From 7aee122f3076c8f8818f2719eb4d7bca2f70f44a Mon Sep 17 00:00:00 2001 From: Sarvesh Bodakhe Date: Wed, 5 Aug 2026 13:26:22 +0530 Subject: [PATCH] fix(wpa_supplicant): accept NIK follow-up key descriptor with Key Type=0 iPhone (and hostap) set Key Type=0 in the pairing NIK follow-up Shared-Key Descriptor (key_info=0x1340) since the NIK is not a pairwise key. We required the pairwise bit and rejected the frame before decryption, so the NIK exchange timed out and pairing was torn down. Require only the Encrypted Key Data bit. (cherry picked from commit 94988c5aa49cd7e95a77495ad18eec2ec5efc76f) --- .../wpa_supplicant/esp_supplicant/src/esp_nan_supplicant.c | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/components/wpa_supplicant/esp_supplicant/src/esp_nan_supplicant.c b/components/wpa_supplicant/esp_supplicant/src/esp_nan_supplicant.c index d7b797e975f..93aa5aebf3b 100644 --- a/components/wpa_supplicant/esp_supplicant/src/esp_nan_supplicant.c +++ b/components/wpa_supplicant/esp_supplicant/src/esp_nan_supplicant.c @@ -761,11 +761,7 @@ int nan_pasn_followup_decrypt_keys(const uint8_t *shared_key_attr, key_desc = (const struct wpa_eapol_key *)(body + 1); key_info = WPA_GET_BE16(key_desc->key_info); - if (!(key_info & WPA_KEY_INFO_KEY_TYPE)) { - wpa_printf(MSG_INFO, - "NAN: Follow-up frame does not contain pairwise key"); - return -1; - } + /* iPhone/hostap set Key Type=0 (NIK is not a pairwise key); don't require the bit. */ if (!(key_info & WPA_KEY_INFO_ENCR_KEY_DATA)) { wpa_printf(MSG_INFO, "NAN: Follow-up frame does not contain encrypted key data");