From patchwork Fri Mar 2 20:11:03 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Michael Siedzik X-Patchwork-Id: 880853 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=none (mailfrom) smtp.mailfrom=lists.infradead.org (client-ip=2607:7c80:54:e::133; helo=bombadil.infradead.org; envelope-from=hostap-bounces+incoming=patchwork.ozlabs.org@lists.infradead.org; receiver=) Authentication-Results: ozlabs.org; dmarc=none (p=none dis=none) header.from=extremenetworks.com Authentication-Results: ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=lists.infradead.org header.i=@lists.infradead.org header.b="W1+ASrD2"; dkim-atps=neutral Received: from bombadil.infradead.org (bombadil.infradead.org [IPv6:2607:7c80:54:e::133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 3ztLBJ17VVz9s33 for ; Sat, 3 Mar 2018 07:14:48 +1100 (AEDT) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20170209; h=Sender: Content-Transfer-Encoding:Content-Type:Cc:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:MIME-Version:References:In-Reply-To: Message-ID:Date:Subject:To:From:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=ZyWIQzL7mKDGUHEsa7b+Ih9e9hJfD+/ELsLvkEiSeJY=; b=W1+ASrD2+aUAlT 2lhE/nEUGGNZRJc2mgqsn8P7NfsISSFcItveFPdLZ4zlgEOFMvhJ/aB5O+NjJOgUZ1WGGZ5yy+c0S MkXPJ29JxEl1Gn1w0S27Oy3hnxrRScZiMsEBkWfBiDq9b1doc/h7N3EPUsbucECqDcP2d83106RiW tcoCSHRUtQEvZGm0AXBg2xTIi7QM8b4MGr8fzPrZVReKgOLIoGjcM6WUfJHKMEvIlHJoZWPtEQ4IO pvbUbuaJhAsTtA76PLa6MBqvZgnFSurIM7FXJuf0AsWjYwGDOPKUQ8DOTeE+7/ovkNiysfDOftU3i YaTc6Fjhz4U3vnbClfKQ==; Received: from localhost ([127.0.0.1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.89 #1 (Red Hat Linux)) id 1err4S-00023r-MS; Fri, 02 Mar 2018 20:14:24 +0000 Received: from us-smtp-delivery-183.mimecast.com ([216.205.24.183]) by bombadil.infradead.org with esmtps (Exim 4.89 #1 (Red Hat Linux)) id 1err3M-0001JQ-1u for hostap@lists.infradead.org; Fri, 02 Mar 2018 20:13:20 +0000 Received: from USNH-CASHT-P2.corp.extremenetworks.com (owamail.extremenetworks.com [134.141.4.38]) (Using TLS) by us-smtp-1.mimecast.com with ESMTP id us-mta-166-rR82tpoFNHu2xzd80HNb4A-6; Fri, 02 Mar 2018 15:11:05 -0500 Received: from usnh-casht-p2.corp.extremenetworks.com (134.141.77.27) by USNH-CASHT-P2.corp.extremenetworks.com (134.141.77.27) with Microsoft SMTP Server (TLS) id 15.0.1210.3; Fri, 2 Mar 2018 15:10:59 -0500 Received: from smtp1.extremenetworks.com (10.6.24.34) by usnh-casht-p2.corp.extremenetworks.com (134.141.77.27) with Microsoft SMTP Server (TLS) id 15.0.1210.3 via Frontend Transport; Fri, 2 Mar 2018 15:10:59 -0500 Received: from cm-exos1.extremenetworks.com (a10-smtp.extremenetworks.com [10.6.24.14]) by smtp1.extremenetworks.com (8.13.8/8.13.8) with ESMTP id w22KAw6O032596; Fri, 2 Mar 2018 12:10:58 -0800 Received: from cm-exos1.extremenetworks.com (localhost [127.0.0.1]) by cm-exos1.extremenetworks.com (Postfix) with ESMTP id 322B92C0417; Fri, 2 Mar 2018 15:11:10 -0500 (EST) Received: (from msiedzik@localhost) by cm-exos1.extremenetworks.com (8.14.7/8.14.7/Submit) id w22KBAnC016353; Fri, 2 Mar 2018 15:11:10 -0500 From: To: Subject: [PATCH 15/15] mka: do not update potential peer liveness timer Date: Fri, 2 Mar 2018 15:11:03 -0500 Message-ID: <20180302201103.16264-16-msiedzik@extremenetworks.com> X-Mailer: git-send-email 2.11.1 In-Reply-To: <20180302201103.16264-1-msiedzik@extremenetworks.com> References: <20180302201103.16264-1-msiedzik@extremenetworks.com> MIME-Version: 1.0 X-MC-Unique: rR82tpoFNHu2xzd80HNb4A-6 X-Spam-Note: CRM114 invocation failed X-Spam-Score: -2.6 (--) X-Spam-Report: SpamAssassin version 3.4.1 on bombadil.infradead.org summary: Content analysis details: (-2.6 points) pts rule name description ---- ---------------------- -------------------------------------------------- -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [216.205.24.183 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record -1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1% [score: 0.0000] X-BeenThere: hostap@lists.infradead.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Mike Siedzik Sender: "Hostap" Errors-To: hostap-bounces+incoming=patchwork.ozlabs.org@lists.infradead.org From: Mike Siedzik To prevent a remote peer from getting stuck in a perpetual 'potential peer' state, only update the peer liveness timer 'peer->expire' for live peers and not for potential peers. Per IEEE802.1X-2010 9.4.3 Determining liveness, potential peers need to show liveness by including our MI/MN in their transmitted MKPDU (within potential or live parameter sets). When a potential peer does include our MI/MN in an MKPDU, we respond by moving the peer from 'potential_peers' to 'live_peers'. If a potential peer does not include our MI/MN in an MKPDU within MKPDU_LIFE_TIME, then let the peer expire to facilitate getting back in sync with the remote peer. Signed-off-by: Michael Siedzik --- src/pae/ieee802_1x_kay.c | 15 +++++++++++---- 1 file changed, 11 insertions(+), 4 deletions(-) -- 2.11.1 diff --git a/src/pae/ieee802_1x_kay.c b/src/pae/ieee802_1x_kay.c index 4323b6dc0..6ac7d02d1 100644 --- a/src/pae/ieee802_1x_kay.c +++ b/src/pae/ieee802_1x_kay.c @@ -3180,14 +3180,21 @@ static int ieee802_1x_kay_decode_mkpdu(struct ieee802_1x_kay *kay, } else { peer->missing_sak_use_count = 0; } + + /* Only update live peer watchdog after successful decode of all parameter sets */ + peer->expire = time(NULL) + MKA_LIFE_TIME / 1000; } else { /* MKPDU is from new or potential peer */ peer = ieee802_1x_kay_get_peer(participant, participant->current_peer_id.mi); - } + if (!peer) + return -1; - /* Only update live peer watchdog after successful decode of all parameter sets */ - if (peer) - peer->expire = time(NULL) + MKA_LIFE_TIME / 1000; + /* Do not update potential peer watchdog. Per IEEE802.1X-2010 9.4.3, + * potential peers need to show liveness by including our MI/MN in their + * transmitted MKPDU (within potential or live parameter sets). When + * a potential peer does include our MI/MN in an MKPDU, we respond by + * moving the peer from 'potential_peers' to 'live_peers'. */ + } kay->active = TRUE; participant->retry_count = 0;