summary refs log tree commit diff
path: root/src/core
diff options
context:
space:
mode:
Diffstat (limited to 'src/core')
-rw-r--r--src/core/devices/nm-device-bond.c6
-rw-r--r--src/core/devices/nm-device-infiniband.c2
-rw-r--r--src/core/devices/nm-device-macsec.c5
-rw-r--r--src/core/devices/nm-device-private.h6
-rw-r--r--src/core/devices/nm-device-vrf.c2
-rw-r--r--src/core/devices/nm-device-wpan.c4
-rw-r--r--src/core/devices/nm-device.c31
-rw-r--r--src/core/devices/ovs/nm-device-ovs-interface.c2
-rw-r--r--src/core/devices/team/nm-device-team.c4
-rw-r--r--src/core/devices/wifi/nm-device-olpc-mesh.c2
-rw-r--r--src/core/devices/wifi/nm-device-wifi.c4
-rw-r--r--src/core/devices/wwan/nm-modem-broadband.c4
-rw-r--r--src/core/dhcp/nm-dhcp-helper.c2
-rw-r--r--src/core/ndisc/nm-ndisc.c8
-rw-r--r--src/core/nm-core-utils.c35
-rw-r--r--src/core/nm-netns.c5
-rw-r--r--src/core/supplicant/nm-supplicant-config.c14
17 files changed, 86 insertions, 50 deletions
diff --git a/src/core/devices/nm-device-bond.c b/src/core/devices/nm-device-bond.c
index 3e083de4..10765b60 100644
--- a/src/core/devices/nm-device-bond.c
+++ b/src/core/devices/nm-device-bond.c
@@ -492,7 +492,7 @@ act_stage1_prepare(NMDevice *device, NMDeviceStateReason *out_failure_reason)
     /* This is a workaround because netlink do not support ifname as primary */
     set_bond_attr_or_default(device, s_bond, NM_SETTING_BOND_OPTION_PRIMARY);
 
-    nm_device_bring_up(device, TRUE, NULL);
+    nm_device_bring_up(device);
 
     return ret;
 }
@@ -540,7 +540,7 @@ attach_port(NMDevice                  *device,
         success = nm_platform_link_enslave(nm_device_get_platform(device),
                                            nm_device_get_ip_ifindex(device),
                                            nm_device_get_ip_ifindex(port));
-        nm_device_bring_up(port, TRUE, NULL);
+        nm_device_bring_up(port);
 
         if (!success) {
             _LOGI(LOGD_BOND, "attaching bond port %s: failed", nm_device_get_ip_iface(port));
@@ -613,7 +613,7 @@ detach_port(NMDevice *device, NMDevice *port, gboolean configure)
          * other state is noticed by the now-released slave.
          */
         if (ifindex_slave > 0) {
-            if (!nm_device_bring_up(port, TRUE, NULL))
+            if (!nm_device_bring_up(port))
                 _LOGW(LOGD_BOND, "detached bond port could not be brought up.");
         }
     } else {
diff --git a/src/core/devices/nm-device-infiniband.c b/src/core/devices/nm-device-infiniband.c
index aef61222..6b6aef86 100644
--- a/src/core/devices/nm-device-infiniband.c
+++ b/src/core/devices/nm-device-infiniband.c
@@ -89,7 +89,7 @@ act_stage1_prepare(NMDevice *device, NMDeviceStateReason *out_failure_reason)
     ok = nm_platform_sysctl_set(nm_device_get_platform(device),
                                 NMP_SYSCTL_PATHID_NETDIR(dirfd, ifname_verified, "mode"),
                                 transport_mode);
-    nm_device_bring_up(device, TRUE, NULL);
+    nm_device_bring_up(device);
 
     if (!ok) {
         NM_SET_OUT(out_failure_reason, NM_DEVICE_STATE_REASON_CONFIG_FAILED);
diff --git a/src/core/devices/nm-device-macsec.c b/src/core/devices/nm-device-macsec.c
index 5cc0b8da..5b1f5fdc 100644
--- a/src/core/devices/nm-device-macsec.c
+++ b/src/core/devices/nm-device-macsec.c
@@ -187,8 +187,7 @@ update_properties(NMDevice *device)
 
     g_object_freeze_notify((GObject *) device);
 
-    if (priv->props.parent_ifindex != props->parent_ifindex)
-        nm_device_parent_set_ifindex(device, props->parent_ifindex);
+    nm_device_parent_set_ifindex(device, plink->parent);
 
 #define CHECK_PROPERTY_CHANGED(field, prop)      \
     G_STMT_START                                 \
@@ -402,7 +401,7 @@ supplicant_iface_state_is_completed(NMDeviceMacsec *self, NMSupplicantInterfaceS
         nm_clear_g_source(&priv->supplicant.lnk_timeout_id);
         nm_clear_g_source(&priv->supplicant.con_timeout_id);
 
-        nm_device_bring_up(NM_DEVICE(self), TRUE, NULL);
+        nm_device_bring_up(NM_DEVICE(self));
 
         /* If this is the initial association during device activation,
          * schedule the next activation stage.
diff --git a/src/core/devices/nm-device-private.h b/src/core/devices/nm-device-private.h
index 31424d5c..c597e052 100644
--- a/src/core/devices/nm-device-private.h
+++ b/src/core/devices/nm-device-private.h
@@ -37,7 +37,11 @@ gboolean nm_device_set_ip_ifindex(NMDevice *self, int ifindex);
 
 gboolean nm_device_set_ip_iface(NMDevice *self, const char *iface);
 
-gboolean nm_device_bring_up(NMDevice *self, gboolean wait, gboolean *no_firmware);
+gboolean nm_device_bring_up(NMDevice *self);
+gboolean nm_device_bring_up_full(NMDevice *self,
+                                 gboolean  block,
+                                 gboolean  update_carrier,
+                                 gboolean *no_firmware);
 
 void nm_device_take_down(NMDevice *self, gboolean block);
 
diff --git a/src/core/devices/nm-device-vrf.c b/src/core/devices/nm-device-vrf.c
index 2aef0e3d..91eb195a 100644
--- a/src/core/devices/nm-device-vrf.c
+++ b/src/core/devices/nm-device-vrf.c
@@ -226,7 +226,7 @@ attach_port(NMDevice                  *device,
         success = nm_platform_link_enslave(nm_device_get_platform(device),
                                            nm_device_get_ip_ifindex(device),
                                            nm_device_get_ip_ifindex(port));
-        nm_device_bring_up(port, TRUE, NULL);
+        nm_device_bring_up(port);
 
         if (!success)
             return FALSE;
diff --git a/src/core/devices/nm-device-wpan.c b/src/core/devices/nm-device-wpan.c
index f7b712ea..ecb5ee23 100644
--- a/src/core/devices/nm-device-wpan.c
+++ b/src/core/devices/nm-device-wpan.c
@@ -176,10 +176,10 @@ act_stage1_prepare(NMDevice *device, NMDeviceStateReason *out_failure_reason)
     ret = NM_ACT_STAGE_RETURN_SUCCESS;
 
 out:
-    nm_device_bring_up(device, TRUE, NULL);
+    nm_device_bring_up(device);
 
     if (lowpan_device)
-        nm_device_bring_up(lowpan_device, TRUE, NULL);
+        nm_device_bring_up(lowpan_device);
 
     return ret;
 }
diff --git a/src/core/devices/nm-device.c b/src/core/devices/nm-device.c
index 2cda9b0d..059e31f2 100644
--- a/src/core/devices/nm-device.c
+++ b/src/core/devices/nm-device.c
@@ -4838,6 +4838,7 @@ get_ip_iface_identifier(NMDevice *self, NMUtilsIPv6IfaceId *out_iid)
     NMDevicePrivate      *priv     = NM_DEVICE_GET_PRIVATE(self);
     NMPlatform           *platform = nm_device_get_platform(self);
     const NMPlatformLink *pllink;
+    NMLinkType            link_type;
     const guint8         *hwaddr;
     guint8                pseudo_hwaddr[ETH_ALEN];
     gsize                 hwaddr_len;
@@ -4856,6 +4857,8 @@ get_ip_iface_identifier(NMDevice *self, NMUtilsIPv6IfaceId *out_iid)
     if (hwaddr_len <= 0)
         return FALSE;
 
+    link_type = pllink->type;
+
     if (pllink->type == NM_LINK_TYPE_6LOWPAN) {
         /* If the underlying IEEE 802.15.4 device has a short address we generate
          * a "pseudo 48-bit address" that's to be used in the same fashion as a
@@ -4876,10 +4879,11 @@ get_ip_iface_identifier(NMDevice *self, NMUtilsIPv6IfaceId *out_iid)
 
             hwaddr     = pseudo_hwaddr;
             hwaddr_len = G_N_ELEMENTS(pseudo_hwaddr);
+            link_type  = NM_LINK_TYPE_ETHERNET;
         }
     }
 
-    success = nm_utils_get_ipv6_interface_identifier(pllink->type,
+    success = nm_utils_get_ipv6_interface_identifier(link_type,
                                                      hwaddr,
                                                      hwaddr_len,
                                                      priv->dev_id,
@@ -6828,7 +6832,7 @@ device_link_changed(gpointer user_data)
          * bring it up probably has failed because of the
          * invalid hardware address; try again.
          */
-        nm_device_bring_up(self, TRUE, NULL);
+        nm_device_bring_up(self);
         nm_device_queue_recheck_available(self,
                                           NM_DEVICE_STATE_REASON_NONE,
                                           NM_DEVICE_STATE_REASON_NONE);
@@ -9719,7 +9723,7 @@ activate_stage2_device_config(NMDevice *self)
     _routing_rules_sync(self, NM_TERNARY_TRUE);
 
     if (!nm_device_sys_iface_state_is_external_or_assume(self)) {
-        if (!nm_device_bring_up(self, FALSE, &no_firmware)) {
+        if (!nm_device_bring_up_full(self, FALSE, TRUE, &no_firmware)) {
             nm_device_state_changed(self,
                                     NM_DEVICE_STATE_FAILED,
                                     no_firmware ? NM_DEVICE_STATE_REASON_FIRMWARE_MISSING
@@ -13994,7 +13998,10 @@ carrier_detect_wait(NMDevice *self)
 }
 
 gboolean
-nm_device_bring_up(NMDevice *self, gboolean block, gboolean *no_firmware)
+nm_device_bring_up_full(NMDevice *self,
+                        gboolean  block,
+                        gboolean  update_carrier,
+                        gboolean *no_firmware)
 {
     gboolean             device_is_up = FALSE;
     NMDeviceCapabilities capabilities;
@@ -14021,8 +14028,8 @@ nm_device_bring_up(NMDevice *self, gboolean block, gboolean *no_firmware)
             return FALSE;
     }
 
-    /* Store carrier immediately. */
-    nm_device_set_carrier_from_platform(self);
+    if (update_carrier)
+        nm_device_set_carrier_from_platform(self);
 
     device_is_up = nm_device_is_up(self);
     if (block && !device_is_up) {
@@ -14061,6 +14068,12 @@ nm_device_bring_up(NMDevice *self, gboolean block, gboolean *no_firmware)
     return TRUE;
 }
 
+gboolean
+nm_device_bring_up(NMDevice *self)
+{
+    return nm_device_bring_up_full(self, TRUE, TRUE, NULL);
+}
+
 void
 nm_device_take_down(NMDevice *self, gboolean block)
 {
@@ -15814,7 +15827,7 @@ _set_state_full(NMDevice *self, NMDeviceState state, NMDeviceStateReason reason,
 
         if (priv->sys_iface_state == NM_DEVICE_SYS_IFACE_STATE_MANAGED) {
             if (old_state == NM_DEVICE_STATE_UNMANAGED || priv->firmware_missing) {
-                if (!nm_device_bring_up(self, TRUE, &no_firmware) && no_firmware)
+                if (!nm_device_bring_up_full(self, TRUE, FALSE, &no_firmware) && no_firmware)
                     _LOGW(LOGD_PLATFORM, "firmware may be missing.");
                 nm_device_set_firmware_missing(self, no_firmware ? TRUE : FALSE);
             }
@@ -16574,7 +16587,7 @@ handle_fail:
     }
 
     if (was_taken_down) {
-        if (!nm_device_bring_up(self, TRUE, NULL))
+        if (!nm_device_bring_up(self))
             return FALSE;
     }
 
@@ -17832,7 +17845,7 @@ dispose(GObject *object)
         priv->sriov.next = NULL;
     }
 
-    g_clear_object(&priv->l3cfg);
+    g_clear_object(&priv->l3cfg_);
     g_clear_object(&priv->l3ipdata_4.ip_config);
     g_clear_object(&priv->l3ipdata_6.ip_config);
 
diff --git a/src/core/devices/ovs/nm-device-ovs-interface.c b/src/core/devices/ovs/nm-device-ovs-interface.c
index 1f531a6f..711f65cb 100644
--- a/src/core/devices/ovs/nm-device-ovs-interface.c
+++ b/src/core/devices/ovs/nm-device-ovs-interface.c
@@ -132,7 +132,7 @@ link_changed(NMDevice *device, const NMPlatformLink *pllink)
             nm_device_devip_set_failed(device, AF_INET6, NM_DEVICE_STATE_REASON_CONFIG_FAILED);
             return;
         }
-        nm_device_bring_up(device, TRUE, NULL);
+        nm_device_bring_up(device);
 
         nm_device_devip_set_state(device, AF_INET, NM_DEVICE_IP_STATE_PENDING, NULL);
         nm_device_devip_set_state(device, AF_INET6, NM_DEVICE_IP_STATE_PENDING, NULL);
diff --git a/src/core/devices/team/nm-device-team.c b/src/core/devices/team/nm-device-team.c
index 4e073ddf..9eca008a 100644
--- a/src/core/devices/team/nm-device-team.c
+++ b/src/core/devices/team/nm-device-team.c
@@ -884,7 +884,7 @@ attach_port(NMDevice                  *device,
         success = nm_platform_link_enslave(nm_device_get_platform(device),
                                            nm_device_get_ip_ifindex(device),
                                            nm_device_get_ip_ifindex(port));
-        nm_device_bring_up(port, TRUE, NULL);
+        nm_device_bring_up(port);
 
         if (!success)
             return FALSE;
@@ -934,7 +934,7 @@ detach_port(NMDevice *device, NMDevice *port, gboolean configure)
          * IFF_UP), so we must bring it back up here to ensure carrier changes and
          * other state is noticed by the now-released port.
          */
-        if (!nm_device_bring_up(port, TRUE, NULL)) {
+        if (!nm_device_bring_up(port)) {
             _LOGW(LOGD_TEAM, "detached team port %s could not be brought up", port_iface);
         }
 
diff --git a/src/core/devices/wifi/nm-device-olpc-mesh.c b/src/core/devices/wifi/nm-device-olpc-mesh.c
index fd851ebc..4705f75c 100644
--- a/src/core/devices/wifi/nm-device-olpc-mesh.c
+++ b/src/core/devices/wifi/nm-device-olpc-mesh.c
@@ -198,7 +198,7 @@ act_stage2_config(NMDevice *device, NMDeviceStateReason *out_failure_reason)
                                         nm_device_get_ifindex(device),
                                         g_bytes_get_data(ssid, NULL),
                                         g_bytes_get_size(ssid));
-    nm_device_bring_up(NM_DEVICE(self), TRUE, NULL);
+    nm_device_bring_up(NM_DEVICE(self));
     if (!success) {
         _LOGW(LOGD_WIFI, "Unable to set the mesh ID");
         return NM_ACT_STAGE_RETURN_FAILURE;
diff --git a/src/core/devices/wifi/nm-device-wifi.c b/src/core/devices/wifi/nm-device-wifi.c
index 43798b85..8af974d0 100644
--- a/src/core/devices/wifi/nm-device-wifi.c
+++ b/src/core/devices/wifi/nm-device-wifi.c
@@ -960,7 +960,7 @@ deactivate(NMDevice *device)
         != _NM_802_11_MODE_INFRA) {
         nm_device_take_down(NM_DEVICE(self), TRUE);
         nm_platform_wifi_set_mode(nm_device_get_platform(device), ifindex, _NM_802_11_MODE_INFRA);
-        nm_device_bring_up(NM_DEVICE(self), TRUE, NULL);
+        nm_device_bring_up(NM_DEVICE(self));
     }
 
     if (priv->mode != _NM_802_11_MODE_INFRA) {
@@ -3586,7 +3586,7 @@ set_enabled(NMDevice *device, gboolean enabled)
         if (state != NM_DEVICE_STATE_UNAVAILABLE)
             _LOGW(LOGD_CORE, "not in expected unavailable state!");
 
-        if (!nm_device_bring_up(NM_DEVICE(self), TRUE, &no_firmware)) {
+        if (!nm_device_bring_up_full(NM_DEVICE(self), TRUE, TRUE, &no_firmware)) {
             _LOGD(LOGD_WIFI, "enable blocked by failure to bring device up");
 
             if (no_firmware)
diff --git a/src/core/devices/wwan/nm-modem-broadband.c b/src/core/devices/wwan/nm-modem-broadband.c
index 997fe727..db4fb29f 100644
--- a/src/core/devices/wwan/nm-modem-broadband.c
+++ b/src/core/devices/wwan/nm-modem-broadband.c
@@ -1123,8 +1123,8 @@ stage3_ip_config_start(NMModem *modem, int addr_family, NMModemIPMethod ip_metho
         address.plen = mm_bearer_ip_config_get_prefix(self->_priv.ipv6_config);
         if (address.plen <= 128) {
             if (IN6_IS_ADDR_LINKLOCAL(&address.address)) {
-                iid_data.id = ((guint64 *) (&address.address.s6_addr))[1];
-                iid         = &iid_data;
+                nm_utils_ipv6_interface_identifier_get_from_addr(&iid_data, &address.address);
+                iid = &iid_data;
             } else
                 do_auto = FALSE;
             nm_l3_config_data_add_address_6(l3cd, &address);
diff --git a/src/core/dhcp/nm-dhcp-helper.c b/src/core/dhcp/nm-dhcp-helper.c
index 78db617c..213d9496 100644
--- a/src/core/dhcp/nm-dhcp-helper.c
+++ b/src/core/dhcp/nm-dhcp-helper.c
@@ -252,7 +252,7 @@ do_notify:
     success = FALSE;
 
 out:
-    if (!g_dbus_connection_flush_sync(connection, NULL, &error_flush)) {
+    if (connection && !g_dbus_connection_flush_sync(connection, NULL, &error_flush)) {
         _LOGE("could not flush D-Bus connection: %s", error_flush->message);
         /* if we considered this a success so far, don't fail because of this. */
     }
diff --git a/src/core/ndisc/nm-ndisc.c b/src/core/ndisc/nm-ndisc.c
index 04b673e5..9a6038d4 100644
--- a/src/core/ndisc/nm-ndisc.c
+++ b/src/core/ndisc/nm-ndisc.c
@@ -1609,27 +1609,27 @@ calc_pre_expiry_rs_msec(NMNDisc *ndisc)
         _calc_pre_expiry_rs_msec_worker(
             &expiry_msec,
             priv->last_rs_msec,
-            g_array_index(rdata->addresses, NMNDiscAddress, 0).expiry_msec);
+            g_array_index(rdata->addresses, NMNDiscAddress, i).expiry_msec);
     }
 
     for (i = 0; i < rdata->routes->len; i++) {
         _calc_pre_expiry_rs_msec_worker(&expiry_msec,
                                         priv->last_rs_msec,
-                                        g_array_index(rdata->routes, NMNDiscRoute, 0).expiry_msec);
+                                        g_array_index(rdata->routes, NMNDiscRoute, i).expiry_msec);
     }
 
     for (i = 0; i < rdata->dns_servers->len; i++) {
         _calc_pre_expiry_rs_msec_worker(
             &expiry_msec,
             priv->last_rs_msec,
-            g_array_index(rdata->dns_servers, NMNDiscDNSServer, 0).expiry_msec);
+            g_array_index(rdata->dns_servers, NMNDiscDNSServer, i).expiry_msec);
     }
 
     for (i = 0; i < rdata->dns_domains->len; i++) {
         _calc_pre_expiry_rs_msec_worker(
             &expiry_msec,
             priv->last_rs_msec,
-            g_array_index(rdata->dns_domains, NMNDiscDNSDomain, 0).expiry_msec);
+            g_array_index(rdata->dns_domains, NMNDiscDNSDomain, i).expiry_msec);
     }
 
     return expiry_msec - solicit_retransmit_time_jitter(NM_NDISC_PRE_EXPIRY_TIME_MSEC);
diff --git a/src/core/nm-core-utils.c b/src/core/nm-core-utils.c
index 480e9b28..4aad9414 100644
--- a/src/core/nm-core-utils.c
+++ b/src/core/nm-core-utils.c
@@ -3265,25 +3265,32 @@ nm_utils_get_ipv6_interface_identifier(NMLinkType          link_type,
          * making sure to set the 'u' bit to 1.  The GUID is the lower 64 bits
          * of the IPoIB interface's hardware address.
          */
-        g_return_val_if_fail(hwaddr_len == INFINIBAND_ALEN, FALSE);
-        memcpy(out_iid->id_u8, hwaddr + INFINIBAND_ALEN - 8, 8);
-        out_iid->id_u8[0] |= 0x02;
-        return TRUE;
+        if (hwaddr_len == INFINIBAND_ALEN) {
+            memcpy(out_iid->id_u8, hwaddr + INFINIBAND_ALEN - 8, 8);
+            out_iid->id_u8[0] |= 0x02;
+            return TRUE;
+        }
+        break;
     case NM_LINK_TYPE_GRE:
         /* Hardware address is the network-endian IPv4 address */
-        g_return_val_if_fail(hwaddr_len == 4, FALSE);
-        addr              = *(guint32 *) hwaddr;
-        out_iid->id_u8[0] = get_gre_eui64_u_bit(addr);
-        out_iid->id_u8[1] = 0x00;
-        out_iid->id_u8[2] = 0x5E;
-        out_iid->id_u8[3] = 0xFE;
-        memcpy(out_iid->id_u8 + 4, &addr, 4);
-        return TRUE;
+        if (hwaddr_len == 4) {
+            addr              = unaligned_read_ne32(hwaddr);
+            out_iid->id_u8[0] = get_gre_eui64_u_bit(addr);
+            out_iid->id_u8[1] = 0x00;
+            out_iid->id_u8[2] = 0x5E;
+            out_iid->id_u8[3] = 0xFE;
+            memcpy(out_iid->id_u8 + 4, &addr, 4);
+            return TRUE;
+        }
+        break;
     case NM_LINK_TYPE_6LOWPAN:
         /* The hardware address is already 64-bit. This is the case for
          * IEEE 802.15.4 networks. */
-        memcpy(out_iid->id_u8, hwaddr, sizeof(out_iid->id_u8));
-        return TRUE;
+        if (hwaddr_len == sizeof(out_iid->id_u8)) {
+            memcpy(out_iid->id_u8, hwaddr, sizeof(out_iid->id_u8));
+            return TRUE;
+        }
+        break;
     default:
         if (hwaddr_len == ETH_ALEN) {
             /* Translate 48-bit MAC address to a 64-bit Modified EUI-64.  See
diff --git a/src/core/nm-netns.c b/src/core/nm-netns.c
index 5ee63152..859dbb21 100644
--- a/src/core/nm-netns.c
+++ b/src/core/nm-netns.c
@@ -129,13 +129,16 @@ NML3Cfg *
 nm_netns_l3cfg_get(NMNetns *self, int ifindex)
 {
     NMNetnsPrivate *priv;
+    L3CfgData      *l3cfg_data;
 
     g_return_val_if_fail(NM_IS_NETNS(self), NULL);
     g_return_val_if_fail(ifindex > 0, NULL);
 
     priv = NM_NETNS_GET_PRIVATE(self);
 
-    return g_hash_table_lookup(priv->l3cfgs, &ifindex);
+    l3cfg_data = g_hash_table_lookup(priv->l3cfgs, &ifindex);
+
+    return l3cfg_data ? l3cfg_data->l3cfg : NULL;
 }
 
 NML3Cfg *
diff --git a/src/core/supplicant/nm-supplicant-config.c b/src/core/supplicant/nm-supplicant-config.c
index 22c422a2..bd48ed92 100644
--- a/src/core/supplicant/nm-supplicant-config.c
+++ b/src/core/supplicant/nm-supplicant-config.c
@@ -403,6 +403,7 @@ nm_supplicant_config_add_setting_macsec(NMSupplicantConfig *self,
     const char *value;
     char        buf[32];
     int         port;
+    gsize       key_len;
 
     g_return_val_if_fail(NM_IS_SUPPLICANT_CONFIG(self), FALSE);
     g_return_val_if_fail(setting != NULL, FALSE);
@@ -446,7 +447,16 @@ nm_supplicant_config_add_setting_macsec(NMSupplicantConfig *self,
             return FALSE;
 
         value = nm_setting_macsec_get_mka_ckn(setting);
-        if (!value || !nm_utils_hexstr2bin_buf(value, FALSE, FALSE, NULL, buffer_ckn)) {
+        if (!value
+            || !nm_utils_hexstr2bin_full(value,
+                                         FALSE,
+                                         FALSE,
+                                         FALSE,
+                                         NULL,
+                                         0,
+                                         buffer_ckn,
+                                         G_N_ELEMENTS(buffer_ckn),
+                                         &key_len)) {
             g_set_error_literal(error,
                                 NM_SUPPLICANT_ERROR,
                                 NM_SUPPLICANT_ERROR_CONFIG,
@@ -456,7 +466,7 @@ nm_supplicant_config_add_setting_macsec(NMSupplicantConfig *self,
         if (!nm_supplicant_config_add_option(self,
                                              "mka_ckn",
                                              (char *) buffer_ckn,
-                                             sizeof(buffer_ckn),
+                                             key_len,
                                              value,
                                              error))
             return FALSE;