about summary refs log tree commit diff
path: root/debian
diff options
context:
space:
mode:
Diffstat (limited to 'debian')
-rw-r--r--debian/patches/Force-online-state-with-unmanaged-devices.patch22
-rw-r--r--debian/patches/series2
-rw-r--r--debian/patches/supplicant-add-BIP-interface-capability.patch117
-rw-r--r--debian/patches/supplicant-enable-WPA3-transition-mode-only-when-interfac.patch58
4 files changed, 11 insertions, 188 deletions
diff --git a/debian/patches/Force-online-state-with-unmanaged-devices.patch b/debian/patches/Force-online-state-with-unmanaged-devices.patch
index 4765891f..e6b80752 100644
--- a/debian/patches/Force-online-state-with-unmanaged-devices.patch
+++ b/debian/patches/Force-online-state-with-unmanaged-devices.patch
@@ -12,7 +12,7 @@ Bug-Debian: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512286
  1 file changed, 115 insertions(+)
 
 diff --git a/src/core/nm-manager.c b/src/core/nm-manager.c
-index 6c73d23..9a73a16 100644
+index 5215369..462b887 100644
 --- a/src/core/nm-manager.c
 +++ b/src/core/nm-manager.c
 @@ -51,6 +51,8 @@
@@ -24,7 +24,7 @@ index 6c73d23..9a73a16 100644
  /*****************************************************************************/
  
  typedef struct {
-@@ -186,6 +188,10 @@ typedef struct {
+@@ -191,6 +193,10 @@ typedef struct {
      GFileMonitor *fw_monitor;
      guint         fw_changed_id;
  
@@ -35,7 +35,7 @@ index 6c73d23..9a73a16 100644
      guint timestamp_update_id;
  
      guint devices_inited_id;
-@@ -1477,6 +1483,27 @@ find_best_device_state(NMManager *manager)
+@@ -1491,6 +1497,27 @@ find_best_device_state(NMManager *manager)
      return best_state;
  }
  
@@ -63,7 +63,7 @@ index 6c73d23..9a73a16 100644
  static void
  nm_manager_update_metered(NMManager *self)
  {
-@@ -1523,6 +1550,9 @@ nm_manager_update_state(NMManager *self)
+@@ -1537,6 +1564,9 @@ nm_manager_update_state(NMManager *self)
      else
          new_state = find_best_device_state(self);
  
@@ -73,7 +73,7 @@ index 6c73d23..9a73a16 100644
      if (new_state >= NM_STATE_CONNECTED_LOCAL && priv->connectivity_state == NM_CONNECTIVITY_FULL) {
          new_state = NM_STATE_CONNECTED_GLOBAL;
      }
-@@ -6673,6 +6703,62 @@ impl_manager_get_logging(NMDBusObject                      *obj,
+@@ -6872,6 +6902,62 @@ impl_manager_get_logging(NMDBusObject                      *obj,
          g_variant_new("(ss)", nm_logging_level_to_string(), nm_logging_domains_to_string()));
  }
  
@@ -136,7 +136,7 @@ index 6c73d23..9a73a16 100644
  typedef struct {
      NMManager             *self;
      GDBusMethodInvocation *context;
-@@ -6987,6 +7073,9 @@ nm_manager_start(NMManager *self, GError **error)
+@@ -7182,6 +7268,9 @@ nm_manager_start(NMManager *self, GError **error)
      nm_clear_g_source(&priv->devices_inited_id);
      priv->devices_inited_id = g_idle_add_full(G_PRIORITY_LOW + 10, devices_inited_cb, self, NULL);
  
@@ -146,7 +146,7 @@ index 6c73d23..9a73a16 100644
      return TRUE;
  }
  
-@@ -7984,6 +8073,22 @@ nm_manager_init(NMManager *self)
+@@ -8035,6 +8124,22 @@ nm_manager_init(NMManager *self)
          _LOGW(LOGD_CORE, "failed to monitor kernel firmware directory '%s'.", KERNEL_FIRMWARE_DIR);
      }
  
@@ -166,10 +166,10 @@ index 6c73d23..9a73a16 100644
 +                    IFUPDOWN_STATE_FILE);
 +    }
 +
-     /* Update timestamps in active connections */
-     priv->timestamp_update_id =
-         g_timeout_add_seconds(300,
-@@ -8269,6 +8374,16 @@ dispose(GObject *object)
+     priv->metered       = NM_METERED_UNKNOWN;
+     priv->sleep_devices = g_hash_table_new(nm_direct_hash, NULL);
+ }
+@@ -8317,6 +8422,16 @@ dispose(GObject *object)
          g_clear_object(&priv->fw_monitor);
      }
  
diff --git a/debian/patches/series b/debian/patches/series
index c61b47cb..a2d7e06d 100644
--- a/debian/patches/series
+++ b/debian/patches/series
@@ -1,3 +1 @@
 Force-online-state-with-unmanaged-devices.patch
-supplicant-add-BIP-interface-capability.patch
-supplicant-enable-WPA3-transition-mode-only-when-interfac.patch
diff --git a/debian/patches/supplicant-add-BIP-interface-capability.patch b/debian/patches/supplicant-add-BIP-interface-capability.patch
deleted file mode 100644
index e1cc05e2..00000000
--- a/debian/patches/supplicant-add-BIP-interface-capability.patch
+++ /dev/null
@@ -1,117 +0,0 @@
-From: Beniamino Galvani <bgalvani@redhat.com>
-Date: Fri, 1 Apr 2022 15:32:34 +0200
-Subject: supplicant: add BIP interface capability
-
-Introduce a new capability indicating whether the interface supports
-any of the BIP ciphers that can be used for 802.11w (PMF).
-
-(cherry picked from commit cd1e0193abcf26f523bd52d83af5aab086ceaa92)
-(cherry picked from commit 55ee796c3b14cb6bb7ff4916d6580202a95a00d1)
----
- src/core/supplicant/nm-supplicant-interface.c | 28 +++++++++++++++++++++++++--
- src/core/supplicant/nm-supplicant-types.h     |  4 ++++
- 2 files changed, 30 insertions(+), 2 deletions(-)
-
-diff --git a/src/core/supplicant/nm-supplicant-interface.c b/src/core/supplicant/nm-supplicant-interface.c
-index d827614..e502ae8 100644
---- a/src/core/supplicant/nm-supplicant-interface.c
-+++ b/src/core/supplicant/nm-supplicant-interface.c
-@@ -1225,8 +1225,10 @@ parse_capabilities(NMSupplicantInterface *self, GVariant *capabilities)
-     const guint32                 old_max_scan_ssids   = priv->max_scan_ssids;
-     gboolean                      have_ft              = FALSE;
-     gboolean                      have_sae             = FALSE;
-+    gboolean                      have_bip             = FALSE;
-     gint32                        max_scan_ssids;
-     const char                  **array;
-+    guint                         i;
- 
-     nm_assert(capabilities && g_variant_is_of_type(capabilities, G_VARIANT_TYPE_VARDICT));
- 
-@@ -1236,12 +1238,28 @@ parse_capabilities(NMSupplicantInterface *self, GVariant *capabilities)
-         g_free(array);
-     }
- 
-+    if (g_variant_lookup(capabilities, "GroupMgmt", "^a&s", &array)) {
-+        for (i = 0; array[i]; i++) {
-+            if (NM_IN_STRSET(array[i],
-+                             "aes-128-cmac",
-+                             "bip-gmac-128",
-+                             "bip-gmac-256",
-+                             "bip-cmac-256")) {
-+                have_bip = TRUE;
-+                break;
-+            }
-+        }
-+    }
-+
-     priv->iface_capabilities = NM_SUPPL_CAP_MASK_SET(priv->iface_capabilities,
-                                                      NM_SUPPL_CAP_TYPE_FT,
-                                                      have_ft ? NM_TERNARY_TRUE : NM_TERNARY_FALSE);
-     priv->iface_capabilities = NM_SUPPL_CAP_MASK_SET(priv->iface_capabilities,
-                                                      NM_SUPPL_CAP_TYPE_SAE,
-                                                      have_sae ? NM_TERNARY_TRUE : NM_TERNARY_FALSE);
-+    priv->iface_capabilities = NM_SUPPL_CAP_MASK_SET(priv->iface_capabilities,
-+                                                     NM_SUPPL_CAP_TYPE_BIP,
-+                                                     have_bip ? NM_TERNARY_TRUE : NM_TERNARY_FALSE);
- 
-     if (g_variant_lookup(capabilities, "Modes", "^a&s", &array)) {
-         /* Setting p2p_capable might toggle _prop_p2p_available_get(). However,
-@@ -1317,10 +1335,12 @@ _starting_check_ready(NMSupplicantInterface *self)
-           " AP%c"
-           " FT%c"
-           " SAE%c"
-+          " BIP%c"
-           "",
-           NM_SUPPL_CAP_TO_CHAR(priv->iface_capabilities, NM_SUPPL_CAP_TYPE_AP),
-           NM_SUPPL_CAP_TO_CHAR(priv->iface_capabilities, NM_SUPPL_CAP_TYPE_FT),
--          NM_SUPPL_CAP_TO_CHAR(priv->iface_capabilities, NM_SUPPL_CAP_TYPE_SAE));
-+          NM_SUPPL_CAP_TO_CHAR(priv->iface_capabilities, NM_SUPPL_CAP_TYPE_SAE),
-+          NM_SUPPL_CAP_TO_CHAR(priv->iface_capabilities, NM_SUPPL_CAP_TYPE_BIP));
- 
-     /* Other global properties are set in constructed() because they don't
-      * depend on interface capabilities. */
-@@ -1362,6 +1382,7 @@ _get_capability(NMSupplicantInterfacePrivate *priv, NMSupplCapType type)
-         }
-         break;
-     case NM_SUPPL_CAP_TYPE_SAE:
-+    case NM_SUPPL_CAP_TYPE_BIP:
-         nm_assert(NM_SUPPL_CAP_MASK_GET(priv->global_capabilities, type) == NM_TERNARY_DEFAULT);
-         value = NM_SUPPL_CAP_MASK_GET(priv->iface_capabilities, type);
-         break;
-@@ -1395,10 +1416,13 @@ nm_supplicant_interface_get_capabilities(NMSupplicantInterface *self)
-     caps = NM_SUPPL_CAP_MASK_SET(caps,
-                                  NM_SUPPL_CAP_TYPE_SAE,
-                                  _get_capability(priv, NM_SUPPL_CAP_TYPE_SAE));
-+    caps = NM_SUPPL_CAP_MASK_SET(caps,
-+                                 NM_SUPPL_CAP_TYPE_BIP,
-+                                 _get_capability(priv, NM_SUPPL_CAP_TYPE_BIP));
- 
-     nm_assert(!NM_FLAGS_ANY(priv->iface_capabilities,
-                             ~(NM_SUPPL_CAP_MASK_T_AP_MASK | NM_SUPPL_CAP_MASK_T_FT_MASK
--                              | NM_SUPPL_CAP_MASK_T_SAE_MASK)));
-+                              | NM_SUPPL_CAP_MASK_T_SAE_MASK | NM_SUPPL_CAP_MASK_T_BIP_MASK)));
- 
- #if NM_MORE_ASSERTS > 10
-     {
-diff --git a/src/core/supplicant/nm-supplicant-types.h b/src/core/supplicant/nm-supplicant-types.h
-index d5cf1bf..8904372 100644
---- a/src/core/supplicant/nm-supplicant-types.h
-+++ b/src/core/supplicant/nm-supplicant-types.h
-@@ -48,6 +48,9 @@ typedef enum {
-     NM_SUPPL_CAP_TYPE_FAST,
-     NM_SUPPL_CAP_TYPE_WFD,
-     NM_SUPPL_CAP_TYPE_SUITEB192,
-+    NM_SUPPL_CAP_TYPE_BIP,
-+    /* Note: if you're adding a capability here, log its presence at the
-+     * bottom of _dbus_get_capabilities_cb(). */
-     _NM_SUPPL_CAP_TYPE_NUM,
- } NMSupplCapType;
- 
-@@ -75,6 +78,7 @@ typedef enum {
-     _NM_SUPPL_CAP_MASK_DEFINE(FT),
-     _NM_SUPPL_CAP_MASK_DEFINE(SAE),
-     _NM_SUPPL_CAP_MASK_DEFINE(SHA384),
-+    _NM_SUPPL_CAP_MASK_DEFINE(BIP),
- #undef _NM_SUPPL_CAP_MASK_DEFINE
- } NMSupplCapMask;
- 
diff --git a/debian/patches/supplicant-enable-WPA3-transition-mode-only-when-interfac.patch b/debian/patches/supplicant-enable-WPA3-transition-mode-only-when-interfac.patch
deleted file mode 100644
index 2e79268b..00000000
--- a/debian/patches/supplicant-enable-WPA3-transition-mode-only-when-interfac.patch
+++ /dev/null
@@ -1,58 +0,0 @@
-From: Beniamino Galvani <bgalvani@redhat.com>
-Date: Fri, 1 Apr 2022 15:49:13 +0200
-Subject: supplicant: enable WPA3 transition mode only when interface supports
- PMF
-
-We have some reports of APs that advertise WPA2/WPA3 with
-MFP-required=0/MFP-capable=0, and reject the association when the
-client doesn't support 802.11w.
-
-According to WPA3_Specification_v3.0 section 2.3, when operating in
-WPA3-Personal transition mode a STA:
-
-- should allow AKM suite selector: 00-0F-AC:6 (WPA-PSK-SHA256) to be
-  selected for an association;
-
-- shall negotiate PMF when associating to an AP using SAE.
-
-The first is guaranteed by capability PMF; the second by checking that
-the interface supports BIP ciphers suitable for PMF.
-
-https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/issues/964
-https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003907
-(cherry picked from commit 1a7db1d7f712d7696f64b089011bc45fc86e7924)
-(cherry picked from commit 4dbf7778acef65fb7f5258e5b69d321bc79a490e)
----
- src/core/supplicant/nm-supplicant-config.c | 19 ++++++++++++++++++-
- 1 file changed, 18 insertions(+), 1 deletion(-)
-
-diff --git a/src/core/supplicant/nm-supplicant-config.c b/src/core/supplicant/nm-supplicant-config.c
-index 96c2357..8626042 100644
---- a/src/core/supplicant/nm-supplicant-config.c
-+++ b/src/core/supplicant/nm-supplicant-config.c
-@@ -854,7 +854,24 @@ nm_supplicant_config_add_setting_wireless_security(NMSupplicantConfig
-             g_string_append(key_mgmt_conf, " WPA-PSK-SHA256");
-         if (_get_capability(priv, NM_SUPPL_CAP_TYPE_FT))
-             g_string_append(key_mgmt_conf, " FT-PSK");
--        if (_get_capability(priv, NM_SUPPL_CAP_TYPE_SAE)) {
-+
-+        /* For NM "key-mgmt=wpa-psk" doesn't strictly mean WPA1/wPA2 only,
-+         * but also allows WPA3 (SAE), so that existing connections can
-+         * benefit from the improved security when the AP gets upgraded.
-+         *
-+         * According to WPA3_Specification_v3.0 section 2.3, when operating
-+         * in WPA3-Personal transition mode a STA:
-+         *
-+         * - should allow AKM suite selector: 00-0F-AC:6 (WPA-PSK-SHA256) to
-+         *   be selected for an association;
-+         * - shall negotiate PMF when associating to an AP using SAE.
-+         *
-+         * Those conditions are met when the interface has capabilities
-+         * SAE, PMF, BIP.
-+         */
-+        if (_get_capability(priv, NM_SUPPL_CAP_TYPE_SAE)
-+            && _get_capability(priv, NM_SUPPL_CAP_TYPE_PMF)
-+            && _get_capability(priv, NM_SUPPL_CAP_TYPE_BIP)) {
-             g_string_append(key_mgmt_conf, " SAE");
-             if (_get_capability(priv, NM_SUPPL_CAP_TYPE_FT))
-                 g_string_append(key_mgmt_conf, " FT-SAE");