driver_nl80211_event.c 65 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275
  1. /*
  2. * Driver interaction with Linux nl80211/cfg80211 - Event processing
  3. * Copyright (c) 2002-2014, Jouni Malinen <j@w1.fi>
  4. * Copyright (c) 2007, Johannes Berg <johannes@sipsolutions.net>
  5. * Copyright (c) 2009-2010, Atheros Communications
  6. *
  7. * This software may be distributed under the terms of the BSD license.
  8. * See README for more details.
  9. */
  10. #include "includes.h"
  11. #include <netlink/genl/genl.h>
  12. #include "utils/common.h"
  13. #include "utils/eloop.h"
  14. #include "common/qca-vendor.h"
  15. #include "common/qca-vendor-attr.h"
  16. #include "common/ieee802_11_defs.h"
  17. #include "common/ieee802_11_common.h"
  18. #include "driver_nl80211.h"
  19. static const char * nl80211_command_to_string(enum nl80211_commands cmd)
  20. {
  21. #define C2S(x) case x: return #x;
  22. switch (cmd) {
  23. C2S(NL80211_CMD_UNSPEC)
  24. C2S(NL80211_CMD_GET_WIPHY)
  25. C2S(NL80211_CMD_SET_WIPHY)
  26. C2S(NL80211_CMD_NEW_WIPHY)
  27. C2S(NL80211_CMD_DEL_WIPHY)
  28. C2S(NL80211_CMD_GET_INTERFACE)
  29. C2S(NL80211_CMD_SET_INTERFACE)
  30. C2S(NL80211_CMD_NEW_INTERFACE)
  31. C2S(NL80211_CMD_DEL_INTERFACE)
  32. C2S(NL80211_CMD_GET_KEY)
  33. C2S(NL80211_CMD_SET_KEY)
  34. C2S(NL80211_CMD_NEW_KEY)
  35. C2S(NL80211_CMD_DEL_KEY)
  36. C2S(NL80211_CMD_GET_BEACON)
  37. C2S(NL80211_CMD_SET_BEACON)
  38. C2S(NL80211_CMD_START_AP)
  39. C2S(NL80211_CMD_STOP_AP)
  40. C2S(NL80211_CMD_GET_STATION)
  41. C2S(NL80211_CMD_SET_STATION)
  42. C2S(NL80211_CMD_NEW_STATION)
  43. C2S(NL80211_CMD_DEL_STATION)
  44. C2S(NL80211_CMD_GET_MPATH)
  45. C2S(NL80211_CMD_SET_MPATH)
  46. C2S(NL80211_CMD_NEW_MPATH)
  47. C2S(NL80211_CMD_DEL_MPATH)
  48. C2S(NL80211_CMD_SET_BSS)
  49. C2S(NL80211_CMD_SET_REG)
  50. C2S(NL80211_CMD_REQ_SET_REG)
  51. C2S(NL80211_CMD_GET_MESH_CONFIG)
  52. C2S(NL80211_CMD_SET_MESH_CONFIG)
  53. C2S(NL80211_CMD_SET_MGMT_EXTRA_IE)
  54. C2S(NL80211_CMD_GET_REG)
  55. C2S(NL80211_CMD_GET_SCAN)
  56. C2S(NL80211_CMD_TRIGGER_SCAN)
  57. C2S(NL80211_CMD_NEW_SCAN_RESULTS)
  58. C2S(NL80211_CMD_SCAN_ABORTED)
  59. C2S(NL80211_CMD_REG_CHANGE)
  60. C2S(NL80211_CMD_AUTHENTICATE)
  61. C2S(NL80211_CMD_ASSOCIATE)
  62. C2S(NL80211_CMD_DEAUTHENTICATE)
  63. C2S(NL80211_CMD_DISASSOCIATE)
  64. C2S(NL80211_CMD_MICHAEL_MIC_FAILURE)
  65. C2S(NL80211_CMD_REG_BEACON_HINT)
  66. C2S(NL80211_CMD_JOIN_IBSS)
  67. C2S(NL80211_CMD_LEAVE_IBSS)
  68. C2S(NL80211_CMD_TESTMODE)
  69. C2S(NL80211_CMD_CONNECT)
  70. C2S(NL80211_CMD_ROAM)
  71. C2S(NL80211_CMD_DISCONNECT)
  72. C2S(NL80211_CMD_SET_WIPHY_NETNS)
  73. C2S(NL80211_CMD_GET_SURVEY)
  74. C2S(NL80211_CMD_NEW_SURVEY_RESULTS)
  75. C2S(NL80211_CMD_SET_PMKSA)
  76. C2S(NL80211_CMD_DEL_PMKSA)
  77. C2S(NL80211_CMD_FLUSH_PMKSA)
  78. C2S(NL80211_CMD_REMAIN_ON_CHANNEL)
  79. C2S(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL)
  80. C2S(NL80211_CMD_SET_TX_BITRATE_MASK)
  81. C2S(NL80211_CMD_REGISTER_FRAME)
  82. C2S(NL80211_CMD_FRAME)
  83. C2S(NL80211_CMD_FRAME_TX_STATUS)
  84. C2S(NL80211_CMD_SET_POWER_SAVE)
  85. C2S(NL80211_CMD_GET_POWER_SAVE)
  86. C2S(NL80211_CMD_SET_CQM)
  87. C2S(NL80211_CMD_NOTIFY_CQM)
  88. C2S(NL80211_CMD_SET_CHANNEL)
  89. C2S(NL80211_CMD_SET_WDS_PEER)
  90. C2S(NL80211_CMD_FRAME_WAIT_CANCEL)
  91. C2S(NL80211_CMD_JOIN_MESH)
  92. C2S(NL80211_CMD_LEAVE_MESH)
  93. C2S(NL80211_CMD_UNPROT_DEAUTHENTICATE)
  94. C2S(NL80211_CMD_UNPROT_DISASSOCIATE)
  95. C2S(NL80211_CMD_NEW_PEER_CANDIDATE)
  96. C2S(NL80211_CMD_GET_WOWLAN)
  97. C2S(NL80211_CMD_SET_WOWLAN)
  98. C2S(NL80211_CMD_START_SCHED_SCAN)
  99. C2S(NL80211_CMD_STOP_SCHED_SCAN)
  100. C2S(NL80211_CMD_SCHED_SCAN_RESULTS)
  101. C2S(NL80211_CMD_SCHED_SCAN_STOPPED)
  102. C2S(NL80211_CMD_SET_REKEY_OFFLOAD)
  103. C2S(NL80211_CMD_PMKSA_CANDIDATE)
  104. C2S(NL80211_CMD_TDLS_OPER)
  105. C2S(NL80211_CMD_TDLS_MGMT)
  106. C2S(NL80211_CMD_UNEXPECTED_FRAME)
  107. C2S(NL80211_CMD_PROBE_CLIENT)
  108. C2S(NL80211_CMD_REGISTER_BEACONS)
  109. C2S(NL80211_CMD_UNEXPECTED_4ADDR_FRAME)
  110. C2S(NL80211_CMD_SET_NOACK_MAP)
  111. C2S(NL80211_CMD_CH_SWITCH_NOTIFY)
  112. C2S(NL80211_CMD_START_P2P_DEVICE)
  113. C2S(NL80211_CMD_STOP_P2P_DEVICE)
  114. C2S(NL80211_CMD_CONN_FAILED)
  115. C2S(NL80211_CMD_SET_MCAST_RATE)
  116. C2S(NL80211_CMD_SET_MAC_ACL)
  117. C2S(NL80211_CMD_RADAR_DETECT)
  118. C2S(NL80211_CMD_GET_PROTOCOL_FEATURES)
  119. C2S(NL80211_CMD_UPDATE_FT_IES)
  120. C2S(NL80211_CMD_FT_EVENT)
  121. C2S(NL80211_CMD_CRIT_PROTOCOL_START)
  122. C2S(NL80211_CMD_CRIT_PROTOCOL_STOP)
  123. C2S(NL80211_CMD_GET_COALESCE)
  124. C2S(NL80211_CMD_SET_COALESCE)
  125. C2S(NL80211_CMD_CHANNEL_SWITCH)
  126. C2S(NL80211_CMD_VENDOR)
  127. C2S(NL80211_CMD_SET_QOS_MAP)
  128. C2S(NL80211_CMD_ADD_TX_TS)
  129. C2S(NL80211_CMD_DEL_TX_TS)
  130. default:
  131. return "NL80211_CMD_UNKNOWN";
  132. }
  133. #undef C2S
  134. }
  135. static void mlme_event_auth(struct wpa_driver_nl80211_data *drv,
  136. const u8 *frame, size_t len)
  137. {
  138. const struct ieee80211_mgmt *mgmt;
  139. union wpa_event_data event;
  140. if (!(drv->capa.flags & WPA_DRIVER_FLAGS_SME) &&
  141. drv->force_connect_cmd) {
  142. /*
  143. * Avoid reporting two association events that would confuse
  144. * the core code.
  145. */
  146. wpa_printf(MSG_DEBUG,
  147. "nl80211: Ignore auth event when using driver SME");
  148. return;
  149. }
  150. wpa_printf(MSG_DEBUG, "nl80211: Authenticate event");
  151. mgmt = (const struct ieee80211_mgmt *) frame;
  152. if (len < 24 + sizeof(mgmt->u.auth)) {
  153. wpa_printf(MSG_DEBUG, "nl80211: Too short association event "
  154. "frame");
  155. return;
  156. }
  157. os_memcpy(drv->auth_bssid, mgmt->sa, ETH_ALEN);
  158. os_memset(drv->auth_attempt_bssid, 0, ETH_ALEN);
  159. os_memset(&event, 0, sizeof(event));
  160. os_memcpy(event.auth.peer, mgmt->sa, ETH_ALEN);
  161. event.auth.auth_type = le_to_host16(mgmt->u.auth.auth_alg);
  162. event.auth.auth_transaction =
  163. le_to_host16(mgmt->u.auth.auth_transaction);
  164. event.auth.status_code = le_to_host16(mgmt->u.auth.status_code);
  165. if (len > 24 + sizeof(mgmt->u.auth)) {
  166. event.auth.ies = mgmt->u.auth.variable;
  167. event.auth.ies_len = len - 24 - sizeof(mgmt->u.auth);
  168. }
  169. wpa_supplicant_event(drv->ctx, EVENT_AUTH, &event);
  170. }
  171. static void nl80211_parse_wmm_params(struct nlattr *wmm_attr,
  172. struct wmm_params *wmm_params)
  173. {
  174. struct nlattr *wmm_info[NL80211_STA_WME_MAX + 1];
  175. static struct nla_policy wme_policy[NL80211_STA_WME_MAX + 1] = {
  176. [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
  177. };
  178. if (!wmm_attr ||
  179. nla_parse_nested(wmm_info, NL80211_STA_WME_MAX, wmm_attr,
  180. wme_policy) ||
  181. !wmm_info[NL80211_STA_WME_UAPSD_QUEUES])
  182. return;
  183. wmm_params->uapsd_queues =
  184. nla_get_u8(wmm_info[NL80211_STA_WME_UAPSD_QUEUES]);
  185. wmm_params->info_bitmap |= WMM_PARAMS_UAPSD_QUEUES_INFO;
  186. }
  187. static void mlme_event_assoc(struct wpa_driver_nl80211_data *drv,
  188. const u8 *frame, size_t len, struct nlattr *wmm)
  189. {
  190. const struct ieee80211_mgmt *mgmt;
  191. union wpa_event_data event;
  192. u16 status;
  193. if (!(drv->capa.flags & WPA_DRIVER_FLAGS_SME) &&
  194. drv->force_connect_cmd) {
  195. /*
  196. * Avoid reporting two association events that would confuse
  197. * the core code.
  198. */
  199. wpa_printf(MSG_DEBUG,
  200. "nl80211: Ignore assoc event when using driver SME");
  201. return;
  202. }
  203. wpa_printf(MSG_DEBUG, "nl80211: Associate event");
  204. mgmt = (const struct ieee80211_mgmt *) frame;
  205. if (len < 24 + sizeof(mgmt->u.assoc_resp)) {
  206. wpa_printf(MSG_DEBUG, "nl80211: Too short association event "
  207. "frame");
  208. return;
  209. }
  210. status = le_to_host16(mgmt->u.assoc_resp.status_code);
  211. if (status != WLAN_STATUS_SUCCESS) {
  212. os_memset(&event, 0, sizeof(event));
  213. event.assoc_reject.bssid = mgmt->bssid;
  214. if (len > 24 + sizeof(mgmt->u.assoc_resp)) {
  215. event.assoc_reject.resp_ies =
  216. (u8 *) mgmt->u.assoc_resp.variable;
  217. event.assoc_reject.resp_ies_len =
  218. len - 24 - sizeof(mgmt->u.assoc_resp);
  219. }
  220. event.assoc_reject.status_code = status;
  221. wpa_supplicant_event(drv->ctx, EVENT_ASSOC_REJECT, &event);
  222. return;
  223. }
  224. drv->associated = 1;
  225. os_memcpy(drv->bssid, mgmt->sa, ETH_ALEN);
  226. os_memcpy(drv->prev_bssid, mgmt->sa, ETH_ALEN);
  227. os_memset(&event, 0, sizeof(event));
  228. if (len > 24 + sizeof(mgmt->u.assoc_resp)) {
  229. event.assoc_info.resp_ies = (u8 *) mgmt->u.assoc_resp.variable;
  230. event.assoc_info.resp_ies_len =
  231. len - 24 - sizeof(mgmt->u.assoc_resp);
  232. }
  233. event.assoc_info.freq = drv->assoc_freq;
  234. nl80211_parse_wmm_params(wmm, &event.assoc_info.wmm_params);
  235. wpa_supplicant_event(drv->ctx, EVENT_ASSOC, &event);
  236. }
  237. static void mlme_event_connect(struct wpa_driver_nl80211_data *drv,
  238. enum nl80211_commands cmd, struct nlattr *status,
  239. struct nlattr *addr, struct nlattr *req_ie,
  240. struct nlattr *resp_ie,
  241. struct nlattr *authorized,
  242. struct nlattr *key_replay_ctr,
  243. struct nlattr *ptk_kck,
  244. struct nlattr *ptk_kek,
  245. struct nlattr *subnet_status)
  246. {
  247. union wpa_event_data event;
  248. const u8 *ssid;
  249. u16 status_code;
  250. if (drv->capa.flags & WPA_DRIVER_FLAGS_SME) {
  251. /*
  252. * Avoid reporting two association events that would confuse
  253. * the core code.
  254. */
  255. wpa_printf(MSG_DEBUG, "nl80211: Ignore connect event (cmd=%d) "
  256. "when using userspace SME", cmd);
  257. return;
  258. }
  259. status_code = status ? nla_get_u16(status) : WLAN_STATUS_SUCCESS;
  260. if (cmd == NL80211_CMD_CONNECT) {
  261. wpa_printf(MSG_DEBUG,
  262. "nl80211: Connect event (status=%u ignore_next_local_disconnect=%d)",
  263. status_code, drv->ignore_next_local_disconnect);
  264. } else if (cmd == NL80211_CMD_ROAM) {
  265. wpa_printf(MSG_DEBUG, "nl80211: Roam event");
  266. }
  267. os_memset(&event, 0, sizeof(event));
  268. if (cmd == NL80211_CMD_CONNECT && status_code != WLAN_STATUS_SUCCESS) {
  269. if (addr)
  270. event.assoc_reject.bssid = nla_data(addr);
  271. if (drv->ignore_next_local_disconnect) {
  272. drv->ignore_next_local_disconnect = 0;
  273. if (!event.assoc_reject.bssid ||
  274. (os_memcmp(event.assoc_reject.bssid,
  275. drv->auth_attempt_bssid,
  276. ETH_ALEN) != 0)) {
  277. /*
  278. * Ignore the event that came without a BSSID or
  279. * for the old connection since this is likely
  280. * not relevant to the new Connect command.
  281. */
  282. wpa_printf(MSG_DEBUG,
  283. "nl80211: Ignore connection failure event triggered during reassociation");
  284. return;
  285. }
  286. }
  287. if (resp_ie) {
  288. event.assoc_reject.resp_ies = nla_data(resp_ie);
  289. event.assoc_reject.resp_ies_len = nla_len(resp_ie);
  290. }
  291. event.assoc_reject.status_code = status_code;
  292. wpa_supplicant_event(drv->ctx, EVENT_ASSOC_REJECT, &event);
  293. return;
  294. }
  295. drv->associated = 1;
  296. if (addr) {
  297. os_memcpy(drv->bssid, nla_data(addr), ETH_ALEN);
  298. os_memcpy(drv->prev_bssid, drv->bssid, ETH_ALEN);
  299. }
  300. if (req_ie) {
  301. event.assoc_info.req_ies = nla_data(req_ie);
  302. event.assoc_info.req_ies_len = nla_len(req_ie);
  303. if (cmd == NL80211_CMD_ROAM) {
  304. ssid = nl80211_get_ie(event.assoc_info.req_ies,
  305. event.assoc_info.req_ies_len,
  306. WLAN_EID_SSID);
  307. if (ssid && ssid[1] > 0 && ssid[1] <= 32) {
  308. drv->ssid_len = ssid[1];
  309. os_memcpy(drv->ssid, ssid + 2, ssid[1]);
  310. }
  311. }
  312. }
  313. if (resp_ie) {
  314. event.assoc_info.resp_ies = nla_data(resp_ie);
  315. event.assoc_info.resp_ies_len = nla_len(resp_ie);
  316. }
  317. event.assoc_info.freq = nl80211_get_assoc_freq(drv);
  318. if (authorized && nla_get_u8(authorized)) {
  319. event.assoc_info.authorized = 1;
  320. wpa_printf(MSG_DEBUG, "nl80211: connection authorized");
  321. }
  322. if (key_replay_ctr) {
  323. event.assoc_info.key_replay_ctr = nla_data(key_replay_ctr);
  324. event.assoc_info.key_replay_ctr_len = nla_len(key_replay_ctr);
  325. }
  326. if (ptk_kck) {
  327. event.assoc_info.ptk_kck = nla_data(ptk_kck);
  328. event.assoc_info.ptk_kck_len = nla_len(ptk_kck);
  329. }
  330. if (ptk_kek) {
  331. event.assoc_info.ptk_kek = nla_data(ptk_kek);
  332. event.assoc_info.ptk_kek_len = nla_len(ptk_kek);
  333. }
  334. if (subnet_status) {
  335. /*
  336. * At least for now, this is only available from
  337. * QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_SUBNET_STATUS and that
  338. * attribute has the same values 0, 1, 2 as are used in the
  339. * variable here, so no mapping between different values are
  340. * needed.
  341. */
  342. event.assoc_info.subnet_status = nla_get_u8(subnet_status);
  343. }
  344. wpa_supplicant_event(drv->ctx, EVENT_ASSOC, &event);
  345. }
  346. static void mlme_event_disconnect(struct wpa_driver_nl80211_data *drv,
  347. struct nlattr *reason, struct nlattr *addr,
  348. struct nlattr *by_ap)
  349. {
  350. union wpa_event_data data;
  351. unsigned int locally_generated = by_ap == NULL;
  352. if (drv->capa.flags & WPA_DRIVER_FLAGS_SME) {
  353. /*
  354. * Avoid reporting two disassociation events that could
  355. * confuse the core code.
  356. */
  357. wpa_printf(MSG_DEBUG, "nl80211: Ignore disconnect "
  358. "event when using userspace SME");
  359. return;
  360. }
  361. if (drv->ignore_next_local_disconnect) {
  362. drv->ignore_next_local_disconnect = 0;
  363. if (locally_generated) {
  364. wpa_printf(MSG_DEBUG, "nl80211: Ignore disconnect "
  365. "event triggered during reassociation");
  366. return;
  367. }
  368. wpa_printf(MSG_WARNING, "nl80211: Was expecting local "
  369. "disconnect but got another disconnect "
  370. "event first");
  371. }
  372. wpa_printf(MSG_DEBUG, "nl80211: Disconnect event");
  373. nl80211_mark_disconnected(drv);
  374. os_memset(&data, 0, sizeof(data));
  375. if (reason)
  376. data.deauth_info.reason_code = nla_get_u16(reason);
  377. data.deauth_info.locally_generated = by_ap == NULL;
  378. wpa_supplicant_event(drv->ctx, EVENT_DEAUTH, &data);
  379. }
  380. static int calculate_chan_offset(int width, int freq, int cf1, int cf2)
  381. {
  382. int freq1 = 0;
  383. switch (convert2width(width)) {
  384. case CHAN_WIDTH_20_NOHT:
  385. case CHAN_WIDTH_20:
  386. return 0;
  387. case CHAN_WIDTH_40:
  388. freq1 = cf1 - 10;
  389. break;
  390. case CHAN_WIDTH_80:
  391. freq1 = cf1 - 30;
  392. break;
  393. case CHAN_WIDTH_160:
  394. freq1 = cf1 - 70;
  395. break;
  396. case CHAN_WIDTH_UNKNOWN:
  397. case CHAN_WIDTH_80P80:
  398. /* FIXME: implement this */
  399. return 0;
  400. }
  401. return (abs(freq - freq1) / 20) % 2 == 0 ? 1 : -1;
  402. }
  403. static void mlme_event_ch_switch(struct wpa_driver_nl80211_data *drv,
  404. struct nlattr *ifindex, struct nlattr *freq,
  405. struct nlattr *type, struct nlattr *bw,
  406. struct nlattr *cf1, struct nlattr *cf2)
  407. {
  408. struct i802_bss *bss;
  409. union wpa_event_data data;
  410. int ht_enabled = 1;
  411. int chan_offset = 0;
  412. int ifidx;
  413. wpa_printf(MSG_DEBUG, "nl80211: Channel switch event");
  414. if (!freq)
  415. return;
  416. ifidx = nla_get_u32(ifindex);
  417. bss = get_bss_ifindex(drv, ifidx);
  418. if (bss == NULL) {
  419. wpa_printf(MSG_WARNING, "nl80211: Unknown ifindex (%d) for channel switch, ignoring",
  420. ifidx);
  421. return;
  422. }
  423. if (type) {
  424. enum nl80211_channel_type ch_type = nla_get_u32(type);
  425. wpa_printf(MSG_DEBUG, "nl80211: Channel type: %d", ch_type);
  426. switch (ch_type) {
  427. case NL80211_CHAN_NO_HT:
  428. ht_enabled = 0;
  429. break;
  430. case NL80211_CHAN_HT20:
  431. break;
  432. case NL80211_CHAN_HT40PLUS:
  433. chan_offset = 1;
  434. break;
  435. case NL80211_CHAN_HT40MINUS:
  436. chan_offset = -1;
  437. break;
  438. }
  439. } else if (bw && cf1) {
  440. /* This can happen for example with VHT80 ch switch */
  441. chan_offset = calculate_chan_offset(nla_get_u32(bw),
  442. nla_get_u32(freq),
  443. nla_get_u32(cf1),
  444. cf2 ? nla_get_u32(cf2) : 0);
  445. } else {
  446. wpa_printf(MSG_WARNING, "nl80211: Unknown secondary channel information - following channel definition calculations may fail");
  447. }
  448. os_memset(&data, 0, sizeof(data));
  449. data.ch_switch.freq = nla_get_u32(freq);
  450. data.ch_switch.ht_enabled = ht_enabled;
  451. data.ch_switch.ch_offset = chan_offset;
  452. if (bw)
  453. data.ch_switch.ch_width = convert2width(nla_get_u32(bw));
  454. if (cf1)
  455. data.ch_switch.cf1 = nla_get_u32(cf1);
  456. if (cf2)
  457. data.ch_switch.cf2 = nla_get_u32(cf2);
  458. bss->freq = data.ch_switch.freq;
  459. wpa_supplicant_event(bss->ctx, EVENT_CH_SWITCH, &data);
  460. }
  461. static void mlme_timeout_event(struct wpa_driver_nl80211_data *drv,
  462. enum nl80211_commands cmd, struct nlattr *addr)
  463. {
  464. union wpa_event_data event;
  465. enum wpa_event_type ev;
  466. if (nla_len(addr) != ETH_ALEN)
  467. return;
  468. wpa_printf(MSG_DEBUG, "nl80211: MLME event %d; timeout with " MACSTR,
  469. cmd, MAC2STR((u8 *) nla_data(addr)));
  470. if (cmd == NL80211_CMD_AUTHENTICATE)
  471. ev = EVENT_AUTH_TIMED_OUT;
  472. else if (cmd == NL80211_CMD_ASSOCIATE)
  473. ev = EVENT_ASSOC_TIMED_OUT;
  474. else
  475. return;
  476. os_memset(&event, 0, sizeof(event));
  477. os_memcpy(event.timeout_event.addr, nla_data(addr), ETH_ALEN);
  478. wpa_supplicant_event(drv->ctx, ev, &event);
  479. }
  480. static void mlme_event_mgmt(struct i802_bss *bss,
  481. struct nlattr *freq, struct nlattr *sig,
  482. const u8 *frame, size_t len)
  483. {
  484. struct wpa_driver_nl80211_data *drv = bss->drv;
  485. const struct ieee80211_mgmt *mgmt;
  486. union wpa_event_data event;
  487. u16 fc, stype;
  488. int ssi_signal = 0;
  489. int rx_freq = 0;
  490. wpa_printf(MSG_MSGDUMP, "nl80211: Frame event");
  491. mgmt = (const struct ieee80211_mgmt *) frame;
  492. if (len < 24) {
  493. wpa_printf(MSG_DEBUG, "nl80211: Too short management frame");
  494. return;
  495. }
  496. fc = le_to_host16(mgmt->frame_control);
  497. stype = WLAN_FC_GET_STYPE(fc);
  498. if (sig)
  499. ssi_signal = (s32) nla_get_u32(sig);
  500. os_memset(&event, 0, sizeof(event));
  501. if (freq) {
  502. event.rx_mgmt.freq = nla_get_u32(freq);
  503. rx_freq = drv->last_mgmt_freq = event.rx_mgmt.freq;
  504. }
  505. wpa_printf(MSG_DEBUG,
  506. "nl80211: RX frame sa=" MACSTR
  507. " freq=%d ssi_signal=%d fc=0x%x seq_ctrl=0x%x stype=%u (%s) len=%u",
  508. MAC2STR(mgmt->sa), rx_freq, ssi_signal, fc,
  509. le_to_host16(mgmt->seq_ctrl), stype, fc2str(fc),
  510. (unsigned int) len);
  511. event.rx_mgmt.frame = frame;
  512. event.rx_mgmt.frame_len = len;
  513. event.rx_mgmt.ssi_signal = ssi_signal;
  514. event.rx_mgmt.drv_priv = bss;
  515. wpa_supplicant_event(drv->ctx, EVENT_RX_MGMT, &event);
  516. }
  517. static void mlme_event_mgmt_tx_status(struct wpa_driver_nl80211_data *drv,
  518. struct nlattr *cookie, const u8 *frame,
  519. size_t len, struct nlattr *ack)
  520. {
  521. union wpa_event_data event;
  522. const struct ieee80211_hdr *hdr;
  523. u16 fc;
  524. wpa_printf(MSG_DEBUG, "nl80211: Frame TX status event");
  525. if (!is_ap_interface(drv->nlmode)) {
  526. u64 cookie_val;
  527. if (!cookie)
  528. return;
  529. cookie_val = nla_get_u64(cookie);
  530. wpa_printf(MSG_DEBUG, "nl80211: Action TX status:"
  531. " cookie=0%llx%s (ack=%d)",
  532. (long long unsigned int) cookie_val,
  533. cookie_val == drv->send_action_cookie ?
  534. " (match)" : " (unknown)", ack != NULL);
  535. if (cookie_val != drv->send_action_cookie)
  536. return;
  537. }
  538. hdr = (const struct ieee80211_hdr *) frame;
  539. fc = le_to_host16(hdr->frame_control);
  540. os_memset(&event, 0, sizeof(event));
  541. event.tx_status.type = WLAN_FC_GET_TYPE(fc);
  542. event.tx_status.stype = WLAN_FC_GET_STYPE(fc);
  543. event.tx_status.dst = hdr->addr1;
  544. event.tx_status.data = frame;
  545. event.tx_status.data_len = len;
  546. event.tx_status.ack = ack != NULL;
  547. wpa_supplicant_event(drv->ctx, EVENT_TX_STATUS, &event);
  548. }
  549. static void mlme_event_deauth_disassoc(struct wpa_driver_nl80211_data *drv,
  550. enum wpa_event_type type,
  551. const u8 *frame, size_t len)
  552. {
  553. const struct ieee80211_mgmt *mgmt;
  554. union wpa_event_data event;
  555. const u8 *bssid = NULL;
  556. u16 reason_code = 0;
  557. if (type == EVENT_DEAUTH)
  558. wpa_printf(MSG_DEBUG, "nl80211: Deauthenticate event");
  559. else
  560. wpa_printf(MSG_DEBUG, "nl80211: Disassociate event");
  561. mgmt = (const struct ieee80211_mgmt *) frame;
  562. if (len >= 24) {
  563. bssid = mgmt->bssid;
  564. if ((drv->capa.flags & WPA_DRIVER_FLAGS_SME) &&
  565. !drv->associated &&
  566. os_memcmp(bssid, drv->auth_bssid, ETH_ALEN) != 0 &&
  567. os_memcmp(bssid, drv->auth_attempt_bssid, ETH_ALEN) != 0 &&
  568. os_memcmp(bssid, drv->prev_bssid, ETH_ALEN) == 0) {
  569. /*
  570. * Avoid issues with some roaming cases where
  571. * disconnection event for the old AP may show up after
  572. * we have started connection with the new AP.
  573. * In case of locally generated event clear
  574. * ignore_next_local_deauth as well, to avoid next local
  575. * deauth event be wrongly ignored.
  576. */
  577. if (!os_memcmp(mgmt->sa, drv->first_bss->addr,
  578. ETH_ALEN)) {
  579. wpa_printf(MSG_DEBUG,
  580. "nl80211: Received a locally generated deauth event. Clear ignore_next_local_deauth flag");
  581. drv->ignore_next_local_deauth = 0;
  582. } else {
  583. wpa_printf(MSG_DEBUG,
  584. "nl80211: Ignore deauth/disassoc event from old AP " MACSTR " when already authenticating with " MACSTR,
  585. MAC2STR(bssid),
  586. MAC2STR(drv->auth_attempt_bssid));
  587. }
  588. return;
  589. }
  590. if (drv->associated != 0 &&
  591. os_memcmp(bssid, drv->bssid, ETH_ALEN) != 0 &&
  592. os_memcmp(bssid, drv->auth_bssid, ETH_ALEN) != 0) {
  593. /*
  594. * We have presumably received this deauth as a
  595. * response to a clear_state_mismatch() outgoing
  596. * deauth. Don't let it take us offline!
  597. */
  598. wpa_printf(MSG_DEBUG, "nl80211: Deauth received "
  599. "from Unknown BSSID " MACSTR " -- ignoring",
  600. MAC2STR(bssid));
  601. return;
  602. }
  603. }
  604. nl80211_mark_disconnected(drv);
  605. os_memset(&event, 0, sizeof(event));
  606. /* Note: Same offset for Reason Code in both frame subtypes */
  607. if (len >= 24 + sizeof(mgmt->u.deauth))
  608. reason_code = le_to_host16(mgmt->u.deauth.reason_code);
  609. if (type == EVENT_DISASSOC) {
  610. event.disassoc_info.locally_generated =
  611. !os_memcmp(mgmt->sa, drv->first_bss->addr, ETH_ALEN);
  612. event.disassoc_info.addr = bssid;
  613. event.disassoc_info.reason_code = reason_code;
  614. if (frame + len > mgmt->u.disassoc.variable) {
  615. event.disassoc_info.ie = mgmt->u.disassoc.variable;
  616. event.disassoc_info.ie_len = frame + len -
  617. mgmt->u.disassoc.variable;
  618. }
  619. } else {
  620. event.deauth_info.locally_generated =
  621. !os_memcmp(mgmt->sa, drv->first_bss->addr, ETH_ALEN);
  622. if (drv->ignore_deauth_event) {
  623. wpa_printf(MSG_DEBUG, "nl80211: Ignore deauth event due to previous forced deauth-during-auth");
  624. drv->ignore_deauth_event = 0;
  625. if (event.deauth_info.locally_generated)
  626. drv->ignore_next_local_deauth = 0;
  627. return;
  628. }
  629. if (drv->ignore_next_local_deauth) {
  630. drv->ignore_next_local_deauth = 0;
  631. if (event.deauth_info.locally_generated) {
  632. wpa_printf(MSG_DEBUG, "nl80211: Ignore deauth event triggered due to own deauth request");
  633. return;
  634. }
  635. wpa_printf(MSG_WARNING, "nl80211: Was expecting local deauth but got another disconnect event first");
  636. }
  637. event.deauth_info.addr = bssid;
  638. event.deauth_info.reason_code = reason_code;
  639. if (frame + len > mgmt->u.deauth.variable) {
  640. event.deauth_info.ie = mgmt->u.deauth.variable;
  641. event.deauth_info.ie_len = frame + len -
  642. mgmt->u.deauth.variable;
  643. }
  644. }
  645. wpa_supplicant_event(drv->ctx, type, &event);
  646. }
  647. static void mlme_event_unprot_disconnect(struct wpa_driver_nl80211_data *drv,
  648. enum wpa_event_type type,
  649. const u8 *frame, size_t len)
  650. {
  651. const struct ieee80211_mgmt *mgmt;
  652. union wpa_event_data event;
  653. u16 reason_code = 0;
  654. if (type == EVENT_UNPROT_DEAUTH)
  655. wpa_printf(MSG_DEBUG, "nl80211: Unprot Deauthenticate event");
  656. else
  657. wpa_printf(MSG_DEBUG, "nl80211: Unprot Disassociate event");
  658. if (len < 24)
  659. return;
  660. mgmt = (const struct ieee80211_mgmt *) frame;
  661. os_memset(&event, 0, sizeof(event));
  662. /* Note: Same offset for Reason Code in both frame subtypes */
  663. if (len >= 24 + sizeof(mgmt->u.deauth))
  664. reason_code = le_to_host16(mgmt->u.deauth.reason_code);
  665. if (type == EVENT_UNPROT_DISASSOC) {
  666. event.unprot_disassoc.sa = mgmt->sa;
  667. event.unprot_disassoc.da = mgmt->da;
  668. event.unprot_disassoc.reason_code = reason_code;
  669. } else {
  670. event.unprot_deauth.sa = mgmt->sa;
  671. event.unprot_deauth.da = mgmt->da;
  672. event.unprot_deauth.reason_code = reason_code;
  673. }
  674. wpa_supplicant_event(drv->ctx, type, &event);
  675. }
  676. static void mlme_event(struct i802_bss *bss,
  677. enum nl80211_commands cmd, struct nlattr *frame,
  678. struct nlattr *addr, struct nlattr *timed_out,
  679. struct nlattr *freq, struct nlattr *ack,
  680. struct nlattr *cookie, struct nlattr *sig,
  681. struct nlattr *wmm)
  682. {
  683. struct wpa_driver_nl80211_data *drv = bss->drv;
  684. const u8 *data;
  685. size_t len;
  686. if (timed_out && addr) {
  687. mlme_timeout_event(drv, cmd, addr);
  688. return;
  689. }
  690. if (frame == NULL) {
  691. wpa_printf(MSG_DEBUG,
  692. "nl80211: MLME event %d (%s) without frame data",
  693. cmd, nl80211_command_to_string(cmd));
  694. return;
  695. }
  696. data = nla_data(frame);
  697. len = nla_len(frame);
  698. if (len < 4 + 2 * ETH_ALEN) {
  699. wpa_printf(MSG_MSGDUMP, "nl80211: MLME event %d (%s) on %s("
  700. MACSTR ") - too short",
  701. cmd, nl80211_command_to_string(cmd), bss->ifname,
  702. MAC2STR(bss->addr));
  703. return;
  704. }
  705. wpa_printf(MSG_MSGDUMP, "nl80211: MLME event %d (%s) on %s(" MACSTR
  706. ") A1=" MACSTR " A2=" MACSTR, cmd,
  707. nl80211_command_to_string(cmd), bss->ifname,
  708. MAC2STR(bss->addr), MAC2STR(data + 4),
  709. MAC2STR(data + 4 + ETH_ALEN));
  710. if (cmd != NL80211_CMD_FRAME_TX_STATUS && !(data[4] & 0x01) &&
  711. os_memcmp(bss->addr, data + 4, ETH_ALEN) != 0 &&
  712. os_memcmp(bss->addr, data + 4 + ETH_ALEN, ETH_ALEN) != 0) {
  713. wpa_printf(MSG_MSGDUMP, "nl80211: %s: Ignore MLME frame event "
  714. "for foreign address", bss->ifname);
  715. return;
  716. }
  717. wpa_hexdump(MSG_MSGDUMP, "nl80211: MLME event frame",
  718. nla_data(frame), nla_len(frame));
  719. switch (cmd) {
  720. case NL80211_CMD_AUTHENTICATE:
  721. mlme_event_auth(drv, nla_data(frame), nla_len(frame));
  722. break;
  723. case NL80211_CMD_ASSOCIATE:
  724. mlme_event_assoc(drv, nla_data(frame), nla_len(frame), wmm);
  725. break;
  726. case NL80211_CMD_DEAUTHENTICATE:
  727. mlme_event_deauth_disassoc(drv, EVENT_DEAUTH,
  728. nla_data(frame), nla_len(frame));
  729. break;
  730. case NL80211_CMD_DISASSOCIATE:
  731. mlme_event_deauth_disassoc(drv, EVENT_DISASSOC,
  732. nla_data(frame), nla_len(frame));
  733. break;
  734. case NL80211_CMD_FRAME:
  735. mlme_event_mgmt(bss, freq, sig, nla_data(frame),
  736. nla_len(frame));
  737. break;
  738. case NL80211_CMD_FRAME_TX_STATUS:
  739. mlme_event_mgmt_tx_status(drv, cookie, nla_data(frame),
  740. nla_len(frame), ack);
  741. break;
  742. case NL80211_CMD_UNPROT_DEAUTHENTICATE:
  743. mlme_event_unprot_disconnect(drv, EVENT_UNPROT_DEAUTH,
  744. nla_data(frame), nla_len(frame));
  745. break;
  746. case NL80211_CMD_UNPROT_DISASSOCIATE:
  747. mlme_event_unprot_disconnect(drv, EVENT_UNPROT_DISASSOC,
  748. nla_data(frame), nla_len(frame));
  749. break;
  750. default:
  751. break;
  752. }
  753. }
  754. static void mlme_event_michael_mic_failure(struct i802_bss *bss,
  755. struct nlattr *tb[])
  756. {
  757. union wpa_event_data data;
  758. wpa_printf(MSG_DEBUG, "nl80211: MLME event Michael MIC failure");
  759. os_memset(&data, 0, sizeof(data));
  760. if (tb[NL80211_ATTR_MAC]) {
  761. wpa_hexdump(MSG_DEBUG, "nl80211: Source MAC address",
  762. nla_data(tb[NL80211_ATTR_MAC]),
  763. nla_len(tb[NL80211_ATTR_MAC]));
  764. data.michael_mic_failure.src = nla_data(tb[NL80211_ATTR_MAC]);
  765. }
  766. if (tb[NL80211_ATTR_KEY_SEQ]) {
  767. wpa_hexdump(MSG_DEBUG, "nl80211: TSC",
  768. nla_data(tb[NL80211_ATTR_KEY_SEQ]),
  769. nla_len(tb[NL80211_ATTR_KEY_SEQ]));
  770. }
  771. if (tb[NL80211_ATTR_KEY_TYPE]) {
  772. enum nl80211_key_type key_type =
  773. nla_get_u32(tb[NL80211_ATTR_KEY_TYPE]);
  774. wpa_printf(MSG_DEBUG, "nl80211: Key Type %d", key_type);
  775. if (key_type == NL80211_KEYTYPE_PAIRWISE)
  776. data.michael_mic_failure.unicast = 1;
  777. } else
  778. data.michael_mic_failure.unicast = 1;
  779. if (tb[NL80211_ATTR_KEY_IDX]) {
  780. u8 key_id = nla_get_u8(tb[NL80211_ATTR_KEY_IDX]);
  781. wpa_printf(MSG_DEBUG, "nl80211: Key Id %d", key_id);
  782. }
  783. wpa_supplicant_event(bss->ctx, EVENT_MICHAEL_MIC_FAILURE, &data);
  784. }
  785. static void mlme_event_join_ibss(struct wpa_driver_nl80211_data *drv,
  786. struct nlattr *tb[])
  787. {
  788. unsigned int freq;
  789. if (tb[NL80211_ATTR_MAC] == NULL) {
  790. wpa_printf(MSG_DEBUG, "nl80211: No address in IBSS joined "
  791. "event");
  792. return;
  793. }
  794. os_memcpy(drv->bssid, nla_data(tb[NL80211_ATTR_MAC]), ETH_ALEN);
  795. drv->associated = 1;
  796. wpa_printf(MSG_DEBUG, "nl80211: IBSS " MACSTR " joined",
  797. MAC2STR(drv->bssid));
  798. freq = nl80211_get_assoc_freq(drv);
  799. if (freq) {
  800. wpa_printf(MSG_DEBUG, "nl80211: IBSS on frequency %u MHz",
  801. freq);
  802. drv->first_bss->freq = freq;
  803. }
  804. wpa_supplicant_event(drv->ctx, EVENT_ASSOC, NULL);
  805. }
  806. static void mlme_event_remain_on_channel(struct wpa_driver_nl80211_data *drv,
  807. int cancel_event, struct nlattr *tb[])
  808. {
  809. unsigned int freq, chan_type, duration;
  810. union wpa_event_data data;
  811. u64 cookie;
  812. if (tb[NL80211_ATTR_WIPHY_FREQ])
  813. freq = nla_get_u32(tb[NL80211_ATTR_WIPHY_FREQ]);
  814. else
  815. freq = 0;
  816. if (tb[NL80211_ATTR_WIPHY_CHANNEL_TYPE])
  817. chan_type = nla_get_u32(tb[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
  818. else
  819. chan_type = 0;
  820. if (tb[NL80211_ATTR_DURATION])
  821. duration = nla_get_u32(tb[NL80211_ATTR_DURATION]);
  822. else
  823. duration = 0;
  824. if (tb[NL80211_ATTR_COOKIE])
  825. cookie = nla_get_u64(tb[NL80211_ATTR_COOKIE]);
  826. else
  827. cookie = 0;
  828. wpa_printf(MSG_DEBUG, "nl80211: Remain-on-channel event (cancel=%d "
  829. "freq=%u channel_type=%u duration=%u cookie=0x%llx (%s))",
  830. cancel_event, freq, chan_type, duration,
  831. (long long unsigned int) cookie,
  832. cookie == drv->remain_on_chan_cookie ? "match" : "unknown");
  833. if (cookie != drv->remain_on_chan_cookie)
  834. return; /* not for us */
  835. if (cancel_event)
  836. drv->pending_remain_on_chan = 0;
  837. os_memset(&data, 0, sizeof(data));
  838. data.remain_on_channel.freq = freq;
  839. data.remain_on_channel.duration = duration;
  840. wpa_supplicant_event(drv->ctx, cancel_event ?
  841. EVENT_CANCEL_REMAIN_ON_CHANNEL :
  842. EVENT_REMAIN_ON_CHANNEL, &data);
  843. }
  844. static void mlme_event_ft_event(struct wpa_driver_nl80211_data *drv,
  845. struct nlattr *tb[])
  846. {
  847. union wpa_event_data data;
  848. os_memset(&data, 0, sizeof(data));
  849. if (tb[NL80211_ATTR_IE]) {
  850. data.ft_ies.ies = nla_data(tb[NL80211_ATTR_IE]);
  851. data.ft_ies.ies_len = nla_len(tb[NL80211_ATTR_IE]);
  852. }
  853. if (tb[NL80211_ATTR_IE_RIC]) {
  854. data.ft_ies.ric_ies = nla_data(tb[NL80211_ATTR_IE_RIC]);
  855. data.ft_ies.ric_ies_len = nla_len(tb[NL80211_ATTR_IE_RIC]);
  856. }
  857. if (tb[NL80211_ATTR_MAC])
  858. os_memcpy(data.ft_ies.target_ap,
  859. nla_data(tb[NL80211_ATTR_MAC]), ETH_ALEN);
  860. wpa_printf(MSG_DEBUG, "nl80211: FT event target_ap " MACSTR,
  861. MAC2STR(data.ft_ies.target_ap));
  862. wpa_supplicant_event(drv->ctx, EVENT_FT_RESPONSE, &data);
  863. }
  864. static void send_scan_event(struct wpa_driver_nl80211_data *drv, int aborted,
  865. struct nlattr *tb[], int external_scan)
  866. {
  867. union wpa_event_data event;
  868. struct nlattr *nl;
  869. int rem;
  870. struct scan_info *info;
  871. #define MAX_REPORT_FREQS 50
  872. int freqs[MAX_REPORT_FREQS];
  873. int num_freqs = 0;
  874. if (!external_scan && drv->scan_for_auth) {
  875. drv->scan_for_auth = 0;
  876. wpa_printf(MSG_DEBUG, "nl80211: Scan results for missing "
  877. "cfg80211 BSS entry");
  878. wpa_driver_nl80211_authenticate_retry(drv);
  879. return;
  880. }
  881. os_memset(&event, 0, sizeof(event));
  882. info = &event.scan_info;
  883. info->aborted = aborted;
  884. info->external_scan = external_scan;
  885. info->nl_scan_event = 1;
  886. if (tb[NL80211_ATTR_SCAN_SSIDS]) {
  887. nla_for_each_nested(nl, tb[NL80211_ATTR_SCAN_SSIDS], rem) {
  888. struct wpa_driver_scan_ssid *s =
  889. &info->ssids[info->num_ssids];
  890. s->ssid = nla_data(nl);
  891. s->ssid_len = nla_len(nl);
  892. wpa_printf(MSG_DEBUG, "nl80211: Scan probed for SSID '%s'",
  893. wpa_ssid_txt(s->ssid, s->ssid_len));
  894. info->num_ssids++;
  895. if (info->num_ssids == WPAS_MAX_SCAN_SSIDS)
  896. break;
  897. }
  898. }
  899. if (tb[NL80211_ATTR_SCAN_FREQUENCIES]) {
  900. char msg[300], *pos, *end;
  901. int res;
  902. pos = msg;
  903. end = pos + sizeof(msg);
  904. *pos = '\0';
  905. nla_for_each_nested(nl, tb[NL80211_ATTR_SCAN_FREQUENCIES], rem)
  906. {
  907. freqs[num_freqs] = nla_get_u32(nl);
  908. res = os_snprintf(pos, end - pos, " %d",
  909. freqs[num_freqs]);
  910. if (!os_snprintf_error(end - pos, res))
  911. pos += res;
  912. num_freqs++;
  913. if (num_freqs == MAX_REPORT_FREQS - 1)
  914. break;
  915. }
  916. info->freqs = freqs;
  917. info->num_freqs = num_freqs;
  918. wpa_printf(MSG_DEBUG, "nl80211: Scan included frequencies:%s",
  919. msg);
  920. }
  921. wpa_supplicant_event(drv->ctx, EVENT_SCAN_RESULTS, &event);
  922. }
  923. static void nl80211_cqm_event(struct wpa_driver_nl80211_data *drv,
  924. struct nlattr *tb[])
  925. {
  926. static struct nla_policy cqm_policy[NL80211_ATTR_CQM_MAX + 1] = {
  927. [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
  928. [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U8 },
  929. [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
  930. [NL80211_ATTR_CQM_PKT_LOSS_EVENT] = { .type = NLA_U32 },
  931. };
  932. struct nlattr *cqm[NL80211_ATTR_CQM_MAX + 1];
  933. enum nl80211_cqm_rssi_threshold_event event;
  934. union wpa_event_data ed;
  935. struct wpa_signal_info sig;
  936. int res;
  937. if (tb[NL80211_ATTR_CQM] == NULL ||
  938. nla_parse_nested(cqm, NL80211_ATTR_CQM_MAX, tb[NL80211_ATTR_CQM],
  939. cqm_policy)) {
  940. wpa_printf(MSG_DEBUG, "nl80211: Ignore invalid CQM event");
  941. return;
  942. }
  943. os_memset(&ed, 0, sizeof(ed));
  944. if (cqm[NL80211_ATTR_CQM_PKT_LOSS_EVENT]) {
  945. if (!tb[NL80211_ATTR_MAC])
  946. return;
  947. os_memcpy(ed.low_ack.addr, nla_data(tb[NL80211_ATTR_MAC]),
  948. ETH_ALEN);
  949. wpa_supplicant_event(drv->ctx, EVENT_STATION_LOW_ACK, &ed);
  950. return;
  951. }
  952. if (cqm[NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] == NULL)
  953. return;
  954. event = nla_get_u32(cqm[NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT]);
  955. if (event == NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH) {
  956. wpa_printf(MSG_DEBUG, "nl80211: Connection quality monitor "
  957. "event: RSSI high");
  958. ed.signal_change.above_threshold = 1;
  959. } else if (event == NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW) {
  960. wpa_printf(MSG_DEBUG, "nl80211: Connection quality monitor "
  961. "event: RSSI low");
  962. ed.signal_change.above_threshold = 0;
  963. } else
  964. return;
  965. res = nl80211_get_link_signal(drv, &sig);
  966. if (res == 0) {
  967. ed.signal_change.current_signal = sig.current_signal;
  968. ed.signal_change.current_txrate = sig.current_txrate;
  969. wpa_printf(MSG_DEBUG, "nl80211: Signal: %d dBm txrate: %d",
  970. sig.current_signal, sig.current_txrate);
  971. }
  972. res = nl80211_get_link_noise(drv, &sig);
  973. if (res == 0) {
  974. ed.signal_change.current_noise = sig.current_noise;
  975. wpa_printf(MSG_DEBUG, "nl80211: Noise: %d dBm",
  976. sig.current_noise);
  977. }
  978. wpa_supplicant_event(drv->ctx, EVENT_SIGNAL_CHANGE, &ed);
  979. }
  980. static void nl80211_new_peer_candidate(struct wpa_driver_nl80211_data *drv,
  981. struct nlattr **tb)
  982. {
  983. const u8 *addr;
  984. union wpa_event_data data;
  985. if (drv->nlmode != NL80211_IFTYPE_MESH_POINT ||
  986. !tb[NL80211_ATTR_MAC] || !tb[NL80211_ATTR_IE])
  987. return;
  988. addr = nla_data(tb[NL80211_ATTR_MAC]);
  989. wpa_printf(MSG_DEBUG, "nl80211: New peer candidate " MACSTR,
  990. MAC2STR(addr));
  991. os_memset(&data, 0, sizeof(data));
  992. data.mesh_peer.peer = addr;
  993. data.mesh_peer.ies = nla_data(tb[NL80211_ATTR_IE]);
  994. data.mesh_peer.ie_len = nla_len(tb[NL80211_ATTR_IE]);
  995. wpa_supplicant_event(drv->ctx, EVENT_NEW_PEER_CANDIDATE, &data);
  996. }
  997. static void nl80211_new_station_event(struct wpa_driver_nl80211_data *drv,
  998. struct i802_bss *bss,
  999. struct nlattr **tb)
  1000. {
  1001. u8 *addr;
  1002. union wpa_event_data data;
  1003. if (tb[NL80211_ATTR_MAC] == NULL)
  1004. return;
  1005. addr = nla_data(tb[NL80211_ATTR_MAC]);
  1006. wpa_printf(MSG_DEBUG, "nl80211: New station " MACSTR, MAC2STR(addr));
  1007. if (is_ap_interface(drv->nlmode) && drv->device_ap_sme) {
  1008. u8 *ies = NULL;
  1009. size_t ies_len = 0;
  1010. if (tb[NL80211_ATTR_IE]) {
  1011. ies = nla_data(tb[NL80211_ATTR_IE]);
  1012. ies_len = nla_len(tb[NL80211_ATTR_IE]);
  1013. }
  1014. wpa_hexdump(MSG_DEBUG, "nl80211: Assoc Req IEs", ies, ies_len);
  1015. drv_event_assoc(bss->ctx, addr, ies, ies_len, 0);
  1016. return;
  1017. }
  1018. if (drv->nlmode != NL80211_IFTYPE_ADHOC)
  1019. return;
  1020. os_memset(&data, 0, sizeof(data));
  1021. os_memcpy(data.ibss_rsn_start.peer, addr, ETH_ALEN);
  1022. wpa_supplicant_event(bss->ctx, EVENT_IBSS_RSN_START, &data);
  1023. }
  1024. static void nl80211_del_station_event(struct wpa_driver_nl80211_data *drv,
  1025. struct nlattr **tb)
  1026. {
  1027. u8 *addr;
  1028. union wpa_event_data data;
  1029. if (tb[NL80211_ATTR_MAC] == NULL)
  1030. return;
  1031. addr = nla_data(tb[NL80211_ATTR_MAC]);
  1032. wpa_printf(MSG_DEBUG, "nl80211: Delete station " MACSTR,
  1033. MAC2STR(addr));
  1034. if (is_ap_interface(drv->nlmode) && drv->device_ap_sme) {
  1035. drv_event_disassoc(drv->ctx, addr);
  1036. return;
  1037. }
  1038. if (drv->nlmode != NL80211_IFTYPE_ADHOC)
  1039. return;
  1040. os_memset(&data, 0, sizeof(data));
  1041. os_memcpy(data.ibss_peer_lost.peer, addr, ETH_ALEN);
  1042. wpa_supplicant_event(drv->ctx, EVENT_IBSS_PEER_LOST, &data);
  1043. }
  1044. static void nl80211_rekey_offload_event(struct wpa_driver_nl80211_data *drv,
  1045. struct nlattr **tb)
  1046. {
  1047. struct nlattr *rekey_info[NUM_NL80211_REKEY_DATA];
  1048. static struct nla_policy rekey_policy[NUM_NL80211_REKEY_DATA] = {
  1049. [NL80211_REKEY_DATA_KEK] = {
  1050. .minlen = NL80211_KEK_LEN,
  1051. .maxlen = NL80211_KEK_LEN,
  1052. },
  1053. [NL80211_REKEY_DATA_KCK] = {
  1054. .minlen = NL80211_KCK_LEN,
  1055. .maxlen = NL80211_KCK_LEN,
  1056. },
  1057. [NL80211_REKEY_DATA_REPLAY_CTR] = {
  1058. .minlen = NL80211_REPLAY_CTR_LEN,
  1059. .maxlen = NL80211_REPLAY_CTR_LEN,
  1060. },
  1061. };
  1062. union wpa_event_data data;
  1063. if (!tb[NL80211_ATTR_MAC] ||
  1064. !tb[NL80211_ATTR_REKEY_DATA] ||
  1065. nla_parse_nested(rekey_info, MAX_NL80211_REKEY_DATA,
  1066. tb[NL80211_ATTR_REKEY_DATA], rekey_policy) ||
  1067. !rekey_info[NL80211_REKEY_DATA_REPLAY_CTR])
  1068. return;
  1069. os_memset(&data, 0, sizeof(data));
  1070. data.driver_gtk_rekey.bssid = nla_data(tb[NL80211_ATTR_MAC]);
  1071. wpa_printf(MSG_DEBUG, "nl80211: Rekey offload event for BSSID " MACSTR,
  1072. MAC2STR(data.driver_gtk_rekey.bssid));
  1073. data.driver_gtk_rekey.replay_ctr =
  1074. nla_data(rekey_info[NL80211_REKEY_DATA_REPLAY_CTR]);
  1075. wpa_hexdump(MSG_DEBUG, "nl80211: Rekey offload - Replay Counter",
  1076. data.driver_gtk_rekey.replay_ctr, NL80211_REPLAY_CTR_LEN);
  1077. wpa_supplicant_event(drv->ctx, EVENT_DRIVER_GTK_REKEY, &data);
  1078. }
  1079. static void nl80211_pmksa_candidate_event(struct wpa_driver_nl80211_data *drv,
  1080. struct nlattr **tb)
  1081. {
  1082. struct nlattr *cand[NUM_NL80211_PMKSA_CANDIDATE];
  1083. static struct nla_policy cand_policy[NUM_NL80211_PMKSA_CANDIDATE] = {
  1084. [NL80211_PMKSA_CANDIDATE_INDEX] = { .type = NLA_U32 },
  1085. [NL80211_PMKSA_CANDIDATE_BSSID] = {
  1086. .minlen = ETH_ALEN,
  1087. .maxlen = ETH_ALEN,
  1088. },
  1089. [NL80211_PMKSA_CANDIDATE_PREAUTH] = { .type = NLA_FLAG },
  1090. };
  1091. union wpa_event_data data;
  1092. wpa_printf(MSG_DEBUG, "nl80211: PMKSA candidate event");
  1093. if (!tb[NL80211_ATTR_PMKSA_CANDIDATE] ||
  1094. nla_parse_nested(cand, MAX_NL80211_PMKSA_CANDIDATE,
  1095. tb[NL80211_ATTR_PMKSA_CANDIDATE], cand_policy) ||
  1096. !cand[NL80211_PMKSA_CANDIDATE_INDEX] ||
  1097. !cand[NL80211_PMKSA_CANDIDATE_BSSID])
  1098. return;
  1099. os_memset(&data, 0, sizeof(data));
  1100. os_memcpy(data.pmkid_candidate.bssid,
  1101. nla_data(cand[NL80211_PMKSA_CANDIDATE_BSSID]), ETH_ALEN);
  1102. data.pmkid_candidate.index =
  1103. nla_get_u32(cand[NL80211_PMKSA_CANDIDATE_INDEX]);
  1104. data.pmkid_candidate.preauth =
  1105. cand[NL80211_PMKSA_CANDIDATE_PREAUTH] != NULL;
  1106. wpa_supplicant_event(drv->ctx, EVENT_PMKID_CANDIDATE, &data);
  1107. }
  1108. static void nl80211_client_probe_event(struct wpa_driver_nl80211_data *drv,
  1109. struct nlattr **tb)
  1110. {
  1111. union wpa_event_data data;
  1112. wpa_printf(MSG_DEBUG, "nl80211: Probe client event");
  1113. if (!tb[NL80211_ATTR_MAC] || !tb[NL80211_ATTR_ACK])
  1114. return;
  1115. os_memset(&data, 0, sizeof(data));
  1116. os_memcpy(data.client_poll.addr,
  1117. nla_data(tb[NL80211_ATTR_MAC]), ETH_ALEN);
  1118. wpa_supplicant_event(drv->ctx, EVENT_DRIVER_CLIENT_POLL_OK, &data);
  1119. }
  1120. static void nl80211_tdls_oper_event(struct wpa_driver_nl80211_data *drv,
  1121. struct nlattr **tb)
  1122. {
  1123. union wpa_event_data data;
  1124. wpa_printf(MSG_DEBUG, "nl80211: TDLS operation event");
  1125. if (!tb[NL80211_ATTR_MAC] || !tb[NL80211_ATTR_TDLS_OPERATION])
  1126. return;
  1127. os_memset(&data, 0, sizeof(data));
  1128. os_memcpy(data.tdls.peer, nla_data(tb[NL80211_ATTR_MAC]), ETH_ALEN);
  1129. switch (nla_get_u8(tb[NL80211_ATTR_TDLS_OPERATION])) {
  1130. case NL80211_TDLS_SETUP:
  1131. wpa_printf(MSG_DEBUG, "nl80211: TDLS setup request for peer "
  1132. MACSTR, MAC2STR(data.tdls.peer));
  1133. data.tdls.oper = TDLS_REQUEST_SETUP;
  1134. break;
  1135. case NL80211_TDLS_TEARDOWN:
  1136. wpa_printf(MSG_DEBUG, "nl80211: TDLS teardown request for peer "
  1137. MACSTR, MAC2STR(data.tdls.peer));
  1138. data.tdls.oper = TDLS_REQUEST_TEARDOWN;
  1139. break;
  1140. case NL80211_TDLS_DISCOVERY_REQ:
  1141. wpa_printf(MSG_DEBUG,
  1142. "nl80211: TDLS discovery request for peer " MACSTR,
  1143. MAC2STR(data.tdls.peer));
  1144. data.tdls.oper = TDLS_REQUEST_DISCOVER;
  1145. break;
  1146. default:
  1147. wpa_printf(MSG_DEBUG, "nl80211: Unsupported TDLS operatione "
  1148. "event");
  1149. return;
  1150. }
  1151. if (tb[NL80211_ATTR_REASON_CODE]) {
  1152. data.tdls.reason_code =
  1153. nla_get_u16(tb[NL80211_ATTR_REASON_CODE]);
  1154. }
  1155. wpa_supplicant_event(drv->ctx, EVENT_TDLS, &data);
  1156. }
  1157. static void nl80211_stop_ap(struct wpa_driver_nl80211_data *drv,
  1158. struct nlattr **tb)
  1159. {
  1160. wpa_supplicant_event(drv->ctx, EVENT_INTERFACE_UNAVAILABLE, NULL);
  1161. }
  1162. static void nl80211_connect_failed_event(struct wpa_driver_nl80211_data *drv,
  1163. struct nlattr **tb)
  1164. {
  1165. union wpa_event_data data;
  1166. u32 reason;
  1167. wpa_printf(MSG_DEBUG, "nl80211: Connect failed event");
  1168. if (!tb[NL80211_ATTR_MAC] || !tb[NL80211_ATTR_CONN_FAILED_REASON])
  1169. return;
  1170. os_memset(&data, 0, sizeof(data));
  1171. os_memcpy(data.connect_failed_reason.addr,
  1172. nla_data(tb[NL80211_ATTR_MAC]), ETH_ALEN);
  1173. reason = nla_get_u32(tb[NL80211_ATTR_CONN_FAILED_REASON]);
  1174. switch (reason) {
  1175. case NL80211_CONN_FAIL_MAX_CLIENTS:
  1176. wpa_printf(MSG_DEBUG, "nl80211: Max client reached");
  1177. data.connect_failed_reason.code = MAX_CLIENT_REACHED;
  1178. break;
  1179. case NL80211_CONN_FAIL_BLOCKED_CLIENT:
  1180. wpa_printf(MSG_DEBUG, "nl80211: Blocked client " MACSTR
  1181. " tried to connect",
  1182. MAC2STR(data.connect_failed_reason.addr));
  1183. data.connect_failed_reason.code = BLOCKED_CLIENT;
  1184. break;
  1185. default:
  1186. wpa_printf(MSG_DEBUG, "nl8021l: Unknown connect failed reason "
  1187. "%u", reason);
  1188. return;
  1189. }
  1190. wpa_supplicant_event(drv->ctx, EVENT_CONNECT_FAILED_REASON, &data);
  1191. }
  1192. static void nl80211_radar_event(struct wpa_driver_nl80211_data *drv,
  1193. struct nlattr **tb)
  1194. {
  1195. union wpa_event_data data;
  1196. enum nl80211_radar_event event_type;
  1197. if (!tb[NL80211_ATTR_WIPHY_FREQ] || !tb[NL80211_ATTR_RADAR_EVENT])
  1198. return;
  1199. os_memset(&data, 0, sizeof(data));
  1200. data.dfs_event.freq = nla_get_u32(tb[NL80211_ATTR_WIPHY_FREQ]);
  1201. event_type = nla_get_u32(tb[NL80211_ATTR_RADAR_EVENT]);
  1202. /* Check HT params */
  1203. if (tb[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
  1204. data.dfs_event.ht_enabled = 1;
  1205. data.dfs_event.chan_offset = 0;
  1206. switch (nla_get_u32(tb[NL80211_ATTR_WIPHY_CHANNEL_TYPE])) {
  1207. case NL80211_CHAN_NO_HT:
  1208. data.dfs_event.ht_enabled = 0;
  1209. break;
  1210. case NL80211_CHAN_HT20:
  1211. break;
  1212. case NL80211_CHAN_HT40PLUS:
  1213. data.dfs_event.chan_offset = 1;
  1214. break;
  1215. case NL80211_CHAN_HT40MINUS:
  1216. data.dfs_event.chan_offset = -1;
  1217. break;
  1218. }
  1219. }
  1220. /* Get VHT params */
  1221. if (tb[NL80211_ATTR_CHANNEL_WIDTH])
  1222. data.dfs_event.chan_width =
  1223. convert2width(nla_get_u32(
  1224. tb[NL80211_ATTR_CHANNEL_WIDTH]));
  1225. if (tb[NL80211_ATTR_CENTER_FREQ1])
  1226. data.dfs_event.cf1 = nla_get_u32(tb[NL80211_ATTR_CENTER_FREQ1]);
  1227. if (tb[NL80211_ATTR_CENTER_FREQ2])
  1228. data.dfs_event.cf2 = nla_get_u32(tb[NL80211_ATTR_CENTER_FREQ2]);
  1229. wpa_printf(MSG_DEBUG, "nl80211: DFS event on freq %d MHz, ht: %d, offset: %d, width: %d, cf1: %dMHz, cf2: %dMHz",
  1230. data.dfs_event.freq, data.dfs_event.ht_enabled,
  1231. data.dfs_event.chan_offset, data.dfs_event.chan_width,
  1232. data.dfs_event.cf1, data.dfs_event.cf2);
  1233. switch (event_type) {
  1234. case NL80211_RADAR_DETECTED:
  1235. wpa_supplicant_event(drv->ctx, EVENT_DFS_RADAR_DETECTED, &data);
  1236. break;
  1237. case NL80211_RADAR_CAC_FINISHED:
  1238. wpa_supplicant_event(drv->ctx, EVENT_DFS_CAC_FINISHED, &data);
  1239. break;
  1240. case NL80211_RADAR_CAC_ABORTED:
  1241. wpa_supplicant_event(drv->ctx, EVENT_DFS_CAC_ABORTED, &data);
  1242. break;
  1243. case NL80211_RADAR_NOP_FINISHED:
  1244. wpa_supplicant_event(drv->ctx, EVENT_DFS_NOP_FINISHED, &data);
  1245. break;
  1246. default:
  1247. wpa_printf(MSG_DEBUG, "nl80211: Unknown radar event %d "
  1248. "received", event_type);
  1249. break;
  1250. }
  1251. }
  1252. static void nl80211_spurious_frame(struct i802_bss *bss, struct nlattr **tb,
  1253. int wds)
  1254. {
  1255. struct wpa_driver_nl80211_data *drv = bss->drv;
  1256. union wpa_event_data event;
  1257. if (!tb[NL80211_ATTR_MAC])
  1258. return;
  1259. os_memset(&event, 0, sizeof(event));
  1260. event.rx_from_unknown.bssid = bss->addr;
  1261. event.rx_from_unknown.addr = nla_data(tb[NL80211_ATTR_MAC]);
  1262. event.rx_from_unknown.wds = wds;
  1263. wpa_supplicant_event(drv->ctx, EVENT_RX_FROM_UNKNOWN, &event);
  1264. }
  1265. #ifdef CONFIG_DRIVER_NL80211_QCA
  1266. static void qca_nl80211_avoid_freq(struct wpa_driver_nl80211_data *drv,
  1267. const u8 *data, size_t len)
  1268. {
  1269. u32 i, count;
  1270. union wpa_event_data event;
  1271. struct wpa_freq_range *range = NULL;
  1272. const struct qca_avoid_freq_list *freq_range;
  1273. freq_range = (const struct qca_avoid_freq_list *) data;
  1274. if (len < sizeof(freq_range->count))
  1275. return;
  1276. count = freq_range->count;
  1277. if (len < sizeof(freq_range->count) +
  1278. count * sizeof(struct qca_avoid_freq_range)) {
  1279. wpa_printf(MSG_DEBUG, "nl80211: Ignored too short avoid frequency list (len=%u)",
  1280. (unsigned int) len);
  1281. return;
  1282. }
  1283. if (count > 0) {
  1284. range = os_calloc(count, sizeof(struct wpa_freq_range));
  1285. if (range == NULL)
  1286. return;
  1287. }
  1288. os_memset(&event, 0, sizeof(event));
  1289. for (i = 0; i < count; i++) {
  1290. unsigned int idx = event.freq_range.num;
  1291. range[idx].min = freq_range->range[i].start_freq;
  1292. range[idx].max = freq_range->range[i].end_freq;
  1293. wpa_printf(MSG_DEBUG, "nl80211: Avoid frequency range: %u-%u",
  1294. range[idx].min, range[idx].max);
  1295. if (range[idx].min > range[idx].max) {
  1296. wpa_printf(MSG_DEBUG, "nl80211: Ignore invalid frequency range");
  1297. continue;
  1298. }
  1299. event.freq_range.num++;
  1300. }
  1301. event.freq_range.range = range;
  1302. wpa_supplicant_event(drv->ctx, EVENT_AVOID_FREQUENCIES, &event);
  1303. os_free(range);
  1304. }
  1305. static enum hostapd_hw_mode get_qca_hw_mode(u8 hw_mode)
  1306. {
  1307. switch (hw_mode) {
  1308. case QCA_ACS_MODE_IEEE80211B:
  1309. return HOSTAPD_MODE_IEEE80211B;
  1310. case QCA_ACS_MODE_IEEE80211G:
  1311. return HOSTAPD_MODE_IEEE80211G;
  1312. case QCA_ACS_MODE_IEEE80211A:
  1313. return HOSTAPD_MODE_IEEE80211A;
  1314. case QCA_ACS_MODE_IEEE80211AD:
  1315. return HOSTAPD_MODE_IEEE80211AD;
  1316. case QCA_ACS_MODE_IEEE80211ANY:
  1317. return HOSTAPD_MODE_IEEE80211ANY;
  1318. default:
  1319. return NUM_HOSTAPD_MODES;
  1320. }
  1321. }
  1322. static void qca_nl80211_acs_select_ch(struct wpa_driver_nl80211_data *drv,
  1323. const u8 *data, size_t len)
  1324. {
  1325. struct nlattr *tb[QCA_WLAN_VENDOR_ATTR_ACS_MAX + 1];
  1326. union wpa_event_data event;
  1327. wpa_printf(MSG_DEBUG,
  1328. "nl80211: ACS channel selection vendor event received");
  1329. if (nla_parse(tb, QCA_WLAN_VENDOR_ATTR_ACS_MAX,
  1330. (struct nlattr *) data, len, NULL) ||
  1331. !tb[QCA_WLAN_VENDOR_ATTR_ACS_PRIMARY_CHANNEL] ||
  1332. !tb[QCA_WLAN_VENDOR_ATTR_ACS_SECONDARY_CHANNEL])
  1333. return;
  1334. os_memset(&event, 0, sizeof(event));
  1335. event.acs_selected_channels.pri_channel =
  1336. nla_get_u8(tb[QCA_WLAN_VENDOR_ATTR_ACS_PRIMARY_CHANNEL]);
  1337. event.acs_selected_channels.sec_channel =
  1338. nla_get_u8(tb[QCA_WLAN_VENDOR_ATTR_ACS_SECONDARY_CHANNEL]);
  1339. if (tb[QCA_WLAN_VENDOR_ATTR_ACS_VHT_SEG0_CENTER_CHANNEL])
  1340. event.acs_selected_channels.vht_seg0_center_ch =
  1341. nla_get_u8(tb[QCA_WLAN_VENDOR_ATTR_ACS_VHT_SEG0_CENTER_CHANNEL]);
  1342. if (tb[QCA_WLAN_VENDOR_ATTR_ACS_VHT_SEG0_CENTER_CHANNEL])
  1343. event.acs_selected_channels.vht_seg1_center_ch =
  1344. nla_get_u8(tb[QCA_WLAN_VENDOR_ATTR_ACS_VHT_SEG1_CENTER_CHANNEL]);
  1345. if (tb[QCA_WLAN_VENDOR_ATTR_ACS_CHWIDTH])
  1346. event.acs_selected_channels.ch_width =
  1347. nla_get_u16(tb[QCA_WLAN_VENDOR_ATTR_ACS_CHWIDTH]);
  1348. if (tb[QCA_WLAN_VENDOR_ATTR_ACS_HW_MODE]) {
  1349. u8 hw_mode = nla_get_u8(tb[QCA_WLAN_VENDOR_ATTR_ACS_HW_MODE]);
  1350. event.acs_selected_channels.hw_mode = get_qca_hw_mode(hw_mode);
  1351. if (event.acs_selected_channels.hw_mode == NUM_HOSTAPD_MODES ||
  1352. event.acs_selected_channels.hw_mode ==
  1353. HOSTAPD_MODE_IEEE80211ANY) {
  1354. wpa_printf(MSG_DEBUG,
  1355. "nl80211: Invalid hw_mode %d in ACS selection event",
  1356. hw_mode);
  1357. return;
  1358. }
  1359. }
  1360. wpa_printf(MSG_INFO,
  1361. "nl80211: ACS Results: PCH: %d SCH: %d BW: %d VHT0: %d VHT1: %d HW_MODE: %d",
  1362. event.acs_selected_channels.pri_channel,
  1363. event.acs_selected_channels.sec_channel,
  1364. event.acs_selected_channels.ch_width,
  1365. event.acs_selected_channels.vht_seg0_center_ch,
  1366. event.acs_selected_channels.vht_seg1_center_ch,
  1367. event.acs_selected_channels.hw_mode);
  1368. /* Ignore ACS channel list check for backwards compatibility */
  1369. wpa_supplicant_event(drv->ctx, EVENT_ACS_CHANNEL_SELECTED, &event);
  1370. }
  1371. static void qca_nl80211_key_mgmt_auth(struct wpa_driver_nl80211_data *drv,
  1372. const u8 *data, size_t len)
  1373. {
  1374. struct nlattr *tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_MAX + 1];
  1375. u8 *bssid;
  1376. wpa_printf(MSG_DEBUG,
  1377. "nl80211: Key management roam+auth vendor event received");
  1378. if (nla_parse(tb, QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_MAX,
  1379. (struct nlattr *) data, len, NULL) ||
  1380. !tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_BSSID] ||
  1381. nla_len(tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_BSSID]) != ETH_ALEN ||
  1382. !tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_REQ_IE] ||
  1383. !tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_RESP_IE] ||
  1384. !tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_AUTHORIZED])
  1385. return;
  1386. bssid = nla_data(tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_BSSID]);
  1387. wpa_printf(MSG_DEBUG, " * roam BSSID " MACSTR, MAC2STR(bssid));
  1388. mlme_event_connect(drv, NL80211_CMD_ROAM, NULL,
  1389. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_BSSID],
  1390. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_REQ_IE],
  1391. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_RESP_IE],
  1392. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_AUTHORIZED],
  1393. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_KEY_REPLAY_CTR],
  1394. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_PTK_KCK],
  1395. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_PTK_KEK],
  1396. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_SUBNET_STATUS]);
  1397. }
  1398. static void qca_nl80211_dfs_offload_radar_event(
  1399. struct wpa_driver_nl80211_data *drv, u32 subcmd, u8 *msg, int length)
  1400. {
  1401. union wpa_event_data data;
  1402. struct nlattr *tb[NL80211_ATTR_MAX + 1];
  1403. wpa_printf(MSG_DEBUG,
  1404. "nl80211: DFS offload radar vendor event received");
  1405. if (nla_parse(tb, NL80211_ATTR_MAX,
  1406. (struct nlattr *) msg, length, NULL))
  1407. return;
  1408. if (!tb[NL80211_ATTR_WIPHY_FREQ]) {
  1409. wpa_printf(MSG_INFO,
  1410. "nl80211: Error parsing WIPHY_FREQ in FS offload radar vendor event");
  1411. return;
  1412. }
  1413. os_memset(&data, 0, sizeof(data));
  1414. data.dfs_event.freq = nla_get_u32(tb[NL80211_ATTR_WIPHY_FREQ]);
  1415. wpa_printf(MSG_DEBUG, "nl80211: DFS event on freq %d MHz",
  1416. data.dfs_event.freq);
  1417. /* Check HT params */
  1418. if (tb[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
  1419. data.dfs_event.ht_enabled = 1;
  1420. data.dfs_event.chan_offset = 0;
  1421. switch (nla_get_u32(tb[NL80211_ATTR_WIPHY_CHANNEL_TYPE])) {
  1422. case NL80211_CHAN_NO_HT:
  1423. data.dfs_event.ht_enabled = 0;
  1424. break;
  1425. case NL80211_CHAN_HT20:
  1426. break;
  1427. case NL80211_CHAN_HT40PLUS:
  1428. data.dfs_event.chan_offset = 1;
  1429. break;
  1430. case NL80211_CHAN_HT40MINUS:
  1431. data.dfs_event.chan_offset = -1;
  1432. break;
  1433. }
  1434. }
  1435. /* Get VHT params */
  1436. if (tb[NL80211_ATTR_CHANNEL_WIDTH])
  1437. data.dfs_event.chan_width =
  1438. convert2width(nla_get_u32(
  1439. tb[NL80211_ATTR_CHANNEL_WIDTH]));
  1440. if (tb[NL80211_ATTR_CENTER_FREQ1])
  1441. data.dfs_event.cf1 = nla_get_u32(tb[NL80211_ATTR_CENTER_FREQ1]);
  1442. if (tb[NL80211_ATTR_CENTER_FREQ2])
  1443. data.dfs_event.cf2 = nla_get_u32(tb[NL80211_ATTR_CENTER_FREQ2]);
  1444. wpa_printf(MSG_DEBUG, "nl80211: DFS event on freq %d MHz, ht: %d, "
  1445. "offset: %d, width: %d, cf1: %dMHz, cf2: %dMHz",
  1446. data.dfs_event.freq, data.dfs_event.ht_enabled,
  1447. data.dfs_event.chan_offset, data.dfs_event.chan_width,
  1448. data.dfs_event.cf1, data.dfs_event.cf2);
  1449. switch (subcmd) {
  1450. case QCA_NL80211_VENDOR_SUBCMD_DFS_OFFLOAD_RADAR_DETECTED:
  1451. wpa_supplicant_event(drv->ctx, EVENT_DFS_RADAR_DETECTED, &data);
  1452. break;
  1453. case QCA_NL80211_VENDOR_SUBCMD_DFS_OFFLOAD_CAC_STARTED:
  1454. wpa_supplicant_event(drv->ctx, EVENT_DFS_CAC_STARTED, &data);
  1455. break;
  1456. case QCA_NL80211_VENDOR_SUBCMD_DFS_OFFLOAD_CAC_FINISHED:
  1457. wpa_supplicant_event(drv->ctx, EVENT_DFS_CAC_FINISHED, &data);
  1458. break;
  1459. case QCA_NL80211_VENDOR_SUBCMD_DFS_OFFLOAD_CAC_ABORTED:
  1460. wpa_supplicant_event(drv->ctx, EVENT_DFS_CAC_ABORTED, &data);
  1461. break;
  1462. case QCA_NL80211_VENDOR_SUBCMD_DFS_OFFLOAD_CAC_NOP_FINISHED:
  1463. wpa_supplicant_event(drv->ctx, EVENT_DFS_NOP_FINISHED, &data);
  1464. break;
  1465. default:
  1466. wpa_printf(MSG_DEBUG,
  1467. "nl80211: Unknown DFS offload radar event %d received",
  1468. subcmd);
  1469. break;
  1470. }
  1471. }
  1472. static void qca_nl80211_scan_trigger_event(struct wpa_driver_nl80211_data *drv,
  1473. u8 *data, size_t len)
  1474. {
  1475. struct nlattr *tb[QCA_WLAN_VENDOR_ATTR_SCAN_MAX + 1];
  1476. u64 cookie = 0;
  1477. union wpa_event_data event;
  1478. struct scan_info *info;
  1479. if (nla_parse(tb, QCA_WLAN_VENDOR_ATTR_SCAN_MAX,
  1480. (struct nlattr *) data, len, NULL) ||
  1481. !tb[QCA_WLAN_VENDOR_ATTR_SCAN_COOKIE])
  1482. return;
  1483. cookie = nla_get_u64(tb[QCA_WLAN_VENDOR_ATTR_SCAN_COOKIE]);
  1484. if (cookie != drv->vendor_scan_cookie) {
  1485. /* External scan trigger event, ignore */
  1486. return;
  1487. }
  1488. /* Cookie match, own scan */
  1489. os_memset(&event, 0, sizeof(event));
  1490. info = &event.scan_info;
  1491. info->external_scan = 0;
  1492. info->nl_scan_event = 0;
  1493. drv->scan_state = SCAN_STARTED;
  1494. wpa_supplicant_event(drv->ctx, EVENT_SCAN_STARTED, &event);
  1495. }
  1496. static void send_vendor_scan_event(struct wpa_driver_nl80211_data *drv,
  1497. int aborted, struct nlattr *tb[],
  1498. int external_scan)
  1499. {
  1500. union wpa_event_data event;
  1501. struct nlattr *nl;
  1502. int rem;
  1503. struct scan_info *info;
  1504. int freqs[MAX_REPORT_FREQS];
  1505. int num_freqs = 0;
  1506. os_memset(&event, 0, sizeof(event));
  1507. info = &event.scan_info;
  1508. info->aborted = aborted;
  1509. info->external_scan = external_scan;
  1510. if (tb[QCA_WLAN_VENDOR_ATTR_SCAN_SSIDS]) {
  1511. nla_for_each_nested(nl,
  1512. tb[QCA_WLAN_VENDOR_ATTR_SCAN_SSIDS], rem) {
  1513. struct wpa_driver_scan_ssid *s =
  1514. &info->ssids[info->num_ssids];
  1515. s->ssid = nla_data(nl);
  1516. s->ssid_len = nla_len(nl);
  1517. wpa_printf(MSG_DEBUG,
  1518. "nl80211: Scan probed for SSID '%s'",
  1519. wpa_ssid_txt(s->ssid, s->ssid_len));
  1520. info->num_ssids++;
  1521. if (info->num_ssids == WPAS_MAX_SCAN_SSIDS)
  1522. break;
  1523. }
  1524. }
  1525. if (tb[QCA_WLAN_VENDOR_ATTR_SCAN_FREQUENCIES]) {
  1526. char msg[300], *pos, *end;
  1527. int res;
  1528. pos = msg;
  1529. end = pos + sizeof(msg);
  1530. *pos = '\0';
  1531. nla_for_each_nested(nl,
  1532. tb[QCA_WLAN_VENDOR_ATTR_SCAN_FREQUENCIES],
  1533. rem) {
  1534. freqs[num_freqs] = nla_get_u32(nl);
  1535. res = os_snprintf(pos, end - pos, " %d",
  1536. freqs[num_freqs]);
  1537. if (!os_snprintf_error(end - pos, res))
  1538. pos += res;
  1539. num_freqs++;
  1540. if (num_freqs == MAX_REPORT_FREQS - 1)
  1541. break;
  1542. }
  1543. info->freqs = freqs;
  1544. info->num_freqs = num_freqs;
  1545. wpa_printf(MSG_DEBUG, "nl80211: Scan included frequencies:%s",
  1546. msg);
  1547. }
  1548. wpa_supplicant_event(drv->ctx, EVENT_SCAN_RESULTS, &event);
  1549. }
  1550. static void qca_nl80211_scan_done_event(struct wpa_driver_nl80211_data *drv,
  1551. u8 *data, size_t len)
  1552. {
  1553. struct nlattr *tb[QCA_WLAN_VENDOR_ATTR_SCAN_MAX + 1];
  1554. u64 cookie = 0;
  1555. enum scan_status status;
  1556. int external_scan;
  1557. if (nla_parse(tb, QCA_WLAN_VENDOR_ATTR_SCAN_MAX,
  1558. (struct nlattr *) data, len, NULL) ||
  1559. !tb[QCA_WLAN_VENDOR_ATTR_SCAN_STATUS] ||
  1560. !tb[QCA_WLAN_VENDOR_ATTR_SCAN_COOKIE])
  1561. return;
  1562. status = nla_get_u8(tb[QCA_WLAN_VENDOR_ATTR_SCAN_STATUS]);
  1563. if (status >= VENDOR_SCAN_STATUS_MAX)
  1564. return; /* invalid status */
  1565. cookie = nla_get_u64(tb[QCA_WLAN_VENDOR_ATTR_SCAN_COOKIE]);
  1566. if (cookie != drv->vendor_scan_cookie) {
  1567. /* Event from an external scan, get scan results */
  1568. external_scan = 1;
  1569. } else {
  1570. external_scan = 0;
  1571. if (status == VENDOR_SCAN_STATUS_NEW_RESULTS)
  1572. drv->scan_state = SCAN_COMPLETED;
  1573. else
  1574. drv->scan_state = SCAN_ABORTED;
  1575. eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout, drv,
  1576. drv->ctx);
  1577. drv->vendor_scan_cookie = 0;
  1578. drv->last_scan_cmd = 0;
  1579. }
  1580. send_vendor_scan_event(drv, (status == VENDOR_SCAN_STATUS_ABORTED), tb,
  1581. external_scan);
  1582. }
  1583. #endif /* CONFIG_DRIVER_NL80211_QCA */
  1584. static void nl80211_vendor_event_qca(struct wpa_driver_nl80211_data *drv,
  1585. u32 subcmd, u8 *data, size_t len)
  1586. {
  1587. switch (subcmd) {
  1588. case QCA_NL80211_VENDOR_SUBCMD_TEST:
  1589. wpa_hexdump(MSG_DEBUG, "nl80211: QCA test event", data, len);
  1590. break;
  1591. #ifdef CONFIG_DRIVER_NL80211_QCA
  1592. case QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY:
  1593. qca_nl80211_avoid_freq(drv, data, len);
  1594. break;
  1595. case QCA_NL80211_VENDOR_SUBCMD_KEY_MGMT_ROAM_AUTH:
  1596. qca_nl80211_key_mgmt_auth(drv, data, len);
  1597. break;
  1598. case QCA_NL80211_VENDOR_SUBCMD_DO_ACS:
  1599. qca_nl80211_acs_select_ch(drv, data, len);
  1600. break;
  1601. case QCA_NL80211_VENDOR_SUBCMD_DFS_OFFLOAD_CAC_STARTED:
  1602. case QCA_NL80211_VENDOR_SUBCMD_DFS_OFFLOAD_CAC_FINISHED:
  1603. case QCA_NL80211_VENDOR_SUBCMD_DFS_OFFLOAD_CAC_ABORTED:
  1604. case QCA_NL80211_VENDOR_SUBCMD_DFS_OFFLOAD_CAC_NOP_FINISHED:
  1605. case QCA_NL80211_VENDOR_SUBCMD_DFS_OFFLOAD_RADAR_DETECTED:
  1606. qca_nl80211_dfs_offload_radar_event(drv, subcmd, data, len);
  1607. break;
  1608. case QCA_NL80211_VENDOR_SUBCMD_TRIGGER_SCAN:
  1609. qca_nl80211_scan_trigger_event(drv, data, len);
  1610. break;
  1611. case QCA_NL80211_VENDOR_SUBCMD_SCAN_DONE:
  1612. qca_nl80211_scan_done_event(drv, data, len);
  1613. break;
  1614. #endif /* CONFIG_DRIVER_NL80211_QCA */
  1615. default:
  1616. wpa_printf(MSG_DEBUG,
  1617. "nl80211: Ignore unsupported QCA vendor event %u",
  1618. subcmd);
  1619. break;
  1620. }
  1621. }
  1622. static void nl80211_vendor_event(struct wpa_driver_nl80211_data *drv,
  1623. struct nlattr **tb)
  1624. {
  1625. u32 vendor_id, subcmd, wiphy = 0;
  1626. int wiphy_idx;
  1627. u8 *data = NULL;
  1628. size_t len = 0;
  1629. if (!tb[NL80211_ATTR_VENDOR_ID] ||
  1630. !tb[NL80211_ATTR_VENDOR_SUBCMD])
  1631. return;
  1632. vendor_id = nla_get_u32(tb[NL80211_ATTR_VENDOR_ID]);
  1633. subcmd = nla_get_u32(tb[NL80211_ATTR_VENDOR_SUBCMD]);
  1634. if (tb[NL80211_ATTR_WIPHY])
  1635. wiphy = nla_get_u32(tb[NL80211_ATTR_WIPHY]);
  1636. wpa_printf(MSG_DEBUG, "nl80211: Vendor event: wiphy=%u vendor_id=0x%x subcmd=%u",
  1637. wiphy, vendor_id, subcmd);
  1638. if (tb[NL80211_ATTR_VENDOR_DATA]) {
  1639. data = nla_data(tb[NL80211_ATTR_VENDOR_DATA]);
  1640. len = nla_len(tb[NL80211_ATTR_VENDOR_DATA]);
  1641. wpa_hexdump(MSG_MSGDUMP, "nl80211: Vendor data", data, len);
  1642. }
  1643. wiphy_idx = nl80211_get_wiphy_index(drv->first_bss);
  1644. if (wiphy_idx >= 0 && wiphy_idx != (int) wiphy) {
  1645. wpa_printf(MSG_DEBUG, "nl80211: Ignore vendor event for foreign wiphy %u (own: %d)",
  1646. wiphy, wiphy_idx);
  1647. return;
  1648. }
  1649. switch (vendor_id) {
  1650. case OUI_QCA:
  1651. nl80211_vendor_event_qca(drv, subcmd, data, len);
  1652. break;
  1653. default:
  1654. wpa_printf(MSG_DEBUG, "nl80211: Ignore unsupported vendor event");
  1655. break;
  1656. }
  1657. }
  1658. static void nl80211_reg_change_event(struct wpa_driver_nl80211_data *drv,
  1659. struct nlattr *tb[])
  1660. {
  1661. union wpa_event_data data;
  1662. enum nl80211_reg_initiator init;
  1663. wpa_printf(MSG_DEBUG, "nl80211: Regulatory domain change");
  1664. if (tb[NL80211_ATTR_REG_INITIATOR] == NULL)
  1665. return;
  1666. os_memset(&data, 0, sizeof(data));
  1667. init = nla_get_u8(tb[NL80211_ATTR_REG_INITIATOR]);
  1668. wpa_printf(MSG_DEBUG, " * initiator=%d", init);
  1669. switch (init) {
  1670. case NL80211_REGDOM_SET_BY_CORE:
  1671. data.channel_list_changed.initiator = REGDOM_SET_BY_CORE;
  1672. break;
  1673. case NL80211_REGDOM_SET_BY_USER:
  1674. data.channel_list_changed.initiator = REGDOM_SET_BY_USER;
  1675. break;
  1676. case NL80211_REGDOM_SET_BY_DRIVER:
  1677. data.channel_list_changed.initiator = REGDOM_SET_BY_DRIVER;
  1678. break;
  1679. case NL80211_REGDOM_SET_BY_COUNTRY_IE:
  1680. data.channel_list_changed.initiator = REGDOM_SET_BY_COUNTRY_IE;
  1681. break;
  1682. }
  1683. if (tb[NL80211_ATTR_REG_TYPE]) {
  1684. enum nl80211_reg_type type;
  1685. type = nla_get_u8(tb[NL80211_ATTR_REG_TYPE]);
  1686. wpa_printf(MSG_DEBUG, " * type=%d", type);
  1687. switch (type) {
  1688. case NL80211_REGDOM_TYPE_COUNTRY:
  1689. data.channel_list_changed.type = REGDOM_TYPE_COUNTRY;
  1690. break;
  1691. case NL80211_REGDOM_TYPE_WORLD:
  1692. data.channel_list_changed.type = REGDOM_TYPE_WORLD;
  1693. break;
  1694. case NL80211_REGDOM_TYPE_CUSTOM_WORLD:
  1695. data.channel_list_changed.type =
  1696. REGDOM_TYPE_CUSTOM_WORLD;
  1697. break;
  1698. case NL80211_REGDOM_TYPE_INTERSECTION:
  1699. data.channel_list_changed.type =
  1700. REGDOM_TYPE_INTERSECTION;
  1701. break;
  1702. }
  1703. }
  1704. if (tb[NL80211_ATTR_REG_ALPHA2]) {
  1705. os_strlcpy(data.channel_list_changed.alpha2,
  1706. nla_get_string(tb[NL80211_ATTR_REG_ALPHA2]),
  1707. sizeof(data.channel_list_changed.alpha2));
  1708. wpa_printf(MSG_DEBUG, " * alpha2=%s",
  1709. data.channel_list_changed.alpha2);
  1710. }
  1711. wpa_supplicant_event(drv->ctx, EVENT_CHANNEL_LIST_CHANGED, &data);
  1712. }
  1713. static void do_process_drv_event(struct i802_bss *bss, int cmd,
  1714. struct nlattr **tb)
  1715. {
  1716. struct wpa_driver_nl80211_data *drv = bss->drv;
  1717. union wpa_event_data data;
  1718. int external_scan_event = 0;
  1719. wpa_printf(MSG_DEBUG, "nl80211: Drv Event %d (%s) received for %s",
  1720. cmd, nl80211_command_to_string(cmd), bss->ifname);
  1721. if (cmd == NL80211_CMD_ROAM &&
  1722. (drv->capa.flags & WPA_DRIVER_FLAGS_KEY_MGMT_OFFLOAD)) {
  1723. /*
  1724. * Device will use roam+auth vendor event to indicate
  1725. * roaming, so ignore the regular roam event.
  1726. */
  1727. wpa_printf(MSG_DEBUG,
  1728. "nl80211: Ignore roam event (cmd=%d), device will use vendor event roam+auth",
  1729. cmd);
  1730. return;
  1731. }
  1732. if (drv->ap_scan_as_station != NL80211_IFTYPE_UNSPECIFIED &&
  1733. (cmd == NL80211_CMD_NEW_SCAN_RESULTS ||
  1734. cmd == NL80211_CMD_SCAN_ABORTED)) {
  1735. wpa_driver_nl80211_set_mode(drv->first_bss,
  1736. drv->ap_scan_as_station);
  1737. drv->ap_scan_as_station = NL80211_IFTYPE_UNSPECIFIED;
  1738. }
  1739. switch (cmd) {
  1740. case NL80211_CMD_TRIGGER_SCAN:
  1741. wpa_dbg(drv->ctx, MSG_DEBUG, "nl80211: Scan trigger");
  1742. drv->scan_state = SCAN_STARTED;
  1743. if (drv->scan_for_auth) {
  1744. /*
  1745. * Cannot indicate EVENT_SCAN_STARTED here since we skip
  1746. * EVENT_SCAN_RESULTS in scan_for_auth case and the
  1747. * upper layer implementation could get confused about
  1748. * scanning state.
  1749. */
  1750. wpa_printf(MSG_DEBUG, "nl80211: Do not indicate scan-start event due to internal scan_for_auth");
  1751. break;
  1752. }
  1753. wpa_supplicant_event(drv->ctx, EVENT_SCAN_STARTED, NULL);
  1754. break;
  1755. case NL80211_CMD_START_SCHED_SCAN:
  1756. wpa_dbg(drv->ctx, MSG_DEBUG, "nl80211: Sched scan started");
  1757. drv->scan_state = SCHED_SCAN_STARTED;
  1758. break;
  1759. case NL80211_CMD_SCHED_SCAN_STOPPED:
  1760. wpa_dbg(drv->ctx, MSG_DEBUG, "nl80211: Sched scan stopped");
  1761. drv->scan_state = SCHED_SCAN_STOPPED;
  1762. wpa_supplicant_event(drv->ctx, EVENT_SCHED_SCAN_STOPPED, NULL);
  1763. break;
  1764. case NL80211_CMD_NEW_SCAN_RESULTS:
  1765. wpa_dbg(drv->ctx, MSG_DEBUG,
  1766. "nl80211: New scan results available");
  1767. drv->scan_complete_events = 1;
  1768. if (drv->last_scan_cmd == NL80211_CMD_TRIGGER_SCAN) {
  1769. drv->scan_state = SCAN_COMPLETED;
  1770. eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout,
  1771. drv, drv->ctx);
  1772. drv->last_scan_cmd = 0;
  1773. } else {
  1774. external_scan_event = 1;
  1775. }
  1776. send_scan_event(drv, 0, tb, external_scan_event);
  1777. break;
  1778. case NL80211_CMD_SCHED_SCAN_RESULTS:
  1779. wpa_dbg(drv->ctx, MSG_DEBUG,
  1780. "nl80211: New sched scan results available");
  1781. drv->scan_state = SCHED_SCAN_RESULTS;
  1782. send_scan_event(drv, 0, tb, 0);
  1783. break;
  1784. case NL80211_CMD_SCAN_ABORTED:
  1785. wpa_dbg(drv->ctx, MSG_DEBUG, "nl80211: Scan aborted");
  1786. if (drv->last_scan_cmd == NL80211_CMD_TRIGGER_SCAN) {
  1787. drv->scan_state = SCAN_ABORTED;
  1788. /*
  1789. * Need to indicate that scan results are available in
  1790. * order not to make wpa_supplicant stop its scanning.
  1791. */
  1792. eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout,
  1793. drv, drv->ctx);
  1794. drv->last_scan_cmd = 0;
  1795. } else {
  1796. external_scan_event = 1;
  1797. }
  1798. send_scan_event(drv, 1, tb, external_scan_event);
  1799. break;
  1800. case NL80211_CMD_AUTHENTICATE:
  1801. case NL80211_CMD_ASSOCIATE:
  1802. case NL80211_CMD_DEAUTHENTICATE:
  1803. case NL80211_CMD_DISASSOCIATE:
  1804. case NL80211_CMD_FRAME_TX_STATUS:
  1805. case NL80211_CMD_UNPROT_DEAUTHENTICATE:
  1806. case NL80211_CMD_UNPROT_DISASSOCIATE:
  1807. mlme_event(bss, cmd, tb[NL80211_ATTR_FRAME],
  1808. tb[NL80211_ATTR_MAC], tb[NL80211_ATTR_TIMED_OUT],
  1809. tb[NL80211_ATTR_WIPHY_FREQ], tb[NL80211_ATTR_ACK],
  1810. tb[NL80211_ATTR_COOKIE],
  1811. tb[NL80211_ATTR_RX_SIGNAL_DBM],
  1812. tb[NL80211_ATTR_STA_WME]);
  1813. break;
  1814. case NL80211_CMD_CONNECT:
  1815. case NL80211_CMD_ROAM:
  1816. mlme_event_connect(drv, cmd,
  1817. tb[NL80211_ATTR_STATUS_CODE],
  1818. tb[NL80211_ATTR_MAC],
  1819. tb[NL80211_ATTR_REQ_IE],
  1820. tb[NL80211_ATTR_RESP_IE],
  1821. NULL, NULL, NULL, NULL, NULL);
  1822. break;
  1823. case NL80211_CMD_CH_SWITCH_NOTIFY:
  1824. mlme_event_ch_switch(drv,
  1825. tb[NL80211_ATTR_IFINDEX],
  1826. tb[NL80211_ATTR_WIPHY_FREQ],
  1827. tb[NL80211_ATTR_WIPHY_CHANNEL_TYPE],
  1828. tb[NL80211_ATTR_CHANNEL_WIDTH],
  1829. tb[NL80211_ATTR_CENTER_FREQ1],
  1830. tb[NL80211_ATTR_CENTER_FREQ2]);
  1831. break;
  1832. case NL80211_CMD_DISCONNECT:
  1833. mlme_event_disconnect(drv, tb[NL80211_ATTR_REASON_CODE],
  1834. tb[NL80211_ATTR_MAC],
  1835. tb[NL80211_ATTR_DISCONNECTED_BY_AP]);
  1836. break;
  1837. case NL80211_CMD_MICHAEL_MIC_FAILURE:
  1838. mlme_event_michael_mic_failure(bss, tb);
  1839. break;
  1840. case NL80211_CMD_JOIN_IBSS:
  1841. mlme_event_join_ibss(drv, tb);
  1842. break;
  1843. case NL80211_CMD_REMAIN_ON_CHANNEL:
  1844. mlme_event_remain_on_channel(drv, 0, tb);
  1845. break;
  1846. case NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL:
  1847. mlme_event_remain_on_channel(drv, 1, tb);
  1848. break;
  1849. case NL80211_CMD_NOTIFY_CQM:
  1850. nl80211_cqm_event(drv, tb);
  1851. break;
  1852. case NL80211_CMD_REG_CHANGE:
  1853. nl80211_reg_change_event(drv, tb);
  1854. break;
  1855. case NL80211_CMD_REG_BEACON_HINT:
  1856. wpa_printf(MSG_DEBUG, "nl80211: Regulatory beacon hint");
  1857. os_memset(&data, 0, sizeof(data));
  1858. data.channel_list_changed.initiator = REGDOM_BEACON_HINT;
  1859. wpa_supplicant_event(drv->ctx, EVENT_CHANNEL_LIST_CHANGED,
  1860. &data);
  1861. break;
  1862. case NL80211_CMD_NEW_STATION:
  1863. nl80211_new_station_event(drv, bss, tb);
  1864. break;
  1865. case NL80211_CMD_DEL_STATION:
  1866. nl80211_del_station_event(drv, tb);
  1867. break;
  1868. case NL80211_CMD_SET_REKEY_OFFLOAD:
  1869. nl80211_rekey_offload_event(drv, tb);
  1870. break;
  1871. case NL80211_CMD_PMKSA_CANDIDATE:
  1872. nl80211_pmksa_candidate_event(drv, tb);
  1873. break;
  1874. case NL80211_CMD_PROBE_CLIENT:
  1875. nl80211_client_probe_event(drv, tb);
  1876. break;
  1877. case NL80211_CMD_TDLS_OPER:
  1878. nl80211_tdls_oper_event(drv, tb);
  1879. break;
  1880. case NL80211_CMD_CONN_FAILED:
  1881. nl80211_connect_failed_event(drv, tb);
  1882. break;
  1883. case NL80211_CMD_FT_EVENT:
  1884. mlme_event_ft_event(drv, tb);
  1885. break;
  1886. case NL80211_CMD_RADAR_DETECT:
  1887. nl80211_radar_event(drv, tb);
  1888. break;
  1889. case NL80211_CMD_STOP_AP:
  1890. nl80211_stop_ap(drv, tb);
  1891. break;
  1892. case NL80211_CMD_VENDOR:
  1893. nl80211_vendor_event(drv, tb);
  1894. break;
  1895. case NL80211_CMD_NEW_PEER_CANDIDATE:
  1896. nl80211_new_peer_candidate(drv, tb);
  1897. break;
  1898. default:
  1899. wpa_dbg(drv->ctx, MSG_DEBUG, "nl80211: Ignored unknown event "
  1900. "(cmd=%d)", cmd);
  1901. break;
  1902. }
  1903. }
  1904. int process_global_event(struct nl_msg *msg, void *arg)
  1905. {
  1906. struct nl80211_global *global = arg;
  1907. struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
  1908. struct nlattr *tb[NL80211_ATTR_MAX + 1];
  1909. struct wpa_driver_nl80211_data *drv, *tmp;
  1910. int ifidx = -1;
  1911. struct i802_bss *bss;
  1912. u64 wdev_id = 0;
  1913. int wdev_id_set = 0;
  1914. nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
  1915. genlmsg_attrlen(gnlh, 0), NULL);
  1916. if (tb[NL80211_ATTR_IFINDEX])
  1917. ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]);
  1918. else if (tb[NL80211_ATTR_WDEV]) {
  1919. wdev_id = nla_get_u64(tb[NL80211_ATTR_WDEV]);
  1920. wdev_id_set = 1;
  1921. }
  1922. dl_list_for_each_safe(drv, tmp, &global->interfaces,
  1923. struct wpa_driver_nl80211_data, list) {
  1924. for (bss = drv->first_bss; bss; bss = bss->next) {
  1925. if ((ifidx == -1 && !wdev_id_set) ||
  1926. ifidx == bss->ifindex ||
  1927. (wdev_id_set && bss->wdev_id_set &&
  1928. wdev_id == bss->wdev_id)) {
  1929. do_process_drv_event(bss, gnlh->cmd, tb);
  1930. return NL_SKIP;
  1931. }
  1932. }
  1933. wpa_printf(MSG_DEBUG,
  1934. "nl80211: Ignored event (cmd=%d) for foreign interface (ifindex %d wdev 0x%llx)",
  1935. gnlh->cmd, ifidx, (long long unsigned int) wdev_id);
  1936. }
  1937. return NL_SKIP;
  1938. }
  1939. int process_bss_event(struct nl_msg *msg, void *arg)
  1940. {
  1941. struct i802_bss *bss = arg;
  1942. struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
  1943. struct nlattr *tb[NL80211_ATTR_MAX + 1];
  1944. nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
  1945. genlmsg_attrlen(gnlh, 0), NULL);
  1946. wpa_printf(MSG_DEBUG, "nl80211: BSS Event %d (%s) received for %s",
  1947. gnlh->cmd, nl80211_command_to_string(gnlh->cmd),
  1948. bss->ifname);
  1949. switch (gnlh->cmd) {
  1950. case NL80211_CMD_FRAME:
  1951. case NL80211_CMD_FRAME_TX_STATUS:
  1952. mlme_event(bss, gnlh->cmd, tb[NL80211_ATTR_FRAME],
  1953. tb[NL80211_ATTR_MAC], tb[NL80211_ATTR_TIMED_OUT],
  1954. tb[NL80211_ATTR_WIPHY_FREQ], tb[NL80211_ATTR_ACK],
  1955. tb[NL80211_ATTR_COOKIE],
  1956. tb[NL80211_ATTR_RX_SIGNAL_DBM],
  1957. tb[NL80211_ATTR_STA_WME]);
  1958. break;
  1959. case NL80211_CMD_UNEXPECTED_FRAME:
  1960. nl80211_spurious_frame(bss, tb, 0);
  1961. break;
  1962. case NL80211_CMD_UNEXPECTED_4ADDR_FRAME:
  1963. nl80211_spurious_frame(bss, tb, 1);
  1964. break;
  1965. default:
  1966. wpa_printf(MSG_DEBUG, "nl80211: Ignored unknown event "
  1967. "(cmd=%d)", gnlh->cmd);
  1968. break;
  1969. }
  1970. return NL_SKIP;
  1971. }