ieee802_11_common.c 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488
  1. /*
  2. * IEEE 802.11 Common routines
  3. * Copyright (c) 2002-2012, Jouni Malinen <j@w1.fi>
  4. *
  5. * This software may be distributed under the terms of the BSD license.
  6. * See README for more details.
  7. */
  8. #include "includes.h"
  9. #include "common.h"
  10. #include "ieee802_11_defs.h"
  11. #include "ieee802_11_common.h"
  12. static int ieee802_11_parse_vendor_specific(const u8 *pos, size_t elen,
  13. struct ieee802_11_elems *elems,
  14. int show_errors)
  15. {
  16. unsigned int oui;
  17. /* first 3 bytes in vendor specific information element are the IEEE
  18. * OUI of the vendor. The following byte is used a vendor specific
  19. * sub-type. */
  20. if (elen < 4) {
  21. if (show_errors) {
  22. wpa_printf(MSG_MSGDUMP, "short vendor specific "
  23. "information element ignored (len=%lu)",
  24. (unsigned long) elen);
  25. }
  26. return -1;
  27. }
  28. oui = WPA_GET_BE24(pos);
  29. switch (oui) {
  30. case OUI_MICROSOFT:
  31. /* Microsoft/Wi-Fi information elements are further typed and
  32. * subtyped */
  33. switch (pos[3]) {
  34. case 1:
  35. /* Microsoft OUI (00:50:F2) with OUI Type 1:
  36. * real WPA information element */
  37. elems->wpa_ie = pos;
  38. elems->wpa_ie_len = elen;
  39. break;
  40. case WMM_OUI_TYPE:
  41. /* WMM information element */
  42. if (elen < 5) {
  43. wpa_printf(MSG_MSGDUMP, "short WMM "
  44. "information element ignored "
  45. "(len=%lu)",
  46. (unsigned long) elen);
  47. return -1;
  48. }
  49. switch (pos[4]) {
  50. case WMM_OUI_SUBTYPE_INFORMATION_ELEMENT:
  51. case WMM_OUI_SUBTYPE_PARAMETER_ELEMENT:
  52. /*
  53. * Share same pointer since only one of these
  54. * is used and they start with same data.
  55. * Length field can be used to distinguish the
  56. * IEs.
  57. */
  58. elems->wmm = pos;
  59. elems->wmm_len = elen;
  60. break;
  61. case WMM_OUI_SUBTYPE_TSPEC_ELEMENT:
  62. elems->wmm_tspec = pos;
  63. elems->wmm_tspec_len = elen;
  64. break;
  65. default:
  66. wpa_printf(MSG_EXCESSIVE, "unknown WMM "
  67. "information element ignored "
  68. "(subtype=%d len=%lu)",
  69. pos[4], (unsigned long) elen);
  70. return -1;
  71. }
  72. break;
  73. case 4:
  74. /* Wi-Fi Protected Setup (WPS) IE */
  75. elems->wps_ie = pos;
  76. elems->wps_ie_len = elen;
  77. break;
  78. default:
  79. wpa_printf(MSG_EXCESSIVE, "Unknown Microsoft "
  80. "information element ignored "
  81. "(type=%d len=%lu)",
  82. pos[3], (unsigned long) elen);
  83. return -1;
  84. }
  85. break;
  86. case OUI_WFA:
  87. switch (pos[3]) {
  88. case P2P_OUI_TYPE:
  89. /* Wi-Fi Alliance - P2P IE */
  90. elems->p2p = pos;
  91. elems->p2p_len = elen;
  92. break;
  93. case WFD_OUI_TYPE:
  94. /* Wi-Fi Alliance - WFD IE */
  95. elems->wfd = pos;
  96. elems->wfd_len = elen;
  97. break;
  98. case HS20_INDICATION_OUI_TYPE:
  99. /* Hotspot 2.0 */
  100. elems->hs20 = pos;
  101. elems->hs20_len = elen;
  102. break;
  103. default:
  104. wpa_printf(MSG_MSGDUMP, "Unknown WFA "
  105. "information element ignored "
  106. "(type=%d len=%lu)\n",
  107. pos[3], (unsigned long) elen);
  108. return -1;
  109. }
  110. break;
  111. case OUI_BROADCOM:
  112. switch (pos[3]) {
  113. case VENDOR_HT_CAPAB_OUI_TYPE:
  114. elems->vendor_ht_cap = pos;
  115. elems->vendor_ht_cap_len = elen;
  116. break;
  117. default:
  118. wpa_printf(MSG_EXCESSIVE, "Unknown Broadcom "
  119. "information element ignored "
  120. "(type=%d len=%lu)",
  121. pos[3], (unsigned long) elen);
  122. return -1;
  123. }
  124. break;
  125. default:
  126. wpa_printf(MSG_EXCESSIVE, "unknown vendor specific "
  127. "information element ignored (vendor OUI "
  128. "%02x:%02x:%02x len=%lu)",
  129. pos[0], pos[1], pos[2], (unsigned long) elen);
  130. return -1;
  131. }
  132. return 0;
  133. }
  134. /**
  135. * ieee802_11_parse_elems - Parse information elements in management frames
  136. * @start: Pointer to the start of IEs
  137. * @len: Length of IE buffer in octets
  138. * @elems: Data structure for parsed elements
  139. * @show_errors: Whether to show parsing errors in debug log
  140. * Returns: Parsing result
  141. */
  142. ParseRes ieee802_11_parse_elems(const u8 *start, size_t len,
  143. struct ieee802_11_elems *elems,
  144. int show_errors)
  145. {
  146. size_t left = len;
  147. const u8 *pos = start;
  148. int unknown = 0;
  149. os_memset(elems, 0, sizeof(*elems));
  150. while (left >= 2) {
  151. u8 id, elen;
  152. id = *pos++;
  153. elen = *pos++;
  154. left -= 2;
  155. if (elen > left) {
  156. if (show_errors) {
  157. wpa_printf(MSG_DEBUG, "IEEE 802.11 element "
  158. "parse failed (id=%d elen=%d "
  159. "left=%lu)",
  160. id, elen, (unsigned long) left);
  161. wpa_hexdump(MSG_MSGDUMP, "IEs", start, len);
  162. }
  163. return ParseFailed;
  164. }
  165. switch (id) {
  166. case WLAN_EID_SSID:
  167. elems->ssid = pos;
  168. elems->ssid_len = elen;
  169. break;
  170. case WLAN_EID_SUPP_RATES:
  171. elems->supp_rates = pos;
  172. elems->supp_rates_len = elen;
  173. break;
  174. case WLAN_EID_FH_PARAMS:
  175. elems->fh_params = pos;
  176. elems->fh_params_len = elen;
  177. break;
  178. case WLAN_EID_DS_PARAMS:
  179. elems->ds_params = pos;
  180. elems->ds_params_len = elen;
  181. break;
  182. case WLAN_EID_CF_PARAMS:
  183. elems->cf_params = pos;
  184. elems->cf_params_len = elen;
  185. break;
  186. case WLAN_EID_TIM:
  187. elems->tim = pos;
  188. elems->tim_len = elen;
  189. break;
  190. case WLAN_EID_IBSS_PARAMS:
  191. elems->ibss_params = pos;
  192. elems->ibss_params_len = elen;
  193. break;
  194. case WLAN_EID_CHALLENGE:
  195. elems->challenge = pos;
  196. elems->challenge_len = elen;
  197. break;
  198. case WLAN_EID_ERP_INFO:
  199. elems->erp_info = pos;
  200. elems->erp_info_len = elen;
  201. break;
  202. case WLAN_EID_EXT_SUPP_RATES:
  203. elems->ext_supp_rates = pos;
  204. elems->ext_supp_rates_len = elen;
  205. break;
  206. case WLAN_EID_VENDOR_SPECIFIC:
  207. if (ieee802_11_parse_vendor_specific(pos, elen,
  208. elems,
  209. show_errors))
  210. unknown++;
  211. break;
  212. case WLAN_EID_RSN:
  213. elems->rsn_ie = pos;
  214. elems->rsn_ie_len = elen;
  215. break;
  216. case WLAN_EID_PWR_CAPABILITY:
  217. elems->power_cap = pos;
  218. elems->power_cap_len = elen;
  219. break;
  220. case WLAN_EID_SUPPORTED_CHANNELS:
  221. elems->supp_channels = pos;
  222. elems->supp_channels_len = elen;
  223. break;
  224. case WLAN_EID_MOBILITY_DOMAIN:
  225. elems->mdie = pos;
  226. elems->mdie_len = elen;
  227. break;
  228. case WLAN_EID_FAST_BSS_TRANSITION:
  229. elems->ftie = pos;
  230. elems->ftie_len = elen;
  231. break;
  232. case WLAN_EID_TIMEOUT_INTERVAL:
  233. elems->timeout_int = pos;
  234. elems->timeout_int_len = elen;
  235. break;
  236. case WLAN_EID_HT_CAP:
  237. elems->ht_capabilities = pos;
  238. elems->ht_capabilities_len = elen;
  239. break;
  240. case WLAN_EID_HT_OPERATION:
  241. elems->ht_operation = pos;
  242. elems->ht_operation_len = elen;
  243. break;
  244. case WLAN_EID_VHT_CAP:
  245. elems->vht_capabilities = pos;
  246. elems->vht_capabilities_len = elen;
  247. break;
  248. case WLAN_EID_VHT_OPERATION:
  249. elems->vht_operation = pos;
  250. elems->vht_operation_len = elen;
  251. break;
  252. case WLAN_EID_LINK_ID:
  253. if (elen < 18)
  254. break;
  255. elems->link_id = pos;
  256. break;
  257. case WLAN_EID_INTERWORKING:
  258. elems->interworking = pos;
  259. elems->interworking_len = elen;
  260. break;
  261. case WLAN_EID_EXT_CAPAB:
  262. elems->ext_capab = pos;
  263. elems->ext_capab_len = elen;
  264. break;
  265. case WLAN_EID_BSS_MAX_IDLE_PERIOD:
  266. if (elen < 3)
  267. break;
  268. elems->bss_max_idle_period = pos;
  269. break;
  270. case WLAN_EID_SSID_LIST:
  271. elems->ssid_list = pos;
  272. elems->ssid_list_len = elen;
  273. break;
  274. default:
  275. unknown++;
  276. if (!show_errors)
  277. break;
  278. wpa_printf(MSG_MSGDUMP, "IEEE 802.11 element parse "
  279. "ignored unknown element (id=%d elen=%d)",
  280. id, elen);
  281. break;
  282. }
  283. left -= elen;
  284. pos += elen;
  285. }
  286. if (left)
  287. return ParseFailed;
  288. return unknown ? ParseUnknown : ParseOK;
  289. }
  290. int ieee802_11_ie_count(const u8 *ies, size_t ies_len)
  291. {
  292. int count = 0;
  293. const u8 *pos, *end;
  294. if (ies == NULL)
  295. return 0;
  296. pos = ies;
  297. end = ies + ies_len;
  298. while (pos + 2 <= end) {
  299. if (pos + 2 + pos[1] > end)
  300. break;
  301. count++;
  302. pos += 2 + pos[1];
  303. }
  304. return count;
  305. }
  306. struct wpabuf * ieee802_11_vendor_ie_concat(const u8 *ies, size_t ies_len,
  307. u32 oui_type)
  308. {
  309. struct wpabuf *buf;
  310. const u8 *end, *pos, *ie;
  311. pos = ies;
  312. end = ies + ies_len;
  313. ie = NULL;
  314. while (pos + 1 < end) {
  315. if (pos + 2 + pos[1] > end)
  316. return NULL;
  317. if (pos[0] == WLAN_EID_VENDOR_SPECIFIC && pos[1] >= 4 &&
  318. WPA_GET_BE32(&pos[2]) == oui_type) {
  319. ie = pos;
  320. break;
  321. }
  322. pos += 2 + pos[1];
  323. }
  324. if (ie == NULL)
  325. return NULL; /* No specified vendor IE found */
  326. buf = wpabuf_alloc(ies_len);
  327. if (buf == NULL)
  328. return NULL;
  329. /*
  330. * There may be multiple vendor IEs in the message, so need to
  331. * concatenate their data fields.
  332. */
  333. while (pos + 1 < end) {
  334. if (pos + 2 + pos[1] > end)
  335. break;
  336. if (pos[0] == WLAN_EID_VENDOR_SPECIFIC && pos[1] >= 4 &&
  337. WPA_GET_BE32(&pos[2]) == oui_type)
  338. wpabuf_put_data(buf, pos + 6, pos[1] - 4);
  339. pos += 2 + pos[1];
  340. }
  341. return buf;
  342. }
  343. const u8 * get_hdr_bssid(const struct ieee80211_hdr *hdr, size_t len)
  344. {
  345. u16 fc, type, stype;
  346. /*
  347. * PS-Poll frames are 16 bytes. All other frames are
  348. * 24 bytes or longer.
  349. */
  350. if (len < 16)
  351. return NULL;
  352. fc = le_to_host16(hdr->frame_control);
  353. type = WLAN_FC_GET_TYPE(fc);
  354. stype = WLAN_FC_GET_STYPE(fc);
  355. switch (type) {
  356. case WLAN_FC_TYPE_DATA:
  357. if (len < 24)
  358. return NULL;
  359. switch (fc & (WLAN_FC_FROMDS | WLAN_FC_TODS)) {
  360. case WLAN_FC_FROMDS | WLAN_FC_TODS:
  361. case WLAN_FC_TODS:
  362. return hdr->addr1;
  363. case WLAN_FC_FROMDS:
  364. return hdr->addr2;
  365. default:
  366. return NULL;
  367. }
  368. case WLAN_FC_TYPE_CTRL:
  369. if (stype != WLAN_FC_STYPE_PSPOLL)
  370. return NULL;
  371. return hdr->addr1;
  372. case WLAN_FC_TYPE_MGMT:
  373. return hdr->addr3;
  374. default:
  375. return NULL;
  376. }
  377. }
  378. int hostapd_config_wmm_ac(struct hostapd_wmm_ac_params wmm_ac_params[],
  379. const char *name, const char *val)
  380. {
  381. int num, v;
  382. const char *pos;
  383. struct hostapd_wmm_ac_params *ac;
  384. /* skip 'wme_ac_' or 'wmm_ac_' prefix */
  385. pos = name + 7;
  386. if (os_strncmp(pos, "be_", 3) == 0) {
  387. num = 0;
  388. pos += 3;
  389. } else if (os_strncmp(pos, "bk_", 3) == 0) {
  390. num = 1;
  391. pos += 3;
  392. } else if (os_strncmp(pos, "vi_", 3) == 0) {
  393. num = 2;
  394. pos += 3;
  395. } else if (os_strncmp(pos, "vo_", 3) == 0) {
  396. num = 3;
  397. pos += 3;
  398. } else {
  399. wpa_printf(MSG_ERROR, "Unknown WMM name '%s'", pos);
  400. return -1;
  401. }
  402. ac = &wmm_ac_params[num];
  403. if (os_strcmp(pos, "aifs") == 0) {
  404. v = atoi(val);
  405. if (v < 1 || v > 255) {
  406. wpa_printf(MSG_ERROR, "Invalid AIFS value %d", v);
  407. return -1;
  408. }
  409. ac->aifs = v;
  410. } else if (os_strcmp(pos, "cwmin") == 0) {
  411. v = atoi(val);
  412. if (v < 0 || v > 12) {
  413. wpa_printf(MSG_ERROR, "Invalid cwMin value %d", v);
  414. return -1;
  415. }
  416. ac->cwmin = v;
  417. } else if (os_strcmp(pos, "cwmax") == 0) {
  418. v = atoi(val);
  419. if (v < 0 || v > 12) {
  420. wpa_printf(MSG_ERROR, "Invalid cwMax value %d", v);
  421. return -1;
  422. }
  423. ac->cwmax = v;
  424. } else if (os_strcmp(pos, "txop_limit") == 0) {
  425. v = atoi(val);
  426. if (v < 0 || v > 0xffff) {
  427. wpa_printf(MSG_ERROR, "Invalid txop value %d", v);
  428. return -1;
  429. }
  430. ac->txop_limit = v;
  431. } else if (os_strcmp(pos, "acm") == 0) {
  432. v = atoi(val);
  433. if (v < 0 || v > 1) {
  434. wpa_printf(MSG_ERROR, "Invalid acm value %d", v);
  435. return -1;
  436. }
  437. ac->admission_control_mandatory = v;
  438. } else {
  439. wpa_printf(MSG_ERROR, "Unknown wmm_ac_ field '%s'", pos);
  440. return -1;
  441. }
  442. return 0;
  443. }