Skip to content

Releases: shunnag/openpilot

AGNOS 19.9 WPA3-SAE boot image with H2E (unofficial)

Choose a tag to compare

@shunnag shunnag released this 01 Oct 01:52
afa4703

Unofficial files for AGNOS 19.9, for personal use. They are not supported by comma.

AGNOS 19.9 用の非公式ファイルです。個人利用向けで、comma のサポート対象ではありません。

This release moves the fork's WPA3 support to AGNOS 19.9. The kernel changes are the same as in agnos-19.8-wpa3.2, rebuilt on AGNOS 19.9's kernel. The nightly and nightly-chestnut branches of this fork use the boot image from this release. See the README on the wpa3-ci branch for how they're installed.

このリリースで、fork の WPA3 対応を AGNOS 19.9 に移します。カーネルの変更は agnos-19.8-wpa3.2 と同じで、AGNOS 19.9 のカーネルの上で作り直したものです。この fork の nightly と nightly-chestnut は、このリリースの boot イメージを使います。インストールの仕組みは、wpa3-ci ブランチの README を参照してください。

Files

file description 内容
boot-f94c88e8….img.xz boot image (xz) boot イメージ(xz 圧縮)
0001-qcacld-3.0-enable-SAE.patch kernel: enable SAE (commaai/agnos-kernel-sdm845#142) カーネル: SAE の有効化
0002-qcacld-3.0-include-RSNXE-in-the-association-request.patch kernel: RSNXE for H2E (commaai/agnos-kernel-sdm845#143) カーネル: H2E 用の RSNXE
wpasupplicant_2.10-21ubuntu0.4+agnos1_arm64.deb patched wpa_supplicant (commaai/agnos-builder#629), same as in agnos-19.8-wpa3.2 修正版 wpa_supplicant(agnos-19.8-wpa3.2 と同じ)
wpasupplicant-agnos1-patches.tar.gz its patches and build script, same as in agnos-19.8-wpa3.2 そのパッチとビルドスクリプト(同じ)
  • Boot image, decompressed SHA-256 / 展開後の SHA-256: f94c88e80909c556f20c426898cebced72e2470f520606282448c1275b68dd8d (46,962,688 bytes)
  • wpa_supplicant binary shipped in the fork / fork に同梱するバイナリ: 139be31dde5f000d99af5f2692b792989bb3d6cbe332d662b2ddf822de89fd93 (unchanged / 変更なし)
  • See SHA256SUMS for the other files. / ほかのファイルは SHA256SUMS を参照してください。

Changes since agnos-19.8-wpa3.2

  • Kernel: rebuilt on comma's AGNOS 19.9 kernel, which is 19.8's kernel plus comma's backport of the xhci soft retry for USB transaction errors. The two WPA3 patches are unchanged: the source diff is byte-identical to the one in agnos-19.8-wpa3.2. The command line tag is now wpa3.sae=3, so devices on the previous image switch automatically when the fork moves to AGNOS 19.9.

  • wpa_supplicant: unchanged. AGNOS 19.9 ships the same stock binary as AGNOS 19.8 (Ubuntu's 2:2.10-21ubuntu0.4, SHA-256 b0f1c8ee9bb32153faed468c68390db4691b252ffd6a90e6d3d7b49f4d106bdd), so the fork's override works as before.

  • カーネル: comma の AGNOS 19.9 のカーネルの上で作り直しました。19.9 のカーネルは、19.8 のカーネルに、USB の転送エラーを速く回復させる xhci の soft retry(comma のバックポート)を加えたものです。2 つの WPA3 のパッチは変わりません。ソースの差分は agnos-19.8-wpa3.2 のものとバイト単位で同じです。コマンドラインのタグは wpa3.sae=3 になり、fork が AGNOS 19.9 に移ると、以前のイメージの端末は自動で切り替わります。

  • wpa_supplicant: 変更はありません。AGNOS 19.9 の純正のバイナリは AGNOS 19.8 と同じ(Ubuntu の 2:2.10-21ubuntu0.4、SHA-256 b0f1c8ee9bb32153faed468c68390db4691b252ffd6a90e6d3d7b49f4d106bdd)なので、fork の差し替えはこれまでどおり働きます。

Source

  • Kernel (GPLv2): commaai/agnos-kernel-sdm845 at 8b0e4d289b246a5cc1b0484b25a3f9f8d4772544 (comma's AGNOS 19.9 kernel), with the two kernel patches above. agnos-builder has no agnos19.9 branch yet; building this commit with build_kernel.sh from commaai/agnos-builder agnos19.8 and comma's GCC 8.2.1 toolchain reproduces comma's 19.9 boot image, except for the build identity and the order of the appended device trees. Signed with agnos-builder's vble-qti.key, with wpa3.sae=3 appended to the mkbootimg --cmdline.

  • wpa_supplicant (BSD): Ubuntu's wpa 2:2.10-21ubuntu0.4 source package plus the patches in wpasupplicant-agnos1-patches.tar.gz. The license is in the package's copyright file, which the fork ships next to the binary.

  • カーネル(GPLv2): commaai/agnos-kernel-sdm845 の 8b0e4d289b246a5cc1b0484b25a3f9f8d4772544(comma の AGNOS 19.9 のカーネル)に、上の 2 つのパッチを当てたものです。agnos-builder にはまだ agnos19.9 のブランチがありません。このコミットを commaai/agnos-builder の agnos19.8 の build_kernel.sh と comma の GCC 8.2.1 でビルドすると、ビルドの識別情報と、末尾に付くデバイスツリーの順番を除いて、comma の 19.9 の boot イメージと同じものができます。署名には agnos-builder の vble-qti.key を使い、mkbootimg の --cmdline の末尾に wpa3.sae=3 を追加しています。

  • wpa_supplicant(BSD): Ubuntu の wpa 2:2.10-21ubuntu0.4 のソースパッケージに、wpasupplicant-agnos1-patches.tar.gz のパッチを当てたものです。ライセンスはパッケージの copyright ファイルにあり、fork はこれをバイナリの隣に同梱しています。

Notes

Tested only on the comma four, with a Wi-Fi 7 mesh AP in WPA3-only mode (H2E advertised): the update from agnos-19.8-wpa3.2 on nightly-chestnut, then SAE with H2E and PMF, and the patched wpa_supplicant. The comma 3X is untested.

On the comma four, the AGNOS update screen waits until you tap "next" and then "download & install". While it is shown, the stock wpa_supplicant is still in use, as with agnos-19.8-wpa3.2. If your AP only allows H2E, use another network for the update.

動作確認は comma four でのみ、WPA3 専用モードの Wi-Fi 7 メッシュ AP(H2E を広告)で行っています。nightly-chestnut で agnos-19.8-wpa3.2 から更新し、H2E と PMF を使う SAE の接続と、修正版の wpa_supplicant を確かめました。comma 3X は未確認です。

comma four では、AGNOS の更新の画面は「next」と「download & install」を押すまで始まりません。この画面の間は、agnos-19.8-wpa3.2 のときと同じく、純正の wpa_supplicant のままです。H2E しか受け付けない AP の場合は、更新のときだけ別のネットワークを使ってください。

AGNOS 19.8 WPA3-SAE boot image with H2E (unofficial)

Choose a tag to compare

@shunnag shunnag released this 25 Sep 22:12
afa4703

Unofficial files for AGNOS 19.8, for personal use. They are not supported by comma.

AGNOS 19.8 用の非公式ファイルです。個人利用向けで、comma のサポート対象ではありません。

This release adds SAE hash-to-element (H2E) to the fork's WPA3 support. The nightly and nightly-chestnut branches of this fork use the boot image from this release, and ship the patched wpa_supplicant in the openpilot tree. See the README on the wpa3-ci branch for how they're installed.

このリリースで、fork の WPA3 対応に SAE の hash-to-element(H2E)が加わります。この fork の nightly と nightly-chestnut は、このリリースの boot イメージを使い、修正版の wpa_supplicant を openpilot の中に同梱します。インストールの仕組みは、wpa3-ci ブランチの README を参照してください。

Files

file description 内容
boot-862b653d….img.xz boot image (xz) boot イメージ(xz 圧縮)
0001-qcacld-3.0-enable-SAE.patch kernel: enable SAE (commaai/agnos-kernel-sdm845#142) カーネル: SAE の有効化
0002-qcacld-3.0-include-RSNXE-in-the-association-request.patch kernel: RSNXE for H2E (commaai/agnos-kernel-sdm845#143) カーネル: H2E 用の RSNXE
wpasupplicant_2.10-21ubuntu0.4+agnos1_arm64.deb patched wpa_supplicant (commaai/agnos-builder#629) 修正版 wpa_supplicant
wpasupplicant-agnos1-patches.tar.gz its patches and build script そのパッチとビルドスクリプト
  • Boot image, decompressed SHA-256 / 展開後の SHA-256: 862b653d80c9d7ac933a60d2bb748371a3267f658194e6ca7273f33c2973de94 (46,962,688 bytes)
  • wpa_supplicant binary shipped in the fork / fork に同梱するバイナリ: 139be31dde5f000d99af5f2692b792989bb3d6cbe332d662b2ddf822de89fd93
  • See SHA256SUMS for the other files. / ほかのファイルは SHA256SUMS を参照してください。

Changes since agnos-19.8-wpa3.1

  • Kernel: qcacld-3.0 now puts the RSNXE from wpa_supplicant in the association request. It ports upstream qcacld-3.0 c051588e6, dfba36b6f and 7c07f228f6. The command line tag is now wpa3.sae=2, so devices on the previous image switch automatically.

  • wpa_supplicant: Ubuntu's 2:2.10-21ubuntu0.4 rebuilt with the SAE fixes from hostap 2.11/2.12 (advisories 2024-2, 2026-2, 2026-3) and sae_pwe=2 as the default, so SAE uses H2E when the AP advertises it. At boot, the fork bind-mounts it over /usr/sbin/wpa_supplicant only if the stock binary is exactly Ubuntu's 2:2.10-21ubuntu0.4 and the patched one starts; otherwise the stock one is kept.

  • カーネル: qcacld-3.0 が、wpa_supplicant から渡された RSNXE を接続要求に載せるようになりました。本家 qcacld-3.0 の c051588e6、dfba36b6f、7c07f228f6 を移植したものです。コマンドラインのタグは wpa3.sae=2 になり、以前のイメージの端末は自動で切り替わります。

  • wpa_supplicant: Ubuntu の 2:2.10-21ubuntu0.4 を、hostap 2.11/2.12 の SAE の修正(アドバイザリ 2024-2、2026-2、2026-3)と、既定値 sae_pwe=2 で作り直しました。AP が H2E を広告していれば、SAE で H2E を使います。起動時に fork が /usr/sbin/wpa_supplicant へ bind mount しますが、純正のバイナリが Ubuntu の 2:2.10-21ubuntu0.4 と完全に一致し、修正版が起動できる場合に限ります。それ以外は純正のまま使います。

Source

  • Kernel (GPLv2): commaai/agnos-kernel-sdm845 at eccd146599f2e2f159d951092642689bede91632 (agnos-builder agnos19.8), with the two kernel patches above. Built with build_kernel.sh from commaai/agnos-builder agnos19.8 and comma's GCC 8.2.1 toolchain, signed with agnos-builder's vble-qti.key, with wpa3.sae=2 appended to the mkbootimg --cmdline.

  • wpa_supplicant (BSD): Ubuntu's wpa 2:2.10-21ubuntu0.4 source package plus the patches in wpasupplicant-agnos1-patches.tar.gz. The license is in the package's copyright file, which the fork ships next to the binary.

  • カーネル(GPLv2): commaai/agnos-kernel-sdm845 の eccd146599f2e2f159d951092642689bede91632(agnos-builder の agnos19.8)に、上の 2 つのパッチを当てたものです。commaai/agnos-builder の agnos19.8 の build_kernel.sh を、comma の GCC 8.2.1 でビルドしました。署名には agnos-builder の vble-qti.key を使い、mkbootimg の --cmdline の末尾に wpa3.sae=2 を追加しています。

  • wpa_supplicant(BSD): Ubuntu の wpa 2:2.10-21ubuntu0.4 のソースパッケージに、wpasupplicant-agnos1-patches.tar.gz のパッチを当てたものです。ライセンスはパッケージの copyright ファイルにあり、fork はこれをバイナリの隣に同梱しています。

Notes

Tested only on the comma four, with a Wi-Fi 7 mesh AP in WPA3-only mode (H2E advertised). APs that only allow H2E are tested on mac80211_hwsim, not on the device. The comma 3X is untested.

動作確認は comma four でのみ、WPA3 専用モードの Wi-Fi 7 メッシュ AP(H2E を広告)で行っています。H2E しか受け付けない AP は、実機ではなく mac80211_hwsim で確認しました。comma 3X は未確認です。

AGNOS 19.8 WPA3-SAE boot image (unofficial)

Choose a tag to compare

@shunnag shunnag released this 24 Sep 19:53
afa4703

Unofficial boot image for AGNOS 19.8, for personal use. It is not supported by comma.

AGNOS 19.8 用の非公式な boot イメージです。個人利用向けで、comma のサポート対象ではありません。

This is comma's AGNOS 19.8 kernel with SAE enabled in the qcacld-3.0 Wi-Fi driver, so the comma four can join WPA3-only networks. The nightly and nightly-chestnut branches of this fork point their AGNOS manifest's boot entry here. All other AGNOS images are comma's. See the README on the wpa3-ci branch for how it's installed.

comma の AGNOS 19.8 のカーネルで、qcacld-3.0 Wi-Fi ドライバの SAE を有効にしたものです。これで comma four が WPA3 専用のネットワークにつながります。この fork の nightly と nightly-chestnut ブランチは、AGNOS の manifest の boot にこのイメージを指定しています。ほかの AGNOS イメージは comma のままです。インストールの仕組みは、wpa3-ci ブランチの README を参照してください。

Files

file description 内容
boot-18c888b8….img.xz boot image (xz) boot イメージ(xz 圧縮)
wpa3-sae.patch kernel changes (4 files, +11/−2) カーネルへの変更(4 ファイル、+11/−2)
  • Decompressed SHA-256 / 展開後の SHA-256: 18c888b86f8846cd49bf3312b2c02fb60fc3f5e2f165d3a77417a7ad4e2c5549
  • Decompressed size / 展開後のサイズ: 46,962,688 bytes
  • wpa3-sae.patch SHA-256: 06e362ad6a2cf674c9797f7853b3cba9aaa180a638399efe80b573fc05e6cbfa

Changes

  • Enable SAE (WLAN_FEATURE_SAE) in qcacld-3.0
  • Move the SAE auth type case out of the FILS guard
  • Map SAE with open authentication (PMKSA caching reconnects) to SAE

The same changes are proposed upstream in commaai/agnos-kernel-sdm845#142.

  • qcacld-3.0 の SAE(WLAN_FEATURE_SAE)を有効化
  • SAE の認証方式の処理を FILS の条件分岐の外に移動
  • SAE + open authentication(PMKSA キャッシュでの再接続)を SAE として扱うよう対応付け

同じ変更を commaai/agnos-kernel-sdm845#142 で本家に提案しています。

Source (GPLv2)

  • Kernel: commaai/agnos-kernel-sdm845 at eccd146599f2e2f159d951092642689bede91632 (the commit used by agnos-builder's agnos19.8 branch), with wpa3-sae.patch applied.

  • Build: build_kernel.sh from commaai/agnos-builder at bdbf1bc40d4252362f8891fd2f5894a97f2756ca (agnos19.8), with comma's GCC 8.2.1 toolchain. Signed with vble-qti.key from agnos-builder.

  • Command line: comma's, with wpa3.sae=1 appended to the mkbootimg --cmdline. openpilot on this fork uses this tag to tell whether the WPA3 kernel is running.

  • カーネル: commaai/agnos-kernel-sdm845 の eccd146599f2e2f159d951092642689bede91632(agnos-builder の agnos19.8 ブランチが参照するコミット)に wpa3-sae.patch を適用したものです。

  • ビルド: commaai/agnos-builder の bdbf1bc40d4252362f8891fd2f5894a97f2756ca(agnos19.8)の build_kernel.sh を、comma の GCC 8.2.1 ツールチェーンで実行しました。署名には agnos-builder に含まれる vble-qti.key を使っています。

  • コマンドライン: comma のものに、mkbootimg の --cmdline の末尾へ wpa3.sae=1 を追加しています。この fork の openpilot は、このタグで WPA3 カーネルが動いているかを判断します。

Notes

Tested only on the comma four. The comma 3X is untested. Access points that only allow SAE-H2E are not supported.

動作確認は comma four でのみ行っています。comma 3X は未確認です。SAE-H2E しか受け付けないアクセスポイントには対応していません。