driver_nl80211.c 70 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763
  1. /*
  2. * WPA Supplicant - driver interaction with Linux nl80211/cfg80211
  3. * Copyright (c) 2003-2008, Jouni Malinen <j@w1.fi>
  4. *
  5. * This program is free software; you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License version 2 as
  7. * published by the Free Software Foundation.
  8. *
  9. * Alternatively, this software may be distributed under the terms of BSD
  10. * license.
  11. *
  12. * See README and COPYING for more details.
  13. */
  14. #include "includes.h"
  15. #include <sys/ioctl.h>
  16. #include <net/if_arp.h>
  17. #include <netlink/genl/genl.h>
  18. #include <netlink/genl/family.h>
  19. #include <netlink/genl/ctrl.h>
  20. #include "nl80211_copy.h"
  21. #ifdef CONFIG_CLIENT_MLME
  22. #include <netpacket/packet.h>
  23. #include <linux/if_ether.h>
  24. #include "radiotap.h"
  25. #include "radiotap_iter.h"
  26. #endif /* CONFIG_CLIENT_MLME */
  27. #include "wireless_copy.h"
  28. #include "common.h"
  29. #include "driver.h"
  30. #include "eloop.h"
  31. #include "ieee802_11_defs.h"
  32. #ifndef IFF_LOWER_UP
  33. #define IFF_LOWER_UP 0x10000 /* driver signals L1 up */
  34. #endif
  35. #ifndef IFF_DORMANT
  36. #define IFF_DORMANT 0x20000 /* driver signals dormant */
  37. #endif
  38. #ifndef IF_OPER_DORMANT
  39. #define IF_OPER_DORMANT 5
  40. #endif
  41. #ifndef IF_OPER_UP
  42. #define IF_OPER_UP 6
  43. #endif
  44. struct wpa_driver_nl80211_data {
  45. void *ctx;
  46. int wext_event_sock;
  47. int ioctl_sock;
  48. char ifname[IFNAMSIZ + 1];
  49. int ifindex;
  50. int if_removed;
  51. u8 *assoc_req_ies;
  52. size_t assoc_req_ies_len;
  53. u8 *assoc_resp_ies;
  54. size_t assoc_resp_ies_len;
  55. struct wpa_driver_capa capa;
  56. int has_capability;
  57. int we_version_compiled;
  58. /* for set_auth_alg fallback */
  59. int use_crypt;
  60. int auth_alg_fallback;
  61. int operstate;
  62. char mlmedev[IFNAMSIZ + 1];
  63. int scan_complete_events;
  64. struct nl_handle *nl_handle;
  65. struct nl_cache *nl_cache;
  66. struct nl_cb *nl_cb;
  67. struct genl_family *nl80211;
  68. #ifdef CONFIG_CLIENT_MLME
  69. int monitor_sock; /* socket for monitor */
  70. int monitor_ifidx;
  71. #endif /* CONFIG_CLIENT_MLME */
  72. };
  73. static void wpa_driver_nl80211_scan_timeout(void *eloop_ctx,
  74. void *timeout_ctx);
  75. static int wpa_driver_nl80211_set_mode(void *priv, int mode);
  76. static int wpa_driver_nl80211_flush_pmkid(void *priv);
  77. static int wpa_driver_nl80211_get_range(void *priv);
  78. static void
  79. wpa_driver_nl80211_finish_drv_init(struct wpa_driver_nl80211_data *drv);
  80. /* nl80211 code */
  81. static int ack_handler(struct nl_msg *msg, void *arg)
  82. {
  83. int *err = arg;
  84. *err = 0;
  85. return NL_STOP;
  86. }
  87. static int finish_handler(struct nl_msg *msg, void *arg)
  88. {
  89. int *ret = arg;
  90. *ret = 0;
  91. return NL_SKIP;
  92. }
  93. static int error_handler(struct sockaddr_nl *nla, struct nlmsgerr *err,
  94. void *arg)
  95. {
  96. int *ret = arg;
  97. *ret = err->error;
  98. return NL_SKIP;
  99. }
  100. static int send_and_recv_msgs(struct wpa_driver_nl80211_data *drv,
  101. struct nl_msg *msg,
  102. int (*valid_handler)(struct nl_msg *, void *),
  103. void *valid_data)
  104. {
  105. struct nl_cb *cb;
  106. int err = -ENOMEM;
  107. cb = nl_cb_clone(drv->nl_cb);
  108. if (!cb)
  109. goto out;
  110. err = nl_send_auto_complete(drv->nl_handle, msg);
  111. if (err < 0)
  112. goto out;
  113. err = 1;
  114. nl_cb_err(cb, NL_CB_CUSTOM, error_handler, &err);
  115. nl_cb_set(cb, NL_CB_FINISH, NL_CB_CUSTOM, finish_handler, &err);
  116. nl_cb_set(cb, NL_CB_ACK, NL_CB_CUSTOM, ack_handler, &err);
  117. if (valid_handler)
  118. nl_cb_set(cb, NL_CB_VALID, NL_CB_CUSTOM,
  119. valid_handler, valid_data);
  120. while (err > 0)
  121. nl_recvmsgs(drv->nl_handle, cb);
  122. out:
  123. nl_cb_put(cb);
  124. nlmsg_free(msg);
  125. return err;
  126. }
  127. struct family_data {
  128. const char *group;
  129. int id;
  130. };
  131. static int family_handler(struct nl_msg *msg, void *arg)
  132. {
  133. struct family_data *res = arg;
  134. struct nlattr *tb[CTRL_ATTR_MAX + 1];
  135. struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
  136. struct nlattr *mcgrp;
  137. int i;
  138. nla_parse(tb, CTRL_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
  139. genlmsg_attrlen(gnlh, 0), NULL);
  140. if (!tb[CTRL_ATTR_MCAST_GROUPS])
  141. return NL_SKIP;
  142. nla_for_each_nested(mcgrp, tb[CTRL_ATTR_MCAST_GROUPS], i) {
  143. struct nlattr *tb2[CTRL_ATTR_MCAST_GRP_MAX + 1];
  144. nla_parse(tb2, CTRL_ATTR_MCAST_GRP_MAX, nla_data(mcgrp),
  145. nla_len(mcgrp), NULL);
  146. if (!tb2[CTRL_ATTR_MCAST_GRP_NAME] ||
  147. !tb2[CTRL_ATTR_MCAST_GRP_ID] ||
  148. os_strncmp(nla_data(tb2[CTRL_ATTR_MCAST_GRP_NAME]),
  149. res->group,
  150. nla_len(tb2[CTRL_ATTR_MCAST_GRP_NAME])) != 0)
  151. continue;
  152. res->id = nla_get_u32(tb2[CTRL_ATTR_MCAST_GRP_ID]);
  153. break;
  154. };
  155. return NL_SKIP;
  156. }
  157. static int nl_get_multicast_id(struct wpa_driver_nl80211_data *drv,
  158. const char *family, const char *group)
  159. {
  160. struct nl_msg *msg;
  161. int ret = -1;
  162. struct family_data res = { group, -ENOENT };
  163. msg = nlmsg_alloc();
  164. if (!msg)
  165. return -ENOMEM;
  166. genlmsg_put(msg, 0, 0, genl_ctrl_resolve(drv->nl_handle, "nlctrl"),
  167. 0, 0, CTRL_CMD_GETFAMILY, 0);
  168. NLA_PUT_STRING(msg, CTRL_ATTR_FAMILY_NAME, family);
  169. ret = send_and_recv_msgs(drv, msg, family_handler, &res);
  170. msg = NULL;
  171. if (ret == 0)
  172. ret = res.id;
  173. nla_put_failure:
  174. nlmsg_free(msg);
  175. return ret;
  176. }
  177. static int wpa_driver_nl80211_send_oper_ifla(
  178. struct wpa_driver_nl80211_data *drv,
  179. int linkmode, int operstate)
  180. {
  181. struct {
  182. struct nlmsghdr hdr;
  183. struct ifinfomsg ifinfo;
  184. char opts[16];
  185. } req;
  186. struct rtattr *rta;
  187. static int nl_seq;
  188. ssize_t ret;
  189. os_memset(&req, 0, sizeof(req));
  190. req.hdr.nlmsg_len = NLMSG_LENGTH(sizeof(struct ifinfomsg));
  191. req.hdr.nlmsg_type = RTM_SETLINK;
  192. req.hdr.nlmsg_flags = NLM_F_REQUEST;
  193. req.hdr.nlmsg_seq = ++nl_seq;
  194. req.hdr.nlmsg_pid = 0;
  195. req.ifinfo.ifi_family = AF_UNSPEC;
  196. req.ifinfo.ifi_type = 0;
  197. req.ifinfo.ifi_index = drv->ifindex;
  198. req.ifinfo.ifi_flags = 0;
  199. req.ifinfo.ifi_change = 0;
  200. if (linkmode != -1) {
  201. rta = (struct rtattr *)
  202. ((char *) &req + NLMSG_ALIGN(req.hdr.nlmsg_len));
  203. rta->rta_type = IFLA_LINKMODE;
  204. rta->rta_len = RTA_LENGTH(sizeof(char));
  205. *((char *) RTA_DATA(rta)) = linkmode;
  206. req.hdr.nlmsg_len = NLMSG_ALIGN(req.hdr.nlmsg_len) +
  207. RTA_LENGTH(sizeof(char));
  208. }
  209. if (operstate != -1) {
  210. rta = (struct rtattr *)
  211. ((char *) &req + NLMSG_ALIGN(req.hdr.nlmsg_len));
  212. rta->rta_type = IFLA_OPERSTATE;
  213. rta->rta_len = RTA_LENGTH(sizeof(char));
  214. *((char *) RTA_DATA(rta)) = operstate;
  215. req.hdr.nlmsg_len = NLMSG_ALIGN(req.hdr.nlmsg_len) +
  216. RTA_LENGTH(sizeof(char));
  217. }
  218. wpa_printf(MSG_DEBUG, "WEXT: Operstate: linkmode=%d, operstate=%d",
  219. linkmode, operstate);
  220. ret = send(drv->wext_event_sock, &req, req.hdr.nlmsg_len, 0);
  221. if (ret < 0) {
  222. wpa_printf(MSG_DEBUG, "WEXT: Sending operstate IFLA failed: "
  223. "%s (assume operstate is not supported)",
  224. strerror(errno));
  225. }
  226. return ret < 0 ? -1 : 0;
  227. }
  228. static int wpa_driver_nl80211_set_auth_param(
  229. struct wpa_driver_nl80211_data *drv, int idx, u32 value)
  230. {
  231. struct iwreq iwr;
  232. int ret = 0;
  233. os_memset(&iwr, 0, sizeof(iwr));
  234. os_strlcpy(iwr.ifr_name, drv->ifname, IFNAMSIZ);
  235. iwr.u.param.flags = idx & IW_AUTH_INDEX;
  236. iwr.u.param.value = value;
  237. if (ioctl(drv->ioctl_sock, SIOCSIWAUTH, &iwr) < 0) {
  238. if (errno != EOPNOTSUPP) {
  239. wpa_printf(MSG_DEBUG, "WEXT: SIOCSIWAUTH(param %d "
  240. "value 0x%x) failed: %s)",
  241. idx, value, strerror(errno));
  242. }
  243. ret = errno == EOPNOTSUPP ? -2 : -1;
  244. }
  245. return ret;
  246. }
  247. static int wpa_driver_nl80211_get_bssid(void *priv, u8 *bssid)
  248. {
  249. struct wpa_driver_nl80211_data *drv = priv;
  250. struct iwreq iwr;
  251. int ret = 0;
  252. os_memset(&iwr, 0, sizeof(iwr));
  253. os_strlcpy(iwr.ifr_name, drv->ifname, IFNAMSIZ);
  254. if (ioctl(drv->ioctl_sock, SIOCGIWAP, &iwr) < 0) {
  255. perror("ioctl[SIOCGIWAP]");
  256. ret = -1;
  257. }
  258. os_memcpy(bssid, iwr.u.ap_addr.sa_data, ETH_ALEN);
  259. return ret;
  260. }
  261. static int wpa_driver_nl80211_set_bssid(void *priv, const u8 *bssid)
  262. {
  263. struct wpa_driver_nl80211_data *drv = priv;
  264. struct iwreq iwr;
  265. int ret = 0;
  266. os_memset(&iwr, 0, sizeof(iwr));
  267. os_strlcpy(iwr.ifr_name, drv->ifname, IFNAMSIZ);
  268. iwr.u.ap_addr.sa_family = ARPHRD_ETHER;
  269. if (bssid)
  270. os_memcpy(iwr.u.ap_addr.sa_data, bssid, ETH_ALEN);
  271. else
  272. os_memset(iwr.u.ap_addr.sa_data, 0, ETH_ALEN);
  273. if (ioctl(drv->ioctl_sock, SIOCSIWAP, &iwr) < 0) {
  274. perror("ioctl[SIOCSIWAP]");
  275. ret = -1;
  276. }
  277. return ret;
  278. }
  279. static int wpa_driver_nl80211_get_ssid(void *priv, u8 *ssid)
  280. {
  281. struct wpa_driver_nl80211_data *drv = priv;
  282. struct iwreq iwr;
  283. int ret = 0;
  284. os_memset(&iwr, 0, sizeof(iwr));
  285. os_strlcpy(iwr.ifr_name, drv->ifname, IFNAMSIZ);
  286. iwr.u.essid.pointer = (caddr_t) ssid;
  287. iwr.u.essid.length = 32;
  288. if (ioctl(drv->ioctl_sock, SIOCGIWESSID, &iwr) < 0) {
  289. perror("ioctl[SIOCGIWESSID]");
  290. ret = -1;
  291. } else {
  292. ret = iwr.u.essid.length;
  293. if (ret > 32)
  294. ret = 32;
  295. /* Some drivers include nul termination in the SSID, so let's
  296. * remove it here before further processing. WE-21 changes this
  297. * to explicitly require the length _not_ to include nul
  298. * termination. */
  299. if (ret > 0 && ssid[ret - 1] == '\0' &&
  300. drv->we_version_compiled < 21)
  301. ret--;
  302. }
  303. return ret;
  304. }
  305. static int wpa_driver_nl80211_set_ssid(void *priv, const u8 *ssid,
  306. size_t ssid_len)
  307. {
  308. struct wpa_driver_nl80211_data *drv = priv;
  309. struct iwreq iwr;
  310. int ret = 0;
  311. char buf[33];
  312. if (ssid_len > 32)
  313. return -1;
  314. os_memset(&iwr, 0, sizeof(iwr));
  315. os_strlcpy(iwr.ifr_name, drv->ifname, IFNAMSIZ);
  316. /* flags: 1 = ESSID is active, 0 = not (promiscuous) */
  317. iwr.u.essid.flags = (ssid_len != 0);
  318. os_memset(buf, 0, sizeof(buf));
  319. os_memcpy(buf, ssid, ssid_len);
  320. iwr.u.essid.pointer = (caddr_t) buf;
  321. if (drv->we_version_compiled < 21) {
  322. /* For historic reasons, set SSID length to include one extra
  323. * character, C string nul termination, even though SSID is
  324. * really an octet string that should not be presented as a C
  325. * string. Some Linux drivers decrement the length by one and
  326. * can thus end up missing the last octet of the SSID if the
  327. * length is not incremented here. WE-21 changes this to
  328. * explicitly require the length _not_ to include nul
  329. * termination. */
  330. if (ssid_len)
  331. ssid_len++;
  332. }
  333. iwr.u.essid.length = ssid_len;
  334. if (ioctl(drv->ioctl_sock, SIOCSIWESSID, &iwr) < 0) {
  335. perror("ioctl[SIOCSIWESSID]");
  336. ret = -1;
  337. }
  338. return ret;
  339. }
  340. static int wpa_driver_nl80211_set_freq(void *priv, int freq)
  341. {
  342. struct wpa_driver_nl80211_data *drv = priv;
  343. struct iwreq iwr;
  344. int ret = 0;
  345. os_memset(&iwr, 0, sizeof(iwr));
  346. os_strlcpy(iwr.ifr_name, drv->ifname, IFNAMSIZ);
  347. iwr.u.freq.m = freq * 100000;
  348. iwr.u.freq.e = 1;
  349. if (ioctl(drv->ioctl_sock, SIOCSIWFREQ, &iwr) < 0) {
  350. perror("ioctl[SIOCSIWFREQ]");
  351. ret = -1;
  352. }
  353. return ret;
  354. }
  355. static void
  356. wpa_driver_nl80211_event_wireless_custom(void *ctx, char *custom)
  357. {
  358. union wpa_event_data data;
  359. wpa_printf(MSG_MSGDUMP, "WEXT: Custom wireless event: '%s'",
  360. custom);
  361. os_memset(&data, 0, sizeof(data));
  362. /* Host AP driver */
  363. if (os_strncmp(custom, "MLME-MICHAELMICFAILURE.indication", 33) == 0) {
  364. data.michael_mic_failure.unicast =
  365. os_strstr(custom, " unicast ") != NULL;
  366. /* TODO: parse parameters(?) */
  367. wpa_supplicant_event(ctx, EVENT_MICHAEL_MIC_FAILURE, &data);
  368. } else if (os_strncmp(custom, "ASSOCINFO(ReqIEs=", 17) == 0) {
  369. char *spos;
  370. int bytes;
  371. spos = custom + 17;
  372. bytes = strspn(spos, "0123456789abcdefABCDEF");
  373. if (!bytes || (bytes & 1))
  374. return;
  375. bytes /= 2;
  376. data.assoc_info.req_ies = os_malloc(bytes);
  377. if (data.assoc_info.req_ies == NULL)
  378. return;
  379. data.assoc_info.req_ies_len = bytes;
  380. hexstr2bin(spos, data.assoc_info.req_ies, bytes);
  381. spos += bytes * 2;
  382. data.assoc_info.resp_ies = NULL;
  383. data.assoc_info.resp_ies_len = 0;
  384. if (os_strncmp(spos, " RespIEs=", 9) == 0) {
  385. spos += 9;
  386. bytes = strspn(spos, "0123456789abcdefABCDEF");
  387. if (!bytes || (bytes & 1))
  388. goto done;
  389. bytes /= 2;
  390. data.assoc_info.resp_ies = os_malloc(bytes);
  391. if (data.assoc_info.resp_ies == NULL)
  392. goto done;
  393. data.assoc_info.resp_ies_len = bytes;
  394. hexstr2bin(spos, data.assoc_info.resp_ies, bytes);
  395. }
  396. wpa_supplicant_event(ctx, EVENT_ASSOCINFO, &data);
  397. done:
  398. os_free(data.assoc_info.resp_ies);
  399. os_free(data.assoc_info.req_ies);
  400. #ifdef CONFIG_PEERKEY
  401. } else if (os_strncmp(custom, "STKSTART.request=", 17) == 0) {
  402. if (hwaddr_aton(custom + 17, data.stkstart.peer)) {
  403. wpa_printf(MSG_DEBUG, "WEXT: unrecognized "
  404. "STKSTART.request '%s'", custom + 17);
  405. return;
  406. }
  407. wpa_supplicant_event(ctx, EVENT_STKSTART, &data);
  408. #endif /* CONFIG_PEERKEY */
  409. }
  410. }
  411. static int wpa_driver_nl80211_event_wireless_michaelmicfailure(
  412. void *ctx, const char *ev, size_t len)
  413. {
  414. const struct iw_michaelmicfailure *mic;
  415. union wpa_event_data data;
  416. if (len < sizeof(*mic))
  417. return -1;
  418. mic = (const struct iw_michaelmicfailure *) ev;
  419. wpa_printf(MSG_DEBUG, "Michael MIC failure wireless event: "
  420. "flags=0x%x src_addr=" MACSTR, mic->flags,
  421. MAC2STR(mic->src_addr.sa_data));
  422. os_memset(&data, 0, sizeof(data));
  423. data.michael_mic_failure.unicast = !(mic->flags & IW_MICFAILURE_GROUP);
  424. wpa_supplicant_event(ctx, EVENT_MICHAEL_MIC_FAILURE, &data);
  425. return 0;
  426. }
  427. static int wpa_driver_nl80211_event_wireless_pmkidcand(
  428. struct wpa_driver_nl80211_data *drv, const char *ev, size_t len)
  429. {
  430. const struct iw_pmkid_cand *cand;
  431. union wpa_event_data data;
  432. const u8 *addr;
  433. if (len < sizeof(*cand))
  434. return -1;
  435. cand = (const struct iw_pmkid_cand *) ev;
  436. addr = (const u8 *) cand->bssid.sa_data;
  437. wpa_printf(MSG_DEBUG, "PMKID candidate wireless event: "
  438. "flags=0x%x index=%d bssid=" MACSTR, cand->flags,
  439. cand->index, MAC2STR(addr));
  440. os_memset(&data, 0, sizeof(data));
  441. os_memcpy(data.pmkid_candidate.bssid, addr, ETH_ALEN);
  442. data.pmkid_candidate.index = cand->index;
  443. data.pmkid_candidate.preauth = cand->flags & IW_PMKID_CAND_PREAUTH;
  444. wpa_supplicant_event(drv->ctx, EVENT_PMKID_CANDIDATE, &data);
  445. return 0;
  446. }
  447. static int wpa_driver_nl80211_event_wireless_assocreqie(
  448. struct wpa_driver_nl80211_data *drv, const char *ev, int len)
  449. {
  450. if (len < 0)
  451. return -1;
  452. wpa_hexdump(MSG_DEBUG, "AssocReq IE wireless event", (const u8 *) ev,
  453. len);
  454. os_free(drv->assoc_req_ies);
  455. drv->assoc_req_ies = os_malloc(len);
  456. if (drv->assoc_req_ies == NULL) {
  457. drv->assoc_req_ies_len = 0;
  458. return -1;
  459. }
  460. os_memcpy(drv->assoc_req_ies, ev, len);
  461. drv->assoc_req_ies_len = len;
  462. return 0;
  463. }
  464. static int wpa_driver_nl80211_event_wireless_assocrespie(
  465. struct wpa_driver_nl80211_data *drv, const char *ev, int len)
  466. {
  467. if (len < 0)
  468. return -1;
  469. wpa_hexdump(MSG_DEBUG, "AssocResp IE wireless event", (const u8 *) ev,
  470. len);
  471. os_free(drv->assoc_resp_ies);
  472. drv->assoc_resp_ies = os_malloc(len);
  473. if (drv->assoc_resp_ies == NULL) {
  474. drv->assoc_resp_ies_len = 0;
  475. return -1;
  476. }
  477. os_memcpy(drv->assoc_resp_ies, ev, len);
  478. drv->assoc_resp_ies_len = len;
  479. return 0;
  480. }
  481. static void wpa_driver_nl80211_event_assoc_ies(struct wpa_driver_nl80211_data *drv)
  482. {
  483. union wpa_event_data data;
  484. if (drv->assoc_req_ies == NULL && drv->assoc_resp_ies == NULL)
  485. return;
  486. os_memset(&data, 0, sizeof(data));
  487. if (drv->assoc_req_ies) {
  488. data.assoc_info.req_ies = drv->assoc_req_ies;
  489. drv->assoc_req_ies = NULL;
  490. data.assoc_info.req_ies_len = drv->assoc_req_ies_len;
  491. }
  492. if (drv->assoc_resp_ies) {
  493. data.assoc_info.resp_ies = drv->assoc_resp_ies;
  494. drv->assoc_resp_ies = NULL;
  495. data.assoc_info.resp_ies_len = drv->assoc_resp_ies_len;
  496. }
  497. wpa_supplicant_event(drv->ctx, EVENT_ASSOCINFO, &data);
  498. os_free(data.assoc_info.req_ies);
  499. os_free(data.assoc_info.resp_ies);
  500. }
  501. static void wpa_driver_nl80211_event_wireless(struct wpa_driver_nl80211_data *drv,
  502. void *ctx, char *data, int len)
  503. {
  504. struct iw_event iwe_buf, *iwe = &iwe_buf;
  505. char *pos, *end, *custom, *buf;
  506. pos = data;
  507. end = data + len;
  508. while (pos + IW_EV_LCP_LEN <= end) {
  509. /* Event data may be unaligned, so make a local, aligned copy
  510. * before processing. */
  511. os_memcpy(&iwe_buf, pos, IW_EV_LCP_LEN);
  512. wpa_printf(MSG_DEBUG, "Wireless event: cmd=0x%x len=%d",
  513. iwe->cmd, iwe->len);
  514. if (iwe->len <= IW_EV_LCP_LEN)
  515. return;
  516. custom = pos + IW_EV_POINT_LEN;
  517. if (drv->we_version_compiled > 18 &&
  518. (iwe->cmd == IWEVMICHAELMICFAILURE ||
  519. iwe->cmd == IWEVCUSTOM ||
  520. iwe->cmd == IWEVASSOCREQIE ||
  521. iwe->cmd == IWEVASSOCRESPIE ||
  522. iwe->cmd == IWEVPMKIDCAND)) {
  523. /* WE-19 removed the pointer from struct iw_point */
  524. char *dpos = (char *) &iwe_buf.u.data.length;
  525. int dlen = dpos - (char *) &iwe_buf;
  526. os_memcpy(dpos, pos + IW_EV_LCP_LEN,
  527. sizeof(struct iw_event) - dlen);
  528. } else {
  529. os_memcpy(&iwe_buf, pos, sizeof(struct iw_event));
  530. custom += IW_EV_POINT_OFF;
  531. }
  532. switch (iwe->cmd) {
  533. case SIOCGIWAP:
  534. wpa_printf(MSG_DEBUG, "Wireless event: new AP: "
  535. MACSTR,
  536. MAC2STR((u8 *) iwe->u.ap_addr.sa_data));
  537. if (is_zero_ether_addr(
  538. (const u8 *) iwe->u.ap_addr.sa_data) ||
  539. os_memcmp(iwe->u.ap_addr.sa_data,
  540. "\x44\x44\x44\x44\x44\x44", ETH_ALEN) ==
  541. 0) {
  542. os_free(drv->assoc_req_ies);
  543. drv->assoc_req_ies = NULL;
  544. os_free(drv->assoc_resp_ies);
  545. drv->assoc_resp_ies = NULL;
  546. wpa_supplicant_event(ctx, EVENT_DISASSOC,
  547. NULL);
  548. } else {
  549. wpa_driver_nl80211_event_assoc_ies(drv);
  550. wpa_supplicant_event(ctx, EVENT_ASSOC, NULL);
  551. }
  552. break;
  553. case IWEVMICHAELMICFAILURE:
  554. wpa_driver_nl80211_event_wireless_michaelmicfailure(
  555. ctx, custom, iwe->u.data.length);
  556. break;
  557. case IWEVCUSTOM:
  558. if (custom + iwe->u.data.length > end)
  559. return;
  560. buf = os_malloc(iwe->u.data.length + 1);
  561. if (buf == NULL)
  562. return;
  563. os_memcpy(buf, custom, iwe->u.data.length);
  564. buf[iwe->u.data.length] = '\0';
  565. wpa_driver_nl80211_event_wireless_custom(ctx, buf);
  566. os_free(buf);
  567. break;
  568. case IWEVASSOCREQIE:
  569. wpa_driver_nl80211_event_wireless_assocreqie(
  570. drv, custom, iwe->u.data.length);
  571. break;
  572. case IWEVASSOCRESPIE:
  573. wpa_driver_nl80211_event_wireless_assocrespie(
  574. drv, custom, iwe->u.data.length);
  575. break;
  576. case IWEVPMKIDCAND:
  577. wpa_driver_nl80211_event_wireless_pmkidcand(
  578. drv, custom, iwe->u.data.length);
  579. break;
  580. }
  581. pos += iwe->len;
  582. }
  583. }
  584. static void wpa_driver_nl80211_event_link(struct wpa_driver_nl80211_data *drv,
  585. void *ctx, char *buf, size_t len,
  586. int del)
  587. {
  588. union wpa_event_data event;
  589. os_memset(&event, 0, sizeof(event));
  590. if (len > sizeof(event.interface_status.ifname))
  591. len = sizeof(event.interface_status.ifname) - 1;
  592. os_memcpy(event.interface_status.ifname, buf, len);
  593. event.interface_status.ievent = del ? EVENT_INTERFACE_REMOVED :
  594. EVENT_INTERFACE_ADDED;
  595. wpa_printf(MSG_DEBUG, "RTM_%sLINK, IFLA_IFNAME: Interface '%s' %s",
  596. del ? "DEL" : "NEW",
  597. event.interface_status.ifname,
  598. del ? "removed" : "added");
  599. if (os_strcmp(drv->ifname, event.interface_status.ifname) == 0) {
  600. if (del)
  601. drv->if_removed = 1;
  602. else
  603. drv->if_removed = 0;
  604. }
  605. wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &event);
  606. }
  607. static int wpa_driver_nl80211_own_ifname(struct wpa_driver_nl80211_data *drv,
  608. struct nlmsghdr *h)
  609. {
  610. struct ifinfomsg *ifi;
  611. int attrlen, _nlmsg_len, rta_len;
  612. struct rtattr *attr;
  613. ifi = NLMSG_DATA(h);
  614. _nlmsg_len = NLMSG_ALIGN(sizeof(struct ifinfomsg));
  615. attrlen = h->nlmsg_len - _nlmsg_len;
  616. if (attrlen < 0)
  617. return 0;
  618. attr = (struct rtattr *) (((char *) ifi) + _nlmsg_len);
  619. rta_len = RTA_ALIGN(sizeof(struct rtattr));
  620. while (RTA_OK(attr, attrlen)) {
  621. if (attr->rta_type == IFLA_IFNAME) {
  622. if (os_strcmp(((char *) attr) + rta_len, drv->ifname)
  623. == 0)
  624. return 1;
  625. else
  626. break;
  627. }
  628. attr = RTA_NEXT(attr, attrlen);
  629. }
  630. return 0;
  631. }
  632. static int wpa_driver_nl80211_own_ifindex(struct wpa_driver_nl80211_data *drv,
  633. int ifindex, struct nlmsghdr *h)
  634. {
  635. if (drv->ifindex == ifindex)
  636. return 1;
  637. if (drv->if_removed && wpa_driver_nl80211_own_ifname(drv, h)) {
  638. drv->ifindex = if_nametoindex(drv->ifname);
  639. wpa_printf(MSG_DEBUG, "nl80211: Update ifindex for a removed "
  640. "interface");
  641. wpa_driver_nl80211_finish_drv_init(drv);
  642. return 1;
  643. }
  644. return 0;
  645. }
  646. static void wpa_driver_nl80211_event_rtm_newlink(struct wpa_driver_nl80211_data *drv,
  647. void *ctx, struct nlmsghdr *h,
  648. size_t len)
  649. {
  650. struct ifinfomsg *ifi;
  651. int attrlen, _nlmsg_len, rta_len;
  652. struct rtattr * attr;
  653. if (len < sizeof(*ifi))
  654. return;
  655. ifi = NLMSG_DATA(h);
  656. if (!wpa_driver_nl80211_own_ifindex(drv, ifi->ifi_index, h)) {
  657. wpa_printf(MSG_DEBUG, "Ignore event for foreign ifindex %d",
  658. ifi->ifi_index);
  659. return;
  660. }
  661. wpa_printf(MSG_DEBUG, "RTM_NEWLINK: operstate=%d ifi_flags=0x%x "
  662. "(%s%s%s%s)",
  663. drv->operstate, ifi->ifi_flags,
  664. (ifi->ifi_flags & IFF_UP) ? "[UP]" : "",
  665. (ifi->ifi_flags & IFF_RUNNING) ? "[RUNNING]" : "",
  666. (ifi->ifi_flags & IFF_LOWER_UP) ? "[LOWER_UP]" : "",
  667. (ifi->ifi_flags & IFF_DORMANT) ? "[DORMANT]" : "");
  668. /*
  669. * Some drivers send the association event before the operup event--in
  670. * this case, lifting operstate in wpa_driver_nl80211_set_operstate()
  671. * fails. This will hit us when wpa_supplicant does not need to do
  672. * IEEE 802.1X authentication
  673. */
  674. if (drv->operstate == 1 &&
  675. (ifi->ifi_flags & (IFF_LOWER_UP | IFF_DORMANT)) == IFF_LOWER_UP &&
  676. !(ifi->ifi_flags & IFF_RUNNING))
  677. wpa_driver_nl80211_send_oper_ifla(drv, -1, IF_OPER_UP);
  678. _nlmsg_len = NLMSG_ALIGN(sizeof(struct ifinfomsg));
  679. attrlen = h->nlmsg_len - _nlmsg_len;
  680. if (attrlen < 0)
  681. return;
  682. attr = (struct rtattr *) (((char *) ifi) + _nlmsg_len);
  683. rta_len = RTA_ALIGN(sizeof(struct rtattr));
  684. while (RTA_OK(attr, attrlen)) {
  685. if (attr->rta_type == IFLA_WIRELESS) {
  686. wpa_driver_nl80211_event_wireless(
  687. drv, ctx, ((char *) attr) + rta_len,
  688. attr->rta_len - rta_len);
  689. } else if (attr->rta_type == IFLA_IFNAME) {
  690. wpa_driver_nl80211_event_link(
  691. drv, ctx,
  692. ((char *) attr) + rta_len,
  693. attr->rta_len - rta_len, 0);
  694. }
  695. attr = RTA_NEXT(attr, attrlen);
  696. }
  697. }
  698. static void wpa_driver_nl80211_event_rtm_dellink(struct wpa_driver_nl80211_data *drv,
  699. void *ctx, struct nlmsghdr *h,
  700. size_t len)
  701. {
  702. struct ifinfomsg *ifi;
  703. int attrlen, _nlmsg_len, rta_len;
  704. struct rtattr * attr;
  705. if (len < sizeof(*ifi))
  706. return;
  707. ifi = NLMSG_DATA(h);
  708. _nlmsg_len = NLMSG_ALIGN(sizeof(struct ifinfomsg));
  709. attrlen = h->nlmsg_len - _nlmsg_len;
  710. if (attrlen < 0)
  711. return;
  712. attr = (struct rtattr *) (((char *) ifi) + _nlmsg_len);
  713. rta_len = RTA_ALIGN(sizeof(struct rtattr));
  714. while (RTA_OK(attr, attrlen)) {
  715. if (attr->rta_type == IFLA_IFNAME) {
  716. wpa_driver_nl80211_event_link(
  717. drv, ctx,
  718. ((char *) attr) + rta_len,
  719. attr->rta_len - rta_len, 1);
  720. }
  721. attr = RTA_NEXT(attr, attrlen);
  722. }
  723. }
  724. static void wpa_driver_nl80211_event_receive_wext(int sock, void *eloop_ctx,
  725. void *sock_ctx)
  726. {
  727. char buf[8192];
  728. int left;
  729. struct sockaddr_nl from;
  730. socklen_t fromlen;
  731. struct nlmsghdr *h;
  732. int max_events = 10;
  733. try_again:
  734. fromlen = sizeof(from);
  735. left = recvfrom(sock, buf, sizeof(buf), MSG_DONTWAIT,
  736. (struct sockaddr *) &from, &fromlen);
  737. if (left < 0) {
  738. if (errno != EINTR && errno != EAGAIN)
  739. perror("recvfrom(netlink)");
  740. return;
  741. }
  742. h = (struct nlmsghdr *) buf;
  743. while (left >= (int) sizeof(*h)) {
  744. int len, plen;
  745. len = h->nlmsg_len;
  746. plen = len - sizeof(*h);
  747. if (len > left || plen < 0) {
  748. wpa_printf(MSG_DEBUG, "Malformed netlink message: "
  749. "len=%d left=%d plen=%d",
  750. len, left, plen);
  751. break;
  752. }
  753. switch (h->nlmsg_type) {
  754. case RTM_NEWLINK:
  755. wpa_driver_nl80211_event_rtm_newlink(eloop_ctx, sock_ctx,
  756. h, plen);
  757. break;
  758. case RTM_DELLINK:
  759. wpa_driver_nl80211_event_rtm_dellink(eloop_ctx, sock_ctx,
  760. h, plen);
  761. break;
  762. }
  763. len = NLMSG_ALIGN(len);
  764. left -= len;
  765. h = (struct nlmsghdr *) ((char *) h + len);
  766. }
  767. if (left > 0) {
  768. wpa_printf(MSG_DEBUG, "%d extra bytes in the end of netlink "
  769. "message", left);
  770. }
  771. if (--max_events > 0) {
  772. /*
  773. * Try to receive all events in one eloop call in order to
  774. * limit race condition on cases where AssocInfo event, Assoc
  775. * event, and EAPOL frames are received more or less at the
  776. * same time. We want to process the event messages first
  777. * before starting EAPOL processing.
  778. */
  779. goto try_again;
  780. }
  781. }
  782. static int no_seq_check(struct nl_msg *msg, void *arg)
  783. {
  784. return NL_OK;
  785. }
  786. static int process_event(struct nl_msg *msg, void *arg)
  787. {
  788. struct wpa_driver_nl80211_data *drv = arg;
  789. struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
  790. struct nlattr *tb[NL80211_ATTR_MAX + 1];
  791. nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
  792. genlmsg_attrlen(gnlh, 0), NULL);
  793. if (tb[NL80211_ATTR_IFINDEX]) {
  794. int ifindex = nla_get_u32(tb[NL80211_ATTR_IFINDEX]);
  795. if (ifindex != drv->ifindex) {
  796. wpa_printf(MSG_DEBUG, "nl80211: Ignored event (cmd=%d)"
  797. " for foreign interface (ifindex %d)",
  798. gnlh->cmd, ifindex);
  799. return NL_SKIP;
  800. }
  801. }
  802. switch (gnlh->cmd) {
  803. case NL80211_CMD_NEW_SCAN_RESULTS:
  804. wpa_printf(MSG_DEBUG, "nl80211: New scan results available");
  805. drv->scan_complete_events = 1;
  806. eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout, drv,
  807. drv->ctx);
  808. wpa_supplicant_event(drv->ctx, EVENT_SCAN_RESULTS, NULL);
  809. break;
  810. case NL80211_CMD_SCAN_ABORTED:
  811. wpa_printf(MSG_DEBUG, "nl80211: Scan aborted");
  812. /*
  813. * Need to indicate that scan results are available in order
  814. * not to make wpa_supplicant stop its scanning.
  815. */
  816. eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout, drv,
  817. drv->ctx);
  818. wpa_supplicant_event(drv->ctx, EVENT_SCAN_RESULTS, NULL);
  819. break;
  820. default:
  821. wpa_printf(MSG_DEBUG, "nl0211: Ignored unknown event (cmd=%d)",
  822. gnlh->cmd);
  823. break;
  824. }
  825. return NL_SKIP;
  826. }
  827. static void wpa_driver_nl80211_event_receive(int sock, void *eloop_ctx,
  828. void *sock_ctx)
  829. {
  830. struct nl_cb *cb;
  831. struct wpa_driver_nl80211_data *drv = eloop_ctx;
  832. wpa_printf(MSG_DEBUG, "nl80211: Event message available");
  833. cb = nl_cb_clone(drv->nl_cb);
  834. if (!cb)
  835. return;
  836. nl_cb_set(cb, NL_CB_SEQ_CHECK, NL_CB_CUSTOM, no_seq_check, NULL);
  837. nl_cb_set(cb, NL_CB_VALID, NL_CB_CUSTOM, process_event, drv);
  838. nl_recvmsgs(drv->nl_handle, cb);
  839. nl_cb_put(cb);
  840. }
  841. static int wpa_driver_nl80211_get_ifflags_ifname(struct wpa_driver_nl80211_data *drv,
  842. const char *ifname, int *flags)
  843. {
  844. struct ifreq ifr;
  845. os_memset(&ifr, 0, sizeof(ifr));
  846. os_strlcpy(ifr.ifr_name, ifname, IFNAMSIZ);
  847. if (ioctl(drv->ioctl_sock, SIOCGIFFLAGS, (caddr_t) &ifr) < 0) {
  848. perror("ioctl[SIOCGIFFLAGS]");
  849. return -1;
  850. }
  851. *flags = ifr.ifr_flags & 0xffff;
  852. return 0;
  853. }
  854. /**
  855. * wpa_driver_nl80211_get_ifflags - Get interface flags (SIOCGIFFLAGS)
  856. * @drv: driver_nl80211 private data
  857. * @flags: Pointer to returned flags value
  858. * Returns: 0 on success, -1 on failure
  859. */
  860. static int wpa_driver_nl80211_get_ifflags(struct wpa_driver_nl80211_data *drv,
  861. int *flags)
  862. {
  863. return wpa_driver_nl80211_get_ifflags_ifname(drv, drv->ifname, flags);
  864. }
  865. static int wpa_driver_nl80211_set_ifflags_ifname(
  866. struct wpa_driver_nl80211_data *drv,
  867. const char *ifname, int flags)
  868. {
  869. struct ifreq ifr;
  870. os_memset(&ifr, 0, sizeof(ifr));
  871. os_strlcpy(ifr.ifr_name, ifname, IFNAMSIZ);
  872. ifr.ifr_flags = flags & 0xffff;
  873. if (ioctl(drv->ioctl_sock, SIOCSIFFLAGS, (caddr_t) &ifr) < 0) {
  874. perror("SIOCSIFFLAGS");
  875. return -1;
  876. }
  877. return 0;
  878. }
  879. /**
  880. * wpa_driver_nl80211_set_ifflags - Set interface flags (SIOCSIFFLAGS)
  881. * @drv: driver_nl80211 private data
  882. * @flags: New value for flags
  883. * Returns: 0 on success, -1 on failure
  884. */
  885. static int wpa_driver_nl80211_set_ifflags(struct wpa_driver_nl80211_data *drv,
  886. int flags)
  887. {
  888. return wpa_driver_nl80211_set_ifflags_ifname(drv, drv->ifname, flags);
  889. }
  890. /**
  891. * wpa_driver_nl80211_set_country - ask nl80211 to set the regulatory domain
  892. * @priv: driver_nl80211 private data
  893. * @alpha2_arg: country to which to switch to
  894. * Returns: 0 on success, -1 on failure
  895. *
  896. * This asks nl80211 to set the regulatory domain for given
  897. * country ISO / IEC alpha2.
  898. */
  899. static int wpa_driver_nl80211_set_country(void *priv, const char *alpha2_arg)
  900. {
  901. struct wpa_driver_nl80211_data *drv = priv;
  902. char alpha2[3];
  903. struct nl_msg *msg;
  904. msg = nlmsg_alloc();
  905. if (!msg)
  906. goto nla_put_failure;
  907. alpha2[0] = alpha2_arg[0];
  908. alpha2[1] = alpha2_arg[1];
  909. alpha2[2] = '\0';
  910. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
  911. 0, NL80211_CMD_REQ_SET_REG, 0);
  912. NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, alpha2);
  913. if (send_and_recv_msgs(drv, msg, NULL, NULL))
  914. return -EINVAL;
  915. return 0;
  916. nla_put_failure:
  917. return -EINVAL;
  918. }
  919. static int wpa_driver_nl80211_set_probe_req_ie(void *priv, const u8 *ies,
  920. size_t ies_len)
  921. {
  922. struct wpa_driver_nl80211_data *drv = priv;
  923. struct nl_msg *msg;
  924. int ret = -1;
  925. msg = nlmsg_alloc();
  926. if (!msg)
  927. return -ENOMEM;
  928. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
  929. NL80211_CMD_SET_MGMT_EXTRA_IE, 0);
  930. NLA_PUT_U8(msg, NL80211_ATTR_MGMT_SUBTYPE, 4 /* ProbeReq */);
  931. if (ies)
  932. NLA_PUT(msg, NL80211_ATTR_IE, ies_len, ies);
  933. ret = 0;
  934. NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
  935. ret = send_and_recv_msgs(drv, msg, NULL, NULL);
  936. return ret;
  937. nla_put_failure:
  938. return -ENOBUFS;
  939. }
  940. #ifdef CONFIG_CLIENT_MLME
  941. static int nl80211_set_vif(struct wpa_driver_nl80211_data *drv,
  942. int drop_unencrypted, int userspace_mlme)
  943. {
  944. #ifdef NL80211_CMD_SET_VIF
  945. struct nl_msg *msg;
  946. int ret = -1;
  947. msg = nlmsg_alloc();
  948. if (!msg)
  949. return -ENOMEM;
  950. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
  951. NL80211_CMD_SET_VIF, 0);
  952. if (drop_unencrypted >= 0)
  953. NLA_PUT_U8(msg, NL80211_ATTR_VIF_DROP_UNENCRYPTED,
  954. drop_unencrypted);
  955. if (userspace_mlme >= 0)
  956. NLA_PUT_U8(msg, NL80211_ATTR_VIF_USERSPACE_MLME,
  957. userspace_mlme);
  958. ret = 0;
  959. NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
  960. ret = send_and_recv_msgs(drv, msg, NULL, NULL);
  961. return ret;
  962. nla_put_failure:
  963. return -ENOBUFS;
  964. #else /* NL80211_CMD_SET_VIF */
  965. return -1;
  966. #endif /* NL80211_CMD_SET_VIF */
  967. }
  968. static int wpa_driver_nl80211_set_userspace_mlme(
  969. struct wpa_driver_nl80211_data *drv, int enabled)
  970. {
  971. return nl80211_set_vif(drv, -1, enabled);
  972. }
  973. static void nl80211_remove_iface(struct wpa_driver_nl80211_data *drv,
  974. int ifidx)
  975. {
  976. struct nl_msg *msg;
  977. msg = nlmsg_alloc();
  978. if (!msg)
  979. goto nla_put_failure;
  980. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
  981. 0, NL80211_CMD_DEL_INTERFACE, 0);
  982. NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, ifidx);
  983. if (send_and_recv_msgs(drv, msg, NULL, NULL) == 0)
  984. return;
  985. nla_put_failure:
  986. wpa_printf(MSG_ERROR, "nl80211: Failed to remove interface.");
  987. }
  988. static int nl80211_create_iface(struct wpa_driver_nl80211_data *drv,
  989. const char *ifname, enum nl80211_iftype iftype)
  990. {
  991. struct nl_msg *msg, *flags = NULL;
  992. int ifidx, err;
  993. int ret = -ENOBUFS;
  994. msg = nlmsg_alloc();
  995. if (!msg)
  996. return -1;
  997. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
  998. 0, NL80211_CMD_NEW_INTERFACE, 0);
  999. NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, if_nametoindex(drv->ifname));
  1000. NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, ifname);
  1001. NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, iftype);
  1002. if (iftype == NL80211_IFTYPE_MONITOR) {
  1003. flags = nlmsg_alloc();
  1004. if (!flags)
  1005. goto nla_put_failure;
  1006. NLA_PUT_FLAG(flags, NL80211_MNTR_FLAG_COOK_FRAMES);
  1007. err = nla_put_nested(msg, NL80211_ATTR_MNTR_FLAGS, flags);
  1008. nlmsg_free(flags);
  1009. if (err)
  1010. goto nla_put_failure;
  1011. }
  1012. ret = send_and_recv_msgs(drv, msg, NULL, NULL);
  1013. if (ret) {
  1014. nla_put_failure:
  1015. wpa_printf(MSG_ERROR, "nl80211: Failed to create interface %d",
  1016. ret);
  1017. return ret;
  1018. }
  1019. ifidx = if_nametoindex(ifname);
  1020. if (ifidx <= 0)
  1021. return -1;
  1022. return ifidx;
  1023. }
  1024. static void handle_monitor_read(int sock, void *eloop_ctx, void *sock_ctx)
  1025. {
  1026. struct wpa_driver_nl80211_data *drv = eloop_ctx;
  1027. int len;
  1028. unsigned char buf[3000];
  1029. struct ieee80211_radiotap_iterator iter;
  1030. int ret;
  1031. int injected = 0, failed = 0, rxflags = 0;
  1032. struct ieee80211_rx_status rx_status;
  1033. len = recv(sock, buf, sizeof(buf), 0);
  1034. if (len < 0) {
  1035. perror("recv");
  1036. return;
  1037. }
  1038. if (ieee80211_radiotap_iterator_init(&iter, (void *) buf, len)) {
  1039. wpa_printf(MSG_DEBUG, "nl80211: received invalid radiotap "
  1040. "frame");
  1041. return;
  1042. }
  1043. os_memset(&rx_status, 0, sizeof(rx_status));
  1044. while (1) {
  1045. ret = ieee80211_radiotap_iterator_next(&iter);
  1046. if (ret == -ENOENT)
  1047. break;
  1048. if (ret) {
  1049. wpa_printf(MSG_DEBUG, "nl80211: received invalid "
  1050. "radiotap frame (%d)", ret);
  1051. return;
  1052. }
  1053. switch (iter.this_arg_index) {
  1054. case IEEE80211_RADIOTAP_FLAGS:
  1055. if (*iter.this_arg & IEEE80211_RADIOTAP_F_FCS)
  1056. len -= 4;
  1057. break;
  1058. case IEEE80211_RADIOTAP_RX_FLAGS:
  1059. rxflags = 1;
  1060. break;
  1061. case IEEE80211_RADIOTAP_TX_FLAGS:
  1062. injected = 1;
  1063. failed = le_to_host16((*(u16 *) iter.this_arg)) &
  1064. IEEE80211_RADIOTAP_F_TX_FAIL;
  1065. break;
  1066. case IEEE80211_RADIOTAP_DATA_RETRIES:
  1067. break;
  1068. case IEEE80211_RADIOTAP_CHANNEL:
  1069. /* TODO convert from freq/flags to channel number
  1070. * rx_status.channel = XXX;
  1071. */
  1072. break;
  1073. case IEEE80211_RADIOTAP_RATE:
  1074. break;
  1075. case IEEE80211_RADIOTAP_DB_ANTSIGNAL:
  1076. rx_status.ssi = *iter.this_arg;
  1077. break;
  1078. }
  1079. }
  1080. if (rxflags && injected)
  1081. return;
  1082. if (!injected) {
  1083. wpa_supplicant_sta_rx(drv->ctx, buf + iter.max_length,
  1084. len - iter.max_length, &rx_status);
  1085. } else if (failed) {
  1086. /* TX failure callback */
  1087. } else {
  1088. /* TX success (ACK) callback */
  1089. }
  1090. }
  1091. static int wpa_driver_nl80211_create_monitor_interface(
  1092. struct wpa_driver_nl80211_data *drv)
  1093. {
  1094. char buf[IFNAMSIZ];
  1095. struct sockaddr_ll ll;
  1096. int optval, flags;
  1097. socklen_t optlen;
  1098. os_snprintf(buf, IFNAMSIZ, "mon.%s", drv->ifname);
  1099. buf[IFNAMSIZ - 1] = '\0';
  1100. drv->monitor_ifidx =
  1101. nl80211_create_iface(drv, buf, NL80211_IFTYPE_MONITOR);
  1102. if (drv->monitor_ifidx < 0)
  1103. return -1;
  1104. if (wpa_driver_nl80211_get_ifflags_ifname(drv, buf, &flags) != 0 ||
  1105. wpa_driver_nl80211_set_ifflags_ifname(drv, buf, flags | IFF_UP) !=
  1106. 0) {
  1107. wpa_printf(MSG_ERROR, "nl80211: Could not set interface '%s' "
  1108. "UP", buf);
  1109. goto error;
  1110. }
  1111. os_memset(&ll, 0, sizeof(ll));
  1112. ll.sll_family = AF_PACKET;
  1113. ll.sll_ifindex = drv->monitor_ifidx;
  1114. drv->monitor_sock = socket(PF_PACKET, SOCK_RAW, htons(ETH_P_ALL));
  1115. if (drv->monitor_sock < 0) {
  1116. perror("socket[PF_PACKET,SOCK_RAW]");
  1117. goto error;
  1118. }
  1119. if (bind(drv->monitor_sock, (struct sockaddr *) &ll,
  1120. sizeof(ll)) < 0) {
  1121. perror("monitor socket bind");
  1122. goto error;
  1123. }
  1124. optlen = sizeof(optval);
  1125. optval = 20;
  1126. if (setsockopt
  1127. (drv->monitor_sock, SOL_SOCKET, SO_PRIORITY, &optval, optlen)) {
  1128. perror("Failed to set socket priority");
  1129. goto error;
  1130. }
  1131. if (eloop_register_read_sock(drv->monitor_sock, handle_monitor_read,
  1132. drv, NULL)) {
  1133. wpa_printf(MSG_ERROR, "nl80211: Could not register monitor "
  1134. "read socket");
  1135. goto error;
  1136. }
  1137. return 0;
  1138. error:
  1139. nl80211_remove_iface(drv, drv->monitor_ifidx);
  1140. return -1;
  1141. }
  1142. #endif /* CONFIG_CLIENT_MLME */
  1143. /**
  1144. * wpa_driver_nl80211_init - Initialize nl80211 driver interface
  1145. * @ctx: context to be used when calling wpa_supplicant functions,
  1146. * e.g., wpa_supplicant_event()
  1147. * @ifname: interface name, e.g., wlan0
  1148. * Returns: Pointer to private data, %NULL on failure
  1149. */
  1150. static void * wpa_driver_nl80211_init(void *ctx, const char *ifname)
  1151. {
  1152. int s, ret;
  1153. struct sockaddr_nl local;
  1154. struct wpa_driver_nl80211_data *drv;
  1155. drv = os_zalloc(sizeof(*drv));
  1156. if (drv == NULL)
  1157. return NULL;
  1158. drv->ctx = ctx;
  1159. os_strlcpy(drv->ifname, ifname, sizeof(drv->ifname));
  1160. drv->nl_cb = nl_cb_alloc(NL_CB_DEFAULT);
  1161. if (drv->nl_cb == NULL) {
  1162. wpa_printf(MSG_ERROR, "nl80211: Failed to allocate netlink "
  1163. "callbacks");
  1164. goto err1;
  1165. }
  1166. drv->nl_handle = nl_handle_alloc_cb(drv->nl_cb);
  1167. if (drv->nl_handle == NULL) {
  1168. wpa_printf(MSG_ERROR, "nl80211: Failed to allocate netlink "
  1169. "callbacks");
  1170. goto err2;
  1171. }
  1172. if (genl_connect(drv->nl_handle)) {
  1173. wpa_printf(MSG_ERROR, "nl80211: Failed to connect to generic "
  1174. "netlink");
  1175. goto err3;
  1176. }
  1177. drv->nl_cache = genl_ctrl_alloc_cache(drv->nl_handle);
  1178. if (drv->nl_cache == NULL) {
  1179. wpa_printf(MSG_ERROR, "nl80211: Failed to allocate generic "
  1180. "netlink cache");
  1181. goto err3;
  1182. }
  1183. drv->nl80211 = genl_ctrl_search_by_name(drv->nl_cache, "nl80211");
  1184. if (drv->nl80211 == NULL) {
  1185. wpa_printf(MSG_ERROR, "nl80211: 'nl80211' generic netlink not "
  1186. "found");
  1187. goto err4;
  1188. }
  1189. ret = nl_get_multicast_id(drv, "nl80211", "scan");
  1190. if (ret >= 0)
  1191. ret = nl_socket_add_membership(drv->nl_handle, ret);
  1192. if (ret < 0) {
  1193. wpa_printf(MSG_ERROR, "nl80211: Could not add multicast "
  1194. "membership for scan events: %d (%s)",
  1195. ret, strerror(-ret));
  1196. goto err4;
  1197. }
  1198. eloop_register_read_sock(nl_socket_get_fd(drv->nl_handle),
  1199. wpa_driver_nl80211_event_receive, drv, ctx);
  1200. drv->ioctl_sock = socket(PF_INET, SOCK_DGRAM, 0);
  1201. if (drv->ioctl_sock < 0) {
  1202. perror("socket(PF_INET,SOCK_DGRAM)");
  1203. goto err5;
  1204. }
  1205. s = socket(PF_NETLINK, SOCK_RAW, NETLINK_ROUTE);
  1206. if (s < 0) {
  1207. perror("socket(PF_NETLINK,SOCK_RAW,NETLINK_ROUTE)");
  1208. goto err6;
  1209. }
  1210. os_memset(&local, 0, sizeof(local));
  1211. local.nl_family = AF_NETLINK;
  1212. local.nl_groups = RTMGRP_LINK;
  1213. if (bind(s, (struct sockaddr *) &local, sizeof(local)) < 0) {
  1214. perror("bind(netlink)");
  1215. close(s);
  1216. goto err6;
  1217. }
  1218. eloop_register_read_sock(s, wpa_driver_nl80211_event_receive_wext, drv,
  1219. ctx);
  1220. drv->wext_event_sock = s;
  1221. wpa_driver_nl80211_finish_drv_init(drv);
  1222. return drv;
  1223. err6:
  1224. close(drv->ioctl_sock);
  1225. err5:
  1226. genl_family_put(drv->nl80211);
  1227. err4:
  1228. nl_cache_free(drv->nl_cache);
  1229. err3:
  1230. nl_handle_destroy(drv->nl_handle);
  1231. err2:
  1232. nl_cb_put(drv->nl_cb);
  1233. err1:
  1234. os_free(drv);
  1235. return NULL;
  1236. }
  1237. static void
  1238. wpa_driver_nl80211_finish_drv_init(struct wpa_driver_nl80211_data *drv)
  1239. {
  1240. int flags;
  1241. if (wpa_driver_nl80211_get_ifflags(drv, &flags) != 0)
  1242. printf("Could not get interface '%s' flags\n", drv->ifname);
  1243. else if (!(flags & IFF_UP)) {
  1244. if (wpa_driver_nl80211_set_ifflags(drv, flags | IFF_UP) != 0) {
  1245. printf("Could not set interface '%s' UP\n",
  1246. drv->ifname);
  1247. } else {
  1248. /*
  1249. * Wait some time to allow driver to initialize before
  1250. * starting configuring the driver. This seems to be
  1251. * needed at least some drivers that load firmware etc.
  1252. * when the interface is set up.
  1253. */
  1254. wpa_printf(MSG_DEBUG, "Interface %s set UP - waiting "
  1255. "a second for the driver to complete "
  1256. "initialization", drv->ifname);
  1257. sleep(1);
  1258. }
  1259. }
  1260. /*
  1261. * Make sure that the driver does not have any obsolete PMKID entries.
  1262. */
  1263. wpa_driver_nl80211_flush_pmkid(drv);
  1264. if (wpa_driver_nl80211_set_mode(drv, 0) < 0) {
  1265. printf("Could not configure driver to use managed mode\n");
  1266. }
  1267. wpa_driver_nl80211_get_range(drv);
  1268. drv->ifindex = if_nametoindex(drv->ifname);
  1269. wpa_driver_nl80211_send_oper_ifla(drv, 1, IF_OPER_DORMANT);
  1270. }
  1271. /**
  1272. * wpa_driver_nl80211_deinit - Deinitialize nl80211 driver interface
  1273. * @priv: Pointer to private nl80211 data from wpa_driver_nl80211_init()
  1274. *
  1275. * Shut down driver interface and processing of driver events. Free
  1276. * private data buffer if one was allocated in wpa_driver_nl80211_init().
  1277. */
  1278. static void wpa_driver_nl80211_deinit(void *priv)
  1279. {
  1280. struct wpa_driver_nl80211_data *drv = priv;
  1281. int flags;
  1282. #ifdef CONFIG_CLIENT_MLME
  1283. if (drv->monitor_sock >= 0) {
  1284. eloop_unregister_read_sock(drv->monitor_sock);
  1285. close(drv->monitor_sock);
  1286. }
  1287. if (drv->monitor_ifidx > 0)
  1288. nl80211_remove_iface(drv, drv->monitor_ifidx);
  1289. if (drv->capa.flags & WPA_DRIVER_FLAGS_USER_SPACE_MLME)
  1290. wpa_driver_nl80211_set_userspace_mlme(drv, 0);
  1291. #endif /* CONFIG_CLIENT_MLME */
  1292. eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout, drv, drv->ctx);
  1293. /*
  1294. * Clear possibly configured driver parameters in order to make it
  1295. * easier to use the driver after wpa_supplicant has been terminated.
  1296. */
  1297. (void) wpa_driver_nl80211_set_bssid(drv,
  1298. (u8 *) "\x00\x00\x00\x00\x00\x00");
  1299. wpa_driver_nl80211_send_oper_ifla(priv, 0, IF_OPER_UP);
  1300. eloop_unregister_read_sock(drv->wext_event_sock);
  1301. if (wpa_driver_nl80211_get_ifflags(drv, &flags) == 0)
  1302. (void) wpa_driver_nl80211_set_ifflags(drv, flags & ~IFF_UP);
  1303. close(drv->wext_event_sock);
  1304. close(drv->ioctl_sock);
  1305. os_free(drv->assoc_req_ies);
  1306. os_free(drv->assoc_resp_ies);
  1307. eloop_unregister_read_sock(nl_socket_get_fd(drv->nl_handle));
  1308. genl_family_put(drv->nl80211);
  1309. nl_cache_free(drv->nl_cache);
  1310. nl_handle_destroy(drv->nl_handle);
  1311. nl_cb_put(drv->nl_cb);
  1312. os_free(drv);
  1313. }
  1314. /**
  1315. * wpa_driver_nl80211_scan_timeout - Scan timeout to report scan completion
  1316. * @eloop_ctx: Unused
  1317. * @timeout_ctx: ctx argument given to wpa_driver_nl80211_init()
  1318. *
  1319. * This function can be used as registered timeout when starting a scan to
  1320. * generate a scan completed event if the driver does not report this.
  1321. */
  1322. static void wpa_driver_nl80211_scan_timeout(void *eloop_ctx, void *timeout_ctx)
  1323. {
  1324. wpa_printf(MSG_DEBUG, "Scan timeout - try to get results");
  1325. wpa_supplicant_event(timeout_ctx, EVENT_SCAN_RESULTS, NULL);
  1326. }
  1327. /**
  1328. * wpa_driver_nl80211_scan - Request the driver to initiate scan
  1329. * @priv: Pointer to private wext data from wpa_driver_nl80211_init()
  1330. * @ssid: Specific SSID to scan for (ProbeReq) or %NULL to scan for
  1331. * all SSIDs (either active scan with broadcast SSID or passive
  1332. * scan
  1333. * @ssid_len: Length of the SSID
  1334. * Returns: 0 on success, -1 on failure
  1335. */
  1336. static int wpa_driver_nl80211_scan(void *priv, const u8 *ssid, size_t ssid_len)
  1337. {
  1338. struct wpa_driver_nl80211_data *drv = priv;
  1339. int ret = 0, timeout;
  1340. struct nl_msg *msg, *ssids;
  1341. msg = nlmsg_alloc();
  1342. ssids = nlmsg_alloc();
  1343. if (!msg || !ssids) {
  1344. nlmsg_free(msg);
  1345. nlmsg_free(ssids);
  1346. return -1;
  1347. }
  1348. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
  1349. NL80211_CMD_TRIGGER_SCAN, 0);
  1350. NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
  1351. if (ssid && ssid_len) {
  1352. /* Request an active scan for a specific SSID */
  1353. NLA_PUT(ssids, 1, ssid_len, ssid);
  1354. } else {
  1355. /* Request an active scan for wildcard SSID */
  1356. NLA_PUT(ssids, 1, 0, "");
  1357. }
  1358. nla_put_nested(msg, NL80211_ATTR_SCAN_SSIDS, ssids);
  1359. ret = send_and_recv_msgs(drv, msg, NULL, NULL);
  1360. msg = NULL;
  1361. if (ret) {
  1362. wpa_printf(MSG_DEBUG, "nl80211: Scan trigger failed: ret=%d "
  1363. "(%s)", ret, strerror(-ret));
  1364. goto nla_put_failure;
  1365. }
  1366. /* Not all drivers generate "scan completed" wireless event, so try to
  1367. * read results after a timeout. */
  1368. timeout = 10;
  1369. if (drv->scan_complete_events) {
  1370. /*
  1371. * The driver seems to deliver SIOCGIWSCAN events to notify
  1372. * when scan is complete, so use longer timeout to avoid race
  1373. * conditions with scanning and following association request.
  1374. */
  1375. timeout = 30;
  1376. }
  1377. wpa_printf(MSG_DEBUG, "Scan requested (ret=%d) - scan timeout %d "
  1378. "seconds", ret, timeout);
  1379. eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout, drv, drv->ctx);
  1380. eloop_register_timeout(timeout, 0, wpa_driver_nl80211_scan_timeout,
  1381. drv, drv->ctx);
  1382. nla_put_failure:
  1383. nlmsg_free(ssids);
  1384. nlmsg_free(msg);
  1385. return ret;
  1386. }
  1387. static int bss_info_handler(struct nl_msg *msg, void *arg)
  1388. {
  1389. struct nlattr *tb[NL80211_ATTR_MAX + 1];
  1390. struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
  1391. struct nlattr *bss[NL80211_BSS_MAX + 1];
  1392. static struct nla_policy bss_policy[NL80211_BSS_MAX + 1] = {
  1393. [NL80211_BSS_BSSID] = { .type = NLA_UNSPEC },
  1394. [NL80211_BSS_FREQUENCY] = { .type = NLA_U32 },
  1395. [NL80211_BSS_TSF] = { .type = NLA_U64 },
  1396. [NL80211_BSS_BEACON_INTERVAL] = { .type = NLA_U16 },
  1397. [NL80211_BSS_CAPABILITY] = { .type = NLA_U16 },
  1398. [NL80211_BSS_INFORMATION_ELEMENTS] = { .type = NLA_UNSPEC },
  1399. [NL80211_BSS_SIGNAL_MBM] = { .type = NLA_U32 },
  1400. [NL80211_BSS_SIGNAL_UNSPEC] = { .type = NLA_U8 },
  1401. };
  1402. struct wpa_scan_results *res = arg;
  1403. struct wpa_scan_res **tmp;
  1404. struct wpa_scan_res *r;
  1405. const u8 *ie;
  1406. size_t ie_len;
  1407. nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
  1408. genlmsg_attrlen(gnlh, 0), NULL);
  1409. if (!tb[NL80211_ATTR_BSS])
  1410. return NL_SKIP;
  1411. if (nla_parse_nested(bss, NL80211_BSS_MAX, tb[NL80211_ATTR_BSS],
  1412. bss_policy))
  1413. return NL_SKIP;
  1414. if (bss[NL80211_BSS_INFORMATION_ELEMENTS]) {
  1415. ie = nla_data(bss[NL80211_BSS_INFORMATION_ELEMENTS]);
  1416. ie_len = nla_len(bss[NL80211_BSS_INFORMATION_ELEMENTS]);
  1417. } else {
  1418. ie = NULL;
  1419. ie_len = 0;
  1420. }
  1421. r = os_zalloc(sizeof(*r) + ie_len);
  1422. if (r == NULL)
  1423. return NL_SKIP;
  1424. if (bss[NL80211_BSS_BSSID])
  1425. os_memcpy(r->bssid, nla_data(bss[NL80211_BSS_BSSID]),
  1426. ETH_ALEN);
  1427. if (bss[NL80211_BSS_FREQUENCY])
  1428. r->freq = nla_get_u32(bss[NL80211_BSS_FREQUENCY]);
  1429. if (bss[NL80211_BSS_BEACON_INTERVAL])
  1430. r->beacon_int = nla_get_u16(bss[NL80211_BSS_BEACON_INTERVAL]);
  1431. if (bss[NL80211_BSS_CAPABILITY])
  1432. r->caps = nla_get_u16(bss[NL80211_BSS_CAPABILITY]);
  1433. if (bss[NL80211_BSS_SIGNAL_UNSPEC])
  1434. r->qual = nla_get_u8(bss[NL80211_BSS_SIGNAL_UNSPEC]);
  1435. if (bss[NL80211_BSS_SIGNAL_MBM])
  1436. r->level = nla_get_u32(bss[NL80211_BSS_SIGNAL_MBM]);
  1437. if (bss[NL80211_BSS_TSF])
  1438. r->tsf = nla_get_u64(bss[NL80211_BSS_TSF]);
  1439. r->ie_len = ie_len;
  1440. if (ie)
  1441. os_memcpy(r + 1, ie, ie_len);
  1442. tmp = os_realloc(res->res,
  1443. (res->num + 1) * sizeof(struct wpa_scan_res *));
  1444. if (tmp == NULL) {
  1445. os_free(r);
  1446. return NL_SKIP;
  1447. }
  1448. tmp[res->num++] = r;
  1449. res->res = tmp;
  1450. return NL_SKIP;
  1451. }
  1452. /**
  1453. * wpa_driver_nl80211_get_scan_results - Fetch the latest scan results
  1454. * @priv: Pointer to private wext data from wpa_driver_nl80211_init()
  1455. * Returns: Scan results on success, -1 on failure
  1456. */
  1457. static struct wpa_scan_results *
  1458. wpa_driver_nl80211_get_scan_results(void *priv)
  1459. {
  1460. struct wpa_driver_nl80211_data *drv = priv;
  1461. struct nl_msg *msg;
  1462. struct wpa_scan_results *res;
  1463. int ret;
  1464. res = os_zalloc(sizeof(*res));
  1465. if (res == NULL)
  1466. return 0;
  1467. msg = nlmsg_alloc();
  1468. if (!msg)
  1469. goto nla_put_failure;
  1470. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, NLM_F_DUMP,
  1471. NL80211_CMD_GET_SCAN, 0);
  1472. NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
  1473. ret = send_and_recv_msgs(drv, msg, bss_info_handler, res);
  1474. msg = NULL;
  1475. if (ret == 0) {
  1476. wpa_printf(MSG_DEBUG, "Received scan results (%lu BSSes)",
  1477. (unsigned long) res->num);
  1478. return res;
  1479. }
  1480. wpa_printf(MSG_DEBUG, "nl80211: Scan result fetch failed: ret=%d "
  1481. "(%s)", ret, strerror(-ret));
  1482. nla_put_failure:
  1483. nlmsg_free(msg);
  1484. wpa_scan_results_free(res);
  1485. return NULL;
  1486. }
  1487. static int wpa_driver_nl80211_get_range(void *priv)
  1488. {
  1489. struct wpa_driver_nl80211_data *drv = priv;
  1490. struct iw_range *range;
  1491. struct iwreq iwr;
  1492. int minlen;
  1493. size_t buflen;
  1494. /*
  1495. * Use larger buffer than struct iw_range in order to allow the
  1496. * structure to grow in the future.
  1497. */
  1498. buflen = sizeof(struct iw_range) + 500;
  1499. range = os_zalloc(buflen);
  1500. if (range == NULL)
  1501. return -1;
  1502. os_memset(&iwr, 0, sizeof(iwr));
  1503. os_strlcpy(iwr.ifr_name, drv->ifname, IFNAMSIZ);
  1504. iwr.u.data.pointer = (caddr_t) range;
  1505. iwr.u.data.length = buflen;
  1506. minlen = ((char *) &range->enc_capa) - (char *) range +
  1507. sizeof(range->enc_capa);
  1508. if (ioctl(drv->ioctl_sock, SIOCGIWRANGE, &iwr) < 0) {
  1509. perror("ioctl[SIOCGIWRANGE]");
  1510. os_free(range);
  1511. return -1;
  1512. } else if (iwr.u.data.length >= minlen &&
  1513. range->we_version_compiled >= 18) {
  1514. wpa_printf(MSG_DEBUG, "SIOCGIWRANGE: WE(compiled)=%d "
  1515. "WE(source)=%d enc_capa=0x%x",
  1516. range->we_version_compiled,
  1517. range->we_version_source,
  1518. range->enc_capa);
  1519. drv->has_capability = 1;
  1520. drv->we_version_compiled = range->we_version_compiled;
  1521. if (range->enc_capa & IW_ENC_CAPA_WPA) {
  1522. drv->capa.key_mgmt |= WPA_DRIVER_CAPA_KEY_MGMT_WPA |
  1523. WPA_DRIVER_CAPA_KEY_MGMT_WPA_PSK;
  1524. }
  1525. if (range->enc_capa & IW_ENC_CAPA_WPA2) {
  1526. drv->capa.key_mgmt |= WPA_DRIVER_CAPA_KEY_MGMT_WPA2 |
  1527. WPA_DRIVER_CAPA_KEY_MGMT_WPA2_PSK;
  1528. }
  1529. drv->capa.enc |= WPA_DRIVER_CAPA_ENC_WEP40 |
  1530. WPA_DRIVER_CAPA_ENC_WEP104;
  1531. if (range->enc_capa & IW_ENC_CAPA_CIPHER_TKIP)
  1532. drv->capa.enc |= WPA_DRIVER_CAPA_ENC_TKIP;
  1533. if (range->enc_capa & IW_ENC_CAPA_CIPHER_CCMP)
  1534. drv->capa.enc |= WPA_DRIVER_CAPA_ENC_CCMP;
  1535. wpa_printf(MSG_DEBUG, " capabilities: key_mgmt 0x%x enc 0x%x",
  1536. drv->capa.key_mgmt, drv->capa.enc);
  1537. } else {
  1538. wpa_printf(MSG_DEBUG, "SIOCGIWRANGE: too old (short) data - "
  1539. "assuming WPA is not supported");
  1540. }
  1541. os_free(range);
  1542. return 0;
  1543. }
  1544. static int wpa_driver_nl80211_set_wpa(void *priv, int enabled)
  1545. {
  1546. struct wpa_driver_nl80211_data *drv = priv;
  1547. wpa_printf(MSG_DEBUG, "%s", __FUNCTION__);
  1548. return wpa_driver_nl80211_set_auth_param(drv, IW_AUTH_WPA_ENABLED,
  1549. enabled);
  1550. }
  1551. static int wpa_driver_nl80211_set_key(void *priv, wpa_alg alg,
  1552. const u8 *addr, int key_idx,
  1553. int set_tx, const u8 *seq,
  1554. size_t seq_len,
  1555. const u8 *key, size_t key_len)
  1556. {
  1557. struct wpa_driver_nl80211_data *drv = priv;
  1558. int err;
  1559. struct nl_msg *msg;
  1560. wpa_printf(MSG_DEBUG, "%s: alg=%d addr=%p key_idx=%d set_tx=%d "
  1561. "seq_len=%lu key_len=%lu",
  1562. __func__, alg, addr, key_idx, set_tx,
  1563. (unsigned long) seq_len, (unsigned long) key_len);
  1564. msg = nlmsg_alloc();
  1565. if (msg == NULL)
  1566. return -1;
  1567. if (alg == WPA_ALG_NONE) {
  1568. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
  1569. NL80211_CMD_DEL_KEY, 0);
  1570. } else {
  1571. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0, 0,
  1572. NL80211_CMD_NEW_KEY, 0);
  1573. NLA_PUT(msg, NL80211_ATTR_KEY_DATA, key_len, key);
  1574. switch (alg) {
  1575. case WPA_ALG_WEP:
  1576. if (key_len == 5)
  1577. NLA_PUT_U32(msg, NL80211_ATTR_KEY_CIPHER,
  1578. 0x000FAC01);
  1579. else
  1580. NLA_PUT_U32(msg, NL80211_ATTR_KEY_CIPHER,
  1581. 0x000FAC05);
  1582. break;
  1583. case WPA_ALG_TKIP:
  1584. NLA_PUT_U32(msg, NL80211_ATTR_KEY_CIPHER, 0x000FAC02);
  1585. break;
  1586. case WPA_ALG_CCMP:
  1587. NLA_PUT_U32(msg, NL80211_ATTR_KEY_CIPHER, 0x000FAC04);
  1588. break;
  1589. default:
  1590. nlmsg_free(msg);
  1591. return -1;
  1592. }
  1593. }
  1594. if (addr && os_memcmp(addr, "\xff\xff\xff\xff\xff\xff", ETH_ALEN) != 0)
  1595. {
  1596. wpa_printf(MSG_DEBUG, " addr=" MACSTR, MAC2STR(addr));
  1597. NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
  1598. }
  1599. NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
  1600. NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
  1601. err = send_and_recv_msgs(drv, msg, NULL, NULL);
  1602. if (err) {
  1603. wpa_printf(MSG_DEBUG, "nl80211: set_key failed; err=%d", err);
  1604. return -1;
  1605. }
  1606. if (set_tx && alg != WPA_ALG_NONE) {
  1607. msg = nlmsg_alloc();
  1608. if (msg == NULL)
  1609. return -1;
  1610. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
  1611. 0, NL80211_CMD_SET_KEY, 0);
  1612. NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
  1613. NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
  1614. NLA_PUT_FLAG(msg, NL80211_ATTR_KEY_DEFAULT);
  1615. err = send_and_recv_msgs(drv, msg, NULL, NULL);
  1616. if (err) {
  1617. wpa_printf(MSG_DEBUG, "nl80211: set default key "
  1618. "failed; err=%d", err);
  1619. return -1;
  1620. }
  1621. }
  1622. return 0;
  1623. nla_put_failure:
  1624. return -ENOBUFS;
  1625. }
  1626. static int wpa_driver_nl80211_set_countermeasures(void *priv,
  1627. int enabled)
  1628. {
  1629. struct wpa_driver_nl80211_data *drv = priv;
  1630. wpa_printf(MSG_DEBUG, "%s", __FUNCTION__);
  1631. return wpa_driver_nl80211_set_auth_param(drv,
  1632. IW_AUTH_TKIP_COUNTERMEASURES,
  1633. enabled);
  1634. }
  1635. static int wpa_driver_nl80211_set_drop_unencrypted(void *priv,
  1636. int enabled)
  1637. {
  1638. struct wpa_driver_nl80211_data *drv = priv;
  1639. wpa_printf(MSG_DEBUG, "%s", __FUNCTION__);
  1640. drv->use_crypt = enabled;
  1641. return wpa_driver_nl80211_set_auth_param(drv, IW_AUTH_DROP_UNENCRYPTED,
  1642. enabled);
  1643. }
  1644. static int wpa_driver_nl80211_mlme(struct wpa_driver_nl80211_data *drv,
  1645. const u8 *addr, int cmd, int reason_code)
  1646. {
  1647. struct iwreq iwr;
  1648. struct iw_mlme mlme;
  1649. int ret = 0;
  1650. os_memset(&iwr, 0, sizeof(iwr));
  1651. os_strlcpy(iwr.ifr_name, drv->ifname, IFNAMSIZ);
  1652. os_memset(&mlme, 0, sizeof(mlme));
  1653. mlme.cmd = cmd;
  1654. mlme.reason_code = reason_code;
  1655. mlme.addr.sa_family = ARPHRD_ETHER;
  1656. os_memcpy(mlme.addr.sa_data, addr, ETH_ALEN);
  1657. iwr.u.data.pointer = (caddr_t) &mlme;
  1658. iwr.u.data.length = sizeof(mlme);
  1659. if (ioctl(drv->ioctl_sock, SIOCSIWMLME, &iwr) < 0) {
  1660. perror("ioctl[SIOCSIWMLME]");
  1661. ret = -1;
  1662. }
  1663. return ret;
  1664. }
  1665. static int wpa_driver_nl80211_deauthenticate(void *priv, const u8 *addr,
  1666. int reason_code)
  1667. {
  1668. struct wpa_driver_nl80211_data *drv = priv;
  1669. wpa_printf(MSG_DEBUG, "%s", __FUNCTION__);
  1670. return wpa_driver_nl80211_mlme(drv, addr, IW_MLME_DEAUTH, reason_code);
  1671. }
  1672. static int wpa_driver_nl80211_disassociate(void *priv, const u8 *addr,
  1673. int reason_code)
  1674. {
  1675. struct wpa_driver_nl80211_data *drv = priv;
  1676. wpa_printf(MSG_DEBUG, "%s", __FUNCTION__);
  1677. return wpa_driver_nl80211_mlme(drv, addr, IW_MLME_DISASSOC,
  1678. reason_code);
  1679. }
  1680. static int wpa_driver_nl80211_set_gen_ie(void *priv, const u8 *ie,
  1681. size_t ie_len)
  1682. {
  1683. struct wpa_driver_nl80211_data *drv = priv;
  1684. struct iwreq iwr;
  1685. int ret = 0;
  1686. os_memset(&iwr, 0, sizeof(iwr));
  1687. os_strlcpy(iwr.ifr_name, drv->ifname, IFNAMSIZ);
  1688. iwr.u.data.pointer = (caddr_t) ie;
  1689. iwr.u.data.length = ie_len;
  1690. if (ioctl(drv->ioctl_sock, SIOCSIWGENIE, &iwr) < 0) {
  1691. perror("ioctl[SIOCSIWGENIE]");
  1692. ret = -1;
  1693. }
  1694. return ret;
  1695. }
  1696. static int wpa_driver_nl80211_cipher2wext(int cipher)
  1697. {
  1698. switch (cipher) {
  1699. case CIPHER_NONE:
  1700. return IW_AUTH_CIPHER_NONE;
  1701. case CIPHER_WEP40:
  1702. return IW_AUTH_CIPHER_WEP40;
  1703. case CIPHER_TKIP:
  1704. return IW_AUTH_CIPHER_TKIP;
  1705. case CIPHER_CCMP:
  1706. return IW_AUTH_CIPHER_CCMP;
  1707. case CIPHER_WEP104:
  1708. return IW_AUTH_CIPHER_WEP104;
  1709. default:
  1710. return 0;
  1711. }
  1712. }
  1713. static int wpa_driver_nl80211_keymgmt2wext(int keymgmt)
  1714. {
  1715. switch (keymgmt) {
  1716. case KEY_MGMT_802_1X:
  1717. case KEY_MGMT_802_1X_NO_WPA:
  1718. return IW_AUTH_KEY_MGMT_802_1X;
  1719. case KEY_MGMT_PSK:
  1720. return IW_AUTH_KEY_MGMT_PSK;
  1721. default:
  1722. return 0;
  1723. }
  1724. }
  1725. static int
  1726. wpa_driver_nl80211_auth_alg_fallback(struct wpa_driver_nl80211_data *drv,
  1727. struct wpa_driver_associate_params *params)
  1728. {
  1729. struct iwreq iwr;
  1730. int ret = 0;
  1731. wpa_printf(MSG_DEBUG, "WEXT: Driver did not support "
  1732. "SIOCSIWAUTH for AUTH_ALG, trying SIOCSIWENCODE");
  1733. os_memset(&iwr, 0, sizeof(iwr));
  1734. os_strlcpy(iwr.ifr_name, drv->ifname, IFNAMSIZ);
  1735. /* Just changing mode, not actual keys */
  1736. iwr.u.encoding.flags = 0;
  1737. iwr.u.encoding.pointer = (caddr_t) NULL;
  1738. iwr.u.encoding.length = 0;
  1739. /*
  1740. * Note: IW_ENCODE_{OPEN,RESTRICTED} can be interpreted to mean two
  1741. * different things. Here they are used to indicate Open System vs.
  1742. * Shared Key authentication algorithm. However, some drivers may use
  1743. * them to select between open/restricted WEP encrypted (open = allow
  1744. * both unencrypted and encrypted frames; restricted = only allow
  1745. * encrypted frames).
  1746. */
  1747. if (!drv->use_crypt) {
  1748. iwr.u.encoding.flags |= IW_ENCODE_DISABLED;
  1749. } else {
  1750. if (params->auth_alg & AUTH_ALG_OPEN_SYSTEM)
  1751. iwr.u.encoding.flags |= IW_ENCODE_OPEN;
  1752. if (params->auth_alg & AUTH_ALG_SHARED_KEY)
  1753. iwr.u.encoding.flags |= IW_ENCODE_RESTRICTED;
  1754. }
  1755. if (ioctl(drv->ioctl_sock, SIOCSIWENCODE, &iwr) < 0) {
  1756. perror("ioctl[SIOCSIWENCODE]");
  1757. ret = -1;
  1758. }
  1759. return ret;
  1760. }
  1761. static int wpa_driver_nl80211_associate(
  1762. void *priv, struct wpa_driver_associate_params *params)
  1763. {
  1764. struct wpa_driver_nl80211_data *drv = priv;
  1765. int ret = 0;
  1766. int allow_unencrypted_eapol;
  1767. int value;
  1768. wpa_printf(MSG_DEBUG, "%s", __FUNCTION__);
  1769. /*
  1770. * If the driver did not support SIOCSIWAUTH, fallback to
  1771. * SIOCSIWENCODE here.
  1772. */
  1773. if (drv->auth_alg_fallback &&
  1774. wpa_driver_nl80211_auth_alg_fallback(drv, params) < 0)
  1775. ret = -1;
  1776. if (!params->bssid &&
  1777. wpa_driver_nl80211_set_bssid(drv, NULL) < 0)
  1778. ret = -1;
  1779. /* TODO: should consider getting wpa version and cipher/key_mgmt suites
  1780. * from configuration, not from here, where only the selected suite is
  1781. * available */
  1782. if (wpa_driver_nl80211_set_gen_ie(drv, params->wpa_ie, params->wpa_ie_len)
  1783. < 0)
  1784. ret = -1;
  1785. if (params->wpa_ie == NULL || params->wpa_ie_len == 0)
  1786. value = IW_AUTH_WPA_VERSION_DISABLED;
  1787. else if (params->wpa_ie[0] == WLAN_EID_RSN)
  1788. value = IW_AUTH_WPA_VERSION_WPA2;
  1789. else
  1790. value = IW_AUTH_WPA_VERSION_WPA;
  1791. if (wpa_driver_nl80211_set_auth_param(drv,
  1792. IW_AUTH_WPA_VERSION, value) < 0)
  1793. ret = -1;
  1794. value = wpa_driver_nl80211_cipher2wext(params->pairwise_suite);
  1795. if (wpa_driver_nl80211_set_auth_param(drv,
  1796. IW_AUTH_CIPHER_PAIRWISE, value) < 0)
  1797. ret = -1;
  1798. value = wpa_driver_nl80211_cipher2wext(params->group_suite);
  1799. if (wpa_driver_nl80211_set_auth_param(drv,
  1800. IW_AUTH_CIPHER_GROUP, value) < 0)
  1801. ret = -1;
  1802. value = wpa_driver_nl80211_keymgmt2wext(params->key_mgmt_suite);
  1803. if (wpa_driver_nl80211_set_auth_param(drv,
  1804. IW_AUTH_KEY_MGMT, value) < 0)
  1805. ret = -1;
  1806. value = params->key_mgmt_suite != KEY_MGMT_NONE ||
  1807. params->pairwise_suite != CIPHER_NONE ||
  1808. params->group_suite != CIPHER_NONE ||
  1809. params->wpa_ie_len;
  1810. if (wpa_driver_nl80211_set_auth_param(drv,
  1811. IW_AUTH_PRIVACY_INVOKED, value) < 0)
  1812. ret = -1;
  1813. /* Allow unencrypted EAPOL messages even if pairwise keys are set when
  1814. * not using WPA. IEEE 802.1X specifies that these frames are not
  1815. * encrypted, but WPA encrypts them when pairwise keys are in use. */
  1816. if (params->key_mgmt_suite == KEY_MGMT_802_1X ||
  1817. params->key_mgmt_suite == KEY_MGMT_PSK)
  1818. allow_unencrypted_eapol = 0;
  1819. else
  1820. allow_unencrypted_eapol = 1;
  1821. if (wpa_driver_nl80211_set_auth_param(drv,
  1822. IW_AUTH_RX_UNENCRYPTED_EAPOL,
  1823. allow_unencrypted_eapol) < 0)
  1824. ret = -1;
  1825. if (params->freq && wpa_driver_nl80211_set_freq(drv, params->freq) < 0)
  1826. ret = -1;
  1827. if (wpa_driver_nl80211_set_ssid(drv, params->ssid, params->ssid_len) < 0)
  1828. ret = -1;
  1829. if (params->bssid &&
  1830. wpa_driver_nl80211_set_bssid(drv, params->bssid) < 0)
  1831. ret = -1;
  1832. return ret;
  1833. }
  1834. static int wpa_driver_nl80211_set_auth_alg(void *priv, int auth_alg)
  1835. {
  1836. struct wpa_driver_nl80211_data *drv = priv;
  1837. int algs = 0, res;
  1838. if (auth_alg & AUTH_ALG_OPEN_SYSTEM)
  1839. algs |= IW_AUTH_ALG_OPEN_SYSTEM;
  1840. if (auth_alg & AUTH_ALG_SHARED_KEY)
  1841. algs |= IW_AUTH_ALG_SHARED_KEY;
  1842. if (auth_alg & AUTH_ALG_LEAP)
  1843. algs |= IW_AUTH_ALG_LEAP;
  1844. if (algs == 0) {
  1845. /* at least one algorithm should be set */
  1846. algs = IW_AUTH_ALG_OPEN_SYSTEM;
  1847. }
  1848. res = wpa_driver_nl80211_set_auth_param(drv, IW_AUTH_80211_AUTH_ALG,
  1849. algs);
  1850. drv->auth_alg_fallback = res == -2;
  1851. return res;
  1852. }
  1853. /**
  1854. * wpa_driver_nl80211_set_mode - Set wireless mode (infra/adhoc), SIOCSIWMODE
  1855. * @priv: Pointer to private wext data from wpa_driver_nl80211_init()
  1856. * @mode: 0 = infra/BSS (associate with an AP), 1 = adhoc/IBSS
  1857. * Returns: 0 on success, -1 on failure
  1858. */
  1859. static int wpa_driver_nl80211_set_mode(void *priv, int mode)
  1860. {
  1861. struct wpa_driver_nl80211_data *drv = priv;
  1862. int ret = -1, flags;
  1863. struct nl_msg *msg;
  1864. msg = nlmsg_alloc();
  1865. if (!msg)
  1866. return -1;
  1867. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
  1868. 0, NL80211_CMD_SET_INTERFACE, 0);
  1869. NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
  1870. NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE,
  1871. mode ? NL80211_IFTYPE_ADHOC : NL80211_IFTYPE_STATION);
  1872. ret = send_and_recv_msgs(drv, msg, NULL, NULL);
  1873. if (!ret)
  1874. return 0;
  1875. else
  1876. goto try_again;
  1877. nla_put_failure:
  1878. wpa_printf(MSG_ERROR, "nl80211: Failed to set interface mode");
  1879. return -1;
  1880. try_again:
  1881. /* mac80211 doesn't allow mode changes while the device is up, so
  1882. * take the device down, try to set the mode again, and bring the
  1883. * device back up.
  1884. */
  1885. if (wpa_driver_nl80211_get_ifflags(drv, &flags) == 0) {
  1886. (void) wpa_driver_nl80211_set_ifflags(drv, flags & ~IFF_UP);
  1887. /* Try to set the mode again while the interface is down */
  1888. msg = nlmsg_alloc();
  1889. if (!msg)
  1890. return -1;
  1891. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
  1892. 0, NL80211_CMD_SET_INTERFACE, 0);
  1893. NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
  1894. NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE,
  1895. mode ? NL80211_IFTYPE_ADHOC :
  1896. NL80211_IFTYPE_STATION);
  1897. ret = send_and_recv_msgs(drv, msg, NULL, NULL);
  1898. if (ret) {
  1899. wpa_printf(MSG_ERROR, "Failed to set interface %s "
  1900. "mode", drv->ifname);
  1901. }
  1902. /* Ignore return value of get_ifflags to ensure that the device
  1903. * is always up like it was before this function was called.
  1904. */
  1905. (void) wpa_driver_nl80211_get_ifflags(drv, &flags);
  1906. (void) wpa_driver_nl80211_set_ifflags(drv, flags | IFF_UP);
  1907. }
  1908. return ret;
  1909. }
  1910. static int wpa_driver_nl80211_pmksa(struct wpa_driver_nl80211_data *drv,
  1911. u32 cmd, const u8 *bssid, const u8 *pmkid)
  1912. {
  1913. struct iwreq iwr;
  1914. struct iw_pmksa pmksa;
  1915. int ret = 0;
  1916. os_memset(&iwr, 0, sizeof(iwr));
  1917. os_strlcpy(iwr.ifr_name, drv->ifname, IFNAMSIZ);
  1918. os_memset(&pmksa, 0, sizeof(pmksa));
  1919. pmksa.cmd = cmd;
  1920. pmksa.bssid.sa_family = ARPHRD_ETHER;
  1921. if (bssid)
  1922. os_memcpy(pmksa.bssid.sa_data, bssid, ETH_ALEN);
  1923. if (pmkid)
  1924. os_memcpy(pmksa.pmkid, pmkid, IW_PMKID_LEN);
  1925. iwr.u.data.pointer = (caddr_t) &pmksa;
  1926. iwr.u.data.length = sizeof(pmksa);
  1927. if (ioctl(drv->ioctl_sock, SIOCSIWPMKSA, &iwr) < 0) {
  1928. if (errno != EOPNOTSUPP)
  1929. perror("ioctl[SIOCSIWPMKSA]");
  1930. ret = -1;
  1931. }
  1932. return ret;
  1933. }
  1934. static int wpa_driver_nl80211_add_pmkid(void *priv, const u8 *bssid,
  1935. const u8 *pmkid)
  1936. {
  1937. struct wpa_driver_nl80211_data *drv = priv;
  1938. return wpa_driver_nl80211_pmksa(drv, IW_PMKSA_ADD, bssid, pmkid);
  1939. }
  1940. static int wpa_driver_nl80211_remove_pmkid(void *priv, const u8 *bssid,
  1941. const u8 *pmkid)
  1942. {
  1943. struct wpa_driver_nl80211_data *drv = priv;
  1944. return wpa_driver_nl80211_pmksa(drv, IW_PMKSA_REMOVE, bssid, pmkid);
  1945. }
  1946. static int wpa_driver_nl80211_flush_pmkid(void *priv)
  1947. {
  1948. struct wpa_driver_nl80211_data *drv = priv;
  1949. return wpa_driver_nl80211_pmksa(drv, IW_PMKSA_FLUSH, NULL, NULL);
  1950. }
  1951. static int wpa_driver_nl80211_get_capa(void *priv,
  1952. struct wpa_driver_capa *capa)
  1953. {
  1954. struct wpa_driver_nl80211_data *drv = priv;
  1955. if (!drv->has_capability)
  1956. return -1;
  1957. os_memcpy(capa, &drv->capa, sizeof(*capa));
  1958. return 0;
  1959. }
  1960. static int wpa_driver_nl80211_set_operstate(void *priv, int state)
  1961. {
  1962. struct wpa_driver_nl80211_data *drv = priv;
  1963. wpa_printf(MSG_DEBUG, "%s: operstate %d->%d (%s)",
  1964. __func__, drv->operstate, state, state ? "UP" : "DORMANT");
  1965. drv->operstate = state;
  1966. return wpa_driver_nl80211_send_oper_ifla(
  1967. drv, -1, state ? IF_OPER_UP : IF_OPER_DORMANT);
  1968. }
  1969. #ifdef CONFIG_CLIENT_MLME
  1970. static int wpa_driver_nl80211_open_mlme(struct wpa_driver_nl80211_data *drv)
  1971. {
  1972. if (wpa_driver_nl80211_set_userspace_mlme(drv, 1) < 0) {
  1973. wpa_printf(MSG_ERROR, "nl80211: Failed to enable userspace "
  1974. "MLME");
  1975. return -1;
  1976. }
  1977. if (wpa_driver_nl80211_create_monitor_interface(drv)) {
  1978. wpa_printf(MSG_ERROR, "nl80211: Failed to create monitor "
  1979. "interface");
  1980. return -1;
  1981. }
  1982. return 0;
  1983. }
  1984. #endif /* CONFIG_CLIENT_MLME */
  1985. static int wpa_driver_nl80211_set_param(void *priv, const char *param)
  1986. {
  1987. #ifdef CONFIG_CLIENT_MLME
  1988. struct wpa_driver_nl80211_data *drv = priv;
  1989. if (param == NULL)
  1990. return 0;
  1991. wpa_printf(MSG_DEBUG, "%s: param='%s'", __func__, param);
  1992. if (os_strstr(param, "use_mlme=1")) {
  1993. wpa_printf(MSG_DEBUG, "nl80211: Using user space MLME");
  1994. drv->capa.flags |= WPA_DRIVER_FLAGS_USER_SPACE_MLME;
  1995. if (wpa_driver_nl80211_open_mlme(drv))
  1996. return -1;
  1997. }
  1998. #endif /* CONFIG_CLIENT_MLME */
  1999. return 0;
  2000. }
  2001. #ifdef CONFIG_CLIENT_MLME
  2002. struct phy_info_arg {
  2003. u16 *num_modes;
  2004. struct wpa_hw_modes *modes;
  2005. };
  2006. static int phy_info_handler(struct nl_msg *msg, void *arg)
  2007. {
  2008. struct nlattr *tb_msg[NL80211_ATTR_MAX + 1];
  2009. struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
  2010. struct phy_info_arg *phy_info = arg;
  2011. struct nlattr *tb_band[NL80211_BAND_ATTR_MAX + 1];
  2012. struct nlattr *tb_freq[NL80211_FREQUENCY_ATTR_MAX + 1];
  2013. static struct nla_policy freq_policy[NL80211_FREQUENCY_ATTR_MAX + 1]
  2014. = {
  2015. [NL80211_FREQUENCY_ATTR_FREQ] = { .type = NLA_U32 },
  2016. [NL80211_FREQUENCY_ATTR_DISABLED] = { .type = NLA_FLAG },
  2017. [NL80211_FREQUENCY_ATTR_PASSIVE_SCAN] = { .type = NLA_FLAG },
  2018. [NL80211_FREQUENCY_ATTR_NO_IBSS] = { .type = NLA_FLAG },
  2019. [NL80211_FREQUENCY_ATTR_RADAR] = { .type = NLA_FLAG },
  2020. };
  2021. struct nlattr *tb_rate[NL80211_BITRATE_ATTR_MAX + 1];
  2022. static struct nla_policy rate_policy[NL80211_BITRATE_ATTR_MAX + 1] = {
  2023. [NL80211_BITRATE_ATTR_RATE] = { .type = NLA_U32 },
  2024. [NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE] =
  2025. { .type = NLA_FLAG },
  2026. };
  2027. struct nlattr *nl_band;
  2028. struct nlattr *nl_freq;
  2029. struct nlattr *nl_rate;
  2030. int rem_band, rem_freq, rem_rate;
  2031. struct wpa_hw_modes *mode;
  2032. int idx, mode_is_set;
  2033. nla_parse(tb_msg, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
  2034. genlmsg_attrlen(gnlh, 0), NULL);
  2035. if (!tb_msg[NL80211_ATTR_WIPHY_BANDS])
  2036. return NL_SKIP;
  2037. nla_for_each_nested(nl_band, tb_msg[NL80211_ATTR_WIPHY_BANDS],
  2038. rem_band) {
  2039. mode = os_realloc(phy_info->modes,
  2040. (*phy_info->num_modes + 1) * sizeof(*mode));
  2041. if (!mode)
  2042. return NL_SKIP;
  2043. phy_info->modes = mode;
  2044. mode_is_set = 0;
  2045. mode = &phy_info->modes[*(phy_info->num_modes)];
  2046. os_memset(mode, 0, sizeof(*mode));
  2047. *(phy_info->num_modes) += 1;
  2048. nla_parse(tb_band, NL80211_BAND_ATTR_MAX, nla_data(nl_band),
  2049. nla_len(nl_band), NULL);
  2050. nla_for_each_nested(nl_freq, tb_band[NL80211_BAND_ATTR_FREQS],
  2051. rem_freq) {
  2052. nla_parse(tb_freq, NL80211_FREQUENCY_ATTR_MAX,
  2053. nla_data(nl_freq), nla_len(nl_freq),
  2054. freq_policy);
  2055. if (!tb_freq[NL80211_FREQUENCY_ATTR_FREQ])
  2056. continue;
  2057. mode->num_channels++;
  2058. }
  2059. mode->channels = os_zalloc(mode->num_channels *
  2060. sizeof(struct wpa_channel_data));
  2061. if (!mode->channels)
  2062. return NL_SKIP;
  2063. idx = 0;
  2064. nla_for_each_nested(nl_freq, tb_band[NL80211_BAND_ATTR_FREQS],
  2065. rem_freq) {
  2066. nla_parse(tb_freq, NL80211_FREQUENCY_ATTR_MAX,
  2067. nla_data(nl_freq), nla_len(nl_freq),
  2068. freq_policy);
  2069. if (!tb_freq[NL80211_FREQUENCY_ATTR_FREQ])
  2070. continue;
  2071. mode->channels[idx].freq = nla_get_u32(
  2072. tb_freq[NL80211_FREQUENCY_ATTR_FREQ]);
  2073. mode->channels[idx].flag |= WPA_CHAN_W_SCAN |
  2074. WPA_CHAN_W_ACTIVE_SCAN |
  2075. WPA_CHAN_W_IBSS;
  2076. if (!mode_is_set) {
  2077. /* crude heuristic */
  2078. if (mode->channels[idx].freq < 4000)
  2079. mode->mode = WPA_MODE_IEEE80211B;
  2080. else
  2081. mode->mode = WPA_MODE_IEEE80211A;
  2082. mode_is_set = 1;
  2083. }
  2084. /* crude heuristic */
  2085. if (mode->channels[idx].freq < 4000) {
  2086. if (mode->channels[idx].freq == 2848)
  2087. mode->channels[idx].chan = 14;
  2088. else
  2089. mode->channels[idx].chan =
  2090. (mode->channels[idx].freq -
  2091. 2407) / 5;
  2092. } else
  2093. mode->channels[idx].chan =
  2094. mode->channels[idx].freq / 5 - 1000;
  2095. if (tb_freq[NL80211_FREQUENCY_ATTR_DISABLED])
  2096. mode->channels[idx].flag &= ~WPA_CHAN_W_SCAN;
  2097. if (tb_freq[NL80211_FREQUENCY_ATTR_PASSIVE_SCAN])
  2098. mode->channels[idx].flag &=
  2099. ~WPA_CHAN_W_ACTIVE_SCAN;
  2100. if (tb_freq[NL80211_FREQUENCY_ATTR_NO_IBSS])
  2101. mode->channels[idx].flag &= ~WPA_CHAN_W_IBSS;
  2102. idx++;
  2103. }
  2104. nla_for_each_nested(nl_rate, tb_band[NL80211_BAND_ATTR_RATES],
  2105. rem_rate) {
  2106. nla_parse(tb_rate, NL80211_BITRATE_ATTR_MAX,
  2107. nla_data(nl_rate), nla_len(nl_rate),
  2108. rate_policy);
  2109. if (!tb_rate[NL80211_BITRATE_ATTR_RATE])
  2110. continue;
  2111. mode->num_rates++;
  2112. }
  2113. mode->rates = os_zalloc(mode->num_rates *
  2114. sizeof(struct wpa_rate_data));
  2115. if (!mode->rates)
  2116. return NL_SKIP;
  2117. idx = 0;
  2118. nla_for_each_nested(nl_rate, tb_band[NL80211_BAND_ATTR_RATES],
  2119. rem_rate) {
  2120. nla_parse(tb_rate, NL80211_BITRATE_ATTR_MAX,
  2121. nla_data(nl_rate), nla_len(nl_rate),
  2122. rate_policy);
  2123. if (!tb_rate[NL80211_BITRATE_ATTR_RATE])
  2124. continue;
  2125. mode->rates[idx].rate = nla_get_u32(
  2126. tb_rate[NL80211_BITRATE_ATTR_RATE]);
  2127. /* crude heuristic */
  2128. if (mode->mode == WPA_MODE_IEEE80211B &&
  2129. mode->rates[idx].rate > 200)
  2130. mode->mode = WPA_MODE_IEEE80211G;
  2131. if (tb_rate[NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE])
  2132. mode->rates[idx].flags |= WPA_RATE_PREAMBLE2;
  2133. idx++;
  2134. }
  2135. }
  2136. return NL_SKIP;
  2137. }
  2138. static struct wpa_hw_modes *
  2139. wpa_driver_nl80211_get_hw_feature_data(void *priv, u16 *num_modes, u16 *flags)
  2140. {
  2141. struct wpa_driver_nl80211_data *drv = priv;
  2142. struct nl_msg *msg;
  2143. struct phy_info_arg result = {
  2144. .num_modes = num_modes,
  2145. .modes = NULL,
  2146. };
  2147. *num_modes = 0;
  2148. *flags = 0;
  2149. msg = nlmsg_alloc();
  2150. if (!msg)
  2151. return NULL;
  2152. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
  2153. 0, NL80211_CMD_GET_WIPHY, 0);
  2154. NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
  2155. if (send_and_recv_msgs(drv, msg, phy_info_handler, &result) == 0)
  2156. return result.modes;
  2157. nla_put_failure:
  2158. return NULL;
  2159. }
  2160. static int wpa_driver_nl80211_set_channel(void *priv, wpa_hw_mode phymode,
  2161. int chan, int freq)
  2162. {
  2163. return wpa_driver_nl80211_set_freq(priv, freq);
  2164. }
  2165. static int wpa_driver_nl80211_send_mlme(void *priv, const u8 *data,
  2166. size_t data_len)
  2167. {
  2168. struct wpa_driver_nl80211_data *drv = priv;
  2169. __u8 rtap_hdr[] = {
  2170. 0x00, 0x00, /* radiotap version */
  2171. 0x0e, 0x00, /* radiotap length */
  2172. 0x02, 0xc0, 0x00, 0x00, /* bmap: flags, tx and rx flags */
  2173. 0x0c, /* F_WEP | F_FRAG (encrypt/fragment if required) */
  2174. 0x00, /* padding */
  2175. 0x00, 0x00, /* RX and TX flags to indicate that */
  2176. 0x00, 0x00, /* this is the injected frame directly */
  2177. };
  2178. struct iovec iov[2] = {
  2179. {
  2180. .iov_base = &rtap_hdr,
  2181. .iov_len = sizeof(rtap_hdr),
  2182. },
  2183. {
  2184. .iov_base = (void *) data,
  2185. .iov_len = data_len,
  2186. }
  2187. };
  2188. struct msghdr msg = {
  2189. .msg_name = NULL,
  2190. .msg_namelen = 0,
  2191. .msg_iov = iov,
  2192. .msg_iovlen = 2,
  2193. .msg_control = NULL,
  2194. .msg_controllen = 0,
  2195. .msg_flags = 0,
  2196. };
  2197. if (sendmsg(drv->monitor_sock, &msg, 0) < 0) {
  2198. perror("send[MLME]");
  2199. return -1;
  2200. }
  2201. return 0;
  2202. }
  2203. static int wpa_driver_nl80211_mlme_add_sta(void *priv, const u8 *addr,
  2204. const u8 *supp_rates,
  2205. size_t supp_rates_len)
  2206. {
  2207. struct wpa_driver_nl80211_data *drv = priv;
  2208. struct nl_msg *msg;
  2209. int ret = -1;
  2210. msg = nlmsg_alloc();
  2211. if (!msg)
  2212. return -ENOMEM;
  2213. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
  2214. 0, NL80211_CMD_NEW_STATION, 0);
  2215. NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
  2216. NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
  2217. /* TODO: Get proper Association ID and listen interval */
  2218. NLA_PUT_U16(msg, NL80211_ATTR_STA_AID, 1);
  2219. NLA_PUT(msg, NL80211_ATTR_STA_SUPPORTED_RATES, supp_rates_len,
  2220. supp_rates);
  2221. NLA_PUT_U16(msg, NL80211_ATTR_STA_LISTEN_INTERVAL, 1);
  2222. ret = send_and_recv_msgs(drv, msg, NULL, NULL);
  2223. /* ignore EEXIST, this happens if a STA associates while associated */
  2224. if (ret == -EEXIST || ret >= 0)
  2225. ret = 0;
  2226. nla_put_failure:
  2227. return ret;
  2228. }
  2229. static int wpa_driver_nl80211_mlme_remove_sta(void *priv, const u8 *addr)
  2230. {
  2231. struct wpa_driver_nl80211_data *drv = priv;
  2232. struct nl_msg *msg;
  2233. int ret = -1;
  2234. msg = nlmsg_alloc();
  2235. if (!msg)
  2236. return -ENOMEM;
  2237. genlmsg_put(msg, 0, 0, genl_family_get_id(drv->nl80211), 0,
  2238. 0, NL80211_CMD_DEL_STATION, 0);
  2239. NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, drv->ifindex);
  2240. NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
  2241. ret = 0;
  2242. ret = send_and_recv_msgs(drv, msg, NULL, NULL);
  2243. return ret;
  2244. nla_put_failure:
  2245. return -ENOBUFS;
  2246. }
  2247. #endif /* CONFIG_CLIENT_MLME */
  2248. const struct wpa_driver_ops wpa_driver_nl80211_ops = {
  2249. .name = "nl80211",
  2250. .desc = "Linux nl80211/cfg80211",
  2251. .get_bssid = wpa_driver_nl80211_get_bssid,
  2252. .get_ssid = wpa_driver_nl80211_get_ssid,
  2253. .set_wpa = wpa_driver_nl80211_set_wpa,
  2254. .set_key = wpa_driver_nl80211_set_key,
  2255. .set_countermeasures = wpa_driver_nl80211_set_countermeasures,
  2256. .set_drop_unencrypted = wpa_driver_nl80211_set_drop_unencrypted,
  2257. .scan = wpa_driver_nl80211_scan,
  2258. .get_scan_results2 = wpa_driver_nl80211_get_scan_results,
  2259. .deauthenticate = wpa_driver_nl80211_deauthenticate,
  2260. .disassociate = wpa_driver_nl80211_disassociate,
  2261. .set_mode = wpa_driver_nl80211_set_mode,
  2262. .associate = wpa_driver_nl80211_associate,
  2263. .set_auth_alg = wpa_driver_nl80211_set_auth_alg,
  2264. .init = wpa_driver_nl80211_init,
  2265. .deinit = wpa_driver_nl80211_deinit,
  2266. .set_param = wpa_driver_nl80211_set_param,
  2267. .add_pmkid = wpa_driver_nl80211_add_pmkid,
  2268. .remove_pmkid = wpa_driver_nl80211_remove_pmkid,
  2269. .flush_pmkid = wpa_driver_nl80211_flush_pmkid,
  2270. .get_capa = wpa_driver_nl80211_get_capa,
  2271. .set_operstate = wpa_driver_nl80211_set_operstate,
  2272. .set_country = wpa_driver_nl80211_set_country,
  2273. .set_probe_req_ie = wpa_driver_nl80211_set_probe_req_ie,
  2274. #ifdef CONFIG_CLIENT_MLME
  2275. .get_hw_feature_data = wpa_driver_nl80211_get_hw_feature_data,
  2276. .set_channel = wpa_driver_nl80211_set_channel,
  2277. .set_ssid = wpa_driver_nl80211_set_ssid,
  2278. .set_bssid = wpa_driver_nl80211_set_bssid,
  2279. .send_mlme = wpa_driver_nl80211_send_mlme,
  2280. .mlme_add_sta = wpa_driver_nl80211_mlme_add_sta,
  2281. .mlme_remove_sta = wpa_driver_nl80211_mlme_remove_sta,
  2282. #endif /* CONFIG_CLIENT_MLME */
  2283. };