From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 From: Markus Zehnder Date: Fri, 28 Aug 2026 00:00:00 +0200 Subject: [PATCH] wpa_supplicant: cap the temporary network disable after auth failures at 30 s wpas_auth_failed() escalates the time a network stays TEMP-DISABLED with the number of consecutive authentication failures: 10, 20, 30, 60 (>3), 90 (>5), 120 (>10) and 300 s (>50). The escalation is hard-coded; there is no configuration parameter. On a battery-powered remote control this backoff protects nothing (there is no lockout risk on home access points) while it turns a short firmware- or AP-side hiccup into minutes without network: measured on a Remote 3 with a firmware that rejects every join instantly, the sequence 10, 20, 30, 60, 60, 90, 90 s kept the device offline for 4+ minutes until the user restarted the supplicant from the UI. Every stall we have seen so far was on our own side (band lock vs. first scan, same-BSS rejoin without deauth, PMF mismatch), so a long backoff only delays the retry that would succeed. Keep the first three steps (10/20/30 s) as damping and cap everything above at 30 s. The final value is capped as well: the 802.1X random jitter (up to auth_failures * 10 s) is added whenever the network block lists an 802.1X AKM, which a permissive key_mgmt list does on a PSK network too - a Remote Two showed 44..99 s with only the base capped (2026-09-10). Remote Two builds the upstream hostap 2.10 package instead of this fork; its counterpart lives in buildroot-external/patches/wpa_supplicant/0002-wpa_supplicant-cap-auth-failure-backoff-at-30s-hostap-2.10.patch. Keep the two in sync. Signed-off-by: Markus Zehnder --- wpa_supplicant/wpa_supplicant.c | 20 ++++++++++++-------- 1 file changed, 12 insertions(+), 8 deletions(-) diff --git a/wpa_supplicant/wpa_supplicant.c b/wpa_supplicant/wpa_supplicant.c --- a/wpa_supplicant/wpa_supplicant.c +++ b/wpa_supplicant/wpa_supplicant.c @@ -8724,15 +8724,11 @@ } #endif /* CONFIG_P2P */ - if (ssid->auth_failures > 50) - dur = 300; - else if (ssid->auth_failures > 10) - dur = 120; - else if (ssid->auth_failures > 5) - dur = 90; - else if (ssid->auth_failures > 3) - dur = 60; - else if (ssid->auth_failures > 2) + /* Unfolded Circle: cap the backoff at 30 s (upstream escalates to 60, + * 90, 120 and 300 s). On a remote control a long backoff only delays + * the retry that would succeed; see doc/reviews/2026-08-27 ยง9.4. + */ + if (ssid->auth_failures > 2) dur = 30; else if (ssid->auth_failures > 1) dur = 20; @@ -8742,6 +8738,14 @@ if (ssid->auth_failures > 1 && wpa_key_mgmt_wpa_ieee8021x(ssid->key_mgmt)) dur += os_random() % (ssid->auth_failures * 10); + + /* Unfolded Circle: the jitter above is added whenever the network + * block lists an 802.1X AKM, PSK networks included when the app's + * key_mgmt list is permissive - measured 44..99 s on a Remote Two + * (2026-09-10). Cap the final value, not only the base. + */ + if (dur > 30) + dur = 30; os_get_reltime(&now); if (now.sec + dur <= ssid->disabled_until.sec) -- 2.39.5