Commit Graph
1027 Commits
Author SHA1 Message Date
Jiang Jiang Jian 57602151fa Merge branch 'fix/supplicant_checks' into 'master'
Fixed OOB read on short FT auth and RRM action frames

Closes SEC-766 and SEC-767

See merge request espressif/esp-idf!52683
2026-09-11 10:25:44 +08:00
tarun.kumar 0ba37921dd fix(wifi) : Fixed OOB read on short FT auth and RRM action frames 2026-09-10 12:36:27 +05:30
tarun.kumar 4bbab381f3 fix(wifi) : Add length/NULL checks and some minor changes
- Check os_malloc failure in wpas_mbo_update_non_pref_chan
  - Guard WAPI EID read with wpa_ie_len >= 1 in wpa_parse_wpa_ie
  - Require full 5-byte RRM Enabled Capabilities IE before copy
  - NULL-check FT mobility domain before memcmp in wpa_set_bss
  - Use wpabuf_clear_free for WPS decrypted M4/M6/M8 data
  - Drop redundant wpabuf_free before clear_free in eap_peap
2026-09-10 11:59:45 +08:00
Sajia 812634176b refactor(wifi): Improve owe scan time and refactor code 2026-09-03 14:19:57 +05:30
Jiang Jiang Jian ef2b8a164d Merge branch 'fix/scan_only_parse' into 'master'
Add scan only parser to show AP full compatibility

Closes ESPCS-1092

See merge request espressif/esp-idf!49948
2026-09-03 16:43:42 +08:00
Nachiket Kukade a9b89a3fd5 Merge branch 'fix/eloop-wifi-deinit-leak-delay' into 'master'
test(wpa_supplicant): wait for the idle task after esp_wifi_deinit in eloop unit test

Closes IDFCI-11307 and IDFCI-12170

See merge request espressif/esp-idf!52111
2026-09-03 14:03:45 +08:00
tarun.kumar 3a33ee7aa9 fix(wifi) : Add scan only parser to show AP full compatibility 2026-09-02 16:12:35 +05:30
Sarvesh Bodakhe bff264775a test(wifi): wait for the idle task after esp_wifi_deinit in Wi-Fi UTs
The Wi-Fi task deletes itself when esp_wifi_deinit() is called, and FreeRTOS
only reclaims its TCB and stack from the idle task afterwards. Test apps that
read the heap right after deinit therefore see that memory as still allocated
and report a leak, most visibly as the eloop unit tests failing on ESP32.

Wait for the idle task at every point where a test deinitialises Wi-Fi
before a leak check, replacing the single-tick delays that only matched what
esp_wifi_deinit() already waits for internally.
2026-09-01 14:17:10 +05:30
Akshat Agrawal c4c59271ee fix(wpa_supplicant): Assign correct return value for SAE y-construction failure 2026-09-01 12:11:10 +05:30
Jiang Jiang Jian f1cbff98e3 Merge branch 'bugfix/dpp_stray_auth_confirm' into 'master'
fix(esp_wifi): Harden dpp Auth confirm and drop mismatched auth confirms

Closes WIFIBUG-2032 and WIFIBUG-2075

See merge request espressif/esp-idf!51554
2026-08-19 17:15:35 +08:00
Shreyas Sheth 475bb48880 fix(esp_wifi): Harden dpp Auth confirm and drop mismatched auth confirms 2026-08-18 10:39:21 +08:00
Richard Allen 654d8a3f42 TLS: Avoid discarded-qualifiers
Just a build issue fix depending on GCC5+ configuration, fixes:

assignment discards 'const' qualifier from pointer target type [-Werror=discarded-qualifiers]
return discards 'const' qualifier from pointer target type [-Werror=discarded-qualifiers]

Signed-off-by: Richard Allen <richard@bryghtlabs.com>
2026-08-13 13:32:38 +08:00
Jimi Chen babdd168c1 SAE: Fix crash due to NULL pointer dereference in H2E parsing
In H2E (Hash-to-Element) mode, sae_parse_commit() parses the optional
Anti-Clogging Token Container by calling sae_parse_token_container().

However, callers of sae_parse_commit() that do not require retrieving
the anti-clogging token (such as PASN initiator/responder and SME auth)
pass NULL for the token and token_len output arguments.

If the peer sends a Commit frame containing a valid Anti-Clogging
Token Container element, sae_parse_token_container() unconditionally
sets *token and *token_len, resulting in a NULL pointer dereference
(SIGSEGV) and crashing wpa_supplicant.

Fix this by adding NULL checks before writing to token and token_len.
Update the debug log to print the token directly using 'pos'.

Fixes: 5e32fb0170f4 ("SAE: Use Anti-Clogging Token Container element with H2E")
Signed-off-by: Amarnath Hullur Subramanyam <amarnathhs@google.com>
2026-08-13 13:32:38 +08:00
Jouni Malinen be7d95c1a1 Require network_ctx and AKMP match for accepting PMKSA entry
When wpa_supplicant was processing EAPOL-Key msg 1/4 with a PMKID
indicated by the AP/Authenticator, a PMKSA for the same AA was accepted
without enforcing matching network_ctx (i.e., same network configuration
block) and AKMP. This could allow misbehaving APs to make wpa_supplicant
use an unacceptable PMKSA entry that was generated for a different
network for AKMP under certain conditions. This could result in showing
a connection to an incorrect network when an attacker has credentials to
one network in wpa_supplicant configuration, but not to another network.

Fix this by accepting the PMKID to set the PMKSA for an association only
if the PMKSA with the same PMKID is for the same network and was
generated using the same AKMP.

Signed-off-by: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
2026-08-13 13:32:38 +08:00
Jiang Jiang Jian 67b6ef3c1c Merge branch 'fix/owe_prevent_double_free' into 'master'
fix(wifi): Prevent double free in owe failure path

Closes SEC-261

See merge request espressif/esp-idf!51401
2026-08-10 14:18:26 +08:00
Sarvesh Bodakhe 94988c5aa4 fix(wpa_supplicant): accept NIK follow-up key descriptor with Key Type=0
iPhone (and hostap) set Key Type=0 in the pairing NIK follow-up Shared-Key
Descriptor (key_info=0x1340) since the NIK is not a pairwise key. We required
the pairwise bit and rejected the frame before decryption, so the NIK
exchange timed out and pairing was torn down. Require only the Encrypted
Key Data bit.
2026-08-06 17:25:35 +05:30
Sajia d9ba2da026 fix(wifi): Prevent double free in owe failure path 2026-07-31 12:33:11 +05:30
Akshat Agrawal 4f93a6777b Fix(NAN): fix Memory Corruption due to BIP encryption
- Set internal NAN params based on the user configurable Platform

 - On a secured NDP the responder could not derive keys
   (passphrase/credential mismatch); reject cleanly and
   fire ndp_terminated/ndp_confirm(REJECTED) on every
   teardown path so the host frees the NDP-ID.

 - Tear down the old NDP when the same peer re-initiates with
   a new M1, instead of rejecting and leaking the NDL.
2026-07-17 13:51:16 +05:30
Jiang Jiang Jian 23b3c3d4ca Merge branch 'bugfix/supplicant_crypto_code_correction' into 'master'
fix(wpa_supplicant): Correct some functions in crypto porting layer

See merge request espressif/esp-idf!50236
2026-07-17 14:12:59 +08:00
Kapil Gupta b3b955cd6e fix(wpa_supplicant): Correct some functions in crypto porting layer 2026-07-16 17:48:27 +08:00
Alexey Lapshin 1791325998 change(ci): enable -Werror=unused-but-set-variable 2026-07-16 10:54:36 +07:00
Shreyas Sheth 53e36b0ce4 fix(wpa_supplicant): Fix issues related to pmkid mismatch and eloop for dpp 2026-07-09 17:38:49 +05:30
Sarvesh Bodakhe 5bf61777b6 fix(wpa_supplicant): guard pbkdf2_sha256 for PSA-provided SHA-256
mbedtls 4.x is PSA-first: CONFIG_MBEDTLS_SHA256_C now maps to
PSA_WANT_ALG_SHA_256, and on ESP targets the hardware SHA accelerator
serves SHA-256 through PSA, leaving the legacy MBEDTLS_SHA256_C builtin
macro undefined. The inner guard on pbkdf2_sha256 was gating on bare
MBEDTLS_SHA256_C, so the function was compiled out and NAN ND-PMK
derivation (nan_derive_nd_pmk_from_passphrase) failed to link.

Guard on (MBEDTLS_SHA256_C || PSA_WANT_ALG_SHA_256) to match the idiom
already used elsewhere in the supplicant mbedtls port (tls_mbedtls.c),
covering both the legacy builtin and PSA-provided SHA-256.
2026-07-06 14:41:23 +05:30
Jiang Jiang Jian fa86d80f71 Merge branch 'feat/nan_gtk_support' into 'master'
feat(wifi_aware): advertise group data/mgmt protection (GTK/IGTK/BIGTK) and iOS compliance fixes

See merge request espressif/esp-idf!49800
2026-07-02 18:32:56 +08:00
Mahavir Jain bd567cf046 fix(wpa_supplicant): fix unused-but-set-variable warnings with GCC 16
GCC 16 raised the default level of -Wunused-but-set-variable and now
flags variables that are only used to update themselves. Remove the
'removed' counter in pmksa_cache_flush() (its only read was commented
out) and mark the EAP-FAST PAC entry counters as unused, since their
only read is inside wpa_printf(MSG_DEBUG, ...) which compiles to a
no-op when debug logging is disabled.
2026-07-02 07:55:13 +05:30
Sarvesh Bodakhe ebb9539d17 refactor(nan): use shared nan_key_type_t from esp_wifi_driver.h
The NAN key-type selectors are defined by the blob in esp_wifi_driver.h
(nan_key_type_t), which nan_i.h already includes. Add the group-integrity
key types NAN_KEY_ND_IGTK (3) and NAN_KEY_ND_BIGTK (4) there to match the
blob, and drop the duplicate host definitions from nan_i.h so a single
shared enum is used. Resolves the review request to declare these in
nan_key_type_t and avoids redefining the typedef.
2026-07-01 18:12:24 +05:30
akshat f4708595e6 bugfix(wifi): Clear Sta TX queue to prevent key 2 send failure
Also, Ensure correct return values for key 2 and key 4.
2026-06-30 14:56:15 +05:30
Nachiket Kukade 17ff376098 bugfix(nan): Fix hard/soft reset cases in NAN Pairing verification
- Update pairing complete API to record for peer
- Terminate NAN Datapaths using publish_id after receiving PASN M1
2026-06-30 12:58:44 +05:30
Sajia c18887b05c feat(nan): Add support for NAN Pairing Verification
- Add nira attr and verification for pasn auth frames
- Refine key clearing and pairing complete logic for pasn verify
- Add NIRA own-service resolution, cached NIK checks, and dynamic
  pairing IE construction for bootstrap vs verify paths.
- Replace NAN bootstrap events by private callbacks
2026-06-30 12:58:41 +05:30
Nachiket Kukade d36416980c feat(nan): Add aes_wrap/unwrap crypto callbacks
- Use crypto callbacks instead of calling internal API's
- Clean up of unused code, flags. Re-arrange functions
2026-06-23 22:08:06 +05:30
Akshat Agrawal c4b1e06057 Address review comments VNC 2026-06-23 22:08:06 +05:30
Akshat Agrawal 2c134933ec Address review comments and fix build errors 2026-06-23 22:08:06 +05:30
Akshat Agrawal 601faef85b fix(nan): Add service hash to NVS to maintain pairing states after reset 2026-06-23 22:08:06 +05:30
Akshat Agrawal afd5a13e71 Change the NIRA verification logic 2026-06-23 22:08:06 +05:30
Nachiket Kukade 7d6d7ead9a feat(nan): persist NIK/NPK credentials in NVS
Replace nik/nik_valid in wifi_nan_sync_config_t with reset_current_nvs_creds
and use_nvs_for_caching. On NAN start, load the saved own NIK and peer
credentials from NVS (or erase them when reset is requested); generate and
persist a fresh own NIK only when none is valid and caching is enabled.

PASN reuses the SAE module (PWE/crypto and the comeback-token mechanism),
so define CONFIG_SAE whenever SoftAP-SAE or PASN is enabled. This fixes the
undefined references to check_comeback_token()/auth_build_token_req() when
SOFTAP config is disabled.
2026-06-23 22:08:06 +05:30
Akshat Agrawal 92a41a8f37 Address Review comments 2026-06-23 22:08:06 +05:30
Akshat Agrawal f68fb697f7 fix(nan): fix NAN pairing NIK/NIRA exchange and verification
Register esp_nan_verify_nira, cache NIRA for publish frames, send own_nik
in pairing follow-up, and complete pairing only after peer NIK is stored.
2026-06-23 22:08:06 +05:30
Akshat Agrawal 2a8c1b5b24 fix(nan): Add NDP Setup timeout at the publisher side
- fix PASN initiator pmksa_cache_get() usage with the extra argument
- Add attributes to secured NDP frames according to Specs
- Resolve M2 MIC verification failure in secured datapath
2026-06-23 22:08:06 +05:30
Alexey Lapshin 406bd2393e fix(ci): suppress GNU static analyzer warnings 2026-06-15 18:53:21 +07:00
Jiang Jiang Jian c73c20a61f Merge branch 'bugfix/update_supplicant_nist_api' into 'master'
fix(wpa_supplicant): migrate aes_wrap to PSA NIST-KW API

Closes IDFGH-17750

See merge request espressif/esp-idf!49091
2026-06-05 14:41:01 +08:00
Kapil Gupta f652f629fe Merge branch 'bugfix/ft_igtk_installation' into 'master'
fix(esp_wifi): Correct igtk key installation in ft-psk mode

See merge request espressif/esp-idf!49048
2026-06-02 17:36:33 +05:30
Kapil Gupta e88879e8ef refactor(wpa_supplicant): add shared psa_import_aes_key helper
Centralize PSA AES key import used by ECB, CBC, CTR, CCM, CMAC, and
NIST key-wrap paths in crypto_mbedtls.c.
2026-06-01 12:34:42 +05:30
Kapil Gupta 05f74a8355 fix(wpa_supplicant): migrate aes_wrap to PSA NIST-KW API
mbedTLS 3.x removed mbedtls_nist_kw_context; use psa_import_key and
mbedtls_nist_kw_wrap/unwrap with PSA key IDs instead.

Closes https://github.com/espressif/esp-idf/issues/18678
2026-06-01 12:22:08 +05:30
Kapil Gupta 2d6bac1e21 fix(esp_wifi): Correct igtk key installation in ft 2026-06-01 10:30:53 +05:30
Guillaume Souchere d670774f5c feat(esp_common): implement composable error code registration via link-time arrays
Refactor the esp_err_to_name() system to decouple esp_common from
higher-level components. Instead of a monolithic generated table,
each component registers its error codes into a dedicated linker
section (.esp_err_msg_table) via idf_define_esp_err_codes() in its
CMakeLists.txt.

New files:
- tools/err_codes_extract.py: extract ESP_ERR_* defines from headers to CSV
- tools/err_codes_to_c.py: generate C source placing entries into linker section
- tools/err_codes_to_rst.py: generate RST documentation from error codes
- tools/cmake/err_codes.cmake: CMake module providing idf_define_esp_err_codes()
- components/esp_common/include/esp_err_codes.h: esp_err_msg_t typedef
- components/esp_common/src/esp_err_to_name_new.c: new lookup using link-time array
- tools/test_apps/build_system/err_codes_check/: CI test app

Changes:
- Remove all optional component dependencies from esp_common/CMakeLists.txt
- Add .esp_err_msg_table section to all 5 linker scripts
- Register error codes in 18 components via idf_define_esp_err_codes()
- Add new scripts to .gitlab/ci/rules.yml build_check patterns
- use new scripts to generate doc and add CI validation
- Update esp_err.rst to add description of composable code registration
2026-05-28 09:53:32 +02:00
Shreyas Sheth 41b4d70ad4 feat(esp_wifi): Add support for multiconfig support for DPP 2026-05-25 13:57:28 +08:00
Shreyas Sheth 958c7bef43 feat(esp_wifi): Harden dpp code and add improvements for dpp 2026-05-25 13:57:28 +08:00
Shreyas Sheth 2d3c11b277 fix(esp_wifi): Fix ci pipeline for random mac feature 2026-05-25 11:22:45 +08:00
JackandCursor 4786ab4d14 docs(wifi): add Chinese translation for MAC randomization
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-25 11:22:45 +08:00
Aditi 18cbdbf2b1 feat(esp_wifi): Add improvements for privacy extension
1) Add support for MAC randomization in Active scan and connect
  2) Add support for randomizaton of sequence numbers
  3) Add support for randomization of dialog token for GAS frames
2026-05-25 11:22:45 +08:00