driver_nl80211_event.c 55 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927
  1. /*
  2. * Driver interaction with Linux nl80211/cfg80211 - Event processing
  3. * Copyright (c) 2002-2014, Jouni Malinen <j@w1.fi>
  4. * Copyright (c) 2007, Johannes Berg <johannes@sipsolutions.net>
  5. * Copyright (c) 2009-2010, Atheros Communications
  6. *
  7. * This software may be distributed under the terms of the BSD license.
  8. * See README for more details.
  9. */
  10. #include "includes.h"
  11. #include <netlink/genl/genl.h>
  12. #include "utils/common.h"
  13. #include "utils/eloop.h"
  14. #include "common/qca-vendor.h"
  15. #include "common/qca-vendor-attr.h"
  16. #include "common/ieee802_11_defs.h"
  17. #include "common/ieee802_11_common.h"
  18. #include "driver_nl80211.h"
  19. static const char * nl80211_command_to_string(enum nl80211_commands cmd)
  20. {
  21. #define C2S(x) case x: return #x;
  22. switch (cmd) {
  23. C2S(NL80211_CMD_UNSPEC)
  24. C2S(NL80211_CMD_GET_WIPHY)
  25. C2S(NL80211_CMD_SET_WIPHY)
  26. C2S(NL80211_CMD_NEW_WIPHY)
  27. C2S(NL80211_CMD_DEL_WIPHY)
  28. C2S(NL80211_CMD_GET_INTERFACE)
  29. C2S(NL80211_CMD_SET_INTERFACE)
  30. C2S(NL80211_CMD_NEW_INTERFACE)
  31. C2S(NL80211_CMD_DEL_INTERFACE)
  32. C2S(NL80211_CMD_GET_KEY)
  33. C2S(NL80211_CMD_SET_KEY)
  34. C2S(NL80211_CMD_NEW_KEY)
  35. C2S(NL80211_CMD_DEL_KEY)
  36. C2S(NL80211_CMD_GET_BEACON)
  37. C2S(NL80211_CMD_SET_BEACON)
  38. C2S(NL80211_CMD_START_AP)
  39. C2S(NL80211_CMD_STOP_AP)
  40. C2S(NL80211_CMD_GET_STATION)
  41. C2S(NL80211_CMD_SET_STATION)
  42. C2S(NL80211_CMD_NEW_STATION)
  43. C2S(NL80211_CMD_DEL_STATION)
  44. C2S(NL80211_CMD_GET_MPATH)
  45. C2S(NL80211_CMD_SET_MPATH)
  46. C2S(NL80211_CMD_NEW_MPATH)
  47. C2S(NL80211_CMD_DEL_MPATH)
  48. C2S(NL80211_CMD_SET_BSS)
  49. C2S(NL80211_CMD_SET_REG)
  50. C2S(NL80211_CMD_REQ_SET_REG)
  51. C2S(NL80211_CMD_GET_MESH_CONFIG)
  52. C2S(NL80211_CMD_SET_MESH_CONFIG)
  53. C2S(NL80211_CMD_SET_MGMT_EXTRA_IE)
  54. C2S(NL80211_CMD_GET_REG)
  55. C2S(NL80211_CMD_GET_SCAN)
  56. C2S(NL80211_CMD_TRIGGER_SCAN)
  57. C2S(NL80211_CMD_NEW_SCAN_RESULTS)
  58. C2S(NL80211_CMD_SCAN_ABORTED)
  59. C2S(NL80211_CMD_REG_CHANGE)
  60. C2S(NL80211_CMD_AUTHENTICATE)
  61. C2S(NL80211_CMD_ASSOCIATE)
  62. C2S(NL80211_CMD_DEAUTHENTICATE)
  63. C2S(NL80211_CMD_DISASSOCIATE)
  64. C2S(NL80211_CMD_MICHAEL_MIC_FAILURE)
  65. C2S(NL80211_CMD_REG_BEACON_HINT)
  66. C2S(NL80211_CMD_JOIN_IBSS)
  67. C2S(NL80211_CMD_LEAVE_IBSS)
  68. C2S(NL80211_CMD_TESTMODE)
  69. C2S(NL80211_CMD_CONNECT)
  70. C2S(NL80211_CMD_ROAM)
  71. C2S(NL80211_CMD_DISCONNECT)
  72. C2S(NL80211_CMD_SET_WIPHY_NETNS)
  73. C2S(NL80211_CMD_GET_SURVEY)
  74. C2S(NL80211_CMD_NEW_SURVEY_RESULTS)
  75. C2S(NL80211_CMD_SET_PMKSA)
  76. C2S(NL80211_CMD_DEL_PMKSA)
  77. C2S(NL80211_CMD_FLUSH_PMKSA)
  78. C2S(NL80211_CMD_REMAIN_ON_CHANNEL)
  79. C2S(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL)
  80. C2S(NL80211_CMD_SET_TX_BITRATE_MASK)
  81. C2S(NL80211_CMD_REGISTER_FRAME)
  82. C2S(NL80211_CMD_FRAME)
  83. C2S(NL80211_CMD_FRAME_TX_STATUS)
  84. C2S(NL80211_CMD_SET_POWER_SAVE)
  85. C2S(NL80211_CMD_GET_POWER_SAVE)
  86. C2S(NL80211_CMD_SET_CQM)
  87. C2S(NL80211_CMD_NOTIFY_CQM)
  88. C2S(NL80211_CMD_SET_CHANNEL)
  89. C2S(NL80211_CMD_SET_WDS_PEER)
  90. C2S(NL80211_CMD_FRAME_WAIT_CANCEL)
  91. C2S(NL80211_CMD_JOIN_MESH)
  92. C2S(NL80211_CMD_LEAVE_MESH)
  93. C2S(NL80211_CMD_UNPROT_DEAUTHENTICATE)
  94. C2S(NL80211_CMD_UNPROT_DISASSOCIATE)
  95. C2S(NL80211_CMD_NEW_PEER_CANDIDATE)
  96. C2S(NL80211_CMD_GET_WOWLAN)
  97. C2S(NL80211_CMD_SET_WOWLAN)
  98. C2S(NL80211_CMD_START_SCHED_SCAN)
  99. C2S(NL80211_CMD_STOP_SCHED_SCAN)
  100. C2S(NL80211_CMD_SCHED_SCAN_RESULTS)
  101. C2S(NL80211_CMD_SCHED_SCAN_STOPPED)
  102. C2S(NL80211_CMD_SET_REKEY_OFFLOAD)
  103. C2S(NL80211_CMD_PMKSA_CANDIDATE)
  104. C2S(NL80211_CMD_TDLS_OPER)
  105. C2S(NL80211_CMD_TDLS_MGMT)
  106. C2S(NL80211_CMD_UNEXPECTED_FRAME)
  107. C2S(NL80211_CMD_PROBE_CLIENT)
  108. C2S(NL80211_CMD_REGISTER_BEACONS)
  109. C2S(NL80211_CMD_UNEXPECTED_4ADDR_FRAME)
  110. C2S(NL80211_CMD_SET_NOACK_MAP)
  111. C2S(NL80211_CMD_CH_SWITCH_NOTIFY)
  112. C2S(NL80211_CMD_START_P2P_DEVICE)
  113. C2S(NL80211_CMD_STOP_P2P_DEVICE)
  114. C2S(NL80211_CMD_CONN_FAILED)
  115. C2S(NL80211_CMD_SET_MCAST_RATE)
  116. C2S(NL80211_CMD_SET_MAC_ACL)
  117. C2S(NL80211_CMD_RADAR_DETECT)
  118. C2S(NL80211_CMD_GET_PROTOCOL_FEATURES)
  119. C2S(NL80211_CMD_UPDATE_FT_IES)
  120. C2S(NL80211_CMD_FT_EVENT)
  121. C2S(NL80211_CMD_CRIT_PROTOCOL_START)
  122. C2S(NL80211_CMD_CRIT_PROTOCOL_STOP)
  123. C2S(NL80211_CMD_GET_COALESCE)
  124. C2S(NL80211_CMD_SET_COALESCE)
  125. C2S(NL80211_CMD_CHANNEL_SWITCH)
  126. C2S(NL80211_CMD_VENDOR)
  127. C2S(NL80211_CMD_SET_QOS_MAP)
  128. C2S(NL80211_CMD_ADD_TX_TS)
  129. C2S(NL80211_CMD_DEL_TX_TS)
  130. default:
  131. return "NL80211_CMD_UNKNOWN";
  132. }
  133. #undef C2S
  134. }
  135. static void mlme_event_auth(struct wpa_driver_nl80211_data *drv,
  136. const u8 *frame, size_t len)
  137. {
  138. const struct ieee80211_mgmt *mgmt;
  139. union wpa_event_data event;
  140. if (!(drv->capa.flags & WPA_DRIVER_FLAGS_SME) &&
  141. drv->force_connect_cmd) {
  142. /*
  143. * Avoid reporting two association events that would confuse
  144. * the core code.
  145. */
  146. wpa_printf(MSG_DEBUG,
  147. "nl80211: Ignore auth event when using driver SME");
  148. return;
  149. }
  150. wpa_printf(MSG_DEBUG, "nl80211: Authenticate event");
  151. mgmt = (const struct ieee80211_mgmt *) frame;
  152. if (len < 24 + sizeof(mgmt->u.auth)) {
  153. wpa_printf(MSG_DEBUG, "nl80211: Too short association event "
  154. "frame");
  155. return;
  156. }
  157. os_memcpy(drv->auth_bssid, mgmt->sa, ETH_ALEN);
  158. os_memset(drv->auth_attempt_bssid, 0, ETH_ALEN);
  159. os_memset(&event, 0, sizeof(event));
  160. os_memcpy(event.auth.peer, mgmt->sa, ETH_ALEN);
  161. event.auth.auth_type = le_to_host16(mgmt->u.auth.auth_alg);
  162. event.auth.auth_transaction =
  163. le_to_host16(mgmt->u.auth.auth_transaction);
  164. event.auth.status_code = le_to_host16(mgmt->u.auth.status_code);
  165. if (len > 24 + sizeof(mgmt->u.auth)) {
  166. event.auth.ies = mgmt->u.auth.variable;
  167. event.auth.ies_len = len - 24 - sizeof(mgmt->u.auth);
  168. }
  169. wpa_supplicant_event(drv->ctx, EVENT_AUTH, &event);
  170. }
  171. static void nl80211_parse_wmm_params(struct nlattr *wmm_attr,
  172. struct wmm_params *wmm_params)
  173. {
  174. struct nlattr *wmm_info[NL80211_STA_WME_MAX + 1];
  175. static struct nla_policy wme_policy[NL80211_STA_WME_MAX + 1] = {
  176. [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
  177. };
  178. if (!wmm_attr ||
  179. nla_parse_nested(wmm_info, NL80211_STA_WME_MAX, wmm_attr,
  180. wme_policy) ||
  181. !wmm_info[NL80211_STA_WME_UAPSD_QUEUES])
  182. return;
  183. wmm_params->uapsd_queues =
  184. nla_get_u8(wmm_info[NL80211_STA_WME_UAPSD_QUEUES]);
  185. wmm_params->info_bitmap |= WMM_PARAMS_UAPSD_QUEUES_INFO;
  186. }
  187. static void mlme_event_assoc(struct wpa_driver_nl80211_data *drv,
  188. const u8 *frame, size_t len, struct nlattr *wmm)
  189. {
  190. const struct ieee80211_mgmt *mgmt;
  191. union wpa_event_data event;
  192. u16 status;
  193. if (!(drv->capa.flags & WPA_DRIVER_FLAGS_SME) &&
  194. drv->force_connect_cmd) {
  195. /*
  196. * Avoid reporting two association events that would confuse
  197. * the core code.
  198. */
  199. wpa_printf(MSG_DEBUG,
  200. "nl80211: Ignore assoc event when using driver SME");
  201. return;
  202. }
  203. wpa_printf(MSG_DEBUG, "nl80211: Associate event");
  204. mgmt = (const struct ieee80211_mgmt *) frame;
  205. if (len < 24 + sizeof(mgmt->u.assoc_resp)) {
  206. wpa_printf(MSG_DEBUG, "nl80211: Too short association event "
  207. "frame");
  208. return;
  209. }
  210. status = le_to_host16(mgmt->u.assoc_resp.status_code);
  211. if (status != WLAN_STATUS_SUCCESS) {
  212. os_memset(&event, 0, sizeof(event));
  213. event.assoc_reject.bssid = mgmt->bssid;
  214. if (len > 24 + sizeof(mgmt->u.assoc_resp)) {
  215. event.assoc_reject.resp_ies =
  216. (u8 *) mgmt->u.assoc_resp.variable;
  217. event.assoc_reject.resp_ies_len =
  218. len - 24 - sizeof(mgmt->u.assoc_resp);
  219. }
  220. event.assoc_reject.status_code = status;
  221. wpa_supplicant_event(drv->ctx, EVENT_ASSOC_REJECT, &event);
  222. return;
  223. }
  224. drv->associated = 1;
  225. os_memcpy(drv->bssid, mgmt->sa, ETH_ALEN);
  226. os_memcpy(drv->prev_bssid, mgmt->sa, ETH_ALEN);
  227. os_memset(&event, 0, sizeof(event));
  228. if (len > 24 + sizeof(mgmt->u.assoc_resp)) {
  229. event.assoc_info.resp_ies = (u8 *) mgmt->u.assoc_resp.variable;
  230. event.assoc_info.resp_ies_len =
  231. len - 24 - sizeof(mgmt->u.assoc_resp);
  232. }
  233. event.assoc_info.freq = drv->assoc_freq;
  234. nl80211_parse_wmm_params(wmm, &event.assoc_info.wmm_params);
  235. wpa_supplicant_event(drv->ctx, EVENT_ASSOC, &event);
  236. }
  237. static void mlme_event_connect(struct wpa_driver_nl80211_data *drv,
  238. enum nl80211_commands cmd, struct nlattr *status,
  239. struct nlattr *addr, struct nlattr *req_ie,
  240. struct nlattr *resp_ie,
  241. struct nlattr *authorized,
  242. struct nlattr *key_replay_ctr,
  243. struct nlattr *ptk_kck,
  244. struct nlattr *ptk_kek)
  245. {
  246. union wpa_event_data event;
  247. u16 status_code;
  248. if (drv->capa.flags & WPA_DRIVER_FLAGS_SME) {
  249. /*
  250. * Avoid reporting two association events that would confuse
  251. * the core code.
  252. */
  253. wpa_printf(MSG_DEBUG, "nl80211: Ignore connect event (cmd=%d) "
  254. "when using userspace SME", cmd);
  255. return;
  256. }
  257. status_code = status ? nla_get_u16(status) : WLAN_STATUS_SUCCESS;
  258. if (cmd == NL80211_CMD_CONNECT) {
  259. wpa_printf(MSG_DEBUG,
  260. "nl80211: Connect event (status=%u ignore_next_local_disconnect=%d)",
  261. status_code, drv->ignore_next_local_disconnect);
  262. } else if (cmd == NL80211_CMD_ROAM) {
  263. wpa_printf(MSG_DEBUG, "nl80211: Roam event");
  264. }
  265. os_memset(&event, 0, sizeof(event));
  266. if (cmd == NL80211_CMD_CONNECT && status_code != WLAN_STATUS_SUCCESS) {
  267. if (addr)
  268. event.assoc_reject.bssid = nla_data(addr);
  269. if (drv->ignore_next_local_disconnect) {
  270. drv->ignore_next_local_disconnect = 0;
  271. if (!event.assoc_reject.bssid ||
  272. (os_memcmp(event.assoc_reject.bssid,
  273. drv->auth_attempt_bssid,
  274. ETH_ALEN) != 0)) {
  275. /*
  276. * Ignore the event that came without a BSSID or
  277. * for the old connection since this is likely
  278. * not relevant to the new Connect command.
  279. */
  280. wpa_printf(MSG_DEBUG,
  281. "nl80211: Ignore connection failure event triggered during reassociation");
  282. return;
  283. }
  284. }
  285. if (resp_ie) {
  286. event.assoc_reject.resp_ies = nla_data(resp_ie);
  287. event.assoc_reject.resp_ies_len = nla_len(resp_ie);
  288. }
  289. event.assoc_reject.status_code = status_code;
  290. wpa_supplicant_event(drv->ctx, EVENT_ASSOC_REJECT, &event);
  291. return;
  292. }
  293. drv->associated = 1;
  294. if (addr) {
  295. os_memcpy(drv->bssid, nla_data(addr), ETH_ALEN);
  296. os_memcpy(drv->prev_bssid, drv->bssid, ETH_ALEN);
  297. }
  298. if (req_ie) {
  299. event.assoc_info.req_ies = nla_data(req_ie);
  300. event.assoc_info.req_ies_len = nla_len(req_ie);
  301. }
  302. if (resp_ie) {
  303. event.assoc_info.resp_ies = nla_data(resp_ie);
  304. event.assoc_info.resp_ies_len = nla_len(resp_ie);
  305. }
  306. event.assoc_info.freq = nl80211_get_assoc_freq(drv);
  307. if (authorized && nla_get_u8(authorized)) {
  308. event.assoc_info.authorized = 1;
  309. wpa_printf(MSG_DEBUG, "nl80211: connection authorized");
  310. }
  311. if (key_replay_ctr) {
  312. event.assoc_info.key_replay_ctr = nla_data(key_replay_ctr);
  313. event.assoc_info.key_replay_ctr_len = nla_len(key_replay_ctr);
  314. }
  315. if (ptk_kck) {
  316. event.assoc_info.ptk_kck = nla_data(ptk_kck);
  317. event.assoc_info.ptk_kck_len = nla_len(ptk_kck);
  318. }
  319. if (ptk_kek) {
  320. event.assoc_info.ptk_kek = nla_data(ptk_kek);
  321. event.assoc_info.ptk_kek_len = nla_len(ptk_kek);
  322. }
  323. wpa_supplicant_event(drv->ctx, EVENT_ASSOC, &event);
  324. }
  325. static void mlme_event_disconnect(struct wpa_driver_nl80211_data *drv,
  326. struct nlattr *reason, struct nlattr *addr,
  327. struct nlattr *by_ap)
  328. {
  329. union wpa_event_data data;
  330. unsigned int locally_generated = by_ap == NULL;
  331. if (drv->capa.flags & WPA_DRIVER_FLAGS_SME) {
  332. /*
  333. * Avoid reporting two disassociation events that could
  334. * confuse the core code.
  335. */
  336. wpa_printf(MSG_DEBUG, "nl80211: Ignore disconnect "
  337. "event when using userspace SME");
  338. return;
  339. }
  340. if (drv->ignore_next_local_disconnect) {
  341. drv->ignore_next_local_disconnect = 0;
  342. if (locally_generated) {
  343. wpa_printf(MSG_DEBUG, "nl80211: Ignore disconnect "
  344. "event triggered during reassociation");
  345. return;
  346. }
  347. wpa_printf(MSG_WARNING, "nl80211: Was expecting local "
  348. "disconnect but got another disconnect "
  349. "event first");
  350. }
  351. wpa_printf(MSG_DEBUG, "nl80211: Disconnect event");
  352. nl80211_mark_disconnected(drv);
  353. os_memset(&data, 0, sizeof(data));
  354. if (reason)
  355. data.deauth_info.reason_code = nla_get_u16(reason);
  356. data.deauth_info.locally_generated = by_ap == NULL;
  357. wpa_supplicant_event(drv->ctx, EVENT_DEAUTH, &data);
  358. }
  359. static int calculate_chan_offset(int width, int freq, int cf1, int cf2)
  360. {
  361. int freq1 = 0;
  362. switch (convert2width(width)) {
  363. case CHAN_WIDTH_20_NOHT:
  364. case CHAN_WIDTH_20:
  365. return 0;
  366. case CHAN_WIDTH_40:
  367. freq1 = cf1 - 10;
  368. break;
  369. case CHAN_WIDTH_80:
  370. freq1 = cf1 - 30;
  371. break;
  372. case CHAN_WIDTH_160:
  373. freq1 = cf1 - 70;
  374. break;
  375. case CHAN_WIDTH_UNKNOWN:
  376. case CHAN_WIDTH_80P80:
  377. /* FIXME: implement this */
  378. return 0;
  379. }
  380. return (abs(freq - freq1) / 20) % 2 == 0 ? 1 : -1;
  381. }
  382. static void mlme_event_ch_switch(struct wpa_driver_nl80211_data *drv,
  383. struct nlattr *ifindex, struct nlattr *freq,
  384. struct nlattr *type, struct nlattr *bw,
  385. struct nlattr *cf1, struct nlattr *cf2)
  386. {
  387. struct i802_bss *bss;
  388. union wpa_event_data data;
  389. int ht_enabled = 1;
  390. int chan_offset = 0;
  391. int ifidx;
  392. wpa_printf(MSG_DEBUG, "nl80211: Channel switch event");
  393. if (!freq)
  394. return;
  395. ifidx = nla_get_u32(ifindex);
  396. bss = get_bss_ifindex(drv, ifidx);
  397. if (bss == NULL) {
  398. wpa_printf(MSG_WARNING, "nl80211: Unknown ifindex (%d) for channel switch, ignoring",
  399. ifidx);
  400. return;
  401. }
  402. if (type) {
  403. enum nl80211_channel_type ch_type = nla_get_u32(type);
  404. wpa_printf(MSG_DEBUG, "nl80211: Channel type: %d", ch_type);
  405. switch (ch_type) {
  406. case NL80211_CHAN_NO_HT:
  407. ht_enabled = 0;
  408. break;
  409. case NL80211_CHAN_HT20:
  410. break;
  411. case NL80211_CHAN_HT40PLUS:
  412. chan_offset = 1;
  413. break;
  414. case NL80211_CHAN_HT40MINUS:
  415. chan_offset = -1;
  416. break;
  417. }
  418. } else if (bw && cf1) {
  419. /* This can happen for example with VHT80 ch switch */
  420. chan_offset = calculate_chan_offset(nla_get_u32(bw),
  421. nla_get_u32(freq),
  422. nla_get_u32(cf1),
  423. cf2 ? nla_get_u32(cf2) : 0);
  424. } else {
  425. wpa_printf(MSG_WARNING, "nl80211: Unknown secondary channel information - following channel definition calculations may fail");
  426. }
  427. os_memset(&data, 0, sizeof(data));
  428. data.ch_switch.freq = nla_get_u32(freq);
  429. data.ch_switch.ht_enabled = ht_enabled;
  430. data.ch_switch.ch_offset = chan_offset;
  431. if (bw)
  432. data.ch_switch.ch_width = convert2width(nla_get_u32(bw));
  433. if (cf1)
  434. data.ch_switch.cf1 = nla_get_u32(cf1);
  435. if (cf2)
  436. data.ch_switch.cf2 = nla_get_u32(cf2);
  437. bss->freq = data.ch_switch.freq;
  438. wpa_supplicant_event(bss->ctx, EVENT_CH_SWITCH, &data);
  439. }
  440. static void mlme_timeout_event(struct wpa_driver_nl80211_data *drv,
  441. enum nl80211_commands cmd, struct nlattr *addr)
  442. {
  443. union wpa_event_data event;
  444. enum wpa_event_type ev;
  445. if (nla_len(addr) != ETH_ALEN)
  446. return;
  447. wpa_printf(MSG_DEBUG, "nl80211: MLME event %d; timeout with " MACSTR,
  448. cmd, MAC2STR((u8 *) nla_data(addr)));
  449. if (cmd == NL80211_CMD_AUTHENTICATE)
  450. ev = EVENT_AUTH_TIMED_OUT;
  451. else if (cmd == NL80211_CMD_ASSOCIATE)
  452. ev = EVENT_ASSOC_TIMED_OUT;
  453. else
  454. return;
  455. os_memset(&event, 0, sizeof(event));
  456. os_memcpy(event.timeout_event.addr, nla_data(addr), ETH_ALEN);
  457. wpa_supplicant_event(drv->ctx, ev, &event);
  458. }
  459. static void mlme_event_mgmt(struct i802_bss *bss,
  460. struct nlattr *freq, struct nlattr *sig,
  461. const u8 *frame, size_t len)
  462. {
  463. struct wpa_driver_nl80211_data *drv = bss->drv;
  464. const struct ieee80211_mgmt *mgmt;
  465. union wpa_event_data event;
  466. u16 fc, stype;
  467. int ssi_signal = 0;
  468. int rx_freq = 0;
  469. wpa_printf(MSG_MSGDUMP, "nl80211: Frame event");
  470. mgmt = (const struct ieee80211_mgmt *) frame;
  471. if (len < 24) {
  472. wpa_printf(MSG_DEBUG, "nl80211: Too short management frame");
  473. return;
  474. }
  475. fc = le_to_host16(mgmt->frame_control);
  476. stype = WLAN_FC_GET_STYPE(fc);
  477. if (sig)
  478. ssi_signal = (s32) nla_get_u32(sig);
  479. os_memset(&event, 0, sizeof(event));
  480. if (freq) {
  481. event.rx_mgmt.freq = nla_get_u32(freq);
  482. rx_freq = drv->last_mgmt_freq = event.rx_mgmt.freq;
  483. }
  484. wpa_printf(MSG_DEBUG,
  485. "nl80211: RX frame sa=" MACSTR
  486. " freq=%d ssi_signal=%d fc=0x%x seq_ctrl=0x%x stype=%u (%s) len=%u",
  487. MAC2STR(mgmt->sa), rx_freq, ssi_signal, fc,
  488. le_to_host16(mgmt->seq_ctrl), stype, fc2str(fc),
  489. (unsigned int) len);
  490. event.rx_mgmt.frame = frame;
  491. event.rx_mgmt.frame_len = len;
  492. event.rx_mgmt.ssi_signal = ssi_signal;
  493. event.rx_mgmt.drv_priv = bss;
  494. wpa_supplicant_event(drv->ctx, EVENT_RX_MGMT, &event);
  495. }
  496. static void mlme_event_mgmt_tx_status(struct wpa_driver_nl80211_data *drv,
  497. struct nlattr *cookie, const u8 *frame,
  498. size_t len, struct nlattr *ack)
  499. {
  500. union wpa_event_data event;
  501. const struct ieee80211_hdr *hdr;
  502. u16 fc;
  503. wpa_printf(MSG_DEBUG, "nl80211: Frame TX status event");
  504. if (!is_ap_interface(drv->nlmode)) {
  505. u64 cookie_val;
  506. if (!cookie)
  507. return;
  508. cookie_val = nla_get_u64(cookie);
  509. wpa_printf(MSG_DEBUG, "nl80211: Action TX status:"
  510. " cookie=0%llx%s (ack=%d)",
  511. (long long unsigned int) cookie_val,
  512. cookie_val == drv->send_action_cookie ?
  513. " (match)" : " (unknown)", ack != NULL);
  514. if (cookie_val != drv->send_action_cookie)
  515. return;
  516. }
  517. hdr = (const struct ieee80211_hdr *) frame;
  518. fc = le_to_host16(hdr->frame_control);
  519. os_memset(&event, 0, sizeof(event));
  520. event.tx_status.type = WLAN_FC_GET_TYPE(fc);
  521. event.tx_status.stype = WLAN_FC_GET_STYPE(fc);
  522. event.tx_status.dst = hdr->addr1;
  523. event.tx_status.data = frame;
  524. event.tx_status.data_len = len;
  525. event.tx_status.ack = ack != NULL;
  526. wpa_supplicant_event(drv->ctx, EVENT_TX_STATUS, &event);
  527. }
  528. static void mlme_event_deauth_disassoc(struct wpa_driver_nl80211_data *drv,
  529. enum wpa_event_type type,
  530. const u8 *frame, size_t len)
  531. {
  532. const struct ieee80211_mgmt *mgmt;
  533. union wpa_event_data event;
  534. const u8 *bssid = NULL;
  535. u16 reason_code = 0;
  536. if (type == EVENT_DEAUTH)
  537. wpa_printf(MSG_DEBUG, "nl80211: Deauthenticate event");
  538. else
  539. wpa_printf(MSG_DEBUG, "nl80211: Disassociate event");
  540. mgmt = (const struct ieee80211_mgmt *) frame;
  541. if (len >= 24) {
  542. bssid = mgmt->bssid;
  543. if ((drv->capa.flags & WPA_DRIVER_FLAGS_SME) &&
  544. !drv->associated &&
  545. os_memcmp(bssid, drv->auth_bssid, ETH_ALEN) != 0 &&
  546. os_memcmp(bssid, drv->auth_attempt_bssid, ETH_ALEN) != 0 &&
  547. os_memcmp(bssid, drv->prev_bssid, ETH_ALEN) == 0) {
  548. /*
  549. * Avoid issues with some roaming cases where
  550. * disconnection event for the old AP may show up after
  551. * we have started connection with the new AP.
  552. */
  553. wpa_printf(MSG_DEBUG, "nl80211: Ignore deauth/disassoc event from old AP " MACSTR " when already authenticating with " MACSTR,
  554. MAC2STR(bssid),
  555. MAC2STR(drv->auth_attempt_bssid));
  556. return;
  557. }
  558. if (drv->associated != 0 &&
  559. os_memcmp(bssid, drv->bssid, ETH_ALEN) != 0 &&
  560. os_memcmp(bssid, drv->auth_bssid, ETH_ALEN) != 0) {
  561. /*
  562. * We have presumably received this deauth as a
  563. * response to a clear_state_mismatch() outgoing
  564. * deauth. Don't let it take us offline!
  565. */
  566. wpa_printf(MSG_DEBUG, "nl80211: Deauth received "
  567. "from Unknown BSSID " MACSTR " -- ignoring",
  568. MAC2STR(bssid));
  569. return;
  570. }
  571. }
  572. nl80211_mark_disconnected(drv);
  573. os_memset(&event, 0, sizeof(event));
  574. /* Note: Same offset for Reason Code in both frame subtypes */
  575. if (len >= 24 + sizeof(mgmt->u.deauth))
  576. reason_code = le_to_host16(mgmt->u.deauth.reason_code);
  577. if (type == EVENT_DISASSOC) {
  578. event.disassoc_info.locally_generated =
  579. !os_memcmp(mgmt->sa, drv->first_bss->addr, ETH_ALEN);
  580. event.disassoc_info.addr = bssid;
  581. event.disassoc_info.reason_code = reason_code;
  582. if (frame + len > mgmt->u.disassoc.variable) {
  583. event.disassoc_info.ie = mgmt->u.disassoc.variable;
  584. event.disassoc_info.ie_len = frame + len -
  585. mgmt->u.disassoc.variable;
  586. }
  587. } else {
  588. if (drv->ignore_deauth_event) {
  589. wpa_printf(MSG_DEBUG, "nl80211: Ignore deauth event due to previous forced deauth-during-auth");
  590. drv->ignore_deauth_event = 0;
  591. return;
  592. }
  593. event.deauth_info.locally_generated =
  594. !os_memcmp(mgmt->sa, drv->first_bss->addr, ETH_ALEN);
  595. if (drv->ignore_next_local_deauth) {
  596. drv->ignore_next_local_deauth = 0;
  597. if (event.deauth_info.locally_generated) {
  598. wpa_printf(MSG_DEBUG, "nl80211: Ignore deauth event triggered due to own deauth request");
  599. return;
  600. }
  601. wpa_printf(MSG_WARNING, "nl80211: Was expecting local deauth but got another disconnect event first");
  602. }
  603. event.deauth_info.addr = bssid;
  604. event.deauth_info.reason_code = reason_code;
  605. if (frame + len > mgmt->u.deauth.variable) {
  606. event.deauth_info.ie = mgmt->u.deauth.variable;
  607. event.deauth_info.ie_len = frame + len -
  608. mgmt->u.deauth.variable;
  609. }
  610. }
  611. wpa_supplicant_event(drv->ctx, type, &event);
  612. }
  613. static void mlme_event_unprot_disconnect(struct wpa_driver_nl80211_data *drv,
  614. enum wpa_event_type type,
  615. const u8 *frame, size_t len)
  616. {
  617. const struct ieee80211_mgmt *mgmt;
  618. union wpa_event_data event;
  619. u16 reason_code = 0;
  620. if (type == EVENT_UNPROT_DEAUTH)
  621. wpa_printf(MSG_DEBUG, "nl80211: Unprot Deauthenticate event");
  622. else
  623. wpa_printf(MSG_DEBUG, "nl80211: Unprot Disassociate event");
  624. if (len < 24)
  625. return;
  626. mgmt = (const struct ieee80211_mgmt *) frame;
  627. os_memset(&event, 0, sizeof(event));
  628. /* Note: Same offset for Reason Code in both frame subtypes */
  629. if (len >= 24 + sizeof(mgmt->u.deauth))
  630. reason_code = le_to_host16(mgmt->u.deauth.reason_code);
  631. if (type == EVENT_UNPROT_DISASSOC) {
  632. event.unprot_disassoc.sa = mgmt->sa;
  633. event.unprot_disassoc.da = mgmt->da;
  634. event.unprot_disassoc.reason_code = reason_code;
  635. } else {
  636. event.unprot_deauth.sa = mgmt->sa;
  637. event.unprot_deauth.da = mgmt->da;
  638. event.unprot_deauth.reason_code = reason_code;
  639. }
  640. wpa_supplicant_event(drv->ctx, type, &event);
  641. }
  642. static void mlme_event(struct i802_bss *bss,
  643. enum nl80211_commands cmd, struct nlattr *frame,
  644. struct nlattr *addr, struct nlattr *timed_out,
  645. struct nlattr *freq, struct nlattr *ack,
  646. struct nlattr *cookie, struct nlattr *sig,
  647. struct nlattr *wmm)
  648. {
  649. struct wpa_driver_nl80211_data *drv = bss->drv;
  650. const u8 *data;
  651. size_t len;
  652. if (timed_out && addr) {
  653. mlme_timeout_event(drv, cmd, addr);
  654. return;
  655. }
  656. if (frame == NULL) {
  657. wpa_printf(MSG_DEBUG,
  658. "nl80211: MLME event %d (%s) without frame data",
  659. cmd, nl80211_command_to_string(cmd));
  660. return;
  661. }
  662. data = nla_data(frame);
  663. len = nla_len(frame);
  664. if (len < 4 + 2 * ETH_ALEN) {
  665. wpa_printf(MSG_MSGDUMP, "nl80211: MLME event %d (%s) on %s("
  666. MACSTR ") - too short",
  667. cmd, nl80211_command_to_string(cmd), bss->ifname,
  668. MAC2STR(bss->addr));
  669. return;
  670. }
  671. wpa_printf(MSG_MSGDUMP, "nl80211: MLME event %d (%s) on %s(" MACSTR
  672. ") A1=" MACSTR " A2=" MACSTR, cmd,
  673. nl80211_command_to_string(cmd), bss->ifname,
  674. MAC2STR(bss->addr), MAC2STR(data + 4),
  675. MAC2STR(data + 4 + ETH_ALEN));
  676. if (cmd != NL80211_CMD_FRAME_TX_STATUS && !(data[4] & 0x01) &&
  677. os_memcmp(bss->addr, data + 4, ETH_ALEN) != 0 &&
  678. os_memcmp(bss->addr, data + 4 + ETH_ALEN, ETH_ALEN) != 0) {
  679. wpa_printf(MSG_MSGDUMP, "nl80211: %s: Ignore MLME frame event "
  680. "for foreign address", bss->ifname);
  681. return;
  682. }
  683. wpa_hexdump(MSG_MSGDUMP, "nl80211: MLME event frame",
  684. nla_data(frame), nla_len(frame));
  685. switch (cmd) {
  686. case NL80211_CMD_AUTHENTICATE:
  687. mlme_event_auth(drv, nla_data(frame), nla_len(frame));
  688. break;
  689. case NL80211_CMD_ASSOCIATE:
  690. mlme_event_assoc(drv, nla_data(frame), nla_len(frame), wmm);
  691. break;
  692. case NL80211_CMD_DEAUTHENTICATE:
  693. mlme_event_deauth_disassoc(drv, EVENT_DEAUTH,
  694. nla_data(frame), nla_len(frame));
  695. break;
  696. case NL80211_CMD_DISASSOCIATE:
  697. mlme_event_deauth_disassoc(drv, EVENT_DISASSOC,
  698. nla_data(frame), nla_len(frame));
  699. break;
  700. case NL80211_CMD_FRAME:
  701. mlme_event_mgmt(bss, freq, sig, nla_data(frame),
  702. nla_len(frame));
  703. break;
  704. case NL80211_CMD_FRAME_TX_STATUS:
  705. mlme_event_mgmt_tx_status(drv, cookie, nla_data(frame),
  706. nla_len(frame), ack);
  707. break;
  708. case NL80211_CMD_UNPROT_DEAUTHENTICATE:
  709. mlme_event_unprot_disconnect(drv, EVENT_UNPROT_DEAUTH,
  710. nla_data(frame), nla_len(frame));
  711. break;
  712. case NL80211_CMD_UNPROT_DISASSOCIATE:
  713. mlme_event_unprot_disconnect(drv, EVENT_UNPROT_DISASSOC,
  714. nla_data(frame), nla_len(frame));
  715. break;
  716. default:
  717. break;
  718. }
  719. }
  720. static void mlme_event_michael_mic_failure(struct i802_bss *bss,
  721. struct nlattr *tb[])
  722. {
  723. union wpa_event_data data;
  724. wpa_printf(MSG_DEBUG, "nl80211: MLME event Michael MIC failure");
  725. os_memset(&data, 0, sizeof(data));
  726. if (tb[NL80211_ATTR_MAC]) {
  727. wpa_hexdump(MSG_DEBUG, "nl80211: Source MAC address",
  728. nla_data(tb[NL80211_ATTR_MAC]),
  729. nla_len(tb[NL80211_ATTR_MAC]));
  730. data.michael_mic_failure.src = nla_data(tb[NL80211_ATTR_MAC]);
  731. }
  732. if (tb[NL80211_ATTR_KEY_SEQ]) {
  733. wpa_hexdump(MSG_DEBUG, "nl80211: TSC",
  734. nla_data(tb[NL80211_ATTR_KEY_SEQ]),
  735. nla_len(tb[NL80211_ATTR_KEY_SEQ]));
  736. }
  737. if (tb[NL80211_ATTR_KEY_TYPE]) {
  738. enum nl80211_key_type key_type =
  739. nla_get_u32(tb[NL80211_ATTR_KEY_TYPE]);
  740. wpa_printf(MSG_DEBUG, "nl80211: Key Type %d", key_type);
  741. if (key_type == NL80211_KEYTYPE_PAIRWISE)
  742. data.michael_mic_failure.unicast = 1;
  743. } else
  744. data.michael_mic_failure.unicast = 1;
  745. if (tb[NL80211_ATTR_KEY_IDX]) {
  746. u8 key_id = nla_get_u8(tb[NL80211_ATTR_KEY_IDX]);
  747. wpa_printf(MSG_DEBUG, "nl80211: Key Id %d", key_id);
  748. }
  749. wpa_supplicant_event(bss->ctx, EVENT_MICHAEL_MIC_FAILURE, &data);
  750. }
  751. static void mlme_event_join_ibss(struct wpa_driver_nl80211_data *drv,
  752. struct nlattr *tb[])
  753. {
  754. unsigned int freq;
  755. if (tb[NL80211_ATTR_MAC] == NULL) {
  756. wpa_printf(MSG_DEBUG, "nl80211: No address in IBSS joined "
  757. "event");
  758. return;
  759. }
  760. os_memcpy(drv->bssid, nla_data(tb[NL80211_ATTR_MAC]), ETH_ALEN);
  761. drv->associated = 1;
  762. wpa_printf(MSG_DEBUG, "nl80211: IBSS " MACSTR " joined",
  763. MAC2STR(drv->bssid));
  764. freq = nl80211_get_assoc_freq(drv);
  765. if (freq) {
  766. wpa_printf(MSG_DEBUG, "nl80211: IBSS on frequency %u MHz",
  767. freq);
  768. drv->first_bss->freq = freq;
  769. }
  770. wpa_supplicant_event(drv->ctx, EVENT_ASSOC, NULL);
  771. }
  772. static void mlme_event_remain_on_channel(struct wpa_driver_nl80211_data *drv,
  773. int cancel_event, struct nlattr *tb[])
  774. {
  775. unsigned int freq, chan_type, duration;
  776. union wpa_event_data data;
  777. u64 cookie;
  778. if (tb[NL80211_ATTR_WIPHY_FREQ])
  779. freq = nla_get_u32(tb[NL80211_ATTR_WIPHY_FREQ]);
  780. else
  781. freq = 0;
  782. if (tb[NL80211_ATTR_WIPHY_CHANNEL_TYPE])
  783. chan_type = nla_get_u32(tb[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
  784. else
  785. chan_type = 0;
  786. if (tb[NL80211_ATTR_DURATION])
  787. duration = nla_get_u32(tb[NL80211_ATTR_DURATION]);
  788. else
  789. duration = 0;
  790. if (tb[NL80211_ATTR_COOKIE])
  791. cookie = nla_get_u64(tb[NL80211_ATTR_COOKIE]);
  792. else
  793. cookie = 0;
  794. wpa_printf(MSG_DEBUG, "nl80211: Remain-on-channel event (cancel=%d "
  795. "freq=%u channel_type=%u duration=%u cookie=0x%llx (%s))",
  796. cancel_event, freq, chan_type, duration,
  797. (long long unsigned int) cookie,
  798. cookie == drv->remain_on_chan_cookie ? "match" : "unknown");
  799. if (cookie != drv->remain_on_chan_cookie)
  800. return; /* not for us */
  801. if (cancel_event)
  802. drv->pending_remain_on_chan = 0;
  803. os_memset(&data, 0, sizeof(data));
  804. data.remain_on_channel.freq = freq;
  805. data.remain_on_channel.duration = duration;
  806. wpa_supplicant_event(drv->ctx, cancel_event ?
  807. EVENT_CANCEL_REMAIN_ON_CHANNEL :
  808. EVENT_REMAIN_ON_CHANNEL, &data);
  809. }
  810. static void mlme_event_ft_event(struct wpa_driver_nl80211_data *drv,
  811. struct nlattr *tb[])
  812. {
  813. union wpa_event_data data;
  814. os_memset(&data, 0, sizeof(data));
  815. if (tb[NL80211_ATTR_IE]) {
  816. data.ft_ies.ies = nla_data(tb[NL80211_ATTR_IE]);
  817. data.ft_ies.ies_len = nla_len(tb[NL80211_ATTR_IE]);
  818. }
  819. if (tb[NL80211_ATTR_IE_RIC]) {
  820. data.ft_ies.ric_ies = nla_data(tb[NL80211_ATTR_IE_RIC]);
  821. data.ft_ies.ric_ies_len = nla_len(tb[NL80211_ATTR_IE_RIC]);
  822. }
  823. if (tb[NL80211_ATTR_MAC])
  824. os_memcpy(data.ft_ies.target_ap,
  825. nla_data(tb[NL80211_ATTR_MAC]), ETH_ALEN);
  826. wpa_printf(MSG_DEBUG, "nl80211: FT event target_ap " MACSTR,
  827. MAC2STR(data.ft_ies.target_ap));
  828. wpa_supplicant_event(drv->ctx, EVENT_FT_RESPONSE, &data);
  829. }
  830. static void send_scan_event(struct wpa_driver_nl80211_data *drv, int aborted,
  831. struct nlattr *tb[])
  832. {
  833. union wpa_event_data event;
  834. struct nlattr *nl;
  835. int rem;
  836. struct scan_info *info;
  837. #define MAX_REPORT_FREQS 50
  838. int freqs[MAX_REPORT_FREQS];
  839. int num_freqs = 0;
  840. if (drv->scan_for_auth) {
  841. drv->scan_for_auth = 0;
  842. wpa_printf(MSG_DEBUG, "nl80211: Scan results for missing "
  843. "cfg80211 BSS entry");
  844. wpa_driver_nl80211_authenticate_retry(drv);
  845. return;
  846. }
  847. os_memset(&event, 0, sizeof(event));
  848. info = &event.scan_info;
  849. info->aborted = aborted;
  850. if (tb[NL80211_ATTR_SCAN_SSIDS]) {
  851. nla_for_each_nested(nl, tb[NL80211_ATTR_SCAN_SSIDS], rem) {
  852. struct wpa_driver_scan_ssid *s =
  853. &info->ssids[info->num_ssids];
  854. s->ssid = nla_data(nl);
  855. s->ssid_len = nla_len(nl);
  856. wpa_printf(MSG_DEBUG, "nl80211: Scan probed for SSID '%s'",
  857. wpa_ssid_txt(s->ssid, s->ssid_len));
  858. info->num_ssids++;
  859. if (info->num_ssids == WPAS_MAX_SCAN_SSIDS)
  860. break;
  861. }
  862. }
  863. if (tb[NL80211_ATTR_SCAN_FREQUENCIES]) {
  864. char msg[200], *pos, *end;
  865. int res;
  866. pos = msg;
  867. end = pos + sizeof(msg);
  868. *pos = '\0';
  869. nla_for_each_nested(nl, tb[NL80211_ATTR_SCAN_FREQUENCIES], rem)
  870. {
  871. freqs[num_freqs] = nla_get_u32(nl);
  872. res = os_snprintf(pos, end - pos, " %d",
  873. freqs[num_freqs]);
  874. if (!os_snprintf_error(end - pos, res))
  875. pos += res;
  876. num_freqs++;
  877. if (num_freqs == MAX_REPORT_FREQS - 1)
  878. break;
  879. }
  880. info->freqs = freqs;
  881. info->num_freqs = num_freqs;
  882. wpa_printf(MSG_DEBUG, "nl80211: Scan included frequencies:%s",
  883. msg);
  884. }
  885. wpa_supplicant_event(drv->ctx, EVENT_SCAN_RESULTS, &event);
  886. }
  887. static void nl80211_cqm_event(struct wpa_driver_nl80211_data *drv,
  888. struct nlattr *tb[])
  889. {
  890. static struct nla_policy cqm_policy[NL80211_ATTR_CQM_MAX + 1] = {
  891. [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
  892. [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U8 },
  893. [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
  894. [NL80211_ATTR_CQM_PKT_LOSS_EVENT] = { .type = NLA_U32 },
  895. };
  896. struct nlattr *cqm[NL80211_ATTR_CQM_MAX + 1];
  897. enum nl80211_cqm_rssi_threshold_event event;
  898. union wpa_event_data ed;
  899. struct wpa_signal_info sig;
  900. int res;
  901. if (tb[NL80211_ATTR_CQM] == NULL ||
  902. nla_parse_nested(cqm, NL80211_ATTR_CQM_MAX, tb[NL80211_ATTR_CQM],
  903. cqm_policy)) {
  904. wpa_printf(MSG_DEBUG, "nl80211: Ignore invalid CQM event");
  905. return;
  906. }
  907. os_memset(&ed, 0, sizeof(ed));
  908. if (cqm[NL80211_ATTR_CQM_PKT_LOSS_EVENT]) {
  909. if (!tb[NL80211_ATTR_MAC])
  910. return;
  911. os_memcpy(ed.low_ack.addr, nla_data(tb[NL80211_ATTR_MAC]),
  912. ETH_ALEN);
  913. wpa_supplicant_event(drv->ctx, EVENT_STATION_LOW_ACK, &ed);
  914. return;
  915. }
  916. if (cqm[NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] == NULL)
  917. return;
  918. event = nla_get_u32(cqm[NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT]);
  919. if (event == NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH) {
  920. wpa_printf(MSG_DEBUG, "nl80211: Connection quality monitor "
  921. "event: RSSI high");
  922. ed.signal_change.above_threshold = 1;
  923. } else if (event == NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW) {
  924. wpa_printf(MSG_DEBUG, "nl80211: Connection quality monitor "
  925. "event: RSSI low");
  926. ed.signal_change.above_threshold = 0;
  927. } else
  928. return;
  929. res = nl80211_get_link_signal(drv, &sig);
  930. if (res == 0) {
  931. ed.signal_change.current_signal = sig.current_signal;
  932. ed.signal_change.current_txrate = sig.current_txrate;
  933. wpa_printf(MSG_DEBUG, "nl80211: Signal: %d dBm txrate: %d",
  934. sig.current_signal, sig.current_txrate);
  935. }
  936. res = nl80211_get_link_noise(drv, &sig);
  937. if (res == 0) {
  938. ed.signal_change.current_noise = sig.current_noise;
  939. wpa_printf(MSG_DEBUG, "nl80211: Noise: %d dBm",
  940. sig.current_noise);
  941. }
  942. wpa_supplicant_event(drv->ctx, EVENT_SIGNAL_CHANGE, &ed);
  943. }
  944. static void nl80211_new_peer_candidate(struct wpa_driver_nl80211_data *drv,
  945. struct nlattr **tb)
  946. {
  947. const u8 *addr;
  948. union wpa_event_data data;
  949. if (drv->nlmode != NL80211_IFTYPE_MESH_POINT ||
  950. !tb[NL80211_ATTR_MAC] || !tb[NL80211_ATTR_IE])
  951. return;
  952. addr = nla_data(tb[NL80211_ATTR_MAC]);
  953. wpa_printf(MSG_DEBUG, "nl80211: New peer candidate" MACSTR,
  954. MAC2STR(addr));
  955. os_memset(&data, 0, sizeof(data));
  956. data.mesh_peer.peer = addr;
  957. data.mesh_peer.ies = nla_data(tb[NL80211_ATTR_IE]);
  958. data.mesh_peer.ie_len = nla_len(tb[NL80211_ATTR_IE]);
  959. wpa_supplicant_event(drv->ctx, EVENT_NEW_PEER_CANDIDATE, &data);
  960. }
  961. static void nl80211_new_station_event(struct wpa_driver_nl80211_data *drv,
  962. struct i802_bss *bss,
  963. struct nlattr **tb)
  964. {
  965. u8 *addr;
  966. union wpa_event_data data;
  967. if (tb[NL80211_ATTR_MAC] == NULL)
  968. return;
  969. addr = nla_data(tb[NL80211_ATTR_MAC]);
  970. wpa_printf(MSG_DEBUG, "nl80211: New station " MACSTR, MAC2STR(addr));
  971. if (is_ap_interface(drv->nlmode) && drv->device_ap_sme) {
  972. u8 *ies = NULL;
  973. size_t ies_len = 0;
  974. if (tb[NL80211_ATTR_IE]) {
  975. ies = nla_data(tb[NL80211_ATTR_IE]);
  976. ies_len = nla_len(tb[NL80211_ATTR_IE]);
  977. }
  978. wpa_hexdump(MSG_DEBUG, "nl80211: Assoc Req IEs", ies, ies_len);
  979. drv_event_assoc(bss->ctx, addr, ies, ies_len, 0);
  980. return;
  981. }
  982. if (drv->nlmode != NL80211_IFTYPE_ADHOC)
  983. return;
  984. os_memset(&data, 0, sizeof(data));
  985. os_memcpy(data.ibss_rsn_start.peer, addr, ETH_ALEN);
  986. wpa_supplicant_event(bss->ctx, EVENT_IBSS_RSN_START, &data);
  987. }
  988. static void nl80211_del_station_event(struct wpa_driver_nl80211_data *drv,
  989. struct nlattr **tb)
  990. {
  991. u8 *addr;
  992. union wpa_event_data data;
  993. if (tb[NL80211_ATTR_MAC] == NULL)
  994. return;
  995. addr = nla_data(tb[NL80211_ATTR_MAC]);
  996. wpa_printf(MSG_DEBUG, "nl80211: Delete station " MACSTR,
  997. MAC2STR(addr));
  998. if (is_ap_interface(drv->nlmode) && drv->device_ap_sme) {
  999. drv_event_disassoc(drv->ctx, addr);
  1000. return;
  1001. }
  1002. if (drv->nlmode != NL80211_IFTYPE_ADHOC)
  1003. return;
  1004. os_memset(&data, 0, sizeof(data));
  1005. os_memcpy(data.ibss_peer_lost.peer, addr, ETH_ALEN);
  1006. wpa_supplicant_event(drv->ctx, EVENT_IBSS_PEER_LOST, &data);
  1007. }
  1008. static void nl80211_rekey_offload_event(struct wpa_driver_nl80211_data *drv,
  1009. struct nlattr **tb)
  1010. {
  1011. struct nlattr *rekey_info[NUM_NL80211_REKEY_DATA];
  1012. static struct nla_policy rekey_policy[NUM_NL80211_REKEY_DATA] = {
  1013. [NL80211_REKEY_DATA_KEK] = {
  1014. .minlen = NL80211_KEK_LEN,
  1015. .maxlen = NL80211_KEK_LEN,
  1016. },
  1017. [NL80211_REKEY_DATA_KCK] = {
  1018. .minlen = NL80211_KCK_LEN,
  1019. .maxlen = NL80211_KCK_LEN,
  1020. },
  1021. [NL80211_REKEY_DATA_REPLAY_CTR] = {
  1022. .minlen = NL80211_REPLAY_CTR_LEN,
  1023. .maxlen = NL80211_REPLAY_CTR_LEN,
  1024. },
  1025. };
  1026. union wpa_event_data data;
  1027. if (!tb[NL80211_ATTR_MAC] ||
  1028. !tb[NL80211_ATTR_REKEY_DATA] ||
  1029. nla_parse_nested(rekey_info, MAX_NL80211_REKEY_DATA,
  1030. tb[NL80211_ATTR_REKEY_DATA], rekey_policy) ||
  1031. !rekey_info[NL80211_REKEY_DATA_REPLAY_CTR])
  1032. return;
  1033. os_memset(&data, 0, sizeof(data));
  1034. data.driver_gtk_rekey.bssid = nla_data(tb[NL80211_ATTR_MAC]);
  1035. wpa_printf(MSG_DEBUG, "nl80211: Rekey offload event for BSSID " MACSTR,
  1036. MAC2STR(data.driver_gtk_rekey.bssid));
  1037. data.driver_gtk_rekey.replay_ctr =
  1038. nla_data(rekey_info[NL80211_REKEY_DATA_REPLAY_CTR]);
  1039. wpa_hexdump(MSG_DEBUG, "nl80211: Rekey offload - Replay Counter",
  1040. data.driver_gtk_rekey.replay_ctr, NL80211_REPLAY_CTR_LEN);
  1041. wpa_supplicant_event(drv->ctx, EVENT_DRIVER_GTK_REKEY, &data);
  1042. }
  1043. static void nl80211_pmksa_candidate_event(struct wpa_driver_nl80211_data *drv,
  1044. struct nlattr **tb)
  1045. {
  1046. struct nlattr *cand[NUM_NL80211_PMKSA_CANDIDATE];
  1047. static struct nla_policy cand_policy[NUM_NL80211_PMKSA_CANDIDATE] = {
  1048. [NL80211_PMKSA_CANDIDATE_INDEX] = { .type = NLA_U32 },
  1049. [NL80211_PMKSA_CANDIDATE_BSSID] = {
  1050. .minlen = ETH_ALEN,
  1051. .maxlen = ETH_ALEN,
  1052. },
  1053. [NL80211_PMKSA_CANDIDATE_PREAUTH] = { .type = NLA_FLAG },
  1054. };
  1055. union wpa_event_data data;
  1056. wpa_printf(MSG_DEBUG, "nl80211: PMKSA candidate event");
  1057. if (!tb[NL80211_ATTR_PMKSA_CANDIDATE] ||
  1058. nla_parse_nested(cand, MAX_NL80211_PMKSA_CANDIDATE,
  1059. tb[NL80211_ATTR_PMKSA_CANDIDATE], cand_policy) ||
  1060. !cand[NL80211_PMKSA_CANDIDATE_INDEX] ||
  1061. !cand[NL80211_PMKSA_CANDIDATE_BSSID])
  1062. return;
  1063. os_memset(&data, 0, sizeof(data));
  1064. os_memcpy(data.pmkid_candidate.bssid,
  1065. nla_data(cand[NL80211_PMKSA_CANDIDATE_BSSID]), ETH_ALEN);
  1066. data.pmkid_candidate.index =
  1067. nla_get_u32(cand[NL80211_PMKSA_CANDIDATE_INDEX]);
  1068. data.pmkid_candidate.preauth =
  1069. cand[NL80211_PMKSA_CANDIDATE_PREAUTH] != NULL;
  1070. wpa_supplicant_event(drv->ctx, EVENT_PMKID_CANDIDATE, &data);
  1071. }
  1072. static void nl80211_client_probe_event(struct wpa_driver_nl80211_data *drv,
  1073. struct nlattr **tb)
  1074. {
  1075. union wpa_event_data data;
  1076. wpa_printf(MSG_DEBUG, "nl80211: Probe client event");
  1077. if (!tb[NL80211_ATTR_MAC] || !tb[NL80211_ATTR_ACK])
  1078. return;
  1079. os_memset(&data, 0, sizeof(data));
  1080. os_memcpy(data.client_poll.addr,
  1081. nla_data(tb[NL80211_ATTR_MAC]), ETH_ALEN);
  1082. wpa_supplicant_event(drv->ctx, EVENT_DRIVER_CLIENT_POLL_OK, &data);
  1083. }
  1084. static void nl80211_tdls_oper_event(struct wpa_driver_nl80211_data *drv,
  1085. struct nlattr **tb)
  1086. {
  1087. union wpa_event_data data;
  1088. wpa_printf(MSG_DEBUG, "nl80211: TDLS operation event");
  1089. if (!tb[NL80211_ATTR_MAC] || !tb[NL80211_ATTR_TDLS_OPERATION])
  1090. return;
  1091. os_memset(&data, 0, sizeof(data));
  1092. os_memcpy(data.tdls.peer, nla_data(tb[NL80211_ATTR_MAC]), ETH_ALEN);
  1093. switch (nla_get_u8(tb[NL80211_ATTR_TDLS_OPERATION])) {
  1094. case NL80211_TDLS_SETUP:
  1095. wpa_printf(MSG_DEBUG, "nl80211: TDLS setup request for peer "
  1096. MACSTR, MAC2STR(data.tdls.peer));
  1097. data.tdls.oper = TDLS_REQUEST_SETUP;
  1098. break;
  1099. case NL80211_TDLS_TEARDOWN:
  1100. wpa_printf(MSG_DEBUG, "nl80211: TDLS teardown request for peer "
  1101. MACSTR, MAC2STR(data.tdls.peer));
  1102. data.tdls.oper = TDLS_REQUEST_TEARDOWN;
  1103. break;
  1104. default:
  1105. wpa_printf(MSG_DEBUG, "nl80211: Unsupported TDLS operatione "
  1106. "event");
  1107. return;
  1108. }
  1109. if (tb[NL80211_ATTR_REASON_CODE]) {
  1110. data.tdls.reason_code =
  1111. nla_get_u16(tb[NL80211_ATTR_REASON_CODE]);
  1112. }
  1113. wpa_supplicant_event(drv->ctx, EVENT_TDLS, &data);
  1114. }
  1115. static void nl80211_stop_ap(struct wpa_driver_nl80211_data *drv,
  1116. struct nlattr **tb)
  1117. {
  1118. wpa_supplicant_event(drv->ctx, EVENT_INTERFACE_UNAVAILABLE, NULL);
  1119. }
  1120. static void nl80211_connect_failed_event(struct wpa_driver_nl80211_data *drv,
  1121. struct nlattr **tb)
  1122. {
  1123. union wpa_event_data data;
  1124. u32 reason;
  1125. wpa_printf(MSG_DEBUG, "nl80211: Connect failed event");
  1126. if (!tb[NL80211_ATTR_MAC] || !tb[NL80211_ATTR_CONN_FAILED_REASON])
  1127. return;
  1128. os_memset(&data, 0, sizeof(data));
  1129. os_memcpy(data.connect_failed_reason.addr,
  1130. nla_data(tb[NL80211_ATTR_MAC]), ETH_ALEN);
  1131. reason = nla_get_u32(tb[NL80211_ATTR_CONN_FAILED_REASON]);
  1132. switch (reason) {
  1133. case NL80211_CONN_FAIL_MAX_CLIENTS:
  1134. wpa_printf(MSG_DEBUG, "nl80211: Max client reached");
  1135. data.connect_failed_reason.code = MAX_CLIENT_REACHED;
  1136. break;
  1137. case NL80211_CONN_FAIL_BLOCKED_CLIENT:
  1138. wpa_printf(MSG_DEBUG, "nl80211: Blocked client " MACSTR
  1139. " tried to connect",
  1140. MAC2STR(data.connect_failed_reason.addr));
  1141. data.connect_failed_reason.code = BLOCKED_CLIENT;
  1142. break;
  1143. default:
  1144. wpa_printf(MSG_DEBUG, "nl8021l: Unknown connect failed reason "
  1145. "%u", reason);
  1146. return;
  1147. }
  1148. wpa_supplicant_event(drv->ctx, EVENT_CONNECT_FAILED_REASON, &data);
  1149. }
  1150. static void nl80211_radar_event(struct wpa_driver_nl80211_data *drv,
  1151. struct nlattr **tb)
  1152. {
  1153. union wpa_event_data data;
  1154. enum nl80211_radar_event event_type;
  1155. if (!tb[NL80211_ATTR_WIPHY_FREQ] || !tb[NL80211_ATTR_RADAR_EVENT])
  1156. return;
  1157. os_memset(&data, 0, sizeof(data));
  1158. data.dfs_event.freq = nla_get_u32(tb[NL80211_ATTR_WIPHY_FREQ]);
  1159. event_type = nla_get_u32(tb[NL80211_ATTR_RADAR_EVENT]);
  1160. /* Check HT params */
  1161. if (tb[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
  1162. data.dfs_event.ht_enabled = 1;
  1163. data.dfs_event.chan_offset = 0;
  1164. switch (nla_get_u32(tb[NL80211_ATTR_WIPHY_CHANNEL_TYPE])) {
  1165. case NL80211_CHAN_NO_HT:
  1166. data.dfs_event.ht_enabled = 0;
  1167. break;
  1168. case NL80211_CHAN_HT20:
  1169. break;
  1170. case NL80211_CHAN_HT40PLUS:
  1171. data.dfs_event.chan_offset = 1;
  1172. break;
  1173. case NL80211_CHAN_HT40MINUS:
  1174. data.dfs_event.chan_offset = -1;
  1175. break;
  1176. }
  1177. }
  1178. /* Get VHT params */
  1179. if (tb[NL80211_ATTR_CHANNEL_WIDTH])
  1180. data.dfs_event.chan_width =
  1181. convert2width(nla_get_u32(
  1182. tb[NL80211_ATTR_CHANNEL_WIDTH]));
  1183. if (tb[NL80211_ATTR_CENTER_FREQ1])
  1184. data.dfs_event.cf1 = nla_get_u32(tb[NL80211_ATTR_CENTER_FREQ1]);
  1185. if (tb[NL80211_ATTR_CENTER_FREQ2])
  1186. data.dfs_event.cf2 = nla_get_u32(tb[NL80211_ATTR_CENTER_FREQ2]);
  1187. wpa_printf(MSG_DEBUG, "nl80211: DFS event on freq %d MHz, ht: %d, offset: %d, width: %d, cf1: %dMHz, cf2: %dMHz",
  1188. data.dfs_event.freq, data.dfs_event.ht_enabled,
  1189. data.dfs_event.chan_offset, data.dfs_event.chan_width,
  1190. data.dfs_event.cf1, data.dfs_event.cf2);
  1191. switch (event_type) {
  1192. case NL80211_RADAR_DETECTED:
  1193. wpa_supplicant_event(drv->ctx, EVENT_DFS_RADAR_DETECTED, &data);
  1194. break;
  1195. case NL80211_RADAR_CAC_FINISHED:
  1196. wpa_supplicant_event(drv->ctx, EVENT_DFS_CAC_FINISHED, &data);
  1197. break;
  1198. case NL80211_RADAR_CAC_ABORTED:
  1199. wpa_supplicant_event(drv->ctx, EVENT_DFS_CAC_ABORTED, &data);
  1200. break;
  1201. case NL80211_RADAR_NOP_FINISHED:
  1202. wpa_supplicant_event(drv->ctx, EVENT_DFS_NOP_FINISHED, &data);
  1203. break;
  1204. default:
  1205. wpa_printf(MSG_DEBUG, "nl80211: Unknown radar event %d "
  1206. "received", event_type);
  1207. break;
  1208. }
  1209. }
  1210. static void nl80211_spurious_frame(struct i802_bss *bss, struct nlattr **tb,
  1211. int wds)
  1212. {
  1213. struct wpa_driver_nl80211_data *drv = bss->drv;
  1214. union wpa_event_data event;
  1215. if (!tb[NL80211_ATTR_MAC])
  1216. return;
  1217. os_memset(&event, 0, sizeof(event));
  1218. event.rx_from_unknown.bssid = bss->addr;
  1219. event.rx_from_unknown.addr = nla_data(tb[NL80211_ATTR_MAC]);
  1220. event.rx_from_unknown.wds = wds;
  1221. wpa_supplicant_event(drv->ctx, EVENT_RX_FROM_UNKNOWN, &event);
  1222. }
  1223. static void qca_nl80211_avoid_freq(struct wpa_driver_nl80211_data *drv,
  1224. const u8 *data, size_t len)
  1225. {
  1226. u32 i, count;
  1227. union wpa_event_data event;
  1228. struct wpa_freq_range *range = NULL;
  1229. const struct qca_avoid_freq_list *freq_range;
  1230. freq_range = (const struct qca_avoid_freq_list *) data;
  1231. if (len < sizeof(freq_range->count))
  1232. return;
  1233. count = freq_range->count;
  1234. if (len < sizeof(freq_range->count) +
  1235. count * sizeof(struct qca_avoid_freq_range)) {
  1236. wpa_printf(MSG_DEBUG, "nl80211: Ignored too short avoid frequency list (len=%u)",
  1237. (unsigned int) len);
  1238. return;
  1239. }
  1240. if (count > 0) {
  1241. range = os_calloc(count, sizeof(struct wpa_freq_range));
  1242. if (range == NULL)
  1243. return;
  1244. }
  1245. os_memset(&event, 0, sizeof(event));
  1246. for (i = 0; i < count; i++) {
  1247. unsigned int idx = event.freq_range.num;
  1248. range[idx].min = freq_range->range[i].start_freq;
  1249. range[idx].max = freq_range->range[i].end_freq;
  1250. wpa_printf(MSG_DEBUG, "nl80211: Avoid frequency range: %u-%u",
  1251. range[idx].min, range[idx].max);
  1252. if (range[idx].min > range[idx].max) {
  1253. wpa_printf(MSG_DEBUG, "nl80211: Ignore invalid frequency range");
  1254. continue;
  1255. }
  1256. event.freq_range.num++;
  1257. }
  1258. event.freq_range.range = range;
  1259. wpa_supplicant_event(drv->ctx, EVENT_AVOID_FREQUENCIES, &event);
  1260. os_free(range);
  1261. }
  1262. static void qca_nl80211_acs_select_ch(struct wpa_driver_nl80211_data *drv,
  1263. const u8 *data, size_t len)
  1264. {
  1265. struct nlattr *tb[QCA_WLAN_VENDOR_ATTR_ACS_MAX + 1];
  1266. union wpa_event_data event;
  1267. wpa_printf(MSG_DEBUG,
  1268. "nl80211: ACS channel selection vendor event received");
  1269. if (nla_parse(tb, QCA_WLAN_VENDOR_ATTR_ACS_MAX,
  1270. (struct nlattr *) data, len, NULL) ||
  1271. !tb[QCA_WLAN_VENDOR_ATTR_ACS_PRIMARY_CHANNEL] ||
  1272. !tb[QCA_WLAN_VENDOR_ATTR_ACS_SECONDARY_CHANNEL])
  1273. return;
  1274. os_memset(&event, 0, sizeof(event));
  1275. event.acs_selected_channels.pri_channel =
  1276. nla_get_u8(tb[QCA_WLAN_VENDOR_ATTR_ACS_PRIMARY_CHANNEL]);
  1277. event.acs_selected_channels.sec_channel =
  1278. nla_get_u8(tb[QCA_WLAN_VENDOR_ATTR_ACS_SECONDARY_CHANNEL]);
  1279. wpa_supplicant_event(drv->ctx, EVENT_ACS_CHANNEL_SELECTED, &event);
  1280. }
  1281. static void qca_nl80211_key_mgmt_auth(struct wpa_driver_nl80211_data *drv,
  1282. const u8 *data, size_t len)
  1283. {
  1284. struct nlattr *tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_MAX + 1];
  1285. u8 *bssid;
  1286. wpa_printf(MSG_DEBUG,
  1287. "nl80211: Key management roam+auth vendor event received");
  1288. if (nla_parse(tb, QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_MAX,
  1289. (struct nlattr *) data, len, NULL) ||
  1290. !tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_BSSID] ||
  1291. nla_len(tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_BSSID]) != ETH_ALEN ||
  1292. !tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_REQ_IE] ||
  1293. !tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_RESP_IE] ||
  1294. !tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_AUTHORIZED])
  1295. return;
  1296. bssid = nla_data(tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_BSSID]);
  1297. wpa_printf(MSG_DEBUG, " * roam BSSID " MACSTR, MAC2STR(bssid));
  1298. mlme_event_connect(drv, NL80211_CMD_ROAM, NULL,
  1299. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_BSSID],
  1300. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_REQ_IE],
  1301. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_RESP_IE],
  1302. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_AUTHORIZED],
  1303. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_KEY_REPLAY_CTR],
  1304. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_PTK_KCK],
  1305. tb[QCA_WLAN_VENDOR_ATTR_ROAM_AUTH_PTK_KEK]);
  1306. }
  1307. static void nl80211_vendor_event_qca(struct wpa_driver_nl80211_data *drv,
  1308. u32 subcmd, u8 *data, size_t len)
  1309. {
  1310. switch (subcmd) {
  1311. case QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY:
  1312. qca_nl80211_avoid_freq(drv, data, len);
  1313. break;
  1314. case QCA_NL80211_VENDOR_SUBCMD_KEY_MGMT_ROAM_AUTH:
  1315. qca_nl80211_key_mgmt_auth(drv, data, len);
  1316. break;
  1317. case QCA_NL80211_VENDOR_SUBCMD_DO_ACS:
  1318. qca_nl80211_acs_select_ch(drv, data, len);
  1319. break;
  1320. default:
  1321. wpa_printf(MSG_DEBUG,
  1322. "nl80211: Ignore unsupported QCA vendor event %u",
  1323. subcmd);
  1324. break;
  1325. }
  1326. }
  1327. static void nl80211_vendor_event(struct wpa_driver_nl80211_data *drv,
  1328. struct nlattr **tb)
  1329. {
  1330. u32 vendor_id, subcmd, wiphy = 0;
  1331. int wiphy_idx;
  1332. u8 *data = NULL;
  1333. size_t len = 0;
  1334. if (!tb[NL80211_ATTR_VENDOR_ID] ||
  1335. !tb[NL80211_ATTR_VENDOR_SUBCMD])
  1336. return;
  1337. vendor_id = nla_get_u32(tb[NL80211_ATTR_VENDOR_ID]);
  1338. subcmd = nla_get_u32(tb[NL80211_ATTR_VENDOR_SUBCMD]);
  1339. if (tb[NL80211_ATTR_WIPHY])
  1340. wiphy = nla_get_u32(tb[NL80211_ATTR_WIPHY]);
  1341. wpa_printf(MSG_DEBUG, "nl80211: Vendor event: wiphy=%u vendor_id=0x%x subcmd=%u",
  1342. wiphy, vendor_id, subcmd);
  1343. if (tb[NL80211_ATTR_VENDOR_DATA]) {
  1344. data = nla_data(tb[NL80211_ATTR_VENDOR_DATA]);
  1345. len = nla_len(tb[NL80211_ATTR_VENDOR_DATA]);
  1346. wpa_hexdump(MSG_MSGDUMP, "nl80211: Vendor data", data, len);
  1347. }
  1348. wiphy_idx = nl80211_get_wiphy_index(drv->first_bss);
  1349. if (wiphy_idx >= 0 && wiphy_idx != (int) wiphy) {
  1350. wpa_printf(MSG_DEBUG, "nl80211: Ignore vendor event for foreign wiphy %u (own: %d)",
  1351. wiphy, wiphy_idx);
  1352. return;
  1353. }
  1354. switch (vendor_id) {
  1355. case OUI_QCA:
  1356. nl80211_vendor_event_qca(drv, subcmd, data, len);
  1357. break;
  1358. default:
  1359. wpa_printf(MSG_DEBUG, "nl80211: Ignore unsupported vendor event");
  1360. break;
  1361. }
  1362. }
  1363. static void nl80211_reg_change_event(struct wpa_driver_nl80211_data *drv,
  1364. struct nlattr *tb[])
  1365. {
  1366. union wpa_event_data data;
  1367. enum nl80211_reg_initiator init;
  1368. wpa_printf(MSG_DEBUG, "nl80211: Regulatory domain change");
  1369. if (tb[NL80211_ATTR_REG_INITIATOR] == NULL)
  1370. return;
  1371. os_memset(&data, 0, sizeof(data));
  1372. init = nla_get_u8(tb[NL80211_ATTR_REG_INITIATOR]);
  1373. wpa_printf(MSG_DEBUG, " * initiator=%d", init);
  1374. switch (init) {
  1375. case NL80211_REGDOM_SET_BY_CORE:
  1376. data.channel_list_changed.initiator = REGDOM_SET_BY_CORE;
  1377. break;
  1378. case NL80211_REGDOM_SET_BY_USER:
  1379. data.channel_list_changed.initiator = REGDOM_SET_BY_USER;
  1380. break;
  1381. case NL80211_REGDOM_SET_BY_DRIVER:
  1382. data.channel_list_changed.initiator = REGDOM_SET_BY_DRIVER;
  1383. break;
  1384. case NL80211_REGDOM_SET_BY_COUNTRY_IE:
  1385. data.channel_list_changed.initiator = REGDOM_SET_BY_COUNTRY_IE;
  1386. break;
  1387. }
  1388. if (tb[NL80211_ATTR_REG_TYPE]) {
  1389. enum nl80211_reg_type type;
  1390. type = nla_get_u8(tb[NL80211_ATTR_REG_TYPE]);
  1391. wpa_printf(MSG_DEBUG, " * type=%d", type);
  1392. switch (type) {
  1393. case NL80211_REGDOM_TYPE_COUNTRY:
  1394. data.channel_list_changed.type = REGDOM_TYPE_COUNTRY;
  1395. break;
  1396. case NL80211_REGDOM_TYPE_WORLD:
  1397. data.channel_list_changed.type = REGDOM_TYPE_WORLD;
  1398. break;
  1399. case NL80211_REGDOM_TYPE_CUSTOM_WORLD:
  1400. data.channel_list_changed.type =
  1401. REGDOM_TYPE_CUSTOM_WORLD;
  1402. break;
  1403. case NL80211_REGDOM_TYPE_INTERSECTION:
  1404. data.channel_list_changed.type =
  1405. REGDOM_TYPE_INTERSECTION;
  1406. break;
  1407. }
  1408. }
  1409. if (tb[NL80211_ATTR_REG_ALPHA2]) {
  1410. os_strlcpy(data.channel_list_changed.alpha2,
  1411. nla_get_string(tb[NL80211_ATTR_REG_ALPHA2]),
  1412. sizeof(data.channel_list_changed.alpha2));
  1413. wpa_printf(MSG_DEBUG, " * alpha2=%s",
  1414. data.channel_list_changed.alpha2);
  1415. }
  1416. wpa_supplicant_event(drv->ctx, EVENT_CHANNEL_LIST_CHANGED, &data);
  1417. }
  1418. static void do_process_drv_event(struct i802_bss *bss, int cmd,
  1419. struct nlattr **tb)
  1420. {
  1421. struct wpa_driver_nl80211_data *drv = bss->drv;
  1422. union wpa_event_data data;
  1423. wpa_printf(MSG_DEBUG, "nl80211: Drv Event %d (%s) received for %s",
  1424. cmd, nl80211_command_to_string(cmd), bss->ifname);
  1425. if (cmd == NL80211_CMD_ROAM &&
  1426. (drv->capa.flags & WPA_DRIVER_FLAGS_KEY_MGMT_OFFLOAD)) {
  1427. /*
  1428. * Device will use roam+auth vendor event to indicate
  1429. * roaming, so ignore the regular roam event.
  1430. */
  1431. wpa_printf(MSG_DEBUG,
  1432. "nl80211: Ignore roam event (cmd=%d), device will use vendor event roam+auth",
  1433. cmd);
  1434. return;
  1435. }
  1436. if (drv->ap_scan_as_station != NL80211_IFTYPE_UNSPECIFIED &&
  1437. (cmd == NL80211_CMD_NEW_SCAN_RESULTS ||
  1438. cmd == NL80211_CMD_SCAN_ABORTED)) {
  1439. wpa_driver_nl80211_set_mode(drv->first_bss,
  1440. drv->ap_scan_as_station);
  1441. drv->ap_scan_as_station = NL80211_IFTYPE_UNSPECIFIED;
  1442. }
  1443. switch (cmd) {
  1444. case NL80211_CMD_TRIGGER_SCAN:
  1445. wpa_dbg(drv->ctx, MSG_DEBUG, "nl80211: Scan trigger");
  1446. drv->scan_state = SCAN_STARTED;
  1447. if (drv->scan_for_auth) {
  1448. /*
  1449. * Cannot indicate EVENT_SCAN_STARTED here since we skip
  1450. * EVENT_SCAN_RESULTS in scan_for_auth case and the
  1451. * upper layer implementation could get confused about
  1452. * scanning state.
  1453. */
  1454. wpa_printf(MSG_DEBUG, "nl80211: Do not indicate scan-start event due to internal scan_for_auth");
  1455. break;
  1456. }
  1457. wpa_supplicant_event(drv->ctx, EVENT_SCAN_STARTED, NULL);
  1458. break;
  1459. case NL80211_CMD_START_SCHED_SCAN:
  1460. wpa_dbg(drv->ctx, MSG_DEBUG, "nl80211: Sched scan started");
  1461. drv->scan_state = SCHED_SCAN_STARTED;
  1462. break;
  1463. case NL80211_CMD_SCHED_SCAN_STOPPED:
  1464. wpa_dbg(drv->ctx, MSG_DEBUG, "nl80211: Sched scan stopped");
  1465. drv->scan_state = SCHED_SCAN_STOPPED;
  1466. wpa_supplicant_event(drv->ctx, EVENT_SCHED_SCAN_STOPPED, NULL);
  1467. break;
  1468. case NL80211_CMD_NEW_SCAN_RESULTS:
  1469. wpa_dbg(drv->ctx, MSG_DEBUG,
  1470. "nl80211: New scan results available");
  1471. drv->scan_state = SCAN_COMPLETED;
  1472. drv->scan_complete_events = 1;
  1473. eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout, drv,
  1474. drv->ctx);
  1475. send_scan_event(drv, 0, tb);
  1476. break;
  1477. case NL80211_CMD_SCHED_SCAN_RESULTS:
  1478. wpa_dbg(drv->ctx, MSG_DEBUG,
  1479. "nl80211: New sched scan results available");
  1480. drv->scan_state = SCHED_SCAN_RESULTS;
  1481. send_scan_event(drv, 0, tb);
  1482. break;
  1483. case NL80211_CMD_SCAN_ABORTED:
  1484. wpa_dbg(drv->ctx, MSG_DEBUG, "nl80211: Scan aborted");
  1485. drv->scan_state = SCAN_ABORTED;
  1486. /*
  1487. * Need to indicate that scan results are available in order
  1488. * not to make wpa_supplicant stop its scanning.
  1489. */
  1490. eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout, drv,
  1491. drv->ctx);
  1492. send_scan_event(drv, 1, tb);
  1493. break;
  1494. case NL80211_CMD_AUTHENTICATE:
  1495. case NL80211_CMD_ASSOCIATE:
  1496. case NL80211_CMD_DEAUTHENTICATE:
  1497. case NL80211_CMD_DISASSOCIATE:
  1498. case NL80211_CMD_FRAME_TX_STATUS:
  1499. case NL80211_CMD_UNPROT_DEAUTHENTICATE:
  1500. case NL80211_CMD_UNPROT_DISASSOCIATE:
  1501. mlme_event(bss, cmd, tb[NL80211_ATTR_FRAME],
  1502. tb[NL80211_ATTR_MAC], tb[NL80211_ATTR_TIMED_OUT],
  1503. tb[NL80211_ATTR_WIPHY_FREQ], tb[NL80211_ATTR_ACK],
  1504. tb[NL80211_ATTR_COOKIE],
  1505. tb[NL80211_ATTR_RX_SIGNAL_DBM],
  1506. tb[NL80211_ATTR_STA_WME]);
  1507. break;
  1508. case NL80211_CMD_CONNECT:
  1509. case NL80211_CMD_ROAM:
  1510. mlme_event_connect(drv, cmd,
  1511. tb[NL80211_ATTR_STATUS_CODE],
  1512. tb[NL80211_ATTR_MAC],
  1513. tb[NL80211_ATTR_REQ_IE],
  1514. tb[NL80211_ATTR_RESP_IE],
  1515. NULL, NULL, NULL, NULL);
  1516. break;
  1517. case NL80211_CMD_CH_SWITCH_NOTIFY:
  1518. mlme_event_ch_switch(drv,
  1519. tb[NL80211_ATTR_IFINDEX],
  1520. tb[NL80211_ATTR_WIPHY_FREQ],
  1521. tb[NL80211_ATTR_WIPHY_CHANNEL_TYPE],
  1522. tb[NL80211_ATTR_CHANNEL_WIDTH],
  1523. tb[NL80211_ATTR_CENTER_FREQ1],
  1524. tb[NL80211_ATTR_CENTER_FREQ2]);
  1525. break;
  1526. case NL80211_CMD_DISCONNECT:
  1527. mlme_event_disconnect(drv, tb[NL80211_ATTR_REASON_CODE],
  1528. tb[NL80211_ATTR_MAC],
  1529. tb[NL80211_ATTR_DISCONNECTED_BY_AP]);
  1530. break;
  1531. case NL80211_CMD_MICHAEL_MIC_FAILURE:
  1532. mlme_event_michael_mic_failure(bss, tb);
  1533. break;
  1534. case NL80211_CMD_JOIN_IBSS:
  1535. mlme_event_join_ibss(drv, tb);
  1536. break;
  1537. case NL80211_CMD_REMAIN_ON_CHANNEL:
  1538. mlme_event_remain_on_channel(drv, 0, tb);
  1539. break;
  1540. case NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL:
  1541. mlme_event_remain_on_channel(drv, 1, tb);
  1542. break;
  1543. case NL80211_CMD_NOTIFY_CQM:
  1544. nl80211_cqm_event(drv, tb);
  1545. break;
  1546. case NL80211_CMD_REG_CHANGE:
  1547. nl80211_reg_change_event(drv, tb);
  1548. break;
  1549. case NL80211_CMD_REG_BEACON_HINT:
  1550. wpa_printf(MSG_DEBUG, "nl80211: Regulatory beacon hint");
  1551. os_memset(&data, 0, sizeof(data));
  1552. data.channel_list_changed.initiator = REGDOM_BEACON_HINT;
  1553. wpa_supplicant_event(drv->ctx, EVENT_CHANNEL_LIST_CHANGED,
  1554. &data);
  1555. break;
  1556. case NL80211_CMD_NEW_STATION:
  1557. nl80211_new_station_event(drv, bss, tb);
  1558. break;
  1559. case NL80211_CMD_DEL_STATION:
  1560. nl80211_del_station_event(drv, tb);
  1561. break;
  1562. case NL80211_CMD_SET_REKEY_OFFLOAD:
  1563. nl80211_rekey_offload_event(drv, tb);
  1564. break;
  1565. case NL80211_CMD_PMKSA_CANDIDATE:
  1566. nl80211_pmksa_candidate_event(drv, tb);
  1567. break;
  1568. case NL80211_CMD_PROBE_CLIENT:
  1569. nl80211_client_probe_event(drv, tb);
  1570. break;
  1571. case NL80211_CMD_TDLS_OPER:
  1572. nl80211_tdls_oper_event(drv, tb);
  1573. break;
  1574. case NL80211_CMD_CONN_FAILED:
  1575. nl80211_connect_failed_event(drv, tb);
  1576. break;
  1577. case NL80211_CMD_FT_EVENT:
  1578. mlme_event_ft_event(drv, tb);
  1579. break;
  1580. case NL80211_CMD_RADAR_DETECT:
  1581. nl80211_radar_event(drv, tb);
  1582. break;
  1583. case NL80211_CMD_STOP_AP:
  1584. nl80211_stop_ap(drv, tb);
  1585. break;
  1586. case NL80211_CMD_VENDOR:
  1587. nl80211_vendor_event(drv, tb);
  1588. break;
  1589. case NL80211_CMD_NEW_PEER_CANDIDATE:
  1590. nl80211_new_peer_candidate(drv, tb);
  1591. break;
  1592. default:
  1593. wpa_dbg(drv->ctx, MSG_DEBUG, "nl80211: Ignored unknown event "
  1594. "(cmd=%d)", cmd);
  1595. break;
  1596. }
  1597. }
  1598. int process_global_event(struct nl_msg *msg, void *arg)
  1599. {
  1600. struct nl80211_global *global = arg;
  1601. struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
  1602. struct nlattr *tb[NL80211_ATTR_MAX + 1];
  1603. struct wpa_driver_nl80211_data *drv, *tmp;
  1604. int ifidx = -1;
  1605. struct i802_bss *bss;
  1606. u64 wdev_id = 0;
  1607. int wdev_id_set = 0;
  1608. nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
  1609. genlmsg_attrlen(gnlh, 0), NULL);
  1610. if (tb[NL80211_ATTR_IFINDEX])
  1611. ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]);
  1612. else if (tb[NL80211_ATTR_WDEV]) {
  1613. wdev_id = nla_get_u64(tb[NL80211_ATTR_WDEV]);
  1614. wdev_id_set = 1;
  1615. }
  1616. dl_list_for_each_safe(drv, tmp, &global->interfaces,
  1617. struct wpa_driver_nl80211_data, list) {
  1618. for (bss = drv->first_bss; bss; bss = bss->next) {
  1619. if ((ifidx == -1 && !wdev_id_set) ||
  1620. ifidx == bss->ifindex ||
  1621. (wdev_id_set && bss->wdev_id_set &&
  1622. wdev_id == bss->wdev_id)) {
  1623. do_process_drv_event(bss, gnlh->cmd, tb);
  1624. return NL_SKIP;
  1625. }
  1626. }
  1627. wpa_printf(MSG_DEBUG,
  1628. "nl80211: Ignored event (cmd=%d) for foreign interface (ifindex %d wdev 0x%llx)",
  1629. gnlh->cmd, ifidx, (long long unsigned int) wdev_id);
  1630. }
  1631. return NL_SKIP;
  1632. }
  1633. int process_bss_event(struct nl_msg *msg, void *arg)
  1634. {
  1635. struct i802_bss *bss = arg;
  1636. struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
  1637. struct nlattr *tb[NL80211_ATTR_MAX + 1];
  1638. nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
  1639. genlmsg_attrlen(gnlh, 0), NULL);
  1640. wpa_printf(MSG_DEBUG, "nl80211: BSS Event %d (%s) received for %s",
  1641. gnlh->cmd, nl80211_command_to_string(gnlh->cmd),
  1642. bss->ifname);
  1643. switch (gnlh->cmd) {
  1644. case NL80211_CMD_FRAME:
  1645. case NL80211_CMD_FRAME_TX_STATUS:
  1646. mlme_event(bss, gnlh->cmd, tb[NL80211_ATTR_FRAME],
  1647. tb[NL80211_ATTR_MAC], tb[NL80211_ATTR_TIMED_OUT],
  1648. tb[NL80211_ATTR_WIPHY_FREQ], tb[NL80211_ATTR_ACK],
  1649. tb[NL80211_ATTR_COOKIE],
  1650. tb[NL80211_ATTR_RX_SIGNAL_DBM],
  1651. tb[NL80211_ATTR_STA_WME]);
  1652. break;
  1653. case NL80211_CMD_UNEXPECTED_FRAME:
  1654. nl80211_spurious_frame(bss, tb, 0);
  1655. break;
  1656. case NL80211_CMD_UNEXPECTED_4ADDR_FRAME:
  1657. nl80211_spurious_frame(bss, tb, 1);
  1658. break;
  1659. default:
  1660. wpa_printf(MSG_DEBUG, "nl80211: Ignored unknown event "
  1661. "(cmd=%d)", gnlh->cmd);
  1662. break;
  1663. }
  1664. return NL_SKIP;
  1665. }