]> git.ipfire.org Git - thirdparty/hostap.git/blame - src/drivers/driver_nl80211.c
Sync with wireless-testing.git include/linux/nl80211.h
[thirdparty/hostap.git] / src / drivers / driver_nl80211.c
CommitLineData
3f5285e8 1/*
c5121837 2 * Driver interaction with Linux nl80211/cfg80211
8d923a4a 3 * Copyright (c) 2002-2010, Jouni Malinen <j@w1.fi>
072ad14c
JM
4 * Copyright (c) 2003-2004, Instant802 Networks, Inc.
5 * Copyright (c) 2005-2006, Devicescape Software, Inc.
6 * Copyright (c) 2007, Johannes Berg <johannes@sipsolutions.net>
58f6fbe0 7 * Copyright (c) 2009-2010, Atheros Communications
3f5285e8
JM
8 *
9 * This program is free software; you can redistribute it and/or modify
10 * it under the terms of the GNU General Public License version 2 as
11 * published by the Free Software Foundation.
12 *
13 * Alternatively, this software may be distributed under the terms of BSD
14 * license.
15 *
16 * See README and COPYING for more details.
17 */
18
19#include "includes.h"
20#include <sys/ioctl.h>
37b7d082 21#include <net/if.h>
3f5285e8
JM
22#include <netlink/genl/genl.h>
23#include <netlink/genl/family.h>
24#include <netlink/genl/ctrl.h>
1b648c7e
JM
25#include <netpacket/packet.h>
26#include <linux/filter.h>
7e45830a 27#include "nl80211_copy.h"
625f587b 28
3f5285e8 29#include "common.h"
1b648c7e
JM
30#include "eloop.h"
31#include "common/ieee802_11_defs.h"
e2d02c29 32#include "netlink.h"
34f2f814 33#include "linux_ioctl.h"
e2d02c29
JM
34#include "radiotap.h"
35#include "radiotap_iter.h"
1b648c7e 36#include "driver.h"
0915d02c 37
c5121837
JM
38#ifdef CONFIG_LIBNL20
39/* libnl 2.0 compatibility code */
2e8eac2d 40#define nl_handle nl_sock
c5121837
JM
41#define nl_handle_alloc_cb nl_socket_alloc_cb
42#define nl_handle_destroy nl_socket_free
43#endif /* CONFIG_LIBNL20 */
44
c5121837 45
3f5285e8
JM
46#ifndef IFF_LOWER_UP
47#define IFF_LOWER_UP 0x10000 /* driver signals L1 up */
48#endif
49#ifndef IFF_DORMANT
50#define IFF_DORMANT 0x20000 /* driver signals dormant */
51#endif
52
53#ifndef IF_OPER_DORMANT
54#define IF_OPER_DORMANT 5
55#endif
56#ifndef IF_OPER_UP
57#define IF_OPER_UP 6
58#endif
59
c5121837 60struct i802_bss {
a2e40bb6 61 struct wpa_driver_nl80211_data *drv;
c5121837 62 struct i802_bss *next;
b4fd6fab 63 int ifindex;
a2e40bb6 64 char ifname[IFNAMSIZ + 1];
c5121837
JM
65 unsigned int beacon_set:1;
66};
3f5285e8
JM
67
68struct wpa_driver_nl80211_data {
69 void *ctx;
08063178 70 struct netlink_data *netlink;
c5121837 71 int ioctl_sock; /* socket for ioctl() use */
94627f6c 72 char brname[IFNAMSIZ];
3f5285e8 73 int ifindex;
7524cfb1 74 int if_removed;
c2a04078
JM
75 struct wpa_driver_capa capa;
76 int has_capability;
c2a04078 77
3f5285e8
JM
78 int operstate;
79
3f5285e8
JM
80 int scan_complete_events;
81
82 struct nl_handle *nl_handle;
335ce76b 83 struct nl_handle *nl_handle_event;
3f5285e8 84 struct nl_cache *nl_cache;
335ce76b 85 struct nl_cache *nl_cache_event;
3f5285e8
JM
86 struct nl_cb *nl_cb;
87 struct genl_family *nl80211;
1c873584 88
e6b8efeb 89 u8 auth_bssid[ETH_ALEN];
c2a04078
JM
90 u8 bssid[ETH_ALEN];
91 int associated;
fd05d64e
JM
92 u8 ssid[32];
93 size_t ssid_len;
ad1e68e6
JM
94 int nlmode;
95 int ap_scan_as_station;
4832ecd7 96 unsigned int assoc_freq;
d2440ba0 97
0915d02c
JM
98 int monitor_sock;
99 int monitor_ifidx;
504e905c 100 int probe_req_report;
4e5cb1a3 101 int disable_11b_rates;
7da3abe7 102
55777702 103 unsigned int pending_remain_on_chan:1;
58f6fbe0 104 unsigned int pending_send_action:1;
94627f6c
JM
105 unsigned int added_bridge:1;
106 unsigned int added_if_into_bridge:1;
55777702
JM
107
108 u64 remain_on_chan_cookie;
58f6fbe0 109 u64 send_action_cookie;
c5121837 110
3812464c
JM
111 struct wpa_driver_scan_filter *filter_ssids;
112 size_t num_filter_ssids;
113
a2e40bb6
FF
114 struct i802_bss first_bss;
115
c5121837 116#ifdef HOSTAPD
c5121837 117 int eapol_sock; /* socket for EAPOL frames */
c5121837
JM
118
119 int default_if_indices[16];
120 int *if_indices;
121 int num_if_indices;
122
c5121837
JM
123 int last_freq;
124 int last_freq_ht;
c5121837 125#endif /* HOSTAPD */
3f5285e8
JM
126};
127
128
129static void wpa_driver_nl80211_scan_timeout(void *eloop_ctx,
130 void *timeout_ctx);
ad1e68e6 131static int wpa_driver_nl80211_set_mode(void *priv, int mode);
362f781e 132static int
7524cfb1 133wpa_driver_nl80211_finish_drv_init(struct wpa_driver_nl80211_data *drv);
d72aad94
JM
134static int wpa_driver_nl80211_mlme(struct wpa_driver_nl80211_data *drv,
135 const u8 *addr, int cmd, u16 reason_code);
460456f8
JM
136static void nl80211_remove_monitor_interface(
137 struct wpa_driver_nl80211_data *drv);
0915d02c 138
072ad14c 139#ifdef HOSTAPD
2135f224
JM
140static void add_ifidx(struct wpa_driver_nl80211_data *drv, int ifidx);
141static void del_ifidx(struct wpa_driver_nl80211_data *drv, int ifidx);
bbaf0837 142static int i802_set_freq(void *priv, struct hostapd_freq_params *freq);
fbbfcbac
FF
143static int wpa_driver_nl80211_if_remove(void *priv,
144 enum wpa_driver_if_type type,
145 const char *ifname);
072ad14c
JM
146#endif /* HOSTAPD */
147
504e905c
JM
148static void wpa_driver_nl80211_probe_req_report_timeout(void *eloop_ctx,
149 void *timeout_ctx);
4e5cb1a3
JM
150static int nl80211_disable_11b_rates(struct wpa_driver_nl80211_data *drv,
151 int ifindex, int disabled);
504e905c 152
3f5285e8 153
6241fcb1
JM
154/* nl80211 code */
155static int ack_handler(struct nl_msg *msg, void *arg)
156{
157 int *err = arg;
158 *err = 0;
159 return NL_STOP;
160}
161
162static int finish_handler(struct nl_msg *msg, void *arg)
163{
8e8df255
JM
164 int *ret = arg;
165 *ret = 0;
6241fcb1
JM
166 return NL_SKIP;
167}
168
169static int error_handler(struct sockaddr_nl *nla, struct nlmsgerr *err,
170 void *arg)
171{
172 int *ret = arg;
173 *ret = err->error;
174 return NL_SKIP;
175}
176
5b7b85f6
JM
177
178static int no_seq_check(struct nl_msg *msg, void *arg)
179{
180 return NL_OK;
181}
182
183
58f6fbe0
JM
184static int send_and_recv(struct wpa_driver_nl80211_data *drv,
185 struct nl_handle *nl_handle, struct nl_msg *msg,
186 int (*valid_handler)(struct nl_msg *, void *),
187 void *valid_data)
6241fcb1
JM
188{
189 struct nl_cb *cb;
190 int err = -ENOMEM;
191
192 cb = nl_cb_clone(drv->nl_cb);
193 if (!cb)
194 goto out;
195
58f6fbe0 196 err = nl_send_auto_complete(nl_handle, msg);
6241fcb1
JM
197 if (err < 0)
198 goto out;
199
200 err = 1;
201
202 nl_cb_err(cb, NL_CB_CUSTOM, error_handler, &err);
8e8df255 203 nl_cb_set(cb, NL_CB_FINISH, NL_CB_CUSTOM, finish_handler, &err);
6241fcb1
JM
204 nl_cb_set(cb, NL_CB_ACK, NL_CB_CUSTOM, ack_handler, &err);
205
206 if (valid_handler)
207 nl_cb_set(cb, NL_CB_VALID, NL_CB_CUSTOM,
208 valid_handler, valid_data);
209
210 while (err > 0)
58f6fbe0 211 nl_recvmsgs(nl_handle, cb);
6241fcb1
JM
212 out:
213 nl_cb_put(cb);
214 nlmsg_free(msg);
215 return err;
216}
217
218
58f6fbe0
JM
219static int send_and_recv_msgs(struct wpa_driver_nl80211_data *drv,
220 struct nl_msg *msg,
221 int (*valid_handler)(struct nl_msg *, void *),
222 void *valid_data)
223{
224 return send_and_recv(drv, drv->nl_handle, msg, valid_handler,
225 valid_data);
226}
227
228
97865538
JM
229struct family_data {
230 const char *group;
231 int id;
232};
233
234
235static int family_handler(struct nl_msg *msg, void *arg)
236{
237 struct family_data *res = arg;
238 struct nlattr *tb[CTRL_ATTR_MAX + 1];
239 struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
240 struct nlattr *mcgrp;
241 int i;
242
243 nla_parse(tb, CTRL_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
244 genlmsg_attrlen(gnlh, 0), NULL);
245 if (!tb[CTRL_ATTR_MCAST_GROUPS])
246 return NL_SKIP;
247
248 nla_for_each_nested(mcgrp, tb[CTRL_ATTR_MCAST_GROUPS], i) {
249 struct nlattr *tb2[CTRL_ATTR_MCAST_GRP_MAX + 1];
250 nla_parse(tb2, CTRL_ATTR_MCAST_GRP_MAX, nla_data(mcgrp),
251 nla_len(mcgrp), NULL);
252 if (!tb2[CTRL_ATTR_MCAST_GRP_NAME] ||
253 !tb2[CTRL_ATTR_MCAST_GRP_ID] ||
254 os_strncmp(nla_data(tb2[CTRL_ATTR_MCAST_GRP_NAME]),
255 res->group,
256 nla_len(tb2[CTRL_ATTR_MCAST_GRP_NAME])) != 0)
257 continue;
258 res->id = nla_get_u32(tb2[CTRL_ATTR_MCAST_GRP_ID]);
259 break;
260 };
261
262 return NL_SKIP;
263}
264
265
266static int nl_get_multicast_id(struct wpa_driver_nl80211_data *drv,
267 const char *family, const char *group)
268{
269 struct nl_msg *msg;
270 int ret = -1;
271 struct family_data res = { group, -ENOENT };
272
273 msg = nlmsg_alloc();
274 if (!msg)
275 return -ENOMEM;
276 genlmsg_put(msg, 0, 0, genl_ctrl_resolve(drv->nl_handle, "nlctrl"),
277 0, 0, CTRL_CMD_GETFAMILY, 0);
278 NLA_PUT_STRING(msg, CTRL_ATTR_FAMILY_NAME, family);
279
280 ret = send_and_recv_msgs(drv, msg, family_handler, &res);
281 msg = NULL;
282 if (ret == 0)
283 ret = res.id;
284
285nla_put_failure:
286 nlmsg_free(msg);
287 return ret;
288}
289
290
3f5285e8
JM
291static int wpa_driver_nl80211_get_bssid(void *priv, u8 *bssid)
292{
a2e40bb6
FF
293 struct i802_bss *bss = priv;
294 struct wpa_driver_nl80211_data *drv = bss->drv;
c2a04078
JM
295 if (!drv->associated)
296 return -1;
297 os_memcpy(bssid, drv->bssid, ETH_ALEN);
298 return 0;
3f5285e8
JM
299}
300
301
3f5285e8
JM
302static int wpa_driver_nl80211_get_ssid(void *priv, u8 *ssid)
303{
a2e40bb6
FF
304 struct i802_bss *bss = priv;
305 struct wpa_driver_nl80211_data *drv = bss->drv;
fd05d64e
JM
306 if (!drv->associated)
307 return -1;
308 os_memcpy(ssid, drv->ssid, drv->ssid_len);
309 return drv->ssid_len;
3f5285e8
JM
310}
311
312
7524cfb1 313static void wpa_driver_nl80211_event_link(struct wpa_driver_nl80211_data *drv,
08063178 314 char *buf, size_t len, int del)
3f5285e8
JM
315{
316 union wpa_event_data event;
317
318 os_memset(&event, 0, sizeof(event));
319 if (len > sizeof(event.interface_status.ifname))
320 len = sizeof(event.interface_status.ifname) - 1;
321 os_memcpy(event.interface_status.ifname, buf, len);
322 event.interface_status.ievent = del ? EVENT_INTERFACE_REMOVED :
323 EVENT_INTERFACE_ADDED;
324
325 wpa_printf(MSG_DEBUG, "RTM_%sLINK, IFLA_IFNAME: Interface '%s' %s",
326 del ? "DEL" : "NEW",
327 event.interface_status.ifname,
328 del ? "removed" : "added");
329
a2e40bb6 330 if (os_strcmp(drv->first_bss.ifname, event.interface_status.ifname) == 0) {
7524cfb1
JM
331 if (del)
332 drv->if_removed = 1;
333 else
334 drv->if_removed = 0;
335 }
336
08063178 337 wpa_supplicant_event(drv->ctx, EVENT_INTERFACE_STATUS, &event);
3f5285e8
JM
338}
339
340
7524cfb1 341static int wpa_driver_nl80211_own_ifname(struct wpa_driver_nl80211_data *drv,
62d680c3 342 u8 *buf, size_t len)
7524cfb1 343{
62d680c3 344 int attrlen, rta_len;
7524cfb1
JM
345 struct rtattr *attr;
346
62d680c3
JM
347 attrlen = len;
348 attr = (struct rtattr *) buf;
7524cfb1
JM
349
350 rta_len = RTA_ALIGN(sizeof(struct rtattr));
351 while (RTA_OK(attr, attrlen)) {
352 if (attr->rta_type == IFLA_IFNAME) {
a2e40bb6 353 if (os_strcmp(((char *) attr) + rta_len, drv->first_bss.ifname)
7524cfb1
JM
354 == 0)
355 return 1;
356 else
357 break;
358 }
359 attr = RTA_NEXT(attr, attrlen);
360 }
361
362 return 0;
363}
364
365
366static int wpa_driver_nl80211_own_ifindex(struct wpa_driver_nl80211_data *drv,
62d680c3 367 int ifindex, u8 *buf, size_t len)
7524cfb1
JM
368{
369 if (drv->ifindex == ifindex)
370 return 1;
371
62d680c3 372 if (drv->if_removed && wpa_driver_nl80211_own_ifname(drv, buf, len)) {
a2e40bb6 373 drv->first_bss.ifindex = if_nametoindex(drv->first_bss.ifname);
7524cfb1
JM
374 wpa_printf(MSG_DEBUG, "nl80211: Update ifindex for a removed "
375 "interface");
376 wpa_driver_nl80211_finish_drv_init(drv);
377 return 1;
378 }
379
380 return 0;
381}
382
383
62d680c3
JM
384static void wpa_driver_nl80211_event_rtm_newlink(void *ctx,
385 struct ifinfomsg *ifi,
386 u8 *buf, size_t len)
3f5285e8 387{
08063178 388 struct wpa_driver_nl80211_data *drv = ctx;
62d680c3
JM
389 int attrlen, rta_len;
390 struct rtattr *attr;
3f5285e8 391
62d680c3 392 if (!wpa_driver_nl80211_own_ifindex(drv, ifi->ifi_index, buf, len)) {
3f5285e8
JM
393 wpa_printf(MSG_DEBUG, "Ignore event for foreign ifindex %d",
394 ifi->ifi_index);
395 return;
396 }
397
398 wpa_printf(MSG_DEBUG, "RTM_NEWLINK: operstate=%d ifi_flags=0x%x "
399 "(%s%s%s%s)",
400 drv->operstate, ifi->ifi_flags,
401 (ifi->ifi_flags & IFF_UP) ? "[UP]" : "",
402 (ifi->ifi_flags & IFF_RUNNING) ? "[RUNNING]" : "",
403 (ifi->ifi_flags & IFF_LOWER_UP) ? "[LOWER_UP]" : "",
404 (ifi->ifi_flags & IFF_DORMANT) ? "[DORMANT]" : "");
405 /*
406 * Some drivers send the association event before the operup event--in
407 * this case, lifting operstate in wpa_driver_nl80211_set_operstate()
408 * fails. This will hit us when wpa_supplicant does not need to do
409 * IEEE 802.1X authentication
410 */
411 if (drv->operstate == 1 &&
412 (ifi->ifi_flags & (IFF_LOWER_UP | IFF_DORMANT)) == IFF_LOWER_UP &&
413 !(ifi->ifi_flags & IFF_RUNNING))
08063178 414 netlink_send_oper_ifla(drv->netlink, drv->ifindex,
e2d02c29 415 -1, IF_OPER_UP);
3f5285e8 416
62d680c3
JM
417 attrlen = len;
418 attr = (struct rtattr *) buf;
3f5285e8
JM
419 rta_len = RTA_ALIGN(sizeof(struct rtattr));
420 while (RTA_OK(attr, attrlen)) {
d8816397 421 if (attr->rta_type == IFLA_IFNAME) {
7524cfb1 422 wpa_driver_nl80211_event_link(
08063178 423 drv,
7524cfb1
JM
424 ((char *) attr) + rta_len,
425 attr->rta_len - rta_len, 0);
3f5285e8
JM
426 }
427 attr = RTA_NEXT(attr, attrlen);
428 }
429}
430
431
62d680c3
JM
432static void wpa_driver_nl80211_event_rtm_dellink(void *ctx,
433 struct ifinfomsg *ifi,
434 u8 *buf, size_t len)
3f5285e8 435{
08063178 436 struct wpa_driver_nl80211_data *drv = ctx;
62d680c3
JM
437 int attrlen, rta_len;
438 struct rtattr *attr;
3f5285e8 439
62d680c3
JM
440 attrlen = len;
441 attr = (struct rtattr *) buf;
3f5285e8
JM
442
443 rta_len = RTA_ALIGN(sizeof(struct rtattr));
444 while (RTA_OK(attr, attrlen)) {
445 if (attr->rta_type == IFLA_IFNAME) {
7524cfb1 446 wpa_driver_nl80211_event_link(
08063178 447 drv,
7524cfb1
JM
448 ((char *) attr) + rta_len,
449 attr->rta_len - rta_len, 1);
3f5285e8
JM
450 }
451 attr = RTA_NEXT(attr, attrlen);
452 }
453}
454
455
c2a04078
JM
456static void mlme_event_auth(struct wpa_driver_nl80211_data *drv,
457 const u8 *frame, size_t len)
458{
459 const struct ieee80211_mgmt *mgmt;
460 union wpa_event_data event;
461
462 mgmt = (const struct ieee80211_mgmt *) frame;
463 if (len < 24 + sizeof(mgmt->u.auth)) {
464 wpa_printf(MSG_DEBUG, "nl80211: Too short association event "
465 "frame");
466 return;
467 }
468
e6b8efeb 469 os_memcpy(drv->auth_bssid, mgmt->sa, ETH_ALEN);
c2a04078
JM
470 os_memset(&event, 0, sizeof(event));
471 os_memcpy(event.auth.peer, mgmt->sa, ETH_ALEN);
472 event.auth.auth_type = le_to_host16(mgmt->u.auth.auth_alg);
473 event.auth.status_code = le_to_host16(mgmt->u.auth.status_code);
474 if (len > 24 + sizeof(mgmt->u.auth)) {
475 event.auth.ies = mgmt->u.auth.variable;
476 event.auth.ies_len = len - 24 - sizeof(mgmt->u.auth);
477 }
478
479 wpa_supplicant_event(drv->ctx, EVENT_AUTH, &event);
480}
481
482
483static void mlme_event_assoc(struct wpa_driver_nl80211_data *drv,
484 const u8 *frame, size_t len)
485{
486 const struct ieee80211_mgmt *mgmt;
487 union wpa_event_data event;
488 u16 status;
489
490 mgmt = (const struct ieee80211_mgmt *) frame;
491 if (len < 24 + sizeof(mgmt->u.assoc_resp)) {
492 wpa_printf(MSG_DEBUG, "nl80211: Too short association event "
493 "frame");
494 return;
495 }
496
497 status = le_to_host16(mgmt->u.assoc_resp.status_code);
498 if (status != WLAN_STATUS_SUCCESS) {
efa46078
JM
499 os_memset(&event, 0, sizeof(event));
500 if (len > 24 + sizeof(mgmt->u.assoc_resp)) {
501 event.assoc_reject.resp_ies =
502 (u8 *) mgmt->u.assoc_resp.variable;
503 event.assoc_reject.resp_ies_len =
504 len - 24 - sizeof(mgmt->u.assoc_resp);
505 }
506 event.assoc_reject.status_code = status;
507
508 wpa_supplicant_event(drv->ctx, EVENT_ASSOC_REJECT, &event);
c2a04078
JM
509 return;
510 }
511
512 drv->associated = 1;
513 os_memcpy(drv->bssid, mgmt->sa, ETH_ALEN);
514
515 os_memset(&event, 0, sizeof(event));
516 if (len > 24 + sizeof(mgmt->u.assoc_resp)) {
517 event.assoc_info.resp_ies = (u8 *) mgmt->u.assoc_resp.variable;
518 event.assoc_info.resp_ies_len =
efa46078 519 len - 24 - sizeof(mgmt->u.assoc_resp);
c2a04078
JM
520 }
521
4832ecd7
JM
522 event.assoc_info.freq = drv->assoc_freq;
523
c2a04078
JM
524 wpa_supplicant_event(drv->ctx, EVENT_ASSOC, &event);
525}
526
c1bb3e0a 527
da72a1c1
ZY
528static void mlme_event_connect(struct wpa_driver_nl80211_data *drv,
529 enum nl80211_commands cmd, struct nlattr *status,
530 struct nlattr *addr, struct nlattr *req_ie,
531 struct nlattr *resp_ie)
532{
533 union wpa_event_data event;
534
7da2c527
JM
535 if (drv->capa.flags & WPA_DRIVER_FLAGS_SME) {
536 /*
537 * Avoid reporting two association events that would confuse
538 * the core code.
539 */
540 wpa_printf(MSG_DEBUG, "nl80211: Ignore connect event (cmd=%d) "
541 "when using userspace SME", cmd);
542 return;
543 }
544
da72a1c1
ZY
545 os_memset(&event, 0, sizeof(event));
546 if (cmd == NL80211_CMD_CONNECT &&
547 nla_get_u16(status) != WLAN_STATUS_SUCCESS) {
548 if (resp_ie) {
549 event.assoc_reject.resp_ies = nla_data(resp_ie);
550 event.assoc_reject.resp_ies_len = nla_len(resp_ie);
551 }
552 event.assoc_reject.status_code = nla_get_u16(status);
553 wpa_supplicant_event(drv->ctx, EVENT_ASSOC_REJECT, &event);
554 return;
555 }
556
557 drv->associated = 1;
558 if (addr)
559 os_memcpy(drv->bssid, nla_data(addr), ETH_ALEN);
560
561 if (req_ie) {
562 event.assoc_info.req_ies = nla_data(req_ie);
563 event.assoc_info.req_ies_len = nla_len(req_ie);
564 }
565 if (resp_ie) {
566 event.assoc_info.resp_ies = nla_data(resp_ie);
567 event.assoc_info.resp_ies_len = nla_len(resp_ie);
568 }
569
570 wpa_supplicant_event(drv->ctx, EVENT_ASSOC, &event);
571}
c2a04078 572
c1bb3e0a 573
da1fb17c
JM
574static void mlme_timeout_event(struct wpa_driver_nl80211_data *drv,
575 enum nl80211_commands cmd, struct nlattr *addr)
576{
577 union wpa_event_data event;
578 enum wpa_event_type ev;
579
580 if (nla_len(addr) != ETH_ALEN)
581 return;
582
583 wpa_printf(MSG_DEBUG, "nl80211: MLME event %d; timeout with " MACSTR,
584 cmd, MAC2STR((u8 *) nla_data(addr)));
585
586 if (cmd == NL80211_CMD_AUTHENTICATE)
587 ev = EVENT_AUTH_TIMED_OUT;
588 else if (cmd == NL80211_CMD_ASSOCIATE)
589 ev = EVENT_ASSOC_TIMED_OUT;
590 else
591 return;
592
593 os_memset(&event, 0, sizeof(event));
594 os_memcpy(event.timeout_event.addr, nla_data(addr), ETH_ALEN);
595 wpa_supplicant_event(drv->ctx, ev, &event);
596}
597
598
58f6fbe0
JM
599static void mlme_event_action(struct wpa_driver_nl80211_data *drv,
600 struct nlattr *freq, const u8 *frame, size_t len)
601{
602 const struct ieee80211_mgmt *mgmt;
603 union wpa_event_data event;
604 u16 fc, stype;
605
606 mgmt = (const struct ieee80211_mgmt *) frame;
607 if (len < 24) {
608 wpa_printf(MSG_DEBUG, "nl80211: Too short action frame");
609 return;
610 }
611
612 fc = le_to_host16(mgmt->frame_control);
613 stype = WLAN_FC_GET_STYPE(fc);
614
615 os_memset(&event, 0, sizeof(event));
616 event.rx_action.da = mgmt->da;
617 event.rx_action.sa = mgmt->sa;
618 event.rx_action.bssid = mgmt->bssid;
619 event.rx_action.category = mgmt->u.action.category;
620 event.rx_action.data = &mgmt->u.action.category + 1;
621 event.rx_action.len = frame + len - event.rx_action.data;
622 if (freq)
623 event.rx_action.freq = nla_get_u32(freq);
624 wpa_supplicant_event(drv->ctx, EVENT_RX_ACTION, &event);
625}
626
627
628static void mlme_event_action_tx_status(struct wpa_driver_nl80211_data *drv,
629 struct nlattr *cookie, const u8 *frame,
630 size_t len, struct nlattr *ack)
631{
632 union wpa_event_data event;
633 const struct ieee80211_hdr *hdr;
634 u16 fc;
635 u64 cookie_val;
636
637 if (!cookie)
638 return;
639
640 cookie_val = nla_get_u64(cookie);
641 wpa_printf(MSG_DEBUG, "nl80211: Action TX status: cookie=0%llx%s",
642 (long long unsigned int) cookie_val,
643 cookie_val == drv->send_action_cookie ?
644 " (match)" : " (unknown)");
645 if (cookie_val != drv->send_action_cookie)
646 return;
647
648 hdr = (const struct ieee80211_hdr *) frame;
649 fc = le_to_host16(hdr->frame_control);
650
651 os_memset(&event, 0, sizeof(event));
652 event.tx_status.type = WLAN_FC_GET_TYPE(fc);
653 event.tx_status.stype = WLAN_FC_GET_STYPE(fc);
654 event.tx_status.dst = hdr->addr1;
655 event.tx_status.data = frame;
656 event.tx_status.data_len = len;
657 event.tx_status.ack = ack != NULL;
658 wpa_supplicant_event(drv->ctx, EVENT_TX_STATUS, &event);
659}
660
661
c2a04078 662static void mlme_event(struct wpa_driver_nl80211_data *drv,
da1fb17c 663 enum nl80211_commands cmd, struct nlattr *frame,
58f6fbe0
JM
664 struct nlattr *addr, struct nlattr *timed_out,
665 struct nlattr *freq, struct nlattr *ack,
666 struct nlattr *cookie)
c2a04078 667{
da1fb17c
JM
668 if (timed_out && addr) {
669 mlme_timeout_event(drv, cmd, addr);
670 return;
671 }
672
c2a04078
JM
673 if (frame == NULL) {
674 wpa_printf(MSG_DEBUG, "nl80211: MLME event %d without frame "
675 "data", cmd);
676 return;
677 }
678
679 wpa_printf(MSG_DEBUG, "nl80211: MLME event %d", cmd);
680 wpa_hexdump(MSG_MSGDUMP, "nl80211: MLME event frame",
681 nla_data(frame), nla_len(frame));
682
683 switch (cmd) {
684 case NL80211_CMD_AUTHENTICATE:
685 mlme_event_auth(drv, nla_data(frame), nla_len(frame));
686 break;
687 case NL80211_CMD_ASSOCIATE:
688 mlme_event_assoc(drv, nla_data(frame), nla_len(frame));
689 break;
690 case NL80211_CMD_DEAUTHENTICATE:
691 drv->associated = 0;
692 wpa_supplicant_event(drv->ctx, EVENT_DEAUTH, NULL);
693 break;
694 case NL80211_CMD_DISASSOCIATE:
695 drv->associated = 0;
696 wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
697 break;
58f6fbe0
JM
698 case NL80211_CMD_ACTION:
699 mlme_event_action(drv, freq, nla_data(frame), nla_len(frame));
700 break;
701 case NL80211_CMD_ACTION_TX_STATUS:
702 mlme_event_action_tx_status(drv, cookie, nla_data(frame),
703 nla_len(frame), ack);
704 break;
c2a04078
JM
705 default:
706 break;
707 }
708}
709
710
35583f3f
JM
711static void mlme_event_michael_mic_failure(struct wpa_driver_nl80211_data *drv,
712 struct nlattr *tb[])
713{
714 union wpa_event_data data;
715
716 wpa_printf(MSG_DEBUG, "nl80211: MLME event Michael MIC failure");
717 os_memset(&data, 0, sizeof(data));
718 if (tb[NL80211_ATTR_MAC]) {
719 wpa_hexdump(MSG_DEBUG, "nl80211: Source MAC address",
720 nla_data(tb[NL80211_ATTR_MAC]),
721 nla_len(tb[NL80211_ATTR_MAC]));
ad1e68e6 722 data.michael_mic_failure.src = nla_data(tb[NL80211_ATTR_MAC]);
35583f3f
JM
723 }
724 if (tb[NL80211_ATTR_KEY_SEQ]) {
725 wpa_hexdump(MSG_DEBUG, "nl80211: TSC",
726 nla_data(tb[NL80211_ATTR_KEY_SEQ]),
727 nla_len(tb[NL80211_ATTR_KEY_SEQ]));
728 }
729 if (tb[NL80211_ATTR_KEY_TYPE]) {
730 enum nl80211_key_type key_type =
731 nla_get_u32(tb[NL80211_ATTR_KEY_TYPE]);
732 wpa_printf(MSG_DEBUG, "nl80211: Key Type %d", key_type);
733 if (key_type == NL80211_KEYTYPE_PAIRWISE)
734 data.michael_mic_failure.unicast = 1;
735 } else
736 data.michael_mic_failure.unicast = 1;
737
738 if (tb[NL80211_ATTR_KEY_IDX]) {
739 u8 key_id = nla_get_u8(tb[NL80211_ATTR_KEY_IDX]);
740 wpa_printf(MSG_DEBUG, "nl80211: Key Id %d", key_id);
741 }
742
743 wpa_supplicant_event(drv->ctx, EVENT_MICHAEL_MIC_FAILURE, &data);
744}
745
746
5cc4d64b
JM
747static void mlme_event_join_ibss(struct wpa_driver_nl80211_data *drv,
748 struct nlattr *tb[])
749{
750 if (tb[NL80211_ATTR_MAC] == NULL) {
751 wpa_printf(MSG_DEBUG, "nl80211: No address in IBSS joined "
752 "event");
753 return;
754 }
755 os_memcpy(drv->bssid, nla_data(tb[NL80211_ATTR_MAC]), ETH_ALEN);
756 drv->associated = 1;
757 wpa_printf(MSG_DEBUG, "nl80211: IBSS " MACSTR " joined",
758 MAC2STR(drv->bssid));
759
760 wpa_supplicant_event(drv->ctx, EVENT_ASSOC, NULL);
761}
762
763
55777702
JM
764static void mlme_event_remain_on_channel(struct wpa_driver_nl80211_data *drv,
765 int cancel_event, struct nlattr *tb[])
766{
767 unsigned int freq, chan_type, duration;
768 union wpa_event_data data;
769 u64 cookie;
770
771 if (tb[NL80211_ATTR_WIPHY_FREQ])
772 freq = nla_get_u32(tb[NL80211_ATTR_WIPHY_FREQ]);
773 else
774 freq = 0;
775
776 if (tb[NL80211_ATTR_WIPHY_CHANNEL_TYPE])
777 chan_type = nla_get_u32(tb[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
778 else
779 chan_type = 0;
780
781 if (tb[NL80211_ATTR_DURATION])
782 duration = nla_get_u32(tb[NL80211_ATTR_DURATION]);
783 else
784 duration = 0;
785
786 if (tb[NL80211_ATTR_COOKIE])
787 cookie = nla_get_u64(tb[NL80211_ATTR_COOKIE]);
788 else
789 cookie = 0;
790
791 wpa_printf(MSG_DEBUG, "nl80211: Remain-on-channel event (cancel=%d "
792 "freq=%u channel_type=%u duration=%u cookie=0x%llx (%s))",
793 cancel_event, freq, chan_type, duration,
794 (long long unsigned int) cookie,
795 cookie == drv->remain_on_chan_cookie ? "match" : "unknown");
796
797 if (cookie != drv->remain_on_chan_cookie)
798 return; /* not for us */
799
800 drv->pending_remain_on_chan = !cancel_event;
801
802 os_memset(&data, 0, sizeof(data));
803 data.remain_on_channel.freq = freq;
804 data.remain_on_channel.duration = duration;
805 wpa_supplicant_event(drv->ctx, cancel_event ?
806 EVENT_CANCEL_REMAIN_ON_CHANNEL :
807 EVENT_REMAIN_ON_CHANNEL, &data);
808}
809
810
8d923a4a
JM
811static void send_scan_event(struct wpa_driver_nl80211_data *drv, int aborted,
812 struct nlattr *tb[])
813{
814 union wpa_event_data event;
815 struct nlattr *nl;
816 int rem;
817 struct scan_info *info;
818#define MAX_REPORT_FREQS 50
819 int freqs[MAX_REPORT_FREQS];
820 int num_freqs = 0;
821
822 os_memset(&event, 0, sizeof(event));
823 info = &event.scan_info;
824 info->aborted = aborted;
825
826 if (tb[NL80211_ATTR_SCAN_SSIDS]) {
827 nla_for_each_nested(nl, tb[NL80211_ATTR_SCAN_SSIDS], rem) {
828 struct wpa_driver_scan_ssid *s =
829 &info->ssids[info->num_ssids];
830 s->ssid = nla_data(nl);
831 s->ssid_len = nla_len(nl);
832 info->num_ssids++;
833 if (info->num_ssids == WPAS_MAX_SCAN_SSIDS)
834 break;
835 }
836 }
837 if (tb[NL80211_ATTR_SCAN_FREQUENCIES]) {
838 nla_for_each_nested(nl, tb[NL80211_ATTR_SCAN_FREQUENCIES], rem)
839 {
840 freqs[num_freqs] = nla_get_u32(nl);
841 num_freqs++;
842 if (num_freqs == MAX_REPORT_FREQS - 1)
843 break;
844 }
845 info->freqs = freqs;
846 info->num_freqs = num_freqs;
847 }
848 wpa_supplicant_event(drv->ctx, EVENT_SCAN_RESULTS, &event);
849}
850
851
93910401
JM
852static void nl80211_cqm_event(struct wpa_driver_nl80211_data *drv,
853 struct nlattr *tb[])
854{
855 static struct nla_policy cqm_policy[NL80211_ATTR_CQM_MAX + 1] = {
856 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
857 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U8 },
858 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
859 };
860 struct nlattr *cqm[NL80211_ATTR_CQM_MAX + 1];
861 enum nl80211_cqm_rssi_threshold_event event;
b625473c 862 union wpa_event_data ed;
93910401
JM
863
864 if (tb[NL80211_ATTR_CQM] == NULL ||
865 nla_parse_nested(cqm, NL80211_ATTR_CQM_MAX, tb[NL80211_ATTR_CQM],
866 cqm_policy)) {
867 wpa_printf(MSG_DEBUG, "nl80211: Ignore invalid CQM event");
868 return;
869 }
870
871 if (cqm[NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] == NULL)
872 return;
873 event = nla_get_u32(cqm[NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT]);
b625473c
JM
874
875 os_memset(&ed, 0, sizeof(ed));
876
93910401
JM
877 if (event == NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH) {
878 wpa_printf(MSG_DEBUG, "nl80211: Connection quality monitor "
879 "event: RSSI high");
b625473c 880 ed.signal_change.above_threshold = 1;
93910401
JM
881 } else if (event == NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW) {
882 wpa_printf(MSG_DEBUG, "nl80211: Connection quality monitor "
883 "event: RSSI low");
b625473c
JM
884 ed.signal_change.above_threshold = 0;
885 } else
886 return;
887
888 wpa_supplicant_event(drv->ctx, EVENT_SIGNAL_CHANGE, &ed);
93910401
JM
889}
890
891
97865538
JM
892static int process_event(struct nl_msg *msg, void *arg)
893{
894 struct wpa_driver_nl80211_data *drv = arg;
895 struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
896 struct nlattr *tb[NL80211_ATTR_MAX + 1];
897
898 nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
899 genlmsg_attrlen(gnlh, 0), NULL);
900
901 if (tb[NL80211_ATTR_IFINDEX]) {
902 int ifindex = nla_get_u32(tb[NL80211_ATTR_IFINDEX]);
903 if (ifindex != drv->ifindex) {
904 wpa_printf(MSG_DEBUG, "nl80211: Ignored event (cmd=%d)"
905 " for foreign interface (ifindex %d)",
906 gnlh->cmd, ifindex);
907 return NL_SKIP;
908 }
909 }
910
ad1e68e6
JM
911 if (drv->ap_scan_as_station &&
912 (gnlh->cmd == NL80211_CMD_NEW_SCAN_RESULTS ||
913 gnlh->cmd == NL80211_CMD_SCAN_ABORTED)) {
a2e40bb6
FF
914 wpa_driver_nl80211_set_mode(&drv->first_bss,
915 IEEE80211_MODE_AP);
ad1e68e6
JM
916 drv->ap_scan_as_station = 0;
917 }
918
97865538 919 switch (gnlh->cmd) {
d942a79e
JM
920 case NL80211_CMD_TRIGGER_SCAN:
921 wpa_printf(MSG_DEBUG, "nl80211: Scan trigger");
922 break;
97865538
JM
923 case NL80211_CMD_NEW_SCAN_RESULTS:
924 wpa_printf(MSG_DEBUG, "nl80211: New scan results available");
925 drv->scan_complete_events = 1;
926 eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout, drv,
927 drv->ctx);
8d923a4a 928 send_scan_event(drv, 0, tb);
97865538
JM
929 break;
930 case NL80211_CMD_SCAN_ABORTED:
931 wpa_printf(MSG_DEBUG, "nl80211: Scan aborted");
932 /*
933 * Need to indicate that scan results are available in order
934 * not to make wpa_supplicant stop its scanning.
935 */
936 eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout, drv,
937 drv->ctx);
8d923a4a 938 send_scan_event(drv, 1, tb);
97865538 939 break;
c2a04078
JM
940 case NL80211_CMD_AUTHENTICATE:
941 case NL80211_CMD_ASSOCIATE:
942 case NL80211_CMD_DEAUTHENTICATE:
943 case NL80211_CMD_DISASSOCIATE:
58f6fbe0
JM
944 case NL80211_CMD_ACTION:
945 case NL80211_CMD_ACTION_TX_STATUS:
da1fb17c 946 mlme_event(drv, gnlh->cmd, tb[NL80211_ATTR_FRAME],
58f6fbe0
JM
947 tb[NL80211_ATTR_MAC], tb[NL80211_ATTR_TIMED_OUT],
948 tb[NL80211_ATTR_WIPHY_FREQ], tb[NL80211_ATTR_ACK],
949 tb[NL80211_ATTR_COOKIE]);
c2a04078 950 break;
da72a1c1
ZY
951 case NL80211_CMD_CONNECT:
952 case NL80211_CMD_ROAM:
953 mlme_event_connect(drv, gnlh->cmd,
954 tb[NL80211_ATTR_STATUS_CODE],
955 tb[NL80211_ATTR_MAC],
956 tb[NL80211_ATTR_REQ_IE],
957 tb[NL80211_ATTR_RESP_IE]);
958 break;
959 case NL80211_CMD_DISCONNECT:
7da2c527
JM
960 if (drv->capa.flags & WPA_DRIVER_FLAGS_SME) {
961 /*
962 * Avoid reporting two disassociation events that could
963 * confuse the core code.
964 */
965 wpa_printf(MSG_DEBUG, "nl80211: Ignore disconnect "
966 "event when using userspace SME");
967 break;
968 }
da72a1c1
ZY
969 drv->associated = 0;
970 wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
971 break;
35583f3f
JM
972 case NL80211_CMD_MICHAEL_MIC_FAILURE:
973 mlme_event_michael_mic_failure(drv, tb);
974 break;
5cc4d64b
JM
975 case NL80211_CMD_JOIN_IBSS:
976 mlme_event_join_ibss(drv, tb);
977 break;
55777702
JM
978 case NL80211_CMD_REMAIN_ON_CHANNEL:
979 mlme_event_remain_on_channel(drv, 0, tb);
980 break;
981 case NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL:
982 mlme_event_remain_on_channel(drv, 1, tb);
983 break;
93910401
JM
984 case NL80211_CMD_NOTIFY_CQM:
985 nl80211_cqm_event(drv, tb);
986 break;
97865538 987 default:
c2a04078
JM
988 wpa_printf(MSG_DEBUG, "nl80211: Ignored unknown event "
989 "(cmd=%d)", gnlh->cmd);
97865538
JM
990 break;
991 }
992
993 return NL_SKIP;
994}
995
996
997static void wpa_driver_nl80211_event_receive(int sock, void *eloop_ctx,
998 void *sock_ctx)
999{
1000 struct nl_cb *cb;
1001 struct wpa_driver_nl80211_data *drv = eloop_ctx;
1002
1003 wpa_printf(MSG_DEBUG, "nl80211: Event message available");
1004
1005 cb = nl_cb_clone(drv->nl_cb);
1006 if (!cb)
1007 return;
1008 nl_cb_set(cb, NL_CB_SEQ_CHECK, NL_CB_CUSTOM, no_seq_check, NULL);
1009 nl_cb_set(cb, NL_CB_VALID, NL_CB_CUSTOM, process_event, drv);
335ce76b 1010 nl_recvmsgs(drv->nl_handle_event, cb);
97865538
JM
1011 nl_cb_put(cb);
1012}
1013
1014
6d158490
LR
1015/**
1016 * wpa_driver_nl80211_set_country - ask nl80211 to set the regulatory domain
1017 * @priv: driver_nl80211 private data
1018 * @alpha2_arg: country to which to switch to
1019 * Returns: 0 on success, -1 on failure
1020 *
1021 * This asks nl80211 to set the regulatory domain for given
1022 * country ISO / IEC alpha2.
1023 */
1024static int wpa_driver_nl80211_set_country(void *priv, const char *alpha2_arg)
1025{
a2e40bb6
FF
1026 struct i802_bss *bss = priv;
1027 struct wpa_driver_nl80211_data *drv = bss->drv;
6d158490
LR
1028 char alpha2[3];
1029 struct nl_msg *msg;
1030
1031 msg = nlmsg_alloc();
1032 if (!msg)
e785c2ba 1033 return -ENOMEM;
6d158490
LR
1034
1035 alpha2[0] = alpha2_arg[0];
1036 alpha2[1] = alpha2_arg[1];
1037 alpha2[2] = '\0';
1038
1039 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
1040 0, NL80211_CMD_REQ_SET_REG, 0);
1041
1042 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, alpha2);
1043 if (send_and_recv_msgs(drv, msg, NULL, NULL))
1044 return -EINVAL;
1045 return 0;
1046nla_put_failure:
1047 return -EINVAL;
1048}
1049
1050
bbaf0837 1051#ifndef HOSTAPD
80bc75f1
JM
1052struct wiphy_info_data {
1053 int max_scan_ssids;
1581b38b 1054 int ap_supported;
93d11400
ZY
1055 int auth_supported;
1056 int connect_supported;
80bc75f1
JM
1057};
1058
1059
1060static int wiphy_info_handler(struct nl_msg *msg, void *arg)
1061{
1062 struct nlattr *tb[NL80211_ATTR_MAX + 1];
1063 struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
1064 struct wiphy_info_data *info = arg;
1065
1066 nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
1067 genlmsg_attrlen(gnlh, 0), NULL);
1068
1069 if (tb[NL80211_ATTR_MAX_NUM_SCAN_SSIDS])
1070 info->max_scan_ssids =
1071 nla_get_u8(tb[NL80211_ATTR_MAX_NUM_SCAN_SSIDS]);
1072
1581b38b
JM
1073 if (tb[NL80211_ATTR_SUPPORTED_IFTYPES]) {
1074 struct nlattr *nl_mode;
1075 int i;
1076 nla_for_each_nested(nl_mode,
1077 tb[NL80211_ATTR_SUPPORTED_IFTYPES], i) {
1078 if (nl_mode->nla_type == NL80211_IFTYPE_AP) {
1079 info->ap_supported = 1;
1080 break;
1081 }
1082 }
1083 }
1084
93d11400
ZY
1085 if (tb[NL80211_ATTR_SUPPORTED_COMMANDS]) {
1086 struct nlattr *nl_cmd;
1087 int i;
1088
1089 nla_for_each_nested(nl_cmd,
1090 tb[NL80211_ATTR_SUPPORTED_COMMANDS], i) {
1091 u32 cmd = nla_get_u32(nl_cmd);
1092 if (cmd == NL80211_CMD_AUTHENTICATE)
1093 info->auth_supported = 1;
1094 else if (cmd == NL80211_CMD_CONNECT)
1095 info->connect_supported = 1;
1096 }
1097 }
1098
80bc75f1
JM
1099 return NL_SKIP;
1100}
1101
1102
1103static int wpa_driver_nl80211_get_info(struct wpa_driver_nl80211_data *drv,
1104 struct wiphy_info_data *info)
1105{
1106 struct nl_msg *msg;
1107
1108 os_memset(info, 0, sizeof(*info));
1109 msg = nlmsg_alloc();
1110 if (!msg)
1111 return -1;
1112
1113 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
1114 0, NL80211_CMD_GET_WIPHY, 0);
1115
a2e40bb6 1116 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->first_bss.ifindex);
80bc75f1
JM
1117
1118 if (send_and_recv_msgs(drv, msg, wiphy_info_handler, info) == 0)
1119 return 0;
1120 msg = NULL;
1121nla_put_failure:
1122 nlmsg_free(msg);
1123 return -1;
1124}
1125
1126
93d11400 1127static int wpa_driver_nl80211_capa(struct wpa_driver_nl80211_data *drv)
80bc75f1
JM
1128{
1129 struct wiphy_info_data info;
1130 if (wpa_driver_nl80211_get_info(drv, &info))
93d11400 1131 return -1;
80bc75f1 1132 drv->has_capability = 1;
1b2a72e8
JM
1133 /* For now, assume TKIP, CCMP, WPA, WPA2 are supported */
1134 drv->capa.key_mgmt = WPA_DRIVER_CAPA_KEY_MGMT_WPA |
1135 WPA_DRIVER_CAPA_KEY_MGMT_WPA_PSK |
1136 WPA_DRIVER_CAPA_KEY_MGMT_WPA2 |
1137 WPA_DRIVER_CAPA_KEY_MGMT_WPA2_PSK;
1138 drv->capa.enc = WPA_DRIVER_CAPA_ENC_WEP40 |
1139 WPA_DRIVER_CAPA_ENC_WEP104 |
1140 WPA_DRIVER_CAPA_ENC_TKIP |
1141 WPA_DRIVER_CAPA_ENC_CCMP;
291b6068
JM
1142 drv->capa.auth = WPA_DRIVER_AUTH_OPEN |
1143 WPA_DRIVER_AUTH_SHARED |
1144 WPA_DRIVER_AUTH_LEAP;
1b2a72e8 1145
80bc75f1 1146 drv->capa.max_scan_ssids = info.max_scan_ssids;
1581b38b
JM
1147 if (info.ap_supported)
1148 drv->capa.flags |= WPA_DRIVER_FLAGS_AP;
93d11400
ZY
1149
1150 if (info.auth_supported)
1151 drv->capa.flags |= WPA_DRIVER_FLAGS_SME;
1152 else if (!info.connect_supported) {
1153 wpa_printf(MSG_INFO, "nl80211: Driver does not support "
1154 "authentication/association or connect commands");
1155 return -1;
1156 }
1157
0194fedb
JB
1158 drv->capa.flags |= WPA_DRIVER_FLAGS_SET_KEYS_AFTER_ASSOC_DONE;
1159
93d11400 1160 return 0;
80bc75f1 1161}
bbaf0837 1162#endif /* HOSTAPD */
80bc75f1
JM
1163
1164
9fff9fdc
JM
1165static int wpa_driver_nl80211_init_nl(struct wpa_driver_nl80211_data *drv,
1166 void *ctx)
3f5285e8 1167{
9fff9fdc 1168 int ret;
3f5285e8 1169
9fff9fdc 1170 /* Initialize generic netlink and nl80211 */
3f5285e8
JM
1171
1172 drv->nl_cb = nl_cb_alloc(NL_CB_DEFAULT);
1173 if (drv->nl_cb == NULL) {
1174 wpa_printf(MSG_ERROR, "nl80211: Failed to allocate netlink "
1175 "callbacks");
1176 goto err1;
1177 }
1178
1179 drv->nl_handle = nl_handle_alloc_cb(drv->nl_cb);
1180 if (drv->nl_handle == NULL) {
1181 wpa_printf(MSG_ERROR, "nl80211: Failed to allocate netlink "
1182 "callbacks");
1183 goto err2;
1184 }
1185
335ce76b
JM
1186 drv->nl_handle_event = nl_handle_alloc_cb(drv->nl_cb);
1187 if (drv->nl_handle_event == NULL) {
1188 wpa_printf(MSG_ERROR, "nl80211: Failed to allocate netlink "
1189 "callbacks (event)");
1190 goto err2b;
1191 }
1192
3f5285e8
JM
1193 if (genl_connect(drv->nl_handle)) {
1194 wpa_printf(MSG_ERROR, "nl80211: Failed to connect to generic "
1195 "netlink");
1196 goto err3;
1197 }
1198
335ce76b
JM
1199 if (genl_connect(drv->nl_handle_event)) {
1200 wpa_printf(MSG_ERROR, "nl80211: Failed to connect to generic "
1201 "netlink (event)");
1202 goto err3;
1203 }
1204
9fff9fdc
JM
1205#ifdef CONFIG_LIBNL20
1206 if (genl_ctrl_alloc_cache(drv->nl_handle, &drv->nl_cache) < 0) {
1207 wpa_printf(MSG_ERROR, "nl80211: Failed to allocate generic "
1208 "netlink cache");
1209 goto err3;
1210 }
335ce76b
JM
1211 if (genl_ctrl_alloc_cache(drv->nl_handle_event, &drv->nl_cache_event) <
1212 0) {
1213 wpa_printf(MSG_ERROR, "nl80211: Failed to allocate generic "
1214 "netlink cache (event)");
1215 goto err3b;
1216 }
9fff9fdc 1217#else /* CONFIG_LIBNL20 */
3f5285e8
JM
1218 drv->nl_cache = genl_ctrl_alloc_cache(drv->nl_handle);
1219 if (drv->nl_cache == NULL) {
1220 wpa_printf(MSG_ERROR, "nl80211: Failed to allocate generic "
1221 "netlink cache");
1222 goto err3;
1223 }
335ce76b
JM
1224 drv->nl_cache_event = genl_ctrl_alloc_cache(drv->nl_handle_event);
1225 if (drv->nl_cache_event == NULL) {
1226 wpa_printf(MSG_ERROR, "nl80211: Failed to allocate generic "
1227 "netlink cache (event)");
1228 goto err3b;
1229 }
9fff9fdc
JM
1230#endif /* CONFIG_LIBNL20 */
1231
3f5285e8
JM
1232 drv->nl80211 = genl_ctrl_search_by_name(drv->nl_cache, "nl80211");
1233 if (drv->nl80211 == NULL) {
1234 wpa_printf(MSG_ERROR, "nl80211: 'nl80211' generic netlink not "
1235 "found");
1236 goto err4;
1237 }
1238
97865538
JM
1239 ret = nl_get_multicast_id(drv, "nl80211", "scan");
1240 if (ret >= 0)
335ce76b 1241 ret = nl_socket_add_membership(drv->nl_handle_event, ret);
97865538
JM
1242 if (ret < 0) {
1243 wpa_printf(MSG_ERROR, "nl80211: Could not add multicast "
1244 "membership for scan events: %d (%s)",
1245 ret, strerror(-ret));
1246 goto err4;
1247 }
c2a04078
JM
1248
1249 ret = nl_get_multicast_id(drv, "nl80211", "mlme");
1250 if (ret >= 0)
335ce76b 1251 ret = nl_socket_add_membership(drv->nl_handle_event, ret);
c2a04078
JM
1252 if (ret < 0) {
1253 wpa_printf(MSG_ERROR, "nl80211: Could not add multicast "
1254 "membership for mlme events: %d (%s)",
1255 ret, strerror(-ret));
1256 goto err4;
1257 }
c2a04078 1258
335ce76b 1259 eloop_register_read_sock(nl_socket_get_fd(drv->nl_handle_event),
97865538
JM
1260 wpa_driver_nl80211_event_receive, drv, ctx);
1261
9fff9fdc
JM
1262 return 0;
1263
1264err4:
335ce76b
JM
1265 nl_cache_free(drv->nl_cache_event);
1266err3b:
9fff9fdc
JM
1267 nl_cache_free(drv->nl_cache);
1268err3:
335ce76b
JM
1269 nl_handle_destroy(drv->nl_handle_event);
1270err2b:
9fff9fdc
JM
1271 nl_handle_destroy(drv->nl_handle);
1272err2:
1273 nl_cb_put(drv->nl_cb);
1274err1:
1275 return -1;
1276}
1277
1278
1279/**
1280 * wpa_driver_nl80211_init - Initialize nl80211 driver interface
1281 * @ctx: context to be used when calling wpa_supplicant functions,
1282 * e.g., wpa_supplicant_event()
1283 * @ifname: interface name, e.g., wlan0
1284 * Returns: Pointer to private data, %NULL on failure
1285 */
1286static void * wpa_driver_nl80211_init(void *ctx, const char *ifname)
1287{
9fff9fdc 1288 struct wpa_driver_nl80211_data *drv;
08063178 1289 struct netlink_config *cfg;
a2e40bb6 1290 struct i802_bss *bss;
9fff9fdc
JM
1291
1292 drv = os_zalloc(sizeof(*drv));
1293 if (drv == NULL)
1294 return NULL;
1295 drv->ctx = ctx;
a2e40bb6
FF
1296 bss = &drv->first_bss;
1297 bss->drv = drv;
1298 os_strlcpy(bss->ifname, ifname, sizeof(bss->ifname));
9fff9fdc
JM
1299 drv->monitor_ifidx = -1;
1300 drv->monitor_sock = -1;
bbaf0837 1301 drv->ioctl_sock = -1;
9fff9fdc 1302
bbaf0837
JM
1303 if (wpa_driver_nl80211_init_nl(drv, ctx)) {
1304 os_free(drv);
1305 return NULL;
1306 }
9fff9fdc 1307
3f5285e8
JM
1308 drv->ioctl_sock = socket(PF_INET, SOCK_DGRAM, 0);
1309 if (drv->ioctl_sock < 0) {
1310 perror("socket(PF_INET,SOCK_DGRAM)");
bbaf0837 1311 goto failed;
3f5285e8
JM
1312 }
1313
08063178
JM
1314 cfg = os_zalloc(sizeof(*cfg));
1315 if (cfg == NULL)
1316 goto failed;
1317 cfg->ctx = drv;
1318 cfg->newlink_cb = wpa_driver_nl80211_event_rtm_newlink;
1319 cfg->dellink_cb = wpa_driver_nl80211_event_rtm_dellink;
1320 drv->netlink = netlink_init(cfg);
1321 if (drv->netlink == NULL) {
1322 os_free(cfg);
1323 goto failed;
1324 }
1325 if (wpa_driver_nl80211_finish_drv_init(drv))
bbaf0837 1326 goto failed;
7524cfb1 1327
a2e40bb6 1328 return bss;
7524cfb1 1329
bbaf0837 1330failed:
08063178 1331 netlink_deinit(drv->netlink);
bbaf0837
JM
1332 if (drv->ioctl_sock >= 0)
1333 close(drv->ioctl_sock);
1334
7524cfb1 1335 genl_family_put(drv->nl80211);
7524cfb1 1336 nl_cache_free(drv->nl_cache);
7524cfb1 1337 nl_handle_destroy(drv->nl_handle);
7524cfb1 1338 nl_cb_put(drv->nl_cb);
05ba8690 1339 eloop_unregister_read_sock(nl_socket_get_fd(drv->nl_handle_event));
bbaf0837 1340
7524cfb1
JM
1341 os_free(drv);
1342 return NULL;
1343}
1344
1345
58f6fbe0
JM
1346static int nl80211_register_action_frame(struct wpa_driver_nl80211_data *drv,
1347 const u8 *match, size_t match_len)
1348{
1349 struct nl_msg *msg;
1350 int ret = -1;
1351
1352 msg = nlmsg_alloc();
1353 if (!msg)
1354 return -1;
1355
1356 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
1357 NL80211_CMD_REGISTER_ACTION, 0);
1358
1359 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
1360 NLA_PUT(msg, NL80211_ATTR_FRAME_MATCH, match_len, match);
1361
1362 ret = send_and_recv(drv, drv->nl_handle_event, msg, NULL, NULL);
1363 msg = NULL;
1364 if (ret) {
1365 wpa_printf(MSG_DEBUG, "nl80211: Register Action command "
1366 "failed: ret=%d (%s)", ret, strerror(-ret));
1367 wpa_hexdump(MSG_DEBUG, "nl80211: Register Action match",
1368 match, match_len);
1369 goto nla_put_failure;
1370 }
1371 ret = 0;
1372nla_put_failure:
1373 nlmsg_free(msg);
1374 return ret;
1375}
1376
1377
1378static int nl80211_register_action_frames(struct wpa_driver_nl80211_data *drv)
1379{
1380 if (0) {
1381 /* Public Action frames */
1382 return nl80211_register_action_frame(drv, (u8 *) "\x04", 1);
1383 }
7b90c16a
JM
1384
1385 /* FT Action frames */
1386 if (nl80211_register_action_frame(drv, (u8 *) "\x06", 1) < 0)
1387 return -1;
1388 else
1389 drv->capa.key_mgmt |= WPA_DRIVER_CAPA_KEY_MGMT_FT |
1390 WPA_DRIVER_CAPA_KEY_MGMT_FT_PSK;
1391
58f6fbe0
JM
1392 return 0;
1393}
1394
1395
362f781e 1396static int
7524cfb1
JM
1397wpa_driver_nl80211_finish_drv_init(struct wpa_driver_nl80211_data *drv)
1398{
a2e40bb6
FF
1399 struct i802_bss *bss = &drv->first_bss;
1400
1401 drv->ifindex = if_nametoindex(bss->ifname);
1402 drv->first_bss.ifindex = drv->ifindex;
a87c9d96 1403
bbaf0837 1404#ifndef HOSTAPD
a2e40bb6 1405 if (wpa_driver_nl80211_set_mode(bss, IEEE80211_MODE_INFRA) < 0) {
a87c9d96
JM
1406 wpa_printf(MSG_DEBUG, "nl80211: Could not configure driver to "
1407 "use managed mode");
1408 }
1409
a2e40bb6 1410 if (linux_set_iface_flags(drv->ioctl_sock, bss->ifname, 1)) {
34f2f814 1411 wpa_printf(MSG_ERROR, "Could not set interface '%s' UP",
a2e40bb6 1412 bss->ifname);
362f781e
JM
1413 return -1;
1414 }
3f5285e8 1415
93d11400
ZY
1416 if (wpa_driver_nl80211_capa(drv))
1417 return -1;
80bc75f1 1418
08063178 1419 netlink_send_oper_ifla(drv->netlink, drv->ifindex,
e2d02c29 1420 1, IF_OPER_DORMANT);
bbaf0837 1421#endif /* HOSTAPD */
362f781e 1422
7b90c16a
JM
1423 if (nl80211_register_action_frames(drv) < 0) {
1424 wpa_printf(MSG_DEBUG, "nl80211: Failed to register Action "
1425 "frame processing - ignore for now");
1426 /*
1427 * Older kernel versions did not support this, so ignore the
1428 * error for now. Some functionality may not be available
1429 * because of this.
1430 */
1431 }
58f6fbe0 1432
362f781e 1433 return 0;
3f5285e8
JM
1434}
1435
1436
8a27af5c
JM
1437static int wpa_driver_nl80211_del_beacon(struct wpa_driver_nl80211_data *drv)
1438{
1439 struct nl_msg *msg;
1440
1441 msg = nlmsg_alloc();
1442 if (!msg)
1443 return -ENOMEM;
1444
1445 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
1446 0, NL80211_CMD_DEL_BEACON, 0);
1447 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
1448
1449 return send_and_recv_msgs(drv, msg, NULL, NULL);
1450 nla_put_failure:
1451 return -ENOBUFS;
1452}
8a27af5c
JM
1453
1454
3f5285e8 1455/**
7e5ba1b9
JM
1456 * wpa_driver_nl80211_deinit - Deinitialize nl80211 driver interface
1457 * @priv: Pointer to private nl80211 data from wpa_driver_nl80211_init()
3f5285e8
JM
1458 *
1459 * Shut down driver interface and processing of driver events. Free
1460 * private data buffer if one was allocated in wpa_driver_nl80211_init().
1461 */
7e5ba1b9 1462static void wpa_driver_nl80211_deinit(void *priv)
3f5285e8 1463{
a2e40bb6
FF
1464 struct i802_bss *bss = priv;
1465 struct wpa_driver_nl80211_data *drv = bss->drv;
3f5285e8 1466
94627f6c 1467 if (drv->added_if_into_bridge) {
a2e40bb6 1468 if (linux_br_del_if(drv->ioctl_sock, drv->brname, bss->ifname)
94627f6c
JM
1469 < 0)
1470 wpa_printf(MSG_INFO, "nl80211: Failed to remove "
1471 "interface %s from bridge %s: %s",
a2e40bb6 1472 bss->ifname, drv->brname, strerror(errno));
94627f6c
JM
1473 }
1474 if (drv->added_bridge) {
1475 if (linux_br_del(drv->ioctl_sock, drv->brname) < 0)
1476 wpa_printf(MSG_INFO, "nl80211: Failed to remove "
1477 "bridge %s: %s",
1478 drv->brname, strerror(errno));
1479 }
1480
460456f8 1481 nl80211_remove_monitor_interface(drv);
8a27af5c
JM
1482
1483 if (drv->nlmode == NL80211_IFTYPE_AP)
1484 wpa_driver_nl80211_del_beacon(drv);
0915d02c 1485
bbaf0837
JM
1486#ifdef HOSTAPD
1487 if (drv->last_freq_ht) {
1488 /* Clear HT flags from the driver */
1489 struct hostapd_freq_params freq;
1490 os_memset(&freq, 0, sizeof(freq));
1491 freq.freq = drv->last_freq;
1492 i802_set_freq(priv, &freq);
1493 }
1494
bbaf0837
JM
1495 if (drv->eapol_sock >= 0) {
1496 eloop_unregister_read_sock(drv->eapol_sock);
1497 close(drv->eapol_sock);
1498 }
1499
1500 if (drv->if_indices != drv->default_if_indices)
1501 os_free(drv->if_indices);
1b648c7e 1502#endif /* HOSTAPD */
3f5285e8 1503
4e5cb1a3
JM
1504 if (drv->disable_11b_rates)
1505 nl80211_disable_11b_rates(drv, drv->ifindex, 0);
1506
08063178
JM
1507 netlink_send_oper_ifla(drv->netlink, drv->ifindex, 0, IF_OPER_UP);
1508 netlink_deinit(drv->netlink);
3f5285e8 1509
bbaf0837
JM
1510 eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout, drv, drv->ctx);
1511
a2e40bb6
FF
1512 (void) linux_set_iface_flags(drv->ioctl_sock, bss->ifname, 0);
1513 wpa_driver_nl80211_set_mode(bss, IEEE80211_MODE_INFRA);
3f5285e8 1514
bbaf0837
JM
1515 if (drv->ioctl_sock >= 0)
1516 close(drv->ioctl_sock);
3f5285e8 1517
335ce76b 1518 eloop_unregister_read_sock(nl_socket_get_fd(drv->nl_handle_event));
3f5285e8
JM
1519 genl_family_put(drv->nl80211);
1520 nl_cache_free(drv->nl_cache);
335ce76b 1521 nl_cache_free(drv->nl_cache_event);
3f5285e8 1522 nl_handle_destroy(drv->nl_handle);
335ce76b 1523 nl_handle_destroy(drv->nl_handle_event);
3f5285e8
JM
1524 nl_cb_put(drv->nl_cb);
1525
504e905c
JM
1526 eloop_cancel_timeout(wpa_driver_nl80211_probe_req_report_timeout,
1527 drv, NULL);
1528
3812464c
JM
1529 os_free(drv->filter_ssids);
1530
3f5285e8
JM
1531 os_free(drv);
1532}
1533
1534
1535/**
1536 * wpa_driver_nl80211_scan_timeout - Scan timeout to report scan completion
ad1e68e6 1537 * @eloop_ctx: Driver private data
3f5285e8
JM
1538 * @timeout_ctx: ctx argument given to wpa_driver_nl80211_init()
1539 *
1540 * This function can be used as registered timeout when starting a scan to
1541 * generate a scan completed event if the driver does not report this.
1542 */
1543static void wpa_driver_nl80211_scan_timeout(void *eloop_ctx, void *timeout_ctx)
1544{
ad1e68e6
JM
1545 struct wpa_driver_nl80211_data *drv = eloop_ctx;
1546 if (drv->ap_scan_as_station) {
a2e40bb6
FF
1547 wpa_driver_nl80211_set_mode(&drv->first_bss,
1548 IEEE80211_MODE_AP);
ad1e68e6
JM
1549 drv->ap_scan_as_station = 0;
1550 }
3f5285e8
JM
1551 wpa_printf(MSG_DEBUG, "Scan timeout - try to get results");
1552 wpa_supplicant_event(timeout_ctx, EVENT_SCAN_RESULTS, NULL);
1553}
1554
1555
1556/**
1557 * wpa_driver_nl80211_scan - Request the driver to initiate scan
ad1e68e6 1558 * @priv: Pointer to private driver data from wpa_driver_nl80211_init()
6a1063e0 1559 * @params: Scan parameters
3f5285e8
JM
1560 * Returns: 0 on success, -1 on failure
1561 */
6a1063e0
JM
1562static int wpa_driver_nl80211_scan(void *priv,
1563 struct wpa_driver_scan_params *params)
3f5285e8 1564{
a2e40bb6
FF
1565 struct i802_bss *bss = priv;
1566 struct wpa_driver_nl80211_data *drv = bss->drv;
3f5285e8 1567 int ret = 0, timeout;
d3a98225 1568 struct nl_msg *msg, *ssids, *freqs;
6a1063e0 1569 size_t i;
3f5285e8 1570
0e75527f
JM
1571 msg = nlmsg_alloc();
1572 ssids = nlmsg_alloc();
d3a98225
JM
1573 freqs = nlmsg_alloc();
1574 if (!msg || !ssids || !freqs) {
0e75527f
JM
1575 nlmsg_free(msg);
1576 nlmsg_free(ssids);
d3a98225 1577 nlmsg_free(freqs);
3f5285e8
JM
1578 return -1;
1579 }
1580
3812464c
JM
1581 os_free(drv->filter_ssids);
1582 drv->filter_ssids = params->filter_ssids;
1583 params->filter_ssids = NULL;
1584 drv->num_filter_ssids = params->num_filter_ssids;
1585
0e75527f
JM
1586 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
1587 NL80211_CMD_TRIGGER_SCAN, 0);
1588
1589 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
3f5285e8 1590
6a1063e0 1591 for (i = 0; i < params->num_ssids; i++) {
9fad706c
JM
1592 wpa_hexdump_ascii(MSG_MSGDUMP, "nl80211: Scan SSID",
1593 params->ssids[i].ssid,
1594 params->ssids[i].ssid_len);
6a1063e0
JM
1595 NLA_PUT(ssids, i + 1, params->ssids[i].ssid_len,
1596 params->ssids[i].ssid);
3f5285e8 1597 }
6a1063e0
JM
1598 if (params->num_ssids)
1599 nla_put_nested(msg, NL80211_ATTR_SCAN_SSIDS, ssids);
3f5285e8 1600
d173df52 1601 if (params->extra_ies) {
9fad706c
JM
1602 wpa_hexdump_ascii(MSG_MSGDUMP, "nl80211: Scan extra IEs",
1603 params->extra_ies, params->extra_ies_len);
d173df52
JM
1604 NLA_PUT(msg, NL80211_ATTR_IE, params->extra_ies_len,
1605 params->extra_ies);
1606 }
1607
d3a98225 1608 if (params->freqs) {
9fad706c
JM
1609 for (i = 0; params->freqs[i]; i++) {
1610 wpa_printf(MSG_MSGDUMP, "nl80211: Scan frequency %u "
1611 "MHz", params->freqs[i]);
d3a98225 1612 NLA_PUT_U32(freqs, i + 1, params->freqs[i]);
9fad706c 1613 }
d3a98225
JM
1614 nla_put_nested(msg, NL80211_ATTR_SCAN_FREQUENCIES, freqs);
1615 }
1616
0e75527f
JM
1617 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
1618 msg = NULL;
1619 if (ret) {
1620 wpa_printf(MSG_DEBUG, "nl80211: Scan trigger failed: ret=%d "
1621 "(%s)", ret, strerror(-ret));
ad1e68e6
JM
1622#ifdef HOSTAPD
1623 if (drv->nlmode == NL80211_IFTYPE_AP) {
1624 /*
1625 * mac80211 does not allow scan requests in AP mode, so
1626 * try to do this in station mode.
1627 */
a2e40bb6 1628 if (wpa_driver_nl80211_set_mode(bss,
ad1e68e6
JM
1629 IEEE80211_MODE_INFRA))
1630 goto nla_put_failure;
1631
1632 if (wpa_driver_nl80211_scan(drv, params)) {
a2e40bb6 1633 wpa_driver_nl80211_set_mode(bss,
ad1e68e6
JM
1634 IEEE80211_MODE_AP);
1635 goto nla_put_failure;
1636 }
1637
1638 /* Restore AP mode when processing scan results */
1639 drv->ap_scan_as_station = 1;
1640 ret = 0;
1641 } else
1642 goto nla_put_failure;
1643#else /* HOSTAPD */
0e75527f 1644 goto nla_put_failure;
ad1e68e6 1645#endif /* HOSTAPD */
3f5285e8
JM
1646 }
1647
1648 /* Not all drivers generate "scan completed" wireless event, so try to
1649 * read results after a timeout. */
0e75527f 1650 timeout = 10;
3f5285e8
JM
1651 if (drv->scan_complete_events) {
1652 /*
d173df52
JM
1653 * The driver seems to deliver events to notify when scan is
1654 * complete, so use longer timeout to avoid race conditions
1655 * with scanning and following association request.
3f5285e8
JM
1656 */
1657 timeout = 30;
1658 }
1659 wpa_printf(MSG_DEBUG, "Scan requested (ret=%d) - scan timeout %d "
1660 "seconds", ret, timeout);
1661 eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout, drv, drv->ctx);
0e75527f
JM
1662 eloop_register_timeout(timeout, 0, wpa_driver_nl80211_scan_timeout,
1663 drv, drv->ctx);
3f5285e8 1664
0e75527f
JM
1665nla_put_failure:
1666 nlmsg_free(ssids);
1667 nlmsg_free(msg);
d3a98225 1668 nlmsg_free(freqs);
3f5285e8
JM
1669 return ret;
1670}
1671
1672
3812464c
JM
1673static const u8 * nl80211_get_ie(const u8 *ies, size_t ies_len, u8 ie)
1674{
1675 const u8 *end, *pos;
1676
1677 if (ies == NULL)
1678 return NULL;
1679
1680 pos = ies;
1681 end = ies + ies_len;
1682
1683 while (pos + 1 < end) {
1684 if (pos + 2 + pos[1] > end)
1685 break;
1686 if (pos[0] == ie)
1687 return pos;
1688 pos += 2 + pos[1];
1689 }
1690
1691 return NULL;
1692}
1693
1694
1695static int nl80211_scan_filtered(struct wpa_driver_nl80211_data *drv,
1696 const u8 *ie, size_t ie_len)
1697{
1698 const u8 *ssid;
1699 size_t i;
1700
1701 if (drv->filter_ssids == NULL)
1702 return 0;
1703
1704 ssid = nl80211_get_ie(ie, ie_len, WLAN_EID_SSID);
1705 if (ssid == NULL)
1706 return 1;
1707
1708 for (i = 0; i < drv->num_filter_ssids; i++) {
1709 if (ssid[1] == drv->filter_ssids[i].ssid_len &&
1710 os_memcmp(ssid + 2, drv->filter_ssids[i].ssid, ssid[1]) ==
1711 0)
1712 return 0;
1713 }
1714
1715 return 1;
1716}
1717
1718
1719struct nl80211_bss_info_arg {
1720 struct wpa_driver_nl80211_data *drv;
1721 struct wpa_scan_results *res;
1722};
1723
b3db1e1c 1724static int bss_info_handler(struct nl_msg *msg, void *arg)
3f5285e8 1725{
b3db1e1c
JM
1726 struct nlattr *tb[NL80211_ATTR_MAX + 1];
1727 struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
1728 struct nlattr *bss[NL80211_BSS_MAX + 1];
1729 static struct nla_policy bss_policy[NL80211_BSS_MAX + 1] = {
1730 [NL80211_BSS_BSSID] = { .type = NLA_UNSPEC },
1731 [NL80211_BSS_FREQUENCY] = { .type = NLA_U32 },
1732 [NL80211_BSS_TSF] = { .type = NLA_U64 },
1733 [NL80211_BSS_BEACON_INTERVAL] = { .type = NLA_U16 },
1734 [NL80211_BSS_CAPABILITY] = { .type = NLA_U16 },
1735 [NL80211_BSS_INFORMATION_ELEMENTS] = { .type = NLA_UNSPEC },
1736 [NL80211_BSS_SIGNAL_MBM] = { .type = NLA_U32 },
1737 [NL80211_BSS_SIGNAL_UNSPEC] = { .type = NLA_U8 },
e6b8efeb 1738 [NL80211_BSS_STATUS] = { .type = NLA_U32 },
b3ad11bb 1739 [NL80211_BSS_SEEN_MS_AGO] = { .type = NLA_U32 },
8c090654 1740 [NL80211_BSS_BEACON_IES] = { .type = NLA_UNSPEC },
b3db1e1c 1741 };
3812464c
JM
1742 struct nl80211_bss_info_arg *_arg = arg;
1743 struct wpa_scan_results *res = _arg->res;
3f5285e8
JM
1744 struct wpa_scan_res **tmp;
1745 struct wpa_scan_res *r;
8c090654
JM
1746 const u8 *ie, *beacon_ie;
1747 size_t ie_len, beacon_ie_len;
1748 u8 *pos;
3f5285e8 1749
b3db1e1c
JM
1750 nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
1751 genlmsg_attrlen(gnlh, 0), NULL);
1752 if (!tb[NL80211_ATTR_BSS])
1753 return NL_SKIP;
1754 if (nla_parse_nested(bss, NL80211_BSS_MAX, tb[NL80211_ATTR_BSS],
1755 bss_policy))
1756 return NL_SKIP;
1757 if (bss[NL80211_BSS_INFORMATION_ELEMENTS]) {
1758 ie = nla_data(bss[NL80211_BSS_INFORMATION_ELEMENTS]);
1759 ie_len = nla_len(bss[NL80211_BSS_INFORMATION_ELEMENTS]);
1760 } else {
1761 ie = NULL;
1762 ie_len = 0;
1763 }
8c090654
JM
1764 if (bss[NL80211_BSS_BEACON_IES]) {
1765 beacon_ie = nla_data(bss[NL80211_BSS_BEACON_IES]);
1766 beacon_ie_len = nla_len(bss[NL80211_BSS_BEACON_IES]);
1767 } else {
1768 beacon_ie = NULL;
1769 beacon_ie_len = 0;
1770 }
3f5285e8 1771
3812464c
JM
1772 if (nl80211_scan_filtered(_arg->drv, ie ? ie : beacon_ie,
1773 ie ? ie_len : beacon_ie_len))
1774 return NL_SKIP;
1775
8c090654 1776 r = os_zalloc(sizeof(*r) + ie_len + beacon_ie_len);
3f5285e8 1777 if (r == NULL)
b3db1e1c
JM
1778 return NL_SKIP;
1779 if (bss[NL80211_BSS_BSSID])
1780 os_memcpy(r->bssid, nla_data(bss[NL80211_BSS_BSSID]),
1781 ETH_ALEN);
1782 if (bss[NL80211_BSS_FREQUENCY])
1783 r->freq = nla_get_u32(bss[NL80211_BSS_FREQUENCY]);
1784 if (bss[NL80211_BSS_BEACON_INTERVAL])
1785 r->beacon_int = nla_get_u16(bss[NL80211_BSS_BEACON_INTERVAL]);
1786 if (bss[NL80211_BSS_CAPABILITY])
1787 r->caps = nla_get_u16(bss[NL80211_BSS_CAPABILITY]);
7c2849d2
JM
1788 r->flags |= WPA_SCAN_NOISE_INVALID;
1789 if (bss[NL80211_BSS_SIGNAL_MBM]) {
b3db1e1c 1790 r->level = nla_get_u32(bss[NL80211_BSS_SIGNAL_MBM]);
7c2849d2
JM
1791 r->level /= 100; /* mBm to dBm */
1792 r->flags |= WPA_SCAN_LEVEL_DBM | WPA_SCAN_QUAL_INVALID;
1793 } else if (bss[NL80211_BSS_SIGNAL_UNSPEC]) {
1794 r->level = nla_get_u8(bss[NL80211_BSS_SIGNAL_UNSPEC]);
1795 r->flags |= WPA_SCAN_LEVEL_INVALID;
1796 } else
1797 r->flags |= WPA_SCAN_LEVEL_INVALID | WPA_SCAN_QUAL_INVALID;
b3db1e1c
JM
1798 if (bss[NL80211_BSS_TSF])
1799 r->tsf = nla_get_u64(bss[NL80211_BSS_TSF]);
b3ad11bb
JM
1800 if (bss[NL80211_BSS_SEEN_MS_AGO])
1801 r->age = nla_get_u32(bss[NL80211_BSS_SEEN_MS_AGO]);
b3db1e1c 1802 r->ie_len = ie_len;
8c090654
JM
1803 pos = (u8 *) (r + 1);
1804 if (ie) {
1805 os_memcpy(pos, ie, ie_len);
1806 pos += ie_len;
1807 }
1808 r->beacon_ie_len = beacon_ie_len;
1809 if (beacon_ie)
1810 os_memcpy(pos, beacon_ie, beacon_ie_len);
3f5285e8 1811
e6b8efeb
JM
1812 if (bss[NL80211_BSS_STATUS]) {
1813 enum nl80211_bss_status status;
1814 status = nla_get_u32(bss[NL80211_BSS_STATUS]);
1815 switch (status) {
1816 case NL80211_BSS_STATUS_AUTHENTICATED:
1817 r->flags |= WPA_SCAN_AUTHENTICATED;
1818 break;
1819 case NL80211_BSS_STATUS_ASSOCIATED:
1820 r->flags |= WPA_SCAN_ASSOCIATED;
1821 break;
1822 default:
1823 break;
1824 }
1825 }
1826
3f5285e8
JM
1827 tmp = os_realloc(res->res,
1828 (res->num + 1) * sizeof(struct wpa_scan_res *));
1829 if (tmp == NULL) {
1830 os_free(r);
b3db1e1c 1831 return NL_SKIP;
3f5285e8
JM
1832 }
1833 tmp[res->num++] = r;
1834 res->res = tmp;
b3db1e1c
JM
1835
1836 return NL_SKIP;
3f5285e8 1837}
b3db1e1c 1838
3f5285e8 1839
d72aad94
JM
1840static void clear_state_mismatch(struct wpa_driver_nl80211_data *drv,
1841 const u8 *addr)
1842{
1843 if (drv->capa.flags & WPA_DRIVER_FLAGS_SME) {
1844 wpa_printf(MSG_DEBUG, "nl80211: Clear possible state "
582507be 1845 "mismatch (" MACSTR ")", MAC2STR(addr));
d72aad94
JM
1846 wpa_driver_nl80211_mlme(drv, addr,
1847 NL80211_CMD_DEAUTHENTICATE,
1848 WLAN_REASON_PREV_AUTH_NOT_VALID);
1849 }
1850}
1851
1852
e6b8efeb
JM
1853static void wpa_driver_nl80211_check_bss_status(
1854 struct wpa_driver_nl80211_data *drv, struct wpa_scan_results *res)
1855{
1856 size_t i;
1857
1858 for (i = 0; i < res->num; i++) {
1859 struct wpa_scan_res *r = res->res[i];
1860 if (r->flags & WPA_SCAN_AUTHENTICATED) {
1861 wpa_printf(MSG_DEBUG, "nl80211: Scan results "
1862 "indicates BSS status with " MACSTR
1863 " as authenticated",
1864 MAC2STR(r->bssid));
1865 if (drv->nlmode == NL80211_IFTYPE_STATION &&
1866 os_memcmp(r->bssid, drv->bssid, ETH_ALEN) != 0 &&
1867 os_memcmp(r->bssid, drv->auth_bssid, ETH_ALEN) !=
1868 0) {
1869 wpa_printf(MSG_DEBUG, "nl80211: Unknown BSSID"
1870 " in local state (auth=" MACSTR
1871 " assoc=" MACSTR ")",
1872 MAC2STR(drv->auth_bssid),
1873 MAC2STR(drv->bssid));
582507be 1874 clear_state_mismatch(drv, r->bssid);
e6b8efeb
JM
1875 }
1876 }
1877
1878 if (r->flags & WPA_SCAN_ASSOCIATED) {
1879 wpa_printf(MSG_DEBUG, "nl80211: Scan results "
1880 "indicate BSS status with " MACSTR
1881 " as associated",
1882 MAC2STR(r->bssid));
1883 if (drv->nlmode == NL80211_IFTYPE_STATION &&
1884 !drv->associated) {
1885 wpa_printf(MSG_DEBUG, "nl80211: Local state "
1886 "(not associated) does not match "
1887 "with BSS state");
d72aad94 1888 clear_state_mismatch(drv, r->bssid);
e6b8efeb
JM
1889 } else if (drv->nlmode == NL80211_IFTYPE_STATION &&
1890 os_memcmp(drv->bssid, r->bssid, ETH_ALEN) !=
1891 0) {
1892 wpa_printf(MSG_DEBUG, "nl80211: Local state "
1893 "(associated with " MACSTR ") does "
1894 "not match with BSS state",
d72aad94
JM
1895 MAC2STR(drv->bssid));
1896 clear_state_mismatch(drv, r->bssid);
1897 clear_state_mismatch(drv, drv->bssid);
e6b8efeb
JM
1898 }
1899 }
1900 }
1901}
1902
1903
d1f9c410
JM
1904static void wpa_scan_results_free(struct wpa_scan_results *res)
1905{
1906 size_t i;
1907
1908 if (res == NULL)
1909 return;
1910
1911 for (i = 0; i < res->num; i++)
1912 os_free(res->res[i]);
1913 os_free(res->res);
1914 os_free(res);
1915}
1916
1917
7e5ba1b9 1918static struct wpa_scan_results *
8856462d 1919nl80211_get_scan_results(struct wpa_driver_nl80211_data *drv)
3f5285e8 1920{
b3db1e1c 1921 struct nl_msg *msg;
3f5285e8 1922 struct wpa_scan_results *res;
b3db1e1c 1923 int ret;
3812464c 1924 struct nl80211_bss_info_arg arg;
3f5285e8
JM
1925
1926 res = os_zalloc(sizeof(*res));
b3db1e1c 1927 if (res == NULL)
8e2c104f 1928 return NULL;
b3db1e1c
JM
1929 msg = nlmsg_alloc();
1930 if (!msg)
1931 goto nla_put_failure;
3f5285e8 1932
b3db1e1c
JM
1933 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, NLM_F_DUMP,
1934 NL80211_CMD_GET_SCAN, 0);
1935 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
3f5285e8 1936
3812464c
JM
1937 arg.drv = drv;
1938 arg.res = res;
1939 ret = send_and_recv_msgs(drv, msg, bss_info_handler, &arg);
b3db1e1c
JM
1940 msg = NULL;
1941 if (ret == 0) {
1942 wpa_printf(MSG_DEBUG, "Received scan results (%lu BSSes)",
1943 (unsigned long) res->num);
1944 return res;
3f5285e8 1945 }
b3db1e1c
JM
1946 wpa_printf(MSG_DEBUG, "nl80211: Scan result fetch failed: ret=%d "
1947 "(%s)", ret, strerror(-ret));
1948nla_put_failure:
1949 nlmsg_free(msg);
1950 wpa_scan_results_free(res);
1951 return NULL;
3f5285e8
JM
1952}
1953
1954
8856462d
JM
1955/**
1956 * wpa_driver_nl80211_get_scan_results - Fetch the latest scan results
1957 * @priv: Pointer to private wext data from wpa_driver_nl80211_init()
1958 * Returns: Scan results on success, -1 on failure
1959 */
1960static struct wpa_scan_results *
1961wpa_driver_nl80211_get_scan_results(void *priv)
1962{
a2e40bb6
FF
1963 struct i802_bss *bss = priv;
1964 struct wpa_driver_nl80211_data *drv = bss->drv;
8856462d
JM
1965 struct wpa_scan_results *res;
1966
1967 res = nl80211_get_scan_results(drv);
1968 if (res)
1969 wpa_driver_nl80211_check_bss_status(drv, res);
1970 return res;
1971}
1972
1973
1974static void nl80211_dump_scan(struct wpa_driver_nl80211_data *drv)
1975{
1976 struct wpa_scan_results *res;
1977 size_t i;
1978
1979 res = nl80211_get_scan_results(drv);
1980 if (res == NULL) {
1981 wpa_printf(MSG_DEBUG, "nl80211: Failed to get scan results");
1982 return;
1983 }
1984
1985 wpa_printf(MSG_DEBUG, "nl80211: Scan result dump");
1986 for (i = 0; i < res->num; i++) {
1987 struct wpa_scan_res *r = res->res[i];
1988 wpa_printf(MSG_DEBUG, "nl80211: %d/%d " MACSTR "%s%s",
1989 (int) i, (int) res->num, MAC2STR(r->bssid),
1990 r->flags & WPA_SCAN_AUTHENTICATED ? " [auth]" : "",
1991 r->flags & WPA_SCAN_ASSOCIATED ? " [assoc]" : "");
1992 }
1993
1994 wpa_scan_results_free(res);
1995}
1996
1997
642187d6 1998static int wpa_driver_nl80211_set_key(const char *ifname, void *priv,
71934751
JM
1999 enum wpa_alg alg, const u8 *addr,
2000 int key_idx, int set_tx,
642187d6
JM
2001 const u8 *seq, size_t seq_len,
2002 const u8 *key, size_t key_len)
3f5285e8 2003{
a2e40bb6
FF
2004 struct i802_bss *bss = priv;
2005 struct wpa_driver_nl80211_data *drv = bss->drv;
642187d6 2006 int ifindex = if_nametoindex(ifname);
3f5285e8 2007 struct nl_msg *msg;
1ad1cdc2 2008 int ret;
3f5285e8 2009
1ad1cdc2
JM
2010 wpa_printf(MSG_DEBUG, "%s: ifindex=%d alg=%d addr=%p key_idx=%d "
2011 "set_tx=%d seq_len=%lu key_len=%lu",
2012 __func__, ifindex, alg, addr, key_idx, set_tx,
3f5285e8
JM
2013 (unsigned long) seq_len, (unsigned long) key_len);
2014
2015 msg = nlmsg_alloc();
1ad1cdc2
JM
2016 if (!msg)
2017 return -ENOMEM;
3f5285e8
JM
2018
2019 if (alg == WPA_ALG_NONE) {
1ad1cdc2
JM
2020 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
2021 0, NL80211_CMD_DEL_KEY, 0);
3f5285e8 2022 } else {
1ad1cdc2
JM
2023 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
2024 0, NL80211_CMD_NEW_KEY, 0);
3f5285e8 2025 NLA_PUT(msg, NL80211_ATTR_KEY_DATA, key_len, key);
d723bab4
JM
2026 switch (alg) {
2027 case WPA_ALG_WEP:
2028 if (key_len == 5)
2029 NLA_PUT_U32(msg, NL80211_ATTR_KEY_CIPHER,
2030 WLAN_CIPHER_SUITE_WEP40);
2031 else
2032 NLA_PUT_U32(msg, NL80211_ATTR_KEY_CIPHER,
2033 WLAN_CIPHER_SUITE_WEP104);
2034 break;
2035 case WPA_ALG_TKIP:
2036 NLA_PUT_U32(msg, NL80211_ATTR_KEY_CIPHER,
2037 WLAN_CIPHER_SUITE_TKIP);
2038 break;
2039 case WPA_ALG_CCMP:
2040 NLA_PUT_U32(msg, NL80211_ATTR_KEY_CIPHER,
2041 WLAN_CIPHER_SUITE_CCMP);
2042 break;
2043 case WPA_ALG_IGTK:
2044 NLA_PUT_U32(msg, NL80211_ATTR_KEY_CIPHER,
2045 WLAN_CIPHER_SUITE_AES_CMAC);
2046 break;
2047 default:
2048 wpa_printf(MSG_ERROR, "%s: Unsupported encryption "
2049 "algorithm %d", __func__, alg);
3f5285e8
JM
2050 nlmsg_free(msg);
2051 return -1;
2052 }
2053 }
2054
849ef835 2055 if (seq && seq_len)
1ad1cdc2
JM
2056 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, seq_len, seq);
2057
3f5285e8
JM
2058 if (addr && os_memcmp(addr, "\xff\xff\xff\xff\xff\xff", ETH_ALEN) != 0)
2059 {
2060 wpa_printf(MSG_DEBUG, " addr=" MACSTR, MAC2STR(addr));
2061 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
2062 }
2063 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1ad1cdc2 2064 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, ifindex);
3f5285e8 2065
1ad1cdc2 2066 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
15664ad0 2067 if ((ret == -ENOENT || ret == -ENOLINK) && alg == WPA_ALG_NONE)
1ad1cdc2
JM
2068 ret = 0;
2069 if (ret)
2070 wpa_printf(MSG_DEBUG, "nl80211: set_key failed; err=%d %s)",
2071 ret, strerror(-ret));
3f5285e8 2072
1ad1cdc2
JM
2073 /*
2074 * If we failed or don't need to set the default TX key (below),
2075 * we're done here.
2076 */
2077 if (ret || !set_tx || alg == WPA_ALG_NONE)
2078 return ret;
2079#ifdef HOSTAPD /* FIX: is this needed? */
2080 if (addr)
2081 return ret;
2082#endif /* HOSTAPD */
3f5285e8 2083
1ad1cdc2
JM
2084 msg = nlmsg_alloc();
2085 if (!msg)
2086 return -ENOMEM;
3f5285e8 2087
1ad1cdc2
JM
2088 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
2089 0, NL80211_CMD_SET_KEY, 0);
2090 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
2091 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, ifindex);
2092 if (alg == WPA_ALG_IGTK)
2093 NLA_PUT_FLAG(msg, NL80211_ATTR_KEY_DEFAULT_MGMT);
2094 else
2095 NLA_PUT_FLAG(msg, NL80211_ATTR_KEY_DEFAULT);
3f5285e8 2096
1ad1cdc2
JM
2097 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
2098 if (ret == -ENOENT)
2099 ret = 0;
2100 if (ret)
2101 wpa_printf(MSG_DEBUG, "nl80211: set_key default failed; "
2102 "err=%d %s)", ret, strerror(-ret));
2103 return ret;
3f5285e8
JM
2104
2105nla_put_failure:
6241fcb1 2106 return -ENOBUFS;
3f5285e8
JM
2107}
2108
2109
71934751 2110static int nl_add_key(struct nl_msg *msg, enum wpa_alg alg,
0194fedb
JB
2111 int key_idx, int defkey,
2112 const u8 *seq, size_t seq_len,
2113 const u8 *key, size_t key_len)
2114{
2115 struct nlattr *key_attr = nla_nest_start(msg, NL80211_ATTR_KEY);
2116 if (!key_attr)
2117 return -1;
2118
2119 if (defkey && alg == WPA_ALG_IGTK)
2120 NLA_PUT_FLAG(msg, NL80211_KEY_DEFAULT_MGMT);
2121 else if (defkey)
2122 NLA_PUT_FLAG(msg, NL80211_KEY_DEFAULT);
2123
2124 NLA_PUT_U8(msg, NL80211_KEY_IDX, key_idx);
2125
d723bab4
JM
2126 switch (alg) {
2127 case WPA_ALG_WEP:
2128 if (key_len == 5)
2aa5f847
JM
2129 NLA_PUT_U32(msg, NL80211_KEY_CIPHER,
2130 WLAN_CIPHER_SUITE_WEP40);
d723bab4 2131 else
2aa5f847
JM
2132 NLA_PUT_U32(msg, NL80211_KEY_CIPHER,
2133 WLAN_CIPHER_SUITE_WEP104);
d723bab4
JM
2134 break;
2135 case WPA_ALG_TKIP:
2aa5f847 2136 NLA_PUT_U32(msg, NL80211_KEY_CIPHER, WLAN_CIPHER_SUITE_TKIP);
d723bab4
JM
2137 break;
2138 case WPA_ALG_CCMP:
2aa5f847 2139 NLA_PUT_U32(msg, NL80211_KEY_CIPHER, WLAN_CIPHER_SUITE_CCMP);
d723bab4
JM
2140 break;
2141 case WPA_ALG_IGTK:
2aa5f847
JM
2142 NLA_PUT_U32(msg, NL80211_KEY_CIPHER,
2143 WLAN_CIPHER_SUITE_AES_CMAC);
d723bab4
JM
2144 break;
2145 default:
2146 wpa_printf(MSG_ERROR, "%s: Unsupported encryption "
2147 "algorithm %d", __func__, alg);
0194fedb 2148 return -1;
d723bab4 2149 }
0194fedb
JB
2150
2151 if (seq && seq_len)
2152 NLA_PUT(msg, NL80211_KEY_SEQ, seq_len, seq);
2153
2154 NLA_PUT(msg, NL80211_KEY_DATA, key_len, key);
2155
2156 nla_nest_end(msg, key_attr);
2157
2158 return 0;
2159 nla_put_failure:
2160 return -1;
2161}
2162
c811d5bc 2163
cfaab580
ZY
2164static int nl80211_set_conn_keys(struct wpa_driver_associate_params *params,
2165 struct nl_msg *msg)
2166{
2167 int i, privacy = 0;
2168 struct nlattr *nl_keys, *nl_key;
2169
2170 for (i = 0; i < 4; i++) {
2171 if (!params->wep_key[i])
2172 continue;
2173 privacy = 1;
2174 break;
2175 }
2176 if (!privacy)
2177 return 0;
2178
2179 NLA_PUT_FLAG(msg, NL80211_ATTR_PRIVACY);
2180
2181 nl_keys = nla_nest_start(msg, NL80211_ATTR_KEYS);
2182 if (!nl_keys)
2183 goto nla_put_failure;
2184
2185 for (i = 0; i < 4; i++) {
2186 if (!params->wep_key[i])
2187 continue;
2188
2189 nl_key = nla_nest_start(msg, i);
2190 if (!nl_key)
2191 goto nla_put_failure;
2192
2193 NLA_PUT(msg, NL80211_KEY_DATA, params->wep_key_len[i],
2194 params->wep_key[i]);
2195 if (params->wep_key_len[i] == 5)
2196 NLA_PUT_U32(msg, NL80211_KEY_CIPHER,
2197 WLAN_CIPHER_SUITE_WEP40);
2198 else
2199 NLA_PUT_U32(msg, NL80211_KEY_CIPHER,
2200 WLAN_CIPHER_SUITE_WEP104);
2201
2202 NLA_PUT_U8(msg, NL80211_KEY_IDX, i);
2203
2204 if (i == params->wep_tx_keyidx)
2205 NLA_PUT_FLAG(msg, NL80211_KEY_DEFAULT);
2206
2207 nla_nest_end(msg, nl_key);
2208 }
2209 nla_nest_end(msg, nl_keys);
2210
2211 return 0;
2212
2213nla_put_failure:
2214 return -ENOBUFS;
2215}
2216
2217
c2a04078
JM
2218static int wpa_driver_nl80211_mlme(struct wpa_driver_nl80211_data *drv,
2219 const u8 *addr, int cmd, u16 reason_code)
2220{
2221 int ret = -1;
2222 struct nl_msg *msg;
2223
2224 msg = nlmsg_alloc();
2225 if (!msg)
2226 return -1;
2227
2228 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0, cmd, 0);
2229
2230 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
2231 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason_code);
2232 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
2233
2234 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
2235 msg = NULL;
2236 if (ret) {
2237 wpa_printf(MSG_DEBUG, "nl80211: MLME command failed: ret=%d "
2238 "(%s)", ret, strerror(-ret));
2239 goto nla_put_failure;
2240 }
2241 ret = 0;
2242
2243nla_put_failure:
2244 nlmsg_free(msg);
2245 return ret;
2246}
3f5285e8
JM
2247
2248
cfaab580
ZY
2249static int wpa_driver_nl80211_disconnect(struct wpa_driver_nl80211_data *drv,
2250 const u8 *addr, int reason_code)
2251{
2252 wpa_printf(MSG_DEBUG, "%s", __func__);
2253 drv->associated = 0;
2254 return wpa_driver_nl80211_mlme(drv, addr, NL80211_CMD_DISCONNECT,
2255 reason_code);
2256}
2257
2258
3f5285e8 2259static int wpa_driver_nl80211_deauthenticate(void *priv, const u8 *addr,
c2a04078 2260 int reason_code)
3f5285e8 2261{
a2e40bb6
FF
2262 struct i802_bss *bss = priv;
2263 struct wpa_driver_nl80211_data *drv = bss->drv;
cfaab580
ZY
2264 if (!(drv->capa.flags & WPA_DRIVER_FLAGS_SME))
2265 return wpa_driver_nl80211_disconnect(drv, addr, reason_code);
c2a04078 2266 wpa_printf(MSG_DEBUG, "%s", __func__);
13405f35 2267 drv->associated = 0;
c2a04078
JM
2268 return wpa_driver_nl80211_mlme(drv, addr, NL80211_CMD_DEAUTHENTICATE,
2269 reason_code);
3f5285e8
JM
2270}
2271
2272
2273static int wpa_driver_nl80211_disassociate(void *priv, const u8 *addr,
c2a04078 2274 int reason_code)
3f5285e8 2275{
a2e40bb6
FF
2276 struct i802_bss *bss = priv;
2277 struct wpa_driver_nl80211_data *drv = bss->drv;
cfaab580
ZY
2278 if (!(drv->capa.flags & WPA_DRIVER_FLAGS_SME))
2279 return wpa_driver_nl80211_disconnect(drv, addr, reason_code);
c2a04078 2280 wpa_printf(MSG_DEBUG, "%s", __func__);
13405f35 2281 drv->associated = 0;
c2a04078
JM
2282 return wpa_driver_nl80211_mlme(drv, addr, NL80211_CMD_DISASSOCIATE,
2283 reason_code);
3f5285e8
JM
2284}
2285
2286
c2a04078
JM
2287static int wpa_driver_nl80211_authenticate(
2288 void *priv, struct wpa_driver_auth_params *params)
2289{
a2e40bb6
FF
2290 struct i802_bss *bss = priv;
2291 struct wpa_driver_nl80211_data *drv = bss->drv;
a0b2f99b 2292 int ret = -1, i;
c2a04078
JM
2293 struct nl_msg *msg;
2294 enum nl80211_auth_type type;
6d6f4bb8 2295 int count = 0;
c2a04078
JM
2296
2297 drv->associated = 0;
e6b8efeb 2298 os_memset(drv->auth_bssid, 0, ETH_ALEN);
af473088
JM
2299 /* FIX: IBSS mode */
2300 if (drv->nlmode != NL80211_IFTYPE_STATION)
2301 wpa_driver_nl80211_set_mode(priv, IEEE80211_MODE_INFRA);
c2a04078 2302
a2e40bb6 2303 if (wpa_driver_nl80211_set_mode(priv, IEEE80211_MODE_INFRA) < 0)
4a867032
JM
2304 return -1;
2305
6d6f4bb8 2306retry:
c2a04078
JM
2307 msg = nlmsg_alloc();
2308 if (!msg)
2309 return -1;
2310
2311 wpa_printf(MSG_DEBUG, "nl80211: Authenticate (ifindex=%d)",
2312 drv->ifindex);
a0b2f99b 2313
0194fedb
JB
2314 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
2315 NL80211_CMD_AUTHENTICATE, 0);
2316
a0b2f99b
JM
2317 for (i = 0; i < 4; i++) {
2318 if (!params->wep_key[i])
2319 continue;
2ea2fcc7
HS
2320 wpa_driver_nl80211_set_key(bss->ifname, priv, WPA_ALG_WEP,
2321 NULL, i,
a0b2f99b
JM
2322 i == params->wep_tx_keyidx, NULL, 0,
2323 params->wep_key[i],
2324 params->wep_key_len[i]);
0194fedb
JB
2325 if (params->wep_tx_keyidx != i)
2326 continue;
2327 if (nl_add_key(msg, WPA_ALG_WEP, i, 1, NULL, 0,
2328 params->wep_key[i], params->wep_key_len[i])) {
2329 nlmsg_free(msg);
2330 return -1;
2331 }
a0b2f99b
JM
2332 }
2333
c2a04078
JM
2334 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
2335 if (params->bssid) {
2336 wpa_printf(MSG_DEBUG, " * bssid=" MACSTR,
2337 MAC2STR(params->bssid));
2338 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, params->bssid);
2339 }
2340 if (params->freq) {
2341 wpa_printf(MSG_DEBUG, " * freq=%d", params->freq);
2342 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, params->freq);
2343 }
2344 if (params->ssid) {
2345 wpa_hexdump_ascii(MSG_DEBUG, " * SSID",
2346 params->ssid, params->ssid_len);
2347 NLA_PUT(msg, NL80211_ATTR_SSID, params->ssid_len,
2348 params->ssid);
2349 }
2350 wpa_hexdump(MSG_DEBUG, " * IEs", params->ie, params->ie_len);
2351 if (params->ie)
2352 NLA_PUT(msg, NL80211_ATTR_IE, params->ie_len, params->ie);
2353 /*
2354 * TODO: if multiple auth_alg options enabled, try them one by one if
2355 * the AP rejects authentication due to unknown auth alg
2356 */
abd9fafa 2357 if (params->auth_alg & WPA_AUTH_ALG_OPEN)
c2a04078 2358 type = NL80211_AUTHTYPE_OPEN_SYSTEM;
abd9fafa 2359 else if (params->auth_alg & WPA_AUTH_ALG_SHARED)
c2a04078 2360 type = NL80211_AUTHTYPE_SHARED_KEY;
abd9fafa 2361 else if (params->auth_alg & WPA_AUTH_ALG_LEAP)
c2a04078 2362 type = NL80211_AUTHTYPE_NETWORK_EAP;
abd9fafa 2363 else if (params->auth_alg & WPA_AUTH_ALG_FT)
c2a04078
JM
2364 type = NL80211_AUTHTYPE_FT;
2365 else
2366 goto nla_put_failure;
2367 wpa_printf(MSG_DEBUG, " * Auth Type %d", type);
2368 NLA_PUT_U32(msg, NL80211_ATTR_AUTH_TYPE, type);
2369
2370 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
2371 msg = NULL;
2372 if (ret) {
2373 wpa_printf(MSG_DEBUG, "nl80211: MLME command failed: ret=%d "
2374 "(%s)", ret, strerror(-ret));
6d6f4bb8
JM
2375 count++;
2376 if (ret == -EALREADY && count == 1 && params->bssid) {
2377 /*
2378 * mac80211 does not currently accept new
2379 * authentication if we are already authenticated. As a
2380 * workaround, force deauthentication and try again.
2381 */
2382 wpa_printf(MSG_DEBUG, "nl80211: Retry authentication "
2383 "after forced deauthentication");
2384 wpa_driver_nl80211_deauthenticate(
5205c4f9 2385 bss, params->bssid,
6d6f4bb8
JM
2386 WLAN_REASON_PREV_AUTH_NOT_VALID);
2387 nlmsg_free(msg);
2388 goto retry;
2389 }
c2a04078
JM
2390 goto nla_put_failure;
2391 }
2392 ret = 0;
2393 wpa_printf(MSG_DEBUG, "nl80211: Authentication request send "
2394 "successfully");
2395
2396nla_put_failure:
2397 nlmsg_free(msg);
2398 return ret;
2399}
2400
2401
282d5590
JM
2402struct phy_info_arg {
2403 u16 *num_modes;
2404 struct hostapd_hw_modes *modes;
2405};
2406
2407static int phy_info_handler(struct nl_msg *msg, void *arg)
2408{
2409 struct nlattr *tb_msg[NL80211_ATTR_MAX + 1];
2410 struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
2411 struct phy_info_arg *phy_info = arg;
2412
2413 struct nlattr *tb_band[NL80211_BAND_ATTR_MAX + 1];
2414
2415 struct nlattr *tb_freq[NL80211_FREQUENCY_ATTR_MAX + 1];
2416 static struct nla_policy freq_policy[NL80211_FREQUENCY_ATTR_MAX + 1] = {
2417 [NL80211_FREQUENCY_ATTR_FREQ] = { .type = NLA_U32 },
2418 [NL80211_FREQUENCY_ATTR_DISABLED] = { .type = NLA_FLAG },
2419 [NL80211_FREQUENCY_ATTR_PASSIVE_SCAN] = { .type = NLA_FLAG },
2420 [NL80211_FREQUENCY_ATTR_NO_IBSS] = { .type = NLA_FLAG },
2421 [NL80211_FREQUENCY_ATTR_RADAR] = { .type = NLA_FLAG },
2422 [NL80211_FREQUENCY_ATTR_MAX_TX_POWER] = { .type = NLA_U32 },
2423 };
2424
2425 struct nlattr *tb_rate[NL80211_BITRATE_ATTR_MAX + 1];
2426 static struct nla_policy rate_policy[NL80211_BITRATE_ATTR_MAX + 1] = {
2427 [NL80211_BITRATE_ATTR_RATE] = { .type = NLA_U32 },
2428 [NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE] = { .type = NLA_FLAG },
2429 };
2430
2431 struct nlattr *nl_band;
2432 struct nlattr *nl_freq;
2433 struct nlattr *nl_rate;
2434 int rem_band, rem_freq, rem_rate;
2435 struct hostapd_hw_modes *mode;
2436 int idx, mode_is_set;
2437
2438 nla_parse(tb_msg, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
2439 genlmsg_attrlen(gnlh, 0), NULL);
2440
2441 if (!tb_msg[NL80211_ATTR_WIPHY_BANDS])
2442 return NL_SKIP;
2443
2444 nla_for_each_nested(nl_band, tb_msg[NL80211_ATTR_WIPHY_BANDS], rem_band) {
e62fb0a0 2445 mode = os_realloc(phy_info->modes, (*phy_info->num_modes + 1) * sizeof(*mode));
282d5590
JM
2446 if (!mode)
2447 return NL_SKIP;
2448 phy_info->modes = mode;
2449
2450 mode_is_set = 0;
2451
2452 mode = &phy_info->modes[*(phy_info->num_modes)];
2453 memset(mode, 0, sizeof(*mode));
2454 *(phy_info->num_modes) += 1;
2455
2456 nla_parse(tb_band, NL80211_BAND_ATTR_MAX, nla_data(nl_band),
2457 nla_len(nl_band), NULL);
2458
2459 if (tb_band[NL80211_BAND_ATTR_HT_CAPA]) {
2460 mode->ht_capab = nla_get_u16(
2461 tb_band[NL80211_BAND_ATTR_HT_CAPA]);
2462 }
2463
be8eb8ab
JM
2464 if (tb_band[NL80211_BAND_ATTR_HT_AMPDU_FACTOR]) {
2465 mode->a_mpdu_params |= nla_get_u8(
2466 tb_band[NL80211_BAND_ATTR_HT_AMPDU_FACTOR]) &
2467 0x03;
2468 }
2469
2470 if (tb_band[NL80211_BAND_ATTR_HT_AMPDU_DENSITY]) {
2471 mode->a_mpdu_params |= nla_get_u8(
2472 tb_band[NL80211_BAND_ATTR_HT_AMPDU_DENSITY]) <<
2473 2;
2474 }
2475
08eb154d
JM
2476 if (tb_band[NL80211_BAND_ATTR_HT_MCS_SET] &&
2477 nla_len(tb_band[NL80211_BAND_ATTR_HT_MCS_SET])) {
2478 u8 *mcs;
2479 mcs = nla_data(tb_band[NL80211_BAND_ATTR_HT_MCS_SET]);
2480 os_memcpy(mode->mcs_set, mcs, 16);
2481 }
2482
282d5590
JM
2483 nla_for_each_nested(nl_freq, tb_band[NL80211_BAND_ATTR_FREQS], rem_freq) {
2484 nla_parse(tb_freq, NL80211_FREQUENCY_ATTR_MAX, nla_data(nl_freq),
2485 nla_len(nl_freq), freq_policy);
2486 if (!tb_freq[NL80211_FREQUENCY_ATTR_FREQ])
2487 continue;
2488 mode->num_channels++;
2489 }
2490
e62fb0a0 2491 mode->channels = os_zalloc(mode->num_channels * sizeof(struct hostapd_channel_data));
282d5590
JM
2492 if (!mode->channels)
2493 return NL_SKIP;
2494
2495 idx = 0;
2496
2497 nla_for_each_nested(nl_freq, tb_band[NL80211_BAND_ATTR_FREQS], rem_freq) {
2498 nla_parse(tb_freq, NL80211_FREQUENCY_ATTR_MAX, nla_data(nl_freq),
2499 nla_len(nl_freq), freq_policy);
2500 if (!tb_freq[NL80211_FREQUENCY_ATTR_FREQ])
2501 continue;
2502
2503 mode->channels[idx].freq = nla_get_u32(tb_freq[NL80211_FREQUENCY_ATTR_FREQ]);
2504 mode->channels[idx].flag = 0;
2505
2506 if (!mode_is_set) {
2507 /* crude heuristic */
2508 if (mode->channels[idx].freq < 4000)
2509 mode->mode = HOSTAPD_MODE_IEEE80211B;
2510 else
2511 mode->mode = HOSTAPD_MODE_IEEE80211A;
2512 mode_is_set = 1;
2513 }
2514
2515 /* crude heuristic */
2516 if (mode->channels[idx].freq < 4000)
5a0ffb5f 2517 if (mode->channels[idx].freq == 2484)
282d5590
JM
2518 mode->channels[idx].chan = 14;
2519 else
2520 mode->channels[idx].chan = (mode->channels[idx].freq - 2407) / 5;
2521 else
2522 mode->channels[idx].chan = mode->channels[idx].freq/5 - 1000;
2523
2524 if (tb_freq[NL80211_FREQUENCY_ATTR_DISABLED])
2525 mode->channels[idx].flag |=
2526 HOSTAPD_CHAN_DISABLED;
2527 if (tb_freq[NL80211_FREQUENCY_ATTR_PASSIVE_SCAN])
2528 mode->channels[idx].flag |=
2529 HOSTAPD_CHAN_PASSIVE_SCAN;
2530 if (tb_freq[NL80211_FREQUENCY_ATTR_NO_IBSS])
2531 mode->channels[idx].flag |=
2532 HOSTAPD_CHAN_NO_IBSS;
2533 if (tb_freq[NL80211_FREQUENCY_ATTR_RADAR])
2534 mode->channels[idx].flag |=
2535 HOSTAPD_CHAN_RADAR;
2536
2537 if (tb_freq[NL80211_FREQUENCY_ATTR_MAX_TX_POWER] &&
2538 !tb_freq[NL80211_FREQUENCY_ATTR_DISABLED])
2539 mode->channels[idx].max_tx_power =
2540 nla_get_u32(tb_freq[NL80211_FREQUENCY_ATTR_MAX_TX_POWER]) / 100;
2541
2542 idx++;
2543 }
2544
2545 nla_for_each_nested(nl_rate, tb_band[NL80211_BAND_ATTR_RATES], rem_rate) {
2546 nla_parse(tb_rate, NL80211_BITRATE_ATTR_MAX, nla_data(nl_rate),
2547 nla_len(nl_rate), rate_policy);
2548 if (!tb_rate[NL80211_BITRATE_ATTR_RATE])
2549 continue;
2550 mode->num_rates++;
2551 }
2552
e62fb0a0 2553 mode->rates = os_zalloc(mode->num_rates * sizeof(int));
282d5590
JM
2554 if (!mode->rates)
2555 return NL_SKIP;
2556
2557 idx = 0;
2558
2559 nla_for_each_nested(nl_rate, tb_band[NL80211_BAND_ATTR_RATES], rem_rate) {
2560 nla_parse(tb_rate, NL80211_BITRATE_ATTR_MAX, nla_data(nl_rate),
2561 nla_len(nl_rate), rate_policy);
2562 if (!tb_rate[NL80211_BITRATE_ATTR_RATE])
2563 continue;
fb7842aa 2564 mode->rates[idx] = nla_get_u32(tb_rate[NL80211_BITRATE_ATTR_RATE]);
282d5590
JM
2565
2566 /* crude heuristic */
2567 if (mode->mode == HOSTAPD_MODE_IEEE80211B &&
fb7842aa 2568 mode->rates[idx] > 200)
282d5590
JM
2569 mode->mode = HOSTAPD_MODE_IEEE80211G;
2570
282d5590
JM
2571 idx++;
2572 }
2573 }
2574
2575 return NL_SKIP;
2576}
2577
2578static struct hostapd_hw_modes *
2579wpa_driver_nl80211_add_11b(struct hostapd_hw_modes *modes, u16 *num_modes)
2580{
2581 u16 m;
2582 struct hostapd_hw_modes *mode11g = NULL, *nmodes, *mode;
2583 int i, mode11g_idx = -1;
2584
2585 /* If only 802.11g mode is included, use it to construct matching
2586 * 802.11b mode data. */
2587
2588 for (m = 0; m < *num_modes; m++) {
2589 if (modes[m].mode == HOSTAPD_MODE_IEEE80211B)
2590 return modes; /* 802.11b already included */
2591 if (modes[m].mode == HOSTAPD_MODE_IEEE80211G)
2592 mode11g_idx = m;
2593 }
2594
2595 if (mode11g_idx < 0)
2596 return modes; /* 2.4 GHz band not supported at all */
2597
2598 nmodes = os_realloc(modes, (*num_modes + 1) * sizeof(*nmodes));
2599 if (nmodes == NULL)
2600 return modes; /* Could not add 802.11b mode */
2601
2602 mode = &nmodes[*num_modes];
2603 os_memset(mode, 0, sizeof(*mode));
2604 (*num_modes)++;
2605 modes = nmodes;
2606
2607 mode->mode = HOSTAPD_MODE_IEEE80211B;
2608
2609 mode11g = &modes[mode11g_idx];
2610 mode->num_channels = mode11g->num_channels;
2611 mode->channels = os_malloc(mode11g->num_channels *
2612 sizeof(struct hostapd_channel_data));
2613 if (mode->channels == NULL) {
2614 (*num_modes)--;
2615 return modes; /* Could not add 802.11b mode */
2616 }
2617 os_memcpy(mode->channels, mode11g->channels,
2618 mode11g->num_channels * sizeof(struct hostapd_channel_data));
2619
2620 mode->num_rates = 0;
fb7842aa 2621 mode->rates = os_malloc(4 * sizeof(int));
282d5590
JM
2622 if (mode->rates == NULL) {
2623 os_free(mode->channels);
2624 (*num_modes)--;
2625 return modes; /* Could not add 802.11b mode */
2626 }
2627
2628 for (i = 0; i < mode11g->num_rates; i++) {
fb7842aa
JM
2629 if (mode11g->rates[i] != 10 && mode11g->rates[i] != 20 &&
2630 mode11g->rates[i] != 55 && mode11g->rates[i] != 110)
282d5590
JM
2631 continue;
2632 mode->rates[mode->num_rates] = mode11g->rates[i];
2633 mode->num_rates++;
2634 if (mode->num_rates == 4)
2635 break;
2636 }
2637
2638 if (mode->num_rates == 0) {
2639 os_free(mode->channels);
2640 os_free(mode->rates);
2641 (*num_modes)--;
2642 return modes; /* No 802.11b rates */
2643 }
2644
2645 wpa_printf(MSG_DEBUG, "nl80211: Added 802.11b mode based on 802.11g "
2646 "information");
2647
2648 return modes;
2649}
2650
2651
2652static struct hostapd_hw_modes *
2653wpa_driver_nl80211_get_hw_feature_data(void *priv, u16 *num_modes, u16 *flags)
2654{
a2e40bb6
FF
2655 struct i802_bss *bss = priv;
2656 struct wpa_driver_nl80211_data *drv = bss->drv;
282d5590
JM
2657 struct nl_msg *msg;
2658 struct phy_info_arg result = {
2659 .num_modes = num_modes,
2660 .modes = NULL,
2661 };
2662
2663 *num_modes = 0;
2664 *flags = 0;
2665
2666 msg = nlmsg_alloc();
2667 if (!msg)
2668 return NULL;
2669
2670 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
2671 0, NL80211_CMD_GET_WIPHY, 0);
2672
2673 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
2674
2675 if (send_and_recv_msgs(drv, msg, phy_info_handler, &result) == 0)
2676 return wpa_driver_nl80211_add_11b(result.modes, num_modes);
2677 nla_put_failure:
2678 return NULL;
2679}
2680
2681
2c2010ac
JM
2682static int wpa_driver_nl80211_send_frame(struct wpa_driver_nl80211_data *drv,
2683 const void *data, size_t len,
2684 int encrypt)
2685{
2686 __u8 rtap_hdr[] = {
2687 0x00, 0x00, /* radiotap version */
2688 0x0e, 0x00, /* radiotap length */
2689 0x02, 0xc0, 0x00, 0x00, /* bmap: flags, tx and rx flags */
2690 IEEE80211_RADIOTAP_F_FRAG, /* F_FRAG (fragment if required) */
2691 0x00, /* padding */
2692 0x00, 0x00, /* RX and TX flags to indicate that */
2693 0x00, 0x00, /* this is the injected frame directly */
2694 };
2695 struct iovec iov[2] = {
2696 {
2697 .iov_base = &rtap_hdr,
2698 .iov_len = sizeof(rtap_hdr),
2699 },
2700 {
2701 .iov_base = (void *) data,
2702 .iov_len = len,
2703 }
2704 };
2705 struct msghdr msg = {
2706 .msg_name = NULL,
2707 .msg_namelen = 0,
2708 .msg_iov = iov,
2709 .msg_iovlen = 2,
2710 .msg_control = NULL,
2711 .msg_controllen = 0,
2712 .msg_flags = 0,
2713 };
2714
2715 if (encrypt)
2716 rtap_hdr[8] |= IEEE80211_RADIOTAP_F_WEP;
2717
2718 return sendmsg(drv->monitor_sock, &msg, 0);
2719}
2720
2721
2722static int wpa_driver_nl80211_send_mlme(void *priv, const u8 *data,
2723 size_t data_len)
2724{
a2e40bb6
FF
2725 struct i802_bss *bss = priv;
2726 struct wpa_driver_nl80211_data *drv = bss->drv;
2c2010ac 2727 struct ieee80211_mgmt *mgmt;
7a47d567 2728 int encrypt = 1;
2c2010ac
JM
2729 u16 fc;
2730
2731 mgmt = (struct ieee80211_mgmt *) data;
2732 fc = le_to_host16(mgmt->frame_control);
2733
2734 if (WLAN_FC_GET_TYPE(fc) == WLAN_FC_TYPE_MGMT &&
2735 WLAN_FC_GET_STYPE(fc) == WLAN_FC_STYPE_AUTH) {
2736 /*
2737 * Only one of the authentication frame types is encrypted.
2738 * In order for static WEP encryption to work properly (i.e.,
2739 * to not encrypt the frame), we need to tell mac80211 about
2740 * the frames that must not be encrypted.
2741 */
2742 u16 auth_alg = le_to_host16(mgmt->u.auth.auth_alg);
2743 u16 auth_trans = le_to_host16(mgmt->u.auth.auth_transaction);
7a47d567
JB
2744 if (auth_alg != WLAN_AUTH_SHARED_KEY || auth_trans != 3)
2745 encrypt = 0;
2c2010ac
JM
2746 }
2747
7a47d567 2748 return wpa_driver_nl80211_send_frame(drv, data, data_len, encrypt);
2c2010ac
JM
2749}
2750
2751
8b897f5a 2752static int wpa_driver_nl80211_set_beacon(void *priv,
5d674872
JM
2753 const u8 *head, size_t head_len,
2754 const u8 *tail, size_t tail_len,
2755 int dtim_period, int beacon_int)
d2440ba0 2756{
a2e40bb6
FF
2757 struct i802_bss *bss = priv;
2758 struct wpa_driver_nl80211_data *drv = bss->drv;
d2440ba0
JM
2759 struct nl_msg *msg;
2760 u8 cmd = NL80211_CMD_NEW_BEACON;
2761 int ret;
b4fd6fab 2762 int beacon_set;
8b897f5a 2763 int ifindex = if_nametoindex(bss->ifname);
b4fd6fab 2764
b4fd6fab 2765 beacon_set = bss->beacon_set;
d2440ba0
JM
2766
2767 msg = nlmsg_alloc();
2768 if (!msg)
2769 return -ENOMEM;
2770
2771 wpa_printf(MSG_DEBUG, "nl80211: Set beacon (beacon_set=%d)",
b4fd6fab
JM
2772 beacon_set);
2773 if (beacon_set)
d2440ba0
JM
2774 cmd = NL80211_CMD_SET_BEACON;
2775
2776 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
2777 0, cmd, 0);
2778 NLA_PUT(msg, NL80211_ATTR_BEACON_HEAD, head_len, head);
2779 NLA_PUT(msg, NL80211_ATTR_BEACON_TAIL, tail_len, tail);
b4fd6fab 2780 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, ifindex);
5d674872 2781 NLA_PUT_U32(msg, NL80211_ATTR_BEACON_INTERVAL, beacon_int);
d2440ba0
JM
2782 NLA_PUT_U32(msg, NL80211_ATTR_DTIM_PERIOD, dtim_period);
2783
2784 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
2785 if (ret) {
2786 wpa_printf(MSG_DEBUG, "nl80211: Beacon set failed: %d (%s)",
2787 ret, strerror(-ret));
b4fd6fab 2788 } else {
b4fd6fab 2789 bss->beacon_set = 1;
b4fd6fab 2790 }
d2440ba0
JM
2791 return ret;
2792 nla_put_failure:
2793 return -ENOBUFS;
2794}
2795
2796
f019981a
JM
2797static int wpa_driver_nl80211_set_freq(struct wpa_driver_nl80211_data *drv,
2798 int freq, int ht_enabled,
2799 int sec_channel_offset)
1581b38b
JM
2800{
2801 struct nl_msg *msg;
d2440ba0 2802 int ret;
1581b38b
JM
2803
2804 msg = nlmsg_alloc();
2805 if (!msg)
2806 return -1;
2807
2808 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
2809 NL80211_CMD_SET_WIPHY, 0);
2810
2811 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
f019981a
JM
2812 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
2813 if (ht_enabled) {
2814 switch (sec_channel_offset) {
2815 case -1:
2816 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
2817 NL80211_CHAN_HT40MINUS);
2818 break;
2819 case 1:
2820 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
2821 NL80211_CHAN_HT40PLUS);
2822 break;
2823 default:
2824 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
2825 NL80211_CHAN_HT20);
2826 break;
2827 }
2828 }
1581b38b 2829
d2440ba0
JM
2830 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
2831 if (ret == 0)
1581b38b 2832 return 0;
f019981a
JM
2833 wpa_printf(MSG_DEBUG, "nl80211: Failed to set channel (freq=%d): "
2834 "%d (%s)", freq, ret, strerror(-ret));
1581b38b
JM
2835nla_put_failure:
2836 return -1;
2837}
2838
0f4e8b4f 2839
62847751 2840static int wpa_driver_nl80211_sta_add(void *priv,
0f4e8b4f
JM
2841 struct hostapd_sta_add_params *params)
2842{
a2e40bb6
FF
2843 struct i802_bss *bss = priv;
2844 struct wpa_driver_nl80211_data *drv = bss->drv;
0f4e8b4f
JM
2845 struct nl_msg *msg;
2846 int ret = -ENOBUFS;
2847
2848 msg = nlmsg_alloc();
2849 if (!msg)
2850 return -ENOMEM;
2851
2852 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
2853 0, NL80211_CMD_NEW_STATION, 0);
2854
62847751 2855 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, if_nametoindex(bss->ifname));
0f4e8b4f
JM
2856 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, params->addr);
2857 NLA_PUT_U16(msg, NL80211_ATTR_STA_AID, params->aid);
2858 NLA_PUT(msg, NL80211_ATTR_STA_SUPPORTED_RATES, params->supp_rates_len,
2859 params->supp_rates);
2860 NLA_PUT_U16(msg, NL80211_ATTR_STA_LISTEN_INTERVAL,
2861 params->listen_interval);
0f4e8b4f
JM
2862 if (params->ht_capabilities) {
2863 NLA_PUT(msg, NL80211_ATTR_HT_CAPABILITY,
fc4e2d95
JM
2864 sizeof(*params->ht_capabilities),
2865 params->ht_capabilities);
0f4e8b4f 2866 }
0f4e8b4f
JM
2867
2868 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
2869 if (ret)
2870 wpa_printf(MSG_DEBUG, "nl80211: NL80211_CMD_NEW_STATION "
2871 "result: %d (%s)", ret, strerror(-ret));
2872 if (ret == -EEXIST)
2873 ret = 0;
2874 nla_put_failure:
2875 return ret;
2876}
2877
2878
2879static int wpa_driver_nl80211_sta_remove(void *priv, const u8 *addr)
2880{
a2e40bb6
FF
2881 struct i802_bss *bss = priv;
2882 struct wpa_driver_nl80211_data *drv = bss->drv;
0f4e8b4f
JM
2883 struct nl_msg *msg;
2884 int ret;
2885
2886 msg = nlmsg_alloc();
2887 if (!msg)
2888 return -ENOMEM;
2889
2890 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
2891 0, NL80211_CMD_DEL_STATION, 0);
2892
2893 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX,
a2e40bb6 2894 if_nametoindex(bss->ifname));
0f4e8b4f
JM
2895 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
2896
2897 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
2898 if (ret == -ENOENT)
2899 return 0;
2900 return ret;
2901 nla_put_failure:
2902 return -ENOBUFS;
2903}
2904
1581b38b 2905
0915d02c
JM
2906static void nl80211_remove_iface(struct wpa_driver_nl80211_data *drv,
2907 int ifidx)
2908{
2909 struct nl_msg *msg;
2910
c6e8e8e4
JM
2911 wpa_printf(MSG_DEBUG, "nl80211: Remove interface ifindex=%d", ifidx);
2912
2135f224
JM
2913#ifdef HOSTAPD
2914 /* stop listening for EAPOL on this interface */
2915 del_ifidx(drv, ifidx);
2916#endif /* HOSTAPD */
2917
0915d02c
JM
2918 msg = nlmsg_alloc();
2919 if (!msg)
2920 goto nla_put_failure;
2921
2922 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
2923 0, NL80211_CMD_DEL_INTERFACE, 0);
2924 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, ifidx);
2925
2926 if (send_and_recv_msgs(drv, msg, NULL, NULL) == 0)
2927 return;
2928 nla_put_failure:
e748062b 2929 wpa_printf(MSG_ERROR, "Failed to remove interface (ifidx=%d)", ifidx);
0915d02c
JM
2930}
2931
2932
a35187e7
KH
2933static int nl80211_create_iface_once(struct wpa_driver_nl80211_data *drv,
2934 const char *ifname,
2935 enum nl80211_iftype iftype,
fbbfcbac 2936 const u8 *addr, int wds)
0915d02c
JM
2937{
2938 struct nl_msg *msg, *flags = NULL;
2939 int ifidx;
2940 int ret = -ENOBUFS;
2941
2942 msg = nlmsg_alloc();
2943 if (!msg)
2944 return -1;
2945
2946 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
2947 0, NL80211_CMD_NEW_INTERFACE, 0);
2948 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
2949 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, ifname);
2950 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, iftype);
2951
2952 if (iftype == NL80211_IFTYPE_MONITOR) {
2953 int err;
2954
2955 flags = nlmsg_alloc();
2956 if (!flags)
2957 goto nla_put_failure;
2958
2959 NLA_PUT_FLAG(flags, NL80211_MNTR_FLAG_COOK_FRAMES);
2960
2961 err = nla_put_nested(msg, NL80211_ATTR_MNTR_FLAGS, flags);
2962
2963 nlmsg_free(flags);
2964
2965 if (err)
2966 goto nla_put_failure;
fbbfcbac
FF
2967 } else if (wds) {
2968 NLA_PUT_U8(msg, NL80211_ATTR_4ADDR, wds);
0915d02c
JM
2969 }
2970
2971 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
2972 if (ret) {
2973 nla_put_failure:
a35187e7
KH
2974 wpa_printf(MSG_ERROR, "Failed to create interface %s: %d (%s)",
2975 ifname, ret, strerror(-ret));
0915d02c
JM
2976 return ret;
2977 }
2978
2979 ifidx = if_nametoindex(ifname);
c6e8e8e4
JM
2980 wpa_printf(MSG_DEBUG, "nl80211: New interface %s created: ifindex=%d",
2981 ifname, ifidx);
0915d02c
JM
2982
2983 if (ifidx <= 0)
2984 return -1;
2985
2135f224
JM
2986#ifdef HOSTAPD
2987 /* start listening for EAPOL on this interface */
2988 add_ifidx(drv, ifidx);
7bfc47c3 2989#endif /* HOSTAPD */
2135f224 2990
7bfc47c3 2991 if (addr && iftype != NL80211_IFTYPE_MONITOR &&
2ac9688e 2992 linux_set_ifhwaddr(drv->ioctl_sock, ifname, addr)) {
41d931ee
JM
2993 nl80211_remove_iface(drv, ifidx);
2994 return -1;
2135f224 2995 }
2135f224 2996
0915d02c
JM
2997 return ifidx;
2998}
22a7c9d7
JM
2999
3000
a35187e7
KH
3001static int nl80211_create_iface(struct wpa_driver_nl80211_data *drv,
3002 const char *ifname, enum nl80211_iftype iftype,
fbbfcbac 3003 const u8 *addr, int wds)
a35187e7
KH
3004{
3005 int ret;
3006
fbbfcbac 3007 ret = nl80211_create_iface_once(drv, ifname, iftype, addr, wds);
a35187e7
KH
3008
3009 /* if error occured and interface exists already */
3010 if (ret == -ENFILE && if_nametoindex(ifname)) {
3011 wpa_printf(MSG_INFO, "Try to remove and re-create %s", ifname);
3012
3013 /* Try to remove the interface that was already there. */
3014 nl80211_remove_iface(drv, if_nametoindex(ifname));
3015
3016 /* Try to create the interface again */
fbbfcbac
FF
3017 ret = nl80211_create_iface_once(drv, ifname, iftype, addr,
3018 wds);
a35187e7
KH
3019 }
3020
4e5cb1a3
JM
3021 if (ret >= 0 && drv->disable_11b_rates)
3022 nl80211_disable_11b_rates(drv, ret, 1);
3023
a35187e7
KH
3024 return ret;
3025}
0915d02c 3026
2135f224 3027
0915d02c
JM
3028static void handle_tx_callback(void *ctx, u8 *buf, size_t len, int ok)
3029{
3030 struct ieee80211_hdr *hdr;
f8b1f695
JM
3031 u16 fc;
3032 union wpa_event_data event;
0915d02c
JM
3033
3034 hdr = (struct ieee80211_hdr *) buf;
3035 fc = le_to_host16(hdr->frame_control);
3036
f8b1f695
JM
3037 os_memset(&event, 0, sizeof(event));
3038 event.tx_status.type = WLAN_FC_GET_TYPE(fc);
3039 event.tx_status.stype = WLAN_FC_GET_STYPE(fc);
3040 event.tx_status.dst = hdr->addr1;
3041 event.tx_status.data = buf;
3042 event.tx_status.data_len = len;
3043 event.tx_status.ack = ok;
3044 wpa_supplicant_event(ctx, EVENT_TX_STATUS, &event);
0915d02c
JM
3045}
3046
3047
4b9841d3 3048static void from_unknown_sta(struct wpa_driver_nl80211_data *drv,
0d9fc3d8 3049 u8 *buf, size_t len)
0915d02c 3050{
f8b1f695
JM
3051 union wpa_event_data event;
3052 os_memset(&event, 0, sizeof(event));
0d9fc3d8 3053 event.rx_from_unknown.frame = buf;
f8b1f695
JM
3054 event.rx_from_unknown.len = len;
3055 wpa_supplicant_event(drv->ctx, EVENT_RX_FROM_UNKNOWN, &event);
4b9841d3 3056}
0915d02c 3057
4b9841d3
JM
3058
3059static void handle_frame(struct wpa_driver_nl80211_data *drv,
2a8b7416 3060 u8 *buf, size_t len, int datarate, int ssi_signal)
4b9841d3
JM
3061{
3062 struct ieee80211_hdr *hdr;
f8b1f695
JM
3063 u16 fc;
3064 union wpa_event_data event;
0915d02c
JM
3065
3066 hdr = (struct ieee80211_hdr *) buf;
3067 fc = le_to_host16(hdr->frame_control);
0915d02c 3068
4b9841d3 3069 switch (WLAN_FC_GET_TYPE(fc)) {
0915d02c 3070 case WLAN_FC_TYPE_MGMT:
f8b1f695
JM
3071 os_memset(&event, 0, sizeof(event));
3072 event.rx_mgmt.frame = buf;
3073 event.rx_mgmt.frame_len = len;
2a8b7416
JM
3074 event.rx_mgmt.datarate = datarate;
3075 event.rx_mgmt.ssi_signal = ssi_signal;
f8b1f695 3076 wpa_supplicant_event(drv->ctx, EVENT_RX_MGMT, &event);
0915d02c
JM
3077 break;
3078 case WLAN_FC_TYPE_CTRL:
3079 /* can only get here with PS-Poll frames */
3080 wpa_printf(MSG_DEBUG, "CTRL");
0d9fc3d8 3081 from_unknown_sta(drv, buf, len);
0915d02c
JM
3082 break;
3083 case WLAN_FC_TYPE_DATA:
0d9fc3d8 3084 from_unknown_sta(drv, buf, len);
0915d02c
JM
3085 break;
3086 }
3087}
3088
3089
3090static void handle_monitor_read(int sock, void *eloop_ctx, void *sock_ctx)
3091{
3092 struct wpa_driver_nl80211_data *drv = eloop_ctx;
3093 int len;
3094 unsigned char buf[3000];
3095 struct ieee80211_radiotap_iterator iter;
3096 int ret;
2a8b7416 3097 int datarate = 0, ssi_signal = 0;
4b9841d3 3098 int injected = 0, failed = 0, rxflags = 0;
0915d02c
JM
3099
3100 len = recv(sock, buf, sizeof(buf), 0);
3101 if (len < 0) {
3102 perror("recv");
3103 return;
3104 }
3105
504e905c
JM
3106 if (drv->nlmode == NL80211_IFTYPE_STATION && !drv->probe_req_report) {
3107 wpa_printf(MSG_DEBUG, "nl80211: Ignore monitor interface "
3108 "frame since Probe Request reporting is disabled");
3109 return;
3110 }
3111
0915d02c
JM
3112 if (ieee80211_radiotap_iterator_init(&iter, (void*)buf, len)) {
3113 printf("received invalid radiotap frame\n");
3114 return;
3115 }
3116
0915d02c
JM
3117 while (1) {
3118 ret = ieee80211_radiotap_iterator_next(&iter);
3119 if (ret == -ENOENT)
3120 break;
3121 if (ret) {
3122 printf("received invalid radiotap frame (%d)\n", ret);
3123 return;
3124 }
3125 switch (iter.this_arg_index) {
3126 case IEEE80211_RADIOTAP_FLAGS:
3127 if (*iter.this_arg & IEEE80211_RADIOTAP_F_FCS)
3128 len -= 4;
3129 break;
3130 case IEEE80211_RADIOTAP_RX_FLAGS:
3131 rxflags = 1;
3132 break;
3133 case IEEE80211_RADIOTAP_TX_FLAGS:
3134 injected = 1;
3135 failed = le_to_host16((*(uint16_t *) iter.this_arg)) &
3136 IEEE80211_RADIOTAP_F_TX_FAIL;
3137 break;
3138 case IEEE80211_RADIOTAP_DATA_RETRIES:
3139 break;
3140 case IEEE80211_RADIOTAP_CHANNEL:
2a8b7416 3141 /* TODO: convert from freq/flags to channel number */
0915d02c
JM
3142 break;
3143 case IEEE80211_RADIOTAP_RATE:
2a8b7416 3144 datarate = *iter.this_arg * 5;
0915d02c
JM
3145 break;
3146 case IEEE80211_RADIOTAP_DB_ANTSIGNAL:
2a8b7416 3147 ssi_signal = *iter.this_arg;
0915d02c
JM
3148 break;
3149 }
3150 }
3151
3152 if (rxflags && injected)
3153 return;
3154
3155 if (!injected)
4b9841d3 3156 handle_frame(drv, buf + iter.max_length,
2a8b7416 3157 len - iter.max_length, datarate, ssi_signal);
0915d02c 3158 else
4b9841d3
JM
3159 handle_tx_callback(drv->ctx, buf + iter.max_length,
3160 len - iter.max_length, !failed);
0915d02c
JM
3161}
3162
3163
3164/*
3165 * we post-process the filter code later and rewrite
3166 * this to the offset to the last instruction
3167 */
3168#define PASS 0xFF
3169#define FAIL 0xFE
3170
3171static struct sock_filter msock_filter_insns[] = {
3172 /*
3173 * do a little-endian load of the radiotap length field
3174 */
3175 /* load lower byte into A */
3176 BPF_STMT(BPF_LD | BPF_B | BPF_ABS, 2),
3177 /* put it into X (== index register) */
3178 BPF_STMT(BPF_MISC| BPF_TAX, 0),
3179 /* load upper byte into A */
3180 BPF_STMT(BPF_LD | BPF_B | BPF_ABS, 3),
3181 /* left-shift it by 8 */
3182 BPF_STMT(BPF_ALU | BPF_LSH | BPF_K, 8),
3183 /* or with X */
3184 BPF_STMT(BPF_ALU | BPF_OR | BPF_X, 0),
3185 /* put result into X */
3186 BPF_STMT(BPF_MISC| BPF_TAX, 0),
3187
3188 /*
3189 * Allow management frames through, this also gives us those
3190 * management frames that we sent ourselves with status
3191 */
3192 /* load the lower byte of the IEEE 802.11 frame control field */
3193 BPF_STMT(BPF_LD | BPF_B | BPF_IND, 0),
3194 /* mask off frame type and version */
3195 BPF_STMT(BPF_ALU | BPF_AND | BPF_K, 0xF),
3196 /* accept frame if it's both 0, fall through otherwise */
3197 BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, 0, PASS, 0),
3198
3199 /*
3200 * TODO: add a bit to radiotap RX flags that indicates
3201 * that the sending station is not associated, then
3202 * add a filter here that filters on our DA and that flag
3203 * to allow us to deauth frames to that bad station.
3204 *
3205 * Not a regression -- we didn't do it before either.
3206 */
3207
3208#if 0
3209 /*
fbbfcbac 3210 * drop non-data frames
0915d02c
JM
3211 */
3212 /* load the lower byte of the frame control field */
3213 BPF_STMT(BPF_LD | BPF_B | BPF_IND, 0),
3214 /* mask off QoS bit */
3215 BPF_STMT(BPF_ALU | BPF_AND | BPF_K, 0x0c),
3216 /* drop non-data frames */
3217 BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, 8, 0, FAIL),
fbbfcbac 3218#endif
0915d02c 3219 /* load the upper byte of the frame control field */
fbbfcbac 3220 BPF_STMT(BPF_LD | BPF_B | BPF_IND, 1),
0915d02c
JM
3221 /* mask off toDS/fromDS */
3222 BPF_STMT(BPF_ALU | BPF_AND | BPF_K, 0x03),
fbbfcbac
FF
3223 /* accept WDS frames */
3224 BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, 3, PASS, 0),
0915d02c
JM
3225
3226 /*
3227 * add header length to index
3228 */
3229 /* load the lower byte of the frame control field */
3230 BPF_STMT(BPF_LD | BPF_B | BPF_IND, 0),
3231 /* mask off QoS bit */
3232 BPF_STMT(BPF_ALU | BPF_AND | BPF_K, 0x80),
3233 /* right shift it by 6 to give 0 or 2 */
3234 BPF_STMT(BPF_ALU | BPF_RSH | BPF_K, 6),
3235 /* add data frame header length */
3236 BPF_STMT(BPF_ALU | BPF_ADD | BPF_K, 24),
3237 /* add index, was start of 802.11 header */
3238 BPF_STMT(BPF_ALU | BPF_ADD | BPF_X, 0),
3239 /* move to index, now start of LL header */
3240 BPF_STMT(BPF_MISC | BPF_TAX, 0),
3241
3242 /*
3243 * Accept empty data frames, we use those for
3244 * polling activity.
3245 */
3246 BPF_STMT(BPF_LD | BPF_W | BPF_LEN, 0),
3247 BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_X, 0, PASS, 0),
3248
3249 /*
3250 * Accept EAPOL frames
3251 */
3252 BPF_STMT(BPF_LD | BPF_W | BPF_IND, 0),
3253 BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, 0xAAAA0300, 0, FAIL),
3254 BPF_STMT(BPF_LD | BPF_W | BPF_IND, 4),
3255 BPF_JUMP(BPF_JMP | BPF_JEQ | BPF_K, 0x0000888E, PASS, FAIL),
3256
3257 /* keep these last two statements or change the code below */
3258 /* return 0 == "DROP" */
3259 BPF_STMT(BPF_RET | BPF_K, 0),
3260 /* return ~0 == "keep all" */
3261 BPF_STMT(BPF_RET | BPF_K, ~0),
3262};
3263
3264static struct sock_fprog msock_filter = {
3265 .len = sizeof(msock_filter_insns)/sizeof(msock_filter_insns[0]),
3266 .filter = msock_filter_insns,
3267};
3268
3269
3270static int add_monitor_filter(int s)
3271{
3272 int idx;
3273
3274 /* rewrite all PASS/FAIL jump offsets */
3275 for (idx = 0; idx < msock_filter.len; idx++) {
3276 struct sock_filter *insn = &msock_filter_insns[idx];
3277
3278 if (BPF_CLASS(insn->code) == BPF_JMP) {
3279 if (insn->code == (BPF_JMP|BPF_JA)) {
3280 if (insn->k == PASS)
3281 insn->k = msock_filter.len - idx - 2;
3282 else if (insn->k == FAIL)
3283 insn->k = msock_filter.len - idx - 3;
3284 }
3285
3286 if (insn->jt == PASS)
3287 insn->jt = msock_filter.len - idx - 2;
3288 else if (insn->jt == FAIL)
3289 insn->jt = msock_filter.len - idx - 3;
3290
3291 if (insn->jf == PASS)
3292 insn->jf = msock_filter.len - idx - 2;
3293 else if (insn->jf == FAIL)
3294 insn->jf = msock_filter.len - idx - 3;
3295 }
3296 }
3297
3298 if (setsockopt(s, SOL_SOCKET, SO_ATTACH_FILTER,
3299 &msock_filter, sizeof(msock_filter))) {
3300 perror("SO_ATTACH_FILTER");
3301 return -1;
3302 }
3303
3304 return 0;
3305}
3306
3307
460456f8
JM
3308static void nl80211_remove_monitor_interface(
3309 struct wpa_driver_nl80211_data *drv)
3310{
3311 if (drv->monitor_ifidx >= 0) {
3312 nl80211_remove_iface(drv, drv->monitor_ifidx);
3313 drv->monitor_ifidx = -1;
3314 }
504e905c
JM
3315 if (drv->monitor_sock >= 0) {
3316 eloop_unregister_read_sock(drv->monitor_sock);
3317 close(drv->monitor_sock);
3318 drv->monitor_sock = -1;
3319 }
460456f8
JM
3320}
3321
3322
0915d02c
JM
3323static int
3324nl80211_create_monitor_interface(struct wpa_driver_nl80211_data *drv)
3325{
3326 char buf[IFNAMSIZ];
3327 struct sockaddr_ll ll;
3328 int optval;
3329 socklen_t optlen;
0915d02c 3330
a2e40bb6 3331 snprintf(buf, IFNAMSIZ, "mon.%s", drv->first_bss.ifname);
0915d02c
JM
3332 buf[IFNAMSIZ - 1] = '\0';
3333
3334 drv->monitor_ifidx =
fbbfcbac
FF
3335 nl80211_create_iface(drv, buf, NL80211_IFTYPE_MONITOR, NULL,
3336 0);
0915d02c
JM
3337
3338 if (drv->monitor_ifidx < 0)
3339 return -1;
3340
34f2f814 3341 if (linux_set_iface_flags(drv->ioctl_sock, buf, 1))
0915d02c 3342 goto error;
0915d02c
JM
3343
3344 memset(&ll, 0, sizeof(ll));
3345 ll.sll_family = AF_PACKET;
3346 ll.sll_ifindex = drv->monitor_ifidx;
3347 drv->monitor_sock = socket(PF_PACKET, SOCK_RAW, htons(ETH_P_ALL));
3348 if (drv->monitor_sock < 0) {
3349 perror("socket[PF_PACKET,SOCK_RAW]");
3350 goto error;
3351 }
3352
3353 if (add_monitor_filter(drv->monitor_sock)) {
3354 wpa_printf(MSG_INFO, "Failed to set socket filter for monitor "
3355 "interface; do filtering in user space");
3356 /* This works, but will cost in performance. */
3357 }
3358
2135f224 3359 if (bind(drv->monitor_sock, (struct sockaddr *) &ll, sizeof(ll)) < 0) {
0915d02c
JM
3360 perror("monitor socket bind");
3361 goto error;
3362 }
3363
3364 optlen = sizeof(optval);
3365 optval = 20;
3366 if (setsockopt
3367 (drv->monitor_sock, SOL_SOCKET, SO_PRIORITY, &optval, optlen)) {
3368 perror("Failed to set socket priority");
3369 goto error;
3370 }
3371
3372 if (eloop_register_read_sock(drv->monitor_sock, handle_monitor_read,
3373 drv, NULL)) {
3374 printf("Could not register monitor read socket\n");
3375 goto error;
3376 }
3377
3378 return 0;
3379 error:
460456f8 3380 nl80211_remove_monitor_interface(drv);
0915d02c
JM
3381 return -1;
3382}
3383
db149ac9
JM
3384
3385static const u8 rfc1042_header[6] = { 0xaa, 0xaa, 0x03, 0x00, 0x00, 0x00 };
3386
3387static int wpa_driver_nl80211_hapd_send_eapol(
3388 void *priv, const u8 *addr, const u8 *data,
3389 size_t data_len, int encrypt, const u8 *own_addr)
3390{
a2e40bb6
FF
3391 struct i802_bss *bss = priv;
3392 struct wpa_driver_nl80211_data *drv = bss->drv;
db149ac9
JM
3393 struct ieee80211_hdr *hdr;
3394 size_t len;
3395 u8 *pos;
3396 int res;
3397#if 0 /* FIX */
0de39516 3398 int qos = sta->flags & WPA_STA_WMM;
db149ac9
JM
3399#else
3400 int qos = 0;
3401#endif
3402
3403 len = sizeof(*hdr) + (qos ? 2 : 0) + sizeof(rfc1042_header) + 2 +
3404 data_len;
3405 hdr = os_zalloc(len);
3406 if (hdr == NULL) {
3407 printf("malloc() failed for i802_send_data(len=%lu)\n",
3408 (unsigned long) len);
3409 return -1;
3410 }
3411
3412 hdr->frame_control =
3413 IEEE80211_FC(WLAN_FC_TYPE_DATA, WLAN_FC_STYPE_DATA);
3414 hdr->frame_control |= host_to_le16(WLAN_FC_FROMDS);
3415 if (encrypt)
3416 hdr->frame_control |= host_to_le16(WLAN_FC_ISWEP);
3417#if 0 /* To be enabled if qos determination is added above */
3418 if (qos) {
3419 hdr->frame_control |=
3420 host_to_le16(WLAN_FC_STYPE_QOS_DATA << 4);
3421 }
3422#endif
3423
3424 memcpy(hdr->IEEE80211_DA_FROMDS, addr, ETH_ALEN);
3425 memcpy(hdr->IEEE80211_BSSID_FROMDS, own_addr, ETH_ALEN);
3426 memcpy(hdr->IEEE80211_SA_FROMDS, own_addr, ETH_ALEN);
3427 pos = (u8 *) (hdr + 1);
3428
3429#if 0 /* To be enabled if qos determination is added above */
3430 if (qos) {
3431 /* add an empty QoS header if needed */
3432 pos[0] = 0;
3433 pos[1] = 0;
3434 pos += 2;
3435 }
3436#endif
3437
3438 memcpy(pos, rfc1042_header, sizeof(rfc1042_header));
3439 pos += sizeof(rfc1042_header);
3440 WPA_PUT_BE16(pos, ETH_P_PAE);
3441 pos += 2;
3442 memcpy(pos, data, data_len);
3443
3444 res = wpa_driver_nl80211_send_frame(drv, (u8 *) hdr, len, encrypt);
3445 if (res < 0) {
3446 wpa_printf(MSG_ERROR, "i802_send_eapol - packet len: %lu - "
3447 "failed: %d (%s)",
3448 (unsigned long) len, errno, strerror(errno));
3449 }
7bf12757 3450 os_free(hdr);
db149ac9
JM
3451
3452 return res;
3453}
3454
a8d6ffa4 3455
7e76ee9c
JM
3456static u32 sta_flags_nl80211(int flags)
3457{
3458 u32 f = 0;
3459
0de39516 3460 if (flags & WPA_STA_AUTHORIZED)
7e76ee9c 3461 f |= BIT(NL80211_STA_FLAG_AUTHORIZED);
0de39516 3462 if (flags & WPA_STA_WMM)
7e76ee9c 3463 f |= BIT(NL80211_STA_FLAG_WME);
0de39516 3464 if (flags & WPA_STA_SHORT_PREAMBLE)
7e76ee9c 3465 f |= BIT(NL80211_STA_FLAG_SHORT_PREAMBLE);
0de39516 3466 if (flags & WPA_STA_MFP)
7e76ee9c
JM
3467 f |= BIT(NL80211_STA_FLAG_MFP);
3468
3469 return f;
3470}
3471
3472
3234cba4
JM
3473static int wpa_driver_nl80211_sta_set_flags(void *priv, const u8 *addr,
3474 int total_flags,
4c32757d 3475 int flags_or, int flags_and)
a8d6ffa4 3476{
a2e40bb6
FF
3477 struct i802_bss *bss = priv;
3478 struct wpa_driver_nl80211_data *drv = bss->drv;
a8d6ffa4 3479 struct nl_msg *msg, *flags = NULL;
7e76ee9c 3480 struct nl80211_sta_flag_update upd;
a8d6ffa4
JM
3481
3482 msg = nlmsg_alloc();
3483 if (!msg)
3484 return -ENOMEM;
3485
3486 flags = nlmsg_alloc();
3487 if (!flags) {
3488 nlmsg_free(msg);
3489 return -ENOMEM;
3490 }
3491
3492 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
3493 0, NL80211_CMD_SET_STATION, 0);
3494
3495 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX,
3234cba4 3496 if_nametoindex(bss->ifname));
a8d6ffa4
JM
3497 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
3498
7e76ee9c
JM
3499 /*
3500 * Backwards compatibility version using NL80211_ATTR_STA_FLAGS. This
3501 * can be removed eventually.
3502 */
0de39516 3503 if (total_flags & WPA_STA_AUTHORIZED)
a8d6ffa4
JM
3504 NLA_PUT_FLAG(flags, NL80211_STA_FLAG_AUTHORIZED);
3505
0de39516 3506 if (total_flags & WPA_STA_WMM)
a8d6ffa4
JM
3507 NLA_PUT_FLAG(flags, NL80211_STA_FLAG_WME);
3508
0de39516 3509 if (total_flags & WPA_STA_SHORT_PREAMBLE)
a8d6ffa4
JM
3510 NLA_PUT_FLAG(flags, NL80211_STA_FLAG_SHORT_PREAMBLE);
3511
0de39516 3512 if (total_flags & WPA_STA_MFP)
a8d6ffa4
JM
3513 NLA_PUT_FLAG(flags, NL80211_STA_FLAG_MFP);
3514
3515 if (nla_put_nested(msg, NL80211_ATTR_STA_FLAGS, flags))
3516 goto nla_put_failure;
3517
7e76ee9c
JM
3518 os_memset(&upd, 0, sizeof(upd));
3519 upd.mask = sta_flags_nl80211(flags_or | ~flags_and);
3520 upd.set = sta_flags_nl80211(flags_or);
3521 NLA_PUT(msg, NL80211_ATTR_STA_FLAGS2, sizeof(upd), &upd);
3522
a8d6ffa4
JM
3523 nlmsg_free(flags);
3524
3525 return send_and_recv_msgs(drv, msg, NULL, NULL);
3526 nla_put_failure:
3527 nlmsg_free(flags);
3528 return -ENOBUFS;
3529}
3530
0915d02c 3531
1581b38b
JM
3532static int wpa_driver_nl80211_ap(struct wpa_driver_nl80211_data *drv,
3533 struct wpa_driver_associate_params *params)
3534{
a2e40bb6 3535 if (wpa_driver_nl80211_set_mode(&drv->first_bss, params->mode) ||
f019981a 3536 wpa_driver_nl80211_set_freq(drv, params->freq, 0, 0)) {
460456f8 3537 nl80211_remove_monitor_interface(drv);
1581b38b 3538 return -1;
0915d02c 3539 }
1581b38b
JM
3540
3541 /* TODO: setup monitor interface (and add code somewhere to remove this
3542 * when AP mode is stopped; associate with mode != 2 or drv_deinit) */
1581b38b
JM
3543
3544 return 0;
3545}
1581b38b
JM
3546
3547
5cc4d64b
JM
3548static int nl80211_leave_ibss(struct wpa_driver_nl80211_data *drv)
3549{
3550 struct nl_msg *msg;
3551 int ret = -1;
3552
3553 msg = nlmsg_alloc();
3554 if (!msg)
3555 return -1;
3556
3557 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
3558 NL80211_CMD_LEAVE_IBSS, 0);
3559 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
3560 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
3561 msg = NULL;
3562 if (ret) {
3563 wpa_printf(MSG_DEBUG, "nl80211: Leave IBSS failed: ret=%d "
3564 "(%s)", ret, strerror(-ret));
3565 goto nla_put_failure;
3566 }
3567
3568 ret = 0;
3569 wpa_printf(MSG_DEBUG, "nl80211: Leave IBSS request sent successfully");
3570
3571nla_put_failure:
3572 nlmsg_free(msg);
3573 return ret;
3574}
3575
3576
3577static int wpa_driver_nl80211_ibss(struct wpa_driver_nl80211_data *drv,
3578 struct wpa_driver_associate_params *params)
3579{
3580 struct nl_msg *msg;
3581 int ret = -1;
3582 int count = 0;
3583
3584 wpa_printf(MSG_DEBUG, "nl80211: Join IBSS (ifindex=%d)", drv->ifindex);
3585
a2e40bb6 3586 if (wpa_driver_nl80211_set_mode(&drv->first_bss, params->mode)) {
5cc4d64b
JM
3587 wpa_printf(MSG_INFO, "nl80211: Failed to set interface into "
3588 "IBSS mode");
3589 return -1;
3590 }
3591
3592retry:
3593 msg = nlmsg_alloc();
3594 if (!msg)
3595 return -1;
3596
3597 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
3598 NL80211_CMD_JOIN_IBSS, 0);
3599 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
3600
3601 if (params->ssid == NULL || params->ssid_len > sizeof(drv->ssid))
3602 goto nla_put_failure;
3603
3604 wpa_hexdump_ascii(MSG_DEBUG, " * SSID",
3605 params->ssid, params->ssid_len);
3606 NLA_PUT(msg, NL80211_ATTR_SSID, params->ssid_len,
3607 params->ssid);
3608 os_memcpy(drv->ssid, params->ssid, params->ssid_len);
3609 drv->ssid_len = params->ssid_len;
3610
3611 wpa_printf(MSG_DEBUG, " * freq=%d", params->freq);
3612 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, params->freq);
3613
3614 ret = nl80211_set_conn_keys(params, msg);
3615 if (ret)
3616 goto nla_put_failure;
3617
a95795ad
JM
3618 if (params->wpa_ie) {
3619 wpa_hexdump(MSG_DEBUG,
3620 " * Extra IEs for Beacon/Probe Response frames",
3621 params->wpa_ie, params->wpa_ie_len);
3622 NLA_PUT(msg, NL80211_ATTR_IE, params->wpa_ie_len,
3623 params->wpa_ie);
3624 }
3625
5cc4d64b
JM
3626 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
3627 msg = NULL;
3628 if (ret) {
3629 wpa_printf(MSG_DEBUG, "nl80211: Join IBSS failed: ret=%d (%s)",
3630 ret, strerror(-ret));
3631 count++;
3632 if (ret == -EALREADY && count == 1) {
3633 wpa_printf(MSG_DEBUG, "nl80211: Retry IBSS join after "
3634 "forced leave");
3635 nl80211_leave_ibss(drv);
3636 nlmsg_free(msg);
3637 goto retry;
3638 }
3639
3640 goto nla_put_failure;
3641 }
3642 ret = 0;
3643 wpa_printf(MSG_DEBUG, "nl80211: Join IBSS request sent successfully");
3644
3645nla_put_failure:
3646 nlmsg_free(msg);
3647 return ret;
3648}
3649
3650
cfaab580
ZY
3651static int wpa_driver_nl80211_connect(
3652 struct wpa_driver_nl80211_data *drv,
3653 struct wpa_driver_associate_params *params)
3654{
3655 struct nl_msg *msg;
3656 enum nl80211_auth_type type;
3657 int ret = 0;
3658
3659 msg = nlmsg_alloc();
3660 if (!msg)
3661 return -1;
3662
3663 wpa_printf(MSG_DEBUG, "nl80211: Connect (ifindex=%d)", drv->ifindex);
3664 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
3665 NL80211_CMD_CONNECT, 0);
3666
3667 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
3668 if (params->bssid) {
3669 wpa_printf(MSG_DEBUG, " * bssid=" MACSTR,
3670 MAC2STR(params->bssid));
3671 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, params->bssid);
3672 }
3673 if (params->freq) {
3674 wpa_printf(MSG_DEBUG, " * freq=%d", params->freq);
3675 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, params->freq);
3676 }
3677 if (params->ssid) {
3678 wpa_hexdump_ascii(MSG_DEBUG, " * SSID",
3679 params->ssid, params->ssid_len);
3680 NLA_PUT(msg, NL80211_ATTR_SSID, params->ssid_len,
3681 params->ssid);
3682 if (params->ssid_len > sizeof(drv->ssid))
3683 goto nla_put_failure;
3684 os_memcpy(drv->ssid, params->ssid, params->ssid_len);
3685 drv->ssid_len = params->ssid_len;
3686 }
3687 wpa_hexdump(MSG_DEBUG, " * IEs", params->wpa_ie, params->wpa_ie_len);
3688 if (params->wpa_ie)
3689 NLA_PUT(msg, NL80211_ATTR_IE, params->wpa_ie_len,
3690 params->wpa_ie);
3691
abd9fafa 3692 if (params->auth_alg & WPA_AUTH_ALG_OPEN)
cfaab580 3693 type = NL80211_AUTHTYPE_OPEN_SYSTEM;
abd9fafa 3694 else if (params->auth_alg & WPA_AUTH_ALG_SHARED)
cfaab580 3695 type = NL80211_AUTHTYPE_SHARED_KEY;
abd9fafa 3696 else if (params->auth_alg & WPA_AUTH_ALG_LEAP)
cfaab580 3697 type = NL80211_AUTHTYPE_NETWORK_EAP;
abd9fafa 3698 else if (params->auth_alg & WPA_AUTH_ALG_FT)
cfaab580
ZY
3699 type = NL80211_AUTHTYPE_FT;
3700 else
3701 goto nla_put_failure;
3702
3703 wpa_printf(MSG_DEBUG, " * Auth Type %d", type);
3704 NLA_PUT_U32(msg, NL80211_ATTR_AUTH_TYPE, type);
3705
3706 if (params->wpa_ie && params->wpa_ie_len) {
3707 enum nl80211_wpa_versions ver;
3708
3709 if (params->wpa_ie[0] == WLAN_EID_RSN)
3710 ver = NL80211_WPA_VERSION_2;
3711 else
3712 ver = NL80211_WPA_VERSION_1;
3713
3714 wpa_printf(MSG_DEBUG, " * WPA Version %d", ver);
3715 NLA_PUT_U32(msg, NL80211_ATTR_WPA_VERSIONS, ver);
3716 }
3717
3718 if (params->pairwise_suite != CIPHER_NONE) {
c1bb3e0a 3719 int cipher;
cfaab580
ZY
3720
3721 switch (params->pairwise_suite) {
3722 case CIPHER_WEP40:
3723 cipher = WLAN_CIPHER_SUITE_WEP40;
3724 break;
3725 case CIPHER_WEP104:
3726 cipher = WLAN_CIPHER_SUITE_WEP104;
3727 break;
3728 case CIPHER_CCMP:
3729 cipher = WLAN_CIPHER_SUITE_CCMP;
3730 break;
3731 case CIPHER_TKIP:
3732 default:
3733 cipher = WLAN_CIPHER_SUITE_TKIP;
3734 break;
3735 }
3736 NLA_PUT_U32(msg, NL80211_ATTR_CIPHER_SUITES_PAIRWISE, cipher);
3737 }
3738
3739 if (params->group_suite != CIPHER_NONE) {
c1bb3e0a 3740 int cipher;
cfaab580
ZY
3741
3742 switch (params->group_suite) {
3743 case CIPHER_WEP40:
3744 cipher = WLAN_CIPHER_SUITE_WEP40;
3745 break;
3746 case CIPHER_WEP104:
3747 cipher = WLAN_CIPHER_SUITE_WEP104;
3748 break;
3749 case CIPHER_CCMP:
3750 cipher = WLAN_CIPHER_SUITE_CCMP;
3751 break;
3752 case CIPHER_TKIP:
3753 default:
3754 cipher = WLAN_CIPHER_SUITE_TKIP;
3755 break;
3756 }
3757 NLA_PUT_U32(msg, NL80211_ATTR_CIPHER_SUITE_GROUP, cipher);
3758 }
3759
3760 if (params->key_mgmt_suite == KEY_MGMT_802_1X ||
3761 params->key_mgmt_suite == KEY_MGMT_PSK) {
3762 int mgmt = WLAN_AKM_SUITE_PSK;
3763
3764 switch (params->key_mgmt_suite) {
3765 case KEY_MGMT_802_1X:
3766 mgmt = WLAN_AKM_SUITE_8021X;
3767 break;
3768 case KEY_MGMT_PSK:
3769 default:
3770 mgmt = WLAN_AKM_SUITE_PSK;
3771 break;
3772 }
3773 NLA_PUT_U32(msg, NL80211_ATTR_AKM_SUITES, mgmt);
3774 }
3775
3776 ret = nl80211_set_conn_keys(params, msg);
3777 if (ret)
3778 goto nla_put_failure;
3779
3780 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
3781 msg = NULL;
3782 if (ret) {
3783 wpa_printf(MSG_DEBUG, "nl80211: MLME connect failed: ret=%d "
3784 "(%s)", ret, strerror(-ret));
3785 goto nla_put_failure;
3786 }
3787 ret = 0;
3788 wpa_printf(MSG_DEBUG, "nl80211: Connect request send successfully");
3789
3790nla_put_failure:
3791 nlmsg_free(msg);
3792 return ret;
3793
3794}
3795
3796
c2a04078
JM
3797static int wpa_driver_nl80211_associate(
3798 void *priv, struct wpa_driver_associate_params *params)
3799{
a2e40bb6
FF
3800 struct i802_bss *bss = priv;
3801 struct wpa_driver_nl80211_data *drv = bss->drv;
c2a04078
JM
3802 int ret = -1;
3803 struct nl_msg *msg;
3804
5cc4d64b 3805 if (params->mode == IEEE80211_MODE_AP)
1581b38b 3806 return wpa_driver_nl80211_ap(drv, params);
1581b38b 3807
5cc4d64b
JM
3808 if (params->mode == IEEE80211_MODE_IBSS)
3809 return wpa_driver_nl80211_ibss(drv, params);
3810
4a867032 3811 if (!(drv->capa.flags & WPA_DRIVER_FLAGS_SME)) {
a2e40bb6 3812 if (wpa_driver_nl80211_set_mode(priv, params->mode) < 0)
4a867032 3813 return -1;
cfaab580 3814 return wpa_driver_nl80211_connect(drv, params);
4a867032 3815 }
cfaab580 3816
c2a04078
JM
3817 drv->associated = 0;
3818
3819 msg = nlmsg_alloc();
3820 if (!msg)
3821 return -1;
3822
3823 wpa_printf(MSG_DEBUG, "nl80211: Associate (ifindex=%d)",
3824 drv->ifindex);
3825 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
3826 NL80211_CMD_ASSOCIATE, 0);
3827
3828 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
3829 if (params->bssid) {
3830 wpa_printf(MSG_DEBUG, " * bssid=" MACSTR,
3831 MAC2STR(params->bssid));
3832 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, params->bssid);
3833 }
3834 if (params->freq) {
3835 wpa_printf(MSG_DEBUG, " * freq=%d", params->freq);
3836 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, params->freq);
4832ecd7
JM
3837 drv->assoc_freq = params->freq;
3838 } else
3839 drv->assoc_freq = 0;
c2a04078
JM
3840 if (params->ssid) {
3841 wpa_hexdump_ascii(MSG_DEBUG, " * SSID",
3842 params->ssid, params->ssid_len);
3843 NLA_PUT(msg, NL80211_ATTR_SSID, params->ssid_len,
3844 params->ssid);
fd05d64e
JM
3845 if (params->ssid_len > sizeof(drv->ssid))
3846 goto nla_put_failure;
3847 os_memcpy(drv->ssid, params->ssid, params->ssid_len);
3848 drv->ssid_len = params->ssid_len;
c2a04078
JM
3849 }
3850 wpa_hexdump(MSG_DEBUG, " * IEs", params->wpa_ie, params->wpa_ie_len);
3851 if (params->wpa_ie)
3852 NLA_PUT(msg, NL80211_ATTR_IE, params->wpa_ie_len,
3853 params->wpa_ie);
3854
e572fa33
JM
3855#ifdef CONFIG_IEEE80211W
3856 if (params->mgmt_frame_protection == MGMT_FRAME_PROTECTION_REQUIRED)
3857 NLA_PUT_U32(msg, NL80211_ATTR_USE_MFP, NL80211_MFP_REQUIRED);
3858#endif /* CONFIG_IEEE80211W */
3859
01652550
JM
3860 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT);
3861
62fa124c
JM
3862 if (params->prev_bssid) {
3863 wpa_printf(MSG_DEBUG, " * prev_bssid=" MACSTR,
3864 MAC2STR(params->prev_bssid));
3865 NLA_PUT(msg, NL80211_ATTR_PREV_BSSID, ETH_ALEN,
3866 params->prev_bssid);
3867 }
3868
c2a04078
JM
3869 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
3870 msg = NULL;
3871 if (ret) {
3872 wpa_printf(MSG_DEBUG, "nl80211: MLME command failed: ret=%d "
3873 "(%s)", ret, strerror(-ret));
8856462d 3874 nl80211_dump_scan(drv);
c2a04078
JM
3875 goto nla_put_failure;
3876 }
3877 ret = 0;
3878 wpa_printf(MSG_DEBUG, "nl80211: Association request send "
3879 "successfully");
3880
3881nla_put_failure:
3882 nlmsg_free(msg);
3883 return ret;
3884}
3f5285e8
JM
3885
3886
ad1e68e6
JM
3887static int nl80211_set_mode(struct wpa_driver_nl80211_data *drv,
3888 int ifindex, int mode)
3f5285e8 3889{
3f5285e8 3890 struct nl_msg *msg;
ad1e68e6
JM
3891 int ret = -ENOBUFS;
3892
3893 msg = nlmsg_alloc();
3894 if (!msg)
3895 return -ENOMEM;
3896
3897 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
3898 0, NL80211_CMD_SET_INTERFACE, 0);
3899 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, ifindex);
3900 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, mode);
3901
3902 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
3903 if (!ret)
3904 return 0;
3905nla_put_failure:
3906 wpa_printf(MSG_DEBUG, "nl80211: Failed to set interface %d to mode %d:"
3907 " %d (%s)", ifindex, mode, ret, strerror(-ret));
3908 return ret;
3909}
3910
3911
3912static int wpa_driver_nl80211_set_mode(void *priv, int mode)
3913{
a2e40bb6
FF
3914 struct i802_bss *bss = priv;
3915 struct wpa_driver_nl80211_data *drv = bss->drv;
ad1e68e6 3916 int ret = -1;
1581b38b
JM
3917 int nlmode;
3918
3919 switch (mode) {
3920 case 0:
3921 nlmode = NL80211_IFTYPE_STATION;
3922 break;
3923 case 1:
3924 nlmode = NL80211_IFTYPE_ADHOC;
3925 break;
3926 case 2:
3927 nlmode = NL80211_IFTYPE_AP;
3928 break;
3929 default:
3930 return -1;
3931 }
3f5285e8 3932
ad1e68e6
JM
3933 if (nl80211_set_mode(drv, drv->ifindex, nlmode) == 0) {
3934 drv->nlmode = nlmode;
460456f8
JM
3935 ret = 0;
3936 goto done;
ad1e68e6 3937 }
3f5285e8 3938
460456f8 3939 if (nlmode == drv->nlmode) {
c6e8e8e4
JM
3940 wpa_printf(MSG_DEBUG, "nl80211: Interface already in "
3941 "requested mode - ignore error");
460456f8
JM
3942 ret = 0;
3943 goto done; /* Already in the requested mode */
3944 }
3f5285e8 3945
3f5285e8
JM
3946 /* mac80211 doesn't allow mode changes while the device is up, so
3947 * take the device down, try to set the mode again, and bring the
3948 * device back up.
3949 */
a2e40bb6 3950 if (linux_set_iface_flags(drv->ioctl_sock, bss->ifname, 0) == 0) {
3f5285e8 3951 /* Try to set the mode again while the interface is down */
ad1e68e6 3952 ret = nl80211_set_mode(drv, drv->ifindex, nlmode);
a2e40bb6 3953 if (linux_set_iface_flags(drv->ioctl_sock, bss->ifname, 1))
2135f224 3954 ret = -1;
3f5285e8
JM
3955 }
3956
c6e8e8e4
JM
3957 if (!ret) {
3958 wpa_printf(MSG_DEBUG, "nl80211: Mode change succeeded while "
3959 "interface is down");
ad1e68e6 3960 drv->nlmode = nlmode;
c6e8e8e4 3961 }
ad1e68e6 3962
460456f8 3963done:
460456f8
JM
3964 if (!ret && nlmode == NL80211_IFTYPE_AP) {
3965 /* Setup additional AP mode functionality if needed */
3966 if (drv->monitor_ifidx < 0 &&
3967 nl80211_create_monitor_interface(drv))
3968 return -1;
3969 } else if (!ret && nlmode != NL80211_IFTYPE_AP) {
3970 /* Remove additional AP mode functionality */
3971 nl80211_remove_monitor_interface(drv);
a2e40bb6 3972 bss->beacon_set = 0;
460456f8 3973 }
460456f8 3974
c6e8e8e4
JM
3975 if (ret)
3976 wpa_printf(MSG_DEBUG, "nl80211: Interface mode change to %d "
3977 "from %d failed", nlmode, drv->nlmode);
3978
3f5285e8
JM
3979 return ret;
3980}
3981
3982
3f5285e8
JM
3983static int wpa_driver_nl80211_get_capa(void *priv,
3984 struct wpa_driver_capa *capa)
3985{
a2e40bb6
FF
3986 struct i802_bss *bss = priv;
3987 struct wpa_driver_nl80211_data *drv = bss->drv;
3f5285e8
JM
3988 if (!drv->has_capability)
3989 return -1;
3990 os_memcpy(capa, &drv->capa, sizeof(*capa));
3991 return 0;
3992}
3993
3994
3995static int wpa_driver_nl80211_set_operstate(void *priv, int state)
3996{
a2e40bb6
FF
3997 struct i802_bss *bss = priv;
3998 struct wpa_driver_nl80211_data *drv = bss->drv;
3f5285e8
JM
3999
4000 wpa_printf(MSG_DEBUG, "%s: operstate %d->%d (%s)",
4001 __func__, drv->operstate, state, state ? "UP" : "DORMANT");
4002 drv->operstate = state;
08063178 4003 return netlink_send_oper_ifla(drv->netlink, drv->ifindex, -1,
e2d02c29 4004 state ? IF_OPER_UP : IF_OPER_DORMANT);
3f5285e8
JM
4005}
4006
01652550
JM
4007
4008static int wpa_driver_nl80211_set_supp_port(void *priv, int authorized)
4009{
a2e40bb6
FF
4010 struct i802_bss *bss = priv;
4011 struct wpa_driver_nl80211_data *drv = bss->drv;
01652550
JM
4012 struct nl_msg *msg;
4013 struct nl80211_sta_flag_update upd;
4014
4015 msg = nlmsg_alloc();
4016 if (!msg)
4017 return -ENOMEM;
4018
4019 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
4020 0, NL80211_CMD_SET_STATION, 0);
4021
4022 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX,
a2e40bb6 4023 if_nametoindex(bss->ifname));
01652550
JM
4024 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, drv->bssid);
4025
4026 os_memset(&upd, 0, sizeof(upd));
4027 upd.mask = BIT(NL80211_STA_FLAG_AUTHORIZED);
4028 if (authorized)
4029 upd.set = BIT(NL80211_STA_FLAG_AUTHORIZED);
4030 NLA_PUT(msg, NL80211_ATTR_STA_FLAGS2, sizeof(upd), &upd);
4031
4032 return send_and_recv_msgs(drv, msg, NULL, NULL);
4033 nla_put_failure:
4034 return -ENOBUFS;
4035}
4036
3f5285e8 4037
c5121837
JM
4038#ifdef HOSTAPD
4039
c5121837
JM
4040static void add_ifidx(struct wpa_driver_nl80211_data *drv, int ifidx)
4041{
4042 int i;
4043 int *old;
4044
4045 wpa_printf(MSG_DEBUG, "nl80211: Add own interface ifindex %d",
4046 ifidx);
4047 for (i = 0; i < drv->num_if_indices; i++) {
4048 if (drv->if_indices[i] == 0) {
4049 drv->if_indices[i] = ifidx;
4050 return;
4051 }
4052 }
4053
4054 if (drv->if_indices != drv->default_if_indices)
4055 old = drv->if_indices;
4056 else
4057 old = NULL;
4058
7bf12757
JM
4059 drv->if_indices = os_realloc(old,
4060 sizeof(int) * (drv->num_if_indices + 1));
c5121837
JM
4061 if (!drv->if_indices) {
4062 if (!old)
4063 drv->if_indices = drv->default_if_indices;
4064 else
4065 drv->if_indices = old;
4066 wpa_printf(MSG_ERROR, "Failed to reallocate memory for "
4067 "interfaces");
4068 wpa_printf(MSG_ERROR, "Ignoring EAPOL on interface %d", ifidx);
4069 return;
4070 }
4071 drv->if_indices[drv->num_if_indices] = ifidx;
4072 drv->num_if_indices++;
4073}
4074
4075
4076static void del_ifidx(struct wpa_driver_nl80211_data *drv, int ifidx)
4077{
4078 int i;
4079
4080 for (i = 0; i < drv->num_if_indices; i++) {
4081 if (drv->if_indices[i] == ifidx) {
4082 drv->if_indices[i] = 0;
4083 break;
4084 }
4085 }
4086}
4087
4088
4089static int have_ifidx(struct wpa_driver_nl80211_data *drv, int ifidx)
4090{
4091 int i;
4092
4093 for (i = 0; i < drv->num_if_indices; i++)
4094 if (drv->if_indices[i] == ifidx)
4095 return 1;
4096
4097 return 0;
4098}
4099
4100
c5121837
JM
4101static inline int min_int(int a, int b)
4102{
4103 if (a < b)
4104 return a;
4105 return b;
4106}
4107
4108
4109static int get_key_handler(struct nl_msg *msg, void *arg)
4110{
4111 struct nlattr *tb[NL80211_ATTR_MAX + 1];
4112 struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
4113
4114 nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
4115 genlmsg_attrlen(gnlh, 0), NULL);
4116
4117 /*
4118 * TODO: validate the key index and mac address!
4119 * Otherwise, there's a race condition as soon as
4120 * the kernel starts sending key notifications.
4121 */
4122
4123 if (tb[NL80211_ATTR_KEY_SEQ])
4124 memcpy(arg, nla_data(tb[NL80211_ATTR_KEY_SEQ]),
4125 min_int(nla_len(tb[NL80211_ATTR_KEY_SEQ]), 6));
4126 return NL_SKIP;
4127}
4128
4129
4130static int i802_get_seqnum(const char *iface, void *priv, const u8 *addr,
4131 int idx, u8 *seq)
4132{
a2e40bb6
FF
4133 struct i802_bss *bss = priv;
4134 struct wpa_driver_nl80211_data *drv = bss->drv;
c5121837
JM
4135 struct nl_msg *msg;
4136
4137 msg = nlmsg_alloc();
4138 if (!msg)
4139 return -ENOMEM;
4140
4141 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
4142 0, NL80211_CMD_GET_KEY, 0);
4143
4144 if (addr)
4145 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4146 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, idx);
4147 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, if_nametoindex(iface));
4148
4149 memset(seq, 0, 6);
4150
4151 return send_and_recv_msgs(drv, msg, get_key_handler, seq);
4152 nla_put_failure:
4153 return -ENOBUFS;
4154}
4155
4156
4157static int i802_set_rate_sets(void *priv, int *supp_rates, int *basic_rates,
4158 int mode)
4159{
a2e40bb6
FF
4160 struct i802_bss *bss = priv;
4161 struct wpa_driver_nl80211_data *drv = bss->drv;
c5121837
JM
4162 struct nl_msg *msg;
4163 u8 rates[NL80211_MAX_SUPP_RATES];
4164 u8 rates_len = 0;
4165 int i;
4166
4167 msg = nlmsg_alloc();
4168 if (!msg)
4169 return -ENOMEM;
4170
4171 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
4172 NL80211_CMD_SET_BSS, 0);
4173
4174 for (i = 0; i < NL80211_MAX_SUPP_RATES && basic_rates[i] >= 0; i++)
4175 rates[rates_len++] = basic_rates[i] / 5;
4176
4177 NLA_PUT(msg, NL80211_ATTR_BSS_BASIC_RATES, rates_len, rates);
4178
a2e40bb6 4179 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, if_nametoindex(bss->ifname));
c5121837
JM
4180
4181 return send_and_recv_msgs(drv, msg, NULL, NULL);
4182 nla_put_failure:
4183 return -ENOBUFS;
4184}
4185
4186
c5121837
JM
4187/* Set kernel driver on given frequency (MHz) */
4188static int i802_set_freq(void *priv, struct hostapd_freq_params *freq)
4189{
a2e40bb6
FF
4190 struct i802_bss *bss = priv;
4191 struct wpa_driver_nl80211_data *drv = bss->drv;
f019981a
JM
4192 return wpa_driver_nl80211_set_freq(drv, freq->freq, freq->ht_enabled,
4193 freq->sec_channel_offset);
c5121837
JM
4194}
4195
4196
4197static int i802_set_rts(void *priv, int rts)
4198{
a2e40bb6
FF
4199 struct i802_bss *bss = priv;
4200 struct wpa_driver_nl80211_data *drv = bss->drv;
ad649451
JM
4201 struct nl_msg *msg;
4202 int ret = -ENOBUFS;
4203 u32 val;
c5121837 4204
ad649451
JM
4205 msg = nlmsg_alloc();
4206 if (!msg)
4207 return -ENOMEM;
c5121837 4208
ad649451
JM
4209 if (rts >= 2347)
4210 val = (u32) -1;
4211 else
4212 val = rts;
c5121837 4213
ad649451
JM
4214 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
4215 0, NL80211_CMD_SET_WIPHY, 0);
4216 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
4217 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD, val);
4218
4219 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
4220 if (!ret)
4221 return 0;
4222nla_put_failure:
4223 wpa_printf(MSG_DEBUG, "nl80211: Failed to set RTS threshold %d: "
4224 "%d (%s)", rts, ret, strerror(-ret));
4225 return ret;
c5121837
JM
4226}
4227
4228
4229static int i802_set_frag(void *priv, int frag)
4230{
a2e40bb6
FF
4231 struct i802_bss *bss = priv;
4232 struct wpa_driver_nl80211_data *drv = bss->drv;
ad649451
JM
4233 struct nl_msg *msg;
4234 int ret = -ENOBUFS;
4235 u32 val;
c5121837 4236
ad649451
JM
4237 msg = nlmsg_alloc();
4238 if (!msg)
4239 return -ENOMEM;
c5121837 4240
ad649451
JM
4241 if (frag >= 2346)
4242 val = (u32) -1;
4243 else
4244 val = frag;
c5121837 4245
ad649451
JM
4246 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
4247 0, NL80211_CMD_SET_WIPHY, 0);
4248 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
4249 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD, val);
4250
4251 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
4252 if (!ret)
4253 return 0;
4254nla_put_failure:
4255 wpa_printf(MSG_DEBUG, "nl80211: Failed to set fragmentation threshold "
4256 "%d: %d (%s)", frag, ret, strerror(-ret));
4257 return ret;
c5121837
JM
4258}
4259
4260
c5121837
JM
4261static int i802_flush(void *priv)
4262{
a2e40bb6
FF
4263 struct i802_bss *bss = priv;
4264 struct wpa_driver_nl80211_data *drv = bss->drv;
c5121837
JM
4265 struct nl_msg *msg;
4266
4267 msg = nlmsg_alloc();
4268 if (!msg)
4269 return -1;
4270
4271 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
4272 0, NL80211_CMD_DEL_STATION, 0);
4273
4274 /*
4275 * XXX: FIX! this needs to flush all VLANs too
4276 */
4277 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX,
a2e40bb6 4278 if_nametoindex(bss->ifname));
c5121837
JM
4279
4280 return send_and_recv_msgs(drv, msg, NULL, NULL);
4281 nla_put_failure:
4282 return -ENOBUFS;
4283}
4284
4285
4286static int get_sta_handler(struct nl_msg *msg, void *arg)
4287{
4288 struct nlattr *tb[NL80211_ATTR_MAX + 1];
4289 struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
4290 struct hostap_sta_driver_data *data = arg;
4291 struct nlattr *stats[NL80211_STA_INFO_MAX + 1];
4292 static struct nla_policy stats_policy[NL80211_STA_INFO_MAX + 1] = {
4293 [NL80211_STA_INFO_INACTIVE_TIME] = { .type = NLA_U32 },
4294 [NL80211_STA_INFO_RX_BYTES] = { .type = NLA_U32 },
4295 [NL80211_STA_INFO_TX_BYTES] = { .type = NLA_U32 },
4296 [NL80211_STA_INFO_RX_PACKETS] = { .type = NLA_U32 },
4297 [NL80211_STA_INFO_TX_PACKETS] = { .type = NLA_U32 },
4298 };
4299
4300 nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
4301 genlmsg_attrlen(gnlh, 0), NULL);
4302
4303 /*
4304 * TODO: validate the interface and mac address!
4305 * Otherwise, there's a race condition as soon as
4306 * the kernel starts sending station notifications.
4307 */
4308
4309 if (!tb[NL80211_ATTR_STA_INFO]) {
4310 wpa_printf(MSG_DEBUG, "sta stats missing!");
4311 return NL_SKIP;
4312 }
4313 if (nla_parse_nested(stats, NL80211_STA_INFO_MAX,
4314 tb[NL80211_ATTR_STA_INFO],
4315 stats_policy)) {
4316 wpa_printf(MSG_DEBUG, "failed to parse nested attributes!");
4317 return NL_SKIP;
4318 }
4319
4320 if (stats[NL80211_STA_INFO_INACTIVE_TIME])
4321 data->inactive_msec =
4322 nla_get_u32(stats[NL80211_STA_INFO_INACTIVE_TIME]);
4323 if (stats[NL80211_STA_INFO_RX_BYTES])
4324 data->rx_bytes = nla_get_u32(stats[NL80211_STA_INFO_RX_BYTES]);
4325 if (stats[NL80211_STA_INFO_TX_BYTES])
4326 data->tx_bytes = nla_get_u32(stats[NL80211_STA_INFO_TX_BYTES]);
4327 if (stats[NL80211_STA_INFO_RX_PACKETS])
4328 data->rx_packets =
4329 nla_get_u32(stats[NL80211_STA_INFO_RX_PACKETS]);
4330 if (stats[NL80211_STA_INFO_TX_PACKETS])
4331 data->tx_packets =
4332 nla_get_u32(stats[NL80211_STA_INFO_TX_PACKETS]);
4333
4334 return NL_SKIP;
4335}
4336
4337static int i802_read_sta_data(void *priv, struct hostap_sta_driver_data *data,
4338 const u8 *addr)
4339{
a2e40bb6
FF
4340 struct i802_bss *bss = priv;
4341 struct wpa_driver_nl80211_data *drv = bss->drv;
c5121837
JM
4342 struct nl_msg *msg;
4343
4344 os_memset(data, 0, sizeof(*data));
4345 msg = nlmsg_alloc();
4346 if (!msg)
4347 return -ENOMEM;
4348
4349 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
4350 0, NL80211_CMD_GET_STATION, 0);
4351
4352 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
a2e40bb6 4353 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, if_nametoindex(bss->ifname));
c5121837
JM
4354
4355 return send_and_recv_msgs(drv, msg, get_sta_handler, data);
4356 nla_put_failure:
4357 return -ENOBUFS;
4358}
4359
4360
c5121837
JM
4361static int i802_set_tx_queue_params(void *priv, int queue, int aifs,
4362 int cw_min, int cw_max, int burst_time)
4363{
a2e40bb6
FF
4364 struct i802_bss *bss = priv;
4365 struct wpa_driver_nl80211_data *drv = bss->drv;
c5121837
JM
4366 struct nl_msg *msg;
4367 struct nlattr *txq, *params;
4368
4369 msg = nlmsg_alloc();
4370 if (!msg)
4371 return -1;
4372
4373 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
4374 0, NL80211_CMD_SET_WIPHY, 0);
4375
a2e40bb6 4376 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, if_nametoindex(bss->ifname));
c5121837
JM
4377
4378 txq = nla_nest_start(msg, NL80211_ATTR_WIPHY_TXQ_PARAMS);
4379 if (!txq)
4380 goto nla_put_failure;
4381
4382 /* We are only sending parameters for a single TXQ at a time */
4383 params = nla_nest_start(msg, 1);
4384 if (!params)
4385 goto nla_put_failure;
4386
4387 NLA_PUT_U8(msg, NL80211_TXQ_ATTR_QUEUE, queue);
4388 /* Burst time is configured in units of 0.1 msec and TXOP parameter in
4389 * 32 usec, so need to convert the value here. */
4390 NLA_PUT_U16(msg, NL80211_TXQ_ATTR_TXOP, (burst_time * 100 + 16) / 32);
4391 NLA_PUT_U16(msg, NL80211_TXQ_ATTR_CWMIN, cw_min);
4392 NLA_PUT_U16(msg, NL80211_TXQ_ATTR_CWMAX, cw_max);
4393 NLA_PUT_U8(msg, NL80211_TXQ_ATTR_AIFS, aifs);
4394
4395 nla_nest_end(msg, params);
4396
4397 nla_nest_end(msg, txq);
4398
4399 if (send_and_recv_msgs(drv, msg, NULL, NULL) == 0)
4400 return 0;
4401 nla_put_failure:
4402 return -1;
4403}
4404
4405
c5121837
JM
4406static int i802_set_bss(void *priv, int cts, int preamble, int slot)
4407{
a2e40bb6
FF
4408 struct i802_bss *bss = priv;
4409 struct wpa_driver_nl80211_data *drv = bss->drv;
c5121837
JM
4410 struct nl_msg *msg;
4411
4412 msg = nlmsg_alloc();
4413 if (!msg)
4414 return -ENOMEM;
4415
4416 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
4417 NL80211_CMD_SET_BSS, 0);
4418
4419 if (cts >= 0)
4420 NLA_PUT_U8(msg, NL80211_ATTR_BSS_CTS_PROT, cts);
4421 if (preamble >= 0)
4422 NLA_PUT_U8(msg, NL80211_ATTR_BSS_SHORT_PREAMBLE, preamble);
4423 if (slot >= 0)
4424 NLA_PUT_U8(msg, NL80211_ATTR_BSS_SHORT_SLOT_TIME, slot);
4425
a2e40bb6 4426 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, if_nametoindex(bss->ifname));
c5121837
JM
4427
4428 return send_and_recv_msgs(drv, msg, NULL, NULL);
4429 nla_put_failure:
4430 return -ENOBUFS;
4431}
4432
4433
4434static int i802_set_cts_protect(void *priv, int value)
4435{
4436 return i802_set_bss(priv, value, -1, -1);
4437}
4438
4439
4440static int i802_set_preamble(void *priv, int value)
4441{
4442 return i802_set_bss(priv, -1, value, -1);
4443}
4444
4445
4446static int i802_set_short_slot_time(void *priv, int value)
4447{
4448 return i802_set_bss(priv, -1, -1, value);
4449}
4450
4451
c5121837
JM
4452static int i802_set_sta_vlan(void *priv, const u8 *addr,
4453 const char *ifname, int vlan_id)
4454{
a2e40bb6
FF
4455 struct i802_bss *bss = priv;
4456 struct wpa_driver_nl80211_data *drv = bss->drv;
c5121837
JM
4457 struct nl_msg *msg;
4458
4459 msg = nlmsg_alloc();
4460 if (!msg)
4461 return -ENOMEM;
4462
4463 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
4464 0, NL80211_CMD_SET_STATION, 0);
4465
4466 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX,
a2e40bb6 4467 if_nametoindex(bss->ifname));
c5121837 4468 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
1c766b09 4469 NLA_PUT_U32(msg, NL80211_ATTR_STA_VLAN,
c5121837
JM
4470 if_nametoindex(ifname));
4471
4472 return send_and_recv_msgs(drv, msg, NULL, NULL);
4473 nla_put_failure:
4474 return -ENOBUFS;
4475}
4476
4477
fbbfcbac
FF
4478static int i802_set_wds_sta(void *priv, const u8 *addr, int aid, int val)
4479{
a2e40bb6
FF
4480 struct i802_bss *bss = priv;
4481 struct wpa_driver_nl80211_data *drv = bss->drv;
e748062b 4482 char name[IFNAMSIZ + 1];
fbbfcbac 4483
a2e40bb6 4484 os_snprintf(name, sizeof(name), "%s.sta%d", bss->ifname, aid);
e748062b
JM
4485 wpa_printf(MSG_DEBUG, "nl80211: Set WDS STA addr=" MACSTR
4486 " aid=%d val=%d name=%s", MAC2STR(addr), aid, val, name);
fbbfcbac 4487 if (val) {
a2e40bb6 4488 if (nl80211_create_iface(drv, name, NL80211_IFTYPE_AP_VLAN,
fbbfcbac
FF
4489 NULL, 1) < 0)
4490 return -1;
34f2f814 4491 linux_set_iface_flags(drv->ioctl_sock, name, 1);
fbbfcbac
FF
4492 return i802_set_sta_vlan(priv, addr, name, 0);
4493 } else {
a2e40bb6 4494 i802_set_sta_vlan(priv, addr, bss->ifname, 0);
fbbfcbac
FF
4495 return wpa_driver_nl80211_if_remove(priv, WPA_IF_AP_VLAN,
4496 name);
4497 }
4498}
4499
4500
c5121837
JM
4501static void handle_eapol(int sock, void *eloop_ctx, void *sock_ctx)
4502{
4503 struct wpa_driver_nl80211_data *drv = eloop_ctx;
4504 struct sockaddr_ll lladdr;
4505 unsigned char buf[3000];
4506 int len;
4507 socklen_t fromlen = sizeof(lladdr);
4508
4509 len = recvfrom(sock, buf, sizeof(buf), 0,
4510 (struct sockaddr *)&lladdr, &fromlen);
4511 if (len < 0) {
4512 perror("recv");
4513 return;
4514 }
4515
baac6490
JM
4516 if (have_ifidx(drv, lladdr.sll_ifindex))
4517 drv_event_eapol_rx(drv->ctx, lladdr.sll_addr, buf, len);
c5121837
JM
4518}
4519
4520
c5121837
JM
4521static int i802_get_inact_sec(void *priv, const u8 *addr)
4522{
4523 struct hostap_sta_driver_data data;
4524 int ret;
4525
4526 data.inactive_msec = (unsigned long) -1;
4527 ret = i802_read_sta_data(priv, &data, addr);
4528 if (ret || data.inactive_msec == (unsigned long) -1)
4529 return -1;
4530 return data.inactive_msec / 1000;
4531}
4532
4533
4534static int i802_sta_clear_stats(void *priv, const u8 *addr)
4535{
4536#if 0
4537 /* TODO */
4538#endif
4539 return 0;
4540}
4541
4542
731723a5
JM
4543static int i802_sta_deauth(void *priv, const u8 *own_addr, const u8 *addr,
4544 int reason)
c5121837 4545{
a2e40bb6 4546 struct i802_bss *bss = priv;
c5121837
JM
4547 struct ieee80211_mgmt mgmt;
4548
4549 memset(&mgmt, 0, sizeof(mgmt));
4550 mgmt.frame_control = IEEE80211_FC(WLAN_FC_TYPE_MGMT,
4551 WLAN_FC_STYPE_DEAUTH);
4552 memcpy(mgmt.da, addr, ETH_ALEN);
731723a5
JM
4553 memcpy(mgmt.sa, own_addr, ETH_ALEN);
4554 memcpy(mgmt.bssid, own_addr, ETH_ALEN);
c5121837 4555 mgmt.u.deauth.reason_code = host_to_le16(reason);
a2e40bb6 4556 return wpa_driver_nl80211_send_mlme(bss, (u8 *) &mgmt,
9f324b61
JM
4557 IEEE80211_HDRLEN +
4558 sizeof(mgmt.u.deauth));
c5121837
JM
4559}
4560
4561
731723a5
JM
4562static int i802_sta_disassoc(void *priv, const u8 *own_addr, const u8 *addr,
4563 int reason)
c5121837 4564{
a2e40bb6 4565 struct i802_bss *bss = priv;
c5121837
JM
4566 struct ieee80211_mgmt mgmt;
4567
4568 memset(&mgmt, 0, sizeof(mgmt));
4569 mgmt.frame_control = IEEE80211_FC(WLAN_FC_TYPE_MGMT,
4570 WLAN_FC_STYPE_DISASSOC);
4571 memcpy(mgmt.da, addr, ETH_ALEN);
731723a5
JM
4572 memcpy(mgmt.sa, own_addr, ETH_ALEN);
4573 memcpy(mgmt.bssid, own_addr, ETH_ALEN);
c5121837 4574 mgmt.u.disassoc.reason_code = host_to_le16(reason);
a2e40bb6 4575 return wpa_driver_nl80211_send_mlme(bss, (u8 *) &mgmt,
9f324b61
JM
4576 IEEE80211_HDRLEN +
4577 sizeof(mgmt.u.disassoc));
c5121837
JM
4578}
4579
4580
94627f6c
JM
4581static int i802_check_bridge(struct wpa_driver_nl80211_data *drv,
4582 const char *brname, const char *ifname)
4583{
4584 int ifindex;
4585 char in_br[IFNAMSIZ];
4586
4587 os_strlcpy(drv->brname, brname, IFNAMSIZ);
4588 ifindex = if_nametoindex(brname);
4589 if (ifindex == 0) {
4590 /*
4591 * Bridge was configured, but the bridge device does
4592 * not exist. Try to add it now.
4593 */
4594 if (linux_br_add(drv->ioctl_sock, brname) < 0) {
4595 wpa_printf(MSG_ERROR, "nl80211: Failed to add the "
4596 "bridge interface %s: %s",
4597 brname, strerror(errno));
4598 return -1;
4599 }
4600 drv->added_bridge = 1;
4601 add_ifidx(drv, if_nametoindex(brname));
4602 }
4603
4604 if (linux_br_get(in_br, ifname) == 0) {
4605 if (os_strcmp(in_br, brname) == 0)
4606 return 0; /* already in the bridge */
4607
4608 wpa_printf(MSG_DEBUG, "nl80211: Removing interface %s from "
4609 "bridge %s", ifname, in_br);
4610 if (linux_br_del_if(drv->ioctl_sock, in_br, ifname) < 0) {
4611 wpa_printf(MSG_ERROR, "nl80211: Failed to "
4612 "remove interface %s from bridge "
4613 "%s: %s",
4614 ifname, brname, strerror(errno));
4615 return -1;
4616 }
4617 }
4618
4619 wpa_printf(MSG_DEBUG, "nl80211: Adding interface %s into bridge %s",
4620 ifname, brname);
4621 if (linux_br_add_if(drv->ioctl_sock, brname, ifname) < 0) {
4622 wpa_printf(MSG_ERROR, "nl80211: Failed to add interface %s "
4623 "into bridge %s: %s",
4624 ifname, brname, strerror(errno));
4625 return -1;
4626 }
4627 drv->added_if_into_bridge = 1;
4628
4629 return 0;
4630}
4631
4632
92f475b4
JM
4633static void *i802_init(struct hostapd_data *hapd,
4634 struct wpa_init_params *params)
c5121837
JM
4635{
4636 struct wpa_driver_nl80211_data *drv;
a2e40bb6 4637 struct i802_bss *bss;
c5121837 4638 size_t i;
94627f6c
JM
4639 char brname[IFNAMSIZ];
4640 int ifindex, br_ifindex;
4641 int br_added = 0;
c5121837 4642
a2e40bb6
FF
4643 bss = wpa_driver_nl80211_init(hapd, params->ifname);
4644 if (bss == NULL)
c5121837 4645 return NULL;
c5121837 4646
a2e40bb6 4647 drv = bss->drv;
94627f6c
JM
4648 if (linux_br_get(brname, params->ifname) == 0) {
4649 wpa_printf(MSG_DEBUG, "nl80211: Interface %s is in bridge %s",
4650 params->ifname, brname);
4651 br_ifindex = if_nametoindex(brname);
4652 } else {
4653 brname[0] = '\0';
4654 br_ifindex = 0;
4655 }
4656
c5121837
JM
4657 drv->num_if_indices = sizeof(drv->default_if_indices) / sizeof(int);
4658 drv->if_indices = drv->default_if_indices;
92f475b4 4659 for (i = 0; i < params->num_bridge; i++) {
94627f6c
JM
4660 if (params->bridge[i]) {
4661 ifindex = if_nametoindex(params->bridge[i]);
4662 if (ifindex)
4663 add_ifidx(drv, ifindex);
4664 if (ifindex == br_ifindex)
4665 br_added = 1;
4666 }
c5121837 4667 }
94627f6c
JM
4668 if (!br_added && br_ifindex &&
4669 (params->num_bridge == 0 || !params->bridge[0]))
4670 add_ifidx(drv, br_ifindex);
c5121837 4671
ad1e68e6
JM
4672 /* start listening for EAPOL on the default AP interface */
4673 add_ifidx(drv, drv->ifindex);
4674
a2e40bb6 4675 if (linux_set_iface_flags(drv->ioctl_sock, bss->ifname, 0))
6980c191 4676 goto failed;
ad1e68e6 4677
6980c191 4678 if (params->bssid) {
a2e40bb6 4679 if (linux_set_ifhwaddr(drv->ioctl_sock, bss->ifname,
2ac9688e 4680 params->bssid))
460456f8
JM
4681 goto failed;
4682 }
ad1e68e6 4683
a2e40bb6 4684 if (wpa_driver_nl80211_set_mode(bss, IEEE80211_MODE_AP)) {
ad1e68e6 4685 wpa_printf(MSG_ERROR, "nl80211: Failed to set interface %s "
a2e40bb6 4686 "into AP mode", bss->ifname);
bbaf0837 4687 goto failed;
ad1e68e6
JM
4688 }
4689
94627f6c
JM
4690 if (params->num_bridge && params->bridge[0] &&
4691 i802_check_bridge(drv, params->bridge[0], params->ifname) < 0)
4692 goto failed;
4693
a2e40bb6 4694 if (linux_set_iface_flags(drv->ioctl_sock, bss->ifname, 1))
bbaf0837 4695 goto failed;
ad1e68e6
JM
4696
4697 drv->eapol_sock = socket(PF_PACKET, SOCK_DGRAM, htons(ETH_P_PAE));
4698 if (drv->eapol_sock < 0) {
4699 perror("socket(PF_PACKET, SOCK_DGRAM, ETH_P_PAE)");
bbaf0837 4700 goto failed;
ad1e68e6
JM
4701 }
4702
4703 if (eloop_register_read_sock(drv->eapol_sock, handle_eapol, drv, NULL))
4704 {
4705 printf("Could not register read socket for eapol\n");
c5121837 4706 goto failed;
ad1e68e6
JM
4707 }
4708
a2e40bb6 4709 if (linux_get_ifhwaddr(drv->ioctl_sock, bss->ifname, params->own_addr))
bbaf0837 4710 goto failed;
c5121837 4711
a2e40bb6 4712 return bss;
c5121837
JM
4713
4714failed:
460456f8 4715 nl80211_remove_monitor_interface(drv);
c5121837
JM
4716 if (drv->ioctl_sock >= 0)
4717 close(drv->ioctl_sock);
c5121837
JM
4718
4719 genl_family_put(drv->nl80211);
4720 nl_cache_free(drv->nl_cache);
4721 nl_handle_destroy(drv->nl_handle);
4722 nl_cb_put(drv->nl_cb);
4723
bbaf0837
JM
4724 os_free(drv);
4725 return NULL;
4726}
c5121837 4727
c5121837 4728
bbaf0837
JM
4729static void i802_deinit(void *priv)
4730{
4731 wpa_driver_nl80211_deinit(priv);
c5121837
JM
4732}
4733
4734#endif /* HOSTAPD */
4735
4736
22a7c9d7
JM
4737static enum nl80211_iftype wpa_driver_nl80211_if_type(
4738 enum wpa_driver_if_type type)
4739{
4740 switch (type) {
4741 case WPA_IF_STATION:
4742 return NL80211_IFTYPE_STATION;
4743 case WPA_IF_AP_VLAN:
4744 return NL80211_IFTYPE_AP_VLAN;
4745 case WPA_IF_AP_BSS:
4746 return NL80211_IFTYPE_AP;
4747 }
4748 return -1;
4749}
4750
4751
7ab68865 4752static int wpa_driver_nl80211_if_add(void *priv, enum wpa_driver_if_type type,
8043e725 4753 const char *ifname, const u8 *addr,
a2e40bb6 4754 void *bss_ctx, void **drv_priv)
22a7c9d7 4755{
a2e40bb6
FF
4756 struct i802_bss *bss = priv;
4757 struct wpa_driver_nl80211_data *drv = bss->drv;
22a7c9d7
JM
4758 int ifidx;
4759#ifdef HOSTAPD
a2e40bb6 4760 struct i802_bss *new_bss = NULL;
22a7c9d7
JM
4761
4762 if (type == WPA_IF_AP_BSS) {
a2e40bb6
FF
4763 new_bss = os_zalloc(sizeof(*new_bss));
4764 if (new_bss == NULL)
22a7c9d7
JM
4765 return -1;
4766 }
4767#endif /* HOSTAPD */
4768
4769 ifidx = nl80211_create_iface(drv, ifname,
fbbfcbac
FF
4770 wpa_driver_nl80211_if_type(type), addr,
4771 0);
22a7c9d7
JM
4772 if (ifidx < 0) {
4773#ifdef HOSTAPD
a2e40bb6 4774 os_free(new_bss);
22a7c9d7
JM
4775#endif /* HOSTAPD */
4776 return -1;
4777 }
4778
4779#ifdef HOSTAPD
4780 if (type == WPA_IF_AP_BSS) {
34f2f814
JM
4781 if (linux_set_iface_flags(drv->ioctl_sock, ifname, 1)) {
4782 nl80211_remove_iface(drv, ifidx);
07179987 4783 os_free(new_bss);
22a7c9d7
JM
4784 return -1;
4785 }
a2e40bb6
FF
4786 os_strlcpy(new_bss->ifname, ifname, IFNAMSIZ);
4787 new_bss->ifindex = ifidx;
4788 new_bss->drv = drv;
4789 new_bss->next = drv->first_bss.next;
4790 drv->first_bss.next = new_bss;
4791 if (drv_priv)
4792 *drv_priv = new_bss;
22a7c9d7
JM
4793 }
4794#endif /* HOSTAPD */
4795
4796 return 0;
4797}
4798
4799
4800static int wpa_driver_nl80211_if_remove(void *priv,
4801 enum wpa_driver_if_type type,
4802 const char *ifname)
4803{
a2e40bb6
FF
4804 struct i802_bss *bss = priv;
4805 struct wpa_driver_nl80211_data *drv = bss->drv;
22a7c9d7
JM
4806 int ifindex = if_nametoindex(ifname);
4807
e748062b
JM
4808 wpa_printf(MSG_DEBUG, "nl80211: %s(type=%d ifname=%s) ifindex=%d",
4809 __func__, type, ifname, ifindex);
4810 if (ifindex <= 0)
4811 return -1;
22a7c9d7
JM
4812 nl80211_remove_iface(drv, ifindex);
4813
4814#ifdef HOSTAPD
a2e40bb6
FF
4815 if (type != WPA_IF_AP_BSS)
4816 return 0;
4817
4818 if (bss != &drv->first_bss) {
4819 struct i802_bss *tbss = &drv->first_bss;
4820
4821 while (tbss) {
4822 if (tbss->next != bss)
4823 continue;
4824
4825 tbss->next = bss->next;
4826 os_free(bss);
4827 break;
22a7c9d7
JM
4828 }
4829 }
4830#endif /* HOSTAPD */
4831
4832 return 0;
4833}
4834
4835
55777702
JM
4836static int cookie_handler(struct nl_msg *msg, void *arg)
4837{
4838 struct nlattr *tb[NL80211_ATTR_MAX + 1];
4839 struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
4840 u64 *cookie = arg;
4841 nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
4842 genlmsg_attrlen(gnlh, 0), NULL);
4843 if (tb[NL80211_ATTR_COOKIE])
4844 *cookie = nla_get_u64(tb[NL80211_ATTR_COOKIE]);
4845 return NL_SKIP;
4846}
4847
4848
58f6fbe0
JM
4849static int wpa_driver_nl80211_send_action(void *priv, unsigned int freq,
4850 const u8 *dst, const u8 *src,
4851 const u8 *bssid,
4852 const u8 *data, size_t data_len)
4853{
a2e40bb6
FF
4854 struct i802_bss *bss = priv;
4855 struct wpa_driver_nl80211_data *drv = bss->drv;
58f6fbe0
JM
4856 int ret = -1;
4857 struct nl_msg *msg;
4858 u8 *buf;
4859 struct ieee80211_hdr *hdr;
4860 u64 cookie;
4861
4862 wpa_printf(MSG_DEBUG, "nl80211: Send Action frame (ifindex=%d)",
4863 drv->ifindex);
4864
4865 buf = os_zalloc(24 + data_len);
4866 if (buf == NULL)
4867 return ret;
4868 os_memcpy(buf + 24, data, data_len);
4869 hdr = (struct ieee80211_hdr *) buf;
4870 hdr->frame_control =
4871 IEEE80211_FC(WLAN_FC_TYPE_MGMT, WLAN_FC_STYPE_ACTION);
4872 os_memcpy(hdr->addr1, dst, ETH_ALEN);
4873 os_memcpy(hdr->addr2, src, ETH_ALEN);
4874 os_memcpy(hdr->addr3, bssid, ETH_ALEN);
4875
4876 if (drv->nlmode == NL80211_IFTYPE_AP) {
4877 ret = wpa_driver_nl80211_send_mlme(priv, buf, 24 + data_len);
4878 os_free(buf);
4879 return ret;
4880 }
4881
4882 msg = nlmsg_alloc();
4883 if (!msg)
4884 return -1;
4885
4886 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
4887 NL80211_CMD_ACTION, 0);
4888
4889 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
4890 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
4891 NLA_PUT(msg, NL80211_ATTR_FRAME, 24 + data_len, buf);
4892 os_free(buf);
4893
4894 cookie = 0;
4895 ret = send_and_recv_msgs(drv, msg, cookie_handler, &cookie);
4896 msg = NULL;
4897 if (ret) {
4898 wpa_printf(MSG_DEBUG, "nl80211: Action command failed: ret=%d "
4899 "(%s)", ret, strerror(-ret));
4900 goto nla_put_failure;
4901 }
4902 wpa_printf(MSG_DEBUG, "nl80211: Action TX command accepted; "
4903 "cookie 0x%llx", (long long unsigned int) cookie);
4904 drv->send_action_cookie = cookie;
4905 drv->pending_send_action = 1;
4906 ret = 0;
4907
4908nla_put_failure:
4909 nlmsg_free(msg);
4910 return ret;
4911}
4912
4913
55777702
JM
4914static int wpa_driver_nl80211_remain_on_channel(void *priv, unsigned int freq,
4915 unsigned int duration)
4916{
a2e40bb6
FF
4917 struct i802_bss *bss = priv;
4918 struct wpa_driver_nl80211_data *drv = bss->drv;
55777702
JM
4919 struct nl_msg *msg;
4920 int ret;
4921 u64 cookie;
4922
4923 msg = nlmsg_alloc();
4924 if (!msg)
4925 return -1;
4926
4927 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
4928 NL80211_CMD_REMAIN_ON_CHANNEL, 0);
4929
4930 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
4931 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
4932 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
4933
4934 cookie = 0;
4935 ret = send_and_recv_msgs(drv, msg, cookie_handler, &cookie);
4936 if (ret == 0) {
4937 wpa_printf(MSG_DEBUG, "nl80211: Remain-on-channel cookie "
4938 "0x%llx for freq=%u MHz duration=%u",
4939 (long long unsigned int) cookie, freq, duration);
4940 drv->remain_on_chan_cookie = cookie;
4941 return 0;
4942 }
4943 wpa_printf(MSG_DEBUG, "nl80211: Failed to request remain-on-channel "
4944 "(freq=%d): %d (%s)", freq, ret, strerror(-ret));
4945nla_put_failure:
4946 return -1;
4947}
4948
4949
4950static int wpa_driver_nl80211_cancel_remain_on_channel(void *priv)
4951{
a2e40bb6
FF
4952 struct i802_bss *bss = priv;
4953 struct wpa_driver_nl80211_data *drv = bss->drv;
55777702
JM
4954 struct nl_msg *msg;
4955 int ret;
4956
4957 if (!drv->pending_remain_on_chan) {
4958 wpa_printf(MSG_DEBUG, "nl80211: No pending remain-on-channel "
4959 "to cancel");
4960 return -1;
4961 }
4962
4963 wpa_printf(MSG_DEBUG, "nl80211: Cancel remain-on-channel with cookie "
4964 "0x%llx",
4965 (long long unsigned int) drv->remain_on_chan_cookie);
4966
4967 msg = nlmsg_alloc();
4968 if (!msg)
4969 return -1;
4970
4971 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
4972 NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL, 0);
4973
4974 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
4975 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, drv->remain_on_chan_cookie);
4976
4977 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
4978 if (ret == 0)
4979 return 0;
4980 wpa_printf(MSG_DEBUG, "nl80211: Failed to cancel remain-on-channel: "
4981 "%d (%s)", ret, strerror(-ret));
4982nla_put_failure:
4983 return -1;
4984}
4985
4986
504e905c
JM
4987static void wpa_driver_nl80211_probe_req_report_timeout(void *eloop_ctx,
4988 void *timeout_ctx)
4989{
4990 struct wpa_driver_nl80211_data *drv = eloop_ctx;
4991 if (drv->monitor_ifidx < 0)
4992 return; /* monitor interface already removed */
4993
4994 if (drv->nlmode != NL80211_IFTYPE_STATION)
4995 return; /* not in station mode anymore */
4996
4997 if (drv->probe_req_report)
4998 return; /* reporting enabled */
4999
5000 wpa_printf(MSG_DEBUG, "nl80211: Remove monitor interface due to no "
5001 "Probe Request reporting needed anymore");
5002 nl80211_remove_monitor_interface(drv);
5003}
5004
5005
5006static int wpa_driver_nl80211_probe_req_report(void *priv, int report)
5007{
a2e40bb6
FF
5008 struct i802_bss *bss = priv;
5009 struct wpa_driver_nl80211_data *drv = bss->drv;
504e905c
JM
5010
5011 if (drv->nlmode != NL80211_IFTYPE_STATION) {
5012 wpa_printf(MSG_DEBUG, "nl80211: probe_req_report control only "
5013 "allowed in station mode (iftype=%d)",
5014 drv->nlmode);
5015 return -1;
5016 }
5017 drv->probe_req_report = report;
5018
5019 if (report) {
5020 eloop_cancel_timeout(
5021 wpa_driver_nl80211_probe_req_report_timeout,
5022 drv, NULL);
5023 if (drv->monitor_ifidx < 0 &&
5024 nl80211_create_monitor_interface(drv))
5025 return -1;
5026 } else {
5027 /*
5028 * It takes a while to remove the monitor interface, so try to
5029 * avoid doing this if it is needed again shortly. Instead,
5030 * schedule the interface to be removed later if no need for it
5031 * is seen.
5032 */
5033 wpa_printf(MSG_DEBUG, "nl80211: Scheduling monitor interface "
5034 "to be removed after 10 seconds of no use");
5035 eloop_register_timeout(
5036 10, 0, wpa_driver_nl80211_probe_req_report_timeout,
5037 drv, NULL);
5038 }
5039
5040 return 0;
5041}
5042
5043
b7a2b0b6
JM
5044static int wpa_driver_nl80211_alloc_interface_addr(void *priv, u8 *addr,
5045 char *ifname)
7bfc47c3 5046{
a2e40bb6
FF
5047 struct i802_bss *bss = priv;
5048 struct wpa_driver_nl80211_data *drv = bss->drv;
7bfc47c3 5049
b7a2b0b6
JM
5050 if (ifname)
5051 ifname[0] = '\0';
5052
a2e40bb6 5053 if (linux_get_ifhwaddr(drv->ioctl_sock, bss->ifname, addr) < 0)
7bfc47c3
JM
5054 return -1;
5055
5056 if (addr[0] & 0x02) {
5057 /* TODO: add support for generating multiple addresses */
5058 addr[0] ^= 0x80;
5059 } else
5060 addr[0] = 0x02; /* locally administered */
5061
5062 return 0;
5063}
5064
5065
5066static void wpa_driver_nl80211_release_interface_addr(void *priv,
5067 const u8 *addr)
5068{
5069 /* TODO: keep list of allocated address and release them here */
5070}
5071
5072
4e5cb1a3
JM
5073static int nl80211_disable_11b_rates(struct wpa_driver_nl80211_data *drv,
5074 int ifindex, int disabled)
5075{
5076 struct nl_msg *msg;
5077 struct nlattr *bands, *band;
5078 int ret;
5079
5080 msg = nlmsg_alloc();
5081 if (!msg)
5082 return -1;
5083
5084 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
5085 NL80211_CMD_SET_TX_BITRATE_MASK, 0);
5086 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, ifindex);
5087
5088 bands = nla_nest_start(msg, NL80211_ATTR_TX_RATES);
5089 if (!bands)
5090 goto nla_put_failure;
5091
5092 /*
5093 * Disable 2 GHz rates 1, 2, 5.5, 11 Mbps by masking out everything
5094 * else apart from 6, 9, 12, 18, 24, 36, 48, 54 Mbps from non-MCS
5095 * rates. All 5 GHz rates are left enabled.
5096 */
5097 band = nla_nest_start(msg, NL80211_BAND_2GHZ);
5098 if (!band)
5099 goto nla_put_failure;
5100 NLA_PUT(msg, NL80211_TXRATE_LEGACY, 8,
5101 "\x0c\x12\x18\x24\x30\x48\x60\x6c");
5102 nla_nest_end(msg, band);
5103
5104 nla_nest_end(msg, bands);
5105
5106 ret = send_and_recv_msgs(drv, msg, NULL, NULL);
5107 msg = NULL;
5108 if (ret) {
5109 wpa_printf(MSG_DEBUG, "nl80211: Set TX rates failed: ret=%d "
5110 "(%s)", ret, strerror(-ret));
5111 }
5112
5113 return ret;
5114
5115nla_put_failure:
5116 nlmsg_free(msg);
5117 return -1;
5118}
5119
5120
5121static int wpa_driver_nl80211_disable_11b_rates(void *priv, int disabled)
5122{
a2e40bb6
FF
5123 struct i802_bss *bss = priv;
5124 struct wpa_driver_nl80211_data *drv = bss->drv;
4e5cb1a3
JM
5125 drv->disable_11b_rates = disabled;
5126 return nl80211_disable_11b_rates(drv, drv->ifindex, disabled);
5127}
5128
5129
af473088
JM
5130static int wpa_driver_nl80211_deinit_ap(void *priv)
5131{
a2e40bb6
FF
5132 struct i802_bss *bss = priv;
5133 struct wpa_driver_nl80211_data *drv = bss->drv;
af473088
JM
5134 if (drv->nlmode != NL80211_IFTYPE_AP)
5135 return -1;
5136 wpa_driver_nl80211_del_beacon(drv);
a2e40bb6 5137 return wpa_driver_nl80211_set_mode(priv, IEEE80211_MODE_INFRA);
af473088
JM
5138}
5139
5140
207ef3fb
JM
5141static void wpa_driver_nl80211_resume(void *priv)
5142{
a2e40bb6
FF
5143 struct i802_bss *bss = priv;
5144 struct wpa_driver_nl80211_data *drv = bss->drv;
5145 if (linux_set_iface_flags(drv->ioctl_sock, bss->ifname, 1)) {
207ef3fb
JM
5146 wpa_printf(MSG_DEBUG, "nl80211: Failed to set interface up on "
5147 "resume event");
5148 }
5149}
5150
5151
7b90c16a
JM
5152static int nl80211_send_ft_action(void *priv, u8 action, const u8 *target_ap,
5153 const u8 *ies, size_t ies_len)
5154{
5155 struct i802_bss *bss = priv;
5156 struct wpa_driver_nl80211_data *drv = bss->drv;
5157 int ret;
5158 u8 *data, *pos;
5159 size_t data_len;
5160 u8 own_addr[ETH_ALEN];
5161
5162 if (linux_get_ifhwaddr(drv->ioctl_sock, bss->ifname, own_addr) < 0)
5163 return -1;
5164
5165 if (action != 1) {
5166 wpa_printf(MSG_ERROR, "nl80211: Unsupported send_ft_action "
5167 "action %d", action);
5168 return -1;
5169 }
5170
5171 /*
5172 * Action frame payload:
5173 * Category[1] = 6 (Fast BSS Transition)
5174 * Action[1] = 1 (Fast BSS Transition Request)
5175 * STA Address
5176 * Target AP Address
5177 * FT IEs
5178 */
5179
73fc617d
JM
5180 data_len = 2 + 2 * ETH_ALEN + ies_len;
5181 data = os_malloc(data_len);
7b90c16a
JM
5182 if (data == NULL)
5183 return -1;
5184 pos = data;
5185 *pos++ = 0x06; /* FT Action category */
5186 *pos++ = action;
5187 os_memcpy(pos, own_addr, ETH_ALEN);
5188 pos += ETH_ALEN;
5189 os_memcpy(pos, target_ap, ETH_ALEN);
5190 pos += ETH_ALEN;
5191 os_memcpy(pos, ies, ies_len);
5192
5193 ret = wpa_driver_nl80211_send_action(bss, drv->assoc_freq, drv->bssid,
5194 own_addr, drv->bssid,
5195 data, data_len);
5196 os_free(data);
5197
5198 return ret;
5199}
5200
5201
b625473c
JM
5202static int nl80211_signal_monitor(void *priv, int threshold, int hysteresis)
5203{
5204 struct i802_bss *bss = priv;
5205 struct wpa_driver_nl80211_data *drv = bss->drv;
5206 struct nl_msg *msg, *cqm = NULL;
5207
5208 wpa_printf(MSG_DEBUG, "nl80211: Signal monitor threshold=%d "
5209 "hysteresis=%d", threshold, hysteresis);
5210
5211 msg = nlmsg_alloc();
5212 if (!msg)
5213 return -1;
5214
5215 genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
5216 0, NL80211_CMD_SET_CQM, 0);
5217
5218 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, bss->ifindex);
5219
5220 cqm = nlmsg_alloc();
5221 if (cqm == NULL)
5222 return -1;
5223
5224 NLA_PUT_U32(cqm, NL80211_ATTR_CQM_RSSI_THOLD, threshold);
5225 NLA_PUT_U32(cqm, NL80211_ATTR_CQM_RSSI_HYST, hysteresis);
5226 nla_put_nested(msg, NL80211_ATTR_CQM, cqm);
5227
5228 if (send_and_recv_msgs(drv, msg, NULL, NULL) == 0)
5229 return 0;
5230 msg = NULL;
5231
5232nla_put_failure:
5233 if (cqm)
5234 nlmsg_free(cqm);
5235 nlmsg_free(msg);
5236 return -1;
5237}
5238
5239
b91ab76e
JM
5240static int nl80211_send_frame(void *priv, const u8 *data, size_t data_len,
5241 int encrypt)
5242{
5243 struct i802_bss *bss = priv;
5244 struct wpa_driver_nl80211_data *drv = bss->drv;
5245 return wpa_driver_nl80211_send_frame(drv, data, data_len, encrypt);
5246}
5247
5248
3f5285e8
JM
5249const struct wpa_driver_ops wpa_driver_nl80211_ops = {
5250 .name = "nl80211",
5251 .desc = "Linux nl80211/cfg80211",
5252 .get_bssid = wpa_driver_nl80211_get_bssid,
5253 .get_ssid = wpa_driver_nl80211_get_ssid,
3f5285e8 5254 .set_key = wpa_driver_nl80211_set_key,
6a1063e0 5255 .scan2 = wpa_driver_nl80211_scan,
3f5285e8
JM
5256 .get_scan_results2 = wpa_driver_nl80211_get_scan_results,
5257 .deauthenticate = wpa_driver_nl80211_deauthenticate,
5258 .disassociate = wpa_driver_nl80211_disassociate,
c2a04078 5259 .authenticate = wpa_driver_nl80211_authenticate,
3f5285e8 5260 .associate = wpa_driver_nl80211_associate,
3f5285e8
JM
5261 .init = wpa_driver_nl80211_init,
5262 .deinit = wpa_driver_nl80211_deinit,
3f5285e8
JM
5263 .get_capa = wpa_driver_nl80211_get_capa,
5264 .set_operstate = wpa_driver_nl80211_set_operstate,
01652550 5265 .set_supp_port = wpa_driver_nl80211_set_supp_port,
6d158490 5266 .set_country = wpa_driver_nl80211_set_country,
d2440ba0 5267 .set_beacon = wpa_driver_nl80211_set_beacon,
22a7c9d7
JM
5268 .if_add = wpa_driver_nl80211_if_add,
5269 .if_remove = wpa_driver_nl80211_if_remove,
071f8ac4 5270 .send_mlme = wpa_driver_nl80211_send_mlme,
c3965310 5271 .get_hw_feature_data = wpa_driver_nl80211_get_hw_feature_data,
0f4e8b4f
JM
5272 .sta_add = wpa_driver_nl80211_sta_add,
5273 .sta_remove = wpa_driver_nl80211_sta_remove,
db149ac9 5274 .hapd_send_eapol = wpa_driver_nl80211_hapd_send_eapol,
a8d6ffa4 5275 .sta_set_flags = wpa_driver_nl80211_sta_set_flags,
c5121837
JM
5276#ifdef HOSTAPD
5277 .hapd_init = i802_init,
c5121837 5278 .hapd_deinit = i802_deinit,
c5121837
JM
5279 .get_seqnum = i802_get_seqnum,
5280 .flush = i802_flush,
5281 .read_sta_data = i802_read_sta_data,
c5121837
JM
5282 .sta_deauth = i802_sta_deauth,
5283 .sta_disassoc = i802_sta_disassoc,
c5121837
JM
5284 .get_inact_sec = i802_get_inact_sec,
5285 .sta_clear_stats = i802_sta_clear_stats,
5286 .set_freq = i802_set_freq,
5287 .set_rts = i802_set_rts,
5288 .set_frag = i802_set_frag,
c5121837 5289 .set_rate_sets = i802_set_rate_sets,
c5121837
JM
5290 .set_cts_protect = i802_set_cts_protect,
5291 .set_preamble = i802_set_preamble,
5292 .set_short_slot_time = i802_set_short_slot_time,
5293 .set_tx_queue_params = i802_set_tx_queue_params,
c5121837 5294 .set_sta_vlan = i802_set_sta_vlan,
fbbfcbac 5295 .set_wds_sta = i802_set_wds_sta,
c5121837 5296#endif /* HOSTAPD */
58f6fbe0 5297 .send_action = wpa_driver_nl80211_send_action,
55777702
JM
5298 .remain_on_channel = wpa_driver_nl80211_remain_on_channel,
5299 .cancel_remain_on_channel =
5300 wpa_driver_nl80211_cancel_remain_on_channel,
504e905c 5301 .probe_req_report = wpa_driver_nl80211_probe_req_report,
7bfc47c3
JM
5302 .alloc_interface_addr = wpa_driver_nl80211_alloc_interface_addr,
5303 .release_interface_addr = wpa_driver_nl80211_release_interface_addr,
4e5cb1a3 5304 .disable_11b_rates = wpa_driver_nl80211_disable_11b_rates,
af473088 5305 .deinit_ap = wpa_driver_nl80211_deinit_ap,
207ef3fb 5306 .resume = wpa_driver_nl80211_resume,
7b90c16a 5307 .send_ft_action = nl80211_send_ft_action,
b625473c 5308 .signal_monitor = nl80211_signal_monitor,
b91ab76e 5309 .send_frame = nl80211_send_frame,
3f5285e8 5310};