On 11/10/15(Sun) 14:23, Stefan Sperling wrote:
> The index into sc->txq used by iwm_tx() is only initialized for
> management frames. For data frames, iwm picks a garbage index off
> the stack which is not initialized unless a mgmt frame was processed
> first in the same loop.
>
> This could end rather badly. Fix it the easy way for now, because
> overall qos handling needs more love than just this.
Why not using an "enum ieee80211_edca_ac" while here? Plus does it make
sense to pass a constant argument to iwm_tx()? Anyway I'm fine with
this.
>
> Index: if_iwm.c
> ===================================================================
> RCS file: /cvs/src/sys/dev/pci/if_iwm.c,v
> retrieving revision 1.55
> diff -u -p -r1.55 if_iwm.c
> --- if_iwm.c 11 Oct 2015 10:22:28 -0000 1.55
> +++ if_iwm.c 11 Oct 2015 12:15:25 -0000
> @@ -5572,7 +5572,7 @@ iwm_start(struct ifnet *ifp)
> struct ieee80211_node *ni;
> struct ether_header *eh;
> struct mbuf *m;
> - int ac;
> + int ac = EDCA_AC_BE; /* XXX */
>
> if ((ifp->if_flags & (IFF_RUNNING | IFF_OACTIVE)) != IFF_RUNNING)
> return;
> @@ -5588,7 +5588,6 @@ iwm_start(struct ifnet *ifp)
> IF_DEQUEUE(&ic->ic_mgtq, m);
> if (m) {
> ni = m->m_pkthdr.ph_cookie;
> - ac = 0;
> goto sendit;
> }
> if (ic->ic_state != IEEE80211_S_RUN) {
>