From 97b3d0426579237de9c02fdf349f781514e85e2b Mon Sep 17 00:00:00 2001 From: Srikanth Marepalli Date: Wed, 3 Jul 2024 01:47:40 +0530 Subject: [PATCH 1/6] qcacld-3.0: Fix the AKM precedence order for RSN IE When the AP is configured with multiple AKMs for eg. SuiteB and FT-SuiteB then Supplicant selects the FT-SuiteB based on its precedence order but driver was selecting SuiteB due to its incorrect AKM precedence. Due to this the RSN IE in assoc-request was filled with SuiteB AKM but all other IEs were used of FT-SuiteB as sent by the Supplicant. And this is resulting in association failure. Fix the AKM precedence in the order of more secure AKM. Change-Id: I96ff786924778d336507e3bca4a38de4d7c07ffc CRs-Fixed: 3861554 --- core/sme/src/csr/csr_util.c | 76 ++++++++++++++++++------------------- 1 file changed, 38 insertions(+), 38 deletions(-) diff --git a/core/sme/src/csr/csr_util.c b/core/sme/src/csr/csr_util.c index 0343476c116a..f8c2f48b711c 100644 --- a/core/sme/src/csr/csr_util.c +++ b/core/sme/src/csr/csr_util.c @@ -2451,6 +2451,7 @@ static void csr_update_key_mgmt_crypto_param(struct wlan_objmgr_vdev *vdev, { int32_t key_mgmt = 0; int32_t neg_akm; + uint8_t i; neg_akm = wlan_crypto_get_param(vdev, WLAN_CRYPTO_PARAM_KEY_MGMT); if (neg_akm < 0) { @@ -2458,69 +2459,66 @@ static void csr_update_key_mgmt_crypto_param(struct wlan_objmgr_vdev *vdev, return; } - SET_PARAM(neg_akm, - wlan_crypto_rsn_suite_to_keymgmt(ap_rsn.akm_suite[0])); + for (i = 0; i < ap_rsn.akm_suite_cnt; i++) + SET_PARAM(neg_akm, + wlan_crypto_rsn_suite_to_keymgmt(ap_rsn.akm_suite[i])); /* * As there can be multiple AKM present select the most secured AKM * present */ - if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_SAE)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_SAE); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_SAE)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_SAE); + if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B_192)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B_192); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B); - else if (HAS_PARAM(neg_akm, - WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B_192)) - SET_PARAM(key_mgmt, - WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B_192); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FILS_SHA256)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FILS_SHA256); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA384)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA384); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FILS_SHA384)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FILS_SHA384); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA256)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA256); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA384)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA384); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_OWE)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_OWE); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_DPP)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_DPP); - else if (HAS_PARAM(neg_akm, - WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384)) - SET_PARAM(key_mgmt, - WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_PSK)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_PSK); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FILS_SHA256)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FILS_SHA256); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_PSK)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_PSK); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SHA256)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SHA256); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_PSK_SHA256)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_PSK_SHA256); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_DPP)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_DPP); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_SAE)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_SAE); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_SAE)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_SAE); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_PSK_SHA384)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_PSK_SHA384); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_FT_PSK)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_PSK); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SHA256)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SHA256); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_PSK_SHA384)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_PSK_SHA384); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_PSK_SHA256)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_PSK_SHA256); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_IEEE8021X); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_PSK)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_PSK); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_WPA_NONE)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_WPA_NONE); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_OSEN)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_OSEN); + else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_OWE)) + SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_OWE); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_WAPI_PSK)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_WAPI_PSK); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_WAPI_CERT)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_WAPI_CERT); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_CCKM)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_CCKM); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_OSEN)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_OSEN); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_WPS)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_WPS); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_IEEE8021X); else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_NO_WPA)) SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_NO_WPA); - else if (HAS_PARAM(neg_akm, WLAN_CRYPTO_KEY_MGMT_WPA_NONE)) - SET_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_WPA_NONE); else /* use original if no akm match */ key_mgmt = neg_akm; @@ -2533,6 +2531,7 @@ static void csr_update_ucast_cipher_crypto_param(struct wlan_objmgr_vdev *vdev, { int32_t ucastcipherset = 0; int32_t neg_ucastcipher; + uint8_t i; neg_ucastcipher = wlan_crypto_get_param(vdev, WLAN_CRYPTO_PARAM_UCAST_CIPHER); @@ -2541,8 +2540,9 @@ static void csr_update_ucast_cipher_crypto_param(struct wlan_objmgr_vdev *vdev, return; } - SET_PARAM(neg_ucastcipher, - wlan_crypto_rsn_suite_to_cipher(ap_rsn.pwise_cipher_suites[0])); + for (i = 0; i < ap_rsn.pwise_cipher_suite_count; i++) + SET_PARAM(neg_ucastcipher, + wlan_crypto_rsn_suite_to_cipher(ap_rsn.pwise_cipher_suites[i])); /* * As there can be multiple ucastcipher present select the most secured From 790d2cd6c9dbb822ac155deb25d3994cd2e4dcb2 Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Tue, 9 Jul 2024 03:38:24 -0700 Subject: [PATCH 2/6] Release 2.0.8.34S Release 2.0.8.34S Change-Id: I293aecf6a1d2657c78315f7c334779b8283a3745 CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index 8432ca26e339..d750097bf8b7 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "R" +#define QWLAN_VERSION_EXTRA "S" #define QWLAN_VERSION_BUILD 34 -#define QWLAN_VERSIONSTR "2.0.8.34R" +#define QWLAN_VERSIONSTR "2.0.8.34S" #endif /* QWLAN_VERSION_H */ From da35d8eb464e58166dd19b74a4c2959e6e0b7778 Mon Sep 17 00:00:00 2001 From: Aravind Kishore Sukla Date: Mon, 6 Jun 2022 16:39:51 +0530 Subject: [PATCH 3/6] qcacld-3.0: Update wiphy max_num_akms_connect variable Update wiphy->max_num_akms_connect to wiphy->max_num_akm_suites, based on the upstream kernel change. Change-Id: I54455b1d3fc162ddea5a0f9380f66a4a06236076 CRs-Fixed: 3214543 --- core/hdd/src/wlan_hdd_cfg80211.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/core/hdd/src/wlan_hdd_cfg80211.c b/core/hdd/src/wlan_hdd_cfg80211.c index 8531cf162dc0..32ef0a23a050 100644 --- a/core/hdd/src/wlan_hdd_cfg80211.c +++ b/core/hdd/src/wlan_hdd_cfg80211.c @@ -17359,7 +17359,7 @@ wlan_hdd_update_akm_suit_info(struct wiphy *wiphy) static void wlan_hdd_update_max_connect_akm(struct wiphy *wiphy) { - wiphy->max_num_akms_connect = WLAN_CM_MAX_CONNECT_AKMS; + wiphy->max_num_akm_suites = WLAN_CM_MAX_CONNECT_AKMS; } #else static void From d4e50bce791c0384c97dfe40b0098b8d6eb0c6a3 Mon Sep 17 00:00:00 2001 From: Srikanth Marepalli Date: Sat, 4 May 2024 00:42:26 +0530 Subject: [PATCH 4/6] qcacld-3.0: Enable CFG80211_MULTI_AKM_CONNECT_SUPPORT from kernelv6.0 Current code supports CFG80211_MULTI_AKM_CONNECT_SUPPORT only for v5.15 kernel. Enable this feature support from kernelv6.0 by default. Change-Id: I6fbf83df54fd898abde0546f526b193a6d8dc620 CRs-Fixed: 3806550 --- core/hdd/src/wlan_hdd_cfg80211.h | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/core/hdd/src/wlan_hdd_cfg80211.h b/core/hdd/src/wlan_hdd_cfg80211.h index f59eccad6adf..08cdc03c2bb3 100644 --- a/core/hdd/src/wlan_hdd_cfg80211.h +++ b/core/hdd/src/wlan_hdd_cfg80211.h @@ -208,6 +208,20 @@ extern const struct nla_policy wlan_hdd_wisa_cmd_policy[ #define USE_CFG80211_DEL_STA_V2 #endif +/* + * CFG80211_MULTI_AKM_CONNECT_SUPPORT + * used to indicate the Linux kernel contains support for multi AKM connect + * support + * + * This feature was introduced in Linux Kernel 6.0 via: + * ecad3b0b99bf wifi: cfg80211: Increase akm_suites array size in + * cfg80211_crypto_settings. + */ +#if (LINUX_VERSION_CODE >= KERNEL_VERSION(6, 0, 0) || \ + (defined CFG80211_MAX_NUM_AKM_SUITES)) +#define CFG80211_MULTI_AKM_CONNECT_SUPPORT 1 +#endif + #ifdef CFG80211_MULTI_AKM_CONNECT_SUPPORT #define WLAN_CM_MAX_CONNECT_AKMS 5 #endif From c9f42e357d4163050af4996b26b08768aad76d7e Mon Sep 17 00:00:00 2001 From: Srikanth Marepalli Date: Sat, 4 May 2024 01:56:51 +0530 Subject: [PATCH 5/6] qcacld-3.0: Update connect request crypto parameters Update the connect request crypto parameters based on the new kernel changes to increase the size of the akm_suites array in connect request Change-Id: I36eb265d3dafe9d822879fdbed340ba0c6bb7225 CRs-Fixed: 3806556 --- core/hdd/src/wlan_hdd_cfg80211.c | 86 +++++++------------------------- 1 file changed, 17 insertions(+), 69 deletions(-) diff --git a/core/hdd/src/wlan_hdd_cfg80211.c b/core/hdd/src/wlan_hdd_cfg80211.c index 32ef0a23a050..76831317f09b 100644 --- a/core/hdd/src/wlan_hdd_cfg80211.c +++ b/core/hdd/src/wlan_hdd_cfg80211.c @@ -20513,7 +20513,23 @@ static bool wlan_hdd_is_akm_suite_fils(uint32_t key_mgmt) } } +static int +hdd_get_num_akm_suites(const struct cfg80211_connect_params *req) +{ + return req->crypto.n_akm_suites; +} + +static uint32_t* +hdd_get_akm_suites(const struct cfg80211_connect_params *req) +{ + return (uint32_t *)req->crypto.akm_suites; +} + #ifdef CFG80211_MULTI_AKM_CONNECT_SUPPORT +#define MAX_AKM_SUITES WLAN_CM_MAX_CONNECT_AKMS +#else +#define MAX_AKM_SUITES NL80211_MAX_NR_AKM_SUITES +#endif /** * hdd_populate_crypto_akm_type() - populate akm type for crypto * @vdev: pointed to vdev obmgr @@ -20533,64 +20549,9 @@ hdd_populate_crypto_akm_type(struct wlan_objmgr_vdev *vdev, uint32_t set_val = 0; wlan_crypto_key_mgmt akm; - if (req->crypto.n_connect_akm_suites) { - for (i = 0; i < req->crypto.n_connect_akm_suites && - i < WLAN_CM_MAX_CONNECT_AKMS; i++) { - akm = osif_nl_to_crypto_akm_type( - req->crypto.connect_akm_suites[i]); - - HDD_SET_BIT(set_val, akm); - } - - status = wlan_crypto_set_vdev_param(vdev, - WLAN_CRYPTO_PARAM_KEY_MGMT, - set_val); - if (QDF_IS_STATUS_ERROR(status)) - hdd_err("Failed to set akm type %0x to crypto", - set_val); - - status = wlan_crypto_set_vdev_param( - vdev, WLAN_CRYPTO_PARAM_ORIG_KEY_MGMT, set_val); - if (QDF_IS_STATUS_ERROR(status)) - hdd_err("Failed to set original akm type %0x to crypto", - set_val); - } else { - set_val = 0; - /* Reset to none */ - HDD_SET_BIT(set_val, WLAN_CRYPTO_KEY_MGMT_NONE); - wlan_crypto_set_vdev_param(vdev, - WLAN_CRYPTO_PARAM_KEY_MGMT, - set_val); - wlan_crypto_set_vdev_param(vdev, - WLAN_CRYPTO_PARAM_ORIG_KEY_MGMT, - set_val); - } -} - -static int -hdd_get_num_akm_suites(const struct cfg80211_connect_params *req) -{ - return req->crypto.n_connect_akm_suites; -} - -static uint32_t* -hdd_get_akm_suites(const struct cfg80211_connect_params *req) -{ - return (uint32_t *)req->crypto.connect_akm_suites; -} -#else -static void -hdd_populate_crypto_akm_type(struct wlan_objmgr_vdev *vdev, - const struct cfg80211_connect_params *req) -{ - QDF_STATUS status; - uint32_t i = 0; - uint32_t set_val = 0; - wlan_crypto_key_mgmt akm; - if (req->crypto.n_akm_suites) { for (i = 0; i < req->crypto.n_akm_suites && - i < NL80211_MAX_NR_AKM_SUITES; i++) { + i < MAX_AKM_SUITES; i++) { akm = osif_nl_to_crypto_akm_type( req->crypto.akm_suites[i]); @@ -20623,19 +20584,6 @@ hdd_populate_crypto_akm_type(struct wlan_objmgr_vdev *vdev, } } -static int -hdd_get_num_akm_suites(const struct cfg80211_connect_params *req) -{ - return req->crypto.n_akm_suites; -} - -static uint32_t* -hdd_get_akm_suites(const struct cfg80211_connect_params *req) -{ - return (uint32_t *)req->crypto.akm_suites; -} -#endif - static bool wlan_hdd_is_conn_type_fils(struct cfg80211_connect_params *req) { enum nl80211_auth_type auth_type = req->auth_type; From d4e8774068cab408d7ef6697c6ccb13d396ef303 Mon Sep 17 00:00:00 2001 From: Ravindra Konda Date: Mon, 15 Jul 2024 01:08:10 -0700 Subject: [PATCH 6/6] Release 2.0.8.34T Release 2.0.8.34T Change-Id: Idacaae744b054dc32c1fc9b4874945459884a0dc CRs-Fixed: 774533 --- core/mac/inc/qwlan_version.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/core/mac/inc/qwlan_version.h b/core/mac/inc/qwlan_version.h index d750097bf8b7..ad8382fecb06 100644 --- a/core/mac/inc/qwlan_version.h +++ b/core/mac/inc/qwlan_version.h @@ -32,9 +32,9 @@ #define QWLAN_VERSION_MAJOR 2 #define QWLAN_VERSION_MINOR 0 #define QWLAN_VERSION_PATCH 8 -#define QWLAN_VERSION_EXTRA "S" +#define QWLAN_VERSION_EXTRA "T" #define QWLAN_VERSION_BUILD 34 -#define QWLAN_VERSIONSTR "2.0.8.34S" +#define QWLAN_VERSIONSTR "2.0.8.34T" #endif /* QWLAN_VERSION_H */