Re: [PATCH v3] wifi: mwifiex: replace one-element arrays with flexible array members
From: George Valkov
Date: Mon Jul 27 2026 - 08:20:07 EST
Any update on the progress? Do I need to do or change anything?
On Thu, 16 Jul 2026 at 11:09, George Valkov <gvalkov@xxxxxxxxx> wrote:
>
> On Thu, 16 Jul 2026 at 09:55, Dan Carpenter <error27@xxxxxxxxx> wrote:
> >
> > On Thu, Jul 16, 2026 at 08:32:46AM +0200, Francesco Dolcini wrote:
> > > On Thu, Jul 16, 2026 at 09:27:23AM +0300, Dan Carpenter wrote:
> > > > On Thu, Jul 16, 2026 at 08:16:38AM +0200, Francesco Dolcini wrote:
> > > > > On Thu, Jul 16, 2026 at 03:17:28AM +0300, Georgi Valkov wrote:
> > > > > > Replace deprecated one-element arrays with flexible array members.
> > > > > > CONFIG_FORTIFY_SOURCE reports the following warning when
> > > > > > one-element arrays are used as variable-length buffers:
> > > > > >
> > > > > > sta_cmd.c:1033 mwifiex_sta_prepare_cmd
> > > > > > memcpy: detected field-spanning write (size 84) of single field
> > > > > > "domain->triplet" at .../marvell/mwifiex/sta_cmd.c:1033 (size 3)
> > > > > >
> > > > > > Convert affected structs to use flexible array members.
> > > > > > - Preserve existing wire layouts.
> > > > > > - Use DECLARE_FLEX_ARRAY() for structs inside affected unions.
> > > > > >
> > > > > > Tested-on: WRT3200ACM, OpenWrt
> > > > > > Signed-off-by: Georgi Valkov <gvalkov@xxxxxxxxx>
> > > > >
> > > > > Cc: stable@xxxxxxxxxxxxxxx # 6.12+
> > > > > Reviewed-by: Francesco Dolcini <francesco.dolcini@xxxxxxxxxxx>
> > > >
> > > > Are we CCing stable for this sort of thing? How many FORTIFY_SOURCE
> > > > warnings are still remaining?
> > >
> > > Yes, you are right, my mistake.
> > >
> > > Johannes, please be sure to not have the stable tag in once you apply the
> > > patch.
> >
> > Wait... No no. It was a serious question. I guess these warnings
> > are pretty annoying for a real user on WRT so it's fine to CC stable.
> > I just assumed these warnings were more common still.
>
> When I first saw it, I thought it was a kernel panic.
> There was an unrelated bug before the warning. My other PR fixes it:
> wifi: mwifiex: fix freeze for 60 seconds caused by request_firmware
>
> But after fixing the freeze, the warning remained.
> Next I thought it was a driver crash. To confirm, I added:
> mwifiex_dbg(ERROR) right before and after memcpy(),
> and printed all values in both source and destination:
> - memcpy has copied all data to the destination
> - execution is allowed to continue
> - so it is just a scary warning
>
> I wanted to ask both patches to be backported to stable, but
> at the time I sent them, I did not know that I could insert
> free text between the commit message and the patch.
> I will reply to the other PR and ask them.
>
> Full text of the warning fixed here:
>
> [ 90.484902] ------------[ cut here ]------------
> [ 90.489549] WARNING: CPU: 1 PID: 3059 at
> backports-6.18.26/drivers/net/wireless/marvell/mwifiex/sta_cmd.c:1033
> mwifiex_sta_prepare_cmd+0x1904/0x19b0 [mwifiex]
> [ 90.503877] memcpy: detected field-spanning write (size 84) of
> single field "domain->triplet" at
> backports-6.18.26/drivers/net/wireless/marvell/mwifiex/sta_cmd.c:1033
> (size 3)
> [ 90.519602] Modules linked in: option cdc_mbim uvcvideo usb_wwan
> rndis_host qmi_wwan nft_fib_inet nf_flow_table_inet ftdi_sio
> ebtable_nat ebtable_filter ebtable_broute cdc_ncm cdc_ether xt_time
> xt_tcpmss xt_statistic xt_state xt_nat xt_multiport xt_mark xt_mac
> xt_limit xt_length xt_iprange xt_hl xt_fuzzy(O) xt_ecn xt_dscp
> xt_conntrack xt_comment xt_TEE xt_TCPMSS xt_REDIRECT xt_MASQUERADE
> xt_LOG xt_IPMARK(O) xt_HL xt_FLOWOFFLOAD xt_DSCP xt_CT xt_CLASSIFY
> xt_DELUDE(O) xt_TARPIT(O) ipt_REJECT xt_tcpudp xt_CHAOS(O)
> videobuf2_v4l2 uvc usbserial usbnet ums_usbat ums_sddr55 ums_sddr09
> ums_karma ums_jumpshot ums_isd200 ums_freecom ums_datafab ums_cypress
> ums_alauda rfcomm nft_reject_ipv6 nft_reject_ipv4 nft_reject_inet
> nft_reject_bridge nft_reject nft_redir nft_quota nft_numgen nft_nat
> nft_meta_bridge nft_masq nft_log nft_limit nft_hash nft_flow_offload
> nft_fib_ipv6 nft_fib_ipv4 nft_fib nft_ct nft_compat nft_chain_nat
> nf_tables nf_reject_ipv4 nf_log_syslog nf_flow_table nf_dup_ipv6
> nf_dup_ipv4 nf_conntrack_bridge
> [ 90.519758] mwifiex_sdio(O) mwifiex(O) libcrc32c iptable_nat
> iptable_mangle iptable_filter ipt_ECN ipheth ip_tables hidp ebtables
> ebt_vlan ebt_stp ebt_snat ebt_redirect ebt_pkttype ebt_mark_m ebt_mark
> ebt_limit ebt_ip6 ebt_ip ebt_dnat ebt_arpreply ebt_arp ebt_among
> ebt_802_3 cdc_wdm cdc_acm btmrvl_sdio btmrvl bnep bluetooth
> arptable_filter arpt_mangle arp_tables fuse ntfs3 videobuf2_vmalloc
> videobuf2_memops videobuf2_common hid videodev mc evdev input_core
> mwlwifi(O) mac80211(O) cfg80211(O) compat(O) cryptodev(O) xt_set
> ip_set_list_set ip_set_hash_netportnet ip_set_hash_netport
> ip_set_hash_netnet ip_set_hash_netiface ip_set_hash_net
> ip_set_hash_mac ip_set_hash_ipportnet ip_set_hash_ipportip
> ip_set_hash_ipport ip_set_hash_ipmark ip_set_hash_ipmac ip_set_hash_ip
> ip_set_bitmap_port ip_set_bitmap_ipmac ip_set_bitmap_ip ip_set
> nfnetlink ip6table_nat nf_nat nf_conntrack nf_defrag_ipv6
> nf_defrag_ipv4 ip6t_NPT ip6t_rt ip6t_mh ip6t_ipv6header ip6t_hbh
> ip6t_frag ip6t_eui64 ip6t_ah ip6table_mangle ip6table_filter
> ip6_tables
> [ 90.609354] ip6t_REJECT x_tables nf_reject_ipv6 msdos tun nls_utf8
> nls_iso8859_2 nls_iso8859_15 nls_iso8859_13 nls_iso8859_1 nls_cp866
> nls_cp437 nls_cp1251 dma_shared_buffer ecdh_generic ecc crypto_user
> algif_skcipher algif_rng algif_hash algif_aead af_alg sha512_generic
> sha256_generic seqiv sha3_generic jitterentropy_rng drbg kpp hmac
> ghash_arm_ce geniv rng cmac uas gpio_button_hotplug(O) vfat fat exfat
> mii
> [ 90.736063] CPU: 1 UID: 101 PID: 3059 Comm: hostapd Tainted: G
> O 6.12.92 #0
> [ 90.736073] Tainted: [O]=OOT_MODULE
> [ 90.736074] Hardware name: Marvell Armada 380/385 (Device Tree)
> [ 90.736077] Call trace:
> [ 90.736082] unwind_backtrace from show_stack+0x10/0x14
> [ 90.736094] show_stack from dump_stack_lvl+0x50/0x64
> [ 90.736105] dump_stack_lvl from __warn+0x7c/0xd4
> [ 90.736116] __warn from warn_slowpath_fmt+0xf8/0x15c
> [ 90.736124] warn_slowpath_fmt from
> mwifiex_sta_prepare_cmd+0x1904/0x19b0 [mwifiex]
> [ 90.736217] mwifiex_sta_prepare_cmd [mwifiex] from
> mwifiex_send_cmd+0x2f4/0x410 [mwifiex]
> [ 90.736286] mwifiex_send_cmd [mwifiex] from
> mwifiex_send_domain_info_cmd_fw+0x150/0x1b4 [mwifiex]
> [ 90.736351] mwifiex_send_domain_info_cmd_fw [mwifiex] from
> mwifiex_uap_set_channel+0x100/0x150 [mwifiex]
> [ 90.736416] mwifiex_uap_set_channel [mwifiex] from
> mwifiex_cfg80211_start_ap+0x12c/0x39c [mwifiex]
> [ 90.736480] mwifiex_cfg80211_start_ap [mwifiex] from
> nl80211_start_ap+0xa24/0x1048 [cfg80211]
> [ 90.736607] nl80211_start_ap [cfg80211] from genl_rcv_msg+0x260/0x3a8
> [ 90.736670] genl_rcv_msg from netlink_rcv_skb+0xb8/0x11c
> [ 90.736681] netlink_rcv_skb from genl_rcv+0x28/0x34
> [ 90.736690] genl_rcv from netlink_unicast+0x22c/0x330
> [ 90.736698] netlink_unicast from netlink_sendmsg+0x198/0x3d0
> [ 90.736707] netlink_sendmsg from ____sys_sendmsg+0x1cc/0x260
> [ 90.736717] ____sys_sendmsg from ___sys_sendmsg+0x6c/0xa4
> [ 90.736723] ___sys_sendmsg from __sys_sendmsg+0x5c/0x94
> [ 90.736732] __sys_sendmsg from ret_fast_syscall+0x0/0x4c
> [ 90.736738] Exception stack(0xc4181fa8 to 0xc4181ff0)
> [ 90.736743] 1fa0: 00000000 00000000 0000001f
> bed78be0 00000000 00000000
> [ 90.736748] 1fc0: 00000000 00000000 b69d6b90 00000128 00000004
> 00000001 bed78c34 b69c1cd0
> [ 90.736751] 1fe0: bed78b90 bed78b80 b6f7a848 b6f79b6c
> [ 90.736754] ---[ end trace 0000000000000000 ]---