Re: [PATCH v2 1/2] wifi: rtw88: download the beacon the reserved page was built with
From: Luka Gejak
Date: Thu Oct 01 2026 - 03:17:24 EST
On Wed, 30 Sep 2026, Mehmet Fide wrote:
> - if (page == 0)
> + if (page == 0) {
> page += rtw_len_to_page(rsvd_pkt->skb->len +
> tx_desc_sz, page_size);
> + /* the caller downloads it once more on its own */
> + *beacon = rsvd_pkt->skb;
> + } else {
[...]
> free:
> + dev_kfree_skb(beacon);
> kfree(buf);
beacon is written in that branch only, and the caller declares it without an
initialiser while the free at the end frees whatever it holds. The first page
always takes that branch today, but the caller cannot see that, so a later
change in the build would free a stack value. Would you mind initialising it to
NULL?
> @@ -2345,7 +2353,7 @@ int rtw_hw_scan_offload(struct rtw_dev *rtwdev, struct ieee80211_vif *vif,
> out:
> if (rtwdev->ap_active) {
> - ret = rtw_download_beacon(rtwdev);
> + ret = rtw_download_beacon(rtwdev, NULL);
> if (ret)
> rtw_err(rtwdev, "HW scan download beacon failed\n");
The cover says this path is compile tested only. The feature comes from the
firmware header rather than from the chip:
fw->feature = feature & FW_FEATURE_SIG ? feature : 0;
so another firmware for the same hardware can reach it, and this is the path
that v1 got wrong. Can it be run once on a device whose firmware has scan
offload?
Best regards,
Luka Gejak