1209139Srpaulo/*
2209139Srpaulo * WPA Supplicant - privilege separated driver interface
3209139Srpaulo * Copyright (c) 2007-2009, Jouni Malinen <j@w1.fi>
4209139Srpaulo *
5252190Srpaulo * This software may be distributed under the terms of the BSD license.
6252190Srpaulo * See README for more details.
7209139Srpaulo */
8209139Srpaulo
9209139Srpaulo#include "includes.h"
10209139Srpaulo#include <sys/un.h>
11209139Srpaulo
12209139Srpaulo#include "common.h"
13209139Srpaulo#include "driver.h"
14209139Srpaulo#include "eloop.h"
15214501Srpaulo#include "common/privsep_commands.h"
16209139Srpaulo
17209139Srpaulo
18209139Srpaulostruct wpa_driver_privsep_data {
19209139Srpaulo	void *ctx;
20209139Srpaulo	u8 own_addr[ETH_ALEN];
21209139Srpaulo	int priv_socket;
22209139Srpaulo	char *own_socket_path;
23209139Srpaulo	int cmd_socket;
24209139Srpaulo	char *own_cmd_path;
25209139Srpaulo	struct sockaddr_un priv_addr;
26209139Srpaulo	char ifname[16];
27209139Srpaulo};
28209139Srpaulo
29209139Srpaulo
30209139Srpaulostatic int wpa_priv_reg_cmd(struct wpa_driver_privsep_data *drv, int cmd)
31209139Srpaulo{
32209139Srpaulo	int res;
33209139Srpaulo
34209139Srpaulo	res = sendto(drv->priv_socket, &cmd, sizeof(cmd), 0,
35209139Srpaulo		     (struct sockaddr *) &drv->priv_addr,
36209139Srpaulo		     sizeof(drv->priv_addr));
37209139Srpaulo	if (res < 0)
38209139Srpaulo		perror("sendto");
39209139Srpaulo	return res < 0 ? -1 : 0;
40209139Srpaulo}
41209139Srpaulo
42209139Srpaulo
43209139Srpaulostatic int wpa_priv_cmd(struct wpa_driver_privsep_data *drv, int cmd,
44209139Srpaulo			const void *data, size_t data_len,
45209139Srpaulo			void *reply, size_t *reply_len)
46209139Srpaulo{
47209139Srpaulo	struct msghdr msg;
48209139Srpaulo	struct iovec io[2];
49209139Srpaulo
50209139Srpaulo	io[0].iov_base = &cmd;
51209139Srpaulo	io[0].iov_len = sizeof(cmd);
52209139Srpaulo	io[1].iov_base = (u8 *) data;
53209139Srpaulo	io[1].iov_len = data_len;
54209139Srpaulo
55209139Srpaulo	os_memset(&msg, 0, sizeof(msg));
56209139Srpaulo	msg.msg_iov = io;
57209139Srpaulo	msg.msg_iovlen = data ? 2 : 1;
58209139Srpaulo	msg.msg_name = &drv->priv_addr;
59209139Srpaulo	msg.msg_namelen = sizeof(drv->priv_addr);
60209139Srpaulo
61209139Srpaulo	if (sendmsg(drv->cmd_socket, &msg, 0) < 0) {
62209139Srpaulo		perror("sendmsg(cmd_socket)");
63209139Srpaulo		return -1;
64209139Srpaulo	}
65209139Srpaulo
66209139Srpaulo	if (reply) {
67209139Srpaulo		fd_set rfds;
68209139Srpaulo		struct timeval tv;
69209139Srpaulo		int res;
70209139Srpaulo
71209139Srpaulo		FD_ZERO(&rfds);
72209139Srpaulo		FD_SET(drv->cmd_socket, &rfds);
73209139Srpaulo		tv.tv_sec = 5;
74209139Srpaulo		tv.tv_usec = 0;
75209139Srpaulo		res = select(drv->cmd_socket + 1, &rfds, NULL, NULL, &tv);
76209139Srpaulo		if (res < 0 && errno != EINTR) {
77209139Srpaulo			perror("select");
78209139Srpaulo			return -1;
79209139Srpaulo		}
80209139Srpaulo
81209139Srpaulo		if (FD_ISSET(drv->cmd_socket, &rfds)) {
82209139Srpaulo			res = recv(drv->cmd_socket, reply, *reply_len, 0);
83209139Srpaulo			if (res < 0) {
84209139Srpaulo				perror("recv");
85209139Srpaulo				return -1;
86209139Srpaulo			}
87209139Srpaulo			*reply_len = res;
88209139Srpaulo		} else {
89209139Srpaulo			wpa_printf(MSG_DEBUG, "PRIVSEP: Timeout while waiting "
90209139Srpaulo				   "for reply (cmd=%d)", cmd);
91209139Srpaulo			return -1;
92209139Srpaulo		}
93209139Srpaulo	}
94209139Srpaulo
95209139Srpaulo	return 0;
96209139Srpaulo}
97209139Srpaulo
98209139Srpaulo
99214501Srpaulostatic int wpa_driver_privsep_scan(void *priv,
100214501Srpaulo				   struct wpa_driver_scan_params *params)
101209139Srpaulo{
102209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
103214501Srpaulo	const u8 *ssid = params->ssids[0].ssid;
104214501Srpaulo	size_t ssid_len = params->ssids[0].ssid_len;
105209139Srpaulo	wpa_printf(MSG_DEBUG, "%s: priv=%p", __func__, priv);
106209139Srpaulo	return wpa_priv_cmd(drv, PRIVSEP_CMD_SCAN, ssid, ssid_len,
107209139Srpaulo			    NULL, NULL);
108209139Srpaulo}
109209139Srpaulo
110209139Srpaulo
111209139Srpaulostatic struct wpa_scan_results *
112209139Srpaulowpa_driver_privsep_get_scan_results2(void *priv)
113209139Srpaulo{
114209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
115209139Srpaulo	int res, num;
116209139Srpaulo	u8 *buf, *pos, *end;
117209139Srpaulo	size_t reply_len = 60000;
118209139Srpaulo	struct wpa_scan_results *results;
119209139Srpaulo	struct wpa_scan_res *r;
120209139Srpaulo
121209139Srpaulo	buf = os_malloc(reply_len);
122209139Srpaulo	if (buf == NULL)
123209139Srpaulo		return NULL;
124209139Srpaulo	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SCAN_RESULTS,
125209139Srpaulo			   NULL, 0, buf, &reply_len);
126209139Srpaulo	if (res < 0) {
127209139Srpaulo		os_free(buf);
128209139Srpaulo		return NULL;
129209139Srpaulo	}
130209139Srpaulo
131209139Srpaulo	wpa_printf(MSG_DEBUG, "privsep: Received %lu bytes of scan results",
132209139Srpaulo		   (unsigned long) reply_len);
133209139Srpaulo	if (reply_len < sizeof(int)) {
134209139Srpaulo		wpa_printf(MSG_DEBUG, "privsep: Invalid scan result len %lu",
135209139Srpaulo			   (unsigned long) reply_len);
136209139Srpaulo		os_free(buf);
137209139Srpaulo		return NULL;
138209139Srpaulo	}
139209139Srpaulo
140209139Srpaulo	pos = buf;
141209139Srpaulo	end = buf + reply_len;
142209139Srpaulo	os_memcpy(&num, pos, sizeof(int));
143209139Srpaulo	if (num < 0 || num > 1000) {
144209139Srpaulo		os_free(buf);
145209139Srpaulo		return NULL;
146209139Srpaulo	}
147209139Srpaulo	pos += sizeof(int);
148209139Srpaulo
149209139Srpaulo	results = os_zalloc(sizeof(*results));
150209139Srpaulo	if (results == NULL) {
151209139Srpaulo		os_free(buf);
152209139Srpaulo		return NULL;
153209139Srpaulo	}
154209139Srpaulo
155252190Srpaulo	results->res = os_calloc(num, sizeof(struct wpa_scan_res *));
156209139Srpaulo	if (results->res == NULL) {
157209139Srpaulo		os_free(results);
158209139Srpaulo		os_free(buf);
159209139Srpaulo		return NULL;
160209139Srpaulo	}
161209139Srpaulo
162209139Srpaulo	while (results->num < (size_t) num && pos + sizeof(int) < end) {
163209139Srpaulo		int len;
164209139Srpaulo		os_memcpy(&len, pos, sizeof(int));
165209139Srpaulo		pos += sizeof(int);
166209139Srpaulo		if (len < 0 || len > 10000 || pos + len > end)
167209139Srpaulo			break;
168209139Srpaulo
169209139Srpaulo		r = os_malloc(len);
170209139Srpaulo		if (r == NULL)
171209139Srpaulo			break;
172209139Srpaulo		os_memcpy(r, pos, len);
173209139Srpaulo		pos += len;
174209139Srpaulo		if (sizeof(*r) + r->ie_len > (size_t) len) {
175209139Srpaulo			os_free(r);
176209139Srpaulo			break;
177209139Srpaulo		}
178209139Srpaulo
179209139Srpaulo		results->res[results->num++] = r;
180209139Srpaulo	}
181209139Srpaulo
182209139Srpaulo	os_free(buf);
183209139Srpaulo	return results;
184209139Srpaulo}
185209139Srpaulo
186209139Srpaulo
187214501Srpaulostatic int wpa_driver_privsep_set_key(const char *ifname, void *priv,
188214501Srpaulo				      enum wpa_alg alg, const u8 *addr,
189214501Srpaulo				      int key_idx, int set_tx,
190214501Srpaulo				      const u8 *seq, size_t seq_len,
191214501Srpaulo				      const u8 *key, size_t key_len)
192209139Srpaulo{
193209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
194209139Srpaulo	struct privsep_cmd_set_key cmd;
195209139Srpaulo
196209139Srpaulo	wpa_printf(MSG_DEBUG, "%s: priv=%p alg=%d key_idx=%d set_tx=%d",
197209139Srpaulo		   __func__, priv, alg, key_idx, set_tx);
198209139Srpaulo
199209139Srpaulo	os_memset(&cmd, 0, sizeof(cmd));
200209139Srpaulo	cmd.alg = alg;
201209139Srpaulo	if (addr)
202209139Srpaulo		os_memcpy(cmd.addr, addr, ETH_ALEN);
203209139Srpaulo	else
204209139Srpaulo		os_memset(cmd.addr, 0xff, ETH_ALEN);
205209139Srpaulo	cmd.key_idx = key_idx;
206209139Srpaulo	cmd.set_tx = set_tx;
207209139Srpaulo	if (seq && seq_len > 0 && seq_len < sizeof(cmd.seq)) {
208209139Srpaulo		os_memcpy(cmd.seq, seq, seq_len);
209209139Srpaulo		cmd.seq_len = seq_len;
210209139Srpaulo	}
211209139Srpaulo	if (key && key_len > 0 && key_len < sizeof(cmd.key)) {
212209139Srpaulo		os_memcpy(cmd.key, key, key_len);
213209139Srpaulo		cmd.key_len = key_len;
214209139Srpaulo	}
215209139Srpaulo
216209139Srpaulo	return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_KEY, &cmd, sizeof(cmd),
217209139Srpaulo			    NULL, NULL);
218209139Srpaulo}
219209139Srpaulo
220209139Srpaulo
221209139Srpaulostatic int wpa_driver_privsep_associate(
222209139Srpaulo	void *priv, struct wpa_driver_associate_params *params)
223209139Srpaulo{
224209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
225209139Srpaulo	struct privsep_cmd_associate *data;
226209139Srpaulo	int res;
227209139Srpaulo	size_t buflen;
228209139Srpaulo
229209139Srpaulo	wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d pairwise_suite=%d "
230209139Srpaulo		   "group_suite=%d key_mgmt_suite=%d auth_alg=%d mode=%d",
231209139Srpaulo		   __func__, priv, params->freq, params->pairwise_suite,
232209139Srpaulo		   params->group_suite, params->key_mgmt_suite,
233209139Srpaulo		   params->auth_alg, params->mode);
234209139Srpaulo
235209139Srpaulo	buflen = sizeof(*data) + params->wpa_ie_len;
236209139Srpaulo	data = os_zalloc(buflen);
237209139Srpaulo	if (data == NULL)
238209139Srpaulo		return -1;
239209139Srpaulo
240209139Srpaulo	if (params->bssid)
241209139Srpaulo		os_memcpy(data->bssid, params->bssid, ETH_ALEN);
242209139Srpaulo	os_memcpy(data->ssid, params->ssid, params->ssid_len);
243209139Srpaulo	data->ssid_len = params->ssid_len;
244209139Srpaulo	data->freq = params->freq;
245209139Srpaulo	data->pairwise_suite = params->pairwise_suite;
246209139Srpaulo	data->group_suite = params->group_suite;
247209139Srpaulo	data->key_mgmt_suite = params->key_mgmt_suite;
248209139Srpaulo	data->auth_alg = params->auth_alg;
249209139Srpaulo	data->mode = params->mode;
250209139Srpaulo	data->wpa_ie_len = params->wpa_ie_len;
251209139Srpaulo	if (params->wpa_ie)
252209139Srpaulo		os_memcpy(data + 1, params->wpa_ie, params->wpa_ie_len);
253209139Srpaulo	/* TODO: add support for other assoc parameters */
254209139Srpaulo
255209139Srpaulo	res = wpa_priv_cmd(drv, PRIVSEP_CMD_ASSOCIATE, data, buflen,
256209139Srpaulo			   NULL, NULL);
257209139Srpaulo	os_free(data);
258209139Srpaulo
259209139Srpaulo	return res;
260209139Srpaulo}
261209139Srpaulo
262209139Srpaulo
263209139Srpaulostatic int wpa_driver_privsep_get_bssid(void *priv, u8 *bssid)
264209139Srpaulo{
265209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
266209139Srpaulo	int res;
267209139Srpaulo	size_t len = ETH_ALEN;
268209139Srpaulo
269209139Srpaulo	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_BSSID, NULL, 0, bssid, &len);
270209139Srpaulo	if (res < 0 || len != ETH_ALEN)
271209139Srpaulo		return -1;
272209139Srpaulo	return 0;
273209139Srpaulo}
274209139Srpaulo
275209139Srpaulo
276209139Srpaulostatic int wpa_driver_privsep_get_ssid(void *priv, u8 *ssid)
277209139Srpaulo{
278209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
279209139Srpaulo	int res, ssid_len;
280209139Srpaulo	u8 reply[sizeof(int) + 32];
281209139Srpaulo	size_t len = sizeof(reply);
282209139Srpaulo
283209139Srpaulo	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SSID, NULL, 0, reply, &len);
284209139Srpaulo	if (res < 0 || len < sizeof(int))
285209139Srpaulo		return -1;
286209139Srpaulo	os_memcpy(&ssid_len, reply, sizeof(int));
287209139Srpaulo	if (ssid_len < 0 || ssid_len > 32 || sizeof(int) + ssid_len > len) {
288209139Srpaulo		wpa_printf(MSG_DEBUG, "privsep: Invalid get SSID reply");
289209139Srpaulo		return -1;
290209139Srpaulo	}
291209139Srpaulo	os_memcpy(ssid, &reply[sizeof(int)], ssid_len);
292209139Srpaulo	return ssid_len;
293209139Srpaulo}
294209139Srpaulo
295209139Srpaulo
296209139Srpaulostatic int wpa_driver_privsep_deauthenticate(void *priv, const u8 *addr,
297209139Srpaulo					  int reason_code)
298209139Srpaulo{
299209139Srpaulo	//struct wpa_driver_privsep_data *drv = priv;
300209139Srpaulo	wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
301209139Srpaulo		   __func__, MAC2STR(addr), reason_code);
302209139Srpaulo	wpa_printf(MSG_DEBUG, "%s - TODO", __func__);
303209139Srpaulo	return 0;
304209139Srpaulo}
305209139Srpaulo
306209139Srpaulo
307214501Srpaulostatic void wpa_driver_privsep_event_assoc(void *ctx,
308214501Srpaulo					   enum wpa_event_type event,
309209139Srpaulo					   u8 *buf, size_t len)
310209139Srpaulo{
311209139Srpaulo	union wpa_event_data data;
312209139Srpaulo	int inc_data = 0;
313209139Srpaulo	u8 *pos, *end;
314209139Srpaulo	int ie_len;
315209139Srpaulo
316209139Srpaulo	os_memset(&data, 0, sizeof(data));
317209139Srpaulo
318209139Srpaulo	pos = buf;
319209139Srpaulo	end = buf + len;
320209139Srpaulo
321209139Srpaulo	if (end - pos < (int) sizeof(int))
322209139Srpaulo		return;
323209139Srpaulo	os_memcpy(&ie_len, pos, sizeof(int));
324209139Srpaulo	pos += sizeof(int);
325209139Srpaulo	if (ie_len < 0 || ie_len > end - pos)
326209139Srpaulo		return;
327209139Srpaulo	if (ie_len) {
328209139Srpaulo		data.assoc_info.req_ies = pos;
329209139Srpaulo		data.assoc_info.req_ies_len = ie_len;
330209139Srpaulo		pos += ie_len;
331209139Srpaulo		inc_data = 1;
332209139Srpaulo	}
333209139Srpaulo
334209139Srpaulo	wpa_supplicant_event(ctx, event, inc_data ? &data : NULL);
335209139Srpaulo}
336209139Srpaulo
337209139Srpaulo
338209139Srpaulostatic void wpa_driver_privsep_event_interface_status(void *ctx, u8 *buf,
339209139Srpaulo						      size_t len)
340209139Srpaulo{
341209139Srpaulo	union wpa_event_data data;
342209139Srpaulo	int ievent;
343209139Srpaulo
344209139Srpaulo	if (len < sizeof(int) ||
345209139Srpaulo	    len - sizeof(int) > sizeof(data.interface_status.ifname))
346209139Srpaulo		return;
347209139Srpaulo
348209139Srpaulo	os_memcpy(&ievent, buf, sizeof(int));
349209139Srpaulo
350209139Srpaulo	os_memset(&data, 0, sizeof(data));
351209139Srpaulo	data.interface_status.ievent = ievent;
352209139Srpaulo	os_memcpy(data.interface_status.ifname, buf + sizeof(int),
353209139Srpaulo		  len - sizeof(int));
354209139Srpaulo	wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &data);
355209139Srpaulo}
356209139Srpaulo
357209139Srpaulo
358209139Srpaulostatic void wpa_driver_privsep_event_michael_mic_failure(
359209139Srpaulo	void *ctx, u8 *buf, size_t len)
360209139Srpaulo{
361209139Srpaulo	union wpa_event_data data;
362209139Srpaulo
363209139Srpaulo	if (len != sizeof(int))
364209139Srpaulo		return;
365209139Srpaulo
366209139Srpaulo	os_memset(&data, 0, sizeof(data));
367209139Srpaulo	os_memcpy(&data.michael_mic_failure.unicast, buf, sizeof(int));
368209139Srpaulo	wpa_supplicant_event(ctx, EVENT_MICHAEL_MIC_FAILURE, &data);
369209139Srpaulo}
370209139Srpaulo
371209139Srpaulo
372209139Srpaulostatic void wpa_driver_privsep_event_pmkid_candidate(void *ctx, u8 *buf,
373209139Srpaulo						     size_t len)
374209139Srpaulo{
375209139Srpaulo	union wpa_event_data data;
376209139Srpaulo
377209139Srpaulo	if (len != sizeof(struct pmkid_candidate))
378209139Srpaulo		return;
379209139Srpaulo
380209139Srpaulo	os_memset(&data, 0, sizeof(data));
381209139Srpaulo	os_memcpy(&data.pmkid_candidate, buf, len);
382209139Srpaulo	wpa_supplicant_event(ctx, EVENT_PMKID_CANDIDATE, &data);
383209139Srpaulo}
384209139Srpaulo
385209139Srpaulo
386209139Srpaulostatic void wpa_driver_privsep_event_stkstart(void *ctx, u8 *buf, size_t len)
387209139Srpaulo{
388209139Srpaulo	union wpa_event_data data;
389209139Srpaulo
390209139Srpaulo	if (len != ETH_ALEN)
391209139Srpaulo		return;
392209139Srpaulo
393209139Srpaulo	os_memset(&data, 0, sizeof(data));
394209139Srpaulo	os_memcpy(data.stkstart.peer, buf, ETH_ALEN);
395209139Srpaulo	wpa_supplicant_event(ctx, EVENT_STKSTART, &data);
396209139Srpaulo}
397209139Srpaulo
398209139Srpaulo
399209139Srpaulostatic void wpa_driver_privsep_event_ft_response(void *ctx, u8 *buf,
400209139Srpaulo						 size_t len)
401209139Srpaulo{
402209139Srpaulo	union wpa_event_data data;
403209139Srpaulo
404209139Srpaulo	if (len < sizeof(int) + ETH_ALEN)
405209139Srpaulo		return;
406209139Srpaulo
407209139Srpaulo	os_memset(&data, 0, sizeof(data));
408209139Srpaulo	os_memcpy(&data.ft_ies.ft_action, buf, sizeof(int));
409209139Srpaulo	os_memcpy(data.ft_ies.target_ap, buf + sizeof(int), ETH_ALEN);
410209139Srpaulo	data.ft_ies.ies = buf + sizeof(int) + ETH_ALEN;
411209139Srpaulo	data.ft_ies.ies_len = len - sizeof(int) - ETH_ALEN;
412209139Srpaulo	wpa_supplicant_event(ctx, EVENT_FT_RESPONSE, &data);
413209139Srpaulo}
414209139Srpaulo
415209139Srpaulo
416209139Srpaulostatic void wpa_driver_privsep_event_rx_eapol(void *ctx, u8 *buf, size_t len)
417209139Srpaulo{
418209139Srpaulo	if (len < ETH_ALEN)
419209139Srpaulo		return;
420214501Srpaulo	drv_event_eapol_rx(ctx, buf, buf + ETH_ALEN, len - ETH_ALEN);
421209139Srpaulo}
422209139Srpaulo
423209139Srpaulo
424209139Srpaulostatic void wpa_driver_privsep_receive(int sock, void *eloop_ctx,
425209139Srpaulo				       void *sock_ctx)
426209139Srpaulo{
427209139Srpaulo	struct wpa_driver_privsep_data *drv = eloop_ctx;
428209139Srpaulo	u8 *buf, *event_buf;
429209139Srpaulo	size_t event_len;
430209139Srpaulo	int res, event;
431209139Srpaulo	enum privsep_event e;
432209139Srpaulo	struct sockaddr_un from;
433209139Srpaulo	socklen_t fromlen = sizeof(from);
434209139Srpaulo	const size_t buflen = 2000;
435209139Srpaulo
436209139Srpaulo	buf = os_malloc(buflen);
437209139Srpaulo	if (buf == NULL)
438209139Srpaulo		return;
439209139Srpaulo	res = recvfrom(sock, buf, buflen, 0,
440209139Srpaulo		       (struct sockaddr *) &from, &fromlen);
441209139Srpaulo	if (res < 0) {
442209139Srpaulo		perror("recvfrom(priv_socket)");
443209139Srpaulo		os_free(buf);
444209139Srpaulo		return;
445209139Srpaulo	}
446209139Srpaulo
447209139Srpaulo	wpa_printf(MSG_DEBUG, "privsep_driver: received %u bytes", res);
448209139Srpaulo
449209139Srpaulo	if (res < (int) sizeof(int)) {
450209139Srpaulo		wpa_printf(MSG_DEBUG, "Too short event message (len=%d)", res);
451209139Srpaulo		return;
452209139Srpaulo	}
453209139Srpaulo
454209139Srpaulo	os_memcpy(&event, buf, sizeof(int));
455209139Srpaulo	event_buf = &buf[sizeof(int)];
456209139Srpaulo	event_len = res - sizeof(int);
457209139Srpaulo	wpa_printf(MSG_DEBUG, "privsep: Event %d received (len=%lu)",
458209139Srpaulo		   event, (unsigned long) event_len);
459209139Srpaulo
460209139Srpaulo	e = event;
461209139Srpaulo	switch (e) {
462209139Srpaulo	case PRIVSEP_EVENT_SCAN_RESULTS:
463209139Srpaulo		wpa_supplicant_event(drv->ctx, EVENT_SCAN_RESULTS, NULL);
464209139Srpaulo		break;
465209139Srpaulo	case PRIVSEP_EVENT_ASSOC:
466209139Srpaulo		wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOC,
467209139Srpaulo					       event_buf, event_len);
468209139Srpaulo		break;
469209139Srpaulo	case PRIVSEP_EVENT_DISASSOC:
470209139Srpaulo		wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
471209139Srpaulo		break;
472209139Srpaulo	case PRIVSEP_EVENT_ASSOCINFO:
473209139Srpaulo		wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOCINFO,
474209139Srpaulo					       event_buf, event_len);
475209139Srpaulo		break;
476209139Srpaulo	case PRIVSEP_EVENT_MICHAEL_MIC_FAILURE:
477209139Srpaulo		wpa_driver_privsep_event_michael_mic_failure(
478209139Srpaulo			drv->ctx, event_buf, event_len);
479209139Srpaulo		break;
480209139Srpaulo	case PRIVSEP_EVENT_INTERFACE_STATUS:
481209139Srpaulo		wpa_driver_privsep_event_interface_status(drv->ctx, event_buf,
482209139Srpaulo							  event_len);
483209139Srpaulo		break;
484209139Srpaulo	case PRIVSEP_EVENT_PMKID_CANDIDATE:
485209139Srpaulo		wpa_driver_privsep_event_pmkid_candidate(drv->ctx, event_buf,
486209139Srpaulo							 event_len);
487209139Srpaulo		break;
488209139Srpaulo	case PRIVSEP_EVENT_STKSTART:
489209139Srpaulo		wpa_driver_privsep_event_stkstart(drv->ctx, event_buf,
490209139Srpaulo						  event_len);
491209139Srpaulo		break;
492209139Srpaulo	case PRIVSEP_EVENT_FT_RESPONSE:
493209139Srpaulo		wpa_driver_privsep_event_ft_response(drv->ctx, event_buf,
494209139Srpaulo						     event_len);
495209139Srpaulo		break;
496209139Srpaulo	case PRIVSEP_EVENT_RX_EAPOL:
497209139Srpaulo		wpa_driver_privsep_event_rx_eapol(drv->ctx, event_buf,
498209139Srpaulo						  event_len);
499209139Srpaulo		break;
500209139Srpaulo	}
501209139Srpaulo
502209139Srpaulo	os_free(buf);
503209139Srpaulo}
504209139Srpaulo
505209139Srpaulo
506209139Srpaulostatic void * wpa_driver_privsep_init(void *ctx, const char *ifname)
507209139Srpaulo{
508209139Srpaulo	struct wpa_driver_privsep_data *drv;
509209139Srpaulo
510209139Srpaulo	drv = os_zalloc(sizeof(*drv));
511209139Srpaulo	if (drv == NULL)
512209139Srpaulo		return NULL;
513209139Srpaulo	drv->ctx = ctx;
514209139Srpaulo	drv->priv_socket = -1;
515209139Srpaulo	drv->cmd_socket = -1;
516209139Srpaulo	os_strlcpy(drv->ifname, ifname, sizeof(drv->ifname));
517209139Srpaulo
518209139Srpaulo	return drv;
519209139Srpaulo}
520209139Srpaulo
521209139Srpaulo
522209139Srpaulostatic void wpa_driver_privsep_deinit(void *priv)
523209139Srpaulo{
524209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
525209139Srpaulo
526209139Srpaulo	if (drv->priv_socket >= 0) {
527209139Srpaulo		wpa_priv_reg_cmd(drv, PRIVSEP_CMD_UNREGISTER);
528209139Srpaulo		eloop_unregister_read_sock(drv->priv_socket);
529209139Srpaulo		close(drv->priv_socket);
530209139Srpaulo	}
531209139Srpaulo
532209139Srpaulo	if (drv->own_socket_path) {
533209139Srpaulo		unlink(drv->own_socket_path);
534209139Srpaulo		os_free(drv->own_socket_path);
535209139Srpaulo	}
536209139Srpaulo
537209139Srpaulo	if (drv->cmd_socket >= 0) {
538209139Srpaulo		eloop_unregister_read_sock(drv->cmd_socket);
539209139Srpaulo		close(drv->cmd_socket);
540209139Srpaulo	}
541209139Srpaulo
542209139Srpaulo	if (drv->own_cmd_path) {
543209139Srpaulo		unlink(drv->own_cmd_path);
544209139Srpaulo		os_free(drv->own_cmd_path);
545209139Srpaulo	}
546209139Srpaulo
547209139Srpaulo	os_free(drv);
548209139Srpaulo}
549209139Srpaulo
550209139Srpaulo
551209139Srpaulostatic int wpa_driver_privsep_set_param(void *priv, const char *param)
552209139Srpaulo{
553209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
554209139Srpaulo	const char *pos;
555209139Srpaulo	char *own_dir, *priv_dir;
556209139Srpaulo	static unsigned int counter = 0;
557209139Srpaulo	size_t len;
558209139Srpaulo	struct sockaddr_un addr;
559209139Srpaulo
560209139Srpaulo	wpa_printf(MSG_DEBUG, "%s: param='%s'", __func__, param);
561209139Srpaulo	if (param == NULL)
562209139Srpaulo		pos = NULL;
563209139Srpaulo	else
564209139Srpaulo		pos = os_strstr(param, "own_dir=");
565209139Srpaulo	if (pos) {
566209139Srpaulo		char *end;
567209139Srpaulo		own_dir = os_strdup(pos + 8);
568209139Srpaulo		if (own_dir == NULL)
569209139Srpaulo			return -1;
570209139Srpaulo		end = os_strchr(own_dir, ' ');
571209139Srpaulo		if (end)
572209139Srpaulo			*end = '\0';
573209139Srpaulo	} else {
574209139Srpaulo		own_dir = os_strdup("/tmp");
575209139Srpaulo		if (own_dir == NULL)
576209139Srpaulo			return -1;
577209139Srpaulo	}
578209139Srpaulo
579209139Srpaulo	if (param == NULL)
580209139Srpaulo		pos = NULL;
581209139Srpaulo	else
582209139Srpaulo		pos = os_strstr(param, "priv_dir=");
583209139Srpaulo	if (pos) {
584209139Srpaulo		char *end;
585209139Srpaulo		priv_dir = os_strdup(pos + 9);
586209139Srpaulo		if (priv_dir == NULL) {
587209139Srpaulo			os_free(own_dir);
588209139Srpaulo			return -1;
589209139Srpaulo		}
590209139Srpaulo		end = os_strchr(priv_dir, ' ');
591209139Srpaulo		if (end)
592209139Srpaulo			*end = '\0';
593209139Srpaulo	} else {
594209139Srpaulo		priv_dir = os_strdup("/var/run/wpa_priv");
595209139Srpaulo		if (priv_dir == NULL) {
596209139Srpaulo			os_free(own_dir);
597209139Srpaulo			return -1;
598209139Srpaulo		}
599209139Srpaulo	}
600209139Srpaulo
601209139Srpaulo	len = os_strlen(own_dir) + 50;
602209139Srpaulo	drv->own_socket_path = os_malloc(len);
603209139Srpaulo	if (drv->own_socket_path == NULL) {
604209139Srpaulo		os_free(priv_dir);
605209139Srpaulo		os_free(own_dir);
606209139Srpaulo		return -1;
607209139Srpaulo	}
608209139Srpaulo	os_snprintf(drv->own_socket_path, len, "%s/wpa_privsep-%d-%d",
609209139Srpaulo		    own_dir, getpid(), counter++);
610209139Srpaulo
611209139Srpaulo	len = os_strlen(own_dir) + 50;
612209139Srpaulo	drv->own_cmd_path = os_malloc(len);
613209139Srpaulo	if (drv->own_cmd_path == NULL) {
614209139Srpaulo		os_free(drv->own_socket_path);
615209139Srpaulo		drv->own_socket_path = NULL;
616209139Srpaulo		os_free(priv_dir);
617209139Srpaulo		os_free(own_dir);
618209139Srpaulo		return -1;
619209139Srpaulo	}
620209139Srpaulo	os_snprintf(drv->own_cmd_path, len, "%s/wpa_privsep-%d-%d",
621209139Srpaulo		    own_dir, getpid(), counter++);
622209139Srpaulo
623209139Srpaulo	os_free(own_dir);
624209139Srpaulo
625209139Srpaulo	drv->priv_addr.sun_family = AF_UNIX;
626209139Srpaulo	os_snprintf(drv->priv_addr.sun_path, sizeof(drv->priv_addr.sun_path),
627209139Srpaulo		    "%s/%s", priv_dir, drv->ifname);
628209139Srpaulo	os_free(priv_dir);
629209139Srpaulo
630209139Srpaulo	drv->priv_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
631209139Srpaulo	if (drv->priv_socket < 0) {
632209139Srpaulo		perror("socket(PF_UNIX)");
633209139Srpaulo		os_free(drv->own_socket_path);
634209139Srpaulo		drv->own_socket_path = NULL;
635209139Srpaulo		return -1;
636209139Srpaulo	}
637209139Srpaulo
638209139Srpaulo	os_memset(&addr, 0, sizeof(addr));
639209139Srpaulo	addr.sun_family = AF_UNIX;
640209139Srpaulo	os_strlcpy(addr.sun_path, drv->own_socket_path, sizeof(addr.sun_path));
641209139Srpaulo	if (bind(drv->priv_socket, (struct sockaddr *) &addr, sizeof(addr)) <
642209139Srpaulo	    0) {
643252190Srpaulo		perror("privsep-set-params priv-sock: bind(PF_UNIX)");
644209139Srpaulo		close(drv->priv_socket);
645209139Srpaulo		drv->priv_socket = -1;
646209139Srpaulo		unlink(drv->own_socket_path);
647209139Srpaulo		os_free(drv->own_socket_path);
648209139Srpaulo		drv->own_socket_path = NULL;
649209139Srpaulo		return -1;
650209139Srpaulo	}
651209139Srpaulo
652209139Srpaulo	eloop_register_read_sock(drv->priv_socket, wpa_driver_privsep_receive,
653209139Srpaulo				 drv, NULL);
654209139Srpaulo
655209139Srpaulo	drv->cmd_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
656209139Srpaulo	if (drv->cmd_socket < 0) {
657209139Srpaulo		perror("socket(PF_UNIX)");
658209139Srpaulo		os_free(drv->own_cmd_path);
659209139Srpaulo		drv->own_cmd_path = NULL;
660209139Srpaulo		return -1;
661209139Srpaulo	}
662209139Srpaulo
663209139Srpaulo	os_memset(&addr, 0, sizeof(addr));
664209139Srpaulo	addr.sun_family = AF_UNIX;
665209139Srpaulo	os_strlcpy(addr.sun_path, drv->own_cmd_path, sizeof(addr.sun_path));
666209139Srpaulo	if (bind(drv->cmd_socket, (struct sockaddr *) &addr, sizeof(addr)) < 0)
667209139Srpaulo	{
668252190Srpaulo		perror("privsep-set-params cmd-sock: bind(PF_UNIX)");
669209139Srpaulo		close(drv->cmd_socket);
670209139Srpaulo		drv->cmd_socket = -1;
671209139Srpaulo		unlink(drv->own_cmd_path);
672209139Srpaulo		os_free(drv->own_cmd_path);
673209139Srpaulo		drv->own_cmd_path = NULL;
674209139Srpaulo		return -1;
675209139Srpaulo	}
676209139Srpaulo
677209139Srpaulo	if (wpa_priv_reg_cmd(drv, PRIVSEP_CMD_REGISTER) < 0) {
678209139Srpaulo		wpa_printf(MSG_ERROR, "Failed to register with wpa_priv");
679209139Srpaulo		return -1;
680209139Srpaulo	}
681209139Srpaulo
682209139Srpaulo	return 0;
683209139Srpaulo}
684209139Srpaulo
685209139Srpaulo
686209139Srpaulostatic int wpa_driver_privsep_get_capa(void *priv,
687209139Srpaulo				       struct wpa_driver_capa *capa)
688209139Srpaulo{
689209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
690209139Srpaulo	int res;
691209139Srpaulo	size_t len = sizeof(*capa);
692209139Srpaulo
693209139Srpaulo	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_CAPA, NULL, 0, capa, &len);
694209139Srpaulo	if (res < 0 || len != sizeof(*capa))
695209139Srpaulo		return -1;
696209139Srpaulo	return 0;
697209139Srpaulo}
698209139Srpaulo
699209139Srpaulo
700209139Srpaulostatic const u8 * wpa_driver_privsep_get_mac_addr(void *priv)
701209139Srpaulo{
702209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
703209139Srpaulo	wpa_printf(MSG_DEBUG, "%s", __func__);
704209139Srpaulo	return drv->own_addr;
705209139Srpaulo}
706209139Srpaulo
707209139Srpaulo
708209139Srpaulostatic int wpa_driver_privsep_set_country(void *priv, const char *alpha2)
709209139Srpaulo{
710209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
711209139Srpaulo	wpa_printf(MSG_DEBUG, "%s country='%s'", __func__, alpha2);
712209139Srpaulo	return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_COUNTRY, alpha2,
713209139Srpaulo			    os_strlen(alpha2), NULL, NULL);
714209139Srpaulo}
715209139Srpaulo
716209139Srpaulo
717209139Srpaulostruct wpa_driver_ops wpa_driver_privsep_ops = {
718209139Srpaulo	"privsep",
719209139Srpaulo	"wpa_supplicant privilege separated driver",
720214501Srpaulo	.get_bssid = wpa_driver_privsep_get_bssid,
721214501Srpaulo	.get_ssid = wpa_driver_privsep_get_ssid,
722214501Srpaulo	.set_key = wpa_driver_privsep_set_key,
723214501Srpaulo	.init = wpa_driver_privsep_init,
724214501Srpaulo	.deinit = wpa_driver_privsep_deinit,
725214501Srpaulo	.set_param = wpa_driver_privsep_set_param,
726214501Srpaulo	.scan2 = wpa_driver_privsep_scan,
727214501Srpaulo	.deauthenticate = wpa_driver_privsep_deauthenticate,
728214501Srpaulo	.associate = wpa_driver_privsep_associate,
729214501Srpaulo	.get_capa = wpa_driver_privsep_get_capa,
730214501Srpaulo	.get_mac_addr = wpa_driver_privsep_get_mac_addr,
731214501Srpaulo	.get_scan_results2 = wpa_driver_privsep_get_scan_results2,
732214501Srpaulo	.set_country = wpa_driver_privsep_set_country,
733209139Srpaulo};
734209139Srpaulo
735209139Srpaulo
736214501Srpaulostruct wpa_driver_ops *wpa_drivers[] =
737209139Srpaulo{
738209139Srpaulo	&wpa_driver_privsep_ops,
739209139Srpaulo	NULL
740209139Srpaulo};
741