]> git.ipfire.org Git - thirdparty/hostap.git/log
thirdparty/hostap.git
14 months agoWNM: AP configuration to allow BSS max idle period requests
Jouni Malinen [Wed, 29 May 2024 16:41:59 +0000 (19:41 +0300)] 
WNM: AP configuration to allow BSS max idle period requests

Add a new hostapd configuration parameter max_acceptable_idle_period to
allow the AP to accept per-STA requested BSS max idle periods.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
14 months agoWNM: Allow a specific BSS max idle period to be requested
Jouni Malinen [Wed, 29 May 2024 16:40:27 +0000 (19:40 +0300)] 
WNM: Allow a specific BSS max idle period to be requested

Add a new wpa_supplicant network profile parameter max_idle that can be
used to specify a specific maximum idle period in units of 1000 TUs
(1.024 s) for associations.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
14 months agotests: Use consistent indentation level for clear_regdom_state()
Jouni Malinen [Wed, 29 May 2024 10:21:02 +0000 (13:21 +0300)] 
tests: Use consistent indentation level for clear_regdom_state()

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
14 months agotests: More coverage for WNM BSS max idle period management
Jouni Malinen [Wed, 29 May 2024 10:20:02 +0000 (13:20 +0300)] 
tests: More coverage for WNM BSS max idle period management

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
14 months agoWNM: Group rekeying skipping with BSS max idle period management
Jouni Malinen [Wed, 29 May 2024 09:57:08 +0000 (12:57 +0300)] 
WNM: Group rekeying skipping with BSS max idle period management

Allow hostapd to be configured to not disconnect a STA if the STA fails
to reply to a group key handshake when BSS max idle period management is
used. This might be needed for some STAs that use aggressive power
saving (e.g., battery powered IoT devices).

This is disabled by default since this can delayed group rekeying
slightly and also to maintain the previous behavior. The more relaxed
operation can be enabled with the new configuration parameter
no_disconnect_on_group_keyerror=1.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
14 months agoWNM: Configurable BSS Max Idle Period management on AP
Jouni Malinen [Wed, 29 May 2024 09:41:51 +0000 (12:41 +0300)] 
WNM: Configurable BSS Max Idle Period management on AP

Allow AP's behavior for BSS Max Idle Period management to be configured.
Previously, this was automatically enabled for all CONFIG_WNM_AP=y
builds. This can now be changed with the new hostapd configuration
parameter bss_max_idle:
0 = BSS Max Idle Period management disabled
1 = BSS Max Idle Period management enabled
    (default and the previous behavior)
2 = BSS Max Idle Period management enabled with requirement for
    protected keep-alive frames

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
14 months agoAdd QCA vendor attribute to get number of TX/RX packets for each NSS
Aleti Nageshwar Reddy [Mon, 6 May 2024 10:01:33 +0000 (15:31 +0530)] 
Add QCA vendor attribute to get number of TX/RX packets for each NSS

Add support to get the number of TX/RX packets for each NSS value from
the driver.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
14 months agoAdd vendor attributes to configure TX/RX NSS and chains per band
Aditya Kodukula [Wed, 8 May 2024 01:04:31 +0000 (18:04 -0700)] 
Add vendor attributes to configure TX/RX NSS and chains per band

Add attributes to QCA_NL80211_VENDOR_SUBCMD_SET_WIFI_CONFIGURATION
vendor command to configure asymmetric TX/RX NSS and chains per band.
Also document driver's response when existing attributes to configure
TX/RX NSS and chains for all the bands 2.4 GHz and 5/6 GHz are used in
the same command.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
14 months agoAdd kernel documentation for nss and chain configuration vendor command
Aditya Kodukula [Tue, 7 May 2024 19:48:42 +0000 (12:48 -0700)] 
Add kernel documentation for nss and chain configuration vendor command

Add kernel documentation to the attributes used in the vendor command
QCA_NL80211_VENDOR_SUBCMD_SET_WIFI_CONFIGURATION to configure the NSS
and chains values used for transmitting and receiving the data.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
14 months agoAdd QCA vendor attribute for uplink delay jitter
Veerendranath Jakkam [Fri, 3 May 2024 15:24:33 +0000 (20:54 +0530)] 
Add QCA vendor attribute for uplink delay jitter

Add uplink delay jitter attribute in responses of
QCA_NL80211_VENDOR_SUBCMD_GET_STA_INFO vendor command.

Signed-off-by: Veerendranath Jakkam <quic_vjakkam@quicinc.com>
14 months agoP2P: Fix fast IP address allocation for invitation of a persistent group
mtk30479 [Wed, 24 Jan 2024 03:51:43 +0000 (11:51 +0800)] 
P2P: Fix fast IP address allocation for invitation of a persistent group

Allocate static IPv4 address in EAPOL frames during 4-way handshake
instead of DHCP when using P2P invitation. wpa_s->current_bss needs to
be set for the P2P specific IP address assignment mechanism to be used
in wpa_supplicant_rsn_supp_set_config(). This worked for the initial P2P
connection, but not for some cases reinvoking a persistent group.

Since there is only one AP (P2P GO) in the P2P client case, the
conditions added in commit 4d3be9cdd143 ("Postpone updating of
wpa_s->current_bss till association event") are not needed and the
easiest approach for this is to allow current_bss to be set for
p2p_in_invitation cases. If the GO P2P Interface Address (BSSID) could
be determined for all the related cases, this could be addressed a bit
more cleanly by setting the go_bssid argument for
wpas_start_p2p_client(), but that can be left as a possible future step.

Signed-off-by: tzu-meng wang <tzu-meng.wang@mediatek.com>
14 months agoAdd a new QCA vendor attribute to set reduced power scan mode
Mukul Sharma [Fri, 3 May 2024 10:27:14 +0000 (15:57 +0530)] 
Add a new QCA vendor attribute to set reduced power scan mode

Userspace can use QCA_WLAN_VENDOR_ATTR_CONFIG_REDUCED_POWER_SCAN_MODE to
configure reduce power scan mode to the driver/firmware.

Signed-off-by: Mukul Sharma <quic_mukul@quicinc.com>
15 months agoAP MLD: Remove unused get_ml_rsn_info callback definition
Jouni Malinen [Thu, 25 Apr 2024 08:56:23 +0000 (11:56 +0300)] 
AP MLD: Remove unused get_ml_rsn_info callback definition

This is not used anymore after the previous AP MLD cleanup.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agotests: Cohosted MLDs connectivity testing
Aditya Kumar Singh [Mon, 22 Apr 2024 04:12:39 +0000 (09:42 +0530)] 
tests: Cohosted MLDs connectivity testing

Add a test case 'eht_mld_cohosted_connectivity' which creates two 2 link
AP MLDs and connect a 2 link MLD client to each one of them and test
data traffic.

Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agotests: Basic cohosted MLDs functionality testing
Aditya Kumar Singh [Mon, 22 Apr 2024 04:12:38 +0000 (09:42 +0530)] 
tests: Basic cohosted MLDs functionality testing

Add test cases to test basic cohosted MLDs functionality. Add helper
functions to create the configuration file, start hostapd instance.

Client connectivity test case will be added via a subsequent commit.

eht_mld_cohosted_discovery: 2 co-hosted MLDs without non-MLD RNR. Basic
bring up and beacon, MLD RNR, scan validation.

eht_mld_cohosted_discovery_with_rnr: Same like eht_mld_cohosted_discovery
but additionally non-MLD RNR (rnr=1) is also enabled. Validate the non-MLD
RNR as well.

Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoUpdate Probe Response template on BSS color change
Rathees Kumar R Chinannan [Mon, 8 Apr 2024 06:35:16 +0000 (12:05 +0530)] 
Update Probe Response template on BSS color change

When AP is beaconing only on the 6 GHz band and unsol_bcast_presp
interval is set, AP sends unsolicited broadcast Probe Response frames
for in-band discovery. hostapd sent the Probe Response template for this
frame only when setting a new Beacon frame template.

Extend this to update the Probe Response template during BSS color
change.

Signed-off-by: Rathees Kumar R Chinannan <quic_rrchinan@quicinc.com>
15 months agoUpdate Probe Response template on channel switch
Rathees Kumar R Chinannan [Mon, 8 Apr 2024 06:35:16 +0000 (12:05 +0530)] 
Update Probe Response template on channel switch

When AP is beaconing only on the 6 GHz band and unsol_bcast_presp
interval is set, AP sends unsolicited broadcast Probe Response frames
for in-band discovery. hostapd sent the Probe Response template for this
frame only when setting a new Beacon frame template.

Extend this to update the Probe Response template during channel switch.

Signed-off-by: Rathees Kumar R Chinannan <quic_rrchinan@quicinc.com>
15 months agoMore generic unsolicited broadcast Probe Response template setup
Rathees Kumar R Chinannan [Mon, 8 Apr 2024 06:35:16 +0000 (12:05 +0530)] 
More generic unsolicited broadcast Probe Response template setup

When AP is beaconing only on the 6 GHz band and unsol_bcast_presp
interval is set, AP sends unsolicited broadcast Probe Response frames
for in-band discovery. hostapd sent the Probe Response template for this
frame only when setting a new beacon.

As a preparation for extending this functionality to other cases, move
the generation of the unsolicited broadcast Probe Response template into
a more generic function and data structure.

Signed-off-by: Rathees Kumar R Chinannan <quic_rrchinan@quicinc.com>
15 months agotests: Update opclass 124 test to use opclass 125
Jouni Malinen [Wed, 24 Apr 2024 18:06:33 +0000 (21:06 +0300)] 
tests: Update opclass 124 test to use opclass 125

This is needed to match the implementation change to map the 5 GHz
channels 149-175 to the global operating class 125 instead of 124.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agotests: Fix a typo in opclass test descriptions
Jouni Malinen [Wed, 24 Apr 2024 18:01:28 +0000 (21:01 +0300)] 
tests: Fix a typo in opclass test descriptions

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agoMake selection of current opclass more generic for 20 MHz UNI-III channels
Amith A [Mon, 8 Apr 2024 09:11:16 +0000 (14:41 +0530)] 
Make selection of current opclass more generic for 20 MHz UNI-III channels

According to IEEE Std 802.11-2020, Operating classes Table E-2 (Europe)
and Table E-6 (China) map channels in the range 149 to 161 to the global
operating class 125, while Table E-1 (United States) maps these channels
to global operating classes 125 and 124 as well. The global operating
class 125 contains all channels from the global operating class 124 and
some additional channels.

Hence, to make the selection of the current operating class generic, use
operating class 125 for all 20 MHz channels in the range 149 to 161.

Signed-off-by: Amith A <quic_amitajit@quicinc.com>
15 months agoFILS: Add Operating Class and Primary Channel in FD for non-PSC chan
Sriram R [Mon, 22 Apr 2024 17:08:42 +0000 (22:38 +0530)] 
FILS: Add Operating Class and Primary Channel in FD for non-PSC chan

If a non-PSC 6 GHz channel with bandwidth higher than 20 MHz is
configured, duplicate beacons/FD/UBPR will be transmitted in other 20
MHz channels of the current configured bandwidth to aid in faster scan.
In such cases the duplicate FD needs to carry the Operating Class and
Primary Channel subfields for non-AP STAs to identify the primary
non-PSC.

IEEE Std 802.11-2020, 9.6.7.36 (FILS Discovery frame format):
"The Operating Class subfield specifies the operating class of the
Primary Channel of the transmitting AP (see 9.4.1.36).

The Primary Channel subfield is set to the channel number of the primary
channel (see 11.15.2) if the FILS Discovery frame is transmitted as a
non-HT duplicate PPDU; otherwise, the subfield is not present."

Hence, add the Operating Class and Primary Channel subfields if the
current channel is non-PSC and the channel bandwidth is 40 MHz or
higher.

Signed-off-by: Sriram R <quic_srirrama@quicinc.com>
Signed-off-by: Karthikeyan Kathirvel <quic_kathirve@quicinc.com>
15 months agoDefine QCA vendor commands for flow stats/classification
Rakesh Pillai [Mon, 11 Mar 2024 10:33:42 +0000 (03:33 -0700)] 
Define QCA vendor commands for flow stats/classification

Add nl80211 vendor commands and attributes for the collection of flow
stats and classification.

- QCA_NL80211_VENDOR_SUBCMD_FLOW_STATS
- QCA_NL80211_VENDOR_SUBCMD_FLOW_CLASSIFY_RESULT
- QCA_NL80211_VENDOR_SUBCMD_ASYNC_STATS_POLICY
- QCA_NL80211_VENDOR_SUBCMD_CLASSIFIED_FLOW_REPORT

Signed-off-by: Rakesh Pillai <quic_pillair@quicinc.com>
15 months agonl80211: Update link bandwidth when receiving channel switch event
Chenming Huang [Wed, 17 Apr 2024 03:32:27 +0000 (09:02 +0530)] 
nl80211: Update link bandwidth when receiving channel switch event

There is a chance that the driver has switched the channel width so we
should update the bandwidth, too, when receiving a channel switch event.
Otherwise, this may cause out of sync for bandwidth between i802_link
and hostapd_config.

Signed-off-by: Chenming Huang <quic_chenhuan@quicinc.com>
15 months agoAP MLD: Set link_id field in hostapd_freq_params when setting up AP
Chenming Huang [Wed, 17 Apr 2024 01:23:30 +0000 (06:53 +0530)] 
AP MLD: Set link_id field in hostapd_freq_params when setting up AP

If not set, 0 is set by default and this could fail in the following
code path when link ID is not matching:
hostapd_drv_set_ap -> wpa_driver_nl80211_set_ap -> nl80211_set_channel

Signed-off-by: Chenming Huang <quic_chenhuan@quicinc.com>
15 months agoAdd QCA vendor subcommand to suspend/resume AP interface
Purushottam Kushwaha [Fri, 29 Mar 2024 12:27:36 +0000 (17:57 +0530)] 
Add QCA vendor subcommand to suspend/resume AP interface

Add a new QCA vendor subcommand QCA_NL80211_VENDOR_SUBCMD_AP_SUSPEND to
allow suspend and resume the AP interface. When an AP is suspended, it
disconnects all connected clients and stops all TX/RX operations on the
AP interface. The driver retains the AP configuration and on resume, all
AP operations are resumed with the same configuration.

This subcommand is also used in the event path to notify userspace about
AP suspended or resumed state changes.

This uses attributes defined in enum qca_wlan_vendor_attr_ap_suspend.

Signed-off-by: Purushottam Kushwaha <quic_pkushwah@quicinc.com>
15 months agotests: Fix a race condition in mesh_link_probe
Jouni Malinen [Mon, 22 Apr 2024 20:14:08 +0000 (23:14 +0300)] 
tests: Fix a race condition in mesh_link_probe

Wait for both peers to be connected before checking MESH_LINK_PROBE
behavior. Without this, it was possible for a MESH_LINK_PROBE command to
be issues before the specific peer had been added and that would result
in the nl80211 command failing.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agotests: Fix autogo_chan_switch to not drop HT capability
Jouni Malinen [Mon, 22 Apr 2024 13:17:39 +0000 (16:17 +0300)] 
tests: Fix autogo_chan_switch to not drop HT capability

This test case ended up dropping HT capability on channel switch which
is now resulting in mac80211 disconnecting. Avoid this by leaving HT
enabled. In addition, check the P2P Client events explicitly.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agotests: AP MLD with two links when only one of the links is negotiated
Jouni Malinen [Mon, 22 Apr 2024 10:31:06 +0000 (13:31 +0300)] 
tests: AP MLD with two links when only one of the links is negotiated

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agoAP MLD: Add MLO Link KDE for each affiliated link in EAPOL-Key 3/4
Jouni Malinen [Mon, 22 Apr 2024 11:35:35 +0000 (14:35 +0300)] 
AP MLD: Add MLO Link KDE for each affiliated link in EAPOL-Key 3/4

Previously, MLO Link KDE was added only for each link that was
negotiated for the ML association. However, IEEE Std 802.11be/D5.0,
12.7.6.1 defines the MLO Link KDE to be included "for each affiliated
AP" which is not constrained by what the non-AP MLD might have requested
or what the negotiation outcome for this particular ML association is.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agoAP MLD: Do not store per-supplicant AP RSNE/RSNXE information
Jouni Malinen [Mon, 22 Apr 2024 11:19:57 +0000 (14:19 +0300)] 
AP MLD: Do not store per-supplicant AP RSNE/RSNXE information

There is no need to store the AP MLD's RSNE/RSNXE within per-supplicant
data structure in struct wpa_state_machine since those elements are
available from the generic authenticator data in struct
wpa_authenticator.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agoAP MLD: Do not store per-supplicant AP link MAC address information
Jouni Malinen [Mon, 22 Apr 2024 11:08:57 +0000 (14:08 +0300)] 
AP MLD: Do not store per-supplicant AP link MAC address information

There is no need to store the AP MLD's link MAC addresses within
per-supplicant data structure in struct wpa_state_machine since those
MAC addresses are available from the generic authenticator data in
struct wpa_authenticator.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agoAP MLD: Do not store per-supplicant AP MLD MAC address information
Jouni Malinen [Mon, 22 Apr 2024 10:31:43 +0000 (13:31 +0300)] 
AP MLD: Do not store per-supplicant AP MLD MAC address information

There is no need to store the AP MLD MAC address within per-supplicant
data structure in struct wpa_state_machine since that MLD MAC address is
available from the generic authenticator data in struct
wpa_authenticator.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agoAdd a vendor attribute value to set aggressive roaming mode
Aleti Nageshwar Reddy [Thu, 28 Mar 2024 09:35:13 +0000 (15:05 +0530)] 
Add a vendor attribute value to set aggressive roaming mode

Add QCA_ROAMING_MODE_AGGRESSIVE in enum qca_roaming_policy to set
aggressive roaming mode. In addition, document the existing enum values.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agotests: WPA2-PSK from RADIUS during 4-way handshake with Session-Timeout
Jouni Malinen [Sun, 21 Apr 2024 08:35:25 +0000 (11:35 +0300)] 
tests: WPA2-PSK from RADIUS during 4-way handshake with Session-Timeout

Signed-off-by: Jouni Malinen <j@w1.fi>
15 months agoAllow Session-Timeout with PSK RADIUS during 4-way handshake
Lee Harding [Tue, 9 Apr 2024 22:06:38 +0000 (15:06 -0700)] 
Allow Session-Timeout with PSK RADIUS during 4-way handshake

When the RADIUS response included a Session-Timeout attribute, but is
otherwise valid (an Access-Accept with a valid Tunnel-Password), the
association still failed due to the strict comparison of the accepted
value with HOSTAPD_ACL_ACCEPT. Apparently this combination wasn't
previously tested.

Extend this to allow a packet containing a valid Session-Timeout
attribute to be accepted by extending the "success" comparison to
include HOSTAPD_ACL_ACCEPT_TIMEOUT.

Fixes: 1c3438fec4ba ("RADIUS ACL/PSK check during 4-way handshake")
Signed-off-by: Lee Harding <somerandomstring@gmail.com>
15 months agowpa_cli: Make WPA_EVENT_CHANNEL_SWITCH events accessible to action scripts
arun.jose [Mon, 15 Apr 2024 08:48:22 +0000 (14:18 +0530)] 
wpa_cli: Make WPA_EVENT_CHANNEL_SWITCH events accessible to action scripts

Make the channel switch complete event, WPA_EVENT_CHANNEL_SWITCH,
accessible to the action script.

Signed-off-by: arun.jose <arun.jose.wg@bp.renesas.com>
15 months agoFix center segment indexes in channel switch fallback to non-5 GHz cases
Jurijs Soloveckis [Tue, 16 Apr 2024 11:47:36 +0000 (11:47 +0000)] 
Fix center segment indexes in channel switch fallback to non-5 GHz cases

Hardcoded conversion for 5 GHz band was used, but this won't work for
other cases. Set the correct center segment indexes in channel switch
fallback for non-5GHz band.

Signed-off-by: Jurijs Soloveckis <jsoloveckis@maxlinear.com>
15 months agoP2P: Call normal SD query callback on RX/TX race
Benjamin Berg [Wed, 17 Apr 2024 12:45:24 +0000 (15:45 +0300)] 
P2P: Call normal SD query callback on RX/TX race

If the TX success response races with the RX frame then the state
machine was simply move to P2P_SD_DURING_FIND to continue the operation.
However, this does not take into account broadcast queries where the
callback handler updates the peer's sd_pending_bcast_queries.

Fix this by exporting the callback and calling it directly. This is
fine, as the operation is cancelled immediately afterwards, ensuring
that the callback is not called a second time.

Signed-off-by: Benjamin Berg <benjamin.berg@intel.com>
15 months agodbus: Use correct values for persistent group
Andrei Otcheretianski [Wed, 17 Apr 2024 12:28:12 +0000 (15:28 +0300)] 
dbus: Use correct values for persistent group

D-Bus expects "persistent" to be a bool (0/1) and crashes otherwise.
Since persistent may also be 2 convert it to boolean.

Signed-off-by: Andrei Otcheretianski <andrei.otcheretianski@intel.com>
Signed-off-by: Benjamin Berg <benjamin.berg@intel.com>
15 months agowpa_supplicant: Do not allow fast associate before scanning 6 GHz
Ilan Peer [Mon, 8 Apr 2024 13:07:01 +0000 (16:07 +0300)] 
wpa_supplicant: Do not allow fast associate before scanning 6 GHz

In case the channel map was updated to include the 6 GHz but these channels
were not scanned yet, do not allow fast associate.

Signed-off-by: Ilan Peer <ilan.peer@intel.com>
15 months agoctrl_iface: Allow sending ML probe without AP MLD ID
Benjamin Berg [Mon, 8 Apr 2024 13:07:00 +0000 (16:07 +0300)] 
ctrl_iface: Allow sending ML probe without AP MLD ID

If one sends a Probe Request frame to a non-TX BSSID, no AP MLD ID
should be included in the request. Permit mld_id to be -1 so that it is
not a required argument and can be left out.

Signed-off-by: Benjamin Berg <benjamin.berg@intel.com>
15 months agoMLD: Use AP MLD MAC address with deauthenticate
Ilan Peer [Mon, 8 Apr 2024 13:06:59 +0000 (16:06 +0300)] 
MLD: Use AP MLD MAC address with deauthenticate

When the authentication is an MLD authentication need to use the AP MLD
MAC address when requesting the driver to deauthenticate.

Signed-off-by: Ilan Peer <ilan.peer@intel.com>
15 months agoSME: MLD: Clear MLD state only after the deauthentication
Ilan Peer [Mon, 8 Apr 2024 13:06:59 +0000 (16:06 +0300)] 
SME: MLD: Clear MLD state only after the deauthentication

In case of failure handling an Authentication frame from the AP MLD,
clear the MLD state only after the deauthentication is done. This allows
deauthentication process to use the AP MLD MAC address.

Signed-off-by: Ilan Peer <ilan.peer@intel.com>
15 months agoSME: MLD: Deauthenticate when failing to parse ML element
Ilan Peer [Mon, 8 Apr 2024 13:06:57 +0000 (16:06 +0300)] 
SME: MLD: Deauthenticate when failing to parse ML element

If parsing the basic ML element in the Authenticate frame fails,
instead of only disassociating, completely deauthenticate so all
state machines would be in a consistent state.

Signed-off-by: Ilan Peer <ilan.peer@intel.com>
15 months agowpa_supplicant: Do not roam to an associated link
Ilan Peer [Mon, 8 Apr 2024 13:06:56 +0000 (16:06 +0300)] 
wpa_supplicant: Do not roam to an associated link

When considering to roam to a different BSS and the connection
is an MLD connection, do not roam to a BSS which is already
included in the MLD connection.

Signed-off-by: Ilan Peer <ilan.peer@intel.com>
15 months agotests: Wait after removing a BSS
Ilan Peer [Mon, 8 Apr 2024 13:06:55 +0000 (16:06 +0300)] 
tests: Wait after removing a BSS

When a BSS is removed, the flow continues without actually
waiting for the AP to be stopped. This is racy in flows that
actually expect the AP to be stopped, e.g., test_ap_bss_add_remove().

Try to mitigate such cases by adding a short sleep after the
AP is removed.

Signed-off-by: Ilan Peer <ilan.peer@intel.com>
15 months agoClear connect_without_scan on network profile removal
Jouni Malinen [Sat, 20 Apr 2024 15:37:35 +0000 (18:37 +0300)] 
Clear connect_without_scan on network profile removal

wpa_s->connect_without_scan could have been left pointing to invalid
network when a network profile was removed. It seems to be possible for
this to happen in some hwsim test case scenarios under specific timing,
but the exact reason for this is not clear. In any case, this pointer
needs to be cleared.

Signed-off-by: Jouni Malinen <j@w1.fi>
15 months agotests: Clear scan cache in ap_hs20_anqp_invalid_gas_response
Jouni Malinen [Sat, 20 Apr 2024 09:27:03 +0000 (12:27 +0300)] 
tests: Clear scan cache in ap_hs20_anqp_invalid_gas_response

This is needed to avoid unexpected behavior if a previously executed
test case has left a BSS entry with Interworking emabled into the case.

Signed-off-by: Jouni Malinen <j@w1.fi>
15 months agoCheck whether to skip a BSS in RNR with a shared helper
Jouni Malinen [Sat, 20 Apr 2024 15:11:55 +0000 (18:11 +0300)] 
Check whether to skip a BSS in RNR with a shared helper

The functions that determine the length of the RNR information and that
build the actual RNR need to use the same conditions for skipping BSSs.
Use a shared helper function for this to avoid having to maintain two
copies of the same implementation and the risking those getting out of
sync.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agoFix RNR building for co-location and MLO
Aditya Kumar Singh [Thu, 28 Mar 2024 18:16:50 +0000 (23:46 +0530)] 
Fix RNR building for co-location and MLO

RNR formation for co-location or MLO did not work as expected. Fix this.

For example, during co-location, if the BSS is also its ML partner
there is no need to include a separate TBTT for it.

Also, during co-location, if the BSS is not its partner but it is ML
capable, the TBTT length should be 16 bytes and it should include the
MLD Parameters for it in the RNR.

During co-location, for a given Neighbor AP (operating on a given
channel and op-class) if it has BSSs which are ML capable as well as
BSSs which are not, there should be two Neighbor AP Info present: one
indicating TBTT length as 13 bytes and one indicating TBTT info length
as 16 bytes.

Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Add link details in STATUS command
Harshitha Prem [Thu, 28 Mar 2024 18:16:49 +0000 (23:46 +0530)] 
AP MLD: Add link details in STATUS command

Include link ID and partner link details in the STATUS command output
for AP MLDs.

The details would be seen as below for an AP MLD interface:

$ hostapd_cli -i wlan0 status | grep link
num_links=1
link_id=0
link_addr=AA:BB:CC:DD:EE:FF

$ hostapd_cli -i wlan1 status | grep link
num_links=2
link_id=0
link_addr=AA:BB:CC:DD:EE:FF
partner_link[1]=AA:BB:CC:DD:EE:AA

Signed-off-by: Harshitha Prem <quic_hprem@quicinc.com>
Co-developed-by: Manish Dharanenthiran <quic_mdharane@quicinc.com>
Signed-off-by: Manish Dharanenthiran <quic_mdharane@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Link-specific flushing of stations
Aditya Kumar Singh [Thu, 28 Mar 2024 18:16:48 +0000 (23:46 +0530)] 
AP MLD: Link-specific flushing of stations

Whenever a BSS was set up,hostapd flushed all stations via the flush()
driver operation which maps to NL80211_CMD_DEL_STATION in the nl80211
interface. However, in case of MLO, a station could have been connected
to other links by the time this link is coming up. Since link ID was not
passed to flush(), all those stations entries were also removed in the
driver which is wrong.

Include the link ID along with the command in AP MLD so that the driver
can use this link ID and flush only the stations that use the passed
link ID as one of their links.

Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Run authenticator state machine for all links
Rameshkumar Sundaram [Thu, 28 Mar 2024 18:16:47 +0000 (23:46 +0530)] 
AP MLD: Run authenticator state machine for all links

This is needed for MLO group rekeying.

Signed-off-by: Rameshkumar Sundaram <quic_ramess@quicinc.com>
Co-developed-by: Adil Saeed Musthafa <quic_adilm@quicinc.com>
Signed-off-by: Adil Saeed Musthafa <quic_adilm@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Support group rekeying for MLO
Rameshkumar Sundaram [Thu, 28 Mar 2024 18:16:47 +0000 (23:46 +0530)] 
AP MLD: Support group rekeying for MLO

Group rekeying was not supported for ML stations when non-association
link initiates a group rekey. Support this by arming the group key rekey
timer on one of the affiliated links and whenever this timer fires,
rekey group keys on all the affiliated links.

Signed-off-by: Rameshkumar Sundaram <quic_ramess@quicinc.com>
Co-developed-by: Adil Saeed Musthafa <quic_adilm@quicinc.com>
Signed-off-by: Adil Saeed Musthafa <quic_adilm@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Calculate ML KDE length separately for each link
Rameshkumar Sundaram [Thu, 28 Mar 2024 18:16:47 +0000 (23:46 +0530)] 
AP MLD: Calculate ML KDE length separately for each link

Calculate links specific MLO GTK/IGTK/BIGTK KDE lengths based on
corresponding cipher and key instead of taking length of one link and
multiplying it by no of associated links. This is needed since the group
ciphers might be different between the affiliated links.

Signed-off-by: Rameshkumar Sundaram <quic_ramess@quicinc.com>
Co-developed-by: Adil Saeed Musthafa <quic_adilm@quicinc.com>
Signed-off-by: Adil Saeed Musthafa <quic_adilm@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Mark GKeyDone completed for STAs in a helper function
Rameshkumar Sundaram [Thu, 28 Mar 2024 18:16:47 +0000 (23:46 +0530)] 
AP MLD: Mark GKeyDone completed for STAs in a helper function

This makes it easier to extend the design for MLO group rekeying.

Signed-off-by: Rameshkumar Sundaram <quic_ramess@quicinc.com>
Co-developed-by: Adil Saeed Musthafa <quic_adilm@quicinc.com>
Signed-off-by: Adil Saeed Musthafa <quic_adilm@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Debug print of MLO KDE lengths
Rameshkumar Sundaram [Thu, 28 Mar 2024 18:16:47 +0000 (23:46 +0530)] 
AP MLD: Debug print of MLO KDE lengths

Signed-off-by: Rameshkumar Sundaram <quic_ramess@quicinc.com>
Co-developed-by: Adil Saeed Musthafa <quic_adilm@quicinc.com>
Signed-off-by: Adil Saeed Musthafa <quic_adilm@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Require same AKM and pairwise cipher for all links
Rameshkumar Sundaram [Thu, 28 Mar 2024 18:16:47 +0000 (23:46 +0530)] 
AP MLD: Require same AKM and pairwise cipher for all links

Signed-off-by: Rameshkumar Sundaram <quic_ramess@quicinc.com>
Co-developed-by: Adil Saeed Musthafa <quic_adilm@quicinc.com>
Signed-off-by: Adil Saeed Musthafa <quic_adilm@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoUse defined values for RSN PN length
Jouni Malinen [Sat, 20 Apr 2024 13:15:01 +0000 (16:15 +0300)] 
Use defined values for RSN PN length

Make the code more readable by using a define for the PN length to avoid
potential confusion of this 6 octet length with the MAC address length.
In addition, Use ETH_ALEN more consistently for the latter.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agoAP MLD: Enhance authenticator state machine
Rameshkumar Sundaram [Thu, 28 Mar 2024 18:16:46 +0000 (23:46 +0530)] 
AP MLD: Enhance authenticator state machine

Add required ML specific members in struct wpa_authenticator and struct
wpa_state_machine to maintain self and partner link information.

Maintain state machine object in all associated link stations and
destroy/remove references from the same whenever link stations are
getting removed.

Increase the wpa_group object reference count for all links in which ML
station is getting associated and release the same whenever link
stations are getting removed.

Signed-off-by: Rameshkumar Sundaram <quic_ramess@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Skip association link processing in ML info
Aditya Kumar Singh [Thu, 28 Mar 2024 18:16:45 +0000 (23:46 +0530)] 
AP MLD: Skip association link processing in ML info

All links were iterated over during processing ML info in Association
Request frame. However, the association link info will not be present in
the ML info and hence the following debug print is observed during ML
association (assoc link is 1):

MLD: No link match for link_id=1

Skip processing for the association link to avoid this.

Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Update all partner links' beacons
Sriram R [Thu, 28 Mar 2024 18:16:44 +0000 (23:46 +0530)] 
AP MLD: Update all partner links' beacons

Whenever there is a beacon update for any one of the affiliated link,
all the other partner links' beacon should be refreshed.

Signed-off-by: Sriram R <quic_srirrama@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Handle link_id in EAPOL RX handler
Sriram R [Thu, 28 Mar 2024 18:16:43 +0000 (23:46 +0530)] 
AP MLD: Handle link_id in EAPOL RX handler

Add link ID support into EAPOL RX handler so that the events can
be routed to the appropriate link BSSs.

Signed-off-by: Sriram R <quic_srirrama@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Handle link_id in EAPOL TX status handler
Sriram R [Thu, 28 Mar 2024 18:16:43 +0000 (23:46 +0530)] 
AP MLD: Handle link_id in EAPOL TX status handler

Add link ID support into EAPOL TX status handler so that the events can
be routed to the appropriate link BSSs.

Check each BSS's other partner link BSS STA list as well in
hostapd_find_by_sta() to support this.

Signed-off-by: Sriram R <quic_srirrama@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agohostapd: Make hostapd_eapol_tx_status() function static
Sriram R [Thu, 28 Mar 2024 18:16:42 +0000 (23:46 +0530)] 
hostapd: Make hostapd_eapol_tx_status() function static

hostapd_eapol_tx_status() function is used only in drv_callbacks.c.
However, it is defined in ieee802_11.c which is not really the correct
place for it.

Hence, move the function into drv_callbacks.c and make it static.

No functionality changes.

Signed-off-by: Sriram R <quic_srirrama@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agonl80211: Move control port TX status to per BSS handling
Sriram R [Thu, 28 Mar 2024 18:16:41 +0000 (23:46 +0530)] 
nl80211: Move control port TX status to per BSS handling

Control port TX status events were handled on drv's first BSS
only. However, to support multiple MLDs there is requirement to handle
this on a given BSS.

Use the passed BSS instead of always going with drv's first BSS.

Signed-off-by: Sriram R <quic_srirrama@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agonl80211: Move Management frame TX status to per BSS handling
Sriram R [Thu, 28 Mar 2024 18:16:41 +0000 (23:46 +0530)] 
nl80211: Move Management frame TX status to per BSS handling

Management frame TX status events were handled on drv's first BSS
only. However, to support multiple MLDs there is requirement to handle
this on a given BSS.

Use the passed BSS instead of always going with drv's first BSS.

Signed-off-by: Sriram R <quic_srirrama@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD/nl80211: Pass ctx in mlme_event_mgmt()
Sriram R [Thu, 28 Mar 2024 18:16:40 +0000 (23:46 +0530)] 
AP MLD/nl80211: Pass ctx in mlme_event_mgmt()

Pass ctx in mlme_event_mgmt(). This will help in routing the event
properly to the link BSS.

Signed-off-by: Sriram R <quic_srirrama@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Use link_id in the get_hapd_bssid() helper function
Sriram R [Thu, 28 Mar 2024 18:16:39 +0000 (23:46 +0530)] 
AP MLD: Use link_id in the get_hapd_bssid() helper function

The get_hapd_bssid() function matched the given BSSID in all BSSs of its
own interface. However with MLO, there is requirement to check its own
partner BSS at least.

Compare the BSS's link partners as well and if the specified link ID
matches the link ID of the partner, return the BSS.

Signed-off-by: Sriram R <quic_srirrama@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP NLD: Extend support for cohosted ML BSS
Sriram R [Thu, 28 Mar 2024 18:16:38 +0000 (23:46 +0530)] 
AP NLD: Extend support for cohosted ML BSS

Modify necessary helper functions to support multiple BSS support for
MLO to make the changes scalable.

Signed-off-by: Sriram R <quic_srirrama@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Support cohosted ML BSS
Sriram R [Thu, 28 Mar 2024 18:16:37 +0000 (23:46 +0530)] 
AP MLD: Support cohosted ML BSS

AP MLD was added with an assumption of only a single BSS per link in the
hostapd configuration. This needs to be extended when a cohosted ML BSS
exist in the same configuration.

Extend the support for cohosted BSSs. This is required for MBSSID MLO
support as well.

Signed-off-by: Sriram R <quic_srirrama@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Reset authenticator state machine's ML info
Aditya Kumar Singh [Thu, 28 Mar 2024 18:16:36 +0000 (23:46 +0530)] 
AP MLD: Reset authenticator state machine's ML info

Authenticator state machine ML info was set only when it was created.
However, if the association is tried again, the state machine will
already exist and hence the ML info will not be refreshed. This leads to
an issue where if in the subsequent association request, the MLD info is
different than the old info, validation of it will fail.

Fix this issue by refreshing the authenticator state machine's ML info
every time association request is handled.

Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoRemove the bssid argument from send_auth_reply()
Jouni Malinen [Sat, 20 Apr 2024 08:28:54 +0000 (11:28 +0300)] 
Remove the bssid argument from send_auth_reply()

This became unused, so remove the argument from this function, all its
callers, and from places that became unused with these changes.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agoAP MLD: Handle authentication and association on link address
Sriram R [Wed, 17 Apr 2024 04:27:44 +0000 (09:57 +0530)] 
AP MLD: Handle authentication and association on link address

The nl80211 driver interface function mlme_event_mgmt_tx_status(),
filled in link_id only if the frame was the last transmitted on the
whole drv (driver) level. With co-hosted MLDs, there could be cases
where multiple frames are sent out by various interfaces (BSS) under the
same drv. Now while handling the TX status, only one interface will get
the proper link_id. Rest will get -1 and the event will be routed to the
first BSS always. If the frame was not sent from the first BSS this
leads to possibility of the frame getting dropped.

Hence to make the underlying link identification easier, modify
authentication and association frames to be always sent with the link
address as A1 and A3 for ease of TX status handling.

Signed-off-by: Sriram R <quic_srirrama@quicinc.com>
Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Use if/else/endif comments more consistently
Jouni Malinen [Sat, 20 Apr 2024 12:58:12 +0000 (15:58 +0300)] 
AP MLD: Use if/else/endif comments more consistently

Include the condition in #else similarly to #endif.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agotests: Enable TLSv1.3 test cases with OpenSSL 3.3
Jouni Malinen [Sat, 20 Apr 2024 08:08:50 +0000 (11:08 +0300)] 
tests: Enable TLSv1.3 test cases with OpenSSL 3.3

Signed-off-by: Jouni Malinen <j@w1.fi>
15 months agonl80211: Restore libnl3-route inclusion for full VLAN support with netlink
Jouni Malinen [Fri, 19 Apr 2024 16:04:14 +0000 (19:04 +0300)] 
nl80211: Restore libnl3-route inclusion for full VLAN support with netlink

The changes in nl80211 to get rid of the libnl3-route dependency are not
sufficient to fully remove the depency from other parts of the code.
Revert the makefile related changes from that commit to avoid build
issues for cases where CONFIG_FULL_DYNAMIC_VLAN=y and
CONFIG_VLAN_NETLINK=y are used without CONFIG_DRIVER_MACSEC_LINUX=y
pulling in the needed library.

Fixes: a210fdb1c717 ("nl80211: Rewrite neigh code to not depend on libnl3-route")
Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agoAdd a vendor attribute to configure custom keep-alive interval for STA
Aleti Nageshwar Reddy [Thu, 7 Mar 2024 09:30:15 +0000 (15:00 +0530)] 
Add a vendor attribute to configure custom keep-alive interval for STA

Introduce an attribute QCA_WLAN_VENDOR_ATTR_CONFIG_KEEP_ALIVE_INTERVAL
in QCA_NL80211_VENDOR_SUBCMD_SET_WIFI_CONFIGURATION to configure
station's keep-alive interval to the driver/firmware. This can be used
to resolve kickout issues from APs which kick out STAs before the BSS
maximum idle period expires.

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agoAdd QCA vendor interface for reporting station info in unicast event
Veerendranath Jakkam [Mon, 8 Apr 2024 22:09:47 +0000 (03:39 +0530)] 
Add QCA vendor interface for reporting station info in unicast event

Add a QCA vendor command for registering NL80211_CMD_GET_STATION
response as a unicast event when there is a NL80211_CMD_GET_STATION
request from any userspace module.

The driver will send the unicast events with the same netlink port ID
which is used by userspace application for sending the registration
command. If multiple registration commands are received with different
netlink port IDs, the driver will send unicast event with each netlink
port ID separately.

Userspace application can deregister the unicast events with disable
configuration. The registrations will be removed automatically by the
driver when the corresponding netlink socket is closed.

This will help avoid multiple NL80211_CMD_GET_STATION requests from
different userspace applications in short span. The userspace
application which registers for the unicast event can avoid sending
NL80211_CMD_GET_STATION request again if the response is available with
a recently received unicast event.

Signed-off-by: Veerendranath Jakkam <quic_vjakkam@quicinc.com>
15 months agoAdd TWT responder support for AP in HT and VHT modes
Manaswini Paluri [Wed, 28 Feb 2024 05:41:43 +0000 (11:11 +0530)] 
Add TWT responder support for AP in HT and VHT modes

Add support for TWT responder for AP operating in HT and VHT modes by
introducing a new configuration parameter ht_vht_twt_responder. When
this is enabled, TWT responder mode support in HT and VHT modes is
enabled if the driver supports this and is disabled otherwise.

Signed-off-by: Manaswini Paluri<quic_mpaluri@quicinc.com>
15 months agoAdd QCA vendor feature flag for TWT responder support in HT and VHT modes
Manaswini Paluri [Mon, 9 Oct 2023 12:06:31 +0000 (17:36 +0530)] 
Add QCA vendor feature flag for TWT responder support in HT and VHT modes

Add a feature flag to indicate driver support for TWT responder for AP
operating in HT and VHT modes.

Signed-off-by: Manaswini Paluri<quic_mpaluri@quicinc.com>
15 months agotests: Update RSA 3k certificates (2024)
Jouni Malinen [Wed, 17 Apr 2024 18:26:36 +0000 (21:26 +0300)] 
tests: Update RSA 3k certificates (2024)

These have not yet expired, but it is easier to get in sync with all
certificate updates.

Signed-off-by: Jouni Malinen <j@w1.fi>
15 months agotests: Update server and user certificates (2024)
Jouni Malinen [Wed, 17 Apr 2024 18:25:56 +0000 (21:25 +0300)] 
tests: Update server and user certificates (2024)

At least some of the previous versions have expired, so need to re-sign
these to avoid EAP test case failures. This contains updates from
running tests/hwsim/auth_server/update.sh.

Signed-off-by: Jouni Malinen <j@w1.fi>
15 months agotests: Fix sigma_dut_dpp_pb_ap to clear sae_groups
Jouni Malinen [Tue, 16 Apr 2024 08:22:41 +0000 (11:22 +0300)] 
tests: Fix sigma_dut_dpp_pb_ap to clear sae_groups

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agonl80211: Send link_id on sta_deauth()
Aditya Kumar Singh [Thu, 28 Mar 2024 18:16:34 +0000 (23:46 +0530)] 
nl80211: Send link_id on sta_deauth()

i802_sta_deauth() already has the link_id passed to it in its arguments.
Use that to pass it down to send MLME handler as well.

Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agonl80211: Print the interface name in debug during link add
Aditya Kumar Singh [Thu, 28 Mar 2024 18:16:33 +0000 (23:46 +0530)] 
nl80211: Print the interface name in debug during link add

Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agonl80211: Generate link add command on per-BSS basis for AP MLD
Aditya Kumar Singh [Thu, 28 Mar 2024 18:16:32 +0000 (23:46 +0530)] 
nl80211: Generate link add command on per-BSS basis for AP MLD

Function nl80211_link_add() created the link add netlink message on drv
basis which in turn always uses the drv's first BSS. To support link add
for various other interfaces, use the per-BSS function to create the
netlink message.

Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agoAP MLD: Simplify for_each_mld_link() macro
Aditya Kumar Singh [Thu, 28 Mar 2024 18:16:31 +0000 (23:46 +0530)] 
AP MLD: Simplify for_each_mld_link() macro

for_each_mld_link() macro used three nested for loops. Since now the
affliated links are linked together via a linked list, the logic can be
improved by using dl_list_for_each() macro instead which uses one for
loop.

Modify for_each_mld_link() macro to use dl_list_for_each() instead.

Signed-off-by: Aditya Kumar Singh <quic_adisi@quicinc.com>
15 months agotests: Add test with stuck ECSA in Probe Response frames
Johannes Berg [Thu, 28 Mar 2024 13:07:00 +0000 (14:07 +0100)] 
tests: Add test with stuck ECSA in Probe Response frames

Add a test behaving like an Asus RT-AC53 with firmware
3.0.0.4.380_10760-g21a5898, which (in some cases?) can have an ECSA
element stuck in the probe response, when the channel switch is long
finished.

Signed-off-by: Johannes Berg <johannes.berg@intel.com>
15 months agotests: Add connecting-while-CSA tests
Johannes Berg [Thu, 28 Mar 2024 13:06:59 +0000 (14:06 +0100)] 
tests: Add connecting-while-CSA tests

Add a few tests to validate what happens with connections
while an AP is doing CSA:
 - quiet to diff channel (shouldn't connect)
 - quiet to same channel (shouldn't connect)
 - non-quiet to diff channel (shouldn't connect)
 - non-quiet to same channel (should connect)

Signed-off-by: Johannes Berg <johannes.berg@intel.com>
15 months agohostapd: Add support for testing Probe Response frame elements
Johannes Berg [Thu, 28 Mar 2024 13:06:58 +0000 (14:06 +0100)] 
hostapd: Add support for testing Probe Response frame elements

Add support for additional (vendor) elements to be added
to only Probe Response frames, for testing.

Signed-off-by: Johannes Berg <johannes.berg@intel.com>
15 months agotests: Fix he_6ghz_reg to clear sae_groups
Jouni Malinen [Mon, 15 Apr 2024 20:35:29 +0000 (23:35 +0300)] 
tests: Fix he_6ghz_reg to clear sae_groups

Signed-off-by: Jouni Malinen <quic_jouni@quicinc.com>
15 months agobuild: De-duplicate _DIRS before calling mkdir
Felix Fietkau [Thu, 4 Apr 2024 13:03:27 +0000 (15:03 +0200)] 
build: De-duplicate _DIRS before calling mkdir

If the build path is long, the contents of the _DIRS variable can be
very long, since it repeats the same directories very often. In some
cases, this has triggered an "Argument list too long" build error.

Reported-by: Robert Marko <robimarko@gmail.com>
Suggested-by: Eneas U de Queiroz <cotequeiroz@gmail.com>
Signed-off-by: Felix Fietkau <nbd@nbd.name>
15 months agohostapd: Only attempt to set QoS map if supported by the driver
Felix Fietkau [Thu, 4 Apr 2024 10:52:17 +0000 (12:52 +0200)] 
hostapd: Only attempt to set QoS map if supported by the driver

This fixes issues with full-MAC drivers like brcmfmac.

Signed-off-by: Felix Fietkau <nbd@nbd.name>
15 months agoSupport qos_map_set without CONFIG_INTERWORKING
Felix Fietkau [Thu, 4 Apr 2024 10:52:16 +0000 (12:52 +0200)] 
Support qos_map_set without CONFIG_INTERWORKING

This feature is useful on its own even without full interworking
support.

Signed-off-by: Felix Fietkau <nbd@nbd.name>
15 months agomesh: Allow processing authentication frames in blocked state
Felix Fietkau [Thu, 4 Apr 2024 10:52:15 +0000 (12:52 +0200)] 
mesh: Allow processing authentication frames in blocked state

If authentication fails repeatedly, e.g., because of a weak signal, the
link can end up in blocked state. If one of the nodes tries to establish
a link again before it is unblocked on the other side, it will block the
link to that other side. The same happens on the other side when it
unblocks the link. In that scenario, the link never recovers on its own.

To fix this, allow restarting authentication even if the link is in
blocked state, but don't initiate the attempt until the blocked period
is over. This reverts commit 09d96de09e01 ("mesh: Drop Authentication
frames from BLOCKED STA").

Signed-off-by: Felix Fietkau <nbd@nbd.name>
15 months agonl80211: Rewrite neigh code to not depend on libnl3-route
Felix Fietkau [Thu, 4 Apr 2024 10:52:14 +0000 (12:52 +0200)] 
nl80211: Rewrite neigh code to not depend on libnl3-route

This removes an unnecessary dependency and also makes the code smaller.

Signed-off-by: Felix Fietkau <nbd@nbd.name>
15 months agondisc_snoop: Call dl_list_del() before freeing IPv6 addresses
Felix Fietkau [Thu, 4 Apr 2024 10:52:13 +0000 (12:52 +0200)] 
ndisc_snoop: Call dl_list_del() before freeing IPv6 addresses

This fixes a segmentation fault on STA disconnect in case IPv6 addresses
where learned for the STA based on snooped neighbor solicication.

Fixes: bd00c4311c0e ("AP: Add Neighbor Discovery snooping mechanism for Proxy ARP")
Signed-off-by: Felix Fietkau <nbd@nbd.name>
15 months agoCancel channel_list_update_timeout() in hostapd_cleanup_iface_partial()
Felix Fietkau [Thu, 4 Apr 2024 10:52:12 +0000 (12:52 +0200)] 
Cancel channel_list_update_timeout() in hostapd_cleanup_iface_partial()

This fixes a crash when disabling an interface during channel list
update.

Signed-off-by: Felix Fietkau <nbd@nbd.name>