2 * Driver interaction with Linux nl80211/cfg80211
3 * Copyright (c) 2002-2010, Jouni Malinen <j@w1.fi>
4 * Copyright (c) 2003-2004, Instant802 Networks, Inc.
5 * Copyright (c) 2005-2006, Devicescape Software, Inc.
6 * Copyright (c) 2007, Johannes Berg <johannes@sipsolutions.net>
7 * Copyright (c) 2009, Atheros Communications
9 * This program is free software; you can redistribute it and/or modify
10 * it under the terms of the GNU General Public License version 2 as
11 * published by the Free Software Foundation.
13 * Alternatively, this software may be distributed under the terms of BSD
16 * See README and COPYING for more details.
20 #include <sys/ioctl.h>
22 #include <netlink/genl/genl.h>
23 #include <netlink/genl/family.h>
24 #include <netlink/genl/ctrl.h>
25 #include <netpacket/packet.h>
26 #include <linux/filter.h>
27 #include "nl80211_copy.h"
31 #include "common/ieee802_11_defs.h"
33 #include "linux_ioctl.h"
35 #include "radiotap_iter.h"
39 /* libnl 2.0 compatibility code */
40 #define nl_handle nl_sock
41 #define nl_handle_alloc_cb nl_socket_alloc_cb
42 #define nl_handle_destroy nl_socket_free
43 #endif /* CONFIG_LIBNL20 */
47 #define IFF_LOWER_UP 0x10000 /* driver signals L1 up */
50 #define IFF_DORMANT 0x20000 /* driver signals dormant */
53 #ifndef IF_OPER_DORMANT
54 #define IF_OPER_DORMANT 5
61 struct i802_bss
*next
;
63 unsigned int beacon_set
:1;
66 struct wpa_driver_nl80211_data
{
68 struct netlink_data
*netlink
;
69 int ioctl_sock
; /* socket for ioctl() use */
70 char ifname
[IFNAMSIZ
+ 1];
73 struct wpa_driver_capa capa
;
78 int scan_complete_events
;
80 struct nl_handle
*nl_handle
;
81 struct nl_handle
*nl_handle_event
;
82 struct nl_cache
*nl_cache
;
83 struct nl_cache
*nl_cache_event
;
85 struct genl_family
*nl80211
;
87 u8 auth_bssid
[ETH_ALEN
];
93 int ap_scan_as_station
;
94 unsigned int assoc_freq
;
99 int disable_11b_rates
;
101 unsigned int beacon_set
:1;
102 unsigned int pending_remain_on_chan
:1;
104 u64 remain_on_chan_cookie
;
107 int eapol_sock
; /* socket for EAPOL frames */
109 int default_if_indices
[16];
121 static void wpa_driver_nl80211_scan_timeout(void *eloop_ctx
,
123 static int wpa_driver_nl80211_set_mode(void *priv
, int mode
);
125 wpa_driver_nl80211_finish_drv_init(struct wpa_driver_nl80211_data
*drv
);
126 static int wpa_driver_nl80211_mlme(struct wpa_driver_nl80211_data
*drv
,
127 const u8
*addr
, int cmd
, u16 reason_code
);
128 static void nl80211_remove_monitor_interface(
129 struct wpa_driver_nl80211_data
*drv
);
132 static void add_ifidx(struct wpa_driver_nl80211_data
*drv
, int ifidx
);
133 static void del_ifidx(struct wpa_driver_nl80211_data
*drv
, int ifidx
);
134 static struct i802_bss
* get_bss(struct wpa_driver_nl80211_data
*drv
,
136 static int i802_set_freq(void *priv
, struct hostapd_freq_params
*freq
);
137 static int wpa_driver_nl80211_if_remove(void *priv
,
138 enum wpa_driver_if_type type
,
142 static void wpa_driver_nl80211_probe_req_report_timeout(void *eloop_ctx
,
144 static int nl80211_disable_11b_rates(struct wpa_driver_nl80211_data
*drv
,
145 int ifindex
, int disabled
);
149 static int ack_handler(struct nl_msg
*msg
, void *arg
)
156 static int finish_handler(struct nl_msg
*msg
, void *arg
)
163 static int error_handler(struct sockaddr_nl
*nla
, struct nlmsgerr
*err
,
172 static int no_seq_check(struct nl_msg
*msg
, void *arg
)
178 static int send_and_recv_msgs(struct wpa_driver_nl80211_data
*drv
,
180 int (*valid_handler
)(struct nl_msg
*, void *),
186 cb
= nl_cb_clone(drv
->nl_cb
);
190 err
= nl_send_auto_complete(drv
->nl_handle
, msg
);
196 nl_cb_err(cb
, NL_CB_CUSTOM
, error_handler
, &err
);
197 nl_cb_set(cb
, NL_CB_FINISH
, NL_CB_CUSTOM
, finish_handler
, &err
);
198 nl_cb_set(cb
, NL_CB_ACK
, NL_CB_CUSTOM
, ack_handler
, &err
);
201 nl_cb_set(cb
, NL_CB_VALID
, NL_CB_CUSTOM
,
202 valid_handler
, valid_data
);
205 nl_recvmsgs(drv
->nl_handle
, cb
);
219 static int family_handler(struct nl_msg
*msg
, void *arg
)
221 struct family_data
*res
= arg
;
222 struct nlattr
*tb
[CTRL_ATTR_MAX
+ 1];
223 struct genlmsghdr
*gnlh
= nlmsg_data(nlmsg_hdr(msg
));
224 struct nlattr
*mcgrp
;
227 nla_parse(tb
, CTRL_ATTR_MAX
, genlmsg_attrdata(gnlh
, 0),
228 genlmsg_attrlen(gnlh
, 0), NULL
);
229 if (!tb
[CTRL_ATTR_MCAST_GROUPS
])
232 nla_for_each_nested(mcgrp
, tb
[CTRL_ATTR_MCAST_GROUPS
], i
) {
233 struct nlattr
*tb2
[CTRL_ATTR_MCAST_GRP_MAX
+ 1];
234 nla_parse(tb2
, CTRL_ATTR_MCAST_GRP_MAX
, nla_data(mcgrp
),
235 nla_len(mcgrp
), NULL
);
236 if (!tb2
[CTRL_ATTR_MCAST_GRP_NAME
] ||
237 !tb2
[CTRL_ATTR_MCAST_GRP_ID
] ||
238 os_strncmp(nla_data(tb2
[CTRL_ATTR_MCAST_GRP_NAME
]),
240 nla_len(tb2
[CTRL_ATTR_MCAST_GRP_NAME
])) != 0)
242 res
->id
= nla_get_u32(tb2
[CTRL_ATTR_MCAST_GRP_ID
]);
250 static int nl_get_multicast_id(struct wpa_driver_nl80211_data
*drv
,
251 const char *family
, const char *group
)
255 struct family_data res
= { group
, -ENOENT
};
260 genlmsg_put(msg
, 0, 0, genl_ctrl_resolve(drv
->nl_handle
, "nlctrl"),
261 0, 0, CTRL_CMD_GETFAMILY
, 0);
262 NLA_PUT_STRING(msg
, CTRL_ATTR_FAMILY_NAME
, family
);
264 ret
= send_and_recv_msgs(drv
, msg
, family_handler
, &res
);
275 static int wpa_driver_nl80211_get_bssid(void *priv
, u8
*bssid
)
277 struct wpa_driver_nl80211_data
*drv
= priv
;
278 if (!drv
->associated
)
280 os_memcpy(bssid
, drv
->bssid
, ETH_ALEN
);
285 static int wpa_driver_nl80211_get_ssid(void *priv
, u8
*ssid
)
287 struct wpa_driver_nl80211_data
*drv
= priv
;
288 if (!drv
->associated
)
290 os_memcpy(ssid
, drv
->ssid
, drv
->ssid_len
);
291 return drv
->ssid_len
;
295 static void wpa_driver_nl80211_event_link(struct wpa_driver_nl80211_data
*drv
,
296 char *buf
, size_t len
, int del
)
298 union wpa_event_data event
;
300 os_memset(&event
, 0, sizeof(event
));
301 if (len
> sizeof(event
.interface_status
.ifname
))
302 len
= sizeof(event
.interface_status
.ifname
) - 1;
303 os_memcpy(event
.interface_status
.ifname
, buf
, len
);
304 event
.interface_status
.ievent
= del
? EVENT_INTERFACE_REMOVED
:
305 EVENT_INTERFACE_ADDED
;
307 wpa_printf(MSG_DEBUG
, "RTM_%sLINK, IFLA_IFNAME: Interface '%s' %s",
309 event
.interface_status
.ifname
,
310 del
? "removed" : "added");
312 if (os_strcmp(drv
->ifname
, event
.interface_status
.ifname
) == 0) {
319 wpa_supplicant_event(drv
->ctx
, EVENT_INTERFACE_STATUS
, &event
);
323 static int wpa_driver_nl80211_own_ifname(struct wpa_driver_nl80211_data
*drv
,
326 int attrlen
, rta_len
;
330 attr
= (struct rtattr
*) buf
;
332 rta_len
= RTA_ALIGN(sizeof(struct rtattr
));
333 while (RTA_OK(attr
, attrlen
)) {
334 if (attr
->rta_type
== IFLA_IFNAME
) {
335 if (os_strcmp(((char *) attr
) + rta_len
, drv
->ifname
)
341 attr
= RTA_NEXT(attr
, attrlen
);
348 static int wpa_driver_nl80211_own_ifindex(struct wpa_driver_nl80211_data
*drv
,
349 int ifindex
, u8
*buf
, size_t len
)
351 if (drv
->ifindex
== ifindex
)
354 if (drv
->if_removed
&& wpa_driver_nl80211_own_ifname(drv
, buf
, len
)) {
355 drv
->ifindex
= if_nametoindex(drv
->ifname
);
356 wpa_printf(MSG_DEBUG
, "nl80211: Update ifindex for a removed "
358 wpa_driver_nl80211_finish_drv_init(drv
);
366 static void wpa_driver_nl80211_event_rtm_newlink(void *ctx
,
367 struct ifinfomsg
*ifi
,
370 struct wpa_driver_nl80211_data
*drv
= ctx
;
371 int attrlen
, rta_len
;
374 if (!wpa_driver_nl80211_own_ifindex(drv
, ifi
->ifi_index
, buf
, len
)) {
375 wpa_printf(MSG_DEBUG
, "Ignore event for foreign ifindex %d",
380 wpa_printf(MSG_DEBUG
, "RTM_NEWLINK: operstate=%d ifi_flags=0x%x "
382 drv
->operstate
, ifi
->ifi_flags
,
383 (ifi
->ifi_flags
& IFF_UP
) ? "[UP]" : "",
384 (ifi
->ifi_flags
& IFF_RUNNING
) ? "[RUNNING]" : "",
385 (ifi
->ifi_flags
& IFF_LOWER_UP
) ? "[LOWER_UP]" : "",
386 (ifi
->ifi_flags
& IFF_DORMANT
) ? "[DORMANT]" : "");
388 * Some drivers send the association event before the operup event--in
389 * this case, lifting operstate in wpa_driver_nl80211_set_operstate()
390 * fails. This will hit us when wpa_supplicant does not need to do
391 * IEEE 802.1X authentication
393 if (drv
->operstate
== 1 &&
394 (ifi
->ifi_flags
& (IFF_LOWER_UP
| IFF_DORMANT
)) == IFF_LOWER_UP
&&
395 !(ifi
->ifi_flags
& IFF_RUNNING
))
396 netlink_send_oper_ifla(drv
->netlink
, drv
->ifindex
,
400 attr
= (struct rtattr
*) buf
;
401 rta_len
= RTA_ALIGN(sizeof(struct rtattr
));
402 while (RTA_OK(attr
, attrlen
)) {
403 if (attr
->rta_type
== IFLA_IFNAME
) {
404 wpa_driver_nl80211_event_link(
406 ((char *) attr
) + rta_len
,
407 attr
->rta_len
- rta_len
, 0);
409 attr
= RTA_NEXT(attr
, attrlen
);
414 static void wpa_driver_nl80211_event_rtm_dellink(void *ctx
,
415 struct ifinfomsg
*ifi
,
418 struct wpa_driver_nl80211_data
*drv
= ctx
;
419 int attrlen
, rta_len
;
423 attr
= (struct rtattr
*) buf
;
425 rta_len
= RTA_ALIGN(sizeof(struct rtattr
));
426 while (RTA_OK(attr
, attrlen
)) {
427 if (attr
->rta_type
== IFLA_IFNAME
) {
428 wpa_driver_nl80211_event_link(
430 ((char *) attr
) + rta_len
,
431 attr
->rta_len
- rta_len
, 1);
433 attr
= RTA_NEXT(attr
, attrlen
);
438 static void mlme_event_auth(struct wpa_driver_nl80211_data
*drv
,
439 const u8
*frame
, size_t len
)
441 const struct ieee80211_mgmt
*mgmt
;
442 union wpa_event_data event
;
444 mgmt
= (const struct ieee80211_mgmt
*) frame
;
445 if (len
< 24 + sizeof(mgmt
->u
.auth
)) {
446 wpa_printf(MSG_DEBUG
, "nl80211: Too short association event "
451 os_memcpy(drv
->auth_bssid
, mgmt
->sa
, ETH_ALEN
);
452 os_memset(&event
, 0, sizeof(event
));
453 os_memcpy(event
.auth
.peer
, mgmt
->sa
, ETH_ALEN
);
454 event
.auth
.auth_type
= le_to_host16(mgmt
->u
.auth
.auth_alg
);
455 event
.auth
.status_code
= le_to_host16(mgmt
->u
.auth
.status_code
);
456 if (len
> 24 + sizeof(mgmt
->u
.auth
)) {
457 event
.auth
.ies
= mgmt
->u
.auth
.variable
;
458 event
.auth
.ies_len
= len
- 24 - sizeof(mgmt
->u
.auth
);
461 wpa_supplicant_event(drv
->ctx
, EVENT_AUTH
, &event
);
465 static void mlme_event_assoc(struct wpa_driver_nl80211_data
*drv
,
466 const u8
*frame
, size_t len
)
468 const struct ieee80211_mgmt
*mgmt
;
469 union wpa_event_data event
;
472 mgmt
= (const struct ieee80211_mgmt
*) frame
;
473 if (len
< 24 + sizeof(mgmt
->u
.assoc_resp
)) {
474 wpa_printf(MSG_DEBUG
, "nl80211: Too short association event "
479 status
= le_to_host16(mgmt
->u
.assoc_resp
.status_code
);
480 if (status
!= WLAN_STATUS_SUCCESS
) {
481 os_memset(&event
, 0, sizeof(event
));
482 if (len
> 24 + sizeof(mgmt
->u
.assoc_resp
)) {
483 event
.assoc_reject
.resp_ies
=
484 (u8
*) mgmt
->u
.assoc_resp
.variable
;
485 event
.assoc_reject
.resp_ies_len
=
486 len
- 24 - sizeof(mgmt
->u
.assoc_resp
);
488 event
.assoc_reject
.status_code
= status
;
490 wpa_supplicant_event(drv
->ctx
, EVENT_ASSOC_REJECT
, &event
);
495 os_memcpy(drv
->bssid
, mgmt
->sa
, ETH_ALEN
);
497 os_memset(&event
, 0, sizeof(event
));
498 if (len
> 24 + sizeof(mgmt
->u
.assoc_resp
)) {
499 event
.assoc_info
.resp_ies
= (u8
*) mgmt
->u
.assoc_resp
.variable
;
500 event
.assoc_info
.resp_ies_len
=
501 len
- 24 - sizeof(mgmt
->u
.assoc_resp
);
504 event
.assoc_info
.freq
= drv
->assoc_freq
;
506 wpa_supplicant_event(drv
->ctx
, EVENT_ASSOC
, &event
);
510 static void mlme_event_connect(struct wpa_driver_nl80211_data
*drv
,
511 enum nl80211_commands cmd
, struct nlattr
*status
,
512 struct nlattr
*addr
, struct nlattr
*req_ie
,
513 struct nlattr
*resp_ie
)
515 union wpa_event_data event
;
517 if (drv
->capa
.flags
& WPA_DRIVER_FLAGS_SME
) {
519 * Avoid reporting two association events that would confuse
522 wpa_printf(MSG_DEBUG
, "nl80211: Ignore connect event (cmd=%d) "
523 "when using userspace SME", cmd
);
527 os_memset(&event
, 0, sizeof(event
));
528 if (cmd
== NL80211_CMD_CONNECT
&&
529 nla_get_u16(status
) != WLAN_STATUS_SUCCESS
) {
531 event
.assoc_reject
.resp_ies
= nla_data(resp_ie
);
532 event
.assoc_reject
.resp_ies_len
= nla_len(resp_ie
);
534 event
.assoc_reject
.status_code
= nla_get_u16(status
);
535 wpa_supplicant_event(drv
->ctx
, EVENT_ASSOC_REJECT
, &event
);
541 os_memcpy(drv
->bssid
, nla_data(addr
), ETH_ALEN
);
544 event
.assoc_info
.req_ies
= nla_data(req_ie
);
545 event
.assoc_info
.req_ies_len
= nla_len(req_ie
);
548 event
.assoc_info
.resp_ies
= nla_data(resp_ie
);
549 event
.assoc_info
.resp_ies_len
= nla_len(resp_ie
);
552 wpa_supplicant_event(drv
->ctx
, EVENT_ASSOC
, &event
);
556 static void mlme_timeout_event(struct wpa_driver_nl80211_data
*drv
,
557 enum nl80211_commands cmd
, struct nlattr
*addr
)
559 union wpa_event_data event
;
560 enum wpa_event_type ev
;
562 if (nla_len(addr
) != ETH_ALEN
)
565 wpa_printf(MSG_DEBUG
, "nl80211: MLME event %d; timeout with " MACSTR
,
566 cmd
, MAC2STR((u8
*) nla_data(addr
)));
568 if (cmd
== NL80211_CMD_AUTHENTICATE
)
569 ev
= EVENT_AUTH_TIMED_OUT
;
570 else if (cmd
== NL80211_CMD_ASSOCIATE
)
571 ev
= EVENT_ASSOC_TIMED_OUT
;
575 os_memset(&event
, 0, sizeof(event
));
576 os_memcpy(event
.timeout_event
.addr
, nla_data(addr
), ETH_ALEN
);
577 wpa_supplicant_event(drv
->ctx
, ev
, &event
);
581 static void mlme_event(struct wpa_driver_nl80211_data
*drv
,
582 enum nl80211_commands cmd
, struct nlattr
*frame
,
583 struct nlattr
*addr
, struct nlattr
*timed_out
)
585 if (timed_out
&& addr
) {
586 mlme_timeout_event(drv
, cmd
, addr
);
591 wpa_printf(MSG_DEBUG
, "nl80211: MLME event %d without frame "
596 wpa_printf(MSG_DEBUG
, "nl80211: MLME event %d", cmd
);
597 wpa_hexdump(MSG_MSGDUMP
, "nl80211: MLME event frame",
598 nla_data(frame
), nla_len(frame
));
601 case NL80211_CMD_AUTHENTICATE
:
602 mlme_event_auth(drv
, nla_data(frame
), nla_len(frame
));
604 case NL80211_CMD_ASSOCIATE
:
605 mlme_event_assoc(drv
, nla_data(frame
), nla_len(frame
));
607 case NL80211_CMD_DEAUTHENTICATE
:
609 wpa_supplicant_event(drv
->ctx
, EVENT_DEAUTH
, NULL
);
611 case NL80211_CMD_DISASSOCIATE
:
613 wpa_supplicant_event(drv
->ctx
, EVENT_DISASSOC
, NULL
);
621 static void mlme_event_michael_mic_failure(struct wpa_driver_nl80211_data
*drv
,
624 union wpa_event_data data
;
626 wpa_printf(MSG_DEBUG
, "nl80211: MLME event Michael MIC failure");
627 os_memset(&data
, 0, sizeof(data
));
628 if (tb
[NL80211_ATTR_MAC
]) {
629 wpa_hexdump(MSG_DEBUG
, "nl80211: Source MAC address",
630 nla_data(tb
[NL80211_ATTR_MAC
]),
631 nla_len(tb
[NL80211_ATTR_MAC
]));
632 data
.michael_mic_failure
.src
= nla_data(tb
[NL80211_ATTR_MAC
]);
634 if (tb
[NL80211_ATTR_KEY_SEQ
]) {
635 wpa_hexdump(MSG_DEBUG
, "nl80211: TSC",
636 nla_data(tb
[NL80211_ATTR_KEY_SEQ
]),
637 nla_len(tb
[NL80211_ATTR_KEY_SEQ
]));
639 if (tb
[NL80211_ATTR_KEY_TYPE
]) {
640 enum nl80211_key_type key_type
=
641 nla_get_u32(tb
[NL80211_ATTR_KEY_TYPE
]);
642 wpa_printf(MSG_DEBUG
, "nl80211: Key Type %d", key_type
);
643 if (key_type
== NL80211_KEYTYPE_PAIRWISE
)
644 data
.michael_mic_failure
.unicast
= 1;
646 data
.michael_mic_failure
.unicast
= 1;
648 if (tb
[NL80211_ATTR_KEY_IDX
]) {
649 u8 key_id
= nla_get_u8(tb
[NL80211_ATTR_KEY_IDX
]);
650 wpa_printf(MSG_DEBUG
, "nl80211: Key Id %d", key_id
);
653 wpa_supplicant_event(drv
->ctx
, EVENT_MICHAEL_MIC_FAILURE
, &data
);
657 static void mlme_event_join_ibss(struct wpa_driver_nl80211_data
*drv
,
660 if (tb
[NL80211_ATTR_MAC
] == NULL
) {
661 wpa_printf(MSG_DEBUG
, "nl80211: No address in IBSS joined "
665 os_memcpy(drv
->bssid
, nla_data(tb
[NL80211_ATTR_MAC
]), ETH_ALEN
);
667 wpa_printf(MSG_DEBUG
, "nl80211: IBSS " MACSTR
" joined",
668 MAC2STR(drv
->bssid
));
670 wpa_supplicant_event(drv
->ctx
, EVENT_ASSOC
, NULL
);
674 static void mlme_event_remain_on_channel(struct wpa_driver_nl80211_data
*drv
,
675 int cancel_event
, struct nlattr
*tb
[])
677 unsigned int freq
, chan_type
, duration
;
678 union wpa_event_data data
;
681 if (tb
[NL80211_ATTR_WIPHY_FREQ
])
682 freq
= nla_get_u32(tb
[NL80211_ATTR_WIPHY_FREQ
]);
686 if (tb
[NL80211_ATTR_WIPHY_CHANNEL_TYPE
])
687 chan_type
= nla_get_u32(tb
[NL80211_ATTR_WIPHY_CHANNEL_TYPE
]);
691 if (tb
[NL80211_ATTR_DURATION
])
692 duration
= nla_get_u32(tb
[NL80211_ATTR_DURATION
]);
696 if (tb
[NL80211_ATTR_COOKIE
])
697 cookie
= nla_get_u64(tb
[NL80211_ATTR_COOKIE
]);
701 wpa_printf(MSG_DEBUG
, "nl80211: Remain-on-channel event (cancel=%d "
702 "freq=%u channel_type=%u duration=%u cookie=0x%llx (%s))",
703 cancel_event
, freq
, chan_type
, duration
,
704 (long long unsigned int) cookie
,
705 cookie
== drv
->remain_on_chan_cookie
? "match" : "unknown");
707 if (cookie
!= drv
->remain_on_chan_cookie
)
708 return; /* not for us */
710 drv
->pending_remain_on_chan
= !cancel_event
;
712 os_memset(&data
, 0, sizeof(data
));
713 data
.remain_on_channel
.freq
= freq
;
714 data
.remain_on_channel
.duration
= duration
;
715 wpa_supplicant_event(drv
->ctx
, cancel_event
?
716 EVENT_CANCEL_REMAIN_ON_CHANNEL
:
717 EVENT_REMAIN_ON_CHANNEL
, &data
);
721 static void send_scan_event(struct wpa_driver_nl80211_data
*drv
, int aborted
,
724 union wpa_event_data event
;
727 struct scan_info
*info
;
728 #define MAX_REPORT_FREQS 50
729 int freqs
[MAX_REPORT_FREQS
];
732 os_memset(&event
, 0, sizeof(event
));
733 info
= &event
.scan_info
;
734 info
->aborted
= aborted
;
736 if (tb
[NL80211_ATTR_SCAN_SSIDS
]) {
737 nla_for_each_nested(nl
, tb
[NL80211_ATTR_SCAN_SSIDS
], rem
) {
738 struct wpa_driver_scan_ssid
*s
=
739 &info
->ssids
[info
->num_ssids
];
740 s
->ssid
= nla_data(nl
);
741 s
->ssid_len
= nla_len(nl
);
743 if (info
->num_ssids
== WPAS_MAX_SCAN_SSIDS
)
747 if (tb
[NL80211_ATTR_SCAN_FREQUENCIES
]) {
748 nla_for_each_nested(nl
, tb
[NL80211_ATTR_SCAN_FREQUENCIES
], rem
)
750 freqs
[num_freqs
] = nla_get_u32(nl
);
752 if (num_freqs
== MAX_REPORT_FREQS
- 1)
756 info
->num_freqs
= num_freqs
;
758 wpa_supplicant_event(drv
->ctx
, EVENT_SCAN_RESULTS
, &event
);
762 static int process_event(struct nl_msg
*msg
, void *arg
)
764 struct wpa_driver_nl80211_data
*drv
= arg
;
765 struct genlmsghdr
*gnlh
= nlmsg_data(nlmsg_hdr(msg
));
766 struct nlattr
*tb
[NL80211_ATTR_MAX
+ 1];
768 nla_parse(tb
, NL80211_ATTR_MAX
, genlmsg_attrdata(gnlh
, 0),
769 genlmsg_attrlen(gnlh
, 0), NULL
);
771 if (tb
[NL80211_ATTR_IFINDEX
]) {
772 int ifindex
= nla_get_u32(tb
[NL80211_ATTR_IFINDEX
]);
773 if (ifindex
!= drv
->ifindex
) {
774 wpa_printf(MSG_DEBUG
, "nl80211: Ignored event (cmd=%d)"
775 " for foreign interface (ifindex %d)",
781 if (drv
->ap_scan_as_station
&&
782 (gnlh
->cmd
== NL80211_CMD_NEW_SCAN_RESULTS
||
783 gnlh
->cmd
== NL80211_CMD_SCAN_ABORTED
)) {
784 wpa_driver_nl80211_set_mode(drv
, IEEE80211_MODE_AP
);
785 drv
->ap_scan_as_station
= 0;
789 case NL80211_CMD_TRIGGER_SCAN
:
790 wpa_printf(MSG_DEBUG
, "nl80211: Scan trigger");
792 case NL80211_CMD_NEW_SCAN_RESULTS
:
793 wpa_printf(MSG_DEBUG
, "nl80211: New scan results available");
794 drv
->scan_complete_events
= 1;
795 eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout
, drv
,
797 send_scan_event(drv
, 0, tb
);
799 case NL80211_CMD_SCAN_ABORTED
:
800 wpa_printf(MSG_DEBUG
, "nl80211: Scan aborted");
802 * Need to indicate that scan results are available in order
803 * not to make wpa_supplicant stop its scanning.
805 eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout
, drv
,
807 send_scan_event(drv
, 1, tb
);
809 case NL80211_CMD_AUTHENTICATE
:
810 case NL80211_CMD_ASSOCIATE
:
811 case NL80211_CMD_DEAUTHENTICATE
:
812 case NL80211_CMD_DISASSOCIATE
:
813 mlme_event(drv
, gnlh
->cmd
, tb
[NL80211_ATTR_FRAME
],
814 tb
[NL80211_ATTR_MAC
], tb
[NL80211_ATTR_TIMED_OUT
]);
816 case NL80211_CMD_CONNECT
:
817 case NL80211_CMD_ROAM
:
818 mlme_event_connect(drv
, gnlh
->cmd
,
819 tb
[NL80211_ATTR_STATUS_CODE
],
820 tb
[NL80211_ATTR_MAC
],
821 tb
[NL80211_ATTR_REQ_IE
],
822 tb
[NL80211_ATTR_RESP_IE
]);
824 case NL80211_CMD_DISCONNECT
:
825 if (drv
->capa
.flags
& WPA_DRIVER_FLAGS_SME
) {
827 * Avoid reporting two disassociation events that could
828 * confuse the core code.
830 wpa_printf(MSG_DEBUG
, "nl80211: Ignore disconnect "
831 "event when using userspace SME");
835 wpa_supplicant_event(drv
->ctx
, EVENT_DISASSOC
, NULL
);
837 case NL80211_CMD_MICHAEL_MIC_FAILURE
:
838 mlme_event_michael_mic_failure(drv
, tb
);
840 case NL80211_CMD_JOIN_IBSS
:
841 mlme_event_join_ibss(drv
, tb
);
843 case NL80211_CMD_REMAIN_ON_CHANNEL
:
844 mlme_event_remain_on_channel(drv
, 0, tb
);
846 case NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL
:
847 mlme_event_remain_on_channel(drv
, 1, tb
);
850 wpa_printf(MSG_DEBUG
, "nl80211: Ignored unknown event "
851 "(cmd=%d)", gnlh
->cmd
);
859 static void wpa_driver_nl80211_event_receive(int sock
, void *eloop_ctx
,
863 struct wpa_driver_nl80211_data
*drv
= eloop_ctx
;
865 wpa_printf(MSG_DEBUG
, "nl80211: Event message available");
867 cb
= nl_cb_clone(drv
->nl_cb
);
870 nl_cb_set(cb
, NL_CB_SEQ_CHECK
, NL_CB_CUSTOM
, no_seq_check
, NULL
);
871 nl_cb_set(cb
, NL_CB_VALID
, NL_CB_CUSTOM
, process_event
, drv
);
872 nl_recvmsgs(drv
->nl_handle_event
, cb
);
878 * wpa_driver_nl80211_set_country - ask nl80211 to set the regulatory domain
879 * @priv: driver_nl80211 private data
880 * @alpha2_arg: country to which to switch to
881 * Returns: 0 on success, -1 on failure
883 * This asks nl80211 to set the regulatory domain for given
884 * country ISO / IEC alpha2.
886 static int wpa_driver_nl80211_set_country(void *priv
, const char *alpha2_arg
)
888 struct wpa_driver_nl80211_data
*drv
= priv
;
896 alpha2
[0] = alpha2_arg
[0];
897 alpha2
[1] = alpha2_arg
[1];
900 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
901 0, NL80211_CMD_REQ_SET_REG
, 0);
903 NLA_PUT_STRING(msg
, NL80211_ATTR_REG_ALPHA2
, alpha2
);
904 if (send_and_recv_msgs(drv
, msg
, NULL
, NULL
))
913 struct wiphy_info_data
{
917 int connect_supported
;
921 static int wiphy_info_handler(struct nl_msg
*msg
, void *arg
)
923 struct nlattr
*tb
[NL80211_ATTR_MAX
+ 1];
924 struct genlmsghdr
*gnlh
= nlmsg_data(nlmsg_hdr(msg
));
925 struct wiphy_info_data
*info
= arg
;
927 nla_parse(tb
, NL80211_ATTR_MAX
, genlmsg_attrdata(gnlh
, 0),
928 genlmsg_attrlen(gnlh
, 0), NULL
);
930 if (tb
[NL80211_ATTR_MAX_NUM_SCAN_SSIDS
])
931 info
->max_scan_ssids
=
932 nla_get_u8(tb
[NL80211_ATTR_MAX_NUM_SCAN_SSIDS
]);
934 if (tb
[NL80211_ATTR_SUPPORTED_IFTYPES
]) {
935 struct nlattr
*nl_mode
;
937 nla_for_each_nested(nl_mode
,
938 tb
[NL80211_ATTR_SUPPORTED_IFTYPES
], i
) {
939 if (nl_mode
->nla_type
== NL80211_IFTYPE_AP
) {
940 info
->ap_supported
= 1;
946 if (tb
[NL80211_ATTR_SUPPORTED_COMMANDS
]) {
947 struct nlattr
*nl_cmd
;
950 nla_for_each_nested(nl_cmd
,
951 tb
[NL80211_ATTR_SUPPORTED_COMMANDS
], i
) {
952 u32 cmd
= nla_get_u32(nl_cmd
);
953 if (cmd
== NL80211_CMD_AUTHENTICATE
)
954 info
->auth_supported
= 1;
955 else if (cmd
== NL80211_CMD_CONNECT
)
956 info
->connect_supported
= 1;
964 static int wpa_driver_nl80211_get_info(struct wpa_driver_nl80211_data
*drv
,
965 struct wiphy_info_data
*info
)
969 os_memset(info
, 0, sizeof(*info
));
974 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
975 0, NL80211_CMD_GET_WIPHY
, 0);
977 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
979 if (send_and_recv_msgs(drv
, msg
, wiphy_info_handler
, info
) == 0)
988 static int wpa_driver_nl80211_capa(struct wpa_driver_nl80211_data
*drv
)
990 struct wiphy_info_data info
;
991 if (wpa_driver_nl80211_get_info(drv
, &info
))
993 drv
->has_capability
= 1;
994 /* For now, assume TKIP, CCMP, WPA, WPA2 are supported */
995 drv
->capa
.key_mgmt
= WPA_DRIVER_CAPA_KEY_MGMT_WPA
|
996 WPA_DRIVER_CAPA_KEY_MGMT_WPA_PSK
|
997 WPA_DRIVER_CAPA_KEY_MGMT_WPA2
|
998 WPA_DRIVER_CAPA_KEY_MGMT_WPA2_PSK
;
999 drv
->capa
.enc
= WPA_DRIVER_CAPA_ENC_WEP40
|
1000 WPA_DRIVER_CAPA_ENC_WEP104
|
1001 WPA_DRIVER_CAPA_ENC_TKIP
|
1002 WPA_DRIVER_CAPA_ENC_CCMP
;
1003 drv
->capa
.auth
= WPA_DRIVER_AUTH_OPEN
|
1004 WPA_DRIVER_AUTH_SHARED
|
1005 WPA_DRIVER_AUTH_LEAP
;
1007 drv
->capa
.max_scan_ssids
= info
.max_scan_ssids
;
1008 if (info
.ap_supported
)
1009 drv
->capa
.flags
|= WPA_DRIVER_FLAGS_AP
;
1011 if (info
.auth_supported
)
1012 drv
->capa
.flags
|= WPA_DRIVER_FLAGS_SME
;
1013 else if (!info
.connect_supported
) {
1014 wpa_printf(MSG_INFO
, "nl80211: Driver does not support "
1015 "authentication/association or connect commands");
1019 drv
->capa
.flags
|= WPA_DRIVER_FLAGS_SET_KEYS_AFTER_ASSOC_DONE
;
1023 #endif /* HOSTAPD */
1026 static int wpa_driver_nl80211_init_nl(struct wpa_driver_nl80211_data
*drv
,
1031 /* Initialize generic netlink and nl80211 */
1033 drv
->nl_cb
= nl_cb_alloc(NL_CB_DEFAULT
);
1034 if (drv
->nl_cb
== NULL
) {
1035 wpa_printf(MSG_ERROR
, "nl80211: Failed to allocate netlink "
1040 drv
->nl_handle
= nl_handle_alloc_cb(drv
->nl_cb
);
1041 if (drv
->nl_handle
== NULL
) {
1042 wpa_printf(MSG_ERROR
, "nl80211: Failed to allocate netlink "
1047 drv
->nl_handle_event
= nl_handle_alloc_cb(drv
->nl_cb
);
1048 if (drv
->nl_handle_event
== NULL
) {
1049 wpa_printf(MSG_ERROR
, "nl80211: Failed to allocate netlink "
1050 "callbacks (event)");
1054 if (genl_connect(drv
->nl_handle
)) {
1055 wpa_printf(MSG_ERROR
, "nl80211: Failed to connect to generic "
1060 if (genl_connect(drv
->nl_handle_event
)) {
1061 wpa_printf(MSG_ERROR
, "nl80211: Failed to connect to generic "
1066 #ifdef CONFIG_LIBNL20
1067 if (genl_ctrl_alloc_cache(drv
->nl_handle
, &drv
->nl_cache
) < 0) {
1068 wpa_printf(MSG_ERROR
, "nl80211: Failed to allocate generic "
1072 if (genl_ctrl_alloc_cache(drv
->nl_handle_event
, &drv
->nl_cache_event
) <
1074 wpa_printf(MSG_ERROR
, "nl80211: Failed to allocate generic "
1075 "netlink cache (event)");
1078 #else /* CONFIG_LIBNL20 */
1079 drv
->nl_cache
= genl_ctrl_alloc_cache(drv
->nl_handle
);
1080 if (drv
->nl_cache
== NULL
) {
1081 wpa_printf(MSG_ERROR
, "nl80211: Failed to allocate generic "
1085 drv
->nl_cache_event
= genl_ctrl_alloc_cache(drv
->nl_handle_event
);
1086 if (drv
->nl_cache_event
== NULL
) {
1087 wpa_printf(MSG_ERROR
, "nl80211: Failed to allocate generic "
1088 "netlink cache (event)");
1091 #endif /* CONFIG_LIBNL20 */
1093 drv
->nl80211
= genl_ctrl_search_by_name(drv
->nl_cache
, "nl80211");
1094 if (drv
->nl80211
== NULL
) {
1095 wpa_printf(MSG_ERROR
, "nl80211: 'nl80211' generic netlink not "
1100 ret
= nl_get_multicast_id(drv
, "nl80211", "scan");
1102 ret
= nl_socket_add_membership(drv
->nl_handle_event
, ret
);
1104 wpa_printf(MSG_ERROR
, "nl80211: Could not add multicast "
1105 "membership for scan events: %d (%s)",
1106 ret
, strerror(-ret
));
1110 ret
= nl_get_multicast_id(drv
, "nl80211", "mlme");
1112 ret
= nl_socket_add_membership(drv
->nl_handle_event
, ret
);
1114 wpa_printf(MSG_ERROR
, "nl80211: Could not add multicast "
1115 "membership for mlme events: %d (%s)",
1116 ret
, strerror(-ret
));
1120 eloop_register_read_sock(nl_socket_get_fd(drv
->nl_handle_event
),
1121 wpa_driver_nl80211_event_receive
, drv
, ctx
);
1126 nl_cache_free(drv
->nl_cache_event
);
1128 nl_cache_free(drv
->nl_cache
);
1130 nl_handle_destroy(drv
->nl_handle_event
);
1132 nl_handle_destroy(drv
->nl_handle
);
1134 nl_cb_put(drv
->nl_cb
);
1141 * wpa_driver_nl80211_init - Initialize nl80211 driver interface
1142 * @ctx: context to be used when calling wpa_supplicant functions,
1143 * e.g., wpa_supplicant_event()
1144 * @ifname: interface name, e.g., wlan0
1145 * Returns: Pointer to private data, %NULL on failure
1147 static void * wpa_driver_nl80211_init(void *ctx
, const char *ifname
)
1149 struct wpa_driver_nl80211_data
*drv
;
1150 struct netlink_config
*cfg
;
1152 drv
= os_zalloc(sizeof(*drv
));
1156 os_strlcpy(drv
->ifname
, ifname
, sizeof(drv
->ifname
));
1157 drv
->monitor_ifidx
= -1;
1158 drv
->monitor_sock
= -1;
1159 drv
->ioctl_sock
= -1;
1161 if (wpa_driver_nl80211_init_nl(drv
, ctx
)) {
1166 drv
->ioctl_sock
= socket(PF_INET
, SOCK_DGRAM
, 0);
1167 if (drv
->ioctl_sock
< 0) {
1168 perror("socket(PF_INET,SOCK_DGRAM)");
1172 cfg
= os_zalloc(sizeof(*cfg
));
1176 cfg
->newlink_cb
= wpa_driver_nl80211_event_rtm_newlink
;
1177 cfg
->dellink_cb
= wpa_driver_nl80211_event_rtm_dellink
;
1178 drv
->netlink
= netlink_init(cfg
);
1179 if (drv
->netlink
== NULL
) {
1183 if (wpa_driver_nl80211_finish_drv_init(drv
))
1189 netlink_deinit(drv
->netlink
);
1190 if (drv
->ioctl_sock
>= 0)
1191 close(drv
->ioctl_sock
);
1193 genl_family_put(drv
->nl80211
);
1194 nl_cache_free(drv
->nl_cache
);
1195 nl_handle_destroy(drv
->nl_handle
);
1196 nl_cb_put(drv
->nl_cb
);
1204 wpa_driver_nl80211_finish_drv_init(struct wpa_driver_nl80211_data
*drv
)
1206 drv
->ifindex
= if_nametoindex(drv
->ifname
);
1209 if (wpa_driver_nl80211_set_mode(drv
, IEEE80211_MODE_INFRA
) < 0) {
1210 wpa_printf(MSG_DEBUG
, "nl80211: Could not configure driver to "
1211 "use managed mode");
1214 if (linux_set_iface_flags(drv
->ioctl_sock
, drv
->ifname
, 1)) {
1215 wpa_printf(MSG_ERROR
, "Could not set interface '%s' UP",
1220 if (wpa_driver_nl80211_capa(drv
))
1223 netlink_send_oper_ifla(drv
->netlink
, drv
->ifindex
,
1224 1, IF_OPER_DORMANT
);
1225 #endif /* HOSTAPD */
1232 static void wpa_driver_nl80211_free_bss(struct wpa_driver_nl80211_data
*drv
)
1234 struct i802_bss
*bss
, *prev
;
1235 bss
= drv
->bss
.next
;
1242 #endif /* HOSTAPD */
1245 static int wpa_driver_nl80211_del_beacon(struct wpa_driver_nl80211_data
*drv
)
1249 msg
= nlmsg_alloc();
1253 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
1254 0, NL80211_CMD_DEL_BEACON
, 0);
1255 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
1257 return send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
1264 * wpa_driver_nl80211_deinit - Deinitialize nl80211 driver interface
1265 * @priv: Pointer to private nl80211 data from wpa_driver_nl80211_init()
1267 * Shut down driver interface and processing of driver events. Free
1268 * private data buffer if one was allocated in wpa_driver_nl80211_init().
1270 static void wpa_driver_nl80211_deinit(void *priv
)
1272 struct wpa_driver_nl80211_data
*drv
= priv
;
1274 nl80211_remove_monitor_interface(drv
);
1276 if (drv
->nlmode
== NL80211_IFTYPE_AP
)
1277 wpa_driver_nl80211_del_beacon(drv
);
1280 if (drv
->last_freq_ht
) {
1281 /* Clear HT flags from the driver */
1282 struct hostapd_freq_params freq
;
1283 os_memset(&freq
, 0, sizeof(freq
));
1284 freq
.freq
= drv
->last_freq
;
1285 i802_set_freq(priv
, &freq
);
1288 if (drv
->eapol_sock
>= 0) {
1289 eloop_unregister_read_sock(drv
->eapol_sock
);
1290 close(drv
->eapol_sock
);
1293 if (drv
->if_indices
!= drv
->default_if_indices
)
1294 os_free(drv
->if_indices
);
1296 wpa_driver_nl80211_free_bss(drv
);
1297 #endif /* HOSTAPD */
1299 if (drv
->disable_11b_rates
)
1300 nl80211_disable_11b_rates(drv
, drv
->ifindex
, 0);
1302 netlink_send_oper_ifla(drv
->netlink
, drv
->ifindex
, 0, IF_OPER_UP
);
1303 netlink_deinit(drv
->netlink
);
1305 eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout
, drv
, drv
->ctx
);
1307 (void) linux_set_iface_flags(drv
->ioctl_sock
, drv
->ifname
, 0);
1308 wpa_driver_nl80211_set_mode(drv
, IEEE80211_MODE_INFRA
);
1310 if (drv
->ioctl_sock
>= 0)
1311 close(drv
->ioctl_sock
);
1313 eloop_unregister_read_sock(nl_socket_get_fd(drv
->nl_handle_event
));
1314 genl_family_put(drv
->nl80211
);
1315 nl_cache_free(drv
->nl_cache
);
1316 nl_cache_free(drv
->nl_cache_event
);
1317 nl_handle_destroy(drv
->nl_handle
);
1318 nl_handle_destroy(drv
->nl_handle_event
);
1319 nl_cb_put(drv
->nl_cb
);
1321 eloop_cancel_timeout(wpa_driver_nl80211_probe_req_report_timeout
,
1329 * wpa_driver_nl80211_scan_timeout - Scan timeout to report scan completion
1330 * @eloop_ctx: Driver private data
1331 * @timeout_ctx: ctx argument given to wpa_driver_nl80211_init()
1333 * This function can be used as registered timeout when starting a scan to
1334 * generate a scan completed event if the driver does not report this.
1336 static void wpa_driver_nl80211_scan_timeout(void *eloop_ctx
, void *timeout_ctx
)
1338 struct wpa_driver_nl80211_data
*drv
= eloop_ctx
;
1339 if (drv
->ap_scan_as_station
) {
1340 wpa_driver_nl80211_set_mode(drv
, IEEE80211_MODE_AP
);
1341 drv
->ap_scan_as_station
= 0;
1343 wpa_printf(MSG_DEBUG
, "Scan timeout - try to get results");
1344 wpa_supplicant_event(timeout_ctx
, EVENT_SCAN_RESULTS
, NULL
);
1349 * wpa_driver_nl80211_scan - Request the driver to initiate scan
1350 * @priv: Pointer to private driver data from wpa_driver_nl80211_init()
1351 * @params: Scan parameters
1352 * Returns: 0 on success, -1 on failure
1354 static int wpa_driver_nl80211_scan(void *priv
,
1355 struct wpa_driver_scan_params
*params
)
1357 struct wpa_driver_nl80211_data
*drv
= priv
;
1358 int ret
= 0, timeout
;
1359 struct nl_msg
*msg
, *ssids
, *freqs
;
1362 msg
= nlmsg_alloc();
1363 ssids
= nlmsg_alloc();
1364 freqs
= nlmsg_alloc();
1365 if (!msg
|| !ssids
|| !freqs
) {
1372 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0, 0,
1373 NL80211_CMD_TRIGGER_SCAN
, 0);
1375 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
1377 for (i
= 0; i
< params
->num_ssids
; i
++) {
1378 NLA_PUT(ssids
, i
+ 1, params
->ssids
[i
].ssid_len
,
1379 params
->ssids
[i
].ssid
);
1381 if (params
->num_ssids
)
1382 nla_put_nested(msg
, NL80211_ATTR_SCAN_SSIDS
, ssids
);
1384 if (params
->extra_ies
) {
1385 NLA_PUT(msg
, NL80211_ATTR_IE
, params
->extra_ies_len
,
1389 if (params
->freqs
) {
1390 for (i
= 0; params
->freqs
[i
]; i
++)
1391 NLA_PUT_U32(freqs
, i
+ 1, params
->freqs
[i
]);
1392 nla_put_nested(msg
, NL80211_ATTR_SCAN_FREQUENCIES
, freqs
);
1395 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
1398 wpa_printf(MSG_DEBUG
, "nl80211: Scan trigger failed: ret=%d "
1399 "(%s)", ret
, strerror(-ret
));
1401 if (drv
->nlmode
== NL80211_IFTYPE_AP
) {
1403 * mac80211 does not allow scan requests in AP mode, so
1404 * try to do this in station mode.
1406 if (wpa_driver_nl80211_set_mode(drv
,
1407 IEEE80211_MODE_INFRA
))
1408 goto nla_put_failure
;
1410 if (wpa_driver_nl80211_scan(drv
, params
)) {
1411 wpa_driver_nl80211_set_mode(drv
,
1413 goto nla_put_failure
;
1416 /* Restore AP mode when processing scan results */
1417 drv
->ap_scan_as_station
= 1;
1420 goto nla_put_failure
;
1422 goto nla_put_failure
;
1423 #endif /* HOSTAPD */
1426 /* Not all drivers generate "scan completed" wireless event, so try to
1427 * read results after a timeout. */
1429 if (drv
->scan_complete_events
) {
1431 * The driver seems to deliver events to notify when scan is
1432 * complete, so use longer timeout to avoid race conditions
1433 * with scanning and following association request.
1437 wpa_printf(MSG_DEBUG
, "Scan requested (ret=%d) - scan timeout %d "
1438 "seconds", ret
, timeout
);
1439 eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout
, drv
, drv
->ctx
);
1440 eloop_register_timeout(timeout
, 0, wpa_driver_nl80211_scan_timeout
,
1451 static int bss_info_handler(struct nl_msg
*msg
, void *arg
)
1453 struct nlattr
*tb
[NL80211_ATTR_MAX
+ 1];
1454 struct genlmsghdr
*gnlh
= nlmsg_data(nlmsg_hdr(msg
));
1455 struct nlattr
*bss
[NL80211_BSS_MAX
+ 1];
1456 static struct nla_policy bss_policy
[NL80211_BSS_MAX
+ 1] = {
1457 [NL80211_BSS_BSSID
] = { .type
= NLA_UNSPEC
},
1458 [NL80211_BSS_FREQUENCY
] = { .type
= NLA_U32
},
1459 [NL80211_BSS_TSF
] = { .type
= NLA_U64
},
1460 [NL80211_BSS_BEACON_INTERVAL
] = { .type
= NLA_U16
},
1461 [NL80211_BSS_CAPABILITY
] = { .type
= NLA_U16
},
1462 [NL80211_BSS_INFORMATION_ELEMENTS
] = { .type
= NLA_UNSPEC
},
1463 [NL80211_BSS_SIGNAL_MBM
] = { .type
= NLA_U32
},
1464 [NL80211_BSS_SIGNAL_UNSPEC
] = { .type
= NLA_U8
},
1465 [NL80211_BSS_STATUS
] = { .type
= NLA_U32
},
1466 [NL80211_BSS_SEEN_MS_AGO
] = { .type
= NLA_U32
},
1468 struct wpa_scan_results
*res
= arg
;
1469 struct wpa_scan_res
**tmp
;
1470 struct wpa_scan_res
*r
;
1474 nla_parse(tb
, NL80211_ATTR_MAX
, genlmsg_attrdata(gnlh
, 0),
1475 genlmsg_attrlen(gnlh
, 0), NULL
);
1476 if (!tb
[NL80211_ATTR_BSS
])
1478 if (nla_parse_nested(bss
, NL80211_BSS_MAX
, tb
[NL80211_ATTR_BSS
],
1481 if (bss
[NL80211_BSS_INFORMATION_ELEMENTS
]) {
1482 ie
= nla_data(bss
[NL80211_BSS_INFORMATION_ELEMENTS
]);
1483 ie_len
= nla_len(bss
[NL80211_BSS_INFORMATION_ELEMENTS
]);
1489 r
= os_zalloc(sizeof(*r
) + ie_len
);
1492 if (bss
[NL80211_BSS_BSSID
])
1493 os_memcpy(r
->bssid
, nla_data(bss
[NL80211_BSS_BSSID
]),
1495 if (bss
[NL80211_BSS_FREQUENCY
])
1496 r
->freq
= nla_get_u32(bss
[NL80211_BSS_FREQUENCY
]);
1497 if (bss
[NL80211_BSS_BEACON_INTERVAL
])
1498 r
->beacon_int
= nla_get_u16(bss
[NL80211_BSS_BEACON_INTERVAL
]);
1499 if (bss
[NL80211_BSS_CAPABILITY
])
1500 r
->caps
= nla_get_u16(bss
[NL80211_BSS_CAPABILITY
]);
1501 r
->flags
|= WPA_SCAN_NOISE_INVALID
;
1502 if (bss
[NL80211_BSS_SIGNAL_MBM
]) {
1503 r
->level
= nla_get_u32(bss
[NL80211_BSS_SIGNAL_MBM
]);
1504 r
->level
/= 100; /* mBm to dBm */
1505 r
->flags
|= WPA_SCAN_LEVEL_DBM
| WPA_SCAN_QUAL_INVALID
;
1506 } else if (bss
[NL80211_BSS_SIGNAL_UNSPEC
]) {
1507 r
->level
= nla_get_u8(bss
[NL80211_BSS_SIGNAL_UNSPEC
]);
1508 r
->flags
|= WPA_SCAN_LEVEL_INVALID
;
1510 r
->flags
|= WPA_SCAN_LEVEL_INVALID
| WPA_SCAN_QUAL_INVALID
;
1511 if (bss
[NL80211_BSS_TSF
])
1512 r
->tsf
= nla_get_u64(bss
[NL80211_BSS_TSF
]);
1513 if (bss
[NL80211_BSS_SEEN_MS_AGO
])
1514 r
->age
= nla_get_u32(bss
[NL80211_BSS_SEEN_MS_AGO
]);
1517 os_memcpy(r
+ 1, ie
, ie_len
);
1519 if (bss
[NL80211_BSS_STATUS
]) {
1520 enum nl80211_bss_status status
;
1521 status
= nla_get_u32(bss
[NL80211_BSS_STATUS
]);
1523 case NL80211_BSS_STATUS_AUTHENTICATED
:
1524 r
->flags
|= WPA_SCAN_AUTHENTICATED
;
1526 case NL80211_BSS_STATUS_ASSOCIATED
:
1527 r
->flags
|= WPA_SCAN_ASSOCIATED
;
1534 tmp
= os_realloc(res
->res
,
1535 (res
->num
+ 1) * sizeof(struct wpa_scan_res
*));
1540 tmp
[res
->num
++] = r
;
1547 static void clear_state_mismatch(struct wpa_driver_nl80211_data
*drv
,
1550 if (drv
->capa
.flags
& WPA_DRIVER_FLAGS_SME
) {
1551 wpa_printf(MSG_DEBUG
, "nl80211: Clear possible state "
1553 wpa_driver_nl80211_mlme(drv
, addr
,
1554 NL80211_CMD_DEAUTHENTICATE
,
1555 WLAN_REASON_PREV_AUTH_NOT_VALID
);
1560 static void wpa_driver_nl80211_check_bss_status(
1561 struct wpa_driver_nl80211_data
*drv
, struct wpa_scan_results
*res
)
1565 for (i
= 0; i
< res
->num
; i
++) {
1566 struct wpa_scan_res
*r
= res
->res
[i
];
1567 if (r
->flags
& WPA_SCAN_AUTHENTICATED
) {
1568 wpa_printf(MSG_DEBUG
, "nl80211: Scan results "
1569 "indicates BSS status with " MACSTR
1570 " as authenticated",
1572 if (drv
->nlmode
== NL80211_IFTYPE_STATION
&&
1573 os_memcmp(r
->bssid
, drv
->bssid
, ETH_ALEN
) != 0 &&
1574 os_memcmp(r
->bssid
, drv
->auth_bssid
, ETH_ALEN
) !=
1576 wpa_printf(MSG_DEBUG
, "nl80211: Unknown BSSID"
1577 " in local state (auth=" MACSTR
1578 " assoc=" MACSTR
")",
1579 MAC2STR(drv
->auth_bssid
),
1580 MAC2STR(drv
->bssid
));
1584 if (r
->flags
& WPA_SCAN_ASSOCIATED
) {
1585 wpa_printf(MSG_DEBUG
, "nl80211: Scan results "
1586 "indicate BSS status with " MACSTR
1589 if (drv
->nlmode
== NL80211_IFTYPE_STATION
&&
1591 wpa_printf(MSG_DEBUG
, "nl80211: Local state "
1592 "(not associated) does not match "
1594 clear_state_mismatch(drv
, r
->bssid
);
1595 } else if (drv
->nlmode
== NL80211_IFTYPE_STATION
&&
1596 os_memcmp(drv
->bssid
, r
->bssid
, ETH_ALEN
) !=
1598 wpa_printf(MSG_DEBUG
, "nl80211: Local state "
1599 "(associated with " MACSTR
") does "
1600 "not match with BSS state",
1601 MAC2STR(drv
->bssid
));
1602 clear_state_mismatch(drv
, r
->bssid
);
1603 clear_state_mismatch(drv
, drv
->bssid
);
1610 static void wpa_scan_results_free(struct wpa_scan_results
*res
)
1617 for (i
= 0; i
< res
->num
; i
++)
1618 os_free(res
->res
[i
]);
1625 * wpa_driver_nl80211_get_scan_results - Fetch the latest scan results
1626 * @priv: Pointer to private wext data from wpa_driver_nl80211_init()
1627 * Returns: Scan results on success, -1 on failure
1629 static struct wpa_scan_results
*
1630 wpa_driver_nl80211_get_scan_results(void *priv
)
1632 struct wpa_driver_nl80211_data
*drv
= priv
;
1634 struct wpa_scan_results
*res
;
1637 res
= os_zalloc(sizeof(*res
));
1640 msg
= nlmsg_alloc();
1642 goto nla_put_failure
;
1644 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0, NLM_F_DUMP
,
1645 NL80211_CMD_GET_SCAN
, 0);
1646 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
1648 ret
= send_and_recv_msgs(drv
, msg
, bss_info_handler
, res
);
1651 wpa_printf(MSG_DEBUG
, "Received scan results (%lu BSSes)",
1652 (unsigned long) res
->num
);
1653 wpa_driver_nl80211_check_bss_status(drv
, res
);
1656 wpa_printf(MSG_DEBUG
, "nl80211: Scan result fetch failed: ret=%d "
1657 "(%s)", ret
, strerror(-ret
));
1660 wpa_scan_results_free(res
);
1665 static int wpa_driver_nl80211_set_key(const char *ifname
, void *priv
,
1666 enum wpa_alg alg
, const u8
*addr
,
1667 int key_idx
, int set_tx
,
1668 const u8
*seq
, size_t seq_len
,
1669 const u8
*key
, size_t key_len
)
1671 struct wpa_driver_nl80211_data
*drv
= priv
;
1672 int ifindex
= if_nametoindex(ifname
);
1676 wpa_printf(MSG_DEBUG
, "%s: ifindex=%d alg=%d addr=%p key_idx=%d "
1677 "set_tx=%d seq_len=%lu key_len=%lu",
1678 __func__
, ifindex
, alg
, addr
, key_idx
, set_tx
,
1679 (unsigned long) seq_len
, (unsigned long) key_len
);
1681 msg
= nlmsg_alloc();
1685 if (alg
== WPA_ALG_NONE
) {
1686 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
1687 0, NL80211_CMD_DEL_KEY
, 0);
1689 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
1690 0, NL80211_CMD_NEW_KEY
, 0);
1691 NLA_PUT(msg
, NL80211_ATTR_KEY_DATA
, key_len
, key
);
1695 NLA_PUT_U32(msg
, NL80211_ATTR_KEY_CIPHER
,
1696 WLAN_CIPHER_SUITE_WEP40
);
1698 NLA_PUT_U32(msg
, NL80211_ATTR_KEY_CIPHER
,
1699 WLAN_CIPHER_SUITE_WEP104
);
1702 NLA_PUT_U32(msg
, NL80211_ATTR_KEY_CIPHER
,
1703 WLAN_CIPHER_SUITE_TKIP
);
1706 NLA_PUT_U32(msg
, NL80211_ATTR_KEY_CIPHER
,
1707 WLAN_CIPHER_SUITE_CCMP
);
1710 NLA_PUT_U32(msg
, NL80211_ATTR_KEY_CIPHER
,
1711 WLAN_CIPHER_SUITE_AES_CMAC
);
1714 wpa_printf(MSG_ERROR
, "%s: Unsupported encryption "
1715 "algorithm %d", __func__
, alg
);
1722 NLA_PUT(msg
, NL80211_ATTR_KEY_SEQ
, seq_len
, seq
);
1724 if (addr
&& os_memcmp(addr
, "\xff\xff\xff\xff\xff\xff", ETH_ALEN
) != 0)
1726 wpa_printf(MSG_DEBUG
, " addr=" MACSTR
, MAC2STR(addr
));
1727 NLA_PUT(msg
, NL80211_ATTR_MAC
, ETH_ALEN
, addr
);
1729 NLA_PUT_U8(msg
, NL80211_ATTR_KEY_IDX
, key_idx
);
1730 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, ifindex
);
1732 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
1733 if (ret
== -ENOENT
&& alg
== WPA_ALG_NONE
)
1736 wpa_printf(MSG_DEBUG
, "nl80211: set_key failed; err=%d %s)",
1737 ret
, strerror(-ret
));
1740 * If we failed or don't need to set the default TX key (below),
1743 if (ret
|| !set_tx
|| alg
== WPA_ALG_NONE
)
1745 #ifdef HOSTAPD /* FIX: is this needed? */
1748 #endif /* HOSTAPD */
1750 msg
= nlmsg_alloc();
1754 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
1755 0, NL80211_CMD_SET_KEY
, 0);
1756 NLA_PUT_U8(msg
, NL80211_ATTR_KEY_IDX
, key_idx
);
1757 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, ifindex
);
1758 if (alg
== WPA_ALG_IGTK
)
1759 NLA_PUT_FLAG(msg
, NL80211_ATTR_KEY_DEFAULT_MGMT
);
1761 NLA_PUT_FLAG(msg
, NL80211_ATTR_KEY_DEFAULT
);
1763 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
1767 wpa_printf(MSG_DEBUG
, "nl80211: set_key default failed; "
1768 "err=%d %s)", ret
, strerror(-ret
));
1776 static int nl_add_key(struct nl_msg
*msg
, enum wpa_alg alg
,
1777 int key_idx
, int defkey
,
1778 const u8
*seq
, size_t seq_len
,
1779 const u8
*key
, size_t key_len
)
1781 struct nlattr
*key_attr
= nla_nest_start(msg
, NL80211_ATTR_KEY
);
1785 if (defkey
&& alg
== WPA_ALG_IGTK
)
1786 NLA_PUT_FLAG(msg
, NL80211_KEY_DEFAULT_MGMT
);
1788 NLA_PUT_FLAG(msg
, NL80211_KEY_DEFAULT
);
1790 NLA_PUT_U8(msg
, NL80211_KEY_IDX
, key_idx
);
1795 NLA_PUT_U32(msg
, NL80211_KEY_CIPHER
,
1796 WLAN_CIPHER_SUITE_WEP40
);
1798 NLA_PUT_U32(msg
, NL80211_KEY_CIPHER
,
1799 WLAN_CIPHER_SUITE_WEP104
);
1802 NLA_PUT_U32(msg
, NL80211_KEY_CIPHER
, WLAN_CIPHER_SUITE_TKIP
);
1805 NLA_PUT_U32(msg
, NL80211_KEY_CIPHER
, WLAN_CIPHER_SUITE_CCMP
);
1808 NLA_PUT_U32(msg
, NL80211_KEY_CIPHER
,
1809 WLAN_CIPHER_SUITE_AES_CMAC
);
1812 wpa_printf(MSG_ERROR
, "%s: Unsupported encryption "
1813 "algorithm %d", __func__
, alg
);
1818 NLA_PUT(msg
, NL80211_KEY_SEQ
, seq_len
, seq
);
1820 NLA_PUT(msg
, NL80211_KEY_DATA
, key_len
, key
);
1822 nla_nest_end(msg
, key_attr
);
1830 static int nl80211_set_conn_keys(struct wpa_driver_associate_params
*params
,
1834 struct nlattr
*nl_keys
, *nl_key
;
1836 for (i
= 0; i
< 4; i
++) {
1837 if (!params
->wep_key
[i
])
1845 NLA_PUT_FLAG(msg
, NL80211_ATTR_PRIVACY
);
1847 nl_keys
= nla_nest_start(msg
, NL80211_ATTR_KEYS
);
1849 goto nla_put_failure
;
1851 for (i
= 0; i
< 4; i
++) {
1852 if (!params
->wep_key
[i
])
1855 nl_key
= nla_nest_start(msg
, i
);
1857 goto nla_put_failure
;
1859 NLA_PUT(msg
, NL80211_KEY_DATA
, params
->wep_key_len
[i
],
1860 params
->wep_key
[i
]);
1861 if (params
->wep_key_len
[i
] == 5)
1862 NLA_PUT_U32(msg
, NL80211_KEY_CIPHER
,
1863 WLAN_CIPHER_SUITE_WEP40
);
1865 NLA_PUT_U32(msg
, NL80211_KEY_CIPHER
,
1866 WLAN_CIPHER_SUITE_WEP104
);
1868 NLA_PUT_U8(msg
, NL80211_KEY_IDX
, i
);
1870 if (i
== params
->wep_tx_keyidx
)
1871 NLA_PUT_FLAG(msg
, NL80211_KEY_DEFAULT
);
1873 nla_nest_end(msg
, nl_key
);
1875 nla_nest_end(msg
, nl_keys
);
1884 static int wpa_driver_nl80211_mlme(struct wpa_driver_nl80211_data
*drv
,
1885 const u8
*addr
, int cmd
, u16 reason_code
)
1890 msg
= nlmsg_alloc();
1894 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0, 0, cmd
, 0);
1896 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
1897 NLA_PUT_U16(msg
, NL80211_ATTR_REASON_CODE
, reason_code
);
1898 NLA_PUT(msg
, NL80211_ATTR_MAC
, ETH_ALEN
, addr
);
1900 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
1903 wpa_printf(MSG_DEBUG
, "nl80211: MLME command failed: ret=%d "
1904 "(%s)", ret
, strerror(-ret
));
1905 goto nla_put_failure
;
1915 static int wpa_driver_nl80211_disconnect(struct wpa_driver_nl80211_data
*drv
,
1916 const u8
*addr
, int reason_code
)
1918 wpa_printf(MSG_DEBUG
, "%s", __func__
);
1919 drv
->associated
= 0;
1920 return wpa_driver_nl80211_mlme(drv
, addr
, NL80211_CMD_DISCONNECT
,
1925 static int wpa_driver_nl80211_deauthenticate(void *priv
, const u8
*addr
,
1928 struct wpa_driver_nl80211_data
*drv
= priv
;
1929 if (!(drv
->capa
.flags
& WPA_DRIVER_FLAGS_SME
))
1930 return wpa_driver_nl80211_disconnect(drv
, addr
, reason_code
);
1931 wpa_printf(MSG_DEBUG
, "%s", __func__
);
1932 drv
->associated
= 0;
1933 return wpa_driver_nl80211_mlme(drv
, addr
, NL80211_CMD_DEAUTHENTICATE
,
1938 static int wpa_driver_nl80211_disassociate(void *priv
, const u8
*addr
,
1941 struct wpa_driver_nl80211_data
*drv
= priv
;
1942 if (!(drv
->capa
.flags
& WPA_DRIVER_FLAGS_SME
))
1943 return wpa_driver_nl80211_disconnect(drv
, addr
, reason_code
);
1944 wpa_printf(MSG_DEBUG
, "%s", __func__
);
1945 drv
->associated
= 0;
1946 return wpa_driver_nl80211_mlme(drv
, addr
, NL80211_CMD_DISASSOCIATE
,
1951 static int wpa_driver_nl80211_authenticate(
1952 void *priv
, struct wpa_driver_auth_params
*params
)
1954 struct wpa_driver_nl80211_data
*drv
= priv
;
1957 enum nl80211_auth_type type
;
1960 drv
->associated
= 0;
1961 os_memset(drv
->auth_bssid
, 0, ETH_ALEN
);
1963 if (wpa_driver_nl80211_set_mode(drv
, IEEE80211_MODE_INFRA
) < 0)
1967 msg
= nlmsg_alloc();
1971 wpa_printf(MSG_DEBUG
, "nl80211: Authenticate (ifindex=%d)",
1974 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0, 0,
1975 NL80211_CMD_AUTHENTICATE
, 0);
1977 for (i
= 0; i
< 4; i
++) {
1978 if (!params
->wep_key
[i
])
1980 wpa_driver_nl80211_set_key(drv
->ifname
, drv
, WPA_ALG_WEP
, NULL
,
1982 i
== params
->wep_tx_keyidx
, NULL
, 0,
1984 params
->wep_key_len
[i
]);
1985 if (params
->wep_tx_keyidx
!= i
)
1987 if (nl_add_key(msg
, WPA_ALG_WEP
, i
, 1, NULL
, 0,
1988 params
->wep_key
[i
], params
->wep_key_len
[i
])) {
1994 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
1995 if (params
->bssid
) {
1996 wpa_printf(MSG_DEBUG
, " * bssid=" MACSTR
,
1997 MAC2STR(params
->bssid
));
1998 NLA_PUT(msg
, NL80211_ATTR_MAC
, ETH_ALEN
, params
->bssid
);
2001 wpa_printf(MSG_DEBUG
, " * freq=%d", params
->freq
);
2002 NLA_PUT_U32(msg
, NL80211_ATTR_WIPHY_FREQ
, params
->freq
);
2005 wpa_hexdump_ascii(MSG_DEBUG
, " * SSID",
2006 params
->ssid
, params
->ssid_len
);
2007 NLA_PUT(msg
, NL80211_ATTR_SSID
, params
->ssid_len
,
2010 wpa_hexdump(MSG_DEBUG
, " * IEs", params
->ie
, params
->ie_len
);
2012 NLA_PUT(msg
, NL80211_ATTR_IE
, params
->ie_len
, params
->ie
);
2014 * TODO: if multiple auth_alg options enabled, try them one by one if
2015 * the AP rejects authentication due to unknown auth alg
2017 if (params
->auth_alg
& WPA_AUTH_ALG_OPEN
)
2018 type
= NL80211_AUTHTYPE_OPEN_SYSTEM
;
2019 else if (params
->auth_alg
& WPA_AUTH_ALG_SHARED
)
2020 type
= NL80211_AUTHTYPE_SHARED_KEY
;
2021 else if (params
->auth_alg
& WPA_AUTH_ALG_LEAP
)
2022 type
= NL80211_AUTHTYPE_NETWORK_EAP
;
2023 else if (params
->auth_alg
& WPA_AUTH_ALG_FT
)
2024 type
= NL80211_AUTHTYPE_FT
;
2026 goto nla_put_failure
;
2027 wpa_printf(MSG_DEBUG
, " * Auth Type %d", type
);
2028 NLA_PUT_U32(msg
, NL80211_ATTR_AUTH_TYPE
, type
);
2030 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
2033 wpa_printf(MSG_DEBUG
, "nl80211: MLME command failed: ret=%d "
2034 "(%s)", ret
, strerror(-ret
));
2036 if (ret
== -EALREADY
&& count
== 1 && params
->bssid
) {
2038 * mac80211 does not currently accept new
2039 * authentication if we are already authenticated. As a
2040 * workaround, force deauthentication and try again.
2042 wpa_printf(MSG_DEBUG
, "nl80211: Retry authentication "
2043 "after forced deauthentication");
2044 wpa_driver_nl80211_deauthenticate(
2046 WLAN_REASON_PREV_AUTH_NOT_VALID
);
2050 goto nla_put_failure
;
2053 wpa_printf(MSG_DEBUG
, "nl80211: Authentication request send "
2062 struct phy_info_arg
{
2064 struct hostapd_hw_modes
*modes
;
2067 static int phy_info_handler(struct nl_msg
*msg
, void *arg
)
2069 struct nlattr
*tb_msg
[NL80211_ATTR_MAX
+ 1];
2070 struct genlmsghdr
*gnlh
= nlmsg_data(nlmsg_hdr(msg
));
2071 struct phy_info_arg
*phy_info
= arg
;
2073 struct nlattr
*tb_band
[NL80211_BAND_ATTR_MAX
+ 1];
2075 struct nlattr
*tb_freq
[NL80211_FREQUENCY_ATTR_MAX
+ 1];
2076 static struct nla_policy freq_policy
[NL80211_FREQUENCY_ATTR_MAX
+ 1] = {
2077 [NL80211_FREQUENCY_ATTR_FREQ
] = { .type
= NLA_U32
},
2078 [NL80211_FREQUENCY_ATTR_DISABLED
] = { .type
= NLA_FLAG
},
2079 [NL80211_FREQUENCY_ATTR_PASSIVE_SCAN
] = { .type
= NLA_FLAG
},
2080 [NL80211_FREQUENCY_ATTR_NO_IBSS
] = { .type
= NLA_FLAG
},
2081 [NL80211_FREQUENCY_ATTR_RADAR
] = { .type
= NLA_FLAG
},
2082 [NL80211_FREQUENCY_ATTR_MAX_TX_POWER
] = { .type
= NLA_U32
},
2085 struct nlattr
*tb_rate
[NL80211_BITRATE_ATTR_MAX
+ 1];
2086 static struct nla_policy rate_policy
[NL80211_BITRATE_ATTR_MAX
+ 1] = {
2087 [NL80211_BITRATE_ATTR_RATE
] = { .type
= NLA_U32
},
2088 [NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE
] = { .type
= NLA_FLAG
},
2091 struct nlattr
*nl_band
;
2092 struct nlattr
*nl_freq
;
2093 struct nlattr
*nl_rate
;
2094 int rem_band
, rem_freq
, rem_rate
;
2095 struct hostapd_hw_modes
*mode
;
2096 int idx
, mode_is_set
;
2098 nla_parse(tb_msg
, NL80211_ATTR_MAX
, genlmsg_attrdata(gnlh
, 0),
2099 genlmsg_attrlen(gnlh
, 0), NULL
);
2101 if (!tb_msg
[NL80211_ATTR_WIPHY_BANDS
])
2104 nla_for_each_nested(nl_band
, tb_msg
[NL80211_ATTR_WIPHY_BANDS
], rem_band
) {
2105 mode
= os_realloc(phy_info
->modes
, (*phy_info
->num_modes
+ 1) * sizeof(*mode
));
2108 phy_info
->modes
= mode
;
2112 mode
= &phy_info
->modes
[*(phy_info
->num_modes
)];
2113 memset(mode
, 0, sizeof(*mode
));
2114 *(phy_info
->num_modes
) += 1;
2116 nla_parse(tb_band
, NL80211_BAND_ATTR_MAX
, nla_data(nl_band
),
2117 nla_len(nl_band
), NULL
);
2119 if (tb_band
[NL80211_BAND_ATTR_HT_CAPA
]) {
2120 mode
->ht_capab
= nla_get_u16(
2121 tb_band
[NL80211_BAND_ATTR_HT_CAPA
]);
2124 if (tb_band
[NL80211_BAND_ATTR_HT_AMPDU_FACTOR
]) {
2125 mode
->a_mpdu_params
|= nla_get_u8(
2126 tb_band
[NL80211_BAND_ATTR_HT_AMPDU_FACTOR
]) &
2130 if (tb_band
[NL80211_BAND_ATTR_HT_AMPDU_DENSITY
]) {
2131 mode
->a_mpdu_params
|= nla_get_u8(
2132 tb_band
[NL80211_BAND_ATTR_HT_AMPDU_DENSITY
]) <<
2136 if (tb_band
[NL80211_BAND_ATTR_HT_MCS_SET
] &&
2137 nla_len(tb_band
[NL80211_BAND_ATTR_HT_MCS_SET
])) {
2139 mcs
= nla_data(tb_band
[NL80211_BAND_ATTR_HT_MCS_SET
]);
2140 os_memcpy(mode
->mcs_set
, mcs
, 16);
2143 nla_for_each_nested(nl_freq
, tb_band
[NL80211_BAND_ATTR_FREQS
], rem_freq
) {
2144 nla_parse(tb_freq
, NL80211_FREQUENCY_ATTR_MAX
, nla_data(nl_freq
),
2145 nla_len(nl_freq
), freq_policy
);
2146 if (!tb_freq
[NL80211_FREQUENCY_ATTR_FREQ
])
2148 mode
->num_channels
++;
2151 mode
->channels
= os_zalloc(mode
->num_channels
* sizeof(struct hostapd_channel_data
));
2152 if (!mode
->channels
)
2157 nla_for_each_nested(nl_freq
, tb_band
[NL80211_BAND_ATTR_FREQS
], rem_freq
) {
2158 nla_parse(tb_freq
, NL80211_FREQUENCY_ATTR_MAX
, nla_data(nl_freq
),
2159 nla_len(nl_freq
), freq_policy
);
2160 if (!tb_freq
[NL80211_FREQUENCY_ATTR_FREQ
])
2163 mode
->channels
[idx
].freq
= nla_get_u32(tb_freq
[NL80211_FREQUENCY_ATTR_FREQ
]);
2164 mode
->channels
[idx
].flag
= 0;
2167 /* crude heuristic */
2168 if (mode
->channels
[idx
].freq
< 4000)
2169 mode
->mode
= HOSTAPD_MODE_IEEE80211B
;
2171 mode
->mode
= HOSTAPD_MODE_IEEE80211A
;
2175 /* crude heuristic */
2176 if (mode
->channels
[idx
].freq
< 4000)
2177 if (mode
->channels
[idx
].freq
== 2484)
2178 mode
->channels
[idx
].chan
= 14;
2180 mode
->channels
[idx
].chan
= (mode
->channels
[idx
].freq
- 2407) / 5;
2182 mode
->channels
[idx
].chan
= mode
->channels
[idx
].freq
/5 - 1000;
2184 if (tb_freq
[NL80211_FREQUENCY_ATTR_DISABLED
])
2185 mode
->channels
[idx
].flag
|=
2186 HOSTAPD_CHAN_DISABLED
;
2187 if (tb_freq
[NL80211_FREQUENCY_ATTR_PASSIVE_SCAN
])
2188 mode
->channels
[idx
].flag
|=
2189 HOSTAPD_CHAN_PASSIVE_SCAN
;
2190 if (tb_freq
[NL80211_FREQUENCY_ATTR_NO_IBSS
])
2191 mode
->channels
[idx
].flag
|=
2192 HOSTAPD_CHAN_NO_IBSS
;
2193 if (tb_freq
[NL80211_FREQUENCY_ATTR_RADAR
])
2194 mode
->channels
[idx
].flag
|=
2197 if (tb_freq
[NL80211_FREQUENCY_ATTR_MAX_TX_POWER
] &&
2198 !tb_freq
[NL80211_FREQUENCY_ATTR_DISABLED
])
2199 mode
->channels
[idx
].max_tx_power
=
2200 nla_get_u32(tb_freq
[NL80211_FREQUENCY_ATTR_MAX_TX_POWER
]) / 100;
2205 nla_for_each_nested(nl_rate
, tb_band
[NL80211_BAND_ATTR_RATES
], rem_rate
) {
2206 nla_parse(tb_rate
, NL80211_BITRATE_ATTR_MAX
, nla_data(nl_rate
),
2207 nla_len(nl_rate
), rate_policy
);
2208 if (!tb_rate
[NL80211_BITRATE_ATTR_RATE
])
2213 mode
->rates
= os_zalloc(mode
->num_rates
* sizeof(int));
2219 nla_for_each_nested(nl_rate
, tb_band
[NL80211_BAND_ATTR_RATES
], rem_rate
) {
2220 nla_parse(tb_rate
, NL80211_BITRATE_ATTR_MAX
, nla_data(nl_rate
),
2221 nla_len(nl_rate
), rate_policy
);
2222 if (!tb_rate
[NL80211_BITRATE_ATTR_RATE
])
2224 mode
->rates
[idx
] = nla_get_u32(tb_rate
[NL80211_BITRATE_ATTR_RATE
]);
2226 /* crude heuristic */
2227 if (mode
->mode
== HOSTAPD_MODE_IEEE80211B
&&
2228 mode
->rates
[idx
] > 200)
2229 mode
->mode
= HOSTAPD_MODE_IEEE80211G
;
2238 static struct hostapd_hw_modes
*
2239 wpa_driver_nl80211_add_11b(struct hostapd_hw_modes
*modes
, u16
*num_modes
)
2242 struct hostapd_hw_modes
*mode11g
= NULL
, *nmodes
, *mode
;
2243 int i
, mode11g_idx
= -1;
2245 /* If only 802.11g mode is included, use it to construct matching
2246 * 802.11b mode data. */
2248 for (m
= 0; m
< *num_modes
; m
++) {
2249 if (modes
[m
].mode
== HOSTAPD_MODE_IEEE80211B
)
2250 return modes
; /* 802.11b already included */
2251 if (modes
[m
].mode
== HOSTAPD_MODE_IEEE80211G
)
2255 if (mode11g_idx
< 0)
2256 return modes
; /* 2.4 GHz band not supported at all */
2258 nmodes
= os_realloc(modes
, (*num_modes
+ 1) * sizeof(*nmodes
));
2260 return modes
; /* Could not add 802.11b mode */
2262 mode
= &nmodes
[*num_modes
];
2263 os_memset(mode
, 0, sizeof(*mode
));
2267 mode
->mode
= HOSTAPD_MODE_IEEE80211B
;
2269 mode11g
= &modes
[mode11g_idx
];
2270 mode
->num_channels
= mode11g
->num_channels
;
2271 mode
->channels
= os_malloc(mode11g
->num_channels
*
2272 sizeof(struct hostapd_channel_data
));
2273 if (mode
->channels
== NULL
) {
2275 return modes
; /* Could not add 802.11b mode */
2277 os_memcpy(mode
->channels
, mode11g
->channels
,
2278 mode11g
->num_channels
* sizeof(struct hostapd_channel_data
));
2280 mode
->num_rates
= 0;
2281 mode
->rates
= os_malloc(4 * sizeof(int));
2282 if (mode
->rates
== NULL
) {
2283 os_free(mode
->channels
);
2285 return modes
; /* Could not add 802.11b mode */
2288 for (i
= 0; i
< mode11g
->num_rates
; i
++) {
2289 if (mode11g
->rates
[i
] != 10 && mode11g
->rates
[i
] != 20 &&
2290 mode11g
->rates
[i
] != 55 && mode11g
->rates
[i
] != 110)
2292 mode
->rates
[mode
->num_rates
] = mode11g
->rates
[i
];
2294 if (mode
->num_rates
== 4)
2298 if (mode
->num_rates
== 0) {
2299 os_free(mode
->channels
);
2300 os_free(mode
->rates
);
2302 return modes
; /* No 802.11b rates */
2305 wpa_printf(MSG_DEBUG
, "nl80211: Added 802.11b mode based on 802.11g "
2312 static struct hostapd_hw_modes
*
2313 wpa_driver_nl80211_get_hw_feature_data(void *priv
, u16
*num_modes
, u16
*flags
)
2315 struct wpa_driver_nl80211_data
*drv
= priv
;
2317 struct phy_info_arg result
= {
2318 .num_modes
= num_modes
,
2325 msg
= nlmsg_alloc();
2329 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
2330 0, NL80211_CMD_GET_WIPHY
, 0);
2332 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
2334 if (send_and_recv_msgs(drv
, msg
, phy_info_handler
, &result
) == 0)
2335 return wpa_driver_nl80211_add_11b(result
.modes
, num_modes
);
2341 static int wpa_driver_nl80211_send_frame(struct wpa_driver_nl80211_data
*drv
,
2342 const void *data
, size_t len
,
2346 0x00, 0x00, /* radiotap version */
2347 0x0e, 0x00, /* radiotap length */
2348 0x02, 0xc0, 0x00, 0x00, /* bmap: flags, tx and rx flags */
2349 IEEE80211_RADIOTAP_F_FRAG
, /* F_FRAG (fragment if required) */
2351 0x00, 0x00, /* RX and TX flags to indicate that */
2352 0x00, 0x00, /* this is the injected frame directly */
2354 struct iovec iov
[2] = {
2356 .iov_base
= &rtap_hdr
,
2357 .iov_len
= sizeof(rtap_hdr
),
2360 .iov_base
= (void *) data
,
2364 struct msghdr msg
= {
2369 .msg_control
= NULL
,
2370 .msg_controllen
= 0,
2375 rtap_hdr
[8] |= IEEE80211_RADIOTAP_F_WEP
;
2377 return sendmsg(drv
->monitor_sock
, &msg
, 0);
2381 static int wpa_driver_nl80211_send_mlme(void *priv
, const u8
*data
,
2384 struct wpa_driver_nl80211_data
*drv
= priv
;
2385 struct ieee80211_mgmt
*mgmt
;
2389 mgmt
= (struct ieee80211_mgmt
*) data
;
2390 fc
= le_to_host16(mgmt
->frame_control
);
2392 if (WLAN_FC_GET_TYPE(fc
) == WLAN_FC_TYPE_MGMT
&&
2393 WLAN_FC_GET_STYPE(fc
) == WLAN_FC_STYPE_AUTH
) {
2395 * Only one of the authentication frame types is encrypted.
2396 * In order for static WEP encryption to work properly (i.e.,
2397 * to not encrypt the frame), we need to tell mac80211 about
2398 * the frames that must not be encrypted.
2400 u16 auth_alg
= le_to_host16(mgmt
->u
.auth
.auth_alg
);
2401 u16 auth_trans
= le_to_host16(mgmt
->u
.auth
.auth_transaction
);
2402 if (auth_alg
!= WLAN_AUTH_SHARED_KEY
|| auth_trans
!= 3)
2406 return wpa_driver_nl80211_send_frame(drv
, data
, data_len
, encrypt
);
2410 static int wpa_driver_nl80211_set_beacon(const char *ifname
, void *priv
,
2411 const u8
*head
, size_t head_len
,
2412 const u8
*tail
, size_t tail_len
,
2413 int dtim_period
, int beacon_int
)
2415 struct wpa_driver_nl80211_data
*drv
= priv
;
2417 u8 cmd
= NL80211_CMD_NEW_BEACON
;
2420 int ifindex
= if_nametoindex(ifname
);
2422 struct i802_bss
*bss
;
2424 bss
= get_bss(drv
, ifindex
);
2427 beacon_set
= bss
->beacon_set
;
2429 beacon_set
= drv
->beacon_set
;
2430 #endif /* HOSTAPD */
2432 msg
= nlmsg_alloc();
2436 wpa_printf(MSG_DEBUG
, "nl80211: Set beacon (beacon_set=%d)",
2439 cmd
= NL80211_CMD_SET_BEACON
;
2441 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
2443 NLA_PUT(msg
, NL80211_ATTR_BEACON_HEAD
, head_len
, head
);
2444 NLA_PUT(msg
, NL80211_ATTR_BEACON_TAIL
, tail_len
, tail
);
2445 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, ifindex
);
2446 NLA_PUT_U32(msg
, NL80211_ATTR_BEACON_INTERVAL
, beacon_int
);
2447 NLA_PUT_U32(msg
, NL80211_ATTR_DTIM_PERIOD
, dtim_period
);
2449 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
2451 wpa_printf(MSG_DEBUG
, "nl80211: Beacon set failed: %d (%s)",
2452 ret
, strerror(-ret
));
2455 bss
->beacon_set
= 1;
2457 drv
->beacon_set
= 1;
2458 #endif /* HOSTAPD */
2466 static int wpa_driver_nl80211_set_freq(struct wpa_driver_nl80211_data
*drv
,
2467 int freq
, int ht_enabled
,
2468 int sec_channel_offset
)
2473 msg
= nlmsg_alloc();
2477 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0, 0,
2478 NL80211_CMD_SET_WIPHY
, 0);
2480 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
2481 NLA_PUT_U32(msg
, NL80211_ATTR_WIPHY_FREQ
, freq
);
2483 switch (sec_channel_offset
) {
2485 NLA_PUT_U32(msg
, NL80211_ATTR_WIPHY_CHANNEL_TYPE
,
2486 NL80211_CHAN_HT40MINUS
);
2489 NLA_PUT_U32(msg
, NL80211_ATTR_WIPHY_CHANNEL_TYPE
,
2490 NL80211_CHAN_HT40PLUS
);
2493 NLA_PUT_U32(msg
, NL80211_ATTR_WIPHY_CHANNEL_TYPE
,
2499 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
2502 wpa_printf(MSG_DEBUG
, "nl80211: Failed to set channel (freq=%d): "
2503 "%d (%s)", freq
, ret
, strerror(-ret
));
2509 static int wpa_driver_nl80211_sta_add(const char *ifname
, void *priv
,
2510 struct hostapd_sta_add_params
*params
)
2512 struct wpa_driver_nl80211_data
*drv
= priv
;
2516 msg
= nlmsg_alloc();
2520 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
2521 0, NL80211_CMD_NEW_STATION
, 0);
2523 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, if_nametoindex(ifname
));
2524 NLA_PUT(msg
, NL80211_ATTR_MAC
, ETH_ALEN
, params
->addr
);
2525 NLA_PUT_U16(msg
, NL80211_ATTR_STA_AID
, params
->aid
);
2526 NLA_PUT(msg
, NL80211_ATTR_STA_SUPPORTED_RATES
, params
->supp_rates_len
,
2527 params
->supp_rates
);
2528 NLA_PUT_U16(msg
, NL80211_ATTR_STA_LISTEN_INTERVAL
,
2529 params
->listen_interval
);
2530 if (params
->ht_capabilities
) {
2531 NLA_PUT(msg
, NL80211_ATTR_HT_CAPABILITY
,
2532 sizeof(*params
->ht_capabilities
),
2533 params
->ht_capabilities
);
2536 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
2538 wpa_printf(MSG_DEBUG
, "nl80211: NL80211_CMD_NEW_STATION "
2539 "result: %d (%s)", ret
, strerror(-ret
));
2547 static int wpa_driver_nl80211_sta_remove(void *priv
, const u8
*addr
)
2549 struct wpa_driver_nl80211_data
*drv
= priv
;
2553 msg
= nlmsg_alloc();
2557 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
2558 0, NL80211_CMD_DEL_STATION
, 0);
2560 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
,
2561 if_nametoindex(drv
->ifname
));
2562 NLA_PUT(msg
, NL80211_ATTR_MAC
, ETH_ALEN
, addr
);
2564 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
2573 static void nl80211_remove_iface(struct wpa_driver_nl80211_data
*drv
,
2578 wpa_printf(MSG_DEBUG
, "nl80211: Remove interface ifindex=%d", ifidx
);
2581 /* stop listening for EAPOL on this interface */
2582 del_ifidx(drv
, ifidx
);
2583 #endif /* HOSTAPD */
2585 msg
= nlmsg_alloc();
2587 goto nla_put_failure
;
2589 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
2590 0, NL80211_CMD_DEL_INTERFACE
, 0);
2591 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, ifidx
);
2593 if (send_and_recv_msgs(drv
, msg
, NULL
, NULL
) == 0)
2596 wpa_printf(MSG_ERROR
, "Failed to remove interface (ifidx=%d).\n",
2601 static int nl80211_create_iface_once(struct wpa_driver_nl80211_data
*drv
,
2603 enum nl80211_iftype iftype
,
2604 const u8
*addr
, int wds
)
2606 struct nl_msg
*msg
, *flags
= NULL
;
2610 msg
= nlmsg_alloc();
2614 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
2615 0, NL80211_CMD_NEW_INTERFACE
, 0);
2616 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
2617 NLA_PUT_STRING(msg
, NL80211_ATTR_IFNAME
, ifname
);
2618 NLA_PUT_U32(msg
, NL80211_ATTR_IFTYPE
, iftype
);
2620 if (iftype
== NL80211_IFTYPE_MONITOR
) {
2623 flags
= nlmsg_alloc();
2625 goto nla_put_failure
;
2627 NLA_PUT_FLAG(flags
, NL80211_MNTR_FLAG_COOK_FRAMES
);
2629 err
= nla_put_nested(msg
, NL80211_ATTR_MNTR_FLAGS
, flags
);
2634 goto nla_put_failure
;
2636 NLA_PUT_U8(msg
, NL80211_ATTR_4ADDR
, wds
);
2639 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
2642 wpa_printf(MSG_ERROR
, "Failed to create interface %s: %d (%s)",
2643 ifname
, ret
, strerror(-ret
));
2647 ifidx
= if_nametoindex(ifname
);
2648 wpa_printf(MSG_DEBUG
, "nl80211: New interface %s created: ifindex=%d",
2655 /* start listening for EAPOL on this interface */
2656 add_ifidx(drv
, ifidx
);
2657 #endif /* HOSTAPD */
2659 if (addr
&& iftype
!= NL80211_IFTYPE_MONITOR
&&
2660 linux_set_ifhwaddr(drv
->ioctl_sock
, ifname
, addr
)) {
2661 nl80211_remove_iface(drv
, ifidx
);
2669 static int nl80211_create_iface(struct wpa_driver_nl80211_data
*drv
,
2670 const char *ifname
, enum nl80211_iftype iftype
,
2671 const u8
*addr
, int wds
)
2675 ret
= nl80211_create_iface_once(drv
, ifname
, iftype
, addr
, wds
);
2677 /* if error occured and interface exists already */
2678 if (ret
== -ENFILE
&& if_nametoindex(ifname
)) {
2679 wpa_printf(MSG_INFO
, "Try to remove and re-create %s", ifname
);
2681 /* Try to remove the interface that was already there. */
2682 nl80211_remove_iface(drv
, if_nametoindex(ifname
));
2684 /* Try to create the interface again */
2685 ret
= nl80211_create_iface_once(drv
, ifname
, iftype
, addr
,
2689 if (ret
>= 0 && drv
->disable_11b_rates
)
2690 nl80211_disable_11b_rates(drv
, ret
, 1);
2696 static void handle_tx_callback(void *ctx
, u8
*buf
, size_t len
, int ok
)
2698 struct ieee80211_hdr
*hdr
;
2700 union wpa_event_data event
;
2702 hdr
= (struct ieee80211_hdr
*) buf
;
2703 fc
= le_to_host16(hdr
->frame_control
);
2705 os_memset(&event
, 0, sizeof(event
));
2706 event
.tx_status
.type
= WLAN_FC_GET_TYPE(fc
);
2707 event
.tx_status
.stype
= WLAN_FC_GET_STYPE(fc
);
2708 event
.tx_status
.dst
= hdr
->addr1
;
2709 event
.tx_status
.data
= buf
;
2710 event
.tx_status
.data_len
= len
;
2711 event
.tx_status
.ack
= ok
;
2712 wpa_supplicant_event(ctx
, EVENT_TX_STATUS
, &event
);
2716 static void from_unknown_sta(struct wpa_driver_nl80211_data
*drv
,
2717 u8
*buf
, size_t len
)
2719 union wpa_event_data event
;
2720 os_memset(&event
, 0, sizeof(event
));
2721 event
.rx_from_unknown
.frame
= buf
;
2722 event
.rx_from_unknown
.len
= len
;
2723 wpa_supplicant_event(drv
->ctx
, EVENT_RX_FROM_UNKNOWN
, &event
);
2727 static void handle_frame(struct wpa_driver_nl80211_data
*drv
,
2728 u8
*buf
, size_t len
, int datarate
, int ssi_signal
)
2730 struct ieee80211_hdr
*hdr
;
2732 union wpa_event_data event
;
2734 hdr
= (struct ieee80211_hdr
*) buf
;
2735 fc
= le_to_host16(hdr
->frame_control
);
2737 switch (WLAN_FC_GET_TYPE(fc
)) {
2738 case WLAN_FC_TYPE_MGMT
:
2739 os_memset(&event
, 0, sizeof(event
));
2740 event
.rx_mgmt
.frame
= buf
;
2741 event
.rx_mgmt
.frame_len
= len
;
2742 event
.rx_mgmt
.datarate
= datarate
;
2743 event
.rx_mgmt
.ssi_signal
= ssi_signal
;
2744 wpa_supplicant_event(drv
->ctx
, EVENT_RX_MGMT
, &event
);
2746 case WLAN_FC_TYPE_CTRL
:
2747 /* can only get here with PS-Poll frames */
2748 wpa_printf(MSG_DEBUG
, "CTRL");
2749 from_unknown_sta(drv
, buf
, len
);
2751 case WLAN_FC_TYPE_DATA
:
2752 from_unknown_sta(drv
, buf
, len
);
2758 static void handle_monitor_read(int sock
, void *eloop_ctx
, void *sock_ctx
)
2760 struct wpa_driver_nl80211_data
*drv
= eloop_ctx
;
2762 unsigned char buf
[3000];
2763 struct ieee80211_radiotap_iterator iter
;
2765 int datarate
= 0, ssi_signal
= 0;
2766 int injected
= 0, failed
= 0, rxflags
= 0;
2768 len
= recv(sock
, buf
, sizeof(buf
), 0);
2774 if (drv
->nlmode
== NL80211_IFTYPE_STATION
&& !drv
->probe_req_report
) {
2775 wpa_printf(MSG_DEBUG
, "nl80211: Ignore monitor interface "
2776 "frame since Probe Request reporting is disabled");
2780 if (ieee80211_radiotap_iterator_init(&iter
, (void*)buf
, len
)) {
2781 printf("received invalid radiotap frame\n");
2786 ret
= ieee80211_radiotap_iterator_next(&iter
);
2790 printf("received invalid radiotap frame (%d)\n", ret
);
2793 switch (iter
.this_arg_index
) {
2794 case IEEE80211_RADIOTAP_FLAGS
:
2795 if (*iter
.this_arg
& IEEE80211_RADIOTAP_F_FCS
)
2798 case IEEE80211_RADIOTAP_RX_FLAGS
:
2801 case IEEE80211_RADIOTAP_TX_FLAGS
:
2803 failed
= le_to_host16((*(uint16_t *) iter
.this_arg
)) &
2804 IEEE80211_RADIOTAP_F_TX_FAIL
;
2806 case IEEE80211_RADIOTAP_DATA_RETRIES
:
2808 case IEEE80211_RADIOTAP_CHANNEL
:
2809 /* TODO: convert from freq/flags to channel number */
2811 case IEEE80211_RADIOTAP_RATE
:
2812 datarate
= *iter
.this_arg
* 5;
2814 case IEEE80211_RADIOTAP_DB_ANTSIGNAL
:
2815 ssi_signal
= *iter
.this_arg
;
2820 if (rxflags
&& injected
)
2824 handle_frame(drv
, buf
+ iter
.max_length
,
2825 len
- iter
.max_length
, datarate
, ssi_signal
);
2827 handle_tx_callback(drv
->ctx
, buf
+ iter
.max_length
,
2828 len
- iter
.max_length
, !failed
);
2833 * we post-process the filter code later and rewrite
2834 * this to the offset to the last instruction
2839 static struct sock_filter msock_filter_insns
[] = {
2841 * do a little-endian load of the radiotap length field
2843 /* load lower byte into A */
2844 BPF_STMT(BPF_LD
| BPF_B
| BPF_ABS
, 2),
2845 /* put it into X (== index register) */
2846 BPF_STMT(BPF_MISC
| BPF_TAX
, 0),
2847 /* load upper byte into A */
2848 BPF_STMT(BPF_LD
| BPF_B
| BPF_ABS
, 3),
2849 /* left-shift it by 8 */
2850 BPF_STMT(BPF_ALU
| BPF_LSH
| BPF_K
, 8),
2852 BPF_STMT(BPF_ALU
| BPF_OR
| BPF_X
, 0),
2853 /* put result into X */
2854 BPF_STMT(BPF_MISC
| BPF_TAX
, 0),
2857 * Allow management frames through, this also gives us those
2858 * management frames that we sent ourselves with status
2860 /* load the lower byte of the IEEE 802.11 frame control field */
2861 BPF_STMT(BPF_LD
| BPF_B
| BPF_IND
, 0),
2862 /* mask off frame type and version */
2863 BPF_STMT(BPF_ALU
| BPF_AND
| BPF_K
, 0xF),
2864 /* accept frame if it's both 0, fall through otherwise */
2865 BPF_JUMP(BPF_JMP
| BPF_JEQ
| BPF_K
, 0, PASS
, 0),
2868 * TODO: add a bit to radiotap RX flags that indicates
2869 * that the sending station is not associated, then
2870 * add a filter here that filters on our DA and that flag
2871 * to allow us to deauth frames to that bad station.
2873 * Not a regression -- we didn't do it before either.
2878 * drop non-data frames
2880 /* load the lower byte of the frame control field */
2881 BPF_STMT(BPF_LD
| BPF_B
| BPF_IND
, 0),
2882 /* mask off QoS bit */
2883 BPF_STMT(BPF_ALU
| BPF_AND
| BPF_K
, 0x0c),
2884 /* drop non-data frames */
2885 BPF_JUMP(BPF_JMP
| BPF_JEQ
| BPF_K
, 8, 0, FAIL
),
2887 /* load the upper byte of the frame control field */
2888 BPF_STMT(BPF_LD
| BPF_B
| BPF_IND
, 1),
2889 /* mask off toDS/fromDS */
2890 BPF_STMT(BPF_ALU
| BPF_AND
| BPF_K
, 0x03),
2891 /* accept WDS frames */
2892 BPF_JUMP(BPF_JMP
| BPF_JEQ
| BPF_K
, 3, PASS
, 0),
2895 * add header length to index
2897 /* load the lower byte of the frame control field */
2898 BPF_STMT(BPF_LD
| BPF_B
| BPF_IND
, 0),
2899 /* mask off QoS bit */
2900 BPF_STMT(BPF_ALU
| BPF_AND
| BPF_K
, 0x80),
2901 /* right shift it by 6 to give 0 or 2 */
2902 BPF_STMT(BPF_ALU
| BPF_RSH
| BPF_K
, 6),
2903 /* add data frame header length */
2904 BPF_STMT(BPF_ALU
| BPF_ADD
| BPF_K
, 24),
2905 /* add index, was start of 802.11 header */
2906 BPF_STMT(BPF_ALU
| BPF_ADD
| BPF_X
, 0),
2907 /* move to index, now start of LL header */
2908 BPF_STMT(BPF_MISC
| BPF_TAX
, 0),
2911 * Accept empty data frames, we use those for
2914 BPF_STMT(BPF_LD
| BPF_W
| BPF_LEN
, 0),
2915 BPF_JUMP(BPF_JMP
| BPF_JEQ
| BPF_X
, 0, PASS
, 0),
2918 * Accept EAPOL frames
2920 BPF_STMT(BPF_LD
| BPF_W
| BPF_IND
, 0),
2921 BPF_JUMP(BPF_JMP
| BPF_JEQ
| BPF_K
, 0xAAAA0300, 0, FAIL
),
2922 BPF_STMT(BPF_LD
| BPF_W
| BPF_IND
, 4),
2923 BPF_JUMP(BPF_JMP
| BPF_JEQ
| BPF_K
, 0x0000888E, PASS
, FAIL
),
2925 /* keep these last two statements or change the code below */
2926 /* return 0 == "DROP" */
2927 BPF_STMT(BPF_RET
| BPF_K
, 0),
2928 /* return ~0 == "keep all" */
2929 BPF_STMT(BPF_RET
| BPF_K
, ~0),
2932 static struct sock_fprog msock_filter
= {
2933 .len
= sizeof(msock_filter_insns
)/sizeof(msock_filter_insns
[0]),
2934 .filter
= msock_filter_insns
,
2938 static int add_monitor_filter(int s
)
2942 /* rewrite all PASS/FAIL jump offsets */
2943 for (idx
= 0; idx
< msock_filter
.len
; idx
++) {
2944 struct sock_filter
*insn
= &msock_filter_insns
[idx
];
2946 if (BPF_CLASS(insn
->code
) == BPF_JMP
) {
2947 if (insn
->code
== (BPF_JMP
|BPF_JA
)) {
2948 if (insn
->k
== PASS
)
2949 insn
->k
= msock_filter
.len
- idx
- 2;
2950 else if (insn
->k
== FAIL
)
2951 insn
->k
= msock_filter
.len
- idx
- 3;
2954 if (insn
->jt
== PASS
)
2955 insn
->jt
= msock_filter
.len
- idx
- 2;
2956 else if (insn
->jt
== FAIL
)
2957 insn
->jt
= msock_filter
.len
- idx
- 3;
2959 if (insn
->jf
== PASS
)
2960 insn
->jf
= msock_filter
.len
- idx
- 2;
2961 else if (insn
->jf
== FAIL
)
2962 insn
->jf
= msock_filter
.len
- idx
- 3;
2966 if (setsockopt(s
, SOL_SOCKET
, SO_ATTACH_FILTER
,
2967 &msock_filter
, sizeof(msock_filter
))) {
2968 perror("SO_ATTACH_FILTER");
2976 static void nl80211_remove_monitor_interface(
2977 struct wpa_driver_nl80211_data
*drv
)
2979 if (drv
->monitor_ifidx
>= 0) {
2980 nl80211_remove_iface(drv
, drv
->monitor_ifidx
);
2981 drv
->monitor_ifidx
= -1;
2983 if (drv
->monitor_sock
>= 0) {
2984 eloop_unregister_read_sock(drv
->monitor_sock
);
2985 close(drv
->monitor_sock
);
2986 drv
->monitor_sock
= -1;
2992 nl80211_create_monitor_interface(struct wpa_driver_nl80211_data
*drv
)
2995 struct sockaddr_ll ll
;
2999 snprintf(buf
, IFNAMSIZ
, "mon.%s", drv
->ifname
);
3000 buf
[IFNAMSIZ
- 1] = '\0';
3002 drv
->monitor_ifidx
=
3003 nl80211_create_iface(drv
, buf
, NL80211_IFTYPE_MONITOR
, NULL
,
3006 if (drv
->monitor_ifidx
< 0)
3009 if (linux_set_iface_flags(drv
->ioctl_sock
, buf
, 1))
3012 memset(&ll
, 0, sizeof(ll
));
3013 ll
.sll_family
= AF_PACKET
;
3014 ll
.sll_ifindex
= drv
->monitor_ifidx
;
3015 drv
->monitor_sock
= socket(PF_PACKET
, SOCK_RAW
, htons(ETH_P_ALL
));
3016 if (drv
->monitor_sock
< 0) {
3017 perror("socket[PF_PACKET,SOCK_RAW]");
3021 if (add_monitor_filter(drv
->monitor_sock
)) {
3022 wpa_printf(MSG_INFO
, "Failed to set socket filter for monitor "
3023 "interface; do filtering in user space");
3024 /* This works, but will cost in performance. */
3027 if (bind(drv
->monitor_sock
, (struct sockaddr
*) &ll
, sizeof(ll
)) < 0) {
3028 perror("monitor socket bind");
3032 optlen
= sizeof(optval
);
3035 (drv
->monitor_sock
, SOL_SOCKET
, SO_PRIORITY
, &optval
, optlen
)) {
3036 perror("Failed to set socket priority");
3040 if (eloop_register_read_sock(drv
->monitor_sock
, handle_monitor_read
,
3042 printf("Could not register monitor read socket\n");
3048 nl80211_remove_monitor_interface(drv
);
3053 static const u8 rfc1042_header
[6] = { 0xaa, 0xaa, 0x03, 0x00, 0x00, 0x00 };
3055 static int wpa_driver_nl80211_hapd_send_eapol(
3056 void *priv
, const u8
*addr
, const u8
*data
,
3057 size_t data_len
, int encrypt
, const u8
*own_addr
)
3059 struct wpa_driver_nl80211_data
*drv
= priv
;
3060 struct ieee80211_hdr
*hdr
;
3065 int qos
= sta
->flags
& WPA_STA_WMM
;
3070 len
= sizeof(*hdr
) + (qos
? 2 : 0) + sizeof(rfc1042_header
) + 2 +
3072 hdr
= os_zalloc(len
);
3074 printf("malloc() failed for i802_send_data(len=%lu)\n",
3075 (unsigned long) len
);
3079 hdr
->frame_control
=
3080 IEEE80211_FC(WLAN_FC_TYPE_DATA
, WLAN_FC_STYPE_DATA
);
3081 hdr
->frame_control
|= host_to_le16(WLAN_FC_FROMDS
);
3083 hdr
->frame_control
|= host_to_le16(WLAN_FC_ISWEP
);
3084 #if 0 /* To be enabled if qos determination is added above */
3086 hdr
->frame_control
|=
3087 host_to_le16(WLAN_FC_STYPE_QOS_DATA
<< 4);
3091 memcpy(hdr
->IEEE80211_DA_FROMDS
, addr
, ETH_ALEN
);
3092 memcpy(hdr
->IEEE80211_BSSID_FROMDS
, own_addr
, ETH_ALEN
);
3093 memcpy(hdr
->IEEE80211_SA_FROMDS
, own_addr
, ETH_ALEN
);
3094 pos
= (u8
*) (hdr
+ 1);
3096 #if 0 /* To be enabled if qos determination is added above */
3098 /* add an empty QoS header if needed */
3105 memcpy(pos
, rfc1042_header
, sizeof(rfc1042_header
));
3106 pos
+= sizeof(rfc1042_header
);
3107 WPA_PUT_BE16(pos
, ETH_P_PAE
);
3109 memcpy(pos
, data
, data_len
);
3111 res
= wpa_driver_nl80211_send_frame(drv
, (u8
*) hdr
, len
, encrypt
);
3113 wpa_printf(MSG_ERROR
, "i802_send_eapol - packet len: %lu - "
3115 (unsigned long) len
, errno
, strerror(errno
));
3123 static u32
sta_flags_nl80211(int flags
)
3127 if (flags
& WPA_STA_AUTHORIZED
)
3128 f
|= BIT(NL80211_STA_FLAG_AUTHORIZED
);
3129 if (flags
& WPA_STA_WMM
)
3130 f
|= BIT(NL80211_STA_FLAG_WME
);
3131 if (flags
& WPA_STA_SHORT_PREAMBLE
)
3132 f
|= BIT(NL80211_STA_FLAG_SHORT_PREAMBLE
);
3133 if (flags
& WPA_STA_MFP
)
3134 f
|= BIT(NL80211_STA_FLAG_MFP
);
3140 static int wpa_driver_nl80211_sta_set_flags(void *priv
, const u8
*addr
,
3141 int total_flags
, int flags_or
,
3144 struct wpa_driver_nl80211_data
*drv
= priv
;
3145 struct nl_msg
*msg
, *flags
= NULL
;
3146 struct nl80211_sta_flag_update upd
;
3148 msg
= nlmsg_alloc();
3152 flags
= nlmsg_alloc();
3158 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
3159 0, NL80211_CMD_SET_STATION
, 0);
3161 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
,
3162 if_nametoindex(drv
->ifname
));
3163 NLA_PUT(msg
, NL80211_ATTR_MAC
, ETH_ALEN
, addr
);
3166 * Backwards compatibility version using NL80211_ATTR_STA_FLAGS. This
3167 * can be removed eventually.
3169 if (total_flags
& WPA_STA_AUTHORIZED
)
3170 NLA_PUT_FLAG(flags
, NL80211_STA_FLAG_AUTHORIZED
);
3172 if (total_flags
& WPA_STA_WMM
)
3173 NLA_PUT_FLAG(flags
, NL80211_STA_FLAG_WME
);
3175 if (total_flags
& WPA_STA_SHORT_PREAMBLE
)
3176 NLA_PUT_FLAG(flags
, NL80211_STA_FLAG_SHORT_PREAMBLE
);
3178 if (total_flags
& WPA_STA_MFP
)
3179 NLA_PUT_FLAG(flags
, NL80211_STA_FLAG_MFP
);
3181 if (nla_put_nested(msg
, NL80211_ATTR_STA_FLAGS
, flags
))
3182 goto nla_put_failure
;
3184 os_memset(&upd
, 0, sizeof(upd
));
3185 upd
.mask
= sta_flags_nl80211(flags_or
| ~flags_and
);
3186 upd
.set
= sta_flags_nl80211(flags_or
);
3187 NLA_PUT(msg
, NL80211_ATTR_STA_FLAGS2
, sizeof(upd
), &upd
);
3191 return send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
3198 static int wpa_driver_nl80211_ap(struct wpa_driver_nl80211_data
*drv
,
3199 struct wpa_driver_associate_params
*params
)
3201 if (wpa_driver_nl80211_set_mode(drv
, params
->mode
) ||
3202 wpa_driver_nl80211_set_freq(drv
, params
->freq
, 0, 0)) {
3203 nl80211_remove_monitor_interface(drv
);
3207 /* TODO: setup monitor interface (and add code somewhere to remove this
3208 * when AP mode is stopped; associate with mode != 2 or drv_deinit) */
3214 static int nl80211_leave_ibss(struct wpa_driver_nl80211_data
*drv
)
3219 msg
= nlmsg_alloc();
3223 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0, 0,
3224 NL80211_CMD_LEAVE_IBSS
, 0);
3225 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
3226 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
3229 wpa_printf(MSG_DEBUG
, "nl80211: Leave IBSS failed: ret=%d "
3230 "(%s)", ret
, strerror(-ret
));
3231 goto nla_put_failure
;
3235 wpa_printf(MSG_DEBUG
, "nl80211: Leave IBSS request sent successfully");
3243 static int wpa_driver_nl80211_ibss(struct wpa_driver_nl80211_data
*drv
,
3244 struct wpa_driver_associate_params
*params
)
3250 wpa_printf(MSG_DEBUG
, "nl80211: Join IBSS (ifindex=%d)", drv
->ifindex
);
3252 if (wpa_driver_nl80211_set_mode(drv
, params
->mode
)) {
3253 wpa_printf(MSG_INFO
, "nl80211: Failed to set interface into "
3259 msg
= nlmsg_alloc();
3263 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0, 0,
3264 NL80211_CMD_JOIN_IBSS
, 0);
3265 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
3267 if (params
->ssid
== NULL
|| params
->ssid_len
> sizeof(drv
->ssid
))
3268 goto nla_put_failure
;
3270 wpa_hexdump_ascii(MSG_DEBUG
, " * SSID",
3271 params
->ssid
, params
->ssid_len
);
3272 NLA_PUT(msg
, NL80211_ATTR_SSID
, params
->ssid_len
,
3274 os_memcpy(drv
->ssid
, params
->ssid
, params
->ssid_len
);
3275 drv
->ssid_len
= params
->ssid_len
;
3277 wpa_printf(MSG_DEBUG
, " * freq=%d", params
->freq
);
3278 NLA_PUT_U32(msg
, NL80211_ATTR_WIPHY_FREQ
, params
->freq
);
3280 ret
= nl80211_set_conn_keys(params
, msg
);
3282 goto nla_put_failure
;
3284 if (params
->wpa_ie
) {
3285 wpa_hexdump(MSG_DEBUG
,
3286 " * Extra IEs for Beacon/Probe Response frames",
3287 params
->wpa_ie
, params
->wpa_ie_len
);
3288 NLA_PUT(msg
, NL80211_ATTR_IE
, params
->wpa_ie_len
,
3292 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
3295 wpa_printf(MSG_DEBUG
, "nl80211: Join IBSS failed: ret=%d (%s)",
3296 ret
, strerror(-ret
));
3298 if (ret
== -EALREADY
&& count
== 1) {
3299 wpa_printf(MSG_DEBUG
, "nl80211: Retry IBSS join after "
3301 nl80211_leave_ibss(drv
);
3306 goto nla_put_failure
;
3309 wpa_printf(MSG_DEBUG
, "nl80211: Join IBSS request sent successfully");
3317 static int wpa_driver_nl80211_connect(
3318 struct wpa_driver_nl80211_data
*drv
,
3319 struct wpa_driver_associate_params
*params
)
3322 enum nl80211_auth_type type
;
3325 msg
= nlmsg_alloc();
3329 wpa_printf(MSG_DEBUG
, "nl80211: Connect (ifindex=%d)", drv
->ifindex
);
3330 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0, 0,
3331 NL80211_CMD_CONNECT
, 0);
3333 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
3334 if (params
->bssid
) {
3335 wpa_printf(MSG_DEBUG
, " * bssid=" MACSTR
,
3336 MAC2STR(params
->bssid
));
3337 NLA_PUT(msg
, NL80211_ATTR_MAC
, ETH_ALEN
, params
->bssid
);
3340 wpa_printf(MSG_DEBUG
, " * freq=%d", params
->freq
);
3341 NLA_PUT_U32(msg
, NL80211_ATTR_WIPHY_FREQ
, params
->freq
);
3344 wpa_hexdump_ascii(MSG_DEBUG
, " * SSID",
3345 params
->ssid
, params
->ssid_len
);
3346 NLA_PUT(msg
, NL80211_ATTR_SSID
, params
->ssid_len
,
3348 if (params
->ssid_len
> sizeof(drv
->ssid
))
3349 goto nla_put_failure
;
3350 os_memcpy(drv
->ssid
, params
->ssid
, params
->ssid_len
);
3351 drv
->ssid_len
= params
->ssid_len
;
3353 wpa_hexdump(MSG_DEBUG
, " * IEs", params
->wpa_ie
, params
->wpa_ie_len
);
3355 NLA_PUT(msg
, NL80211_ATTR_IE
, params
->wpa_ie_len
,
3358 if (params
->auth_alg
& WPA_AUTH_ALG_OPEN
)
3359 type
= NL80211_AUTHTYPE_OPEN_SYSTEM
;
3360 else if (params
->auth_alg
& WPA_AUTH_ALG_SHARED
)
3361 type
= NL80211_AUTHTYPE_SHARED_KEY
;
3362 else if (params
->auth_alg
& WPA_AUTH_ALG_LEAP
)
3363 type
= NL80211_AUTHTYPE_NETWORK_EAP
;
3364 else if (params
->auth_alg
& WPA_AUTH_ALG_FT
)
3365 type
= NL80211_AUTHTYPE_FT
;
3367 goto nla_put_failure
;
3369 wpa_printf(MSG_DEBUG
, " * Auth Type %d", type
);
3370 NLA_PUT_U32(msg
, NL80211_ATTR_AUTH_TYPE
, type
);
3372 if (params
->wpa_ie
&& params
->wpa_ie_len
) {
3373 enum nl80211_wpa_versions ver
;
3375 if (params
->wpa_ie
[0] == WLAN_EID_RSN
)
3376 ver
= NL80211_WPA_VERSION_2
;
3378 ver
= NL80211_WPA_VERSION_1
;
3380 wpa_printf(MSG_DEBUG
, " * WPA Version %d", ver
);
3381 NLA_PUT_U32(msg
, NL80211_ATTR_WPA_VERSIONS
, ver
);
3384 if (params
->pairwise_suite
!= CIPHER_NONE
) {
3387 switch (params
->pairwise_suite
) {
3389 cipher
= WLAN_CIPHER_SUITE_WEP40
;
3392 cipher
= WLAN_CIPHER_SUITE_WEP104
;
3395 cipher
= WLAN_CIPHER_SUITE_CCMP
;
3399 cipher
= WLAN_CIPHER_SUITE_TKIP
;
3402 NLA_PUT_U32(msg
, NL80211_ATTR_CIPHER_SUITES_PAIRWISE
, cipher
);
3405 if (params
->group_suite
!= CIPHER_NONE
) {
3408 switch (params
->group_suite
) {
3410 cipher
= WLAN_CIPHER_SUITE_WEP40
;
3413 cipher
= WLAN_CIPHER_SUITE_WEP104
;
3416 cipher
= WLAN_CIPHER_SUITE_CCMP
;
3420 cipher
= WLAN_CIPHER_SUITE_TKIP
;
3423 NLA_PUT_U32(msg
, NL80211_ATTR_CIPHER_SUITE_GROUP
, cipher
);
3426 if (params
->key_mgmt_suite
== KEY_MGMT_802_1X
||
3427 params
->key_mgmt_suite
== KEY_MGMT_PSK
) {
3428 int mgmt
= WLAN_AKM_SUITE_PSK
;
3430 switch (params
->key_mgmt_suite
) {
3431 case KEY_MGMT_802_1X
:
3432 mgmt
= WLAN_AKM_SUITE_8021X
;
3436 mgmt
= WLAN_AKM_SUITE_PSK
;
3439 NLA_PUT_U32(msg
, NL80211_ATTR_AKM_SUITES
, mgmt
);
3442 ret
= nl80211_set_conn_keys(params
, msg
);
3444 goto nla_put_failure
;
3446 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
3449 wpa_printf(MSG_DEBUG
, "nl80211: MLME connect failed: ret=%d "
3450 "(%s)", ret
, strerror(-ret
));
3451 goto nla_put_failure
;
3454 wpa_printf(MSG_DEBUG
, "nl80211: Connect request send successfully");
3463 static int wpa_driver_nl80211_associate(
3464 void *priv
, struct wpa_driver_associate_params
*params
)
3466 struct wpa_driver_nl80211_data
*drv
= priv
;
3470 if (params
->mode
== IEEE80211_MODE_AP
)
3471 return wpa_driver_nl80211_ap(drv
, params
);
3473 if (params
->mode
== IEEE80211_MODE_IBSS
)
3474 return wpa_driver_nl80211_ibss(drv
, params
);
3476 if (!(drv
->capa
.flags
& WPA_DRIVER_FLAGS_SME
)) {
3477 if (wpa_driver_nl80211_set_mode(drv
, params
->mode
) < 0)
3479 return wpa_driver_nl80211_connect(drv
, params
);
3482 drv
->associated
= 0;
3484 msg
= nlmsg_alloc();
3488 wpa_printf(MSG_DEBUG
, "nl80211: Associate (ifindex=%d)",
3490 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0, 0,
3491 NL80211_CMD_ASSOCIATE
, 0);
3493 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
3494 if (params
->bssid
) {
3495 wpa_printf(MSG_DEBUG
, " * bssid=" MACSTR
,
3496 MAC2STR(params
->bssid
));
3497 NLA_PUT(msg
, NL80211_ATTR_MAC
, ETH_ALEN
, params
->bssid
);
3500 wpa_printf(MSG_DEBUG
, " * freq=%d", params
->freq
);
3501 NLA_PUT_U32(msg
, NL80211_ATTR_WIPHY_FREQ
, params
->freq
);
3502 drv
->assoc_freq
= params
->freq
;
3504 drv
->assoc_freq
= 0;
3506 wpa_hexdump_ascii(MSG_DEBUG
, " * SSID",
3507 params
->ssid
, params
->ssid_len
);
3508 NLA_PUT(msg
, NL80211_ATTR_SSID
, params
->ssid_len
,
3510 if (params
->ssid_len
> sizeof(drv
->ssid
))
3511 goto nla_put_failure
;
3512 os_memcpy(drv
->ssid
, params
->ssid
, params
->ssid_len
);
3513 drv
->ssid_len
= params
->ssid_len
;
3515 wpa_hexdump(MSG_DEBUG
, " * IEs", params
->wpa_ie
, params
->wpa_ie_len
);
3517 NLA_PUT(msg
, NL80211_ATTR_IE
, params
->wpa_ie_len
,
3520 #ifdef CONFIG_IEEE80211W
3521 if (params
->mgmt_frame_protection
== MGMT_FRAME_PROTECTION_REQUIRED
)
3522 NLA_PUT_U32(msg
, NL80211_ATTR_USE_MFP
, NL80211_MFP_REQUIRED
);
3523 #endif /* CONFIG_IEEE80211W */
3525 NLA_PUT_FLAG(msg
, NL80211_ATTR_CONTROL_PORT
);
3527 if (params
->prev_bssid
) {
3528 wpa_printf(MSG_DEBUG
, " * prev_bssid=" MACSTR
,
3529 MAC2STR(params
->prev_bssid
));
3530 NLA_PUT(msg
, NL80211_ATTR_PREV_BSSID
, ETH_ALEN
,
3531 params
->prev_bssid
);
3534 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
3537 wpa_printf(MSG_DEBUG
, "nl80211: MLME command failed: ret=%d "
3538 "(%s)", ret
, strerror(-ret
));
3539 goto nla_put_failure
;
3542 wpa_printf(MSG_DEBUG
, "nl80211: Association request send "
3551 static int nl80211_set_mode(struct wpa_driver_nl80211_data
*drv
,
3552 int ifindex
, int mode
)
3557 msg
= nlmsg_alloc();
3561 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
3562 0, NL80211_CMD_SET_INTERFACE
, 0);
3563 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, ifindex
);
3564 NLA_PUT_U32(msg
, NL80211_ATTR_IFTYPE
, mode
);
3566 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
3570 wpa_printf(MSG_DEBUG
, "nl80211: Failed to set interface %d to mode %d:"
3571 " %d (%s)", ifindex
, mode
, ret
, strerror(-ret
));
3576 static int wpa_driver_nl80211_set_mode(void *priv
, int mode
)
3578 struct wpa_driver_nl80211_data
*drv
= priv
;
3584 nlmode
= NL80211_IFTYPE_STATION
;
3587 nlmode
= NL80211_IFTYPE_ADHOC
;
3590 nlmode
= NL80211_IFTYPE_AP
;
3596 if (nl80211_set_mode(drv
, drv
->ifindex
, nlmode
) == 0) {
3597 drv
->nlmode
= nlmode
;
3602 if (nlmode
== drv
->nlmode
) {
3603 wpa_printf(MSG_DEBUG
, "nl80211: Interface already in "
3604 "requested mode - ignore error");
3606 goto done
; /* Already in the requested mode */
3609 /* mac80211 doesn't allow mode changes while the device is up, so
3610 * take the device down, try to set the mode again, and bring the
3613 if (linux_set_iface_flags(drv
->ioctl_sock
, drv
->ifname
, 0) == 0) {
3614 /* Try to set the mode again while the interface is down */
3615 ret
= nl80211_set_mode(drv
, drv
->ifindex
, nlmode
);
3616 if (linux_set_iface_flags(drv
->ioctl_sock
, drv
->ifname
, 1))
3621 wpa_printf(MSG_DEBUG
, "nl80211: Mode change succeeded while "
3622 "interface is down");
3623 drv
->nlmode
= nlmode
;
3627 if (!ret
&& nlmode
== NL80211_IFTYPE_AP
) {
3628 /* Setup additional AP mode functionality if needed */
3629 if (drv
->monitor_ifidx
< 0 &&
3630 nl80211_create_monitor_interface(drv
))
3632 } else if (!ret
&& nlmode
!= NL80211_IFTYPE_AP
) {
3633 /* Remove additional AP mode functionality */
3634 nl80211_remove_monitor_interface(drv
);
3638 wpa_printf(MSG_DEBUG
, "nl80211: Interface mode change to %d "
3639 "from %d failed", nlmode
, drv
->nlmode
);
3645 static int wpa_driver_nl80211_get_capa(void *priv
,
3646 struct wpa_driver_capa
*capa
)
3648 struct wpa_driver_nl80211_data
*drv
= priv
;
3649 if (!drv
->has_capability
)
3651 os_memcpy(capa
, &drv
->capa
, sizeof(*capa
));
3656 static int wpa_driver_nl80211_set_operstate(void *priv
, int state
)
3658 struct wpa_driver_nl80211_data
*drv
= priv
;
3660 wpa_printf(MSG_DEBUG
, "%s: operstate %d->%d (%s)",
3661 __func__
, drv
->operstate
, state
, state
? "UP" : "DORMANT");
3662 drv
->operstate
= state
;
3663 return netlink_send_oper_ifla(drv
->netlink
, drv
->ifindex
, -1,
3664 state
? IF_OPER_UP
: IF_OPER_DORMANT
);
3668 static int wpa_driver_nl80211_set_supp_port(void *priv
, int authorized
)
3670 struct wpa_driver_nl80211_data
*drv
= priv
;
3672 struct nl80211_sta_flag_update upd
;
3674 msg
= nlmsg_alloc();
3678 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
3679 0, NL80211_CMD_SET_STATION
, 0);
3681 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
,
3682 if_nametoindex(drv
->ifname
));
3683 NLA_PUT(msg
, NL80211_ATTR_MAC
, ETH_ALEN
, drv
->bssid
);
3685 os_memset(&upd
, 0, sizeof(upd
));
3686 upd
.mask
= BIT(NL80211_STA_FLAG_AUTHORIZED
);
3688 upd
.set
= BIT(NL80211_STA_FLAG_AUTHORIZED
);
3689 NLA_PUT(msg
, NL80211_ATTR_STA_FLAGS2
, sizeof(upd
), &upd
);
3691 return send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
3699 static struct i802_bss
* get_bss(struct wpa_driver_nl80211_data
*drv
,
3702 struct i802_bss
*bss
= &drv
->bss
;
3704 if (ifindex
== bss
->ifindex
)
3708 wpa_printf(MSG_DEBUG
, "nl80211: get_bss(%d) failed", ifindex
);
3713 static void add_ifidx(struct wpa_driver_nl80211_data
*drv
, int ifidx
)
3718 wpa_printf(MSG_DEBUG
, "nl80211: Add own interface ifindex %d",
3720 for (i
= 0; i
< drv
->num_if_indices
; i
++) {
3721 if (drv
->if_indices
[i
] == 0) {
3722 drv
->if_indices
[i
] = ifidx
;
3727 if (drv
->if_indices
!= drv
->default_if_indices
)
3728 old
= drv
->if_indices
;
3732 drv
->if_indices
= os_realloc(old
,
3733 sizeof(int) * (drv
->num_if_indices
+ 1));
3734 if (!drv
->if_indices
) {
3736 drv
->if_indices
= drv
->default_if_indices
;
3738 drv
->if_indices
= old
;
3739 wpa_printf(MSG_ERROR
, "Failed to reallocate memory for "
3741 wpa_printf(MSG_ERROR
, "Ignoring EAPOL on interface %d", ifidx
);
3744 drv
->if_indices
[drv
->num_if_indices
] = ifidx
;
3745 drv
->num_if_indices
++;
3749 static void del_ifidx(struct wpa_driver_nl80211_data
*drv
, int ifidx
)
3753 for (i
= 0; i
< drv
->num_if_indices
; i
++) {
3754 if (drv
->if_indices
[i
] == ifidx
) {
3755 drv
->if_indices
[i
] = 0;
3762 static int have_ifidx(struct wpa_driver_nl80211_data
*drv
, int ifidx
)
3766 for (i
= 0; i
< drv
->num_if_indices
; i
++)
3767 if (drv
->if_indices
[i
] == ifidx
)
3774 static inline int min_int(int a
, int b
)
3782 static int get_key_handler(struct nl_msg
*msg
, void *arg
)
3784 struct nlattr
*tb
[NL80211_ATTR_MAX
+ 1];
3785 struct genlmsghdr
*gnlh
= nlmsg_data(nlmsg_hdr(msg
));
3787 nla_parse(tb
, NL80211_ATTR_MAX
, genlmsg_attrdata(gnlh
, 0),
3788 genlmsg_attrlen(gnlh
, 0), NULL
);
3791 * TODO: validate the key index and mac address!
3792 * Otherwise, there's a race condition as soon as
3793 * the kernel starts sending key notifications.
3796 if (tb
[NL80211_ATTR_KEY_SEQ
])
3797 memcpy(arg
, nla_data(tb
[NL80211_ATTR_KEY_SEQ
]),
3798 min_int(nla_len(tb
[NL80211_ATTR_KEY_SEQ
]), 6));
3803 static int i802_get_seqnum(const char *iface
, void *priv
, const u8
*addr
,
3806 struct wpa_driver_nl80211_data
*drv
= priv
;
3809 msg
= nlmsg_alloc();
3813 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
3814 0, NL80211_CMD_GET_KEY
, 0);
3817 NLA_PUT(msg
, NL80211_ATTR_MAC
, ETH_ALEN
, addr
);
3818 NLA_PUT_U8(msg
, NL80211_ATTR_KEY_IDX
, idx
);
3819 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, if_nametoindex(iface
));
3823 return send_and_recv_msgs(drv
, msg
, get_key_handler
, seq
);
3829 static int i802_set_rate_sets(void *priv
, int *supp_rates
, int *basic_rates
,
3832 struct wpa_driver_nl80211_data
*drv
= priv
;
3834 u8 rates
[NL80211_MAX_SUPP_RATES
];
3838 msg
= nlmsg_alloc();
3842 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0, 0,
3843 NL80211_CMD_SET_BSS
, 0);
3845 for (i
= 0; i
< NL80211_MAX_SUPP_RATES
&& basic_rates
[i
] >= 0; i
++)
3846 rates
[rates_len
++] = basic_rates
[i
] / 5;
3848 NLA_PUT(msg
, NL80211_ATTR_BSS_BASIC_RATES
, rates_len
, rates
);
3850 /* TODO: multi-BSS support */
3851 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, if_nametoindex(drv
->ifname
));
3853 return send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
3859 /* Set kernel driver on given frequency (MHz) */
3860 static int i802_set_freq(void *priv
, struct hostapd_freq_params
*freq
)
3862 struct wpa_driver_nl80211_data
*drv
= priv
;
3863 return wpa_driver_nl80211_set_freq(drv
, freq
->freq
, freq
->ht_enabled
,
3864 freq
->sec_channel_offset
);
3868 static int i802_set_rts(void *priv
, int rts
)
3870 struct wpa_driver_nl80211_data
*drv
= priv
;
3875 msg
= nlmsg_alloc();
3884 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
3885 0, NL80211_CMD_SET_WIPHY
, 0);
3886 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
3887 NLA_PUT_U32(msg
, NL80211_ATTR_WIPHY_RTS_THRESHOLD
, val
);
3889 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
3893 wpa_printf(MSG_DEBUG
, "nl80211: Failed to set RTS threshold %d: "
3894 "%d (%s)", rts
, ret
, strerror(-ret
));
3899 static int i802_set_frag(void *priv
, int frag
)
3901 struct wpa_driver_nl80211_data
*drv
= priv
;
3906 msg
= nlmsg_alloc();
3915 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
3916 0, NL80211_CMD_SET_WIPHY
, 0);
3917 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
3918 NLA_PUT_U32(msg
, NL80211_ATTR_WIPHY_FRAG_THRESHOLD
, val
);
3920 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
3924 wpa_printf(MSG_DEBUG
, "nl80211: Failed to set fragmentation threshold "
3925 "%d: %d (%s)", frag
, ret
, strerror(-ret
));
3930 static int i802_flush(void *priv
)
3932 struct wpa_driver_nl80211_data
*drv
= priv
;
3935 msg
= nlmsg_alloc();
3939 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
3940 0, NL80211_CMD_DEL_STATION
, 0);
3943 * XXX: FIX! this needs to flush all VLANs too
3945 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
,
3946 if_nametoindex(drv
->ifname
));
3948 return send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
3954 static int get_sta_handler(struct nl_msg
*msg
, void *arg
)
3956 struct nlattr
*tb
[NL80211_ATTR_MAX
+ 1];
3957 struct genlmsghdr
*gnlh
= nlmsg_data(nlmsg_hdr(msg
));
3958 struct hostap_sta_driver_data
*data
= arg
;
3959 struct nlattr
*stats
[NL80211_STA_INFO_MAX
+ 1];
3960 static struct nla_policy stats_policy
[NL80211_STA_INFO_MAX
+ 1] = {
3961 [NL80211_STA_INFO_INACTIVE_TIME
] = { .type
= NLA_U32
},
3962 [NL80211_STA_INFO_RX_BYTES
] = { .type
= NLA_U32
},
3963 [NL80211_STA_INFO_TX_BYTES
] = { .type
= NLA_U32
},
3964 [NL80211_STA_INFO_RX_PACKETS
] = { .type
= NLA_U32
},
3965 [NL80211_STA_INFO_TX_PACKETS
] = { .type
= NLA_U32
},
3968 nla_parse(tb
, NL80211_ATTR_MAX
, genlmsg_attrdata(gnlh
, 0),
3969 genlmsg_attrlen(gnlh
, 0), NULL
);
3972 * TODO: validate the interface and mac address!
3973 * Otherwise, there's a race condition as soon as
3974 * the kernel starts sending station notifications.
3977 if (!tb
[NL80211_ATTR_STA_INFO
]) {
3978 wpa_printf(MSG_DEBUG
, "sta stats missing!");
3981 if (nla_parse_nested(stats
, NL80211_STA_INFO_MAX
,
3982 tb
[NL80211_ATTR_STA_INFO
],
3984 wpa_printf(MSG_DEBUG
, "failed to parse nested attributes!");
3988 if (stats
[NL80211_STA_INFO_INACTIVE_TIME
])
3989 data
->inactive_msec
=
3990 nla_get_u32(stats
[NL80211_STA_INFO_INACTIVE_TIME
]);
3991 if (stats
[NL80211_STA_INFO_RX_BYTES
])
3992 data
->rx_bytes
= nla_get_u32(stats
[NL80211_STA_INFO_RX_BYTES
]);
3993 if (stats
[NL80211_STA_INFO_TX_BYTES
])
3994 data
->tx_bytes
= nla_get_u32(stats
[NL80211_STA_INFO_TX_BYTES
]);
3995 if (stats
[NL80211_STA_INFO_RX_PACKETS
])
3997 nla_get_u32(stats
[NL80211_STA_INFO_RX_PACKETS
]);
3998 if (stats
[NL80211_STA_INFO_TX_PACKETS
])
4000 nla_get_u32(stats
[NL80211_STA_INFO_TX_PACKETS
]);
4005 static int i802_read_sta_data(void *priv
, struct hostap_sta_driver_data
*data
,
4008 struct wpa_driver_nl80211_data
*drv
= priv
;
4011 os_memset(data
, 0, sizeof(*data
));
4012 msg
= nlmsg_alloc();
4016 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
4017 0, NL80211_CMD_GET_STATION
, 0);
4019 NLA_PUT(msg
, NL80211_ATTR_MAC
, ETH_ALEN
, addr
);
4020 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, if_nametoindex(drv
->ifname
));
4022 return send_and_recv_msgs(drv
, msg
, get_sta_handler
, data
);
4028 static int i802_set_tx_queue_params(void *priv
, int queue
, int aifs
,
4029 int cw_min
, int cw_max
, int burst_time
)
4031 struct wpa_driver_nl80211_data
*drv
= priv
;
4033 struct nlattr
*txq
, *params
;
4035 msg
= nlmsg_alloc();
4039 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
4040 0, NL80211_CMD_SET_WIPHY
, 0);
4042 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, if_nametoindex(drv
->ifname
));
4044 txq
= nla_nest_start(msg
, NL80211_ATTR_WIPHY_TXQ_PARAMS
);
4046 goto nla_put_failure
;
4048 /* We are only sending parameters for a single TXQ at a time */
4049 params
= nla_nest_start(msg
, 1);
4051 goto nla_put_failure
;
4053 NLA_PUT_U8(msg
, NL80211_TXQ_ATTR_QUEUE
, queue
);
4054 /* Burst time is configured in units of 0.1 msec and TXOP parameter in
4055 * 32 usec, so need to convert the value here. */
4056 NLA_PUT_U16(msg
, NL80211_TXQ_ATTR_TXOP
, (burst_time
* 100 + 16) / 32);
4057 NLA_PUT_U16(msg
, NL80211_TXQ_ATTR_CWMIN
, cw_min
);
4058 NLA_PUT_U16(msg
, NL80211_TXQ_ATTR_CWMAX
, cw_max
);
4059 NLA_PUT_U8(msg
, NL80211_TXQ_ATTR_AIFS
, aifs
);
4061 nla_nest_end(msg
, params
);
4063 nla_nest_end(msg
, txq
);
4065 if (send_and_recv_msgs(drv
, msg
, NULL
, NULL
) == 0)
4072 static int i802_set_bss(void *priv
, int cts
, int preamble
, int slot
)
4074 struct wpa_driver_nl80211_data
*drv
= priv
;
4077 msg
= nlmsg_alloc();
4081 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0, 0,
4082 NL80211_CMD_SET_BSS
, 0);
4085 NLA_PUT_U8(msg
, NL80211_ATTR_BSS_CTS_PROT
, cts
);
4087 NLA_PUT_U8(msg
, NL80211_ATTR_BSS_SHORT_PREAMBLE
, preamble
);
4089 NLA_PUT_U8(msg
, NL80211_ATTR_BSS_SHORT_SLOT_TIME
, slot
);
4091 /* TODO: multi-BSS support */
4092 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, if_nametoindex(drv
->ifname
));
4094 return send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
4100 static int i802_set_cts_protect(void *priv
, int value
)
4102 return i802_set_bss(priv
, value
, -1, -1);
4106 static int i802_set_preamble(void *priv
, int value
)
4108 return i802_set_bss(priv
, -1, value
, -1);
4112 static int i802_set_short_slot_time(void *priv
, int value
)
4114 return i802_set_bss(priv
, -1, -1, value
);
4118 static int i802_set_sta_vlan(void *priv
, const u8
*addr
,
4119 const char *ifname
, int vlan_id
)
4121 struct wpa_driver_nl80211_data
*drv
= priv
;
4124 msg
= nlmsg_alloc();
4128 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0,
4129 0, NL80211_CMD_SET_STATION
, 0);
4131 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
,
4132 if_nametoindex(drv
->ifname
));
4133 NLA_PUT(msg
, NL80211_ATTR_MAC
, ETH_ALEN
, addr
);
4134 NLA_PUT_U32(msg
, NL80211_ATTR_STA_VLAN
,
4135 if_nametoindex(ifname
));
4137 return send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
4143 static int i802_set_wds_sta(void *priv
, const u8
*addr
, int aid
, int val
)
4145 struct wpa_driver_nl80211_data
*drv
= priv
;
4148 os_snprintf(name
, sizeof(name
), "%s.sta%d", drv
->ifname
, aid
);
4150 if (nl80211_create_iface(priv
, name
, NL80211_IFTYPE_AP_VLAN
,
4153 linux_set_iface_flags(drv
->ioctl_sock
, name
, 1);
4154 return i802_set_sta_vlan(priv
, addr
, name
, 0);
4156 i802_set_sta_vlan(priv
, addr
, drv
->ifname
, 0);
4157 return wpa_driver_nl80211_if_remove(priv
, WPA_IF_AP_VLAN
,
4163 static void handle_eapol(int sock
, void *eloop_ctx
, void *sock_ctx
)
4165 struct wpa_driver_nl80211_data
*drv
= eloop_ctx
;
4166 struct sockaddr_ll lladdr
;
4167 unsigned char buf
[3000];
4169 socklen_t fromlen
= sizeof(lladdr
);
4171 len
= recvfrom(sock
, buf
, sizeof(buf
), 0,
4172 (struct sockaddr
*)&lladdr
, &fromlen
);
4178 if (have_ifidx(drv
, lladdr
.sll_ifindex
))
4179 drv_event_eapol_rx(drv
->ctx
, lladdr
.sll_addr
, buf
, len
);
4183 static int i802_get_inact_sec(void *priv
, const u8
*addr
)
4185 struct hostap_sta_driver_data data
;
4188 data
.inactive_msec
= (unsigned long) -1;
4189 ret
= i802_read_sta_data(priv
, &data
, addr
);
4190 if (ret
|| data
.inactive_msec
== (unsigned long) -1)
4192 return data
.inactive_msec
/ 1000;
4196 static int i802_sta_clear_stats(void *priv
, const u8
*addr
)
4205 static int i802_sta_deauth(void *priv
, const u8
*own_addr
, const u8
*addr
,
4208 struct wpa_driver_nl80211_data
*drv
= priv
;
4209 struct ieee80211_mgmt mgmt
;
4211 memset(&mgmt
, 0, sizeof(mgmt
));
4212 mgmt
.frame_control
= IEEE80211_FC(WLAN_FC_TYPE_MGMT
,
4213 WLAN_FC_STYPE_DEAUTH
);
4214 memcpy(mgmt
.da
, addr
, ETH_ALEN
);
4215 memcpy(mgmt
.sa
, own_addr
, ETH_ALEN
);
4216 memcpy(mgmt
.bssid
, own_addr
, ETH_ALEN
);
4217 mgmt
.u
.deauth
.reason_code
= host_to_le16(reason
);
4218 return wpa_driver_nl80211_send_mlme(drv
, (u8
*) &mgmt
,
4220 sizeof(mgmt
.u
.deauth
));
4224 static int i802_sta_disassoc(void *priv
, const u8
*own_addr
, const u8
*addr
,
4227 struct wpa_driver_nl80211_data
*drv
= priv
;
4228 struct ieee80211_mgmt mgmt
;
4230 memset(&mgmt
, 0, sizeof(mgmt
));
4231 mgmt
.frame_control
= IEEE80211_FC(WLAN_FC_TYPE_MGMT
,
4232 WLAN_FC_STYPE_DISASSOC
);
4233 memcpy(mgmt
.da
, addr
, ETH_ALEN
);
4234 memcpy(mgmt
.sa
, own_addr
, ETH_ALEN
);
4235 memcpy(mgmt
.bssid
, own_addr
, ETH_ALEN
);
4236 mgmt
.u
.disassoc
.reason_code
= host_to_le16(reason
);
4237 return wpa_driver_nl80211_send_mlme(drv
, (u8
*) &mgmt
,
4239 sizeof(mgmt
.u
.disassoc
));
4243 static void *i802_init(struct hostapd_data
*hapd
,
4244 struct wpa_init_params
*params
)
4246 struct wpa_driver_nl80211_data
*drv
;
4249 drv
= wpa_driver_nl80211_init(hapd
, params
->ifname
);
4253 drv
->bss
.ifindex
= drv
->ifindex
;
4255 drv
->num_if_indices
= sizeof(drv
->default_if_indices
) / sizeof(int);
4256 drv
->if_indices
= drv
->default_if_indices
;
4257 for (i
= 0; i
< params
->num_bridge
; i
++) {
4258 if (params
->bridge
[i
])
4259 add_ifidx(drv
, if_nametoindex(params
->bridge
[i
]));
4262 /* start listening for EAPOL on the default AP interface */
4263 add_ifidx(drv
, drv
->ifindex
);
4265 if (linux_set_iface_flags(drv
->ioctl_sock
, drv
->ifname
, 0))
4268 if (params
->bssid
) {
4269 if (linux_set_ifhwaddr(drv
->ioctl_sock
, drv
->ifname
,
4274 if (wpa_driver_nl80211_set_mode(drv
, IEEE80211_MODE_AP
)) {
4275 wpa_printf(MSG_ERROR
, "nl80211: Failed to set interface %s "
4276 "into AP mode", drv
->ifname
);
4280 if (linux_set_iface_flags(drv
->ioctl_sock
, drv
->ifname
, 1))
4283 drv
->eapol_sock
= socket(PF_PACKET
, SOCK_DGRAM
, htons(ETH_P_PAE
));
4284 if (drv
->eapol_sock
< 0) {
4285 perror("socket(PF_PACKET, SOCK_DGRAM, ETH_P_PAE)");
4289 if (eloop_register_read_sock(drv
->eapol_sock
, handle_eapol
, drv
, NULL
))
4291 printf("Could not register read socket for eapol\n");
4295 if (linux_get_ifhwaddr(drv
->ioctl_sock
, drv
->ifname
, params
->own_addr
))
4301 nl80211_remove_monitor_interface(drv
);
4302 if (drv
->ioctl_sock
>= 0)
4303 close(drv
->ioctl_sock
);
4305 genl_family_put(drv
->nl80211
);
4306 nl_cache_free(drv
->nl_cache
);
4307 nl_handle_destroy(drv
->nl_handle
);
4308 nl_cb_put(drv
->nl_cb
);
4315 static void i802_deinit(void *priv
)
4317 wpa_driver_nl80211_deinit(priv
);
4320 #endif /* HOSTAPD */
4323 static enum nl80211_iftype
wpa_driver_nl80211_if_type(
4324 enum wpa_driver_if_type type
)
4327 case WPA_IF_STATION
:
4328 return NL80211_IFTYPE_STATION
;
4329 case WPA_IF_AP_VLAN
:
4330 return NL80211_IFTYPE_AP_VLAN
;
4332 return NL80211_IFTYPE_AP
;
4338 static int wpa_driver_nl80211_if_add(const char *iface
, void *priv
,
4339 enum wpa_driver_if_type type
,
4340 const char *ifname
, const u8
*addr
,
4343 struct wpa_driver_nl80211_data
*drv
= priv
;
4346 struct i802_bss
*bss
= NULL
;
4348 if (type
== WPA_IF_AP_BSS
) {
4349 bss
= os_zalloc(sizeof(*bss
));
4353 #endif /* HOSTAPD */
4355 ifidx
= nl80211_create_iface(drv
, ifname
,
4356 wpa_driver_nl80211_if_type(type
), addr
,
4361 #endif /* HOSTAPD */
4366 if (type
== WPA_IF_AP_BSS
) {
4367 if (linux_set_iface_flags(drv
->ioctl_sock
, ifname
, 1)) {
4368 nl80211_remove_iface(drv
, ifidx
);
4372 bss
->ifindex
= ifidx
;
4373 bss
->next
= drv
->bss
.next
;
4374 drv
->bss
.next
= bss
;
4376 #endif /* HOSTAPD */
4382 static int wpa_driver_nl80211_if_remove(void *priv
,
4383 enum wpa_driver_if_type type
,
4386 struct wpa_driver_nl80211_data
*drv
= priv
;
4387 int ifindex
= if_nametoindex(ifname
);
4389 nl80211_remove_iface(drv
, ifindex
);
4392 if (type
== WPA_IF_AP_BSS
) {
4393 struct i802_bss
*bss
, *prev
;
4395 bss
= drv
->bss
.next
;
4397 if (ifindex
== bss
->ifindex
) {
4398 prev
->next
= bss
->next
;
4406 #endif /* HOSTAPD */
4412 static int cookie_handler(struct nl_msg
*msg
, void *arg
)
4414 struct nlattr
*tb
[NL80211_ATTR_MAX
+ 1];
4415 struct genlmsghdr
*gnlh
= nlmsg_data(nlmsg_hdr(msg
));
4417 nla_parse(tb
, NL80211_ATTR_MAX
, genlmsg_attrdata(gnlh
, 0),
4418 genlmsg_attrlen(gnlh
, 0), NULL
);
4419 if (tb
[NL80211_ATTR_COOKIE
])
4420 *cookie
= nla_get_u64(tb
[NL80211_ATTR_COOKIE
]);
4425 static int wpa_driver_nl80211_remain_on_channel(void *priv
, unsigned int freq
,
4426 unsigned int duration
)
4428 struct wpa_driver_nl80211_data
*drv
= priv
;
4433 msg
= nlmsg_alloc();
4437 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0, 0,
4438 NL80211_CMD_REMAIN_ON_CHANNEL
, 0);
4440 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
4441 NLA_PUT_U32(msg
, NL80211_ATTR_WIPHY_FREQ
, freq
);
4442 NLA_PUT_U32(msg
, NL80211_ATTR_DURATION
, duration
);
4445 ret
= send_and_recv_msgs(drv
, msg
, cookie_handler
, &cookie
);
4447 wpa_printf(MSG_DEBUG
, "nl80211: Remain-on-channel cookie "
4448 "0x%llx for freq=%u MHz duration=%u",
4449 (long long unsigned int) cookie
, freq
, duration
);
4450 drv
->remain_on_chan_cookie
= cookie
;
4453 wpa_printf(MSG_DEBUG
, "nl80211: Failed to request remain-on-channel "
4454 "(freq=%d): %d (%s)", freq
, ret
, strerror(-ret
));
4460 static int wpa_driver_nl80211_cancel_remain_on_channel(void *priv
)
4462 struct wpa_driver_nl80211_data
*drv
= priv
;
4466 if (!drv
->pending_remain_on_chan
) {
4467 wpa_printf(MSG_DEBUG
, "nl80211: No pending remain-on-channel "
4472 wpa_printf(MSG_DEBUG
, "nl80211: Cancel remain-on-channel with cookie "
4474 (long long unsigned int) drv
->remain_on_chan_cookie
);
4476 msg
= nlmsg_alloc();
4480 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0, 0,
4481 NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL
, 0);
4483 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, drv
->ifindex
);
4484 NLA_PUT_U64(msg
, NL80211_ATTR_COOKIE
, drv
->remain_on_chan_cookie
);
4486 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
4489 wpa_printf(MSG_DEBUG
, "nl80211: Failed to cancel remain-on-channel: "
4490 "%d (%s)", ret
, strerror(-ret
));
4496 static void wpa_driver_nl80211_probe_req_report_timeout(void *eloop_ctx
,
4499 struct wpa_driver_nl80211_data
*drv
= eloop_ctx
;
4500 if (drv
->monitor_ifidx
< 0)
4501 return; /* monitor interface already removed */
4503 if (drv
->nlmode
!= NL80211_IFTYPE_STATION
)
4504 return; /* not in station mode anymore */
4506 if (drv
->probe_req_report
)
4507 return; /* reporting enabled */
4509 wpa_printf(MSG_DEBUG
, "nl80211: Remove monitor interface due to no "
4510 "Probe Request reporting needed anymore");
4511 nl80211_remove_monitor_interface(drv
);
4515 static int wpa_driver_nl80211_probe_req_report(void *priv
, int report
)
4517 struct wpa_driver_nl80211_data
*drv
= priv
;
4519 if (drv
->nlmode
!= NL80211_IFTYPE_STATION
) {
4520 wpa_printf(MSG_DEBUG
, "nl80211: probe_req_report control only "
4521 "allowed in station mode (iftype=%d)",
4525 drv
->probe_req_report
= report
;
4528 eloop_cancel_timeout(
4529 wpa_driver_nl80211_probe_req_report_timeout
,
4531 if (drv
->monitor_ifidx
< 0 &&
4532 nl80211_create_monitor_interface(drv
))
4536 * It takes a while to remove the monitor interface, so try to
4537 * avoid doing this if it is needed again shortly. Instead,
4538 * schedule the interface to be removed later if no need for it
4541 wpa_printf(MSG_DEBUG
, "nl80211: Scheduling monitor interface "
4542 "to be removed after 10 seconds of no use");
4543 eloop_register_timeout(
4544 10, 0, wpa_driver_nl80211_probe_req_report_timeout
,
4552 static int wpa_driver_nl80211_alloc_interface_addr(void *priv
, u8
*addr
)
4554 struct wpa_driver_nl80211_data
*drv
= priv
;
4556 if (linux_get_ifhwaddr(drv
->ioctl_sock
, drv
->ifname
, addr
) < 0)
4559 if (addr
[0] & 0x02) {
4560 /* TODO: add support for generating multiple addresses */
4563 addr
[0] = 0x02; /* locally administered */
4569 static void wpa_driver_nl80211_release_interface_addr(void *priv
,
4572 /* TODO: keep list of allocated address and release them here */
4576 static int nl80211_disable_11b_rates(struct wpa_driver_nl80211_data
*drv
,
4577 int ifindex
, int disabled
)
4580 struct nlattr
*bands
, *band
;
4583 msg
= nlmsg_alloc();
4587 genlmsg_put(msg
, 0, 0, genl_family_get_id(drv
->nl80211
), 0, 0,
4588 NL80211_CMD_SET_TX_BITRATE_MASK
, 0);
4589 NLA_PUT_U32(msg
, NL80211_ATTR_IFINDEX
, ifindex
);
4591 bands
= nla_nest_start(msg
, NL80211_ATTR_TX_RATES
);
4593 goto nla_put_failure
;
4596 * Disable 2 GHz rates 1, 2, 5.5, 11 Mbps by masking out everything
4597 * else apart from 6, 9, 12, 18, 24, 36, 48, 54 Mbps from non-MCS
4598 * rates. All 5 GHz rates are left enabled.
4600 band
= nla_nest_start(msg
, NL80211_BAND_2GHZ
);
4602 goto nla_put_failure
;
4603 NLA_PUT(msg
, NL80211_TXRATE_LEGACY
, 8,
4604 "\x0c\x12\x18\x24\x30\x48\x60\x6c");
4605 nla_nest_end(msg
, band
);
4607 nla_nest_end(msg
, bands
);
4609 ret
= send_and_recv_msgs(drv
, msg
, NULL
, NULL
);
4612 wpa_printf(MSG_DEBUG
, "nl80211: Set TX rates failed: ret=%d "
4613 "(%s)", ret
, strerror(-ret
));
4624 static int wpa_driver_nl80211_disable_11b_rates(void *priv
, int disabled
)
4626 struct wpa_driver_nl80211_data
*drv
= priv
;
4627 drv
->disable_11b_rates
= disabled
;
4628 return nl80211_disable_11b_rates(drv
, drv
->ifindex
, disabled
);
4632 const struct wpa_driver_ops wpa_driver_nl80211_ops
= {
4634 .desc
= "Linux nl80211/cfg80211",
4635 .get_bssid
= wpa_driver_nl80211_get_bssid
,
4636 .get_ssid
= wpa_driver_nl80211_get_ssid
,
4637 .set_key
= wpa_driver_nl80211_set_key
,
4638 .scan2
= wpa_driver_nl80211_scan
,
4639 .get_scan_results2
= wpa_driver_nl80211_get_scan_results
,
4640 .deauthenticate
= wpa_driver_nl80211_deauthenticate
,
4641 .disassociate
= wpa_driver_nl80211_disassociate
,
4642 .authenticate
= wpa_driver_nl80211_authenticate
,
4643 .associate
= wpa_driver_nl80211_associate
,
4644 .init
= wpa_driver_nl80211_init
,
4645 .deinit
= wpa_driver_nl80211_deinit
,
4646 .get_capa
= wpa_driver_nl80211_get_capa
,
4647 .set_operstate
= wpa_driver_nl80211_set_operstate
,
4648 .set_supp_port
= wpa_driver_nl80211_set_supp_port
,
4649 .set_country
= wpa_driver_nl80211_set_country
,
4650 .set_beacon
= wpa_driver_nl80211_set_beacon
,
4651 .if_add
= wpa_driver_nl80211_if_add
,
4652 .if_remove
= wpa_driver_nl80211_if_remove
,
4653 .send_mlme
= wpa_driver_nl80211_send_mlme
,
4654 .get_hw_feature_data
= wpa_driver_nl80211_get_hw_feature_data
,
4655 .sta_add
= wpa_driver_nl80211_sta_add
,
4656 .sta_remove
= wpa_driver_nl80211_sta_remove
,
4657 .hapd_send_eapol
= wpa_driver_nl80211_hapd_send_eapol
,
4658 .sta_set_flags
= wpa_driver_nl80211_sta_set_flags
,
4660 .hapd_init
= i802_init
,
4661 .hapd_deinit
= i802_deinit
,
4662 .get_seqnum
= i802_get_seqnum
,
4663 .flush
= i802_flush
,
4664 .read_sta_data
= i802_read_sta_data
,
4665 .sta_deauth
= i802_sta_deauth
,
4666 .sta_disassoc
= i802_sta_disassoc
,
4667 .get_inact_sec
= i802_get_inact_sec
,
4668 .sta_clear_stats
= i802_sta_clear_stats
,
4669 .set_freq
= i802_set_freq
,
4670 .set_rts
= i802_set_rts
,
4671 .set_frag
= i802_set_frag
,
4672 .set_rate_sets
= i802_set_rate_sets
,
4673 .set_cts_protect
= i802_set_cts_protect
,
4674 .set_preamble
= i802_set_preamble
,
4675 .set_short_slot_time
= i802_set_short_slot_time
,
4676 .set_tx_queue_params
= i802_set_tx_queue_params
,
4677 .set_sta_vlan
= i802_set_sta_vlan
,
4678 .set_wds_sta
= i802_set_wds_sta
,
4679 #endif /* HOSTAPD */
4680 .remain_on_channel
= wpa_driver_nl80211_remain_on_channel
,
4681 .cancel_remain_on_channel
=
4682 wpa_driver_nl80211_cancel_remain_on_channel
,
4683 .probe_req_report
= wpa_driver_nl80211_probe_req_report
,
4684 .alloc_interface_addr
= wpa_driver_nl80211_alloc_interface_addr
,
4685 .release_interface_addr
= wpa_driver_nl80211_release_interface_addr
,
4686 .disable_11b_rates
= wpa_driver_nl80211_disable_11b_rates
,