Commit Graph
1013 Commits
Author SHA1 Message Date
Jiang Jiang Jian 67b6ef3c1c Merge branch 'fix/owe_prevent_double_free' into 'master'
fix(wifi): Prevent double free in owe failure path

Closes SEC-261

See merge request espressif/esp-idf!51401
2026-08-10 14:18:26 +08:00
Sarvesh Bodakhe 94988c5aa4 fix(wpa_supplicant): accept NIK follow-up key descriptor with Key Type=0
iPhone (and hostap) set Key Type=0 in the pairing NIK follow-up Shared-Key
Descriptor (key_info=0x1340) since the NIK is not a pairwise key. We required
the pairwise bit and rejected the frame before decryption, so the NIK
exchange timed out and pairing was torn down. Require only the Encrypted
Key Data bit.
2026-08-06 17:25:35 +05:30
Sajia d9ba2da026 fix(wifi): Prevent double free in owe failure path 2026-07-31 12:33:11 +05:30
Akshat Agrawal 4f93a6777b Fix(NAN): fix Memory Corruption due to BIP encryption
- Set internal NAN params based on the user configurable Platform

 - On a secured NDP the responder could not derive keys
   (passphrase/credential mismatch); reject cleanly and
   fire ndp_terminated/ndp_confirm(REJECTED) on every
   teardown path so the host frees the NDP-ID.

 - Tear down the old NDP when the same peer re-initiates with
   a new M1, instead of rejecting and leaking the NDL.
2026-07-17 13:51:16 +05:30
Jiang Jiang Jian 23b3c3d4ca Merge branch 'bugfix/supplicant_crypto_code_correction' into 'master'
fix(wpa_supplicant): Correct some functions in crypto porting layer

See merge request espressif/esp-idf!50236
2026-07-17 14:12:59 +08:00
Kapil Gupta b3b955cd6e fix(wpa_supplicant): Correct some functions in crypto porting layer 2026-07-16 17:48:27 +08:00
Alexey Lapshin 1791325998 change(ci): enable -Werror=unused-but-set-variable 2026-07-16 10:54:36 +07:00
Shreyas Sheth 53e36b0ce4 fix(wpa_supplicant): Fix issues related to pmkid mismatch and eloop for dpp 2026-07-09 17:38:49 +05:30
Sarvesh Bodakhe 5bf61777b6 fix(wpa_supplicant): guard pbkdf2_sha256 for PSA-provided SHA-256
mbedtls 4.x is PSA-first: CONFIG_MBEDTLS_SHA256_C now maps to
PSA_WANT_ALG_SHA_256, and on ESP targets the hardware SHA accelerator
serves SHA-256 through PSA, leaving the legacy MBEDTLS_SHA256_C builtin
macro undefined. The inner guard on pbkdf2_sha256 was gating on bare
MBEDTLS_SHA256_C, so the function was compiled out and NAN ND-PMK
derivation (nan_derive_nd_pmk_from_passphrase) failed to link.

Guard on (MBEDTLS_SHA256_C || PSA_WANT_ALG_SHA_256) to match the idiom
already used elsewhere in the supplicant mbedtls port (tls_mbedtls.c),
covering both the legacy builtin and PSA-provided SHA-256.
2026-07-06 14:41:23 +05:30
Jiang Jiang Jian fa86d80f71 Merge branch 'feat/nan_gtk_support' into 'master'
feat(wifi_aware): advertise group data/mgmt protection (GTK/IGTK/BIGTK) and iOS compliance fixes

See merge request espressif/esp-idf!49800
2026-07-02 18:32:56 +08:00
Mahavir Jain bd567cf046 fix(wpa_supplicant): fix unused-but-set-variable warnings with GCC 16
GCC 16 raised the default level of -Wunused-but-set-variable and now
flags variables that are only used to update themselves. Remove the
'removed' counter in pmksa_cache_flush() (its only read was commented
out) and mark the EAP-FAST PAC entry counters as unused, since their
only read is inside wpa_printf(MSG_DEBUG, ...) which compiles to a
no-op when debug logging is disabled.
2026-07-02 07:55:13 +05:30
Sarvesh Bodakhe ebb9539d17 refactor(nan): use shared nan_key_type_t from esp_wifi_driver.h
The NAN key-type selectors are defined by the blob in esp_wifi_driver.h
(nan_key_type_t), which nan_i.h already includes. Add the group-integrity
key types NAN_KEY_ND_IGTK (3) and NAN_KEY_ND_BIGTK (4) there to match the
blob, and drop the duplicate host definitions from nan_i.h so a single
shared enum is used. Resolves the review request to declare these in
nan_key_type_t and avoids redefining the typedef.
2026-07-01 18:12:24 +05:30
akshat f4708595e6 bugfix(wifi): Clear Sta TX queue to prevent key 2 send failure
Also, Ensure correct return values for key 2 and key 4.
2026-06-30 14:56:15 +05:30
Nachiket Kukade 17ff376098 bugfix(nan): Fix hard/soft reset cases in NAN Pairing verification
- Update pairing complete API to record for peer
- Terminate NAN Datapaths using publish_id after receiving PASN M1
2026-06-30 12:58:44 +05:30
Sajia c18887b05c feat(nan): Add support for NAN Pairing Verification
- Add nira attr and verification for pasn auth frames
- Refine key clearing and pairing complete logic for pasn verify
- Add NIRA own-service resolution, cached NIK checks, and dynamic
  pairing IE construction for bootstrap vs verify paths.
- Replace NAN bootstrap events by private callbacks
2026-06-30 12:58:41 +05:30
Nachiket Kukade d36416980c feat(nan): Add aes_wrap/unwrap crypto callbacks
- Use crypto callbacks instead of calling internal API's
- Clean up of unused code, flags. Re-arrange functions
2026-06-23 22:08:06 +05:30
Akshat Agrawal c4b1e06057 Address review comments VNC 2026-06-23 22:08:06 +05:30
Akshat Agrawal 2c134933ec Address review comments and fix build errors 2026-06-23 22:08:06 +05:30
Akshat Agrawal 601faef85b fix(nan): Add service hash to NVS to maintain pairing states after reset 2026-06-23 22:08:06 +05:30
Akshat Agrawal afd5a13e71 Change the NIRA verification logic 2026-06-23 22:08:06 +05:30
Nachiket Kukade 7d6d7ead9a feat(nan): persist NIK/NPK credentials in NVS
Replace nik/nik_valid in wifi_nan_sync_config_t with reset_current_nvs_creds
and use_nvs_for_caching. On NAN start, load the saved own NIK and peer
credentials from NVS (or erase them when reset is requested); generate and
persist a fresh own NIK only when none is valid and caching is enabled.

PASN reuses the SAE module (PWE/crypto and the comeback-token mechanism),
so define CONFIG_SAE whenever SoftAP-SAE or PASN is enabled. This fixes the
undefined references to check_comeback_token()/auth_build_token_req() when
SOFTAP config is disabled.
2026-06-23 22:08:06 +05:30
Akshat Agrawal 92a41a8f37 Address Review comments 2026-06-23 22:08:06 +05:30
Akshat Agrawal f68fb697f7 fix(nan): fix NAN pairing NIK/NIRA exchange and verification
Register esp_nan_verify_nira, cache NIRA for publish frames, send own_nik
in pairing follow-up, and complete pairing only after peer NIK is stored.
2026-06-23 22:08:06 +05:30
Akshat Agrawal 2a8c1b5b24 fix(nan): Add NDP Setup timeout at the publisher side
- fix PASN initiator pmksa_cache_get() usage with the extra argument
- Add attributes to secured NDP frames according to Specs
- Resolve M2 MIC verification failure in secured datapath
2026-06-23 22:08:06 +05:30
Alexey Lapshin 406bd2393e fix(ci): suppress GNU static analyzer warnings 2026-06-15 18:53:21 +07:00
Jiang Jiang Jian c73c20a61f Merge branch 'bugfix/update_supplicant_nist_api' into 'master'
fix(wpa_supplicant): migrate aes_wrap to PSA NIST-KW API

Closes IDFGH-17750

See merge request espressif/esp-idf!49091
2026-06-05 14:41:01 +08:00
Kapil Gupta f652f629fe Merge branch 'bugfix/ft_igtk_installation' into 'master'
fix(esp_wifi): Correct igtk key installation in ft-psk mode

See merge request espressif/esp-idf!49048
2026-06-02 17:36:33 +05:30
Kapil Gupta e88879e8ef refactor(wpa_supplicant): add shared psa_import_aes_key helper
Centralize PSA AES key import used by ECB, CBC, CTR, CCM, CMAC, and
NIST key-wrap paths in crypto_mbedtls.c.
2026-06-01 12:34:42 +05:30
Kapil Gupta 05f74a8355 fix(wpa_supplicant): migrate aes_wrap to PSA NIST-KW API
mbedTLS 3.x removed mbedtls_nist_kw_context; use psa_import_key and
mbedtls_nist_kw_wrap/unwrap with PSA key IDs instead.

Closes https://github.com/espressif/esp-idf/issues/18678
2026-06-01 12:22:08 +05:30
Kapil Gupta 2d6bac1e21 fix(esp_wifi): Correct igtk key installation in ft 2026-06-01 10:30:53 +05:30
Guillaume Souchere d670774f5c feat(esp_common): implement composable error code registration via link-time arrays
Refactor the esp_err_to_name() system to decouple esp_common from
higher-level components. Instead of a monolithic generated table,
each component registers its error codes into a dedicated linker
section (.esp_err_msg_table) via idf_define_esp_err_codes() in its
CMakeLists.txt.

New files:
- tools/err_codes_extract.py: extract ESP_ERR_* defines from headers to CSV
- tools/err_codes_to_c.py: generate C source placing entries into linker section
- tools/err_codes_to_rst.py: generate RST documentation from error codes
- tools/cmake/err_codes.cmake: CMake module providing idf_define_esp_err_codes()
- components/esp_common/include/esp_err_codes.h: esp_err_msg_t typedef
- components/esp_common/src/esp_err_to_name_new.c: new lookup using link-time array
- tools/test_apps/build_system/err_codes_check/: CI test app

Changes:
- Remove all optional component dependencies from esp_common/CMakeLists.txt
- Add .esp_err_msg_table section to all 5 linker scripts
- Register error codes in 18 components via idf_define_esp_err_codes()
- Add new scripts to .gitlab/ci/rules.yml build_check patterns
- use new scripts to generate doc and add CI validation
- Update esp_err.rst to add description of composable code registration
2026-05-28 09:53:32 +02:00
Shreyas Sheth 41b4d70ad4 feat(esp_wifi): Add support for multiconfig support for DPP 2026-05-25 13:57:28 +08:00
Shreyas Sheth 958c7bef43 feat(esp_wifi): Harden dpp code and add improvements for dpp 2026-05-25 13:57:28 +08:00
Shreyas Sheth 2d3c11b277 fix(esp_wifi): Fix ci pipeline for random mac feature 2026-05-25 11:22:45 +08:00
JackandCursor 4786ab4d14 docs(wifi): add Chinese translation for MAC randomization
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-25 11:22:45 +08:00
Aditi 18cbdbf2b1 feat(esp_wifi): Add improvements for privacy extension
1) Add support for MAC randomization in Active scan and connect
  2) Add support for randomizaton of sequence numbers
  3) Add support for randomization of dialog token for GAS frames
2026-05-25 11:22:45 +08:00
0f8d4b74a0 feat(esp_wifi): NAN Pairing Improvements and bugfixes
- Route NAN pairing bootstrap via NPBA receive path
- extend datapath_req wait time to fit secured M1-M4 handshake
- Plug ND-PMK derived from KDK into NDP
- prefers paired-peer cached ND-PMK (from PASN pairing complete), when available
- carry ND-PMK metadata in pairing install callback
- Extend PASN key-installed callback payload to include role, mapped NDP CSID
  and derived ND-PMK so the NAN layer can populate paired-peer security cache.

Co-authored-by: Akshat Agrawal <akshat.agrawal@espressif.com>
Co-authored-by: Sarvesh Bodakhe <sarvesh.bodakhe@espressif.com>
2026-05-22 11:30:00 +05:30
9f361f478d feat(esp_wifi): Add NAN Pairing support
- Add container struct for internal extra params for follow-up
- Support for parsing Shared Key Desc in Pairing follow-up
- Implement NAN Pairing API's with required parameters
- In KeyData set cipher_ver to 0, Key Info to 0x12C8
  (AKM-defined | Pairwise | Install | ACK |
   Secure | Encrypted Key Data) for iOS compatibility
- Move NAN PASN into esp_nan_supplicant.c, move declarations
  to esp_private/esp_supp_nan.h
- Align PASN/ND-PMK derivation with hostap

Co-authored-by: Sajia <sajia.ali@espressif.com>
Co-authored-by: Akshat Agrawal <akshat.agrawal@espressif.com>
Co-authored-by: Sarvesh Bodakhe <sarvesh.bodakhe@espressif.com>
2026-05-22 13:01:51 +08:00
Nachiket Kukade e731ff3598 feat(wpa_supplicant): Add PASN Support to for NAN Pairing
- Create pasn module from upstream. Changes till 1a791e9c
- Add ecdh prime len api to MbedTLS port
- Integrate nan and pasn modules for PIN code method
- Fix KCK length and add auth timeout
- Add NAN Pairing PASN support
2026-05-22 13:01:51 +08:00
Jiang Jiang Jian 426295f132 Merge branch 'bugfix/allow_m1_for_pmk_cache' into 'master'
fix(esp_wifi): Allow M1 in pmk caching case

Closes WIFIBUG-1884

See merge request espressif/esp-idf!48403
2026-05-20 15:52:58 +08:00
Sarvesh Bodakhe 67aeac85e5 feat(wpa_supplicant): expose pbkdf2_sha256 for NAN crypto
Re-export the pbkdf2_sha256 declaration from sha256.h and add the
mbedTLS-backed implementation in crypto_mbedtls.c. NAN uses this for
ND-PMK derivation from a passphrase; the helper is also available for
any future caller that needs RFC 8018 PBKDF2 over SHA-256.
2026-05-19 10:48:13 +05:30
Kapil Gupta 4721a8849b fix(esp_wifi): Allow M1 in pmk caching case 2026-05-11 23:09:21 +05:30
Kapil Gupta 797059d239 fix(esp_wifi): Add support to bypass rng for bringup 2026-05-11 14:10:11 +05:30
Shreyas Sheth 0df4edc1d3 fix(wpa_supplicant): alter the check for eloop_is_running before wifi_task assertion 2026-05-08 13:32:45 +05:30
Shreyas Sheth d841c78cf0 fix(esp_wifi): Fix concurrency for flags between wpa3 and Wi-Fi task 2026-05-08 13:32:45 +05:30
Shreyas Sheth 697239e7e3 fix(wpa_supplicant): Address comments for concurrency between WiFi and WPA3 task 2026-05-08 13:32:45 +05:30
Shreyas Sheth b1f0e65e8b fix(wpa_supplicant): Fix concurrency issues between wpa3 and wifi task 2026-05-08 13:32:45 +05:30
Jiang Jiang Jian 8f498b1c56 Merge branch 'bugfix/concurrency_issues' into 'master'
fix(esp_wifi): Fixed some issues in esp_supplicant code

See merge request espressif/esp-idf!46630
2026-05-07 10:24:21 +08:00
Jiang Jiang Jian f7a5ef7ad5 Merge branch 'feature/softap_owe_support' into 'master'
Add support for OWE Only in SoftAP mode

Closes WIFI-4281 and IDFGH-12437

See merge request espressif/esp-idf!47341
2026-05-06 19:38:29 +08:00
Jiang Jiang Jian 43a7fdee43 Merge branch 'bugfix/roaming_app_issues' into 'master'
fix(esp_wifi): Fixed some issues in roaming app found using static analysis

Closes WIFIBUG-1836 and WIFIBUG-1842

See merge request espressif/esp-idf!47372
2026-05-06 15:50:55 +08:00