1209139Srpaulo/*
2209139Srpaulo * WPA Supplicant - privilege separated driver interface
3209139Srpaulo * Copyright (c) 2007-2009, Jouni Malinen <j@w1.fi>
4209139Srpaulo *
5252190Srpaulo * This software may be distributed under the terms of the BSD license.
6252190Srpaulo * See README for more details.
7209139Srpaulo */
8209139Srpaulo
9209139Srpaulo#include "includes.h"
10209139Srpaulo#include <sys/un.h>
11209139Srpaulo
12209139Srpaulo#include "common.h"
13209139Srpaulo#include "driver.h"
14209139Srpaulo#include "eloop.h"
15214501Srpaulo#include "common/privsep_commands.h"
16209139Srpaulo
17209139Srpaulo
18209139Srpaulostruct wpa_driver_privsep_data {
19209139Srpaulo	void *ctx;
20209139Srpaulo	u8 own_addr[ETH_ALEN];
21209139Srpaulo	int priv_socket;
22209139Srpaulo	char *own_socket_path;
23209139Srpaulo	int cmd_socket;
24209139Srpaulo	char *own_cmd_path;
25209139Srpaulo	struct sockaddr_un priv_addr;
26209139Srpaulo	char ifname[16];
27209139Srpaulo};
28209139Srpaulo
29209139Srpaulo
30209139Srpaulostatic int wpa_priv_reg_cmd(struct wpa_driver_privsep_data *drv, int cmd)
31209139Srpaulo{
32209139Srpaulo	int res;
33209139Srpaulo
34209139Srpaulo	res = sendto(drv->priv_socket, &cmd, sizeof(cmd), 0,
35209139Srpaulo		     (struct sockaddr *) &drv->priv_addr,
36209139Srpaulo		     sizeof(drv->priv_addr));
37209139Srpaulo	if (res < 0)
38281806Srpaulo		wpa_printf(MSG_ERROR, "sendto: %s", strerror(errno));
39209139Srpaulo	return res < 0 ? -1 : 0;
40209139Srpaulo}
41209139Srpaulo
42209139Srpaulo
43209139Srpaulostatic int wpa_priv_cmd(struct wpa_driver_privsep_data *drv, int cmd,
44209139Srpaulo			const void *data, size_t data_len,
45209139Srpaulo			void *reply, size_t *reply_len)
46209139Srpaulo{
47209139Srpaulo	struct msghdr msg;
48209139Srpaulo	struct iovec io[2];
49209139Srpaulo
50209139Srpaulo	io[0].iov_base = &cmd;
51209139Srpaulo	io[0].iov_len = sizeof(cmd);
52209139Srpaulo	io[1].iov_base = (u8 *) data;
53209139Srpaulo	io[1].iov_len = data_len;
54209139Srpaulo
55209139Srpaulo	os_memset(&msg, 0, sizeof(msg));
56209139Srpaulo	msg.msg_iov = io;
57209139Srpaulo	msg.msg_iovlen = data ? 2 : 1;
58209139Srpaulo	msg.msg_name = &drv->priv_addr;
59209139Srpaulo	msg.msg_namelen = sizeof(drv->priv_addr);
60209139Srpaulo
61209139Srpaulo	if (sendmsg(drv->cmd_socket, &msg, 0) < 0) {
62281806Srpaulo		wpa_printf(MSG_ERROR, "sendmsg(cmd_socket): %s",
63281806Srpaulo			   strerror(errno));
64209139Srpaulo		return -1;
65209139Srpaulo	}
66209139Srpaulo
67209139Srpaulo	if (reply) {
68209139Srpaulo		fd_set rfds;
69209139Srpaulo		struct timeval tv;
70209139Srpaulo		int res;
71209139Srpaulo
72209139Srpaulo		FD_ZERO(&rfds);
73209139Srpaulo		FD_SET(drv->cmd_socket, &rfds);
74209139Srpaulo		tv.tv_sec = 5;
75209139Srpaulo		tv.tv_usec = 0;
76209139Srpaulo		res = select(drv->cmd_socket + 1, &rfds, NULL, NULL, &tv);
77209139Srpaulo		if (res < 0 && errno != EINTR) {
78281806Srpaulo			wpa_printf(MSG_ERROR, "select: %s", strerror(errno));
79209139Srpaulo			return -1;
80209139Srpaulo		}
81209139Srpaulo
82209139Srpaulo		if (FD_ISSET(drv->cmd_socket, &rfds)) {
83209139Srpaulo			res = recv(drv->cmd_socket, reply, *reply_len, 0);
84209139Srpaulo			if (res < 0) {
85281806Srpaulo				wpa_printf(MSG_ERROR, "recv: %s",
86281806Srpaulo					   strerror(errno));
87209139Srpaulo				return -1;
88209139Srpaulo			}
89209139Srpaulo			*reply_len = res;
90209139Srpaulo		} else {
91209139Srpaulo			wpa_printf(MSG_DEBUG, "PRIVSEP: Timeout while waiting "
92209139Srpaulo				   "for reply (cmd=%d)", cmd);
93209139Srpaulo			return -1;
94209139Srpaulo		}
95209139Srpaulo	}
96209139Srpaulo
97209139Srpaulo	return 0;
98209139Srpaulo}
99209139Srpaulo
100346981Scy
101214501Srpaulostatic int wpa_driver_privsep_scan(void *priv,
102214501Srpaulo				   struct wpa_driver_scan_params *params)
103209139Srpaulo{
104209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
105346981Scy	struct privsep_cmd_scan scan;
106346981Scy	size_t i;
107346981Scy
108209139Srpaulo	wpa_printf(MSG_DEBUG, "%s: priv=%p", __func__, priv);
109346981Scy	os_memset(&scan, 0, sizeof(scan));
110346981Scy	scan.num_ssids = params->num_ssids;
111346981Scy	for (i = 0; i < params->num_ssids; i++) {
112346981Scy		if (!params->ssids[i].ssid)
113346981Scy			continue;
114346981Scy		scan.ssid_lens[i] = params->ssids[i].ssid_len;
115346981Scy		os_memcpy(scan.ssids[i], params->ssids[i].ssid,
116346981Scy			  scan.ssid_lens[i]);
117346981Scy	}
118346981Scy
119346981Scy	for (i = 0; i < PRIVSEP_MAX_SCAN_FREQS &&
120346981Scy		     params->freqs && params->freqs[i]; i++)
121346981Scy		scan.freqs[i] = params->freqs[i];
122346981Scy	scan.num_freqs = i;
123346981Scy
124346981Scy	return wpa_priv_cmd(drv, PRIVSEP_CMD_SCAN, &scan, sizeof(scan),
125209139Srpaulo			    NULL, NULL);
126209139Srpaulo}
127209139Srpaulo
128209139Srpaulo
129209139Srpaulostatic struct wpa_scan_results *
130209139Srpaulowpa_driver_privsep_get_scan_results2(void *priv)
131209139Srpaulo{
132209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
133209139Srpaulo	int res, num;
134209139Srpaulo	u8 *buf, *pos, *end;
135209139Srpaulo	size_t reply_len = 60000;
136209139Srpaulo	struct wpa_scan_results *results;
137209139Srpaulo	struct wpa_scan_res *r;
138209139Srpaulo
139209139Srpaulo	buf = os_malloc(reply_len);
140209139Srpaulo	if (buf == NULL)
141209139Srpaulo		return NULL;
142209139Srpaulo	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SCAN_RESULTS,
143209139Srpaulo			   NULL, 0, buf, &reply_len);
144209139Srpaulo	if (res < 0) {
145209139Srpaulo		os_free(buf);
146209139Srpaulo		return NULL;
147209139Srpaulo	}
148209139Srpaulo
149209139Srpaulo	wpa_printf(MSG_DEBUG, "privsep: Received %lu bytes of scan results",
150209139Srpaulo		   (unsigned long) reply_len);
151209139Srpaulo	if (reply_len < sizeof(int)) {
152209139Srpaulo		wpa_printf(MSG_DEBUG, "privsep: Invalid scan result len %lu",
153209139Srpaulo			   (unsigned long) reply_len);
154209139Srpaulo		os_free(buf);
155209139Srpaulo		return NULL;
156209139Srpaulo	}
157209139Srpaulo
158209139Srpaulo	pos = buf;
159209139Srpaulo	end = buf + reply_len;
160209139Srpaulo	os_memcpy(&num, pos, sizeof(int));
161209139Srpaulo	if (num < 0 || num > 1000) {
162209139Srpaulo		os_free(buf);
163209139Srpaulo		return NULL;
164209139Srpaulo	}
165209139Srpaulo	pos += sizeof(int);
166209139Srpaulo
167209139Srpaulo	results = os_zalloc(sizeof(*results));
168209139Srpaulo	if (results == NULL) {
169209139Srpaulo		os_free(buf);
170209139Srpaulo		return NULL;
171209139Srpaulo	}
172209139Srpaulo
173252190Srpaulo	results->res = os_calloc(num, sizeof(struct wpa_scan_res *));
174209139Srpaulo	if (results->res == NULL) {
175209139Srpaulo		os_free(results);
176209139Srpaulo		os_free(buf);
177209139Srpaulo		return NULL;
178209139Srpaulo	}
179209139Srpaulo
180337817Scy	while (results->num < (size_t) num && end - pos > (int) sizeof(int)) {
181209139Srpaulo		int len;
182209139Srpaulo		os_memcpy(&len, pos, sizeof(int));
183209139Srpaulo		pos += sizeof(int);
184337817Scy		if (len < 0 || len > 10000 || len > end - pos)
185209139Srpaulo			break;
186209139Srpaulo
187346981Scy		r = os_memdup(pos, len);
188209139Srpaulo		if (r == NULL)
189209139Srpaulo			break;
190209139Srpaulo		pos += len;
191346981Scy		if (sizeof(*r) + r->ie_len + r->beacon_ie_len > (size_t) len) {
192346981Scy			wpa_printf(MSG_ERROR,
193346981Scy				   "privsep: Invalid scan result len (%d + %d + %d > %d)",
194346981Scy				   (int) sizeof(*r), (int) r->ie_len,
195346981Scy				   (int) r->beacon_ie_len, len);
196209139Srpaulo			os_free(r);
197209139Srpaulo			break;
198209139Srpaulo		}
199209139Srpaulo
200209139Srpaulo		results->res[results->num++] = r;
201209139Srpaulo	}
202209139Srpaulo
203209139Srpaulo	os_free(buf);
204209139Srpaulo	return results;
205209139Srpaulo}
206209139Srpaulo
207209139Srpaulo
208214501Srpaulostatic int wpa_driver_privsep_set_key(const char *ifname, void *priv,
209214501Srpaulo				      enum wpa_alg alg, const u8 *addr,
210214501Srpaulo				      int key_idx, int set_tx,
211214501Srpaulo				      const u8 *seq, size_t seq_len,
212214501Srpaulo				      const u8 *key, size_t key_len)
213209139Srpaulo{
214209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
215209139Srpaulo	struct privsep_cmd_set_key cmd;
216209139Srpaulo
217209139Srpaulo	wpa_printf(MSG_DEBUG, "%s: priv=%p alg=%d key_idx=%d set_tx=%d",
218209139Srpaulo		   __func__, priv, alg, key_idx, set_tx);
219209139Srpaulo
220209139Srpaulo	os_memset(&cmd, 0, sizeof(cmd));
221209139Srpaulo	cmd.alg = alg;
222209139Srpaulo	if (addr)
223209139Srpaulo		os_memcpy(cmd.addr, addr, ETH_ALEN);
224209139Srpaulo	else
225209139Srpaulo		os_memset(cmd.addr, 0xff, ETH_ALEN);
226209139Srpaulo	cmd.key_idx = key_idx;
227209139Srpaulo	cmd.set_tx = set_tx;
228209139Srpaulo	if (seq && seq_len > 0 && seq_len < sizeof(cmd.seq)) {
229209139Srpaulo		os_memcpy(cmd.seq, seq, seq_len);
230209139Srpaulo		cmd.seq_len = seq_len;
231209139Srpaulo	}
232209139Srpaulo	if (key && key_len > 0 && key_len < sizeof(cmd.key)) {
233209139Srpaulo		os_memcpy(cmd.key, key, key_len);
234209139Srpaulo		cmd.key_len = key_len;
235209139Srpaulo	}
236209139Srpaulo
237209139Srpaulo	return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_KEY, &cmd, sizeof(cmd),
238209139Srpaulo			    NULL, NULL);
239209139Srpaulo}
240209139Srpaulo
241209139Srpaulo
242289549Srpaulostatic int wpa_driver_privsep_authenticate(
243289549Srpaulo	void *priv, struct wpa_driver_auth_params *params)
244289549Srpaulo{
245289549Srpaulo	struct wpa_driver_privsep_data *drv = priv;
246289549Srpaulo	struct privsep_cmd_authenticate *data;
247289549Srpaulo	int i, res;
248289549Srpaulo	size_t buflen;
249289549Srpaulo	u8 *pos;
250289549Srpaulo
251289549Srpaulo	wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d bssid=" MACSTR
252289549Srpaulo		   " auth_alg=%d local_state_change=%d p2p=%d",
253289549Srpaulo		   __func__, priv, params->freq, MAC2STR(params->bssid),
254289549Srpaulo		   params->auth_alg, params->local_state_change, params->p2p);
255289549Srpaulo
256346981Scy	buflen = sizeof(*data) + params->ie_len + params->auth_data_len;
257289549Srpaulo	data = os_zalloc(buflen);
258289549Srpaulo	if (data == NULL)
259289549Srpaulo		return -1;
260289549Srpaulo
261289549Srpaulo	data->freq = params->freq;
262289549Srpaulo	os_memcpy(data->bssid, params->bssid, ETH_ALEN);
263289549Srpaulo	os_memcpy(data->ssid, params->ssid, params->ssid_len);
264289549Srpaulo	data->ssid_len = params->ssid_len;
265289549Srpaulo	data->auth_alg = params->auth_alg;
266289549Srpaulo	data->ie_len = params->ie_len;
267289549Srpaulo	for (i = 0; i < 4; i++) {
268289549Srpaulo		if (params->wep_key[i])
269289549Srpaulo			os_memcpy(data->wep_key[i], params->wep_key[i],
270289549Srpaulo				  params->wep_key_len[i]);
271289549Srpaulo		data->wep_key_len[i] = params->wep_key_len[i];
272289549Srpaulo	}
273289549Srpaulo	data->wep_tx_keyidx = params->wep_tx_keyidx;
274289549Srpaulo	data->local_state_change = params->local_state_change;
275289549Srpaulo	data->p2p = params->p2p;
276289549Srpaulo	pos = (u8 *) (data + 1);
277289549Srpaulo	if (params->ie_len) {
278289549Srpaulo		os_memcpy(pos, params->ie, params->ie_len);
279289549Srpaulo		pos += params->ie_len;
280289549Srpaulo	}
281346981Scy	if (params->auth_data_len)
282346981Scy		os_memcpy(pos, params->auth_data, params->auth_data_len);
283289549Srpaulo
284289549Srpaulo	res = wpa_priv_cmd(drv, PRIVSEP_CMD_AUTHENTICATE, data, buflen,
285289549Srpaulo			   NULL, NULL);
286289549Srpaulo	os_free(data);
287289549Srpaulo
288289549Srpaulo	return res;
289289549Srpaulo}
290289549Srpaulo
291289549Srpaulo
292209139Srpaulostatic int wpa_driver_privsep_associate(
293209139Srpaulo	void *priv, struct wpa_driver_associate_params *params)
294209139Srpaulo{
295209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
296209139Srpaulo	struct privsep_cmd_associate *data;
297209139Srpaulo	int res;
298209139Srpaulo	size_t buflen;
299209139Srpaulo
300209139Srpaulo	wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d pairwise_suite=%d "
301209139Srpaulo		   "group_suite=%d key_mgmt_suite=%d auth_alg=%d mode=%d",
302281806Srpaulo		   __func__, priv, params->freq.freq, params->pairwise_suite,
303209139Srpaulo		   params->group_suite, params->key_mgmt_suite,
304209139Srpaulo		   params->auth_alg, params->mode);
305209139Srpaulo
306209139Srpaulo	buflen = sizeof(*data) + params->wpa_ie_len;
307209139Srpaulo	data = os_zalloc(buflen);
308209139Srpaulo	if (data == NULL)
309209139Srpaulo		return -1;
310209139Srpaulo
311209139Srpaulo	if (params->bssid)
312209139Srpaulo		os_memcpy(data->bssid, params->bssid, ETH_ALEN);
313209139Srpaulo	os_memcpy(data->ssid, params->ssid, params->ssid_len);
314209139Srpaulo	data->ssid_len = params->ssid_len;
315281806Srpaulo	data->hwmode = params->freq.mode;
316281806Srpaulo	data->freq = params->freq.freq;
317281806Srpaulo	data->channel = params->freq.channel;
318209139Srpaulo	data->pairwise_suite = params->pairwise_suite;
319209139Srpaulo	data->group_suite = params->group_suite;
320209139Srpaulo	data->key_mgmt_suite = params->key_mgmt_suite;
321209139Srpaulo	data->auth_alg = params->auth_alg;
322209139Srpaulo	data->mode = params->mode;
323209139Srpaulo	data->wpa_ie_len = params->wpa_ie_len;
324209139Srpaulo	if (params->wpa_ie)
325209139Srpaulo		os_memcpy(data + 1, params->wpa_ie, params->wpa_ie_len);
326209139Srpaulo	/* TODO: add support for other assoc parameters */
327209139Srpaulo
328209139Srpaulo	res = wpa_priv_cmd(drv, PRIVSEP_CMD_ASSOCIATE, data, buflen,
329209139Srpaulo			   NULL, NULL);
330209139Srpaulo	os_free(data);
331209139Srpaulo
332209139Srpaulo	return res;
333209139Srpaulo}
334209139Srpaulo
335209139Srpaulo
336209139Srpaulostatic int wpa_driver_privsep_get_bssid(void *priv, u8 *bssid)
337209139Srpaulo{
338209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
339209139Srpaulo	int res;
340209139Srpaulo	size_t len = ETH_ALEN;
341209139Srpaulo
342209139Srpaulo	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_BSSID, NULL, 0, bssid, &len);
343209139Srpaulo	if (res < 0 || len != ETH_ALEN)
344209139Srpaulo		return -1;
345209139Srpaulo	return 0;
346209139Srpaulo}
347209139Srpaulo
348209139Srpaulo
349209139Srpaulostatic int wpa_driver_privsep_get_ssid(void *priv, u8 *ssid)
350209139Srpaulo{
351209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
352209139Srpaulo	int res, ssid_len;
353289549Srpaulo	u8 reply[sizeof(int) + SSID_MAX_LEN];
354209139Srpaulo	size_t len = sizeof(reply);
355209139Srpaulo
356209139Srpaulo	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SSID, NULL, 0, reply, &len);
357209139Srpaulo	if (res < 0 || len < sizeof(int))
358209139Srpaulo		return -1;
359209139Srpaulo	os_memcpy(&ssid_len, reply, sizeof(int));
360289549Srpaulo	if (ssid_len < 0 || ssid_len > SSID_MAX_LEN ||
361289549Srpaulo	    sizeof(int) + ssid_len > len) {
362209139Srpaulo		wpa_printf(MSG_DEBUG, "privsep: Invalid get SSID reply");
363209139Srpaulo		return -1;
364209139Srpaulo	}
365209139Srpaulo	os_memcpy(ssid, &reply[sizeof(int)], ssid_len);
366209139Srpaulo	return ssid_len;
367209139Srpaulo}
368209139Srpaulo
369209139Srpaulo
370209139Srpaulostatic int wpa_driver_privsep_deauthenticate(void *priv, const u8 *addr,
371351611Scy					     u16 reason_code)
372209139Srpaulo{
373209139Srpaulo	//struct wpa_driver_privsep_data *drv = priv;
374209139Srpaulo	wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
375209139Srpaulo		   __func__, MAC2STR(addr), reason_code);
376209139Srpaulo	wpa_printf(MSG_DEBUG, "%s - TODO", __func__);
377209139Srpaulo	return 0;
378209139Srpaulo}
379209139Srpaulo
380209139Srpaulo
381289549Srpaulostatic void wpa_driver_privsep_event_auth(void *ctx, u8 *buf, size_t len)
382289549Srpaulo{
383289549Srpaulo	union wpa_event_data data;
384289549Srpaulo	struct privsep_event_auth *auth;
385289549Srpaulo
386289549Srpaulo	os_memset(&data, 0, sizeof(data));
387289549Srpaulo	if (len < sizeof(*auth))
388289549Srpaulo		return;
389289549Srpaulo	auth = (struct privsep_event_auth *) buf;
390289549Srpaulo	if (len < sizeof(*auth) + auth->ies_len)
391289549Srpaulo		return;
392289549Srpaulo
393289549Srpaulo	os_memcpy(data.auth.peer, auth->peer, ETH_ALEN);
394289549Srpaulo	os_memcpy(data.auth.bssid, auth->bssid, ETH_ALEN);
395289549Srpaulo	data.auth.auth_type = auth->auth_type;
396289549Srpaulo	data.auth.auth_transaction = auth->auth_transaction;
397289549Srpaulo	data.auth.status_code = auth->status_code;
398289549Srpaulo	if (auth->ies_len) {
399289549Srpaulo		data.auth.ies = (u8 *) (auth + 1);
400289549Srpaulo		data.auth.ies_len = auth->ies_len;
401289549Srpaulo	}
402289549Srpaulo
403289549Srpaulo	wpa_supplicant_event(ctx, EVENT_AUTH, &data);
404289549Srpaulo}
405289549Srpaulo
406289549Srpaulo
407214501Srpaulostatic void wpa_driver_privsep_event_assoc(void *ctx,
408214501Srpaulo					   enum wpa_event_type event,
409209139Srpaulo					   u8 *buf, size_t len)
410209139Srpaulo{
411209139Srpaulo	union wpa_event_data data;
412209139Srpaulo	int inc_data = 0;
413209139Srpaulo	u8 *pos, *end;
414209139Srpaulo	int ie_len;
415209139Srpaulo
416209139Srpaulo	os_memset(&data, 0, sizeof(data));
417209139Srpaulo
418209139Srpaulo	pos = buf;
419209139Srpaulo	end = buf + len;
420209139Srpaulo
421209139Srpaulo	if (end - pos < (int) sizeof(int))
422209139Srpaulo		return;
423209139Srpaulo	os_memcpy(&ie_len, pos, sizeof(int));
424209139Srpaulo	pos += sizeof(int);
425209139Srpaulo	if (ie_len < 0 || ie_len > end - pos)
426209139Srpaulo		return;
427209139Srpaulo	if (ie_len) {
428209139Srpaulo		data.assoc_info.req_ies = pos;
429209139Srpaulo		data.assoc_info.req_ies_len = ie_len;
430209139Srpaulo		pos += ie_len;
431209139Srpaulo		inc_data = 1;
432209139Srpaulo	}
433209139Srpaulo
434209139Srpaulo	wpa_supplicant_event(ctx, event, inc_data ? &data : NULL);
435209139Srpaulo}
436209139Srpaulo
437209139Srpaulo
438209139Srpaulostatic void wpa_driver_privsep_event_interface_status(void *ctx, u8 *buf,
439209139Srpaulo						      size_t len)
440209139Srpaulo{
441209139Srpaulo	union wpa_event_data data;
442209139Srpaulo	int ievent;
443209139Srpaulo
444209139Srpaulo	if (len < sizeof(int) ||
445209139Srpaulo	    len - sizeof(int) > sizeof(data.interface_status.ifname))
446209139Srpaulo		return;
447209139Srpaulo
448209139Srpaulo	os_memcpy(&ievent, buf, sizeof(int));
449209139Srpaulo
450209139Srpaulo	os_memset(&data, 0, sizeof(data));
451209139Srpaulo	data.interface_status.ievent = ievent;
452209139Srpaulo	os_memcpy(data.interface_status.ifname, buf + sizeof(int),
453209139Srpaulo		  len - sizeof(int));
454209139Srpaulo	wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &data);
455209139Srpaulo}
456209139Srpaulo
457209139Srpaulo
458209139Srpaulostatic void wpa_driver_privsep_event_michael_mic_failure(
459209139Srpaulo	void *ctx, u8 *buf, size_t len)
460209139Srpaulo{
461209139Srpaulo	union wpa_event_data data;
462209139Srpaulo
463209139Srpaulo	if (len != sizeof(int))
464209139Srpaulo		return;
465209139Srpaulo
466209139Srpaulo	os_memset(&data, 0, sizeof(data));
467209139Srpaulo	os_memcpy(&data.michael_mic_failure.unicast, buf, sizeof(int));
468209139Srpaulo	wpa_supplicant_event(ctx, EVENT_MICHAEL_MIC_FAILURE, &data);
469209139Srpaulo}
470209139Srpaulo
471209139Srpaulo
472209139Srpaulostatic void wpa_driver_privsep_event_pmkid_candidate(void *ctx, u8 *buf,
473209139Srpaulo						     size_t len)
474209139Srpaulo{
475209139Srpaulo	union wpa_event_data data;
476209139Srpaulo
477209139Srpaulo	if (len != sizeof(struct pmkid_candidate))
478209139Srpaulo		return;
479209139Srpaulo
480209139Srpaulo	os_memset(&data, 0, sizeof(data));
481209139Srpaulo	os_memcpy(&data.pmkid_candidate, buf, len);
482209139Srpaulo	wpa_supplicant_event(ctx, EVENT_PMKID_CANDIDATE, &data);
483209139Srpaulo}
484209139Srpaulo
485209139Srpaulo
486209139Srpaulostatic void wpa_driver_privsep_event_ft_response(void *ctx, u8 *buf,
487209139Srpaulo						 size_t len)
488209139Srpaulo{
489209139Srpaulo	union wpa_event_data data;
490209139Srpaulo
491209139Srpaulo	if (len < sizeof(int) + ETH_ALEN)
492209139Srpaulo		return;
493209139Srpaulo
494209139Srpaulo	os_memset(&data, 0, sizeof(data));
495209139Srpaulo	os_memcpy(&data.ft_ies.ft_action, buf, sizeof(int));
496209139Srpaulo	os_memcpy(data.ft_ies.target_ap, buf + sizeof(int), ETH_ALEN);
497209139Srpaulo	data.ft_ies.ies = buf + sizeof(int) + ETH_ALEN;
498209139Srpaulo	data.ft_ies.ies_len = len - sizeof(int) - ETH_ALEN;
499209139Srpaulo	wpa_supplicant_event(ctx, EVENT_FT_RESPONSE, &data);
500209139Srpaulo}
501209139Srpaulo
502209139Srpaulo
503209139Srpaulostatic void wpa_driver_privsep_event_rx_eapol(void *ctx, u8 *buf, size_t len)
504209139Srpaulo{
505209139Srpaulo	if (len < ETH_ALEN)
506209139Srpaulo		return;
507214501Srpaulo	drv_event_eapol_rx(ctx, buf, buf + ETH_ALEN, len - ETH_ALEN);
508209139Srpaulo}
509209139Srpaulo
510209139Srpaulo
511209139Srpaulostatic void wpa_driver_privsep_receive(int sock, void *eloop_ctx,
512209139Srpaulo				       void *sock_ctx)
513209139Srpaulo{
514209139Srpaulo	struct wpa_driver_privsep_data *drv = eloop_ctx;
515209139Srpaulo	u8 *buf, *event_buf;
516209139Srpaulo	size_t event_len;
517209139Srpaulo	int res, event;
518209139Srpaulo	enum privsep_event e;
519209139Srpaulo	struct sockaddr_un from;
520209139Srpaulo	socklen_t fromlen = sizeof(from);
521209139Srpaulo	const size_t buflen = 2000;
522209139Srpaulo
523209139Srpaulo	buf = os_malloc(buflen);
524209139Srpaulo	if (buf == NULL)
525209139Srpaulo		return;
526209139Srpaulo	res = recvfrom(sock, buf, buflen, 0,
527209139Srpaulo		       (struct sockaddr *) &from, &fromlen);
528209139Srpaulo	if (res < 0) {
529281806Srpaulo		wpa_printf(MSG_ERROR, "recvfrom(priv_socket): %s",
530281806Srpaulo			   strerror(errno));
531209139Srpaulo		os_free(buf);
532209139Srpaulo		return;
533209139Srpaulo	}
534209139Srpaulo
535209139Srpaulo	wpa_printf(MSG_DEBUG, "privsep_driver: received %u bytes", res);
536209139Srpaulo
537209139Srpaulo	if (res < (int) sizeof(int)) {
538209139Srpaulo		wpa_printf(MSG_DEBUG, "Too short event message (len=%d)", res);
539209139Srpaulo		return;
540209139Srpaulo	}
541209139Srpaulo
542209139Srpaulo	os_memcpy(&event, buf, sizeof(int));
543209139Srpaulo	event_buf = &buf[sizeof(int)];
544209139Srpaulo	event_len = res - sizeof(int);
545209139Srpaulo	wpa_printf(MSG_DEBUG, "privsep: Event %d received (len=%lu)",
546209139Srpaulo		   event, (unsigned long) event_len);
547209139Srpaulo
548209139Srpaulo	e = event;
549209139Srpaulo	switch (e) {
550209139Srpaulo	case PRIVSEP_EVENT_SCAN_RESULTS:
551209139Srpaulo		wpa_supplicant_event(drv->ctx, EVENT_SCAN_RESULTS, NULL);
552209139Srpaulo		break;
553289549Srpaulo	case PRIVSEP_EVENT_SCAN_STARTED:
554289549Srpaulo		wpa_supplicant_event(drv->ctx, EVENT_SCAN_STARTED, NULL);
555289549Srpaulo		break;
556209139Srpaulo	case PRIVSEP_EVENT_ASSOC:
557209139Srpaulo		wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOC,
558209139Srpaulo					       event_buf, event_len);
559209139Srpaulo		break;
560209139Srpaulo	case PRIVSEP_EVENT_DISASSOC:
561209139Srpaulo		wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
562209139Srpaulo		break;
563209139Srpaulo	case PRIVSEP_EVENT_ASSOCINFO:
564209139Srpaulo		wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOCINFO,
565209139Srpaulo					       event_buf, event_len);
566209139Srpaulo		break;
567209139Srpaulo	case PRIVSEP_EVENT_MICHAEL_MIC_FAILURE:
568209139Srpaulo		wpa_driver_privsep_event_michael_mic_failure(
569209139Srpaulo			drv->ctx, event_buf, event_len);
570209139Srpaulo		break;
571209139Srpaulo	case PRIVSEP_EVENT_INTERFACE_STATUS:
572209139Srpaulo		wpa_driver_privsep_event_interface_status(drv->ctx, event_buf,
573209139Srpaulo							  event_len);
574209139Srpaulo		break;
575209139Srpaulo	case PRIVSEP_EVENT_PMKID_CANDIDATE:
576209139Srpaulo		wpa_driver_privsep_event_pmkid_candidate(drv->ctx, event_buf,
577209139Srpaulo							 event_len);
578209139Srpaulo		break;
579209139Srpaulo	case PRIVSEP_EVENT_FT_RESPONSE:
580209139Srpaulo		wpa_driver_privsep_event_ft_response(drv->ctx, event_buf,
581209139Srpaulo						     event_len);
582209139Srpaulo		break;
583209139Srpaulo	case PRIVSEP_EVENT_RX_EAPOL:
584209139Srpaulo		wpa_driver_privsep_event_rx_eapol(drv->ctx, event_buf,
585209139Srpaulo						  event_len);
586209139Srpaulo		break;
587289549Srpaulo	case PRIVSEP_EVENT_AUTH:
588289549Srpaulo		wpa_driver_privsep_event_auth(drv->ctx, event_buf, event_len);
589289549Srpaulo		break;
590209139Srpaulo	}
591209139Srpaulo
592209139Srpaulo	os_free(buf);
593209139Srpaulo}
594209139Srpaulo
595209139Srpaulo
596209139Srpaulostatic void * wpa_driver_privsep_init(void *ctx, const char *ifname)
597209139Srpaulo{
598209139Srpaulo	struct wpa_driver_privsep_data *drv;
599209139Srpaulo
600209139Srpaulo	drv = os_zalloc(sizeof(*drv));
601209139Srpaulo	if (drv == NULL)
602209139Srpaulo		return NULL;
603209139Srpaulo	drv->ctx = ctx;
604209139Srpaulo	drv->priv_socket = -1;
605209139Srpaulo	drv->cmd_socket = -1;
606209139Srpaulo	os_strlcpy(drv->ifname, ifname, sizeof(drv->ifname));
607209139Srpaulo
608209139Srpaulo	return drv;
609209139Srpaulo}
610209139Srpaulo
611209139Srpaulo
612209139Srpaulostatic void wpa_driver_privsep_deinit(void *priv)
613209139Srpaulo{
614209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
615209139Srpaulo
616209139Srpaulo	if (drv->priv_socket >= 0) {
617209139Srpaulo		wpa_priv_reg_cmd(drv, PRIVSEP_CMD_UNREGISTER);
618209139Srpaulo		eloop_unregister_read_sock(drv->priv_socket);
619209139Srpaulo		close(drv->priv_socket);
620209139Srpaulo	}
621209139Srpaulo
622209139Srpaulo	if (drv->own_socket_path) {
623209139Srpaulo		unlink(drv->own_socket_path);
624209139Srpaulo		os_free(drv->own_socket_path);
625209139Srpaulo	}
626209139Srpaulo
627209139Srpaulo	if (drv->cmd_socket >= 0) {
628209139Srpaulo		eloop_unregister_read_sock(drv->cmd_socket);
629209139Srpaulo		close(drv->cmd_socket);
630209139Srpaulo	}
631209139Srpaulo
632209139Srpaulo	if (drv->own_cmd_path) {
633209139Srpaulo		unlink(drv->own_cmd_path);
634209139Srpaulo		os_free(drv->own_cmd_path);
635209139Srpaulo	}
636209139Srpaulo
637209139Srpaulo	os_free(drv);
638209139Srpaulo}
639209139Srpaulo
640209139Srpaulo
641209139Srpaulostatic int wpa_driver_privsep_set_param(void *priv, const char *param)
642209139Srpaulo{
643209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
644209139Srpaulo	const char *pos;
645209139Srpaulo	char *own_dir, *priv_dir;
646209139Srpaulo	static unsigned int counter = 0;
647209139Srpaulo	size_t len;
648209139Srpaulo	struct sockaddr_un addr;
649209139Srpaulo
650209139Srpaulo	wpa_printf(MSG_DEBUG, "%s: param='%s'", __func__, param);
651209139Srpaulo	if (param == NULL)
652209139Srpaulo		pos = NULL;
653209139Srpaulo	else
654209139Srpaulo		pos = os_strstr(param, "own_dir=");
655209139Srpaulo	if (pos) {
656209139Srpaulo		char *end;
657209139Srpaulo		own_dir = os_strdup(pos + 8);
658209139Srpaulo		if (own_dir == NULL)
659209139Srpaulo			return -1;
660209139Srpaulo		end = os_strchr(own_dir, ' ');
661209139Srpaulo		if (end)
662209139Srpaulo			*end = '\0';
663209139Srpaulo	} else {
664209139Srpaulo		own_dir = os_strdup("/tmp");
665209139Srpaulo		if (own_dir == NULL)
666209139Srpaulo			return -1;
667209139Srpaulo	}
668209139Srpaulo
669209139Srpaulo	if (param == NULL)
670209139Srpaulo		pos = NULL;
671209139Srpaulo	else
672209139Srpaulo		pos = os_strstr(param, "priv_dir=");
673209139Srpaulo	if (pos) {
674209139Srpaulo		char *end;
675209139Srpaulo		priv_dir = os_strdup(pos + 9);
676209139Srpaulo		if (priv_dir == NULL) {
677209139Srpaulo			os_free(own_dir);
678209139Srpaulo			return -1;
679209139Srpaulo		}
680209139Srpaulo		end = os_strchr(priv_dir, ' ');
681209139Srpaulo		if (end)
682209139Srpaulo			*end = '\0';
683209139Srpaulo	} else {
684209139Srpaulo		priv_dir = os_strdup("/var/run/wpa_priv");
685209139Srpaulo		if (priv_dir == NULL) {
686209139Srpaulo			os_free(own_dir);
687209139Srpaulo			return -1;
688209139Srpaulo		}
689209139Srpaulo	}
690209139Srpaulo
691209139Srpaulo	len = os_strlen(own_dir) + 50;
692209139Srpaulo	drv->own_socket_path = os_malloc(len);
693209139Srpaulo	if (drv->own_socket_path == NULL) {
694209139Srpaulo		os_free(priv_dir);
695209139Srpaulo		os_free(own_dir);
696209139Srpaulo		return -1;
697209139Srpaulo	}
698209139Srpaulo	os_snprintf(drv->own_socket_path, len, "%s/wpa_privsep-%d-%d",
699209139Srpaulo		    own_dir, getpid(), counter++);
700209139Srpaulo
701209139Srpaulo	len = os_strlen(own_dir) + 50;
702209139Srpaulo	drv->own_cmd_path = os_malloc(len);
703209139Srpaulo	if (drv->own_cmd_path == NULL) {
704209139Srpaulo		os_free(drv->own_socket_path);
705209139Srpaulo		drv->own_socket_path = NULL;
706209139Srpaulo		os_free(priv_dir);
707209139Srpaulo		os_free(own_dir);
708209139Srpaulo		return -1;
709209139Srpaulo	}
710209139Srpaulo	os_snprintf(drv->own_cmd_path, len, "%s/wpa_privsep-%d-%d",
711209139Srpaulo		    own_dir, getpid(), counter++);
712209139Srpaulo
713209139Srpaulo	os_free(own_dir);
714209139Srpaulo
715209139Srpaulo	drv->priv_addr.sun_family = AF_UNIX;
716209139Srpaulo	os_snprintf(drv->priv_addr.sun_path, sizeof(drv->priv_addr.sun_path),
717209139Srpaulo		    "%s/%s", priv_dir, drv->ifname);
718209139Srpaulo	os_free(priv_dir);
719209139Srpaulo
720209139Srpaulo	drv->priv_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
721209139Srpaulo	if (drv->priv_socket < 0) {
722281806Srpaulo		wpa_printf(MSG_ERROR, "socket(PF_UNIX): %s", strerror(errno));
723209139Srpaulo		os_free(drv->own_socket_path);
724209139Srpaulo		drv->own_socket_path = NULL;
725209139Srpaulo		return -1;
726209139Srpaulo	}
727209139Srpaulo
728209139Srpaulo	os_memset(&addr, 0, sizeof(addr));
729209139Srpaulo	addr.sun_family = AF_UNIX;
730209139Srpaulo	os_strlcpy(addr.sun_path, drv->own_socket_path, sizeof(addr.sun_path));
731209139Srpaulo	if (bind(drv->priv_socket, (struct sockaddr *) &addr, sizeof(addr)) <
732209139Srpaulo	    0) {
733281806Srpaulo		wpa_printf(MSG_ERROR,
734281806Srpaulo			   "privsep-set-params priv-sock: bind(PF_UNIX): %s",
735281806Srpaulo			   strerror(errno));
736209139Srpaulo		close(drv->priv_socket);
737209139Srpaulo		drv->priv_socket = -1;
738209139Srpaulo		unlink(drv->own_socket_path);
739209139Srpaulo		os_free(drv->own_socket_path);
740209139Srpaulo		drv->own_socket_path = NULL;
741209139Srpaulo		return -1;
742209139Srpaulo	}
743209139Srpaulo
744209139Srpaulo	eloop_register_read_sock(drv->priv_socket, wpa_driver_privsep_receive,
745209139Srpaulo				 drv, NULL);
746209139Srpaulo
747209139Srpaulo	drv->cmd_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
748209139Srpaulo	if (drv->cmd_socket < 0) {
749281806Srpaulo		wpa_printf(MSG_ERROR, "socket(PF_UNIX): %s", strerror(errno));
750209139Srpaulo		os_free(drv->own_cmd_path);
751209139Srpaulo		drv->own_cmd_path = NULL;
752209139Srpaulo		return -1;
753209139Srpaulo	}
754209139Srpaulo
755209139Srpaulo	os_memset(&addr, 0, sizeof(addr));
756209139Srpaulo	addr.sun_family = AF_UNIX;
757209139Srpaulo	os_strlcpy(addr.sun_path, drv->own_cmd_path, sizeof(addr.sun_path));
758209139Srpaulo	if (bind(drv->cmd_socket, (struct sockaddr *) &addr, sizeof(addr)) < 0)
759209139Srpaulo	{
760281806Srpaulo		wpa_printf(MSG_ERROR,
761281806Srpaulo			   "privsep-set-params cmd-sock: bind(PF_UNIX): %s",
762281806Srpaulo			   strerror(errno));
763209139Srpaulo		close(drv->cmd_socket);
764209139Srpaulo		drv->cmd_socket = -1;
765209139Srpaulo		unlink(drv->own_cmd_path);
766209139Srpaulo		os_free(drv->own_cmd_path);
767209139Srpaulo		drv->own_cmd_path = NULL;
768209139Srpaulo		return -1;
769209139Srpaulo	}
770209139Srpaulo
771209139Srpaulo	if (wpa_priv_reg_cmd(drv, PRIVSEP_CMD_REGISTER) < 0) {
772209139Srpaulo		wpa_printf(MSG_ERROR, "Failed to register with wpa_priv");
773209139Srpaulo		return -1;
774209139Srpaulo	}
775209139Srpaulo
776209139Srpaulo	return 0;
777209139Srpaulo}
778209139Srpaulo
779209139Srpaulo
780209139Srpaulostatic int wpa_driver_privsep_get_capa(void *priv,
781209139Srpaulo				       struct wpa_driver_capa *capa)
782209139Srpaulo{
783209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
784209139Srpaulo	int res;
785209139Srpaulo	size_t len = sizeof(*capa);
786209139Srpaulo
787209139Srpaulo	res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_CAPA, NULL, 0, capa, &len);
788209139Srpaulo	if (res < 0 || len != sizeof(*capa))
789209139Srpaulo		return -1;
790289549Srpaulo	/* For now, no support for passing extended_capa pointers */
791289549Srpaulo	capa->extended_capa = NULL;
792289549Srpaulo	capa->extended_capa_mask = NULL;
793289549Srpaulo	capa->extended_capa_len = 0;
794209139Srpaulo	return 0;
795209139Srpaulo}
796209139Srpaulo
797209139Srpaulo
798209139Srpaulostatic const u8 * wpa_driver_privsep_get_mac_addr(void *priv)
799209139Srpaulo{
800209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
801209139Srpaulo	wpa_printf(MSG_DEBUG, "%s", __func__);
802209139Srpaulo	return drv->own_addr;
803209139Srpaulo}
804209139Srpaulo
805209139Srpaulo
806209139Srpaulostatic int wpa_driver_privsep_set_country(void *priv, const char *alpha2)
807209139Srpaulo{
808209139Srpaulo	struct wpa_driver_privsep_data *drv = priv;
809209139Srpaulo	wpa_printf(MSG_DEBUG, "%s country='%s'", __func__, alpha2);
810209139Srpaulo	return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_COUNTRY, alpha2,
811209139Srpaulo			    os_strlen(alpha2), NULL, NULL);
812209139Srpaulo}
813209139Srpaulo
814209139Srpaulo
815209139Srpaulostruct wpa_driver_ops wpa_driver_privsep_ops = {
816209139Srpaulo	"privsep",
817209139Srpaulo	"wpa_supplicant privilege separated driver",
818214501Srpaulo	.get_bssid = wpa_driver_privsep_get_bssid,
819214501Srpaulo	.get_ssid = wpa_driver_privsep_get_ssid,
820214501Srpaulo	.set_key = wpa_driver_privsep_set_key,
821214501Srpaulo	.init = wpa_driver_privsep_init,
822214501Srpaulo	.deinit = wpa_driver_privsep_deinit,
823214501Srpaulo	.set_param = wpa_driver_privsep_set_param,
824214501Srpaulo	.scan2 = wpa_driver_privsep_scan,
825214501Srpaulo	.deauthenticate = wpa_driver_privsep_deauthenticate,
826289549Srpaulo	.authenticate = wpa_driver_privsep_authenticate,
827214501Srpaulo	.associate = wpa_driver_privsep_associate,
828214501Srpaulo	.get_capa = wpa_driver_privsep_get_capa,
829214501Srpaulo	.get_mac_addr = wpa_driver_privsep_get_mac_addr,
830214501Srpaulo	.get_scan_results2 = wpa_driver_privsep_get_scan_results2,
831214501Srpaulo	.set_country = wpa_driver_privsep_set_country,
832209139Srpaulo};
833209139Srpaulo
834209139Srpaulo
835289549Srpauloconst struct wpa_driver_ops *const wpa_drivers[] =
836209139Srpaulo{
837209139Srpaulo	&wpa_driver_privsep_ops,
838209139Srpaulo	NULL
839209139Srpaulo};
840