mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
To: herbert@gondor.apana.org.au, davem@davemloft.net,
	johannes@sipsolutions.net, miriam.rachel.korenblit@intel.com
Cc: ilan.peer@intel.com, emmanuel.grumbach@intel.com,
	linux-crypto@vger.kernel.org, linux-wireless@vger.kernel.org,
	linux-kernel@vger.kernel.org,
	Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
Subject: [PATCH v2 3/5] wifi: iwlwifi: restore FIPS-disabled features with fips_exception
Date: Wed, 30 Sep 2026 14:08:26 +0200	[thread overview]
Message-ID: <20260930120829.383408-4-jtornosm@redhat.com> (raw)
In-Reply-To: <20260930120829.383408-1-jtornosm@redhat.com>

Commit 0636800c8ee1 ("wifi: iwlwifi: disable certain features
for fips_enabled") disabled multiple WiFi features under FIPS
mode because Intel firmware autonomously sends some management
frames without FIPS-validated integrity protection. This is
correct from a compliance standpoint but breaks WiFi connectivity
entirely on WPA3-SAE networks which mandate MFP.

When FIPS_EXCEPTION_WIFI_MFP is set via fips_exception boot
parameter, use fips_allows() to restore the following features
disabled by that commit:

In the mvm driver path (mvm/mac80211.c):
  - MFP_CAPABLE: required for WPA3-SAE association
  - Beacon Protection (full and client-only): integrity
    protection for beacons, handled by firmware

In the mld driver path (mld/mac80211.c):
  - Cipher suites and MFP_CAPABLE: required for WPA3-SAE
  - Beacon Protection: same as mvm path
  - MLO (Multi-Link Operation): disabled because it requires MFP

In iwl-nvm-parse.c (shared by both paths):
  - A-MSDU max sizes: reduced under FIPS, restored with exception
  - EHT/WiFi7 capabilities: disabled because EHT requires MFP
  - 6GHz channels: disabled because 6GHz requires WPA3/MFP

A warning is logged for both mvm and mld drivers when the
exception is active to ensure the known firmware limitation
is visible:
  "FIPS: MFP enabled with known firmware limitation"

WoWLAN remains disabled under FIPS regardless of the exception
flag in both mvm and mld paths. Unlike MFP where only some
management frames bypass host crypto, WoWLAN requires all
traffic to be handled by firmware crypto during suspend, as
the host CPU is not available for mac80211 software crypto.

Without fips_exception set, the behavior remains exactly as
commit 0636800c8ee1 implemented.

Signed-off-by: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
---
v2: complete the conditional FIPS disabling revert
v1: https://lore.kernel.org/all/20260629121213.597038-2-jtornosm@redhat.com/

 drivers/net/wireless/intel/iwlwifi/iwl-nvm-parse.c | 11 +++++++----
 drivers/net/wireless/intel/iwlwifi/mld/mac80211.c  |  7 +++++--
 drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c  |  9 ++++++---
 3 files changed, 18 insertions(+), 9 deletions(-)

diff --git a/drivers/net/wireless/intel/iwlwifi/iwl-nvm-parse.c b/drivers/net/wireless/intel/iwlwifi/iwl-nvm-parse.c
index 863d5e358152..ca565b4311bb 100644
--- a/drivers/net/wireless/intel/iwlwifi/iwl-nvm-parse.c
+++ b/drivers/net/wireless/intel/iwlwifi/iwl-nvm-parse.c
@@ -502,14 +502,16 @@ static void iwl_init_vht_hw_capab(struct iwl_trans *trans,
 	 */
 	switch (iwlwifi_mod_params.amsdu_size) {
 	case IWL_AMSDU_DEF:
-		if (trans->mac_cfg->mq_rx_supported && !fips_enabled)
+		if (trans->mac_cfg->mq_rx_supported &&
+		    fips_allows(FIPS_EXCEPTION_WIFI_MFP))
 			vht_cap->cap |=
 				IEEE80211_VHT_CAP_MAX_MPDU_LENGTH_11454;
 		else
 			vht_cap->cap |= IEEE80211_VHT_CAP_MAX_MPDU_LENGTH_3895;
 		break;
 	case IWL_AMSDU_2K:
-		if (trans->mac_cfg->mq_rx_supported && !fips_enabled)
+		if (trans->mac_cfg->mq_rx_supported &&
+		    fips_allows(FIPS_EXCEPTION_WIFI_MFP))
 			vht_cap->cap |=
 				IEEE80211_VHT_CAP_MAX_MPDU_LENGTH_11454;
 		else
@@ -886,7 +888,7 @@ iwl_nvm_fixup_sband_iftd(struct iwl_trans *trans,
 
 	/* EHT needs WPA3/MFP so cannot do it for fips_enabled */
 	if (!data->sku_cap_11be_enable || iwlwifi_mod_params.disable_11be ||
-	    fips_enabled)
+	    !fips_allows(FIPS_EXCEPTION_WIFI_MFP))
 		iftype_data->eht_cap.has_eht = false;
 
 	if (!data->sku_cap_11bn_enable || !iftype_data->eht_cap.has_eht)
@@ -1221,7 +1223,8 @@ static void iwl_init_sbands(struct iwl_trans *trans,
 	 * avoid spending time on scanning those channels and perhaps
 	 * even finding APs there that cannot be used.
 	 */
-	if (!fips_enabled && data->sku_cap_11ax_enable &&
+	if (fips_allows(FIPS_EXCEPTION_WIFI_MFP) &&
+	    data->sku_cap_11ax_enable &&
 	    !iwlwifi_mod_params.disable_11ax)
 		iwl_init_he_hw_capab(trans, data, sband, tx_chains, rx_chains,
 				     fw);
diff --git a/drivers/net/wireless/intel/iwlwifi/mld/mac80211.c b/drivers/net/wireless/intel/iwlwifi/mld/mac80211.c
index 3a4c8fda68d0..3ccbf1033160 100644
--- a/drivers/net/wireless/intel/iwlwifi/mld/mac80211.c
+++ b/drivers/net/wireless/intel/iwlwifi/mld/mac80211.c
@@ -167,7 +167,7 @@ static void iwl_mld_hw_set_security(struct iwl_mld *mld)
 		WLAN_CIPHER_SUITE_BIP_GMAC_256
 	};
 
-	if (fips_enabled)
+	if (!fips_allows(FIPS_EXCEPTION_WIFI_MFP))
 		return;
 
 	hw->wiphy->n_cipher_suites = ARRAY_SIZE(mld_ciphers);
@@ -176,6 +176,9 @@ static void iwl_mld_hw_set_security(struct iwl_mld *mld)
 	ieee80211_hw_set(hw, MFP_CAPABLE);
 	wiphy_ext_feature_set(hw->wiphy,
 			      NL80211_EXT_FEATURE_BEACON_PROTECTION);
+
+	if (fips_enabled)
+		IWL_WARN(mld, "FIPS: MFP enabled with known firmware limitation\n");
 }
 
 static void iwl_mld_hw_set_antennas(struct iwl_mld *mld)
@@ -344,7 +347,7 @@ static void iwl_mac_hw_set_wiphy(struct iwl_mld *mld)
 	if (mld->nvm_data->sku_cap_11be_enable &&
 	    !iwlwifi_mod_params.disable_11ax &&
 	    !iwlwifi_mod_params.disable_11be &&
-	    !fips_enabled)
+	    fips_allows(FIPS_EXCEPTION_WIFI_MFP))
 		wiphy->flags |= WIPHY_FLAG_SUPPORTS_MLO;
 
 	/* the firmware uses u8 for num of iterations, but 0xff is saved for
diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c b/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c
index 5bd246e37943..f6e20a07e329 100644
--- a/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c
+++ b/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c
@@ -462,8 +462,11 @@ int iwl_mvm_mac_setup_register(struct iwl_mvm *mvm)
 		IWL_ERR(mvm,
 			"iwlmvm doesn't allow to disable BT Coex, check bt_coex_active module parameter\n");
 
-	if (!fips_enabled)
+	if (fips_allows(FIPS_EXCEPTION_WIFI_MFP)) {
 		ieee80211_hw_set(hw, MFP_CAPABLE);
+		if (fips_enabled)
+			IWL_WARN(mvm, "FIPS: MFP enabled with known firmware limitation\n");
+	}
 
 	mvm->ciphers[hw->wiphy->n_cipher_suites] = WLAN_CIPHER_SUITE_AES_CMAC;
 	hw->wiphy->n_cipher_suites++;
@@ -492,12 +495,12 @@ int iwl_mvm_mac_setup_register(struct iwl_mvm *mvm)
 	 * beacon protection must be handled by firmware,
 	 * so cannot be done with fips_enabled
 	 */
-	if (!fips_enabled && sec_key_ver &&
+	if (fips_allows(FIPS_EXCEPTION_WIFI_MFP) && sec_key_ver &&
 	    fw_has_capa(&mvm->fw->ucode_capa,
 			IWL_UCODE_TLV_CAPA_BIGTK_TX_SUPPORT))
 		wiphy_ext_feature_set(hw->wiphy,
 				      NL80211_EXT_FEATURE_BEACON_PROTECTION);
-	else if (!fips_enabled &&
+	else if (fips_allows(FIPS_EXCEPTION_WIFI_MFP) &&
 		 fw_has_capa(&mvm->fw->ucode_capa,
 			     IWL_UCODE_TLV_CAPA_BIGTK_SUPPORT))
 		wiphy_ext_feature_set(hw->wiphy,
-- 
2.55.0


  parent reply	other threads:[~2026-09-30 12:09 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30 12:08 [PATCH v2 0/5] wifi: add opt-in FIPS exception for iwlwifi Jose Ignacio Tornos Martinez
2026-09-30 12:08 ` [PATCH v2 1/5] crypto: fips: add fips_exception kernel boot parameter and fips_allows() helper Jose Ignacio Tornos Martinez
2026-09-30 12:08 ` [PATCH v2 2/5] wifi: mac80211: allow keys to driver with fips_exception Jose Ignacio Tornos Martinez
2026-09-30 12:08 ` Jose Ignacio Tornos Martinez [this message]
2026-09-30 12:08 ` [PATCH v2 4/5] wifi: iwlwifi: use software crypto for management frames in FIPS exception mode Jose Ignacio Tornos Martinez
2026-09-30 12:08 ` [PATCH v2 5/5] wifi: iwlwifi: reduce encryption error message to debug level in FIPS mode Jose Ignacio Tornos Martinez
2026-10-01  7:37 ` [PATCH v2 0/5] wifi: add opt-in FIPS exception for iwlwifi Johannes Berg
2026-10-01 13:08   ` Jose Ignacio Tornos Martinez
2026-10-01 14:06     ` Johannes Berg
2026-10-01 15:59       ` Jose Ignacio Tornos Martinez
2026-10-01 16:19         ` Johannes Berg
2026-10-01 18:52           ` Jose Ignacio Tornos Martinez
2026-10-01 20:22             ` Johannes Berg
2026-10-02 10:45               ` Jose Ignacio Tornos Martinez

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260930120829.383408-4-jtornosm@redhat.com \
    --to=jtornosm@redhat.com \
    --cc=davem@davemloft.net \
    --cc=emmanuel.grumbach@intel.com \
    --cc=herbert@gondor.apana.org.au \
    --cc=ilan.peer@intel.com \
    --cc=johannes@sipsolutions.net \
    --cc=linux-crypto@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-wireless@vger.kernel.org \
    --cc=miriam.rachel.korenblit@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®