From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 From: Markus Zehnder Date: Wed, 20 Aug 2026 00:00:00 +0200 Subject: [PATCH] wpa_supplicant: write config strings as hex when they contain " or # wpa_config_write_string_ascii() wraps the value in quotation marks and copies the bytes verbatim -- it does not escape anything. A value that itself contains a quotation mark or a '#' therefore produces a configuration line whose meaning depends on the reader's quote pairing and comment stripping. wpa_config_get_line() removes '#' comments unless they are inside a quoted string, pairing quotation marks from the left, and wpa_config_parse_string() takes everything up to the *last* quotation mark and requires the line to end there. For a value containing a quotation mark followed by a '#', these two disagree: the line is truncated at the '#' and the remainder no longer ends in a quotation mark, so the value fails to parse and the network loses the credential on the next reload. For example, the passphrase q"and#hash is stored as psk="q"and#hash" and is rejected when the file is read back. Choose the hex form whenever the value contains a character with a special meaning in the configuration file syntax, so that the stored form round-trips unconditionally. The hex form is already produced for values with non-printable bytes (is_hex()) and is accepted everywhere an ASCII value is, so this only changes how the value is written, never what it means. Signed-off-by: Markus Zehnder --- Base: hostap 2.10, tag hostap_2_10, wpa_supplicant/config.c wpa_config_write_string() begins at line 168; hunk context @@ -167,9 +167,22 @@ Source fetched from https://w1.fi/cgit/hostap/plain/wpa_supplicant/config.c?h=hostap_2_10 wpa_supplicant/config.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/wpa_supplicant/config.c b/wpa_supplicant/config.c index bf062b0792b7..5a25c22eb004 100644 --- a/wpa_supplicant/config.c +++ b/wpa_supplicant/config.c @@ -167,9 +167,22 @@ static char * wpa_config_write_string(const u8 *value, size_t len) { + size_t i; + if (value == NULL) return NULL; + /* + * Use the hex format also for values that contain characters with a + * special meaning in the configuration file syntax (the quotation + * marks that delimit an ASCII value and the '#' comment character) + * since the ASCII format does not escape them. + */ + for (i = 0; i < len; i++) { + if (value[i] == '"' || value[i] == '#') + return wpa_config_write_string_hex(value, len); + } + if (is_hex(value, len)) return wpa_config_write_string_hex(value, len); else -- 2.39.5