rx_data.c 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661
  1. /*
  2. * Received Data frame processing
  3. * Copyright (c) 2010-2015, Jouni Malinen <j@w1.fi>
  4. *
  5. * This software may be distributed under the terms of the BSD license.
  6. * See README for more details.
  7. */
  8. #include "utils/includes.h"
  9. #include "utils/common.h"
  10. #include "common/defs.h"
  11. #include "common/ieee802_11_defs.h"
  12. #include "wlantest.h"
  13. static const char * data_stype(u16 stype)
  14. {
  15. switch (stype) {
  16. case WLAN_FC_STYPE_DATA:
  17. return "DATA";
  18. case WLAN_FC_STYPE_DATA_CFACK:
  19. return "DATA-CFACK";
  20. case WLAN_FC_STYPE_DATA_CFPOLL:
  21. return "DATA-CFPOLL";
  22. case WLAN_FC_STYPE_DATA_CFACKPOLL:
  23. return "DATA-CFACKPOLL";
  24. case WLAN_FC_STYPE_NULLFUNC:
  25. return "NULLFUNC";
  26. case WLAN_FC_STYPE_CFACK:
  27. return "CFACK";
  28. case WLAN_FC_STYPE_CFPOLL:
  29. return "CFPOLL";
  30. case WLAN_FC_STYPE_CFACKPOLL:
  31. return "CFACKPOLL";
  32. case WLAN_FC_STYPE_QOS_DATA:
  33. return "QOSDATA";
  34. case WLAN_FC_STYPE_QOS_DATA_CFACK:
  35. return "QOSDATA-CFACK";
  36. case WLAN_FC_STYPE_QOS_DATA_CFPOLL:
  37. return "QOSDATA-CFPOLL";
  38. case WLAN_FC_STYPE_QOS_DATA_CFACKPOLL:
  39. return "QOSDATA-CFACKPOLL";
  40. case WLAN_FC_STYPE_QOS_NULL:
  41. return "QOS-NULL";
  42. case WLAN_FC_STYPE_QOS_CFPOLL:
  43. return "QOS-CFPOLL";
  44. case WLAN_FC_STYPE_QOS_CFACKPOLL:
  45. return "QOS-CFACKPOLL";
  46. }
  47. return "??";
  48. }
  49. static void rx_data_eth(struct wlantest *wt, const u8 *bssid,
  50. const u8 *sta_addr, const u8 *dst, const u8 *src,
  51. u16 ethertype, const u8 *data, size_t len, int prot,
  52. const u8 *peer_addr)
  53. {
  54. switch (ethertype) {
  55. case ETH_P_PAE:
  56. rx_data_eapol(wt, bssid, sta_addr, dst, src, data, len, prot);
  57. break;
  58. case ETH_P_IP:
  59. rx_data_ip(wt, bssid, sta_addr, dst, src, data, len,
  60. peer_addr);
  61. break;
  62. case 0x890d:
  63. rx_data_80211_encap(wt, bssid, sta_addr, dst, src, data, len);
  64. break;
  65. }
  66. }
  67. static void rx_data_process(struct wlantest *wt, const u8 *bssid,
  68. const u8 *sta_addr,
  69. const u8 *dst, const u8 *src,
  70. const u8 *data, size_t len, int prot,
  71. const u8 *peer_addr)
  72. {
  73. if (len == 0)
  74. return;
  75. if (len >= 8 && os_memcmp(data, "\xaa\xaa\x03\x00\x00\x00", 6) == 0) {
  76. rx_data_eth(wt, bssid, sta_addr, dst, src,
  77. WPA_GET_BE16(data + 6), data + 8, len - 8, prot,
  78. peer_addr);
  79. return;
  80. }
  81. wpa_hexdump(MSG_DEBUG, "Unrecognized LLC", data, len > 8 ? 8 : len);
  82. }
  83. static u8 * try_all_ptk(struct wlantest *wt, int pairwise_cipher,
  84. const struct ieee80211_hdr *hdr,
  85. const u8 *data, size_t data_len, size_t *decrypted_len)
  86. {
  87. struct wlantest_ptk *ptk;
  88. u8 *decrypted;
  89. int prev_level = wpa_debug_level;
  90. wpa_debug_level = MSG_WARNING;
  91. dl_list_for_each(ptk, &wt->ptk, struct wlantest_ptk, list) {
  92. unsigned int tk_len = ptk->ptk_len - 32;
  93. decrypted = NULL;
  94. if ((pairwise_cipher == WPA_CIPHER_CCMP ||
  95. pairwise_cipher == 0) && tk_len == 16) {
  96. decrypted = ccmp_decrypt(ptk->ptk.tk, hdr, data,
  97. data_len, decrypted_len);
  98. } else if ((pairwise_cipher == WPA_CIPHER_CCMP_256 ||
  99. pairwise_cipher == 0) && tk_len == 32) {
  100. decrypted = ccmp_256_decrypt(ptk->ptk.tk, hdr, data,
  101. data_len, decrypted_len);
  102. } else if ((pairwise_cipher == WPA_CIPHER_GCMP ||
  103. pairwise_cipher == WPA_CIPHER_GCMP_256 ||
  104. pairwise_cipher == 0) &&
  105. (tk_len == 16 || tk_len == 32)) {
  106. decrypted = gcmp_decrypt(ptk->ptk.tk, tk_len, hdr,
  107. data, data_len, decrypted_len);
  108. } else if ((pairwise_cipher == WPA_CIPHER_TKIP ||
  109. pairwise_cipher == 0) && tk_len == 32) {
  110. decrypted = tkip_decrypt(ptk->ptk.tk, hdr, data,
  111. data_len, decrypted_len);
  112. }
  113. if (decrypted) {
  114. wpa_debug_level = prev_level;
  115. add_note(wt, MSG_DEBUG, "Found PTK match from list of all known PTKs");
  116. return decrypted;
  117. }
  118. }
  119. wpa_debug_level = prev_level;
  120. return NULL;
  121. }
  122. static void rx_data_bss_prot_group(struct wlantest *wt,
  123. const struct ieee80211_hdr *hdr,
  124. const u8 *qos, const u8 *dst, const u8 *src,
  125. const u8 *data, size_t len)
  126. {
  127. struct wlantest_bss *bss;
  128. int keyid;
  129. u8 *decrypted = NULL;
  130. size_t dlen;
  131. u8 pn[6];
  132. bss = bss_get(wt, hdr->addr2);
  133. if (bss == NULL)
  134. return;
  135. if (len < 4) {
  136. add_note(wt, MSG_INFO, "Too short group addressed data frame");
  137. return;
  138. }
  139. if (bss->group_cipher & (WPA_CIPHER_TKIP | WPA_CIPHER_CCMP) &&
  140. !(data[3] & 0x20)) {
  141. add_note(wt, MSG_INFO, "Expected TKIP/CCMP frame from "
  142. MACSTR " did not have ExtIV bit set to 1",
  143. MAC2STR(bss->bssid));
  144. return;
  145. }
  146. if (bss->group_cipher == WPA_CIPHER_TKIP) {
  147. if (data[3] & 0x1f) {
  148. add_note(wt, MSG_INFO, "TKIP frame from " MACSTR
  149. " used non-zero reserved bit",
  150. MAC2STR(bss->bssid));
  151. }
  152. if (data[1] != ((data[0] | 0x20) & 0x7f)) {
  153. add_note(wt, MSG_INFO, "TKIP frame from " MACSTR
  154. " used incorrect WEPSeed[1] (was 0x%x, "
  155. "expected 0x%x)",
  156. MAC2STR(bss->bssid), data[1],
  157. (data[0] | 0x20) & 0x7f);
  158. }
  159. } else if (bss->group_cipher == WPA_CIPHER_CCMP) {
  160. if (data[2] != 0 || (data[3] & 0x1f) != 0) {
  161. add_note(wt, MSG_INFO, "CCMP frame from " MACSTR
  162. " used non-zero reserved bit",
  163. MAC2STR(bss->bssid));
  164. }
  165. }
  166. keyid = data[3] >> 6;
  167. if (bss->gtk_len[keyid] == 0 && bss->group_cipher != WPA_CIPHER_WEP40)
  168. {
  169. add_note(wt, MSG_MSGDUMP, "No GTK known to decrypt the frame "
  170. "(A2=" MACSTR " KeyID=%d)",
  171. MAC2STR(hdr->addr2), keyid);
  172. return;
  173. }
  174. if (bss->group_cipher == WPA_CIPHER_TKIP)
  175. tkip_get_pn(pn, data);
  176. else if (bss->group_cipher == WPA_CIPHER_WEP40)
  177. goto skip_replay_det;
  178. else
  179. ccmp_get_pn(pn, data);
  180. if (os_memcmp(pn, bss->rsc[keyid], 6) <= 0) {
  181. u16 seq_ctrl = le_to_host16(hdr->seq_ctrl);
  182. add_note(wt, MSG_INFO, "CCMP/TKIP replay detected: A1=" MACSTR
  183. " A2=" MACSTR " A3=" MACSTR " seq=%u frag=%u%s",
  184. MAC2STR(hdr->addr1), MAC2STR(hdr->addr2),
  185. MAC2STR(hdr->addr3),
  186. WLAN_GET_SEQ_SEQ(seq_ctrl),
  187. WLAN_GET_SEQ_FRAG(seq_ctrl),
  188. (le_to_host16(hdr->frame_control) & WLAN_FC_RETRY) ?
  189. " Retry" : "");
  190. wpa_hexdump(MSG_INFO, "RX PN", pn, 6);
  191. wpa_hexdump(MSG_INFO, "RSC", bss->rsc[keyid], 6);
  192. }
  193. skip_replay_det:
  194. if (bss->group_cipher == WPA_CIPHER_TKIP)
  195. decrypted = tkip_decrypt(bss->gtk[keyid], hdr, data, len,
  196. &dlen);
  197. else if (bss->group_cipher == WPA_CIPHER_WEP40)
  198. decrypted = wep_decrypt(wt, hdr, data, len, &dlen);
  199. else if (bss->group_cipher == WPA_CIPHER_CCMP)
  200. decrypted = ccmp_decrypt(bss->gtk[keyid], hdr, data, len,
  201. &dlen);
  202. else if (bss->group_cipher == WPA_CIPHER_CCMP_256)
  203. decrypted = ccmp_256_decrypt(bss->gtk[keyid], hdr, data, len,
  204. &dlen);
  205. else if (bss->group_cipher == WPA_CIPHER_GCMP ||
  206. bss->group_cipher == WPA_CIPHER_GCMP_256)
  207. decrypted = gcmp_decrypt(bss->gtk[keyid], bss->gtk_len[keyid],
  208. hdr, data, len, &dlen);
  209. if (decrypted) {
  210. rx_data_process(wt, bss->bssid, NULL, dst, src, decrypted,
  211. dlen, 1, NULL);
  212. os_memcpy(bss->rsc[keyid], pn, 6);
  213. write_pcap_decrypted(wt, (const u8 *) hdr, 24 + (qos ? 2 : 0),
  214. decrypted, dlen);
  215. } else
  216. add_note(wt, MSG_DEBUG, "Failed to decrypt frame");
  217. os_free(decrypted);
  218. }
  219. static void rx_data_bss_prot(struct wlantest *wt,
  220. const struct ieee80211_hdr *hdr, const u8 *qos,
  221. const u8 *dst, const u8 *src, const u8 *data,
  222. size_t len)
  223. {
  224. struct wlantest_bss *bss;
  225. struct wlantest_sta *sta, *sta2;
  226. int keyid;
  227. u16 fc = le_to_host16(hdr->frame_control);
  228. u8 *decrypted;
  229. size_t dlen;
  230. int tid;
  231. u8 pn[6], *rsc;
  232. struct wlantest_tdls *tdls = NULL, *found;
  233. const u8 *tk = NULL;
  234. int ptk_iter_done = 0;
  235. int try_ptk_iter = 0;
  236. if (hdr->addr1[0] & 0x01) {
  237. rx_data_bss_prot_group(wt, hdr, qos, dst, src, data, len);
  238. return;
  239. }
  240. if (fc & WLAN_FC_TODS) {
  241. bss = bss_get(wt, hdr->addr1);
  242. if (bss == NULL)
  243. return;
  244. sta = sta_get(bss, hdr->addr2);
  245. if (sta)
  246. sta->counters[WLANTEST_STA_COUNTER_PROT_DATA_TX]++;
  247. } else if (fc & WLAN_FC_FROMDS) {
  248. bss = bss_get(wt, hdr->addr2);
  249. if (bss == NULL)
  250. return;
  251. sta = sta_get(bss, hdr->addr1);
  252. } else {
  253. bss = bss_get(wt, hdr->addr3);
  254. if (bss == NULL)
  255. return;
  256. sta = sta_find(bss, hdr->addr2);
  257. sta2 = sta_find(bss, hdr->addr1);
  258. if (sta == NULL || sta2 == NULL)
  259. return;
  260. found = NULL;
  261. dl_list_for_each(tdls, &bss->tdls, struct wlantest_tdls, list)
  262. {
  263. if ((tdls->init == sta && tdls->resp == sta2) ||
  264. (tdls->init == sta2 && tdls->resp == sta)) {
  265. found = tdls;
  266. if (tdls->link_up)
  267. break;
  268. }
  269. }
  270. if (found) {
  271. if (!found->link_up)
  272. add_note(wt, MSG_DEBUG,
  273. "TDLS: Link not up, but Data "
  274. "frame seen");
  275. tk = found->tpk.tk;
  276. tdls = found;
  277. }
  278. }
  279. if ((sta == NULL ||
  280. (!sta->ptk_set && sta->pairwise_cipher != WPA_CIPHER_WEP40)) &&
  281. tk == NULL) {
  282. add_note(wt, MSG_MSGDUMP, "No PTK known to decrypt the frame");
  283. if (dl_list_empty(&wt->ptk))
  284. return;
  285. try_ptk_iter = 1;
  286. }
  287. if (len < 4) {
  288. add_note(wt, MSG_INFO, "Too short encrypted data frame");
  289. return;
  290. }
  291. if (sta == NULL)
  292. return;
  293. if (sta->pairwise_cipher & (WPA_CIPHER_TKIP | WPA_CIPHER_CCMP) &&
  294. !(data[3] & 0x20)) {
  295. add_note(wt, MSG_INFO, "Expected TKIP/CCMP frame from "
  296. MACSTR " did not have ExtIV bit set to 1",
  297. MAC2STR(src));
  298. return;
  299. }
  300. if (tk == NULL && sta->pairwise_cipher == WPA_CIPHER_TKIP) {
  301. if (data[3] & 0x1f) {
  302. add_note(wt, MSG_INFO, "TKIP frame from " MACSTR
  303. " used non-zero reserved bit",
  304. MAC2STR(hdr->addr2));
  305. }
  306. if (data[1] != ((data[0] | 0x20) & 0x7f)) {
  307. add_note(wt, MSG_INFO, "TKIP frame from " MACSTR
  308. " used incorrect WEPSeed[1] (was 0x%x, "
  309. "expected 0x%x)",
  310. MAC2STR(hdr->addr2), data[1],
  311. (data[0] | 0x20) & 0x7f);
  312. }
  313. } else if (tk || sta->pairwise_cipher == WPA_CIPHER_CCMP) {
  314. if (data[2] != 0 || (data[3] & 0x1f) != 0) {
  315. add_note(wt, MSG_INFO, "CCMP frame from " MACSTR
  316. " used non-zero reserved bit",
  317. MAC2STR(hdr->addr2));
  318. }
  319. }
  320. keyid = data[3] >> 6;
  321. if (keyid != 0) {
  322. add_note(wt, MSG_INFO, "Unexpected non-zero KeyID %d in "
  323. "individually addressed Data frame from " MACSTR,
  324. keyid, MAC2STR(hdr->addr2));
  325. }
  326. if (qos) {
  327. tid = qos[0] & 0x0f;
  328. if (fc & WLAN_FC_TODS)
  329. sta->tx_tid[tid]++;
  330. else
  331. sta->rx_tid[tid]++;
  332. } else {
  333. tid = 0;
  334. if (fc & WLAN_FC_TODS)
  335. sta->tx_tid[16]++;
  336. else
  337. sta->rx_tid[16]++;
  338. }
  339. if (tk) {
  340. if (os_memcmp(hdr->addr2, tdls->init->addr, ETH_ALEN) == 0)
  341. rsc = tdls->rsc_init[tid];
  342. else
  343. rsc = tdls->rsc_resp[tid];
  344. } else if (fc & WLAN_FC_TODS)
  345. rsc = sta->rsc_tods[tid];
  346. else
  347. rsc = sta->rsc_fromds[tid];
  348. if (tk == NULL && sta->pairwise_cipher == WPA_CIPHER_TKIP)
  349. tkip_get_pn(pn, data);
  350. else if (sta->pairwise_cipher == WPA_CIPHER_WEP40)
  351. goto skip_replay_det;
  352. else
  353. ccmp_get_pn(pn, data);
  354. if (os_memcmp(pn, rsc, 6) <= 0) {
  355. u16 seq_ctrl = le_to_host16(hdr->seq_ctrl);
  356. add_note(wt, MSG_INFO, "CCMP/TKIP replay detected: A1=" MACSTR
  357. " A2=" MACSTR " A3=" MACSTR " seq=%u frag=%u%s",
  358. MAC2STR(hdr->addr1), MAC2STR(hdr->addr2),
  359. MAC2STR(hdr->addr3),
  360. WLAN_GET_SEQ_SEQ(seq_ctrl),
  361. WLAN_GET_SEQ_FRAG(seq_ctrl),
  362. (le_to_host16(hdr->frame_control) & WLAN_FC_RETRY) ?
  363. " Retry" : "");
  364. wpa_hexdump(MSG_INFO, "RX PN", pn, 6);
  365. wpa_hexdump(MSG_INFO, "RSC", rsc, 6);
  366. }
  367. skip_replay_det:
  368. if (tk) {
  369. if (sta->pairwise_cipher == WPA_CIPHER_CCMP_256)
  370. decrypted = ccmp_256_decrypt(tk, hdr, data, len, &dlen);
  371. else if (sta->pairwise_cipher == WPA_CIPHER_GCMP ||
  372. sta->pairwise_cipher == WPA_CIPHER_GCMP_256)
  373. decrypted = gcmp_decrypt(tk, sta->tk_len, hdr, data,
  374. len, &dlen);
  375. else
  376. decrypted = ccmp_decrypt(tk, hdr, data, len, &dlen);
  377. } else if (sta->pairwise_cipher == WPA_CIPHER_TKIP) {
  378. decrypted = tkip_decrypt(sta->ptk.tk, hdr, data, len, &dlen);
  379. } else if (sta->pairwise_cipher == WPA_CIPHER_WEP40) {
  380. decrypted = wep_decrypt(wt, hdr, data, len, &dlen);
  381. } else if (sta->ptk_set) {
  382. if (sta->pairwise_cipher == WPA_CIPHER_CCMP_256)
  383. decrypted = ccmp_256_decrypt(sta->ptk.tk, hdr, data,
  384. len, &dlen);
  385. else if (sta->pairwise_cipher == WPA_CIPHER_GCMP ||
  386. sta->pairwise_cipher == WPA_CIPHER_GCMP_256)
  387. decrypted = gcmp_decrypt(sta->ptk.tk, sta->tk_len,
  388. hdr, data, len, &dlen);
  389. else
  390. decrypted = ccmp_decrypt(sta->ptk.tk, hdr, data, len,
  391. &dlen);
  392. } else {
  393. decrypted = try_all_ptk(wt, sta->pairwise_cipher, hdr, data,
  394. len, &dlen);
  395. ptk_iter_done = 1;
  396. }
  397. if (!decrypted && !ptk_iter_done) {
  398. decrypted = try_all_ptk(wt, sta->pairwise_cipher, hdr, data,
  399. len, &dlen);
  400. if (decrypted) {
  401. add_note(wt, MSG_DEBUG, "Current PTK did not work, but found a match from all known PTKs");
  402. }
  403. }
  404. if (decrypted) {
  405. u16 fc = le_to_host16(hdr->frame_control);
  406. const u8 *peer_addr = NULL;
  407. if (!(fc & (WLAN_FC_FROMDS | WLAN_FC_TODS)))
  408. peer_addr = hdr->addr1;
  409. os_memcpy(rsc, pn, 6);
  410. rx_data_process(wt, bss->bssid, sta->addr, dst, src, decrypted,
  411. dlen, 1, peer_addr);
  412. write_pcap_decrypted(wt, (const u8 *) hdr, 24 + (qos ? 2 : 0),
  413. decrypted, dlen);
  414. } else if (!try_ptk_iter)
  415. add_note(wt, MSG_DEBUG, "Failed to decrypt frame");
  416. os_free(decrypted);
  417. }
  418. static void rx_data_bss(struct wlantest *wt, const struct ieee80211_hdr *hdr,
  419. const u8 *qos, const u8 *dst, const u8 *src,
  420. const u8 *data, size_t len)
  421. {
  422. u16 fc = le_to_host16(hdr->frame_control);
  423. int prot = !!(fc & WLAN_FC_ISWEP);
  424. if (qos) {
  425. u8 ack = (qos[0] & 0x60) >> 5;
  426. wpa_printf(MSG_MSGDUMP, "BSS DATA: " MACSTR " -> " MACSTR
  427. " len=%u%s tid=%u%s%s",
  428. MAC2STR(src), MAC2STR(dst), (unsigned int) len,
  429. prot ? " Prot" : "", qos[0] & 0x0f,
  430. (qos[0] & 0x10) ? " EOSP" : "",
  431. ack == 0 ? "" :
  432. (ack == 1 ? " NoAck" :
  433. (ack == 2 ? " NoExpAck" : " BA")));
  434. } else {
  435. wpa_printf(MSG_MSGDUMP, "BSS DATA: " MACSTR " -> " MACSTR
  436. " len=%u%s",
  437. MAC2STR(src), MAC2STR(dst), (unsigned int) len,
  438. prot ? " Prot" : "");
  439. }
  440. if (prot)
  441. rx_data_bss_prot(wt, hdr, qos, dst, src, data, len);
  442. else {
  443. const u8 *bssid, *sta_addr, *peer_addr;
  444. struct wlantest_bss *bss;
  445. if (fc & WLAN_FC_TODS) {
  446. bssid = hdr->addr1;
  447. sta_addr = hdr->addr2;
  448. peer_addr = NULL;
  449. } else if (fc & WLAN_FC_FROMDS) {
  450. bssid = hdr->addr2;
  451. sta_addr = hdr->addr1;
  452. peer_addr = NULL;
  453. } else {
  454. bssid = hdr->addr3;
  455. sta_addr = hdr->addr2;
  456. peer_addr = hdr->addr1;
  457. }
  458. bss = bss_get(wt, bssid);
  459. if (bss) {
  460. struct wlantest_sta *sta = sta_get(bss, sta_addr);
  461. if (sta) {
  462. if (qos) {
  463. int tid = qos[0] & 0x0f;
  464. if (fc & WLAN_FC_TODS)
  465. sta->tx_tid[tid]++;
  466. else
  467. sta->rx_tid[tid]++;
  468. } else {
  469. if (fc & WLAN_FC_TODS)
  470. sta->tx_tid[16]++;
  471. else
  472. sta->rx_tid[16]++;
  473. }
  474. }
  475. }
  476. rx_data_process(wt, bssid, sta_addr, dst, src, data, len, 0,
  477. peer_addr);
  478. }
  479. }
  480. static struct wlantest_tdls * get_tdls(struct wlantest *wt, const u8 *bssid,
  481. const u8 *sta1_addr,
  482. const u8 *sta2_addr)
  483. {
  484. struct wlantest_bss *bss;
  485. struct wlantest_sta *sta1, *sta2;
  486. struct wlantest_tdls *tdls, *found = NULL;
  487. bss = bss_find(wt, bssid);
  488. if (bss == NULL)
  489. return NULL;
  490. sta1 = sta_find(bss, sta1_addr);
  491. if (sta1 == NULL)
  492. return NULL;
  493. sta2 = sta_find(bss, sta2_addr);
  494. if (sta2 == NULL)
  495. return NULL;
  496. dl_list_for_each(tdls, &bss->tdls, struct wlantest_tdls, list) {
  497. if ((tdls->init == sta1 && tdls->resp == sta2) ||
  498. (tdls->init == sta2 && tdls->resp == sta1)) {
  499. found = tdls;
  500. if (tdls->link_up)
  501. break;
  502. }
  503. }
  504. return found;
  505. }
  506. static void add_direct_link(struct wlantest *wt, const u8 *bssid,
  507. const u8 *sta1_addr, const u8 *sta2_addr)
  508. {
  509. struct wlantest_tdls *tdls;
  510. tdls = get_tdls(wt, bssid, sta1_addr, sta2_addr);
  511. if (tdls == NULL)
  512. return;
  513. if (tdls->link_up)
  514. tdls->counters[WLANTEST_TDLS_COUNTER_VALID_DIRECT_LINK]++;
  515. else
  516. tdls->counters[WLANTEST_TDLS_COUNTER_INVALID_DIRECT_LINK]++;
  517. }
  518. static void add_ap_path(struct wlantest *wt, const u8 *bssid,
  519. const u8 *sta1_addr, const u8 *sta2_addr)
  520. {
  521. struct wlantest_tdls *tdls;
  522. tdls = get_tdls(wt, bssid, sta1_addr, sta2_addr);
  523. if (tdls == NULL)
  524. return;
  525. if (tdls->link_up)
  526. tdls->counters[WLANTEST_TDLS_COUNTER_INVALID_AP_PATH]++;
  527. else
  528. tdls->counters[WLANTEST_TDLS_COUNTER_VALID_AP_PATH]++;
  529. }
  530. void rx_data(struct wlantest *wt, const u8 *data, size_t len)
  531. {
  532. const struct ieee80211_hdr *hdr;
  533. u16 fc, stype;
  534. size_t hdrlen;
  535. const u8 *qos = NULL;
  536. if (len < 24)
  537. return;
  538. hdr = (const struct ieee80211_hdr *) data;
  539. fc = le_to_host16(hdr->frame_control);
  540. stype = WLAN_FC_GET_STYPE(fc);
  541. hdrlen = 24;
  542. if ((fc & (WLAN_FC_TODS | WLAN_FC_FROMDS)) ==
  543. (WLAN_FC_TODS | WLAN_FC_FROMDS))
  544. hdrlen += ETH_ALEN;
  545. if (stype & 0x08) {
  546. qos = data + hdrlen;
  547. hdrlen += 2;
  548. }
  549. if (len < hdrlen)
  550. return;
  551. wt->rx_data++;
  552. switch (fc & (WLAN_FC_TODS | WLAN_FC_FROMDS)) {
  553. case 0:
  554. wpa_printf(MSG_EXCESSIVE, "DATA %s%s%s IBSS DA=" MACSTR " SA="
  555. MACSTR " BSSID=" MACSTR,
  556. data_stype(WLAN_FC_GET_STYPE(fc)),
  557. fc & WLAN_FC_PWRMGT ? " PwrMgt" : "",
  558. fc & WLAN_FC_ISWEP ? " Prot" : "",
  559. MAC2STR(hdr->addr1), MAC2STR(hdr->addr2),
  560. MAC2STR(hdr->addr3));
  561. add_direct_link(wt, hdr->addr3, hdr->addr1, hdr->addr2);
  562. rx_data_bss(wt, hdr, qos, hdr->addr1, hdr->addr2,
  563. data + hdrlen, len - hdrlen);
  564. break;
  565. case WLAN_FC_FROMDS:
  566. wpa_printf(MSG_EXCESSIVE, "DATA %s%s%s FromDS DA=" MACSTR
  567. " BSSID=" MACSTR " SA=" MACSTR,
  568. data_stype(WLAN_FC_GET_STYPE(fc)),
  569. fc & WLAN_FC_PWRMGT ? " PwrMgt" : "",
  570. fc & WLAN_FC_ISWEP ? " Prot" : "",
  571. MAC2STR(hdr->addr1), MAC2STR(hdr->addr2),
  572. MAC2STR(hdr->addr3));
  573. add_ap_path(wt, hdr->addr2, hdr->addr1, hdr->addr3);
  574. rx_data_bss(wt, hdr, qos, hdr->addr1, hdr->addr3,
  575. data + hdrlen, len - hdrlen);
  576. break;
  577. case WLAN_FC_TODS:
  578. wpa_printf(MSG_EXCESSIVE, "DATA %s%s%s ToDS BSSID=" MACSTR
  579. " SA=" MACSTR " DA=" MACSTR,
  580. data_stype(WLAN_FC_GET_STYPE(fc)),
  581. fc & WLAN_FC_PWRMGT ? " PwrMgt" : "",
  582. fc & WLAN_FC_ISWEP ? " Prot" : "",
  583. MAC2STR(hdr->addr1), MAC2STR(hdr->addr2),
  584. MAC2STR(hdr->addr3));
  585. add_ap_path(wt, hdr->addr1, hdr->addr3, hdr->addr2);
  586. rx_data_bss(wt, hdr, qos, hdr->addr3, hdr->addr2,
  587. data + hdrlen, len - hdrlen);
  588. break;
  589. case WLAN_FC_TODS | WLAN_FC_FROMDS:
  590. wpa_printf(MSG_EXCESSIVE, "DATA %s%s%s WDS RA=" MACSTR " TA="
  591. MACSTR " DA=" MACSTR " SA=" MACSTR,
  592. data_stype(WLAN_FC_GET_STYPE(fc)),
  593. fc & WLAN_FC_PWRMGT ? " PwrMgt" : "",
  594. fc & WLAN_FC_ISWEP ? " Prot" : "",
  595. MAC2STR(hdr->addr1), MAC2STR(hdr->addr2),
  596. MAC2STR(hdr->addr3),
  597. MAC2STR((const u8 *) (hdr + 1)));
  598. break;
  599. }
  600. }