feat(roaming): ignore WPA2-only APs on transition disable

This commit introduces a new feature to the roaming logic. If the
currently connected AP has the 'transition disable' bit set in its
RSN IE, the roaming logic will now ignore any scanned APs that only
support WPA2-PSK. This prevents a security downgrade when roaming in a
mixed WPA2/WPA3 environment.

A new Kconfig option, CONFIG_ESP_WIFI_IGNORE_WPA2_ONLY_ON_TRANSITION_DISABLE,
has been added to control this feature. It is disabled by default.
This commit is contained in:
Kapil Gupta
2026-04-07 10:23:54 +08:00
committed by BOT
parent e7d65ec349
commit bf055692a1
6 changed files with 58 additions and 1 deletions
@@ -219,4 +219,13 @@ menu "Blacklist Configuration"
default 5
help
Maximum number of roaming candidates to consider. This also defines the size of the blacklist.
config ESP_WIFI_ROAMING_PREVENT_DOWNGRADE
bool "Prevent security downgrade when roaming"
default n
help
If the currently connected AP sends a "transition disable" bit,
this option will make the roaming logic ignore less secure APs.
This helps prevent security downgrades when roaming in a mixed
security environment (e.g., WPA2/WPA3).
endmenu # "Blacklist Configuration"
@@ -605,8 +605,40 @@ static bool candidate_security_match(wifi_ap_record_t candidate)
return false;
}
#include "esp_wpas_glue.h"
static bool candidate_profile_match(wifi_ap_record_t candidate)
{
u8 transition_disable = wpa_supplicant_get_transition_disable();
#if CONFIG_ESP_WIFI_ROAMING_PREVENT_DOWNGRADE
if (transition_disable & TRANSITION_DISABLE_WPA3_PERSONAL) {
if (candidate.authmode == WIFI_AUTH_WPA2_PSK) {
return false;
}
}
if (transition_disable & TRANSITION_DISABLE_ENHANCED_OPEN) {
if (candidate.authmode == WIFI_AUTH_OPEN) {
return false;
}
}
if (transition_disable & TRANSITION_DISABLE_WPA3_ENTERPRISE) {
if (candidate.authmode == WIFI_AUTH_WPA2_ENTERPRISE) {
return false;
}
}
#if TODO // application doesn't have a way to know SAE-PK enabled AP atm
if (transition_disable & TRANSITION_DISABLE_SAE_PK) {
/* This is a simplification. A more accurate check would involve
* parsing the candidate's RSN IE to see if it supports SAE-PK.
* For now, we reject all SAE APs if SAE-PK is enforced. */
if (candidate.authmode == WIFI_AUTH_WPA3_PSK) {
return false;
}
}
#endif
#endif
return candidate_security_match(candidate);
}