From 2cfc1dab45df4d5bbd93c42ede0036dc24f89913 Mon Sep 17 00:00:00 2001 From: Kiran Kumar Lokere Date: Mon, 26 Apr 2021 20:10:15 -0700 Subject: [PATCH] qcacmn: Update the security check mask for 6GHz AP Update the security check mask value for 6GHz AP. Change-Id: I8d9637a95c6191124372a7bdba119837e6553ed4 CRs-Fixed: 2930941 --- .../crypto/inc/wlan_crypto_global_def.h | 6 ++++-- .../crypto/src/wlan_crypto_def_i.h | 4 +++- .../crypto/src/wlan_crypto_global_api.c | 4 ++++ .../core/src/wlan_cm_bss_scoring.c | 4 +++- umac/scan/core/src/wlan_scan_cache_db.c | 20 +++++++++++++++++-- 5 files changed, 32 insertions(+), 6 deletions(-) diff --git a/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h b/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h index e42a1a65cf05..df72eff262b8 100644 --- a/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h +++ b/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h @@ -220,6 +220,8 @@ typedef enum wlan_crypto_key_mgmt { WLAN_CRYPTO_KEY_MGMT_OWE = 22, WLAN_CRYPTO_KEY_MGMT_DPP = 23, WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384 = 24, + WLAN_CRYPTO_KEY_MGMT_FT_PSK_SHA384 = 25, + WLAN_CRYPTO_KEY_MGMT_PSK_SHA384 = 26, /** Keep WLAN_CRYPTO_KEY_MGMT_MAX at the end. */ WLAN_CRYPTO_KEY_MGMT_MAX = WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384, } wlan_crypto_key_mgmt; @@ -235,8 +237,8 @@ enum wlan_crypto_key_type { #define DEFAULT_KEYMGMT_6G_MASK 0xFFFFFFFF -/* AKM wlan_crypto_key_mgmt 0-8, 12-15 and 24 are not allowed. */ -#define ALLOWED_KEYMGMT_6G_MASK 0xFEFF0E00 +/* AKM wlan_crypto_key_mgmt 1, 6, 8, 25 and 26 are not allowed. */ +#define ALLOWED_KEYMGMT_6G_MASK 0x01FFFEBD /* * enum fils_erp_cryptosuite: this enum defines the cryptosuites used diff --git a/umac/cmn_services/crypto/src/wlan_crypto_def_i.h b/umac/cmn_services/crypto/src/wlan_crypto_def_i.h index 9be3fb714b36..a891ea327087 100644 --- a/umac/cmn_services/crypto/src/wlan_crypto_def_i.h +++ b/umac/cmn_services/crypto/src/wlan_crypto_def_i.h @@ -1,5 +1,5 @@ /* - * Copyright (c) 2017-2020 The Linux Foundation. All rights reserved. + * Copyright (c) 2017-2021 The Linux Foundation. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -266,6 +266,8 @@ static inline void wlan_crypto_put_be64(u8 *a, u64 val) #define RSN_AUTH_KEY_MGMT_FT_FILS_SHA384\ WLAN_RSN_SEL(17) #define RSN_AUTH_KEY_MGMT_OWE WLAN_RSN_SEL(18) +#define RSN_AUTH_KEY_MGMT_FT_PSK_SHA384 WLAN_RSN_SEL(19) +#define RSN_AUTH_KEY_MGMT_PSK_SHA384 WLAN_RSN_SEL(20) #define RSN_AUTH_KEY_MGMT_CCKM (WLAN_RSN_CCKM_AKM) #define RSN_AUTH_KEY_MGMT_OSEN (0x019a6f50) diff --git a/umac/cmn_services/crypto/src/wlan_crypto_global_api.c b/umac/cmn_services/crypto/src/wlan_crypto_global_api.c index c61d97fc0565..7504ed44a7de 100644 --- a/umac/cmn_services/crypto/src/wlan_crypto_global_api.c +++ b/umac/cmn_services/crypto/src/wlan_crypto_global_api.c @@ -2627,6 +2627,10 @@ static int32_t wlan_crypto_rsn_suite_to_keymgmt(const uint8_t *sel) return WLAN_CRYPTO_KEY_MGMT_DPP; case RSN_AUTH_KEY_MGMT_FT_802_1X_SUITE_B_384: return WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384; + case RSN_AUTH_KEY_MGMT_FT_PSK_SHA384: + return WLAN_CRYPTO_KEY_MGMT_FT_PSK_SHA384; + case RSN_AUTH_KEY_MGMT_PSK_SHA384: + return WLAN_CRYPTO_KEY_MGMT_PSK_SHA384; } return status; diff --git a/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c b/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c index 3566a567ec5d..6329c0a90ef1 100644 --- a/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c +++ b/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c @@ -1848,8 +1848,10 @@ bool wlan_cm_6ghz_allowed_for_akm(struct wlan_objmgr_psoc *psoc, return false; /* if check_6ghz_security is set validate all checks for 6Ghz */ - if (!(rsn_caps & WLAN_CRYPTO_RSN_CAP_MFP_ENABLED)) + if (!(rsn_caps & WLAN_CRYPTO_RSN_CAP_MFP_ENABLED)) { + mlme_debug("PMF not enabled for 6GHz AP"); return false; + } /* for SAE we need to check H2E support */ if (!(QDF_HAS_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_SAE) || diff --git a/umac/scan/core/src/wlan_scan_cache_db.c b/umac/scan/core/src/wlan_scan_cache_db.c index 1cf0de0f617b..5f73e1e7b89b 100644 --- a/umac/scan/core/src/wlan_scan_cache_db.c +++ b/umac/scan/core/src/wlan_scan_cache_db.c @@ -1038,15 +1038,31 @@ QDF_STATUS __scm_handle_bcn_probe(struct scan_bcn_probe_event *bcn) qdf_mem_free(scan_node); continue; } + if ((QDF_HAS_PARAM(sec_params.ucastcipherset, + WLAN_CRYPTO_CIPHER_NONE)) || + (QDF_HAS_PARAM(sec_params.ucastcipherset, + WLAN_CRYPTO_CIPHER_TKIP)) || + (QDF_HAS_PARAM(sec_params.ucastcipherset, + WLAN_CRYPTO_CIPHER_WEP_40)) || + (QDF_HAS_PARAM(sec_params.ucastcipherset, + WLAN_CRYPTO_CIPHER_WEP_104))) { + scm_info("Drop frame from "QDF_MAC_ADDR_FMT + ": Invalid sec type %0X for 6GHz AP", + QDF_MAC_ADDR_REF( + scan_entry->bssid.bytes), + sec_params.ucastcipherset); + continue; + } if (!wlan_cm_6ghz_allowed_for_akm(psoc, sec_params.key_mgmt, sec_params.rsn_caps, util_scan_entry_rsnxe(scan_entry), 0, false)) { scm_info("Drop frame from "QDF_MAC_ADDR_FMT - ": Security check failed for 6GHz AP", + ": Invalid AKM suite %0X for 6GHz AP", QDF_MAC_ADDR_REF( - scan_entry->bssid.bytes)); + scan_entry->bssid.bytes), + sec_params.key_mgmt); util_scan_free_cache_entry(scan_entry); qdf_mem_free(scan_node); continue;