Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 5 Oct 2021 22:16:54 GMT
From:      Cy Schubert <cy@FreeBSD.org>
To:        src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org
Subject:   git: 0ab6ecd1dda7 - stable/13 - wpa: Fix EAP/PEAP MSCHAPv2 authentication SIGSEGV
Message-ID:  <202110052216.195MGsBr016770@gitrepo.freebsd.org>

next in thread | raw e-mail | index | archive | help
The branch stable/13 has been updated by cy:

URL: https://cgit.FreeBSD.org/src/commit/?id=0ab6ecd1dda7b6194b7aa09f70f9c6a7049708e4

commit 0ab6ecd1dda7b6194b7aa09f70f9c6a7049708e4
Author:     Cy Schubert <cy@FreeBSD.org>
AuthorDate: 2021-10-05 21:54:06 +0000
Commit:     Cy Schubert <cy@FreeBSD.org>
CommitDate: 2021-10-05 22:12:38 +0000

    wpa: Fix EAP/PEAP MSCHAPv2 authentication SIGSEGV
    
    25ecdc7d52770caf1c9b44b5ec11f468f6b636f3 (MFCed by
    13f32ff71eeb7213bb9f34bdfa88c7ccecf451bc) introduced a link error
    causing a SIGSEGV when using EAP/PEAP MSCHAPv2 authentication. It was
    subsequently addressed by c1d255d3ffdbe447de3ab875bf4e7d7accc5bfc5,
    discovered by build time link errors not experienced during testing of
    25ecdc7d52770caf1c9b44b5ec11f468f6b636f3. This commit MFCs a portion
    of c1d255d3ffdbe447de3ab875bf4e7d7accc5bfc5 addressing only the
    SIGSEGV. The rest of c1d255d3ffdbe447de3ab875bf4e7d7accc5bfc5 will
    be MFCed in November 2021.
    
    This is a direct commit to stable/13.
    
    PR:             258527
    Reported by:    Marek Zarychta <zarychtam@plan-b.pwste.edu.pl>
    Tested by:      Marek Zarychta <zarychtam@plan-b.pwste.edu.pl>
---
 usr.sbin/wpa/Makefile.crypto       | 1 +
 usr.sbin/wpa/Makefile.inc          | 5 +++--
 usr.sbin/wpa/hostapd/Makefile      | 2 --
 usr.sbin/wpa/src/ap/Makefile       | 9 +--------
 usr.sbin/wpa/src/common/Makefile   | 1 +
 usr.sbin/wpa/src/rsn_supp/Makefile | 4 ----
 6 files changed, 6 insertions(+), 16 deletions(-)

diff --git a/usr.sbin/wpa/Makefile.crypto b/usr.sbin/wpa/Makefile.crypto
index a65ee29e0ebe..2046c32d76ac 100644
--- a/usr.sbin/wpa/Makefile.crypto
+++ b/usr.sbin/wpa/Makefile.crypto
@@ -3,6 +3,7 @@
 .if ${MK_OPENSSL} != "no"
 LIBADD+=	ssl crypto
 CFLAGS+= -DCONFIG_SHA256
+CFLAGS+= -DCONFIG_ECC
 .else
 CFLAGS+=-DCONFIG_CRYPTO_INTERNAL
 CONFIG_INTERNAL_AES=y
diff --git a/usr.sbin/wpa/Makefile.inc b/usr.sbin/wpa/Makefile.inc
index ef94c7b312a9..49c7344e8957 100644
--- a/usr.sbin/wpa/Makefile.inc
+++ b/usr.sbin/wpa/Makefile.inc
@@ -40,8 +40,6 @@ CFLAGS+=-DCONFIG_IEEE80211AC
 CFLAGS+=-DCONFIG_IEEE80211N
 CFLAGS+=-DCONFIG_IEEE80211R
 CFLAGS+=-DCONFIG_IEEE80211W
-CFLAGS+=-DCONFIG_IEEE80211AX
-CFLAGS+=-DNEED_AP_MLME
 CFLAGS+=-DTLS_DEFAULT_CIPHERS=\"DEFAULT:!EXP:!LOW\"
 CFLAGS+=-DCONFIG_DEBUG_SYSLOG
 CFLAGS+=-DCONFIG_WPS
@@ -54,9 +52,12 @@ CFLAGS+=-DCONFIG_GAS
 CFLAGS+=-DCONFIG_PEERKEY
 CFLAGS+=-DCONFIG_PRIVSEP
 CFLAGS+=-DCONFIG_SMARTCARD
+CFLAGS+=-DCONFIG_TDLS
 CFLAGS+=-DCONFIG_TERMINATE_ONLASTIF
 CFLAGS+=-DCONFIG_TLS=openssl
 CFLAGS+=-DCONFIG_MATCH_IFACE
+CFLAGS+=-DCONFIG_PASN
+CFLAGS+=-DCONFIG_PTKSA_CACHE
 CFLAGS+=-DEAP_SERVER
 CFLAGS+=-DEAP_SERVER_GTC
 CFLAGS+=-DEAP_SERVER_IDENTITY
diff --git a/usr.sbin/wpa/hostapd/Makefile b/usr.sbin/wpa/hostapd/Makefile
index 1ae4481a863e..ce3b7d82fd69 100644
--- a/usr.sbin/wpa/hostapd/Makefile
+++ b/usr.sbin/wpa/hostapd/Makefile
@@ -26,8 +26,6 @@ FILES=	hostapd.conf hostapd.eap_user hostapd.wpa_psk
 
 CFLAGS+=-I${.CURDIR:H}/wpa_supplicant \
 	-I${WPA_DISTDIR}/src/eap_peer \
-	-DCONFIG_MBO \
-	-DCONFIG_RSN_PREAUTH \
 	-DHOSTAPD
 .if ${MK_INET6} != "no"
 CFLAGS+= -DCONFIG_IPV6
diff --git a/usr.sbin/wpa/src/ap/Makefile b/usr.sbin/wpa/src/ap/Makefile
index 77caf1ed8efe..b6d53b0d5dbb 100644
--- a/usr.sbin/wpa/src/ap/Makefile
+++ b/usr.sbin/wpa/src/ap/Makefile
@@ -12,7 +12,6 @@ INTERNALLIB=
 SRCS=	accounting.c \
 	ap_config.c \
 	ap_drv_ops.c \
-	ap_list.c \
 	ap_mlme.c \
 	authsrv.c \
 	beacon.c \
@@ -24,15 +23,11 @@ SRCS=	accounting.c \
 	gas_serv.c \
 	hostapd.c \
 	hs20.c \
-	hw_features.c \
-	ieee802_11.c \
 	ieee802_11_auth.c \
-	ieee802_11_he.c \
 	ieee802_11_ht.c \
 	ieee802_11_shared.c \
 	ieee802_11_vht.c \
 	ieee802_1x.c \
-	mbo_ap.c \
 	neighbor_db.c \
 	pmksa_cache_auth.c \
 	preauth_auth.c \
@@ -49,9 +44,7 @@ SRCS=	accounting.c \
 	wpa_auth_ie.c \
 	wps_hostapd.c
 
-CFLAGS+=-DCONFIG_MBO \
-	-DCONFIG_RSN_PREAUTH \
-	-DHOSTAPD
+CFLAGS+=-DHOSTAPD
 
 # We are only interested in includes at this point. Not libraries.
 LIBADD=
diff --git a/usr.sbin/wpa/src/common/Makefile b/usr.sbin/wpa/src/common/Makefile
index b415b926c207..99c4c04fb7fe 100644
--- a/usr.sbin/wpa/src/common/Makefile
+++ b/usr.sbin/wpa/src/common/Makefile
@@ -11,6 +11,7 @@ INTERNALLIB=
 
 SRCS=	cli.c \
 	ctrl_iface_common.c \
+	dragonfly.c \
 	gas.c \
 	hw_features_common.c \
 	ieee802_11_common.c \
diff --git a/usr.sbin/wpa/src/rsn_supp/Makefile b/usr.sbin/wpa/src/rsn_supp/Makefile
index 4d952c2204c4..3ffa1e524890 100644
--- a/usr.sbin/wpa/src/rsn_supp/Makefile
+++ b/usr.sbin/wpa/src/rsn_supp/Makefile
@@ -16,10 +16,6 @@ SRCS=	pmksa_cache.c \
 	wpa.c \
 	wpa_ie.c
 
-CFLAGS+=-DCONFIG_TDLS \
-	-DCONFIG_WNM \
-	-DIEEE8021X_EAPOL
-
 # We are only interested in includes at this point. Not libraries.
 LIBADD=
 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202110052216.195MGsBr016770>