
hdr[1] = pn[4];
|
|
hdr[2] = 0;
|
|
hdr[3] = 0x20 | (key_id << 6);
|
|
hdr[4] = pn[3];
|
|
hdr[5] = pn[2];
|
|
hdr[6] = pn[1];
|
|
hdr[7] = pn[0];
|
|
}
|
|
|
|
static inline void gcmp_hdr2pn(u8 *pn, const u8 *hdr)
|
|
{
|
|
pn[0] = hdr[7];
|
|
pn[1] = hdr[6];
|
|
pn[2] = hdr[5];
|
|
pn[3] = hdr[4];
|
|
pn[4] = hdr[1];
|
|
pn[5] = hdr[0];
|
|
}
|
|
|
|
static int gcmp_encrypt_skb(struct ieee80211_tx_data *tx, struct sk_buff *skb)
|
|
{
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
|
|
struct ieee80211_key *key = tx->key;
|
|
struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb);
|
|
int hdrlen, len, tail;
|
|
u8 *pos;
|
|
u8 pn[6];
|
|
u64 pn64;
|
|
u8 aad[GCM_AAD_LEN];
|
|
u8 j_0[AES_BLOCK_SIZE];
|
|
|
|
if (info->control.hw_key &&
|
|
!(info->control.hw_key->flags & IEEE80211_KEY_FLAG_GENERATE_IV) &&
|
|
!(info->control.hw_key->flags & IEEE80211_KEY_FLAG_PUT_IV_SPACE) &&
|
|
!((info->control.hw_key->flags &
|
|
IEEE80211_KEY_FLAG_GENERATE_IV_MGMT) &&
|
|
ieee80211_is_mgmt(hdr->frame_control))) {
|
|
/* hwaccel has no need for preallocated room for GCMP
|
|
* header or MIC fields
|
|
*/
|
|
return 0;
|
|
}
|
|
|
|
hdrlen = ieee80211_hdrlen(hdr->frame_control);
|
|
len = skb->len - hdrlen;
|
|
|
|
if (info->control.hw_key)
|
|
tail = 0;
|
|
else
|
|
tail = IEEE80211_GCMP_MIC_LEN;
|
|
|
|
if (WARN_ON(skb_tailroom(skb) < tail ||
|
|
skb_headroom(skb) < IEEE80211_GCMP_HDR_LEN))
|
|
return -1;
|
|
|
|
pos = skb_push(skb, IEEE80211_GCMP_HDR_LEN);
|
|
memmove(pos, pos + IEEE80211_GCMP_HDR_LEN, hdrlen);
|
|
skb_set_network_header(skb, skb_network_offset(skb) +
|
|
IEEE80211_GCMP_HDR_LEN);
|
|
|
|
/* the HW only needs room for the IV, but not the actual IV */
|
|
if (info->control.hw_key &&
|
|
(info->control.hw_key->flags & IEEE80211_KEY_FLAG_PUT_IV_SPACE))
|
|
return 0;
|
|
|
|
hdr = (struct ieee80211_hdr *)pos;
|
|
pos += hdrlen;
|
|
|
|
pn64 = atomic64_inc_return(&key->conf.tx_pn);
|
|
|
|
pn[5] = pn64;
|
|
pn[4] = pn64 >> 8;
|
|
pn[3] = pn64 >> 16;
|
|
pn[2] = pn64 >> 24;
|
|
pn[1] = pn64 >> 32;
|
|
pn[0] = pn64 >> 40;
|
|
|
|
gcmp_pn2hdr(pos, pn, key->conf.keyidx);
|
|
|
|
/* hwaccel - with software GCMP header */
|
|
if (info->control.hw_key)
|
|
return 0;
|
|
|
|
pos += IEEE80211_GCMP_HDR_LEN;
|
|
gcmp_special_blocks(skb, pn, j_0, aad);
|
|
return ieee80211_aes_gcm_encrypt(key->u.gcmp.tfm, j_0, aad, pos, len,
|
|
skb_put(skb, IEEE80211_GCMP_MIC_LEN));
|
|
}
|
|
|
|
ieee80211_tx_result
|
|
ieee80211_crypto_gcmp_encrypt(struct ieee80211_tx_data *tx)
|
|
{
|
|
struct sk_buff *skb;
|
|
|
|
ieee80211_tx_set_protected(tx);
|
|
|
|
skb_queue_walk(&tx->skbs, skb) {
|
|
if (gcmp_encrypt_skb(tx, skb) < 0)
|
|
return TX_DROP;
|
|
}
|
|
|
|
return TX_CONTINUE;
|
|
}
|
|
|
|
ieee80211_rx_result
|
|
ieee80211_crypto_gcmp_decrypt(struct ieee80211_rx_data *rx)
|
|
{
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)rx->skb->data;
|
|
int hdrlen;
|
|
struct ieee80211_key *key = rx->key;
|
|
struct sk_buff *skb = rx->skb;
|
|
struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
|
|
u8 pn[IEEE80211_GCMP_PN_LEN];
|
|
int data_len, queue, mic_len = IEEE80211_GCMP_MIC_LEN;
|
|
|
|
hdrlen = ieee80211_hdrlen(hdr->frame_control);
|
|
|
|
if (!ieee80211_is_data(hdr->frame_control) &&
|
|
!ieee80211_is_robust_mgmt_frame(skb))
|
|
return RX_CONTINUE;
|
|
|
|
if (status->flag & RX_FLAG_DECRYPTED) {
|
|
if (!pskb_may_pull(rx->skb, hdrlen + IEEE80211_GCMP_HDR_LEN))
|
|
return RX_DROP_UNUSABLE;
|
|
if (status->flag & RX_FLAG_MIC_STRIPPED)
|
|
mic_len = 0;
|
|
} else {
|
|
if (skb_linearize(rx->skb))
|
|
return RX_DROP_UNUSABLE;
|
|
}
|
|
|
|
/* reload hdr - skb might have been reallocated */
|
|
hdr = (void *)rx->skb->data;
|
|
|
|
data_len = skb->len - hdrlen - IEEE80211_GCMP_HDR_LEN - mic_len;
|
|
if (!rx->sta || data_len < 0)
|
|
return RX_DROP_UNUSABLE;
|
|
|
|
if (!(status->flag & RX_FLAG_PN_VALIDATED)) {
|
|
int res;
|
|
|
|
gcmp_hdr2pn(pn, skb->data + hdrlen);
|
|
|
|
queue = rx->security_idx;
|
|
|
|
res = memcmp(pn, key->u.gcmp.rx_pn[queue],
|
|
IEEE80211_GCMP_PN_LEN);
|
|
if (res < 0 ||
|
|
(!res && !(status->flag & RX_FLAG_ALLOW_SAME_PN))) {
|
|
key->u.gcmp.replays++;
|
|
return RX_DROP_UNUSABLE;
|
|
}
|
|
|
|
if (!(status->flag & RX_FLAG_DECRYPTED)) {
|
|
u8 aad[2 * AES_BLOCK_SIZE];
|
|
u8 j_0[AES_BLOCK_SIZE];
|
|
/* hardware didn't decrypt/verify MIC */
|
|
gcmp_special_blocks(skb, pn, j_0, aad);
|
|
|
|
if (ieee80211_aes_gcm_decrypt(
|
|
key->u.gcmp.tfm, j_0, aad,
|
|
skb->data + hdrlen + IEEE80211_GCMP_HDR_LEN,
|
|
data_len,
|
|
skb->data + skb->len -
|
|
IEEE80211_GCMP_MIC_LEN))
|
|
return RX_DROP_UNUSABLE;
|
|
}
|
|
|
|
memcpy(key->u.gcmp.rx_pn[queue], pn, IEEE80211_GCMP_PN_LEN);
|
|
if (unlikely(ieee80211_is_frag(hdr)))
|
|
memcpy(rx->ccm_gcm.pn, pn, IEEE80211_CCMP_PN_LEN);
|
|
}
|
|
|
|
/* Remove GCMP header and MIC */
|
|
if (pskb_trim(skb, skb->len - mic_len))
|
|
return RX_DROP_UNUSABLE;
|
|
memmove(skb->data + IEEE80211_GCMP_HDR_LEN, skb->data, hdrlen);
|
|
skb_pull(skb, IEEE80211_GCMP_HDR_LEN);
|
|
|
|
return RX_CONTINUE;
|
|
}
|
|
|
|
static ieee80211_tx_result
|
|
ieee80211_crypto_cs_encrypt(struct ieee80211_tx_data *tx,
|
|
struct sk_buff *skb)
|
|
{
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
|
|
struct ieee80211_key *key = tx->key;
|
|
struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb);
|
|
int hdrlen;
|
|
u8 *pos, iv_len = key->conf.iv_len;
|
|
|
|
if (info->control.hw_key &&
|
|
!(info->control.hw_key->flags & IEEE80211_KEY_FLAG_PUT_IV_SPACE)) {
|
|
/* hwaccel has no need for preallocated head room */
|
|
return TX_CONTINUE;
|
|
}
|
|
|
|
if (unlikely(skb_headroom(skb) < iv_len &&
|
|
pskb_expand_head(skb, iv_len, 0, GFP_ATOMIC)))
|
|
return TX_DROP;
|
|
|
|
hdrlen = ieee80211_hdrlen(hdr->frame_control);
|
|
|
|
pos = skb_push(skb, iv_len);
|
|
memmove(pos, pos + iv_len, hdrlen);
|
|
|
|
return TX_CONTINUE;
|
|
}
|
|
|
|
static inline int ieee80211_crypto_cs_pn_compare(u8 *pn1, u8 *pn2, int len)
|
|
{
|
|
int i;
|
|
|
|
/* pn is little endian */
|
|
for (i = len - 1; i >= 0; i--) {
|
|
if (pn1[i] < pn2[i])
|
|
return -1;
|
|
else if (pn1[i] > pn2[i])
|
|
return 1;
|
|
}
|
|
|
|
return 0;
|
|
}
|
|
|
|
static ieee80211_rx_result
|
|
ieee80211_crypto_cs_decrypt(struct ieee80211_rx_data *rx)
|
|
{
|
|
struct ieee80211_key *key = rx->key;
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)rx->skb->data;
|
|
const struct ieee80211_cipher_scheme *cs = NULL;
|
|
int hdrlen = ieee80211_hdrlen(hdr->frame_control);
|
|
struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(rx->skb);
|
|
int data_len;
|
|
u8 *rx_pn;
|
|
u8 *skb_pn;
|
|
u8 qos_tid;
|
|
|
|
if (!rx->sta || !rx->sta->cipher_scheme ||
|
|
!(status->flag & RX_FLAG_DECRYPTED))
|
|
return RX_DROP_UNUSABLE;
|
|
|
|
if (!ieee80211_is_data(hdr->frame_control))
|
|
return RX_CONTINUE;
|
|
|
|
cs = rx->sta->cipher_scheme;
|
|
|
|
data_len = rx->skb->len - hdrlen - cs->hdr_len;
|
|
|
|
if (data_len < 0)
|
|
return RX_DROP_UNUSABLE;
|
|
|
|
if (ieee80211_is_data_qos(hdr->frame_control))
|
|
qos_tid = ieee80211_get_tid(hdr);
|
|
else
|
|
qos_tid = 0;
|
|
|
|
if (skb_linearize(rx->skb))
|
|
return RX_DROP_UNUSABLE;
|
|
|
|
hdr = (struct ieee80211_hdr *)rx->skb->data;
|
|
|
|
rx_pn = key->u.gen.rx_pn[qos_tid];
|
|
skb_pn = rx->skb->data + hdrlen + cs->pn_off;
|
|
|
|
if (ieee80211_crypto_cs_pn_compare(skb_pn, rx_pn, cs->pn_len) <= 0)
|
|
return RX_DROP_UNUSABLE;
|
|
|
|
memcpy(rx_pn, skb_pn, cs->pn_len);
|
|
|
|
/* remove security header and MIC */
|
|
if (pskb_trim(rx->skb, rx->skb->len - cs->mic_len))
|
|
return RX_DROP_UNUSABLE;
|
|
|
|
memmove(rx->skb->data + cs->hdr_len, rx->skb->data, hdrlen);
|
|
skb_pull(rx->skb, cs->hdr_len);
|
|
|
|
return RX_CONTINUE;
|
|
}
|
|
|
|
static void bip_aad(struct sk_buff *skb, u8 *aad)
|
|
{
|
|
__le16 mask_fc;
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *) skb->data;
|
|
|
|
/* BIP AAD: FC(masked) || A1 || A2 || A3 */
|
|
|
|
/* FC type/subtype */
|
|
/* Mask FC Retry, PwrMgt, MoreData flags to zero */
|
|
mask_fc = hdr->frame_control;
|
|
mask_fc &= ~cpu_to_le16(IEEE80211_FCTL_RETRY | IEEE80211_FCTL_PM |
|
|
IEEE80211_FCTL_MOREDATA);
|
|
put_unaligned(mask_fc, (__le16 *) &aad[0]);
|
|
/* A1 || A2 || A3 */
|
|
memcpy(aad + 2, &hdr->addr1, 3 * ETH_ALEN);
|
|
}
|
|
|
|
|
|
static inline void bip_ipn_set64(u8 *d, u64 pn)
|
|
{
|
|
*d++ = pn;
|
|
*d++ = pn >> 8;
|
|
*d++ = pn >> 16;
|
|
*d++ = pn >> 24;
|
|
*d++ = pn >> 32;
|
|
*d = pn >> 40;
|
|
}
|
|
|
|
static inline void bip_ipn_swap(u8 *d, const u8 *s)
|
|
{
|
|
*d++ = s[5];
|
|
*d++ = s[4];
|
|
*d++ = s[3];
|
|
*d++ = s[2];
|
|
*d++ = s[1];
|
|
*d = s[0];
|
|
}
|
|
|
|
|
|
ieee80211_tx_result
|
|
ieee80211_crypto_aes_cmac_encrypt(struct ieee80211_tx_data *tx)
|
|
{
|
|
struct sk_buff *skb;
|
|
struct ieee80211_tx_info *info;
|
|
struct ieee80211_key *key = tx->key;
|
|
struct ieee80211_mmie *mmie;
|
|
u8 aad[20];
|
|
u64 pn64;
|
|
|
|
if (WARN_ON(skb_queue_len(&tx->skbs) != 1))
|
|
return TX_DROP;
|
|
|
|
skb = skb_peek(&tx->skbs);
|
|
|
|
info = IEEE80211_SKB_CB(skb);
|
|
|
|
if (info->control.hw_key &&
|
|
!(key->conf.flags & IEEE80211_KEY_FLAG_GENERATE_MMIE))
|
|
return TX_CONTINUE;
|
|
|
|
if (WARN_ON(skb_tailroom(skb) < sizeof(*mmie)))
|
|
return TX_DROP;
|
|
|
|
mmie = skb_put(skb, sizeof(*mmie));
|
|
mmie->element_id = WLAN_EID_MMIE;
|
|
mmie->length = sizeof(*mmie) - 2;
|
|
mmie->key_id = cpu_to_le16(key->conf.keyidx);
|
|
|
|
/* PN = PN + 1 */
|
|
pn64 = atomic64_inc_return(&key->conf.tx_pn);
|
|
|
|
bip_ipn_set64(mmie->sequence_number, pn64);
|
|
|
|
if (info->control.hw_key)
|
|
return TX_CONTINUE;
|
|
|
|
bip_aad(skb, aad);
|
|
|
|
/*
|
|
* MIC = AES-128-CMAC(IGTK, AAD || Management Frame Body || MMIE, 64)
|
|
*/
|
|
ieee80211_aes_cmac(key->u.aes_cmac.tfm, aad,
|
|
skb->data + 24, skb->len - 24, mmie->mic);
|
|
|
|
return TX_CONTINUE;
|
|
}
|
|
|
|
ieee80211_tx_result
|
|
ieee80211_crypto_aes_cmac_256_encrypt(struct ieee80211_tx_data *tx)
|
|
{
|
|
struct sk_buff *skb;
|
|
struct ieee80211_tx_info *info;
|
|
struct ieee80211_key *key = tx->key;
|
|
struct ieee80211_mmie_16 *mmie;
|
|
u8 aad[20];
|
|
u64 pn64;
|
|
|
|
if (WARN_ON(skb_queue_len(&tx->skbs) != 1))
|
|
return TX_DROP;
|
|
|
|
skb = skb_peek(&tx->skbs);
|
|
if (!skb)
|
|
return TX_DROP;
|
|
|
|
info = IEEE80211_SKB_CB(skb);
|
|
|
|
if (info->control.hw_key)
|
|
return TX_CONTINUE;
|
|
|
|
if (WARN_ON(skb_tailroom(skb) < sizeof(*mmie)))
|
|
return TX_DROP;
|
|
|
|
mmie = skb_put(skb, sizeof(*mmie));
|
|
mmie->element_id = WLAN_EID_MMIE;
|
|
mmie->length = sizeof(*mmie) - 2;
|
|
mmie->key_id = cpu_to_le16(key->conf.keyidx);
|
|
|
|
/* PN = PN + 1 */
|
|
pn64 = atomic64_inc_return(&key->conf.tx_pn);
|
|
|
|
bip_ipn_set64(mmie->sequence_number, pn64);
|
|
|
|
bip_aad(skb, aad);
|
|
|
|
/* MIC = AES-256-CMAC(IGTK, AAD || Management Frame Body || MMIE, 128)
|
|
*/
|
|
ieee80211_aes_cmac_256(key->u.aes_cmac.tfm, aad,
|
|
skb->data + 24, skb->len - 24, mmie->mic);
|
|
|
|
return TX_CONTINUE;
|
|
}
|
|
|
|
ieee80211_rx_result
|
|
ieee80211_crypto_aes_cmac_decrypt(struct ieee80211_rx_data *rx)
|
|
{
|
|
struct sk_buff *skb = rx->skb;
|
|
struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
|
|
struct ieee80211_key *key = rx->key;
|
|
struct ieee80211_mmie *mmie;
|
|
u8 aad[20], mic[8], ipn[6];
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *) skb->data;
|
|
|
|
if (!ieee80211_is_mgmt(hdr->frame_control))
|
|
return RX_CONTINUE;
|
|
|
|
/* management frames are already linear */
|
|
|
|
if (skb->len < 24 + sizeof(*mmie))
|
|
return RX_DROP_UNUSABLE;
|
|
|
|
mmie = (struct ieee80211_mmie *)
|
|
(skb->data + skb->len - sizeof(*mmie));
|
|
if (mmie->element_id != WLAN_EID_MMIE ||
|
|
mmie->length != sizeof(*mmie) - 2)
|
|
return RX_DROP_UNUSABLE; /* Invalid MMIE */
|
|
|
|
bip_ipn_swap(ipn, mmie->sequence_number);
|
|
|
|
if (memcmp(ipn, key->u.aes_cmac.rx_pn, 6) <= 0) {
|
|
key->u.aes_cmac.replays++;
|
|
return RX_DROP_UNUSABLE;
|
|
}
|
|
|
|
if (!(status->flag & RX_FLAG_DECRYPTED)) {
|
|
/* hardware didn't decrypt/verify MIC */
|
|
bip_aad(skb, aad);
|
|
ieee80211_aes_cmac(key->u.aes_cmac.tfm, aad,
|
|
skb->data + 24, skb->len - 24, mic);
|
|
if (crypto_memneq(mic, mmie->mic, sizeof(mmie->mic))) {
|
|
key->u.aes_cmac.icverrors++;
|
|
return RX_DROP_UNUSABLE;
|
|
}
|
|
}
|
|
|
|
memcpy(key->u.aes_cmac.rx_pn, ipn, 6);
|
|
|
|
/* Remove MMIE */
|
|
skb_trim(skb, skb->len - sizeof(*mmie));
|
|
|
|
return RX_CONTINUE;
|
|
}
|
|
|
|
ieee80211_rx_result
|
|
ieee80211_crypto_aes_cmac_256_decrypt(struct ieee80211_rx_data *rx)
|
|
{
|
|
struct sk_buff *skb = rx->skb;
|
|
struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
|
|
struct ieee80211_key *key = rx->key;
|
|
struct ieee80211_mmie_16 *mmie;
|
|
u8 aad[20], mic[16], ipn[6];
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
|
|
|
|
if (!ieee80211_is_mgmt(hdr->frame_control))
|
|
return RX_CONTINUE;
|
|
|
|
/* management frames are already linear */
|
|
|
|
if (skb->len < 24 + sizeof(*mmie))
|
|
return RX_DROP_UNUSABLE;
|
|
|
|
mmie = (struct ieee80211_mmie_16 *)
|
|
(skb->data + skb->len - sizeof(*mmie));
|
|
if (mmie->element_id != WLAN_EID_MMIE ||
|
|
mmie->length != sizeof(*mmie) - 2)
|
|
return RX_DROP_UNUSABLE; /* Invalid MMIE */
|
|
|
|
bip_ipn_swap(ipn, mmie->sequence_number);
|
|
|
|
if (memcmp(ipn, key->u.aes_cmac.rx_pn, 6) <= 0) {
|
|
key->u.aes_cmac.replays++;
|
|
return RX_DROP_UNUSABLE;
|
|
}
|
|
|
|
if (!(status->flag & RX_FLAG_DECRYPTED)) {
|
|
/* hardware didn't decrypt/verify MIC */
|
|
bip_aad(skb, aad);
|
|
ieee80211_aes_cmac_256(key->u.aes_cmac.tfm, aad,
|
|
skb->data + 24, skb->len - 24, mic);
|
|
if (crypto_memneq(mic, mmie->mic, sizeof(mmie->mic))) {
|
|
key->u.aes_cmac.icverrors++;
|
|
return RX_DROP_UNUSABLE;
|
|
}
|
|
}
|
|
|
|
memcpy(key->u.aes_cmac.rx_pn, ipn, 6);
|
|
|
|
/* Remove MMIE */
|
|
skb_trim(skb, skb->len - sizeof(*mmie));
|
|
|
|
return RX_CONTINUE;
|
|
}
|
|
|
|
ieee80211_tx_result
|
|
ieee80211_crypto_aes_gmac_encrypt(struct ieee80211_tx_data *tx)
|
|
{
|
|
struct sk_buff *skb;
|
|
struct ieee80211_tx_info *info;
|
|
struct ieee80211_key *key = tx->key;
|
|
struct ieee80211_mmie_16 *mmie;
|
|
struct ieee80211_hdr *hdr;
|
|
u8 aad[GMAC_AAD_LEN];
|
|
u64 pn64;
|
|
u8 nonce[GMAC_NONCE_LEN];
|
|
|
|
if (WARN_ON(skb_queue_len(&tx->skbs) != 1))
|
|
return TX_DROP;
|
|
|
|
skb = skb_peek(&tx->skbs);
|
|
if (!skb)
|
|
return TX_DROP;
|
|
|
|
info = IEEE80211_SKB_CB(skb);
|
|
|
|
if (info->control.hw_key)
|
|
return TX_CONTINUE;
|
|
|
|
if (WARN_ON(skb_tailroom(skb) < sizeof(*mmie)))
|
|
return TX_DROP;
|
|
|
|
mmie = skb_put(skb, sizeof(*mmie));
|
|
mmie->element_id = WLAN_EID_MMIE;
|
|
mmie->length = sizeof(*mmie) - 2;
|
|
mmie->key_id = cpu_to_le16(key->conf.keyidx);
|
|
|
|
/* PN = PN + 1 */
|
|
pn64 = atomic64_inc_return(&key->conf.tx_pn);
|
|
|
|
bip_ipn_set64(mmie->sequence_number, pn64);
|
|
|
|
bip_aad(skb, aad);
|
|
|
|
hdr = (struct ieee80211_hdr *)skb->data;
|
|
memcpy(nonce, hdr->addr2, ETH_ALEN);
|
|
bip_ipn_swap(nonce + ETH_ALEN, mmie->sequence_number);
|
|
|
|
/* MIC = AES-GMAC(IGTK, AAD || Management Frame Body || MMIE, 128) */
|
|
if (ieee80211_aes_gmac(key->u.aes_gmac.tfm, aad, nonce,
|
|
skb->data + 24, skb->len - 24, mmie->mic) < 0)
|
|
return TX_DROP;
|
|
|
|
return TX_CONTINUE;
|
|
}
|
|
|
|
ieee80211_rx_result
|
|
ieee80211_crypto_aes_gmac_decrypt(struct ieee80211_rx_data *rx)
|
|
{
|
|
struct sk_buff *skb = rx->skb;
|
|
struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
|
|
struct ieee80211_key *key = rx->key;
|
|
struct ieee80211_mmie_16 *mmie;
|
|
u8 aad[GMAC_AAD_LEN], *mic, ipn[6], nonce[GMAC_NONCE_LEN];
|
|
struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
|
|
|
|
if (!ieee80211_is_mgmt(hdr->frame_control))
|
|
return RX_CONTINUE;
|
|
|
|
/* management frames are already linear */
|
|
|
|
if (skb->len < 24 + sizeof(*mmie))
|
|
return RX_DROP_UNUSABLE;
|
|
|
|
mmie = (struct ieee80211_mmie_16 *)
|
|
(skb->data + skb->len - sizeof(*mmie));
|
|
if (mmie->element_id != WLAN_EID_MMIE ||
|
|
mmie->length != sizeof(*mmie) - 2)
|
|
return RX_DROP_UNUSABLE; /* Invalid MMIE */
|
|
|
|
bip_ipn_swap(ipn, mmie->sequence_number);
|
|
|
|
if (memcmp(ipn, key->u.aes_gmac.rx_pn, 6) <= 0) {
|
|
key->u.aes_gmac.replays++;
|
|
return RX_DROP_UNUSABLE;
|
|
}
|
|
|
|
if (!(status->flag & RX_FLAG_DECRYPTED)) {
|
|
/* hardware didn't decrypt/verify MIC */
|
|
bip_aad(skb, aad);
|
|
|
|
memcpy(nonce, hdr->addr2, ETH_ALEN);
|
|
memcpy(nonce + ETH_ALEN, ipn, 6);
|
|
|
|
mic = kmalloc(GMAC_MIC_LEN, GFP_ATOMIC);
|
|
if (!mic)
|
|
return RX_DROP_UNUSABLE;
|
|
if (ieee80211_aes_gmac(key->u.aes_gmac.tfm, aad, nonce,
|
|
skb->data + 24, skb->len - 24,
|
|
mic) < 0 ||
|
|
crypto_memneq(mic, mmie->mic, sizeof(mmie->mic))) {
|
|
key->u.aes_gmac.icverrors++;
|
|
kfree(mic);
|
|
return RX_DROP_UNUSABLE;
|
|
}
|
|
kfree(mic);
|
|
}
|
|
|
|
memcpy(key->u.aes_gmac.rx_pn, ipn, 6);
|
|
|
|
/* Remove MMIE */
|
|
skb_trim(skb, skb->len - sizeof(*mmie));
|
|
|
|
return RX_CONTINUE;
|
|
}
|
|
|
|
ieee80211_tx_result
|
|
ieee80211_crypto_hw_encrypt(struct ieee80211_tx_data *tx)
|
|
{
|
|
struct sk_buff *skb;
|
|
struct ieee80211_tx_info *info = NULL;
|
|
ieee80211_tx_result res;
|
|
|
|
skb_queue_walk(&tx->skbs, skb) {
|
|
info = IEEE80211_SKB_CB(skb);
|
|
|
|
/* handle hw-only algorithm */
|
|
if (!info->control.hw_key)
|
|
return TX_DROP;
|
|
|
|
if (tx->key->flags & KEY_FLAG_CIPHER_SCHEME) {
|
|
res = ieee80211_crypto_cs_encrypt(tx, skb);
|
|
if (res != TX_CONTINUE)
|
|
return res;
|
|
}
|
|
}
|
|
|
|
ieee80211_tx_set_protected(tx);
|
|
|
|
return TX_CONTINUE;
|
|
}
|
|
|
|
ieee80211_rx_result
|
|
ieee80211_crypto_hw_decrypt(struct ieee80211_rx_data *rx)
|
|
{
|
|
if (rx->sta && rx->sta->cipher_scheme)
|
|
return ieee80211_crypto_cs_decrypt(rx);
|
|
|
|
return RX_DROP_UNUSABLE;
|
|
}
|