Received: by 2002:a05:6a10:a852:0:0:0:0 with SMTP id d18csp632768pxy; Wed, 5 May 2021 09:57:24 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwvaDAVkiKIUGwSBqsVs8FIlp6yuGzMUEsSMT4c7iHqZyQUAz1JGeHbVV/MotYJtdCEOffA X-Received: by 2002:a17:90a:7897:: with SMTP id x23mr12449074pjk.133.1620233843983; Wed, 05 May 2021 09:57:23 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1620233843; cv=none; d=google.com; s=arc-20160816; b=0kTcGCuBUxENlTKzwmgM+jVhT3Fl/BWVNWZB9BxygAYdTayyajXqWSaVTu2qR/YROt 9JrEhHxGGHKtPFX/Fg67r5aX9RJKljQeqQLldkJbY57GVyhUcc/q6lKb0EBn3bFAESBn EaHOiOd5Y7voRQodfFJ7cKYXCb38+f2EYJH+HkCnLwMMbe7E7z1Uk/fZj3HgpJR4wOc6 4hE6w2bcRuO37pIvRPXOcdnIP841ZGUmBKtFzVOju432N30Kcn469Iyj0AZZCHS2y7tG ou/GOHQZ7TRs8ORbJQgUQcj5WyZmArLh814zhkBbIWC+pfJhvemIjIGGWYh55IZsCj8Q 4GYw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=WCT/wUsy4P2JyvPokTiNxmu/wtWgrl7lE4INfqHBHMA=; b=z76xrhzOr3SXtZJdTrVcU3mRwycUdx5/q8ZOf7rbvHKd76kB7NQocaxwX7yTIhTzDD 8wWJyWM+kBneyohX1swfWS933uD/AO4yNiAVrHZSZZYaEXUXZfK5sZOVuAybdQHNBlNS vbahAQItkQbZ2s0t5iYKOvvzwOYEt3eeDQ4O5rCNSx7KhihIjZg//WczLzhA9ZxDIyq8 IU2XBjdAoJEQeFMliyOdumbdbsaIMJZq4rB/SFr0HK9jXfSlFiPXoku2cc0tzzgWYCfv 6vw5leEv/b4j85/xyMzNpSjXykHq6EW2hTtyDQ2yBTqllDc8yQcGbC569lD1cS9QrQc/ 3Itw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=S6qWMCUz; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id gi13si20483348pjb.56.2021.05.05.09.57.11; Wed, 05 May 2021 09:57:23 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=S6qWMCUz; spf=pass (google.com: domain of linux-wireless-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-wireless-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S235700AbhEEQ4Y (ORCPT + 99 others); Wed, 5 May 2021 12:56:24 -0400 Received: from mail.kernel.org ([198.145.29.99]:59428 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S235600AbhEEQvm (ORCPT ); Wed, 5 May 2021 12:51:42 -0400 Received: by mail.kernel.org (Postfix) with ESMTPSA id 081506197B; Wed, 5 May 2021 16:37:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1620232671; bh=7/yiiwyr0m7qxRY/F3kNmtS+61oV1lKmu4wBeIw884Y=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=S6qWMCUziKQ5VGff7bVj4cZF/fHv64LIozMgBADs6a4vhp+n8J2Gzm2cxuPdCCnQn nOfHHgc8hxUtMVZZViB+0BrOBDsx/x5qXBdBwBcwKihMXYYlekXh2uSADNzmLqZbbd N56I86DQ15kdjgVp9WQxMxIBsLALZQ735s2Uohnbq95K3r4jm9bh5JuxR5XarZZ8rM Gcyk28OnUkw1Xnr/hnhKk8OIPntiTDkZma0b3he4AQpkeVsY+YVppJ3unnNVFICGSU 04JneMX1ki94Kspf/T8gk1e86Jx6OmAhF7RlBK61yV8VPsnfyNgNHqVvcfcx+xBHdE DDYS7seiu80lA== From: Sasha Levin To: linux-kernel@vger.kernel.org, stable@vger.kernel.org Cc: David Bauer , Felix Fietkau , Sasha Levin , linux-wireless@vger.kernel.org, netdev@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-mediatek@lists.infradead.org Subject: [PATCH AUTOSEL 5.10 42/85] mt76: mt76x0: disable GTK offloading Date: Wed, 5 May 2021 12:36:05 -0400 Message-Id: <20210505163648.3462507-42-sashal@kernel.org> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20210505163648.3462507-1-sashal@kernel.org> References: <20210505163648.3462507-1-sashal@kernel.org> MIME-Version: 1.0 X-stable: review X-Patchwork-Hint: Ignore Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: linux-wireless@vger.kernel.org From: David Bauer [ Upstream commit 4b36cc6b390f18dbc59a45fb4141f90d7dfe2b23 ] When operating two VAP on a MT7610 with encryption (PSK2, SAE, OWE), only the first one to be created will transmit properly encrypteded frames. All subsequently created VAPs will sent out frames with the payload left unencrypted, breaking multicast traffic (ICMP6 NDP) and potentially disclosing information to a third party. Disable GTK offloading and encrypt these frames in software to circumvent this issue. THis only seems to be necessary on MT7610 chips, as MT7612 is not affected from our testing. Signed-off-by: David Bauer Signed-off-by: Felix Fietkau Signed-off-by: Sasha Levin --- drivers/net/wireless/mediatek/mt76/mt76x02_util.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/net/wireless/mediatek/mt76/mt76x02_util.c b/drivers/net/wireless/mediatek/mt76/mt76x02_util.c index 11b769af2f8f..0f191bd28417 100644 --- a/drivers/net/wireless/mediatek/mt76/mt76x02_util.c +++ b/drivers/net/wireless/mediatek/mt76/mt76x02_util.c @@ -446,6 +446,10 @@ int mt76x02_set_key(struct ieee80211_hw *hw, enum set_key_cmd cmd, !(key->flags & IEEE80211_KEY_FLAG_PAIRWISE)) return -EOPNOTSUPP; + /* MT76x0 GTK offloading does not work with more than one VIF */ + if (is_mt76x0(dev) && !(key->flags & IEEE80211_KEY_FLAG_PAIRWISE)) + return -EOPNOTSUPP; + msta = sta ? (struct mt76x02_sta *)sta->drv_priv : NULL; wcid = msta ? &msta->wcid : &mvif->group_wcid; -- 2.30.2