123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049805080518052805380548055805680578058805980608061806280638064806580668067806880698070807180728073807480758076807780788079808080818082808380848085808680878088808980908091809280938094809580968097809880998100810181028103810481058106810781088109811081118112811381148115811681178118811981208121812281238124812581268127812881298130813181328133813481358136813781388139814081418142814381448145814681478148814981508151815281538154815581568157815881598160816181628163816481658166816781688169817081718172817381748175817681778178817981808181818281838184818581868187818881898190819181928193819481958196819781988199820082018202820382048205820682078208820982108211821282138214821582168217821882198220822182228223822482258226822782288229823082318232823382348235823682378238823982408241824282438244824582468247824882498250825182528253825482558256825782588259826082618262826382648265826682678268826982708271827282738274827582768277827882798280828182828283828482858286828782888289829082918292829382948295829682978298829983008301830283038304830583068307830883098310831183128313831483158316831783188319832083218322832383248325832683278328832983308331833283338334833583368337833883398340834183428343834483458346834783488349835083518352835383548355835683578358835983608361836283638364836583668367836883698370837183728373837483758376837783788379838083818382838383848385838683878388838983908391839283938394839583968397839883998400840184028403840484058406840784088409841084118412841384148415841684178418841984208421842284238424842584268427842884298430843184328433843484358436843784388439844084418442844384448445844684478448844984508451845284538454845584568457845884598460846184628463846484658466846784688469847084718472847384748475847684778478847984808481848284838484848584868487848884898490849184928493849484958496849784988499850085018502850385048505850685078508850985108511851285138514851585168517851885198520852185228523852485258526852785288529853085318532853385348535853685378538853985408541854285438544854585468547854885498550855185528553855485558556855785588559856085618562856385648565856685678568856985708571857285738574857585768577857885798580858185828583858485858586858785888589859085918592859385948595859685978598859986008601860286038604860586068607860886098610861186128613861486158616861786188619862086218622862386248625862686278628862986308631863286338634863586368637863886398640864186428643864486458646864786488649865086518652865386548655865686578658865986608661866286638664866586668667866886698670867186728673867486758676867786788679868086818682868386848685868686878688868986908691869286938694869586968697869886998700870187028703870487058706870787088709871087118712871387148715871687178718871987208721872287238724872587268727872887298730873187328733873487358736873787388739874087418742874387448745874687478748874987508751875287538754875587568757875887598760876187628763876487658766876787688769877087718772877387748775877687778778877987808781878287838784878587868787878887898790879187928793879487958796879787988799880088018802880388048805880688078808880988108811881288138814881588168817881888198820882188228823882488258826882788288829883088318832883388348835883688378838883988408841884288438844884588468847884888498850885188528853885488558856885788588859886088618862886388648865886688678868886988708871887288738874887588768877887888798880888188828883888488858886888788888889889088918892889388948895889688978898889989008901890289038904890589068907890889098910891189128913891489158916891789188919892089218922892389248925892689278928892989308931893289338934893589368937893889398940894189428943894489458946894789488949895089518952895389548955895689578958895989608961896289638964896589668967896889698970897189728973897489758976897789788979898089818982898389848985898689878988898989908991899289938994899589968997899889999000900190029003900490059006900790089009901090119012901390149015901690179018901990209021902290239024902590269027902890299030903190329033903490359036903790389039904090419042904390449045904690479048904990509051905290539054905590569057905890599060906190629063906490659066906790689069907090719072907390749075907690779078907990809081908290839084908590869087908890899090909190929093909490959096909790989099910091019102910391049105910691079108910991109111911291139114911591169117911891199120912191229123912491259126912791289129913091319132913391349135913691379138913991409141914291439144914591469147914891499150915191529153915491559156915791589159916091619162916391649165916691679168916991709171917291739174917591769177917891799180918191829183918491859186918791889189919091919192919391949195919691979198919992009201920292039204920592069207920892099210921192129213921492159216921792189219922092219222922392249225922692279228922992309231923292339234923592369237923892399240924192429243924492459246924792489249925092519252925392549255925692579258925992609261926292639264926592669267926892699270927192729273927492759276927792789279928092819282928392849285928692879288928992909291929292939294929592969297929892999300930193029303930493059306930793089309931093119312931393149315931693179318931993209321932293239324932593269327932893299330933193329333933493359336933793389339934093419342934393449345934693479348934993509351935293539354935593569357935893599360936193629363936493659366936793689369937093719372937393749375937693779378937993809381938293839384938593869387938893899390939193929393939493959396939793989399940094019402940394049405940694079408940994109411941294139414941594169417941894199420942194229423942494259426942794289429943094319432943394349435943694379438943994409441944294439444944594469447944894499450945194529453945494559456945794589459946094619462946394649465946694679468946994709471947294739474947594769477947894799480948194829483948494859486948794889489949094919492949394949495949694979498949995009501950295039504950595069507950895099510951195129513951495159516951795189519952095219522952395249525952695279528952995309531953295339534953595369537953895399540954195429543954495459546954795489549955095519552955395549555955695579558955995609561956295639564956595669567956895699570957195729573957495759576957795789579958095819582958395849585958695879588958995909591959295939594959595969597959895999600960196029603960496059606960796089609961096119612961396149615961696179618961996209621962296239624962596269627962896299630 |
- # WPS tests
- # Copyright (c) 2013-2015, Jouni Malinen <j@w1.fi>
- #
- # This software may be distributed under the terms of the BSD license.
- # See README for more details.
- from remotehost import remote_compatible
- import base64
- import binascii
- from Crypto.Cipher import AES
- import hashlib
- import hmac
- import os
- import time
- import stat
- import subprocess
- import logging
- logger = logging.getLogger()
- import re
- import socket
- import struct
- import httplib
- import urlparse
- import urllib
- import xml.etree.ElementTree as ET
- import StringIO
- import SocketServer
- import hwsim_utils
- import hostapd
- from wpasupplicant import WpaSupplicant
- from utils import HwsimSkip, alloc_fail, fail_test, skip_with_fips
- from utils import wait_fail_trigger
- from test_ap_eap import int_eap_server_params
- def wps_start_ap(apdev, ssid="test-wps-conf"):
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP" }
- return hostapd.add_ap(apdev, params)
- @remote_compatible
- def test_ap_wps_init(dev, apdev):
- """Initial AP configuration with first WPS Enrollee"""
- ssid = "test-wps"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "1" })
- logger.info("WPS provisioning step")
- hapd.request("WPS_PBC")
- if "PBC Status: Active" not in hapd.request("WPS_GET_STATUS"):
- raise Exception("PBC status not shown correctly")
- id = dev[0].add_network()
- dev[0].set_network_quoted(id, "ssid", "home")
- dev[0].set_network_quoted(id, "psk", "12345678")
- dev[0].request("ENABLE_NETWORK %s no-connect" % id)
- id = dev[0].add_network()
- dev[0].set_network_quoted(id, "ssid", "home2")
- dev[0].set_network(id, "bssid", "00:11:22:33:44:55")
- dev[0].set_network(id, "key_mgmt", "NONE")
- dev[0].request("ENABLE_NETWORK %s no-connect" % id)
- dev[0].request("WPS_PBC")
- dev[0].wait_connected(timeout=30)
- status = dev[0].get_status()
- if status['wpa_state'] != 'COMPLETED' or status['bssid'] != apdev[0]['bssid']:
- raise Exception("Not fully connected")
- if status['ssid'] != ssid:
- raise Exception("Unexpected SSID")
- if status['pairwise_cipher'] != 'CCMP':
- raise Exception("Unexpected encryption configuration")
- if status['key_mgmt'] != 'WPA2-PSK':
- raise Exception("Unexpected key_mgmt")
- status = hapd.request("WPS_GET_STATUS")
- if "PBC Status: Disabled" not in status:
- raise Exception("PBC status not shown correctly")
- if "Last WPS result: Success" not in status:
- raise Exception("Last WPS result not shown correctly")
- if "Peer Address: " + dev[0].p2p_interface_addr() not in status:
- raise Exception("Peer address not shown correctly")
- conf = hapd.request("GET_CONFIG")
- if "wps_state=configured" not in conf:
- raise Exception("AP not in WPS configured state")
- if "wpa=3" not in conf:
- raise Exception("AP not in WPA+WPA2 configuration")
- if "rsn_pairwise_cipher=CCMP TKIP" not in conf:
- raise Exception("Unexpected rsn_pairwise_cipher")
- if "wpa_pairwise_cipher=CCMP TKIP" not in conf:
- raise Exception("Unexpected wpa_pairwise_cipher")
- if "group_cipher=TKIP" not in conf:
- raise Exception("Unexpected group_cipher")
- if len(dev[0].list_networks()) != 3:
- raise Exception("Unexpected number of network blocks")
- def test_ap_wps_init_2ap_pbc(dev, apdev):
- """Initial two-radio AP configuration with first WPS PBC Enrollee"""
- ssid = "test-wps"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "1" }
- hapd = hostapd.add_ap(apdev[0], params)
- hostapd.add_ap(apdev[1], params)
- logger.info("WPS provisioning step")
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412", force_scan=True)
- dev[0].scan_for_bss(apdev[1]['bssid'], freq="2412")
- bss = dev[0].get_bss(apdev[0]['bssid'])
- if "[WPS-PBC]" not in bss['flags']:
- raise Exception("WPS-PBC flag missing from AP1")
- bss = dev[0].get_bss(apdev[1]['bssid'])
- if "[WPS-PBC]" not in bss['flags']:
- raise Exception("WPS-PBC flag missing from AP2")
- dev[0].dump_monitor()
- dev[0].request("SET wps_cred_processing 2")
- dev[0].request("WPS_PBC")
- ev = dev[0].wait_event(["WPS-CRED-RECEIVED"], timeout=30)
- dev[0].request("SET wps_cred_processing 0")
- if ev is None:
- raise Exception("WPS cred event not seen")
- if "100e" not in ev:
- raise Exception("WPS attributes not included in the cred event")
- dev[0].wait_connected(timeout=30)
- dev[1].scan_for_bss(apdev[0]['bssid'], freq="2412", force_scan=True)
- dev[1].scan_for_bss(apdev[1]['bssid'], freq="2412")
- bss = dev[1].get_bss(apdev[0]['bssid'])
- if "[WPS-PBC]" in bss['flags']:
- raise Exception("WPS-PBC flag not cleared from AP1")
- bss = dev[1].get_bss(apdev[1]['bssid'])
- if "[WPS-PBC]" in bss['flags']:
- raise Exception("WPS-PBC flag not cleared from AP2")
- def test_ap_wps_init_2ap_pin(dev, apdev):
- """Initial two-radio AP configuration with first WPS PIN Enrollee"""
- ssid = "test-wps"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "1" }
- hapd = hostapd.add_ap(apdev[0], params)
- hostapd.add_ap(apdev[1], params)
- logger.info("WPS provisioning step")
- pin = dev[0].wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412", force_scan=True)
- dev[0].scan_for_bss(apdev[1]['bssid'], freq="2412")
- bss = dev[0].get_bss(apdev[0]['bssid'])
- if "[WPS-AUTH]" not in bss['flags']:
- raise Exception("WPS-AUTH flag missing from AP1")
- bss = dev[0].get_bss(apdev[1]['bssid'])
- if "[WPS-AUTH]" not in bss['flags']:
- raise Exception("WPS-AUTH flag missing from AP2")
- dev[0].dump_monitor()
- dev[0].request("WPS_PIN any " + pin)
- dev[0].wait_connected(timeout=30)
- dev[1].scan_for_bss(apdev[0]['bssid'], freq="2412", force_scan=True)
- dev[1].scan_for_bss(apdev[1]['bssid'], freq="2412")
- bss = dev[1].get_bss(apdev[0]['bssid'])
- if "[WPS-AUTH]" in bss['flags']:
- raise Exception("WPS-AUTH flag not cleared from AP1")
- bss = dev[1].get_bss(apdev[1]['bssid'])
- if "[WPS-AUTH]" in bss['flags']:
- raise Exception("WPS-AUTH flag not cleared from AP2")
- @remote_compatible
- def test_ap_wps_init_through_wps_config(dev, apdev):
- """Initial AP configuration using wps_config command"""
- ssid = "test-wps-init-config"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "1" })
- if "FAIL" in hapd.request("WPS_CONFIG " + ssid.encode("hex") + " WPA2PSK CCMP " + "12345678".encode("hex")):
- raise Exception("WPS_CONFIG command failed")
- ev = hapd.wait_event(["WPS-NEW-AP-SETTINGS"], timeout=5)
- if ev is None:
- raise Exception("Timeout on WPS-NEW-AP-SETTINGS events")
- # It takes some time for the AP to update Beacon and Probe Response frames,
- # so wait here before requesting the scan to be started to avoid adding
- # extra five second wait to the test due to fetching obsolete scan results.
- hapd.ping()
- time.sleep(0.2)
- dev[0].connect(ssid, psk="12345678", scan_freq="2412", proto="WPA2",
- pairwise="CCMP", group="CCMP")
- @remote_compatible
- def test_ap_wps_init_through_wps_config_2(dev, apdev):
- """AP configuration using wps_config and wps_cred_processing=2"""
- ssid = "test-wps-init-config"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "1",
- "wps_cred_processing": "2" })
- if "FAIL" in hapd.request("WPS_CONFIG " + ssid.encode("hex") + " WPA2PSK CCMP " + "12345678".encode("hex")):
- raise Exception("WPS_CONFIG command failed")
- ev = hapd.wait_event(["WPS-NEW-AP-SETTINGS"], timeout=5)
- if ev is None:
- raise Exception("Timeout on WPS-NEW-AP-SETTINGS events")
- if "100e" not in ev:
- raise Exception("WPS-NEW-AP-SETTINGS did not include Credential")
- @remote_compatible
- def test_ap_wps_invalid_wps_config_passphrase(dev, apdev):
- """AP configuration using wps_config command with invalid passphrase"""
- ssid = "test-wps-init-config"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "1" })
- if "FAIL" not in hapd.request("WPS_CONFIG " + ssid.encode("hex") + " WPA2PSK CCMP " + "1234567".encode("hex")):
- raise Exception("Invalid WPS_CONFIG command accepted")
- def test_ap_wps_conf(dev, apdev):
- """WPS PBC provisioning with configured AP"""
- ssid = "test-wps-conf"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- logger.info("WPS provisioning step")
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].dump_monitor()
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- dev[0].wait_connected(timeout=30)
- status = dev[0].get_status()
- if status['wpa_state'] != 'COMPLETED':
- raise Exception("Not fully connected")
- if status['bssid'] != apdev[0]['bssid']:
- raise Exception("Unexpected BSSID")
- if status['ssid'] != ssid:
- raise Exception("Unexpected SSID")
- if status['pairwise_cipher'] != 'CCMP' or status['group_cipher'] != 'CCMP':
- raise Exception("Unexpected encryption configuration")
- if status['key_mgmt'] != 'WPA2-PSK':
- raise Exception("Unexpected key_mgmt")
- sta = hapd.get_sta(dev[0].p2p_interface_addr())
- if 'wpsDeviceName' not in sta or sta['wpsDeviceName'] != "Device A":
- raise Exception("Device name not available in STA command")
- def test_ap_wps_conf_5ghz(dev, apdev):
- """WPS PBC provisioning with configured AP on 5 GHz band"""
- try:
- hapd = None
- ssid = "test-wps-conf"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "country_code": "FI", "hw_mode": "a", "channel": "36" }
- hapd = hostapd.add_ap(apdev[0], params)
- logger.info("WPS provisioning step")
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="5180")
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- dev[0].wait_connected(timeout=30)
- sta = hapd.get_sta(dev[0].p2p_interface_addr())
- if 'wpsDeviceName' not in sta or sta['wpsDeviceName'] != "Device A":
- raise Exception("Device name not available in STA command")
- finally:
- dev[0].request("DISCONNECT")
- if hapd:
- hapd.request("DISABLE")
- subprocess.call(['iw', 'reg', 'set', '00'])
- dev[0].flush_scan_cache()
- def test_ap_wps_conf_chan14(dev, apdev):
- """WPS PBC provisioning with configured AP on channel 14"""
- try:
- hapd = None
- ssid = "test-wps-conf"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "country_code": "JP", "hw_mode": "b", "channel": "14" }
- hapd = hostapd.add_ap(apdev[0], params)
- logger.info("WPS provisioning step")
- hapd.request("WPS_PBC")
- dev[0].request("WPS_PBC")
- dev[0].wait_connected(timeout=30)
- sta = hapd.get_sta(dev[0].p2p_interface_addr())
- if 'wpsDeviceName' not in sta or sta['wpsDeviceName'] != "Device A":
- raise Exception("Device name not available in STA command")
- finally:
- dev[0].request("DISCONNECT")
- if hapd:
- hapd.request("DISABLE")
- subprocess.call(['iw', 'reg', 'set', '00'])
- dev[0].flush_scan_cache()
- @remote_compatible
- def test_ap_wps_twice(dev, apdev):
- """WPS provisioning with twice to change passphrase"""
- ssid = "test-wps-twice"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP" }
- hapd = hostapd.add_ap(apdev[0], params)
- logger.info("WPS provisioning step")
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].dump_monitor()
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- dev[0].wait_connected(timeout=30)
- dev[0].request("DISCONNECT")
- logger.info("Restart AP with different passphrase and re-run WPS")
- hostapd.remove_bss(apdev[0])
- params['wpa_passphrase'] = 'another passphrase'
- hapd = hostapd.add_ap(apdev[0], params)
- logger.info("WPS provisioning step")
- hapd.request("WPS_PBC")
- dev[0].dump_monitor()
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- dev[0].wait_connected(timeout=30)
- networks = dev[0].list_networks()
- if len(networks) > 1:
- raise Exception("Unexpected duplicated network block present")
- @remote_compatible
- def test_ap_wps_incorrect_pin(dev, apdev):
- """WPS PIN provisioning with incorrect PIN"""
- ssid = "test-wps-incorrect-pin"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- logger.info("WPS provisioning attempt 1")
- hapd.request("WPS_PIN any 12345670")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].dump_monitor()
- dev[0].request("WPS_PIN %s 55554444" % apdev[0]['bssid'])
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=30)
- if ev is None:
- raise Exception("WPS operation timed out")
- if "config_error=18" not in ev:
- raise Exception("Incorrect config_error reported")
- if "msg=8" not in ev:
- raise Exception("PIN error detected on incorrect message")
- dev[0].wait_disconnected(timeout=10)
- dev[0].request("WPS_CANCEL")
- # if a scan was in progress, wait for it to complete before trying WPS again
- ev = dev[0].wait_event(["CTRL-EVENT-SCAN-RESULTS"], 5)
- status = hapd.request("WPS_GET_STATUS")
- if "Last WPS result: Failed" not in status:
- raise Exception("WPS failure result not shown correctly")
- logger.info("WPS provisioning attempt 2")
- hapd.request("WPS_PIN any 12345670")
- dev[0].dump_monitor()
- dev[0].request("WPS_PIN %s 12344444" % apdev[0]['bssid'])
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=30)
- if ev is None:
- raise Exception("WPS operation timed out")
- if "config_error=18" not in ev:
- raise Exception("Incorrect config_error reported")
- if "msg=10" not in ev:
- raise Exception("PIN error detected on incorrect message")
- dev[0].wait_disconnected(timeout=10)
- @remote_compatible
- def test_ap_wps_conf_pin(dev, apdev):
- """WPS PIN provisioning with configured AP"""
- ssid = "test-wps-conf-pin"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- logger.info("WPS provisioning step")
- pin = dev[0].wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].dump_monitor()
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- dev[0].wait_connected(timeout=30)
- status = dev[0].get_status()
- if status['wpa_state'] != 'COMPLETED' or status['bssid'] != apdev[0]['bssid']:
- raise Exception("Not fully connected")
- if status['ssid'] != ssid:
- raise Exception("Unexpected SSID")
- if status['pairwise_cipher'] != 'CCMP' or status['group_cipher'] != 'CCMP':
- raise Exception("Unexpected encryption configuration")
- if status['key_mgmt'] != 'WPA2-PSK':
- raise Exception("Unexpected key_mgmt")
- dev[1].scan_for_bss(apdev[0]['bssid'], freq="2412", force_scan=True)
- bss = dev[1].get_bss(apdev[0]['bssid'])
- if "[WPS-AUTH]" in bss['flags']:
- raise Exception("WPS-AUTH flag not cleared")
- logger.info("Try to connect from another station using the same PIN")
- pin = dev[1].request("WPS_PIN " + apdev[0]['bssid'])
- ev = dev[1].wait_event(["WPS-M2D","CTRL-EVENT-CONNECTED"], timeout=30)
- if ev is None:
- raise Exception("Operation timed out")
- if "WPS-M2D" not in ev:
- raise Exception("Unexpected WPS operation started")
- hapd.request("WPS_PIN any " + pin)
- dev[1].wait_connected(timeout=30)
- def test_ap_wps_conf_pin_mixed_mode(dev, apdev):
- """WPS PIN provisioning with configured AP (WPA+WPA2)"""
- ssid = "test-wps-conf-pin-mixed"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "3",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "wpa_pairwise": "TKIP" })
- logger.info("WPS provisioning step")
- pin = dev[0].wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].dump_monitor()
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- dev[0].wait_connected(timeout=30)
- status = dev[0].get_status()
- dev[0].request("REMOVE_NETWORK all")
- dev[0].wait_disconnected()
- if status['pairwise_cipher'] != 'CCMP' or status['group_cipher'] != 'TKIP' or status['key_mgmt'] != 'WPA2-PSK':
- raise Exception("Unexpected encryption/key_mgmt configuration: pairwise=%s group=%s key_mgmt=%s" % (status['pairwise_cipher'], status['group_cipher'], status['key_mgmt']))
- logger.info("WPS provisioning step (auth_types=0x1b)")
- if "OK" not in dev[0].request("SET wps_force_auth_types 0x1b"):
- raise Exception("Failed to set wps_force_auth_types 0x1b")
- pin = dev[0].wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].dump_monitor()
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- dev[0].wait_connected(timeout=30)
- status = dev[0].get_status()
- dev[0].request("REMOVE_NETWORK all")
- dev[0].wait_disconnected()
- if status['pairwise_cipher'] != 'CCMP' or status['group_cipher'] != 'TKIP' or status['key_mgmt'] != 'WPA2-PSK':
- raise Exception("Unexpected encryption/key_mgmt configuration: pairwise=%s group=%s key_mgmt=%s" % (status['pairwise_cipher'], status['group_cipher'], status['key_mgmt']))
- logger.info("WPS provisioning step (auth_types=0 encr_types=0)")
- if "OK" not in dev[0].request("SET wps_force_auth_types 0"):
- raise Exception("Failed to set wps_force_auth_types 0")
- if "OK" not in dev[0].request("SET wps_force_encr_types 0"):
- raise Exception("Failed to set wps_force_encr_types 0")
- pin = dev[0].wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].dump_monitor()
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- dev[0].wait_connected(timeout=30)
- status = dev[0].get_status()
- dev[0].request("REMOVE_NETWORK all")
- dev[0].wait_disconnected()
- if status['pairwise_cipher'] != 'CCMP' or status['group_cipher'] != 'TKIP' or status['key_mgmt'] != 'WPA2-PSK':
- raise Exception("Unexpected encryption/key_mgmt configuration: pairwise=%s group=%s key_mgmt=%s" % (status['pairwise_cipher'], status['group_cipher'], status['key_mgmt']))
- dev[0].request("SET wps_force_auth_types ")
- dev[0].request("SET wps_force_encr_types ")
- @remote_compatible
- def test_ap_wps_conf_pin_v1(dev, apdev):
- """WPS PIN provisioning with configured WPS v1.0 AP"""
- ssid = "test-wps-conf-pin-v1"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- logger.info("WPS provisioning step")
- pin = dev[0].wps_read_pin()
- hapd.request("SET wps_version_number 0x10")
- hapd.request("WPS_PIN any " + pin)
- found = False
- for i in range(0, 10):
- dev[0].scan(freq="2412")
- if "[WPS-PIN]" in dev[0].request("SCAN_RESULTS"):
- found = True
- break
- if not found:
- hapd.request("SET wps_version_number 0x20")
- raise Exception("WPS-PIN flag not seen in scan results")
- dev[0].dump_monitor()
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- dev[0].wait_connected(timeout=30)
- hapd.request("SET wps_version_number 0x20")
- @remote_compatible
- def test_ap_wps_conf_pin_2sta(dev, apdev):
- """Two stations trying to use WPS PIN at the same time"""
- ssid = "test-wps-conf-pin2"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- logger.info("WPS provisioning step")
- pin = "12345670"
- pin2 = "55554444"
- hapd.request("WPS_PIN " + dev[0].get_status_field("uuid") + " " + pin)
- hapd.request("WPS_PIN " + dev[1].get_status_field("uuid") + " " + pin)
- dev[0].dump_monitor()
- dev[1].dump_monitor()
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[1].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- dev[1].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- dev[0].wait_connected(timeout=30)
- dev[1].wait_connected(timeout=30)
- @remote_compatible
- def test_ap_wps_conf_pin_timeout(dev, apdev):
- """WPS PIN provisioning with configured AP timing out PIN"""
- ssid = "test-wps-conf-pin"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- addr = dev[0].p2p_interface_addr()
- pin = dev[0].wps_read_pin()
- if "FAIL" not in hapd.request("WPS_PIN "):
- raise Exception("Unexpected success on invalid WPS_PIN")
- hapd.request("WPS_PIN any " + pin + " 1")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- time.sleep(1.1)
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = hapd.wait_event(["WPS-PIN-NEEDED"], timeout=20)
- if ev is None:
- raise Exception("WPS-PIN-NEEDED event timed out")
- ev = dev[0].wait_event(["WPS-M2D"])
- if ev is None:
- raise Exception("M2D not reported")
- dev[0].request("WPS_CANCEL")
- hapd.request("WPS_PIN any " + pin + " 20 " + addr)
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- dev[0].wait_connected(timeout=30)
- def test_ap_wps_reg_connect(dev, apdev):
- """WPS registrar using AP PIN to connect"""
- ssid = "test-wps-reg-ap-pin"
- appin = "12345670"
- hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "ap_pin": appin})
- logger.info("WPS provisioning step")
- dev[0].dump_monitor()
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], appin)
- status = dev[0].get_status()
- if status['wpa_state'] != 'COMPLETED' or status['bssid'] != apdev[0]['bssid']:
- raise Exception("Not fully connected")
- if status['ssid'] != ssid:
- raise Exception("Unexpected SSID")
- if status['pairwise_cipher'] != 'CCMP' or status['group_cipher'] != 'CCMP':
- raise Exception("Unexpected encryption configuration")
- if status['key_mgmt'] != 'WPA2-PSK':
- raise Exception("Unexpected key_mgmt")
- def test_ap_wps_reg_connect_mixed_mode(dev, apdev):
- """WPS registrar using AP PIN to connect (WPA+WPA2)"""
- ssid = "test-wps-reg-ap-pin"
- appin = "12345670"
- hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "3",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "wpa_pairwise": "TKIP", "ap_pin": appin})
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], appin)
- status = dev[0].get_status()
- if status['wpa_state'] != 'COMPLETED' or status['bssid'] != apdev[0]['bssid']:
- raise Exception("Not fully connected")
- if status['ssid'] != ssid:
- raise Exception("Unexpected SSID")
- if status['pairwise_cipher'] != 'CCMP' or status['group_cipher'] != 'TKIP':
- raise Exception("Unexpected encryption configuration")
- if status['key_mgmt'] != 'WPA2-PSK':
- raise Exception("Unexpected key_mgmt")
- def test_ap_wps_reg_override_ap_settings(dev, apdev):
- """WPS registrar and ap_settings override"""
- ap_settings = "/tmp/ap_wps_reg_override_ap_settings"
- try:
- os.remove(ap_settings)
- except:
- pass
- # Override AP Settings with values that point to another AP
- data = build_wsc_attr(ATTR_NETWORK_INDEX, '\x01')
- data += build_wsc_attr(ATTR_SSID, "test")
- data += build_wsc_attr(ATTR_AUTH_TYPE, '\x00\x01')
- data += build_wsc_attr(ATTR_ENCR_TYPE, '\x00\x01')
- data += build_wsc_attr(ATTR_NETWORK_KEY, '')
- data += build_wsc_attr(ATTR_MAC_ADDR, binascii.unhexlify(apdev[1]['bssid'].replace(':', '')))
- with open(ap_settings, "w") as f:
- f.write(data)
- ssid = "test-wps-reg-ap-pin"
- appin = "12345670"
- hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "ap_pin": appin, "ap_settings": ap_settings })
- hapd2 = hostapd.add_ap(apdev[1], { "ssid": "test" })
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].scan_for_bss(apdev[1]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], appin)
- ev = hapd2.wait_event(['AP-STA-CONNECTED'], timeout=10)
- os.remove(ap_settings)
- if ev is None:
- raise Exception("No connection with the other AP")
- def check_wps_reg_failure(dev, ap, appin):
- dev.request("WPS_REG " + ap['bssid'] + " " + appin)
- ev = dev.wait_event(["WPS-SUCCESS", "WPS-FAIL"], timeout=15)
- if ev is None:
- raise Exception("WPS operation timed out")
- if "WPS-SUCCESS" in ev:
- raise Exception("WPS operation succeeded unexpectedly")
- if "config_error=15" not in ev:
- raise Exception("WPS setup locked state was not reported correctly")
- def test_ap_wps_random_ap_pin(dev, apdev):
- """WPS registrar using random AP PIN"""
- ssid = "test-wps-reg-random-ap-pin"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- "config_methods": "label push_button",
- "uuid": ap_uuid, "upnp_iface": "lo" }
- hapd = hostapd.add_ap(apdev[0], params)
- appin = hapd.request("WPS_AP_PIN random")
- if "FAIL" in appin:
- raise Exception("Could not generate random AP PIN")
- if appin not in hapd.request("WPS_AP_PIN get"):
- raise Exception("Could not fetch current AP PIN")
- logger.info("WPS provisioning step")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], appin)
- hapd.request("WPS_AP_PIN disable")
- logger.info("WPS provisioning step with AP PIN disabled")
- dev[1].scan_for_bss(apdev[0]['bssid'], freq=2412)
- check_wps_reg_failure(dev[1], apdev[0], appin)
- logger.info("WPS provisioning step with AP PIN reset")
- appin = "12345670"
- hapd.request("WPS_AP_PIN set " + appin)
- dev[1].wps_reg(apdev[0]['bssid'], appin)
- dev[0].request("REMOVE_NETWORK all")
- dev[1].request("REMOVE_NETWORK all")
- dev[0].wait_disconnected(timeout=10)
- dev[1].wait_disconnected(timeout=10)
- logger.info("WPS provisioning step after AP PIN timeout")
- hapd.request("WPS_AP_PIN disable")
- appin = hapd.request("WPS_AP_PIN random 1")
- time.sleep(1.1)
- if "FAIL" not in hapd.request("WPS_AP_PIN get"):
- raise Exception("AP PIN unexpectedly still enabled")
- check_wps_reg_failure(dev[0], apdev[0], appin)
- logger.info("WPS provisioning step after AP PIN timeout(2)")
- hapd.request("WPS_AP_PIN disable")
- appin = "12345670"
- hapd.request("WPS_AP_PIN set " + appin + " 1")
- time.sleep(1.1)
- if "FAIL" not in hapd.request("WPS_AP_PIN get"):
- raise Exception("AP PIN unexpectedly still enabled")
- check_wps_reg_failure(dev[1], apdev[0], appin)
- with fail_test(hapd, 1, "os_get_random;wps_generate_pin"):
- hapd.request("WPS_AP_PIN random 1")
- hapd.request("WPS_AP_PIN disable")
- with alloc_fail(hapd, 1, "upnp_wps_set_ap_pin"):
- hapd.request("WPS_AP_PIN set 12345670")
- hapd.request("WPS_AP_PIN disable")
- def test_ap_wps_reg_config(dev, apdev):
- """WPS registrar configuring an AP using AP PIN"""
- ssid = "test-wps-init-ap-pin"
- appin = "12345670"
- hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "ap_pin": appin})
- logger.info("WPS configuration step")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].dump_monitor()
- new_ssid = "wps-new-ssid"
- new_passphrase = "1234567890"
- dev[0].wps_reg(apdev[0]['bssid'], appin, new_ssid, "WPA2PSK", "CCMP",
- new_passphrase)
- status = dev[0].get_status()
- if status['wpa_state'] != 'COMPLETED' or status['bssid'] != apdev[0]['bssid']:
- raise Exception("Not fully connected")
- if status['ssid'] != new_ssid:
- raise Exception("Unexpected SSID")
- if status['pairwise_cipher'] != 'CCMP' or status['group_cipher'] != 'CCMP':
- raise Exception("Unexpected encryption configuration")
- if status['key_mgmt'] != 'WPA2-PSK':
- raise Exception("Unexpected key_mgmt")
- logger.info("Re-configure back to open")
- dev[0].request("REMOVE_NETWORK all")
- dev[0].flush_scan_cache()
- dev[0].dump_monitor()
- dev[0].wps_reg(apdev[0]['bssid'], appin, "wps-open", "OPEN", "NONE", "")
- status = dev[0].get_status()
- if status['wpa_state'] != 'COMPLETED' or status['bssid'] != apdev[0]['bssid']:
- raise Exception("Not fully connected")
- if status['ssid'] != "wps-open":
- raise Exception("Unexpected SSID")
- if status['key_mgmt'] != 'NONE':
- raise Exception("Unexpected key_mgmt")
- def test_ap_wps_reg_config_ext_processing(dev, apdev):
- """WPS registrar configuring an AP with external config processing"""
- ssid = "test-wps-init-ap-pin"
- appin = "12345670"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wps_cred_processing": "1", "ap_pin": appin}
- hapd = hostapd.add_ap(apdev[0], params)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- new_ssid = "wps-new-ssid"
- new_passphrase = "1234567890"
- dev[0].wps_reg(apdev[0]['bssid'], appin, new_ssid, "WPA2PSK", "CCMP",
- new_passphrase, no_wait=True)
- ev = dev[0].wait_event(["WPS-SUCCESS"], timeout=15)
- if ev is None:
- raise Exception("WPS registrar operation timed out")
- ev = hapd.wait_event(["WPS-NEW-AP-SETTINGS"], timeout=15)
- if ev is None:
- raise Exception("WPS configuration timed out")
- if "1026" not in ev:
- raise Exception("AP Settings missing from event")
- hapd.request("SET wps_cred_processing 0")
- if "FAIL" in hapd.request("WPS_CONFIG " + new_ssid.encode("hex") + " WPA2PSK CCMP " + new_passphrase.encode("hex")):
- raise Exception("WPS_CONFIG command failed")
- dev[0].wait_connected(timeout=15)
- def test_ap_wps_reg_config_tkip(dev, apdev):
- """WPS registrar configuring AP to use TKIP and AP upgrading to TKIP+CCMP"""
- skip_with_fips(dev[0])
- ssid = "test-wps-init-ap"
- appin = "12345670"
- hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "1",
- "ap_pin": appin})
- logger.info("WPS configuration step")
- dev[0].request("SET wps_version_number 0x10")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].dump_monitor()
- new_ssid = "wps-new-ssid-with-tkip"
- new_passphrase = "1234567890"
- dev[0].wps_reg(apdev[0]['bssid'], appin, new_ssid, "WPAPSK", "TKIP",
- new_passphrase)
- logger.info("Re-connect to verify WPA2 mixed mode")
- dev[0].request("DISCONNECT")
- id = 0
- dev[0].set_network(id, "pairwise", "CCMP")
- dev[0].set_network(id, "proto", "RSN")
- dev[0].connect_network(id)
- status = dev[0].get_status()
- if status['wpa_state'] != 'COMPLETED' or status['bssid'] != apdev[0]['bssid']:
- raise Exception("Not fully connected: wpa_state={} bssid={}".format(status['wpa_state'], status['bssid']))
- if status['ssid'] != new_ssid:
- raise Exception("Unexpected SSID")
- if status['pairwise_cipher'] != 'CCMP' or status['group_cipher'] != 'TKIP':
- raise Exception("Unexpected encryption configuration")
- if status['key_mgmt'] != 'WPA2-PSK':
- raise Exception("Unexpected key_mgmt")
- def test_ap_wps_setup_locked(dev, apdev):
- """WPS registrar locking up AP setup on AP PIN failures"""
- ssid = "test-wps-incorrect-ap-pin"
- appin = "12345670"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "ap_pin": appin})
- new_ssid = "wps-new-ssid-test"
- new_passphrase = "1234567890"
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- ap_setup_locked=False
- for pin in ["55554444", "1234", "12345678", "00000000", "11111111"]:
- dev[0].dump_monitor()
- logger.info("Try incorrect AP PIN - attempt " + pin)
- dev[0].wps_reg(apdev[0]['bssid'], pin, new_ssid, "WPA2PSK",
- "CCMP", new_passphrase, no_wait=True)
- ev = dev[0].wait_event(["WPS-FAIL", "CTRL-EVENT-CONNECTED"])
- if ev is None:
- raise Exception("Timeout on receiving WPS operation failure event")
- if "CTRL-EVENT-CONNECTED" in ev:
- raise Exception("Unexpected connection")
- if "config_error=15" in ev:
- logger.info("AP Setup Locked")
- ap_setup_locked=True
- elif "config_error=18" not in ev:
- raise Exception("config_error=18 not reported")
- dev[0].wait_disconnected(timeout=10)
- time.sleep(0.1)
- if not ap_setup_locked:
- raise Exception("AP setup was not locked")
- dev[0].request("WPS_CANCEL")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412, force_scan=True,
- only_new=True)
- bss = dev[0].get_bss(apdev[0]['bssid'])
- if 'wps_ap_setup_locked' not in bss or bss['wps_ap_setup_locked'] != '1':
- logger.info("BSS: " + str(bss))
- raise Exception("AP Setup Locked not indicated in scan results")
- status = hapd.request("WPS_GET_STATUS")
- if "Last WPS result: Failed" not in status:
- raise Exception("WPS failure result not shown correctly")
- if "Peer Address: " + dev[0].p2p_interface_addr() not in status:
- raise Exception("Peer address not shown correctly")
- time.sleep(0.5)
- dev[0].dump_monitor()
- logger.info("WPS provisioning step")
- pin = dev[0].wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = dev[0].wait_event(["WPS-SUCCESS"], timeout=30)
- if ev is None:
- raise Exception("WPS success was not reported")
- dev[0].wait_connected(timeout=30)
- appin = hapd.request("WPS_AP_PIN random")
- if "FAIL" in appin:
- raise Exception("Could not generate random AP PIN")
- ev = hapd.wait_event(["WPS-AP-SETUP-UNLOCKED"], timeout=10)
- if ev is None:
- raise Exception("Failed to unlock AP PIN")
- def test_ap_wps_setup_locked_timeout(dev, apdev):
- """WPS re-enabling AP PIN after timeout"""
- ssid = "test-wps-incorrect-ap-pin"
- appin = "12345670"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "ap_pin": appin})
- new_ssid = "wps-new-ssid-test"
- new_passphrase = "1234567890"
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- ap_setup_locked=False
- for pin in ["55554444", "1234", "12345678", "00000000", "11111111"]:
- dev[0].dump_monitor()
- logger.info("Try incorrect AP PIN - attempt " + pin)
- dev[0].wps_reg(apdev[0]['bssid'], pin, new_ssid, "WPA2PSK",
- "CCMP", new_passphrase, no_wait=True)
- ev = dev[0].wait_event(["WPS-FAIL", "CTRL-EVENT-CONNECTED"], timeout=15)
- if ev is None:
- raise Exception("Timeout on receiving WPS operation failure event")
- if "CTRL-EVENT-CONNECTED" in ev:
- raise Exception("Unexpected connection")
- if "config_error=15" in ev:
- logger.info("AP Setup Locked")
- ap_setup_locked=True
- break
- elif "config_error=18" not in ev:
- raise Exception("config_error=18 not reported")
- dev[0].wait_disconnected(timeout=10)
- time.sleep(0.1)
- if not ap_setup_locked:
- raise Exception("AP setup was not locked")
- ev = hapd.wait_event(["WPS-AP-SETUP-UNLOCKED"], timeout=80)
- if ev is None:
- raise Exception("AP PIN did not get unlocked on 60 second timeout")
- def test_ap_wps_setup_locked_2(dev, apdev):
- """WPS AP configured for special ap_setup_locked=2 mode"""
- ssid = "test-wps-ap-pin"
- appin = "12345670"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "ap_pin": appin, "ap_setup_locked": "2" }
- hapd = hostapd.add_ap(apdev[0], params)
- new_ssid = "wps-new-ssid-test"
- new_passphrase = "1234567890"
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], appin)
- dev[0].request("REMOVE_NETWORK all")
- dev[0].wait_disconnected()
- hapd.dump_monitor()
- dev[0].dump_monitor()
- dev[0].wps_reg(apdev[0]['bssid'], appin, new_ssid, "WPA2PSK",
- "CCMP", new_passphrase, no_wait=True)
- ev = hapd.wait_event(["WPS-FAIL"], timeout=5)
- if ev is None:
- raise Exception("hostapd did not report WPS failure")
- if "msg=12 config_error=15" not in ev:
- raise Exception("Unexpected failure reason (AP): " + ev)
- ev = dev[0].wait_event(["WPS-FAIL", "CTRL-EVENT-CONNECTED"])
- if ev is None:
- raise Exception("Timeout on receiving WPS operation failure event")
- if "CTRL-EVENT-CONNECTED" in ev:
- raise Exception("Unexpected connection")
- if "config_error=15" not in ev:
- raise Exception("Unexpected failure reason (STA): " + ev)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- @remote_compatible
- def test_ap_wps_pbc_overlap_2ap(dev, apdev):
- """WPS PBC session overlap with two active APs"""
- params = { "ssid": "wps1", "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "wps_independent": "1"}
- hapd = hostapd.add_ap(apdev[0], params)
- params = { "ssid": "wps2", "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "123456789", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "wps_independent": "1"}
- hapd2 = hostapd.add_ap(apdev[1], params)
- hapd.request("WPS_PBC")
- hapd2.request("WPS_PBC")
- logger.info("WPS provisioning step")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412", force_scan=True)
- dev[0].scan_for_bss(apdev[1]['bssid'], freq="2412")
- dev[0].request("WPS_PBC")
- ev = dev[0].wait_event(["WPS-OVERLAP-DETECTED"], timeout=15)
- if ev is None:
- raise Exception("PBC session overlap not detected")
- hapd.request("DISABLE")
- hapd2.request("DISABLE")
- dev[0].flush_scan_cache()
- @remote_compatible
- def test_ap_wps_pbc_overlap_2sta(dev, apdev):
- """WPS PBC session overlap with two active STAs"""
- ssid = "test-wps-pbc-overlap"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- logger.info("WPS provisioning step")
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].dump_monitor()
- dev[1].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[1].dump_monitor()
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- dev[1].request("WPS_PBC " + apdev[0]['bssid'])
- ev = dev[0].wait_event(["WPS-M2D"], timeout=15)
- if ev is None:
- raise Exception("PBC session overlap not detected (dev0)")
- if "config_error=12" not in ev:
- raise Exception("PBC session overlap not correctly reported (dev0)")
- dev[0].request("WPS_CANCEL")
- dev[0].request("DISCONNECT")
- ev = dev[1].wait_event(["WPS-M2D"], timeout=15)
- if ev is None:
- raise Exception("PBC session overlap not detected (dev1)")
- if "config_error=12" not in ev:
- raise Exception("PBC session overlap not correctly reported (dev1)")
- dev[1].request("WPS_CANCEL")
- dev[1].request("DISCONNECT")
- hapd.request("WPS_CANCEL")
- ret = hapd.request("WPS_PBC")
- if "FAIL" not in ret:
- raise Exception("PBC mode allowed to be started while PBC overlap still active")
- hapd.request("DISABLE")
- dev[0].flush_scan_cache()
- dev[1].flush_scan_cache()
- @remote_compatible
- def test_ap_wps_cancel(dev, apdev):
- """WPS AP cancelling enabled config method"""
- ssid = "test-wps-ap-cancel"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP" })
- bssid = apdev[0]['bssid']
- logger.info("Verify PBC enable/cancel")
- hapd.request("WPS_PBC")
- dev[0].scan(freq="2412")
- dev[0].scan(freq="2412")
- bss = dev[0].get_bss(apdev[0]['bssid'])
- if "[WPS-PBC]" not in bss['flags']:
- raise Exception("WPS-PBC flag missing")
- if "FAIL" in hapd.request("WPS_CANCEL"):
- raise Exception("WPS_CANCEL failed")
- dev[0].scan(freq="2412")
- dev[0].scan(freq="2412")
- bss = dev[0].get_bss(apdev[0]['bssid'])
- if "[WPS-PBC]" in bss['flags']:
- raise Exception("WPS-PBC flag not cleared")
- logger.info("Verify PIN enable/cancel")
- hapd.request("WPS_PIN any 12345670")
- dev[0].scan(freq="2412")
- dev[0].scan(freq="2412")
- bss = dev[0].get_bss(apdev[0]['bssid'])
- if "[WPS-AUTH]" not in bss['flags']:
- raise Exception("WPS-AUTH flag missing")
- if "FAIL" in hapd.request("WPS_CANCEL"):
- raise Exception("WPS_CANCEL failed")
- dev[0].scan(freq="2412")
- dev[0].scan(freq="2412")
- bss = dev[0].get_bss(apdev[0]['bssid'])
- if "[WPS-AUTH]" in bss['flags']:
- raise Exception("WPS-AUTH flag not cleared")
- def test_ap_wps_er_add_enrollee(dev, apdev):
- """WPS ER configuring AP and adding a new enrollee using PIN"""
- try:
- _test_ap_wps_er_add_enrollee(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_add_enrollee(dev, apdev):
- ssid = "wps-er-add-enrollee"
- ap_pin = "12345670"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "1",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- 'friendly_name': "WPS AP - <>&'\" - TEST",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo"})
- logger.info("WPS configuration step")
- new_passphrase = "1234567890"
- dev[0].dump_monitor()
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], ap_pin, ssid, "WPA2PSK", "CCMP",
- new_passphrase)
- status = dev[0].get_status()
- if status['wpa_state'] != 'COMPLETED' or status['bssid'] != apdev[0]['bssid']:
- raise Exception("Not fully connected")
- if status['ssid'] != ssid:
- raise Exception("Unexpected SSID")
- if status['pairwise_cipher'] != 'CCMP' or status['group_cipher'] != 'CCMP':
- raise Exception("Unexpected encryption configuration")
- if status['key_mgmt'] != 'WPA2-PSK':
- raise Exception("Unexpected key_mgmt")
- logger.info("Start ER")
- dev[0].request("WPS_ER_START ifname=lo")
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=15)
- if ev is None:
- raise Exception("AP discovery timed out")
- if ap_uuid not in ev:
- raise Exception("Expected AP UUID not found")
- if "|WPS AP - <>&'" - TEST|Company|" not in ev:
- raise Exception("Expected friendly name not found")
- logger.info("Learn AP configuration through UPnP")
- dev[0].dump_monitor()
- dev[0].request("WPS_ER_LEARN " + ap_uuid + " " + ap_pin)
- ev = dev[0].wait_event(["WPS-ER-AP-SETTINGS"], timeout=15)
- if ev is None:
- raise Exception("AP learn timed out")
- if ap_uuid not in ev:
- raise Exception("Expected AP UUID not in settings")
- if "ssid=" + ssid not in ev:
- raise Exception("Expected SSID not in settings")
- if "key=" + new_passphrase not in ev:
- raise Exception("Expected passphrase not in settings")
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=15)
- if ev is None:
- raise Exception("WPS-FAIL after AP learn timed out")
- time.sleep(0.1)
- logger.info("Add Enrollee using ER")
- pin = dev[1].wps_read_pin()
- dev[0].dump_monitor()
- dev[0].request("WPS_ER_PIN any " + pin + " " + dev[1].p2p_interface_addr())
- dev[1].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[1].dump_monitor()
- dev[1].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = dev[1].wait_event(["WPS-SUCCESS"], timeout=30)
- if ev is None:
- raise Exception("Enrollee did not report success")
- dev[1].wait_connected(timeout=15)
- ev = dev[0].wait_event(["WPS-SUCCESS"], timeout=15)
- if ev is None:
- raise Exception("WPS ER did not report success")
- hwsim_utils.test_connectivity_sta(dev[0], dev[1])
- logger.info("Add a specific Enrollee using ER")
- pin = dev[2].wps_read_pin()
- addr2 = dev[2].p2p_interface_addr()
- dev[0].dump_monitor()
- dev[2].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[2].dump_monitor()
- dev[2].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = dev[0].wait_event(["WPS-ER-ENROLLEE-ADD"], timeout=10)
- if ev is None:
- raise Exception("Enrollee not seen")
- if addr2 not in ev:
- raise Exception("Unexpected Enrollee MAC address")
- dev[0].request("WPS_ER_PIN " + addr2 + " " + pin + " " + addr2)
- dev[2].wait_connected(timeout=30)
- ev = dev[0].wait_event(["WPS-SUCCESS"], timeout=15)
- if ev is None:
- raise Exception("WPS ER did not report success")
- logger.info("Verify registrar selection behavior")
- dev[0].request("WPS_ER_PIN any " + pin + " " + dev[1].p2p_interface_addr())
- dev[1].request("DISCONNECT")
- dev[1].wait_disconnected(timeout=10)
- dev[1].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[1].scan(freq="2412")
- bss = dev[1].get_bss(apdev[0]['bssid'])
- if "[WPS-AUTH]" not in bss['flags']:
- # It is possible for scan to miss an update especially when running
- # tests under load with multiple VMs, so allow another attempt.
- dev[1].scan(freq="2412")
- bss = dev[1].get_bss(apdev[0]['bssid'])
- if "[WPS-AUTH]" not in bss['flags']:
- raise Exception("WPS-AUTH flag missing")
- logger.info("Stop ER")
- dev[0].dump_monitor()
- dev[0].request("WPS_ER_STOP")
- ev = dev[0].wait_event(["WPS-ER-AP-REMOVE"])
- if ev is None:
- raise Exception("WPS ER unsubscription timed out")
- # It takes some time for the UPnP UNSUBSCRIBE command to go through, so wait
- # a bit before verifying that the scan results have changed.
- time.sleep(0.2)
- for i in range(0, 10):
- dev[1].request("BSS_FLUSH 0")
- dev[1].scan(freq="2412", only_new=True)
- bss = dev[1].get_bss(apdev[0]['bssid'])
- if bss and 'flags' in bss and "[WPS-AUTH]" not in bss['flags']:
- break
- logger.debug("WPS-AUTH flag was still in place - wait a bit longer")
- time.sleep(0.1)
- if "[WPS-AUTH]" in bss['flags']:
- raise Exception("WPS-AUTH flag not removed")
- def test_ap_wps_er_add_enrollee_uuid(dev, apdev):
- """WPS ER adding a new enrollee identified by UUID"""
- try:
- _test_ap_wps_er_add_enrollee_uuid(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_add_enrollee_uuid(dev, apdev):
- ssid = "wps-er-add-enrollee"
- ap_pin = "12345670"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo"})
- logger.info("WPS configuration step")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], ap_pin)
- logger.info("Start ER")
- dev[0].request("WPS_ER_START ifname=lo")
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=15)
- if ev is None:
- raise Exception("AP discovery timed out")
- if ap_uuid not in ev:
- raise Exception("Expected AP UUID not found")
- logger.info("Learn AP configuration through UPnP")
- dev[0].dump_monitor()
- dev[0].request("WPS_ER_LEARN " + ap_uuid + " " + ap_pin)
- ev = dev[0].wait_event(["WPS-ER-AP-SETTINGS"], timeout=15)
- if ev is None:
- raise Exception("AP learn timed out")
- if ap_uuid not in ev:
- raise Exception("Expected AP UUID not in settings")
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=15)
- if ev is None:
- raise Exception("WPS-FAIL after AP learn timed out")
- time.sleep(0.1)
- logger.info("Add a specific Enrollee using ER (PBC/UUID)")
- addr1 = dev[1].p2p_interface_addr()
- dev[0].dump_monitor()
- dev[1].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[1].dump_monitor()
- dev[1].request("WPS_PBC %s" % apdev[0]['bssid'])
- ev = dev[0].wait_event(["WPS-ER-ENROLLEE-ADD"], timeout=10)
- if ev is None:
- raise Exception("Enrollee not seen")
- if addr1 not in ev:
- raise Exception("Unexpected Enrollee MAC address")
- uuid = ev.split(' ')[1]
- dev[0].request("WPS_ER_PBC " + uuid)
- dev[1].wait_connected(timeout=30)
- ev = dev[0].wait_event(["WPS-SUCCESS"], timeout=15)
- if ev is None:
- raise Exception("WPS ER did not report success")
- logger.info("Add a specific Enrollee using ER (PIN/UUID)")
- pin = dev[2].wps_read_pin()
- addr2 = dev[2].p2p_interface_addr()
- dev[0].dump_monitor()
- dev[2].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[2].dump_monitor()
- dev[2].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = dev[0].wait_event(["WPS-ER-ENROLLEE-ADD"], timeout=10)
- if ev is None:
- raise Exception("Enrollee not seen")
- if addr2 not in ev:
- raise Exception("Unexpected Enrollee MAC address")
- uuid = ev.split(' ')[1]
- dev[0].request("WPS_ER_PIN " + uuid + " " + pin)
- dev[2].wait_connected(timeout=30)
- ev = dev[0].wait_event(["WPS-SUCCESS"], timeout=15)
- if ev is None:
- raise Exception("WPS ER did not report success")
- ev = dev[0].wait_event(["WPS-ER-ENROLLEE-REMOVE"], timeout=15)
- if ev is None:
- raise Exception("No Enrollee STA entry timeout seen")
- logger.info("Stop ER")
- dev[0].dump_monitor()
- dev[0].request("WPS_ER_STOP")
- def test_ap_wps_er_multi_add_enrollee(dev, apdev):
- """Multiple WPS ERs adding a new enrollee using PIN"""
- try:
- _test_ap_wps_er_multi_add_enrollee(dev, apdev)
- finally:
- for i in range(2):
- dev[i].request("WPS_ER_STOP")
- def _test_ap_wps_er_multi_add_enrollee(dev, apdev):
- ssid = "wps-er-add-enrollee"
- ap_pin = "12345670"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- 'friendly_name': "WPS AP",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo"})
- for i in range(2):
- dev[i].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[i].wps_reg(apdev[0]['bssid'], ap_pin)
- for i in range(2):
- dev[i].request("WPS_ER_START ifname=lo")
- for i in range(2):
- ev = dev[i].wait_event(["WPS-ER-AP-ADD"], timeout=15)
- if ev is None:
- raise Exception("AP discovery timed out")
- dev[i].dump_monitor()
- for i in range(2):
- dev[i].request("WPS_ER_LEARN " + ap_uuid + " " + ap_pin)
- for i in range(2):
- ev = dev[i].wait_event(["WPS-ER-AP-SETTINGS"], timeout=15)
- if ev is None:
- raise Exception("AP learn timed out")
- ev = dev[i].wait_event(["WPS-FAIL"], timeout=15)
- if ev is None:
- raise Exception("WPS-FAIL after AP learn timed out")
- time.sleep(0.1)
- pin = dev[2].wps_read_pin()
- addr = dev[2].own_addr()
- dev[0].dump_monitor()
- dev[0].request("WPS_ER_PIN any " + pin + " " + addr)
- dev[1].dump_monitor()
- dev[1].request("WPS_ER_PIN any " + pin + " " + addr)
- dev[2].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[2].dump_monitor()
- dev[2].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = dev[2].wait_event(["WPS-SUCCESS"], timeout=30)
- if ev is None:
- raise Exception("Enrollee did not report success")
- dev[2].wait_connected(timeout=15)
- def test_ap_wps_er_add_enrollee_pbc(dev, apdev):
- """WPS ER connected to AP and adding a new enrollee using PBC"""
- try:
- _test_ap_wps_er_add_enrollee_pbc(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_add_enrollee_pbc(dev, apdev):
- ssid = "wps-er-add-enrollee-pbc"
- ap_pin = "12345670"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo"})
- logger.info("Learn AP configuration")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].dump_monitor()
- dev[0].wps_reg(apdev[0]['bssid'], ap_pin)
- status = dev[0].get_status()
- if status['wpa_state'] != 'COMPLETED' or status['bssid'] != apdev[0]['bssid']:
- raise Exception("Not fully connected")
- logger.info("Start ER")
- dev[0].request("WPS_ER_START ifname=lo")
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=15)
- if ev is None:
- raise Exception("AP discovery timed out")
- if ap_uuid not in ev:
- raise Exception("Expected AP UUID not found")
- enrollee = dev[1].p2p_interface_addr()
- if "FAIL-UNKNOWN-UUID" not in dev[0].request("WPS_ER_PBC " + enrollee):
- raise Exception("Unknown UUID not reported")
- logger.info("Add Enrollee using ER and PBC")
- dev[0].dump_monitor()
- dev[1].dump_monitor()
- dev[1].request("WPS_PBC")
- for i in range(0, 2):
- ev = dev[0].wait_event(["WPS-ER-ENROLLEE-ADD"], timeout=15)
- if ev is None:
- raise Exception("Enrollee discovery timed out")
- if enrollee in ev:
- break
- if i == 1:
- raise Exception("Expected Enrollee not found")
- if "FAIL-NO-AP-SETTINGS" not in dev[0].request("WPS_ER_PBC " + enrollee):
- raise Exception("Unknown UUID not reported")
- logger.info("Use learned network configuration on ER")
- dev[0].request("WPS_ER_SET_CONFIG " + ap_uuid + " 0")
- if "OK" not in dev[0].request("WPS_ER_PBC " + enrollee):
- raise Exception("WPS_ER_PBC failed")
- ev = dev[1].wait_event(["WPS-SUCCESS"], timeout=15)
- if ev is None:
- raise Exception("Enrollee did not report success")
- dev[1].wait_connected(timeout=15)
- ev = dev[0].wait_event(["WPS-SUCCESS"], timeout=15)
- if ev is None:
- raise Exception("WPS ER did not report success")
- hwsim_utils.test_connectivity_sta(dev[0], dev[1])
- def test_ap_wps_er_pbc_overlap(dev, apdev):
- """WPS ER connected to AP and PBC session overlap"""
- try:
- _test_ap_wps_er_pbc_overlap(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_pbc_overlap(dev, apdev):
- ssid = "wps-er-add-enrollee-pbc"
- ap_pin = "12345670"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo"})
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].dump_monitor()
- dev[0].wps_reg(apdev[0]['bssid'], ap_pin)
- dev[1].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[2].scan_for_bss(apdev[0]['bssid'], freq="2412")
- # avoid leaving dev 1 or 2 as the last Probe Request to the AP
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412, force_scan=True)
- dev[0].dump_monitor()
- dev[0].request("WPS_ER_START ifname=lo")
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=15)
- if ev is None:
- raise Exception("AP discovery timed out")
- if ap_uuid not in ev:
- raise Exception("Expected AP UUID not found")
- # verify BSSID selection of the AP instead of UUID
- if "FAIL" in dev[0].request("WPS_ER_SET_CONFIG " + apdev[0]['bssid'] + " 0"):
- raise Exception("Could not select AP based on BSSID")
- dev[0].dump_monitor()
- dev[1].request("WPS_PBC " + apdev[0]['bssid'])
- dev[2].request("WPS_PBC " + apdev[0]['bssid'])
- ev = dev[1].wait_event(["CTRL-EVENT-SCAN-RESULTS"], timeout=10)
- if ev is None:
- raise Exception("PBC scan failed")
- ev = dev[2].wait_event(["CTRL-EVENT-SCAN-RESULTS"], timeout=10)
- if ev is None:
- raise Exception("PBC scan failed")
- found1 = False
- found2 = False
- addr1 = dev[1].own_addr()
- addr2 = dev[2].own_addr()
- for i in range(3):
- ev = dev[0].wait_event(["WPS-ER-ENROLLEE-ADD"], timeout=15)
- if ev is None:
- raise Exception("Enrollee discovery timed out")
- if addr1 in ev:
- found1 = True
- if found2:
- break
- if addr2 in ev:
- found2 = True
- if found1:
- break
- if dev[0].request("WPS_ER_PBC " + ap_uuid) != "FAIL-PBC-OVERLAP\n":
- raise Exception("PBC overlap not reported")
- dev[1].request("WPS_CANCEL")
- dev[2].request("WPS_CANCEL")
- if dev[0].request("WPS_ER_PBC foo") != "FAIL\n":
- raise Exception("Invalid WPS_ER_PBC accepted")
- def test_ap_wps_er_v10_add_enrollee_pin(dev, apdev):
- """WPS v1.0 ER connected to AP and adding a new enrollee using PIN"""
- try:
- _test_ap_wps_er_v10_add_enrollee_pin(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_v10_add_enrollee_pin(dev, apdev):
- ssid = "wps-er-add-enrollee-pbc"
- ap_pin = "12345670"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo"})
- logger.info("Learn AP configuration")
- dev[0].request("SET wps_version_number 0x10")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].dump_monitor()
- dev[0].wps_reg(apdev[0]['bssid'], ap_pin)
- status = dev[0].get_status()
- if status['wpa_state'] != 'COMPLETED' or status['bssid'] != apdev[0]['bssid']:
- raise Exception("Not fully connected")
- logger.info("Start ER")
- dev[0].request("WPS_ER_START ifname=lo")
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=15)
- if ev is None:
- raise Exception("AP discovery timed out")
- if ap_uuid not in ev:
- raise Exception("Expected AP UUID not found")
- logger.info("Use learned network configuration on ER")
- dev[0].request("WPS_ER_SET_CONFIG " + ap_uuid + " 0")
- logger.info("Add Enrollee using ER and PIN")
- enrollee = dev[1].p2p_interface_addr()
- pin = dev[1].wps_read_pin()
- dev[0].dump_monitor()
- dev[0].request("WPS_ER_PIN any " + pin + " " + enrollee)
- dev[1].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[1].dump_monitor()
- dev[1].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- dev[1].wait_connected(timeout=30)
- ev = dev[0].wait_event(["WPS-SUCCESS"], timeout=15)
- if ev is None:
- raise Exception("WPS ER did not report success")
- @remote_compatible
- def test_ap_wps_er_config_ap(dev, apdev):
- """WPS ER configuring AP over UPnP"""
- try:
- _test_ap_wps_er_config_ap(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_config_ap(dev, apdev):
- ssid = "wps-er-ap-config"
- ap_pin = "12345670"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo"})
- logger.info("Connect ER to the AP")
- dev[0].connect(ssid, psk="12345678", scan_freq="2412")
- logger.info("WPS configuration step")
- dev[0].request("WPS_ER_START ifname=lo")
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=15)
- if ev is None:
- raise Exception("AP discovery timed out")
- if ap_uuid not in ev:
- raise Exception("Expected AP UUID not found")
- new_passphrase = "1234567890"
- dev[0].request("WPS_ER_CONFIG " + apdev[0]['bssid'] + " " + ap_pin + " " +
- ssid.encode("hex") + " WPA2PSK CCMP " +
- new_passphrase.encode("hex"))
- ev = dev[0].wait_event(["WPS-SUCCESS"])
- if ev is None:
- raise Exception("WPS ER configuration operation timed out")
- dev[0].wait_disconnected(timeout=10)
- dev[0].connect(ssid, psk="1234567890", scan_freq="2412")
- logger.info("WPS ER restart")
- dev[0].request("WPS_ER_START")
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=15)
- if ev is None:
- raise Exception("AP discovery timed out on ER restart")
- if ap_uuid not in ev:
- raise Exception("Expected AP UUID not found on ER restart")
- if "OK" not in dev[0].request("WPS_ER_STOP"):
- raise Exception("WPS_ER_STOP failed")
- if "OK" not in dev[0].request("WPS_ER_STOP"):
- raise Exception("WPS_ER_STOP failed")
- @remote_compatible
- def test_ap_wps_er_cache_ap_settings(dev, apdev):
- """WPS ER caching AP settings"""
- try:
- _test_ap_wps_er_cache_ap_settings(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_cache_ap_settings(dev, apdev):
- ssid = "wps-er-add-enrollee"
- ap_pin = "12345670"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo" }
- hapd = hostapd.add_ap(apdev[0], params)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], ap_pin)
- id = int(dev[0].list_networks()[0]['id'])
- dev[0].set_network(id, "scan_freq", "2412")
- dev[0].request("WPS_ER_START ifname=lo")
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=15)
- if ev is None:
- raise Exception("AP discovery timed out")
- if ap_uuid not in ev:
- raise Exception("Expected AP UUID not found")
- dev[0].dump_monitor()
- dev[0].request("WPS_ER_LEARN " + ap_uuid + " " + ap_pin)
- ev = dev[0].wait_event(["WPS-ER-AP-SETTINGS"], timeout=15)
- if ev is None:
- raise Exception("AP learn timed out")
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=15)
- if ev is None:
- raise Exception("WPS-FAIL after AP learn timed out")
- time.sleep(0.1)
- hapd.disable()
- for i in range(2):
- ev = dev[0].wait_event([ "WPS-ER-AP-REMOVE",
- "CTRL-EVENT-DISCONNECTED" ],
- timeout=15)
- if ev is None:
- raise Exception("AP removal or disconnection timed out")
- hapd = hostapd.add_ap(apdev[0], params)
- for i in range(2):
- ev = dev[0].wait_event([ "WPS-ER-AP-ADD", "CTRL-EVENT-CONNECTED" ],
- timeout=15)
- if ev is None:
- raise Exception("AP discovery or connection timed out")
- pin = dev[1].wps_read_pin()
- dev[0].dump_monitor()
- dev[0].request("WPS_ER_PIN any " + pin + " " + dev[1].p2p_interface_addr())
- time.sleep(0.2)
- dev[1].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[1].dump_monitor()
- dev[1].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = dev[1].wait_event(["WPS-SUCCESS"], timeout=30)
- if ev is None:
- raise Exception("Enrollee did not report success")
- dev[1].wait_connected(timeout=15)
- ev = dev[0].wait_event(["WPS-SUCCESS"], timeout=15)
- if ev is None:
- raise Exception("WPS ER did not report success")
- dev[0].dump_monitor()
- dev[0].request("WPS_ER_STOP")
- def test_ap_wps_er_cache_ap_settings_oom(dev, apdev):
- """WPS ER caching AP settings (OOM)"""
- try:
- _test_ap_wps_er_cache_ap_settings_oom(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_cache_ap_settings_oom(dev, apdev):
- ssid = "wps-er-add-enrollee"
- ap_pin = "12345670"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo" }
- hapd = hostapd.add_ap(apdev[0], params)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], ap_pin)
- id = int(dev[0].list_networks()[0]['id'])
- dev[0].set_network(id, "scan_freq", "2412")
- dev[0].request("WPS_ER_START ifname=lo")
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=15)
- if ev is None:
- raise Exception("AP discovery timed out")
- if ap_uuid not in ev:
- raise Exception("Expected AP UUID not found")
- dev[0].dump_monitor()
- dev[0].request("WPS_ER_LEARN " + ap_uuid + " " + ap_pin)
- ev = dev[0].wait_event(["WPS-ER-AP-SETTINGS"], timeout=15)
- if ev is None:
- raise Exception("AP learn timed out")
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=15)
- if ev is None:
- raise Exception("WPS-FAIL after AP learn timed out")
- time.sleep(0.1)
- with alloc_fail(dev[0], 1, "=wps_er_ap_use_cached_settings"):
- hapd.disable()
- for i in range(2):
- ev = dev[0].wait_event([ "WPS-ER-AP-REMOVE",
- "CTRL-EVENT-DISCONNECTED" ],
- timeout=15)
- if ev is None:
- raise Exception("AP removal or disconnection timed out")
- hapd = hostapd.add_ap(apdev[0], params)
- for i in range(2):
- ev = dev[0].wait_event([ "WPS-ER-AP-ADD", "CTRL-EVENT-CONNECTED" ],
- timeout=15)
- if ev is None:
- raise Exception("AP discovery or connection timed out")
- dev[0].request("WPS_ER_STOP")
- def test_ap_wps_er_cache_ap_settings_oom2(dev, apdev):
- """WPS ER caching AP settings (OOM 2)"""
- try:
- _test_ap_wps_er_cache_ap_settings_oom2(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_cache_ap_settings_oom2(dev, apdev):
- ssid = "wps-er-add-enrollee"
- ap_pin = "12345670"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo" }
- hapd = hostapd.add_ap(apdev[0], params)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], ap_pin)
- id = int(dev[0].list_networks()[0]['id'])
- dev[0].set_network(id, "scan_freq", "2412")
- dev[0].request("WPS_ER_START ifname=lo")
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=15)
- if ev is None:
- raise Exception("AP discovery timed out")
- if ap_uuid not in ev:
- raise Exception("Expected AP UUID not found")
- dev[0].dump_monitor()
- dev[0].request("WPS_ER_LEARN " + ap_uuid + " " + ap_pin)
- ev = dev[0].wait_event(["WPS-ER-AP-SETTINGS"], timeout=15)
- if ev is None:
- raise Exception("AP learn timed out")
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=15)
- if ev is None:
- raise Exception("WPS-FAIL after AP learn timed out")
- time.sleep(0.1)
- with alloc_fail(dev[0], 1, "=wps_er_ap_cache_settings"):
- hapd.disable()
- for i in range(2):
- ev = dev[0].wait_event([ "WPS-ER-AP-REMOVE",
- "CTRL-EVENT-DISCONNECTED" ],
- timeout=15)
- if ev is None:
- raise Exception("AP removal or disconnection timed out")
- hapd = hostapd.add_ap(apdev[0], params)
- for i in range(2):
- ev = dev[0].wait_event([ "WPS-ER-AP-ADD", "CTRL-EVENT-CONNECTED" ],
- timeout=15)
- if ev is None:
- raise Exception("AP discovery or connection timed out")
- dev[0].request("WPS_ER_STOP")
- def test_ap_wps_er_subscribe_oom(dev, apdev):
- """WPS ER subscribe OOM"""
- try:
- _test_ap_wps_er_subscribe_oom(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_subscribe_oom(dev, apdev):
- ssid = "wps-er-add-enrollee"
- ap_pin = "12345670"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo" }
- hapd = hostapd.add_ap(apdev[0], params)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], ap_pin)
- id = int(dev[0].list_networks()[0]['id'])
- dev[0].set_network(id, "scan_freq", "2412")
- with alloc_fail(dev[0], 1, "http_client_addr;wps_er_subscribe"):
- dev[0].request("WPS_ER_START ifname=lo")
- for i in range(50):
- res = dev[0].request("GET_ALLOC_FAIL")
- if res.startswith("0:"):
- break
- time.sleep(0.1)
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=0)
- if ev:
- raise Exception("Unexpected AP discovery during OOM")
- dev[0].request("WPS_ER_STOP")
- def test_ap_wps_er_set_sel_reg_oom(dev, apdev):
- """WPS ER SetSelectedRegistrar OOM"""
- try:
- _test_ap_wps_er_set_sel_reg_oom(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_set_sel_reg_oom(dev, apdev):
- ssid = "wps-er-add-enrollee"
- ap_pin = "12345670"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo" }
- hapd = hostapd.add_ap(apdev[0], params)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], ap_pin)
- dev[0].request("WPS_ER_START ifname=lo")
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=10)
- if ev is None:
- raise Exception("AP not discovered")
- dev[0].request("WPS_ER_LEARN " + ap_uuid + " " + ap_pin)
- ev = dev[0].wait_event(["WPS-ER-AP-SETTINGS"], timeout=15)
- if ev is None:
- raise Exception("AP learn timed out")
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=15)
- if ev is None:
- raise Exception("WPS-FAIL timed out")
- time.sleep(0.1)
- for func in [ "http_client_url_parse;wps_er_send_set_sel_reg",
- "wps_er_soap_hdr;wps_er_send_set_sel_reg",
- "http_client_addr;wps_er_send_set_sel_reg",
- "wpabuf_alloc;wps_er_set_sel_reg" ]:
- with alloc_fail(dev[0], 1, func):
- if "OK" not in dev[0].request("WPS_ER_PBC " + ap_uuid):
- raise Exception("WPS_ER_PBC failed")
- ev = dev[0].wait_event(["WPS-PBC-ACTIVE"], timeout=3)
- if ev is None:
- raise Exception("WPS-PBC-ACTIVE not seen")
- dev[0].request("WPS_ER_STOP")
- @remote_compatible
- def test_ap_wps_er_learn_oom(dev, apdev):
- """WPS ER learn OOM"""
- try:
- _test_ap_wps_er_learn_oom(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_learn_oom(dev, apdev):
- ssid = "wps-er-add-enrollee"
- ap_pin = "12345670"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo" }
- hapd = hostapd.add_ap(apdev[0], params)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], ap_pin)
- dev[0].request("WPS_ER_START ifname=lo")
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=10)
- if ev is None:
- raise Exception("AP not discovered")
- for func in [ "wps_er_http_put_message_cb",
- "xml_get_base64_item;wps_er_http_put_message_cb",
- "http_client_url_parse;wps_er_ap_put_message",
- "wps_er_soap_hdr;wps_er_ap_put_message",
- "http_client_addr;wps_er_ap_put_message" ]:
- with alloc_fail(dev[0], 1, func):
- dev[0].request("WPS_ER_LEARN " + ap_uuid + " " + ap_pin)
- ev = dev[0].wait_event(["WPS-ER-AP-SETTINGS"], timeout=1)
- if ev is not None:
- raise Exception("AP learn succeeded during OOM")
- dev[0].request("WPS_ER_LEARN " + ap_uuid + " " + ap_pin)
- ev = dev[0].wait_event(["WPS-ER-AP-SETTINGS"], timeout=10)
- if ev is None:
- raise Exception("AP learn did not succeed")
- if "FAIL" not in dev[0].request("WPS_ER_LEARN 00000000-9e5c-4e73-bd82-f89cbcd10d7e " + ap_pin):
- raise Exception("WPS_ER_LEARN for unknown AP accepted")
- dev[0].request("WPS_ER_STOP")
- def test_ap_wps_fragmentation(dev, apdev):
- """WPS with fragmentation in EAP-WSC and mixed mode WPA+WPA2"""
- ssid = "test-wps-fragmentation"
- appin = "12345670"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "3",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "wpa_pairwise": "TKIP", "ap_pin": appin,
- "fragment_size": "50" })
- logger.info("WPS provisioning step (PBC)")
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].dump_monitor()
- dev[0].request("SET wps_fragment_size 50")
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- dev[0].wait_connected(timeout=30)
- status = dev[0].get_status()
- if status['wpa_state'] != 'COMPLETED':
- raise Exception("Not fully connected")
- if status['pairwise_cipher'] != 'CCMP' or status['group_cipher'] != 'TKIP':
- raise Exception("Unexpected encryption configuration")
- if status['key_mgmt'] != 'WPA2-PSK':
- raise Exception("Unexpected key_mgmt")
- logger.info("WPS provisioning step (PIN)")
- pin = dev[1].wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev[1].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[1].request("SET wps_fragment_size 50")
- dev[1].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- dev[1].wait_connected(timeout=30)
- status = dev[1].get_status()
- if status['wpa_state'] != 'COMPLETED':
- raise Exception("Not fully connected")
- if status['pairwise_cipher'] != 'CCMP' or status['group_cipher'] != 'TKIP':
- raise Exception("Unexpected encryption configuration")
- if status['key_mgmt'] != 'WPA2-PSK':
- raise Exception("Unexpected key_mgmt")
- logger.info("WPS connection as registrar")
- dev[2].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[2].request("SET wps_fragment_size 50")
- dev[2].wps_reg(apdev[0]['bssid'], appin)
- status = dev[2].get_status()
- if status['wpa_state'] != 'COMPLETED':
- raise Exception("Not fully connected")
- if status['pairwise_cipher'] != 'CCMP' or status['group_cipher'] != 'TKIP':
- raise Exception("Unexpected encryption configuration")
- if status['key_mgmt'] != 'WPA2-PSK':
- raise Exception("Unexpected key_mgmt")
- @remote_compatible
- def test_ap_wps_new_version_sta(dev, apdev):
- """WPS compatibility with new version number on the station"""
- ssid = "test-wps-ver"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP" })
- logger.info("WPS provisioning step")
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].dump_monitor()
- dev[0].request("SET wps_version_number 0x43")
- dev[0].request("SET wps_vendor_ext_m1 000137100100020001")
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- dev[0].wait_connected(timeout=30)
- @remote_compatible
- def test_ap_wps_new_version_ap(dev, apdev):
- """WPS compatibility with new version number on the AP"""
- ssid = "test-wps-ver"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP" })
- logger.info("WPS provisioning step")
- if "FAIL" in hapd.request("SET wps_version_number 0x43"):
- raise Exception("Failed to enable test functionality")
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].dump_monitor()
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- dev[0].wait_connected(timeout=30)
- hapd.request("SET wps_version_number 0x20")
- @remote_compatible
- def test_ap_wps_check_pin(dev, apdev):
- """Verify PIN checking through control interface"""
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": "wps", "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP" })
- for t in [ ("12345670", "12345670"),
- ("12345678", "FAIL-CHECKSUM"),
- ("12345", "FAIL"),
- ("123456789", "FAIL"),
- ("1234-5670", "12345670"),
- ("1234 5670", "12345670"),
- ("1-2.3:4 5670", "12345670") ]:
- res = hapd.request("WPS_CHECK_PIN " + t[0]).rstrip('\n')
- res2 = dev[0].request("WPS_CHECK_PIN " + t[0]).rstrip('\n')
- if res != res2:
- raise Exception("Unexpected difference in WPS_CHECK_PIN responses")
- if res != t[1]:
- raise Exception("Incorrect WPS_CHECK_PIN response {} (expected {})".format(res, t[1]))
- if "FAIL" not in hapd.request("WPS_CHECK_PIN 12345"):
- raise Exception("Unexpected WPS_CHECK_PIN success")
- if "FAIL" not in hapd.request("WPS_CHECK_PIN 123456789"):
- raise Exception("Unexpected WPS_CHECK_PIN success")
- for i in range(0, 10):
- pin = dev[0].request("WPS_PIN get")
- rpin = dev[0].request("WPS_CHECK_PIN " + pin).rstrip('\n')
- if pin != rpin:
- raise Exception("Random PIN validation failed for " + pin)
- def test_ap_wps_wep_config(dev, apdev):
- """WPS 2.0 AP rejecting WEP configuration"""
- ssid = "test-wps-config"
- appin = "12345670"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "ap_pin": appin})
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], appin, "wps-new-ssid-wep", "OPEN", "WEP",
- "hello", no_wait=True)
- ev = hapd.wait_event(["WPS-FAIL"], timeout=15)
- if ev is None:
- raise Exception("WPS-FAIL timed out")
- if "reason=2" not in ev:
- raise Exception("Unexpected reason code in WPS-FAIL")
- status = hapd.request("WPS_GET_STATUS")
- if "Last WPS result: Failed" not in status:
- raise Exception("WPS failure result not shown correctly")
- if "Failure Reason: WEP Prohibited" not in status:
- raise Exception("Failure reason not reported correctly")
- if "Peer Address: " + dev[0].p2p_interface_addr() not in status:
- raise Exception("Peer address not shown correctly")
- def test_ap_wps_wep_enroll(dev, apdev):
- """WPS 2.0 STA rejecting WEP configuration"""
- ssid = "test-wps-wep"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "skip_cred_build": "1", "extra_cred": "wps-wep-cred" }
- hapd = hostapd.add_ap(apdev[0], params)
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=15)
- if ev is None:
- raise Exception("WPS-FAIL event timed out")
- if "msg=12" not in ev or "reason=2 (WEP Prohibited)" not in ev:
- raise Exception("Unexpected WPS-FAIL event: " + ev)
- @remote_compatible
- def test_ap_wps_ie_fragmentation(dev, apdev):
- """WPS AP using fragmented WPS IE"""
- ssid = "test-wps-ie-fragmentation"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "1234567890abcdef1234567890abcdef",
- "manufacturer": "1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef",
- "model_name": "1234567890abcdef1234567890abcdef",
- "model_number": "1234567890abcdef1234567890abcdef",
- "serial_number": "1234567890abcdef1234567890abcdef" }
- hapd = hostapd.add_ap(apdev[0], params)
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- dev[0].wait_connected(timeout=30)
- bss = dev[0].get_bss(apdev[0]['bssid'])
- if "wps_device_name" not in bss or bss['wps_device_name'] != "1234567890abcdef1234567890abcdef":
- logger.info("Device Name not received correctly")
- logger.info(bss)
- # This can fail if Probe Response frame is missed and Beacon frame was
- # used to fill in the BSS entry. This can happen, e.g., during heavy
- # load every now and then and is not really an error, so try to
- # workaround by runnign another scan.
- dev[0].scan(freq="2412", only_new=True)
- bss = dev[0].get_bss(apdev[0]['bssid'])
- if not bss or "wps_device_name" not in bss or bss['wps_device_name'] != "1234567890abcdef1234567890abcdef":
- logger.info(bss)
- raise Exception("Device Name not received correctly")
- if len(re.findall("dd..0050f204", bss['ie'])) != 2:
- raise Exception("Unexpected number of WPS IEs")
- def get_psk(pskfile):
- psks = {}
- with open(pskfile, "r") as f:
- lines = f.read().splitlines()
- for l in lines:
- if l == "# WPA PSKs":
- continue
- (addr,psk) = l.split(' ')
- psks[addr] = psk
- return psks
- def test_ap_wps_per_station_psk(dev, apdev):
- """WPS PBC provisioning with per-station PSK"""
- addr0 = dev[0].own_addr()
- addr1 = dev[1].own_addr()
- addr2 = dev[2].own_addr()
- ssid = "wps"
- appin = "12345670"
- pskfile = "/tmp/ap_wps_per_enrollee_psk.psk_file"
- try:
- os.remove(pskfile)
- except:
- pass
- hapd = None
- try:
- with open(pskfile, "w") as f:
- f.write("# WPA PSKs\n")
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa": "2", "wpa_key_mgmt": "WPA-PSK",
- "rsn_pairwise": "CCMP", "ap_pin": appin,
- "wpa_psk_file": pskfile }
- hapd = hostapd.add_ap(apdev[0], params)
- logger.info("First enrollee")
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- dev[0].wait_connected(timeout=30)
- logger.info("Second enrollee")
- hapd.request("WPS_PBC")
- dev[1].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[1].request("WPS_PBC " + apdev[0]['bssid'])
- dev[1].wait_connected(timeout=30)
- logger.info("External registrar")
- dev[2].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[2].wps_reg(apdev[0]['bssid'], appin)
- logger.info("Verifying PSK results")
- psks = get_psk(pskfile)
- if addr0 not in psks:
- raise Exception("No PSK recorded for sta0")
- if addr1 not in psks:
- raise Exception("No PSK recorded for sta1")
- if addr2 not in psks:
- raise Exception("No PSK recorded for sta2")
- if psks[addr0] == psks[addr1]:
- raise Exception("Same PSK recorded for sta0 and sta1")
- if psks[addr0] == psks[addr2]:
- raise Exception("Same PSK recorded for sta0 and sta2")
- if psks[addr1] == psks[addr2]:
- raise Exception("Same PSK recorded for sta1 and sta2")
- dev[0].request("REMOVE_NETWORK all")
- logger.info("Second external registrar")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].wps_reg(apdev[0]['bssid'], appin)
- psks2 = get_psk(pskfile)
- if addr0 not in psks2:
- raise Exception("No PSK recorded for sta0(reg)")
- if psks[addr0] == psks2[addr0]:
- raise Exception("Same PSK recorded for sta0(enrollee) and sta0(reg)")
- finally:
- os.remove(pskfile)
- if hapd:
- dev[0].request("DISCONNECT")
- dev[1].request("DISCONNECT")
- dev[2].request("DISCONNECT")
- hapd.disable()
- dev[0].flush_scan_cache()
- dev[1].flush_scan_cache()
- dev[2].flush_scan_cache()
- def test_ap_wps_per_station_psk_failure(dev, apdev):
- """WPS PBC provisioning with per-station PSK (file not writable)"""
- addr0 = dev[0].p2p_dev_addr()
- addr1 = dev[1].p2p_dev_addr()
- addr2 = dev[2].p2p_dev_addr()
- ssid = "wps"
- appin = "12345670"
- pskfile = "/tmp/ap_wps_per_enrollee_psk.psk_file"
- try:
- os.remove(pskfile)
- except:
- pass
- try:
- with open(pskfile, "w") as f:
- f.write("# WPA PSKs\n")
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa": "2", "wpa_key_mgmt": "WPA-PSK",
- "rsn_pairwise": "CCMP", "ap_pin": appin,
- "wpa_psk_file": pskfile }
- hapd = hostapd.add_ap(apdev[0], params)
- if "FAIL" in hapd.request("SET wpa_psk_file /tmp/does/not/exists/ap_wps_per_enrollee_psk_failure.psk_file"):
- raise Exception("Failed to set wpa_psk_file")
- logger.info("First enrollee")
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- dev[0].wait_connected(timeout=30)
- logger.info("Second enrollee")
- hapd.request("WPS_PBC")
- dev[1].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[1].request("WPS_PBC " + apdev[0]['bssid'])
- dev[1].wait_connected(timeout=30)
- logger.info("External registrar")
- dev[2].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[2].wps_reg(apdev[0]['bssid'], appin)
- logger.info("Verifying PSK results")
- psks = get_psk(pskfile)
- if len(psks) > 0:
- raise Exception("PSK recorded unexpectedly")
- finally:
- os.remove(pskfile)
- def test_ap_wps_pin_request_file(dev, apdev):
- """WPS PIN provisioning with configured AP"""
- ssid = "wps"
- pinfile = "/tmp/ap_wps_pin_request_file.log"
- if os.path.exists(pinfile):
- os.remove(pinfile)
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wps_pin_requests": pinfile,
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- uuid = dev[0].get_status_field("uuid")
- pin = dev[0].wps_read_pin()
- try:
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = hapd.wait_event(["WPS-PIN-NEEDED"], timeout=15)
- if ev is None:
- raise Exception("PIN needed event not shown")
- if uuid not in ev:
- raise Exception("UUID mismatch")
- dev[0].request("WPS_CANCEL")
- success = False
- with open(pinfile, "r") as f:
- lines = f.readlines()
- for l in lines:
- if uuid in l:
- success = True
- break
- if not success:
- raise Exception("PIN request entry not in the log file")
- finally:
- try:
- os.remove(pinfile)
- except:
- pass
- def test_ap_wps_auto_setup_with_config_file(dev, apdev):
- """WPS auto-setup with configuration file"""
- conffile = "/tmp/ap_wps_auto_setup_with_config_file.conf"
- ifname = apdev[0]['ifname']
- try:
- with open(conffile, "w") as f:
- f.write("driver=nl80211\n")
- f.write("hw_mode=g\n")
- f.write("channel=1\n")
- f.write("ieee80211n=1\n")
- f.write("interface=%s\n" % ifname)
- f.write("ctrl_interface=/var/run/hostapd\n")
- f.write("ssid=wps\n")
- f.write("eap_server=1\n")
- f.write("wps_state=1\n")
- hapd = hostapd.add_bss(apdev[0], ifname, conffile)
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- dev[0].wait_connected(timeout=30)
- with open(conffile, "r") as f:
- lines = f.read().splitlines()
- vals = dict()
- for l in lines:
- try:
- [name,value] = l.split('=', 1)
- vals[name] = value
- except ValueError, e:
- if "# WPS configuration" in l:
- pass
- else:
- raise Exception("Unexpected configuration line: " + l)
- if vals['ieee80211n'] != '1' or vals['wps_state'] != '2' or "WPA-PSK" not in vals['wpa_key_mgmt']:
- raise Exception("Incorrect configuration: " + str(vals))
- finally:
- try:
- os.remove(conffile)
- except:
- pass
- def test_ap_wps_pbc_timeout(dev, apdev, params):
- """wpa_supplicant PBC walk time and WPS ER SelReg timeout [long]"""
- if not params['long']:
- raise HwsimSkip("Skip test case with long duration due to --long not specified")
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- hapd = add_ssdp_ap(apdev[0], ap_uuid)
- location = ssdp_get_location(ap_uuid)
- urls = upnp_get_urls(location)
- eventurl = urlparse.urlparse(urls['event_sub_url'])
- ctrlurl = urlparse.urlparse(urls['control_url'])
- url = urlparse.urlparse(location)
- conn = httplib.HTTPConnection(url.netloc)
- class WPSERHTTPServer(SocketServer.StreamRequestHandler):
- def handle(self):
- data = self.rfile.readline().strip()
- logger.debug(data)
- self.wfile.write(gen_wps_event())
- server = MyTCPServer(("127.0.0.1", 12345), WPSERHTTPServer)
- server.timeout = 1
- headers = { "callback": '<http://127.0.0.1:12345/event>',
- "NT": "upnp:event",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- sid = resp.getheader("sid")
- logger.debug("Subscription SID " + sid)
- msg = '''<?xml version="1.0"?>
- <s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
- <s:Body>
- <u:SetSelectedRegistrar xmlns:u="urn:schemas-wifialliance-org:service:WFAWLANConfig:1">
- <NewMessage>EEoAARAQQQABARASAAIAABBTAAIxSBBJAA4ANyoAASABBv///////xBIABA2LbR7pTpRkYj7
- VFi5hrLk
- </NewMessage>
- </u:SetSelectedRegistrar>
- </s:Body>
- </s:Envelope>'''
- headers = { "Content-type": 'text/xml; charset="utf-8"' }
- headers["SOAPAction"] = '"urn:schemas-wifialliance-org:service:WFAWLANConfig:1#%s"' % "SetSelectedRegistrar"
- conn.request("POST", ctrlurl.path, msg, headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- server.handle_request()
- logger.info("Start WPS_PBC and wait for PBC walk time expiration")
- if "OK" not in dev[0].request("WPS_PBC"):
- raise Exception("WPS_PBC failed")
- start = os.times()[4]
- server.handle_request()
- dev[1].request("BSS_FLUSH 0")
- dev[1].scan_for_bss(apdev[0]['bssid'], freq="2412", force_scan=True,
- only_new=True)
- bss = dev[1].get_bss(apdev[0]['bssid'])
- logger.debug("BSS: " + str(bss))
- if '[WPS-AUTH]' not in bss['flags']:
- raise Exception("WPS not indicated authorized")
- server.handle_request()
- wps_timeout_seen = False
- while True:
- hapd.dump_monitor()
- dev[1].dump_monitor()
- if not wps_timeout_seen:
- ev = dev[0].wait_event(["WPS-TIMEOUT"], timeout=0)
- if ev is not None:
- logger.info("PBC timeout seen")
- wps_timeout_seen = True
- else:
- dev[0].dump_monitor()
- now = os.times()[4]
- if now - start > 130:
- raise Exception("Selected registration information not removed")
- dev[1].request("BSS_FLUSH 0")
- dev[1].scan_for_bss(apdev[0]['bssid'], freq="2412", force_scan=True,
- only_new=True)
- bss = dev[1].get_bss(apdev[0]['bssid'])
- logger.debug("BSS: " + str(bss))
- if '[WPS-AUTH]' not in bss['flags']:
- break
- server.handle_request()
- server.server_close()
- if wps_timeout_seen:
- return
- now = os.times()[4]
- if now < start + 150:
- dur = start + 150 - now
- else:
- dur = 1
- logger.info("Continue waiting for PBC timeout (%d sec)" % dur)
- ev = dev[0].wait_event(["WPS-TIMEOUT"], timeout=dur)
- if ev is None:
- raise Exception("WPS-TIMEOUT not reported")
- def add_ssdp_ap(ap, ap_uuid):
- ssid = "wps-ssdp"
- ap_pin = "12345670"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo",
- "friendly_name": "WPS Access Point",
- "manufacturer_url": "http://www.example.com/",
- "model_description": "Wireless Access Point",
- "model_url": "http://www.example.com/model/",
- "upc": "123456789012" }
- return hostapd.add_ap(ap, params)
- def ssdp_send(msg, no_recv=False):
- socket.setdefaulttimeout(1)
- sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
- sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
- sock.setsockopt(socket.IPPROTO_IP, socket.IP_MULTICAST_TTL, 2)
- sock.bind(("127.0.0.1", 0))
- sock.sendto(msg, ("239.255.255.250", 1900))
- if no_recv:
- return None
- return sock.recv(1000)
- def ssdp_send_msearch(st, no_recv=False):
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MX: 1',
- 'MAN: "ssdp:discover"',
- 'ST: ' + st,
- '', ''])
- return ssdp_send(msg, no_recv=no_recv)
- def test_ap_wps_ssdp_msearch(dev, apdev):
- """WPS AP and SSDP M-SEARCH messages"""
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- add_ssdp_ap(apdev[0], ap_uuid)
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'Host: 239.255.255.250:1900',
- 'Mx: 1',
- 'Man: "ssdp:discover"',
- 'St: urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- ssdp_send(msg)
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'host:\t239.255.255.250:1900\t\t\t\t \t\t',
- 'mx: \t1\t\t ',
- 'man: \t \t "ssdp:discover" ',
- 'st: urn:schemas-wifialliance-org:device:WFADevice:1\t\t',
- '', ''])
- ssdp_send(msg)
- ssdp_send_msearch("ssdp:all")
- ssdp_send_msearch("upnp:rootdevice")
- ssdp_send_msearch("uuid:" + ap_uuid)
- ssdp_send_msearch("urn:schemas-wifialliance-org:service:WFAWLANConfig:1")
- ssdp_send_msearch("urn:schemas-wifialliance-org:device:WFADevice:1")
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST:\t239.255.255.250:1900',
- 'MAN: "ssdp:discover"',
- 'MX: 130',
- 'ST: urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- ssdp_send(msg, no_recv=True)
- def test_ap_wps_ssdp_invalid_msearch(dev, apdev):
- """WPS AP and invalid SSDP M-SEARCH messages"""
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- add_ssdp_ap(apdev[0], ap_uuid)
- socket.setdefaulttimeout(1)
- sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
- sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
- sock.setsockopt(socket.IPPROTO_IP, socket.IP_MULTICAST_TTL, 2)
- sock.bind(("127.0.0.1", 0))
- logger.debug("Missing MX")
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MAN: "ssdp:discover"',
- 'ST: urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- logger.debug("Negative MX")
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MX: -1',
- 'MAN: "ssdp:discover"',
- 'ST: urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- logger.debug("Invalid MX")
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MX; 1',
- 'MAN: "ssdp:discover"',
- 'ST: urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- logger.debug("Missing MAN")
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MX: 1',
- 'ST: urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- logger.debug("Invalid MAN")
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MX: 1',
- 'MAN: foo',
- 'ST: urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MX: 1',
- 'MAN; "ssdp:discover"',
- 'ST: urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- logger.debug("Missing HOST")
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'MAN: "ssdp:discover"',
- 'MX: 1',
- 'ST: urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- logger.debug("Missing ST")
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MAN: "ssdp:discover"',
- 'MX: 1',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- logger.debug("Mismatching ST")
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MAN: "ssdp:discover"',
- 'MX: 1',
- 'ST: uuid:16d5f8a9-4ee4-4f5e-81f9-cc6e2f47f42d',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MAN: "ssdp:discover"',
- 'MX: 1',
- 'ST: foo:bar',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MAN: "ssdp:discover"',
- 'MX: 1',
- 'ST: foobar',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- logger.debug("Invalid ST")
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MAN: "ssdp:discover"',
- 'MX: 1',
- 'ST; urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- logger.debug("Invalid M-SEARCH")
- msg = '\r\n'.join([
- 'M+SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MAN: "ssdp:discover"',
- 'MX: 1',
- 'ST: urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- msg = '\r\n'.join([
- 'M-SEARCH-* HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MAN: "ssdp:discover"',
- 'MX: 1',
- 'ST: urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- logger.debug("Invalid message format")
- sock.sendto("NOTIFY * HTTP/1.1", ("239.255.255.250", 1900))
- msg = '\r'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MAN: "ssdp:discover"',
- 'MX: 1',
- 'ST: urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- try:
- r = sock.recv(1000)
- raise Exception("Unexpected M-SEARCH response: " + r)
- except socket.timeout:
- pass
- logger.debug("Valid M-SEARCH")
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MAN: "ssdp:discover"',
- 'MX: 1',
- 'ST: urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- sock.sendto(msg, ("239.255.255.250", 1900))
- try:
- r = sock.recv(1000)
- pass
- except socket.timeout:
- raise Exception("No SSDP response")
- def test_ap_wps_ssdp_burst(dev, apdev):
- """WPS AP and SSDP burst"""
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- add_ssdp_ap(apdev[0], ap_uuid)
- msg = '\r\n'.join([
- 'M-SEARCH * HTTP/1.1',
- 'HOST: 239.255.255.250:1900',
- 'MAN: "ssdp:discover"',
- 'MX: 1',
- 'ST: urn:schemas-wifialliance-org:device:WFADevice:1',
- '', ''])
- socket.setdefaulttimeout(1)
- sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
- sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
- sock.setsockopt(socket.IPPROTO_IP, socket.IP_MULTICAST_TTL, 2)
- sock.bind(("127.0.0.1", 0))
- for i in range(0, 25):
- sock.sendto(msg, ("239.255.255.250", 1900))
- resp = 0
- while True:
- try:
- r = sock.recv(1000)
- if not r.startswith("HTTP/1.1 200 OK\r\n"):
- raise Exception("Unexpected message: " + r)
- resp += 1
- except socket.timeout:
- break
- if resp < 20:
- raise Exception("Too few SSDP responses")
- sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
- sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
- sock.setsockopt(socket.IPPROTO_IP, socket.IP_MULTICAST_TTL, 2)
- sock.bind(("127.0.0.1", 0))
- for i in range(0, 25):
- sock.sendto(msg, ("239.255.255.250", 1900))
- while True:
- try:
- r = sock.recv(1000)
- if ap_uuid in r:
- break
- except socket.timeout:
- raise Exception("No SSDP response")
- def ssdp_get_location(uuid):
- res = ssdp_send_msearch("uuid:" + uuid)
- location = None
- for l in res.splitlines():
- if l.lower().startswith("location:"):
- location = l.split(':', 1)[1].strip()
- break
- if location is None:
- raise Exception("No UPnP location found")
- return location
- def upnp_get_urls(location):
- conn = urllib.urlopen(location, proxies={})
- tree = ET.parse(conn)
- root = tree.getroot()
- urn = '{urn:schemas-upnp-org:device-1-0}'
- service = root.find("./" + urn + "device/" + urn + "serviceList/" + urn + "service")
- res = {}
- res['scpd_url'] = urlparse.urljoin(location, service.find(urn + 'SCPDURL').text)
- res['control_url'] = urlparse.urljoin(location, service.find(urn + 'controlURL').text)
- res['event_sub_url'] = urlparse.urljoin(location, service.find(urn + 'eventSubURL').text)
- return res
- def upnp_soap_action(conn, path, action, include_soap_action=True,
- soap_action_override=None, newmsg=None, neweventtype=None,
- neweventmac=None):
- soapns = 'http://schemas.xmlsoap.org/soap/envelope/'
- wpsns = 'urn:schemas-wifialliance-org:service:WFAWLANConfig:1'
- ET.register_namespace('soapenv', soapns)
- ET.register_namespace('wfa', wpsns)
- attrib = {}
- attrib['{%s}encodingStyle' % soapns] = 'http://schemas.xmlsoap.org/soap/encoding/'
- root = ET.Element("{%s}Envelope" % soapns, attrib=attrib)
- body = ET.SubElement(root, "{%s}Body" % soapns)
- act = ET.SubElement(body, "{%s}%s" % (wpsns, action))
- if newmsg:
- msg = ET.SubElement(act, "NewMessage")
- msg.text = base64.b64encode(newmsg)
- if neweventtype:
- msg = ET.SubElement(act, "NewWLANEventType")
- msg.text = neweventtype
- if neweventmac:
- msg = ET.SubElement(act, "NewWLANEventMAC")
- msg.text = neweventmac
- tree = ET.ElementTree(root)
- soap = StringIO.StringIO()
- tree.write(soap, xml_declaration=True, encoding='utf-8')
- headers = { "Content-type": 'text/xml; charset="utf-8"' }
- if include_soap_action:
- headers["SOAPAction"] = '"urn:schemas-wifialliance-org:service:WFAWLANConfig:1#%s"' % action
- elif soap_action_override:
- headers["SOAPAction"] = soap_action_override
- conn.request("POST", path, soap.getvalue(), headers)
- return conn.getresponse()
- def test_ap_wps_upnp(dev, apdev):
- """WPS AP and UPnP operations"""
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- add_ssdp_ap(apdev[0], ap_uuid)
- location = ssdp_get_location(ap_uuid)
- urls = upnp_get_urls(location)
- conn = urllib.urlopen(urls['scpd_url'], proxies={})
- scpd = conn.read()
- conn = urllib.urlopen(urlparse.urljoin(location, "unknown.html"),
- proxies={})
- if conn.getcode() != 404:
- raise Exception("Unexpected HTTP response to GET unknown URL")
- url = urlparse.urlparse(location)
- conn = httplib.HTTPConnection(url.netloc)
- #conn.set_debuglevel(1)
- headers = { "Content-type": 'text/xml; charset="utf-8"',
- "SOAPAction": '"urn:schemas-wifialliance-org:service:WFAWLANConfig:1#GetDeviceInfo"' }
- conn.request("POST", "hello", "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 404:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- conn.request("UNKNOWN", "hello", "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 501:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- headers = { "Content-type": 'text/xml; charset="utf-8"',
- "SOAPAction": '"urn:some-unknown-action#GetDeviceInfo"' }
- ctrlurl = urlparse.urlparse(urls['control_url'])
- conn.request("POST", ctrlurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 401:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("GetDeviceInfo without SOAPAction header")
- resp = upnp_soap_action(conn, ctrlurl.path, "GetDeviceInfo",
- include_soap_action=False)
- if resp.status != 401:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("GetDeviceInfo with invalid SOAPAction header")
- for act in [ "foo",
- "urn:schemas-wifialliance-org:service:WFAWLANConfig:1#GetDeviceInfo",
- '"urn:schemas-wifialliance-org:service:WFAWLANConfig:1"',
- '"urn:schemas-wifialliance-org:service:WFAWLANConfig:123#GetDevice']:
- resp = upnp_soap_action(conn, ctrlurl.path, "GetDeviceInfo",
- include_soap_action=False,
- soap_action_override=act)
- if resp.status != 401:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- resp = upnp_soap_action(conn, ctrlurl.path, "GetDeviceInfo")
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- dev = resp.read()
- if "NewDeviceInfo" not in dev:
- raise Exception("Unexpected GetDeviceInfo response")
- logger.debug("PutMessage without required parameters")
- resp = upnp_soap_action(conn, ctrlurl.path, "PutMessage")
- if resp.status != 600:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("PutWLANResponse without required parameters")
- resp = upnp_soap_action(conn, ctrlurl.path, "PutWLANResponse")
- if resp.status != 600:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("SetSelectedRegistrar from unregistered ER")
- resp = upnp_soap_action(conn, ctrlurl.path, "SetSelectedRegistrar")
- if resp.status != 501:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("Unknown action")
- resp = upnp_soap_action(conn, ctrlurl.path, "Unknown")
- if resp.status != 401:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- def test_ap_wps_upnp_subscribe(dev, apdev):
- """WPS AP and UPnP event subscription"""
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- hapd = add_ssdp_ap(apdev[0], ap_uuid)
- location = ssdp_get_location(ap_uuid)
- urls = upnp_get_urls(location)
- eventurl = urlparse.urlparse(urls['event_sub_url'])
- url = urlparse.urlparse(location)
- conn = httplib.HTTPConnection(url.netloc)
- #conn.set_debuglevel(1)
- headers = { "callback": '<http://127.0.0.1:12345/event>',
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", "hello", "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 412:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 412:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- headers = { "NT": "upnp:event",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 412:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- headers = { "callback": '<http://127.0.0.1:12345/event>',
- "NT": "upnp:foobar",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 400:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("Valid subscription")
- headers = { "callback": '<http://127.0.0.1:12345/event>',
- "NT": "upnp:event",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- sid = resp.getheader("sid")
- logger.debug("Subscription SID " + sid)
- logger.debug("Invalid re-subscription")
- headers = { "NT": "upnp:event",
- "sid": "123456734567854",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 400:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("Invalid re-subscription")
- headers = { "NT": "upnp:event",
- "sid": "uuid:123456734567854",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 400:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("Invalid re-subscription")
- headers = { "callback": '<http://127.0.0.1:12345/event>',
- "NT": "upnp:event",
- "sid": sid,
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 400:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("SID mismatch in re-subscription")
- headers = { "NT": "upnp:event",
- "sid": "uuid:4c2bca79-1ff4-4e43-85d4-952a2b8a51fb",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 412:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("Valid re-subscription")
- headers = { "NT": "upnp:event",
- "sid": sid,
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- sid2 = resp.getheader("sid")
- logger.debug("Subscription SID " + sid2)
- if sid != sid2:
- raise Exception("Unexpected SID change")
- logger.debug("Valid re-subscription")
- headers = { "NT": "upnp:event",
- "sid": "uuid: \t \t" + sid.split(':')[1],
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("Invalid unsubscription")
- headers = { "sid": sid }
- conn.request("UNSUBSCRIBE", "/hello", "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 412:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- headers = { "foo": "bar" }
- conn.request("UNSUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 412:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("Valid unsubscription")
- headers = { "sid": sid }
- conn.request("UNSUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("Unsubscription for not existing SID")
- headers = { "sid": sid }
- conn.request("UNSUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 412:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("Invalid unsubscription")
- headers = { "sid": " \t \tfoo" }
- conn.request("UNSUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 400:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("Invalid unsubscription")
- headers = { "sid": "uuid:\t \tfoo" }
- conn.request("UNSUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 400:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("Invalid unsubscription")
- headers = { "NT": "upnp:event",
- "sid": sid }
- conn.request("UNSUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 400:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- headers = { "callback": '<http://127.0.0.1:12345/event>',
- "sid": sid }
- conn.request("UNSUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 400:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.debug("Valid subscription with multiple callbacks")
- headers = { "callback": '<http://127.0.0.1:12345/event> <http://127.0.0.1:12345/event>\t<http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event><http://127.0.0.1:12345/event>',
- "NT": "upnp:event",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- sid = resp.getheader("sid")
- logger.debug("Subscription SID " + sid)
- # Force subscription to be deleted due to errors
- dev[1].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[2].scan_for_bss(apdev[0]['bssid'], freq=2412)
- with alloc_fail(hapd, 1, "event_build_message"):
- for i in range(10):
- dev[1].dump_monitor()
- dev[2].dump_monitor()
- dev[1].request("WPS_PIN " + apdev[0]['bssid'] + " 12345670")
- dev[2].request("WPS_PIN " + apdev[0]['bssid'] + " 12345670")
- dev[1].wait_event(["CTRL-EVENT-SCAN-RESULTS"], 5)
- dev[1].request("WPS_CANCEL")
- dev[2].wait_event(["CTRL-EVENT-SCAN-RESULTS"], 5)
- dev[2].request("WPS_CANCEL")
- if i % 4 == 1:
- time.sleep(1)
- else:
- time.sleep(0.1)
- time.sleep(0.2)
- headers = { "sid": sid }
- conn.request("UNSUBSCRIBE", eventurl.path, "", headers)
- resp = conn.getresponse()
- if resp.status != 200 and resp.status != 412:
- raise Exception("Unexpected HTTP response for UNSUBSCRIBE: %d" % resp.status)
- headers = { "callback": '<http://127.0.0.1:12345/event>',
- "NT": "upnp:event",
- "timeout": "Second-1234" }
- with alloc_fail(hapd, 1, "http_client_addr;event_send_start"):
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response for SUBSCRIBE: %d" % resp.status)
- sid = resp.getheader("sid")
- logger.debug("Subscription SID " + sid)
- headers = { "sid": sid }
- conn.request("UNSUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response for UNSUBSCRIBE: %d" % resp.status)
- headers = { "callback": '<http://127.0.0.1:12345/event>',
- "NT": "upnp:event",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- sid = resp.getheader("sid")
- logger.debug("Subscription SID " + sid)
- with alloc_fail(hapd, 1, "=event_add"):
- for i in range(2):
- dev[1].dump_monitor()
- dev[2].dump_monitor()
- dev[1].request("WPS_PIN " + apdev[0]['bssid'] + " 12345670")
- dev[2].request("WPS_PIN " + apdev[0]['bssid'] + " 12345670")
- dev[1].wait_event(["CTRL-EVENT-SCAN-RESULTS"], 5)
- dev[1].request("WPS_CANCEL")
- dev[2].wait_event(["CTRL-EVENT-SCAN-RESULTS"], 5)
- dev[2].request("WPS_CANCEL")
- if i == 0:
- time.sleep(1)
- else:
- time.sleep(0.1)
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- with alloc_fail(hapd, 1, "wpabuf_dup;event_add"):
- dev[1].dump_monitor()
- dev[2].dump_monitor()
- dev[1].request("WPS_PIN " + apdev[0]['bssid'] + " 12345670")
- dev[2].request("WPS_PIN " + apdev[0]['bssid'] + " 12345670")
- dev[1].wait_event(["CTRL-EVENT-SCAN-RESULTS"], 5)
- dev[1].request("WPS_CANCEL")
- dev[2].wait_event(["CTRL-EVENT-SCAN-RESULTS"], 5)
- dev[2].request("WPS_CANCEL")
- time.sleep(0.1)
- with fail_test(hapd, 1, "os_get_random;uuid_make;subscription_start"):
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 500:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- with alloc_fail(hapd, 1, "=subscription_start"):
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 500:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- headers = { "callback": '',
- "NT": "upnp:event",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 500:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- headers = { "callback": ' <',
- "NT": "upnp:event",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 500:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- headers = { "callback": '<http://127.0.0.1:12345/event>',
- "NT": "upnp:event",
- "timeout": "Second-1234" }
- with alloc_fail(hapd, 1, "wpabuf_alloc;subscription_first_event"):
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 500:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- with alloc_fail(hapd, 1, "event_add;subscription_first_event"):
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 500:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- with alloc_fail(hapd, 1, "subscr_addr_add_url"):
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 500:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- with alloc_fail(hapd, 2, "subscr_addr_add_url"):
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 500:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- for i in range(6):
- headers = { "callback": '<http://127.0.0.1:%d/event>' % (12345 + i),
- "NT": "upnp:event",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- with alloc_fail(hapd, 1, "=upnp_wps_device_send_wlan_event"):
- dev[1].dump_monitor()
- dev[1].request("WPS_PIN " + apdev[0]['bssid'] + " 12345670")
- dev[1].wait_event(["CTRL-EVENT-SCAN-RESULTS"], 5)
- dev[1].request("WPS_CANCEL")
- time.sleep(0.1)
- with alloc_fail(hapd, 1, "wpabuf_alloc;upnp_wps_device_send_event"):
- dev[1].dump_monitor()
- dev[1].request("WPS_PIN " + apdev[0]['bssid'] + " 12345670")
- dev[1].wait_event(["CTRL-EVENT-SCAN-RESULTS"], 5)
- dev[1].request("WPS_CANCEL")
- time.sleep(0.1)
- with alloc_fail(hapd, 1, "base64_encode;upnp_wps_device_send_wlan_event"):
- dev[1].dump_monitor()
- dev[1].request("WPS_PIN " + apdev[0]['bssid'] + " 12345670")
- dev[1].wait_event(["CTRL-EVENT-SCAN-RESULTS"], 5)
- dev[1].request("WPS_CANCEL")
- time.sleep(0.1)
- hapd.disable()
- with alloc_fail(hapd, 1, "get_netif_info"):
- if "FAIL" not in hapd.request("ENABLE"):
- raise Exception("ENABLE succeeded during OOM")
- def test_ap_wps_upnp_subscribe_events(dev, apdev):
- """WPS AP and UPnP event subscription and many events"""
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- hapd = add_ssdp_ap(apdev[0], ap_uuid)
- location = ssdp_get_location(ap_uuid)
- urls = upnp_get_urls(location)
- eventurl = urlparse.urlparse(urls['event_sub_url'])
- class WPSERHTTPServer(SocketServer.StreamRequestHandler):
- def handle(self):
- data = self.rfile.readline().strip()
- logger.debug(data)
- self.wfile.write(gen_wps_event())
- server = MyTCPServer(("127.0.0.1", 12345), WPSERHTTPServer)
- server.timeout = 1
- url = urlparse.urlparse(location)
- conn = httplib.HTTPConnection(url.netloc)
- headers = { "callback": '<http://127.0.0.1:12345/event>',
- "NT": "upnp:event",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- sid = resp.getheader("sid")
- logger.debug("Subscription SID " + sid)
- # Fetch the first event message
- server.handle_request()
- # Force subscription event queue to reach the maximum length by generating
- # new proxied events without the ER fetching any of the pending events.
- dev[1].scan_for_bss(apdev[0]['bssid'], freq=2412)
- dev[2].scan_for_bss(apdev[0]['bssid'], freq=2412)
- for i in range(16):
- dev[1].dump_monitor()
- dev[2].dump_monitor()
- dev[1].request("WPS_PIN " + apdev[0]['bssid'] + " 12345670")
- dev[2].request("WPS_PIN " + apdev[0]['bssid'] + " 12345670")
- dev[1].wait_event(["CTRL-EVENT-SCAN-RESULTS"], 5)
- dev[1].request("WPS_CANCEL")
- dev[2].wait_event(["CTRL-EVENT-SCAN-RESULTS"], 5)
- dev[2].request("WPS_CANCEL")
- if i % 4 == 1:
- time.sleep(1)
- else:
- time.sleep(0.1)
- hapd.request("WPS_PIN any 12345670")
- dev[1].dump_monitor()
- dev[1].request("WPS_PIN " + apdev[0]['bssid'] + " 12345670")
- ev = dev[1].wait_event(["WPS-SUCCESS"], timeout=10)
- if ev is None:
- raise Exception("WPS success not reported")
- # Close the WPS ER HTTP server without fetching all the pending events.
- # This tests hostapd code path that clears subscription and the remaining
- # event queue when the interface is deinitialized.
- server.handle_request()
- server.server_close()
- dev[1].wait_connected()
- def test_ap_wps_upnp_http_proto(dev, apdev):
- """WPS AP and UPnP/HTTP protocol testing"""
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- add_ssdp_ap(apdev[0], ap_uuid)
- location = ssdp_get_location(ap_uuid)
- url = urlparse.urlparse(location)
- conn = httplib.HTTPConnection(url.netloc, timeout=0.2)
- #conn.set_debuglevel(1)
- conn.request("HEAD", "hello")
- resp = conn.getresponse()
- if resp.status != 501:
- raise Exception("Unexpected response to HEAD: " + str(resp.status))
- conn.close()
- for cmd in [ "PUT", "DELETE", "TRACE", "CONNECT", "M-SEARCH", "M-POST" ]:
- try:
- conn.request(cmd, "hello")
- resp = conn.getresponse()
- except Exception, e:
- pass
- conn.close()
- headers = { "Content-Length": 'abc' }
- conn.request("HEAD", "hello", "\r\n\r\n", headers)
- try:
- resp = conn.getresponse()
- except Exception, e:
- pass
- conn.close()
- headers = { "Content-Length": '-10' }
- conn.request("HEAD", "hello", "\r\n\r\n", headers)
- try:
- resp = conn.getresponse()
- except Exception, e:
- pass
- conn.close()
- headers = { "Content-Length": '10000000000000' }
- conn.request("HEAD", "hello", "\r\n\r\nhello", headers)
- try:
- resp = conn.getresponse()
- except Exception, e:
- pass
- conn.close()
- headers = { "Transfer-Encoding": 'abc' }
- conn.request("HEAD", "hello", "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 501:
- raise Exception("Unexpected response to HEAD: " + str(resp.status))
- conn.close()
- headers = { "Transfer-Encoding": 'chunked' }
- conn.request("HEAD", "hello", "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 501:
- raise Exception("Unexpected response to HEAD: " + str(resp.status))
- conn.close()
- # Too long a header
- conn.request("HEAD", 5000 * 'A')
- try:
- resp = conn.getresponse()
- except Exception, e:
- pass
- conn.close()
- # Long URL but within header length limits
- conn.request("HEAD", 3000 * 'A')
- resp = conn.getresponse()
- if resp.status != 501:
- raise Exception("Unexpected response to HEAD: " + str(resp.status))
- conn.close()
- headers = { "Content-Length": '20' }
- conn.request("POST", "hello", 10 * 'A' + "\r\n\r\n", headers)
- try:
- resp = conn.getresponse()
- except Exception, e:
- pass
- conn.close()
- conn.request("POST", "hello", 5000 * 'A' + "\r\n\r\n")
- resp = conn.getresponse()
- if resp.status != 404:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- conn.close()
- conn.request("POST", "hello", 60000 * 'A' + "\r\n\r\n")
- try:
- resp = conn.getresponse()
- except Exception, e:
- pass
- conn.close()
- def test_ap_wps_upnp_http_proto_chunked(dev, apdev):
- """WPS AP and UPnP/HTTP protocol testing for chunked encoding"""
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- add_ssdp_ap(apdev[0], ap_uuid)
- location = ssdp_get_location(ap_uuid)
- url = urlparse.urlparse(location)
- conn = httplib.HTTPConnection(url.netloc)
- #conn.set_debuglevel(1)
- headers = { "Transfer-Encoding": 'chunked' }
- conn.request("POST", "hello",
- "a\r\nabcdefghij\r\n" + "2\r\nkl\r\n" + "0\r\n\r\n",
- headers)
- resp = conn.getresponse()
- if resp.status != 404:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- conn.close()
- conn.putrequest("POST", "hello")
- conn.putheader('Transfer-Encoding', 'chunked')
- conn.endheaders()
- conn.send("a\r\nabcdefghij\r\n")
- time.sleep(0.1)
- conn.send("2\r\nkl\r\n")
- conn.send("0\r\n\r\n")
- resp = conn.getresponse()
- if resp.status != 404:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- conn.close()
- conn.putrequest("POST", "hello")
- conn.putheader('Transfer-Encoding', 'chunked')
- conn.endheaders()
- completed = False
- try:
- for i in range(20000):
- conn.send("1\r\nZ\r\n")
- conn.send("0\r\n\r\n")
- resp = conn.getresponse()
- completed = True
- except Exception, e:
- pass
- conn.close()
- if completed:
- raise Exception("Too long chunked request did not result in connection reset")
- headers = { "Transfer-Encoding": 'chunked' }
- conn.request("POST", "hello", "80000000\r\na", headers)
- try:
- resp = conn.getresponse()
- except Exception, e:
- pass
- conn.close()
- conn.request("POST", "hello", "10000000\r\na", headers)
- try:
- resp = conn.getresponse()
- except Exception, e:
- pass
- conn.close()
- @remote_compatible
- def test_ap_wps_disabled(dev, apdev):
- """WPS operations while WPS is disabled"""
- ssid = "test-wps-disabled"
- hapd = hostapd.add_ap(apdev[0], { "ssid": ssid })
- if "FAIL" not in hapd.request("WPS_PBC"):
- raise Exception("WPS_PBC succeeded unexpectedly")
- if "FAIL" not in hapd.request("WPS_CANCEL"):
- raise Exception("WPS_CANCEL succeeded unexpectedly")
- def test_ap_wps_mixed_cred(dev, apdev):
- """WPS 2.0 STA merging mixed mode WPA/WPA2 credentials"""
- ssid = "test-wps-wep"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "skip_cred_build": "1", "extra_cred": "wps-mixed-cred" }
- hapd = hostapd.add_ap(apdev[0], params)
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- ev = dev[0].wait_event(["WPS-SUCCESS"], timeout=30)
- if ev is None:
- raise Exception("WPS-SUCCESS event timed out")
- nets = dev[0].list_networks()
- if len(nets) != 1:
- raise Exception("Unexpected number of network blocks")
- id = nets[0]['id']
- proto = dev[0].get_network(id, "proto")
- if proto != "WPA RSN":
- raise Exception("Unexpected merged proto field value: " + proto)
- pairwise = dev[0].get_network(id, "pairwise")
- if pairwise != "CCMP TKIP" and pairwise != "CCMP GCMP TKIP":
- raise Exception("Unexpected merged pairwise field value: " + pairwise)
- @remote_compatible
- def test_ap_wps_while_connected(dev, apdev):
- """WPS PBC provisioning while connected to another AP"""
- ssid = "test-wps-conf"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- hostapd.add_ap(apdev[1], { "ssid": "open" })
- dev[0].connect("open", key_mgmt="NONE", scan_freq="2412")
- logger.info("WPS provisioning step")
- hapd.request("WPS_PBC")
- dev[0].dump_monitor()
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- dev[0].wait_connected(timeout=30)
- status = dev[0].get_status()
- if status['bssid'] != apdev[0]['bssid']:
- raise Exception("Unexpected BSSID")
- @remote_compatible
- def test_ap_wps_while_connected_no_autoconnect(dev, apdev):
- """WPS PBC provisioning while connected to another AP and STA_AUTOCONNECT disabled"""
- ssid = "test-wps-conf"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- hostapd.add_ap(apdev[1], { "ssid": "open" })
- try:
- dev[0].request("STA_AUTOCONNECT 0")
- dev[0].connect("open", key_mgmt="NONE", scan_freq="2412")
- logger.info("WPS provisioning step")
- hapd.request("WPS_PBC")
- dev[0].dump_monitor()
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- dev[0].wait_connected(timeout=30)
- status = dev[0].get_status()
- if status['bssid'] != apdev[0]['bssid']:
- raise Exception("Unexpected BSSID")
- finally:
- dev[0].request("STA_AUTOCONNECT 1")
- @remote_compatible
- def test_ap_wps_from_event(dev, apdev):
- """WPS PBC event on AP to enable PBC"""
- ssid = "test-wps-conf"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].dump_monitor()
- hapd.dump_monitor()
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- ev = hapd.wait_event(['WPS-ENROLLEE-SEEN'], timeout=15)
- if ev is None:
- raise Exception("No WPS-ENROLLEE-SEEN event on AP")
- vals = ev.split(' ')
- if vals[1] != dev[0].p2p_interface_addr():
- raise Exception("Unexpected enrollee address: " + vals[1])
- if vals[5] != '4':
- raise Exception("Unexpected Device Password Id: " + vals[5])
- hapd.request("WPS_PBC")
- dev[0].wait_connected(timeout=30)
- def test_ap_wps_ap_scan_2(dev, apdev):
- """AP_SCAN 2 for WPS"""
- ssid = "test-wps-conf"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- hapd.request("WPS_PBC")
- wpas = WpaSupplicant(global_iface='/tmp/wpas-wlan5')
- wpas.interface_add("wlan5", drv_params="force_connect_cmd=1")
- wpas.dump_monitor()
- if "OK" not in wpas.request("AP_SCAN 2"):
- raise Exception("Failed to set AP_SCAN 2")
- wpas.flush_scan_cache()
- wpas.scan_for_bss(apdev[0]['bssid'], freq="2412")
- wpas.dump_monitor()
- wpas.request("WPS_PBC " + apdev[0]['bssid'])
- ev = wpas.wait_event(["WPS-SUCCESS"], timeout=15)
- if ev is None:
- raise Exception("WPS-SUCCESS event timed out")
- wpas.wait_connected(timeout=30)
- wpas.dump_monitor()
- wpas.request("DISCONNECT")
- wpas.request("BSS_FLUSH 0")
- wpas.dump_monitor()
- wpas.request("REASSOCIATE")
- wpas.wait_connected(timeout=30)
- wpas.dump_monitor()
- @remote_compatible
- def test_ap_wps_eapol_workaround(dev, apdev):
- """EAPOL workaround code path for 802.1X header length mismatch"""
- ssid = "test-wps"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "1" })
- bssid = apdev[0]['bssid']
- hapd.request("SET ext_eapol_frame_io 1")
- dev[0].request("SET ext_eapol_frame_io 1")
- hapd.request("WPS_PBC")
- dev[0].request("WPS_PBC")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=15)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX from hostapd")
- res = dev[0].request("EAPOL_RX " + bssid + " 020000040193000501FFFF")
- if "OK" not in res:
- raise Exception("EAPOL_RX to wpa_supplicant failed")
- def test_ap_wps_iteration(dev, apdev):
- """WPS PIN and iterate through APs without selected registrar"""
- ssid = "test-wps-conf"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- ssid2 = "test-wps-conf2"
- hapd2 = hostapd.add_ap(apdev[1],
- { "ssid": ssid2, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].scan_for_bss(apdev[1]['bssid'], freq="2412")
- dev[0].dump_monitor()
- pin = dev[0].request("WPS_PIN any")
- # Wait for iteration through all WPS APs to happen before enabling any
- # Registrar.
- for i in range(2):
- ev = dev[0].wait_event(["Associated with"], timeout=30)
- if ev is None:
- raise Exception("No association seen")
- ev = dev[0].wait_event(["WPS-M2D"], timeout=10)
- if ev is None:
- raise Exception("No M2D from AP")
- dev[0].wait_disconnected()
- # Verify that each AP requested PIN
- ev = hapd.wait_event(["WPS-PIN-NEEDED"], timeout=1)
- if ev is None:
- raise Exception("No WPS-PIN-NEEDED event from AP")
- ev = hapd2.wait_event(["WPS-PIN-NEEDED"], timeout=1)
- if ev is None:
- raise Exception("No WPS-PIN-NEEDED event from AP2")
- # Provide PIN to one of the APs and verify that connection gets formed
- hapd.request("WPS_PIN any " + pin)
- dev[0].wait_connected(timeout=30)
- def test_ap_wps_iteration_error(dev, apdev):
- """WPS AP iteration on no Selected Registrar and error case with an AP"""
- ssid = "test-wps-conf-pin"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "wps_independent": "1" })
- hapd.request("SET ext_eapol_frame_io 1")
- bssid = apdev[0]['bssid']
- pin = dev[0].wps_read_pin()
- dev[0].request("WPS_PIN any " + pin)
- ev = hapd.wait_event(["EAPOL-TX"], timeout=15)
- if ev is None:
- raise Exception("No EAPOL-TX (EAP-Request/Identity) from hostapd")
- dev[0].request("EAPOL_RX " + bssid + " " + ev.split(' ')[2])
- ev = hapd.wait_event(["EAPOL-TX"], timeout=15)
- if ev is None:
- raise Exception("No EAPOL-TX (EAP-WSC/Start) from hostapd")
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED"], timeout=5)
- if ev is None:
- raise Exception("No CTRL-EVENT-EAP-STARTED")
- # Do not forward any more EAPOL frames to test wpa_supplicant behavior for
- # a case with an incorrectly behaving WPS AP.
- # Start the real target AP and activate registrar on it.
- hapd2 = hostapd.add_ap(apdev[1],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "wps_independent": "1" })
- hapd2.request("WPS_PIN any " + pin)
- dev[0].wait_disconnected(timeout=15)
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED"], timeout=15)
- if ev is None:
- raise Exception("No CTRL-EVENT-EAP-STARTED for the second AP")
- ev = dev[0].wait_event(["WPS-CRED-RECEIVED"], timeout=15)
- if ev is None:
- raise Exception("No WPS-CRED-RECEIVED for the second AP")
- dev[0].wait_connected(timeout=15)
- @remote_compatible
- def test_ap_wps_priority(dev, apdev):
- """WPS PIN provisioning with configured AP and wps_priority"""
- ssid = "test-wps-conf-pin"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- logger.info("WPS provisioning step")
- pin = dev[0].wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].dump_monitor()
- try:
- dev[0].request("SET wps_priority 6")
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- dev[0].wait_connected(timeout=30)
- netw = dev[0].list_networks()
- prio = dev[0].get_network(netw[0]['id'], 'priority')
- if prio != '6':
- raise Exception("Unexpected network priority: " + prio)
- finally:
- dev[0].request("SET wps_priority 0")
- @remote_compatible
- def test_ap_wps_and_non_wps(dev, apdev):
- """WPS and non-WPS AP in single hostapd process"""
- params = { "ssid": "wps", "eap_server": "1", "wps_state": "1" }
- hapd = hostapd.add_ap(apdev[0], params)
- params = { "ssid": "no wps" }
- hapd2 = hostapd.add_ap(apdev[1], params)
- appin = hapd.request("WPS_AP_PIN random")
- if "FAIL" in appin:
- raise Exception("Could not generate random AP PIN")
- if appin not in hapd.request("WPS_AP_PIN get"):
- raise Exception("Could not fetch current AP PIN")
- if "FAIL" in hapd.request("WPS_PBC"):
- raise Exception("WPS_PBC failed")
- if "FAIL" in hapd.request("WPS_CANCEL"):
- raise Exception("WPS_CANCEL failed")
- def test_ap_wps_init_oom(dev, apdev):
- """Initial AP configuration and OOM during PSK generation"""
- ssid = "test-wps"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "1" }
- hapd = hostapd.add_ap(apdev[0], params)
- with alloc_fail(hapd, 1, "base64_encode;wps_build_cred"):
- pin = dev[0].wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- dev[0].wait_disconnected()
- hapd.request("WPS_PIN any " + pin)
- dev[0].wait_connected(timeout=30)
- @remote_compatible
- def test_ap_wps_er_oom(dev, apdev):
- """WPS ER OOM in XML processing"""
- try:
- _test_ap_wps_er_oom(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- dev[1].request("WPS_CANCEL")
- dev[0].request("DISCONNECT")
- def _test_ap_wps_er_oom(dev, apdev):
- ssid = "wps-er-ap-config"
- ap_pin = "12345670"
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "device_name": "Wireless AP", "manufacturer": "Company",
- "model_name": "WAP", "model_number": "123",
- "serial_number": "12345", "device_type": "6-0050F204-1",
- "os_version": "01020300",
- "config_methods": "label push_button",
- "ap_pin": ap_pin, "uuid": ap_uuid, "upnp_iface": "lo"})
- dev[0].connect(ssid, psk="12345678", scan_freq="2412")
- with alloc_fail(dev[0], 1, "base64_decode;xml_get_base64_item"):
- dev[0].request("WPS_ER_START ifname=lo")
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=3)
- if ev is not None:
- raise Exception("Unexpected AP discovery")
- dev[0].request("WPS_ER_STOP")
- dev[0].request("WPS_ER_START ifname=lo")
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=10)
- if ev is None:
- raise Exception("AP discovery timed out")
- dev[1].scan_for_bss(apdev[0]['bssid'], freq=2412)
- with alloc_fail(dev[0], 1, "base64_decode;xml_get_base64_item"):
- dev[1].request("WPS_PBC " + apdev[0]['bssid'])
- ev = dev[1].wait_event(["CTRL-EVENT-SCAN-RESULTS"], timeout=10)
- if ev is None:
- raise Exception("PBC scan failed")
- ev = dev[0].wait_event(["WPS-ER-ENROLLEE-ADD"], timeout=15)
- if ev is None:
- raise Exception("Enrollee discovery timed out")
- @remote_compatible
- def test_ap_wps_er_init_oom(dev, apdev):
- """WPS ER and OOM during init"""
- try:
- _test_ap_wps_er_init_oom(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_init_oom(dev, apdev):
- with alloc_fail(dev[0], 1, "wps_er_init"):
- if "FAIL" not in dev[0].request("WPS_ER_START ifname=lo"):
- raise Exception("WPS_ER_START succeeded during OOM")
- with alloc_fail(dev[0], 1, "http_server_init"):
- if "FAIL" not in dev[0].request("WPS_ER_START ifname=lo"):
- raise Exception("WPS_ER_START succeeded during OOM")
- with alloc_fail(dev[0], 2, "http_server_init"):
- if "FAIL" not in dev[0].request("WPS_ER_START ifname=lo"):
- raise Exception("WPS_ER_START succeeded during OOM")
- with alloc_fail(dev[0], 1, "eloop_sock_table_add_sock;?eloop_register_sock;wps_er_ssdp_init"):
- if "FAIL" not in dev[0].request("WPS_ER_START ifname=lo"):
- raise Exception("WPS_ER_START succeeded during OOM")
- with fail_test(dev[0], 1, "os_get_random;wps_er_init"):
- if "FAIL" not in dev[0].request("WPS_ER_START ifname=lo"):
- raise Exception("WPS_ER_START succeeded during os_get_random failure")
- @remote_compatible
- def test_ap_wps_er_init_fail(dev, apdev):
- """WPS ER init failure"""
- if "FAIL" not in dev[0].request("WPS_ER_START ifname=does-not-exist"):
- dev[0].request("WPS_ER_STOP")
- raise Exception("WPS_ER_START with non-existing ifname succeeded")
- def test_ap_wps_wpa_cli_action(dev, apdev, test_params):
- """WPS events and wpa_cli action script"""
- logdir = os.path.abspath(test_params['logdir'])
- pidfile = os.path.join(logdir, 'ap_wps_wpa_cli_action.wpa_cli.pid')
- logfile = os.path.join(logdir, 'ap_wps_wpa_cli_action.wpa_cli.res')
- actionfile = os.path.join(logdir, 'ap_wps_wpa_cli_action.wpa_cli.action.sh')
- with open(actionfile, 'w') as f:
- f.write('#!/bin/sh\n')
- f.write('echo $* >> %s\n' % logfile)
- # Kill the process and wait some time before returning to allow all the
- # pending events to be processed with some of this happening after the
- # eloop SIGALRM signal has been scheduled.
- f.write('if [ $2 = "WPS-SUCCESS" -a -r %s ]; then kill `cat %s`; sleep 1; fi\n' % (pidfile, pidfile))
- os.chmod(actionfile, stat.S_IREAD | stat.S_IWRITE | stat.S_IEXEC |
- stat.S_IRGRP | stat.S_IXGRP | stat.S_IROTH | stat.S_IXOTH)
- ssid = "test-wps-conf"
- hapd = hostapd.add_ap(apdev[0],
- { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"})
- prg = os.path.join(test_params['logdir'],
- 'alt-wpa_supplicant/wpa_supplicant/wpa_cli')
- if not os.path.exists(prg):
- prg = '../../wpa_supplicant/wpa_cli'
- arg = [ prg, '-P', pidfile, '-B', '-i', dev[0].ifname, '-a', actionfile ]
- subprocess.call(arg)
- arg = [ 'ps', 'ax' ]
- cmd = subprocess.Popen(arg, stdout=subprocess.PIPE)
- out = cmd.communicate()[0]
- cmd.wait()
- logger.debug("Processes:\n" + out)
- if "wpa_cli -P %s -B -i %s" % (pidfile, dev[0].ifname) not in out:
- raise Exception("Did not see wpa_cli running")
- hapd.request("WPS_PIN any 12345670")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].dump_monitor()
- dev[0].request("WPS_PIN " + apdev[0]['bssid'] + " 12345670")
- dev[0].wait_connected(timeout=30)
- for i in range(30):
- if not os.path.exists(pidfile):
- break
- time.sleep(0.1)
- if not os.path.exists(logfile):
- raise Exception("wpa_cli action results file not found")
- with open(logfile, 'r') as f:
- res = f.read()
- if "WPS-SUCCESS" not in res:
- raise Exception("WPS-SUCCESS event not seen in action file")
- arg = [ 'ps', 'ax' ]
- cmd = subprocess.Popen(arg, stdout=subprocess.PIPE)
- out = cmd.communicate()[0]
- cmd.wait()
- logger.debug("Remaining processes:\n" + out)
- if "wpa_cli -P %s -B -i %s" % (pidfile, dev[0].ifname) in out:
- raise Exception("wpa_cli still running")
- if os.path.exists(pidfile):
- raise Exception("PID file not removed")
- def test_ap_wps_er_ssdp_proto(dev, apdev):
- """WPS ER SSDP protocol testing"""
- try:
- _test_ap_wps_er_ssdp_proto(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_ssdp_proto(dev, apdev):
- socket.setdefaulttimeout(1)
- sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
- sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
- sock.bind(("239.255.255.250", 1900))
- if "FAIL" not in dev[0].request("WPS_ER_START ifname=lo foo"):
- raise Exception("Invalid filter accepted")
- if "OK" not in dev[0].request("WPS_ER_START ifname=lo 1.2.3.4"):
- raise Exception("WPS_ER_START with filter failed")
- (msg,addr) = sock.recvfrom(1000)
- logger.debug("Received SSDP message from %s: %s" % (str(addr), msg))
- if "M-SEARCH" not in msg:
- raise Exception("Not an M-SEARCH")
- sock.sendto("FOO", addr)
- time.sleep(0.1)
- dev[0].request("WPS_ER_STOP")
- dev[0].request("WPS_ER_START ifname=lo")
- (msg,addr) = sock.recvfrom(1000)
- logger.debug("Received SSDP message from %s: %s" % (str(addr), msg))
- if "M-SEARCH" not in msg:
- raise Exception("Not an M-SEARCH")
- sock.sendto("FOO", addr)
- sock.sendto("HTTP/1.1 200 OK\r\nFOO\r\n\r\n", addr)
- sock.sendto("HTTP/1.1 200 OK\r\nNTS:foo\r\n\r\n", addr)
- sock.sendto("HTTP/1.1 200 OK\r\nNTS:ssdp:byebye\r\n\r\n", addr)
- sock.sendto("HTTP/1.1 200 OK\r\ncache-control: foo=1\r\n\r\n", addr)
- sock.sendto("HTTP/1.1 200 OK\r\ncache-control: max-age=1\r\n\r\n", addr)
- sock.sendto("HTTP/1.1 200 OK\r\nusn:\r\n\r\n", addr)
- sock.sendto("HTTP/1.1 200 OK\r\nusn:foo\r\n\r\n", addr)
- sock.sendto("HTTP/1.1 200 OK\r\nusn: uuid:\r\n\r\n", addr)
- sock.sendto("HTTP/1.1 200 OK\r\nusn: uuid: \r\n\r\n", addr)
- sock.sendto("HTTP/1.1 200 OK\r\nusn: uuid: foo\r\n\r\n", addr)
- sock.sendto("HTTP/1.1 200 OK\r\nST: urn:schemas-wifialliance-org:device:WFADevice:1\r\n\r\n", addr)
- sock.sendto("HTTP/1.1 200 OK\r\nST: urn:schemas-wifialliance-org:device:WFADevice:1\r\nNTS:ssdp:byebye\r\n\r\n", addr)
- sock.sendto("HTTP/1.1 200 OK\r\nST: urn:schemas-wifialliance-org:device:WFADevice:1\r\nlocation:foo\r\n\r\n", addr)
- with alloc_fail(dev[0], 1, "wps_er_ap_add"):
- sock.sendto("HTTP/1.1 200 OK\r\nST: urn:schemas-wifialliance-org:device:WFADevice:1\r\nlocation:foo\r\ncache-control:max-age=1\r\n\r\n", addr)
- time.sleep(0.1)
- with alloc_fail(dev[0], 2, "wps_er_ap_add"):
- sock.sendto("HTTP/1.1 200 OK\r\nST: urn:schemas-wifialliance-org:device:WFADevice:1\r\nlocation:foo\r\ncache-control:max-age=1\r\n\r\n", addr)
- time.sleep(0.1)
- # Add an AP with bogus URL
- sock.sendto("HTTP/1.1 200 OK\r\nST: urn:schemas-wifialliance-org:device:WFADevice:1\r\nlocation:foo\r\ncache-control:max-age=1\r\n\r\n", addr)
- # Update timeout on AP without updating URL
- sock.sendto("HTTP/1.1 200 OK\r\nST: urn:schemas-wifialliance-org:device:WFADevice:1\r\nlocation:http://127.0.0.1:12345/foo.xml\r\ncache-control:max-age=1\r\n\r\n", addr)
- ev = dev[0].wait_event(["WPS-ER-AP-REMOVE"], timeout=5)
- if ev is None:
- raise Exception("No WPS-ER-AP-REMOVE event on max-age timeout")
- # Add an AP with a valid URL (but no server listing to it)
- sock.sendto("HTTP/1.1 200 OK\r\nST: urn:schemas-wifialliance-org:device:WFADevice:1\r\nlocation:http://127.0.0.1:12345/foo.xml\r\ncache-control:max-age=1\r\n\r\n", addr)
- ev = dev[0].wait_event(["WPS-ER-AP-REMOVE"], timeout=5)
- if ev is None:
- raise Exception("No WPS-ER-AP-REMOVE event on max-age timeout")
- sock.close()
- wps_event_url = None
- def gen_upnp_info(eventSubURL='wps_event', controlURL='wps_control',
- udn='uuid:27ea801a-9e5c-4e73-bd82-f89cbcd10d7e'):
- payload = '''<?xml version="1.0"?>
- <root xmlns="urn:schemas-upnp-org:device-1-0">
- <specVersion>
- <major>1</major>
- <minor>0</minor>
- </specVersion>
- <device>
- <deviceType>urn:schemas-wifialliance-org:device:WFADevice:1</deviceType>
- <friendlyName>WPS Access Point</friendlyName>
- <manufacturer>Company</manufacturer>
- <modelName>WAP</modelName>
- <modelNumber>123</modelNumber>
- <serialNumber>12345</serialNumber>
- '''
- if udn:
- payload += '<UDN>' + udn + '</UDN>'
- payload += '''<serviceList>
- <service>
- <serviceType>urn:schemas-wifialliance-org:service:WFAWLANConfig:1</serviceType>
- <serviceId>urn:wifialliance-org:serviceId:WFAWLANConfig1</serviceId>
- <SCPDURL>wps_scpd.xml</SCPDURL>
- '''
- if controlURL:
- payload += '<controlURL>' + controlURL + '</controlURL>\n'
- if eventSubURL:
- payload += '<eventSubURL>' + eventSubURL + '</eventSubURL>\n'
- payload += '''</service>
- </serviceList>
- </device>
- </root>
- '''
- hdr = 'HTTP/1.1 200 OK\r\n' + \
- 'Content-Type: text/xml; charset="utf-8"\r\n' + \
- 'Server: Unspecified, UPnP/1.0, Unspecified\r\n' + \
- 'Connection: close\r\n' + \
- 'Content-Length: ' + str(len(payload)) + '\r\n' + \
- 'Date: Sat, 15 Aug 2015 18:55:08 GMT\r\n\r\n'
- return hdr + payload
- def gen_wps_control(payload_override=None):
- payload = '''<?xml version="1.0"?>
- <s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
- <s:Body>
- <u:GetDeviceInfoResponse xmlns:u="urn:schemas-wifialliance-org:service:WFAWLANConfig:1">
- <NewDeviceInfo>EEoAARAQIgABBBBHABAn6oAanlxOc72C+Jy80Q1+ECAABgIAAAADABAaABCJZ7DPtbU3Ust9
- Z3wJF07WEDIAwH45D3i1OqB7eJGwTzqeapS71h3KyXncK2xJZ+xqScrlorNEg6LijBJzG2Ca
- +FZli0iliDJd397yAx/jk4nFXco3q5ylBSvSw9dhJ5u1xBKSnTilKGlUHPhLP75PUqM3fot9
- 7zwtFZ4bx6x1sBA6oEe2d0aUJmLumQGCiKEIWlnxs44zego/2tAe81bDzdPBM7o5HH/FUhD+
- KoGzFXp51atP+1n9Vta6AkI0Vye99JKLcC6Md9dMJltSVBgd4Xc4lRAEAAIAIxAQAAIADRAN
- AAEBEAgAAgAEEEQAAQIQIQAHQ29tcGFueRAjAANXQVAQJAADMTIzEEIABTEyMzQ1EFQACAAG
- AFDyBAABEBEAC1dpcmVsZXNzIEFQEDwAAQEQAgACAAAQEgACAAAQCQACAAAQLQAEgQIDABBJ
- AAYANyoAASA=
- </NewDeviceInfo>
- </u:GetDeviceInfoResponse>
- </s:Body>
- </s:Envelope>
- '''
- if payload_override:
- payload = payload_override
- hdr = 'HTTP/1.1 200 OK\r\n' + \
- 'Content-Type: text/xml; charset="utf-8"\r\n' + \
- 'Server: Unspecified, UPnP/1.0, Unspecified\r\n' + \
- 'Connection: close\r\n' + \
- 'Content-Length: ' + str(len(payload)) + '\r\n' + \
- 'Date: Sat, 15 Aug 2015 18:55:08 GMT\r\n\r\n'
- return hdr + payload
- def gen_wps_event(sid='uuid:7eb3342a-8a5f-47fe-a585-0785bfec6d8a'):
- payload = ""
- hdr = 'HTTP/1.1 200 OK\r\n' + \
- 'Content-Type: text/xml; charset="utf-8"\r\n' + \
- 'Server: Unspecified, UPnP/1.0, Unspecified\r\n' + \
- 'Connection: close\r\n' + \
- 'Content-Length: ' + str(len(payload)) + '\r\n'
- if sid:
- hdr += 'SID: ' + sid + '\r\n'
- hdr += 'Timeout: Second-1801\r\n' + \
- 'Date: Sat, 15 Aug 2015 18:55:08 GMT\r\n\r\n'
- return hdr + payload
- class WPSAPHTTPServer(SocketServer.StreamRequestHandler):
- def handle(self):
- data = self.rfile.readline().strip()
- logger.info("HTTP server received: " + data)
- while True:
- hdr = self.rfile.readline().strip()
- if len(hdr) == 0:
- break
- logger.info("HTTP header: " + hdr)
- if "CALLBACK:" in hdr:
- global wps_event_url
- wps_event_url = hdr.split(' ')[1].strip('<>')
- if "GET /foo.xml" in data:
- self.handle_upnp_info()
- elif "POST /wps_control" in data:
- self.handle_wps_control()
- elif "SUBSCRIBE /wps_event" in data:
- self.handle_wps_event()
- else:
- self.handle_others(data)
- def handle_upnp_info(self):
- self.wfile.write(gen_upnp_info())
- def handle_wps_control(self):
- self.wfile.write(gen_wps_control())
- def handle_wps_event(self):
- self.wfile.write(gen_wps_event())
- def handle_others(self, data):
- logger.info("Ignore HTTP request: " + data)
- class MyTCPServer(SocketServer.TCPServer):
- def __init__(self, addr, handler):
- self.allow_reuse_address = True
- SocketServer.TCPServer.__init__(self, addr, handler)
- def wps_er_start(dev, http_server, max_age=1, wait_m_search=False,
- location_url=None):
- socket.setdefaulttimeout(1)
- sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
- sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
- sock.bind(("239.255.255.250", 1900))
- dev.request("WPS_ER_START ifname=lo")
- for i in range(100):
- (msg,addr) = sock.recvfrom(1000)
- logger.debug("Received SSDP message from %s: %s" % (str(addr), msg))
- if "M-SEARCH" in msg:
- break
- if not wait_m_search:
- raise Exception("Not an M-SEARCH")
- if i == 99:
- raise Exception("No M-SEARCH seen")
- # Add an AP with a valid URL and server listing to it
- server = MyTCPServer(("127.0.0.1", 12345), http_server)
- if not location_url:
- location_url = 'http://127.0.0.1:12345/foo.xml'
- sock.sendto("HTTP/1.1 200 OK\r\nST: urn:schemas-wifialliance-org:device:WFADevice:1\r\nlocation:%s\r\ncache-control:max-age=%d\r\n\r\n" % (location_url, max_age), addr)
- server.timeout = 1
- return server,sock
- def wps_er_stop(dev, sock, server, on_alloc_fail=False):
- sock.close()
- server.server_close()
- if on_alloc_fail:
- done = False
- for i in range(50):
- res = dev.request("GET_ALLOC_FAIL")
- if res.startswith("0:"):
- done = True
- break
- time.sleep(0.1)
- if not done:
- raise Exception("No allocation failure reported")
- else:
- ev = dev.wait_event(["WPS-ER-AP-REMOVE"], timeout=5)
- if ev is None:
- raise Exception("No WPS-ER-AP-REMOVE event on max-age timeout")
- dev.request("WPS_ER_STOP")
- def run_wps_er_proto_test(dev, handler, no_event_url=False, location_url=None):
- try:
- uuid = '27ea801a-9e5c-4e73-bd82-f89cbcd10d7e'
- server,sock = wps_er_start(dev, handler, location_url=location_url)
- global wps_event_url
- wps_event_url = None
- server.handle_request()
- server.handle_request()
- server.handle_request()
- server.server_close()
- if no_event_url:
- if wps_event_url:
- raise Exception("Received event URL unexpectedly")
- return
- if wps_event_url is None:
- raise Exception("Did not get event URL")
- logger.info("Event URL: " + wps_event_url)
- finally:
- dev.request("WPS_ER_STOP")
- def send_wlanevent(url, uuid, data, no_response=False):
- conn = httplib.HTTPConnection(url.netloc)
- payload = '''<?xml version="1.0" encoding="utf-8"?>
- <e:propertyset xmlns:e="urn:schemas-upnp-org:event-1-0">
- <e:property><STAStatus>1</STAStatus></e:property>
- <e:property><APStatus>1</APStatus></e:property>
- <e:property><WLANEvent>'''
- payload += base64.b64encode(data)
- payload += '</WLANEvent></e:property></e:propertyset>'
- headers = { "Content-type": 'text/xml; charset="utf-8"',
- "Server": "Unspecified, UPnP/1.0, Unspecified",
- "HOST": url.netloc,
- "NT": "upnp:event",
- "SID": "uuid:" + uuid,
- "SEQ": "0",
- "Content-Length": str(len(payload)) }
- conn.request("NOTIFY", url.path, payload, headers)
- if no_response:
- try:
- conn.getresponse()
- except Exception, e:
- pass
- return
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- def test_ap_wps_er_http_proto(dev, apdev):
- """WPS ER HTTP protocol testing"""
- try:
- _test_ap_wps_er_http_proto(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_http_proto(dev, apdev):
- uuid = '27ea801a-9e5c-4e73-bd82-f89cbcd10d7e'
- server,sock = wps_er_start(dev[0], WPSAPHTTPServer, max_age=15)
- global wps_event_url
- wps_event_url = None
- server.handle_request()
- server.handle_request()
- server.handle_request()
- server.server_close()
- if wps_event_url is None:
- raise Exception("Did not get event URL")
- logger.info("Event URL: " + wps_event_url)
- ev = dev[0].wait_event(["WPS-ER-AP-ADD"], timeout=10)
- if ev is None:
- raise Exception("No WPS-ER-AP-ADD event")
- if uuid not in ev:
- raise Exception("UUID mismatch")
- sock.close()
- logger.info("Valid Probe Request notification")
- url = urlparse.urlparse(wps_event_url)
- conn = httplib.HTTPConnection(url.netloc)
- payload = '''<?xml version="1.0" encoding="utf-8"?>
- <e:propertyset xmlns:e="urn:schemas-upnp-org:event-1-0">
- <e:property><STAStatus>1</STAStatus></e:property>
- <e:property><APStatus>1</APStatus></e:property>
- <e:property><WLANEvent>ATAyOjAwOjAwOjAwOjAwOjAwEEoAARAQOgABAhAIAAIxSBBHABA2LbR7pTpRkYj7VFi5hrLk
- EFQACAAAAAAAAAAAEDwAAQMQAgACAAAQCQACAAAQEgACAAAQIQABIBAjAAEgECQAASAQEQAI
- RGV2aWNlIEEQSQAGADcqAAEg
- </WLANEvent></e:property>
- </e:propertyset>
- '''
- headers = { "Content-type": 'text/xml; charset="utf-8"',
- "Server": "Unspecified, UPnP/1.0, Unspecified",
- "HOST": url.netloc,
- "NT": "upnp:event",
- "SID": "uuid:" + uuid,
- "SEQ": "0",
- "Content-Length": str(len(payload)) }
- conn.request("NOTIFY", url.path, payload, headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- ev = dev[0].wait_event(["WPS-ER-ENROLLEE-ADD"], timeout=5)
- if ev is None:
- raise Exception("No WPS-ER-ENROLLEE-ADD event")
- if "362db47b-a53a-5191-88fb-5458b986b2e4" not in ev:
- raise Exception("No Enrollee UUID match")
- logger.info("Incorrect event URL AP id")
- conn = httplib.HTTPConnection(url.netloc)
- conn.request("NOTIFY", url.path + '123', payload, headers)
- resp = conn.getresponse()
- if resp.status != 404:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.info("Missing AP id")
- conn = httplib.HTTPConnection(url.netloc)
- conn.request("NOTIFY", '/event/' + url.path.split('/')[2],
- payload, headers)
- time.sleep(0.1)
- logger.info("Incorrect event URL event id")
- conn = httplib.HTTPConnection(url.netloc)
- conn.request("NOTIFY", '/event/123456789/123', payload, headers)
- time.sleep(0.1)
- logger.info("Incorrect event URL prefix")
- conn = httplib.HTTPConnection(url.netloc)
- conn.request("NOTIFY", '/foobar/123456789/123', payload, headers)
- resp = conn.getresponse()
- if resp.status != 404:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.info("Unsupported request")
- conn = httplib.HTTPConnection(url.netloc)
- conn.request("FOOBAR", '/foobar/123456789/123', payload, headers)
- resp = conn.getresponse()
- if resp.status != 501:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- logger.info("Unsupported request and OOM")
- with alloc_fail(dev[0], 1, "wps_er_http_req"):
- conn = httplib.HTTPConnection(url.netloc)
- conn.request("FOOBAR", '/foobar/123456789/123', payload, headers)
- time.sleep(0.5)
- logger.info("Too short WLANEvent")
- data = '\x00'
- send_wlanevent(url, uuid, data)
- logger.info("Invalid WLANEventMAC")
- data = '\x00qwertyuiopasdfghjklzxcvbnm'
- send_wlanevent(url, uuid, data)
- logger.info("Unknown WLANEventType")
- data = '\xff02:00:00:00:00:00'
- send_wlanevent(url, uuid, data)
- logger.info("Probe Request notification without any attributes")
- data = '\x0102:00:00:00:00:00'
- send_wlanevent(url, uuid, data)
- logger.info("Probe Request notification with invalid attribute")
- data = '\x0102:00:00:00:00:00\xff'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message without any attributes")
- data = '\x0202:00:00:00:00:00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message with invalid attribute")
- data = '\x0202:00:00:00:00:00\xff'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message from new STA and not M1")
- data = '\x0202:ff:ff:ff:ff:ff' + '\x10\x22\x00\x01\x05'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1")
- data = '\x0202:00:00:00:00:00'
- data += '\x10\x22\x00\x01\x04'
- data += '\x10\x47\x00\x10' + 16*'\x00'
- data += '\x10\x20\x00\x06\x02\x00\x00\x00\x00\x00'
- data += '\x10\x1a\x00\x10' + 16*'\x00'
- data += '\x10\x32\x00\xc0' + 192*'\x00'
- data += '\x10\x04\x00\x02\x00\x00'
- data += '\x10\x10\x00\x02\x00\x00'
- data += '\x10\x0d\x00\x01\x00'
- data += '\x10\x08\x00\x02\x00\x00'
- data += '\x10\x44\x00\x01\x00'
- data += '\x10\x21\x00\x00'
- data += '\x10\x23\x00\x00'
- data += '\x10\x24\x00\x00'
- data += '\x10\x42\x00\x00'
- data += '\x10\x54\x00\x08' + 8*'\x00'
- data += '\x10\x11\x00\x00'
- data += '\x10\x3c\x00\x01\x00'
- data += '\x10\x02\x00\x02\x00\x00'
- data += '\x10\x12\x00\x02\x00\x00'
- data += '\x10\x09\x00\x02\x00\x00'
- data += '\x10\x2d\x00\x04\x00\x00\x00\x00'
- m1 = data
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: WSC_ACK")
- data = '\x0202:00:00:00:00:00' + '\x10\x22\x00\x01\x0d'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1")
- send_wlanevent(url, uuid, m1)
- logger.info("EAP message: WSC_NACK")
- data = '\x0202:00:00:00:00:00' + '\x10\x22\x00\x01\x0e'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 - Too long attribute values")
- data = '\x0202:00:00:00:00:00'
- data += '\x10\x11\x00\x21' + 33*'\x00'
- data += '\x10\x45\x00\x21' + 33*'\x00'
- data += '\x10\x42\x00\x21' + 33*'\x00'
- data += '\x10\x24\x00\x21' + 33*'\x00'
- data += '\x10\x23\x00\x21' + 33*'\x00'
- data += '\x10\x21\x00\x41' + 65*'\x00'
- data += '\x10\x49\x00\x09\x00\x37\x2a\x05\x02\x00\x00\x05\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing UUID-E")
- data = '\x0202:00:00:00:00:00'
- data += '\x10\x22\x00\x01\x04'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing MAC Address")
- data += '\x10\x47\x00\x10' + 16*'\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Enrollee Nonce")
- data += '\x10\x20\x00\x06\x02\x00\x00\x00\x00\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Public Key")
- data += '\x10\x1a\x00\x10' + 16*'\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Authentication Type flags")
- data += '\x10\x32\x00\xc0' + 192*'\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Encryption Type Flags")
- data += '\x10\x04\x00\x02\x00\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Connection Type flags")
- data += '\x10\x10\x00\x02\x00\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Config Methods")
- data += '\x10\x0d\x00\x01\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Wi-Fi Protected Setup State")
- data += '\x10\x08\x00\x02\x00\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Manufacturer")
- data += '\x10\x44\x00\x01\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Model Name")
- data += '\x10\x21\x00\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Model Number")
- data += '\x10\x23\x00\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Serial Number")
- data += '\x10\x24\x00\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Primary Device Type")
- data += '\x10\x42\x00\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Device Name")
- data += '\x10\x54\x00\x08' + 8*'\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing RF Bands")
- data += '\x10\x11\x00\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Association State")
- data += '\x10\x3c\x00\x01\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Device Password ID")
- data += '\x10\x02\x00\x02\x00\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing Configuration Error")
- data += '\x10\x12\x00\x02\x00\x00'
- send_wlanevent(url, uuid, data)
- logger.info("EAP message: M1 missing OS Version")
- data += '\x10\x09\x00\x02\x00\x00'
- send_wlanevent(url, uuid, data)
- logger.info("Check max concurrent requests")
- addr = (url.hostname, url.port)
- socks = {}
- for i in range(20):
- socks[i] = socket.socket(socket.AF_INET, socket.SOCK_STREAM,
- socket.IPPROTO_TCP)
- socks[i].settimeout(10)
- socks[i].connect(addr)
- for i in range(20):
- socks[i].send("GET / HTTP/1.1\r\n\r\n")
- count = 0
- for i in range(20):
- try:
- res = socks[i].recv(100)
- if "HTTP/1" in res:
- count += 1
- except:
- pass
- socks[i].close()
- logger.info("%d concurrent HTTP GET operations returned response" % count)
- if count < 10:
- raise Exception("Too few concurrent HTTP connections accepted")
- logger.info("OOM in HTTP server")
- for func in [ "http_request_init", "httpread_create",
- "eloop_register_timeout;httpread_create",
- "eloop_sock_table_add_sock;?eloop_register_sock;httpread_create",
- "httpread_hdr_analyze" ]:
- with alloc_fail(dev[0], 1, func):
- sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM,
- socket.IPPROTO_TCP)
- sock.connect(addr)
- sock.send("GET / HTTP/1.1\r\n\r\n")
- try:
- sock.recv(100)
- except:
- pass
- sock.close()
- logger.info("Invalid HTTP header")
- for req in [ " GET / HTTP/1.1\r\n\r\n",
- "HTTP/1.1 200 OK\r\n\r\n",
- "HTTP/\r\n\r\n",
- "GET %%a%aa% HTTP/1.1\r\n\r\n",
- "GET / HTTP/1.1\r\n FOO\r\n\r\n",
- "NOTIFY / HTTP/1.1\r\n" + 4097*'a' + '\r\n\r\n',
- "NOTIFY / HTTP/1.1\r\n\r\n" + 8193*'a',
- "POST / HTTP/1.1\r\nTransfer-Encoding: CHUNKED\r\n\r\n foo\r\n",
- "POST / HTTP/1.1\r\nTransfer-Encoding: CHUNKED\r\n\r\n1\r\nfoo\r\n",
- "POST / HTTP/1.1\r\nTransfer-Encoding: CHUNKED\r\n\r\n0\r\n",
- "POST / HTTP/1.1\r\nTransfer-Encoding: CHUNKED\r\n\r\n0\r\naa\ra\r\n\ra" ]:
- sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM,
- socket.IPPROTO_TCP)
- sock.settimeout(0.1)
- sock.connect(addr)
- sock.send(req)
- try:
- sock.recv(100)
- except:
- pass
- sock.close()
- with alloc_fail(dev[0], 2, "httpread_read_handler"):
- sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM,
- socket.IPPROTO_TCP)
- sock.connect(addr)
- sock.send("NOTIFY / HTTP/1.1\r\n\r\n" + 4500*'a')
- try:
- sock.recv(100)
- except:
- pass
- sock.close()
- conn = httplib.HTTPConnection(url.netloc)
- payload = '<foo'
- headers = { "Content-type": 'text/xml; charset="utf-8"',
- "Server": "Unspecified, UPnP/1.0, Unspecified",
- "HOST": url.netloc,
- "NT": "upnp:event",
- "SID": "uuid:" + uuid,
- "SEQ": "0",
- "Content-Length": str(len(payload)) }
- conn.request("NOTIFY", url.path, payload, headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- conn = httplib.HTTPConnection(url.netloc)
- payload = '<WLANEvent foo></WLANEvent>'
- headers = { "Content-type": 'text/xml; charset="utf-8"',
- "Server": "Unspecified, UPnP/1.0, Unspecified",
- "HOST": url.netloc,
- "NT": "upnp:event",
- "SID": "uuid:" + uuid,
- "SEQ": "0",
- "Content-Length": str(len(payload)) }
- conn.request("NOTIFY", url.path, payload, headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- with alloc_fail(dev[0], 1, "xml_get_first_item"):
- send_wlanevent(url, uuid, '')
- with alloc_fail(dev[0], 1, "wpabuf_alloc_ext_data;xml_get_base64_item"):
- send_wlanevent(url, uuid, 'foo')
- for func in [ "wps_init",
- "wps_process_manufacturer",
- "wps_process_model_name",
- "wps_process_model_number",
- "wps_process_serial_number",
- "wps_process_dev_name" ]:
- with alloc_fail(dev[0], 1, func):
- send_wlanevent(url, uuid, m1)
- with alloc_fail(dev[0], 1, "wps_er_http_resp_ok"):
- send_wlanevent(url, uuid, m1, no_response=True)
- with alloc_fail(dev[0], 1, "wps_er_http_resp_not_found"):
- url2 = urlparse.urlparse(wps_event_url.replace('/event/', '/notfound/'))
- send_wlanevent(url2, uuid, m1, no_response=True)
- logger.info("EAP message: M1")
- data = '\x0202:11:22:00:00:00'
- data += '\x10\x22\x00\x01\x04'
- data += '\x10\x47\x00\x10' + 16*'\x00'
- data += '\x10\x20\x00\x06\x02\x00\x00\x00\x00\x00'
- data += '\x10\x1a\x00\x10' + 16*'\x00'
- data += '\x10\x32\x00\xc0' + 192*'\x00'
- data += '\x10\x04\x00\x02\x00\x00'
- data += '\x10\x10\x00\x02\x00\x00'
- data += '\x10\x0d\x00\x01\x00'
- data += '\x10\x08\x00\x02\x00\x00'
- data += '\x10\x44\x00\x01\x00'
- data += '\x10\x21\x00\x00'
- data += '\x10\x23\x00\x00'
- data += '\x10\x24\x00\x00'
- data += '\x10\x42\x00\x00'
- data += '\x10\x54\x00\x08' + 8*'\x00'
- data += '\x10\x11\x00\x00'
- data += '\x10\x3c\x00\x01\x00'
- data += '\x10\x02\x00\x02\x00\x00'
- data += '\x10\x12\x00\x02\x00\x00'
- data += '\x10\x09\x00\x02\x00\x00'
- data += '\x10\x2d\x00\x04\x00\x00\x00\x00'
- dev[0].dump_monitor()
- with alloc_fail(dev[0], 1, "wps_er_add_sta_data"):
- send_wlanevent(url, uuid, data)
- ev = dev[0].wait_event(["WPS-ER-ENROLLEE-ADD"], timeout=0.1)
- if ev is not None:
- raise Exception("Unexpected enrollee add event")
- send_wlanevent(url, uuid, data)
- ev = dev[0].wait_event(["WPS-ER-ENROLLEE-ADD"], timeout=2)
- if ev is None:
- raise Exception("Enrollee add event not seen")
- with alloc_fail(dev[0], 1, "base64_encode;wps_er_soap_hdr"):
- send_wlanevent(url, uuid, data)
- with alloc_fail(dev[0], 1, "wpabuf_alloc;wps_er_soap_hdr"):
- send_wlanevent(url, uuid, data)
- with alloc_fail(dev[0], 1, "http_client_url_parse;wps_er_sta_send_msg"):
- send_wlanevent(url, uuid, data)
- with alloc_fail(dev[0], 1, "http_client_addr;wps_er_sta_send_msg"):
- send_wlanevent(url, uuid, data)
- def test_ap_wps_er_http_proto_no_event_sub_url(dev, apdev):
- """WPS ER HTTP protocol testing - no eventSubURL"""
- class WPSAPHTTPServer_no_event_sub_url(WPSAPHTTPServer):
- def handle_upnp_info(self):
- self.wfile.write(gen_upnp_info(eventSubURL=None))
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_no_event_sub_url,
- no_event_url=True)
- def test_ap_wps_er_http_proto_event_sub_url_dns(dev, apdev):
- """WPS ER HTTP protocol testing - DNS name in eventSubURL"""
- class WPSAPHTTPServer_event_sub_url_dns(WPSAPHTTPServer):
- def handle_upnp_info(self):
- self.wfile.write(gen_upnp_info(eventSubURL='http://example.com/wps_event'))
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_event_sub_url_dns,
- no_event_url=True)
- def test_ap_wps_er_http_proto_subscribe_oom(dev, apdev):
- """WPS ER HTTP protocol testing - subscribe OOM"""
- try:
- _test_ap_wps_er_http_proto_subscribe_oom(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_http_proto_subscribe_oom(dev, apdev):
- tests = [ (1, "http_client_url_parse"),
- (1, "wpabuf_alloc;wps_er_subscribe"),
- (1, "http_client_addr"),
- (1, "eloop_sock_table_add_sock;?eloop_register_sock;http_client_addr"),
- (1, "eloop_register_timeout;http_client_addr") ]
- for count,func in tests:
- with alloc_fail(dev[0], count, func):
- server,sock = wps_er_start(dev[0], WPSAPHTTPServer)
- server.handle_request()
- server.handle_request()
- wps_er_stop(dev[0], sock, server, on_alloc_fail=True)
- def test_ap_wps_er_http_proto_no_sid(dev, apdev):
- """WPS ER HTTP protocol testing - no SID"""
- class WPSAPHTTPServer_no_sid(WPSAPHTTPServer):
- def handle_wps_event(self):
- self.wfile.write(gen_wps_event(sid=None))
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_no_sid)
- def test_ap_wps_er_http_proto_invalid_sid_no_uuid(dev, apdev):
- """WPS ER HTTP protocol testing - invalid SID - no UUID"""
- class WPSAPHTTPServer_invalid_sid_no_uuid(WPSAPHTTPServer):
- def handle_wps_event(self):
- self.wfile.write(gen_wps_event(sid='FOO'))
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_invalid_sid_no_uuid)
- def test_ap_wps_er_http_proto_invalid_sid_uuid(dev, apdev):
- """WPS ER HTTP protocol testing - invalid SID UUID"""
- class WPSAPHTTPServer_invalid_sid_uuid(WPSAPHTTPServer):
- def handle_wps_event(self):
- self.wfile.write(gen_wps_event(sid='uuid:FOO'))
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_invalid_sid_uuid)
- def test_ap_wps_er_http_proto_subscribe_failing(dev, apdev):
- """WPS ER HTTP protocol testing - SUBSCRIBE failing"""
- class WPSAPHTTPServer_fail_subscribe(WPSAPHTTPServer):
- def handle_wps_event(self):
- payload = ""
- hdr = 'HTTP/1.1 404 Not Found\r\n' + \
- 'Content-Type: text/xml; charset="utf-8"\r\n' + \
- 'Server: Unspecified, UPnP/1.0, Unspecified\r\n' + \
- 'Connection: close\r\n' + \
- 'Content-Length: ' + str(len(payload)) + '\r\n' + \
- 'Timeout: Second-1801\r\n' + \
- 'Date: Sat, 15 Aug 2015 18:55:08 GMT\r\n\r\n'
- self.wfile.write(hdr + payload)
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_fail_subscribe)
- def test_ap_wps_er_http_proto_subscribe_invalid_response(dev, apdev):
- """WPS ER HTTP protocol testing - SUBSCRIBE and invalid response"""
- class WPSAPHTTPServer_subscribe_invalid_response(WPSAPHTTPServer):
- def handle_wps_event(self):
- payload = ""
- hdr = 'HTTP/1.1 FOO\r\n' + \
- 'Content-Type: text/xml; charset="utf-8"\r\n' + \
- 'Server: Unspecified, UPnP/1.0, Unspecified\r\n' + \
- 'Connection: close\r\n' + \
- 'Content-Length: ' + str(len(payload)) + '\r\n' + \
- 'Timeout: Second-1801\r\n' + \
- 'Date: Sat, 15 Aug 2015 18:55:08 GMT\r\n\r\n'
- self.wfile.write(hdr + payload)
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_subscribe_invalid_response)
- def test_ap_wps_er_http_proto_subscribe_invalid_response(dev, apdev):
- """WPS ER HTTP protocol testing - SUBSCRIBE and invalid response"""
- class WPSAPHTTPServer_invalid_m1(WPSAPHTTPServer):
- def handle_wps_control(self):
- payload = '''<?xml version="1.0"?>
- <s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
- <s:Body>
- <u:GetDeviceInfoResponse xmlns:u="urn:schemas-wifialliance-org:service:WFAWLANConfig:1">
- <NewDeviceInfo>Rk9P</NewDeviceInfo>
- </u:GetDeviceInfoResponse>
- </s:Body>
- </s:Envelope>
- '''
- self.wfile.write(gen_wps_control(payload_override=payload))
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_invalid_m1, no_event_url=True)
- def test_ap_wps_er_http_proto_upnp_info_no_device(dev, apdev):
- """WPS ER HTTP protocol testing - No device in UPnP info"""
- class WPSAPHTTPServer_no_device(WPSAPHTTPServer):
- def handle_upnp_info(self):
- payload = '''<?xml version="1.0"?>
- <root xmlns="urn:schemas-upnp-org:device-1-0">
- <specVersion>
- <major>1</major>
- <minor>0</minor>
- </specVersion>
- </root>
- '''
- hdr = 'HTTP/1.1 200 OK\r\n' + \
- 'Content-Type: text/xml; charset="utf-8"\r\n' + \
- 'Server: Unspecified, UPnP/1.0, Unspecified\r\n' + \
- 'Connection: close\r\n' + \
- 'Content-Length: ' + str(len(payload)) + '\r\n' + \
- 'Date: Sat, 15 Aug 2015 18:55:08 GMT\r\n\r\n'
- self.wfile.write(hdr + payload)
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_no_device, no_event_url=True)
- def test_ap_wps_er_http_proto_upnp_info_no_device_type(dev, apdev):
- """WPS ER HTTP protocol testing - No deviceType in UPnP info"""
- class WPSAPHTTPServer_no_device(WPSAPHTTPServer):
- def handle_upnp_info(self):
- payload = '''<?xml version="1.0"?>
- <root xmlns="urn:schemas-upnp-org:device-1-0">
- <specVersion>
- <major>1</major>
- <minor>0</minor>
- </specVersion>
- <device>
- </device>
- </root>
- '''
- hdr = 'HTTP/1.1 200 OK\r\n' + \
- 'Content-Type: text/xml; charset="utf-8"\r\n' + \
- 'Server: Unspecified, UPnP/1.0, Unspecified\r\n' + \
- 'Connection: close\r\n' + \
- 'Content-Length: ' + str(len(payload)) + '\r\n' + \
- 'Date: Sat, 15 Aug 2015 18:55:08 GMT\r\n\r\n'
- self.wfile.write(hdr + payload)
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_no_device, no_event_url=True)
- def test_ap_wps_er_http_proto_upnp_info_invalid_udn_uuid(dev, apdev):
- """WPS ER HTTP protocol testing - Invalid UDN UUID"""
- class WPSAPHTTPServer_invalid_udn_uuid(WPSAPHTTPServer):
- def handle_upnp_info(self):
- self.wfile.write(gen_upnp_info(udn='uuid:foo'))
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_invalid_udn_uuid)
- def test_ap_wps_er_http_proto_no_control_url(dev, apdev):
- """WPS ER HTTP protocol testing - no controlURL"""
- class WPSAPHTTPServer_no_control_url(WPSAPHTTPServer):
- def handle_upnp_info(self):
- self.wfile.write(gen_upnp_info(controlURL=None))
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_no_control_url,
- no_event_url=True)
- def test_ap_wps_er_http_proto_control_url_dns(dev, apdev):
- """WPS ER HTTP protocol testing - DNS name in controlURL"""
- class WPSAPHTTPServer_control_url_dns(WPSAPHTTPServer):
- def handle_upnp_info(self):
- self.wfile.write(gen_upnp_info(controlURL='http://example.com/wps_control'))
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_control_url_dns,
- no_event_url=True)
- def test_ap_wps_http_timeout(dev, apdev):
- """WPS AP/ER and HTTP timeout"""
- try:
- _test_ap_wps_http_timeout(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_http_timeout(dev, apdev):
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- add_ssdp_ap(apdev[0], ap_uuid)
- location = ssdp_get_location(ap_uuid)
- url = urlparse.urlparse(location)
- addr = (url.hostname, url.port)
- logger.debug("Open HTTP connection to hostapd, but do not complete request")
- sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM,
- socket.IPPROTO_TCP)
- sock.connect(addr)
- sock.send("G")
- class DummyServer(SocketServer.StreamRequestHandler):
- def handle(self):
- logger.debug("DummyServer - start 31 sec wait")
- time.sleep(31)
- logger.debug("DummyServer - wait done")
- logger.debug("Start WPS ER")
- server,sock2 = wps_er_start(dev[0], DummyServer, max_age=40,
- wait_m_search=True)
- logger.debug("Start server to accept, but not complete, HTTP connection from WPS ER")
- # This will wait for 31 seconds..
- server.handle_request()
- logger.debug("Complete HTTP connection with hostapd (that should have already closed the connection)")
- try:
- sock.send("ET / HTTP/1.1\r\n\r\n")
- res = sock.recv(100)
- sock.close()
- except:
- pass
- def test_ap_wps_er_url_parse(dev, apdev):
- """WPS ER and URL parsing special cases"""
- try:
- _test_ap_wps_er_url_parse(dev, apdev)
- finally:
- dev[0].request("WPS_ER_STOP")
- def _test_ap_wps_er_url_parse(dev, apdev):
- sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
- sock.settimeout(1)
- sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
- sock.bind(("239.255.255.250", 1900))
- dev[0].request("WPS_ER_START ifname=lo")
- (msg,addr) = sock.recvfrom(1000)
- logger.debug("Received SSDP message from %s: %s" % (str(addr), msg))
- if "M-SEARCH" not in msg:
- raise Exception("Not an M-SEARCH")
- sock.sendto("HTTP/1.1 200 OK\r\nST: urn:schemas-wifialliance-org:device:WFADevice:1\r\nlocation:http://127.0.0.1\r\ncache-control:max-age=1\r\n\r\n", addr)
- ev = dev[0].wait_event(["WPS-ER-AP-REMOVE"], timeout=2)
- sock.sendto("HTTP/1.1 200 OK\r\nST: urn:schemas-wifialliance-org:device:WFADevice:1\r\nlocation:http://127.0.0.1/:foo\r\ncache-control:max-age=1\r\n\r\n", addr)
- ev = dev[0].wait_event(["WPS-ER-AP-REMOVE"], timeout=2)
- sock.sendto("HTTP/1.1 200 OK\r\nST: urn:schemas-wifialliance-org:device:WFADevice:1\r\nlocation:http://255.255.255.255:0/foo.xml\r\ncache-control:max-age=1\r\n\r\n", addr)
- ev = dev[0].wait_event(["WPS-ER-AP-REMOVE"], timeout=2)
- sock.close()
- def test_ap_wps_er_link_update(dev, apdev):
- """WPS ER and link update special cases"""
- class WPSAPHTTPServer_link_update(WPSAPHTTPServer):
- def handle_upnp_info(self):
- self.wfile.write(gen_upnp_info(controlURL='/wps_control'))
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_link_update)
- class WPSAPHTTPServer_link_update2(WPSAPHTTPServer):
- def handle_others(self, data):
- if "GET / " in data:
- self.wfile.write(gen_upnp_info(controlURL='/wps_control'))
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_link_update2,
- location_url='http://127.0.0.1:12345')
- def test_ap_wps_er_http_client(dev, apdev):
- """WPS ER and HTTP client special cases"""
- with alloc_fail(dev[0], 1, "http_link_update"):
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer)
- with alloc_fail(dev[0], 1, "wpabuf_alloc;http_client_url"):
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer, no_event_url=True)
- with alloc_fail(dev[0], 1, "httpread_create;http_client_tx_ready"):
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer, no_event_url=True)
- class WPSAPHTTPServer_req_as_resp(WPSAPHTTPServer):
- def handle_upnp_info(self):
- self.wfile.write("GET / HTTP/1.1\r\n\r\n")
- run_wps_er_proto_test(dev[0], WPSAPHTTPServer_req_as_resp,
- no_event_url=True)
- def test_ap_wps_init_oom(dev, apdev):
- """wps_init OOM cases"""
- ssid = "test-wps"
- appin = "12345670"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "ap_pin": appin }
- hapd = hostapd.add_ap(apdev[0], params)
- pin = dev[0].wps_read_pin()
- with alloc_fail(hapd, 1, "wps_init"):
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = hapd.wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=10)
- if ev is None:
- raise Exception("No EAP failure reported")
- dev[0].request("WPS_CANCEL")
- with alloc_fail(dev[0], 2, "wps_init"):
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = hapd.wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=10)
- if ev is None:
- raise Exception("No EAP failure reported")
- dev[0].request("WPS_CANCEL")
- with alloc_fail(dev[0], 2, "wps_init"):
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].request("WPS_PBC %s" % (apdev[0]['bssid']))
- ev = hapd.wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=10)
- if ev is None:
- raise Exception("No EAP failure reported")
- dev[0].request("WPS_CANCEL")
- dev[0].dump_monitor()
- new_ssid = "wps-new-ssid"
- new_passphrase = "1234567890"
- with alloc_fail(dev[0], 3, "wps_init"):
- dev[0].wps_reg(apdev[0]['bssid'], appin, new_ssid, "WPA2PSK", "CCMP",
- new_passphrase, no_wait=True)
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=10)
- if ev is None:
- raise Exception("No EAP failure reported")
- dev[0].flush_scan_cache()
- @remote_compatible
- def test_ap_wps_invalid_assoc_req_elem(dev, apdev):
- """WPS and invalid IE in Association Request frame"""
- ssid = "test-wps"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2" }
- hapd = hostapd.add_ap(apdev[0], params)
- pin = "12345670"
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- try:
- dev[0].request("VENDOR_ELEM_ADD 13 dd050050f20410")
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- for i in range(5):
- ev = hapd.wait_event(["CTRL-EVENT-EAP-PROPOSED-METHOD"], timeout=10)
- if ev and "vendor=14122" in ev:
- break
- if ev is None or "vendor=14122" not in ev:
- raise Exception("EAP-WSC not started")
- dev[0].request("WPS_CANCEL")
- finally:
- dev[0].request("VENDOR_ELEM_REMOVE 13 *")
- def test_ap_wps_pbc_pin_mismatch(dev, apdev):
- """WPS PBC/PIN mismatch"""
- ssid = "test-wps"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2" }
- hapd = hostapd.add_ap(apdev[0], params)
- hapd.request("SET wps_version_number 0x10")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- hapd.request("WPS_PBC")
- pin = dev[0].wps_read_pin()
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = dev[0].wait_event(["CTRL-EVENT-SCAN-RESULTS"])
- if ev is None:
- raise Exception("Scan did not complete")
- dev[0].request("WPS_CANCEL")
- hapd.request("WPS_CANCEL")
- dev[0].flush_scan_cache()
- @remote_compatible
- def test_ap_wps_ie_invalid(dev, apdev):
- """WPS PIN attempt with AP that has invalid WSC IE"""
- ssid = "test-wps"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "vendor_elements": "dd050050f20410" }
- hapd = hostapd.add_ap(apdev[0], params)
- params = { 'ssid': "another", "vendor_elements": "dd050050f20410" }
- hostapd.add_ap(apdev[1], params)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- pin = dev[0].wps_read_pin()
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = dev[0].wait_event(["CTRL-EVENT-SCAN-RESULTS"])
- if ev is None:
- raise Exception("Scan did not complete")
- dev[0].request("WPS_CANCEL")
- @remote_compatible
- def test_ap_wps_scan_prio_order(dev, apdev):
- """WPS scan priority ordering"""
- ssid = "test-wps"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2" }
- hapd = hostapd.add_ap(apdev[0], params)
- params = { 'ssid': "another", "vendor_elements": "dd050050f20410" }
- hostapd.add_ap(apdev[1], params)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].scan_for_bss(apdev[1]['bssid'], freq="2412")
- pin = dev[0].wps_read_pin()
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = dev[0].wait_event(["CTRL-EVENT-SCAN-RESULTS"])
- if ev is None:
- raise Exception("Scan did not complete")
- dev[0].request("WPS_CANCEL")
- def test_ap_wps_probe_req_ie_oom(dev, apdev):
- """WPS ProbeReq IE OOM"""
- ssid = "test-wps"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2" }
- hapd = hostapd.add_ap(apdev[0], params)
- pin = dev[0].wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- with alloc_fail(dev[0], 1, "wps_build_probe_req_ie"):
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = hapd.wait_event(["AP-STA-CONNECTED"], timeout=10)
- if ev is None:
- raise Exception("Association not seen")
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- with alloc_fail(dev[0], 1, "wps_ie_encapsulate"):
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = hapd.wait_event(["AP-STA-CONNECTED"], timeout=10)
- if ev is None:
- raise Exception("Association not seen")
- dev[0].request("WPS_CANCEL")
- hapd.disable()
- dev[0].request("REMOVE_NETWORK all")
- dev[0].wait_disconnected()
- time.sleep(0.2)
- dev[0].flush_scan_cache()
- def test_ap_wps_assoc_req_ie_oom(dev, apdev):
- """WPS AssocReq IE OOM"""
- ssid = "test-wps"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2" }
- hapd = hostapd.add_ap(apdev[0], params)
- pin = dev[0].wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- with alloc_fail(dev[0], 1, "wps_build_assoc_req_ie"):
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = hapd.wait_event(["AP-STA-CONNECTED"], timeout=10)
- if ev is None:
- raise Exception("Association not seen")
- dev[0].request("WPS_CANCEL")
- def test_ap_wps_assoc_resp_ie_oom(dev, apdev):
- """WPS AssocResp IE OOM"""
- ssid = "test-wps"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2" }
- hapd = hostapd.add_ap(apdev[0], params)
- pin = dev[0].wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- with alloc_fail(hapd, 1, "wps_build_assoc_resp_ie"):
- dev[0].request("WPS_PIN %s %s" % (apdev[0]['bssid'], pin))
- ev = hapd.wait_event(["AP-STA-CONNECTED"], timeout=10)
- if ev is None:
- raise Exception("Association not seen")
- dev[0].request("WPS_CANCEL")
- @remote_compatible
- def test_ap_wps_bss_info_errors(dev, apdev):
- """WPS BSS info errors"""
- params = { "ssid": "1",
- "vendor_elements": "dd0e0050f20410440001ff101100010a" }
- hostapd.add_ap(apdev[0], params)
- params = { 'ssid': "2", "vendor_elements": "dd050050f20410" }
- hostapd.add_ap(apdev[1], params)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].scan_for_bss(apdev[1]['bssid'], freq="2412")
- bss = dev[0].get_bss(apdev[0]['bssid'])
- logger.info("BSS: " + str(bss))
- if "wps_state" in bss:
- raise Exception("Unexpected wps_state in BSS info")
- if 'wps_device_name' not in bss:
- raise Exception("No wps_device_name in BSS info")
- if bss['wps_device_name'] != '_':
- raise Exception("Unexpected wps_device_name value")
- bss = dev[0].get_bss(apdev[1]['bssid'])
- logger.info("BSS: " + str(bss))
- with alloc_fail(dev[0], 1, "=wps_attr_text"):
- bss = dev[0].get_bss(apdev[0]['bssid'])
- logger.info("BSS(OOM): " + str(bss))
- def wps_run_pbc_fail_ap(apdev, dev, hapd):
- hapd.request("WPS_PBC")
- dev.scan_for_bss(apdev['bssid'], freq="2412")
- dev.request("WPS_PBC " + apdev['bssid'])
- ev = dev.wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=10)
- if ev is None:
- raise Exception("No EAP failure reported")
- dev.request("WPS_CANCEL")
- dev.wait_disconnected()
- for i in range(5):
- try:
- dev.flush_scan_cache()
- break
- except Exception, e:
- if str(e).startswith("Failed to trigger scan"):
- # Try again
- time.sleep(1)
- else:
- raise
- def wps_run_pbc_fail(apdev, dev):
- hapd = wps_start_ap(apdev)
- wps_run_pbc_fail_ap(apdev, dev, hapd)
- @remote_compatible
- def test_ap_wps_pk_oom(dev, apdev):
- """WPS and public key OOM"""
- with alloc_fail(dev[0], 1, "wps_build_public_key"):
- wps_run_pbc_fail(apdev[0], dev[0])
- @remote_compatible
- def test_ap_wps_pk_oom_ap(dev, apdev):
- """WPS and public key OOM on AP"""
- hapd = wps_start_ap(apdev[0])
- with alloc_fail(hapd, 1, "wps_build_public_key"):
- wps_run_pbc_fail_ap(apdev[0], dev[0], hapd)
- @remote_compatible
- def test_ap_wps_encr_oom_ap(dev, apdev):
- """WPS and encrypted settings decryption OOM on AP"""
- hapd = wps_start_ap(apdev[0])
- pin = dev[0].wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- with alloc_fail(hapd, 1, "wps_decrypt_encr_settings"):
- dev[0].request("WPS_PIN " + apdev[0]['bssid'] + " " + pin)
- ev = hapd.wait_event(["WPS-FAIL"], timeout=10)
- if ev is None:
- raise Exception("No WPS-FAIL reported")
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- @remote_compatible
- def test_ap_wps_encr_no_random_ap(dev, apdev):
- """WPS and no random data available for encryption on AP"""
- hapd = wps_start_ap(apdev[0])
- with fail_test(hapd, 1, "os_get_random;wps_build_encr_settings"):
- wps_run_pbc_fail_ap(apdev[0], dev[0], hapd)
- @remote_compatible
- def test_ap_wps_e_hash_no_random_sta(dev, apdev):
- """WPS and no random data available for e-hash on STA"""
- with fail_test(dev[0], 1, "os_get_random;wps_build_e_hash"):
- wps_run_pbc_fail(apdev[0], dev[0])
- @remote_compatible
- def test_ap_wps_m1_no_random(dev, apdev):
- """WPS and no random for M1 on STA"""
- with fail_test(dev[0], 1, "os_get_random;wps_build_m1"):
- wps_run_pbc_fail(apdev[0], dev[0])
- @remote_compatible
- def test_ap_wps_m1_oom(dev, apdev):
- """WPS and OOM for M1 on STA"""
- with alloc_fail(dev[0], 1, "wps_build_m1"):
- wps_run_pbc_fail(apdev[0], dev[0])
- @remote_compatible
- def test_ap_wps_m3_oom(dev, apdev):
- """WPS and OOM for M3 on STA"""
- with alloc_fail(dev[0], 1, "wps_build_m3"):
- wps_run_pbc_fail(apdev[0], dev[0])
- @remote_compatible
- def test_ap_wps_m5_oom(dev, apdev):
- """WPS and OOM for M5 on STA"""
- hapd = wps_start_ap(apdev[0])
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- for i in range(1, 3):
- with alloc_fail(dev[0], i, "wps_build_m5"):
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=10)
- if ev is None:
- raise Exception("No EAP failure reported")
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- @remote_compatible
- def test_ap_wps_m5_no_random(dev, apdev):
- """WPS and no random for M5 on STA"""
- with fail_test(dev[0], 1,
- "os_get_random;wps_build_encr_settings;wps_build_m5"):
- wps_run_pbc_fail(apdev[0], dev[0])
- @remote_compatible
- def test_ap_wps_m7_oom(dev, apdev):
- """WPS and OOM for M7 on STA"""
- hapd = wps_start_ap(apdev[0])
- hapd.request("WPS_PBC")
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- for i in range(1, 3):
- with alloc_fail(dev[0], i, "wps_build_m7"):
- dev[0].request("WPS_PBC " + apdev[0]['bssid'])
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=10)
- if ev is None:
- raise Exception("No EAP failure reported")
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- @remote_compatible
- def test_ap_wps_m7_no_random(dev, apdev):
- """WPS and no random for M7 on STA"""
- with fail_test(dev[0], 1,
- "os_get_random;wps_build_encr_settings;wps_build_m7"):
- wps_run_pbc_fail(apdev[0], dev[0])
- @remote_compatible
- def test_ap_wps_wsc_done_oom(dev, apdev):
- """WPS and OOM for WSC_Done on STA"""
- with alloc_fail(dev[0], 1, "wps_build_wsc_done"):
- wps_run_pbc_fail(apdev[0], dev[0])
- def test_ap_wps_random_psk_fail(dev, apdev):
- """WPS and no random for PSK on AP"""
- ssid = "test-wps"
- pskfile = "/tmp/ap_wps_per_enrollee_psk.psk_file"
- appin = "12345670"
- try:
- os.remove(pskfile)
- except:
- pass
- try:
- with open(pskfile, "w") as f:
- f.write("# WPA PSKs\n")
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa": "2", "wpa_key_mgmt": "WPA-PSK",
- "rsn_pairwise": "CCMP", "ap_pin": appin,
- "wpa_psk_file": pskfile }
- hapd = hostapd.add_ap(apdev[0], params)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- with fail_test(hapd, 1, "os_get_random;wps_build_cred_network_key"):
- dev[0].request("WPS_REG " + apdev[0]['bssid'] + " " + appin)
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=10)
- if ev is None:
- raise Exception("No EAP failure reported")
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- with fail_test(hapd, 1, "os_get_random;wps_build_cred"):
- wps_run_pbc_fail_ap(apdev[0], dev[0], hapd)
- with alloc_fail(hapd, 1, "wps_build_cred"):
- wps_run_pbc_fail_ap(apdev[0], dev[0], hapd)
- with alloc_fail(hapd, 2, "wps_build_cred"):
- wps_run_pbc_fail_ap(apdev[0], dev[0], hapd)
- finally:
- os.remove(pskfile)
- def wps_ext_eap_identity_req(dev, hapd, bssid):
- logger.debug("EAP-Identity/Request")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX from hostapd")
- res = dev.request("EAPOL_RX " + bssid + " " + ev.split(' ')[2])
- if "OK" not in res:
- raise Exception("EAPOL_RX to wpa_supplicant failed")
- def wps_ext_eap_identity_resp(hapd, dev, addr):
- ev = dev.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX from wpa_supplicant")
- res = hapd.request("EAPOL_RX " + addr + " " + ev.split(' ')[2])
- if "OK" not in res:
- raise Exception("EAPOL_RX to hostapd failed")
- def wps_ext_eap_wsc(dst, src, src_addr, msg):
- logger.debug(msg)
- ev = src.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- res = dst.request("EAPOL_RX " + src_addr + " " + ev.split(' ')[2])
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- def wps_start_ext(apdev, dev, pbc=False, pin=None):
- addr = dev.own_addr()
- bssid = apdev['bssid']
- ssid = "test-wps-conf"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP"}
- hapd = hostapd.add_ap(apdev, params)
- if pbc:
- hapd.request("WPS_PBC")
- else:
- if pin is None:
- pin = dev.wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev.scan_for_bss(bssid, freq="2412")
- hapd.request("SET ext_eapol_frame_io 1")
- dev.request("SET ext_eapol_frame_io 1")
- if pbc:
- dev.request("WPS_PBC " + bssid)
- else:
- dev.request("WPS_PIN " + bssid + " " + pin)
- return addr,bssid,hapd
- def wps_auth_corrupt(dst, src, addr):
- ev = src.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- src.request("SET ext_eapol_frame_io 0")
- dst.request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- if msg[-24:-16] != '10050008':
- raise Exception("Could not find Authenticator attribute")
- # Corrupt Authenticator value
- msg = msg[:-1] + '%x' % ((int(msg[-1], 16) + 1) % 16)
- res = dst.request("EAPOL_RX " + addr + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- def wps_fail_finish(hapd, dev, fail_str):
- ev = hapd.wait_event(["WPS-FAIL"], timeout=5)
- if ev is None:
- raise Exception("WPS-FAIL not indicated")
- if fail_str not in ev:
- raise Exception("Unexpected WPS-FAIL value: " + ev)
- dev.request("WPS_CANCEL")
- dev.wait_disconnected()
- def wps_auth_corrupt_from_ap(dev, hapd, bssid, fail_str):
- wps_auth_corrupt(dev, hapd, bssid)
- wps_fail_finish(hapd, dev, fail_str)
- def wps_auth_corrupt_to_ap(dev, hapd, addr, fail_str):
- wps_auth_corrupt(hapd, dev, addr)
- wps_fail_finish(hapd, dev, fail_str)
- def test_ap_wps_authenticator_mismatch_m2(dev, apdev):
- """WPS and Authenticator attribute mismatch in M2"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0])
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- wps_auth_corrupt_from_ap(dev[0], hapd, bssid, "msg=5")
- def test_ap_wps_authenticator_mismatch_m3(dev, apdev):
- """WPS and Authenticator attribute mismatch in M3"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0])
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- wps_ext_eap_wsc(dev[0], hapd, bssid, "M2")
- logger.debug("M3")
- wps_auth_corrupt_to_ap(dev[0], hapd, addr, "msg=7")
- def test_ap_wps_authenticator_mismatch_m4(dev, apdev):
- """WPS and Authenticator attribute mismatch in M4"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0])
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- wps_ext_eap_wsc(dev[0], hapd, bssid, "M2")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M3")
- logger.debug("M4")
- wps_auth_corrupt_from_ap(dev[0], hapd, bssid, "msg=8")
- def test_ap_wps_authenticator_mismatch_m5(dev, apdev):
- """WPS and Authenticator attribute mismatch in M5"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0])
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- wps_ext_eap_wsc(dev[0], hapd, bssid, "M2")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M3")
- wps_ext_eap_wsc(dev[0], hapd, bssid, "M4")
- logger.debug("M5")
- wps_auth_corrupt_to_ap(dev[0], hapd, addr, "msg=9")
- def test_ap_wps_authenticator_mismatch_m6(dev, apdev):
- """WPS and Authenticator attribute mismatch in M6"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0])
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- wps_ext_eap_wsc(dev[0], hapd, bssid, "M2")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M3")
- wps_ext_eap_wsc(dev[0], hapd, bssid, "M4")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M5")
- logger.debug("M6")
- wps_auth_corrupt_from_ap(dev[0], hapd, bssid, "msg=10")
- def test_ap_wps_authenticator_mismatch_m7(dev, apdev):
- """WPS and Authenticator attribute mismatch in M7"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0])
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- wps_ext_eap_wsc(dev[0], hapd, bssid, "M2")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M3")
- wps_ext_eap_wsc(dev[0], hapd, bssid, "M4")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M5")
- wps_ext_eap_wsc(dev[0], hapd, bssid, "M6")
- logger.debug("M7")
- wps_auth_corrupt_to_ap(dev[0], hapd, addr, "msg=11")
- def test_ap_wps_authenticator_mismatch_m8(dev, apdev):
- """WPS and Authenticator attribute mismatch in M8"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0])
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- wps_ext_eap_wsc(dev[0], hapd, bssid, "M2")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M3")
- wps_ext_eap_wsc(dev[0], hapd, bssid, "M4")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M5")
- wps_ext_eap_wsc(dev[0], hapd, bssid, "M6")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M7")
- logger.debug("M8")
- wps_auth_corrupt_from_ap(dev[0], hapd, bssid, "msg=12")
- def test_ap_wps_authenticator_missing_m2(dev, apdev):
- """WPS and Authenticator attribute missing from M2"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0])
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- if msg[-24:-16] != '10050008':
- raise Exception("Could not find Authenticator attribute")
- # Remove Authenticator value
- msg = msg[:-24]
- mlen = "%04x" % (int(msg[4:8], 16) - 12)
- msg = msg[0:4] + mlen + msg[8:12] + mlen + msg[16:]
- res = dev[0].request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- wps_fail_finish(hapd, dev[0], "msg=5")
- def test_ap_wps_m2_dev_passwd_id_p2p(dev, apdev):
- """WPS and M2 with different Device Password ID (P2P)"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0])
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- if msg[722:730] != '10120002':
- raise Exception("Could not find Device Password ID attribute")
- # Replace Device Password ID value. This will fail Authenticator check, but
- # allows the code path in wps_process_dev_pw_id() to be checked from debug
- # log.
- msg = msg[0:730] + "0005" + msg[734:]
- res = dev[0].request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- wps_fail_finish(hapd, dev[0], "msg=5")
- def test_ap_wps_m2_dev_passwd_id_change_pin_to_pbc(dev, apdev):
- """WPS and M2 with different Device Password ID (PIN to PBC)"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0])
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- if msg[722:730] != '10120002':
- raise Exception("Could not find Device Password ID attribute")
- # Replace Device Password ID value (PIN --> PBC). This will be rejected.
- msg = msg[0:730] + "0004" + msg[734:]
- res = dev[0].request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- wps_fail_finish(hapd, dev[0], "msg=5")
- def test_ap_wps_m2_dev_passwd_id_change_pbc_to_pin(dev, apdev):
- """WPS and M2 with different Device Password ID (PBC to PIN)"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pbc=True)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- if msg[722:730] != '10120002':
- raise Exception("Could not find Device Password ID attribute")
- # Replace Device Password ID value. This will fail Authenticator check, but
- # allows the code path in wps_process_dev_pw_id() to be checked from debug
- # log.
- msg = msg[0:730] + "0000" + msg[734:]
- res = dev[0].request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- wps_fail_finish(hapd, dev[0], "msg=5")
- dev[0].flush_scan_cache()
- def test_ap_wps_m2_missing_dev_passwd_id(dev, apdev):
- """WPS and M2 without Device Password ID"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0])
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- if msg[722:730] != '10120002':
- raise Exception("Could not find Device Password ID attribute")
- # Remove Device Password ID value. This will fail Authenticator check, but
- # allows the code path in wps_process_dev_pw_id() to be checked from debug
- # log.
- mlen = "%04x" % (int(msg[4:8], 16) - 6)
- msg = msg[0:4] + mlen + msg[8:12] + mlen + msg[16:722] + msg[734:]
- res = dev[0].request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- wps_fail_finish(hapd, dev[0], "msg=5")
- def test_ap_wps_m2_missing_registrar_nonce(dev, apdev):
- """WPS and M2 without Registrar Nonce"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pbc=True)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- if msg[96:104] != '10390010':
- raise Exception("Could not find Registrar Nonce attribute")
- # Remove Registrar Nonce. This will fail Authenticator check, but
- # allows the code path in wps_process_registrar_nonce() to be checked from
- # the debug log.
- mlen = "%04x" % (int(msg[4:8], 16) - 20)
- msg = msg[0:4] + mlen + msg[8:12] + mlen + msg[16:96] + msg[136:]
- res = dev[0].request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- ev = dev[0].wait_event(["CTRL-EVENT-DISCONNECT"], timeout=5)
- if ev is None:
- raise Exception("Disconnect event not seen")
- dev[0].request("WPS_CANCEL")
- dev[0].flush_scan_cache()
- def test_ap_wps_m2_missing_enrollee_nonce(dev, apdev):
- """WPS and M2 without Enrollee Nonce"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pbc=True)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- if msg[56:64] != '101a0010':
- raise Exception("Could not find enrollee Nonce attribute")
- # Remove Enrollee Nonce. This will fail Authenticator check, but
- # allows the code path in wps_process_enrollee_nonce() to be checked from
- # the debug log.
- mlen = "%04x" % (int(msg[4:8], 16) - 20)
- msg = msg[0:4] + mlen + msg[8:12] + mlen + msg[16:56] + msg[96:]
- res = dev[0].request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- ev = dev[0].wait_event(["CTRL-EVENT-DISCONNECT"], timeout=5)
- if ev is None:
- raise Exception("Disconnect event not seen")
- dev[0].request("WPS_CANCEL")
- dev[0].flush_scan_cache()
- def test_ap_wps_m2_missing_uuid_r(dev, apdev):
- """WPS and M2 without UUID-R"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pbc=True)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- if msg[136:144] != '10480010':
- raise Exception("Could not find enrollee Nonce attribute")
- # Remove UUID-R. This will fail Authenticator check, but allows the code
- # path in wps_process_uuid_r() to be checked from the debug log.
- mlen = "%04x" % (int(msg[4:8], 16) - 20)
- msg = msg[0:4] + mlen + msg[8:12] + mlen + msg[16:136] + msg[176:]
- res = dev[0].request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- ev = dev[0].wait_event(["CTRL-EVENT-DISCONNECT"], timeout=5)
- if ev is None:
- raise Exception("Disconnect event not seen")
- dev[0].request("WPS_CANCEL")
- dev[0].flush_scan_cache()
- def test_ap_wps_m2_invalid(dev, apdev):
- """WPS and M2 parsing failure"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pbc=True)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- if msg[136:144] != '10480010':
- raise Exception("Could not find enrollee Nonce attribute")
- # Remove UUID-R. This will fail Authenticator check, but allows the code
- # path in wps_process_uuid_r() to be checked from the debug log.
- mlen = "%04x" % (int(msg[4:8], 16) - 1)
- msg = msg[0:4] + mlen + msg[8:12] + mlen + msg[16:-2]
- res = dev[0].request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- ev = dev[0].wait_event(["CTRL-EVENT-DISCONNECT"], timeout=5)
- if ev is None:
- raise Exception("Disconnect event not seen")
- dev[0].request("WPS_CANCEL")
- dev[0].flush_scan_cache()
- def test_ap_wps_m2_missing_msg_type(dev, apdev):
- """WPS and M2 without Message Type"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pbc=True)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- if msg[46:54] != '10220001':
- raise Exception("Could not find Message Type attribute")
- # Remove Message Type. This will fail Authenticator check, but allows the
- # code path in wps_process_wsc_msg() to be checked from the debug log.
- mlen = "%04x" % (int(msg[4:8], 16) - 5)
- msg = msg[0:4] + mlen + msg[8:12] + mlen + msg[16:46] + msg[56:]
- res = dev[0].request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- ev = dev[0].wait_event(["CTRL-EVENT-DISCONNECT"], timeout=5)
- if ev is None:
- raise Exception("Disconnect event not seen")
- dev[0].request("WPS_CANCEL")
- dev[0].flush_scan_cache()
- def test_ap_wps_m2_unknown_msg_type(dev, apdev):
- """WPS and M2 but unknown Message Type"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pbc=True)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- if msg[46:54] != '10220001':
- raise Exception("Could not find Message Type attribute")
- # Replace Message Type value. This will be rejected.
- msg = msg[0:54] + "00" + msg[56:]
- res = dev[0].request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- ev = dev[0].wait_event(["CTRL-EVENT-DISCONNECT"], timeout=5)
- if ev is None:
- raise Exception("Disconnect event not seen")
- dev[0].request("WPS_CANCEL")
- dev[0].flush_scan_cache()
- def test_ap_wps_m2_unknown_opcode(dev, apdev):
- """WPS and M2 but unknown opcode"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pbc=True)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- # Replace opcode. This will be discarded in EAP-WSC processing.
- msg = msg[0:32] + "00" + msg[34:]
- res = dev[0].request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_ap_wps_m2_unknown_opcode2(dev, apdev):
- """WPS and M2 but unknown opcode (WSC_Start)"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pbc=True)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- # Replace opcode. This will be discarded in EAP-WSC processing.
- msg = msg[0:32] + "01" + msg[34:]
- res = dev[0].request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_ap_wps_m2_unknown_opcode3(dev, apdev):
- """WPS and M2 but unknown opcode (WSC_Done)"""
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pbc=True)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev[0], addr, "M1")
- logger.debug("M2")
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- # Replace opcode. This will be discarded in WPS Enrollee processing.
- msg = msg[0:32] + "05" + msg[34:]
- res = dev[0].request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def wps_m2_but_other(dev, apdev, title, msgtype):
- addr,bssid,hapd = wps_start_ext(apdev, dev)
- wps_ext_eap_identity_req(dev, hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev, addr)
- wps_ext_eap_wsc(dev, hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev, addr, "M1")
- logger.debug(title)
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev.request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- if msg[46:54] != '10220001':
- raise Exception("Could not find Message Type attribute")
- # Replace Message Type value. This will be rejected.
- msg = msg[0:54] + msgtype + msg[56:]
- res = dev.request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- ev = dev.wait_event(["WPS-FAIL"], timeout=5)
- if ev is None:
- raise Exception("WPS-FAIL event not seen")
- dev.request("WPS_CANCEL")
- dev.wait_disconnected()
- def wps_m4_but_other(dev, apdev, title, msgtype):
- addr,bssid,hapd = wps_start_ext(apdev, dev)
- wps_ext_eap_identity_req(dev, hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev, addr)
- wps_ext_eap_wsc(dev, hapd, bssid, "EAP-WSC/Start")
- wps_ext_eap_wsc(hapd, dev, addr, "M1")
- wps_ext_eap_wsc(dev, hapd, bssid, "M2")
- wps_ext_eap_wsc(hapd, dev, addr, "M3")
- logger.debug(title)
- ev = hapd.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- hapd.request("SET ext_eapol_frame_io 0")
- dev.request("SET ext_eapol_frame_io 0")
- msg = ev.split(' ')[2]
- if msg[46:54] != '10220001':
- raise Exception("Could not find Message Type attribute")
- # Replace Message Type value. This will be rejected.
- msg = msg[0:54] + msgtype + msg[56:]
- res = dev.request("EAPOL_RX " + bssid + " " + msg)
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- ev = hapd.wait_event(["WPS-FAIL"], timeout=5)
- if ev is None:
- raise Exception("WPS-FAIL event not seen")
- dev.request("WPS_CANCEL")
- dev.wait_disconnected()
- def test_ap_wps_m2_msg_type_m4(dev, apdev):
- """WPS and M2 but Message Type M4"""
- wps_m2_but_other(dev[0], apdev[0], "M2/M4", "08")
- def test_ap_wps_m2_msg_type_m6(dev, apdev):
- """WPS and M2 but Message Type M6"""
- wps_m2_but_other(dev[0], apdev[0], "M2/M6", "0a")
- def test_ap_wps_m2_msg_type_m8(dev, apdev):
- """WPS and M2 but Message Type M8"""
- wps_m2_but_other(dev[0], apdev[0], "M2/M8", "0c")
- def test_ap_wps_m4_msg_type_m2(dev, apdev):
- """WPS and M4 but Message Type M2"""
- wps_m4_but_other(dev[0], apdev[0], "M4/M2", "05")
- def test_ap_wps_m4_msg_type_m2d(dev, apdev):
- """WPS and M4 but Message Type M2D"""
- wps_m4_but_other(dev[0], apdev[0], "M4/M2D", "06")
- @remote_compatible
- def test_ap_wps_config_methods(dev, apdev):
- """WPS configuration method parsing"""
- ssid = "test-wps-conf"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "config_methods": "ethernet display ext_nfc_token int_nfc_token physical_display physical_push_button" }
- hapd = hostapd.add_ap(apdev[0], params)
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "config_methods": "display push_button" }
- hapd2 = hostapd.add_ap(apdev[1], params)
- def test_ap_wps_set_selected_registrar_proto(dev, apdev):
- """WPS UPnP SetSelectedRegistrar protocol testing"""
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- hapd = add_ssdp_ap(apdev[0], ap_uuid)
- location = ssdp_get_location(ap_uuid)
- urls = upnp_get_urls(location)
- eventurl = urlparse.urlparse(urls['event_sub_url'])
- ctrlurl = urlparse.urlparse(urls['control_url'])
- url = urlparse.urlparse(location)
- conn = httplib.HTTPConnection(url.netloc)
- class WPSERHTTPServer(SocketServer.StreamRequestHandler):
- def handle(self):
- data = self.rfile.readline().strip()
- logger.debug(data)
- self.wfile.write(gen_wps_event())
- server = MyTCPServer(("127.0.0.1", 12345), WPSERHTTPServer)
- server.timeout = 1
- headers = { "callback": '<http://127.0.0.1:12345/event>',
- "NT": "upnp:event",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- sid = resp.getheader("sid")
- logger.debug("Subscription SID " + sid)
- server.handle_request()
- tests = [ (500, "10"),
- (200, "104a000110" + "1041000101" + "101200020000" +
- "105300023148" +
- "1049002c00372a0001200124111111111111222222222222333333333333444444444444555555555555666666666666" +
- "10480010362db47ba53a519188fb5458b986b2e4"),
- (200, "104a000110" + "1041000100" + "101200020000" +
- "105300020000"),
- (200, "104a000110" + "1041000100"),
- (200, "104a000110") ]
- for status,test in tests:
- tlvs = binascii.unhexlify(test)
- newmsg = base64.b64encode(tlvs)
- msg = '<?xml version="1.0"?>\n'
- msg += '<s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">'
- msg += '<s:Body>'
- msg += '<u:SetSelectedRegistrar xmlns:u="urn:schemas-wifialliance-org:service:WFAWLANConfig:1">'
- msg += '<NewMessage>'
- msg += newmsg
- msg += "</NewMessage></u:SetSelectedRegistrar></s:Body></s:Envelope>"
- headers = { "Content-type": 'text/xml; charset="utf-8"' }
- headers["SOAPAction"] = '"urn:schemas-wifialliance-org:service:WFAWLANConfig:1#%s"' % "SetSelectedRegistrar"
- conn.request("POST", ctrlurl.path, msg, headers)
- resp = conn.getresponse()
- if resp.status != status:
- raise Exception("Unexpected HTTP response: %d (expected %d)" % (resp.status, status))
- def test_ap_wps_adv_oom(dev, apdev):
- """WPS AP and advertisement OOM"""
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- hapd = add_ssdp_ap(apdev[0], ap_uuid)
- with alloc_fail(hapd, 1, "=msearchreply_state_machine_start"):
- ssdp_send_msearch("urn:schemas-wifialliance-org:service:WFAWLANConfig:1",
- no_recv=True)
- time.sleep(0.2)
- with alloc_fail(hapd, 1, "eloop_register_timeout;msearchreply_state_machine_start"):
- ssdp_send_msearch("urn:schemas-wifialliance-org:service:WFAWLANConfig:1",
- no_recv=True)
- time.sleep(0.2)
- with alloc_fail(hapd, 1,
- "next_advertisement;advertisement_state_machine_stop"):
- hapd.disable()
- with alloc_fail(hapd, 1, "ssdp_listener_start"):
- if "FAIL" not in hapd.request("ENABLE"):
- raise Exception("ENABLE succeeded during OOM")
- def test_wps_config_methods(dev):
- """WPS config method update"""
- wpas = WpaSupplicant(global_iface='/tmp/wpas-wlan5')
- wpas.interface_add("wlan5")
- if "OK" not in wpas.request("SET config_methods display label"):
- raise Exception("Failed to set config_methods")
- if wpas.request("GET config_methods").strip() != "display label":
- raise Exception("config_methods were not updated")
- if "OK" not in wpas.request("SET config_methods "):
- raise Exception("Failed to clear config_methods")
- if wpas.request("GET config_methods").strip() != "":
- raise Exception("config_methods were not cleared")
- WPS_VENDOR_ID_WFA = 14122
- WPS_VENDOR_TYPE = 1
- # EAP-WSC Op-Code values
- WSC_Start = 0x01
- WSC_ACK = 0x02
- WSC_NACK = 0x03
- WSC_MSG = 0x04
- WSC_Done = 0x05
- WSC_FRAG_ACK = 0x06
- ATTR_AP_CHANNEL = 0x1001
- ATTR_ASSOC_STATE = 0x1002
- ATTR_AUTH_TYPE = 0x1003
- ATTR_AUTH_TYPE_FLAGS = 0x1004
- ATTR_AUTHENTICATOR = 0x1005
- ATTR_CONFIG_METHODS = 0x1008
- ATTR_CONFIG_ERROR = 0x1009
- ATTR_CONFIRM_URL4 = 0x100a
- ATTR_CONFIRM_URL6 = 0x100b
- ATTR_CONN_TYPE = 0x100c
- ATTR_CONN_TYPE_FLAGS = 0x100d
- ATTR_CRED = 0x100e
- ATTR_ENCR_TYPE = 0x100f
- ATTR_ENCR_TYPE_FLAGS = 0x1010
- ATTR_DEV_NAME = 0x1011
- ATTR_DEV_PASSWORD_ID = 0x1012
- ATTR_E_HASH1 = 0x1014
- ATTR_E_HASH2 = 0x1015
- ATTR_E_SNONCE1 = 0x1016
- ATTR_E_SNONCE2 = 0x1017
- ATTR_ENCR_SETTINGS = 0x1018
- ATTR_ENROLLEE_NONCE = 0x101a
- ATTR_FEATURE_ID = 0x101b
- ATTR_IDENTITY = 0x101c
- ATTR_IDENTITY_PROOF = 0x101d
- ATTR_KEY_WRAP_AUTH = 0x101e
- ATTR_KEY_ID = 0x101f
- ATTR_MAC_ADDR = 0x1020
- ATTR_MANUFACTURER = 0x1021
- ATTR_MSG_TYPE = 0x1022
- ATTR_MODEL_NAME = 0x1023
- ATTR_MODEL_NUMBER = 0x1024
- ATTR_NETWORK_INDEX = 0x1026
- ATTR_NETWORK_KEY = 0x1027
- ATTR_NETWORK_KEY_INDEX = 0x1028
- ATTR_NEW_DEVICE_NAME = 0x1029
- ATTR_NEW_PASSWORD = 0x102a
- ATTR_OOB_DEVICE_PASSWORD = 0x102c
- ATTR_OS_VERSION = 0x102d
- ATTR_POWER_LEVEL = 0x102f
- ATTR_PSK_CURRENT = 0x1030
- ATTR_PSK_MAX = 0x1031
- ATTR_PUBLIC_KEY = 0x1032
- ATTR_RADIO_ENABLE = 0x1033
- ATTR_REBOOT = 0x1034
- ATTR_REGISTRAR_CURRENT = 0x1035
- ATTR_REGISTRAR_ESTABLISHED = 0x1036
- ATTR_REGISTRAR_LIST = 0x1037
- ATTR_REGISTRAR_MAX = 0x1038
- ATTR_REGISTRAR_NONCE = 0x1039
- ATTR_REQUEST_TYPE = 0x103a
- ATTR_RESPONSE_TYPE = 0x103b
- ATTR_RF_BANDS = 0x103c
- ATTR_R_HASH1 = 0x103d
- ATTR_R_HASH2 = 0x103e
- ATTR_R_SNONCE1 = 0x103f
- ATTR_R_SNONCE2 = 0x1040
- ATTR_SELECTED_REGISTRAR = 0x1041
- ATTR_SERIAL_NUMBER = 0x1042
- ATTR_WPS_STATE = 0x1044
- ATTR_SSID = 0x1045
- ATTR_TOTAL_NETWORKS = 0x1046
- ATTR_UUID_E = 0x1047
- ATTR_UUID_R = 0x1048
- ATTR_VENDOR_EXT = 0x1049
- ATTR_VERSION = 0x104a
- ATTR_X509_CERT_REQ = 0x104b
- ATTR_X509_CERT = 0x104c
- ATTR_EAP_IDENTITY = 0x104d
- ATTR_MSG_COUNTER = 0x104e
- ATTR_PUBKEY_HASH = 0x104f
- ATTR_REKEY_KEY = 0x1050
- ATTR_KEY_LIFETIME = 0x1051
- ATTR_PERMITTED_CFG_METHODS = 0x1052
- ATTR_SELECTED_REGISTRAR_CONFIG_METHODS = 0x1053
- ATTR_PRIMARY_DEV_TYPE = 0x1054
- ATTR_SECONDARY_DEV_TYPE_LIST = 0x1055
- ATTR_PORTABLE_DEV = 0x1056
- ATTR_AP_SETUP_LOCKED = 0x1057
- ATTR_APPLICATION_EXT = 0x1058
- ATTR_EAP_TYPE = 0x1059
- ATTR_IV = 0x1060
- ATTR_KEY_PROVIDED_AUTO = 0x1061
- ATTR_802_1X_ENABLED = 0x1062
- ATTR_APPSESSIONKEY = 0x1063
- ATTR_WEPTRANSMITKEY = 0x1064
- ATTR_REQUESTED_DEV_TYPE = 0x106a
- # Message Type
- WPS_Beacon = 0x01
- WPS_ProbeRequest = 0x02
- WPS_ProbeResponse = 0x03
- WPS_M1 = 0x04
- WPS_M2 = 0x05
- WPS_M2D = 0x06
- WPS_M3 = 0x07
- WPS_M4 = 0x08
- WPS_M5 = 0x09
- WPS_M6 = 0x0a
- WPS_M7 = 0x0b
- WPS_M8 = 0x0c
- WPS_WSC_ACK = 0x0d
- WPS_WSC_NACK = 0x0e
- WPS_WSC_DONE = 0x0f
- def get_wsc_msg(dev):
- ev = dev.wait_event(["EAPOL-TX"], timeout=10)
- if ev is None:
- raise Exception("Timeout on EAPOL-TX")
- data = binascii.unhexlify(ev.split(' ')[2])
- msg = {}
- # Parse EAPOL header
- if len(data) < 4:
- raise Exception("No room for EAPOL header")
- version,type,length = struct.unpack('>BBH', data[0:4])
- msg['eapol_version'] = version
- msg['eapol_type'] = type
- msg['eapol_length'] = length
- data = data[4:]
- if length != len(data):
- raise Exception("EAPOL header length mismatch (%d != %d)" % (length, len(data)))
- if type != 0:
- raise Exception("Unexpected EAPOL header type: %d" % type)
- # Parse EAP header
- if len(data) < 4:
- raise Exception("No room for EAP header")
- code,identifier,length = struct.unpack('>BBH', data[0:4])
- msg['eap_code'] = code
- msg['eap_identifier'] = identifier
- msg['eap_length'] = length
- data = data[4:]
- if msg['eapol_length'] != msg['eap_length']:
- raise Exception("EAP header length mismatch (%d != %d)" % (msg['eapol_length'], length))
- # Parse EAP expanded header
- if len(data) < 1:
- raise Exception("No EAP type included")
- msg['eap_type'], = struct.unpack('B', data[0])
- data = data[1:]
- if msg['eap_type'] == 254:
- if len(data) < 3 + 4:
- raise Exception("Truncated EAP expanded header")
- msg['eap_vendor_id'], msg['eap_vendor_type'] = struct.unpack('>LL', '\0' + data[0:7])
- data = data[7:]
- else:
- raise Exception("Unexpected EAP type")
- if msg['eap_vendor_id'] != WPS_VENDOR_ID_WFA:
- raise Exception("Unexpected Vendor-Id")
- if msg['eap_vendor_type'] != WPS_VENDOR_TYPE:
- raise Exception("Unexpected Vendor-Type")
- # Parse EAP-WSC header
- if len(data) < 2:
- raise Exception("Truncated EAP-WSC header")
- msg['wsc_opcode'], msg['wsc_flags'] = struct.unpack('BB', data[0:2])
- data = data[2:]
- # Parse WSC attributes
- msg['raw_attrs'] = data
- attrs = {}
- while len(data) > 0:
- if len(data) < 4:
- raise Exception("Truncated attribute header")
- attr,length = struct.unpack('>HH', data[0:4])
- data = data[4:]
- if length > len(data):
- raise Exception("Truncated attribute 0x%04x" % attr)
- attrs[attr] = data[0:length]
- data = data[length:]
- msg['wsc_attrs'] = attrs
- if ATTR_MSG_TYPE in attrs:
- msg['wsc_msg_type'], = struct.unpack('B', attrs[ATTR_MSG_TYPE])
- return msg
- def recv_wsc_msg(dev, opcode, msg_type):
- msg = get_wsc_msg(dev)
- if msg['wsc_opcode'] != opcode or msg['wsc_msg_type'] != msg_type:
- raise Exception("Unexpected Op-Code/MsgType")
- return msg, msg['wsc_attrs'], msg['raw_attrs']
- def build_wsc_attr(attr, payload):
- return struct.pack('>HH', attr, len(payload)) + payload
- def build_attr_msg_type(msg_type):
- return build_wsc_attr(ATTR_MSG_TYPE, struct.pack('B', msg_type))
- def build_eap_wsc(eap_code, eap_id, payload, opcode=WSC_MSG):
- length = 4 + 8 + 2 + len(payload)
- # EAPOL header
- msg = struct.pack('>BBH', 2, 0, length)
- # EAP header
- msg += struct.pack('>BBH', eap_code, eap_id, length)
- # EAP expanded header for EAP-WSC
- msg += struct.pack('B', 254)
- msg += struct.pack('>L', WPS_VENDOR_ID_WFA)[1:4]
- msg += struct.pack('>L', WPS_VENDOR_TYPE)
- # EAP-WSC header
- msg += struct.pack('BB', opcode, 0)
- # WSC attributes
- msg += payload
- return msg
- def build_eap_success(eap_id):
- length = 4
- # EAPOL header
- msg = struct.pack('>BBH', 2, 0, length)
- # EAP header
- msg += struct.pack('>BBH', 3, eap_id, length)
- return msg
- def build_eap_failure(eap_id):
- length = 4
- # EAPOL header
- msg = struct.pack('>BBH', 2, 0, length)
- # EAP header
- msg += struct.pack('>BBH', 4, eap_id, length)
- return msg
- def send_wsc_msg(dev, src, msg):
- res = dev.request("EAPOL_RX " + src + " " + binascii.hexlify(msg))
- if "OK" not in res:
- raise Exception("EAPOL_RX failed")
- group_5_prime = 0xFFFFFFFFFFFFFFFFC90FDAA22168C234C4C6628B80DC1CD129024E088A67CC74020BBEA63B139B22514A08798E3404DDEF9519B3CD3A431B302B0A6DF25F14374FE1356D6D51C245E485B576625E7EC6F44C42E9A637ED6B0BFF5CB6F406B7EDEE386BFB5A899FA5AE9F24117C4B1FE649286651ECE45B3DC2007CB8A163BF0598DA48361C55D39A69163FA8FD24CF5F83655D23DCA3AD961C62F356208552BB9ED529077096966D670C354E4ABC9804F1746C08CA237327FFFFFFFFFFFFFFFF
- group_5_generator = 2
- def wsc_kdf(key, label, bits):
- result = ''
- i = 1
- while len(result) * 8 < bits:
- data = struct.pack('>L', i) + label + struct.pack('>L', bits)
- m = hmac.new(key, data, hashlib.sha256)
- result += m.digest()
- i += 1
- return result[0:bits / 8]
- def wsc_keys(kdk):
- keys = wsc_kdf(kdk, "Wi-Fi Easy and Secure Key Derivation", 640)
- authkey = keys[0:32]
- keywrapkey = keys[32:48]
- emsk = keys[48:80]
- return authkey,keywrapkey,emsk
- def wsc_dev_pw_half_psk(authkey, dev_pw):
- m = hmac.new(authkey, dev_pw, hashlib.sha256)
- return m.digest()[0:16]
- def wsc_dev_pw_psk(authkey, dev_pw):
- dev_pw_1 = dev_pw[0:len(dev_pw) / 2]
- dev_pw_2 = dev_pw[len(dev_pw) / 2:]
- psk1 = wsc_dev_pw_half_psk(authkey, dev_pw_1)
- psk2 = wsc_dev_pw_half_psk(authkey, dev_pw_2)
- return psk1,psk2
- def build_attr_authenticator(authkey, prev_msg, curr_msg):
- m = hmac.new(authkey, prev_msg + curr_msg, hashlib.sha256)
- auth = m.digest()[0:8]
- return build_wsc_attr(ATTR_AUTHENTICATOR, auth)
- def build_attr_encr_settings(authkey, keywrapkey, data):
- m = hmac.new(authkey, data, hashlib.sha256)
- kwa = m.digest()[0:8]
- data += build_wsc_attr(ATTR_KEY_WRAP_AUTH, kwa)
- iv = 16*'\x99'
- aes = AES.new(keywrapkey, AES.MODE_CBC, iv)
- pad_len = 16 - len(data) % 16
- ps = pad_len * struct.pack('B', pad_len)
- data += ps
- wrapped = aes.encrypt(data)
- return build_wsc_attr(ATTR_ENCR_SETTINGS, iv + wrapped)
- def decrypt_attr_encr_settings(authkey, keywrapkey, data):
- if len(data) < 32 or len(data) % 16 != 0:
- raise Exception("Unexpected Encrypted Settings length: %d" % len(data))
- iv = data[0:16]
- encr = data[16:]
- aes = AES.new(keywrapkey, AES.MODE_CBC, iv)
- decrypted = aes.decrypt(encr)
- pad_len, = struct.unpack('B', decrypted[-1])
- if pad_len > len(decrypted):
- raise Exception("Invalid padding in Encrypted Settings")
- for i in range(-pad_len, -1):
- if decrypted[i] != decrypted[-1]:
- raise Exception("Invalid PS value in Encrypted Settings")
-
- decrypted = decrypted[0:len(decrypted) - pad_len]
- if len(decrypted) < 12:
- raise Exception("Truncated Encrypted Settings plaintext")
- kwa = decrypted[-12:]
- attr,length = struct.unpack(">HH", kwa[0:4])
- if attr != ATTR_KEY_WRAP_AUTH or length != 8:
- raise Exception("Invalid KWA header")
- kwa = kwa[4:]
- decrypted = decrypted[0:len(decrypted) - 12]
- m = hmac.new(authkey, decrypted, hashlib.sha256)
- calc_kwa = m.digest()[0:8]
- if kwa != calc_kwa:
- raise Exception("KWA mismatch")
- return decrypted
- def zeropad_str(val, pad_len):
- while len(val) < pad_len * 2:
- val = '0' + val
- return val
- def wsc_dh_init():
- # For now, use a hardcoded private key. In theory, this is supposed to be
- # randomly selected.
- own_private = 0x123456789
- own_public = pow(group_5_generator, own_private, group_5_prime)
- pk = binascii.unhexlify(zeropad_str(format(own_public, '02x'), 192))
- return own_private, pk
- def wsc_dh_kdf(peer_pk, own_private, mac_addr, e_nonce, r_nonce):
- peer_public = long(binascii.hexlify(peer_pk), 16)
- if peer_public < 2 or peer_public >= group_5_prime:
- raise Exception("Invalid peer public key")
- if pow(peer_public, (group_5_prime - 1) / 2, group_5_prime) != 1:
- raise Exception("Unexpected Legendre symbol for peer public key")
- shared_secret = pow(peer_public, own_private, group_5_prime)
- ss = zeropad_str(format(shared_secret, "02x"), 192)
- logger.debug("DH shared secret: " + ss)
- dhkey = hashlib.sha256(binascii.unhexlify(ss)).digest()
- logger.debug("DHKey: " + binascii.hexlify(dhkey))
- m = hmac.new(dhkey, e_nonce + mac_addr + r_nonce, hashlib.sha256)
- kdk = m.digest()
- logger.debug("KDK: " + binascii.hexlify(kdk))
- authkey,keywrapkey,emsk = wsc_keys(kdk)
- logger.debug("AuthKey: " + binascii.hexlify(authkey))
- logger.debug("KeyWrapKey: " + binascii.hexlify(keywrapkey))
- logger.debug("EMSK: " + binascii.hexlify(emsk))
- return authkey,keywrapkey
- def wsc_dev_pw_hash(authkey, dev_pw, e_pk, r_pk):
- psk1,psk2 = wsc_dev_pw_psk(authkey, dev_pw)
- logger.debug("PSK1: " + binascii.hexlify(psk1))
- logger.debug("PSK2: " + binascii.hexlify(psk2))
- # Note: Secret values are supposed to be random, but hardcoded values are
- # fine for testing.
- s1 = 16*'\x77'
- m = hmac.new(authkey, s1 + psk1 + e_pk + r_pk, hashlib.sha256)
- hash1 = m.digest()
- logger.debug("Hash1: " + binascii.hexlify(hash1))
- s2 = 16*'\x88'
- m = hmac.new(authkey, s2 + psk2 + e_pk + r_pk, hashlib.sha256)
- hash2 = m.digest()
- logger.debug("Hash2: " + binascii.hexlify(hash2))
- return s1,s2,hash1,hash2
- def build_m1(eap_id, uuid_e, mac_addr, e_nonce, e_pk,
- manufacturer='', model_name='', config_methods='\x00\x00'):
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M1)
- attrs += build_wsc_attr(ATTR_UUID_E, uuid_e)
- attrs += build_wsc_attr(ATTR_MAC_ADDR, mac_addr)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- attrs += build_wsc_attr(ATTR_PUBLIC_KEY, e_pk)
- attrs += build_wsc_attr(ATTR_AUTH_TYPE_FLAGS, '\x00\x00')
- attrs += build_wsc_attr(ATTR_ENCR_TYPE_FLAGS, '\x00\x00')
- attrs += build_wsc_attr(ATTR_CONN_TYPE_FLAGS, '\x00')
- attrs += build_wsc_attr(ATTR_CONFIG_METHODS, config_methods)
- attrs += build_wsc_attr(ATTR_WPS_STATE, '\x00')
- attrs += build_wsc_attr(ATTR_MANUFACTURER, manufacturer)
- attrs += build_wsc_attr(ATTR_MODEL_NAME, model_name)
- attrs += build_wsc_attr(ATTR_MODEL_NUMBER, '')
- attrs += build_wsc_attr(ATTR_SERIAL_NUMBER, '')
- attrs += build_wsc_attr(ATTR_PRIMARY_DEV_TYPE, 8*'\x00')
- attrs += build_wsc_attr(ATTR_DEV_NAME, '')
- attrs += build_wsc_attr(ATTR_RF_BANDS, '\x00')
- attrs += build_wsc_attr(ATTR_ASSOC_STATE, '\x00\x00')
- attrs += build_wsc_attr(ATTR_DEV_PASSWORD_ID, '\x00\x00')
- attrs += build_wsc_attr(ATTR_CONFIG_ERROR, '\x00\x00')
- attrs += build_wsc_attr(ATTR_OS_VERSION, '\x00\x00\x00\x00')
- m1 = build_eap_wsc(2, eap_id, attrs)
- return m1, attrs
- def build_m2(authkey, m1, eap_id, e_nonce, r_nonce, uuid_r, r_pk,
- dev_pw_id='\x00\x00', eap_code=1):
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M2)
- if e_nonce:
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- if r_nonce:
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- attrs += build_wsc_attr(ATTR_UUID_R, uuid_r)
- if r_pk:
- attrs += build_wsc_attr(ATTR_PUBLIC_KEY, r_pk)
- attrs += build_wsc_attr(ATTR_AUTH_TYPE_FLAGS, '\x00\x00')
- attrs += build_wsc_attr(ATTR_ENCR_TYPE_FLAGS, '\x00\x00')
- attrs += build_wsc_attr(ATTR_CONN_TYPE_FLAGS, '\x00')
- attrs += build_wsc_attr(ATTR_CONFIG_METHODS, '\x00\x00')
- attrs += build_wsc_attr(ATTR_MANUFACTURER, '')
- attrs += build_wsc_attr(ATTR_MODEL_NAME, '')
- attrs += build_wsc_attr(ATTR_MODEL_NUMBER, '')
- attrs += build_wsc_attr(ATTR_SERIAL_NUMBER, '')
- attrs += build_wsc_attr(ATTR_PRIMARY_DEV_TYPE, 8*'\x00')
- attrs += build_wsc_attr(ATTR_DEV_NAME, '')
- attrs += build_wsc_attr(ATTR_RF_BANDS, '\x00')
- attrs += build_wsc_attr(ATTR_ASSOC_STATE, '\x00\x00')
- attrs += build_wsc_attr(ATTR_CONFIG_ERROR, '\x00\x00')
- attrs += build_wsc_attr(ATTR_DEV_PASSWORD_ID, dev_pw_id)
- attrs += build_wsc_attr(ATTR_OS_VERSION, '\x00\x00\x00\x00')
- attrs += build_attr_authenticator(authkey, m1, attrs)
- m2 = build_eap_wsc(eap_code, eap_id, attrs)
- return m2, attrs
- def build_m2d(m1, eap_id, e_nonce, r_nonce, uuid_r, dev_pw_id=None, eap_code=1):
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M2D)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- attrs += build_wsc_attr(ATTR_UUID_R, uuid_r)
- attrs += build_wsc_attr(ATTR_AUTH_TYPE_FLAGS, '\x00\x00')
- attrs += build_wsc_attr(ATTR_ENCR_TYPE_FLAGS, '\x00\x00')
- attrs += build_wsc_attr(ATTR_CONN_TYPE_FLAGS, '\x00')
- attrs += build_wsc_attr(ATTR_CONFIG_METHODS, '\x00\x00')
- attrs += build_wsc_attr(ATTR_MANUFACTURER, '')
- attrs += build_wsc_attr(ATTR_MODEL_NAME, '')
- #attrs += build_wsc_attr(ATTR_MODEL_NUMBER, '')
- attrs += build_wsc_attr(ATTR_SERIAL_NUMBER, '')
- attrs += build_wsc_attr(ATTR_PRIMARY_DEV_TYPE, 8*'\x00')
- attrs += build_wsc_attr(ATTR_DEV_NAME, '')
- attrs += build_wsc_attr(ATTR_RF_BANDS, '\x00')
- attrs += build_wsc_attr(ATTR_ASSOC_STATE, '\x00\x00')
- attrs += build_wsc_attr(ATTR_CONFIG_ERROR, '\x00\x00')
- attrs += build_wsc_attr(ATTR_OS_VERSION, '\x00\x00\x00\x00')
- if dev_pw_id:
- attrs += build_wsc_attr(ATTR_DEV_PASSWORD_ID, dev_pw_id)
- m2d = build_eap_wsc(eap_code, eap_id, attrs)
- return m2d, attrs
- def build_ack(eap_id, e_nonce, r_nonce, msg_type=WPS_WSC_ACK, eap_code=1):
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- if msg_type is not None:
- attrs += build_attr_msg_type(msg_type)
- if e_nonce:
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- if r_nonce:
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- msg = build_eap_wsc(eap_code, eap_id, attrs, opcode=WSC_ACK)
- return msg, attrs
- def build_nack(eap_id, e_nonce, r_nonce, config_error='\x00\x00',
- msg_type=WPS_WSC_NACK, eap_code=1):
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- if msg_type is not None:
- attrs += build_attr_msg_type(msg_type)
- if e_nonce:
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- if r_nonce:
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- if config_error:
- attrs += build_wsc_attr(ATTR_CONFIG_ERROR, config_error)
- msg = build_eap_wsc(eap_code, eap_id, attrs, opcode=WSC_NACK)
- return msg, attrs
- def test_wps_ext(dev, apdev):
- """WPS against external implementation"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- wsc_start_id = msg['eap_identifier']
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- authkey,keywrapkey = wsc_dh_kdf(m2_attrs[ATTR_PUBLIC_KEY], own_private,
- mac_addr, e_nonce,
- m2_attrs[ATTR_REGISTRAR_NONCE])
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk,
- m2_attrs[ATTR_PUBLIC_KEY])
- logger.debug("Send M3 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M3)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE,
- m2_attrs[ATTR_REGISTRAR_NONCE])
- attrs += build_wsc_attr(ATTR_E_HASH1, e_hash1)
- attrs += build_wsc_attr(ATTR_E_HASH2, e_hash2)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m3)
- logger.debug("Receive M4 from AP")
- msg, m4_attrs, raw_m4_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M4)
- logger.debug("Send M5 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M5)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE,
- m2_attrs[ATTR_REGISTRAR_NONCE])
- data = build_wsc_attr(ATTR_E_SNONCE1, e_s1)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m4_attrs, attrs)
- raw_m5_attrs = attrs
- m5 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m5)
- logger.debug("Receive M6 from AP")
- msg, m6_attrs, raw_m6_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M6)
- logger.debug("Send M7 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M7)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE,
- m2_attrs[ATTR_REGISTRAR_NONCE])
- data = build_wsc_attr(ATTR_E_SNONCE2, e_s2)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m6_attrs, attrs)
- m7 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- raw_m7_attrs = attrs
- send_wsc_msg(hapd, addr, m7)
- logger.debug("Receive M8 from AP")
- msg, m8_attrs, raw_m8_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M8)
- m8_cred = decrypt_attr_encr_settings(authkey, keywrapkey,
- m8_attrs[ATTR_ENCR_SETTINGS])
- logger.debug("M8 Credential: " + binascii.hexlify(m8_cred))
- logger.debug("Prepare WSC_Done")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_WSC_DONE)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE,
- m2_attrs[ATTR_REGISTRAR_NONCE])
- wsc_done = build_eap_wsc(2, msg['eap_identifier'], attrs, opcode=WSC_Done)
- # Do not send WSC_Done yet to allow exchangw with STA complete before the
- # AP disconnects.
- uuid_r = 16*'\x33'
- r_nonce = 16*'\x44'
- eap_id = wsc_start_id
- logger.debug("Send WSC/Start to STA")
- wsc_start = build_eap_wsc(1, eap_id, "", opcode=WSC_Start)
- send_wsc_msg(dev[0], bssid, wsc_start)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M1 from STA")
- msg, m1_attrs, raw_m1_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M1)
- authkey,keywrapkey = wsc_dh_kdf(m1_attrs[ATTR_PUBLIC_KEY], own_private,
- mac_addr, m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce)
- r_s1,r_s2,r_hash1,r_hash2 = wsc_dev_pw_hash(authkey, pin,
- m1_attrs[ATTR_PUBLIC_KEY], e_pk)
- logger.debug("Send M2 to STA")
- m2, raw_m2_attrs = build_m2(authkey, raw_m1_attrs, eap_id,
- m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce, uuid_r, e_pk)
- send_wsc_msg(dev[0], bssid, m2)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M3 from STA")
- msg, m3_attrs, raw_m3_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M3)
- logger.debug("Send M4 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M4)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, m1_attrs[ATTR_ENROLLEE_NONCE])
- attrs += build_wsc_attr(ATTR_R_HASH1, r_hash1)
- attrs += build_wsc_attr(ATTR_R_HASH2, r_hash2)
- data = build_wsc_attr(ATTR_R_SNONCE1, r_s1)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m3_attrs, attrs)
- raw_m4_attrs = attrs
- m4 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m4)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M5 from STA")
- msg, m5_attrs, raw_m5_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M5)
- logger.debug("Send M6 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M6)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE,
- m1_attrs[ATTR_ENROLLEE_NONCE])
- data = build_wsc_attr(ATTR_R_SNONCE2, r_s2)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m5_attrs, attrs)
- raw_m6_attrs = attrs
- m6 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m6)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M7 from STA")
- msg, m7_attrs, raw_m7_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M7)
- logger.debug("Send M8 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M8)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE,
- m1_attrs[ATTR_ENROLLEE_NONCE])
- attrs += build_attr_encr_settings(authkey, keywrapkey, m8_cred)
- attrs += build_attr_authenticator(authkey, raw_m7_attrs, attrs)
- raw_m8_attrs = attrs
- m8 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m8)
- eap_id = (eap_id + 1) % 256
- ev = dev[0].wait_event(["WPS-CRED-RECEIVED"], timeout=5)
- if ev is None:
- raise Exception("wpa_supplicant did not report credential")
- logger.debug("Receive WSC_Done from STA")
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_Done or msg['wsc_msg_type'] != WPS_WSC_DONE:
- raise Exception("Unexpected Op-Code/MsgType for WSC_Done")
- logger.debug("Send WSC_Done to AP")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- send_wsc_msg(hapd, addr, wsc_done)
- ev = hapd.wait_event(["WPS-REG-SUCCESS"], timeout=5)
- if ev is None:
- raise Exception("hostapd did not report WPS success")
- dev[0].wait_connected()
- def wps_start_kwa(dev, apdev):
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_r = 16*'\x33'
- r_nonce = 16*'\x44'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Receive M1 from STA")
- msg, m1_attrs, raw_m1_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M1)
- eap_id = (msg['eap_identifier'] + 1) % 256
- authkey,keywrapkey = wsc_dh_kdf(m1_attrs[ATTR_PUBLIC_KEY], own_private,
- mac_addr, m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce)
- r_s1,r_s2,r_hash1,r_hash2 = wsc_dev_pw_hash(authkey, pin,
- m1_attrs[ATTR_PUBLIC_KEY], e_pk)
- logger.debug("Send M2 to STA")
- m2, raw_m2_attrs = build_m2(authkey, raw_m1_attrs, eap_id,
- m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce, uuid_r, e_pk)
- send_wsc_msg(dev[0], bssid, m2)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M3 from STA")
- msg, m3_attrs, raw_m3_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M3)
- logger.debug("Send M4 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M4)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, m1_attrs[ATTR_ENROLLEE_NONCE])
- attrs += build_wsc_attr(ATTR_R_HASH1, r_hash1)
- attrs += build_wsc_attr(ATTR_R_HASH2, r_hash2)
- return r_s1, keywrapkey, authkey, raw_m3_attrs, eap_id, bssid, attrs
- def wps_stop_kwa(dev, bssid, attrs, authkey, raw_m3_attrs, eap_id):
- attrs += build_attr_authenticator(authkey, raw_m3_attrs, attrs)
- m4 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m4)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M5 from STA")
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_Nack")
- dev[0].request("WPS_CANCEL")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- def test_wps_ext_kwa_proto_no_kwa(dev, apdev):
- """WPS and KWA error: No KWA attribute"""
- r_s1,keywrapkey,authkey,raw_m3_attrs,eap_id,bssid,attrs = wps_start_kwa(dev, apdev)
- data = build_wsc_attr(ATTR_R_SNONCE1, r_s1)
- # Encrypted Settings without KWA
- iv = 16*'\x99'
- aes = AES.new(keywrapkey, AES.MODE_CBC, iv)
- pad_len = 16 - len(data) % 16
- ps = pad_len * struct.pack('B', pad_len)
- data += ps
- wrapped = aes.encrypt(data)
- attrs += build_wsc_attr(ATTR_ENCR_SETTINGS, iv + wrapped)
- wps_stop_kwa(dev, bssid, attrs, authkey, raw_m3_attrs, eap_id)
- def test_wps_ext_kwa_proto_data_after_kwa(dev, apdev):
- """WPS and KWA error: Data after KWA"""
- r_s1,keywrapkey,authkey,raw_m3_attrs,eap_id,bssid,attrs = wps_start_kwa(dev, apdev)
- data = build_wsc_attr(ATTR_R_SNONCE1, r_s1)
- # Encrypted Settings and data after KWA
- m = hmac.new(authkey, data, hashlib.sha256)
- kwa = m.digest()[0:8]
- data += build_wsc_attr(ATTR_KEY_WRAP_AUTH, kwa)
- data += build_wsc_attr(ATTR_VENDOR_EXT, "1234567890")
- iv = 16*'\x99'
- aes = AES.new(keywrapkey, AES.MODE_CBC, iv)
- pad_len = 16 - len(data) % 16
- ps = pad_len * struct.pack('B', pad_len)
- data += ps
- wrapped = aes.encrypt(data)
- attrs += build_wsc_attr(ATTR_ENCR_SETTINGS, iv + wrapped)
- wps_stop_kwa(dev, bssid, attrs, authkey, raw_m3_attrs, eap_id)
- def test_wps_ext_kwa_proto_kwa_mismatch(dev, apdev):
- """WPS and KWA error: KWA mismatch"""
- r_s1,keywrapkey,authkey,raw_m3_attrs,eap_id,bssid,attrs = wps_start_kwa(dev, apdev)
- data = build_wsc_attr(ATTR_R_SNONCE1, r_s1)
- # Encrypted Settings and KWA with incorrect value
- data += build_wsc_attr(ATTR_KEY_WRAP_AUTH, 8*'\x00')
- iv = 16*'\x99'
- aes = AES.new(keywrapkey, AES.MODE_CBC, iv)
- pad_len = 16 - len(data) % 16
- ps = pad_len * struct.pack('B', pad_len)
- data += ps
- wrapped = aes.encrypt(data)
- attrs += build_wsc_attr(ATTR_ENCR_SETTINGS, iv + wrapped)
- wps_stop_kwa(dev, bssid, attrs, authkey, raw_m3_attrs, eap_id)
- def wps_run_cred_proto(dev, apdev, m8_cred, connect=False, no_connect=False):
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_r = 16*'\x33'
- r_nonce = 16*'\x44'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Receive M1 from STA")
- msg, m1_attrs, raw_m1_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M1)
- eap_id = (msg['eap_identifier'] + 1) % 256
- authkey,keywrapkey = wsc_dh_kdf(m1_attrs[ATTR_PUBLIC_KEY], own_private,
- mac_addr, m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce)
- r_s1,r_s2,r_hash1,r_hash2 = wsc_dev_pw_hash(authkey, pin,
- m1_attrs[ATTR_PUBLIC_KEY], e_pk)
- logger.debug("Send M2 to STA")
- m2, raw_m2_attrs = build_m2(authkey, raw_m1_attrs, eap_id,
- m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce, uuid_r, e_pk)
- send_wsc_msg(dev[0], bssid, m2)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M3 from STA")
- msg, m3_attrs, raw_m3_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M3)
- logger.debug("Send M4 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M4)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, m1_attrs[ATTR_ENROLLEE_NONCE])
- attrs += build_wsc_attr(ATTR_R_HASH1, r_hash1)
- attrs += build_wsc_attr(ATTR_R_HASH2, r_hash2)
- data = build_wsc_attr(ATTR_R_SNONCE1, r_s1)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m3_attrs, attrs)
- raw_m4_attrs = attrs
- m4 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m4)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M5 from STA")
- msg, m5_attrs, raw_m5_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M5)
- logger.debug("Send M6 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M6)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE,
- m1_attrs[ATTR_ENROLLEE_NONCE])
- data = build_wsc_attr(ATTR_R_SNONCE2, r_s2)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m5_attrs, attrs)
- raw_m6_attrs = attrs
- m6 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m6)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M7 from STA")
- msg, m7_attrs, raw_m7_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M7)
- logger.debug("Send M8 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M8)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE,
- m1_attrs[ATTR_ENROLLEE_NONCE])
- attrs += build_attr_encr_settings(authkey, keywrapkey, m8_cred)
- attrs += build_attr_authenticator(authkey, raw_m7_attrs, attrs)
- raw_m8_attrs = attrs
- m8 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m8)
- eap_id = (eap_id + 1) % 256
- if no_connect:
- logger.debug("Receive WSC_Done from STA")
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_Done or msg['wsc_msg_type'] != WPS_WSC_DONE:
- raise Exception("Unexpected Op-Code/MsgType for WSC_Done")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- dev[0].request("REMOVE_NETWORK all")
- elif connect:
- logger.debug("Receive WSC_Done from STA")
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_Done or msg['wsc_msg_type'] != WPS_WSC_DONE:
- raise Exception("Unexpected Op-Code/MsgType for WSC_Done")
- hapd.request("SET ext_eapol_frame_io 0")
- dev[0].request("SET ext_eapol_frame_io 0")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_connected()
- else:
- # Verify STA NACK's the credential
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_Nack")
- dev[0].request("WPS_CANCEL")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- def build_cred(nw_idx='\x01', ssid='test-wps-conf', auth_type='\x00\x20',
- encr_type='\x00\x08', nw_key="12345678",
- mac_addr='\x00\x00\x00\x00\x00\x00'):
- attrs = ''
- if nw_idx is not None:
- attrs += build_wsc_attr(ATTR_NETWORK_INDEX, nw_idx)
- if ssid is not None:
- attrs += build_wsc_attr(ATTR_SSID, ssid)
- if auth_type is not None:
- attrs += build_wsc_attr(ATTR_AUTH_TYPE, auth_type)
- if encr_type is not None:
- attrs += build_wsc_attr(ATTR_ENCR_TYPE, encr_type)
- if nw_key is not None:
- attrs += build_wsc_attr(ATTR_NETWORK_KEY, nw_key)
- if mac_addr is not None:
- attrs += build_wsc_attr(ATTR_MAC_ADDR, mac_addr)
- return build_wsc_attr(ATTR_CRED, attrs)
- def test_wps_ext_cred_proto_success(dev, apdev):
- """WPS and Credential: success"""
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- m8_cred = build_cred(mac_addr=mac_addr)
- wps_run_cred_proto(dev, apdev, m8_cred, connect=True)
- def test_wps_ext_cred_proto_mac_addr_mismatch(dev, apdev):
- """WPS and Credential: MAC Address mismatch"""
- m8_cred = build_cred()
- wps_run_cred_proto(dev, apdev, m8_cred, connect=True)
- def test_wps_ext_cred_proto_zero_padding(dev, apdev):
- """WPS and Credential: zeropadded attributes"""
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- m8_cred = build_cred(mac_addr=mac_addr, ssid='test-wps-conf\x00',
- nw_key="12345678\x00")
- wps_run_cred_proto(dev, apdev, m8_cred, connect=True)
- def test_wps_ext_cred_proto_ssid_missing(dev, apdev):
- """WPS and Credential: SSID missing"""
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- m8_cred = build_cred(mac_addr=mac_addr, ssid=None)
- wps_run_cred_proto(dev, apdev, m8_cred)
- def test_wps_ext_cred_proto_ssid_zero_len(dev, apdev):
- """WPS and Credential: Zero-length SSID"""
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- m8_cred = build_cred(mac_addr=mac_addr, ssid="")
- wps_run_cred_proto(dev, apdev, m8_cred, no_connect=True)
- def test_wps_ext_cred_proto_auth_type_missing(dev, apdev):
- """WPS and Credential: Auth Type missing"""
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- m8_cred = build_cred(mac_addr=mac_addr, auth_type=None)
- wps_run_cred_proto(dev, apdev, m8_cred)
- def test_wps_ext_cred_proto_encr_type_missing(dev, apdev):
- """WPS and Credential: Encr Type missing"""
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- m8_cred = build_cred(mac_addr=mac_addr, encr_type=None)
- wps_run_cred_proto(dev, apdev, m8_cred)
- def test_wps_ext_cred_proto_network_key_missing(dev, apdev):
- """WPS and Credential: Network Key missing"""
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- m8_cred = build_cred(mac_addr=mac_addr, nw_key=None)
- wps_run_cred_proto(dev, apdev, m8_cred)
- def test_wps_ext_cred_proto_network_key_missing_open(dev, apdev):
- """WPS and Credential: Network Key missing (open)"""
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- m8_cred = build_cred(mac_addr=mac_addr, auth_type='\x00\x01',
- encr_type='\x00\x01', nw_key=None, ssid="foo")
- wps_run_cred_proto(dev, apdev, m8_cred, no_connect=True)
- def test_wps_ext_cred_proto_mac_addr_missing(dev, apdev):
- """WPS and Credential: MAC Address missing"""
- m8_cred = build_cred(mac_addr=None)
- wps_run_cred_proto(dev, apdev, m8_cred)
- def test_wps_ext_cred_proto_invalid_encr_type(dev, apdev):
- """WPS and Credential: Invalid Encr Type"""
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- m8_cred = build_cred(mac_addr=mac_addr, encr_type='\x00\x00')
- wps_run_cred_proto(dev, apdev, m8_cred)
- def test_wps_ext_cred_proto_missing_cred(dev, apdev):
- """WPS and Credential: Missing Credential"""
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- m8_cred = ''
- wps_run_cred_proto(dev, apdev, m8_cred)
- def test_wps_ext_proto_m2_no_public_key(dev, apdev):
- """WPS and no Public Key in M2"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_r = 16*'\x33'
- r_nonce = 16*'\x44'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Receive M1 from STA")
- msg, m1_attrs, raw_m1_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M1)
- eap_id = (msg['eap_identifier'] + 1) % 256
- authkey,keywrapkey = wsc_dh_kdf(m1_attrs[ATTR_PUBLIC_KEY], own_private,
- mac_addr, m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce)
- r_s1,r_s2,r_hash1,r_hash2 = wsc_dev_pw_hash(authkey, pin,
- m1_attrs[ATTR_PUBLIC_KEY], e_pk)
- logger.debug("Send M2 to STA")
- m2, raw_m2_attrs = build_m2(authkey, raw_m1_attrs, eap_id,
- m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce, uuid_r, None)
- send_wsc_msg(dev[0], bssid, m2)
- eap_id = (eap_id + 1) % 256
- # Verify STA NACK's the credential
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_Nack")
- dev[0].request("WPS_CANCEL")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- def test_wps_ext_proto_m2_invalid_public_key(dev, apdev):
- """WPS and invalid Public Key in M2"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_r = 16*'\x33'
- r_nonce = 16*'\x44'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Receive M1 from STA")
- msg, m1_attrs, raw_m1_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M1)
- eap_id = (msg['eap_identifier'] + 1) % 256
- authkey,keywrapkey = wsc_dh_kdf(m1_attrs[ATTR_PUBLIC_KEY], own_private,
- mac_addr, m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce)
- r_s1,r_s2,r_hash1,r_hash2 = wsc_dev_pw_hash(authkey, pin,
- m1_attrs[ATTR_PUBLIC_KEY], e_pk)
- logger.debug("Send M2 to STA")
- m2, raw_m2_attrs = build_m2(authkey, raw_m1_attrs, eap_id,
- m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce, uuid_r, 192*'\xff')
- send_wsc_msg(dev[0], bssid, m2)
- eap_id = (eap_id + 1) % 256
- # Verify STA NACK's the credential
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_Nack")
- dev[0].request("WPS_CANCEL")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- def test_wps_ext_proto_m2_public_key_oom(dev, apdev):
- """WPS and Public Key OOM in M2"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_r = 16*'\x33'
- r_nonce = 16*'\x44'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Receive M1 from STA")
- msg, m1_attrs, raw_m1_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M1)
- eap_id = (msg['eap_identifier'] + 1) % 256
- authkey,keywrapkey = wsc_dh_kdf(m1_attrs[ATTR_PUBLIC_KEY], own_private,
- mac_addr, m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce)
- r_s1,r_s2,r_hash1,r_hash2 = wsc_dev_pw_hash(authkey, pin,
- m1_attrs[ATTR_PUBLIC_KEY], e_pk)
- logger.debug("Send M2 to STA")
- m2, raw_m2_attrs = build_m2(authkey, raw_m1_attrs, eap_id,
- m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce, uuid_r, e_pk)
- with alloc_fail(dev[0], 1, "wpabuf_alloc_copy;wps_process_pubkey"):
- send_wsc_msg(dev[0], bssid, m2)
- eap_id = (eap_id + 1) % 256
- # Verify STA NACK's the credential
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_Nack")
- dev[0].request("WPS_CANCEL")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- def test_wps_ext_proto_nack_m3(dev, apdev):
- """WPS and NACK M3"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_r = 16*'\x33'
- r_nonce = 16*'\x44'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Receive M1 from STA")
- msg, m1_attrs, raw_m1_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M1)
- eap_id = (msg['eap_identifier'] + 1) % 256
- authkey,keywrapkey = wsc_dh_kdf(m1_attrs[ATTR_PUBLIC_KEY], own_private,
- mac_addr, m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce)
- r_s1,r_s2,r_hash1,r_hash2 = wsc_dev_pw_hash(authkey, pin,
- m1_attrs[ATTR_PUBLIC_KEY], e_pk)
- logger.debug("Send M2 to STA")
- m2, raw_m2_attrs = build_m2(authkey, raw_m1_attrs, eap_id,
- m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce, uuid_r, e_pk)
- send_wsc_msg(dev[0], bssid, m2)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M3 from STA")
- msg, m3_attrs, raw_m3_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M3)
- logger.debug("Send NACK to STA")
- msg, attrs = build_nack(eap_id, m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce, config_error='\x01\x23')
- send_wsc_msg(dev[0], bssid, msg)
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=5)
- if ev is None:
- raise Exception("Failure not reported")
- if "msg=7 config_error=291" not in ev:
- raise Exception("Unexpected failure reason: " + ev)
- def test_wps_ext_proto_nack_m5(dev, apdev):
- """WPS and NACK M5"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_r = 16*'\x33'
- r_nonce = 16*'\x44'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Receive M1 from STA")
- msg, m1_attrs, raw_m1_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M1)
- eap_id = (msg['eap_identifier'] + 1) % 256
- authkey,keywrapkey = wsc_dh_kdf(m1_attrs[ATTR_PUBLIC_KEY], own_private,
- mac_addr, m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce)
- r_s1,r_s2,r_hash1,r_hash2 = wsc_dev_pw_hash(authkey, pin,
- m1_attrs[ATTR_PUBLIC_KEY], e_pk)
- logger.debug("Send M2 to STA")
- m2, raw_m2_attrs = build_m2(authkey, raw_m1_attrs, eap_id,
- m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce, uuid_r, e_pk)
- send_wsc_msg(dev[0], bssid, m2)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M3 from STA")
- msg, m3_attrs, raw_m3_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M3)
- logger.debug("Send M4 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M4)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, m1_attrs[ATTR_ENROLLEE_NONCE])
- attrs += build_wsc_attr(ATTR_R_HASH1, r_hash1)
- attrs += build_wsc_attr(ATTR_R_HASH2, r_hash2)
- data = build_wsc_attr(ATTR_R_SNONCE1, r_s1)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m3_attrs, attrs)
- raw_m4_attrs = attrs
- m4 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m4)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M5 from STA")
- msg, m5_attrs, raw_m5_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M5)
- logger.debug("Send NACK to STA")
- msg, attrs = build_nack(eap_id, m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce, config_error='\x01\x24')
- send_wsc_msg(dev[0], bssid, msg)
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=5)
- if ev is None:
- raise Exception("Failure not reported")
- if "msg=9 config_error=292" not in ev:
- raise Exception("Unexpected failure reason: " + ev)
- def wps_nack_m3(dev, apdev):
- pin = "00000000"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pbc=True)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_r = 16*'\x33'
- r_nonce = 16*'\x44'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Receive M1 from STA")
- msg, m1_attrs, raw_m1_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M1)
- eap_id = (msg['eap_identifier'] + 1) % 256
- authkey,keywrapkey = wsc_dh_kdf(m1_attrs[ATTR_PUBLIC_KEY], own_private,
- mac_addr, m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce)
- r_s1,r_s2,r_hash1,r_hash2 = wsc_dev_pw_hash(authkey, pin,
- m1_attrs[ATTR_PUBLIC_KEY], e_pk)
- logger.debug("Send M2 to STA")
- m2, raw_m2_attrs = build_m2(authkey, raw_m1_attrs, eap_id,
- m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce, uuid_r, e_pk, dev_pw_id='\x00\x04')
- send_wsc_msg(dev[0], bssid, m2)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M3 from STA")
- msg, m3_attrs, raw_m3_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M3)
- return eap_id, m1_attrs[ATTR_ENROLLEE_NONCE], r_nonce, bssid
- def test_wps_ext_proto_nack_m3_no_config_error(dev, apdev):
- """WPS and NACK M3 missing Config Error"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send NACK to STA")
- msg, attrs = build_nack(eap_id, e_nonce, r_nonce, config_error=None)
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_nack_m3_no_e_nonce(dev, apdev):
- """WPS and NACK M3 missing E-Nonce"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send NACK to STA")
- msg, attrs = build_nack(eap_id, None, r_nonce)
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_nack_m3_e_nonce_mismatch(dev, apdev):
- """WPS and NACK M3 E-Nonce mismatch"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send NACK to STA")
- msg, attrs = build_nack(eap_id, 16*'\x00', r_nonce)
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_nack_m3_no_r_nonce(dev, apdev):
- """WPS and NACK M3 missing R-Nonce"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send NACK to STA")
- msg, attrs = build_nack(eap_id, e_nonce, None)
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_nack_m3_r_nonce_mismatch(dev, apdev):
- """WPS and NACK M3 R-Nonce mismatch"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send NACK to STA")
- msg, attrs = build_nack(eap_id, e_nonce, 16*'\x00')
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_nack_m3_no_msg_type(dev, apdev):
- """WPS and NACK M3 no Message Type"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send NACK to STA")
- msg, attrs = build_nack(eap_id, e_nonce, r_nonce, msg_type=None)
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_nack_m3_invalid_msg_type(dev, apdev):
- """WPS and NACK M3 invalid Message Type"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send NACK to STA")
- msg, attrs = build_nack(eap_id, e_nonce, r_nonce, msg_type=123)
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_nack_m3_invalid_attr(dev, apdev):
- """WPS and NACK M3 invalid attribute"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send NACK to STA")
- attrs = '\x10\x10\x00'
- msg = build_eap_wsc(1, eap_id, attrs, opcode=WSC_NACK)
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_ack_m3_no_e_nonce(dev, apdev):
- """WPS and ACK M3 missing E-Nonce"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send NACK to STA")
- msg, attrs = build_ack(eap_id, None, r_nonce)
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_ack_m3_e_nonce_mismatch(dev, apdev):
- """WPS and ACK M3 E-Nonce mismatch"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send NACK to STA")
- msg, attrs = build_ack(eap_id, 16*'\x00', r_nonce)
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_ack_m3_no_r_nonce(dev, apdev):
- """WPS and ACK M3 missing R-Nonce"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send NACK to STA")
- msg, attrs = build_ack(eap_id, e_nonce, None)
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_ack_m3_r_nonce_mismatch(dev, apdev):
- """WPS and ACK M3 R-Nonce mismatch"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send NACK to STA")
- msg, attrs = build_ack(eap_id, e_nonce, 16*'\x00')
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_ack_m3_no_msg_type(dev, apdev):
- """WPS and ACK M3 no Message Type"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send NACK to STA")
- msg, attrs = build_ack(eap_id, e_nonce, r_nonce, msg_type=None)
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_ack_m3_invalid_msg_type(dev, apdev):
- """WPS and ACK M3 invalid Message Type"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send NACK to STA")
- msg, attrs = build_ack(eap_id, e_nonce, r_nonce, msg_type=123)
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_ack_m3_invalid_attr(dev, apdev):
- """WPS and ACK M3 invalid attribute"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send ACK to STA")
- attrs = '\x10\x10\x00'
- msg = build_eap_wsc(1, eap_id, attrs, opcode=WSC_ACK)
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def test_wps_ext_proto_ack_m3(dev, apdev):
- """WPS and ACK M3"""
- eap_id, e_nonce, r_nonce, bssid = wps_nack_m3(dev, apdev)
- logger.debug("Send ACK to STA")
- msg, attrs = build_ack(eap_id, e_nonce, r_nonce)
- send_wsc_msg(dev[0], bssid, msg)
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- dev[0].flush_scan_cache()
- def wps_to_m3_helper(dev, apdev):
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- wps_ext_eap_wsc(dev[0], hapd, bssid, "EAP-WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_r = 16*'\x33'
- r_nonce = 16*'\x44'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Receive M1 from STA")
- msg, m1_attrs, raw_m1_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M1)
- eap_id = (msg['eap_identifier'] + 1) % 256
- authkey,keywrapkey = wsc_dh_kdf(m1_attrs[ATTR_PUBLIC_KEY], own_private,
- mac_addr, m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce)
- r_s1,r_s2,r_hash1,r_hash2 = wsc_dev_pw_hash(authkey, pin,
- m1_attrs[ATTR_PUBLIC_KEY], e_pk)
- logger.debug("Send M2 to STA")
- m2, raw_m2_attrs = build_m2(authkey, raw_m1_attrs, eap_id,
- m1_attrs[ATTR_ENROLLEE_NONCE],
- r_nonce, uuid_r, e_pk)
- send_wsc_msg(dev[0], bssid, m2)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M3 from STA")
- msg, m3_attrs, raw_m3_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M3)
- return eap_id, m1_attrs, r_nonce, bssid, r_hash1, r_hash2, r_s1, r_s2, raw_m3_attrs, authkey, keywrapkey
- def wps_to_m3(dev, apdev):
- eap_id, m1_attrs, r_nonce, bssid, r_hash1, r_hash2, r_s1, r_s2, raw_m3_attrs, authkey, keywrapkey = wps_to_m3_helper(dev, apdev)
- return eap_id, m1_attrs[ATTR_ENROLLEE_NONCE], r_nonce, bssid, r_hash1, r_hash2, r_s1, raw_m3_attrs, authkey, keywrapkey
- def wps_to_m5(dev, apdev):
- eap_id, m1_attrs, r_nonce, bssid, r_hash1, r_hash2, r_s1, r_s2, raw_m3_attrs, authkey, keywrapkey = wps_to_m3_helper(dev, apdev)
- logger.debug("Send M4 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M4)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, m1_attrs[ATTR_ENROLLEE_NONCE])
- attrs += build_wsc_attr(ATTR_R_HASH1, r_hash1)
- attrs += build_wsc_attr(ATTR_R_HASH2, r_hash2)
- data = build_wsc_attr(ATTR_R_SNONCE1, r_s1)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m3_attrs, attrs)
- raw_m4_attrs = attrs
- m4 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m4)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M5 from STA")
- msg, m5_attrs, raw_m5_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M5)
- return eap_id, m1_attrs[ATTR_ENROLLEE_NONCE], r_nonce, bssid, r_hash1, r_hash2, r_s2, raw_m5_attrs, authkey, keywrapkey
- def test_wps_ext_proto_m4_missing_r_hash1(dev, apdev):
- """WPS and no R-Hash1 in M4"""
- eap_id, e_nonce, r_nonce, bssid, r_hash1, r_hash2, r_s1, m3, authkey, keywrapkey = wps_to_m3(dev, apdev)
- logger.debug("Send M4 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M4)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- #attrs += build_wsc_attr(ATTR_R_HASH1, r_hash1)
- attrs += build_wsc_attr(ATTR_R_HASH2, r_hash2)
- data = build_wsc_attr(ATTR_R_SNONCE1, r_s1)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, m3, attrs)
- m4 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m4)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M5 (NACK) from STA")
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_Nack")
- dev[0].request("WPS_CANCEL")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- def test_wps_ext_proto_m4_missing_r_hash2(dev, apdev):
- """WPS and no R-Hash2 in M4"""
- eap_id, e_nonce, r_nonce, bssid, r_hash1, r_hash2, r_s1, m3, authkey, keywrapkey = wps_to_m3(dev, apdev)
- logger.debug("Send M4 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M4)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- attrs += build_wsc_attr(ATTR_R_HASH1, r_hash1)
- #attrs += build_wsc_attr(ATTR_R_HASH2, r_hash2)
- data = build_wsc_attr(ATTR_R_SNONCE1, r_s1)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, m3, attrs)
- m4 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m4)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M5 (NACK) from STA")
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_Nack")
- dev[0].request("WPS_CANCEL")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- def test_wps_ext_proto_m4_missing_r_snonce1(dev, apdev):
- """WPS and no R-SNonce1 in M4"""
- eap_id, e_nonce, r_nonce, bssid, r_hash1, r_hash2, r_s1, m3, authkey, keywrapkey = wps_to_m3(dev, apdev)
- logger.debug("Send M4 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M4)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- attrs += build_wsc_attr(ATTR_R_HASH1, r_hash1)
- attrs += build_wsc_attr(ATTR_R_HASH2, r_hash2)
- #data = build_wsc_attr(ATTR_R_SNONCE1, r_s1)
- data = ''
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, m3, attrs)
- m4 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m4)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M5 (NACK) from STA")
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_Nack")
- dev[0].request("WPS_CANCEL")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- def test_wps_ext_proto_m4_invalid_pad_string(dev, apdev):
- """WPS and invalid pad string in M4"""
- eap_id, e_nonce, r_nonce, bssid, r_hash1, r_hash2, r_s1, m3, authkey, keywrapkey = wps_to_m3(dev, apdev)
- logger.debug("Send M4 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M4)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- attrs += build_wsc_attr(ATTR_R_HASH1, r_hash1)
- attrs += build_wsc_attr(ATTR_R_HASH2, r_hash2)
- data = build_wsc_attr(ATTR_R_SNONCE1, r_s1)
- m = hmac.new(authkey, data, hashlib.sha256)
- kwa = m.digest()[0:8]
- data += build_wsc_attr(ATTR_KEY_WRAP_AUTH, kwa)
- iv = 16*'\x99'
- aes = AES.new(keywrapkey, AES.MODE_CBC, iv)
- pad_len = 16 - len(data) % 16
- ps = (pad_len - 1) * struct.pack('B', pad_len) + struct.pack('B', pad_len - 1)
- data += ps
- wrapped = aes.encrypt(data)
- attrs += build_wsc_attr(ATTR_ENCR_SETTINGS, iv + wrapped)
- attrs += build_attr_authenticator(authkey, m3, attrs)
- m4 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m4)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M5 (NACK) from STA")
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_Nack")
- dev[0].request("WPS_CANCEL")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- def test_wps_ext_proto_m4_invalid_pad_value(dev, apdev):
- """WPS and invalid pad value in M4"""
- eap_id, e_nonce, r_nonce, bssid, r_hash1, r_hash2, r_s1, m3, authkey, keywrapkey = wps_to_m3(dev, apdev)
- logger.debug("Send M4 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M4)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- attrs += build_wsc_attr(ATTR_R_HASH1, r_hash1)
- attrs += build_wsc_attr(ATTR_R_HASH2, r_hash2)
- data = build_wsc_attr(ATTR_R_SNONCE1, r_s1)
- m = hmac.new(authkey, data, hashlib.sha256)
- kwa = m.digest()[0:8]
- data += build_wsc_attr(ATTR_KEY_WRAP_AUTH, kwa)
- iv = 16*'\x99'
- aes = AES.new(keywrapkey, AES.MODE_CBC, iv)
- pad_len = 16 - len(data) % 16
- ps = (pad_len - 1) * struct.pack('B', pad_len) + struct.pack('B', 255)
- data += ps
- wrapped = aes.encrypt(data)
- attrs += build_wsc_attr(ATTR_ENCR_SETTINGS, iv + wrapped)
- attrs += build_attr_authenticator(authkey, m3, attrs)
- m4 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m4)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M5 (NACK) from STA")
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_Nack")
- dev[0].request("WPS_CANCEL")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- def test_wps_ext_proto_m4_no_encr_settings(dev, apdev):
- """WPS and no Encr Settings in M4"""
- eap_id, e_nonce, r_nonce, bssid, r_hash1, r_hash2, r_s1, m3, authkey, keywrapkey = wps_to_m3(dev, apdev)
- logger.debug("Send M4 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M4)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- attrs += build_wsc_attr(ATTR_R_HASH1, r_hash1)
- attrs += build_wsc_attr(ATTR_R_HASH2, r_hash2)
- attrs += build_attr_authenticator(authkey, m3, attrs)
- m4 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m4)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M5 (NACK) from STA")
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_Nack")
- dev[0].request("WPS_CANCEL")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- def test_wps_ext_proto_m6_missing_r_snonce2(dev, apdev):
- """WPS and no R-SNonce2 in M6"""
- eap_id, e_nonce, r_nonce, bssid, r_hash1, r_hash2, r_s2, m5, authkey, keywrapkey = wps_to_m5(dev, apdev)
- logger.debug("Send M6 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M6)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- #data = build_wsc_attr(ATTR_R_SNONCE2, r_s2)
- data = ''
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, m5, attrs)
- m6 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m6)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M7 (NACK) from STA")
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_Nack")
- dev[0].request("WPS_CANCEL")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- def test_wps_ext_proto_m6_no_encr_settings(dev, apdev):
- """WPS and no Encr Settings in M6"""
- eap_id, e_nonce, r_nonce, bssid, r_hash1, r_hash2, r_s2, m5, authkey, keywrapkey = wps_to_m5(dev, apdev)
- logger.debug("Send M6 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M6)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- data = build_wsc_attr(ATTR_R_SNONCE2, r_s2)
- #attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, m5, attrs)
- m6 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m6)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M7 (NACK) from STA")
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_Nack")
- dev[0].request("WPS_CANCEL")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- def test_wps_ext_proto_m8_no_encr_settings(dev, apdev):
- """WPS and no Encr Settings in M6"""
- eap_id, e_nonce, r_nonce, bssid, r_hash1, r_hash2, r_s2, m5, authkey, keywrapkey = wps_to_m5(dev, apdev)
- logger.debug("Send M6 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M6)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- data = build_wsc_attr(ATTR_R_SNONCE2, r_s2)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, m5, attrs)
- raw_m6_attrs = attrs
- m6 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m6)
- eap_id = (eap_id + 1) % 256
- logger.debug("Receive M7 from STA")
- msg, m7_attrs, raw_m7_attrs = recv_wsc_msg(dev[0], WSC_MSG, WPS_M7)
- logger.debug("Send M8 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M8)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- #attrs += build_attr_encr_settings(authkey, keywrapkey, m8_cred)
- attrs += build_attr_authenticator(authkey, raw_m7_attrs, attrs)
- raw_m8_attrs = attrs
- m8 = build_eap_wsc(1, eap_id, attrs)
- send_wsc_msg(dev[0], bssid, m8)
- logger.debug("Receive WSC_Done (NACK) from STA")
- msg = get_wsc_msg(dev[0])
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_Nack")
- dev[0].request("WPS_CANCEL")
- send_wsc_msg(dev[0], bssid, build_eap_failure(eap_id))
- dev[0].wait_disconnected()
- def wps_start_ext_reg(apdev, dev):
- addr = dev.own_addr()
- bssid = apdev['bssid']
- ssid = "test-wps-conf"
- appin = "12345670"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "ap_pin": appin }
- hapd = hostapd.add_ap(apdev, params)
- dev.scan_for_bss(bssid, freq="2412")
- hapd.request("SET ext_eapol_frame_io 1")
- dev.request("SET ext_eapol_frame_io 1")
- dev.request("WPS_REG " + bssid + " " + appin)
- return addr,bssid,hapd
- def wps_run_ap_settings_proto(dev, apdev, ap_settings, success):
- addr,bssid,hapd = wps_start_ext_reg(apdev[0], dev[0])
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive M1 from AP")
- msg, m1_attrs, raw_m1_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M1)
- mac_addr = m1_attrs[ATTR_MAC_ADDR]
- e_nonce = m1_attrs[ATTR_ENROLLEE_NONCE]
- e_pk = m1_attrs[ATTR_PUBLIC_KEY]
- appin = '12345670'
- uuid_r = 16*'\x33'
- r_nonce = 16*'\x44'
- own_private, r_pk = wsc_dh_init()
- authkey,keywrapkey = wsc_dh_kdf(e_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- r_s1,r_s2,r_hash1,r_hash2 = wsc_dev_pw_hash(authkey, appin, e_pk, r_pk)
- logger.debug("Send M2 to AP")
- m2, raw_m2_attrs = build_m2(authkey, raw_m1_attrs, msg['eap_identifier'],
- e_nonce, r_nonce, uuid_r, r_pk, eap_code=2)
- send_wsc_msg(hapd, addr, m2)
- logger.debug("Receive M3 from AP")
- msg, m3_attrs, raw_m3_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M3)
- logger.debug("Send M4 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M4)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- attrs += build_wsc_attr(ATTR_R_HASH1, r_hash1)
- attrs += build_wsc_attr(ATTR_R_HASH2, r_hash2)
- data = build_wsc_attr(ATTR_R_SNONCE1, r_s1)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m3_attrs, attrs)
- raw_m4_attrs = attrs
- m4 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m4)
- logger.debug("Receive M5 from AP")
- msg, m5_attrs, raw_m5_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M5)
- logger.debug("Send M6 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M6)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- data = build_wsc_attr(ATTR_R_SNONCE2, r_s2)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m5_attrs, attrs)
- raw_m6_attrs = attrs
- m6 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m6)
- logger.debug("Receive M7 from AP")
- msg, m7_attrs, raw_m7_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M7)
- logger.debug("Send M8 to STA")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M8)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- if ap_settings:
- attrs += build_attr_encr_settings(authkey, keywrapkey, ap_settings)
- attrs += build_attr_authenticator(authkey, raw_m7_attrs, attrs)
- raw_m8_attrs = attrs
- m8 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m8)
- if success:
- ev = hapd.wait_event(["WPS-NEW-AP-SETTINGS"], timeout=5)
- if ev is None:
- raise Exception("New AP settings not reported")
- logger.debug("Receive WSC_Done from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Done:
- raise Exception("Unexpected message - expected WSC_Done")
- logger.debug("Send WSC_ACK to AP")
- ack,attrs = build_ack(msg['eap_identifier'], e_nonce, r_nonce,
- eap_code=2)
- send_wsc_msg(hapd, addr, ack)
- dev[0].wait_disconnected()
- else:
- ev = hapd.wait_event(["WPS-FAIL"], timeout=5)
- if ev is None:
- raise Exception("WPS failure not reported")
- logger.debug("Receive WSC_NACK from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_NACK")
- logger.debug("Send WSC_NACK to AP")
- nack,attrs = build_nack(msg['eap_identifier'], e_nonce, r_nonce,
- eap_code=2)
- send_wsc_msg(hapd, addr, nack)
- dev[0].wait_disconnected()
- def test_wps_ext_ap_settings_success(dev, apdev):
- """WPS and AP Settings: success"""
- ap_settings = build_wsc_attr(ATTR_NETWORK_INDEX, '\x01')
- ap_settings += build_wsc_attr(ATTR_SSID, "test")
- ap_settings += build_wsc_attr(ATTR_AUTH_TYPE, '\x00\x01')
- ap_settings += build_wsc_attr(ATTR_ENCR_TYPE, '\x00\x01')
- ap_settings += build_wsc_attr(ATTR_NETWORK_KEY, '')
- ap_settings += build_wsc_attr(ATTR_MAC_ADDR, binascii.unhexlify(apdev[0]['bssid'].replace(':', '')))
- wps_run_ap_settings_proto(dev, apdev, ap_settings, True)
- @remote_compatible
- def test_wps_ext_ap_settings_missing(dev, apdev):
- """WPS and AP Settings: missing"""
- wps_run_ap_settings_proto(dev, apdev, None, False)
- @remote_compatible
- def test_wps_ext_ap_settings_mac_addr_mismatch(dev, apdev):
- """WPS and AP Settings: MAC Address mismatch"""
- ap_settings = build_wsc_attr(ATTR_NETWORK_INDEX, '\x01')
- ap_settings += build_wsc_attr(ATTR_SSID, "test")
- ap_settings += build_wsc_attr(ATTR_AUTH_TYPE, '\x00\x01')
- ap_settings += build_wsc_attr(ATTR_ENCR_TYPE, '\x00\x01')
- ap_settings += build_wsc_attr(ATTR_NETWORK_KEY, '')
- ap_settings += build_wsc_attr(ATTR_MAC_ADDR, '\x00\x00\x00\x00\x00\x00')
- wps_run_ap_settings_proto(dev, apdev, ap_settings, True)
- @remote_compatible
- def test_wps_ext_ap_settings_mac_addr_missing(dev, apdev):
- """WPS and AP Settings: missing MAC Address"""
- ap_settings = build_wsc_attr(ATTR_NETWORK_INDEX, '\x01')
- ap_settings += build_wsc_attr(ATTR_SSID, "test")
- ap_settings += build_wsc_attr(ATTR_AUTH_TYPE, '\x00\x01')
- ap_settings += build_wsc_attr(ATTR_ENCR_TYPE, '\x00\x01')
- ap_settings += build_wsc_attr(ATTR_NETWORK_KEY, '')
- wps_run_ap_settings_proto(dev, apdev, ap_settings, False)
- @remote_compatible
- def test_wps_ext_ap_settings_reject_encr_type(dev, apdev):
- """WPS and AP Settings: reject Encr Type"""
- ap_settings = build_wsc_attr(ATTR_NETWORK_INDEX, '\x01')
- ap_settings += build_wsc_attr(ATTR_SSID, "test")
- ap_settings += build_wsc_attr(ATTR_AUTH_TYPE, '\x00\x01')
- ap_settings += build_wsc_attr(ATTR_ENCR_TYPE, '\x00\x00')
- ap_settings += build_wsc_attr(ATTR_NETWORK_KEY, '')
- ap_settings += build_wsc_attr(ATTR_MAC_ADDR, binascii.unhexlify(apdev[0]['bssid'].replace(':', '')))
- wps_run_ap_settings_proto(dev, apdev, ap_settings, False)
- @remote_compatible
- def test_wps_ext_ap_settings_m2d(dev, apdev):
- """WPS and AP Settings: M2D"""
- addr,bssid,hapd = wps_start_ext_reg(apdev[0], dev[0])
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive M1 from AP")
- msg, m1_attrs, raw_m1_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M1)
- e_nonce = m1_attrs[ATTR_ENROLLEE_NONCE]
- r_nonce = 16*'\x44'
- uuid_r = 16*'\x33'
- logger.debug("Send M2D to AP")
- m2d, raw_m2d_attrs = build_m2d(raw_m1_attrs, msg['eap_identifier'],
- e_nonce, r_nonce, uuid_r,
- dev_pw_id='\x00\x00', eap_code=2)
- send_wsc_msg(hapd, addr, m2d)
- ev = hapd.wait_event(["WPS-M2D"], timeout=5)
- if ev is None:
- raise Exception("M2D not reported")
- wps_wait_ap_nack(hapd, dev[0], e_nonce, r_nonce)
- def wps_wait_ap_nack(hapd, dev, e_nonce, r_nonce):
- logger.debug("Receive WSC_NACK from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_NACK:
- raise Exception("Unexpected message - expected WSC_NACK")
- logger.debug("Send WSC_NACK to AP")
- nack,attrs = build_nack(msg['eap_identifier'], e_nonce, r_nonce,
- eap_code=2)
- send_wsc_msg(hapd, dev.own_addr(), nack)
- dev.wait_disconnected()
- @remote_compatible
- def test_wps_ext_m3_missing_e_hash1(dev, apdev):
- """WPS proto: M3 missing E-Hash1"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send M3 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M3)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- #attrs += build_wsc_attr(ATTR_E_HASH1, e_hash1)
- attrs += build_wsc_attr(ATTR_E_HASH2, e_hash2)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m3)
- wps_wait_ap_nack(hapd, dev[0], e_nonce, r_nonce)
- @remote_compatible
- def test_wps_ext_m3_missing_e_hash2(dev, apdev):
- """WPS proto: M3 missing E-Hash2"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send M3 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M3)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- attrs += build_wsc_attr(ATTR_E_HASH1, e_hash1)
- #attrs += build_wsc_attr(ATTR_E_HASH2, e_hash2)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m3)
- wps_wait_ap_nack(hapd, dev[0], e_nonce, r_nonce)
- @remote_compatible
- def test_wps_ext_m5_missing_e_snonce1(dev, apdev):
- """WPS proto: M5 missing E-SNonce1"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send M3 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M3)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- attrs += build_wsc_attr(ATTR_E_HASH1, e_hash1)
- attrs += build_wsc_attr(ATTR_E_HASH2, e_hash2)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m3)
- logger.debug("Receive M4 from AP")
- msg, m4_attrs, raw_m4_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M4)
- logger.debug("Send M5 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M5)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- #data = build_wsc_attr(ATTR_E_SNONCE1, e_s1)
- data = ''
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m4_attrs, attrs)
- raw_m5_attrs = attrs
- m5 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m5)
- wps_wait_ap_nack(hapd, dev[0], e_nonce, r_nonce)
- @remote_compatible
- def test_wps_ext_m5_e_snonce1_mismatch(dev, apdev):
- """WPS proto: M5 E-SNonce1 mismatch"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send M3 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M3)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- attrs += build_wsc_attr(ATTR_E_HASH1, e_hash1)
- attrs += build_wsc_attr(ATTR_E_HASH2, e_hash2)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m3)
- logger.debug("Receive M4 from AP")
- msg, m4_attrs, raw_m4_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M4)
- logger.debug("Send M5 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M5)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- data = build_wsc_attr(ATTR_E_SNONCE1, 16*'\x00')
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m4_attrs, attrs)
- raw_m5_attrs = attrs
- m5 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m5)
- wps_wait_ap_nack(hapd, dev[0], e_nonce, r_nonce)
- def test_wps_ext_m7_missing_e_snonce2(dev, apdev):
- """WPS proto: M7 missing E-SNonce2"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send M3 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M3)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- attrs += build_wsc_attr(ATTR_E_HASH1, e_hash1)
- attrs += build_wsc_attr(ATTR_E_HASH2, e_hash2)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m3)
- logger.debug("Receive M4 from AP")
- msg, m4_attrs, raw_m4_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M4)
- logger.debug("Send M5 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M5)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- data = build_wsc_attr(ATTR_E_SNONCE1, e_s1)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m4_attrs, attrs)
- raw_m5_attrs = attrs
- m5 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m5)
- logger.debug("Receive M6 from AP")
- msg, m6_attrs, raw_m6_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M6)
- logger.debug("Send M7 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M7)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- #data = build_wsc_attr(ATTR_E_SNONCE2, e_s2)
- data = ''
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m6_attrs, attrs)
- m7 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- raw_m7_attrs = attrs
- send_wsc_msg(hapd, addr, m7)
- wps_wait_ap_nack(hapd, dev[0], e_nonce, r_nonce)
- @remote_compatible
- def test_wps_ext_m7_e_snonce2_mismatch(dev, apdev):
- """WPS proto: M7 E-SNonce2 mismatch"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send M3 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M3)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- attrs += build_wsc_attr(ATTR_E_HASH1, e_hash1)
- attrs += build_wsc_attr(ATTR_E_HASH2, e_hash2)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m3)
- logger.debug("Receive M4 from AP")
- msg, m4_attrs, raw_m4_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M4)
- logger.debug("Send M5 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M5)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- data = build_wsc_attr(ATTR_E_SNONCE1, e_s1)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m4_attrs, attrs)
- raw_m5_attrs = attrs
- m5 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m5)
- logger.debug("Receive M6 from AP")
- msg, m6_attrs, raw_m6_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M6)
- logger.debug("Send M7 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M7)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- data = build_wsc_attr(ATTR_E_SNONCE2, 16*'\x00')
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m6_attrs, attrs)
- m7 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- raw_m7_attrs = attrs
- send_wsc_msg(hapd, addr, m7)
- wps_wait_ap_nack(hapd, dev[0], e_nonce, r_nonce)
- @remote_compatible
- def test_wps_ext_m1_pubkey_oom(dev, apdev):
- """WPS proto: M1 PubKey OOM"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- with alloc_fail(hapd, 1, "wpabuf_alloc_copy;wps_process_pubkey"):
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- wps_wait_eap_failure(hapd, dev[0])
- def wps_wait_eap_failure(hapd, dev):
- ev = hapd.wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=5)
- if ev is None:
- raise Exception("EAP-Failure not reported")
- dev.wait_disconnected()
- @remote_compatible
- def test_wps_ext_m3_m1(dev, apdev):
- """WPS proto: M3 replaced with M1"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send M3(M1) to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M1)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- attrs += build_wsc_attr(ATTR_E_HASH1, e_hash1)
- attrs += build_wsc_attr(ATTR_E_HASH2, e_hash2)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m3)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_m5_m3(dev, apdev):
- """WPS proto: M5 replaced with M3"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send M3 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M3)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- attrs += build_wsc_attr(ATTR_E_HASH1, e_hash1)
- attrs += build_wsc_attr(ATTR_E_HASH2, e_hash2)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m3)
- logger.debug("Receive M4 from AP")
- msg, m4_attrs, raw_m4_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M4)
- logger.debug("Send M5(M3) to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M3)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- data = build_wsc_attr(ATTR_E_SNONCE1, e_s1)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m4_attrs, attrs)
- raw_m5_attrs = attrs
- m5 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m5)
- wps_wait_ap_nack(hapd, dev[0], e_nonce, r_nonce)
- @remote_compatible
- def test_wps_ext_m3_m2(dev, apdev):
- """WPS proto: M3 replaced with M2"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send M3(M2) to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M2)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m3)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_m3_m5(dev, apdev):
- """WPS proto: M3 replaced with M5"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send M3(M5) to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M5)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- attrs += build_wsc_attr(ATTR_E_HASH1, e_hash1)
- attrs += build_wsc_attr(ATTR_E_HASH2, e_hash2)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m3)
- wps_wait_ap_nack(hapd, dev[0], e_nonce, r_nonce)
- @remote_compatible
- def test_wps_ext_m3_m7(dev, apdev):
- """WPS proto: M3 replaced with M7"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send M3(M7) to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M7)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- attrs += build_wsc_attr(ATTR_E_HASH1, e_hash1)
- attrs += build_wsc_attr(ATTR_E_HASH2, e_hash2)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m3)
- wps_wait_ap_nack(hapd, dev[0], e_nonce, r_nonce)
- @remote_compatible
- def test_wps_ext_m3_done(dev, apdev):
- """WPS proto: M3 replaced with WSC_Done"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send M3(WSC_Done) to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_WSC_DONE)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs, opcode=WSC_Done)
- send_wsc_msg(hapd, addr, m3)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_m2_nack_invalid(dev, apdev):
- """WPS proto: M2 followed by invalid NACK"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send WSC_NACK to AP")
- attrs = '\x10\x00\x00'
- nack = build_eap_wsc(2, msg['eap_identifier'], attrs, opcode=WSC_NACK)
- send_wsc_msg(hapd, addr, nack)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_m2_nack_no_msg_type(dev, apdev):
- """WPS proto: M2 followed by NACK without Msg Type"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send WSC_NACK to AP")
- nack,attrs = build_nack(msg['eap_identifier'], e_nonce, r_nonce,
- msg_type=None, eap_code=2)
- send_wsc_msg(hapd, addr, nack)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_m2_nack_invalid_msg_type(dev, apdev):
- """WPS proto: M2 followed by NACK with invalid Msg Type"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send WSC_NACK to AP")
- nack,attrs = build_nack(msg['eap_identifier'], e_nonce, r_nonce,
- msg_type=WPS_WSC_ACK, eap_code=2)
- send_wsc_msg(hapd, addr, nack)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_m2_nack_e_nonce_mismatch(dev, apdev):
- """WPS proto: M2 followed by NACK with e-nonce mismatch"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send WSC_NACK to AP")
- nack,attrs = build_nack(msg['eap_identifier'], 16*'\x00', r_nonce,
- eap_code=2)
- send_wsc_msg(hapd, addr, nack)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_m2_nack_no_config_error(dev, apdev):
- """WPS proto: M2 followed by NACK without Config Error"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send WSC_NACK to AP")
- nack,attrs = build_nack(msg['eap_identifier'], e_nonce, r_nonce,
- config_error=None, eap_code=2)
- send_wsc_msg(hapd, addr, nack)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_m2_ack_invalid(dev, apdev):
- """WPS proto: M2 followed by invalid ACK"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send WSC_ACK to AP")
- attrs = '\x10\x00\x00'
- ack = build_eap_wsc(2, msg['eap_identifier'], attrs, opcode=WSC_ACK)
- send_wsc_msg(hapd, addr, ack)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_m2_ack(dev, apdev):
- """WPS proto: M2 followed by ACK"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send WSC_ACK to AP")
- ack,attrs = build_ack(msg['eap_identifier'], e_nonce, r_nonce, eap_code=2)
- send_wsc_msg(hapd, addr, ack)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_m2_ack_no_msg_type(dev, apdev):
- """WPS proto: M2 followed by ACK missing Msg Type"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send WSC_ACK to AP")
- ack,attrs = build_ack(msg['eap_identifier'], e_nonce, r_nonce,
- msg_type=None, eap_code=2)
- send_wsc_msg(hapd, addr, ack)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_m2_ack_invalid_msg_type(dev, apdev):
- """WPS proto: M2 followed by ACK with invalid Msg Type"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send WSC_ACK to AP")
- ack,attrs = build_ack(msg['eap_identifier'], e_nonce, r_nonce,
- msg_type=WPS_WSC_NACK, eap_code=2)
- send_wsc_msg(hapd, addr, ack)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_m2_ack_e_nonce_mismatch(dev, apdev):
- """WPS proto: M2 followed by ACK with e-nonce mismatch"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send WSC_ACK to AP")
- ack,attrs = build_ack(msg['eap_identifier'], 16*'\x00', r_nonce,
- eap_code=2)
- send_wsc_msg(hapd, addr, ack)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_m1_invalid(dev, apdev):
- """WPS proto: M1 failing parsing"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- logger.debug("Send M1 to AP")
- attrs = '\x10\x00\x00'
- m1 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m1)
- wps_wait_eap_failure(hapd, dev[0])
- def test_wps_ext_m1_missing_msg_type(dev, apdev):
- """WPS proto: M1 missing Msg Type"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- logger.debug("Send M1 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- m1 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m1)
- wps_wait_ap_nack(hapd, dev[0], 16*'\x00', 16*'\x00')
- def wps_ext_wsc_done(dev, apdev):
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send M3 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M3)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- attrs += build_wsc_attr(ATTR_E_HASH1, e_hash1)
- attrs += build_wsc_attr(ATTR_E_HASH2, e_hash2)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m3)
- logger.debug("Receive M4 from AP")
- msg, m4_attrs, raw_m4_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M4)
- logger.debug("Send M5 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M5)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- data = build_wsc_attr(ATTR_E_SNONCE1, e_s1)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m4_attrs, attrs)
- raw_m5_attrs = attrs
- m5 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m5)
- logger.debug("Receive M6 from AP")
- msg, m6_attrs, raw_m6_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M6)
- logger.debug("Send M7 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M7)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- data = build_wsc_attr(ATTR_E_SNONCE2, e_s2)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m6_attrs, attrs)
- m7 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- raw_m7_attrs = attrs
- send_wsc_msg(hapd, addr, m7)
- logger.debug("Receive M8 from AP")
- msg, m8_attrs, raw_m8_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M8)
- return hapd, msg, e_nonce, r_nonce
- @remote_compatible
- def test_wps_ext_wsc_done_invalid(dev, apdev):
- """WPS proto: invalid WSC_Done"""
- hapd, msg, e_nonce, r_nonce = wps_ext_wsc_done(dev, apdev)
- logger.debug("Send WSC_Done to AP")
- attrs = '\x10\x00\x00'
- wsc_done = build_eap_wsc(2, msg['eap_identifier'], attrs, opcode=WSC_Done)
- send_wsc_msg(hapd, dev[0].own_addr(), wsc_done)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_wsc_done_no_msg_type(dev, apdev):
- """WPS proto: invalid WSC_Done"""
- hapd, msg, e_nonce, r_nonce = wps_ext_wsc_done(dev, apdev)
- logger.debug("Send WSC_Done to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- #attrs += build_attr_msg_type(WPS_WSC_DONE)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- wsc_done = build_eap_wsc(2, msg['eap_identifier'], attrs, opcode=WSC_Done)
- send_wsc_msg(hapd, dev[0].own_addr(), wsc_done)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_wsc_done_wrong_msg_type(dev, apdev):
- """WPS proto: WSC_Done with wrong Msg Type"""
- hapd, msg, e_nonce, r_nonce = wps_ext_wsc_done(dev, apdev)
- logger.debug("Send WSC_Done to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_WSC_ACK)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- wsc_done = build_eap_wsc(2, msg['eap_identifier'], attrs, opcode=WSC_Done)
- send_wsc_msg(hapd, dev[0].own_addr(), wsc_done)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_wsc_done_no_e_nonce(dev, apdev):
- """WPS proto: WSC_Done without e_nonce"""
- hapd, msg, e_nonce, r_nonce = wps_ext_wsc_done(dev, apdev)
- logger.debug("Send WSC_Done to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_WSC_DONE)
- #attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- wsc_done = build_eap_wsc(2, msg['eap_identifier'], attrs, opcode=WSC_Done)
- send_wsc_msg(hapd, dev[0].own_addr(), wsc_done)
- wps_wait_eap_failure(hapd, dev[0])
- def test_wps_ext_wsc_done_no_r_nonce(dev, apdev):
- """WPS proto: WSC_Done without r_nonce"""
- hapd, msg, e_nonce, r_nonce = wps_ext_wsc_done(dev, apdev)
- logger.debug("Send WSC_Done to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_WSC_DONE)
- attrs += build_wsc_attr(ATTR_ENROLLEE_NONCE, e_nonce)
- #attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- wsc_done = build_eap_wsc(2, msg['eap_identifier'], attrs, opcode=WSC_Done)
- send_wsc_msg(hapd, dev[0].own_addr(), wsc_done)
- wps_wait_eap_failure(hapd, dev[0])
- @remote_compatible
- def test_wps_ext_m7_no_encr_settings(dev, apdev):
- """WPS proto: M7 without Encr Settings"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk)
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- r_nonce = m2_attrs[ATTR_REGISTRAR_NONCE]
- r_pk = m2_attrs[ATTR_PUBLIC_KEY]
- authkey,keywrapkey = wsc_dh_kdf(r_pk, own_private, mac_addr, e_nonce,
- r_nonce)
- e_s1,e_s2,e_hash1,e_hash2 = wsc_dev_pw_hash(authkey, pin, e_pk, r_pk)
- logger.debug("Send M3 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M3)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- attrs += build_wsc_attr(ATTR_E_HASH1, e_hash1)
- attrs += build_wsc_attr(ATTR_E_HASH2, e_hash2)
- attrs += build_attr_authenticator(authkey, raw_m2_attrs, attrs)
- raw_m3_attrs = attrs
- m3 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m3)
- logger.debug("Receive M4 from AP")
- msg, m4_attrs, raw_m4_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M4)
- logger.debug("Send M5 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M5)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- data = build_wsc_attr(ATTR_E_SNONCE1, e_s1)
- attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m4_attrs, attrs)
- raw_m5_attrs = attrs
- m5 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- send_wsc_msg(hapd, addr, m5)
- logger.debug("Receive M6 from AP")
- msg, m6_attrs, raw_m6_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M6)
- logger.debug("Send M7 to AP")
- attrs = build_wsc_attr(ATTR_VERSION, '\x10')
- attrs += build_attr_msg_type(WPS_M7)
- attrs += build_wsc_attr(ATTR_REGISTRAR_NONCE, r_nonce)
- #data = build_wsc_attr(ATTR_E_SNONCE2, e_s2)
- #attrs += build_attr_encr_settings(authkey, keywrapkey, data)
- attrs += build_attr_authenticator(authkey, raw_m6_attrs, attrs)
- m7 = build_eap_wsc(2, msg['eap_identifier'], attrs)
- raw_m7_attrs = attrs
- send_wsc_msg(hapd, addr, m7)
- wps_wait_ap_nack(hapd, dev[0], e_nonce, r_nonce)
- @remote_compatible
- def test_wps_ext_m1_workaround(dev, apdev):
- """WPS proto: M1 Manufacturer/Model workaround"""
- pin = "12345670"
- addr,bssid,hapd = wps_start_ext(apdev[0], dev[0], pin=pin)
- wps_ext_eap_identity_req(dev[0], hapd, bssid)
- wps_ext_eap_identity_resp(hapd, dev[0], addr)
- logger.debug("Receive WSC/Start from AP")
- msg = get_wsc_msg(hapd)
- if msg['wsc_opcode'] != WSC_Start:
- raise Exception("Unexpected Op-Code for WSC/Start")
- mac_addr = binascii.unhexlify(dev[0].own_addr().replace(':', ''))
- uuid_e = 16*'\x11'
- e_nonce = 16*'\x22'
- own_private, e_pk = wsc_dh_init()
- logger.debug("Send M1 to AP")
- m1, raw_m1_attrs = build_m1(msg['eap_identifier'], uuid_e, mac_addr,
- e_nonce, e_pk, manufacturer='Apple TEST',
- model_name='AirPort', config_methods='\xff\xff')
- send_wsc_msg(hapd, addr, m1)
- logger.debug("Receive M2 from AP")
- msg, m2_attrs, raw_m2_attrs = recv_wsc_msg(hapd, WSC_MSG, WPS_M2)
- @remote_compatible
- def test_ap_wps_disable_enable(dev, apdev):
- """WPS and DISABLE/ENABLE AP"""
- hapd = wps_start_ap(apdev[0])
- hapd.disable()
- hapd.enable()
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- def test_ap_wps_upnp_web_oom(dev, apdev, params):
- """hostapd WPS UPnP web OOM"""
- ap_uuid = "27ea801a-9e5c-4e73-bd82-f89cbcd10d7e"
- hapd = add_ssdp_ap(apdev[0], ap_uuid)
- location = ssdp_get_location(ap_uuid)
- url = urlparse.urlparse(location)
- urls = upnp_get_urls(location)
- eventurl = urlparse.urlparse(urls['event_sub_url'])
- ctrlurl = urlparse.urlparse(urls['control_url'])
- conn = httplib.HTTPConnection(url.netloc)
- with alloc_fail(hapd, 1, "web_connection_parse_get"):
- conn.request("GET", "/wps_device.xml")
- try:
- resp = conn.getresponse()
- except:
- pass
- conn = httplib.HTTPConnection(url.netloc)
- conn.request("GET", "/unknown")
- resp = conn.getresponse()
- if resp.status != 404:
- raise Exception("Unexpected HTTP result for unknown URL: %d" + resp.status)
- with alloc_fail(hapd, 1, "web_connection_parse_get"):
- conn.request("GET", "/unknown")
- try:
- resp = conn.getresponse()
- print resp.status
- except:
- pass
- conn = httplib.HTTPConnection(url.netloc)
- conn.request("GET", "/wps_device.xml")
- resp = conn.getresponse()
- if resp.status != 200:
- raise Exception("GET /wps_device.xml failed")
- conn = httplib.HTTPConnection(url.netloc)
- resp = upnp_soap_action(conn, ctrlurl.path, "GetDeviceInfo")
- if resp.status != 200:
- raise Exception("GetDeviceInfo failed")
- with alloc_fail(hapd, 1, "web_process_get_device_info"):
- conn = httplib.HTTPConnection(url.netloc)
- resp = upnp_soap_action(conn, ctrlurl.path, "GetDeviceInfo")
- if resp.status != 500:
- raise Exception("Internal error not reported from GetDeviceInfo OOM")
- with alloc_fail(hapd, 1, "wps_build_m1;web_process_get_device_info"):
- conn = httplib.HTTPConnection(url.netloc)
- resp = upnp_soap_action(conn, ctrlurl.path, "GetDeviceInfo")
- if resp.status != 500:
- raise Exception("Internal error not reported from GetDeviceInfo OOM")
- with alloc_fail(hapd, 1, "wpabuf_alloc;web_connection_send_reply"):
- conn = httplib.HTTPConnection(url.netloc)
- try:
- resp = upnp_soap_action(conn, ctrlurl.path, "GetDeviceInfo")
- except:
- pass
- conn = httplib.HTTPConnection(url.netloc)
- resp = upnp_soap_action(conn, ctrlurl.path, "GetDeviceInfo")
- if resp.status != 200:
- raise Exception("GetDeviceInfo failed")
- # No NewWLANEventType in PutWLANResponse NewMessage
- conn = httplib.HTTPConnection(url.netloc)
- resp = upnp_soap_action(conn, ctrlurl.path, "PutWLANResponse", newmsg="foo")
- if resp.status != 600:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- # No NewWLANEventMAC in PutWLANResponse NewMessage
- conn = httplib.HTTPConnection(url.netloc)
- resp = upnp_soap_action(conn, ctrlurl.path, "PutWLANResponse",
- newmsg="foo", neweventtype="1")
- if resp.status != 600:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- # Invalid NewWLANEventMAC in PutWLANResponse NewMessage
- conn = httplib.HTTPConnection(url.netloc)
- resp = upnp_soap_action(conn, ctrlurl.path, "PutWLANResponse",
- newmsg="foo", neweventtype="1",
- neweventmac="foo")
- if resp.status != 600:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- # Workaround for NewWLANEventMAC in PutWLANResponse NewMessage
- # Ignored unexpected PutWLANResponse WLANEventType 1
- conn = httplib.HTTPConnection(url.netloc)
- resp = upnp_soap_action(conn, ctrlurl.path, "PutWLANResponse",
- newmsg="foo", neweventtype="1",
- neweventmac="00.11.22.33.44.55")
- if resp.status != 500:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- # PutWLANResponse NewMessage with invalid EAP message
- conn = httplib.HTTPConnection(url.netloc)
- resp = upnp_soap_action(conn, ctrlurl.path, "PutWLANResponse",
- newmsg="foo", neweventtype="2",
- neweventmac="00:11:22:33:44:55")
- if resp.status != 200:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- with alloc_fail(hapd, 1, "web_connection_parse_subscribe"):
- conn = httplib.HTTPConnection(url.netloc)
- headers = { "callback": '<http://127.0.0.1:12345/event>',
- "NT": "upnp:event",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- try:
- resp = conn.getresponse()
- except:
- pass
- with alloc_fail(hapd, 1, "dup_binstr;web_connection_parse_subscribe"):
- conn = httplib.HTTPConnection(url.netloc)
- headers = { "callback": '<http://127.0.0.1:12345/event>',
- "NT": "upnp:event",
- "timeout": "Second-1234" }
- conn.request("SUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- resp = conn.getresponse()
- if resp.status != 500:
- raise Exception("Unexpected HTTP response: %d" % resp.status)
- with alloc_fail(hapd, 1, "wpabuf_alloc;web_connection_parse_unsubscribe"):
- conn = httplib.HTTPConnection(url.netloc)
- headers = { "callback": '<http://127.0.0.1:12345/event>',
- "NT": "upnp:event",
- "timeout": "Second-1234" }
- conn.request("UNSUBSCRIBE", eventurl.path, "\r\n\r\n", headers)
- try:
- resp = conn.getresponse()
- except:
- pass
- with alloc_fail(hapd, 1, "web_connection_unimplemented"):
- conn = httplib.HTTPConnection(url.netloc)
- conn.request("HEAD", "/wps_device.xml")
- try:
- resp = conn.getresponse()
- except:
- pass
- def test_ap_wps_frag_ack_oom(dev, apdev):
- """WPS and fragment ack OOM"""
- dev[0].request("SET wps_fragment_size 50")
- hapd = wps_start_ap(apdev[0])
- with alloc_fail(hapd, 1, "eap_wsc_build_frag_ack"):
- wps_run_pbc_fail_ap(apdev[0], dev[0], hapd)
- def wait_scan_stopped(dev):
- dev.request("ABORT_SCAN")
- for i in range(50):
- res = dev.get_driver_status_field("scan_state")
- if "SCAN_STARTED" not in res and "SCAN_REQUESTED" not in res:
- break
- logger.debug("Waiting for scan to complete")
- time.sleep(0.1)
- @remote_compatible
- def test_ap_wps_eap_wsc_errors(dev, apdev):
- """WPS and EAP-WSC error cases"""
- ssid = "test-wps-conf-pin"
- appin = "12345670"
- params = { "ssid": ssid, "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP",
- "fragment_size": "300", "ap_pin": appin }
- hapd = hostapd.add_ap(apdev[0], params)
- bssid = apdev[0]['bssid']
- pin = dev[0].wps_read_pin()
- hapd.request("WPS_PIN any " + pin)
- dev[0].scan_for_bss(apdev[0]['bssid'], freq="2412")
- dev[0].dump_monitor()
- dev[0].wps_reg(bssid, appin + " new_ssid=a", "new ssid", "WPA2PSK", "CCMP",
- "new passphrase", no_wait=True)
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=10)
- if ev is None:
- raise Exception("WPS-FAIL not reported")
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- wait_scan_stopped(dev[0])
- dev[0].dump_monitor()
- dev[0].wps_reg(bssid, appin, "new ssid", "FOO", "CCMP",
- "new passphrase", no_wait=True)
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=10)
- if ev is None:
- raise Exception("WPS-FAIL not reported")
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- wait_scan_stopped(dev[0])
- dev[0].dump_monitor()
- dev[0].wps_reg(bssid, appin, "new ssid", "WPA2PSK", "FOO",
- "new passphrase", no_wait=True)
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=10)
- if ev is None:
- raise Exception("WPS-FAIL not reported")
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- wait_scan_stopped(dev[0])
- dev[0].dump_monitor()
- dev[0].wps_reg(bssid, appin + "new_key=a", "new ssid", "WPA2PSK", "CCMP",
- "new passphrase", no_wait=True)
- ev = dev[0].wait_event(["WPS-FAIL"], timeout=10)
- if ev is None:
- raise Exception("WPS-FAIL not reported")
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- wait_scan_stopped(dev[0])
- dev[0].dump_monitor()
- tests = [ "eap_wsc_init",
- "eap_msg_alloc;eap_wsc_build_msg",
- "wpabuf_alloc;eap_wsc_process_fragment" ]
- for func in tests:
- with alloc_fail(dev[0], 1, func):
- dev[0].request("WPS_PIN %s %s" % (bssid, pin))
- wait_fail_trigger(dev[0], "GET_ALLOC_FAIL")
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- wait_scan_stopped(dev[0])
- dev[0].dump_monitor()
- with alloc_fail(dev[0], 1, "eap_msg_alloc;eap_sm_build_expanded_nak"):
- dev[0].wps_reg(bssid, appin + " new_ssid=a", "new ssid", "WPA2PSK",
- "CCMP", "new passphrase", no_wait=True)
- wait_fail_trigger(dev[0], "GET_ALLOC_FAIL")
- dev[0].request("WPS_CANCEL")
- dev[0].wait_disconnected()
- wait_scan_stopped(dev[0])
- dev[0].dump_monitor()
- def test_ap_wps_eap_wsc(dev, apdev):
- """WPS and EAP-WSC in network profile"""
- params = int_eap_server_params()
- params["wps_state"] = "2"
- hapd = hostapd.add_ap(apdev[0], params)
- bssid = apdev[0]['bssid']
- logger.info("Unexpected identity")
- dev[0].connect("test-wpa2-eap", key_mgmt="WPA-EAP", scan_freq="2412",
- eap="WSC", identity="WFA-SimpleConfig-Enrollee-unexpected",
- wait_connect=False)
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=5)
- if ev is None:
- raise Exception("No EAP-Failure seen")
- dev[0].request("REMOVE_NETWORK all")
- dev[0].wait_disconnected()
- logger.info("No phase1 parameter")
- dev[0].connect("test-wpa2-eap", key_mgmt="WPA-EAP", scan_freq="2412",
- eap="WSC", identity="WFA-SimpleConfig-Enrollee-1-0",
- wait_connect=False)
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-PROPOSED-METHOD"], timeout=5)
- if ev is None:
- raise Exception("Timeout on EAP method start")
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=5)
- if ev is None:
- raise Exception("No EAP-Failure seen")
- dev[0].request("REMOVE_NETWORK all")
- dev[0].wait_disconnected()
- logger.info("No PIN/PBC in phase1")
- dev[0].connect("test-wpa2-eap", key_mgmt="WPA-EAP", scan_freq="2412",
- eap="WSC", identity="WFA-SimpleConfig-Enrollee-1-0",
- phase1="foo", wait_connect=False)
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-PROPOSED-METHOD"], timeout=5)
- if ev is None:
- raise Exception("Timeout on EAP method start")
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=5)
- if ev is None:
- raise Exception("No EAP-Failure seen")
- dev[0].request("REMOVE_NETWORK all")
- dev[0].wait_disconnected()
- logger.info("Invalid pkhash in phase1")
- dev[0].connect("test-wpa2-eap", key_mgmt="WPA-EAP", scan_freq="2412",
- eap="WSC", identity="WFA-SimpleConfig-Enrollee-1-0",
- phase1="foo pkhash=q pbc=1", wait_connect=False)
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-PROPOSED-METHOD"], timeout=5)
- if ev is None:
- raise Exception("Timeout on EAP method start")
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=5)
- if ev is None:
- raise Exception("No EAP-Failure seen")
- dev[0].request("REMOVE_NETWORK all")
- dev[0].wait_disconnected()
- logger.info("Zero fragment_size")
- dev[0].connect("test-wpa2-eap", key_mgmt="WPA-EAP", scan_freq="2412",
- eap="WSC", identity="WFA-SimpleConfig-Enrollee-1-0",
- fragment_size="0", phase1="pin=12345670", wait_connect=False)
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-PROPOSED-METHOD"], timeout=5)
- if ev is None:
- raise Exception("Timeout on EAP method start")
- ev = dev[0].wait_event(["WPS-M2D"], timeout=5)
- if ev is None:
- raise Exception("No M2D seen")
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=5)
- if ev is None:
- raise Exception("No EAP-Failure seen")
- dev[0].request("REMOVE_NETWORK all")
- dev[0].wait_disconnected()
- logger.info("Missing new_auth")
- dev[0].connect("test-wpa2-eap", key_mgmt="WPA-EAP", scan_freq="2412",
- eap="WSC", identity="WFA-SimpleConfig-Enrollee-1-0",
- phase1="pin=12345670 new_ssid=aa", wait_connect=False)
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-PROPOSED-METHOD"], timeout=5)
- if ev is None:
- raise Exception("Timeout on EAP method start")
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=5)
- if ev is None:
- raise Exception("No EAP-Failure seen")
- dev[0].request("REMOVE_NETWORK all")
- dev[0].wait_disconnected()
- logger.info("Missing new_encr")
- dev[0].connect("test-wpa2-eap", key_mgmt="WPA-EAP", scan_freq="2412",
- eap="WSC", identity="WFA-SimpleConfig-Enrollee-1-0",
- phase1="pin=12345670 new_auth=WPA2PSK new_ssid=aa", wait_connect=False)
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-PROPOSED-METHOD"], timeout=5)
- if ev is None:
- raise Exception("Timeout on EAP method start")
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=5)
- if ev is None:
- raise Exception("No EAP-Failure seen")
- dev[0].request("REMOVE_NETWORK all")
- dev[0].wait_disconnected()
- logger.info("Missing new_key")
- dev[0].connect("test-wpa2-eap", key_mgmt="WPA-EAP", scan_freq="2412",
- eap="WSC", identity="WFA-SimpleConfig-Enrollee-1-0",
- phase1="pin=12345670 new_auth=WPA2PSK new_ssid=aa new_encr=CCMP",
- wait_connect=False)
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-PROPOSED-METHOD"], timeout=5)
- if ev is None:
- raise Exception("Timeout on EAP method start")
- ev = dev[0].wait_event(["CTRL-EVENT-EAP-FAILURE"], timeout=5)
- if ev is None:
- raise Exception("No EAP-Failure seen")
- dev[0].request("REMOVE_NETWORK all")
- dev[0].wait_disconnected()
- def test_ap_wps_and_bss_limit(dev, apdev):
- """WPS and wpa_supplicant BSS entry limit"""
- try:
- _test_ap_wps_and_bss_limit(dev, apdev)
- finally:
- dev[0].request("SET bss_max_count 200")
- pass
- def _test_ap_wps_and_bss_limit(dev, apdev):
- params = { "ssid": "test-wps", "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "12345678", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP" }
- hapd = hostapd.add_ap(apdev[0], params)
- params = { "ssid": "test-wps-2", "eap_server": "1", "wps_state": "2",
- "wpa_passphrase": "1234567890", "wpa": "2",
- "wpa_key_mgmt": "WPA-PSK", "rsn_pairwise": "CCMP" }
- hapd2 = hostapd.add_ap(apdev[1], params)
- id = dev[1].add_network()
- dev[1].set_network(id, "mode", "2")
- dev[1].set_network_quoted(id, "ssid", "wpas-ap-no-wps")
- dev[1].set_network_quoted(id, "psk", "12345678")
- dev[1].set_network(id, "frequency", "2462")
- dev[1].set_network(id, "scan_freq", "2462")
- dev[1].set_network(id, "wps_disabled", "1")
- dev[1].select_network(id)
- id = dev[2].add_network()
- dev[2].set_network(id, "mode", "2")
- dev[2].set_network_quoted(id, "ssid", "wpas-ap")
- dev[2].set_network_quoted(id, "psk", "12345678")
- dev[2].set_network(id, "frequency", "2437")
- dev[2].set_network(id, "scan_freq", "2437")
- dev[2].select_network(id)
- wpas = WpaSupplicant(global_iface='/tmp/wpas-wlan5')
- wpas.interface_add("wlan5")
- id = wpas.add_network()
- wpas.set_network(id, "mode", "2")
- wpas.set_network_quoted(id, "ssid", "wpas-ap")
- wpas.set_network_quoted(id, "psk", "12345678")
- wpas.set_network(id, "frequency", "2437")
- wpas.set_network(id, "scan_freq", "2437")
- wpas.select_network(id)
- dev[1].wait_connected()
- dev[2].wait_connected()
- wpas.wait_connected()
- wpas.request("WPS_PIN any 12345670")
- hapd.request("WPS_PBC")
- hapd2.request("WPS_PBC")
- dev[0].request("SET bss_max_count 1")
- id = dev[0].add_network()
- dev[0].set_network_quoted(id, "ssid", "testing")
- id = dev[0].add_network()
- dev[0].set_network_quoted(id, "ssid", "testing")
- dev[0].set_network(id, "key_mgmt", "WPS")
- dev[0].request("WPS_PBC")
- ev = dev[0].wait_event(["CTRL-EVENT-SCAN-RESULTS"], timeout=10)
- dev[0].request("WPS_CANCEL")
- id = dev[0].add_network()
- dev[0].set_network_quoted(id, "ssid", "testing")
- dev[0].set_network(id, "key_mgmt", "WPS")
- dev[0].scan(freq="2412")
|