Blame SOURCES/macsec-0012-mka-Fix-getting-capabilities-from-the-driver.patch

6c9f0c
From 088d53dd15b14a1868b70fd0b8d695ac6b68f642 Mon Sep 17 00:00:00 2001
6c9f0c
Message-Id: <088d53dd15b14a1868b70fd0b8d695ac6b68f642.1488376601.git.dcaratti@redhat.com>
6c9f0c
From: Sabrina Dubroca <sd@queasysnail.net>
6c9f0c
Date: Tue, 15 Nov 2016 18:06:23 +0100
6c9f0c
Subject: [PATCH] mka: Fix getting capabilities from the driver
6c9f0c
6c9f0c
In commit a25e4efc9e428d968e83398bd8c9c94698ba5851 ('mka: Add driver op
6c9f0c
to get macsec capabilities') I added some code to check the driver's
6c9f0c
capabilities. This commit has two problems:
6c9f0c
 - wrong enum type set in kay->macsec_confidentiality
6c9f0c
 - ignores that drivers could report MACSEC_CAP_NOT_IMPLEMENTED, in
6c9f0c
   which case the MKA would claim that MACsec is supported.
6c9f0c
6c9f0c
Fix this by interpreting MACSEC_CAP_NOT_IMPLEMENTED in the same way as a
6c9f0c
DO_NOT_SECURE policy, and set the correct value in
6c9f0c
kay->macsec_confidentiality.
6c9f0c
6c9f0c
Signed-off-by: Sabrina Dubroca <sd@queasysnail.net>
6c9f0c
---
6c9f0c
 src/pae/ieee802_1x_kay.c | 16 +++++++++-------
6c9f0c
 1 file changed, 9 insertions(+), 7 deletions(-)
6c9f0c
6c9f0c
diff --git a/src/pae/ieee802_1x_kay.c b/src/pae/ieee802_1x_kay.c
6c9f0c
index 63bbd13..2841b10 100644
6c9f0c
--- a/src/pae/ieee802_1x_kay.c
6c9f0c
+++ b/src/pae/ieee802_1x_kay.c
6c9f0c
@@ -3111,7 +3111,14 @@ ieee802_1x_kay_init(struct ieee802_1x_kay_ctx *ctx, enum macsec_policy policy,
6c9f0c
 
6c9f0c
 	dl_list_init(&kay->participant_list);
6c9f0c
 
6c9f0c
-	if (policy == DO_NOT_SECURE) {
6c9f0c
+	if (policy != DO_NOT_SECURE &&
6c9f0c
+	    secy_get_capability(kay, &kay->macsec_capable) < 0) {
6c9f0c
+		os_free(kay);
6c9f0c
+		return NULL;
6c9f0c
+	}
6c9f0c
+
6c9f0c
+	if (policy == DO_NOT_SECURE ||
6c9f0c
+	    kay->macsec_capable == MACSEC_CAP_NOT_IMPLEMENTED) {
6c9f0c
 		kay->macsec_capable = MACSEC_CAP_NOT_IMPLEMENTED;
6c9f0c
 		kay->macsec_desired = FALSE;
6c9f0c
 		kay->macsec_protect = FALSE;
6c9f0c
@@ -3120,11 +3127,6 @@ ieee802_1x_kay_init(struct ieee802_1x_kay_ctx *ctx, enum macsec_policy policy,
6c9f0c
 		kay->macsec_replay_window = 0;
6c9f0c
 		kay->macsec_confidentiality = CONFIDENTIALITY_NONE;
6c9f0c
 	} else {
6c9f0c
-		if (secy_get_capability(kay, &kay->macsec_capable) < 0) {
6c9f0c
-			os_free(kay);
6c9f0c
-			return NULL;
6c9f0c
-		}
6c9f0c
-
6c9f0c
 		kay->macsec_desired = TRUE;
6c9f0c
 		kay->macsec_protect = TRUE;
6c9f0c
 		kay->macsec_validate = Strict;
6c9f0c
@@ -3133,7 +3135,7 @@ ieee802_1x_kay_init(struct ieee802_1x_kay_ctx *ctx, enum macsec_policy policy,
6c9f0c
 		if (kay->macsec_capable >= MACSEC_CAP_INTEG_AND_CONF)
6c9f0c
 			kay->macsec_confidentiality = CONFIDENTIALITY_OFFSET_0;
6c9f0c
 		else
6c9f0c
-			kay->macsec_confidentiality = MACSEC_CAP_INTEGRITY;
6c9f0c
+			kay->macsec_confidentiality = CONFIDENTIALITY_NONE;
6c9f0c
 	}
6c9f0c
 
6c9f0c
 	wpa_printf(MSG_DEBUG, "KaY: state machine created");
6c9f0c
-- 
6c9f0c
2.7.4
6c9f0c