From nobody Mon Aug 10 14:10:55 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hJc9Y1Xnsz6nqbR for ; Mon, 10 Aug 2026 14:10:57 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hJc9X1KkNz3Rkj for ; Mon, 10 Aug 2026 14:10:56 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1786371056; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=N9APtPeWhlMrRpQpkGT2ZRnprV2reOaxdjUIzOdsptk=; b=fhxPe1ODaDOWaarGO243xgl6naWyFz35H83a0OsvodEOS8eudkuCva93+86aPAH2zDcQ+R XQD7AtGU0kB66x93TxwR9ZgoVAwhYCc823owDXLbW2BJWVbEj17bYWCggetpdeegJ7tXsc Y4eSmrIjoWqzC09/HqS5BwlSocwZXOwTaj5lV0qxjQ2xxhJmi4ziF+NQxcV5Re8EnUfyC9 81HVRzWfCzpCJ4yZbw+fKi0exIf59/Q/uKzE/ZJBojxVy3Ua6RN5lpak6SVYy4nczdsJLy 1lzxPRi07d45+/n45bJUz5FiWKhHa2zDyQ7e3gSH9lwKnfY48mL0vWVOlOO/3Q== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1786371056; a=rsa-sha256; cv=none; b=Dyt9XdZfhvsg6dToxld9NruT/IOXlebYGhAH4vzuIQrFacqCXMnFHyQV2vM2a9svY9s1vM XmYDM0BGZ120eJvpAfnXmFRfADoR3T/JfzAHthgbShR1plt0qr0pzkPMIzRBr+Ks7aA4FO VRmIC2bbqQ9x7ualb6rIZl9U7gqigoCJl1uGulJYFZXZFMeXW4ReO+RkczqtH4GrzSjkH9 BJUBPRfC8isbBJVhacQtfpOMMBQJGCjdnf5RW7JJU1+qU8RSHhv4ctpjhr8LuaplHQj2xJ JUovEtnRGhbuTdqmNq23+0hP1PzEg7nOI8E/84yPg6tLu9o65gsc3pE4KfZ/dg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1786371056; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=N9APtPeWhlMrRpQpkGT2ZRnprV2reOaxdjUIzOdsptk=; b=NEK2R58+RdJdaWLTPz9iP4F3ITN/JuUbnP/7GT+y5kKohFaup+SwguXV9irFkf4XdoOcI2 EeId4ZW5G5EOFjwHbKmuEyonkr63h/XpLqXPRkGxRKva/J9f08Vbtt8WHMUcRR4gxz+vgr VaeIs9gD7x8GGMD7Cc2CGnxoZ4J3MPVjlARK2AgUkCf6m/Cq3DdrwaHLPGWp6+NrIG/ji6 gj+djmmW5YtBEBTjgxK0kkS/B2NAgi9MAFpMvi92ekyJITvblPwbDoMtQCVL80Y/olcbuU VLrMhitZYz7eAdgWnHw+2IHkxA3xaWbNVDJFclb0wP9uWwPxxGS624N1SeuvgQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hJc9W5bRSz1BSB for ; Mon, 10 Aug 2026 14:10:55 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 2277b by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Mon, 10 Aug 2026 14:10:55 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org From: Cy Schubert Subject: git: e4e2f564de99 - Create tag vendor/wpa/2.12 List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: cy X-Git-Repository: src X-Git-Refname: refs/tags/vendor/wpa/2.12 X-Git-Reftype: annotated tag X-Git-Commit: e4e2f564de993b7a14f3162befd915974163592e Auto-Submitted: auto-generated Date: Mon, 10 Aug 2026 14:10:55 +0000 Message-Id: <6a79dbef.2277b.322c3431@gitrepo.freebsd.org> The annotated tag vendor/wpa/2.12 has been created by cy: URL: https://cgit.FreeBSD.org/src/tag/?h=vendor/wpa/2.12 tag vendor/wpa/2.12 Tagger: Cy Schubert TaggerDate: 2026-08-10 14:08:36 +0000 wpa: Tag 2.12 commit 513264698a892550ba20aeb9da7f360417fdc63b Author: Cy Schubert AuthorDate: 2026-08-10 13:56:41 +0000 Commit: Cy Schubert CommitDate: 2026-08-10 13:56:41 +0000 wpa: Update to 2.12 Fixes and new features include: hostapd: * support RSN overriding (e.g., WPA3-Personal Compatibility Mode) * EHT/IEEE 802.11be/Wi-Fi 7 - more complete support - fix message validation issues that could enable DoS attacks - fix group key rekeying * enable SAE group 20 by default if SAE-EXT-KEY is enabled * reject unexpected SAE password identifier to avoid DoS attack against a specific STA * mandate use of SAE H2E when using password identifiers * assign VLAN when using SAE with PMKSA caching * support SPP A-MSDU negotiation * support IEEE 802.11bi functionality - changing SAE password identifiers - EPPKE - IEEE 802.1X/EAP in Authentication frames - Association frame encryption - PMKID privacy * remove the driver interface for now obsolete Host AP driver * remove the driver interface for now obsolete Atheros WEXT interface * move supported, basic, and Beacon TX rate configuration to be at BSS level instead of per-radio for all BSSs * fix various issues in Multiple-BSSID functionality * support OpenSSL 3.0 API changes * EAP-TEAP: protocol changes based on RFC 9930; this is not compatible with previous versions * support Automated Frequency Coordination (AFC) on the 6 GHz band * improve GAS/ANQP processing to support larger ANQP responses * a large number of other fixes, cleanup, and extensions wpa_supplicant: * support RSN overriding (e.g., WPA3-Personal Compatibility Mode) * improve BSS transition management support * EHT/IEEE 802.11be/Wi-Fi 7 - more complete support - fix message validation issues that could enable DoS attacks * support Wi-Fi Direct R2 * support Wi-Fi Aware (add synchronized NAN; extend USD support) * support Proximity Ranging * support SPP A-MSDU negotiation * support IEEE 802.11bi functionality - changing SAE password identifiers - EPPKE - IEEE 802.1X/EAP in Authentication frames - Association frame encryption - PMKID privacy * enable layer 2/Wi-Fi multicast filtering for all networks (not just some Passpoint networks which enabled this before) * wpa_gui: port to Qt6 * support OpenSSL 3.0 API changes * EAP-TEAP: protocol changes based on RFC 9930; this is not compatible with previous versions * maintain configuration file permissions when writing updated configuration * add option to validate PKCS#11/OpenSC engine and module paths * fix PMKSA caching to enforce network context to avoid misuse of unexpected PMKSA cache entries * fix a potential DoS attack in SAE processing of an unexpected element * fix incomplete bounds checking of mesh AMPE messages that could have resulted in DoS attacks and memory corruption * a large number of other fixes, cleanup, and extensions