Coverage Report

Created: 2026-09-03 06:18

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/hostap/wpa_supplicant/wpa_supplicant.c
Line
Count
Source
1
/*
2
 * WPA Supplicant
3
 * Copyright (c) 2003-2024, Jouni Malinen <j@w1.fi>
4
 *
5
 * This software may be distributed under the terms of the BSD license.
6
 * See README for more details.
7
 *
8
 * This file implements functions for registering and unregistering
9
 * %wpa_supplicant interfaces. In addition, this file contains number of
10
 * functions for managing network connections.
11
 */
12
13
#include "includes.h"
14
#ifdef CONFIG_MATCH_IFACE
15
#include <net/if.h>
16
#include <fnmatch.h>
17
#endif /* CONFIG_MATCH_IFACE */
18
19
#include "common.h"
20
#include "crypto/crypto.h"
21
#include "crypto/random.h"
22
#include "crypto/sha1.h"
23
#include "eapol_supp/eapol_supp_sm.h"
24
#include "eap_peer/eap.h"
25
#include "eap_peer/eap_proxy.h"
26
#include "eap_server/eap_methods.h"
27
#include "rsn_supp/wpa.h"
28
#include "eloop.h"
29
#include "config.h"
30
#include "utils/ext_password.h"
31
#include "l2_packet/l2_packet.h"
32
#include "wpa_supplicant_i.h"
33
#include "driver_i.h"
34
#include "ctrl_iface.h"
35
#include "pcsc_funcs.h"
36
#include "common/version.h"
37
#include "rsn_supp/preauth.h"
38
#include "rsn_supp/pmksa_cache.h"
39
#include "rsn_supp/wpa_ie.h"
40
#include "common/wpa_ctrl.h"
41
#include "common/ieee802_11_common.h"
42
#include "common/ieee802_11_defs.h"
43
#include "common/hw_features_common.h"
44
#include "common/gas_server.h"
45
#include "common/dpp.h"
46
#include "common/ptksa_cache.h"
47
#include "common/proc_coord.h"
48
#include "p2p/p2p.h"
49
#include "fst/fst.h"
50
#include "bssid_ignore.h"
51
#include "wpas_glue.h"
52
#include "wps_supplicant.h"
53
#include "ibss_rsn.h"
54
#include "sme.h"
55
#include "gas_query.h"
56
#include "ap.h"
57
#include "p2p_supplicant.h"
58
#include "wifi_display.h"
59
#include "notify.h"
60
#include "bgscan.h"
61
#include "autoscan.h"
62
#include "bss.h"
63
#include "scan.h"
64
#include "offchannel.h"
65
#include "hs20_supplicant.h"
66
#include "wnm_sta.h"
67
#include "wpas_kay.h"
68
#include "mesh.h"
69
#include "dpp_supplicant.h"
70
#include "pr_supplicant.h"
71
#include "nan_supplicant.h"
72
#ifdef CONFIG_MESH
73
#include "ap/ap_config.h"
74
#include "ap/hostapd.h"
75
#endif /* CONFIG_MESH */
76
77
const char *const wpa_supplicant_version =
78
"wpa_supplicant v" VERSION_STR "\n"
79
"Copyright (c) 2003-2026, Jouni Malinen <j@w1.fi> and contributors";
80
81
const char *const wpa_supplicant_license =
82
"This software may be distributed under the terms of the BSD license.\n"
83
"See README for more details.\n"
84
#ifdef EAP_TLS_OPENSSL
85
"\nThis product includes software developed by the OpenSSL Project\n"
86
"for use in the OpenSSL Toolkit (http://www.openssl.org/)\n"
87
#endif /* EAP_TLS_OPENSSL */
88
;
89
90
#ifndef CONFIG_NO_STDOUT_DEBUG
91
/* Long text divided into parts in order to fit in C89 strings size limits. */
92
const char *const wpa_supplicant_full_license1 =
93
"";
94
const char *const wpa_supplicant_full_license2 =
95
"This software may be distributed under the terms of the BSD license.\n"
96
"\n"
97
"Redistribution and use in source and binary forms, with or without\n"
98
"modification, are permitted provided that the following conditions are\n"
99
"met:\n"
100
"\n";
101
const char *const wpa_supplicant_full_license3 =
102
"1. Redistributions of source code must retain the above copyright\n"
103
"   notice, this list of conditions and the following disclaimer.\n"
104
"\n"
105
"2. Redistributions in binary form must reproduce the above copyright\n"
106
"   notice, this list of conditions and the following disclaimer in the\n"
107
"   documentation and/or other materials provided with the distribution.\n"
108
"\n";
109
const char *const wpa_supplicant_full_license4 =
110
"3. Neither the name(s) of the above-listed copyright holder(s) nor the\n"
111
"   names of its contributors may be used to endorse or promote products\n"
112
"   derived from this software without specific prior written permission.\n"
113
"\n"
114
"THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS\n"
115
"\"AS IS\" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT\n"
116
"LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR\n"
117
"A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT\n";
118
const char *const wpa_supplicant_full_license5 =
119
"OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,\n"
120
"SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT\n"
121
"LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,\n"
122
"DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY\n"
123
"THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT\n"
124
"(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE\n"
125
"OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.\n"
126
"\n";
127
#endif /* CONFIG_NO_STDOUT_DEBUG */
128
129
130
static void wpa_bss_tmp_disallow_timeout(void *eloop_ctx, void *timeout_ctx);
131
static void wpas_verify_ssid_beacon(void *eloop_ctx, void *timeout_ctx);
132
#if defined(CONFIG_FILS) && defined(IEEE8021X_EAPOL)
133
static void wpas_update_fils_connect_params(struct wpa_supplicant *wpa_s);
134
#endif /* CONFIG_FILS && IEEE8021X_EAPOL */
135
#ifdef CONFIG_OWE
136
static void wpas_update_owe_connect_params(struct wpa_supplicant *wpa_s);
137
#endif /* CONFIG_OWE */
138
static void radio_remove_pending_connect(struct wpa_supplicant *wpa_s,
139
           const struct wpa_ssid *ssid);
140
141
142
#ifdef CONFIG_WEP
143
/* Configure default/group WEP keys for static WEP */
144
int wpa_set_wep_keys(struct wpa_supplicant *wpa_s, struct wpa_ssid *ssid)
145
{
146
  int i, set = 0;
147
148
  for (i = 0; i < NUM_WEP_KEYS; i++) {
149
    if (ssid->wep_key_len[i] == 0)
150
      continue;
151
152
    set = 1;
153
    wpa_drv_set_key(wpa_s, -1, WPA_ALG_WEP, NULL,
154
        i, i == ssid->wep_tx_keyidx, NULL, 0,
155
        ssid->wep_key[i], ssid->wep_key_len[i],
156
        i == ssid->wep_tx_keyidx ?
157
        KEY_FLAG_GROUP_RX_TX_DEFAULT :
158
        KEY_FLAG_GROUP_RX_TX);
159
  }
160
161
  return set;
162
}
163
#endif /* CONFIG_WEP */
164
165
166
int wpa_supplicant_set_wpa_none_key(struct wpa_supplicant *wpa_s,
167
            struct wpa_ssid *ssid)
168
0
{
169
0
  u8 key[32];
170
0
  size_t keylen;
171
0
  enum wpa_alg alg;
172
0
  u8 seq[6] = { 0 };
173
0
  int ret;
174
175
  /* IBSS/WPA-None uses only one key (Group) for both receiving and
176
   * sending unicast and multicast packets. */
177
178
0
  if (ssid->mode != WPAS_MODE_IBSS) {
179
0
    wpa_msg(wpa_s, MSG_INFO, "WPA: Invalid mode %d (not "
180
0
      "IBSS/ad-hoc) for WPA-None", ssid->mode);
181
0
    return -1;
182
0
  }
183
184
0
  if (!ssid->psk_set) {
185
0
    wpa_msg(wpa_s, MSG_INFO, "WPA: No PSK configured for "
186
0
      "WPA-None");
187
0
    return -1;
188
0
  }
189
190
0
  switch (wpa_s->group_cipher) {
191
0
  case WPA_CIPHER_CCMP:
192
0
    os_memcpy(key, ssid->psk, 16);
193
0
    keylen = 16;
194
0
    alg = WPA_ALG_CCMP;
195
0
    break;
196
0
  case WPA_CIPHER_GCMP:
197
0
    os_memcpy(key, ssid->psk, 16);
198
0
    keylen = 16;
199
0
    alg = WPA_ALG_GCMP;
200
0
    break;
201
0
  case WPA_CIPHER_TKIP:
202
    /* WPA-None uses the same Michael MIC key for both TX and RX */
203
0
    os_memcpy(key, ssid->psk, 16 + 8);
204
0
    os_memcpy(key + 16 + 8, ssid->psk + 16, 8);
205
0
    keylen = 32;
206
0
    alg = WPA_ALG_TKIP;
207
0
    break;
208
0
  default:
209
0
    wpa_msg(wpa_s, MSG_INFO, "WPA: Invalid group cipher %d for "
210
0
      "WPA-None", wpa_s->group_cipher);
211
0
    return -1;
212
0
  }
213
214
  /* TODO: should actually remember the previously used seq#, both for TX
215
   * and RX from each STA.. */
216
217
0
  ret = wpa_drv_set_key(wpa_s, -1, alg, NULL, 0, 1, seq, 6, key, keylen,
218
0
            KEY_FLAG_GROUP_RX_TX_DEFAULT);
219
0
  os_memset(key, 0, sizeof(key));
220
0
  return ret;
221
0
}
222
223
224
static void wpa_supplicant_timeout(void *eloop_ctx, void *timeout_ctx)
225
0
{
226
0
  struct wpa_supplicant *wpa_s = eloop_ctx;
227
0
  const u8 *bssid = wpa_s->bssid;
228
0
  if (!is_zero_ether_addr(wpa_s->pending_bssid) &&
229
0
      (wpa_s->wpa_state == WPA_AUTHENTICATING ||
230
0
       wpa_s->wpa_state == WPA_ASSOCIATING))
231
0
    bssid = wpa_s->pending_bssid;
232
0
  wpa_msg(wpa_s, MSG_INFO, "Authentication with " MACSTR " timed out.",
233
0
    MAC2STR(bssid));
234
0
  wpa_bssid_ignore_add(wpa_s, bssid);
235
0
  wpa_sm_notify_disassoc(wpa_s->wpa);
236
0
  wpa_supplicant_deauthenticate(wpa_s, WLAN_REASON_DEAUTH_LEAVING);
237
0
  wpa_s->reassociate = 1;
238
239
  /*
240
   * If we timed out, the AP or the local radio may be busy.
241
   * So, wait a second until scanning again.
242
   */
243
0
  wpa_supplicant_req_scan(wpa_s, 1, 0);
244
0
}
245
246
247
/**
248
 * wpa_supplicant_req_auth_timeout - Schedule a timeout for authentication
249
 * @wpa_s: Pointer to wpa_supplicant data
250
 * @sec: Number of seconds after which to time out authentication
251
 * @usec: Number of microseconds after which to time out authentication
252
 *
253
 * This function is used to schedule a timeout for the current authentication
254
 * attempt.
255
 */
256
void wpa_supplicant_req_auth_timeout(struct wpa_supplicant *wpa_s,
257
             int sec, int usec)
258
0
{
259
0
  if (wpa_s->conf->ap_scan == 0 &&
260
0
      (wpa_s->drv_flags & WPA_DRIVER_FLAGS_WIRED))
261
0
    return;
262
263
0
  wpa_dbg(wpa_s, MSG_DEBUG, "Setting authentication timeout: %d sec "
264
0
    "%d usec", sec, usec);
265
0
  eloop_cancel_timeout(wpa_supplicant_timeout, wpa_s, NULL);
266
0
  wpa_s->last_auth_timeout_sec = sec;
267
0
  eloop_register_timeout(sec, usec, wpa_supplicant_timeout, wpa_s, NULL);
268
0
}
269
270
271
/*
272
 * wpas_auth_timeout_restart - Restart and change timeout for authentication
273
 * @wpa_s: Pointer to wpa_supplicant data
274
 * @sec_diff: difference in seconds applied to original timeout value
275
 */
276
void wpas_auth_timeout_restart(struct wpa_supplicant *wpa_s, int sec_diff)
277
0
{
278
0
  int new_sec = wpa_s->last_auth_timeout_sec + sec_diff;
279
280
0
  if (eloop_is_timeout_registered(wpa_supplicant_timeout, wpa_s, NULL)) {
281
0
    wpa_dbg(wpa_s, MSG_DEBUG,
282
0
      "Authentication timeout restart: %d sec", new_sec);
283
0
    eloop_cancel_timeout(wpa_supplicant_timeout, wpa_s, NULL);
284
0
    eloop_register_timeout(new_sec, 0, wpa_supplicant_timeout,
285
0
               wpa_s, NULL);
286
0
  }
287
0
}
288
289
290
/**
291
 * wpa_supplicant_cancel_auth_timeout - Cancel authentication timeout
292
 * @wpa_s: Pointer to wpa_supplicant data
293
 *
294
 * This function is used to cancel authentication timeout scheduled with
295
 * wpa_supplicant_req_auth_timeout() and it is called when authentication has
296
 * been completed.
297
 */
298
void wpa_supplicant_cancel_auth_timeout(struct wpa_supplicant *wpa_s)
299
0
{
300
0
  wpa_dbg(wpa_s, MSG_DEBUG, "Cancelling authentication timeout");
301
0
  eloop_cancel_timeout(wpa_supplicant_timeout, wpa_s, NULL);
302
0
  wpa_bssid_ignore_del(wpa_s, wpa_s->bssid);
303
0
  os_free(wpa_s->last_con_fail_realm);
304
0
  wpa_s->last_con_fail_realm = NULL;
305
0
  wpa_s->last_con_fail_realm_len = 0;
306
0
}
307
308
309
/**
310
 * wpa_supplicant_initiate_eapol - Configure EAPOL state machine
311
 * @wpa_s: Pointer to wpa_supplicant data
312
 *
313
 * This function is used to configure EAPOL state machine based on the selected
314
 * authentication mode.
315
 */
316
void wpa_supplicant_initiate_eapol(struct wpa_supplicant *wpa_s)
317
0
{
318
0
#ifdef IEEE8021X_EAPOL
319
0
  struct eapol_config eapol_conf;
320
0
  struct wpa_ssid *ssid = wpa_s->current_ssid;
321
322
#ifdef CONFIG_IBSS_RSN
323
  if (ssid->mode == WPAS_MODE_IBSS &&
324
      wpa_s->key_mgmt != WPA_KEY_MGMT_NONE &&
325
      wpa_s->key_mgmt != WPA_KEY_MGMT_WPA_NONE) {
326
    /*
327
     * RSN IBSS authentication is per-STA and we can disable the
328
     * per-BSSID EAPOL authentication.
329
     */
330
    eapol_sm_notify_portControl(wpa_s->eapol, ForceAuthorized);
331
    eapol_sm_notify_eap_success(wpa_s->eapol, true);
332
    eapol_sm_notify_eap_fail(wpa_s->eapol, false);
333
    return;
334
  }
335
#endif /* CONFIG_IBSS_RSN */
336
337
0
  eapol_sm_notify_eap_success(wpa_s->eapol, false);
338
0
  eapol_sm_notify_eap_fail(wpa_s->eapol, false);
339
340
0
  if (wpa_s->key_mgmt == WPA_KEY_MGMT_NONE ||
341
0
      wpa_s->key_mgmt == WPA_KEY_MGMT_WPA_NONE)
342
0
    eapol_sm_notify_portControl(wpa_s->eapol, ForceAuthorized);
343
0
  else
344
0
    eapol_sm_notify_portControl(wpa_s->eapol, Auto);
345
346
0
  os_memset(&eapol_conf, 0, sizeof(eapol_conf));
347
0
  if (wpa_s->key_mgmt == WPA_KEY_MGMT_IEEE8021X_NO_WPA) {
348
0
    eapol_conf.accept_802_1x_keys = 1;
349
0
    eapol_conf.required_keys = 0;
350
0
    if (ssid->eapol_flags & EAPOL_FLAG_REQUIRE_KEY_UNICAST) {
351
0
      eapol_conf.required_keys |= EAPOL_REQUIRE_KEY_UNICAST;
352
0
    }
353
0
    if (ssid->eapol_flags & EAPOL_FLAG_REQUIRE_KEY_BROADCAST) {
354
0
      eapol_conf.required_keys |=
355
0
        EAPOL_REQUIRE_KEY_BROADCAST;
356
0
    }
357
358
0
    if (wpa_s->drv_flags & WPA_DRIVER_FLAGS_WIRED)
359
0
      eapol_conf.required_keys = 0;
360
0
  }
361
0
  eapol_conf.fast_reauth = wpa_s->conf->fast_reauth;
362
0
  eapol_conf.workaround = ssid->eap_workaround;
363
0
  eapol_conf.eap_disabled =
364
0
    !wpa_key_mgmt_wpa_ieee8021x(wpa_s->key_mgmt) &&
365
0
    wpa_s->key_mgmt != WPA_KEY_MGMT_IEEE8021X_NO_WPA &&
366
0
    wpa_s->key_mgmt != WPA_KEY_MGMT_WPS;
367
0
  eapol_conf.external_sim = wpa_s->conf->external_sim;
368
369
#ifdef CONFIG_WPS
370
0
  if (wpa_s->key_mgmt == WPA_KEY_MGMT_WPS) {
371
0
    eapol_conf.wps |= EAPOL_LOCAL_WPS_IN_USE;
372
0
    if (wpa_s->current_bss) {
373
0
      struct wpabuf *ie;
374
0
      ie = wpa_bss_get_vendor_ie_multi(wpa_s->current_bss,
375
0
               WPS_IE_VENDOR_TYPE);
376
0
      if (ie) {
377
0
        if (wps_is_20(ie))
378
0
          eapol_conf.wps |=
379
0
            EAPOL_PEER_IS_WPS20_AP;
380
0
        wpabuf_free(ie);
381
0
      }
382
0
    }
383
0
  }
384
#endif /* CONFIG_WPS */
385
386
0
  eapol_sm_notify_config(wpa_s->eapol, &ssid->eap, &eapol_conf);
387
388
#ifdef CONFIG_MACSEC
389
  if (wpa_s->key_mgmt == WPA_KEY_MGMT_NONE && ssid->mka_psk_set)
390
    ieee802_1x_create_preshared_mka(wpa_s, ssid);
391
  else
392
    ieee802_1x_alloc_kay_sm(wpa_s, ssid);
393
#endif /* CONFIG_MACSEC */
394
0
#endif /* IEEE8021X_EAPOL */
395
0
}
Unexecuted instantiation: wpa_supplicant_initiate_eapol
Unexecuted instantiation: wpa_supplicant_initiate_eapol
396
397
398
/**
399
 * wpa_supplicant_set_non_wpa_policy - Set WPA parameters to non-WPA mode
400
 * @wpa_s: Pointer to wpa_supplicant data
401
 * @ssid: Configuration data for the network
402
 *
403
 * This function is used to configure WPA state machine and related parameters
404
 * to a mode where WPA is not enabled. This is called as part of the
405
 * authentication configuration when the selected network does not use WPA.
406
 */
407
void wpa_supplicant_set_non_wpa_policy(struct wpa_supplicant *wpa_s,
408
               struct wpa_ssid *ssid)
409
0
{
410
#ifdef CONFIG_WEP
411
  int i;
412
#endif /* CONFIG_WEP */
413
0
  struct wpa_sm_mlo mlo;
414
415
0
  if (ssid->key_mgmt & WPA_KEY_MGMT_WPS)
416
0
    wpa_s->key_mgmt = WPA_KEY_MGMT_WPS;
417
0
  else if (ssid->key_mgmt & WPA_KEY_MGMT_IEEE8021X_NO_WPA)
418
0
    wpa_s->key_mgmt = WPA_KEY_MGMT_IEEE8021X_NO_WPA;
419
0
  else
420
0
    wpa_s->key_mgmt = WPA_KEY_MGMT_NONE;
421
0
  wpa_sm_set_ap_wpa_ie(wpa_s->wpa, NULL, 0);
422
0
  wpa_sm_set_ap_rsn_ie(wpa_s->wpa, NULL, 0);
423
0
  wpa_sm_set_ap_rsnxe(wpa_s->wpa, NULL, 0);
424
0
  wpa_sm_set_ap_rsne_override(wpa_s->wpa, NULL, 0);
425
0
  wpa_sm_set_ap_rsne_override_2(wpa_s->wpa, NULL, 0);
426
0
  wpa_sm_set_ap_rsnxe_override(wpa_s->wpa, NULL, 0);
427
0
  wpa_sm_set_ap_security_profile(wpa_s->wpa, NULL, 0);
428
0
  wpa_sm_set_assoc_wpa_ie(wpa_s->wpa, NULL, 0);
429
0
#ifndef CONFIG_NO_WPA
430
0
  wpa_sm_set_assoc_rsnxe(wpa_s->wpa, NULL, 0);
431
0
#endif /* CONFIG_NO_WPA */
432
0
  wpa_s->rsnxe_len = 0;
433
0
  wpa_s->sel_security_profile = -1;
434
0
  wpa_s->security_profile_len = 0;
435
0
  wpa_s->pairwise_cipher = WPA_CIPHER_NONE;
436
0
  wpa_s->group_cipher = WPA_CIPHER_NONE;
437
0
  wpa_s->mgmt_group_cipher = 0;
438
439
#ifdef CONFIG_WEP
440
  for (i = 0; i < NUM_WEP_KEYS; i++) {
441
    if (ssid->wep_key_len[i] > 5) {
442
      wpa_s->pairwise_cipher = WPA_CIPHER_WEP104;
443
      wpa_s->group_cipher = WPA_CIPHER_WEP104;
444
      break;
445
    } else if (ssid->wep_key_len[i] > 0) {
446
      wpa_s->pairwise_cipher = WPA_CIPHER_WEP40;
447
      wpa_s->group_cipher = WPA_CIPHER_WEP40;
448
      break;
449
    }
450
  }
451
#endif /* CONFIG_WEP */
452
453
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_RSN_ENABLED, 0);
454
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_KEY_MGMT, wpa_s->key_mgmt);
455
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_PAIRWISE,
456
0
       wpa_s->pairwise_cipher);
457
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_GROUP, wpa_s->group_cipher);
458
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_MGMT_GROUP,
459
0
       wpa_s->mgmt_group_cipher);
460
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_SSID_PROTECTION, 0);
461
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_ASSOC_ENC, 0);
462
463
0
  pmksa_cache_clear_current(wpa_s->wpa);
464
0
  os_memset(&mlo, 0, sizeof(mlo));
465
0
  wpa_sm_set_mlo_params(wpa_s->wpa, &mlo);
466
0
}
467
468
469
void free_hw_features(struct wpa_supplicant *wpa_s)
470
0
{
471
0
  int i;
472
0
  if (wpa_s->hw.modes == NULL)
473
0
    return;
474
475
0
  for (i = 0; i < wpa_s->hw.num_modes; i++) {
476
0
    os_free(wpa_s->hw.modes[i].channels);
477
0
    os_free(wpa_s->hw.modes[i].rates);
478
0
  }
479
480
0
  os_free(wpa_s->hw.modes);
481
0
  wpa_s->hw.modes = NULL;
482
0
}
483
484
485
static void remove_bss_tmp_disallowed_entry(struct wpa_supplicant *wpa_s,
486
              struct wpa_bss_tmp_disallowed *bss)
487
0
{
488
0
  eloop_cancel_timeout(wpa_bss_tmp_disallow_timeout, wpa_s, bss);
489
0
  dl_list_del(&bss->list);
490
0
  os_free(bss);
491
0
}
492
493
494
void free_bss_tmp_disallowed(struct wpa_supplicant *wpa_s)
495
0
{
496
0
  struct wpa_bss_tmp_disallowed *bss, *prev;
497
498
0
  dl_list_for_each_safe(bss, prev, &wpa_s->bss_tmp_disallowed,
499
0
            struct wpa_bss_tmp_disallowed, list)
500
0
    remove_bss_tmp_disallowed_entry(wpa_s, bss);
501
0
}
502
503
504
void wpas_flush_fils_hlp_req(struct wpa_supplicant *wpa_s)
505
0
{
506
0
  struct fils_hlp_req *req;
507
508
0
  while ((req = dl_list_first(&wpa_s->fils_hlp_req, struct fils_hlp_req,
509
0
            list)) != NULL) {
510
0
    dl_list_del(&req->list);
511
0
    wpabuf_free(req->pkt);
512
0
    os_free(req);
513
0
  }
514
0
}
515
516
517
static struct wpabuf * wpas_wfa_gen_capab_attr(struct wpa_supplicant *wpa_s)
518
0
{
519
0
  struct wpabuf *attr;
520
0
  size_t gen_len, supp_len;
521
0
  const u8 *supp;
522
0
  u8 supp_buf[1];
523
524
0
  if (wpa_s->conf->wfa_gen_capa == WFA_GEN_CAPA_DISABLED)
525
0
    return NULL;
526
527
0
  if (!wpa_s->conf->wfa_gen_capa_supp ||
528
0
      wpabuf_len(wpa_s->conf->wfa_gen_capa_supp) == 0) {
529
0
    supp_len = 1;
530
0
    supp_buf[0] = 0;
531
0
    if (wpa_s->hw_capab & BIT(CAPAB_HT))
532
0
      supp_buf[0] |= BIT(0); /* Wi-Fi 4 */
533
0
    if (wpa_s->hw_capab & BIT(CAPAB_VHT))
534
0
      supp_buf[0] |= BIT(1); /* Wi-Fi 5 */
535
0
    if (wpa_s->hw_capab & BIT(CAPAB_HE))
536
0
      supp_buf[0] |= BIT(2); /* Wi-Fi 6 */
537
0
    if (wpa_s->hw_capab & BIT(CAPAB_EHT))
538
0
      supp_buf[0] |= BIT(3); /* Wi-Fi 7 */
539
0
    supp = supp_buf;
540
0
  } else {
541
0
    supp_len = wpabuf_len(wpa_s->conf->wfa_gen_capa_supp);
542
0
    supp = wpabuf_head(wpa_s->conf->wfa_gen_capa_supp);
543
0
  }
544
545
0
  gen_len = 1 + supp_len;
546
547
0
  attr = wpabuf_alloc(2 + gen_len);
548
0
  if (!attr)
549
0
    return NULL;
550
551
0
  wpabuf_put_u8(attr, WFA_CAPA_ATTR_GENERATIONAL_CAPAB);
552
0
  wpabuf_put_u8(attr, gen_len);
553
0
  wpabuf_put_u8(attr, supp_len);
554
0
  wpabuf_put_data(attr, supp, supp_len);
555
556
0
  return attr;
557
0
}
558
559
560
561
static void wpas_wfa_capab_tx(void *eloop_ctx, void *timeout_ctx)
562
0
{
563
0
  struct wpa_supplicant *wpa_s = eloop_ctx;
564
0
  struct wpabuf *attr, *buf;
565
0
  size_t buf_len;
566
567
0
  if (wpa_s->conf->wfa_gen_capa != WFA_GEN_CAPA_PROTECTED ||
568
0
      wpa_s->wpa_state != WPA_COMPLETED ||
569
0
      !pmf_in_use(wpa_s, wpa_s->bssid))
570
0
    return;
571
572
0
  attr = wpas_wfa_gen_capab_attr(wpa_s);
573
0
  if (!attr)
574
0
    return;
575
576
0
  buf_len = 1 + 3 + 1 + 1 + wpabuf_len(attr);
577
0
  buf = wpabuf_alloc(buf_len);
578
0
  if (!buf) {
579
0
    wpabuf_free(attr);
580
0
    return;
581
0
  }
582
583
0
  wpabuf_put_u8(buf, WLAN_ACTION_VENDOR_SPECIFIC_PROTECTED);
584
0
  wpabuf_put_be32(buf, WFA_CAPAB_VENDOR_TYPE);
585
0
  wpabuf_put_u8(buf, 0); /* Capabilities Length */
586
0
  wpabuf_put_buf(buf, attr);
587
0
  wpabuf_free(attr);
588
589
0
  wpa_printf(MSG_DEBUG, "WFA: Send WFA Capabilities frame");
590
0
  if (wpa_drv_send_action(wpa_s, wpa_s->assoc_freq, 0, wpa_s->bssid,
591
0
        wpa_s->own_addr, wpa_s->bssid,
592
0
        wpabuf_head(buf), wpabuf_len(buf), 0) < 0)
593
0
    wpa_printf(MSG_DEBUG,
594
0
         "WFA: Failed to send WFA Capabilities frame");
595
596
0
  wpabuf_free(buf);
597
0
}
598
599
600
void wpas_clear_disabled_interface(void *eloop_ctx, void *timeout_ctx)
601
0
{
602
0
  struct wpa_supplicant *wpa_s = eloop_ctx;
603
604
0
  if (wpa_s->wpa_state != WPA_INTERFACE_DISABLED)
605
0
    return;
606
0
  wpa_dbg(wpa_s, MSG_DEBUG, "Clear cached state on disabled interface");
607
0
  wpa_bss_flush(wpa_s);
608
0
}
609
610
611
#ifdef CONFIG_TESTING_OPTIONS
612
void wpas_clear_driver_signal_override(struct wpa_supplicant *wpa_s)
613
{
614
  struct driver_signal_override *dso;
615
616
  while ((dso = dl_list_first(&wpa_s->drv_signal_override,
617
            struct driver_signal_override, list))) {
618
    dl_list_del(&dso->list);
619
    os_free(dso);
620
  }
621
}
622
#endif /* CONFIG_TESTING_OPTIONS */
623
624
625
static void wpa_supplicant_cleanup(struct wpa_supplicant *wpa_s)
626
0
{
627
0
  int i;
628
629
0
  bgscan_deinit(wpa_s);
630
0
  autoscan_deinit(wpa_s);
631
0
  scard_deinit(wpa_s->scard);
632
0
  wpa_s->scard = NULL;
633
0
  wpa_sm_set_scard_ctx(wpa_s->wpa, NULL);
634
0
  eapol_sm_register_scard_ctx(wpa_s->eapol, NULL);
635
0
  l2_packet_deinit(wpa_s->l2);
636
0
  wpa_s->l2 = NULL;
637
0
  if (wpa_s->l2_br) {
638
0
    l2_packet_deinit(wpa_s->l2_br);
639
0
    wpa_s->l2_br = NULL;
640
0
  }
641
#ifdef CONFIG_TESTING_OPTIONS
642
  l2_packet_deinit(wpa_s->l2_test);
643
  wpa_s->l2_test = NULL;
644
  os_free(wpa_s->get_pref_freq_list_override);
645
  wpa_s->get_pref_freq_list_override = NULL;
646
  wpabuf_free(wpa_s->last_assoc_req_wpa_ie);
647
  wpa_s->last_assoc_req_wpa_ie = NULL;
648
  os_free(wpa_s->extra_sae_rejected_groups);
649
  wpa_s->extra_sae_rejected_groups = NULL;
650
  wpabuf_free(wpa_s->rsne_override_eapol);
651
  wpa_s->rsne_override_eapol = NULL;
652
  wpabuf_free(wpa_s->rsnxe_override_assoc);
653
  wpa_s->rsnxe_override_assoc = NULL;
654
  wpabuf_free(wpa_s->rsnxe_override_eapol);
655
  wpa_s->rsnxe_override_eapol = NULL;
656
  wpabuf_free(wpa_s->sec_prof_override_auth);
657
  wpa_s->sec_prof_override_auth = NULL;
658
  wpabuf_free(wpa_s->sec_prof_override_assoc);
659
  wpa_s->sec_prof_override_assoc = NULL;
660
  wpas_clear_driver_signal_override(wpa_s);
661
  for (i = 0; i < MAX_NUM_MLD_LINKS; i++) {
662
    wpabuf_free(wpa_s->link_ies[i]);
663
    wpa_s->link_ies[i] = NULL;
664
  }
665
#endif /* CONFIG_TESTING_OPTIONS */
666
667
0
  if (wpa_s->conf != NULL) {
668
0
    struct wpa_ssid *ssid;
669
0
    for (ssid = wpa_s->conf->ssid; ssid; ssid = ssid->next)
670
0
      wpas_notify_network_removed(wpa_s, ssid);
671
0
  }
672
673
0
  os_free(wpa_s->confname);
674
0
  wpa_s->confname = NULL;
675
676
0
  os_free(wpa_s->confanother);
677
0
  wpa_s->confanother = NULL;
678
679
0
  os_free(wpa_s->last_con_fail_realm);
680
0
  wpa_s->last_con_fail_realm = NULL;
681
0
  wpa_s->last_con_fail_realm_len = 0;
682
683
0
  wpa_sm_set_eapol(wpa_s->wpa, NULL);
684
0
  eapol_sm_deinit(wpa_s->eapol);
685
0
  wpa_s->eapol = NULL;
686
687
0
  rsn_preauth_deinit(wpa_s->wpa);
688
689
#ifdef CONFIG_TDLS
690
  wpa_tdls_deinit(wpa_s->wpa);
691
#endif /* CONFIG_TDLS */
692
693
0
#ifndef CONFIG_NO_WMM_AC
694
0
  wmm_ac_clear_saved_tspecs(wpa_s);
695
0
#endif /* CONFIG_NO_WMM_AC */
696
0
  pmksa_candidate_free(wpa_s->wpa);
697
0
  ptksa_cache_deinit(wpa_s->ptksa);
698
0
  wpa_s->ptksa = NULL;
699
0
  wpa_sm_deinit(wpa_s->wpa);
700
0
  wpa_s->wpa = NULL;
701
0
  wpa_bssid_ignore_clear(wpa_s);
702
703
#ifdef CONFIG_PASN
704
  wpas_pasn_auth_stop(wpa_s);
705
#endif /* CONFIG_PASN */
706
707
0
  wpa_bss_deinit(wpa_s);
708
709
0
  wpa_supplicant_cancel_delayed_sched_scan(wpa_s);
710
0
  wpa_supplicant_cancel_scan(wpa_s);
711
0
  wpa_supplicant_cancel_auth_timeout(wpa_s);
712
0
  eloop_cancel_timeout(wpa_supplicant_stop_countermeasures, wpa_s, NULL);
713
#ifdef CONFIG_DELAYED_MIC_ERROR_REPORT
714
  eloop_cancel_timeout(wpa_supplicant_delayed_mic_error_report,
715
           wpa_s, NULL);
716
#endif /* CONFIG_DELAYED_MIC_ERROR_REPORT */
717
718
0
  eloop_cancel_timeout(wpas_network_reenabled, wpa_s, NULL);
719
0
  eloop_cancel_timeout(wpas_clear_disabled_interface, wpa_s, NULL);
720
0
  eloop_cancel_timeout(wpas_verify_ssid_beacon, wpa_s, NULL);
721
0
  eloop_cancel_timeout(wpas_wfa_capab_tx, wpa_s, NULL);
722
723
0
  wpas_wps_deinit(wpa_s);
724
725
0
  wpabuf_free(wpa_s->pending_eapol_rx);
726
0
  wpa_s->pending_eapol_rx = NULL;
727
728
#ifdef CONFIG_IBSS_RSN
729
  ibss_rsn_deinit(wpa_s->ibss_rsn);
730
  wpa_s->ibss_rsn = NULL;
731
#endif /* CONFIG_IBSS_RSN */
732
733
0
  sme_deinit(wpa_s);
734
735
#ifdef CONFIG_AP
736
  wpa_supplicant_ap_deinit(wpa_s);
737
#endif /* CONFIG_AP */
738
739
0
  wpas_p2p_deinit(wpa_s);
740
741
0
  wpas_pr_deinit(wpa_s);
742
743
#ifdef CONFIG_OFFCHANNEL
744
  offchannel_deinit(wpa_s);
745
#endif /* CONFIG_OFFCHANNEL */
746
747
0
  wpa_supplicant_cancel_sched_scan(wpa_s);
748
749
0
  os_free(wpa_s->next_scan_freqs);
750
0
  wpa_s->next_scan_freqs = NULL;
751
752
0
  os_free(wpa_s->manual_scan_freqs);
753
0
  wpa_s->manual_scan_freqs = NULL;
754
0
  os_free(wpa_s->select_network_scan_freqs);
755
0
  wpa_s->select_network_scan_freqs = NULL;
756
757
0
  os_free(wpa_s->manual_sched_scan_freqs);
758
0
  wpa_s->manual_sched_scan_freqs = NULL;
759
760
0
  wpas_mac_addr_rand_scan_clear(wpa_s, MAC_ADDR_RAND_ALL);
761
762
  /*
763
   * Need to remove any pending gas-query radio work before the
764
   * gas_query_deinit() call because gas_query::work has not yet been set
765
   * for works that have not been started. gas_query_free() will be unable
766
   * to cancel such pending radio works and once the pending gas-query
767
   * radio work eventually gets removed, the deinit notification call to
768
   * gas_query_start_cb() would result in dereferencing freed memory.
769
   */
770
0
  if (wpa_s->radio)
771
0
    radio_remove_works(wpa_s, "gas-query", 0);
772
0
  gas_query_deinit(wpa_s->gas);
773
0
  wpa_s->gas = NULL;
774
0
  gas_server_deinit(wpa_s->gas_server);
775
0
  wpa_s->gas_server = NULL;
776
777
0
  free_hw_features(wpa_s);
778
779
0
  ieee802_1x_dealloc_kay_sm(wpa_s);
780
781
0
  os_free(wpa_s->bssid_filter);
782
0
  wpa_s->bssid_filter = NULL;
783
784
0
  os_free(wpa_s->disallow_aps_bssid);
785
0
  wpa_s->disallow_aps_bssid = NULL;
786
0
  os_free(wpa_s->disallow_aps_ssid);
787
0
  wpa_s->disallow_aps_ssid = NULL;
788
789
0
  wnm_bss_keep_alive_deinit(wpa_s);
790
0
  wnm_btm_reset(wpa_s);
791
0
  wnm_sleep_mode_clear(wpa_s);
792
793
0
  ext_password_deinit(wpa_s->ext_pw);
794
0
  wpa_s->ext_pw = NULL;
795
796
0
  wpabuf_free(wpa_s->last_gas_resp);
797
0
  wpa_s->last_gas_resp = NULL;
798
0
  wpabuf_free(wpa_s->prev_gas_resp);
799
0
  wpa_s->prev_gas_resp = NULL;
800
801
0
  os_free(wpa_s->last_scan_res);
802
0
  wpa_s->last_scan_res = NULL;
803
804
#ifdef CONFIG_P2P
805
  os_free(wpa_s->p2p_pmksa_entry);
806
  wpa_s->p2p_pmksa_entry = NULL;
807
#endif /* CONFIG_P2P */
808
809
0
  if (wpa_s->drv_priv)
810
0
    wpa_drv_configure_frame_filters(wpa_s, 0);
811
812
0
  for (i = 0; i < NUM_VENDOR_ELEM_FRAMES; i++) {
813
0
    wpabuf_free(wpa_s->vendor_elem[i]);
814
0
    wpa_s->vendor_elem[i] = NULL;
815
0
  }
816
817
0
#ifndef CONFIG_NO_WMM_AC
818
0
  wmm_ac_notify_disassoc(wpa_s);
819
0
#endif /* CONFIG_NO_WMM_AC */
820
821
0
  wpa_s->sched_scan_plans_num = 0;
822
0
  os_free(wpa_s->sched_scan_plans);
823
0
  wpa_s->sched_scan_plans = NULL;
824
825
#ifdef CONFIG_MBO
826
  wpa_s->non_pref_chan_num = 0;
827
0
  os_free(wpa_s->non_pref_chan);
828
  wpa_s->non_pref_chan = NULL;
829
#endif /* CONFIG_MBO */
830
831
0
  free_bss_tmp_disallowed(wpa_s);
832
833
0
  wpabuf_free(wpa_s->lci);
834
0
  wpa_s->lci = NULL;
835
0
#ifndef CONFIG_NO_RRM
836
0
  wpas_clear_beacon_rep_data(wpa_s);
837
0
#endif /* CONFIG_NO_RRM */
838
839
#ifdef CONFIG_PMKSA_CACHE_EXTERNAL
840
#ifdef CONFIG_MESH
841
  {
842
    struct external_pmksa_cache *entry;
843
844
    while ((entry = dl_list_last(&wpa_s->mesh_external_pmksa_cache,
845
               struct external_pmksa_cache,
846
               list)) != NULL) {
847
      dl_list_del(&entry->list);
848
      os_free(entry->pmksa_cache);
849
      os_free(entry);
850
    }
851
  }
852
#endif /* CONFIG_MESH */
853
#endif /* CONFIG_PMKSA_CACHE_EXTERNAL */
854
855
0
  wpas_flush_fils_hlp_req(wpa_s);
856
857
0
  wpabuf_free(wpa_s->ric_ies);
858
0
  wpa_s->ric_ies = NULL;
859
860
#ifdef CONFIG_DPP
861
  wpas_dpp_deinit(wpa_s);
862
  dpp_global_deinit(wpa_s->dpp);
863
  wpa_s->dpp = NULL;
864
#endif /* CONFIG_DPP */
865
866
0
  wpas_nan_de_deinit(wpa_s);
867
868
#ifdef CONFIG_PASN
869
  wpas_pasn_auth_stop(wpa_s);
870
  wpas_pasn_free_params(wpa_s);
871
#endif /* CONFIG_PASN */
872
0
#ifndef CONFIG_NO_ROBUST_AV
873
0
  wpas_scs_deinit(wpa_s);
874
0
  wpas_dscp_deinit(wpa_s);
875
0
#endif /* CONFIG_NO_ROBUST_AV */
876
877
#ifdef CONFIG_OWE
878
  os_free(wpa_s->owe_trans_scan_freq);
879
  wpa_s->owe_trans_scan_freq = NULL;
880
#endif /* CONFIG_OWE */
881
882
0
  for (i = 0; i < MAX_NUM_MLD_LINKS; i++) {
883
0
    wpabuf_free(wpa_s->links[i].ies);
884
0
    wpa_s->links[i].ies = NULL;
885
0
  }
886
0
}
Unexecuted instantiation: wpa_supplicant.c:wpa_supplicant_cleanup
Unexecuted instantiation: wpa_supplicant.c:wpa_supplicant_cleanup
887
888
889
/**
890
 * wpa_clear_keys - Clear keys configured for the driver
891
 * @wpa_s: Pointer to wpa_supplicant data
892
 * @addr: Previously used BSSID or %NULL if not available
893
 *
894
 * This function clears the encryption keys that has been previously configured
895
 * for the driver.
896
 */
897
void wpa_clear_keys(struct wpa_supplicant *wpa_s, const u8 *addr)
898
0
{
899
0
  int i, max = 6;
900
901
  /* MLME-DELETEKEYS.request
902
   *
903
   * For still associated MLO connections, group keys are per-link and at
904
   * least in the case of Linux nl80211 interface, the cfg80211 validator
905
   * rejects DEL_KEY for group keys with link_id=-1 when wdev->valid_links
906
   * is set. Iterate over each valid link and pass the corresponding
907
   * link_id so the keys are properly cleared.
908
   */
909
0
  if (wpa_s->valid_links && wpa_s->wpa_state > WPA_ASSOCIATED) {
910
0
    int link_id;
911
912
0
    for_each_link(wpa_s->valid_links, link_id) {
913
0
      for (i = 0; i < max; i++) {
914
0
        if (wpa_s->keys_cleared & BIT(i))
915
0
          continue;
916
0
        wpa_drv_set_key(wpa_s, link_id, WPA_ALG_NONE,
917
0
            NULL, i, 0, NULL, 0,
918
0
            NULL, 0, KEY_FLAG_GROUP);
919
0
      }
920
0
    }
921
0
  } else {
922
0
    for (i = 0; i < max; i++) {
923
0
      if (wpa_s->keys_cleared & BIT(i))
924
0
        continue;
925
0
      wpa_drv_set_key(wpa_s, -1, WPA_ALG_NONE, NULL, i, 0,
926
0
          NULL, 0, NULL, 0, KEY_FLAG_GROUP);
927
0
    }
928
0
  }
929
  /* Pairwise Key ID 1 for Extended Key ID is tracked in bit 15 */
930
0
  if (~wpa_s->keys_cleared & (BIT(0) | BIT(15)) && addr &&
931
0
      !is_zero_ether_addr(addr)) {
932
0
    if (!(wpa_s->keys_cleared & BIT(0)))
933
0
      wpa_drv_set_key(wpa_s, -1, WPA_ALG_NONE, addr, 0, 0,
934
0
          NULL, 0, NULL, 0, KEY_FLAG_PAIRWISE);
935
0
    if (!(wpa_s->keys_cleared & BIT(15)))
936
0
      wpa_drv_set_key(wpa_s, -1, WPA_ALG_NONE, addr, 1, 0,
937
0
          NULL, 0, NULL, 0, KEY_FLAG_PAIRWISE);
938
    /* MLME-SETPROTECTION.request(None) */
939
0
    wpa_drv_mlme_setprotection(
940
0
      wpa_s, addr,
941
0
      MLME_SETPROTECTION_PROTECT_TYPE_NONE,
942
0
      MLME_SETPROTECTION_KEY_TYPE_PAIRWISE);
943
0
  }
944
0
  wpa_s->keys_cleared = (u32) -1;
945
0
}
946
947
948
/**
949
 * wpa_supplicant_state_txt - Get the connection state name as a text string
950
 * @state: State (wpa_state; WPA_*)
951
 * Returns: The state name as a printable text string
952
 */
953
const char * wpa_supplicant_state_txt(enum wpa_states state)
954
0
{
955
0
  switch (state) {
956
0
  case WPA_DISCONNECTED:
957
0
    return "DISCONNECTED";
958
0
  case WPA_INACTIVE:
959
0
    return "INACTIVE";
960
0
  case WPA_INTERFACE_DISABLED:
961
0
    return "INTERFACE_DISABLED";
962
0
  case WPA_SCANNING:
963
0
    return "SCANNING";
964
0
  case WPA_AUTHENTICATING:
965
0
    return "AUTHENTICATING";
966
0
  case WPA_ASSOCIATING:
967
0
    return "ASSOCIATING";
968
0
  case WPA_ASSOCIATED:
969
0
    return "ASSOCIATED";
970
0
  case WPA_4WAY_HANDSHAKE:
971
0
    return "4WAY_HANDSHAKE";
972
0
  case WPA_GROUP_HANDSHAKE:
973
0
    return "GROUP_HANDSHAKE";
974
0
  case WPA_COMPLETED:
975
0
    return "COMPLETED";
976
0
  default:
977
0
    return "UNKNOWN";
978
0
  }
979
0
}
980
981
982
#ifdef CONFIG_BGSCAN
983
984
static void wpa_supplicant_stop_bgscan(struct wpa_supplicant *wpa_s)
985
{
986
  if (wpa_s->bgscan_ssid) {
987
    bgscan_deinit(wpa_s);
988
    wpa_s->bgscan_ssid = NULL;
989
  }
990
}
991
992
993
/**
994
 * wpa_supplicant_reset_bgscan - Reset the bgscan for the current SSID.
995
 * @wpa_s: Pointer to the wpa_supplicant data
996
 *
997
 * Stop, start, or reconfigure the scan parameters depending on the method.
998
 */
999
void wpa_supplicant_reset_bgscan(struct wpa_supplicant *wpa_s)
1000
{
1001
  const char *name;
1002
1003
  if (wpa_s->current_ssid && wpa_s->current_ssid->bgscan)
1004
    name = wpa_s->current_ssid->bgscan;
1005
  else
1006
    name = wpa_s->conf->bgscan;
1007
  if (!name || name[0] == '\0') {
1008
    wpa_supplicant_stop_bgscan(wpa_s);
1009
    return;
1010
  }
1011
  if (wpas_driver_bss_selection(wpa_s))
1012
    return;
1013
#ifdef CONFIG_P2P
1014
  if (wpa_s->p2p_group_interface != NOT_P2P_GROUP_INTERFACE)
1015
    return;
1016
#endif /* CONFIG_P2P */
1017
1018
  bgscan_deinit(wpa_s);
1019
  if (wpa_s->current_ssid) {
1020
    if (bgscan_init(wpa_s, wpa_s->current_ssid, name)) {
1021
      wpa_dbg(wpa_s, MSG_DEBUG, "Failed to initialize "
1022
        "bgscan");
1023
      /*
1024
       * Live without bgscan; it is only used as a roaming
1025
       * optimization, so the initial connection is not
1026
       * affected.
1027
       */
1028
    } else {
1029
      struct wpa_scan_results *scan_res;
1030
      wpa_s->bgscan_ssid = wpa_s->current_ssid;
1031
      scan_res = wpa_supplicant_get_scan_results(wpa_s, NULL,
1032
                   0, NULL);
1033
      if (scan_res) {
1034
        bgscan_notify_scan(wpa_s, scan_res);
1035
        wpa_scan_results_free(scan_res);
1036
      }
1037
    }
1038
  } else
1039
    wpa_s->bgscan_ssid = NULL;
1040
}
1041
1042
#endif /* CONFIG_BGSCAN */
1043
1044
1045
static void wpa_supplicant_start_autoscan(struct wpa_supplicant *wpa_s)
1046
0
{
1047
0
  if (autoscan_init(wpa_s, 0))
1048
0
    wpa_dbg(wpa_s, MSG_DEBUG, "Failed to initialize autoscan");
1049
0
}
1050
1051
1052
static void wpa_supplicant_stop_autoscan(struct wpa_supplicant *wpa_s)
1053
0
{
1054
0
  autoscan_deinit(wpa_s);
1055
0
}
1056
1057
1058
void wpa_supplicant_reinit_autoscan(struct wpa_supplicant *wpa_s)
1059
0
{
1060
0
  if (wpa_s->wpa_state == WPA_DISCONNECTED ||
1061
0
      wpa_s->wpa_state == WPA_SCANNING) {
1062
0
    autoscan_deinit(wpa_s);
1063
0
    wpa_supplicant_start_autoscan(wpa_s);
1064
0
  }
1065
0
}
1066
1067
1068
static void wpas_verify_ssid_beacon(void *eloop_ctx, void *timeout_ctx)
1069
0
{
1070
0
  struct wpa_supplicant *wpa_s = eloop_ctx;
1071
0
  struct wpa_bss *bss;
1072
0
  const u8 *ssid;
1073
0
  size_t ssid_len;
1074
1075
0
  if (!wpa_s->current_ssid || !wpa_s->current_bss)
1076
0
    return;
1077
1078
0
  ssid = wpa_s->current_bss->ssid;
1079
0
  ssid_len = wpa_s->current_bss->ssid_len;
1080
1081
0
  if (wpa_s->current_ssid->ssid_len &&
1082
0
      (wpa_s->current_ssid->ssid_len != ssid_len ||
1083
0
       os_memcmp(wpa_s->current_ssid->ssid, ssid, ssid_len) != 0))
1084
0
    return;
1085
1086
0
  if (wpa_s->wpa_state < WPA_4WAY_HANDSHAKE ||
1087
0
      !wpa_s->bigtk_set || wpa_s->ssid_verified)
1088
0
    return;
1089
1090
0
  wpa_printf(MSG_DEBUG,
1091
0
       "SSID not yet verified; check if the driver has received a verified Beacon frame");
1092
0
  if (wpa_supplicant_update_scan_results(wpa_s, wpa_s->bssid) < 0)
1093
0
    return;
1094
1095
  /* wpa->current_bss might have changed due to memory reallocation, so
1096
   * need to update ssid/ssid_len */
1097
0
  if (!wpa_s->current_bss)
1098
0
    return;
1099
0
  ssid = wpa_s->current_bss->ssid;
1100
0
  ssid_len = wpa_s->current_bss->ssid_len;
1101
1102
0
  bss = wpa_bss_get_bssid_latest(wpa_s, wpa_s->bssid);
1103
0
  if (!bss)
1104
0
    return;
1105
0
  wpa_printf(MSG_DEBUG, "The current beacon time stamp: 0x%llx",
1106
0
       (long long unsigned int) bss->tsf);
1107
0
  if (bss->tsf > wpa_s->first_beacon_tsf) {
1108
0
    const u8 *ie;
1109
1110
0
    wpa_printf(MSG_DEBUG,
1111
0
         "Verified Beacon frame has been received");
1112
0
    wpa_s->beacons_checked++;
1113
1114
0
    ie = wpa_bss_get_ie_beacon(bss, WLAN_EID_SSID);
1115
0
    if (ie && ie[1] == ssid_len &&
1116
0
        os_memcmp(&ie[2], ssid, ssid_len) == 0) {
1117
0
      wpa_printf(MSG_DEBUG,
1118
0
           "SSID verified based on a Beacon frame and beacon protection");
1119
0
      wpa_s->ssid_verified = true;
1120
0
      return;
1121
0
    }
1122
1123
    /* TODO: Multiple BSSID element */
1124
0
  }
1125
1126
0
  if (wpa_s->beacons_checked < 16) {
1127
0
    eloop_register_timeout(wpa_s->next_beacon_check, 0,
1128
0
               wpas_verify_ssid_beacon, wpa_s, NULL);
1129
0
    wpa_s->next_beacon_check++;
1130
0
  }
1131
0
}
1132
1133
1134
static void wpas_verify_ssid_beacon_prot(struct wpa_supplicant *wpa_s)
1135
0
{
1136
0
  struct wpa_bss *bss;
1137
1138
0
  wpa_printf(MSG_DEBUG,
1139
0
       "SSID not yet verified; try to verify using beacon protection");
1140
  /* Fetch the current scan result which is likely based on not yet
1141
   * verified payload since the current BIGTK was just received. Any
1142
   * newer update in the future with a larger timestamp value is an
1143
   * indication that a verified Beacon frame has been received. */
1144
0
  if (wpa_supplicant_update_scan_results(wpa_s, wpa_s->bssid) < 0)
1145
0
    return;
1146
1147
0
  bss = wpa_bss_get_bssid_latest(wpa_s, wpa_s->bssid);
1148
0
  if (!bss)
1149
0
    return;
1150
0
  wpa_printf(MSG_DEBUG, "The initial beacon time stamp: 0x%llx",
1151
0
       (long long unsigned int) bss->tsf);
1152
0
  wpa_s->first_beacon_tsf = bss->tsf;
1153
0
  wpa_s->beacons_checked = 0;
1154
0
  wpa_s->next_beacon_check = 1;
1155
0
  eloop_cancel_timeout(wpas_verify_ssid_beacon, wpa_s, NULL);
1156
0
  eloop_register_timeout(1, 0, wpas_verify_ssid_beacon, wpa_s, NULL);
1157
0
}
1158
1159
1160
/**
1161
 * wpa_supplicant_set_state - Set current connection state
1162
 * @wpa_s: Pointer to wpa_supplicant data
1163
 * @state: The new connection state
1164
 *
1165
 * This function is called whenever the connection state changes, e.g.,
1166
 * association is completed for WPA/WPA2 4-Way Handshake is started.
1167
 */
1168
void wpa_supplicant_set_state(struct wpa_supplicant *wpa_s,
1169
            enum wpa_states state)
1170
0
{
1171
0
  enum wpa_states old_state = wpa_s->wpa_state;
1172
0
  int new_connection = wpa_s->new_connection;
1173
#if defined(CONFIG_FILS) && defined(IEEE8021X_EAPOL)
1174
  bool update_fils_connect_params = false;
1175
#endif /* CONFIG_FILS && IEEE8021X_EAPOL */
1176
1177
0
  wpa_dbg(wpa_s, MSG_DEBUG, "State: %s -> %s",
1178
0
    wpa_supplicant_state_txt(wpa_s->wpa_state),
1179
0
    wpa_supplicant_state_txt(state));
1180
1181
0
  if (state == WPA_COMPLETED &&
1182
0
      os_reltime_initialized(&wpa_s->roam_start)) {
1183
0
    os_reltime_age(&wpa_s->roam_start, &wpa_s->roam_time);
1184
0
    wpa_s->roam_start.sec = 0;
1185
0
    wpa_s->roam_start.usec = 0;
1186
0
    wpas_notify_auth_changed(wpa_s);
1187
0
    wpas_notify_roam_time(wpa_s);
1188
0
    wpas_notify_roam_complete(wpa_s);
1189
0
  } else if (state == WPA_DISCONNECTED &&
1190
0
       os_reltime_initialized(&wpa_s->roam_start)) {
1191
0
    wpa_s->roam_start.sec = 0;
1192
0
    wpa_s->roam_start.usec = 0;
1193
0
    wpa_s->roam_time.sec = 0;
1194
0
    wpa_s->roam_time.usec = 0;
1195
0
    wpas_notify_roam_complete(wpa_s);
1196
0
  }
1197
1198
0
  if (state == WPA_INTERFACE_DISABLED) {
1199
    /* Assure normal scan when interface is restored */
1200
0
    wpa_s->normal_scans = 0;
1201
1202
    /*
1203
     * A NAN management interface is not expected to be disabled. If
1204
     * it disabled, it means that NAN functionality is no longer
1205
     * possible so deinit (which would also stop any ongoing NAN
1206
     * operations).
1207
     */
1208
0
    if (wpa_s->nan_mgmt)
1209
0
      wpas_nan_deinit(wpa_s);
1210
0
  }
1211
1212
0
  if (state == WPA_COMPLETED) {
1213
0
    wpas_connect_work_done(wpa_s);
1214
    /* Reinitialize normal_scan counter */
1215
0
    wpa_s->normal_scans = 0;
1216
0
  }
1217
1218
#ifdef CONFIG_P2P
1219
  /*
1220
   * P2PS client has to reply to Probe Request frames received on the
1221
   * group operating channel. Enable Probe Request frame reporting for
1222
   * P2P connected client in case p2p_cli_probe configuration property is
1223
   * set to 1.
1224
   */
1225
  if (wpa_s->conf->p2p_cli_probe && wpa_s->current_ssid &&
1226
      wpa_s->current_ssid->mode == WPAS_MODE_INFRA &&
1227
      wpa_s->current_ssid->p2p_group) {
1228
    if (state == WPA_COMPLETED && !wpa_s->p2p_cli_probe) {
1229
      wpa_dbg(wpa_s, MSG_DEBUG,
1230
        "P2P: Enable CLI Probe Request RX reporting");
1231
      wpa_s->p2p_cli_probe =
1232
        wpa_drv_probe_req_report(wpa_s, 1) >= 0;
1233
    } else if (state != WPA_COMPLETED && wpa_s->p2p_cli_probe) {
1234
      wpa_dbg(wpa_s, MSG_DEBUG,
1235
        "P2P: Disable CLI Probe Request RX reporting");
1236
      wpa_s->p2p_cli_probe = 0;
1237
      wpa_drv_probe_req_report(wpa_s, 0);
1238
    }
1239
  }
1240
#endif /* CONFIG_P2P */
1241
1242
0
  if (state != WPA_SCANNING)
1243
0
    wpa_supplicant_notify_scanning(wpa_s, 0);
1244
1245
0
  if (state == WPA_COMPLETED && wpa_s->new_connection) {
1246
0
    struct wpa_ssid *ssid = wpa_s->current_ssid;
1247
0
    int fils_hlp_sent = 0;
1248
0
    char mld_addr[50];
1249
1250
0
    mld_addr[0] = '\0';
1251
0
    if (wpa_s->valid_links)
1252
0
      os_snprintf(mld_addr, sizeof(mld_addr),
1253
0
            " ap_mld_addr=" MACSTR,
1254
0
            MAC2STR(wpa_s->ap_mld_addr));
1255
1256
#ifdef CONFIG_SME
1257
    if ((wpa_s->drv_flags & WPA_DRIVER_FLAGS_SME) &&
1258
        wpa_auth_alg_fils(wpa_s->sme.auth_alg))
1259
      fils_hlp_sent = 1;
1260
#endif /* CONFIG_SME */
1261
0
    if (!(wpa_s->drv_flags & WPA_DRIVER_FLAGS_SME) &&
1262
0
        wpa_auth_alg_fils(wpa_s->auth_alg))
1263
0
      fils_hlp_sent = 1;
1264
1265
0
#if defined(CONFIG_CTRL_IFACE) || !defined(CONFIG_NO_STDOUT_DEBUG)
1266
0
    wpa_msg(wpa_s, MSG_INFO, WPA_EVENT_CONNECTED "- Connection to "
1267
0
      MACSTR " completed [id=%d id_str=%s%s]%s",
1268
0
      MAC2STR(wpa_s->bssid),
1269
0
      ssid ? ssid->id : -1,
1270
0
      ssid && ssid->id_str ? ssid->id_str : "",
1271
0
      fils_hlp_sent ? " FILS_HLP_SENT" : "", mld_addr);
1272
0
#endif /* CONFIG_CTRL_IFACE || !CONFIG_NO_STDOUT_DEBUG */
1273
0
    wpas_clear_temp_disabled(wpa_s, ssid, 1);
1274
0
    wpa_s->consecutive_conn_failures = 0;
1275
0
    wpa_s->new_connection = 0;
1276
0
    wpa_drv_set_operstate(wpa_s, 1);
1277
#ifndef IEEE8021X_EAPOL
1278
    wpa_drv_set_supp_port(wpa_s, 1);
1279
#endif /* IEEE8021X_EAPOL */
1280
0
    wpa_s->after_wps = 0;
1281
0
    wpa_s->known_wps_freq = 0;
1282
0
    wpas_p2p_completed(wpa_s);
1283
1284
0
    sme_sched_obss_scan(wpa_s, 1);
1285
1286
#if defined(CONFIG_FILS) && defined(IEEE8021X_EAPOL)
1287
    if (!fils_hlp_sent && ssid && ssid->eap.erp)
1288
      update_fils_connect_params = true;
1289
#endif /* CONFIG_FILS && IEEE8021X_EAPOL */
1290
#ifdef CONFIG_OWE
1291
    if (ssid && (ssid->key_mgmt & WPA_KEY_MGMT_OWE))
1292
      wpas_update_owe_connect_params(wpa_s);
1293
#endif /* CONFIG_OWE */
1294
0
  } else if (state == WPA_DISCONNECTED || state == WPA_ASSOCIATING ||
1295
0
       state == WPA_ASSOCIATED) {
1296
0
    wpa_s->new_connection = 1;
1297
0
    wpa_drv_set_operstate(wpa_s, 0);
1298
#ifndef IEEE8021X_EAPOL
1299
    wpa_drv_set_supp_port(wpa_s, 0);
1300
#endif /* IEEE8021X_EAPOL */
1301
0
    sme_sched_obss_scan(wpa_s, 0);
1302
0
  }
1303
0
  wpa_s->wpa_state = state;
1304
1305
0
  if (state == WPA_COMPLETED && new_connection &&
1306
0
      wpa_s->conf->wfa_gen_capa == WFA_GEN_CAPA_PROTECTED &&
1307
0
      pmf_in_use(wpa_s, wpa_s->bssid)) {
1308
0
    eloop_cancel_timeout(wpas_wfa_capab_tx, wpa_s, NULL);
1309
0
    eloop_register_timeout(0, 100000, wpas_wfa_capab_tx,
1310
0
               wpa_s, NULL);
1311
0
  }
1312
1313
0
#ifndef CONFIG_NO_ROBUST_AV
1314
0
  if (state == WPA_COMPLETED && dl_list_len(&wpa_s->active_scs_ids) &&
1315
0
      wpa_s->scs_reconfigure)
1316
0
    wpas_scs_reconfigure(wpa_s);
1317
0
#endif /* CONFIG_NO_ROBUST_AV */
1318
1319
#ifdef CONFIG_BGSCAN
1320
  if (state == WPA_COMPLETED && wpa_s->current_ssid != wpa_s->bgscan_ssid)
1321
    wpa_supplicant_reset_bgscan(wpa_s);
1322
  else if (state < WPA_ASSOCIATED)
1323
    wpa_supplicant_stop_bgscan(wpa_s);
1324
#endif /* CONFIG_BGSCAN */
1325
1326
0
  if (state > WPA_SCANNING)
1327
0
    wpa_supplicant_stop_autoscan(wpa_s);
1328
1329
0
  if (state == WPA_DISCONNECTED || state == WPA_INACTIVE)
1330
0
    wpa_supplicant_start_autoscan(wpa_s);
1331
1332
0
  if (state == WPA_COMPLETED || state == WPA_INTERFACE_DISABLED ||
1333
0
      state == WPA_INACTIVE)
1334
0
    wnm_btm_reset(wpa_s);
1335
1336
0
#ifndef CONFIG_NO_WMM_AC
1337
0
  if (old_state >= WPA_ASSOCIATED && wpa_s->wpa_state < WPA_ASSOCIATED)
1338
0
    wmm_ac_notify_disassoc(wpa_s);
1339
0
#endif /* CONFIG_NO_WMM_AC */
1340
1341
0
  if (wpa_s->wpa_state != old_state) {
1342
0
    wpas_notify_state_changed(wpa_s, wpa_s->wpa_state, old_state);
1343
1344
    /*
1345
     * Notify the P2P Device interface about a state change in one
1346
     * of the interfaces.
1347
     */
1348
0
    wpas_p2p_indicate_state_change(wpa_s);
1349
1350
0
    if (wpa_s->wpa_state == WPA_COMPLETED ||
1351
0
        old_state == WPA_COMPLETED)
1352
0
      wpas_notify_auth_changed(wpa_s);
1353
#ifdef CONFIG_DPP2
1354
    if (wpa_s->wpa_state == WPA_COMPLETED)
1355
      wpas_dpp_connected(wpa_s);
1356
#endif /* CONFIG_DPP2 */
1357
1358
0
    if (wpa_s->wpa_state == WPA_COMPLETED &&
1359
0
        wpa_s->bigtk_set && !wpa_s->ssid_verified)
1360
0
      wpas_verify_ssid_beacon_prot(wpa_s);
1361
0
  }
1362
#if defined(CONFIG_FILS) && defined(IEEE8021X_EAPOL)
1363
  if (update_fils_connect_params)
1364
    wpas_update_fils_connect_params(wpa_s);
1365
#endif /* CONFIG_FILS && IEEE8021X_EAPOL */
1366
1367
0
  wpas_nan_usd_state_change_notif(wpa_s);
1368
0
}
1369
1370
1371
void wpa_supplicant_terminate_proc(struct wpa_global *global)
1372
0
{
1373
0
  int pending = 0;
1374
0
#ifdef CONFIG_WPS
1375
0
  struct wpa_supplicant *wpa_s = global->ifaces;
1376
0
  while (wpa_s) {
1377
0
    struct wpa_supplicant *next = wpa_s->next;
1378
0
    if (wpas_wps_terminate_pending(wpa_s) == 1)
1379
0
      pending = 1;
1380
#ifdef CONFIG_P2P
1381
    if (wpa_s->p2p_group_interface != NOT_P2P_GROUP_INTERFACE ||
1382
        (wpa_s->current_ssid && wpa_s->current_ssid->p2p_group))
1383
      wpas_p2p_disconnect(wpa_s);
1384
#endif /* CONFIG_P2P */
1385
0
    wpa_s = next;
1386
0
  }
1387
0
#endif /* CONFIG_WPS */
1388
0
  if (pending)
1389
0
    return;
1390
0
  eloop_terminate();
1391
0
}
1392
1393
1394
static void wpa_supplicant_terminate(int sig, void *signal_ctx)
1395
0
{
1396
0
  struct wpa_global *global = signal_ctx;
1397
0
  wpa_supplicant_terminate_proc(global);
1398
0
}
1399
1400
1401
void wpa_supplicant_clear_status(struct wpa_supplicant *wpa_s)
1402
0
{
1403
0
  enum wpa_states old_state = wpa_s->wpa_state;
1404
0
  enum wpa_states new_state;
1405
1406
0
  if (old_state == WPA_SCANNING)
1407
0
    new_state = WPA_SCANNING;
1408
0
  else
1409
0
    new_state = WPA_DISCONNECTED;
1410
1411
0
  wpa_s->pairwise_cipher = 0;
1412
0
  wpa_s->group_cipher = 0;
1413
0
  wpa_s->mgmt_group_cipher = 0;
1414
0
  wpa_s->key_mgmt = 0;
1415
0
  wpa_s->allowed_key_mgmts = 0;
1416
0
  if (wpa_s->wpa_state != WPA_INTERFACE_DISABLED)
1417
0
    wpa_supplicant_set_state(wpa_s, new_state);
1418
1419
0
  if (wpa_s->wpa_state != old_state)
1420
0
    wpas_notify_state_changed(wpa_s, wpa_s->wpa_state, old_state);
1421
0
}
1422
1423
1424
/**
1425
 * wpa_supplicant_reload_configuration - Reload configuration data
1426
 * @wpa_s: Pointer to wpa_supplicant data
1427
 * Returns: 0 on success or -1 if configuration parsing failed
1428
 *
1429
 * This function can be used to request that the configuration data is reloaded
1430
 * (e.g., after configuration file change). This function is reloading
1431
 * configuration only for one interface, so this may need to be called multiple
1432
 * times if %wpa_supplicant is controlling multiple interfaces and all
1433
 * interfaces need reconfiguration.
1434
 */
1435
int wpa_supplicant_reload_configuration(struct wpa_supplicant *wpa_s)
1436
0
{
1437
0
  struct wpa_config *conf;
1438
0
  int reconf_ctrl;
1439
0
  int old_ap_scan;
1440
1441
0
  if (wpa_s->confname == NULL)
1442
0
    return -1;
1443
0
  conf = wpa_config_read(wpa_s->confname, NULL, false,
1444
0
             wpa_s->global->params.show_details);
1445
0
  if (conf == NULL) {
1446
0
    wpa_msg(wpa_s, MSG_ERROR, "Failed to parse the configuration "
1447
0
      "file '%s' - exiting", wpa_s->confname);
1448
0
    return -1;
1449
0
  }
1450
0
  if (wpa_s->confanother &&
1451
0
      !wpa_config_read(wpa_s->confanother, conf, true,
1452
0
           wpa_s->global->params.show_details)) {
1453
0
    wpa_msg(wpa_s, MSG_ERROR,
1454
0
      "Failed to parse the configuration file '%s' - exiting",
1455
0
      wpa_s->confanother);
1456
0
    return -1;
1457
0
  }
1458
1459
0
  conf->changed_parameters = (unsigned int) -1;
1460
1461
0
  reconf_ctrl = !!conf->ctrl_interface != !!wpa_s->conf->ctrl_interface
1462
0
    || (conf->ctrl_interface && wpa_s->conf->ctrl_interface &&
1463
0
        os_strcmp(conf->ctrl_interface,
1464
0
            wpa_s->conf->ctrl_interface) != 0);
1465
1466
0
  if (reconf_ctrl) {
1467
0
    wpa_supplicant_ctrl_iface_deinit(wpa_s, wpa_s->ctrl_iface);
1468
0
    wpa_s->ctrl_iface = NULL;
1469
0
  }
1470
1471
0
  eapol_sm_invalidate_cached_session(wpa_s->eapol);
1472
0
  if (wpa_s->current_ssid) {
1473
0
    if (wpa_s->wpa_state >= WPA_AUTHENTICATING)
1474
0
      wpa_s->own_disconnect_req = 1;
1475
0
    wpa_supplicant_deauthenticate(wpa_s,
1476
0
                WLAN_REASON_DEAUTH_LEAVING);
1477
0
  }
1478
1479
  /*
1480
   * TODO: should notify EAPOL SM about changes in opensc_engine_path,
1481
   * pkcs11_engine_path, pkcs11_module_path, openssl_ciphers.
1482
   */
1483
0
  if (wpa_key_mgmt_wpa_psk(wpa_s->key_mgmt) ||
1484
0
      wpa_s->key_mgmt == WPA_KEY_MGMT_OWE ||
1485
0
      wpa_s->key_mgmt == WPA_KEY_MGMT_DPP) {
1486
    /*
1487
     * Clear forced success to clear EAP state for next
1488
     * authentication.
1489
     */
1490
0
    eapol_sm_notify_eap_success(wpa_s->eapol, false);
1491
0
  }
1492
0
  eapol_sm_notify_config(wpa_s->eapol, NULL, NULL);
1493
0
  wpa_sm_set_config(wpa_s->wpa, NULL);
1494
0
  wpa_sm_pmksa_cache_flush(wpa_s->wpa, NULL);
1495
0
  wpa_sm_set_fast_reauth(wpa_s->wpa, wpa_s->conf->fast_reauth);
1496
0
  rsn_preauth_deinit(wpa_s->wpa);
1497
1498
0
  old_ap_scan = wpa_s->conf->ap_scan;
1499
0
  wpa_config_free(wpa_s->conf);
1500
0
  wpa_s->conf = conf;
1501
0
  if (old_ap_scan != wpa_s->conf->ap_scan)
1502
0
    wpas_notify_ap_scan_changed(wpa_s);
1503
1504
0
  if (reconf_ctrl)
1505
0
    wpa_s->ctrl_iface = wpa_supplicant_ctrl_iface_init(wpa_s);
1506
1507
0
  wpa_supplicant_update_config(wpa_s);
1508
1509
0
  wpa_supplicant_clear_status(wpa_s);
1510
0
  if (wpa_supplicant_enabled_networks(wpa_s)) {
1511
0
    wpa_s->reassociate = 1;
1512
0
    wpa_supplicant_req_scan(wpa_s, 0, 0);
1513
0
  }
1514
0
  wpa_bssid_ignore_clear(wpa_s);
1515
0
  wpa_dbg(wpa_s, MSG_DEBUG, "Reconfiguration completed");
1516
0
  return 0;
1517
0
}
1518
1519
1520
static void wpa_supplicant_reconfig(int sig, void *signal_ctx)
1521
0
{
1522
0
  struct wpa_global *global = signal_ctx;
1523
0
  struct wpa_supplicant *wpa_s;
1524
0
  for (wpa_s = global->ifaces; wpa_s; wpa_s = wpa_s->next) {
1525
0
    wpa_dbg(wpa_s, MSG_DEBUG, "Signal %d received - reconfiguring",
1526
0
      sig);
1527
0
    if (wpa_supplicant_reload_configuration(wpa_s) < 0) {
1528
0
      wpa_supplicant_terminate_proc(global);
1529
0
    }
1530
0
  }
1531
1532
0
  if (wpa_debug_reopen_file() < 0) {
1533
    /* Ignore errors since we cannot really do much to fix this */
1534
0
    wpa_printf(MSG_DEBUG, "Could not reopen debug log file");
1535
0
  }
1536
0
}
1537
1538
1539
static int wpa_supplicant_suites_from_ai(struct wpa_supplicant *wpa_s,
1540
           struct wpa_ssid *ssid,
1541
           struct wpa_ie_data *ie)
1542
0
{
1543
0
  int ret = wpa_sm_parse_own_wpa_ie(wpa_s->wpa, ie);
1544
0
  if (ret) {
1545
0
    if (ret == -2) {
1546
0
      wpa_msg(wpa_s, MSG_INFO, "WPA: Failed to parse WPA IE "
1547
0
        "from association info");
1548
0
    }
1549
0
    return -1;
1550
0
  }
1551
1552
0
  wpa_dbg(wpa_s, MSG_DEBUG, "WPA: Using WPA IE from AssocReq to set "
1553
0
    "cipher suites");
1554
0
  if (!(ie->group_cipher & ssid->group_cipher)) {
1555
0
    wpa_msg(wpa_s, MSG_INFO, "WPA: Driver used disabled group "
1556
0
      "cipher 0x%x (mask 0x%x) - reject",
1557
0
      ie->group_cipher, ssid->group_cipher);
1558
0
    return -1;
1559
0
  }
1560
0
  if (!(ie->pairwise_cipher & ssid->pairwise_cipher)) {
1561
0
    wpa_msg(wpa_s, MSG_INFO, "WPA: Driver used disabled pairwise "
1562
0
      "cipher 0x%x (mask 0x%x) - reject",
1563
0
      ie->pairwise_cipher, ssid->pairwise_cipher);
1564
0
    return -1;
1565
0
  }
1566
0
  if (!(ie->key_mgmt & ssid->key_mgmt)) {
1567
0
    wpa_msg(wpa_s, MSG_INFO, "WPA: Driver used disabled key "
1568
0
      "management 0x%x (mask 0x%x) - reject",
1569
0
      ie->key_mgmt, ssid->key_mgmt);
1570
0
    return -1;
1571
0
  }
1572
1573
0
  if (!(ie->capabilities & WPA_CAPABILITY_MFPC) &&
1574
0
      wpas_get_ssid_pmf(wpa_s, ssid) == MGMT_FRAME_PROTECTION_REQUIRED) {
1575
0
    wpa_msg(wpa_s, MSG_INFO, "WPA: Driver associated with an AP "
1576
0
      "that does not support management frame protection - "
1577
0
      "reject");
1578
0
    return -1;
1579
0
  }
1580
1581
0
  return 0;
1582
0
}
1583
1584
1585
static int matching_ciphers(struct wpa_ssid *ssid, struct wpa_ie_data *ie,
1586
          int freq)
1587
0
{
1588
0
  if (!ie->has_group)
1589
0
    ie->group_cipher = wpa_default_rsn_cipher(freq);
1590
0
  if (!ie->has_pairwise)
1591
0
    ie->pairwise_cipher = wpa_default_rsn_cipher(freq);
1592
0
  return (ie->group_cipher & ssid->group_cipher) &&
1593
0
    (ie->pairwise_cipher & ssid->pairwise_cipher);
1594
0
}
1595
1596
1597
/*
1598
 * security_profile_get_key_mgmt - Get key_mgmt bitmask implied by any
1599
 * profile in the AP's Security Profile element that matches ssid->key_mgmt.
1600
 *
1601
 * Walks the AP's Security Profile Bitmap and returns a WPA_KEY_MGMT_* bitmask
1602
 * covering all profiles whose bit is set and whose AKM matches at least one
1603
 * AKM in ssid->key_mgmt. Returns 0 if no matching profile is found.
1604
 *
1605
 * This is used to augment ie.key_mgmt so that the RSNE check in
1606
 * wpa_supplicant_set_suites() succeeds even when the RSNE/RSNOE/RSNO2E does
1607
 * not explicitly list the AKM that the security profile implies.
1608
 */
1609
int security_profile_get_key_mgmt(const u8 *sp, int ssid_key_mgmt)
1610
0
{
1611
0
  u8 bitmap_len, num_vendor;
1612
0
  const u8 *bitmap;
1613
0
  int profile, result = 0;
1614
0
  int akm_bit;
1615
1616
  /*
1617
   * sp_ie layout (wpa_bss_get_ie_ext returns full element):
1618
   *   [0] = 255 (EID_EXTENSION)
1619
   *   [1] = Length
1620
   *   [2] = 162 (EID_EXT_SECURITY_PROFILE)
1621
   *   [3] = Reduced RSN Capabilities
1622
   *   [4] = Security Profile Indication (B0-B3 = bitmap_octets)
1623
   *   [5..] = Security Profile Bitmap
1624
   */
1625
0
  if (!sp || sp[1] < 3)
1626
0
    return 0;
1627
1628
0
  bitmap_len = sp[4] & 0x0F;
1629
0
  num_vendor = (sp[4] & 0xF0) >> 4;
1630
0
  if (sp[1] < 3 + bitmap_len + 4 * num_vendor)
1631
0
    return 0;
1632
1633
0
  bitmap = sp + 5;
1634
1635
0
  for (profile = 0; profile <= SEC_PROF_MAX && profile < bitmap_len * 8;
1636
0
       profile++) {
1637
0
    if (!(bitmap[profile / 8] & BIT(profile % 8)))
1638
0
      continue;
1639
1640
    /*
1641
     * security_profile_akm_matches() expects a single key_mgmt
1642
     * value (not a bitmask), so iterate over each set bit in
1643
     * ssid_key_mgmt and test them individually.
1644
     */
1645
0
    for (akm_bit = 0; akm_bit < 32; akm_bit++) {
1646
0
      int akm = ssid_key_mgmt & BIT(akm_bit);
1647
1648
0
      if (!akm)
1649
0
        continue;
1650
0
      if (security_profile_akm_matches(profile, akm)) {
1651
0
        result |= akm;
1652
0
        break;
1653
0
      }
1654
0
    }
1655
0
  }
1656
1657
0
  return result;
1658
0
}
1659
1660
1661
/*
1662
 * security_profile_get_rsnx - Return a pointer to the Extended RSN
1663
 * Capabilities field inside the AP's Security Profile element, formatted
1664
 * identically to an RSNXE body (length-prefix in bits 0-3 of the first octet).
1665
 *
1666
 * Returns a pointer to the first octet of the Extended RSN Capabilities field
1667
 * within sp, and sets *rsnx_len to its length. Returns NULL if the element is
1668
 * too short to contain the field.
1669
 *
1670
 * The returned pointer is valid for the lifetime of sp.
1671
 */
1672
const u8 * security_profile_get_rsnx(const u8 *sp, size_t *rsnx_len)
1673
0
{
1674
0
  u8 bitmap_len, num_vendor;
1675
0
  size_t offset;
1676
0
  const u8 *rsnxe;
1677
1678
0
  if (!sp || sp[1] < 3)
1679
0
    return NULL;
1680
1681
0
  bitmap_len = sp[4] & 0x0F;
1682
0
  num_vendor = (sp[4] & 0xF0) >> 4;
1683
0
  if (sp[1] < 3 + bitmap_len + 4 * num_vendor)
1684
0
    return NULL;
1685
1686
  /*
1687
   * Offset of Extended RSN Capabilities within sp:
1688
   *   EID(1) + Len(1) + EID_EXT(1) + ReducedRSNCaps(1) +
1689
   *   SecProfInd(1) + bitmap(bitmap_len) + vendor specific security
1690
   *   profiles = 5 + bitmap_len + 4 * num_vendor
1691
   */
1692
0
  offset = 5 + bitmap_len + 4 * num_vendor;
1693
0
  if ((size_t) (sp[1] + 2) <= offset)
1694
0
    return NULL; /* no room for the full field */
1695
1696
0
  rsnxe = sp + offset;
1697
0
  *rsnx_len = (size_t) (sp[1] + 2) - offset;
1698
0
  if (*rsnx_len > 0) {
1699
0
    unsigned int capa_len;
1700
1701
    /* Use the Field length bits 0-3 to determine the length of the
1702
     * field. */
1703
0
    capa_len = (rsnxe[0] & 0x0f) + 1;
1704
0
    if (capa_len > *rsnx_len)
1705
0
      return NULL; /* no room for the full field */
1706
0
    *rsnx_len = capa_len;
1707
0
  }
1708
1709
0
  return rsnxe;
1710
0
}
1711
1712
1713
/*
1714
 * security_profile_get_rsn_caps - Derive RSN Capabilities from the AP's
1715
 * Security Profile element.
1716
 *
1717
 * All defined security profiles (0-15) require MFPR=1 and MFPC=1 per IEEE
1718
 * P802.11bn/D2.0, Table 9-bb18. The Reduced RSN Capabilities field
1719
 * additionally carries ExtKeyID (bit 0) and OCVC (bit 1).
1720
 *
1721
 * Returns a WPA_CAPABILITY_* bitmask suitable for use as ie.capabilities,
1722
 * or 0 if sp is NULL or too short.
1723
 */
1724
int security_profile_get_rsn_caps(const u8 *sp)
1725
0
{
1726
0
  u8 reduced;
1727
0
  int caps;
1728
1729
0
  if (!sp || sp[1] < 2)
1730
0
    return 0;
1731
1732
  /*
1733
   * sp[3] = Reduced RSN Capabilities (IEEE P802.11bn/D2.0, Figure
1734
   * 9-aa75):
1735
   *   B0 = Extended Key ID for Unicast Frames
1736
   *   B1 = OCVC
1737
   * All defined profiles mandate MFPR=1 (per Table 9-bb18).
1738
   */
1739
0
  reduced = sp[3];
1740
1741
0
  caps = WPA_CAPABILITY_MFPC | WPA_CAPABILITY_MFPR;
1742
0
  if (reduced & SEC_PROF_REDUCED_RSN_CAPA_EXT_KEY_ID)
1743
0
    caps |= WPA_CAPABILITY_EXT_KEY_ID_FOR_UNICAST;
1744
0
  if (reduced & SEC_PROF_REDUCED_RSN_CAPA_OCVC)
1745
0
    caps |= WPA_CAPABILITY_OCVC;
1746
1747
0
  return caps;
1748
0
}
1749
1750
1751
void wpas_set_mgmt_group_cipher(struct wpa_supplicant *wpa_s,
1752
        struct wpa_ssid *ssid, struct wpa_ie_data *ie)
1753
0
{
1754
0
  int sel;
1755
1756
0
  sel = ie->mgmt_group_cipher;
1757
0
  if (ssid->group_mgmt_cipher)
1758
0
    sel &= ssid->group_mgmt_cipher;
1759
0
  if (wpas_get_ssid_pmf(wpa_s, ssid) == NO_MGMT_FRAME_PROTECTION ||
1760
0
      !(ie->capabilities & WPA_CAPABILITY_MFPC))
1761
0
    sel = 0;
1762
0
  wpa_dbg(wpa_s, MSG_DEBUG,
1763
0
    "WPA: AP mgmt_group_cipher 0x%x network profile mgmt_group_cipher 0x%x; available mgmt_group_cipher 0x%x",
1764
0
    ie->mgmt_group_cipher, ssid->group_mgmt_cipher, sel);
1765
0
  if (sel & WPA_CIPHER_AES_128_CMAC) {
1766
0
    wpa_s->mgmt_group_cipher = WPA_CIPHER_AES_128_CMAC;
1767
0
    wpa_dbg(wpa_s, MSG_DEBUG,
1768
0
      "WPA: using MGMT group cipher AES-128-CMAC");
1769
0
  } else if (sel & WPA_CIPHER_BIP_GMAC_128) {
1770
0
    wpa_s->mgmt_group_cipher = WPA_CIPHER_BIP_GMAC_128;
1771
0
    wpa_dbg(wpa_s, MSG_DEBUG,
1772
0
      "WPA: using MGMT group cipher BIP-GMAC-128");
1773
0
  } else if (sel & WPA_CIPHER_BIP_GMAC_256) {
1774
0
    wpa_s->mgmt_group_cipher = WPA_CIPHER_BIP_GMAC_256;
1775
0
    wpa_dbg(wpa_s, MSG_DEBUG,
1776
0
      "WPA: using MGMT group cipher BIP-GMAC-256");
1777
0
  } else if (sel & WPA_CIPHER_BIP_CMAC_256) {
1778
0
    wpa_s->mgmt_group_cipher = WPA_CIPHER_BIP_CMAC_256;
1779
0
    wpa_dbg(wpa_s, MSG_DEBUG,
1780
0
      "WPA: using MGMT group cipher BIP-CMAC-256");
1781
0
  } else {
1782
0
    wpa_s->mgmt_group_cipher = 0;
1783
0
    wpa_dbg(wpa_s, MSG_DEBUG, "WPA: not using MGMT group cipher");
1784
0
  }
1785
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_MGMT_GROUP,
1786
0
       wpa_s->mgmt_group_cipher);
1787
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_MFP,
1788
0
       wpas_get_ssid_pmf(wpa_s, ssid));
1789
0
}
1790
1791
/**
1792
 * wpa_supplicant_get_psk - Get PSK from config or external database
1793
 * @wpa_s: Pointer to wpa_supplicant data
1794
 * @bss: Scan results for the selected BSS, or %NULL if not available
1795
 * @ssid: Configuration data for the selected network
1796
 * @psk: Buffer for the PSK
1797
 * Returns: 0 on success or -1 if configuration parsing failed
1798
 *
1799
 * This function obtains the PSK for a network, either included inline in the
1800
 * config or retrieved from an external database.
1801
 */
1802
static int wpa_supplicant_get_psk(struct wpa_supplicant *wpa_s,
1803
          struct wpa_bss *bss, struct wpa_ssid *ssid,
1804
          u8 *psk)
1805
0
{
1806
0
  if (ssid->psk_set) {
1807
0
    wpa_hexdump_key(MSG_MSGDUMP, "PSK (set in config)",
1808
0
        ssid->psk, PMK_LEN);
1809
0
    os_memcpy(psk, ssid->psk, PMK_LEN);
1810
0
    return 0;
1811
0
  }
1812
1813
0
#ifndef CONFIG_NO_PBKDF2
1814
0
  if (bss && ssid->bssid_set && ssid->ssid_len == 0 && ssid->passphrase) {
1815
0
    if (pbkdf2_sha1(ssid->passphrase, bss->ssid, bss->ssid_len,
1816
0
        4096, psk, PMK_LEN) != 0) {
1817
0
      wpa_msg(wpa_s, MSG_WARNING, "Error in pbkdf2_sha1()");
1818
0
      return -1;
1819
0
    }
1820
0
    wpa_hexdump_key(MSG_MSGDUMP, "PSK (from passphrase)",
1821
0
        psk, PMK_LEN);
1822
0
    return 0;
1823
0
  }
1824
0
#endif /* CONFIG_NO_PBKDF2 */
1825
1826
#ifdef CONFIG_EXT_PASSWORD
1827
  if (ssid->ext_psk) {
1828
    struct wpabuf *pw = ext_password_get(wpa_s->ext_pw,
1829
                 ssid->ext_psk);
1830
    char pw_str[64 + 1];
1831
1832
    if (!pw) {
1833
      wpa_msg(wpa_s, MSG_INFO,
1834
        "EXT PW: No PSK found from external storage");
1835
      return -1;
1836
    }
1837
1838
    if (wpabuf_len(pw) < 8 || wpabuf_len(pw) > 64) {
1839
      wpa_msg(wpa_s, MSG_INFO,
1840
        "EXT PW: Unexpected PSK length %d in external storage",
1841
        (int) wpabuf_len(pw));
1842
      ext_password_free(pw);
1843
      return -1;
1844
    }
1845
1846
    os_memcpy(pw_str, wpabuf_head(pw), wpabuf_len(pw));
1847
    pw_str[wpabuf_len(pw)] = '\0';
1848
1849
#ifndef CONFIG_NO_PBKDF2
1850
    if (wpabuf_len(pw) >= 8 && wpabuf_len(pw) < 64 && bss)
1851
    {
1852
      if (pbkdf2_sha1(pw_str, bss->ssid, bss->ssid_len,
1853
          4096, psk, PMK_LEN) != 0) {
1854
        wpa_msg(wpa_s, MSG_WARNING,
1855
          "Error in pbkdf2_sha1()");
1856
        forced_memzero(pw_str, sizeof(pw_str));
1857
        ext_password_free(pw);
1858
        return -1;
1859
      }
1860
      wpa_hexdump_key(MSG_MSGDUMP,
1861
          "PSK (from external passphrase)",
1862
          psk, PMK_LEN);
1863
    } else
1864
#endif /* CONFIG_NO_PBKDF2 */
1865
    if (wpabuf_len(pw) == 2 * PMK_LEN) {
1866
      if (hexstr2bin(pw_str, psk, PMK_LEN) < 0) {
1867
        wpa_msg(wpa_s, MSG_INFO,
1868
          "EXT PW: Invalid PSK hex string");
1869
        forced_memzero(pw_str, sizeof(pw_str));
1870
        ext_password_free(pw);
1871
        return -1;
1872
      }
1873
      wpa_hexdump_key(MSG_MSGDUMP, "PSK (from external PSK)",
1874
          psk, PMK_LEN);
1875
    } else {
1876
      wpa_msg(wpa_s, MSG_INFO,
1877
        "EXT PW: No suitable PSK available");
1878
      forced_memzero(pw_str, sizeof(pw_str));
1879
      ext_password_free(pw);
1880
      return -1;
1881
    }
1882
1883
    forced_memzero(pw_str, sizeof(pw_str));
1884
    ext_password_free(pw);
1885
1886
    return 0;
1887
  }
1888
#endif /* CONFIG_EXT_PASSWORD */
1889
1890
0
  return -1;
1891
0
}
1892
1893
1894
static void wpas_update_allowed_key_mgmt(struct wpa_supplicant *wpa_s,
1895
           struct wpa_ssid *ssid)
1896
0
{
1897
0
  int akm_count = wpa_s->max_num_akms;
1898
0
  u8 capab = 0;
1899
#ifdef CONFIG_SAE
1900
  enum sae_pwe sae_pwe;
1901
#endif /* CONFIG_SAE */
1902
1903
0
  if (akm_count < 2)
1904
0
    return;
1905
1906
0
  akm_count--;
1907
0
  wpa_s->allowed_key_mgmts = 0;
1908
0
  switch (wpa_s->key_mgmt) {
1909
0
  case WPA_KEY_MGMT_PSK:
1910
0
    if (ssid->key_mgmt & WPA_KEY_MGMT_SAE) {
1911
0
      akm_count--;
1912
0
      wpa_s->allowed_key_mgmts |= WPA_KEY_MGMT_SAE;
1913
0
    }
1914
0
    if (!akm_count)
1915
0
      break;
1916
0
    if (ssid->key_mgmt & WPA_KEY_MGMT_SAE_EXT_KEY) {
1917
0
      akm_count--;
1918
0
      wpa_s->allowed_key_mgmts |= WPA_KEY_MGMT_SAE_EXT_KEY;
1919
0
    }
1920
0
    if (!akm_count)
1921
0
      break;
1922
0
    if (ssid->key_mgmt & WPA_KEY_MGMT_PSK_SHA256)
1923
0
      wpa_s->allowed_key_mgmts |=
1924
0
        WPA_KEY_MGMT_PSK_SHA256;
1925
0
    break;
1926
0
  case WPA_KEY_MGMT_PSK_SHA256:
1927
0
    if (ssid->key_mgmt & WPA_KEY_MGMT_SAE) {
1928
0
      akm_count--;
1929
0
      wpa_s->allowed_key_mgmts |= WPA_KEY_MGMT_SAE;
1930
0
    }
1931
0
    if (!akm_count)
1932
0
      break;
1933
0
    if (ssid->key_mgmt & WPA_KEY_MGMT_SAE_EXT_KEY) {
1934
0
      akm_count--;
1935
0
      wpa_s->allowed_key_mgmts |= WPA_KEY_MGMT_SAE_EXT_KEY;
1936
0
    }
1937
0
    if (!akm_count)
1938
0
      break;
1939
0
    if (ssid->key_mgmt & WPA_KEY_MGMT_PSK)
1940
0
      wpa_s->allowed_key_mgmts |= WPA_KEY_MGMT_PSK;
1941
0
    break;
1942
0
  case WPA_KEY_MGMT_SAE:
1943
0
    if (ssid->key_mgmt & WPA_KEY_MGMT_PSK) {
1944
0
      akm_count--;
1945
0
      wpa_s->allowed_key_mgmts |= WPA_KEY_MGMT_PSK;
1946
0
    }
1947
0
    if (!akm_count)
1948
0
      break;
1949
0
    if (ssid->key_mgmt & WPA_KEY_MGMT_SAE_EXT_KEY) {
1950
0
      akm_count--;
1951
0
      wpa_s->allowed_key_mgmts |= WPA_KEY_MGMT_SAE_EXT_KEY;
1952
0
    }
1953
0
    if (!akm_count)
1954
0
      break;
1955
0
    if (ssid->key_mgmt & WPA_KEY_MGMT_PSK_SHA256)
1956
0
      wpa_s->allowed_key_mgmts |=
1957
0
        WPA_KEY_MGMT_PSK_SHA256;
1958
0
    break;
1959
0
  case WPA_KEY_MGMT_SAE_EXT_KEY:
1960
0
    if (ssid->key_mgmt & WPA_KEY_MGMT_SAE) {
1961
0
      akm_count--;
1962
0
      wpa_s->allowed_key_mgmts |= WPA_KEY_MGMT_SAE;
1963
0
    }
1964
0
    if (!akm_count)
1965
0
      break;
1966
0
    if (ssid->key_mgmt & WPA_KEY_MGMT_PSK) {
1967
0
      akm_count--;
1968
0
      wpa_s->allowed_key_mgmts |= WPA_KEY_MGMT_PSK;
1969
0
    }
1970
0
    if (!akm_count)
1971
0
      break;
1972
0
    if (ssid->key_mgmt & WPA_KEY_MGMT_PSK_SHA256)
1973
0
      wpa_s->allowed_key_mgmts |=
1974
0
        WPA_KEY_MGMT_PSK_SHA256;
1975
0
    break;
1976
0
  default:
1977
0
    return;
1978
0
  }
1979
1980
#ifdef CONFIG_SAE
1981
  sae_pwe = wpas_get_ssid_sae_pwe(wpa_s, ssid);
1982
  if (sae_pwe != SAE_PWE_HUNT_AND_PECK &&
1983
      sae_pwe != SAE_PWE_FORCE_HUNT_AND_PECK)
1984
    capab |= BIT(WLAN_RSNX_CAPAB_SAE_H2E);
1985
#ifdef CONFIG_SAE_PK
1986
  if (ssid->sae_pk)
1987
    capab |= BIT(WLAN_RSNX_CAPAB_SAE_PK);
1988
#endif /* CONFIG_SAE_PK */
1989
#endif /* CONFIG_SAE */
1990
1991
0
  if (!((wpa_s->allowed_key_mgmts &
1992
0
         (WPA_KEY_MGMT_SAE | WPA_KEY_MGMT_SAE_EXT_KEY)) && capab))
1993
0
    return;
1994
1995
0
  if (!wpa_s->rsnxe_len) {
1996
0
    wpa_s->rsnxe_len = 3;
1997
0
    wpa_s->rsnxe[0] = WLAN_EID_RSNX;
1998
0
    wpa_s->rsnxe[1] = 1;
1999
0
    wpa_s->rsnxe[2] = 0;
2000
0
  }
2001
2002
0
  wpa_s->rsnxe[2] |= capab;
2003
0
}
2004
2005
2006
/**
2007
 * wpa_supplicant_set_suites - Set authentication and encryption parameters
2008
 * @wpa_s: Pointer to wpa_supplicant data
2009
 * @bss: Scan results for the selected BSS, or %NULL if not available
2010
 * @ssid: Configuration data for the selected network
2011
 * @wpa_ie: Buffer for the WPA/RSN IE
2012
 * @wpa_ie_len: Maximum wpa_ie buffer size on input. This is changed to be the
2013
 * used buffer length in case the functions returns success.
2014
 * @skip_default_rsne: Whether to skip setting of the default RSNE/RSNXE
2015
 * Returns: 0 on success or -1 on failure
2016
 *
2017
 * This function is used to configure authentication and encryption parameters
2018
 * based on the network configuration and scan result for the selected BSS (if
2019
 * available).
2020
 */
2021
int wpa_supplicant_set_suites(struct wpa_supplicant *wpa_s,
2022
            struct wpa_bss *bss, struct wpa_ssid *ssid,
2023
            u8 *wpa_ie, size_t *wpa_ie_len,
2024
            bool skip_default_rsne)
2025
0
{
2026
0
  struct wpa_ie_data ie;
2027
0
  int sel, proto;
2028
#ifdef CONFIG_SAE
2029
  enum sae_pwe sae_pwe;
2030
#endif /* CONFIG_SAE */
2031
0
  const u8 *bss_wpa, *bss_rsn, *bss_rsnx;
2032
0
  const u8 *bss_sp = NULL; /* AP's Security Profile element */
2033
0
  u8 sp_rsnx_buf[2 + 255]; /* Synthetic RSNXE from Security Profile
2034
          * element */
2035
0
  bool wmm;
2036
0
  struct rsn_pmksa_cache_entry *pmksa;
2037
2038
0
  if (bss) {
2039
0
    bss_wpa = wpa_bss_get_vendor_ie(bss, WPA_IE_VENDOR_TYPE);
2040
0
    bss_rsn = wpa_bss_get_rsne(wpa_s, bss, ssid, false);
2041
0
    bss_rsnx = wpa_bss_get_rsnxe(wpa_s, bss, ssid, false);
2042
2043
    /*
2044
     * Security Profile element (IEEE P802.11bn/D2.0, 9.4.2.369):
2045
     * When the AP advertises this element and the driver and
2046
     * wpa_supplicant supports security profile negotiation, the
2047
     * security profile number takes precedence over the
2048
     * RSNE/RSNOE/RSNO2E/RSNXE/RSNXOE for AKM, pairwise cipher, RSN
2049
     * capabilities, and RSNX capabilities selection.
2050
     */
2051
0
    if (wpas_security_profile_active(wpa_s))
2052
0
      bss_sp = wpa_bss_get_ie_ext(
2053
0
        bss, WLAN_EID_EXT_SECURITY_PROFILE);
2054
0
  } else {
2055
0
    bss_wpa = bss_rsn = bss_rsnx = NULL;
2056
0
  }
2057
2058
0
  if (bss_rsn && (ssid->proto & WPA_PROTO_RSN) &&
2059
0
      wpa_parse_wpa_ie(bss_rsn, 2 + bss_rsn[1], &ie) == 0 &&
2060
0
      (matching_ciphers(ssid, &ie, bss->freq) ||
2061
       /*
2062
        * Security profile preference (IEEE P802.11bn/D2.0, 37.33):
2063
        * All defined profiles use GCMP-256 as pairwise cipher.
2064
        * If the AP advertises a security profile that matches the
2065
        * STA's configured AKM, treat GCMP-256 as available even if
2066
        * the RSNE/RSNOE/RSNO2E does not list it.
2067
        */
2068
0
       (bss_sp &&
2069
0
        security_profile_get_key_mgmt(bss_sp, ssid->key_mgmt) &&
2070
0
        (ssid->pairwise_cipher & WPA_CIPHER_GCMP_256))) &&
2071
0
      ((ie.key_mgmt & ssid->key_mgmt) ||
2072
       /*
2073
        * Security profile preference (IEEE P802.11bn/D2.0, 37.33):
2074
        * Consider the AP as supporting the AKM implied by any security
2075
        * profile number it advertises, even if the RSNE/RSNOE/RSNO2E
2076
        * does not explicitly list that AKM. Similarly, all defined
2077
        * profiles use GCMP-256 as pairwise cipher, so treat GCMP-256 as
2078
        * available when a matching profile exists.
2079
        */
2080
0
       (bss_sp &&
2081
0
        security_profile_get_key_mgmt(bss_sp, ssid->key_mgmt) &&
2082
0
        (ssid->pairwise_cipher & WPA_CIPHER_GCMP_256)))) {
2083
    /*
2084
     * When the RSNE did not advertise the AKM/cipher but the
2085
     * Security Profile element did, augment ie so that the rest of
2086
     * wpa_supplicant_set_suites() can proceed normally.
2087
     */
2088
0
    if (bss_sp &&
2089
0
        security_profile_get_key_mgmt(bss_sp, ssid->key_mgmt)) {
2090
0
      int sp_key_mgmt = security_profile_get_key_mgmt(
2091
0
        bss_sp, ssid->key_mgmt);
2092
2093
0
      if (!(ie.pairwise_cipher & WPA_CIPHER_GCMP_256) &&
2094
0
          (ssid->pairwise_cipher & WPA_CIPHER_GCMP_256)) {
2095
0
        wpa_dbg(wpa_s, MSG_DEBUG,
2096
0
          "RSN: Security Profile element overrides RSNE pairwise cipher (GCMP-256)");
2097
0
        ie.pairwise_cipher |= WPA_CIPHER_GCMP_256;
2098
0
        ie.has_pairwise = 1;
2099
0
      }
2100
0
      if (!(ie.key_mgmt & ssid->key_mgmt) && sp_key_mgmt) {
2101
0
        wpa_dbg(wpa_s, MSG_DEBUG,
2102
0
          "RSN: Security Profile element overrides RSNE AKM (key_mgmt=0x%x)",
2103
0
          sp_key_mgmt);
2104
0
        ie.key_mgmt |= sp_key_mgmt;
2105
0
      }
2106
0
    }
2107
0
    wpa_dbg(wpa_s, MSG_DEBUG, "RSN: using IEEE 802.11i/D9.0");
2108
0
    proto = WPA_PROTO_RSN;
2109
0
  } else if (bss_wpa && (ssid->proto & WPA_PROTO_WPA) &&
2110
0
       wpa_parse_wpa_ie(bss_wpa, 2 + bss_wpa[1], &ie) == 0 &&
2111
0
       (ie.group_cipher & ssid->group_cipher) &&
2112
0
       (ie.pairwise_cipher & ssid->pairwise_cipher) &&
2113
0
       (ie.key_mgmt & ssid->key_mgmt)) {
2114
0
    wpa_dbg(wpa_s, MSG_DEBUG, "WPA: using IEEE 802.11i/D3.0");
2115
0
    proto = WPA_PROTO_WPA;
2116
0
  } else if (bss) {
2117
0
    wpa_msg(wpa_s, MSG_WARNING, "WPA: Failed to select WPA/RSN");
2118
0
    wpa_dbg(wpa_s, MSG_DEBUG,
2119
0
      "WPA: ssid proto=0x%x pairwise_cipher=0x%x group_cipher=0x%x key_mgmt=0x%x",
2120
0
      ssid->proto, ssid->pairwise_cipher, ssid->group_cipher,
2121
0
      ssid->key_mgmt);
2122
0
    wpa_dbg(wpa_s, MSG_DEBUG, "WPA: BSS " MACSTR " ssid='%s'%s%s",
2123
0
      MAC2STR(bss->bssid),
2124
0
      wpa_ssid_txt(bss->ssid, bss->ssid_len),
2125
0
      bss_wpa ? " WPA" : "",
2126
0
      bss_rsn ? " RSN" : "");
2127
0
    if (bss_rsn) {
2128
0
      wpa_hexdump(MSG_DEBUG, "RSN", bss_rsn, 2 + bss_rsn[1]);
2129
0
      if (wpa_parse_wpa_ie(bss_rsn, 2 + bss_rsn[1], &ie)) {
2130
0
        wpa_dbg(wpa_s, MSG_DEBUG,
2131
0
          "Could not parse RSN element");
2132
0
      } else {
2133
0
        wpa_dbg(wpa_s, MSG_DEBUG,
2134
0
          "RSN: pairwise_cipher=0x%x group_cipher=0x%x key_mgmt=0x%x",
2135
0
          ie.pairwise_cipher, ie.group_cipher,
2136
0
          ie.key_mgmt);
2137
0
      }
2138
0
    }
2139
0
    if (bss_wpa) {
2140
0
      wpa_hexdump(MSG_DEBUG, "WPA", bss_wpa, 2 + bss_wpa[1]);
2141
0
      if (wpa_parse_wpa_ie(bss_wpa, 2 + bss_wpa[1], &ie)) {
2142
0
        wpa_dbg(wpa_s, MSG_DEBUG,
2143
0
          "Could not parse WPA element");
2144
0
      } else {
2145
0
        wpa_dbg(wpa_s, MSG_DEBUG,
2146
0
          "WPA: pairwise_cipher=0x%x group_cipher=0x%x key_mgmt=0x%x",
2147
0
          ie.pairwise_cipher, ie.group_cipher,
2148
0
          ie.key_mgmt);
2149
0
      }
2150
0
    }
2151
0
    return -1;
2152
0
  } else {
2153
0
    if (ssid->proto & WPA_PROTO_RSN)
2154
0
      proto = WPA_PROTO_RSN;
2155
0
    else
2156
0
      proto = WPA_PROTO_WPA;
2157
0
    if (wpa_supplicant_suites_from_ai(wpa_s, ssid, &ie) < 0) {
2158
0
      os_memset(&ie, 0, sizeof(ie));
2159
0
      ie.group_cipher = ssid->group_cipher;
2160
0
      ie.pairwise_cipher = ssid->pairwise_cipher;
2161
0
      ie.key_mgmt = ssid->key_mgmt;
2162
0
      ie.mgmt_group_cipher = 0;
2163
0
      if (ssid->ieee80211w != NO_MGMT_FRAME_PROTECTION) {
2164
0
        if (ssid->group_mgmt_cipher &
2165
0
            WPA_CIPHER_BIP_GMAC_256)
2166
0
          ie.mgmt_group_cipher =
2167
0
            WPA_CIPHER_BIP_GMAC_256;
2168
0
        else if (ssid->group_mgmt_cipher &
2169
0
           WPA_CIPHER_BIP_CMAC_256)
2170
0
          ie.mgmt_group_cipher =
2171
0
            WPA_CIPHER_BIP_CMAC_256;
2172
0
        else if (ssid->group_mgmt_cipher &
2173
0
           WPA_CIPHER_BIP_GMAC_128)
2174
0
          ie.mgmt_group_cipher =
2175
0
            WPA_CIPHER_BIP_GMAC_128;
2176
0
        else
2177
0
          ie.mgmt_group_cipher =
2178
0
            WPA_CIPHER_AES_128_CMAC;
2179
0
      }
2180
#ifdef CONFIG_OWE
2181
      if ((ssid->key_mgmt & WPA_KEY_MGMT_OWE) &&
2182
          !ssid->owe_only &&
2183
          !bss_wpa && !bss_rsn) {
2184
        wpa_supplicant_set_non_wpa_policy(wpa_s, ssid);
2185
        wpa_s->wpa_proto = 0;
2186
        *wpa_ie_len = 0;
2187
        return 0;
2188
      }
2189
#endif /* CONFIG_OWE */
2190
0
      wpa_dbg(wpa_s, MSG_DEBUG, "WPA: Set cipher suites "
2191
0
        "based on configuration");
2192
0
    } else
2193
0
      proto = ie.proto;
2194
0
  }
2195
2196
0
  wpa_dbg(wpa_s, MSG_DEBUG, "WPA: Selected cipher suites: group %d "
2197
0
    "pairwise %d key_mgmt %d proto %d",
2198
0
    ie.group_cipher, ie.pairwise_cipher, ie.key_mgmt, proto);
2199
0
  if (ssid->ieee80211w) {
2200
0
    wpa_dbg(wpa_s, MSG_DEBUG, "WPA: Selected mgmt group cipher %d",
2201
0
      ie.mgmt_group_cipher);
2202
0
  }
2203
2204
  /*
2205
   * Security Profile element preference (IEEE P802.11bn/D2.0, 37.33):
2206
   *
2207
   * 1. RSN Capabilities: The Reduced RSN Capabilities field in the
2208
   *    Security Profile element takes precedence over the RSN
2209
   *    Capabilities field in the RSNE/RSNOE/RSNO2E.
2210
   *    All defined profiles (0-15) mandate MFPR=1 and MFPC=1.
2211
   *    ExtKeyID and OCVC are taken from the Reduced RSN Capabilities.
2212
   *
2213
   * 2. RSNX Capabilities: The Extended RSN Capabilities field in the
2214
   *    Security Profile element takes precedence over the RSNXE/RSNXOE.
2215
   *
2216
   * Apply these overrides now so that all subsequent capability checks
2217
   * (MFPC, ExtKeyID, SSID protection, association encryption, SPP A-MSDU,
2218
   * etc.) use the security profile values.
2219
   */
2220
0
  if (bss_sp && proto == WPA_PROTO_RSN) {
2221
0
    int sp_rsn_caps = security_profile_get_rsn_caps(bss_sp);
2222
0
    size_t ext_rsnx_len;
2223
0
    const u8 *ext_rsnx;
2224
2225
0
    if (sp_rsn_caps && sp_rsn_caps != ie.capabilities) {
2226
0
      wpa_dbg(wpa_s, MSG_DEBUG,
2227
0
        "RSN: Security Profile element overrides RSN capabilities: 0x%x -> 0x%x",
2228
0
        ie.capabilities, sp_rsn_caps);
2229
0
      ie.capabilities = sp_rsn_caps;
2230
0
    }
2231
2232
    /*
2233
     * Override bss_rsnx with the Extended RSN Capabilities from
2234
     * the Security Profile element. The field is encoded in the
2235
     * same wire format as an RSNXE body (length prefix in bits
2236
     * 0-3 of the first octet), so ieee802_11_rsnx_capab_len() can
2237
     * consume it directly.
2238
     *
2239
     * We synthesise a minimal two-byte RSNXE header (EID=244,
2240
     * Length) so that ieee802_11_rsnx_capab() - which expects a
2241
     * full element starting at EID - works without modification.
2242
     * The synthetic element is stored in a local buffer and
2243
     * bss_rsnx is pointed at it for the remainder of this
2244
     * function.
2245
     */
2246
0
    ext_rsnx = security_profile_get_rsnx(bss_sp, &ext_rsnx_len);
2247
2248
0
    if (ext_rsnx && ext_rsnx_len > 0 &&
2249
0
        ext_rsnx_len <= sizeof(sp_rsnx_buf) - 2) {
2250
0
      sp_rsnx_buf[0] = WLAN_EID_RSNX;
2251
0
      sp_rsnx_buf[1] = (u8) ext_rsnx_len;
2252
0
      os_memcpy(sp_rsnx_buf + 2, ext_rsnx, ext_rsnx_len);
2253
0
      wpa_dbg(wpa_s, MSG_DEBUG,
2254
0
        "RSN: Security Profile element overrides RSNX capabilities");
2255
0
      bss_rsnx = sp_rsnx_buf;
2256
0
    }
2257
0
  }
2258
2259
0
  wpa_s->wpa_proto = proto;
2260
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_PROTO, proto);
2261
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_RSN_ENABLED,
2262
0
       !!(ssid->proto & WPA_PROTO_RSN));
2263
2264
0
  if (bss || !wpa_s->ap_ies_from_associnfo) {
2265
0
    const u8 *rsnoe = NULL, *rsno2e = NULL, *rsnxoe = NULL;
2266
0
    const u8 *sec_prof = NULL;
2267
2268
0
    if (bss) {
2269
0
      bss_rsn = wpa_bss_get_ie(bss, WLAN_EID_RSN);
2270
0
      bss_rsnx = wpa_bss_get_ie(bss, WLAN_EID_RSNX);
2271
0
      rsnoe = wpa_bss_get_vendor_ie(
2272
0
        bss, RSNE_OVERRIDE_IE_VENDOR_TYPE);
2273
0
      rsno2e = wpa_bss_get_vendor_ie(
2274
0
        bss, RSNE_OVERRIDE_2_IE_VENDOR_TYPE);
2275
0
      rsnxoe = wpa_bss_get_vendor_ie(
2276
0
        bss, RSNXE_OVERRIDE_IE_VENDOR_TYPE);
2277
0
      sec_prof = wpa_bss_get_ie_ext(
2278
0
        bss, WLAN_EID_EXT_SECURITY_PROFILE);
2279
0
    }
2280
2281
0
    if (wpa_sm_set_ap_wpa_ie(wpa_s->wpa, bss_wpa,
2282
0
           bss_wpa ? 2 + bss_wpa[1] : 0) ||
2283
0
        wpa_sm_set_ap_rsn_ie(wpa_s->wpa, bss_rsn,
2284
0
           bss_rsn ? 2 + bss_rsn[1] : 0) ||
2285
0
        wpa_sm_set_ap_rsnxe(wpa_s->wpa, bss_rsnx,
2286
0
          bss_rsnx ? 2 + bss_rsnx[1] : 0) ||
2287
0
        wpa_sm_set_ap_rsne_override(wpa_s->wpa, rsnoe,
2288
0
            rsnoe ? 2 + rsnoe[1] : 0) ||
2289
0
        wpa_sm_set_ap_rsne_override_2(wpa_s->wpa, rsno2e,
2290
0
              rsno2e ? 2 + rsno2e[1] : 0) ||
2291
0
        wpa_sm_set_ap_rsnxe_override(wpa_s->wpa, rsnxoe,
2292
0
             rsnxoe ? 2 + rsnxoe[1] : 0)||
2293
0
        wpa_sm_set_ap_security_profile(wpa_s->wpa, sec_prof,
2294
0
               sec_prof ? 2 + sec_prof[1] :
2295
0
               0))
2296
0
      return -1;
2297
0
  }
2298
2299
#ifdef CONFIG_NO_WPA
2300
  wpa_s->group_cipher = WPA_CIPHER_NONE;
2301
  wpa_s->pairwise_cipher = WPA_CIPHER_NONE;
2302
#else /* CONFIG_NO_WPA */
2303
0
  sel = ie.group_cipher & ssid->group_cipher;
2304
0
  wpa_dbg(wpa_s, MSG_DEBUG,
2305
0
    "WPA: AP group 0x%x network profile group 0x%x; available group 0x%x",
2306
0
    ie.group_cipher, ssid->group_cipher, sel);
2307
0
  wpa_s->group_cipher = wpa_pick_group_cipher(sel);
2308
0
  if (wpa_s->group_cipher < 0) {
2309
0
    wpa_msg(wpa_s, MSG_WARNING, "WPA: Failed to select group "
2310
0
      "cipher");
2311
0
    return -1;
2312
0
  }
2313
0
  wpa_dbg(wpa_s, MSG_DEBUG, "WPA: using GTK %s",
2314
0
    wpa_cipher_txt(wpa_s->group_cipher));
2315
2316
0
  sel = ie.pairwise_cipher & ssid->pairwise_cipher;
2317
0
  wpa_dbg(wpa_s, MSG_DEBUG,
2318
0
    "WPA: AP pairwise 0x%x network profile pairwise 0x%x; available pairwise 0x%x",
2319
0
    ie.pairwise_cipher, ssid->pairwise_cipher, sel);
2320
0
  wpa_s->pairwise_cipher = wpa_pick_pairwise_cipher(sel, 1);
2321
0
  if (wpa_s->pairwise_cipher < 0) {
2322
0
    wpa_msg(wpa_s, MSG_WARNING, "WPA: Failed to select pairwise "
2323
0
      "cipher");
2324
0
    return -1;
2325
0
  }
2326
0
  wpa_dbg(wpa_s, MSG_DEBUG, "WPA: using PTK %s",
2327
0
    wpa_cipher_txt(wpa_s->pairwise_cipher));
2328
0
#endif /* CONFIG_NO_WPA */
2329
2330
0
  sel = ie.key_mgmt & ssid->key_mgmt;
2331
#ifdef CONFIG_SAE
2332
  if ((!(wpa_s->drv_flags & WPA_DRIVER_FLAGS_SAE) &&
2333
       !(wpa_s->drv_flags2 & WPA_DRIVER_FLAGS2_SAE_OFFLOAD_STA)) ||
2334
      wpas_is_sae_avoided(wpa_s, ssid, &ie))
2335
    sel &= ~(WPA_KEY_MGMT_SAE | WPA_KEY_MGMT_SAE_EXT_KEY |
2336
       WPA_KEY_MGMT_FT_SAE | WPA_KEY_MGMT_FT_SAE_EXT_KEY);
2337
#endif /* CONFIG_SAE */
2338
#ifdef CONFIG_IEEE80211R
2339
  if (!(wpa_s->drv_flags & (WPA_DRIVER_FLAGS_SME |
2340
          WPA_DRIVER_FLAGS_UPDATE_FT_IES)))
2341
    sel &= ~WPA_KEY_MGMT_FT;
2342
#endif /* CONFIG_IEEE80211R */
2343
0
  wpa_dbg(wpa_s, MSG_DEBUG,
2344
0
    "WPA: AP key_mgmt 0x%x network profile key_mgmt 0x%x; available key_mgmt 0x%x",
2345
0
    ie.key_mgmt, ssid->key_mgmt, sel);
2346
0
  if (0) {
2347
#ifdef CONFIG_IEEE80211R
2348
#ifdef CONFIG_SHA384
2349
  } else if ((sel & WPA_KEY_MGMT_FT_IEEE8021X_SHA384) &&
2350
       os_strcmp(wpa_supplicant_get_eap_mode(wpa_s), "LEAP") != 0) {
2351
    wpa_s->key_mgmt = WPA_KEY_MGMT_FT_IEEE8021X_SHA384;
2352
    wpa_dbg(wpa_s, MSG_DEBUG,
2353
      "WPA: using KEY_MGMT FT/802.1X-SHA384");
2354
    if (!ssid->ft_eap_pmksa_caching &&
2355
        pmksa_cache_get_current(wpa_s->wpa)) {
2356
      /* PMKSA caching with FT may have interoperability
2357
       * issues, so disable that case by default for now. */
2358
      wpa_dbg(wpa_s, MSG_DEBUG,
2359
        "WPA: Disable PMKSA caching for FT/802.1X connection");
2360
      pmksa_cache_clear_current(wpa_s->wpa);
2361
    }
2362
#endif /* CONFIG_SHA384 */
2363
#endif /* CONFIG_IEEE80211R */
2364
#ifdef CONFIG_SUITEB192
2365
  } else if (sel & WPA_KEY_MGMT_IEEE8021X_SUITE_B_192) {
2366
    wpa_s->key_mgmt = WPA_KEY_MGMT_IEEE8021X_SUITE_B_192;
2367
    wpa_dbg(wpa_s, MSG_DEBUG,
2368
      "WPA: using KEY_MGMT 802.1X with Suite B (192-bit)");
2369
#endif /* CONFIG_SUITEB192 */
2370
#ifdef CONFIG_SUITEB
2371
  } else if (sel & WPA_KEY_MGMT_IEEE8021X_SUITE_B) {
2372
    wpa_s->key_mgmt = WPA_KEY_MGMT_IEEE8021X_SUITE_B;
2373
    wpa_dbg(wpa_s, MSG_DEBUG,
2374
      "WPA: using KEY_MGMT 802.1X with Suite B");
2375
#endif /* CONFIG_SUITEB */
2376
#ifdef CONFIG_SHA384
2377
  } else if (sel & WPA_KEY_MGMT_IEEE8021X_SHA384) {
2378
    wpa_s->key_mgmt = WPA_KEY_MGMT_IEEE8021X_SHA384;
2379
    wpa_dbg(wpa_s, MSG_DEBUG,
2380
      "WPA: using KEY_MGMT 802.1X with SHA384");
2381
#endif /* CONFIG_SHA384 */
2382
#ifdef CONFIG_FILS
2383
#ifdef CONFIG_IEEE80211R
2384
  } else if (sel & WPA_KEY_MGMT_FT_FILS_SHA384) {
2385
    wpa_s->key_mgmt = WPA_KEY_MGMT_FT_FILS_SHA384;
2386
    wpa_dbg(wpa_s, MSG_DEBUG, "WPA: using KEY_MGMT FT-FILS-SHA384");
2387
#endif /* CONFIG_IEEE80211R */
2388
  } else if (sel & WPA_KEY_MGMT_FILS_SHA384) {
2389
    wpa_s->key_mgmt = WPA_KEY_MGMT_FILS_SHA384;
2390
    wpa_dbg(wpa_s, MSG_DEBUG, "WPA: using KEY_MGMT FILS-SHA384");
2391
#ifdef CONFIG_IEEE80211R
2392
  } else if (sel & WPA_KEY_MGMT_FT_FILS_SHA256) {
2393
    wpa_s->key_mgmt = WPA_KEY_MGMT_FT_FILS_SHA256;
2394
    wpa_dbg(wpa_s, MSG_DEBUG, "WPA: using KEY_MGMT FT-FILS-SHA256");
2395
#endif /* CONFIG_IEEE80211R */
2396
  } else if (sel & WPA_KEY_MGMT_FILS_SHA256) {
2397
    wpa_s->key_mgmt = WPA_KEY_MGMT_FILS_SHA256;
2398
    wpa_dbg(wpa_s, MSG_DEBUG, "WPA: using KEY_MGMT FILS-SHA256");
2399
#endif /* CONFIG_FILS */
2400
#ifdef CONFIG_IEEE80211R
2401
  } else if ((sel & WPA_KEY_MGMT_FT_IEEE8021X) &&
2402
       os_strcmp(wpa_supplicant_get_eap_mode(wpa_s), "LEAP") != 0) {
2403
    wpa_s->key_mgmt = WPA_KEY_MGMT_FT_IEEE8021X;
2404
    wpa_dbg(wpa_s, MSG_DEBUG, "WPA: using KEY_MGMT FT/802.1X");
2405
    if (!ssid->ft_eap_pmksa_caching &&
2406
        pmksa_cache_get_current(wpa_s->wpa)) {
2407
      /* PMKSA caching with FT may have interoperability
2408
       * issues, so disable that case by default for now. */
2409
      wpa_dbg(wpa_s, MSG_DEBUG,
2410
        "WPA: Disable PMKSA caching for FT/802.1X connection");
2411
      pmksa_cache_clear_current(wpa_s->wpa);
2412
    }
2413
#endif /* CONFIG_IEEE80211R */
2414
#ifdef CONFIG_DPP
2415
  } else if (sel & WPA_KEY_MGMT_DPP) {
2416
    wpa_s->key_mgmt = WPA_KEY_MGMT_DPP;
2417
    wpa_dbg(wpa_s, MSG_DEBUG, "RSN: using KEY_MGMT DPP");
2418
#endif /* CONFIG_DPP */
2419
#ifdef CONFIG_SAE
2420
  } else if (sel & WPA_KEY_MGMT_FT_SAE_EXT_KEY) {
2421
    wpa_s->key_mgmt = WPA_KEY_MGMT_FT_SAE_EXT_KEY;
2422
    wpa_dbg(wpa_s, MSG_DEBUG,
2423
      "RSN: using KEY_MGMT FT/SAE (ext key)");
2424
  } else if (sel & WPA_KEY_MGMT_SAE_EXT_KEY) {
2425
    wpa_s->key_mgmt = WPA_KEY_MGMT_SAE_EXT_KEY;
2426
    wpa_dbg(wpa_s, MSG_DEBUG, "RSN: using KEY_MGMT SAE (ext key)");
2427
  } else if (sel & WPA_KEY_MGMT_FT_SAE) {
2428
    wpa_s->key_mgmt = WPA_KEY_MGMT_FT_SAE;
2429
    wpa_dbg(wpa_s, MSG_DEBUG, "RSN: using KEY_MGMT FT/SAE");
2430
  } else if (sel & WPA_KEY_MGMT_SAE) {
2431
    wpa_s->key_mgmt = WPA_KEY_MGMT_SAE;
2432
    wpa_dbg(wpa_s, MSG_DEBUG, "RSN: using KEY_MGMT SAE");
2433
#endif /* CONFIG_SAE */
2434
#ifdef CONFIG_IEEE80211R
2435
  } else if (sel & WPA_KEY_MGMT_FT_PSK) {
2436
    wpa_s->key_mgmt = WPA_KEY_MGMT_FT_PSK;
2437
    wpa_dbg(wpa_s, MSG_DEBUG, "WPA: using KEY_MGMT FT/PSK");
2438
#endif /* CONFIG_IEEE80211R */
2439
0
  } else if (sel & WPA_KEY_MGMT_IEEE8021X_SHA256) {
2440
0
    wpa_s->key_mgmt = WPA_KEY_MGMT_IEEE8021X_SHA256;
2441
0
    wpa_dbg(wpa_s, MSG_DEBUG,
2442
0
      "WPA: using KEY_MGMT 802.1X with SHA256");
2443
0
  } else if (sel & WPA_KEY_MGMT_PSK_SHA256) {
2444
0
    wpa_s->key_mgmt = WPA_KEY_MGMT_PSK_SHA256;
2445
0
    wpa_dbg(wpa_s, MSG_DEBUG,
2446
0
      "WPA: using KEY_MGMT PSK with SHA256");
2447
0
  } else if (sel & WPA_KEY_MGMT_IEEE8021X) {
2448
0
    wpa_s->key_mgmt = WPA_KEY_MGMT_IEEE8021X;
2449
0
    wpa_dbg(wpa_s, MSG_DEBUG, "WPA: using KEY_MGMT 802.1X");
2450
0
  } else if (sel & WPA_KEY_MGMT_PSK) {
2451
0
    wpa_s->key_mgmt = WPA_KEY_MGMT_PSK;
2452
0
    wpa_dbg(wpa_s, MSG_DEBUG, "WPA: using KEY_MGMT WPA-PSK");
2453
0
  } else if (sel & WPA_KEY_MGMT_WPA_NONE) {
2454
0
    wpa_s->key_mgmt = WPA_KEY_MGMT_WPA_NONE;
2455
0
    wpa_dbg(wpa_s, MSG_DEBUG, "WPA: using KEY_MGMT WPA-NONE");
2456
#ifdef CONFIG_OWE
2457
  } else if (sel & WPA_KEY_MGMT_OWE) {
2458
    wpa_s->key_mgmt = WPA_KEY_MGMT_OWE;
2459
    wpa_dbg(wpa_s, MSG_DEBUG, "RSN: using KEY_MGMT OWE");
2460
#endif /* CONFIG_OWE */
2461
#ifdef CONFIG_ENC_ASSOC
2462
  } else if (sel & WPA_KEY_MGMT_EPPKE) {
2463
    wpa_s->key_mgmt = WPA_KEY_MGMT_EPPKE;
2464
    wpa_dbg(wpa_s, MSG_DEBUG, "RSN: using KEY_MGMT EPPKE");
2465
#endif /* CONFIG_ENC_ASSOC */
2466
0
  } else {
2467
0
    wpa_msg(wpa_s, MSG_WARNING, "WPA: Failed to select "
2468
0
      "authenticated key management type");
2469
0
    return -1;
2470
0
  }
2471
2472
  /* There might be a PMKSA cache entry for the target AP, but the current
2473
   * connection is trying to use PSK (which does not use PMKSA caching) or
2474
   * an AKM that does not match the one that was used to generate the
2475
   * selected PMKSA entry. The previously selected PMKSA cache entry needs
2476
   * to be cleared in such cases to avoid indicating an incorrect PMKID
2477
   * and exchange that would likely end up failing with the AP attempting
2478
   * to use a different PMK. This is not really supposed to happen in
2479
   * normal use cases, but it is possible that some corner cases of the AP
2480
   * changing its configuration might trigger a failure due to mismatching
2481
   * PMK. */
2482
0
  pmksa = pmksa_cache_get_current(wpa_s->wpa);
2483
0
  if (pmksa &&
2484
0
      (wpa_key_mgmt_wpa_psk_no_sae(wpa_s->key_mgmt) ||
2485
0
       (pmksa->akmp && pmksa->akmp != wpa_s->key_mgmt))) {
2486
0
    wpa_printf(MSG_DEBUG,
2487
0
         "RSN: Disable PMKSA caching due to incompatible AKMP (PMKSA: 0x%x, selected: 0x%x)",
2488
0
         pmksa->akmp, wpa_s->key_mgmt);
2489
0
    pmksa_cache_clear_current(wpa_s->wpa);
2490
0
  }
2491
2492
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_KEY_MGMT, wpa_s->key_mgmt);
2493
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_PAIRWISE,
2494
0
       wpa_s->pairwise_cipher);
2495
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_GROUP, wpa_s->group_cipher);
2496
2497
0
  if (!(ie.capabilities & WPA_CAPABILITY_MFPC) &&
2498
0
      (wpas_get_ssid_pmf(wpa_s, ssid) == MGMT_FRAME_PROTECTION_REQUIRED ||
2499
0
       (bss && is_6ghz_freq(bss->freq)))) {
2500
0
    wpa_msg(wpa_s, MSG_INFO,
2501
0
      "RSN: Management frame protection required but the selected AP does not enable it");
2502
0
    return -1;
2503
0
  }
2504
2505
0
  wpas_set_mgmt_group_cipher(wpa_s, ssid, &ie);
2506
#ifdef CONFIG_OCV
2507
  if ((wpa_s->drv_flags & WPA_DRIVER_FLAGS_SME) ||
2508
      (wpa_s->drv_flags2 & WPA_DRIVER_FLAGS2_OCV))
2509
    wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_OCV, ssid->ocv);
2510
#endif /* CONFIG_OCV */
2511
#ifdef CONFIG_SAE
2512
  sae_pwe = wpas_get_ssid_sae_pwe(wpa_s, ssid);
2513
  if ((ssid->sae_password_id ||
2514
       wpa_key_mgmt_sae_ext_key(wpa_s->key_mgmt)) &&
2515
      sae_pwe != SAE_PWE_FORCE_HUNT_AND_PECK)
2516
    sae_pwe = SAE_PWE_HASH_TO_ELEMENT;
2517
  if (bss && is_6ghz_freq(bss->freq) &&
2518
      sae_pwe == SAE_PWE_HUNT_AND_PECK) {
2519
    wpa_dbg(wpa_s, MSG_DEBUG,
2520
      "RSN: Enable SAE hash-to-element mode for 6 GHz BSS");
2521
    sae_pwe = SAE_PWE_BOTH;
2522
  }
2523
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_SAE_PWE, sae_pwe);
2524
#ifdef CONFIG_SAE_PK
2525
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_SAE_PK,
2526
       wpa_key_mgmt_sae(ssid->key_mgmt) &&
2527
       ssid->sae_pk != SAE_PK_MODE_DISABLED &&
2528
       ((ssid->sae_password &&
2529
         sae_pk_valid_password(ssid->sae_password)) ||
2530
        (!ssid->sae_password && ssid->passphrase &&
2531
         sae_pk_valid_password(ssid->passphrase))));
2532
#endif /* CONFIG_SAE_PK */
2533
#endif /* CONFIG_SAE */
2534
0
  if (bss && is_6ghz_freq(bss->freq) &&
2535
0
      wpas_get_ssid_pmf(wpa_s, ssid) != MGMT_FRAME_PROTECTION_REQUIRED) {
2536
0
    wpa_dbg(wpa_s, MSG_DEBUG, "RSN: Force MFPR=1 on 6 GHz");
2537
0
    wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_MFP,
2538
0
         MGMT_FRAME_PROTECTION_REQUIRED);
2539
0
  }
2540
#ifdef CONFIG_TESTING_OPTIONS
2541
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_FT_RSNXE_USED,
2542
       wpa_s->ft_rsnxe_used);
2543
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_OCI_FREQ_EAPOL,
2544
       wpa_s->oci_freq_override_eapol);
2545
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_OCI_FREQ_EAPOL_G2,
2546
       wpa_s->oci_freq_override_eapol_g2);
2547
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_OCI_FREQ_FT_ASSOC,
2548
       wpa_s->oci_freq_override_ft_assoc);
2549
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_OCI_FREQ_FILS_ASSOC,
2550
       wpa_s->oci_freq_override_fils_assoc);
2551
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_DISABLE_EAPOL_G2_TX,
2552
       wpa_s->disable_eapol_g2_tx);
2553
  wpa_sm_set_param(wpa_s->wpa,
2554
       WPA_PARAM_EAPOL_2_KEY_INFO_SET_MASK,
2555
       wpa_s->eapol_2_key_info_set_mask);
2556
#endif /* CONFIG_TESTING_OPTIONS */
2557
2558
  /* Extended Key ID is only supported in infrastructure BSS so far */
2559
0
  if (ssid->mode == WPAS_MODE_INFRA && wpa_s->conf->extended_key_id &&
2560
0
      (ssid->proto & WPA_PROTO_RSN) &&
2561
0
      ssid->pairwise_cipher & (WPA_CIPHER_CCMP | WPA_CIPHER_CCMP_256 |
2562
0
             WPA_CIPHER_GCMP | WPA_CIPHER_GCMP_256) &&
2563
0
      (wpa_s->drv_flags & WPA_DRIVER_FLAGS_EXTENDED_KEY_ID)) {
2564
0
    int use_ext_key_id = 0;
2565
2566
0
    wpa_msg(wpa_s, MSG_DEBUG,
2567
0
      "WPA: Enable Extended Key ID support");
2568
0
    wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_EXT_KEY_ID,
2569
0
         wpa_s->conf->extended_key_id);
2570
0
    if (bss_rsn &&
2571
0
        wpa_s->conf->extended_key_id &&
2572
0
        wpa_s->pairwise_cipher != WPA_CIPHER_TKIP &&
2573
0
        (ie.capabilities & WPA_CAPABILITY_EXT_KEY_ID_FOR_UNICAST))
2574
0
      use_ext_key_id = 1;
2575
0
    wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_USE_EXT_KEY_ID,
2576
0
         use_ext_key_id);
2577
0
  } else {
2578
0
    wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_EXT_KEY_ID, 0);
2579
0
    wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_USE_EXT_KEY_ID, 0);
2580
0
  }
2581
2582
  /* Mark WMM enabled for any HT/VHT/HE/EHT/UHR association to get more
2583
   * appropriate advertisement of the supported number of PTKSA receive
2584
   * counters. In theory, this could be based on a driver capability, but
2585
   * in practice all cases using WMM support at least eight replay
2586
   * counters, so use a hardcoded value for now since there is no explicit
2587
   * driver capability indication for this.
2588
   *
2589
   * In addition, claim WMM to be enabled if the AP supports it since it
2590
   * is far more likely for any current device to support WMM. */
2591
0
  wmm = wpa_s->connection_set &&
2592
0
    (wpa_s->connection_ht || wpa_s->connection_vht ||
2593
0
     wpa_s->connection_he || wpa_s->connection_eht ||
2594
0
     wpa_s->connection_uhr);
2595
0
  if (!wmm && bss)
2596
0
    wmm = !!wpa_bss_get_vendor_ie(bss, WMM_IE_VENDOR_TYPE);
2597
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_WMM_ENABLED, wmm);
2598
2599
0
  if (ssid->ssid_protection && proto == WPA_PROTO_RSN) {
2600
0
    bool ssid_prot;
2601
2602
    /* Enable SSID protection based on the AP advertising support
2603
     * for it to avoid potential interoperability issues with
2604
     * incorrect AP behavior if we were to send an "unexpected"
2605
     * RSNXE with multiple octets of payload.
2606
     *
2607
     * Security Profile element preference (IEEE P802.11bn/D2.0,
2608
     * 37.33):
2609
     * bss_rsnx was already reassigned back to the AP's RSNXE
2610
     * above (for wpa_sm_set_ap_rsnxe()), so also consult the
2611
     * Security Profile element's unmasked copy here -- an AP
2612
     * that strips this bit from its RSNXE still advertises the true
2613
     * capability through the Security Profile element. */
2614
0
    ssid_prot = ieee802_11_rsnx_capab(
2615
0
      bss_rsnx, WLAN_RSNX_CAPAB_SSID_PROTECTION) ||
2616
0
      (bss && wpas_eppke_ap_rsnx_capab(
2617
0
        wpa_s, bss,
2618
0
        WLAN_RSNX_CAPAB_SSID_PROTECTION));
2619
0
    if (!skip_default_rsne)
2620
0
      wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_SSID_PROTECTION,
2621
0
           proto == WPA_PROTO_RSN && ssid_prot);
2622
0
  } else {
2623
0
    wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_SSID_PROTECTION, false);
2624
0
  }
2625
2626
#ifdef CONFIG_ENC_ASSOC
2627
  if (proto == WPA_PROTO_RSN &&
2628
      (wpa_s->drv_flags2 &
2629
       WPA_DRIVER_FLAGS2_ASSOCIATION_FRAME_ENCRYPTION)) {
2630
    bool assoc_enc;
2631
2632
    /* Enable association frame encryption based on the AP
2633
     * advertising support for it to avoid potential
2634
     * interoperability issues with incorrect AP behavior if we
2635
     * were to send an "unexpected" RSNXE with multiple octets of
2636
     * payload.
2637
     *
2638
     * Security Profile element preference (IEEE P802.11bn/D2.0,
2639
     * 37.33):
2640
     * bss_rsnx was already reassigned back to the AP's RSNXE above
2641
     * (for wpa_sm_set_ap_rsnxe()), so also consult the
2642
     * Security Profile element's unmasked copy here -- an AP
2643
     * that strips this bit from its RSNXE still advertises the true
2644
     * capability through the Security Profile element. */
2645
    assoc_enc = ieee802_11_rsnx_capab(
2646
      bss_rsnx, WLAN_RSNX_CAPAB_ASSOC_FRAME_ENCRYPTION) ||
2647
      (bss && wpas_eppke_ap_rsnx_capab(
2648
        wpa_s, bss,
2649
        WLAN_RSNX_CAPAB_ASSOC_FRAME_ENCRYPTION));
2650
    if (!skip_default_rsne)
2651
      wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_ASSOC_ENC,
2652
           assoc_enc);
2653
  } else {
2654
    wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_ASSOC_ENC, false);
2655
  }
2656
#endif /* CONFIG_ENC_ASSOC */
2657
2658
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_SPP_AMSDU,
2659
0
       (wpa_s->drv_flags2 & WPA_DRIVER_FLAGS2_SPP_AMSDU) &&
2660
0
       ieee802_11_rsnx_capab(bss_rsnx,
2661
0
                 WLAN_RSNX_CAPAB_SPP_A_MSDU) &&
2662
0
       wpa_s->pairwise_cipher & (WPA_CIPHER_CCMP_256 |
2663
0
               WPA_CIPHER_GCMP_256 |
2664
0
               WPA_CIPHER_CCMP |
2665
0
               WPA_CIPHER_GCMP) &&
2666
0
       (wpa_s->wpa_proto & WPA_PROTO_RSN));
2667
2668
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_SAE_PW_ID_CHANGE,
2669
0
       ssid->sae_password_id && ssid->sae_password_id_change);
2670
#ifdef CONFIG_PMKSA_PRIVACY
2671
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_PMKSA_CACHING_PRIVACY,
2672
       ssid->pmksa_privacy);
2673
#endif /* CONFIG_PMKSA_PRIVACY */
2674
2675
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_SECURITY_PROFILE_ACTIVE, false);
2676
2677
  /*
2678
   * Security Profile element - profile selection (IEEE P802.11bn/D2.0,
2679
   * 37.33, Table 9-bb18).
2680
   *
2681
   * When the AP advertises the Security Profile element, the STA selects
2682
   * a single profile number whose AKM and pairwise cipher match the
2683
   * already-negotiated wpa_s->key_mgmt and wpa_s->pairwise_cipher, and
2684
   * whose bit is set in the AP's Security Profile Bitmap.
2685
   *
2686
   * For SME in wpa_supplicant (WPA_DRIVER_FLAGS_SME): always run
2687
   * selection.
2688
   * For SME in driver: only run when the driver indicates Security
2689
   *  Profile element support via WPA_DRIVER_FLAGS2_SECURITY_PROFILE.
2690
   *  Without this flag, leave sel_security_profile = -1 so no element is
2691
   * built or sent.
2692
   *
2693
   * sel_security_profile is set here (or left at -1 if no matching
2694
   * profile is found or the AP does not advertise the element).
2695
   */
2696
0
  wpa_s->sel_security_profile = -1;
2697
0
  if (bss && wpas_security_profile_active(wpa_s)) {
2698
0
    const u8 *sp = wpa_bss_get_ie_ext(
2699
0
      bss, WLAN_EID_EXT_SECURITY_PROFILE);
2700
0
    u8 bitmap_len;
2701
0
    const u8 *bitmap;
2702
0
    bool eap_over_auth = false;
2703
2704
0
    if (!sp ||sp[1] < 3)
2705
0
      goto no_valid_sp;
2706
2707
    /*
2708
     * Element layout (from wpa_bss_get_ie_ext(), which returns
2709
     * the full element starting at EID byte):
2710
     *   [0] = 255 (EID_EXTENSION)
2711
     *   [1] = Length
2712
     *   [2] = 162 (EID_EXT_SECURITY_PROFILE)
2713
     *   [3] = Reduced RSN Capabilities
2714
     *   [4] = Security Profile Indication
2715
     *         B0-B3 = Number Of Octets Of Bitmap
2716
     *         B4-B7 = Number Of Vendor Profiles
2717
     *   [5..] = Security Profile Bitmap
2718
     */
2719
0
    bitmap_len = sp[4] & 0x0F;
2720
0
    bitmap = sp + 5;
2721
2722
0
    if (sp[1] < 3 + bitmap_len)
2723
0
      goto no_valid_sp;
2724
2725
    /*
2726
     * Compute eap_over_auth to disambiguate 802.1X _AUTH profiles
2727
     * (EAP over Authentication frames, profiles 3-7) from non-_AUTH
2728
     * profiles (EAPOL frames, profiles 11-15). Both groups share
2729
     * the same AKM, so this flag is the only distinguishing
2730
     * parameter available without a new driver attribute. The
2731
     * condition mirrors sme_check_802_1x_pmksa_caching() which sets
2732
     * auth_1x->derive_ptk using the same three checks.
2733
     *
2734
     * For EPPKE sub-profiles (0-2), eap_over_auth is irrelevant:
2735
     * the akmp field already carries the pre-authentication AKM.
2736
     * Per IEEE P802.11bn/D2.0, Table 9-bb18, profiles 1 and 2 use
2737
     * the SAE_EXT_KEY (hash-to-element) AKM variants specifically,
2738
     * not the legacy SAE/FT-SAE AKMs (WPA_KEY_MGMT_EPPKE for
2739
     * profile 0, WPA_KEY_MGMT_SAE_EXT_KEY for profile 1,
2740
     * WPA_KEY_MGMT_FT_SAE_EXT_KEY for profile 2), so
2741
     * security_profile_akm_matches() resolves the ambiguity without
2742
     * any extra parameter.
2743
     */
2744
#ifdef CONFIG_IEEE8021X_AUTH
2745
    if (ssid && ssid->eap_over_auth_frame) {
2746
      const u8 *bss_rsnxe =
2747
        wpa_bss_get_ie(bss, WLAN_EID_RSNX);
2748
2749
      eap_over_auth =
2750
        ieee802_11_rsnx_capab(
2751
          bss_rsnxe,
2752
          WLAN_RSNX_CAPAB_ASSOC_FRAME_ENCRYPTION) &&
2753
        (wpa_s->drv_flags2 &
2754
         WPA_DRIVER_FLAGS2_ASSOCIATION_FRAME_ENCRYPTION);
2755
    }
2756
#endif /* CONFIG_IEEE8021X_AUTH */
2757
2758
0
    wpa_s->sel_security_profile =
2759
0
      security_profile_select_num(
2760
0
        wpa_s->key_mgmt, wpa_s->pairwise_cipher,
2761
0
        eap_over_auth, bitmap, bitmap_len);
2762
2763
0
    if (wpa_s->sel_security_profile >= 0) {
2764
0
      wpa_dbg(wpa_s, MSG_DEBUG,
2765
0
        "Security Profile: selected profile %d (key_mgmt=0x%x eap_over_auth=%d)",
2766
0
        wpa_s->sel_security_profile, wpa_s->key_mgmt,
2767
0
        eap_over_auth);
2768
0
      wpa_sm_set_param(wpa_s->wpa,
2769
0
           WPA_PARAM_SECURITY_PROFILE_ACTIVE,
2770
0
           true);
2771
0
    } else {
2772
0
      wpa_dbg(wpa_s, MSG_DEBUG,
2773
0
        "Security Profile: no matching profile found in AP bitmap (key_mgmt=0x%x pairwise=0x%x eap_over_auth=%d)",
2774
0
        wpa_s->key_mgmt, wpa_s->pairwise_cipher,
2775
0
        eap_over_auth);
2776
0
    }
2777
0
  no_valid_sp:
2778
0
  }
2779
2780
0
  if (!skip_default_rsne) {
2781
0
    if (wpa_sm_set_assoc_wpa_ie_default(wpa_s->wpa, wpa_ie,
2782
0
                wpa_ie_len)) {
2783
0
      wpa_msg(wpa_s, MSG_WARNING,
2784
0
        "RSN: Failed to generate RSNE/WPA IE");
2785
0
      return -1;
2786
0
    }
2787
2788
0
#ifndef CONFIG_NO_WPA
2789
0
    wpa_s->rsnxe_len = sizeof(wpa_s->rsnxe);
2790
0
    if (wpa_sm_set_assoc_rsnxe_default(wpa_s->wpa, wpa_s->rsnxe,
2791
0
               &wpa_s->rsnxe_len)) {
2792
0
      wpa_msg(wpa_s, MSG_WARNING,
2793
0
        "RSN: Failed to generate RSNXE");
2794
0
      return -1;
2795
0
    }
2796
0
#endif /* CONFIG_NO_WPA */
2797
0
  }
2798
2799
  /*
2800
   * Security Profile element (IEEE P802.11bn/D2.0, 9.4.2.369, 37.33).
2801
   *
2802
   * Build the element after the RSNE and RSNXE are finalised so that all
2803
   * wpa_sm parameters (mfp, ocv, ext_key_id, assoc_encryption, etc.)
2804
   * are fully committed before we read them via rsn_supp_capab(sm) and
2805
   * wpa_sm_get_rsnxe_capab(sm). This guarantees that the Security Profile
2806
   * element's Reduced RSN Capabilities and Extended RSN Capabilities
2807
   * fields are identical to the values in the RSNE and RSNXE
2808
   * respectively.
2809
   *
2810
   * The element is stored in wpa_s->security_profile and appended to
2811
   * Authentication and (Re)Association Request frames by
2812
   * sme_send_authentication() and sme_associate().
2813
   */
2814
0
  wpa_s->security_profile_len = 0;
2815
0
  if (wpa_s->sel_security_profile >= 0) {
2816
0
    int ret;
2817
2818
0
    ret = security_profile_build_sta(
2819
0
      wpa_s->wpa, wpa_s->sel_security_profile,
2820
0
      wpa_s->security_profile,
2821
0
      sizeof(wpa_s->security_profile));
2822
0
    if (ret > 0) {
2823
0
      wpa_s->security_profile_len = ret;
2824
0
      wpa_dbg(wpa_s, MSG_DEBUG,
2825
0
        "Security Profile element built: profile=%d len=%d",
2826
0
        wpa_s->sel_security_profile, ret);
2827
0
    } else {
2828
0
      wpa_msg(wpa_s, MSG_WARNING,
2829
0
        "Security Profile: failed to build element (profile=%d)",
2830
0
        wpa_s->sel_security_profile);
2831
0
      return -1;
2832
0
    }
2833
0
  }
2834
2835
0
  if (0) {
2836
#ifdef CONFIG_DPP
2837
  } else if (wpa_s->key_mgmt == WPA_KEY_MGMT_DPP) {
2838
    /* Use PMK from DPP network introduction (PMKSA entry) */
2839
    wpa_sm_set_pmk_from_pmksa(wpa_s->wpa);
2840
#ifdef CONFIG_DPP2
2841
    wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_DPP_PFS, ssid->dpp_pfs);
2842
#endif /* CONFIG_DPP2 */
2843
#endif /* CONFIG_DPP */
2844
0
  } else if (wpa_key_mgmt_wpa_psk(ssid->key_mgmt)) {
2845
0
    int psk_set = 0;
2846
2847
0
    if (wpa_key_mgmt_wpa_psk_no_sae(ssid->key_mgmt)) {
2848
0
      u8 psk[PMK_LEN];
2849
2850
0
      if (wpa_supplicant_get_psk(wpa_s, bss, ssid,
2851
0
               psk) == 0) {
2852
0
        wpa_sm_set_pmk(wpa_s->wpa, psk, PMK_LEN, NULL,
2853
0
                 NULL);
2854
0
        psk_set = 1;
2855
0
      }
2856
0
      forced_memzero(psk, sizeof(psk));
2857
0
    }
2858
2859
0
    if (wpa_key_mgmt_sae(ssid->key_mgmt) &&
2860
0
        (ssid->sae_password || ssid->passphrase || ssid->ext_psk))
2861
0
      psk_set = 1;
2862
2863
0
    if (!psk_set && !ssid->pmk_valid) {
2864
0
      wpa_msg(wpa_s, MSG_INFO,
2865
0
        "No PSK/PMK available for association");
2866
0
      wpas_auth_failed(wpa_s, "NO_PSK_AVAILABLE", NULL);
2867
0
      return -1;
2868
0
    }
2869
#ifdef CONFIG_OWE
2870
  } else if (wpa_s->key_mgmt == WPA_KEY_MGMT_OWE) {
2871
    /* OWE Diffie-Hellman exchange in (Re)Association
2872
     * Request/Response frames set the PMK, so do not override it
2873
     * here. */
2874
#endif /* CONFIG_OWE */
2875
0
  } else
2876
0
    wpa_sm_set_pmk_from_pmksa(wpa_s->wpa);
2877
2878
0
  if (ssid->mode != WPAS_MODE_IBSS &&
2879
0
      !(wpa_s->drv_flags & WPA_DRIVER_FLAGS_WIRED) &&
2880
0
      (ssid->wpa_deny_ptk0_rekey == PTK0_REKEY_ALLOW_NEVER ||
2881
0
       (ssid->wpa_deny_ptk0_rekey == PTK0_REKEY_ALLOW_LOCAL_OK &&
2882
0
        !(wpa_s->drv_flags & WPA_DRIVER_FLAGS_SAFE_PTK0_REKEYS)))) {
2883
0
    wpa_msg(wpa_s, MSG_INFO,
2884
0
      "Disable PTK0 rekey support - replaced with reconnect");
2885
0
    wpa_s->deny_ptk0_rekey = 1;
2886
0
    wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_DENY_PTK0_REKEY, 1);
2887
0
  } else {
2888
0
    wpa_s->deny_ptk0_rekey = 0;
2889
0
    wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_DENY_PTK0_REKEY, 0);
2890
0
  }
2891
2892
0
  if (wpa_key_mgmt_cross_akm(wpa_s->key_mgmt) &&
2893
0
      !(wpa_s->drv_flags & WPA_DRIVER_FLAGS_SME))
2894
0
    wpas_update_allowed_key_mgmt(wpa_s, ssid);
2895
2896
0
  return 0;
2897
0
}
2898
2899
2900
static void wpas_ext_capab_byte(struct wpa_supplicant *wpa_s, u8 *pos, int idx,
2901
        struct wpa_bss *bss)
2902
0
{
2903
0
#ifndef CONFIG_NO_ROBUST_AV
2904
0
  bool scs = true, mscs = true;
2905
0
#endif /* CONFIG_NO_ROBUST_AV */
2906
2907
0
  *pos = 0x00;
2908
2909
0
  switch (idx) {
2910
0
  case 0: /* Bits 0-7 */
2911
0
    break;
2912
0
  case 1: /* Bits 8-15 */
2913
0
    if (wpa_s->conf->coloc_intf_reporting) {
2914
      /* Bit 13 - Collocated Interference Reporting */
2915
0
      *pos |= 0x20;
2916
0
    }
2917
0
    break;
2918
0
  case 2: /* Bits 16-23 */
2919
0
#ifdef CONFIG_WNM
2920
0
    *pos |= 0x02; /* Bit 17 - WNM-Sleep Mode */
2921
0
    if ((wpas_driver_bss_selection(wpa_s) ||
2922
0
         !wpa_s->disable_mbo_oce) &&
2923
0
        !wpa_s->conf->disable_btm)
2924
0
      *pos |= 0x08; /* Bit 19 - BSS Transition */
2925
0
#endif /* CONFIG_WNM */
2926
0
    break;
2927
0
  case 3: /* Bits 24-31 */
2928
0
#ifdef CONFIG_WNM
2929
0
    *pos |= 0x02; /* Bit 25 - SSID List */
2930
0
#endif /* CONFIG_WNM */
2931
0
#ifdef CONFIG_INTERWORKING
2932
0
    if (wpa_s->conf->interworking)
2933
0
      *pos |= 0x80; /* Bit 31 - Interworking */
2934
0
#endif /* CONFIG_INTERWORKING */
2935
0
    break;
2936
0
  case 4: /* Bits 32-39 */
2937
0
#ifdef CONFIG_INTERWORKING
2938
0
    if (wpa_s->drv_flags & WPA_DRIVER_FLAGS_QOS_MAPPING)
2939
0
      *pos |= 0x01; /* Bit 32 - QoS Map */
2940
0
#endif /* CONFIG_INTERWORKING */
2941
0
    break;
2942
0
  case 5: /* Bits 40-47 */
2943
0
#ifdef CONFIG_HS20
2944
0
    if (wpa_s->conf->hs20)
2945
0
      *pos |= 0x40; /* Bit 46 - WNM-Notification */
2946
0
#endif /* CONFIG_HS20 */
2947
0
#ifdef CONFIG_MBO
2948
0
    *pos |= 0x40; /* Bit 46 - WNM-Notification */
2949
0
#endif /* CONFIG_MBO */
2950
0
    break;
2951
0
  case 6: /* Bits 48-55 */
2952
0
#ifndef CONFIG_NO_ROBUST_AV
2953
#ifdef CONFIG_TESTING_OPTIONS
2954
    if (wpa_s->disable_scs_support)
2955
      scs = false;
2956
#endif /* CONFIG_TESTING_OPTIONS */
2957
0
    if (bss && !wpa_bss_ext_capab(bss, WLAN_EXT_CAPAB_SCS)) {
2958
      /* Drop own SCS capability indication since the AP does
2959
       * not support it. This is needed to avoid
2960
       * interoperability issues with APs that get confused
2961
       * with Extended Capabilities element. */
2962
0
      scs = false;
2963
0
    }
2964
0
    if (scs)
2965
0
      *pos |= 0x40; /* Bit 54 - SCS */
2966
0
#endif /* CONFIG_NO_ROBUST_AV */
2967
0
    break;
2968
0
  case 7: /* Bits 56-63 */
2969
0
    break;
2970
0
  case 8: /* Bits 64-71 */
2971
0
    if (wpa_s->conf->ftm_responder)
2972
0
      *pos |= 0x40; /* Bit 70 - FTM responder */
2973
0
    if (wpa_s->conf->ftm_initiator)
2974
0
      *pos |= 0x80; /* Bit 71 - FTM initiator */
2975
0
    break;
2976
0
  case 9: /* Bits 72-79 */
2977
#ifdef CONFIG_FILS
2978
    if (!wpa_s->disable_fils)
2979
      *pos |= 0x01;
2980
#endif /* CONFIG_FILS */
2981
0
    if (wpa_s->conf->twt_requester)
2982
0
      *pos |= 0x20; /* Bit 77 - TWT Requester Support */
2983
0
    break;
2984
0
  case 10: /* Bits 80-87 */
2985
0
#ifndef CONFIG_NO_ROBUST_AV
2986
#ifdef CONFIG_TESTING_OPTIONS
2987
    if (wpa_s->disable_mscs_support)
2988
      mscs = false;
2989
#endif /* CONFIG_TESTING_OPTIONS */
2990
0
    if (bss && !wpa_bss_ext_capab(bss, WLAN_EXT_CAPAB_MSCS)) {
2991
      /* Drop own MSCS capability indication since the AP does
2992
       * not support it. This is needed to avoid
2993
       * interoperability issues with APs that get confused
2994
       * with Extended Capabilities element. */
2995
0
      mscs = false;
2996
0
    }
2997
0
    if (mscs)
2998
0
      *pos |= 0x20; /* Bit 85 - Mirrored SCS */
2999
0
#endif /* CONFIG_NO_ROBUST_AV */
3000
0
    break;
3001
0
  }
3002
0
}
3003
3004
3005
int wpas_build_ext_capab(struct wpa_supplicant *wpa_s, u8 *buf,
3006
        size_t buflen, struct wpa_bss *bss)
3007
0
{
3008
0
  u8 *pos = buf;
3009
0
  u8 len = 11, i;
3010
3011
0
  if (len < wpa_s->extended_capa_len)
3012
0
    len = wpa_s->extended_capa_len;
3013
0
  if (buflen < (size_t) len + 2) {
3014
0
    wpa_printf(MSG_INFO,
3015
0
         "Not enough room for building extended capabilities element");
3016
0
    return -1;
3017
0
  }
3018
3019
0
  *pos++ = WLAN_EID_EXT_CAPAB;
3020
0
  *pos++ = len;
3021
0
  for (i = 0; i < len; i++, pos++) {
3022
0
    wpas_ext_capab_byte(wpa_s, pos, i, bss);
3023
3024
0
    if (i < wpa_s->extended_capa_len) {
3025
0
      *pos &= ~wpa_s->extended_capa_mask[i];
3026
0
      *pos |= wpa_s->extended_capa[i];
3027
0
    }
3028
0
  }
3029
3030
0
  while (len > 0 && buf[1 + len] == 0) {
3031
0
    len--;
3032
0
    buf[1] = len;
3033
0
  }
3034
0
  if (len == 0)
3035
0
    return 0;
3036
3037
0
  return 2 + len;
3038
0
}
3039
3040
3041
static int wpas_valid_bss(struct wpa_supplicant *wpa_s,
3042
        struct wpa_bss *test_bss)
3043
0
{
3044
0
  struct wpa_bss *bss;
3045
3046
0
  dl_list_for_each(bss, &wpa_s->bss, struct wpa_bss, list) {
3047
0
    if (bss == test_bss)
3048
0
      return 1;
3049
0
  }
3050
3051
0
  return 0;
3052
0
}
3053
3054
3055
static int wpas_valid_ssid(struct wpa_supplicant *wpa_s,
3056
         struct wpa_ssid *test_ssid)
3057
0
{
3058
0
  struct wpa_ssid *ssid;
3059
3060
0
  for (ssid = wpa_s->conf->ssid; ssid; ssid = ssid->next) {
3061
0
    if (ssid == test_ssid)
3062
0
      return 1;
3063
0
  }
3064
3065
0
  return 0;
3066
0
}
3067
3068
3069
int wpas_valid_bss_ssid(struct wpa_supplicant *wpa_s, struct wpa_bss *test_bss,
3070
      struct wpa_ssid *test_ssid)
3071
0
{
3072
0
  if (test_bss && !wpas_valid_bss(wpa_s, test_bss))
3073
0
    return 0;
3074
3075
0
  return test_ssid == NULL || wpas_valid_ssid(wpa_s, test_ssid);
3076
0
}
3077
3078
3079
void wpas_connect_work_free(struct wpa_connect_work *cwork)
3080
0
{
3081
0
  if (cwork == NULL)
3082
0
    return;
3083
0
  os_free(cwork);
3084
0
}
3085
3086
3087
void wpas_connect_work_done(struct wpa_supplicant *wpa_s)
3088
0
{
3089
0
  struct wpa_connect_work *cwork;
3090
0
  struct wpa_radio_work *work = wpa_s->connect_work;
3091
3092
0
  if (!work)
3093
0
    return;
3094
3095
0
  wpa_s->connect_work = NULL;
3096
0
  cwork = work->ctx;
3097
0
  work->ctx = NULL;
3098
0
  wpas_connect_work_free(cwork);
3099
0
  radio_work_done(work);
3100
0
}
3101
3102
3103
int wpas_update_random_addr(struct wpa_supplicant *wpa_s,
3104
          enum wpas_mac_addr_style style,
3105
          struct wpa_ssid *ssid)
3106
0
{
3107
0
  struct os_reltime now;
3108
0
  u8 addr[ETH_ALEN];
3109
3110
0
  os_get_reltime(&now);
3111
  /* Random addresses are valid within a given ESS so check
3112
   * expiration/value only when continuing to use the same ESS. */
3113
0
  if (wpa_s->last_mac_addr_style == style && wpa_s->reassoc_same_ess) {
3114
0
    if (style == WPAS_MAC_ADDR_STYLE_DEDICATED_PER_ESS) {
3115
      /* Pregenerated addresses do not expire but their value
3116
       * might have changed, so let's check that. */
3117
0
      if (ssid &&
3118
0
          ether_addr_equal(wpa_s->own_addr, ssid->mac_value))
3119
0
        return 0;
3120
0
    } else if ((wpa_s->last_mac_addr_change.sec != 0 ||
3121
0
          wpa_s->last_mac_addr_change.usec != 0) &&
3122
0
         !os_reltime_expired(
3123
0
           &now,
3124
0
           &wpa_s->last_mac_addr_change,
3125
0
           wpa_s->conf->rand_addr_lifetime)) {
3126
0
      wpa_msg(wpa_s, MSG_DEBUG,
3127
0
        "Previously selected random MAC address has not yet expired");
3128
0
      return 0;
3129
0
    }
3130
0
  }
3131
3132
0
  switch (style) {
3133
0
  case WPAS_MAC_ADDR_STYLE_RANDOM:
3134
0
    if (random_mac_addr(addr) < 0)
3135
0
      return -1;
3136
0
    break;
3137
0
  case WPAS_MAC_ADDR_STYLE_RANDOM_SAME_OUI:
3138
0
    os_memcpy(addr, wpa_s->perm_addr, ETH_ALEN);
3139
0
    if (random_mac_addr_keep_oui(addr) < 0)
3140
0
      return -1;
3141
0
    break;
3142
0
  case WPAS_MAC_ADDR_STYLE_DEDICATED_PER_ESS:
3143
0
    if (!ssid) {
3144
0
      wpa_msg(wpa_s, MSG_INFO,
3145
0
        "Invalid 'ssid' for address policy 3");
3146
0
      return -1;
3147
0
    }
3148
0
    os_memcpy(addr, ssid->mac_value, ETH_ALEN);
3149
0
    break;
3150
0
  default:
3151
0
    return -1;
3152
0
  }
3153
3154
0
  if (wpa_drv_set_mac_addr(wpa_s, addr) < 0) {
3155
0
    wpa_msg(wpa_s, MSG_INFO,
3156
0
      "Failed to set random MAC address");
3157
0
    return -1;
3158
0
  }
3159
3160
0
  os_get_reltime(&wpa_s->last_mac_addr_change);
3161
0
  wpa_s->mac_addr_changed = 1;
3162
0
  wpa_s->last_mac_addr_style = style;
3163
3164
0
  if (wpa_supplicant_update_mac_addr(wpa_s) < 0) {
3165
0
    wpa_msg(wpa_s, MSG_INFO,
3166
0
      "Could not update MAC address information");
3167
0
    return -1;
3168
0
  }
3169
3170
0
  wpas_p2p_update_dev_addr(wpa_s);
3171
0
  wpas_pr_update_dev_addr(wpa_s);
3172
3173
0
  wpa_msg(wpa_s, MSG_DEBUG, "Using random MAC address " MACSTR,
3174
0
    MAC2STR(addr));
3175
3176
0
  return 1;
3177
0
}
3178
3179
3180
int wpas_update_random_addr_disassoc(struct wpa_supplicant *wpa_s)
3181
0
{
3182
0
  if (wpa_s->wpa_state >= WPA_AUTHENTICATING ||
3183
0
      !wpa_s->conf->preassoc_mac_addr)
3184
0
    return 0;
3185
3186
0
  return wpas_update_random_addr(wpa_s, wpa_s->conf->preassoc_mac_addr,
3187
0
               NULL);
3188
0
}
3189
3190
3191
void wpa_s_setup_sae_pt(struct wpa_supplicant *wpa_s, struct wpa_ssid *ssid,
3192
      bool force)
3193
0
{
3194
#ifdef CONFIG_SAE
3195
  struct wpa_config *conf = wpa_s->conf;
3196
  int *groups = conf->sae_groups;
3197
  int default_groups[] = { 19, 20, 21, 0 };
3198
  const char *password;
3199
  enum sae_pwe sae_pwe;
3200
  const u8 *password_id = (const u8 *) ssid->sae_password_id;
3201
  size_t password_id_len = ssid->sae_password_id ?
3202
    os_strlen(ssid->sae_password_id) : 0;
3203
  struct wpabuf_array *ids;
3204
3205
  if (!groups || groups[0] <= 0)
3206
    groups = default_groups;
3207
3208
  password = ssid->sae_password;
3209
  if (!password)
3210
    password = ssid->passphrase;
3211
3212
  sae_pwe = wpas_get_ssid_sae_pwe(wpa_s, ssid);
3213
3214
  if (!password ||
3215
      !wpa_key_mgmt_sae(ssid->key_mgmt) ||
3216
      (sae_pwe == SAE_PWE_HUNT_AND_PECK && !ssid->sae_password_id &&
3217
       !wpa_key_mgmt_sae_ext_key(ssid->key_mgmt) &&
3218
       !force &&
3219
       !sae_pk_valid_password(password)) ||
3220
      sae_pwe == SAE_PWE_FORCE_HUNT_AND_PECK) {
3221
    /* PT derivation not needed */
3222
    sae_deinit_pt(ssid->pt);
3223
    ssid->pt = NULL;
3224
    return;
3225
  }
3226
3227
  ids = ssid->alt_sae_password_ids;
3228
  if (ids && ids->num) {
3229
    unsigned int idx = os_random() % ids->num;
3230
    struct wpabuf *id = ids->buf[idx];
3231
3232
    password_id = wpabuf_head(id);
3233
    password_id_len = wpabuf_len(id);
3234
    wpa_hexdump(MSG_DEBUG,
3235
          "SAE: Prepare PT for alternative password ID",
3236
          password_id, password_id_len);
3237
    ssid->alt_sae_passwords_ids_idx = idx;
3238
    ssid->alt_sae_passwords_ids_used = true;
3239
  }
3240
3241
  if (ssid->pt) {
3242
    if (!password_id && !ssid->pt->password_id)
3243
      return; /* PT already derived for no PW ID */
3244
    if (password_id && ssid->pt->password_id &&
3245
        password_id_len == wpabuf_len(ssid->pt->password_id) &&
3246
        os_memcmp(password_id, wpabuf_head(ssid->pt->password_id),
3247
            password_id_len) == 0)
3248
      return; /* PT already derived for same PW ID */
3249
3250
    /* PT was derived for another password identifier */
3251
    sae_deinit_pt(ssid->pt);
3252
    ssid->pt = NULL;
3253
  }
3254
  ssid->pt = sae_derive_pt(groups, ssid->ssid, ssid->ssid_len,
3255
         (const u8 *) password, os_strlen(password),
3256
         password_id, password_id_len);
3257
#endif /* CONFIG_SAE */
3258
0
}
3259
3260
3261
void wpa_s_clear_sae_rejected(struct wpa_supplicant *wpa_s)
3262
0
{
3263
#if defined(CONFIG_SAE) && defined(CONFIG_SME)
3264
  os_free(wpa_s->sme.sae_rejected_groups);
3265
  wpa_s->sme.sae_rejected_groups = NULL;
3266
#ifdef CONFIG_TESTING_OPTIONS
3267
  if (wpa_s->extra_sae_rejected_groups) {
3268
    int i, *groups = wpa_s->extra_sae_rejected_groups;
3269
3270
    for (i = 0; groups[i]; i++) {
3271
      wpa_printf(MSG_DEBUG,
3272
           "TESTING: Indicate rejection of an extra SAE group %d",
3273
           groups[i]);
3274
      int_array_add_unique(&wpa_s->sme.sae_rejected_groups,
3275
               groups[i]);
3276
    }
3277
  }
3278
#endif /* CONFIG_TESTING_OPTIONS */
3279
#endif /* CONFIG_SAE && CONFIG_SME */
3280
0
}
3281
3282
3283
int wpas_restore_permanent_mac_addr(struct wpa_supplicant *wpa_s)
3284
0
{
3285
0
  if (wpa_drv_set_mac_addr(wpa_s, NULL) < 0) {
3286
0
    wpa_msg(wpa_s, MSG_INFO,
3287
0
      "Could not restore permanent MAC address");
3288
0
    return -1;
3289
0
  }
3290
0
  wpa_s->mac_addr_changed = 0;
3291
0
  if (wpa_supplicant_update_mac_addr(wpa_s) < 0) {
3292
0
    wpa_msg(wpa_s, MSG_INFO,
3293
0
      "Could not update MAC address information");
3294
0
    return -1;
3295
0
  }
3296
3297
0
  wpas_p2p_update_dev_addr(wpa_s);
3298
3299
0
  wpa_msg(wpa_s, MSG_DEBUG, "Using permanent MAC address");
3300
0
  return 0;
3301
0
}
3302
3303
3304
static void wpas_start_assoc_cb(struct wpa_radio_work *work, int deinit);
3305
3306
/**
3307
 * wpa_supplicant_associate - Request association
3308
 * @wpa_s: Pointer to wpa_supplicant data
3309
 * @bss: Scan results for the selected BSS, or %NULL if not available
3310
 * @ssid: Configuration data for the selected network
3311
 *
3312
 * This function is used to request %wpa_supplicant to associate with a BSS.
3313
 */
3314
void wpa_supplicant_associate(struct wpa_supplicant *wpa_s,
3315
            struct wpa_bss *bss, struct wpa_ssid *ssid)
3316
0
{
3317
0
  bool clear_rejected = true;
3318
0
  struct wpa_connect_work *cwork;
3319
0
  enum wpas_mac_addr_style rand_style;
3320
3321
0
  wpa_s->own_disconnect_req = 0;
3322
0
  wpa_s->own_reconnect_req = 0;
3323
3324
  /*
3325
   * If we are starting a new connection, any previously pending EAPOL
3326
   * RX cannot be valid anymore.
3327
   */
3328
0
  wpabuf_free(wpa_s->pending_eapol_rx);
3329
0
  wpa_s->pending_eapol_rx = NULL;
3330
3331
0
  if (ssid->mac_addr == WPAS_MAC_ADDR_STYLE_NOT_SET)
3332
0
    rand_style = wpa_s->conf->mac_addr;
3333
0
  else
3334
0
    rand_style = ssid->mac_addr;
3335
3336
0
  wpa_s->eapol_failed = 0;
3337
0
  wpa_s->multi_ap_ie = 0;
3338
0
#ifndef CONFIG_NO_WMM_AC
3339
0
  wmm_ac_clear_saved_tspecs(wpa_s);
3340
0
#endif /* CONFIG_NO_WMM_AC */
3341
0
#ifdef CONFIG_WNM
3342
0
  wpa_s->wnm_mode = 0;
3343
0
  wpa_s->wnm_target_bss = NULL;
3344
0
#endif /* CONFIG_WNM */
3345
0
  wpa_s->reassoc_same_bss = 0;
3346
0
  wpa_s->reassoc_same_ess = 0;
3347
#ifdef CONFIG_TESTING_OPTIONS
3348
  wpa_s->testing_resend_assoc = 0;
3349
#endif /* CONFIG_TESTING_OPTIONS */
3350
3351
0
  if (wpa_s->last_ssid == ssid) {
3352
0
    wpa_dbg(wpa_s, MSG_DEBUG, "Re-association to the same ESS");
3353
0
    wpa_s->reassoc_same_ess = 1;
3354
0
    if (wpa_s->current_bss && wpa_s->current_bss == bss) {
3355
0
#ifndef CONFIG_NO_WMM_AC
3356
0
      wmm_ac_save_tspecs(wpa_s);
3357
0
#endif /* CONFIG_NO_WMM_AC */
3358
0
      wpa_s->reassoc_same_bss = 1;
3359
0
      clear_rejected = false;
3360
0
    } else if (wpa_s->current_bss && wpa_s->current_bss != bss) {
3361
0
      os_get_reltime(&wpa_s->roam_start);
3362
0
    }
3363
0
  }
3364
3365
0
  if (clear_rejected)
3366
0
    wpa_s_clear_sae_rejected(wpa_s);
3367
3368
#ifdef CONFIG_SAE
3369
  wpa_s_setup_sae_pt(wpa_s, ssid, false);
3370
#endif /* CONFIG_SAE */
3371
3372
0
  if (rand_style > WPAS_MAC_ADDR_STYLE_PERMANENT) {
3373
0
    int status = wpas_update_random_addr(wpa_s, rand_style, ssid);
3374
3375
0
    if (status < 0)
3376
0
      return;
3377
0
    if (rand_style != WPAS_MAC_ADDR_STYLE_DEDICATED_PER_ESS &&
3378
0
        status > 0) /* MAC changed */
3379
0
      wpa_sm_pmksa_cache_flush(wpa_s->wpa, ssid);
3380
0
  } else if (rand_style == WPAS_MAC_ADDR_STYLE_PERMANENT &&
3381
0
       wpa_s->mac_addr_changed) {
3382
0
    if (wpas_restore_permanent_mac_addr(wpa_s) < 0)
3383
0
      return;
3384
0
  }
3385
0
  wpa_s->last_ssid = ssid;
3386
3387
#ifdef CONFIG_IBSS_RSN
3388
  ibss_rsn_deinit(wpa_s->ibss_rsn);
3389
  wpa_s->ibss_rsn = NULL;
3390
#else /* CONFIG_IBSS_RSN */
3391
0
  if (ssid->mode == WPAS_MODE_IBSS &&
3392
0
      !(ssid->key_mgmt & (WPA_KEY_MGMT_NONE | WPA_KEY_MGMT_WPA_NONE))) {
3393
0
    wpa_msg(wpa_s, MSG_INFO,
3394
0
      "IBSS RSN not supported in the build");
3395
0
    return;
3396
0
  }
3397
0
#endif /* CONFIG_IBSS_RSN */
3398
3399
0
  if (ssid->mode == WPAS_MODE_AP || ssid->mode == WPAS_MODE_P2P_GO ||
3400
0
      ssid->mode == WPAS_MODE_P2P_GROUP_FORMATION) {
3401
#ifdef CONFIG_AP
3402
    if (!(wpa_s->drv_flags & WPA_DRIVER_FLAGS_AP)) {
3403
      wpa_msg(wpa_s, MSG_INFO, "Driver does not support AP "
3404
        "mode");
3405
      return;
3406
    }
3407
    if (wpa_supplicant_create_ap(wpa_s, ssid) < 0) {
3408
      wpa_supplicant_set_state(wpa_s, WPA_DISCONNECTED);
3409
      if (ssid->mode == WPAS_MODE_P2P_GROUP_FORMATION)
3410
        wpas_p2p_ap_setup_failed(wpa_s);
3411
      return;
3412
    }
3413
    wpa_s->current_bss = bss;
3414
#else /* CONFIG_AP */
3415
0
    wpa_msg(wpa_s, MSG_ERROR, "AP mode support not included in "
3416
0
      "the build");
3417
0
#endif /* CONFIG_AP */
3418
0
    return;
3419
0
  }
3420
3421
0
  if (ssid->mode == WPAS_MODE_MESH) {
3422
#ifdef CONFIG_MESH
3423
    if (!(wpa_s->drv_flags & WPA_DRIVER_FLAGS_MESH)) {
3424
      wpa_msg(wpa_s, MSG_INFO,
3425
        "Driver does not support mesh mode");
3426
      return;
3427
    }
3428
    if (bss)
3429
      ssid->frequency = bss->freq;
3430
    if (wpa_supplicant_join_mesh(wpa_s, ssid) < 0) {
3431
      wpa_supplicant_set_state(wpa_s, WPA_INACTIVE);
3432
      wpa_msg(wpa_s, MSG_ERROR, "Could not join mesh");
3433
      return;
3434
    }
3435
    wpa_s->current_bss = bss;
3436
#else /* CONFIG_MESH */
3437
0
    wpa_msg(wpa_s, MSG_ERROR,
3438
0
      "mesh mode support not included in the build");
3439
0
#endif /* CONFIG_MESH */
3440
0
    return;
3441
0
  }
3442
3443
  /*
3444
   * Set WPA state machine configuration to match the selected network now
3445
   * so that the information is available before wpas_start_assoc_cb()
3446
   * gets called. This is needed at least for RSN pre-authentication where
3447
   * candidate APs are added to a list based on scan result processing
3448
   * before completion of the first association.
3449
   */
3450
0
  wpa_supplicant_rsn_supp_set_config(wpa_s, ssid);
3451
3452
#ifdef CONFIG_DPP
3453
  if (wpas_dpp_check_connect(wpa_s, ssid, bss) != 0)
3454
    return;
3455
#endif /* CONFIG_DPP */
3456
3457
#ifdef CONFIG_TDLS
3458
  if (bss)
3459
    wpa_tdls_ap_ies(wpa_s->wpa, wpa_bss_ie_ptr(bss), bss->ie_len);
3460
#endif /* CONFIG_TDLS */
3461
3462
0
#ifdef CONFIG_MBO
3463
0
  wpas_mbo_check_pmf(wpa_s, bss, ssid);
3464
0
#endif /* CONFIG_MBO */
3465
3466
0
  if ((wpa_s->drv_flags & WPA_DRIVER_FLAGS_SME) &&
3467
0
      ssid->mode == WPAS_MODE_INFRA) {
3468
0
    sme_authenticate(wpa_s, bss, ssid);
3469
0
    return;
3470
0
  }
3471
3472
0
  if (wpa_s->connect_work) {
3473
0
    wpa_dbg(wpa_s, MSG_DEBUG, "Reject wpa_supplicant_associate() call since connect_work exist");
3474
0
    return;
3475
0
  }
3476
3477
0
  if (radio_work_pending(wpa_s, "connect")) {
3478
0
    wpa_dbg(wpa_s, MSG_DEBUG, "Reject wpa_supplicant_associate() call since pending work exist");
3479
0
    return;
3480
0
  }
3481
3482
#ifdef CONFIG_SME
3483
  if (ssid->mode == WPAS_MODE_IBSS || ssid->mode == WPAS_MODE_MESH) {
3484
    /* Clear possibly set auth_alg, if any, from last attempt. */
3485
    wpa_s->sme.auth_alg = WPA_AUTH_ALG_OPEN;
3486
  }
3487
#endif /* CONFIG_SME */
3488
3489
0
  wpas_abort_ongoing_scan(wpa_s);
3490
3491
0
  cwork = os_zalloc(sizeof(*cwork));
3492
0
  if (cwork == NULL)
3493
0
    return;
3494
3495
0
  cwork->bss = bss;
3496
0
  cwork->ssid = ssid;
3497
3498
0
  if (!radio_add_work(wpa_s, bss ? bss->freq : 0, "connect", 1,
3499
0
          wpas_start_assoc_cb, cwork)) {
3500
0
    os_free(cwork);
3501
0
  }
3502
0
}
3503
3504
3505
static int bss_is_ibss(struct wpa_bss *bss)
3506
0
{
3507
0
  return (bss->caps & (IEEE80211_CAP_ESS | IEEE80211_CAP_IBSS)) ==
3508
0
    IEEE80211_CAP_IBSS;
3509
0
}
3510
3511
3512
static int drv_supports_vht(struct wpa_supplicant *wpa_s,
3513
          const struct wpa_ssid *ssid)
3514
0
{
3515
0
  enum hostapd_hw_mode hw_mode;
3516
0
  struct hostapd_hw_modes *mode = NULL;
3517
0
  u8 channel;
3518
0
  int i;
3519
3520
0
  hw_mode = ieee80211_freq_to_chan(ssid->frequency, &channel);
3521
0
  if (hw_mode == NUM_HOSTAPD_MODES)
3522
0
    return 0;
3523
0
  for (i = 0; wpa_s->hw.modes && i < wpa_s->hw.num_modes; i++) {
3524
0
    if (wpa_s->hw.modes[i].mode == hw_mode) {
3525
0
      mode = &wpa_s->hw.modes[i];
3526
0
      break;
3527
0
    }
3528
0
  }
3529
3530
0
  if (!mode)
3531
0
    return 0;
3532
3533
0
  return mode->vht_capab != 0;
3534
0
}
3535
3536
3537
static bool ibss_mesh_is_80mhz_avail(int channel, struct hostapd_hw_modes *mode)
3538
0
{
3539
0
  int i;
3540
3541
0
  for (i = channel; i < channel + 16; i += 4) {
3542
0
    struct hostapd_channel_data *chan;
3543
3544
0
    chan = hw_get_channel_chan(mode, i, NULL);
3545
0
    if (!chan ||
3546
0
        chan->flag & (HOSTAPD_CHAN_DISABLED | HOSTAPD_CHAN_NO_IR))
3547
0
      return false;
3548
0
  }
3549
3550
0
  return true;
3551
0
}
3552
3553
3554
static struct wpa_bss * ibss_find_existing_bss(struct wpa_supplicant *wpa_s,
3555
                 const struct wpa_ssid *ssid)
3556
0
{
3557
0
  unsigned int j;
3558
3559
0
  for (j = 0; j < wpa_s->last_scan_res_used; j++) {
3560
0
    struct wpa_bss *bss = wpa_s->last_scan_res[j];
3561
3562
0
    if (!bss_is_ibss(bss))
3563
0
      continue;
3564
3565
0
    if (ssid->ssid_len == bss->ssid_len &&
3566
0
        os_memcmp(ssid->ssid, bss->ssid, bss->ssid_len) == 0)
3567
0
      return bss;
3568
0
  }
3569
0
  return NULL;
3570
0
}
3571
3572
3573
static bool ibss_mesh_can_use_ht(struct wpa_supplicant *wpa_s,
3574
         const struct wpa_ssid *ssid,
3575
         struct hostapd_hw_modes *mode)
3576
0
{
3577
  /* For IBSS check HT_IBSS flag */
3578
0
  if (ssid->mode == WPAS_MODE_IBSS &&
3579
0
      !(wpa_s->drv_flags & WPA_DRIVER_FLAGS_HT_IBSS))
3580
0
    return false;
3581
3582
0
  if (wpa_s->group_cipher == WPA_CIPHER_WEP40 ||
3583
0
      wpa_s->group_cipher == WPA_CIPHER_WEP104 ||
3584
0
      wpa_s->pairwise_cipher == WPA_CIPHER_TKIP) {
3585
0
    wpa_printf(MSG_DEBUG,
3586
0
         "IBSS: WEP/TKIP detected, do not try to enable HT");
3587
0
    return false;
3588
0
  }
3589
3590
0
  if (!ht_supported(mode))
3591
0
    return false;
3592
3593
#ifdef CONFIG_HT_OVERRIDES
3594
  if (ssid->disable_ht)
3595
    return false;
3596
#endif /* CONFIG_HT_OVERRIDES */
3597
3598
0
  return true;
3599
0
}
3600
3601
3602
static bool ibss_mesh_can_use_vht(struct wpa_supplicant *wpa_s,
3603
          const struct wpa_ssid *ssid,
3604
          struct hostapd_hw_modes *mode)
3605
0
{
3606
0
  if (mode->mode != HOSTAPD_MODE_IEEE80211A)
3607
0
    return false;
3608
3609
0
  if (!drv_supports_vht(wpa_s, ssid))
3610
0
    return false;
3611
3612
  /* For IBSS check VHT_IBSS flag */
3613
0
  if (ssid->mode == WPAS_MODE_IBSS &&
3614
0
      !(wpa_s->drv_flags & WPA_DRIVER_FLAGS_VHT_IBSS))
3615
0
    return false;
3616
3617
0
  if (!vht_supported(mode))
3618
0
    return false;
3619
3620
#ifdef CONFIG_VHT_OVERRIDES
3621
  if (ssid->disable_vht)
3622
    return false;
3623
#endif /* CONFIG_VHT_OVERRIDES */
3624
3625
0
  return true;
3626
0
}
3627
3628
3629
static bool ibss_mesh_can_use_he(struct wpa_supplicant *wpa_s,
3630
         const struct wpa_ssid *ssid,
3631
         const struct hostapd_hw_modes *mode,
3632
         int ieee80211_mode)
3633
0
{
3634
#ifdef CONFIG_HE_OVERRIDES
3635
  if (ssid->disable_he)
3636
    return false;
3637
#endif /* CONFIG_HE_OVERRIDES */
3638
3639
0
  switch (mode->mode) {
3640
0
  case HOSTAPD_MODE_IEEE80211G:
3641
0
  case HOSTAPD_MODE_IEEE80211B:
3642
0
  case HOSTAPD_MODE_IEEE80211A:
3643
0
    return mode->he_capab[ieee80211_mode].he_supported;
3644
0
  default:
3645
0
    return false;
3646
0
  }
3647
0
}
3648
3649
3650
static bool ibss_mesh_can_use_eht(struct wpa_supplicant *wpa_s,
3651
          const struct wpa_ssid *ssid,
3652
          const struct hostapd_hw_modes *mode,
3653
          int ieee80211_mode)
3654
0
{
3655
0
  if (ssid->disable_eht)
3656
0
    return false;
3657
3658
0
  switch(mode->mode) {
3659
0
  case HOSTAPD_MODE_IEEE80211G:
3660
0
  case HOSTAPD_MODE_IEEE80211B:
3661
0
  case HOSTAPD_MODE_IEEE80211A:
3662
0
    return mode->eht_capab[ieee80211_mode].eht_supported;
3663
0
  default:
3664
0
    return false;
3665
0
  }
3666
0
}
3667
3668
3669
static void ibss_mesh_select_40mhz(struct wpa_supplicant *wpa_s,
3670
           const struct wpa_ssid *ssid,
3671
           struct hostapd_hw_modes *mode,
3672
           struct hostapd_freq_params *freq,
3673
           int obss_scan, bool is_6ghz)
3674
0
{
3675
0
  int chan_idx;
3676
0
  struct hostapd_channel_data *pri_chan = NULL, *sec_chan = NULL;
3677
0
  int i, res;
3678
0
  unsigned int j;
3679
0
  static const int ht40plus_5ghz[] = {
3680
0
    36, 44, 52, 60, 100, 108, 116, 124, 132, 140,
3681
0
    149, 157, 165, 173, 184, 192
3682
0
  };
3683
0
  static const int ht40plus_6ghz[] = {
3684
0
    1, 9, 17, 25, 33, 41, 49, 57, 65, 73,
3685
0
    81, 89, 97, 105, 113, 121, 129, 137, 145, 153,
3686
0
    161, 169, 177, 185, 193, 201, 209, 217, 225
3687
0
  };
3688
3689
0
  int ht40 = -1;
3690
3691
0
  if (!freq->ht_enabled && !is_6ghz)
3692
0
    return;
3693
3694
0
  for (chan_idx = 0; chan_idx < mode->num_channels; chan_idx++) {
3695
0
    pri_chan = &mode->channels[chan_idx];
3696
0
    if (pri_chan->chan == freq->channel)
3697
0
      break;
3698
0
    pri_chan = NULL;
3699
0
  }
3700
0
  if (!pri_chan)
3701
0
    return;
3702
3703
  /* Check primary channel flags */
3704
0
  if (pri_chan->flag & (HOSTAPD_CHAN_DISABLED | HOSTAPD_CHAN_NO_IR))
3705
0
    return;
3706
3707
#ifdef CONFIG_HT_OVERRIDES
3708
  if (ssid->disable_ht40)
3709
    return;
3710
#endif
3711
3712
  /* Check/setup HT40+/HT40- */
3713
0
  if (is_6ghz) {
3714
0
    for (j = 0; j < ARRAY_SIZE(ht40plus_6ghz); j++) {
3715
0
      if (ht40plus_6ghz[j] == freq->channel) {
3716
0
        ht40 = 1;
3717
0
        break;
3718
0
      }
3719
0
    }
3720
0
  } else {
3721
0
    for (j = 0; j < ARRAY_SIZE(ht40plus_5ghz); j++) {
3722
0
      if (ht40plus_5ghz[j] == freq->channel) {
3723
0
        ht40 = 1;
3724
0
        break;
3725
0
      }
3726
0
    }
3727
0
  }
3728
3729
  /* Find secondary channel */
3730
0
  for (i = 0; i < mode->num_channels; i++) {
3731
0
    sec_chan = &mode->channels[i];
3732
0
    if (sec_chan->chan == freq->channel + ht40 * 4)
3733
0
      break;
3734
0
    sec_chan = NULL;
3735
0
  }
3736
0
  if (!sec_chan)
3737
0
    return;
3738
3739
  /* Check secondary channel flags */
3740
0
  if (sec_chan->flag & (HOSTAPD_CHAN_DISABLED | HOSTAPD_CHAN_NO_IR))
3741
0
    return;
3742
3743
0
  if (freq->ht_enabled) {
3744
0
    if (ht40 == -1) {
3745
0
      if (!(pri_chan->flag & HOSTAPD_CHAN_HT40MINUS))
3746
0
        return;
3747
0
    } else {
3748
0
      if (!(pri_chan->flag & HOSTAPD_CHAN_HT40PLUS))
3749
0
        return;
3750
0
    }
3751
0
  }
3752
0
  freq->sec_channel_offset = ht40;
3753
3754
0
  if (obss_scan) {
3755
0
    struct wpa_scan_results *scan_res;
3756
3757
0
    scan_res = wpa_supplicant_get_scan_results(wpa_s, NULL, 0,
3758
0
                 NULL);
3759
0
    if (scan_res == NULL) {
3760
      /* Back to HT20 */
3761
0
      freq->sec_channel_offset = 0;
3762
0
      return;
3763
0
    }
3764
3765
0
    res = check_40mhz_5g(scan_res, pri_chan, sec_chan);
3766
0
    switch (res) {
3767
0
    case 0:
3768
      /* Back to HT20 */
3769
0
      freq->sec_channel_offset = 0;
3770
0
      break;
3771
0
    case 1:
3772
      /* Configuration allowed */
3773
0
      break;
3774
0
    case 2:
3775
      /* Switch pri/sec channels */
3776
0
      freq->freq = hw_get_freq(mode, sec_chan->chan);
3777
0
      freq->sec_channel_offset = -freq->sec_channel_offset;
3778
0
      freq->channel = sec_chan->chan;
3779
0
      break;
3780
0
    default:
3781
0
      freq->sec_channel_offset = 0;
3782
0
      break;
3783
0
    }
3784
3785
0
    wpa_scan_results_free(scan_res);
3786
0
  }
3787
3788
0
  wpa_printf(MSG_DEBUG,
3789
0
       "IBSS/mesh: setup freq channel %d, sec_channel_offset %d",
3790
0
       freq->channel, freq->sec_channel_offset);
3791
0
}
3792
3793
3794
static int ibss_get_center_320mhz(int channel)
3795
0
{
3796
0
  int seg0;
3797
3798
0
  if (channel >= 1 && channel <= 45)
3799
0
    seg0 = 31;
3800
0
  else if (channel >= 49 && channel <= 77)
3801
0
    seg0 = 63;
3802
0
  else if (channel >= 81 && channel <= 109)
3803
0
    seg0 = 95;
3804
0
  else if (channel >= 113 && channel <= 141)
3805
0
    seg0 = 127;
3806
0
  else if (channel >= 145 && channel <= 173)
3807
0
    seg0 = 159;
3808
0
  else
3809
0
    seg0 = 191;
3810
3811
0
  return seg0;
3812
0
}
3813
3814
3815
static bool ibss_mesh_select_80_160mhz(struct wpa_supplicant *wpa_s,
3816
               const struct wpa_ssid *ssid,
3817
               struct hostapd_hw_modes *mode,
3818
               struct hostapd_freq_params *freq,
3819
0
               int ieee80211_mode, bool is_6ghz) {
3820
0
  static const int bw80[] = {
3821
0
    5180, 5260, 5500, 5580, 5660, 5745, 5825,
3822
0
    5955, 6035, 6115, 6195, 6275, 6355, 6435,
3823
0
    6515, 6595, 6675, 6755, 6835, 6915, 6995
3824
0
  };
3825
0
  static const int bw160[] = {
3826
0
    5180, 5500, 5745, 5955, 6115, 6275, 6435,
3827
0
    6595, 6755, 6915
3828
0
  };
3829
0
  static const int bw320[]= {
3830
0
    5955, 6255, 6115, 6415, 6275, 6575, 6435,
3831
0
    6735, 6595, 6895, 6755, 7055
3832
0
  };
3833
3834
0
  struct hostapd_freq_params vht_freq;
3835
0
  struct hostapd_channel_info info;
3836
0
  int i;
3837
0
  unsigned int j, k;
3838
0
  int chwidth, seg0, seg1;
3839
0
  int offset_in_160 = 1;
3840
0
  int offset_in_320 = 0;
3841
0
  u32 vht_caps = 0;
3842
0
  u8 channel = freq->channel;
3843
3844
0
  if (!freq->vht_enabled && !freq->he_enabled)
3845
0
    return true;
3846
3847
0
  vht_freq = *freq;
3848
3849
0
  chwidth = CONF_OPER_CHWIDTH_USE_HT;
3850
0
  seg0 = freq->channel + 2 * freq->sec_channel_offset;
3851
0
  seg1 = 0;
3852
0
  if (freq->sec_channel_offset == 0) {
3853
0
    seg0 = 0;
3854
    /* Don't try 80 MHz if 40 MHz failed, except in 6 GHz */
3855
0
    if (freq->ht_enabled && !is_6ghz)
3856
0
      goto skip_80mhz;
3857
0
  }
3858
0
  if (ssid->max_oper_chwidth == CONF_OPER_CHWIDTH_USE_HT)
3859
0
    goto skip_80mhz;
3860
3861
  /* setup center_freq1, bandwidth */
3862
0
  for (j = 0; j < ARRAY_SIZE(bw80); j++) {
3863
0
    if (freq->freq >= bw80[j] &&
3864
0
        freq->freq < bw80[j] + 80)
3865
0
      break;
3866
0
  }
3867
3868
0
  if (j == ARRAY_SIZE(bw80) ||
3869
0
      ieee80211_freq_to_chan(bw80[j], &channel) == NUM_HOSTAPD_MODES)
3870
0
    goto skip_80mhz;
3871
3872
  /* Use 40 MHz if channel not usable */
3873
0
  if (!ibss_mesh_is_80mhz_avail(channel, mode))
3874
0
    goto skip_80mhz;
3875
3876
0
  chwidth = CONF_OPER_CHWIDTH_80MHZ;
3877
0
  seg0 = channel + 6;
3878
0
  seg1 = 0;
3879
3880
0
  for (k = 0; k < ARRAY_SIZE(bw160); k++) {
3881
0
    if (bw80[j] >= bw160[k] &&
3882
0
        bw80[j] < bw160[k] + 160) {
3883
0
      if (bw80[j] == bw160[k])
3884
0
        offset_in_160 = 1;
3885
0
      else
3886
0
        offset_in_160 = -1;
3887
0
      break;
3888
0
    }
3889
0
  }
3890
3891
0
  for (k = 0; k < ARRAY_SIZE(bw320); k++) {
3892
0
    if (bw80[j] >= bw320[k] &&
3893
0
        bw80[j] < bw320[k] + 320) {
3894
0
      if (bw80[j] == bw320[k])
3895
0
        offset_in_320 = 0;
3896
0
      else if (bw80[j] == bw320[k] + 80)
3897
0
        offset_in_320 = 1;
3898
0
      else if (bw80[j] == bw320[k] + 160)
3899
0
        offset_in_320 = 2;
3900
0
      else
3901
0
        offset_in_320 = 3;
3902
0
      break;
3903
0
    }
3904
0
  }
3905
3906
  /* In 160 MHz, the initial four 20 MHz channels were validated
3907
   * above. If 160 MHz is supported, check the remaining four 20 MHz
3908
   * channels for the total of 160 MHz bandwidth.
3909
   */
3910
0
  if ((mode->he_capab[ieee80211_mode].phy_cap[
3911
0
         HE_PHYCAP_CHANNEL_WIDTH_SET_IDX] &
3912
0
       HE_PHYCAP_CHANNEL_WIDTH_SET_160MHZ_IN_5G) &&
3913
0
      (ssid->max_oper_chwidth == CONF_OPER_CHWIDTH_160MHZ ||
3914
0
       ssid->max_oper_chwidth == CONF_OPER_CHWIDTH_320MHZ) &&
3915
0
      ibss_mesh_is_80mhz_avail(channel + 16 * offset_in_160, mode)) {
3916
0
    for (j = 0; j < ARRAY_SIZE(bw160); j++) {
3917
0
      u8 start_chan;
3918
3919
0
      if (freq->freq >= bw160[j] &&
3920
0
          freq->freq < bw160[j] + 160) {
3921
0
        chwidth = CONF_OPER_CHWIDTH_160MHZ;
3922
0
        ieee80211_freq_to_chan(bw160[j], &start_chan);
3923
0
        seg0 = start_chan + 14;
3924
0
        break;
3925
0
      }
3926
0
    }
3927
0
  }
3928
3929
  /* In 320 MHz, the initial four 20 MHz channels were validated
3930
   * above. If 320 MHz is supported, check the remaining 12 20 MHz
3931
   * channels for the total of 320 MHz bandwidth for 6 GHz.
3932
   */
3933
0
  if ((mode->eht_capab[ieee80211_mode].phy_cap[
3934
0
         EHT_PHYCAP_320MHZ_IN_6GHZ_SUPPORT_IDX] &
3935
0
       EHT_PHYCAP_320MHZ_IN_6GHZ_SUPPORT_MASK) && is_6ghz &&
3936
0
      ssid->max_oper_chwidth == CONF_OPER_CHWIDTH_320MHZ &&
3937
0
      ibss_mesh_is_80mhz_avail(channel + 16 -
3938
0
             64 * ((offset_in_320 + 1) / 4), mode) &&
3939
0
      ibss_mesh_is_80mhz_avail(channel + 32 -
3940
0
             64 * ((offset_in_320 + 2) / 4), mode) &&
3941
0
      ibss_mesh_is_80mhz_avail(channel + 48 -
3942
0
             64 * ((offset_in_320 + 3) / 4), mode)) {
3943
0
    for (j = 0; j < ARRAY_SIZE(bw320); j += 2) {
3944
0
      if (freq->freq >= bw320[j] &&
3945
0
          freq->freq <= bw320[j + 1]) {
3946
0
        chwidth = CONF_OPER_CHWIDTH_320MHZ;
3947
0
        seg0 = ibss_get_center_320mhz(freq->channel);
3948
0
        break;
3949
0
      }
3950
0
    }
3951
0
  }
3952
3953
0
  if (ssid->max_oper_chwidth == CONF_OPER_CHWIDTH_80P80MHZ) {
3954
    /* setup center_freq2, bandwidth */
3955
0
    for (k = 0; k < ARRAY_SIZE(bw80); k++) {
3956
      /* Only accept 80 MHz segments separated by a gap */
3957
0
      if (j == k || abs(bw80[j] - bw80[k]) == 80)
3958
0
        continue;
3959
3960
0
      if (ieee80211_freq_to_chan(bw80[k], &channel) ==
3961
0
          NUM_HOSTAPD_MODES)
3962
0
        break;
3963
3964
0
      for (i = channel; i < channel + 16; i += 4) {
3965
0
        struct hostapd_channel_data *chan;
3966
3967
0
        chan = hw_get_channel_chan(mode, i, NULL);
3968
0
        if (!chan)
3969
0
          continue;
3970
3971
0
        if (chan->flag & (HOSTAPD_CHAN_DISABLED |
3972
0
              HOSTAPD_CHAN_NO_IR |
3973
0
              HOSTAPD_CHAN_RADAR))
3974
0
          continue;
3975
3976
        /* Found a suitable second segment for 80+80 */
3977
0
        chwidth = CONF_OPER_CHWIDTH_80P80MHZ;
3978
0
        if (!is_6ghz)
3979
0
          vht_caps |=
3980
0
            VHT_CAP_SUPP_CHAN_WIDTH_160_80PLUS80MHZ;
3981
0
        seg1 = channel + 6;
3982
0
      }
3983
3984
0
      if (chwidth == CONF_OPER_CHWIDTH_80P80MHZ)
3985
0
        break;
3986
0
    }
3987
0
  } else if (ssid->max_oper_chwidth == CONF_OPER_CHWIDTH_160MHZ) {
3988
0
    if (freq->freq == 5180) {
3989
0
      chwidth = CONF_OPER_CHWIDTH_160MHZ;
3990
0
      vht_caps |= VHT_CAP_SUPP_CHAN_WIDTH_160MHZ;
3991
0
      seg0 = 50;
3992
0
    } else if (freq->freq == 5520) {
3993
0
      chwidth = CONF_OPER_CHWIDTH_160MHZ;
3994
0
      vht_caps |= VHT_CAP_SUPP_CHAN_WIDTH_160MHZ;
3995
0
      seg0 = 114;
3996
0
    }
3997
0
  }
3998
3999
0
skip_80mhz:
4000
0
  info = (struct hostapd_channel_info) {
4001
0
    .mode = mode->mode,
4002
0
    .freq = freq->freq,
4003
0
    .channel = freq->channel,
4004
0
    .edmg.enabled = ssid->enable_edmg,
4005
0
    .edmg.channel = ssid->edmg_channel,
4006
0
    .ht.enabled = freq->ht_enabled,
4007
0
    .vht.enabled = freq->vht_enabled,
4008
0
    .he.enabled = freq->he_enabled,
4009
0
    .eht.enabled = freq->eht_enabled,
4010
0
    .ht.sec_channel_offset = freq->sec_channel_offset,
4011
0
    .oper_chwidth = chwidth,
4012
0
    .center_segment0 = seg0,
4013
0
    .center_segment1 = seg1,
4014
0
    .vht.caps = vht_caps,
4015
0
    .he.cap = &mode->he_capab[ieee80211_mode],
4016
0
    .eht.cap = &mode->eht_capab[ieee80211_mode],
4017
0
  };
4018
0
  if (hostapd_set_freq_params(&vht_freq, &info))
4019
0
    return false;
4020
4021
0
  *freq = vht_freq;
4022
4023
0
  wpa_printf(MSG_DEBUG, "IBSS: VHT setup freq cf1 %d, cf2 %d, bw %d",
4024
0
       freq->center_freq1, freq->center_freq2, freq->bandwidth);
4025
0
  return true;
4026
0
}
4027
4028
4029
void ibss_mesh_setup_freq(struct wpa_supplicant *wpa_s,
4030
        const struct wpa_ssid *ssid,
4031
        struct hostapd_freq_params *freq)
4032
0
{
4033
0
  int ieee80211_mode = wpas_mode_to_ieee80211_mode(ssid->mode);
4034
0
  enum hostapd_hw_mode hw_mode;
4035
0
  struct hostapd_hw_modes *mode = NULL;
4036
0
  int obss_scan = 1;
4037
0
  u8 channel;
4038
0
  bool is_6ghz, is_24ghz;
4039
4040
0
  freq->freq = ssid->frequency;
4041
4042
0
  if (ssid->mode == WPAS_MODE_IBSS && !ssid->fixed_freq) {
4043
0
    struct wpa_bss *bss = ibss_find_existing_bss(wpa_s, ssid);
4044
4045
0
    if (bss) {
4046
0
      wpa_printf(MSG_DEBUG,
4047
0
           "IBSS already found in scan results, adjust control freq: %d",
4048
0
           bss->freq);
4049
0
      freq->freq = bss->freq;
4050
0
      obss_scan = 0;
4051
0
    }
4052
0
  }
4053
4054
0
  hw_mode = ieee80211_freq_to_chan(freq->freq, &channel);
4055
0
  mode = get_mode(wpa_s->hw.modes, wpa_s->hw.num_modes,
4056
0
      hw_mode, is_6ghz_freq(ssid->frequency));
4057
4058
0
  if (!mode)
4059
0
    return;
4060
4061
0
  is_24ghz = hw_mode == HOSTAPD_MODE_IEEE80211G ||
4062
0
    hw_mode == HOSTAPD_MODE_IEEE80211B;
4063
4064
0
  is_6ghz = is_6ghz_freq(freq->freq);
4065
4066
0
  freq->ht_enabled = 0;
4067
0
  freq->vht_enabled = 0;
4068
0
  freq->he_enabled = 0;
4069
0
  freq->eht_enabled = 0;
4070
4071
0
  if (!is_6ghz)
4072
0
    freq->ht_enabled = ibss_mesh_can_use_ht(wpa_s, ssid, mode);
4073
0
  if (freq->ht_enabled)
4074
0
    freq->vht_enabled = ibss_mesh_can_use_vht(wpa_s, ssid, mode);
4075
0
  if (freq->vht_enabled || (freq->ht_enabled && is_24ghz) || is_6ghz)
4076
0
    freq->he_enabled = ibss_mesh_can_use_he(wpa_s, ssid, mode,
4077
0
              ieee80211_mode);
4078
0
  freq->channel = channel;
4079
  /* Setup higher BW only for 5 and 6 GHz */
4080
0
  if (mode->mode == HOSTAPD_MODE_IEEE80211A) {
4081
0
    ibss_mesh_select_40mhz(wpa_s, ssid, mode, freq, obss_scan,
4082
0
               is_6ghz);
4083
0
    if (!ibss_mesh_select_80_160mhz(wpa_s, ssid, mode, freq,
4084
0
            ieee80211_mode, is_6ghz))
4085
0
      freq->he_enabled = freq->vht_enabled = false;
4086
0
  }
4087
4088
0
  if (freq->he_enabled)
4089
0
    freq->eht_enabled = ibss_mesh_can_use_eht(wpa_s, ssid, mode,
4090
0
                ieee80211_mode);
4091
0
}
4092
4093
4094
#ifdef CONFIG_FILS
4095
static size_t wpas_add_fils_hlp_req(struct wpa_supplicant *wpa_s, u8 *ie_buf,
4096
            size_t ie_buf_len)
4097
{
4098
  struct fils_hlp_req *req;
4099
  size_t rem_len, hdr_len, hlp_len, len, ie_len = 0;
4100
  const u8 *pos;
4101
  u8 *buf = ie_buf;
4102
4103
  dl_list_for_each(req, &wpa_s->fils_hlp_req, struct fils_hlp_req,
4104
       list) {
4105
    rem_len = ie_buf_len - ie_len;
4106
    pos = wpabuf_head(req->pkt);
4107
    hdr_len = 1 + 2 * ETH_ALEN + 6;
4108
    hlp_len = wpabuf_len(req->pkt);
4109
4110
    if (rem_len < 2 + hdr_len + hlp_len) {
4111
      wpa_printf(MSG_ERROR,
4112
           "FILS: Cannot fit HLP - rem_len=%lu to_fill=%lu",
4113
           (unsigned long) rem_len,
4114
           (unsigned long) (2 + hdr_len + hlp_len));
4115
      break;
4116
    }
4117
4118
    len = (hdr_len + hlp_len) > 255 ? 255 : hdr_len + hlp_len;
4119
    /* Element ID */
4120
    *buf++ = WLAN_EID_EXTENSION;
4121
    /* Length */
4122
    *buf++ = len;
4123
    /* Element ID Extension */
4124
    *buf++ = WLAN_EID_EXT_FILS_HLP_CONTAINER;
4125
    /* Destination MAC address */
4126
    os_memcpy(buf, req->dst, ETH_ALEN);
4127
    buf += ETH_ALEN;
4128
    /* Source MAC address */
4129
    os_memcpy(buf, wpa_s->own_addr, ETH_ALEN);
4130
    buf += ETH_ALEN;
4131
    /* LLC/SNAP Header */
4132
    os_memcpy(buf, "\xaa\xaa\x03\x00\x00\x00", 6);
4133
    buf += 6;
4134
    /* HLP Packet */
4135
    os_memcpy(buf, pos, len - hdr_len);
4136
    buf += len - hdr_len;
4137
    pos += len - hdr_len;
4138
4139
    hlp_len -= len - hdr_len;
4140
    ie_len += 2 + len;
4141
    rem_len -= 2 + len;
4142
4143
    while (hlp_len) {
4144
      len = (hlp_len > 255) ? 255 : hlp_len;
4145
      if (rem_len < 2 + len)
4146
        break;
4147
      *buf++ = WLAN_EID_FRAGMENT;
4148
      *buf++ = len;
4149
      os_memcpy(buf, pos, len);
4150
      buf += len;
4151
      pos += len;
4152
4153
      hlp_len -= len;
4154
      ie_len += 2 + len;
4155
      rem_len -= 2 + len;
4156
    }
4157
  }
4158
4159
  return ie_len;
4160
}
4161
4162
4163
int wpa_is_fils_supported(struct wpa_supplicant *wpa_s)
4164
{
4165
  return (((wpa_s->drv_flags & WPA_DRIVER_FLAGS_SME) &&
4166
     (wpa_s->drv_flags & WPA_DRIVER_FLAGS_SUPPORT_FILS)) ||
4167
    (!(wpa_s->drv_flags & WPA_DRIVER_FLAGS_SME) &&
4168
     (wpa_s->drv_flags & WPA_DRIVER_FLAGS_FILS_SK_OFFLOAD)));
4169
}
4170
4171
4172
int wpa_is_fils_sk_pfs_supported(struct wpa_supplicant *wpa_s)
4173
{
4174
#ifdef CONFIG_FILS_SK_PFS
4175
  return (wpa_s->drv_flags & WPA_DRIVER_FLAGS_SME) &&
4176
    (wpa_s->drv_flags & WPA_DRIVER_FLAGS_SUPPORT_FILS);
4177
#else /* CONFIG_FILS_SK_PFS */
4178
  return 0;
4179
#endif /* CONFIG_FILS_SK_PFS */
4180
}
4181
4182
#endif /* CONFIG_FILS */
4183
4184
4185
bool wpa_is_non_eht_scs_traffic_desc_supported(struct wpa_bss *bss)
4186
0
{
4187
0
  const u8 *wfa_capa;
4188
4189
0
  if (!bss)
4190
0
    return false;
4191
4192
  /* Get WFA capability from Beacon or Probe Response frame elements */
4193
0
  wfa_capa = wpa_bss_get_vendor_ie(bss, WFA_CAPA_IE_VENDOR_TYPE);
4194
0
  if (!wfa_capa)
4195
0
    wfa_capa = wpa_bss_get_vendor_ie_beacon(
4196
0
      bss, WFA_CAPA_IE_VENDOR_TYPE);
4197
4198
0
  if (!wfa_capa || wfa_capa[1] < 6 || wfa_capa[6] < 1 ||
4199
0
      !(wfa_capa[7] & WFA_CAPA_QM_NON_EHT_SCS_TRAFFIC_DESC)) {
4200
    /* AP does not enable QM non EHT traffic description policy */
4201
0
    return false;
4202
0
  }
4203
4204
0
  return true;
4205
0
}
4206
4207
4208
int wpas_populate_wfa_capa(struct wpa_supplicant *wpa_s, struct wpa_bss *bss,
4209
         u8 *wpa_ie, size_t wpa_ie_len, size_t max_wpa_ie_len)
4210
0
{
4211
0
  struct wpabuf *wfa_ie = NULL, *attr = NULL;
4212
0
  u8 wfa_capa[1];
4213
0
  u8 capab_len = 0;
4214
0
  size_t wfa_ie_len, buf_len;
4215
4216
0
  os_memset(wfa_capa, 0, sizeof(wfa_capa));
4217
0
#ifndef CONFIG_NO_ROBUST_AV
4218
0
  if (wpa_s->enable_dscp_policy_capa)
4219
0
    wfa_capa[0] |= WFA_CAPA_QM_DSCP_POLICY;
4220
0
#endif /* CONFIG_NO_ROBUST_AV */
4221
4222
0
  if (wpa_is_non_eht_scs_traffic_desc_supported(bss))
4223
0
    wfa_capa[0] |= WFA_CAPA_QM_NON_EHT_SCS_TRAFFIC_DESC;
4224
4225
0
  if (wfa_capa[0])
4226
0
    capab_len = 1;
4227
4228
0
  if (wpa_s->conf->wfa_gen_capa == WFA_GEN_CAPA_UNPROTECTED)
4229
0
    attr = wpas_wfa_gen_capab_attr(wpa_s);
4230
4231
0
  if (capab_len == 0 && !attr)
4232
0
    return wpa_ie_len;
4233
4234
  /* Wi-Fi Alliance element */
4235
0
  buf_len = 1 + /* Element ID */
4236
0
      1 + /* Length */
4237
0
      3 + /* OUI */
4238
0
      1 + /* OUI Type */
4239
0
      1 + /* Capabilities Length */
4240
0
      capab_len + /* Capabilities */
4241
0
      (attr ? wpabuf_len(attr) : 0) /* Attributes */;
4242
0
  wfa_ie = wpabuf_alloc(buf_len);
4243
0
  if (!wfa_ie) {
4244
0
    wpabuf_free(attr);
4245
0
    return wpa_ie_len;
4246
0
  }
4247
4248
0
  wpabuf_put_u8(wfa_ie, WLAN_EID_VENDOR_SPECIFIC);
4249
0
  wpabuf_put_u8(wfa_ie, buf_len - 2);
4250
0
  wpabuf_put_be24(wfa_ie, OUI_WFA);
4251
0
  wpabuf_put_u8(wfa_ie, WFA_CAPA_OUI_TYPE);
4252
0
  wpabuf_put_u8(wfa_ie, capab_len);
4253
0
  wpabuf_put_data(wfa_ie, wfa_capa, capab_len);
4254
0
  if (attr)
4255
0
    wpabuf_put_buf(wfa_ie, attr);
4256
0
  wpabuf_free(attr);
4257
4258
0
  wfa_ie_len = wpabuf_len(wfa_ie);
4259
0
  if (wpa_ie_len + wfa_ie_len <= max_wpa_ie_len) {
4260
0
    wpa_hexdump_buf(MSG_MSGDUMP, "WFA Capabilities element",
4261
0
        wfa_ie);
4262
0
    os_memcpy(wpa_ie + wpa_ie_len, wpabuf_head(wfa_ie),
4263
0
        wfa_ie_len);
4264
0
    wpa_ie_len += wfa_ie_len;
4265
0
  }
4266
4267
0
  wpabuf_free(wfa_ie);
4268
0
  return wpa_ie_len;
4269
0
}
4270
4271
4272
#ifdef CONFIG_IEEE8021X_AUTH
4273
static bool wpas_set_802_1x_auth_alg(struct wpa_supplicant *wpa_s,
4274
             struct wpa_bss *bss,
4275
             struct wpa_ssid *ssid,
4276
             struct wpa_driver_associate_params *params)
4277
{
4278
  const u8 *rsnxe;
4279
4280
  if (!ssid->eap_over_auth_frame ||
4281
      !(wpa_s->drv_flags2 & WPA_DRIVER_FLAGS2_802_1X_AUTH) ||
4282
      !wpa_key_mgmt_wpa_ieee8021x(ssid->key_mgmt &
4283
          ~WPA_KEY_MGMT_IEEE8021X))
4284
    return false;
4285
4286
  params->ieee8021x_auth_supported = true;
4287
4288
  if (!bss)
4289
    return false;
4290
4291
  if (!wpa_key_mgmt_wpa_ieee8021x(wpa_s->key_mgmt &
4292
          ~WPA_KEY_MGMT_IEEE8021X))
4293
    return false;
4294
4295
  rsnxe = wpa_bss_get_ie(bss, WLAN_EID_RSNX);
4296
  if (ieee802_11_rsnx_capab(rsnxe,
4297
          WLAN_RSNX_CAPAB_802_1X_IN_AUTH_FRAMES)) {
4298
    wpa_dbg(wpa_s, MSG_DEBUG,
4299
      "Using IEEE 802.1X authentication using Authentication frames");
4300
    return true;
4301
  }
4302
4303
  return false;
4304
}
4305
#endif /* CONFIG_IEEE8021X_AUTH */
4306
4307
4308
/*
4309
 * wpas_eppke_ap_rsnx_capab - Check an RSNX capability bit for EPPKE purposes,
4310
 * consulting both the AP's RSNXE and the (unmasked) Extended RSN
4311
 * Capabilities embedded in its Security Profile element.
4312
 *
4313
 * The AP is expected to build the Security Profile element's Extended RSN
4314
 * Capabilities field from the full, unmasked RSNXE while it might mask some
4315
 * capabilities from the RSNXE. So a deployment that intentionally strips a
4316
 * capability bit from the RSNXE can still advertise the true capability through
4317
 * the Security Profile element, per IEEE P802.11bn/D2.0, 37.33 where the
4318
 * Security Profile element takes precedence over the RSNXE. Treat the bit as
4319
 * present if either source sets it.
4320
 */
4321
bool wpas_eppke_ap_rsnx_capab(struct wpa_supplicant *wpa_s,
4322
            struct wpa_bss *bss, unsigned int capab)
4323
0
{
4324
0
  const u8 *ap_rsnxe = wpa_bss_get_rsnxe(wpa_s, bss, NULL, false);
4325
4326
0
  if (ieee802_11_rsnx_capab(ap_rsnxe, capab))
4327
0
    return true;
4328
4329
0
  if (wpas_security_profile_active(wpa_s)) {
4330
0
    const u8 *sp_rsnx;
4331
0
    size_t sp_rsnx_len;
4332
0
    const u8 *sp = wpa_bss_get_ie_ext(
4333
0
      bss, WLAN_EID_EXT_SECURITY_PROFILE);
4334
4335
0
    sp_rsnx = security_profile_get_rsnx(sp, &sp_rsnx_len);
4336
0
    if (sp_rsnx &&
4337
0
        ieee802_11_rsnx_capab_len(sp_rsnx, sp_rsnx_len, capab))
4338
0
      return true;
4339
0
  }
4340
4341
0
  return false;
4342
0
}
4343
4344
4345
#ifdef CONFIG_ENC_ASSOC
4346
4347
bool wpas_eppke_ap_capable(struct wpa_supplicant *wpa_s,
4348
          struct wpa_bss *bss, bool unauth_eppke)
4349
{
4350
  if (!(wpa_s->drv_flags2 &
4351
        WPA_DRIVER_FLAGS2_ASSOCIATION_FRAME_ENCRYPTION)) {
4352
    wpa_printf(MSG_DEBUG,
4353
         "EPPKE: Driver does not support association frame encryption");
4354
    return false;
4355
  }
4356
4357
  if (!wpas_eppke_ap_rsnx_capab(wpa_s, bss, WLAN_RSNX_CAPAB_KEK_IN_PASN))
4358
  {
4359
    wpa_printf(MSG_DEBUG, "EPPKE: AP does not support KEK_IN_PASN");
4360
    return false;
4361
  }
4362
4363
  if (!wpas_eppke_ap_rsnx_capab(wpa_s, bss,
4364
          WLAN_RSNX_CAPAB_ASSOC_FRAME_ENCRYPTION))
4365
  {
4366
    wpa_printf(MSG_DEBUG,
4367
         "EPPKE: AP does not support association frame encryption");
4368
    return false;
4369
  }
4370
4371
  if (unauth_eppke &&
4372
      !wpas_eppke_ap_rsnx_capab(wpa_s, bss, WLAN_RSNX_CAPAB_UNAUTH_EPPKE))
4373
  {
4374
    wpa_printf(MSG_DEBUG,
4375
         "EPPKE: AP does not support unauthenticated EPPKE");
4376
    return false;
4377
  }
4378
4379
  return true;
4380
}
4381
4382
4383
static bool wpas_set_eppke_auth_alg(struct wpa_supplicant *wpa_s,
4384
            struct wpa_bss *bss,
4385
            struct wpa_ssid *ssid,
4386
            struct wpa_driver_associate_params *params)
4387
{
4388
  const u8 *rsn;
4389
  struct wpa_ie_data ied;
4390
4391
  if (!wpa_key_mgmt_eppke(ssid->key_mgmt) ||
4392
      !(wpa_s->drv_flags2 & WPA_DRIVER_FLAGS2_EPPKE))
4393
    return false;
4394
4395
  params->eppke_supported = true;
4396
4397
  if (!bss)
4398
    return false;
4399
4400
  rsn = wpa_bss_get_rsne(wpa_s, bss, ssid, false);
4401
  if (!rsn) {
4402
    wpa_dbg(wpa_s, MSG_DEBUG,
4403
      "EPPKE: Target BSS does not advertise RSN");
4404
    return false;
4405
  }
4406
4407
  if (wpa_parse_wpa_ie(rsn, 2 + rsn[1], &ied)) {
4408
    wpa_printf(MSG_DEBUG, "EPPKE: Failed parsing RSNE data");
4409
    return false;
4410
  }
4411
4412
  if (!(ied.key_mgmt & WPA_KEY_MGMT_EPPKE)) {
4413
    wpa_dbg(wpa_s, MSG_DEBUG,
4414
      "EPPKE: Target BSS does not advertise EPPKE AKM");
4415
    return false;
4416
  }
4417
4418
  if (!wpa_key_mgmt_eppke(wpa_s->key_mgmt) &&
4419
      !wpa_key_mgmt_sae_ext_key(wpa_s->key_mgmt)) {
4420
    wpa_dbg(wpa_s, MSG_DEBUG,
4421
      "EPPKE: Negotiated AKM is not an EPPKE Authentication AKM");
4422
    return false;
4423
  }
4424
4425
  if (!wpas_eppke_ap_capable(wpa_s, bss,
4426
           !!wpa_key_mgmt_eppke(wpa_s->key_mgmt))) {
4427
    wpa_dbg(wpa_s, MSG_DEBUG,
4428
      "EPPKE: Target BSS does not indicate support for EPPKE");
4429
    return false;
4430
  }
4431
4432
  wpa_dbg(wpa_s, MSG_DEBUG, "Using EPPKE Authentication");
4433
4434
  return true;
4435
}
4436
4437
#endif /* CONFIG_ENC_ASSOC */
4438
4439
4440
static u8 * wpas_populate_assoc_ies(
4441
  struct wpa_supplicant *wpa_s,
4442
  struct wpa_bss *bss, struct wpa_ssid *ssid,
4443
  struct wpa_driver_associate_params *params,
4444
  enum wpa_drv_update_connect_params_mask *mask)
4445
0
{
4446
0
  u8 *wpa_ie;
4447
0
  size_t max_wpa_ie_len = 500;
4448
0
  size_t wpa_ie_len;
4449
0
  int algs = WPA_AUTH_ALG_OPEN;
4450
#ifdef CONFIG_MBO
4451
  const u8 *mbo_ie;
4452
#endif
4453
#if defined(CONFIG_SAE) || defined(CONFIG_FILS)
4454
  int pmksa_cached = 0;
4455
#endif /* CONFIG_SAE || CONFIG_FILS */
4456
#ifdef CONFIG_FILS
4457
  const u8 *realm, *username, *rrk;
4458
  size_t realm_len, username_len, rrk_len;
4459
  u16 next_seq_num;
4460
  struct fils_hlp_req *req;
4461
4462
  dl_list_for_each(req, &wpa_s->fils_hlp_req, struct fils_hlp_req,
4463
       list) {
4464
    max_wpa_ie_len += 3 + 2 * ETH_ALEN + 6 + wpabuf_len(req->pkt) +
4465
          2 + 2 * wpabuf_len(req->pkt) / 255;
4466
  }
4467
#endif /* CONFIG_FILS */
4468
4469
0
  wpa_ie = os_malloc(max_wpa_ie_len);
4470
0
  if (!wpa_ie) {
4471
0
    wpa_printf(MSG_ERROR,
4472
0
         "Failed to allocate connect IE buffer for %lu bytes",
4473
0
         (unsigned long) max_wpa_ie_len);
4474
0
    return NULL;
4475
0
  }
4476
4477
0
  if (bss && (wpa_bss_get_vendor_ie(bss, WPA_IE_VENDOR_TYPE) ||
4478
0
        wpa_bss_get_rsne(wpa_s, bss, ssid, false)) &&
4479
0
      wpa_key_mgmt_wpa(ssid->key_mgmt)) {
4480
0
    int try_opportunistic;
4481
0
    const u8 *cache_id = NULL;
4482
0
    const u8 *addr = bss->bssid;
4483
4484
0
    if (!(wpa_s->drv_flags & WPA_DRIVER_FLAGS_SME) &&
4485
0
        (wpa_s->drv_flags2 & WPA_DRIVER_FLAGS2_MLO) &&
4486
0
        !is_zero_ether_addr(bss->mld_addr))
4487
0
      addr = bss->mld_addr;
4488
4489
0
    if ((wpa_s->drv_flags & WPA_DRIVER_FLAGS_SME) &&
4490
0
        wpa_s->valid_links)
4491
0
      addr = wpa_s->ap_mld_addr;
4492
4493
0
    try_opportunistic = (ssid->proactive_key_caching < 0 ?
4494
0
             wpa_s->conf->okc :
4495
0
             ssid->proactive_key_caching) &&
4496
0
      (ssid->proto & WPA_PROTO_RSN);
4497
#ifdef CONFIG_FILS
4498
    if (wpa_key_mgmt_fils(ssid->key_mgmt))
4499
      cache_id = wpa_bss_get_fils_cache_id(bss);
4500
#endif /* CONFIG_FILS */
4501
0
    if (pmksa_cache_set_current(wpa_s->wpa, NULL, addr,
4502
0
              ssid, try_opportunistic,
4503
0
              cache_id, 0, false) == 0) {
4504
0
      eapol_sm_notify_pmkid_attempt(wpa_s->eapol);
4505
#if defined(CONFIG_SAE) || defined(CONFIG_FILS)
4506
      pmksa_cached = 1;
4507
#endif /* CONFIG_SAE || CONFIG_FILS */
4508
0
    }
4509
0
    wpa_ie_len = max_wpa_ie_len;
4510
0
    if (wpa_supplicant_set_suites(wpa_s, bss, ssid,
4511
0
                wpa_ie, &wpa_ie_len, false)) {
4512
0
      wpa_msg(wpa_s, MSG_WARNING, "WPA: Failed to set WPA "
4513
0
        "key management and encryption suites");
4514
0
      os_free(wpa_ie);
4515
0
      return NULL;
4516
0
    }
4517
0
  } else if ((ssid->key_mgmt & WPA_KEY_MGMT_IEEE8021X_NO_WPA) && bss &&
4518
0
       wpa_key_mgmt_wpa_ieee8021x(ssid->key_mgmt)) {
4519
    /*
4520
     * Both WPA and non-WPA IEEE 802.1X enabled in configuration -
4521
     * use non-WPA since the scan results did not indicate that the
4522
     * AP is using WPA or WPA2.
4523
     */
4524
0
    wpa_supplicant_set_non_wpa_policy(wpa_s, ssid);
4525
0
    wpa_ie_len = 0;
4526
0
    wpa_s->wpa_proto = 0;
4527
0
  } else if (wpa_key_mgmt_wpa_any(ssid->key_mgmt)) {
4528
0
    wpa_ie_len = max_wpa_ie_len;
4529
0
    if (wpa_supplicant_set_suites(wpa_s, NULL, ssid,
4530
0
                wpa_ie, &wpa_ie_len, false)) {
4531
0
      wpa_msg(wpa_s, MSG_WARNING, "WPA: Failed to set WPA "
4532
0
        "key management and encryption suites (no "
4533
0
        "scan results)");
4534
0
      os_free(wpa_ie);
4535
0
      return NULL;
4536
0
    }
4537
#ifdef CONFIG_WPS
4538
0
  } else if (ssid->key_mgmt & WPA_KEY_MGMT_WPS) {
4539
0
    struct wpabuf *wps_ie;
4540
0
    wps_ie = wps_build_assoc_req_ie(wpas_wps_get_req_type(ssid));
4541
0
    if (wps_ie && wpabuf_len(wps_ie) <= max_wpa_ie_len) {
4542
0
      wpa_ie_len = wpabuf_len(wps_ie);
4543
0
      os_memcpy(wpa_ie, wpabuf_head(wps_ie), wpa_ie_len);
4544
0
    } else
4545
0
      wpa_ie_len = 0;
4546
0
    wpabuf_free(wps_ie);
4547
0
    wpa_supplicant_set_non_wpa_policy(wpa_s, ssid);
4548
0
    if (!bss || (bss->caps & IEEE80211_CAP_PRIVACY))
4549
0
      params->wps = WPS_MODE_PRIVACY;
4550
0
    else
4551
0
      params->wps = WPS_MODE_OPEN;
4552
    wpa_s->wpa_proto = 0;
4553
#endif /* CONFIG_WPS */
4554
0
  } else {
4555
0
    wpa_supplicant_set_non_wpa_policy(wpa_s, ssid);
4556
0
    wpa_ie_len = 0;
4557
0
    wpa_s->wpa_proto = 0;
4558
0
  }
4559
4560
0
#ifdef IEEE8021X_EAPOL
4561
0
  if (ssid->key_mgmt & WPA_KEY_MGMT_IEEE8021X_NO_WPA) {
4562
0
    if (ssid->leap) {
4563
0
      if (ssid->non_leap == 0)
4564
0
        algs = WPA_AUTH_ALG_LEAP;
4565
0
      else
4566
0
        algs |= WPA_AUTH_ALG_LEAP;
4567
0
    }
4568
0
  }
4569
4570
#ifdef CONFIG_FILS
4571
  /* Clear FILS association */
4572
  wpa_sm_set_reset_fils_completed(wpa_s->wpa, 0);
4573
4574
  if ((wpa_s->drv_flags & WPA_DRIVER_FLAGS_FILS_SK_OFFLOAD) &&
4575
      ssid->eap.erp && wpa_key_mgmt_fils(wpa_s->key_mgmt) &&
4576
      eapol_sm_get_erp_info(wpa_s->eapol, &ssid->eap, &username,
4577
          &username_len, &realm, &realm_len,
4578
          &next_seq_num, &rrk, &rrk_len) == 0 &&
4579
      (!wpa_s->last_con_fail_realm ||
4580
       wpa_s->last_con_fail_realm_len != realm_len ||
4581
       os_memcmp(wpa_s->last_con_fail_realm, realm, realm_len) != 0)) {
4582
    algs = WPA_AUTH_ALG_FILS;
4583
    params->fils_erp_username = username;
4584
    params->fils_erp_username_len = username_len;
4585
    params->fils_erp_realm = realm;
4586
    params->fils_erp_realm_len = realm_len;
4587
    params->fils_erp_next_seq_num = next_seq_num;
4588
    params->fils_erp_rrk = rrk;
4589
    params->fils_erp_rrk_len = rrk_len;
4590
4591
    if (mask)
4592
      *mask |= WPA_DRV_UPDATE_FILS_ERP_INFO;
4593
  } else if ((wpa_s->drv_flags & WPA_DRIVER_FLAGS_FILS_SK_OFFLOAD) &&
4594
       ssid->eap.erp && wpa_key_mgmt_fils(wpa_s->key_mgmt) &&
4595
       pmksa_cached) {
4596
    algs = WPA_AUTH_ALG_FILS;
4597
  }
4598
#endif /* CONFIG_FILS */
4599
0
#endif /* IEEE8021X_EAPOL */
4600
#ifdef CONFIG_SAE
4601
  if (wpa_key_mgmt_sae(wpa_s->key_mgmt))
4602
    algs = WPA_AUTH_ALG_SAE;
4603
#endif /* CONFIG_SAE */
4604
4605
#ifdef CONFIG_IEEE8021X_AUTH
4606
  if (wpas_set_802_1x_auth_alg(wpa_s, bss, ssid, params))
4607
    algs = WPA_AUTH_ALG_802_1X;
4608
#endif /* CONFIG_IEEE8021X_AUTH */
4609
4610
#ifdef CONFIG_ENC_ASSOC
4611
  if (wpas_set_eppke_auth_alg(wpa_s, bss, ssid, params))
4612
    algs = WPA_AUTH_ALG_EPPKE;
4613
#endif /* CONFIG_ENC_ASSOC */
4614
4615
0
  wpa_dbg(wpa_s, MSG_DEBUG, "Automatic auth_alg selection: 0x%x", algs);
4616
0
  if (ssid->auth_alg) {
4617
0
    algs = ssid->auth_alg;
4618
0
    wpa_dbg(wpa_s, MSG_DEBUG,
4619
0
      "Overriding auth_alg selection: 0x%x", algs);
4620
0
  }
4621
4622
#ifdef CONFIG_SAE
4623
  if (pmksa_cached && algs == WPA_AUTH_ALG_SAE) {
4624
    wpa_dbg(wpa_s, MSG_DEBUG,
4625
      "SAE: Use WPA_AUTH_ALG_OPEN for PMKSA caching attempt");
4626
    algs = WPA_AUTH_ALG_OPEN;
4627
  }
4628
#endif /* CONFIG_SAE */
4629
4630
#ifdef CONFIG_P2P
4631
  if (wpa_s->global->p2p) {
4632
    u8 *pos;
4633
    size_t len;
4634
    int res;
4635
    pos = wpa_ie + wpa_ie_len;
4636
    len = max_wpa_ie_len - wpa_ie_len;
4637
    res = wpas_p2p_assoc_req_ie(wpa_s, bss, pos, len,
4638
              ssid->p2p_group);
4639
    if (res >= 0)
4640
      wpa_ie_len += res;
4641
  }
4642
4643
  wpa_s->cross_connect_disallowed = 0;
4644
  if (bss) {
4645
    struct wpabuf *p2p;
4646
    p2p = wpa_bss_get_vendor_ie_multi(bss, P2P_IE_VENDOR_TYPE);
4647
    if (p2p) {
4648
      wpa_s->cross_connect_disallowed =
4649
        p2p_get_cross_connect_disallowed(p2p);
4650
      wpabuf_free(p2p);
4651
      wpa_dbg(wpa_s, MSG_DEBUG, "P2P: WLAN AP %s cross "
4652
        "connection",
4653
        wpa_s->cross_connect_disallowed ?
4654
        "disallows" : "allows");
4655
    }
4656
  }
4657
4658
  os_memset(wpa_s->p2p_ip_addr_info, 0, sizeof(wpa_s->p2p_ip_addr_info));
4659
#endif /* CONFIG_P2P */
4660
4661
0
#ifndef CONFIG_NO_RRM
4662
0
  if (bss) {
4663
0
    wpa_ie_len += wpas_supp_op_class_ie(wpa_s, ssid, bss,
4664
0
                wpa_ie + wpa_ie_len,
4665
0
                max_wpa_ie_len -
4666
0
                wpa_ie_len);
4667
0
  }
4668
0
#endif /* CONFIG_NO_RRM */
4669
4670
  /*
4671
   * Workaround: Add Extended Capabilities element only if the AP
4672
   * included this element in Beacon/Probe Response frames. Some older
4673
   * APs seem to have interoperability issues if this element is
4674
   * included, so while the standard may require us to include the
4675
   * element in all cases, it is justifiable to skip it to avoid
4676
   * interoperability issues.
4677
   */
4678
0
  if (ssid->p2p_group)
4679
0
    wpa_drv_get_ext_capa(wpa_s, WPA_IF_P2P_CLIENT);
4680
0
  else
4681
0
    wpa_drv_get_ext_capa(wpa_s, WPA_IF_STATION);
4682
4683
0
  if (!bss || wpa_bss_get_ie(bss, WLAN_EID_EXT_CAPAB)) {
4684
0
    u8 ext_capab[18];
4685
0
    int ext_capab_len;
4686
0
    ext_capab_len = wpas_build_ext_capab(wpa_s, ext_capab,
4687
0
                 sizeof(ext_capab), bss);
4688
0
    if (ext_capab_len > 0 &&
4689
0
        wpa_ie_len + ext_capab_len <= max_wpa_ie_len) {
4690
0
      u8 *pos = wpa_ie;
4691
0
      if (wpa_ie_len > 0 && pos[0] == WLAN_EID_RSN)
4692
0
        pos += 2 + pos[1];
4693
0
      os_memmove(pos + ext_capab_len, pos,
4694
0
           wpa_ie_len - (pos - wpa_ie));
4695
0
      wpa_ie_len += ext_capab_len;
4696
0
      os_memcpy(pos, ext_capab, ext_capab_len);
4697
0
    }
4698
0
  }
4699
4700
0
  if (ssid->max_idle && wpa_ie_len + 5 <= max_wpa_ie_len) {
4701
0
    u8 *pos = wpa_ie;
4702
4703
0
    *pos++ = WLAN_EID_BSS_MAX_IDLE_PERIOD;
4704
0
    *pos++ = 3;
4705
0
    WPA_PUT_LE16(pos, ssid->max_idle);
4706
0
    pos += 2;
4707
0
    *pos = 0; /* Idle Options */
4708
0
    wpa_ie_len += 5;
4709
0
  }
4710
4711
0
#ifdef CONFIG_HS20
4712
0
  if (is_hs20_network(wpa_s, ssid, bss)) {
4713
0
    struct wpabuf *hs20;
4714
4715
0
    hs20 = wpabuf_alloc(20 + MAX_ROAMING_CONS_OI_LEN);
4716
0
    if (hs20) {
4717
0
      int pps_mo_id = hs20_get_pps_mo_id(wpa_s, ssid);
4718
0
      size_t len;
4719
4720
0
      wpas_hs20_add_indication(hs20, pps_mo_id,
4721
0
             get_hs20_version(bss));
4722
0
      wpas_hs20_add_roam_cons_sel(hs20, ssid);
4723
0
      len = max_wpa_ie_len - wpa_ie_len;
4724
0
      if (wpabuf_len(hs20) <= len) {
4725
0
        os_memcpy(wpa_ie + wpa_ie_len,
4726
0
            wpabuf_head(hs20), wpabuf_len(hs20));
4727
0
        wpa_ie_len += wpabuf_len(hs20);
4728
0
      }
4729
0
      wpabuf_free(hs20);
4730
0
    }
4731
0
  }
4732
0
#endif /* CONFIG_HS20 */
4733
4734
0
  wpas_configure_frame_filters(wpa_s);
4735
4736
0
  if (wpa_s->vendor_elem[VENDOR_ELEM_ASSOC_REQ]) {
4737
0
    struct wpabuf *buf = wpa_s->vendor_elem[VENDOR_ELEM_ASSOC_REQ];
4738
0
    size_t len;
4739
4740
0
    len = max_wpa_ie_len - wpa_ie_len;
4741
0
    if (wpabuf_len(buf) <= len) {
4742
0
      os_memcpy(wpa_ie + wpa_ie_len,
4743
0
          wpabuf_head(buf), wpabuf_len(buf));
4744
0
      wpa_ie_len += wpabuf_len(buf);
4745
0
    }
4746
0
  }
4747
4748
#ifdef CONFIG_FST
4749
  if (wpa_s->fst_ies) {
4750
    int fst_ies_len = wpabuf_len(wpa_s->fst_ies);
4751
4752
    if (wpa_ie_len + fst_ies_len <= max_wpa_ie_len) {
4753
      os_memcpy(wpa_ie + wpa_ie_len,
4754
          wpabuf_head(wpa_s->fst_ies), fst_ies_len);
4755
      wpa_ie_len += fst_ies_len;
4756
    }
4757
  }
4758
#endif /* CONFIG_FST */
4759
4760
#ifdef CONFIG_MBO
4761
0
  mbo_ie = bss ? wpa_bss_get_vendor_ie(bss, MBO_IE_VENDOR_TYPE) : NULL;
4762
0
  if (!wpa_s->disable_mbo_oce && mbo_ie) {
4763
0
    int len;
4764
4765
0
    len = wpas_mbo_ie(wpa_s, wpa_ie + wpa_ie_len,
4766
0
          max_wpa_ie_len - wpa_ie_len,
4767
0
          !!mbo_attr_from_mbo_ie(mbo_ie,
4768
0
               OCE_ATTR_ID_CAPA_IND));
4769
0
    if (len >= 0)
4770
0
      wpa_ie_len += len;
4771
0
  }
4772
#endif /* CONFIG_MBO */
4773
4774
#ifdef CONFIG_FILS
4775
  if (algs == WPA_AUTH_ALG_FILS) {
4776
    size_t len;
4777
4778
    len = wpas_add_fils_hlp_req(wpa_s, wpa_ie + wpa_ie_len,
4779
              max_wpa_ie_len - wpa_ie_len);
4780
    wpa_ie_len += len;
4781
  }
4782
#endif /* CONFIG_FILS */
4783
4784
#ifdef CONFIG_OWE
4785
#ifdef CONFIG_TESTING_OPTIONS
4786
  if (get_ie_ext(wpa_ie, wpa_ie_len, WLAN_EID_EXT_OWE_DH_PARAM)) {
4787
    wpa_printf(MSG_INFO, "TESTING: Override OWE DH element");
4788
  } else
4789
#endif /* CONFIG_TESTING_OPTIONS */
4790
  if (algs == WPA_AUTH_ALG_OPEN &&
4791
      ssid->key_mgmt == WPA_KEY_MGMT_OWE &&
4792
      !(wpa_s->drv_flags2 & WPA_DRIVER_FLAGS2_OWE_OFFLOAD_STA)) {
4793
    struct wpabuf *owe_ie;
4794
    u16 group;
4795
4796
    if (ssid->owe_group) {
4797
      group = ssid->owe_group;
4798
    } else if (wpa_s->assoc_status_code ==
4799
         WLAN_STATUS_FINITE_CYCLIC_GROUP_NOT_SUPPORTED) {
4800
      if (wpa_s->last_owe_group == 19)
4801
        group = 20;
4802
      else if (wpa_s->last_owe_group == 20)
4803
        group = 21;
4804
      else
4805
        group = OWE_DH_GROUP;
4806
    } else {
4807
      group = OWE_DH_GROUP;
4808
    }
4809
4810
    wpa_s->last_owe_group = group;
4811
    wpa_printf(MSG_DEBUG, "OWE: Try to use group %u", group);
4812
    owe_ie = owe_build_assoc_req(wpa_s->wpa, group);
4813
    if (owe_ie &&
4814
        wpabuf_len(owe_ie) <= max_wpa_ie_len - wpa_ie_len) {
4815
      os_memcpy(wpa_ie + wpa_ie_len,
4816
          wpabuf_head(owe_ie), wpabuf_len(owe_ie));
4817
      wpa_ie_len += wpabuf_len(owe_ie);
4818
    }
4819
    wpabuf_free(owe_ie);
4820
  }
4821
#endif /* CONFIG_OWE */
4822
4823
#ifdef CONFIG_DPP2
4824
  if (DPP_VERSION > 1 &&
4825
      wpa_sm_get_key_mgmt(wpa_s->wpa) == WPA_KEY_MGMT_DPP &&
4826
      ssid->dpp_netaccesskey &&
4827
      ssid->dpp_pfs != 2 && !ssid->dpp_pfs_fallback) {
4828
    struct rsn_pmksa_cache_entry *pmksa;
4829
4830
    pmksa = pmksa_cache_get_current(wpa_s->wpa);
4831
    if (!pmksa || !pmksa->dpp_pfs)
4832
      goto pfs_fail;
4833
4834
    dpp_pfs_free(wpa_s->dpp_pfs);
4835
    wpa_s->dpp_pfs = dpp_pfs_init(ssid->dpp_netaccesskey,
4836
                ssid->dpp_netaccesskey_len);
4837
    if (!wpa_s->dpp_pfs) {
4838
      wpa_printf(MSG_DEBUG, "DPP: Could not initialize PFS");
4839
      /* Try to continue without PFS */
4840
      goto pfs_fail;
4841
    }
4842
    if (wpabuf_len(wpa_s->dpp_pfs->ie) <=
4843
        max_wpa_ie_len - wpa_ie_len) {
4844
      os_memcpy(wpa_ie + wpa_ie_len,
4845
          wpabuf_head(wpa_s->dpp_pfs->ie),
4846
          wpabuf_len(wpa_s->dpp_pfs->ie));
4847
      wpa_ie_len += wpabuf_len(wpa_s->dpp_pfs->ie);
4848
    }
4849
  }
4850
pfs_fail:
4851
#endif /* CONFIG_DPP2 */
4852
4853
#ifdef CONFIG_IEEE80211R
4854
  /*
4855
   * Add MDIE under these conditions: the network profile allows FT,
4856
   * the AP supports FT, and the mobility domain ID matches.
4857
   */
4858
  if (bss && wpa_key_mgmt_ft(wpa_sm_get_key_mgmt(wpa_s->wpa))) {
4859
    const u8 *mdie = wpa_bss_get_ie(bss, WLAN_EID_MOBILITY_DOMAIN);
4860
4861
    if (mdie && mdie[1] >= MOBILITY_DOMAIN_ID_LEN) {
4862
      size_t len = 0;
4863
      const u8 *md = mdie + 2;
4864
      const u8 *wpa_md = wpa_sm_get_ft_md(wpa_s->wpa);
4865
4866
      if (os_memcmp(md, wpa_md,
4867
              MOBILITY_DOMAIN_ID_LEN) == 0) {
4868
        /* Add mobility domain IE */
4869
        len = wpa_ft_add_mdie(
4870
          wpa_s->wpa, wpa_ie + wpa_ie_len,
4871
          max_wpa_ie_len - wpa_ie_len, mdie);
4872
        wpa_ie_len += len;
4873
      }
4874
#ifdef CONFIG_SME
4875
      if (len > 0 && wpa_s->sme.ft_used &&
4876
          wpa_sm_has_ft_keys(wpa_s->wpa, md)) {
4877
        wpa_dbg(wpa_s, MSG_DEBUG,
4878
          "SME: Trying to use FT over-the-air");
4879
        algs |= WPA_AUTH_ALG_FT;
4880
      }
4881
#endif /* CONFIG_SME */
4882
    }
4883
  }
4884
#endif /* CONFIG_IEEE80211R */
4885
4886
#ifdef CONFIG_TESTING_OPTIONS
4887
  if (wpa_s->rsnxe_override_assoc &&
4888
      wpabuf_len(wpa_s->rsnxe_override_assoc) <=
4889
      max_wpa_ie_len - wpa_ie_len) {
4890
    wpa_printf(MSG_DEBUG, "TESTING: RSNXE AssocReq override");
4891
    os_memcpy(wpa_ie + wpa_ie_len,
4892
        wpabuf_head(wpa_s->rsnxe_override_assoc),
4893
        wpabuf_len(wpa_s->rsnxe_override_assoc));
4894
    wpa_ie_len += wpabuf_len(wpa_s->rsnxe_override_assoc);
4895
  } else
4896
#endif /* CONFIG_TESTING_OPTIONS */
4897
0
  if (wpa_s->rsnxe_len > 0 &&
4898
0
      wpa_s->rsnxe_len <= max_wpa_ie_len - wpa_ie_len) {
4899
0
    os_memcpy(wpa_ie + wpa_ie_len, wpa_s->rsnxe, wpa_s->rsnxe_len);
4900
0
    wpa_ie_len += wpa_s->rsnxe_len;
4901
0
  }
4902
4903
  /* Security Profile element - driver-SME path */
4904
#ifdef CONFIG_TESTING_OPTIONS
4905
  if (wpa_s->sec_prof_override_assoc &&
4906
      wpabuf_len(wpa_s->sec_prof_override_assoc) <=
4907
      max_wpa_ie_len - wpa_ie_len) {
4908
    wpa_printf(MSG_DEBUG,
4909
         "TESTING: Security Profile element AssocReq override");
4910
    os_memcpy(wpa_ie + wpa_ie_len,
4911
        wpabuf_head(wpa_s->sec_prof_override_assoc),
4912
        wpabuf_len(wpa_s->sec_prof_override_assoc));
4913
    wpa_ie_len += wpabuf_len(wpa_s->sec_prof_override_assoc);
4914
  } else
4915
#endif /* CONFIG_TESTING_OPTIONS */
4916
0
  if (wpa_s->security_profile_len > 0 &&
4917
0
      wpas_security_profile_active(wpa_s) &&
4918
0
      wpa_s->security_profile_len <= max_wpa_ie_len - wpa_ie_len) {
4919
0
    os_memcpy(wpa_ie + wpa_ie_len,
4920
0
        wpa_s->security_profile,
4921
0
        wpa_s->security_profile_len);
4922
0
    wpa_ie_len += wpa_s->security_profile_len;
4923
0
    wpa_dbg(wpa_s, MSG_DEBUG,
4924
0
      "Security Profile element appended to connect elements (profile=%d)",
4925
0
      wpa_s->sel_security_profile);
4926
0
  } else if (wpa_s->security_profile_len > 0 &&
4927
0
       !wpas_security_profile_active(wpa_s)) {
4928
0
    wpa_dbg(wpa_s, MSG_DEBUG,
4929
0
      "Security Profile: driver does not support element - omitting from connect elements");
4930
0
  }
4931
4932
0
#ifndef CONFIG_NO_ROBUST_AV
4933
#ifdef CONFIG_TESTING_OPTIONS
4934
  if (wpa_s->disable_mscs_support)
4935
    goto mscs_end;
4936
#endif /* CONFIG_TESTING_OPTIONS */
4937
0
  if (wpa_bss_ext_capab(bss, WLAN_EXT_CAPAB_MSCS) &&
4938
0
      wpa_s->robust_av.valid_config) {
4939
0
    struct wpabuf *mscs_ie;
4940
0
    size_t mscs_ie_len, buf_len;
4941
4942
0
    buf_len = 3 + /* MSCS descriptor IE header */
4943
0
        1 + /* Request type */
4944
0
        2 + /* User priority control */
4945
0
        4 + /* Stream timeout */
4946
0
        3 + /* TCLAS Mask IE header */
4947
0
        wpa_s->robust_av.frame_classifier_len;
4948
0
    mscs_ie = wpabuf_alloc(buf_len);
4949
0
    if (!mscs_ie) {
4950
0
      wpa_printf(MSG_INFO,
4951
0
           "MSCS: Failed to allocate MSCS IE");
4952
0
      goto mscs_end;
4953
0
    }
4954
4955
0
    wpas_populate_mscs_descriptor_ie(&wpa_s->robust_av, mscs_ie);
4956
0
    if ((wpa_ie_len + wpabuf_len(mscs_ie)) <= max_wpa_ie_len) {
4957
0
      wpa_hexdump_buf(MSG_MSGDUMP, "MSCS IE", mscs_ie);
4958
0
      mscs_ie_len = wpabuf_len(mscs_ie);
4959
0
      os_memcpy(wpa_ie + wpa_ie_len, wpabuf_head(mscs_ie),
4960
0
          mscs_ie_len);
4961
0
      wpa_ie_len += mscs_ie_len;
4962
0
    }
4963
4964
0
    wpabuf_free(mscs_ie);
4965
0
  }
4966
0
mscs_end:
4967
0
#endif /* CONFIG_NO_ROBUST_AV */
4968
4969
0
  wpa_ie_len = wpas_populate_wfa_capa(wpa_s, bss, wpa_ie, wpa_ie_len,
4970
0
              max_wpa_ie_len);
4971
4972
0
  if (ssid->multi_ap_backhaul_sta) {
4973
0
    size_t multi_ap_ie_len;
4974
0
    struct multi_ap_params multi_ap = { 0 };
4975
4976
0
    multi_ap.capability = MULTI_AP_BACKHAUL_STA;
4977
0
    multi_ap.profile = ssid->multi_ap_profile;
4978
4979
0
    multi_ap_ie_len = add_multi_ap_ie(wpa_ie + wpa_ie_len,
4980
0
              max_wpa_ie_len - wpa_ie_len,
4981
0
              &multi_ap);
4982
0
    if (multi_ap_ie_len == 0) {
4983
0
      wpa_printf(MSG_ERROR,
4984
0
           "Multi-AP: Failed to build Multi-AP IE");
4985
0
      os_free(wpa_ie);
4986
0
      return NULL;
4987
0
    }
4988
0
    wpa_ie_len += multi_ap_ie_len;
4989
0
  }
4990
4991
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_RSN_OVERRIDE_SUPPORT,
4992
0
       wpas_rsn_overriding(wpa_s, ssid));
4993
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_RSN_OVERRIDE,
4994
0
       RSN_OVERRIDE_NOT_USED);
4995
0
  if (wpas_rsn_overriding(wpa_s, ssid) &&
4996
0
      wpas_ap_supports_rsn_overriding(wpa_s, bss) &&
4997
0
      wpa_ie_len + 2 + 4 + 1 <= max_wpa_ie_len) {
4998
0
    u8 *pos = wpa_ie + wpa_ie_len, *start = pos;
4999
0
    const u8 *ie;
5000
0
    enum rsn_selection_variant variant = RSN_SELECTION_RSNE;
5001
5002
0
    wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_RSN_OVERRIDE,
5003
0
         RSN_OVERRIDE_RSNE);
5004
0
    ie = wpa_bss_get_rsne(wpa_s, bss, ssid, wpa_s->valid_links);
5005
0
    if (ie && ie[0] == WLAN_EID_VENDOR_SPECIFIC && ie[1] >= 4) {
5006
0
      u32 type;
5007
5008
0
      type = WPA_GET_BE32(&ie[2]);
5009
0
      if (type == RSNE_OVERRIDE_IE_VENDOR_TYPE) {
5010
0
        variant = RSN_SELECTION_RSNE_OVERRIDE;
5011
0
        wpa_sm_set_param(wpa_s->wpa,
5012
0
             WPA_PARAM_RSN_OVERRIDE,
5013
0
             RSN_OVERRIDE_RSNE_OVERRIDE);
5014
0
      } else if (type == RSNE_OVERRIDE_2_IE_VENDOR_TYPE) {
5015
0
        variant = RSN_SELECTION_RSNE_OVERRIDE_2;
5016
0
        wpa_sm_set_param(wpa_s->wpa,
5017
0
             WPA_PARAM_RSN_OVERRIDE,
5018
0
             RSN_OVERRIDE_RSNE_OVERRIDE_2);
5019
0
      }
5020
0
    }
5021
5022
    /* Indicate which RSNE variant was used */
5023
0
    *pos++ = WLAN_EID_VENDOR_SPECIFIC;
5024
0
    *pos++ = 4 + 1;
5025
0
    WPA_PUT_BE32(pos, RSN_SELECTION_IE_VENDOR_TYPE);
5026
0
    pos += 4;
5027
0
    *pos++ = variant;
5028
0
    wpa_hexdump(MSG_MSGDUMP, "RSN Selection", start, pos - start);
5029
0
    wpa_ie_len += pos - start;
5030
0
  }
5031
5032
0
  params->rsn_overriding = wpas_rsn_overriding(wpa_s, ssid);
5033
0
  params->wpa_ie = wpa_ie;
5034
0
  params->wpa_ie_len = wpa_ie_len;
5035
0
  params->auth_alg = algs;
5036
0
  if (mask)
5037
0
    *mask |= WPA_DRV_UPDATE_ASSOC_IES | WPA_DRV_UPDATE_AUTH_TYPE;
5038
5039
0
  return wpa_ie;
5040
0
}
Unexecuted instantiation: wpa_supplicant.c:wpas_populate_assoc_ies
Unexecuted instantiation: wpa_supplicant.c:wpas_populate_assoc_ies
5041
5042
5043
#ifdef CONFIG_OWE
5044
static void wpas_update_owe_connect_params(struct wpa_supplicant *wpa_s)
5045
{
5046
  struct wpa_driver_associate_params params;
5047
  u8 *wpa_ie;
5048
5049
  os_memset(&params, 0, sizeof(params));
5050
  wpa_ie = wpas_populate_assoc_ies(wpa_s, wpa_s->current_bss,
5051
           wpa_s->current_ssid, &params, NULL);
5052
  if (!wpa_ie)
5053
    return;
5054
5055
  wpa_drv_update_connect_params(wpa_s, &params, WPA_DRV_UPDATE_ASSOC_IES);
5056
  os_free(wpa_ie);
5057
}
5058
#endif /* CONFIG_OWE */
5059
5060
5061
#if defined(CONFIG_FILS) && defined(IEEE8021X_EAPOL)
5062
static void wpas_update_fils_connect_params(struct wpa_supplicant *wpa_s)
5063
{
5064
  struct wpa_driver_associate_params params;
5065
  enum wpa_drv_update_connect_params_mask mask = 0;
5066
  u8 *wpa_ie;
5067
5068
  if (wpa_s->auth_alg != WPA_AUTH_ALG_OPEN)
5069
    return; /* nothing to do */
5070
5071
  os_memset(&params, 0, sizeof(params));
5072
  wpa_ie = wpas_populate_assoc_ies(wpa_s, wpa_s->current_bss,
5073
           wpa_s->current_ssid, &params, &mask);
5074
  if (!wpa_ie)
5075
    return;
5076
5077
  if (params.auth_alg == WPA_AUTH_ALG_FILS) {
5078
    wpa_s->auth_alg = params.auth_alg;
5079
    wpa_drv_update_connect_params(wpa_s, &params, mask);
5080
  }
5081
5082
  os_free(wpa_ie);
5083
}
5084
#endif /* CONFIG_FILS && IEEE8021X_EAPOL */
5085
5086
5087
static u8 wpa_ie_get_edmg_oper_chans(const u8 *edmg_ie)
5088
0
{
5089
0
  if (!edmg_ie || edmg_ie[1] < 6)
5090
0
    return 0;
5091
0
  return edmg_ie[EDMG_BSS_OPERATING_CHANNELS_OFFSET];
5092
0
}
5093
5094
5095
static u8 wpa_ie_get_edmg_oper_chan_width(const u8 *edmg_ie)
5096
0
{
5097
0
  if (!edmg_ie || edmg_ie[1] < 6)
5098
0
    return 0;
5099
0
  return edmg_ie[EDMG_OPERATING_CHANNEL_WIDTH_OFFSET];
5100
0
}
5101
5102
5103
/* Returns the intersection of two EDMG configurations.
5104
 * Note: The current implementation is limited to CB2 only (CB1 included),
5105
 * i.e., the implementation supports up to 2 contiguous channels.
5106
 * For supporting non-contiguous (aggregated) channels and for supporting
5107
 * CB3 and above, this function will need to be extended.
5108
 */
5109
static struct ieee80211_edmg_config
5110
get_edmg_intersection(struct ieee80211_edmg_config a,
5111
          struct ieee80211_edmg_config b,
5112
          u8 primary_channel)
5113
0
{
5114
0
  struct ieee80211_edmg_config result;
5115
0
  int i, contiguous = 0;
5116
0
  int max_contiguous = 0;
5117
5118
0
  result.channels = b.channels & a.channels;
5119
0
  if (!result.channels) {
5120
0
    wpa_printf(MSG_DEBUG,
5121
0
         "EDMG not possible: cannot intersect channels 0x%x and 0x%x",
5122
0
         a.channels, b.channels);
5123
0
    goto fail;
5124
0
  }
5125
5126
0
  if (!(result.channels & BIT(primary_channel - 1))) {
5127
0
    wpa_printf(MSG_DEBUG,
5128
0
         "EDMG not possible: the primary channel %d is not one of the intersected channels 0x%x",
5129
0
         primary_channel, result.channels);
5130
0
    goto fail;
5131
0
  }
5132
5133
  /* Find max contiguous channels */
5134
0
  for (i = 0; i < 6; i++) {
5135
0
    if (result.channels & BIT(i))
5136
0
      contiguous++;
5137
0
    else
5138
0
      contiguous = 0;
5139
5140
0
    if (contiguous > max_contiguous)
5141
0
      max_contiguous = contiguous;
5142
0
  }
5143
5144
  /* Assuming AP and STA supports ONLY contiguous channels,
5145
   * bw configuration can have value between 4-7.
5146
   */
5147
0
  if ((b.bw_config < a.bw_config))
5148
0
    result.bw_config = b.bw_config;
5149
0
  else
5150
0
    result.bw_config = a.bw_config;
5151
5152
0
  if ((max_contiguous >= 2 && result.bw_config < EDMG_BW_CONFIG_5) ||
5153
0
      (max_contiguous >= 1 && result.bw_config < EDMG_BW_CONFIG_4)) {
5154
0
    wpa_printf(MSG_DEBUG,
5155
0
         "EDMG not possible: not enough contiguous channels %d for supporting CB1 or CB2",
5156
0
         max_contiguous);
5157
0
    goto fail;
5158
0
  }
5159
5160
0
  return result;
5161
5162
0
fail:
5163
0
  result.channels = 0;
5164
0
  result.bw_config = 0;
5165
0
  return result;
5166
0
}
5167
5168
5169
static struct ieee80211_edmg_config
5170
get_supported_edmg(struct wpa_supplicant *wpa_s,
5171
       struct hostapd_freq_params *freq,
5172
       struct ieee80211_edmg_config request_edmg)
5173
0
{
5174
0
  enum hostapd_hw_mode hw_mode;
5175
0
  struct hostapd_hw_modes *mode = NULL;
5176
0
  u8 primary_channel;
5177
5178
0
  if (!wpa_s->hw.modes)
5179
0
    goto fail;
5180
5181
0
  hw_mode = ieee80211_freq_to_chan(freq->freq, &primary_channel);
5182
0
  if (hw_mode == NUM_HOSTAPD_MODES)
5183
0
    goto fail;
5184
5185
0
  mode = get_mode(wpa_s->hw.modes, wpa_s->hw.num_modes, hw_mode, false);
5186
0
  if (!mode)
5187
0
    goto fail;
5188
5189
0
  return get_edmg_intersection(mode->edmg, request_edmg, primary_channel);
5190
5191
0
fail:
5192
0
  request_edmg.channels = 0;
5193
0
  request_edmg.bw_config = 0;
5194
0
  return request_edmg;
5195
0
}
5196
5197
5198
#ifdef CONFIG_MBO
5199
void wpas_update_mbo_connect_params(struct wpa_supplicant *wpa_s)
5200
0
{
5201
0
  struct wpa_driver_associate_params params;
5202
0
  u8 *wpa_ie;
5203
5204
  /*
5205
   * Update MBO connect params only in case of change of MBO attributes
5206
   * when connected, if the AP support MBO.
5207
   */
5208
5209
0
  if (wpa_s->wpa_state != WPA_COMPLETED || !wpa_s->current_ssid ||
5210
0
      !wpa_s->current_bss ||
5211
0
      !wpa_bss_get_vendor_ie(wpa_s->current_bss, MBO_IE_VENDOR_TYPE))
5212
0
    return;
5213
5214
0
  os_memset(&params, 0, sizeof(params));
5215
0
  wpa_ie = wpas_populate_assoc_ies(wpa_s, wpa_s->current_bss,
5216
0
           wpa_s->current_ssid, &params, NULL);
5217
0
  if (!wpa_ie)
5218
0
    return;
5219
5220
0
  wpa_drv_update_connect_params(wpa_s, &params, WPA_DRV_UPDATE_ASSOC_IES);
5221
0
  os_free(wpa_ie);
5222
0
}
5223
#endif /* CONFIG_MBO */
5224
5225
5226
static void wpas_start_assoc_cb(struct wpa_radio_work *work, int deinit)
5227
0
{
5228
0
  struct wpa_connect_work *cwork = work->ctx;
5229
0
  struct wpa_bss *bss = cwork->bss;
5230
0
  struct wpa_ssid *ssid = cwork->ssid;
5231
0
  struct wpa_supplicant *wpa_s = work->wpa_s;
5232
0
  u8 *wpa_ie;
5233
0
  const u8 *edmg_ie_oper;
5234
0
  int use_crypt, ret, bssid_changed;
5235
0
  unsigned int cipher_pairwise, cipher_group, cipher_group_mgmt;
5236
0
  struct wpa_driver_associate_params params;
5237
0
  u8 psk[PMK_LEN];
5238
0
#if defined(CONFIG_WEP) || defined(IEEE8021X_EAPOL)
5239
0
  int wep_keys_set = 0;
5240
0
#endif /* CONFIG_WEP || IEEE8021X_EAPOL */
5241
0
  int assoc_failed = 0;
5242
0
  struct wpa_ssid *old_ssid;
5243
0
  u8 prev_bssid[ETH_ALEN];
5244
#ifdef CONFIG_HT_OVERRIDES
5245
  struct ieee80211_ht_capabilities htcaps;
5246
  struct ieee80211_ht_capabilities htcaps_mask;
5247
#endif /* CONFIG_HT_OVERRIDES */
5248
#ifdef CONFIG_VHT_OVERRIDES
5249
       struct ieee80211_vht_capabilities vhtcaps;
5250
       struct ieee80211_vht_capabilities vhtcaps_mask;
5251
#endif /* CONFIG_VHT_OVERRIDES */
5252
5253
0
  wpa_s->roam_in_progress = false;
5254
0
#ifdef CONFIG_WNM
5255
0
  wpa_s->bss_trans_mgmt_in_progress = false;
5256
0
#endif /* CONFIG_WNM */
5257
0
  wpa_s->no_suitable_network = 0;
5258
5259
0
  if (deinit) {
5260
0
    if (work->started) {
5261
0
      wpa_s->connect_work = NULL;
5262
5263
      /* cancel possible auth. timeout */
5264
0
      eloop_cancel_timeout(wpa_supplicant_timeout, wpa_s,
5265
0
               NULL);
5266
0
    }
5267
0
    wpas_connect_work_free(cwork);
5268
0
    return;
5269
0
  }
5270
5271
0
  wpa_s->connect_work = work;
5272
5273
0
  if (cwork->bss_removed || !wpas_valid_bss_ssid(wpa_s, bss, ssid) ||
5274
0
      wpas_network_disabled(wpa_s, ssid)) {
5275
0
    wpa_dbg(wpa_s, MSG_DEBUG, "BSS/SSID entry for association not valid anymore - drop connection attempt");
5276
0
    wpas_connect_work_done(wpa_s);
5277
0
    return;
5278
0
  }
5279
5280
  /*
5281
   * Set the current AP's BSSID (for non-MLO connection) or MLD address
5282
   * (for MLO connection) as the previous BSSID for reassociation requests
5283
   * handled by SME-in-driver. If wpa_supplicant is in disconnected state,
5284
   * prev_bssid will be zero as both wpa_s->valid_links and wpa_s->bssid
5285
   * will be zero.
5286
   */
5287
0
  os_memcpy(prev_bssid,
5288
0
      wpa_s->valid_links ? wpa_s->ap_mld_addr : wpa_s->bssid,
5289
0
      ETH_ALEN);
5290
0
  os_memset(&params, 0, sizeof(params));
5291
0
  wpa_s->reassociate = 0;
5292
0
  wpa_s->eap_expected_failure = 0;
5293
5294
  /* Starting new association, so clear the possibly used WPA IE from the
5295
   * previous association. */
5296
0
  wpa_sm_set_assoc_wpa_ie(wpa_s->wpa, NULL, 0);
5297
0
#ifndef CONFIG_NO_WPA
5298
0
  wpa_sm_set_assoc_rsnxe(wpa_s->wpa, NULL, 0);
5299
0
#endif /* CONFIG_NO_WPA */
5300
0
  wpa_s->rsnxe_len = 0;
5301
0
  wpa_s->sel_security_profile = -1;
5302
0
  wpa_s->security_profile_len = 0;
5303
0
#ifndef CONFIG_NO_ROBUST_AV
5304
0
  wpa_s->mscs_setup_done = false;
5305
0
#endif /* CONFIG_NO_ROBUST_AV */
5306
5307
0
  wpa_ie = wpas_populate_assoc_ies(wpa_s, bss, ssid, &params, NULL);
5308
0
  if (!wpa_ie) {
5309
0
    wpas_connect_work_done(wpa_s);
5310
0
    return;
5311
0
  }
5312
5313
0
  if (bss &&
5314
0
      (!wpas_driver_bss_selection(wpa_s) || wpas_wps_searching(wpa_s))) {
5315
#ifdef CONFIG_IEEE80211R
5316
    const u8 *ie, *md = NULL;
5317
#endif /* CONFIG_IEEE80211R */
5318
0
    wpa_msg(wpa_s, MSG_INFO, "Trying to associate with " MACSTR
5319
0
      " (SSID='%s' freq=%d MHz)", MAC2STR(bss->bssid),
5320
0
      wpa_ssid_txt(bss->ssid, bss->ssid_len), bss->freq);
5321
0
    bssid_changed = !is_zero_ether_addr(wpa_s->bssid);
5322
0
    os_memset(wpa_s->bssid, 0, ETH_ALEN);
5323
0
    os_memcpy(wpa_s->pending_bssid, bss->bssid, ETH_ALEN);
5324
0
    if (bssid_changed)
5325
0
      wpas_notify_bssid_changed(wpa_s);
5326
#ifdef CONFIG_IEEE80211R
5327
    ie = wpa_bss_get_ie(bss, WLAN_EID_MOBILITY_DOMAIN);
5328
    if (ie && ie[1] >= MOBILITY_DOMAIN_ID_LEN)
5329
      md = ie + 2;
5330
    wpa_sm_set_ft_params(wpa_s->wpa, ie, ie ? 2 + ie[1] : 0);
5331
    if (md) {
5332
      /* Prepare for the next transition */
5333
      wpa_ft_prepare_auth_request(wpa_s->wpa, ie);
5334
    }
5335
#endif /* CONFIG_IEEE80211R */
5336
#ifdef CONFIG_WPS
5337
0
  } else if ((ssid->ssid == NULL || ssid->ssid_len == 0) &&
5338
0
       wpa_s->conf->ap_scan == 2 &&
5339
0
       (ssid->key_mgmt & WPA_KEY_MGMT_WPS)) {
5340
    /* Use ap_scan==1 style network selection to find the network
5341
     */
5342
0
    wpas_connect_work_done(wpa_s);
5343
0
    wpa_s->scan_req = MANUAL_SCAN_REQ;
5344
0
    wpa_s->reassociate = 1;
5345
0
    wpa_supplicant_req_scan(wpa_s, 0, 0);
5346
0
    os_free(wpa_ie);
5347
    return;
5348
#endif /* CONFIG_WPS */
5349
0
  } else {
5350
0
    wpa_msg(wpa_s, MSG_INFO, "Trying to associate with SSID '%s'",
5351
0
      wpa_ssid_txt(ssid->ssid, ssid->ssid_len));
5352
0
    if (bss)
5353
0
      os_memcpy(wpa_s->pending_bssid, bss->bssid, ETH_ALEN);
5354
0
    else
5355
0
      os_memset(wpa_s->pending_bssid, 0, ETH_ALEN);
5356
0
  }
5357
0
  if (!wpa_s->pno)
5358
0
    wpa_supplicant_cancel_sched_scan(wpa_s);
5359
5360
0
  wpa_supplicant_cancel_scan(wpa_s);
5361
5362
0
  wpa_clear_keys(wpa_s, bss ? bss->bssid : NULL);
5363
0
  use_crypt = 1;
5364
0
  cipher_pairwise = wpa_s->pairwise_cipher;
5365
0
  cipher_group = wpa_s->group_cipher;
5366
0
  cipher_group_mgmt = wpa_s->mgmt_group_cipher;
5367
0
  if (wpa_s->key_mgmt == WPA_KEY_MGMT_NONE ||
5368
0
      wpa_s->key_mgmt == WPA_KEY_MGMT_IEEE8021X_NO_WPA) {
5369
0
    if (wpa_s->key_mgmt == WPA_KEY_MGMT_NONE)
5370
0
      use_crypt = 0;
5371
#ifdef CONFIG_WEP
5372
    if (wpa_set_wep_keys(wpa_s, ssid)) {
5373
      use_crypt = 1;
5374
      wep_keys_set = 1;
5375
    }
5376
#endif /* CONFIG_WEP */
5377
0
  }
5378
0
  if (wpa_s->key_mgmt == WPA_KEY_MGMT_WPS)
5379
0
    use_crypt = 0;
5380
5381
0
#ifdef IEEE8021X_EAPOL
5382
0
  if (wpa_s->key_mgmt == WPA_KEY_MGMT_IEEE8021X_NO_WPA) {
5383
0
    if ((ssid->eapol_flags &
5384
0
         (EAPOL_FLAG_REQUIRE_KEY_UNICAST |
5385
0
          EAPOL_FLAG_REQUIRE_KEY_BROADCAST)) == 0 &&
5386
0
        !wep_keys_set) {
5387
0
      use_crypt = 0;
5388
0
    } else {
5389
      /* Assume that dynamic WEP-104 keys will be used and
5390
       * set cipher suites in order for drivers to expect
5391
       * encryption. */
5392
0
      cipher_pairwise = cipher_group = WPA_CIPHER_WEP104;
5393
0
    }
5394
0
  }
5395
0
#endif /* IEEE8021X_EAPOL */
5396
5397
0
  if (wpa_s->key_mgmt == WPA_KEY_MGMT_WPA_NONE) {
5398
    /* Set the key before (and later after) association */
5399
0
    wpa_supplicant_set_wpa_none_key(wpa_s, ssid);
5400
0
  }
5401
5402
  /* Set current_ssid before changing state to ASSOCIATING, so that the
5403
   * selected SSID is available to wpas_notify_state_changed(). */
5404
0
  old_ssid = wpa_s->current_ssid;
5405
0
  wpa_s->current_ssid = ssid;
5406
5407
0
  wpa_supplicant_set_state(wpa_s, WPA_ASSOCIATING);
5408
0
  if (bss) {
5409
0
    params.ssid = bss->ssid;
5410
0
    params.ssid_len = bss->ssid_len;
5411
0
    if (!wpas_driver_bss_selection(wpa_s) || ssid->bssid_set ||
5412
0
        wpa_s->key_mgmt == WPA_KEY_MGMT_WPS) {
5413
0
      wpa_printf(MSG_DEBUG, "Limit connection to BSSID "
5414
0
           MACSTR " freq=%u MHz based on scan results "
5415
0
           "(bssid_set=%d wps=%d)",
5416
0
           MAC2STR(bss->bssid), bss->freq,
5417
0
           ssid->bssid_set,
5418
0
           wpa_s->key_mgmt == WPA_KEY_MGMT_WPS);
5419
0
      params.bssid = bss->bssid;
5420
0
      params.freq.freq = bss->freq;
5421
0
    }
5422
0
    params.bssid_hint = bss->bssid;
5423
0
    params.freq_hint = bss->freq;
5424
0
    params.pbss = bss_is_pbss(bss);
5425
0
  } else {
5426
0
    if (ssid->bssid_hint_set)
5427
0
      params.bssid_hint = ssid->bssid_hint;
5428
5429
0
    params.ssid = ssid->ssid;
5430
0
    params.ssid_len = ssid->ssid_len;
5431
0
    params.pbss = (ssid->pbss != 2) ? ssid->pbss : 0;
5432
0
  }
5433
5434
0
  params.bssid_filter = wpa_s->bssid_filter;
5435
0
  params.bssid_filter_count = wpa_s->bssid_filter_count;
5436
5437
0
  if (ssid->mode == WPAS_MODE_IBSS && ssid->bssid_set &&
5438
0
      wpa_s->conf->ap_scan == 2) {
5439
0
    params.bssid = ssid->bssid;
5440
0
    params.fixed_bssid = 1;
5441
0
  }
5442
5443
  /* Initial frequency for IBSS/mesh */
5444
0
  if ((ssid->mode == WPAS_MODE_IBSS || ssid->mode == WPAS_MODE_MESH) &&
5445
0
      ssid->frequency > 0 && params.freq.freq == 0)
5446
0
    ibss_mesh_setup_freq(wpa_s, ssid, &params.freq);
5447
5448
0
  if (ssid->mode == WPAS_MODE_IBSS) {
5449
0
    params.fixed_freq = ssid->fixed_freq;
5450
0
    if (ssid->beacon_int)
5451
0
      params.beacon_int = ssid->beacon_int;
5452
0
    else
5453
0
      params.beacon_int = wpa_s->conf->beacon_int;
5454
0
  }
5455
5456
0
  if (bss && ssid->enable_edmg)
5457
0
    edmg_ie_oper = wpa_bss_get_ie_ext(bss,
5458
0
              WLAN_EID_EXT_EDMG_OPERATION);
5459
0
  else
5460
0
    edmg_ie_oper = NULL;
5461
5462
0
  if (edmg_ie_oper) {
5463
0
    params.freq.edmg.channels =
5464
0
      wpa_ie_get_edmg_oper_chans(edmg_ie_oper);
5465
0
    params.freq.edmg.bw_config =
5466
0
      wpa_ie_get_edmg_oper_chan_width(edmg_ie_oper);
5467
0
    wpa_printf(MSG_DEBUG,
5468
0
         "AP supports EDMG channels 0x%x, bw_config %d",
5469
0
         params.freq.edmg.channels,
5470
0
         params.freq.edmg.bw_config);
5471
5472
    /* User may ask for specific EDMG channel for EDMG connection
5473
     * (must be supported by AP)
5474
     */
5475
0
    if (ssid->edmg_channel) {
5476
0
      struct ieee80211_edmg_config configured_edmg;
5477
0
      enum hostapd_hw_mode hw_mode;
5478
0
      u8 primary_channel;
5479
5480
0
      hw_mode = ieee80211_freq_to_chan(bss->freq,
5481
0
               &primary_channel);
5482
0
      if (hw_mode == NUM_HOSTAPD_MODES)
5483
0
        goto edmg_fail;
5484
5485
0
      hostapd_encode_edmg_chan(ssid->enable_edmg,
5486
0
             ssid->edmg_channel,
5487
0
             primary_channel,
5488
0
             &configured_edmg);
5489
5490
0
      if (ieee802_edmg_is_allowed(params.freq.edmg,
5491
0
                configured_edmg)) {
5492
0
        params.freq.edmg = configured_edmg;
5493
0
        wpa_printf(MSG_DEBUG,
5494
0
             "Use EDMG channel %d for connection",
5495
0
             ssid->edmg_channel);
5496
0
      } else {
5497
0
      edmg_fail:
5498
0
        params.freq.edmg.channels = 0;
5499
0
        params.freq.edmg.bw_config = 0;
5500
0
        wpa_printf(MSG_WARNING,
5501
0
             "EDMG channel %d not supported by AP, fallback to DMG",
5502
0
             ssid->edmg_channel);
5503
0
      }
5504
0
    }
5505
5506
0
    if (params.freq.edmg.channels) {
5507
0
      wpa_printf(MSG_DEBUG,
5508
0
           "EDMG before: channels 0x%x, bw_config %d",
5509
0
           params.freq.edmg.channels,
5510
0
           params.freq.edmg.bw_config);
5511
0
      params.freq.edmg = get_supported_edmg(wpa_s,
5512
0
                    &params.freq,
5513
0
                    params.freq.edmg);
5514
0
      wpa_printf(MSG_DEBUG,
5515
0
           "EDMG after: channels 0x%x, bw_config %d",
5516
0
           params.freq.edmg.channels,
5517
0
           params.freq.edmg.bw_config);
5518
0
    }
5519
0
  }
5520
5521
0
  params.pairwise_suite = cipher_pairwise;
5522
0
  params.group_suite = cipher_group;
5523
0
  params.mgmt_group_suite = cipher_group_mgmt;
5524
0
  params.key_mgmt_suite = wpa_s->key_mgmt;
5525
0
  params.allowed_key_mgmts = wpa_s->allowed_key_mgmts;
5526
0
  params.wpa_proto = wpa_s->wpa_proto;
5527
0
  wpa_s->auth_alg = params.auth_alg;
5528
0
  params.mode = ssid->mode;
5529
0
  params.bg_scan_period = ssid->bg_scan_period;
5530
#ifdef CONFIG_WEP
5531
  {
5532
    int i;
5533
5534
    for (i = 0; i < NUM_WEP_KEYS; i++) {
5535
      if (ssid->wep_key_len[i])
5536
        params.wep_key[i] = ssid->wep_key[i];
5537
      params.wep_key_len[i] = ssid->wep_key_len[i];
5538
    }
5539
    params.wep_tx_keyidx = ssid->wep_tx_keyidx;
5540
  }
5541
#endif /* CONFIG_WEP */
5542
5543
0
  if ((wpa_s->drv_flags & WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_PSK) &&
5544
0
      (params.key_mgmt_suite == WPA_KEY_MGMT_PSK ||
5545
0
       params.key_mgmt_suite == WPA_KEY_MGMT_FT_PSK ||
5546
0
       (params.allowed_key_mgmts &
5547
0
        (WPA_KEY_MGMT_PSK | WPA_KEY_MGMT_FT_PSK)))) {
5548
0
    params.passphrase = ssid->passphrase;
5549
0
    if (wpa_supplicant_get_psk(wpa_s, bss, ssid, psk) == 0)
5550
0
      params.psk = psk;
5551
0
  }
5552
5553
0
  if ((wpa_s->drv_flags & WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_8021X) &&
5554
0
      (params.key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X ||
5555
0
       params.key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X_SHA256 ||
5556
0
       params.key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X_SUITE_B ||
5557
0
       params.key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X_SUITE_B_192 ||
5558
0
       params.key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X_SHA384))
5559
0
    params.req_handshake_offload = 1;
5560
5561
0
  if (wpa_s->conf->key_mgmt_offload) {
5562
0
    if (params.key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X ||
5563
0
        params.key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X_SHA256 ||
5564
0
        params.key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X_SUITE_B ||
5565
0
        params.key_mgmt_suite ==
5566
0
        WPA_KEY_MGMT_IEEE8021X_SUITE_B_192 ||
5567
0
        params.key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X_SHA384)
5568
0
      params.req_key_mgmt_offload =
5569
0
        ssid->proactive_key_caching < 0 ?
5570
0
        wpa_s->conf->okc : ssid->proactive_key_caching;
5571
0
    else
5572
0
      params.req_key_mgmt_offload = 1;
5573
5574
0
    if ((wpa_key_mgmt_wpa_psk_no_sae(params.key_mgmt_suite) ||
5575
0
         wpa_key_mgmt_wpa_psk_no_sae(params.allowed_key_mgmts)) &&
5576
0
        wpa_supplicant_get_psk(wpa_s, bss, ssid, psk) == 0)
5577
0
      params.psk = psk;
5578
0
  }
5579
5580
0
  if ((wpa_s->drv_flags2 & WPA_DRIVER_FLAGS2_SAE_OFFLOAD_STA) &&
5581
0
      wpa_key_mgmt_sae(params.key_mgmt_suite)) {
5582
0
    params.auth_alg = WPA_AUTH_ALG_SAE;
5583
0
    if (ssid->sae_password) {
5584
0
      params.sae_password = ssid->sae_password;
5585
0
      params.sae_password_id = ssid->sae_password_id;
5586
0
    } else if (ssid->passphrase) {
5587
0
      params.passphrase = ssid->passphrase;
5588
0
    }
5589
0
  }
5590
5591
0
  if ((wpa_s->drv_flags2 & WPA_DRIVER_FLAGS2_OKC_PMKID_IN_ASSOC) &&
5592
0
      (ssid->proactive_key_caching < 0 ? wpa_s->conf->okc :
5593
0
       ssid->proactive_key_caching) &&
5594
0
      (ssid->proto & WPA_PROTO_RSN))
5595
0
    params.okc_pmkid_in_assoc = true;
5596
5597
0
  params.drop_unencrypted = use_crypt;
5598
5599
0
  params.mgmt_frame_protection = wpas_get_ssid_pmf(wpa_s, ssid);
5600
0
  if (params.mgmt_frame_protection != NO_MGMT_FRAME_PROTECTION && bss) {
5601
0
    const u8 *rsn = wpa_bss_get_rsne(wpa_s, bss, ssid, false);
5602
0
    struct wpa_ie_data ie;
5603
0
    if (!wpas_driver_bss_selection(wpa_s) && rsn &&
5604
0
        wpa_parse_wpa_ie(rsn, 2 + rsn[1], &ie) == 0 &&
5605
0
        ie.capabilities &
5606
0
        (WPA_CAPABILITY_MFPC | WPA_CAPABILITY_MFPR)) {
5607
0
      wpa_dbg(wpa_s, MSG_DEBUG, "WPA: Selected AP supports "
5608
0
        "MFP: require MFP");
5609
0
      params.mgmt_frame_protection =
5610
0
        MGMT_FRAME_PROTECTION_REQUIRED;
5611
#ifdef CONFIG_OWE
5612
    } else if (!rsn && (ssid->key_mgmt & WPA_KEY_MGMT_OWE) &&
5613
         !ssid->owe_only) {
5614
      params.mgmt_frame_protection = NO_MGMT_FRAME_PROTECTION;
5615
#endif /* CONFIG_OWE */
5616
0
    }
5617
0
  }
5618
5619
0
  params.p2p = ssid->p2p_group;
5620
5621
0
  if (wpa_s->p2pdev->set_sta_uapsd)
5622
0
    params.uapsd = wpa_s->p2pdev->sta_uapsd;
5623
0
  else
5624
0
    params.uapsd = -1;
5625
5626
#ifdef CONFIG_HT_OVERRIDES
5627
  os_memset(&htcaps, 0, sizeof(htcaps));
5628
  os_memset(&htcaps_mask, 0, sizeof(htcaps_mask));
5629
  params.htcaps = (u8 *) &htcaps;
5630
  params.htcaps_mask = (u8 *) &htcaps_mask;
5631
  wpa_supplicant_apply_ht_overrides(wpa_s, ssid, &params);
5632
#endif /* CONFIG_HT_OVERRIDES */
5633
#ifdef CONFIG_VHT_OVERRIDES
5634
  os_memset(&vhtcaps, 0, sizeof(vhtcaps));
5635
  os_memset(&vhtcaps_mask, 0, sizeof(vhtcaps_mask));
5636
  params.vhtcaps = &vhtcaps;
5637
  params.vhtcaps_mask = &vhtcaps_mask;
5638
  wpa_supplicant_apply_vht_overrides(wpa_s, ssid, &params);
5639
#endif /* CONFIG_VHT_OVERRIDES */
5640
#ifdef CONFIG_HE_OVERRIDES
5641
  wpa_supplicant_apply_he_overrides(wpa_s, ssid, &params);
5642
#endif /* CONFIG_HE_OVERRIDES */
5643
0
  wpa_supplicant_apply_eht_overrides(wpa_s, ssid, &params);
5644
0
  wpa_supplicant_apply_uhr_overrides(wpa_s, ssid, &params);
5645
5646
#ifdef CONFIG_P2P
5647
  /*
5648
   * If multi-channel concurrency is not supported, check for any
5649
   * frequency conflict. In case of any frequency conflict, remove the
5650
   * least prioritized connection.
5651
   */
5652
  if (wpa_s->num_multichan_concurrent < 2) {
5653
    int freq, num;
5654
    num = get_shared_radio_freqs(wpa_s, &freq, 1, false);
5655
    if (num > 0 && freq > 0 && freq != params.freq.freq) {
5656
      wpa_printf(MSG_DEBUG,
5657
           "Assoc conflicting freq found (%d != %d)",
5658
           freq, params.freq.freq);
5659
      if (wpas_p2p_handle_frequency_conflicts(
5660
            wpa_s, params.freq.freq, ssid) < 0) {
5661
        wpas_connect_work_done(wpa_s);
5662
        os_free(wpa_ie);
5663
        return;
5664
      }
5665
    }
5666
  }
5667
#endif /* CONFIG_P2P */
5668
5669
0
  if (wpa_s->reassoc_same_ess && !is_zero_ether_addr(prev_bssid) &&
5670
0
      old_ssid)
5671
0
    params.prev_bssid = prev_bssid;
5672
5673
#ifdef CONFIG_SAE
5674
  params.sae_pwe = wpas_get_ssid_sae_pwe(wpa_s, ssid);
5675
#endif /* CONFIG_SAE */
5676
5677
0
  params.security_profile_active = wpas_security_profile_active(wpa_s);
5678
5679
0
  ret = wpa_drv_associate(wpa_s, &params);
5680
0
  forced_memzero(psk, sizeof(psk));
5681
0
  os_free(wpa_ie);
5682
0
  if (ret < 0) {
5683
0
    wpa_msg(wpa_s, MSG_INFO, "Association request to the driver "
5684
0
      "failed");
5685
0
    if (wpa_s->drv_flags & WPA_DRIVER_FLAGS_VALID_ERROR_CODES) {
5686
      /*
5687
       * The driver is known to mean what is saying, so we
5688
       * can stop right here; the association will not
5689
       * succeed.
5690
       */
5691
0
      wpas_connection_failed(wpa_s, wpa_s->pending_bssid,
5692
0
                 NULL);
5693
0
      wpa_supplicant_set_state(wpa_s, WPA_DISCONNECTED);
5694
0
      os_memset(wpa_s->pending_bssid, 0, ETH_ALEN);
5695
0
      return;
5696
0
    }
5697
    /* try to continue anyway; new association will be tried again
5698
     * after timeout */
5699
0
    assoc_failed = 1;
5700
0
  }
5701
5702
0
  if (wpa_s->key_mgmt == WPA_KEY_MGMT_WPA_NONE) {
5703
    /* Set the key after the association just in case association
5704
     * cleared the previously configured key. */
5705
0
    wpa_supplicant_set_wpa_none_key(wpa_s, ssid);
5706
    /* No need to timeout authentication since there is no key
5707
     * management. */
5708
0
    wpa_supplicant_cancel_auth_timeout(wpa_s);
5709
0
    wpa_supplicant_set_state(wpa_s, WPA_COMPLETED);
5710
#ifdef CONFIG_IBSS_RSN
5711
  } else if (ssid->mode == WPAS_MODE_IBSS &&
5712
       wpa_s->key_mgmt != WPA_KEY_MGMT_NONE &&
5713
       wpa_s->key_mgmt != WPA_KEY_MGMT_WPA_NONE) {
5714
    /*
5715
     * RSN IBSS authentication is per-STA and we can disable the
5716
     * per-BSSID authentication.
5717
     */
5718
    wpa_supplicant_cancel_auth_timeout(wpa_s);
5719
#endif /* CONFIG_IBSS_RSN */
5720
0
  } else {
5721
    /* Timeout for IEEE 802.11 authentication and association */
5722
0
    int timeout = 60;
5723
5724
0
    if (assoc_failed) {
5725
      /* give IBSS a bit more time */
5726
0
      timeout = ssid->mode == WPAS_MODE_IBSS ? 10 : 5;
5727
0
    } else if (wpa_s->conf->ap_scan == 1) {
5728
      /* give IBSS a bit more time */
5729
0
      timeout = ssid->mode == WPAS_MODE_IBSS ? 20 : 10;
5730
0
    }
5731
0
    wpa_supplicant_req_auth_timeout(wpa_s, timeout, 0);
5732
0
  }
5733
5734
#ifdef CONFIG_P2P
5735
  if (ssid->pmk_valid && wpa_s->p2p_pmksa_entry &&
5736
      !(wpa_s->drv_flags & WPA_DRIVER_FLAGS_SME)) {
5737
    wpa_sm_pmksa_cache_add_entry(wpa_s->wpa,
5738
               wpa_s->p2p_pmksa_entry);
5739
    wpa_s->p2p_pmksa_entry = NULL;
5740
  }
5741
#endif /* CONFIG_P2P */
5742
5743
#ifdef CONFIG_WEP
5744
  if (wep_keys_set &&
5745
      (wpa_s->drv_flags & WPA_DRIVER_FLAGS_SET_KEYS_AFTER_ASSOC)) {
5746
    /* Set static WEP keys again */
5747
    wpa_set_wep_keys(wpa_s, ssid);
5748
  }
5749
#endif /* CONFIG_WEP */
5750
5751
0
  if (old_ssid && old_ssid != ssid) {
5752
    /*
5753
     * Do not allow EAP session resumption between different
5754
     * network configurations.
5755
     */
5756
0
    eapol_sm_invalidate_cached_session(wpa_s->eapol);
5757
0
  }
5758
5759
0
  if (!wpas_driver_bss_selection(wpa_s) ||
5760
#ifdef CONFIG_P2P
5761
      wpa_s->p2p_in_invitation ||
5762
#endif /* CONFIG_P2P */
5763
0
      ssid->bssid_set) {
5764
0
    wpa_s->current_bss = bss;
5765
0
    wpas_configure_frame_filters(wpa_s);
5766
0
  }
5767
5768
0
  wpa_supplicant_rsn_supp_set_config(wpa_s, wpa_s->current_ssid);
5769
0
  if (bss)
5770
0
    wpa_sm_set_ssid(wpa_s->wpa, bss->ssid, bss->ssid_len);
5771
0
  wpa_supplicant_initiate_eapol(wpa_s);
5772
0
  if (old_ssid != wpa_s->current_ssid)
5773
0
    wpas_notify_network_changed(wpa_s);
5774
0
  if (!(wpa_s->drv_flags & WPA_DRIVER_FLAGS_SME))
5775
0
    wpas_notify_auth_changed(wpa_s);
5776
0
}
Unexecuted instantiation: wpa_supplicant.c:wpas_start_assoc_cb
Unexecuted instantiation: wpa_supplicant.c:wpas_start_assoc_cb
5777
5778
5779
static void wpa_supplicant_clear_connection(struct wpa_supplicant *wpa_s,
5780
              const u8 *addr)
5781
0
{
5782
0
  struct wpa_ssid *old_ssid;
5783
5784
0
  wpa_s->ml_connect_probe_ssid = NULL;
5785
0
  wpa_s->ml_connect_probe_bss = NULL;
5786
0
  wpas_connect_work_done(wpa_s);
5787
0
  wpa_clear_keys(wpa_s, addr);
5788
0
  old_ssid = wpa_s->current_ssid;
5789
0
  wpa_supplicant_mark_disassoc(wpa_s);
5790
0
  wpa_sm_set_config(wpa_s->wpa, NULL);
5791
0
  eapol_sm_notify_config(wpa_s->eapol, NULL, NULL);
5792
0
  if (old_ssid != wpa_s->current_ssid)
5793
0
    wpas_notify_network_changed(wpa_s);
5794
5795
0
#ifndef CONFIG_NO_ROBUST_AV
5796
0
  wpas_scs_deinit(wpa_s);
5797
0
  wpas_dscp_deinit(wpa_s);
5798
0
#endif /* CONFIG_NO_ROBUST_AV */
5799
0
  eloop_cancel_timeout(wpa_supplicant_timeout, wpa_s, NULL);
5800
0
}
5801
5802
5803
/**
5804
 * wpa_supplicant_deauthenticate - Deauthenticate the current connection
5805
 * @wpa_s: Pointer to wpa_supplicant data
5806
 * @reason_code: IEEE 802.11 reason code for the deauthenticate frame
5807
 *
5808
 * This function is used to request %wpa_supplicant to deauthenticate from the
5809
 * current AP.
5810
 */
5811
void wpa_supplicant_deauthenticate(struct wpa_supplicant *wpa_s,
5812
           u16 reason_code)
5813
0
{
5814
0
  u8 *addr = NULL;
5815
0
  union wpa_event_data event;
5816
0
  int zero_addr = 0;
5817
5818
0
  wpa_dbg(wpa_s, MSG_DEBUG, "Request to deauthenticate - bssid=" MACSTR
5819
0
    " pending_bssid=" MACSTR
5820
0
    " reason=%d (%s) state=%s valid_links=0x%x ap_mld_addr=" MACSTR,
5821
0
    MAC2STR(wpa_s->bssid), MAC2STR(wpa_s->pending_bssid),
5822
0
    reason_code, reason2str(reason_code),
5823
0
    wpa_supplicant_state_txt(wpa_s->wpa_state), wpa_s->valid_links,
5824
0
    MAC2STR(wpa_s->ap_mld_addr));
5825
5826
0
  if (wpa_s->valid_links && !is_zero_ether_addr(wpa_s->ap_mld_addr))
5827
0
    addr = wpa_s->ap_mld_addr;
5828
0
  else if (!is_zero_ether_addr(wpa_s->pending_bssid) &&
5829
0
     (wpa_s->wpa_state == WPA_AUTHENTICATING ||
5830
0
      wpa_s->wpa_state == WPA_ASSOCIATING))
5831
0
    addr = wpa_s->pending_bssid;
5832
0
  else if (!is_zero_ether_addr(wpa_s->bssid))
5833
0
    addr = wpa_s->bssid;
5834
0
  else if (wpa_s->wpa_state == WPA_ASSOCIATING) {
5835
    /*
5836
     * When using driver-based BSS selection, we may not know the
5837
     * BSSID with which we are currently trying to associate. We
5838
     * need to notify the driver of this disconnection even in such
5839
     * a case, so use the all zeros address here.
5840
     */
5841
0
    addr = wpa_s->bssid;
5842
0
    zero_addr = 1;
5843
0
  }
5844
5845
0
  if (wpa_s->enabled_4addr_mode && wpa_drv_set_4addr_mode(wpa_s, 0) == 0)
5846
0
    wpa_s->enabled_4addr_mode = 0;
5847
5848
#ifdef CONFIG_TDLS
5849
  wpa_tdls_teardown_peers(wpa_s->wpa);
5850
#endif /* CONFIG_TDLS */
5851
5852
#ifdef CONFIG_MESH
5853
  if (wpa_s->ifmsh) {
5854
    struct mesh_conf *mconf;
5855
5856
    mconf = wpa_s->ifmsh->mconf;
5857
    wpa_msg(wpa_s, MSG_INFO, MESH_GROUP_REMOVED "%s",
5858
      wpa_s->ifname);
5859
    wpas_notify_mesh_group_removed(wpa_s, mconf->meshid,
5860
                 mconf->meshid_len, reason_code);
5861
    wpa_supplicant_leave_mesh(wpa_s, true);
5862
  }
5863
#endif /* CONFIG_MESH */
5864
5865
0
  if (addr) {
5866
0
    wpa_drv_deauthenticate(wpa_s, addr, reason_code);
5867
0
    os_memset(&event, 0, sizeof(event));
5868
0
    event.deauth_info.reason_code = reason_code;
5869
0
    event.deauth_info.locally_generated = 1;
5870
0
    wpa_supplicant_event(wpa_s, EVENT_DEAUTH, &event);
5871
0
    if (zero_addr)
5872
0
      addr = NULL;
5873
0
  }
5874
5875
0
  wpa_supplicant_clear_connection(wpa_s, addr);
5876
0
}
5877
5878
5879
void wpa_supplicant_reconnect(struct wpa_supplicant *wpa_s)
5880
0
{
5881
0
  wpa_s->own_reconnect_req = 1;
5882
0
  wpa_supplicant_deauthenticate(wpa_s, WLAN_REASON_UNSPECIFIED);
5883
5884
0
}
5885
5886
5887
static void wpa_supplicant_enable_one_network(struct wpa_supplicant *wpa_s,
5888
                struct wpa_ssid *ssid)
5889
0
{
5890
0
  if (!ssid || !ssid->disabled || ssid->disabled == 2)
5891
0
    return;
5892
5893
0
  ssid->disabled = 0;
5894
0
  ssid->owe_transition_bss_select_count = 0;
5895
0
  wpas_clear_temp_disabled(wpa_s, ssid, 1);
5896
0
  wpas_notify_network_enabled_changed(wpa_s, ssid);
5897
5898
  /*
5899
   * Try to reassociate since there is no current configuration and a new
5900
   * network was made available.
5901
   */
5902
0
  if (!wpa_s->current_ssid && !wpa_s->disconnected)
5903
0
    wpa_s->reassociate = 1;
5904
0
}
5905
5906
5907
/**
5908
 * wpa_supplicant_add_network - Add a new network
5909
 * @wpa_s: wpa_supplicant structure for a network interface
5910
 * Returns: The new network configuration or %NULL if operation failed
5911
 *
5912
 * This function performs the following operations:
5913
 * 1. Adds a new network.
5914
 * 2. Send network addition notification.
5915
 * 3. Marks the network disabled.
5916
 * 4. Set network default parameters.
5917
 */
5918
struct wpa_ssid * wpa_supplicant_add_network(struct wpa_supplicant *wpa_s)
5919
0
{
5920
0
  struct wpa_ssid *ssid;
5921
5922
0
  ssid = wpa_config_add_network(wpa_s->conf);
5923
0
  if (!ssid)
5924
0
    return NULL;
5925
0
  wpas_notify_network_added(wpa_s, ssid);
5926
0
  ssid->disabled = 1;
5927
0
  wpa_config_set_network_defaults(ssid);
5928
5929
0
  return ssid;
5930
0
}
5931
5932
5933
/**
5934
 * wpa_supplicant_remove_network - Remove a configured network based on id
5935
 * @wpa_s: wpa_supplicant structure for a network interface
5936
 * @id: Unique network id to search for
5937
 * Returns: 0 on success, or -1 if the network was not found, -2 if the network
5938
 * could not be removed
5939
 *
5940
 * This function performs the following operations:
5941
 * 1. Removes the network.
5942
 * 2. Send network removal notification.
5943
 * 3. Update internal state machines.
5944
 * 4. Stop any running sched scans.
5945
 */
5946
int wpa_supplicant_remove_network(struct wpa_supplicant *wpa_s, int id)
5947
0
{
5948
0
  struct wpa_ssid *ssid, *prev = wpa_s->current_ssid;
5949
0
  int was_disabled;
5950
5951
0
  ssid = wpa_config_get_network(wpa_s->conf, id);
5952
0
  if (!ssid)
5953
0
    return -1;
5954
0
  wpas_notify_network_removed(wpa_s, ssid);
5955
0
  radio_remove_pending_connect(wpa_s, ssid);
5956
5957
0
  if (ssid == prev || !prev) {
5958
#ifdef CONFIG_SME
5959
    wpa_s->sme.prev_bssid_set = 0;
5960
#endif /* CONFIG_SME */
5961
    /*
5962
     * Invalidate the EAP session cache if the current or
5963
     * previously used network is removed.
5964
     */
5965
0
    eapol_sm_invalidate_cached_session(wpa_s->eapol);
5966
0
  }
5967
5968
0
  if (ssid == prev) {
5969
0
    wpa_sm_set_config(wpa_s->wpa, NULL);
5970
0
    eapol_sm_notify_config(wpa_s->eapol, NULL, NULL);
5971
5972
0
    if (wpa_s->wpa_state >= WPA_AUTHENTICATING)
5973
0
      wpa_s->own_disconnect_req = 1;
5974
0
    wpa_supplicant_deauthenticate(wpa_s,
5975
0
                WLAN_REASON_DEAUTH_LEAVING);
5976
0
  }
5977
5978
0
  was_disabled = ssid->disabled;
5979
5980
0
  if (wpa_config_remove_network(wpa_s->conf, id) < 0)
5981
0
    return -2;
5982
5983
0
  if (!was_disabled && wpa_s->sched_scanning) {
5984
0
    wpa_printf(MSG_DEBUG,
5985
0
         "Stop ongoing sched_scan to remove network from filters");
5986
0
    wpa_supplicant_cancel_sched_scan(wpa_s);
5987
0
    wpa_supplicant_req_scan(wpa_s, 0, 0);
5988
0
  }
5989
5990
0
  return 0;
5991
0
}
5992
5993
5994
/**
5995
 * wpa_supplicant_remove_all_networks - Remove all configured networks
5996
 * @wpa_s: wpa_supplicant structure for a network interface
5997
 * Returns: 0 on success (errors are currently ignored)
5998
 *
5999
 * This function performs the following operations:
6000
 * 1. Remove all networks.
6001
 * 2. Send network removal notifications.
6002
 * 3. Update internal state machines.
6003
 * 4. Stop any running sched scans.
6004
 */
6005
int wpa_supplicant_remove_all_networks(struct wpa_supplicant *wpa_s)
6006
0
{
6007
0
  struct wpa_ssid *ssid;
6008
6009
0
  if (wpa_s->drv_flags2 &
6010
0
      (WPA_DRIVER_FLAGS2_SAE_OFFLOAD_STA |
6011
0
       WPA_DRIVER_FLAGS2_OWE_OFFLOAD_STA))
6012
0
    wpa_drv_flush_pmkid(wpa_s);
6013
6014
0
  if (wpa_s->sched_scanning)
6015
0
    wpa_supplicant_cancel_sched_scan(wpa_s);
6016
6017
0
  eapol_sm_invalidate_cached_session(wpa_s->eapol);
6018
0
  if (wpa_s->current_ssid) {
6019
#ifdef CONFIG_SME
6020
    wpa_s->sme.prev_bssid_set = 0;
6021
#endif /* CONFIG_SME */
6022
0
    wpa_sm_set_config(wpa_s->wpa, NULL);
6023
0
    eapol_sm_notify_config(wpa_s->eapol, NULL, NULL);
6024
0
    if (wpa_s->wpa_state >= WPA_AUTHENTICATING)
6025
0
      wpa_s->own_disconnect_req = 1;
6026
0
    wpa_supplicant_deauthenticate(
6027
0
      wpa_s, WLAN_REASON_DEAUTH_LEAVING);
6028
0
  }
6029
0
  ssid = wpa_s->conf->ssid;
6030
0
  while (ssid) {
6031
0
    struct wpa_ssid *remove_ssid = ssid;
6032
0
    int id;
6033
6034
0
    id = ssid->id;
6035
0
    ssid = ssid->next;
6036
0
    wpas_notify_network_removed(wpa_s, remove_ssid);
6037
0
    wpa_config_remove_network(wpa_s->conf, id);
6038
0
  }
6039
0
  return 0;
6040
0
}
6041
6042
6043
/**
6044
 * wpa_supplicant_enable_network - Mark a configured network as enabled
6045
 * @wpa_s: wpa_supplicant structure for a network interface
6046
 * @ssid: wpa_ssid structure for a configured network or %NULL
6047
 *
6048
 * Enables the specified network or all networks if no network specified.
6049
 */
6050
void wpa_supplicant_enable_network(struct wpa_supplicant *wpa_s,
6051
           struct wpa_ssid *ssid)
6052
0
{
6053
0
  if (ssid == NULL) {
6054
0
    for (ssid = wpa_s->conf->ssid; ssid; ssid = ssid->next)
6055
0
      wpa_supplicant_enable_one_network(wpa_s, ssid);
6056
0
  } else
6057
0
    wpa_supplicant_enable_one_network(wpa_s, ssid);
6058
6059
0
  if (wpa_s->reassociate && !wpa_s->disconnected &&
6060
0
      (!wpa_s->current_ssid ||
6061
0
       wpa_s->wpa_state == WPA_DISCONNECTED ||
6062
0
       wpa_s->wpa_state == WPA_SCANNING)) {
6063
0
    if (wpa_s->sched_scanning) {
6064
0
      wpa_printf(MSG_DEBUG, "Stop ongoing sched_scan to add "
6065
0
           "new network to scan filters");
6066
0
      wpa_supplicant_cancel_sched_scan(wpa_s);
6067
0
    }
6068
6069
0
    if (wpa_supplicant_fast_associate(wpa_s) != 1) {
6070
0
      wpa_s->scan_req = NORMAL_SCAN_REQ;
6071
0
      wpa_supplicant_req_scan(wpa_s, 0, 0);
6072
0
    }
6073
0
  }
6074
0
}
6075
6076
6077
/**
6078
 * wpa_supplicant_disable_network - Mark a configured network as disabled
6079
 * @wpa_s: wpa_supplicant structure for a network interface
6080
 * @ssid: wpa_ssid structure for a configured network or %NULL
6081
 *
6082
 * Disables the specified network or all networks if no network specified.
6083
 */
6084
void wpa_supplicant_disable_network(struct wpa_supplicant *wpa_s,
6085
            struct wpa_ssid *ssid)
6086
0
{
6087
0
  struct wpa_ssid *other_ssid;
6088
0
  int was_disabled;
6089
6090
0
  if (ssid == NULL) {
6091
0
    if (wpa_s->sched_scanning)
6092
0
      wpa_supplicant_cancel_sched_scan(wpa_s);
6093
6094
0
    for (other_ssid = wpa_s->conf->ssid; other_ssid;
6095
0
         other_ssid = other_ssid->next) {
6096
0
      was_disabled = other_ssid->disabled;
6097
0
      if (was_disabled == 2)
6098
0
        continue; /* do not change persistent P2P group
6099
             * data */
6100
6101
0
      other_ssid->disabled = 1;
6102
6103
0
      if (was_disabled != other_ssid->disabled)
6104
0
        wpas_notify_network_enabled_changed(
6105
0
          wpa_s, other_ssid);
6106
0
    }
6107
0
    if (wpa_s->current_ssid) {
6108
0
      if (wpa_s->wpa_state >= WPA_AUTHENTICATING)
6109
0
        wpa_s->own_disconnect_req = 1;
6110
0
      wpa_supplicant_deauthenticate(
6111
0
        wpa_s, WLAN_REASON_DEAUTH_LEAVING);
6112
0
    }
6113
0
  } else if (ssid->disabled != 2) {
6114
0
    if (ssid == wpa_s->current_ssid) {
6115
0
      if (wpa_s->wpa_state >= WPA_AUTHENTICATING)
6116
0
        wpa_s->own_disconnect_req = 1;
6117
0
      wpa_supplicant_deauthenticate(
6118
0
        wpa_s, WLAN_REASON_DEAUTH_LEAVING);
6119
0
    }
6120
6121
0
    was_disabled = ssid->disabled;
6122
6123
0
    ssid->disabled = 1;
6124
6125
0
    if (was_disabled != ssid->disabled) {
6126
0
      wpas_notify_network_enabled_changed(wpa_s, ssid);
6127
0
      if (wpa_s->sched_scanning) {
6128
0
        wpa_printf(MSG_DEBUG, "Stop ongoing sched_scan "
6129
0
             "to remove network from filters");
6130
0
        wpa_supplicant_cancel_sched_scan(wpa_s);
6131
0
        wpa_supplicant_req_scan(wpa_s, 0, 0);
6132
0
      }
6133
0
    }
6134
0
  }
6135
0
}
6136
6137
6138
static bool ssid_in_last_scan(struct wpa_supplicant *wpa_s,
6139
            struct wpa_ssid *ssid)
6140
0
{
6141
0
  size_t i;
6142
6143
  /* Check if the previous scan included the selected network */
6144
0
  if (wpa_s->last_scan_num_ssids <= 1 ||
6145
0
      !ssid->ssid || ssid->ssid_len == 0)
6146
0
    return false;
6147
6148
  /* Iterate through the previous scan SSIDs */
6149
0
  for (i = 0; i < wpa_s->last_scan_num_ssids;  i++) {
6150
0
    if (os_memcmp(wpa_s->last_scan_ssids[i].ssid, ssid->ssid,
6151
0
            ssid->ssid_len) == 0)
6152
0
      return true;
6153
0
  }
6154
6155
0
  return false;
6156
0
}
6157
6158
6159
/**
6160
 * Checks whether an SSID was discovered in the last scan.
6161
 * @wpa_s: wpa_supplicant structure for a network interface.
6162
 * @ssid: wpa_ssid structure for a configured network.
6163
 * Returns: true if ssid found, false otherwise.
6164
 */
6165
static bool ssid_in_last_scan_res(struct wpa_supplicant *wpa_s,
6166
          struct wpa_ssid *ssid)
6167
0
{
6168
0
  size_t i;
6169
6170
0
  if (!wpa_s->last_scan_res || !ssid->ssid || ssid->ssid_len == 0)
6171
0
    return false;
6172
6173
0
  for (i = 0; i < wpa_s->last_scan_res_used; i++) {
6174
0
    if (os_memcmp(wpa_s->last_scan_res[i]->ssid,
6175
0
            ssid->ssid, ssid->ssid_len) == 0)
6176
0
      return true;
6177
0
  }
6178
6179
0
  return false;
6180
0
}
6181
6182
6183
/**
6184
 * wpa_supplicant_select_network - Attempt association with a network
6185
 * @wpa_s: wpa_supplicant structure for a network interface
6186
 * @ssid: wpa_ssid structure for a configured network or %NULL for any network
6187
 */
6188
void wpa_supplicant_select_network(struct wpa_supplicant *wpa_s,
6189
           struct wpa_ssid *ssid)
6190
0
{
6191
6192
0
  struct wpa_ssid *other_ssid;
6193
0
  int disconnected = 0;
6194
0
  bool request_new_scan = false;
6195
6196
0
  if (ssid && ssid != wpa_s->current_ssid && wpa_s->current_ssid) {
6197
0
    if (wpa_s->wpa_state >= WPA_AUTHENTICATING)
6198
0
      wpa_s->own_disconnect_req = 1;
6199
0
    wpa_supplicant_deauthenticate(
6200
0
      wpa_s, WLAN_REASON_DEAUTH_LEAVING);
6201
0
    disconnected = 1;
6202
0
  }
6203
6204
0
  if (ssid)
6205
0
    wpas_clear_temp_disabled(wpa_s, ssid, 1);
6206
6207
  /*
6208
   * Mark all other networks disabled or mark all networks enabled if no
6209
   * network specified.
6210
   */
6211
0
  for (other_ssid = wpa_s->conf->ssid; other_ssid;
6212
0
       other_ssid = other_ssid->next) {
6213
0
    int was_disabled = other_ssid->disabled;
6214
0
    if (was_disabled == 2)
6215
0
      continue; /* do not change persistent P2P group data */
6216
6217
0
    other_ssid->disabled = ssid ? (ssid->id != other_ssid->id) : 0;
6218
0
    if (was_disabled && !other_ssid->disabled)
6219
0
      wpas_clear_temp_disabled(wpa_s, other_ssid, 0);
6220
6221
0
    if (was_disabled != other_ssid->disabled)
6222
0
      wpas_notify_network_enabled_changed(wpa_s, other_ssid);
6223
0
  }
6224
6225
0
  if (ssid && ssid == wpa_s->current_ssid && wpa_s->current_ssid &&
6226
0
      wpa_s->wpa_state >= WPA_AUTHENTICATING) {
6227
    /* We are already associated with the selected network */
6228
0
    wpa_printf(MSG_DEBUG, "Already associated with the "
6229
0
         "selected network - do nothing");
6230
0
    return;
6231
0
  }
6232
6233
0
  if (ssid) {
6234
0
    wpa_s->current_ssid = ssid;
6235
0
    eapol_sm_notify_config(wpa_s->eapol, NULL, NULL);
6236
0
    wpa_s->connect_without_scan =
6237
0
      (ssid->mode == WPAS_MODE_MESH ||
6238
0
       ssid->mode == WPAS_MODE_AP) ? ssid : NULL;
6239
6240
0
    if (ssid->scan_ssid) {
6241
0
      if (ssid_in_last_scan(wpa_s, ssid)) {
6242
0
        wpa_printf(MSG_DEBUG,
6243
0
             "Hidden network was scanned for in last scan");
6244
0
      } else if (ssid_in_last_scan_res(wpa_s, ssid)) {
6245
0
        wpa_printf(MSG_DEBUG,
6246
0
             "Hidden network was found in last scan results");
6247
0
      } else {
6248
0
        request_new_scan = true;
6249
0
        wpa_printf(MSG_DEBUG,
6250
0
             "Request a new scan for hidden network");
6251
0
      }
6252
0
    }
6253
6254
0
    if (!request_new_scan && (ssid->key_mgmt & WPA_KEY_MGMT_OWE) &&
6255
0
        !ssid->owe_only) {
6256
0
      wpa_printf(MSG_DEBUG,
6257
0
           "Request a new scan for OWE transition SSID");
6258
0
      request_new_scan = true;
6259
0
    }
6260
6261
    /*
6262
     * Don't optimize next scan freqs since a new ESS has been
6263
     * selected.
6264
     */
6265
0
    os_free(wpa_s->next_scan_freqs);
6266
0
    wpa_s->next_scan_freqs = NULL;
6267
0
  } else {
6268
0
    wpa_s->connect_without_scan = NULL;
6269
0
  }
6270
6271
0
  wpa_s->disconnected = 0;
6272
0
  wpa_s->reassociate = 1;
6273
0
  wpa_s_clear_sae_rejected(wpa_s);
6274
0
  wpa_s->last_owe_group = 0;
6275
0
  if (ssid) {
6276
0
    ssid->owe_transition_bss_select_count = 0;
6277
0
    wpa_s_setup_sae_pt(wpa_s, ssid, false);
6278
0
  }
6279
6280
0
  if (wpa_s->connect_without_scan || request_new_scan ||
6281
0
      wpa_supplicant_fast_associate(wpa_s) != 1) {
6282
0
    wpa_s->scan_req = NORMAL_SCAN_REQ;
6283
0
    wpas_scan_reset_sched_scan(wpa_s);
6284
0
    wpa_supplicant_req_scan(wpa_s, 0, disconnected ? 100000 : 0);
6285
0
  }
6286
6287
0
  if (ssid)
6288
0
    wpas_notify_network_selected(wpa_s, ssid);
6289
0
}
6290
6291
6292
/**
6293
 * wpas_remove_cred - Remove the specified credential and all the network
6294
 * entries created based on the removed credential
6295
 * @wpa_s: wpa_supplicant structure for a network interface
6296
 * @cred: The credential to remove
6297
 * Returns: 0 on success, -1 on failure
6298
 */
6299
int wpas_remove_cred(struct wpa_supplicant *wpa_s, struct wpa_cred *cred)
6300
0
{
6301
0
  struct wpa_ssid *ssid, *next;
6302
0
  int id;
6303
6304
0
  if (!cred) {
6305
0
    wpa_printf(MSG_DEBUG, "Could not find cred");
6306
0
    return -1;
6307
0
  }
6308
6309
0
  id = cred->id;
6310
0
  if (wpa_config_remove_cred(wpa_s->conf, id) < 0) {
6311
0
    wpa_printf(MSG_DEBUG, "Could not find cred %d", id);
6312
0
    return -1;
6313
0
  }
6314
6315
0
  wpa_msg(wpa_s, MSG_INFO, CRED_REMOVED "%d", id);
6316
6317
  /* Remove any network entry created based on the removed credential */
6318
0
  ssid = wpa_s->conf->ssid;
6319
0
  while (ssid) {
6320
0
    next = ssid->next;
6321
6322
0
    if (ssid->parent_cred == cred) {
6323
0
      wpa_printf(MSG_DEBUG,
6324
0
           "Remove network id %d since it used the removed credential",
6325
0
           ssid->id);
6326
0
      if (wpa_supplicant_remove_network(wpa_s, ssid->id) ==
6327
0
          -1) {
6328
0
        wpa_printf(MSG_DEBUG,
6329
0
             "Could not find network id=%d",
6330
0
             ssid->id);
6331
0
      }
6332
0
    }
6333
6334
0
    ssid = next;
6335
0
  }
6336
6337
0
  return 0;
6338
0
}
6339
6340
6341
/**
6342
 * wpas_remove_cred - Remove all the Interworking credentials
6343
 * @wpa_s: wpa_supplicant structure for a network interface
6344
 * Returns: 0 on success, -1 on failure
6345
 */
6346
int wpas_remove_all_creds(struct wpa_supplicant *wpa_s)
6347
0
{
6348
0
  int res, ret = 0;
6349
0
  struct wpa_cred *cred, *prev;
6350
6351
0
  cred = wpa_s->conf->cred;
6352
0
  while (cred) {
6353
0
    prev = cred;
6354
0
    cred = cred->next;
6355
0
    res = wpas_remove_cred(wpa_s, prev);
6356
0
    if (res < 0) {
6357
0
      wpa_printf(MSG_DEBUG,
6358
0
           "Removal of all credentials failed - failed to remove credential id=%d",
6359
0
           prev->id);
6360
0
      ret = -1;
6361
0
    }
6362
0
  }
6363
6364
0
  return ret;
6365
0
}
6366
6367
6368
/**
6369
 * wpas_set_pkcs11_engine_and_module_path - Set PKCS #11 engine and module path
6370
 * @wpa_s: wpa_supplicant structure for a network interface
6371
 * @pkcs11_engine_path: PKCS #11 engine path or NULL
6372
 * @pkcs11_module_path: PKCS #11 module path or NULL
6373
 * Returns: 0 on success; -1 on failure
6374
 *
6375
 * Sets the PKCS #11 engine and module path. Both have to be NULL or a valid
6376
 * path. If resetting the EAPOL state machine with the new PKCS #11 engine and
6377
 * module path fails the paths will be reset to the default value (NULL).
6378
 */
6379
int wpas_set_pkcs11_engine_and_module_path(struct wpa_supplicant *wpa_s,
6380
             const char *pkcs11_engine_path,
6381
             const char *pkcs11_module_path)
6382
0
{
6383
0
  char *pkcs11_engine_path_copy = NULL;
6384
0
  char *pkcs11_module_path_copy = NULL;
6385
6386
0
  if (pkcs11_engine_path != NULL) {
6387
0
    pkcs11_engine_path_copy = os_strdup(pkcs11_engine_path);
6388
0
    if (pkcs11_engine_path_copy == NULL)
6389
0
      return -1;
6390
0
  }
6391
0
  if (pkcs11_module_path != NULL) {
6392
0
    pkcs11_module_path_copy = os_strdup(pkcs11_module_path);
6393
0
    if (pkcs11_module_path_copy == NULL) {
6394
0
      os_free(pkcs11_engine_path_copy);
6395
0
      return -1;
6396
0
    }
6397
0
  }
6398
6399
0
#ifndef CONFIG_PKCS11_ENGINE_PATH
6400
0
  os_free(wpa_s->conf->pkcs11_engine_path);
6401
0
  wpa_s->conf->pkcs11_engine_path = pkcs11_engine_path_copy;
6402
0
#endif /* CONFIG_PKCS11_ENGINE_PATH */
6403
0
#ifndef CONFIG_PKCS11_MODULE_PATH
6404
0
  os_free(wpa_s->conf->pkcs11_module_path);
6405
0
  wpa_s->conf->pkcs11_module_path = pkcs11_module_path_copy;
6406
0
#endif /* CONFIG_PKCS11_MODULE_PATH */
6407
6408
0
  wpa_sm_set_eapol(wpa_s->wpa, NULL);
6409
0
  eapol_sm_deinit(wpa_s->eapol);
6410
0
  wpa_s->eapol = NULL;
6411
0
  if (wpa_supplicant_init_eapol(wpa_s)) {
6412
    /* Error -> Reset paths to the default value (NULL) once. */
6413
0
    if (pkcs11_engine_path != NULL && pkcs11_module_path != NULL)
6414
0
      wpas_set_pkcs11_engine_and_module_path(wpa_s, NULL,
6415
0
                     NULL);
6416
6417
0
    return -1;
6418
0
  }
6419
0
  wpa_sm_set_eapol(wpa_s->wpa, wpa_s->eapol);
6420
6421
0
  return 0;
6422
0
}
6423
6424
6425
/**
6426
 * wpa_supplicant_set_ap_scan - Set AP scan mode for interface
6427
 * @wpa_s: wpa_supplicant structure for a network interface
6428
 * @ap_scan: AP scan mode
6429
 * Returns: 0 if succeed or -1 if ap_scan has an invalid value
6430
 *
6431
 */
6432
int wpa_supplicant_set_ap_scan(struct wpa_supplicant *wpa_s, int ap_scan)
6433
0
{
6434
6435
0
  int old_ap_scan;
6436
6437
0
  if (ap_scan < 0 || ap_scan > 2)
6438
0
    return -1;
6439
6440
0
  if (ap_scan == 2 && os_strcmp(wpa_s->driver->name, "nl80211") == 0) {
6441
0
    wpa_printf(MSG_INFO,
6442
0
         "Note: nl80211 driver interface is not designed to be used with ap_scan=2; this can result in connection failures");
6443
0
  }
6444
6445
#ifdef ANDROID
6446
  if (ap_scan == 2 && ap_scan != wpa_s->conf->ap_scan &&
6447
      wpa_s->wpa_state >= WPA_ASSOCIATING &&
6448
      wpa_s->wpa_state < WPA_COMPLETED) {
6449
    wpa_printf(MSG_ERROR, "ap_scan = %d (%d) rejected while "
6450
         "associating", wpa_s->conf->ap_scan, ap_scan);
6451
    return 0;
6452
  }
6453
#endif /* ANDROID */
6454
6455
0
  old_ap_scan = wpa_s->conf->ap_scan;
6456
0
  wpa_s->conf->ap_scan = ap_scan;
6457
6458
0
  if (old_ap_scan != wpa_s->conf->ap_scan)
6459
0
    wpas_notify_ap_scan_changed(wpa_s);
6460
6461
0
  return 0;
6462
0
}
6463
6464
6465
/**
6466
 * wpa_supplicant_set_bss_expiration_age - Set BSS entry expiration age
6467
 * @wpa_s: wpa_supplicant structure for a network interface
6468
 * @expire_age: Expiration age in seconds
6469
 * Returns: 0 if succeed or -1 if expire_age has an invalid value
6470
 *
6471
 */
6472
int wpa_supplicant_set_bss_expiration_age(struct wpa_supplicant *wpa_s,
6473
            unsigned int bss_expire_age)
6474
0
{
6475
0
  if (bss_expire_age < 10) {
6476
0
    wpa_msg(wpa_s, MSG_ERROR, "Invalid bss expiration age %u",
6477
0
      bss_expire_age);
6478
0
    return -1;
6479
0
  }
6480
0
  wpa_msg(wpa_s, MSG_DEBUG, "Setting bss expiration age: %d sec",
6481
0
    bss_expire_age);
6482
0
  wpa_s->conf->bss_expiration_age = bss_expire_age;
6483
6484
0
  return 0;
6485
0
}
6486
6487
6488
/**
6489
 * wpa_supplicant_set_bss_expiration_count - Set BSS entry expiration scan count
6490
 * @wpa_s: wpa_supplicant structure for a network interface
6491
 * @expire_count: number of scans after which an unseen BSS is reclaimed
6492
 * Returns: 0 if succeed or -1 if expire_count has an invalid value
6493
 *
6494
 */
6495
int wpa_supplicant_set_bss_expiration_count(struct wpa_supplicant *wpa_s,
6496
              unsigned int bss_expire_count)
6497
0
{
6498
0
  if (bss_expire_count < 1) {
6499
0
    wpa_msg(wpa_s, MSG_ERROR, "Invalid bss expiration count %u",
6500
0
      bss_expire_count);
6501
0
    return -1;
6502
0
  }
6503
0
  wpa_msg(wpa_s, MSG_DEBUG, "Setting bss expiration scan count: %u",
6504
0
    bss_expire_count);
6505
0
  wpa_s->conf->bss_expiration_scan_count = bss_expire_count;
6506
6507
0
  return 0;
6508
0
}
6509
6510
6511
/**
6512
 * wpa_supplicant_set_scan_interval - Set scan interval
6513
 * @wpa_s: wpa_supplicant structure for a network interface
6514
 * @scan_interval: scan interval in seconds
6515
 * Returns: 0 if succeed or -1 if scan_interval has an invalid value
6516
 *
6517
 */
6518
int wpa_supplicant_set_scan_interval(struct wpa_supplicant *wpa_s,
6519
             int scan_interval)
6520
0
{
6521
0
  if (scan_interval < 0) {
6522
0
    wpa_msg(wpa_s, MSG_ERROR, "Invalid scan interval %d",
6523
0
      scan_interval);
6524
0
    return -1;
6525
0
  }
6526
0
  wpa_msg(wpa_s, MSG_DEBUG, "Setting scan interval: %d sec",
6527
0
    scan_interval);
6528
0
  wpa_supplicant_update_scan_int(wpa_s, scan_interval);
6529
6530
0
  return 0;
6531
0
}
6532
6533
6534
/**
6535
 * wpa_supplicant_set_debug_params - Set global debug params
6536
 * @global: wpa_global structure
6537
 * @debug_level: debug level
6538
 * @debug_timestamp: determines if show timestamp in debug data
6539
 * @debug_show_keys: determines if show keys in debug data
6540
 * Returns: 0 if succeed or -1 if debug_level has wrong value
6541
 */
6542
int wpa_supplicant_set_debug_params(struct wpa_global *global, int debug_level,
6543
            int debug_timestamp, int debug_show_keys)
6544
0
{
6545
6546
0
  int old_level, old_timestamp, old_show_keys;
6547
6548
  /* check for allowed debuglevels */
6549
0
  if (debug_level != MSG_EXCESSIVE &&
6550
0
      debug_level != MSG_MSGDUMP &&
6551
0
      debug_level != MSG_DEBUG &&
6552
0
      debug_level != MSG_INFO &&
6553
0
      debug_level != MSG_WARNING &&
6554
0
      debug_level != MSG_ERROR)
6555
0
    return -1;
6556
6557
0
  old_level = wpa_debug_level;
6558
0
  old_timestamp = wpa_debug_timestamp;
6559
0
  old_show_keys = wpa_debug_show_keys;
6560
6561
0
  wpa_debug_level = debug_level;
6562
0
  wpa_debug_timestamp = debug_timestamp ? 1 : 0;
6563
0
  wpa_debug_show_keys = debug_show_keys ? 1 : 0;
6564
6565
0
  if (wpa_debug_level != old_level)
6566
0
    wpas_notify_debug_level_changed(global);
6567
0
  if (wpa_debug_timestamp != old_timestamp)
6568
0
    wpas_notify_debug_timestamp_changed(global);
6569
0
  if (wpa_debug_show_keys != old_show_keys)
6570
0
    wpas_notify_debug_show_keys_changed(global);
6571
6572
0
  return 0;
6573
0
}
6574
6575
6576
#ifdef CONFIG_OWE
6577
static int owe_trans_ssid_match(struct wpa_supplicant *wpa_s, const u8 *bssid,
6578
        const u8 *entry_ssid, size_t entry_ssid_len)
6579
{
6580
  const u8 *owe, *owe_bssid, *owe_ssid;
6581
  size_t owe_ssid_len;
6582
  struct wpa_bss *bss;
6583
6584
  /* Check network profile SSID aganst the SSID in the
6585
   * OWE Transition Mode element. */
6586
6587
  bss = wpa_bss_get_bssid_latest(wpa_s, bssid);
6588
  if (!bss)
6589
    return 0;
6590
6591
  owe = wpa_bss_get_vendor_ie(bss, OWE_IE_VENDOR_TYPE);
6592
  if (!owe)
6593
    return 0;
6594
6595
  if (wpas_get_owe_trans_network(owe, &owe_bssid, &owe_ssid,
6596
               &owe_ssid_len))
6597
    return 0;
6598
6599
  return entry_ssid_len == owe_ssid_len &&
6600
    os_memcmp(owe_ssid, entry_ssid, owe_ssid_len) == 0;
6601
}
6602
#endif /* CONFIG_OWE */
6603
6604
6605
/**
6606
 * wpa_supplicant_get_ssid - Get a pointer to the current network structure
6607
 * @wpa_s: Pointer to wpa_supplicant data
6608
 * Returns: A pointer to the current network structure or %NULL on failure
6609
 */
6610
struct wpa_ssid * wpa_supplicant_get_ssid(struct wpa_supplicant *wpa_s)
6611
0
{
6612
0
  struct wpa_ssid *entry;
6613
0
  u8 ssid[SSID_MAX_LEN];
6614
0
  int res;
6615
0
  size_t ssid_len;
6616
0
  u8 bssid[ETH_ALEN];
6617
0
  int wired;
6618
6619
0
  res = wpa_drv_get_ssid(wpa_s, ssid);
6620
0
  if (res < 0) {
6621
0
    wpa_msg(wpa_s, MSG_WARNING, "Could not read SSID from "
6622
0
      "driver");
6623
0
    return NULL;
6624
0
  }
6625
0
  ssid_len = res;
6626
6627
0
  if (wpa_drv_get_bssid(wpa_s, bssid) < 0) {
6628
0
    wpa_msg(wpa_s, MSG_WARNING, "Could not read BSSID from "
6629
0
      "driver");
6630
0
    return NULL;
6631
0
  }
6632
6633
0
  wired = wpa_s->conf->ap_scan == 0 &&
6634
0
    (wpa_s->drv_flags & WPA_DRIVER_FLAGS_WIRED);
6635
6636
0
  entry = wpa_s->conf->ssid;
6637
0
  while (entry) {
6638
0
    if (!wpas_network_disabled(wpa_s, entry) &&
6639
0
        ((ssid_len == entry->ssid_len &&
6640
0
          (!entry->ssid ||
6641
0
           os_memcmp(ssid, entry->ssid, ssid_len) == 0)) ||
6642
0
         wired) &&
6643
0
        (wpa_s->valid_links || !entry->bssid_set ||
6644
0
         ether_addr_equal(bssid, entry->bssid)))
6645
0
      return entry;
6646
#ifdef CONFIG_WPS
6647
0
    if (!wpas_network_disabled(wpa_s, entry) &&
6648
0
        (entry->key_mgmt & WPA_KEY_MGMT_WPS) &&
6649
0
        (entry->ssid == NULL || entry->ssid_len == 0) &&
6650
0
        (wpa_s->valid_links || !entry->bssid_set ||
6651
0
         ether_addr_equal(bssid, entry->bssid)))
6652
0
      return entry;
6653
0
#endif /* CONFIG_WPS */
6654
6655
#ifdef CONFIG_OWE
6656
    if (!wpas_network_disabled(wpa_s, entry) &&
6657
        (entry->ssid &&
6658
         owe_trans_ssid_match(wpa_s, bssid, entry->ssid,
6659
            entry->ssid_len)) &&
6660
        (wpa_s->valid_links || !entry->bssid_set ||
6661
         ether_addr_equal(bssid, entry->bssid)))
6662
      return entry;
6663
#endif /* CONFIG_OWE */
6664
6665
0
    if (!wpas_network_disabled(wpa_s, entry) && entry->bssid_set &&
6666
0
        entry->ssid_len == 0 &&
6667
0
        ether_addr_equal(bssid, entry->bssid))
6668
0
      return entry;
6669
6670
0
    entry = entry->next;
6671
0
  }
6672
6673
0
  return NULL;
6674
0
}
Unexecuted instantiation: wpa_supplicant_get_ssid
Unexecuted instantiation: wpa_supplicant_get_ssid
6675
6676
6677
static int select_driver(struct wpa_supplicant *wpa_s, int i)
6678
0
{
6679
0
  struct wpa_global *global = wpa_s->global;
6680
6681
0
  if (wpa_drivers[i]->global_init && global->drv_priv[i] == NULL) {
6682
0
    global->drv_priv[i] = wpa_drivers[i]->global_init(global);
6683
0
    if (global->drv_priv[i] == NULL) {
6684
0
      wpa_printf(MSG_ERROR, "Failed to initialize driver "
6685
0
           "'%s'", wpa_drivers[i]->name);
6686
0
      return -1;
6687
0
    }
6688
0
  }
6689
6690
0
  wpa_s->driver = wpa_drivers[i];
6691
0
  wpa_s->global_drv_priv = global->drv_priv[i];
6692
6693
0
  return 0;
6694
0
}
6695
6696
6697
static int wpa_supplicant_set_driver(struct wpa_supplicant *wpa_s,
6698
             const char *name)
6699
0
{
6700
0
  int i;
6701
0
  size_t len;
6702
0
  const char *pos, *driver = name;
6703
6704
0
  if (wpa_s == NULL)
6705
0
    return -1;
6706
6707
0
  if (wpa_drivers[0] == NULL) {
6708
0
    wpa_msg(wpa_s, MSG_ERROR, "No driver interfaces build into "
6709
0
      "wpa_supplicant");
6710
0
    return -1;
6711
0
  }
6712
6713
0
  if (name == NULL) {
6714
    /* Default to first successful driver in the list */
6715
0
    for (i = 0; wpa_drivers[i]; i++) {
6716
0
      if (select_driver(wpa_s, i) == 0)
6717
0
        return 0;
6718
0
    }
6719
    /* Drivers have each reported failure, so no wpa_msg() here. */
6720
0
    return -1;
6721
0
  }
6722
6723
0
  do {
6724
0
    pos = os_strchr(driver, ',');
6725
0
    if (pos)
6726
0
      len = pos - driver;
6727
0
    else
6728
0
      len = os_strlen(driver);
6729
6730
0
    for (i = 0; wpa_drivers[i]; i++) {
6731
0
      if (os_strlen(wpa_drivers[i]->name) == len &&
6732
0
          os_strncmp(driver, wpa_drivers[i]->name, len) ==
6733
0
          0) {
6734
        /* First driver that succeeds wins */
6735
0
        if (select_driver(wpa_s, i) == 0)
6736
0
          return 0;
6737
0
      }
6738
0
    }
6739
6740
0
    driver = pos + 1;
6741
0
  } while (pos);
6742
6743
0
  wpa_msg(wpa_s, MSG_ERROR, "Unsupported driver '%s'", name);
6744
0
  return -1;
6745
0
}
6746
6747
6748
/**
6749
 * wpa_supplicant_rx_eapol - Deliver a received EAPOL frame to wpa_supplicant
6750
 * @ctx: Context pointer (wpa_s); this is the ctx variable registered
6751
 *  with struct wpa_driver_ops::init()
6752
 * @src_addr: Source address of the EAPOL frame
6753
 * @buf: EAPOL data starting from the EAPOL header (i.e., no Ethernet header)
6754
 * @len: Length of the EAPOL data
6755
 * @encrypted: Whether the frame was encrypted
6756
 *
6757
 * This function is called for each received EAPOL frame. Most driver
6758
 * interfaces rely on more generic OS mechanism for receiving frames through
6759
 * l2_packet, but if such a mechanism is not available, the driver wrapper may
6760
 * take care of received EAPOL frames and deliver them to the core supplicant
6761
 * code by calling this function.
6762
 */
6763
void wpa_supplicant_rx_eapol(void *ctx, const u8 *src_addr,
6764
           const u8 *buf, size_t len,
6765
           enum frame_encryption encrypted)
6766
0
{
6767
0
  struct wpa_supplicant *wpa_s = ctx;
6768
0
  const u8 *connected_addr = wpa_s->valid_links ?
6769
0
    wpa_s->ap_mld_addr : wpa_s->bssid;
6770
6771
0
  wpa_dbg(wpa_s, MSG_DEBUG, "RX EAPOL from " MACSTR " (encrypted=%d)",
6772
0
    MAC2STR(src_addr), encrypted);
6773
0
  wpa_hexdump(MSG_MSGDUMP, "RX EAPOL", buf, len);
6774
6775
0
  if (wpa_s->own_disconnect_req) {
6776
0
    wpa_printf(MSG_DEBUG,
6777
0
         "Drop received EAPOL frame as we are disconnecting");
6778
0
    return;
6779
0
  }
6780
6781
#ifdef CONFIG_TESTING_OPTIONS
6782
  wpa_msg_ctrl(wpa_s, MSG_INFO, "EAPOL-RX " MACSTR " %zu",
6783
         MAC2STR(src_addr), len);
6784
  if (wpa_s->ignore_auth_resp) {
6785
    wpa_printf(MSG_INFO, "RX EAPOL - ignore_auth_resp active!");
6786
    return;
6787
  }
6788
#endif /* CONFIG_TESTING_OPTIONS */
6789
6790
0
  if (wpa_s->wpa_state < WPA_ASSOCIATED ||
6791
0
      wpa_s->ext_auth_to_same_bss ||
6792
0
      (wpa_s->last_eapol_matches_bssid &&
6793
#ifdef CONFIG_AP
6794
       !wpa_s->ap_iface &&
6795
#endif /* CONFIG_AP */
6796
0
       !ether_addr_equal(src_addr, connected_addr))) {
6797
    /*
6798
     * There is possible race condition between receiving the
6799
     * association event and the EAPOL frame since they are coming
6800
     * through different paths from the driver. In order to avoid
6801
     * issues in trying to process the EAPOL frame before receiving
6802
     * association information, lets queue it for processing until
6803
     * the association event is received. This may also be needed in
6804
     * driver-based roaming case, so also use src_addr != BSSID as a
6805
     * trigger if we have previously confirmed that the
6806
     * Authenticator uses BSSID as the src_addr (which is not the
6807
     * case with wired IEEE 802.1X).
6808
     */
6809
0
    wpa_dbg(wpa_s, MSG_DEBUG,
6810
0
      "Not associated - Delay processing of received EAPOL frame (state=%s connected_addr="
6811
0
      MACSTR ")",
6812
0
      wpa_supplicant_state_txt(wpa_s->wpa_state),
6813
0
      MAC2STR(connected_addr));
6814
0
  delay_processing:
6815
0
    wpabuf_free(wpa_s->pending_eapol_rx);
6816
0
    wpa_s->pending_eapol_rx = wpabuf_alloc_copy(buf, len);
6817
0
    if (wpa_s->pending_eapol_rx) {
6818
0
      os_get_reltime(&wpa_s->pending_eapol_rx_time);
6819
0
      os_memcpy(wpa_s->pending_eapol_rx_src, src_addr,
6820
0
          ETH_ALEN);
6821
0
      wpa_s->pending_eapol_encrypted = encrypted;
6822
0
    }
6823
0
    return;
6824
0
  }
6825
6826
0
  wpa_s->last_eapol_matches_bssid =
6827
0
    ether_addr_equal(src_addr, connected_addr);
6828
6829
#ifdef CONFIG_AP
6830
  if (wpa_s->ap_iface) {
6831
    wpa_supplicant_ap_rx_eapol(wpa_s, src_addr, buf, len,
6832
             encrypted);
6833
    return;
6834
  }
6835
#endif /* CONFIG_AP */
6836
6837
0
  if (wpa_s->key_mgmt == WPA_KEY_MGMT_NONE) {
6838
0
    wpa_dbg(wpa_s, MSG_DEBUG, "Ignored received EAPOL frame since "
6839
0
      "no key management is configured");
6840
0
    return;
6841
0
  }
6842
6843
0
  if (wpa_s->eapol_received == 0 &&
6844
0
      (!(wpa_s->drv_flags & WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_PSK) ||
6845
0
       !wpa_key_mgmt_wpa_psk(wpa_s->key_mgmt) ||
6846
0
       wpa_s->wpa_state != WPA_COMPLETED) &&
6847
0
      (wpa_s->current_ssid == NULL ||
6848
0
       wpa_s->current_ssid->mode != WPAS_MODE_IBSS)) {
6849
    /* Timeout for completing IEEE 802.1X and WPA authentication */
6850
0
    int timeout = 10;
6851
6852
0
    if (wpa_key_mgmt_wpa_ieee8021x(wpa_s->key_mgmt) ||
6853
0
        wpa_s->key_mgmt == WPA_KEY_MGMT_IEEE8021X_NO_WPA ||
6854
0
        wpa_s->key_mgmt == WPA_KEY_MGMT_WPS) {
6855
      /* Use longer timeout for IEEE 802.1X/EAP */
6856
0
      timeout = 70;
6857
0
    }
6858
6859
#ifdef CONFIG_WPS
6860
0
    if (wpa_s->current_ssid && wpa_s->current_bss &&
6861
0
        (wpa_s->current_ssid->key_mgmt & WPA_KEY_MGMT_WPS) &&
6862
0
        eap_is_wps_pin_enrollee(&wpa_s->current_ssid->eap)) {
6863
      /*
6864
       * Use shorter timeout if going through WPS AP iteration
6865
       * for PIN config method with an AP that does not
6866
       * advertise Selected Registrar.
6867
       */
6868
0
      struct wpabuf *wps_ie;
6869
6870
0
      wps_ie = wpa_bss_get_vendor_ie_multi(
6871
0
        wpa_s->current_bss, WPS_IE_VENDOR_TYPE);
6872
0
      if (wps_ie &&
6873
0
          !wps_is_addr_authorized(wps_ie, wpa_s->own_addr, 1))
6874
0
        timeout = 10;
6875
0
      wpabuf_free(wps_ie);
6876
0
    }
6877
#endif /* CONFIG_WPS */
6878
6879
0
    wpa_supplicant_req_auth_timeout(wpa_s, timeout, 0);
6880
0
  }
6881
0
  wpa_s->eapol_received++;
6882
6883
0
  if (wpa_s->countermeasures) {
6884
0
    wpa_msg(wpa_s, MSG_INFO, "WPA: Countermeasures - dropped "
6885
0
      "EAPOL packet");
6886
0
    return;
6887
0
  }
6888
6889
#ifdef CONFIG_IBSS_RSN
6890
  if (wpa_s->current_ssid &&
6891
      wpa_s->current_ssid->mode == WPAS_MODE_IBSS) {
6892
    ibss_rsn_rx_eapol(wpa_s->ibss_rsn, src_addr, buf, len,
6893
          encrypted);
6894
    return;
6895
  }
6896
#endif /* CONFIG_IBSS_RSN */
6897
6898
  /* Source address of the incoming EAPOL frame could be compared to the
6899
   * current BSSID. However, it is possible that a centralized
6900
   * Authenticator could be using another MAC address than the BSSID of
6901
   * an AP, so just allow any address to be used for now. The replies are
6902
   * still sent to the current BSSID (if available), though. */
6903
6904
0
  os_memcpy(wpa_s->last_eapol_src, src_addr, ETH_ALEN);
6905
0
  if (!wpa_key_mgmt_wpa_psk(wpa_s->key_mgmt) &&
6906
0
      wpa_s->key_mgmt != WPA_KEY_MGMT_OWE &&
6907
0
      wpa_s->key_mgmt != WPA_KEY_MGMT_DPP &&
6908
0
      eapol_sm_rx_eapol(wpa_s->eapol, src_addr, buf, len,
6909
0
            encrypted) > 0)
6910
0
    return;
6911
0
  wpa_drv_poll(wpa_s);
6912
0
  if (!(wpa_s->drv_flags & WPA_DRIVER_FLAGS_4WAY_HANDSHAKE_PSK)) {
6913
0
    if (wpa_sm_rx_eapol(wpa_s->wpa, src_addr, buf, len,
6914
0
            encrypted) == -2 &&
6915
#ifdef CONFIG_AP
6916
        !wpa_s->ap_iface &&
6917
#endif /* CONFIG_AP */
6918
0
        wpa_s->last_eapol_matches_bssid) {
6919
      /* Handle the case where reassociation occurs to the
6920
       * current connected AP */
6921
0
      wpa_dbg(wpa_s, MSG_DEBUG,
6922
0
        "Delay processing of received EAPOL frame for reassociation to the current connected AP (state=%s connected_addr="
6923
0
        MACSTR ")",
6924
0
        wpa_supplicant_state_txt(wpa_s->wpa_state),
6925
0
        MAC2STR(connected_addr));
6926
0
      goto delay_processing;
6927
0
    }
6928
0
  } else if (wpa_key_mgmt_wpa_ieee8021x(wpa_s->key_mgmt)) {
6929
    /*
6930
     * Set portValid = true here since we are going to skip 4-way
6931
     * handshake processing which would normally set portValid. We
6932
     * need this to allow the EAPOL state machines to be completed
6933
     * without going through EAPOL-Key handshake.
6934
     */
6935
0
    eapol_sm_notify_portValid(wpa_s->eapol, true);
6936
0
  }
6937
0
}
Unexecuted instantiation: wpa_supplicant_rx_eapol
Unexecuted instantiation: wpa_supplicant_rx_eapol
6938
6939
6940
static void wpa_supplicant_rx_eapol_cb(void *ctx, const u8 *src_addr,
6941
               const u8 *buf, size_t len)
6942
0
{
6943
0
  wpa_supplicant_rx_eapol(ctx, src_addr, buf, len,
6944
0
        FRAME_ENCRYPTION_UNKNOWN);
6945
0
}
6946
6947
6948
static int wpas_eapol_needs_l2_packet(struct wpa_supplicant *wpa_s)
6949
0
{
6950
0
  return !(wpa_s->drv_flags & WPA_DRIVER_FLAGS_CONTROL_PORT) ||
6951
0
    !(wpa_s->drv_flags2 & WPA_DRIVER_FLAGS2_CONTROL_PORT_RX);
6952
0
}
6953
6954
6955
int wpa_supplicant_update_mac_addr(struct wpa_supplicant *wpa_s)
6956
0
{
6957
0
  u8 prev_mac_addr[ETH_ALEN];
6958
6959
0
  os_memcpy(prev_mac_addr, wpa_s->own_addr, ETH_ALEN);
6960
6961
0
  if ((!wpa_s->p2p_mgmt ||
6962
0
       !(wpa_s->drv_flags & WPA_DRIVER_FLAGS_DEDICATED_P2P_DEVICE)) &&
6963
0
      !(wpa_s->drv_flags & WPA_DRIVER_FLAGS_P2P_DEDICATED_INTERFACE) &&
6964
0
      !wpa_s->nan_mgmt) {
6965
0
    l2_packet_deinit(wpa_s->l2);
6966
0
    wpa_s->l2 = l2_packet_init(wpa_s->ifname,
6967
0
             wpa_drv_get_mac_addr(wpa_s),
6968
0
             ETH_P_EAPOL,
6969
0
             wpas_eapol_needs_l2_packet(wpa_s) ?
6970
0
             wpa_supplicant_rx_eapol_cb : NULL,
6971
0
             wpa_s, 0);
6972
0
    if (wpa_s->l2 == NULL)
6973
0
      return -1;
6974
6975
0
    if (l2_packet_set_packet_filter(wpa_s->l2,
6976
0
            L2_PACKET_FILTER_PKTTYPE))
6977
0
      wpa_dbg(wpa_s, MSG_DEBUG,
6978
0
        "Failed to attach pkt_type filter");
6979
6980
0
    if (l2_packet_get_own_addr(wpa_s->l2, wpa_s->own_addr)) {
6981
0
      wpa_msg(wpa_s, MSG_ERROR,
6982
0
        "Failed to get own L2 address");
6983
0
      return -1;
6984
0
    }
6985
0
  } else {
6986
0
    const u8 *addr = wpa_drv_get_mac_addr(wpa_s);
6987
0
    if (addr)
6988
0
      os_memcpy(wpa_s->own_addr, addr, ETH_ALEN);
6989
0
  }
6990
6991
0
  wpa_sm_set_own_addr(wpa_s->wpa, wpa_s->own_addr);
6992
0
  wpas_wps_update_mac_addr(wpa_s);
6993
6994
#ifdef CONFIG_NAN_USD
6995
  if (wpa_s->nan_de)
6996
    nan_de_update_nmi(wpa_s->nan_de, wpa_s->own_addr);
6997
#endif /* CONFIG_NAN_USD */
6998
6999
#ifdef CONFIG_FST
7000
  if (wpa_s->fst)
7001
    fst_update_mac_addr(wpa_s->fst, wpa_s->own_addr);
7002
#endif /* CONFIG_FST */
7003
7004
0
  if (!ether_addr_equal(prev_mac_addr, wpa_s->own_addr))
7005
0
    wpas_notify_mac_address_changed(wpa_s);
7006
7007
0
  return 0;
7008
0
}
7009
7010
7011
static void wpa_supplicant_rx_eapol_bridge(void *ctx, const u8 *src_addr,
7012
             const u8 *buf, size_t len)
7013
0
{
7014
0
  struct wpa_supplicant *wpa_s = ctx;
7015
0
  const struct l2_ethhdr *eth;
7016
7017
0
  if (len < sizeof(*eth))
7018
0
    return;
7019
0
  eth = (const struct l2_ethhdr *) buf;
7020
7021
0
  if (!ether_addr_equal(eth->h_dest, wpa_s->own_addr) &&
7022
0
      !(eth->h_dest[0] & 0x01)) {
7023
0
    wpa_dbg(wpa_s, MSG_DEBUG, "RX EAPOL from " MACSTR " to " MACSTR
7024
0
      " (bridge - not for this interface - ignore)",
7025
0
      MAC2STR(src_addr), MAC2STR(eth->h_dest));
7026
0
    return;
7027
0
  }
7028
7029
0
  wpa_dbg(wpa_s, MSG_DEBUG, "RX EAPOL from " MACSTR " to " MACSTR
7030
0
    " (bridge)", MAC2STR(src_addr), MAC2STR(eth->h_dest));
7031
0
  wpa_supplicant_rx_eapol(wpa_s, src_addr, buf + sizeof(*eth),
7032
0
        len - sizeof(*eth), FRAME_ENCRYPTION_UNKNOWN);
7033
0
}
7034
7035
7036
int wpa_supplicant_update_bridge_ifname(struct wpa_supplicant *wpa_s,
7037
          const char *bridge_ifname)
7038
0
{
7039
0
  if (wpa_s->wpa_state > WPA_SCANNING)
7040
0
    return -EBUSY;
7041
7042
0
  if (bridge_ifname &&
7043
0
      os_strlen(bridge_ifname) >= sizeof(wpa_s->bridge_ifname))
7044
0
    return -EINVAL;
7045
7046
0
  if (!bridge_ifname)
7047
0
    bridge_ifname = "";
7048
7049
0
  if (os_strcmp(wpa_s->bridge_ifname, bridge_ifname) == 0)
7050
0
    return 0;
7051
7052
0
  if (wpa_s->l2_br) {
7053
0
    l2_packet_deinit(wpa_s->l2_br);
7054
0
    wpa_s->l2_br = NULL;
7055
0
  }
7056
7057
0
  os_strlcpy(wpa_s->bridge_ifname, bridge_ifname,
7058
0
       sizeof(wpa_s->bridge_ifname));
7059
7060
0
  if (wpa_s->bridge_ifname[0]) {
7061
0
    wpa_dbg(wpa_s, MSG_DEBUG,
7062
0
      "Receiving packets from bridge interface '%s'",
7063
0
      wpa_s->bridge_ifname);
7064
0
    wpa_s->l2_br = l2_packet_init_bridge(
7065
0
      wpa_s->bridge_ifname, wpa_s->ifname, wpa_s->own_addr,
7066
0
      ETH_P_EAPOL, wpa_supplicant_rx_eapol_bridge, wpa_s, 1);
7067
0
    if (!wpa_s->l2_br) {
7068
0
      wpa_msg(wpa_s, MSG_ERROR,
7069
0
        "Failed to open l2_packet connection for the bridge interface '%s'",
7070
0
        wpa_s->bridge_ifname);
7071
0
      goto fail;
7072
0
    }
7073
0
  }
7074
7075
#ifdef CONFIG_TDLS
7076
  if (!wpa_s->p2p_mgmt && wpa_tdls_init(wpa_s->wpa))
7077
    goto fail;
7078
#endif /* CONFIG_TDLS */
7079
7080
0
  return 0;
7081
0
fail:
7082
0
  wpa_s->bridge_ifname[0] = 0;
7083
0
  if (wpa_s->l2_br) {
7084
0
    l2_packet_deinit(wpa_s->l2_br);
7085
0
    wpa_s->l2_br = NULL;
7086
0
  }
7087
#ifdef CONFIG_TDLS
7088
  if (!wpa_s->p2p_mgmt)
7089
    wpa_tdls_init(wpa_s->wpa);
7090
#endif /* CONFIG_TDLS */
7091
0
  return -EIO;
7092
0
}
7093
7094
7095
/**
7096
 * wpa_supplicant_driver_init - Initialize driver interface parameters
7097
 * @wpa_s: Pointer to wpa_supplicant data
7098
 * Returns: 0 on success, -1 on failure
7099
 *
7100
 * This function is called to initialize driver interface parameters.
7101
 * wpa_drv_init() must have been called before this function to initialize the
7102
 * driver interface.
7103
 */
7104
int wpa_supplicant_driver_init(struct wpa_supplicant *wpa_s)
7105
0
{
7106
0
  static int interface_count = 0;
7107
7108
0
  if (wpa_supplicant_update_mac_addr(wpa_s) < 0)
7109
0
    return -1;
7110
7111
0
  wpa_dbg(wpa_s, MSG_DEBUG, "Own MAC address: " MACSTR,
7112
0
    MAC2STR(wpa_s->own_addr));
7113
0
  os_memcpy(wpa_s->perm_addr, wpa_s->own_addr, ETH_ALEN);
7114
0
  wpa_sm_set_own_addr(wpa_s->wpa, wpa_s->own_addr);
7115
7116
0
  if (wpa_s->bridge_ifname[0] && wpas_eapol_needs_l2_packet(wpa_s)) {
7117
0
    wpa_dbg(wpa_s, MSG_DEBUG, "Receiving packets from bridge "
7118
0
      "interface '%s'", wpa_s->bridge_ifname);
7119
0
    wpa_s->l2_br = l2_packet_init_bridge(
7120
0
      wpa_s->bridge_ifname, wpa_s->ifname, wpa_s->own_addr,
7121
0
      ETH_P_EAPOL, wpa_supplicant_rx_eapol_bridge, wpa_s, 1);
7122
0
    if (wpa_s->l2_br == NULL) {
7123
0
      wpa_msg(wpa_s, MSG_ERROR, "Failed to open l2_packet "
7124
0
        "connection for the bridge interface '%s'",
7125
0
        wpa_s->bridge_ifname);
7126
0
      return -1;
7127
0
    }
7128
0
  }
7129
7130
0
  if (wpa_s->conf->ap_scan == 2 &&
7131
0
      os_strcmp(wpa_s->driver->name, "nl80211") == 0) {
7132
0
    wpa_printf(MSG_INFO,
7133
0
         "Note: nl80211 driver interface is not designed to be used with ap_scan=2; this can result in connection failures");
7134
0
  }
7135
7136
0
  wpa_clear_keys(wpa_s, NULL);
7137
7138
  /* Make sure that TKIP countermeasures are not left enabled (could
7139
   * happen if wpa_supplicant is killed during countermeasures. */
7140
0
  wpa_drv_set_countermeasures(wpa_s, 0);
7141
7142
0
  wpa_dbg(wpa_s, MSG_DEBUG, "RSN: flushing PMKID list in the driver");
7143
0
  wpa_drv_flush_pmkid(wpa_s);
7144
7145
0
  wpa_s->prev_scan_ssid = WILDCARD_SSID_SCAN;
7146
0
  wpa_s->prev_scan_wildcard = 0;
7147
7148
0
  if (wpa_supplicant_enabled_networks(wpa_s)) {
7149
0
    if (wpa_s->wpa_state == WPA_INTERFACE_DISABLED) {
7150
0
      wpa_supplicant_set_state(wpa_s, WPA_DISCONNECTED);
7151
0
      interface_count = 0;
7152
0
    }
7153
0
#ifndef ANDROID
7154
0
    if (!wpa_s->p2p_mgmt &&
7155
0
        wpa_supplicant_delayed_sched_scan(wpa_s,
7156
0
                  interface_count % 3,
7157
0
                  100000))
7158
0
      wpa_supplicant_req_scan(wpa_s, interface_count % 3,
7159
0
            100000);
7160
0
#endif /* ANDROID */
7161
0
    interface_count++;
7162
0
  } else
7163
0
    wpa_supplicant_set_state(wpa_s, WPA_INACTIVE);
7164
7165
0
  return 0;
7166
0
}
7167
7168
7169
static int wpa_supplicant_daemon(const char *pid_file)
7170
0
{
7171
0
  wpa_printf(MSG_DEBUG, "Daemonize..");
7172
0
  return os_daemonize(pid_file);
7173
0
}
7174
7175
7176
static struct wpa_supplicant *
7177
wpa_supplicant_alloc(struct wpa_supplicant *parent)
7178
0
{
7179
0
  struct wpa_supplicant *wpa_s;
7180
7181
0
  wpa_s = os_zalloc(sizeof(*wpa_s));
7182
0
  if (wpa_s == NULL)
7183
0
    return NULL;
7184
0
  wpa_s->scan_req = INITIAL_SCAN_REQ;
7185
0
  wpa_s->scan_interval = 5;
7186
0
  wpa_s->new_connection = 1;
7187
0
  wpa_s->parent = parent ? parent : wpa_s;
7188
0
  wpa_s->p2pdev = wpa_s->parent;
7189
#ifdef CONFIG_P2P
7190
  if (parent)
7191
    wpa_s->p2p_mode = parent->p2p_mode;
7192
#endif /* CONFIG_P2P */
7193
0
  wpa_s->sched_scanning = 0;
7194
0
  wpa_s->setband_mask = WPA_SETBAND_AUTO;
7195
7196
0
  dl_list_init(&wpa_s->bss_tmp_disallowed);
7197
0
  dl_list_init(&wpa_s->fils_hlp_req);
7198
#ifdef CONFIG_TESTING_OPTIONS
7199
  dl_list_init(&wpa_s->drv_signal_override);
7200
  wpa_s->test_assoc_comeback_type = -1;
7201
#endif /* CONFIG_TESTING_OPTIONS */
7202
0
#ifndef CONFIG_NO_ROBUST_AV
7203
0
  dl_list_init(&wpa_s->active_scs_ids);
7204
0
#endif /* CONFIG_NO_ROBUST_AV */
7205
0
  wpa_s->ml_probe_mld_id = -1;
7206
7207
#ifdef CONFIG_PMKSA_CACHE_EXTERNAL
7208
#ifdef CONFIG_MESH
7209
  dl_list_init(&wpa_s->mesh_external_pmksa_cache);
7210
#endif /* CONFIG_MESH */
7211
#endif /* CONFIG_PMKSA_CACHE_EXTERNAL */
7212
7213
0
  return wpa_s;
7214
0
}
7215
7216
7217
#ifdef CONFIG_HT_OVERRIDES
7218
7219
static int wpa_set_htcap_mcs(struct wpa_supplicant *wpa_s,
7220
           struct ieee80211_ht_capabilities *htcaps,
7221
           struct ieee80211_ht_capabilities *htcaps_mask,
7222
           const char *ht_mcs)
7223
{
7224
  /* parse ht_mcs into hex array */
7225
  int i;
7226
  const char *tmp = ht_mcs;
7227
  char *end = NULL;
7228
7229
  /* If ht_mcs is null, do not set anything */
7230
  if (!ht_mcs)
7231
    return 0;
7232
7233
  /* This is what we are setting in the kernel */
7234
  os_memset(&htcaps->supported_mcs_set, 0, IEEE80211_HT_MCS_MASK_LEN);
7235
7236
  wpa_msg(wpa_s, MSG_DEBUG, "set_htcap, ht_mcs -:%s:-", ht_mcs);
7237
7238
  for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++) {
7239
    long v;
7240
7241
    errno = 0;
7242
    v = strtol(tmp, &end, 16);
7243
7244
    if (errno == 0) {
7245
      wpa_msg(wpa_s, MSG_DEBUG,
7246
        "htcap value[%i]: %ld end: %p  tmp: %p",
7247
        i, v, end, tmp);
7248
      if (end == tmp)
7249
        break;
7250
7251
      htcaps->supported_mcs_set[i] = v;
7252
      tmp = end;
7253
    } else {
7254
      wpa_msg(wpa_s, MSG_ERROR,
7255
        "Failed to parse ht-mcs: %s, error: %s\n",
7256
        ht_mcs, strerror(errno));
7257
      return -1;
7258
    }
7259
  }
7260
7261
  /*
7262
   * If we were able to parse any values, then set mask for the MCS set.
7263
   */
7264
  if (i) {
7265
    os_memset(&htcaps_mask->supported_mcs_set, 0xff,
7266
        IEEE80211_HT_MCS_MASK_LEN - 1);
7267
    /* skip the 3 reserved bits */
7268
    htcaps_mask->supported_mcs_set[IEEE80211_HT_MCS_MASK_LEN - 1] =
7269
      0x1f;
7270
  }
7271
7272
  return 0;
7273
}
7274
7275
7276
static int wpa_disable_max_amsdu(struct wpa_supplicant *wpa_s,
7277
         struct ieee80211_ht_capabilities *htcaps,
7278
         struct ieee80211_ht_capabilities *htcaps_mask,
7279
         int disabled)
7280
{
7281
  le16 msk;
7282
7283
  if (disabled == -1)
7284
    return 0;
7285
7286
  wpa_msg(wpa_s, MSG_DEBUG, "set_disable_max_amsdu: %d", disabled);
7287
7288
  msk = host_to_le16(HT_CAP_INFO_MAX_AMSDU_SIZE);
7289
  htcaps_mask->ht_capabilities_info |= msk;
7290
  if (disabled)
7291
    htcaps->ht_capabilities_info &= msk;
7292
  else
7293
    htcaps->ht_capabilities_info |= msk;
7294
7295
  return 0;
7296
}
7297
7298
7299
static int wpa_set_ampdu_factor(struct wpa_supplicant *wpa_s,
7300
        struct ieee80211_ht_capabilities *htcaps,
7301
        struct ieee80211_ht_capabilities *htcaps_mask,
7302
        int factor)
7303
{
7304
  if (factor == -1)
7305
    return 0;
7306
7307
  wpa_msg(wpa_s, MSG_DEBUG, "set_ampdu_factor: %d", factor);
7308
7309
  if (factor < 0 || factor > 3) {
7310
    wpa_msg(wpa_s, MSG_ERROR, "ampdu_factor: %d out of range. "
7311
      "Must be 0-3 or -1", factor);
7312
    return -EINVAL;
7313
  }
7314
7315
  htcaps_mask->a_mpdu_params |= 0x3; /* 2 bits for factor */
7316
  htcaps->a_mpdu_params &= ~0x3;
7317
  htcaps->a_mpdu_params |= factor & 0x3;
7318
7319
  return 0;
7320
}
7321
7322
7323
static int wpa_set_ampdu_density(struct wpa_supplicant *wpa_s,
7324
         struct ieee80211_ht_capabilities *htcaps,
7325
         struct ieee80211_ht_capabilities *htcaps_mask,
7326
         int density)
7327
{
7328
  if (density == -1)
7329
    return 0;
7330
7331
  wpa_msg(wpa_s, MSG_DEBUG, "set_ampdu_density: %d", density);
7332
7333
  if (density < 0 || density > 7) {
7334
    wpa_msg(wpa_s, MSG_ERROR,
7335
      "ampdu_density: %d out of range. Must be 0-7 or -1.",
7336
      density);
7337
    return -EINVAL;
7338
  }
7339
7340
  htcaps_mask->a_mpdu_params |= 0x1C;
7341
  htcaps->a_mpdu_params &= ~(0x1C);
7342
  htcaps->a_mpdu_params |= (density << 2) & 0x1C;
7343
7344
  return 0;
7345
}
7346
7347
7348
static int wpa_set_disable_ht40(struct wpa_supplicant *wpa_s,
7349
        struct ieee80211_ht_capabilities *htcaps,
7350
        struct ieee80211_ht_capabilities *htcaps_mask,
7351
        int disabled)
7352
{
7353
  if (disabled)
7354
    wpa_msg(wpa_s, MSG_DEBUG, "set_disable_ht40: %d", disabled);
7355
7356
  set_disable_ht40(htcaps, disabled);
7357
  set_disable_ht40(htcaps_mask, 0);
7358
7359
  return 0;
7360
}
7361
7362
7363
static int wpa_set_disable_sgi(struct wpa_supplicant *wpa_s,
7364
             struct ieee80211_ht_capabilities *htcaps,
7365
             struct ieee80211_ht_capabilities *htcaps_mask,
7366
             int disabled)
7367
{
7368
  /* Masking these out disables SGI */
7369
  le16 msk = host_to_le16(HT_CAP_INFO_SHORT_GI20MHZ |
7370
        HT_CAP_INFO_SHORT_GI40MHZ);
7371
7372
  if (disabled)
7373
    wpa_msg(wpa_s, MSG_DEBUG, "set_disable_sgi: %d", disabled);
7374
7375
  if (disabled)
7376
    htcaps->ht_capabilities_info &= ~msk;
7377
  else
7378
    htcaps->ht_capabilities_info |= msk;
7379
7380
  htcaps_mask->ht_capabilities_info |= msk;
7381
7382
  return 0;
7383
}
7384
7385
7386
static int wpa_set_disable_ldpc(struct wpa_supplicant *wpa_s,
7387
             struct ieee80211_ht_capabilities *htcaps,
7388
             struct ieee80211_ht_capabilities *htcaps_mask,
7389
             int disabled)
7390
{
7391
  /* Masking these out disables LDPC */
7392
  le16 msk = host_to_le16(HT_CAP_INFO_LDPC_CODING_CAP);
7393
7394
  if (disabled)
7395
    wpa_msg(wpa_s, MSG_DEBUG, "set_disable_ldpc: %d", disabled);
7396
7397
  if (disabled)
7398
    htcaps->ht_capabilities_info &= ~msk;
7399
  else
7400
    htcaps->ht_capabilities_info |= msk;
7401
7402
  htcaps_mask->ht_capabilities_info |= msk;
7403
7404
  return 0;
7405
}
7406
7407
7408
static int wpa_set_tx_stbc(struct wpa_supplicant *wpa_s,
7409
         struct ieee80211_ht_capabilities *htcaps,
7410
         struct ieee80211_ht_capabilities *htcaps_mask,
7411
         int tx_stbc)
7412
{
7413
  le16 msk = host_to_le16(HT_CAP_INFO_TX_STBC);
7414
7415
  if (tx_stbc == -1)
7416
    return 0;
7417
7418
  wpa_msg(wpa_s, MSG_DEBUG, "set_tx_stbc: %d", tx_stbc);
7419
7420
  if (tx_stbc < 0 || tx_stbc > 1) {
7421
    wpa_msg(wpa_s, MSG_ERROR,
7422
      "tx_stbc: %d out of range. Must be 0-1 or -1", tx_stbc);
7423
    return -EINVAL;
7424
  }
7425
7426
  htcaps_mask->ht_capabilities_info |= msk;
7427
  htcaps->ht_capabilities_info &= ~msk;
7428
  htcaps->ht_capabilities_info |= host_to_le16(tx_stbc << 7) & msk;
7429
7430
  return 0;
7431
}
7432
7433
7434
static int wpa_set_rx_stbc(struct wpa_supplicant *wpa_s,
7435
         struct ieee80211_ht_capabilities *htcaps,
7436
         struct ieee80211_ht_capabilities *htcaps_mask,
7437
         int rx_stbc)
7438
{
7439
  le16 msk = host_to_le16(HT_CAP_INFO_RX_STBC_MASK);
7440
7441
  if (rx_stbc == -1)
7442
    return 0;
7443
7444
  wpa_msg(wpa_s, MSG_DEBUG, "set_rx_stbc: %d", rx_stbc);
7445
7446
  if (rx_stbc < 0 || rx_stbc > 3) {
7447
    wpa_msg(wpa_s, MSG_ERROR,
7448
      "rx_stbc: %d out of range. Must be 0-3 or -1", rx_stbc);
7449
    return -EINVAL;
7450
  }
7451
7452
  htcaps_mask->ht_capabilities_info |= msk;
7453
  htcaps->ht_capabilities_info &= ~msk;
7454
  htcaps->ht_capabilities_info |= host_to_le16(rx_stbc << 8) & msk;
7455
7456
  return 0;
7457
}
7458
7459
7460
void wpa_supplicant_apply_ht_overrides(
7461
  struct wpa_supplicant *wpa_s, struct wpa_ssid *ssid,
7462
  struct wpa_driver_associate_params *params)
7463
{
7464
  struct ieee80211_ht_capabilities *htcaps;
7465
  struct ieee80211_ht_capabilities *htcaps_mask;
7466
7467
  if (!ssid)
7468
    return;
7469
7470
  params->disable_ht = ssid->disable_ht;
7471
  if (!params->htcaps || !params->htcaps_mask)
7472
    return;
7473
7474
  htcaps = (struct ieee80211_ht_capabilities *) params->htcaps;
7475
  htcaps_mask = (struct ieee80211_ht_capabilities *) params->htcaps_mask;
7476
  wpa_set_htcap_mcs(wpa_s, htcaps, htcaps_mask, ssid->ht_mcs);
7477
  wpa_disable_max_amsdu(wpa_s, htcaps, htcaps_mask,
7478
            ssid->disable_max_amsdu);
7479
  wpa_set_ampdu_factor(wpa_s, htcaps, htcaps_mask, ssid->ampdu_factor);
7480
  wpa_set_ampdu_density(wpa_s, htcaps, htcaps_mask, ssid->ampdu_density);
7481
  wpa_set_disable_ht40(wpa_s, htcaps, htcaps_mask, ssid->disable_ht40);
7482
  wpa_set_disable_sgi(wpa_s, htcaps, htcaps_mask, ssid->disable_sgi);
7483
  wpa_set_disable_ldpc(wpa_s, htcaps, htcaps_mask, ssid->disable_ldpc);
7484
  wpa_set_rx_stbc(wpa_s, htcaps, htcaps_mask, ssid->rx_stbc);
7485
  wpa_set_tx_stbc(wpa_s, htcaps, htcaps_mask, ssid->tx_stbc);
7486
7487
  if (ssid->ht40_intolerant) {
7488
    le16 bit = host_to_le16(HT_CAP_INFO_40MHZ_INTOLERANT);
7489
    htcaps->ht_capabilities_info |= bit;
7490
    htcaps_mask->ht_capabilities_info |= bit;
7491
  }
7492
}
7493
7494
#endif /* CONFIG_HT_OVERRIDES */
7495
7496
7497
#ifdef CONFIG_VHT_OVERRIDES
7498
void wpa_supplicant_apply_vht_overrides(
7499
  struct wpa_supplicant *wpa_s, struct wpa_ssid *ssid,
7500
  struct wpa_driver_associate_params *params)
7501
{
7502
  struct ieee80211_vht_capabilities *vhtcaps;
7503
  struct ieee80211_vht_capabilities *vhtcaps_mask;
7504
7505
  if (!ssid)
7506
    return;
7507
7508
  params->disable_vht = ssid->disable_vht;
7509
7510
  vhtcaps = (void *) params->vhtcaps;
7511
  vhtcaps_mask = (void *) params->vhtcaps_mask;
7512
7513
  if (!vhtcaps || !vhtcaps_mask)
7514
    return;
7515
7516
  vhtcaps->vht_capabilities_info = host_to_le32(ssid->vht_capa);
7517
  vhtcaps_mask->vht_capabilities_info = host_to_le32(ssid->vht_capa_mask);
7518
7519
#ifdef CONFIG_HT_OVERRIDES
7520
  if (ssid->disable_sgi) {
7521
    vhtcaps_mask->vht_capabilities_info |=
7522
      host_to_le32(VHT_CAP_SHORT_GI_80 |
7523
             VHT_CAP_SHORT_GI_160);
7524
    vhtcaps->vht_capabilities_info &=
7525
      host_to_le32(~(VHT_CAP_SHORT_GI_80 |
7526
               VHT_CAP_SHORT_GI_160));
7527
    wpa_msg(wpa_s, MSG_DEBUG,
7528
      "disable-sgi override specified, vht-caps: 0x%x",
7529
      le_to_host32(vhtcaps->vht_capabilities_info));
7530
  }
7531
7532
  /* if max ampdu is <= 3, we have to make the HT cap the same */
7533
  if (ssid->vht_capa_mask & VHT_CAP_MAX_A_MPDU_LENGTH_EXPONENT_MAX) {
7534
    int max_ampdu;
7535
7536
    max_ampdu = (ssid->vht_capa &
7537
           VHT_CAP_MAX_A_MPDU_LENGTH_EXPONENT_MAX) >>
7538
      VHT_CAP_MAX_A_MPDU_LENGTH_EXPONENT_MAX_SHIFT;
7539
7540
    max_ampdu = max_ampdu < 3 ? max_ampdu : 3;
7541
    wpa_set_ampdu_factor(wpa_s,
7542
             (void *) params->htcaps,
7543
             (void *) params->htcaps_mask,
7544
             max_ampdu);
7545
  }
7546
#endif /* CONFIG_HT_OVERRIDES */
7547
7548
#define OVERRIDE_MCS(i)             \
7549
  if (ssid->vht_tx_mcs_nss_ ##i >= 0) {       \
7550
    vhtcaps_mask->vht_supported_mcs_set.tx_map |=   \
7551
      host_to_le16(3 << 2 * (i - 1));     \
7552
    vhtcaps->vht_supported_mcs_set.tx_map |=    \
7553
      host_to_le16(ssid->vht_tx_mcs_nss_ ##i << \
7554
             2 * (i - 1));      \
7555
  }               \
7556
  if (ssid->vht_rx_mcs_nss_ ##i >= 0) {       \
7557
    vhtcaps_mask->vht_supported_mcs_set.rx_map |=   \
7558
      host_to_le16(3 << 2 * (i - 1));     \
7559
    vhtcaps->vht_supported_mcs_set.rx_map |=    \
7560
      host_to_le16(ssid->vht_rx_mcs_nss_ ##i << \
7561
             2 * (i - 1));      \
7562
  }
7563
7564
  OVERRIDE_MCS(1);
7565
  OVERRIDE_MCS(2);
7566
  OVERRIDE_MCS(3);
7567
  OVERRIDE_MCS(4);
7568
  OVERRIDE_MCS(5);
7569
  OVERRIDE_MCS(6);
7570
  OVERRIDE_MCS(7);
7571
  OVERRIDE_MCS(8);
7572
}
7573
#endif /* CONFIG_VHT_OVERRIDES */
7574
7575
7576
#ifdef CONFIG_HE_OVERRIDES
7577
void wpa_supplicant_apply_he_overrides(
7578
  struct wpa_supplicant *wpa_s, struct wpa_ssid *ssid,
7579
  struct wpa_driver_associate_params *params)
7580
{
7581
  if (!ssid)
7582
    return;
7583
7584
  params->disable_he = ssid->disable_he;
7585
}
7586
#endif /* CONFIG_HE_OVERRIDES */
7587
7588
7589
void wpa_supplicant_apply_eht_overrides(
7590
  struct wpa_supplicant *wpa_s, struct wpa_ssid *ssid,
7591
  struct wpa_driver_associate_params *params)
7592
0
{
7593
0
  if (!ssid)
7594
0
    return;
7595
7596
0
  params->disable_eht = ssid->disable_eht;
7597
0
}
7598
7599
7600
void wpa_supplicant_apply_uhr_overrides(
7601
  struct wpa_supplicant *wpa_s, struct wpa_ssid *ssid,
7602
  struct wpa_driver_associate_params *params)
7603
0
{
7604
0
  if (!ssid)
7605
0
    return;
7606
7607
0
  params->disable_uhr = ssid->disable_uhr;
7608
0
}
7609
7610
7611
static int pcsc_reader_init(struct wpa_supplicant *wpa_s)
7612
0
{
7613
#ifdef PCSC_FUNCS
7614
  size_t len;
7615
7616
  if (!wpa_s->conf->pcsc_reader)
7617
    return 0;
7618
7619
  wpa_s->scard = scard_init(wpa_s->conf->pcsc_reader);
7620
  if (!wpa_s->scard)
7621
    return 1;
7622
7623
  if (wpa_s->conf->pcsc_pin &&
7624
      scard_set_pin(wpa_s->scard, wpa_s->conf->pcsc_pin) < 0) {
7625
    scard_deinit(wpa_s->scard);
7626
    wpa_s->scard = NULL;
7627
    wpa_msg(wpa_s, MSG_ERROR, "PC/SC PIN validation failed");
7628
    return -1;
7629
  }
7630
7631
  len = sizeof(wpa_s->imsi) - 1;
7632
  if (scard_get_imsi(wpa_s->scard, wpa_s->imsi, &len)) {
7633
    scard_deinit(wpa_s->scard);
7634
    wpa_s->scard = NULL;
7635
    wpa_msg(wpa_s, MSG_ERROR, "Could not read IMSI");
7636
    return -1;
7637
  }
7638
  wpa_s->imsi[len] = '\0';
7639
7640
  wpa_s->mnc_len = scard_get_mnc_len(wpa_s->scard);
7641
7642
  wpa_printf(MSG_DEBUG, "SCARD: IMSI %s (MNC length %d)",
7643
       wpa_s->imsi, wpa_s->mnc_len);
7644
7645
  wpa_sm_set_scard_ctx(wpa_s->wpa, wpa_s->scard);
7646
  eapol_sm_register_scard_ctx(wpa_s->eapol, wpa_s->scard);
7647
#endif /* PCSC_FUNCS */
7648
7649
0
  return 0;
7650
0
}
7651
7652
7653
int wpas_init_ext_pw(struct wpa_supplicant *wpa_s)
7654
0
{
7655
0
  char *val, *pos;
7656
7657
0
  ext_password_deinit(wpa_s->ext_pw);
7658
0
  wpa_s->ext_pw = NULL;
7659
0
  eapol_sm_set_ext_pw_ctx(wpa_s->eapol, NULL);
7660
7661
0
  if (!wpa_s->conf->ext_password_backend)
7662
0
    return 0;
7663
7664
0
  val = os_strdup(wpa_s->conf->ext_password_backend);
7665
0
  if (val == NULL)
7666
0
    return -1;
7667
0
  pos = os_strchr(val, ':');
7668
0
  if (pos)
7669
0
    *pos++ = '\0';
7670
7671
0
  wpa_printf(MSG_DEBUG, "EXT PW: Initialize backend '%s'", val);
7672
7673
0
  wpa_s->ext_pw = ext_password_init(val, pos);
7674
0
  os_free(val);
7675
0
  if (wpa_s->ext_pw == NULL) {
7676
0
    wpa_printf(MSG_DEBUG, "EXT PW: Failed to initialize backend");
7677
0
    return -1;
7678
0
  }
7679
0
  eapol_sm_set_ext_pw_ctx(wpa_s->eapol, wpa_s->ext_pw);
7680
7681
0
  return 0;
7682
0
}
7683
7684
7685
#ifdef CONFIG_FST
7686
7687
static const u8 * wpas_fst_get_bssid_cb(void *ctx)
7688
{
7689
  struct wpa_supplicant *wpa_s = ctx;
7690
7691
  return (is_zero_ether_addr(wpa_s->bssid) ||
7692
    wpa_s->wpa_state != WPA_COMPLETED) ? NULL : wpa_s->bssid;
7693
}
7694
7695
7696
static void wpas_fst_get_channel_info_cb(void *ctx,
7697
           enum hostapd_hw_mode *hw_mode,
7698
           u8 *channel)
7699
{
7700
  struct wpa_supplicant *wpa_s = ctx;
7701
7702
  if (wpa_s->current_bss) {
7703
    *hw_mode = ieee80211_freq_to_chan(wpa_s->current_bss->freq,
7704
              channel);
7705
  } else if (wpa_s->hw.num_modes) {
7706
    *hw_mode = wpa_s->hw.modes[0].mode;
7707
  } else {
7708
    WPA_ASSERT(0);
7709
    *hw_mode = 0;
7710
  }
7711
}
7712
7713
7714
static int wpas_fst_get_hw_modes(void *ctx, struct hostapd_hw_modes **modes)
7715
{
7716
  struct wpa_supplicant *wpa_s = ctx;
7717
7718
  *modes = wpa_s->hw.modes;
7719
  return wpa_s->hw.num_modes;
7720
}
7721
7722
7723
static void wpas_fst_set_ies_cb(void *ctx, const struct wpabuf *fst_ies)
7724
{
7725
  struct wpa_supplicant *wpa_s = ctx;
7726
7727
  wpa_hexdump_buf(MSG_DEBUG, "FST: Set IEs", fst_ies);
7728
  wpa_s->fst_ies = fst_ies;
7729
}
7730
7731
7732
static int wpas_fst_send_action_cb(void *ctx, const u8 *da, struct wpabuf *data)
7733
{
7734
  struct wpa_supplicant *wpa_s = ctx;
7735
7736
  if (!ether_addr_equal(wpa_s->bssid, da)) {
7737
    wpa_printf(MSG_INFO, "FST:%s:bssid=" MACSTR " != da=" MACSTR,
7738
         __func__, MAC2STR(wpa_s->bssid), MAC2STR(da));
7739
    return -1;
7740
  }
7741
  return wpa_drv_send_action(wpa_s, wpa_s->assoc_freq, 0, wpa_s->bssid,
7742
           wpa_s->own_addr, wpa_s->bssid,
7743
           wpabuf_head(data), wpabuf_len(data),
7744
           0);
7745
}
7746
7747
7748
static const struct wpabuf * wpas_fst_get_mb_ie_cb(void *ctx, const u8 *addr)
7749
{
7750
  struct wpa_supplicant *wpa_s = ctx;
7751
7752
  WPA_ASSERT(ether_addr_equal(wpa_s->bssid, addr));
7753
  return wpa_s->received_mb_ies;
7754
}
7755
7756
7757
static void wpas_fst_update_mb_ie_cb(void *ctx, const u8 *addr,
7758
             const u8 *buf, size_t size)
7759
{
7760
  struct wpa_supplicant *wpa_s = ctx;
7761
  struct mb_ies_info info;
7762
7763
  WPA_ASSERT(ether_addr_equal(wpa_s->bssid, addr));
7764
7765
  if (!mb_ies_info_by_ies(&info, buf, size)) {
7766
    wpabuf_free(wpa_s->received_mb_ies);
7767
    wpa_s->received_mb_ies = mb_ies_by_info(&info);
7768
  }
7769
}
7770
7771
7772
static const u8 * wpas_fst_get_peer_first(void *ctx,
7773
            struct fst_get_peer_ctx **get_ctx,
7774
            bool mb_only)
7775
{
7776
  struct wpa_supplicant *wpa_s = ctx;
7777
7778
  *get_ctx = NULL;
7779
  if (!is_zero_ether_addr(wpa_s->bssid))
7780
    return (wpa_s->received_mb_ies || !mb_only) ?
7781
      wpa_s->bssid : NULL;
7782
  return NULL;
7783
}
7784
7785
7786
static const u8 * wpas_fst_get_peer_next(void *ctx,
7787
           struct fst_get_peer_ctx **get_ctx,
7788
           bool mb_only)
7789
{
7790
  return NULL;
7791
}
7792
7793
void fst_wpa_supplicant_fill_iface_obj(struct wpa_supplicant *wpa_s,
7794
               struct fst_wpa_obj *iface_obj)
7795
{
7796
  os_memset(iface_obj, 0, sizeof(*iface_obj));
7797
  iface_obj->ctx              = wpa_s;
7798
  iface_obj->get_bssid        = wpas_fst_get_bssid_cb;
7799
  iface_obj->get_channel_info = wpas_fst_get_channel_info_cb;
7800
  iface_obj->get_hw_modes     = wpas_fst_get_hw_modes;
7801
  iface_obj->set_ies          = wpas_fst_set_ies_cb;
7802
  iface_obj->send_action      = wpas_fst_send_action_cb;
7803
  iface_obj->get_mb_ie        = wpas_fst_get_mb_ie_cb;
7804
  iface_obj->update_mb_ie     = wpas_fst_update_mb_ie_cb;
7805
  iface_obj->get_peer_first   = wpas_fst_get_peer_first;
7806
  iface_obj->get_peer_next    = wpas_fst_get_peer_next;
7807
}
7808
#endif /* CONFIG_FST */
7809
7810
static int wpas_set_wowlan_triggers(struct wpa_supplicant *wpa_s,
7811
            const struct wpa_driver_capa *capa)
7812
0
{
7813
0
  struct wowlan_triggers *triggers;
7814
0
  int ret = 0;
7815
7816
0
  if (!wpa_s->conf->wowlan_triggers)
7817
0
    return 0;
7818
7819
0
  triggers = wpa_get_wowlan_triggers(wpa_s->conf->wowlan_triggers, capa);
7820
0
  if (triggers) {
7821
0
    ret = wpa_drv_wowlan(wpa_s, triggers);
7822
0
    os_free(triggers);
7823
0
  }
7824
0
  return ret;
7825
0
}
7826
7827
7828
enum wpa_radio_work_band wpas_freq_to_band(int freq)
7829
0
{
7830
0
  if (freq < 3000)
7831
0
    return BAND_2_4_GHZ;
7832
0
  if (freq > 50000)
7833
0
    return BAND_60_GHZ;
7834
0
  return BAND_5_GHZ;
7835
0
}
7836
7837
7838
unsigned int wpas_get_bands(struct wpa_supplicant *wpa_s, const int *freqs)
7839
0
{
7840
0
  int i;
7841
0
  unsigned int band = 0;
7842
7843
0
  if (freqs) {
7844
    /* freqs are specified for the radio work */
7845
0
    for (i = 0; freqs[i]; i++)
7846
0
      band |= wpas_freq_to_band(freqs[i]);
7847
0
  } else {
7848
    /*
7849
     * freqs are not specified, implies all
7850
     * the supported freqs by HW
7851
     */
7852
0
    for (i = 0; i < wpa_s->hw.num_modes; i++) {
7853
0
      if (wpa_s->hw.modes[i].num_channels != 0) {
7854
0
        if (wpa_s->hw.modes[i].mode ==
7855
0
            HOSTAPD_MODE_IEEE80211B ||
7856
0
            wpa_s->hw.modes[i].mode ==
7857
0
            HOSTAPD_MODE_IEEE80211G)
7858
0
          band |= BAND_2_4_GHZ;
7859
0
        else if (wpa_s->hw.modes[i].mode ==
7860
0
           HOSTAPD_MODE_IEEE80211A)
7861
0
          band |= BAND_5_GHZ;
7862
0
        else if (wpa_s->hw.modes[i].mode ==
7863
0
           HOSTAPD_MODE_IEEE80211AD)
7864
0
          band |= BAND_60_GHZ;
7865
0
        else if (wpa_s->hw.modes[i].mode ==
7866
0
           HOSTAPD_MODE_IEEE80211ANY)
7867
0
          band = BAND_2_4_GHZ | BAND_5_GHZ |
7868
0
            BAND_60_GHZ;
7869
0
      }
7870
0
    }
7871
0
  }
7872
7873
0
  return band;
7874
0
}
7875
7876
7877
static struct wpa_radio * radio_add_interface(struct wpa_supplicant *wpa_s,
7878
                const char *rn)
7879
0
{
7880
0
  struct wpa_supplicant *iface = wpa_s->global->ifaces;
7881
0
  struct wpa_radio *radio;
7882
7883
0
  while (rn && iface) {
7884
0
    radio = iface->radio;
7885
0
    if (radio && os_strcmp(rn, radio->name) == 0) {
7886
0
      wpa_printf(MSG_DEBUG, "Add interface %s to existing radio %s",
7887
0
           wpa_s->ifname, rn);
7888
0
      dl_list_add(&radio->ifaces, &wpa_s->radio_list);
7889
0
      return radio;
7890
0
    }
7891
7892
0
    iface = iface->next;
7893
0
  }
7894
7895
0
  wpa_printf(MSG_DEBUG, "Add interface %s to a new radio %s",
7896
0
       wpa_s->ifname, rn ? rn : "N/A");
7897
0
  radio = os_zalloc(sizeof(*radio));
7898
0
  if (radio == NULL)
7899
0
    return NULL;
7900
7901
0
  if (rn)
7902
0
    os_strlcpy(radio->name, rn, sizeof(radio->name));
7903
0
  dl_list_init(&radio->ifaces);
7904
0
  dl_list_init(&radio->work);
7905
0
  dl_list_add(&radio->ifaces, &wpa_s->radio_list);
7906
7907
0
  return radio;
7908
0
}
7909
7910
7911
static void radio_work_free(struct wpa_radio_work *work)
7912
0
{
7913
0
  if (work->wpa_s->scan_work == work) {
7914
    /* This should not really happen. */
7915
0
    wpa_dbg(work->wpa_s, MSG_INFO, "Freeing radio work '%s'@%p (started=%d) that is marked as scan_work",
7916
0
      work->type, work, work->started);
7917
0
    work->wpa_s->scan_work = NULL;
7918
0
  }
7919
7920
#ifdef CONFIG_P2P
7921
  if (work->wpa_s->p2p_scan_work == work) {
7922
    /* This should not really happen. */
7923
    wpa_dbg(work->wpa_s, MSG_INFO, "Freeing radio work '%s'@%p (started=%d) that is marked as p2p_scan_work",
7924
      work->type, work, work->started);
7925
    work->wpa_s->p2p_scan_work = NULL;
7926
  }
7927
#endif /* CONFIG_P2P */
7928
7929
0
  if (work->started) {
7930
0
    work->wpa_s->radio->num_active_works--;
7931
0
    wpa_dbg(work->wpa_s, MSG_DEBUG,
7932
0
      "radio_work_free('%s'@%p): num_active_works --> %u",
7933
0
      work->type, work,
7934
0
      work->wpa_s->radio->num_active_works);
7935
0
  }
7936
7937
0
  os_free(work);
7938
0
}
7939
7940
7941
static int radio_work_is_connect(struct wpa_radio_work *work)
7942
0
{
7943
0
  return os_strcmp(work->type, "sme-connect") == 0 ||
7944
0
    os_strcmp(work->type, "connect") == 0;
7945
0
}
7946
7947
7948
static int radio_work_is_scan(struct wpa_radio_work *work)
7949
0
{
7950
0
  return os_strcmp(work->type, "scan") == 0 ||
7951
0
    os_strcmp(work->type, "p2p-scan") == 0;
7952
0
}
7953
7954
7955
static struct wpa_radio_work * radio_work_get_next_work(struct wpa_radio *radio)
7956
0
{
7957
0
  struct wpa_radio_work *active_work = NULL;
7958
0
  struct wpa_radio_work *tmp;
7959
7960
  /* Get the active work to know the type and band. */
7961
0
  dl_list_for_each(tmp, &radio->work, struct wpa_radio_work, list) {
7962
0
    if (tmp->started) {
7963
0
      active_work = tmp;
7964
0
      break;
7965
0
    }
7966
0
  }
7967
7968
0
  if (!active_work) {
7969
    /* No active work, start one */
7970
0
    radio->num_active_works = 0;
7971
0
    dl_list_for_each(tmp, &radio->work, struct wpa_radio_work,
7972
0
         list) {
7973
0
      if (os_strcmp(tmp->type, "scan") == 0 &&
7974
0
          external_scan_running(radio) &&
7975
0
          (((struct wpa_driver_scan_params *)
7976
0
            tmp->ctx)->only_new_results ||
7977
0
           tmp->wpa_s->clear_driver_scan_cache))
7978
0
        continue;
7979
0
      return tmp;
7980
0
    }
7981
0
    return NULL;
7982
0
  }
7983
7984
0
  if (radio_work_is_connect(active_work)) {
7985
    /*
7986
     * If the active work is either connect or sme-connect,
7987
     * do not parallelize them with other radio works.
7988
     */
7989
0
    wpa_dbg(active_work->wpa_s, MSG_DEBUG,
7990
0
      "Do not parallelize radio work with %s",
7991
0
      active_work->type);
7992
0
    return NULL;
7993
0
  }
7994
7995
0
  dl_list_for_each(tmp, &radio->work, struct wpa_radio_work, list) {
7996
0
    if (tmp->started)
7997
0
      continue;
7998
7999
    /*
8000
     * If connect or sme-connect are enqueued, parallelize only
8001
     * those operations ahead of them in the queue.
8002
     */
8003
0
    if (radio_work_is_connect(tmp))
8004
0
      break;
8005
8006
    /* Serialize parallel scan and p2p_scan operations on the same
8007
     * interface since the driver_nl80211 mechanism for tracking
8008
     * scan cookies does not yet have support for this. */
8009
0
    if (active_work->wpa_s == tmp->wpa_s &&
8010
0
        radio_work_is_scan(active_work) &&
8011
0
        radio_work_is_scan(tmp)) {
8012
0
      wpa_dbg(active_work->wpa_s, MSG_DEBUG,
8013
0
        "Do not start work '%s' when another work '%s' is already scheduled",
8014
0
        tmp->type, active_work->type);
8015
0
      continue;
8016
0
    }
8017
    /*
8018
     * Check that the radio works are distinct and
8019
     * on different bands.
8020
     */
8021
0
    if (os_strcmp(active_work->type, tmp->type) != 0 &&
8022
0
        (active_work->bands != tmp->bands)) {
8023
      /*
8024
       * If a scan has to be scheduled through nl80211 scan
8025
       * interface and if an external scan is already running,
8026
       * do not schedule the scan since it is likely to get
8027
       * rejected by kernel.
8028
       */
8029
0
      if (os_strcmp(tmp->type, "scan") == 0 &&
8030
0
          external_scan_running(radio) &&
8031
0
          (((struct wpa_driver_scan_params *)
8032
0
            tmp->ctx)->only_new_results ||
8033
0
           tmp->wpa_s->clear_driver_scan_cache))
8034
0
        continue;
8035
8036
0
      wpa_dbg(active_work->wpa_s, MSG_DEBUG,
8037
0
        "active_work:%s new_work:%s",
8038
0
        active_work->type, tmp->type);
8039
0
      return tmp;
8040
0
    }
8041
0
  }
8042
8043
  /* Did not find a radio work to schedule in parallel. */
8044
0
  return NULL;
8045
0
}
8046
8047
8048
static void radio_start_next_work(void *eloop_ctx, void *timeout_ctx)
8049
0
{
8050
0
  struct wpa_radio *radio = eloop_ctx;
8051
0
  struct wpa_radio_work *work;
8052
0
  struct os_reltime now, diff;
8053
0
  struct wpa_supplicant *wpa_s;
8054
8055
0
  work = dl_list_first(&radio->work, struct wpa_radio_work, list);
8056
0
  if (work == NULL) {
8057
0
    radio->num_active_works = 0;
8058
0
    return;
8059
0
  }
8060
8061
0
  wpa_s = dl_list_first(&radio->ifaces, struct wpa_supplicant,
8062
0
            radio_list);
8063
8064
0
  if (!(wpa_s &&
8065
0
        wpa_s->drv_flags & WPA_DRIVER_FLAGS_OFFCHANNEL_SIMULTANEOUS)) {
8066
0
    if (work->started)
8067
0
      return; /* already started and still in progress */
8068
8069
0
    if (wpa_s && external_scan_running(wpa_s->radio)) {
8070
0
      wpa_printf(MSG_DEBUG, "Delay radio work start until externally triggered scan completes");
8071
0
      return;
8072
0
    }
8073
0
  } else {
8074
0
    work = NULL;
8075
0
    if (radio->num_active_works < MAX_ACTIVE_WORKS) {
8076
      /* get the work to schedule next */
8077
0
      work = radio_work_get_next_work(radio);
8078
0
    }
8079
0
    if (!work)
8080
0
      return;
8081
0
  }
8082
8083
0
  wpa_s = work->wpa_s;
8084
0
  os_get_reltime(&now);
8085
0
  os_reltime_sub(&now, &work->time, &diff);
8086
0
  wpa_dbg(wpa_s, MSG_DEBUG,
8087
0
    "Starting radio work '%s'@%p after %ld.%06ld second wait",
8088
0
    work->type, work, diff.sec, diff.usec);
8089
0
  work->started = 1;
8090
0
  work->time = now;
8091
0
  radio->num_active_works++;
8092
8093
0
  work->cb(work, 0);
8094
8095
0
  if ((wpa_s->drv_flags & WPA_DRIVER_FLAGS_OFFCHANNEL_SIMULTANEOUS) &&
8096
0
      radio->num_active_works < MAX_ACTIVE_WORKS)
8097
0
    radio_work_check_next(wpa_s);
8098
0
}
8099
8100
8101
/*
8102
 * This function removes both started and pending radio works running on
8103
 * the provided interface's radio.
8104
 * Prior to the removal of the radio work, its callback (cb) is called with
8105
 * deinit set to be 1. Each work's callback is responsible for clearing its
8106
 * internal data and restoring to a correct state.
8107
 * @wpa_s: wpa_supplicant data
8108
 * @type: type of works to be removed
8109
 * @remove_all: 1 to remove all the works on this radio, 0 to remove only
8110
 * this interface's works.
8111
 */
8112
void radio_remove_works(struct wpa_supplicant *wpa_s,
8113
      const char *type, int remove_all)
8114
0
{
8115
0
  struct wpa_radio_work *work, *tmp;
8116
0
  struct wpa_radio *radio = wpa_s->radio;
8117
8118
0
  dl_list_for_each_safe(work, tmp, &radio->work, struct wpa_radio_work,
8119
0
            list) {
8120
0
    if (type && os_strcmp(type, work->type) != 0)
8121
0
      continue;
8122
8123
    /* skip other ifaces' works */
8124
0
    if (!remove_all && work->wpa_s != wpa_s)
8125
0
      continue;
8126
8127
0
    wpa_dbg(wpa_s, MSG_DEBUG, "Remove radio work '%s'@%p%s",
8128
0
      work->type, work, work->started ? " (started)" : "");
8129
0
    dl_list_del(&work->list);
8130
0
    work->cb(work, 1);
8131
0
    radio_work_free(work);
8132
0
  }
8133
8134
  /* in case we removed the started work */
8135
0
  radio_work_check_next(wpa_s);
8136
0
}
8137
8138
8139
static void radio_remove_pending_connect(struct wpa_supplicant *wpa_s,
8140
           const struct wpa_ssid *ssid)
8141
0
{
8142
0
  struct wpa_radio_work *work, *tmp;
8143
0
  struct wpa_radio *radio = wpa_s->radio;
8144
0
  struct wpa_connect_work *cwork;
8145
8146
0
  dl_list_for_each_safe(work, tmp, &radio->work, struct wpa_radio_work,
8147
0
            list) {
8148
0
    if (!radio_work_is_connect(work))
8149
0
      continue;
8150
8151
0
    cwork = work->ctx;
8152
0
    if (cwork->ssid != ssid)
8153
0
      continue;
8154
8155
0
    wpa_printf(MSG_DEBUG, "Remove radio work '%s'@%p ssid=%s",
8156
0
         work->type, work,
8157
0
         wpa_ssid_txt(ssid->ssid, ssid->ssid_len));
8158
0
    dl_list_del(&work->list);
8159
0
    work->cb(work, 1);
8160
0
    radio_work_free(work);
8161
0
  }
8162
0
}
8163
8164
8165
static void radio_remove_interface(struct wpa_supplicant *wpa_s)
8166
0
{
8167
0
  struct wpa_radio *radio = wpa_s->radio;
8168
8169
0
  if (!radio)
8170
0
    return;
8171
8172
0
  wpa_printf(MSG_DEBUG, "Remove interface %s from radio %s",
8173
0
       wpa_s->ifname, radio->name);
8174
0
  dl_list_del(&wpa_s->radio_list);
8175
0
  radio_remove_works(wpa_s, NULL, 0);
8176
  /* If the interface that triggered the external scan was removed, the
8177
   * external scan is no longer running. */
8178
0
  if (wpa_s == radio->external_scan_req_interface)
8179
0
    radio->external_scan_req_interface = NULL;
8180
0
  wpa_s->radio = NULL;
8181
0
  if (!dl_list_empty(&radio->ifaces))
8182
0
    return; /* Interfaces remain for this radio */
8183
8184
0
  wpa_printf(MSG_DEBUG, "Remove radio %s", radio->name);
8185
0
  eloop_cancel_timeout(radio_start_next_work, radio, NULL);
8186
0
  os_free(radio);
8187
0
}
8188
8189
8190
void radio_work_check_next(struct wpa_supplicant *wpa_s)
8191
0
{
8192
0
  struct wpa_radio *radio = wpa_s->radio;
8193
8194
0
  if (dl_list_empty(&radio->work))
8195
0
    return;
8196
0
  if (wpa_s->ext_work_in_progress) {
8197
0
    wpa_printf(MSG_DEBUG,
8198
0
         "External radio work in progress - delay start of pending item");
8199
0
    return;
8200
0
  }
8201
0
  eloop_cancel_timeout(radio_start_next_work, radio, NULL);
8202
0
  eloop_register_timeout(0, 0, radio_start_next_work, radio, NULL);
8203
0
}
8204
8205
8206
/**
8207
 * radio_add_work - Add a radio work item
8208
 * @wpa_s: Pointer to wpa_supplicant data
8209
 * @freq: Frequency of the offchannel operation in MHz or 0
8210
 * @type: Unique identifier for each type of work
8211
 * @next: Force as the next work to be executed
8212
 * @cb: Callback function for indicating when radio is available
8213
 * @ctx: Context pointer for the work (work->ctx in cb())
8214
 * Returns: Pointer to the newly created work, or %NULL on failure
8215
 *
8216
 * This function is used to request time for an operation that requires
8217
 * exclusive radio control. Once the radio is available, the registered callback
8218
 * function will be called. radio_work_done() must be called once the exclusive
8219
 * radio operation has been completed, so that the radio is freed for other
8220
 * operations. The special case of deinit=1 is used to free the context data
8221
 * during interface removal. That does not allow the callback function to start
8222
 * the radio operation, i.e., it must free any resources allocated for the radio
8223
 * work and return.
8224
 *
8225
 * The @freq parameter can be used to indicate a single channel on which the
8226
 * offchannel operation will occur. This may allow multiple radio work
8227
 * operations to be performed in parallel if they apply for the same channel.
8228
 * Setting this to 0 indicates that the work item may use multiple channels or
8229
 * requires exclusive control of the radio.
8230
 */
8231
struct wpa_radio_work *
8232
radio_add_work(struct wpa_supplicant *wpa_s, unsigned int freq,
8233
         const char *type, int next,
8234
         void (*cb)(struct wpa_radio_work *work, int deinit),
8235
         void *ctx)
8236
0
{
8237
0
  struct wpa_radio *radio = wpa_s->radio;
8238
0
  struct wpa_radio_work *work;
8239
0
  int was_empty;
8240
8241
0
  work = os_zalloc(sizeof(*work));
8242
0
  if (work == NULL)
8243
0
    return NULL;
8244
0
  wpa_dbg(wpa_s, MSG_DEBUG, "Add radio work '%s'@%p", type, work);
8245
0
  os_get_reltime(&work->time);
8246
0
  work->freq = freq;
8247
0
  work->type = type;
8248
0
  work->wpa_s = wpa_s;
8249
0
  work->cb = cb;
8250
0
  work->ctx = ctx;
8251
8252
0
  if (freq)
8253
0
    work->bands = wpas_freq_to_band(freq);
8254
0
  else if (os_strcmp(type, "scan") == 0 ||
8255
0
     os_strcmp(type, "p2p-scan") == 0)
8256
0
    work->bands = wpas_get_bands(wpa_s,
8257
0
               ((struct wpa_driver_scan_params *)
8258
0
                ctx)->freqs);
8259
0
  else
8260
0
    work->bands = wpas_get_bands(wpa_s, NULL);
8261
8262
0
  was_empty = dl_list_empty(&wpa_s->radio->work);
8263
0
  if (next)
8264
0
    dl_list_add(&wpa_s->radio->work, &work->list);
8265
0
  else
8266
0
    dl_list_add_tail(&wpa_s->radio->work, &work->list);
8267
0
  if (was_empty) {
8268
0
    wpa_dbg(wpa_s, MSG_DEBUG, "First radio work item in the queue - schedule start immediately");
8269
0
    radio_work_check_next(wpa_s);
8270
0
  } else if ((wpa_s->drv_flags & WPA_DRIVER_FLAGS_OFFCHANNEL_SIMULTANEOUS)
8271
0
       && radio->num_active_works < MAX_ACTIVE_WORKS) {
8272
0
    wpa_dbg(wpa_s, MSG_DEBUG,
8273
0
      "Try to schedule a radio work (num_active_works=%u)",
8274
0
      radio->num_active_works);
8275
0
    radio_work_check_next(wpa_s);
8276
0
  }
8277
8278
0
  return work;
8279
0
}
8280
8281
8282
/**
8283
 * radio_work_done - Indicate that a radio work item has been completed
8284
 * @work: Completed work
8285
 *
8286
 * This function is called once the callback function registered with
8287
 * radio_add_work() has completed its work.
8288
 */
8289
void radio_work_done(struct wpa_radio_work *work)
8290
0
{
8291
0
  struct wpa_supplicant *wpa_s = work->wpa_s;
8292
0
  struct os_reltime now, diff;
8293
0
  unsigned int started = work->started;
8294
8295
  /* If next is poisoned, then we are free'ing it already */
8296
0
  if (work->list.next == NULL)
8297
0
    return;
8298
8299
0
  os_get_reltime(&now);
8300
0
  os_reltime_sub(&now, &work->time, &diff);
8301
0
  wpa_dbg(wpa_s, MSG_DEBUG, "Radio work '%s'@%p %s in %ld.%06ld seconds",
8302
0
    work->type, work, started ? "done" : "canceled",
8303
0
    diff.sec, diff.usec);
8304
0
  dl_list_del(&work->list);
8305
0
  radio_work_free(work);
8306
0
  if (started)
8307
0
    radio_work_check_next(wpa_s);
8308
0
}
8309
8310
8311
struct wpa_radio_work *
8312
radio_work_pending(struct wpa_supplicant *wpa_s, const char *type)
8313
5.99k
{
8314
5.99k
  struct wpa_radio_work *work;
8315
5.99k
  struct wpa_radio *radio = wpa_s->radio;
8316
8317
5.99k
  if (!radio)
8318
5.99k
    return NULL;
8319
8320
0
  dl_list_for_each(work, &radio->work, struct wpa_radio_work, list) {
8321
0
    if (work->wpa_s == wpa_s && os_strcmp(work->type, type) == 0)
8322
0
      return work;
8323
0
  }
8324
8325
0
  return NULL;
8326
0
}
8327
8328
8329
static int wpas_init_driver(struct wpa_supplicant *wpa_s,
8330
          const struct wpa_interface *iface)
8331
0
{
8332
0
  const char *ifname, *driver, *rn;
8333
8334
0
  driver = iface->driver;
8335
0
next_driver:
8336
0
  if (wpa_supplicant_set_driver(wpa_s, driver) < 0)
8337
0
    return -1;
8338
8339
0
  wpa_s->drv_priv = wpa_drv_init(wpa_s, wpa_s->ifname);
8340
0
  if (wpa_s->drv_priv == NULL) {
8341
0
    const char *pos;
8342
0
    int level = MSG_ERROR;
8343
8344
0
    pos = driver ? os_strchr(driver, ',') : NULL;
8345
0
    if (pos) {
8346
0
      wpa_dbg(wpa_s, MSG_DEBUG, "Failed to initialize "
8347
0
        "driver interface - try next driver wrapper");
8348
0
      driver = pos + 1;
8349
0
      goto next_driver;
8350
0
    }
8351
8352
#ifdef CONFIG_MATCH_IFACE
8353
    if (wpa_s->matched == WPA_IFACE_MATCHED_NULL)
8354
      level = MSG_DEBUG;
8355
#endif /* CONFIG_MATCH_IFACE */
8356
0
    wpa_msg(wpa_s, level, "Failed to initialize driver interface");
8357
0
    return -1;
8358
0
  }
8359
0
  if (wpa_drv_set_param(wpa_s, wpa_s->conf->driver_param) < 0) {
8360
0
    wpa_msg(wpa_s, MSG_ERROR, "Driver interface rejected "
8361
0
      "driver_param '%s'", wpa_s->conf->driver_param);
8362
0
    return -1;
8363
0
  }
8364
8365
0
  ifname = wpa_drv_get_ifname(wpa_s);
8366
0
  if (ifname && os_strcmp(ifname, wpa_s->ifname) != 0) {
8367
0
    wpa_dbg(wpa_s, MSG_DEBUG, "Driver interface replaced "
8368
0
      "interface name with '%s'", ifname);
8369
0
    os_strlcpy(wpa_s->ifname, ifname, sizeof(wpa_s->ifname));
8370
0
  }
8371
8372
0
  rn = wpa_driver_get_radio_name(wpa_s);
8373
0
  if (rn && rn[0] == '\0')
8374
0
    rn = NULL;
8375
8376
0
  wpa_s->radio = radio_add_interface(wpa_s, rn);
8377
0
  if (wpa_s->radio == NULL)
8378
0
    return -1;
8379
8380
0
  return 0;
8381
0
}
8382
8383
8384
#ifdef CONFIG_GAS_SERVER
8385
8386
static void wpas_gas_server_tx_status(struct wpa_supplicant *wpa_s,
8387
              unsigned int freq, const u8 *dst,
8388
              const u8 *src, const u8 *bssid,
8389
              const u8 *data, size_t data_len,
8390
              enum offchannel_send_action_result result)
8391
{
8392
  wpa_printf(MSG_DEBUG, "GAS: TX status: freq=%u dst=" MACSTR
8393
       " result=%s",
8394
       freq, MAC2STR(dst),
8395
       result == OFFCHANNEL_SEND_ACTION_SUCCESS ? "SUCCESS" :
8396
       (result == OFFCHANNEL_SEND_ACTION_NO_ACK ? "no-ACK" :
8397
        "FAILED"));
8398
  gas_server_tx_status(wpa_s->gas_server, dst, data, data_len,
8399
           result == OFFCHANNEL_SEND_ACTION_SUCCESS);
8400
}
8401
8402
8403
static void wpas_gas_server_tx(void *ctx, int freq, const u8 *da,
8404
             struct wpabuf *buf, unsigned int wait_time)
8405
{
8406
  struct wpa_supplicant *wpa_s = ctx;
8407
  const u8 broadcast[ETH_ALEN] = { 0xff, 0xff, 0xff, 0xff, 0xff, 0xff };
8408
8409
  if (wait_time > wpa_s->max_remain_on_chan)
8410
    wait_time = wpa_s->max_remain_on_chan;
8411
8412
  offchannel_send_action(wpa_s, freq, da, wpa_s->own_addr, broadcast,
8413
             wpabuf_head(buf), wpabuf_len(buf),
8414
             wait_time, wpas_gas_server_tx_status, 0);
8415
}
8416
8417
#endif /* CONFIG_GAS_SERVER */
8418
8419
static int wpa_supplicant_init_iface(struct wpa_supplicant *wpa_s,
8420
             const struct wpa_interface *iface)
8421
0
{
8422
0
  struct wpa_driver_capa capa;
8423
0
  int capa_res;
8424
0
  u8 dfs_domain;
8425
8426
0
  wpa_printf(MSG_DEBUG, "Initializing interface '%s' conf '%s' driver "
8427
0
       "'%s' ctrl_interface '%s' bridge '%s'", iface->ifname,
8428
0
       iface->confname ? iface->confname : "N/A",
8429
0
       iface->driver ? iface->driver : "default",
8430
0
       iface->ctrl_interface ? iface->ctrl_interface : "N/A",
8431
0
       iface->bridge_ifname ? iface->bridge_ifname : "N/A");
8432
8433
0
  if (iface->confname) {
8434
#ifdef CONFIG_BACKEND_FILE
8435
    const char *prefix = wpa_s->global->params.conf_file_prefix;
8436
8437
    wpa_s->confname = os_rel2abs_path(iface->confname);
8438
    if (wpa_s->confname == NULL) {
8439
      wpa_printf(MSG_ERROR, "Failed to get absolute path "
8440
           "for configuration file '%s'.",
8441
           iface->confname);
8442
      return -1;
8443
    }
8444
    wpa_printf(MSG_DEBUG, "Configuration file '%s' -> '%s'",
8445
         iface->confname, wpa_s->confname);
8446
    if (prefix &&
8447
        os_strncmp(wpa_s->confname, prefix,
8448
             os_strlen(prefix)) != 0) {
8449
      wpa_printf(MSG_ERROR,
8450
           "Specified configuration file (%s) does not start with the required prefix (%s)",
8451
           wpa_s->confname, prefix);
8452
      return -1;
8453
    }
8454
    if (prefix && os_strstr(wpa_s->confname, "/../")) {
8455
      wpa_printf(MSG_ERROR,
8456
           "Specified configuration file (%s) has /../ in it",
8457
           wpa_s->confname);
8458
      return -1;
8459
    }
8460
#else /* CONFIG_BACKEND_FILE */
8461
0
    wpa_s->confname = os_strdup(iface->confname);
8462
0
#endif /* CONFIG_BACKEND_FILE */
8463
0
    wpa_s->conf = wpa_config_read(
8464
0
      wpa_s->confname, NULL, false,
8465
0
      wpa_s->global->params.show_details);
8466
0
    if (wpa_s->conf == NULL) {
8467
0
      wpa_printf(MSG_ERROR, "Failed to read or parse "
8468
0
           "configuration '%s'.", wpa_s->confname);
8469
0
      return -1;
8470
0
    }
8471
0
    wpa_s->confanother = os_rel2abs_path(iface->confanother);
8472
0
    if (wpa_s->confanother &&
8473
0
        !wpa_config_read(wpa_s->confanother, wpa_s->conf, true,
8474
0
             wpa_s->global->params.show_details)) {
8475
0
      wpa_printf(MSG_ERROR,
8476
0
           "Failed to read or parse configuration '%s'.",
8477
0
           wpa_s->confanother);
8478
0
      return -1;
8479
0
    }
8480
8481
    /*
8482
     * Override ctrl_interface and driver_param if set on command
8483
     * line.
8484
     */
8485
0
    if (iface->ctrl_interface) {
8486
0
      os_free(wpa_s->conf->ctrl_interface);
8487
0
      wpa_s->conf->ctrl_interface =
8488
0
        os_strdup(iface->ctrl_interface);
8489
0
      if (!wpa_s->conf->ctrl_interface) {
8490
0
        wpa_printf(MSG_ERROR,
8491
0
             "Failed to duplicate control interface '%s'.",
8492
0
             iface->ctrl_interface);
8493
0
        return -1;
8494
0
      }
8495
0
    }
8496
8497
0
    if (iface->driver_param) {
8498
0
      os_free(wpa_s->conf->driver_param);
8499
0
      wpa_s->conf->driver_param =
8500
0
        os_strdup(iface->driver_param);
8501
0
      if (!wpa_s->conf->driver_param) {
8502
0
        wpa_printf(MSG_ERROR,
8503
0
             "Failed to duplicate driver param '%s'.",
8504
0
             iface->driver_param);
8505
0
        return -1;
8506
0
      }
8507
0
    }
8508
8509
0
    if (iface->p2p_mgmt && !iface->ctrl_interface) {
8510
0
      os_free(wpa_s->conf->ctrl_interface);
8511
0
      wpa_s->conf->ctrl_interface = NULL;
8512
0
    }
8513
0
  } else
8514
0
    wpa_s->conf = wpa_config_alloc_empty(iface->ctrl_interface,
8515
0
                 iface->driver_param);
8516
8517
0
  if (wpa_s->conf == NULL) {
8518
0
    wpa_printf(MSG_ERROR, "\nNo configuration found.");
8519
0
    return -1;
8520
0
  }
8521
8522
0
  if (iface->ifname == NULL) {
8523
0
    wpa_printf(MSG_ERROR, "\nInterface name is required.");
8524
0
    return -1;
8525
0
  }
8526
0
  if (os_strlen(iface->ifname) >= sizeof(wpa_s->ifname)) {
8527
0
    wpa_printf(MSG_ERROR, "\nToo long interface name '%s'.",
8528
0
         iface->ifname);
8529
0
    return -1;
8530
0
  }
8531
0
  os_strlcpy(wpa_s->ifname, iface->ifname, sizeof(wpa_s->ifname));
8532
#ifdef CONFIG_MATCH_IFACE
8533
  wpa_s->matched = iface->matched;
8534
#endif /* CONFIG_MATCH_IFACE */
8535
8536
0
  if (iface->bridge_ifname) {
8537
0
    if (os_strlen(iface->bridge_ifname) >=
8538
0
        sizeof(wpa_s->bridge_ifname)) {
8539
0
      wpa_printf(MSG_ERROR, "\nToo long bridge interface "
8540
0
           "name '%s'.", iface->bridge_ifname);
8541
0
      return -1;
8542
0
    }
8543
0
    os_strlcpy(wpa_s->bridge_ifname, iface->bridge_ifname,
8544
0
         sizeof(wpa_s->bridge_ifname));
8545
0
  }
8546
8547
  /* RSNA Supplicant Key Management - INITIALIZE */
8548
0
  eapol_sm_notify_portEnabled(wpa_s->eapol, false);
8549
0
  eapol_sm_notify_portValid(wpa_s->eapol, false);
8550
8551
  /* Initialize driver interface and register driver event handler before
8552
   * L2 receive handler so that association events are processed before
8553
   * EAPOL-Key packets if both become available for the same select()
8554
   * call. */
8555
0
  if (wpas_init_driver(wpa_s, iface) < 0)
8556
0
    return -1;
8557
8558
0
  if (wpa_supplicant_init_wpa(wpa_s) < 0)
8559
0
    return -1;
8560
8561
0
  wpa_sm_set_ifname(wpa_s->wpa, wpa_s->ifname,
8562
0
        wpa_s->bridge_ifname[0] ? wpa_s->bridge_ifname :
8563
0
        NULL);
8564
0
  wpa_sm_set_fast_reauth(wpa_s->wpa, wpa_s->conf->fast_reauth);
8565
8566
0
  if (wpa_s->conf->dot11RSNAConfigPMKLifetime &&
8567
0
      wpa_sm_set_param(wpa_s->wpa, RSNA_PMK_LIFETIME,
8568
0
           wpa_s->conf->dot11RSNAConfigPMKLifetime)) {
8569
0
    wpa_msg(wpa_s, MSG_ERROR, "Invalid WPA parameter value for "
8570
0
      "dot11RSNAConfigPMKLifetime");
8571
0
    return -1;
8572
0
  }
8573
8574
0
  if (wpa_s->conf->dot11RSNAConfigPMKReauthThreshold &&
8575
0
      wpa_sm_set_param(wpa_s->wpa, RSNA_PMK_REAUTH_THRESHOLD,
8576
0
           wpa_s->conf->dot11RSNAConfigPMKReauthThreshold)) {
8577
0
    wpa_msg(wpa_s, MSG_ERROR, "Invalid WPA parameter value for "
8578
0
      "dot11RSNAConfigPMKReauthThreshold");
8579
0
    return -1;
8580
0
  }
8581
8582
0
  if (wpa_s->conf->dot11RSNAConfigSATimeout &&
8583
0
      wpa_sm_set_param(wpa_s->wpa, RSNA_SA_TIMEOUT,
8584
0
           wpa_s->conf->dot11RSNAConfigSATimeout)) {
8585
0
    wpa_msg(wpa_s, MSG_ERROR, "Invalid WPA parameter value for "
8586
0
      "dot11RSNAConfigSATimeout");
8587
0
    return -1;
8588
0
  }
8589
8590
0
  wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_FT_PREPEND_PMKID,
8591
0
       wpa_s->conf->ft_prepend_pmkid);
8592
8593
0
  wpa_s->hw.modes = wpa_drv_get_hw_feature_data(
8594
0
    wpa_s, &wpa_s->hw.num_modes, &wpa_s->hw.flags, &dfs_domain,
8595
0
    wpa_s->device_country, sizeof(wpa_s->device_country));
8596
0
  wpa_s->hw_dfs_domain = dfs_domain;
8597
0
  if (!wpa_s->device_country_set &&
8598
0
      wpa_s->device_country[0] && wpa_s->device_country[1]) {
8599
0
    wpa_s->device_country_set = true;
8600
0
    wpa_printf(MSG_DEBUG,
8601
0
         "Device country code set to '%s' from hw feature data at init",
8602
0
         wpa_s->device_country);
8603
0
  }
8604
0
  if (wpa_s->hw.modes) {
8605
0
    u16 i;
8606
8607
0
    for (i = 0; i < wpa_s->hw.num_modes; i++) {
8608
0
      if (wpa_s->hw.modes[i].eht_capab[IEEE80211_MODE_INFRA].
8609
0
          eht_supported)
8610
0
        wpa_s->hw_capab |= BIT(CAPAB_EHT);
8611
0
      if (wpa_s->hw.modes[i].he_capab[IEEE80211_MODE_INFRA].
8612
0
          he_supported)
8613
0
        wpa_s->hw_capab |= BIT(CAPAB_HE);
8614
0
      if (wpa_s->hw.modes[i].vht_capab)
8615
0
        wpa_s->hw_capab |= BIT(CAPAB_VHT);
8616
0
      if (wpa_s->hw.modes[i].ht_capab)
8617
0
        wpa_s->hw_capab |= BIT(CAPAB_HT);
8618
0
    }
8619
0
    wpa_s->support_6ghz = wpas_is_6ghz_supported(wpa_s, false);
8620
0
  }
8621
8622
0
  capa_res = wpa_drv_get_capa(wpa_s, &capa);
8623
0
  if (capa_res == 0) {
8624
0
    u16 eml_capa, mld_capa;
8625
8626
0
    wpa_s->drv_capa_known = 1;
8627
0
    wpa_s->drv_flags = capa.flags;
8628
0
    wpa_s->drv_flags2 = capa.flags2;
8629
0
    wpa_s->drv_enc = capa.enc;
8630
0
    wpa_s->drv_key_mgmt = capa.key_mgmt;
8631
0
    wpa_s->drv_rrm_flags = capa.rrm_flags;
8632
0
    wpa_s->drv_max_acl_mac_addrs = capa.max_acl_mac_addrs;
8633
0
    wpa_s->probe_resp_offloads = capa.probe_resp_offloads;
8634
0
    wpa_s->max_scan_ssids = capa.max_scan_ssids;
8635
0
    wpa_s->max_sched_scan_ssids = capa.max_sched_scan_ssids;
8636
0
    wpa_s->max_sched_scan_plans = capa.max_sched_scan_plans;
8637
0
    wpa_s->max_sched_scan_plan_interval =
8638
0
      capa.max_sched_scan_plan_interval;
8639
0
    wpa_s->max_sched_scan_plan_iterations =
8640
0
      capa.max_sched_scan_plan_iterations;
8641
0
    wpa_s->sched_scan_supported = capa.sched_scan_supported;
8642
0
    wpa_s->max_match_sets = capa.max_match_sets;
8643
0
    wpa_s->max_remain_on_chan = capa.max_remain_on_chan;
8644
0
    wpa_s->max_stations = capa.max_stations;
8645
0
    wpa_s->extended_capa = capa.extended_capa;
8646
0
    wpa_s->extended_capa_mask = capa.extended_capa_mask;
8647
0
    wpa_s->extended_capa_len = capa.extended_capa_len;
8648
0
    wpa_s->num_multichan_concurrent =
8649
0
      capa.num_multichan_concurrent;
8650
0
#ifndef CONFIG_NO_WMM_AC
8651
0
    wpa_s->wmm_ac_supported = capa.wmm_ac_supported;
8652
0
#endif /* CONFIG_NO_WMM_AC */
8653
0
    wpa_s->max_num_akms = capa.max_num_akms;
8654
8655
0
    if (capa.mac_addr_rand_scan_supported)
8656
0
      wpa_s->mac_addr_rand_supported |= MAC_ADDR_RAND_SCAN;
8657
0
    if (wpa_s->sched_scan_supported &&
8658
0
        capa.mac_addr_rand_sched_scan_supported)
8659
0
      wpa_s->mac_addr_rand_supported |=
8660
0
        (MAC_ADDR_RAND_SCHED_SCAN | MAC_ADDR_RAND_PNO);
8661
0
    wpa_s->drv_max_probe_req_ie_len = capa.max_probe_req_ie_len;
8662
8663
0
    wpa_drv_get_ext_capa(wpa_s, WPA_IF_STATION);
8664
0
    if (wpa_s->extended_capa &&
8665
0
        wpa_s->extended_capa_len >= 3 &&
8666
0
        wpa_s->extended_capa[2] & 0x40)
8667
0
      wpa_s->multi_bss_support = 1;
8668
8669
0
    if (wpa_drv_get_mld_capa(wpa_s, WPA_IF_STATION,
8670
0
           &eml_capa, &mld_capa) == 0) {
8671
0
      wpa_s->eml_capa = eml_capa;
8672
0
      wpa_s->mld_capa = mld_capa;
8673
0
    }
8674
0
  } else {
8675
0
    wpa_s->drv_max_probe_req_ie_len = 1500;
8676
0
  }
8677
#ifdef CONFIG_PASN
8678
  wpa_pasn_sm_set_caps(wpa_s->wpa, wpa_s->drv_flags2);
8679
#endif /* CONFIG_PASN */
8680
8681
#ifdef CONFIG_IEEE8021X_AUTH
8682
  wpa_sm_set_802_1x_auth_caps(wpa_s->wpa, wpa_s->drv_flags2);
8683
#endif /* CONFIG_IEEE8021X_AUTH */
8684
8685
0
  wpa_sm_set_driver_bss_selection(wpa_s->wpa,
8686
0
          !!(wpa_s->drv_flags &
8687
0
             WPA_DRIVER_FLAGS_BSS_SELECTION));
8688
0
  if (wpa_s->max_remain_on_chan == 0)
8689
0
    wpa_s->max_remain_on_chan = 1000;
8690
8691
  /*
8692
   * Only take p2p_mgmt parameters when P2P Device is supported.
8693
   * Doing it here as it determines whether l2_packet_init() will be done
8694
   * during wpa_supplicant_driver_init().
8695
   */
8696
0
  if (wpa_s->drv_flags & WPA_DRIVER_FLAGS_DEDICATED_P2P_DEVICE)
8697
0
    wpa_s->p2p_mgmt = iface->p2p_mgmt;
8698
8699
0
  wpa_s->nan_mgmt = iface->nan_mgmt;
8700
0
  wpa_s->nan_data = iface->nan_data;
8701
8702
0
  if ((wpa_s->drv_flags2 & WPA_DRIVER_FLAGS2_P2P_ASSISTED_DFS) &&
8703
0
      wpa_s->conf->p2p_assisted_dfs_chan_enable)
8704
0
    wpa_s->allow_p2p_assisted_dfs = true;
8705
8706
0
  if (wpa_s->num_multichan_concurrent == 0)
8707
0
    wpa_s->num_multichan_concurrent = 1;
8708
8709
0
  if (wpa_supplicant_driver_init(wpa_s) < 0)
8710
0
    return -1;
8711
8712
#ifdef CONFIG_TDLS
8713
  if (!iface->p2p_mgmt && !iface->nan_mgmt && wpa_tdls_init(wpa_s->wpa))
8714
    return -1;
8715
#endif /* CONFIG_TDLS */
8716
8717
0
  if (wpa_s->conf->country[0] && wpa_s->conf->country[1] &&
8718
0
      wpa_drv_set_country(wpa_s, wpa_s->conf->country)) {
8719
0
    wpa_dbg(wpa_s, MSG_DEBUG, "Failed to set country");
8720
0
    return -1;
8721
0
  }
8722
8723
#ifdef CONFIG_FST
8724
  if (wpa_s->conf->fst_group_id) {
8725
    struct fst_iface_cfg cfg;
8726
    struct fst_wpa_obj iface_obj;
8727
8728
    fst_wpa_supplicant_fill_iface_obj(wpa_s, &iface_obj);
8729
    os_strlcpy(cfg.group_id, wpa_s->conf->fst_group_id,
8730
         sizeof(cfg.group_id));
8731
    cfg.priority = wpa_s->conf->fst_priority;
8732
    cfg.llt = wpa_s->conf->fst_llt;
8733
8734
    wpa_s->fst = fst_attach(wpa_s->ifname, wpa_s->own_addr,
8735
          &iface_obj, &cfg);
8736
    if (!wpa_s->fst) {
8737
      wpa_msg(wpa_s, MSG_ERROR,
8738
        "FST: Cannot attach iface %s to group %s",
8739
        wpa_s->ifname, cfg.group_id);
8740
      return -1;
8741
    }
8742
  }
8743
#endif /* CONFIG_FST */
8744
8745
0
  if (wpas_wps_init(wpa_s))
8746
0
    return -1;
8747
8748
#ifdef CONFIG_GAS_SERVER
8749
  wpa_s->gas_server = gas_server_init(wpa_s, wpas_gas_server_tx);
8750
  if (!wpa_s->gas_server) {
8751
    wpa_printf(MSG_ERROR, "Failed to initialize GAS server");
8752
    return -1;
8753
  }
8754
#endif /* CONFIG_GAS_SERVER */
8755
8756
#ifdef CONFIG_DPP
8757
  if (wpas_dpp_init(wpa_s) < 0)
8758
    return -1;
8759
#endif /* CONFIG_DPP */
8760
8761
0
  if (wpas_nan_de_init(wpa_s) < 0)
8762
0
    return -1;
8763
8764
#ifdef CONFIG_NAN
8765
  os_memcpy(&wpa_s->nan_capa, &capa.nan_capa,
8766
      sizeof(wpa_s->nan_capa));
8767
#endif /* CONFIG_NAN */
8768
8769
0
  if (wpa_supplicant_init_eapol(wpa_s) < 0)
8770
0
    return -1;
8771
0
  wpa_sm_set_eapol(wpa_s->wpa, wpa_s->eapol);
8772
8773
0
  wpa_s->ctrl_iface = wpa_supplicant_ctrl_iface_init(wpa_s);
8774
0
  if (wpa_s->ctrl_iface == NULL) {
8775
0
    wpa_printf(MSG_ERROR,
8776
0
         "Failed to initialize control interface '%s'.\n"
8777
0
         "You may have another wpa_supplicant process "
8778
0
         "already running or the file was\n"
8779
0
         "left by an unclean termination of wpa_supplicant "
8780
0
         "in which case you will need\n"
8781
0
         "to manually remove this file before starting "
8782
0
         "wpa_supplicant again.\n",
8783
0
         wpa_s->conf->ctrl_interface);
8784
0
    return -1;
8785
0
  }
8786
8787
0
  wpa_s->gas = gas_query_init(wpa_s);
8788
0
  if (wpa_s->gas == NULL) {
8789
0
    wpa_printf(MSG_ERROR, "Failed to initialize GAS query");
8790
0
    return -1;
8791
0
  }
8792
8793
#ifdef CONFIG_P2P
8794
  if (wpa_s->drv_flags2 & (WPA_DRIVER_FLAGS2_P2P_FEATURE_V2 |
8795
         WPA_DRIVER_FLAGS2_P2P_FEATURE_PCC_MODE)) {
8796
    wpa_s->p2p_pairing_setup = true;
8797
    wpa_s->p2p_pairing_cache = true;
8798
  }
8799
#endif /* CONFIG_P2P */
8800
8801
0
  if ((!(wpa_s->drv_flags & WPA_DRIVER_FLAGS_DEDICATED_P2P_DEVICE) ||
8802
0
       wpa_s->p2p_mgmt) &&
8803
0
      wpas_p2p_init(wpa_s->global, wpa_s) < 0) {
8804
0
    wpa_msg(wpa_s, MSG_ERROR, "Failed to init P2P");
8805
0
    return -1;
8806
0
  }
8807
8808
0
  if (!capa.ranging_type.pd_support) {
8809
0
    wpa_printf(MSG_DEBUG,
8810
0
         "PR: Driver does not support Proximity Ranging - PR disabled");
8811
0
  } else if (wpas_pr_init(wpa_s->global, wpa_s, &capa) < 0) {
8812
0
    return -1;
8813
0
  }
8814
8815
0
  if (wpa_bss_init(wpa_s) < 0)
8816
0
    return -1;
8817
8818
  /*
8819
   * Set Wake-on-WLAN triggers, if configured.
8820
   * Note: We don't restore/remove the triggers on shutdown (it doesn't
8821
   * have effect anyway when the interface is down).
8822
   */
8823
0
  if (capa_res == 0 && wpas_set_wowlan_triggers(wpa_s, &capa) < 0)
8824
0
    return -1;
8825
8826
#ifdef CONFIG_EAP_PROXY
8827
{
8828
  size_t len;
8829
  wpa_s->mnc_len = eapol_sm_get_eap_proxy_imsi(wpa_s->eapol, -1,
8830
                 wpa_s->imsi, &len);
8831
  if (wpa_s->mnc_len > 0) {
8832
    wpa_s->imsi[len] = '\0';
8833
    wpa_printf(MSG_DEBUG, "eap_proxy: IMSI %s (MNC length %d)",
8834
         wpa_s->imsi, wpa_s->mnc_len);
8835
  } else {
8836
    wpa_printf(MSG_DEBUG, "eap_proxy: IMSI not available");
8837
  }
8838
}
8839
#endif /* CONFIG_EAP_PROXY */
8840
8841
0
  if (pcsc_reader_init(wpa_s) < 0)
8842
0
    return -1;
8843
8844
0
  if (wpas_init_ext_pw(wpa_s) < 0)
8845
0
    return -1;
8846
8847
0
#ifndef CONFIG_NO_RRM
8848
0
  wpas_rrm_reset(wpa_s);
8849
0
#endif /* CONFIG_NO_RRM */
8850
8851
0
  wpas_sched_scan_plans_set(wpa_s, wpa_s->conf->sched_scan_plans);
8852
8853
#ifdef CONFIG_MBO
8854
0
  if (!wpa_s->disable_mbo_oce && wpa_s->conf->oce) {
8855
0
    if ((wpa_s->conf->oce & OCE_STA) &&
8856
0
        (wpa_s->drv_flags & WPA_DRIVER_FLAGS_OCE_STA))
8857
0
      wpa_s->enable_oce = OCE_STA;
8858
0
    if ((wpa_s->conf->oce & OCE_STA_CFON) &&
8859
0
        (wpa_s->drv_flags & WPA_DRIVER_FLAGS_OCE_STA_CFON)) {
8860
      /* TODO: Need to add STA-CFON support */
8861
0
      wpa_printf(MSG_ERROR,
8862
0
           "OCE STA-CFON feature is not yet supported");
8863
0
    }
8864
0
  }
8865
  wpas_mbo_update_non_pref_chan(wpa_s, wpa_s->conf->non_pref_chan);
8866
#endif /* CONFIG_MBO */
8867
8868
0
  wpa_supplicant_set_default_scan_ies(wpa_s);
8869
8870
0
  if (wpa_s->nan_mgmt && wpas_nan_init(wpa_s) < 0) {
8871
0
    wpa_msg(wpa_s, MSG_ERROR, "Failed to init NAN");
8872
0
    return -1;
8873
0
  }
8874
8875
0
  return 0;
8876
0
}
Unexecuted instantiation: wpa_supplicant.c:wpa_supplicant_init_iface
Unexecuted instantiation: wpa_supplicant.c:wpa_supplicant_init_iface
8877
8878
8879
static void wpa_supplicant_deinit_iface(struct wpa_supplicant *wpa_s,
8880
          int notify, int terminate)
8881
0
{
8882
0
  struct wpa_global *global = wpa_s->global;
8883
0
  struct wpa_supplicant *iface, *prev;
8884
8885
0
  if (wpa_s == wpa_s->parent)
8886
0
    wpas_p2p_group_remove(wpa_s, "*");
8887
8888
0
  iface = global->ifaces;
8889
0
  while (iface) {
8890
0
    if (iface->p2pdev == wpa_s)
8891
0
      iface->p2pdev = iface->parent;
8892
0
    if (iface == wpa_s || iface->parent != wpa_s) {
8893
0
      iface = iface->next;
8894
0
      continue;
8895
0
    }
8896
0
    wpa_printf(MSG_DEBUG,
8897
0
         "Remove remaining child interface %s from parent %s",
8898
0
         iface->ifname, wpa_s->ifname);
8899
0
    prev = iface;
8900
0
    iface = iface->next;
8901
0
    wpa_supplicant_remove_iface(global, prev, terminate);
8902
0
  }
8903
8904
0
  wpa_s->disconnected = 1;
8905
0
  if (wpa_s->drv_priv) {
8906
    /*
8907
     * Don't deauthenticate if WoWLAN is enable and not explicitly
8908
     * been configured to disconnect.
8909
     */
8910
0
    if (!wpa_drv_get_wowlan(wpa_s) ||
8911
0
        wpa_s->conf->wowlan_disconnect_on_deinit) {
8912
0
      wpa_supplicant_deauthenticate(
8913
0
        wpa_s, WLAN_REASON_DEAUTH_LEAVING);
8914
8915
0
      wpa_drv_set_countermeasures(wpa_s, 0);
8916
0
      wpa_clear_keys(wpa_s, NULL);
8917
0
    } else {
8918
0
      wpa_msg(wpa_s, MSG_INFO,
8919
0
        "Do not deauthenticate as part of interface deinit since WoWLAN is enabled");
8920
0
    }
8921
0
  }
8922
8923
0
  wpa_supplicant_cleanup(wpa_s);
8924
0
  wpas_p2p_deinit_iface(wpa_s);
8925
8926
0
  wpas_nan_deinit(wpa_s);
8927
8928
0
  wpas_ctrl_radio_work_flush(wpa_s);
8929
0
  radio_remove_interface(wpa_s);
8930
8931
#ifdef CONFIG_FST
8932
  if (wpa_s->fst) {
8933
    fst_detach(wpa_s->fst);
8934
    wpa_s->fst = NULL;
8935
  }
8936
  if (wpa_s->received_mb_ies) {
8937
    wpabuf_free(wpa_s->received_mb_ies);
8938
    wpa_s->received_mb_ies = NULL;
8939
  }
8940
#endif /* CONFIG_FST */
8941
8942
0
  if (wpa_s->drv_priv)
8943
0
    wpa_drv_deinit(wpa_s);
8944
8945
0
  if (notify)
8946
0
    wpas_notify_iface_removed(wpa_s);
8947
8948
0
  if (terminate)
8949
0
    wpa_msg(wpa_s, MSG_INFO, WPA_EVENT_TERMINATING);
8950
8951
0
  wpa_supplicant_ctrl_iface_deinit(wpa_s, wpa_s->ctrl_iface);
8952
0
  wpa_s->ctrl_iface = NULL;
8953
8954
#ifdef CONFIG_MESH
8955
  if (wpa_s->ifmsh) {
8956
    wpa_supplicant_mesh_iface_deinit(wpa_s, wpa_s->ifmsh, true);
8957
    wpa_s->ifmsh = NULL;
8958
  }
8959
#endif /* CONFIG_MESH */
8960
8961
0
  if (wpa_s->conf != NULL) {
8962
0
    wpa_config_free(wpa_s->conf);
8963
0
    wpa_s->conf = NULL;
8964
0
  }
8965
8966
0
  os_free(wpa_s->ssids_from_scan_req);
8967
0
  os_free(wpa_s->last_scan_freqs);
8968
8969
0
  os_free(wpa_s);
8970
0
}
8971
8972
8973
#ifdef CONFIG_MATCH_IFACE
8974
8975
/**
8976
 * wpa_supplicant_match_iface - Match an interface description to a name
8977
 * @global: Pointer to global data from wpa_supplicant_init()
8978
 * @ifname: Name of the interface to match
8979
 * Returns: Pointer to the created interface description or %NULL on failure
8980
 */
8981
struct wpa_interface * wpa_supplicant_match_iface(struct wpa_global *global,
8982
              const char *ifname)
8983
{
8984
  int i;
8985
  struct wpa_interface *iface, *miface;
8986
8987
  for (i = 0; i < global->params.match_iface_count; i++) {
8988
    miface = &global->params.match_ifaces[i];
8989
    if (!miface->ifname ||
8990
        fnmatch(miface->ifname, ifname, 0) == 0) {
8991
      iface = os_zalloc(sizeof(*iface));
8992
      if (!iface)
8993
        return NULL;
8994
      *iface = *miface;
8995
      if (!miface->ifname)
8996
        iface->matched = WPA_IFACE_MATCHED_NULL;
8997
      else
8998
        iface->matched = WPA_IFACE_MATCHED;
8999
      iface->ifname = ifname;
9000
      return iface;
9001
    }
9002
  }
9003
9004
  return NULL;
9005
}
9006
9007
9008
/**
9009
 * wpa_supplicant_match_existing - Match existing interfaces
9010
 * @global: Pointer to global data from wpa_supplicant_init()
9011
 * Returns: 0 on success, -1 on failure
9012
 */
9013
static int wpa_supplicant_match_existing(struct wpa_global *global)
9014
{
9015
  struct if_nameindex *ifi, *ifp;
9016
  struct wpa_supplicant *wpa_s;
9017
  struct wpa_interface *iface;
9018
9019
  ifp = if_nameindex();
9020
  if (!ifp) {
9021
    wpa_printf(MSG_ERROR, "if_nameindex: %s", strerror(errno));
9022
    return -1;
9023
  }
9024
9025
  for (ifi = ifp; ifi->if_name; ifi++) {
9026
    wpa_s = wpa_supplicant_get_iface(global, ifi->if_name);
9027
    if (wpa_s)
9028
      continue;
9029
    iface = wpa_supplicant_match_iface(global, ifi->if_name);
9030
    if (iface) {
9031
      wpa_supplicant_add_iface(global, iface, NULL);
9032
      os_free(iface);
9033
    }
9034
  }
9035
9036
  if_freenameindex(ifp);
9037
  return 0;
9038
}
9039
9040
#endif /* CONFIG_MATCH_IFACE */
9041
9042
9043
/**
9044
 * wpa_supplicant_add_iface - Add a new network interface
9045
 * @global: Pointer to global data from wpa_supplicant_init()
9046
 * @iface: Interface configuration options
9047
 * @parent: Parent interface or %NULL to assign new interface as parent
9048
 * Returns: Pointer to the created interface or %NULL on failure
9049
 *
9050
 * This function is used to add new network interfaces for %wpa_supplicant.
9051
 * This can be called before wpa_supplicant_run() to add interfaces before the
9052
 * main event loop has been started. In addition, new interfaces can be added
9053
 * dynamically while %wpa_supplicant is already running. This could happen,
9054
 * e.g., when a hotplug network adapter is inserted.
9055
 */
9056
struct wpa_supplicant * wpa_supplicant_add_iface(struct wpa_global *global,
9057
             struct wpa_interface *iface,
9058
             struct wpa_supplicant *parent)
9059
0
{
9060
0
  struct wpa_supplicant *wpa_s;
9061
0
  struct wpa_interface t_iface;
9062
0
  struct wpa_ssid *ssid;
9063
9064
0
  if (global == NULL || iface == NULL)
9065
0
    return NULL;
9066
9067
0
  wpa_s = wpa_supplicant_alloc(parent);
9068
0
  if (wpa_s == NULL)
9069
0
    return NULL;
9070
9071
0
  wpa_s->global = global;
9072
9073
0
  t_iface = *iface;
9074
0
  if (global->params.override_driver) {
9075
0
    wpa_printf(MSG_DEBUG, "Override interface parameter: driver "
9076
0
         "('%s' -> '%s')",
9077
0
         iface->driver, global->params.override_driver);
9078
0
    t_iface.driver = global->params.override_driver;
9079
0
  }
9080
0
  if (global->params.override_ctrl_interface) {
9081
0
    wpa_printf(MSG_DEBUG, "Override interface parameter: "
9082
0
         "ctrl_interface ('%s' -> '%s')",
9083
0
         iface->ctrl_interface,
9084
0
         global->params.override_ctrl_interface);
9085
0
    t_iface.ctrl_interface =
9086
0
      global->params.override_ctrl_interface;
9087
0
  }
9088
0
  if (wpa_supplicant_init_iface(wpa_s, &t_iface)) {
9089
0
    wpa_printf(MSG_DEBUG, "Failed to add interface %s",
9090
0
         iface->ifname);
9091
0
    wpa_supplicant_deinit_iface(wpa_s, 0, 0);
9092
0
    return NULL;
9093
0
  }
9094
9095
0
  if (iface->p2p_mgmt == 0 && !iface->nan_mgmt) {
9096
    /* Notify the control interfaces about new iface */
9097
0
    if (wpas_notify_iface_added(wpa_s)) {
9098
0
      wpa_supplicant_deinit_iface(wpa_s, 1, 0);
9099
0
      return NULL;
9100
0
    }
9101
9102
0
    for (ssid = wpa_s->conf->ssid; ssid; ssid = ssid->next)
9103
0
      wpas_notify_network_added(wpa_s, ssid);
9104
0
  }
9105
9106
0
  wpa_s->next = global->ifaces;
9107
0
  global->ifaces = wpa_s;
9108
9109
0
  wpa_dbg(wpa_s, MSG_DEBUG, "Added interface %s", wpa_s->ifname);
9110
0
  wpa_supplicant_set_state(wpa_s, WPA_DISCONNECTED);
9111
9112
#ifdef CONFIG_P2P
9113
  if (!wpa_s->global->p2p && !wpas_is_nan_iface(wpa_s) &&
9114
      !wpa_s->global->p2p_disabled && !wpa_s->conf->p2p_disabled &&
9115
      (wpa_s->drv_flags & WPA_DRIVER_FLAGS_DEDICATED_P2P_DEVICE) &&
9116
      wpas_p2p_add_p2pdev_interface(
9117
        wpa_s, wpa_s->global->params.conf_p2p_dev) < 0) {
9118
    wpa_printf(MSG_INFO,
9119
         "P2P: Failed to enable P2P Device interface");
9120
    /* Try to continue without. P2P will be disabled. */
9121
  }
9122
#endif /* CONFIG_P2P */
9123
9124
0
  return wpa_s;
9125
0
}
9126
9127
9128
/**
9129
 * wpa_supplicant_remove_iface - Remove a network interface
9130
 * @global: Pointer to global data from wpa_supplicant_init()
9131
 * @wpa_s: Pointer to the network interface to be removed
9132
 * Returns: 0 if interface was removed, -1 if interface was not found
9133
 *
9134
 * This function can be used to dynamically remove network interfaces from
9135
 * %wpa_supplicant, e.g., when a hotplug network adapter is ejected. In
9136
 * addition, this function is used to remove all remaining interfaces when
9137
 * %wpa_supplicant is terminated.
9138
 */
9139
int wpa_supplicant_remove_iface(struct wpa_global *global,
9140
        struct wpa_supplicant *wpa_s,
9141
        int terminate)
9142
0
{
9143
0
  struct wpa_supplicant *prev;
9144
#ifdef CONFIG_MESH
9145
  unsigned int mesh_if_created = wpa_s->mesh_if_created;
9146
  char *ifname = NULL;
9147
  struct wpa_supplicant *parent = wpa_s->parent;
9148
#endif /* CONFIG_MESH */
9149
9150
  /* Remove interface from the global list of interfaces */
9151
0
  prev = global->ifaces;
9152
0
  if (prev == wpa_s) {
9153
0
    global->ifaces = wpa_s->next;
9154
0
  } else {
9155
0
    while (prev && prev->next != wpa_s)
9156
0
      prev = prev->next;
9157
0
    if (prev == NULL)
9158
0
      return -1;
9159
0
    prev->next = wpa_s->next;
9160
0
  }
9161
9162
0
  wpa_dbg(wpa_s, MSG_DEBUG, "Removing interface %s", wpa_s->ifname);
9163
9164
#ifdef CONFIG_MESH
9165
  if (mesh_if_created) {
9166
    ifname = os_strdup(wpa_s->ifname);
9167
    if (ifname == NULL) {
9168
      wpa_dbg(wpa_s, MSG_ERROR,
9169
        "mesh: Failed to malloc ifname");
9170
      return -1;
9171
    }
9172
  }
9173
#endif /* CONFIG_MESH */
9174
9175
0
  if (global->p2p_group_formation == wpa_s)
9176
0
    global->p2p_group_formation = NULL;
9177
0
  if (global->p2p_invite_group == wpa_s)
9178
0
    global->p2p_invite_group = NULL;
9179
0
  wpa_supplicant_deinit_iface(wpa_s, 1, terminate);
9180
9181
#ifdef CONFIG_MESH
9182
  if (mesh_if_created) {
9183
    wpa_drv_if_remove(parent, WPA_IF_MESH, ifname);
9184
    os_free(ifname);
9185
  }
9186
#endif /* CONFIG_MESH */
9187
9188
0
  return 0;
9189
0
}
9190
9191
9192
/**
9193
 * wpa_supplicant_get_eap_mode - Get the current EAP mode
9194
 * @wpa_s: Pointer to the network interface
9195
 * Returns: Pointer to the eap mode or the string "UNKNOWN" if not found
9196
 */
9197
const char * wpa_supplicant_get_eap_mode(struct wpa_supplicant *wpa_s)
9198
0
{
9199
0
  const char *eapol_method;
9200
9201
0
        if (wpa_key_mgmt_wpa_ieee8021x(wpa_s->key_mgmt) == 0 &&
9202
0
            wpa_s->key_mgmt != WPA_KEY_MGMT_IEEE8021X_NO_WPA) {
9203
0
    return "NO-EAP";
9204
0
  }
9205
9206
0
  eapol_method = eapol_sm_get_method_name(wpa_s->eapol);
9207
0
  if (eapol_method == NULL)
9208
0
    return "UNKNOWN-EAP";
9209
9210
0
  return eapol_method;
9211
0
}
9212
9213
9214
/**
9215
 * wpa_supplicant_get_iface - Get a new network interface
9216
 * @global: Pointer to global data from wpa_supplicant_init()
9217
 * @ifname: Interface name
9218
 * Returns: Pointer to the interface or %NULL if not found
9219
 */
9220
struct wpa_supplicant * wpa_supplicant_get_iface(struct wpa_global *global,
9221
             const char *ifname)
9222
0
{
9223
0
  struct wpa_supplicant *wpa_s;
9224
9225
0
  for (wpa_s = global->ifaces; wpa_s; wpa_s = wpa_s->next) {
9226
0
    if (os_strcmp(wpa_s->ifname, ifname) == 0)
9227
0
      return wpa_s;
9228
0
  }
9229
0
  return NULL;
9230
0
}
9231
9232
9233
#ifndef CONFIG_NO_WPA_MSG
9234
static const char * wpa_supplicant_msg_ifname_cb(void *ctx)
9235
0
{
9236
0
  struct wpa_supplicant *wpa_s = ctx;
9237
0
  if (wpa_s == NULL)
9238
0
    return NULL;
9239
0
  return wpa_s->ifname;
9240
0
}
9241
#endif /* CONFIG_NO_WPA_MSG */
9242
9243
9244
#ifndef WPA_SUPPLICANT_CLEANUP_INTERVAL
9245
0
#define WPA_SUPPLICANT_CLEANUP_INTERVAL 10
9246
#endif /* WPA_SUPPLICANT_CLEANUP_INTERVAL */
9247
9248
/* Periodic cleanup tasks */
9249
static void wpas_periodic(void *eloop_ctx, void *timeout_ctx)
9250
0
{
9251
0
  struct wpa_global *global = eloop_ctx;
9252
0
  struct wpa_supplicant *wpa_s;
9253
9254
0
  eloop_register_timeout(WPA_SUPPLICANT_CLEANUP_INTERVAL, 0,
9255
0
             wpas_periodic, global, NULL);
9256
9257
#ifdef CONFIG_P2P
9258
  if (global->p2p)
9259
    p2p_expire_peers(global->p2p);
9260
#endif /* CONFIG_P2P */
9261
9262
0
  for (wpa_s = global->ifaces; wpa_s; wpa_s = wpa_s->next) {
9263
0
    wpa_bss_flush_by_age(wpa_s, wpa_s->conf->bss_expiration_age);
9264
#ifdef CONFIG_AP
9265
    ap_periodic(wpa_s);
9266
#endif /* CONFIG_AP */
9267
0
  }
9268
0
}
9269
9270
9271
/**
9272
 * wpa_supplicant_init - Initialize %wpa_supplicant
9273
 * @params: Parameters for %wpa_supplicant
9274
 * Returns: Pointer to global %wpa_supplicant data, or %NULL on failure
9275
 *
9276
 * This function is used to initialize %wpa_supplicant. After successful
9277
 * initialization, the returned data pointer can be used to add and remove
9278
 * network interfaces, and eventually, to deinitialize %wpa_supplicant.
9279
 */
9280
struct wpa_global * wpa_supplicant_init(struct wpa_params *params)
9281
0
{
9282
0
  struct wpa_global *global;
9283
0
  int ret, i;
9284
9285
0
  if (params == NULL)
9286
0
    return NULL;
9287
9288
#ifdef CONFIG_DRIVER_NDIS
9289
  {
9290
    void driver_ndis_init_ops(void);
9291
    driver_ndis_init_ops();
9292
  }
9293
#endif /* CONFIG_DRIVER_NDIS */
9294
9295
0
#ifndef CONFIG_NO_WPA_MSG
9296
0
  wpa_msg_register_ifname_cb(wpa_supplicant_msg_ifname_cb);
9297
0
#endif /* CONFIG_NO_WPA_MSG */
9298
9299
0
  if (params->wpa_debug_file_path)
9300
0
    wpa_debug_open_file(params->wpa_debug_file_path);
9301
0
  if (!params->wpa_debug_file_path && !params->wpa_debug_syslog)
9302
0
    wpa_debug_setup_stdout();
9303
0
  if (params->wpa_debug_syslog)
9304
0
    wpa_debug_open_syslog();
9305
0
  if (params->wpa_debug_tracing) {
9306
0
    ret = wpa_debug_open_linux_tracing();
9307
0
    if (ret) {
9308
0
      wpa_printf(MSG_ERROR,
9309
0
           "Failed to enable trace logging");
9310
0
      return NULL;
9311
0
    }
9312
0
  }
9313
9314
0
  ret = eap_register_methods();
9315
0
  if (ret) {
9316
0
    wpa_printf(MSG_ERROR, "Failed to register EAP methods");
9317
0
    if (ret == -2)
9318
0
      wpa_printf(MSG_ERROR, "Two or more EAP methods used "
9319
0
           "the same EAP type.");
9320
0
    return NULL;
9321
0
  }
9322
9323
0
  global = os_zalloc(sizeof(*global));
9324
0
  if (global == NULL)
9325
0
    return NULL;
9326
0
  dl_list_init(&global->p2p_srv_bonjour);
9327
0
  dl_list_init(&global->p2p_srv_upnp);
9328
0
  global->params.daemonize = params->daemonize;
9329
0
  global->params.wait_for_monitor = params->wait_for_monitor;
9330
0
  global->params.dbus_ctrl_interface = params->dbus_ctrl_interface;
9331
0
  global->params.show_details = params->show_details;
9332
0
  global->params.conf_file_prefix = params->conf_file_prefix;
9333
9334
0
  if (params->pid_file) {
9335
0
    global->params.pid_file = os_strdup(params->pid_file);
9336
0
    if (!global->params.pid_file) {
9337
0
      wpa_supplicant_deinit(global);
9338
0
      return NULL;
9339
0
    }
9340
0
  }
9341
9342
0
  if (params->ctrl_interface) {
9343
0
    global->params.ctrl_interface =
9344
0
      os_strdup(params->ctrl_interface);
9345
0
    if (!global->params.ctrl_interface) {
9346
0
      wpa_supplicant_deinit(global);
9347
0
      return NULL;
9348
0
    }
9349
0
  }
9350
9351
0
  if (params->ctrl_interface_group) {
9352
0
    global->params.ctrl_interface_group =
9353
0
      os_strdup(params->ctrl_interface_group);
9354
0
    if (!global->params.ctrl_interface_group) {
9355
0
      wpa_supplicant_deinit(global);
9356
0
      return NULL;
9357
0
    }
9358
0
  }
9359
9360
0
  if (params->override_driver) {
9361
0
    global->params.override_driver =
9362
0
      os_strdup(params->override_driver);
9363
0
    if (!global->params.override_driver) {
9364
0
      wpa_supplicant_deinit(global);
9365
0
      return NULL;
9366
0
    }
9367
0
  }
9368
9369
0
  if (params->override_ctrl_interface) {
9370
0
    global->params.override_ctrl_interface =
9371
0
      os_strdup(params->override_ctrl_interface);
9372
0
    if (!global->params.override_ctrl_interface) {
9373
0
      wpa_supplicant_deinit(global);
9374
0
      return NULL;
9375
0
    }
9376
0
  }
9377
9378
#ifdef CONFIG_MATCH_IFACE
9379
  global->params.match_iface_count = params->match_iface_count;
9380
  if (params->match_iface_count) {
9381
    global->params.match_ifaces =
9382
      os_calloc(params->match_iface_count,
9383
          sizeof(struct wpa_interface));
9384
    if (!global->params.match_ifaces) {
9385
      wpa_printf(MSG_ERROR,
9386
           "Failed to allocate match interfaces");
9387
      wpa_supplicant_deinit(global);
9388
      return NULL;
9389
    }
9390
    os_memcpy(global->params.match_ifaces,
9391
        params->match_ifaces,
9392
        params->match_iface_count *
9393
        sizeof(struct wpa_interface));
9394
  }
9395
#endif /* CONFIG_MATCH_IFACE */
9396
#ifdef CONFIG_P2P
9397
  if (params->conf_p2p_dev) {
9398
    global->params.conf_p2p_dev =
9399
      os_strdup(params->conf_p2p_dev);
9400
    if (!global->params.conf_p2p_dev) {
9401
      wpa_printf(MSG_ERROR, "Failed to allocate conf p2p");
9402
      wpa_supplicant_deinit(global);
9403
      return NULL;
9404
    }
9405
  }
9406
#endif /* CONFIG_P2P */
9407
0
  wpa_debug_level = global->params.wpa_debug_level =
9408
0
    params->wpa_debug_level;
9409
0
  wpa_debug_show_keys = global->params.wpa_debug_show_keys =
9410
0
    params->wpa_debug_show_keys;
9411
0
  wpa_debug_timestamp = global->params.wpa_debug_timestamp =
9412
0
    params->wpa_debug_timestamp;
9413
9414
0
  wpa_printf(MSG_DEBUG, "wpa_supplicant v%s", VERSION_STR);
9415
9416
0
  if (eloop_init()) {
9417
0
    wpa_printf(MSG_ERROR, "Failed to initialize event loop");
9418
0
    wpa_supplicant_deinit(global);
9419
0
    return NULL;
9420
0
  }
9421
9422
0
  random_init(params->entropy_file);
9423
9424
#ifdef CONFIG_PROCESS_COORDINATION
9425
  if (params->proc_coord_dir) {
9426
    global->pc = proc_coord_init(params->proc_coord_dir);
9427
    if (!global->pc) {
9428
      wpa_supplicant_deinit(global);
9429
      return NULL;
9430
    }
9431
  }
9432
#endif /* CONFIG_PROCESS_COORDINATION */
9433
9434
0
  global->ctrl_iface = wpa_supplicant_global_ctrl_iface_init(global);
9435
0
  if (global->ctrl_iface == NULL) {
9436
0
    wpa_supplicant_deinit(global);
9437
0
    return NULL;
9438
0
  }
9439
9440
0
  if (wpas_notify_supplicant_initialized(global)) {
9441
0
    wpa_supplicant_deinit(global);
9442
0
    return NULL;
9443
0
  }
9444
9445
0
  for (i = 0; wpa_drivers[i]; i++)
9446
0
    global->drv_count++;
9447
0
  if (global->drv_count == 0) {
9448
0
    wpa_printf(MSG_ERROR, "No drivers enabled");
9449
0
    wpa_supplicant_deinit(global);
9450
0
    return NULL;
9451
0
  }
9452
0
  global->drv_priv = os_calloc(global->drv_count, sizeof(void *));
9453
0
  if (global->drv_priv == NULL) {
9454
0
    wpa_supplicant_deinit(global);
9455
0
    return NULL;
9456
0
  }
9457
9458
#ifdef CONFIG_WIFI_DISPLAY
9459
  if (wifi_display_init(global) < 0) {
9460
    wpa_printf(MSG_ERROR, "Failed to initialize Wi-Fi Display");
9461
    wpa_supplicant_deinit(global);
9462
    return NULL;
9463
  }
9464
#endif /* CONFIG_WIFI_DISPLAY */
9465
9466
0
  eloop_register_timeout(WPA_SUPPLICANT_CLEANUP_INTERVAL, 0,
9467
0
             wpas_periodic, global, NULL);
9468
9469
0
  return global;
9470
0
}
9471
9472
9473
/**
9474
 * wpa_supplicant_run - Run the %wpa_supplicant main event loop
9475
 * @global: Pointer to global data from wpa_supplicant_init()
9476
 * Returns: 0 after successful event loop run, -1 on failure
9477
 *
9478
 * This function starts the main event loop and continues running as long as
9479
 * there are any remaining events. In most cases, this function is running as
9480
 * long as the %wpa_supplicant process in still in use.
9481
 */
9482
int wpa_supplicant_run(struct wpa_global *global)
9483
0
{
9484
0
  struct wpa_supplicant *wpa_s;
9485
9486
0
  if (global->params.daemonize &&
9487
0
      (wpa_supplicant_daemon(global->params.pid_file) ||
9488
0
       eloop_sock_requeue()))
9489
0
    return -1;
9490
9491
#ifdef CONFIG_MATCH_IFACE
9492
  if (wpa_supplicant_match_existing(global))
9493
    return -1;
9494
#endif
9495
9496
0
  if (global->params.wait_for_monitor) {
9497
0
    for (wpa_s = global->ifaces; wpa_s; wpa_s = wpa_s->next)
9498
0
      if (wpa_s->ctrl_iface && !wpa_s->p2p_mgmt)
9499
0
        wpa_supplicant_ctrl_iface_wait(
9500
0
          wpa_s->ctrl_iface);
9501
0
  }
9502
9503
0
  eloop_register_signal_terminate(wpa_supplicant_terminate, global);
9504
0
  eloop_register_signal_reconfig(wpa_supplicant_reconfig, global);
9505
9506
0
  eloop_run();
9507
9508
0
  return 0;
9509
0
}
9510
9511
9512
/**
9513
 * wpa_supplicant_deinit - Deinitialize %wpa_supplicant
9514
 * @global: Pointer to global data from wpa_supplicant_init()
9515
 *
9516
 * This function is called to deinitialize %wpa_supplicant and to free all
9517
 * allocated resources. Remaining network interfaces will also be removed.
9518
 */
9519
void wpa_supplicant_deinit(struct wpa_global *global)
9520
0
{
9521
0
  int i;
9522
9523
0
  if (global == NULL)
9524
0
    return;
9525
9526
0
  eloop_cancel_timeout(wpas_periodic, global, NULL);
9527
9528
#ifdef CONFIG_WIFI_DISPLAY
9529
  wifi_display_deinit(global);
9530
#endif /* CONFIG_WIFI_DISPLAY */
9531
9532
0
  while (global->ifaces)
9533
0
    wpa_supplicant_remove_iface(global, global->ifaces, 1);
9534
9535
0
  if (global->ctrl_iface)
9536
0
    wpa_supplicant_global_ctrl_iface_deinit(global->ctrl_iface);
9537
9538
0
  wpas_notify_supplicant_deinitialized(global);
9539
9540
0
  eap_peer_unregister_methods();
9541
#ifdef CONFIG_AP
9542
  eap_server_unregister_methods();
9543
#endif /* CONFIG_AP */
9544
9545
0
  for (i = 0; wpa_drivers[i] && global->drv_priv; i++) {
9546
0
    if (!global->drv_priv[i])
9547
0
      continue;
9548
0
    wpa_drivers[i]->global_deinit(global->drv_priv[i]);
9549
0
  }
9550
0
  os_free(global->drv_priv);
9551
9552
0
  random_deinit();
9553
9554
#ifdef CONFIG_PROCESS_COORDINATION
9555
  proc_coord_deinit(global->pc);
9556
#endif /* CONFIG_PROCESS_COORDINATION */
9557
9558
0
  eloop_destroy();
9559
9560
0
  if (global->params.pid_file) {
9561
0
    os_daemonize_terminate(global->params.pid_file);
9562
0
    os_free(global->params.pid_file);
9563
0
  }
9564
0
  os_free(global->params.ctrl_interface);
9565
0
  os_free(global->params.ctrl_interface_group);
9566
0
  os_free(global->params.override_driver);
9567
0
  os_free(global->params.override_ctrl_interface);
9568
#ifdef CONFIG_MATCH_IFACE
9569
  os_free(global->params.match_ifaces);
9570
#endif /* CONFIG_MATCH_IFACE */
9571
#ifdef CONFIG_P2P
9572
  os_free(global->params.conf_p2p_dev);
9573
#endif /* CONFIG_P2P */
9574
9575
0
  os_free(global->p2p_disallow_freq.range);
9576
0
  os_free(global->p2p_go_avoid_freq.range);
9577
0
  os_free(global->add_psk);
9578
9579
0
  os_free(global);
9580
0
  wpa_debug_close_syslog();
9581
0
  wpa_debug_close_file();
9582
0
  wpa_debug_close_linux_tracing();
9583
0
}
9584
9585
9586
int wpa_supplicant_parse_config(const char *fname)
9587
0
{
9588
0
  struct wpa_config *conf;
9589
0
  int ret = -1;
9590
9591
0
  wpa_printf(MSG_INFO, "Validating parsing of %s", fname);
9592
0
  conf = wpa_config_read(fname, NULL, false, true);
9593
0
  if (conf) {
9594
0
    wpa_printf(MSG_INFO, "Parsing succeeded");
9595
0
    ret = 0;
9596
0
    wpa_config_free(conf);
9597
0
  } else {
9598
0
    wpa_printf(MSG_INFO, "Parsing failed");
9599
0
  }
9600
0
  return ret;
9601
0
}
9602
9603
9604
void wpa_supplicant_update_config(struct wpa_supplicant *wpa_s)
9605
0
{
9606
0
  if ((wpa_s->conf->changed_parameters & CFG_CHANGED_COUNTRY) &&
9607
0
      wpa_s->conf->country[0] && wpa_s->conf->country[1]) {
9608
0
    char country[3];
9609
0
    country[0] = wpa_s->conf->country[0];
9610
0
    country[1] = wpa_s->conf->country[1];
9611
0
    country[2] = '\0';
9612
0
    if (wpa_drv_set_country(wpa_s, country) < 0) {
9613
0
      wpa_printf(MSG_ERROR, "Failed to set country code "
9614
0
           "'%s'", country);
9615
0
    }
9616
0
  }
9617
9618
0
  if (wpa_s->conf->changed_parameters & CFG_CHANGED_EXT_PW_BACKEND)
9619
0
    wpas_init_ext_pw(wpa_s);
9620
9621
0
  if (wpa_s->conf->changed_parameters & CFG_CHANGED_SCHED_SCAN_PLANS)
9622
0
    wpas_sched_scan_plans_set(wpa_s, wpa_s->conf->sched_scan_plans);
9623
9624
0
  if (wpa_s->conf->changed_parameters & CFG_CHANGED_WOWLAN_TRIGGERS) {
9625
0
    struct wpa_driver_capa capa;
9626
0
    int res = wpa_drv_get_capa(wpa_s, &capa);
9627
9628
0
    if (res == 0 && wpas_set_wowlan_triggers(wpa_s, &capa) < 0)
9629
0
      wpa_printf(MSG_ERROR,
9630
0
           "Failed to update wowlan_triggers to '%s'",
9631
0
           wpa_s->conf->wowlan_triggers);
9632
0
  }
9633
9634
0
  if (wpa_s->conf->changed_parameters & CFG_CHANGED_DISABLE_BTM)
9635
0
    wpa_supplicant_set_default_scan_ies(wpa_s);
9636
9637
0
  if (wpa_s->conf->changed_parameters & CFG_CHANGED_FT_PREPEND_PMKID)
9638
0
    wpa_sm_set_param(wpa_s->wpa, WPA_PARAM_FT_PREPEND_PMKID,
9639
0
         wpa_s->conf->ft_prepend_pmkid);
9640
9641
#ifdef CONFIG_P2P
9642
  if (wpa_s->conf->changed_parameters & CFG_CHANGED_P2P_DISABLED)
9643
    wpas_p2p_disabled_changed(wpa_s);
9644
#endif /* CONFIG_P2P */
9645
9646
#ifdef CONFIG_BGSCAN
9647
  /*
9648
   * We default to global bgscan parameters only when per-network bgscan
9649
   * parameters aren't set. Only bother resetting bgscan parameters if
9650
   * this is the case.
9651
   */
9652
  if ((wpa_s->conf->changed_parameters & CFG_CHANGED_BGSCAN) &&
9653
      wpa_s->current_ssid && !wpa_s->current_ssid->bgscan &&
9654
      wpa_s->wpa_state == WPA_COMPLETED)
9655
    wpa_supplicant_reset_bgscan(wpa_s);
9656
#endif /* CONFIG_BGSCAN */
9657
9658
0
#ifdef CONFIG_WPS
9659
0
  wpas_wps_update_config(wpa_s);
9660
0
#endif /* CONFIG_WPS */
9661
0
  wpas_p2p_update_config(wpa_s);
9662
0
  wpa_s->conf->changed_parameters = 0;
9663
0
}
9664
9665
9666
void wpas_connection_failed(struct wpa_supplicant *wpa_s, const u8 *bssid,
9667
          const u8 **link_bssids)
9668
0
{
9669
0
  int timeout;
9670
0
  int count;
9671
9672
0
  wpas_connect_work_done(wpa_s);
9673
9674
  /*
9675
   * Remove possible authentication timeout since the connection failed.
9676
   */
9677
0
  eloop_cancel_timeout(wpa_supplicant_timeout, wpa_s, NULL);
9678
9679
  /*
9680
   * There is no point in ignoring the AP temporarily if this event is
9681
   * generated based on local request to disconnect.
9682
   */
9683
0
  if (wpa_s->own_disconnect_req || wpa_s->own_reconnect_req) {
9684
0
    wpa_s->own_disconnect_req = 0;
9685
0
    wpa_dbg(wpa_s, MSG_DEBUG,
9686
0
      "Ignore connection failure due to local request to disconnect");
9687
0
    return;
9688
0
  }
9689
0
  if (wpa_s->disconnected) {
9690
0
    wpa_dbg(wpa_s, MSG_DEBUG, "Ignore connection failure "
9691
0
      "indication since interface has been put into "
9692
0
      "disconnected state");
9693
0
    return;
9694
0
  }
9695
9696
  /* Also mark links as failed */
9697
0
  while (link_bssids && *link_bssids) {
9698
0
    wpa_bssid_ignore_add(wpa_s, *link_bssids);
9699
0
    link_bssids++;
9700
0
  }
9701
9702
  /*
9703
   * Add the failed BSSID into the ignore list and speed up next scan
9704
   * attempt if there could be other APs that could accept association.
9705
   */
9706
0
  count = wpa_bssid_ignore_add(wpa_s, bssid);
9707
9708
  /*
9709
   * This BSS was not in the ignore list before. If there is
9710
   * another BSS available for the same ESS, we should try that
9711
   * next. Otherwise, we may as well try this one once more
9712
   * before allowing other, likely worse, ESSes to be considered.
9713
   */
9714
0
  if (count == 1 && wpa_supplicant_fast_associate(wpa_s) == 1)
9715
0
    return;
9716
9717
0
  wpa_s->consecutive_conn_failures++;
9718
9719
0
  if (wpa_s->consecutive_conn_failures > 3 && wpa_s->current_ssid) {
9720
0
    wpa_printf(MSG_DEBUG, "Continuous association failures - "
9721
0
         "consider temporary network disabling");
9722
0
    wpas_auth_failed(wpa_s, "CONN_FAILED", bssid);
9723
0
  }
9724
  /*
9725
   * Multiple consecutive connection failures mean that other APs are
9726
   * either not available or have already been tried, so we can start
9727
   * increasing the delay here to avoid constant scanning.
9728
   */
9729
0
  switch (wpa_s->consecutive_conn_failures) {
9730
0
  case 1:
9731
0
    timeout = 100;
9732
0
    break;
9733
0
  case 2:
9734
0
    timeout = 500;
9735
0
    break;
9736
0
  case 3:
9737
0
    timeout = 1000;
9738
0
    break;
9739
0
  case 4:
9740
0
    timeout = 5000;
9741
0
    break;
9742
0
  default:
9743
0
    timeout = 10000;
9744
0
    break;
9745
0
  }
9746
9747
0
  wpa_dbg(wpa_s, MSG_DEBUG,
9748
0
    "Consecutive connection failures: %d --> request scan in %d ms",
9749
0
    wpa_s->consecutive_conn_failures, timeout);
9750
9751
  /* speed up the connection attempt with normal scan */
9752
0
  wpa_s->normal_scans = 0;
9753
0
  wpa_supplicant_req_scan(wpa_s, timeout / 1000,
9754
0
        1000 * (timeout % 1000));
9755
0
}
9756
9757
9758
#ifdef CONFIG_FILS
9759
9760
void fils_pmksa_cache_flush(struct wpa_supplicant *wpa_s)
9761
{
9762
  struct wpa_ssid *ssid = wpa_s->current_ssid;
9763
  const u8 *realm, *username, *rrk;
9764
  size_t realm_len, username_len, rrk_len;
9765
  u16 next_seq_num;
9766
9767
  /* Clear the PMKSA cache entry if FILS authentication was rejected.
9768
   * Check for ERP keys existing to limit when this can be done since
9769
   * the rejection response is not protected and such triggers should
9770
   * really not allow internal state to be modified unless required to
9771
   * avoid significant issues in functionality. In addition, drop
9772
   * externally configure PMKSA entries even without ERP keys since it
9773
   * is possible for an external component to add PMKSA entries for FILS
9774
   * authentication without restoring previously generated ERP keys.
9775
   *
9776
   * In this case, this is needed to allow recovery from cases where the
9777
   * AP or authentication server has dropped PMKSAs and ERP keys. */
9778
  if (!ssid || !ssid->eap.erp || !wpa_key_mgmt_fils(ssid->key_mgmt))
9779
    return;
9780
9781
  if (eapol_sm_get_erp_info(wpa_s->eapol, &ssid->eap,
9782
          &username, &username_len,
9783
          &realm, &realm_len, &next_seq_num,
9784
          &rrk, &rrk_len) != 0 ||
9785
      !realm) {
9786
    wpa_dbg(wpa_s, MSG_DEBUG,
9787
      "FILS: Drop external PMKSA cache entry");
9788
    wpa_sm_aborted_external_cached(wpa_s->wpa);
9789
    wpa_sm_external_pmksa_cache_flush(wpa_s->wpa, ssid);
9790
    return;
9791
  }
9792
9793
  wpa_dbg(wpa_s, MSG_DEBUG, "FILS: Drop PMKSA cache entry");
9794
  wpa_sm_aborted_cached(wpa_s->wpa);
9795
  wpa_sm_pmksa_cache_flush(wpa_s->wpa, ssid);
9796
}
9797
9798
9799
void fils_connection_failure(struct wpa_supplicant *wpa_s)
9800
{
9801
  struct wpa_ssid *ssid = wpa_s->current_ssid;
9802
  const u8 *realm, *username, *rrk;
9803
  size_t realm_len, username_len, rrk_len;
9804
  u16 next_seq_num;
9805
9806
  if (!ssid || !ssid->eap.erp || !wpa_key_mgmt_fils(ssid->key_mgmt) ||
9807
      eapol_sm_get_erp_info(wpa_s->eapol, &ssid->eap,
9808
          &username, &username_len,
9809
          &realm, &realm_len, &next_seq_num,
9810
          &rrk, &rrk_len) != 0 ||
9811
      !realm)
9812
    return;
9813
9814
  wpa_hexdump_ascii(MSG_DEBUG,
9815
        "FILS: Store last connection failure realm",
9816
        realm, realm_len);
9817
  os_free(wpa_s->last_con_fail_realm);
9818
  wpa_s->last_con_fail_realm = os_malloc(realm_len);
9819
  if (wpa_s->last_con_fail_realm) {
9820
    wpa_s->last_con_fail_realm_len = realm_len;
9821
    os_memcpy(wpa_s->last_con_fail_realm, realm, realm_len);
9822
  }
9823
}
9824
#endif /* CONFIG_FILS */
9825
9826
9827
int wpas_driver_bss_selection(struct wpa_supplicant *wpa_s)
9828
0
{
9829
0
  return wpa_s->conf->ap_scan == 2 ||
9830
0
    (wpa_s->drv_flags & WPA_DRIVER_FLAGS_BSS_SELECTION);
9831
0
}
9832
9833
9834
static bool wpas_driver_rsn_override(struct wpa_supplicant *wpa_s)
9835
0
{
9836
0
  return !!(wpa_s->drv_flags2 & WPA_DRIVER_FLAGS2_RSN_OVERRIDE_STA);
9837
0
}
9838
9839
9840
bool wpas_rsn_overriding(struct wpa_supplicant *wpa_s, struct wpa_ssid *ssid)
9841
0
{
9842
0
  enum wpas_rsn_overriding rsno;
9843
9844
0
  if (ssid && ssid->rsn_overriding != RSN_OVERRIDING_NOT_SET)
9845
0
    rsno = ssid->rsn_overriding;
9846
0
  else
9847
0
    rsno = wpa_s->conf->rsn_overriding;
9848
9849
0
  if (rsno == RSN_OVERRIDING_DISABLED)
9850
0
    return false;
9851
9852
0
  if (rsno == RSN_OVERRIDING_ENABLED)
9853
0
    return true;
9854
9855
0
  if (!(wpa_s->drv_flags & WPA_DRIVER_FLAGS_SME) ||
9856
0
      wpas_driver_bss_selection(wpa_s))
9857
0
    return wpas_driver_rsn_override(wpa_s);
9858
9859
0
  return true;
9860
0
}
9861
9862
9863
#if defined(CONFIG_CTRL_IFACE) || defined(CONFIG_CTRL_IFACE_DBUS_NEW)
9864
int wpa_supplicant_ctrl_iface_ctrl_rsp_handle(struct wpa_supplicant *wpa_s,
9865
                struct wpa_ssid *ssid,
9866
                const char *field,
9867
                const char *value)
9868
{
9869
#ifdef IEEE8021X_EAPOL
9870
  struct eap_peer_config *eap = &ssid->eap;
9871
9872
  wpa_printf(MSG_DEBUG, "CTRL_IFACE: response handle field=%s", field);
9873
  wpa_hexdump_ascii_key(MSG_DEBUG, "CTRL_IFACE: response value",
9874
            (const u8 *) value, os_strlen(value));
9875
9876
  switch (wpa_supplicant_ctrl_req_from_string(field)) {
9877
  case WPA_CTRL_REQ_EAP_IDENTITY:
9878
    os_free(eap->identity);
9879
    eap->identity = (u8 *) os_strdup(value);
9880
    if (!eap->identity)
9881
      return -1;
9882
    eap->identity_len = os_strlen(value);
9883
    eap->pending_req_identity = 0;
9884
    if (ssid == wpa_s->current_ssid)
9885
      wpa_s->reassociate = 1;
9886
    break;
9887
  case WPA_CTRL_REQ_EAP_PASSWORD:
9888
    bin_clear_free(eap->password, eap->password_len);
9889
    eap->password = (u8 *) os_strdup(value);
9890
    if (!eap->password)
9891
      return -1;
9892
    eap->password_len = os_strlen(value);
9893
    eap->pending_req_password = 0;
9894
    if (ssid == wpa_s->current_ssid)
9895
      wpa_s->reassociate = 1;
9896
    break;
9897
  case WPA_CTRL_REQ_EAP_NEW_PASSWORD:
9898
    bin_clear_free(eap->new_password, eap->new_password_len);
9899
    eap->new_password = (u8 *) os_strdup(value);
9900
    if (!eap->new_password)
9901
      return -1;
9902
    eap->new_password_len = os_strlen(value);
9903
    eap->pending_req_new_password = 0;
9904
    if (ssid == wpa_s->current_ssid)
9905
      wpa_s->reassociate = 1;
9906
    break;
9907
  case WPA_CTRL_REQ_EAP_PIN:
9908
    str_clear_free(eap->cert.pin);
9909
    eap->cert.pin = os_strdup(value);
9910
    if (!eap->cert.pin)
9911
      return -1;
9912
    eap->pending_req_pin = 0;
9913
    if (ssid == wpa_s->current_ssid)
9914
      wpa_s->reassociate = 1;
9915
    break;
9916
  case WPA_CTRL_REQ_EAP_OTP:
9917
    bin_clear_free(eap->otp, eap->otp_len);
9918
    eap->otp = (u8 *) os_strdup(value);
9919
    if (!eap->otp)
9920
      return -1;
9921
    eap->otp_len = os_strlen(value);
9922
    os_free(eap->pending_req_otp);
9923
    eap->pending_req_otp = NULL;
9924
    eap->pending_req_otp_len = 0;
9925
    break;
9926
  case WPA_CTRL_REQ_EAP_PASSPHRASE:
9927
    str_clear_free(eap->cert.private_key_passwd);
9928
    eap->cert.private_key_passwd = os_strdup(value);
9929
    if (!eap->cert.private_key_passwd)
9930
      return -1;
9931
    eap->pending_req_passphrase = 0;
9932
    if (ssid == wpa_s->current_ssid)
9933
      wpa_s->reassociate = 1;
9934
    break;
9935
  case WPA_CTRL_REQ_SIM:
9936
    str_clear_free(eap->external_sim_resp);
9937
    eap->external_sim_resp = os_strdup(value);
9938
    if (!eap->external_sim_resp)
9939
      return -1;
9940
    eap->pending_req_sim = 0;
9941
    break;
9942
  case WPA_CTRL_REQ_PSK_PASSPHRASE:
9943
    if (wpa_config_set(ssid, "psk", value, 0) < 0)
9944
      return -1;
9945
    ssid->mem_only_psk = 1;
9946
    if (ssid->passphrase)
9947
      wpa_config_update_psk(ssid);
9948
    if (wpa_s->wpa_state == WPA_SCANNING && !wpa_s->scanning)
9949
      wpa_supplicant_req_scan(wpa_s, 0, 0);
9950
    break;
9951
  case WPA_CTRL_REQ_EXT_CERT_CHECK:
9952
    if (eap->pending_ext_cert_check != PENDING_CHECK)
9953
      return -1;
9954
    if (os_strcmp(value, "good") == 0)
9955
      eap->pending_ext_cert_check = EXT_CERT_CHECK_GOOD;
9956
    else if (os_strcmp(value, "bad") == 0)
9957
      eap->pending_ext_cert_check = EXT_CERT_CHECK_BAD;
9958
    else
9959
      return -1;
9960
    break;
9961
  default:
9962
    wpa_printf(MSG_DEBUG, "CTRL_IFACE: Unknown field '%s'", field);
9963
    return -1;
9964
  }
9965
9966
  return 0;
9967
#else /* IEEE8021X_EAPOL */
9968
  wpa_printf(MSG_DEBUG, "CTRL_IFACE: IEEE 802.1X not included");
9969
  return -1;
9970
#endif /* IEEE8021X_EAPOL */
9971
}
9972
#endif /* CONFIG_CTRL_IFACE || CONFIG_CTRL_IFACE_DBUS_NEW */
9973
9974
9975
int wpas_network_disabled(struct wpa_supplicant *wpa_s, struct wpa_ssid *ssid)
9976
0
{
9977
#ifdef CONFIG_WEP
9978
  int i;
9979
  unsigned int drv_enc;
9980
#endif /* CONFIG_WEP */
9981
9982
0
  if (wpa_s->p2p_mgmt)
9983
0
    return 1; /* no normal network profiles on p2p_mgmt interface */
9984
9985
0
  if (ssid == NULL)
9986
0
    return 1;
9987
9988
0
  if (ssid->disabled)
9989
0
    return 1;
9990
9991
#ifdef CONFIG_WEP
9992
  if (wpa_s->drv_capa_known)
9993
    drv_enc = wpa_s->drv_enc;
9994
  else
9995
    drv_enc = (unsigned int) -1;
9996
9997
  for (i = 0; i < NUM_WEP_KEYS; i++) {
9998
    size_t len = ssid->wep_key_len[i];
9999
    if (len == 0)
10000
      continue;
10001
    if (len == 5 && (drv_enc & WPA_DRIVER_CAPA_ENC_WEP40))
10002
      continue;
10003
    if (len == 13 && (drv_enc & WPA_DRIVER_CAPA_ENC_WEP104))
10004
      continue;
10005
    if (len == 16 && (drv_enc & WPA_DRIVER_CAPA_ENC_WEP128))
10006
      continue;
10007
    return 1; /* invalid WEP key */
10008
  }
10009
#endif /* CONFIG_WEP */
10010
10011
0
  if (wpa_key_mgmt_wpa_psk(ssid->key_mgmt) && !ssid->psk_set &&
10012
0
      (!ssid->passphrase || ssid->ssid_len != 0) && !ssid->ext_psk &&
10013
0
      !(wpa_key_mgmt_sae(ssid->key_mgmt) &&
10014
0
        (ssid->passphrase || ssid->sae_password || ssid->pmk_valid)) &&
10015
0
      !ssid->mem_only_psk)
10016
0
    return 1;
10017
10018
0
#ifdef IEEE8021X_EAPOL
10019
#ifdef CRYPTO_RSA_OAEP_SHA256
10020
  if (ssid->eap.imsi_privacy_cert) {
10021
    struct crypto_rsa_key *key;
10022
    bool failed = false;
10023
10024
    key = crypto_rsa_key_read(ssid->eap.imsi_privacy_cert, false);
10025
    if (!key)
10026
      failed = true;
10027
    crypto_rsa_key_free(key);
10028
    if (failed) {
10029
      wpa_printf(MSG_DEBUG,
10030
           "Invalid imsi_privacy_cert (%s) - disable network",
10031
           ssid->eap.imsi_privacy_cert);
10032
      return 1;
10033
    }
10034
  }
10035
#endif /* CRYPTO_RSA_OAEP_SHA256 */
10036
0
#endif /* IEEE8021X_EAPOL */
10037
10038
0
  return 0;
10039
0
}
10040
10041
10042
int wpas_get_ssid_pmf(struct wpa_supplicant *wpa_s, struct wpa_ssid *ssid)
10043
0
{
10044
0
  if (ssid == NULL || ssid->ieee80211w == MGMT_FRAME_PROTECTION_DEFAULT) {
10045
0
    if (wpa_s->conf->pmf == MGMT_FRAME_PROTECTION_OPTIONAL &&
10046
0
        !(wpa_s->drv_enc & WPA_DRIVER_CAPA_ENC_BIP)) {
10047
      /*
10048
       * Driver does not support BIP -- ignore pmf=1 default
10049
       * since the connection with PMF would fail and the
10050
       * configuration does not require PMF to be enabled.
10051
       */
10052
0
      return NO_MGMT_FRAME_PROTECTION;
10053
0
    }
10054
10055
0
    if (ssid &&
10056
0
        (ssid->key_mgmt &
10057
0
         ~(WPA_KEY_MGMT_NONE | WPA_KEY_MGMT_WPS |
10058
0
           WPA_KEY_MGMT_IEEE8021X_NO_WPA)) == 0) {
10059
      /*
10060
       * Do not use the default PMF value for non-RSN networks
10061
       * since PMF is available only with RSN and pmf=2
10062
       * configuration would otherwise prevent connections to
10063
       * all open networks.
10064
       */
10065
0
      return NO_MGMT_FRAME_PROTECTION;
10066
0
    }
10067
10068
#ifdef CONFIG_OCV
10069
    /* Enable PMF if OCV is being enabled */
10070
    if (wpa_s->conf->pmf == NO_MGMT_FRAME_PROTECTION &&
10071
        ssid && ssid->ocv)
10072
      return MGMT_FRAME_PROTECTION_OPTIONAL;
10073
#endif /* CONFIG_OCV */
10074
10075
0
    return wpa_s->conf->pmf;
10076
0
  }
10077
10078
0
  return ssid->ieee80211w;
10079
0
}
10080
10081
10082
#ifdef CONFIG_SAE
10083
10084
enum sae_pwe wpas_get_ssid_sae_pwe(struct wpa_supplicant *wpa_s,
10085
           struct wpa_ssid *ssid)
10086
{
10087
  if (!ssid || ssid->sae_pwe == DEFAULT_SAE_PWE)
10088
    return wpa_s->conf->sae_pwe;
10089
  return ssid->sae_pwe;
10090
}
10091
10092
10093
bool wpas_is_sae_avoided(struct wpa_supplicant *wpa_s,
10094
       struct wpa_ssid *ssid,
10095
       const struct wpa_ie_data *ie)
10096
{
10097
  return wpa_s->conf->sae_check_mfp &&
10098
    (!(ie->capabilities &
10099
       (WPA_CAPABILITY_MFPC | WPA_CAPABILITY_MFPR)) ||
10100
     wpas_get_ssid_pmf(wpa_s, ssid) == NO_MGMT_FRAME_PROTECTION);
10101
}
10102
10103
#endif /* CONFIG_SAE */
10104
10105
10106
int pmf_in_use(struct wpa_supplicant *wpa_s, const u8 *addr)
10107
0
{
10108
0
  if (wpa_s->current_ssid == NULL ||
10109
0
      wpa_s->wpa_state < WPA_4WAY_HANDSHAKE)
10110
0
    return 0;
10111
0
  if (wpa_s->valid_links) {
10112
0
    if (!ether_addr_equal(addr, wpa_s->ap_mld_addr) &&
10113
0
        !wpas_ap_link_address(wpa_s, addr))
10114
0
      return 0;
10115
0
  } else {
10116
0
    if (!ether_addr_equal(addr, wpa_s->bssid))
10117
0
      return 0;
10118
0
  }
10119
0
  return wpa_sm_pmf_enabled(wpa_s->wpa);
10120
0
}
10121
10122
10123
int wpas_is_p2p_prioritized(struct wpa_supplicant *wpa_s)
10124
0
{
10125
0
  if (wpa_s->global->conc_pref == WPA_CONC_PREF_P2P)
10126
0
    return 1;
10127
0
  if (wpa_s->global->conc_pref == WPA_CONC_PREF_STA)
10128
0
    return 0;
10129
0
  return -1;
10130
0
}
10131
10132
10133
void wpas_auth_failed(struct wpa_supplicant *wpa_s, const char *reason,
10134
          const u8 *bssid)
10135
0
{
10136
0
  struct wpa_ssid *ssid = wpa_s->current_ssid;
10137
0
  int dur;
10138
0
  struct os_reltime now;
10139
10140
0
  if (ssid == NULL) {
10141
0
    wpa_printf(MSG_DEBUG, "Authentication failure but no known "
10142
0
         "SSID block");
10143
0
    return;
10144
0
  }
10145
10146
0
  if (ssid->key_mgmt == WPA_KEY_MGMT_WPS)
10147
0
    return;
10148
10149
0
  ssid->auth_failures++;
10150
10151
#ifdef CONFIG_P2P
10152
  if (ssid->p2p_group &&
10153
      (wpa_s->p2p_in_provisioning || wpa_s->show_group_started)) {
10154
    /*
10155
     * Skip the wait time since there is a short timeout on the
10156
     * connection to a P2P group.
10157
     */
10158
    return;
10159
  }
10160
#endif /* CONFIG_P2P */
10161
10162
0
  if (ssid->auth_failures > 50)
10163
0
    dur = 300;
10164
0
  else if (ssid->auth_failures > 10)
10165
0
    dur = 120;
10166
0
  else if (ssid->auth_failures > 5)
10167
0
    dur = 90;
10168
0
  else if (ssid->auth_failures > 3)
10169
0
    dur = 60;
10170
0
  else if (ssid->auth_failures > 2)
10171
0
    dur = 30;
10172
0
  else if (ssid->auth_failures > 1)
10173
0
    dur = 20;
10174
0
  else
10175
0
    dur = 10;
10176
10177
0
  if (ssid->auth_failures > 1 &&
10178
0
      wpa_key_mgmt_wpa_ieee8021x(ssid->key_mgmt))
10179
0
    dur += os_random() % (ssid->auth_failures * 10);
10180
10181
0
  os_get_reltime(&now);
10182
0
  if (now.sec + dur <= ssid->disabled_until.sec)
10183
0
    return;
10184
10185
0
  ssid->disabled_until.sec = now.sec + dur;
10186
10187
0
  wpa_msg(wpa_s, MSG_INFO, WPA_EVENT_TEMP_DISABLED
10188
0
    "id=%d ssid=\"%s\" auth_failures=%u duration=%d reason=%s",
10189
0
    ssid->id, wpa_ssid_txt(ssid->ssid, ssid->ssid_len),
10190
0
    ssid->auth_failures, dur, reason);
10191
10192
0
  if (bssid)
10193
0
    os_memcpy(ssid->disabled_due_to, bssid, ETH_ALEN);
10194
0
}
10195
10196
10197
void wpas_clear_temp_disabled(struct wpa_supplicant *wpa_s,
10198
            struct wpa_ssid *ssid, int clear_failures)
10199
0
{
10200
0
  if (ssid == NULL)
10201
0
    return;
10202
10203
0
  if (ssid->disabled_until.sec) {
10204
0
    wpa_msg(wpa_s, MSG_INFO, WPA_EVENT_REENABLED
10205
0
      "id=%d ssid=\"%s\"",
10206
0
      ssid->id, wpa_ssid_txt(ssid->ssid, ssid->ssid_len));
10207
0
  }
10208
0
  ssid->disabled_until.sec = 0;
10209
0
  ssid->disabled_until.usec = 0;
10210
0
  if (clear_failures) {
10211
0
    ssid->auth_failures = 0;
10212
0
  } else if (!is_zero_ether_addr(ssid->disabled_due_to)) {
10213
0
    wpa_printf(MSG_DEBUG, "Mark BSSID " MACSTR
10214
0
         " ignored to allow a lower priority BSS, if any, to be tried next",
10215
0
         MAC2STR(ssid->disabled_due_to));
10216
0
    wpa_bssid_ignore_add(wpa_s, ssid->disabled_due_to);
10217
0
    os_memset(ssid->disabled_due_to, 0, ETH_ALEN);
10218
0
  }
10219
0
}
10220
10221
10222
int disallowed_bssid(struct wpa_supplicant *wpa_s, const u8 *bssid)
10223
0
{
10224
0
  size_t i;
10225
10226
0
  if (wpa_s->disallow_aps_bssid == NULL)
10227
0
    return 0;
10228
10229
0
  for (i = 0; i < wpa_s->disallow_aps_bssid_count; i++) {
10230
0
    if (ether_addr_equal(wpa_s->disallow_aps_bssid + i * ETH_ALEN,
10231
0
             bssid))
10232
0
      return 1;
10233
0
  }
10234
10235
0
  return 0;
10236
0
}
10237
10238
10239
int disallowed_ssid(struct wpa_supplicant *wpa_s, const u8 *ssid,
10240
        size_t ssid_len)
10241
0
{
10242
0
  size_t i;
10243
10244
0
  if (wpa_s->disallow_aps_ssid == NULL || ssid == NULL)
10245
0
    return 0;
10246
10247
0
  for (i = 0; i < wpa_s->disallow_aps_ssid_count; i++) {
10248
0
    struct wpa_ssid_value *s = &wpa_s->disallow_aps_ssid[i];
10249
0
    if (ssid_len == s->ssid_len &&
10250
0
        os_memcmp(ssid, s->ssid, ssid_len) == 0)
10251
0
      return 1;
10252
0
  }
10253
10254
0
  return 0;
10255
0
}
10256
10257
10258
/**
10259
 * wpas_request_connection - Request a new connection
10260
 * @wpa_s: Pointer to the network interface
10261
 *
10262
 * This function is used to request a new connection to be found. It will mark
10263
 * the interface to allow reassociation and request a new scan to find a
10264
 * suitable network to connect to.
10265
 */
10266
void wpas_request_connection(struct wpa_supplicant *wpa_s)
10267
0
{
10268
0
  wpa_s->normal_scans = 0;
10269
0
  wpa_s->scan_req = NORMAL_SCAN_REQ;
10270
0
  wpa_supplicant_reinit_autoscan(wpa_s);
10271
0
  wpa_s->disconnected = 0;
10272
0
  wpa_s->reassociate = 1;
10273
0
  wpa_s->last_owe_group = 0;
10274
#ifdef CONFIG_PASN
10275
  wpa_pasn_reset(&wpa_s->pasn);
10276
#endif /* CONFIG_PASN */
10277
10278
0
  if (wpa_supplicant_fast_associate(wpa_s) != 1)
10279
0
    wpa_supplicant_req_scan(wpa_s, 0, 0);
10280
0
  else
10281
0
    wpa_s->reattach = 0;
10282
0
}
10283
10284
10285
/**
10286
 * wpas_request_disconnection - Request disconnection
10287
 * @wpa_s: Pointer to the network interface
10288
 *
10289
 * This function is used to request disconnection from the currently connected
10290
 * network. This will stop any ongoing scans and initiate deauthentication.
10291
 */
10292
void wpas_request_disconnection(struct wpa_supplicant *wpa_s)
10293
0
{
10294
#ifdef CONFIG_SME
10295
  wpa_s->sme.prev_bssid_set = 0;
10296
#endif /* CONFIG_SME */
10297
0
  wpa_s->reassociate = 0;
10298
0
  wpa_s->disconnected = 1;
10299
0
  wpa_supplicant_cancel_sched_scan(wpa_s);
10300
0
  wpa_supplicant_cancel_scan(wpa_s);
10301
0
  wpas_abort_ongoing_scan(wpa_s);
10302
0
  wpa_supplicant_deauthenticate(wpa_s, WLAN_REASON_DEAUTH_LEAVING);
10303
0
  eloop_cancel_timeout(wpas_network_reenabled, wpa_s, NULL);
10304
0
  radio_remove_works(wpa_s, "connect", 0);
10305
0
  radio_remove_works(wpa_s, "sme-connect", 0);
10306
0
  wpa_s->roam_in_progress = false;
10307
0
#ifdef CONFIG_WNM
10308
0
  wpa_s->bss_trans_mgmt_in_progress = false;
10309
0
#endif /* CONFIG_WNM */
10310
0
}
10311
10312
10313
void dump_freq_data(struct wpa_supplicant *wpa_s, const char *title,
10314
        struct wpa_used_freq_data *freqs_data,
10315
        unsigned int len)
10316
0
{
10317
0
  unsigned int i;
10318
10319
0
  wpa_dbg(wpa_s, MSG_DEBUG, "Shared frequencies (len=%u): %s",
10320
0
    len, title);
10321
0
  for (i = 0; i < len; i++) {
10322
0
    struct wpa_used_freq_data *cur = &freqs_data[i];
10323
0
    wpa_dbg(wpa_s, MSG_DEBUG, "freq[%u]: %d, flags=0x%X",
10324
0
      i, cur->freq, cur->flags);
10325
0
  }
10326
0
}
10327
10328
10329
/*
10330
 * Find the operating frequencies of any of the virtual interfaces that
10331
 * are using the same radio as the current interface, and in addition, get
10332
 * information about the interface types that are using the frequency.
10333
 */
10334
int get_shared_radio_freqs_data(struct wpa_supplicant *wpa_s,
10335
        struct wpa_used_freq_data *freqs_data,
10336
        unsigned int len, bool exclude_current)
10337
0
{
10338
0
  struct wpa_supplicant *ifs;
10339
0
  u8 bssid[ETH_ALEN];
10340
0
  unsigned int idx = 0, i;
10341
10342
0
  wpa_dbg(wpa_s, MSG_DEBUG,
10343
0
    "Determining shared radio frequencies (max len %u)", len);
10344
0
  os_memset(freqs_data, 0, sizeof(struct wpa_used_freq_data) * len);
10345
10346
0
  dl_list_for_each(ifs, &wpa_s->radio->ifaces, struct wpa_supplicant,
10347
0
       radio_list) {
10348
0
    int freqs[MAX_NUM_MLD_LINKS];
10349
0
    unsigned int j, n_freqs = 0;
10350
10351
0
    if (idx == len)
10352
0
      break;
10353
10354
0
    if (exclude_current && ifs == wpa_s)
10355
0
      continue;
10356
10357
0
    if (!ifs->current_ssid ||
10358
0
        (!ifs->assoc_freq && !ifs->valid_links))
10359
0
      continue;
10360
10361
0
    if (ifs->current_ssid->mode == WPAS_MODE_AP ||
10362
0
        ifs->current_ssid->mode == WPAS_MODE_P2P_GO ||
10363
0
        ifs->current_ssid->mode == WPAS_MODE_MESH) {
10364
0
      freqs[n_freqs++] = ifs->current_ssid->frequency;
10365
0
    } else if (ifs->valid_links) {
10366
0
      struct driver_sta_mlo_info drv_mlo;
10367
10368
0
      os_memset(&drv_mlo, 0, sizeof(drv_mlo));
10369
10370
0
      if (wpas_drv_get_sta_mlo_info(ifs, &drv_mlo)) {
10371
0
        wpa_dbg(wpa_s, MSG_INFO,
10372
0
          "Failed to get MLO link info");
10373
0
        continue;
10374
0
      }
10375
10376
0
      if (!drv_mlo.valid_links)
10377
0
        continue;
10378
10379
0
      for_each_link(drv_mlo.valid_links, j) {
10380
0
        if (!drv_mlo.links[j].freq)
10381
0
          continue;
10382
10383
0
        freqs[n_freqs++] = drv_mlo.links[j].freq;
10384
0
      }
10385
0
    } else if (wpa_drv_get_bssid(ifs, bssid) == 0) {
10386
0
      freqs[n_freqs++] = ifs->assoc_freq;
10387
0
    } else {
10388
0
      continue;
10389
0
    }
10390
10391
    /* Hold only distinct freqs */
10392
0
    for (j = 0; j < n_freqs && idx < len; j++) {
10393
0
      for (i = 0; i < idx; i++)
10394
0
        if (freqs_data[i].freq == freqs[j])
10395
0
          break;
10396
10397
0
      if (i == idx)
10398
0
        freqs_data[idx++].freq = freqs[j];
10399
10400
0
      if (ifs->current_ssid->mode == WPAS_MODE_INFRA) {
10401
0
        freqs_data[i].flags |=
10402
0
          ifs->current_ssid->p2p_group ?
10403
0
          WPA_FREQ_USED_BY_P2P_CLIENT :
10404
0
          WPA_FREQ_USED_BY_INFRA_STATION;
10405
0
      }
10406
0
    }
10407
0
  }
10408
10409
0
  dump_freq_data(wpa_s, "completed iteration", freqs_data, idx);
10410
0
  return idx;
10411
0
}
10412
10413
10414
/*
10415
 * Find the operating frequencies of any of the virtual interfaces that
10416
 * are using the same radio as the current interface.
10417
 */
10418
int get_shared_radio_freqs(struct wpa_supplicant *wpa_s,
10419
         int *freq_array, unsigned int len,
10420
         bool exclude_current)
10421
0
{
10422
0
  struct wpa_used_freq_data *freqs_data;
10423
0
  int num, i;
10424
10425
0
  os_memset(freq_array, 0, sizeof(int) * len);
10426
10427
0
  freqs_data = os_calloc(len, sizeof(struct wpa_used_freq_data));
10428
0
  if (!freqs_data)
10429
0
    return -1;
10430
10431
0
  num = get_shared_radio_freqs_data(wpa_s, freqs_data, len,
10432
0
            exclude_current);
10433
0
  for (i = 0; i < num; i++)
10434
0
    freq_array[i] = freqs_data[i].freq;
10435
10436
0
  os_free(freqs_data);
10437
10438
0
  return num;
10439
0
}
10440
10441
10442
struct wpa_supplicant *
10443
wpas_vendor_elem(struct wpa_supplicant *wpa_s, enum wpa_vendor_elem_frame frame)
10444
0
{
10445
0
  switch (frame) {
10446
#ifdef CONFIG_P2P
10447
  case VENDOR_ELEM_PROBE_REQ_P2P:
10448
  case VENDOR_ELEM_PROBE_RESP_P2P:
10449
  case VENDOR_ELEM_PROBE_RESP_P2P_GO:
10450
  case VENDOR_ELEM_BEACON_P2P_GO:
10451
  case VENDOR_ELEM_P2P_PD_REQ:
10452
  case VENDOR_ELEM_P2P_PD_RESP:
10453
  case VENDOR_ELEM_P2P_GO_NEG_REQ:
10454
  case VENDOR_ELEM_P2P_GO_NEG_RESP:
10455
  case VENDOR_ELEM_P2P_GO_NEG_CONF:
10456
  case VENDOR_ELEM_P2P_INV_REQ:
10457
  case VENDOR_ELEM_P2P_INV_RESP:
10458
  case VENDOR_ELEM_P2P_ASSOC_REQ:
10459
  case VENDOR_ELEM_P2P_ASSOC_RESP:
10460
    return wpa_s->p2pdev;
10461
#endif /* CONFIG_P2P */
10462
0
  default:
10463
0
    return wpa_s;
10464
0
  }
10465
0
}
10466
10467
10468
void wpas_vendor_elem_update(struct wpa_supplicant *wpa_s)
10469
0
{
10470
0
  unsigned int i;
10471
0
  char buf[30];
10472
10473
0
  wpa_printf(MSG_DEBUG, "Update vendor elements");
10474
10475
0
  for (i = 0; i < NUM_VENDOR_ELEM_FRAMES; i++) {
10476
0
    if (wpa_s->vendor_elem[i]) {
10477
0
      int res;
10478
10479
0
      res = os_snprintf(buf, sizeof(buf), "frame[%u]", i);
10480
0
      if (!os_snprintf_error(sizeof(buf), res)) {
10481
0
        wpa_hexdump_buf(MSG_DEBUG, buf,
10482
0
            wpa_s->vendor_elem[i]);
10483
0
      }
10484
0
    }
10485
0
  }
10486
10487
#ifdef CONFIG_P2P
10488
  if (wpa_s->parent == wpa_s &&
10489
      wpa_s->global->p2p &&
10490
      !wpa_s->global->p2p_disabled)
10491
    p2p_set_vendor_elems(wpa_s->global->p2p, wpa_s->vendor_elem);
10492
#endif /* CONFIG_P2P */
10493
0
}
10494
10495
10496
int wpas_vendor_elem_remove(struct wpa_supplicant *wpa_s, int frame,
10497
          const u8 *elem, size_t len)
10498
0
{
10499
0
  u8 *ie, *end;
10500
10501
0
  ie = wpabuf_mhead_u8(wpa_s->vendor_elem[frame]);
10502
0
  end = ie + wpabuf_len(wpa_s->vendor_elem[frame]);
10503
10504
0
  for (; ie + 1 < end; ie += 2 + ie[1]) {
10505
0
    if (ie + len > end)
10506
0
      break;
10507
0
    if (os_memcmp(ie, elem, len) != 0)
10508
0
      continue;
10509
10510
0
    if (wpabuf_len(wpa_s->vendor_elem[frame]) == len) {
10511
0
      wpabuf_free(wpa_s->vendor_elem[frame]);
10512
0
      wpa_s->vendor_elem[frame] = NULL;
10513
0
    } else {
10514
0
      os_memmove(ie, ie + len, end - (ie + len));
10515
0
      wpa_s->vendor_elem[frame]->used -= len;
10516
0
    }
10517
0
    wpas_vendor_elem_update(wpa_s);
10518
0
    return 0;
10519
0
  }
10520
10521
0
  return -1;
10522
0
}
10523
10524
10525
struct hostapd_hw_modes * get_mode(struct hostapd_hw_modes *modes,
10526
           u16 num_modes, enum hostapd_hw_mode mode,
10527
           bool is_6ghz)
10528
0
{
10529
0
  u16 i;
10530
10531
0
  if (!modes)
10532
0
    return NULL;
10533
10534
0
  for (i = 0; i < num_modes; i++) {
10535
0
    if (modes[i].mode != mode ||
10536
0
        !modes[i].num_channels || !modes[i].channels)
10537
0
      continue;
10538
0
    if (is_6ghz == modes[i].is_6ghz)
10539
0
      return &modes[i];
10540
0
  }
10541
10542
0
  return NULL;
10543
0
}
10544
10545
10546
struct hostapd_hw_modes * get_mode_with_freq(struct hostapd_hw_modes *modes,
10547
               u16 num_modes, int freq)
10548
0
{
10549
0
  int i, j;
10550
10551
0
  for (i = 0; i < num_modes; i++) {
10552
0
    for (j = 0; j < modes[i].num_channels; j++) {
10553
0
      if (freq == modes[i].channels[j].freq)
10554
0
        return &modes[i];
10555
0
    }
10556
0
  }
10557
10558
0
  return NULL;
10559
0
}
10560
10561
10562
static struct
10563
wpa_bss_tmp_disallowed * wpas_get_disallowed_bss(struct wpa_supplicant *wpa_s,
10564
             const u8 *bssid)
10565
0
{
10566
0
  struct wpa_bss_tmp_disallowed *bss;
10567
10568
0
  dl_list_for_each(bss, &wpa_s->bss_tmp_disallowed,
10569
0
       struct wpa_bss_tmp_disallowed, list) {
10570
0
    if (ether_addr_equal(bssid, bss->bssid))
10571
0
      return bss;
10572
0
  }
10573
10574
0
  return NULL;
10575
0
}
10576
10577
10578
static int wpa_set_driver_tmp_disallow_list(struct wpa_supplicant *wpa_s)
10579
0
{
10580
0
  struct wpa_bss_tmp_disallowed *tmp;
10581
0
  unsigned int num_bssid = 0;
10582
0
  u8 *bssids;
10583
0
  int ret;
10584
10585
0
  bssids = os_malloc(dl_list_len(&wpa_s->bss_tmp_disallowed) * ETH_ALEN);
10586
0
  if (!bssids)
10587
0
    return -1;
10588
0
  dl_list_for_each(tmp, &wpa_s->bss_tmp_disallowed,
10589
0
       struct wpa_bss_tmp_disallowed, list) {
10590
0
    os_memcpy(&bssids[num_bssid * ETH_ALEN], tmp->bssid,
10591
0
        ETH_ALEN);
10592
0
    num_bssid++;
10593
0
  }
10594
0
  ret = wpa_drv_set_bssid_tmp_disallow(wpa_s, num_bssid, bssids);
10595
0
  os_free(bssids);
10596
0
  return ret;
10597
0
}
10598
10599
10600
static void wpa_bss_tmp_disallow_timeout(void *eloop_ctx, void *timeout_ctx)
10601
0
{
10602
0
  struct wpa_supplicant *wpa_s = eloop_ctx;
10603
0
  struct wpa_bss_tmp_disallowed *tmp, *bss = timeout_ctx;
10604
10605
  /* Make sure the bss is not already freed */
10606
0
  dl_list_for_each(tmp, &wpa_s->bss_tmp_disallowed,
10607
0
       struct wpa_bss_tmp_disallowed, list) {
10608
0
    if (bss == tmp) {
10609
0
      remove_bss_tmp_disallowed_entry(wpa_s, tmp);
10610
0
      wpa_set_driver_tmp_disallow_list(wpa_s);
10611
0
      break;
10612
0
    }
10613
0
  }
10614
0
}
10615
10616
10617
void wpa_bss_tmp_disallow(struct wpa_supplicant *wpa_s, const u8 *bssid,
10618
        unsigned int sec, int rssi_threshold)
10619
0
{
10620
0
  struct wpa_bss_tmp_disallowed *bss;
10621
10622
0
  bss = wpas_get_disallowed_bss(wpa_s, bssid);
10623
0
  if (bss) {
10624
0
    eloop_cancel_timeout(wpa_bss_tmp_disallow_timeout, wpa_s, bss);
10625
0
    goto finish;
10626
0
  }
10627
10628
0
  bss = os_malloc(sizeof(*bss));
10629
0
  if (!bss) {
10630
0
    wpa_printf(MSG_DEBUG,
10631
0
         "Failed to allocate memory for temp disallow BSS");
10632
0
    return;
10633
0
  }
10634
10635
0
  os_memcpy(bss->bssid, bssid, ETH_ALEN);
10636
0
  dl_list_add(&wpa_s->bss_tmp_disallowed, &bss->list);
10637
0
  wpa_set_driver_tmp_disallow_list(wpa_s);
10638
10639
0
finish:
10640
0
  bss->rssi_threshold = rssi_threshold;
10641
0
  eloop_register_timeout(sec, 0, wpa_bss_tmp_disallow_timeout,
10642
0
             wpa_s, bss);
10643
0
}
10644
10645
10646
int wpa_is_bss_tmp_disallowed(struct wpa_supplicant *wpa_s,
10647
            struct wpa_bss *bss)
10648
0
{
10649
0
  struct wpa_bss_tmp_disallowed *disallowed = NULL, *tmp, *prev;
10650
10651
0
  dl_list_for_each_safe(tmp, prev, &wpa_s->bss_tmp_disallowed,
10652
0
       struct wpa_bss_tmp_disallowed, list) {
10653
0
    if (ether_addr_equal(bss->bssid, tmp->bssid)) {
10654
0
      disallowed = tmp;
10655
0
      break;
10656
0
    }
10657
0
  }
10658
0
  if (!disallowed)
10659
0
    return 0;
10660
10661
0
  if (disallowed->rssi_threshold != 0 &&
10662
0
      bss->level > disallowed->rssi_threshold) {
10663
0
    remove_bss_tmp_disallowed_entry(wpa_s, disallowed);
10664
0
    wpa_set_driver_tmp_disallow_list(wpa_s);
10665
0
    return 0;
10666
0
  }
10667
10668
0
  return 1;
10669
0
}
10670
10671
10672
int wpas_enable_mac_addr_randomization(struct wpa_supplicant *wpa_s,
10673
               unsigned int type, const u8 *addr,
10674
               const u8 *mask)
10675
0
{
10676
0
  if ((addr && !mask) || (!addr && mask)) {
10677
0
    wpa_printf(MSG_INFO,
10678
0
         "MAC_ADDR_RAND_SCAN invalid addr/mask combination");
10679
0
    return -1;
10680
0
  }
10681
10682
0
  if (addr && mask && (!(mask[0] & 0x01) || (addr[0] & 0x01))) {
10683
0
    wpa_printf(MSG_INFO,
10684
0
         "MAC_ADDR_RAND_SCAN cannot allow multicast address");
10685
0
    return -1;
10686
0
  }
10687
10688
0
  if (type & MAC_ADDR_RAND_SCAN) {
10689
0
    if (wpas_mac_addr_rand_scan_set(wpa_s, MAC_ADDR_RAND_SCAN,
10690
0
            addr, mask))
10691
0
      return -1;
10692
0
  }
10693
10694
0
  if (type & MAC_ADDR_RAND_SCHED_SCAN) {
10695
0
    if (wpas_mac_addr_rand_scan_set(wpa_s, MAC_ADDR_RAND_SCHED_SCAN,
10696
0
            addr, mask))
10697
0
      return -1;
10698
10699
0
    if (wpa_s->sched_scanning && !wpa_s->pno)
10700
0
      wpas_scan_restart_sched_scan(wpa_s);
10701
0
  }
10702
10703
0
  if (type & MAC_ADDR_RAND_PNO) {
10704
0
    if (wpas_mac_addr_rand_scan_set(wpa_s, MAC_ADDR_RAND_PNO,
10705
0
            addr, mask))
10706
0
      return -1;
10707
10708
0
    if (wpa_s->pno) {
10709
0
      wpas_stop_pno(wpa_s);
10710
0
      wpas_start_pno(wpa_s);
10711
0
    }
10712
0
  }
10713
10714
0
  return 0;
10715
0
}
10716
10717
10718
int wpas_disable_mac_addr_randomization(struct wpa_supplicant *wpa_s,
10719
          unsigned int type)
10720
0
{
10721
0
  wpas_mac_addr_rand_scan_clear(wpa_s, type);
10722
0
  if (wpa_s->pno) {
10723
0
    if (type & MAC_ADDR_RAND_PNO) {
10724
0
      wpas_stop_pno(wpa_s);
10725
0
      wpas_start_pno(wpa_s);
10726
0
    }
10727
0
  } else if (wpa_s->sched_scanning && (type & MAC_ADDR_RAND_SCHED_SCAN)) {
10728
0
    wpas_scan_restart_sched_scan(wpa_s);
10729
0
  }
10730
10731
0
  return 0;
10732
0
}
10733
10734
10735
int wpa_drv_signal_poll(struct wpa_supplicant *wpa_s,
10736
      struct wpa_signal_info *si)
10737
0
{
10738
0
  int res;
10739
10740
0
  if (!wpa_s->driver->signal_poll)
10741
0
    return -1;
10742
10743
0
  res = wpa_s->driver->signal_poll(wpa_s->drv_priv, si);
10744
10745
#ifdef CONFIG_TESTING_OPTIONS
10746
  if (res == 0) {
10747
    struct driver_signal_override *dso;
10748
10749
    dl_list_for_each(dso, &wpa_s->drv_signal_override,
10750
         struct driver_signal_override, list) {
10751
      if (!ether_addr_equal(wpa_s->bssid, dso->bssid))
10752
        continue;
10753
      wpa_printf(MSG_DEBUG,
10754
           "Override driver signal_poll information: current_signal: %d->%d avg_signal: %d->%d avg_beacon_signal: %d->%d current_noise: %d->%d",
10755
           si->data.signal,
10756
           dso->si_current_signal,
10757
           si->data.avg_signal,
10758
           dso->si_avg_signal,
10759
           si->data.avg_beacon_signal,
10760
           dso->si_avg_beacon_signal,
10761
           si->current_noise,
10762
           dso->si_current_noise);
10763
      si->data.signal = dso->si_current_signal;
10764
      si->data.avg_signal = dso->si_avg_signal;
10765
      si->data.avg_beacon_signal = dso->si_avg_beacon_signal;
10766
      si->current_noise = dso->si_current_noise;
10767
      break;
10768
    }
10769
  }
10770
#endif /* CONFIG_TESTING_OPTIONS */
10771
10772
0
  return res;
10773
0
}
10774
10775
10776
struct wpa_scan_results *
10777
wpa_drv_get_scan_results(struct wpa_supplicant *wpa_s, const u8 *bssid)
10778
1.10k
{
10779
1.10k
  struct wpa_scan_results *scan_res;
10780
#ifdef CONFIG_TESTING_OPTIONS
10781
  size_t idx;
10782
#endif /* CONFIG_TESTING_OPTIONS */
10783
10784
1.10k
  if (wpa_s->driver->get_scan_results)
10785
0
    scan_res = wpa_s->driver->get_scan_results(wpa_s->drv_priv,
10786
0
                 bssid);
10787
1.10k
  else if (wpa_s->driver->get_scan_results2)
10788
0
    scan_res = wpa_s->driver->get_scan_results2(wpa_s->drv_priv);
10789
1.10k
  else
10790
1.10k
    return NULL;
10791
10792
10793
#ifdef CONFIG_TESTING_OPTIONS
10794
  for (idx = 0; scan_res && idx < scan_res->num; idx++) {
10795
    struct driver_signal_override *dso;
10796
    struct wpa_scan_res *res = scan_res->res[idx];
10797
10798
    dl_list_for_each(dso, &wpa_s->drv_signal_override,
10799
         struct driver_signal_override, list) {
10800
      if (!ether_addr_equal(res->bssid, dso->bssid))
10801
        continue;
10802
      wpa_printf(MSG_DEBUG,
10803
           "Override driver scan signal level %d->%d for "
10804
           MACSTR,
10805
           res->level, dso->scan_level,
10806
           MAC2STR(res->bssid));
10807
      res->flags |= WPA_SCAN_QUAL_INVALID;
10808
      if (dso->scan_level < 0)
10809
        res->flags |= WPA_SCAN_LEVEL_DBM;
10810
      else
10811
        res->flags &= ~WPA_SCAN_LEVEL_DBM;
10812
      res->level = dso->scan_level;
10813
      break;
10814
    }
10815
  }
10816
#endif /* CONFIG_TESTING_OPTIONS */
10817
10818
0
  return scan_res;
10819
1.10k
}
10820
10821
10822
bool wpas_ap_link_address(struct wpa_supplicant *wpa_s, const u8 *addr)
10823
0
{
10824
0
  int i;
10825
10826
0
  if (!wpa_s->valid_links)
10827
0
    return false;
10828
10829
0
  for_each_link(wpa_s->valid_links, i) {
10830
0
    if (ether_addr_equal(wpa_s->links[i].bssid, addr))
10831
0
      return true;
10832
0
  }
10833
10834
0
  return false;
10835
0
}
10836
10837
10838
int wpa_drv_send_action(struct wpa_supplicant *wpa_s, unsigned int freq,
10839
      unsigned int wait, const u8 *dst, const u8 *src,
10840
      const u8 *bssid, const u8 *data, size_t data_len,
10841
      int no_cck)
10842
21
{
10843
21
  if (!wpa_s->driver->send_action)
10844
21
    return -1;
10845
10846
0
  if (data_len > 0 && data[0] != WLAN_ACTION_PUBLIC) {
10847
0
    if (wpas_ap_link_address(wpa_s, dst))
10848
0
      dst = wpa_s->ap_mld_addr;
10849
10850
0
    if (wpas_ap_link_address(wpa_s, bssid))
10851
0
      bssid = wpa_s->ap_mld_addr;
10852
0
  }
10853
10854
0
  return wpa_s->driver->send_action(wpa_s->drv_priv, freq, wait, dst, src,
10855
0
            bssid, data, data_len, no_cck, -1);
10856
21
}
10857
10858
10859
bool wpas_is_6ghz_supported(struct wpa_supplicant *wpa_s, bool only_enabled)
10860
0
{
10861
0
  struct hostapd_channel_data *chnl;
10862
0
  int i, j;
10863
10864
0
  for (i = 0; i < wpa_s->hw.num_modes; i++) {
10865
0
    if (wpa_s->hw.modes[i].mode == HOSTAPD_MODE_IEEE80211A) {
10866
0
      chnl = wpa_s->hw.modes[i].channels;
10867
0
      for (j = 0; j < wpa_s->hw.modes[i].num_channels; j++) {
10868
0
        if (only_enabled &&
10869
0
            (chnl[j].flag & HOSTAPD_CHAN_DISABLED))
10870
0
          continue;
10871
0
        if (is_6ghz_freq(chnl[j].freq))
10872
0
          return true;
10873
0
      }
10874
0
    }
10875
0
  }
10876
10877
0
  return false;
10878
0
}
10879
10880
10881
bool wpas_ap_supports_rsn_overriding(struct wpa_supplicant *wpa_s,
10882
             struct wpa_bss *bss)
10883
0
{
10884
0
  int i;
10885
10886
0
  if (!bss)
10887
0
    return false;
10888
0
  if (wpa_bss_get_vendor_ie(bss, RSNE_OVERRIDE_IE_VENDOR_TYPE) ||
10889
0
      wpa_bss_get_vendor_ie(bss, RSNE_OVERRIDE_2_IE_VENDOR_TYPE))
10890
0
    return true;
10891
10892
0
  if (!wpa_s->valid_links)
10893
0
    return false;
10894
10895
0
  for_each_link(wpa_s->valid_links, i) {
10896
0
    if (wpa_s->links[i].bss &&
10897
0
        (wpa_bss_get_vendor_ie(wpa_s->links[i].bss,
10898
0
             RSNE_OVERRIDE_IE_VENDOR_TYPE) ||
10899
0
         wpa_bss_get_vendor_ie(wpa_s->links[i].bss,
10900
0
             RSNE_OVERRIDE_2_IE_VENDOR_TYPE)))
10901
0
      return true;
10902
0
  }
10903
10904
0
  return false;
10905
0
}
10906
10907
10908
bool wpas_ap_supports_rsn_overriding_2(struct wpa_supplicant *wpa_s,
10909
               struct wpa_bss *bss)
10910
0
{
10911
0
  int i;
10912
10913
0
  if (!bss)
10914
0
    return false;
10915
0
  if (wpa_bss_get_vendor_ie(bss, RSNE_OVERRIDE_2_IE_VENDOR_TYPE))
10916
0
    return true;
10917
10918
0
  if (!wpa_s->valid_links)
10919
0
    return false;
10920
10921
0
  for_each_link(wpa_s->valid_links, i) {
10922
0
    if (wpa_s->links[i].bss &&
10923
0
        wpa_bss_get_vendor_ie(wpa_s->links[i].bss,
10924
0
            RSNE_OVERRIDE_2_IE_VENDOR_TYPE))
10925
0
      return true;
10926
0
  }
10927
10928
0
  return false;
10929
0
}
10930
10931
10932
int wpas_get_owe_trans_network(const u8 *owe_ie, const u8 **bssid,
10933
             const u8 **ssid, size_t *ssid_len)
10934
0
{
10935
#ifdef CONFIG_OWE
10936
  const u8 *pos, *end;
10937
  u8 ssid_len_tmp;
10938
10939
  if (!owe_ie)
10940
    return -1;
10941
10942
  pos = owe_ie + 6;
10943
  end = owe_ie + 2 + owe_ie[1];
10944
10945
  if (end - pos < ETH_ALEN + 1)
10946
    return -1;
10947
  *bssid = pos;
10948
  pos += ETH_ALEN;
10949
  ssid_len_tmp = *pos++;
10950
  if (end - pos < ssid_len_tmp || ssid_len_tmp > SSID_MAX_LEN)
10951
    return -1;
10952
10953
  *ssid = pos;
10954
  *ssid_len = ssid_len_tmp;
10955
10956
  return 0;
10957
#else /* CONFIG_OWE */
10958
0
  return -1;
10959
0
#endif /* CONFIG_OWE */
10960
0
}
10961
10962
10963
void wpas_update_dfs_ap_info(struct wpa_supplicant *wpa_s, int freq,
10964
           enum chan_width ap_ch_width,
10965
           bool disconnect_evt)
10966
0
{
10967
0
  if (disconnect_evt) {
10968
0
    wpa_printf(MSG_DEBUG, "Disconnect event of DFS AP");
10969
0
    wpa_s->sta_connected_freq = 0;
10970
0
    wpa_s->sta_connected_chan_width = CHAN_WIDTH_UNKNOWN;
10971
0
  } else {
10972
0
    wpa_s->sta_connected_freq = freq;
10973
0
    wpa_s->sta_connected_chan_width = ap_ch_width;
10974
0
  }
10975
0
  wpa_s->dfs_ap_connected = !disconnect_evt;
10976
10977
#ifdef CONFIG_P2P
10978
  if (wpa_s->global->p2p)
10979
    p2p_update_dfs_ap_info(wpa_s->global->p2p, freq, ap_ch_width,
10980
               disconnect_evt);
10981
#endif /* CONFIG_P2P */
10982
0
}
10983
10984
10985
void wpas_configure_frame_filters(struct wpa_supplicant *wpa_s)
10986
0
{
10987
0
  struct wpa_bss *bss = wpa_s->current_bss;
10988
0
  u32 filter = 0;
10989
0
  bool hs20, proxy_arp_capa;
10990
10991
0
  if (!bss)
10992
0
    return;
10993
10994
0
#ifdef CONFIG_HS20
10995
0
  hs20 = is_hs20_network(wpa_s, wpa_s->current_ssid, bss);
10996
#else /* CONFIG_HS20 */
10997
  hs20 = false;
10998
#endif /* CONFIG_HS20 */
10999
11000
0
  if (wpa_s->current_ssid &&
11001
0
      wpa_s->current_ssid->drop_unicast_ip_in_l2_multicast) {
11002
0
    filter |= WPA_DATA_FRAME_FILTER_FLAG_GTK;
11003
0
  } else if (!hs20) {
11004
    /* Not configuring frame filtering - BSS is not a Hotspot 2.0
11005
     * network */
11006
0
    return;
11007
0
  } else {
11008
0
#ifdef CONFIG_HS20
11009
0
    const u8 *ie;
11010
11011
0
    ie = wpa_bss_get_vendor_ie(bss, HS20_IE_VENDOR_TYPE);
11012
11013
    /* Check if DGAF disabled bit is zero (5th byte in the IE) */
11014
0
    if (!ie || ie[1] < 5)
11015
0
      wpa_printf(MSG_DEBUG,
11016
0
           "Not configuring frame filtering - Can't extract DGAF bit");
11017
0
    else if (!(ie[6] & HS20_DGAF_DISABLED))
11018
0
      filter |= WPA_DATA_FRAME_FILTER_FLAG_GTK;
11019
0
#endif /* CONFIG_HS20 */
11020
0
  }
11021
11022
0
  proxy_arp_capa = wpa_bss_ext_capab(bss, WLAN_EXT_CAPAB_PROXY_ARP);
11023
11024
0
  if ((hs20 && proxy_arp_capa) ||
11025
0
      (wpa_s->current_ssid &&
11026
0
       wpa_s->current_ssid->always_use_proxy_arp == 2) ||
11027
0
      (proxy_arp_capa && wpa_s->current_ssid &&
11028
0
       wpa_s->current_ssid->always_use_proxy_arp == 1))
11029
0
    filter |= WPA_DATA_FRAME_FILTER_FLAG_ARP |
11030
0
      WPA_DATA_FRAME_FILTER_FLAG_NA;
11031
11032
0
  wpa_drv_configure_frame_filters(wpa_s, filter);
11033
0
}
11034
11035
11036
/**
11037
 * wpas_security_profile_active - Is Security Profile element active?
11038
 * @wpa_s: Pointer to wpa_supplicant data
11039
 *
11040
 * Returns true when Security Profile element functionality is enabled:
11041
 *   - wpa_supplicant-SME path (WPA_DRIVER_FLAGS_SME): always active when the
11042
 *     AP
11043
 *     advertises the element.
11044
 *   - Driver-SME path: only active when the driver explicitly indicates
11045
 *     support via WPA_DRIVER_FLAGS2_SECURITY_PROFILE.
11046
 *     Without this flag the feature is fully disabled even if the AP
11047
 *     advertises the Security Profile element.
11048
 *
11049
 * Use this helper as the single gate for all Security Profile element parsing,
11050
 * override, and validation logic so that the driver-SME path without driver
11051
 * support behaves identically to a legacy STA.
11052
 */
11053
bool wpas_security_profile_active(struct wpa_supplicant *wpa_s)
11054
0
{
11055
0
  if (!wpa_s->conf->security_profiles)
11056
0
    return false;
11057
0
  if (wpa_s->drv_flags & WPA_DRIVER_FLAGS_SME)
11058
0
    return true; /* wpa_supplicant-SME: always active */
11059
  /* driver-SME: only when driver advertises support */
11060
0
  return !!(wpa_s->drv_flags2 & WPA_DRIVER_FLAGS2_SECURITY_PROFILE);
11061
0
}