Merge wpa_supplicant and hostapd driver wrapper implementations
[wpasupplicant] / src / drivers / driver_bsd.c
1 /*
2  * WPA Supplicant - driver interaction with BSD net80211 layer
3  * Copyright (c) 2004, Sam Leffler <sam@errno.com>
4  * Copyright (c) 2004, 2Wire, Inc
5  *
6  * This program is free software; you can redistribute it and/or modify
7  * it under the terms of the GNU General Public License version 2 as
8  * published by the Free Software Foundation.
9  *
10  * Alternatively, this software may be distributed under the terms of BSD
11  * license.
12  *
13  * See README and COPYING for more details.
14  */
15
16 #include "includes.h"
17 #include <sys/ioctl.h>
18
19 #include "common.h"
20 #include "driver.h"
21 #include "eloop.h"
22 #include "ieee802_11_defs.h"
23
24 #include <net/if.h>
25
26 #ifdef __NetBSD__
27 #include <net/if_ether.h>
28 #define COMPAT_FREEBSD_NET80211
29 #else
30 #include <net/ethernet.h>
31 #endif
32
33 #include <net80211/ieee80211.h>
34 #include <net80211/ieee80211_crypto.h>
35 #include <net80211/ieee80211_ioctl.h>
36
37 /*
38  * Avoid conflicts with hostapd definitions by undefining couple of defines
39  * from net80211 header files.
40  */
41 #undef RSN_VERSION
42 #undef WPA_VERSION
43 #undef WPA_OUI_TYPE
44
45
46 #ifdef HOSTAPD
47
48 #include "l2_packet/l2_packet.h"
49 #include "../../hostapd/hostapd.h"
50 #include "../../hostapd/config.h"
51 #include "../../hostapd/eapol_sm.h"
52
53 struct bsd_driver_data {
54         struct hostapd_data *hapd;              /* back pointer */
55
56         char    iface[IFNAMSIZ + 1];
57         struct l2_packet_data *sock_xmit;       /* raw packet xmit socket */
58         int     ioctl_sock;                     /* socket for ioctl() use */
59         int     wext_sock;                      /* socket for wireless events */
60 };
61
62 static int bsd_sta_deauth(void *priv, const u8 *addr, int reason_code);
63
64 static int
65 set80211var(struct bsd_driver_data *drv, int op, const void *arg, int arg_len)
66 {
67         struct ieee80211req ireq;
68
69         memset(&ireq, 0, sizeof(ireq));
70         os_strlcpy(ireq.i_name, drv->iface, IFNAMSIZ);
71         ireq.i_type = op;
72         ireq.i_len = arg_len;
73         ireq.i_data = (void *) arg;
74
75         if (ioctl(drv->ioctl_sock, SIOCS80211, &ireq) < 0) {
76                 perror("ioctl[SIOCS80211]");
77                 return -1;
78         }
79         return 0;
80 }
81
82 static int
83 get80211var(struct bsd_driver_data *drv, int op, void *arg, int arg_len)
84 {
85         struct ieee80211req ireq;
86
87         memset(&ireq, 0, sizeof(ireq));
88         os_strlcpy(ireq.i_name, drv->iface, IFNAMSIZ);
89         ireq.i_type = op;
90         ireq.i_len = arg_len;
91         ireq.i_data = arg;
92
93         if (ioctl(drv->ioctl_sock, SIOCG80211, &ireq) < 0) {
94                 perror("ioctl[SIOCG80211]");
95                 return -1;
96         }
97         return ireq.i_len;
98 }
99
100 static int
101 set80211param(struct bsd_driver_data *drv, int op, int arg)
102 {
103         struct ieee80211req ireq;
104
105         memset(&ireq, 0, sizeof(ireq));
106         os_strlcpy(ireq.i_name, drv->iface, IFNAMSIZ);
107         ireq.i_type = op;
108         ireq.i_val = arg;
109
110         if (ioctl(drv->ioctl_sock, SIOCS80211, &ireq) < 0) {
111                 perror("ioctl[SIOCS80211]");
112                 return -1;
113         }
114         return 0;
115 }
116
117 static const char *
118 ether_sprintf(const u8 *addr)
119 {
120         static char buf[sizeof(MACSTR)];
121
122         if (addr != NULL)
123                 snprintf(buf, sizeof(buf), MACSTR, MAC2STR(addr));
124         else
125                 snprintf(buf, sizeof(buf), MACSTR, 0,0,0,0,0,0);
126         return buf;
127 }
128
129 /*
130  * Configure WPA parameters.
131  */
132 static int
133 bsd_configure_wpa(struct bsd_driver_data *drv)
134 {
135         static const char *ciphernames[] =
136                 { "WEP", "TKIP", "AES-OCB", "AES-CCM", "CKIP", "NONE" };
137         struct hostapd_data *hapd = drv->hapd;
138         struct hostapd_bss_config *conf = hapd->conf;
139         int v;
140
141         switch (conf->wpa_group) {
142         case WPA_CIPHER_CCMP:
143                 v = IEEE80211_CIPHER_AES_CCM;
144                 break;
145         case WPA_CIPHER_TKIP:
146                 v = IEEE80211_CIPHER_TKIP;
147                 break;
148         case WPA_CIPHER_WEP104:
149                 v = IEEE80211_CIPHER_WEP;
150                 break;
151         case WPA_CIPHER_WEP40:
152                 v = IEEE80211_CIPHER_WEP;
153                 break;
154         case WPA_CIPHER_NONE:
155                 v = IEEE80211_CIPHER_NONE;
156                 break;
157         default:
158                 printf("Unknown group key cipher %u\n",
159                         conf->wpa_group);
160                 return -1;
161         }
162         wpa_printf(MSG_DEBUG, "%s: group key cipher=%s (%u)",
163                    __func__, ciphernames[v], v);
164         if (set80211param(drv, IEEE80211_IOC_MCASTCIPHER, v)) {
165                 printf("Unable to set group key cipher to %u (%s)\n",
166                         v, ciphernames[v]);
167                 return -1;
168         }
169         if (v == IEEE80211_CIPHER_WEP) {
170                 /* key length is done only for specific ciphers */
171                 v = (conf->wpa_group == WPA_CIPHER_WEP104 ? 13 : 5);
172                 if (set80211param(drv, IEEE80211_IOC_MCASTKEYLEN, v)) {
173                         printf("Unable to set group key length to %u\n", v);
174                         return -1;
175                 }
176         }
177
178         v = 0;
179         if (conf->wpa_pairwise & WPA_CIPHER_CCMP)
180                 v |= 1<<IEEE80211_CIPHER_AES_CCM;
181         if (conf->wpa_pairwise & WPA_CIPHER_TKIP)
182                 v |= 1<<IEEE80211_CIPHER_TKIP;
183         if (conf->wpa_pairwise & WPA_CIPHER_NONE)
184                 v |= 1<<IEEE80211_CIPHER_NONE;
185         wpa_printf(MSG_DEBUG, "%s: pairwise key ciphers=0x%x", __func__, v);
186         if (set80211param(drv, IEEE80211_IOC_UCASTCIPHERS, v)) {
187                 printf("Unable to set pairwise key ciphers to 0x%x\n", v);
188                 return -1;
189         }
190
191         wpa_printf(MSG_DEBUG, "%s: key management algorithms=0x%x",
192                    __func__, conf->wpa_key_mgmt);
193         if (set80211param(drv, IEEE80211_IOC_KEYMGTALGS, conf->wpa_key_mgmt)) {
194                 printf("Unable to set key management algorithms to 0x%x\n",
195                         conf->wpa_key_mgmt);
196                 return -1;
197         }
198
199         v = 0;
200         if (conf->rsn_preauth)
201                 v |= BIT(0);
202         wpa_printf(MSG_DEBUG, "%s: rsn capabilities=0x%x",
203                    __func__, conf->rsn_preauth);
204         if (set80211param(drv, IEEE80211_IOC_RSNCAPS, v)) {
205                 printf("Unable to set RSN capabilities to 0x%x\n", v);
206                 return -1;
207         }
208
209         wpa_printf(MSG_DEBUG, "%s: enable WPA= 0x%x", __func__, conf->wpa);
210         if (set80211param(drv, IEEE80211_IOC_WPA, conf->wpa)) {
211                 printf("Unable to set WPA to %u\n", conf->wpa);
212                 return -1;
213         }
214         return 0;
215 }
216
217
218 static int
219 bsd_set_iface_flags(void *priv, int dev_up)
220 {
221         struct bsd_driver_data *drv = priv;
222         struct ifreq ifr;
223
224         wpa_printf(MSG_DEBUG, "%s: dev_up=%d", __func__, dev_up);
225
226         if (drv->ioctl_sock < 0)
227                 return -1;
228
229         memset(&ifr, 0, sizeof(ifr));
230         os_strlcpy(ifr.ifr_name, drv->iface, IFNAMSIZ);
231
232         if (ioctl(drv->ioctl_sock, SIOCGIFFLAGS, &ifr) != 0) {
233                 perror("ioctl[SIOCGIFFLAGS]");
234                 return -1;
235         }
236
237         if (dev_up)
238                 ifr.ifr_flags |= IFF_UP;
239         else
240                 ifr.ifr_flags &= ~IFF_UP;
241
242         if (ioctl(drv->ioctl_sock, SIOCSIFFLAGS, &ifr) != 0) {
243                 perror("ioctl[SIOCSIFFLAGS]");
244                 return -1;
245         }
246
247         if (dev_up) {
248                 memset(&ifr, 0, sizeof(ifr));
249                 os_strlcpy(ifr.ifr_name, drv->iface, IFNAMSIZ);
250                 ifr.ifr_mtu = HOSTAPD_MTU;
251                 if (ioctl(drv->ioctl_sock, SIOCSIFMTU, &ifr) != 0) {
252                         perror("ioctl[SIOCSIFMTU]");
253                         printf("Setting MTU failed - trying to survive with "
254                                "current value\n");
255                 }
256         }
257
258         return 0;
259 }
260
261 static int
262 bsd_set_ieee8021x(const char *ifname, void *priv, int enabled)
263 {
264         struct bsd_driver_data *drv = priv;
265         struct hostapd_data *hapd = drv->hapd;
266         struct hostapd_bss_config *conf = hapd->conf;
267
268         wpa_printf(MSG_DEBUG, "%s: enabled=%d", __func__, enabled);
269
270         if (!enabled) {
271                 /* XXX restore state */
272                 return set80211param(priv, IEEE80211_IOC_AUTHMODE,
273                         IEEE80211_AUTH_AUTO);
274         }
275         if (!conf->wpa && !conf->ieee802_1x) {
276                 hostapd_logger(hapd, NULL, HOSTAPD_MODULE_DRIVER,
277                         HOSTAPD_LEVEL_WARNING, "No 802.1X or WPA enabled!");
278                 return -1;
279         }
280         if (conf->wpa && bsd_configure_wpa(drv) != 0) {
281                 hostapd_logger(hapd, NULL, HOSTAPD_MODULE_DRIVER,
282                         HOSTAPD_LEVEL_WARNING, "Error configuring WPA state!");
283                 return -1;
284         }
285         if (set80211param(priv, IEEE80211_IOC_AUTHMODE,
286                 (conf->wpa ?  IEEE80211_AUTH_WPA : IEEE80211_AUTH_8021X))) {
287                 hostapd_logger(hapd, NULL, HOSTAPD_MODULE_DRIVER,
288                         HOSTAPD_LEVEL_WARNING, "Error enabling WPA/802.1X!");
289                 return -1;
290         }
291         return bsd_set_iface_flags(priv, 1);
292 }
293
294 static int
295 bsd_set_privacy(const char *ifname, void *priv, int enabled)
296 {
297         struct bsd_driver_data *drv = priv;
298
299         wpa_printf(MSG_DEBUG, "%s: enabled=%d", __func__, enabled);
300
301         return set80211param(drv, IEEE80211_IOC_PRIVACY, enabled);
302 }
303
304 static int
305 bsd_set_sta_authorized(void *priv, const u8 *addr, int authorized)
306 {
307         struct bsd_driver_data *drv = priv;
308         struct ieee80211req_mlme mlme;
309
310         wpa_printf(MSG_DEBUG, "%s: addr=%s authorized=%d",
311                    __func__, ether_sprintf(addr), authorized);
312
313         if (authorized)
314                 mlme.im_op = IEEE80211_MLME_AUTHORIZE;
315         else
316                 mlme.im_op = IEEE80211_MLME_UNAUTHORIZE;
317         mlme.im_reason = 0;
318         memcpy(mlme.im_macaddr, addr, IEEE80211_ADDR_LEN);
319         return set80211var(drv, IEEE80211_IOC_MLME, &mlme, sizeof(mlme));
320 }
321
322 static int
323 bsd_sta_set_flags(void *priv, const u8 *addr, int total_flags, int flags_or,
324                   int flags_and)
325 {
326         /* For now, only support setting Authorized flag */
327         if (flags_or & WLAN_STA_AUTHORIZED)
328                 return bsd_set_sta_authorized(priv, addr, 1);
329         if (!(flags_and & WLAN_STA_AUTHORIZED))
330                 return bsd_set_sta_authorized(priv, addr, 0);
331         return 0;
332 }
333
334 static int
335 bsd_del_key(void *priv, const u8 *addr, int key_idx)
336 {
337         struct bsd_driver_data *drv = priv;
338         struct ieee80211req_del_key wk;
339
340         wpa_printf(MSG_DEBUG, "%s: addr=%s key_idx=%d",
341                    __func__, ether_sprintf(addr), key_idx);
342
343         memset(&wk, 0, sizeof(wk));
344         if (addr != NULL) {
345                 memcpy(wk.idk_macaddr, addr, IEEE80211_ADDR_LEN);
346                 wk.idk_keyix = (u_int8_t) IEEE80211_KEYIX_NONE; /* XXX */
347         } else {
348                 wk.idk_keyix = key_idx;
349         }
350
351         return set80211var(drv, IEEE80211_IOC_DELKEY, &wk, sizeof(wk));
352 }
353
354 static int
355 bsd_set_key(const char *ifname, void *priv, wpa_alg alg,
356             const u8 *addr, int key_idx, int set_tx, const u8 *seq,
357             size_t seq_len, const u8 *key, size_t key_len)
358 {
359         struct bsd_driver_data *drv = priv;
360         struct ieee80211req_key wk;
361         u_int8_t cipher;
362
363         if (alg == WPA_ALG_NONE)
364                 return bsd_del_key(drv, addr, key_idx);
365
366         wpa_printf(MSG_DEBUG, "%s: alg=%d addr=%s key_idx=%d",
367                    __func__, alg, ether_sprintf(addr), key_idx);
368
369         if (alg == WPA_ALG_WEP)
370                 cipher = IEEE80211_CIPHER_WEP;
371         else if (alg == WPA_ALG_TKIP)
372                 cipher = IEEE80211_CIPHER_TKIP;
373         else if (alg == WPA_ALG_CCMP)
374                 cipher = IEEE80211_CIPHER_AES_CCM;
375         else {
376                 printf("%s: unknown/unsupported algorithm %d\n",
377                         __func__, alg);
378                 return -1;
379         }
380
381         if (key_len > sizeof(wk.ik_keydata)) {
382                 printf("%s: key length %d too big\n", __func__, key_len);
383                 return -3;
384         }
385
386         memset(&wk, 0, sizeof(wk));
387         wk.ik_type = cipher;
388         wk.ik_flags = IEEE80211_KEY_RECV | IEEE80211_KEY_XMIT;
389         if (addr == NULL) {
390                 memset(wk.ik_macaddr, 0xff, IEEE80211_ADDR_LEN);
391                 wk.ik_keyix = key_idx;
392                 wk.ik_flags |= IEEE80211_KEY_DEFAULT;
393         } else {
394                 memcpy(wk.ik_macaddr, addr, IEEE80211_ADDR_LEN);
395                 wk.ik_keyix = IEEE80211_KEYIX_NONE;
396         }
397         wk.ik_keylen = key_len;
398         memcpy(wk.ik_keydata, key, key_len);
399
400         return set80211var(drv, IEEE80211_IOC_WPAKEY, &wk, sizeof(wk));
401 }
402
403
404 static int
405 bsd_get_seqnum(const char *ifname, void *priv, const u8 *addr, int idx,
406                u8 *seq)
407 {
408         struct bsd_driver_data *drv = priv;
409         struct ieee80211req_key wk;
410
411         wpa_printf(MSG_DEBUG, "%s: addr=%s idx=%d",
412                    __func__, ether_sprintf(addr), idx);
413
414         memset(&wk, 0, sizeof(wk));
415         if (addr == NULL)
416                 memset(wk.ik_macaddr, 0xff, IEEE80211_ADDR_LEN);
417         else
418                 memcpy(wk.ik_macaddr, addr, IEEE80211_ADDR_LEN);
419         wk.ik_keyix = idx;
420
421         if (get80211var(drv, IEEE80211_IOC_WPAKEY, &wk, sizeof(wk)) < 0) {
422                 printf("Failed to get encryption.\n");
423                 return -1;
424         }
425
426 #ifdef WORDS_BIGENDIAN
427         {
428                 /*
429                  * wk.ik_keytsc is in host byte order (big endian), need to
430                  * swap it to match with the byte order used in WPA.
431                  */
432                 int i;
433                 u8 tmp[WPA_KEY_RSC_LEN];
434                 memcpy(tmp, &wk.ik_keytsc, sizeof(wk.ik_keytsc));
435                 for (i = 0; i < WPA_KEY_RSC_LEN; i++) {
436                         seq[i] = tmp[WPA_KEY_RSC_LEN - i - 1];
437                 }
438         }
439 #else /* WORDS_BIGENDIAN */
440         memcpy(seq, &wk.ik_keytsc, sizeof(wk.ik_keytsc));
441 #endif /* WORDS_BIGENDIAN */
442         return 0;
443 }
444
445
446 static int 
447 bsd_flush(void *priv)
448 {
449         u8 allsta[IEEE80211_ADDR_LEN];
450
451         memset(allsta, 0xff, IEEE80211_ADDR_LEN);
452         return bsd_sta_deauth(priv, allsta, IEEE80211_REASON_AUTH_LEAVE);
453 }
454
455
456 static int
457 bsd_read_sta_driver_data(void *priv, struct hostap_sta_driver_data *data,
458                          const u8 *addr)
459 {
460         struct bsd_driver_data *drv = priv;
461         struct ieee80211req_sta_stats stats;
462
463         memcpy(stats.is_u.macaddr, addr, IEEE80211_ADDR_LEN);
464         if (get80211var(drv, IEEE80211_IOC_STA_STATS, &stats, sizeof(stats)) > 0) {
465                 /* XXX? do packets counts include non-data frames? */
466                 data->rx_packets = stats.is_stats.ns_rx_data;
467                 data->rx_bytes = stats.is_stats.ns_rx_bytes;
468                 data->tx_packets = stats.is_stats.ns_tx_data;
469                 data->tx_bytes = stats.is_stats.ns_tx_bytes;
470         }
471         return 0;
472 }
473
474 static int
475 bsd_set_opt_ie(const char *ifname, void *priv, const u8 *ie, size_t ie_len)
476 {
477         /*
478          * Do nothing; we setup parameters at startup that define the
479          * contents of the beacon information element.
480          */
481         return 0;
482 }
483
484 static int
485 bsd_sta_deauth(void *priv, const u8 *addr, int reason_code)
486 {
487         struct bsd_driver_data *drv = priv;
488         struct ieee80211req_mlme mlme;
489
490         wpa_printf(MSG_DEBUG, "%s: addr=%s reason_code=%d",
491                    __func__, ether_sprintf(addr), reason_code);
492
493         mlme.im_op = IEEE80211_MLME_DEAUTH;
494         mlme.im_reason = reason_code;
495         memcpy(mlme.im_macaddr, addr, IEEE80211_ADDR_LEN);
496         return set80211var(drv, IEEE80211_IOC_MLME, &mlme, sizeof(mlme));
497 }
498
499 static int
500 bsd_sta_disassoc(void *priv, const u8 *addr, int reason_code)
501 {
502         struct bsd_driver_data *drv = priv;
503         struct ieee80211req_mlme mlme;
504
505         wpa_printf(MSG_DEBUG, "%s: addr=%s reason_code=%d",
506                    __func__, ether_sprintf(addr), reason_code);
507
508         mlme.im_op = IEEE80211_MLME_DISASSOC;
509         mlme.im_reason = reason_code;
510         memcpy(mlme.im_macaddr, addr, IEEE80211_ADDR_LEN);
511         return set80211var(drv, IEEE80211_IOC_MLME, &mlme, sizeof(mlme));
512 }
513
514 static int
515 bsd_new_sta(struct bsd_driver_data *drv, u8 addr[IEEE80211_ADDR_LEN])
516 {
517         struct hostapd_data *hapd = drv->hapd;
518         struct ieee80211req_wpaie ie;
519         int ielen = 0;
520         u8 *iebuf = NULL;
521
522         /*
523          * Fetch and validate any negotiated WPA/RSN parameters.
524          */
525         memset(&ie, 0, sizeof(ie));
526         memcpy(ie.wpa_macaddr, addr, IEEE80211_ADDR_LEN);
527         if (get80211var(drv, IEEE80211_IOC_WPAIE, &ie, sizeof(ie)) < 0) {
528                 printf("Failed to get WPA/RSN information element.\n");
529                 goto no_ie;
530         }
531         iebuf = ie.wpa_ie;
532         ielen = ie.wpa_ie[1];
533         if (ielen == 0)
534                 iebuf = NULL;
535         else
536                 ielen += 2;
537
538 no_ie:
539         return hostapd_notif_assoc(hapd, addr, iebuf, ielen);
540 }
541
542 #include <net/route.h>
543 #include <net80211/ieee80211_freebsd.h>
544
545 static void
546 bsd_wireless_event_receive(int sock, void *ctx, void *sock_ctx)
547 {
548         struct bsd_driver_data *drv = ctx;
549         struct hostapd_data *hapd = drv->hapd;
550         char buf[2048];
551         struct if_announcemsghdr *ifan;
552         struct rt_msghdr *rtm;
553         struct ieee80211_michael_event *mic;
554         struct ieee80211_join_event *join;
555         struct ieee80211_leave_event *leave;
556         int n;
557
558         n = read(sock, buf, sizeof(buf));
559         if (n < 0) {
560                 if (errno != EINTR && errno != EAGAIN)
561                         perror("read(PF_ROUTE)");
562                 return;
563         }
564
565         rtm = (struct rt_msghdr *) buf;
566         if (rtm->rtm_version != RTM_VERSION) {
567                 wpa_printf(MSG_DEBUG, "Routing message version %d not "
568                         "understood\n", rtm->rtm_version);
569                 return;
570         }
571         ifan = (struct if_announcemsghdr *) rtm;
572         switch (rtm->rtm_type) {
573         case RTM_IEEE80211:
574                 switch (ifan->ifan_what) {
575                 case RTM_IEEE80211_ASSOC:
576                 case RTM_IEEE80211_REASSOC:
577                 case RTM_IEEE80211_DISASSOC:
578                 case RTM_IEEE80211_SCAN:
579                         break;
580                 case RTM_IEEE80211_LEAVE:
581                         leave = (struct ieee80211_leave_event *) &ifan[1];
582                         hostapd_notif_disassoc(drv->hapd, leave->iev_addr);
583                         break;
584                 case RTM_IEEE80211_JOIN:
585 #ifdef RTM_IEEE80211_REJOIN
586                 case RTM_IEEE80211_REJOIN:
587 #endif
588                         join = (struct ieee80211_join_event *) &ifan[1];
589                         bsd_new_sta(drv, join->iev_addr);
590                         break;
591                 case RTM_IEEE80211_REPLAY:
592                         /* ignore */
593                         break;
594                 case RTM_IEEE80211_MICHAEL:
595                         mic = (struct ieee80211_michael_event *) &ifan[1];
596                         wpa_printf(MSG_DEBUG,
597                                 "Michael MIC failure wireless event: "
598                                 "keyix=%u src_addr=" MACSTR, mic->iev_keyix,
599                                 MAC2STR(mic->iev_src));
600                         hostapd_michael_mic_failure(hapd, mic->iev_src);
601                         break;
602                 }
603                 break;
604         }
605 }
606
607 static int
608 bsd_wireless_event_init(struct bsd_driver_data *drv)
609 {
610         int s;
611
612         drv->wext_sock = -1;
613
614         s = socket(PF_ROUTE, SOCK_RAW, 0);
615         if (s < 0) {
616                 perror("socket(PF_ROUTE,SOCK_RAW)");
617                 return -1;
618         }
619         eloop_register_read_sock(s, bsd_wireless_event_receive, drv, NULL);
620         drv->wext_sock = s;
621
622         return 0;
623 }
624
625 static void
626 bsd_wireless_event_deinit(struct bsd_driver_data *drv)
627 {
628         if (drv->wext_sock < 0)
629                 return;
630         eloop_unregister_read_sock(drv->wext_sock);
631         close(drv->wext_sock);
632 }
633
634
635 static int
636 bsd_send_eapol(void *priv, const u8 *addr, const u8 *data, size_t data_len,
637                int encrypt, const u8 *own_addr)
638 {
639         struct bsd_driver_data *drv = priv;
640         unsigned char buf[3000];
641         unsigned char *bp = buf;
642         struct l2_ethhdr *eth;
643         size_t len;
644         int status;
645
646         /*
647          * Prepend the Etherent header.  If the caller left us
648          * space at the front we could just insert it but since
649          * we don't know we copy to a local buffer.  Given the frequency
650          * and size of frames this probably doesn't matter.
651          */
652         len = data_len + sizeof(struct l2_ethhdr);
653         if (len > sizeof(buf)) {
654                 bp = malloc(len);
655                 if (bp == NULL) {
656                         printf("EAPOL frame discarded, cannot malloc temp "
657                                 "buffer of size %u!\n", len);
658                         return -1;
659                 }
660         }
661         eth = (struct l2_ethhdr *) bp;
662         memcpy(eth->h_dest, addr, ETH_ALEN);
663         memcpy(eth->h_source, own_addr, ETH_ALEN);
664         eth->h_proto = htons(ETH_P_EAPOL);
665         memcpy(eth+1, data, data_len);
666
667         wpa_hexdump(MSG_MSGDUMP, "TX EAPOL", bp, len);
668
669         status = l2_packet_send(drv->sock_xmit, addr, ETH_P_EAPOL, bp, len);
670
671         if (bp != buf)
672                 free(bp);
673         return status;
674 }
675
676 static void
677 handle_read(void *ctx, const u8 *src_addr, const u8 *buf, size_t len)
678 {
679         struct bsd_driver_data *drv = ctx;
680         hostapd_eapol_receive(drv->hapd, src_addr,
681                               buf + sizeof(struct l2_ethhdr),
682                               len - sizeof(struct l2_ethhdr));
683 }
684
685 static int
686 bsd_get_ssid(const char *ifname, void *priv, u8 *buf, int len)
687 {
688         struct bsd_driver_data *drv = priv;
689         int ssid_len = get80211var(drv, IEEE80211_IOC_SSID, buf, len);
690
691         wpa_printf(MSG_DEBUG, "%s: ssid=\"%.*s\"", __func__, ssid_len, buf);
692
693         return ssid_len;
694 }
695
696 static int
697 bsd_set_ssid(const char *ifname, void *priv, const u8 *buf, int len)
698 {
699         struct bsd_driver_data *drv = priv;
700
701         wpa_printf(MSG_DEBUG, "%s: ssid=\"%.*s\"", __func__, len, buf);
702
703         return set80211var(drv, IEEE80211_IOC_SSID, buf, len);
704 }
705
706 static void *
707 bsd_init(struct hostapd_data *hapd)
708 {
709         struct bsd_driver_data *drv;
710
711         drv = os_zalloc(sizeof(struct bsd_driver_data));
712         if (drv == NULL) {
713                 printf("Could not allocate memory for bsd driver data\n");
714                 goto bad;
715         }
716
717         drv->hapd = hapd;
718         drv->ioctl_sock = socket(PF_INET, SOCK_DGRAM, 0);
719         if (drv->ioctl_sock < 0) {
720                 perror("socket[PF_INET,SOCK_DGRAM]");
721                 goto bad;
722         }
723         memcpy(drv->iface, hapd->conf->iface, sizeof(drv->iface));
724
725         drv->sock_xmit = l2_packet_init(drv->iface, NULL, ETH_P_EAPOL,
726                                         handle_read, drv, 1);
727         if (drv->sock_xmit == NULL)
728                 goto bad;
729         if (l2_packet_get_own_addr(drv->sock_xmit, hapd->own_addr))
730                 goto bad;
731
732         bsd_set_iface_flags(drv, 0);    /* mark down during setup */
733         if (bsd_wireless_event_init(drv))
734                 goto bad;
735
736         return drv;
737 bad:
738         if (drv->sock_xmit != NULL)
739                 l2_packet_deinit(drv->sock_xmit);
740         if (drv->ioctl_sock >= 0)
741                 close(drv->ioctl_sock);
742         if (drv != NULL)
743                 free(drv);
744         return NULL;
745 }
746
747
748 static void
749 bsd_deinit(void *priv)
750 {
751         struct bsd_driver_data *drv = priv;
752
753         bsd_wireless_event_deinit(drv);
754         (void) bsd_set_iface_flags(drv, 0);
755         if (drv->ioctl_sock >= 0)
756                 close(drv->ioctl_sock);
757         if (drv->sock_xmit != NULL)
758                 l2_packet_deinit(drv->sock_xmit);
759         free(drv);
760 }
761
762 const struct wpa_driver_ops wpa_driver_bsd_ops = {
763         .name                   = "bsd",
764         .hapd_init              = bsd_init,
765         .hapd_deinit            = bsd_deinit,
766         .set_ieee8021x          = bsd_set_ieee8021x,
767         .set_privacy            = bsd_set_privacy,
768         .hapd_set_key           = bsd_set_key,
769         .get_seqnum             = bsd_get_seqnum,
770         .flush                  = bsd_flush,
771         .set_generic_elem       = bsd_set_opt_ie,
772         .sta_set_flags          = bsd_sta_set_flags,
773         .read_sta_data          = bsd_read_sta_driver_data,
774         .hapd_send_eapol        = bsd_send_eapol,
775         .sta_disassoc           = bsd_sta_disassoc,
776         .sta_deauth             = bsd_sta_deauth,
777         .hapd_set_ssid          = bsd_set_ssid,
778         .hapd_get_ssid          = bsd_get_ssid,
779 };
780
781 #else /* HOSTAPD */
782
783 struct wpa_driver_bsd_data {
784         int     sock;                   /* open socket for 802.11 ioctls */
785         int     route;                  /* routing socket for events */
786         char    ifname[IFNAMSIZ+1];     /* interface name */
787         unsigned int ifindex;           /* interface index */
788         void    *ctx;
789         int     prev_roaming;           /* roaming state to restore on deinit */
790         int     prev_privacy;           /* privacy state to restore on deinit */
791         int     prev_wpa;               /* wpa state to restore on deinit */
792 };
793
794 static int
795 set80211var(struct wpa_driver_bsd_data *drv, int op, const void *arg, int arg_len)
796 {
797         struct ieee80211req ireq;
798
799         os_memset(&ireq, 0, sizeof(ireq));
800         os_strlcpy(ireq.i_name, drv->ifname, IFNAMSIZ);
801         ireq.i_type = op;
802         ireq.i_len = arg_len;
803         ireq.i_data = (void *) arg;
804
805         if (ioctl(drv->sock, SIOCS80211, &ireq) < 0) {
806                 fprintf(stderr, "ioctl[SIOCS80211, op %u, len %u]: %s\n",
807                         op, arg_len, strerror(errno));
808                 return -1;
809         }
810         return 0;
811 }
812
813 static int
814 get80211var(struct wpa_driver_bsd_data *drv, int op, void *arg, int arg_len)
815 {
816         struct ieee80211req ireq;
817
818         os_memset(&ireq, 0, sizeof(ireq));
819         os_strlcpy(ireq.i_name, drv->ifname, IFNAMSIZ);
820         ireq.i_type = op;
821         ireq.i_len = arg_len;
822         ireq.i_data = arg;
823
824         if (ioctl(drv->sock, SIOCG80211, &ireq) < 0) {
825                 fprintf(stderr, "ioctl[SIOCG80211, op %u, len %u]: %s\n",
826                         op, arg_len, strerror(errno));
827                 return -1;
828         }
829         return ireq.i_len;
830 }
831
832 static int
833 set80211param(struct wpa_driver_bsd_data *drv, int op, int arg)
834 {
835         struct ieee80211req ireq;
836
837         os_memset(&ireq, 0, sizeof(ireq));
838         os_strlcpy(ireq.i_name, drv->ifname, IFNAMSIZ);
839         ireq.i_type = op;
840         ireq.i_val = arg;
841
842         if (ioctl(drv->sock, SIOCS80211, &ireq) < 0) {
843                 fprintf(stderr, "ioctl[SIOCS80211, op %u, arg 0x%x]: %s\n",
844                         op, arg, strerror(errno));
845                 return -1;
846         }
847         return 0;
848 }
849
850 static int
851 get80211param(struct wpa_driver_bsd_data *drv, int op)
852 {
853         struct ieee80211req ireq;
854
855         os_memset(&ireq, 0, sizeof(ireq));
856         os_strlcpy(ireq.i_name, drv->ifname, IFNAMSIZ);
857         ireq.i_type = op;
858
859         if (ioctl(drv->sock, SIOCG80211, &ireq) < 0) {
860                 fprintf(stderr, "ioctl[SIOCG80211, op %u]: %s\n",
861                         op, strerror(errno));
862                 return -1;
863         }
864         return ireq.i_val;
865 }
866
867 static int
868 getifflags(struct wpa_driver_bsd_data *drv, int *flags)
869 {
870         struct ifreq ifr;
871
872         os_memset(&ifr, 0, sizeof(ifr));
873         os_strlcpy(ifr.ifr_name, drv->ifname, sizeof(ifr.ifr_name));
874         if (ioctl(drv->sock, SIOCGIFFLAGS, (caddr_t)&ifr) < 0) {
875                 perror("SIOCGIFFLAGS");
876                 return errno;
877         }
878         *flags = ifr.ifr_flags & 0xffff;
879         return 0;
880 }
881
882 static int
883 setifflags(struct wpa_driver_bsd_data *drv, int flags)
884 {
885         struct ifreq ifr;
886
887         os_memset(&ifr, 0, sizeof(ifr));
888         os_strlcpy(ifr.ifr_name, drv->ifname, sizeof(ifr.ifr_name));
889         ifr.ifr_flags = flags & 0xffff;
890         if (ioctl(drv->sock, SIOCSIFFLAGS, (caddr_t)&ifr) < 0) {
891                 perror("SIOCSIFFLAGS");
892                 return errno;
893         }
894         return 0;
895 }
896
897 static int
898 wpa_driver_bsd_get_bssid(void *priv, u8 *bssid)
899 {
900         struct wpa_driver_bsd_data *drv = priv;
901
902         return get80211var(drv, IEEE80211_IOC_BSSID,
903                 bssid, IEEE80211_ADDR_LEN) < 0 ? -1 : 0;
904 }
905
906 #if 0
907 static int
908 wpa_driver_bsd_set_bssid(void *priv, const char *bssid)
909 {
910         struct wpa_driver_bsd_data *drv = priv;
911
912         return set80211var(drv, IEEE80211_IOC_BSSID,
913                 bssid, IEEE80211_ADDR_LEN);
914 }
915 #endif
916
917 static int
918 wpa_driver_bsd_get_ssid(void *priv, u8 *ssid)
919 {
920         struct wpa_driver_bsd_data *drv = priv;
921
922         return get80211var(drv, IEEE80211_IOC_SSID,
923                 ssid, IEEE80211_NWID_LEN);
924 }
925
926 static int
927 wpa_driver_bsd_set_ssid(void *priv, const u8 *ssid,
928                              size_t ssid_len)
929 {
930         struct wpa_driver_bsd_data *drv = priv;
931
932         return set80211var(drv, IEEE80211_IOC_SSID, ssid, ssid_len);
933 }
934
935 static int
936 wpa_driver_bsd_set_wpa_ie(struct wpa_driver_bsd_data *drv,
937         const u8 *wpa_ie, size_t wpa_ie_len)
938 {
939         return set80211var(drv, IEEE80211_IOC_OPTIE, wpa_ie, wpa_ie_len);
940 }
941
942 static int
943 wpa_driver_bsd_set_wpa_internal(void *priv, int wpa, int privacy)
944 {
945         struct wpa_driver_bsd_data *drv = priv;
946         int ret = 0;
947
948         wpa_printf(MSG_DEBUG, "%s: wpa=%d privacy=%d",
949                 __FUNCTION__, wpa, privacy);
950
951         if (!wpa && wpa_driver_bsd_set_wpa_ie(drv, NULL, 0) < 0)
952                 ret = -1;
953         if (set80211param(drv, IEEE80211_IOC_PRIVACY, privacy) < 0)
954                 ret = -1;
955         if (set80211param(drv, IEEE80211_IOC_WPA, wpa) < 0)
956                 ret = -1;
957
958         return ret;
959 }
960
961 static int
962 wpa_driver_bsd_set_wpa(void *priv, int enabled)
963 {
964         wpa_printf(MSG_DEBUG, "%s: enabled=%d", __FUNCTION__, enabled);
965
966         return wpa_driver_bsd_set_wpa_internal(priv, enabled ? 3 : 0, enabled);
967 }
968
969 static int
970 wpa_driver_bsd_del_key(struct wpa_driver_bsd_data *drv, int key_idx,
971                        const unsigned char *addr)
972 {
973         struct ieee80211req_del_key wk;
974
975         os_memset(&wk, 0, sizeof(wk));
976         if (addr != NULL &&
977             bcmp(addr, "\xff\xff\xff\xff\xff\xff", IEEE80211_ADDR_LEN) != 0) {
978                 struct ether_addr ea;
979
980                 os_memcpy(&ea, addr, IEEE80211_ADDR_LEN);
981                 wpa_printf(MSG_DEBUG, "%s: addr=%s keyidx=%d",
982                         __func__, ether_ntoa(&ea), key_idx);
983                 os_memcpy(wk.idk_macaddr, addr, IEEE80211_ADDR_LEN);
984                 wk.idk_keyix = (uint8_t) IEEE80211_KEYIX_NONE;
985         } else {
986                 wpa_printf(MSG_DEBUG, "%s: keyidx=%d", __func__, key_idx);
987                 wk.idk_keyix = key_idx;
988         }
989         return set80211var(drv, IEEE80211_IOC_DELKEY, &wk, sizeof(wk));
990 }
991
992 static int
993 wpa_driver_bsd_set_key(void *priv, wpa_alg alg,
994                        const unsigned char *addr, int key_idx, int set_tx,
995                        const u8 *seq, size_t seq_len,
996                        const u8 *key, size_t key_len)
997 {
998         struct wpa_driver_bsd_data *drv = priv;
999         struct ieee80211req_key wk;
1000         struct ether_addr ea;
1001         char *alg_name;
1002         u_int8_t cipher;
1003
1004         if (alg == WPA_ALG_NONE)
1005                 return wpa_driver_bsd_del_key(drv, key_idx, addr);
1006
1007         switch (alg) {
1008         case WPA_ALG_WEP:
1009                 alg_name = "WEP";
1010                 cipher = IEEE80211_CIPHER_WEP;
1011                 break;
1012         case WPA_ALG_TKIP:
1013                 alg_name = "TKIP";
1014                 cipher = IEEE80211_CIPHER_TKIP;
1015                 break;
1016         case WPA_ALG_CCMP:
1017                 alg_name = "CCMP";
1018                 cipher = IEEE80211_CIPHER_AES_CCM;
1019                 break;
1020         default:
1021                 wpa_printf(MSG_DEBUG, "%s: unknown/unsupported algorithm %d",
1022                         __func__, alg);
1023                 return -1;
1024         }
1025
1026         os_memcpy(&ea, addr, IEEE80211_ADDR_LEN);
1027         wpa_printf(MSG_DEBUG,
1028                 "%s: alg=%s addr=%s key_idx=%d set_tx=%d seq_len=%zu key_len=%zu",
1029                 __func__, alg_name, ether_ntoa(&ea), key_idx, set_tx,
1030                 seq_len, key_len);
1031
1032         if (seq_len > sizeof(u_int64_t)) {
1033                 wpa_printf(MSG_DEBUG, "%s: seq_len %zu too big",
1034                         __func__, seq_len);
1035                 return -2;
1036         }
1037         if (key_len > sizeof(wk.ik_keydata)) {
1038                 wpa_printf(MSG_DEBUG, "%s: key length %zu too big",
1039                         __func__, key_len);
1040                 return -3;
1041         }
1042
1043         os_memset(&wk, 0, sizeof(wk));
1044         wk.ik_type = cipher;
1045         wk.ik_flags = IEEE80211_KEY_RECV;
1046         if (set_tx)
1047                 wk.ik_flags |= IEEE80211_KEY_XMIT;
1048         os_memcpy(wk.ik_macaddr, addr, IEEE80211_ADDR_LEN);
1049         /*
1050          * Deduce whether group/global or unicast key by checking
1051          * the address (yech).  Note also that we can only mark global
1052          * keys default; doing this for a unicast key is an error.
1053          */
1054         if (bcmp(addr, "\xff\xff\xff\xff\xff\xff", IEEE80211_ADDR_LEN) == 0) {
1055                 wk.ik_flags |= IEEE80211_KEY_GROUP;
1056                 wk.ik_keyix = key_idx;
1057         } else {
1058                 wk.ik_keyix = (key_idx == 0 ? IEEE80211_KEYIX_NONE : key_idx);
1059         }
1060         if (wk.ik_keyix != IEEE80211_KEYIX_NONE && set_tx)
1061                 wk.ik_flags |= IEEE80211_KEY_DEFAULT;
1062         wk.ik_keylen = key_len;
1063         os_memcpy(&wk.ik_keyrsc, seq, seq_len);
1064         os_memcpy(wk.ik_keydata, key, key_len);
1065
1066         return set80211var(drv, IEEE80211_IOC_WPAKEY, &wk, sizeof(wk));
1067 }
1068
1069 static int
1070 wpa_driver_bsd_set_countermeasures(void *priv, int enabled)
1071 {
1072         struct wpa_driver_bsd_data *drv = priv;
1073
1074         wpa_printf(MSG_DEBUG, "%s: enabled=%d", __func__, enabled);
1075         return set80211param(drv, IEEE80211_IOC_COUNTERMEASURES, enabled);
1076 }
1077
1078
1079 static int
1080 wpa_driver_bsd_set_drop_unencrypted(void *priv, int enabled)
1081 {
1082         struct wpa_driver_bsd_data *drv = priv;
1083
1084         wpa_printf(MSG_DEBUG, "%s: enabled=%d", __func__, enabled);
1085         return set80211param(drv, IEEE80211_IOC_DROPUNENCRYPTED, enabled);
1086 }
1087
1088 static int
1089 wpa_driver_bsd_deauthenticate(void *priv, const u8 *addr, int reason_code)
1090 {
1091         struct wpa_driver_bsd_data *drv = priv;
1092         struct ieee80211req_mlme mlme;
1093
1094         wpa_printf(MSG_DEBUG, "%s", __func__);
1095         os_memset(&mlme, 0, sizeof(mlme));
1096         mlme.im_op = IEEE80211_MLME_DEAUTH;
1097         mlme.im_reason = reason_code;
1098         os_memcpy(mlme.im_macaddr, addr, IEEE80211_ADDR_LEN);
1099         return set80211var(drv, IEEE80211_IOC_MLME, &mlme, sizeof(mlme));
1100 }
1101
1102 static int
1103 wpa_driver_bsd_disassociate(void *priv, const u8 *addr, int reason_code)
1104 {
1105         struct wpa_driver_bsd_data *drv = priv;
1106         struct ieee80211req_mlme mlme;
1107
1108         wpa_printf(MSG_DEBUG, "%s", __func__);
1109         os_memset(&mlme, 0, sizeof(mlme));
1110         mlme.im_op = IEEE80211_MLME_DISASSOC;
1111         mlme.im_reason = reason_code;
1112         os_memcpy(mlme.im_macaddr, addr, IEEE80211_ADDR_LEN);
1113         return set80211var(drv, IEEE80211_IOC_MLME, &mlme, sizeof(mlme));
1114 }
1115
1116 static int
1117 wpa_driver_bsd_associate(void *priv, struct wpa_driver_associate_params *params)
1118 {
1119         struct wpa_driver_bsd_data *drv = priv;
1120         struct ieee80211req_mlme mlme;
1121         int privacy;
1122
1123         wpa_printf(MSG_DEBUG,
1124                 "%s: ssid '%.*s' wpa ie len %u pairwise %u group %u key mgmt %u"
1125                 , __func__
1126                 , params->ssid_len, params->ssid
1127                 , params->wpa_ie_len
1128                 , params->pairwise_suite
1129                 , params->group_suite
1130                 , params->key_mgmt_suite
1131         );
1132
1133         /* XXX error handling is wrong but unclear what to do... */
1134         if (wpa_driver_bsd_set_wpa_ie(drv, params->wpa_ie, params->wpa_ie_len) < 0)
1135                 return -1;
1136 #ifndef NEW_FREEBSD_MLME_ASSOC
1137         if (wpa_driver_bsd_set_ssid(drv, params->ssid, params->ssid_len) < 0)
1138                 return -1;
1139 #endif
1140
1141         privacy = !(params->pairwise_suite == CIPHER_NONE &&
1142             params->group_suite == CIPHER_NONE &&
1143             params->key_mgmt_suite == KEY_MGMT_NONE &&
1144             params->wpa_ie_len == 0);
1145         wpa_printf(MSG_DEBUG, "%s: set PRIVACY %u", __func__, privacy);
1146
1147         if (set80211param(drv, IEEE80211_IOC_PRIVACY, privacy) < 0)
1148                 return -1;
1149
1150         if (params->wpa_ie_len &&
1151             set80211param(drv, IEEE80211_IOC_WPA,
1152                           params->wpa_ie[0] == WLAN_EID_RSN ? 2 : 1) < 0)
1153                 return -1;
1154
1155         os_memset(&mlme, 0, sizeof(mlme));
1156         mlme.im_op = IEEE80211_MLME_ASSOC;
1157 #ifdef NEW_FREEBSD_MLME_ASSOC
1158         if (params->ssid != NULL)
1159                 os_memcpy(mlme.im_ssid, params->ssid, params->ssid_len);
1160         mlme.im_ssid_len = params->ssid_len;
1161 #endif
1162         if (params->bssid != NULL)
1163                 os_memcpy(mlme.im_macaddr, params->bssid, IEEE80211_ADDR_LEN);
1164         if (set80211var(drv, IEEE80211_IOC_MLME, &mlme, sizeof(mlme)) < 0)
1165                 return -1;
1166         return 0;
1167 }
1168
1169 static int
1170 wpa_driver_bsd_set_auth_alg(void *priv, int auth_alg)
1171 {
1172         struct wpa_driver_bsd_data *drv = priv;
1173         int authmode;
1174
1175         if ((auth_alg & AUTH_ALG_OPEN_SYSTEM) &&
1176             (auth_alg & AUTH_ALG_SHARED_KEY))
1177                 authmode = IEEE80211_AUTH_AUTO;
1178         else if (auth_alg & AUTH_ALG_SHARED_KEY)
1179                 authmode = IEEE80211_AUTH_SHARED;
1180         else
1181                 authmode = IEEE80211_AUTH_OPEN;
1182
1183         return set80211param(drv, IEEE80211_IOC_AUTHMODE, authmode);
1184 }
1185
1186 static int
1187 wpa_driver_bsd_scan(void *priv, const u8 *ssid, size_t ssid_len)
1188 {
1189         struct wpa_driver_bsd_data *drv = priv;
1190         int flags;
1191
1192         /* NB: interface must be marked UP to do a scan */
1193         if (getifflags(drv, &flags) != 0 || setifflags(drv, flags | IFF_UP) != 0)
1194                 return -1;
1195
1196         /* set desired ssid before scan */
1197         if (wpa_driver_bsd_set_ssid(drv, ssid, ssid_len) < 0)
1198                 return -1;
1199
1200         /* NB: net80211 delivers a scan complete event so no need to poll */
1201         return set80211param(drv, IEEE80211_IOC_SCAN_REQ, 0);
1202 }
1203
1204 #include <net/route.h>
1205 #if __FreeBSD__
1206 #include <net80211/ieee80211_freebsd.h>
1207 #endif
1208 #if __NetBSD__
1209 #include <net80211/ieee80211_netbsd.h>
1210 #endif
1211
1212 static void
1213 wpa_driver_bsd_event_receive(int sock, void *ctx, void *sock_ctx)
1214 {
1215         struct wpa_driver_bsd_data *drv = sock_ctx;
1216         char buf[2048];
1217         struct if_announcemsghdr *ifan;
1218         struct if_msghdr *ifm;
1219         struct rt_msghdr *rtm;
1220         union wpa_event_data event;
1221         struct ieee80211_michael_event *mic;
1222         int n;
1223
1224         n = read(sock, buf, sizeof(buf));
1225         if (n < 0) {
1226                 if (errno != EINTR && errno != EAGAIN)
1227                         perror("read(PF_ROUTE)");
1228                 return;
1229         }
1230
1231         rtm = (struct rt_msghdr *) buf;
1232         if (rtm->rtm_version != RTM_VERSION) {
1233                 wpa_printf(MSG_DEBUG, "Routing message version %d not "
1234                         "understood\n", rtm->rtm_version);
1235                 return;
1236         }
1237         os_memset(&event, 0, sizeof(event));
1238         switch (rtm->rtm_type) {
1239         case RTM_IFANNOUNCE:
1240                 ifan = (struct if_announcemsghdr *) rtm;
1241                 if (ifan->ifan_index != drv->ifindex)
1242                         break;
1243                 strlcpy(event.interface_status.ifname, drv->ifname,
1244                         sizeof(event.interface_status.ifname));
1245                 switch (ifan->ifan_what) {
1246                 case IFAN_DEPARTURE:
1247                         event.interface_status.ievent = EVENT_INTERFACE_REMOVED;
1248                 default:
1249                         return;
1250                 }
1251                 wpa_printf(MSG_DEBUG, "RTM_IFANNOUNCE: Interface '%s' %s",
1252                            event.interface_status.ifname,
1253                            ifan->ifan_what == IFAN_DEPARTURE ?
1254                                 "removed" : "added");
1255                 wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &event);
1256                 break;
1257         case RTM_IEEE80211:
1258                 ifan = (struct if_announcemsghdr *) rtm;
1259                 if (ifan->ifan_index != drv->ifindex)
1260                         break;
1261                 switch (ifan->ifan_what) {
1262                 case RTM_IEEE80211_ASSOC:
1263                 case RTM_IEEE80211_REASSOC:
1264                         wpa_supplicant_event(ctx, EVENT_ASSOC, NULL);
1265                         break;
1266                 case RTM_IEEE80211_DISASSOC:
1267                         wpa_supplicant_event(ctx, EVENT_DISASSOC, NULL);
1268                         break;
1269                 case RTM_IEEE80211_SCAN:
1270                         wpa_supplicant_event(ctx, EVENT_SCAN_RESULTS, NULL);
1271                         break;
1272                 case RTM_IEEE80211_REPLAY:
1273                         /* ignore */
1274                         break;
1275                 case RTM_IEEE80211_MICHAEL:
1276                         mic = (struct ieee80211_michael_event *) &ifan[1];
1277                         wpa_printf(MSG_DEBUG,
1278                                 "Michael MIC failure wireless event: "
1279                                 "keyix=%u src_addr=" MACSTR, mic->iev_keyix,
1280                                 MAC2STR(mic->iev_src));
1281
1282                         os_memset(&event, 0, sizeof(event));
1283                         event.michael_mic_failure.unicast =
1284                                 !IEEE80211_IS_MULTICAST(mic->iev_dst);
1285                         wpa_supplicant_event(ctx, EVENT_MICHAEL_MIC_FAILURE,
1286                                 &event);
1287                         break;
1288                 }
1289                 break;
1290         case RTM_IFINFO:
1291                 ifm = (struct if_msghdr *) rtm;
1292                 if (ifm->ifm_index != drv->ifindex)
1293                         break;
1294                 if ((rtm->rtm_flags & RTF_UP) == 0) {
1295                         strlcpy(event.interface_status.ifname, drv->ifname,
1296                                 sizeof(event.interface_status.ifname));
1297                         event.interface_status.ievent = EVENT_INTERFACE_REMOVED;
1298                         wpa_printf(MSG_DEBUG, "RTM_IFINFO: Interface '%s' DOWN",
1299                                    event.interface_status.ifname);
1300                         wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &event);
1301                 }
1302                 break;
1303         }
1304 }
1305
1306 /* Compare function for sorting scan results. Return >0 if @b is consider
1307  * better. */
1308 static int
1309 wpa_scan_result_compar(const void *a, const void *b)
1310 {
1311         const struct wpa_scan_result *wa = a;
1312         const struct wpa_scan_result *wb = b;
1313
1314         /* WPA/WPA2 support preferred */
1315         if ((wb->wpa_ie_len || wb->rsn_ie_len) &&
1316             !(wa->wpa_ie_len || wa->rsn_ie_len))
1317                 return 1;
1318         if (!(wb->wpa_ie_len || wb->rsn_ie_len) &&
1319             (wa->wpa_ie_len || wa->rsn_ie_len))
1320                 return -1;
1321
1322         /* privacy support preferred */
1323         if ((wa->caps & IEEE80211_CAPINFO_PRIVACY) &&
1324             (wb->caps & IEEE80211_CAPINFO_PRIVACY) == 0)
1325                 return 1;
1326         if ((wa->caps & IEEE80211_CAPINFO_PRIVACY) == 0 &&
1327             (wb->caps & IEEE80211_CAPINFO_PRIVACY))
1328                 return -1;
1329
1330         /* best/max rate preferred if signal level close enough XXX */
1331         if (wa->maxrate != wb->maxrate && abs(wb->level - wa->level) < 5)
1332                 return wb->maxrate - wa->maxrate;
1333
1334         /* use freq for channel preference */
1335
1336         /* all things being equal, use signal level */
1337         return wb->level - wa->level;
1338 }
1339
1340 static int
1341 getmaxrate(uint8_t rates[15], uint8_t nrates)
1342 {
1343         int i, maxrate = -1;
1344
1345         for (i = 0; i < nrates; i++) {
1346                 int rate = rates[i] & IEEE80211_RATE_VAL;
1347                 if (rate > maxrate)
1348                         rate = maxrate;
1349         }
1350         return maxrate;
1351 }
1352
1353 /* unalligned little endian access */     
1354 #define LE_READ_4(p)                                    \
1355         ((u_int32_t)                                    \
1356          ((((const u_int8_t *)(p))[0]      ) |          \
1357           (((const u_int8_t *)(p))[1] <<  8) |          \
1358           (((const u_int8_t *)(p))[2] << 16) |          \
1359           (((const u_int8_t *)(p))[3] << 24)))
1360
1361 static int __inline
1362 iswpaoui(const u_int8_t *frm)
1363 {
1364         return frm[1] > 3 && LE_READ_4(frm+2) == ((WPA_OUI_TYPE<<24)|WPA_OUI);
1365 }
1366
1367 static int
1368 wpa_driver_bsd_get_scan_results(void *priv,
1369                                      struct wpa_scan_result *results,
1370                                      size_t max_size)
1371 {
1372 #define min(a,b)        ((a)>(b)?(b):(a))
1373         struct wpa_driver_bsd_data *drv = priv;
1374         uint8_t buf[24*1024];
1375         uint8_t *cp, *vp;
1376         struct ieee80211req_scan_result *sr;
1377         struct wpa_scan_result *wsr;
1378         int len, ielen;
1379
1380         os_memset(results, 0, max_size * sizeof(struct wpa_scan_result));
1381
1382         len = get80211var(drv, IEEE80211_IOC_SCAN_RESULTS, buf, sizeof(buf));
1383         if (len < 0)
1384                 return -1;
1385         cp = buf;
1386         wsr = results;
1387         while (len >= sizeof(struct ieee80211req_scan_result)) {
1388                 sr = (struct ieee80211req_scan_result *) cp;
1389                 os_memcpy(wsr->bssid, sr->isr_bssid, IEEE80211_ADDR_LEN);
1390                 wsr->ssid_len = sr->isr_ssid_len;
1391                 wsr->freq = sr->isr_freq;
1392                 wsr->noise = sr->isr_noise;
1393                 wsr->qual = sr->isr_rssi;
1394                 wsr->level = 0;         /* XXX? */
1395                 wsr->caps = sr->isr_capinfo;
1396                 wsr->maxrate = getmaxrate(sr->isr_rates, sr->isr_nrates);
1397                 vp = (u_int8_t *)(sr+1);
1398                 os_memcpy(wsr->ssid, vp, sr->isr_ssid_len);
1399                 if (sr->isr_ie_len > 0) {
1400                         vp += sr->isr_ssid_len;
1401                         ielen = sr->isr_ie_len;
1402                         while (ielen > 0) {
1403                                 switch (vp[0]) {
1404                                 case IEEE80211_ELEMID_VENDOR:
1405                                         if (!iswpaoui(vp))
1406                                                 break;
1407                                         wsr->wpa_ie_len =
1408                                             min(2+vp[1], SSID_MAX_WPA_IE_LEN);
1409                                         os_memcpy(wsr->wpa_ie, vp,
1410                                                   wsr->wpa_ie_len);
1411                                         break;
1412                                 case IEEE80211_ELEMID_RSN:
1413                                         wsr->rsn_ie_len =
1414                                             min(2+vp[1], SSID_MAX_WPA_IE_LEN);
1415                                         os_memcpy(wsr->rsn_ie, vp,
1416                                                   wsr->rsn_ie_len);
1417                                         break;
1418                                 }
1419                                 ielen -= 2+vp[1];
1420                                 vp += 2+vp[1];
1421                         }
1422                 }
1423
1424                 cp += sr->isr_len, len -= sr->isr_len;
1425                 wsr++;
1426         }
1427         qsort(results, wsr - results, sizeof(struct wpa_scan_result),
1428               wpa_scan_result_compar);
1429
1430         wpa_printf(MSG_DEBUG, "Received %d bytes of scan results (%d BSSes)",
1431                    len, wsr - results);
1432
1433         return wsr - results;
1434 #undef min
1435 }
1436
1437 static void *
1438 wpa_driver_bsd_init(void *ctx, const char *ifname)
1439 {
1440 #define GETPARAM(drv, param, v) \
1441         (((v) = get80211param(drv, param)) != -1)
1442         struct wpa_driver_bsd_data *drv;
1443
1444         drv = os_zalloc(sizeof(*drv));
1445         if (drv == NULL)
1446                 return NULL;
1447         /*
1448          * NB: We require the interface name be mappable to an index.
1449          *     This implies we do not support having wpa_supplicant
1450          *     wait for an interface to appear.  This seems ok; that
1451          *     doesn't belong here; it's really the job of devd.
1452          */
1453         drv->ifindex = if_nametoindex(ifname);
1454         if (drv->ifindex == 0) {
1455                 wpa_printf(MSG_DEBUG, "%s: interface %s does not exist",
1456                            __func__, ifname);
1457                 goto fail1;
1458         }
1459         drv->sock = socket(PF_INET, SOCK_DGRAM, 0);
1460         if (drv->sock < 0)
1461                 goto fail1;
1462         drv->route = socket(PF_ROUTE, SOCK_RAW, 0);
1463         if (drv->route < 0)
1464                 goto fail;
1465         eloop_register_read_sock(drv->route,
1466                 wpa_driver_bsd_event_receive, ctx, drv);
1467
1468         drv->ctx = ctx;
1469         os_strlcpy(drv->ifname, ifname, sizeof(drv->ifname));
1470
1471         if (!GETPARAM(drv, IEEE80211_IOC_ROAMING, drv->prev_roaming)) {
1472                 wpa_printf(MSG_DEBUG, "%s: failed to get roaming state: %s",
1473                         __func__, strerror(errno));
1474                 goto fail;
1475         }
1476         if (!GETPARAM(drv, IEEE80211_IOC_PRIVACY, drv->prev_privacy)) {
1477                 wpa_printf(MSG_DEBUG, "%s: failed to get privacy state: %s",
1478                         __func__, strerror(errno));
1479                 goto fail;
1480         }
1481         if (!GETPARAM(drv, IEEE80211_IOC_WPA, drv->prev_wpa)) {
1482                 wpa_printf(MSG_DEBUG, "%s: failed to get wpa state: %s",
1483                         __func__, strerror(errno));
1484                 goto fail;
1485         }
1486         if (set80211param(drv, IEEE80211_IOC_ROAMING, IEEE80211_ROAMING_MANUAL) < 0) {
1487                 wpa_printf(MSG_DEBUG, "%s: failed to set wpa_supplicant-based "
1488                            "roaming: %s", __func__, strerror(errno));
1489                 goto fail;
1490         }
1491
1492         if (set80211param(drv, IEEE80211_IOC_WPA, 1+2) < 0) {
1493                 wpa_printf(MSG_DEBUG, "%s: failed to enable WPA support %s",
1494                            __func__, strerror(errno));
1495                 goto fail;
1496         }
1497
1498         return drv;
1499 fail:
1500         close(drv->sock);
1501 fail1:
1502         os_free(drv);
1503         return NULL;
1504 #undef GETPARAM
1505 }
1506
1507 static void
1508 wpa_driver_bsd_deinit(void *priv)
1509 {
1510         struct wpa_driver_bsd_data *drv = priv;
1511         int flags;
1512
1513         eloop_unregister_read_sock(drv->route);
1514
1515         /* NB: mark interface down */
1516         if (getifflags(drv, &flags) == 0)
1517                 (void) setifflags(drv, flags &~ IFF_UP);
1518
1519         wpa_driver_bsd_set_wpa_internal(drv, drv->prev_wpa, drv->prev_privacy);
1520         if (set80211param(drv, IEEE80211_IOC_ROAMING, drv->prev_roaming) < 0)
1521                 wpa_printf(MSG_DEBUG, "%s: failed to restore roaming state",
1522                         __func__);
1523
1524         (void) close(drv->route);               /* ioctl socket */
1525         (void) close(drv->sock);                /* event socket */
1526         os_free(drv);
1527 }
1528
1529
1530 const struct wpa_driver_ops wpa_driver_bsd_ops = {
1531         .name                   = "bsd",
1532         .desc                   = "BSD 802.11 support (Atheros, etc.)",
1533         .init                   = wpa_driver_bsd_init,
1534         .deinit                 = wpa_driver_bsd_deinit,
1535         .get_bssid              = wpa_driver_bsd_get_bssid,
1536         .get_ssid               = wpa_driver_bsd_get_ssid,
1537         .set_wpa                = wpa_driver_bsd_set_wpa,
1538         .set_key                = wpa_driver_bsd_set_key,
1539         .set_countermeasures    = wpa_driver_bsd_set_countermeasures,
1540         .set_drop_unencrypted   = wpa_driver_bsd_set_drop_unencrypted,
1541         .scan                   = wpa_driver_bsd_scan,
1542         .get_scan_results       = wpa_driver_bsd_get_scan_results,
1543         .deauthenticate         = wpa_driver_bsd_deauthenticate,
1544         .disassociate           = wpa_driver_bsd_disassociate,
1545         .associate              = wpa_driver_bsd_associate,
1546         .set_auth_alg           = wpa_driver_bsd_set_auth_alg,
1547 };
1548
1549 #endif /* HOSTAPD */