On Mon, 2023-01-02 at 15:47 -0800, Doug Brown wrote: > The existing code only converts the first IE to a TLV, but it returns > a > value that takes the length of all IEs into account. When there is > more > than one IE (which happens with modern wpa_supplicant versions for > example), the returned length is too long and extra junk TLVs get > sent > to the firmware, resulting in an association failure. > > Fix this by returning a length that only factors in the single IE > that > was converted. The firmware doesn't seem to support the additional > IEs, > so there is no value in trying to convert them to additional TLVs. > > Fixes: e86dc1ca4676 ("Libertas: cfg80211 support") > Signed-off-by: Doug Brown <doug@xxxxxxxxxxxxx> > --- > drivers/net/wireless/marvell/libertas/cfg.c | 7 +++---- > 1 file changed, 3 insertions(+), 4 deletions(-) > > diff --git a/drivers/net/wireless/marvell/libertas/cfg.c > b/drivers/net/wireless/marvell/libertas/cfg.c > index 3e065cbb0af9..fcc5420ec7ea 100644 > --- a/drivers/net/wireless/marvell/libertas/cfg.c > +++ b/drivers/net/wireless/marvell/libertas/cfg.c > @@ -432,10 +432,9 @@ static int lbs_add_wpa_tlv(u8 *tlv, const u8 > *ie, u8 ie_len) > *tlv++ = 0; > tlv_len = *tlv++ = *ie++; > *tlv++ = 0; > - while (tlv_len--) > - *tlv++ = *ie++; > - /* the TLV is two bytes larger than the IE */ > - return ie_len + 2; > + memcpy(tlv, ie, tlv_len); > + /* the TLV has a four-byte header */ > + return tlv_len + 4; Since you're removing ie_len usage in the function, you might as well remove it from the function's arguments. Can you also update the comments to say something like "only copy the first IE into the command buffer". Lastly, should you check the IE to make sure you're copying the WPA or WMM IE that the firmware expects? What other IEs does wpa_supplicant/cfg80211 add these days? Dan > } > > /*