mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
To: herbert@gondor.apana.org.au, davem@davemloft.net,
	johannes@sipsolutions.net, miriam.rachel.korenblit@intel.com
Cc: ilan.peer@intel.com, emmanuel.grumbach@intel.com,
	linux-crypto@vger.kernel.org, linux-wireless@vger.kernel.org,
	linux-kernel@vger.kernel.org,
	Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
Subject: [PATCH v2 4/5] wifi: iwlwifi: use software crypto for management frames in FIPS exception mode
Date: Wed, 30 Sep 2026 14:08:27 +0200	[thread overview]
Message-ID: <20260930120829.383408-5-jtornosm@redhat.com> (raw)
In-Reply-To: <20260930120829.383408-1-jtornosm@redhat.com>

Best effort to protect as many outgoing robust management frames
as possible via host-side software crypto, given the firmware
limitations.

When the FIPS exception is active and keys are delivered to
firmware, mac80211 delegates management frame encryption to
firmware via hw_key. However, Intel firmware does not properly
apply CCMP/GCMP integrity protection to these frames, causing
the AP to drop them when MFP is negotiated.

Set IEEE80211_KEY_FLAG_SW_MGMT_TX on pairwise CCMP/GCMP keys
when fips_enabled, so that mac80211 encrypts unicast management
frames in software using FIPS-approved algorithms on the host
CPU. This is the same mechanism used by ath9k, ath5k, carl9170,
mt76x02, rtw88, rtw89, rtlwifi, ... and other drivers whose
firmware cannot encrypt management frames.

This protects SA Query, deauth, disassoc and other unicast
robust management frames built by mac80211. Multicast robust
management frames (IGTK/AES-CMAC/GMAC) are already handled
in software by mac80211, so no additional flag is needed.

AddBA (TX aggregation setup) cannot be fixed this way because
firmware creates these frames autonomously when
TX_AMPDU_SETUP_IN_HW is set, bypassing mac80211's TX path
entirely. Fixing this would require firmware-side changes.

The only observed degradation with the exception active is
reduced uplink throughput: firmware-created AddBA requests are
sent without integrity protection and silently discarded by
the AP, so TX aggregation is not established. Downlink
aggregation (AP to STA) works normally. No other functionality
is observed to be affected. Since the AP drops unprotected
firmware-autonomous frames rather than accepting them, the
system remains secure — those frames are simply not considered.

When set_key is reached with fips_enabled, the exception must
be active (otherwise drv_set_key blocks keys), so checking
fips_enabled alone is sufficient.

Both mvm and mld driver paths are covered.

Signed-off-by: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
---
v2: new, to improve the behavior
v1: https://lore.kernel.org/all/20260629121213.597038-1-jtornosm@redhat.com/

 drivers/net/wireless/intel/iwlwifi/mld/mac80211.c | 3 +++
 drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c | 2 ++
 2 files changed, 5 insertions(+)

diff --git a/drivers/net/wireless/intel/iwlwifi/mld/mac80211.c b/drivers/net/wireless/intel/iwlwifi/mld/mac80211.c
index 3ccbf1033160..3fd88420cd17 100644
--- a/drivers/net/wireless/intel/iwlwifi/mld/mac80211.c
+++ b/drivers/net/wireless/intel/iwlwifi/mld/mac80211.c
@@ -2230,6 +2230,9 @@ static int iwl_mld_set_key_add(struct iwl_mld *mld,
 	case WLAN_CIPHER_SUITE_CCMP:
 	case WLAN_CIPHER_SUITE_GCMP:
 	case WLAN_CIPHER_SUITE_GCMP_256:
+		if (fips_enabled && (key->flags & IEEE80211_KEY_FLAG_PAIRWISE))
+			key->flags |= IEEE80211_KEY_FLAG_SW_MGMT_TX;
+		break;
 	case WLAN_CIPHER_SUITE_AES_CMAC:
 	case WLAN_CIPHER_SUITE_BIP_GMAC_128:
 	case WLAN_CIPHER_SUITE_BIP_GMAC_256:
diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c b/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c
index f6e20a07e329..38fe710ef414 100644
--- a/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c
+++ b/drivers/net/wireless/intel/iwlwifi/mvm/mac80211.c
@@ -4247,6 +4247,8 @@ static int __iwl_mvm_mac_set_key(struct ieee80211_hw *hw,
 	case WLAN_CIPHER_SUITE_GCMP_256:
 		if (!iwl_mvm_has_new_tx_api(mvm))
 			key->flags |= IEEE80211_KEY_FLAG_PUT_IV_SPACE;
+		if (fips_enabled && (key->flags & IEEE80211_KEY_FLAG_PAIRWISE))
+			key->flags |= IEEE80211_KEY_FLAG_SW_MGMT_TX;
 		break;
 	case WLAN_CIPHER_SUITE_AES_CMAC:
 	case WLAN_CIPHER_SUITE_BIP_GMAC_128:
-- 
2.55.0


  parent reply	other threads:[~2026-09-30 12:09 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30 12:08 [PATCH v2 0/5] wifi: add opt-in FIPS exception for iwlwifi Jose Ignacio Tornos Martinez
2026-09-30 12:08 ` [PATCH v2 1/5] crypto: fips: add fips_exception kernel boot parameter and fips_allows() helper Jose Ignacio Tornos Martinez
2026-09-30 12:08 ` [PATCH v2 2/5] wifi: mac80211: allow keys to driver with fips_exception Jose Ignacio Tornos Martinez
2026-09-30 12:08 ` [PATCH v2 3/5] wifi: iwlwifi: restore FIPS-disabled features " Jose Ignacio Tornos Martinez
2026-09-30 12:08 ` Jose Ignacio Tornos Martinez [this message]
2026-09-30 12:08 ` [PATCH v2 5/5] wifi: iwlwifi: reduce encryption error message to debug level in FIPS mode Jose Ignacio Tornos Martinez
2026-10-01  7:37 ` [PATCH v2 0/5] wifi: add opt-in FIPS exception for iwlwifi Johannes Berg

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260930120829.383408-5-jtornosm@redhat.com \
    --to=jtornosm@redhat.com \
    --cc=davem@davemloft.net \
    --cc=emmanuel.grumbach@intel.com \
    --cc=herbert@gondor.apana.org.au \
    --cc=ilan.peer@intel.com \
    --cc=johannes@sipsolutions.net \
    --cc=linux-crypto@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-wireless@vger.kernel.org \
    --cc=miriam.rachel.korenblit@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®