From f2c5ba0150ff82bb163af3c1ba087cd2cda6c129 Mon Sep 17 00:00:00 2001 From: Krupali Dhanvijay Date: Mon, 1 Jul 2024 11:29:38 +0530 Subject: [PATCH 1/5] qcacmn: Allow WAPI packet delivering if no valid peer During STA roaming, WAPI M1 might send to host before roam_sync completion, host peer has not been created or mapped to FW peer ID, no corresponding host peer can be found to deliver this WAPI packet then dropped. To not affect roaming efficiency, allow this WAPI packet can be delivered to stack without peer if with valid DP vdev. Change-Id: I37bdcd2d4ed4057eedae56d8c524e5f412773187 CRs-Fixed: 3857096 --- dp/wifi3.0/dp_internal.h | 2 ++ dp/wifi3.0/dp_rx.c | 5 +++-- dp/wifi3.0/dp_rx.h | 5 ++++- 3 files changed, 9 insertions(+), 3 deletions(-) diff --git a/dp/wifi3.0/dp_internal.h b/dp/wifi3.0/dp_internal.h index e9f8de7431e7..77b1337baca5 100644 --- a/dp/wifi3.0/dp_internal.h +++ b/dp/wifi3.0/dp_internal.h @@ -1,5 +1,6 @@ /* * Copyright (c) 2016-2021 The Linux Foundation. All rights reserved. + * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -390,6 +391,7 @@ while (0) #define FRAME_MASK_IPV4_DHCP 2 #define FRAME_MASK_IPV4_EAPOL 4 #define FRAME_MASK_IPV6_DHCP 8 +#define FRAME_MASK_IPV4_WAPI 0x40 #ifdef QCA_SUPPORT_PEER_ISOLATION #define dp_get_peer_isolation(_peer) ((_peer)->isolation) diff --git a/dp/wifi3.0/dp_rx.c b/dp/wifi3.0/dp_rx.c index 2ad820e6703a..9c76684a63fa 100644 --- a/dp/wifi3.0/dp_rx.c +++ b/dp/wifi3.0/dp_rx.c @@ -1,6 +1,6 @@ /* * Copyright (c) 2016-2020 The Linux Foundation. All rights reserved. - * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -2129,7 +2129,8 @@ void dp_rx_deliver_to_stack_no_peer(struct dp_soc *soc, qdf_nbuf_t nbuf) uint32_t pkt_len = 0; uint8_t *rx_tlv_hdr; uint32_t frame_mask = FRAME_MASK_IPV4_ARP | FRAME_MASK_IPV4_DHCP | - FRAME_MASK_IPV4_EAPOL | FRAME_MASK_IPV6_DHCP; + FRAME_MASK_IPV4_EAPOL | FRAME_MASK_IPV6_DHCP | + FRAME_MASK_IPV4_WAPI; peer_id = QDF_NBUF_CB_RX_PEER_ID(nbuf); if (peer_id > soc->max_peers) diff --git a/dp/wifi3.0/dp_rx.h b/dp/wifi3.0/dp_rx.h index 0818acf4aebf..c367e58a7276 100644 --- a/dp/wifi3.0/dp_rx.h +++ b/dp/wifi3.0/dp_rx.h @@ -1,5 +1,6 @@ /* * Copyright (c) 2016-2020 The Linux Foundation. All rights reserved. + * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Permission to use, copy, modify, and/or distribute this software for * any purpose with or without fee is hereby granted, provided that the @@ -209,7 +210,9 @@ bool dp_rx_is_special_frame(qdf_nbuf_t nbuf, uint32_t frame_mask) ((frame_mask & FRAME_MASK_IPV4_EAPOL) && qdf_nbuf_is_ipv4_eapol_pkt(nbuf)) || ((frame_mask & FRAME_MASK_IPV6_DHCP) && - qdf_nbuf_is_ipv6_dhcp_pkt(nbuf))) + qdf_nbuf_is_ipv6_dhcp_pkt(nbuf)) || + ((frame_mask & FRAME_MASK_IPV4_WAPI) && + qdf_nbuf_is_ipv4_wapi_pkt(nbuf))) return true; return false; From ab3c4a8142a555742094118d49c29285d80b18b5 Mon Sep 17 00:00:00 2001 From: Surya Prakash Sivaraj Date: Tue, 19 Mar 2024 15:55:28 +0530 Subject: [PATCH 2/5] qcacmn: Correct RSNXE capability indexes Currently, RSNXE capability indexes are defined incorrect. It seems BIT index is misinterpreted. Correct the same as defined below in spec(IEEE Std 802.11-2020, 9.4.2.241, Table 9-780). The Extended RSN Capabilities field, except its first 4 bits, is a bit field indicating the extended RSN capabilities being advertised by the STA transmitting the element. The length of the Extended RSN Capabilities field is a variable n, in octets, as indicated by the first 4 bits in the field. Also, add a macro to check if the given akm is WPA/WPA2 i.e. legacy than WPA3. Change-Id: I3d8eee15f6734b2364628f699b7829a1edb246f0 CRs-Fixed: 3257715 --- .../crypto/inc/wlan_crypto_global_def.h | 20 +++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h b/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h index d5f386bef272..0ba235650b4d 100644 --- a/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h +++ b/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h @@ -493,4 +493,24 @@ struct wlan_lmac_if_crypto_rx_ops { #define WLAN_CRYPTO_RX_OPS_SET_PEER_WEP_KEYS(crypto_rx_ops) \ (crypto_rx_ops->set_peer_wep_keys) +#define WLAN_CRYPTO_IS_WPA_WPA2(akm) \ + (QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_PSK) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_PSK) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SHA256) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_PSK_SHA256) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_WPS) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_WAPI_PSK) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_WAPI_CERT) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_CCKM) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_OSEN) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FILS_SHA256) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FILS_SHA384) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA256) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_FILS_SHA384) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_PSK_SHA384) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_PSK_SHA384)) + #endif /* end of _WLAN_CRYPTO_GLOBAL_DEF_H_ */ From 389a047ba7c9e4c0f57cfd52f41fcbcf37fe85a6 Mon Sep 17 00:00:00 2001 From: Surya Prakash Sivaraj Date: Tue, 19 Mar 2024 15:56:34 +0530 Subject: [PATCH 3/5] qcacmn: Add macro to determine WPA3 AKM Add a macro to determine if a particular AKM is WPA3-based AKM. Change-Id: I9b3f546e2e0f69281305ca9052dc109fb6812e21 CRs-Fixed: 3418837 --- umac/cmn_services/crypto/inc/wlan_crypto_global_def.h | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h b/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h index 0ba235650b4d..74d047350ac6 100644 --- a/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h +++ b/umac/cmn_services/crypto/inc/wlan_crypto_global_def.h @@ -513,4 +513,11 @@ struct wlan_lmac_if_crypto_rx_ops { QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_PSK_SHA384) || \ QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_PSK_SHA384)) +#define WLAN_CRYPTO_IS_WPA3(akm) \ + (QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_SAE) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_SAE) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_IEEE8021X_SUITE_B_192) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_OWE) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_DPP) || \ + QDF_HAS_PARAM(akm, WLAN_CRYPTO_KEY_MGMT_FT_IEEE8021X_SHA384)) #endif /* end of _WLAN_CRYPTO_GLOBAL_DEF_H_ */ From c303459d07819ce443e6e980c74688b16ca78eb7 Mon Sep 17 00:00:00 2001 From: "Kaushik K.N" Date: Thu, 7 Sep 2023 19:00:31 +0800 Subject: [PATCH 4/5] qcacmn: Fix issue about generating MBSSID frames When generating MBSSID beacon/probe response frames, it misses the last IE in the MBSSID ie list. To address it, correcting the comparing length. CRs-Fixed: 3609711 Change-Id: Ia406be0ade901c9bc01698faec473bd25c59dfb3 --- umac/scan/dispatcher/src/wlan_scan_utils_api.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/umac/scan/dispatcher/src/wlan_scan_utils_api.c b/umac/scan/dispatcher/src/wlan_scan_utils_api.c index c9fcd7db83a0..64498dc9b22c 100644 --- a/umac/scan/dispatcher/src/wlan_scan_utils_api.c +++ b/umac/scan/dispatcher/src/wlan_scan_utils_api.c @@ -2161,7 +2161,7 @@ static uint32_t util_gen_new_ie(uint8_t *ie, uint32_t ielen, tmp_new = sub_copy; while ((subie_len > 0) && (((tmp_new + tmp_new[1] + MIN_IE_LEN) - sub_copy) <= - (subie_len - 1))) { + subie_len)) { if (!(tmp_new[0] == WLAN_ELEMID_NONTX_BSSID_CAP || tmp_new[0] == WLAN_ELEMID_SSID || tmp_new[0] == WLAN_ELEMID_MULTI_BSSID_IDX || From a2450eb8bc188bdbaf38d7a6707ab1de99502832 Mon Sep 17 00:00:00 2001 From: "Kaushik K.N" Date: Thu, 9 May 2024 09:25:57 +0200 Subject: [PATCH 5/5] qcacmn: Fix length check to parse non-inheritance list Fix length check and add sub_copy and length subie_len checks before accessing extn_elem to avoid any OOB read. Change-Id: I85ea636d5fe64e8508e91b06f0302d5f6258e583 CRs-Fixed: 3800831 --- umac/scan/dispatcher/src/wlan_scan_utils_api.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/umac/scan/dispatcher/src/wlan_scan_utils_api.c b/umac/scan/dispatcher/src/wlan_scan_utils_api.c index 64498dc9b22c..b11c4ceca6ad 100644 --- a/umac/scan/dispatcher/src/wlan_scan_utils_api.c +++ b/umac/scan/dispatcher/src/wlan_scan_utils_api.c @@ -2019,7 +2019,7 @@ static uint32_t util_gen_new_ie(uint8_t *ie, uint32_t ielen, if (extn_elem && extn_elem[TAG_LEN_POS] >= VALID_ELEM_LEAST_LEN) { if (((extn_elem + extn_elem[1] + MIN_IE_LEN) - sub_copy) - < subie_len) + <= subie_len) util_parse_noninheritance_list(extn_elem, &elem_list, &extn_elem_list, &ninh); }