3 * Thomas Skibo <skibo@pacbell.net>. All rights reserved.
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
8 * 1. Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * 2. Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in the
12 * documentation and/or other materials provided with the distribution.
13 * 3. All advertising materials mentioning features or use of this software
14 * must display the following acknowledgement:
15 * This product includes software developed by Thomas Skibo.
16 * 4. Neither the name of the author nor the names of any co-contributors
17 * may be used to endorse or promote products derived from this software
18 * without specific prior written permission.
20 * THIS SOFTWARE IS PROVIDED BY Thomas Skibo AND CONTRIBUTORS ``AS IS'' AND
21 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
22 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23 * ARE DISCLAIMED. IN NO EVENT SHALL Thomas Skibo OR HIS DRINKING PALS
24 * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
25 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
26 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
27 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
28 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
29 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
30 * THE POSSIBILITY OF SUCH DAMAGE.
32 * $FreeBSD: src/sys/dev/wi/wi_hostap.c,v 1.7.2.4 2002/08/02 07:11:34 imp Exp $
35 /* This is experimental Host AP software for Prism 2 802.11b interfaces.
37 * Much of this is based upon the "Linux Host AP driver Host AP driver
38 * for Intersil Prism2" by Jouni Malinen <jkm@ssh.com> or <jkmaline@cc.hut.fi>.
41 #include <sys/param.h>
42 #include <sys/systm.h>
43 #if __FreeBSD_version >= 500033
44 #include <sys/endian.h>
46 #include <sys/sockio.h>
48 #include <sys/malloc.h>
49 #include <sys/kernel.h>
51 #include <sys/ucred.h>
52 #include <sys/socket.h>
53 #include <sys/module.h>
54 #include <sys/queue.h>
56 #include <sys/syslog.h>
57 #include <sys/sysctl.h>
59 #include <machine/bus.h>
60 #include <machine/resource.h>
61 #include <machine/clock.h>
62 #include <machine/md_var.h>
63 #include <machine/bus_pio.h>
67 #include <net/if_arp.h>
68 #include <net/ethernet.h>
69 #include <net/if_dl.h>
70 #include <net/if_media.h>
71 #include <net/if_types.h>
72 #include <net/if_ieee80211.h>
74 #include <netinet/in.h>
75 #include <netinet/in_systm.h>
76 #include <netinet/in_var.h>
77 #include <netinet/ip.h>
78 #include <netinet/if_ether.h>
80 #include <dev/wi/if_wavelan_ieee.h>
81 #include <dev/wi/wi_hostap.h>
82 #include <dev/wi/if_wivar.h>
83 #include <dev/wi/if_wireg.h>
85 MALLOC_DEFINE(M_HAP_STA, "hostap_sta", "if_wi host AP mode station entry");
87 static void wihap_sta_timeout(void *v);
88 static struct wihap_sta_info *wihap_sta_alloc(struct wi_softc *sc,
90 static void wihap_sta_delete(struct wihap_sta_info *sta);
91 static struct wihap_sta_info *wihap_sta_find(struct wihap_info *whi,
93 static int wihap_sta_is_assoc(struct wihap_info *whi, u_int8_t addr[]);
94 static void wihap_auth_req(struct wi_softc *sc, struct wi_frame *rxfrm,
95 caddr_t pkt, int len);
96 static void wihap_sta_deauth(struct wi_softc *sc, u_int8_t sta_addr[],
98 static void wihap_deauth_req(struct wi_softc *sc, struct wi_frame *rxfrm,
99 caddr_t pkt, int len);
100 static void wihap_assoc_req(struct wi_softc *sc, struct wi_frame *rxfrm,
101 caddr_t pkt, int len);
102 static void wihap_sta_disassoc(struct wi_softc *sc, u_int8_t sta_addr[],
104 static void wihap_disassoc_req(struct wi_softc *sc, struct wi_frame *rxfrm,
105 caddr_t pkt, int len);
108 * Spl use in this driver.
110 * splnet is used everywhere here to block timeouts when we need to do
117 * Used for parsing management frames. The pkt pointer and length
118 * variables are updated after the value is removed.
120 static __inline u_int16_t
121 take_hword(caddr_t *ppkt, int *plen)
123 u_int16_t s = le16toh(* (u_int16_t *) *ppkt);
124 *ppkt += sizeof(u_int16_t);
125 *plen -= sizeof(u_int16_t);
131 * Parse out TLV element from a packet, check for underflow of packet
132 * or overflow of buffer, update pkt/len.
135 take_tlv(caddr_t *ppkt, int *plen, int id_expect, void *dst, int maxlen)
142 id = ((u_int8_t *)*ppkt)[0];
143 len = ((u_int8_t *)*ppkt)[1];
145 if (id != id_expect || *plen < len+2 || maxlen < len)
148 bcopy(*ppkt + 2, dst, len);
156 * Put half-word element into management frames.
159 put_hword(caddr_t *ppkt, u_int16_t s)
161 * (u_int16_t *) *ppkt = htole16(s);
162 *ppkt += sizeof(u_int16_t);
166 * Put TLV elements into management frames.
169 put_tlv(caddr_t *ppkt, u_int8_t id, void *src, u_int8_t len)
173 bcopy(src, (*ppkt) + 2, len);
178 put_rates(caddr_t *ppkt, u_int16_t rates)
183 if (rates & WI_SUPPRATES_1M)
184 ratebuf[len++] = 0x82;
185 if (rates & WI_SUPPRATES_2M)
186 ratebuf[len++] = 0x84;
187 if (rates & WI_SUPPRATES_5M)
188 ratebuf[len++] = 0x8b;
189 if (rates & WI_SUPPRATES_11M)
190 ratebuf[len++] = 0x96;
192 put_tlv(ppkt, IEEE80211_ELEMID_RATES, ratebuf, len);
198 * Initialize host AP data structures. Called even if port type is
202 wihap_init(struct wi_softc *sc)
205 struct wihap_info *whi = &sc->wi_hostap_info;
207 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
208 printf("wihap_init: sc=0x%x whi=0x%x\n", (int)sc, (int)whi);
210 bzero(whi, sizeof(struct wihap_info));
212 if (sc->wi_ptype != WI_PORTTYPE_AP)
215 whi->apflags = WIHAPFL_ACTIVE;
217 LIST_INIT(&whi->sta_list);
218 for (i = 0; i < WI_STA_HASH_SIZE; i++)
219 LIST_INIT(&whi->sta_hash[i]);
221 whi->inactivity_time = WIHAP_DFLT_INACTIVITY_TIME;
224 /* wihap_sta_disassoc()
226 * Send a disassociation frame to a specified station.
229 wihap_sta_disassoc(struct wi_softc *sc, u_int8_t sta_addr[], u_int16_t reason)
231 struct wi_80211_hdr *resp_hdr;
234 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
235 printf("Sending disassoc to sta %6D\n", sta_addr, ":");
237 /* Send disassoc packet. */
238 resp_hdr = (struct wi_80211_hdr *) sc->wi_txbuf;
239 bzero(resp_hdr, sizeof(struct wi_80211_hdr));
240 resp_hdr->frame_ctl = WI_FTYPE_MGMT | WI_STYPE_MGMT_DISAS;
241 pkt = sc->wi_txbuf + sizeof(struct wi_80211_hdr);
243 bcopy(sta_addr, resp_hdr->addr1, ETHER_ADDR_LEN);
244 bcopy(sc->arpcom.ac_enaddr, resp_hdr->addr2, ETHER_ADDR_LEN);
245 bcopy(sc->arpcom.ac_enaddr, resp_hdr->addr3, ETHER_ADDR_LEN);
247 put_hword(&pkt, reason);
249 wi_mgmt_xmit(sc, sc->wi_txbuf, 2 + sizeof(struct wi_80211_hdr));
252 /* wihap_sta_deauth()
254 * Send a deauthentication message to a specified station.
257 wihap_sta_deauth(struct wi_softc *sc, u_int8_t sta_addr[], u_int16_t reason)
259 struct wi_80211_hdr *resp_hdr;
262 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
263 printf("Sending deauth to sta %6D\n", sta_addr, ":");
265 /* Send deauth packet. */
266 resp_hdr = (struct wi_80211_hdr *) sc->wi_txbuf;
267 bzero(resp_hdr, sizeof(struct wi_80211_hdr));
268 resp_hdr->frame_ctl = htole16(WI_FTYPE_MGMT | WI_STYPE_MGMT_DEAUTH);
269 pkt = sc->wi_txbuf + sizeof(struct wi_80211_hdr);
271 bcopy(sta_addr, resp_hdr->addr1, ETHER_ADDR_LEN);
272 bcopy(sc->arpcom.ac_enaddr, resp_hdr->addr2, ETHER_ADDR_LEN);
273 bcopy(sc->arpcom.ac_enaddr, resp_hdr->addr3, ETHER_ADDR_LEN);
275 put_hword(&pkt, reason);
277 wi_mgmt_xmit(sc, sc->wi_txbuf, 2 + sizeof(struct wi_80211_hdr));
282 * Disassociate all stations and free up data structures.
285 wihap_shutdown(struct wi_softc *sc)
287 struct wihap_info *whi = &sc->wi_hostap_info;
288 struct wihap_sta_info *sta, *next;
291 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
292 printf("wihap_shutdown: sc=0x%x whi=0x%x\n",
295 if (!(whi->apflags & WIHAPFL_ACTIVE))
298 /* XXX: I read somewhere you can deauth all the stations with
299 * a single broadcast. Maybe try that someday.
303 sta = LIST_FIRST(&whi->sta_list);
305 untimeout(wihap_sta_timeout, sta, sta->tmo);
307 /* Disassociate station. */
308 if (sta->flags & WI_SIFLAGS_ASSOC)
309 wihap_sta_disassoc(sc, sta->addr,
310 IEEE80211_REASON_ASSOC_LEAVE);
311 /* Deauth station. */
312 if (sta->flags & WI_SIFLAGS_AUTHEN)
313 wihap_sta_deauth(sc, sta->addr,
314 IEEE80211_REASON_AUTH_LEAVE);
317 /* Delete the structure. */
318 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
319 printf("wihap_shutdown: FREE(sta=0x%x)\n", (int)sta);
320 next = LIST_NEXT(sta, list);
321 FREE(sta, M_HAP_STA);
330 * Hash function for finding stations from ethernet address.
333 sta_hash_func(u_int8_t addr[])
335 return ((addr[3] + addr[4] + addr[5]) % WI_STA_HASH_SIZE);
338 /* addr_cmp(): Maybe this is a faster way to compare addresses? */
340 addr_cmp(u_int8_t a[], u_int8_t b[])
342 return (*(u_int16_t *)(a + 4) == *(u_int16_t *)(b + 4) &&
343 *(u_int32_t *)(a ) == *(u_int32_t *)(b));
347 wihap_sta_timeout(void *v)
349 struct wihap_sta_info *sta = v;
350 struct wi_softc *sc = sta->sc;
351 struct wihap_info *whi = &sc->wi_hostap_info;
355 if (sta->flags & WI_SIFLAGS_ASSOC) {
356 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
357 device_printf(sc->dev, "inactivity disassoc: %6D\n",
360 /* Disassoc station. */
361 wihap_sta_disassoc(sc, sta->addr,
362 IEEE80211_REASON_ASSOC_EXPIRE);
363 sta->flags &= ~WI_SIFLAGS_ASSOC;
365 sta->tmo = timeout(wihap_sta_timeout, sta,
366 hz * whi->inactivity_time);
368 } else if (sta->flags & WI_SIFLAGS_AUTHEN) {
370 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
371 device_printf(sc->dev, "inactivity disassoc: %6D\n",
374 /* Deauthenticate station. */
375 wihap_sta_deauth(sc, sta->addr, IEEE80211_REASON_AUTH_EXPIRE);
376 sta->flags &= ~WI_SIFLAGS_AUTHEN;
378 /* Delete the station if it's not permanent. */
379 if (!(sta->flags & WI_SIFLAGS_PERM))
380 wihap_sta_delete(sta);
385 /* wihap_sta_delete()
386 * Delete a single station and free up its data structure.
389 wihap_sta_delete(struct wihap_sta_info *sta)
391 struct wi_softc *sc = sta->sc;
392 struct wihap_info *whi = &sc->wi_hostap_info;
393 int i = sta->asid - 0xc001;
395 untimeout(wihap_sta_timeout, sta, sta->tmo);
397 whi->asid_inuse_mask[i >> 4] &= ~(1UL << (i & 0xf));
399 LIST_REMOVE(sta, list);
400 LIST_REMOVE(sta, hash);
402 FREE(sta->challenge, M_TEMP);
403 FREE(sta, M_HAP_STA);
409 * Create a new station data structure and put it in the list
412 static struct wihap_sta_info *
413 wihap_sta_alloc(struct wi_softc *sc, u_int8_t *addr)
415 struct wihap_info *whi = &sc->wi_hostap_info;
416 struct wihap_sta_info *sta;
417 int i, hash = sta_hash_func(addr);
419 /* Allocate structure. */
420 MALLOC(sta, struct wihap_sta_info *, sizeof(struct wihap_sta_info),
421 M_HAP_STA, M_NOWAIT);
425 bzero(sta, sizeof(struct wihap_sta_info));
427 /* Allocate an ASID. */
429 while (whi->asid_inuse_mask[i >> 4] & (1UL << (i & 0xf)))
430 i = (i == (WI_STA_HASH_SIZE << 4) - 1) ? 0 : (i + 1);
431 whi->asid_inuse_mask[i >> 4] |= (1UL << (i & 0xf));
432 sta->asid = 0xc001 + i;
434 /* Insert in list and hash list. */
435 LIST_INSERT_HEAD(&whi->sta_list, sta, list);
436 LIST_INSERT_HEAD(&whi->sta_hash[hash], sta, hash);
440 bcopy(addr, &sta->addr, ETHER_ADDR_LEN);
447 * Find station structure given address.
449 static struct wihap_sta_info *
450 wihap_sta_find(struct wihap_info *whi, u_int8_t *addr)
453 struct wihap_sta_info *sta;
455 i = sta_hash_func(addr);
456 LIST_FOREACH(sta, &whi->sta_hash[i], hash)
457 if (addr_cmp(addr,sta->addr))
464 wihap_check_rates(struct wihap_sta_info *sta, u_int8_t rates[], int rates_len)
466 struct wi_softc *sc = sta->sc;
470 sta->tx_max_rate = 0;
471 for (i=0; i<rates_len; i++)
472 switch (rates[i] & 0x7f) {
474 sta->rates |= WI_SUPPRATES_1M;
477 sta->rates |= WI_SUPPRATES_2M;
478 if (sta->tx_max_rate<1)
479 sta->tx_max_rate = 1;
482 sta->rates |= WI_SUPPRATES_5M;
483 if (sta->tx_max_rate<2)
484 sta->tx_max_rate = 2;
487 sta->rates |= WI_SUPPRATES_11M;
488 sta->tx_max_rate = 3;
492 sta->rates &= sc->wi_supprates;
493 sta->tx_curr_rate = sta->tx_max_rate;
495 return (sta->rates == 0 ? -1 : 0);
501 * Handle incoming authentication request. Only handle OPEN
505 wihap_auth_req(struct wi_softc *sc, struct wi_frame *rxfrm,
506 caddr_t pkt, int len)
508 struct wihap_info *whi = &sc->wi_hostap_info;
509 struct wihap_sta_info *sta;
514 int i, challenge_len;
515 u_int32_t challenge[32];
517 struct wi_80211_hdr *resp_hdr;
522 /* Break open packet. */
523 algo = take_hword(&pkt, &len);
524 seq = take_hword(&pkt, &len);
525 status = take_hword(&pkt, &len);
527 if (len > 0 && (challenge_len = take_tlv(&pkt, &len,
528 IEEE80211_ELEMID_CHALLENGE, challenge, sizeof(challenge))) < 0)
531 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
532 printf("wihap_auth_req: station %6D algo=0x%x seq=0x%x\n",
533 rxfrm->wi_addr2, ":", algo, seq);
535 /* Find or create station info. */
536 sta = wihap_sta_find(whi, rxfrm->wi_addr2);
539 /* Are we allowing new stations?
541 if (whi->apflags & WIHAPFL_MAC_FILT) {
542 status = IEEE80211_STATUS_OTHER; /* XXX */
546 /* Check for too many stations.
548 if (whi->n_stations >= WIHAP_MAX_STATIONS) {
549 status = IEEE80211_STATUS_TOO_MANY_STATIONS;
553 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
554 printf("wihap_auth_req: new station\n");
556 /* Create new station. */
557 sta = wihap_sta_alloc(sc, rxfrm->wi_addr2);
560 status = IEEE80211_STATUS_TOO_MANY_STATIONS;
565 /* Note: it's okay to leave the station info structure around
566 * if the authen fails. It'll be timed out eventually.
569 case IEEE80211_AUTH_ALG_OPEN:
570 if (sc->wi_authmode != IEEE80211_AUTH_OPEN) {
572 status = IEEE80211_STATUS_ALG;
577 status = IEEE80211_STATUS_SEQUENCE;
582 sta->flags |= WI_SIFLAGS_AUTHEN;
584 case IEEE80211_AUTH_ALG_SHARED:
585 if (sc->wi_authmode != IEEE80211_AUTH_SHARED) {
587 status = IEEE80211_STATUS_ALG;
592 /* Create a challenge frame. */
593 if (!sta->challenge) {
594 MALLOC(sta->challenge, u_int32_t *, 128,
599 for (i = 0; i < 32; i++)
600 challenge[i] = sta->challenge[i] =
606 if (challenge_len != 128 || !sta->challenge ||
607 !(le16toh(rxfrm->wi_frame_ctl) & WI_FCTL_WEP)) {
608 status = IEEE80211_STATUS_CHALLENGE;
614 /* Check the challenge text. (Was decrypted by
618 if (sta->challenge[i] != challenge[i]) {
619 status = IEEE80211_STATUS_CHALLENGE;
620 FREE(sta->challenge, M_TEMP);
621 sta->challenge = NULL;
625 sta->flags |= WI_SIFLAGS_AUTHEN;
626 FREE(sta->challenge, M_TEMP);
627 sta->challenge = NULL;
631 status = IEEE80211_STATUS_SEQUENCE;
636 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
637 printf("wihap_auth_req: algorithm unsupported: 0x%x\n",
639 status = IEEE80211_STATUS_ALG;
641 } /* switch (algo) */
643 status = IEEE80211_STATUS_SUCCESS;
646 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
647 printf("wihap_auth_req: returns status=0x%x\n", status);
650 resp_hdr = (struct wi_80211_hdr *) sc->wi_txbuf;
651 bzero(resp_hdr, sizeof(struct wi_80211_hdr));
652 resp_hdr->frame_ctl = htole16(WI_FTYPE_MGMT | WI_STYPE_MGMT_AUTH);
653 bcopy(rxfrm->wi_addr2, resp_hdr->addr1, ETHER_ADDR_LEN);
654 bcopy(sc->arpcom.ac_enaddr, resp_hdr->addr2, ETHER_ADDR_LEN);
655 bcopy(sc->arpcom.ac_enaddr, resp_hdr->addr3, ETHER_ADDR_LEN);
656 pkt = &sc->wi_txbuf[sizeof(struct wi_80211_hdr)];
657 put_hword(&pkt, algo);
658 put_hword(&pkt, seq);
659 put_hword(&pkt, status);
660 if (challenge_len > 0)
661 put_tlv(&pkt, IEEE80211_ELEMID_CHALLENGE,
662 challenge, challenge_len);
663 wi_mgmt_xmit(sc, sc->wi_txbuf, (char *) pkt - (char *) sc->wi_txbuf);
668 * Handle incoming association and reassociation requests.
671 wihap_assoc_req(struct wi_softc *sc, struct wi_frame *rxfrm,
672 caddr_t pkt, int len)
674 struct wihap_info *whi = &sc->wi_hostap_info;
675 struct wihap_sta_info *sta;
676 struct wi_80211_hdr *resp_hdr;
680 int ssid_len, rates_len;
688 /* Pull out request parameters. */
689 capinfo = take_hword(&pkt, &len);
690 lstintvl = take_hword(&pkt, &len);
692 if ((rxfrm->wi_frame_ctl & htole16(WI_FCTL_STYPE)) ==
693 htole16(WI_STYPE_MGMT_REASREQ)) {
696 /* Eat the MAC address of the current AP */
697 take_hword(&pkt, &len);
698 take_hword(&pkt, &len);
699 take_hword(&pkt, &len);
702 if ((ssid_len = take_tlv(&pkt, &len, IEEE80211_ELEMID_SSID,
703 ssid, sizeof(ssid) - 1))<0)
705 ssid[ssid_len] = '\0';
706 if ((rates_len = take_tlv(&pkt, &len, IEEE80211_ELEMID_RATES,
707 rates, sizeof(rates)))<0)
710 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
711 printf("wihap_assoc_req: from station %6D\n",
712 rxfrm->wi_addr2, ":");
714 /* If SSID doesn't match, simply drop. */
715 if (strcmp(sc->wi_net_name, ssid) != 0) {
716 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
717 printf("wihap_assoc_req: bad ssid: '%s' != '%s'\n",
718 ssid, sc->wi_net_name);
722 /* Is this station authenticated yet? */
723 sta = wihap_sta_find(whi, rxfrm->wi_addr2);
724 if (sta == NULL || !(sta->flags & WI_SIFLAGS_AUTHEN)) {
725 wihap_sta_deauth(sc, rxfrm->wi_addr2,
726 IEEE80211_REASON_NOT_AUTHED);
730 /* Check supported rates against ours. */
731 if (wihap_check_rates(sta, rates, rates_len) < 0) {
732 status = IEEE80211_STATUS_RATES;
737 * Check for ESS, not IBSS.
738 * Check WEP/PRIVACY flags match.
739 * Refuse stations requesting to be put on CF-polling list.
741 sta->capinfo = capinfo;
742 status = IEEE80211_STATUS_CAPINFO;
743 if ((capinfo & (IEEE80211_CAPINFO_ESS | IEEE80211_CAPINFO_IBSS)) !=
744 IEEE80211_CAPINFO_ESS) {
745 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
746 printf("wihap_assoc_req: capinfo mismatch: "
747 "client using IBSS mode\n");
751 if ((sc->wi_use_wep && !(capinfo & IEEE80211_CAPINFO_PRIVACY)) ||
752 (!sc->wi_use_wep && (capinfo & IEEE80211_CAPINFO_PRIVACY))) {
753 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
754 printf("wihap_assoc_req: capinfo mismatch: client "
755 "%susing WEP\n", sc->wi_use_wep ? "not " : "");
758 if ((capinfo & (IEEE80211_CAPINFO_CF_POLLABLE |
759 IEEE80211_CAPINFO_CF_POLLREQ)) == IEEE80211_CAPINFO_CF_POLLABLE) {
760 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
761 printf("wihap_assoc_req: capinfo mismatch: "
762 "client requested CF polling\n");
766 /* Use ASID is allocated by whi_sta_alloc(). */
769 if (sta->flags & WI_SIFLAGS_ASSOC) {
770 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
771 printf("wihap_assoc_req: already assoc'ed?\n");
774 sta->flags |= WI_SIFLAGS_ASSOC;
775 sta->inactivity_timer = whi->inactivity_time;
776 status = IEEE80211_STATUS_SUCCESS;
779 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
780 printf("wihap_assoc_req: returns status=0x%x\n", status);
783 resp_hdr = (struct wi_80211_hdr *) sc->wi_txbuf;
784 bzero(resp_hdr, sizeof(struct wi_80211_hdr));
785 resp_hdr->frame_ctl = htole16(WI_FTYPE_MGMT | WI_STYPE_MGMT_ASRESP);
786 pkt = sc->wi_txbuf + sizeof(struct wi_80211_hdr);
788 bcopy(rxfrm->wi_addr2, resp_hdr->addr1, ETHER_ADDR_LEN);
789 bcopy(sc->arpcom.ac_enaddr, resp_hdr->addr2, ETHER_ADDR_LEN);
790 bcopy(sc->arpcom.ac_enaddr, resp_hdr->addr3, ETHER_ADDR_LEN);
792 put_hword(&pkt, capinfo);
793 put_hword(&pkt, status);
794 put_hword(&pkt, asid);
795 rates_len = put_rates(&pkt, sc->wi_supprates);
797 wi_mgmt_xmit(sc, sc->wi_txbuf,
798 8 + rates_len + sizeof(struct wi_80211_hdr));
801 /* wihap_deauth_req()
803 * Handle deauthentication requests. Delete the station.
806 wihap_deauth_req(struct wi_softc *sc, struct wi_frame *rxfrm,
807 caddr_t pkt, int len)
809 struct wihap_info *whi = &sc->wi_hostap_info;
810 struct wihap_sta_info *sta;
816 reason = take_hword(&pkt, &len);
818 sta = wihap_sta_find(whi, rxfrm->wi_addr2);
820 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
821 printf("wihap_deauth_req: unknown station: %6D\n",
822 rxfrm->wi_addr2, ":");
825 wihap_sta_delete(sta);
828 /* wihap_disassoc_req()
830 * Handle disassociation requests. Just reset the assoc flag.
831 * We'll free up the station resources when we get a deauth
832 * request or when it times out.
835 wihap_disassoc_req(struct wi_softc *sc, struct wi_frame *rxfrm,
836 caddr_t pkt, int len)
838 struct wihap_info *whi = &sc->wi_hostap_info;
839 struct wihap_sta_info *sta;
845 reason = take_hword(&pkt, &len);
847 sta = wihap_sta_find(whi, rxfrm->wi_addr2);
849 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
850 printf("wihap_disassoc_req: unknown station: %6D\n",
851 rxfrm->wi_addr2, ":");
853 else if (!(sta->flags & WI_SIFLAGS_AUTHEN)) {
855 * If station is not authenticated, send deauthentication
858 wihap_sta_deauth(sc, rxfrm->wi_addr2,
859 IEEE80211_REASON_NOT_AUTHED);
863 sta->flags &= ~WI_SIFLAGS_ASSOC;
866 /* wihap_debug_frame_type()
868 * Print out frame type. Used in early debugging.
871 wihap_debug_frame_type(struct wi_frame *rxfrm)
873 printf("wihap_mgmt_input: len=%d ", le16toh(rxfrm->wi_dat_len));
875 if ((rxfrm->wi_frame_ctl & htole16(WI_FCTL_FTYPE)) ==
876 htole16(WI_FTYPE_MGMT)) {
880 switch (le16toh(rxfrm->wi_frame_ctl) & WI_FCTL_STYPE) {
881 case WI_STYPE_MGMT_ASREQ:
882 printf("assoc req: \n");
884 case WI_STYPE_MGMT_ASRESP:
885 printf("assoc resp: \n");
887 case WI_STYPE_MGMT_REASREQ:
888 printf("reassoc req: \n");
890 case WI_STYPE_MGMT_REASRESP:
891 printf("reassoc resp: \n");
893 case WI_STYPE_MGMT_PROBEREQ:
894 printf("probe req: \n");
896 case WI_STYPE_MGMT_PROBERESP:
897 printf("probe resp: \n");
899 case WI_STYPE_MGMT_BEACON:
900 printf("beacon: \n");
902 case WI_STYPE_MGMT_ATIM:
903 printf("ann traf ind \n");
905 case WI_STYPE_MGMT_DISAS:
906 printf("disassociation: \n");
908 case WI_STYPE_MGMT_AUTH:
911 case WI_STYPE_MGMT_DEAUTH:
912 printf("deauth: \n");
915 printf("unknown (stype=0x%x)\n",
916 le16toh(rxfrm->wi_frame_ctl) & WI_FCTL_STYPE);
921 printf("ftype=0x%x (ctl=0x%x)\n",
922 le16toh(rxfrm->wi_frame_ctl) & WI_FCTL_FTYPE,
923 le16toh(rxfrm->wi_frame_ctl));
929 * Called for each management frame received in host ap mode.
930 * wihap_mgmt_input() is expected to free the mbuf.
933 wihap_mgmt_input(struct wi_softc *sc, struct wi_frame *rxfrm, struct mbuf *m)
938 if (sc->arpcom.ac_if.if_flags & IFF_DEBUG)
939 wihap_debug_frame_type(rxfrm);
941 pkt = mtod(m, caddr_t) + WI_802_11_OFFSET_RAW;
942 len = m->m_len - WI_802_11_OFFSET_RAW;
944 if ((rxfrm->wi_frame_ctl & htole16(WI_FCTL_FTYPE)) ==
945 htole16(WI_FTYPE_MGMT)) {
947 /* any of the following will mess w/ the station list */
949 switch (le16toh(rxfrm->wi_frame_ctl) & WI_FCTL_STYPE) {
950 case WI_STYPE_MGMT_ASREQ:
951 wihap_assoc_req(sc, rxfrm, pkt, len);
953 case WI_STYPE_MGMT_ASRESP:
955 case WI_STYPE_MGMT_REASREQ:
956 wihap_assoc_req(sc, rxfrm, pkt, len);
958 case WI_STYPE_MGMT_REASRESP:
960 case WI_STYPE_MGMT_PROBEREQ:
962 case WI_STYPE_MGMT_PROBERESP:
964 case WI_STYPE_MGMT_BEACON:
966 case WI_STYPE_MGMT_ATIM:
968 case WI_STYPE_MGMT_DISAS:
969 wihap_disassoc_req(sc, rxfrm, pkt, len);
971 case WI_STYPE_MGMT_AUTH:
972 wihap_auth_req(sc, rxfrm, pkt, len);
974 case WI_STYPE_MGMT_DEAUTH:
975 wihap_deauth_req(sc, rxfrm, pkt, len);
984 /* wihap_sta_is_assoc()
986 * Determine if a station is assoc'ed. Update its activity
987 * counter as a side-effect.
990 wihap_sta_is_assoc(struct wihap_info *whi, u_int8_t addr[])
992 struct wihap_sta_info *sta;
997 sta = wihap_sta_find(whi, addr);
998 if (sta != NULL && (sta->flags & WI_SIFLAGS_ASSOC)) {
999 /* Keep it active. */
1000 untimeout(wihap_sta_timeout, sta, sta->tmo);
1001 sta->tmo = timeout(wihap_sta_timeout, sta,
1002 hz * whi->inactivity_time);
1011 * Determine if a station is assoc'ed, get its tx rate, and update
1015 wihap_check_tx(struct wihap_info *whi, u_int8_t addr[], u_int8_t *txrate)
1017 struct wihap_sta_info *sta;
1018 static u_int8_t txratetable[] = { 10, 20, 55, 110 };
1021 if (addr[0] & 0x01) {
1022 *txrate = 0; /* XXX: multicast rate? */
1026 sta = wihap_sta_find(whi, addr);
1027 if (sta != NULL && (sta->flags & WI_SIFLAGS_ASSOC)) {
1028 /* Keep it active. */
1029 untimeout(wihap_sta_timeout, sta, sta->tmo);
1030 sta->tmo = timeout(wihap_sta_timeout, sta,
1031 hz * whi->inactivity_time);
1032 *txrate = txratetable[ sta->tx_curr_rate ];
1042 * wihap_data_input()
1044 * Handle all data input on interface when in Host AP mode.
1045 * Some packets are destined for this machine, others are
1046 * repeated to other stations.
1048 * If wihap_data_input() returns a non-zero, it has processed
1049 * the packet and will free the mbuf.
1052 wihap_data_input(struct wi_softc *sc, struct wi_frame *rxfrm, struct mbuf *m)
1054 struct ifnet *ifp = &sc->arpcom.ac_if;
1055 struct wihap_info *whi = &sc->wi_hostap_info;
1056 struct wihap_sta_info *sta;
1059 /* TODS flag must be set. */
1060 if (!(rxfrm->wi_frame_ctl & htole16(WI_FCTL_TODS))) {
1061 if (ifp->if_flags & IFF_DEBUG)
1062 printf("wihap_data_input: no TODS src=%6D\n",
1063 rxfrm->wi_addr2, ":");
1068 /* Check BSSID. (Is this necessary?) */
1069 if (!addr_cmp(rxfrm->wi_addr1, sc->arpcom.ac_enaddr)) {
1070 if (ifp->if_flags & IFF_DEBUG)
1071 printf("wihap_data_input: incorrect bss: %6D\n",
1072 rxfrm->wi_addr1, ":");
1079 /* Find source station. */
1080 sta = wihap_sta_find(whi, rxfrm->wi_addr2);
1082 /* Source station must be associated. */
1083 if (sta == NULL || !(sta->flags & WI_SIFLAGS_ASSOC)) {
1084 if (ifp->if_flags & IFF_DEBUG)
1085 printf("wihap_data_input: dropping unassoc src %6D\n",
1086 rxfrm->wi_addr2, ":");
1087 wihap_sta_disassoc(sc, rxfrm->wi_addr2,
1088 IEEE80211_REASON_ASSOC_LEAVE);
1094 untimeout(wihap_sta_timeout, sta, sta->tmo);
1095 sta->tmo = timeout(wihap_sta_timeout, sta,
1096 hz * whi->inactivity_time);
1097 sta->sig_info = le16toh(rxfrm->wi_q_info);
1101 /* Repeat this packet to BSS? */
1102 mcast = (rxfrm->wi_addr3[0] & 0x01) != 0;
1103 if (mcast || wihap_sta_is_assoc(whi, rxfrm->wi_addr3)) {
1105 /* If it's multicast, make a copy.
1108 m = m_copym(m, 0, M_COPYALL, M_DONTWAIT);
1111 m->m_flags |= M_MCAST; /* XXX */
1114 /* Queue up for repeating.
1116 IF_HANDOFF(&ifp->if_snd, m, ifp);
1125 * Handle Host AP specific ioctls. Called from wi_ioctl().
1128 wihap_ioctl(struct wi_softc *sc, u_long command, caddr_t data)
1130 struct ifreq *ifr = (struct ifreq *) data;
1131 struct wihap_info *whi = &sc->wi_hostap_info;
1132 struct wihap_sta_info *sta;
1133 struct hostap_getall reqall;
1134 struct hostap_sta reqsta;
1135 struct hostap_sta stabuf;
1136 int s, error = 0, n, flag;
1137 #if __FreeBSD_version >= 500000
1138 struct thread *td = curthread;
1140 struct proc *td = curproc; /* Little white lie */
1143 if (!(sc->arpcom.ac_if.if_flags & IFF_RUNNING))
1147 case SIOCHOSTAP_DEL:
1148 if ((error = suser(td)))
1150 if ((error = copyin(ifr->ifr_data, &reqsta, sizeof(reqsta))))
1153 sta = wihap_sta_find(whi, reqsta.addr);
1157 /* Disassociate station. */
1158 if (sta->flags & WI_SIFLAGS_ASSOC)
1159 wihap_sta_disassoc(sc, sta->addr,
1160 IEEE80211_REASON_ASSOC_LEAVE);
1161 /* Deauth station. */
1162 if (sta->flags & WI_SIFLAGS_AUTHEN)
1163 wihap_sta_deauth(sc, sta->addr,
1164 IEEE80211_REASON_AUTH_LEAVE);
1166 wihap_sta_delete(sta);
1171 case SIOCHOSTAP_GET:
1172 if ((error = copyin(ifr->ifr_data, &reqsta, sizeof(reqsta))))
1175 sta = wihap_sta_find(whi, reqsta.addr);
1180 reqsta.flags = sta->flags;
1181 reqsta.asid = sta->asid;
1182 reqsta.capinfo = sta->capinfo;
1183 reqsta.sig_info = sta->sig_info;
1184 reqsta.rates = sta->rates;
1186 error = copyout(&reqsta, ifr->ifr_data,
1191 case SIOCHOSTAP_ADD:
1192 if ((error = suser(td)))
1194 if ((error = copyin(ifr->ifr_data, &reqsta, sizeof(reqsta))))
1197 sta = wihap_sta_find(whi, reqsta.addr);
1203 if (whi->n_stations >= WIHAP_MAX_STATIONS) {
1208 sta = wihap_sta_alloc(sc, reqsta.addr);
1209 sta->flags = reqsta.flags;
1210 sta->tmo = timeout(wihap_sta_timeout, sta,
1211 hz * whi->inactivity_time);
1215 case SIOCHOSTAP_SFLAGS:
1216 if ((error = suser(td)))
1218 if ((error = copyin(ifr->ifr_data, &flag, sizeof(int))))
1221 whi->apflags = (whi->apflags & WIHAPFL_CANTCHANGE) |
1222 (flag & ~WIHAPFL_CANTCHANGE);
1225 case SIOCHOSTAP_GFLAGS:
1226 flag = (int) whi->apflags;
1227 error = copyout(&flag, ifr->ifr_data, sizeof(int));
1230 case SIOCHOSTAP_GETALL:
1231 if ((error = copyin(ifr->ifr_data, &reqall, sizeof(reqall))))
1234 reqall.nstations = whi->n_stations;
1237 sta = LIST_FIRST(&whi->sta_list);
1238 while (sta && reqall.size >= n+sizeof(struct hostap_sta)) {
1240 bcopy(sta->addr, stabuf.addr, ETHER_ADDR_LEN);
1241 stabuf.asid = sta->asid;
1242 stabuf.flags = sta->flags;
1243 stabuf.capinfo = sta->capinfo;
1244 stabuf.sig_info = sta->sig_info;
1245 stabuf.rates = sta->rates;
1247 error = copyout(&stabuf, (caddr_t) reqall.addr + n,
1248 sizeof(struct hostap_sta));
1252 sta = LIST_NEXT(sta, list);
1253 n += sizeof(struct hostap_sta);
1258 error = copyout(&reqall, ifr->ifr_data,
1262 printf("wihap_ioctl: i shouldn't get other ioctls!\n");