640-bridge_no_eap_forward.patch 767 B

1234567891011121314151617181920212223
  1. From: Felix Fietkau <nbd@nbd.name>
  2. Subject: [PATCH] bridge: no EAP forward
  3. When bridging, do not forward EAP frames to other ports, only deliver
  4. them locally.
  5. Fixes WPA authentication issues with multiples APs that are connected to
  6. each other via bridges.
  7. ---
  8. --- a/net/bridge/br_input.c
  9. +++ b/net/bridge/br_input.c
  10. @@ -168,7 +168,11 @@ int br_handle_frame_finish(struct net *n
  11. if (IS_ENABLED(CONFIG_INET) && skb->protocol == htons(ETH_P_ARP))
  12. br_do_proxy_arp(skb, br, vid, p);
  13. - if (is_broadcast_ether_addr(dest)) {
  14. + if (skb->protocol == htons(ETH_P_PAE)) {
  15. + skb2 = skb;
  16. + /* Do not forward 802.1x/EAP frames */
  17. + skb = NULL;
  18. + } else if (is_broadcast_ether_addr(dest)) {
  19. skb2 = skb;
  20. unicast = false;
  21. } else if (is_multicast_ether_addr(dest)) {