mirror of
https://github.com/torvalds/linux.git
synced 2026-07-28 01:55:51 +02:00
wifi: mt76: mt7996: fix potential tx_retries underflow
When FIELD_GET returns 0 for the retry count, subtracting 1 causes
an unsigned integer underflow, resulting in tx_retries becoming a
very large value (0xFFFFFFFF for u32).
Fix by checking if count is non-zero before subtracting 1.
Fixes: 2461599f83 ("wifi: mt76: mt7996: get tx_retries and tx_failed from txfree")
Signed-off-by: Ryder Lee <ryder.lee@mediatek.com>
Link: https://patch.msgid.link/20260605113306.3485554-4-ryder.lee@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
This commit is contained in:
parent
1e1fd84571
commit
4d8bba99d6
|
|
@ -1359,13 +1359,13 @@ mt7996_mac_tx_free(struct mt7996_dev *dev, void *data, int len)
|
|||
cur_info++;
|
||||
continue;
|
||||
} else if (info & MT_TXFREE_INFO_HEADER) {
|
||||
u32 tx_retries = 0, tx_failed = 0;
|
||||
u32 tx_retries = 0, tx_failed = 0, count;
|
||||
|
||||
if (!wcid)
|
||||
continue;
|
||||
|
||||
tx_retries =
|
||||
FIELD_GET(MT_TXFREE_INFO_COUNT, info) - 1;
|
||||
count = FIELD_GET(MT_TXFREE_INFO_COUNT, info);
|
||||
tx_retries = count ? count - 1 : 0;
|
||||
tx_failed = tx_retries +
|
||||
!!FIELD_GET(MT_TXFREE_INFO_STAT, info);
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user