<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux-toradex.git/drivers/net/wireless/nxp/nxpwifi/11n.c, branch master</title>
<subtitle>Linux kernel for Apalis and Colibri modules</subtitle>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/'/>
<entry>
<title>wifi: nxpwifi: fix inverted check in Tx BA stream entry deletion</title>
<updated>2026-10-06T13:13:54+00:00</updated>
<author>
<name>David Carlier</name>
<email>devnexen@gmail.com</email>
</author>
<published>2026-08-25T23:17:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=32d1a000e99612e010335760363936d85591fd69'/>
<id>32d1a000e99612e010335760363936d85591fd69</id>
<content type='text'>
nxpwifi_is_tx_ba_stream_ptr_valid() returns true when the entry is still
linked, and every caller passes an entry that is on the list, so the early
return always fires and nothing is ever unlinked or freed. Entries leak on
every teardown and, since nxpwifi_space_avail_for_new_ba_stream() counts
them, Tx aggregation stops being negotiated once the stale count reaches
the maximum.

Changing the original dead &amp;&amp; test to || to silence a NULL dereference
report inverted the validity test along with it.

Fixes: 00c786a7581e ("wifi: nxpwifi: fix multiple static analysis errors and warnings")
Assisted-by: Claude:claude-opus-5
Signed-off-by: David Carlier &lt;devnexen@gmail.com&gt;
Signed-off-by: Jeff Chen &lt;jeff.chen_1@nxp.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
nxpwifi_is_tx_ba_stream_ptr_valid() returns true when the entry is still
linked, and every caller passes an entry that is on the list, so the early
return always fires and nothing is ever unlinked or freed. Entries leak on
every teardown and, since nxpwifi_space_avail_for_new_ba_stream() counts
them, Tx aggregation stops being negotiated once the stale count reaches
the maximum.

Changing the original dead &amp;&amp; test to || to silence a NULL dereference
report inverted the validity test along with it.

Fixes: 00c786a7581e ("wifi: nxpwifi: fix multiple static analysis errors and warnings")
Assisted-by: Claude:claude-opus-5
Signed-off-by: David Carlier &lt;devnexen@gmail.com&gt;
Signed-off-by: Jeff Chen &lt;jeff.chen_1@nxp.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>wifi: nxpwifi: fix multiple static analysis errors and warnings</title>
<updated>2026-08-06T12:03:15+00:00</updated>
<author>
<name>Jeff Chen</name>
<email>jeff.chen_1@nxp.com</email>
</author>
<published>2026-08-03T16:27:41+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=00c786a7581e62243608592543bca3c0ec3514cc'/>
<id>00c786a7581e62243608592543bca3c0ec3514cc</id>
<content type='text'>
Fix various development-phase bugs, code quality, and logical issues
reported by the kernel test robot (using the Smatch static analysis tool).

The following addressable fixes are included:

- 11n.c &amp; 11ax.c: Fix potential NULL pointer dereferences by correcting
  logical operators (&amp;&amp; to ||) in 11n.c and hoisting the bss_desc
  verification to the top of the function in 11ax.c.
- 11n.c: Fix a severe Use-After-Free (UAF) memory corruption during RCU
  list traversal. Restore the proper list_for_each_entry_safe() loop
  structure along with the required array index [i] within the locked
  writer path.
- sdio.c: Fix a missing unwind resource cleanup pathway where a protocol
  error branch returned directly via -EINVAL instead of using
  'goto term_cmd', leaving the SDIO hardware state machine out of sync.
- main.h: Fix a signedness mismatch bug where nxpwifi_get_unused_bss_num()
  could return -2 as an unsigned integer fallback.
- util.c: Remove a redundant and dead condition check (position &lt;= 15)
  which was always true for a 4-bit unsigned bit-field member variable.
- cfg80211.c: Clean up a dead unreachable 'return 0' at the bottom of the
  switch-case logic.
- uap_txrx.c: Clean up mismatched and inconsistent indentations within the
  handling of multicast RX forward paths.

Reported-by: kernel test robot &lt;lkp@intel.com&gt;
Closes: https://lore.kernel.org/oe-kbuild-all/202608020855.QwN5n7i5-lkp@intel.com/
Assisted-by: Gemini:unknown-model
Signed-off-by: Jeff Chen &lt;jeff.chen_1@nxp.com&gt;
Link: https://patch.msgid.link/20260803162741.438820-1-chunfan.chen@gmail.com
Signed-off-by: Johannes Berg &lt;johannes.berg@intel.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Fix various development-phase bugs, code quality, and logical issues
reported by the kernel test robot (using the Smatch static analysis tool).

The following addressable fixes are included:

- 11n.c &amp; 11ax.c: Fix potential NULL pointer dereferences by correcting
  logical operators (&amp;&amp; to ||) in 11n.c and hoisting the bss_desc
  verification to the top of the function in 11ax.c.
- 11n.c: Fix a severe Use-After-Free (UAF) memory corruption during RCU
  list traversal. Restore the proper list_for_each_entry_safe() loop
  structure along with the required array index [i] within the locked
  writer path.
- sdio.c: Fix a missing unwind resource cleanup pathway where a protocol
  error branch returned directly via -EINVAL instead of using
  'goto term_cmd', leaving the SDIO hardware state machine out of sync.
- main.h: Fix a signedness mismatch bug where nxpwifi_get_unused_bss_num()
  could return -2 as an unsigned integer fallback.
- util.c: Remove a redundant and dead condition check (position &lt;= 15)
  which was always true for a 4-bit unsigned bit-field member variable.
- cfg80211.c: Clean up a dead unreachable 'return 0' at the bottom of the
  switch-case logic.
- uap_txrx.c: Clean up mismatched and inconsistent indentations within the
  handling of multicast RX forward paths.

Reported-by: kernel test robot &lt;lkp@intel.com&gt;
Closes: https://lore.kernel.org/oe-kbuild-all/202608020855.QwN5n7i5-lkp@intel.com/
Assisted-by: Gemini:unknown-model
Signed-off-by: Jeff Chen &lt;jeff.chen_1@nxp.com&gt;
Link: https://patch.msgid.link/20260803162741.438820-1-chunfan.chen@gmail.com
Signed-off-by: Johannes Berg &lt;johannes.berg@intel.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>wifi: nxp: add nxpwifi driver for IW61x</title>
<updated>2026-07-15T12:52:52+00:00</updated>
<author>
<name>Jeff Chen</name>
<email>jeff.chen_1@nxp.com</email>
</author>
<published>2026-06-05T02:33:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.toradex.cn/cgit/linux-toradex.git/commit/?id=73b01e57ed3e3d6102c0cbcb21f62086c5429437'/>
<id>73b01e57ed3e3d6102c0cbcb21f62086c5429437</id>
<content type='text'>
Add support for the NXP IW61x wireless devices.

The nxpwifi driver implements a full-MAC design and integrates with
cfg80211 for configuration and control, supporting both station (STA)
and access point (AP) modes.

The driver provides a firmware-based command/event interface using TLV
messages, with the core handling command processing, event dispatching,
and device lifecycle management. A SDIO transport layer is implemented
to support IW61x devices.

Key features include:
- 802.11n/ac/ax (HT/VHT/HE) capability support
- Scan, association, and connection management
- Data path handling for TX/RX, including aggregation and reorder
- WMM QoS support and traffic prioritization
- 802.11h (DFS/TPC) support for regulatory compliance
- cfg80211 integration for STA and AP operations
- Debugfs and ethtool support
- Wake-on-LAN support

The driver translates cfg80211 configuration into firmware commands
and implements required data path processing in software where needed.

Signed-off-by: Jeff Chen &lt;jeff.chen_1@nxp.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Add support for the NXP IW61x wireless devices.

The nxpwifi driver implements a full-MAC design and integrates with
cfg80211 for configuration and control, supporting both station (STA)
and access point (AP) modes.

The driver provides a firmware-based command/event interface using TLV
messages, with the core handling command processing, event dispatching,
and device lifecycle management. A SDIO transport layer is implemented
to support IW61x devices.

Key features include:
- 802.11n/ac/ax (HT/VHT/HE) capability support
- Scan, association, and connection management
- Data path handling for TX/RX, including aggregation and reorder
- WMM QoS support and traffic prioritization
- 802.11h (DFS/TPC) support for regulatory compliance
- cfg80211 integration for STA and AP operations
- Debugfs and ethtool support
- Wake-on-LAN support

The driver translates cfg80211 configuration into firmware commands
and implements required data path processing in software where needed.

Signed-off-by: Jeff Chen &lt;jeff.chen_1@nxp.com&gt;
</pre>
</div>
</content>
</entry>
</feed>
