diff --git a/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/cmn_defs/inc/wlan_cmn_ieee80211.h b/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/cmn_defs/inc/wlan_cmn_ieee80211.h index f4ccb035f530..7bb3e657a8d9 100644 --- a/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/cmn_defs/inc/wlan_cmn_ieee80211.h +++ b/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/cmn_defs/inc/wlan_cmn_ieee80211.h @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -918,6 +918,7 @@ enum wlan_status_code { #define WLAN_ASE_SHA256_PSK 0x100 #define WLAN_ASE_WPS 0x200 +#define RSN_CAP_MFP_DISABLED 0x00 #define RSN_CAP_MFP_CAPABLE 0x80 #define RSN_CAP_MFP_REQUIRED 0x40 diff --git a/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/inc/wlan_crypto_global_api.h b/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/inc/wlan_crypto_global_api.h index 4f1eaf957603..a9741e6367b9 100644 --- a/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/inc/wlan_crypto_global_api.h +++ b/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/inc/wlan_crypto_global_api.h @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -1130,4 +1130,23 @@ wlan_crypto_set_sae_single_pmk_info(struct wlan_objmgr_vdev *vdev, QDF_STATUS wlan_crypto_create_fils_rik(uint8_t *rrk, uint8_t rrk_len, uint8_t *rik, uint32_t *rik_len); #endif /* WLAN_FEATURE_FILS_SK */ + +/** + * wlan_crypto_rsn_suite_to_cipher - This API converts a RSN cipher selector OUI + * to an internal cipher algorithm. Where appropriate we also record any key + * length. + * @sel: input RSN suite + * + * Return: cipher suite value + */ +int32_t wlan_crypto_rsn_suite_to_cipher(const uint8_t *sel); + +/** + * wlan_crypto_rsn_suite_to_keymgmt() - This API converts an RSN key management/ + * authentication algorithm to an internal code. + * @sel: input RSN suite + * + * Return: keymgmt value + */ +int32_t wlan_crypto_rsn_suite_to_keymgmt(const uint8_t *sel); #endif /* end of _WLAN_CRYPTO_GLOBAL_API_H_ */ diff --git a/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h b/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h index df72eff262b8..d5f386bef272 100644 --- a/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h +++ b/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h @@ -1,5 +1,6 @@ /* * Copyright (c) 2017-2021 The Linux Foundation. All rights reserved. + * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -157,7 +158,7 @@ typedef enum wlan_crypto_auth_mode { WLAN_CRYPTO_AUTH_SAE = 9, WLAN_CRYPTO_AUTH_FILS_SK = 10, /** Keep WLAN_CRYPTO_AUTH_MAX at the end. */ - WLAN_CRYPTO_AUTH_MAX = WLAN_CRYPTO_AUTH_FILS_SK, + WLAN_CRYPTO_AUTH_MAX, } wlan_crypto_auth_mode; /* crypto capabilities */ @@ -223,7 +224,7 @@ typedef enum wlan_crypto_key_mgmt { WLAN_CRYPTO_KEY_MGMT_FT_PSK_SHA384 = 25, WLAN_CRYPTO_KEY_MGMT_PSK_SHA384 = 26, /** Keep WLAN_CRYPTO_KEY_MGMT_MAX at the end. */ - WLAN_CRYPTO_KEY_MGMT_MAX = WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384, + WLAN_CRYPTO_KEY_MGMT_MAX, } wlan_crypto_key_mgmt; enum wlan_crypto_key_type { @@ -308,6 +309,10 @@ struct wlan_crypto_pmksa { * @key_mgmt: key mgmt * @pmksa: pmksa * @rsn_caps: rsn_capability + * @orig_ucastcipher: connection request unicast ciphers + * @orig_mcastcipher: connection request multicast cipher + * @orig_key_mgmt: connection request key mgmt + * @orig_rsn_caps: connection request rsn_capability * * This structure holds crypto params for peer or vdev */ @@ -320,6 +325,10 @@ struct wlan_crypto_params { uint32_t key_mgmt; struct wlan_crypto_pmksa *pmksa[WLAN_CRYPTO_MAX_PMKID]; uint16_t rsn_caps; + uint32_t orig_ucastcipher; + uint32_t orig_mcastcipher; + uint32_t orig_key_mgmt; + uint16_t orig_rsn_caps; }; typedef enum wlan_crypto_param_type { @@ -331,6 +340,10 @@ typedef enum wlan_crypto_param_type { WLAN_CRYPTO_PARAM_RSN_CAP, WLAN_CRYPTO_PARAM_KEY_MGMT, WLAN_CRYPTO_PARAM_PMKSA, + WLAN_CRYPTO_PARAM_ORIG_UCAST_CIPHER, + WLAN_CRYPTO_PARAM_ORIG_MCAST_CIPHER, + WLAN_CRYPTO_PARAM_ORIG_KEY_MGMT, + WLAN_CRYPTO_PARAM_ORIG_RSN_CAP, } wlan_crypto_param_type; /** diff --git a/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/src/wlan_crypto_global_api.c b/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/src/wlan_crypto_global_api.c index 6b496baa3dbf..8bf19d70cbb6 100644 --- a/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/src/wlan_crypto_global_api.c +++ b/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/src/wlan_crypto_global_api.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2021 The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -172,6 +172,18 @@ static QDF_STATUS wlan_crypto_set_param(struct wlan_crypto_params *crypto_params case WLAN_CRYPTO_PARAM_KEY_MGMT: status = wlan_crypto_set_key_mgmt(crypto_params, value); break; + case WLAN_CRYPTO_PARAM_ORIG_UCAST_CIPHER: + status = wlan_crypto_set_orig_ucastcipher(crypto_params, value); + break; + case WLAN_CRYPTO_PARAM_ORIG_MCAST_CIPHER: + status = wlan_crypto_set_orig_mcastcipher(crypto_params, value); + break; + case WLAN_CRYPTO_PARAM_ORIG_KEY_MGMT: + status = wlan_crypto_set_orig_key_mgmt(crypto_params, value); + break; + case WLAN_CRYPTO_PARAM_ORIG_RSN_CAP: + status = wlan_crypto_set_orig_rsn_cap(crypto_params, value); + break; default: status = QDF_STATUS_E_INVAL; } @@ -279,6 +291,18 @@ static int32_t wlan_crypto_get_param_value(wlan_crypto_param_type param, case WLAN_CRYPTO_PARAM_KEY_MGMT: value = wlan_crypto_get_key_mgmt(crypto_params); break; + case WLAN_CRYPTO_PARAM_ORIG_UCAST_CIPHER: + value = wlan_crypto_get_orig_ucastcipher(crypto_params); + break; + case WLAN_CRYPTO_PARAM_ORIG_MCAST_CIPHER: + value = wlan_crypto_get_orig_mcastcipher(crypto_params); + break; + case WLAN_CRYPTO_PARAM_ORIG_KEY_MGMT: + value = wlan_crypto_get_orig_key_mgmt(crypto_params); + break; + case WLAN_CRYPTO_PARAM_ORIG_RSN_CAP: + value = wlan_crypto_get_orig_rsn_cap(crypto_params); + break; default: value = -1; } @@ -2553,12 +2577,7 @@ static int32_t wlan_crypto_wpa_suite_to_keymgmt(const uint8_t *sel) return status; } -/* - * Convert a RSN cipher selector OUI to an internal - * cipher algorithm. Where appropriate we also - * record any key length. - */ -static int32_t wlan_crypto_rsn_suite_to_cipher(const uint8_t *sel) +int32_t wlan_crypto_rsn_suite_to_cipher(const uint8_t *sel) { uint32_t w = LE_READ_4(sel); int32_t status = -1; @@ -2588,11 +2607,8 @@ static int32_t wlan_crypto_rsn_suite_to_cipher(const uint8_t *sel) return status; } -/* - * Convert an RSN key management/authentication algorithm - * to an internal code. - */ -static int32_t wlan_crypto_rsn_suite_to_keymgmt(const uint8_t *sel) + +int32_t wlan_crypto_rsn_suite_to_keymgmt(const uint8_t *sel) { uint32_t w = LE_READ_4(sel); int32_t status = -1; diff --git a/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/src/wlan_crypto_param_handling.c b/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/src/wlan_crypto_param_handling.c index 33d24db046d3..12a78b4334c9 100644 --- a/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/src/wlan_crypto_param_handling.c +++ b/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/src/wlan_crypto_param_handling.c @@ -1,5 +1,6 @@ /* * Copyright (c) 2017-2019 The Linux Foundation. All rights reserved. + * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -302,3 +303,137 @@ int32_t wlan_crypto_get_key_mgmt(struct wlan_crypto_params *crypto_params) { return crypto_params->key_mgmt; } + +/** + * wlan_crypto_set_orig_ucastcipher - called by ucfg to configure connection + * request unicast ciphers in vdev + * @crypto_params: pointer to crypto params structure + * @value: bitmap value of all supported unicast ciphers + * + * This function gets called from ucfg to configure unicast ciphers in vdev + * + * Return: QDF_STATUS_SUCCESS - in case of success + */ +QDF_STATUS +wlan_crypto_set_orig_ucastcipher(struct wlan_crypto_params *crypto_params, + uint32_t value) +{ + crypto_params->orig_ucastcipher = value; + + return QDF_STATUS_SUCCESS; +} + +/** + * wlan_crypto_get_orig_ucastcipher - called by ucfg to get connection request + * ucastcipher value from vdev + * @crypto_params: pointer to crypto params structure + * + * This function gets called from ucfg to get supported unicast ciphers + * + * Return: bitmap value of all supported unicast ciphers + */ +int32_t +wlan_crypto_get_orig_ucastcipher(struct wlan_crypto_params *crypto_params) +{ + return crypto_params->orig_ucastcipher; +} + +/** + * wlan_crypto_set_orig_mcastcipher - called by ucfg to configure connection + * request mcastcipher in vdev + * @crypto_params: pointer to crypto params structure + * @value: mcast cipher value. + * + * This function gets called from ucfg to configure mcastcipher in vdev + * + * Return: QDF_STATUS_SUCCESS - in case of success + */ +QDF_STATUS +wlan_crypto_set_orig_mcastcipher(struct wlan_crypto_params *crypto_params, + wlan_crypto_cipher_type value) +{ + crypto_params->orig_mcastcipher = value; + + return QDF_STATUS_SUCCESS; +} + +/** + * wlan_crypto_get_orig_mcastcipher - called by ucfg to get connection request + * mcastcipher value from vdev + * @crypto_params: pointer to crypto params structure + * + * This function gets called from ucfg to get mcastcipher of particular vdev + * + * Return: mcast cipher + */ +int32_t +wlan_crypto_get_orig_mcastcipher(struct wlan_crypto_params *crypto_params) +{ + return crypto_params->orig_mcastcipher; +} + +/** + * wlan_crypto_set_orig_key_mgmt - called by ucfg to configure connection + * request key_mgmt in vdev + * @crypto_params: pointer to crypto params structure + * @value: bitmap value of all supported AKMs + * + * This function gets called from ucfg to configure AKMs in vdev + * + * Return: QDF_STATUS_SUCCESS - in case of success + */ +QDF_STATUS +wlan_crypto_set_orig_key_mgmt(struct wlan_crypto_params *crypto_params, + uint32_t value) +{ + crypto_params->orig_key_mgmt = value; + + return QDF_STATUS_SUCCESS; +} + +/** + * wlan_crypto_get_orig_key_mgmt - called by ucfg to get connection request + * key mgmt value from vdev + * @crypto_params: pointer to crypto params structure + * + * This function gets called from ucfg to get supported AKMs + * + * Return: bitmap value of all supported AKMs + */ +int32_t wlan_crypto_get_orig_key_mgmt(struct wlan_crypto_params *crypto_params) +{ + return crypto_params->orig_key_mgmt; +} + +/** + * wlan_crypto_set_orig_rsn_cap - called by ucfg to configure connection + * request RSN capabilities in vdev + * @crypto_params: pointer to crypto params structure + * @value: bitmap value of all supported RSN capabilities + * + * This function gets called from ucfg to configure RSN caps in vdev + * + * Return: QDF_STATUS_SUCCESS - in case of success + */ +QDF_STATUS +wlan_crypto_set_orig_rsn_cap(struct wlan_crypto_params *crypto_params, + uint32_t value) +{ + crypto_params->orig_rsn_caps = value; + + return QDF_STATUS_SUCCESS; +} + +/** + * wlan_crypto_get_orig_rsn_cap - called by ucfg to get connection request + * RSN capabilities from vdev + * @crypto_params: pointer to crypto params structure + * + * This function gets called from ucfg to get supported RSN capabilities + * + * Return: bitmap value of all supported RSN caps + */ +int32_t wlan_crypto_get_orig_rsn_cap(struct wlan_crypto_params *crypto_params) +{ + return crypto_params->orig_rsn_caps; +} diff --git a/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/src/wlan_crypto_param_handling_i.h b/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/src/wlan_crypto_param_handling_i.h index d6198b4b2aa1..718001866cad 100644 --- a/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/src/wlan_crypto_param_handling_i.h +++ b/drivers/staging/qca-wifi-host-cmn/umac/cmn_services/crypto/src/wlan_crypto_param_handling_i.h @@ -1,5 +1,6 @@ /* * Copyright (c) 2017-2018 The Linux Foundation. All rights reserved. + * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -179,4 +180,103 @@ QDF_STATUS wlan_crypto_set_key_mgmt(struct wlan_crypto_params *crypto_params, * Return: bitmap value of all supported unicast ciphers */ int32_t wlan_crypto_get_key_mgmt(struct wlan_crypto_params *crypto_params); + +/** + * wlan_crypto_set_orig_ucastcipher - called by ucfg to configure connection + * request unicast ciphers in vdev + * @crypto_params: pointer to crypto params structure + * @value: bitmap value of all supported unicast ciphers + * + * This function gets called from ucfg to configure unicast ciphers in vdev + * + * Return: QDF_STATUS_SUCCESS - in case of success + */ +QDF_STATUS +wlan_crypto_set_orig_ucastcipher(struct wlan_crypto_params *crypto_params, + uint32_t value); + +/** + * wlan_crypto_get_orig_ucastcipher - called by ucfg to get connection request + * unicast cipher from vdev + * @crypto_params: pointer to crypto params structure + * + * This function gets called from ucfg to get supported unicast ciphers + * + * Return: bitmap value of all supported unicast ciphers + */ +int32_t +wlan_crypto_get_orig_ucastcipher(struct wlan_crypto_params *crypto_params); + +/** + * wlan_crypto_set_orig_mcastcipher - called by ucfg to configure connection + * request mcastcipher in vdev + * @crypto_params: pointer to crypto params structure + * @wlan_crypto_cipher_type: mcast cipher value. + * + * This function gets called from ucfg to configure mcastcipher in vdev + * + * Return: QDF_STATUS_SUCCESS - in case of success + */ +QDF_STATUS +wlan_crypto_set_orig_mcastcipher(struct wlan_crypto_params *crypto_params, + wlan_crypto_cipher_type cipher); +/** + * wlan_crypto_get_orig_mcastcipher - called by ucfg to get connection request + * mcastcipher from vdev + * @crypto_params: pointer to crypto params structure + * + * This function gets called from ucfg to get mcastcipher of particular vdev + * + * Return: mcast cipher + */ +int32_t +wlan_crypto_get_orig_mcastcipher(struct wlan_crypto_params *crypto_params); + +/** + * wlan_crypto_set_orig_key_mgmt - called by ucfg to configure connection + * request key_mgmt in vdev + * @crypto_params: pointer to crypto params structure + * @value: bitmap value of all supported AKMs + * + * This function gets called from ucfg to configure AKMs in vdev + * + * Return: QDF_STATUS_SUCCESS - in case of success + */ +QDF_STATUS +wlan_crypto_set_orig_key_mgmt(struct wlan_crypto_params *crypto_params, + uint32_t value); + +/** + * wlan_crypto_get_orig_key_mgmt - called by ucfg to get connection request key + * mgmt from vdev + * @crypto_params: pointer to crypto params structure + * + * This function gets called from ucfg to get supported AKMs + * + * Return: bitmap value of all supported AKMs + */ +int32_t wlan_crypto_get_orig_key_mgmt(struct wlan_crypto_params *crypto_params); + +/** + * wlan_crypto_set_orig_rsn_cap - called by ucfg to configure + * RSN cap in vdev + * @crypto_params: pointer to crypto params + * @value: bitmap value of all supported RSN cap + * + * This function gets called from ucfg to configure RSN cap in vdev + * + * Return: QDF_STATUS_SUCCESS - in case of success + */ +QDF_STATUS wlan_crypto_set_orig_rsn_cap(struct wlan_crypto_params *crypto_params, + uint32_t value); + +/** + * wlan_crypto_get_orig_rsn_cap - called by ucfg to get RSN cap from vdev + * @crypto_params: pointer to crypto params + * + * This function gets called from ucfg to get supported RSN cap + * + * Return: bitmap value of all supported RSN cap + */ +int32_t wlan_crypto_get_orig_rsn_cap(struct wlan_crypto_params *crypto_params); #endif /* __WLAN_CRYPTO_PARAM_HANDLING_I_H_ */ diff --git a/drivers/staging/qca-wifi-host-cmn/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c b/drivers/staging/qca-wifi-host-cmn/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c index 843c042f6cc9..04d9f3db9d7c 100644 --- a/drivers/staging/qca-wifi-host-cmn/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c +++ b/drivers/staging/qca-wifi-host-cmn/umac/mlme/connection_mgr/core/src/wlan_cm_bss_scoring.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2021, The Linux Foundation. All rights reserved. - * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for any * purpose with or without fee is hereby granted, provided that the above @@ -82,6 +82,7 @@ #define CM_CHAN_WIDTH_WEIGHTAGE 12 #define CM_CHAN_BAND_WEIGHTAGE 2 #define CM_NSS_WEIGHTAGE 16 +#define CM_SECURITY_WEIGHTAGE 4 #define CM_BEAMFORMING_CAP_WEIGHTAGE 2 #define CM_PCL_WEIGHT 10 #define CM_CHANNEL_CONGESTION_WEIGHTAGE 5 @@ -93,6 +94,21 @@ #define CM_MAX_PCT_SCORE 100 #define CM_MAX_INDEX_PER_INI 4 +/** + * This macro give percentage value of security_weightage to be used as per + * security Eg if AP security is WPA 10% will be given for AP. + * + * Indexes are defined in this way. + * 0 Index (BITS 0-7): WPA - Def 25% + * 1 Index (BITS 8-15): WPA2- Def 50% + * 2 Index (BITS 16-23): WPA3- Def 100% + * 3 Index (BITS 24-31): reserved + * + * if AP security is Open/WEP 0% will be given for AP + * These percentage values are stored in HEX. For any index max value, can be 64 + */ +#define CM_SECURITY_INDEX_WEIGHTAGE 0x00643219 + #define CM_BEST_CANDIDATE_MAX_BSS_SCORE (CM_BEST_CANDIDATE_MAX_WEIGHT * 100) #define CM_AVOID_CANDIDATE_MIN_SCORE 1 @@ -535,6 +551,68 @@ static int32_t cm_calculate_nss_score(struct wlan_objmgr_psoc *psoc, prorated_pct) / CM_MAX_PCT_SCORE; } +static int32_t cm_calculate_security_score(struct scoring_cfg *score_config, + struct security_info neg_sec_info) +{ + uint32_t authmode, key_mgmt, ucastcipherset; + uint8_t score_pct = 0; + + authmode = neg_sec_info.authmodeset; + key_mgmt = neg_sec_info.key_mgmt; + ucastcipherset = neg_sec_info.ucastcipherset; + + if (QDF_HAS_PARAM(authmode, WLAN_CRYPTO_AUTH_FILS_SK) || + QDF_HAS_PARAM(authmode, WLAN_CRYPTO_AUTH_SAE) || + QDF_HAS_PARAM(authmode, WLAN_CRYPTO_AUTH_CCKM) || + QDF_HAS_PARAM(authmode, WLAN_CRYPTO_AUTH_RSNA) || + QDF_HAS_PARAM(authmode, WLAN_CRYPTO_AUTH_8021X)) { + if (QDF_HAS_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_SAE) || + QDF_HAS_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FT_SAE) || + QDF_HAS_PARAM(key_mgmt, + WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B) || + QDF_HAS_PARAM(key_mgmt, + WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B_192) || + QDF_HAS_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FILS_SHA256) || + QDF_HAS_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_FILS_SHA384) || + QDF_HAS_PARAM(key_mgmt, + WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA256) || + QDF_HAS_PARAM(key_mgmt, + WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA384) || + QDF_HAS_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_OWE) || + QDF_HAS_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_DPP) || + QDF_HAS_PARAM(key_mgmt, + WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384)) { + /*If security is WPA3, consider score_pct = 100%*/ + score_pct = CM_GET_SCORE_PERCENTAGE( + score_config->security_weight_per_index, + CM_SECURITY_WPA3_INDEX); + } else if (QDF_HAS_PARAM(key_mgmt, WLAN_CRYPTO_KEY_MGMT_PSK) || + QDF_HAS_PARAM(key_mgmt, + WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X) || + QDF_HAS_PARAM(key_mgmt, + WLAN_CRYPTO_KEY_MGMT_FT_PSK) || + QDF_HAS_PARAM(key_mgmt, + WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SHA256) || + QDF_HAS_PARAM(key_mgmt, + WLAN_CRYPTO_KEY_MGMT_PSK_SHA256)) { + /*If security is WPA2, consider score_pct = 50%*/ + score_pct = CM_GET_SCORE_PERCENTAGE( + score_config->security_weight_per_index, + CM_SECURITY_WPA2_INDEX); + } + } else if (QDF_HAS_PARAM(authmode, WLAN_CRYPTO_AUTH_SHARED) || + QDF_HAS_PARAM(authmode, WLAN_CRYPTO_AUTH_WPA) || + QDF_HAS_PARAM(authmode, WLAN_CRYPTO_AUTH_WAPI)) { + /*If security is WPA, consider score_pct = 25%*/ + score_pct = CM_GET_SCORE_PERCENTAGE( + score_config->security_weight_per_index, + CM_SECURITY_WPA_INDEX); + } + + return (score_config->weight_config.security_weightage * score_pct) / + CM_MAX_PCT_SCORE; +} + #ifdef WLAN_POLICY_MGR_ENABLE static uint32_t cm_get_sta_nss(struct wlan_objmgr_psoc *psoc, qdf_freq_t bss_channel_freq, @@ -1401,6 +1479,7 @@ static int cm_calculate_bss_score(struct wlan_objmgr_psoc *psoc, int32_t beamformee_score = 0; int32_t band_score = 0; int32_t nss_score = 0; + int32_t security_score = 0; int32_t congestion_score = 0; int32_t congestion_pct = 0; int32_t oce_wan_score = 0; @@ -1581,7 +1660,16 @@ static int cm_calculate_bss_score(struct wlan_objmgr_psoc *psoc, prorated_pcnt, sta_nss); score += nss_score; - mlme_nofl_debug("Candidate("QDF_MAC_ADDR_FMT" freq %d): rssi %d HT %d VHT %d HE %d su bfer %d phy %d air time frac %d qbss %d cong_pct %d NSS %d ap_tx_pwr_dbm %d oce_subnet_id_present %d sae_pk_cap_present %d prorated_pcnt %d", + /* + * Since older FW will stick to the single AKM for roaming, + * no need to check the fw capability. + */ + security_score = cm_calculate_security_score(score_config, + entry->neg_sec_info); + + score += security_score; + + mlme_nofl_debug("Candidate("QDF_MAC_ADDR_FMT" freq %d): rssi %d HT %d VHT %d HE %d su bfer %d phy %d air time frac %d qbss %d cong_pct %d NSS %d ap_tx_pwr_dbm %d oce_subnet_id_present %d sae_pk_cap_present %d prorated_pcnt %d keymgmt 0x%x", QDF_MAC_ADDR_REF(entry->bssid.bytes), entry->channel.chan_freq, entry->rssi_raw, util_scan_entry_htcap(entry) ? 1 : 0, @@ -1590,14 +1678,15 @@ static int cm_calculate_bss_score(struct wlan_objmgr_psoc *psoc, entry->phy_mode, entry->air_time_fraction, entry->qbss_chan_load, congestion_pct, entry->nss, ap_tx_pwr_dbm, oce_subnet_id_present, - sae_pk_cap_present, prorated_pcnt); + sae_pk_cap_present, prorated_pcnt, + entry->neg_sec_info.key_mgmt); - mlme_nofl_debug("Scores: rssi %d pcl %d ht %d vht %d he %d bfee %d bw %d band %d congestion %d nss %d oce wan %d oce ap tx pwr %d subnet %d sae_pk %d TOTAL %d", + mlme_nofl_debug("Scores: rssi %d pcl %d ht %d vht %d he %d bfee %d bw %d band %d congestion %d nss %d oce wan %d oce ap tx pwr %d subnet %d sae_pk %d security %d TOTAL %d", rssi_score, pcl_score, ht_score, vht_score, he_score, beamformee_score, bandwidth_score, band_score, congestion_score, nss_score, oce_wan_score, oce_ap_tx_pwr_score, oce_subnet_id_score, - sae_pk_score, score); + sae_pk_score, security_score, score); entry->bss_score = score; @@ -2019,6 +2108,7 @@ void wlan_cm_init_score_config(struct wlan_objmgr_psoc *psoc, cfg_get(psoc, CFG_OCE_SUBNET_ID_WEIGHTAGE); score_cfg->weight_config.sae_pk_ap_weightage = cfg_get(psoc, CFG_SAE_PK_AP_WEIGHTAGE); + score_cfg->weight_config.security_weightage = CM_SECURITY_WEIGHTAGE; total_weight = score_cfg->weight_config.rssi_weightage + score_cfg->weight_config.ht_caps_weightage + @@ -2033,7 +2123,8 @@ void wlan_cm_init_score_config(struct wlan_objmgr_psoc *psoc, score_cfg->weight_config.oce_wan_weightage + score_cfg->weight_config.oce_ap_tx_pwr_weightage + score_cfg->weight_config.oce_subnet_id_weightage + - score_cfg->weight_config.sae_pk_ap_weightage; + score_cfg->weight_config.sae_pk_ap_weightage + + score_cfg->weight_config.security_weightage; /* * If configured weights are greater than max weight, @@ -2134,4 +2225,5 @@ void wlan_cm_init_score_config(struct wlan_objmgr_psoc *psoc, cfg_get(psoc, CFG_VENDOR_ROAM_SCORE_ALGORITHM); score_cfg->check_assoc_disallowed = true; cm_fill_6ghz_params(psoc, score_cfg); + score_cfg->security_weight_per_index = CM_SECURITY_INDEX_WEIGHTAGE; } diff --git a/drivers/staging/qca-wifi-host-cmn/umac/mlme/connection_mgr/dispatcher/inc/wlan_cm_bss_score_param.h b/drivers/staging/qca-wifi-host-cmn/umac/mlme/connection_mgr/dispatcher/inc/wlan_cm_bss_score_param.h index 55388bd0b9d1..5ddb522b0923 100644 --- a/drivers/staging/qca-wifi-host-cmn/umac/mlme/connection_mgr/dispatcher/inc/wlan_cm_bss_score_param.h +++ b/drivers/staging/qca-wifi-host-cmn/umac/mlme/connection_mgr/dispatcher/inc/wlan_cm_bss_score_param.h @@ -1,6 +1,6 @@ /* * Copyright (c) 2017-2020, The Linux Foundation. All rights reserved. - * Copyright (c) 2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2023-2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for any * purpose with or without fee is hereby granted, provided that the above @@ -41,6 +41,7 @@ * @oce_ap_tx_pwr_weightage: OCE AP tx power weigtage * @oce_subnet_id_weightage: OCE subnet id weigtage * @sae_pk_ap_weightage: SAE-PK AP weigtage + * @security_weightage: Security weightage */ struct weight_cfg { uint8_t rssi_weightage; @@ -57,6 +58,7 @@ struct weight_cfg { uint8_t oce_ap_tx_pwr_weightage; uint8_t oce_subnet_id_weightage; uint8_t sae_pk_ap_weightage; + uint8_t security_weightage; }; /** @@ -132,6 +134,8 @@ struct per_slot_score { * @check_6ghz_security: check security for 6Ghz candidate * @standard_6ghz_conn_policy: check for 6 GHz standard connection policy * @key_mgmt_mask_6ghz: user configurable mask for 6ghz AKM + * @roam_tgt_score_cap: Roam score capability + * @security_weight_per_index: security weight per index */ struct scoring_cfg { struct weight_cfg weight_config; @@ -147,6 +151,8 @@ struct scoring_cfg { uint8_t check_6ghz_security; uint8_t standard_6ghz_conn_policy:1; uint32_t key_mgmt_mask_6ghz; + uint32_t roam_tgt_score_cap; + uint32_t security_weight_per_index; }; /** @@ -207,6 +213,14 @@ wlan_blacklist_action_on_bssid(struct wlan_objmgr_pdev *pdev, } #endif +enum cm_security_idx { + CM_SECURITY_WPA_INDEX, + CM_SECURITY_WPA2_INDEX, + CM_SECURITY_WPA3_INDEX, + CM_SECURITY_WPA_OPEN_WEP_INDEX, + CM_MAX_SECURITY_INDEX +}; + /** * wlan_cm_calculate_bss_score() - calculate bss score for the scan list * @pdev: pointer to pdev object diff --git a/drivers/staging/qca-wifi-host-cmn/umac/scan/core/src/wlan_scan_filter.c b/drivers/staging/qca-wifi-host-cmn/umac/scan/core/src/wlan_scan_filter.c index 73836d7bade6..24847e97e2fc 100644 --- a/drivers/staging/qca-wifi-host-cmn/umac/scan/core/src/wlan_scan_filter.c +++ b/drivers/staging/qca-wifi-host-cmn/umac/scan/core/src/wlan_scan_filter.c @@ -1,5 +1,6 @@ /* * Copyright (c) 2017-2021 The Linux Foundation. All rights reserved. + * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -490,7 +491,7 @@ static bool scm_is_security_match(struct scan_filter *filter, if (!filter->authmodeset) return scm_match_any_security(filter, db_entry, security); - for (i = 0; i <= WLAN_CRYPTO_AUTH_MAX && !match; i++) { + for (i = 0; i < WLAN_CRYPTO_AUTH_MAX && !match; i++) { if (!QDF_HAS_PARAM(filter->authmodeset, i)) continue;