5c19a34b8834acc25e8377bca343e38b347acc8e
[dragonfly.git] / usr.sbin / 802_11 / wpa_supplicant / driver_dragonfly.c
1 /*
2  * WPA Supplicant - driver interaction with BSD net80211 layer
3  * Copyright (c) 2004, Sam Leffler <sam@errno.com>
4  *
5  * This program is free software; you can redistribute it and/or modify
6  * it under the terms of the GNU General Public License version 2 as
7  * published by the Free Software Foundation.
8  *
9  * Alternatively, this software may be distributed under the terms of BSD
10  * license.
11  *
12  * See README and COPYING for more details.
13  *
14  * $FreeBSD: head/usr.sbin/wpa/wpa_supplicant/driver_freebsd.c 189263 2009-03-02 02:28:22Z sam $
15  * $DragonFly$
16  */
17
18 #include <stdlib.h>
19 #include <stdio.h>
20 #include <unistd.h>
21 #include <string.h>
22 #include <sys/ioctl.h>
23 #include <errno.h>
24
25 #include "common.h"
26 #include "drivers/driver.h"
27 #include "eloop.h"
28 #include "l2_packet.h"
29 #include "ieee802_11_defs.h"
30
31 #include <sys/socket.h>
32 #include <net/if.h>
33 #include <net/ethernet.h>
34
35 #include <netproto/802_11/ieee80211_ioctl.h>
36
37 struct wpa_driver_bsd_data {
38         int     sock;                   /* open socket for 802.11 ioctls */
39         int     route;                  /* routing socket for events */
40         char    ifname[IFNAMSIZ+1];     /* interface name */
41         unsigned int ifindex;           /* interface index */
42         void    *ctx;
43         int     prev_roaming;           /* roaming state to restore on deinit */
44         int     prev_privacy;           /* privacy state to restore on deinit */
45         int     prev_wpa;               /* wpa state to restore on deinit */
46         int     prev_scanvalid;         /* scan valid to restore on deinit */
47         uint8_t lastssid[IEEE80211_NWID_LEN];
48         int     lastssid_len;
49         uint32_t drivercaps;            /* general driver capabilities */
50         uint32_t cryptocaps;            /* hardware crypto support */
51 };
52
53 static int
54 set80211var(struct wpa_driver_bsd_data *drv, int op, const void *arg, int arg_len)
55 {
56         struct ieee80211req ireq;
57
58         memset(&ireq, 0, sizeof(ireq));
59         strncpy(ireq.i_name, drv->ifname, IFNAMSIZ);
60         ireq.i_type = op;
61         ireq.i_len = arg_len;
62         ireq.i_data = (void *) arg;
63
64         if (ioctl(drv->sock, SIOCS80211, &ireq) < 0) {
65                 fprintf(stderr, "ioctl[SIOCS80211, op %u, len %u]: %s\n",
66                         op, arg_len, strerror(errno));
67                 return -1;
68         }
69         return 0;
70 }
71
72 static int
73 get80211var(struct wpa_driver_bsd_data *drv, int op, void *arg, int arg_len)
74 {
75         struct ieee80211req ireq;
76
77         memset(&ireq, 0, sizeof(ireq));
78         strncpy(ireq.i_name, drv->ifname, IFNAMSIZ);
79         ireq.i_type = op;
80         ireq.i_len = arg_len;
81         ireq.i_data = arg;
82
83         if (ioctl(drv->sock, SIOCG80211, &ireq) < 0) {
84                 fprintf(stderr, "ioctl[SIOCG80211, op %u, len %u]: %s\n",
85                         op, arg_len, strerror(errno));
86                 return -1;
87         }
88         return ireq.i_len;
89 }
90
91 static int
92 set80211param(struct wpa_driver_bsd_data *drv, int op, int arg)
93 {
94         struct ieee80211req ireq;
95
96         memset(&ireq, 0, sizeof(ireq));
97         strncpy(ireq.i_name, drv->ifname, IFNAMSIZ);
98         ireq.i_type = op;
99         ireq.i_val = arg;
100
101         if (ioctl(drv->sock, SIOCS80211, &ireq) < 0) {
102                 fprintf(stderr, "ioctl[SIOCS80211, op %u, arg 0x%x]: %s\n",
103                         op, arg, strerror(errno));
104                 return -1;
105         }
106         return 0;
107 }
108
109 static int
110 get80211param(struct wpa_driver_bsd_data *drv, int op)
111 {
112         struct ieee80211req ireq;
113
114         memset(&ireq, 0, sizeof(ireq));
115         strncpy(ireq.i_name, drv->ifname, IFNAMSIZ);
116         ireq.i_type = op;
117
118         if (ioctl(drv->sock, SIOCG80211, &ireq) < 0) {
119                 fprintf(stderr, "ioctl[SIOCG80211, op %u]: %s\n",
120                         op, strerror(errno));
121                 return -1;
122         }
123         return ireq.i_val;
124 }
125
126 static int
127 getifflags(struct wpa_driver_bsd_data *drv, int *flags)
128 {
129         struct ifreq ifr;
130
131         memset(&ifr, 0, sizeof(ifr));
132         strncpy(ifr.ifr_name, drv->ifname, sizeof (ifr.ifr_name));
133         if (ioctl(drv->sock, SIOCGIFFLAGS, (caddr_t)&ifr) < 0) {
134                 perror("SIOCGIFFLAGS");
135                 return errno;
136         }
137         *flags = (ifr.ifr_flags & 0xffff) | (ifr.ifr_flagshigh << 16);
138         return 0;
139 }
140
141 static int
142 setifflags(struct wpa_driver_bsd_data *drv, int flags)
143 {
144         struct ifreq ifr;
145
146         memset(&ifr, 0, sizeof(ifr));
147         strncpy(ifr.ifr_name, drv->ifname, sizeof (ifr.ifr_name));
148         ifr.ifr_flags = flags & 0xffff;
149         ifr.ifr_flagshigh = flags >> 16;
150         if (ioctl(drv->sock, SIOCSIFFLAGS, (caddr_t)&ifr) < 0) {
151                 perror("SIOCSIFFLAGS");
152                 return errno;
153         }
154         return 0;
155 }
156
157 static int
158 wpa_driver_bsd_get_bssid(void *priv, u8 *bssid)
159 {
160         struct wpa_driver_bsd_data *drv = priv;
161
162         return get80211var(drv, IEEE80211_IOC_BSSID,
163                 bssid, IEEE80211_ADDR_LEN) < 0 ? -1 : 0;
164 }
165
166 #if 0
167 static int
168 wpa_driver_bsd_set_bssid(void *priv, const char *bssid)
169 {
170         struct wpa_driver_bsd_data *drv = priv;
171
172         return set80211var(drv, IEEE80211_IOC_BSSID,
173                 bssid, IEEE80211_ADDR_LEN);
174 }
175 #endif
176
177 static int
178 wpa_driver_bsd_get_ssid(void *priv, u8 *ssid)
179 {
180         struct wpa_driver_bsd_data *drv = priv;
181
182         return get80211var(drv, IEEE80211_IOC_SSID,
183                 ssid, IEEE80211_NWID_LEN);
184 }
185
186 static int
187 wpa_driver_bsd_set_ssid(void *priv, const char *ssid,
188                              size_t ssid_len)
189 {
190         struct wpa_driver_bsd_data *drv = priv;
191
192         return set80211var(drv, IEEE80211_IOC_SSID, ssid, ssid_len);
193 }
194
195 static int
196 wpa_driver_bsd_set_wpa_ie(struct wpa_driver_bsd_data *drv,
197         const char *wpa_ie, size_t wpa_ie_len)
198 {
199         struct ieee80211req ireq;
200
201         memset(&ireq, 0, sizeof(ireq));
202         strncpy(ireq.i_name, drv->ifname, IFNAMSIZ);
203         ireq.i_type = IEEE80211_IOC_APPIE;
204         ireq.i_val = IEEE80211_APPIE_WPA;
205         ireq.i_len = wpa_ie_len;
206         ireq.i_data = (void *) wpa_ie;
207         if (ioctl(drv->sock, SIOCS80211, &ireq) < 0) {
208                 fprintf(stderr,
209                     "ioctl[IEEE80211_IOC_APPIE:IEEE80211_APPIE_WPA]: %s\n",
210                     strerror(errno));
211                 return -1;
212         }
213         return 0;
214 }
215
216 static int
217 wpa_driver_bsd_set_wpa_internal(void *priv, int wpa, int privacy)
218 {
219         struct wpa_driver_bsd_data *drv = priv;
220         int ret = 0;
221
222         wpa_printf(MSG_DEBUG, "%s: wpa=%d privacy=%d",
223                 __FUNCTION__, wpa, privacy);
224
225         if (!wpa && wpa_driver_bsd_set_wpa_ie(drv, NULL, 0) < 0)
226                 ret = -1;
227         if (set80211param(drv, IEEE80211_IOC_PRIVACY, privacy) < 0)
228                 ret = -1;
229         if (set80211param(drv, IEEE80211_IOC_WPA, wpa) < 0)
230                 ret = -1;
231
232         return ret;
233 }
234
235 static int
236 wpa_driver_bsd_set_wpa(void *priv, int enabled)
237 {
238         wpa_printf(MSG_DEBUG, "%s: enabled=%d", __FUNCTION__, enabled);
239
240         return wpa_driver_bsd_set_wpa_internal(priv, enabled ? 3 : 0, enabled);
241 }
242
243 static int
244 wpa_driver_bsd_del_key(struct wpa_driver_bsd_data *drv, int key_idx,
245                        const unsigned char *addr)
246 {
247         struct ieee80211req_del_key wk;
248
249         memset(&wk, 0, sizeof(wk));
250         if (addr != NULL &&
251             bcmp(addr, "\xff\xff\xff\xff\xff\xff", IEEE80211_ADDR_LEN) != 0) {
252                 struct ether_addr ea;
253
254                 memcpy(&ea, addr, IEEE80211_ADDR_LEN);
255                 wpa_printf(MSG_DEBUG, "%s: addr=%s keyidx=%d",
256                         __func__, ether_ntoa(&ea), key_idx);
257                 memcpy(wk.idk_macaddr, addr, IEEE80211_ADDR_LEN);
258                 wk.idk_keyix = (uint8_t) IEEE80211_KEYIX_NONE;
259         } else {
260                 wpa_printf(MSG_DEBUG, "%s: keyidx=%d", __func__, key_idx);
261                 wk.idk_keyix = key_idx;
262         }
263         return set80211var(drv, IEEE80211_IOC_DELKEY, &wk, sizeof(wk));
264 }
265
266 static int
267 wpa_driver_bsd_set_key(void *priv, wpa_alg alg,
268                        const unsigned char *addr, int key_idx, int set_tx,
269                        const u8 *seq, size_t seq_len,
270                        const u8 *key, size_t key_len)
271 {
272         struct wpa_driver_bsd_data *drv = priv;
273         struct ieee80211req_key wk;
274         struct ether_addr ea;
275         char *alg_name;
276         u_int8_t cipher;
277
278         if (alg == WPA_ALG_NONE)
279                 return wpa_driver_bsd_del_key(drv, key_idx, addr);
280
281         switch (alg) {
282         case WPA_ALG_WEP:
283                 alg_name = "WEP";
284                 cipher = IEEE80211_CIPHER_WEP;
285                 break;
286         case WPA_ALG_TKIP:
287                 alg_name = "TKIP";
288                 cipher = IEEE80211_CIPHER_TKIP;
289                 break;
290         case WPA_ALG_CCMP:
291                 alg_name = "CCMP";
292                 cipher = IEEE80211_CIPHER_AES_CCM;
293                 break;
294         default:
295                 wpa_printf(MSG_DEBUG, "%s: unknown/unsupported algorithm %d",
296                         __func__, alg);
297                 return -1;
298         }
299
300         memcpy(&ea, addr, IEEE80211_ADDR_LEN);
301         wpa_printf(MSG_DEBUG,
302             "%s: alg=%s addr=%s key_idx=%d set_tx=%d seq_len=%zu key_len=%zu",
303             __func__, alg_name, ether_ntoa(&ea), key_idx, set_tx,
304             seq_len, key_len);
305
306         if (seq_len > sizeof(u_int64_t)) {
307                 wpa_printf(MSG_DEBUG, "%s: seq_len %zu too big",
308                         __func__, seq_len);
309                 return -2;
310         }
311         if (key_len > sizeof(wk.ik_keydata)) {
312                 wpa_printf(MSG_DEBUG, "%s: key length %zu too big",
313                         __func__, key_len);
314                 return -3;
315         }
316
317         memset(&wk, 0, sizeof(wk));
318         wk.ik_type = cipher;
319         wk.ik_flags = IEEE80211_KEY_RECV;
320         if (set_tx)
321                 wk.ik_flags |= IEEE80211_KEY_XMIT;
322         memcpy(wk.ik_macaddr, addr, IEEE80211_ADDR_LEN);
323         /*
324          * Deduce whether group/global or unicast key by checking
325          * the address (yech).  Note also that we can only mark global
326          * keys default; doing this for a unicast key is an error.
327          */
328         if (bcmp(addr, "\xff\xff\xff\xff\xff\xff", IEEE80211_ADDR_LEN) == 0) {
329                 wk.ik_flags |= IEEE80211_KEY_GROUP;
330                 wk.ik_keyix = key_idx;
331         } else {
332                 wk.ik_keyix = (key_idx == 0 ? IEEE80211_KEYIX_NONE : key_idx);
333         }
334         if (wk.ik_keyix != IEEE80211_KEYIX_NONE && set_tx)
335                 wk.ik_flags |= IEEE80211_KEY_DEFAULT;
336         wk.ik_keylen = key_len;
337         memcpy(&wk.ik_keyrsc, seq, seq_len);
338         wk.ik_keyrsc = le64toh(wk.ik_keyrsc);
339         memcpy(wk.ik_keydata, key, key_len);
340
341         return set80211var(drv, IEEE80211_IOC_WPAKEY, &wk, sizeof(wk));
342 }
343
344 static int
345 wpa_driver_bsd_set_countermeasures(void *priv, int enabled)
346 {
347         struct wpa_driver_bsd_data *drv = priv;
348
349         wpa_printf(MSG_DEBUG, "%s: enabled=%d", __func__, enabled);
350         return set80211param(drv, IEEE80211_IOC_COUNTERMEASURES, enabled);
351 }
352
353
354 static int
355 wpa_driver_bsd_set_drop_unencrypted(void *priv, int enabled)
356 {
357         struct wpa_driver_bsd_data *drv = priv;
358
359         wpa_printf(MSG_DEBUG, "%s: enabled=%d", __func__, enabled);
360         return set80211param(drv, IEEE80211_IOC_DROPUNENCRYPTED, enabled);
361 }
362
363 static int
364 wpa_driver_bsd_deauthenticate(void *priv, const u8 *addr, int reason_code)
365 {
366         struct wpa_driver_bsd_data *drv = priv;
367         struct ieee80211req_mlme mlme;
368
369         drv->lastssid_len = 0;
370
371         wpa_printf(MSG_DEBUG, "%s", __func__);
372         memset(&mlme, 0, sizeof(mlme));
373         mlme.im_op = IEEE80211_MLME_DEAUTH;
374         mlme.im_reason = reason_code;
375         memcpy(mlme.im_macaddr, addr, IEEE80211_ADDR_LEN);
376         return set80211var(drv, IEEE80211_IOC_MLME, &mlme, sizeof(mlme));
377 }
378
379 static int
380 wpa_driver_bsd_disassociate(void *priv, const u8 *addr, int reason_code)
381 {
382         struct wpa_driver_bsd_data *drv = priv;
383         struct ieee80211req_mlme mlme;
384
385         drv->lastssid_len = 0;
386
387         wpa_printf(MSG_DEBUG, "%s", __func__);
388         memset(&mlme, 0, sizeof(mlme));
389         mlme.im_op = IEEE80211_MLME_DISASSOC;
390         mlme.im_reason = reason_code;
391         memcpy(mlme.im_macaddr, addr, IEEE80211_ADDR_LEN);
392         return set80211var(drv, IEEE80211_IOC_MLME, &mlme, sizeof(mlme));
393 }
394
395 static int
396 wpa_driver_bsd_associate(void *priv, struct wpa_driver_associate_params *params)
397 {
398         struct wpa_driver_bsd_data *drv = priv;
399         struct ieee80211req_mlme mlme;
400         int privacy;
401
402         wpa_printf(MSG_DEBUG,
403                 "%s: ssid '%.*s' wpa ie len %u pairwise %u group %u key mgmt %u"
404                 , __func__
405                 , params->ssid_len, params->ssid
406                 , params->wpa_ie_len
407                 , params->pairwise_suite
408                 , params->group_suite
409                 , params->key_mgmt_suite
410         );
411
412         /* XXX error handling is wrong but unclear what to do... */
413         if (wpa_driver_bsd_set_wpa_ie(drv, params->wpa_ie, params->wpa_ie_len) < 0)
414                 return -1;
415
416         privacy = !(params->pairwise_suite == CIPHER_NONE &&
417             params->group_suite == CIPHER_NONE &&
418             params->key_mgmt_suite == KEY_MGMT_NONE &&
419             params->wpa_ie_len == 0);
420         wpa_printf(MSG_DEBUG, "%s: set PRIVACY %u", __func__, privacy);
421
422         if (set80211param(drv, IEEE80211_IOC_PRIVACY, privacy) < 0)
423                 return -1;
424
425         if (params->wpa_ie_len &&
426             set80211param(drv, IEEE80211_IOC_WPA,
427                           params->wpa_ie[0] == WLAN_EID_RSN ? 2 : 1) < 0)
428                 return -1;
429
430         memset(&mlme, 0, sizeof(mlme));
431         mlme.im_op = IEEE80211_MLME_ASSOC;
432         if (params->ssid != NULL)
433                 memcpy(mlme.im_ssid, params->ssid, params->ssid_len);
434         mlme.im_ssid_len = params->ssid_len;
435         if (params->bssid != NULL)
436                 memcpy(mlme.im_macaddr, params->bssid, IEEE80211_ADDR_LEN);
437         if (set80211var(drv, IEEE80211_IOC_MLME, &mlme, sizeof(mlme)) < 0)
438                 return -1;
439         memcpy(drv->lastssid, params->ssid, params->ssid_len);
440         drv->lastssid_len = params->ssid_len;
441         return 0;
442 }
443
444 static int
445 wpa_driver_bsd_set_auth_alg(void *priv, int auth_alg)
446 {
447         struct wpa_driver_bsd_data *drv = priv;
448         int authmode;
449
450         if ((auth_alg & AUTH_ALG_OPEN_SYSTEM) &&
451             (auth_alg & AUTH_ALG_SHARED_KEY))
452                 authmode = IEEE80211_AUTH_AUTO;
453         else if (auth_alg & AUTH_ALG_SHARED_KEY)
454                 authmode = IEEE80211_AUTH_SHARED;
455         else
456                 authmode = IEEE80211_AUTH_OPEN;
457
458         wpa_printf(MSG_DEBUG, "%s alg 0x%x authmode %u",
459                 __func__, auth_alg, authmode);
460
461         return set80211param(drv, IEEE80211_IOC_AUTHMODE, authmode);
462 }
463
464 static int
465 wpa_driver_bsd_scan(void *priv, const u8 *ssid, size_t ssid_len)
466 {
467         struct wpa_driver_bsd_data *drv = priv;
468         struct ieee80211_scan_req sr;
469         int flags;
470
471         /* XXX not true but easiest to perpetuate the myth */
472         /* NB: interface must be marked UP to do a scan */
473         if (getifflags(drv, &flags) != 0) {
474                 wpa_printf(MSG_DEBUG, "%s did not mark interface UP", __func__);
475                 return -1;
476         }
477         if ((flags & IFF_UP) == 0 && setifflags(drv, flags | IFF_UP) != 0) {
478                 wpa_printf(MSG_DEBUG, "%s unable to mark interface UP",
479                     __func__);
480                 return -1;
481         }
482
483         memset(&sr, 0, sizeof(sr));
484         sr.sr_flags = IEEE80211_IOC_SCAN_ACTIVE
485                     | IEEE80211_IOC_SCAN_ONCE
486                     | IEEE80211_IOC_SCAN_NOJOIN
487                     ;
488         sr.sr_duration = IEEE80211_IOC_SCAN_FOREVER;
489         if (ssid_len != 0) {
490                 /* XXX ssid_len must be <= IEEE80211_NWID_LEN */
491                 memcpy(sr.sr_ssid[sr.sr_nssid].ssid, ssid, ssid_len);
492                 sr.sr_ssid[sr.sr_nssid].len = ssid_len;
493                 sr.sr_nssid++;
494         }
495         if (drv->lastssid_len != 0 &&
496             (drv->lastssid_len != ssid_len ||
497              memcmp(drv->lastssid, ssid, ssid_len) != 0)) {
498                 /*
499                  * If we are scanning because we received a deauth
500                  * and the scan cache is warm then we'll find the
501                  * ap there and short circuit a full-blown scan.
502                  */
503                 memcpy(sr.sr_ssid[sr.sr_nssid].ssid, drv->lastssid,
504                     drv->lastssid_len);
505                 sr.sr_ssid[sr.sr_nssid].len = drv->lastssid_len;
506                 sr.sr_nssid++;
507                 /* NB: clear so we don't retry w/o associating first */
508                 drv->lastssid_len = 0;
509         }
510         if (sr.sr_nssid != 0)           /* NB: check scan cache first */
511                 sr.sr_flags |= IEEE80211_IOC_SCAN_CHECK;
512
513         /* NB: net80211 delivers a scan complete event so no need to poll */
514         return set80211var(drv, IEEE80211_IOC_SCAN_REQ, &sr, sizeof(sr));
515 }
516
517 #include <net/route.h>
518 #include <netproto/802_11/ieee80211_dragonfly.h>
519
520 static void
521 wpa_driver_bsd_event_receive(int sock, void *ctx, void *sock_ctx)
522 {
523         struct wpa_driver_bsd_data *drv = sock_ctx;
524         char buf[2048];
525         struct if_announcemsghdr *ifan;
526         struct if_msghdr *ifm;
527         struct rt_msghdr *rtm;
528         union wpa_event_data event;
529         struct ieee80211_michael_event *mic;
530         int n;
531
532         n = read(sock, buf, sizeof(buf));
533         if (n < 0) {
534                 if (errno != EINTR && errno != EAGAIN)
535                         perror("read(PF_ROUTE)");
536                 return;
537         }
538
539         rtm = (struct rt_msghdr *) buf;
540         if (rtm->rtm_version != RTM_VERSION) {
541                 wpa_printf(MSG_DEBUG, "Routing message version %d not "
542                         "understood\n", rtm->rtm_version);
543                 return;
544         }
545         memset(&event, 0, sizeof(event));
546         switch (rtm->rtm_type) {
547         case RTM_IFANNOUNCE:
548                 ifan = (struct if_announcemsghdr *) rtm;
549                 if (ifan->ifan_index != drv->ifindex)
550                         break;
551                 strlcpy(event.interface_status.ifname, drv->ifname,
552                         sizeof(event.interface_status.ifname));
553                 switch (ifan->ifan_what) {
554                 case IFAN_DEPARTURE:
555                         event.interface_status.ievent = EVENT_INTERFACE_REMOVED;
556                 default:
557                         return;
558                 }
559                 wpa_printf(MSG_DEBUG, "RTM_IFANNOUNCE: Interface '%s' %s",
560                            event.interface_status.ifname,
561                            ifan->ifan_what == IFAN_DEPARTURE ?
562                                 "removed" : "added");
563                 wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &event);
564                 break;
565         case RTM_IEEE80211:
566                 ifan = (struct if_announcemsghdr *) rtm;
567                 if (ifan->ifan_index != drv->ifindex)
568                         break;
569                 switch (ifan->ifan_what) {
570                 case RTM_IEEE80211_ASSOC:
571                 case RTM_IEEE80211_REASSOC:
572                         wpa_supplicant_event(ctx, EVENT_ASSOC, NULL);
573                         break;
574                 case RTM_IEEE80211_DISASSOC:
575                         wpa_supplicant_event(ctx, EVENT_DISASSOC, NULL);
576                         break;
577                 case RTM_IEEE80211_SCAN:
578                         wpa_supplicant_event(ctx, EVENT_SCAN_RESULTS, NULL);
579                         break;
580                 case RTM_IEEE80211_REPLAY:
581                         /* ignore */
582                         break;
583                 case RTM_IEEE80211_MICHAEL:
584                         mic = (struct ieee80211_michael_event *) &ifan[1];
585                         wpa_printf(MSG_DEBUG,
586                                 "Michael MIC failure wireless event: "
587                                 "keyix=%u src_addr=" MACSTR, mic->iev_keyix,
588                                 MAC2STR(mic->iev_src));
589
590                         memset(&event, 0, sizeof(event));
591                         event.michael_mic_failure.unicast =
592                                 !IEEE80211_IS_MULTICAST(mic->iev_dst);
593                         wpa_supplicant_event(ctx, EVENT_MICHAEL_MIC_FAILURE,
594                                 &event);
595                         break;
596                 }
597                 break;
598         case RTM_IFINFO:
599                 ifm = (struct if_msghdr *) rtm;
600                 if (ifm->ifm_index != drv->ifindex)
601                         break;
602                 if ((rtm->rtm_flags & RTF_UP) == 0) {
603                         strlcpy(event.interface_status.ifname, drv->ifname,
604                                 sizeof(event.interface_status.ifname));
605                         event.interface_status.ievent = EVENT_INTERFACE_REMOVED;
606                         wpa_printf(MSG_DEBUG, "RTM_IFINFO: Interface '%s' DOWN",
607                                    event.interface_status.ifname);
608                         wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &event);
609                 }
610                 break;
611         }
612 }
613
614 /* Compare function for sorting scan results. Return >0 if @b is consider
615  * better. */
616 static int
617 wpa_scan_result_compar(const void *a, const void *b)
618 {
619         const struct wpa_scan_result *wa = a;
620         const struct wpa_scan_result *wb = b;
621
622         /* WPA/WPA2 support preferred */
623         if ((wb->wpa_ie_len || wb->rsn_ie_len) &&
624             !(wa->wpa_ie_len || wa->rsn_ie_len))
625                 return 1;
626         if (!(wb->wpa_ie_len || wb->rsn_ie_len) &&
627             (wa->wpa_ie_len || wa->rsn_ie_len))
628                 return -1;
629
630         /* privacy support preferred */
631         if ((wa->caps & IEEE80211_CAPINFO_PRIVACY) &&
632             (wb->caps & IEEE80211_CAPINFO_PRIVACY) == 0)
633                 return 1;
634         if ((wa->caps & IEEE80211_CAPINFO_PRIVACY) == 0 &&
635             (wb->caps & IEEE80211_CAPINFO_PRIVACY))
636                 return -1;
637
638         /* best/max rate preferred if signal level close enough XXX */
639         if (wa->maxrate != wb->maxrate && abs(wb->level - wa->level) < 5)
640                 return wb->maxrate - wa->maxrate;
641
642         /* use freq for channel preference */
643
644         /* all things being equal, use signal level */
645         return wb->level - wa->level;
646 }
647
648 static int
649 getmaxrate(const uint8_t rates[15], uint8_t nrates)
650 {
651         int i, maxrate = -1;
652
653         for (i = 0; i < nrates; i++) {
654                 int rate = rates[i] & IEEE80211_RATE_VAL;
655                 if (rate > maxrate)
656                         rate = maxrate;
657         }
658         return maxrate;
659 }
660
661 /* unalligned little endian access */     
662 #define LE_READ_4(p)                                    \
663         ((u_int32_t)                                    \
664          ((((const u_int8_t *)(p))[0]      ) |          \
665           (((const u_int8_t *)(p))[1] <<  8) |          \
666           (((const u_int8_t *)(p))[2] << 16) |          \
667           (((const u_int8_t *)(p))[3] << 24)))
668
669 static int __inline
670 iswpaoui(const u_int8_t *frm)
671 {
672         return frm[1] > 3 && LE_READ_4(frm+2) == ((WPA_OUI_TYPE<<24)|WPA_OUI);
673 }
674
675 static int
676 wpa_driver_bsd_get_scan_results(void *priv,
677                                      struct wpa_scan_result *results,
678                                      size_t max_size)
679 {
680 #define min(a,b)        ((a)>(b)?(b):(a))
681         struct wpa_driver_bsd_data *drv = priv;
682         uint8_t buf[24*1024];
683         const uint8_t *cp, *vp;
684         const struct ieee80211req_scan_result *sr;
685         struct wpa_scan_result *wsr;
686         int len, ielen;
687
688         memset(results, 0, max_size * sizeof(struct wpa_scan_result));
689
690         len = get80211var(drv, IEEE80211_IOC_SCAN_RESULTS, buf, sizeof(buf));
691         if (len < 0)
692                 return -1;
693         cp = buf;
694         wsr = results;
695         while (len >= sizeof(struct ieee80211req_scan_result)) {
696                 sr = (const struct ieee80211req_scan_result *) cp;
697                 memcpy(wsr->bssid, sr->isr_bssid, IEEE80211_ADDR_LEN);
698                 wsr->ssid_len = sr->isr_ssid_len;
699                 wsr->freq = sr->isr_freq;
700                 wsr->noise = sr->isr_noise;
701                 wsr->qual = sr->isr_rssi;
702                 wsr->level = 0;         /* XXX? */
703                 wsr->caps = sr->isr_capinfo;
704                 wsr->maxrate = getmaxrate(sr->isr_rates, sr->isr_nrates);
705                 vp = ((u_int8_t *)sr) + sr->isr_ie_off;
706                 memcpy(wsr->ssid, vp, sr->isr_ssid_len);
707                 if (sr->isr_ie_len > 0) {
708                         vp += sr->isr_ssid_len;
709                         ielen = sr->isr_ie_len;
710                         while (ielen > 0) {
711                                 switch (vp[0]) {
712                                 case IEEE80211_ELEMID_VENDOR:
713                                         if (!iswpaoui(vp))
714                                                 break;
715                                         wsr->wpa_ie_len =
716                                             min(2+vp[1], SSID_MAX_WPA_IE_LEN);
717                                         memcpy(wsr->wpa_ie, vp, wsr->wpa_ie_len);
718                                         break;
719                                 case IEEE80211_ELEMID_RSN:
720                                         wsr->rsn_ie_len =
721                                             min(2+vp[1], SSID_MAX_WPA_IE_LEN);
722                                         memcpy(wsr->rsn_ie, vp, wsr->rsn_ie_len);
723                                         break;
724                                 }
725                                 ielen -= 2+vp[1];
726                                 vp += 2+vp[1];
727                         }
728                 }
729
730                 cp += sr->isr_len, len -= sr->isr_len;
731                 wsr++;
732         }
733         qsort(results, wsr - results, sizeof(struct wpa_scan_result),
734               wpa_scan_result_compar);
735
736         wpa_printf(MSG_DEBUG, "Received %d bytes of scan results (%d BSSes)",
737                    len, wsr - results);
738
739         return wsr - results;
740 #undef min
741 }
742
743 #define GETPARAM(drv, param, v) \
744         (((v) = get80211param(drv, param)) != -1)
745 #define IEEE80211_C_BGSCAN      0x20000000
746
747 /*
748  * Set the scan cache valid threshold to 1.5 x bg scan interval
749  * to force all scan requests to consult the cache unless they
750  * explicitly bypass it.
751  */
752 static int
753 setscanvalid(struct wpa_driver_bsd_data *drv)
754 {
755         int bgscan, scanvalid;
756
757         if (!GETPARAM(drv, IEEE80211_IOC_SCANVALID, drv->prev_scanvalid) ||
758             !GETPARAM(drv, IEEE80211_IOC_BGSCAN_INTERVAL, bgscan))
759                 return -1;
760         scanvalid = 3*bgscan/2;
761         return (drv->prev_scanvalid < scanvalid) ?
762             set80211param(drv, IEEE80211_IOC_SCANVALID, scanvalid) : 0;
763 }
764
765 static void *
766 wpa_driver_bsd_init(void *ctx, const char *ifname)
767 {
768         struct wpa_driver_bsd_data *drv;
769         struct ieee80211_devcaps_req devcaps;
770         int flags;
771
772         drv = malloc(sizeof(*drv));
773         if (drv == NULL)
774                 return NULL;
775         memset(drv, 0, sizeof(*drv));
776         /*
777          * NB: We require the interface name be mappable to an index.
778          *     This implies we do not support having wpa_supplicant
779          *     wait for an interface to appear.  This seems ok; that
780          *     doesn't belong here; it's really the job of devd.
781          */
782         drv->ifindex = if_nametoindex(ifname);
783         if (drv->ifindex == 0) {
784                 wpa_printf(MSG_DEBUG, "%s: interface %s does not exist",
785                            __func__, ifname);
786                 goto fail1;
787         }
788         drv->sock = socket(PF_INET, SOCK_DGRAM, 0);
789         if (drv->sock < 0)
790                 goto fail1;
791         drv->ctx = ctx;
792         strncpy(drv->ifname, ifname, sizeof(drv->ifname));
793
794         /*
795          * Mark the interface as down to ensure wpa_supplicant has exclusive
796          * access to the net80211 state machine, do this before opening the
797          * route socket to avoid a false event that the interface disappeared.
798          */
799         if (getifflags(drv, &flags) == 0)
800                 (void) setifflags(drv, flags &~ IFF_UP);
801
802         drv->route = socket(PF_ROUTE, SOCK_RAW, 0);
803         if (drv->route < 0)
804                 goto fail;
805         eloop_register_read_sock(drv->route,
806                 wpa_driver_bsd_event_receive, ctx, drv);
807
808         if (get80211var(drv, IEEE80211_IOC_DEVCAPS, &devcaps, sizeof(devcaps)) < 0) {
809                 wpa_printf(MSG_DEBUG,
810                     "%s: failed to get device capabilities: %s",
811                     __func__, strerror(errno));
812                 goto fail;
813         }
814         drv->drivercaps = devcaps.dc_drivercaps;
815         drv->cryptocaps = devcaps.dc_cryptocaps;
816
817         if (!GETPARAM(drv, IEEE80211_IOC_ROAMING, drv->prev_roaming)) {
818                 wpa_printf(MSG_DEBUG, "%s: failed to get roaming state: %s",
819                         __func__, strerror(errno));
820                 goto fail;
821         }
822         if (!GETPARAM(drv, IEEE80211_IOC_PRIVACY, drv->prev_privacy)) {
823                 wpa_printf(MSG_DEBUG, "%s: failed to get privacy state: %s",
824                         __func__, strerror(errno));
825                 goto fail;
826         }
827         if (!GETPARAM(drv, IEEE80211_IOC_WPA, drv->prev_wpa)) {
828                 wpa_printf(MSG_DEBUG, "%s: failed to get wpa state: %s",
829                         __func__, strerror(errno));
830                 goto fail;
831         }
832         if (set80211param(drv, IEEE80211_IOC_ROAMING, IEEE80211_ROAMING_MANUAL) < 0) {
833                 wpa_printf(MSG_DEBUG, "%s: failed to set wpa_supplicant-based "
834                            "roaming: %s", __func__, strerror(errno));
835                 goto fail;
836         }
837         if (drv->drivercaps & IEEE80211_C_BGSCAN) {
838                 /*
839                  * Driver does background scanning; force the scan valid
840                  * setting to 1.5 x bg scan interval so the scan cache is
841                  * always consulted before we force a foreground scan.
842                  */ 
843                 if (setscanvalid(drv) < 0) {
844                         wpa_printf(MSG_DEBUG,
845                             "%s: warning, failed to set scanvalid, scanning "
846                             "may be suboptimal: %s", __func__, strerror(errno));
847                 }
848         }
849         if (set80211param(drv, IEEE80211_IOC_WPA, 1+2) < 0) {
850                 wpa_printf(MSG_DEBUG, "%s: failed to enable WPA support %s",
851                            __func__, strerror(errno));
852                 goto fail;
853         }
854
855         return drv;
856 fail:
857         close(drv->sock);
858 fail1:
859         free(drv);
860         return NULL;
861 }
862 #undef GETPARAM
863
864 static void
865 wpa_driver_bsd_deinit(void *priv)
866 {
867         struct wpa_driver_bsd_data *drv = priv;
868         int flags;
869
870         /* NB: mark interface down */
871         if (getifflags(drv, &flags) == 0)
872                 (void) setifflags(drv, flags &~ IFF_UP);
873
874         wpa_driver_bsd_set_wpa_internal(drv, drv->prev_wpa, drv->prev_privacy);
875         if (set80211param(drv, IEEE80211_IOC_ROAMING, drv->prev_roaming) < 0) {
876                 /* NB: don't whinge if device ejected or equivalent */
877                 if (errno != ENXIO)
878                         wpa_printf(MSG_DEBUG, "%s: failed to restore roaming "
879                             "state", __func__);
880         }
881         if (drv->drivercaps & IEEE80211_C_BGSCAN) {
882                 /* XXX check return value */
883                 (void) set80211param(drv, IEEE80211_IOC_SCANVALID,
884                     drv->prev_scanvalid);
885         }
886
887         (void) close(drv->route);               /* ioctl socket */
888         (void) close(drv->sock);                /* event socket */
889         free(drv);
890 }
891
892
893 struct wpa_driver_ops wpa_driver_bsd_ops = {
894         .name                   = "bsd",
895         .desc                   = "BSD 802.11 support (Atheros, etc.)",
896         .init                   = wpa_driver_bsd_init,
897         .deinit                 = wpa_driver_bsd_deinit,
898         .get_bssid              = wpa_driver_bsd_get_bssid,
899         .get_ssid               = wpa_driver_bsd_get_ssid,
900         .set_wpa                = wpa_driver_bsd_set_wpa,
901         .set_key                = wpa_driver_bsd_set_key,
902         .set_countermeasures    = wpa_driver_bsd_set_countermeasures,
903         .set_drop_unencrypted   = wpa_driver_bsd_set_drop_unencrypted,
904         .scan                   = wpa_driver_bsd_scan,
905         .get_scan_results       = wpa_driver_bsd_get_scan_results,
906         .deauthenticate         = wpa_driver_bsd_deauthenticate,
907         .disassociate           = wpa_driver_bsd_disassociate,
908         .associate              = wpa_driver_bsd_associate,
909         .set_auth_alg           = wpa_driver_bsd_set_auth_alg,
910 };