RADIUS DAS: Support Chargeable-User-Identity with Disconnect-Request
[mech_eap.git] / src / ap / hostapd.c
1 /*
2  * hostapd / Initialization and configuration
3  * Copyright (c) 2002-2012, Jouni Malinen <j@w1.fi>
4  *
5  * This software may be distributed under the terms of the BSD license.
6  * See README for more details.
7  */
8
9 #include "utils/includes.h"
10
11 #include "utils/common.h"
12 #include "utils/eloop.h"
13 #include "common/ieee802_11_defs.h"
14 #include "radius/radius_client.h"
15 #include "radius/radius_das.h"
16 #include "drivers/driver.h"
17 #include "hostapd.h"
18 #include "authsrv.h"
19 #include "sta_info.h"
20 #include "accounting.h"
21 #include "ap_list.h"
22 #include "beacon.h"
23 #include "iapp.h"
24 #include "ieee802_1x.h"
25 #include "ieee802_11_auth.h"
26 #include "vlan_init.h"
27 #include "wpa_auth.h"
28 #include "wps_hostapd.h"
29 #include "hw_features.h"
30 #include "wpa_auth_glue.h"
31 #include "ap_drv_ops.h"
32 #include "ap_config.h"
33 #include "p2p_hostapd.h"
34 #include "gas_serv.h"
35
36
37 static int hostapd_flush_old_stations(struct hostapd_data *hapd, u16 reason);
38 static int hostapd_setup_encryption(char *iface, struct hostapd_data *hapd);
39 static int hostapd_broadcast_wep_clear(struct hostapd_data *hapd);
40
41 extern int wpa_debug_level;
42
43
44 int hostapd_for_each_interface(struct hapd_interfaces *interfaces,
45                                int (*cb)(struct hostapd_iface *iface,
46                                          void *ctx), void *ctx)
47 {
48         size_t i;
49         int ret;
50
51         for (i = 0; i < interfaces->count; i++) {
52                 ret = cb(interfaces->iface[i], ctx);
53                 if (ret)
54                         return ret;
55         }
56
57         return 0;
58 }
59
60
61 static void hostapd_reload_bss(struct hostapd_data *hapd)
62 {
63 #ifndef CONFIG_NO_RADIUS
64         radius_client_reconfig(hapd->radius, hapd->conf->radius);
65 #endif /* CONFIG_NO_RADIUS */
66
67         if (hostapd_setup_wpa_psk(hapd->conf)) {
68                 wpa_printf(MSG_ERROR, "Failed to re-configure WPA PSK "
69                            "after reloading configuration");
70         }
71
72         if (hapd->conf->ieee802_1x || hapd->conf->wpa)
73                 hostapd_set_drv_ieee8021x(hapd, hapd->conf->iface, 1);
74         else
75                 hostapd_set_drv_ieee8021x(hapd, hapd->conf->iface, 0);
76
77         if (hapd->conf->wpa && hapd->wpa_auth == NULL) {
78                 hostapd_setup_wpa(hapd);
79                 if (hapd->wpa_auth)
80                         wpa_init_keys(hapd->wpa_auth);
81         } else if (hapd->conf->wpa) {
82                 const u8 *wpa_ie;
83                 size_t wpa_ie_len;
84                 hostapd_reconfig_wpa(hapd);
85                 wpa_ie = wpa_auth_get_wpa_ie(hapd->wpa_auth, &wpa_ie_len);
86                 if (hostapd_set_generic_elem(hapd, wpa_ie, wpa_ie_len))
87                         wpa_printf(MSG_ERROR, "Failed to configure WPA IE for "
88                                    "the kernel driver.");
89         } else if (hapd->wpa_auth) {
90                 wpa_deinit(hapd->wpa_auth);
91                 hapd->wpa_auth = NULL;
92                 hostapd_set_privacy(hapd, 0);
93                 hostapd_setup_encryption(hapd->conf->iface, hapd);
94                 hostapd_set_generic_elem(hapd, (u8 *) "", 0);
95         }
96
97         ieee802_11_set_beacon(hapd);
98         hostapd_update_wps(hapd);
99
100         if (hapd->conf->ssid.ssid_set &&
101             hostapd_set_ssid(hapd, (u8 *) hapd->conf->ssid.ssid,
102                              hapd->conf->ssid.ssid_len)) {
103                 wpa_printf(MSG_ERROR, "Could not set SSID for kernel driver");
104                 /* try to continue */
105         }
106         wpa_printf(MSG_DEBUG, "Reconfigured interface %s", hapd->conf->iface);
107 }
108
109
110 int hostapd_reload_config(struct hostapd_iface *iface)
111 {
112         struct hostapd_data *hapd = iface->bss[0];
113         struct hostapd_config *newconf, *oldconf;
114         size_t j;
115
116         if (iface->config_read_cb == NULL)
117                 return -1;
118         newconf = iface->config_read_cb(iface->config_fname);
119         if (newconf == NULL)
120                 return -1;
121
122         /*
123          * Deauthenticate all stations since the new configuration may not
124          * allow them to use the BSS anymore.
125          */
126         for (j = 0; j < iface->num_bss; j++) {
127                 hostapd_flush_old_stations(iface->bss[j],
128                                            WLAN_REASON_PREV_AUTH_NOT_VALID);
129                 hostapd_broadcast_wep_clear(iface->bss[j]);
130
131 #ifndef CONFIG_NO_RADIUS
132                 /* TODO: update dynamic data based on changed configuration
133                  * items (e.g., open/close sockets, etc.) */
134                 radius_client_flush(iface->bss[j]->radius, 0);
135 #endif /* CONFIG_NO_RADIUS */
136         }
137
138         oldconf = hapd->iconf;
139         iface->conf = newconf;
140
141         for (j = 0; j < iface->num_bss; j++) {
142                 hapd = iface->bss[j];
143                 hapd->iconf = newconf;
144                 hapd->conf = &newconf->bss[j];
145                 hostapd_reload_bss(hapd);
146         }
147
148         hostapd_config_free(oldconf);
149
150
151         return 0;
152 }
153
154
155 static void hostapd_broadcast_key_clear_iface(struct hostapd_data *hapd,
156                                               char *ifname)
157 {
158         int i;
159
160         for (i = 0; i < NUM_WEP_KEYS; i++) {
161                 if (hostapd_drv_set_key(ifname, hapd, WPA_ALG_NONE, NULL, i,
162                                         0, NULL, 0, NULL, 0)) {
163                         wpa_printf(MSG_DEBUG, "Failed to clear default "
164                                    "encryption keys (ifname=%s keyidx=%d)",
165                                    ifname, i);
166                 }
167         }
168 #ifdef CONFIG_IEEE80211W
169         if (hapd->conf->ieee80211w) {
170                 for (i = NUM_WEP_KEYS; i < NUM_WEP_KEYS + 2; i++) {
171                         if (hostapd_drv_set_key(ifname, hapd, WPA_ALG_NONE,
172                                                 NULL, i, 0, NULL,
173                                                 0, NULL, 0)) {
174                                 wpa_printf(MSG_DEBUG, "Failed to clear "
175                                            "default mgmt encryption keys "
176                                            "(ifname=%s keyidx=%d)", ifname, i);
177                         }
178                 }
179         }
180 #endif /* CONFIG_IEEE80211W */
181 }
182
183
184 static int hostapd_broadcast_wep_clear(struct hostapd_data *hapd)
185 {
186         hostapd_broadcast_key_clear_iface(hapd, hapd->conf->iface);
187         return 0;
188 }
189
190
191 static int hostapd_broadcast_wep_set(struct hostapd_data *hapd)
192 {
193         int errors = 0, idx;
194         struct hostapd_ssid *ssid = &hapd->conf->ssid;
195
196         idx = ssid->wep.idx;
197         if (ssid->wep.default_len &&
198             hostapd_drv_set_key(hapd->conf->iface,
199                                 hapd, WPA_ALG_WEP, broadcast_ether_addr, idx,
200                                 1, NULL, 0, ssid->wep.key[idx],
201                                 ssid->wep.len[idx])) {
202                 wpa_printf(MSG_WARNING, "Could not set WEP encryption.");
203                 errors++;
204         }
205
206         if (ssid->dyn_vlan_keys) {
207                 size_t i;
208                 for (i = 0; i <= ssid->max_dyn_vlan_keys; i++) {
209                         const char *ifname;
210                         struct hostapd_wep_keys *key = ssid->dyn_vlan_keys[i];
211                         if (key == NULL)
212                                 continue;
213                         ifname = hostapd_get_vlan_id_ifname(hapd->conf->vlan,
214                                                             i);
215                         if (ifname == NULL)
216                                 continue;
217
218                         idx = key->idx;
219                         if (hostapd_drv_set_key(ifname, hapd, WPA_ALG_WEP,
220                                                 broadcast_ether_addr, idx, 1,
221                                                 NULL, 0, key->key[idx],
222                                                 key->len[idx])) {
223                                 wpa_printf(MSG_WARNING, "Could not set "
224                                            "dynamic VLAN WEP encryption.");
225                                 errors++;
226                         }
227                 }
228         }
229
230         return errors;
231 }
232
233
234 static void hostapd_free_hapd_data(struct hostapd_data *hapd)
235 {
236         iapp_deinit(hapd->iapp);
237         hapd->iapp = NULL;
238         accounting_deinit(hapd);
239         hostapd_deinit_wpa(hapd);
240         vlan_deinit(hapd);
241         hostapd_acl_deinit(hapd);
242 #ifndef CONFIG_NO_RADIUS
243         radius_client_deinit(hapd->radius);
244         hapd->radius = NULL;
245         radius_das_deinit(hapd->radius_das);
246         hapd->radius_das = NULL;
247 #endif /* CONFIG_NO_RADIUS */
248
249         hostapd_deinit_wps(hapd);
250
251         authsrv_deinit(hapd);
252
253         if (hapd->interface_added &&
254             hostapd_if_remove(hapd, WPA_IF_AP_BSS, hapd->conf->iface)) {
255                 wpa_printf(MSG_WARNING, "Failed to remove BSS interface %s",
256                            hapd->conf->iface);
257         }
258
259         os_free(hapd->probereq_cb);
260         hapd->probereq_cb = NULL;
261
262 #ifdef CONFIG_P2P
263         wpabuf_free(hapd->p2p_beacon_ie);
264         hapd->p2p_beacon_ie = NULL;
265         wpabuf_free(hapd->p2p_probe_resp_ie);
266         hapd->p2p_probe_resp_ie = NULL;
267 #endif /* CONFIG_P2P */
268
269         wpabuf_free(hapd->time_adv);
270
271 #ifdef CONFIG_INTERWORKING
272         gas_serv_deinit(hapd);
273 #endif /* CONFIG_INTERWORKING */
274 }
275
276
277 /**
278  * hostapd_cleanup - Per-BSS cleanup (deinitialization)
279  * @hapd: Pointer to BSS data
280  *
281  * This function is used to free all per-BSS data structures and resources.
282  * This gets called in a loop for each BSS between calls to
283  * hostapd_cleanup_iface_pre() and hostapd_cleanup_iface() when an interface
284  * is deinitialized. Most of the modules that are initialized in
285  * hostapd_setup_bss() are deinitialized here.
286  */
287 static void hostapd_cleanup(struct hostapd_data *hapd)
288 {
289         if (hapd->iface->ctrl_iface_deinit)
290                 hapd->iface->ctrl_iface_deinit(hapd);
291         hostapd_free_hapd_data(hapd);
292 }
293
294
295 /**
296  * hostapd_cleanup_iface_pre - Preliminary per-interface cleanup
297  * @iface: Pointer to interface data
298  *
299  * This function is called before per-BSS data structures are deinitialized
300  * with hostapd_cleanup().
301  */
302 static void hostapd_cleanup_iface_pre(struct hostapd_iface *iface)
303 {
304 }
305
306
307 static void hostapd_cleanup_iface_partial(struct hostapd_iface *iface)
308 {
309         hostapd_free_hw_features(iface->hw_features, iface->num_hw_features);
310         iface->hw_features = NULL;
311         os_free(iface->current_rates);
312         iface->current_rates = NULL;
313         os_free(iface->basic_rates);
314         iface->basic_rates = NULL;
315         ap_list_deinit(iface);
316 }
317
318
319 /**
320  * hostapd_cleanup_iface - Complete per-interface cleanup
321  * @iface: Pointer to interface data
322  *
323  * This function is called after per-BSS data structures are deinitialized
324  * with hostapd_cleanup().
325  */
326 static void hostapd_cleanup_iface(struct hostapd_iface *iface)
327 {
328         hostapd_cleanup_iface_partial(iface);
329         hostapd_config_free(iface->conf);
330         iface->conf = NULL;
331
332         os_free(iface->config_fname);
333         os_free(iface->bss);
334         os_free(iface);
335 }
336
337
338 static void hostapd_clear_wep(struct hostapd_data *hapd)
339 {
340         if (hapd->drv_priv) {
341                 hostapd_set_privacy(hapd, 0);
342                 hostapd_broadcast_wep_clear(hapd);
343         }
344 }
345
346
347 static int hostapd_setup_encryption(char *iface, struct hostapd_data *hapd)
348 {
349         int i;
350
351         hostapd_broadcast_wep_set(hapd);
352
353         if (hapd->conf->ssid.wep.default_len) {
354                 hostapd_set_privacy(hapd, 1);
355                 return 0;
356         }
357
358         /*
359          * When IEEE 802.1X is not enabled, the driver may need to know how to
360          * set authentication algorithms for static WEP.
361          */
362         hostapd_drv_set_authmode(hapd, hapd->conf->auth_algs);
363
364         for (i = 0; i < 4; i++) {
365                 if (hapd->conf->ssid.wep.key[i] &&
366                     hostapd_drv_set_key(iface, hapd, WPA_ALG_WEP, NULL, i,
367                                         i == hapd->conf->ssid.wep.idx, NULL, 0,
368                                         hapd->conf->ssid.wep.key[i],
369                                         hapd->conf->ssid.wep.len[i])) {
370                         wpa_printf(MSG_WARNING, "Could not set WEP "
371                                    "encryption.");
372                         return -1;
373                 }
374                 if (hapd->conf->ssid.wep.key[i] &&
375                     i == hapd->conf->ssid.wep.idx)
376                         hostapd_set_privacy(hapd, 1);
377         }
378
379         return 0;
380 }
381
382
383 static int hostapd_flush_old_stations(struct hostapd_data *hapd, u16 reason)
384 {
385         int ret = 0;
386         u8 addr[ETH_ALEN];
387
388         if (hostapd_drv_none(hapd) || hapd->drv_priv == NULL)
389                 return 0;
390
391         wpa_dbg(hapd->msg_ctx, MSG_DEBUG, "Flushing old station entries");
392         if (hostapd_flush(hapd)) {
393                 wpa_msg(hapd->msg_ctx, MSG_WARNING, "Could not connect to "
394                         "kernel driver");
395                 ret = -1;
396         }
397         wpa_dbg(hapd->msg_ctx, MSG_DEBUG, "Deauthenticate all stations");
398         os_memset(addr, 0xff, ETH_ALEN);
399         hostapd_drv_sta_deauth(hapd, addr, reason);
400         hostapd_free_stas(hapd);
401
402         return ret;
403 }
404
405
406 /**
407  * hostapd_validate_bssid_configuration - Validate BSSID configuration
408  * @iface: Pointer to interface data
409  * Returns: 0 on success, -1 on failure
410  *
411  * This function is used to validate that the configured BSSIDs are valid.
412  */
413 static int hostapd_validate_bssid_configuration(struct hostapd_iface *iface)
414 {
415         u8 mask[ETH_ALEN] = { 0 };
416         struct hostapd_data *hapd = iface->bss[0];
417         unsigned int i = iface->conf->num_bss, bits = 0, j;
418         int auto_addr = 0;
419
420         if (hostapd_drv_none(hapd))
421                 return 0;
422
423         /* Generate BSSID mask that is large enough to cover the BSSIDs. */
424
425         /* Determine the bits necessary to cover the number of BSSIDs. */
426         for (i--; i; i >>= 1)
427                 bits++;
428
429         /* Determine the bits necessary to any configured BSSIDs,
430            if they are higher than the number of BSSIDs. */
431         for (j = 0; j < iface->conf->num_bss; j++) {
432                 if (hostapd_mac_comp_empty(iface->conf->bss[j].bssid) == 0) {
433                         if (j)
434                                 auto_addr++;
435                         continue;
436                 }
437
438                 for (i = 0; i < ETH_ALEN; i++) {
439                         mask[i] |=
440                                 iface->conf->bss[j].bssid[i] ^
441                                 hapd->own_addr[i];
442                 }
443         }
444
445         if (!auto_addr)
446                 goto skip_mask_ext;
447
448         for (i = 0; i < ETH_ALEN && mask[i] == 0; i++)
449                 ;
450         j = 0;
451         if (i < ETH_ALEN) {
452                 j = (5 - i) * 8;
453
454                 while (mask[i] != 0) {
455                         mask[i] >>= 1;
456                         j++;
457                 }
458         }
459
460         if (bits < j)
461                 bits = j;
462
463         if (bits > 40) {
464                 wpa_printf(MSG_ERROR, "Too many bits in the BSSID mask (%u)",
465                            bits);
466                 return -1;
467         }
468
469         os_memset(mask, 0xff, ETH_ALEN);
470         j = bits / 8;
471         for (i = 5; i > 5 - j; i--)
472                 mask[i] = 0;
473         j = bits % 8;
474         while (j--)
475                 mask[i] <<= 1;
476
477 skip_mask_ext:
478         wpa_printf(MSG_DEBUG, "BSS count %lu, BSSID mask " MACSTR " (%d bits)",
479                    (unsigned long) iface->conf->num_bss, MAC2STR(mask), bits);
480
481         if (!auto_addr)
482                 return 0;
483
484         for (i = 0; i < ETH_ALEN; i++) {
485                 if ((hapd->own_addr[i] & mask[i]) != hapd->own_addr[i]) {
486                         wpa_printf(MSG_ERROR, "Invalid BSSID mask " MACSTR
487                                    " for start address " MACSTR ".",
488                                    MAC2STR(mask), MAC2STR(hapd->own_addr));
489                         wpa_printf(MSG_ERROR, "Start address must be the "
490                                    "first address in the block (i.e., addr "
491                                    "AND mask == addr).");
492                         return -1;
493                 }
494         }
495
496         return 0;
497 }
498
499
500 static int mac_in_conf(struct hostapd_config *conf, const void *a)
501 {
502         size_t i;
503
504         for (i = 0; i < conf->num_bss; i++) {
505                 if (hostapd_mac_comp(conf->bss[i].bssid, a) == 0) {
506                         return 1;
507                 }
508         }
509
510         return 0;
511 }
512
513
514 #ifndef CONFIG_NO_RADIUS
515
516 static int hostapd_das_nas_mismatch(struct hostapd_data *hapd,
517                                     struct radius_das_attrs *attr)
518 {
519         /* TODO */
520         return 0;
521 }
522
523
524 static struct sta_info * hostapd_das_find_sta(struct hostapd_data *hapd,
525                                               struct radius_das_attrs *attr)
526 {
527         struct sta_info *sta = NULL;
528         char buf[128];
529
530         if (attr->sta_addr)
531                 sta = ap_get_sta(hapd, attr->sta_addr);
532
533         if (sta == NULL && attr->acct_session_id &&
534             attr->acct_session_id_len == 17) {
535                 for (sta = hapd->sta_list; sta; sta = sta->next) {
536                         os_snprintf(buf, sizeof(buf), "%08X-%08X",
537                                     sta->acct_session_id_hi,
538                                     sta->acct_session_id_lo);
539                         if (os_memcmp(attr->acct_session_id, buf, 17) == 0)
540                                 break;
541                 }
542         }
543
544         if (sta == NULL && attr->cui) {
545                 for (sta = hapd->sta_list; sta; sta = sta->next) {
546                         struct wpabuf *cui;
547                         cui = ieee802_1x_get_radius_cui(sta->eapol_sm);
548                         if (cui && wpabuf_len(cui) == attr->cui_len &&
549                             os_memcmp(wpabuf_head(cui), attr->cui,
550                                       attr->cui_len) == 0)
551                                 break;
552                 }
553         }
554
555         if (sta == NULL && attr->user_name) {
556                 for (sta = hapd->sta_list; sta; sta = sta->next) {
557                         u8 *identity;
558                         size_t identity_len;
559                         identity = ieee802_1x_get_identity(sta->eapol_sm,
560                                                            &identity_len);
561                         if (identity &&
562                             identity_len == attr->user_name_len &&
563                             os_memcmp(identity, attr->user_name, identity_len)
564                             == 0)
565                                 break;
566                 }
567         }
568
569         return sta;
570 }
571
572
573 static enum radius_das_res
574 hostapd_das_disconnect(void *ctx, struct radius_das_attrs *attr)
575 {
576         struct hostapd_data *hapd = ctx;
577         struct sta_info *sta;
578
579         if (hostapd_das_nas_mismatch(hapd, attr))
580                 return RADIUS_DAS_NAS_MISMATCH;
581
582         sta = hostapd_das_find_sta(hapd, attr);
583         if (sta == NULL)
584                 return RADIUS_DAS_SESSION_NOT_FOUND;
585
586         hostapd_drv_sta_deauth(hapd, sta->addr,
587                                WLAN_REASON_PREV_AUTH_NOT_VALID);
588         ap_sta_deauthenticate(hapd, sta, WLAN_REASON_PREV_AUTH_NOT_VALID);
589
590         return RADIUS_DAS_SUCCESS;
591 }
592
593 #endif /* CONFIG_NO_RADIUS */
594
595
596 /**
597  * hostapd_setup_bss - Per-BSS setup (initialization)
598  * @hapd: Pointer to BSS data
599  * @first: Whether this BSS is the first BSS of an interface
600  *
601  * This function is used to initialize all per-BSS data structures and
602  * resources. This gets called in a loop for each BSS when an interface is
603  * initialized. Most of the modules that are initialized here will be
604  * deinitialized in hostapd_cleanup().
605  */
606 static int hostapd_setup_bss(struct hostapd_data *hapd, int first)
607 {
608         struct hostapd_bss_config *conf = hapd->conf;
609         u8 ssid[HOSTAPD_MAX_SSID_LEN + 1];
610         int ssid_len, set_ssid;
611         char force_ifname[IFNAMSIZ];
612         u8 if_addr[ETH_ALEN];
613
614         if (!first) {
615                 if (hostapd_mac_comp_empty(hapd->conf->bssid) == 0) {
616                         /* Allocate the next available BSSID. */
617                         do {
618                                 inc_byte_array(hapd->own_addr, ETH_ALEN);
619                         } while (mac_in_conf(hapd->iconf, hapd->own_addr));
620                 } else {
621                         /* Allocate the configured BSSID. */
622                         os_memcpy(hapd->own_addr, hapd->conf->bssid, ETH_ALEN);
623
624                         if (hostapd_mac_comp(hapd->own_addr,
625                                              hapd->iface->bss[0]->own_addr) ==
626                             0) {
627                                 wpa_printf(MSG_ERROR, "BSS '%s' may not have "
628                                            "BSSID set to the MAC address of "
629                                            "the radio", hapd->conf->iface);
630                                 return -1;
631                         }
632                 }
633
634                 hapd->interface_added = 1;
635                 if (hostapd_if_add(hapd->iface->bss[0], WPA_IF_AP_BSS,
636                                    hapd->conf->iface, hapd->own_addr, hapd,
637                                    &hapd->drv_priv, force_ifname, if_addr,
638                                    hapd->conf->bridge[0] ? hapd->conf->bridge :
639                                    NULL)) {
640                         wpa_printf(MSG_ERROR, "Failed to add BSS (BSSID="
641                                    MACSTR ")", MAC2STR(hapd->own_addr));
642                         return -1;
643                 }
644         }
645
646         if (conf->wmm_enabled < 0)
647                 conf->wmm_enabled = hapd->iconf->ieee80211n;
648
649         hostapd_flush_old_stations(hapd, WLAN_REASON_PREV_AUTH_NOT_VALID);
650         hostapd_set_privacy(hapd, 0);
651
652         hostapd_broadcast_wep_clear(hapd);
653         if (hostapd_setup_encryption(hapd->conf->iface, hapd))
654                 return -1;
655
656         /*
657          * Fetch the SSID from the system and use it or,
658          * if one was specified in the config file, verify they
659          * match.
660          */
661         ssid_len = hostapd_get_ssid(hapd, ssid, sizeof(ssid));
662         if (ssid_len < 0) {
663                 wpa_printf(MSG_ERROR, "Could not read SSID from system");
664                 return -1;
665         }
666         if (conf->ssid.ssid_set) {
667                 /*
668                  * If SSID is specified in the config file and it differs
669                  * from what is being used then force installation of the
670                  * new SSID.
671                  */
672                 set_ssid = (conf->ssid.ssid_len != (size_t) ssid_len ||
673                             os_memcmp(conf->ssid.ssid, ssid, ssid_len) != 0);
674         } else {
675                 /*
676                  * No SSID in the config file; just use the one we got
677                  * from the system.
678                  */
679                 set_ssid = 0;
680                 conf->ssid.ssid_len = ssid_len;
681                 os_memcpy(conf->ssid.ssid, ssid, conf->ssid.ssid_len);
682                 conf->ssid.ssid[conf->ssid.ssid_len] = '\0';
683         }
684
685         if (!hostapd_drv_none(hapd)) {
686                 wpa_printf(MSG_ERROR, "Using interface %s with hwaddr " MACSTR
687                            " and ssid '%s'",
688                            hapd->conf->iface, MAC2STR(hapd->own_addr),
689                            hapd->conf->ssid.ssid);
690         }
691
692         if (hostapd_setup_wpa_psk(conf)) {
693                 wpa_printf(MSG_ERROR, "WPA-PSK setup failed.");
694                 return -1;
695         }
696
697         /* Set SSID for the kernel driver (to be used in beacon and probe
698          * response frames) */
699         if (set_ssid && hostapd_set_ssid(hapd, (u8 *) conf->ssid.ssid,
700                                          conf->ssid.ssid_len)) {
701                 wpa_printf(MSG_ERROR, "Could not set SSID for kernel driver");
702                 return -1;
703         }
704
705         if (wpa_debug_level == MSG_MSGDUMP)
706                 conf->radius->msg_dumps = 1;
707 #ifndef CONFIG_NO_RADIUS
708         hapd->radius = radius_client_init(hapd, conf->radius);
709         if (hapd->radius == NULL) {
710                 wpa_printf(MSG_ERROR, "RADIUS client initialization failed.");
711                 return -1;
712         }
713
714         if (hapd->conf->radius_das_port) {
715                 struct radius_das_conf das_conf;
716                 os_memset(&das_conf, 0, sizeof(das_conf));
717                 das_conf.port = hapd->conf->radius_das_port;
718                 das_conf.shared_secret = hapd->conf->radius_das_shared_secret;
719                 das_conf.shared_secret_len =
720                         hapd->conf->radius_das_shared_secret_len;
721                 das_conf.client_addr = &hapd->conf->radius_das_client_addr;
722                 das_conf.time_window = hapd->conf->radius_das_time_window;
723                 das_conf.require_event_timestamp =
724                         hapd->conf->radius_das_require_event_timestamp;
725                 das_conf.ctx = hapd;
726                 das_conf.disconnect = hostapd_das_disconnect;
727                 hapd->radius_das = radius_das_init(&das_conf);
728                 if (hapd->radius_das == NULL) {
729                         wpa_printf(MSG_ERROR, "RADIUS DAS initialization "
730                                    "failed.");
731                         return -1;
732                 }
733         }
734 #endif /* CONFIG_NO_RADIUS */
735
736         if (hostapd_acl_init(hapd)) {
737                 wpa_printf(MSG_ERROR, "ACL initialization failed.");
738                 return -1;
739         }
740         if (hostapd_init_wps(hapd, conf))
741                 return -1;
742
743         if (authsrv_init(hapd) < 0)
744                 return -1;
745
746         if (ieee802_1x_init(hapd)) {
747                 wpa_printf(MSG_ERROR, "IEEE 802.1X initialization failed.");
748                 return -1;
749         }
750
751         if (hapd->conf->wpa && hostapd_setup_wpa(hapd))
752                 return -1;
753
754         if (accounting_init(hapd)) {
755                 wpa_printf(MSG_ERROR, "Accounting initialization failed.");
756                 return -1;
757         }
758
759         if (hapd->conf->ieee802_11f &&
760             (hapd->iapp = iapp_init(hapd, hapd->conf->iapp_iface)) == NULL) {
761                 wpa_printf(MSG_ERROR, "IEEE 802.11F (IAPP) initialization "
762                            "failed.");
763                 return -1;
764         }
765
766 #ifdef CONFIG_INTERWORKING
767         if (gas_serv_init(hapd)) {
768                 wpa_printf(MSG_ERROR, "GAS server initialization failed");
769                 return -1;
770         }
771 #endif /* CONFIG_INTERWORKING */
772
773         if (hapd->iface->ctrl_iface_init &&
774             hapd->iface->ctrl_iface_init(hapd)) {
775                 wpa_printf(MSG_ERROR, "Failed to setup control interface");
776                 return -1;
777         }
778
779         if (!hostapd_drv_none(hapd) && vlan_init(hapd)) {
780                 wpa_printf(MSG_ERROR, "VLAN initialization failed.");
781                 return -1;
782         }
783
784         ieee802_11_set_beacon(hapd);
785
786         if (hapd->wpa_auth && wpa_init_keys(hapd->wpa_auth) < 0)
787                 return -1;
788
789         if (hapd->driver && hapd->driver->set_operstate)
790                 hapd->driver->set_operstate(hapd->drv_priv, 1);
791
792         return 0;
793 }
794
795
796 static void hostapd_tx_queue_params(struct hostapd_iface *iface)
797 {
798         struct hostapd_data *hapd = iface->bss[0];
799         int i;
800         struct hostapd_tx_queue_params *p;
801
802         for (i = 0; i < NUM_TX_QUEUES; i++) {
803                 p = &iface->conf->tx_queue[i];
804
805                 if (hostapd_set_tx_queue_params(hapd, i, p->aifs, p->cwmin,
806                                                 p->cwmax, p->burst)) {
807                         wpa_printf(MSG_DEBUG, "Failed to set TX queue "
808                                    "parameters for queue %d.", i);
809                         /* Continue anyway */
810                 }
811         }
812 }
813
814
815 static int setup_interface(struct hostapd_iface *iface)
816 {
817         struct hostapd_data *hapd = iface->bss[0];
818         size_t i;
819         char country[4];
820
821         /*
822          * Make sure that all BSSes get configured with a pointer to the same
823          * driver interface.
824          */
825         for (i = 1; i < iface->num_bss; i++) {
826                 iface->bss[i]->driver = hapd->driver;
827                 iface->bss[i]->drv_priv = hapd->drv_priv;
828         }
829
830         if (hostapd_validate_bssid_configuration(iface))
831                 return -1;
832
833         if (hapd->iconf->country[0] && hapd->iconf->country[1]) {
834                 os_memcpy(country, hapd->iconf->country, 3);
835                 country[3] = '\0';
836                 if (hostapd_set_country(hapd, country) < 0) {
837                         wpa_printf(MSG_ERROR, "Failed to set country code");
838                         return -1;
839                 }
840         }
841
842         if (hostapd_get_hw_features(iface)) {
843                 /* Not all drivers support this yet, so continue without hw
844                  * feature data. */
845         } else {
846                 int ret = hostapd_select_hw_mode(iface);
847                 if (ret < 0) {
848                         wpa_printf(MSG_ERROR, "Could not select hw_mode and "
849                                    "channel. (%d)", ret);
850                         return -1;
851                 }
852                 ret = hostapd_check_ht_capab(iface);
853                 if (ret < 0)
854                         return -1;
855                 if (ret == 1) {
856                         wpa_printf(MSG_DEBUG, "Interface initialization will "
857                                    "be completed in a callback");
858                         return 0;
859                 }
860         }
861         return hostapd_setup_interface_complete(iface, 0);
862 }
863
864
865 int hostapd_setup_interface_complete(struct hostapd_iface *iface, int err)
866 {
867         struct hostapd_data *hapd = iface->bss[0];
868         size_t j;
869         u8 *prev_addr;
870
871         if (err) {
872                 wpa_printf(MSG_ERROR, "Interface initialization failed");
873                 eloop_terminate();
874                 return -1;
875         }
876
877         wpa_printf(MSG_DEBUG, "Completing interface initialization");
878         if (hapd->iconf->channel) {
879                 iface->freq = hostapd_hw_get_freq(hapd, hapd->iconf->channel);
880                 wpa_printf(MSG_DEBUG, "Mode: %s  Channel: %d  "
881                            "Frequency: %d MHz",
882                            hostapd_hw_mode_txt(hapd->iconf->hw_mode),
883                            hapd->iconf->channel, iface->freq);
884
885                 if (hostapd_set_freq(hapd, hapd->iconf->hw_mode, iface->freq,
886                                      hapd->iconf->channel,
887                                      hapd->iconf->ieee80211n,
888                                      hapd->iconf->secondary_channel)) {
889                         wpa_printf(MSG_ERROR, "Could not set channel for "
890                                    "kernel driver");
891                         return -1;
892                 }
893         }
894
895         if (iface->current_mode) {
896                 if (hostapd_prepare_rates(iface, iface->current_mode)) {
897                         wpa_printf(MSG_ERROR, "Failed to prepare rates "
898                                    "table.");
899                         hostapd_logger(hapd, NULL, HOSTAPD_MODULE_IEEE80211,
900                                        HOSTAPD_LEVEL_WARNING,
901                                        "Failed to prepare rates table.");
902                         return -1;
903                 }
904         }
905
906         if (hapd->iconf->rts_threshold > -1 &&
907             hostapd_set_rts(hapd, hapd->iconf->rts_threshold)) {
908                 wpa_printf(MSG_ERROR, "Could not set RTS threshold for "
909                            "kernel driver");
910                 return -1;
911         }
912
913         if (hapd->iconf->fragm_threshold > -1 &&
914             hostapd_set_frag(hapd, hapd->iconf->fragm_threshold)) {
915                 wpa_printf(MSG_ERROR, "Could not set fragmentation threshold "
916                            "for kernel driver");
917                 return -1;
918         }
919
920         prev_addr = hapd->own_addr;
921
922         for (j = 0; j < iface->num_bss; j++) {
923                 hapd = iface->bss[j];
924                 if (j)
925                         os_memcpy(hapd->own_addr, prev_addr, ETH_ALEN);
926                 if (hostapd_setup_bss(hapd, j == 0))
927                         return -1;
928                 if (hostapd_mac_comp_empty(hapd->conf->bssid) == 0)
929                         prev_addr = hapd->own_addr;
930         }
931
932         hostapd_tx_queue_params(iface);
933
934         ap_list_init(iface);
935
936         if (hostapd_driver_commit(hapd) < 0) {
937                 wpa_printf(MSG_ERROR, "%s: Failed to commit driver "
938                            "configuration", __func__);
939                 return -1;
940         }
941
942         /*
943          * WPS UPnP module can be initialized only when the "upnp_iface" is up.
944          * If "interface" and "upnp_iface" are the same (e.g., non-bridge
945          * mode), the interface is up only after driver_commit, so initialize
946          * WPS after driver_commit.
947          */
948         for (j = 0; j < iface->num_bss; j++) {
949                 if (hostapd_init_wps_complete(iface->bss[j]))
950                         return -1;
951         }
952
953         if (hapd->setup_complete_cb)
954                 hapd->setup_complete_cb(hapd->setup_complete_cb_ctx);
955
956         wpa_printf(MSG_DEBUG, "%s: Setup of interface done.",
957                    iface->bss[0]->conf->iface);
958
959         return 0;
960 }
961
962
963 /**
964  * hostapd_setup_interface - Setup of an interface
965  * @iface: Pointer to interface data.
966  * Returns: 0 on success, -1 on failure
967  *
968  * Initializes the driver interface, validates the configuration,
969  * and sets driver parameters based on the configuration.
970  * Flushes old stations, sets the channel, encryption,
971  * beacons, and WDS links based on the configuration.
972  */
973 int hostapd_setup_interface(struct hostapd_iface *iface)
974 {
975         int ret;
976
977         ret = setup_interface(iface);
978         if (ret) {
979                 wpa_printf(MSG_ERROR, "%s: Unable to setup interface.",
980                            iface->bss[0]->conf->iface);
981                 return -1;
982         }
983
984         return 0;
985 }
986
987
988 /**
989  * hostapd_alloc_bss_data - Allocate and initialize per-BSS data
990  * @hapd_iface: Pointer to interface data
991  * @conf: Pointer to per-interface configuration
992  * @bss: Pointer to per-BSS configuration for this BSS
993  * Returns: Pointer to allocated BSS data
994  *
995  * This function is used to allocate per-BSS data structure. This data will be
996  * freed after hostapd_cleanup() is called for it during interface
997  * deinitialization.
998  */
999 struct hostapd_data *
1000 hostapd_alloc_bss_data(struct hostapd_iface *hapd_iface,
1001                        struct hostapd_config *conf,
1002                        struct hostapd_bss_config *bss)
1003 {
1004         struct hostapd_data *hapd;
1005
1006         hapd = os_zalloc(sizeof(*hapd));
1007         if (hapd == NULL)
1008                 return NULL;
1009
1010         hapd->new_assoc_sta_cb = hostapd_new_assoc_sta;
1011         hapd->iconf = conf;
1012         hapd->conf = bss;
1013         hapd->iface = hapd_iface;
1014         hapd->driver = hapd->iconf->driver;
1015         hapd->ctrl_sock = -1;
1016
1017         return hapd;
1018 }
1019
1020
1021 void hostapd_interface_deinit(struct hostapd_iface *iface)
1022 {
1023         size_t j;
1024
1025         if (iface == NULL)
1026                 return;
1027
1028         hostapd_cleanup_iface_pre(iface);
1029         for (j = 0; j < iface->num_bss; j++) {
1030                 struct hostapd_data *hapd = iface->bss[j];
1031                 hostapd_free_stas(hapd);
1032                 hostapd_flush_old_stations(hapd, WLAN_REASON_DEAUTH_LEAVING);
1033                 hostapd_clear_wep(hapd);
1034                 hostapd_cleanup(hapd);
1035         }
1036 }
1037
1038
1039 void hostapd_interface_free(struct hostapd_iface *iface)
1040 {
1041         size_t j;
1042         for (j = 0; j < iface->num_bss; j++)
1043                 os_free(iface->bss[j]);
1044         hostapd_cleanup_iface(iface);
1045 }
1046
1047
1048 /**
1049  * hostapd_new_assoc_sta - Notify that a new station associated with the AP
1050  * @hapd: Pointer to BSS data
1051  * @sta: Pointer to the associated STA data
1052  * @reassoc: 1 to indicate this was a re-association; 0 = first association
1053  *
1054  * This function will be called whenever a station associates with the AP. It
1055  * can be called from ieee802_11.c for drivers that export MLME to hostapd and
1056  * from drv_callbacks.c based on driver events for drivers that take care of
1057  * management frames (IEEE 802.11 authentication and association) internally.
1058  */
1059 void hostapd_new_assoc_sta(struct hostapd_data *hapd, struct sta_info *sta,
1060                            int reassoc)
1061 {
1062         if (hapd->tkip_countermeasures) {
1063                 hostapd_drv_sta_deauth(hapd, sta->addr,
1064                                        WLAN_REASON_MICHAEL_MIC_FAILURE);
1065                 return;
1066         }
1067
1068         hostapd_prune_associations(hapd, sta->addr);
1069
1070         /* IEEE 802.11F (IAPP) */
1071         if (hapd->conf->ieee802_11f)
1072                 iapp_new_station(hapd->iapp, sta);
1073
1074 #ifdef CONFIG_P2P
1075         if (sta->p2p_ie == NULL && !sta->no_p2p_set) {
1076                 sta->no_p2p_set = 1;
1077                 hapd->num_sta_no_p2p++;
1078                 if (hapd->num_sta_no_p2p == 1)
1079                         hostapd_p2p_non_p2p_sta_connected(hapd);
1080         }
1081 #endif /* CONFIG_P2P */
1082
1083         /* Start accounting here, if IEEE 802.1X and WPA are not used.
1084          * IEEE 802.1X/WPA code will start accounting after the station has
1085          * been authorized. */
1086         if (!hapd->conf->ieee802_1x && !hapd->conf->wpa)
1087                 accounting_sta_start(hapd, sta);
1088
1089         /* Start IEEE 802.1X authentication process for new stations */
1090         ieee802_1x_new_station(hapd, sta);
1091         if (reassoc) {
1092                 if (sta->auth_alg != WLAN_AUTH_FT &&
1093                     !(sta->flags & (WLAN_STA_WPS | WLAN_STA_MAYBE_WPS)))
1094                         wpa_auth_sm_event(sta->wpa_sm, WPA_REAUTH);
1095         } else
1096                 wpa_auth_sta_associated(hapd->wpa_auth, sta->wpa_sm);
1097
1098         wpa_printf(MSG_DEBUG, "%s: reschedule ap_handle_timer timeout "
1099                    "for " MACSTR " (%d seconds - ap_max_inactivity)",
1100                    __func__, MAC2STR(sta->addr),
1101                    hapd->conf->ap_max_inactivity);
1102         eloop_cancel_timeout(ap_handle_timer, hapd, sta);
1103         eloop_register_timeout(hapd->conf->ap_max_inactivity, 0,
1104                                ap_handle_timer, hapd, sta);
1105 }