Page MenuHomeFreeBSD

mtw: fix zero-length queue array that can corrupt struct mtw_softc
ClosedPublic

Authored by markj on Aug 17 2026, 7:22 PM.
Tags
None
Referenced Files
F174516401: D58897.id184213.diff
Sat, Oct 3, 8:54 PM
F174497426: D58897.id.diff
Sat, Oct 3, 5:32 PM
F174434523: D58897.diff
Sat, Oct 3, 4:47 AM
Unknown Object (File)
Thu, Oct 1, 2:52 AM
Unknown Object (File)
Wed, Sep 30, 5:30 AM
Unknown Object (File)
Tue, Sep 29, 5:41 PM
Unknown Object (File)
Thu, Sep 24, 8:52 PM
Unknown Object (File)
Sat, Sep 19, 9:28 AM
Subscribers

Details

Summary

The mtw softc declares sc_epq with MTW_BULK_RX even though MTW_BULK_RX is enum
value 0, while initialization and queue handling index up to MTW_EP_QUEUES;
attaching a matching USB WLAN device can drive writes past the absent array and
corrupt adjacent softc fields.

This suggested patch sizes sc_epq with MTW_EP_QUEUES so the softc contains the
endpoint queues the driver initializes and uses.

Fixes: c14b01624261 ("mt7601U: Importing if_mtw from OpenBSD")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

markj requested review of this revision.Aug 17 2026, 7:22 PM
bz added subscribers: adrian, bz.

I'll accept this for the queue index problem; looking through the driver it feels like something else got convoluted but I could be wrong on that. @jsm and @adrian should probably cross-check that.

This revision is now accepted and ready to land.Aug 17 2026, 8:30 PM

Perhaps also check https://reviews.freebsd.org/D50174 I never committed it because it seemed to get device time outs on aarch64 (rpi4 in my test)

In D58897#1352929, @jsm wrote:

Perhaps also check https://reviews.freebsd.org/D50174 I never committed it because it seemed to get device time outs on aarch64 (rpi4 in my test)

I don't have any hardware to test this with, this is a patch that was submitted to secteam. It's clearly "right" since otherwise sc_epq is an array of length 0, and today it works by accident probably because most of the fields following the array are copy+pasted from somewhere and don't actually get used.