xref: /netbsd-src/external/bsd/wpa/dist/src/drivers/driver_bsd.c (revision b1c86f5f087524e68db12794ee9c3e3da1ab17a0)
1 /*
2  * WPA Supplicant - driver interaction with BSD net80211 layer
3  * Copyright (c) 2004, Sam Leffler <sam@errno.com>
4  * Copyright (c) 2004, 2Wire, Inc
5  *
6  * This program is free software; you can redistribute it and/or modify
7  * it under the terms of the GNU General Public License version 2 as
8  * published by the Free Software Foundation.
9  *
10  * Alternatively, this software may be distributed under the terms of BSD
11  * license.
12  *
13  * See README and COPYING for more details.
14  */
15 
16 #include "includes.h"
17 #include <sys/ioctl.h>
18 
19 #include "common.h"
20 #include "driver.h"
21 #include "eloop.h"
22 #include "common/ieee802_11_defs.h"
23 
24 #include <net/if.h>
25 #include <net/if_media.h>
26 
27 #ifdef __NetBSD__
28 #include <net/if_ether.h>
29 #else
30 #include <net/ethernet.h>
31 #endif
32 #include <net/route.h>
33 
34 #ifdef __DragonFly__
35 #include <netproto/802_11/ieee80211_ioctl.h>
36 #include <netproto/802_11/ieee80211_dragonfly.h>
37 #else /* __DragonFly__ */
38 #ifdef __GLIBC__
39 #include <netinet/ether.h>
40 #endif /* __GLIBC__ */
41 #include <net80211/ieee80211.h>
42 #include <net80211/ieee80211_ioctl.h>
43 #include <net80211/ieee80211_crypto.h>
44 #endif /* __DragonFly__ || __GLIBC__ */
45 #if defined(__FreeBSD__) || defined(__FreeBSD_kernel__)
46 #include <net80211/ieee80211_freebsd.h>
47 #endif
48 #if __NetBSD__
49 #include <net80211/ieee80211_netbsd.h>
50 #endif
51 
52 #include "l2_packet/l2_packet.h"
53 
54 struct bsd_driver_data {
55 	struct hostapd_data *hapd;	/* back pointer */
56 
57 	int	sock;			/* open socket for 802.11 ioctls */
58 	struct l2_packet_data *sock_xmit;/* raw packet xmit socket */
59 	int	route;			/* routing socket for events */
60 	char	ifname[IFNAMSIZ+1];	/* interface name */
61 	int	flags;
62 	unsigned int ifindex;		/* interface index */
63 	void	*ctx;
64 	struct wpa_driver_capa capa;	/* driver capability */
65 	int	is_ap;			/* Access point mode */
66 	int	prev_roaming;	/* roaming state to restore on deinit */
67 	int	prev_privacy;	/* privacy state to restore on deinit */
68 	int	prev_wpa;	/* wpa state to restore on deinit */
69 };
70 
71 /* Generic functions for hostapd and wpa_supplicant */
72 
73 static int
74 bsd_set80211(void *priv, int op, int val, const void *arg, int arg_len)
75 {
76 	struct bsd_driver_data *drv = priv;
77 	struct ieee80211req ireq;
78 
79 	os_memset(&ireq, 0, sizeof(ireq));
80 	os_strlcpy(ireq.i_name, drv->ifname, sizeof(ireq.i_name));
81 	ireq.i_type = op;
82 	ireq.i_val = val;
83 	ireq.i_data = (void *) arg;
84 	ireq.i_len = arg_len;
85 
86 	if (ioctl(drv->sock, SIOCS80211, &ireq) < 0) {
87 		wpa_printf(MSG_ERROR, "ioctl[SIOCS80211, op=%u, val=%u, "
88 			   "arg_len=%u]: %s", op, val, arg_len,
89 			   strerror(errno));
90 		return -1;
91 	}
92 	return 0;
93 }
94 
95 static int
96 bsd_get80211(void *priv, struct ieee80211req *ireq, int op, void *arg,
97 	     int arg_len)
98 {
99 	struct bsd_driver_data *drv = priv;
100 
101 	os_memset(ireq, 0, sizeof(*ireq));
102 	os_strlcpy(ireq->i_name, drv->ifname, sizeof(ireq->i_name));
103 	ireq->i_type = op;
104 	ireq->i_len = arg_len;
105 	ireq->i_data = arg;
106 
107 	if (ioctl(drv->sock, SIOCG80211, ireq) < 0) {
108 		wpa_printf(MSG_ERROR, "ioctl[SIOCS80211, op=%u, "
109 			   "arg_len=%u]: %s", op, arg_len, strerror(errno));
110 		return -1;
111 	}
112 	return 0;
113 }
114 
115 static int
116 get80211var(struct bsd_driver_data *drv, int op, void *arg, int arg_len)
117 {
118 	struct ieee80211req ireq;
119 
120 	if (bsd_get80211(drv, &ireq, op, arg, arg_len) < 0)
121 		return -1;
122 	return ireq.i_len;
123 }
124 
125 static int
126 set80211var(struct bsd_driver_data *drv, int op, const void *arg, int arg_len)
127 {
128 	return bsd_set80211(drv, op, 0, arg, arg_len);
129 }
130 
131 static int
132 set80211param(struct bsd_driver_data *drv, int op, int arg)
133 {
134 	return bsd_set80211(drv, op, arg, NULL, 0);
135 }
136 
137 static int
138 bsd_get_ssid(void *priv, u8 *ssid, int len)
139 {
140 	struct bsd_driver_data *drv = priv;
141 #ifdef SIOCG80211NWID
142 	struct ieee80211_nwid nwid;
143 	struct ifreq ifr;
144 
145 	os_memset(&ifr, 0, sizeof(ifr));
146 	os_strlcpy(ifr.ifr_name, drv->ifname, sizeof(ifr.ifr_name));
147 	ifr.ifr_data = (void *)&nwid;
148 	if (ioctl(drv->sock, SIOCG80211NWID, &ifr) < 0 ||
149 	    nwid.i_len > IEEE80211_NWID_LEN)
150 		return -1;
151 	os_memcpy(ssid, nwid.i_nwid, nwid.i_len);
152 	return nwid.i_len;
153 #else
154 	return get80211var(drv, IEEE80211_IOC_SSID, ssid, IEEE80211_NWID_LEN);
155 #endif
156 }
157 
158 static int
159 bsd_set_ssid(void *priv, const u8 *ssid, int ssid_len)
160 {
161 	struct bsd_driver_data *drv = priv;
162 #ifdef SIOCS80211NWID
163 	struct ieee80211_nwid nwid;
164 	struct ifreq ifr;
165 
166 	os_memcpy(nwid.i_nwid, ssid, ssid_len);
167 	nwid.i_len = ssid_len;
168 	os_memset(&ifr, 0, sizeof(ifr));
169 	os_strlcpy(ifr.ifr_name, drv->ifname, sizeof(ifr.ifr_name));
170 	ifr.ifr_data = (void *)&nwid;
171 	return ioctl(drv->sock, SIOCS80211NWID, &ifr);
172 #else
173 	return set80211var(drv, IEEE80211_IOC_SSID, ssid, ssid_len);
174 #endif
175 }
176 
177 static int
178 bsd_get_if_media(void *priv)
179 {
180 	struct bsd_driver_data *drv = priv;
181 	struct ifmediareq ifmr;
182 
183 	os_memset(&ifmr, 0, sizeof(ifmr));
184 	os_strlcpy(ifmr.ifm_name, drv->ifname, sizeof(ifmr.ifm_name));
185 
186 	if (ioctl(drv->sock, SIOCGIFMEDIA, &ifmr) < 0) {
187 		wpa_printf(MSG_ERROR, "%s: SIOCGIFMEDIA %s", __func__,
188 			   strerror(errno));
189 		return -1;
190 	}
191 
192 	return ifmr.ifm_current;
193 }
194 
195 static int
196 bsd_set_if_media(void *priv, int media)
197 {
198 	struct bsd_driver_data *drv = priv;
199 	struct ifreq ifr;
200 
201 	os_memset(&ifr, 0, sizeof(ifr));
202 	os_strlcpy(ifr.ifr_name, drv->ifname, sizeof(ifr.ifr_name));
203 	ifr.ifr_media = media;
204 
205 	if (ioctl(drv->sock, SIOCSIFMEDIA, &ifr) < 0) {
206 		wpa_printf(MSG_ERROR, "%s: SIOCSIFMEDIA %s", __func__,
207 			   strerror(errno));
208 		return -1;
209 	}
210 
211 	return 0;
212 }
213 
214 static int
215 bsd_set_mediaopt(void *priv, uint32_t mask, uint32_t mode)
216 {
217 	int media = bsd_get_if_media(priv);
218 
219 	if (media < 0)
220 		return -1;
221 	media &= ~mask;
222 	media |= mode;
223 	if (bsd_set_if_media(priv, media) < 0)
224 		return -1;
225 	return 0;
226 }
227 
228 static int
229 bsd_del_key(void *priv, const u8 *addr, int key_idx)
230 {
231 	struct ieee80211req_del_key wk;
232 
233 	os_memset(&wk, 0, sizeof(wk));
234 	if (addr == NULL) {
235 		wpa_printf(MSG_DEBUG, "%s: key_idx=%d", __func__, key_idx);
236 		wk.idk_keyix = key_idx;
237 	} else {
238 		wpa_printf(MSG_DEBUG, "%s: addr=" MACSTR, __func__,
239 			   MAC2STR(addr));
240 		os_memcpy(wk.idk_macaddr, addr, IEEE80211_ADDR_LEN);
241 		wk.idk_keyix = (u_int8_t) IEEE80211_KEYIX_NONE;	/* XXX */
242 	}
243 
244 	return set80211var(priv, IEEE80211_IOC_DELKEY, &wk, sizeof(wk));
245 }
246 
247 static int
248 bsd_send_mlme_param(void *priv, const u8 op, const u16 reason, const u8 *addr)
249 {
250 	struct ieee80211req_mlme mlme;
251 
252 	os_memset(&mlme, 0, sizeof(mlme));
253 	mlme.im_op = op;
254 	mlme.im_reason = reason;
255 	os_memcpy(mlme.im_macaddr, addr, IEEE80211_ADDR_LEN);
256 	return set80211var(priv, IEEE80211_IOC_MLME, &mlme, sizeof(mlme));
257 }
258 
259 static int
260 bsd_ctrl_iface(void *priv, int enable)
261 {
262 	struct bsd_driver_data *drv = priv;
263 	struct ifreq ifr;
264 
265 	os_memset(&ifr, 0, sizeof(ifr));
266 	os_strlcpy(ifr.ifr_name, drv->ifname, sizeof(ifr.ifr_name));
267 
268 	if (ioctl(drv->sock, SIOCGIFFLAGS, &ifr) < 0) {
269 		perror("ioctl[SIOCGIFFLAGS]");
270 		return -1;
271 	}
272 
273 	if (enable)
274 		ifr.ifr_flags |= IFF_UP;
275 	else
276 		ifr.ifr_flags &= ~IFF_UP;
277 
278 	if (ioctl(drv->sock, SIOCSIFFLAGS, &ifr) < 0) {
279 		perror("ioctl[SIOCSIFFLAGS]");
280 		return -1;
281 	}
282 
283 	return 0;
284 }
285 
286 static int
287 bsd_set_key(const char *ifname, void *priv, enum wpa_alg alg,
288 	    const unsigned char *addr, int key_idx, int set_tx, const u8 *seq,
289 	    size_t seq_len, const u8 *key, size_t key_len)
290 {
291 	struct ieee80211req_key wk;
292 
293 	wpa_printf(MSG_DEBUG, "%s: alg=%d addr=%p key_idx=%d set_tx=%d "
294 		   "seq_len=%zu key_len=%zu", __func__, alg, addr, key_idx,
295 		   set_tx, seq_len, key_len);
296 
297 	if (alg == WPA_ALG_NONE) {
298 #ifndef HOSTAPD
299 		if (addr == NULL ||
300 		    os_memcmp(addr, "\xff\xff\xff\xff\xff\xff",
301 			      IEEE80211_ADDR_LEN) == 0)
302 			return bsd_del_key(priv, NULL, key_idx);
303 		else
304 #endif /* HOSTAPD */
305 			return bsd_del_key(priv, addr, key_idx);
306 	}
307 
308 	os_memset(&wk, 0, sizeof(wk));
309 	switch (alg) {
310 	case WPA_ALG_WEP:
311 		wk.ik_type = IEEE80211_CIPHER_WEP;
312 		break;
313 	case WPA_ALG_TKIP:
314 		wk.ik_type = IEEE80211_CIPHER_TKIP;
315 		break;
316 	case WPA_ALG_CCMP:
317 		wk.ik_type = IEEE80211_CIPHER_AES_CCM;
318 		break;
319 	default:
320 		wpa_printf(MSG_ERROR, "%s: unknown alg=%d", __func__, alg);
321 		return -1;
322 	}
323 
324 	wk.ik_flags = IEEE80211_KEY_RECV;
325 	if (set_tx)
326 		wk.ik_flags |= IEEE80211_KEY_XMIT;
327 
328 	if (addr == NULL) {
329 		os_memset(wk.ik_macaddr, 0xff, IEEE80211_ADDR_LEN);
330 		wk.ik_keyix = key_idx;
331 	} else {
332 		os_memcpy(wk.ik_macaddr, addr, IEEE80211_ADDR_LEN);
333 		/*
334 		 * Deduce whether group/global or unicast key by checking
335 		 * the address (yech).  Note also that we can only mark global
336 		 * keys default; doing this for a unicast key is an error.
337 		 */
338 		if (os_memcmp(addr, "\xff\xff\xff\xff\xff\xff",
339 			      IEEE80211_ADDR_LEN) == 0) {
340 			wk.ik_flags |= IEEE80211_KEY_GROUP;
341 			wk.ik_keyix = key_idx;
342 		} else {
343 			wk.ik_keyix = key_idx == 0 ? IEEE80211_KEYIX_NONE :
344 				key_idx;
345 		}
346 	}
347 	if (wk.ik_keyix != IEEE80211_KEYIX_NONE && set_tx)
348 		wk.ik_flags |= IEEE80211_KEY_DEFAULT;
349 	wk.ik_keylen = key_len;
350 	os_memcpy(&wk.ik_keyrsc, seq, seq_len);
351 	os_memcpy(wk.ik_keydata, key, key_len);
352 
353 	return set80211var(priv, IEEE80211_IOC_WPAKEY, &wk, sizeof(wk));
354 }
355 
356 static int
357 bsd_configure_wpa(void *priv, struct wpa_bss_params *params)
358 {
359 #ifndef IEEE80211_IOC_APPIE
360 	static const char *ciphernames[] =
361 		{ "WEP", "TKIP", "AES-OCB", "AES-CCM", "CKIP", "NONE" };
362 	int v;
363 
364 	switch (params->wpa_group) {
365 	case WPA_CIPHER_CCMP:
366 		v = IEEE80211_CIPHER_AES_CCM;
367 		break;
368 	case WPA_CIPHER_TKIP:
369 		v = IEEE80211_CIPHER_TKIP;
370 		break;
371 	case WPA_CIPHER_WEP104:
372 		v = IEEE80211_CIPHER_WEP;
373 		break;
374 	case WPA_CIPHER_WEP40:
375 		v = IEEE80211_CIPHER_WEP;
376 		break;
377 	case WPA_CIPHER_NONE:
378 		v = IEEE80211_CIPHER_NONE;
379 		break;
380 	default:
381 		printf("Unknown group key cipher %u\n",
382 			params->wpa_group);
383 		return -1;
384 	}
385 	wpa_printf(MSG_DEBUG, "%s: group key cipher=%s (%u)",
386 		   __func__, ciphernames[v], v);
387 	if (set80211param(priv, IEEE80211_IOC_MCASTCIPHER, v)) {
388 		printf("Unable to set group key cipher to %u (%s)\n",
389 			v, ciphernames[v]);
390 		return -1;
391 	}
392 	if (v == IEEE80211_CIPHER_WEP) {
393 		/* key length is done only for specific ciphers */
394 		v = (params->wpa_group == WPA_CIPHER_WEP104 ? 13 : 5);
395 		if (set80211param(priv, IEEE80211_IOC_MCASTKEYLEN, v)) {
396 			printf("Unable to set group key length to %u\n", v);
397 			return -1;
398 		}
399 	}
400 
401 	v = 0;
402 	if (params->wpa_pairwise & WPA_CIPHER_CCMP)
403 		v |= 1<<IEEE80211_CIPHER_AES_CCM;
404 	if (params->wpa_pairwise & WPA_CIPHER_TKIP)
405 		v |= 1<<IEEE80211_CIPHER_TKIP;
406 	if (params->wpa_pairwise & WPA_CIPHER_NONE)
407 		v |= 1<<IEEE80211_CIPHER_NONE;
408 	wpa_printf(MSG_DEBUG, "%s: pairwise key ciphers=0x%x", __func__, v);
409 	if (set80211param(priv, IEEE80211_IOC_UCASTCIPHERS, v)) {
410 		printf("Unable to set pairwise key ciphers to 0x%x\n", v);
411 		return -1;
412 	}
413 
414 	wpa_printf(MSG_DEBUG, "%s: key management algorithms=0x%x",
415 		   __func__, params->wpa_key_mgmt);
416 	if (set80211param(priv, IEEE80211_IOC_KEYMGTALGS,
417 			  params->wpa_key_mgmt)) {
418 		printf("Unable to set key management algorithms to 0x%x\n",
419 			params->wpa_key_mgmt);
420 		return -1;
421 	}
422 
423 	v = 0;
424 	if (params->rsn_preauth)
425 		v |= BIT(0);
426 	wpa_printf(MSG_DEBUG, "%s: rsn capabilities=0x%x",
427 		   __func__, params->rsn_preauth);
428 	if (set80211param(priv, IEEE80211_IOC_RSNCAPS, v)) {
429 		printf("Unable to set RSN capabilities to 0x%x\n", v);
430 		return -1;
431 	}
432 #endif /* IEEE80211_IOC_APPIE */
433 
434 	wpa_printf(MSG_DEBUG, "%s: enable WPA= 0x%x", __func__, params->wpa);
435 	if (set80211param(priv, IEEE80211_IOC_WPA, params->wpa)) {
436 		printf("Unable to set WPA to %u\n", params->wpa);
437 		return -1;
438 	}
439 	return 0;
440 }
441 
442 static int
443 bsd_set_ieee8021x(void *priv, struct wpa_bss_params *params)
444 {
445 	wpa_printf(MSG_DEBUG, "%s: enabled=%d", __func__, params->enabled);
446 
447 	if (!params->enabled) {
448 		/* XXX restore state */
449 		return set80211param(priv, IEEE80211_IOC_AUTHMODE,
450 				     IEEE80211_AUTH_AUTO);
451 	}
452 	if (!params->wpa && !params->ieee802_1x) {
453 		wpa_printf(MSG_ERROR, "%s: No 802.1X or WPA enabled",
454 			   __func__);
455 		return -1;
456 	}
457 	if (params->wpa && bsd_configure_wpa(priv, params) != 0) {
458 		wpa_printf(MSG_ERROR, "%s: Failed to configure WPA state",
459 			   __func__);
460 		return -1;
461 	}
462 	if (set80211param(priv, IEEE80211_IOC_AUTHMODE,
463 		(params->wpa ? IEEE80211_AUTH_WPA : IEEE80211_AUTH_8021X))) {
464 		wpa_printf(MSG_ERROR, "%s: Failed to enable WPA/802.1X",
465 			   __func__);
466 		return -1;
467 	}
468 	return bsd_ctrl_iface(priv, 1);
469 }
470 
471 static int
472 bsd_set_sta_authorized(void *priv, const u8 *addr,
473 		       int total_flags, int flags_or, int flags_and)
474 {
475 	int authorized = -1;
476 
477 	/* For now, only support setting Authorized flag */
478 	if (flags_or & WPA_STA_AUTHORIZED)
479 		authorized = 1;
480 	if (!(flags_and & WPA_STA_AUTHORIZED))
481 		authorized = 0;
482 
483 	if (authorized < 0)
484 		return 0;
485 
486 	return bsd_send_mlme_param(priv, authorized ?
487 				   IEEE80211_MLME_AUTHORIZE :
488 				   IEEE80211_MLME_UNAUTHORIZE, 0, addr);
489 }
490 
491 static void
492 bsd_new_sta(void *priv, void *ctx, u8 addr[IEEE80211_ADDR_LEN])
493 {
494 	struct ieee80211req_wpaie ie;
495 	int ielen = 0;
496 	u8 *iebuf = NULL;
497 
498 	/*
499 	 * Fetch and validate any negotiated WPA/RSN parameters.
500 	 */
501 	memset(&ie, 0, sizeof(ie));
502 	memcpy(ie.wpa_macaddr, addr, IEEE80211_ADDR_LEN);
503 	if (get80211var(priv, IEEE80211_IOC_WPAIE, &ie, sizeof(ie)) < 0) {
504 		printf("Failed to get WPA/RSN information element.\n");
505 		goto no_ie;
506 	}
507 	iebuf = ie.wpa_ie;
508 	ielen = ie.wpa_ie[1];
509 	if (ielen == 0)
510 		iebuf = NULL;
511 	else
512 		ielen += 2;
513 
514 no_ie:
515 	drv_event_assoc(ctx, addr, iebuf, ielen);
516 }
517 
518 static int
519 bsd_send_eapol(void *priv, const u8 *addr, const u8 *data, size_t data_len,
520 	       int encrypt, const u8 *own_addr)
521 {
522 	struct bsd_driver_data *drv = priv;
523 
524 	wpa_hexdump(MSG_MSGDUMP, "TX EAPOL", data, data_len);
525 
526 	return l2_packet_send(drv->sock_xmit, addr, ETH_P_EAPOL, data,
527 			      data_len);
528 }
529 
530 static int
531 bsd_set_freq(void *priv, u16 channel)
532 {
533 	struct bsd_driver_data *drv = priv;
534 #ifdef SIOCS80211CHANNEL
535 	struct ieee80211chanreq creq;
536 #endif /* SIOCS80211CHANNEL */
537 	u32 mode;
538 
539 	if (channel < 14)
540 		mode = IFM_IEEE80211_11G;
541 	else if (channel == 14)
542 		mode = IFM_IEEE80211_11B;
543 	else
544 		mode = IFM_IEEE80211_11A;
545 	if (bsd_set_mediaopt(drv, IFM_MMASK, mode) < 0) {
546 		wpa_printf(MSG_ERROR, "%s: failed to set modulation mode",
547 			   __func__);
548 		return -1;
549 	}
550 
551 #ifdef SIOCS80211CHANNEL
552 	os_memset(&creq, 0, sizeof(creq));
553 	os_strlcpy(creq.i_name, drv->ifname, sizeof(creq.i_name));
554 	creq.i_channel = channel;
555 	return ioctl(drv->sock, SIOCS80211CHANNEL, &creq);
556 #else /* SIOCS80211CHANNEL */
557 	return set80211param(priv, IEEE80211_IOC_CHANNEL, channel);
558 #endif /* SIOCS80211CHANNEL */
559 }
560 
561 static int
562 bsd_set_opt_ie(void *priv, const u8 *ie, size_t ie_len)
563 {
564 #ifdef IEEE80211_IOC_APPIE
565 	wpa_printf(MSG_DEBUG, "%s: set WPA+RSN ie (len %lu)", __func__,
566 		   (unsigned long)ie_len);
567 	return bsd_set80211(priv, IEEE80211_IOC_APPIE, IEEE80211_APPIE_WPA,
568 			    ie, ie_len);
569 #endif /* IEEE80211_IOC_APPIE */
570 	return 0;
571 }
572 
573 
574 #ifdef HOSTAPD
575 
576 /*
577  * Avoid conflicts with hostapd definitions by undefining couple of defines
578  * from net80211 header files.
579  */
580 #undef RSN_VERSION
581 #undef WPA_VERSION
582 #undef WPA_OUI_TYPE
583 
584 static int bsd_sta_deauth(void *priv, const u8 *own_addr, const u8 *addr,
585 			  int reason_code);
586 
587 static const char *
588 ether_sprintf(const u8 *addr)
589 {
590 	static char buf[sizeof(MACSTR)];
591 
592 	if (addr != NULL)
593 		snprintf(buf, sizeof(buf), MACSTR, MAC2STR(addr));
594 	else
595 		snprintf(buf, sizeof(buf), MACSTR, 0,0,0,0,0,0);
596 	return buf;
597 }
598 
599 static int
600 bsd_set_privacy(void *priv, int enabled)
601 {
602 	wpa_printf(MSG_DEBUG, "%s: enabled=%d", __func__, enabled);
603 
604 	return set80211param(priv, IEEE80211_IOC_PRIVACY, enabled);
605 }
606 
607 static int
608 bsd_get_seqnum(const char *ifname, void *priv, const u8 *addr, int idx,
609 	       u8 *seq)
610 {
611 	struct ieee80211req_key wk;
612 
613 	wpa_printf(MSG_DEBUG, "%s: addr=%s idx=%d",
614 		   __func__, ether_sprintf(addr), idx);
615 
616 	memset(&wk, 0, sizeof(wk));
617 	if (addr == NULL)
618 		memset(wk.ik_macaddr, 0xff, IEEE80211_ADDR_LEN);
619 	else
620 		memcpy(wk.ik_macaddr, addr, IEEE80211_ADDR_LEN);
621 	wk.ik_keyix = idx;
622 
623 	if (get80211var(priv, IEEE80211_IOC_WPAKEY, &wk, sizeof(wk)) < 0) {
624 		printf("Failed to get encryption.\n");
625 		return -1;
626 	}
627 
628 #ifdef WORDS_BIGENDIAN
629 #ifndef WPA_KEY_RSC_LEN
630 #define WPA_KEY_RSC_LEN 8
631 #endif
632 	{
633 		/*
634 		 * wk.ik_keytsc is in host byte order (big endian), need to
635 		 * swap it to match with the byte order used in WPA.
636 		 */
637 		int i;
638 		u8 tmp[WPA_KEY_RSC_LEN];
639 		memcpy(tmp, &wk.ik_keytsc, sizeof(wk.ik_keytsc));
640 		for (i = 0; i < WPA_KEY_RSC_LEN; i++) {
641 			seq[i] = tmp[WPA_KEY_RSC_LEN - i - 1];
642 		}
643 	}
644 #else /* WORDS_BIGENDIAN */
645 	memcpy(seq, &wk.ik_keytsc, sizeof(wk.ik_keytsc));
646 #endif /* WORDS_BIGENDIAN */
647 	return 0;
648 }
649 
650 
651 static int
652 bsd_flush(void *priv)
653 {
654 	u8 allsta[IEEE80211_ADDR_LEN];
655 
656 	memset(allsta, 0xff, IEEE80211_ADDR_LEN);
657 	return bsd_sta_deauth(priv, NULL, allsta, IEEE80211_REASON_AUTH_LEAVE);
658 }
659 
660 
661 static int
662 bsd_read_sta_driver_data(void *priv, struct hostap_sta_driver_data *data,
663 			 const u8 *addr)
664 {
665 	struct ieee80211req_sta_stats stats;
666 
667 	memcpy(stats.is_u.macaddr, addr, IEEE80211_ADDR_LEN);
668 	if (get80211var(priv, IEEE80211_IOC_STA_STATS, &stats, sizeof(stats))
669 	    > 0) {
670 		/* XXX? do packets counts include non-data frames? */
671 		data->rx_packets = stats.is_stats.ns_rx_data;
672 		data->rx_bytes = stats.is_stats.ns_rx_bytes;
673 		data->tx_packets = stats.is_stats.ns_tx_data;
674 		data->tx_bytes = stats.is_stats.ns_tx_bytes;
675 	}
676 	return 0;
677 }
678 
679 static int
680 bsd_sta_deauth(void *priv, const u8 *own_addr, const u8 *addr, int reason_code)
681 {
682 	return bsd_send_mlme_param(priv, IEEE80211_MLME_DEAUTH, reason_code,
683 				   addr);
684 }
685 
686 static int
687 bsd_sta_disassoc(void *priv, const u8 *own_addr, const u8 *addr,
688 		 int reason_code)
689 {
690 	return bsd_send_mlme_param(priv, IEEE80211_MLME_DISASSOC, reason_code,
691 				   addr);
692 }
693 
694 static void
695 bsd_wireless_event_receive(int sock, void *ctx, void *sock_ctx)
696 {
697 	struct bsd_driver_data *drv = ctx;
698 	char buf[2048];
699 	struct if_announcemsghdr *ifan;
700 	struct rt_msghdr *rtm;
701 	struct ieee80211_michael_event *mic;
702 	struct ieee80211_join_event *join;
703 	struct ieee80211_leave_event *leave;
704 	int n;
705 	union wpa_event_data data;
706 
707 	n = read(sock, buf, sizeof(buf));
708 	if (n < 0) {
709 		if (errno != EINTR && errno != EAGAIN)
710 			perror("read(PF_ROUTE)");
711 		return;
712 	}
713 
714 	rtm = (struct rt_msghdr *) buf;
715 	if (rtm->rtm_version != RTM_VERSION) {
716 		wpa_printf(MSG_DEBUG, "Routing message version %d not "
717 			"understood\n", rtm->rtm_version);
718 		return;
719 	}
720 	ifan = (struct if_announcemsghdr *) rtm;
721 	switch (rtm->rtm_type) {
722 	case RTM_IEEE80211:
723 		switch (ifan->ifan_what) {
724 		case RTM_IEEE80211_ASSOC:
725 		case RTM_IEEE80211_REASSOC:
726 		case RTM_IEEE80211_DISASSOC:
727 		case RTM_IEEE80211_SCAN:
728 			break;
729 		case RTM_IEEE80211_LEAVE:
730 			leave = (struct ieee80211_leave_event *) &ifan[1];
731 			drv_event_disassoc(drv->hapd, leave->iev_addr);
732 			break;
733 		case RTM_IEEE80211_JOIN:
734 #ifdef RTM_IEEE80211_REJOIN
735 		case RTM_IEEE80211_REJOIN:
736 #endif
737 			join = (struct ieee80211_join_event *) &ifan[1];
738 			bsd_new_sta(drv, drv->hapd, join->iev_addr);
739 			break;
740 		case RTM_IEEE80211_REPLAY:
741 			/* ignore */
742 			break;
743 		case RTM_IEEE80211_MICHAEL:
744 			mic = (struct ieee80211_michael_event *) &ifan[1];
745 			wpa_printf(MSG_DEBUG,
746 				"Michael MIC failure wireless event: "
747 				"keyix=%u src_addr=" MACSTR, mic->iev_keyix,
748 				MAC2STR(mic->iev_src));
749 			os_memset(&data, 0, sizeof(data));
750 			data.michael_mic_failure.unicast = 1;
751 			data.michael_mic_failure.src = mic->iev_src;
752 			wpa_supplicant_event(drv->hapd,
753 					     EVENT_MICHAEL_MIC_FAILURE, &data);
754 			break;
755 		}
756 		break;
757 	}
758 }
759 
760 static void
761 handle_read(void *ctx, const u8 *src_addr, const u8 *buf, size_t len)
762 {
763 	struct bsd_driver_data *drv = ctx;
764 	drv_event_eapol_rx(drv->hapd, src_addr, buf, len);
765 }
766 
767 static int
768 hostapd_bsd_set_freq(void *priv, struct hostapd_freq_params *freq)
769 {
770 	return bsd_set_freq(priv, freq->channel);
771 }
772 
773 static void *
774 bsd_init(struct hostapd_data *hapd, struct wpa_init_params *params)
775 {
776 	struct bsd_driver_data *drv;
777 
778 	drv = os_zalloc(sizeof(struct bsd_driver_data));
779 	if (drv == NULL) {
780 		printf("Could not allocate memory for bsd driver data\n");
781 		goto bad;
782 	}
783 
784 	drv->hapd = hapd;
785 	drv->sock = socket(PF_INET, SOCK_DGRAM, 0);
786 	if (drv->sock < 0) {
787 		perror("socket[PF_INET,SOCK_DGRAM]");
788 		goto bad;
789 	}
790 	os_strlcpy(drv->ifname, params->ifname, sizeof(drv->ifname));
791 
792 	drv->sock_xmit = l2_packet_init(drv->ifname, NULL, ETH_P_EAPOL,
793 					handle_read, drv, 0);
794 	if (drv->sock_xmit == NULL)
795 		goto bad;
796 	if (l2_packet_get_own_addr(drv->sock_xmit, params->own_addr))
797 		goto bad;
798 
799 	/* mark down during setup */
800 	if (bsd_ctrl_iface(drv, 0) < 0)
801 		goto bad;
802 
803 	drv->route = socket(PF_ROUTE, SOCK_RAW, 0);
804 	if (drv->route < 0) {
805 		perror("socket(PF_ROUTE,SOCK_RAW)");
806 		goto bad;
807 	}
808 	eloop_register_read_sock(drv->route, bsd_wireless_event_receive, drv,
809 				 NULL);
810 
811 	if (bsd_set_mediaopt(drv, IFM_OMASK, IFM_IEEE80211_HOSTAP) < 0) {
812 		wpa_printf(MSG_ERROR, "%s: failed to set operation mode",
813 			   __func__);
814 		goto bad;
815 	}
816 
817 	return drv;
818 bad:
819 	if (drv->sock_xmit != NULL)
820 		l2_packet_deinit(drv->sock_xmit);
821 	if (drv->sock >= 0)
822 		close(drv->sock);
823 	if (drv != NULL)
824 		os_free(drv);
825 	return NULL;
826 }
827 
828 
829 static void
830 bsd_deinit(void *priv)
831 {
832 	struct bsd_driver_data *drv = priv;
833 
834 	if (drv->route >= 0) {
835 		eloop_unregister_read_sock(drv->route);
836 		close(drv->route);
837 	}
838 	bsd_ctrl_iface(drv, 0);
839 	if (drv->sock >= 0)
840 		close(drv->sock);
841 	if (drv->sock_xmit != NULL)
842 		l2_packet_deinit(drv->sock_xmit);
843 	os_free(drv);
844 }
845 
846 #else /* HOSTAPD */
847 
848 static int
849 get80211param(struct bsd_driver_data *drv, int op)
850 {
851 	struct ieee80211req ireq;
852 
853 	if (bsd_get80211(drv, &ireq, op, NULL, 0) < 0)
854 		return -1;
855 	return ireq.i_val;
856 }
857 
858 static int
859 wpa_driver_bsd_get_bssid(void *priv, u8 *bssid)
860 {
861 	struct bsd_driver_data *drv = priv;
862 #ifdef SIOCG80211BSSID
863 	struct ieee80211_bssid bs;
864 
865 	os_strlcpy(bs.i_name, drv->ifname, sizeof(bs.i_name));
866 	if (ioctl(drv->sock, SIOCG80211BSSID, &bs) < 0)
867 		return -1;
868 	os_memcpy(bssid, bs.i_bssid, sizeof(bs.i_bssid));
869 	return 0;
870 #else
871 	return get80211var(drv, IEEE80211_IOC_BSSID,
872 		bssid, IEEE80211_ADDR_LEN) < 0 ? -1 : 0;
873 #endif
874 }
875 
876 static int
877 wpa_driver_bsd_get_ssid(void *priv, u8 *ssid)
878 {
879 	struct bsd_driver_data *drv = priv;
880 	return bsd_get_ssid(drv, ssid, 0);
881 }
882 
883 static int
884 wpa_driver_bsd_set_wpa_ie(struct bsd_driver_data *drv, const u8 *wpa_ie,
885 			  size_t wpa_ie_len)
886 {
887 #ifdef IEEE80211_IOC_APPIE
888 	return bsd_set_opt_ie(drv, wpa_ie, wpa_ie_len);
889 #else /* IEEE80211_IOC_APPIE */
890 	return set80211var(drv, IEEE80211_IOC_OPTIE, wpa_ie, wpa_ie_len);
891 #endif /* IEEE80211_IOC_APPIE */
892 }
893 
894 static int
895 wpa_driver_bsd_set_wpa_internal(void *priv, int wpa, int privacy)
896 {
897 	int ret = 0;
898 
899 	wpa_printf(MSG_DEBUG, "%s: wpa=%d privacy=%d",
900 		__func__, wpa, privacy);
901 
902 	if (!wpa && wpa_driver_bsd_set_wpa_ie(priv, NULL, 0) < 0)
903 		ret = -1;
904 	if (set80211param(priv, IEEE80211_IOC_PRIVACY, privacy) < 0)
905 		ret = -1;
906 	if (set80211param(priv, IEEE80211_IOC_WPA, wpa) < 0)
907 		ret = -1;
908 
909 	return ret;
910 }
911 
912 static int
913 wpa_driver_bsd_set_wpa(void *priv, int enabled)
914 {
915 	wpa_printf(MSG_DEBUG, "%s: enabled=%d", __func__, enabled);
916 
917 	return wpa_driver_bsd_set_wpa_internal(priv, enabled ? 3 : 0, enabled);
918 }
919 
920 static int
921 wpa_driver_bsd_set_countermeasures(void *priv, int enabled)
922 {
923 	wpa_printf(MSG_DEBUG, "%s: enabled=%d", __func__, enabled);
924 	return set80211param(priv, IEEE80211_IOC_COUNTERMEASURES, enabled);
925 }
926 
927 
928 static int
929 wpa_driver_bsd_set_drop_unencrypted(void *priv, int enabled)
930 {
931 	wpa_printf(MSG_DEBUG, "%s: enabled=%d", __func__, enabled);
932 	return set80211param(priv, IEEE80211_IOC_DROPUNENCRYPTED, enabled);
933 }
934 
935 static int
936 wpa_driver_bsd_deauthenticate(void *priv, const u8 *addr, int reason_code)
937 {
938 	return bsd_send_mlme_param(priv, IEEE80211_MLME_DEAUTH, reason_code,
939 				   addr);
940 }
941 
942 static int
943 wpa_driver_bsd_disassociate(void *priv, const u8 *addr, int reason_code)
944 {
945 	return bsd_send_mlme_param(priv, IEEE80211_MLME_DISASSOC, reason_code,
946 				   addr);
947 }
948 
949 static int
950 wpa_driver_bsd_set_auth_alg(void *priv, int auth_alg)
951 {
952 	int authmode;
953 
954 	if ((auth_alg & WPA_AUTH_ALG_OPEN) &&
955 	    (auth_alg & WPA_AUTH_ALG_SHARED))
956 		authmode = IEEE80211_AUTH_AUTO;
957 	else if (auth_alg & WPA_AUTH_ALG_SHARED)
958 		authmode = IEEE80211_AUTH_SHARED;
959 	else
960 		authmode = IEEE80211_AUTH_OPEN;
961 
962 	return set80211param(priv, IEEE80211_IOC_AUTHMODE, authmode);
963 }
964 
965 static void
966 handle_read(void *ctx, const u8 *src_addr, const u8 *buf, size_t len)
967 {
968 	struct bsd_driver_data *drv = ctx;
969 
970 	drv_event_eapol_rx(drv->ctx, src_addr, buf, len);
971 }
972 
973 static int
974 wpa_driver_bsd_associate(void *priv, struct wpa_driver_associate_params *params)
975 {
976 	struct bsd_driver_data *drv = priv;
977 	struct ieee80211req_mlme mlme;
978 	u32 mode;
979 	u16 channel;
980 	int privacy;
981 	int ret = 0;
982 
983 	wpa_printf(MSG_DEBUG,
984 		"%s: ssid '%.*s' wpa ie len %u pairwise %u group %u key mgmt %u"
985 		, __func__
986 		   , (unsigned int) params->ssid_len, params->ssid
987 		, (unsigned int) params->wpa_ie_len
988 		, params->pairwise_suite
989 		, params->group_suite
990 		, params->key_mgmt_suite
991 	);
992 
993 	switch (params->mode) {
994 	case IEEE80211_MODE_INFRA:
995 		mode = 0 /* STA */;
996 		break;
997 	case IEEE80211_MODE_IBSS:
998 		mode = IFM_IEEE80211_IBSS;
999 		break;
1000 	case IEEE80211_MODE_AP:
1001 		mode = IFM_IEEE80211_HOSTAP;
1002 		break;
1003 	default:
1004 		wpa_printf(MSG_ERROR, "%s: unknown operation mode", __func__);
1005 		return -1;
1006 	}
1007 	if (bsd_set_mediaopt(drv, IFM_OMASK, mode) < 0) {
1008 		wpa_printf(MSG_ERROR, "%s: failed to set operation mode",
1009 			   __func__);
1010 		return -1;
1011 	}
1012 
1013 	if (params->mode == IEEE80211_MODE_AP) {
1014 		if (params->freq >= 2412 && params->freq <= 2472)
1015 			channel = (params->freq - 2407) / 5;
1016 		else if (params->freq == 2484)
1017 			channel = 14;
1018 		else if ((params->freq >= 5180 && params->freq <= 5240) ||
1019 			 (params->freq >= 5745 && params->freq <= 5825))
1020 			channel = (params->freq - 5000) / 5;
1021 		else
1022 			channel = 0;
1023 		if (bsd_set_freq(drv, channel) < 0)
1024 			return -1;
1025 
1026 		drv->sock_xmit = l2_packet_init(drv->ifname, NULL, ETH_P_EAPOL,
1027 						handle_read, drv, 0);
1028 		if (drv->sock_xmit == NULL)
1029 			return -1;
1030 		drv->is_ap = 1;
1031 		return 0;
1032 	}
1033 
1034 	if (wpa_driver_bsd_set_drop_unencrypted(drv, params->drop_unencrypted)
1035 	    < 0)
1036 		ret = -1;
1037 	if (wpa_driver_bsd_set_auth_alg(drv, params->auth_alg) < 0)
1038 		ret = -1;
1039 	/* XXX error handling is wrong but unclear what to do... */
1040 	if (wpa_driver_bsd_set_wpa_ie(drv, params->wpa_ie, params->wpa_ie_len) < 0)
1041 		return -1;
1042 
1043 	privacy = !(params->pairwise_suite == CIPHER_NONE &&
1044 	    params->group_suite == CIPHER_NONE &&
1045 	    params->key_mgmt_suite == KEY_MGMT_NONE &&
1046 	    params->wpa_ie_len == 0);
1047 	wpa_printf(MSG_DEBUG, "%s: set PRIVACY %u", __func__, privacy);
1048 
1049 	if (set80211param(drv, IEEE80211_IOC_PRIVACY, privacy) < 0)
1050 		return -1;
1051 
1052 	if (params->wpa_ie_len &&
1053 	    set80211param(drv, IEEE80211_IOC_WPA,
1054 			  params->wpa_ie[0] == WLAN_EID_RSN ? 2 : 1) < 0)
1055 		return -1;
1056 
1057 	os_memset(&mlme, 0, sizeof(mlme));
1058 	mlme.im_op = IEEE80211_MLME_ASSOC;
1059 	if (params->ssid != NULL)
1060 		os_memcpy(mlme.im_ssid, params->ssid, params->ssid_len);
1061 	mlme.im_ssid_len = params->ssid_len;
1062 	if (params->bssid != NULL)
1063 		os_memcpy(mlme.im_macaddr, params->bssid, IEEE80211_ADDR_LEN);
1064 	if (set80211var(drv, IEEE80211_IOC_MLME, &mlme, sizeof(mlme)) < 0)
1065 		return -1;
1066 	return ret;
1067 }
1068 
1069 static int
1070 wpa_driver_bsd_scan(void *priv, struct wpa_driver_scan_params *params)
1071 {
1072 	struct bsd_driver_data *drv = priv;
1073 #ifdef IEEE80211_IOC_SCAN_MAX_SSID
1074 	struct ieee80211_scan_req sr;
1075 	int i;
1076 #endif /* IEEE80211_IOC_SCAN_MAX_SSID */
1077 
1078 	if (bsd_set_mediaopt(drv, IFM_OMASK, 0 /* STA */) < 0) {
1079 		wpa_printf(MSG_ERROR, "%s: failed to set operation mode",
1080 			   __func__);
1081 		return -1;
1082 	}
1083 
1084 	if (set80211param(drv, IEEE80211_IOC_ROAMING,
1085 			  IEEE80211_ROAMING_MANUAL) < 0) {
1086 		wpa_printf(MSG_ERROR, "%s: failed to set "
1087 			   "wpa_supplicant-based roaming: %s", __func__,
1088 			   strerror(errno));
1089 		return -1;
1090 	}
1091 
1092 	if (wpa_driver_bsd_set_wpa(drv, 1) < 0) {
1093 		wpa_printf(MSG_ERROR, "%s: failed to set wpa: %s", __func__,
1094 			   strerror(errno));
1095 		return -1;
1096 	}
1097 
1098 	/* NB: interface must be marked UP to do a scan */
1099 	if (bsd_ctrl_iface(drv, 1) < 0)
1100 		return -1;
1101 
1102 #ifdef IEEE80211_IOC_SCAN_MAX_SSID
1103 	os_memset(&sr, 0, sizeof(sr));
1104 	sr.sr_flags = IEEE80211_IOC_SCAN_ACTIVE | IEEE80211_IOC_SCAN_ONCE |
1105 		IEEE80211_IOC_SCAN_NOJOIN;
1106 	sr.sr_duration = IEEE80211_IOC_SCAN_FOREVER;
1107 	if (params->num_ssids > 0) {
1108 		sr.sr_nssid = params->num_ssids;
1109 #if 0
1110 		/* Boundary check is done by upper layer */
1111 		if (sr.sr_nssid > IEEE80211_IOC_SCAN_MAX_SSID)
1112 			sr.sr_nssid = IEEE80211_IOC_SCAN_MAX_SSID;
1113 #endif
1114 
1115 		/* NB: check scan cache first */
1116 		sr.sr_flags |= IEEE80211_IOC_SCAN_CHECK;
1117 	}
1118 	for (i = 0; i < sr.sr_nssid; i++) {
1119 		sr.sr_ssid[i].len = params->ssids[i].ssid_len;
1120 		os_memcpy(sr.sr_ssid[i].ssid, params->ssids[i].ssid,
1121 			  sr.sr_ssid[i].len);
1122 	}
1123 
1124 	/* NB: net80211 delivers a scan complete event so no need to poll */
1125 	return set80211var(drv, IEEE80211_IOC_SCAN_REQ, &sr, sizeof(sr));
1126 #else /* IEEE80211_IOC_SCAN_MAX_SSID */
1127 	/* set desired ssid before scan */
1128 	if (bsd_set_ssid(drv, params->ssids[0].ssid,
1129 			 params->ssids[0].ssid_len) < 0)
1130 		return -1;
1131 
1132 	/* NB: net80211 delivers a scan complete event so no need to poll */
1133 	return set80211param(drv, IEEE80211_IOC_SCAN_REQ, 0);
1134 #endif /* IEEE80211_IOC_SCAN_MAX_SSID */
1135 }
1136 
1137 static void
1138 wpa_driver_bsd_event_receive(int sock, void *ctx, void *sock_ctx)
1139 {
1140 	struct bsd_driver_data *drv = sock_ctx;
1141 	char buf[2048];
1142 	struct if_announcemsghdr *ifan;
1143 	struct if_msghdr *ifm;
1144 	struct rt_msghdr *rtm;
1145 	union wpa_event_data event;
1146 	struct ieee80211_michael_event *mic;
1147 	struct ieee80211_leave_event *leave;
1148 	struct ieee80211_join_event *join;
1149 	int n;
1150 
1151 	n = read(sock, buf, sizeof(buf));
1152 	if (n < 0) {
1153 		if (errno != EINTR && errno != EAGAIN)
1154 			perror("read(PF_ROUTE)");
1155 		return;
1156 	}
1157 
1158 	rtm = (struct rt_msghdr *) buf;
1159 	if (rtm->rtm_version != RTM_VERSION) {
1160 		wpa_printf(MSG_DEBUG, "Routing message version %d not "
1161 			"understood\n", rtm->rtm_version);
1162 		return;
1163 	}
1164 	os_memset(&event, 0, sizeof(event));
1165 	switch (rtm->rtm_type) {
1166 	case RTM_IFANNOUNCE:
1167 		ifan = (struct if_announcemsghdr *) rtm;
1168 		if (ifan->ifan_index != drv->ifindex)
1169 			break;
1170 		os_strlcpy(event.interface_status.ifname, drv->ifname,
1171 			   sizeof(event.interface_status.ifname));
1172 		switch (ifan->ifan_what) {
1173 		case IFAN_DEPARTURE:
1174 			event.interface_status.ievent = EVENT_INTERFACE_REMOVED;
1175 		default:
1176 			event.interface_status.ievent = EVENT_INTERFACE_ADDED;
1177 			break;
1178 		}
1179 		wpa_printf(MSG_DEBUG, "RTM_IFANNOUNCE: Interface '%s' %s (%d)",
1180 			   event.interface_status.ifname,
1181 			   ifan->ifan_what == IFAN_DEPARTURE ?
1182 				"removed" : "added", ifan->ifan_what);
1183 		wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &event);
1184 		return;
1185 	case RTM_IEEE80211:
1186 		ifan = (struct if_announcemsghdr *) rtm;
1187 		if (ifan->ifan_index != drv->ifindex)
1188 			break;
1189 		switch (ifan->ifan_what) {
1190 		case RTM_IEEE80211_ASSOC:
1191 		case RTM_IEEE80211_REASSOC:
1192 			if (drv->is_ap)
1193 				break;
1194 			wpa_printf(MSG_DEBUG, "RTM_IEEE80211: (re)assoc (%d)",
1195 			    ifan->ifan_what);
1196 			wpa_supplicant_event(ctx, EVENT_ASSOC, NULL);
1197 			break;
1198 		case RTM_IEEE80211_DISASSOC:
1199 			if (drv->is_ap)
1200 				break;
1201 			wpa_printf(MSG_DEBUG, "RTM_IEEE80211: disassoc (%d)",
1202 			    ifan->ifan_what);
1203 			wpa_supplicant_event(ctx, EVENT_DISASSOC, NULL);
1204 			break;
1205 		case RTM_IEEE80211_SCAN:
1206 			if (drv->is_ap)
1207 				break;
1208 			wpa_printf(MSG_DEBUG, "RTM_IEEE80211: scan result (%d)",
1209 			    ifan->ifan_what);
1210 			wpa_supplicant_event(ctx, EVENT_SCAN_RESULTS, NULL);
1211 			break;
1212 		case RTM_IEEE80211_LEAVE:
1213 			leave = (struct ieee80211_leave_event *) &ifan[1];
1214 			drv_event_disassoc(ctx, leave->iev_addr);
1215 			break;
1216 		case RTM_IEEE80211_JOIN:
1217 #ifdef RTM_IEEE80211_REJOIN
1218 		case RTM_IEEE80211_REJOIN:
1219 #endif
1220 			join = (struct ieee80211_join_event *) &ifan[1];
1221 			bsd_new_sta(drv, ctx, join->iev_addr);
1222 			break;
1223 		case RTM_IEEE80211_REPLAY:
1224 			wpa_printf(MSG_DEBUG, "RTM_IEEE80211: replay (%d)",
1225 			    ifan->ifan_what);
1226 			/* ignore */
1227 			break;
1228 		case RTM_IEEE80211_MICHAEL:
1229 			mic = (struct ieee80211_michael_event *) &ifan[1];
1230 			wpa_printf(MSG_DEBUG,
1231 				"Michael MIC failure wireless event: "
1232 				"keyix=%u src_addr=" MACSTR, mic->iev_keyix,
1233 				MAC2STR(mic->iev_src));
1234 
1235 			os_memset(&event, 0, sizeof(event));
1236 			event.michael_mic_failure.unicast =
1237 				!IEEE80211_IS_MULTICAST(mic->iev_dst);
1238 			wpa_supplicant_event(ctx, EVENT_MICHAEL_MIC_FAILURE,
1239 				&event);
1240 			break;
1241 		default:
1242 			wpa_printf(MSG_DEBUG, "RTM_IEEE80211: ??? (%d)",
1243 			    ifan->ifan_what);
1244 			break;
1245 		}
1246 		break;
1247 	case RTM_IFINFO:
1248 		ifm = (struct if_msghdr *) rtm;
1249 		if (ifm->ifm_index != drv->ifindex)
1250 			break;
1251 		if ((ifm->ifm_flags & IFF_UP) == 0 &&
1252 		    (drv->flags & IFF_UP) != 0) {
1253 			os_strlcpy(event.interface_status.ifname, drv->ifname,
1254 				   sizeof(event.interface_status.ifname));
1255 			event.interface_status.ievent = EVENT_INTERFACE_REMOVED;
1256 			wpa_printf(MSG_DEBUG, "RTM_IFINFO: Interface '%s' DOWN",
1257 				   event.interface_status.ifname);
1258 			wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &event);
1259 		} else if ((ifm->ifm_flags & IFF_UP) != 0 &&
1260 		    (drv->flags & IFF_UP) == 0) {
1261 			strlcpy(event.interface_status.ifname, drv->ifname,
1262 				sizeof(event.interface_status.ifname));
1263 			event.interface_status.ievent = EVENT_INTERFACE_ADDED;
1264 			wpa_printf(MSG_DEBUG, "RTM_IFINFO: Interface '%s' UP",
1265 				   event.interface_status.ifname);
1266 			wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &event);
1267 		} else {
1268 			wpa_printf(MSG_DEBUG, "RTM_IFINFO: Interface '%s' "
1269 			    "if=%x drv=%x", event.interface_status.ifname,
1270 			    ifm->ifm_flags, drv->flags);
1271  		}
1272 		drv->flags = ifm->ifm_flags;
1273 		break;
1274 	case RTM_LOSING:
1275 		wpa_printf(MSG_DEBUG, "RTM_LOSING: %d", rtm->rtm_type);
1276 		break;
1277 	default:
1278 		wpa_printf(MSG_DEBUG, "RTM_???: %d", rtm->rtm_type);
1279 		break;
1280 	}
1281 }
1282 
1283 static void
1284 wpa_driver_bsd_add_scan_entry(struct wpa_scan_results *res,
1285 			      struct ieee80211req_scan_result *sr)
1286 {
1287 	struct wpa_scan_res *result, **tmp;
1288 	size_t extra_len;
1289 	u8 *pos;
1290 
1291 	extra_len = 2 + sr->isr_ssid_len;
1292 	extra_len += 2 + sr->isr_nrates;
1293 	extra_len += 3; /* ERP IE */
1294 	extra_len += sr->isr_ie_len;
1295 
1296 	result = os_zalloc(sizeof(*result) + extra_len);
1297 	if (result == NULL)
1298 		return;
1299 	os_memcpy(result->bssid, sr->isr_bssid, ETH_ALEN);
1300 	result->freq = sr->isr_freq;
1301 	result->beacon_int = sr->isr_intval;
1302 	result->caps = sr->isr_capinfo;
1303 	result->qual = sr->isr_rssi;
1304 	result->noise = sr->isr_noise;
1305 
1306 	pos = (u8 *)(result + 1);
1307 
1308 	*pos++ = WLAN_EID_SSID;
1309 	*pos++ = sr->isr_ssid_len;
1310 	os_memcpy(pos, sr + 1, sr->isr_ssid_len);
1311 	pos += sr->isr_ssid_len;
1312 
1313 	/*
1314 	 * Deal all rates as supported rate.
1315 	 * Because net80211 doesn't report extended supported rate or not.
1316 	 */
1317 	*pos++ = WLAN_EID_SUPP_RATES;
1318 	*pos++ = sr->isr_nrates;
1319 	os_memcpy(pos, sr->isr_rates, sr->isr_nrates);
1320 	pos += sr->isr_nrates;
1321 
1322 	*pos++ = WLAN_EID_ERP_INFO;
1323 	*pos++ = 1;
1324 	*pos++ = sr->isr_erp;
1325 
1326 	os_memcpy(pos, (u8 *)(sr + 1) + sr->isr_ssid_len, sr->isr_ie_len);
1327 	pos += sr->isr_ie_len;
1328 
1329 	result->ie_len = pos - (u8 *)(result + 1);
1330 
1331 	tmp = os_realloc(res->res,
1332 			 (res->num + 1) * sizeof(struct wpa_scan_res *));
1333 	if (tmp == NULL) {
1334 		os_free(result);
1335 		return;
1336 	}
1337 	tmp[res->num++] = result;
1338 	res->res = tmp;
1339 }
1340 
1341 struct wpa_scan_results *
1342 wpa_driver_bsd_get_scan_results2(void *priv)
1343 {
1344 	struct ieee80211req_scan_result *sr;
1345 	struct wpa_scan_results *res;
1346 	int len, rest;
1347 	uint8_t buf[24*1024], *pos;
1348 
1349 	len = get80211var(priv, IEEE80211_IOC_SCAN_RESULTS, buf, 24*1024);
1350 	if (len < 0)
1351 		return NULL;
1352 
1353 	res = os_zalloc(sizeof(*res));
1354 	if (res == NULL)
1355 		return NULL;
1356 
1357 	pos = buf;
1358 	rest = len;
1359 	while (rest >= sizeof(struct ieee80211req_scan_result)) {
1360 		sr = (struct ieee80211req_scan_result *)pos;
1361 		wpa_driver_bsd_add_scan_entry(res, sr);
1362 		pos += sr->isr_len;
1363 		rest -= sr->isr_len;
1364 	}
1365 
1366 	wpa_printf(MSG_DEBUG, "Received %d bytes of scan results (%lu BSSes)",
1367 		   len, (unsigned long)res->num);
1368 
1369 	return res;
1370 }
1371 
1372 static int wpa_driver_bsd_capa(struct bsd_driver_data *drv)
1373 {
1374 #ifdef IEEE80211_IOC_DEVCAPS
1375 /* kernel definitions copied from net80211/ieee80211_var.h */
1376 #define IEEE80211_CIPHER_WEP            0
1377 #define IEEE80211_CIPHER_TKIP           1
1378 #define IEEE80211_CIPHER_AES_CCM        3
1379 #define IEEE80211_CRYPTO_WEP            (1<<IEEE80211_CIPHER_WEP)
1380 #define IEEE80211_CRYPTO_TKIP           (1<<IEEE80211_CIPHER_TKIP)
1381 #define IEEE80211_CRYPTO_AES_CCM        (1<<IEEE80211_CIPHER_AES_CCM)
1382 #define IEEE80211_C_HOSTAP      0x00000400      /* CAPABILITY: HOSTAP avail */
1383 #define IEEE80211_C_WPA1        0x00800000      /* CAPABILITY: WPA1 avail */
1384 #define IEEE80211_C_WPA2        0x01000000      /* CAPABILITY: WPA2 avail */
1385 	struct ieee80211_devcaps_req devcaps;
1386 
1387 	if (get80211var(drv, IEEE80211_IOC_DEVCAPS, &devcaps,
1388 			sizeof(devcaps)) < 0) {
1389 		wpa_printf(MSG_ERROR, "failed to IEEE80211_IOC_DEVCAPS: %s",
1390 			   strerror(errno));
1391 		return -1;
1392 	}
1393 
1394 	wpa_printf(MSG_DEBUG, "%s: drivercaps=0x%08x,cryptocaps=0x%08x",
1395 		   __func__, devcaps.dc_drivercaps, devcaps.dc_cryptocaps);
1396 
1397 	if (devcaps.dc_drivercaps & IEEE80211_C_WPA1)
1398 		drv->capa.key_mgmt = WPA_DRIVER_CAPA_KEY_MGMT_WPA |
1399 			WPA_DRIVER_CAPA_KEY_MGMT_WPA_PSK;
1400 	if (devcaps.dc_drivercaps & IEEE80211_C_WPA2)
1401 		drv->capa.key_mgmt = WPA_DRIVER_CAPA_KEY_MGMT_WPA2 |
1402 			WPA_DRIVER_CAPA_KEY_MGMT_WPA2_PSK;
1403 
1404 	if (devcaps.dc_cryptocaps & IEEE80211_CRYPTO_WEP)
1405 		drv->capa.enc |= WPA_DRIVER_CAPA_ENC_WEP40 |
1406 			WPA_DRIVER_CAPA_ENC_WEP104;
1407 	if (devcaps.dc_cryptocaps & IEEE80211_CRYPTO_TKIP)
1408 		drv->capa.enc |= WPA_DRIVER_CAPA_ENC_TKIP;
1409 	if (devcaps.dc_cryptocaps & IEEE80211_CRYPTO_AES_CCM)
1410 		drv->capa.enc |= WPA_DRIVER_CAPA_ENC_CCMP;
1411 
1412 	if (devcaps.dc_drivercaps & IEEE80211_C_HOSTAP)
1413 		drv->capa.flags |= WPA_DRIVER_FLAGS_AP;
1414 #undef IEEE80211_CIPHER_WEP
1415 #undef IEEE80211_CIPHER_TKIP
1416 #undef IEEE80211_CIPHER_AES_CCM
1417 #undef IEEE80211_CRYPTO_WEP
1418 #undef IEEE80211_CRYPTO_TKIP
1419 #undef IEEE80211_CRYPTO_AES_CCM
1420 #undef IEEE80211_C_HOSTAP
1421 #undef IEEE80211_C_WPA1
1422 #undef IEEE80211_C_WPA2
1423 #else /* IEEE80211_IOC_DEVCAPS */
1424 	/* For now, assume TKIP, CCMP, WPA, WPA2 are supported */
1425 	drv->capa.key_mgmt = WPA_DRIVER_CAPA_KEY_MGMT_WPA |
1426 		WPA_DRIVER_CAPA_KEY_MGMT_WPA_PSK |
1427 		WPA_DRIVER_CAPA_KEY_MGMT_WPA2 |
1428 		WPA_DRIVER_CAPA_KEY_MGMT_WPA2_PSK;
1429 	drv->capa.enc = WPA_DRIVER_CAPA_ENC_WEP40 |
1430 		WPA_DRIVER_CAPA_ENC_WEP104 |
1431 		WPA_DRIVER_CAPA_ENC_TKIP |
1432 		WPA_DRIVER_CAPA_ENC_CCMP;
1433 	drv->capa.flags |= WPA_DRIVER_FLAGS_AP;
1434 #endif /* IEEE80211_IOC_DEVCAPS */
1435 #ifdef IEEE80211_IOC_SCAN_MAX_SSID
1436 	drv->capa.max_scan_ssids = IEEE80211_IOC_SCAN_MAX_SSID;
1437 #else /* IEEE80211_IOC_SCAN_MAX_SSID */
1438 	drv->capa.max_scan_ssids = 1;
1439 #endif /* IEEE80211_IOC_SCAN_MAX_SSID */
1440 	drv->capa.auth = WPA_DRIVER_AUTH_OPEN |
1441 		WPA_DRIVER_AUTH_SHARED |
1442 		WPA_DRIVER_AUTH_LEAP;
1443 	return 0;
1444 }
1445 
1446 static void *
1447 wpa_driver_bsd_init(void *ctx, const char *ifname)
1448 {
1449 #define	GETPARAM(drv, param, v) \
1450 	(((v) = get80211param(drv, param)) != -1)
1451 	struct bsd_driver_data *drv;
1452 
1453 	drv = os_zalloc(sizeof(*drv));
1454 	if (drv == NULL)
1455 		return NULL;
1456 	/*
1457 	 * NB: We require the interface name be mappable to an index.
1458 	 *     This implies we do not support having wpa_supplicant
1459 	 *     wait for an interface to appear.  This seems ok; that
1460 	 *     doesn't belong here; it's really the job of devd.
1461 	 */
1462 	drv->ifindex = if_nametoindex(ifname);
1463 	if (drv->ifindex == 0) {
1464 		wpa_printf(MSG_DEBUG, "%s: interface %s does not exist",
1465 			   __func__, ifname);
1466 		goto fail1;
1467 	}
1468 	drv->sock = socket(PF_INET, SOCK_DGRAM, 0);
1469 	if (drv->sock < 0)
1470 		goto fail1;
1471 	drv->route = socket(PF_ROUTE, SOCK_RAW, 0);
1472 	if (drv->route < 0)
1473 		goto fail;
1474 	eloop_register_read_sock(drv->route,
1475 		wpa_driver_bsd_event_receive, ctx, drv);
1476 
1477 	drv->ctx = ctx;
1478 	os_strlcpy(drv->ifname, ifname, sizeof(drv->ifname));
1479 
1480 	/* Down interface during setup. */
1481 	if (bsd_ctrl_iface(drv, 0) < 0)
1482 		goto fail;
1483 
1484 	if (!GETPARAM(drv, IEEE80211_IOC_ROAMING, drv->prev_roaming)) {
1485 		wpa_printf(MSG_DEBUG, "%s: failed to get roaming state: %s",
1486 			__func__, strerror(errno));
1487 		goto fail;
1488 	}
1489 	if (!GETPARAM(drv, IEEE80211_IOC_PRIVACY, drv->prev_privacy)) {
1490 		wpa_printf(MSG_DEBUG, "%s: failed to get privacy state: %s",
1491 			__func__, strerror(errno));
1492 		goto fail;
1493 	}
1494 	if (!GETPARAM(drv, IEEE80211_IOC_WPA, drv->prev_wpa)) {
1495 		wpa_printf(MSG_DEBUG, "%s: failed to get wpa state: %s",
1496 			__func__, strerror(errno));
1497 		goto fail;
1498 	}
1499 
1500 	if (wpa_driver_bsd_capa(drv))
1501 		goto fail;
1502 
1503 	return drv;
1504 fail:
1505 	close(drv->sock);
1506 fail1:
1507 	os_free(drv);
1508 	return NULL;
1509 #undef GETPARAM
1510 }
1511 
1512 static void
1513 wpa_driver_bsd_deinit(void *priv)
1514 {
1515 	struct bsd_driver_data *drv = priv;
1516 
1517 	wpa_driver_bsd_set_wpa(drv, 0);
1518 	eloop_unregister_read_sock(drv->route);
1519 
1520 	/* NB: mark interface down */
1521 	bsd_ctrl_iface(drv, 0);
1522 
1523 	wpa_driver_bsd_set_wpa_internal(drv, drv->prev_wpa, drv->prev_privacy);
1524 	if (set80211param(drv, IEEE80211_IOC_ROAMING, drv->prev_roaming) < 0)
1525 		wpa_printf(MSG_DEBUG, "%s: failed to restore roaming state",
1526 			__func__);
1527 
1528 	if (drv->sock_xmit != NULL)
1529 		l2_packet_deinit(drv->sock_xmit);
1530 	(void) close(drv->route);		/* ioctl socket */
1531 	(void) close(drv->sock);		/* event socket */
1532 	os_free(drv);
1533 }
1534 
1535 static int
1536 wpa_driver_bsd_get_capa(void *priv, struct wpa_driver_capa *capa)
1537 {
1538 	struct bsd_driver_data *drv = priv;
1539 
1540 	os_memcpy(capa, &drv->capa, sizeof(*capa));
1541 	return 0;
1542 }
1543 #endif /* HOSTAPD */
1544 
1545 
1546 const struct wpa_driver_ops wpa_driver_bsd_ops = {
1547 	.name			= "bsd",
1548 	.desc			= "BSD 802.11 support",
1549 #ifdef HOSTAPD
1550 	.hapd_init		= bsd_init,
1551 	.hapd_deinit		= bsd_deinit,
1552 	.set_privacy		= bsd_set_privacy,
1553 	.get_seqnum		= bsd_get_seqnum,
1554 	.flush			= bsd_flush,
1555 	.read_sta_data		= bsd_read_sta_driver_data,
1556 	.sta_disassoc		= bsd_sta_disassoc,
1557 	.sta_deauth		= bsd_sta_deauth,
1558 	.set_freq		= hostapd_bsd_set_freq,
1559 #else /* HOSTAPD */
1560 	.init			= wpa_driver_bsd_init,
1561 	.deinit			= wpa_driver_bsd_deinit,
1562 	.get_bssid		= wpa_driver_bsd_get_bssid,
1563 	.get_ssid		= wpa_driver_bsd_get_ssid,
1564 	.set_countermeasures	= wpa_driver_bsd_set_countermeasures,
1565 	.scan2			= wpa_driver_bsd_scan,
1566 	.get_scan_results2	= wpa_driver_bsd_get_scan_results2,
1567 	.deauthenticate		= wpa_driver_bsd_deauthenticate,
1568 	.disassociate		= wpa_driver_bsd_disassociate,
1569 	.associate		= wpa_driver_bsd_associate,
1570 	.get_capa		= wpa_driver_bsd_get_capa,
1571 #endif /* HOSTAPD */
1572 	.set_key		= bsd_set_key,
1573 	.set_ieee8021x		= bsd_set_ieee8021x,
1574 	.hapd_set_ssid		= bsd_set_ssid,
1575 	.hapd_get_ssid		= bsd_get_ssid,
1576 	.hapd_send_eapol	= bsd_send_eapol,
1577 	.sta_set_flags		= bsd_set_sta_authorized,
1578 	.set_generic_elem	= bsd_set_opt_ie,
1579 };
1580