ath10k: correct the tlv len of ath10k_wmi_tlv_op_gen_config_pno_start
authorWen Gong <wgong@codeaurora.org>
Fri, 15 Nov 2019 07:21:32 +0000 (09:21 +0200)
committerKalle Valo <kvalo@codeaurora.org>
Mon, 25 Nov 2019 11:52:22 +0000 (13:52 +0200)
the tlv len is set to the total len of the wmi cmd, it will trigger
firmware crash, correct the tlv len.

Tested with QCA6174 SDIO with firmware
WLAN.RMH.4.4.1-00017-QCARMSWP-1 and QCA6174
PCIE with firmware WLAN.RM.4.4.1-00110-QCARMSWPZ-1.

Fixes: ce834e280f2f875 ("ath10k: support NET_DETECT WoWLAN feature")
Signed-off-by: Wen Gong <wgong@codeaurora.org>
Signed-off-by: Kalle Valo <kvalo@codeaurora.org>
drivers/net/wireless/ath/ath10k/wmi-tlv.c

index 69a1ec5..7b35848 100644 (file)
@@ -3707,6 +3707,7 @@ ath10k_wmi_tlv_op_gen_config_pno_start(struct ath10k *ar,
        struct wmi_tlv *tlv;
        struct sk_buff *skb;
        __le32 *channel_list;
+       u16 tlv_len;
        size_t len;
        void *ptr;
        u32 i;
@@ -3764,10 +3765,12 @@ ath10k_wmi_tlv_op_gen_config_pno_start(struct ath10k *ar,
        /* nlo_configured_parameters(nlo_list) */
        cmd->no_of_ssids = __cpu_to_le32(min_t(u8, pno->uc_networks_count,
                                               WMI_NLO_MAX_SSIDS));
+       tlv_len = __le32_to_cpu(cmd->no_of_ssids) *
+               sizeof(struct nlo_configured_parameters);
 
        tlv = ptr;
        tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
-       tlv->len = __cpu_to_le16(len);
+       tlv->len = __cpu_to_le16(tlv_len);
 
        ptr += sizeof(*tlv);
        nlo_list = ptr;