From 4b0a8cb3f21b5c1098081bbe3f2ea6aca50b481d Mon Sep 17 00:00:00 2001 From: Sridhar Selvaraj Date: Thu, 27 Jul 2017 19:39:58 +0530 Subject: [PATCH] wlan: Change local variables to dynamic in limProcessAuthFrame Currently limProcessAuthFrame stack frame size exceeds 1024 and causes build failures for 32 bit platforms. Move multiple variables from local to dynamic allocation to reduce the frame size of limProcessAuthFrame. Change-Id: I83cf5ab24693e0ce012894d808ac79bf37fa9a08 CRs-Fixed: 2083572 --- .../CORE/MAC/src/pe/lim/limProcessAuthFrame.c | 355 ++++++++++-------- 1 file changed, 203 insertions(+), 152 deletions(-) diff --git a/drivers/staging/prima/CORE/MAC/src/pe/lim/limProcessAuthFrame.c b/drivers/staging/prima/CORE/MAC/src/pe/lim/limProcessAuthFrame.c index 2adcf9eab48..133fed3c5b7 100644 --- a/drivers/staging/prima/CORE/MAC/src/pe/lim/limProcessAuthFrame.c +++ b/drivers/staging/prima/CORE/MAC/src/pe/lim/limProcessAuthFrame.c @@ -140,12 +140,14 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse { tANI_U8 *pBody, keyId, cfgPrivacyOptImp, defaultKey[SIR_MAC_KEY_LENGTH], - encrAuthFrame[LIM_ENCR_AUTH_BODY_LEN], - plainBody[256]; + *encrAuthFrame = NULL, + *plainBody = NULL; tANI_U16 frameLen; //tANI_U32 authRspTimeout, maxNumPreAuth, val; tANI_U32 maxNumPreAuth, val; - tSirMacAuthFrameBody *pRxAuthFrameBody, rxAuthFrame, authFrame; + tSirMacAuthFrameBody *pRxAuthFrameBody, + *rxAuthFrame = NULL, + *authFrame = NULL; tpSirMacMgmtHdr pHdr; tCfgWepKeyEntry *pKeyMapEntry = NULL; struct tLimPreAuthNode *pAuthNode; @@ -153,7 +155,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse tANI_U8 decryptResult; tANI_U8 *pChallenge; tANI_U32 key_length=8; - tANI_U8 challengeTextArray[SIR_MAC_AUTH_CHALLENGE_LENGTH]; + tANI_U8 *challengeTextArray = NULL; tpDphHashNode pStaDs = NULL; tANI_U16 assocId = 0; tANI_U16 currSeqNo = 0; @@ -203,6 +205,42 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse ccmCfgSetInt(pMac,WNI_CFG_AUTHENTICATE_FAILURE_TIMEOUT , psessionEntry->defaultAuthFailureTimeout, NULL, eANI_BOOLEAN_FALSE); } + + rxAuthFrame = vos_mem_malloc(sizeof(tSirMacAuthFrameBody)); + if (!rxAuthFrame) { + limLog(pMac, LOGE, FL("Failed to allocate memory")); + return; + } + + authFrame = vos_mem_malloc(sizeof(tSirMacAuthFrameBody)); + if (!authFrame) { + limLog(pMac, LOGE, FL("failed to allocate memory")); + goto free; + } + + encrAuthFrame = vos_mem_malloc(LIM_ENCR_AUTH_BODY_LEN); + if (!encrAuthFrame) { + limLog(pMac, LOGE, FL("failed to allocate memory")); + goto free; + } + + plainBody = vos_mem_malloc(LIM_ENCR_AUTH_BODY_LEN); + if (!plainBody) { + limLog(pMac, LOGE, FL("failed to allocate memory")); + goto free; + } + + challengeTextArray = vos_mem_malloc(SIR_MAC_AUTH_CHALLENGE_LENGTH); + if(!challengeTextArray) { + limLog(pMac, LOGE, FL("failed to allocate memory")); + goto free; + } + + vos_mem_set(rxAuthFrame, sizeof(tSirMacAuthFrameBody), 0); + vos_mem_set(authFrame, sizeof(tSirMacAuthFrameBody), 0); + vos_mem_set(encrAuthFrame, LIM_ENCR_AUTH_BODY_LEN, 0); + vos_mem_set(plainBody, LIM_ENCR_AUTH_BODY_LEN, 0); + vos_mem_set(challengeTextArray, SIR_MAC_AUTH_CHALLENGE_LENGTH, 0); /// Determine if WEP bit is set in the FC or received MAC header if (pHdr->fc.wep) @@ -220,7 +258,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse limSendDeauthMgmtFrame( pMac, eSIR_MAC_MIC_FAILURE_REASON, pHdr->sa, psessionEntry, FALSE ); - return; + goto free; } // Extract key ID from IV (most 2 bits of 4th byte of IV) @@ -238,19 +276,19 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse if (psessionEntry->limSystemRole == eLIM_STA_ROLE || psessionEntry->limSystemRole == eLIM_BT_AMP_STA_ROLE) { - authFrame.authAlgoNumber = eSIR_SHARED_KEY; - authFrame.authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; - authFrame.authStatusCode = eSIR_MAC_CHALLENGE_FAILURE_STATUS; + authFrame->authAlgoNumber = eSIR_SHARED_KEY; + authFrame->authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; + authFrame->authStatusCode = eSIR_MAC_CHALLENGE_FAILURE_STATUS; // Log error PELOGE(limLog(pMac, LOGE, FL("received Authentication frame with wep bit set on " "role=%d "MAC_ADDRESS_STR), psessionEntry->limSystemRole, MAC_ADDR_ARRAY(pHdr->sa) );) - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } if (frameLen < LIM_ENCR_AUTH_BODY_LEN) @@ -261,7 +299,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse frameLen); limPrintMacAddr(pMac, pHdr->sa, LOGE); - return; + goto free; } if(psessionEntry->limSystemRole == eLIM_AP_ROLE) { @@ -303,18 +341,18 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * an Authentication frame with FC bit set. * Send Auth frame4 with 'out of sequence' status code. */ - authFrame.authAlgoNumber = eSIR_SHARED_KEY; - authFrame.authTransactionSeqNumber = + authFrame->authAlgoNumber = eSIR_SHARED_KEY; + authFrame->authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_AUTH_FRAME_OUT_OF_SEQ_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } else { @@ -342,18 +380,18 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * out of sequence Auth frame status code. */ - authFrame.authAlgoNumber = eSIR_SHARED_KEY; - authFrame.authTransactionSeqNumber = + authFrame->authAlgoNumber = eSIR_SHARED_KEY; + authFrame->authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_AUTH_FRAME_OUT_OF_SEQ_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } } @@ -378,18 +416,18 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * Send Authentication frame * with challenge failure status code */ - authFrame.authAlgoNumber = eSIR_SHARED_KEY; - authFrame.authTransactionSeqNumber = + authFrame->authAlgoNumber = eSIR_SHARED_KEY; + authFrame->authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_CHALLENGE_FAILURE_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } // if (!pKeyMapEntry->wepOn) else { @@ -411,30 +449,30 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse limDeletePreAuthNode(pMac, pHdr->sa); - authFrame.authAlgoNumber = eSIR_SHARED_KEY; - authFrame.authTransactionSeqNumber = + authFrame->authAlgoNumber = eSIR_SHARED_KEY; + authFrame->authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_CHALLENGE_FAILURE_STATUS; limSendAuthMgmtFrame( - pMac, &authFrame, + pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } if ( ( sirConvertAuthFrame2Struct(pMac, plainBody, frameLen-8, - &rxAuthFrame)!=eSIR_SUCCESS ) || - ( !isAuthValid(pMac, &rxAuthFrame,psessionEntry) ) ) + rxAuthFrame)!=eSIR_SUCCESS ) || + ( !isAuthValid(pMac, rxAuthFrame,psessionEntry) ) ) { PELOGE(limLog(pMac, LOGE, FL("failed to convert Auth Frame to structure " "or Auth is not valid "));) - return; + goto free; } @@ -466,18 +504,18 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * with challenge failure status code */ - authFrame.authAlgoNumber = eSIR_SHARED_KEY; - authFrame.authTransactionSeqNumber = + authFrame->authAlgoNumber = eSIR_SHARED_KEY; + authFrame->authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_CHALLENGE_FAILURE_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } key_length=val; @@ -499,28 +537,28 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse /// ICV failure limDeletePreAuthNode(pMac, pHdr->sa); - authFrame.authAlgoNumber = eSIR_SHARED_KEY; - authFrame.authTransactionSeqNumber = + authFrame->authAlgoNumber = eSIR_SHARED_KEY; + authFrame->authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_CHALLENGE_FAILURE_STATUS; limSendAuthMgmtFrame( - pMac, &authFrame, + pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } if ( ( sirConvertAuthFrame2Struct(pMac, plainBody, frameLen-8, - &rxAuthFrame)!=eSIR_SUCCESS ) || - ( !isAuthValid(pMac, &rxAuthFrame, psessionEntry) ) ) + rxAuthFrame)!=eSIR_SUCCESS ) || + ( !isAuthValid(pMac, rxAuthFrame, psessionEntry) ) ) { limLog(pMac, LOGE, FL("failed to convert Auth Frame to structure " "or Auth is not valid ")); - return; + goto free; } } // End of check for Key Mapping/Default key presence } @@ -540,18 +578,18 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * should have been 'unsupported algorithm' status code. */ - authFrame.authAlgoNumber = eSIR_SHARED_KEY; - authFrame.authTransactionSeqNumber = + authFrame->authAlgoNumber = eSIR_SHARED_KEY; + authFrame->authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_CHALLENGE_FAILURE_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } // else if (wlan_cfgGetInt(CFG_PRIVACY_OPTION_IMPLEMENTED)) } // if (fc.wep) else @@ -559,18 +597,18 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse if ( ( sirConvertAuthFrame2Struct(pMac, pBody, - frameLen, &rxAuthFrame)!=eSIR_SUCCESS ) || - ( !isAuthValid(pMac, &rxAuthFrame,psessionEntry) ) ) + frameLen, rxAuthFrame)!=eSIR_SUCCESS ) || + ( !isAuthValid(pMac, rxAuthFrame,psessionEntry) ) ) { PELOGE(limLog(pMac, LOGE, FL("failed to convert Auth Frame to structure or Auth is " "not valid "));) - return; + goto free; } } - pRxAuthFrameBody = &rxAuthFrame; + pRxAuthFrameBody = rxAuthFrame; PELOGW(limLog(pMac, LOGW, FL("Received Auth frame with type=%d seqnum=%d, status=%d (%d)"), @@ -642,7 +680,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse limSendDeauthMgmtFrame(pMac, eSIR_MAC_UNSPEC_FAILURE_REASON, (tANI_U8 *) pHdr->sa, psessionEntry, FALSE); limTriggerSTAdeletion(pMac, pStaDs, psessionEntry); - return; + goto free; } } @@ -705,7 +743,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse limSendDeauthMgmtFrame(pMac, eSIR_MAC_UNSPEC_FAILURE_REASON, (tANI_U8 *) pAuthNode->peerMacAddr, psessionEntry, FALSE); limTriggerSTAdeletion(pMac, pStaDs, psessionEntry); - return; + goto free; } } else @@ -717,7 +755,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * */ PELOGE(limLog(pMac, LOGE, FL("STA is initiating " "Authentication after ACK lost..."));) - return; + goto free; } } if (wlan_cfgGetInt(pMac, WNI_CFG_MAX_NUM_PRE_AUTH, @@ -741,19 +779,19 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * reached. Send Authentication frame * with unspecified failure */ - authFrame.authAlgoNumber = + authFrame->authAlgoNumber = pRxAuthFrameBody->authAlgoNumber; - authFrame.authTransactionSeqNumber = + authFrame->authTransactionSeqNumber = pRxAuthFrameBody->authTransactionSeqNumber + 1; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_UNSPEC_FAILURE_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } /// No Pre-auth context exists for the STA. if (limIsAuthAlgoSupported( @@ -773,8 +811,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse limLog(pMac, LOGW, FL("Max pre-auth nodes reached ")); limPrintMacAddr(pMac, pHdr->sa, LOGW); - - return; + goto free; } limLog(pMac, LOG1, @@ -801,13 +838,13 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * status code. */ - authFrame.authAlgoNumber = + authFrame->authAlgoNumber = pRxAuthFrameBody->authAlgoNumber; - authFrame.authTransactionSeqNumber = + authFrame->authTransactionSeqNumber = pRxAuthFrameBody->authTransactionSeqNumber + 1; - authFrame.authStatusCode = eSIR_MAC_SUCCESS_STATUS; + authFrame->authStatusCode = eSIR_MAC_SUCCESS_STATUS; limSendAuthMgmtFrame( - pMac, &authFrame, + pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); @@ -860,20 +897,20 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * code. */ - authFrame.authAlgoNumber = + authFrame->authAlgoNumber = pRxAuthFrameBody->authAlgoNumber; - authFrame.authTransactionSeqNumber = + authFrame->authTransactionSeqNumber = pRxAuthFrameBody->authTransactionSeqNumber + 1; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_AUTH_ALGO_NOT_SUPPORTED_STATUS; limSendAuthMgmtFrame( - pMac, &authFrame, + pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } else { @@ -887,7 +924,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse FL("Max pre-auth nodes reached ")); limPrintMacAddr(pMac, pHdr->sa, LOGW); - return; + goto free; } vos_mem_copy((tANI_U8 *) pAuthNode->peerMacAddr, @@ -924,33 +961,34 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * unspecified failure status code. */ - authFrame.authAlgoNumber = + authFrame->authAlgoNumber = pRxAuthFrameBody->authAlgoNumber; - authFrame.authTransactionSeqNumber = + authFrame->authTransactionSeqNumber = pRxAuthFrameBody->authTransactionSeqNumber + 1; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_UNSPEC_FAILURE_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); limDeletePreAuthNode(pMac, pHdr->sa); - return; + goto free; } limActivateAuthRspTimer(pMac, pAuthNode); pAuthNode->fTimerStarted = 1; - // get random bytes and use as - // challenge text - // TODO - //if( !VOS_IS_STATUS_SUCCESS( vos_rand_get_bytes( 0, (tANI_U8 *)challengeTextArray, SIR_MAC_AUTH_CHALLENGE_LENGTH ) ) ) + /* + * get random bytes and use as challenge text + */ + if( !VOS_IS_STATUS_SUCCESS( vos_rand_get_bytes( 0, (tANI_U8 *)challengeTextArray, SIR_MAC_AUTH_CHALLENGE_LENGTH ) ) ) { limLog(pMac, LOGE,FL("Challenge text " "preparation failed in limProcessAuthFrame")); + goto free; } pChallenge = pAuthNode->challengeText; @@ -963,20 +1001,20 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * Sending Authenticaton frame with challenge. */ - authFrame.authAlgoNumber = + authFrame->authAlgoNumber = pRxAuthFrameBody->authAlgoNumber; - authFrame.authTransactionSeqNumber = + authFrame->authTransactionSeqNumber = pRxAuthFrameBody->authTransactionSeqNumber + 1; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_SUCCESS_STATUS; - authFrame.type = SIR_MAC_CHALLENGE_TEXT_EID; - authFrame.length = SIR_MAC_AUTH_CHALLENGE_LENGTH; - vos_mem_copy(authFrame.challengeText, + authFrame->type = SIR_MAC_CHALLENGE_TEXT_EID; + authFrame->length = SIR_MAC_AUTH_CHALLENGE_LENGTH; + vos_mem_copy(authFrame->challengeText, pAuthNode->challengeText, SIR_MAC_AUTH_CHALLENGE_LENGTH); limSendAuthMgmtFrame( - pMac, &authFrame, + pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); @@ -1000,20 +1038,20 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * with auth algorithm not supported status code */ - authFrame.authAlgoNumber = + authFrame->authAlgoNumber = pRxAuthFrameBody->authAlgoNumber; - authFrame.authTransactionSeqNumber = + authFrame->authTransactionSeqNumber = pRxAuthFrameBody->authTransactionSeqNumber + 1; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_AUTH_ALGO_NOT_SUPPORTED_STATUS; limSendAuthMgmtFrame( - pMac, &authFrame, + pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } // end switch(pRxAuthFrameBody->authAlgoNumber) } // if (limIsAuthAlgoSupported(pRxAuthFrameBody->authAlgoNumber)) else @@ -1030,19 +1068,19 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * authentication algorithm requested by sending party. * Reject Authentication with StatusCode=13. */ - authFrame.authAlgoNumber = + authFrame->authAlgoNumber = pRxAuthFrameBody->authAlgoNumber; - authFrame.authTransactionSeqNumber = + authFrame->authTransactionSeqNumber = pRxAuthFrameBody->authTransactionSeqNumber + 1; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_AUTH_ALGO_NOT_SUPPORTED_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } //end if (limIsAuthAlgoSupported(pRxAuthFrameBody->authAlgoNumber)) break; @@ -1062,7 +1100,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse psessionEntry->limMlmState); limPrintMacAddr(pMac, pHdr->sa, LOG1); - return; + goto free; } if ( !vos_mem_compare((tANI_U8 *) pHdr->sa, @@ -1137,7 +1175,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse FL("Max pre-auth nodes reached ")); limPrintMacAddr(pMac, pHdr->sa, LOGW); - return; + goto free; } limLog(pMac, LOG1, @@ -1192,18 +1230,18 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse MAC_ADDRESS_STR), pRxAuthFrameBody->authAlgoNumber, MAC_ADDR_ARRAY(pHdr->sa));) - authFrame.authAlgoNumber = + authFrame->authAlgoNumber = pRxAuthFrameBody->authAlgoNumber; - authFrame.authTransactionSeqNumber = + authFrame->authTransactionSeqNumber = pRxAuthFrameBody->authTransactionSeqNumber + 1; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_AUTH_ALGO_NOT_SUPPORTED_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } else { @@ -1216,7 +1254,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse FL("received Auth frame with invalid " "challenge text IE"));) - return; + goto free; } /** @@ -1241,14 +1279,14 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * Send Auth frame with * challenge failure status code */ - authFrame.authAlgoNumber = + authFrame->authAlgoNumber = pRxAuthFrameBody->authAlgoNumber; - authFrame.authTransactionSeqNumber = + authFrame->authTransactionSeqNumber = pRxAuthFrameBody->authTransactionSeqNumber + 1; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_CHALLENGE_FAILURE_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); @@ -1256,7 +1294,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse limRestoreFromAuthState(pMac, eSIR_SME_NO_KEY_MAPPING_KEY_FOR_PEER, eSIR_MAC_UNSPEC_FAILURE_REASON,psessionEntry); - return; + goto free; } // if (pKeyMapEntry->key == NULL) else { @@ -1321,15 +1359,15 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse limLog(pMac, LOGP, FL("could not retrieve Default key")); - authFrame.authAlgoNumber = + authFrame->authAlgoNumber = pRxAuthFrameBody->authAlgoNumber; - authFrame.authTransactionSeqNumber = + authFrame->authTransactionSeqNumber = pRxAuthFrameBody->authTransactionSeqNumber + 1; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_CHALLENGE_FAILURE_STATUS; limSendAuthMgmtFrame( - pMac, &authFrame, + pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); @@ -1407,18 +1445,18 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * Shared Key authentication type. Reject with Auth frame4 * with 'out of sequence' status code. */ - authFrame.authAlgoNumber = eSIR_SHARED_KEY; - authFrame.authTransactionSeqNumber = + authFrame->authAlgoNumber = eSIR_SHARED_KEY; + authFrame->authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_AUTH_FRAME_OUT_OF_SEQ_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } if (psessionEntry->limSystemRole == eLIM_AP_ROLE || psessionEntry->limSystemRole == eLIM_BT_AMP_AP_ROLE || @@ -1438,18 +1476,18 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse MAC_ADDR_ARRAY(pHdr->sa));) /// WEP bit is not set in FC of Auth Frame3 - authFrame.authAlgoNumber = eSIR_SHARED_KEY; - authFrame.authTransactionSeqNumber = + authFrame->authAlgoNumber = eSIR_SHARED_KEY; + authFrame->authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_CHALLENGE_FAILURE_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } pAuthNode = limSearchPreAuthList(pMac, @@ -1469,18 +1507,18 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * Send Auth frame4 with 'out of sequence' * status code. */ - authFrame.authAlgoNumber = eSIR_SHARED_KEY; - authFrame.authTransactionSeqNumber = + authFrame->authAlgoNumber = eSIR_SHARED_KEY; + authFrame->authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_AUTH_FRAME_OUT_OF_SEQ_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } if (pAuthNode->mlmState == eLIM_MLM_AUTH_RSP_TIMEOUT_STATE) @@ -1494,14 +1532,14 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * Reject by sending Auth Frame4 with * Auth respone timeout Status Code. */ - authFrame.authAlgoNumber = eSIR_SHARED_KEY; - authFrame.authTransactionSeqNumber = + authFrame->authAlgoNumber = eSIR_SHARED_KEY; + authFrame->authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_AUTH_RSP_TIMEOUT_STATUS; limSendAuthMgmtFrame( - pMac, &authFrame, + pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); @@ -1510,7 +1548,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse limDeletePreAuthNode(pMac, pHdr->sa); - return; + goto free; } // end switch (pAuthNode->mlmState) if (pRxAuthFrameBody->authStatusCode != eSIR_MAC_SUCCESS_STATUS) @@ -1527,7 +1565,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse MAC_ADDRESS_STR), pRxAuthFrameBody->authStatusCode, MAC_ADDR_ARRAY(pHdr->sa));) - return; + goto free; } /** @@ -1552,12 +1590,12 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse /** * Send Authentication Frame4 with 'success' Status Code. */ - authFrame.authAlgoNumber = eSIR_SHARED_KEY; - authFrame.authTransactionSeqNumber = + authFrame->authAlgoNumber = eSIR_SHARED_KEY; + authFrame->authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; - authFrame.authStatusCode = eSIR_MAC_SUCCESS_STATUS; + authFrame->authStatusCode = eSIR_MAC_SUCCESS_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); @@ -1590,19 +1628,19 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse * delete STA context. */ - authFrame.authAlgoNumber = + authFrame->authAlgoNumber = pRxAuthFrameBody->authAlgoNumber; - authFrame.authTransactionSeqNumber = + authFrame->authTransactionSeqNumber = SIR_MAC_AUTH_FRAME_4; - authFrame.authStatusCode = + authFrame->authStatusCode = eSIR_MAC_CHALLENGE_FAILURE_STATUS; - limSendAuthMgmtFrame(pMac, &authFrame, + limSendAuthMgmtFrame(pMac, authFrame, pHdr->sa, LIM_NO_WEP_IN_FC, psessionEntry, eSIR_FALSE); - return; + goto free; } } // if (pMac->lim.gLimSystemRole == eLIM_AP_ROLE || ... @@ -1623,7 +1661,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse "%d, addr "MAC_ADDRESS_STR), psessionEntry->limMlmState, MAC_ADDR_ARRAY(pHdr->sa)); - return; + goto free; } if (pRxAuthFrameBody->authAlgoNumber != eSIR_SHARED_KEY) @@ -1641,7 +1679,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse "algo %d "MAC_ADDRESS_STR), pRxAuthFrameBody->authAlgoNumber, MAC_ADDR_ARRAY(pHdr->sa));) - return; + goto free; } if ( !vos_mem_compare((tANI_U8 *) pHdr->sa, @@ -1697,7 +1735,7 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse FL("Max pre-auth nodes reached ")); limPrintMacAddr(pMac, pHdr->sa, LOGW); - return; + goto free; } limLog(pMac, LOG1, FL("Alloc new data: peer " MAC_ADDRESS_STR), @@ -1746,6 +1784,19 @@ limProcessAuthFrame(tpAniSirGlobal pMac, tANI_U8 *pRxPacketInfo, tpPESession pse break; } // end switch (pRxAuthFrameBody->authTransactionSeqNumber) + +free: + if (authFrame) + vos_mem_free(authFrame); + if (rxAuthFrame) + vos_mem_free(rxAuthFrame); + if (encrAuthFrame) + vos_mem_free(encrAuthFrame); + if (plainBody) + vos_mem_free(plainBody); + if (challengeTextArray) + vos_mem_free(challengeTextArray); + } /*** end limProcessAuthFrame() ***/