2 * hostapd / Initialization and configuration
3 * Copyright (c) 2002-2012, Jouni Malinen <j@w1.fi>
5 * This software may be distributed under the terms of the BSD license.
6 * See README for more details.
9 #include "utils/includes.h"
11 #include "utils/common.h"
12 #include "utils/eloop.h"
13 #include "common/ieee802_11_defs.h"
14 #include "radius/radius_client.h"
15 #include "radius/radius_das.h"
16 #include "drivers/driver.h"
20 #include "accounting.h"
24 #include "ieee802_1x.h"
25 #include "ieee802_11_auth.h"
26 #include "vlan_init.h"
28 #include "wps_hostapd.h"
29 #include "hw_features.h"
30 #include "wpa_auth_glue.h"
31 #include "ap_drv_ops.h"
32 #include "ap_config.h"
33 #include "p2p_hostapd.h"
38 static int hostapd_flush_old_stations(struct hostapd_data
*hapd
, u16 reason
);
39 static int hostapd_setup_encryption(char *iface
, struct hostapd_data
*hapd
);
40 static int hostapd_broadcast_wep_clear(struct hostapd_data
*hapd
);
42 extern int wpa_debug_level
;
43 extern struct wpa_driver_ops
*wpa_drivers
[];
46 int hostapd_for_each_interface(struct hapd_interfaces
*interfaces
,
47 int (*cb
)(struct hostapd_iface
*iface
,
48 void *ctx
), void *ctx
)
53 for (i
= 0; i
< interfaces
->count
; i
++) {
54 ret
= cb(interfaces
->iface
[i
], ctx
);
63 static void hostapd_reload_bss(struct hostapd_data
*hapd
)
65 struct hostapd_ssid
*ssid
;
67 #ifndef CONFIG_NO_RADIUS
68 radius_client_reconfig(hapd
->radius
, hapd
->conf
->radius
);
69 #endif /* CONFIG_NO_RADIUS */
71 ssid
= &hapd
->conf
->ssid
;
72 if (!ssid
->wpa_psk_set
&& ssid
->wpa_psk
&& !ssid
->wpa_psk
->next
&&
73 ssid
->wpa_passphrase_set
&& ssid
->wpa_passphrase
) {
75 * Force PSK to be derived again since SSID or passphrase may
78 os_free(ssid
->wpa_psk
);
81 if (hostapd_setup_wpa_psk(hapd
->conf
)) {
82 wpa_printf(MSG_ERROR
, "Failed to re-configure WPA PSK "
83 "after reloading configuration");
86 if (hapd
->conf
->ieee802_1x
|| hapd
->conf
->wpa
)
87 hostapd_set_drv_ieee8021x(hapd
, hapd
->conf
->iface
, 1);
89 hostapd_set_drv_ieee8021x(hapd
, hapd
->conf
->iface
, 0);
91 if (hapd
->conf
->wpa
&& hapd
->wpa_auth
== NULL
) {
92 hostapd_setup_wpa(hapd
);
94 wpa_init_keys(hapd
->wpa_auth
);
95 } else if (hapd
->conf
->wpa
) {
98 hostapd_reconfig_wpa(hapd
);
99 wpa_ie
= wpa_auth_get_wpa_ie(hapd
->wpa_auth
, &wpa_ie_len
);
100 if (hostapd_set_generic_elem(hapd
, wpa_ie
, wpa_ie_len
))
101 wpa_printf(MSG_ERROR
, "Failed to configure WPA IE for "
102 "the kernel driver.");
103 } else if (hapd
->wpa_auth
) {
104 wpa_deinit(hapd
->wpa_auth
);
105 hapd
->wpa_auth
= NULL
;
106 hostapd_set_privacy(hapd
, 0);
107 hostapd_setup_encryption(hapd
->conf
->iface
, hapd
);
108 hostapd_set_generic_elem(hapd
, (u8
*) "", 0);
111 ieee802_11_set_beacon(hapd
);
112 hostapd_update_wps(hapd
);
114 if (hapd
->conf
->ssid
.ssid_set
&&
115 hostapd_set_ssid(hapd
, hapd
->conf
->ssid
.ssid
,
116 hapd
->conf
->ssid
.ssid_len
)) {
117 wpa_printf(MSG_ERROR
, "Could not set SSID for kernel driver");
118 /* try to continue */
120 wpa_printf(MSG_DEBUG
, "Reconfigured interface %s", hapd
->conf
->iface
);
124 static void hostapd_clear_old(struct hostapd_iface
*iface
)
129 * Deauthenticate all stations since the new configuration may not
130 * allow them to use the BSS anymore.
132 for (j
= 0; j
< iface
->num_bss
; j
++) {
133 hostapd_flush_old_stations(iface
->bss
[j
],
134 WLAN_REASON_PREV_AUTH_NOT_VALID
);
135 hostapd_broadcast_wep_clear(iface
->bss
[j
]);
137 #ifndef CONFIG_NO_RADIUS
138 /* TODO: update dynamic data based on changed configuration
139 * items (e.g., open/close sockets, etc.) */
140 radius_client_flush(iface
->bss
[j
]->radius
, 0);
141 #endif /* CONFIG_NO_RADIUS */
146 int hostapd_reload_config(struct hostapd_iface
*iface
)
148 struct hostapd_data
*hapd
= iface
->bss
[0];
149 struct hostapd_config
*newconf
, *oldconf
;
152 if (iface
->config_fname
== NULL
) {
153 /* Only in-memory config in use - assume it has been updated */
154 hostapd_clear_old(iface
);
155 for (j
= 0; j
< iface
->num_bss
; j
++)
156 hostapd_reload_bss(iface
->bss
[j
]);
160 if (iface
->interfaces
== NULL
||
161 iface
->interfaces
->config_read_cb
== NULL
)
163 newconf
= iface
->interfaces
->config_read_cb(iface
->config_fname
);
167 hostapd_clear_old(iface
);
169 oldconf
= hapd
->iconf
;
170 iface
->conf
= newconf
;
172 for (j
= 0; j
< iface
->num_bss
; j
++) {
173 hapd
= iface
->bss
[j
];
174 hapd
->iconf
= newconf
;
175 hapd
->conf
= newconf
->bss
[j
];
176 hostapd_reload_bss(hapd
);
179 hostapd_config_free(oldconf
);
186 static void hostapd_broadcast_key_clear_iface(struct hostapd_data
*hapd
,
191 for (i
= 0; i
< NUM_WEP_KEYS
; i
++) {
192 if (hostapd_drv_set_key(ifname
, hapd
, WPA_ALG_NONE
, NULL
, i
,
193 0, NULL
, 0, NULL
, 0)) {
194 wpa_printf(MSG_DEBUG
, "Failed to clear default "
195 "encryption keys (ifname=%s keyidx=%d)",
199 #ifdef CONFIG_IEEE80211W
200 if (hapd
->conf
->ieee80211w
) {
201 for (i
= NUM_WEP_KEYS
; i
< NUM_WEP_KEYS
+ 2; i
++) {
202 if (hostapd_drv_set_key(ifname
, hapd
, WPA_ALG_NONE
,
205 wpa_printf(MSG_DEBUG
, "Failed to clear "
206 "default mgmt encryption keys "
207 "(ifname=%s keyidx=%d)", ifname
, i
);
211 #endif /* CONFIG_IEEE80211W */
215 static int hostapd_broadcast_wep_clear(struct hostapd_data
*hapd
)
217 hostapd_broadcast_key_clear_iface(hapd
, hapd
->conf
->iface
);
222 static int hostapd_broadcast_wep_set(struct hostapd_data
*hapd
)
225 struct hostapd_ssid
*ssid
= &hapd
->conf
->ssid
;
228 if (ssid
->wep
.default_len
&&
229 hostapd_drv_set_key(hapd
->conf
->iface
,
230 hapd
, WPA_ALG_WEP
, broadcast_ether_addr
, idx
,
231 1, NULL
, 0, ssid
->wep
.key
[idx
],
232 ssid
->wep
.len
[idx
])) {
233 wpa_printf(MSG_WARNING
, "Could not set WEP encryption.");
241 static void hostapd_free_hapd_data(struct hostapd_data
*hapd
)
243 iapp_deinit(hapd
->iapp
);
245 accounting_deinit(hapd
);
246 hostapd_deinit_wpa(hapd
);
248 hostapd_acl_deinit(hapd
);
249 #ifndef CONFIG_NO_RADIUS
250 radius_client_deinit(hapd
->radius
);
252 radius_das_deinit(hapd
->radius_das
);
253 hapd
->radius_das
= NULL
;
254 #endif /* CONFIG_NO_RADIUS */
256 hostapd_deinit_wps(hapd
);
258 authsrv_deinit(hapd
);
260 if (hapd
->interface_added
&&
261 hostapd_if_remove(hapd
, WPA_IF_AP_BSS
, hapd
->conf
->iface
)) {
262 wpa_printf(MSG_WARNING
, "Failed to remove BSS interface %s",
266 os_free(hapd
->probereq_cb
);
267 hapd
->probereq_cb
= NULL
;
270 wpabuf_free(hapd
->p2p_beacon_ie
);
271 hapd
->p2p_beacon_ie
= NULL
;
272 wpabuf_free(hapd
->p2p_probe_resp_ie
);
273 hapd
->p2p_probe_resp_ie
= NULL
;
274 #endif /* CONFIG_P2P */
276 wpabuf_free(hapd
->time_adv
);
278 #ifdef CONFIG_INTERWORKING
279 gas_serv_deinit(hapd
);
280 #endif /* CONFIG_INTERWORKING */
283 os_free(hapd
->tmp_eap_user
.identity
);
284 os_free(hapd
->tmp_eap_user
.password
);
285 #endif /* CONFIG_SQLITE */
290 * hostapd_cleanup - Per-BSS cleanup (deinitialization)
291 * @hapd: Pointer to BSS data
293 * This function is used to free all per-BSS data structures and resources.
294 * This gets called in a loop for each BSS between calls to
295 * hostapd_cleanup_iface_pre() and hostapd_cleanup_iface() when an interface
296 * is deinitialized. Most of the modules that are initialized in
297 * hostapd_setup_bss() are deinitialized here.
299 static void hostapd_cleanup(struct hostapd_data
*hapd
)
301 if (hapd
->iface
->interfaces
&&
302 hapd
->iface
->interfaces
->ctrl_iface_deinit
)
303 hapd
->iface
->interfaces
->ctrl_iface_deinit(hapd
);
304 hostapd_free_hapd_data(hapd
);
309 * hostapd_cleanup_iface_pre - Preliminary per-interface cleanup
310 * @iface: Pointer to interface data
312 * This function is called before per-BSS data structures are deinitialized
313 * with hostapd_cleanup().
315 static void hostapd_cleanup_iface_pre(struct hostapd_iface
*iface
)
320 static void hostapd_cleanup_iface_partial(struct hostapd_iface
*iface
)
322 hostapd_free_hw_features(iface
->hw_features
, iface
->num_hw_features
);
323 iface
->hw_features
= NULL
;
324 os_free(iface
->current_rates
);
325 iface
->current_rates
= NULL
;
326 os_free(iface
->basic_rates
);
327 iface
->basic_rates
= NULL
;
328 ap_list_deinit(iface
);
333 * hostapd_cleanup_iface - Complete per-interface cleanup
334 * @iface: Pointer to interface data
336 * This function is called after per-BSS data structures are deinitialized
337 * with hostapd_cleanup().
339 static void hostapd_cleanup_iface(struct hostapd_iface
*iface
)
341 hostapd_cleanup_iface_partial(iface
);
342 hostapd_config_free(iface
->conf
);
345 os_free(iface
->config_fname
);
351 static void hostapd_clear_wep(struct hostapd_data
*hapd
)
353 if (hapd
->drv_priv
) {
354 hostapd_set_privacy(hapd
, 0);
355 hostapd_broadcast_wep_clear(hapd
);
360 static int hostapd_setup_encryption(char *iface
, struct hostapd_data
*hapd
)
364 hostapd_broadcast_wep_set(hapd
);
366 if (hapd
->conf
->ssid
.wep
.default_len
) {
367 hostapd_set_privacy(hapd
, 1);
372 * When IEEE 802.1X is not enabled, the driver may need to know how to
373 * set authentication algorithms for static WEP.
375 hostapd_drv_set_authmode(hapd
, hapd
->conf
->auth_algs
);
377 for (i
= 0; i
< 4; i
++) {
378 if (hapd
->conf
->ssid
.wep
.key
[i
] &&
379 hostapd_drv_set_key(iface
, hapd
, WPA_ALG_WEP
, NULL
, i
,
380 i
== hapd
->conf
->ssid
.wep
.idx
, NULL
, 0,
381 hapd
->conf
->ssid
.wep
.key
[i
],
382 hapd
->conf
->ssid
.wep
.len
[i
])) {
383 wpa_printf(MSG_WARNING
, "Could not set WEP "
387 if (hapd
->conf
->ssid
.wep
.key
[i
] &&
388 i
== hapd
->conf
->ssid
.wep
.idx
)
389 hostapd_set_privacy(hapd
, 1);
396 static int hostapd_flush_old_stations(struct hostapd_data
*hapd
, u16 reason
)
401 if (hostapd_drv_none(hapd
) || hapd
->drv_priv
== NULL
)
404 wpa_dbg(hapd
->msg_ctx
, MSG_DEBUG
, "Flushing old station entries");
405 if (hostapd_flush(hapd
)) {
406 wpa_msg(hapd
->msg_ctx
, MSG_WARNING
, "Could not connect to "
410 wpa_dbg(hapd
->msg_ctx
, MSG_DEBUG
, "Deauthenticate all stations");
411 os_memset(addr
, 0xff, ETH_ALEN
);
412 hostapd_drv_sta_deauth(hapd
, addr
, reason
);
413 hostapd_free_stas(hapd
);
420 * hostapd_validate_bssid_configuration - Validate BSSID configuration
421 * @iface: Pointer to interface data
422 * Returns: 0 on success, -1 on failure
424 * This function is used to validate that the configured BSSIDs are valid.
426 static int hostapd_validate_bssid_configuration(struct hostapd_iface
*iface
)
428 u8 mask
[ETH_ALEN
] = { 0 };
429 struct hostapd_data
*hapd
= iface
->bss
[0];
430 unsigned int i
= iface
->conf
->num_bss
, bits
= 0, j
;
433 if (hostapd_drv_none(hapd
))
436 /* Generate BSSID mask that is large enough to cover the BSSIDs. */
438 /* Determine the bits necessary to cover the number of BSSIDs. */
439 for (i
--; i
; i
>>= 1)
442 /* Determine the bits necessary to any configured BSSIDs,
443 if they are higher than the number of BSSIDs. */
444 for (j
= 0; j
< iface
->conf
->num_bss
; j
++) {
445 if (hostapd_mac_comp_empty(iface
->conf
->bss
[j
]->bssid
) == 0) {
451 for (i
= 0; i
< ETH_ALEN
; i
++) {
453 iface
->conf
->bss
[j
]->bssid
[i
] ^
461 for (i
= 0; i
< ETH_ALEN
&& mask
[i
] == 0; i
++)
467 while (mask
[i
] != 0) {
477 wpa_printf(MSG_ERROR
, "Too many bits in the BSSID mask (%u)",
482 os_memset(mask
, 0xff, ETH_ALEN
);
484 for (i
= 5; i
> 5 - j
; i
--)
491 wpa_printf(MSG_DEBUG
, "BSS count %lu, BSSID mask " MACSTR
" (%d bits)",
492 (unsigned long) iface
->conf
->num_bss
, MAC2STR(mask
), bits
);
497 for (i
= 0; i
< ETH_ALEN
; i
++) {
498 if ((hapd
->own_addr
[i
] & mask
[i
]) != hapd
->own_addr
[i
]) {
499 wpa_printf(MSG_ERROR
, "Invalid BSSID mask " MACSTR
500 " for start address " MACSTR
".",
501 MAC2STR(mask
), MAC2STR(hapd
->own_addr
));
502 wpa_printf(MSG_ERROR
, "Start address must be the "
503 "first address in the block (i.e., addr "
504 "AND mask == addr).");
513 static int mac_in_conf(struct hostapd_config
*conf
, const void *a
)
517 for (i
= 0; i
< conf
->num_bss
; i
++) {
518 if (hostapd_mac_comp(conf
->bss
[i
]->bssid
, a
) == 0) {
527 #ifndef CONFIG_NO_RADIUS
529 static int hostapd_das_nas_mismatch(struct hostapd_data
*hapd
,
530 struct radius_das_attrs
*attr
)
537 static struct sta_info
* hostapd_das_find_sta(struct hostapd_data
*hapd
,
538 struct radius_das_attrs
*attr
)
540 struct sta_info
*sta
= NULL
;
544 sta
= ap_get_sta(hapd
, attr
->sta_addr
);
546 if (sta
== NULL
&& attr
->acct_session_id
&&
547 attr
->acct_session_id_len
== 17) {
548 for (sta
= hapd
->sta_list
; sta
; sta
= sta
->next
) {
549 os_snprintf(buf
, sizeof(buf
), "%08X-%08X",
550 sta
->acct_session_id_hi
,
551 sta
->acct_session_id_lo
);
552 if (os_memcmp(attr
->acct_session_id
, buf
, 17) == 0)
557 if (sta
== NULL
&& attr
->cui
) {
558 for (sta
= hapd
->sta_list
; sta
; sta
= sta
->next
) {
560 cui
= ieee802_1x_get_radius_cui(sta
->eapol_sm
);
561 if (cui
&& wpabuf_len(cui
) == attr
->cui_len
&&
562 os_memcmp(wpabuf_head(cui
), attr
->cui
,
568 if (sta
== NULL
&& attr
->user_name
) {
569 for (sta
= hapd
->sta_list
; sta
; sta
= sta
->next
) {
572 identity
= ieee802_1x_get_identity(sta
->eapol_sm
,
575 identity_len
== attr
->user_name_len
&&
576 os_memcmp(identity
, attr
->user_name
, identity_len
)
586 static enum radius_das_res
587 hostapd_das_disconnect(void *ctx
, struct radius_das_attrs
*attr
)
589 struct hostapd_data
*hapd
= ctx
;
590 struct sta_info
*sta
;
592 if (hostapd_das_nas_mismatch(hapd
, attr
))
593 return RADIUS_DAS_NAS_MISMATCH
;
595 sta
= hostapd_das_find_sta(hapd
, attr
);
597 return RADIUS_DAS_SESSION_NOT_FOUND
;
599 hostapd_drv_sta_deauth(hapd
, sta
->addr
,
600 WLAN_REASON_PREV_AUTH_NOT_VALID
);
601 ap_sta_deauthenticate(hapd
, sta
, WLAN_REASON_PREV_AUTH_NOT_VALID
);
603 return RADIUS_DAS_SUCCESS
;
606 #endif /* CONFIG_NO_RADIUS */
610 * hostapd_setup_bss - Per-BSS setup (initialization)
611 * @hapd: Pointer to BSS data
612 * @first: Whether this BSS is the first BSS of an interface
614 * This function is used to initialize all per-BSS data structures and
615 * resources. This gets called in a loop for each BSS when an interface is
616 * initialized. Most of the modules that are initialized here will be
617 * deinitialized in hostapd_cleanup().
619 static int hostapd_setup_bss(struct hostapd_data
*hapd
, int first
)
621 struct hostapd_bss_config
*conf
= hapd
->conf
;
622 u8 ssid
[HOSTAPD_MAX_SSID_LEN
+ 1];
623 int ssid_len
, set_ssid
;
624 char force_ifname
[IFNAMSIZ
];
625 u8 if_addr
[ETH_ALEN
];
628 if (hostapd_mac_comp_empty(hapd
->conf
->bssid
) == 0) {
629 /* Allocate the next available BSSID. */
631 inc_byte_array(hapd
->own_addr
, ETH_ALEN
);
632 } while (mac_in_conf(hapd
->iconf
, hapd
->own_addr
));
634 /* Allocate the configured BSSID. */
635 os_memcpy(hapd
->own_addr
, hapd
->conf
->bssid
, ETH_ALEN
);
637 if (hostapd_mac_comp(hapd
->own_addr
,
638 hapd
->iface
->bss
[0]->own_addr
) ==
640 wpa_printf(MSG_ERROR
, "BSS '%s' may not have "
641 "BSSID set to the MAC address of "
642 "the radio", hapd
->conf
->iface
);
647 hapd
->interface_added
= 1;
648 if (hostapd_if_add(hapd
->iface
->bss
[0], WPA_IF_AP_BSS
,
649 hapd
->conf
->iface
, hapd
->own_addr
, hapd
,
650 &hapd
->drv_priv
, force_ifname
, if_addr
,
651 hapd
->conf
->bridge
[0] ? hapd
->conf
->bridge
:
653 wpa_printf(MSG_ERROR
, "Failed to add BSS (BSSID="
654 MACSTR
")", MAC2STR(hapd
->own_addr
));
659 if (conf
->wmm_enabled
< 0)
660 conf
->wmm_enabled
= hapd
->iconf
->ieee80211n
;
662 hostapd_flush_old_stations(hapd
, WLAN_REASON_PREV_AUTH_NOT_VALID
);
663 hostapd_set_privacy(hapd
, 0);
665 hostapd_broadcast_wep_clear(hapd
);
666 if (hostapd_setup_encryption(hapd
->conf
->iface
, hapd
))
670 * Fetch the SSID from the system and use it or,
671 * if one was specified in the config file, verify they
674 ssid_len
= hostapd_get_ssid(hapd
, ssid
, sizeof(ssid
));
676 wpa_printf(MSG_ERROR
, "Could not read SSID from system");
679 if (conf
->ssid
.ssid_set
) {
681 * If SSID is specified in the config file and it differs
682 * from what is being used then force installation of the
685 set_ssid
= (conf
->ssid
.ssid_len
!= (size_t) ssid_len
||
686 os_memcmp(conf
->ssid
.ssid
, ssid
, ssid_len
) != 0);
689 * No SSID in the config file; just use the one we got
693 conf
->ssid
.ssid_len
= ssid_len
;
694 os_memcpy(conf
->ssid
.ssid
, ssid
, conf
->ssid
.ssid_len
);
697 if (!hostapd_drv_none(hapd
)) {
698 wpa_printf(MSG_ERROR
, "Using interface %s with hwaddr " MACSTR
700 hapd
->conf
->iface
, MAC2STR(hapd
->own_addr
),
701 wpa_ssid_txt(hapd
->conf
->ssid
.ssid
,
702 hapd
->conf
->ssid
.ssid_len
));
705 if (hostapd_setup_wpa_psk(conf
)) {
706 wpa_printf(MSG_ERROR
, "WPA-PSK setup failed.");
710 /* Set SSID for the kernel driver (to be used in beacon and probe
711 * response frames) */
712 if (set_ssid
&& hostapd_set_ssid(hapd
, conf
->ssid
.ssid
,
713 conf
->ssid
.ssid_len
)) {
714 wpa_printf(MSG_ERROR
, "Could not set SSID for kernel driver");
718 if (wpa_debug_level
== MSG_MSGDUMP
)
719 conf
->radius
->msg_dumps
= 1;
720 #ifndef CONFIG_NO_RADIUS
721 hapd
->radius
= radius_client_init(hapd
, conf
->radius
);
722 if (hapd
->radius
== NULL
) {
723 wpa_printf(MSG_ERROR
, "RADIUS client initialization failed.");
727 if (hapd
->conf
->radius_das_port
) {
728 struct radius_das_conf das_conf
;
729 os_memset(&das_conf
, 0, sizeof(das_conf
));
730 das_conf
.port
= hapd
->conf
->radius_das_port
;
731 das_conf
.shared_secret
= hapd
->conf
->radius_das_shared_secret
;
732 das_conf
.shared_secret_len
=
733 hapd
->conf
->radius_das_shared_secret_len
;
734 das_conf
.client_addr
= &hapd
->conf
->radius_das_client_addr
;
735 das_conf
.time_window
= hapd
->conf
->radius_das_time_window
;
736 das_conf
.require_event_timestamp
=
737 hapd
->conf
->radius_das_require_event_timestamp
;
739 das_conf
.disconnect
= hostapd_das_disconnect
;
740 hapd
->radius_das
= radius_das_init(&das_conf
);
741 if (hapd
->radius_das
== NULL
) {
742 wpa_printf(MSG_ERROR
, "RADIUS DAS initialization "
747 #endif /* CONFIG_NO_RADIUS */
749 if (hostapd_acl_init(hapd
)) {
750 wpa_printf(MSG_ERROR
, "ACL initialization failed.");
753 if (hostapd_init_wps(hapd
, conf
))
756 if (authsrv_init(hapd
) < 0)
759 if (ieee802_1x_init(hapd
)) {
760 wpa_printf(MSG_ERROR
, "IEEE 802.1X initialization failed.");
764 if (hapd
->conf
->wpa
&& hostapd_setup_wpa(hapd
))
767 if (accounting_init(hapd
)) {
768 wpa_printf(MSG_ERROR
, "Accounting initialization failed.");
772 if (hapd
->conf
->ieee802_11f
&&
773 (hapd
->iapp
= iapp_init(hapd
, hapd
->conf
->iapp_iface
)) == NULL
) {
774 wpa_printf(MSG_ERROR
, "IEEE 802.11F (IAPP) initialization "
779 #ifdef CONFIG_INTERWORKING
780 if (gas_serv_init(hapd
)) {
781 wpa_printf(MSG_ERROR
, "GAS server initialization failed");
784 #endif /* CONFIG_INTERWORKING */
786 if (hapd
->iface
->interfaces
&&
787 hapd
->iface
->interfaces
->ctrl_iface_init
&&
788 hapd
->iface
->interfaces
->ctrl_iface_init(hapd
)) {
789 wpa_printf(MSG_ERROR
, "Failed to setup control interface");
793 if (!hostapd_drv_none(hapd
) && vlan_init(hapd
)) {
794 wpa_printf(MSG_ERROR
, "VLAN initialization failed.");
798 if (!hapd
->conf
->start_disabled
)
799 ieee802_11_set_beacon(hapd
);
801 if (hapd
->wpa_auth
&& wpa_init_keys(hapd
->wpa_auth
) < 0)
804 if (hapd
->driver
&& hapd
->driver
->set_operstate
)
805 hapd
->driver
->set_operstate(hapd
->drv_priv
, 1);
811 static void hostapd_tx_queue_params(struct hostapd_iface
*iface
)
813 struct hostapd_data
*hapd
= iface
->bss
[0];
815 struct hostapd_tx_queue_params
*p
;
817 for (i
= 0; i
< NUM_TX_QUEUES
; i
++) {
818 p
= &iface
->conf
->tx_queue
[i
];
820 if (hostapd_set_tx_queue_params(hapd
, i
, p
->aifs
, p
->cwmin
,
821 p
->cwmax
, p
->burst
)) {
822 wpa_printf(MSG_DEBUG
, "Failed to set TX queue "
823 "parameters for queue %d.", i
);
824 /* Continue anyway */
830 static int hostapd_set_acl_list(struct hostapd_data
*hapd
,
831 struct mac_acl_entry
*mac_acl
,
832 int n_entries
, u8 accept_acl
)
834 struct hostapd_acl_params
*acl_params
;
837 acl_params
= os_zalloc(sizeof(*acl_params
) +
838 (n_entries
* sizeof(acl_params
->mac_acl
[0])));
842 for (i
= 0; i
< n_entries
; i
++)
843 os_memcpy(acl_params
->mac_acl
[i
].addr
, mac_acl
[i
].addr
,
846 acl_params
->acl_policy
= accept_acl
;
847 acl_params
->num_mac_acl
= n_entries
;
849 err
= hostapd_drv_set_acl(hapd
, acl_params
);
857 static void hostapd_set_acl(struct hostapd_data
*hapd
)
859 struct hostapd_config
*conf
= hapd
->iconf
;
863 if (hapd
->iface
->drv_max_acl_mac_addrs
== 0)
865 if (!(conf
->bss
[0]->num_accept_mac
|| conf
->bss
[0]->num_deny_mac
))
868 if (conf
->bss
[0]->macaddr_acl
== DENY_UNLESS_ACCEPTED
) {
869 if (conf
->bss
[0]->num_accept_mac
) {
871 err
= hostapd_set_acl_list(hapd
,
872 conf
->bss
[0]->accept_mac
,
873 conf
->bss
[0]->num_accept_mac
,
876 wpa_printf(MSG_DEBUG
, "Failed to set accept acl");
880 wpa_printf(MSG_DEBUG
, "Mismatch between ACL Policy & Accept/deny lists file");
882 } else if (conf
->bss
[0]->macaddr_acl
== ACCEPT_UNLESS_DENIED
) {
883 if (conf
->bss
[0]->num_deny_mac
) {
885 err
= hostapd_set_acl_list(hapd
, conf
->bss
[0]->deny_mac
,
886 conf
->bss
[0]->num_deny_mac
,
889 wpa_printf(MSG_DEBUG
, "Failed to set deny acl");
893 wpa_printf(MSG_DEBUG
, "Mismatch between ACL Policy & Accept/deny lists file");
899 static int setup_interface(struct hostapd_iface
*iface
)
901 struct hostapd_data
*hapd
= iface
->bss
[0];
906 * Make sure that all BSSes get configured with a pointer to the same
909 for (i
= 1; i
< iface
->num_bss
; i
++) {
910 iface
->bss
[i
]->driver
= hapd
->driver
;
911 iface
->bss
[i
]->drv_priv
= hapd
->drv_priv
;
914 if (hostapd_validate_bssid_configuration(iface
))
917 if (hapd
->iconf
->country
[0] && hapd
->iconf
->country
[1]) {
918 os_memcpy(country
, hapd
->iconf
->country
, 3);
920 if (hostapd_set_country(hapd
, country
) < 0) {
921 wpa_printf(MSG_ERROR
, "Failed to set country code");
926 if (hostapd_get_hw_features(iface
)) {
927 /* Not all drivers support this yet, so continue without hw
930 int ret
= hostapd_select_hw_mode(iface
);
932 wpa_printf(MSG_ERROR
, "Could not select hw_mode and "
933 "channel. (%d)", ret
);
937 wpa_printf(MSG_DEBUG
, "Interface initialization will be completed in a callback (ACS)");
940 ret
= hostapd_check_ht_capab(iface
);
944 wpa_printf(MSG_DEBUG
, "Interface initialization will "
945 "be completed in a callback");
949 if (iface
->conf
->ieee80211h
)
950 wpa_printf(MSG_DEBUG
, "DFS support is enabled");
952 return hostapd_setup_interface_complete(iface
, 0);
956 int hostapd_setup_interface_complete(struct hostapd_iface
*iface
, int err
)
958 struct hostapd_data
*hapd
= iface
->bss
[0];
963 wpa_printf(MSG_ERROR
, "Interface initialization failed");
968 wpa_printf(MSG_DEBUG
, "Completing interface initialization");
969 if (hapd
->iconf
->channel
) {
972 #endif /* NEED_AP_MLME */
974 iface
->freq
= hostapd_hw_get_freq(hapd
, hapd
->iconf
->channel
);
975 wpa_printf(MSG_DEBUG
, "Mode: %s Channel: %d "
977 hostapd_hw_mode_txt(hapd
->iconf
->hw_mode
),
978 hapd
->iconf
->channel
, iface
->freq
);
982 res
= hostapd_handle_dfs(hapd
);
985 #endif /* NEED_AP_MLME */
987 if (hostapd_set_freq(hapd
, hapd
->iconf
->hw_mode
, iface
->freq
,
988 hapd
->iconf
->channel
,
989 hapd
->iconf
->ieee80211n
,
990 hapd
->iconf
->ieee80211ac
,
991 hapd
->iconf
->secondary_channel
,
992 hapd
->iconf
->vht_oper_chwidth
,
993 hapd
->iconf
->vht_oper_centr_freq_seg0_idx
,
994 hapd
->iconf
->vht_oper_centr_freq_seg1_idx
)) {
995 wpa_printf(MSG_ERROR
, "Could not set channel for "
1001 if (iface
->current_mode
) {
1002 if (hostapd_prepare_rates(iface
, iface
->current_mode
)) {
1003 wpa_printf(MSG_ERROR
, "Failed to prepare rates "
1005 hostapd_logger(hapd
, NULL
, HOSTAPD_MODULE_IEEE80211
,
1006 HOSTAPD_LEVEL_WARNING
,
1007 "Failed to prepare rates table.");
1012 if (hapd
->iconf
->rts_threshold
> -1 &&
1013 hostapd_set_rts(hapd
, hapd
->iconf
->rts_threshold
)) {
1014 wpa_printf(MSG_ERROR
, "Could not set RTS threshold for "
1019 if (hapd
->iconf
->fragm_threshold
> -1 &&
1020 hostapd_set_frag(hapd
, hapd
->iconf
->fragm_threshold
)) {
1021 wpa_printf(MSG_ERROR
, "Could not set fragmentation threshold "
1022 "for kernel driver");
1026 prev_addr
= hapd
->own_addr
;
1028 for (j
= 0; j
< iface
->num_bss
; j
++) {
1029 hapd
= iface
->bss
[j
];
1031 os_memcpy(hapd
->own_addr
, prev_addr
, ETH_ALEN
);
1032 if (hostapd_setup_bss(hapd
, j
== 0))
1034 if (hostapd_mac_comp_empty(hapd
->conf
->bssid
) == 0)
1035 prev_addr
= hapd
->own_addr
;
1038 hostapd_tx_queue_params(iface
);
1040 ap_list_init(iface
);
1042 hostapd_set_acl(hapd
);
1044 if (hostapd_driver_commit(hapd
) < 0) {
1045 wpa_printf(MSG_ERROR
, "%s: Failed to commit driver "
1046 "configuration", __func__
);
1051 * WPS UPnP module can be initialized only when the "upnp_iface" is up.
1052 * If "interface" and "upnp_iface" are the same (e.g., non-bridge
1053 * mode), the interface is up only after driver_commit, so initialize
1054 * WPS after driver_commit.
1056 for (j
= 0; j
< iface
->num_bss
; j
++) {
1057 if (hostapd_init_wps_complete(iface
->bss
[j
]))
1061 if (hapd
->setup_complete_cb
)
1062 hapd
->setup_complete_cb(hapd
->setup_complete_cb_ctx
);
1064 wpa_printf(MSG_DEBUG
, "%s: Setup of interface done.",
1065 iface
->bss
[0]->conf
->iface
);
1072 * hostapd_setup_interface - Setup of an interface
1073 * @iface: Pointer to interface data.
1074 * Returns: 0 on success, -1 on failure
1076 * Initializes the driver interface, validates the configuration,
1077 * and sets driver parameters based on the configuration.
1078 * Flushes old stations, sets the channel, encryption,
1079 * beacons, and WDS links based on the configuration.
1081 int hostapd_setup_interface(struct hostapd_iface
*iface
)
1085 ret
= setup_interface(iface
);
1087 wpa_printf(MSG_ERROR
, "%s: Unable to setup interface.",
1088 iface
->bss
[0]->conf
->iface
);
1097 * hostapd_alloc_bss_data - Allocate and initialize per-BSS data
1098 * @hapd_iface: Pointer to interface data
1099 * @conf: Pointer to per-interface configuration
1100 * @bss: Pointer to per-BSS configuration for this BSS
1101 * Returns: Pointer to allocated BSS data
1103 * This function is used to allocate per-BSS data structure. This data will be
1104 * freed after hostapd_cleanup() is called for it during interface
1107 struct hostapd_data
*
1108 hostapd_alloc_bss_data(struct hostapd_iface
*hapd_iface
,
1109 struct hostapd_config
*conf
,
1110 struct hostapd_bss_config
*bss
)
1112 struct hostapd_data
*hapd
;
1114 hapd
= os_zalloc(sizeof(*hapd
));
1118 hapd
->new_assoc_sta_cb
= hostapd_new_assoc_sta
;
1121 hapd
->iface
= hapd_iface
;
1122 hapd
->driver
= hapd
->iconf
->driver
;
1123 hapd
->ctrl_sock
= -1;
1129 void hostapd_interface_deinit(struct hostapd_iface
*iface
)
1136 hostapd_cleanup_iface_pre(iface
);
1137 for (j
= 0; j
< iface
->num_bss
; j
++) {
1138 struct hostapd_data
*hapd
= iface
->bss
[j
];
1139 hostapd_free_stas(hapd
);
1140 hostapd_flush_old_stations(hapd
, WLAN_REASON_DEAUTH_LEAVING
);
1141 hostapd_clear_wep(hapd
);
1142 hostapd_cleanup(hapd
);
1147 void hostapd_interface_free(struct hostapd_iface
*iface
)
1150 for (j
= 0; j
< iface
->num_bss
; j
++)
1151 os_free(iface
->bss
[j
]);
1152 hostapd_cleanup_iface(iface
);
1156 void hostapd_interface_deinit_free(struct hostapd_iface
*iface
)
1158 const struct wpa_driver_ops
*driver
;
1162 driver
= iface
->bss
[0]->driver
;
1163 drv_priv
= iface
->bss
[0]->drv_priv
;
1164 hostapd_interface_deinit(iface
);
1165 if (driver
&& driver
->hapd_deinit
&& drv_priv
)
1166 driver
->hapd_deinit(drv_priv
);
1167 hostapd_interface_free(iface
);
1171 int hostapd_enable_iface(struct hostapd_iface
*hapd_iface
)
1173 if (hapd_iface
->bss
[0]->drv_priv
!= NULL
) {
1174 wpa_printf(MSG_ERROR
, "Interface %s already enabled",
1175 hapd_iface
->conf
->bss
[0]->iface
);
1179 wpa_printf(MSG_DEBUG
, "Enable interface %s",
1180 hapd_iface
->conf
->bss
[0]->iface
);
1182 if (hapd_iface
->interfaces
== NULL
||
1183 hapd_iface
->interfaces
->driver_init
== NULL
||
1184 hapd_iface
->interfaces
->driver_init(hapd_iface
) ||
1185 hostapd_setup_interface(hapd_iface
)) {
1186 hostapd_interface_deinit_free(hapd_iface
);
1193 int hostapd_reload_iface(struct hostapd_iface
*hapd_iface
)
1197 wpa_printf(MSG_DEBUG
, "Reload interface %s",
1198 hapd_iface
->conf
->bss
[0]->iface
);
1199 for (j
= 0; j
< hapd_iface
->num_bss
; j
++)
1200 hostapd_set_security_params(hapd_iface
->conf
->bss
[j
]);
1201 if (hostapd_config_check(hapd_iface
->conf
) < 0) {
1202 wpa_printf(MSG_ERROR
, "Updated configuration is invalid");
1205 hostapd_clear_old(hapd_iface
);
1206 for (j
= 0; j
< hapd_iface
->num_bss
; j
++)
1207 hostapd_reload_bss(hapd_iface
->bss
[j
]);
1213 int hostapd_disable_iface(struct hostapd_iface
*hapd_iface
)
1216 const struct wpa_driver_ops
*driver
;
1219 if (hapd_iface
== NULL
)
1221 driver
= hapd_iface
->bss
[0]->driver
;
1222 drv_priv
= hapd_iface
->bss
[0]->drv_priv
;
1224 /* whatever hostapd_interface_deinit does */
1225 for (j
= 0; j
< hapd_iface
->num_bss
; j
++) {
1226 struct hostapd_data
*hapd
= hapd_iface
->bss
[j
];
1227 hostapd_free_stas(hapd
);
1228 hostapd_flush_old_stations(hapd
, WLAN_REASON_DEAUTH_LEAVING
);
1229 hostapd_clear_wep(hapd
);
1230 hostapd_free_hapd_data(hapd
);
1233 if (driver
&& driver
->hapd_deinit
&& drv_priv
) {
1234 driver
->hapd_deinit(drv_priv
);
1235 hapd_iface
->bss
[0]->drv_priv
= NULL
;
1238 /* From hostapd_cleanup_iface: These were initialized in
1239 * hostapd_setup_interface and hostapd_setup_interface_complete
1241 hostapd_cleanup_iface_partial(hapd_iface
);
1243 wpa_printf(MSG_DEBUG
, "Interface %s disabled",
1244 hapd_iface
->bss
[0]->conf
->iface
);
1249 static struct hostapd_iface
*
1250 hostapd_iface_alloc(struct hapd_interfaces
*interfaces
)
1252 struct hostapd_iface
**iface
, *hapd_iface
;
1254 iface
= os_realloc_array(interfaces
->iface
, interfaces
->count
+ 1,
1255 sizeof(struct hostapd_iface
*));
1258 interfaces
->iface
= iface
;
1259 hapd_iface
= interfaces
->iface
[interfaces
->count
] =
1260 os_zalloc(sizeof(*hapd_iface
));
1261 if (hapd_iface
== NULL
) {
1262 wpa_printf(MSG_ERROR
, "%s: Failed to allocate memory for "
1263 "the interface", __func__
);
1266 interfaces
->count
++;
1267 hapd_iface
->interfaces
= interfaces
;
1273 static struct hostapd_config
*
1274 hostapd_config_alloc(struct hapd_interfaces
*interfaces
, const char *ifname
,
1275 const char *ctrl_iface
)
1277 struct hostapd_bss_config
*bss
;
1278 struct hostapd_config
*conf
;
1280 /* Allocates memory for bss and conf */
1281 conf
= hostapd_config_defaults();
1283 wpa_printf(MSG_ERROR
, "%s: Failed to allocate memory for "
1284 "configuration", __func__
);
1288 conf
->driver
= wpa_drivers
[0];
1289 if (conf
->driver
== NULL
) {
1290 wpa_printf(MSG_ERROR
, "No driver wrappers registered!");
1291 hostapd_config_free(conf
);
1295 bss
= conf
->last_bss
= conf
->bss
[0];
1297 os_strlcpy(bss
->iface
, ifname
, sizeof(bss
->iface
));
1298 bss
->ctrl_interface
= os_strdup(ctrl_iface
);
1299 if (bss
->ctrl_interface
== NULL
) {
1300 hostapd_config_free(conf
);
1304 /* Reading configuration file skipped, will be done in SET!
1305 * From reading the configuration till the end has to be done in
1312 static struct hostapd_iface
* hostapd_data_alloc(
1313 struct hapd_interfaces
*interfaces
, struct hostapd_config
*conf
)
1316 struct hostapd_iface
*hapd_iface
=
1317 interfaces
->iface
[interfaces
->count
- 1];
1318 struct hostapd_data
*hapd
;
1320 hapd_iface
->conf
= conf
;
1321 hapd_iface
->num_bss
= conf
->num_bss
;
1323 hapd_iface
->bss
= os_zalloc(conf
->num_bss
*
1324 sizeof(struct hostapd_data
*));
1325 if (hapd_iface
->bss
== NULL
)
1328 for (i
= 0; i
< conf
->num_bss
; i
++) {
1329 hapd
= hapd_iface
->bss
[i
] =
1330 hostapd_alloc_bss_data(hapd_iface
, conf
, conf
->bss
[i
]);
1333 hapd
->msg_ctx
= hapd
;
1336 hapd_iface
->interfaces
= interfaces
;
1342 int hostapd_add_iface(struct hapd_interfaces
*interfaces
, char *buf
)
1344 struct hostapd_config
*conf
= NULL
;
1345 struct hostapd_iface
*hapd_iface
= NULL
;
1348 const char *conf_file
= NULL
;
1350 ptr
= os_strchr(buf
, ' ');
1355 if (os_strncmp(ptr
, "config=", 7) == 0)
1356 conf_file
= ptr
+ 7;
1358 for (i
= 0; i
< interfaces
->count
; i
++) {
1359 if (!os_strcmp(interfaces
->iface
[i
]->conf
->bss
[0]->iface
,
1361 wpa_printf(MSG_INFO
, "Cannot add interface - it "
1367 hapd_iface
= hostapd_iface_alloc(interfaces
);
1368 if (hapd_iface
== NULL
) {
1369 wpa_printf(MSG_ERROR
, "%s: Failed to allocate memory "
1370 "for interface", __func__
);
1374 if (conf_file
&& interfaces
->config_read_cb
) {
1375 conf
= interfaces
->config_read_cb(conf_file
);
1376 if (conf
&& conf
->bss
)
1377 os_strlcpy(conf
->bss
[0]->iface
, buf
,
1378 sizeof(conf
->bss
[0]->iface
));
1380 conf
= hostapd_config_alloc(interfaces
, buf
, ptr
);
1381 if (conf
== NULL
|| conf
->bss
== NULL
) {
1382 wpa_printf(MSG_ERROR
, "%s: Failed to allocate memory "
1383 "for configuration", __func__
);
1387 hapd_iface
= hostapd_data_alloc(interfaces
, conf
);
1388 if (hapd_iface
== NULL
) {
1389 wpa_printf(MSG_ERROR
, "%s: Failed to allocate memory "
1390 "for hostapd", __func__
);
1394 if (hapd_iface
->interfaces
&&
1395 hapd_iface
->interfaces
->ctrl_iface_init
&&
1396 hapd_iface
->interfaces
->ctrl_iface_init(hapd_iface
->bss
[0])) {
1397 wpa_printf(MSG_ERROR
, "%s: Failed to setup control "
1398 "interface", __func__
);
1401 wpa_printf(MSG_INFO
, "Add interface '%s'", conf
->bss
[0]->iface
);
1407 hostapd_config_free(conf
);
1409 if (hapd_iface
->bss
) {
1410 for (i
= 0; i
< hapd_iface
->num_bss
; i
++)
1411 os_free(hapd_iface
->bss
[i
]);
1412 os_free(hapd_iface
->bss
);
1414 os_free(hapd_iface
);
1420 int hostapd_remove_iface(struct hapd_interfaces
*interfaces
, char *buf
)
1422 struct hostapd_iface
*hapd_iface
;
1425 for (i
= 0; i
< interfaces
->count
; i
++) {
1426 hapd_iface
= interfaces
->iface
[i
];
1427 if (hapd_iface
== NULL
)
1429 if (!os_strcmp(hapd_iface
->conf
->bss
[0]->iface
, buf
)) {
1430 wpa_printf(MSG_INFO
, "Remove interface '%s'", buf
);
1431 hostapd_interface_deinit_free(hapd_iface
);
1433 while (k
< (interfaces
->count
- 1)) {
1434 interfaces
->iface
[k
] =
1435 interfaces
->iface
[k
+ 1];
1438 interfaces
->count
--;
1447 * hostapd_new_assoc_sta - Notify that a new station associated with the AP
1448 * @hapd: Pointer to BSS data
1449 * @sta: Pointer to the associated STA data
1450 * @reassoc: 1 to indicate this was a re-association; 0 = first association
1452 * This function will be called whenever a station associates with the AP. It
1453 * can be called from ieee802_11.c for drivers that export MLME to hostapd and
1454 * from drv_callbacks.c based on driver events for drivers that take care of
1455 * management frames (IEEE 802.11 authentication and association) internally.
1457 void hostapd_new_assoc_sta(struct hostapd_data
*hapd
, struct sta_info
*sta
,
1460 if (hapd
->tkip_countermeasures
) {
1461 hostapd_drv_sta_deauth(hapd
, sta
->addr
,
1462 WLAN_REASON_MICHAEL_MIC_FAILURE
);
1466 hostapd_prune_associations(hapd
, sta
->addr
);
1468 /* IEEE 802.11F (IAPP) */
1469 if (hapd
->conf
->ieee802_11f
)
1470 iapp_new_station(hapd
->iapp
, sta
);
1473 if (sta
->p2p_ie
== NULL
&& !sta
->no_p2p_set
) {
1474 sta
->no_p2p_set
= 1;
1475 hapd
->num_sta_no_p2p
++;
1476 if (hapd
->num_sta_no_p2p
== 1)
1477 hostapd_p2p_non_p2p_sta_connected(hapd
);
1479 #endif /* CONFIG_P2P */
1481 /* Start accounting here, if IEEE 802.1X and WPA are not used.
1482 * IEEE 802.1X/WPA code will start accounting after the station has
1483 * been authorized. */
1484 if (!hapd
->conf
->ieee802_1x
&& !hapd
->conf
->wpa
) {
1485 os_get_time(&sta
->connected_time
);
1486 accounting_sta_start(hapd
, sta
);
1489 /* Start IEEE 802.1X authentication process for new stations */
1490 ieee802_1x_new_station(hapd
, sta
);
1492 if (sta
->auth_alg
!= WLAN_AUTH_FT
&&
1493 !(sta
->flags
& (WLAN_STA_WPS
| WLAN_STA_MAYBE_WPS
)))
1494 wpa_auth_sm_event(sta
->wpa_sm
, WPA_REAUTH
);
1496 wpa_auth_sta_associated(hapd
->wpa_auth
, sta
->wpa_sm
);
1498 wpa_printf(MSG_DEBUG
, "%s: reschedule ap_handle_timer timeout "
1499 "for " MACSTR
" (%d seconds - ap_max_inactivity)",
1500 __func__
, MAC2STR(sta
->addr
),
1501 hapd
->conf
->ap_max_inactivity
);
1502 eloop_cancel_timeout(ap_handle_timer
, hapd
, sta
);
1503 eloop_register_timeout(hapd
->conf
->ap_max_inactivity
, 0,
1504 ap_handle_timer
, hapd
, sta
);