Commit 7b6d932725ec18c1d84892b73c9da4d624939955

Authored by Emmanuel Grumbach
Committed by Greg Kroah-Hartman
1 parent bbc4242a9c

mac80211: ignore NullFunc frames in the duplicate detection

commit 990d71846a0b7281bd933c34d734e6afc7408e7e upstream.

NullFunc packets should never be duplicate just like
QoS-NullFunc packets.

We saw a client that enters / exits power save with
NullFunc frames (and not with QoS-NullFunc) despite the
fact that the association supports HT.
This specific client also re-uses a non-zero sequence number
for different NullFunc frames.
At some point, the client had to send a retransmission of
the NullFunc frame and we dropped it, leading to a
misalignment in the power save state.
Fix this by never consider a NullFunc frame as duplicate,
just like we do for QoS NullFunc frames.

This fixes https://bugzilla.kernel.org/show_bug.cgi?id=201449

CC: <stable@vger.kernel.org>
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Showing 1 changed file with 1 additions and 0 deletions Side-by-side Diff

... ... @@ -1254,6 +1254,7 @@
1254 1254 return RX_CONTINUE;
1255 1255  
1256 1256 if (ieee80211_is_ctl(hdr->frame_control) ||
  1257 + ieee80211_is_nullfunc(hdr->frame_control) ||
1257 1258 ieee80211_is_qos_nullfunc(hdr->frame_control) ||
1258 1259 is_multicast_ether_addr(hdr->addr1))
1259 1260 return RX_CONTINUE;