]> git.ipfire.org Git - thirdparty/hostap.git/log
thirdparty/hostap.git
6 years agoWPS NFC: Fix potential NULL pointer dereference on an error path
Yu Ouyang [Mon, 3 Dec 2018 06:18:53 +0000 (14:18 +0800)] 
WPS NFC: Fix potential NULL pointer dereference on an error path

The NFC connection handover specific case of WPS public key generation
did not verify whether the two wpabuf_dup() calls succeed. Those may
return NULL due to an allocation failure and that would result in a NULL
pointer dereference in dh5_init_fixed().

Fix this by checking memory allocation results explicitly. If either of
the allocations fail, do not try to initialize wps->dh_ctx and instead,
report the failure through the existing error case handler below.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org
6 years agoHS 2.0 server: Fix couple of memory leaks
Jouni Malinen [Tue, 4 Dec 2018 12:12:44 +0000 (14:12 +0200)] 
HS 2.0 server: Fix couple of memory leaks

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoHS 2.0 server: Client certificate reenrollment
Jouni Malinen [Tue, 4 Dec 2018 12:11:39 +0000 (14:11 +0200)] 
HS 2.0 server: Client certificate reenrollment

This adds support for the SPP server to request certificate reenrollment
and for the EST server to support the simplereenroll version.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoHS 2.0 server: Document client certificate related Apache configuration
Jouni Malinen [Mon, 3 Dec 2018 22:15:04 +0000 (00:15 +0200)] 
HS 2.0 server: Document client certificate related Apache configuration

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoHS 2.0 server: Clear remediation requirement for certificate credentials
Jouni Malinen [Mon, 3 Dec 2018 22:11:37 +0000 (00:11 +0200)] 
HS 2.0 server: Clear remediation requirement for certificate credentials

Previous implementation updated user database only for username/password
credentials. While client certificates do not need the updated password
to be written, they do need the remediation requirement to be cleared,
so fix that.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoHS 2.0 server: Do not set phase2=1 for certificate-based users
Jouni Malinen [Mon, 3 Dec 2018 21:45:32 +0000 (23:45 +0200)] 
HS 2.0 server: Do not set phase2=1 for certificate-based users

These are not really using Phase 2, so use more appropriate
configuration when going through online signup for client certificates.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoHS 2.0 server: Include phase2=0 users for TLS in the user list
Jouni Malinen [Mon, 3 Dec 2018 21:38:20 +0000 (23:38 +0200)] 
HS 2.0 server: Include phase2=0 users for TLS in the user list

EAP-TLS users are not really using phase2, so do not require the
database to be set in a way that claim that inaccurately.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoEAP-TLS server: Update user information based on serial number
Jouni Malinen [Mon, 3 Dec 2018 21:29:56 +0000 (23:29 +0200)] 
EAP-TLS server: Update user information based on serial number

This allows EAP user database entries for "cert-<serial number>" to be
used for client certificate based parameters when using EAP-TLS. This
commit addresses only the full authentication case and TLS session
resumption is not yet covered.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoVLAN: Warn about interface name truncation
Jouni Malinen [Mon, 3 Dec 2018 10:44:11 +0000 (12:44 +0200)] 
VLAN: Warn about interface name truncation

Add more snprintf checks to make it clearer if some of the ifname
constructions would end up being too long.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoFT: Fix CONFIG_IEEE80211X=y build without CONFIG_FILS=y
Jouni Malinen [Mon, 3 Dec 2018 10:00:26 +0000 (12:00 +0200)] 
FT: Fix CONFIG_IEEE80211X=y build without CONFIG_FILS=y

remove_ie() was defined within an ifdef CONFIG_FILS block while it is
now needed even without CONFIG_FILS=y. Remove the CONFIG_FILS condition
there.

Fixes 8c41734e5de1 ("FT: Fix Reassociation Request IEs during FT protocol")
Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoThe master branch is now used for v2.8 development
Jouni Malinen [Sun, 2 Dec 2018 20:55:28 +0000 (22:55 +0200)] 
The master branch is now used for v2.8 development

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoUpdate version to v2.7 and copyright years to include 2018 hostap_2_7
Jouni Malinen [Sun, 2 Dec 2018 18:56:31 +0000 (20:56 +0200)] 
Update version to v2.7 and copyright years to include 2018

Also add the ChangeLog entries for both hostapd and wpa_supplicant to
describe main changes between v2.6 and v2.7.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoUncomment CONFIG_LIBNL32=y in defconfig
Jouni Malinen [Sun, 2 Dec 2018 19:25:08 +0000 (21:25 +0200)] 
Uncomment CONFIG_LIBNL32=y in defconfig

libnl 3.2 release is much more likely to be used nowadays than the
versions using the older API, so uncomment this in wpa_supplicant and
hostapd defconfig.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: Opportunistic Wireless Encryption association rejection handling
Jouni Malinen [Sun, 2 Dec 2018 18:34:42 +0000 (20:34 +0200)] 
tests: Opportunistic Wireless Encryption association rejection handling

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoOWE: Try another group only on association rejection with status 77
Ashok Kumar [Thu, 1 Nov 2018 11:03:21 +0000 (16:33 +0530)] 
OWE: Try another group only on association rejection with status 77

Do not change the OWE group if association is rejected for any other
reason than WLAN_STATUS_FINITE_CYCLIC_GROUP_NOT_SUPPORTED to avoid
unnecessary latency in cases where the APs reject association, e.g., for
load balancing reasons.

Signed-off-by: Ashok Kumar <aponnaia@codeaurora.org>
6 years agoOWE: Fix association rejection behavior
Jouni Malinen [Sun, 2 Dec 2018 18:21:21 +0000 (20:21 +0200)] 
OWE: Fix association rejection behavior

If association failed for any non-OWE specific reason, the previous
implementation tried to add the OWE related IEs into the (Re)Association
Response frame. This is not needed and could actually result in
dereferencing a NULL pointer. Fix this by adding those OWE related IEs
only for successful association and only if the RSN state machine has
been initialized.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agonl80211: Debug print TX queue parameter values and result
Jouni Malinen [Sun, 2 Dec 2018 17:50:59 +0000 (19:50 +0200)] 
nl80211: Debug print TX queue parameter values and result

Some mac80211_hwsim test cases have failed with mysterious sequence
where mac80211 has claimed the parameters are invalid ("wlan3: invalid
CW_min/CW_max: 9484/40"). Those values look strange since they are not
from hostapd configuration or default values.. hostapd is seeing TX
queue parameter set failing for queues 0, 1, and 3 (but not 2) for these
cases. Add debug prints to hostapd to get more details on what exactly
is happening if such error cases can be reproduced.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: DPP network addition failure
Jouni Malinen [Sun, 2 Dec 2018 15:17:50 +0000 (17:17 +0200)] 
tests: DPP network addition failure

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: DPP and continue listen state
Jouni Malinen [Sun, 2 Dec 2018 15:04:21 +0000 (17:04 +0200)] 
tests: DPP and continue listen state

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoDPP: Remove unused wpas_dpp_remain_on_channel_cb()
Jouni Malinen [Sun, 2 Dec 2018 15:03:13 +0000 (17:03 +0200)] 
DPP: Remove unused wpas_dpp_remain_on_channel_cb()

This function was apparently never used at all.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: DPP_BOOTSTRAP_GEN/REMOVE/GET_URI/INFO error cases
Jouni Malinen [Sun, 2 Dec 2018 14:37:46 +0000 (16:37 +0200)] 
tests: DPP_BOOTSTRAP_GEN/REMOVE/GET_URI/INFO error cases

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: DPP and unknown configurator id
Jouni Malinen [Sun, 2 Dec 2018 14:08:29 +0000 (16:08 +0200)] 
tests: DPP and unknown configurator id

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: DPP and PKEX with local failure in processing Commit Reveal Req
Jouni Malinen [Sun, 2 Dec 2018 10:52:32 +0000 (12:52 +0200)] 
tests: DPP and PKEX with local failure in processing Commit Reveal Req

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: DPP and PKEX with local failure in processing Exchange Resp
Jouni Malinen [Sun, 2 Dec 2018 10:44:13 +0000 (12:44 +0200)] 
tests: DPP and PKEX with local failure in processing Exchange Resp

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: DPP and PKEX with mismatching curve (local failure)
Jouni Malinen [Sun, 2 Dec 2018 10:39:05 +0000 (12:39 +0200)] 
tests: DPP and PKEX with mismatching curve (local failure)

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: DPP PKEX identifier combinations
Jouni Malinen [Sun, 2 Dec 2018 10:32:17 +0000 (12:32 +0200)] 
tests: DPP PKEX identifier combinations

Check behavior with valid and invalid identifier combinations.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoDPP: Do not reply to PKEX request with identifier if no local identifier
Jouni Malinen [Sun, 2 Dec 2018 10:30:11 +0000 (12:30 +0200)] 
DPP: Do not reply to PKEX request with identifier if no local identifier

The reverse case (local identifier configured but no identifier
received) was already covered, but PKEX is not going to complete
successfully if there is any difference in identifier configuration, so
ignore this other case as well. This avoids unnecessary responses to
PKEX requests with identifier from a device that is ready for PKEX in
general, but not for that particular request.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: SAE and password identifier with FFC
Jouni Malinen [Sun, 2 Dec 2018 09:56:04 +0000 (11:56 +0200)] 
tests: SAE and password identifier with FFC

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: DPP peer introduction local failures
Jouni Malinen [Sat, 1 Dec 2018 23:20:30 +0000 (01:20 +0200)] 
tests: DPP peer introduction local failures

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: DPP peer introduction failures
Jouni Malinen [Sat, 1 Dec 2018 22:44:42 +0000 (00:44 +0200)] 
tests: DPP peer introduction failures

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoDPP: Apply testing configuration option to signing of own config
Jouni Malinen [Sat, 1 Dec 2018 22:26:21 +0000 (00:26 +0200)] 
DPP: Apply testing configuration option to signing of own config

Previous implementation had missed this case of setting configurator
parameters.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: DPP own config signing failure
Jouni Malinen [Sat, 1 Dec 2018 22:10:08 +0000 (00:10 +0200)] 
tests: DPP own config signing failure

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: DPP invalid configurator key
Jouni Malinen [Sat, 1 Dec 2018 21:50:24 +0000 (23:50 +0200)] 
tests: DPP invalid configurator key

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: DPP legacy parameters local failure
Jouni Malinen [Sat, 1 Dec 2018 18:22:53 +0000 (20:22 +0200)] 
tests: DPP legacy parameters local failure

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: Radio measurement capability with roaming
Jouni Malinen [Sat, 1 Dec 2018 18:15:50 +0000 (20:15 +0200)] 
tests: Radio measurement capability with roaming

This verifies that radio measurement capabilities are negotiated
correctly for the reassociation cases with and without FT.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoFT: Fix Reassociation Request IEs during FT protocol
Jouni Malinen [Sat, 1 Dec 2018 18:10:54 +0000 (20:10 +0200)] 
FT: Fix Reassociation Request IEs during FT protocol

The previous implementation ended up replacing all pending IEs prepared
for Association Request frame with the FT specific IEs (RSNE, MDE, FTE)
when going through FT protocol reassociation with the wpa_supplicant
SME. This resulted in dropping all other IEs that might have been
prepared for the association (e.g., Extended Capabilities, RM Enabled
Capabilities, Supported Operating Classes, vendor specific additions).

Fix this by replacing only the known FT specific IEs with the
appropriate values for FT protocol while maintaining other already
prepared elements.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: Do not generate /tmp/hwsim-tests-*.tar.gz in VM case
Jouni Malinen [Sat, 1 Dec 2018 14:44:53 +0000 (16:44 +0200)] 
tests: Do not generate /tmp/hwsim-tests-*.tar.gz in VM case

There is no point in building this tarball in /tmp that is on the
ramdisk of the VM since it will go away when the VM exits.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoUse more consistent Action frame RX handling in both AP mode paths
Jouni Malinen [Sat, 1 Dec 2018 11:19:47 +0000 (13:19 +0200)] 
Use more consistent Action frame RX handling in both AP mode paths

Both handle_action() and hostapd_action_rx() are used for processing
received Action frames depending on what type of driver architecture is
used (MLME in hostapd vs. driver) and which build options were used to
build hostapd. These functions had a bit different sequence for checking
the frame and printing debug prints. Make those more consistent by
checking that the frame includes the category-specific action field and
some payload. Add a debug print for both functions to make it easier to
see which path various Action frames use.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoFT: Check session_timeout pointer consistently
Jouni Malinen [Fri, 30 Nov 2018 19:07:19 +0000 (21:07 +0200)] 
FT: Check session_timeout pointer consistently

Avoid smatch warning on this even thought the only caller of the
function uses a non-NULL pointer in all cases.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoFix hostapd testing functionality for setting key/seq
Jouni Malinen [Fri, 30 Nov 2018 19:03:08 +0000 (21:03 +0200)] 
Fix hostapd testing functionality for setting key/seq

Use sizeof() correctly on seq[].

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoEAP DB: Use NULL to clear a pointer
Jouni Malinen [Fri, 30 Nov 2018 16:00:31 +0000 (18:00 +0200)] 
EAP DB: Use NULL to clear a pointer

Avoid a sparse warning from use of a plain integer.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoDPP: Check own_bi/peer_bi pointers more consistently
Jouni Malinen [Fri, 30 Nov 2018 15:57:35 +0000 (17:57 +0200)] 
DPP: Check own_bi/peer_bi pointers more consistently

This gets rid of smatch warnings about a dereference before check.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoFix indentation level
Jouni Malinen [Fri, 30 Nov 2018 15:56:56 +0000 (17:56 +0200)] 
Fix indentation level

This gets rid of smatch warnings about inconsistent indenting.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoOpenSSL: Include sha512.h to match function prototypes
Jouni Malinen [Fri, 30 Nov 2018 15:38:35 +0000 (17:38 +0200)] 
OpenSSL: Include sha512.h to match function prototypes

This gets rid of sparse warnings.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agomacsec_linux: Make create_transmit_sc() handler use matching arguments
Jouni Malinen [Fri, 30 Nov 2018 15:36:46 +0000 (17:36 +0200)] 
macsec_linux: Make create_transmit_sc() handler use matching arguments

The currently unused conf_offset parameter used a mismatching type (enum
vs. unsigned int) compared to the prototype.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agomacsec_linux: Use NULL to clear a pointer
Jouni Malinen [Fri, 30 Nov 2018 15:32:35 +0000 (17:32 +0200)] 
macsec_linux: Use NULL to clear a pointer

Avoid a sparse warning from use of a plain integer.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agomacsec_qca: Mark macsec_qca_set_transmit_next_pn() static
Jouni Malinen [Fri, 30 Nov 2018 15:31:30 +0000 (17:31 +0200)] 
macsec_qca: Mark macsec_qca_set_transmit_next_pn() static

This function is not used outside this C file. Mark it static to avoid a
warning from sparse.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoSAE: Fix external authentication on big endian platforms
Ashok Ponnaiah [Fri, 30 Nov 2018 15:26:26 +0000 (17:26 +0200)] 
SAE: Fix external authentication on big endian platforms

Need to handle the little endian 16-bit fields properly when building
and parsing Authentication frames.

Fixes: 5ff39c1380d9 ("SAE: Support external authentication offload for driver-SME cases")
Signed-off-by: Ashok Ponnaiah <aponnaia@codeaurora.org>
6 years agotests: DPP invalid legacy parameters
Jouni Malinen [Fri, 30 Nov 2018 15:17:03 +0000 (17:17 +0200)] 
tests: DPP invalid legacy parameters

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoDPP: Reject invalid no-psk/pass legacy configurator parameters
Jouni Malinen [Fri, 30 Nov 2018 15:14:49 +0000 (17:14 +0200)] 
DPP: Reject invalid no-psk/pass legacy configurator parameters

Instead of going through the configuration exchange, reject invalid
legacy configurator parameters explicitly. Previously, configuring
legacy (psk/sae) parameters without psk/pass resulted in a config object
that used a zero length passphrase. With this change, that config object
is not sent and instead, either the initialization attempts is rejected
or the incoming initialization attempt is ignored.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: DPP protocol testing - Auth Conf RX processing failure
Jouni Malinen [Fri, 30 Nov 2018 12:21:35 +0000 (14:21 +0200)] 
tests: DPP protocol testing - Auth Conf RX processing failure

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: DPP Auth Resp AES-SIV issue
Jouni Malinen [Fri, 30 Nov 2018 12:10:12 +0000 (14:10 +0200)] 
tests: DPP Auth Resp AES-SIV issue

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: More DPP incompatible roles coverage
Jouni Malinen [Fri, 30 Nov 2018 11:46:15 +0000 (13:46 +0200)] 
tests: More DPP incompatible roles coverage

Cover the Configurator/Configurator case in addition Enrollee/Enrollee.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: DPP and Auth Resp(status) build failure
Jouni Malinen [Fri, 30 Nov 2018 11:39:19 +0000 (13:39 +0200)] 
tests: DPP and Auth Resp(status) build failure

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: DPP bootstrap key autogen issues
Jouni Malinen [Fri, 30 Nov 2018 11:30:08 +0000 (13:30 +0200)] 
tests: DPP bootstrap key autogen issues

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoOWE: Fix a compiler warning in non-testing build
Jouni Malinen [Tue, 27 Nov 2018 18:49:53 +0000 (20:49 +0200)] 
OWE: Fix a compiler warning in non-testing build

The new conf variable was used only within the CONFIG_TESTING_OPTIONS
block and as such, added a warning about unused variable into
non-testing builds. Fix that by using that variable outside the
conditional block as well.

Fixes: a22e235fd0df ("OWE: Add testing RSNE for OWE assoc response with driver SME/MLME")
Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: DPP protocol testing cases for Auth Resp status-not-OK cases
Jouni Malinen [Tue, 27 Nov 2018 15:21:22 +0000 (17:21 +0200)] 
tests: DPP protocol testing cases for Auth Resp status-not-OK cases

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoDPP: Fix no-Status protocol testing in Auth Resp error case
Jouni Malinen [Tue, 27 Nov 2018 15:20:41 +0000 (17:20 +0200)] 
DPP: Fix no-Status protocol testing in Auth Resp error case

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: Additional DPP AES-SIV local failure coverage
Jouni Malinen [Tue, 27 Nov 2018 15:00:24 +0000 (17:00 +0200)] 
tests: Additional DPP AES-SIV local failure coverage

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: DPP QR Code and keygen failure
Jouni Malinen [Tue, 27 Nov 2018 14:50:36 +0000 (16:50 +0200)] 
tests: DPP QR Code and keygen failure

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: DPP local failure on hashing public key for PKEX bootstrap info
Jouni Malinen [Tue, 27 Nov 2018 14:41:25 +0000 (16:41 +0200)] 
tests: DPP local failure on hashing public key for PKEX bootstrap info

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: DPP QR Code and unsupported curve
Jouni Malinen [Tue, 27 Nov 2018 14:39:21 +0000 (16:39 +0200)] 
tests: DPP QR Code and unsupported curve

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoDefine QCA_NL80211_VENDOR_SUBCMD_LINK_PROPERTIES also as an event
Sunil Dutt [Wed, 21 Nov 2018 13:49:53 +0000 (19:19 +0530)] 
Define QCA_NL80211_VENDOR_SUBCMD_LINK_PROPERTIES also as an event

This commit enhances QCA_NL80211_VENDOR_SUBCMD_LINK_PROPERTIES to
also be an event, aimed to notify the link status (EX: connected
stations status on an AP link).

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: Additional DPP bootstrapping URI parsing coverage
Jouni Malinen [Mon, 26 Nov 2018 19:35:23 +0000 (21:35 +0200)] 
tests: Additional DPP bootstrapping URI parsing coverage

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: DPP invalid attribute checks
Jouni Malinen [Mon, 26 Nov 2018 18:43:30 +0000 (20:43 +0200)] 
tests: DPP invalid attribute checks

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agonl80211: Use netlink connect socket for disconnect (ext auth)
Cedric Izoard [Mon, 26 Nov 2018 07:44:02 +0000 (07:44 +0000)] 
nl80211: Use netlink connect socket for disconnect (ext auth)

When external authentication is used, a specific netlink socket is used
to send the connect command. If the same socket is not used for
disconnect command, cfg80211 will discard the command. This constraint
was added into the kernel in commit bad292973363 ("nl80211: Reject
disconnect commands except from conn_owner"). That requires an update
for the hostap.git commit 40a68f33844f ("nl80211: Create a netlink
socket handle for the Connect interface").

Add a new flag into struct i802_bss to indicate if the special
nl_connect socket was used for the connect command. When sending
disconnect command this flag is tested to select the correct socket.

Signed-off-by: Cedric Izoard <cedric.izoard@ceva-dsp.com>
6 years agoexternal-auth: Check key_mgmt when selecting SSID
Cedric Izoard [Mon, 26 Nov 2018 11:47:37 +0000 (11:47 +0000)] 
external-auth: Check key_mgmt when selecting SSID

When selecting SSID to start external authentication procedure also
check the key_mgmt field as several network configuration may be defined
for the same SSID/BSSID pair. The external authentication mechanism is
only available for SAE.

Signed-off-by: Cedric Izoard <cedric.izoard@ceva-dsp.com>
6 years agotests: Call remove_group() after other cleanup is done
Avraham Stern [Wed, 22 Aug 2018 16:49:07 +0000 (19:49 +0300)] 
tests: Call remove_group() after other cleanup is done

The call to remove_group() may fail, in which case all following
cleanup is skipped. This may result in failing many tests since
cleanup did not complete successfully.

Fix this by calling remove_group() after other cleanup is done so
even it fails it will not affect the following tests.

Signed-off-by: Avraham Stern <avraham.stern@intel.com>
6 years agodrivers: Document struct wpa_signal_info
Emmanuel Grumbach [Wed, 5 Sep 2018 17:44:32 +0000 (20:44 +0300)] 
drivers: Document struct wpa_signal_info

Add documentation to the wpa_signal_info structure.
Add a define for an invalid noise value.

Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
6 years agotests: hostapd configuration reload on SIGHUP with bss remove/add
Jouni Malinen [Sun, 25 Nov 2018 22:53:53 +0000 (00:53 +0200)] 
tests: hostapd configuration reload on SIGHUP with bss remove/add

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoFix hostapd config file reloading with BSS addition/removal
Jouni Malinen [Sun, 25 Nov 2018 22:51:38 +0000 (00:51 +0200)] 
Fix hostapd config file reloading with BSS addition/removal

BSS additional/removal cases were not considered at all in the previous
implementation of hostapd configuration file reloading on SIGHUP. Such
changes resulted in num_bss values getting out of sync in runtime data
and configuration data and likely dereferencing of freed memory (e.g.,
when removing a BSS).

Fix this by forcing a full disable/enable sequence for the interface if
any BSS entry is added/removed or if an interface name changes between
the old and the new configuration.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoFix a typo in a comment
Jouni Malinen [Sun, 25 Nov 2018 22:37:24 +0000 (00:37 +0200)] 
Fix a typo in a comment

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: DPP Connector testing with ECDSA signature in Python
Jouni Malinen [Sun, 25 Nov 2018 20:01:35 +0000 (22:01 +0200)] 
tests: DPP Connector testing with ECDSA signature in Python

Implement ECDSA signing functionality in the Python test script for
generating a valid signedConnector. This allows coverage of DPP config
object testing to be increased more easily.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: More DPP Config Object protocol testing coverage
Jouni Malinen [Sun, 25 Nov 2018 16:50:29 +0000 (18:50 +0200)] 
tests: More DPP Config Object protocol testing coverage

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoDPP: Fix a debug print to use quotation marks consistently
Jouni Malinen [Sun, 25 Nov 2018 15:31:49 +0000 (17:31 +0200)] 
DPP: Fix a debug print to use quotation marks consistently

The "DPP: Unexpected JWK kty" debug print missed one of the quotation
marks.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: Additional coverage for DPP GAS error cases
Jouni Malinen [Sun, 25 Nov 2018 11:53:05 +0000 (13:53 +0200)] 
tests: Additional coverage for DPP GAS error cases

These test cases found number of error handling issues in the DPP/GAS
implementation.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoDPP: Fix error path handling for GAS Comeback Response building
Jouni Malinen [Sun, 25 Nov 2018 11:51:26 +0000 (13:51 +0200)] 
DPP: Fix error path handling for GAS Comeback Response building

A local memory allocation failuring during GAS Comeback Response frame
generation could result in freeing the response context without removing
it from the list. This would result in dereferencing freed memory when
processing the next comeback request.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoDPP: Fix memory leaks in GAS server error path handling
Jouni Malinen [Sun, 25 Nov 2018 11:49:44 +0000 (13:49 +0200)] 
DPP: Fix memory leaks in GAS server error path handling

If local memory allocation for the GAS response failed, couple of error
paths ended up leaking some memory maintaining the state for the
exchange. Fix that by freeing the context properly.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agoDPP: Fix GAS client error case handling
Jouni Malinen [Sun, 25 Nov 2018 11:33:39 +0000 (13:33 +0200)] 
DPP: Fix GAS client error case handling

The GAS client processing of the response callback for DPP did not
properly check for GAS query success. This could result in trying to
check the Advertisement Protocol information in failure cases where that
information is not available and that would have resulted in
dereferencing a NULL pointer. Fix this by checking the GAS query result
before processing with processing of the response.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: More coverage for ATTACH command parameter setting
Jouni Malinen [Sun, 25 Nov 2018 10:02:07 +0000 (12:02 +0200)] 
tests: More coverage for ATTACH command parameter setting

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agotests: D-Bus introspection with busctl
Jouni Malinen [Sat, 24 Nov 2018 16:02:29 +0000 (18:02 +0200)] 
tests: D-Bus introspection with busctl

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agodbus: Expose availability of SHA384 on D-Bus
Lubomir Rintel [Sun, 7 Oct 2018 14:57:27 +0000 (16:57 +0200)] 
dbus: Expose availability of SHA384 on D-Bus

This lets us know whether we can attempt to use FT-EAP-SHA384.

Signed-off-by: Lubomir Rintel <lkundrak@v3.sk>
6 years agodbus: Expose availability of FT on D-Bus
Lubomir Rintel [Sun, 7 Oct 2018 14:57:10 +0000 (16:57 +0200)] 
dbus: Expose availability of FT on D-Bus

This lets us know whether we can attempt to use FT-PSK, FT-EAP,
FT-EAP-SHA384, FT-FILS-SHA256 or FT-FILS-SHA384.

Signed-off-by: Lubomir Rintel <lkundrak@v3.sk>
6 years agotests: D-Bus Get/Set Pmf
Lubomir Rintel [Sun, 7 Oct 2018 14:59:40 +0000 (16:59 +0200)] 
tests: D-Bus Get/Set Pmf

Based on Jouni Malinen's [76055b4c6 "tests: D-Bus Get/Set Pmf"], modified
to use the correct "s" signature for the "Pmf" property.

Removed the negative test cases, because the synthesized property doens't
seem to do error checking upon being set.

Signed-off-by: Jouni Malinen <j@w1.fi>
Signed-off-by: Lubomir Rintel <lkundrak@v3.sk>
6 years agoRevert "D-Bus: Implement Pmf property"
Lubomir Rintel [Sun, 7 Oct 2018 14:59:39 +0000 (16:59 +0200)] 
Revert "D-Bus: Implement Pmf property"

This reverts commit adf8f45f8af27a9ac9429ecde81776b19b6f9224.

It is basically all wrong. The Pmf property did exist, with a signature of
"s" as documented in doc/dbus.doxygen. It was synthesized from
global_fields[].

The patch added a duplicate one, with a signature of "u", in violation
of D-Bus specification and to bemusement of tools that are careful
enough:

  $ busctl introspect fi.w1.wpa_supplicant1 /fi/w1/wpa_supplicant1/Interfaces/666
  Duplicate property

Signed-off-by: Lubomir Rintel <lkundrak@v3.sk>
6 years agoRevert "tests: D-Bus Get/Set Pmf"
Lubomir Rintel [Sun, 7 Oct 2018 14:59:38 +0000 (16:59 +0200)] 
Revert "tests: D-Bus Get/Set Pmf"

This is wrong. The Pmf property has a "s" signature.

This reverts commit 76055b4c6115620421313038b6128f3b93d5160e.

Signed-off-by: Lubomir Rintel <lkundrak@v3.sk>
6 years agomesh: Add Category and Action field to maximum buffer length
Jouni Malinen [Sat, 24 Nov 2018 11:36:54 +0000 (13:36 +0200)] 
mesh: Add Category and Action field to maximum buffer length

Make the buf_len calculation match more closely with the following
wpa_buf*() operations. The extra room from the existing elements was
apparently sufficiently large to cover this, but better add the two
octet header explicitly.

Signed-off-by: Jouni Malinen <j@w1.fi>
6 years agomesh: Fix off-by-one in buf length calculation
Bob Copeland [Fri, 23 Nov 2018 15:15:42 +0000 (10:15 -0500)] 
mesh: Fix off-by-one in buf length calculation

The maximum size of a Mesh Peering Management element in the case
of an AMPE close frame is actually 24 bytes, not 23 bytes, plus the
two bytes of the IE header (IEEE Std 802.11-2016, 9.4.2.102). Found by
inspection.

The other buffer components seem to use large enough extra room in their
allocations to avoid hitting issues with the full buffer size even
without this fix.

Signed-off-by: Bob Copeland <bobcopeland@fb.com>
6 years agoexamples: Fix shellcheck warnings in wps-ap-cli
Davide Caratti [Mon, 10 Sep 2018 11:00:36 +0000 (13:00 +0200)] 
examples: Fix shellcheck warnings in wps-ap-cli

use 'printf' instead of 'echo -n', to suppress the following warning:

In POSIX sh, echo flags are undefined. [SC2039]

Signed-off-by: Davide Caratti <davide.caratti@gmail.com>
6 years agotests: Store the correct PID in hostapd-test.pid file
Andrei Otcheretianski [Tue, 23 Oct 2018 11:07:05 +0000 (14:07 +0300)] 
tests: Store the correct PID in hostapd-test.pid file

The hwsim's start.sh script spawns hostapd process using "sudo".
Since sudo forks a child process, $! holds the pid of sudo itself.
Fix that by storing the PID of the child process instead.
Since in VM "sudo" is replaced with a dummy script, pass an additional
argument to run-all.sh and start.sh scripts to indicate that they are
running inside a VM.

This is needed to fix ap_config_reload and ap_config_reload_file test
cases on some platforms where sudo is apparently not relaying the
signals properly.

Signed-off-by: Andrei Otcheretianski <andrei.otcheretianski@intel.com>
6 years agotests: Fix ap_acl_deny test
Ayala Beker [Tue, 23 Oct 2018 11:23:52 +0000 (14:23 +0300)] 
tests: Fix ap_acl_deny test

In ap_acl_deny test, the AP doesn't send probe responses during scan due
to ACL reject. As the result, dev[0] might miss the AP's Beacon frame
because the dwell time is too short. Make the test more robust and
trigger passive scan, and by that increase the probability of hearing
the AP.

Signed-off-by: Ayala Beker <ayala.beker@intel.com>
6 years agonl80211: Use correct u8 size for NL80211_ATTR_SMPS_MODE
Johannes Berg [Fri, 26 Oct 2018 13:50:48 +0000 (15:50 +0200)] 
nl80211: Use correct u8 size for NL80211_ATTR_SMPS_MODE

Back in December 2017, Jouni fixed the output side since that was
causing a kernel message to be printed, but the input side should
also be fixed, otherwise it will not work correctly on big-endian
platforms.

Signed-off-by: Johannes Berg <johannes.berg@intel.com>
6 years agoFix dpp_configurator_get_key command name in hostapd_cli
Damodaran, Rohit (Contractor) [Thu, 15 Nov 2018 14:20:32 +0000 (14:20 +0000)] 
Fix dpp_configurator_get_key command name in hostapd_cli

The option to get DPP configurator key in hostapd_cli was named
incorrectly. It was wrongly pointing to dpp_configurator_remove. Fix
this by using the correct name.

Signed-off-by: Rohit Damodaran <Rohit_Damodaran@comcast.com>
6 years agoHS 2.0: Update HS2.0 AP version RADIUS attribute Version field
Jouni Malinen [Fri, 9 Nov 2018 21:38:31 +0000 (23:38 +0200)] 
HS 2.0: Update HS2.0 AP version RADIUS attribute Version field

Use HS20_VERSION macro to determine if R3 should be indicated instead of
R2.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: Mark OSU BSS explicitly in sigma_dut_ap_hs20
Jouni Malinen [Fri, 9 Nov 2018 16:10:28 +0000 (18:10 +0200)] 
tests: Mark OSU BSS explicitly in sigma_dut_ap_hs20

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: ap_hs20_osen to test group cipher selection in SME case
Jouni Malinen [Fri, 9 Nov 2018 16:09:34 +0000 (18:09 +0200)] 
tests: ap_hs20_osen to test group cipher selection in SME case

Go through the group cipher selection in both the wpa_supplicant and
driver SME cases.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoHS 2.0: Generate AssocReq OSEN IE based on AP advertisement
Jouni Malinen [Fri, 9 Nov 2018 16:07:16 +0000 (18:07 +0200)] 
HS 2.0: Generate AssocReq OSEN IE based on AP advertisement

Parse the OSEN IE from the AP to determine values used in the AssocReq
instead of using hardcoded cipher suites. This is needed to be able to
set the group cipher based on AP advertisement now that two possible
options exists for this (GTK_NOT_USED in separate OSEN BSS; CCMP or
GTK_NOT_USED in shared BSS case). Furthermore, this is a step towards
allowing other ciphers than CCMP to be used with OSEN.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoDefine new QCA vendor command for coex priority config
Sachin Ahuja [Mon, 29 Oct 2018 11:31:12 +0000 (17:01 +0530)] 
Define new QCA vendor command for coex priority config

Add QCA_NL80211_VENDOR_SUBCMD_COEX_CONFIG vendor command
to set the priorities among different types of traffic of
WLAN/BT/Zigbee during coex scenarios.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agoAdd QCA vendor event to indicate throughput changes
vamsi krishna [Wed, 31 Oct 2018 21:50:21 +0000 (03:20 +0530)] 
Add QCA vendor event to indicate throughput changes

Add interface for drivers to report changes in TX/RX throughput
dynamically to user space. This information can be used by userspace
tools to tune kernel's TCP parameters in order to achieve peak
throughput. The driver may optionally provide guidance on which TCP
parameters to be configured for optimal performance along with the
values to be configured.

The TCP parameters that need to be tuned for peak performance are not
interface specific. Based on the guidance from the driver and
considering the other interfaces that may be affected with the new
configurations, a userspace tool has to choose the values to be
configured for these parameters to achieve optimal performance across
interfaces.

The throughput levels informed by the driver with this event are only
for providing guidance on TCP parameter tuning from userspace. The
driver may change the thresholds used to decide low or medium or high
throughput levels based on several parameters based on the PHY layer
capacity in the current connection, the number of packets being
dispatched per second, or the number of packets pending in queues, etc.
The throughput levels may not be consistent with the actual throughput
of the link.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>
6 years agotests: Use more correct OSU_METHOD value in sigma_dut_ap_hs20
Jouni Malinen [Tue, 6 Nov 2018 00:04:09 +0000 (02:04 +0200)] 
tests: Use more correct OSU_METHOD value in sigma_dut_ap_hs20

The OSU Providers List includes two providers, so there should be two
OSU_METHOD values listed just like there was two OSU_SERVER_URI URLs.

Signed-off-by: Jouni Malinen <jouni@codeaurora.org>