@@ -1727,9 +1727,30 @@ static int wpa_supplicant_install_igtk(struct wpa_sm *sm,
keyidx, MAC2STR(igtk->pn));
wpa_hexdump_key(MSG_DEBUG, "WPA: IGTK", igtk->igtk, len);
if (keyidx > 4095) {
-wpa_msg(sm->ctx->msg_ctx, MSG_WARNING,
-"WPA: Invalid IGTK KeyID %d", keyidx);
-return -1;
+int masked = keyidx & 0xFF;
+if (masked == 4 || masked == 5) {
+/* Assume the AP has broken PMF implementation since it
+ * seems to have swapped the KeyID bytes. The AP cannot
+ * be trusted to implement BIP correctly or provide a
+ * valid IGTK, so do not try to configure this key with
+ * swapped KeyID bytes. Instead, continue without
+ * configuring the IGTK so that the driver can drop any
+ * received group-addressed robust management frames due
+ * to missing keys.
+ *
+ * Normally, this error behavior would result in us
+ * disconnecting, but there are number of deployed APs
+ * with this broken behavior, so as an interoperability
+ * workaround, allow the connection to proceed. */
+wpa_msg(sm->ctx->msg_ctx, MSG_INFO,
+"WPA: Workaround for non-compliant AP: corrected IGTK KeyID %d to %d",
+keyidx, masked);
+keyidx = masked;
+} else {
+wpa_msg(sm->ctx->msg_ctx, MSG_WARNING,
+"WPA: Invalid IGTK KeyID %d", keyidx);
+return -1;
+}
}
if (wpa_sm_set_key(sm, -1, wpa_cipher_to_alg(sm->mgmt_group_cipher),
broadcast_ether_addr,