From: Alexander Wetzel <alexander@wetzel-home.de>
To: Kalle Valo <kvalo@codeaurora.org>, Maya Erez <merez@codeaurora.org>
Cc: Ahmad Masri <amasri@codeaurora.org>,
linux-wireless@vger.kernel.org, wil6210@qti.qualcomm.com
Subject: Re: [PATCH 04/11] wil6210: fix PTK re-key race
Date: Wed, 11 Sep 2019 20:32:26 +0200 [thread overview]
Message-ID: <7b636313-fa4a-5ee4-935a-ba2ed5dde1e5@wetzel-home.de> (raw)
In-Reply-To: <20190910132315.D7AC7602F2@smtp.codeaurora.org>
Am 10.09.19 um 15:23 schrieb Kalle Valo:
> Maya Erez <merez@codeaurora.org> wrote:
>
>> Fix a race between cfg80211 add_key call and transmitting of 4/4 EAP
>> packet. In case the transmit is delayed until after the add key takes
>> place, message 4/4 will be encrypted with the new key, and the
>> receiver side (AP) will drop it due to MIC error.
>>
>> Wil6210 will monitor and look for the transmitted packet 4/4 eap key.
>> In case add_key takes place before the transmission completed, then
>> wil6210 will let the FW store the key and wil6210 will notify the FW
>> to use the PTK key only after 4/4 eap packet transmission was
>> completed.
>
> This is rather ugly but I guess still ok. Or what do people think?
>
I don't know anything about the driver here but in mac80211 the idea to
avoid the race is to simply flush the queues prior deleting the outgoing
key.
Now wpa_supplicant is not yet bypassing qdisks, but adding the socket
parameter PACKET_QDISC_BYPASS is basically a one-liner in wpa_supplicant
and should allow a generic way for drivers to avoid the race with a
simple queue flush...
Alexander
next prev parent reply other threads:[~2019-09-11 18:39 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-09-08 8:32 [PATCH 00/11] wil6210 patches Maya Erez
2019-09-08 8:32 ` [PATCH 01/11] wil6210: add wil_netif_rx() helper function Maya Erez
2019-09-12 15:08 ` Kalle Valo
2019-09-08 8:32 ` [PATCH 02/11] wil6210: add support for pci linkdown recovery Maya Erez
2019-09-12 15:22 ` Kalle Valo
2019-09-08 8:32 ` [PATCH 03/11] wil6210: add debugfs to show PMC ring content Maya Erez
2019-09-08 8:32 ` [PATCH 04/11] wil6210: fix PTK re-key race Maya Erez
2019-09-10 13:23 ` Kalle Valo
2019-09-11 7:50 ` Arend Van Spriel
2019-09-11 18:32 ` Alexander Wetzel [this message]
2019-09-12 17:39 ` Denis Kenzior
2019-09-12 21:04 ` Alexander Wetzel
2019-09-13 8:04 ` Arend Van Spriel
2019-09-13 14:33 ` Denis Kenzior
2019-09-13 20:48 ` Alexander Wetzel
2019-09-17 15:32 ` Denis Kenzior
2019-09-13 18:43 ` Alexander Wetzel
2019-09-08 8:32 ` [PATCH 05/11] wil6210: make sure DR bit is read before rest of the status message Maya Erez
2019-09-08 8:32 ` [PATCH 06/11] wil6210: verify cid value is valid Maya Erez
2019-09-08 8:32 ` [PATCH 07/11] wil6210: properly initialize discovery_expired_work Maya Erez
2019-09-08 8:32 ` [PATCH 08/11] wil6210: report boottime_ns in scan results Maya Erez
2019-09-08 8:32 ` [PATCH 09/11] wil6210: use writel_relaxed in wil_debugfs_iomem_x32_set Maya Erez
2019-09-08 8:32 ` [PATCH 10/11] wil6210: fix RX short frame check Maya Erez
2019-09-08 8:32 ` [PATCH 11/11] wil6210: ignore reset errors for FW during probe Maya Erez
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=7b636313-fa4a-5ee4-935a-ba2ed5dde1e5@wetzel-home.de \
--to=alexander@wetzel-home.de \
--cc=amasri@codeaurora.org \
--cc=kvalo@codeaurora.org \
--cc=linux-wireless@vger.kernel.org \
--cc=merez@codeaurora.org \
--cc=wil6210@qti.qualcomm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).