driver_test: Add support for per-SSID scans for non-MLME case
[libeap.git] / src / drivers / driver_test.c
1 /*
2  * Testing driver interface for a simulated network driver
3  * Copyright (c) 2004-2009, Jouni Malinen <j@w1.fi>
4  *
5  * This program is free software; you can redistribute it and/or modify
6  * it under the terms of the GNU General Public License version 2 as
7  * published by the Free Software Foundation.
8  *
9  * Alternatively, this software may be distributed under the terms of BSD
10  * license.
11  *
12  * See README and COPYING for more details.
13  */
14
15 /* Make sure we get winsock2.h for Windows build to get sockaddr_storage */
16 #include "build_config.h"
17 #ifdef CONFIG_NATIVE_WINDOWS
18 #include <winsock2.h>
19 #endif /* CONFIG_NATIVE_WINDOWS */
20
21 #include "utils/includes.h"
22
23 #ifndef CONFIG_NATIVE_WINDOWS
24 #include <sys/un.h>
25 #include <dirent.h>
26 #include <sys/stat.h>
27 #define DRIVER_TEST_UNIX
28 #endif /* CONFIG_NATIVE_WINDOWS */
29
30 #include "utils/common.h"
31 #include "utils/eloop.h"
32 #include "utils/trace.h"
33 #include "common/ieee802_11_defs.h"
34 #include "crypto/sha1.h"
35 #include "l2_packet/l2_packet.h"
36 #include "driver.h"
37
38
39 struct test_client_socket {
40         struct test_client_socket *next;
41         u8 addr[ETH_ALEN];
42         struct sockaddr_un un;
43         socklen_t unlen;
44         struct test_driver_bss *bss;
45 };
46
47 struct test_driver_bss {
48         struct test_driver_bss *next;
49         void *bss_ctx;
50         char ifname[IFNAMSIZ + 1];
51         u8 bssid[ETH_ALEN];
52         u8 *ie;
53         size_t ielen;
54         u8 *wps_beacon_ie;
55         size_t wps_beacon_ie_len;
56         u8 *wps_probe_resp_ie;
57         size_t wps_probe_resp_ie_len;
58         u8 ssid[32];
59         size_t ssid_len;
60         int privacy;
61 };
62
63 struct wpa_driver_test_global {
64         int bss_add_used;
65         u8 req_addr[ETH_ALEN];
66 };
67
68 struct wpa_driver_test_data {
69         struct wpa_driver_test_global *global;
70         void *ctx;
71         WPA_TRACE_REF(ctx);
72         char ifname[IFNAMSIZ + 1];
73         u8 own_addr[ETH_ALEN];
74         int test_socket;
75 #ifdef DRIVER_TEST_UNIX
76         struct sockaddr_un hostapd_addr;
77 #endif /* DRIVER_TEST_UNIX */
78         int hostapd_addr_set;
79         struct sockaddr_in hostapd_addr_udp;
80         int hostapd_addr_udp_set;
81         char *own_socket_path;
82         char *test_dir;
83         u8 bssid[ETH_ALEN];
84         u8 ssid[32];
85         size_t ssid_len;
86 #define MAX_SCAN_RESULTS 30
87         struct wpa_scan_res *scanres[MAX_SCAN_RESULTS];
88         size_t num_scanres;
89         int use_associnfo;
90         u8 assoc_wpa_ie[80];
91         size_t assoc_wpa_ie_len;
92         int use_mlme;
93         int associated;
94         u8 *probe_req_ie;
95         size_t probe_req_ie_len;
96         u8 probe_req_ssid[32];
97         size_t probe_req_ssid_len;
98         int ibss;
99         int privacy;
100         int ap;
101
102         struct test_client_socket *cli;
103         struct test_driver_bss *bss;
104         int udp_port;
105
106         int alloc_iface_idx;
107
108         int probe_req_report;
109         unsigned int remain_on_channel_freq;
110         unsigned int remain_on_channel_duration;
111
112         int current_freq;
113 };
114
115
116 static void wpa_driver_test_deinit(void *priv);
117 static int wpa_driver_test_attach(struct wpa_driver_test_data *drv,
118                                   const char *dir, int ap);
119 static void wpa_driver_test_close_test_socket(
120         struct wpa_driver_test_data *drv);
121 static void test_remain_on_channel_timeout(void *eloop_ctx, void *timeout_ctx);
122
123
124 static void test_driver_free_bss(struct test_driver_bss *bss)
125 {
126         os_free(bss->ie);
127         os_free(bss->wps_beacon_ie);
128         os_free(bss->wps_probe_resp_ie);
129         os_free(bss);
130 }
131
132
133 static void test_driver_free_bsses(struct wpa_driver_test_data *drv)
134 {
135         struct test_driver_bss *bss, *prev_bss;
136
137         bss = drv->bss;
138         while (bss) {
139                 prev_bss = bss;
140                 bss = bss->next;
141                 test_driver_free_bss(prev_bss);
142         }
143
144         drv->bss = NULL;
145 }
146
147
148 static struct test_client_socket *
149 test_driver_get_cli(struct wpa_driver_test_data *drv, struct sockaddr_un *from,
150                     socklen_t fromlen)
151 {
152         struct test_client_socket *cli = drv->cli;
153
154         while (cli) {
155                 if (cli->unlen == fromlen &&
156                     strncmp(cli->un.sun_path, from->sun_path,
157                             fromlen - sizeof(cli->un.sun_family)) == 0)
158                         return cli;
159                 cli = cli->next;
160         }
161
162         return NULL;
163 }
164
165
166 static int test_driver_send_eapol(void *priv, const u8 *addr, const u8 *data,
167                                   size_t data_len, int encrypt,
168                                   const u8 *own_addr)
169 {
170         struct wpa_driver_test_data *drv = priv;
171         struct test_client_socket *cli;
172         struct msghdr msg;
173         struct iovec io[3];
174         struct l2_ethhdr eth;
175
176         if (drv->test_socket < 0)
177                 return -1;
178
179         cli = drv->cli;
180         while (cli) {
181                 if (memcmp(cli->addr, addr, ETH_ALEN) == 0)
182                         break;
183                 cli = cli->next;
184         }
185
186         if (!cli) {
187                 wpa_printf(MSG_DEBUG, "%s: no destination client entry",
188                            __func__);
189                 return -1;
190         }
191
192         memcpy(eth.h_dest, addr, ETH_ALEN);
193         memcpy(eth.h_source, own_addr, ETH_ALEN);
194         eth.h_proto = host_to_be16(ETH_P_EAPOL);
195
196         io[0].iov_base = "EAPOL ";
197         io[0].iov_len = 6;
198         io[1].iov_base = &eth;
199         io[1].iov_len = sizeof(eth);
200         io[2].iov_base = (u8 *) data;
201         io[2].iov_len = data_len;
202
203         memset(&msg, 0, sizeof(msg));
204         msg.msg_iov = io;
205         msg.msg_iovlen = 3;
206         msg.msg_name = &cli->un;
207         msg.msg_namelen = cli->unlen;
208         return sendmsg(drv->test_socket, &msg, 0);
209 }
210
211
212 static int test_driver_send_ether(void *priv, const u8 *dst, const u8 *src,
213                                   u16 proto, const u8 *data, size_t data_len)
214 {
215         struct wpa_driver_test_data *drv = priv;
216         struct msghdr msg;
217         struct iovec io[3];
218         struct l2_ethhdr eth;
219         char desttxt[30];
220         struct sockaddr_un addr;
221         struct dirent *dent;
222         DIR *dir;
223         int ret = 0, broadcast = 0, count = 0;
224
225         if (drv->test_socket < 0 || drv->test_dir == NULL) {
226                 wpa_printf(MSG_DEBUG, "%s: invalid parameters (sock=%d "
227                            "test_dir=%p)",
228                            __func__, drv->test_socket, drv->test_dir);
229                 return -1;
230         }
231
232         broadcast = memcmp(dst, "\xff\xff\xff\xff\xff\xff", ETH_ALEN) == 0;
233         snprintf(desttxt, sizeof(desttxt), MACSTR, MAC2STR(dst));
234
235         memcpy(eth.h_dest, dst, ETH_ALEN);
236         memcpy(eth.h_source, src, ETH_ALEN);
237         eth.h_proto = host_to_be16(proto);
238
239         io[0].iov_base = "ETHER ";
240         io[0].iov_len = 6;
241         io[1].iov_base = &eth;
242         io[1].iov_len = sizeof(eth);
243         io[2].iov_base = (u8 *) data;
244         io[2].iov_len = data_len;
245
246         memset(&msg, 0, sizeof(msg));
247         msg.msg_iov = io;
248         msg.msg_iovlen = 3;
249
250         dir = opendir(drv->test_dir);
251         if (dir == NULL) {
252                 perror("test_driver: opendir");
253                 return -1;
254         }
255         while ((dent = readdir(dir))) {
256 #ifdef _DIRENT_HAVE_D_TYPE
257                 /* Skip the file if it is not a socket. Also accept
258                  * DT_UNKNOWN (0) in case the C library or underlying file
259                  * system does not support d_type. */
260                 if (dent->d_type != DT_SOCK && dent->d_type != DT_UNKNOWN)
261                         continue;
262 #endif /* _DIRENT_HAVE_D_TYPE */
263                 if (strcmp(dent->d_name, ".") == 0 ||
264                     strcmp(dent->d_name, "..") == 0)
265                         continue;
266
267                 memset(&addr, 0, sizeof(addr));
268                 addr.sun_family = AF_UNIX;
269                 snprintf(addr.sun_path, sizeof(addr.sun_path), "%s/%s",
270                          drv->test_dir, dent->d_name);
271
272                 if (strcmp(addr.sun_path, drv->own_socket_path) == 0)
273                         continue;
274                 if (!broadcast && strstr(dent->d_name, desttxt) == NULL)
275                         continue;
276
277                 wpa_printf(MSG_DEBUG, "%s: Send ether frame to %s",
278                            __func__, dent->d_name);
279
280                 msg.msg_name = &addr;
281                 msg.msg_namelen = sizeof(addr);
282                 ret = sendmsg(drv->test_socket, &msg, 0);
283                 if (ret < 0)
284                         perror("driver_test: sendmsg");
285                 count++;
286         }
287         closedir(dir);
288
289         if (!broadcast && count == 0) {
290                 wpa_printf(MSG_DEBUG, "%s: Destination " MACSTR " not found",
291                            __func__, MAC2STR(dst));
292                 return -1;
293         }
294
295         return ret;
296 }
297
298
299 static int wpa_driver_test_send_mlme(void *priv, const u8 *data,
300                                      size_t data_len)
301 {
302         struct wpa_driver_test_data *drv = priv;
303         struct msghdr msg;
304         struct iovec io[2];
305         const u8 *dest;
306         struct sockaddr_un addr;
307         struct dirent *dent;
308         DIR *dir;
309         int broadcast;
310         int ret = 0;
311         struct ieee80211_hdr *hdr;
312         u16 fc;
313         char cmd[50];
314         int freq;
315 #ifdef HOSTAPD
316         char desttxt[30];
317 #endif /* HOSTAPD */
318         union wpa_event_data event;
319
320         wpa_hexdump(MSG_MSGDUMP, "test_send_mlme", data, data_len);
321         if (drv->test_socket < 0 || data_len < 10) {
322                 wpa_printf(MSG_DEBUG, "%s: invalid parameters (sock=%d len=%lu"
323                            " test_dir=%p)",
324                            __func__, drv->test_socket,
325                            (unsigned long) data_len,
326                            drv->test_dir);
327                 return -1;
328         }
329
330         dest = data + 4;
331         broadcast = os_memcmp(dest, "\xff\xff\xff\xff\xff\xff", ETH_ALEN) == 0;
332
333 #ifdef HOSTAPD
334         snprintf(desttxt, sizeof(desttxt), MACSTR, MAC2STR(dest));
335 #endif /* HOSTAPD */
336
337         if (drv->remain_on_channel_freq)
338                 freq = drv->remain_on_channel_freq;
339         else
340                 freq = drv->current_freq;
341         wpa_printf(MSG_DEBUG, "test_driver(%s): MLME TX on freq %d MHz",
342                    drv->ifname, freq);
343         os_snprintf(cmd, sizeof(cmd), "MLME freq=%d ", freq);
344         io[0].iov_base = cmd;
345         io[0].iov_len = os_strlen(cmd);
346         io[1].iov_base = (void *) data;
347         io[1].iov_len = data_len;
348
349         os_memset(&msg, 0, sizeof(msg));
350         msg.msg_iov = io;
351         msg.msg_iovlen = 2;
352
353 #ifdef HOSTAPD
354         if (drv->test_dir == NULL) {
355                 wpa_printf(MSG_DEBUG, "%s: test_dir == NULL", __func__);
356                 return -1;
357         }
358
359         dir = opendir(drv->test_dir);
360         if (dir == NULL) {
361                 perror("test_driver: opendir");
362                 return -1;
363         }
364         while ((dent = readdir(dir))) {
365 #ifdef _DIRENT_HAVE_D_TYPE
366                 /* Skip the file if it is not a socket. Also accept
367                  * DT_UNKNOWN (0) in case the C library or underlying file
368                  * system does not support d_type. */
369                 if (dent->d_type != DT_SOCK && dent->d_type != DT_UNKNOWN)
370                         continue;
371 #endif /* _DIRENT_HAVE_D_TYPE */
372                 if (os_strcmp(dent->d_name, ".") == 0 ||
373                     os_strcmp(dent->d_name, "..") == 0)
374                         continue;
375
376                 os_memset(&addr, 0, sizeof(addr));
377                 addr.sun_family = AF_UNIX;
378                 os_snprintf(addr.sun_path, sizeof(addr.sun_path), "%s/%s",
379                             drv->test_dir, dent->d_name);
380
381                 if (os_strcmp(addr.sun_path, drv->own_socket_path) == 0)
382                         continue;
383                 if (!broadcast && os_strstr(dent->d_name, desttxt) == NULL)
384                         continue;
385
386                 wpa_printf(MSG_DEBUG, "%s: Send management frame to %s",
387                            __func__, dent->d_name);
388
389                 msg.msg_name = &addr;
390                 msg.msg_namelen = sizeof(addr);
391                 ret = sendmsg(drv->test_socket, &msg, 0);
392                 if (ret < 0)
393                         perror("driver_test: sendmsg(test_socket)");
394         }
395         closedir(dir);
396 #else /* HOSTAPD */
397
398         if (os_memcmp(dest, drv->bssid, ETH_ALEN) == 0 ||
399             drv->test_dir == NULL) {
400                 if (drv->hostapd_addr_udp_set) {
401                         msg.msg_name = &drv->hostapd_addr_udp;
402                         msg.msg_namelen = sizeof(drv->hostapd_addr_udp);
403                 } else {
404 #ifdef DRIVER_TEST_UNIX
405                         msg.msg_name = &drv->hostapd_addr;
406                         msg.msg_namelen = sizeof(drv->hostapd_addr);
407 #endif /* DRIVER_TEST_UNIX */
408                 }
409         } else if (broadcast) {
410                 dir = opendir(drv->test_dir);
411                 if (dir == NULL)
412                         return -1;
413                 while ((dent = readdir(dir))) {
414 #ifdef _DIRENT_HAVE_D_TYPE
415                         /* Skip the file if it is not a socket.
416                          * Also accept DT_UNKNOWN (0) in case
417                          * the C library or underlying file
418                          * system does not support d_type. */
419                         if (dent->d_type != DT_SOCK &&
420                             dent->d_type != DT_UNKNOWN)
421                                 continue;
422 #endif /* _DIRENT_HAVE_D_TYPE */
423                         if (os_strcmp(dent->d_name, ".") == 0 ||
424                             os_strcmp(dent->d_name, "..") == 0)
425                                 continue;
426                         wpa_printf(MSG_DEBUG, "%s: Send broadcast MLME to %s",
427                                    __func__, dent->d_name);
428                         os_memset(&addr, 0, sizeof(addr));
429                         addr.sun_family = AF_UNIX;
430                         os_snprintf(addr.sun_path, sizeof(addr.sun_path),
431                                     "%s/%s", drv->test_dir, dent->d_name);
432
433                         msg.msg_name = &addr;
434                         msg.msg_namelen = sizeof(addr);
435
436                         ret = sendmsg(drv->test_socket, &msg, 0);
437                         if (ret < 0)
438                                 perror("driver_test: sendmsg(test_socket)");
439                 }
440                 closedir(dir);
441                 return ret;
442         } else {
443                 struct stat st;
444                 os_memset(&addr, 0, sizeof(addr));
445                 addr.sun_family = AF_UNIX;
446                 os_snprintf(addr.sun_path, sizeof(addr.sun_path),
447                             "%s/AP-" MACSTR, drv->test_dir, MAC2STR(dest));
448                 if (stat(addr.sun_path, &st) < 0) {
449                         os_snprintf(addr.sun_path, sizeof(addr.sun_path),
450                                     "%s/STA-" MACSTR,
451                                     drv->test_dir, MAC2STR(dest));
452                 }
453                 msg.msg_name = &addr;
454                 msg.msg_namelen = sizeof(addr);
455         }
456
457         if (sendmsg(drv->test_socket, &msg, 0) < 0) {
458                 perror("sendmsg(test_socket)");
459                 return -1;
460         }
461 #endif /* HOSTAPD */
462
463         hdr = (struct ieee80211_hdr *) data;
464         fc = le_to_host16(hdr->frame_control);
465
466         os_memset(&event, 0, sizeof(event));
467         event.tx_status.type = WLAN_FC_GET_TYPE(fc);
468         event.tx_status.stype = WLAN_FC_GET_STYPE(fc);
469         event.tx_status.dst = hdr->addr1;
470         event.tx_status.data = data;
471         event.tx_status.data_len = data_len;
472         event.tx_status.ack = ret >= 0;
473         wpa_supplicant_event(drv->ctx, EVENT_TX_STATUS, &event);
474
475         return ret;
476 }
477
478
479 static void test_driver_scan(struct wpa_driver_test_data *drv,
480                              struct sockaddr_un *from, socklen_t fromlen,
481                              char *data)
482 {
483         char buf[512], *pos, *end;
484         int ret;
485         struct test_driver_bss *bss;
486         u8 sa[ETH_ALEN];
487         u8 ie[512];
488         size_t ielen;
489         union wpa_event_data event;
490
491         /* data: optional [ ' ' | STA-addr | ' ' | IEs(hex) ] */
492
493         wpa_printf(MSG_DEBUG, "test_driver: SCAN");
494
495         if (*data) {
496                 if (*data != ' ' ||
497                     hwaddr_aton(data + 1, sa)) {
498                         wpa_printf(MSG_DEBUG, "test_driver: Unexpected SCAN "
499                                    "command format");
500                         return;
501                 }
502
503                 data += 18;
504                 while (*data == ' ')
505                         data++;
506                 ielen = os_strlen(data) / 2;
507                 if (ielen > sizeof(ie))
508                         ielen = sizeof(ie);
509                 if (hexstr2bin(data, ie, ielen) < 0)
510                         ielen = 0;
511
512                 wpa_printf(MSG_DEBUG, "test_driver: Scan from " MACSTR,
513                            MAC2STR(sa));
514                 wpa_hexdump(MSG_MSGDUMP, "test_driver: scan IEs", ie, ielen);
515
516                 os_memset(&event, 0, sizeof(event));
517                 event.rx_probe_req.sa = sa;
518                 event.rx_probe_req.ie = ie;
519                 event.rx_probe_req.ie_len = ielen;
520                 wpa_supplicant_event(drv->ctx, EVENT_RX_PROBE_REQ, &event);
521         }
522
523         for (bss = drv->bss; bss; bss = bss->next) {
524                 pos = buf;
525                 end = buf + sizeof(buf);
526
527                 /* reply: SCANRESP BSSID SSID IEs */
528                 ret = snprintf(pos, end - pos, "SCANRESP " MACSTR " ",
529                                MAC2STR(bss->bssid));
530                 if (ret < 0 || ret >= end - pos)
531                         return;
532                 pos += ret;
533                 pos += wpa_snprintf_hex(pos, end - pos,
534                                         bss->ssid, bss->ssid_len);
535                 ret = snprintf(pos, end - pos, " ");
536                 if (ret < 0 || ret >= end - pos)
537                         return;
538                 pos += ret;
539                 pos += wpa_snprintf_hex(pos, end - pos, bss->ie, bss->ielen);
540                 pos += wpa_snprintf_hex(pos, end - pos, bss->wps_probe_resp_ie,
541                                         bss->wps_probe_resp_ie_len);
542
543                 if (bss->privacy) {
544                         ret = snprintf(pos, end - pos, " PRIVACY");
545                         if (ret < 0 || ret >= end - pos)
546                                 return;
547                         pos += ret;
548                 }
549
550                 sendto(drv->test_socket, buf, pos - buf, 0,
551                        (struct sockaddr *) from, fromlen);
552         }
553 }
554
555
556 static void test_driver_assoc(struct wpa_driver_test_data *drv,
557                               struct sockaddr_un *from, socklen_t fromlen,
558                               char *data)
559 {
560         struct test_client_socket *cli;
561         u8 ie[256], ssid[32];
562         size_t ielen, ssid_len = 0;
563         char *pos, *pos2, cmd[50];
564         struct test_driver_bss *bss;
565
566         /* data: STA-addr SSID(hex) IEs(hex) */
567
568         cli = os_zalloc(sizeof(*cli));
569         if (cli == NULL)
570                 return;
571
572         if (hwaddr_aton(data, cli->addr)) {
573                 printf("test_socket: Invalid MAC address '%s' in ASSOC\n",
574                        data);
575                 os_free(cli);
576                 return;
577         }
578         pos = data + 17;
579         while (*pos == ' ')
580                 pos++;
581         pos2 = strchr(pos, ' ');
582         ielen = 0;
583         if (pos2) {
584                 ssid_len = (pos2 - pos) / 2;
585                 if (hexstr2bin(pos, ssid, ssid_len) < 0) {
586                         wpa_printf(MSG_DEBUG, "%s: Invalid SSID", __func__);
587                         os_free(cli);
588                         return;
589                 }
590                 wpa_hexdump_ascii(MSG_DEBUG, "test_driver_assoc: SSID",
591                                   ssid, ssid_len);
592
593                 pos = pos2 + 1;
594                 ielen = strlen(pos) / 2;
595                 if (ielen > sizeof(ie))
596                         ielen = sizeof(ie);
597                 if (hexstr2bin(pos, ie, ielen) < 0)
598                         ielen = 0;
599         }
600
601         for (bss = drv->bss; bss; bss = bss->next) {
602                 if (bss->ssid_len == ssid_len &&
603                     memcmp(bss->ssid, ssid, ssid_len) == 0)
604                         break;
605         }
606         if (bss == NULL) {
607                 wpa_printf(MSG_DEBUG, "%s: No matching SSID found from "
608                            "configured BSSes", __func__);
609                 os_free(cli);
610                 return;
611         }
612
613         cli->bss = bss;
614         memcpy(&cli->un, from, sizeof(cli->un));
615         cli->unlen = fromlen;
616         cli->next = drv->cli;
617         drv->cli = cli;
618         wpa_hexdump_ascii(MSG_DEBUG, "test_socket: ASSOC sun_path",
619                           (const u8 *) cli->un.sun_path,
620                           cli->unlen - sizeof(cli->un.sun_family));
621
622         snprintf(cmd, sizeof(cmd), "ASSOCRESP " MACSTR " 0",
623                  MAC2STR(bss->bssid));
624         sendto(drv->test_socket, cmd, strlen(cmd), 0,
625                (struct sockaddr *) from, fromlen);
626
627         drv_event_assoc(bss->bss_ctx, cli->addr, ie, ielen);
628 }
629
630
631 static void test_driver_disassoc(struct wpa_driver_test_data *drv,
632                                  struct sockaddr_un *from, socklen_t fromlen)
633 {
634         struct test_client_socket *cli;
635
636         cli = test_driver_get_cli(drv, from, fromlen);
637         if (!cli)
638                 return;
639
640         drv_event_disassoc(drv->ctx, cli->addr);
641 }
642
643
644 static void test_driver_eapol(struct wpa_driver_test_data *drv,
645                               struct sockaddr_un *from, socklen_t fromlen,
646                               u8 *data, size_t datalen)
647 {
648 #ifdef HOSTAPD
649         struct test_client_socket *cli;
650 #endif /* HOSTAPD */
651         const u8 *src = NULL;
652
653         if (datalen > 14) {
654                 /* Skip Ethernet header */
655                 src = data + ETH_ALEN;
656                 wpa_printf(MSG_DEBUG, "test_driver: dst=" MACSTR " src="
657                            MACSTR " proto=%04x",
658                            MAC2STR(data), MAC2STR(src),
659                            WPA_GET_BE16(data + 2 * ETH_ALEN));
660                 data += 14;
661                 datalen -= 14;
662         }
663
664 #ifdef HOSTAPD
665         cli = test_driver_get_cli(drv, from, fromlen);
666         if (cli) {
667                 drv_event_eapol_rx(cli->bss->bss_ctx, cli->addr, data,
668                                    datalen);
669         } else {
670                 wpa_printf(MSG_DEBUG, "test_socket: EAPOL from unknown "
671                            "client");
672         }
673 #else /* HOSTAPD */
674         if (src)
675                 drv_event_eapol_rx(drv->ctx, src, data, datalen);
676 #endif /* HOSTAPD */
677 }
678
679
680 static void test_driver_ether(struct wpa_driver_test_data *drv,
681                               struct sockaddr_un *from, socklen_t fromlen,
682                               u8 *data, size_t datalen)
683 {
684         struct l2_ethhdr *eth;
685
686         if (datalen < sizeof(*eth))
687                 return;
688
689         eth = (struct l2_ethhdr *) data;
690         wpa_printf(MSG_DEBUG, "test_driver: RX ETHER dst=" MACSTR " src="
691                    MACSTR " proto=%04x",
692                    MAC2STR(eth->h_dest), MAC2STR(eth->h_source),
693                    be_to_host16(eth->h_proto));
694
695 #ifdef CONFIG_IEEE80211R
696         if (be_to_host16(eth->h_proto) == ETH_P_RRB) {
697                 union wpa_event_data ev;
698                 os_memset(&ev, 0, sizeof(ev));
699                 ev.ft_rrb_rx.src = eth->h_source;
700                 ev.ft_rrb_rx.data = data + sizeof(*eth);
701                 ev.ft_rrb_rx.data_len = datalen - sizeof(*eth);
702         }
703 #endif /* CONFIG_IEEE80211R */
704 }
705
706
707 static void test_driver_mlme(struct wpa_driver_test_data *drv,
708                              struct sockaddr_un *from, socklen_t fromlen,
709                              u8 *data, size_t datalen)
710 {
711         struct ieee80211_hdr *hdr;
712         u16 fc;
713         union wpa_event_data event;
714         int freq = 0, own_freq;
715
716         if (datalen > 6 && os_memcmp(data, "freq=", 5) == 0) {
717                 size_t pos;
718                 for (pos = 5; pos < datalen; pos++) {
719                         if (data[pos] == ' ')
720                                 break;
721                 }
722                 if (pos < datalen) {
723                         freq = atoi((const char *) &data[5]);
724                         wpa_printf(MSG_DEBUG, "test_driver(%s): MLME RX on "
725                                    "freq %d MHz", drv->ifname, freq);
726                         pos++;
727                         data += pos;
728                         datalen -= pos;
729                 }
730         }
731
732         if (drv->remain_on_channel_freq)
733                 own_freq = drv->remain_on_channel_freq;
734         else
735                 own_freq = drv->current_freq;
736
737         if (freq && own_freq && freq != own_freq) {
738                 wpa_printf(MSG_DEBUG, "test_driver(%s): Ignore MLME RX on "
739                            "another frequency %d MHz (own %d MHz)",
740                            drv->ifname, freq, own_freq);
741                 return;
742         }
743
744         hdr = (struct ieee80211_hdr *) data;
745
746         if (test_driver_get_cli(drv, from, fromlen) == NULL && datalen >= 16) {
747                 struct test_client_socket *cli;
748                 cli = os_zalloc(sizeof(*cli));
749                 if (cli == NULL)
750                         return;
751                 wpa_printf(MSG_DEBUG, "Adding client entry for " MACSTR,
752                            MAC2STR(hdr->addr2));
753                 memcpy(cli->addr, hdr->addr2, ETH_ALEN);
754                 memcpy(&cli->un, from, sizeof(cli->un));
755                 cli->unlen = fromlen;
756                 cli->next = drv->cli;
757                 drv->cli = cli;
758         }
759
760         wpa_hexdump(MSG_MSGDUMP, "test_driver_mlme: received frame",
761                     data, datalen);
762         fc = le_to_host16(hdr->frame_control);
763         if (WLAN_FC_GET_TYPE(fc) != WLAN_FC_TYPE_MGMT) {
764                 wpa_printf(MSG_ERROR, "%s: received non-mgmt frame",
765                            __func__);
766                 return;
767         }
768
769         os_memset(&event, 0, sizeof(event));
770         event.rx_mgmt.frame = data;
771         event.rx_mgmt.frame_len = datalen;
772         wpa_supplicant_event(drv->ctx, EVENT_RX_MGMT, &event);
773 }
774
775
776 static void test_driver_receive_unix(int sock, void *eloop_ctx, void *sock_ctx)
777 {
778         struct wpa_driver_test_data *drv = eloop_ctx;
779         char buf[2000];
780         int res;
781         struct sockaddr_un from;
782         socklen_t fromlen = sizeof(from);
783
784         res = recvfrom(sock, buf, sizeof(buf) - 1, 0,
785                        (struct sockaddr *) &from, &fromlen);
786         if (res < 0) {
787                 perror("recvfrom(test_socket)");
788                 return;
789         }
790         buf[res] = '\0';
791
792         wpa_printf(MSG_DEBUG, "test_driver: received %u bytes", res);
793
794         if (strncmp(buf, "SCAN", 4) == 0) {
795                 test_driver_scan(drv, &from, fromlen, buf + 4);
796         } else if (strncmp(buf, "ASSOC ", 6) == 0) {
797                 test_driver_assoc(drv, &from, fromlen, buf + 6);
798         } else if (strcmp(buf, "DISASSOC") == 0) {
799                 test_driver_disassoc(drv, &from, fromlen);
800         } else if (strncmp(buf, "EAPOL ", 6) == 0) {
801                 test_driver_eapol(drv, &from, fromlen, (u8 *) buf + 6,
802                                   res - 6);
803         } else if (strncmp(buf, "ETHER ", 6) == 0) {
804                 test_driver_ether(drv, &from, fromlen, (u8 *) buf + 6,
805                                   res - 6);
806         } else if (strncmp(buf, "MLME ", 5) == 0) {
807                 test_driver_mlme(drv, &from, fromlen, (u8 *) buf + 5, res - 5);
808         } else {
809                 wpa_hexdump_ascii(MSG_DEBUG, "Unknown test_socket command",
810                                   (u8 *) buf, res);
811         }
812 }
813
814
815 static struct test_driver_bss *
816 test_driver_get_bss(struct wpa_driver_test_data *drv, const char *ifname)
817 {
818         struct test_driver_bss *bss;
819
820         for (bss = drv->bss; bss; bss = bss->next) {
821                 if (os_strcmp(bss->ifname, ifname) == 0)
822                         return bss;
823         }
824         return NULL;
825 }
826
827
828 static int test_driver_set_generic_elem(const char *ifname, void *priv,
829                                         const u8 *elem, size_t elem_len)
830 {
831         struct wpa_driver_test_data *drv = priv;
832         struct test_driver_bss *bss;
833
834         bss = test_driver_get_bss(drv, ifname);
835         if (bss == NULL)
836                 return -1;
837
838         os_free(bss->ie);
839
840         if (elem == NULL) {
841                 bss->ie = NULL;
842                 bss->ielen = 0;
843                 return 0;
844         }
845
846         bss->ie = os_malloc(elem_len);
847         if (bss->ie == NULL) {
848                 bss->ielen = 0;
849                 return -1;
850         }
851
852         memcpy(bss->ie, elem, elem_len);
853         bss->ielen = elem_len;
854         return 0;
855 }
856
857
858 static int test_driver_set_ap_wps_ie(const char *ifname, void *priv,
859                                      const struct wpabuf *beacon,
860                                      const struct wpabuf *proberesp)
861 {
862         struct wpa_driver_test_data *drv = priv;
863         struct test_driver_bss *bss;
864
865         bss = test_driver_get_bss(drv, ifname);
866         if (bss == NULL)
867                 return -1;
868
869         if (beacon == NULL)
870                 wpa_printf(MSG_DEBUG, "test_driver: Clear Beacon WPS IE");
871         else
872                 wpa_hexdump_buf(MSG_DEBUG, "test_driver: Beacon WPS IE",
873                                 beacon);
874
875         os_free(bss->wps_beacon_ie);
876
877         if (beacon == NULL) {
878                 bss->wps_beacon_ie = NULL;
879                 bss->wps_beacon_ie_len = 0;
880         } else {
881                 bss->wps_beacon_ie = os_malloc(wpabuf_len(beacon));
882                 if (bss->wps_beacon_ie == NULL) {
883                         bss->wps_beacon_ie_len = 0;
884                         return -1;
885                 }
886
887                 os_memcpy(bss->wps_beacon_ie, wpabuf_head(beacon),
888                           wpabuf_len(beacon));
889                 bss->wps_beacon_ie_len = wpabuf_len(beacon);
890         }
891
892         if (proberesp == NULL)
893                 wpa_printf(MSG_DEBUG, "test_driver: Clear Probe Response WPS "
894                            "IE");
895         else
896                 wpa_hexdump_buf(MSG_DEBUG, "test_driver: Probe Response WPS "
897                                 "IE", proberesp);
898
899         os_free(bss->wps_probe_resp_ie);
900
901         if (proberesp == NULL) {
902                 bss->wps_probe_resp_ie = NULL;
903                 bss->wps_probe_resp_ie_len = 0;
904         } else {
905                 bss->wps_probe_resp_ie = os_malloc(wpabuf_len(proberesp));
906                 if (bss->wps_probe_resp_ie == NULL) {
907                         bss->wps_probe_resp_ie_len = 0;
908                         return -1;
909                 }
910
911                 os_memcpy(bss->wps_probe_resp_ie, wpabuf_head(proberesp),
912                           wpabuf_len(proberesp));
913                 bss->wps_probe_resp_ie_len = wpabuf_len(proberesp);
914         }
915
916         return 0;
917 }
918
919
920 static int test_driver_sta_deauth(void *priv, const u8 *own_addr,
921                                   const u8 *addr, int reason)
922 {
923         struct wpa_driver_test_data *drv = priv;
924         struct test_client_socket *cli;
925
926         if (drv->test_socket < 0)
927                 return -1;
928
929         cli = drv->cli;
930         while (cli) {
931                 if (memcmp(cli->addr, addr, ETH_ALEN) == 0)
932                         break;
933                 cli = cli->next;
934         }
935
936         if (!cli)
937                 return -1;
938
939         return sendto(drv->test_socket, "DEAUTH", 6, 0,
940                       (struct sockaddr *) &cli->un, cli->unlen);
941 }
942
943
944 static int test_driver_sta_disassoc(void *priv, const u8 *own_addr,
945                                     const u8 *addr, int reason)
946 {
947         struct wpa_driver_test_data *drv = priv;
948         struct test_client_socket *cli;
949
950         if (drv->test_socket < 0)
951                 return -1;
952
953         cli = drv->cli;
954         while (cli) {
955                 if (memcmp(cli->addr, addr, ETH_ALEN) == 0)
956                         break;
957                 cli = cli->next;
958         }
959
960         if (!cli)
961                 return -1;
962
963         return sendto(drv->test_socket, "DISASSOC", 8, 0,
964                       (struct sockaddr *) &cli->un, cli->unlen);
965 }
966
967
968 static int test_driver_bss_add(void *priv, const char *ifname, const u8 *bssid,
969                                void *bss_ctx)
970 {
971         struct wpa_driver_test_data *drv = priv;
972         struct test_driver_bss *bss;
973
974         wpa_printf(MSG_DEBUG, "%s(ifname=%s bssid=" MACSTR ")",
975                    __func__, ifname, MAC2STR(bssid));
976
977         bss = os_zalloc(sizeof(*bss));
978         if (bss == NULL)
979                 return -1;
980
981         bss->bss_ctx = bss_ctx;
982         os_strlcpy(bss->ifname, ifname, IFNAMSIZ);
983         memcpy(bss->bssid, bssid, ETH_ALEN);
984
985         bss->next = drv->bss;
986         drv->bss = bss;
987         drv->global->bss_add_used = 1;
988         os_memcpy(drv->global->req_addr, bssid, ETH_ALEN);
989
990         return 0;
991 }
992
993
994 static int test_driver_bss_remove(void *priv, const char *ifname)
995 {
996         struct wpa_driver_test_data *drv = priv;
997         struct test_driver_bss *bss, *prev;
998         struct test_client_socket *cli, *prev_c;
999
1000         wpa_printf(MSG_DEBUG, "%s(ifname=%s)", __func__, ifname);
1001
1002         for (prev = NULL, bss = drv->bss; bss; prev = bss, bss = bss->next) {
1003                 if (strcmp(bss->ifname, ifname) != 0)
1004                         continue;
1005
1006                 if (prev)
1007                         prev->next = bss->next;
1008                 else
1009                         drv->bss = bss->next;
1010
1011                 for (prev_c = NULL, cli = drv->cli; cli;
1012                      prev_c = cli, cli = cli->next) {
1013                         if (cli->bss != bss)
1014                                 continue;
1015                         if (prev_c)
1016                                 prev_c->next = cli->next;
1017                         else
1018                                 drv->cli = cli->next;
1019                         os_free(cli);
1020                         break;
1021                 }
1022
1023                 test_driver_free_bss(bss);
1024                 return 0;
1025         }
1026
1027         return -1;
1028 }
1029
1030
1031 static int test_driver_if_add(const char *iface, void *priv,
1032                               enum wpa_driver_if_type type, const char *ifname,
1033                               const u8 *addr, void *bss_ctx)
1034 {
1035         wpa_printf(MSG_DEBUG, "%s(iface=%s type=%d ifname=%s bss_ctx=%p)",
1036                    __func__, iface, type, ifname, bss_ctx);
1037         if (type == WPA_IF_AP_BSS)
1038                 return test_driver_bss_add(priv, ifname, addr, bss_ctx);
1039         return 0;
1040 }
1041
1042
1043 static int test_driver_if_remove(void *priv, enum wpa_driver_if_type type,
1044                                  const char *ifname)
1045 {
1046         wpa_printf(MSG_DEBUG, "%s(type=%d ifname=%s)", __func__, type, ifname);
1047         if (type == WPA_IF_AP_BSS)
1048                 return test_driver_bss_remove(priv, ifname);
1049         return 0;
1050 }
1051
1052
1053 static int test_driver_valid_bss_mask(void *priv, const u8 *addr,
1054                                       const u8 *mask)
1055 {
1056         return 0;
1057 }
1058
1059
1060 static int test_driver_set_ssid(const char *ifname, void *priv, const u8 *buf,
1061                                 int len)
1062 {
1063         struct wpa_driver_test_data *drv = priv;
1064         struct test_driver_bss *bss;
1065
1066         wpa_printf(MSG_DEBUG, "%s(ifname=%s)", __func__, ifname);
1067         wpa_hexdump_ascii(MSG_DEBUG, "test_driver_set_ssid: SSID", buf, len);
1068
1069         bss = test_driver_get_bss(drv, ifname);
1070         if (bss == NULL) {
1071                 wpa_printf(MSG_DEBUG, "%s(ifname=%s): failed to find BSS data",
1072                            __func__, ifname);
1073                 return -1;
1074         }
1075
1076         if (len < 0 || (size_t) len > sizeof(bss->ssid))
1077                 return -1;
1078
1079         os_memcpy(bss->ssid, buf, len);
1080         bss->ssid_len = len;
1081
1082         return 0;
1083 }
1084
1085
1086 static int test_driver_set_privacy(const char *ifname, void *priv, int enabled)
1087 {
1088         struct wpa_driver_test_data *drv = priv;
1089         struct test_driver_bss *bss;
1090
1091         wpa_printf(MSG_DEBUG, "%s(ifname=%s enabled=%d)",
1092                    __func__, ifname, enabled);
1093
1094         bss = test_driver_get_bss(drv, ifname);
1095         if (bss == NULL)
1096                 return -1;
1097
1098         bss->privacy = enabled;
1099
1100         return 0;
1101 }
1102
1103
1104 static int test_driver_set_sta_vlan(void *priv, const u8 *addr,
1105                                     const char *ifname, int vlan_id)
1106 {
1107         wpa_printf(MSG_DEBUG, "%s(addr=" MACSTR " ifname=%s vlan_id=%d)",
1108                    __func__, MAC2STR(addr), ifname, vlan_id);
1109         return 0;
1110 }
1111
1112
1113 static int test_driver_sta_add(const char *ifname, void *priv,
1114                                struct hostapd_sta_add_params *params)
1115 {
1116         struct wpa_driver_test_data *drv = priv;
1117         struct test_client_socket *cli;
1118         struct test_driver_bss *bss;
1119
1120         wpa_printf(MSG_DEBUG, "%s(ifname=%s addr=" MACSTR " aid=%d "
1121                    "capability=0x%x listen_interval=%d)",
1122                    __func__, ifname, MAC2STR(params->addr), params->aid,
1123                    params->capability, params->listen_interval);
1124         wpa_hexdump(MSG_DEBUG, "test_driver_sta_add - supp_rates",
1125                     params->supp_rates, params->supp_rates_len);
1126
1127         cli = drv->cli;
1128         while (cli) {
1129                 if (os_memcmp(cli->addr, params->addr, ETH_ALEN) == 0)
1130                         break;
1131                 cli = cli->next;
1132         }
1133         if (!cli) {
1134                 wpa_printf(MSG_DEBUG, "%s: no matching client entry",
1135                            __func__);
1136                 return -1;
1137         }
1138
1139         bss = test_driver_get_bss(drv, ifname);
1140         if (bss == NULL) {
1141                 wpa_printf(MSG_DEBUG, "%s: No matching interface found from "
1142                            "configured BSSes", __func__);
1143                 return -1;
1144         }
1145
1146         cli->bss = bss;
1147
1148         return 0;
1149 }
1150
1151
1152 static struct wpa_driver_test_data * test_alloc_data(void *ctx,
1153                                                      const char *ifname)
1154 {
1155         struct wpa_driver_test_data *drv;
1156
1157         drv = os_zalloc(sizeof(struct wpa_driver_test_data));
1158         if (drv == NULL) {
1159                 wpa_printf(MSG_ERROR, "Could not allocate memory for test "
1160                            "driver data");
1161                 return NULL;
1162         }
1163
1164         drv->ctx = ctx;
1165         wpa_trace_add_ref(drv, ctx, ctx);
1166         os_strlcpy(drv->ifname, ifname, IFNAMSIZ);
1167
1168         /* Generate a MAC address to help testing with multiple STAs */
1169         drv->own_addr[0] = 0x02; /* locally administered */
1170         sha1_prf((const u8 *) ifname, os_strlen(ifname),
1171                  "test mac addr generation",
1172                  NULL, 0, drv->own_addr + 1, ETH_ALEN - 1);
1173
1174         return drv;
1175 }
1176
1177
1178 static void * test_driver_init(struct hostapd_data *hapd,
1179                                struct wpa_init_params *params)
1180 {
1181         struct wpa_driver_test_data *drv;
1182         struct sockaddr_un addr_un;
1183         struct sockaddr_in addr_in;
1184         struct sockaddr *addr;
1185         socklen_t alen;
1186
1187         drv = test_alloc_data(hapd, params->ifname);
1188         if (drv == NULL)
1189                 return NULL;
1190         drv->ap = 1;
1191         drv->bss = os_zalloc(sizeof(*drv->bss));
1192         if (drv->bss == NULL) {
1193                 wpa_printf(MSG_ERROR, "Could not allocate memory for test "
1194                            "driver BSS data");
1195                 os_free(drv);
1196                 return NULL;
1197         }
1198
1199         drv->bss->bss_ctx = hapd;
1200         os_strlcpy(drv->bss->ifname, params->ifname, IFNAMSIZ);
1201         os_memcpy(drv->bss->bssid, drv->own_addr, ETH_ALEN);
1202         os_memcpy(params->own_addr, drv->own_addr, ETH_ALEN);
1203
1204         if (params->test_socket) {
1205                 if (os_strlen(params->test_socket) >=
1206                     sizeof(addr_un.sun_path)) {
1207                         printf("Too long test_socket path\n");
1208                         wpa_driver_test_deinit(drv);
1209                         return NULL;
1210                 }
1211                 if (strncmp(params->test_socket, "DIR:", 4) == 0) {
1212                         size_t len = strlen(params->test_socket) + 30;
1213                         drv->test_dir = os_strdup(params->test_socket + 4);
1214                         drv->own_socket_path = os_malloc(len);
1215                         if (drv->own_socket_path) {
1216                                 snprintf(drv->own_socket_path, len,
1217                                          "%s/AP-" MACSTR,
1218                                          params->test_socket + 4,
1219                                          MAC2STR(params->own_addr));
1220                         }
1221                 } else if (strncmp(params->test_socket, "UDP:", 4) == 0) {
1222                         drv->udp_port = atoi(params->test_socket + 4);
1223                 } else {
1224                         drv->own_socket_path = os_strdup(params->test_socket);
1225                 }
1226                 if (drv->own_socket_path == NULL && drv->udp_port == 0) {
1227                         wpa_driver_test_deinit(drv);
1228                         return NULL;
1229                 }
1230
1231                 drv->test_socket = socket(drv->udp_port ? PF_INET : PF_UNIX,
1232                                           SOCK_DGRAM, 0);
1233                 if (drv->test_socket < 0) {
1234                         perror("socket");
1235                         wpa_driver_test_deinit(drv);
1236                         return NULL;
1237                 }
1238
1239                 if (drv->udp_port) {
1240                         os_memset(&addr_in, 0, sizeof(addr_in));
1241                         addr_in.sin_family = AF_INET;
1242                         addr_in.sin_port = htons(drv->udp_port);
1243                         addr = (struct sockaddr *) &addr_in;
1244                         alen = sizeof(addr_in);
1245                 } else {
1246                         os_memset(&addr_un, 0, sizeof(addr_un));
1247                         addr_un.sun_family = AF_UNIX;
1248                         os_strlcpy(addr_un.sun_path, drv->own_socket_path,
1249                                    sizeof(addr_un.sun_path));
1250                         addr = (struct sockaddr *) &addr_un;
1251                         alen = sizeof(addr_un);
1252                 }
1253                 if (bind(drv->test_socket, addr, alen) < 0) {
1254                         perror("bind(PF_UNIX)");
1255                         close(drv->test_socket);
1256                         if (drv->own_socket_path)
1257                                 unlink(drv->own_socket_path);
1258                         wpa_driver_test_deinit(drv);
1259                         return NULL;
1260                 }
1261                 eloop_register_read_sock(drv->test_socket,
1262                                          test_driver_receive_unix, drv, NULL);
1263         } else
1264                 drv->test_socket = -1;
1265
1266         return drv;
1267 }
1268
1269
1270 static void wpa_driver_test_poll(void *eloop_ctx, void *timeout_ctx)
1271 {
1272         struct wpa_driver_test_data *drv = eloop_ctx;
1273
1274 #ifdef DRIVER_TEST_UNIX
1275         if (drv->associated && drv->hostapd_addr_set) {
1276                 struct stat st;
1277                 if (stat(drv->hostapd_addr.sun_path, &st) < 0) {
1278                         wpa_printf(MSG_DEBUG, "%s: lost connection to AP: %s",
1279                                    __func__, strerror(errno));
1280                         drv->associated = 0;
1281                         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1282                 }
1283         }
1284 #endif /* DRIVER_TEST_UNIX */
1285
1286         eloop_register_timeout(1, 0, wpa_driver_test_poll, drv, NULL);
1287 }
1288
1289
1290 static void wpa_driver_test_scan_timeout(void *eloop_ctx, void *timeout_ctx)
1291 {
1292         wpa_printf(MSG_DEBUG, "Scan timeout - try to get results");
1293         wpa_supplicant_event(timeout_ctx, EVENT_SCAN_RESULTS, NULL);
1294 }
1295
1296
1297 #ifdef DRIVER_TEST_UNIX
1298 static void wpa_driver_scan_dir(struct wpa_driver_test_data *drv,
1299                                 const char *path)
1300 {
1301         struct dirent *dent;
1302         DIR *dir;
1303         struct sockaddr_un addr;
1304         char cmd[512], *pos, *end;
1305         int ret;
1306
1307         dir = opendir(path);
1308         if (dir == NULL)
1309                 return;
1310
1311         end = cmd + sizeof(cmd);
1312         pos = cmd;
1313         ret = os_snprintf(pos, end - pos, "SCAN " MACSTR,
1314                           MAC2STR(drv->own_addr));
1315         if (ret >= 0 && ret < end - pos)
1316                 pos += ret;
1317         if (drv->probe_req_ie) {
1318                 ret = os_snprintf(pos, end - pos, " ");
1319                 if (ret >= 0 && ret < end - pos)
1320                         pos += ret;
1321                 pos += wpa_snprintf_hex(pos, end - pos, drv->probe_req_ie,
1322                                         drv->probe_req_ie_len);
1323         }
1324         if (drv->probe_req_ssid_len) {
1325                 /* Add SSID IE */
1326                 ret = os_snprintf(pos, end - pos, "%02x%02x",
1327                                   WLAN_EID_SSID,
1328                                   (unsigned int) drv->probe_req_ssid_len);
1329                 if (ret >= 0 && ret < end - pos)
1330                         pos += ret;
1331                 pos += wpa_snprintf_hex(pos, end - pos, drv->probe_req_ssid,
1332                                         drv->probe_req_ssid_len);
1333         }
1334         end[-1] = '\0';
1335
1336         while ((dent = readdir(dir))) {
1337                 if (os_strncmp(dent->d_name, "AP-", 3) != 0 &&
1338                     os_strncmp(dent->d_name, "STA-", 4) != 0)
1339                         continue;
1340                 if (drv->own_socket_path) {
1341                         size_t olen, dlen;
1342                         olen = os_strlen(drv->own_socket_path);
1343                         dlen = os_strlen(dent->d_name);
1344                         if (olen >= dlen &&
1345                             os_strcmp(dent->d_name,
1346                                       drv->own_socket_path + olen - dlen) == 0)
1347                                 continue;
1348                 }
1349                 wpa_printf(MSG_DEBUG, "%s: SCAN %s", __func__, dent->d_name);
1350
1351                 os_memset(&addr, 0, sizeof(addr));
1352                 addr.sun_family = AF_UNIX;
1353                 os_snprintf(addr.sun_path, sizeof(addr.sun_path), "%s/%s",
1354                             path, dent->d_name);
1355
1356                 if (sendto(drv->test_socket, cmd, os_strlen(cmd), 0,
1357                            (struct sockaddr *) &addr, sizeof(addr)) < 0) {
1358                         perror("sendto(test_socket)");
1359                 }
1360         }
1361         closedir(dir);
1362 }
1363 #endif /* DRIVER_TEST_UNIX */
1364
1365
1366 static int wpa_driver_test_scan(void *priv,
1367                                 struct wpa_driver_scan_params *params)
1368 {
1369         struct wpa_driver_test_data *drv = priv;
1370         size_t i;
1371
1372         wpa_printf(MSG_DEBUG, "%s: priv=%p", __func__, priv);
1373
1374         os_free(drv->probe_req_ie);
1375         if (params->extra_ies) {
1376                 drv->probe_req_ie = os_malloc(params->extra_ies_len);
1377                 if (drv->probe_req_ie == NULL) {
1378                         drv->probe_req_ie_len = 0;
1379                         return -1;
1380                 }
1381                 os_memcpy(drv->probe_req_ie, params->extra_ies,
1382                           params->extra_ies_len);
1383                 drv->probe_req_ie_len = params->extra_ies_len;
1384         } else {
1385                 drv->probe_req_ie = NULL;
1386                 drv->probe_req_ie_len = 0;
1387         }
1388
1389         for (i = 0; i < params->num_ssids; i++)
1390                 wpa_hexdump(MSG_DEBUG, "Scan SSID",
1391                             params->ssids[i].ssid, params->ssids[i].ssid_len);
1392         drv->probe_req_ssid_len = 0;
1393         if (params->num_ssids) {
1394                 os_memcpy(drv->probe_req_ssid, params->ssids[0].ssid,
1395                           params->ssids[0].ssid_len);
1396                 drv->probe_req_ssid_len = params->ssids[0].ssid_len;
1397         }
1398         wpa_hexdump(MSG_DEBUG, "Scan extra IE(s)",
1399                     params->extra_ies, params->extra_ies_len);
1400
1401         drv->num_scanres = 0;
1402
1403 #ifdef DRIVER_TEST_UNIX
1404         if (drv->test_socket >= 0 && drv->test_dir)
1405                 wpa_driver_scan_dir(drv, drv->test_dir);
1406
1407         if (drv->test_socket >= 0 && drv->hostapd_addr_set &&
1408             sendto(drv->test_socket, "SCAN", 4, 0,
1409                    (struct sockaddr *) &drv->hostapd_addr,
1410                    sizeof(drv->hostapd_addr)) < 0) {
1411                 perror("sendto(test_socket)");
1412         }
1413 #endif /* DRIVER_TEST_UNIX */
1414
1415         if (drv->test_socket >= 0 && drv->hostapd_addr_udp_set &&
1416             sendto(drv->test_socket, "SCAN", 4, 0,
1417                    (struct sockaddr *) &drv->hostapd_addr_udp,
1418                    sizeof(drv->hostapd_addr_udp)) < 0) {
1419                 perror("sendto(test_socket)");
1420         }
1421
1422         eloop_cancel_timeout(wpa_driver_test_scan_timeout, drv, drv->ctx);
1423         eloop_register_timeout(1, 0, wpa_driver_test_scan_timeout, drv,
1424                                drv->ctx);
1425         return 0;
1426 }
1427
1428
1429 static struct wpa_scan_results * wpa_driver_test_get_scan_results2(void *priv)
1430 {
1431         struct wpa_driver_test_data *drv = priv;
1432         struct wpa_scan_results *res;
1433         size_t i;
1434
1435         res = os_zalloc(sizeof(*res));
1436         if (res == NULL)
1437                 return NULL;
1438
1439         res->res = os_zalloc(drv->num_scanres * sizeof(struct wpa_scan_res *));
1440         if (res->res == NULL) {
1441                 os_free(res);
1442                 return NULL;
1443         }
1444
1445         for (i = 0; i < drv->num_scanres; i++) {
1446                 struct wpa_scan_res *r;
1447                 if (drv->scanres[i] == NULL)
1448                         continue;
1449                 r = os_malloc(sizeof(*r) + drv->scanres[i]->ie_len);
1450                 if (r == NULL)
1451                         break;
1452                 os_memcpy(r, drv->scanres[i],
1453                           sizeof(*r) + drv->scanres[i]->ie_len);
1454                 res->res[res->num++] = r;
1455         }
1456
1457         return res;
1458 }
1459
1460
1461 static int wpa_driver_test_set_key(const char *ifname, void *priv,
1462                                    enum wpa_alg alg, const u8 *addr,
1463                                    int key_idx, int set_tx,
1464                                    const u8 *seq, size_t seq_len,
1465                                    const u8 *key, size_t key_len)
1466 {
1467         wpa_printf(MSG_DEBUG, "%s: ifname=%s priv=%p alg=%d key_idx=%d "
1468                    "set_tx=%d",
1469                    __func__, ifname, priv, alg, key_idx, set_tx);
1470         if (addr)
1471                 wpa_printf(MSG_DEBUG, "   addr=" MACSTR, MAC2STR(addr));
1472         if (seq)
1473                 wpa_hexdump(MSG_DEBUG, "   seq", seq, seq_len);
1474         if (key)
1475                 wpa_hexdump_key(MSG_DEBUG, "   key", key, key_len);
1476         return 0;
1477 }
1478
1479
1480 static int wpa_driver_update_mode(struct wpa_driver_test_data *drv, int ap)
1481 {
1482         if (ap && !drv->ap) {
1483                 wpa_driver_test_close_test_socket(drv);
1484                 wpa_driver_test_attach(drv, drv->test_dir, 1);
1485                 drv->ap = 1;
1486         } else if (!ap && drv->ap) {
1487                 wpa_driver_test_close_test_socket(drv);
1488                 wpa_driver_test_attach(drv, drv->test_dir, 0);
1489                 drv->ap = 0;
1490         }
1491
1492         return 0;
1493 }
1494
1495
1496 static int wpa_driver_test_associate(
1497         void *priv, struct wpa_driver_associate_params *params)
1498 {
1499         struct wpa_driver_test_data *drv = priv;
1500         wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d pairwise_suite=%d "
1501                    "group_suite=%d key_mgmt_suite=%d auth_alg=%d mode=%d",
1502                    __func__, priv, params->freq, params->pairwise_suite,
1503                    params->group_suite, params->key_mgmt_suite,
1504                    params->auth_alg, params->mode);
1505         if (params->bssid) {
1506                 wpa_printf(MSG_DEBUG, "   bssid=" MACSTR,
1507                            MAC2STR(params->bssid));
1508         }
1509         if (params->ssid) {
1510                 wpa_hexdump_ascii(MSG_DEBUG, "   ssid",
1511                                   params->ssid, params->ssid_len);
1512         }
1513         if (params->wpa_ie) {
1514                 wpa_hexdump(MSG_DEBUG, "   wpa_ie",
1515                             params->wpa_ie, params->wpa_ie_len);
1516                 drv->assoc_wpa_ie_len = params->wpa_ie_len;
1517                 if (drv->assoc_wpa_ie_len > sizeof(drv->assoc_wpa_ie))
1518                         drv->assoc_wpa_ie_len = sizeof(drv->assoc_wpa_ie);
1519                 os_memcpy(drv->assoc_wpa_ie, params->wpa_ie,
1520                           drv->assoc_wpa_ie_len);
1521         } else
1522                 drv->assoc_wpa_ie_len = 0;
1523
1524         wpa_driver_update_mode(drv, params->mode == IEEE80211_MODE_AP);
1525
1526         drv->ibss = params->mode == IEEE80211_MODE_IBSS;
1527         drv->privacy = params->key_mgmt_suite &
1528                 (WPA_KEY_MGMT_IEEE8021X |
1529                  WPA_KEY_MGMT_PSK |
1530                  WPA_KEY_MGMT_WPA_NONE |
1531                  WPA_KEY_MGMT_FT_IEEE8021X |
1532                  WPA_KEY_MGMT_FT_PSK |
1533                  WPA_KEY_MGMT_IEEE8021X_SHA256 |
1534                  WPA_KEY_MGMT_PSK_SHA256);
1535         if (params->wep_key_len[params->wep_tx_keyidx])
1536                 drv->privacy = 1;
1537
1538 #ifdef DRIVER_TEST_UNIX
1539         if (drv->test_dir && params->bssid &&
1540             params->mode != IEEE80211_MODE_IBSS) {
1541                 os_memset(&drv->hostapd_addr, 0, sizeof(drv->hostapd_addr));
1542                 drv->hostapd_addr.sun_family = AF_UNIX;
1543                 os_snprintf(drv->hostapd_addr.sun_path,
1544                             sizeof(drv->hostapd_addr.sun_path),
1545                             "%s/AP-" MACSTR,
1546                             drv->test_dir, MAC2STR(params->bssid));
1547                 drv->hostapd_addr_set = 1;
1548         }
1549 #endif /* DRIVER_TEST_UNIX */
1550
1551         if (params->mode == IEEE80211_MODE_AP) {
1552                 struct test_driver_bss *bss;
1553                 os_memcpy(drv->ssid, params->ssid, params->ssid_len);
1554                 drv->ssid_len = params->ssid_len;
1555
1556                 test_driver_free_bsses(drv);
1557                 bss = drv->bss = os_zalloc(sizeof(*drv->bss));
1558                 if (bss == NULL)
1559                         return -1;
1560                 os_strlcpy(bss->ifname, drv->ifname, IFNAMSIZ);
1561                 os_memcpy(bss->bssid, drv->own_addr, ETH_ALEN);
1562                 os_memcpy(bss->ssid, params->ssid, params->ssid_len);
1563                 bss->ssid_len = params->ssid_len;
1564                 bss->privacy = drv->privacy;
1565                 if (params->wpa_ie && params->wpa_ie_len) {
1566                         bss->ie = os_malloc(params->wpa_ie_len);
1567                         if (bss->ie) {
1568                                 os_memcpy(bss->ie, params->wpa_ie,
1569                                           params->wpa_ie_len);
1570                                 bss->ielen = params->wpa_ie_len;
1571                         }
1572                 }
1573         } else if (drv->test_socket >= 0 &&
1574                    (drv->hostapd_addr_set || drv->hostapd_addr_udp_set)) {
1575                 char cmd[200], *pos, *end;
1576                 int ret;
1577                 end = cmd + sizeof(cmd);
1578                 pos = cmd;
1579                 ret = os_snprintf(pos, end - pos, "ASSOC " MACSTR " ",
1580                                   MAC2STR(drv->own_addr));
1581                 if (ret >= 0 && ret < end - pos)
1582                         pos += ret;
1583                 pos += wpa_snprintf_hex(pos, end - pos, params->ssid,
1584                                         params->ssid_len);
1585                 ret = os_snprintf(pos, end - pos, " ");
1586                 if (ret >= 0 && ret < end - pos)
1587                         pos += ret;
1588                 pos += wpa_snprintf_hex(pos, end - pos, params->wpa_ie,
1589                                         params->wpa_ie_len);
1590                 end[-1] = '\0';
1591 #ifdef DRIVER_TEST_UNIX
1592                 if (drv->hostapd_addr_set &&
1593                     sendto(drv->test_socket, cmd, os_strlen(cmd), 0,
1594                            (struct sockaddr *) &drv->hostapd_addr,
1595                            sizeof(drv->hostapd_addr)) < 0) {
1596                         perror("sendto(test_socket)");
1597                         return -1;
1598                 }
1599 #endif /* DRIVER_TEST_UNIX */
1600                 if (drv->hostapd_addr_udp_set &&
1601                     sendto(drv->test_socket, cmd, os_strlen(cmd), 0,
1602                            (struct sockaddr *) &drv->hostapd_addr_udp,
1603                            sizeof(drv->hostapd_addr_udp)) < 0) {
1604                         perror("sendto(test_socket)");
1605                         return -1;
1606                 }
1607
1608                 os_memcpy(drv->ssid, params->ssid, params->ssid_len);
1609                 drv->ssid_len = params->ssid_len;
1610         } else {
1611                 drv->associated = 1;
1612                 if (params->mode == IEEE80211_MODE_IBSS) {
1613                         os_memcpy(drv->ssid, params->ssid, params->ssid_len);
1614                         drv->ssid_len = params->ssid_len;
1615                         if (params->bssid)
1616                                 os_memcpy(drv->bssid, params->bssid, ETH_ALEN);
1617                         else {
1618                                 os_get_random(drv->bssid, ETH_ALEN);
1619                                 drv->bssid[0] &= ~0x01;
1620                                 drv->bssid[0] |= 0x02;
1621                         }
1622                 }
1623                 wpa_supplicant_event(drv->ctx, EVENT_ASSOC, NULL);
1624         }
1625
1626         return 0;
1627 }
1628
1629
1630 static int wpa_driver_test_get_bssid(void *priv, u8 *bssid)
1631 {
1632         struct wpa_driver_test_data *drv = priv;
1633         os_memcpy(bssid, drv->bssid, ETH_ALEN);
1634         return 0;
1635 }
1636
1637
1638 static int wpa_driver_test_get_ssid(void *priv, u8 *ssid)
1639 {
1640         struct wpa_driver_test_data *drv = priv;
1641         os_memcpy(ssid, drv->ssid, 32);
1642         return drv->ssid_len;
1643 }
1644
1645
1646 static int wpa_driver_test_send_disassoc(struct wpa_driver_test_data *drv)
1647 {
1648 #ifdef DRIVER_TEST_UNIX
1649         if (drv->test_socket >= 0 &&
1650             sendto(drv->test_socket, "DISASSOC", 8, 0,
1651                    (struct sockaddr *) &drv->hostapd_addr,
1652                    sizeof(drv->hostapd_addr)) < 0) {
1653                 perror("sendto(test_socket)");
1654                 return -1;
1655         }
1656 #endif /* DRIVER_TEST_UNIX */
1657         if (drv->test_socket >= 0 && drv->hostapd_addr_udp_set &&
1658             sendto(drv->test_socket, "DISASSOC", 8, 0,
1659                    (struct sockaddr *) &drv->hostapd_addr_udp,
1660                    sizeof(drv->hostapd_addr_udp)) < 0) {
1661                 perror("sendto(test_socket)");
1662                 return -1;
1663         }
1664         return 0;
1665 }
1666
1667
1668 static int wpa_driver_test_deauthenticate(void *priv, const u8 *addr,
1669                                           int reason_code)
1670 {
1671         struct wpa_driver_test_data *drv = priv;
1672         wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
1673                    __func__, MAC2STR(addr), reason_code);
1674         os_memset(drv->bssid, 0, ETH_ALEN);
1675         drv->associated = 0;
1676         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1677         return wpa_driver_test_send_disassoc(drv);
1678 }
1679
1680
1681 static int wpa_driver_test_disassociate(void *priv, const u8 *addr,
1682                                         int reason_code)
1683 {
1684         struct wpa_driver_test_data *drv = priv;
1685         wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
1686                    __func__, MAC2STR(addr), reason_code);
1687         os_memset(drv->bssid, 0, ETH_ALEN);
1688         drv->associated = 0;
1689         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1690         return wpa_driver_test_send_disassoc(drv);
1691 }
1692
1693
1694 static void wpa_driver_test_scanresp(struct wpa_driver_test_data *drv,
1695                                      struct sockaddr *from,
1696                                      socklen_t fromlen,
1697                                      const char *data)
1698 {
1699         struct wpa_scan_res *res;
1700         const char *pos, *pos2;
1701         size_t len;
1702         u8 *ie_pos, *ie_start, *ie_end;
1703 #define MAX_IE_LEN 1000
1704
1705         wpa_printf(MSG_DEBUG, "test_driver: SCANRESP %s", data);
1706         if (drv->num_scanres >= MAX_SCAN_RESULTS) {
1707                 wpa_printf(MSG_DEBUG, "test_driver: No room for the new scan "
1708                            "result");
1709                 return;
1710         }
1711
1712         /* SCANRESP BSSID SSID IEs */
1713
1714         res = os_zalloc(sizeof(*res) + MAX_IE_LEN);
1715         if (res == NULL)
1716                 return;
1717         ie_start = ie_pos = (u8 *) (res + 1);
1718         ie_end = ie_pos + MAX_IE_LEN;
1719
1720         if (hwaddr_aton(data, res->bssid)) {
1721                 wpa_printf(MSG_DEBUG, "test_driver: invalid BSSID in scanres");
1722                 os_free(res);
1723                 return;
1724         }
1725
1726         pos = data + 17;
1727         while (*pos == ' ')
1728                 pos++;
1729         pos2 = os_strchr(pos, ' ');
1730         if (pos2 == NULL) {
1731                 wpa_printf(MSG_DEBUG, "test_driver: invalid SSID termination "
1732                            "in scanres");
1733                 os_free(res);
1734                 return;
1735         }
1736         len = (pos2 - pos) / 2;
1737         if (len > 32)
1738                 len = 32;
1739         /*
1740          * Generate SSID IE from the SSID field since this IE is not included
1741          * in the main IE field.
1742          */
1743         *ie_pos++ = WLAN_EID_SSID;
1744         *ie_pos++ = len;
1745         if (hexstr2bin(pos, ie_pos, len) < 0) {
1746                 wpa_printf(MSG_DEBUG, "test_driver: invalid SSID in scanres");
1747                 os_free(res);
1748                 return;
1749         }
1750         ie_pos += len;
1751
1752         pos = pos2 + 1;
1753         pos2 = os_strchr(pos, ' ');
1754         if (pos2 == NULL)
1755                 len = os_strlen(pos) / 2;
1756         else
1757                 len = (pos2 - pos) / 2;
1758         if ((int) len > ie_end - ie_pos)
1759                 len = ie_end - ie_pos;
1760         if (hexstr2bin(pos, ie_pos, len) < 0) {
1761                 wpa_printf(MSG_DEBUG, "test_driver: invalid IEs in scanres");
1762                 os_free(res);
1763                 return;
1764         }
1765         ie_pos += len;
1766         res->ie_len = ie_pos - ie_start;
1767
1768         if (pos2) {
1769                 pos = pos2 + 1;
1770                 while (*pos == ' ')
1771                         pos++;
1772                 if (os_strstr(pos, "PRIVACY"))
1773                         res->caps |= IEEE80211_CAP_PRIVACY;
1774                 if (os_strstr(pos, "IBSS"))
1775                         res->caps |= IEEE80211_CAP_IBSS;
1776         }
1777
1778         os_free(drv->scanres[drv->num_scanres]);
1779         drv->scanres[drv->num_scanres++] = res;
1780 }
1781
1782
1783 static void wpa_driver_test_assocresp(struct wpa_driver_test_data *drv,
1784                                       struct sockaddr *from,
1785                                       socklen_t fromlen,
1786                                       const char *data)
1787 {
1788         /* ASSOCRESP BSSID <res> */
1789         if (hwaddr_aton(data, drv->bssid)) {
1790                 wpa_printf(MSG_DEBUG, "test_driver: invalid BSSID in "
1791                            "assocresp");
1792         }
1793         if (drv->use_associnfo) {
1794                 union wpa_event_data event;
1795                 os_memset(&event, 0, sizeof(event));
1796                 event.assoc_info.req_ies = drv->assoc_wpa_ie;
1797                 event.assoc_info.req_ies_len = drv->assoc_wpa_ie_len;
1798                 wpa_supplicant_event(drv->ctx, EVENT_ASSOCINFO, &event);
1799         }
1800         drv->associated = 1;
1801         wpa_supplicant_event(drv->ctx, EVENT_ASSOC, NULL);
1802 }
1803
1804
1805 static void wpa_driver_test_disassoc(struct wpa_driver_test_data *drv,
1806                                      struct sockaddr *from,
1807                                      socklen_t fromlen)
1808 {
1809         drv->associated = 0;
1810         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1811 }
1812
1813
1814 static void wpa_driver_test_eapol(struct wpa_driver_test_data *drv,
1815                                   struct sockaddr *from,
1816                                   socklen_t fromlen,
1817                                   const u8 *data, size_t data_len)
1818 {
1819         const u8 *src = drv->bssid;
1820
1821         if (data_len > 14) {
1822                 /* Skip Ethernet header */
1823                 src = data + ETH_ALEN;
1824                 data += 14;
1825                 data_len -= 14;
1826         }
1827
1828         drv_event_eapol_rx(drv->ctx, src, data, data_len);
1829 }
1830
1831
1832 static void wpa_driver_test_mlme(struct wpa_driver_test_data *drv,
1833                                  struct sockaddr *from,
1834                                  socklen_t fromlen,
1835                                  const u8 *data, size_t data_len)
1836 {
1837         int freq = 0, own_freq;
1838         union wpa_event_data event;
1839
1840         if (data_len > 6 && os_memcmp(data, "freq=", 5) == 0) {
1841                 size_t pos;
1842                 for (pos = 5; pos < data_len; pos++) {
1843                         if (data[pos] == ' ')
1844                                 break;
1845                 }
1846                 if (pos < data_len) {
1847                         freq = atoi((const char *) &data[5]);
1848                         wpa_printf(MSG_DEBUG, "test_driver(%s): MLME RX on "
1849                                    "freq %d MHz", drv->ifname, freq);
1850                         pos++;
1851                         data += pos;
1852                         data_len -= pos;
1853                 }
1854         }
1855
1856         if (drv->remain_on_channel_freq)
1857                 own_freq = drv->remain_on_channel_freq;
1858         else
1859                 own_freq = drv->current_freq;
1860
1861         if (freq && own_freq && freq != own_freq) {
1862                 wpa_printf(MSG_DEBUG, "test_driver(%s): Ignore MLME RX on "
1863                            "another frequency %d MHz (own %d MHz)",
1864                            drv->ifname, freq, own_freq);
1865                 return;
1866         }
1867
1868         os_memset(&event, 0, sizeof(event));
1869         event.mlme_rx.buf = data;
1870         event.mlme_rx.len = data_len;
1871         event.mlme_rx.freq = freq;
1872         wpa_supplicant_event(drv->ctx, EVENT_MLME_RX, &event);
1873
1874         if (drv->probe_req_report && data_len >= 24) {
1875                 const struct ieee80211_mgmt *mgmt;
1876                 u16 fc;
1877
1878                 mgmt = (const struct ieee80211_mgmt *) data;
1879                 fc = le_to_host16(mgmt->frame_control);
1880                 if (WLAN_FC_GET_TYPE(fc) == WLAN_FC_TYPE_MGMT &&
1881                     WLAN_FC_GET_STYPE(fc) == WLAN_FC_STYPE_PROBE_REQ) {
1882                         os_memset(&event, 0, sizeof(event));
1883                         event.rx_probe_req.sa = mgmt->sa;
1884                         event.rx_probe_req.ie = mgmt->u.probe_req.variable;
1885                         event.rx_probe_req.ie_len =
1886                                 data_len - (mgmt->u.probe_req.variable - data);
1887                         wpa_supplicant_event(drv->ctx, EVENT_RX_PROBE_REQ,
1888                                              &event);
1889                 }
1890         }
1891 }
1892
1893
1894 static void wpa_driver_test_scan_cmd(struct wpa_driver_test_data *drv,
1895                                      struct sockaddr *from,
1896                                      socklen_t fromlen,
1897                                      const u8 *data, size_t data_len)
1898 {
1899         char buf[512], *pos, *end;
1900         int ret;
1901
1902         /* data: optional [ STA-addr | ' ' | IEs(hex) ] */
1903
1904         if (!drv->ibss)
1905                 return;
1906
1907         pos = buf;
1908         end = buf + sizeof(buf);
1909
1910         /* reply: SCANRESP BSSID SSID IEs */
1911         ret = snprintf(pos, end - pos, "SCANRESP " MACSTR " ",
1912                        MAC2STR(drv->bssid));
1913         if (ret < 0 || ret >= end - pos)
1914                 return;
1915         pos += ret;
1916         pos += wpa_snprintf_hex(pos, end - pos,
1917                                 drv->ssid, drv->ssid_len);
1918         ret = snprintf(pos, end - pos, " ");
1919         if (ret < 0 || ret >= end - pos)
1920                 return;
1921         pos += ret;
1922         pos += wpa_snprintf_hex(pos, end - pos, drv->assoc_wpa_ie,
1923                                 drv->assoc_wpa_ie_len);
1924
1925         if (drv->privacy) {
1926                 ret = snprintf(pos, end - pos, " PRIVACY");
1927                 if (ret < 0 || ret >= end - pos)
1928                         return;
1929                 pos += ret;
1930         }
1931
1932         ret = snprintf(pos, end - pos, " IBSS");
1933         if (ret < 0 || ret >= end - pos)
1934                 return;
1935         pos += ret;
1936
1937         sendto(drv->test_socket, buf, pos - buf, 0,
1938                (struct sockaddr *) from, fromlen);
1939 }
1940
1941
1942 static void wpa_driver_test_receive_unix(int sock, void *eloop_ctx,
1943                                          void *sock_ctx)
1944 {
1945         struct wpa_driver_test_data *drv = eloop_ctx;
1946         char *buf;
1947         int res;
1948         struct sockaddr_storage from;
1949         socklen_t fromlen = sizeof(from);
1950         const size_t buflen = 2000;
1951
1952         if (drv->ap) {
1953                 test_driver_receive_unix(sock, eloop_ctx, sock_ctx);
1954                 return;
1955         }
1956
1957         buf = os_malloc(buflen);
1958         if (buf == NULL)
1959                 return;
1960         res = recvfrom(sock, buf, buflen - 1, 0,
1961                        (struct sockaddr *) &from, &fromlen);
1962         if (res < 0) {
1963                 perror("recvfrom(test_socket)");
1964                 os_free(buf);
1965                 return;
1966         }
1967         buf[res] = '\0';
1968
1969         wpa_printf(MSG_DEBUG, "test_driver: received %u bytes", res);
1970
1971         if (os_strncmp(buf, "SCANRESP ", 9) == 0) {
1972                 wpa_driver_test_scanresp(drv, (struct sockaddr *) &from,
1973                                          fromlen, buf + 9);
1974         } else if (os_strncmp(buf, "ASSOCRESP ", 10) == 0) {
1975                 wpa_driver_test_assocresp(drv, (struct sockaddr *) &from,
1976                                           fromlen, buf + 10);
1977         } else if (os_strcmp(buf, "DISASSOC") == 0) {
1978                 wpa_driver_test_disassoc(drv, (struct sockaddr *) &from,
1979                                          fromlen);
1980         } else if (os_strcmp(buf, "DEAUTH") == 0) {
1981                 wpa_driver_test_disassoc(drv, (struct sockaddr *) &from,
1982                                          fromlen);
1983         } else if (os_strncmp(buf, "EAPOL ", 6) == 0) {
1984                 wpa_driver_test_eapol(drv, (struct sockaddr *) &from, fromlen,
1985                                       (const u8 *) buf + 6, res - 6);
1986         } else if (os_strncmp(buf, "MLME ", 5) == 0) {
1987                 wpa_driver_test_mlme(drv, (struct sockaddr *) &from, fromlen,
1988                                      (const u8 *) buf + 5, res - 5);
1989         } else if (os_strncmp(buf, "SCAN ", 5) == 0) {
1990                 wpa_driver_test_scan_cmd(drv, (struct sockaddr *) &from,
1991                                          fromlen,
1992                                          (const u8 *) buf + 5, res - 5);
1993         } else {
1994                 wpa_hexdump_ascii(MSG_DEBUG, "Unknown test_socket command",
1995                                   (u8 *) buf, res);
1996         }
1997         os_free(buf);
1998 }
1999
2000
2001 static void * wpa_driver_test_init2(void *ctx, const char *ifname,
2002                                     void *global_priv)
2003 {
2004         struct wpa_driver_test_data *drv;
2005         struct wpa_driver_test_global *global = global_priv;
2006
2007         drv = test_alloc_data(ctx, ifname);
2008         if (drv == NULL)
2009                 return NULL;
2010         drv->global = global_priv;
2011         drv->test_socket = -1;
2012
2013         /* Set dummy BSSID and SSID for testing. */
2014         drv->bssid[0] = 0x02;
2015         drv->bssid[1] = 0x00;
2016         drv->bssid[2] = 0x00;
2017         drv->bssid[3] = 0x00;
2018         drv->bssid[4] = 0x00;
2019         drv->bssid[5] = 0x01;
2020         os_memcpy(drv->ssid, "test", 5);
2021         drv->ssid_len = 4;
2022
2023         if (global->bss_add_used) {
2024                 os_memcpy(drv->own_addr, global->req_addr, ETH_ALEN);
2025                 global->bss_add_used = 0;
2026         }
2027
2028         eloop_register_timeout(1, 0, wpa_driver_test_poll, drv, NULL);
2029
2030         return drv;
2031 }
2032
2033
2034 static void wpa_driver_test_close_test_socket(struct wpa_driver_test_data *drv)
2035 {
2036         if (drv->test_socket >= 0) {
2037                 eloop_unregister_read_sock(drv->test_socket);
2038                 close(drv->test_socket);
2039                 drv->test_socket = -1;
2040         }
2041
2042         if (drv->own_socket_path) {
2043                 unlink(drv->own_socket_path);
2044                 os_free(drv->own_socket_path);
2045                 drv->own_socket_path = NULL;
2046         }
2047 }
2048
2049
2050 static void wpa_driver_test_deinit(void *priv)
2051 {
2052         struct wpa_driver_test_data *drv = priv;
2053         struct test_client_socket *cli, *prev;
2054         int i;
2055
2056         cli = drv->cli;
2057         while (cli) {
2058                 prev = cli;
2059                 cli = cli->next;
2060                 os_free(prev);
2061         }
2062
2063 #ifdef HOSTAPD
2064         /* There should be only one BSS remaining at this point. */
2065         if (drv->bss == NULL)
2066                 wpa_printf(MSG_ERROR, "%s: drv->bss == NULL", __func__);
2067         else if (drv->bss->next)
2068                 wpa_printf(MSG_ERROR, "%s: drv->bss->next != NULL", __func__);
2069 #endif /* HOSTAPD */
2070
2071         test_driver_free_bsses(drv);
2072
2073         wpa_driver_test_close_test_socket(drv);
2074         eloop_cancel_timeout(wpa_driver_test_scan_timeout, drv, drv->ctx);
2075         eloop_cancel_timeout(wpa_driver_test_poll, drv, NULL);
2076         eloop_cancel_timeout(test_remain_on_channel_timeout, drv, NULL);
2077         os_free(drv->test_dir);
2078         for (i = 0; i < MAX_SCAN_RESULTS; i++)
2079                 os_free(drv->scanres[i]);
2080         os_free(drv->probe_req_ie);
2081         wpa_trace_remove_ref(drv, ctx, drv->ctx);
2082         os_free(drv);
2083 }
2084
2085
2086 static int wpa_driver_test_attach(struct wpa_driver_test_data *drv,
2087                                   const char *dir, int ap)
2088 {
2089 #ifdef DRIVER_TEST_UNIX
2090         static unsigned int counter = 0;
2091         struct sockaddr_un addr;
2092         size_t len;
2093
2094         os_free(drv->own_socket_path);
2095         if (dir) {
2096                 len = os_strlen(dir) + 30;
2097                 drv->own_socket_path = os_malloc(len);
2098                 if (drv->own_socket_path == NULL)
2099                         return -1;
2100                 os_snprintf(drv->own_socket_path, len, "%s/%s-" MACSTR,
2101                             dir, ap ? "AP" : "STA", MAC2STR(drv->own_addr));
2102         } else {
2103                 drv->own_socket_path = os_malloc(100);
2104                 if (drv->own_socket_path == NULL)
2105                         return -1;
2106                 os_snprintf(drv->own_socket_path, 100,
2107                             "/tmp/wpa_supplicant_test-%d-%d",
2108                             getpid(), counter++);
2109         }
2110
2111         drv->test_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
2112         if (drv->test_socket < 0) {
2113                 perror("socket(PF_UNIX)");
2114                 os_free(drv->own_socket_path);
2115                 drv->own_socket_path = NULL;
2116                 return -1;
2117         }
2118
2119         os_memset(&addr, 0, sizeof(addr));
2120         addr.sun_family = AF_UNIX;
2121         os_strlcpy(addr.sun_path, drv->own_socket_path, sizeof(addr.sun_path));
2122         if (bind(drv->test_socket, (struct sockaddr *) &addr,
2123                  sizeof(addr)) < 0) {
2124                 perror("bind(PF_UNIX)");
2125                 close(drv->test_socket);
2126                 unlink(drv->own_socket_path);
2127                 os_free(drv->own_socket_path);
2128                 drv->own_socket_path = NULL;
2129                 return -1;
2130         }
2131
2132         eloop_register_read_sock(drv->test_socket,
2133                                  wpa_driver_test_receive_unix, drv, NULL);
2134
2135         return 0;
2136 #else /* DRIVER_TEST_UNIX */
2137         return -1;
2138 #endif /* DRIVER_TEST_UNIX */
2139 }
2140
2141
2142 static int wpa_driver_test_attach_udp(struct wpa_driver_test_data *drv,
2143                                       char *dst)
2144 {
2145         char *pos;
2146
2147         pos = os_strchr(dst, ':');
2148         if (pos == NULL)
2149                 return -1;
2150         *pos++ = '\0';
2151         wpa_printf(MSG_DEBUG, "%s: addr=%s port=%s", __func__, dst, pos);
2152
2153         drv->test_socket = socket(PF_INET, SOCK_DGRAM, 0);
2154         if (drv->test_socket < 0) {
2155                 perror("socket(PF_INET)");
2156                 return -1;
2157         }
2158
2159         os_memset(&drv->hostapd_addr_udp, 0, sizeof(drv->hostapd_addr_udp));
2160         drv->hostapd_addr_udp.sin_family = AF_INET;
2161 #if defined(CONFIG_NATIVE_WINDOWS) || defined(CONFIG_ANSI_C_EXTRA)
2162         {
2163                 int a[4];
2164                 u8 *pos;
2165                 sscanf(dst, "%d.%d.%d.%d", &a[0], &a[1], &a[2], &a[3]);
2166                 pos = (u8 *) &drv->hostapd_addr_udp.sin_addr;
2167                 *pos++ = a[0];
2168                 *pos++ = a[1];
2169                 *pos++ = a[2];
2170                 *pos++ = a[3];
2171         }
2172 #else /* CONFIG_NATIVE_WINDOWS or CONFIG_ANSI_C_EXTRA */
2173         inet_aton(dst, &drv->hostapd_addr_udp.sin_addr);
2174 #endif /* CONFIG_NATIVE_WINDOWS or CONFIG_ANSI_C_EXTRA */
2175         drv->hostapd_addr_udp.sin_port = htons(atoi(pos));
2176
2177         drv->hostapd_addr_udp_set = 1;
2178
2179         eloop_register_read_sock(drv->test_socket,
2180                                  wpa_driver_test_receive_unix, drv, NULL);
2181
2182         return 0;
2183 }
2184
2185
2186 static int wpa_driver_test_set_param(void *priv, const char *param)
2187 {
2188         struct wpa_driver_test_data *drv = priv;
2189         const char *pos;
2190
2191         wpa_printf(MSG_DEBUG, "%s: param='%s'", __func__, param);
2192         if (param == NULL)
2193                 return 0;
2194
2195         wpa_driver_test_close_test_socket(drv);
2196
2197 #ifdef DRIVER_TEST_UNIX
2198         pos = os_strstr(param, "test_socket=");
2199         if (pos) {
2200                 const char *pos2;
2201                 size_t len;
2202
2203                 pos += 12;
2204                 pos2 = os_strchr(pos, ' ');
2205                 if (pos2)
2206                         len = pos2 - pos;
2207                 else
2208                         len = os_strlen(pos);
2209                 if (len > sizeof(drv->hostapd_addr.sun_path))
2210                         return -1;
2211                 os_memset(&drv->hostapd_addr, 0, sizeof(drv->hostapd_addr));
2212                 drv->hostapd_addr.sun_family = AF_UNIX;
2213                 os_memcpy(drv->hostapd_addr.sun_path, pos, len);
2214                 drv->hostapd_addr_set = 1;
2215         }
2216 #endif /* DRIVER_TEST_UNIX */
2217
2218         pos = os_strstr(param, "test_dir=");
2219         if (pos) {
2220                 char *end;
2221                 os_free(drv->test_dir);
2222                 drv->test_dir = os_strdup(pos + 9);
2223                 if (drv->test_dir == NULL)
2224                         return -1;
2225                 end = os_strchr(drv->test_dir, ' ');
2226                 if (end)
2227                         *end = '\0';
2228                 if (wpa_driver_test_attach(drv, drv->test_dir, 0))
2229                         return -1;
2230         } else {
2231                 pos = os_strstr(param, "test_udp=");
2232                 if (pos) {
2233                         char *dst, *epos;
2234                         dst = os_strdup(pos + 9);
2235                         if (dst == NULL)
2236                                 return -1;
2237                         epos = os_strchr(dst, ' ');
2238                         if (epos)
2239                                 *epos = '\0';
2240                         if (wpa_driver_test_attach_udp(drv, dst))
2241                                 return -1;
2242                         os_free(dst);
2243                 } else if (wpa_driver_test_attach(drv, NULL, 0))
2244                         return -1;
2245         }
2246
2247         if (os_strstr(param, "use_associnfo=1")) {
2248                 wpa_printf(MSG_DEBUG, "test_driver: Use AssocInfo events");
2249                 drv->use_associnfo = 1;
2250         }
2251
2252 #ifdef CONFIG_CLIENT_MLME
2253         if (os_strstr(param, "use_mlme=1")) {
2254                 wpa_printf(MSG_DEBUG, "test_driver: Use internal MLME");
2255                 drv->use_mlme = 1;
2256         }
2257 #endif /* CONFIG_CLIENT_MLME */
2258
2259         return 0;
2260 }
2261
2262
2263 static const u8 * wpa_driver_test_get_mac_addr(void *priv)
2264 {
2265         struct wpa_driver_test_data *drv = priv;
2266         wpa_printf(MSG_DEBUG, "%s", __func__);
2267         return drv->own_addr;
2268 }
2269
2270
2271 static int wpa_driver_test_send_eapol(void *priv, const u8 *dest, u16 proto,
2272                                       const u8 *data, size_t data_len)
2273 {
2274         struct wpa_driver_test_data *drv = priv;
2275         char *msg;
2276         size_t msg_len;
2277         struct l2_ethhdr eth;
2278         struct sockaddr *addr;
2279         socklen_t alen;
2280 #ifdef DRIVER_TEST_UNIX
2281         struct sockaddr_un addr_un;
2282 #endif /* DRIVER_TEST_UNIX */
2283
2284         wpa_hexdump(MSG_MSGDUMP, "test_send_eapol TX frame", data, data_len);
2285
2286         os_memset(&eth, 0, sizeof(eth));
2287         os_memcpy(eth.h_dest, dest, ETH_ALEN);
2288         os_memcpy(eth.h_source, drv->own_addr, ETH_ALEN);
2289         eth.h_proto = host_to_be16(proto);
2290
2291         msg_len = 6 + sizeof(eth) + data_len;
2292         msg = os_malloc(msg_len);
2293         if (msg == NULL)
2294                 return -1;
2295         os_memcpy(msg, "EAPOL ", 6);
2296         os_memcpy(msg + 6, &eth, sizeof(eth));
2297         os_memcpy(msg + 6 + sizeof(eth), data, data_len);
2298
2299         if (os_memcmp(dest, drv->bssid, ETH_ALEN) == 0 ||
2300             drv->test_dir == NULL) {
2301                 if (drv->hostapd_addr_udp_set) {
2302                         addr = (struct sockaddr *) &drv->hostapd_addr_udp;
2303                         alen = sizeof(drv->hostapd_addr_udp);
2304                 } else {
2305 #ifdef DRIVER_TEST_UNIX
2306                         addr = (struct sockaddr *) &drv->hostapd_addr;
2307                         alen = sizeof(drv->hostapd_addr);
2308 #else /* DRIVER_TEST_UNIX */
2309                         os_free(msg);
2310                         return -1;
2311 #endif /* DRIVER_TEST_UNIX */
2312                 }
2313         } else {
2314 #ifdef DRIVER_TEST_UNIX
2315                 struct stat st;
2316                 os_memset(&addr_un, 0, sizeof(addr_un));
2317                 addr_un.sun_family = AF_UNIX;
2318                 os_snprintf(addr_un.sun_path, sizeof(addr_un.sun_path),
2319                             "%s/STA-" MACSTR, drv->test_dir, MAC2STR(dest));
2320                 if (stat(addr_un.sun_path, &st) < 0) {
2321                         os_snprintf(addr_un.sun_path, sizeof(addr_un.sun_path),
2322                                     "%s/AP-" MACSTR,
2323                                     drv->test_dir, MAC2STR(dest));
2324                 }
2325                 addr = (struct sockaddr *) &addr_un;
2326                 alen = sizeof(addr_un);
2327 #else /* DRIVER_TEST_UNIX */
2328                 os_free(msg);
2329                 return -1;
2330 #endif /* DRIVER_TEST_UNIX */
2331         }
2332
2333         if (sendto(drv->test_socket, msg, msg_len, 0, addr, alen) < 0) {
2334                 perror("sendmsg(test_socket)");
2335                 os_free(msg);
2336                 return -1;
2337         }
2338
2339         os_free(msg);
2340         return 0;
2341 }
2342
2343
2344 static int wpa_driver_test_get_capa(void *priv, struct wpa_driver_capa *capa)
2345 {
2346         struct wpa_driver_test_data *drv = priv;
2347         os_memset(capa, 0, sizeof(*capa));
2348         capa->key_mgmt = WPA_DRIVER_CAPA_KEY_MGMT_WPA |
2349                 WPA_DRIVER_CAPA_KEY_MGMT_WPA2 |
2350                 WPA_DRIVER_CAPA_KEY_MGMT_WPA_PSK |
2351                 WPA_DRIVER_CAPA_KEY_MGMT_WPA2_PSK |
2352                 WPA_DRIVER_CAPA_KEY_MGMT_WPA_NONE |
2353                 WPA_DRIVER_CAPA_KEY_MGMT_FT |
2354                 WPA_DRIVER_CAPA_KEY_MGMT_FT_PSK;
2355         capa->enc = WPA_DRIVER_CAPA_ENC_WEP40 |
2356                 WPA_DRIVER_CAPA_ENC_WEP104 |
2357                 WPA_DRIVER_CAPA_ENC_TKIP |
2358                 WPA_DRIVER_CAPA_ENC_CCMP;
2359         capa->auth = WPA_DRIVER_AUTH_OPEN |
2360                 WPA_DRIVER_AUTH_SHARED |
2361                 WPA_DRIVER_AUTH_LEAP;
2362         if (drv->use_mlme)
2363                 capa->flags |= WPA_DRIVER_FLAGS_USER_SPACE_MLME;
2364         capa->flags |= WPA_DRIVER_FLAGS_AP;
2365         capa->max_scan_ssids = 2;
2366
2367         return 0;
2368 }
2369
2370
2371 static int wpa_driver_test_mlme_setprotection(void *priv, const u8 *addr,
2372                                               int protect_type,
2373                                               int key_type)
2374 {
2375         wpa_printf(MSG_DEBUG, "%s: protect_type=%d key_type=%d",
2376                    __func__, protect_type, key_type);
2377
2378         if (addr) {
2379                 wpa_printf(MSG_DEBUG, "%s: addr=" MACSTR,
2380                            __func__, MAC2STR(addr));
2381         }
2382
2383         return 0;
2384 }
2385
2386
2387 static int wpa_driver_test_set_channel(void *priv,
2388                                        enum hostapd_hw_mode phymode,
2389                                        int chan, int freq)
2390 {
2391         struct wpa_driver_test_data *drv = priv;
2392         wpa_printf(MSG_DEBUG, "%s: phymode=%d chan=%d freq=%d",
2393                    __func__, phymode, chan, freq);
2394         drv->current_freq = freq;
2395         return 0;
2396 }
2397
2398
2399 static int wpa_driver_test_mlme_add_sta(void *priv, const u8 *addr,
2400                                         const u8 *supp_rates,
2401                                         size_t supp_rates_len)
2402 {
2403         wpa_printf(MSG_DEBUG, "%s: addr=" MACSTR, __func__, MAC2STR(addr));
2404         return 0;
2405 }
2406
2407
2408 static int wpa_driver_test_mlme_remove_sta(void *priv, const u8 *addr)
2409 {
2410         wpa_printf(MSG_DEBUG, "%s: addr=" MACSTR, __func__, MAC2STR(addr));
2411         return 0;
2412 }
2413
2414
2415 static int wpa_driver_test_set_ssid(void *priv, const u8 *ssid,
2416                                     size_t ssid_len)
2417 {
2418         wpa_printf(MSG_DEBUG, "%s", __func__);
2419         return 0;
2420 }
2421
2422
2423 static int wpa_driver_test_set_bssid(void *priv, const u8 *bssid)
2424 {
2425         wpa_printf(MSG_DEBUG, "%s: bssid=" MACSTR, __func__, MAC2STR(bssid));
2426         return 0;
2427 }
2428
2429
2430 static void * wpa_driver_test_global_init(void)
2431 {
2432         struct wpa_driver_test_global *global;
2433
2434         global = os_zalloc(sizeof(*global));
2435         return global;
2436 }
2437
2438
2439 static void wpa_driver_test_global_deinit(void *priv)
2440 {
2441         struct wpa_driver_test_global *global = priv;
2442         os_free(global);
2443 }
2444
2445
2446 static struct wpa_interface_info *
2447 wpa_driver_test_get_interfaces(void *global_priv)
2448 {
2449         /* struct wpa_driver_test_global *global = priv; */
2450         struct wpa_interface_info *iface;
2451
2452         iface = os_zalloc(sizeof(*iface));
2453         if (iface == NULL)
2454                 return iface;
2455         iface->ifname = os_strdup("sta0");
2456         iface->desc = os_strdup("test interface 0");
2457         iface->drv_name = "test";
2458         iface->next = os_zalloc(sizeof(*iface));
2459         if (iface->next) {
2460                 iface->next->ifname = os_strdup("sta1");
2461                 iface->next->desc = os_strdup("test interface 1");
2462                 iface->next->drv_name = "test";
2463         }
2464
2465         return iface;
2466 }
2467
2468
2469 static struct hostapd_hw_modes *
2470 wpa_driver_test_get_hw_feature_data(void *priv, u16 *num_modes, u16 *flags)
2471 {
2472         struct hostapd_hw_modes *modes;
2473         size_t i;
2474
2475         *num_modes = 3;
2476         *flags = 0;
2477         modes = os_zalloc(*num_modes * sizeof(struct hostapd_hw_modes));
2478         if (modes == NULL)
2479                 return NULL;
2480         modes[0].mode = HOSTAPD_MODE_IEEE80211G;
2481         modes[0].num_channels = 11;
2482         modes[0].num_rates = 12;
2483         modes[0].channels =
2484                 os_zalloc(11 * sizeof(struct hostapd_channel_data));
2485         modes[0].rates = os_zalloc(modes[0].num_rates * sizeof(int));
2486         if (modes[0].channels == NULL || modes[0].rates == NULL)
2487                 goto fail;
2488         for (i = 0; i < 11; i++) {
2489                 modes[0].channels[i].chan = i + 1;
2490                 modes[0].channels[i].freq = 2412 + 5 * i;
2491                 modes[0].channels[i].flag = 0;
2492         }
2493         modes[0].rates[0] = 10;
2494         modes[0].rates[1] = 20;
2495         modes[0].rates[2] = 55;
2496         modes[0].rates[3] = 110;
2497         modes[0].rates[4] = 60;
2498         modes[0].rates[5] = 90;
2499         modes[0].rates[6] = 120;
2500         modes[0].rates[7] = 180;
2501         modes[0].rates[8] = 240;
2502         modes[0].rates[9] = 360;
2503         modes[0].rates[10] = 480;
2504         modes[0].rates[11] = 540;
2505
2506         modes[1].mode = HOSTAPD_MODE_IEEE80211B;
2507         modes[1].num_channels = 11;
2508         modes[1].num_rates = 4;
2509         modes[1].channels =
2510                 os_zalloc(11 * sizeof(struct hostapd_channel_data));
2511         modes[1].rates = os_zalloc(modes[1].num_rates * sizeof(int));
2512         if (modes[1].channels == NULL || modes[1].rates == NULL)
2513                 goto fail;
2514         for (i = 0; i < 11; i++) {
2515                 modes[1].channels[i].chan = i + 1;
2516                 modes[1].channels[i].freq = 2412 + 5 * i;
2517                 modes[1].channels[i].flag = 0;
2518         }
2519         modes[1].rates[0] = 10;
2520         modes[1].rates[1] = 20;
2521         modes[1].rates[2] = 55;
2522         modes[1].rates[3] = 110;
2523
2524         modes[2].mode = HOSTAPD_MODE_IEEE80211A;
2525         modes[2].num_channels = 1;
2526         modes[2].num_rates = 8;
2527         modes[2].channels = os_zalloc(sizeof(struct hostapd_channel_data));
2528         modes[2].rates = os_zalloc(modes[2].num_rates * sizeof(int));
2529         if (modes[2].channels == NULL || modes[2].rates == NULL)
2530                 goto fail;
2531         modes[2].channels[0].chan = 60;
2532         modes[2].channels[0].freq = 5300;
2533         modes[2].channels[0].flag = 0;
2534         modes[2].rates[0] = 60;
2535         modes[2].rates[1] = 90;
2536         modes[2].rates[2] = 120;
2537         modes[2].rates[3] = 180;
2538         modes[2].rates[4] = 240;
2539         modes[2].rates[5] = 360;
2540         modes[2].rates[6] = 480;
2541         modes[2].rates[7] = 540;
2542
2543         return modes;
2544
2545 fail:
2546         if (modes) {
2547                 for (i = 0; i < *num_modes; i++) {
2548                         os_free(modes[i].channels);
2549                         os_free(modes[i].rates);
2550                 }
2551                 os_free(modes);
2552         }
2553         return NULL;
2554 }
2555
2556
2557 static int wpa_driver_test_set_freq(void *priv,
2558                                     struct hostapd_freq_params *freq)
2559 {
2560         struct wpa_driver_test_data *drv = priv;
2561         wpa_printf(MSG_DEBUG, "test: set_freq %u MHz", freq->freq);
2562         drv->current_freq = freq->freq;
2563         return 0;
2564 }
2565
2566
2567 static int wpa_driver_test_send_action(void *priv, unsigned int freq,
2568                                        const u8 *dst, const u8 *src,
2569                                        const u8 *bssid,
2570                                        const u8 *data, size_t data_len)
2571 {
2572         struct wpa_driver_test_data *drv = priv;
2573         int ret = -1;
2574         u8 *buf;
2575         struct ieee80211_hdr *hdr;
2576
2577         wpa_printf(MSG_DEBUG, "test: Send Action frame");
2578
2579         if ((drv->remain_on_channel_freq &&
2580              freq != drv->remain_on_channel_freq) ||
2581             (drv->remain_on_channel_freq == 0 &&
2582              freq != (unsigned int) drv->current_freq)) {
2583                 wpa_printf(MSG_DEBUG, "test: Reject Action frame TX on "
2584                            "unexpected channel: freq=%u MHz (current_freq=%u "
2585                            "MHz, remain-on-channel freq=%u MHz)",
2586                            freq, drv->current_freq,
2587                            drv->remain_on_channel_freq);
2588                 return -1;
2589         }
2590
2591         buf = os_zalloc(24 + data_len);
2592         if (buf == NULL)
2593                 return ret;
2594         os_memcpy(buf + 24, data, data_len);
2595         hdr = (struct ieee80211_hdr *) buf;
2596         hdr->frame_control =
2597                 IEEE80211_FC(WLAN_FC_TYPE_MGMT, WLAN_FC_STYPE_ACTION);
2598         os_memcpy(hdr->addr1, dst, ETH_ALEN);
2599         os_memcpy(hdr->addr2, src, ETH_ALEN);
2600         os_memcpy(hdr->addr3, bssid, ETH_ALEN);
2601
2602         ret = wpa_driver_test_send_mlme(priv, buf, 24 + data_len);
2603         os_free(buf);
2604         return ret;
2605 }
2606
2607
2608 static int wpa_driver_test_alloc_interface_addr(void *priv, u8 *addr)
2609 {
2610         struct wpa_driver_test_data *drv = priv;
2611         drv->alloc_iface_idx++;
2612         addr[0] = 0x02; /* locally administered */
2613         sha1_prf(drv->own_addr, ETH_ALEN, "hostapd test addr generation",
2614                  (const u8 *) &drv->alloc_iface_idx,
2615                  sizeof(drv->alloc_iface_idx),
2616                  addr + 1, ETH_ALEN - 1);
2617         return 0;
2618 }
2619
2620
2621 static void wpa_driver_test_release_interface_addr(void *priv, const u8 *addr)
2622 {
2623 }
2624
2625
2626 static void test_remain_on_channel_timeout(void *eloop_ctx, void *timeout_ctx)
2627 {
2628         struct wpa_driver_test_data *drv = eloop_ctx;
2629         union wpa_event_data data;
2630
2631         wpa_printf(MSG_DEBUG, "test: Remain-on-channel timeout");
2632
2633         os_memset(&data, 0, sizeof(data));
2634         data.remain_on_channel.freq = drv->remain_on_channel_freq;
2635         data.remain_on_channel.duration = drv->remain_on_channel_duration;
2636         wpa_supplicant_event(drv->ctx, EVENT_CANCEL_REMAIN_ON_CHANNEL, &data);
2637
2638         drv->remain_on_channel_freq = 0;
2639 }
2640
2641
2642 static int wpa_driver_test_remain_on_channel(void *priv, unsigned int freq,
2643                                              unsigned int duration)
2644 {
2645         struct wpa_driver_test_data *drv = priv;
2646         union wpa_event_data data;
2647
2648         wpa_printf(MSG_DEBUG, "%s(freq=%u, duration=%u)",
2649                    __func__, freq, duration);
2650         if (drv->remain_on_channel_freq &&
2651             drv->remain_on_channel_freq != freq) {
2652                 wpa_printf(MSG_DEBUG, "test: Refuse concurrent "
2653                            "remain_on_channel request");
2654                 return -1;
2655         }
2656
2657         drv->remain_on_channel_freq = freq;
2658         drv->remain_on_channel_duration = duration;
2659         eloop_cancel_timeout(test_remain_on_channel_timeout, drv, NULL);
2660         eloop_register_timeout(duration / 1000, (duration % 1000) * 1000,
2661                                test_remain_on_channel_timeout, drv, NULL);
2662
2663         os_memset(&data, 0, sizeof(data));
2664         data.remain_on_channel.freq = freq;
2665         data.remain_on_channel.duration = duration;
2666         wpa_supplicant_event(drv->ctx, EVENT_REMAIN_ON_CHANNEL, &data);
2667
2668         return 0;
2669 }
2670
2671
2672 static int wpa_driver_test_cancel_remain_on_channel(void *priv)
2673 {
2674         struct wpa_driver_test_data *drv = priv;
2675         wpa_printf(MSG_DEBUG, "%s", __func__);
2676         if (!drv->remain_on_channel_freq)
2677                 return -1;
2678         drv->remain_on_channel_freq = 0;
2679         eloop_cancel_timeout(test_remain_on_channel_timeout, drv, NULL);
2680         return 0;
2681 }
2682
2683
2684 static int wpa_driver_test_probe_req_report(void *priv, int report)
2685 {
2686         struct wpa_driver_test_data *drv = priv;
2687         wpa_printf(MSG_DEBUG, "%s(report=%d)", __func__, report);
2688         drv->probe_req_report = report;
2689         return 0;
2690 }
2691
2692
2693 const struct wpa_driver_ops wpa_driver_test_ops = {
2694         "test",
2695         "wpa_supplicant test driver",
2696         .hapd_init = test_driver_init,
2697         .hapd_deinit = wpa_driver_test_deinit,
2698         .hapd_send_eapol = test_driver_send_eapol,
2699         .send_mlme = wpa_driver_test_send_mlme,
2700         .set_generic_elem = test_driver_set_generic_elem,
2701         .sta_deauth = test_driver_sta_deauth,
2702         .sta_disassoc = test_driver_sta_disassoc,
2703         .get_hw_feature_data = wpa_driver_test_get_hw_feature_data,
2704         .if_add = test_driver_if_add,
2705         .if_remove = test_driver_if_remove,
2706         .valid_bss_mask = test_driver_valid_bss_mask,
2707         .hapd_set_ssid = test_driver_set_ssid,
2708         .set_privacy = test_driver_set_privacy,
2709         .set_sta_vlan = test_driver_set_sta_vlan,
2710         .sta_add = test_driver_sta_add,
2711         .send_ether = test_driver_send_ether,
2712         .set_ap_wps_ie = test_driver_set_ap_wps_ie,
2713         .get_bssid = wpa_driver_test_get_bssid,
2714         .get_ssid = wpa_driver_test_get_ssid,
2715         .set_key = wpa_driver_test_set_key,
2716         .deinit = wpa_driver_test_deinit,
2717         .set_param = wpa_driver_test_set_param,
2718         .deauthenticate = wpa_driver_test_deauthenticate,
2719         .disassociate = wpa_driver_test_disassociate,
2720         .associate = wpa_driver_test_associate,
2721         .get_capa = wpa_driver_test_get_capa,
2722         .get_mac_addr = wpa_driver_test_get_mac_addr,
2723         .send_eapol = wpa_driver_test_send_eapol,
2724         .mlme_setprotection = wpa_driver_test_mlme_setprotection,
2725         .set_channel = wpa_driver_test_set_channel,
2726         .set_ssid = wpa_driver_test_set_ssid,
2727         .set_bssid = wpa_driver_test_set_bssid,
2728         .mlme_add_sta = wpa_driver_test_mlme_add_sta,
2729         .mlme_remove_sta = wpa_driver_test_mlme_remove_sta,
2730         .get_scan_results2 = wpa_driver_test_get_scan_results2,
2731         .global_init = wpa_driver_test_global_init,
2732         .global_deinit = wpa_driver_test_global_deinit,
2733         .init2 = wpa_driver_test_init2,
2734         .get_interfaces = wpa_driver_test_get_interfaces,
2735         .scan2 = wpa_driver_test_scan,
2736         .set_freq = wpa_driver_test_set_freq,
2737         .send_action = wpa_driver_test_send_action,
2738         .alloc_interface_addr = wpa_driver_test_alloc_interface_addr,
2739         .release_interface_addr = wpa_driver_test_release_interface_addr,
2740         .remain_on_channel = wpa_driver_test_remain_on_channel,
2741         .cancel_remain_on_channel = wpa_driver_test_cancel_remain_on_channel,
2742         .probe_req_report = wpa_driver_test_probe_req_report,
2743 };