ctrl.c 28 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130
  1. /*
  2. * wlantest control interface
  3. * Copyright (c) 2010, Jouni Malinen <j@w1.fi>
  4. *
  5. * This program is free software; you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License version 2 as
  7. * published by the Free Software Foundation.
  8. *
  9. * Alternatively, this software may be distributed under the terms of BSD
  10. * license.
  11. *
  12. * See README and COPYING for more details.
  13. */
  14. #include "utils/includes.h"
  15. #include <sys/un.h>
  16. #include "utils/common.h"
  17. #include "utils/eloop.h"
  18. #include "common/defs.h"
  19. #include "common/version.h"
  20. #include "common/ieee802_11_defs.h"
  21. #include "wlantest.h"
  22. #include "wlantest_ctrl.h"
  23. static u8 * attr_get(u8 *buf, size_t buflen, enum wlantest_ctrl_attr attr,
  24. size_t *len)
  25. {
  26. u8 *pos = buf;
  27. while (pos + 8 <= buf + buflen) {
  28. enum wlantest_ctrl_attr a;
  29. size_t alen;
  30. a = WPA_GET_BE32(pos);
  31. pos += 4;
  32. alen = WPA_GET_BE32(pos);
  33. pos += 4;
  34. if (pos + alen > buf + buflen) {
  35. wpa_printf(MSG_DEBUG, "Invalid control message "
  36. "attribute");
  37. return NULL;
  38. }
  39. if (a == attr) {
  40. *len = alen;
  41. return pos;
  42. }
  43. pos += alen;
  44. }
  45. return NULL;
  46. }
  47. static u8 * attr_get_macaddr(u8 *buf, size_t buflen,
  48. enum wlantest_ctrl_attr attr)
  49. {
  50. u8 *addr;
  51. size_t addr_len;
  52. addr = attr_get(buf, buflen, attr, &addr_len);
  53. if (addr && addr_len != ETH_ALEN)
  54. addr = NULL;
  55. return addr;
  56. }
  57. static int attr_get_int(u8 *buf, size_t buflen, enum wlantest_ctrl_attr attr)
  58. {
  59. u8 *pos;
  60. size_t len;
  61. pos = attr_get(buf, buflen, attr, &len);
  62. if (pos == NULL || len != 4)
  63. return -1;
  64. return WPA_GET_BE32(pos);
  65. }
  66. static u8 * attr_add_str(u8 *pos, u8 *end, enum wlantest_ctrl_attr attr,
  67. const char *str)
  68. {
  69. size_t len = os_strlen(str);
  70. if (pos == NULL || end - pos < 8 + len)
  71. return NULL;
  72. WPA_PUT_BE32(pos, attr);
  73. pos += 4;
  74. WPA_PUT_BE32(pos, len);
  75. pos += 4;
  76. os_memcpy(pos, str, len);
  77. pos += len;
  78. return pos;
  79. }
  80. static u8 * attr_add_be32(u8 *pos, u8 *end, enum wlantest_ctrl_attr attr,
  81. u32 val)
  82. {
  83. if (pos == NULL || end - pos < 12)
  84. return NULL;
  85. WPA_PUT_BE32(pos, attr);
  86. pos += 4;
  87. WPA_PUT_BE32(pos, 4);
  88. pos += 4;
  89. WPA_PUT_BE32(pos, val);
  90. pos += 4;
  91. return pos;
  92. }
  93. static void ctrl_disconnect(struct wlantest *wt, int sock)
  94. {
  95. int i;
  96. wpa_printf(MSG_DEBUG, "Disconnect control interface connection %d",
  97. sock);
  98. for (i = 0; i < MAX_CTRL_CONNECTIONS; i++) {
  99. if (wt->ctrl_socks[i] == sock) {
  100. close(wt->ctrl_socks[i]);
  101. eloop_unregister_read_sock(wt->ctrl_socks[i]);
  102. wt->ctrl_socks[i] = -1;
  103. break;
  104. }
  105. }
  106. }
  107. static void ctrl_send(struct wlantest *wt, int sock, const u8 *buf,
  108. size_t len)
  109. {
  110. if (send(sock, buf, len, 0) < 0) {
  111. wpa_printf(MSG_INFO, "send(ctrl): %s", strerror(errno));
  112. ctrl_disconnect(wt, sock);
  113. }
  114. }
  115. static void ctrl_send_simple(struct wlantest *wt, int sock,
  116. enum wlantest_ctrl_cmd cmd)
  117. {
  118. u8 buf[4];
  119. WPA_PUT_BE32(buf, cmd);
  120. ctrl_send(wt, sock, buf, sizeof(buf));
  121. }
  122. static struct wlantest_bss * ctrl_get_bss(struct wlantest *wt, int sock,
  123. u8 *cmd, size_t clen)
  124. {
  125. struct wlantest_bss *bss;
  126. u8 *pos;
  127. size_t len;
  128. pos = attr_get(cmd, clen, WLANTEST_ATTR_BSSID, &len);
  129. if (pos == NULL || len != ETH_ALEN) {
  130. ctrl_send_simple(wt, sock, WLANTEST_CTRL_INVALID_CMD);
  131. return NULL;
  132. }
  133. bss = bss_find(wt, pos);
  134. if (bss == NULL) {
  135. ctrl_send_simple(wt, sock, WLANTEST_CTRL_FAILURE);
  136. return NULL;
  137. }
  138. return bss;
  139. }
  140. static struct wlantest_sta * ctrl_get_sta(struct wlantest *wt, int sock,
  141. u8 *cmd, size_t clen,
  142. struct wlantest_bss *bss)
  143. {
  144. struct wlantest_sta *sta;
  145. u8 *pos;
  146. size_t len;
  147. if (bss == NULL)
  148. return NULL;
  149. pos = attr_get(cmd, clen, WLANTEST_ATTR_STA_ADDR, &len);
  150. if (pos == NULL || len != ETH_ALEN) {
  151. ctrl_send_simple(wt, sock, WLANTEST_CTRL_INVALID_CMD);
  152. return NULL;
  153. }
  154. sta = sta_find(bss, pos);
  155. if (sta == NULL) {
  156. ctrl_send_simple(wt, sock, WLANTEST_CTRL_FAILURE);
  157. return NULL;
  158. }
  159. return sta;
  160. }
  161. static void ctrl_list_bss(struct wlantest *wt, int sock)
  162. {
  163. u8 buf[WLANTEST_CTRL_MAX_RESP_LEN], *pos, *len;
  164. struct wlantest_bss *bss;
  165. pos = buf;
  166. WPA_PUT_BE32(pos, WLANTEST_CTRL_SUCCESS);
  167. pos += 4;
  168. WPA_PUT_BE32(pos, WLANTEST_ATTR_BSSID);
  169. pos += 4;
  170. len = pos; /* to be filled */
  171. pos += 4;
  172. dl_list_for_each(bss, &wt->bss, struct wlantest_bss, list) {
  173. if (pos + ETH_ALEN > buf + WLANTEST_CTRL_MAX_RESP_LEN)
  174. break;
  175. os_memcpy(pos, bss->bssid, ETH_ALEN);
  176. pos += ETH_ALEN;
  177. }
  178. WPA_PUT_BE32(len, pos - len - 4);
  179. ctrl_send(wt, sock, buf, pos - buf);
  180. }
  181. static void ctrl_list_sta(struct wlantest *wt, int sock, u8 *cmd, size_t clen)
  182. {
  183. u8 buf[WLANTEST_CTRL_MAX_RESP_LEN], *pos, *len;
  184. struct wlantest_bss *bss;
  185. struct wlantest_sta *sta;
  186. bss = ctrl_get_bss(wt, sock, cmd, clen);
  187. if (bss == NULL)
  188. return;
  189. pos = buf;
  190. WPA_PUT_BE32(pos, WLANTEST_CTRL_SUCCESS);
  191. pos += 4;
  192. WPA_PUT_BE32(pos, WLANTEST_ATTR_STA_ADDR);
  193. pos += 4;
  194. len = pos; /* to be filled */
  195. pos += 4;
  196. dl_list_for_each(sta, &bss->sta, struct wlantest_sta, list) {
  197. if (pos + ETH_ALEN > buf + WLANTEST_CTRL_MAX_RESP_LEN)
  198. break;
  199. os_memcpy(pos, sta->addr, ETH_ALEN);
  200. pos += ETH_ALEN;
  201. }
  202. WPA_PUT_BE32(len, pos - len - 4);
  203. ctrl_send(wt, sock, buf, pos - buf);
  204. }
  205. static void ctrl_flush(struct wlantest *wt, int sock)
  206. {
  207. wpa_printf(MSG_DEBUG, "Drop all collected BSS data");
  208. bss_flush(wt);
  209. ctrl_send_simple(wt, sock, WLANTEST_CTRL_SUCCESS);
  210. }
  211. static void ctrl_clear_sta_counters(struct wlantest *wt, int sock, u8 *cmd,
  212. size_t clen)
  213. {
  214. struct wlantest_bss *bss;
  215. struct wlantest_sta *sta;
  216. bss = ctrl_get_bss(wt, sock, cmd, clen);
  217. sta = ctrl_get_sta(wt, sock, cmd, clen, bss);
  218. if (sta == NULL)
  219. return;
  220. os_memset(sta->counters, 0, sizeof(sta->counters));
  221. ctrl_send_simple(wt, sock, WLANTEST_CTRL_SUCCESS);
  222. }
  223. static void ctrl_clear_bss_counters(struct wlantest *wt, int sock, u8 *cmd,
  224. size_t clen)
  225. {
  226. struct wlantest_bss *bss;
  227. bss = ctrl_get_bss(wt, sock, cmd, clen);
  228. if (bss == NULL)
  229. return;
  230. os_memset(bss->counters, 0, sizeof(bss->counters));
  231. ctrl_send_simple(wt, sock, WLANTEST_CTRL_SUCCESS);
  232. }
  233. static void ctrl_get_sta_counter(struct wlantest *wt, int sock, u8 *cmd,
  234. size_t clen)
  235. {
  236. u8 *addr;
  237. size_t addr_len;
  238. struct wlantest_bss *bss;
  239. struct wlantest_sta *sta;
  240. u32 counter;
  241. u8 buf[4 + 12], *end, *pos;
  242. bss = ctrl_get_bss(wt, sock, cmd, clen);
  243. sta = ctrl_get_sta(wt, sock, cmd, clen, bss);
  244. if (sta == NULL)
  245. return;
  246. addr = attr_get(cmd, clen, WLANTEST_ATTR_STA_COUNTER, &addr_len);
  247. if (addr == NULL || addr_len != 4) {
  248. ctrl_send_simple(wt, sock, WLANTEST_CTRL_INVALID_CMD);
  249. return;
  250. }
  251. counter = WPA_GET_BE32(addr);
  252. if (counter >= NUM_WLANTEST_STA_COUNTER) {
  253. ctrl_send_simple(wt, sock, WLANTEST_CTRL_INVALID_CMD);
  254. return;
  255. }
  256. pos = buf;
  257. end = buf + sizeof(buf);
  258. WPA_PUT_BE32(pos, WLANTEST_CTRL_SUCCESS);
  259. pos += 4;
  260. pos = attr_add_be32(pos, end, WLANTEST_ATTR_COUNTER,
  261. sta->counters[counter]);
  262. ctrl_send(wt, sock, buf, pos - buf);
  263. }
  264. static void ctrl_get_bss_counter(struct wlantest *wt, int sock, u8 *cmd,
  265. size_t clen)
  266. {
  267. u8 *addr;
  268. size_t addr_len;
  269. struct wlantest_bss *bss;
  270. u32 counter;
  271. u8 buf[4 + 12], *end, *pos;
  272. bss = ctrl_get_bss(wt, sock, cmd, clen);
  273. if (bss == NULL)
  274. return;
  275. addr = attr_get(cmd, clen, WLANTEST_ATTR_BSS_COUNTER, &addr_len);
  276. if (addr == NULL || addr_len != 4) {
  277. ctrl_send_simple(wt, sock, WLANTEST_CTRL_INVALID_CMD);
  278. return;
  279. }
  280. counter = WPA_GET_BE32(addr);
  281. if (counter >= NUM_WLANTEST_BSS_COUNTER) {
  282. ctrl_send_simple(wt, sock, WLANTEST_CTRL_INVALID_CMD);
  283. return;
  284. }
  285. pos = buf;
  286. end = buf + sizeof(buf);
  287. WPA_PUT_BE32(pos, WLANTEST_CTRL_SUCCESS);
  288. pos += 4;
  289. pos = attr_add_be32(pos, end, WLANTEST_ATTR_COUNTER,
  290. bss->counters[counter]);
  291. ctrl_send(wt, sock, buf, pos - buf);
  292. }
  293. static void build_mgmt_hdr(struct ieee80211_mgmt *mgmt,
  294. struct wlantest_bss *bss, struct wlantest_sta *sta,
  295. int sender_ap, int stype)
  296. {
  297. os_memset(mgmt, 0, 24);
  298. mgmt->frame_control = IEEE80211_FC(WLAN_FC_TYPE_MGMT, stype);
  299. if (sender_ap) {
  300. if (sta)
  301. os_memcpy(mgmt->da, sta->addr, ETH_ALEN);
  302. else
  303. os_memset(mgmt->da, 0xff, ETH_ALEN);
  304. os_memcpy(mgmt->sa, bss->bssid, ETH_ALEN);
  305. } else {
  306. os_memcpy(mgmt->da, bss->bssid, ETH_ALEN);
  307. os_memcpy(mgmt->sa, sta->addr, ETH_ALEN);
  308. }
  309. os_memcpy(mgmt->bssid, bss->bssid, ETH_ALEN);
  310. }
  311. static int ctrl_inject_auth(struct wlantest *wt, struct wlantest_bss *bss,
  312. struct wlantest_sta *sta, int sender_ap,
  313. enum wlantest_inject_protection prot)
  314. {
  315. struct ieee80211_mgmt mgmt;
  316. if (prot != WLANTEST_INJECT_NORMAL &&
  317. prot != WLANTEST_INJECT_UNPROTECTED)
  318. return -1; /* Authentication frame is never protected */
  319. if (sta == NULL)
  320. return -1; /* No broadcast Authentication frames */
  321. if (sender_ap)
  322. wpa_printf(MSG_INFO, "INJECT: Auth " MACSTR " -> " MACSTR,
  323. MAC2STR(bss->bssid), MAC2STR(sta->addr));
  324. else
  325. wpa_printf(MSG_INFO, "INJECT: Auth " MACSTR " -> " MACSTR,
  326. MAC2STR(sta->addr), MAC2STR(bss->bssid));
  327. build_mgmt_hdr(&mgmt, bss, sta, sender_ap, WLAN_FC_STYPE_AUTH);
  328. mgmt.u.auth.auth_alg = host_to_le16(WLAN_AUTH_OPEN);
  329. mgmt.u.auth.auth_transaction = host_to_le16(1);
  330. mgmt.u.auth.status_code = host_to_le16(WLAN_STATUS_SUCCESS);
  331. return wlantest_inject(wt, bss, sta, (u8 *) &mgmt, 24 + 6,
  332. WLANTEST_INJECT_UNPROTECTED);
  333. }
  334. static int ctrl_inject_assocreq(struct wlantest *wt, struct wlantest_bss *bss,
  335. struct wlantest_sta *sta, int sender_ap,
  336. enum wlantest_inject_protection prot)
  337. {
  338. u8 *buf;
  339. struct ieee80211_mgmt *mgmt;
  340. int ret;
  341. if (prot != WLANTEST_INJECT_NORMAL &&
  342. prot != WLANTEST_INJECT_UNPROTECTED)
  343. return -1; /* Association Request frame is never protected */
  344. if (sta == NULL)
  345. return -1; /* No broadcast Association Request frames */
  346. if (sender_ap)
  347. return -1; /* No Association Request frame sent by AP */
  348. if (sta->assocreq_ies == NULL) {
  349. wpa_printf(MSG_INFO, "INJECT: No previous (Re)Association "
  350. "Request available for " MACSTR,
  351. MAC2STR(sta->addr));
  352. return -1;
  353. }
  354. wpa_printf(MSG_INFO, "INJECT: AssocReq " MACSTR " -> " MACSTR,
  355. MAC2STR(sta->addr), MAC2STR(bss->bssid));
  356. buf = os_malloc(sizeof(*mgmt) + sta->assocreq_ies_len);
  357. if (buf == NULL)
  358. return -1;
  359. mgmt = (struct ieee80211_mgmt *) buf;
  360. build_mgmt_hdr(mgmt, bss, sta, sender_ap, WLAN_FC_STYPE_ASSOC_REQ);
  361. mgmt->u.assoc_req.capab_info = host_to_le16(sta->assocreq_capab_info);
  362. mgmt->u.assoc_req.listen_interval =
  363. host_to_le16(sta->assocreq_listen_int);
  364. os_memcpy(mgmt->u.assoc_req.variable, sta->assocreq_ies,
  365. sta->assocreq_ies_len);
  366. ret = wlantest_inject(wt, bss, sta, buf,
  367. 24 + 4 + sta->assocreq_ies_len,
  368. WLANTEST_INJECT_UNPROTECTED);
  369. os_free(buf);
  370. return ret;
  371. }
  372. static int ctrl_inject_reassocreq(struct wlantest *wt,
  373. struct wlantest_bss *bss,
  374. struct wlantest_sta *sta, int sender_ap,
  375. enum wlantest_inject_protection prot)
  376. {
  377. u8 *buf;
  378. struct ieee80211_mgmt *mgmt;
  379. int ret;
  380. if (prot != WLANTEST_INJECT_NORMAL &&
  381. prot != WLANTEST_INJECT_UNPROTECTED)
  382. return -1; /* Reassociation Request frame is never protected */
  383. if (sta == NULL)
  384. return -1; /* No broadcast Reassociation Request frames */
  385. if (sender_ap)
  386. return -1; /* No Reassociation Request frame sent by AP */
  387. if (sta->assocreq_ies == NULL) {
  388. wpa_printf(MSG_INFO, "INJECT: No previous (Re)Association "
  389. "Request available for " MACSTR,
  390. MAC2STR(sta->addr));
  391. return -1;
  392. }
  393. wpa_printf(MSG_INFO, "INJECT: ReassocReq " MACSTR " -> " MACSTR,
  394. MAC2STR(sta->addr), MAC2STR(bss->bssid));
  395. buf = os_malloc(sizeof(*mgmt) + sta->assocreq_ies_len);
  396. if (buf == NULL)
  397. return -1;
  398. mgmt = (struct ieee80211_mgmt *) buf;
  399. build_mgmt_hdr(mgmt, bss, sta, sender_ap, WLAN_FC_STYPE_REASSOC_REQ);
  400. mgmt->u.reassoc_req.capab_info =
  401. host_to_le16(sta->assocreq_capab_info);
  402. mgmt->u.reassoc_req.listen_interval =
  403. host_to_le16(sta->assocreq_listen_int);
  404. os_memcpy(mgmt->u.reassoc_req.current_ap, bss->bssid, ETH_ALEN);
  405. os_memcpy(mgmt->u.reassoc_req.variable, sta->assocreq_ies,
  406. sta->assocreq_ies_len);
  407. ret = wlantest_inject(wt, bss, sta, buf,
  408. 24 + 10 + sta->assocreq_ies_len,
  409. WLANTEST_INJECT_UNPROTECTED);
  410. os_free(buf);
  411. return ret;
  412. }
  413. static int ctrl_inject_deauth(struct wlantest *wt, struct wlantest_bss *bss,
  414. struct wlantest_sta *sta, int sender_ap,
  415. enum wlantest_inject_protection prot)
  416. {
  417. struct ieee80211_mgmt mgmt;
  418. if (sender_ap) {
  419. if (sta)
  420. wpa_printf(MSG_INFO, "INJECT: Deauth " MACSTR " -> "
  421. MACSTR,
  422. MAC2STR(bss->bssid), MAC2STR(sta->addr));
  423. else
  424. wpa_printf(MSG_INFO, "INJECT: Deauth " MACSTR
  425. " -> broadcast", MAC2STR(bss->bssid));
  426. } else
  427. wpa_printf(MSG_INFO, "INJECT: Deauth " MACSTR " -> " MACSTR,
  428. MAC2STR(sta->addr), MAC2STR(bss->bssid));
  429. build_mgmt_hdr(&mgmt, bss, sta, sender_ap, WLAN_FC_STYPE_DEAUTH);
  430. mgmt.u.deauth.reason_code = host_to_le16(WLAN_REASON_UNSPECIFIED);
  431. return wlantest_inject(wt, bss, sta, (u8 *) &mgmt, 24 + 2, prot);
  432. }
  433. static int ctrl_inject_disassoc(struct wlantest *wt, struct wlantest_bss *bss,
  434. struct wlantest_sta *sta, int sender_ap,
  435. enum wlantest_inject_protection prot)
  436. {
  437. struct ieee80211_mgmt mgmt;
  438. if (sender_ap) {
  439. if (sta)
  440. wpa_printf(MSG_INFO, "INJECT: Disassoc " MACSTR " -> "
  441. MACSTR,
  442. MAC2STR(bss->bssid), MAC2STR(sta->addr));
  443. else
  444. wpa_printf(MSG_INFO, "INJECT: Disassoc " MACSTR
  445. " -> broadcast", MAC2STR(bss->bssid));
  446. } else
  447. wpa_printf(MSG_INFO, "INJECT: Disassoc " MACSTR " -> " MACSTR,
  448. MAC2STR(sta->addr), MAC2STR(bss->bssid));
  449. build_mgmt_hdr(&mgmt, bss, sta, sender_ap, WLAN_FC_STYPE_DISASSOC);
  450. mgmt.u.disassoc.reason_code = host_to_le16(WLAN_REASON_UNSPECIFIED);
  451. return wlantest_inject(wt, bss, sta, (u8 *) &mgmt, 24 + 2, prot);
  452. }
  453. static int ctrl_inject_saqueryreq(struct wlantest *wt,
  454. struct wlantest_bss *bss,
  455. struct wlantest_sta *sta, int sender_ap,
  456. enum wlantest_inject_protection prot)
  457. {
  458. struct ieee80211_mgmt mgmt;
  459. if (sta == NULL)
  460. return -1; /* No broadcast SA Query frames */
  461. if (sender_ap)
  462. wpa_printf(MSG_INFO, "INJECT: SA Query Request " MACSTR " -> "
  463. MACSTR, MAC2STR(bss->bssid), MAC2STR(sta->addr));
  464. else
  465. wpa_printf(MSG_INFO, "INJECT: SA Query Request " MACSTR " -> "
  466. MACSTR, MAC2STR(sta->addr), MAC2STR(bss->bssid));
  467. build_mgmt_hdr(&mgmt, bss, sta, sender_ap, WLAN_FC_STYPE_ACTION);
  468. mgmt.u.action.category = WLAN_ACTION_SA_QUERY;
  469. mgmt.u.action.u.sa_query_req.action = WLAN_SA_QUERY_REQUEST;
  470. mgmt.u.action.u.sa_query_req.trans_id[0] = 0x12;
  471. mgmt.u.action.u.sa_query_req.trans_id[1] = 0x34;
  472. os_memcpy(sender_ap ? sta->ap_sa_query_tr : sta->sta_sa_query_tr,
  473. mgmt.u.action.u.sa_query_req.trans_id,
  474. WLAN_SA_QUERY_TR_ID_LEN);
  475. return wlantest_inject(wt, bss, sta, (u8 *) &mgmt, 24 + 4, prot);
  476. }
  477. static void ctrl_inject(struct wlantest *wt, int sock, u8 *cmd, size_t clen)
  478. {
  479. u8 *bssid, *sta_addr;
  480. struct wlantest_bss *bss;
  481. struct wlantest_sta *sta;
  482. int frame, sender_ap, prot;
  483. int ret = 0;
  484. bssid = attr_get_macaddr(cmd, clen, WLANTEST_ATTR_BSSID);
  485. sta_addr = attr_get_macaddr(cmd, clen, WLANTEST_ATTR_STA_ADDR);
  486. frame = attr_get_int(cmd, clen, WLANTEST_ATTR_INJECT_FRAME);
  487. sender_ap = attr_get_int(cmd, clen, WLANTEST_ATTR_INJECT_SENDER_AP);
  488. if (sender_ap < 0)
  489. sender_ap = 0;
  490. prot = attr_get_int(cmd, clen, WLANTEST_ATTR_INJECT_PROTECTION);
  491. if (bssid == NULL || sta_addr == NULL || frame < 0 || prot < 0) {
  492. wpa_printf(MSG_INFO, "Invalid inject command parameters");
  493. ctrl_send_simple(wt, sock, WLANTEST_CTRL_INVALID_CMD);
  494. return;
  495. }
  496. bss = bss_find(wt, bssid);
  497. if (bss == NULL) {
  498. wpa_printf(MSG_INFO, "BSS not found for inject command");
  499. ctrl_send_simple(wt, sock, WLANTEST_CTRL_FAILURE);
  500. return;
  501. }
  502. if (is_broadcast_ether_addr(sta_addr)) {
  503. if (!sender_ap) {
  504. wpa_printf(MSG_INFO, "Invalid broadcast inject "
  505. "command without sender_ap set");
  506. ctrl_send_simple(wt, sock, WLANTEST_CTRL_INVALID_CMD);
  507. return;
  508. } sta = NULL;
  509. } else {
  510. sta = sta_find(bss, sta_addr);
  511. if (sta == NULL) {
  512. wpa_printf(MSG_INFO, "Station not found for inject "
  513. "command");
  514. ctrl_send_simple(wt, sock, WLANTEST_CTRL_FAILURE);
  515. return;
  516. }
  517. }
  518. switch (frame) {
  519. case WLANTEST_FRAME_AUTH:
  520. ret = ctrl_inject_auth(wt, bss, sta, sender_ap, prot);
  521. break;
  522. case WLANTEST_FRAME_ASSOCREQ:
  523. ret = ctrl_inject_assocreq(wt, bss, sta, sender_ap, prot);
  524. break;
  525. case WLANTEST_FRAME_REASSOCREQ:
  526. ret = ctrl_inject_reassocreq(wt, bss, sta, sender_ap, prot);
  527. break;
  528. case WLANTEST_FRAME_DEAUTH:
  529. ret = ctrl_inject_deauth(wt, bss, sta, sender_ap, prot);
  530. break;
  531. case WLANTEST_FRAME_DISASSOC:
  532. ret = ctrl_inject_disassoc(wt, bss, sta, sender_ap, prot);
  533. break;
  534. case WLANTEST_FRAME_SAQUERYREQ:
  535. ret = ctrl_inject_saqueryreq(wt, bss, sta, sender_ap, prot);
  536. break;
  537. default:
  538. wpa_printf(MSG_INFO, "Unsupported inject command frame %d",
  539. frame);
  540. ctrl_send_simple(wt, sock, WLANTEST_CTRL_INVALID_CMD);
  541. return;
  542. }
  543. if (ret)
  544. wpa_printf(MSG_INFO, "Failed to inject frame");
  545. else
  546. wpa_printf(MSG_INFO, "Frame injected successfully");
  547. ctrl_send_simple(wt, sock, ret == 0 ? WLANTEST_CTRL_SUCCESS :
  548. WLANTEST_CTRL_FAILURE);
  549. }
  550. static void ctrl_version(struct wlantest *wt, int sock)
  551. {
  552. u8 buf[WLANTEST_CTRL_MAX_RESP_LEN], *pos;
  553. pos = buf;
  554. WPA_PUT_BE32(pos, WLANTEST_CTRL_SUCCESS);
  555. pos += 4;
  556. pos = attr_add_str(pos, buf + sizeof(buf), WLANTEST_ATTR_VERSION,
  557. VERSION_STR);
  558. ctrl_send(wt, sock, buf, pos - buf);
  559. }
  560. static void ctrl_add_passphrase(struct wlantest *wt, int sock, u8 *cmd,
  561. size_t clen)
  562. {
  563. u8 *passphrase;
  564. size_t len;
  565. struct wlantest_passphrase *p, *pa;
  566. u8 *bssid;
  567. passphrase = attr_get(cmd, clen, WLANTEST_ATTR_PASSPHRASE, &len);
  568. if (passphrase == NULL || len < 8 || len > 63) {
  569. ctrl_send_simple(wt, sock, WLANTEST_CTRL_INVALID_CMD);
  570. return;
  571. }
  572. p = os_zalloc(sizeof(*p));
  573. if (p == NULL) {
  574. ctrl_send_simple(wt, sock, WLANTEST_CTRL_FAILURE);
  575. return;
  576. }
  577. os_memcpy(p->passphrase, passphrase, len);
  578. wpa_printf(MSG_INFO, "Add passphrase '%s'", p->passphrase);
  579. bssid = attr_get_macaddr(cmd, clen, WLANTEST_ATTR_BSSID);
  580. if (bssid) {
  581. os_memcpy(p->bssid, bssid, ETH_ALEN);
  582. wpa_printf(MSG_INFO, "Limit passphrase for BSSID " MACSTR,
  583. MAC2STR(p->bssid));
  584. }
  585. dl_list_for_each(pa, &wt->passphrase, struct wlantest_passphrase, list)
  586. {
  587. if (os_strcmp(p->passphrase, pa->passphrase) == 0 &&
  588. os_memcmp(p->bssid, pa->bssid, ETH_ALEN) == 0) {
  589. wpa_printf(MSG_INFO, "Passphrase was already known");
  590. os_free(p);
  591. p = NULL;
  592. break;
  593. }
  594. }
  595. if (p) {
  596. struct wlantest_bss *bss;
  597. dl_list_add(&wt->passphrase, &p->list);
  598. dl_list_for_each(bss, &wt->bss, struct wlantest_bss, list) {
  599. if (bssid &&
  600. os_memcmp(p->bssid, bss->bssid, ETH_ALEN) != 0)
  601. continue;
  602. bss_add_pmk_from_passphrase(bss, p->passphrase);
  603. }
  604. }
  605. ctrl_send_simple(wt, sock, WLANTEST_CTRL_SUCCESS);
  606. }
  607. static void info_print_proto(char *buf, size_t len, int proto)
  608. {
  609. char *pos, *end;
  610. if (proto == 0) {
  611. os_snprintf(buf, len, "OPEN");
  612. return;
  613. }
  614. pos = buf;
  615. end = buf + len;
  616. if (proto & WPA_PROTO_WPA)
  617. pos += os_snprintf(pos, end - pos, "%sWPA",
  618. pos == buf ? "" : " ");
  619. if (proto & WPA_PROTO_RSN)
  620. pos += os_snprintf(pos, end - pos, "%sWPA2",
  621. pos == buf ? "" : " ");
  622. }
  623. static void info_print_cipher(char *buf, size_t len, int cipher)
  624. {
  625. char *pos, *end;
  626. if (cipher == 0) {
  627. os_snprintf(buf, len, "N/A");
  628. return;
  629. }
  630. pos = buf;
  631. end = buf + len;
  632. if (cipher & WPA_CIPHER_NONE)
  633. pos += os_snprintf(pos, end - pos, "%sNONE",
  634. pos == buf ? "" : " ");
  635. if (cipher & WPA_CIPHER_WEP40)
  636. pos += os_snprintf(pos, end - pos, "%sWEP40",
  637. pos == buf ? "" : " ");
  638. if (cipher & WPA_CIPHER_WEP104)
  639. pos += os_snprintf(pos, end - pos, "%sWEP104",
  640. pos == buf ? "" : " ");
  641. if (cipher & WPA_CIPHER_TKIP)
  642. pos += os_snprintf(pos, end - pos, "%sTKIP",
  643. pos == buf ? "" : " ");
  644. if (cipher & WPA_CIPHER_CCMP)
  645. pos += os_snprintf(pos, end - pos, "%sCCMP",
  646. pos == buf ? "" : " ");
  647. if (cipher & WPA_CIPHER_AES_128_CMAC)
  648. pos += os_snprintf(pos, end - pos, "%sBIP",
  649. pos == buf ? "" : " ");
  650. }
  651. static void info_print_key_mgmt(char *buf, size_t len, int key_mgmt)
  652. {
  653. char *pos, *end;
  654. if (key_mgmt == 0) {
  655. os_snprintf(buf, len, "N/A");
  656. return;
  657. }
  658. pos = buf;
  659. end = buf + len;
  660. if (key_mgmt & WPA_KEY_MGMT_IEEE8021X)
  661. pos += os_snprintf(pos, end - pos, "%sEAP",
  662. pos == buf ? "" : " ");
  663. if (key_mgmt & WPA_KEY_MGMT_PSK)
  664. pos += os_snprintf(pos, end - pos, "%sPSK",
  665. pos == buf ? "" : " ");
  666. if (key_mgmt & WPA_KEY_MGMT_WPA_NONE)
  667. pos += os_snprintf(pos, end - pos, "%sWPA-NONE",
  668. pos == buf ? "" : " ");
  669. if (key_mgmt & WPA_KEY_MGMT_FT_IEEE8021X)
  670. pos += os_snprintf(pos, end - pos, "%sFT-EAP",
  671. pos == buf ? "" : " ");
  672. if (key_mgmt & WPA_KEY_MGMT_FT_PSK)
  673. pos += os_snprintf(pos, end - pos, "%sFT-PSK",
  674. pos == buf ? "" : " ");
  675. if (key_mgmt & WPA_KEY_MGMT_IEEE8021X_SHA256)
  676. pos += os_snprintf(pos, end - pos, "%sEAP-SHA256",
  677. pos == buf ? "" : " ");
  678. if (key_mgmt & WPA_KEY_MGMT_PSK_SHA256)
  679. pos += os_snprintf(pos, end - pos, "%sPSK-SHA256",
  680. pos == buf ? "" : " ");
  681. }
  682. static void info_print_rsn_capab(char *buf, size_t len, int capab)
  683. {
  684. char *pos, *end;
  685. pos = buf;
  686. end = buf + len;
  687. if (capab & WPA_CAPABILITY_PREAUTH)
  688. pos += os_snprintf(pos, end - pos, "%sPREAUTH",
  689. pos == buf ? "" : " ");
  690. if (capab & WPA_CAPABILITY_NO_PAIRWISE)
  691. pos += os_snprintf(pos, end - pos, "%sNO_PAIRWISE",
  692. pos == buf ? "" : " ");
  693. if (capab & WPA_CAPABILITY_MFPR)
  694. pos += os_snprintf(pos, end - pos, "%sMFPR",
  695. pos == buf ? "" : " ");
  696. if (capab & WPA_CAPABILITY_MFPC)
  697. pos += os_snprintf(pos, end - pos, "%sMFPC",
  698. pos == buf ? "" : " ");
  699. if (capab & WPA_CAPABILITY_PEERKEY_ENABLED)
  700. pos += os_snprintf(pos, end - pos, "%sPEERKEY",
  701. pos == buf ? "" : " ");
  702. }
  703. static void info_print_state(char *buf, size_t len, int state)
  704. {
  705. switch (state) {
  706. case STATE1:
  707. os_strlcpy(buf, "NOT-AUTH", len);
  708. break;
  709. case STATE2:
  710. os_strlcpy(buf, "AUTH", len);
  711. break;
  712. case STATE3:
  713. os_strlcpy(buf, "AUTH+ASSOC", len);
  714. break;
  715. }
  716. }
  717. static void ctrl_info_sta(struct wlantest *wt, int sock, u8 *cmd, size_t clen)
  718. {
  719. u8 *addr;
  720. size_t addr_len;
  721. struct wlantest_bss *bss;
  722. struct wlantest_sta *sta;
  723. enum wlantest_sta_info info;
  724. u8 buf[4 + 108], *end, *pos;
  725. char resp[100];
  726. bss = ctrl_get_bss(wt, sock, cmd, clen);
  727. sta = ctrl_get_sta(wt, sock, cmd, clen, bss);
  728. if (sta == NULL)
  729. return;
  730. addr = attr_get(cmd, clen, WLANTEST_ATTR_STA_INFO, &addr_len);
  731. if (addr == NULL || addr_len != 4) {
  732. ctrl_send_simple(wt, sock, WLANTEST_CTRL_INVALID_CMD);
  733. return;
  734. }
  735. info = WPA_GET_BE32(addr);
  736. resp[0] = '\0';
  737. switch (info) {
  738. case WLANTEST_STA_INFO_PROTO:
  739. info_print_proto(resp, sizeof(resp), sta->proto);
  740. break;
  741. case WLANTEST_STA_INFO_PAIRWISE:
  742. info_print_cipher(resp, sizeof(resp), sta->pairwise_cipher);
  743. break;
  744. case WLANTEST_STA_INFO_KEY_MGMT:
  745. info_print_key_mgmt(resp, sizeof(resp), sta->key_mgmt);
  746. break;
  747. case WLANTEST_STA_INFO_RSN_CAPAB:
  748. info_print_rsn_capab(resp, sizeof(resp), sta->rsn_capab);
  749. break;
  750. case WLANTEST_STA_INFO_STATE:
  751. info_print_state(resp, sizeof(resp), sta->state);
  752. break;
  753. default:
  754. ctrl_send_simple(wt, sock, WLANTEST_CTRL_INVALID_CMD);
  755. return;
  756. }
  757. pos = buf;
  758. end = buf + sizeof(buf);
  759. WPA_PUT_BE32(pos, WLANTEST_CTRL_SUCCESS);
  760. pos += 4;
  761. pos = attr_add_str(pos, end, WLANTEST_ATTR_INFO, resp);
  762. ctrl_send(wt, sock, buf, pos - buf);
  763. }
  764. static void ctrl_info_bss(struct wlantest *wt, int sock, u8 *cmd, size_t clen)
  765. {
  766. u8 *addr;
  767. size_t addr_len;
  768. struct wlantest_bss *bss;
  769. enum wlantest_bss_info info;
  770. u8 buf[4 + 108], *end, *pos;
  771. char resp[100];
  772. bss = ctrl_get_bss(wt, sock, cmd, clen);
  773. if (bss == NULL)
  774. return;
  775. addr = attr_get(cmd, clen, WLANTEST_ATTR_BSS_INFO, &addr_len);
  776. if (addr == NULL || addr_len != 4) {
  777. ctrl_send_simple(wt, sock, WLANTEST_CTRL_INVALID_CMD);
  778. return;
  779. }
  780. info = WPA_GET_BE32(addr);
  781. resp[0] = '\0';
  782. switch (info) {
  783. case WLANTEST_BSS_INFO_PROTO:
  784. info_print_proto(resp, sizeof(resp), bss->proto);
  785. break;
  786. case WLANTEST_BSS_INFO_PAIRWISE:
  787. info_print_cipher(resp, sizeof(resp), bss->pairwise_cipher);
  788. break;
  789. case WLANTEST_BSS_INFO_GROUP:
  790. info_print_cipher(resp, sizeof(resp), bss->group_cipher);
  791. break;
  792. case WLANTEST_BSS_INFO_GROUP_MGMT:
  793. info_print_cipher(resp, sizeof(resp), bss->mgmt_group_cipher);
  794. break;
  795. case WLANTEST_BSS_INFO_KEY_MGMT:
  796. info_print_key_mgmt(resp, sizeof(resp), bss->key_mgmt);
  797. break;
  798. case WLANTEST_BSS_INFO_RSN_CAPAB:
  799. info_print_rsn_capab(resp, sizeof(resp), bss->rsn_capab);
  800. break;
  801. default:
  802. ctrl_send_simple(wt, sock, WLANTEST_CTRL_INVALID_CMD);
  803. return;
  804. }
  805. pos = buf;
  806. end = buf + sizeof(buf);
  807. WPA_PUT_BE32(pos, WLANTEST_CTRL_SUCCESS);
  808. pos += 4;
  809. pos = attr_add_str(pos, end, WLANTEST_ATTR_INFO, resp);
  810. ctrl_send(wt, sock, buf, pos - buf);
  811. }
  812. static void ctrl_read(int sock, void *eloop_ctx, void *sock_ctx)
  813. {
  814. struct wlantest *wt = eloop_ctx;
  815. u8 buf[WLANTEST_CTRL_MAX_CMD_LEN];
  816. int len;
  817. enum wlantest_ctrl_cmd cmd;
  818. wpa_printf(MSG_EXCESSIVE, "New control interface message from %d",
  819. sock);
  820. len = recv(sock, buf, sizeof(buf), 0);
  821. if (len < 0) {
  822. wpa_printf(MSG_INFO, "recv(ctrl): %s", strerror(errno));
  823. ctrl_disconnect(wt, sock);
  824. return;
  825. }
  826. if (len == 0) {
  827. ctrl_disconnect(wt, sock);
  828. return;
  829. }
  830. if (len < 4) {
  831. wpa_printf(MSG_INFO, "Too short control interface command "
  832. "from %d", sock);
  833. ctrl_disconnect(wt, sock);
  834. return;
  835. }
  836. cmd = WPA_GET_BE32(buf);
  837. wpa_printf(MSG_EXCESSIVE, "Control interface command %d from %d",
  838. cmd, sock);
  839. switch (cmd) {
  840. case WLANTEST_CTRL_PING:
  841. ctrl_send_simple(wt, sock, WLANTEST_CTRL_SUCCESS);
  842. break;
  843. case WLANTEST_CTRL_TERMINATE:
  844. ctrl_send_simple(wt, sock, WLANTEST_CTRL_SUCCESS);
  845. eloop_terminate();
  846. break;
  847. case WLANTEST_CTRL_LIST_BSS:
  848. ctrl_list_bss(wt, sock);
  849. break;
  850. case WLANTEST_CTRL_LIST_STA:
  851. ctrl_list_sta(wt, sock, buf + 4, len - 4);
  852. break;
  853. case WLANTEST_CTRL_FLUSH:
  854. ctrl_flush(wt, sock);
  855. break;
  856. case WLANTEST_CTRL_CLEAR_STA_COUNTERS:
  857. ctrl_clear_sta_counters(wt, sock, buf + 4, len - 4);
  858. break;
  859. case WLANTEST_CTRL_CLEAR_BSS_COUNTERS:
  860. ctrl_clear_bss_counters(wt, sock, buf + 4, len - 4);
  861. break;
  862. case WLANTEST_CTRL_GET_STA_COUNTER:
  863. ctrl_get_sta_counter(wt, sock, buf + 4, len - 4);
  864. break;
  865. case WLANTEST_CTRL_GET_BSS_COUNTER:
  866. ctrl_get_bss_counter(wt, sock, buf + 4, len - 4);
  867. break;
  868. case WLANTEST_CTRL_INJECT:
  869. ctrl_inject(wt, sock, buf + 4, len - 4);
  870. break;
  871. case WLANTEST_CTRL_VERSION:
  872. ctrl_version(wt, sock);
  873. break;
  874. case WLANTEST_CTRL_ADD_PASSPHRASE:
  875. ctrl_add_passphrase(wt, sock, buf + 4, len - 4);
  876. break;
  877. case WLANTEST_CTRL_INFO_STA:
  878. ctrl_info_sta(wt, sock, buf + 4, len - 4);
  879. break;
  880. case WLANTEST_CTRL_INFO_BSS:
  881. ctrl_info_bss(wt, sock, buf + 4, len - 4);
  882. break;
  883. default:
  884. ctrl_send_simple(wt, sock, WLANTEST_CTRL_UNKNOWN_CMD);
  885. break;
  886. }
  887. }
  888. static void ctrl_connect(int sock, void *eloop_ctx, void *sock_ctx)
  889. {
  890. struct wlantest *wt = eloop_ctx;
  891. int conn, i;
  892. conn = accept(sock, NULL, NULL);
  893. if (conn < 0) {
  894. wpa_printf(MSG_INFO, "accept(ctrl): %s", strerror(errno));
  895. return;
  896. }
  897. wpa_printf(MSG_MSGDUMP, "New control interface connection %d", conn);
  898. for (i = 0; i < MAX_CTRL_CONNECTIONS; i++) {
  899. if (wt->ctrl_socks[i] < 0)
  900. break;
  901. }
  902. if (i == MAX_CTRL_CONNECTIONS) {
  903. wpa_printf(MSG_INFO, "No room for new control connection");
  904. close(conn);
  905. return;
  906. }
  907. wt->ctrl_socks[i] = conn;
  908. eloop_register_read_sock(conn, ctrl_read, wt, NULL);
  909. }
  910. int ctrl_init(struct wlantest *wt)
  911. {
  912. struct sockaddr_un addr;
  913. wt->ctrl_sock = socket(AF_UNIX, SOCK_SEQPACKET, 0);
  914. if (wt->ctrl_sock < 0) {
  915. wpa_printf(MSG_ERROR, "socket: %s", strerror(errno));
  916. return -1;
  917. }
  918. os_memset(&addr, 0, sizeof(addr));
  919. addr.sun_family = AF_UNIX;
  920. os_strlcpy(addr.sun_path + 1, WLANTEST_SOCK_NAME,
  921. sizeof(addr.sun_path) - 1);
  922. if (bind(wt->ctrl_sock, (struct sockaddr *) &addr, sizeof(addr)) < 0) {
  923. wpa_printf(MSG_ERROR, "bind: %s", strerror(errno));
  924. close(wt->ctrl_sock);
  925. wt->ctrl_sock = -1;
  926. return -1;
  927. }
  928. if (listen(wt->ctrl_sock, 5) < 0) {
  929. wpa_printf(MSG_ERROR, "listen: %s", strerror(errno));
  930. close(wt->ctrl_sock);
  931. wt->ctrl_sock = -1;
  932. return -1;
  933. }
  934. if (eloop_register_read_sock(wt->ctrl_sock, ctrl_connect, wt, NULL)) {
  935. close(wt->ctrl_sock);
  936. wt->ctrl_sock = -1;
  937. return -1;
  938. }
  939. return 0;
  940. }
  941. void ctrl_deinit(struct wlantest *wt)
  942. {
  943. int i;
  944. if (wt->ctrl_sock < 0)
  945. return;
  946. for (i = 0; i < MAX_CTRL_CONNECTIONS; i++) {
  947. if (wt->ctrl_socks[i] >= 0) {
  948. close(wt->ctrl_socks[i]);
  949. eloop_unregister_read_sock(wt->ctrl_socks[i]);
  950. wt->ctrl_socks[i] = -1;
  951. }
  952. }
  953. eloop_unregister_read_sock(wt->ctrl_sock);
  954. close(wt->ctrl_sock);
  955. wt->ctrl_sock = -1;
  956. }