diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0003-nl80211-Report-connection-authorized-in-EVENT_ASSOC.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0003-nl80211-Report-connection-authorized-in-EVENT_ASSOC.patch new file mode 100644 index 000000000..8de33d112 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0003-nl80211-Report-connection-authorized-in-EVENT_ASSOC.patch @@ -0,0 +1,43 @@ +From 21271c00b29db8c178aa704daaf665967e141d47 Mon Sep 17 00:00:00 2001 +From: Chung-Hsien Hsu +Date: Tue, 29 Oct 2019 15:55:21 +0800 +Subject: [PATCH 03/49] nl80211: Report connection authorized in EVENT_ASSOC + +When roaming in a network that requires 802.1X authentication, device +driver could set the authorized flag if 4-way handshake offload or FT +offload is considered. + +This patch enables the report of connection authorized in EVENT_ASSOC to +indicate the requirement of 802.1X authentication. + +Signed-off-by: Chung-Hsien Hsu +--- + src/drivers/driver_nl80211_event.c | 5 +++-- + 1 file changed, 3 insertions(+), 2 deletions(-) + +diff --git a/src/drivers/driver_nl80211_event.c b/src/drivers/driver_nl80211_event.c +index 0f0a01d01..fe91fff90 100644 +--- a/src/drivers/driver_nl80211_event.c ++++ b/src/drivers/driver_nl80211_event.c +@@ -557,7 +557,7 @@ static void mlme_event_connect(struct wpa_driver_nl80211_data *drv, + wpa_ssid_txt(drv->ssid, drv->ssid_len)); + } + +- if (authorized && nla_get_u8(authorized)) { ++ if (authorized && nla_get_flag(authorized)) { + event.assoc_info.authorized = 1; + wpa_printf(MSG_DEBUG, "nl80211: connection authorized"); + } +@@ -2988,7 +2988,8 @@ static void do_process_drv_event(struct i802_bss *bss, int cmd, + tb[NL80211_ATTR_RESP_IE], + tb[NL80211_ATTR_TIMED_OUT], + tb[NL80211_ATTR_TIMEOUT_REASON], +- NULL, NULL, NULL, ++ tb[NL80211_ATTR_PORT_AUTHORIZED], ++ NULL, NULL, + tb[NL80211_ATTR_FILS_KEK], + NULL, + tb[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM], +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0005-OpenSSL-Fix-build-with-OpenSSL-1.0.1.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0005-OpenSSL-Fix-build-with-OpenSSL-1.0.1.patch new file mode 100644 index 000000000..879bc9ba7 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0005-OpenSSL-Fix-build-with-OpenSSL-1.0.1.patch @@ -0,0 +1,31 @@ +From 78e7373ad2cf51a881a12e55c3db01580932539e Mon Sep 17 00:00:00 2001 +From: Chung-Hsien Hsu +Date: Fri, 8 Nov 2019 13:23:05 -0600 +Subject: [PATCH 05/49] OpenSSL: Fix build with OpenSSL 1.0.1 + +The openssl_debug_dump_certificate_chains() implementation used +SSL_CERT_SET_FIRST and SSL_CERT_SET_NEXT, which were added in OpenSSL +1.0.2. Bypass this function to fix build failure with OpenSSL 1.0.1. + +Signed-off-by: Chung-Hsien Hsu +--- + src/crypto/tls_openssl.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/src/crypto/tls_openssl.c b/src/crypto/tls_openssl.c +index c9e00b3af..9e5b48a9c 100644 +--- a/src/crypto/tls_openssl.c ++++ b/src/crypto/tls_openssl.c +@@ -5410,7 +5410,8 @@ static void openssl_debug_dump_certificates(SSL_CTX *ssl_ctx) + + static void openssl_debug_dump_certificate_chains(SSL_CTX *ssl_ctx) + { +-#if !defined(LIBRESSL_VERSION_NUMBER) && !defined(BORINGSSL_API_VERSION) ++#if !defined(LIBRESSL_VERSION_NUMBER) && !defined(BORINGSSL_API_VERSION) && \ ++ OPENSSL_VERSION_NUMBER >= 0x10002000L + int res; + + for (res = SSL_CTX_set_current_cert(ssl_ctx, SSL_CERT_SET_FIRST); +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0006-nl80211-Check-SAE-authentication-offload-support.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0006-nl80211-Check-SAE-authentication-offload-support.patch new file mode 100644 index 000000000..9be859305 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0006-nl80211-Check-SAE-authentication-offload-support.patch @@ -0,0 +1,45 @@ +From f6eed1d9e56502fd8cbab309e94f9787795c3e35 Mon Sep 17 00:00:00 2001 +From: Chung-Hsien Hsu +Date: Tue, 29 Oct 2019 17:13:27 +0800 +Subject: [PATCH 06/49] nl80211: Check SAE authentication offload support + +Set WPA_DRIVER_FLAGS2_SAE_OFFLOAD flag if driver indicates SAE +authentication offload support. + +Signed-off-by: Chung-Hsien Hsu +--- + src/drivers/driver.h | 2 ++ + src/drivers/driver_nl80211_capa.c | 4 ++++ + 2 files changed, 6 insertions(+) + +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index d3312a34d..c563317d1 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -2027,6 +2027,8 @@ struct wpa_driver_capa { + #define WPA_DRIVER_FLAGS2_OCV 0x0000000000000080ULL + /** Driver expects user space implementation of SME in AP mode */ + #define WPA_DRIVER_FLAGS2_AP_SME 0x0000000000000100ULL ++/** Driver supports SAE authentication offload */ ++#define WPA_DRIVER_FLAGS2_SAE_OFFLOAD 0x0000000000000200ULL + u64 flags2; + + #define FULL_AP_CLIENT_STATE_SUPP(drv_flags) \ +diff --git a/src/drivers/driver_nl80211_capa.c b/src/drivers/driver_nl80211_capa.c +index 83868b78e..a443b7c87 100644 +--- a/src/drivers/driver_nl80211_capa.c ++++ b/src/drivers/driver_nl80211_capa.c +@@ -594,6 +594,10 @@ static void wiphy_info_ext_feature_flags(struct wiphy_info_data *info, + NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X)) + capa->flags |= WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_8021X; + ++ if (ext_feature_isset(ext_features, len, ++ NL80211_EXT_FEATURE_SAE_OFFLOAD)) ++ capa->flags2 |= WPA_DRIVER_FLAGS2_SAE_OFFLOAD; ++ + if (ext_feature_isset(ext_features, len, + NL80211_EXT_FEATURE_MFP_OPTIONAL)) + capa->flags |= WPA_DRIVER_FLAGS_MFP_OPTIONAL; +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0007-SAE-Pass-SAE-password-on-connect-for-SAE-authenticat.murata.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0007-SAE-Pass-SAE-password-on-connect-for-SAE-authenticat.murata.patch new file mode 100644 index 000000000..16d2d8ced --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0007-SAE-Pass-SAE-password-on-connect-for-SAE-authenticat.murata.patch @@ -0,0 +1,88 @@ +From 417097c87d7027ad319d7e8c9931deb666779533 Mon Sep 17 00:00:00 2001 +From: Chung-Hsien Hsu +Date: Tue, 29 Oct 2019 17:22:18 +0800 +Subject: [PATCH 07/49] SAE: Pass SAE password on connect for SAE + authentication offload support + +Pass SAE password on connect if driver advertises SAE authentication +offload support. + +Signed-off-by: Chung-Hsien Hsu +--- + src/drivers/driver.h | 8 ++++++++ + src/drivers/driver_nl80211.c | 26 ++++++++++++++++++++++++-- + 2 files changed, 32 insertions(+), 2 deletions(-) + +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index c563317d1..7cfa92ed8 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -1014,6 +1014,14 @@ struct wpa_driver_associate_params { + */ + const u8 *psk; + ++ /** ++ * sae_password - Password for SAE authentication ++ * ++ * This value is made available only for WPA3-Personal (SAE) and only ++ * for drivers that set WPA_DRIVER_FLAGS2_SAE_OFFLOAD. ++ */ ++ const char *sae_password; ++ + /** + * drop_unencrypted - Enable/disable unencrypted frame filtering + * +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index aec179ac3..91e8d44d8 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -6173,8 +6173,12 @@ static int nl80211_connect_common(struct wpa_driver_nl80211_data *drv, + + if (params->wpa_proto & WPA_PROTO_WPA) + ver |= NL80211_WPA_VERSION_1; +- if (params->wpa_proto & WPA_PROTO_RSN) +- ver |= NL80211_WPA_VERSION_2; ++ if (params->wpa_proto & WPA_PROTO_RSN) { ++ if (params->key_mgmt_suite == WPA_KEY_MGMT_SAE) ++ ver |= NL80211_WPA_VERSION_3; ++ else ++ ver |= NL80211_WPA_VERSION_2; ++ } + + wpa_printf(MSG_DEBUG, " * WPA Versions 0x%x", ver); + if (nla_put_u32(msg, NL80211_ATTR_WPA_VERSIONS, ver)) +@@ -6304,6 +6308,22 @@ static int nl80211_connect_common(struct wpa_driver_nl80211_data *drv, + return -1; + } + ++ /* add SAE password in case of SAE authentication offload */ ++ if ((params->sae_password || params->passphrase) && ++ (drv->capa.flags2 & WPA_DRIVER_FLAGS2_SAE_OFFLOAD)) { ++ const char *password; ++ size_t pwd_len; ++ ++ password = params->sae_password; ++ if (!password) ++ password = params->passphrase; ++ pwd_len = os_strlen(password); ++ wpa_hexdump_ascii_key(MSG_DEBUG, " * SAE password", ++ (u8 *) password, pwd_len); ++ if (nla_put(msg, NL80211_ATTR_SAE_PASSWORD, pwd_len, password)) ++ return -1; ++ } ++ + if (nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT)) + return -1; + +@@ -6419,6 +6439,8 @@ static int wpa_driver_nl80211_try_connect( + algs++; + if (params->auth_alg & WPA_AUTH_ALG_FT) + algs++; ++ if (params->auth_alg & WPA_AUTH_ALG_SAE) ++ algs++; + if (algs > 1) { + wpa_printf(MSG_DEBUG, " * Leave out Auth Type for automatic " + "selection"); +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0008-nl80211-Support-4-way-handshake-offload-for-WPA-WPA2.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0008-nl80211-Support-4-way-handshake-offload-for-WPA-WPA2.patch new file mode 100644 index 000000000..43b4e31f3 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0008-nl80211-Support-4-way-handshake-offload-for-WPA-WPA2.patch @@ -0,0 +1,116 @@ +From 0bdd3f507d5dc92e42c72df7f4b79ffdab514fe1 Mon Sep 17 00:00:00 2001 +From: Chung-Hsien Hsu +Date: Tue, 10 Dec 2019 14:02:39 -0600 +Subject: [PATCH 08/49] nl80211: Support 4-way handshake offload for + WPA/WPA2-PSK in AP mode + +If driver advertises support for WPA/WPA2-PSK 4-way handshake offload in +AP mode, set WPA_DRIVER_FLAGS2_4WAY_HANDSHAKE_AP_PSK flag and pass PSK +in NL80211_CMD_NEW_BEACON command. + +Signed-off-by: Chung-Hsien Hsu +--- + src/drivers/driver.h | 30 +++++++++++++++++++++++++++--- + src/drivers/driver_nl80211.c | 8 ++++++++ + src/drivers/driver_nl80211_capa.c | 4 ++++ + 3 files changed, 39 insertions(+), 3 deletions(-) + +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index 7cfa92ed8..a42ec5e1f 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -1590,6 +1590,27 @@ struct wpa_driver_ap_params { + * Unsolicited broadcast Probe Response template length + */ + size_t unsol_bcast_probe_resp_tmpl_len; ++ ++ /** ++ * passphrase - RSN passphrase for PSK ++ * ++ * This value is made available only for WPA/WPA2-Personal (PSK) and ++ * only for drivers that set WPA_DRIVER_FLAGS2_4WAY_HANDSHAKE_AP_PSK. ++ * This is the 8..63 character ASCII passphrase, if available. Please ++ * note that this can be %NULL if passphrase was not used to generate ++ * the PSK. In that case, the psk field must be used to fetch the PSK. ++ */ ++ const char *passphrase; ++ ++ /** ++ * psk - RSN PSK (alternative for passphrase for PSK) ++ * ++ * This value is made available only for WPA/WPA2-Personal (PSK) and ++ * only for drivers that set WPA_DRIVER_FLAGS2_4WAY_HANDSHAKE_AP_PSK. ++ * This is the 32-octet (256-bit) PSK, if available. The driver wrapper ++ * should be prepared to handle %NULL value as an error. ++ */ ++ const u8 *psk; + }; + + struct wpa_driver_mesh_bss_params { +@@ -1872,8 +1893,9 @@ struct wpa_driver_capa { + #define WPA_DRIVER_FLAGS_SET_KEYS_AFTER_ASSOC 0x00000002 + /** Driver takes care of all DFS operations */ + #define WPA_DRIVER_FLAGS_DFS_OFFLOAD 0x00000004 +-/** Driver takes care of RSN 4-way handshake internally; PMK is configured with +- * struct wpa_driver_ops::set_key using key_flag = KEY_FLAG_PMK */ ++/** Driver takes care of RSN 4-way handshake internally in station mode; PMK is ++ * configured with struct wpa_driver_ops::set_key using key_flag = KEY_FLAG_PMK ++ */ + #define WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_8021X 0x00000008 + /** Driver is for a wired Ethernet interface */ + #define WPA_DRIVER_FLAGS_WIRED 0x00000010 +@@ -1998,7 +2020,7 @@ struct wpa_driver_capa { + #define WPA_DRIVER_FLAGS_SELF_MANAGED_REGULATORY 0x0080000000000000ULL + /** Driver supports FTM responder functionality */ + #define WPA_DRIVER_FLAGS_FTM_RESPONDER 0x0100000000000000ULL +-/** Driver support 4-way handshake offload for WPA-Personal */ ++/** Driver supports 4-way handshake offload for WPA-Personal in station mode */ + #define WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_PSK 0x0200000000000000ULL + /** Driver supports a separate control port TX for EAPOL frames */ + #define WPA_DRIVER_FLAGS_CONTROL_PORT 0x0400000000000000ULL +@@ -2037,6 +2059,8 @@ struct wpa_driver_capa { + #define WPA_DRIVER_FLAGS2_AP_SME 0x0000000000000100ULL + /** Driver supports SAE authentication offload */ + #define WPA_DRIVER_FLAGS2_SAE_OFFLOAD 0x0000000000000200ULL ++/** Driver supports 4-way handshake offload for WPA-Personal in AP mode */ ++#define WPA_DRIVER_FLAGS2_4WAY_HANDSHAKE_AP_PSK 0x0000000000000400ULL + u64 flags2; + + #define FULL_AP_CLIENT_STATE_SUPP(drv_flags) \ +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index 91e8d44d8..f228a0715 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -4677,6 +4677,14 @@ static int wpa_driver_nl80211_set_ap(void *priv, + nla_put_u32(msg, NL80211_ATTR_CIPHER_SUITE_GROUP, suite)) + goto fail; + ++ /* Add PSK in case of 4-way handshake offload */ ++ if (params->psk && ++ (drv->capa.flags2 & WPA_DRIVER_FLAGS2_4WAY_HANDSHAKE_AP_PSK)) { ++ wpa_hexdump_key(MSG_DEBUG, "nl80211: PSK", params->psk, 32); ++ if (nla_put(msg, NL80211_ATTR_PMK, 32, params->psk)) ++ goto fail; ++ } ++ + if (params->beacon_ies) { + wpa_hexdump_buf(MSG_DEBUG, "nl80211: beacon_ies", + params->beacon_ies); +diff --git a/src/drivers/driver_nl80211_capa.c b/src/drivers/driver_nl80211_capa.c +index a443b7c87..dc4988c7c 100644 +--- a/src/drivers/driver_nl80211_capa.c ++++ b/src/drivers/driver_nl80211_capa.c +@@ -594,6 +594,10 @@ static void wiphy_info_ext_feature_flags(struct wiphy_info_data *info, + NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X)) + capa->flags |= WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_8021X; + ++ if (ext_feature_isset(ext_features, len, ++ NL80211_EXT_FEATURE_4WAY_HANDSHAKE_AP_PSK)) ++ capa->flags2 |= WPA_DRIVER_FLAGS2_4WAY_HANDSHAKE_AP_PSK; ++ + if (ext_feature_isset(ext_features, len, + NL80211_EXT_FEATURE_SAE_OFFLOAD)) + capa->flags2 |= WPA_DRIVER_FLAGS2_SAE_OFFLOAD; +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0009-AP-Support-4-way-handshake-offload-for-WPA-WPA2-PSK.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0009-AP-Support-4-way-handshake-offload-for-WPA-WPA2-PSK.patch new file mode 100644 index 000000000..654fad8e6 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0009-AP-Support-4-way-handshake-offload-for-WPA-WPA2-PSK.patch @@ -0,0 +1,122 @@ +From 2f8529ec491389bdb41911edcf084bc643d7c9ee Mon Sep 17 00:00:00 2001 +From: Chung-Hsien Hsu +Date: Tue, 10 Dec 2019 14:03:57 -0600 +Subject: [PATCH 09/49] AP: Support 4-way handshake offload for WPA/WPA2-PSK + +Add support for WPA/WPA2-PSK 4-way handshake offload in AP mode. In this +case, the 4-way handshake is handled by driver instead of user space. + +Signed-off-by: Chung-Hsien Hsu +--- + src/ap/beacon.c | 10 ++++++++++ + src/ap/hostapd.c | 8 +++++++- + src/ap/wpa_auth.c | 16 ++++++++++++++++ + src/ap/wpa_auth.h | 2 ++ + src/ap/wpa_auth_glue.c | 4 ++++ + 5 files changed, 39 insertions(+), 1 deletion(-) + +diff --git a/src/ap/beacon.c b/src/ap/beacon.c +index 8cd1c4170..583b6836e 100644 +--- a/src/ap/beacon.c ++++ b/src/ap/beacon.c +@@ -1753,6 +1753,16 @@ int ieee802_11_build_ap_params(struct hostapd_data *hapd, + } + } + ++ if ((hapd->iface->drv_flags2 & ++ WPA_DRIVER_FLAGS2_4WAY_HANDSHAKE_AP_PSK) && ++ (params->key_mgmt_suites & ++ (WPA_KEY_MGMT_PSK | WPA_KEY_MGMT_PSK_SHA256))) { ++ if (hapd->conf->ssid.wpa_passphrase) ++ params->passphrase = hapd->conf->ssid.wpa_passphrase; ++ if (hapd->conf->ssid.wpa_psk->psk) ++ params->psk = hapd->conf->ssid.wpa_psk->psk; ++ } ++ + return 0; + } + +diff --git a/src/ap/hostapd.c b/src/ap/hostapd.c +index 4b88641a2..464d8fa95 100644 +--- a/src/ap/hostapd.c ++++ b/src/ap/hostapd.c +@@ -3203,6 +3203,8 @@ int hostapd_remove_iface(struct hapd_interfaces *interfaces, char *buf) + void hostapd_new_assoc_sta(struct hostapd_data *hapd, struct sta_info *sta, + int reassoc) + { ++ int key_mgmt = wpa_auth_sta_key_mgmt(sta->wpa_sm); ++ + if (hapd->tkip_countermeasures) { + hostapd_drv_sta_deauth(hapd, sta->addr, + WLAN_REASON_MICHAEL_MIC_FAILURE); +@@ -3236,7 +3238,11 @@ void hostapd_new_assoc_sta(struct hostapd_data *hapd, struct sta_info *sta, + /* Start IEEE 802.1X authentication process for new stations */ + ieee802_1x_new_station(hapd, sta); + if (reassoc) { +- if (sta->auth_alg != WLAN_AUTH_FT && ++ if ((hapd->iface->drv_flags2 & ++ WPA_DRIVER_FLAGS2_4WAY_HANDSHAKE_AP_PSK) && ++ wpa_key_mgmt_wpa_psk(key_mgmt)) ++ wpa_auth_sta_associated(hapd->wpa_auth, sta->wpa_sm); ++ else if (sta->auth_alg != WLAN_AUTH_FT && + sta->auth_alg != WLAN_AUTH_FILS_SK && + sta->auth_alg != WLAN_AUTH_FILS_SK_PFS && + sta->auth_alg != WLAN_AUTH_FILS_PK && +diff --git a/src/ap/wpa_auth.c b/src/ap/wpa_auth.c +index 6d60f2629..4b506c1db 100644 +--- a/src/ap/wpa_auth.c ++++ b/src/ap/wpa_auth.c +@@ -696,6 +696,22 @@ int wpa_auth_sta_associated(struct wpa_authenticator *wpa_auth, + } + #endif /* CONFIG_FILS */ + ++ if (wpa_auth->conf.psk_4way_hs_offload) { ++ wpa_auth_logger(wpa_auth, sm->addr, LOGGER_DEBUG, ++ "4-way handshake offloading for WPA/WPA2-PSK"); ++ sm->wpa_ptk_state = WPA_PTK_PTKINITDONE; ++ sm->Pair = true; ++ wpa_auth_set_eapol(sm->wpa_auth, sm->addr, ++ WPA_EAPOL_authorized, 1); ++ wpa_auth_set_eapol(sm->wpa_auth, sm->addr, ++ WPA_EAPOL_portValid, 1); ++ wpa_auth_set_eapol(sm->wpa_auth, sm->addr, ++ WPA_EAPOL_keyAvailable, 0); ++ wpa_auth_set_eapol(sm->wpa_auth, sm->addr, ++ WPA_EAPOL_keyDone, 1); ++ return 0; ++ } ++ + if (sm->started) { + os_memset(&sm->key_replay, 0, sizeof(sm->key_replay)); + sm->ReAuthenticationRequest = true; +diff --git a/src/ap/wpa_auth.h b/src/ap/wpa_auth.h +index fe47723b9..2f807893f 100644 +--- a/src/ap/wpa_auth.h ++++ b/src/ap/wpa_auth.h +@@ -273,6 +273,8 @@ struct wpa_auth_config { + * PTK derivation regardless of advertised capabilities. + */ + bool force_kdk_derivation; ++ ++ int psk_4way_hs_offload; + }; + + typedef enum { +diff --git a/src/ap/wpa_auth_glue.c b/src/ap/wpa_auth_glue.c +index 3e9921553..26de12b5b 100644 +--- a/src/ap/wpa_auth_glue.c ++++ b/src/ap/wpa_auth_glue.c +@@ -1528,6 +1528,10 @@ int hostapd_setup_wpa(struct hostapd_data *hapd) + _conf.prot_range_neg = + !!(hapd->iface->drv_flags2 & WPA_DRIVER_FLAGS2_PROT_RANGE_NEG); + ++ if (!hapd->conf->p2p && ++ (hapd->iface->drv_flags2 & WPA_DRIVER_FLAGS2_4WAY_HANDSHAKE_AP_PSK)) ++ _conf.psk_4way_hs_offload = 1; ++ + hapd->wpa_auth = wpa_init(hapd->own_addr, &_conf, &cb, hapd); + if (hapd->wpa_auth == NULL) { + wpa_printf(MSG_ERROR, "WPA initialization failed."); +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0010-nl80211-Support-SAE-authentication-offload-in-AP-mod.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0010-nl80211-Support-SAE-authentication-offload-in-AP-mod.patch new file mode 100644 index 000000000..1a3eef521 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0010-nl80211-Support-SAE-authentication-offload-in-AP-mod.patch @@ -0,0 +1,113 @@ +From 89d2f8b07c948cc5fbe8767948128f487eae2ed5 Mon Sep 17 00:00:00 2001 +From: Chung-Hsien Hsu +Date: Tue, 10 Dec 2019 14:05:16 -0600 +Subject: [PATCH 10/49] nl80211: Support SAE authentication offload in AP mode + +If driver advertises support for SAE authentication offload, pass SAE +password in NL80211_CMD_NEW_BEACON command for AP mode. + +Signed-off-by: Chung-Hsien Hsu +--- + src/drivers/driver.h | 12 +++++++++++- + src/drivers/driver_nl80211.c | 28 +++++++++++++++++++++++++++- + src/drivers/driver_nl80211_capa.c | 4 ++++ + 3 files changed, 42 insertions(+), 2 deletions(-) + +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index a42ec5e1f..45260e8c5 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -1611,6 +1611,14 @@ struct wpa_driver_ap_params { + * should be prepared to handle %NULL value as an error. + */ + const u8 *psk; ++ ++ /** ++ * sae_password - Password for SAE authentication ++ * ++ * This value is made available only for WPA3-Personal (SAE) and only ++ * for drivers that set WPA_DRIVER_FLAGS2_SAE_OFFLOAD_AP. ++ */ ++ const char *sae_password; + }; + + struct wpa_driver_mesh_bss_params { +@@ -2057,10 +2065,12 @@ struct wpa_driver_capa { + #define WPA_DRIVER_FLAGS2_OCV 0x0000000000000080ULL + /** Driver expects user space implementation of SME in AP mode */ + #define WPA_DRIVER_FLAGS2_AP_SME 0x0000000000000100ULL +-/** Driver supports SAE authentication offload */ ++/** Driver supports SAE authentication offload in station mode */ + #define WPA_DRIVER_FLAGS2_SAE_OFFLOAD 0x0000000000000200ULL + /** Driver supports 4-way handshake offload for WPA-Personal in AP mode */ + #define WPA_DRIVER_FLAGS2_4WAY_HANDSHAKE_AP_PSK 0x0000000000000400ULL ++/** Driver supports SAE authentication offload in AP mode */ ++#define WPA_DRIVER_FLAGS2_SAE_OFFLOAD_AP 0x0000000000000800ULL + u64 flags2; + + #define FULL_AP_CLIENT_STATE_SUPP(drv_flags) \ +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index f228a0715..b6afc6e7a 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -4630,8 +4630,13 @@ static int wpa_driver_nl80211_set_ap(void *priv, + ver = 0; + if (params->wpa_version & WPA_PROTO_WPA) + ver |= NL80211_WPA_VERSION_1; +- if (params->wpa_version & WPA_PROTO_RSN) ++ if (params->wpa_version & WPA_PROTO_RSN) { + ver |= NL80211_WPA_VERSION_2; ++#ifdef CONFIG_SAE ++ if (params->key_mgmt_suites & WPA_KEY_MGMT_SAE) ++ ver |= NL80211_WPA_VERSION_3; ++#endif /* CONFIG_SAE */ ++ } + if (ver && + nla_put_u32(msg, NL80211_ATTR_WPA_VERSIONS, ver)) + goto fail; +@@ -4685,6 +4690,27 @@ static int wpa_driver_nl80211_set_ap(void *priv, + goto fail; + } + ++#ifdef CONFIG_SAE ++ /* Add SAE password in case of SAE authentication offload */ ++ if ((params->sae_password || params->passphrase) && ++ (params->key_mgmt_suites & WPA_KEY_MGMT_SAE) && ++ (drv->capa.flags2 & WPA_DRIVER_FLAGS2_SAE_OFFLOAD_AP)) { ++ const char *password; ++ size_t pwd_len; ++ ++ if (params->sae_password) ++ password = params->sae_password; ++ else ++ password = params->passphrase; ++ ++ pwd_len = os_strlen(password); ++ wpa_hexdump_ascii_key(MSG_DEBUG, "nl80211: SAE password", ++ (u8 *) password, pwd_len); ++ if (nla_put(msg, NL80211_ATTR_SAE_PASSWORD, pwd_len, password)) ++ goto fail; ++ } ++#endif /* CONFIG_SAE */ ++ + if (params->beacon_ies) { + wpa_hexdump_buf(MSG_DEBUG, "nl80211: beacon_ies", + params->beacon_ies); +diff --git a/src/drivers/driver_nl80211_capa.c b/src/drivers/driver_nl80211_capa.c +index dc4988c7c..ae6029a92 100644 +--- a/src/drivers/driver_nl80211_capa.c ++++ b/src/drivers/driver_nl80211_capa.c +@@ -602,6 +602,10 @@ static void wiphy_info_ext_feature_flags(struct wiphy_info_data *info, + NL80211_EXT_FEATURE_SAE_OFFLOAD)) + capa->flags2 |= WPA_DRIVER_FLAGS2_SAE_OFFLOAD; + ++ if (ext_feature_isset(ext_features, len, ++ NL80211_EXT_FEATURE_SAE_OFFLOAD_AP)) ++ capa->flags2 |= WPA_DRIVER_FLAGS2_SAE_OFFLOAD_AP; ++ + if (ext_feature_isset(ext_features, len, + NL80211_EXT_FEATURE_MFP_OPTIONAL)) + capa->flags |= WPA_DRIVER_FLAGS_MFP_OPTIONAL; +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0011-SAE-Support-SAE-authentication-offload-in-AP-mode.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0011-SAE-Support-SAE-authentication-offload-in-AP-mode.patch new file mode 100644 index 000000000..6667844f7 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0011-SAE-Support-SAE-authentication-offload-in-AP-mode.patch @@ -0,0 +1,86 @@ +From dfa364f9970f1d88782cc9a9b7292afadbf2358b Mon Sep 17 00:00:00 2001 +From: Chung-Hsien Hsu +Date: Tue, 10 Dec 2019 14:06:20 -0600 +Subject: [PATCH 11/49] SAE: Support SAE authentication offload in AP mode + +Add support for SAE authentication offload in AP mode. In this case, the +SAE authentication process is handled by driver instead of user space. + +Signed-off-by: Chung-Hsien Hsu +--- + src/ap/beacon.c | 11 +++++++++++ + src/ap/wpa_auth.h | 3 +++ + src/ap/wpa_auth_glue.c | 5 +++++ + src/ap/wpa_auth_ie.c | 4 +++- + 4 files changed, 22 insertions(+), 1 deletion(-) + +diff --git a/src/ap/beacon.c b/src/ap/beacon.c +index 583b6836e..e2d7c6970 100644 +--- a/src/ap/beacon.c ++++ b/src/ap/beacon.c +@@ -1763,6 +1763,17 @@ int ieee802_11_build_ap_params(struct hostapd_data *hapd, + params->psk = hapd->conf->ssid.wpa_psk->psk; + } + ++#ifdef CONFIG_SAE ++ if ((hapd->iface->drv_flags2 & WPA_DRIVER_FLAGS2_SAE_OFFLOAD_AP) && ++ (params->key_mgmt_suites & WPA_KEY_MGMT_SAE)) { ++ params->auth_algs |= WPA_AUTH_ALG_SAE; ++ if (hapd->conf->sae_passwords) ++ params->sae_password = hapd->conf->sae_passwords->password; ++ else if (hapd->conf->ssid.wpa_passphrase) ++ params->passphrase = hapd->conf->ssid.wpa_passphrase; ++ } ++#endif /* CONFIG_SAE */ ++ + return 0; + } + +diff --git a/src/ap/wpa_auth.h b/src/ap/wpa_auth.h +index 2f807893f..ff36cfe95 100644 +--- a/src/ap/wpa_auth.h ++++ b/src/ap/wpa_auth.h +@@ -275,6 +275,9 @@ struct wpa_auth_config { + bool force_kdk_derivation; + + int psk_4way_hs_offload; ++#ifdef CONFIG_SAE ++ int sae_offload; ++#endif /* CONFIG_SAE */ + }; + + typedef enum { +diff --git a/src/ap/wpa_auth_glue.c b/src/ap/wpa_auth_glue.c +index 26de12b5b..c8dee2aef 100644 +--- a/src/ap/wpa_auth_glue.c ++++ b/src/ap/wpa_auth_glue.c +@@ -1532,6 +1532,11 @@ int hostapd_setup_wpa(struct hostapd_data *hapd) + (hapd->iface->drv_flags2 & WPA_DRIVER_FLAGS2_4WAY_HANDSHAKE_AP_PSK)) + _conf.psk_4way_hs_offload = 1; + ++#ifdef CONFIG_SAE ++ if (hapd->iface->drv_flags2 & WPA_DRIVER_FLAGS2_SAE_OFFLOAD_AP) ++ _conf.sae_offload = 1; ++#endif /* CONFIG_SAE */ ++ + hapd->wpa_auth = wpa_init(hapd->own_addr, &_conf, &cb, hapd); + if (hapd->wpa_auth == NULL) { + wpa_printf(MSG_ERROR, "WPA initialization failed."); +diff --git a/src/ap/wpa_auth_ie.c b/src/ap/wpa_auth_ie.c +index 524922e4e..30de0c19c 100644 +--- a/src/ap/wpa_auth_ie.c ++++ b/src/ap/wpa_auth_ie.c +@@ -977,7 +977,9 @@ wpa_validate_wpa_ie(struct wpa_authenticator *wpa_auth, + } + + #ifdef CONFIG_SAE +- if (sm->wpa_key_mgmt == WPA_KEY_MGMT_SAE && data.num_pmkid && ++ if (!wpa_auth->conf.psk_4way_hs_offload && ++ !wpa_auth->conf.sae_offload && ++ sm->wpa_key_mgmt == WPA_KEY_MGMT_SAE && data.num_pmkid && + !sm->pmksa) { + wpa_auth_vlogger(wpa_auth, sm->addr, LOGGER_DEBUG, + "No PMKSA cache entry found for SAE"); +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0013-non-upstream-defconfig_base-Add-Infineon-default-con.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0013-non-upstream-defconfig_base-Add-Infineon-default-con.patch new file mode 100644 index 000000000..dff70c0d3 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0013-non-upstream-defconfig_base-Add-Infineon-default-con.patch @@ -0,0 +1,1070 @@ +From 69d18183a1df9e72371e33937c91af5b5b79a110 Mon Sep 17 00:00:00 2001 +From: Chung-Hsien Hsu +Date: Mon, 2 Aug 2021 14:15:06 -0500 +Subject: [PATCH 13/49] non-upstream: defconfig_base: Add Infineon default + configuration + +Add Infineon default configuration files (defconfig_base). + +Signed-off-by: Kurt Lee +Signed-off-by: Chung-Hsien Hsu +--- + hostapd/defconfig_base | 403 +++++++++++++++++++++ + wpa_supplicant/defconfig_base | 635 ++++++++++++++++++++++++++++++++++ + 2 files changed, 1038 insertions(+) + create mode 100644 hostapd/defconfig_base + create mode 100644 wpa_supplicant/defconfig_base + +diff --git a/hostapd/defconfig_base b/hostapd/defconfig_base +new file mode 100644 +index 000000000..9dcf7848d +--- /dev/null ++++ b/hostapd/defconfig_base +@@ -0,0 +1,403 @@ ++# Example hostapd build time configuration ++# ++# This file lists the configuration options that are used when building the ++# hostapd binary. All lines starting with # are ignored. Configuration option ++# lines must be commented out complete, if they are not to be included, i.e., ++# just setting VARIABLE=n is not disabling that variable. ++# ++# This file is included in Makefile, so variables like CFLAGS and LIBS can also ++# be modified from here. In most cass, these lines should use += in order not ++# to override previous values of the variables. ++ ++# Driver interface for Host AP driver ++CONFIG_DRIVER_HOSTAP=y ++ ++# Driver interface for wired authenticator ++#CONFIG_DRIVER_WIRED=y ++ ++# Driver interface for drivers using the nl80211 kernel interface ++CONFIG_DRIVER_NL80211=y ++ ++# QCA vendor extensions to nl80211 ++#CONFIG_DRIVER_NL80211_QCA=y ++ ++# driver_nl80211.c requires libnl. If you are compiling it yourself ++# you may need to point hostapd to your version of libnl. ++# ++#CFLAGS += -I$ ++#LIBS += -L$ ++ ++# Use libnl v2.0 (or 3.0) libraries. ++#CONFIG_LIBNL20=y ++ ++# Use libnl 3.2 libraries (if this is selected, CONFIG_LIBNL20 is ignored) ++CONFIG_LIBNL32=y ++ ++ ++# Driver interface for FreeBSD net80211 layer (e.g., Atheros driver) ++#CONFIG_DRIVER_BSD=y ++#CFLAGS += -I/usr/local/include ++#LIBS += -L/usr/local/lib ++#LIBS_p += -L/usr/local/lib ++#LIBS_c += -L/usr/local/lib ++ ++# Driver interface for no driver (e.g., RADIUS server only) ++#CONFIG_DRIVER_NONE=y ++ ++# WPA2/IEEE 802.11i RSN pre-authentication ++CONFIG_RSN_PREAUTH=y ++ ++# Support Operating Channel Validation ++#CONFIG_OCV=y ++ ++# Integrated EAP server ++CONFIG_EAP=y ++ ++# EAP Re-authentication Protocol (ERP) in integrated EAP server ++CONFIG_ERP=y ++ ++# EAP-MD5 for the integrated EAP server ++CONFIG_EAP_MD5=y ++ ++# EAP-TLS for the integrated EAP server ++CONFIG_EAP_TLS=y ++ ++# EAP-MSCHAPv2 for the integrated EAP server ++CONFIG_EAP_MSCHAPV2=y ++ ++# EAP-PEAP for the integrated EAP server ++CONFIG_EAP_PEAP=y ++ ++# EAP-GTC for the integrated EAP server ++CONFIG_EAP_GTC=y ++ ++# EAP-TTLS for the integrated EAP server ++CONFIG_EAP_TTLS=y ++ ++# EAP-SIM for the integrated EAP server ++#CONFIG_EAP_SIM=y ++ ++# EAP-AKA for the integrated EAP server ++#CONFIG_EAP_AKA=y ++ ++# EAP-AKA' for the integrated EAP server ++# This requires CONFIG_EAP_AKA to be enabled, too. ++#CONFIG_EAP_AKA_PRIME=y ++ ++# EAP-PAX for the integrated EAP server ++#CONFIG_EAP_PAX=y ++ ++# EAP-PSK for the integrated EAP server (this is _not_ needed for WPA-PSK) ++#CONFIG_EAP_PSK=y ++ ++# EAP-pwd for the integrated EAP server (secure authentication with a password) ++#CONFIG_EAP_PWD=y ++ ++# EAP-SAKE for the integrated EAP server ++#CONFIG_EAP_SAKE=y ++ ++# EAP-GPSK for the integrated EAP server ++#CONFIG_EAP_GPSK=y ++# Include support for optional SHA256 cipher suite in EAP-GPSK ++#CONFIG_EAP_GPSK_SHA256=y ++ ++# EAP-FAST for the integrated EAP server ++#CONFIG_EAP_FAST=y ++ ++# EAP-TEAP for the integrated EAP server ++# Note: The current EAP-TEAP implementation is experimental and should not be ++# enabled for production use. The IETF RFC 7170 that defines EAP-TEAP has number ++# of conflicting statements and missing details and the implementation has ++# vendor specific workarounds for those and as such, may not interoperate with ++# any other implementation. This should not be used for anything else than ++# experimentation and interoperability testing until those issues has been ++# resolved. ++#CONFIG_EAP_TEAP=y ++ ++# Wi-Fi Protected Setup (WPS) ++CONFIG_WPS=y ++# Enable UPnP support for external WPS Registrars ++#CONFIG_WPS_UPNP=y ++# Enable WPS support with NFC config method ++#CONFIG_WPS_NFC=y ++ ++# EAP-IKEv2 ++#CONFIG_EAP_IKEV2=y ++ ++# Trusted Network Connect (EAP-TNC) ++#CONFIG_EAP_TNC=y ++ ++# EAP-EKE for the integrated EAP server ++#CONFIG_EAP_EKE=y ++ ++# PKCS#12 (PFX) support (used to read private key and certificate file from ++# a file that usually has extension .p12 or .pfx) ++CONFIG_PKCS12=y ++ ++# RADIUS authentication server. This provides access to the integrated EAP ++# server from external hosts using RADIUS. ++#CONFIG_RADIUS_SERVER=y ++ ++# Build IPv6 support for RADIUS operations ++CONFIG_IPV6=y ++ ++# IEEE Std 802.11r-2008 (Fast BSS Transition) ++CONFIG_IEEE80211R=y ++ ++# Use the hostapd's IEEE 802.11 authentication (ACL), but without ++# the IEEE 802.11 Management capability (e.g., FreeBSD/net80211) ++#CONFIG_DRIVER_RADIUS_ACL=y ++ ++# Wireless Network Management (IEEE Std 802.11v-2011) ++# Note: This is experimental and not complete implementation. ++#CONFIG_WNM=y ++ ++# IEEE 802.11ac (Very High Throughput) support ++CONFIG_IEEE80211AC=y ++ ++# IEEE 802.11ax HE support ++# Note: This is experimental and work in progress. The definitions are still ++# subject to change and this should not be expected to interoperate with the ++# final IEEE 802.11ax version. ++CONFIG_IEEE80211AX=y ++ ++# Remove debugging code that is printing out debug messages to stdout. ++# This can be used to reduce the size of the hostapd considerably if debugging ++# code is not needed. ++#CONFIG_NO_STDOUT_DEBUG=y ++ ++# Add support for writing debug log to a file: -f /tmp/hostapd.log ++# Disabled by default. ++CONFIG_DEBUG_FILE=y ++ ++# Send debug messages to syslog instead of stdout ++#CONFIG_DEBUG_SYSLOG=y ++ ++# Add support for sending all debug messages (regardless of debug verbosity) ++# to the Linux kernel tracing facility. This helps debug the entire stack by ++# making it easy to record everything happening from the driver up into the ++# same file, e.g., using trace-cmd. ++#CONFIG_DEBUG_LINUX_TRACING=y ++ ++# Remove support for RADIUS accounting ++#CONFIG_NO_ACCOUNTING=y ++ ++# Remove support for RADIUS ++#CONFIG_NO_RADIUS=y ++ ++# Remove support for VLANs ++#CONFIG_NO_VLAN=y ++ ++# Enable support for fully dynamic VLANs. This enables hostapd to ++# automatically create bridge and VLAN interfaces if necessary. ++#CONFIG_FULL_DYNAMIC_VLAN=y ++ ++# Use netlink-based kernel API for VLAN operations instead of ioctl() ++# Note: This requires libnl 3.1 or newer. ++#CONFIG_VLAN_NETLINK=y ++ ++# Remove support for dumping internal state through control interface commands ++# This can be used to reduce binary size at the cost of disabling a debugging ++# option. ++#CONFIG_NO_DUMP_STATE=y ++ ++# Enable tracing code for developer debugging ++# This tracks use of memory allocations and other registrations and reports ++# incorrect use with a backtrace of call (or allocation) location. ++#CONFIG_WPA_TRACE=y ++# For BSD, comment out these. ++#LIBS += -lexecinfo ++#LIBS_p += -lexecinfo ++#LIBS_c += -lexecinfo ++ ++# Use libbfd to get more details for developer debugging ++# This enables use of libbfd to get more detailed symbols for the backtraces ++# generated by CONFIG_WPA_TRACE=y. ++#CONFIG_WPA_TRACE_BFD=y ++# For BSD, comment out these. ++#LIBS += -lbfd -liberty -lz ++#LIBS_p += -lbfd -liberty -lz ++#LIBS_c += -lbfd -liberty -lz ++ ++# hostapd depends on strong random number generation being available from the ++# operating system. os_get_random() function is used to fetch random data when ++# needed, e.g., for key generation. On Linux and BSD systems, this works by ++# reading /dev/urandom. It should be noted that the OS entropy pool needs to be ++# properly initialized before hostapd is started. This is important especially ++# on embedded devices that do not have a hardware random number generator and ++# may by default start up with minimal entropy available for random number ++# generation. ++# ++# As a safety net, hostapd is by default trying to internally collect ++# additional entropy for generating random data to mix in with the data ++# fetched from the OS. This by itself is not considered to be very strong, but ++# it may help in cases where the system pool is not initialized properly. ++# However, it is very strongly recommended that the system pool is initialized ++# with enough entropy either by using hardware assisted random number ++# generator or by storing state over device reboots. ++# ++# hostapd can be configured to maintain its own entropy store over restarts to ++# enhance random number generation. This is not perfect, but it is much more ++# secure than using the same sequence of random numbers after every reboot. ++# This can be enabled with -e command line option. The specified ++# file needs to be readable and writable by hostapd. ++# ++# If the os_get_random() is known to provide strong random data (e.g., on ++# Linux/BSD, the board in question is known to have reliable source of random ++# data from /dev/urandom), the internal hostapd random pool can be disabled. ++# This will save some in binary size and CPU use. However, this should only be ++# considered for builds that are known to be used on devices that meet the ++# requirements described above. ++#CONFIG_NO_RANDOM_POOL=y ++ ++# Should we attempt to use the getrandom(2) call that provides more reliable ++# yet secure randomness source than /dev/random on Linux 3.17 and newer. ++# Requires glibc 2.25 to build, falls back to /dev/random if unavailable. ++#CONFIG_GETRANDOM=y ++ ++# Should we use poll instead of select? Select is used by default. ++#CONFIG_ELOOP_POLL=y ++ ++# Should we use epoll instead of select? Select is used by default. ++#CONFIG_ELOOP_EPOLL=y ++ ++# Should we use kqueue instead of select? Select is used by default. ++#CONFIG_ELOOP_KQUEUE=y ++ ++# Select TLS implementation ++# openssl = OpenSSL (default) ++# gnutls = GnuTLS ++# internal = Internal TLSv1 implementation (experimental) ++# linux = Linux kernel AF_ALG and internal TLSv1 implementation (experimental) ++# none = Empty template ++CONFIG_TLS=openssl ++CONFIG_TLS_ADD_DL=y ++ ++# TLS-based EAP methods require at least TLS v1.0. Newer version of TLS (v1.1) ++# can be enabled to get a stronger construction of messages when block ciphers ++# are used. ++#CONFIG_TLSV11=y ++ ++# TLS-based EAP methods require at least TLS v1.0. Newer version of TLS (v1.2) ++# can be enabled to enable use of stronger crypto algorithms. ++#CONFIG_TLSV12=y ++ ++# Select which ciphers to use by default with OpenSSL if the user does not ++# specify them. ++#CONFIG_TLS_DEFAULT_CIPHERS="DEFAULT:!EXP:!LOW" ++ ++# If CONFIG_TLS=internal is used, additional library and include paths are ++# needed for LibTomMath. Alternatively, an integrated, minimal version of ++# LibTomMath can be used. See beginning of libtommath.c for details on benefits ++# and drawbacks of this option. ++#CONFIG_INTERNAL_LIBTOMMATH=y ++#ifndef CONFIG_INTERNAL_LIBTOMMATH ++#LTM_PATH=/usr/src/libtommath-0.39 ++#CFLAGS += -I$(LTM_PATH) ++#LIBS += -L$(LTM_PATH) ++#LIBS_p += -L$(LTM_PATH) ++#endif ++# At the cost of about 4 kB of additional binary size, the internal LibTomMath ++# can be configured to include faster routines for exptmod, sqr, and div to ++# speed up DH and RSA calculation considerably ++#CONFIG_INTERNAL_LIBTOMMATH_FAST=y ++ ++# Interworking (IEEE 802.11u) ++# This can be used to enable functionality to improve interworking with ++# external networks. ++#CONFIG_INTERWORKING=y ++ ++# Hotspot 2.0 ++#CONFIG_HS20=y ++ ++# Enable SQLite database support in hlr_auc_gw, EAP-SIM DB, and eap_user_file ++#CONFIG_SQLITE=y ++ ++# Enable Fast Session Transfer (FST) ++#CONFIG_FST=y ++ ++# Enable CLI commands for FST testing ++#CONFIG_FST_TEST=y ++ ++# Testing options ++# This can be used to enable some testing options (see also the example ++# configuration file) that are really useful only for testing clients that ++# connect to this hostapd. These options allow, for example, to drop a ++# certain percentage of probe requests or auth/(re)assoc frames. ++CONFIG_TESTING_OPTIONS=y ++ ++# Automatic Channel Selection ++# This will allow hostapd to pick the channel automatically when channel is set ++# to "acs_survey" or "0". Eventually, other ACS algorithms can be added in ++# similar way. ++# ++# Automatic selection is currently only done through initialization, later on ++# we hope to do background checks to keep us moving to more ideal channels as ++# time goes by. ACS is currently only supported through the nl80211 driver and ++# your driver must have survey dump capability that is filled by the driver ++# during scanning. ++# ++# You can customize the ACS survey algorithm with the hostapd.conf variable ++# acs_num_scans. ++# ++# Supported ACS drivers: ++# * ath9k ++# * ath5k ++# * ath10k ++# ++# For more details refer to: ++# http://wireless.kernel.org/en/users/Documentation/acs ++# ++#CONFIG_ACS=y ++ ++# Multiband Operation support ++# These extensions facilitate efficient use of multiple frequency bands ++# available to the AP and the devices that may associate with it. ++#CONFIG_MBO=y ++ ++# Client Taxonomy ++# Has the AP retain the Probe Request and (Re)Association Request frames from ++# a client, from which a signature can be produced which can identify the model ++# of client device like "Nexus 6P" or "iPhone 5s". ++#CONFIG_TAXONOMY=y ++ ++# Fast Initial Link Setup (FILS) (IEEE 802.11ai) ++#CONFIG_FILS=y ++# FILS shared key authentication with PFS ++#CONFIG_FILS_SK_PFS=y ++ ++# Include internal line edit mode in hostapd_cli. This can be used to provide ++# limited command line editing and history support. ++#CONFIG_WPA_CLI_EDIT=y ++ ++# Opportunistic Wireless Encryption (OWE) ++# Experimental implementation of draft-harkins-owe-07.txt ++#CONFIG_OWE=y ++ ++# Airtime policy support ++#CONFIG_AIRTIME_POLICY=y ++ ++# Override default value for the wpa_disable_eapol_key_retries configuration ++# parameter. See that parameter in hostapd.conf for more details. ++#CFLAGS += -DDEFAULT_WPA_DISABLE_EAPOL_KEY_RETRIES=1 ++ ++# Wired equivalent privacy (WEP) ++# WEP is an obsolete cryptographic data confidentiality algorithm that is not ++# considered secure. It should not be used for anything anymore. The ++# functionality needed to use WEP is available in the current hostapd ++# release under this optional build parameter. This functionality is subject to ++# be completely removed in a future release. ++#CONFIG_WEP=y ++ ++# Remove all TKIP functionality ++# TKIP is an old cryptographic data confidentiality algorithm that is not ++# considered secure. It should not be used anymore. For now, the default hostapd ++# build includes this to allow mixed mode WPA+WPA2 networks to be enabled, but ++# that functionality is subject to be removed in the future. ++#CONFIG_NO_TKIP=y ++ ++# Simultaneous Authentication of Equals (SAE), WPA3-Personal ++CONFIG_SAE=y ++ ++# Device Provisioning Protocol (DPP) ++CONFIG_DPP=y +diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base +new file mode 100644 +index 000000000..15daf0ad2 +--- /dev/null ++++ b/wpa_supplicant/defconfig_base +@@ -0,0 +1,635 @@ ++# Example wpa_supplicant build time configuration ++# ++# This file lists the configuration options that are used when building the ++# wpa_supplicant binary. All lines starting with # are ignored. Configuration ++# option lines must be commented out complete, if they are not to be included, ++# i.e., just setting VARIABLE=n is not disabling that variable. ++# ++# This file is included in Makefile, so variables like CFLAGS and LIBS can also ++# be modified from here. In most cases, these lines should use += in order not ++# to override previous values of the variables. ++ ++ ++# Uncomment following two lines and fix the paths if you have installed OpenSSL ++# or GnuTLS in non-default location ++#CFLAGS += -I/usr/local/openssl/include ++#LIBS += -L/usr/local/openssl/lib ++ ++# Some Red Hat versions seem to include kerberos header files from OpenSSL, but ++# the kerberos files are not in the default include path. Following line can be ++# used to fix build issues on such systems (krb5.h not found). ++#CFLAGS += -I/usr/include/kerberos ++ ++# Driver interface for generic Linux wireless extensions ++# Note: WEXT is deprecated in the current Linux kernel version and no new ++# functionality is added to it. nl80211-based interface is the new ++# replacement for WEXT and its use allows wpa_supplicant to properly control ++# the driver to improve existing functionality like roaming and to support new ++# functionality. ++CONFIG_DRIVER_WEXT=y ++ ++# Driver interface for Linux drivers using the nl80211 kernel interface ++CONFIG_DRIVER_NL80211=y ++ ++# QCA vendor extensions to nl80211 ++#CONFIG_DRIVER_NL80211_QCA=y ++ ++# driver_nl80211.c requires libnl. If you are compiling it yourself ++# you may need to point hostapd to your version of libnl. ++# ++#CFLAGS += -I$ ++#LIBS += -L$ ++ ++# Use libnl v2.0 (or 3.0) libraries. ++#CONFIG_LIBNL20=y ++ ++# Use libnl 3.2 libraries (if this is selected, CONFIG_LIBNL20 is ignored) ++CONFIG_LIBNL32=y ++ ++ ++# Driver interface for FreeBSD net80211 layer (e.g., Atheros driver) ++#CONFIG_DRIVER_BSD=y ++#CFLAGS += -I/usr/local/include ++#LIBS += -L/usr/local/lib ++#LIBS_p += -L/usr/local/lib ++#LIBS_c += -L/usr/local/lib ++ ++# Driver interface for Windows NDIS ++#CONFIG_DRIVER_NDIS=y ++#CFLAGS += -I/usr/include/w32api/ddk ++#LIBS += -L/usr/local/lib ++# For native build using mingw ++#CONFIG_NATIVE_WINDOWS=y ++# Additional directories for cross-compilation on Linux host for mingw target ++#CFLAGS += -I/opt/mingw/mingw32/include/ddk ++#LIBS += -L/opt/mingw/mingw32/lib ++#CC=mingw32-gcc ++# By default, driver_ndis uses WinPcap for low-level operations. This can be ++# replaced with the following option which replaces WinPcap calls with NDISUIO. ++# However, this requires that WZC is disabled (net stop wzcsvc) before starting ++# wpa_supplicant. ++# CONFIG_USE_NDISUIO=y ++ ++# Driver interface for wired Ethernet drivers ++CONFIG_DRIVER_WIRED=y ++ ++# Driver interface for MACsec capable Qualcomm Atheros drivers ++#CONFIG_DRIVER_MACSEC_QCA=y ++ ++# Driver interface for Linux MACsec drivers ++#CONFIG_DRIVER_MACSEC_LINUX=y ++ ++# Driver interface for the Broadcom RoboSwitch family ++#CONFIG_DRIVER_ROBOSWITCH=y ++ ++# Driver interface for no driver (e.g., WPS ER only) ++#CONFIG_DRIVER_NONE=y ++ ++# Solaris libraries ++#LIBS += -lsocket -ldlpi -lnsl ++#LIBS_c += -lsocket ++ ++# Enable IEEE 802.1X Supplicant (automatically included if any EAP method or ++# MACsec is included) ++CONFIG_IEEE8021X_EAPOL=y ++ ++# EAP-MD5 ++CONFIG_EAP_MD5=y ++ ++# EAP-MSCHAPv2 ++CONFIG_EAP_MSCHAPV2=y ++ ++# EAP-TLS ++CONFIG_EAP_TLS=y ++ ++# EAL-PEAP ++CONFIG_EAP_PEAP=y ++ ++# EAP-TTLS ++CONFIG_EAP_TTLS=y ++ ++# EAP-FAST ++#CONFIG_EAP_FAST=y ++ ++# EAP-TEAP ++# Note: The current EAP-TEAP implementation is experimental and should not be ++# enabled for production use. The IETF RFC 7170 that defines EAP-TEAP has number ++# of conflicting statements and missing details and the implementation has ++# vendor specific workarounds for those and as such, may not interoperate with ++# any other implementation. This should not be used for anything else than ++# experimentation and interoperability testing until those issues has been ++# resolved. ++#CONFIG_EAP_TEAP=y ++ ++# EAP-GTC ++CONFIG_EAP_GTC=y ++ ++# EAP-OTP ++CONFIG_EAP_OTP=y ++ ++# EAP-SIM (enable CONFIG_PCSC, if EAP-SIM is used) ++#CONFIG_EAP_SIM=y ++ ++# Enable SIM simulator (Milenage) for EAP-SIM ++#CONFIG_SIM_SIMULATOR=y ++ ++# EAP-PSK (experimental; this is _not_ needed for WPA-PSK) ++#CONFIG_EAP_PSK=y ++ ++# EAP-pwd (secure authentication using only a password) ++#CONFIG_EAP_PWD=y ++ ++# EAP-PAX ++#CONFIG_EAP_PAX=y ++ ++# LEAP ++CONFIG_EAP_LEAP=y ++ ++# EAP-AKA (enable CONFIG_PCSC, if EAP-AKA is used) ++#CONFIG_EAP_AKA=y ++ ++# EAP-AKA' (enable CONFIG_PCSC, if EAP-AKA' is used). ++# This requires CONFIG_EAP_AKA to be enabled, too. ++#CONFIG_EAP_AKA_PRIME=y ++ ++# Enable USIM simulator (Milenage) for EAP-AKA ++#CONFIG_USIM_SIMULATOR=y ++ ++# EAP-SAKE ++#CONFIG_EAP_SAKE=y ++ ++# EAP-GPSK ++#CONFIG_EAP_GPSK=y ++# Include support for optional SHA256 cipher suite in EAP-GPSK ++#CONFIG_EAP_GPSK_SHA256=y ++ ++# EAP-TNC and related Trusted Network Connect support (experimental) ++#CONFIG_EAP_TNC=y ++ ++# Wi-Fi Protected Setup (WPS) ++CONFIG_WPS=y ++# Enable WPS external registrar functionality ++#CONFIG_WPS_ER=y ++# Disable credentials for an open network by default when acting as a WPS ++# registrar. ++#CONFIG_WPS_REG_DISABLE_OPEN=y ++# Enable WPS support with NFC config method ++#CONFIG_WPS_NFC=y ++ ++# EAP-IKEv2 ++#CONFIG_EAP_IKEV2=y ++ ++# EAP-EKE ++#CONFIG_EAP_EKE=y ++ ++# MACsec ++#CONFIG_MACSEC=y ++ ++# PKCS#12 (PFX) support (used to read private key and certificate file from ++# a file that usually has extension .p12 or .pfx) ++CONFIG_PKCS12=y ++ ++# Smartcard support (i.e., private key on a smartcard), e.g., with openssl ++# engine. ++CONFIG_SMARTCARD=y ++ ++# PC/SC interface for smartcards (USIM, GSM SIM) ++# Enable this if EAP-SIM or EAP-AKA is included ++#CONFIG_PCSC=y ++ ++# Support HT overrides (disable HT/HT40, mask MCS rates, etc.) ++#CONFIG_HT_OVERRIDES=y ++ ++# Support VHT overrides (disable VHT, mask MCS rates, etc.) ++#CONFIG_VHT_OVERRIDES=y ++ ++# Development testing ++#CONFIG_EAPOL_TEST=y ++ ++# Select control interface backend for external programs, e.g, wpa_cli: ++# unix = UNIX domain sockets (default for Linux/*BSD) ++# udp = UDP sockets using localhost (127.0.0.1) ++# udp6 = UDP IPv6 sockets using localhost (::1) ++# named_pipe = Windows Named Pipe (default for Windows) ++# udp-remote = UDP sockets with remote access (only for tests systems/purpose) ++# udp6-remote = UDP IPv6 sockets with remote access (only for tests purpose) ++# y = use default (backwards compatibility) ++# If this option is commented out, control interface is not included in the ++# build. ++CONFIG_CTRL_IFACE=y ++ ++# Include support for GNU Readline and History Libraries in wpa_cli. ++# When building a wpa_cli binary for distribution, please note that these ++# libraries are licensed under GPL and as such, BSD license may not apply for ++# the resulting binary. ++#CONFIG_READLINE=y ++ ++# Include internal line edit mode in wpa_cli. This can be used as a replacement ++# for GNU Readline to provide limited command line editing and history support. ++#CONFIG_WPA_CLI_EDIT=y ++ ++# Remove debugging code that is printing out debug message to stdout. ++# This can be used to reduce the size of the wpa_supplicant considerably ++# if debugging code is not needed. The size reduction can be around 35% ++# (e.g., 90 kB). ++#CONFIG_NO_STDOUT_DEBUG=y ++ ++# Remove WPA support, e.g., for wired-only IEEE 802.1X supplicant, to save ++# 35-50 kB in code size. ++#CONFIG_NO_WPA=y ++ ++# Remove IEEE 802.11i/WPA-Personal ASCII passphrase support ++# This option can be used to reduce code size by removing support for ++# converting ASCII passphrases into PSK. If this functionality is removed, the ++# PSK can only be configured as the 64-octet hexstring (e.g., from ++# wpa_passphrase). This saves about 0.5 kB in code size. ++#CONFIG_NO_WPA_PASSPHRASE=y ++ ++# Simultaneous Authentication of Equals (SAE), WPA3-Personal ++CONFIG_SAE=y ++ ++# Disable scan result processing (ap_scan=1) to save code size by about 1 kB. ++# This can be used if ap_scan=1 mode is never enabled. ++#CONFIG_NO_SCAN_PROCESSING=y ++ ++# Select configuration backend: ++# file = text file (e.g., wpa_supplicant.conf; note: the configuration file ++# path is given on command line, not here; this option is just used to ++# select the backend that allows configuration files to be used) ++# winreg = Windows registry (see win_example.reg for an example) ++CONFIG_BACKEND=file ++ ++# Remove configuration write functionality (i.e., to allow the configuration ++# file to be updated based on runtime configuration changes). The runtime ++# configuration can still be changed, the changes are just not going to be ++# persistent over restarts. This option can be used to reduce code size by ++# about 3.5 kB. ++#CONFIG_NO_CONFIG_WRITE=y ++ ++# Remove support for configuration blobs to reduce code size by about 1.5 kB. ++#CONFIG_NO_CONFIG_BLOBS=y ++ ++# Select program entry point implementation: ++# main = UNIX/POSIX like main() function (default) ++# main_winsvc = Windows service (read parameters from registry) ++# main_none = Very basic example (development use only) ++#CONFIG_MAIN=main ++ ++# Select wrapper for operating system and C library specific functions ++# unix = UNIX/POSIX like systems (default) ++# win32 = Windows systems ++# none = Empty template ++#CONFIG_OS=unix ++ ++# Select event loop implementation ++# eloop = select() loop (default) ++# eloop_win = Windows events and WaitForMultipleObject() loop ++#CONFIG_ELOOP=eloop ++ ++# Should we use poll instead of select? Select is used by default. ++#CONFIG_ELOOP_POLL=y ++ ++# Should we use epoll instead of select? Select is used by default. ++#CONFIG_ELOOP_EPOLL=y ++ ++# Should we use kqueue instead of select? Select is used by default. ++#CONFIG_ELOOP_KQUEUE=y ++ ++# Select layer 2 packet implementation ++# linux = Linux packet socket (default) ++# pcap = libpcap/libdnet/WinPcap ++# freebsd = FreeBSD libpcap ++# winpcap = WinPcap with receive thread ++# ndis = Windows NDISUIO (note: requires CONFIG_USE_NDISUIO=y) ++# none = Empty template ++#CONFIG_L2_PACKET=linux ++ ++# Disable Linux packet socket workaround applicable for station interface ++# in a bridge for EAPOL frames. This should be uncommented only if the kernel ++# is known to not have the regression issue in packet socket behavior with ++# bridge interfaces (commit 'bridge: respect RFC2863 operational state')'). ++#CONFIG_NO_LINUX_PACKET_SOCKET_WAR=y ++ ++# Support Operating Channel Validation ++#CONFIG_OCV=y ++ ++# Select TLS implementation ++# openssl = OpenSSL (default) ++# gnutls = GnuTLS ++# internal = Internal TLSv1 implementation (experimental) ++# linux = Linux kernel AF_ALG and internal TLSv1 implementation (experimental) ++# none = Empty template ++#CONFIG_TLS=openssl ++ ++# TLS-based EAP methods require at least TLS v1.0. Newer version of TLS (v1.1) ++# can be enabled to get a stronger construction of messages when block ciphers ++# are used. It should be noted that some existing TLS v1.0 -based ++# implementation may not be compatible with TLS v1.1 message (ClientHello is ++# sent prior to negotiating which version will be used) ++#CONFIG_TLSV11=y ++ ++# TLS-based EAP methods require at least TLS v1.0. Newer version of TLS (v1.2) ++# can be enabled to enable use of stronger crypto algorithms. It should be ++# noted that some existing TLS v1.0 -based implementation may not be compatible ++# with TLS v1.2 message (ClientHello is sent prior to negotiating which version ++# will be used) ++#CONFIG_TLSV12=y ++ ++# Select which ciphers to use by default with OpenSSL if the user does not ++# specify them. ++#CONFIG_TLS_DEFAULT_CIPHERS="DEFAULT:!EXP:!LOW" ++ ++# If CONFIG_TLS=internal is used, additional library and include paths are ++# needed for LibTomMath. Alternatively, an integrated, minimal version of ++# LibTomMath can be used. See beginning of libtommath.c for details on benefits ++# and drawbacks of this option. ++#CONFIG_INTERNAL_LIBTOMMATH=y ++#ifndef CONFIG_INTERNAL_LIBTOMMATH ++#LTM_PATH=/usr/src/libtommath-0.39 ++#CFLAGS += -I$(LTM_PATH) ++#LIBS += -L$(LTM_PATH) ++#LIBS_p += -L$(LTM_PATH) ++#endif ++# At the cost of about 4 kB of additional binary size, the internal LibTomMath ++# can be configured to include faster routines for exptmod, sqr, and div to ++# speed up DH and RSA calculation considerably ++#CONFIG_INTERNAL_LIBTOMMATH_FAST=y ++ ++# Include NDIS event processing through WMI into wpa_supplicant/wpasvc. ++# This is only for Windows builds and requires WMI-related header files and ++# WbemUuid.Lib from Platform SDK even when building with MinGW. ++#CONFIG_NDIS_EVENTS_INTEGRATED=y ++#PLATFORMSDKLIB="/opt/Program Files/Microsoft Platform SDK/Lib" ++ ++# Add support for new DBus control interface ++# (fi.w1.wpa_supplicant1) ++#CONFIG_CTRL_IFACE_DBUS_NEW=y ++ ++# Add introspection support for new DBus control interface ++#CONFIG_CTRL_IFACE_DBUS_INTRO=y ++ ++# Add support for loading EAP methods dynamically as shared libraries. ++# When this option is enabled, each EAP method can be either included ++# statically (CONFIG_EAP_=y) or dynamically (CONFIG_EAP_=dyn). ++# Dynamic EAP methods are build as shared objects (eap_*.so) and they need to ++# be loaded in the beginning of the wpa_supplicant configuration file ++# (see load_dynamic_eap parameter in the example file) before being used in ++# the network blocks. ++# ++# Note that some shared parts of EAP methods are included in the main program ++# and in order to be able to use dynamic EAP methods using these parts, the ++# main program must have been build with the EAP method enabled (=y or =dyn). ++# This means that EAP-TLS/PEAP/TTLS/FAST cannot be added as dynamic libraries ++# unless at least one of them was included in the main build to force inclusion ++# of the shared code. Similarly, at least one of EAP-SIM/AKA must be included ++# in the main build to be able to load these methods dynamically. ++# ++# Please also note that using dynamic libraries will increase the total binary ++# size. Thus, it may not be the best option for targets that have limited ++# amount of memory/flash. ++#CONFIG_DYNAMIC_EAP_METHODS=y ++ ++# IEEE Std 802.11r-2008 (Fast BSS Transition) for station mode ++CONFIG_IEEE80211R=y ++ ++# Add support for writing debug log to a file (/tmp/wpa_supplicant-log-#.txt) ++CONFIG_DEBUG_FILE=y ++ ++# Send debug messages to syslog instead of stdout ++#CONFIG_DEBUG_SYSLOG=y ++# Set syslog facility for debug messages ++#CONFIG_DEBUG_SYSLOG_FACILITY=LOG_DAEMON ++ ++# Add support for sending all debug messages (regardless of debug verbosity) ++# to the Linux kernel tracing facility. This helps debug the entire stack by ++# making it easy to record everything happening from the driver up into the ++# same file, e.g., using trace-cmd. ++#CONFIG_DEBUG_LINUX_TRACING=y ++ ++# Add support for writing debug log to Android logcat instead of standard ++# output ++#CONFIG_ANDROID_LOG=y ++ ++# Enable privilege separation (see README 'Privilege separation' for details) ++#CONFIG_PRIVSEP=y ++ ++# Enable mitigation against certain attacks against TKIP by delaying Michael ++# MIC error reports by a random amount of time between 0 and 60 seconds ++#CONFIG_DELAYED_MIC_ERROR_REPORT=y ++ ++# Enable tracing code for developer debugging ++# This tracks use of memory allocations and other registrations and reports ++# incorrect use with a backtrace of call (or allocation) location. ++#CONFIG_WPA_TRACE=y ++# For BSD, uncomment these. ++#LIBS += -lexecinfo ++#LIBS_p += -lexecinfo ++#LIBS_c += -lexecinfo ++ ++# Use libbfd to get more details for developer debugging ++# This enables use of libbfd to get more detailed symbols for the backtraces ++# generated by CONFIG_WPA_TRACE=y. ++#CONFIG_WPA_TRACE_BFD=y ++# For BSD, uncomment these. ++#LIBS += -lbfd -liberty -lz ++#LIBS_p += -lbfd -liberty -lz ++#LIBS_c += -lbfd -liberty -lz ++ ++# wpa_supplicant depends on strong random number generation being available ++# from the operating system. os_get_random() function is used to fetch random ++# data when needed, e.g., for key generation. On Linux and BSD systems, this ++# works by reading /dev/urandom. It should be noted that the OS entropy pool ++# needs to be properly initialized before wpa_supplicant is started. This is ++# important especially on embedded devices that do not have a hardware random ++# number generator and may by default start up with minimal entropy available ++# for random number generation. ++# ++# As a safety net, wpa_supplicant is by default trying to internally collect ++# additional entropy for generating random data to mix in with the data fetched ++# from the OS. This by itself is not considered to be very strong, but it may ++# help in cases where the system pool is not initialized properly. However, it ++# is very strongly recommended that the system pool is initialized with enough ++# entropy either by using hardware assisted random number generator or by ++# storing state over device reboots. ++# ++# wpa_supplicant can be configured to maintain its own entropy store over ++# restarts to enhance random number generation. This is not perfect, but it is ++# much more secure than using the same sequence of random numbers after every ++# reboot. This can be enabled with -e command line option. The ++# specified file needs to be readable and writable by wpa_supplicant. ++# ++# If the os_get_random() is known to provide strong random data (e.g., on ++# Linux/BSD, the board in question is known to have reliable source of random ++# data from /dev/urandom), the internal wpa_supplicant random pool can be ++# disabled. This will save some in binary size and CPU use. However, this ++# should only be considered for builds that are known to be used on devices ++# that meet the requirements described above. ++#CONFIG_NO_RANDOM_POOL=y ++ ++# Should we attempt to use the getrandom(2) call that provides more reliable ++# yet secure randomness source than /dev/random on Linux 3.17 and newer. ++# Requires glibc 2.25 to build, falls back to /dev/random if unavailable. ++#CONFIG_GETRANDOM=y ++ ++# IEEE 802.11ac (Very High Throughput) support (mainly for AP mode) ++CONFIG_IEEE80211AC=y ++ ++# IEEE 802.11ax HE support (mainly for AP mode) ++# Note: This is experimental and work in progress. The definitions are still ++# subject to change and this should not be expected to interoperate with the ++# final IEEE 802.11ax version. ++CONFIG_IEEE80211AX=y ++ ++# Wireless Network Management (IEEE Std 802.11v-2011) ++# Note: This is experimental and not complete implementation. ++#CONFIG_WNM=y ++ ++# Interworking (IEEE 802.11u) ++# This can be used to enable functionality to improve interworking with ++# external networks (GAS/ANQP to learn more about the networks and network ++# selection based on available credentials). ++#CONFIG_INTERWORKING=y ++ ++# Hotspot 2.0 ++#CONFIG_HS20=y ++ ++# Enable interface matching in wpa_supplicant ++#CONFIG_MATCH_IFACE=y ++ ++# Disable roaming in wpa_supplicant ++#CONFIG_NO_ROAMING=y ++ ++# AP mode operations with wpa_supplicant ++# This can be used for controlling AP mode operations with wpa_supplicant. It ++# should be noted that this is mainly aimed at simple cases like ++# WPA2-Personal while more complex configurations like WPA2-Enterprise with an ++# external RADIUS server can be supported with hostapd. ++#CONFIG_AP=y ++ ++# P2P (Wi-Fi Direct) ++# This can be used to enable P2P support in wpa_supplicant. See README-P2P for ++# more information on P2P operations. ++CONFIG_P2P=y ++ ++# Enable TDLS support ++#CONFIG_TDLS=y ++ ++# Wi-Fi Display ++# This can be used to enable Wi-Fi Display extensions for P2P using an external ++# program to control the additional information exchanges in the messages. ++#CONFIG_WIFI_DISPLAY=y ++ ++# Autoscan ++# This can be used to enable automatic scan support in wpa_supplicant. ++# See wpa_supplicant.conf for more information on autoscan usage. ++# ++# Enabling directly a module will enable autoscan support. ++# For exponential module: ++#CONFIG_AUTOSCAN_EXPONENTIAL=y ++# For periodic module: ++#CONFIG_AUTOSCAN_PERIODIC=y ++ ++# Password (and passphrase, etc.) backend for external storage ++# These optional mechanisms can be used to add support for storing passwords ++# and other secrets in external (to wpa_supplicant) location. This allows, for ++# example, operating system specific key storage to be used ++# ++# External password backend for testing purposes (developer use) ++#CONFIG_EXT_PASSWORD_TEST=y ++ ++# Enable Fast Session Transfer (FST) ++#CONFIG_FST=y ++ ++# Enable CLI commands for FST testing ++#CONFIG_FST_TEST=y ++ ++# OS X builds. This is only for building eapol_test. ++#CONFIG_OSX=y ++ ++# Automatic Channel Selection ++# This will allow wpa_supplicant to pick the channel automatically when channel ++# is set to "0". ++# ++# TODO: Extend parser to be able to parse "channel=acs_survey" as an alternative ++# to "channel=0". This would enable us to eventually add other ACS algorithms in ++# similar way. ++# ++# Automatic selection is currently only done through initialization, later on ++# we hope to do background checks to keep us moving to more ideal channels as ++# time goes by. ACS is currently only supported through the nl80211 driver and ++# your driver must have survey dump capability that is filled by the driver ++# during scanning. ++# ++# TODO: In analogy to hostapd be able to customize the ACS survey algorithm with ++# a newly to create wpa_supplicant.conf variable acs_num_scans. ++# ++# Supported ACS drivers: ++# * ath9k ++# * ath5k ++# * ath10k ++# ++# For more details refer to: ++# http://wireless.kernel.org/en/users/Documentation/acs ++#CONFIG_ACS=y ++ ++# Support Multi Band Operation ++#CONFIG_MBO=y ++ ++# Fast Initial Link Setup (FILS) (IEEE 802.11ai) ++#CONFIG_FILS=y ++# FILS shared key authentication with PFS ++#CONFIG_FILS_SK_PFS=y ++ ++# Support RSN on IBSS networks ++# This is needed to be able to use mode=1 network profile with proto=RSN and ++# key_mgmt=WPA-PSK (i.e., full key management instead of WPA-None). ++#CONFIG_IBSS_RSN=y ++ ++# External PMKSA cache control ++# This can be used to enable control interface commands that allow the current ++# PMKSA cache entries to be fetched and new entries to be added. ++#CONFIG_PMKSA_CACHE_EXTERNAL=y ++ ++# Mesh Networking (IEEE 802.11s) ++#CONFIG_MESH=y ++ ++# Background scanning modules ++# These can be used to request wpa_supplicant to perform background scanning ++# operations for roaming within an ESS (same SSID). See the bgscan parameter in ++# the wpa_supplicant.conf file for more details. ++# Periodic background scans based on signal strength ++#CONFIG_BGSCAN_SIMPLE=y ++# Learn channels used by the network and try to avoid bgscans on other ++# channels (experimental) ++#CONFIG_BGSCAN_LEARN=y ++ ++# Opportunistic Wireless Encryption (OWE) ++# Experimental implementation of draft-harkins-owe-07.txt ++#CONFIG_OWE=y ++ ++# Device Provisioning Protocol (DPP) ++CONFIG_DPP=y ++ ++# Wired equivalent privacy (WEP) ++# WEP is an obsolete cryptographic data confidentiality algorithm that is not ++# considered secure. It should not be used for anything anymore. The ++# functionality needed to use WEP is available in the current wpa_supplicant ++# release under this optional build parameter. This functionality is subject to ++# be completely removed in a future release. ++#CONFIG_WEP=y ++ ++# Remove all TKIP functionality ++# TKIP is an old cryptographic data confidentiality algorithm that is not ++# considered secure. It should not be used anymore for anything else than a ++# backwards compatibility option as a group cipher when connecting to APs that ++# use WPA+WPA2 mixed mode. For now, the default wpa_supplicant build includes ++# support for this by default, but that functionality is subject to be removed ++# in the future. ++#CONFIG_NO_TKIP=y ++ ++# Testing options ++# This can be used to enable some testing options (see also the example ++# configuration file) that are really useful only for testing clients that ++# connect to this hostapd. These options allow, for example, to drop a ++# certain percentage of probe requests or auth/(re)assoc frames. ++CONFIG_TESTING_OPTIONS=y +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0020-Fix-to-check-Invalid-GTK-IE-length-in-M3-at-STA.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0014-CVE_2019_9501-Fix-to-check-Invalid-GTK-IE-length-in-.patch similarity index 83% rename from meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0020-Fix-to-check-Invalid-GTK-IE-length-in-M3-at-STA.patch rename to meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0014-CVE_2019_9501-Fix-to-check-Invalid-GTK-IE-length-in-.patch index 5ca7125bc..1cc5dc822 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0020-Fix-to-check-Invalid-GTK-IE-length-in-M3-at-STA.patch +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0014-CVE_2019_9501-Fix-to-check-Invalid-GTK-IE-length-in-.patch @@ -1,13 +1,15 @@ +From 28c5794ff336f3ec29be79197198071be9add4ac Mon Sep 17 00:00:00 2001 From: Suresh Sanaboina Date: Tue, 1 Feb 2022 13:02:07 +0000 -Subject: [PATCH] Fix to check Invalid GTK IE length in M3 at STA +Subject: [PATCH 14/49] [CVE_2019_9501] Fix to check Invalid GTK IE length in + M3 at STA --- src/rsn_supp/wpa.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/src/rsn_supp/wpa.c b/src/rsn_supp/wpa.c -index a9f1fb916a8d..1f6401ef39a9 100644 +index 0a2f87787..92ab7d561 100644 --- a/src/rsn_supp/wpa.c +++ b/src/rsn_supp/wpa.c @@ -1661,6 +1661,7 @@ static void wpa_supplicant_process_3_of_4(struct wpa_sm *sm, @@ -30,3 +32,6 @@ index a9f1fb916a8d..1f6401ef39a9 100644 if (wpa_supplicant_send_4_of_4(sm, sm->bssid, key, ver, key_info, &sm->ptk) < 0) { goto failed; +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0015-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes.murata.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0015-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes.murata.patch new file mode 100644 index 000000000..eb24cd711 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0015-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes.murata.patch @@ -0,0 +1,123 @@ +From ab61a3dd6d968c62b407c170079a236194357931 Mon Sep 17 00:00:00 2001 +From: Danny Chiu +Date: Thu, 4 Nov 2021 02:44:17 -0500 +Subject: [PATCH 15/49] Add CONFIG_WPA3_SAE_AUTH_EARLY_SET flags and codes + +Enable this flags allow the AP to set authorization to firmware earier as the SAE confirm from is ok. +--- + hostapd/Android.mk | 4 ++++ + hostapd/Makefile | 4 ++++ + hostapd/android.config | 3 +++ + hostapd/defconfig_base | 3 +++ + src/ap/ieee802_11.c | 11 +++++++++++ + wpa_supplicant/defconfig_base | 3 +++ + 6 files changed, 28 insertions(+) + +diff --git a/hostapd/Android.mk b/hostapd/Android.mk +index bf26e41c6..997e9a447 100644 +--- a/hostapd/Android.mk ++++ b/hostapd/Android.mk +@@ -264,6 +264,10 @@ NEED_HMAC_SHA256_KDF=y + NEED_DRAGONFLY=y + endif + ++ifdef CONFIG_WPA3_SAE_AUTH_EARLY_SET ++L_CFLAGS += -DCONFIG_WPA3_SAE_AUTH_EARLY_SET ++endif ++ + ifdef CONFIG_OWE + L_CFLAGS += -DCONFIG_OWE + NEED_ECC=y +diff --git a/hostapd/Makefile b/hostapd/Makefile +index e37c13b27..c65a51227 100644 +--- a/hostapd/Makefile ++++ b/hostapd/Makefile +@@ -290,6 +290,10 @@ CFLAGS += -DCONFIG_ETH_P_OUI + OBJS += ../src/ap/eth_p_oui.o + endif + ++ifdef CONFIG_WPA3_SAE_AUTH_EARLY_SET ++CFLAGS += -DCONFIG_WPA3_SAE_AUTH_EARLY_SET ++endif ++ + ifdef CONFIG_SAE + CFLAGS += -DCONFIG_SAE + OBJS += ../src/common/sae.o +diff --git a/hostapd/android.config b/hostapd/android.config +index c8b3afabe..3664f1773 100644 +--- a/hostapd/android.config ++++ b/hostapd/android.config +@@ -212,3 +212,6 @@ CONFIG_NO_RANDOM_POOL=y + # release under this optional build parameter. This functionality is subject to + # be completely removed in a future release. + CONFIG_WEP=y ++ ++# Set SAE Auth status early ++CONFIG_WPA3_SAE_AUTH_EARLY_SET=y +diff --git a/hostapd/defconfig_base b/hostapd/defconfig_base +index 9dcf7848d..dafcf0f6c 100644 +--- a/hostapd/defconfig_base ++++ b/hostapd/defconfig_base +@@ -399,5 +399,8 @@ CONFIG_TESTING_OPTIONS=y + # Simultaneous Authentication of Equals (SAE), WPA3-Personal + CONFIG_SAE=y + ++# Set SAE Auth status early ++CONFIG_WPA3_SAE_AUTH_EARLY_SET=y ++ + # Device Provisioning Protocol (DPP) + CONFIG_DPP=y +diff --git a/src/ap/ieee802_11.c b/src/ap/ieee802_11.c +index db4104928..3b735c09f 100644 +--- a/src/ap/ieee802_11.c ++++ b/src/ap/ieee802_11.c +@@ -87,6 +87,10 @@ static void handle_auth(struct hostapd_data *hapd, + const struct ieee80211_mgmt *mgmt, size_t len, + int rssi, int from_queue); + ++#ifdef CONFIG_WPA3_SAE_AUTH_EARLY_SET ++static void sae_sme_send_external_auth_status(struct hostapd_data *hapd, ++ struct sta_info *sta, u16 status); ++#endif /* CONFIG_WPA3_SAE_AUTH_EARLY_SET */ + + u8 * hostapd_eid_multi_ap(struct hostapd_data *hapd, u8 *eid) + { +@@ -677,6 +681,11 @@ static int auth_sae_send_confirm(struct hostapd_data *hapd, + if (data == NULL) + return WLAN_STATUS_UNSPECIFIED_FAILURE; + ++#ifdef CONFIG_WPA3_SAE_AUTH_EARLY_SET ++ wpa_printf(MSG_DEBUG, "\nCalling sae_sme_send_external_auth_status\n"); ++ sae_sme_send_external_auth_status(hapd, sta, WLAN_STATUS_SUCCESS); ++#endif /* CONFIG_WPA3_SAE_AUTH_EARLY_SET */ ++ + reply_res = send_auth_reply(hapd, sta, sta->addr, bssid, + WLAN_AUTH_SAE, 2, + WLAN_STATUS_SUCCESS, wpabuf_head(data), +@@ -973,7 +982,9 @@ void sae_accept_sta(struct hostapd_data *hapd, struct sta_info *sta) + sta->sae->peer_commit_scalar = NULL; + wpa_auth_pmksa_add_sae(hapd->wpa_auth, sta->addr, + sta->sae->pmk, sta->sae->pmkid); ++#ifndef CONFIG_WPA3_SAE_AUTH_EARLY_SET + sae_sme_send_external_auth_status(hapd, sta, WLAN_STATUS_SUCCESS); ++#endif /* CONFIG_WPA3_SAE_AUTH_EARLY_SET */ + } + + +diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base +index 15daf0ad2..99c74853d 100644 +--- a/wpa_supplicant/defconfig_base ++++ b/wpa_supplicant/defconfig_base +@@ -248,6 +248,9 @@ CONFIG_CTRL_IFACE=y + # Simultaneous Authentication of Equals (SAE), WPA3-Personal + CONFIG_SAE=y + ++# Set SAE Auth status early ++CONFIG_WPA3_SAE_AUTH_EARLY_SET=y ++ + # Disable scan result processing (ap_scan=1) to save code size by about 1 kB. + # This can be used if ap_scan=1 mode is never enabled. + #CONFIG_NO_SCAN_PROCESSING=y +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0017-SAE-Set-the-right-WPA-Versions-for-FT-SAE-key-manage.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0016-SAE-Set-the-right-WPA-Versions-for-FT-SAE-key-manage.patch similarity index 81% rename from meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0017-SAE-Set-the-right-WPA-Versions-for-FT-SAE-key-manage.patch rename to meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0016-SAE-Set-the-right-WPA-Versions-for-FT-SAE-key-manage.patch index 9ff0a1965..6843ed4ee 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0017-SAE-Set-the-right-WPA-Versions-for-FT-SAE-key-manage.patch +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0016-SAE-Set-the-right-WPA-Versions-for-FT-SAE-key-manage.patch @@ -1,6 +1,8 @@ +From 32ee9150ccf3f6c242ba2809aab9b9e115a9d1b5 Mon Sep 17 00:00:00 2001 From: Darren Li Date: Fri, 26 Nov 2021 02:09:03 -0600 -Subject: [PATCH] SAE: Set the right WPA Versions for FT-SAE key management +Subject: [PATCH 16/49] SAE: Set the right WPA Versions for FT-SAE key + management Set the right WPA Versions for FT-SAE key management @@ -10,7 +12,7 @@ Signed-off-by: Darren Li Darren.Li@infineon.com 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c -index b6afc6e7aa61..341c753b3e83 100644 +index b6afc6e7a..341c753b3 100644 --- a/src/drivers/driver_nl80211.c +++ b/src/drivers/driver_nl80211.c @@ -6208,7 +6208,8 @@ static int nl80211_connect_common(struct wpa_driver_nl80211_data *drv, @@ -23,3 +25,6 @@ index b6afc6e7aa61..341c753b3e83 100644 ver |= NL80211_WPA_VERSION_3; else ver |= NL80211_WPA_VERSION_2; +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0017-wpa_supplicant-Support-WPA_KEY_MGMT_FT-for-eapol-off.murata.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0017-wpa_supplicant-Support-WPA_KEY_MGMT_FT-for-eapol-off.murata.patch new file mode 100644 index 000000000..f4f9aede6 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0017-wpa_supplicant-Support-WPA_KEY_MGMT_FT-for-eapol-off.murata.patch @@ -0,0 +1,74 @@ +From 6fa06f214ba1cfc4e80dc7413874175146b9c2a5 Mon Sep 17 00:00:00 2001 +From: Chien-Chia Chen +Date: Tue, 23 Nov 2021 21:29:08 -0600 +Subject: [PATCH 17/49] wpa_supplicant: Support WPA_KEY_MGMT_FT for eapol + offloading and driver base roaming + +Add WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_PSK / WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_8021X / +WPA_DRIVER_FLAGS_ROAM_OFFLOAD for IEEE80211R support + +Signed-off-by: Chien-Chia Chen +--- + src/drivers/driver.h | 2 ++ + src/drivers/driver_nl80211.c | 3 ++- + src/drivers/driver_nl80211_capa.c | 4 ++++ + src/drivers/nl80211_copy.h | 1 + + 4 files changed, 9 insertions(+), 1 deletions(-) + +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index 45260e8c5..fb3f8b4a8 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -2071,6 +2071,8 @@ struct wpa_driver_capa { + #define WPA_DRIVER_FLAGS2_4WAY_HANDSHAKE_AP_PSK 0x0000000000000400ULL + /** Driver supports SAE authentication offload in AP mode */ + #define WPA_DRIVER_FLAGS2_SAE_OFFLOAD_AP 0x0000000000000800ULL ++/** Driver supports FT / OKC fast roaming */ ++#define WPA_DRIVER_FLAGS_ROAM_OFFLOAD 0x0000000000001000ULL + u64 flags2; + + #define FULL_AP_CLIENT_STATE_SUPP(drv_flags) \ +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index 341c753b3..964486c11 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -3301,7 +3301,8 @@ static int wpa_driver_nl80211_set_key(struct i802_bss *bss, + #endif /* CONFIG_DRIVER_NL80211_QCA */ + + if (key_flag & KEY_FLAG_PMK) { +- if (drv->capa.flags & WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_8021X) ++ if ((drv->capa.flags & WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_8021X) || ++ (drv->capa.flags2 & WPA_DRIVER_FLAGS_ROAM_OFFLOAD)) + return nl80211_set_pmk(drv, key, key_len, addr); + /* The driver does not have any offload mechanism for PMK, so + * there is no need to configure this key. */ +diff --git a/src/drivers/driver_nl80211_capa.c b/src/drivers/driver_nl80211_capa.c +index ae6029a92..d5cdafa9f 100644 +--- a/src/drivers/driver_nl80211_capa.c ++++ b/src/drivers/driver_nl80211_capa.c +@@ -606,6 +606,10 @@ static void wiphy_info_ext_feature_flags(struct wiphy_info_data *info, + NL80211_EXT_FEATURE_SAE_OFFLOAD_AP)) + capa->flags2 |= WPA_DRIVER_FLAGS2_SAE_OFFLOAD_AP; + ++ if (ext_feature_isset(ext_features, len, ++ NL80211_EXT_FEATURE_ROAM_OFFLOAD)) ++ capa->flags2 |= WPA_DRIVER_FLAGS_ROAM_OFFLOAD; ++ + if (ext_feature_isset(ext_features, len, + NL80211_EXT_FEATURE_MFP_OPTIONAL)) + capa->flags |= WPA_DRIVER_FLAGS_MFP_OPTIONAL; +diff --git a/src/drivers/nl80211_copy.h b/src/drivers/nl80211_copy.h +index f962c06e9..a3e889b35 100644 +--- a/src/drivers/nl80211_copy.h ++++ b/src/drivers/nl80211_copy.h +@@ -6010,6 +6010,7 @@ enum nl80211_ext_feature_index { + NL80211_EXT_FEATURE_SAE_OFFLOAD_AP, + NL80211_EXT_FEATURE_FILS_DISCOVERY, + NL80211_EXT_FEATURE_UNSOL_BCAST_PROBE_RESP, ++ NL80211_EXT_FEATURE_ROAM_OFFLOAD, + NL80211_EXT_FEATURE_BEACON_RATE_HE, + NL80211_EXT_FEATURE_SECURE_LTF, + NL80211_EXT_FEATURE_SECURE_RTT, +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0018-wpa_supplicant-suppress-deauth-for-PMKSA-caching-dis.murata.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0018-wpa_supplicant-suppress-deauth-for-PMKSA-caching-dis.murata.patch new file mode 100644 index 000000000..ce6cb5754 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0018-wpa_supplicant-suppress-deauth-for-PMKSA-caching-dis.murata.patch @@ -0,0 +1,65 @@ +From 9af850cef2007cabe1bbffad3ef1d2b13396832d Mon Sep 17 00:00:00 2001 +From: Darren Li +Date: Tue, 22 Feb 2022 00:34:47 -0600 +Subject: [PATCH 18/49] wpa_supplicant: suppress deauth for PMKSA caching + disabled + +wpa_supplicant: Need a command/parameter suppress deauth for PMKSA caching disabled + +Signed-off-by: Darren Li +--- + src/rsn_supp/wpa.c | 5 ++++- + src/rsn_supp/wpa.h | 1 + + src/rsn_supp/wpa_i.h | 1 + + 3 files changed, 6 insertions(+), 1 deletion(-) + +diff --git a/src/rsn_supp/wpa.c b/src/rsn_supp/wpa.c +index 92ab7d561..1f6401ef3 100644 +--- a/src/rsn_supp/wpa.c ++++ b/src/rsn_supp/wpa.c +@@ -2904,7 +2904,9 @@ static void wpa_sm_pmksa_free_cb(struct rsn_pmksa_cache_entry *entry, + if (deauth) { + sm->pmk_len = 0; + os_memset(sm->pmk, 0, sizeof(sm->pmk)); +- wpa_sm_deauthenticate(sm, WLAN_REASON_UNSPECIFIED); ++ if (!sm->suppress_deauth_no_pmksa) { ++ wpa_sm_deauthenticate(sm, WLAN_REASON_UNSPECIFIED); ++ } + } + } + +@@ -3240,6 +3242,7 @@ void wpa_sm_set_config(struct wpa_sm *sm, struct rsn_supp_config *config) + } + #endif /* CONFIG_FILS */ + sm->beacon_prot = config->beacon_prot; ++ sm->suppress_deauth_no_pmksa = config->suppress_deauth_no_pmksa; + } else { + sm->network_ctx = NULL; + sm->allowed_pairwise_cipher = 0; +diff --git a/src/rsn_supp/wpa.h b/src/rsn_supp/wpa.h +index 41daaae2c..2cd1826e4 100644 +--- a/src/rsn_supp/wpa.h ++++ b/src/rsn_supp/wpa.h +@@ -136,6 +136,7 @@ struct rsn_supp_config { + const u8 *fils_cache_id; + int beacon_prot; + bool force_kdk_derivation; ++ int suppress_deauth_no_pmksa; + }; + + #ifndef CONFIG_NO_WPA +diff --git a/src/rsn_supp/wpa_i.h b/src/rsn_supp/wpa_i.h +index 6cdce321d..3989c9ab3 100644 +--- a/src/rsn_supp/wpa_i.h ++++ b/src/rsn_supp/wpa_i.h +@@ -216,6 +216,7 @@ struct wpa_sm { + struct wpabuf *dpp_z; + int dpp_pfs; + #endif /* CONFIG_DPP2 */ ++ int suppress_deauth_no_pmksa; + }; + + +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0019-Fix-for-PMK-expiration-issue-through-supplicant.murata.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0019-Fix-for-PMK-expiration-issue-through-supplicant.murata.patch new file mode 100644 index 000000000..213edd2c2 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0019-Fix-for-PMK-expiration-issue-through-supplicant.murata.patch @@ -0,0 +1,121 @@ +From 5604eb8aaf8382376e6511850e70b66c6e2a22b8 Mon Sep 17 00:00:00 2001 +From: Kurt Lee +Date: Sun, 13 Feb 2022 21:34:09 -0600 +Subject: [PATCH 19/49] Fix for PMK expiration issue through supplicant + +Description : Sending Deauth from AP once PMK timeout occurs, So that +STA will initiate the Auth process. +Changes : 1) Added support to get the dot11RSNAConfigPMKLifetime conf +element in wpa_authenticator structure to pass to the lower API's +2) Sending deauth from the wpa_auth_pmksa_free_cb once PMK time out +occurs. +Tested: Confirmed once PMK timeout occurs AP is sending deauth and STA +starting AUTH frame. +--- + hostapd/config_file.c | 2 ++ + src/ap/ap_config.h | 2 ++ + src/ap/ieee802_11.c | 1 + + src/ap/wpa_auth.c | 9 ++++++++- + src/ap/wpa_auth.h | 1 + + src/ap/wpa_auth_i.h | 1 + + 6 files changed, 15 insertions(+), 1 deletion(-) + +diff --git a/hostapd/config_file.c b/hostapd/config_file.c +index b14728d1b..386499323 100644 +--- a/hostapd/config_file.c ++++ b/hostapd/config_file.c +@@ -3671,6 +3671,8 @@ static int hostapd_config_fill(struct hostapd_config *conf, + bss->max_listen_interval = atoi(pos); + } else if (os_strcmp(buf, "disable_pmksa_caching") == 0) { + bss->disable_pmksa_caching = atoi(pos); ++ } else if (os_strcmp(buf, "dot11RSNAConfigPMKLifetime") == 0) { ++ bss->dot11RSNAConfigPMKLifetime = atoi(pos); + } else if (os_strcmp(buf, "okc") == 0) { + bss->okc = atoi(pos); + #ifdef CONFIG_WPS +diff --git a/src/ap/ap_config.h b/src/ap/ap_config.h +index 49cd3168a..a82ca1853 100644 +--- a/src/ap/ap_config.h ++++ b/src/ap/ap_config.h +@@ -898,6 +898,8 @@ struct hostapd_bss_config { + u8 ext_capa[EXT_CAPA_MAX_LEN]; + + u8 rnr; ++ ++ unsigned int dot11RSNAConfigPMKLifetime; + }; + + /** +diff --git a/src/ap/ieee802_11.c b/src/ap/ieee802_11.c +index 3b735c09f..c4f7d00cc 100644 +--- a/src/ap/ieee802_11.c ++++ b/src/ap/ieee802_11.c +@@ -980,6 +980,7 @@ void sae_accept_sta(struct hostapd_data *hapd, struct sta_info *sta) + crypto_bignum_deinit(sta->sae->peer_commit_scalar_accepted, 0); + sta->sae->peer_commit_scalar_accepted = sta->sae->peer_commit_scalar; + sta->sae->peer_commit_scalar = NULL; ++ wpa_auth_set_pmk_life_time(hapd->wpa_auth,hapd->conf->dot11RSNAConfigPMKLifetime); + wpa_auth_pmksa_add_sae(hapd->wpa_auth, sta->addr, + sta->sae->pmk, sta->sae->pmkid); + #ifndef CONFIG_WPA3_SAE_AUTH_EARLY_SET +diff --git a/src/ap/wpa_auth.c b/src/ap/wpa_auth.c +index 4b506c1db..e92ea4302 100644 +--- a/src/ap/wpa_auth.c ++++ b/src/ap/wpa_auth.c +@@ -390,6 +390,7 @@ static void wpa_auth_pmksa_free_cb(struct rsn_pmksa_cache_entry *entry, + void *ctx) + { + struct wpa_authenticator *wpa_auth = ctx; ++ wpa_sta_disconnect(wpa_auth, entry->spa, WLAN_REASON_PREV_AUTH_NOT_VALID); + wpa_auth_for_each_sta(wpa_auth, wpa_auth_pmksa_clear_cb, entry); + } + +@@ -4835,6 +4836,12 @@ int wpa_auth_pmksa_add_preauth(struct wpa_authenticator *wpa_auth, + } + + ++void wpa_auth_set_pmk_life_time(struct wpa_authenticator *wpa_auth, unsigned int pmk_life_time) ++{ ++ wpa_auth->pmk_life_time = pmk_life_time; ++} ++ ++ + int wpa_auth_pmksa_add_sae(struct wpa_authenticator *wpa_auth, const u8 *addr, + const u8 *pmk, const u8 *pmkid) + { +@@ -4844,7 +4851,7 @@ int wpa_auth_pmksa_add_sae(struct wpa_authenticator *wpa_auth, const u8 *addr, + wpa_hexdump_key(MSG_DEBUG, "RSN: Cache PMK from SAE", pmk, PMK_LEN); + if (pmksa_cache_auth_add(wpa_auth->pmksa, pmk, PMK_LEN, pmkid, + NULL, 0, +- wpa_auth->addr, addr, 0, NULL, ++ wpa_auth->addr, addr, wpa_auth->pmk_life_time, NULL, + WPA_KEY_MGMT_SAE)) + return 0; + +diff --git a/src/ap/wpa_auth.h b/src/ap/wpa_auth.h +index ff36cfe95..fb456f07c 100644 +--- a/src/ap/wpa_auth.h ++++ b/src/ap/wpa_auth.h +@@ -426,6 +426,7 @@ int wpa_auth_pmksa_add_preauth(struct wpa_authenticator *wpa_auth, + struct eapol_state_machine *eapol); + int wpa_auth_pmksa_add_sae(struct wpa_authenticator *wpa_auth, const u8 *addr, + const u8 *pmk, const u8 *pmkid); ++void wpa_auth_set_pmk_life_time(struct wpa_authenticator *wpa_auth, unsigned int pmk_life_time); + void wpa_auth_add_sae_pmkid(struct wpa_state_machine *sm, const u8 *pmkid); + int wpa_auth_pmksa_add2(struct wpa_authenticator *wpa_auth, const u8 *addr, + const u8 *pmk, size_t pmk_len, const u8 *pmkid, +diff --git a/src/ap/wpa_auth_i.h b/src/ap/wpa_auth_i.h +index a6dc1a591..f46bdabdd 100644 +--- a/src/ap/wpa_auth_i.h ++++ b/src/ap/wpa_auth_i.h +@@ -237,6 +237,7 @@ struct wpa_authenticator { + #ifdef CONFIG_P2P + struct bitfield *ip_pool; + #endif /* CONFIG_P2P */ ++ unsigned int pmk_life_time; + }; + + +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0024-Deauthenticate-STA-only-if-PMK-expired.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0021-Avoid-deauthenticating-STA-if-the-reason-for-freeing.patch similarity index 60% rename from meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0024-Deauthenticate-STA-only-if-PMK-expired.patch rename to meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0021-Avoid-deauthenticating-STA-if-the-reason-for-freeing.patch index 8fe287040..bb1b85bf7 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0024-Deauthenticate-STA-only-if-PMK-expired.patch +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0021-Avoid-deauthenticating-STA-if-the-reason-for-freeing.patch @@ -1,39 +1,50 @@ -From: Kurt Lee -Date: Mon, 28 Mar 2022 03:53:29 -0500 -Subject: [PATCH] Deauthenticate STA only if PMK expired +From ed487600a81fa99688201a50176072555c90e690 Mon Sep 17 00:00:00 2001 +From: Gokul Sivakumar +Date: Mon, 25 Apr 2022 18:35:14 +0530 +Subject: [PATCH 21/49] Avoid deauthenticating STA if the reason for freeing + PMK entry isn't expiry + +The PMK cache entry for a STA in the SoftAP managed by wpa_supplicant +can be freed in multiple scenarios like when a new PMK is created after +reconnection or when the the PMK Life time is expired, etc. + +So avoid sending Deauth to the STA when freeing the PMK cache entry for a +specific STA in the SoftAP when attempting to replace it with a new PMK +cache entry derived as part of STA reconnection. Doing this lets the STA +reconnect to the SoftAP successfully after tearing down the connection +because of configured PMK Life time getting expired in the STA. And send +Deauth to STA only when the reason for freeing PMK cache entry is that the +configured PMK Life time got expired in the SoftAP. + +The PMKSA free reasons PMK_FREE, PMK_REPLACE and PMK_EXPIRE are introduced +for SoftAP to be consistent with the PMKSA reasons defined for STA mode in +src/rsn_supp/pmksa_cache.h + + -Porting from commit 6aaac006af7fd39d618c6546939bed9f0f0cea37 -which acts on hostapd. Don't deauthenticate STA when PMK is freed or -replaced --- - src/ap/pmksa_cache_auth.c | 22 ++++++++++++---------- + src/ap/pmksa_cache_auth.c | 22 +++++++++++++--------- src/ap/pmksa_cache_auth.h | 12 ++++++++++-- - src/ap/wpa_auth.c | 7 ++++--- - 3 files changed, 26 insertions(+), 15 deletions(-) + src/ap/wpa_auth.c | 15 ++++++++++++--- + 3 files changed, 35 insertions(+), 14 deletions(-) diff --git a/src/ap/pmksa_cache_auth.c b/src/ap/pmksa_cache_auth.c -index b67b8522e..8c733cde0 100644 +index b67b8522e..5084dfa13 100644 --- a/src/ap/pmksa_cache_auth.c +++ b/src/ap/pmksa_cache_auth.c -@@ -26,11 +26,12 @@ struct rsn_pmksa_cache { - #define PMKID_HASH(pmkid) (unsigned int) ((pmkid)[0] & 0x7f) - struct rsn_pmksa_cache_entry *pmkid[PMKID_HASH_SIZE]; +@@ -28,7 +28,8 @@ struct rsn_pmksa_cache { struct rsn_pmksa_cache_entry *pmksa; int pmksa_count; - + - void (*free_cb)(struct rsn_pmksa_cache_entry *entry, void *ctx); + void (*free_cb)(struct rsn_pmksa_cache_entry *entry, void *ctx, + enum pmksa_free_reason reason); void *ctx; }; - - - static void pmksa_cache_set_expiration(struct rsn_pmksa_cache *pmksa); -@@ -47,17 +48,18 @@ static void _pmksa_cache_free_entry(struct rsn_pmksa_cache_entry *entry) - bin_clear_free(entry, sizeof(*entry)); - } - - + +@@ -49,13 +50,14 @@ static void _pmksa_cache_free_entry(struct rsn_pmksa_cache_entry *entry) + + void pmksa_cache_free_entry(struct rsn_pmksa_cache *pmksa, - struct rsn_pmksa_cache_entry *entry) + struct rsn_pmksa_cache_entry *entry, @@ -41,18 +52,14 @@ index b67b8522e..8c733cde0 100644 { struct rsn_pmksa_cache_entry *pos, *prev; unsigned int hash; - + pmksa->pmksa_count--; - pmksa->free_cb(entry, pmksa->ctx); + pmksa->free_cb(entry, pmksa->ctx, reason); - + /* unlink from hash list */ hash = PMKID_HASH(entry->pmkid); - pos = pmksa->pmkid[hash]; - prev = NULL; -@@ -99,11 +101,11 @@ void pmksa_cache_free_entry(struct rsn_pmksa_cache *pmksa, - void pmksa_cache_auth_flush(struct rsn_pmksa_cache *pmksa) - { +@@ -101,7 +103,7 @@ void pmksa_cache_auth_flush(struct rsn_pmksa_cache *pmksa) while (pmksa->pmksa) { wpa_printf(MSG_DEBUG, "RSN: Flush PMKSA cache entry for " MACSTR, MAC2STR(pmksa->pmksa->spa)); @@ -60,37 +67,26 @@ index b67b8522e..8c733cde0 100644 + pmksa_cache_free_entry(pmksa, pmksa->pmksa, PMKSA_FREE); } } - - - static void pmksa_cache_expire(void *eloop_ctx, void *timeout_ctx) -@@ -113,17 +115,16 @@ static void pmksa_cache_expire(void *eloop_ctx, void *timeout_ctx) - + +@@ -113,9 +115,10 @@ static void pmksa_cache_expire(void *eloop_ctx, void *timeout_ctx) + os_get_reltime(&now); while (pmksa->pmksa && pmksa->pmksa->expiration <= now.sec) { ++ struct rsn_pmksa_cache_entry *entry = pmksa->pmksa; wpa_printf(MSG_DEBUG, "RSN: expired PMKSA cache entry for " MACSTR, MAC2STR(pmksa->pmksa->spa)); - pmksa_cache_free_entry(pmksa, pmksa->pmksa); -+ pmksa_cache_free_entry(pmksa, pmksa->pmksa, PMKSA_EXPIRE); ++ pmksa_cache_free_entry(pmksa, entry, PMKSA_EXPIRE); } - + pmksa_cache_set_expiration(pmksa); - } - -- - static void pmksa_cache_set_expiration(struct rsn_pmksa_cache *pmksa) - { - int sec; - struct os_reltime now; - -@@ -372,18 +373,18 @@ int pmksa_cache_auth_add_entry(struct rsn_pmksa_cache *pmksa, - - /* Replace an old entry for the same STA (if found) with the new entry +@@ -374,14 +377,14 @@ int pmksa_cache_auth_add_entry(struct rsn_pmksa_cache *pmksa, */ pos = pmksa_cache_auth_get(pmksa, entry->spa, NULL); if (pos) - pmksa_cache_free_entry(pmksa, pos); + pmksa_cache_free_entry(pmksa, pos, PMKSA_REPLACE); - + if (pmksa->pmksa_count >= pmksa_cache_max_entries && pmksa->pmksa) { /* Remove the oldest entry to make room for the new entry */ wpa_printf(MSG_DEBUG, "RSN: removed the oldest PMKSA cache " @@ -99,13 +95,9 @@ index b67b8522e..8c733cde0 100644 - pmksa_cache_free_entry(pmksa, pmksa->pmksa); + pmksa_cache_free_entry(pmksa, pmksa->pmksa, PMKSA_FREE); } - + pmksa_cache_link_entry(pmksa, entry); - - return 0; -@@ -537,11 +538,12 @@ struct rsn_pmksa_cache_entry * pmksa_cache_get_okc( - * @ctx: Context pointer for free_cb function - * Returns: Pointer to PMKSA cache data or %NULL on failure +@@ -539,7 +542,8 @@ struct rsn_pmksa_cache_entry * pmksa_cache_get_okc( */ struct rsn_pmksa_cache * pmksa_cache_auth_init(void (*free_cb)(struct rsn_pmksa_cache_entry *entry, @@ -114,12 +106,8 @@ index b67b8522e..8c733cde0 100644 + void *ctx) { struct rsn_pmksa_cache *pmksa; - - pmksa = os_zalloc(sizeof(*pmksa)); - if (pmksa) { -@@ -611,11 +613,11 @@ int pmksa_cache_auth_radius_das_disconnect(struct rsn_pmksa_cache *pmksa, - while (entry) { - if (das_attr_match(entry, attr)) { + +@@ -613,7 +617,7 @@ int pmksa_cache_auth_radius_das_disconnect(struct rsn_pmksa_cache *pmksa, found++; prev = entry; entry = entry->next; @@ -128,27 +116,20 @@ index b67b8522e..8c733cde0 100644 continue; } entry = entry->next; - } - diff --git a/src/ap/pmksa_cache_auth.h b/src/ap/pmksa_cache_auth.h -index 2ef217435..9c942024d 100644 +index 2ef217435..ed532dd2e 100644 --- a/src/ap/pmksa_cache_auth.h +++ b/src/ap/pmksa_cache_auth.h -@@ -32,16 +32,23 @@ struct rsn_pmksa_cache_entry { - int opportunistic; - - u64 acct_multi_session_id; - }; - +@@ -37,9 +37,16 @@ struct rsn_pmksa_cache_entry { + struct rsn_pmksa_cache; + struct radius_das_attrs; + +enum pmksa_free_reason { + PMKSA_FREE, + PMKSA_REPLACE, + PMKSA_EXPIRE, +}; + - struct rsn_pmksa_cache; - struct radius_das_attrs; - struct rsn_pmksa_cache * pmksa_cache_auth_init(void (*free_cb)(struct rsn_pmksa_cache_entry *entry, - void *ctx), void *ctx); @@ -157,11 +138,7 @@ index 2ef217435..9c942024d 100644 void pmksa_cache_auth_deinit(struct rsn_pmksa_cache *pmksa); struct rsn_pmksa_cache_entry * pmksa_cache_auth_get(struct rsn_pmksa_cache *pmksa, - const u8 *spa, const u8 *pmkid); - struct rsn_pmksa_cache_entry * pmksa_cache_get_okc( -@@ -66,11 +73,12 @@ pmksa_cache_add_okc(struct rsn_pmksa_cache *pmksa, - const u8 *aa, const u8 *pmkid); - void pmksa_cache_to_eapol_data(struct hostapd_data *hapd, +@@ -68,7 +75,8 @@ void pmksa_cache_to_eapol_data(struct hostapd_data *hapd, struct rsn_pmksa_cache_entry *entry, struct eapol_state_machine *eapol); void pmksa_cache_free_entry(struct rsn_pmksa_cache *pmksa, @@ -171,33 +148,33 @@ index 2ef217435..9c942024d 100644 int pmksa_cache_auth_radius_das_disconnect(struct rsn_pmksa_cache *pmksa, struct radius_das_attrs *attr); int pmksa_cache_auth_list(struct rsn_pmksa_cache *pmksa, char *buf, size_t len); - void pmksa_cache_auth_flush(struct rsn_pmksa_cache *pmksa); - int pmksa_cache_auth_list_mesh(struct rsn_pmksa_cache *pmksa, const u8 *addr, diff --git a/src/ap/wpa_auth.c b/src/ap/wpa_auth.c -index e92ea4302..36ab7e5b5 100644 +index e92ea4302..9917c13e8 100644 --- a/src/ap/wpa_auth.c +++ b/src/ap/wpa_auth.c -@@ -385,14 +385,15 @@ static int wpa_auth_pmksa_clear_cb(struct wpa_state_machine *sm, void *ctx) - return 0; - } - - +@@ -387,10 +387,19 @@ static int wpa_auth_pmksa_clear_cb(struct wpa_state_machine *sm, void *ctx) + + static void wpa_auth_pmksa_free_cb(struct rsn_pmksa_cache_entry *entry, - void *ctx) + void *ctx, enum pmksa_free_reason reason) { struct wpa_authenticator *wpa_auth = ctx; - wpa_sta_disconnect(wpa_auth, entry->spa, WLAN_REASON_PREV_AUTH_NOT_VALID); -+ if (reason == PMKSA_EXPIRE) ++ ++ if (reason == PMKSA_EXPIRE) { ++ /* ++ * Once when the PMK cache entry for a STA expires in the SoftAP, ++ * send a deauth to the STA from the SoftAP to make the STA reconnect ++ * to the network and derive a new PMK. ++ */ + wpa_sta_disconnect(wpa_auth, entry->spa, WLAN_REASON_PREV_AUTH_NOT_VALID); ++ } ++ wpa_auth_for_each_sta(wpa_auth, wpa_auth_pmksa_clear_cb, entry); } - - - static int wpa_group_init_gmk_and_counter(struct wpa_authenticator *wpa_auth, -@@ -4892,11 +4893,11 @@ void wpa_auth_pmksa_remove(struct wpa_authenticator *wpa_auth, - return; - pmksa = pmksa_cache_auth_get(wpa_auth->pmksa, sta_addr, NULL); + +@@ -4894,7 +4903,7 @@ void wpa_auth_pmksa_remove(struct wpa_authenticator *wpa_auth, if (pmksa) { wpa_printf(MSG_DEBUG, "WPA: Remove PMKSA cache entry for " MACSTR " based on request", MAC2STR(sta_addr)); @@ -205,6 +182,7 @@ index e92ea4302..36ab7e5b5 100644 + pmksa_cache_free_entry(wpa_auth->pmksa, pmksa, PMKSA_FREE); } } + +-- +2.17.1 - - int wpa_auth_pmksa_list(struct wpa_authenticator *wpa_auth, char *buf, diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0022-wpa_supplicant-support-bgscan.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0022-wpa_supplicant-support-bgscan.patch new file mode 100644 index 000000000..6899b06f4 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0022-wpa_supplicant-support-bgscan.patch @@ -0,0 +1,32 @@ +From cfa528ffe320ac638ca72e87751f76444669c48e Mon Sep 17 00:00:00 2001 +From: Ian Lin +Date: Fri, 20 May 2022 03:00:37 -0500 +Subject: [PATCH 22/49] wpa_supplicant: support bgscan + +Modify defconfig_base to support bgscan feature + +Signed-off-by: Ian Lin +--- + wpa_supplicant/defconfig_base | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base +index 99c74853d..4f71b50ff 100644 +--- a/wpa_supplicant/defconfig_base ++++ b/wpa_supplicant/defconfig_base +@@ -601,10 +601,10 @@ CONFIG_P2P=y + # operations for roaming within an ESS (same SSID). See the bgscan parameter in + # the wpa_supplicant.conf file for more details. + # Periodic background scans based on signal strength +-#CONFIG_BGSCAN_SIMPLE=y ++CONFIG_BGSCAN_SIMPLE=y + # Learn channels used by the network and try to avoid bgscans on other + # channels (experimental) +-#CONFIG_BGSCAN_LEARN=y ++CONFIG_BGSCAN_LEARN=y + + # Opportunistic Wireless Encryption (OWE) + # Experimental implementation of draft-harkins-owe-07.txt +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0023-non-upstream-wl-cmd-create-interface-to-support-driv.murata.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0023-non-upstream-wl-cmd-create-interface-to-support-driv.murata.patch new file mode 100644 index 000000000..066799a9f --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0023-non-upstream-wl-cmd-create-interface-to-support-driv.murata.patch @@ -0,0 +1,846 @@ +From 1cfe2ac93a1b50a6fd2f6d0022ece6e0f2a91259 Mon Sep 17 00:00:00 2001 +From: Kurt Lee +Date: Sun, 10 Apr 2022 22:10:51 -0500 +Subject: [PATCH 23/49] non-upstream: wl-cmd: create interface to support + driver priv command + +1. Create "wl" command interface to set/get driver information +2. Create files and compile flag to separate this feature +3. Support 2g_rate/5g_rate command + +Signed-off-by: Ian Lin +Signed-off-by: Kurt Lee +--- + hostapd/ctrl_iface.c | 20 +++ + hostapd/defconfig_base | 2 + + hostapd/hostapd_cli.c | 11 ++ + src/ap/ap_drv_ops.h | 10 ++ + src/common/brcm_wl_ioctl.h | 10 ++ + src/common/brcm_wl_ioctl_defs.h | 15 ++ + src/common/brcm_wl_rspec.h | 104 +++++++++++ + src/drivers/driver.h | 1 + + src/drivers/driver_brcm_nl80211.h | 26 +++ + src/drivers/driver_brcm_wlu.c | 289 ++++++++++++++++++++++++++++++ + src/drivers/driver_brcm_wlu.h | 12 ++ + src/drivers/driver_nl80211.c | 149 +++++++++++++++ + src/drivers/drivers.mak | 5 + + wpa_supplicant/defconfig_base | 2 + + 14 files changed, 655 insertions(+) + create mode 100644 src/common/brcm_wl_ioctl.h + create mode 100644 src/common/brcm_wl_ioctl_defs.h + create mode 100644 src/common/brcm_wl_rspec.h + create mode 100644 src/drivers/driver_brcm_nl80211.h + create mode 100644 src/drivers/driver_brcm_wlu.c + create mode 100644 src/drivers/driver_brcm_wlu.h + +diff --git a/hostapd/ctrl_iface.c b/hostapd/ctrl_iface.c +index 86adf18e5..ec1a2d1e3 100644 +--- a/hostapd/ctrl_iface.c ++++ b/hostapd/ctrl_iface.c +@@ -3499,6 +3499,21 @@ static int hostapd_ctrl_iface_driver_cmd(struct hostapd_data *hapd, char *cmd, + } + #endif /* ANDROID */ + ++#ifdef CONFIG_DRIVER_BRCM_WL ++static int hostapd_ctrl_iface_wl_cmd(struct hostapd_data *hapd, char *cmd, ++ char *buf, size_t buflen) ++{ ++ int ret; ++ ++ ret = hostapd_drv_wl_cmd(hapd, cmd, buf, buflen); ++ if (ret == 0) { ++ ret = os_snprintf(buf, buflen, "%s\n", "OK"); ++ if (os_snprintf_error(buflen, ret)) ++ ret = -1; ++ } ++ return ret; ++} ++#endif /* CONFIG_DRIVER_BRCM_WL */ + + static int hostapd_ctrl_iface_receive_process(struct hostapd_data *hapd, + char *buf, char *reply, +@@ -4016,6 +4031,11 @@ static int hostapd_ctrl_iface_receive_process(struct hostapd_data *hapd, + reply_len = hostapd_ctrl_iface_driver_cmd(hapd, buf + 7, reply, + reply_size); + #endif /* ANDROID */ ++#ifdef CONFIG_DRIVER_BRCM_WL ++ } else if (os_strncmp(buf, "WL ", 3) == 0) { ++ reply_len = hostapd_ctrl_iface_wl_cmd(hapd, buf + 3, reply, ++ reply_size); ++#endif /* CONFIG_DRIVER_BRCM_WL */ + } else { + os_memcpy(reply, "UNKNOWN COMMAND\n", 16); + reply_len = 16; +diff --git a/hostapd/defconfig_base b/hostapd/defconfig_base +index dafcf0f6c..4e4f0f784 100644 +--- a/hostapd/defconfig_base ++++ b/hostapd/defconfig_base +@@ -21,6 +21,8 @@ CONFIG_DRIVER_NL80211=y + # QCA vendor extensions to nl80211 + #CONFIG_DRIVER_NL80211_QCA=y + ++CONFIG_DRIVER_BRCM_WL=y ++ + # driver_nl80211.c requires libnl. If you are compiling it yourself + # you may need to point hostapd to your version of libnl. + # +diff --git a/hostapd/hostapd_cli.c b/hostapd/hostapd_cli.c +index 260912111..9ab2342c9 100644 +--- a/hostapd/hostapd_cli.c ++++ b/hostapd/hostapd_cli.c +@@ -1549,6 +1549,13 @@ static int hostapd_cli_cmd_driver(struct wpa_ctrl *ctrl, int argc, char *argv[]) + #endif /* ANDROID */ + + ++#ifdef CONFIG_DRIVER_BRCM_WL ++static int hostapd_cli_cmd_wl(struct wpa_ctrl *ctrl, int argc, char *argv[]) ++{ ++ return hostapd_cli_cmd(ctrl, "WL", 1, argc, argv); ++} ++#endif /* CONFIG_DRIVER_BRCM_WL */ ++ + struct hostapd_cli_cmd { + const char *cmd; + int (*handler)(struct wpa_ctrl *ctrl, int argc, char *argv[]); +@@ -1744,6 +1751,10 @@ static const struct hostapd_cli_cmd hostapd_cli_commands[] = { + { "driver", hostapd_cli_cmd_driver, NULL, + " [] = send driver command data" }, + #endif /* ANDROID */ ++#ifdef CONFIG_DRIVER_BRCM_WL ++ { "wl", hostapd_cli_cmd_wl, NULL, ++ " [] = send brcm wl command data" }, ++#endif /* CONFIG_DRIVER_BRCM_WL */ + { NULL, NULL, NULL, NULL } + }; + +diff --git a/src/ap/ap_drv_ops.h b/src/ap/ap_drv_ops.h +index 61c8f64eb..5bf092c46 100644 +--- a/src/ap/ap_drv_ops.h ++++ b/src/ap/ap_drv_ops.h +@@ -403,6 +403,16 @@ static inline int hostapd_drv_driver_cmd(struct hostapd_data *hapd, + } + #endif /* ANDROID */ + ++#ifdef CONFIG_DRIVER_BRCM_WL ++static inline int hostapd_drv_wl_cmd(struct hostapd_data *hapd, ++ char *cmd, char *buf, size_t buf_len) ++{ ++ if (!hapd->driver->wl_cmd) ++ return -1; ++ return hapd->driver->wl_cmd(hapd->drv_priv, cmd, buf, buf_len); ++} ++#endif /* CONFIG_DRIVER_BRCM_WL */ ++ + #ifdef CONFIG_TESTING_OPTIONS + static inline int + hostapd_drv_register_frame(struct hostapd_data *hapd, u16 type, +diff --git a/src/common/brcm_wl_ioctl.h b/src/common/brcm_wl_ioctl.h +new file mode 100644 +index 000000000..768b78616 +--- /dev/null ++++ b/src/common/brcm_wl_ioctl.h +@@ -0,0 +1,10 @@ ++/* ++ * Broadcom Corporation OUI and vendor specific assignments ++ * Copyright (c) 2020, Broadcom Corporation. ++ * ++ * This software may be distributed under the terms of the BSD license. ++ * See README for more details. ++ */ ++ ++#include "common/brcm_wl_ioctl_defs.h" ++#include "common/brcm_wl_rspec.h" +diff --git a/src/common/brcm_wl_ioctl_defs.h b/src/common/brcm_wl_ioctl_defs.h +new file mode 100644 +index 000000000..1834be6fa +--- /dev/null ++++ b/src/common/brcm_wl_ioctl_defs.h +@@ -0,0 +1,15 @@ ++/* ++ * Broadcom Corporation OUI and vendor specific assignments ++ * Copyright (c) 2020, Broadcom Corporation. ++ * ++ * This software may be distributed under the terms of the BSD license. ++ * See README for more details. ++ */ ++ ++#define WLC_IOCTL_SMLEN 256 /* "small" length ioctl buffer required */ ++#define WLC_IOCTL_MEDLEN 1896 /* "med" length ioctl buffer required */ ++ ++/* common ioctl definitions */ ++#define WLC_GET_VAR 262 /* get value of named variable */ ++#define WLC_SET_VAR 263 /* set named variable to value */ ++ +diff --git a/src/common/brcm_wl_rspec.h b/src/common/brcm_wl_rspec.h +new file mode 100644 +index 000000000..d10e82597 +--- /dev/null ++++ b/src/common/brcm_wl_rspec.h +@@ -0,0 +1,104 @@ ++/* ++ * Broadcom Corporation OUI and vendor specific assignments ++ * Copyright (c) 2020, Broadcom Corporation. ++ * ++ * This software may be distributed under the terms of the BSD license. ++ * See README for more details. ++ */ ++ ++/* Rate spec. definitions */ ++#define WL_RSPEC_RATE_MASK 0x000000FF /**< Legacy rate or MCS or MCS + NSS */ ++#define WL_RSPEC_TXEXP_MASK 0x00000300 /**< Tx chain expansion beyond Nsts */ ++#define WL_RSPEC_TXEXP_SHIFT 8 ++#define WL_RSPEC_HE_GI_MASK 0x00000C00 /* HE GI indices */ ++#define WL_RSPEC_HE_GI_SHIFT 10 ++#define WL_RSPEC_BW_MASK 0x00070000 /**< Band width */ ++#define WL_RSPEC_BW_SHIFT 16 ++#define WL_RSPEC_ER_MASK 0x0000C000 /**< Range extension mask */ ++#define WL_RSPEC_ER_SHIFT 14 ++#define WL_RSPEC_ER_ENAB_MASK 0x00008000 /**< Range extension enable */ ++#define WL_RSPEC_ER_ENAB_SHIFT 15 ++#define WL_RSPEC_ER_TONE_MASK 0x00004000 /**< Range extension tone config */ ++#define WL_RSPEC_ER_TONE_SHIFT 14 ++ ++#define WL_RSPEC_DCM 0x00080000 /**< Dual Carrier Modulation */ ++#define WL_RSPEC_DCM_SHIFT 19 ++#define WL_RSPEC_STBC 0x00100000 /**< STBC expansion, Nsts = 2 * Nss */ ++#define WL_RSPEC_TXBF 0x00200000 ++#define WL_RSPEC_LDPC 0x00400000 ++#define WL_RSPEC_SGI 0x00800000 ++#define WL_RSPEC_SHORT_PREAMBLE 0x00800000 /**< DSSS short preable - Encoding 0 */ ++#define WL_RSPEC_ENCODING_MASK 0x03000000 /**< Encoding of RSPEC_RATE field */ ++#define WL_RSPEC_ENCODING_SHIFT 24 ++ ++#define WL_RSPEC_OVERRIDE_RATE 0x40000000 /**< override rate only */ ++#define WL_RSPEC_OVERRIDE_MODE 0x80000000 /**< override both rate & mode */ ++ ++/* ======== RSPEC_HE_GI|RSPEC_SGI fields for HE ======== */ ++ ++/* GI for HE */ ++#define RSPEC_HE_LTF_GI(rspec) (((rspec) & WL_RSPEC_HE_GI_MASK) >> WL_RSPEC_HE_GI_SHIFT) ++#define WL_RSPEC_HE_1x_LTF_GI_0_8us (0x0) ++#define WL_RSPEC_HE_2x_LTF_GI_0_8us (0x1) ++#define WL_RSPEC_HE_2x_LTF_GI_1_6us (0x2) ++#define WL_RSPEC_HE_4x_LTF_GI_3_2us (0x3) ++#define RSPEC_ISHEGI(rspec) (RSPEC_HE_LTF_GI(rspec) > WL_RSPEC_HE_1x_LTF_GI_0_8us) ++#define HE_GI_TO_RSPEC(gi) (((gi) << WL_RSPEC_HE_GI_SHIFT) & WL_RSPEC_HE_GI_MASK) ++ ++/* RSPEC Macros for extracting and using HE-ER and DCM */ ++#define RSPEC_HE_DCM(rspec) (((rspec) & WL_RSPEC_DCM) >> WL_RSPEC_DCM_SHIFT) ++#define RSPEC_HE_ER(rspec) (((rspec) & WL_RSPEC_ER_MASK) >> WL_RSPEC_ER_SHIFT) ++#define RSPEC_HE_ER_ENAB(rspec) (((rspec) & WL_RSPEC_ER_ENAB_MASK) >> \ ++ WL_RSPEC_ER_ENAB_SHIFT) ++#define RSPEC_HE_ER_TONE(rspec) (((rspec) & WL_RSPEC_ER_TONE_MASK) >> \ ++ WL_RSPEC_ER_TONE_SHIFT) ++/* ======== RSPEC_RATE field ======== */ ++ ++/* Encoding 0 - legacy rate */ ++/* DSSS, CCK, and OFDM rates in [500kbps] units */ ++#define WL_RSPEC_LEGACY_RATE_MASK 0x0000007F ++#define WLC_RATE_1M 2 ++#define WLC_RATE_2M 4 ++#define WLC_RATE_5M5 11 ++#define WLC_RATE_11M 22 ++#define WLC_RATE_6M 12 ++#define WLC_RATE_9M 18 ++#define WLC_RATE_12M 24 ++#define WLC_RATE_18M 36 ++#define WLC_RATE_24M 48 ++#define WLC_RATE_36M 72 ++#define WLC_RATE_48M 96 ++#define WLC_RATE_54M 108 ++ ++/* Encoding 1 - HT MCS */ ++#define WL_RSPEC_HT_MCS_MASK 0x0000007F /**< HT MCS value mask in rspec */ ++ ++/* Encoding 2 - VHT MCS + NSS */ ++#define WL_RSPEC_VHT_MCS_MASK 0x0000000F /**< VHT MCS value mask in rspec */ ++#define WL_RSPEC_VHT_NSS_MASK 0x000000F0 /**< VHT Nss value mask in rspec */ ++#define WL_RSPEC_VHT_NSS_SHIFT 4 /**< VHT Nss value shift in rspec */ ++ ++/* Encoding 3 - HE MCS + NSS */ ++#define WL_RSPEC_HE_MCS_MASK 0x0000000F /**< HE MCS value mask in rspec */ ++#define WL_RSPEC_HE_NSS_MASK 0x000000F0 /**< HE Nss value mask in rspec */ ++#define WL_RSPEC_HE_NSS_SHIFT 4 /**< HE Nss value shift in rpsec */ ++ ++/* ======== RSPEC_BW field ======== */ ++ ++#define WL_RSPEC_BW_UNSPECIFIED 0 ++#define WL_RSPEC_BW_20MHZ 0x00010000 ++#define WL_RSPEC_BW_40MHZ 0x00020000 ++#define WL_RSPEC_BW_80MHZ 0x00030000 ++#define WL_RSPEC_BW_160MHZ 0x00040000 ++#define WL_RSPEC_BW_10MHZ 0x00050000 ++#define WL_RSPEC_BW_5MHZ 0x00060000 ++#define WL_RSPEC_BW_2P5MHZ 0x00070000 ++ ++/* ======== RSPEC_ENCODING field ======== */ ++ ++#define WL_RSPEC_ENCODE_RATE 0x00000000 /**< Legacy rate is stored in RSPEC_RATE */ ++#define WL_RSPEC_ENCODE_HT 0x01000000 /**< HT MCS is stored in RSPEC_RATE */ ++#define WL_RSPEC_ENCODE_VHT 0x02000000 /**< VHT MCS and NSS are stored in RSPEC_RATE */ ++#define WL_RSPEC_ENCODE_HE 0x03000000 /**< HE MCS and NSS are stored in RSPEC_RATE */ ++#define WL_RSPEC_HE_NSS_UNSPECIFIED 0xF ++ +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index fb3f8b4a8..3d48f6f07 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -3861,6 +3861,7 @@ struct wpa_driver_ops { + */ + int (*driver_cmd)(void *priv, char *cmd, char *buf, size_t buf_len); + #endif /* ANDROID */ ++ int (*wl_cmd)(void *priv, char *cmd, char *buf, size_t buf_len); + + /** + * vendor_cmd - Execute vendor specific command +diff --git a/src/drivers/driver_brcm_nl80211.h b/src/drivers/driver_brcm_nl80211.h +new file mode 100644 +index 000000000..40a84d125 +--- /dev/null ++++ b/src/drivers/driver_brcm_nl80211.h +@@ -0,0 +1,26 @@ ++/* ++ * Broadcom Corporation OUI and vendor specific assignments ++ * Copyright (c) 2020, Broadcom Corporation. ++ * ++ * This software may be distributed under the terms of the BSD license. ++ * See README for more details. ++ */ ++ ++struct bcm_nlmsg_hdr { ++ uint cmd; /* common ioctl definition */ ++ int len; /* expected return buffer length */ ++ uint offset; /* user buffer offset */ ++ uint set; /* get or set request optional */ ++ uint magic; /* magic number for verification */ ++}; ++ ++enum bcmnl_attrs { ++ BCM_NLATTR_UNSPEC, ++ ++ BCM_NLATTR_LEN, ++ BCM_NLATTR_DATA, ++ ++ __BCM_NLATTR_AFTER_LAST, ++ BCM_NLATTR_MAX = __BCM_NLATTR_AFTER_LAST - 1 ++}; ++ +diff --git a/src/drivers/driver_brcm_wlu.c b/src/drivers/driver_brcm_wlu.c +new file mode 100644 +index 000000000..f2264ebcc +--- /dev/null ++++ b/src/drivers/driver_brcm_wlu.c +@@ -0,0 +1,289 @@ ++/* ++ * Broadcom Corporation OUI and vendor specific assignments ++ * Copyright (c) 2020, Broadcom Corporation. ++ * ++ * This software may be distributed under the terms of the BSD license. ++ * See README for more details. ++ */ ++ ++#include "includes.h" ++#include "common.h" ++#include "common/brcm_vendor.h" ++#include "common/brcm_wl_ioctl.h" ++#include "common/wpa_common.h" ++ ++/* ++ * Format a ratespec for output of any of the wl_rate() iovars ++ */ ++char* ++wl_rate_print(char *rate_buf, size_t buf_len, u32 rspec) ++{ ++ uint encode, rate, txexp, bw_val; ++ const char* stbc; ++ const char* ldpc; ++ const char* bw; ++ const char* dcm; ++ const char* er; ++ u8 valid_encding = false; ++ ++ encode = (rspec & WL_RSPEC_ENCODING_MASK); ++ rate = (rspec & WL_RSPEC_RATE_MASK); ++ txexp = (rspec & WL_RSPEC_TXEXP_MASK) >> WL_RSPEC_TXEXP_SHIFT; ++ bw_val = (rspec & WL_RSPEC_BW_MASK); ++ stbc = ((rspec & WL_RSPEC_STBC) != 0) ? " stbc" : ""; ++ ldpc = ((rspec & WL_RSPEC_LDPC) != 0) ? " ldpc" : ""; ++ dcm = ((rspec & WL_RSPEC_DCM) != 0) ? " dcm" : ""; ++ ++ if (RSPEC_HE_ER_ENAB(rspec) != 0) { ++ er = RSPEC_HE_ER_TONE(rspec) ? " er 106" : " er 242"; ++ } else { ++ er = ""; ++ } ++ ++ if (bw_val == WL_RSPEC_BW_UNSPECIFIED) { ++ bw = "auto"; ++ } else if (bw_val == WL_RSPEC_BW_20MHZ) { ++ bw = "20"; ++ } else if (bw_val == WL_RSPEC_BW_40MHZ) { ++ bw = "40"; ++ } else if (bw_val == WL_RSPEC_BW_80MHZ) { ++ bw = "80"; ++ } else if (bw_val == WL_RSPEC_BW_160MHZ) { ++ bw = "160"; ++ } else if (bw_val == WL_RSPEC_BW_10MHZ) { ++ bw = "10"; ++ } else if (bw_val == WL_RSPEC_BW_5MHZ) { ++ bw = "5"; ++ } else if (bw_val == WL_RSPEC_BW_2P5MHZ) { ++ bw = "2.5"; ++ } else { ++ bw = "???"; ++ } ++ ++ if ((rspec & ~WL_RSPEC_TXEXP_MASK) == 0) { /* Ignore TxExpansion for NULL rspec check */ ++ valid_encding = true; ++ os_snprintf(rate_buf, buf_len, "auto"); ++ } else if (encode == WL_RSPEC_ENCODE_HE) { ++ const char* gi_ltf[] = {" 1xLTF GI 0.8us", " 2xLTF GI 0.8us", ++ " 2xLTF GI 1.6us", " 4xLTF GI 3.2us"}; ++ u8 gi_int = RSPEC_HE_LTF_GI(rspec); ++ uint mcs = (rspec & WL_RSPEC_HE_MCS_MASK); ++ uint Nss = (rspec & WL_RSPEC_HE_NSS_MASK) >> WL_RSPEC_HE_NSS_SHIFT; ++ ++ valid_encding = true; ++ ++ os_snprintf(rate_buf, buf_len, "he mcs %d Nss %d Tx Exp %d BW %s%s%s%s%s%s", ++ mcs, Nss, txexp, bw, stbc, ldpc, gi_ltf[gi_int], dcm, er); ++ ++ } else { ++ const char* sgi; ++ sgi = ((rspec & WL_RSPEC_SGI) != 0) ? " sgi" : ""; ++ if (encode == WL_RSPEC_ENCODE_RATE) { ++ ++ valid_encding = true; ++ ++ os_snprintf(rate_buf, buf_len, "rate %d%s Mbps Tx Exp %d", ++ rate/2, (rate % 2)?".5":"", txexp); ++ } else if (encode == WL_RSPEC_ENCODE_HT) { ++ ++ valid_encding = true; ++ ++ os_snprintf(rate_buf, buf_len, "ht mcs %d Tx Exp %d BW %s%s%s%s", ++ rate, txexp, bw, stbc, ldpc, sgi); ++ } else if (encode == WL_RSPEC_ENCODE_VHT) { ++ uint mcs = (rspec & WL_RSPEC_VHT_MCS_MASK); ++ uint Nss = (rspec & WL_RSPEC_VHT_NSS_MASK) >> WL_RSPEC_VHT_NSS_SHIFT; ++ ++ valid_encding = true; ++ ++ os_snprintf(rate_buf, buf_len, "vht mcs %d Nss %d Tx Exp %d BW %s%s%s%s", ++ mcs, Nss, txexp, bw, stbc, ldpc, sgi); ++ } ++ } ++ ++ if (!valid_encding) { ++ os_snprintf(rate_buf, buf_len, "", rspec); ++ } ++ ++ return rate_buf; ++} ++ ++ ++/* parse the -v/--vht or -c argument for the wl_rate() command. ++ * return FALSE if the arg does not look like MxS or cMsS, where M and S are single digits ++ * return TRUE if the arg does look like MxS or cMsS, setting mcsp to M, and nssp to S ++ */ ++//static int ++int ++wl_parse_he_vht_spec(const char* cp, int* mcsp, int* nssp) ++{ ++ char *startp, *endp; ++ char c; ++ int mcs, nss; ++ char sx; ++ ++ if (cp == NULL || cp[0] == '\0') { ++ return false; ++ } ++ ++ if (cp[0] == 'c') { ++ startp = (char*)cp + 1; ++ sx = 's'; ++ } ++ else { ++ startp = (char*)cp; ++ sx = 'x'; ++ } ++ ++ mcs = (int)strtol(startp, &endp, 10); ++ /* verify MCS 0-11, and next char is 's' or 'x' */ ++ /* HE MCS is 0-11, VHT MCS 0-9 and prop MCS 10-11 */ ++ if (mcs < 0 || mcs > 11 || endp[0] != sx) { ++ return false; ++ } ++ ++ /* grab the char after the 'x'/'s' and convert to value */ ++ c = endp[1]; ++ nss = 0; ++ if (isdigit((int)c)) { ++ nss = c - '0'; ++ } ++ ++ /* consume trailing space after digit */ ++ cp = &endp[2]; ++ while (isspace((int)(*cp))) { ++ cp++; ++ } ++ ++ /* check for trailing garbage after digit */ ++ if (cp[0] != '\0') { ++ return false; ++ } ++ ++ if (nss < 1 || nss > 8) { ++ return false; ++ } ++ ++ *mcsp = mcs; ++ *nssp = nss; ++ ++ return true; ++} ++ ++ ++int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len) ++{ ++ int ret = -1; ++ char *pos; ++ //bool legacy_set = false, ht_set = false, vht_set = false, he_set = false; ++ bool he_set = false; ++ int rate, mcs, Nss, tx_exp, bw; ++ bool stbc, ldpc, sgi, dcm, er; ++ u8 hegi; ++ ++ u32 rspec = 0; ++ int val_int = 0; ++ char *endp; ++ ++ /* set default values */ ++ rate = 0; ++ mcs = 0; ++ Nss = 0; ++ tx_exp = 0; ++ stbc = false; ++ ldpc = false; ++ sgi = false; ++ hegi = 0xFF; ++ bw = 0; ++ dcm = false; ++ er = false; ++ ++ pos = os_strstr(cmd, "-r "); ++ if (pos) { ++ pos += 3; ++ rate = atoi(pos) * 2; ++ rspec = WL_RSPEC_ENCODE_RATE; /* 11abg */ ++ rspec |= rate; ++ } ++ ++ /* Option: -e or --he */ ++ pos = os_strstr(cmd, "-e "); ++ if (pos) { ++ char var_str[10]; ++ pos += 3; ++ endp = os_strchr(pos, ' '); ++ if (endp == NULL) ++ endp = os_strchr(pos, '\0'); ++ os_memcpy(var_str, pos, endp - pos); ++ var_str[endp - pos] = '\0'; ++ ++ val_int = (int)strtol(var_str, &endp, 10); ++ if (*endp == '\0') { ++ mcs = val_int; ++ he_set = true; ++ } else if (wl_parse_he_vht_spec(var_str, &mcs, &Nss)) { ++ he_set = true; ++ } else { ++ wpa_printf(MSG_DEBUG, "%s: could not parse \"%s\"" ++ "as a value for %s option", ++ "5g_rate", pos, "-e"); ++ goto exit; ++ } ++ ++ if (he_set) { ++ rspec = WL_RSPEC_ENCODE_HE; /* 11ax HE */ ++ if (Nss == 0) { ++ Nss = WL_RSPEC_HE_NSS_UNSPECIFIED; ++ } ++ rspec |= (Nss << WL_RSPEC_HE_NSS_SHIFT) | mcs; ++ } ++ } ++ ++ ++ pos = os_strstr(cmd, "-i "); ++ if (pos) { ++ if (!he_set) { ++ wpa_printf(MSG_DEBUG, ":use -i option only in he "); ++ goto exit; ++ } ++ ++ pos += 3; ++ val_int = (int)strtol(pos, &endp, 10); ++ if (*endp == '\0') { ++ if (val_int < 4) ++ { ++ hegi = val_int; ++ } ++ else { ++ wpa_printf(MSG_DEBUG, "%s: could not parse " ++ "\"%s\" as a value for %s option", ++ "5g_rate", pos, "-i"); ++ goto exit; ++ } ++ } ++ } ++ ++ /* Option: -l or --ldpc */ ++ pos = os_strstr(cmd, "-l"); ++ if (pos) { ++ ldpc = true; ++ } ++ ++ /* set the other rspec fields */ ++ rspec |= (tx_exp << WL_RSPEC_TXEXP_SHIFT); ++ rspec |= bw; ++ rspec |= (stbc ? WL_RSPEC_STBC : 0); ++ rspec |= (ldpc ? WL_RSPEC_LDPC : 0); ++ rspec |= (sgi ? WL_RSPEC_SGI : 0); ++ rspec |= ((hegi != 0xFF) ? HE_GI_TO_RSPEC(hegi) : 0); ++ rspec |= (dcm << WL_RSPEC_DCM_SHIFT); ++ rspec |= (er << WL_RSPEC_ER_SHIFT); ++ ++ os_memcpy(set_buf + *set_buf_len, (char *)&rspec, sizeof(rspec)); ++ *set_buf_len += sizeof(rspec); ++ ++ ret = 0; ++exit: ++ return ret; ++} ++ +diff --git a/src/drivers/driver_brcm_wlu.h b/src/drivers/driver_brcm_wlu.h +new file mode 100644 +index 000000000..67832dc6a +--- /dev/null ++++ b/src/drivers/driver_brcm_wlu.h +@@ -0,0 +1,12 @@ ++/* ++ * Broadcom Corporation OUI and vendor specific assignments ++ * Copyright (c) 2020, Broadcom Corporation. ++ * ++ * This software may be distributed under the terms of the BSD license. ++ * See README for more details. ++ */ ++ ++/* Format a ratespec for output of any of the wl_rate() iovars */ ++char* wl_rate_print(char *rate_buf, size_t buf_len, u32 rspec); ++ ++int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len); +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index 964486c11..8b04f9dc9 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -28,6 +28,11 @@ + #include "common/qca-vendor.h" + #include "common/qca-vendor-attr.h" + #include "common/brcm_vendor.h" ++#ifdef CONFIG_DRIVER_BRCM_WL ++#include "common/brcm_wl_ioctl.h" ++#include "driver_brcm_wlu.h" ++#include "drivers/driver_brcm_nl80211.h" ++#endif /* CONFIG_DRIVER_BRCM_WL */ + #include "common/ieee802_11_defs.h" + #include "common/ieee802_11_common.h" + #include "common/wpa_common.h" +@@ -10121,6 +10126,147 @@ static bool is_cmd_with_nested_attrs(unsigned int vendor_id, + } + + ++#ifdef CONFIG_DRIVER_BRCM_WL ++static int nl80211_wl_reply_handler(struct nl_msg *msg, void *arg) ++{ ++ struct nlattr *tb_msg[NL80211_ATTR_MAX + 1]; ++ struct nlattr *bcmnl[BCM_NLATTR_MAX + 1]; ++ struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg)); ++ char *buf = arg; ++ int ret = 0; ++ ++ wpa_printf(MSG_INFO, "nl80211: wl command reply handler"); ++ ++ nla_parse(tb_msg, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0), ++ genlmsg_attrlen(gnlh, 0), NULL); ++ ++ if (tb_msg[NL80211_ATTR_VENDOR_DATA]) { ++ wpa_printf(MSG_INFO, "nl80211: Vendor Data Found"); ++ ret = nla_parse_nested(bcmnl, BCM_NLATTR_MAX, ++ tb_msg[NL80211_ATTR_VENDOR_DATA], NULL); ++ if (ret != 0) ++ return NL_SKIP; ++ os_memcpy(buf, nla_data(bcmnl[BCM_NLATTR_DATA]), nla_get_u16(bcmnl[BCM_NLATTR_LEN])); ++ } ++ ++ return NL_SKIP; ++} ++ ++ ++int nl80211_wl_command(void *priv, char *cmd, char *buf, size_t buf_len) ++{ ++ struct i802_bss *bss = priv; ++ struct wpa_driver_nl80211_data *drv = bss->drv; ++ struct nl_msg *msg; ++ int ret = -1; ++ struct bcm_nlmsg_hdr *nlioc; ++ char *pos; ++ char smbuf[WLC_IOCTL_SMLEN * 2] = {0x00}; ++ char outbuf[WLC_IOCTL_MEDLEN] = {0x00}; ++ u32 msglen = 0; ++ bool set = false; ++ ++ bool is_get_int = false; ++ u32 output_val = 0x00; ++ ++ msg = nlmsg_alloc(); ++ if (!msg) ++ return -ENOMEM; ++ ++ pos = os_strstr(cmd, "5g_rate"); ++ if (pos) { ++ os_memcpy(smbuf, cmd, strlen("5g_rate")); //Keep last byte as 0x00 ++ is_get_int = true; ++ msglen += strlen("5g_rate"); ++ ++ if (os_strncasecmp(cmd, "5g_rate ", 8) == 0) { ++ set = true; ++ cmd += strlen("5g_rate "); ++ msglen += 1; ++ ++ ret = wl_rate_set(cmd, smbuf, &msglen); ++ if (ret != 0) ++ goto exit; ++ } ++ } ++ ++ pos = os_strstr(cmd, "2g_rate"); ++ if (pos) { ++ os_memcpy(smbuf, cmd, strlen("2g_rate")); //Keep last byte as 0x00 ++ is_get_int = true; ++ msglen += strlen("2g_rate"); ++ ++ if (os_strncasecmp(cmd, "2g_rate ", 8) == 0) { ++ set = true; ++ cmd += strlen("2g_rate "); ++ msglen += 1; ++ ++ ret = wl_rate_set(cmd, smbuf, &msglen); ++ if (ret != 0) ++ goto exit; ++ } ++ } ++ ++ /* nlmsg_alloc() can only allocate default_pagesize packet, cap ++ * any buffer send down to 1536 bytes ++ * DO NOT switch to nlmsg_alloc_size because Android doesn't support it ++ */ ++ if (msglen > 0x600) ++ msglen = 0x600; ++ if (set) ++ msglen += sizeof(struct bcm_nlmsg_hdr); ++ else ++ msglen = WLC_IOCTL_SMLEN; ++ nlioc = malloc(msglen); ++ if (nlioc == NULL) { ++ nlmsg_free(msg); ++ return -ENOMEM; ++ } ++ if (set) ++ nlioc->cmd = WLC_SET_VAR; ++ else ++ nlioc->cmd = WLC_GET_VAR; ++ nlioc->len = msglen - sizeof(struct bcm_nlmsg_hdr); ++ nlioc->offset = sizeof(struct bcm_nlmsg_hdr); ++ nlioc->set = set; ++ nlioc->magic = 0; ++ os_memcpy(((void *)nlioc) + nlioc->offset, smbuf, msglen - nlioc->offset); ++ ++ nl80211_cmd(drv, msg, 0, NL80211_CMD_VENDOR); ++ if (nl80211_set_iface_id(msg, bss) < 0) { ++ goto nla_put_failure; ++ } ++ ++ NLA_PUT_U32(msg, NL80211_ATTR_VENDOR_ID, OUI_BRCM); ++ NLA_PUT_U32(msg, NL80211_ATTR_VENDOR_SUBCMD, BRCM_VENDOR_SCMD_PRIV_STR); ++ NLA_PUT(msg, NL80211_ATTR_VENDOR_DATA, msglen, nlioc); ++ ++ ret = send_and_recv_msgs(drv, msg, nl80211_wl_reply_handler, outbuf, NULL, NULL); ++ msg = NULL; ++ if (ret) { ++ wpa_printf(MSG_ERROR, "nl80211: vendor cmd failed: " ++ "ret=%d (%s)", ret, strerror(-ret)); ++ ret = 0; ++ } ++ ++ wpa_printf(MSG_DEBUG, "nl80211: vendor cmd sent successfully "); ++ ++ if (set == false && is_get_int == true) { ++ os_memcpy(&output_val, outbuf, sizeof(output_val)); ++ wl_rate_print(buf, buf_len, output_val); ++ ret = buf_len; ++ } ++ ++nla_put_failure: ++exit: ++ ++ nlmsg_free(msg); ++ ++ return ret; ++} ++#endif /* CONFIG_DRIVER_BRCM_WL */ ++ ++ + static int nl80211_vendor_cmd(void *priv, unsigned int vendor_id, + unsigned int subcmd, const u8 *data, + size_t data_len, enum nested_attr nested_attr, +@@ -12263,6 +12409,9 @@ const struct wpa_driver_ops wpa_driver_nl80211_ops = { + .driver_cmd = wpa_driver_nl80211_driver_cmd, + #endif /* !ANDROID_LIB_STUB */ + #endif /* ANDROID */ ++#ifdef CONFIG_DRIVER_BRCM_WL ++ .wl_cmd = nl80211_wl_command, ++#endif /* CONFIG_DRIVER_BRCM_WL */ + .vendor_cmd = nl80211_vendor_cmd, + .set_qos_map = nl80211_set_qos_map, + .get_wowlan = nl80211_get_wowlan, +diff --git a/src/drivers/drivers.mak b/src/drivers/drivers.mak +index a03d4a034..a986fa379 100644 +--- a/src/drivers/drivers.mak ++++ b/src/drivers/drivers.mak +@@ -30,6 +30,11 @@ ifdef CONFIG_DRIVER_NL80211_BRCM + DRV_CFLAGS += -DCONFIG_DRIVER_NL80211_BRCM + endif + ++ifdef CONFIG_DRIVER_BRCM_WL ++DRV_CFLAGS += -DCONFIG_DRIVER_BRCM_WL ++DRV_OBJS += ../src/drivers/driver_brcm_wlu.o ++endif ++ + ifdef CONFIG_DRIVER_MACSEC_QCA + DRV_CFLAGS += -DCONFIG_DRIVER_MACSEC_QCA + DRV_OBJS += ../src/drivers/driver_macsec_qca.o +diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base +index 4f71b50ff..d4be24c34 100644 +--- a/wpa_supplicant/defconfig_base ++++ b/wpa_supplicant/defconfig_base +@@ -34,6 +34,8 @@ CONFIG_DRIVER_NL80211=y + # QCA vendor extensions to nl80211 + #CONFIG_DRIVER_NL80211_QCA=y + ++CONFIG_DRIVER_BRCM_WL=y ++ + # driver_nl80211.c requires libnl. If you are compiling it yourself + # you may need to point hostapd to your version of libnl. + # +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0024-non-upstream-wl-cmd-create-wl_do_cmd-as-an-entry-doi.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0024-non-upstream-wl-cmd-create-wl_do_cmd-as-an-entry-doi.patch new file mode 100644 index 000000000..cdc0e9b2b --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0024-non-upstream-wl-cmd-create-wl_do_cmd-as-an-entry-doi.patch @@ -0,0 +1,136 @@ +From ea5cd91f744dc3c5ebf8e5b8cf1746bec41c1d19 Mon Sep 17 00:00:00 2001 +From: Kurt Lee +Date: Tue, 26 Apr 2022 03:02:12 -0500 +Subject: [PATCH 24/49] non-upstream: wl-cmd: create wl_do_cmd as an entry + doing wl commands + +Create wl_do_cmd as an entry doing wl commands + +Signed-off-by: Ian Lin +Signed-off-by: Kurt Lee +--- + src/drivers/driver_brcm_wlu.c | 44 +++++++++++++++++++++++++++++++++++ + src/drivers/driver_brcm_wlu.h | 2 +- + src/drivers/driver_nl80211.c | 37 +++-------------------------- + 3 files changed, 48 insertions(+), 35 deletions(-) + +diff --git a/src/drivers/driver_brcm_wlu.c b/src/drivers/driver_brcm_wlu.c +index f2264ebcc..4fc03e446 100644 +--- a/src/drivers/driver_brcm_wlu.c ++++ b/src/drivers/driver_brcm_wlu.c +@@ -287,3 +287,47 @@ exit: + return ret; + } + ++ ++int wl_do_cmd(char *cmd, char *smbuf, u32 *msglen, bool *set, bool *is_get_int) ++{ ++ int ret = -1; ++ char *pos; ++ ++ pos = os_strstr(cmd, "5g_rate"); ++ if (pos) { ++ os_memcpy(smbuf, cmd, strlen("5g_rate")); //Keep last byte as 0x00 ++ *is_get_int = true; ++ *msglen += strlen("5g_rate"); ++ ++ if (os_strncasecmp(cmd, "5g_rate ", 8) == 0) { ++ *set = true; ++ cmd += strlen("5g_rate "); ++ *msglen += 1; ++ ++ ret = wl_rate_set(cmd, smbuf, msglen); ++ if (ret != 0) ++ goto exit; ++ } ++ } ++ ++ pos = os_strstr(cmd, "2g_rate"); ++ if (pos) { ++ os_memcpy(smbuf, cmd, strlen("2g_rate")); //Keep last byte as 0x00 ++ *is_get_int = true; ++ *msglen += strlen("2g_rate"); ++ ++ if (os_strncasecmp(cmd, "2g_rate ", 8) == 0) { ++ *set = true; ++ cmd += strlen("2g_rate "); ++ *msglen += 1; ++ ++ ret = wl_rate_set(cmd, smbuf, msglen); ++ if (ret != 0) ++ goto exit; ++ } ++ } ++ ++exit: ++ return ret; ++} ++ +diff --git a/src/drivers/driver_brcm_wlu.h b/src/drivers/driver_brcm_wlu.h +index 67832dc6a..7fc9118fc 100644 +--- a/src/drivers/driver_brcm_wlu.h ++++ b/src/drivers/driver_brcm_wlu.h +@@ -9,4 +9,4 @@ + /* Format a ratespec for output of any of the wl_rate() iovars */ + char* wl_rate_print(char *rate_buf, size_t buf_len, u32 rspec); + +-int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len); ++int wl_do_cmd(char *cmd, char *smbuf, u32 *msglen, bool *set, bool *is_get_int); +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index 8b04f9dc9..a6b9c860d 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -10160,7 +10160,6 @@ int nl80211_wl_command(void *priv, char *cmd, char *buf, size_t buf_len) + struct nl_msg *msg; + int ret = -1; + struct bcm_nlmsg_hdr *nlioc; +- char *pos; + char smbuf[WLC_IOCTL_SMLEN * 2] = {0x00}; + char outbuf[WLC_IOCTL_MEDLEN] = {0x00}; + u32 msglen = 0; +@@ -10173,39 +10172,9 @@ int nl80211_wl_command(void *priv, char *cmd, char *buf, size_t buf_len) + if (!msg) + return -ENOMEM; + +- pos = os_strstr(cmd, "5g_rate"); +- if (pos) { +- os_memcpy(smbuf, cmd, strlen("5g_rate")); //Keep last byte as 0x00 +- is_get_int = true; +- msglen += strlen("5g_rate"); +- +- if (os_strncasecmp(cmd, "5g_rate ", 8) == 0) { +- set = true; +- cmd += strlen("5g_rate "); +- msglen += 1; +- +- ret = wl_rate_set(cmd, smbuf, &msglen); +- if (ret != 0) +- goto exit; +- } +- } +- +- pos = os_strstr(cmd, "2g_rate"); +- if (pos) { +- os_memcpy(smbuf, cmd, strlen("2g_rate")); //Keep last byte as 0x00 +- is_get_int = true; +- msglen += strlen("2g_rate"); +- +- if (os_strncasecmp(cmd, "2g_rate ", 8) == 0) { +- set = true; +- cmd += strlen("2g_rate "); +- msglen += 1; +- +- ret = wl_rate_set(cmd, smbuf, &msglen); +- if (ret != 0) +- goto exit; +- } +- } ++ ret = wl_do_cmd(cmd, smbuf, &msglen, &set, &is_get_int); ++ if (ret != 0) ++ goto exit; + + /* nlmsg_alloc() can only allocate default_pagesize packet, cap + * any buffer send down to 1536 bytes +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0025-non-upstream-wl-cmd-create-ops-table-to-do-wl-comman.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0025-non-upstream-wl-cmd-create-ops-table-to-do-wl-comman.patch new file mode 100644 index 000000000..c9037f18e --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0025-non-upstream-wl-cmd-create-ops-table-to-do-wl-comman.patch @@ -0,0 +1,467 @@ +From 05b1387d4dc2e74a02cf524733d809acc4fd46fb Mon Sep 17 00:00:00 2001 +From: Kurt Lee +Date: Wed, 27 Apr 2022 22:50:25 -0500 +Subject: [PATCH 25/49] non-upstream: wl-cmd: create ops table to do wl + commands + +Creeate wl_cmds to handle wl commands + +Signed-off-by: Ian Lin +Signed-off-by: Kurt Lee +--- + src/drivers/driver_brcm_wlu.c | 247 ++++++++++++++++++++++++------ + src/drivers/driver_brcm_wlu.h | 2 +- + src/drivers/driver_brcm_wlu_cmd.h | 23 +++ + src/drivers/driver_nl80211.c | 27 ++-- + 4 files changed, 240 insertions(+), 59 deletions(-) + create mode 100644 src/drivers/driver_brcm_wlu_cmd.h + +diff --git a/src/drivers/driver_brcm_wlu.c b/src/drivers/driver_brcm_wlu.c +index 4fc03e446..8e568f9f6 100644 +--- a/src/drivers/driver_brcm_wlu.c ++++ b/src/drivers/driver_brcm_wlu.c +@@ -10,7 +10,110 @@ + #include "common.h" + #include "common/brcm_vendor.h" + #include "common/brcm_wl_ioctl.h" ++#include "common/brcm_wl_ioctl_defs.h" + #include "common/wpa_common.h" ++#include "driver_brcm_wlu_cmd.h" ++ ++static cmd_func_t wl_rate; ++static cmd_func_t wl_varint; ++ ++#define RATE_2G_USAGE \ ++"\tEither \"auto\", or a simple CCK/DSSS/OFDM rate value:\n" \ ++"\t1 2 5.5 11 6 9 12 18 24 36 48 54\n\n" \ ++"\tOr options to specify legacy, HT, or VHT rate:\n" \ ++"\t-r R, --rate=R : legacy rate (CCK, DSSS, OFDM)\n" \ ++"\t-h M, --ht=M : HT MCS index [0-23]\n" \ ++"\t-v M[xS], --vht=M[xS] : VHT MCS index M [0-9],\n" \ ++"\t : and optionally Nss S [1-8], eg. 5x2 is MCS=5, Nss=2\n" \ ++"\t-c cM[sS] : VHT (c notation) MCS index M [0-9],\n" \ ++"\t : and optionally Nss S [1-8], eg. c5s2 is MCS=5, Nss=2\n" \ ++"\t-e M[xS], --he=M[xS] : HE rate M [0-11],\n" \ ++"\t-s S, --ss=S : VHT Nss [1-8], number of spatial streams, default 1.\n" \ ++"\t : Only used with -v/--vht when MxS format is not used\n" \ ++"\t-x T, --exp=T : Tx Expansion, number of tx chains (NTx) beyond the minimum\n" \ ++"\t : required for the space-time-streams, exp = NTx - Nsts\n" \ ++"\t--stbc : Use STBC expansion, otherwise no STBC\n" \ ++"\t-l, --ldpc : Use LDPC encoding, otherwise no LDPC\n" \ ++"\t-g, --sgi : Guard interval. Different values for HT/VHT\n" \ ++"\t : Use Short Guard Interval otherwise standard GI\n" \ ++"\t-i, --hegi : Guard interval. Different values for HE\n" \ ++"\t : For HE, cp_ltf combination allowed values (0,1,2,3)\n" \ ++"\t-b, --bandwidth : transmit bandwidth in MHz [2.5, 5, 10, 20, 40, 80, 160] eg. -b 20\n" \ ++"\t-d D, --dcm=D : Use -d to set DCM, otherwise no DCM\n" \ ++"\t : (only when is MCS [0, 1], NSS 1, -b 20)\n" \ ++"\t-n R, --er=R : R [106,242] HE Range extension\n" \ ++"\t : otherwise no Rang extension and works only in 20 MHz" ++ ++#define RATE_5G_6G_USAGE \ ++"\tEither \"auto\", or a simple OFDM rate value:\n" \ ++"\t6 9 12 18 24 36 48 54\n\n" \ ++"\tOr options to specify legacy OFDM, HT, or VHT rate:\n" \ ++"\t-r R, --rate=R : legacy OFDM rate\n" \ ++"\t-h M, --ht=M : HT MCS index [0-23]\n" \ ++"\t-v M[xS], --vht=M[xS] : VHT MCS index M [0-9],\n" \ ++"\t : and optionally Nss S [1-8], eg. 5x2 is MCS=5, Nss=2\n" \ ++"\t-c cM[sS] : VHT (c notation) MCS index M [0-9],\n" \ ++"\t : and optionally Nss S [1-8], eg. c5s2 is MCS=5, Nss=2\n" \ ++"\t-e M[xS], --he=M[xS] : HE rate M [0-11],\n" \ ++"\t-s S, --ss=S : VHT Nss [1-8], number of spatial streams, default 1.\n" \ ++"\t : Only used with -v/--vht when MxS format is not used\n" \ ++"\t-x T, --exp=T : Tx Expansion, number of tx chains (NTx) beyond the minimum\n" \ ++"\t : required for the space-time-streams, exp = NTx - Nsts\n" \ ++"\t--stbc : Use STBC expansion, otherwise no STBC\n" \ ++"\t-l, --ldpc : Use LDPC encoding, otherwise no LDPC\n" \ ++"\t-g, --sgi : Guard interval. Different values for HT/VHT\n" \ ++"\t : Use Short Guard Interval otherwise standard GI\n" \ ++"\t-i, --hegi : Guard interval. Different values for HE\n" \ ++"\t : For HE cp_ltf combination allowed values (0,1,2,3)\n" \ ++"\t-b, --bandwidth : transmit bandwidth in MHz [2.5, 5, 10, 20, 40, 80, 160] eg. -b 20\n" \ ++"\t-d D, --dcm=D : Use -d to set DCM, otherwise no DCM\n" \ ++"\t : (only when is MCS [0, 1], NSS 1, -b 20)\n" \ ++"\t-n R, --er=R : R [106,242] HE Range extension\n" \ ++"\t : otherwise no Rang extension and works only in 20 MHz" ++ ++/* If the new command needs to be part of 'wc.exe' tool used for WMM, ++ * be sure to modify wc_cmds[] array as well ++ * ++ * If you add a command, please update wlu_cmd.c cmd2cat to categorize the command. ++ */ ++cmd_t wl_cmds[] = { ++ { "2g_rate", wl_rate, WLC_GET_VAR, WLC_SET_VAR, ++ "Force a fixed rate for data frames in the 2.4G band:\n\n" ++ RATE_2G_USAGE ++ }, ++ { "2g_mrate", wl_rate, WLC_GET_VAR, WLC_SET_VAR, ++ "Force a fixed rate for mulitcast/broadcast data frames in the 2.4G band:\n\n" ++ RATE_2G_USAGE ++ }, ++ { "5g_rate", wl_rate, WLC_GET_VAR, WLC_SET_VAR, ++ "Force a fixed rate for data frames in the 5G band:\n\n" ++ RATE_5G_6G_USAGE ++ }, ++ { "5g_mrate", wl_rate, WLC_GET_VAR, WLC_SET_VAR, ++ "Force a fixed rate for mulitcast/broadcast data frames in the 5G band:\n\n" ++ RATE_5G_6G_USAGE ++ }, ++ { NULL, NULL, 0, 0, NULL } ++}; ++ ++cmd_t wl_varcmd = {"var", wl_varint, -1, -1, "unrecognized name, type -h for help"}; ++ ++/* common function to find a command */ ++cmd_t * ++wlu_find_cmd(char *name) ++{ ++ cmd_t *cmd = wl_cmds; ++ ++ /* search cmd in cmd table */ ++ for (; cmd->name; cmd++) { ++ /* stop if we find a matching name */ ++ if (!os_strncasecmp(cmd->name, name, os_strlen(cmd->name))) { ++ break; ++ } ++ } ++ ++ return (cmd->name != NULL) ? cmd : NULL; ++} + + /* + * Format a ratespec for output of any of the wl_rate() iovars +@@ -113,8 +216,7 @@ wl_rate_print(char *rate_buf, size_t buf_len, u32 rspec) + * return FALSE if the arg does not look like MxS or cMsS, where M and S are single digits + * return TRUE if the arg does look like MxS or cMsS, setting mcsp to M, and nssp to S + */ +-//static int +-int ++static int + wl_parse_he_vht_spec(const char* cp, int* mcsp, int* nssp) + { + char *startp, *endp; +@@ -171,12 +273,13 @@ wl_parse_he_vht_spec(const char* cp, int* mcsp, int* nssp) + } + + +-int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len) ++static int ++wl_rate(char *cmd, char *buf, u32 *buf_len, bool *get, bool *is_get_int) + { + int ret = -1; +- char *pos; +- //bool legacy_set = false, ht_set = false, vht_set = false, he_set = false; +- bool he_set = false; ++ char *pos, *param = cmd; ++ bool auto_set = false; ++ bool legacy_set = false, ht_set = false, vht_set = false, he_set = false; + int rate, mcs, Nss, tx_exp, bw; + bool stbc, ldpc, sgi, dcm, er; + u8 hegi; +@@ -198,7 +301,48 @@ int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len) + dcm = false; + er = false; + +- pos = os_strstr(cmd, "-r "); ++ pos = os_strstr(cmd, "5g_rate"); ++ if (pos) { ++ param = cmd + strlen("5g_rate"); ++ os_memcpy(buf, cmd, strlen("5g_rate")); //Keep last byte as 0x00 ++ *is_get_int = true; ++ *buf_len += strlen("5g_rate"); ++ ++ if (os_strncasecmp(cmd, "5g_rate ", 8) == 0) { ++ param += 1; ++ *get = false; ++ cmd += strlen("5g_rate "); ++ *buf_len += 1; ++ } ++ } ++ ++ pos = os_strstr(cmd, "2g_rate"); ++ if (pos) { ++ param = cmd + strlen("2g_rate"); ++ os_memcpy(buf, cmd, strlen("2g_rate")); //Keep last byte as 0x00 ++ *is_get_int = true; ++ *buf_len += strlen("2g_rate"); ++ ++ if (os_strncasecmp(cmd, "2g_rate ", 8) == 0) { ++ param += 1; ++ *get = false; ++ cmd += strlen("2g_rate "); ++ *buf_len += 1; ++ } ++ } ++ ++ if (*get == true) { ++ ret = 0; ++ goto exit; ++ } ++ ++ /* Option: -l or --ldpc */ ++ pos = os_strstr(param, "auto"); ++ if (pos) { ++ auto_set = true; ++ } ++ ++ pos = os_strstr(param, "-r "); + if (pos) { + pos += 3; + rate = atoi(pos) * 2; +@@ -207,7 +351,7 @@ int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len) + } + + /* Option: -e or --he */ +- pos = os_strstr(cmd, "-e "); ++ pos = os_strstr(param, "-e "); + if (pos) { + char var_str[10]; + pos += 3; +@@ -240,7 +384,7 @@ int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len) + } + + +- pos = os_strstr(cmd, "-i "); ++ pos = os_strstr(param, "-i "); + if (pos) { + if (!he_set) { + wpa_printf(MSG_DEBUG, ":use -i option only in he "); +@@ -264,11 +408,39 @@ int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len) + } + + /* Option: -l or --ldpc */ +- pos = os_strstr(cmd, "-l"); ++ pos = os_strstr(param, "-l"); + if (pos) { + ldpc = true; + } + ++ /* set the ratespec encoding type and basic rate value */ ++ if (auto_set) { ++ rspec = 0; ++ } else if (legacy_set) { ++ rspec = WL_RSPEC_ENCODE_RATE; /* 11abg */ ++ rspec |= rate; ++ } else if (ht_set) { ++ rspec = WL_RSPEC_ENCODE_HT; /* 11n HT */ ++ rspec |= mcs; ++ } else if (vht_set) { ++ rspec = WL_RSPEC_ENCODE_VHT; /* 11ac VHT */ ++ if (Nss == 0) { ++ Nss = 1; /* default Nss = 1 if --ss option not given */ ++ } ++ rspec |= (Nss << WL_RSPEC_VHT_NSS_SHIFT) | mcs; ++ } else if (he_set) { ++ rspec = WL_RSPEC_ENCODE_HE; /* 11ax HE */ ++ if (Nss == 0) { ++ Nss = WL_RSPEC_HE_NSS_UNSPECIFIED; ++ } ++ rspec |= (Nss << WL_RSPEC_HE_NSS_SHIFT) | mcs; ++ } else { ++ wpa_printf(MSG_ERROR, ++ "%s: Invalid rate set for %s option\n", ++ "wl", param); ++ goto exit; ++ } ++ + /* set the other rspec fields */ + rspec |= (tx_exp << WL_RSPEC_TXEXP_SHIFT); + rspec |= bw; +@@ -279,54 +451,39 @@ int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len) + rspec |= (dcm << WL_RSPEC_DCM_SHIFT); + rspec |= (er << WL_RSPEC_ER_SHIFT); + +- os_memcpy(set_buf + *set_buf_len, (char *)&rspec, sizeof(rspec)); +- *set_buf_len += sizeof(rspec); ++ os_memcpy(buf + *buf_len, (char *)&rspec, sizeof(rspec)); ++ *buf_len += sizeof(rspec); + + ret = 0; + exit: + return ret; + } + ++/* just issue a wl_var_setint() or a wl_var_getint() if there is a 2nd arg */ ++static int ++wl_varint(char *cmd, char *buf, u32 *buf_len, bool *get, bool *is_get_int) ++{ ++ return -1; ++} + +-int wl_do_cmd(char *cmd, char *smbuf, u32 *msglen, bool *set, bool *is_get_int) ++int wl_do_cmd(char *cmd, char *smbuf, u32 *msglen, bool *get, bool *is_get_int) + { ++ cmd_t *wl_cmd = NULL; + int ret = -1; +- char *pos; +- +- pos = os_strstr(cmd, "5g_rate"); +- if (pos) { +- os_memcpy(smbuf, cmd, strlen("5g_rate")); //Keep last byte as 0x00 +- *is_get_int = true; +- *msglen += strlen("5g_rate"); +- +- if (os_strncasecmp(cmd, "5g_rate ", 8) == 0) { +- *set = true; +- cmd += strlen("5g_rate "); +- *msglen += 1; + +- ret = wl_rate_set(cmd, smbuf, msglen); +- if (ret != 0) +- goto exit; +- } +- } ++ /* search for command */ ++ wl_cmd = wlu_find_cmd(cmd); + +- pos = os_strstr(cmd, "2g_rate"); +- if (pos) { +- os_memcpy(smbuf, cmd, strlen("2g_rate")); //Keep last byte as 0x00 +- *is_get_int = true; +- *msglen += strlen("2g_rate"); +- +- if (os_strncasecmp(cmd, "2g_rate ", 8) == 0) { +- *set = true; +- cmd += strlen("2g_rate "); +- *msglen += 1; +- +- ret = wl_rate_set(cmd, smbuf, msglen); +- if (ret != 0) +- goto exit; +- } ++ /* defaults to using the set_var and get_var commands */ ++ if (!wl_cmd) { ++ wl_cmd = &wl_varcmd; + } ++ /* do command */ ++ ret = (*wl_cmd->func)(cmd, smbuf, msglen, get, is_get_int); ++ if (ret != 0) ++ goto exit; + ++ ret = 0; + exit: + return ret; + } +diff --git a/src/drivers/driver_brcm_wlu.h b/src/drivers/driver_brcm_wlu.h +index 7fc9118fc..a943a0832 100644 +--- a/src/drivers/driver_brcm_wlu.h ++++ b/src/drivers/driver_brcm_wlu.h +@@ -9,4 +9,4 @@ + /* Format a ratespec for output of any of the wl_rate() iovars */ + char* wl_rate_print(char *rate_buf, size_t buf_len, u32 rspec); + +-int wl_do_cmd(char *cmd, char *smbuf, u32 *msglen, bool *set, bool *is_get_int); ++int wl_do_cmd(char *cmd, char *smbuf, u32 *msglen, bool *get, bool *is_get_int); +diff --git a/src/drivers/driver_brcm_wlu_cmd.h b/src/drivers/driver_brcm_wlu_cmd.h +new file mode 100644 +index 000000000..8443a625e +--- /dev/null ++++ b/src/drivers/driver_brcm_wlu_cmd.h +@@ -0,0 +1,23 @@ ++/* ++ * Broadcom Corporation OUI and vendor specific assignments ++ * Copyright (c) 2020, Broadcom Corporation. ++ * ++ * This software may be distributed under the terms of the BSD license. ++ * See README for more details. ++ */ ++ ++typedef struct cmd cmd_t; ++typedef int (cmd_func_t)(char *cmd, char *buf, u32 *buf_len, bool *set, bool *is_get_int); ++ ++/* generic command line argument handler */ ++struct cmd { ++ const char *name; ++ cmd_func_t *func; ++ int get; ++ int set; ++ const char *help; ++}; ++ ++/* list of command line arguments */ ++extern cmd_t wl_cmds[]; ++ +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index a6b9c860d..de58b17e1 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -10141,7 +10141,7 @@ static int nl80211_wl_reply_handler(struct nl_msg *msg, void *arg) + genlmsg_attrlen(gnlh, 0), NULL); + + if (tb_msg[NL80211_ATTR_VENDOR_DATA]) { +- wpa_printf(MSG_INFO, "nl80211: Vendor Data Found"); ++ wpa_printf(MSG_INFO, "nl80211: wl data found"); + ret = nla_parse_nested(bcmnl, BCM_NLATTR_MAX, + tb_msg[NL80211_ATTR_VENDOR_DATA], NULL); + if (ret != 0) +@@ -10163,7 +10163,7 @@ int nl80211_wl_command(void *priv, char *cmd, char *buf, size_t buf_len) + char smbuf[WLC_IOCTL_SMLEN * 2] = {0x00}; + char outbuf[WLC_IOCTL_MEDLEN] = {0x00}; + u32 msglen = 0; +- bool set = false; ++ bool get = true; + + bool is_get_int = false; + u32 output_val = 0x00; +@@ -10172,7 +10172,7 @@ int nl80211_wl_command(void *priv, char *cmd, char *buf, size_t buf_len) + if (!msg) + return -ENOMEM; + +- ret = wl_do_cmd(cmd, smbuf, &msglen, &set, &is_get_int); ++ ret = wl_do_cmd(cmd, smbuf, &msglen, &get, &is_get_int); + if (ret != 0) + goto exit; + +@@ -10182,22 +10182,23 @@ int nl80211_wl_command(void *priv, char *cmd, char *buf, size_t buf_len) + */ + if (msglen > 0x600) + msglen = 0x600; +- if (set) +- msglen += sizeof(struct bcm_nlmsg_hdr); +- else ++ if (get) + msglen = WLC_IOCTL_SMLEN; ++ else ++ msglen += sizeof(struct bcm_nlmsg_hdr); ++ + nlioc = malloc(msglen); + if (nlioc == NULL) { + nlmsg_free(msg); + return -ENOMEM; + } +- if (set) +- nlioc->cmd = WLC_SET_VAR; +- else ++ if (get) + nlioc->cmd = WLC_GET_VAR; ++ else ++ nlioc->cmd = WLC_SET_VAR; + nlioc->len = msglen - sizeof(struct bcm_nlmsg_hdr); + nlioc->offset = sizeof(struct bcm_nlmsg_hdr); +- nlioc->set = set; ++ nlioc->set = !get; + nlioc->magic = 0; + os_memcpy(((void *)nlioc) + nlioc->offset, smbuf, msglen - nlioc->offset); + +@@ -10213,14 +10214,14 @@ int nl80211_wl_command(void *priv, char *cmd, char *buf, size_t buf_len) + ret = send_and_recv_msgs(drv, msg, nl80211_wl_reply_handler, outbuf, NULL, NULL); + msg = NULL; + if (ret) { +- wpa_printf(MSG_ERROR, "nl80211: vendor cmd failed: " ++ wpa_printf(MSG_ERROR, "nl80211: wl cmd failed: " + "ret=%d (%s)", ret, strerror(-ret)); + ret = 0; + } + +- wpa_printf(MSG_DEBUG, "nl80211: vendor cmd sent successfully "); ++ wpa_printf(MSG_DEBUG, "nl80211: wl cmd sent successfully "); + +- if (set == false && is_get_int == true) { ++ if (get == true && is_get_int == true) { + os_memcpy(&output_val, outbuf, sizeof(output_val)); + wl_rate_print(buf, buf_len, output_val); + ret = buf_len; +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0026-non-upstream-wl-cmd-add-more-compile-flag.murata.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0026-non-upstream-wl-cmd-add-more-compile-flag.murata.patch new file mode 100644 index 000000000..0f7410345 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0026-non-upstream-wl-cmd-add-more-compile-flag.murata.patch @@ -0,0 +1,31 @@ +From a6028c58032672f86c9fe87ba3abbd31c79166e3 Mon Sep 17 00:00:00 2001 +From: Kurt Lee +Date: Wed, 25 May 2022 19:12:47 -0500 +Subject: [PATCH 26/49] non-upstream: wl-cmd: add more compile flag + +add more CONFIG_DRIVER_BRCM_WL to separeta this feature + +Signed-off-by: Ian Lin +Signed-off-by: Kurt Lee +--- + src/drivers/driver.h | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index 3d48f6f07..2745b8340 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -3861,7 +3861,10 @@ struct wpa_driver_ops { + */ + int (*driver_cmd)(void *priv, char *cmd, char *buf, size_t buf_len); + #endif /* ANDROID */ ++ ++#ifdef CONFIG_DRIVER_BRCM_WL + int (*wl_cmd)(void *priv, char *cmd, char *buf, size_t buf_len); ++#endif /* CONFIG_DRIVER_BRCM_WL */ + + /** + * vendor_cmd - Execute vendor specific command +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0027-Fix-dpp-config-parameter-setting.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0027-Fix-dpp-config-parameter-setting.patch new file mode 100644 index 000000000..894a71616 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0027-Fix-dpp-config-parameter-setting.patch @@ -0,0 +1,31 @@ +From e2fb675883cf00992ce51e91a3e2055c898ae3e6 Mon Sep 17 00:00:00 2001 +From: "Shankar Amar (CSTIPL CSS ICW SW WFS 1)" +Date: Mon, 20 Jun 2022 05:57:46 +0000 +Subject: [PATCH 27/49] Fix dpp config parameter setting + +--- + src/common/dpp.c | 7 ++++--- + 1 file changed, 4 insertions(+), 3 deletions(-) + +diff --git a/src/common/dpp.c b/src/common/dpp.c +index ac6eae4c8..6e6e4248c 100644 +--- a/src/common/dpp.c ++++ b/src/common/dpp.c +@@ -1029,10 +1029,11 @@ static int dpp_configuration_parse_helper(struct dpp_authentication *auth, + pos += 6; + end = os_strchr(pos, ' '); + conf->ssid_len = end ? (size_t) (end - pos) : os_strlen(pos); +- conf->ssid_len /= 2; +- if (conf->ssid_len > sizeof(conf->ssid) || +- hexstr2bin(pos, conf->ssid, conf->ssid_len) < 0) ++ /* Remove check for ssid in hex as we are supplying ++ * string format in dpp_auth_init */ ++ if (conf->ssid_len > sizeof(conf->ssid)) + goto fail; ++ os_memcpy(conf->ssid, pos, conf->ssid_len); + } else { + #ifdef CONFIG_TESTING_OPTIONS + /* use a default SSID for legacy testing reasons */ +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0028-DPP-Resolving-failure-of-dpp-configurator-exchange-f.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0028-DPP-Resolving-failure-of-dpp-configurator-exchange-f.patch new file mode 100644 index 000000000..4d8448982 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0028-DPP-Resolving-failure-of-dpp-configurator-exchange-f.patch @@ -0,0 +1,35 @@ +From b19b6f1165800106ccd941b6042ea804bfa95d5f Mon Sep 17 00:00:00 2001 +From: "Shankar Amar (CSTIPL CSS ICW SW WFS 1)" +Date: Thu, 30 Jun 2022 08:01:45 +0000 +Subject: [PATCH 28/49] DPP: Resolving failure of dpp configurator exchange for + configurator plus initiator in AP role with fmac + +--- + hostapd/defconfig_base | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/hostapd/defconfig_base b/hostapd/defconfig_base +index 4e4f0f784..16e8c645a 100644 +--- a/hostapd/defconfig_base ++++ b/hostapd/defconfig_base +@@ -307,7 +307,7 @@ CONFIG_TLS_ADD_DL=y + # Interworking (IEEE 802.11u) + # This can be used to enable functionality to improve interworking with + # external networks. +-#CONFIG_INTERWORKING=y ++CONFIG_INTERWORKING=y + + # Hotspot 2.0 + #CONFIG_HS20=y +@@ -370,7 +370,7 @@ CONFIG_TESTING_OPTIONS=y + + # Include internal line edit mode in hostapd_cli. This can be used to provide + # limited command line editing and history support. +-#CONFIG_WPA_CLI_EDIT=y ++CONFIG_WPA_CLI_EDIT=y + + # Opportunistic Wireless Encryption (OWE) + # Experimental implementation of draft-harkins-owe-07.txt +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0029-Enabling-SUITEB192-and-SUITEB-compile-options.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0029-Enabling-SUITEB192-and-SUITEB-compile-options.patch new file mode 100644 index 000000000..49c53d64b --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0029-Enabling-SUITEB192-and-SUITEB-compile-options.patch @@ -0,0 +1,29 @@ +From 7d621a129690b061afd61e8bd21d9b816f09d8ac Mon Sep 17 00:00:00 2001 +From: Carter Chen +Date: Mon, 4 Jul 2022 02:19:48 -0500 +Subject: [PATCH 29/49] Enabling SUITEB192 and SUITEB compile options + +Enabling the compile options for SUITEB and SUITEB-192 related +configurations and wpa_cli commands. + +Fixes: SWLINUX-2712 + +Signed-off-by: Carter Chen +--- + wpa_supplicant/defconfig_base | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base +index d4be24c34..f290ae673 100644 +--- a/wpa_supplicant/defconfig_base ++++ b/wpa_supplicant/defconfig_base +@@ -638,3 +638,6 @@ CONFIG_DPP=y + # connect to this hostapd. These options allow, for example, to drop a + # certain percentage of probe requests or auth/(re)assoc frames. + CONFIG_TESTING_OPTIONS=y ++ ++CONFIG_SUITEB192=y ++CONFIG_SUITEB=y +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0030-DPP-Enabling-CLI_EDIT-option-for-enrollee-plus-respo.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0030-DPP-Enabling-CLI_EDIT-option-for-enrollee-plus-respo.patch new file mode 100644 index 000000000..ea78e16dd --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0030-DPP-Enabling-CLI_EDIT-option-for-enrollee-plus-respo.patch @@ -0,0 +1,26 @@ +From 621de92cbd36719e3febe385411a65ccfa646344 Mon Sep 17 00:00:00 2001 +From: "Shankar Amar (CSTIPL CSS ICW SW WFS 1)" +Date: Fri, 22 Jul 2022 07:52:30 +0000 +Subject: [PATCH 30/49] DPP: Enabling CLI_EDIT option for enrollee plus + responder in STA role with fmac + +--- + wpa_supplicant/defconfig_base | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base +index f290ae673..611a23e3e 100644 +--- a/wpa_supplicant/defconfig_base ++++ b/wpa_supplicant/defconfig_base +@@ -228,7 +228,7 @@ CONFIG_CTRL_IFACE=y + + # Include internal line edit mode in wpa_cli. This can be used as a replacement + # for GNU Readline to provide limited command line editing and history support. +-#CONFIG_WPA_CLI_EDIT=y ++CONFIG_WPA_CLI_EDIT=y + + # Remove debugging code that is printing out debug message to stdout. + # This can be used to reduce the size of the wpa_supplicant considerably +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0032-non-upstream-SAE-disconnect-after-PMKSA-cache-expire.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0032-non-upstream-SAE-disconnect-after-PMKSA-cache-expire.patch new file mode 100644 index 000000000..3381303ca --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0032-non-upstream-SAE-disconnect-after-PMKSA-cache-expire.patch @@ -0,0 +1,68 @@ +From 65ed1eadc11b838a4ba223648bfd3d87bf492319 Mon Sep 17 00:00:00 2001 +From: Ian Lin +Date: Mon, 18 Jul 2022 00:49:49 -0500 +Subject: [PATCH 32/49] non-upstream: SAE: disconnect after PMKSA cache expire + +If the dot11RSNAConfigPMKLifetime is set, skip the flow of postponing +the expiration in b0f457b6 and run disconnect flow. + +Signed-off-by: Ian Lin +--- + src/rsn_supp/pmksa_cache.c | 3 ++- + src/rsn_supp/wpa.c | 5 ++++- + src/rsn_supp/wpa_i.h | 1 + + 3 files changed, 7 insertions(+), 2 deletions(-) + +diff --git a/src/rsn_supp/pmksa_cache.c b/src/rsn_supp/pmksa_cache.c +index 0cd515982..8d517b5d4 100644 +--- a/src/rsn_supp/pmksa_cache.c ++++ b/src/rsn_supp/pmksa_cache.c +@@ -65,7 +65,8 @@ static void pmksa_cache_expire(void *eloop_ctx, void *timeout_ctx) + os_get_reltime(&now); + while (entry && entry->expiration <= now.sec) { + if (wpa_key_mgmt_sae(entry->akmp) && +- pmksa->is_current_cb(entry, pmksa->ctx)) { ++ pmksa->is_current_cb(entry, pmksa->ctx) && ++ !pmksa->sm->dot11RSNAConfigPMKLifetime_UserDef) { + /* Do not expire the currently used PMKSA entry for SAE + * since there is no convenient mechanism for + * reauthenticating during an association with SAE. The +diff --git a/src/rsn_supp/wpa.c b/src/rsn_supp/wpa.c +index 1f6401ef3..3eaa759f6 100644 +--- a/src/rsn_supp/wpa.c ++++ b/src/rsn_supp/wpa.c +@@ -2940,6 +2940,7 @@ struct wpa_sm * wpa_sm_init(struct wpa_sm_ctx *ctx) + sm->ctx = ctx; + + sm->dot11RSNAConfigPMKLifetime = 43200; ++ sm->dot11RSNAConfigPMKLifetime_UserDef = false; + sm->dot11RSNAConfigPMKReauthThreshold = 70; + sm->dot11RSNAConfigSATimeout = 60; + +@@ -3317,8 +3318,10 @@ int wpa_sm_set_param(struct wpa_sm *sm, enum wpa_sm_conf_params param, + + switch (param) { + case RSNA_PMK_LIFETIME: +- if (value > 0) ++ if (value > 0) { + sm->dot11RSNAConfigPMKLifetime = value; ++ sm->dot11RSNAConfigPMKLifetime_UserDef = true; ++ } + else + ret = -1; + break; +diff --git a/src/rsn_supp/wpa_i.h b/src/rsn_supp/wpa_i.h +index 3989c9ab3..f3843d7d4 100644 +--- a/src/rsn_supp/wpa_i.h ++++ b/src/rsn_supp/wpa_i.h +@@ -90,6 +90,7 @@ struct wpa_sm { + u8 bssid[ETH_ALEN]; + + unsigned int dot11RSNAConfigPMKLifetime; ++ bool dot11RSNAConfigPMKLifetime_UserDef; + unsigned int dot11RSNAConfigPMKReauthThreshold; + unsigned int dot11RSNAConfigSATimeout; + +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0034-wpa_supplicant-Set-PMKSA-to-driver-while-key-mgmt-is.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0034-wpa_supplicant-Set-PMKSA-to-driver-while-key-mgmt-is.patch new file mode 100644 index 000000000..743a338bb --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0034-wpa_supplicant-Set-PMKSA-to-driver-while-key-mgmt-is.patch @@ -0,0 +1,34 @@ +From da53435d4d11db827e3661be372e7b9773eaa842 Mon Sep 17 00:00:00 2001 +From: JasonHuang +Date: Thu, 8 Sep 2022 03:26:23 -0500 +Subject: [PATCH 34/49] wpa_supplicant: Set PMKSA to driver while key mgmt is + FT + +When the fast roaming is determined by the firmware, the +firmware needs the pmk to calculate PMK-R0name. + +Signed-off-by: JasonHuang +--- + src/rsn_supp/wpa.c | 6 ++++-- + 1 file changed, 4 insertions(+), 2 deletions(-) + +diff --git a/src/rsn_supp/wpa.c b/src/rsn_supp/wpa.c +index 3eaa759f6..ce01990e5 100644 +--- a/src/rsn_supp/wpa.c ++++ b/src/rsn_supp/wpa.c +@@ -1831,8 +1831,10 @@ static void wpa_supplicant_process_3_of_4(struct wpa_sm *sm, + * existing PMKSA entry after each 4-way handshake (i.e., new KCK/PMKID) + * to avoid unnecessary changes of PMKID while continuing to use the + * same PMK. */ +- if (sm->proto == WPA_PROTO_RSN && wpa_key_mgmt_suite_b(sm->key_mgmt) && +- !sm->cur_pmksa) { ++ /* Add ft case for driver base roaming. FW needs PMK to calculate ++ * PMK-R0name */ ++ if (sm->proto == WPA_PROTO_RSN && (wpa_key_mgmt_suite_b(sm->key_mgmt) || ++ wpa_key_mgmt_ft(sm->key_mgmt)) && !sm->cur_pmksa) { + struct rsn_pmksa_cache_entry *sa; + + sa = pmksa_cache_add(sm->pmksa, sm->pmk, sm->pmk_len, NULL, +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0035-nl80211-Set-NL80211_SCAN_FLAG_COLOCATED_6GHZ-in-scan.murata.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0035-nl80211-Set-NL80211_SCAN_FLAG_COLOCATED_6GHZ-in-scan.murata.patch new file mode 100644 index 000000000..3d0ad0b00 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0035-nl80211-Set-NL80211_SCAN_FLAG_COLOCATED_6GHZ-in-scan.murata.patch @@ -0,0 +1,69 @@ +From 2173b4648a59f7ab499b7974189f2ba025b6a25e Mon Sep 17 00:00:00 2001 +From: Tova Mussai +Date: Sun, 24 Apr 2022 12:57:52 +0300 +Subject: [PATCH 35/49] nl80211: Set NL80211_SCAN_FLAG_COLOCATED_6GHZ in scan + +Set NL80211_SCAN_FLAG_COLOCATED_6GHZ in the scan parameters to enable +scanning for co-located APs discovered based on neighbor reports from +the 2.4/5 GHz bands when not scanning passively. Do so only when +collocated scanning is not disabled by higher layer logic. + +Signed-off-by: Tova Mussai +Signed-off-by: Andrei Otcheretianski +Signed-off-by: Ilan Peer +Signed-off-by: Avraham Stern +--- + src/drivers/driver.h | 10 ++++++++++ + src/drivers/driver_nl80211_scan.c | 15 +++++++++++++++ + 2 files changed, 25 insertions(+) + +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index 2745b8340..d778b1eaa 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -651,6 +651,16 @@ struct wpa_driver_scan_params { + */ + unsigned int p2p_include_6ghz:1; + ++ /** ++ * non_coloc_6ghz - Force scanning of non-PSC 6 GHz channels ++ * ++ * If this is set, the driver should scan non-PSC channels from the ++ * scan request even if neighbor reports from 2.4/5 GHz APs did not ++ * report a co-located AP on these channels. The default is to scan ++ * non-PSC channels only if a co-located AP was reported on the channel. ++ */ ++ unsigned int non_coloc_6ghz:1; ++ + /* + * NOTE: Whenever adding new parameters here, please make sure + * wpa_scan_clone_params() and wpa_scan_free_params() get updated with +diff --git a/src/drivers/driver_nl80211_scan.c b/src/drivers/driver_nl80211_scan.c +index 131608480..1cd15469a 100644 +--- a/src/drivers/driver_nl80211_scan.c ++++ b/src/drivers/driver_nl80211_scan.c +@@ -203,6 +203,21 @@ nl80211_scan_common(struct i802_bss *bss, u8 cmd, + goto fail; + } + nla_nest_end(msg, ssids); ++ ++ /* ++ * If allowed, scan for 6 GHz APs that are reported by other ++ * APs. Note that if the flag is not set and 6 GHz channels are ++ * to be scanned, it is highly likely that non-PSC channels ++ * would be scanned passively (due to the Probe Request frame ++ * transmission restrictions mandated in IEEE Std 802.11ax-2021, ++ * 26.17.2.3 (Scanning in the 6 GHz band). Passive scanning of ++ * all non-PSC channels would take a significant amount of time. ++ */ ++ if (!params->non_coloc_6ghz) { ++ wpa_printf(MSG_DEBUG, ++ "nl80211: Scan co-located APs on 6 GHz"); ++ scan_flags |= NL80211_SCAN_FLAG_COLOCATED_6GHZ; ++ } + } else { + wpa_printf(MSG_DEBUG, "nl80211: Passive scan requested"); + } +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0037-Enabling-OWE-in-wpa_supplicant.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0037-Enabling-OWE-in-wpa_supplicant.patch new file mode 100644 index 000000000..27e02add8 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0037-Enabling-OWE-in-wpa_supplicant.patch @@ -0,0 +1,30 @@ +From 4a920e2446cff3f215614d63798e675bb5e25549 Mon Sep 17 00:00:00 2001 +From: Carter Chen +Date: Wed, 19 Oct 2022 03:29:39 -0500 +Subject: [PATCH 37/49] Enabling OWE in wpa_supplicant + +Enabling the compile options for OWE. + +Fixes: SWLINUX-2956 + +Signed-off-by: Carter Chen +--- + wpa_supplicant/defconfig_base | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base +index 611a23e3e..1c83967ae 100644 +--- a/wpa_supplicant/defconfig_base ++++ b/wpa_supplicant/defconfig_base +@@ -610,7 +610,7 @@ CONFIG_BGSCAN_LEARN=y + + # Opportunistic Wireless Encryption (OWE) + # Experimental implementation of draft-harkins-owe-07.txt +-#CONFIG_OWE=y ++CONFIG_OWE=y + + # Device Provisioning Protocol (DPP) + CONFIG_DPP=y +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0039-FT-Sync-nl80211-ext-feature-index.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0039-FT-Sync-nl80211-ext-feature-index.patch new file mode 100644 index 000000000..91ecd85cf --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0039-FT-Sync-nl80211-ext-feature-index.patch @@ -0,0 +1,34 @@ +From 7076f7634cc9d7a88f009c448ada307841b42a2a Mon Sep 17 00:00:00 2001 +From: JasonHuang +Date: Sun, 30 Oct 2022 21:58:34 -0500 +Subject: [PATCH 39/49] FT: Sync nl80211 ext feature index + +The backports-5.15.58 has been used. Supplicant should sync the +nl80211_ext_feature_index with backports to avoid unexpected fail. + +Signed-off-by: JasonHuang +--- + src/drivers/nl80211_copy.h | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/src/drivers/nl80211_copy.h b/src/drivers/nl80211_copy.h +index a3e889b35..db5b1503d 100644 +--- a/src/drivers/nl80211_copy.h ++++ b/src/drivers/nl80211_copy.h +@@ -6010,11 +6010,12 @@ enum nl80211_ext_feature_index { + NL80211_EXT_FEATURE_SAE_OFFLOAD_AP, + NL80211_EXT_FEATURE_FILS_DISCOVERY, + NL80211_EXT_FEATURE_UNSOL_BCAST_PROBE_RESP, +- NL80211_EXT_FEATURE_ROAM_OFFLOAD, + NL80211_EXT_FEATURE_BEACON_RATE_HE, + NL80211_EXT_FEATURE_SECURE_LTF, + NL80211_EXT_FEATURE_SECURE_RTT, + NL80211_EXT_FEATURE_PROT_RANGE_NEGO_AND_MEASURE, ++ NL80211_EXT_FEATURE_BSS_COLOR, ++ NL80211_EXT_FEATURE_ROAM_OFFLOAD, + + /* add new features before the definition below */ + NUM_NL80211_EXT_FEATURES, +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0040-nl80211-Introduce-a-vendor-header-for-vendor-NL-ifac.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0040-nl80211-Introduce-a-vendor-header-for-vendor-NL-ifac.patch new file mode 100644 index 000000000..4aa8a8767 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0040-nl80211-Introduce-a-vendor-header-for-vendor-NL-ifac.patch @@ -0,0 +1,126 @@ +From 62c82984916623e6e00053dcb148de71d24bdaf5 Mon Sep 17 00:00:00 2001 +From: Gokul Sivakumar +Date: Mon, 11 Jul 2022 11:15:25 +0530 +Subject: [PATCH 40/49] nl80211: Introduce a vendor header for vendor NL iface + to DRV with OUI_IFX + +So far, the proprietary configurations are done either through the private +IOCTL interface or through the vendor nl80211 CMD with OUI_BRCM. For easier +maintainance of the infineon's list of proprietary config interfaces across +DHD, FMAC, wpa_supplicant, hostapd, iw, etc, hereafter start using the new +vendor nl80211 CMD interface with OUI_IFX. + +Infineon OUI - 00:03:19 (Ref https://standards-oui.ieee.org/) + + +Signed-off-by: Gokul Sivakumar +Signed-off-by: Ian Lin +--- + src/common/ifx_vendor.h | 95 +++++++++++++++++++++++++++++++++++++++++ + 1 file changed, 95 insertions(+) + create mode 100644 src/common/ifx_vendor.h + +diff --git a/src/common/ifx_vendor.h b/src/common/ifx_vendor.h +new file mode 100644 +index 000000000..2ea9af0a7 +--- /dev/null ++++ b/src/common/ifx_vendor.h +@@ -0,0 +1,95 @@ ++/* ++ * Infineon: vendor OUI and specific assignments ++ * ++ * ©2022 Cypress Semiconductor Corporation (an Infineon company) ++ * or an affiliate of Cypress Semiconductor Corporation. All rights reserved. ++ * This software, including source code, documentation and related materials ++ * ("Software") is owned by Cypress Semiconductor Corporation or one of its ++ * affiliates ("Cypress") and is protected by and subject to ++ * worldwide patent protection (United States and foreign), ++ * United States copyright laws and international treaty provisions. ++ * Therefore, you may use this Software only as provided in the license agreement ++ * accompanying the software package from which you obtained this Software ("EULA"). ++ * If no EULA applies, Cypress hereby grants you a personal, non-exclusive, ++ * non-transferable license to copy, modify, and compile the Software source code ++ * solely for use in connection with Cypress's integrated circuit products. ++ * Any reproduction, modification, translation, compilation, or representation ++ * of this Software except as specified above is prohibited without ++ * the expresswritten permission of Cypress. ++ * Disclaimer: THIS SOFTWARE IS PROVIDED AS-IS, WITH NO WARRANTY OF ANY KIND, ++ * EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, NONINFRINGEMENT, ++ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. ++ * Cypress reserves the right to make changes to the Software without notice. ++ * Cypress does not assume any liability arising out of the application or ++ * use of the Software or any product or circuit described in the Software. ++ * Cypress does not authorize its products for use in any products where a malfunction ++ * or failure of the Cypress product may reasonably be expected to result in ++ * significant property damage, injury or death ("High Risk Product"). ++ * By including Cypress's product in a High Risk Product, the manufacturer ++ * of such system or application assumes all risk of such use and in doing so ++ * agrees to indemnify Cypress against all liability. ++ */ ++ ++#ifndef IFX_VENDOR_H ++#define IFX_VENDOR_H ++ ++/* ++ * This file is a registry of identifier assignments from the Infineon ++ * OUI 00:03:19 for purposes other than MAC address assignment. New identifiers ++ * can be assigned through normal review process for changes to the upstream ++ * hostap.git repository. ++ */ ++#define OUI_IFX 0x000319 ++ ++/* ++ * enum ifx_nl80211_vendor_subcmds - IFX nl80211 vendor command identifiers ++ * ++ * @IFX_VENDOR_SCMD_UNSPEC: Reserved value 0 ++ * ++ * @IFX_VENDOR_SCMD_FRAMEBURST: Vendor command to enable/disable Frameburst ++ * ++ * @IFX_VENDOR_SCMD_MUEDCA_OPT_ENABLE: Vendor command to enable/disable HE MU-EDCA opt ++ * ++ * @IFX_VENDOR_SCMD_LDPC_CAP: Vendor command enable/disable LDPC Capability ++ * ++ * @IFX_VENDOR_SCMD_AMSDU: Vendor command to enable/disable AMSDU on all the TID queues ++ * ++ * @IFX_VENDOR_SCMD_MAX: This acts as a the tail of cmds list. ++ * Make sure it located at the end of the list. ++ */ ++enum ifx_nl80211_vendor_subcmds { ++ /* ++ * TODO: IFX Vendor subcmd enum IDs between 1-10 are reserved ++ * to be be filled later with BRCM Vendor subcmds that are ++ * already used by IFX. ++ */ ++ IFX_VENDOR_SCMD_UNSPEC = 0, ++ /* Reserved 1-5 */ ++ IFX_VENDOR_SCMD_FRAMEBURST = 6, ++ /* Reserved 7-10 */ ++ IFX_VENDOR_SCMD_MUEDCA_OPT_ENABLE = 11, ++ IFX_VENDOR_SCMD_LDPC_CAP = 12, ++ IFX_VENDOR_SCMD_AMSDU = 13, ++ IFX_VENDOR_SCMD_MAX ++}; ++ ++/* ++ * enum ifx_vendor_attr - IFX nl80211 vendor attributes ++ * ++ * @IFX_VENDOR_ATTR_UNSPEC: Reserved value 0 ++ * ++ * @IFX_VENDOR_ATTR_MAX: This acts as a the tail of attrs list. ++ * Make sure it located at the end of the list. ++ */ ++enum ifx_vendor_attr { ++ /* ++ * TODO: IFX Vendor attr enum IDs between 0-10 are reserved ++ * to be filled later with BRCM Vendor attrs that are ++ * already used by IFX. ++ */ ++ IFX_VENDOR_ATTR_UNSPEC = 0, ++ /* Reserved 1-10 */ ++ IFX_VENDOR_ATTR_MAX = 11 ++}; ++ ++#endif /* IFX_VENDOR_H */ +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0041-add-support-to-offload-TWT-setup-request-handling-to.murata.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0041-add-support-to-offload-TWT-setup-request-handling-to.murata.patch new file mode 100644 index 000000000..cff1286f3 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0041-add-support-to-offload-TWT-setup-request-handling-to.murata.patch @@ -0,0 +1,484 @@ +From 013beb7bc5036bf627fce3707a7a83344ffa05aa Mon Sep 17 00:00:00 2001 +From: Gokul Sivakumar +Date: Mon, 11 Jul 2022 11:16:37 +0530 +Subject: [PATCH 41/49] add support to offload TWT setup request handling to + the Firmware + +With "TWT_SETUP" control sock cmd interface currently available in the +wpa_supplicant, it is currently possible to generate the TWT Setup Action +frame with the desired TWT session params like SP, SI, TWT Setup cmd type, +Flow ID, Trigger/Non-Trigger based, Un-Announced/Announced session types, +etc, without informing the TWT state machine in the Firmware. + +Now introduce a new TWT Offload code path and then when the TWT Setup is +triggerd either through the "$ wpa_cli twt_setup" or directly though the +control sock cmd "TWT_SETUP", construct a Vendor nl80211 cmd of type "TWT" +and pass it to the driver if it supports this new vendor cmd. The driver +then could inform the TWT module in the firmware through the corresponding +IOVAR to initiate a TWT Setup request while updating the TWT negotiation +handshake state machine as needed. + + +Signed-off-by: Gokul Sivakumar +Signed-off-by: Ian Lin +--- + src/common/ifx_vendor.h | 157 ++++++++++++++++++++++++++++++ + src/drivers/driver.h | 38 ++++++++ + src/drivers/driver_nl80211.c | 124 ++++++++++++++++++++++- + src/drivers/driver_nl80211.h | 3 + + src/drivers/driver_nl80211_capa.c | 12 +++ + wpa_supplicant/defconfig_base | 7 ++ + 6 files changed, 340 insertions(+), 1 deletions(-) + +diff --git a/src/common/ifx_vendor.h b/src/common/ifx_vendor.h +index 2ea9af0a7..a94694c93 100644 +--- a/src/common/ifx_vendor.h ++++ b/src/common/ifx_vendor.h +@@ -54,6 +54,9 @@ + * + * @IFX_VENDOR_SCMD_AMSDU: Vendor command to enable/disable AMSDU on all the TID queues + * ++ * @IFX_VENDOR_SCMD_TWT: Vendor subcommand to configure TWT ++ * Uses attributes defined in enum ifx_vendor_attr_twt. ++ * + * @IFX_VENDOR_SCMD_MAX: This acts as a the tail of cmds list. + * Make sure it located at the end of the list. + */ +@@ -70,6 +73,7 @@ enum ifx_nl80211_vendor_subcmds { + IFX_VENDOR_SCMD_MUEDCA_OPT_ENABLE = 11, + IFX_VENDOR_SCMD_LDPC_CAP = 12, + IFX_VENDOR_SCMD_AMSDU = 13, ++ IFX_VENDOR_SCMD_TWT = 14, + IFX_VENDOR_SCMD_MAX + }; + +@@ -92,4 +96,157 @@ enum ifx_vendor_attr { + IFX_VENDOR_ATTR_MAX = 11 + }; + ++/* ++ * enum ifx_vendor_attr_twt - Attributes for the TWT vendor command ++ * ++ * @IFX_VENDOR_ATTR_TWT_UNSPEC: Reserved value 0 ++ * ++ * @IFX_VENDOR_ATTR_TWT_OPER: To specify the type of TWT operation ++ * to be performed. Uses attributes defined in enum ifx_twt_oper. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAMS: Nester attributes representing the ++ * parameters configured for TWT. These parameters are defined in ++ * the enum ifx_vendor_attr_twt_param. ++ * ++ * @IFX_VENDOR_ATTR_TWT_MAX: This acts as a the tail of cmds list. ++ * Make sure it located at the end of the list. ++ */ ++enum ifx_vendor_attr_twt { ++ IFX_VENDOR_ATTR_TWT_UNSPEC, ++ IFX_VENDOR_ATTR_TWT_OPER, ++ IFX_VENDOR_ATTR_TWT_PARAMS, ++ IFX_VENDOR_ATTR_TWT_MAX ++}; ++ ++/* ++ * enum ifx_twt_oper - TWT operation to be specified using the vendor ++ * attribute IFX_VENDOR_ATTR_TWT_OPER ++ * ++ * @IFX_TWT_OPER_UNSPEC: Reserved value 0 ++ * ++ * @IFX_TWT_OPER_SETUP: Setup a TWT session. Required parameters are ++ * obtained through the nested attrs under IFX_VENDOR_ATTR_TWT_PARAMS. ++ * ++ * @IFX_TWT_OPER_MAX: This acts as a the tail of the list. ++ * Make sure it located at the end of the list. ++ */ ++enum ifx_twt_oper { ++ IFX_TWT_OPER_UNSPEC, ++ IFX_TWT_OPER_SETUP, ++ IFX_TWT_OPER_MAX ++}; ++ ++/* ++ * enum ifx_vendor_attr_twt_param - TWT parameters ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_UNSPEC: Reserved value 0 ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_NEGO_TYPE: Specifies the type of Negotiation to be ++ * done during Setup. The four possible types are ++ * 0 - Individual TWT Negotiation ++ * 1 - Wake TBTT Negotiation ++ * 2 - Broadcast TWT in Beacon ++ * 3 - Broadcast TWT Membership Negotiation ++ * ++ * The possible values are defined in the enum ifx_twt_param_nego_type ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_SETUP_CMD_TYPE: Specifies the type of TWT Setup frame ++ * when sent by the TWT Requesting STA ++ * 0 - Request ++ * 1 - Suggest ++ * 2 - Demand ++ * ++ * when sent by the TWT Responding STA. ++ * 3 - Grouping ++ * 4 - Accept ++ * 5 - Alternate ++ * 6 - Dictate ++ * 7 - Reject ++ * ++ * The possible values are defined in the enum ifx_twt_oper_setup_cmd_type. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_DIALOG_TOKEN: Dialog Token used by the TWT Requesting STA to ++ * identify the TWT Setup request/response transaction. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME: Target Wake Time. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION: Nominal Minimum TWT Wake Duration. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_EXPONENT: TWT Wake Interval Exponent. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_MANTISSA: TWT Wake Interval Mantissa. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_REQUESTOR: Specify this is a TWT Requesting / Responding STA. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_TRIGGER: Specify Trigger based / Non-Trigger based TWT Session. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_IMPLICIT: Specify Implicit / Explicit TWT session. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_FLOW_TYPE: Specify Un-Announced / Announced TWT session. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_FLOW_ID: Flow ID of an iTWT session. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_BCAST_TWT_ID: Brocast TWT ID of a bTWT session. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_PROTECTION: Specifies whether Tx within SP is protected. ++ * Set to 1 to indicate that TXOPs within the TWT SPs shall be initiated ++ * with a NAV protection mechanism, such as (MU) RTS/CTS or CTS-to-self frame; ++ * otherwise, it shall set it to 0. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_CHANNEL: TWT channel field which is set to 0, unless ++ * the HE STA sets up a subchannel selective transmission operation. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_TWT_INFO_FRAME_DISABLED: TWT Information frame RX handing ++ * disabled / enabled. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION_UNIT: Nominal Minimum TWT Wake Duration ++ * Unit. 0 represents unit in "256 usecs" and 1 represents unit in "TUs". ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_MAX: This acts as a the tail of the list. ++ * Make sure it located at the end of the list. ++ */ ++enum ifx_vendor_attr_twt_param { ++ IFX_VENDOR_ATTR_TWT_PARAM_UNSPEC, ++ IFX_VENDOR_ATTR_TWT_PARAM_NEGO_TYPE, ++ IFX_VENDOR_ATTR_TWT_PARAM_SETUP_CMD_TYPE, ++ IFX_VENDOR_ATTR_TWT_PARAM_DIALOG_TOKEN, ++ IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME, ++ IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION, ++ IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_EXPONENT, ++ IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_MANTISSA, ++ IFX_VENDOR_ATTR_TWT_PARAM_REQUESTOR, ++ IFX_VENDOR_ATTR_TWT_PARAM_TRIGGER, ++ IFX_VENDOR_ATTR_TWT_PARAM_IMPLICIT, ++ IFX_VENDOR_ATTR_TWT_PARAM_FLOW_TYPE, ++ IFX_VENDOR_ATTR_TWT_PARAM_FLOW_ID, ++ IFX_VENDOR_ATTR_TWT_PARAM_BCAST_TWT_ID, ++ IFX_VENDOR_ATTR_TWT_PARAM_PROTECTION, ++ IFX_VENDOR_ATTR_TWT_PARAM_CHANNEL, ++ IFX_VENDOR_ATTR_TWT_PARAM_TWT_INFO_FRAME_DISABLED, ++ IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION_UNIT, ++ IFX_VENDOR_ATTR_TWT_PARAM_MAX ++}; ++ ++enum ifx_twt_param_nego_type { ++ IFX_TWT_PARAM_NEGO_TYPE_INVALID = -1, ++ IFX_TWT_PARAM_NEGO_TYPE_ITWT = 0, ++ IFX_TWT_PARAM_NEGO_TYPE_WAKE_TBTT = 1, ++ IFX_TWT_PARAM_NEGO_TYPE_BTWT_IE_BCN = 2, ++ IFX_TWT_PARAM_NEGO_TYPE_BTWT = 3, ++ IFX_TWT_PARAM_NEGO_TYPE_MAX = 4 ++}; ++ ++enum ifx_twt_oper_setup_cmd_type { ++ IFX_TWT_OPER_SETUP_CMD_TYPE_INVALID = -1, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_REQUEST = 0, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_SUGGEST = 1, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_DEMAND = 2, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_GROUPING = 3, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_ACCEPT = 4, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_ALTERNATE = 5, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_DICTATE = 6, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_REJECT = 7, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_MAX = 8 ++}; ++ + #endif /* IFX_VENDOR_H */ +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index d778b1eaa..af4d0a5d0 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -26,6 +26,9 @@ + #include "pae/ieee802_1x_kay.h" + #endif /* CONFIG_MACSEC */ + #include "utils/list.h" ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#include "common/ifx_vendor.h" ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + + #define HOSTAPD_CHAN_DISABLED 0x00000001 + #define HOSTAPD_CHAN_NO_IR 0x00000002 +@@ -2519,6 +2522,31 @@ struct drv_acs_params { + int edmg_enabled; + }; + ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++struct drv_setup_twt_params { ++ u8 dtok; ++ u64 twt; ++ u8 min_twt; ++ u8 exponent; ++ u16 mantissa; ++ enum ifx_twt_oper_setup_cmd_type setup_cmd; ++ u8 requestor; ++ u8 trigger; ++ u8 implicit; ++ u8 flow_type; ++ u8 flow_id; ++ u8 bcast_twt_id; ++ u8 protection; ++ u8 twt_channel; ++ u8 control; ++ enum ifx_twt_param_nego_type negotiation_type; ++ u8 twt_info_frame_disabled; ++ u8 min_twt_unit; /* true - in TUs, false - in 256us */ ++}; ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ ++#endif /* CONFIG_DRIVER_NL80211_IFX */ ++ + struct wpa_bss_trans_info { + u8 mbo_transition_reason; + u8 n_candidates; +@@ -4630,6 +4658,16 @@ struct wpa_driver_ops { + const u8 *match, size_t match_len, + bool multicast); + #endif /* CONFIG_TESTING_OPTIONS */ ++ ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++ /** ++ * setup_twt - Setup a TWT session ++ * @params: Setup TWT params ++ */ ++ int (*setup_twt)(void *priv, struct drv_setup_twt_params *params); ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + }; + + /** +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index de58b17e1..fd6fe91a1 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -43,7 +43,9 @@ + #include "radiotap_iter.h" + #include "rfkill.h" + #include "driver_nl80211.h" +- ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#include "common/ifx_vendor.h" ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + + #ifndef NETLINK_CAP_ACK + #define NETLINK_CAP_ACK 10 +@@ -12284,6 +12286,121 @@ static int testing_nl80211_register_frame(void *priv, u16 type, + } + #endif /* CONFIG_TESTING_OPTIONS */ + ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++static int wpa_driver_nl80211_setup_twt(void *priv, struct drv_setup_twt_params *params) ++{ ++ struct i802_bss *bss = priv; ++ struct wpa_driver_nl80211_data *drv = bss->drv; ++ struct nl_msg *msg = NULL; ++ struct nlattr *data, *twt_param_attrs; ++ int ret = -1; ++ ++ if (!drv->ifx_twt_offload) ++ goto fail; ++ ++ if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_VENDOR)) || ++ nla_put_u32(msg, NL80211_ATTR_VENDOR_ID, OUI_IFX) || ++ nla_put_u32(msg, NL80211_ATTR_VENDOR_SUBCMD, IFX_VENDOR_SCMD_TWT)) ++ goto fail; ++ ++ data = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA); ++ if (!data) ++ goto fail; ++ ++ if (nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_OPER, IFX_TWT_OPER_SETUP)) ++ goto fail; ++ ++ twt_param_attrs = nla_nest_start(msg, IFX_VENDOR_ATTR_TWT_PARAMS); ++ if (!twt_param_attrs) ++ goto fail; ++ ++ if (nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_NEGO_TYPE, ++ params->negotiation_type) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_SETUP_CMD_TYPE, ++ params->setup_cmd) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_DIALOG_TOKEN, ++ params->dtok) || ++ ++ (params->twt && ++ nla_put_u64(msg, IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME, ++ params->twt)) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION, ++ params->min_twt) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_EXPONENT, ++ params->exponent) || ++ ++ nla_put_u16(msg, IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_MANTISSA, ++ params->mantissa) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_REQUESTOR, ++ params->requestor) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_TRIGGER, ++ params->trigger) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_IMPLICIT, ++ params->implicit) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_FLOW_TYPE, ++ params->flow_type) || ++ ++ (params->flow_id && ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_FLOW_ID, ++ params->flow_id)) || ++ ++ (params->bcast_twt_id && ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_BCAST_TWT_ID, ++ params->bcast_twt_id)) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_PROTECTION, ++ params->protection) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_CHANNEL, ++ params->twt_channel) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_TWT_INFO_FRAME_DISABLED, ++ params->twt_info_frame_disabled) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION_UNIT, ++ params->min_twt_unit)) ++ goto fail; ++ ++ nla_nest_end(msg, twt_param_attrs); ++ nla_nest_end(msg, data); ++ ++ wpa_printf(MSG_DEBUG, ++ "nl80211: TWT Setup: Neg Type: %d REQ Type: %d TWT: %lu min_twt: %d " ++ "exponent: %d mantissa: %d requestor: %d trigger: %d implicit: %d " ++ "flow_type: %d flow_id: %d bcast_twt_id: %d protection: %d " ++ "twt_channel: %d twt_info_frame_disabled: %d min_twt_unit: %d", ++ params->negotiation_type, params->setup_cmd, params->twt, ++ params->min_twt, params->exponent, params->mantissa, ++ params->requestor, params->trigger, params->implicit, ++ params->flow_type, params->flow_id, params->bcast_twt_id, ++ params->protection, params->twt_channel, ++ params->twt_info_frame_disabled, params->min_twt_unit); ++ ++ ret = send_and_recv_msgs(drv, msg, NULL, NULL, NULL, NULL); ++ if (ret < 0) { ++ wpa_printf(MSG_DEBUG, ++ "nl80211: TWT Setup: Failed to invoke driver " ++ "TWT setup function: %s", ++ strerror(-ret)); ++ } ++ ++ return ret; ++fail: ++ nl80211_nlmsg_clear(msg); ++ nlmsg_free(msg); ++ return ret; ++} ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + + const struct wpa_driver_ops wpa_driver_nl80211_ops = { + .name = "nl80211", +@@ -12429,4 +12546,9 @@ const struct wpa_driver_ops wpa_driver_nl80211_ops = { + #ifdef CONFIG_TESTING_OPTIONS + .register_frame = testing_nl80211_register_frame, + #endif /* CONFIG_TESTING_OPTIONS */ ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++ .setup_twt = wpa_driver_nl80211_setup_twt, ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + }; +diff --git a/src/drivers/driver_nl80211.h b/src/drivers/driver_nl80211.h +index 80d456472..f681afb41 100644 +--- a/src/drivers/driver_nl80211.h ++++ b/src/drivers/driver_nl80211.h +@@ -180,6 +180,9 @@ struct wpa_driver_nl80211_data { + unsigned int unsol_bcast_probe_resp:1; + unsigned int qca_do_acs:1; + unsigned int brcm_do_acs:1; ++#ifdef CONFIG_DRIVER_NL80211_IFX ++ unsigned int ifx_twt_offload:1; ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + + u64 vendor_scan_cookie; + u64 remain_on_chan_cookie; +diff --git a/src/drivers/driver_nl80211_capa.c b/src/drivers/driver_nl80211_capa.c +index d5cdafa9f..19d1569bf 100644 +--- a/src/drivers/driver_nl80211_capa.c ++++ b/src/drivers/driver_nl80211_capa.c +@@ -17,6 +17,9 @@ + #include "common/qca-vendor.h" + #include "common/qca-vendor-attr.h" + #include "common/brcm_vendor.h" ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#include "common/ifx_vendor.h" ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + #include "driver_nl80211.h" + + +@@ -1049,6 +1052,15 @@ static int wiphy_info_handler(struct nl_msg *msg, void *arg) + break; + } + #endif /* CONFIG_DRIVER_NL80211_BRCM */ ++ ++#ifdef CONFIG_DRIVER_NL80211_IFX ++ } else if (vinfo->vendor_id == OUI_IFX) { ++ switch (vinfo->subcmd) { ++ case IFX_VENDOR_SCMD_TWT: ++ drv->ifx_twt_offload = 1; ++ break; ++ } ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + } + + wpa_printf(MSG_DEBUG, "nl80211: Supported vendor command: vendor_id=0x%x subcmd=%u", +diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base +index 1c83967ae..bfaed5d91 100644 +--- a/wpa_supplicant/defconfig_base ++++ b/wpa_supplicant/defconfig_base +@@ -641,3 +641,10 @@ CONFIG_TESTING_OPTIONS=y + + CONFIG_SUITEB192=y + CONFIG_SUITEB=y ++ ++# Enable all IFX/Cypress changes ++CONFIG_DRIVER_NL80211_IFX=y ++ ++# Offload the TWT Session management to FW ++CONFIG_TWT_OFFLOAD_IFX=y ++ +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0042-add-support-to-offload-TWT-Teardown-request-handling.murata.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0042-add-support-to-offload-TWT-Teardown-request-handling.murata.patch new file mode 100644 index 000000000..9a97f17fb --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0042-add-support-to-offload-TWT-Teardown-request-handling.murata.patch @@ -0,0 +1,194 @@ +From 9a87c940340e1c665ce7172e7df147d53d1daabe Mon Sep 17 00:00:00 2001 +From: Gokul Sivakumar +Date: Mon, 11 Jul 2022 11:16:50 +0530 +Subject: [PATCH 42/49] add support to offload TWT Teardown request handling to + the Firmware + +With "TWT_TEARDOWN" control sock cmd interface currently available in the +wpa_supplicant,it is currently possible to generate the TWT Teardown Action +frame with the desired TWT session params like Negotiation Type, Flow ID, +Bcast TWT ID, etc, without informing the TWT state machine in the Firmware. + +Now introduce a new TWT Offload code path and then when the TWT Teardown is +triggered either through the "$ wpa_cli twt_teardown" or directly though +the control sock cmd "TWT_TEARDOWN", construct a Vendor nl80211 cmd of type +"TWT" and pass it to the driver if it supports this new vendor cmd. +The driver then could inform the TWT module in the firmware through the +corresponding IOVAR to initiate a TWT Teardown request while updating the +TWT negotiation handshake state machine as needed. + + +Signed-off-by: Gokul Sivakumar +Signed-off-by: Ian Lin +--- + src/common/ifx_vendor.h | 8 ++++ + src/drivers/driver.h | 14 +++++++ + src/drivers/driver_nl80211.c | 70 +++++++++++++++++++++++++++++++ + 3 files changed, 92 insertions(+) + +diff --git a/src/common/ifx_vendor.h b/src/common/ifx_vendor.h +index a94694c93..2e251c367 100644 +--- a/src/common/ifx_vendor.h ++++ b/src/common/ifx_vendor.h +@@ -127,12 +127,17 @@ enum ifx_vendor_attr_twt { + * @IFX_TWT_OPER_SETUP: Setup a TWT session. Required parameters are + * obtained through the nested attrs under IFX_VENDOR_ATTR_TWT_PARAMS. + * ++ * @IFX_TWT_OPER_TEARDOWN: Teardown the already negotiated TWT session. ++ * Required parameters are obtained through the nested attrs under ++ * IFX_VENDOR_ATTR_TWT_PARAMS. ++ * + * @IFX_TWT_OPER_MAX: This acts as a the tail of the list. + * Make sure it located at the end of the list. + */ + enum ifx_twt_oper { + IFX_TWT_OPER_UNSPEC, + IFX_TWT_OPER_SETUP, ++ IFX_TWT_OPER_TEARDOWN, + IFX_TWT_OPER_MAX + }; + +@@ -202,6 +207,8 @@ enum ifx_twt_oper { + * @IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION_UNIT: Nominal Minimum TWT Wake Duration + * Unit. 0 represents unit in "256 usecs" and 1 represents unit in "TUs". + * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_TEARDOWN_ALL_TWT: Teardown all negotiated TWT sessions. ++ * + * @IFX_VENDOR_ATTR_TWT_PARAM_MAX: This acts as a the tail of the list. + * Make sure it located at the end of the list. + */ +@@ -224,6 +231,7 @@ enum ifx_vendor_attr_twt_param { + IFX_VENDOR_ATTR_TWT_PARAM_CHANNEL, + IFX_VENDOR_ATTR_TWT_PARAM_TWT_INFO_FRAME_DISABLED, + IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION_UNIT, ++ IFX_VENDOR_ATTR_TWT_PARAM_TEARDOWN_ALL_TWT, + IFX_VENDOR_ATTR_TWT_PARAM_MAX + }; + +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index af4d0a5d0..4d810aaa8 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -2544,6 +2544,13 @@ struct drv_setup_twt_params { + u8 twt_info_frame_disabled; + u8 min_twt_unit; /* true - in TUs, false - in 256us */ + }; ++ ++struct drv_teardown_twt_params { ++ u8 negotiation_type; ++ u8 flow_id; ++ u8 bcast_twt_id; ++ u8 teardown_all_twt; ++}; + #endif /* CONFIG_TWT_OFFLOAD_IFX */ + #endif /* CONFIG_DRIVER_NL80211_IFX */ + +@@ -4666,8 +4673,15 @@ struct wpa_driver_ops { + * @params: Setup TWT params + */ + int (*setup_twt)(void *priv, struct drv_setup_twt_params *params); ++ ++ /** ++ * teardown_twt - Teardown the already negotiated TWT session ++ * @params: Teardown TWT params ++ */ ++ int (*teardown_twt)(void *priv, struct drv_teardown_twt_params *params); + #endif /* CONFIG_TWT_OFFLOAD_IFX */ + #endif /* CONFIG_DRIVER_NL80211_IFX */ ++ + }; + + /** +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index fd6fe91a1..8f8f7e2cd 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -12399,6 +12399,75 @@ fail: + nlmsg_free(msg); + return ret; + } ++ ++static int wpa_driver_nl80211_teardown_twt(void *priv, struct drv_teardown_twt_params *params) ++{ ++ struct i802_bss *bss = priv; ++ struct wpa_driver_nl80211_data *drv = bss->drv; ++ struct nl_msg *msg = NULL; ++ struct nlattr *data, *twt_param_attrs; ++ int ret = -1; ++ ++ if (!drv->ifx_twt_offload) ++ goto fail; ++ ++ if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_VENDOR)) || ++ nla_put_u32(msg, NL80211_ATTR_VENDOR_ID, OUI_IFX) || ++ nla_put_u32(msg, NL80211_ATTR_VENDOR_SUBCMD, IFX_VENDOR_SCMD_TWT)) ++ goto fail; ++ ++ data = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA); ++ if (!data) ++ goto fail; ++ ++ if (nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_OPER, IFX_TWT_OPER_TEARDOWN)) ++ goto fail; ++ ++ twt_param_attrs = nla_nest_start(msg, IFX_VENDOR_ATTR_TWT_PARAMS); ++ if (!twt_param_attrs) ++ goto fail; ++ ++ if (nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_NEGO_TYPE, ++ params->negotiation_type)) ++ goto fail; ++ ++ if (params->teardown_all_twt) { ++ if (nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_TEARDOWN_ALL_TWT, ++ params->teardown_all_twt)) ++ goto fail; ++ } else if (params->flow_id && ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_FLOW_ID, ++ params->flow_id)) { ++ goto fail; ++ } else if (params->bcast_twt_id && ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_BCAST_TWT_ID, ++ params->bcast_twt_id)) { ++ goto fail; ++ } ++ ++ nla_nest_end(msg, twt_param_attrs); ++ nla_nest_end(msg, data); ++ ++ wpa_printf(MSG_DEBUG, ++ "nl80211: TWT Teardown: Neg Type: %d teardown_all_twt: %d " ++ "flow_id: %d bcast_twt_id: %d", ++ params->negotiation_type, params->teardown_all_twt, ++ params->flow_id, params->bcast_twt_id); ++ ++ ret = send_and_recv_msgs(drv, msg, NULL, NULL, NULL, NULL); ++ if (ret) { ++ wpa_printf(MSG_DEBUG, ++ "nl80211: TWT Teardown: Failed to invoke driver " ++ "TWT teardown function: %s", ++ strerror(-ret)); ++ } ++ ++ return ret; ++fail: ++ nl80211_nlmsg_clear(msg); ++ nlmsg_free(msg); ++ return ret; ++} + #endif /* CONFIG_TWT_OFFLOAD_IFX */ + #endif /* CONFIG_DRIVER_NL80211_IFX */ + +@@ -12549,6 +12618,7 @@ const struct wpa_driver_ops wpa_driver_nl80211_ops = { + #ifdef CONFIG_DRIVER_NL80211_IFX + #ifdef CONFIG_TWT_OFFLOAD_IFX + .setup_twt = wpa_driver_nl80211_setup_twt, ++ .teardown_twt = wpa_driver_nl80211_teardown_twt, + #endif /* CONFIG_TWT_OFFLOAD_IFX */ + #endif /* CONFIG_DRIVER_NL80211_IFX */ + }; + + +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0043-Add-support-to-configure-TWT-of-a-session-using-offs.murata.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0043-Add-support-to-configure-TWT-of-a-session-using-offs.murata.patch new file mode 100644 index 000000000..6d5492898 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0043-Add-support-to-configure-TWT-of-a-session-using-offs.murata.patch @@ -0,0 +1,76 @@ +From e03937fecb74cf50d70721ea2a0b14fa5e12153a Mon Sep 17 00:00:00 2001 +From: Gokul Sivakumar +Date: Mon, 11 Jul 2022 11:17:04 +0530 +Subject: [PATCH 43/49] Add support to configure TWT of a session using offset + in microseconds + +Introduce a new cmd line argument "twt_offset=" in the existing list +of arguments supported in "$ wpa_cli twt_setup " cmd to set the TWT +in terms of offset from the current remote TSF. + +Example: To set a Target Wake Time of 102.4ms from the current remote TSF + +$ wpa_cli twt_setup setup_cmd=0 min_twt=80 mantissa=38400 exponent=3 \ + twt_offset=102400 trigger=0 implicit=1 flow_type=0 flow_id=5 \ + control=0 + + +Signed-off-by: Gokul Sivakumar +Signed-off-by: Ian Lin +--- + src/common/ifx_vendor.h | 3 +++ + src/drivers/driver.h | 1 + + src/drivers/driver_nl80211.c | 4 ++++ + 3 files changed, 8 insertions(+) + +diff --git a/src/common/ifx_vendor.h b/src/common/ifx_vendor.h +index 2e251c367..aa8e83bc7 100644 +--- a/src/common/ifx_vendor.h ++++ b/src/common/ifx_vendor.h +@@ -175,6 +175,8 @@ enum ifx_twt_oper { + * + * @IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME: Target Wake Time. + * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME_OFFSET: Target Wake Time Offset. ++ * + * @IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION: Nominal Minimum TWT Wake Duration. + * + * @IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_EXPONENT: TWT Wake Interval Exponent. +@@ -218,6 +220,7 @@ enum ifx_vendor_attr_twt_param { + IFX_VENDOR_ATTR_TWT_PARAM_SETUP_CMD_TYPE, + IFX_VENDOR_ATTR_TWT_PARAM_DIALOG_TOKEN, + IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME, ++ IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME_OFFSET, + IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION, + IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_EXPONENT, + IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_MANTISSA, +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index 4d810aaa8..23f599bef 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -2527,6 +2527,7 @@ struct drv_acs_params { + struct drv_setup_twt_params { + u8 dtok; + u64 twt; ++ u64 twt_offset; + u8 min_twt; + u8 exponent; + u16 mantissa; +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index 8f8f7e2cd..3d98e5943 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -12328,6 +12328,10 @@ static int wpa_driver_nl80211_setup_twt(void *priv, struct drv_setup_twt_params + nla_put_u64(msg, IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME, + params->twt)) || + ++ (params->twt_offset && ++ nla_put_u64(msg, IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME_OFFSET, ++ params->twt_offset)) || ++ + nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION, + params->min_twt) || + +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0048-Fix-associating-failed-when-PMK-lifetime-is-set-to-1.patch b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0048-Fix-associating-failed-when-PMK-lifetime-is-set-to-1.patch new file mode 100644 index 000000000..de1124705 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd/murata/0048-Fix-associating-failed-when-PMK-lifetime-is-set-to-1.patch @@ -0,0 +1,61 @@ +From 897917008b37a16985d0f1ae9d768c6450741574 Mon Sep 17 00:00:00 2001 +From: Owen Huang +Date: Wed, 30 Nov 2022 01:35:58 -0600 +Subject: [PATCH 48/49] Fix associating failed when PMK lifetime is set to 1 + +In WPA3 11.1 STAUT server certificate validation test +* set dot11RSNAConfigPMKLifetime to 1 +* set suppress_deauth_no_pmksa to 1 + +pmksa_cache_reauth and pmksa_cache_expire will expired right sway after +receiving the EAP success, and EAPOL start framce will be send to AP. +This scenario will cause the 4-way handshake failed. + +But wpa suulicant do not deauthenticate when PMKSA expired. +That means PMK's lifetime is infinite. +So there's not necessary to reauth with radius server to get the new PMK. + +Solution: use the same parameter to decide whether register timer to reauth. + +Fixed: SWLINUX-2883 +Signed-off-by: Owen Huang +--- + src/rsn_supp/pmksa_cache.c | 22 ++++++++++++++-------- + 1 file changed, 14 insertions(+), 8 deletions(-) + +diff --git a/src/rsn_supp/pmksa_cache.c b/src/rsn_supp/pmksa_cache.c +index 8d517b5d4..658390deb 100644 +--- a/src/rsn_supp/pmksa_cache.c ++++ b/src/rsn_supp/pmksa_cache.c +@@ -138,14 +138,20 @@ static void pmksa_cache_set_expiration(struct rsn_pmksa_cache *pmksa) + } + eloop_register_timeout(sec + 1, 0, pmksa_cache_expire, pmksa, NULL); + +- entry = pmksa->sm->cur_pmksa ? pmksa->sm->cur_pmksa : +- pmksa_cache_get(pmksa, pmksa->sm->bssid, NULL, NULL, 0); +- if (entry && !wpa_key_mgmt_sae(entry->akmp)) { +- sec = pmksa->pmksa->reauth_time - now.sec; +- if (sec < 0) +- sec = 0; +- eloop_register_timeout(sec, 0, pmksa_cache_reauth, pmksa, +- NULL); ++ /* If wpa suulicant do not deauthenticate when PMKSA expired. ++ * Means PMK's lifetime is infinite. So there's not necessary ++ * to reauth with radius server to get the new PMK. ++ */ ++ if (!pmksa->sm->suppress_deauth_no_pmksa) { ++ entry = pmksa->sm->cur_pmksa ? pmksa->sm->cur_pmksa : ++ pmksa_cache_get(pmksa, pmksa->sm->bssid, NULL, NULL, 0); ++ if (entry && !wpa_key_mgmt_sae(entry->akmp)) { ++ sec = pmksa->pmksa->reauth_time - now.sec; ++ if (sec < 0) ++ sec = 0; ++ eloop_register_timeout(sec, 0, pmksa_cache_reauth, pmksa, ++ NULL); ++ } + } + } + +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/hostapd/hostapd_%.bbappend b/meta-digi-dey/recipes-connectivity/hostapd/hostapd_%.bbappend index 92c8796d7..67e1fb75a 100644 --- a/meta-digi-dey/recipes-connectivity/hostapd/hostapd_%.bbappend +++ b/meta-digi-dey/recipes-connectivity/hostapd/hostapd_%.bbappend @@ -1,4 +1,4 @@ -# Copyright (C) 2016-2021 Digi International. +# Copyright (C) 2016-2023 Digi International. FILESEXTRAPATHS:prepend := "${THISDIR}/${BPN}:" @@ -8,6 +8,47 @@ SRC_URI:append = " \ ${@oe.utils.conditional('HAS_WIFI_VIRTWLANS', 'true', 'file://hostapd_wlan1.conf', '', d)} \ " +# Patch series from Murata release +MURATA_COMMON_PATCHES = " \ + file://murata/0003-nl80211-Report-connection-authorized-in-EVENT_ASSOC.patch \ + file://murata/0005-OpenSSL-Fix-build-with-OpenSSL-1.0.1.patch \ + file://murata/0006-nl80211-Check-SAE-authentication-offload-support.patch \ + file://murata/0007-SAE-Pass-SAE-password-on-connect-for-SAE-authenticat.murata.patch \ + file://murata/0008-nl80211-Support-4-way-handshake-offload-for-WPA-WPA2.patch \ + file://murata/0009-AP-Support-4-way-handshake-offload-for-WPA-WPA2-PSK.patch \ + file://murata/0010-nl80211-Support-SAE-authentication-offload-in-AP-mod.patch \ + file://murata/0011-SAE-Support-SAE-authentication-offload-in-AP-mode.patch \ + file://murata/0013-non-upstream-defconfig_base-Add-Infineon-default-con.patch \ + file://murata/0014-CVE_2019_9501-Fix-to-check-Invalid-GTK-IE-length-in-.patch \ + file://murata/0015-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes.murata.patch \ + file://murata/0016-SAE-Set-the-right-WPA-Versions-for-FT-SAE-key-manage.patch \ + file://murata/0017-wpa_supplicant-Support-WPA_KEY_MGMT_FT-for-eapol-off.murata.patch \ + file://murata/0018-wpa_supplicant-suppress-deauth-for-PMKSA-caching-dis.murata.patch \ + file://murata/0019-Fix-for-PMK-expiration-issue-through-supplicant.murata.patch \ + file://murata/0021-Avoid-deauthenticating-STA-if-the-reason-for-freeing.patch \ + file://murata/0022-wpa_supplicant-support-bgscan.patch \ + file://murata/0023-non-upstream-wl-cmd-create-interface-to-support-driv.murata.patch \ + file://murata/0024-non-upstream-wl-cmd-create-wl_do_cmd-as-an-entry-doi.patch \ + file://murata/0025-non-upstream-wl-cmd-create-ops-table-to-do-wl-comman.patch \ + file://murata/0026-non-upstream-wl-cmd-add-more-compile-flag.murata.patch \ + file://murata/0027-Fix-dpp-config-parameter-setting.patch \ + file://murata/0028-DPP-Resolving-failure-of-dpp-configurator-exchange-f.patch \ + file://murata/0029-Enabling-SUITEB192-and-SUITEB-compile-options.patch \ + file://murata/0030-DPP-Enabling-CLI_EDIT-option-for-enrollee-plus-respo.patch \ + file://murata/0032-non-upstream-SAE-disconnect-after-PMKSA-cache-expire.patch \ + file://murata/0034-wpa_supplicant-Set-PMKSA-to-driver-while-key-mgmt-is.patch \ + file://murata/0035-nl80211-Set-NL80211_SCAN_FLAG_COLOCATED_6GHZ-in-scan.murata.patch \ + file://murata/0037-Enabling-OWE-in-wpa_supplicant.patch \ + file://murata/0039-FT-Sync-nl80211-ext-feature-index.patch \ + file://murata/0040-nl80211-Introduce-a-vendor-header-for-vendor-NL-ifac.patch \ + file://murata/0041-add-support-to-offload-TWT-setup-request-handling-to.murata.patch \ + file://murata/0042-add-support-to-offload-TWT-Teardown-request-handling.murata.patch \ + file://murata/0043-Add-support-to-configure-TWT-of-a-session-using-offs.murata.patch \ + file://murata/0048-Fix-associating-failed-when-PMK-lifetime-is-set-to-1.patch \ +" + +SRC_URI:append:ccmp1 = " ${MURATA_COMMON_PATCHES}" + SYSTEMD_SERVICE:${PN}:append = " hostapd@.service" do_install:append() { diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0001-wpa_supplicant-Support-4-way-handshake-offload-for-F.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0001-wpa_supplicant-Support-4-way-handshake-offload-for-F.patch index bc7f94c72..1bd9705e5 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0001-wpa_supplicant-Support-4-way-handshake-offload-for-F.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0001-wpa_supplicant-Support-4-way-handshake-offload-for-F.patch @@ -1,6 +1,8 @@ +From 6b4bc7fbb9be8eb668985de04eb11618f9dc1781 Mon Sep 17 00:00:00 2001 From: Chung-Hsien Hsu Date: Tue, 29 Oct 2019 11:32:11 +0800 -Subject: [PATCH] wpa_supplicant: Support 4-way handshake offload for FT-EAP +Subject: [PATCH 01/49] wpa_supplicant: Support 4-way handshake offload for + FT-EAP Add support of 4-way handshake offload for FT-EAP. @@ -10,7 +12,7 @@ Signed-off-by: Chung-Hsien Hsu 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/wpa_supplicant/wpa_supplicant.c b/wpa_supplicant/wpa_supplicant.c -index d37a994f98a5..7e0e030b8081 100644 +index d37a994f9..7e0e030b8 100644 --- a/wpa_supplicant/wpa_supplicant.c +++ b/wpa_supplicant/wpa_supplicant.c @@ -3898,7 +3898,8 @@ static void wpas_start_assoc_cb(struct wpa_radio_work *work, int deinit) @@ -23,3 +25,6 @@ index d37a994f98a5..7e0e030b8081 100644 params.req_handshake_offload = 1; if (wpa_s->conf->key_mgmt_offload) { +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0002-wpa_supplicant-Notify-Neighbor-Report-for-driver-tri.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0002-wpa_supplicant-Notify-Neighbor-Report-for-driver-tri.patch index 0cb5bc3bf..2b924b185 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0002-wpa_supplicant-Notify-Neighbor-Report-for-driver-tri.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0002-wpa_supplicant-Notify-Neighbor-Report-for-driver-tri.patch @@ -1,7 +1,8 @@ +From 4d8eb3c7f31f66085dfb7f7652bf3b333d776896 Mon Sep 17 00:00:00 2001 From: Chung-Hsien Hsu Date: Tue, 29 Oct 2019 15:22:57 +0800 -Subject: [PATCH] wpa_supplicant: Notify Neighbor Report for driver-triggered - request +Subject: [PATCH 02/49] wpa_supplicant: Notify Neighbor Report for + driver-triggered request Sending a Neighbor Report request can be triggered by either supplicant or device driver. This patch adds the notification of incoming Neighbor @@ -13,7 +14,7 @@ Signed-off-by: Chung-Hsien Hsu 1 file changed, 83 insertions(+), 17 deletions(-) diff --git a/wpa_supplicant/rrm.c b/wpa_supplicant/rrm.c -index cf107ebaf639..16e3ab318250 100644 +index cf107ebaf..16e3ab318 100644 --- a/wpa_supplicant/rrm.c +++ b/wpa_supplicant/rrm.c @@ -52,6 +52,71 @@ void wpas_rrm_reset(struct wpa_supplicant *wpa_s) @@ -139,3 +140,6 @@ index cf107ebaf639..16e3ab318250 100644 #if defined(__CYGWIN__) || defined(CONFIG_NATIVE_WINDOWS) /* Workaround different, undefined for Windows, error codes used here */ +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0003-nl80211-Report-connection-authorized-in-EVENT_ASSOC.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0003-nl80211-Report-connection-authorized-in-EVENT_ASSOC.patch index 2ca3affc9..8de33d112 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0003-nl80211-Report-connection-authorized-in-EVENT_ASSOC.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0003-nl80211-Report-connection-authorized-in-EVENT_ASSOC.patch @@ -1,6 +1,7 @@ +From 21271c00b29db8c178aa704daaf665967e141d47 Mon Sep 17 00:00:00 2001 From: Chung-Hsien Hsu Date: Tue, 29 Oct 2019 15:55:21 +0800 -Subject: [PATCH] nl80211: Report connection authorized in EVENT_ASSOC +Subject: [PATCH 03/49] nl80211: Report connection authorized in EVENT_ASSOC When roaming in a network that requires 802.1X authentication, device driver could set the authorized flag if 4-way handshake offload or FT @@ -15,7 +16,7 @@ Signed-off-by: Chung-Hsien Hsu 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/src/drivers/driver_nl80211_event.c b/src/drivers/driver_nl80211_event.c -index 0f0a01d0180b..fe91fff908ea 100644 +index 0f0a01d01..fe91fff90 100644 --- a/src/drivers/driver_nl80211_event.c +++ b/src/drivers/driver_nl80211_event.c @@ -557,7 +557,7 @@ static void mlme_event_connect(struct wpa_driver_nl80211_data *drv, @@ -37,3 +38,6 @@ index 0f0a01d0180b..fe91fff908ea 100644 tb[NL80211_ATTR_FILS_KEK], NULL, tb[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM], +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0004-wpa_supplicant-Add-PMKSA-cache-for-802.1X-4-way-hand.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0004-wpa_supplicant-Add-PMKSA-cache-for-802.1X-4-way-hand.patch index dcaeca215..0f9876dfc 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0004-wpa_supplicant-Add-PMKSA-cache-for-802.1X-4-way-hand.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0004-wpa_supplicant-Add-PMKSA-cache-for-802.1X-4-way-hand.patch @@ -1,6 +1,8 @@ +From 578eb72569a03cdd608cf384911d46eb372c583e Mon Sep 17 00:00:00 2001 From: Chung-Hsien Hsu Date: Tue, 29 Oct 2019 16:05:49 +0800 -Subject: [PATCH] wpa_supplicant: Add PMKSA cache for 802.1X 4-way handshake +Subject: [PATCH 04/49] wpa_supplicant: Add PMKSA cache for 802.1X 4-way + handshake Add PMKSA cache and set PMK to the driver for 802.1X 4-way handshake offload. @@ -11,7 +13,7 @@ Signed-off-by: Chung-Hsien Hsu 1 file changed, 36 insertions(+), 23 deletions(-) diff --git a/wpa_supplicant/wpas_glue.c b/wpa_supplicant/wpas_glue.c -index 17fc05bcbdab..0cffe52fa9be 100644 +index 17fc05bcb..0cffe52fa 100644 --- a/wpa_supplicant/wpas_glue.c +++ b/wpa_supplicant/wpas_glue.c @@ -12,6 +12,7 @@ @@ -100,3 +102,6 @@ index 17fc05bcbdab..0cffe52fa9be 100644 } wpa_hexdump_key(MSG_DEBUG, "RSN: Configure PMK for driver-based 4-way " +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0005-OpenSSL-Fix-build-with-OpenSSL-1.0.1.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0005-OpenSSL-Fix-build-with-OpenSSL-1.0.1.patch index c19ba0779..879bc9ba7 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0005-OpenSSL-Fix-build-with-OpenSSL-1.0.1.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0005-OpenSSL-Fix-build-with-OpenSSL-1.0.1.patch @@ -1,6 +1,7 @@ +From 78e7373ad2cf51a881a12e55c3db01580932539e Mon Sep 17 00:00:00 2001 From: Chung-Hsien Hsu Date: Fri, 8 Nov 2019 13:23:05 -0600 -Subject: [PATCH] OpenSSL: Fix build with OpenSSL 1.0.1 +Subject: [PATCH 05/49] OpenSSL: Fix build with OpenSSL 1.0.1 The openssl_debug_dump_certificate_chains() implementation used SSL_CERT_SET_FIRST and SSL_CERT_SET_NEXT, which were added in OpenSSL @@ -12,7 +13,7 @@ Signed-off-by: Chung-Hsien Hsu 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/crypto/tls_openssl.c b/src/crypto/tls_openssl.c -index c9e00b3af855..9e5b48a9c18b 100644 +index c9e00b3af..9e5b48a9c 100644 --- a/src/crypto/tls_openssl.c +++ b/src/crypto/tls_openssl.c @@ -5410,7 +5410,8 @@ static void openssl_debug_dump_certificates(SSL_CTX *ssl_ctx) @@ -25,3 +26,6 @@ index c9e00b3af855..9e5b48a9c18b 100644 int res; for (res = SSL_CTX_set_current_cert(ssl_ctx, SSL_CERT_SET_FIRST); +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0006-nl80211-Check-SAE-authentication-offload-support.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0006-nl80211-Check-SAE-authentication-offload-support.patch index a3f4285ba..9be859305 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0006-nl80211-Check-SAE-authentication-offload-support.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0006-nl80211-Check-SAE-authentication-offload-support.patch @@ -1,6 +1,7 @@ +From f6eed1d9e56502fd8cbab309e94f9787795c3e35 Mon Sep 17 00:00:00 2001 From: Chung-Hsien Hsu Date: Tue, 29 Oct 2019 17:13:27 +0800 -Subject: [PATCH] nl80211: Check SAE authentication offload support +Subject: [PATCH 06/49] nl80211: Check SAE authentication offload support Set WPA_DRIVER_FLAGS2_SAE_OFFLOAD flag if driver indicates SAE authentication offload support. @@ -12,7 +13,7 @@ Signed-off-by: Chung-Hsien Hsu 2 files changed, 6 insertions(+) diff --git a/src/drivers/driver.h b/src/drivers/driver.h -index d3312a34d8f8..c563317d1ffc 100644 +index d3312a34d..c563317d1 100644 --- a/src/drivers/driver.h +++ b/src/drivers/driver.h @@ -2027,6 +2027,8 @@ struct wpa_driver_capa { @@ -25,7 +26,7 @@ index d3312a34d8f8..c563317d1ffc 100644 #define FULL_AP_CLIENT_STATE_SUPP(drv_flags) \ diff --git a/src/drivers/driver_nl80211_capa.c b/src/drivers/driver_nl80211_capa.c -index 83868b78e6f0..a443b7c873f7 100644 +index 83868b78e..a443b7c87 100644 --- a/src/drivers/driver_nl80211_capa.c +++ b/src/drivers/driver_nl80211_capa.c @@ -594,6 +594,10 @@ static void wiphy_info_ext_feature_flags(struct wiphy_info_data *info, @@ -39,3 +40,6 @@ index 83868b78e6f0..a443b7c873f7 100644 if (ext_feature_isset(ext_features, len, NL80211_EXT_FEATURE_MFP_OPTIONAL)) capa->flags |= WPA_DRIVER_FLAGS_MFP_OPTIONAL; +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0007-SAE-Pass-SAE-password-on-connect-for-SAE-authenticat.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0007-SAE-Pass-SAE-password-on-connect-for-SAE-authenticat.patch index a0d0c8d92..4be8a4662 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0007-SAE-Pass-SAE-password-on-connect-for-SAE-authenticat.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0007-SAE-Pass-SAE-password-on-connect-for-SAE-authenticat.patch @@ -1,7 +1,8 @@ +From 417097c87d7027ad319d7e8c9931deb666779533 Mon Sep 17 00:00:00 2001 From: Chung-Hsien Hsu Date: Tue, 29 Oct 2019 17:22:18 +0800 -Subject: [PATCH] SAE: Pass SAE password on connect for SAE authentication - offload support +Subject: [PATCH 07/49] SAE: Pass SAE password on connect for SAE + authentication offload support Pass SAE password on connect if driver advertises SAE authentication offload support. @@ -14,7 +15,7 @@ Signed-off-by: Chung-Hsien Hsu 3 files changed, 46 insertions(+), 3 deletions(-) diff --git a/src/drivers/driver.h b/src/drivers/driver.h -index c563317d1ffc..7cfa92ed8523 100644 +index c563317d1..7cfa92ed8 100644 --- a/src/drivers/driver.h +++ b/src/drivers/driver.h @@ -1014,6 +1014,14 @@ struct wpa_driver_associate_params { @@ -33,7 +34,7 @@ index c563317d1ffc..7cfa92ed8523 100644 * drop_unencrypted - Enable/disable unencrypted frame filtering * diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c -index aec179ac38cf..91e8d44d8329 100644 +index aec179ac3..91e8d44d8 100644 --- a/src/drivers/driver_nl80211.c +++ b/src/drivers/driver_nl80211.c @@ -6173,8 +6173,12 @@ static int nl80211_connect_common(struct wpa_driver_nl80211_data *drv, @@ -84,7 +85,7 @@ index aec179ac38cf..91e8d44d8329 100644 wpa_printf(MSG_DEBUG, " * Leave out Auth Type for automatic " "selection"); diff --git a/wpa_supplicant/wpa_supplicant.c b/wpa_supplicant/wpa_supplicant.c -index 7e0e030b8081..a0fb73f43ab3 100644 +index 7e0e030b8..a0fb73f43 100644 --- a/wpa_supplicant/wpa_supplicant.c +++ b/wpa_supplicant/wpa_supplicant.c @@ -1537,7 +1537,8 @@ int wpa_supplicant_set_suites(struct wpa_supplicant *wpa_s, @@ -116,3 +117,6 @@ index 7e0e030b8081..a0fb73f43ab3 100644 params.drop_unencrypted = use_crypt; params.mgmt_frame_protection = wpas_get_ssid_pmf(wpa_s, ssid); +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0008-nl80211-Support-4-way-handshake-offload-for-WPA-WPA2.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0008-nl80211-Support-4-way-handshake-offload-for-WPA-WPA2.patch index 949988d3e..43b4e31f3 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0008-nl80211-Support-4-way-handshake-offload-for-WPA-WPA2.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0008-nl80211-Support-4-way-handshake-offload-for-WPA-WPA2.patch @@ -1,7 +1,8 @@ +From 0bdd3f507d5dc92e42c72df7f4b79ffdab514fe1 Mon Sep 17 00:00:00 2001 From: Chung-Hsien Hsu Date: Tue, 10 Dec 2019 14:02:39 -0600 -Subject: [PATCH] nl80211: Support 4-way handshake offload for WPA/WPA2-PSK in - AP mode +Subject: [PATCH 08/49] nl80211: Support 4-way handshake offload for + WPA/WPA2-PSK in AP mode If driver advertises support for WPA/WPA2-PSK 4-way handshake offload in AP mode, set WPA_DRIVER_FLAGS2_4WAY_HANDSHAKE_AP_PSK flag and pass PSK @@ -15,7 +16,7 @@ Signed-off-by: Chung-Hsien Hsu 3 files changed, 39 insertions(+), 3 deletions(-) diff --git a/src/drivers/driver.h b/src/drivers/driver.h -index 7cfa92ed8523..a42ec5e1fac5 100644 +index 7cfa92ed8..a42ec5e1f 100644 --- a/src/drivers/driver.h +++ b/src/drivers/driver.h @@ -1590,6 +1590,27 @@ struct wpa_driver_ap_params { @@ -77,7 +78,7 @@ index 7cfa92ed8523..a42ec5e1fac5 100644 #define FULL_AP_CLIENT_STATE_SUPP(drv_flags) \ diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c -index 91e8d44d8329..f228a071596f 100644 +index 91e8d44d8..f228a0715 100644 --- a/src/drivers/driver_nl80211.c +++ b/src/drivers/driver_nl80211.c @@ -4677,6 +4677,14 @@ static int wpa_driver_nl80211_set_ap(void *priv, @@ -96,7 +97,7 @@ index 91e8d44d8329..f228a071596f 100644 wpa_hexdump_buf(MSG_DEBUG, "nl80211: beacon_ies", params->beacon_ies); diff --git a/src/drivers/driver_nl80211_capa.c b/src/drivers/driver_nl80211_capa.c -index a443b7c873f7..dc4988c7c383 100644 +index a443b7c87..dc4988c7c 100644 --- a/src/drivers/driver_nl80211_capa.c +++ b/src/drivers/driver_nl80211_capa.c @@ -594,6 +594,10 @@ static void wiphy_info_ext_feature_flags(struct wiphy_info_data *info, @@ -110,3 +111,6 @@ index a443b7c873f7..dc4988c7c383 100644 if (ext_feature_isset(ext_features, len, NL80211_EXT_FEATURE_SAE_OFFLOAD)) capa->flags2 |= WPA_DRIVER_FLAGS2_SAE_OFFLOAD; +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0009-AP-Support-4-way-handshake-offload-for-WPA-WPA2-PSK.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0009-AP-Support-4-way-handshake-offload-for-WPA-WPA2-PSK.patch index 43e96d37f..654fad8e6 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0009-AP-Support-4-way-handshake-offload-for-WPA-WPA2-PSK.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0009-AP-Support-4-way-handshake-offload-for-WPA-WPA2-PSK.patch @@ -1,6 +1,7 @@ +From 2f8529ec491389bdb41911edcf084bc643d7c9ee Mon Sep 17 00:00:00 2001 From: Chung-Hsien Hsu Date: Tue, 10 Dec 2019 14:03:57 -0600 -Subject: [PATCH] AP: Support 4-way handshake offload for WPA/WPA2-PSK +Subject: [PATCH 09/49] AP: Support 4-way handshake offload for WPA/WPA2-PSK Add support for WPA/WPA2-PSK 4-way handshake offload in AP mode. In this case, the 4-way handshake is handled by driver instead of user space. @@ -10,12 +11,12 @@ Signed-off-by: Chung-Hsien Hsu src/ap/beacon.c | 10 ++++++++++ src/ap/hostapd.c | 8 +++++++- src/ap/wpa_auth.c | 16 ++++++++++++++++ - src/ap/wpa_auth.h | 1 + + src/ap/wpa_auth.h | 2 ++ src/ap/wpa_auth_glue.c | 4 ++++ - 5 files changed, 38 insertions(+), 1 deletion(-) + 5 files changed, 39 insertions(+), 1 deletion(-) diff --git a/src/ap/beacon.c b/src/ap/beacon.c -index 8cd1c417043e..583b6836ec33 100644 +index 8cd1c4170..583b6836e 100644 --- a/src/ap/beacon.c +++ b/src/ap/beacon.c @@ -1753,6 +1753,16 @@ int ieee802_11_build_ap_params(struct hostapd_data *hapd, @@ -36,7 +37,7 @@ index 8cd1c417043e..583b6836ec33 100644 } diff --git a/src/ap/hostapd.c b/src/ap/hostapd.c -index 4b88641a2dde..464d8fa95fed 100644 +index 4b88641a2..464d8fa95 100644 --- a/src/ap/hostapd.c +++ b/src/ap/hostapd.c @@ -3203,6 +3203,8 @@ int hostapd_remove_iface(struct hapd_interfaces *interfaces, char *buf) @@ -62,7 +63,7 @@ index 4b88641a2dde..464d8fa95fed 100644 sta->auth_alg != WLAN_AUTH_FILS_SK_PFS && sta->auth_alg != WLAN_AUTH_FILS_PK && diff --git a/src/ap/wpa_auth.c b/src/ap/wpa_auth.c -index 6d60f262991b..4b506c1db373 100644 +index 6d60f2629..4b506c1db 100644 --- a/src/ap/wpa_auth.c +++ b/src/ap/wpa_auth.c @@ -696,6 +696,22 @@ int wpa_auth_sta_associated(struct wpa_authenticator *wpa_auth, @@ -89,19 +90,20 @@ index 6d60f262991b..4b506c1db373 100644 os_memset(&sm->key_replay, 0, sizeof(sm->key_replay)); sm->ReAuthenticationRequest = true; diff --git a/src/ap/wpa_auth.h b/src/ap/wpa_auth.h -index fe47723b9e6b..d610c14804a2 100644 +index fe47723b9..2f807893f 100644 --- a/src/ap/wpa_auth.h +++ b/src/ap/wpa_auth.h -@@ -273,6 +273,7 @@ struct wpa_auth_config { +@@ -273,6 +273,8 @@ struct wpa_auth_config { * PTK derivation regardless of advertised capabilities. */ bool force_kdk_derivation; ++ + int psk_4way_hs_offload; }; typedef enum { diff --git a/src/ap/wpa_auth_glue.c b/src/ap/wpa_auth_glue.c -index 3e992155395e..26de12b5b775 100644 +index 3e9921553..26de12b5b 100644 --- a/src/ap/wpa_auth_glue.c +++ b/src/ap/wpa_auth_glue.c @@ -1528,6 +1528,10 @@ int hostapd_setup_wpa(struct hostapd_data *hapd) @@ -115,3 +117,6 @@ index 3e992155395e..26de12b5b775 100644 hapd->wpa_auth = wpa_init(hapd->own_addr, &_conf, &cb, hapd); if (hapd->wpa_auth == NULL) { wpa_printf(MSG_ERROR, "WPA initialization failed."); +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0010-nl80211-Support-SAE-authentication-offload-in-AP-mod.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0010-nl80211-Support-SAE-authentication-offload-in-AP-mod.patch index e0cc5df98..1a3eef521 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0010-nl80211-Support-SAE-authentication-offload-in-AP-mod.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0010-nl80211-Support-SAE-authentication-offload-in-AP-mod.patch @@ -1,6 +1,7 @@ +From 89d2f8b07c948cc5fbe8767948128f487eae2ed5 Mon Sep 17 00:00:00 2001 From: Chung-Hsien Hsu Date: Tue, 10 Dec 2019 14:05:16 -0600 -Subject: [PATCH] nl80211: Support SAE authentication offload in AP mode +Subject: [PATCH 10/49] nl80211: Support SAE authentication offload in AP mode If driver advertises support for SAE authentication offload, pass SAE password in NL80211_CMD_NEW_BEACON command for AP mode. @@ -13,7 +14,7 @@ Signed-off-by: Chung-Hsien Hsu 3 files changed, 42 insertions(+), 2 deletions(-) diff --git a/src/drivers/driver.h b/src/drivers/driver.h -index a42ec5e1fac5..45260e8c5e30 100644 +index a42ec5e1f..45260e8c5 100644 --- a/src/drivers/driver.h +++ b/src/drivers/driver.h @@ -1611,6 +1611,14 @@ struct wpa_driver_ap_params { @@ -46,7 +47,7 @@ index a42ec5e1fac5..45260e8c5e30 100644 #define FULL_AP_CLIENT_STATE_SUPP(drv_flags) \ diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c -index f228a071596f..b6afc6e7aa61 100644 +index f228a0715..b6afc6e7a 100644 --- a/src/drivers/driver_nl80211.c +++ b/src/drivers/driver_nl80211.c @@ -4630,8 +4630,13 @@ static int wpa_driver_nl80211_set_ap(void *priv, @@ -93,7 +94,7 @@ index f228a071596f..b6afc6e7aa61 100644 wpa_hexdump_buf(MSG_DEBUG, "nl80211: beacon_ies", params->beacon_ies); diff --git a/src/drivers/driver_nl80211_capa.c b/src/drivers/driver_nl80211_capa.c -index dc4988c7c383..ae6029a922b8 100644 +index dc4988c7c..ae6029a92 100644 --- a/src/drivers/driver_nl80211_capa.c +++ b/src/drivers/driver_nl80211_capa.c @@ -602,6 +602,10 @@ static void wiphy_info_ext_feature_flags(struct wiphy_info_data *info, @@ -107,3 +108,6 @@ index dc4988c7c383..ae6029a922b8 100644 if (ext_feature_isset(ext_features, len, NL80211_EXT_FEATURE_MFP_OPTIONAL)) capa->flags |= WPA_DRIVER_FLAGS_MFP_OPTIONAL; +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0011-SAE-Support-SAE-authentication-offload-in-AP-mode.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0011-SAE-Support-SAE-authentication-offload-in-AP-mode.patch index 760f91ca3..6667844f7 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0011-SAE-Support-SAE-authentication-offload-in-AP-mode.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0011-SAE-Support-SAE-authentication-offload-in-AP-mode.patch @@ -1,6 +1,7 @@ +From dfa364f9970f1d88782cc9a9b7292afadbf2358b Mon Sep 17 00:00:00 2001 From: Chung-Hsien Hsu Date: Tue, 10 Dec 2019 14:06:20 -0600 -Subject: [PATCH] SAE: Support SAE authentication offload in AP mode +Subject: [PATCH 11/49] SAE: Support SAE authentication offload in AP mode Add support for SAE authentication offload in AP mode. In this case, the SAE authentication process is handled by driver instead of user space. @@ -14,7 +15,7 @@ Signed-off-by: Chung-Hsien Hsu 4 files changed, 22 insertions(+), 1 deletion(-) diff --git a/src/ap/beacon.c b/src/ap/beacon.c -index 583b6836ec33..e2d7c697014d 100644 +index 583b6836e..e2d7c6970 100644 --- a/src/ap/beacon.c +++ b/src/ap/beacon.c @@ -1763,6 +1763,17 @@ int ieee802_11_build_ap_params(struct hostapd_data *hapd, @@ -36,12 +37,12 @@ index 583b6836ec33..e2d7c697014d 100644 } diff --git a/src/ap/wpa_auth.h b/src/ap/wpa_auth.h -index d610c14804a2..140147e79f31 100644 +index 2f807893f..ff36cfe95 100644 --- a/src/ap/wpa_auth.h +++ b/src/ap/wpa_auth.h -@@ -274,6 +274,9 @@ struct wpa_auth_config { - */ +@@ -275,6 +275,9 @@ struct wpa_auth_config { bool force_kdk_derivation; + int psk_4way_hs_offload; +#ifdef CONFIG_SAE + int sae_offload; @@ -50,7 +51,7 @@ index d610c14804a2..140147e79f31 100644 typedef enum { diff --git a/src/ap/wpa_auth_glue.c b/src/ap/wpa_auth_glue.c -index 26de12b5b775..c8dee2aef347 100644 +index 26de12b5b..c8dee2aef 100644 --- a/src/ap/wpa_auth_glue.c +++ b/src/ap/wpa_auth_glue.c @@ -1532,6 +1532,11 @@ int hostapd_setup_wpa(struct hostapd_data *hapd) @@ -66,7 +67,7 @@ index 26de12b5b775..c8dee2aef347 100644 if (hapd->wpa_auth == NULL) { wpa_printf(MSG_ERROR, "WPA initialization failed."); diff --git a/src/ap/wpa_auth_ie.c b/src/ap/wpa_auth_ie.c -index 524922e4e686..30de0c19c9f3 100644 +index 524922e4e..30de0c19c 100644 --- a/src/ap/wpa_auth_ie.c +++ b/src/ap/wpa_auth_ie.c @@ -977,7 +977,9 @@ wpa_validate_wpa_ie(struct wpa_authenticator *wpa_auth, @@ -80,3 +81,6 @@ index 524922e4e686..30de0c19c9f3 100644 !sm->pmksa) { wpa_auth_vlogger(wpa_auth, sm->addr, LOGGER_DEBUG, "No PMKSA cache entry found for SAE"); +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0012-DPP-Do-more-condition-test-for-AKM-type-DPP-offload.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0012-DPP-Do-more-condition-test-for-AKM-type-DPP-offload.patch index d09ad25e2..fd8a89df6 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0012-DPP-Do-more-condition-test-for-AKM-type-DPP-offload.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0012-DPP-Do-more-condition-test-for-AKM-type-DPP-offload.patch @@ -1,6 +1,7 @@ +From 234dbe729a1041d93efc51b8467ac063b74b2c81 Mon Sep 17 00:00:00 2001 From: Kurt Lee Date: Mon, 18 May 2020 08:36:59 -0500 -Subject: [PATCH] DPP: Do more condition test for AKM type DPP offload. +Subject: [PATCH 12/49] DPP: Do more condition test for AKM type DPP offload. If supplicant recieves eapol frame with driver declared WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_PSK, supplicant will check AKM type @@ -13,7 +14,7 @@ Signed-off-by: Chung-Hsien Hsu 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/wpa_supplicant/wpa_supplicant.c b/wpa_supplicant/wpa_supplicant.c -index a0fb73f43ab3..f00dd57da3c1 100644 +index a0fb73f43..f00dd57da 100644 --- a/wpa_supplicant/wpa_supplicant.c +++ b/wpa_supplicant/wpa_supplicant.c @@ -5140,7 +5140,8 @@ void wpa_supplicant_rx_eapol(void *ctx, const u8 *src_addr, @@ -26,3 +27,6 @@ index a0fb73f43ab3..f00dd57da3c1 100644 wpa_sm_rx_eapol(wpa_s->wpa, src_addr, buf, len); else if (wpa_key_mgmt_wpa_ieee8021x(wpa_s->key_mgmt)) { /* +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0013-non-upstream-defconfig_base-Add-Infineon-default-con.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0013-non-upstream-defconfig_base-Add-Infineon-default-con.patch index c76c8f85b..dff70c0d3 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0013-non-upstream-defconfig_base-Add-Infineon-default-con.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0013-non-upstream-defconfig_base-Add-Infineon-default-con.patch @@ -1,23 +1,432 @@ +From 69d18183a1df9e72371e33937c91af5b5b79a110 Mon Sep 17 00:00:00 2001 From: Chung-Hsien Hsu Date: Mon, 2 Aug 2021 14:15:06 -0500 -Subject: [PATCH] non-upstream: defconfig_base: Add Infineon default - configuration (first) +Subject: [PATCH 13/49] non-upstream: defconfig_base: Add Infineon default + configuration Add Infineon default configuration files (defconfig_base). -First part: changes not touching 'hostapd' directory. - Signed-off-by: Kurt Lee Signed-off-by: Chung-Hsien Hsu -Signed-off-by: Javier Viguera --- + hostapd/defconfig_base | 403 +++++++++++++++++++++ wpa_supplicant/defconfig_base | 635 ++++++++++++++++++++++++++++++++++ - 1 file changed, 635 insertions(+) + 2 files changed, 1038 insertions(+) + create mode 100644 hostapd/defconfig_base create mode 100644 wpa_supplicant/defconfig_base +diff --git a/hostapd/defconfig_base b/hostapd/defconfig_base +new file mode 100644 +index 000000000..9dcf7848d +--- /dev/null ++++ b/hostapd/defconfig_base +@@ -0,0 +1,403 @@ ++# Example hostapd build time configuration ++# ++# This file lists the configuration options that are used when building the ++# hostapd binary. All lines starting with # are ignored. Configuration option ++# lines must be commented out complete, if they are not to be included, i.e., ++# just setting VARIABLE=n is not disabling that variable. ++# ++# This file is included in Makefile, so variables like CFLAGS and LIBS can also ++# be modified from here. In most cass, these lines should use += in order not ++# to override previous values of the variables. ++ ++# Driver interface for Host AP driver ++CONFIG_DRIVER_HOSTAP=y ++ ++# Driver interface for wired authenticator ++#CONFIG_DRIVER_WIRED=y ++ ++# Driver interface for drivers using the nl80211 kernel interface ++CONFIG_DRIVER_NL80211=y ++ ++# QCA vendor extensions to nl80211 ++#CONFIG_DRIVER_NL80211_QCA=y ++ ++# driver_nl80211.c requires libnl. If you are compiling it yourself ++# you may need to point hostapd to your version of libnl. ++# ++#CFLAGS += -I$ ++#LIBS += -L$ ++ ++# Use libnl v2.0 (or 3.0) libraries. ++#CONFIG_LIBNL20=y ++ ++# Use libnl 3.2 libraries (if this is selected, CONFIG_LIBNL20 is ignored) ++CONFIG_LIBNL32=y ++ ++ ++# Driver interface for FreeBSD net80211 layer (e.g., Atheros driver) ++#CONFIG_DRIVER_BSD=y ++#CFLAGS += -I/usr/local/include ++#LIBS += -L/usr/local/lib ++#LIBS_p += -L/usr/local/lib ++#LIBS_c += -L/usr/local/lib ++ ++# Driver interface for no driver (e.g., RADIUS server only) ++#CONFIG_DRIVER_NONE=y ++ ++# WPA2/IEEE 802.11i RSN pre-authentication ++CONFIG_RSN_PREAUTH=y ++ ++# Support Operating Channel Validation ++#CONFIG_OCV=y ++ ++# Integrated EAP server ++CONFIG_EAP=y ++ ++# EAP Re-authentication Protocol (ERP) in integrated EAP server ++CONFIG_ERP=y ++ ++# EAP-MD5 for the integrated EAP server ++CONFIG_EAP_MD5=y ++ ++# EAP-TLS for the integrated EAP server ++CONFIG_EAP_TLS=y ++ ++# EAP-MSCHAPv2 for the integrated EAP server ++CONFIG_EAP_MSCHAPV2=y ++ ++# EAP-PEAP for the integrated EAP server ++CONFIG_EAP_PEAP=y ++ ++# EAP-GTC for the integrated EAP server ++CONFIG_EAP_GTC=y ++ ++# EAP-TTLS for the integrated EAP server ++CONFIG_EAP_TTLS=y ++ ++# EAP-SIM for the integrated EAP server ++#CONFIG_EAP_SIM=y ++ ++# EAP-AKA for the integrated EAP server ++#CONFIG_EAP_AKA=y ++ ++# EAP-AKA' for the integrated EAP server ++# This requires CONFIG_EAP_AKA to be enabled, too. ++#CONFIG_EAP_AKA_PRIME=y ++ ++# EAP-PAX for the integrated EAP server ++#CONFIG_EAP_PAX=y ++ ++# EAP-PSK for the integrated EAP server (this is _not_ needed for WPA-PSK) ++#CONFIG_EAP_PSK=y ++ ++# EAP-pwd for the integrated EAP server (secure authentication with a password) ++#CONFIG_EAP_PWD=y ++ ++# EAP-SAKE for the integrated EAP server ++#CONFIG_EAP_SAKE=y ++ ++# EAP-GPSK for the integrated EAP server ++#CONFIG_EAP_GPSK=y ++# Include support for optional SHA256 cipher suite in EAP-GPSK ++#CONFIG_EAP_GPSK_SHA256=y ++ ++# EAP-FAST for the integrated EAP server ++#CONFIG_EAP_FAST=y ++ ++# EAP-TEAP for the integrated EAP server ++# Note: The current EAP-TEAP implementation is experimental and should not be ++# enabled for production use. The IETF RFC 7170 that defines EAP-TEAP has number ++# of conflicting statements and missing details and the implementation has ++# vendor specific workarounds for those and as such, may not interoperate with ++# any other implementation. This should not be used for anything else than ++# experimentation and interoperability testing until those issues has been ++# resolved. ++#CONFIG_EAP_TEAP=y ++ ++# Wi-Fi Protected Setup (WPS) ++CONFIG_WPS=y ++# Enable UPnP support for external WPS Registrars ++#CONFIG_WPS_UPNP=y ++# Enable WPS support with NFC config method ++#CONFIG_WPS_NFC=y ++ ++# EAP-IKEv2 ++#CONFIG_EAP_IKEV2=y ++ ++# Trusted Network Connect (EAP-TNC) ++#CONFIG_EAP_TNC=y ++ ++# EAP-EKE for the integrated EAP server ++#CONFIG_EAP_EKE=y ++ ++# PKCS#12 (PFX) support (used to read private key and certificate file from ++# a file that usually has extension .p12 or .pfx) ++CONFIG_PKCS12=y ++ ++# RADIUS authentication server. This provides access to the integrated EAP ++# server from external hosts using RADIUS. ++#CONFIG_RADIUS_SERVER=y ++ ++# Build IPv6 support for RADIUS operations ++CONFIG_IPV6=y ++ ++# IEEE Std 802.11r-2008 (Fast BSS Transition) ++CONFIG_IEEE80211R=y ++ ++# Use the hostapd's IEEE 802.11 authentication (ACL), but without ++# the IEEE 802.11 Management capability (e.g., FreeBSD/net80211) ++#CONFIG_DRIVER_RADIUS_ACL=y ++ ++# Wireless Network Management (IEEE Std 802.11v-2011) ++# Note: This is experimental and not complete implementation. ++#CONFIG_WNM=y ++ ++# IEEE 802.11ac (Very High Throughput) support ++CONFIG_IEEE80211AC=y ++ ++# IEEE 802.11ax HE support ++# Note: This is experimental and work in progress. The definitions are still ++# subject to change and this should not be expected to interoperate with the ++# final IEEE 802.11ax version. ++CONFIG_IEEE80211AX=y ++ ++# Remove debugging code that is printing out debug messages to stdout. ++# This can be used to reduce the size of the hostapd considerably if debugging ++# code is not needed. ++#CONFIG_NO_STDOUT_DEBUG=y ++ ++# Add support for writing debug log to a file: -f /tmp/hostapd.log ++# Disabled by default. ++CONFIG_DEBUG_FILE=y ++ ++# Send debug messages to syslog instead of stdout ++#CONFIG_DEBUG_SYSLOG=y ++ ++# Add support for sending all debug messages (regardless of debug verbosity) ++# to the Linux kernel tracing facility. This helps debug the entire stack by ++# making it easy to record everything happening from the driver up into the ++# same file, e.g., using trace-cmd. ++#CONFIG_DEBUG_LINUX_TRACING=y ++ ++# Remove support for RADIUS accounting ++#CONFIG_NO_ACCOUNTING=y ++ ++# Remove support for RADIUS ++#CONFIG_NO_RADIUS=y ++ ++# Remove support for VLANs ++#CONFIG_NO_VLAN=y ++ ++# Enable support for fully dynamic VLANs. This enables hostapd to ++# automatically create bridge and VLAN interfaces if necessary. ++#CONFIG_FULL_DYNAMIC_VLAN=y ++ ++# Use netlink-based kernel API for VLAN operations instead of ioctl() ++# Note: This requires libnl 3.1 or newer. ++#CONFIG_VLAN_NETLINK=y ++ ++# Remove support for dumping internal state through control interface commands ++# This can be used to reduce binary size at the cost of disabling a debugging ++# option. ++#CONFIG_NO_DUMP_STATE=y ++ ++# Enable tracing code for developer debugging ++# This tracks use of memory allocations and other registrations and reports ++# incorrect use with a backtrace of call (or allocation) location. ++#CONFIG_WPA_TRACE=y ++# For BSD, comment out these. ++#LIBS += -lexecinfo ++#LIBS_p += -lexecinfo ++#LIBS_c += -lexecinfo ++ ++# Use libbfd to get more details for developer debugging ++# This enables use of libbfd to get more detailed symbols for the backtraces ++# generated by CONFIG_WPA_TRACE=y. ++#CONFIG_WPA_TRACE_BFD=y ++# For BSD, comment out these. ++#LIBS += -lbfd -liberty -lz ++#LIBS_p += -lbfd -liberty -lz ++#LIBS_c += -lbfd -liberty -lz ++ ++# hostapd depends on strong random number generation being available from the ++# operating system. os_get_random() function is used to fetch random data when ++# needed, e.g., for key generation. On Linux and BSD systems, this works by ++# reading /dev/urandom. It should be noted that the OS entropy pool needs to be ++# properly initialized before hostapd is started. This is important especially ++# on embedded devices that do not have a hardware random number generator and ++# may by default start up with minimal entropy available for random number ++# generation. ++# ++# As a safety net, hostapd is by default trying to internally collect ++# additional entropy for generating random data to mix in with the data ++# fetched from the OS. This by itself is not considered to be very strong, but ++# it may help in cases where the system pool is not initialized properly. ++# However, it is very strongly recommended that the system pool is initialized ++# with enough entropy either by using hardware assisted random number ++# generator or by storing state over device reboots. ++# ++# hostapd can be configured to maintain its own entropy store over restarts to ++# enhance random number generation. This is not perfect, but it is much more ++# secure than using the same sequence of random numbers after every reboot. ++# This can be enabled with -e command line option. The specified ++# file needs to be readable and writable by hostapd. ++# ++# If the os_get_random() is known to provide strong random data (e.g., on ++# Linux/BSD, the board in question is known to have reliable source of random ++# data from /dev/urandom), the internal hostapd random pool can be disabled. ++# This will save some in binary size and CPU use. However, this should only be ++# considered for builds that are known to be used on devices that meet the ++# requirements described above. ++#CONFIG_NO_RANDOM_POOL=y ++ ++# Should we attempt to use the getrandom(2) call that provides more reliable ++# yet secure randomness source than /dev/random on Linux 3.17 and newer. ++# Requires glibc 2.25 to build, falls back to /dev/random if unavailable. ++#CONFIG_GETRANDOM=y ++ ++# Should we use poll instead of select? Select is used by default. ++#CONFIG_ELOOP_POLL=y ++ ++# Should we use epoll instead of select? Select is used by default. ++#CONFIG_ELOOP_EPOLL=y ++ ++# Should we use kqueue instead of select? Select is used by default. ++#CONFIG_ELOOP_KQUEUE=y ++ ++# Select TLS implementation ++# openssl = OpenSSL (default) ++# gnutls = GnuTLS ++# internal = Internal TLSv1 implementation (experimental) ++# linux = Linux kernel AF_ALG and internal TLSv1 implementation (experimental) ++# none = Empty template ++CONFIG_TLS=openssl ++CONFIG_TLS_ADD_DL=y ++ ++# TLS-based EAP methods require at least TLS v1.0. Newer version of TLS (v1.1) ++# can be enabled to get a stronger construction of messages when block ciphers ++# are used. ++#CONFIG_TLSV11=y ++ ++# TLS-based EAP methods require at least TLS v1.0. Newer version of TLS (v1.2) ++# can be enabled to enable use of stronger crypto algorithms. ++#CONFIG_TLSV12=y ++ ++# Select which ciphers to use by default with OpenSSL if the user does not ++# specify them. ++#CONFIG_TLS_DEFAULT_CIPHERS="DEFAULT:!EXP:!LOW" ++ ++# If CONFIG_TLS=internal is used, additional library and include paths are ++# needed for LibTomMath. Alternatively, an integrated, minimal version of ++# LibTomMath can be used. See beginning of libtommath.c for details on benefits ++# and drawbacks of this option. ++#CONFIG_INTERNAL_LIBTOMMATH=y ++#ifndef CONFIG_INTERNAL_LIBTOMMATH ++#LTM_PATH=/usr/src/libtommath-0.39 ++#CFLAGS += -I$(LTM_PATH) ++#LIBS += -L$(LTM_PATH) ++#LIBS_p += -L$(LTM_PATH) ++#endif ++# At the cost of about 4 kB of additional binary size, the internal LibTomMath ++# can be configured to include faster routines for exptmod, sqr, and div to ++# speed up DH and RSA calculation considerably ++#CONFIG_INTERNAL_LIBTOMMATH_FAST=y ++ ++# Interworking (IEEE 802.11u) ++# This can be used to enable functionality to improve interworking with ++# external networks. ++#CONFIG_INTERWORKING=y ++ ++# Hotspot 2.0 ++#CONFIG_HS20=y ++ ++# Enable SQLite database support in hlr_auc_gw, EAP-SIM DB, and eap_user_file ++#CONFIG_SQLITE=y ++ ++# Enable Fast Session Transfer (FST) ++#CONFIG_FST=y ++ ++# Enable CLI commands for FST testing ++#CONFIG_FST_TEST=y ++ ++# Testing options ++# This can be used to enable some testing options (see also the example ++# configuration file) that are really useful only for testing clients that ++# connect to this hostapd. These options allow, for example, to drop a ++# certain percentage of probe requests or auth/(re)assoc frames. ++CONFIG_TESTING_OPTIONS=y ++ ++# Automatic Channel Selection ++# This will allow hostapd to pick the channel automatically when channel is set ++# to "acs_survey" or "0". Eventually, other ACS algorithms can be added in ++# similar way. ++# ++# Automatic selection is currently only done through initialization, later on ++# we hope to do background checks to keep us moving to more ideal channels as ++# time goes by. ACS is currently only supported through the nl80211 driver and ++# your driver must have survey dump capability that is filled by the driver ++# during scanning. ++# ++# You can customize the ACS survey algorithm with the hostapd.conf variable ++# acs_num_scans. ++# ++# Supported ACS drivers: ++# * ath9k ++# * ath5k ++# * ath10k ++# ++# For more details refer to: ++# http://wireless.kernel.org/en/users/Documentation/acs ++# ++#CONFIG_ACS=y ++ ++# Multiband Operation support ++# These extensions facilitate efficient use of multiple frequency bands ++# available to the AP and the devices that may associate with it. ++#CONFIG_MBO=y ++ ++# Client Taxonomy ++# Has the AP retain the Probe Request and (Re)Association Request frames from ++# a client, from which a signature can be produced which can identify the model ++# of client device like "Nexus 6P" or "iPhone 5s". ++#CONFIG_TAXONOMY=y ++ ++# Fast Initial Link Setup (FILS) (IEEE 802.11ai) ++#CONFIG_FILS=y ++# FILS shared key authentication with PFS ++#CONFIG_FILS_SK_PFS=y ++ ++# Include internal line edit mode in hostapd_cli. This can be used to provide ++# limited command line editing and history support. ++#CONFIG_WPA_CLI_EDIT=y ++ ++# Opportunistic Wireless Encryption (OWE) ++# Experimental implementation of draft-harkins-owe-07.txt ++#CONFIG_OWE=y ++ ++# Airtime policy support ++#CONFIG_AIRTIME_POLICY=y ++ ++# Override default value for the wpa_disable_eapol_key_retries configuration ++# parameter. See that parameter in hostapd.conf for more details. ++#CFLAGS += -DDEFAULT_WPA_DISABLE_EAPOL_KEY_RETRIES=1 ++ ++# Wired equivalent privacy (WEP) ++# WEP is an obsolete cryptographic data confidentiality algorithm that is not ++# considered secure. It should not be used for anything anymore. The ++# functionality needed to use WEP is available in the current hostapd ++# release under this optional build parameter. This functionality is subject to ++# be completely removed in a future release. ++#CONFIG_WEP=y ++ ++# Remove all TKIP functionality ++# TKIP is an old cryptographic data confidentiality algorithm that is not ++# considered secure. It should not be used anymore. For now, the default hostapd ++# build includes this to allow mixed mode WPA+WPA2 networks to be enabled, but ++# that functionality is subject to be removed in the future. ++#CONFIG_NO_TKIP=y ++ ++# Simultaneous Authentication of Equals (SAE), WPA3-Personal ++CONFIG_SAE=y ++ ++# Device Provisioning Protocol (DPP) ++CONFIG_DPP=y diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base new file mode 100644 -index 000000000000..15daf0ad2245 +index 000000000..15daf0ad2 --- /dev/null +++ b/wpa_supplicant/defconfig_base @@ -0,0 +1,635 @@ @@ -656,3 +1065,6 @@ index 000000000000..15daf0ad2245 +# connect to this hostapd. These options allow, for example, to drop a +# certain percentage of probe requests or auth/(re)assoc frames. +CONFIG_TESTING_OPTIONS=y +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0014-CVE_2019_9501-Fix-to-check-Invalid-GTK-IE-length-in-.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0014-CVE_2019_9501-Fix-to-check-Invalid-GTK-IE-length-in-.patch new file mode 100644 index 000000000..1cc5dc822 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0014-CVE_2019_9501-Fix-to-check-Invalid-GTK-IE-length-in-.patch @@ -0,0 +1,37 @@ +From 28c5794ff336f3ec29be79197198071be9add4ac Mon Sep 17 00:00:00 2001 +From: Suresh Sanaboina +Date: Tue, 1 Feb 2022 13:02:07 +0000 +Subject: [PATCH 14/49] [CVE_2019_9501] Fix to check Invalid GTK IE length in + M3 at STA + +--- + src/rsn_supp/wpa.c | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/src/rsn_supp/wpa.c b/src/rsn_supp/wpa.c +index 0a2f87787..92ab7d561 100644 +--- a/src/rsn_supp/wpa.c ++++ b/src/rsn_supp/wpa.c +@@ -1661,6 +1661,7 @@ static void wpa_supplicant_process_3_of_4(struct wpa_sm *sm, + { + u16 key_info, keylen; + struct wpa_eapol_ie_parse ie; ++ struct wpa_gtk_data gd; /* Used for checking gtk length*/ + + wpa_sm_set_state(sm, WPA_4WAY_HANDSHAKE); + wpa_dbg(sm->ctx->msg_ctx, MSG_DEBUG, "WPA: RX message 3 of 4-Way " +@@ -1763,6 +1764,11 @@ static void wpa_supplicant_process_3_of_4(struct wpa_sm *sm, + wpa_supplicant_install_ptk(sm, key, KEY_FLAG_RX)) + goto failed; + ++ /* Checking gtk_len before sending msg 4/4. If it is greater than ++ * 32 bytes drop it. No GTK to be set EAPOL WPA KEY */ ++ if (ie.gtk && (ie.gtk_len < 2 || ie.gtk_len - 2 > sizeof(gd.gtk))) ++ goto failed; ++ + if (wpa_supplicant_send_4_of_4(sm, sm->bssid, key, ver, key_info, + &sm->ptk) < 0) { + goto failed; +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0014-non-upstream-defconfig_base-Add-Infineon-default-con.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0014-non-upstream-defconfig_base-Add-Infineon-default-con.patch deleted file mode 100644 index f33d8296d..000000000 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0014-non-upstream-defconfig_base-Add-Infineon-default-con.patch +++ /dev/null @@ -1,426 +0,0 @@ -From: Chung-Hsien Hsu -Date: Mon, 2 Aug 2021 14:15:06 -0500 -Subject: [PATCH] non-upstream: defconfig_base: Add Infineon default - configuration (second) - -Add Infineon default configuration files (defconfig_base). - -Second part: changes to 'hostapd' directory. - -Signed-off-by: Kurt Lee -Signed-off-by: Chung-Hsien Hsu -Signed-off-by: Javier Viguera ---- - hostapd/defconfig_base | 403 +++++++++++++++++++++++++++++++++++++++++ - 1 file changed, 403 insertions(+) - create mode 100644 hostapd/defconfig_base - -diff --git a/hostapd/defconfig_base b/hostapd/defconfig_base -new file mode 100644 -index 000000000000..9dcf7848df92 ---- /dev/null -+++ b/hostapd/defconfig_base -@@ -0,0 +1,403 @@ -+# Example hostapd build time configuration -+# -+# This file lists the configuration options that are used when building the -+# hostapd binary. All lines starting with # are ignored. Configuration option -+# lines must be commented out complete, if they are not to be included, i.e., -+# just setting VARIABLE=n is not disabling that variable. -+# -+# This file is included in Makefile, so variables like CFLAGS and LIBS can also -+# be modified from here. In most cass, these lines should use += in order not -+# to override previous values of the variables. -+ -+# Driver interface for Host AP driver -+CONFIG_DRIVER_HOSTAP=y -+ -+# Driver interface for wired authenticator -+#CONFIG_DRIVER_WIRED=y -+ -+# Driver interface for drivers using the nl80211 kernel interface -+CONFIG_DRIVER_NL80211=y -+ -+# QCA vendor extensions to nl80211 -+#CONFIG_DRIVER_NL80211_QCA=y -+ -+# driver_nl80211.c requires libnl. If you are compiling it yourself -+# you may need to point hostapd to your version of libnl. -+# -+#CFLAGS += -I$ -+#LIBS += -L$ -+ -+# Use libnl v2.0 (or 3.0) libraries. -+#CONFIG_LIBNL20=y -+ -+# Use libnl 3.2 libraries (if this is selected, CONFIG_LIBNL20 is ignored) -+CONFIG_LIBNL32=y -+ -+ -+# Driver interface for FreeBSD net80211 layer (e.g., Atheros driver) -+#CONFIG_DRIVER_BSD=y -+#CFLAGS += -I/usr/local/include -+#LIBS += -L/usr/local/lib -+#LIBS_p += -L/usr/local/lib -+#LIBS_c += -L/usr/local/lib -+ -+# Driver interface for no driver (e.g., RADIUS server only) -+#CONFIG_DRIVER_NONE=y -+ -+# WPA2/IEEE 802.11i RSN pre-authentication -+CONFIG_RSN_PREAUTH=y -+ -+# Support Operating Channel Validation -+#CONFIG_OCV=y -+ -+# Integrated EAP server -+CONFIG_EAP=y -+ -+# EAP Re-authentication Protocol (ERP) in integrated EAP server -+CONFIG_ERP=y -+ -+# EAP-MD5 for the integrated EAP server -+CONFIG_EAP_MD5=y -+ -+# EAP-TLS for the integrated EAP server -+CONFIG_EAP_TLS=y -+ -+# EAP-MSCHAPv2 for the integrated EAP server -+CONFIG_EAP_MSCHAPV2=y -+ -+# EAP-PEAP for the integrated EAP server -+CONFIG_EAP_PEAP=y -+ -+# EAP-GTC for the integrated EAP server -+CONFIG_EAP_GTC=y -+ -+# EAP-TTLS for the integrated EAP server -+CONFIG_EAP_TTLS=y -+ -+# EAP-SIM for the integrated EAP server -+#CONFIG_EAP_SIM=y -+ -+# EAP-AKA for the integrated EAP server -+#CONFIG_EAP_AKA=y -+ -+# EAP-AKA' for the integrated EAP server -+# This requires CONFIG_EAP_AKA to be enabled, too. -+#CONFIG_EAP_AKA_PRIME=y -+ -+# EAP-PAX for the integrated EAP server -+#CONFIG_EAP_PAX=y -+ -+# EAP-PSK for the integrated EAP server (this is _not_ needed for WPA-PSK) -+#CONFIG_EAP_PSK=y -+ -+# EAP-pwd for the integrated EAP server (secure authentication with a password) -+#CONFIG_EAP_PWD=y -+ -+# EAP-SAKE for the integrated EAP server -+#CONFIG_EAP_SAKE=y -+ -+# EAP-GPSK for the integrated EAP server -+#CONFIG_EAP_GPSK=y -+# Include support for optional SHA256 cipher suite in EAP-GPSK -+#CONFIG_EAP_GPSK_SHA256=y -+ -+# EAP-FAST for the integrated EAP server -+#CONFIG_EAP_FAST=y -+ -+# EAP-TEAP for the integrated EAP server -+# Note: The current EAP-TEAP implementation is experimental and should not be -+# enabled for production use. The IETF RFC 7170 that defines EAP-TEAP has number -+# of conflicting statements and missing details and the implementation has -+# vendor specific workarounds for those and as such, may not interoperate with -+# any other implementation. This should not be used for anything else than -+# experimentation and interoperability testing until those issues has been -+# resolved. -+#CONFIG_EAP_TEAP=y -+ -+# Wi-Fi Protected Setup (WPS) -+CONFIG_WPS=y -+# Enable UPnP support for external WPS Registrars -+#CONFIG_WPS_UPNP=y -+# Enable WPS support with NFC config method -+#CONFIG_WPS_NFC=y -+ -+# EAP-IKEv2 -+#CONFIG_EAP_IKEV2=y -+ -+# Trusted Network Connect (EAP-TNC) -+#CONFIG_EAP_TNC=y -+ -+# EAP-EKE for the integrated EAP server -+#CONFIG_EAP_EKE=y -+ -+# PKCS#12 (PFX) support (used to read private key and certificate file from -+# a file that usually has extension .p12 or .pfx) -+CONFIG_PKCS12=y -+ -+# RADIUS authentication server. This provides access to the integrated EAP -+# server from external hosts using RADIUS. -+#CONFIG_RADIUS_SERVER=y -+ -+# Build IPv6 support for RADIUS operations -+CONFIG_IPV6=y -+ -+# IEEE Std 802.11r-2008 (Fast BSS Transition) -+CONFIG_IEEE80211R=y -+ -+# Use the hostapd's IEEE 802.11 authentication (ACL), but without -+# the IEEE 802.11 Management capability (e.g., FreeBSD/net80211) -+#CONFIG_DRIVER_RADIUS_ACL=y -+ -+# Wireless Network Management (IEEE Std 802.11v-2011) -+# Note: This is experimental and not complete implementation. -+#CONFIG_WNM=y -+ -+# IEEE 802.11ac (Very High Throughput) support -+CONFIG_IEEE80211AC=y -+ -+# IEEE 802.11ax HE support -+# Note: This is experimental and work in progress. The definitions are still -+# subject to change and this should not be expected to interoperate with the -+# final IEEE 802.11ax version. -+CONFIG_IEEE80211AX=y -+ -+# Remove debugging code that is printing out debug messages to stdout. -+# This can be used to reduce the size of the hostapd considerably if debugging -+# code is not needed. -+#CONFIG_NO_STDOUT_DEBUG=y -+ -+# Add support for writing debug log to a file: -f /tmp/hostapd.log -+# Disabled by default. -+CONFIG_DEBUG_FILE=y -+ -+# Send debug messages to syslog instead of stdout -+#CONFIG_DEBUG_SYSLOG=y -+ -+# Add support for sending all debug messages (regardless of debug verbosity) -+# to the Linux kernel tracing facility. This helps debug the entire stack by -+# making it easy to record everything happening from the driver up into the -+# same file, e.g., using trace-cmd. -+#CONFIG_DEBUG_LINUX_TRACING=y -+ -+# Remove support for RADIUS accounting -+#CONFIG_NO_ACCOUNTING=y -+ -+# Remove support for RADIUS -+#CONFIG_NO_RADIUS=y -+ -+# Remove support for VLANs -+#CONFIG_NO_VLAN=y -+ -+# Enable support for fully dynamic VLANs. This enables hostapd to -+# automatically create bridge and VLAN interfaces if necessary. -+#CONFIG_FULL_DYNAMIC_VLAN=y -+ -+# Use netlink-based kernel API for VLAN operations instead of ioctl() -+# Note: This requires libnl 3.1 or newer. -+#CONFIG_VLAN_NETLINK=y -+ -+# Remove support for dumping internal state through control interface commands -+# This can be used to reduce binary size at the cost of disabling a debugging -+# option. -+#CONFIG_NO_DUMP_STATE=y -+ -+# Enable tracing code for developer debugging -+# This tracks use of memory allocations and other registrations and reports -+# incorrect use with a backtrace of call (or allocation) location. -+#CONFIG_WPA_TRACE=y -+# For BSD, comment out these. -+#LIBS += -lexecinfo -+#LIBS_p += -lexecinfo -+#LIBS_c += -lexecinfo -+ -+# Use libbfd to get more details for developer debugging -+# This enables use of libbfd to get more detailed symbols for the backtraces -+# generated by CONFIG_WPA_TRACE=y. -+#CONFIG_WPA_TRACE_BFD=y -+# For BSD, comment out these. -+#LIBS += -lbfd -liberty -lz -+#LIBS_p += -lbfd -liberty -lz -+#LIBS_c += -lbfd -liberty -lz -+ -+# hostapd depends on strong random number generation being available from the -+# operating system. os_get_random() function is used to fetch random data when -+# needed, e.g., for key generation. On Linux and BSD systems, this works by -+# reading /dev/urandom. It should be noted that the OS entropy pool needs to be -+# properly initialized before hostapd is started. This is important especially -+# on embedded devices that do not have a hardware random number generator and -+# may by default start up with minimal entropy available for random number -+# generation. -+# -+# As a safety net, hostapd is by default trying to internally collect -+# additional entropy for generating random data to mix in with the data -+# fetched from the OS. This by itself is not considered to be very strong, but -+# it may help in cases where the system pool is not initialized properly. -+# However, it is very strongly recommended that the system pool is initialized -+# with enough entropy either by using hardware assisted random number -+# generator or by storing state over device reboots. -+# -+# hostapd can be configured to maintain its own entropy store over restarts to -+# enhance random number generation. This is not perfect, but it is much more -+# secure than using the same sequence of random numbers after every reboot. -+# This can be enabled with -e command line option. The specified -+# file needs to be readable and writable by hostapd. -+# -+# If the os_get_random() is known to provide strong random data (e.g., on -+# Linux/BSD, the board in question is known to have reliable source of random -+# data from /dev/urandom), the internal hostapd random pool can be disabled. -+# This will save some in binary size and CPU use. However, this should only be -+# considered for builds that are known to be used on devices that meet the -+# requirements described above. -+#CONFIG_NO_RANDOM_POOL=y -+ -+# Should we attempt to use the getrandom(2) call that provides more reliable -+# yet secure randomness source than /dev/random on Linux 3.17 and newer. -+# Requires glibc 2.25 to build, falls back to /dev/random if unavailable. -+#CONFIG_GETRANDOM=y -+ -+# Should we use poll instead of select? Select is used by default. -+#CONFIG_ELOOP_POLL=y -+ -+# Should we use epoll instead of select? Select is used by default. -+#CONFIG_ELOOP_EPOLL=y -+ -+# Should we use kqueue instead of select? Select is used by default. -+#CONFIG_ELOOP_KQUEUE=y -+ -+# Select TLS implementation -+# openssl = OpenSSL (default) -+# gnutls = GnuTLS -+# internal = Internal TLSv1 implementation (experimental) -+# linux = Linux kernel AF_ALG and internal TLSv1 implementation (experimental) -+# none = Empty template -+CONFIG_TLS=openssl -+CONFIG_TLS_ADD_DL=y -+ -+# TLS-based EAP methods require at least TLS v1.0. Newer version of TLS (v1.1) -+# can be enabled to get a stronger construction of messages when block ciphers -+# are used. -+#CONFIG_TLSV11=y -+ -+# TLS-based EAP methods require at least TLS v1.0. Newer version of TLS (v1.2) -+# can be enabled to enable use of stronger crypto algorithms. -+#CONFIG_TLSV12=y -+ -+# Select which ciphers to use by default with OpenSSL if the user does not -+# specify them. -+#CONFIG_TLS_DEFAULT_CIPHERS="DEFAULT:!EXP:!LOW" -+ -+# If CONFIG_TLS=internal is used, additional library and include paths are -+# needed for LibTomMath. Alternatively, an integrated, minimal version of -+# LibTomMath can be used. See beginning of libtommath.c for details on benefits -+# and drawbacks of this option. -+#CONFIG_INTERNAL_LIBTOMMATH=y -+#ifndef CONFIG_INTERNAL_LIBTOMMATH -+#LTM_PATH=/usr/src/libtommath-0.39 -+#CFLAGS += -I$(LTM_PATH) -+#LIBS += -L$(LTM_PATH) -+#LIBS_p += -L$(LTM_PATH) -+#endif -+# At the cost of about 4 kB of additional binary size, the internal LibTomMath -+# can be configured to include faster routines for exptmod, sqr, and div to -+# speed up DH and RSA calculation considerably -+#CONFIG_INTERNAL_LIBTOMMATH_FAST=y -+ -+# Interworking (IEEE 802.11u) -+# This can be used to enable functionality to improve interworking with -+# external networks. -+#CONFIG_INTERWORKING=y -+ -+# Hotspot 2.0 -+#CONFIG_HS20=y -+ -+# Enable SQLite database support in hlr_auc_gw, EAP-SIM DB, and eap_user_file -+#CONFIG_SQLITE=y -+ -+# Enable Fast Session Transfer (FST) -+#CONFIG_FST=y -+ -+# Enable CLI commands for FST testing -+#CONFIG_FST_TEST=y -+ -+# Testing options -+# This can be used to enable some testing options (see also the example -+# configuration file) that are really useful only for testing clients that -+# connect to this hostapd. These options allow, for example, to drop a -+# certain percentage of probe requests or auth/(re)assoc frames. -+CONFIG_TESTING_OPTIONS=y -+ -+# Automatic Channel Selection -+# This will allow hostapd to pick the channel automatically when channel is set -+# to "acs_survey" or "0". Eventually, other ACS algorithms can be added in -+# similar way. -+# -+# Automatic selection is currently only done through initialization, later on -+# we hope to do background checks to keep us moving to more ideal channels as -+# time goes by. ACS is currently only supported through the nl80211 driver and -+# your driver must have survey dump capability that is filled by the driver -+# during scanning. -+# -+# You can customize the ACS survey algorithm with the hostapd.conf variable -+# acs_num_scans. -+# -+# Supported ACS drivers: -+# * ath9k -+# * ath5k -+# * ath10k -+# -+# For more details refer to: -+# http://wireless.kernel.org/en/users/Documentation/acs -+# -+#CONFIG_ACS=y -+ -+# Multiband Operation support -+# These extensions facilitate efficient use of multiple frequency bands -+# available to the AP and the devices that may associate with it. -+#CONFIG_MBO=y -+ -+# Client Taxonomy -+# Has the AP retain the Probe Request and (Re)Association Request frames from -+# a client, from which a signature can be produced which can identify the model -+# of client device like "Nexus 6P" or "iPhone 5s". -+#CONFIG_TAXONOMY=y -+ -+# Fast Initial Link Setup (FILS) (IEEE 802.11ai) -+#CONFIG_FILS=y -+# FILS shared key authentication with PFS -+#CONFIG_FILS_SK_PFS=y -+ -+# Include internal line edit mode in hostapd_cli. This can be used to provide -+# limited command line editing and history support. -+#CONFIG_WPA_CLI_EDIT=y -+ -+# Opportunistic Wireless Encryption (OWE) -+# Experimental implementation of draft-harkins-owe-07.txt -+#CONFIG_OWE=y -+ -+# Airtime policy support -+#CONFIG_AIRTIME_POLICY=y -+ -+# Override default value for the wpa_disable_eapol_key_retries configuration -+# parameter. See that parameter in hostapd.conf for more details. -+#CFLAGS += -DDEFAULT_WPA_DISABLE_EAPOL_KEY_RETRIES=1 -+ -+# Wired equivalent privacy (WEP) -+# WEP is an obsolete cryptographic data confidentiality algorithm that is not -+# considered secure. It should not be used for anything anymore. The -+# functionality needed to use WEP is available in the current hostapd -+# release under this optional build parameter. This functionality is subject to -+# be completely removed in a future release. -+#CONFIG_WEP=y -+ -+# Remove all TKIP functionality -+# TKIP is an old cryptographic data confidentiality algorithm that is not -+# considered secure. It should not be used anymore. For now, the default hostapd -+# build includes this to allow mixed mode WPA+WPA2 networks to be enabled, but -+# that functionality is subject to be removed in the future. -+#CONFIG_NO_TKIP=y -+ -+# Simultaneous Authentication of Equals (SAE), WPA3-Personal -+CONFIG_SAE=y -+ -+# Device Provisioning Protocol (DPP) -+CONFIG_DPP=y diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0015-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes-f.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0015-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes.murata.patch similarity index 81% rename from meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0015-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes-f.patch rename to meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0015-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes.murata.patch index 24ceee1f7..de3a106da 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0015-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes-f.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0015-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes.murata.patch @@ -1,22 +1,33 @@ +From ab61a3dd6d968c62b407c170079a236194357931 Mon Sep 17 00:00:00 2001 From: Danny Chiu Date: Thu, 4 Nov 2021 02:44:17 -0500 -Subject: [PATCH] Add CONFIG_WPA3_SAE_AUTH_EARLY_SET flags and codes (first) +Subject: [PATCH 15/49] Add CONFIG_WPA3_SAE_AUTH_EARLY_SET flags and codes Enable this flags allow the AP to set authorization to firmware earier as the SAE confirm from is ok. - -First part: changes not touching 'hostapd' directory. - -Signed-off-by: Javier Viguera --- + hostapd/defconfig_base | 3 +++ src/ap/ieee802_11.c | 11 +++++++++++ wpa_supplicant/Android.mk | 4 ++++ wpa_supplicant/Makefile | 4 ++++ wpa_supplicant/android.config | 3 +++ wpa_supplicant/defconfig_base | 3 +++ - 5 files changed, 25 insertions(+) + 6 files changed, 28 insertions(+) +diff --git a/hostapd/defconfig_base b/hostapd/defconfig_base +index 9dcf7848d..dafcf0f6c 100644 +--- a/hostapd/defconfig_base ++++ b/hostapd/defconfig_base +@@ -399,5 +399,8 @@ CONFIG_TESTING_OPTIONS=y + # Simultaneous Authentication of Equals (SAE), WPA3-Personal + CONFIG_SAE=y + ++# Set SAE Auth status early ++CONFIG_WPA3_SAE_AUTH_EARLY_SET=y ++ + # Device Provisioning Protocol (DPP) + CONFIG_DPP=y diff --git a/src/ap/ieee802_11.c b/src/ap/ieee802_11.c -index db41049287fc..3b735c09fa2d 100644 +index db4104928..3b735c09f 100644 --- a/src/ap/ieee802_11.c +++ b/src/ap/ieee802_11.c @@ -87,6 +87,10 @@ static void handle_auth(struct hostapd_data *hapd, @@ -53,7 +64,7 @@ index db41049287fc..3b735c09fa2d 100644 diff --git a/wpa_supplicant/Android.mk b/wpa_supplicant/Android.mk -index 7e597f396a07..892cb7507137 100644 +index 7e597f396..892cb7507 100644 --- a/wpa_supplicant/Android.mk +++ b/wpa_supplicant/Android.mk @@ -255,6 +255,10 @@ NEED_DH_GROUPS_ALL=y @@ -68,7 +79,7 @@ index 7e597f396a07..892cb7507137 100644 L_CFLAGS += -DCONFIG_DPP OBJS += src/common/dpp.c diff --git a/wpa_supplicant/Makefile b/wpa_supplicant/Makefile -index cb66defac7c8..66aedaff7c34 100644 +index cb66defac..66aedaff7 100644 --- a/wpa_supplicant/Makefile +++ b/wpa_supplicant/Makefile @@ -254,6 +254,10 @@ OBJS += mesh_mpm.o @@ -83,7 +94,7 @@ index cb66defac7c8..66aedaff7c34 100644 CFLAGS += -DCONFIG_SAE OBJS += ../src/common/sae.o diff --git a/wpa_supplicant/android.config b/wpa_supplicant/android.config -index 283f8eb0a995..3c28f80c9c25 100644 +index 283f8eb0a..3c28f80c9 100644 --- a/wpa_supplicant/android.config +++ b/wpa_supplicant/android.config @@ -534,6 +534,9 @@ CONFIG_WIFI_DISPLAY=y @@ -97,7 +108,7 @@ index 283f8eb0a995..3c28f80c9c25 100644 # WEP is an obsolete cryptographic data confidentiality algorithm that is not # considered secure. It should not be used for anything anymore. The diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base -index 15daf0ad2245..99c74853d404 100644 +index 15daf0ad2..99c74853d 100644 --- a/wpa_supplicant/defconfig_base +++ b/wpa_supplicant/defconfig_base @@ -248,6 +248,9 @@ CONFIG_CTRL_IFACE=y @@ -110,3 +121,6 @@ index 15daf0ad2245..99c74853d404 100644 # Disable scan result processing (ap_scan=1) to save code size by about 1 kB. # This can be used if ap_scan=1 mode is never enabled. #CONFIG_NO_SCAN_PROCESSING=y +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0016-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes-s.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0016-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes-s.patch deleted file mode 100644 index 7bf4ef9dd..000000000 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0016-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes-s.patch +++ /dev/null @@ -1,70 +0,0 @@ -From: Danny Chiu -Date: Thu, 4 Nov 2021 02:44:17 -0500 -Subject: [PATCH] Add CONFIG_WPA3_SAE_AUTH_EARLY_SET flags and codes (second) - -Enable this flags allow the AP to set authorization to firmware earier as the SAE confirm from is ok. - -Second part: changes to 'hostapd' directory. - -Signed-off-by: Javier Viguera ---- - hostapd/Android.mk | 4 ++++ - hostapd/Makefile | 4 ++++ - hostapd/android.config | 3 +++ - hostapd/defconfig_base | 3 +++ - 4 files changed, 14 insertions(+) - -diff --git a/hostapd/Android.mk b/hostapd/Android.mk -index bf26e41c6b23..997e9a44737b 100644 ---- a/hostapd/Android.mk -+++ b/hostapd/Android.mk -@@ -264,6 +264,10 @@ NEED_HMAC_SHA256_KDF=y - NEED_DRAGONFLY=y - endif - -+ifdef CONFIG_WPA3_SAE_AUTH_EARLY_SET -+L_CFLAGS += -DCONFIG_WPA3_SAE_AUTH_EARLY_SET -+endif -+ - ifdef CONFIG_OWE - L_CFLAGS += -DCONFIG_OWE - NEED_ECC=y -diff --git a/hostapd/Makefile b/hostapd/Makefile -index e37c13b27a6e..c65a51227838 100644 ---- a/hostapd/Makefile -+++ b/hostapd/Makefile -@@ -290,6 +290,10 @@ CFLAGS += -DCONFIG_ETH_P_OUI - OBJS += ../src/ap/eth_p_oui.o - endif - -+ifdef CONFIG_WPA3_SAE_AUTH_EARLY_SET -+CFLAGS += -DCONFIG_WPA3_SAE_AUTH_EARLY_SET -+endif -+ - ifdef CONFIG_SAE - CFLAGS += -DCONFIG_SAE - OBJS += ../src/common/sae.o -diff --git a/hostapd/android.config b/hostapd/android.config -index c8b3afabef8d..3664f1773a0e 100644 ---- a/hostapd/android.config -+++ b/hostapd/android.config -@@ -212,3 +212,6 @@ CONFIG_NO_RANDOM_POOL=y - # release under this optional build parameter. This functionality is subject to - # be completely removed in a future release. - CONFIG_WEP=y -+ -+# Set SAE Auth status early -+CONFIG_WPA3_SAE_AUTH_EARLY_SET=y -diff --git a/hostapd/defconfig_base b/hostapd/defconfig_base -index 9dcf7848df92..dafcf0f6cc5b 100644 ---- a/hostapd/defconfig_base -+++ b/hostapd/defconfig_base -@@ -399,5 +399,8 @@ CONFIG_TESTING_OPTIONS=y - # Simultaneous Authentication of Equals (SAE), WPA3-Personal - CONFIG_SAE=y - -+# Set SAE Auth status early -+CONFIG_WPA3_SAE_AUTH_EARLY_SET=y -+ - # Device Provisioning Protocol (DPP) - CONFIG_DPP=y diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0016-SAE-Set-the-right-WPA-Versions-for-FT-SAE-key-manage.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0016-SAE-Set-the-right-WPA-Versions-for-FT-SAE-key-manage.patch new file mode 100644 index 000000000..6843ed4ee --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0016-SAE-Set-the-right-WPA-Versions-for-FT-SAE-key-manage.patch @@ -0,0 +1,30 @@ +From 32ee9150ccf3f6c242ba2809aab9b9e115a9d1b5 Mon Sep 17 00:00:00 2001 +From: Darren Li +Date: Fri, 26 Nov 2021 02:09:03 -0600 +Subject: [PATCH 16/49] SAE: Set the right WPA Versions for FT-SAE key + management + +Set the right WPA Versions for FT-SAE key management + +Signed-off-by: Darren Li Darren.Li@infineon.com +--- + src/drivers/driver_nl80211.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index b6afc6e7a..341c753b3 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -6208,7 +6208,8 @@ static int nl80211_connect_common(struct wpa_driver_nl80211_data *drv, + if (params->wpa_proto & WPA_PROTO_WPA) + ver |= NL80211_WPA_VERSION_1; + if (params->wpa_proto & WPA_PROTO_RSN) { +- if (params->key_mgmt_suite == WPA_KEY_MGMT_SAE) ++ if (params->key_mgmt_suite == WPA_KEY_MGMT_SAE || ++ params->key_mgmt_suite == WPA_KEY_MGMT_FT_SAE) + ver |= NL80211_WPA_VERSION_3; + else + ver |= NL80211_WPA_VERSION_2; +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0018-wpa_supplicant-Support-WPA_KEY_MGMT_FT-for-eapol-off.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0017-wpa_supplicant-Support-WPA_KEY_MGMT_FT-for-eapol-off.patch similarity index 92% rename from meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0018-wpa_supplicant-Support-WPA_KEY_MGMT_FT-for-eapol-off.patch rename to meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0017-wpa_supplicant-Support-WPA_KEY_MGMT_FT-for-eapol-off.patch index 3f8582792..e9a2a0c54 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0018-wpa_supplicant-Support-WPA_KEY_MGMT_FT-for-eapol-off.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0017-wpa_supplicant-Support-WPA_KEY_MGMT_FT-for-eapol-off.patch @@ -1,7 +1,8 @@ +From 6fa06f214ba1cfc4e80dc7413874175146b9c2a5 Mon Sep 17 00:00:00 2001 From: Chien-Chia Chen Date: Tue, 23 Nov 2021 21:29:08 -0600 -Subject: [PATCH] wpa_supplicant: Support WPA_KEY_MGMT_FT for eapol offloading - and driver base roaming +Subject: [PATCH 17/49] wpa_supplicant: Support WPA_KEY_MGMT_FT for eapol + offloading and driver base roaming Add WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_PSK / WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_8021X / WPA_DRIVER_FLAGS_ROAM_OFFLOAD for IEEE80211R support @@ -18,7 +19,7 @@ Signed-off-by: Chien-Chia Chen 7 files changed, 19 insertions(+), 5 deletions(-) diff --git a/src/drivers/driver.h b/src/drivers/driver.h -index 45260e8c5e30..fb3f8b4a866c 100644 +index 45260e8c5..fb3f8b4a8 100644 --- a/src/drivers/driver.h +++ b/src/drivers/driver.h @@ -2071,6 +2071,8 @@ struct wpa_driver_capa { @@ -31,7 +32,7 @@ index 45260e8c5e30..fb3f8b4a866c 100644 #define FULL_AP_CLIENT_STATE_SUPP(drv_flags) \ diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c -index 341c753b3e83..964486c11c1b 100644 +index 341c753b3..964486c11 100644 --- a/src/drivers/driver_nl80211.c +++ b/src/drivers/driver_nl80211.c @@ -3301,7 +3301,8 @@ static int wpa_driver_nl80211_set_key(struct i802_bss *bss, @@ -45,7 +46,7 @@ index 341c753b3e83..964486c11c1b 100644 /* The driver does not have any offload mechanism for PMK, so * there is no need to configure this key. */ diff --git a/src/drivers/driver_nl80211_capa.c b/src/drivers/driver_nl80211_capa.c -index ae6029a922b8..d5cdafa9f061 100644 +index ae6029a92..d5cdafa9f 100644 --- a/src/drivers/driver_nl80211_capa.c +++ b/src/drivers/driver_nl80211_capa.c @@ -606,6 +606,10 @@ static void wiphy_info_ext_feature_flags(struct wiphy_info_data *info, @@ -60,7 +61,7 @@ index ae6029a922b8..d5cdafa9f061 100644 NL80211_EXT_FEATURE_MFP_OPTIONAL)) capa->flags |= WPA_DRIVER_FLAGS_MFP_OPTIONAL; diff --git a/src/drivers/nl80211_copy.h b/src/drivers/nl80211_copy.h -index f962c06e9818..a3e889b35b36 100644 +index f962c06e9..a3e889b35 100644 --- a/src/drivers/nl80211_copy.h +++ b/src/drivers/nl80211_copy.h @@ -6010,6 +6010,7 @@ enum nl80211_ext_feature_index { @@ -72,7 +73,7 @@ index f962c06e9818..a3e889b35b36 100644 NL80211_EXT_FEATURE_SECURE_LTF, NL80211_EXT_FEATURE_SECURE_RTT, diff --git a/wpa_supplicant/events.c b/wpa_supplicant/events.c -index f55e1846e205..fe8dbd91d50a 100644 +index f55e1846e..fe8dbd91d 100644 --- a/wpa_supplicant/events.c +++ b/wpa_supplicant/events.c @@ -3425,7 +3425,8 @@ static void wpa_supplicant_event_assoc(struct wpa_supplicant *wpa_s, @@ -86,7 +87,7 @@ index f55e1846e205..fe8dbd91d50a 100644 /* * The driver will take care of RSN 4-way handshake, so we need diff --git a/wpa_supplicant/wpa_supplicant.c b/wpa_supplicant/wpa_supplicant.c -index f00dd57da3c1..f238dadcf27f 100644 +index f00dd57da..f238dadcf 100644 --- a/wpa_supplicant/wpa_supplicant.c +++ b/wpa_supplicant/wpa_supplicant.c @@ -1543,7 +1543,10 @@ int wpa_supplicant_set_suites(struct wpa_supplicant *wpa_s, @@ -102,7 +103,7 @@ index f00dd57da3c1..f238dadcf27f 100644 #endif /* CONFIG_IEEE80211R */ wpa_dbg(wpa_s, MSG_DEBUG, diff --git a/wpa_supplicant/wpas_glue.c b/wpa_supplicant/wpas_glue.c -index 0cffe52fa9be..816a884a8179 100644 +index 0cffe52fa..816a884a8 100644 --- a/wpa_supplicant/wpas_glue.c +++ b/wpa_supplicant/wpas_glue.c @@ -311,7 +311,8 @@ static void wpa_supplicant_eapol_cb(struct eapol_sm *eapol, @@ -125,3 +126,6 @@ index 0cffe52fa9be..816a884a8179 100644 pmk_len = sm->pmk_len; os_memcpy(pmk, sm->pmk, pmk_len); } else { +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0019-wpa_supplicant-suppress-deauth-for-PMKSA-caching-dis.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0018-wpa_supplicant-suppress-deauth-for-PMKSA-caching-dis.patch similarity index 82% rename from meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0019-wpa_supplicant-suppress-deauth-for-PMKSA-caching-dis.patch rename to meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0018-wpa_supplicant-suppress-deauth-for-PMKSA-caching-dis.patch index e72d1dae2..d2045f7df 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0019-wpa_supplicant-suppress-deauth-for-PMKSA-caching-dis.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0018-wpa_supplicant-suppress-deauth-for-PMKSA-caching-dis.patch @@ -1,6 +1,8 @@ +From 9af850cef2007cabe1bbffad3ef1d2b13396832d Mon Sep 17 00:00:00 2001 From: Darren Li Date: Tue, 22 Feb 2022 00:34:47 -0600 -Subject: [PATCH] wpa_supplicant: suppress deauth for PMKSA caching disabled +Subject: [PATCH 18/49] wpa_supplicant: suppress deauth for PMKSA caching + disabled wpa_supplicant: Need a command/parameter suppress deauth for PMKSA caching disabled @@ -12,14 +14,14 @@ Signed-off-by: Darren Li wpa_supplicant/config.c | 1 + wpa_supplicant/config_file.c | 1 + wpa_supplicant/config_ssid.h | 7 +++++++ - wpa_supplicant/wpas_glue.c | 1 + - 7 files changed, 16 insertions(+), 1 deletion(-) + wpa_supplicant/wpas_glue.c | 2 ++ + 7 files changed, 17 insertions(+), 1 deletion(-) diff --git a/src/rsn_supp/wpa.c b/src/rsn_supp/wpa.c -index 0a2f87787504..a9f1fb916a8d 100644 +index 92ab7d561..1f6401ef3 100644 --- a/src/rsn_supp/wpa.c +++ b/src/rsn_supp/wpa.c -@@ -2898,7 +2898,9 @@ static void wpa_sm_pmksa_free_cb(struct rsn_pmksa_cache_entry *entry, +@@ -2904,7 +2904,9 @@ static void wpa_sm_pmksa_free_cb(struct rsn_pmksa_cache_entry *entry, if (deauth) { sm->pmk_len = 0; os_memset(sm->pmk, 0, sizeof(sm->pmk)); @@ -30,7 +32,7 @@ index 0a2f87787504..a9f1fb916a8d 100644 } } -@@ -3234,6 +3236,7 @@ void wpa_sm_set_config(struct wpa_sm *sm, struct rsn_supp_config *config) +@@ -3240,6 +3242,7 @@ void wpa_sm_set_config(struct wpa_sm *sm, struct rsn_supp_config *config) } #endif /* CONFIG_FILS */ sm->beacon_prot = config->beacon_prot; @@ -39,7 +41,7 @@ index 0a2f87787504..a9f1fb916a8d 100644 sm->network_ctx = NULL; sm->allowed_pairwise_cipher = 0; diff --git a/src/rsn_supp/wpa.h b/src/rsn_supp/wpa.h -index 41daaae2cf72..2cd1826e43e1 100644 +index 41daaae2c..2cd1826e4 100644 --- a/src/rsn_supp/wpa.h +++ b/src/rsn_supp/wpa.h @@ -136,6 +136,7 @@ struct rsn_supp_config { @@ -51,7 +53,7 @@ index 41daaae2cf72..2cd1826e43e1 100644 #ifndef CONFIG_NO_WPA diff --git a/src/rsn_supp/wpa_i.h b/src/rsn_supp/wpa_i.h -index 6cdce321da3b..3989c9ab3dc2 100644 +index 6cdce321d..3989c9ab3 100644 --- a/src/rsn_supp/wpa_i.h +++ b/src/rsn_supp/wpa_i.h @@ -216,6 +216,7 @@ struct wpa_sm { @@ -63,7 +65,7 @@ index 6cdce321da3b..3989c9ab3dc2 100644 diff --git a/wpa_supplicant/config.c b/wpa_supplicant/config.c -index bf062b0792b7..737e46be50f2 100644 +index bf062b079..737e46be5 100644 --- a/wpa_supplicant/config.c +++ b/wpa_supplicant/config.c @@ -2639,6 +2639,7 @@ static const struct parse_data ssid_fields[] = { @@ -75,7 +77,7 @@ index bf062b0792b7..737e46be50f2 100644 #undef OFFSET diff --git a/wpa_supplicant/config_file.c b/wpa_supplicant/config_file.c -index 6db5010db3a7..fe383564d5db 100644 +index 6db5010db..fe383564d 100644 --- a/wpa_supplicant/config_file.c +++ b/wpa_supplicant/config_file.c @@ -844,6 +844,7 @@ static void wpa_config_write_network(FILE *f, struct wpa_ssid *ssid) @@ -87,7 +89,7 @@ index 6db5010db3a7..fe383564d5db 100644 INT_DEF(disable_ht, DEFAULT_DISABLE_HT); INT_DEF(disable_ht40, DEFAULT_DISABLE_HT40); diff --git a/wpa_supplicant/config_ssid.h b/wpa_supplicant/config_ssid.h -index 724534dd0123..ad0bd2b80749 100644 +index 724534dd0..ad0bd2b80 100644 --- a/wpa_supplicant/config_ssid.h +++ b/wpa_supplicant/config_ssid.h @@ -1177,6 +1177,13 @@ struct wpa_ssid { @@ -105,14 +107,18 @@ index 724534dd0123..ad0bd2b80749 100644 #endif /* CONFIG_SSID_H */ diff --git a/wpa_supplicant/wpas_glue.c b/wpa_supplicant/wpas_glue.c -index 816a884a8179..afdcf43194c4 100644 +index 816a884a8..88cbc8fbe 100644 --- a/wpa_supplicant/wpas_glue.c +++ b/wpa_supplicant/wpas_glue.c -@@ -1504,6 +1504,7 @@ void wpa_supplicant_rsn_supp_set_config(struct wpa_supplicant *wpa_s, +@@ -1504,6 +1504,8 @@ void wpa_supplicant_rsn_supp_set_config(struct wpa_supplicant *wpa_s, conf.force_kdk_derivation = wpa_s->conf->force_kdk_derivation; #endif /* CONFIG_TESTING_OPTIONS */ #endif /* CONFIG_PASN */ ++ conf.beacon_prot = ssid->beacon_prot; + conf.suppress_deauth_no_pmksa = ssid->suppress_deauth_no_pmksa; } wpa_sm_set_config(wpa_s->wpa, ssid ? &conf : NULL); } +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0021-SAE-Fix-for-PMK-expiration-issue-through-supplicant.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0019-Fix-for-PMK-expiration-issue-through-supplicant.murata.patch similarity index 61% rename from meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0021-SAE-Fix-for-PMK-expiration-issue-through-supplicant.patch rename to meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0019-Fix-for-PMK-expiration-issue-through-supplicant.murata.patch index 1ddf8074a..7d6f6eea7 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0021-SAE-Fix-for-PMK-expiration-issue-through-supplicant.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0019-Fix-for-PMK-expiration-issue-through-supplicant.murata.patch @@ -1,7 +1,7 @@ +From 5604eb8aaf8382376e6511850e70b66c6e2a22b8 Mon Sep 17 00:00:00 2001 From: Kurt Lee -Date: Mon, 14 Feb 2022 00:08:23 -0600 -Subject: [PATCH] SAE: Fix for PMK expiration issue through supplicant - (first) +Date: Sun, 13 Feb 2022 21:34:09 -0600 +Subject: [PATCH 19/49] Fix for PMK expiration issue through supplicant Description : Sending Deauth from AP once PMK timeout occurs, So that STA will initiate the Auth process. @@ -11,47 +11,33 @@ element in wpa_authenticator structure to pass to the lower API's occurs. Tested: Confirmed once PMK timeout occurs AP is sending deauth and STA starting AUTH frame. - -Porting from project: hostap_upstream, branch: IOT_HOSTAP_BRANCH_1_201 -ID: 587411dd with modified hostapd/config_file.c for configuration of -hostapd - -First part: changes not touching 'hostapd' directory. - -Signed-off-by: Arturo Buzarra --- - src/ap/ap_config.h | 2 ++ - src/ap/ieee802_11.c | 1 + - src/ap/wpa_auth.c | 9 ++++++++- - src/ap/wpa_auth.h | 1 + - src/ap/wpa_auth_i.h | 1 + - wpa_supplicant/ap.c | 2 ++ + src/ap/ap_config.h | 2 ++ + src/ap/ieee802_11.c | 1 + + src/ap/wpa_auth.c | 9 ++++++++- + src/ap/wpa_auth.h | 1 + + src/ap/wpa_auth_i.h | 1 + + wpa_supplicant/ap.c | 2 ++ 6 files changed, 15 insertions(+), 1 deletion(-) diff --git a/src/ap/ap_config.h b/src/ap/ap_config.h index 49cd3168a..a82ca1853 100644 --- a/src/ap/ap_config.h +++ b/src/ap/ap_config.h -@@ -896,10 +896,12 @@ struct hostapd_bss_config { - - u8 ext_capa_mask[EXT_CAPA_MAX_LEN]; +@@ -898,6 +898,8 @@ struct hostapd_bss_config { u8 ext_capa[EXT_CAPA_MAX_LEN]; - + u8 rnr; + + unsigned int dot11RSNAConfigPMKLifetime; }; - + /** - * struct he_phy_capabilities_info - HE PHY capabilities - */ diff --git a/src/ap/ieee802_11.c b/src/ap/ieee802_11.c index 3b735c09f..c4f7d00cc 100644 --- a/src/ap/ieee802_11.c +++ b/src/ap/ieee802_11.c -@@ -978,10 +978,11 @@ void sae_accept_sta(struct hostapd_data *hapd, struct sta_info *sta) - wpa_auth_sm_event(sta->wpa_sm, WPA_AUTH); - sae_set_state(sta, SAE_ACCEPTED, "Accept Confirm"); +@@ -980,6 +980,7 @@ void sae_accept_sta(struct hostapd_data *hapd, struct sta_info *sta) crypto_bignum_deinit(sta->sae->peer_commit_scalar_accepted, 0); sta->sae->peer_commit_scalar_accepted = sta->sae->peer_commit_scalar; sta->sae->peer_commit_scalar = NULL; @@ -59,30 +45,22 @@ index 3b735c09f..c4f7d00cc 100644 wpa_auth_pmksa_add_sae(hapd->wpa_auth, sta->addr, sta->sae->pmk, sta->sae->pmkid); #ifndef CONFIG_WPA3_SAE_AUTH_EARLY_SET - sae_sme_send_external_auth_status(hapd, sta, WLAN_STATUS_SUCCESS); - #endif /* CONFIG_WPA3_SAE_AUTH_EARLY_SET */ diff --git a/src/ap/wpa_auth.c b/src/ap/wpa_auth.c index 4b506c1db..e92ea4302 100644 --- a/src/ap/wpa_auth.c +++ b/src/ap/wpa_auth.c -@@ -388,10 +388,11 @@ static int wpa_auth_pmksa_clear_cb(struct wpa_state_machine *sm, void *ctx) - - static void wpa_auth_pmksa_free_cb(struct rsn_pmksa_cache_entry *entry, +@@ -390,6 +390,7 @@ static void wpa_auth_pmksa_free_cb(struct rsn_pmksa_cache_entry *entry, void *ctx) { struct wpa_authenticator *wpa_auth = ctx; + wpa_sta_disconnect(wpa_auth, entry->spa, WLAN_REASON_PREV_AUTH_NOT_VALID); wpa_auth_for_each_sta(wpa_auth, wpa_auth_pmksa_clear_cb, entry); } - - - static int wpa_group_init_gmk_and_counter(struct wpa_authenticator *wpa_auth, -@@ -4833,20 +4834,26 @@ int wpa_auth_pmksa_add_preauth(struct wpa_authenticator *wpa_auth, - - return -1; + +@@ -4835,6 +4836,12 @@ int wpa_auth_pmksa_add_preauth(struct wpa_authenticator *wpa_auth, } - - + + +void wpa_auth_set_pmk_life_time(struct wpa_authenticator *wpa_auth, unsigned int pmk_life_time) +{ + wpa_auth->pmk_life_time = pmk_life_time; @@ -92,9 +70,7 @@ index 4b506c1db..e92ea4302 100644 int wpa_auth_pmksa_add_sae(struct wpa_authenticator *wpa_auth, const u8 *addr, const u8 *pmk, const u8 *pmkid) { - if (wpa_auth->conf.disable_pmksa_caching) - return -1; - +@@ -4844,7 +4851,7 @@ int wpa_auth_pmksa_add_sae(struct wpa_authenticator *wpa_auth, const u8 *addr, wpa_hexdump_key(MSG_DEBUG, "RSN: Cache PMK from SAE", pmk, PMK_LEN); if (pmksa_cache_auth_add(wpa_auth->pmksa, pmk, PMK_LEN, pmkid, NULL, 0, @@ -102,16 +78,12 @@ index 4b506c1db..e92ea4302 100644 + wpa_auth->addr, addr, wpa_auth->pmk_life_time, NULL, WPA_KEY_MGMT_SAE)) return 0; - - return -1; - } + diff --git a/src/ap/wpa_auth.h b/src/ap/wpa_auth.h -index 140147e79..06fe4d708 100644 +index ff36cfe95..fb456f07c 100644 --- a/src/ap/wpa_auth.h +++ b/src/ap/wpa_auth.h -@@ -423,10 +423,11 @@ int wpa_auth_pmksa_add_preauth(struct wpa_authenticator *wpa_auth, - const u8 *pmk, size_t len, const u8 *sta_addr, - int session_timeout, +@@ -426,6 +426,7 @@ int wpa_auth_pmksa_add_preauth(struct wpa_authenticator *wpa_auth, struct eapol_state_machine *eapol); int wpa_auth_pmksa_add_sae(struct wpa_authenticator *wpa_auth, const u8 *addr, const u8 *pmk, const u8 *pmkid); @@ -119,38 +91,31 @@ index 140147e79..06fe4d708 100644 void wpa_auth_add_sae_pmkid(struct wpa_state_machine *sm, const u8 *pmkid); int wpa_auth_pmksa_add2(struct wpa_authenticator *wpa_auth, const u8 *addr, const u8 *pmk, size_t pmk_len, const u8 *pmkid, - int session_timeout, int akmp); - void wpa_auth_pmksa_remove(struct wpa_authenticator *wpa_auth, diff --git a/src/ap/wpa_auth_i.h b/src/ap/wpa_auth_i.h index a6dc1a591..f46bdabdd 100644 --- a/src/ap/wpa_auth_i.h +++ b/src/ap/wpa_auth_i.h -@@ -235,10 +235,11 @@ struct wpa_authenticator { - struct wpa_ft_pmk_cache *ft_pmk_cache; - +@@ -237,6 +237,7 @@ struct wpa_authenticator { #ifdef CONFIG_P2P struct bitfield *ip_pool; #endif /* CONFIG_P2P */ + unsigned int pmk_life_time; }; - - - #ifdef CONFIG_IEEE80211R_AP - + + diff --git a/wpa_supplicant/ap.c b/wpa_supplicant/ap.c index 6a0a69e68..cade9512b 100644 --- a/wpa_supplicant/ap.c +++ b/wpa_supplicant/ap.c -@@ -603,10 +603,12 @@ static int wpa_supplicant_conf_ap(struct wpa_supplicant *wpa_s, - - if (ssid->sae_pwe != DEFAULT_SAE_PWE) +@@ -605,6 +605,8 @@ static int wpa_supplicant_conf_ap(struct wpa_supplicant *wpa_s, bss->sae_pwe = ssid->sae_pwe; else bss->sae_pwe = wpa_s->conf->sae_pwe; + + bss->dot11RSNAConfigPMKLifetime = wpa_s->conf->dot11RSNAConfigPMKLifetime; #endif /* CONFIG_SAE */ - + if (wpa_s->conf->go_interworking) { - wpa_printf(MSG_DEBUG, - "P2P: Enable Interworking with access_network_type: %d", +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0023-SAE-Drop-PMKSA-cache-after-receiving-specific-deauth.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0020-SAE-Drop-PMKSA-cache-after-receiving-specific-deauth.patch similarity index 81% rename from meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0023-SAE-Drop-PMKSA-cache-after-receiving-specific-deauth.patch rename to meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0020-SAE-Drop-PMKSA-cache-after-receiving-specific-deauth.patch index 251663feb..29d7da831 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0023-SAE-Drop-PMKSA-cache-after-receiving-specific-deauth.patch +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0020-SAE-Drop-PMKSA-cache-after-receiving-specific-deauth.patch @@ -1,6 +1,7 @@ +From ec86cadea38b22595003865c62b5321d55831d9e Mon Sep 17 00:00:00 2001 From: Kurt Lee Date: Thu, 24 Feb 2022 03:57:22 -0600 -Subject: [PATCH] SAE: Drop PMKSA cache after receiving specific deauth +Subject: [PATCH 20/49] SAE: Drop PMKSA cache after receiving specific deauth As a STA mode, when receiving deauth frame with reason code WLAN_REASON_PREV_AUTH_NOT_VALID, it should drop its PMKSA cache. @@ -12,12 +13,10 @@ diff --git a/wpa_supplicant/events.c b/wpa_supplicant/events.c index fe8dbd91d..bfd49ee43 100644 --- a/wpa_supplicant/events.c +++ b/wpa_supplicant/events.c -@@ -4157,10 +4157,29 @@ static void wpas_event_disconnect(struct wpa_supplicant *wpa_s, const u8 *addr, - return; - } +@@ -4159,6 +4159,25 @@ static void wpas_event_disconnect(struct wpa_supplicant *wpa_s, const u8 *addr, } #endif /* CONFIG_P2P */ - + +#ifdef CONFIG_SAE + if (reason_code == WLAN_REASON_PREV_AUTH_NOT_VALID) { + const u8 *bssid = wpa_s->bssid; @@ -40,3 +39,6 @@ index fe8dbd91d..bfd49ee43 100644 wpa_supplicant_event_disassoc_finish(wpa_s, reason_code, locally_generated); } +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0021-Avoid-deauthenticating-STA-if-the-reason-for-freeing.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0021-Avoid-deauthenticating-STA-if-the-reason-for-freeing.patch new file mode 100644 index 000000000..bb1b85bf7 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0021-Avoid-deauthenticating-STA-if-the-reason-for-freeing.patch @@ -0,0 +1,188 @@ +From ed487600a81fa99688201a50176072555c90e690 Mon Sep 17 00:00:00 2001 +From: Gokul Sivakumar +Date: Mon, 25 Apr 2022 18:35:14 +0530 +Subject: [PATCH 21/49] Avoid deauthenticating STA if the reason for freeing + PMK entry isn't expiry + +The PMK cache entry for a STA in the SoftAP managed by wpa_supplicant +can be freed in multiple scenarios like when a new PMK is created after +reconnection or when the the PMK Life time is expired, etc. + +So avoid sending Deauth to the STA when freeing the PMK cache entry for a +specific STA in the SoftAP when attempting to replace it with a new PMK +cache entry derived as part of STA reconnection. Doing this lets the STA +reconnect to the SoftAP successfully after tearing down the connection +because of configured PMK Life time getting expired in the STA. And send +Deauth to STA only when the reason for freeing PMK cache entry is that the +configured PMK Life time got expired in the SoftAP. + +The PMKSA free reasons PMK_FREE, PMK_REPLACE and PMK_EXPIRE are introduced +for SoftAP to be consistent with the PMKSA reasons defined for STA mode in +src/rsn_supp/pmksa_cache.h + + + +--- + src/ap/pmksa_cache_auth.c | 22 +++++++++++++--------- + src/ap/pmksa_cache_auth.h | 12 ++++++++++-- + src/ap/wpa_auth.c | 15 ++++++++++++--- + 3 files changed, 35 insertions(+), 14 deletions(-) + +diff --git a/src/ap/pmksa_cache_auth.c b/src/ap/pmksa_cache_auth.c +index b67b8522e..5084dfa13 100644 +--- a/src/ap/pmksa_cache_auth.c ++++ b/src/ap/pmksa_cache_auth.c +@@ -28,7 +28,8 @@ struct rsn_pmksa_cache { + struct rsn_pmksa_cache_entry *pmksa; + int pmksa_count; + +- void (*free_cb)(struct rsn_pmksa_cache_entry *entry, void *ctx); ++ void (*free_cb)(struct rsn_pmksa_cache_entry *entry, void *ctx, ++ enum pmksa_free_reason reason); + void *ctx; + }; + +@@ -49,13 +50,14 @@ static void _pmksa_cache_free_entry(struct rsn_pmksa_cache_entry *entry) + + + void pmksa_cache_free_entry(struct rsn_pmksa_cache *pmksa, +- struct rsn_pmksa_cache_entry *entry) ++ struct rsn_pmksa_cache_entry *entry, ++ enum pmksa_free_reason reason) + { + struct rsn_pmksa_cache_entry *pos, *prev; + unsigned int hash; + + pmksa->pmksa_count--; +- pmksa->free_cb(entry, pmksa->ctx); ++ pmksa->free_cb(entry, pmksa->ctx, reason); + + /* unlink from hash list */ + hash = PMKID_HASH(entry->pmkid); +@@ -101,7 +103,7 @@ void pmksa_cache_auth_flush(struct rsn_pmksa_cache *pmksa) + while (pmksa->pmksa) { + wpa_printf(MSG_DEBUG, "RSN: Flush PMKSA cache entry for " + MACSTR, MAC2STR(pmksa->pmksa->spa)); +- pmksa_cache_free_entry(pmksa, pmksa->pmksa); ++ pmksa_cache_free_entry(pmksa, pmksa->pmksa, PMKSA_FREE); + } + } + +@@ -113,9 +115,10 @@ static void pmksa_cache_expire(void *eloop_ctx, void *timeout_ctx) + + os_get_reltime(&now); + while (pmksa->pmksa && pmksa->pmksa->expiration <= now.sec) { ++ struct rsn_pmksa_cache_entry *entry = pmksa->pmksa; + wpa_printf(MSG_DEBUG, "RSN: expired PMKSA cache entry for " + MACSTR, MAC2STR(pmksa->pmksa->spa)); +- pmksa_cache_free_entry(pmksa, pmksa->pmksa); ++ pmksa_cache_free_entry(pmksa, entry, PMKSA_EXPIRE); + } + + pmksa_cache_set_expiration(pmksa); +@@ -374,14 +377,14 @@ int pmksa_cache_auth_add_entry(struct rsn_pmksa_cache *pmksa, + */ + pos = pmksa_cache_auth_get(pmksa, entry->spa, NULL); + if (pos) +- pmksa_cache_free_entry(pmksa, pos); ++ pmksa_cache_free_entry(pmksa, pos, PMKSA_REPLACE); + + if (pmksa->pmksa_count >= pmksa_cache_max_entries && pmksa->pmksa) { + /* Remove the oldest entry to make room for the new entry */ + wpa_printf(MSG_DEBUG, "RSN: removed the oldest PMKSA cache " + "entry (for " MACSTR ") to make room for new one", + MAC2STR(pmksa->pmksa->spa)); +- pmksa_cache_free_entry(pmksa, pmksa->pmksa); ++ pmksa_cache_free_entry(pmksa, pmksa->pmksa, PMKSA_FREE); + } + + pmksa_cache_link_entry(pmksa, entry); +@@ -539,7 +542,8 @@ struct rsn_pmksa_cache_entry * pmksa_cache_get_okc( + */ + struct rsn_pmksa_cache * + pmksa_cache_auth_init(void (*free_cb)(struct rsn_pmksa_cache_entry *entry, +- void *ctx), void *ctx) ++ void *ctx, enum pmksa_free_reason reason), ++ void *ctx) + { + struct rsn_pmksa_cache *pmksa; + +@@ -613,7 +617,7 @@ int pmksa_cache_auth_radius_das_disconnect(struct rsn_pmksa_cache *pmksa, + found++; + prev = entry; + entry = entry->next; +- pmksa_cache_free_entry(pmksa, prev); ++ pmksa_cache_free_entry(pmksa, prev, PMKSA_FREE); + continue; + } + entry = entry->next; +diff --git a/src/ap/pmksa_cache_auth.h b/src/ap/pmksa_cache_auth.h +index 2ef217435..ed532dd2e 100644 +--- a/src/ap/pmksa_cache_auth.h ++++ b/src/ap/pmksa_cache_auth.h +@@ -37,9 +37,16 @@ struct rsn_pmksa_cache_entry { + struct rsn_pmksa_cache; + struct radius_das_attrs; + ++enum pmksa_free_reason { ++ PMKSA_FREE, ++ PMKSA_REPLACE, ++ PMKSA_EXPIRE, ++}; ++ + struct rsn_pmksa_cache * + pmksa_cache_auth_init(void (*free_cb)(struct rsn_pmksa_cache_entry *entry, +- void *ctx), void *ctx); ++ void *ctx, enum pmksa_free_reason reason), ++ void *ctx); + void pmksa_cache_auth_deinit(struct rsn_pmksa_cache *pmksa); + struct rsn_pmksa_cache_entry * + pmksa_cache_auth_get(struct rsn_pmksa_cache *pmksa, +@@ -68,7 +75,8 @@ void pmksa_cache_to_eapol_data(struct hostapd_data *hapd, + struct rsn_pmksa_cache_entry *entry, + struct eapol_state_machine *eapol); + void pmksa_cache_free_entry(struct rsn_pmksa_cache *pmksa, +- struct rsn_pmksa_cache_entry *entry); ++ struct rsn_pmksa_cache_entry *entry, ++ enum pmksa_free_reason reason); + int pmksa_cache_auth_radius_das_disconnect(struct rsn_pmksa_cache *pmksa, + struct radius_das_attrs *attr); + int pmksa_cache_auth_list(struct rsn_pmksa_cache *pmksa, char *buf, size_t len); +diff --git a/src/ap/wpa_auth.c b/src/ap/wpa_auth.c +index e92ea4302..9917c13e8 100644 +--- a/src/ap/wpa_auth.c ++++ b/src/ap/wpa_auth.c +@@ -387,10 +387,19 @@ static int wpa_auth_pmksa_clear_cb(struct wpa_state_machine *sm, void *ctx) + + + static void wpa_auth_pmksa_free_cb(struct rsn_pmksa_cache_entry *entry, +- void *ctx) ++ void *ctx, enum pmksa_free_reason reason) + { + struct wpa_authenticator *wpa_auth = ctx; +- wpa_sta_disconnect(wpa_auth, entry->spa, WLAN_REASON_PREV_AUTH_NOT_VALID); ++ ++ if (reason == PMKSA_EXPIRE) { ++ /* ++ * Once when the PMK cache entry for a STA expires in the SoftAP, ++ * send a deauth to the STA from the SoftAP to make the STA reconnect ++ * to the network and derive a new PMK. ++ */ ++ wpa_sta_disconnect(wpa_auth, entry->spa, WLAN_REASON_PREV_AUTH_NOT_VALID); ++ } ++ + wpa_auth_for_each_sta(wpa_auth, wpa_auth_pmksa_clear_cb, entry); + } + +@@ -4894,7 +4903,7 @@ void wpa_auth_pmksa_remove(struct wpa_authenticator *wpa_auth, + if (pmksa) { + wpa_printf(MSG_DEBUG, "WPA: Remove PMKSA cache entry for " + MACSTR " based on request", MAC2STR(sta_addr)); +- pmksa_cache_free_entry(wpa_auth->pmksa, pmksa); ++ pmksa_cache_free_entry(wpa_auth->pmksa, pmksa, PMKSA_FREE); + } + } + +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0022-SAE-Fix-for-PMK-expiration-issue-through-supplicant.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0022-SAE-Fix-for-PMK-expiration-issue-through-supplicant.patch deleted file mode 100644 index 88160f4f0..000000000 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0022-SAE-Fix-for-PMK-expiration-issue-through-supplicant.patch +++ /dev/null @@ -1,42 +0,0 @@ -From: Kurt Lee -Date: Mon, 14 Feb 2022 00:08:23 -0600 -Subject: [PATCH] SAE: Fix for PMK expiration issue through supplicant - (second) - -Description : Sending Deauth from AP once PMK timeout occurs, So that -STA will initiate the Auth process. -Changes : 1) Added support to get the dot11RSNAConfigPMKLifetime conf -element in wpa_authenticator structure to pass to the lower API's -2) Sending deauth from the wpa_auth_pmksa_free_cb once PMK time out -occurs. -Tested: Confirmed once PMK timeout occurs AP is sending deauth and STA -starting AUTH frame. - -Porting from project: hostap_upstream, branch: IOT_HOSTAP_BRANCH_1_201 -ID: 587411dd with modified hostapd/config_file.c for configuration of -hostapd - -Second part: changes to 'hostapd' directory. - -Signed-off-by: Arturo Buzarra ---- - hostapd/config_file.c | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/hostapd/config_file.c b/hostapd/config_file.c -index b14728d1b..386499323 100644 ---- a/hostapd/config_file.c -+++ b/hostapd/config_file.c -@@ -3669,10 +3669,12 @@ static int hostapd_config_fill(struct hostapd_config *conf, - #endif /* CONFIG_IEEE80211AX */ - } else if (os_strcmp(buf, "max_listen_interval") == 0) { - bss->max_listen_interval = atoi(pos); - } else if (os_strcmp(buf, "disable_pmksa_caching") == 0) { - bss->disable_pmksa_caching = atoi(pos); -+ } else if (os_strcmp(buf, "dot11RSNAConfigPMKLifetime") == 0) { -+ bss->dot11RSNAConfigPMKLifetime = atoi(pos); - } else if (os_strcmp(buf, "okc") == 0) { - bss->okc = atoi(pos); - #ifdef CONFIG_WPS - } else if (os_strcmp(buf, "wps_state") == 0) { - bss->wps_state = atoi(pos); diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0022-wpa_supplicant-support-bgscan.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0022-wpa_supplicant-support-bgscan.patch new file mode 100644 index 000000000..6899b06f4 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0022-wpa_supplicant-support-bgscan.patch @@ -0,0 +1,32 @@ +From cfa528ffe320ac638ca72e87751f76444669c48e Mon Sep 17 00:00:00 2001 +From: Ian Lin +Date: Fri, 20 May 2022 03:00:37 -0500 +Subject: [PATCH 22/49] wpa_supplicant: support bgscan + +Modify defconfig_base to support bgscan feature + +Signed-off-by: Ian Lin +--- + wpa_supplicant/defconfig_base | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base +index 99c74853d..4f71b50ff 100644 +--- a/wpa_supplicant/defconfig_base ++++ b/wpa_supplicant/defconfig_base +@@ -601,10 +601,10 @@ CONFIG_P2P=y + # operations for roaming within an ESS (same SSID). See the bgscan parameter in + # the wpa_supplicant.conf file for more details. + # Periodic background scans based on signal strength +-#CONFIG_BGSCAN_SIMPLE=y ++CONFIG_BGSCAN_SIMPLE=y + # Learn channels used by the network and try to avoid bgscans on other + # channels (experimental) +-#CONFIG_BGSCAN_LEARN=y ++CONFIG_BGSCAN_LEARN=y + + # Opportunistic Wireless Encryption (OWE) + # Experimental implementation of draft-harkins-owe-07.txt +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0023-non-upstream-wl-cmd-create-interface-to-support-driv.murata.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0023-non-upstream-wl-cmd-create-interface-to-support-driv.murata.patch new file mode 100644 index 000000000..ac051fce0 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0023-non-upstream-wl-cmd-create-interface-to-support-driv.murata.patch @@ -0,0 +1,867 @@ +From 1cfe2ac93a1b50a6fd2f6d0022ece6e0f2a91259 Mon Sep 17 00:00:00 2001 +From: Kurt Lee +Date: Sun, 10 Apr 2022 22:10:51 -0500 +Subject: [PATCH 23/49] non-upstream: wl-cmd: create interface to support + driver priv command + +1. Create "wl" command interface to set/get driver information +2. Create files and compile flag to separate this feature +3. Support 2g_rate/5g_rate command + +Signed-off-by: Ian Lin +Signed-off-by: Kurt Lee +--- + hostapd/defconfig_base | 2 + + src/ap/ap_drv_ops.h | 10 ++ + src/common/brcm_wl_ioctl.h | 10 ++ + src/common/brcm_wl_ioctl_defs.h | 15 ++ + src/common/brcm_wl_rspec.h | 104 +++++++++++ + src/drivers/driver.h | 1 + + src/drivers/driver_brcm_nl80211.h | 26 +++ + src/drivers/driver_brcm_wlu.c | 289 ++++++++++++++++++++++++++++++ + src/drivers/driver_brcm_wlu.h | 12 ++ + src/drivers/driver_nl80211.c | 149 +++++++++++++++ + src/drivers/drivers.mak | 5 + + wpa_supplicant/ctrl_iface.c | 22 +++ + wpa_supplicant/defconfig_base | 2 + + wpa_supplicant/driver_i.h | 10 ++ + wpa_supplicant/wpa_cli.c | 8 +- + 15 files changed, 664 insertions(+), 1 deletion(-) + create mode 100644 src/common/brcm_wl_ioctl.h + create mode 100644 src/common/brcm_wl_ioctl_defs.h + create mode 100644 src/common/brcm_wl_rspec.h + create mode 100644 src/drivers/driver_brcm_nl80211.h + create mode 100644 src/drivers/driver_brcm_wlu.c + create mode 100644 src/drivers/driver_brcm_wlu.h + +diff --git a/hostapd/defconfig_base b/hostapd/defconfig_base +index dafcf0f6c..4e4f0f784 100644 +--- a/hostapd/defconfig_base ++++ b/hostapd/defconfig_base +@@ -21,6 +21,8 @@ CONFIG_DRIVER_NL80211=y + # QCA vendor extensions to nl80211 + #CONFIG_DRIVER_NL80211_QCA=y + ++CONFIG_DRIVER_BRCM_WL=y ++ + # driver_nl80211.c requires libnl. If you are compiling it yourself + # you may need to point hostapd to your version of libnl. + # +diff --git a/src/ap/ap_drv_ops.h b/src/ap/ap_drv_ops.h +index 61c8f64eb..5bf092c46 100644 +--- a/src/ap/ap_drv_ops.h ++++ b/src/ap/ap_drv_ops.h +@@ -403,6 +403,16 @@ static inline int hostapd_drv_driver_cmd(struct hostapd_data *hapd, + } + #endif /* ANDROID */ + ++#ifdef CONFIG_DRIVER_BRCM_WL ++static inline int hostapd_drv_wl_cmd(struct hostapd_data *hapd, ++ char *cmd, char *buf, size_t buf_len) ++{ ++ if (!hapd->driver->wl_cmd) ++ return -1; ++ return hapd->driver->wl_cmd(hapd->drv_priv, cmd, buf, buf_len); ++} ++#endif /* CONFIG_DRIVER_BRCM_WL */ ++ + #ifdef CONFIG_TESTING_OPTIONS + static inline int + hostapd_drv_register_frame(struct hostapd_data *hapd, u16 type, +diff --git a/src/common/brcm_wl_ioctl.h b/src/common/brcm_wl_ioctl.h +new file mode 100644 +index 000000000..768b78616 +--- /dev/null ++++ b/src/common/brcm_wl_ioctl.h +@@ -0,0 +1,10 @@ ++/* ++ * Broadcom Corporation OUI and vendor specific assignments ++ * Copyright (c) 2020, Broadcom Corporation. ++ * ++ * This software may be distributed under the terms of the BSD license. ++ * See README for more details. ++ */ ++ ++#include "common/brcm_wl_ioctl_defs.h" ++#include "common/brcm_wl_rspec.h" +diff --git a/src/common/brcm_wl_ioctl_defs.h b/src/common/brcm_wl_ioctl_defs.h +new file mode 100644 +index 000000000..1834be6fa +--- /dev/null ++++ b/src/common/brcm_wl_ioctl_defs.h +@@ -0,0 +1,15 @@ ++/* ++ * Broadcom Corporation OUI and vendor specific assignments ++ * Copyright (c) 2020, Broadcom Corporation. ++ * ++ * This software may be distributed under the terms of the BSD license. ++ * See README for more details. ++ */ ++ ++#define WLC_IOCTL_SMLEN 256 /* "small" length ioctl buffer required */ ++#define WLC_IOCTL_MEDLEN 1896 /* "med" length ioctl buffer required */ ++ ++/* common ioctl definitions */ ++#define WLC_GET_VAR 262 /* get value of named variable */ ++#define WLC_SET_VAR 263 /* set named variable to value */ ++ +diff --git a/src/common/brcm_wl_rspec.h b/src/common/brcm_wl_rspec.h +new file mode 100644 +index 000000000..d10e82597 +--- /dev/null ++++ b/src/common/brcm_wl_rspec.h +@@ -0,0 +1,104 @@ ++/* ++ * Broadcom Corporation OUI and vendor specific assignments ++ * Copyright (c) 2020, Broadcom Corporation. ++ * ++ * This software may be distributed under the terms of the BSD license. ++ * See README for more details. ++ */ ++ ++/* Rate spec. definitions */ ++#define WL_RSPEC_RATE_MASK 0x000000FF /**< Legacy rate or MCS or MCS + NSS */ ++#define WL_RSPEC_TXEXP_MASK 0x00000300 /**< Tx chain expansion beyond Nsts */ ++#define WL_RSPEC_TXEXP_SHIFT 8 ++#define WL_RSPEC_HE_GI_MASK 0x00000C00 /* HE GI indices */ ++#define WL_RSPEC_HE_GI_SHIFT 10 ++#define WL_RSPEC_BW_MASK 0x00070000 /**< Band width */ ++#define WL_RSPEC_BW_SHIFT 16 ++#define WL_RSPEC_ER_MASK 0x0000C000 /**< Range extension mask */ ++#define WL_RSPEC_ER_SHIFT 14 ++#define WL_RSPEC_ER_ENAB_MASK 0x00008000 /**< Range extension enable */ ++#define WL_RSPEC_ER_ENAB_SHIFT 15 ++#define WL_RSPEC_ER_TONE_MASK 0x00004000 /**< Range extension tone config */ ++#define WL_RSPEC_ER_TONE_SHIFT 14 ++ ++#define WL_RSPEC_DCM 0x00080000 /**< Dual Carrier Modulation */ ++#define WL_RSPEC_DCM_SHIFT 19 ++#define WL_RSPEC_STBC 0x00100000 /**< STBC expansion, Nsts = 2 * Nss */ ++#define WL_RSPEC_TXBF 0x00200000 ++#define WL_RSPEC_LDPC 0x00400000 ++#define WL_RSPEC_SGI 0x00800000 ++#define WL_RSPEC_SHORT_PREAMBLE 0x00800000 /**< DSSS short preable - Encoding 0 */ ++#define WL_RSPEC_ENCODING_MASK 0x03000000 /**< Encoding of RSPEC_RATE field */ ++#define WL_RSPEC_ENCODING_SHIFT 24 ++ ++#define WL_RSPEC_OVERRIDE_RATE 0x40000000 /**< override rate only */ ++#define WL_RSPEC_OVERRIDE_MODE 0x80000000 /**< override both rate & mode */ ++ ++/* ======== RSPEC_HE_GI|RSPEC_SGI fields for HE ======== */ ++ ++/* GI for HE */ ++#define RSPEC_HE_LTF_GI(rspec) (((rspec) & WL_RSPEC_HE_GI_MASK) >> WL_RSPEC_HE_GI_SHIFT) ++#define WL_RSPEC_HE_1x_LTF_GI_0_8us (0x0) ++#define WL_RSPEC_HE_2x_LTF_GI_0_8us (0x1) ++#define WL_RSPEC_HE_2x_LTF_GI_1_6us (0x2) ++#define WL_RSPEC_HE_4x_LTF_GI_3_2us (0x3) ++#define RSPEC_ISHEGI(rspec) (RSPEC_HE_LTF_GI(rspec) > WL_RSPEC_HE_1x_LTF_GI_0_8us) ++#define HE_GI_TO_RSPEC(gi) (((gi) << WL_RSPEC_HE_GI_SHIFT) & WL_RSPEC_HE_GI_MASK) ++ ++/* RSPEC Macros for extracting and using HE-ER and DCM */ ++#define RSPEC_HE_DCM(rspec) (((rspec) & WL_RSPEC_DCM) >> WL_RSPEC_DCM_SHIFT) ++#define RSPEC_HE_ER(rspec) (((rspec) & WL_RSPEC_ER_MASK) >> WL_RSPEC_ER_SHIFT) ++#define RSPEC_HE_ER_ENAB(rspec) (((rspec) & WL_RSPEC_ER_ENAB_MASK) >> \ ++ WL_RSPEC_ER_ENAB_SHIFT) ++#define RSPEC_HE_ER_TONE(rspec) (((rspec) & WL_RSPEC_ER_TONE_MASK) >> \ ++ WL_RSPEC_ER_TONE_SHIFT) ++/* ======== RSPEC_RATE field ======== */ ++ ++/* Encoding 0 - legacy rate */ ++/* DSSS, CCK, and OFDM rates in [500kbps] units */ ++#define WL_RSPEC_LEGACY_RATE_MASK 0x0000007F ++#define WLC_RATE_1M 2 ++#define WLC_RATE_2M 4 ++#define WLC_RATE_5M5 11 ++#define WLC_RATE_11M 22 ++#define WLC_RATE_6M 12 ++#define WLC_RATE_9M 18 ++#define WLC_RATE_12M 24 ++#define WLC_RATE_18M 36 ++#define WLC_RATE_24M 48 ++#define WLC_RATE_36M 72 ++#define WLC_RATE_48M 96 ++#define WLC_RATE_54M 108 ++ ++/* Encoding 1 - HT MCS */ ++#define WL_RSPEC_HT_MCS_MASK 0x0000007F /**< HT MCS value mask in rspec */ ++ ++/* Encoding 2 - VHT MCS + NSS */ ++#define WL_RSPEC_VHT_MCS_MASK 0x0000000F /**< VHT MCS value mask in rspec */ ++#define WL_RSPEC_VHT_NSS_MASK 0x000000F0 /**< VHT Nss value mask in rspec */ ++#define WL_RSPEC_VHT_NSS_SHIFT 4 /**< VHT Nss value shift in rspec */ ++ ++/* Encoding 3 - HE MCS + NSS */ ++#define WL_RSPEC_HE_MCS_MASK 0x0000000F /**< HE MCS value mask in rspec */ ++#define WL_RSPEC_HE_NSS_MASK 0x000000F0 /**< HE Nss value mask in rspec */ ++#define WL_RSPEC_HE_NSS_SHIFT 4 /**< HE Nss value shift in rpsec */ ++ ++/* ======== RSPEC_BW field ======== */ ++ ++#define WL_RSPEC_BW_UNSPECIFIED 0 ++#define WL_RSPEC_BW_20MHZ 0x00010000 ++#define WL_RSPEC_BW_40MHZ 0x00020000 ++#define WL_RSPEC_BW_80MHZ 0x00030000 ++#define WL_RSPEC_BW_160MHZ 0x00040000 ++#define WL_RSPEC_BW_10MHZ 0x00050000 ++#define WL_RSPEC_BW_5MHZ 0x00060000 ++#define WL_RSPEC_BW_2P5MHZ 0x00070000 ++ ++/* ======== RSPEC_ENCODING field ======== */ ++ ++#define WL_RSPEC_ENCODE_RATE 0x00000000 /**< Legacy rate is stored in RSPEC_RATE */ ++#define WL_RSPEC_ENCODE_HT 0x01000000 /**< HT MCS is stored in RSPEC_RATE */ ++#define WL_RSPEC_ENCODE_VHT 0x02000000 /**< VHT MCS and NSS are stored in RSPEC_RATE */ ++#define WL_RSPEC_ENCODE_HE 0x03000000 /**< HE MCS and NSS are stored in RSPEC_RATE */ ++#define WL_RSPEC_HE_NSS_UNSPECIFIED 0xF ++ +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index fb3f8b4a8..3d48f6f07 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -3861,6 +3861,7 @@ struct wpa_driver_ops { + */ + int (*driver_cmd)(void *priv, char *cmd, char *buf, size_t buf_len); + #endif /* ANDROID */ ++ int (*wl_cmd)(void *priv, char *cmd, char *buf, size_t buf_len); + + /** + * vendor_cmd - Execute vendor specific command +diff --git a/src/drivers/driver_brcm_nl80211.h b/src/drivers/driver_brcm_nl80211.h +new file mode 100644 +index 000000000..40a84d125 +--- /dev/null ++++ b/src/drivers/driver_brcm_nl80211.h +@@ -0,0 +1,26 @@ ++/* ++ * Broadcom Corporation OUI and vendor specific assignments ++ * Copyright (c) 2020, Broadcom Corporation. ++ * ++ * This software may be distributed under the terms of the BSD license. ++ * See README for more details. ++ */ ++ ++struct bcm_nlmsg_hdr { ++ uint cmd; /* common ioctl definition */ ++ int len; /* expected return buffer length */ ++ uint offset; /* user buffer offset */ ++ uint set; /* get or set request optional */ ++ uint magic; /* magic number for verification */ ++}; ++ ++enum bcmnl_attrs { ++ BCM_NLATTR_UNSPEC, ++ ++ BCM_NLATTR_LEN, ++ BCM_NLATTR_DATA, ++ ++ __BCM_NLATTR_AFTER_LAST, ++ BCM_NLATTR_MAX = __BCM_NLATTR_AFTER_LAST - 1 ++}; ++ +diff --git a/src/drivers/driver_brcm_wlu.c b/src/drivers/driver_brcm_wlu.c +new file mode 100644 +index 000000000..f2264ebcc +--- /dev/null ++++ b/src/drivers/driver_brcm_wlu.c +@@ -0,0 +1,289 @@ ++/* ++ * Broadcom Corporation OUI and vendor specific assignments ++ * Copyright (c) 2020, Broadcom Corporation. ++ * ++ * This software may be distributed under the terms of the BSD license. ++ * See README for more details. ++ */ ++ ++#include "includes.h" ++#include "common.h" ++#include "common/brcm_vendor.h" ++#include "common/brcm_wl_ioctl.h" ++#include "common/wpa_common.h" ++ ++/* ++ * Format a ratespec for output of any of the wl_rate() iovars ++ */ ++char* ++wl_rate_print(char *rate_buf, size_t buf_len, u32 rspec) ++{ ++ uint encode, rate, txexp, bw_val; ++ const char* stbc; ++ const char* ldpc; ++ const char* bw; ++ const char* dcm; ++ const char* er; ++ u8 valid_encding = false; ++ ++ encode = (rspec & WL_RSPEC_ENCODING_MASK); ++ rate = (rspec & WL_RSPEC_RATE_MASK); ++ txexp = (rspec & WL_RSPEC_TXEXP_MASK) >> WL_RSPEC_TXEXP_SHIFT; ++ bw_val = (rspec & WL_RSPEC_BW_MASK); ++ stbc = ((rspec & WL_RSPEC_STBC) != 0) ? " stbc" : ""; ++ ldpc = ((rspec & WL_RSPEC_LDPC) != 0) ? " ldpc" : ""; ++ dcm = ((rspec & WL_RSPEC_DCM) != 0) ? " dcm" : ""; ++ ++ if (RSPEC_HE_ER_ENAB(rspec) != 0) { ++ er = RSPEC_HE_ER_TONE(rspec) ? " er 106" : " er 242"; ++ } else { ++ er = ""; ++ } ++ ++ if (bw_val == WL_RSPEC_BW_UNSPECIFIED) { ++ bw = "auto"; ++ } else if (bw_val == WL_RSPEC_BW_20MHZ) { ++ bw = "20"; ++ } else if (bw_val == WL_RSPEC_BW_40MHZ) { ++ bw = "40"; ++ } else if (bw_val == WL_RSPEC_BW_80MHZ) { ++ bw = "80"; ++ } else if (bw_val == WL_RSPEC_BW_160MHZ) { ++ bw = "160"; ++ } else if (bw_val == WL_RSPEC_BW_10MHZ) { ++ bw = "10"; ++ } else if (bw_val == WL_RSPEC_BW_5MHZ) { ++ bw = "5"; ++ } else if (bw_val == WL_RSPEC_BW_2P5MHZ) { ++ bw = "2.5"; ++ } else { ++ bw = "???"; ++ } ++ ++ if ((rspec & ~WL_RSPEC_TXEXP_MASK) == 0) { /* Ignore TxExpansion for NULL rspec check */ ++ valid_encding = true; ++ os_snprintf(rate_buf, buf_len, "auto"); ++ } else if (encode == WL_RSPEC_ENCODE_HE) { ++ const char* gi_ltf[] = {" 1xLTF GI 0.8us", " 2xLTF GI 0.8us", ++ " 2xLTF GI 1.6us", " 4xLTF GI 3.2us"}; ++ u8 gi_int = RSPEC_HE_LTF_GI(rspec); ++ uint mcs = (rspec & WL_RSPEC_HE_MCS_MASK); ++ uint Nss = (rspec & WL_RSPEC_HE_NSS_MASK) >> WL_RSPEC_HE_NSS_SHIFT; ++ ++ valid_encding = true; ++ ++ os_snprintf(rate_buf, buf_len, "he mcs %d Nss %d Tx Exp %d BW %s%s%s%s%s%s", ++ mcs, Nss, txexp, bw, stbc, ldpc, gi_ltf[gi_int], dcm, er); ++ ++ } else { ++ const char* sgi; ++ sgi = ((rspec & WL_RSPEC_SGI) != 0) ? " sgi" : ""; ++ if (encode == WL_RSPEC_ENCODE_RATE) { ++ ++ valid_encding = true; ++ ++ os_snprintf(rate_buf, buf_len, "rate %d%s Mbps Tx Exp %d", ++ rate/2, (rate % 2)?".5":"", txexp); ++ } else if (encode == WL_RSPEC_ENCODE_HT) { ++ ++ valid_encding = true; ++ ++ os_snprintf(rate_buf, buf_len, "ht mcs %d Tx Exp %d BW %s%s%s%s", ++ rate, txexp, bw, stbc, ldpc, sgi); ++ } else if (encode == WL_RSPEC_ENCODE_VHT) { ++ uint mcs = (rspec & WL_RSPEC_VHT_MCS_MASK); ++ uint Nss = (rspec & WL_RSPEC_VHT_NSS_MASK) >> WL_RSPEC_VHT_NSS_SHIFT; ++ ++ valid_encding = true; ++ ++ os_snprintf(rate_buf, buf_len, "vht mcs %d Nss %d Tx Exp %d BW %s%s%s%s", ++ mcs, Nss, txexp, bw, stbc, ldpc, sgi); ++ } ++ } ++ ++ if (!valid_encding) { ++ os_snprintf(rate_buf, buf_len, "", rspec); ++ } ++ ++ return rate_buf; ++} ++ ++ ++/* parse the -v/--vht or -c argument for the wl_rate() command. ++ * return FALSE if the arg does not look like MxS or cMsS, where M and S are single digits ++ * return TRUE if the arg does look like MxS or cMsS, setting mcsp to M, and nssp to S ++ */ ++//static int ++int ++wl_parse_he_vht_spec(const char* cp, int* mcsp, int* nssp) ++{ ++ char *startp, *endp; ++ char c; ++ int mcs, nss; ++ char sx; ++ ++ if (cp == NULL || cp[0] == '\0') { ++ return false; ++ } ++ ++ if (cp[0] == 'c') { ++ startp = (char*)cp + 1; ++ sx = 's'; ++ } ++ else { ++ startp = (char*)cp; ++ sx = 'x'; ++ } ++ ++ mcs = (int)strtol(startp, &endp, 10); ++ /* verify MCS 0-11, and next char is 's' or 'x' */ ++ /* HE MCS is 0-11, VHT MCS 0-9 and prop MCS 10-11 */ ++ if (mcs < 0 || mcs > 11 || endp[0] != sx) { ++ return false; ++ } ++ ++ /* grab the char after the 'x'/'s' and convert to value */ ++ c = endp[1]; ++ nss = 0; ++ if (isdigit((int)c)) { ++ nss = c - '0'; ++ } ++ ++ /* consume trailing space after digit */ ++ cp = &endp[2]; ++ while (isspace((int)(*cp))) { ++ cp++; ++ } ++ ++ /* check for trailing garbage after digit */ ++ if (cp[0] != '\0') { ++ return false; ++ } ++ ++ if (nss < 1 || nss > 8) { ++ return false; ++ } ++ ++ *mcsp = mcs; ++ *nssp = nss; ++ ++ return true; ++} ++ ++ ++int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len) ++{ ++ int ret = -1; ++ char *pos; ++ //bool legacy_set = false, ht_set = false, vht_set = false, he_set = false; ++ bool he_set = false; ++ int rate, mcs, Nss, tx_exp, bw; ++ bool stbc, ldpc, sgi, dcm, er; ++ u8 hegi; ++ ++ u32 rspec = 0; ++ int val_int = 0; ++ char *endp; ++ ++ /* set default values */ ++ rate = 0; ++ mcs = 0; ++ Nss = 0; ++ tx_exp = 0; ++ stbc = false; ++ ldpc = false; ++ sgi = false; ++ hegi = 0xFF; ++ bw = 0; ++ dcm = false; ++ er = false; ++ ++ pos = os_strstr(cmd, "-r "); ++ if (pos) { ++ pos += 3; ++ rate = atoi(pos) * 2; ++ rspec = WL_RSPEC_ENCODE_RATE; /* 11abg */ ++ rspec |= rate; ++ } ++ ++ /* Option: -e or --he */ ++ pos = os_strstr(cmd, "-e "); ++ if (pos) { ++ char var_str[10]; ++ pos += 3; ++ endp = os_strchr(pos, ' '); ++ if (endp == NULL) ++ endp = os_strchr(pos, '\0'); ++ os_memcpy(var_str, pos, endp - pos); ++ var_str[endp - pos] = '\0'; ++ ++ val_int = (int)strtol(var_str, &endp, 10); ++ if (*endp == '\0') { ++ mcs = val_int; ++ he_set = true; ++ } else if (wl_parse_he_vht_spec(var_str, &mcs, &Nss)) { ++ he_set = true; ++ } else { ++ wpa_printf(MSG_DEBUG, "%s: could not parse \"%s\"" ++ "as a value for %s option", ++ "5g_rate", pos, "-e"); ++ goto exit; ++ } ++ ++ if (he_set) { ++ rspec = WL_RSPEC_ENCODE_HE; /* 11ax HE */ ++ if (Nss == 0) { ++ Nss = WL_RSPEC_HE_NSS_UNSPECIFIED; ++ } ++ rspec |= (Nss << WL_RSPEC_HE_NSS_SHIFT) | mcs; ++ } ++ } ++ ++ ++ pos = os_strstr(cmd, "-i "); ++ if (pos) { ++ if (!he_set) { ++ wpa_printf(MSG_DEBUG, ":use -i option only in he "); ++ goto exit; ++ } ++ ++ pos += 3; ++ val_int = (int)strtol(pos, &endp, 10); ++ if (*endp == '\0') { ++ if (val_int < 4) ++ { ++ hegi = val_int; ++ } ++ else { ++ wpa_printf(MSG_DEBUG, "%s: could not parse " ++ "\"%s\" as a value for %s option", ++ "5g_rate", pos, "-i"); ++ goto exit; ++ } ++ } ++ } ++ ++ /* Option: -l or --ldpc */ ++ pos = os_strstr(cmd, "-l"); ++ if (pos) { ++ ldpc = true; ++ } ++ ++ /* set the other rspec fields */ ++ rspec |= (tx_exp << WL_RSPEC_TXEXP_SHIFT); ++ rspec |= bw; ++ rspec |= (stbc ? WL_RSPEC_STBC : 0); ++ rspec |= (ldpc ? WL_RSPEC_LDPC : 0); ++ rspec |= (sgi ? WL_RSPEC_SGI : 0); ++ rspec |= ((hegi != 0xFF) ? HE_GI_TO_RSPEC(hegi) : 0); ++ rspec |= (dcm << WL_RSPEC_DCM_SHIFT); ++ rspec |= (er << WL_RSPEC_ER_SHIFT); ++ ++ os_memcpy(set_buf + *set_buf_len, (char *)&rspec, sizeof(rspec)); ++ *set_buf_len += sizeof(rspec); ++ ++ ret = 0; ++exit: ++ return ret; ++} ++ +diff --git a/src/drivers/driver_brcm_wlu.h b/src/drivers/driver_brcm_wlu.h +new file mode 100644 +index 000000000..67832dc6a +--- /dev/null ++++ b/src/drivers/driver_brcm_wlu.h +@@ -0,0 +1,12 @@ ++/* ++ * Broadcom Corporation OUI and vendor specific assignments ++ * Copyright (c) 2020, Broadcom Corporation. ++ * ++ * This software may be distributed under the terms of the BSD license. ++ * See README for more details. ++ */ ++ ++/* Format a ratespec for output of any of the wl_rate() iovars */ ++char* wl_rate_print(char *rate_buf, size_t buf_len, u32 rspec); ++ ++int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len); +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index 964486c11..8b04f9dc9 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -28,6 +28,11 @@ + #include "common/qca-vendor.h" + #include "common/qca-vendor-attr.h" + #include "common/brcm_vendor.h" ++#ifdef CONFIG_DRIVER_BRCM_WL ++#include "common/brcm_wl_ioctl.h" ++#include "driver_brcm_wlu.h" ++#include "drivers/driver_brcm_nl80211.h" ++#endif /* CONFIG_DRIVER_BRCM_WL */ + #include "common/ieee802_11_defs.h" + #include "common/ieee802_11_common.h" + #include "common/wpa_common.h" +@@ -10121,6 +10126,147 @@ static bool is_cmd_with_nested_attrs(unsigned int vendor_id, + } + + ++#ifdef CONFIG_DRIVER_BRCM_WL ++static int nl80211_wl_reply_handler(struct nl_msg *msg, void *arg) ++{ ++ struct nlattr *tb_msg[NL80211_ATTR_MAX + 1]; ++ struct nlattr *bcmnl[BCM_NLATTR_MAX + 1]; ++ struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg)); ++ char *buf = arg; ++ int ret = 0; ++ ++ wpa_printf(MSG_INFO, "nl80211: wl command reply handler"); ++ ++ nla_parse(tb_msg, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0), ++ genlmsg_attrlen(gnlh, 0), NULL); ++ ++ if (tb_msg[NL80211_ATTR_VENDOR_DATA]) { ++ wpa_printf(MSG_INFO, "nl80211: Vendor Data Found"); ++ ret = nla_parse_nested(bcmnl, BCM_NLATTR_MAX, ++ tb_msg[NL80211_ATTR_VENDOR_DATA], NULL); ++ if (ret != 0) ++ return NL_SKIP; ++ os_memcpy(buf, nla_data(bcmnl[BCM_NLATTR_DATA]), nla_get_u16(bcmnl[BCM_NLATTR_LEN])); ++ } ++ ++ return NL_SKIP; ++} ++ ++ ++int nl80211_wl_command(void *priv, char *cmd, char *buf, size_t buf_len) ++{ ++ struct i802_bss *bss = priv; ++ struct wpa_driver_nl80211_data *drv = bss->drv; ++ struct nl_msg *msg; ++ int ret = -1; ++ struct bcm_nlmsg_hdr *nlioc; ++ char *pos; ++ char smbuf[WLC_IOCTL_SMLEN * 2] = {0x00}; ++ char outbuf[WLC_IOCTL_MEDLEN] = {0x00}; ++ u32 msglen = 0; ++ bool set = false; ++ ++ bool is_get_int = false; ++ u32 output_val = 0x00; ++ ++ msg = nlmsg_alloc(); ++ if (!msg) ++ return -ENOMEM; ++ ++ pos = os_strstr(cmd, "5g_rate"); ++ if (pos) { ++ os_memcpy(smbuf, cmd, strlen("5g_rate")); //Keep last byte as 0x00 ++ is_get_int = true; ++ msglen += strlen("5g_rate"); ++ ++ if (os_strncasecmp(cmd, "5g_rate ", 8) == 0) { ++ set = true; ++ cmd += strlen("5g_rate "); ++ msglen += 1; ++ ++ ret = wl_rate_set(cmd, smbuf, &msglen); ++ if (ret != 0) ++ goto exit; ++ } ++ } ++ ++ pos = os_strstr(cmd, "2g_rate"); ++ if (pos) { ++ os_memcpy(smbuf, cmd, strlen("2g_rate")); //Keep last byte as 0x00 ++ is_get_int = true; ++ msglen += strlen("2g_rate"); ++ ++ if (os_strncasecmp(cmd, "2g_rate ", 8) == 0) { ++ set = true; ++ cmd += strlen("2g_rate "); ++ msglen += 1; ++ ++ ret = wl_rate_set(cmd, smbuf, &msglen); ++ if (ret != 0) ++ goto exit; ++ } ++ } ++ ++ /* nlmsg_alloc() can only allocate default_pagesize packet, cap ++ * any buffer send down to 1536 bytes ++ * DO NOT switch to nlmsg_alloc_size because Android doesn't support it ++ */ ++ if (msglen > 0x600) ++ msglen = 0x600; ++ if (set) ++ msglen += sizeof(struct bcm_nlmsg_hdr); ++ else ++ msglen = WLC_IOCTL_SMLEN; ++ nlioc = malloc(msglen); ++ if (nlioc == NULL) { ++ nlmsg_free(msg); ++ return -ENOMEM; ++ } ++ if (set) ++ nlioc->cmd = WLC_SET_VAR; ++ else ++ nlioc->cmd = WLC_GET_VAR; ++ nlioc->len = msglen - sizeof(struct bcm_nlmsg_hdr); ++ nlioc->offset = sizeof(struct bcm_nlmsg_hdr); ++ nlioc->set = set; ++ nlioc->magic = 0; ++ os_memcpy(((void *)nlioc) + nlioc->offset, smbuf, msglen - nlioc->offset); ++ ++ nl80211_cmd(drv, msg, 0, NL80211_CMD_VENDOR); ++ if (nl80211_set_iface_id(msg, bss) < 0) { ++ goto nla_put_failure; ++ } ++ ++ NLA_PUT_U32(msg, NL80211_ATTR_VENDOR_ID, OUI_BRCM); ++ NLA_PUT_U32(msg, NL80211_ATTR_VENDOR_SUBCMD, BRCM_VENDOR_SCMD_PRIV_STR); ++ NLA_PUT(msg, NL80211_ATTR_VENDOR_DATA, msglen, nlioc); ++ ++ ret = send_and_recv_msgs(drv, msg, nl80211_wl_reply_handler, outbuf, NULL, NULL); ++ msg = NULL; ++ if (ret) { ++ wpa_printf(MSG_ERROR, "nl80211: vendor cmd failed: " ++ "ret=%d (%s)", ret, strerror(-ret)); ++ ret = 0; ++ } ++ ++ wpa_printf(MSG_DEBUG, "nl80211: vendor cmd sent successfully "); ++ ++ if (set == false && is_get_int == true) { ++ os_memcpy(&output_val, outbuf, sizeof(output_val)); ++ wl_rate_print(buf, buf_len, output_val); ++ ret = buf_len; ++ } ++ ++nla_put_failure: ++exit: ++ ++ nlmsg_free(msg); ++ ++ return ret; ++} ++#endif /* CONFIG_DRIVER_BRCM_WL */ ++ ++ + static int nl80211_vendor_cmd(void *priv, unsigned int vendor_id, + unsigned int subcmd, const u8 *data, + size_t data_len, enum nested_attr nested_attr, +@@ -12263,6 +12409,9 @@ const struct wpa_driver_ops wpa_driver_nl80211_ops = { + .driver_cmd = wpa_driver_nl80211_driver_cmd, + #endif /* !ANDROID_LIB_STUB */ + #endif /* ANDROID */ ++#ifdef CONFIG_DRIVER_BRCM_WL ++ .wl_cmd = nl80211_wl_command, ++#endif /* CONFIG_DRIVER_BRCM_WL */ + .vendor_cmd = nl80211_vendor_cmd, + .set_qos_map = nl80211_set_qos_map, + .get_wowlan = nl80211_get_wowlan, +diff --git a/src/drivers/drivers.mak b/src/drivers/drivers.mak +index a03d4a034..a986fa379 100644 +--- a/src/drivers/drivers.mak ++++ b/src/drivers/drivers.mak +@@ -30,6 +30,11 @@ ifdef CONFIG_DRIVER_NL80211_BRCM + DRV_CFLAGS += -DCONFIG_DRIVER_NL80211_BRCM + endif + ++ifdef CONFIG_DRIVER_BRCM_WL ++DRV_CFLAGS += -DCONFIG_DRIVER_BRCM_WL ++DRV_OBJS += ../src/drivers/driver_brcm_wlu.o ++endif ++ + ifdef CONFIG_DRIVER_MACSEC_QCA + DRV_CFLAGS += -DCONFIG_DRIVER_MACSEC_QCA + DRV_OBJS += ../src/drivers/driver_macsec_qca.o +diff --git a/wpa_supplicant/ctrl_iface.c b/wpa_supplicant/ctrl_iface.c +index bcd67fca3..86dcb9d84 100644 +--- a/wpa_supplicant/ctrl_iface.c ++++ b/wpa_supplicant/ctrl_iface.c +@@ -8296,6 +8296,23 @@ static int wpa_supplicant_driver_cmd(struct wpa_supplicant *wpa_s, char *cmd, + #endif /* ANDROID */ + + ++#ifdef CONFIG_DRIVER_BRCM_WL ++static int wpa_supplicant_wl_cmd(struct wpa_supplicant *wpa_s, char *cmd, ++ char *buf, size_t buflen) ++{ ++ int ret; ++ ++ ret = wpa_drv_wl_cmd(wpa_s, cmd, buf, buflen); ++ if (ret == 0) { ++ ret = os_snprintf(buf, buflen, "%s\n", "OK"); ++ if (os_snprintf_error(buflen, ret)) ++ ret = -1; ++ } ++ return ret; ++} ++#endif /* CONFIG_DRIVER_BRCM_WL */ ++ ++ + static int wpa_supplicant_vendor_cmd(struct wpa_supplicant *wpa_s, char *cmd, + char *buf, size_t buflen) + { +@@ -12095,6 +12112,11 @@ char * wpa_supplicant_ctrl_iface_process(struct wpa_supplicant *wpa_s, + reply_len = wpa_supplicant_driver_cmd(wpa_s, buf + 7, reply, + reply_size); + #endif /* ANDROID */ ++#ifdef CONFIG_DRIVER_BRCM_WL ++ } else if (os_strncmp(buf, "WL ", 3) == 0) { ++ reply_len = wpa_supplicant_wl_cmd(wpa_s, buf + 3, reply, ++ reply_size); ++#endif /* CONFIG_DRIVER_BRCM_WL */ + } else if (os_strncmp(buf, "VENDOR ", 7) == 0) { + reply_len = wpa_supplicant_vendor_cmd(wpa_s, buf + 7, reply, + reply_size); +diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base +index 4f71b50ff..d4be24c34 100644 +--- a/wpa_supplicant/defconfig_base ++++ b/wpa_supplicant/defconfig_base +@@ -34,6 +34,8 @@ CONFIG_DRIVER_NL80211=y + # QCA vendor extensions to nl80211 + #CONFIG_DRIVER_NL80211_QCA=y + ++CONFIG_DRIVER_BRCM_WL=y ++ + # driver_nl80211.c requires libnl. If you are compiling it yourself + # you may need to point hostapd to your version of libnl. + # +diff --git a/wpa_supplicant/driver_i.h b/wpa_supplicant/driver_i.h +index 237f4e085..c7ba94ebd 100644 +--- a/wpa_supplicant/driver_i.h ++++ b/wpa_supplicant/driver_i.h +@@ -609,6 +609,16 @@ static inline int wpa_drv_driver_cmd(struct wpa_supplicant *wpa_s, + } + #endif /* ANDROID */ + ++#ifdef CONFIG_DRIVER_BRCM_WL ++static inline int wpa_drv_wl_cmd(struct wpa_supplicant *wpa_s, ++ char *cmd, char *buf, size_t buf_len) ++{ ++ if (!wpa_s->driver->wl_cmd) ++ return -1; ++ return wpa_s->driver->wl_cmd(wpa_s->drv_priv, cmd, buf, buf_len); ++} ++#endif /* CONFIG_DRIVER_BRCM_WL */ ++ + static inline void wpa_drv_set_rekey_info(struct wpa_supplicant *wpa_s, + const u8 *kek, size_t kek_len, + const u8 *kck, size_t kck_len, +diff --git a/wpa_supplicant/wpa_cli.c b/wpa_supplicant/wpa_cli.c +index 033589f76..d3c70d3e5 100644 +--- a/wpa_supplicant/wpa_cli.c ++++ b/wpa_supplicant/wpa_cli.c +@@ -2908,7 +2908,10 @@ static int wpa_cli_cmd_driver(struct wpa_ctrl *ctrl, int argc, char *argv[]) + return wpa_cli_cmd(ctrl, "DRIVER", 1, argc, argv); + } + #endif /* ANDROID */ +- ++static int wpa_cli_cmd_wl(struct wpa_ctrl *ctrl, int argc, char *argv[]) ++{ ++ return wpa_cli_cmd(ctrl, "WL", 1, argc, argv); ++} + + static int wpa_cli_cmd_vendor(struct wpa_ctrl *ctrl, int argc, char *argv[]) + { +@@ -3853,6 +3856,9 @@ static const struct wpa_cli_cmd wpa_cli_commands[] = { + { "driver", wpa_cli_cmd_driver, NULL, cli_cmd_flag_none, + " = driver private commands" }, + #endif /* ANDROID */ ++ { "wl", wpa_cli_cmd_wl, NULL, cli_cmd_flag_none, ++ " = brcm wl commands" }, ++ + { "radio_work", wpa_cli_cmd_radio_work, NULL, cli_cmd_flag_none, + "= radio_work " }, + { "vendor", wpa_cli_cmd_vendor, NULL, cli_cmd_flag_none, +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0024-non-upstream-wl-cmd-create-wl_do_cmd-as-an-entry-doi.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0024-non-upstream-wl-cmd-create-wl_do_cmd-as-an-entry-doi.patch new file mode 100644 index 000000000..cdc0e9b2b --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0024-non-upstream-wl-cmd-create-wl_do_cmd-as-an-entry-doi.patch @@ -0,0 +1,136 @@ +From ea5cd91f744dc3c5ebf8e5b8cf1746bec41c1d19 Mon Sep 17 00:00:00 2001 +From: Kurt Lee +Date: Tue, 26 Apr 2022 03:02:12 -0500 +Subject: [PATCH 24/49] non-upstream: wl-cmd: create wl_do_cmd as an entry + doing wl commands + +Create wl_do_cmd as an entry doing wl commands + +Signed-off-by: Ian Lin +Signed-off-by: Kurt Lee +--- + src/drivers/driver_brcm_wlu.c | 44 +++++++++++++++++++++++++++++++++++ + src/drivers/driver_brcm_wlu.h | 2 +- + src/drivers/driver_nl80211.c | 37 +++-------------------------- + 3 files changed, 48 insertions(+), 35 deletions(-) + +diff --git a/src/drivers/driver_brcm_wlu.c b/src/drivers/driver_brcm_wlu.c +index f2264ebcc..4fc03e446 100644 +--- a/src/drivers/driver_brcm_wlu.c ++++ b/src/drivers/driver_brcm_wlu.c +@@ -287,3 +287,47 @@ exit: + return ret; + } + ++ ++int wl_do_cmd(char *cmd, char *smbuf, u32 *msglen, bool *set, bool *is_get_int) ++{ ++ int ret = -1; ++ char *pos; ++ ++ pos = os_strstr(cmd, "5g_rate"); ++ if (pos) { ++ os_memcpy(smbuf, cmd, strlen("5g_rate")); //Keep last byte as 0x00 ++ *is_get_int = true; ++ *msglen += strlen("5g_rate"); ++ ++ if (os_strncasecmp(cmd, "5g_rate ", 8) == 0) { ++ *set = true; ++ cmd += strlen("5g_rate "); ++ *msglen += 1; ++ ++ ret = wl_rate_set(cmd, smbuf, msglen); ++ if (ret != 0) ++ goto exit; ++ } ++ } ++ ++ pos = os_strstr(cmd, "2g_rate"); ++ if (pos) { ++ os_memcpy(smbuf, cmd, strlen("2g_rate")); //Keep last byte as 0x00 ++ *is_get_int = true; ++ *msglen += strlen("2g_rate"); ++ ++ if (os_strncasecmp(cmd, "2g_rate ", 8) == 0) { ++ *set = true; ++ cmd += strlen("2g_rate "); ++ *msglen += 1; ++ ++ ret = wl_rate_set(cmd, smbuf, msglen); ++ if (ret != 0) ++ goto exit; ++ } ++ } ++ ++exit: ++ return ret; ++} ++ +diff --git a/src/drivers/driver_brcm_wlu.h b/src/drivers/driver_brcm_wlu.h +index 67832dc6a..7fc9118fc 100644 +--- a/src/drivers/driver_brcm_wlu.h ++++ b/src/drivers/driver_brcm_wlu.h +@@ -9,4 +9,4 @@ + /* Format a ratespec for output of any of the wl_rate() iovars */ + char* wl_rate_print(char *rate_buf, size_t buf_len, u32 rspec); + +-int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len); ++int wl_do_cmd(char *cmd, char *smbuf, u32 *msglen, bool *set, bool *is_get_int); +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index 8b04f9dc9..a6b9c860d 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -10160,7 +10160,6 @@ int nl80211_wl_command(void *priv, char *cmd, char *buf, size_t buf_len) + struct nl_msg *msg; + int ret = -1; + struct bcm_nlmsg_hdr *nlioc; +- char *pos; + char smbuf[WLC_IOCTL_SMLEN * 2] = {0x00}; + char outbuf[WLC_IOCTL_MEDLEN] = {0x00}; + u32 msglen = 0; +@@ -10173,39 +10172,9 @@ int nl80211_wl_command(void *priv, char *cmd, char *buf, size_t buf_len) + if (!msg) + return -ENOMEM; + +- pos = os_strstr(cmd, "5g_rate"); +- if (pos) { +- os_memcpy(smbuf, cmd, strlen("5g_rate")); //Keep last byte as 0x00 +- is_get_int = true; +- msglen += strlen("5g_rate"); +- +- if (os_strncasecmp(cmd, "5g_rate ", 8) == 0) { +- set = true; +- cmd += strlen("5g_rate "); +- msglen += 1; +- +- ret = wl_rate_set(cmd, smbuf, &msglen); +- if (ret != 0) +- goto exit; +- } +- } +- +- pos = os_strstr(cmd, "2g_rate"); +- if (pos) { +- os_memcpy(smbuf, cmd, strlen("2g_rate")); //Keep last byte as 0x00 +- is_get_int = true; +- msglen += strlen("2g_rate"); +- +- if (os_strncasecmp(cmd, "2g_rate ", 8) == 0) { +- set = true; +- cmd += strlen("2g_rate "); +- msglen += 1; +- +- ret = wl_rate_set(cmd, smbuf, &msglen); +- if (ret != 0) +- goto exit; +- } +- } ++ ret = wl_do_cmd(cmd, smbuf, &msglen, &set, &is_get_int); ++ if (ret != 0) ++ goto exit; + + /* nlmsg_alloc() can only allocate default_pagesize packet, cap + * any buffer send down to 1536 bytes +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0025-non-upstream-wl-cmd-create-ops-table-to-do-wl-comman.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0025-non-upstream-wl-cmd-create-ops-table-to-do-wl-comman.patch new file mode 100644 index 000000000..c9037f18e --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0025-non-upstream-wl-cmd-create-ops-table-to-do-wl-comman.patch @@ -0,0 +1,467 @@ +From 05b1387d4dc2e74a02cf524733d809acc4fd46fb Mon Sep 17 00:00:00 2001 +From: Kurt Lee +Date: Wed, 27 Apr 2022 22:50:25 -0500 +Subject: [PATCH 25/49] non-upstream: wl-cmd: create ops table to do wl + commands + +Creeate wl_cmds to handle wl commands + +Signed-off-by: Ian Lin +Signed-off-by: Kurt Lee +--- + src/drivers/driver_brcm_wlu.c | 247 ++++++++++++++++++++++++------ + src/drivers/driver_brcm_wlu.h | 2 +- + src/drivers/driver_brcm_wlu_cmd.h | 23 +++ + src/drivers/driver_nl80211.c | 27 ++-- + 4 files changed, 240 insertions(+), 59 deletions(-) + create mode 100644 src/drivers/driver_brcm_wlu_cmd.h + +diff --git a/src/drivers/driver_brcm_wlu.c b/src/drivers/driver_brcm_wlu.c +index 4fc03e446..8e568f9f6 100644 +--- a/src/drivers/driver_brcm_wlu.c ++++ b/src/drivers/driver_brcm_wlu.c +@@ -10,7 +10,110 @@ + #include "common.h" + #include "common/brcm_vendor.h" + #include "common/brcm_wl_ioctl.h" ++#include "common/brcm_wl_ioctl_defs.h" + #include "common/wpa_common.h" ++#include "driver_brcm_wlu_cmd.h" ++ ++static cmd_func_t wl_rate; ++static cmd_func_t wl_varint; ++ ++#define RATE_2G_USAGE \ ++"\tEither \"auto\", or a simple CCK/DSSS/OFDM rate value:\n" \ ++"\t1 2 5.5 11 6 9 12 18 24 36 48 54\n\n" \ ++"\tOr options to specify legacy, HT, or VHT rate:\n" \ ++"\t-r R, --rate=R : legacy rate (CCK, DSSS, OFDM)\n" \ ++"\t-h M, --ht=M : HT MCS index [0-23]\n" \ ++"\t-v M[xS], --vht=M[xS] : VHT MCS index M [0-9],\n" \ ++"\t : and optionally Nss S [1-8], eg. 5x2 is MCS=5, Nss=2\n" \ ++"\t-c cM[sS] : VHT (c notation) MCS index M [0-9],\n" \ ++"\t : and optionally Nss S [1-8], eg. c5s2 is MCS=5, Nss=2\n" \ ++"\t-e M[xS], --he=M[xS] : HE rate M [0-11],\n" \ ++"\t-s S, --ss=S : VHT Nss [1-8], number of spatial streams, default 1.\n" \ ++"\t : Only used with -v/--vht when MxS format is not used\n" \ ++"\t-x T, --exp=T : Tx Expansion, number of tx chains (NTx) beyond the minimum\n" \ ++"\t : required for the space-time-streams, exp = NTx - Nsts\n" \ ++"\t--stbc : Use STBC expansion, otherwise no STBC\n" \ ++"\t-l, --ldpc : Use LDPC encoding, otherwise no LDPC\n" \ ++"\t-g, --sgi : Guard interval. Different values for HT/VHT\n" \ ++"\t : Use Short Guard Interval otherwise standard GI\n" \ ++"\t-i, --hegi : Guard interval. Different values for HE\n" \ ++"\t : For HE, cp_ltf combination allowed values (0,1,2,3)\n" \ ++"\t-b, --bandwidth : transmit bandwidth in MHz [2.5, 5, 10, 20, 40, 80, 160] eg. -b 20\n" \ ++"\t-d D, --dcm=D : Use -d to set DCM, otherwise no DCM\n" \ ++"\t : (only when is MCS [0, 1], NSS 1, -b 20)\n" \ ++"\t-n R, --er=R : R [106,242] HE Range extension\n" \ ++"\t : otherwise no Rang extension and works only in 20 MHz" ++ ++#define RATE_5G_6G_USAGE \ ++"\tEither \"auto\", or a simple OFDM rate value:\n" \ ++"\t6 9 12 18 24 36 48 54\n\n" \ ++"\tOr options to specify legacy OFDM, HT, or VHT rate:\n" \ ++"\t-r R, --rate=R : legacy OFDM rate\n" \ ++"\t-h M, --ht=M : HT MCS index [0-23]\n" \ ++"\t-v M[xS], --vht=M[xS] : VHT MCS index M [0-9],\n" \ ++"\t : and optionally Nss S [1-8], eg. 5x2 is MCS=5, Nss=2\n" \ ++"\t-c cM[sS] : VHT (c notation) MCS index M [0-9],\n" \ ++"\t : and optionally Nss S [1-8], eg. c5s2 is MCS=5, Nss=2\n" \ ++"\t-e M[xS], --he=M[xS] : HE rate M [0-11],\n" \ ++"\t-s S, --ss=S : VHT Nss [1-8], number of spatial streams, default 1.\n" \ ++"\t : Only used with -v/--vht when MxS format is not used\n" \ ++"\t-x T, --exp=T : Tx Expansion, number of tx chains (NTx) beyond the minimum\n" \ ++"\t : required for the space-time-streams, exp = NTx - Nsts\n" \ ++"\t--stbc : Use STBC expansion, otherwise no STBC\n" \ ++"\t-l, --ldpc : Use LDPC encoding, otherwise no LDPC\n" \ ++"\t-g, --sgi : Guard interval. Different values for HT/VHT\n" \ ++"\t : Use Short Guard Interval otherwise standard GI\n" \ ++"\t-i, --hegi : Guard interval. Different values for HE\n" \ ++"\t : For HE cp_ltf combination allowed values (0,1,2,3)\n" \ ++"\t-b, --bandwidth : transmit bandwidth in MHz [2.5, 5, 10, 20, 40, 80, 160] eg. -b 20\n" \ ++"\t-d D, --dcm=D : Use -d to set DCM, otherwise no DCM\n" \ ++"\t : (only when is MCS [0, 1], NSS 1, -b 20)\n" \ ++"\t-n R, --er=R : R [106,242] HE Range extension\n" \ ++"\t : otherwise no Rang extension and works only in 20 MHz" ++ ++/* If the new command needs to be part of 'wc.exe' tool used for WMM, ++ * be sure to modify wc_cmds[] array as well ++ * ++ * If you add a command, please update wlu_cmd.c cmd2cat to categorize the command. ++ */ ++cmd_t wl_cmds[] = { ++ { "2g_rate", wl_rate, WLC_GET_VAR, WLC_SET_VAR, ++ "Force a fixed rate for data frames in the 2.4G band:\n\n" ++ RATE_2G_USAGE ++ }, ++ { "2g_mrate", wl_rate, WLC_GET_VAR, WLC_SET_VAR, ++ "Force a fixed rate for mulitcast/broadcast data frames in the 2.4G band:\n\n" ++ RATE_2G_USAGE ++ }, ++ { "5g_rate", wl_rate, WLC_GET_VAR, WLC_SET_VAR, ++ "Force a fixed rate for data frames in the 5G band:\n\n" ++ RATE_5G_6G_USAGE ++ }, ++ { "5g_mrate", wl_rate, WLC_GET_VAR, WLC_SET_VAR, ++ "Force a fixed rate for mulitcast/broadcast data frames in the 5G band:\n\n" ++ RATE_5G_6G_USAGE ++ }, ++ { NULL, NULL, 0, 0, NULL } ++}; ++ ++cmd_t wl_varcmd = {"var", wl_varint, -1, -1, "unrecognized name, type -h for help"}; ++ ++/* common function to find a command */ ++cmd_t * ++wlu_find_cmd(char *name) ++{ ++ cmd_t *cmd = wl_cmds; ++ ++ /* search cmd in cmd table */ ++ for (; cmd->name; cmd++) { ++ /* stop if we find a matching name */ ++ if (!os_strncasecmp(cmd->name, name, os_strlen(cmd->name))) { ++ break; ++ } ++ } ++ ++ return (cmd->name != NULL) ? cmd : NULL; ++} + + /* + * Format a ratespec for output of any of the wl_rate() iovars +@@ -113,8 +216,7 @@ wl_rate_print(char *rate_buf, size_t buf_len, u32 rspec) + * return FALSE if the arg does not look like MxS or cMsS, where M and S are single digits + * return TRUE if the arg does look like MxS or cMsS, setting mcsp to M, and nssp to S + */ +-//static int +-int ++static int + wl_parse_he_vht_spec(const char* cp, int* mcsp, int* nssp) + { + char *startp, *endp; +@@ -171,12 +273,13 @@ wl_parse_he_vht_spec(const char* cp, int* mcsp, int* nssp) + } + + +-int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len) ++static int ++wl_rate(char *cmd, char *buf, u32 *buf_len, bool *get, bool *is_get_int) + { + int ret = -1; +- char *pos; +- //bool legacy_set = false, ht_set = false, vht_set = false, he_set = false; +- bool he_set = false; ++ char *pos, *param = cmd; ++ bool auto_set = false; ++ bool legacy_set = false, ht_set = false, vht_set = false, he_set = false; + int rate, mcs, Nss, tx_exp, bw; + bool stbc, ldpc, sgi, dcm, er; + u8 hegi; +@@ -198,7 +301,48 @@ int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len) + dcm = false; + er = false; + +- pos = os_strstr(cmd, "-r "); ++ pos = os_strstr(cmd, "5g_rate"); ++ if (pos) { ++ param = cmd + strlen("5g_rate"); ++ os_memcpy(buf, cmd, strlen("5g_rate")); //Keep last byte as 0x00 ++ *is_get_int = true; ++ *buf_len += strlen("5g_rate"); ++ ++ if (os_strncasecmp(cmd, "5g_rate ", 8) == 0) { ++ param += 1; ++ *get = false; ++ cmd += strlen("5g_rate "); ++ *buf_len += 1; ++ } ++ } ++ ++ pos = os_strstr(cmd, "2g_rate"); ++ if (pos) { ++ param = cmd + strlen("2g_rate"); ++ os_memcpy(buf, cmd, strlen("2g_rate")); //Keep last byte as 0x00 ++ *is_get_int = true; ++ *buf_len += strlen("2g_rate"); ++ ++ if (os_strncasecmp(cmd, "2g_rate ", 8) == 0) { ++ param += 1; ++ *get = false; ++ cmd += strlen("2g_rate "); ++ *buf_len += 1; ++ } ++ } ++ ++ if (*get == true) { ++ ret = 0; ++ goto exit; ++ } ++ ++ /* Option: -l or --ldpc */ ++ pos = os_strstr(param, "auto"); ++ if (pos) { ++ auto_set = true; ++ } ++ ++ pos = os_strstr(param, "-r "); + if (pos) { + pos += 3; + rate = atoi(pos) * 2; +@@ -207,7 +351,7 @@ int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len) + } + + /* Option: -e or --he */ +- pos = os_strstr(cmd, "-e "); ++ pos = os_strstr(param, "-e "); + if (pos) { + char var_str[10]; + pos += 3; +@@ -240,7 +384,7 @@ int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len) + } + + +- pos = os_strstr(cmd, "-i "); ++ pos = os_strstr(param, "-i "); + if (pos) { + if (!he_set) { + wpa_printf(MSG_DEBUG, ":use -i option only in he "); +@@ -264,11 +408,39 @@ int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len) + } + + /* Option: -l or --ldpc */ +- pos = os_strstr(cmd, "-l"); ++ pos = os_strstr(param, "-l"); + if (pos) { + ldpc = true; + } + ++ /* set the ratespec encoding type and basic rate value */ ++ if (auto_set) { ++ rspec = 0; ++ } else if (legacy_set) { ++ rspec = WL_RSPEC_ENCODE_RATE; /* 11abg */ ++ rspec |= rate; ++ } else if (ht_set) { ++ rspec = WL_RSPEC_ENCODE_HT; /* 11n HT */ ++ rspec |= mcs; ++ } else if (vht_set) { ++ rspec = WL_RSPEC_ENCODE_VHT; /* 11ac VHT */ ++ if (Nss == 0) { ++ Nss = 1; /* default Nss = 1 if --ss option not given */ ++ } ++ rspec |= (Nss << WL_RSPEC_VHT_NSS_SHIFT) | mcs; ++ } else if (he_set) { ++ rspec = WL_RSPEC_ENCODE_HE; /* 11ax HE */ ++ if (Nss == 0) { ++ Nss = WL_RSPEC_HE_NSS_UNSPECIFIED; ++ } ++ rspec |= (Nss << WL_RSPEC_HE_NSS_SHIFT) | mcs; ++ } else { ++ wpa_printf(MSG_ERROR, ++ "%s: Invalid rate set for %s option\n", ++ "wl", param); ++ goto exit; ++ } ++ + /* set the other rspec fields */ + rspec |= (tx_exp << WL_RSPEC_TXEXP_SHIFT); + rspec |= bw; +@@ -279,54 +451,39 @@ int wl_rate_set(char *cmd, char *set_buf, u32 *set_buf_len) + rspec |= (dcm << WL_RSPEC_DCM_SHIFT); + rspec |= (er << WL_RSPEC_ER_SHIFT); + +- os_memcpy(set_buf + *set_buf_len, (char *)&rspec, sizeof(rspec)); +- *set_buf_len += sizeof(rspec); ++ os_memcpy(buf + *buf_len, (char *)&rspec, sizeof(rspec)); ++ *buf_len += sizeof(rspec); + + ret = 0; + exit: + return ret; + } + ++/* just issue a wl_var_setint() or a wl_var_getint() if there is a 2nd arg */ ++static int ++wl_varint(char *cmd, char *buf, u32 *buf_len, bool *get, bool *is_get_int) ++{ ++ return -1; ++} + +-int wl_do_cmd(char *cmd, char *smbuf, u32 *msglen, bool *set, bool *is_get_int) ++int wl_do_cmd(char *cmd, char *smbuf, u32 *msglen, bool *get, bool *is_get_int) + { ++ cmd_t *wl_cmd = NULL; + int ret = -1; +- char *pos; +- +- pos = os_strstr(cmd, "5g_rate"); +- if (pos) { +- os_memcpy(smbuf, cmd, strlen("5g_rate")); //Keep last byte as 0x00 +- *is_get_int = true; +- *msglen += strlen("5g_rate"); +- +- if (os_strncasecmp(cmd, "5g_rate ", 8) == 0) { +- *set = true; +- cmd += strlen("5g_rate "); +- *msglen += 1; + +- ret = wl_rate_set(cmd, smbuf, msglen); +- if (ret != 0) +- goto exit; +- } +- } ++ /* search for command */ ++ wl_cmd = wlu_find_cmd(cmd); + +- pos = os_strstr(cmd, "2g_rate"); +- if (pos) { +- os_memcpy(smbuf, cmd, strlen("2g_rate")); //Keep last byte as 0x00 +- *is_get_int = true; +- *msglen += strlen("2g_rate"); +- +- if (os_strncasecmp(cmd, "2g_rate ", 8) == 0) { +- *set = true; +- cmd += strlen("2g_rate "); +- *msglen += 1; +- +- ret = wl_rate_set(cmd, smbuf, msglen); +- if (ret != 0) +- goto exit; +- } ++ /* defaults to using the set_var and get_var commands */ ++ if (!wl_cmd) { ++ wl_cmd = &wl_varcmd; + } ++ /* do command */ ++ ret = (*wl_cmd->func)(cmd, smbuf, msglen, get, is_get_int); ++ if (ret != 0) ++ goto exit; + ++ ret = 0; + exit: + return ret; + } +diff --git a/src/drivers/driver_brcm_wlu.h b/src/drivers/driver_brcm_wlu.h +index 7fc9118fc..a943a0832 100644 +--- a/src/drivers/driver_brcm_wlu.h ++++ b/src/drivers/driver_brcm_wlu.h +@@ -9,4 +9,4 @@ + /* Format a ratespec for output of any of the wl_rate() iovars */ + char* wl_rate_print(char *rate_buf, size_t buf_len, u32 rspec); + +-int wl_do_cmd(char *cmd, char *smbuf, u32 *msglen, bool *set, bool *is_get_int); ++int wl_do_cmd(char *cmd, char *smbuf, u32 *msglen, bool *get, bool *is_get_int); +diff --git a/src/drivers/driver_brcm_wlu_cmd.h b/src/drivers/driver_brcm_wlu_cmd.h +new file mode 100644 +index 000000000..8443a625e +--- /dev/null ++++ b/src/drivers/driver_brcm_wlu_cmd.h +@@ -0,0 +1,23 @@ ++/* ++ * Broadcom Corporation OUI and vendor specific assignments ++ * Copyright (c) 2020, Broadcom Corporation. ++ * ++ * This software may be distributed under the terms of the BSD license. ++ * See README for more details. ++ */ ++ ++typedef struct cmd cmd_t; ++typedef int (cmd_func_t)(char *cmd, char *buf, u32 *buf_len, bool *set, bool *is_get_int); ++ ++/* generic command line argument handler */ ++struct cmd { ++ const char *name; ++ cmd_func_t *func; ++ int get; ++ int set; ++ const char *help; ++}; ++ ++/* list of command line arguments */ ++extern cmd_t wl_cmds[]; ++ +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index a6b9c860d..de58b17e1 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -10141,7 +10141,7 @@ static int nl80211_wl_reply_handler(struct nl_msg *msg, void *arg) + genlmsg_attrlen(gnlh, 0), NULL); + + if (tb_msg[NL80211_ATTR_VENDOR_DATA]) { +- wpa_printf(MSG_INFO, "nl80211: Vendor Data Found"); ++ wpa_printf(MSG_INFO, "nl80211: wl data found"); + ret = nla_parse_nested(bcmnl, BCM_NLATTR_MAX, + tb_msg[NL80211_ATTR_VENDOR_DATA], NULL); + if (ret != 0) +@@ -10163,7 +10163,7 @@ int nl80211_wl_command(void *priv, char *cmd, char *buf, size_t buf_len) + char smbuf[WLC_IOCTL_SMLEN * 2] = {0x00}; + char outbuf[WLC_IOCTL_MEDLEN] = {0x00}; + u32 msglen = 0; +- bool set = false; ++ bool get = true; + + bool is_get_int = false; + u32 output_val = 0x00; +@@ -10172,7 +10172,7 @@ int nl80211_wl_command(void *priv, char *cmd, char *buf, size_t buf_len) + if (!msg) + return -ENOMEM; + +- ret = wl_do_cmd(cmd, smbuf, &msglen, &set, &is_get_int); ++ ret = wl_do_cmd(cmd, smbuf, &msglen, &get, &is_get_int); + if (ret != 0) + goto exit; + +@@ -10182,22 +10182,23 @@ int nl80211_wl_command(void *priv, char *cmd, char *buf, size_t buf_len) + */ + if (msglen > 0x600) + msglen = 0x600; +- if (set) +- msglen += sizeof(struct bcm_nlmsg_hdr); +- else ++ if (get) + msglen = WLC_IOCTL_SMLEN; ++ else ++ msglen += sizeof(struct bcm_nlmsg_hdr); ++ + nlioc = malloc(msglen); + if (nlioc == NULL) { + nlmsg_free(msg); + return -ENOMEM; + } +- if (set) +- nlioc->cmd = WLC_SET_VAR; +- else ++ if (get) + nlioc->cmd = WLC_GET_VAR; ++ else ++ nlioc->cmd = WLC_SET_VAR; + nlioc->len = msglen - sizeof(struct bcm_nlmsg_hdr); + nlioc->offset = sizeof(struct bcm_nlmsg_hdr); +- nlioc->set = set; ++ nlioc->set = !get; + nlioc->magic = 0; + os_memcpy(((void *)nlioc) + nlioc->offset, smbuf, msglen - nlioc->offset); + +@@ -10213,14 +10214,14 @@ int nl80211_wl_command(void *priv, char *cmd, char *buf, size_t buf_len) + ret = send_and_recv_msgs(drv, msg, nl80211_wl_reply_handler, outbuf, NULL, NULL); + msg = NULL; + if (ret) { +- wpa_printf(MSG_ERROR, "nl80211: vendor cmd failed: " ++ wpa_printf(MSG_ERROR, "nl80211: wl cmd failed: " + "ret=%d (%s)", ret, strerror(-ret)); + ret = 0; + } + +- wpa_printf(MSG_DEBUG, "nl80211: vendor cmd sent successfully "); ++ wpa_printf(MSG_DEBUG, "nl80211: wl cmd sent successfully "); + +- if (set == false && is_get_int == true) { ++ if (get == true && is_get_int == true) { + os_memcpy(&output_val, outbuf, sizeof(output_val)); + wl_rate_print(buf, buf_len, output_val); + ret = buf_len; +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0026-non-upstream-wl-cmd-add-more-compile-flag.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0026-non-upstream-wl-cmd-add-more-compile-flag.patch new file mode 100644 index 000000000..d5220c068 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0026-non-upstream-wl-cmd-add-more-compile-flag.patch @@ -0,0 +1,64 @@ +From a6028c58032672f86c9fe87ba3abbd31c79166e3 Mon Sep 17 00:00:00 2001 +From: Kurt Lee +Date: Wed, 25 May 2022 19:12:47 -0500 +Subject: [PATCH 26/49] non-upstream: wl-cmd: add more compile flag + +add more CONFIG_DRIVER_BRCM_WL to separeta this feature + +Signed-off-by: Ian Lin +Signed-off-by: Kurt Lee +--- + src/drivers/driver.h | 3 +++ + wpa_supplicant/wpa_cli.c | 8 +++++++- + 2 files changed, 10 insertions(+), 1 deletion(-) + +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index 3d48f6f07..2745b8340 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -3861,7 +3861,10 @@ struct wpa_driver_ops { + */ + int (*driver_cmd)(void *priv, char *cmd, char *buf, size_t buf_len); + #endif /* ANDROID */ ++ ++#ifdef CONFIG_DRIVER_BRCM_WL + int (*wl_cmd)(void *priv, char *cmd, char *buf, size_t buf_len); ++#endif /* CONFIG_DRIVER_BRCM_WL */ + + /** + * vendor_cmd - Execute vendor specific command +diff --git a/wpa_supplicant/wpa_cli.c b/wpa_supplicant/wpa_cli.c +index d3c70d3e5..0f68d8d8a 100644 +--- a/wpa_supplicant/wpa_cli.c ++++ b/wpa_supplicant/wpa_cli.c +@@ -2908,10 +2908,15 @@ static int wpa_cli_cmd_driver(struct wpa_ctrl *ctrl, int argc, char *argv[]) + return wpa_cli_cmd(ctrl, "DRIVER", 1, argc, argv); + } + #endif /* ANDROID */ ++ ++ ++#ifdef CONFIG_DRIVER_BRCM_WL + static int wpa_cli_cmd_wl(struct wpa_ctrl *ctrl, int argc, char *argv[]) + { + return wpa_cli_cmd(ctrl, "WL", 1, argc, argv); + } ++#endif /* CONFIG_DRIVER_BRCM_WL */ ++ + + static int wpa_cli_cmd_vendor(struct wpa_ctrl *ctrl, int argc, char *argv[]) + { +@@ -3856,9 +3861,10 @@ static const struct wpa_cli_cmd wpa_cli_commands[] = { + { "driver", wpa_cli_cmd_driver, NULL, cli_cmd_flag_none, + " = driver private commands" }, + #endif /* ANDROID */ ++#ifdef CONFIG_DRIVER_BRCM_WL + { "wl", wpa_cli_cmd_wl, NULL, cli_cmd_flag_none, + " = brcm wl commands" }, +- ++#endif /* CONFIG_DRIVER_BRCM_WL */ + { "radio_work", wpa_cli_cmd_radio_work, NULL, cli_cmd_flag_none, + "= radio_work " }, + { "vendor", wpa_cli_cmd_vendor, NULL, cli_cmd_flag_none, +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0027-Fix-dpp-config-parameter-setting.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0027-Fix-dpp-config-parameter-setting.patch new file mode 100644 index 000000000..894a71616 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0027-Fix-dpp-config-parameter-setting.patch @@ -0,0 +1,31 @@ +From e2fb675883cf00992ce51e91a3e2055c898ae3e6 Mon Sep 17 00:00:00 2001 +From: "Shankar Amar (CSTIPL CSS ICW SW WFS 1)" +Date: Mon, 20 Jun 2022 05:57:46 +0000 +Subject: [PATCH 27/49] Fix dpp config parameter setting + +--- + src/common/dpp.c | 7 ++++--- + 1 file changed, 4 insertions(+), 3 deletions(-) + +diff --git a/src/common/dpp.c b/src/common/dpp.c +index ac6eae4c8..6e6e4248c 100644 +--- a/src/common/dpp.c ++++ b/src/common/dpp.c +@@ -1029,10 +1029,11 @@ static int dpp_configuration_parse_helper(struct dpp_authentication *auth, + pos += 6; + end = os_strchr(pos, ' '); + conf->ssid_len = end ? (size_t) (end - pos) : os_strlen(pos); +- conf->ssid_len /= 2; +- if (conf->ssid_len > sizeof(conf->ssid) || +- hexstr2bin(pos, conf->ssid, conf->ssid_len) < 0) ++ /* Remove check for ssid in hex as we are supplying ++ * string format in dpp_auth_init */ ++ if (conf->ssid_len > sizeof(conf->ssid)) + goto fail; ++ os_memcpy(conf->ssid, pos, conf->ssid_len); + } else { + #ifdef CONFIG_TESTING_OPTIONS + /* use a default SSID for legacy testing reasons */ +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0028-DPP-Resolving-failure-of-dpp-configurator-exchange-f.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0028-DPP-Resolving-failure-of-dpp-configurator-exchange-f.patch new file mode 100644 index 000000000..4d8448982 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0028-DPP-Resolving-failure-of-dpp-configurator-exchange-f.patch @@ -0,0 +1,35 @@ +From b19b6f1165800106ccd941b6042ea804bfa95d5f Mon Sep 17 00:00:00 2001 +From: "Shankar Amar (CSTIPL CSS ICW SW WFS 1)" +Date: Thu, 30 Jun 2022 08:01:45 +0000 +Subject: [PATCH 28/49] DPP: Resolving failure of dpp configurator exchange for + configurator plus initiator in AP role with fmac + +--- + hostapd/defconfig_base | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/hostapd/defconfig_base b/hostapd/defconfig_base +index 4e4f0f784..16e8c645a 100644 +--- a/hostapd/defconfig_base ++++ b/hostapd/defconfig_base +@@ -307,7 +307,7 @@ CONFIG_TLS_ADD_DL=y + # Interworking (IEEE 802.11u) + # This can be used to enable functionality to improve interworking with + # external networks. +-#CONFIG_INTERWORKING=y ++CONFIG_INTERWORKING=y + + # Hotspot 2.0 + #CONFIG_HS20=y +@@ -370,7 +370,7 @@ CONFIG_TESTING_OPTIONS=y + + # Include internal line edit mode in hostapd_cli. This can be used to provide + # limited command line editing and history support. +-#CONFIG_WPA_CLI_EDIT=y ++CONFIG_WPA_CLI_EDIT=y + + # Opportunistic Wireless Encryption (OWE) + # Experimental implementation of draft-harkins-owe-07.txt +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0029-Enabling-SUITEB192-and-SUITEB-compile-options.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0029-Enabling-SUITEB192-and-SUITEB-compile-options.patch new file mode 100644 index 000000000..49c53d64b --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0029-Enabling-SUITEB192-and-SUITEB-compile-options.patch @@ -0,0 +1,29 @@ +From 7d621a129690b061afd61e8bd21d9b816f09d8ac Mon Sep 17 00:00:00 2001 +From: Carter Chen +Date: Mon, 4 Jul 2022 02:19:48 -0500 +Subject: [PATCH 29/49] Enabling SUITEB192 and SUITEB compile options + +Enabling the compile options for SUITEB and SUITEB-192 related +configurations and wpa_cli commands. + +Fixes: SWLINUX-2712 + +Signed-off-by: Carter Chen +--- + wpa_supplicant/defconfig_base | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base +index d4be24c34..f290ae673 100644 +--- a/wpa_supplicant/defconfig_base ++++ b/wpa_supplicant/defconfig_base +@@ -638,3 +638,6 @@ CONFIG_DPP=y + # connect to this hostapd. These options allow, for example, to drop a + # certain percentage of probe requests or auth/(re)assoc frames. + CONFIG_TESTING_OPTIONS=y ++ ++CONFIG_SUITEB192=y ++CONFIG_SUITEB=y +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0030-DPP-Enabling-CLI_EDIT-option-for-enrollee-plus-respo.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0030-DPP-Enabling-CLI_EDIT-option-for-enrollee-plus-respo.patch new file mode 100644 index 000000000..ea78e16dd --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0030-DPP-Enabling-CLI_EDIT-option-for-enrollee-plus-respo.patch @@ -0,0 +1,26 @@ +From 621de92cbd36719e3febe385411a65ccfa646344 Mon Sep 17 00:00:00 2001 +From: "Shankar Amar (CSTIPL CSS ICW SW WFS 1)" +Date: Fri, 22 Jul 2022 07:52:30 +0000 +Subject: [PATCH 30/49] DPP: Enabling CLI_EDIT option for enrollee plus + responder in STA role with fmac + +--- + wpa_supplicant/defconfig_base | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base +index f290ae673..611a23e3e 100644 +--- a/wpa_supplicant/defconfig_base ++++ b/wpa_supplicant/defconfig_base +@@ -228,7 +228,7 @@ CONFIG_CTRL_IFACE=y + + # Include internal line edit mode in wpa_cli. This can be used as a replacement + # for GNU Readline to provide limited command line editing and history support. +-#CONFIG_WPA_CLI_EDIT=y ++CONFIG_WPA_CLI_EDIT=y + + # Remove debugging code that is printing out debug message to stdout. + # This can be used to reduce the size of the wpa_supplicant considerably +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0031-P2P-Fixes-Scan-trigger-failed-once-GC-invited-by-GO.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0031-P2P-Fixes-Scan-trigger-failed-once-GC-invited-by-GO.patch new file mode 100644 index 000000000..1b94e31b4 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0031-P2P-Fixes-Scan-trigger-failed-once-GC-invited-by-GO.patch @@ -0,0 +1,60 @@ +From a7e23d28ccd14800f0dd3f12bf0d053df6987fe7 Mon Sep 17 00:00:00 2001 +From: JasonHuang +Date: Tue, 19 Jul 2022 01:44:19 -0500 +Subject: [PATCH 31/49] P2P: Fixes Scan trigger failed, once GC invited by GO + +It's regression between 2.9 and 2.10. The 5g frequencys be +repeatedly added to the list, then nl80211 driver will return +-22 (Invalid argument). + +Signed-off-by: JasonHuang +--- + wpa_supplicant/scan.c | 28 ++++++++++------------------ + 1 file changed, 10 insertions(+), 18 deletions(-) + +diff --git a/wpa_supplicant/scan.c b/wpa_supplicant/scan.c +index b0094ca6c..fb41aa718 100644 +--- a/wpa_supplicant/scan.c ++++ b/wpa_supplicant/scan.c +@@ -1365,28 +1365,20 @@ scan: + (wpa_s->p2p_in_invitation || wpa_s->p2p_in_provisioning) && + !is_p2p_allow_6ghz(wpa_s->global->p2p) && + is_6ghz_supported(wpa_s)) { +- int i; + +- /* Exclude 5 GHz channels from the full scan for P2P connection ++ /* Exclude 6 GHz channels from the full scan for P2P connection + * since the 6 GHz band is disabled for P2P uses. */ + wpa_printf(MSG_DEBUG, + "P2P: 6 GHz disabled - update the scan frequency list"); +- for (i = 0; i < wpa_s->hw.num_modes; i++) { +- if (wpa_s->hw.modes[i].num_channels == 0) +- continue; +- if (wpa_s->hw.modes[i].mode == HOSTAPD_MODE_IEEE80211G) +- wpa_add_scan_freqs_list( +- wpa_s, HOSTAPD_MODE_IEEE80211G, +- ¶ms, false); +- if (wpa_s->hw.modes[i].mode == HOSTAPD_MODE_IEEE80211A) +- wpa_add_scan_freqs_list( +- wpa_s, HOSTAPD_MODE_IEEE80211A, +- ¶ms, false); +- if (wpa_s->hw.modes[i].mode == HOSTAPD_MODE_IEEE80211AD) +- wpa_add_scan_freqs_list( +- wpa_s, HOSTAPD_MODE_IEEE80211AD, +- ¶ms, false); +- } ++ wpa_add_scan_freqs_list( ++ wpa_s, HOSTAPD_MODE_IEEE80211G, ++ ¶ms, false); ++ wpa_add_scan_freqs_list( ++ wpa_s, HOSTAPD_MODE_IEEE80211A, ++ ¶ms, false); ++ wpa_add_scan_freqs_list( ++ wpa_s, HOSTAPD_MODE_IEEE80211AD, ++ ¶ms, false); + } + #endif /* CONFIG_P2P */ + +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0032-non-upstream-SAE-disconnect-after-PMKSA-cache-expire.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0032-non-upstream-SAE-disconnect-after-PMKSA-cache-expire.patch new file mode 100644 index 000000000..3381303ca --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0032-non-upstream-SAE-disconnect-after-PMKSA-cache-expire.patch @@ -0,0 +1,68 @@ +From 65ed1eadc11b838a4ba223648bfd3d87bf492319 Mon Sep 17 00:00:00 2001 +From: Ian Lin +Date: Mon, 18 Jul 2022 00:49:49 -0500 +Subject: [PATCH 32/49] non-upstream: SAE: disconnect after PMKSA cache expire + +If the dot11RSNAConfigPMKLifetime is set, skip the flow of postponing +the expiration in b0f457b6 and run disconnect flow. + +Signed-off-by: Ian Lin +--- + src/rsn_supp/pmksa_cache.c | 3 ++- + src/rsn_supp/wpa.c | 5 ++++- + src/rsn_supp/wpa_i.h | 1 + + 3 files changed, 7 insertions(+), 2 deletions(-) + +diff --git a/src/rsn_supp/pmksa_cache.c b/src/rsn_supp/pmksa_cache.c +index 0cd515982..8d517b5d4 100644 +--- a/src/rsn_supp/pmksa_cache.c ++++ b/src/rsn_supp/pmksa_cache.c +@@ -65,7 +65,8 @@ static void pmksa_cache_expire(void *eloop_ctx, void *timeout_ctx) + os_get_reltime(&now); + while (entry && entry->expiration <= now.sec) { + if (wpa_key_mgmt_sae(entry->akmp) && +- pmksa->is_current_cb(entry, pmksa->ctx)) { ++ pmksa->is_current_cb(entry, pmksa->ctx) && ++ !pmksa->sm->dot11RSNAConfigPMKLifetime_UserDef) { + /* Do not expire the currently used PMKSA entry for SAE + * since there is no convenient mechanism for + * reauthenticating during an association with SAE. The +diff --git a/src/rsn_supp/wpa.c b/src/rsn_supp/wpa.c +index 1f6401ef3..3eaa759f6 100644 +--- a/src/rsn_supp/wpa.c ++++ b/src/rsn_supp/wpa.c +@@ -2940,6 +2940,7 @@ struct wpa_sm * wpa_sm_init(struct wpa_sm_ctx *ctx) + sm->ctx = ctx; + + sm->dot11RSNAConfigPMKLifetime = 43200; ++ sm->dot11RSNAConfigPMKLifetime_UserDef = false; + sm->dot11RSNAConfigPMKReauthThreshold = 70; + sm->dot11RSNAConfigSATimeout = 60; + +@@ -3317,8 +3318,10 @@ int wpa_sm_set_param(struct wpa_sm *sm, enum wpa_sm_conf_params param, + + switch (param) { + case RSNA_PMK_LIFETIME: +- if (value > 0) ++ if (value > 0) { + sm->dot11RSNAConfigPMKLifetime = value; ++ sm->dot11RSNAConfigPMKLifetime_UserDef = true; ++ } + else + ret = -1; + break; +diff --git a/src/rsn_supp/wpa_i.h b/src/rsn_supp/wpa_i.h +index 3989c9ab3..f3843d7d4 100644 +--- a/src/rsn_supp/wpa_i.h ++++ b/src/rsn_supp/wpa_i.h +@@ -90,6 +90,7 @@ struct wpa_sm { + u8 bssid[ETH_ALEN]; + + unsigned int dot11RSNAConfigPMKLifetime; ++ bool dot11RSNAConfigPMKLifetime_UserDef; + unsigned int dot11RSNAConfigPMKReauthThreshold; + unsigned int dot11RSNAConfigSATimeout; + +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0033-Add-support-for-beacon-loss-roaming.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0033-Add-support-for-beacon-loss-roaming.patch new file mode 100644 index 000000000..794236c43 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0033-Add-support-for-beacon-loss-roaming.patch @@ -0,0 +1,90 @@ +From b98919427e885679267ac811eb7e02d7209078b4 Mon Sep 17 00:00:00 2001 +From: root +Date: Tue, 26 Jul 2022 17:24:49 -0400 +Subject: [PATCH 33/49] Add support for beacon loss roaming + +--- + wpa_supplicant/bgscan_learn.c | 19 ++++++++++++++++++- + wpa_supplicant/bgscan_simple.c | 20 +++++++++++++++++++- + 2 files changed, 37 insertions(+), 2 deletions(-) + +diff --git a/wpa_supplicant/bgscan_learn.c b/wpa_supplicant/bgscan_learn.c +index cb732f709..115d2c007 100644 +--- a/wpa_supplicant/bgscan_learn.c ++++ b/wpa_supplicant/bgscan_learn.c +@@ -18,6 +18,7 @@ + #include "driver_i.h" + #include "scan.h" + #include "bgscan.h" ++#include "bss.h" + + struct bgscan_learn_bss { + struct dl_list list; +@@ -550,8 +551,24 @@ static int bgscan_learn_notify_scan(void *priv, + + static void bgscan_learn_notify_beacon_loss(void *priv) + { ++ struct bgscan_learn_data *data = priv; ++ + wpa_printf(MSG_DEBUG, "bgscan learn: beacon loss"); +- /* TODO: speed up background scanning */ ++ ++ wpa_printf(MSG_DEBUG, "bgscan learn: Flush all prev bss entries"); ++ wpa_bss_flush(data->wpa_s); ++ ++ wpa_printf(MSG_DEBUG, "bgscan learn: allow reassociation " ++ "to same lost BSS if found"); ++ data->wpa_s->reassociate = 1; ++ ++ wpa_printf(MSG_DEBUG, "bgscan learn: Start using short " ++ "bgscan interval"); ++ data->scan_interval = data->short_interval; ++ ++ wpa_printf(MSG_DEBUG, "bgscan learn: Trigger immediate scan"); ++ eloop_cancel_timeout(bgscan_learn_timeout, data, NULL); ++ eloop_register_timeout(0, 0, bgscan_learn_timeout, data, NULL); + } + + +diff --git a/wpa_supplicant/bgscan_simple.c b/wpa_supplicant/bgscan_simple.c +index 41a26df0d..bc99885fb 100644 +--- a/wpa_supplicant/bgscan_simple.c ++++ b/wpa_supplicant/bgscan_simple.c +@@ -16,6 +16,7 @@ + #include "driver_i.h" + #include "scan.h" + #include "bgscan.h" ++#include "bss.h" + + struct bgscan_simple_data { + struct wpa_supplicant *wpa_s; +@@ -191,8 +192,25 @@ static int bgscan_simple_notify_scan(void *priv, + + static void bgscan_simple_notify_beacon_loss(void *priv) + { ++ struct bgscan_simple_data *data = priv; ++ + wpa_printf(MSG_DEBUG, "bgscan simple: beacon loss"); +- /* TODO: speed up background scanning */ ++ ++ wpa_printf(MSG_DEBUG, "bgscan simple: Flush all prev bss entries"); ++ wpa_bss_flush(data->wpa_s); ++ ++ wpa_printf(MSG_DEBUG, "bgscan simple: allow reassociation " ++ "to same lost BSS if found"); ++ data->wpa_s->reassociate = 1; ++ ++ wpa_printf(MSG_DEBUG, "bgscan simple: Start using short " ++ "bgscan interval"); ++ data->scan_interval = data->short_interval; ++ ++ wpa_printf(MSG_DEBUG, "bgscan simple: Trigger immediate scan"); ++ eloop_cancel_timeout(bgscan_simple_timeout, data, NULL); ++ eloop_register_timeout(0, 0, bgscan_simple_timeout, data, ++ NULL); + } + + +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0034-wpa_supplicant-Set-PMKSA-to-driver-while-key-mgmt-is.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0034-wpa_supplicant-Set-PMKSA-to-driver-while-key-mgmt-is.patch new file mode 100644 index 000000000..743a338bb --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0034-wpa_supplicant-Set-PMKSA-to-driver-while-key-mgmt-is.patch @@ -0,0 +1,34 @@ +From da53435d4d11db827e3661be372e7b9773eaa842 Mon Sep 17 00:00:00 2001 +From: JasonHuang +Date: Thu, 8 Sep 2022 03:26:23 -0500 +Subject: [PATCH 34/49] wpa_supplicant: Set PMKSA to driver while key mgmt is + FT + +When the fast roaming is determined by the firmware, the +firmware needs the pmk to calculate PMK-R0name. + +Signed-off-by: JasonHuang +--- + src/rsn_supp/wpa.c | 6 ++++-- + 1 file changed, 4 insertions(+), 2 deletions(-) + +diff --git a/src/rsn_supp/wpa.c b/src/rsn_supp/wpa.c +index 3eaa759f6..ce01990e5 100644 +--- a/src/rsn_supp/wpa.c ++++ b/src/rsn_supp/wpa.c +@@ -1831,8 +1831,10 @@ static void wpa_supplicant_process_3_of_4(struct wpa_sm *sm, + * existing PMKSA entry after each 4-way handshake (i.e., new KCK/PMKID) + * to avoid unnecessary changes of PMKID while continuing to use the + * same PMK. */ +- if (sm->proto == WPA_PROTO_RSN && wpa_key_mgmt_suite_b(sm->key_mgmt) && +- !sm->cur_pmksa) { ++ /* Add ft case for driver base roaming. FW needs PMK to calculate ++ * PMK-R0name */ ++ if (sm->proto == WPA_PROTO_RSN && (wpa_key_mgmt_suite_b(sm->key_mgmt) || ++ wpa_key_mgmt_ft(sm->key_mgmt)) && !sm->cur_pmksa) { + struct rsn_pmksa_cache_entry *sa; + + sa = pmksa_cache_add(sm->pmksa, sm->pmk, sm->pmk_len, NULL, +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0035-nl80211-Set-NL80211_SCAN_FLAG_COLOCATED_6GHZ-in-scan.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0035-nl80211-Set-NL80211_SCAN_FLAG_COLOCATED_6GHZ-in-scan.patch new file mode 100644 index 000000000..d56ee518b --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0035-nl80211-Set-NL80211_SCAN_FLAG_COLOCATED_6GHZ-in-scan.patch @@ -0,0 +1,82 @@ +From 2173b4648a59f7ab499b7974189f2ba025b6a25e Mon Sep 17 00:00:00 2001 +From: Tova Mussai +Date: Sun, 24 Apr 2022 12:57:52 +0300 +Subject: [PATCH 35/49] nl80211: Set NL80211_SCAN_FLAG_COLOCATED_6GHZ in scan + +Set NL80211_SCAN_FLAG_COLOCATED_6GHZ in the scan parameters to enable +scanning for co-located APs discovered based on neighbor reports from +the 2.4/5 GHz bands when not scanning passively. Do so only when +collocated scanning is not disabled by higher layer logic. + +Signed-off-by: Tova Mussai +Signed-off-by: Andrei Otcheretianski +Signed-off-by: Ilan Peer +Signed-off-by: Avraham Stern +--- + src/drivers/driver.h | 10 ++++++++++ + src/drivers/driver_nl80211_scan.c | 15 +++++++++++++++ + wpa_supplicant/scan.c | 1 + + 3 files changed, 26 insertions(+) + +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index 2745b8340..d778b1eaa 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -651,6 +651,16 @@ struct wpa_driver_scan_params { + */ + unsigned int p2p_include_6ghz:1; + ++ /** ++ * non_coloc_6ghz - Force scanning of non-PSC 6 GHz channels ++ * ++ * If this is set, the driver should scan non-PSC channels from the ++ * scan request even if neighbor reports from 2.4/5 GHz APs did not ++ * report a co-located AP on these channels. The default is to scan ++ * non-PSC channels only if a co-located AP was reported on the channel. ++ */ ++ unsigned int non_coloc_6ghz:1; ++ + /* + * NOTE: Whenever adding new parameters here, please make sure + * wpa_scan_clone_params() and wpa_scan_free_params() get updated with +diff --git a/src/drivers/driver_nl80211_scan.c b/src/drivers/driver_nl80211_scan.c +index 131608480..1cd15469a 100644 +--- a/src/drivers/driver_nl80211_scan.c ++++ b/src/drivers/driver_nl80211_scan.c +@@ -203,6 +203,21 @@ nl80211_scan_common(struct i802_bss *bss, u8 cmd, + goto fail; + } + nla_nest_end(msg, ssids); ++ ++ /* ++ * If allowed, scan for 6 GHz APs that are reported by other ++ * APs. Note that if the flag is not set and 6 GHz channels are ++ * to be scanned, it is highly likely that non-PSC channels ++ * would be scanned passively (due to the Probe Request frame ++ * transmission restrictions mandated in IEEE Std 802.11ax-2021, ++ * 26.17.2.3 (Scanning in the 6 GHz band). Passive scanning of ++ * all non-PSC channels would take a significant amount of time. ++ */ ++ if (!params->non_coloc_6ghz) { ++ wpa_printf(MSG_DEBUG, ++ "nl80211: Scan co-located APs on 6 GHz"); ++ scan_flags |= NL80211_SCAN_FLAG_COLOCATED_6GHZ; ++ } + } else { + wpa_printf(MSG_DEBUG, "nl80211: Passive scan requested"); + } +diff --git a/wpa_supplicant/scan.c b/wpa_supplicant/scan.c +index fb41aa718..3999162be 100644 +--- a/wpa_supplicant/scan.c ++++ b/wpa_supplicant/scan.c +@@ -2894,6 +2894,7 @@ wpa_scan_clone_params(const struct wpa_driver_scan_params *src) + params->relative_adjust_band = src->relative_adjust_band; + params->relative_adjust_rssi = src->relative_adjust_rssi; + params->p2p_include_6ghz = src->p2p_include_6ghz; ++ params->non_coloc_6ghz = src->non_coloc_6ghz; + return params; + + failed: +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0036-scan-Add-option-to-disable-6-GHz-collocated-scanning.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0036-scan-Add-option-to-disable-6-GHz-collocated-scanning.patch new file mode 100644 index 000000000..61b690c39 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0036-scan-Add-option-to-disable-6-GHz-collocated-scanning.patch @@ -0,0 +1,92 @@ +From d2aff0911008db10d28424ca5b8d67f852a5bf89 Mon Sep 17 00:00:00 2001 +From: Ilan Peer +Date: Sun, 24 Apr 2022 12:57:53 +0300 +Subject: [PATCH 36/49] scan: Add option to disable 6 GHz collocated scanning + +Add a parameter (non_coloc_6ghz=1) to the manual scan command to disable +6 GHz collocated scanning. + +This option can be used to disable 6 GHz collocated scan logic. Note +that due to limitations on Probe Request frame transmissions on the 6 +GHz band mandated in IEEE Std 802.11ax-2021 it is very likely that +non-PSC channels would be scanned passively and this can take a +significant amount of time. + +Signed-off-by: Ilan Peer +--- + wpa_supplicant/ctrl_iface.c | 7 +++++++ + wpa_supplicant/scan.c | 6 ++++++ + wpa_supplicant/wpa_supplicant_i.h | 1 + + 3 files changed, 14 insertions(+) + +diff --git a/wpa_supplicant/ctrl_iface.c b/wpa_supplicant/ctrl_iface.c +index 86dcb9d84..1d4c8bcc2 100644 +--- a/wpa_supplicant/ctrl_iface.c ++++ b/wpa_supplicant/ctrl_iface.c +@@ -8843,6 +8843,7 @@ static void wpas_ctrl_scan(struct wpa_supplicant *wpa_s, char *params, + unsigned int manual_scan_only_new = 0; + unsigned int scan_only = 0; + unsigned int scan_id_count = 0; ++ unsigned int manual_non_coloc_6ghz = 0; + int scan_id[MAX_SCAN_ID]; + void (*scan_res_handler)(struct wpa_supplicant *wpa_s, + struct wpa_scan_results *scan_res); +@@ -8920,6 +8921,10 @@ static void wpas_ctrl_scan(struct wpa_supplicant *wpa_s, char *params, + os_strstr(params, "wildcard_ssid=1") != NULL; + } + ++ pos = os_strstr(params, "non_coloc_6ghz="); ++ if (pos) ++ manual_non_coloc_6ghz = !!atoi(pos + 15); ++ + pos = params; + while (pos && *pos != '\0') { + if (os_strncmp(pos, "ssid ", 5) == 0) { +@@ -8989,6 +8994,7 @@ static void wpas_ctrl_scan(struct wpa_supplicant *wpa_s, char *params, + wpa_s->manual_scan_use_id = manual_scan_use_id; + wpa_s->manual_scan_only_new = manual_scan_only_new; + wpa_s->scan_id_count = scan_id_count; ++ wpa_s->manual_non_coloc_6ghz = manual_non_coloc_6ghz; + os_memcpy(wpa_s->scan_id, scan_id, scan_id_count * sizeof(int)); + wpa_s->scan_res_handler = scan_res_handler; + os_free(wpa_s->manual_scan_freqs); +@@ -9012,6 +9018,7 @@ static void wpas_ctrl_scan(struct wpa_supplicant *wpa_s, char *params, + wpa_s->manual_scan_use_id = manual_scan_use_id; + wpa_s->manual_scan_only_new = manual_scan_only_new; + wpa_s->scan_id_count = scan_id_count; ++ wpa_s->manual_non_coloc_6ghz = manual_non_coloc_6ghz; + os_memcpy(wpa_s->scan_id, scan_id, scan_id_count * sizeof(int)); + wpa_s->scan_res_handler = scan_res_handler; + os_free(wpa_s->manual_scan_freqs); +diff --git a/wpa_supplicant/scan.c b/wpa_supplicant/scan.c +index 3999162be..01a995e99 100644 +--- a/wpa_supplicant/scan.c ++++ b/wpa_supplicant/scan.c +@@ -1328,6 +1328,12 @@ ssid_list_set: + } + } + ++ if (wpa_s->last_scan_req == MANUAL_SCAN_REQ && ++ wpa_s->manual_non_coloc_6ghz) { ++ wpa_dbg(wpa_s, MSG_DEBUG, "Collocated 6 GHz logic is disabled"); ++ params.non_coloc_6ghz = 1; ++ } ++ + scan_params = ¶ms; + + scan: +diff --git a/wpa_supplicant/wpa_supplicant_i.h b/wpa_supplicant/wpa_supplicant_i.h +index 8bb8672fb..b671b54e7 100644 +--- a/wpa_supplicant/wpa_supplicant_i.h ++++ b/wpa_supplicant/wpa_supplicant_i.h +@@ -883,6 +883,7 @@ struct wpa_supplicant { + unsigned int own_scan_requested:1; + unsigned int own_scan_running:1; + unsigned int clear_driver_scan_cache:1; ++ unsigned int manual_non_coloc_6ghz:1; + unsigned int manual_scan_id; + int scan_interval; /* time in sec between scans to find suitable AP */ + int normal_scans; /* normal scans run before sched_scan */ +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0037-Enabling-OWE-in-wpa_supplicant.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0037-Enabling-OWE-in-wpa_supplicant.patch new file mode 100644 index 000000000..27e02add8 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0037-Enabling-OWE-in-wpa_supplicant.patch @@ -0,0 +1,30 @@ +From 4a920e2446cff3f215614d63798e675bb5e25549 Mon Sep 17 00:00:00 2001 +From: Carter Chen +Date: Wed, 19 Oct 2022 03:29:39 -0500 +Subject: [PATCH 37/49] Enabling OWE in wpa_supplicant + +Enabling the compile options for OWE. + +Fixes: SWLINUX-2956 + +Signed-off-by: Carter Chen +--- + wpa_supplicant/defconfig_base | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base +index 611a23e3e..1c83967ae 100644 +--- a/wpa_supplicant/defconfig_base ++++ b/wpa_supplicant/defconfig_base +@@ -610,7 +610,7 @@ CONFIG_BGSCAN_LEARN=y + + # Opportunistic Wireless Encryption (OWE) + # Experimental implementation of draft-harkins-owe-07.txt +-#CONFIG_OWE=y ++CONFIG_OWE=y + + # Device Provisioning Protocol (DPP) + CONFIG_DPP=y +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0038-Add-link-loss-timer-on-beacon-loss.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0038-Add-link-loss-timer-on-beacon-loss.patch new file mode 100644 index 000000000..d9b74486c --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0038-Add-link-loss-timer-on-beacon-loss.patch @@ -0,0 +1,115 @@ +From f3695ca19a711fbfcda7233f65af13ac9e8a78f7 Mon Sep 17 00:00:00 2001 +From: root +Date: Tue, 16 Aug 2022 15:00:14 -0400 +Subject: [PATCH 38/49] Add link loss timer on beacon loss + +--- + wpa_supplicant/bgscan_learn.c | 19 +++++++++++++++++++ + wpa_supplicant/bgscan_simple.c | 19 +++++++++++++++++++ + 2 files changed, 38 insertions(+) + +diff --git a/wpa_supplicant/bgscan_learn.c b/wpa_supplicant/bgscan_learn.c +index 115d2c007..c872d8d35 100644 +--- a/wpa_supplicant/bgscan_learn.c ++++ b/wpa_supplicant/bgscan_learn.c +@@ -20,6 +20,8 @@ + #include "bgscan.h" + #include "bss.h" + ++#define BGSCAN_LEARN_LINK_LOSS_THRESH_SECS 600 ++ + struct bgscan_learn_bss { + struct dl_list list; + u8 bssid[ETH_ALEN]; +@@ -316,6 +318,18 @@ static void bgscan_learn_timeout(void *eloop_ctx, void *timeout_ctx) + } + + ++static void bgscan_learn_link_loss_timeout(void *eloop_ctx, void *timeout_ctx) ++{ ++ struct bgscan_learn_data *data = eloop_ctx; ++ struct wpa_supplicant *wpa_s = data->wpa_s; ++ ++ wpa_printf(MSG_DEBUG, "bgscan learn: Link Loss timeout"); ++ ++ eloop_cancel_timeout(bgscan_learn_link_loss_timeout, data, NULL); ++ wpa_supplicant_deauthenticate(wpa_s, WLAN_REASON_DEAUTH_LEAVING); ++} ++ ++ + static int bgscan_learn_get_params(struct bgscan_learn_data *data, + const char *params) + { +@@ -448,6 +462,7 @@ static void bgscan_learn_deinit(void *priv) + struct bgscan_learn_bss *bss, *n; + + bgscan_learn_save(data); ++ eloop_cancel_timeout(bgscan_learn_link_loss_timeout, data, NULL); + eloop_cancel_timeout(bgscan_learn_timeout, data, NULL); + if (data->signal_threshold) + wpa_drv_signal_monitor(data->wpa_s, 0, 0); +@@ -555,6 +570,10 @@ static void bgscan_learn_notify_beacon_loss(void *priv) + + wpa_printf(MSG_DEBUG, "bgscan learn: beacon loss"); + ++ wpa_printf(MSG_DEBUG, "bgscan learn: Start Link Loss timer"); ++ eloop_register_timeout(BGSCAN_LEARN_LINK_LOSS_THRESH_SECS, ++ 0, bgscan_learn_link_loss_timeout, data, NULL); ++ + wpa_printf(MSG_DEBUG, "bgscan learn: Flush all prev bss entries"); + wpa_bss_flush(data->wpa_s); + +diff --git a/wpa_supplicant/bgscan_simple.c b/wpa_supplicant/bgscan_simple.c +index bc99885fb..bf9184e43 100644 +--- a/wpa_supplicant/bgscan_simple.c ++++ b/wpa_supplicant/bgscan_simple.c +@@ -18,6 +18,8 @@ + #include "bgscan.h" + #include "bss.h" + ++#define BGSCAN_SIMPLE_LINK_LOSS_THRESH_SECS 600 ++ + struct bgscan_simple_data { + struct wpa_supplicant *wpa_s; + const struct wpa_ssid *ssid; +@@ -76,6 +78,18 @@ static void bgscan_simple_timeout(void *eloop_ctx, void *timeout_ctx) + } + + ++static void bgscan_simple_link_loss_timeout(void *eloop_ctx, void *timeout_ctx) ++{ ++ struct bgscan_simple_data *data = eloop_ctx; ++ struct wpa_supplicant *wpa_s = data->wpa_s; ++ ++ wpa_printf(MSG_DEBUG, "bgscan simple: Link Loss timeout"); ++ ++ eloop_cancel_timeout(bgscan_simple_link_loss_timeout, data, NULL); ++ wpa_supplicant_deauthenticate(wpa_s, WLAN_REASON_DEAUTH_LEAVING); ++} ++ ++ + static int bgscan_simple_get_params(struct bgscan_simple_data *data, + const char *params) + { +@@ -161,6 +175,7 @@ static void * bgscan_simple_init(struct wpa_supplicant *wpa_s, + static void bgscan_simple_deinit(void *priv) + { + struct bgscan_simple_data *data = priv; ++ eloop_cancel_timeout(bgscan_simple_link_loss_timeout, data, NULL); + eloop_cancel_timeout(bgscan_simple_timeout, data, NULL); + if (data->signal_threshold) + wpa_drv_signal_monitor(data->wpa_s, 0, 0); +@@ -196,6 +211,10 @@ static void bgscan_simple_notify_beacon_loss(void *priv) + + wpa_printf(MSG_DEBUG, "bgscan simple: beacon loss"); + ++ wpa_printf(MSG_DEBUG, "bgscan simple: Start Link Loss timer"); ++ eloop_register_timeout(BGSCAN_SIMPLE_LINK_LOSS_THRESH_SECS, ++ 0, bgscan_simple_link_loss_timeout, data, NULL); ++ + wpa_printf(MSG_DEBUG, "bgscan simple: Flush all prev bss entries"); + wpa_bss_flush(data->wpa_s); + +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0039-FT-Sync-nl80211-ext-feature-index.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0039-FT-Sync-nl80211-ext-feature-index.patch new file mode 100644 index 000000000..91ecd85cf --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0039-FT-Sync-nl80211-ext-feature-index.patch @@ -0,0 +1,34 @@ +From 7076f7634cc9d7a88f009c448ada307841b42a2a Mon Sep 17 00:00:00 2001 +From: JasonHuang +Date: Sun, 30 Oct 2022 21:58:34 -0500 +Subject: [PATCH 39/49] FT: Sync nl80211 ext feature index + +The backports-5.15.58 has been used. Supplicant should sync the +nl80211_ext_feature_index with backports to avoid unexpected fail. + +Signed-off-by: JasonHuang +--- + src/drivers/nl80211_copy.h | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/src/drivers/nl80211_copy.h b/src/drivers/nl80211_copy.h +index a3e889b35..db5b1503d 100644 +--- a/src/drivers/nl80211_copy.h ++++ b/src/drivers/nl80211_copy.h +@@ -6010,11 +6010,12 @@ enum nl80211_ext_feature_index { + NL80211_EXT_FEATURE_SAE_OFFLOAD_AP, + NL80211_EXT_FEATURE_FILS_DISCOVERY, + NL80211_EXT_FEATURE_UNSOL_BCAST_PROBE_RESP, +- NL80211_EXT_FEATURE_ROAM_OFFLOAD, + NL80211_EXT_FEATURE_BEACON_RATE_HE, + NL80211_EXT_FEATURE_SECURE_LTF, + NL80211_EXT_FEATURE_SECURE_RTT, + NL80211_EXT_FEATURE_PROT_RANGE_NEGO_AND_MEASURE, ++ NL80211_EXT_FEATURE_BSS_COLOR, ++ NL80211_EXT_FEATURE_ROAM_OFFLOAD, + + /* add new features before the definition below */ + NUM_NL80211_EXT_FEATURES, +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0040-nl80211-Introduce-a-vendor-header-for-vendor-NL-ifac.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0040-nl80211-Introduce-a-vendor-header-for-vendor-NL-ifac.patch new file mode 100644 index 000000000..4aa8a8767 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0040-nl80211-Introduce-a-vendor-header-for-vendor-NL-ifac.patch @@ -0,0 +1,126 @@ +From 62c82984916623e6e00053dcb148de71d24bdaf5 Mon Sep 17 00:00:00 2001 +From: Gokul Sivakumar +Date: Mon, 11 Jul 2022 11:15:25 +0530 +Subject: [PATCH 40/49] nl80211: Introduce a vendor header for vendor NL iface + to DRV with OUI_IFX + +So far, the proprietary configurations are done either through the private +IOCTL interface or through the vendor nl80211 CMD with OUI_BRCM. For easier +maintainance of the infineon's list of proprietary config interfaces across +DHD, FMAC, wpa_supplicant, hostapd, iw, etc, hereafter start using the new +vendor nl80211 CMD interface with OUI_IFX. + +Infineon OUI - 00:03:19 (Ref https://standards-oui.ieee.org/) + + +Signed-off-by: Gokul Sivakumar +Signed-off-by: Ian Lin +--- + src/common/ifx_vendor.h | 95 +++++++++++++++++++++++++++++++++++++++++ + 1 file changed, 95 insertions(+) + create mode 100644 src/common/ifx_vendor.h + +diff --git a/src/common/ifx_vendor.h b/src/common/ifx_vendor.h +new file mode 100644 +index 000000000..2ea9af0a7 +--- /dev/null ++++ b/src/common/ifx_vendor.h +@@ -0,0 +1,95 @@ ++/* ++ * Infineon: vendor OUI and specific assignments ++ * ++ * ©2022 Cypress Semiconductor Corporation (an Infineon company) ++ * or an affiliate of Cypress Semiconductor Corporation. All rights reserved. ++ * This software, including source code, documentation and related materials ++ * ("Software") is owned by Cypress Semiconductor Corporation or one of its ++ * affiliates ("Cypress") and is protected by and subject to ++ * worldwide patent protection (United States and foreign), ++ * United States copyright laws and international treaty provisions. ++ * Therefore, you may use this Software only as provided in the license agreement ++ * accompanying the software package from which you obtained this Software ("EULA"). ++ * If no EULA applies, Cypress hereby grants you a personal, non-exclusive, ++ * non-transferable license to copy, modify, and compile the Software source code ++ * solely for use in connection with Cypress's integrated circuit products. ++ * Any reproduction, modification, translation, compilation, or representation ++ * of this Software except as specified above is prohibited without ++ * the expresswritten permission of Cypress. ++ * Disclaimer: THIS SOFTWARE IS PROVIDED AS-IS, WITH NO WARRANTY OF ANY KIND, ++ * EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, NONINFRINGEMENT, ++ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. ++ * Cypress reserves the right to make changes to the Software without notice. ++ * Cypress does not assume any liability arising out of the application or ++ * use of the Software or any product or circuit described in the Software. ++ * Cypress does not authorize its products for use in any products where a malfunction ++ * or failure of the Cypress product may reasonably be expected to result in ++ * significant property damage, injury or death ("High Risk Product"). ++ * By including Cypress's product in a High Risk Product, the manufacturer ++ * of such system or application assumes all risk of such use and in doing so ++ * agrees to indemnify Cypress against all liability. ++ */ ++ ++#ifndef IFX_VENDOR_H ++#define IFX_VENDOR_H ++ ++/* ++ * This file is a registry of identifier assignments from the Infineon ++ * OUI 00:03:19 for purposes other than MAC address assignment. New identifiers ++ * can be assigned through normal review process for changes to the upstream ++ * hostap.git repository. ++ */ ++#define OUI_IFX 0x000319 ++ ++/* ++ * enum ifx_nl80211_vendor_subcmds - IFX nl80211 vendor command identifiers ++ * ++ * @IFX_VENDOR_SCMD_UNSPEC: Reserved value 0 ++ * ++ * @IFX_VENDOR_SCMD_FRAMEBURST: Vendor command to enable/disable Frameburst ++ * ++ * @IFX_VENDOR_SCMD_MUEDCA_OPT_ENABLE: Vendor command to enable/disable HE MU-EDCA opt ++ * ++ * @IFX_VENDOR_SCMD_LDPC_CAP: Vendor command enable/disable LDPC Capability ++ * ++ * @IFX_VENDOR_SCMD_AMSDU: Vendor command to enable/disable AMSDU on all the TID queues ++ * ++ * @IFX_VENDOR_SCMD_MAX: This acts as a the tail of cmds list. ++ * Make sure it located at the end of the list. ++ */ ++enum ifx_nl80211_vendor_subcmds { ++ /* ++ * TODO: IFX Vendor subcmd enum IDs between 1-10 are reserved ++ * to be be filled later with BRCM Vendor subcmds that are ++ * already used by IFX. ++ */ ++ IFX_VENDOR_SCMD_UNSPEC = 0, ++ /* Reserved 1-5 */ ++ IFX_VENDOR_SCMD_FRAMEBURST = 6, ++ /* Reserved 7-10 */ ++ IFX_VENDOR_SCMD_MUEDCA_OPT_ENABLE = 11, ++ IFX_VENDOR_SCMD_LDPC_CAP = 12, ++ IFX_VENDOR_SCMD_AMSDU = 13, ++ IFX_VENDOR_SCMD_MAX ++}; ++ ++/* ++ * enum ifx_vendor_attr - IFX nl80211 vendor attributes ++ * ++ * @IFX_VENDOR_ATTR_UNSPEC: Reserved value 0 ++ * ++ * @IFX_VENDOR_ATTR_MAX: This acts as a the tail of attrs list. ++ * Make sure it located at the end of the list. ++ */ ++enum ifx_vendor_attr { ++ /* ++ * TODO: IFX Vendor attr enum IDs between 0-10 are reserved ++ * to be filled later with BRCM Vendor attrs that are ++ * already used by IFX. ++ */ ++ IFX_VENDOR_ATTR_UNSPEC = 0, ++ /* Reserved 1-10 */ ++ IFX_VENDOR_ATTR_MAX = 11 ++}; ++ ++#endif /* IFX_VENDOR_H */ +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0041-add-support-to-offload-TWT-setup-request-handling-to.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0041-add-support-to-offload-TWT-setup-request-handling-to.patch new file mode 100644 index 000000000..5a1d7b781 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0041-add-support-to-offload-TWT-setup-request-handling-to.patch @@ -0,0 +1,750 @@ +From 013beb7bc5036bf627fce3707a7a83344ffa05aa Mon Sep 17 00:00:00 2001 +From: Gokul Sivakumar +Date: Mon, 11 Jul 2022 11:16:37 +0530 +Subject: [PATCH 41/49] add support to offload TWT setup request handling to + the Firmware + +With "TWT_SETUP" control sock cmd interface currently available in the +wpa_supplicant, it is currently possible to generate the TWT Setup Action +frame with the desired TWT session params like SP, SI, TWT Setup cmd type, +Flow ID, Trigger/Non-Trigger based, Un-Announced/Announced session types, +etc, without informing the TWT state machine in the Firmware. + +Now introduce a new TWT Offload code path and then when the TWT Setup is +triggerd either through the "$ wpa_cli twt_setup" or directly though the +control sock cmd "TWT_SETUP", construct a Vendor nl80211 cmd of type "TWT" +and pass it to the driver if it supports this new vendor cmd. The driver +then could inform the TWT module in the firmware through the corresponding +IOVAR to initiate a TWT Setup request while updating the TWT negotiation +handshake state machine as needed. + + +Signed-off-by: Gokul Sivakumar +Signed-off-by: Ian Lin +--- + src/common/ifx_vendor.h | 157 ++++++++++++++++++++++++++++++ + src/drivers/driver.h | 38 ++++++++ + src/drivers/driver_nl80211.c | 124 ++++++++++++++++++++++- + src/drivers/driver_nl80211.h | 3 + + src/drivers/driver_nl80211_capa.c | 12 +++ + wpa_supplicant/Makefile | 8 ++ + wpa_supplicant/ctrl_iface.c | 12 ++- + wpa_supplicant/defconfig_base | 7 ++ + wpa_supplicant/driver_i.h | 12 +++ + wpa_supplicant/twt.c | 119 +++++++++++++++++++++- + wpa_supplicant/wpa_supplicant_i.h | 8 ++ + 11 files changed, 494 insertions(+), 6 deletions(-) + +diff --git a/src/common/ifx_vendor.h b/src/common/ifx_vendor.h +index 2ea9af0a7..a94694c93 100644 +--- a/src/common/ifx_vendor.h ++++ b/src/common/ifx_vendor.h +@@ -54,6 +54,9 @@ + * + * @IFX_VENDOR_SCMD_AMSDU: Vendor command to enable/disable AMSDU on all the TID queues + * ++ * @IFX_VENDOR_SCMD_TWT: Vendor subcommand to configure TWT ++ * Uses attributes defined in enum ifx_vendor_attr_twt. ++ * + * @IFX_VENDOR_SCMD_MAX: This acts as a the tail of cmds list. + * Make sure it located at the end of the list. + */ +@@ -70,6 +73,7 @@ enum ifx_nl80211_vendor_subcmds { + IFX_VENDOR_SCMD_MUEDCA_OPT_ENABLE = 11, + IFX_VENDOR_SCMD_LDPC_CAP = 12, + IFX_VENDOR_SCMD_AMSDU = 13, ++ IFX_VENDOR_SCMD_TWT = 14, + IFX_VENDOR_SCMD_MAX + }; + +@@ -92,4 +96,157 @@ enum ifx_vendor_attr { + IFX_VENDOR_ATTR_MAX = 11 + }; + ++/* ++ * enum ifx_vendor_attr_twt - Attributes for the TWT vendor command ++ * ++ * @IFX_VENDOR_ATTR_TWT_UNSPEC: Reserved value 0 ++ * ++ * @IFX_VENDOR_ATTR_TWT_OPER: To specify the type of TWT operation ++ * to be performed. Uses attributes defined in enum ifx_twt_oper. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAMS: Nester attributes representing the ++ * parameters configured for TWT. These parameters are defined in ++ * the enum ifx_vendor_attr_twt_param. ++ * ++ * @IFX_VENDOR_ATTR_TWT_MAX: This acts as a the tail of cmds list. ++ * Make sure it located at the end of the list. ++ */ ++enum ifx_vendor_attr_twt { ++ IFX_VENDOR_ATTR_TWT_UNSPEC, ++ IFX_VENDOR_ATTR_TWT_OPER, ++ IFX_VENDOR_ATTR_TWT_PARAMS, ++ IFX_VENDOR_ATTR_TWT_MAX ++}; ++ ++/* ++ * enum ifx_twt_oper - TWT operation to be specified using the vendor ++ * attribute IFX_VENDOR_ATTR_TWT_OPER ++ * ++ * @IFX_TWT_OPER_UNSPEC: Reserved value 0 ++ * ++ * @IFX_TWT_OPER_SETUP: Setup a TWT session. Required parameters are ++ * obtained through the nested attrs under IFX_VENDOR_ATTR_TWT_PARAMS. ++ * ++ * @IFX_TWT_OPER_MAX: This acts as a the tail of the list. ++ * Make sure it located at the end of the list. ++ */ ++enum ifx_twt_oper { ++ IFX_TWT_OPER_UNSPEC, ++ IFX_TWT_OPER_SETUP, ++ IFX_TWT_OPER_MAX ++}; ++ ++/* ++ * enum ifx_vendor_attr_twt_param - TWT parameters ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_UNSPEC: Reserved value 0 ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_NEGO_TYPE: Specifies the type of Negotiation to be ++ * done during Setup. The four possible types are ++ * 0 - Individual TWT Negotiation ++ * 1 - Wake TBTT Negotiation ++ * 2 - Broadcast TWT in Beacon ++ * 3 - Broadcast TWT Membership Negotiation ++ * ++ * The possible values are defined in the enum ifx_twt_param_nego_type ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_SETUP_CMD_TYPE: Specifies the type of TWT Setup frame ++ * when sent by the TWT Requesting STA ++ * 0 - Request ++ * 1 - Suggest ++ * 2 - Demand ++ * ++ * when sent by the TWT Responding STA. ++ * 3 - Grouping ++ * 4 - Accept ++ * 5 - Alternate ++ * 6 - Dictate ++ * 7 - Reject ++ * ++ * The possible values are defined in the enum ifx_twt_oper_setup_cmd_type. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_DIALOG_TOKEN: Dialog Token used by the TWT Requesting STA to ++ * identify the TWT Setup request/response transaction. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME: Target Wake Time. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION: Nominal Minimum TWT Wake Duration. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_EXPONENT: TWT Wake Interval Exponent. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_MANTISSA: TWT Wake Interval Mantissa. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_REQUESTOR: Specify this is a TWT Requesting / Responding STA. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_TRIGGER: Specify Trigger based / Non-Trigger based TWT Session. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_IMPLICIT: Specify Implicit / Explicit TWT session. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_FLOW_TYPE: Specify Un-Announced / Announced TWT session. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_FLOW_ID: Flow ID of an iTWT session. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_BCAST_TWT_ID: Brocast TWT ID of a bTWT session. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_PROTECTION: Specifies whether Tx within SP is protected. ++ * Set to 1 to indicate that TXOPs within the TWT SPs shall be initiated ++ * with a NAV protection mechanism, such as (MU) RTS/CTS or CTS-to-self frame; ++ * otherwise, it shall set it to 0. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_CHANNEL: TWT channel field which is set to 0, unless ++ * the HE STA sets up a subchannel selective transmission operation. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_TWT_INFO_FRAME_DISABLED: TWT Information frame RX handing ++ * disabled / enabled. ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION_UNIT: Nominal Minimum TWT Wake Duration ++ * Unit. 0 represents unit in "256 usecs" and 1 represents unit in "TUs". ++ * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_MAX: This acts as a the tail of the list. ++ * Make sure it located at the end of the list. ++ */ ++enum ifx_vendor_attr_twt_param { ++ IFX_VENDOR_ATTR_TWT_PARAM_UNSPEC, ++ IFX_VENDOR_ATTR_TWT_PARAM_NEGO_TYPE, ++ IFX_VENDOR_ATTR_TWT_PARAM_SETUP_CMD_TYPE, ++ IFX_VENDOR_ATTR_TWT_PARAM_DIALOG_TOKEN, ++ IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME, ++ IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION, ++ IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_EXPONENT, ++ IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_MANTISSA, ++ IFX_VENDOR_ATTR_TWT_PARAM_REQUESTOR, ++ IFX_VENDOR_ATTR_TWT_PARAM_TRIGGER, ++ IFX_VENDOR_ATTR_TWT_PARAM_IMPLICIT, ++ IFX_VENDOR_ATTR_TWT_PARAM_FLOW_TYPE, ++ IFX_VENDOR_ATTR_TWT_PARAM_FLOW_ID, ++ IFX_VENDOR_ATTR_TWT_PARAM_BCAST_TWT_ID, ++ IFX_VENDOR_ATTR_TWT_PARAM_PROTECTION, ++ IFX_VENDOR_ATTR_TWT_PARAM_CHANNEL, ++ IFX_VENDOR_ATTR_TWT_PARAM_TWT_INFO_FRAME_DISABLED, ++ IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION_UNIT, ++ IFX_VENDOR_ATTR_TWT_PARAM_MAX ++}; ++ ++enum ifx_twt_param_nego_type { ++ IFX_TWT_PARAM_NEGO_TYPE_INVALID = -1, ++ IFX_TWT_PARAM_NEGO_TYPE_ITWT = 0, ++ IFX_TWT_PARAM_NEGO_TYPE_WAKE_TBTT = 1, ++ IFX_TWT_PARAM_NEGO_TYPE_BTWT_IE_BCN = 2, ++ IFX_TWT_PARAM_NEGO_TYPE_BTWT = 3, ++ IFX_TWT_PARAM_NEGO_TYPE_MAX = 4 ++}; ++ ++enum ifx_twt_oper_setup_cmd_type { ++ IFX_TWT_OPER_SETUP_CMD_TYPE_INVALID = -1, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_REQUEST = 0, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_SUGGEST = 1, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_DEMAND = 2, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_GROUPING = 3, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_ACCEPT = 4, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_ALTERNATE = 5, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_DICTATE = 6, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_REJECT = 7, ++ IFX_TWT_OPER_SETUP_CMD_TYPE_MAX = 8 ++}; ++ + #endif /* IFX_VENDOR_H */ +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index d778b1eaa..af4d0a5d0 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -26,6 +26,9 @@ + #include "pae/ieee802_1x_kay.h" + #endif /* CONFIG_MACSEC */ + #include "utils/list.h" ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#include "common/ifx_vendor.h" ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + + #define HOSTAPD_CHAN_DISABLED 0x00000001 + #define HOSTAPD_CHAN_NO_IR 0x00000002 +@@ -2519,6 +2522,31 @@ struct drv_acs_params { + int edmg_enabled; + }; + ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++struct drv_setup_twt_params { ++ u8 dtok; ++ u64 twt; ++ u8 min_twt; ++ u8 exponent; ++ u16 mantissa; ++ enum ifx_twt_oper_setup_cmd_type setup_cmd; ++ u8 requestor; ++ u8 trigger; ++ u8 implicit; ++ u8 flow_type; ++ u8 flow_id; ++ u8 bcast_twt_id; ++ u8 protection; ++ u8 twt_channel; ++ u8 control; ++ enum ifx_twt_param_nego_type negotiation_type; ++ u8 twt_info_frame_disabled; ++ u8 min_twt_unit; /* true - in TUs, false - in 256us */ ++}; ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ ++#endif /* CONFIG_DRIVER_NL80211_IFX */ ++ + struct wpa_bss_trans_info { + u8 mbo_transition_reason; + u8 n_candidates; +@@ -4630,6 +4658,16 @@ struct wpa_driver_ops { + const u8 *match, size_t match_len, + bool multicast); + #endif /* CONFIG_TESTING_OPTIONS */ ++ ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++ /** ++ * setup_twt - Setup a TWT session ++ * @params: Setup TWT params ++ */ ++ int (*setup_twt)(void *priv, struct drv_setup_twt_params *params); ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + }; + + /** +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index de58b17e1..fd6fe91a1 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -43,7 +43,9 @@ + #include "radiotap_iter.h" + #include "rfkill.h" + #include "driver_nl80211.h" +- ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#include "common/ifx_vendor.h" ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + + #ifndef NETLINK_CAP_ACK + #define NETLINK_CAP_ACK 10 +@@ -12284,6 +12286,121 @@ static int testing_nl80211_register_frame(void *priv, u16 type, + } + #endif /* CONFIG_TESTING_OPTIONS */ + ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++static int wpa_driver_nl80211_setup_twt(void *priv, struct drv_setup_twt_params *params) ++{ ++ struct i802_bss *bss = priv; ++ struct wpa_driver_nl80211_data *drv = bss->drv; ++ struct nl_msg *msg = NULL; ++ struct nlattr *data, *twt_param_attrs; ++ int ret = -1; ++ ++ if (!drv->ifx_twt_offload) ++ goto fail; ++ ++ if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_VENDOR)) || ++ nla_put_u32(msg, NL80211_ATTR_VENDOR_ID, OUI_IFX) || ++ nla_put_u32(msg, NL80211_ATTR_VENDOR_SUBCMD, IFX_VENDOR_SCMD_TWT)) ++ goto fail; ++ ++ data = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA); ++ if (!data) ++ goto fail; ++ ++ if (nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_OPER, IFX_TWT_OPER_SETUP)) ++ goto fail; ++ ++ twt_param_attrs = nla_nest_start(msg, IFX_VENDOR_ATTR_TWT_PARAMS); ++ if (!twt_param_attrs) ++ goto fail; ++ ++ if (nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_NEGO_TYPE, ++ params->negotiation_type) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_SETUP_CMD_TYPE, ++ params->setup_cmd) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_DIALOG_TOKEN, ++ params->dtok) || ++ ++ (params->twt && ++ nla_put_u64(msg, IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME, ++ params->twt)) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION, ++ params->min_twt) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_EXPONENT, ++ params->exponent) || ++ ++ nla_put_u16(msg, IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_MANTISSA, ++ params->mantissa) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_REQUESTOR, ++ params->requestor) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_TRIGGER, ++ params->trigger) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_IMPLICIT, ++ params->implicit) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_FLOW_TYPE, ++ params->flow_type) || ++ ++ (params->flow_id && ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_FLOW_ID, ++ params->flow_id)) || ++ ++ (params->bcast_twt_id && ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_BCAST_TWT_ID, ++ params->bcast_twt_id)) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_PROTECTION, ++ params->protection) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_CHANNEL, ++ params->twt_channel) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_TWT_INFO_FRAME_DISABLED, ++ params->twt_info_frame_disabled) || ++ ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION_UNIT, ++ params->min_twt_unit)) ++ goto fail; ++ ++ nla_nest_end(msg, twt_param_attrs); ++ nla_nest_end(msg, data); ++ ++ wpa_printf(MSG_DEBUG, ++ "nl80211: TWT Setup: Neg Type: %d REQ Type: %d TWT: %lu min_twt: %d " ++ "exponent: %d mantissa: %d requestor: %d trigger: %d implicit: %d " ++ "flow_type: %d flow_id: %d bcast_twt_id: %d protection: %d " ++ "twt_channel: %d twt_info_frame_disabled: %d min_twt_unit: %d", ++ params->negotiation_type, params->setup_cmd, params->twt, ++ params->min_twt, params->exponent, params->mantissa, ++ params->requestor, params->trigger, params->implicit, ++ params->flow_type, params->flow_id, params->bcast_twt_id, ++ params->protection, params->twt_channel, ++ params->twt_info_frame_disabled, params->min_twt_unit); ++ ++ ret = send_and_recv_msgs(drv, msg, NULL, NULL, NULL, NULL); ++ if (ret < 0) { ++ wpa_printf(MSG_DEBUG, ++ "nl80211: TWT Setup: Failed to invoke driver " ++ "TWT setup function: %s", ++ strerror(-ret)); ++ } ++ ++ return ret; ++fail: ++ nl80211_nlmsg_clear(msg); ++ nlmsg_free(msg); ++ return ret; ++} ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + + const struct wpa_driver_ops wpa_driver_nl80211_ops = { + .name = "nl80211", +@@ -12429,4 +12546,9 @@ const struct wpa_driver_ops wpa_driver_nl80211_ops = { + #ifdef CONFIG_TESTING_OPTIONS + .register_frame = testing_nl80211_register_frame, + #endif /* CONFIG_TESTING_OPTIONS */ ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++ .setup_twt = wpa_driver_nl80211_setup_twt, ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + }; +diff --git a/src/drivers/driver_nl80211.h b/src/drivers/driver_nl80211.h +index 80d456472..f681afb41 100644 +--- a/src/drivers/driver_nl80211.h ++++ b/src/drivers/driver_nl80211.h +@@ -180,6 +180,9 @@ struct wpa_driver_nl80211_data { + unsigned int unsol_bcast_probe_resp:1; + unsigned int qca_do_acs:1; + unsigned int brcm_do_acs:1; ++#ifdef CONFIG_DRIVER_NL80211_IFX ++ unsigned int ifx_twt_offload:1; ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + + u64 vendor_scan_cookie; + u64 remain_on_chan_cookie; +diff --git a/src/drivers/driver_nl80211_capa.c b/src/drivers/driver_nl80211_capa.c +index d5cdafa9f..19d1569bf 100644 +--- a/src/drivers/driver_nl80211_capa.c ++++ b/src/drivers/driver_nl80211_capa.c +@@ -17,6 +17,9 @@ + #include "common/qca-vendor.h" + #include "common/qca-vendor-attr.h" + #include "common/brcm_vendor.h" ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#include "common/ifx_vendor.h" ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + #include "driver_nl80211.h" + + +@@ -1049,6 +1052,15 @@ static int wiphy_info_handler(struct nl_msg *msg, void *arg) + break; + } + #endif /* CONFIG_DRIVER_NL80211_BRCM */ ++ ++#ifdef CONFIG_DRIVER_NL80211_IFX ++ } else if (vinfo->vendor_id == OUI_IFX) { ++ switch (vinfo->subcmd) { ++ case IFX_VENDOR_SCMD_TWT: ++ drv->ifx_twt_offload = 1; ++ break; ++ } ++#endif /* CONFIG_DRIVER_NL80211_IFX */ + } + + wpa_printf(MSG_DEBUG, "nl80211: Supported vendor command: vendor_id=0x%x subcmd=%u", +diff --git a/wpa_supplicant/Makefile b/wpa_supplicant/Makefile +index 66aedaff7..16e484ce6 100644 +--- a/wpa_supplicant/Makefile ++++ b/wpa_supplicant/Makefile +@@ -823,6 +823,14 @@ CFLAGS += -DCONFIG_WPS_STRICT + OBJS += ../src/wps/wps_validate.o + endif + ++ifdef CONFIG_DRIVER_NL80211_IFX ++CFLAGS += -DCONFIG_DRIVER_NL80211_IFX ++endif # CONFIG_DRIVER_NL80211_IFX == y ++ ++ifdef CONFIG_TWT_OFFLOAD_IFX ++CFLAGS += -DCONFIG_TWT_OFFLOAD_IFX ++endif # CONFIG_TWT_OFFLOAD_IFX == y ++ + ifdef CONFIG_WPS_TESTING + CFLAGS += -DCONFIG_WPS_TESTING + endif +diff --git a/wpa_supplicant/ctrl_iface.c b/wpa_supplicant/ctrl_iface.c +index 1d4c8bcc2..f93b8d65e 100644 +--- a/wpa_supplicant/ctrl_iface.c ++++ b/wpa_supplicant/ctrl_iface.c +@@ -9988,6 +9988,7 @@ static int wpas_ctrl_resend_assoc(struct wpa_supplicant *wpa_s) + return -1; + #endif /* CONFIG_SME */ + } ++#endif /* CONFIG_TESTING_OPTIONS */ + + + static int wpas_ctrl_iface_send_twt_setup(struct wpa_supplicant *wpa_s, +@@ -10066,10 +10067,18 @@ static int wpas_ctrl_iface_send_twt_setup(struct wpa_supplicant *wpa_s, + if (tok_s) + control = atoi(tok_s + os_strlen(" control=")); + ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++ return wpas_twt_offload_send_setup(wpa_s, dtok, exponent, mantissa, ++ min_twt, setup_cmd, twt, requestor, ++ trigger, implicit, flow_type, ++ flow_id, protection, twt_channel, ++ control); ++#else + return wpas_twt_send_setup(wpa_s, dtok, exponent, mantissa, min_twt, + setup_cmd, twt, requestor, trigger, implicit, + flow_type, flow_id, protection, twt_channel, + control); ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ + } + + +@@ -10086,7 +10095,6 @@ static int wpas_ctrl_iface_send_twt_teardown(struct wpa_supplicant *wpa_s, + return wpas_twt_send_teardown(wpa_s, flags); + } + +-#endif /* CONFIG_TESTING_OPTIONS */ + + + static int wpas_ctrl_vendor_elem_add(struct wpa_supplicant *wpa_s, char *cmd) +@@ -12202,6 +12210,7 @@ char * wpa_supplicant_ctrl_iface_process(struct wpa_supplicant *wpa_s, + sme_event_unprot_disconnect( + wpa_s, wpa_s->bssid, NULL, + WLAN_REASON_CLASS2_FRAME_FROM_NONAUTH_STA); ++#endif /* CONFIG_TESTING_OPTIONS */ + } else if (os_strncmp(buf, "TWT_SETUP ", 10) == 0) { + if (wpas_ctrl_iface_send_twt_setup(wpa_s, buf + 9)) + reply_len = -1; +@@ -12214,7 +12223,6 @@ char * wpa_supplicant_ctrl_iface_process(struct wpa_supplicant *wpa_s, + } else if (os_strcmp(buf, "TWT_TEARDOWN") == 0) { + if (wpas_ctrl_iface_send_twt_teardown(wpa_s, "")) + reply_len = -1; +-#endif /* CONFIG_TESTING_OPTIONS */ + } else if (os_strncmp(buf, "VENDOR_ELEM_ADD ", 16) == 0) { + if (wpas_ctrl_vendor_elem_add(wpa_s, buf + 16) < 0) + reply_len = -1; +diff --git a/wpa_supplicant/defconfig_base b/wpa_supplicant/defconfig_base +index 1c83967ae..bfaed5d91 100644 +--- a/wpa_supplicant/defconfig_base ++++ b/wpa_supplicant/defconfig_base +@@ -641,3 +641,10 @@ CONFIG_TESTING_OPTIONS=y + + CONFIG_SUITEB192=y + CONFIG_SUITEB=y ++ ++# Enable all IFX/Cypress changes ++CONFIG_DRIVER_NL80211_IFX=y ++ ++# Offload the TWT Session management to FW ++CONFIG_TWT_OFFLOAD_IFX=y ++ +diff --git a/wpa_supplicant/driver_i.h b/wpa_supplicant/driver_i.h +index c7ba94ebd..eab01da24 100644 +--- a/wpa_supplicant/driver_i.h ++++ b/wpa_supplicant/driver_i.h +@@ -1127,4 +1127,16 @@ static inline int wpa_drv_dpp_listen(struct wpa_supplicant *wpa_s, bool enable) + return wpa_s->driver->dpp_listen(wpa_s->drv_priv, enable); + } + ++#ifdef CONFIG_DRIVER_NL80211_IFX ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++static inline int wpa_drv_setup_twt(struct wpa_supplicant *wpa_s, ++ struct drv_setup_twt_params *params) ++{ ++ if (!wpa_s->driver->setup_twt) ++ return -1; ++ return wpa_s->driver->setup_twt(wpa_s->drv_priv, params); ++} ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ ++#endif /* CONFIG_DRIVER_NL80211_IFX */ ++ + #endif /* DRIVER_I_H */ +diff --git a/wpa_supplicant/twt.c b/wpa_supplicant/twt.c +index 8ec2c85ac..59933c875 100644 +--- a/wpa_supplicant/twt.c ++++ b/wpa_supplicant/twt.c +@@ -12,8 +12,122 @@ + #include "wpa_supplicant_i.h" + #include "driver_i.h" + ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++/** ++ * wpas_twt_offload_send_setup - Send TWT Setup frame to our AP ++ * @wpa_s: Pointer to wpa_supplicant ++ * @dtok: Dialog token ++ * @exponent: Wake-interval exponent ++ * @mantissa: Wake-interval mantissa ++ * @min_twt: Minimum TWT wake duration in units of 256 usec ++ * @setup_cmd: 0 == request, 1 == suggest, etc. Table 9-297 ++ * @twt: Target Wake Time ++ * @requestor: Specify this is a TWT Requesting / Responding STA ++ * @trigger: Specify Trigger based / Non-Trigger based TWT Session ++ * @implicit: Specify Implicit / Explicit TWT session ++ * @flow_type: Specify Un-Announced / Announced TWT session ++ * @flow_id: Flow ID / Broacast TWT ID to be used in the TWT session ++ * @protection: Specifies whether Tx within SP is protected by RTS & CTS ++ * @twt_channel: Set by the HE SST non-AP STA ++ * @control: Control Field in the TWT Setup Action frame ++ * Returns: 0 in case of success, negative error code otherwise ++ * ++ */ ++int wpas_twt_offload_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int exponent, ++ int mantissa, u8 min_twt, int setup_cmd, u64 twt, ++ bool requestor, bool trigger, bool implicit, ++ bool flow_type, u8 flow_id, bool protection, ++ u8 twt_channel, u8 control) ++{ ++ int ret = 0; ++ struct drv_setup_twt_params params; ++ u8 negotiation_type, twt_info_frame_disabled, min_twt_unit; ++ ++ params.dtok = dtok; ++ params.exponent = (u8)exponent; ++ params.mantissa = (u16)mantissa; ++ params.min_twt = min_twt; ++ params.twt = twt; ++ params.requestor = requestor ? 1 : 0; ++ params.trigger = trigger ? 1 : 0; ++ params.implicit = implicit ? 1 : 0; ++ params.flow_type = flow_type ? 1 : 0; ++ params.protection = protection ? 1 : 0; ++ params.twt_channel = twt_channel; ++ params.flow_id = 0; ++ params.bcast_twt_id = 0; ++ ++ /* Setup Command Field - IEEE 802.11ax-2021 Table 9-297 */ ++ switch(setup_cmd) { ++ case 0: params.setup_cmd = IFX_TWT_OPER_SETUP_CMD_TYPE_REQUEST; ++ break; ++ case 1: params.setup_cmd = IFX_TWT_OPER_SETUP_CMD_TYPE_SUGGEST; ++ break; ++ case 2: params.setup_cmd = IFX_TWT_OPER_SETUP_CMD_TYPE_DEMAND; ++ break; ++ case 3: params.setup_cmd = IFX_TWT_OPER_SETUP_CMD_TYPE_GROUPING; ++ break; ++ case 4: params.setup_cmd = IFX_TWT_OPER_SETUP_CMD_TYPE_ACCEPT; ++ break; ++ case 5: params.setup_cmd = IFX_TWT_OPER_SETUP_CMD_TYPE_ALTERNATE; ++ break; ++ case 6: params.setup_cmd = IFX_TWT_OPER_SETUP_CMD_TYPE_DICTATE; ++ break; ++ case 7: params.setup_cmd = IFX_TWT_OPER_SETUP_CMD_TYPE_REJECT; ++ break; ++ default: ++ wpa_printf(MSG_ERROR, ++ "TWT offload: specified Setup cmd type not supported"); ++ ret = -EOPNOTSUPP; ++ goto fail; ++ } ++ ++ /* Control Field - IEEE 802.11ax-2021 Figure 9-687 */ ++ params.control = control; ++ /* NDP Paging Indicator : Bit 0 */ ++ /* Responder PM Mode : Bit 1 */ ++ negotiation_type = (control & 0xc) >> 2; /* Negotiation type : Bit 2-3 */ ++ twt_info_frame_disabled = (control & 0x10) >> 4;/* TWT Information Frame Disabled: Bit 4 */ ++ min_twt_unit = (control & 0x20) >> 5; /* Wake Duration Unit : Bit 5 */ ++ /* Reserved : Bit 6-7 */ ++ ++ /* Negotiation Type Field - IEEE 802.11ax-2021 Table 9.296a */ ++ switch(negotiation_type) { ++ case 0: /* Individual TWT */ ++ params.negotiation_type = IFX_TWT_PARAM_NEGO_TYPE_ITWT; ++ params.flow_id = flow_id; ++ break; ++ case 1: /* Wake TBTT Negotiation */ ++ params.negotiation_type = IFX_TWT_PARAM_NEGO_TYPE_WAKE_TBTT; ++ break; ++ case 2: /* Broadcast TWT IE in Beacon */ ++ params.negotiation_type = IFX_TWT_PARAM_NEGO_TYPE_BTWT_IE_BCN; ++ break; ++ case 3: /* Broadcast TWT membership */ ++ params.negotiation_type = IFX_TWT_PARAM_NEGO_TYPE_BTWT; ++ params.bcast_twt_id = flow_id; ++ break; ++ default: ++ wpa_printf(MSG_ERROR, ++ "TWT offload: specified Nego type not supported"); ++ ret = -EOPNOTSUPP; ++ goto fail; ++ } + +-#ifdef CONFIG_TESTING_OPTIONS ++ params.twt_info_frame_disabled = twt_info_frame_disabled; ++ params.min_twt_unit = min_twt_unit; /* 1 - in TUs, 0 - in 256us */ ++ ++ if (wpa_drv_setup_twt(wpa_s, ¶ms)) { ++ wpa_printf(MSG_ERROR, "TWT offload: Failed to send TWT Setup Request"); ++ ret = -ECANCELED; ++ goto fail; ++ } ++ ++fail: ++ return ret; ++} ++ ++#else + + /** + * wpas_twt_send_setup - Send TWT Setup frame (Request) to our AP +@@ -95,6 +209,7 @@ int wpas_twt_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int exponent, + return ret; + } + ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ + + /** + * wpas_twt_send_teardown - Send TWT teardown request to our AP +@@ -138,5 +253,3 @@ int wpas_twt_send_teardown(struct wpa_supplicant *wpa_s, u8 flags) + wpabuf_free(buf); + return ret; + } +- +-#endif /* CONFIG_TESTING_OPTIONS */ +diff --git a/wpa_supplicant/wpa_supplicant_i.h b/wpa_supplicant/wpa_supplicant_i.h +index b671b54e7..1f538724e 100644 +--- a/wpa_supplicant/wpa_supplicant_i.h ++++ b/wpa_supplicant/wpa_supplicant_i.h +@@ -1643,11 +1643,19 @@ void add_freq(int *freqs, int *num_freqs, int freq); + int wpas_get_op_chan_phy(int freq, const u8 *ies, size_t ies_len, + u8 *op_class, u8 *chan, u8 *phy_type); + ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++int wpas_twt_offload_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int exponent, ++ int mantissa, u8 min_twt, int setup_cmd, u64 twt, ++ bool requestor, bool trigger, bool implicit, ++ bool flow_type, u8 flow_id, bool protection, ++ u8 twt_channel, u8 control); ++#else + int wpas_twt_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int exponent, + int mantissa, u8 min_twt, int setup_cmd, u64 twt, + bool requestor, bool trigger, bool implicit, + bool flow_type, u8 flow_id, bool protection, + u8 twt_channel, u8 control); ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ + int wpas_twt_send_teardown(struct wpa_supplicant *wpa_s, u8 flags); + + void wpas_rrm_reset(struct wpa_supplicant *wpa_s); +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0042-add-support-to-offload-TWT-Teardown-request-handling.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0042-add-support-to-offload-TWT-Teardown-request-handling.patch new file mode 100644 index 000000000..fda44d72b --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0042-add-support-to-offload-TWT-Teardown-request-handling.patch @@ -0,0 +1,331 @@ +From 9a87c940340e1c665ce7172e7df147d53d1daabe Mon Sep 17 00:00:00 2001 +From: Gokul Sivakumar +Date: Mon, 11 Jul 2022 11:16:50 +0530 +Subject: [PATCH 42/49] add support to offload TWT Teardown request handling to + the Firmware + +With "TWT_TEARDOWN" control sock cmd interface currently available in the +wpa_supplicant,it is currently possible to generate the TWT Teardown Action +frame with the desired TWT session params like Negotiation Type, Flow ID, +Bcast TWT ID, etc, without informing the TWT state machine in the Firmware. + +Now introduce a new TWT Offload code path and then when the TWT Teardown is +triggered either through the "$ wpa_cli twt_teardown" or directly though +the control sock cmd "TWT_TEARDOWN", construct a Vendor nl80211 cmd of type +"TWT" and pass it to the driver if it supports this new vendor cmd. +The driver then could inform the TWT module in the firmware through the +corresponding IOVAR to initiate a TWT Teardown request while updating the +TWT negotiation handshake state machine as needed. + + +Signed-off-by: Gokul Sivakumar +Signed-off-by: Ian Lin +--- + src/common/ifx_vendor.h | 8 ++++ + src/drivers/driver.h | 14 +++++++ + src/drivers/driver_nl80211.c | 70 +++++++++++++++++++++++++++++++ + wpa_supplicant/ctrl_iface.c | 4 ++ + wpa_supplicant/driver_i.h | 8 ++++ + wpa_supplicant/twt.c | 57 ++++++++++++++++++++++++- + wpa_supplicant/wpa_supplicant_i.h | 3 +- + 7 files changed, 162 insertions(+), 2 deletions(-) + +diff --git a/src/common/ifx_vendor.h b/src/common/ifx_vendor.h +index a94694c93..2e251c367 100644 +--- a/src/common/ifx_vendor.h ++++ b/src/common/ifx_vendor.h +@@ -127,12 +127,17 @@ enum ifx_vendor_attr_twt { + * @IFX_TWT_OPER_SETUP: Setup a TWT session. Required parameters are + * obtained through the nested attrs under IFX_VENDOR_ATTR_TWT_PARAMS. + * ++ * @IFX_TWT_OPER_TEARDOWN: Teardown the already negotiated TWT session. ++ * Required parameters are obtained through the nested attrs under ++ * IFX_VENDOR_ATTR_TWT_PARAMS. ++ * + * @IFX_TWT_OPER_MAX: This acts as a the tail of the list. + * Make sure it located at the end of the list. + */ + enum ifx_twt_oper { + IFX_TWT_OPER_UNSPEC, + IFX_TWT_OPER_SETUP, ++ IFX_TWT_OPER_TEARDOWN, + IFX_TWT_OPER_MAX + }; + +@@ -202,6 +207,8 @@ enum ifx_twt_oper { + * @IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION_UNIT: Nominal Minimum TWT Wake Duration + * Unit. 0 represents unit in "256 usecs" and 1 represents unit in "TUs". + * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_TEARDOWN_ALL_TWT: Teardown all negotiated TWT sessions. ++ * + * @IFX_VENDOR_ATTR_TWT_PARAM_MAX: This acts as a the tail of the list. + * Make sure it located at the end of the list. + */ +@@ -224,6 +231,7 @@ enum ifx_vendor_attr_twt_param { + IFX_VENDOR_ATTR_TWT_PARAM_CHANNEL, + IFX_VENDOR_ATTR_TWT_PARAM_TWT_INFO_FRAME_DISABLED, + IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION_UNIT, ++ IFX_VENDOR_ATTR_TWT_PARAM_TEARDOWN_ALL_TWT, + IFX_VENDOR_ATTR_TWT_PARAM_MAX + }; + +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index af4d0a5d0..4d810aaa8 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -2544,6 +2544,13 @@ struct drv_setup_twt_params { + u8 twt_info_frame_disabled; + u8 min_twt_unit; /* true - in TUs, false - in 256us */ + }; ++ ++struct drv_teardown_twt_params { ++ u8 negotiation_type; ++ u8 flow_id; ++ u8 bcast_twt_id; ++ u8 teardown_all_twt; ++}; + #endif /* CONFIG_TWT_OFFLOAD_IFX */ + #endif /* CONFIG_DRIVER_NL80211_IFX */ + +@@ -4666,8 +4673,15 @@ struct wpa_driver_ops { + * @params: Setup TWT params + */ + int (*setup_twt)(void *priv, struct drv_setup_twt_params *params); ++ ++ /** ++ * teardown_twt - Teardown the already negotiated TWT session ++ * @params: Teardown TWT params ++ */ ++ int (*teardown_twt)(void *priv, struct drv_teardown_twt_params *params); + #endif /* CONFIG_TWT_OFFLOAD_IFX */ + #endif /* CONFIG_DRIVER_NL80211_IFX */ ++ + }; + + /** +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index fd6fe91a1..8f8f7e2cd 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -12399,6 +12399,75 @@ fail: + nlmsg_free(msg); + return ret; + } ++ ++static int wpa_driver_nl80211_teardown_twt(void *priv, struct drv_teardown_twt_params *params) ++{ ++ struct i802_bss *bss = priv; ++ struct wpa_driver_nl80211_data *drv = bss->drv; ++ struct nl_msg *msg = NULL; ++ struct nlattr *data, *twt_param_attrs; ++ int ret = -1; ++ ++ if (!drv->ifx_twt_offload) ++ goto fail; ++ ++ if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_VENDOR)) || ++ nla_put_u32(msg, NL80211_ATTR_VENDOR_ID, OUI_IFX) || ++ nla_put_u32(msg, NL80211_ATTR_VENDOR_SUBCMD, IFX_VENDOR_SCMD_TWT)) ++ goto fail; ++ ++ data = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA); ++ if (!data) ++ goto fail; ++ ++ if (nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_OPER, IFX_TWT_OPER_TEARDOWN)) ++ goto fail; ++ ++ twt_param_attrs = nla_nest_start(msg, IFX_VENDOR_ATTR_TWT_PARAMS); ++ if (!twt_param_attrs) ++ goto fail; ++ ++ if (nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_NEGO_TYPE, ++ params->negotiation_type)) ++ goto fail; ++ ++ if (params->teardown_all_twt) { ++ if (nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_TEARDOWN_ALL_TWT, ++ params->teardown_all_twt)) ++ goto fail; ++ } else if (params->flow_id && ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_FLOW_ID, ++ params->flow_id)) { ++ goto fail; ++ } else if (params->bcast_twt_id && ++ nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_BCAST_TWT_ID, ++ params->bcast_twt_id)) { ++ goto fail; ++ } ++ ++ nla_nest_end(msg, twt_param_attrs); ++ nla_nest_end(msg, data); ++ ++ wpa_printf(MSG_DEBUG, ++ "nl80211: TWT Teardown: Neg Type: %d teardown_all_twt: %d " ++ "flow_id: %d bcast_twt_id: %d", ++ params->negotiation_type, params->teardown_all_twt, ++ params->flow_id, params->bcast_twt_id); ++ ++ ret = send_and_recv_msgs(drv, msg, NULL, NULL, NULL, NULL); ++ if (ret) { ++ wpa_printf(MSG_DEBUG, ++ "nl80211: TWT Teardown: Failed to invoke driver " ++ "TWT teardown function: %s", ++ strerror(-ret)); ++ } ++ ++ return ret; ++fail: ++ nl80211_nlmsg_clear(msg); ++ nlmsg_free(msg); ++ return ret; ++} + #endif /* CONFIG_TWT_OFFLOAD_IFX */ + #endif /* CONFIG_DRIVER_NL80211_IFX */ + +@@ -12549,6 +12618,7 @@ const struct wpa_driver_ops wpa_driver_nl80211_ops = { + #ifdef CONFIG_DRIVER_NL80211_IFX + #ifdef CONFIG_TWT_OFFLOAD_IFX + .setup_twt = wpa_driver_nl80211_setup_twt, ++ .teardown_twt = wpa_driver_nl80211_teardown_twt, + #endif /* CONFIG_TWT_OFFLOAD_IFX */ + #endif /* CONFIG_DRIVER_NL80211_IFX */ + }; +diff --git a/wpa_supplicant/ctrl_iface.c b/wpa_supplicant/ctrl_iface.c +index f93b8d65e..9964df6fc 100644 +--- a/wpa_supplicant/ctrl_iface.c ++++ b/wpa_supplicant/ctrl_iface.c +@@ -10092,7 +10092,11 @@ static int wpas_ctrl_iface_send_twt_teardown(struct wpa_supplicant *wpa_s, + if (tok_s) + flags = atoi(tok_s + os_strlen(" flags=")); + ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++ return wpas_twt_offload_send_teardown(wpa_s, flags); ++#else + return wpas_twt_send_teardown(wpa_s, flags); ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ + } + + +diff --git a/wpa_supplicant/driver_i.h b/wpa_supplicant/driver_i.h +index eab01da24..9a7975a6a 100644 +--- a/wpa_supplicant/driver_i.h ++++ b/wpa_supplicant/driver_i.h +@@ -1136,6 +1136,14 @@ static inline int wpa_drv_setup_twt(struct wpa_supplicant *wpa_s, + return -1; + return wpa_s->driver->setup_twt(wpa_s->drv_priv, params); + } ++ ++static inline int wpa_drv_teardown_twt(struct wpa_supplicant *wpa_s, ++ struct drv_teardown_twt_params *params) ++{ ++ if (!wpa_s->driver->teardown_twt) ++ return -1; ++ return wpa_s->driver->teardown_twt(wpa_s->drv_priv, params); ++} + #endif /* CONFIG_TWT_OFFLOAD_IFX */ + #endif /* CONFIG_DRIVER_NL80211_IFX */ + +diff --git a/wpa_supplicant/twt.c b/wpa_supplicant/twt.c +index 59933c875..d653e2db8 100644 +--- a/wpa_supplicant/twt.c ++++ b/wpa_supplicant/twt.c +@@ -127,6 +127,60 @@ fail: + return ret; + } + ++/** ++ * wpas_twt_offload_send_teardown - send TWT teardown request to our AP ++ * @wpa_s: pointer to wpa_supplicant ++ * @flags: the byte that goes inside the twt teardown element ++ * returns: 0 in case of success, negative error code otherwise ++ * ++ */ ++int wpas_twt_offload_send_teardown(struct wpa_supplicant *wpa_s, u8 flags) ++{ ++ int ret = 0; ++ struct drv_teardown_twt_params params; ++ u8 negotiation_type, flow_id, teardown_all_twt; ++ ++ /* TWT Flow Field - IEEE 802.11ax-2021 Figure 9-965 */ ++ flow_id = flags & 0x07; /* Flow ID : Bit 0-2 */ ++ /* Reserved : Bit 3-4 */ ++ negotiation_type = (flags & 0x60) >> 5; /* Negotiation type : Bit 5-6 */ ++ teardown_all_twt = (flags & 0x80) >> 7; /* Teardown all TWT : Bit 7 */ ++ ++ /* Negotiation Type Field - IEEE 802.11ax-2021 Table 9.296a */ ++ switch(negotiation_type) { ++ case 0: /* Individual TWT */ ++ params.negotiation_type = IFX_TWT_PARAM_NEGO_TYPE_ITWT; ++ params.flow_id = flow_id; ++ break; ++ case 1: /* Wake TBTT Negotiation */ ++ params.negotiation_type = IFX_TWT_PARAM_NEGO_TYPE_WAKE_TBTT; ++ break; ++ case 2: /* Broadcast TWT IE in Beacon */ ++ params.negotiation_type = IFX_TWT_PARAM_NEGO_TYPE_BTWT_IE_BCN; ++ break; ++ case 3: /* Broadcast TWT membership */ ++ params.negotiation_type = IFX_TWT_PARAM_NEGO_TYPE_BTWT; ++ params.bcast_twt_id = flow_id; ++ break; ++ default: ++ wpa_printf(MSG_ERROR, ++ "TWT offload: specified Nego Type Not supported"); ++ ret = -EOPNOTSUPP; ++ goto fail; ++ } ++ ++ params.teardown_all_twt = teardown_all_twt; ++ ++ if (wpa_drv_teardown_twt(wpa_s, ¶ms)) { ++ wpa_printf(MSG_ERROR, "TWT offload: Failed to send TWT Teardown frame"); ++ ret = -ECANCELED; ++ goto fail; ++ } ++ ++fail: ++ return ret; ++} ++ + #else + + /** +@@ -209,7 +263,6 @@ int wpas_twt_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int exponent, + return ret; + } + +-#endif /* CONFIG_TWT_OFFLOAD_IFX */ + + /** + * wpas_twt_send_teardown - Send TWT teardown request to our AP +@@ -253,3 +306,5 @@ int wpas_twt_send_teardown(struct wpa_supplicant *wpa_s, u8 flags) + wpabuf_free(buf); + return ret; + } ++ ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ +diff --git a/wpa_supplicant/wpa_supplicant_i.h b/wpa_supplicant/wpa_supplicant_i.h +index 1f538724e..d34383481 100644 +--- a/wpa_supplicant/wpa_supplicant_i.h ++++ b/wpa_supplicant/wpa_supplicant_i.h +@@ -1649,14 +1649,15 @@ int wpas_twt_offload_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int expon + bool requestor, bool trigger, bool implicit, + bool flow_type, u8 flow_id, bool protection, + u8 twt_channel, u8 control); ++int wpas_twt_offload_send_teardown(struct wpa_supplicant *wpa_s, u8 flags); + #else + int wpas_twt_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int exponent, + int mantissa, u8 min_twt, int setup_cmd, u64 twt, + bool requestor, bool trigger, bool implicit, + bool flow_type, u8 flow_id, bool protection, + u8 twt_channel, u8 control); +-#endif /* CONFIG_TWT_OFFLOAD_IFX */ + int wpas_twt_send_teardown(struct wpa_supplicant *wpa_s, u8 flags); ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ + + void wpas_rrm_reset(struct wpa_supplicant *wpa_s); + void wpas_rrm_process_neighbor_rep(struct wpa_supplicant *wpa_s, +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0043-Add-support-to-configure-TWT-of-a-session-using-offs.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0043-Add-support-to-configure-TWT-of-a-session-using-offs.patch new file mode 100644 index 000000000..9ac59f13f --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0043-Add-support-to-configure-TWT-of-a-session-using-offs.patch @@ -0,0 +1,177 @@ +From e03937fecb74cf50d70721ea2a0b14fa5e12153a Mon Sep 17 00:00:00 2001 +From: Gokul Sivakumar +Date: Mon, 11 Jul 2022 11:17:04 +0530 +Subject: [PATCH 43/49] Add support to configure TWT of a session using offset + in microseconds + +Introduce a new cmd line argument "twt_offset=" in the existing list +of arguments supported in "$ wpa_cli twt_setup " cmd to set the TWT +in terms of offset from the current remote TSF. + +Example: To set a Target Wake Time of 102.4ms from the current remote TSF + +$ wpa_cli twt_setup setup_cmd=0 min_twt=80 mantissa=38400 exponent=3 \ + twt_offset=102400 trigger=0 implicit=1 flow_type=0 flow_id=5 \ + control=0 + + +Signed-off-by: Gokul Sivakumar +Signed-off-by: Ian Lin +--- + src/common/ifx_vendor.h | 3 +++ + src/drivers/driver.h | 1 + + src/drivers/driver_nl80211.c | 4 ++++ + wpa_supplicant/ctrl_iface.c | 9 +++++++-- + wpa_supplicant/twt.c | 8 +++++--- + wpa_supplicant/wpa_cli.c | 2 +- + wpa_supplicant/wpa_supplicant_i.h | 6 +++--- + 7 files changed, 24 insertions(+), 9 deletions(-) + +diff --git a/src/common/ifx_vendor.h b/src/common/ifx_vendor.h +index 2e251c367..aa8e83bc7 100644 +--- a/src/common/ifx_vendor.h ++++ b/src/common/ifx_vendor.h +@@ -175,6 +175,8 @@ enum ifx_twt_oper { + * + * @IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME: Target Wake Time. + * ++ * @IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME_OFFSET: Target Wake Time Offset. ++ * + * @IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION: Nominal Minimum TWT Wake Duration. + * + * @IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_EXPONENT: TWT Wake Interval Exponent. +@@ -218,6 +220,7 @@ enum ifx_vendor_attr_twt_param { + IFX_VENDOR_ATTR_TWT_PARAM_SETUP_CMD_TYPE, + IFX_VENDOR_ATTR_TWT_PARAM_DIALOG_TOKEN, + IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME, ++ IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME_OFFSET, + IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION, + IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_EXPONENT, + IFX_VENDOR_ATTR_TWT_PARAM_WAKE_INTVL_MANTISSA, +diff --git a/src/drivers/driver.h b/src/drivers/driver.h +index 4d810aaa8..23f599bef 100644 +--- a/src/drivers/driver.h ++++ b/src/drivers/driver.h +@@ -2527,6 +2527,7 @@ struct drv_acs_params { + struct drv_setup_twt_params { + u8 dtok; + u64 twt; ++ u64 twt_offset; + u8 min_twt; + u8 exponent; + u16 mantissa; +diff --git a/src/drivers/driver_nl80211.c b/src/drivers/driver_nl80211.c +index 8f8f7e2cd..3d98e5943 100644 +--- a/src/drivers/driver_nl80211.c ++++ b/src/drivers/driver_nl80211.c +@@ -12328,6 +12328,10 @@ static int wpa_driver_nl80211_setup_twt(void *priv, struct drv_setup_twt_params + nla_put_u64(msg, IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME, + params->twt)) || + ++ (params->twt_offset && ++ nla_put_u64(msg, IFX_VENDOR_ATTR_TWT_PARAM_WAKE_TIME_OFFSET, ++ params->twt_offset)) || ++ + nla_put_u8(msg, IFX_VENDOR_ATTR_TWT_PARAM_MIN_WAKE_DURATION, + params->min_twt) || + +diff --git a/wpa_supplicant/ctrl_iface.c b/wpa_supplicant/ctrl_iface.c +index 9964df6fc..1d57e393b 100644 +--- a/wpa_supplicant/ctrl_iface.c ++++ b/wpa_supplicant/ctrl_iface.c +@@ -9999,6 +9999,7 @@ static int wpas_ctrl_iface_send_twt_setup(struct wpa_supplicant *wpa_s, + int mantissa = 8192; + u8 min_twt = 255; + unsigned long long twt = 0; ++ unsigned long long twt_offset = 0; + bool requestor = true; + int setup_cmd = 0; + bool trigger = true; +@@ -10035,6 +10036,10 @@ static int wpas_ctrl_iface_send_twt_setup(struct wpa_supplicant *wpa_s, + if (tok_s) + sscanf(tok_s + os_strlen(" twt="), "%llu", &twt); + ++ tok_s = os_strstr(cmd, " twt_offset="); ++ if (tok_s) ++ sscanf(tok_s + os_strlen(" twt_offset="), "%llu", &twt_offset); ++ + tok_s = os_strstr(cmd, " requestor="); + if (tok_s) + requestor = atoi(tok_s + os_strlen(" requestor=")); +@@ -10069,8 +10074,8 @@ static int wpas_ctrl_iface_send_twt_setup(struct wpa_supplicant *wpa_s, + + #ifdef CONFIG_TWT_OFFLOAD_IFX + return wpas_twt_offload_send_setup(wpa_s, dtok, exponent, mantissa, +- min_twt, setup_cmd, twt, requestor, +- trigger, implicit, flow_type, ++ min_twt, setup_cmd, twt, twt_offset, ++ requestor, trigger, implicit, flow_type, + flow_id, protection, twt_channel, + control); + #else +diff --git a/wpa_supplicant/twt.c b/wpa_supplicant/twt.c +index d653e2db8..b1727603f 100644 +--- a/wpa_supplicant/twt.c ++++ b/wpa_supplicant/twt.c +@@ -22,6 +22,7 @@ + * @min_twt: Minimum TWT wake duration in units of 256 usec + * @setup_cmd: 0 == request, 1 == suggest, etc. Table 9-297 + * @twt: Target Wake Time ++ * @twt_offset: Target Wake Time TSF offset + * @requestor: Specify this is a TWT Requesting / Responding STA + * @trigger: Specify Trigger based / Non-Trigger based TWT Session + * @implicit: Specify Implicit / Explicit TWT session +@@ -35,9 +36,9 @@ + */ + int wpas_twt_offload_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int exponent, + int mantissa, u8 min_twt, int setup_cmd, u64 twt, +- bool requestor, bool trigger, bool implicit, +- bool flow_type, u8 flow_id, bool protection, +- u8 twt_channel, u8 control) ++ u64 twt_offset, bool requestor, bool trigger, ++ bool implicit, bool flow_type, u8 flow_id, ++ bool protection, u8 twt_channel, u8 control) + { + int ret = 0; + struct drv_setup_twt_params params; +@@ -48,6 +49,7 @@ int wpas_twt_offload_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int expon + params.mantissa = (u16)mantissa; + params.min_twt = min_twt; + params.twt = twt; ++ params.twt_offset = twt_offset; + params.requestor = requestor ? 1 : 0; + params.trigger = trigger ? 1 : 0; + params.implicit = implicit ? 1 : 0; +diff --git a/wpa_supplicant/wpa_cli.c b/wpa_supplicant/wpa_cli.c +index 0f68d8d8a..07160b5da 100644 +--- a/wpa_supplicant/wpa_cli.c ++++ b/wpa_supplicant/wpa_cli.c +@@ -3876,7 +3876,7 @@ static const struct wpa_cli_cmd wpa_cli_commands[] = { + }, + { "twt_setup", + wpa_cli_cmd_twt_setup, NULL, cli_cmd_flag_none, +- "[dialog=] [exponent=] [mantissa=] [min_twt=] [setup_cmd=] [twt=] [requestor=0|1] [trigger=0|1] [implicit=0|1] [flow_type=0|1] [flow_id=<3-bit-id>] [protection=0|1] [twt_channel=] [control=] = Send TWT Setup frame" ++ "[dialog=] [exponent=] [mantissa=] [min_twt=] [setup_cmd=] [twt=] [twt_offset= ][requestor=0|1] [trigger=0|1] [implicit=0|1] [flow_type=0|1] [flow_id=<3-bit-id>] [protection=0|1] [twt_channel=] [control=] = Send TWT Setup frame" + }, + { "twt_teardown", + wpa_cli_cmd_twt_teardown, NULL, cli_cmd_flag_none, +diff --git a/wpa_supplicant/wpa_supplicant_i.h b/wpa_supplicant/wpa_supplicant_i.h +index d34383481..a4fca4b3a 100644 +--- a/wpa_supplicant/wpa_supplicant_i.h ++++ b/wpa_supplicant/wpa_supplicant_i.h +@@ -1646,9 +1646,9 @@ int wpas_get_op_chan_phy(int freq, const u8 *ies, size_t ies_len, + #ifdef CONFIG_TWT_OFFLOAD_IFX + int wpas_twt_offload_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int exponent, + int mantissa, u8 min_twt, int setup_cmd, u64 twt, +- bool requestor, bool trigger, bool implicit, +- bool flow_type, u8 flow_id, bool protection, +- u8 twt_channel, u8 control); ++ u64 twt_offset, bool requestor, bool trigger, ++ bool implicit, bool flow_type, u8 flow_id, ++ bool protection, u8 twt_channel, u8 control); + int wpas_twt_offload_send_teardown(struct wpa_supplicant *wpa_s, u8 flags); + #else + int wpas_twt_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int exponent, +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0044-Establish-a-Default-TWT-session-in-the-STA-after-ass.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0044-Establish-a-Default-TWT-session-in-the-STA-after-ass.patch new file mode 100644 index 000000000..027a59838 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0044-Establish-a-Default-TWT-session-in-the-STA-after-ass.patch @@ -0,0 +1,216 @@ +From 045ff0dc8aaa1297096c7a941045c74bf1a0e7f3 Mon Sep 17 00:00:00 2001 +From: Ramanathan Ramakrishnan +Date: Thu, 27 Oct 2022 06:00:28 -0500 +Subject: [PATCH 44/49] Establish a Default TWT session in the STA after + associating with the AP + +Add a new wpa_supplicant conf param "twt_def_algo" to set the Default/Auto +TWT profile. Allowed Values are 0-disable, 1-idle profile, 2-active profile +TWT session + + +Signed-off-by: Ramanathan Ramakrishnan +Signed-off-by: Gokul Sivakumar +--- + wpa_supplicant/config.c | 3 ++ + wpa_supplicant/config.h | 11 ++++ + wpa_supplicant/events.c | 6 +++ + wpa_supplicant/twt.c | 85 +++++++++++++++++++++++++++++++ + wpa_supplicant/wpa_supplicant.c | 6 +++ + wpa_supplicant/wpa_supplicant_i.h | 2 + + 6 files changed, 113 insertions(+) + +diff --git a/wpa_supplicant/config.c b/wpa_supplicant/config.c +index 737e46be5..afb36c816 100644 +--- a/wpa_supplicant/config.c ++++ b/wpa_supplicant/config.c +@@ -5094,6 +5094,9 @@ static const struct global_parse_data global_fields[] = { + { INT_RANGE(eapol_version, 1, 2), 0 }, + #endif /* CONFIG_MACSEC */ + { INT(ap_scan), 0 }, ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++ { INT_RANGE(twt_def_algo, 0 , 2), 0 }, ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ + { FUNC(bgscan), CFG_CHANGED_BGSCAN }, + #ifdef CONFIG_MESH + { INT(user_mpm), 0 }, +diff --git a/wpa_supplicant/config.h b/wpa_supplicant/config.h +index d22ef05fb..d824d9ad5 100644 +--- a/wpa_supplicant/config.h ++++ b/wpa_supplicant/config.h +@@ -487,6 +487,17 @@ struct wpa_config { + */ + int ap_scan; + ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++ /** ++ * twt_def_algo - Default (Auto) TWT profile ++ * ++ * This provides the value of the default TWT profile to be setup ++ * Values for this or 0-disable, 1-idle profile, 2-active profile TWT ++ * session ++ */ ++ int twt_def_algo; ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ ++ + /** + * bgscan - Background scan and roaming parameters or %NULL if none + * +diff --git a/wpa_supplicant/events.c b/wpa_supplicant/events.c +index bfd49ee43..7fcd057b3 100644 +--- a/wpa_supplicant/events.c ++++ b/wpa_supplicant/events.c +@@ -3568,6 +3568,12 @@ static void wpa_supplicant_event_disassoc(struct wpa_supplicant *wpa_s, + " reason=%d%s", + MAC2STR(bssid), reason_code, + locally_generated ? " locally_generated=1" : ""); ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++ if (locally_generated && ++ wpas_twt_offload_deinit_default_session(wpa_s)) ++ wpa_msg(wpa_s, MSG_ERROR, ++ "Failed to cleanup all the TWT sessions including Default session"); ++#endif + } + } + +diff --git a/wpa_supplicant/twt.c b/wpa_supplicant/twt.c +index b1727603f..ff75b7ed3 100644 +--- a/wpa_supplicant/twt.c ++++ b/wpa_supplicant/twt.c +@@ -9,10 +9,17 @@ + #include "includes.h" + + #include "utils/common.h" ++#include "config.h" + #include "wpa_supplicant_i.h" + #include "driver_i.h" ++#include "scan.h" + + #ifdef CONFIG_TWT_OFFLOAD_IFX ++#define TWT_NONE 0 ++#define TWT_IDLE 1 ++#define TWT_ACTIVE 2 ++#define TWT_TEARDOWN_ALL 128 ++ + /** + * wpas_twt_offload_send_setup - Send TWT Setup frame to our AP + * @wpa_s: Pointer to wpa_supplicant +@@ -183,6 +190,84 @@ fail: + return ret; + } + ++int wpas_twt_offload_init_default_session(struct wpa_supplicant *wpa_s) ++{ ++ int exponent = 10, mantissa = 8192, setup_cmd = 2, flow_id = 0, ret = 0; ++ unsigned long long twt = 0, twt_offset = 0; ++ bool requestor = true, trigger = true, implicit = true, flow_type = true, ++ protection = false; ++ u8 dtok = 1, min_twt = 255, twt_channel = 0, ++ control = BIT(4); /* Control field (IEEE P802.11ax/D8.0 Figure ++ * 9-687): B4 = TWT Information Frame Disabled */ ++ ++ if (wpa_s->conf->twt_def_algo == TWT_NONE) { ++ wpa_printf(MSG_DEBUG, "TWT offload: Default TWT is disabled"); ++ goto exit; ++ } ++ ++ wpa_printf(MSG_DEBUG, "TWT offload: Init Default TWT, profile %d, freq %d", ++ wpa_s->conf->twt_def_algo, wpa_s->assoc_freq); ++ ++ if (wpa_s->conf->twt_def_algo == TWT_IDLE) { ++ /* TWT profile for Idle traffic */ ++ if (IS_2P4GHZ(wpa_s->assoc_freq)) { ++ /* ++ * 2G Band ++ * SP=2ms and SI=614.4ms ++ */ ++ min_twt = 8; ++ mantissa = 600; ++ exponent = 10; ++ } else { /* ++ * 5G or 6G Band ++ * SP=512us and SI=614.4ms ++ */ ++ min_twt = 2; ++ mantissa = 600; ++ exponent = 10; ++ } ++ } else if (wpa_s->conf->twt_def_algo == TWT_ACTIVE) { ++ /* ++ * TWT profile for Active traffic ++ * 2G, 5G and 6G Bands ++ * SP=8ms and SI=50ms ++ */ ++ min_twt = 31; ++ mantissa = 50000; ++ exponent = 0; ++ } else { ++ wpa_printf(MSG_ERROR, "TWT offload: Invalid Default TWT profile"); ++ ret = -1; ++ goto exit; ++ } ++ ++ ret = wpas_twt_offload_send_setup(wpa_s, dtok, exponent, mantissa, ++ min_twt, setup_cmd, twt, twt_offset, ++ requestor, trigger, implicit, flow_type, ++ flow_id, protection, twt_channel, ++ control); ++exit: ++ return ret; ++} ++ ++int wpas_twt_offload_deinit_default_session(struct wpa_supplicant *wpa_s) ++{ ++ int flags = TWT_TEARDOWN_ALL, ret = 0; ++ ++ if (wpa_s->conf->twt_def_algo == TWT_NONE) { ++ goto exit; ++ } ++ ++ /* Clear all TWT sessions created by STA including default */ ++ wpa_printf(MSG_DEBUG, ++ "TWT offload: De-init Default TWT, profile %d, freq %d", ++ wpa_s->conf->twt_def_algo, wpa_s->assoc_freq); ++ ++ ret = wpas_twt_offload_send_teardown(wpa_s, flags); ++exit: ++ return ret; ++} ++ + #else + + /** +diff --git a/wpa_supplicant/wpa_supplicant.c b/wpa_supplicant/wpa_supplicant.c +index f238dadcf..d3d4fbc5d 100644 +--- a/wpa_supplicant/wpa_supplicant.c ++++ b/wpa_supplicant/wpa_supplicant.c +@@ -1001,7 +1001,13 @@ void wpa_supplicant_set_state(struct wpa_supplicant *wpa_s, + ssid ? ssid->id : -1, + ssid && ssid->id_str ? ssid->id_str : "", + fils_hlp_sent ? " FILS_HLP_SENT" : ""); ++ + #endif /* CONFIG_CTRL_IFACE || !CONFIG_NO_STDOUT_DEBUG */ ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++ if (wpas_twt_offload_init_default_session(wpa_s)) ++ wpa_msg(wpa_s, MSG_ERROR, ++ "Failed to esablish a TWT session by default after Connection"); ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ + wpas_clear_temp_disabled(wpa_s, ssid, 1); + wpa_s->consecutive_conn_failures = 0; + wpa_s->new_connection = 0; +diff --git a/wpa_supplicant/wpa_supplicant_i.h b/wpa_supplicant/wpa_supplicant_i.h +index a4fca4b3a..28eff55ed 100644 +--- a/wpa_supplicant/wpa_supplicant_i.h ++++ b/wpa_supplicant/wpa_supplicant_i.h +@@ -1650,6 +1650,8 @@ int wpas_twt_offload_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int expon + bool implicit, bool flow_type, u8 flow_id, + bool protection, u8 twt_channel, u8 control); + int wpas_twt_offload_send_teardown(struct wpa_supplicant *wpa_s, u8 flags); ++int wpas_twt_offload_init_default_session(struct wpa_supplicant *wpa_s); ++int wpas_twt_offload_deinit_default_session(struct wpa_supplicant *wpa_s); + #else + int wpas_twt_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int exponent, + int mantissa, u8 min_twt, int setup_cmd, u64 twt, +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0045-validate-the-TWT-parameters-exponent-and-mantissa-pa.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0045-validate-the-TWT-parameters-exponent-and-mantissa-pa.patch new file mode 100644 index 000000000..627f15b66 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0045-validate-the-TWT-parameters-exponent-and-mantissa-pa.patch @@ -0,0 +1,94 @@ +From ad935d3fefec7f775188d305a5bf63a64d30a065 Mon Sep 17 00:00:00 2001 +From: Gokul Sivakumar +Date: Fri, 11 Nov 2022 19:40:04 +0530 +Subject: [PATCH 45/49] validate the TWT parameters exponent and mantissa + passed to wpa_cli + +The exponent is a 5 bit param and the max value is 31 (0x1F). The mantissa +is a 16 bit param and its max value is 65535 (0xFFFF). Do this range check +before sending the TWT setup request to the driver. + +Set the default value of flow ID as 255 instead of 0 to let the FW choose +it when explicitly not specified by the userpsace. + + +Signed-off-by: Gokul Sivakumar +--- + wpa_supplicant/ctrl_iface.c | 4 ++++ + wpa_supplicant/twt.c | 30 +++++++++++++++++++++++++----- + 2 files changed, 29 insertions(+), 5 deletions(-) + +diff --git a/wpa_supplicant/ctrl_iface.c b/wpa_supplicant/ctrl_iface.c +index 1d57e393b..d3dfc13aa 100644 +--- a/wpa_supplicant/ctrl_iface.c ++++ b/wpa_supplicant/ctrl_iface.c +@@ -10005,7 +10005,11 @@ static int wpas_ctrl_iface_send_twt_setup(struct wpa_supplicant *wpa_s, + bool trigger = true; + bool implicit = true; + bool flow_type = true; ++#ifdef CONFIG_TWT_OFFLOAD_IFX ++ int flow_id = 0xFF; ++#else + int flow_id = 0; ++#endif /* CONFIG_TWT_OFFLOAD_IFX */ + bool protection = false; + u8 twt_channel = 0; + u8 control = BIT(4); /* Control field (IEEE P802.11ax/D8.0 Figure +diff --git a/wpa_supplicant/twt.c b/wpa_supplicant/twt.c +index ff75b7ed3..fb0c3e3c6 100644 +--- a/wpa_supplicant/twt.c ++++ b/wpa_supplicant/twt.c +@@ -52,8 +52,6 @@ int wpas_twt_offload_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int expon + u8 negotiation_type, twt_info_frame_disabled, min_twt_unit; + + params.dtok = dtok; +- params.exponent = (u8)exponent; +- params.mantissa = (u16)mantissa; + params.min_twt = min_twt; + params.twt = twt; + params.twt_offset = twt_offset; +@@ -63,8 +61,30 @@ int wpas_twt_offload_send_setup(struct wpa_supplicant *wpa_s, u8 dtok, int expon + params.flow_type = flow_type ? 1 : 0; + params.protection = protection ? 1 : 0; + params.twt_channel = twt_channel; +- params.flow_id = 0; +- params.bcast_twt_id = 0; ++ params.flow_id = 0xFF; ++ params.bcast_twt_id = 0xFF; ++ ++ /* exponent range - 0 to 31 */ ++ if (exponent >= 0 && exponent <= 0x1F) { ++ params.exponent = (u8)exponent; ++ } else { ++ wpa_printf(MSG_ERROR, ++ "TWT offload: setup cmd exponent %d not supported", ++ exponent); ++ ret = -EOPNOTSUPP; ++ goto fail; ++ } ++ ++ /* mantissa range - 1 to 65535 */ ++ if (mantissa > 0 && mantissa <= 0xFFFF) { ++ params.mantissa = (u16)mantissa; ++ } else { ++ wpa_printf(MSG_ERROR, ++ "TWT offload: setup cmd mantissa %d not supported", ++ mantissa); ++ ret = -EOPNOTSUPP; ++ goto fail; ++ } + + /* Setup Command Field - IEEE 802.11ax-2021 Table 9-297 */ + switch(setup_cmd) { +@@ -192,7 +212,7 @@ fail: + + int wpas_twt_offload_init_default_session(struct wpa_supplicant *wpa_s) + { +- int exponent = 10, mantissa = 8192, setup_cmd = 2, flow_id = 0, ret = 0; ++ int exponent = 10, mantissa = 8192, setup_cmd = 2, flow_id = 0xFF, ret = 0; + unsigned long long twt = 0, twt_offset = 0; + bool requestor = true, trigger = true, implicit = true, flow_type = true, + protection = false; +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0046-Fix-for-station-sending-open-auth-instead-of-SAE-aut.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0046-Fix-for-station-sending-open-auth-instead-of-SAE-aut.patch new file mode 100644 index 000000000..21d23f945 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0046-Fix-for-station-sending-open-auth-instead-of-SAE-aut.patch @@ -0,0 +1,25 @@ +From ed256e852f6ff9c45974128cba4d2f0fbbdece2f Mon Sep 17 00:00:00 2001 +From: Ramesh Rangavittal +Date: Mon, 21 Nov 2022 11:21:59 -0600 +Subject: [PATCH 46/49] Fix for station sending open auth instead of SAE auth + +--- + wpa_supplicant/events.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/wpa_supplicant/events.c b/wpa_supplicant/events.c +index 7fcd057b3..975110b57 100644 +--- a/wpa_supplicant/events.c ++++ b/wpa_supplicant/events.c +@@ -4166,7 +4166,7 @@ static void wpas_event_disconnect(struct wpa_supplicant *wpa_s, const u8 *addr, + #endif /* CONFIG_P2P */ + + #ifdef CONFIG_SAE +- if (reason_code == WLAN_REASON_PREV_AUTH_NOT_VALID) { ++ if (reason_code <= WLAN_REASON_PREV_AUTH_NOT_VALID) { + const u8 *bssid = wpa_s->bssid; + + if (is_zero_ether_addr(bssid)) +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0047-Fix-ROAMOFFLOAD-raises-portValid-too-early.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0047-Fix-ROAMOFFLOAD-raises-portValid-too-early.patch new file mode 100644 index 000000000..5a2f6cdae --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0047-Fix-ROAMOFFLOAD-raises-portValid-too-early.patch @@ -0,0 +1,54 @@ +From a5ae9fcc3baa099a86ecd2739caadf624258a49d Mon Sep 17 00:00:00 2001 +From: Carter Chen +Date: Mon, 28 Nov 2022 21:39:48 -0600 +Subject: [PATCH 47/49] Fix ROAMOFFLOAD raises portValid too early + +1.) while WPA_DRIVER_FLAGS_ROAM_OFFLOAD flag is set, +and if the cipher_mgmt is 8021x related, +the portValid is set while get wpa_supplicant_event_assoc. + +portValid will make the state_machine of SUPP_PAE jumps AUTHENTICATING to AUTHENTICATED. + +2.) while WPA_DRIVER_FLAGS_ROAM_OFFLOAD flag is set, +the PMKCacheLifeTime and pmksa_cache_reauth timer are set while recevied +assoc response. + +3.) if the PMKCacheLifeTime is set to a small value for disable PMK +cache. the pmksa_cache_reauth will expire right away, +for example, while doing 4-way handshake, the timer has expired. + +in case the timer of pmksa_cache_reauth has expired, +if the state of SUPP_PAE is AUTHENTICATED, +eapol_sm_txStart will be called and restart the Radius handshake. + +Solution: ROAM_OFFLOAD and cipher_mgmt is FT related, such as, FT_1X or +FT_PSK. then raise portValid. + +Fixes: SWLINUX-3041 + +Signed-off-by: Carter Chen +--- + wpa_supplicant/events.c | 7 ++++--- + 1 file changed, 4 insertions(+), 3 deletions(-) + +diff --git a/wpa_supplicant/events.c b/wpa_supplicant/events.c +index 975110b57..b42f758ce 100644 +--- a/wpa_supplicant/events.c ++++ b/wpa_supplicant/events.c +@@ -3425,9 +3425,10 @@ static void wpa_supplicant_event_assoc(struct wpa_supplicant *wpa_s, + wpa_supplicant_set_state(wpa_s, WPA_COMPLETED); + eapol_sm_notify_portValid(wpa_s->eapol, true); + eapol_sm_notify_eap_success(wpa_s->eapol, true); +- } else if (((wpa_s->drv_flags & WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_8021X) || +- (wpa_s->drv_flags2 & WPA_DRIVER_FLAGS_ROAM_OFFLOAD)) && +- wpa_key_mgmt_wpa_ieee8021x(wpa_s->key_mgmt)) { ++ } else if (((wpa_s->drv_flags & WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_8021X) && ++ wpa_key_mgmt_wpa_ieee8021x(wpa_s->key_mgmt)) || ++ ((wpa_s->drv_flags2 & WPA_DRIVER_FLAGS_ROAM_OFFLOAD) && ++ wpa_key_mgmt_ft(wpa_s->key_mgmt))) { + /* + * The driver will take care of RSN 4-way handshake, so we need + * to allow EAPOL supplicant to complete its work without +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0048-Fix-associating-failed-when-PMK-lifetime-is-set-to-1.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0048-Fix-associating-failed-when-PMK-lifetime-is-set-to-1.patch new file mode 100644 index 000000000..de1124705 --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0048-Fix-associating-failed-when-PMK-lifetime-is-set-to-1.patch @@ -0,0 +1,61 @@ +From 897917008b37a16985d0f1ae9d768c6450741574 Mon Sep 17 00:00:00 2001 +From: Owen Huang +Date: Wed, 30 Nov 2022 01:35:58 -0600 +Subject: [PATCH 48/49] Fix associating failed when PMK lifetime is set to 1 + +In WPA3 11.1 STAUT server certificate validation test +* set dot11RSNAConfigPMKLifetime to 1 +* set suppress_deauth_no_pmksa to 1 + +pmksa_cache_reauth and pmksa_cache_expire will expired right sway after +receiving the EAP success, and EAPOL start framce will be send to AP. +This scenario will cause the 4-way handshake failed. + +But wpa suulicant do not deauthenticate when PMKSA expired. +That means PMK's lifetime is infinite. +So there's not necessary to reauth with radius server to get the new PMK. + +Solution: use the same parameter to decide whether register timer to reauth. + +Fixed: SWLINUX-2883 +Signed-off-by: Owen Huang +--- + src/rsn_supp/pmksa_cache.c | 22 ++++++++++++++-------- + 1 file changed, 14 insertions(+), 8 deletions(-) + +diff --git a/src/rsn_supp/pmksa_cache.c b/src/rsn_supp/pmksa_cache.c +index 8d517b5d4..658390deb 100644 +--- a/src/rsn_supp/pmksa_cache.c ++++ b/src/rsn_supp/pmksa_cache.c +@@ -138,14 +138,20 @@ static void pmksa_cache_set_expiration(struct rsn_pmksa_cache *pmksa) + } + eloop_register_timeout(sec + 1, 0, pmksa_cache_expire, pmksa, NULL); + +- entry = pmksa->sm->cur_pmksa ? pmksa->sm->cur_pmksa : +- pmksa_cache_get(pmksa, pmksa->sm->bssid, NULL, NULL, 0); +- if (entry && !wpa_key_mgmt_sae(entry->akmp)) { +- sec = pmksa->pmksa->reauth_time - now.sec; +- if (sec < 0) +- sec = 0; +- eloop_register_timeout(sec, 0, pmksa_cache_reauth, pmksa, +- NULL); ++ /* If wpa suulicant do not deauthenticate when PMKSA expired. ++ * Means PMK's lifetime is infinite. So there's not necessary ++ * to reauth with radius server to get the new PMK. ++ */ ++ if (!pmksa->sm->suppress_deauth_no_pmksa) { ++ entry = pmksa->sm->cur_pmksa ? pmksa->sm->cur_pmksa : ++ pmksa_cache_get(pmksa, pmksa->sm->bssid, NULL, NULL, 0); ++ if (entry && !wpa_key_mgmt_sae(entry->akmp)) { ++ sec = pmksa->pmksa->reauth_time - now.sec; ++ if (sec < 0) ++ sec = 0; ++ eloop_register_timeout(sec, 0, pmksa_cache_reauth, pmksa, ++ NULL); ++ } + } + } + +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0049-non-upstream-p2p_add_group-command-unification.patch b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0049-non-upstream-p2p_add_group-command-unification.patch new file mode 100644 index 000000000..f4e0e02af --- /dev/null +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant/murata/0049-non-upstream-p2p_add_group-command-unification.patch @@ -0,0 +1,100 @@ +From 4624039b5463b1c36fc34cd5ec517a7473981591 Mon Sep 17 00:00:00 2001 +From: Carter Chen +Date: Thu, 8 Dec 2022 02:37:48 -0600 +Subject: [PATCH 49/49] non-upstream: p2p_add_group command unification + +supporting specify operation group of p2p. +- wpa_cli p2p_group_add freq=5180/80 +- wpa_cli p2p_group_add freq=5180/40 +- wpa_cli p2p_group_add freq=5180/20 + +or maximum cap of operation BW +wpa_cli p2p_group_add freq=5180 + +Fixes: SWLINUX-3008 + +Signed-off-by: Carter Chen +--- + wpa_supplicant/ctrl_iface.c | 43 ++++++++++++++++++++++++++++++++++++- + 1 file changed, 42 insertions(+), 1 deletion(-) + +diff --git a/wpa_supplicant/ctrl_iface.c b/wpa_supplicant/ctrl_iface.c +index d3dfc13aa..90cc4861c 100644 +--- a/wpa_supplicant/ctrl_iface.c ++++ b/wpa_supplicant/ctrl_iface.c +@@ -73,6 +73,7 @@ static int wpa_supplicant_global_iface_interfaces(struct wpa_global *global, + static int * freq_range_to_channel_list(struct wpa_supplicant *wpa_s, + char *val); + ++int p2p_parse_channel_width(char *cmd, int freq, int *ht40, int *vht); + + static int set_bssid_filter(struct wpa_supplicant *wpa_s, char *val) + { +@@ -6067,6 +6068,9 @@ static int p2p_ctrl_connect(struct wpa_supplicant *wpa_s, char *cmd, + if (pos2) { + pos2 += 6; + freq = atoi(pos2); ++ ++ if (p2p_parse_channel_width(pos, freq, &ht40, &vht)) ++ return -1; + if (freq <= 0) + return -1; + } +@@ -6830,9 +6834,15 @@ static int p2p_ctrl_group_add(struct wpa_supplicant *wpa_s, char *cmd) + #endif /* CONFIG_ACS */ + + while ((token = str_token(cmd, " ", &context))) { +- if (sscanf(token, "freq2=%d", &freq2) == 1 || ++ if (sscanf(token, "freq=%d", &freq) == 1 || ++ sscanf(token, "freq2=%d", &freq2) == 1 || + sscanf(token, "persistent=%d", &group_id) == 1 || + sscanf(token, "max_oper_chwidth=%d", &chwidth) == 1) { ++ if (freq) { ++ int res = p2p_parse_channel_width(token, freq, &ht40, &vht); ++ if (res) ++ return -1; ++ } + continue; + #ifdef CONFIG_ACS + } else if (os_strcmp(token, "freq=acs") == 0) { +@@ -8381,6 +8391,37 @@ static int wpa_supplicant_vendor_cmd(struct wpa_supplicant *wpa_s, char *cmd, + } + + ++int p2p_parse_channel_width(char *cmd, int freq, int *ht40, int *vht) ++{ ++ char *context_cw = NULL; ++ u8 cw = 0; ++ ++ if (str_token(cmd, "/", &context_cw)) ++ cw = atoi(context_cw); ++ ++ if (cw) { ++ if (cw == 20) { ++ *ht40 = *vht = 0; ++ } else if (cw == 40 && IS_5GHZ(freq)) { ++ *ht40 = 1; ++ *vht = 0; ++ } else if (cw == 80 && IS_5GHZ(freq)) { ++ *ht40 = 1; ++ *vht = 1; ++ } else { ++ wpa_printf(MSG_ERROR, "Function %s: invalid channel width %d\n", ++ __func__, cw); ++ return -1; ++ } ++ } else { ++ /* to indicate that there is no user specified channel width */ ++ *ht40 = 1; ++ *vht = 1; ++ } ++ return 0; ++} ++ ++ + static void wpa_supplicant_ctrl_iface_flush(struct wpa_supplicant *wpa_s) + { + #ifdef CONFIG_P2P +-- +2.17.1 + diff --git a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant_%.bbappend b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant_%.bbappend index e5081c079..038bc5ab9 100644 --- a/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant_%.bbappend +++ b/meta-digi-dey/recipes-connectivity/wpa-supplicant/wpa-supplicant_%.bbappend @@ -1,4 +1,4 @@ -# Copyright (C) 2013-2022 Digi International. +# Copyright (C) 2013-2023 Digi International. FILESEXTRAPATHS:prepend := "${THISDIR}/${BPN}:" @@ -10,9 +10,7 @@ SRC_URI += " \ file://wpa_supplicant_p2p.conf \ " -# We maintain all patches from Infineon release, but do not apply the patches that -# touches files under 'hostapd' directory, as that directory is not available in the -# wpa_supplicant package from a release tarball. +# Patch series from Murata release MURATA_COMMON_PATCHES = " \ file://murata/0001-wpa_supplicant-Support-4-way-handshake-offload-for-F.patch \ file://murata/0002-wpa_supplicant-Notify-Neighbor-Report-for-driver-tri.patch \ @@ -27,17 +25,42 @@ MURATA_COMMON_PATCHES = " \ file://murata/0011-SAE-Support-SAE-authentication-offload-in-AP-mode.patch \ file://murata/0012-DPP-Do-more-condition-test-for-AKM-type-DPP-offload.patch \ file://murata/0013-non-upstream-defconfig_base-Add-Infineon-default-con.patch \ - file://murata/0014-non-upstream-defconfig_base-Add-Infineon-default-con.patch;apply=no \ - file://murata/0015-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes-f.patch \ - file://murata/0016-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes-s.patch;apply=no \ - file://murata/0017-SAE-Set-the-right-WPA-Versions-for-FT-SAE-key-manage.patch \ - file://murata/0018-wpa_supplicant-Support-WPA_KEY_MGMT_FT-for-eapol-off.patch \ - file://murata/0019-wpa_supplicant-suppress-deauth-for-PMKSA-caching-dis.patch \ - file://murata/0020-Fix-to-check-Invalid-GTK-IE-length-in-M3-at-STA.patch \ - file://murata/0021-SAE-Fix-for-PMK-expiration-issue-through-supplicant.patch \ - file://murata/0022-SAE-Fix-for-PMK-expiration-issue-through-supplicant.patch;apply=no \ - file://murata/0023-SAE-Drop-PMKSA-cache-after-receiving-specific-deauth.patch \ - file://murata/0024-Deauthenticate-STA-only-if-PMK-expired.patch \ + file://murata/0014-CVE_2019_9501-Fix-to-check-Invalid-GTK-IE-length-in-.patch \ + file://murata/0015-Add-CONFIG_WPA3_SAE_AUTH_EARLY_SET-flags-and-codes.murata.patch \ + file://murata/0016-SAE-Set-the-right-WPA-Versions-for-FT-SAE-key-manage.patch \ + file://murata/0017-wpa_supplicant-Support-WPA_KEY_MGMT_FT-for-eapol-off.patch \ + file://murata/0018-wpa_supplicant-suppress-deauth-for-PMKSA-caching-dis.patch \ + file://murata/0019-Fix-for-PMK-expiration-issue-through-supplicant.murata.patch \ + file://murata/0020-SAE-Drop-PMKSA-cache-after-receiving-specific-deauth.patch \ + file://murata/0021-Avoid-deauthenticating-STA-if-the-reason-for-freeing.patch \ + file://murata/0022-wpa_supplicant-support-bgscan.patch \ + file://murata/0023-non-upstream-wl-cmd-create-interface-to-support-driv.murata.patch \ + file://murata/0024-non-upstream-wl-cmd-create-wl_do_cmd-as-an-entry-doi.patch \ + file://murata/0025-non-upstream-wl-cmd-create-ops-table-to-do-wl-comman.patch \ + file://murata/0026-non-upstream-wl-cmd-add-more-compile-flag.patch \ + file://murata/0027-Fix-dpp-config-parameter-setting.patch \ + file://murata/0028-DPP-Resolving-failure-of-dpp-configurator-exchange-f.patch \ + file://murata/0029-Enabling-SUITEB192-and-SUITEB-compile-options.patch \ + file://murata/0030-DPP-Enabling-CLI_EDIT-option-for-enrollee-plus-respo.patch \ + file://murata/0031-P2P-Fixes-Scan-trigger-failed-once-GC-invited-by-GO.patch \ + file://murata/0032-non-upstream-SAE-disconnect-after-PMKSA-cache-expire.patch \ + file://murata/0033-Add-support-for-beacon-loss-roaming.patch \ + file://murata/0034-wpa_supplicant-Set-PMKSA-to-driver-while-key-mgmt-is.patch \ + file://murata/0035-nl80211-Set-NL80211_SCAN_FLAG_COLOCATED_6GHZ-in-scan.patch \ + file://murata/0036-scan-Add-option-to-disable-6-GHz-collocated-scanning.patch \ + file://murata/0037-Enabling-OWE-in-wpa_supplicant.patch \ + file://murata/0038-Add-link-loss-timer-on-beacon-loss.patch \ + file://murata/0039-FT-Sync-nl80211-ext-feature-index.patch \ + file://murata/0040-nl80211-Introduce-a-vendor-header-for-vendor-NL-ifac.patch \ + file://murata/0041-add-support-to-offload-TWT-setup-request-handling-to.patch \ + file://murata/0042-add-support-to-offload-TWT-Teardown-request-handling.patch \ + file://murata/0043-Add-support-to-configure-TWT-of-a-session-using-offs.patch \ + file://murata/0044-Establish-a-Default-TWT-session-in-the-STA-after-ass.patch \ + file://murata/0045-validate-the-TWT-parameters-exponent-and-mantissa-pa.patch \ + file://murata/0046-Fix-for-station-sending-open-auth-instead-of-SAE-aut.patch \ + file://murata/0047-Fix-ROAMOFFLOAD-raises-portValid-too-early.patch \ + file://murata/0048-Fix-associating-failed-when-PMK-lifetime-is-set-to-1.patch \ + file://murata/0049-non-upstream-p2p_add_group-command-unification.patch \ " SRC_URI:append:ccimx6sbc = " file://wpa_supplicant_p2p.conf_atheros"