Commit Graph
1004 Commits
Author SHA1 Message Date
Jiang Jiang Jian c8e90095fc Merge branch 'bugfix/supplicant_crypto_code_correction_v6.1' into 'release/v6.1'
fix(wpa_supplicant): Correct some functions in crypto porting layer (v6.1)

See merge request espressif/esp-idf!50873
2026-07-18 21:04:55 +08:00
Akshat Agrawal ef69a06834 Fix(NAN): fix Memory Corruption due to BIP encryption
- Set internal NAN params based on the user configurable Platform

 - On a secured NDP the responder could not derive keys
   (passphrase/credential mismatch); reject cleanly and
   fire ndp_terminated/ndp_confirm(REJECTED) on every
   teardown path so the host frees the NDP-ID.

 - Tear down the old NDP when the same peer re-initiates with
   a new M1, instead of rejecting and leaking the NDL.
2026-07-17 14:01:21 +05:30
Kapil Gupta ce8fb56f9b fix(wpa_supplicant): Correct some functions in crypto porting layer 2026-07-17 13:52:44 +05:30
Jiang Jiang Jian 14f663f003 Merge branch 'fix/pbkdf2_sha256_mbedtls4_guard_v6.1' into 'release/v6.1'
fix(wpa_supplicant): guard pbkdf2_sha256 for PSA-provided SHA-256 (v6.1)

See merge request espressif/esp-idf!50460
2026-07-16 18:57:43 +08:00
Sarvesh Bodakhe faaaea8e67 fix(wpa_supplicant): guard pbkdf2_sha256 for PSA-provided SHA-256
mbedtls 4.x is PSA-first: CONFIG_MBEDTLS_SHA256_C now maps to
PSA_WANT_ALG_SHA_256, and on ESP targets the hardware SHA accelerator
serves SHA-256 through PSA, leaving the legacy MBEDTLS_SHA256_C builtin
macro undefined. The inner guard on pbkdf2_sha256 was gating on bare
MBEDTLS_SHA256_C, so the function was compiled out and NAN ND-PMK
derivation (nan_derive_nd_pmk_from_passphrase) failed to link.

Guard on (MBEDTLS_SHA256_C || PSA_WANT_ALG_SHA_256) to match the idiom
already used elsewhere in the supplicant mbedtls port (tls_mbedtls.c),
covering both the legacy builtin and PSA-provided SHA-256.
2026-07-16 11:29:29 +08:00
Shreyas Sheth 1519772ea8 fix(wpa_supplicant): Fix issues related to pmkid mismatch and eloop for dpp 2026-07-14 10:31:19 +05:30
Sarvesh Bodakhe d8c5ce149d refactor(nan): use shared nan_key_type_t from esp_wifi_driver.h
The NAN key-type selectors are defined by the blob in esp_wifi_driver.h
(nan_key_type_t), which nan_i.h already includes. Add the group-integrity
key types NAN_KEY_ND_IGTK (3) and NAN_KEY_ND_BIGTK (4) there to match the
blob, and drop the duplicate host definitions from nan_i.h so a single
shared enum is used. Resolves the review request to declare these in
nan_key_type_t and avoids redefining the typedef.
2026-07-04 00:05:20 +08:00
akshat cd16349be9 bugfix(wifi): Clear Sta TX queue to prevent key 2 send failure
Also, Ensure correct return values for key 2 and key 4.
2026-07-04 00:05:20 +08:00
Nachiket Kukade 3d30b471c6 bugfix(nan): Fix hard/soft reset cases in NAN Pairing verification
- Update pairing complete API to record for peer
- Terminate NAN Datapaths using publish_id after receiving PASN M1
2026-07-04 00:05:20 +08:00
Sajia bf5907d066 feat(nan): Add support for NAN Pairing Verification
- Add nira attr and verification for pasn auth frames
- Refine key clearing and pairing complete logic for pasn verify
- Add NIRA own-service resolution, cached NIK checks, and dynamic
  pairing IE construction for bootstrap vs verify paths.
- Replace NAN bootstrap events by private callbacks
2026-07-04 00:05:20 +08:00
Nachiket Kukade 478be42bd1 feat(nan): Add aes_wrap/unwrap crypto callbacks
- Use crypto callbacks instead of calling internal API's
- Clean up of unused code, flags. Re-arrange functions
2026-06-30 14:56:45 +08:00
Akshat Agrawal 7475e1bced Address review comments VNC 2026-06-30 14:56:35 +08:00
Akshat Agrawal ff5df2e245 Address review comments and fix build errors 2026-06-30 14:56:26 +08:00
Akshat Agrawal 8a69a08567 fix(nan): Add service hash to NVS to maintain pairing states after reset 2026-06-30 14:56:18 +08:00
Akshat Agrawal fb56779fd1 Change the NIRA verification logic 2026-06-30 14:56:10 +08:00
Nachiket Kukade ebf7dc9b31 feat(nan): persist NIK/NPK credentials in NVS
Replace nik/nik_valid in wifi_nan_sync_config_t with reset_current_nvs_creds
and use_nvs_for_caching. On NAN start, load the saved own NIK and peer
credentials from NVS (or erase them when reset is requested); generate and
persist a fresh own NIK only when none is valid and caching is enabled.

PASN reuses the SAE module (PWE/crypto and the comeback-token mechanism),
so define CONFIG_SAE whenever SoftAP-SAE or PASN is enabled. This fixes the
undefined references to check_comeback_token()/auth_build_token_req() when
SOFTAP config is disabled.
2026-06-30 14:55:51 +08:00
Akshat Agrawal 2e2e63e3d3 Address Review comments 2026-06-30 14:54:58 +08:00
Akshat Agrawal 3e81bc86c7 fix(nan): fix NAN pairing NIK/NIRA exchange and verification
Register esp_nan_verify_nira, cache NIRA for publish frames, send own_nik
in pairing follow-up, and complete pairing only after peer NIK is stored.
2026-06-30 14:54:14 +08:00
Akshat Agrawal b027033c98 fix(nan): Add NDP Setup timeout at the publisher side
- fix PASN initiator pmksa_cache_get() usage with the extra argument
- Add attributes to secured NDP frames according to Specs
- Resolve M2 MIC verification failure in secured datapath
2026-06-30 14:53:56 +08:00
Kapil Gupta 48d253bc26 refactor(wpa_supplicant): add shared psa_import_aes_key helper
Centralize PSA AES key import used by ECB, CBC, CTR, CCM, CMAC, and
NIST key-wrap paths in crypto_mbedtls.c.
2026-06-05 12:11:53 +05:30
Kapil Gupta 613ff76550 fix(wpa_supplicant): migrate aes_wrap to PSA NIST-KW API
mbedTLS 3.x removed mbedtls_nist_kw_context; use psa_import_key and
mbedtls_nist_kw_wrap/unwrap with PSA key IDs instead.

Closes https://github.com/espressif/esp-idf/issues/18678
2026-06-05 12:11:53 +05:30
Kapil Gupta de91d9fb71 fix(esp_wifi): Correct igtk key installation in ft 2026-06-03 08:53:38 +05:30
Shreyas Sheth 41b4d70ad4 feat(esp_wifi): Add support for multiconfig support for DPP 2026-05-25 13:57:28 +08:00
Shreyas Sheth 958c7bef43 feat(esp_wifi): Harden dpp code and add improvements for dpp 2026-05-25 13:57:28 +08:00
Shreyas Sheth 2d3c11b277 fix(esp_wifi): Fix ci pipeline for random mac feature 2026-05-25 11:22:45 +08:00
JackandCursor 4786ab4d14 docs(wifi): add Chinese translation for MAC randomization
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-25 11:22:45 +08:00
Aditi 18cbdbf2b1 feat(esp_wifi): Add improvements for privacy extension
1) Add support for MAC randomization in Active scan and connect
  2) Add support for randomizaton of sequence numbers
  3) Add support for randomization of dialog token for GAS frames
2026-05-25 11:22:45 +08:00
0f8d4b74a0 feat(esp_wifi): NAN Pairing Improvements and bugfixes
- Route NAN pairing bootstrap via NPBA receive path
- extend datapath_req wait time to fit secured M1-M4 handshake
- Plug ND-PMK derived from KDK into NDP
- prefers paired-peer cached ND-PMK (from PASN pairing complete), when available
- carry ND-PMK metadata in pairing install callback
- Extend PASN key-installed callback payload to include role, mapped NDP CSID
  and derived ND-PMK so the NAN layer can populate paired-peer security cache.

Co-authored-by: Akshat Agrawal <akshat.agrawal@espressif.com>
Co-authored-by: Sarvesh Bodakhe <sarvesh.bodakhe@espressif.com>
2026-05-22 11:30:00 +05:30
9f361f478d feat(esp_wifi): Add NAN Pairing support
- Add container struct for internal extra params for follow-up
- Support for parsing Shared Key Desc in Pairing follow-up
- Implement NAN Pairing API's with required parameters
- In KeyData set cipher_ver to 0, Key Info to 0x12C8
  (AKM-defined | Pairwise | Install | ACK |
   Secure | Encrypted Key Data) for iOS compatibility
- Move NAN PASN into esp_nan_supplicant.c, move declarations
  to esp_private/esp_supp_nan.h
- Align PASN/ND-PMK derivation with hostap

Co-authored-by: Sajia <sajia.ali@espressif.com>
Co-authored-by: Akshat Agrawal <akshat.agrawal@espressif.com>
Co-authored-by: Sarvesh Bodakhe <sarvesh.bodakhe@espressif.com>
2026-05-22 13:01:51 +08:00
Nachiket Kukade e731ff3598 feat(wpa_supplicant): Add PASN Support to for NAN Pairing
- Create pasn module from upstream. Changes till 1a791e9c
- Add ecdh prime len api to MbedTLS port
- Integrate nan and pasn modules for PIN code method
- Fix KCK length and add auth timeout
- Add NAN Pairing PASN support
2026-05-22 13:01:51 +08:00
Jiang Jiang Jian 426295f132 Merge branch 'bugfix/allow_m1_for_pmk_cache' into 'master'
fix(esp_wifi): Allow M1 in pmk caching case

Closes WIFIBUG-1884

See merge request espressif/esp-idf!48403
2026-05-20 15:52:58 +08:00
Sarvesh Bodakhe 67aeac85e5 feat(wpa_supplicant): expose pbkdf2_sha256 for NAN crypto
Re-export the pbkdf2_sha256 declaration from sha256.h and add the
mbedTLS-backed implementation in crypto_mbedtls.c. NAN uses this for
ND-PMK derivation from a passphrase; the helper is also available for
any future caller that needs RFC 8018 PBKDF2 over SHA-256.
2026-05-19 10:48:13 +05:30
Kapil Gupta 4721a8849b fix(esp_wifi): Allow M1 in pmk caching case 2026-05-11 23:09:21 +05:30
Kapil Gupta 797059d239 fix(esp_wifi): Add support to bypass rng for bringup 2026-05-11 14:10:11 +05:30
Shreyas Sheth 0df4edc1d3 fix(wpa_supplicant): alter the check for eloop_is_running before wifi_task assertion 2026-05-08 13:32:45 +05:30
Shreyas Sheth d841c78cf0 fix(esp_wifi): Fix concurrency for flags between wpa3 and Wi-Fi task 2026-05-08 13:32:45 +05:30
Shreyas Sheth 697239e7e3 fix(wpa_supplicant): Address comments for concurrency between WiFi and WPA3 task 2026-05-08 13:32:45 +05:30
Shreyas Sheth b1f0e65e8b fix(wpa_supplicant): Fix concurrency issues between wpa3 and wifi task 2026-05-08 13:32:45 +05:30
Jiang Jiang Jian 8f498b1c56 Merge branch 'bugfix/concurrency_issues' into 'master'
fix(esp_wifi): Fixed some issues in esp_supplicant code

See merge request espressif/esp-idf!46630
2026-05-07 10:24:21 +08:00
Jiang Jiang Jian f7a5ef7ad5 Merge branch 'feature/softap_owe_support' into 'master'
Add support for OWE Only in SoftAP mode

Closes WIFI-4281 and IDFGH-12437

See merge request espressif/esp-idf!47341
2026-05-06 19:38:29 +08:00
Jiang Jiang Jian 43a7fdee43 Merge branch 'bugfix/roaming_app_issues' into 'master'
fix(esp_wifi): Fixed some issues in roaming app found using static analysis

Closes WIFIBUG-1836 and WIFIBUG-1842

See merge request espressif/esp-idf!47372
2026-05-06 15:50:55 +08:00
Kapil Gupta b585c0b364 fix(esp_wifi): Fixed some issues in roaming app found using static analysis 2026-05-06 15:50:54 +08:00
tarun.kumar 2c3cd560c4 fix(wifi) : Made changes based on more review comments
-Require STA DH IE for OWE associations.
    - Send failures using Association Response (no silent deauth-only path).
    - Include RSNE in OWE Association Response alongside DH Parameter IE.
    - Check wpabuf_resize return values when building OWE Assoc Response IEs.
    - Recognize OWE AKM in RSN IE when CONFIG_OWE_SOFTAP without CONFIG_OWE_STA.
    - Docs: SoftAP OWE-only; no transition mode; trim misleading OPEN→OWE note.
2026-05-06 01:07:57 +05:30
tarun.kumar d698d5345a feat(wifi) : OWE softAP review follow ups
- OWE: clear PRK on HKDF failure; wipe PMK with bin_clear_free; reuse PMK
      buffer when size matches.
    - 4-way handshake: drop extra OWE check so WPA2-PSK can try the next passphrase.
    - SoftAP: simpler OWE key setup and assoc response IEs (skip useless RSNXE step).
2026-05-05 21:40:56 +05:30
tarun.kumar a5201bb8f4 fix(wifi) : Send assoc response with status code 77 in case of invalid DH group parameter element 2026-05-05 21:40:29 +05:30
tarun.kumar c0b58df382 fix(wifi) : Fixed some issues found using static analysis 2026-05-05 21:40:29 +05:30
Aditi 7d0551257c feat(esp_wifi): Add changes for addressing some review comments
Closes https://github.com/espressif/esp-idf/issues/13457
2026-05-05 21:40:29 +05:30
Aditi 165c9fa44c feat(esp_wifi): Add ESP-IDF specific changes for OWE Only softap
1) Add OWE-Only Support in ESP-IDF softAP example
2) Add changes in documentation
2026-05-05 21:40:29 +05:30
Jouni Malinen 376fb23ff7 OWE: PMKSA caching in AP mode
This extends OWE support in hostapd to allow PMKSA caching to be used.

Signed-off-by: Jouni Malinen <jouni@qca.qualcomm.com>
2026-05-05 21:40:29 +05:30
Aditi 01380bd7d9 feat(esp_wifi): Add ESP-IDF specific changes for OWE-Only SoftAP
1) Add Support for OWE in wifi driver for SoftAP mode.
2) Add some changes in 4-Way Handshake to support OWE in softAP.
3) Add some restructuring changes.
2026-05-05 21:40:29 +05:30