Use generic driver event notification for AP mode assoc/disassoc
[libeap.git] / src / drivers / driver_atheros.c
1 /*
2  * hostapd / Driver interaction with Atheros driver
3  * Copyright (c) 2004, Sam Leffler <sam@errno.com>
4  * Copyright (c) 2004, Video54 Technologies
5  * Copyright (c) 2005-2007, Jouni Malinen <j@w1.fi>
6  * Copyright (c) 2009, Atheros Communications
7  *
8  * This program is free software; you can redistribute it and/or modify
9  * it under the terms of the GNU General Public License version 2 as
10  * published by the Free Software Foundation.
11  *
12  * Alternatively, this software may be distributed under the terms of BSD
13  * license.
14  *
15  * See README and COPYING for more details.
16  */
17
18 #include "includes.h"
19 #include <net/if.h>
20 #include <sys/ioctl.h>
21
22 #include "common.h"
23 #ifndef _BYTE_ORDER
24 #ifdef WORDS_BIGENDIAN
25 #define _BYTE_ORDER _BIG_ENDIAN
26 #else
27 #define _BYTE_ORDER _LITTLE_ENDIAN
28 #endif
29 #endif /* _BYTE_ORDER */
30
31 #include <net80211/ieee80211.h>
32 #include <net80211/_ieee80211.h>
33 #include <net80211/ieee80211_crypto.h>
34
35 /*
36  * Note, the ATH_WPS_IE setting must match with the driver build.. If the
37  * driver does not include this, the IEEE80211_IOCTL_GETWPAIE ioctl will fail.
38  */
39 #define ATH_WPS_IE
40 #include <net80211/ieee80211_ioctl.h>
41
42 #ifdef CONFIG_WPS
43 #ifdef IEEE80211_IOCTL_FILTERFRAME
44 #include <netpacket/packet.h>
45
46 #ifndef ETH_P_80211_RAW
47 #define ETH_P_80211_RAW 0x0019
48 #endif
49 #endif /* IEEE80211_IOCTL_FILTERFRAME */
50 #endif /* CONFIG_WPS */
51
52 /*
53  * Avoid conflicts with hostapd definitions by undefining couple of defines
54  * from madwifi header files.
55  */
56 #undef WPA_OUI_TYPE
57 #undef WME_OUI_TYPE
58
59 #include "wireless_copy.h"
60
61 #include "driver.h"
62 #include "eloop.h"
63 #include "priv_netlink.h"
64 #include "l2_packet/l2_packet.h"
65 #include "common/ieee802_11_defs.h"
66 #include "netlink.h"
67
68
69 struct madwifi_driver_data {
70         struct hostapd_data *hapd;              /* back pointer */
71
72         char    iface[IFNAMSIZ + 1];
73         int     ifindex;
74         struct l2_packet_data *sock_xmit;       /* raw packet xmit socket */
75         struct l2_packet_data *sock_recv;       /* raw packet recv socket */
76         int     ioctl_sock;                     /* socket for ioctl() use */
77         struct netlink_data *netlink;
78         int     we_version;
79         u8      acct_mac[ETH_ALEN];
80         struct hostap_sta_driver_data acct_data;
81
82         struct l2_packet_data *sock_raw; /* raw 802.11 management frames */
83 };
84
85 static int madwifi_sta_deauth(void *priv, const u8 *own_addr, const u8 *addr,
86                               int reason_code);
87
88 static int
89 set80211priv(struct madwifi_driver_data *drv, int op, void *data, int len)
90 {
91         struct iwreq iwr;
92         int do_inline = len < IFNAMSIZ;
93
94         /* Certain ioctls must use the non-inlined method */
95         if (op == IEEE80211_IOCTL_SET_APPIEBUF ||
96             op == IEEE80211_IOCTL_FILTERFRAME)
97                 do_inline = 0;
98
99         memset(&iwr, 0, sizeof(iwr));
100         os_strlcpy(iwr.ifr_name, drv->iface, IFNAMSIZ);
101         if (do_inline) {
102                 /*
103                  * Argument data fits inline; put it there.
104                  */
105                 memcpy(iwr.u.name, data, len);
106         } else {
107                 /*
108                  * Argument data too big for inline transfer; setup a
109                  * parameter block instead; the kernel will transfer
110                  * the data for the driver.
111                  */
112                 iwr.u.data.pointer = data;
113                 iwr.u.data.length = len;
114         }
115
116         if (ioctl(drv->ioctl_sock, op, &iwr) < 0) {
117                 int first = IEEE80211_IOCTL_SETPARAM;
118                 static const char *opnames[] = {
119                         "ioctl[IEEE80211_IOCTL_SETPARAM]",
120                         "ioctl[IEEE80211_IOCTL_GETPARAM]",
121                         "ioctl[IEEE80211_IOCTL_SETKEY]",
122                         "ioctl[IEEE80211_IOCTL_SETWMMPARAMS]",
123                         "ioctl[IEEE80211_IOCTL_DELKEY]",
124                         "ioctl[IEEE80211_IOCTL_GETWMMPARAMS]",
125                         "ioctl[IEEE80211_IOCTL_SETMLME]",
126                         "ioctl[IEEE80211_IOCTL_GETCHANINFO]",
127                         "ioctl[IEEE80211_IOCTL_SETOPTIE]",
128                         "ioctl[IEEE80211_IOCTL_GETOPTIE]",
129                         "ioctl[IEEE80211_IOCTL_ADDMAC]",
130                         "ioctl[IEEE80211_IOCTL_DELMAC]",
131                         "ioctl[IEEE80211_IOCTL_GETCHANLIST]",
132                         "ioctl[IEEE80211_IOCTL_SETCHANLIST]",
133                         "ioctl[IEEE80211_IOCTL_KICKMAC]",
134                         "ioctl[IEEE80211_IOCTL_CHANSWITCH]",
135                         "ioctl[IEEE80211_IOCTL_GETMODE]",
136                         "ioctl[IEEE80211_IOCTL_SETMODE]",
137                         "ioctl[IEEE80211_IOCTL_GET_APPIEBUF]",
138                         "ioctl[IEEE80211_IOCTL_SET_APPIEBUF]",
139                         NULL,
140                         "ioctl[IEEE80211_IOCTL_FILTERFRAME]",
141                 };
142                 int idx = op - first;
143                 if (first <= op &&
144                     idx < (int) (sizeof(opnames) / sizeof(opnames[0])) &&
145                     opnames[idx])
146                         perror(opnames[idx]);
147                 else {
148                         perror("ioctl[unknown???]");
149                         wpa_printf(MSG_DEBUG, "Failed ioctl: 0x%x", op);
150                 }
151                 return -1;
152         }
153         return 0;
154 }
155
156 static int
157 set80211param(struct madwifi_driver_data *drv, int op, int arg)
158 {
159         struct iwreq iwr;
160
161         memset(&iwr, 0, sizeof(iwr));
162         os_strlcpy(iwr.ifr_name, drv->iface, IFNAMSIZ);
163         iwr.u.mode = op;
164         memcpy(iwr.u.name+sizeof(__u32), &arg, sizeof(arg));
165
166         if (ioctl(drv->ioctl_sock, IEEE80211_IOCTL_SETPARAM, &iwr) < 0) {
167                 perror("ioctl[IEEE80211_IOCTL_SETPARAM]");
168                 wpa_printf(MSG_DEBUG, "%s: Failed to set parameter (op %d "
169                            "arg %d)", __func__, op, arg);
170                 return -1;
171         }
172         return 0;
173 }
174
175 #ifndef CONFIG_NO_STDOUT_DEBUG
176 static const char *
177 ether_sprintf(const u8 *addr)
178 {
179         static char buf[sizeof(MACSTR)];
180
181         if (addr != NULL)
182                 snprintf(buf, sizeof(buf), MACSTR, MAC2STR(addr));
183         else
184                 snprintf(buf, sizeof(buf), MACSTR, 0,0,0,0,0,0);
185         return buf;
186 }
187 #endif /* CONFIG_NO_STDOUT_DEBUG */
188
189 /*
190  * Configure WPA parameters.
191  */
192 static int
193 madwifi_configure_wpa(struct madwifi_driver_data *drv,
194                       struct wpa_bss_params *params)
195 {
196         int v;
197
198         switch (params->wpa_group) {
199         case WPA_CIPHER_CCMP:
200                 v = IEEE80211_CIPHER_AES_CCM;
201                 break;
202         case WPA_CIPHER_TKIP:
203                 v = IEEE80211_CIPHER_TKIP;
204                 break;
205         case WPA_CIPHER_WEP104:
206                 v = IEEE80211_CIPHER_WEP;
207                 break;
208         case WPA_CIPHER_WEP40:
209                 v = IEEE80211_CIPHER_WEP;
210                 break;
211         case WPA_CIPHER_NONE:
212                 v = IEEE80211_CIPHER_NONE;
213                 break;
214         default:
215                 wpa_printf(MSG_ERROR, "Unknown group key cipher %u",
216                            params->wpa_group);
217                 return -1;
218         }
219         wpa_printf(MSG_DEBUG, "%s: group key cipher=%d", __func__, v);
220         if (set80211param(drv, IEEE80211_PARAM_MCASTCIPHER, v)) {
221                 printf("Unable to set group key cipher to %u\n", v);
222                 return -1;
223         }
224         if (v == IEEE80211_CIPHER_WEP) {
225                 /* key length is done only for specific ciphers */
226                 v = (params->wpa_group == WPA_CIPHER_WEP104 ? 13 : 5);
227                 if (set80211param(drv, IEEE80211_PARAM_MCASTKEYLEN, v)) {
228                         printf("Unable to set group key length to %u\n", v);
229                         return -1;
230                 }
231         }
232
233         v = 0;
234         if (params->wpa_pairwise & WPA_CIPHER_CCMP)
235                 v |= 1<<IEEE80211_CIPHER_AES_CCM;
236         if (params->wpa_pairwise & WPA_CIPHER_TKIP)
237                 v |= 1<<IEEE80211_CIPHER_TKIP;
238         if (params->wpa_pairwise & WPA_CIPHER_NONE)
239                 v |= 1<<IEEE80211_CIPHER_NONE;
240         wpa_printf(MSG_DEBUG, "%s: pairwise key ciphers=0x%x", __func__, v);
241         if (set80211param(drv, IEEE80211_PARAM_UCASTCIPHERS, v)) {
242                 printf("Unable to set pairwise key ciphers to 0x%x\n", v);
243                 return -1;
244         }
245
246         wpa_printf(MSG_DEBUG, "%s: key management algorithms=0x%x",
247                    __func__, params->wpa_key_mgmt);
248         if (set80211param(drv, IEEE80211_PARAM_KEYMGTALGS,
249                           params->wpa_key_mgmt)) {
250                 printf("Unable to set key management algorithms to 0x%x\n",
251                         params->wpa_key_mgmt);
252                 return -1;
253         }
254
255         v = 0;
256         if (params->rsn_preauth)
257                 v |= BIT(0);
258         wpa_printf(MSG_DEBUG, "%s: rsn capabilities=0x%x",
259                    __func__, params->rsn_preauth);
260         if (set80211param(drv, IEEE80211_PARAM_RSNCAPS, v)) {
261                 printf("Unable to set RSN capabilities to 0x%x\n", v);
262                 return -1;
263         }
264
265         wpa_printf(MSG_DEBUG, "%s: enable WPA=0x%x", __func__, params->wpa);
266         if (set80211param(drv, IEEE80211_PARAM_WPA, params->wpa)) {
267                 printf("Unable to set WPA to %u\n", params->wpa);
268                 return -1;
269         }
270         return 0;
271 }
272
273
274 static int
275 madwifi_set_iface_flags(void *priv, int dev_up)
276 {
277         struct madwifi_driver_data *drv = priv;
278         struct ifreq ifr;
279
280         wpa_printf(MSG_DEBUG, "%s: dev_up=%d", __func__, dev_up);
281
282         if (drv->ioctl_sock < 0)
283                 return -1;
284
285         memset(&ifr, 0, sizeof(ifr));
286         os_strlcpy(ifr.ifr_name, drv->iface, IFNAMSIZ);
287
288         if (ioctl(drv->ioctl_sock, SIOCGIFFLAGS, &ifr) != 0) {
289                 perror("ioctl[SIOCGIFFLAGS]");
290                 return -1;
291         }
292
293         if (dev_up)
294                 ifr.ifr_flags |= IFF_UP;
295         else
296                 ifr.ifr_flags &= ~IFF_UP;
297
298         if (ioctl(drv->ioctl_sock, SIOCSIFFLAGS, &ifr) != 0) {
299                 perror("ioctl[SIOCSIFFLAGS]");
300                 return -1;
301         }
302
303         return 0;
304 }
305
306 static int
307 madwifi_set_ieee8021x(void *priv, struct wpa_bss_params *params)
308 {
309         struct madwifi_driver_data *drv = priv;
310
311         wpa_printf(MSG_DEBUG, "%s: enabled=%d", __func__, params->enabled);
312
313         if (!params->enabled) {
314                 /* XXX restore state */
315                 return set80211param(priv, IEEE80211_PARAM_AUTHMODE,
316                         IEEE80211_AUTH_AUTO);
317         }
318         if (!params->wpa && !params->ieee802_1x) {
319                 hostapd_logger(drv->hapd, NULL, HOSTAPD_MODULE_DRIVER,
320                         HOSTAPD_LEVEL_WARNING, "No 802.1X or WPA enabled!");
321                 return -1;
322         }
323         if (params->wpa && madwifi_configure_wpa(drv, params) != 0) {
324                 hostapd_logger(drv->hapd, NULL, HOSTAPD_MODULE_DRIVER,
325                         HOSTAPD_LEVEL_WARNING, "Error configuring WPA state!");
326                 return -1;
327         }
328         if (set80211param(priv, IEEE80211_PARAM_AUTHMODE,
329                 (params->wpa ? IEEE80211_AUTH_WPA : IEEE80211_AUTH_8021X))) {
330                 hostapd_logger(drv->hapd, NULL, HOSTAPD_MODULE_DRIVER,
331                         HOSTAPD_LEVEL_WARNING, "Error enabling WPA/802.1X!");
332                 return -1;
333         }
334
335         return 0;
336 }
337
338 static int
339 madwifi_set_privacy(const char *ifname, void *priv, int enabled)
340 {
341         struct madwifi_driver_data *drv = priv;
342
343         wpa_printf(MSG_DEBUG, "%s: enabled=%d", __func__, enabled);
344
345         return set80211param(drv, IEEE80211_PARAM_PRIVACY, enabled);
346 }
347
348 static int
349 madwifi_set_sta_authorized(void *priv, const u8 *addr, int authorized)
350 {
351         struct madwifi_driver_data *drv = priv;
352         struct ieee80211req_mlme mlme;
353         int ret;
354
355         wpa_printf(MSG_DEBUG, "%s: addr=%s authorized=%d",
356                    __func__, ether_sprintf(addr), authorized);
357
358         if (authorized)
359                 mlme.im_op = IEEE80211_MLME_AUTHORIZE;
360         else
361                 mlme.im_op = IEEE80211_MLME_UNAUTHORIZE;
362         mlme.im_reason = 0;
363         memcpy(mlme.im_macaddr, addr, IEEE80211_ADDR_LEN);
364         ret = set80211priv(drv, IEEE80211_IOCTL_SETMLME, &mlme, sizeof(mlme));
365         if (ret < 0) {
366                 wpa_printf(MSG_DEBUG, "%s: Failed to %sauthorize STA " MACSTR,
367                            __func__, authorized ? "" : "un", MAC2STR(addr));
368         }
369
370         return ret;
371 }
372
373 static int
374 madwifi_sta_set_flags(void *priv, const u8 *addr, int total_flags,
375                       int flags_or, int flags_and)
376 {
377         /* For now, only support setting Authorized flag */
378         if (flags_or & WPA_STA_AUTHORIZED)
379                 return madwifi_set_sta_authorized(priv, addr, 1);
380         if (!(flags_and & WPA_STA_AUTHORIZED))
381                 return madwifi_set_sta_authorized(priv, addr, 0);
382         return 0;
383 }
384
385 static int
386 madwifi_del_key(void *priv, const u8 *addr, int key_idx)
387 {
388         struct madwifi_driver_data *drv = priv;
389         struct ieee80211req_del_key wk;
390         int ret;
391
392         wpa_printf(MSG_DEBUG, "%s: addr=%s key_idx=%d",
393                    __func__, ether_sprintf(addr), key_idx);
394
395         memset(&wk, 0, sizeof(wk));
396         if (addr != NULL) {
397                 memcpy(wk.idk_macaddr, addr, IEEE80211_ADDR_LEN);
398                 wk.idk_keyix = (u8) IEEE80211_KEYIX_NONE;
399         } else {
400                 wk.idk_keyix = key_idx;
401         }
402
403         ret = set80211priv(drv, IEEE80211_IOCTL_DELKEY, &wk, sizeof(wk));
404         if (ret < 0) {
405                 wpa_printf(MSG_DEBUG, "%s: Failed to delete key (addr %s"
406                            " key_idx %d)", __func__, ether_sprintf(addr),
407                            key_idx);
408         }
409
410         return ret;
411 }
412
413 static int
414 madwifi_set_key(const char *ifname, void *priv, enum wpa_alg alg,
415                 const u8 *addr, int key_idx, int set_tx, const u8 *seq,
416                 size_t seq_len, const u8 *key, size_t key_len)
417 {
418         struct madwifi_driver_data *drv = priv;
419         struct ieee80211req_key wk;
420         u_int8_t cipher;
421         int ret;
422
423         if (alg == WPA_ALG_NONE)
424                 return madwifi_del_key(drv, addr, key_idx);
425
426         wpa_printf(MSG_DEBUG, "%s: alg=%d addr=%s key_idx=%d",
427                    __func__, alg, ether_sprintf(addr), key_idx);
428
429         switch (alg) {
430         case WPA_ALG_WEP:
431                 cipher = IEEE80211_CIPHER_WEP;
432                 break;
433         case WPA_ALG_TKIP:
434                 cipher = IEEE80211_CIPHER_TKIP;
435                 break;
436         case WPA_ALG_CCMP:
437                 cipher = IEEE80211_CIPHER_AES_CCM;
438                 break;
439         default:
440                 printf("%s: unknown/unsupported algorithm %d\n",
441                         __func__, alg);
442                 return -1;
443         }
444
445         if (key_len > sizeof(wk.ik_keydata)) {
446                 printf("%s: key length %lu too big\n", __func__,
447                        (unsigned long) key_len);
448                 return -3;
449         }
450
451         memset(&wk, 0, sizeof(wk));
452         wk.ik_type = cipher;
453         wk.ik_flags = IEEE80211_KEY_RECV | IEEE80211_KEY_XMIT;
454         if (addr == NULL) {
455                 memset(wk.ik_macaddr, 0xff, IEEE80211_ADDR_LEN);
456                 wk.ik_keyix = key_idx;
457                 wk.ik_flags |= IEEE80211_KEY_DEFAULT;
458         } else {
459                 memcpy(wk.ik_macaddr, addr, IEEE80211_ADDR_LEN);
460                 wk.ik_keyix = IEEE80211_KEYIX_NONE;
461         }
462         wk.ik_keylen = key_len;
463         memcpy(wk.ik_keydata, key, key_len);
464
465         ret = set80211priv(drv, IEEE80211_IOCTL_SETKEY, &wk, sizeof(wk));
466         if (ret < 0) {
467                 wpa_printf(MSG_DEBUG, "%s: Failed to set key (addr %s"
468                            " key_idx %d alg %d key_len %lu set_tx %d)",
469                            __func__, ether_sprintf(wk.ik_macaddr), key_idx,
470                            alg, (unsigned long) key_len, set_tx);
471         }
472
473         return ret;
474 }
475
476
477 static int
478 madwifi_get_seqnum(const char *ifname, void *priv, const u8 *addr, int idx,
479                    u8 *seq)
480 {
481         struct madwifi_driver_data *drv = priv;
482         struct ieee80211req_key wk;
483
484         wpa_printf(MSG_DEBUG, "%s: addr=%s idx=%d",
485                    __func__, ether_sprintf(addr), idx);
486
487         memset(&wk, 0, sizeof(wk));
488         if (addr == NULL)
489                 memset(wk.ik_macaddr, 0xff, IEEE80211_ADDR_LEN);
490         else
491                 memcpy(wk.ik_macaddr, addr, IEEE80211_ADDR_LEN);
492         wk.ik_keyix = idx;
493
494         if (set80211priv(drv, IEEE80211_IOCTL_GETKEY, &wk, sizeof(wk))) {
495                 wpa_printf(MSG_DEBUG, "%s: Failed to get encryption data "
496                            "(addr " MACSTR " key_idx %d)",
497                            __func__, MAC2STR(wk.ik_macaddr), idx);
498                 return -1;
499         }
500
501 #ifdef WORDS_BIGENDIAN
502         {
503                 /*
504                  * wk.ik_keytsc is in host byte order (big endian), need to
505                  * swap it to match with the byte order used in WPA.
506                  */
507                 int i;
508                 u8 tmp[WPA_KEY_RSC_LEN];
509                 memcpy(tmp, &wk.ik_keytsc, sizeof(wk.ik_keytsc));
510                 for (i = 0; i < WPA_KEY_RSC_LEN; i++) {
511                         seq[i] = tmp[WPA_KEY_RSC_LEN - i - 1];
512                 }
513         }
514 #else /* WORDS_BIGENDIAN */
515         memcpy(seq, &wk.ik_keytsc, sizeof(wk.ik_keytsc));
516 #endif /* WORDS_BIGENDIAN */
517         return 0;
518 }
519
520
521 static int
522 madwifi_flush(void *priv)
523 {
524         u8 allsta[IEEE80211_ADDR_LEN];
525         memset(allsta, 0xff, IEEE80211_ADDR_LEN);
526         return madwifi_sta_deauth(priv, NULL, allsta,
527                                   IEEE80211_REASON_AUTH_LEAVE);
528 }
529
530
531 static int
532 madwifi_read_sta_driver_data(void *priv, struct hostap_sta_driver_data *data,
533                              const u8 *addr)
534 {
535         struct madwifi_driver_data *drv = priv;
536         struct ieee80211req_sta_stats stats;
537
538         memset(data, 0, sizeof(*data));
539
540         /*
541          * Fetch statistics for station from the system.
542          */
543         memset(&stats, 0, sizeof(stats));
544         memcpy(stats.is_u.macaddr, addr, IEEE80211_ADDR_LEN);
545         if (set80211priv(drv, IEEE80211_IOCTL_STA_STATS,
546                          &stats, sizeof(stats))) {
547                 wpa_printf(MSG_DEBUG, "%s: Failed to fetch STA stats (addr "
548                            MACSTR ")", __func__, MAC2STR(addr));
549                 if (memcmp(addr, drv->acct_mac, ETH_ALEN) == 0) {
550                         memcpy(data, &drv->acct_data, sizeof(*data));
551                         return 0;
552                 }
553
554                 printf("Failed to get station stats information element.\n");
555                 return -1;
556         }
557
558         data->rx_packets = stats.is_stats.ns_rx_data;
559         data->rx_bytes = stats.is_stats.ns_rx_bytes;
560         data->tx_packets = stats.is_stats.ns_tx_data;
561         data->tx_bytes = stats.is_stats.ns_tx_bytes;
562         return 0;
563 }
564
565
566 static int
567 madwifi_sta_clear_stats(void *priv, const u8 *addr)
568 {
569         struct madwifi_driver_data *drv = priv;
570         struct ieee80211req_mlme mlme;
571         int ret;
572
573         wpa_printf(MSG_DEBUG, "%s: addr=%s", __func__, ether_sprintf(addr));
574
575         mlme.im_op = IEEE80211_MLME_CLEAR_STATS;
576         memcpy(mlme.im_macaddr, addr, IEEE80211_ADDR_LEN);
577         ret = set80211priv(drv, IEEE80211_IOCTL_SETMLME, &mlme,
578                            sizeof(mlme));
579         if (ret < 0) {
580                 wpa_printf(MSG_DEBUG, "%s: Failed to clear STA stats (addr "
581                            MACSTR ")", __func__, MAC2STR(addr));
582         }
583
584         return ret;
585 }
586
587
588 static int
589 madwifi_set_opt_ie(const char *ifname, void *priv, const u8 *ie, size_t ie_len)
590 {
591         /*
592          * Do nothing; we setup parameters at startup that define the
593          * contents of the beacon information element.
594          */
595         return 0;
596 }
597
598 static int
599 madwifi_sta_deauth(void *priv, const u8 *own_addr, const u8 *addr,
600                    int reason_code)
601 {
602         struct madwifi_driver_data *drv = priv;
603         struct ieee80211req_mlme mlme;
604         int ret;
605
606         wpa_printf(MSG_DEBUG, "%s: addr=%s reason_code=%d",
607                    __func__, ether_sprintf(addr), reason_code);
608
609         mlme.im_op = IEEE80211_MLME_DEAUTH;
610         mlme.im_reason = reason_code;
611         memcpy(mlme.im_macaddr, addr, IEEE80211_ADDR_LEN);
612         ret = set80211priv(drv, IEEE80211_IOCTL_SETMLME, &mlme, sizeof(mlme));
613         if (ret < 0) {
614                 wpa_printf(MSG_DEBUG, "%s: Failed to deauth STA (addr " MACSTR
615                            " reason %d)",
616                            __func__, MAC2STR(addr), reason_code);
617         }
618
619         return ret;
620 }
621
622 static int
623 madwifi_sta_disassoc(void *priv, const u8 *own_addr, const u8 *addr,
624                      int reason_code)
625 {
626         struct madwifi_driver_data *drv = priv;
627         struct ieee80211req_mlme mlme;
628         int ret;
629
630         wpa_printf(MSG_DEBUG, "%s: addr=%s reason_code=%d",
631                    __func__, ether_sprintf(addr), reason_code);
632
633         mlme.im_op = IEEE80211_MLME_DISASSOC;
634         mlme.im_reason = reason_code;
635         memcpy(mlme.im_macaddr, addr, IEEE80211_ADDR_LEN);
636         ret = set80211priv(drv, IEEE80211_IOCTL_SETMLME, &mlme, sizeof(mlme));
637         if (ret < 0) {
638                 wpa_printf(MSG_DEBUG, "%s: Failed to disassoc STA (addr "
639                            MACSTR " reason %d)",
640                            __func__, MAC2STR(addr), reason_code);
641         }
642
643         return ret;
644 }
645
646 #ifdef CONFIG_WPS
647 static void madwifi_raw_receive(void *ctx, const u8 *src_addr, const u8 *buf,
648                                 size_t len)
649 {
650         struct madwifi_driver_data *drv = ctx;
651         const struct ieee80211_mgmt *mgmt;
652         u16 fc;
653         union wpa_event_data event;
654
655         /* Send Probe Request information to WPS processing */
656
657         if (len < IEEE80211_HDRLEN + sizeof(mgmt->u.probe_req))
658                 return;
659         mgmt = (const struct ieee80211_mgmt *) buf;
660
661         fc = le_to_host16(mgmt->frame_control);
662         if (WLAN_FC_GET_TYPE(fc) != WLAN_FC_TYPE_MGMT ||
663             WLAN_FC_GET_STYPE(fc) != WLAN_FC_STYPE_PROBE_REQ)
664                 return;
665
666         os_memset(&event, 0, sizeof(event));
667         event.rx_probe_req.sa = mgmt->sa;
668         event.rx_probe_req.ie = mgmt->u.probe_req.variable;
669         event.rx_probe_req.ie_len =
670                 len - (IEEE80211_HDRLEN + sizeof(mgmt->u.probe_req));
671         wpa_supplicant_event(drv->hapd, EVENT_RX_PROBE_REQ, &event);
672 }
673 #endif /* CONFIG_WPS */
674
675 static int madwifi_receive_probe_req(struct madwifi_driver_data *drv)
676 {
677         int ret = 0;
678 #ifdef CONFIG_WPS
679         struct ieee80211req_set_filter filt;
680
681         wpa_printf(MSG_DEBUG, "%s Enter", __func__);
682         filt.app_filterype = IEEE80211_FILTER_TYPE_PROBE_REQ;
683
684         ret = set80211priv(drv, IEEE80211_IOCTL_FILTERFRAME, &filt,
685                            sizeof(struct ieee80211req_set_filter));
686         if (ret)
687                 return ret;
688
689         drv->sock_raw = l2_packet_init(drv->iface, NULL, ETH_P_80211_RAW,
690                                        madwifi_raw_receive, drv, 1);
691         if (drv->sock_raw == NULL)
692                 return -1;
693 #endif /* CONFIG_WPS */
694         return ret;
695 }
696
697 #ifdef CONFIG_WPS
698 static int
699 madwifi_set_wps_ie(void *priv, const u8 *ie, size_t len, u32 frametype)
700 {
701         struct madwifi_driver_data *drv = priv;
702         u8 buf[256];
703         struct ieee80211req_getset_appiebuf *beac_ie;
704
705         wpa_printf(MSG_DEBUG, "%s buflen = %lu", __func__,
706                    (unsigned long) len);
707
708         beac_ie = (struct ieee80211req_getset_appiebuf *) buf;
709         beac_ie->app_frmtype = frametype;
710         beac_ie->app_buflen = len;
711         memcpy(&(beac_ie->app_buf[0]), ie, len);
712
713         return set80211priv(drv, IEEE80211_IOCTL_SET_APPIEBUF, beac_ie,
714                             sizeof(struct ieee80211req_getset_appiebuf) + len);
715 }
716
717 static int
718 madwifi_set_ap_wps_ie(const char *ifname, void *priv,
719                       const struct wpabuf *beacon,
720                       const struct wpabuf *proberesp)
721 {
722         if (madwifi_set_wps_ie(priv, beacon ? wpabuf_head(beacon) : NULL,
723                                beacon ? wpabuf_len(beacon) : 0,
724                                IEEE80211_APPIE_FRAME_BEACON))
725                 return -1;
726         return madwifi_set_wps_ie(priv,
727                                   proberesp ? wpabuf_head(proberesp) : NULL,
728                                   proberesp ? wpabuf_len(proberesp): 0,
729                                   IEEE80211_APPIE_FRAME_PROBE_RESP);
730 }
731 #else /* CONFIG_WPS */
732 #define madwifi_set_ap_wps_ie NULL
733 #endif /* CONFIG_WPS */
734
735 static void
736 madwifi_new_sta(struct madwifi_driver_data *drv, u8 addr[IEEE80211_ADDR_LEN])
737 {
738         struct hostapd_data *hapd = drv->hapd;
739         struct ieee80211req_wpaie ie;
740         int ielen = 0;
741         u8 *iebuf = NULL;
742
743         /*
744          * Fetch negotiated WPA/RSN parameters from the system.
745          */
746         memset(&ie, 0, sizeof(ie));
747         memcpy(ie.wpa_macaddr, addr, IEEE80211_ADDR_LEN);
748         if (set80211priv(drv, IEEE80211_IOCTL_GETWPAIE, &ie, sizeof(ie))) {
749                 /*
750                  * See ATH_WPS_IE comment in the beginning of the file for a
751                  * possible cause for the failure..
752                  */
753                 wpa_printf(MSG_DEBUG, "%s: Failed to get WPA/RSN IE: %s",
754                            __func__, strerror(errno));
755                 goto no_ie;
756         }
757         wpa_hexdump(MSG_MSGDUMP, "madwifi req WPA IE",
758                     ie.wpa_ie, IEEE80211_MAX_OPT_IE);
759         wpa_hexdump(MSG_MSGDUMP, "madwifi req RSN IE",
760                     ie.rsn_ie, IEEE80211_MAX_OPT_IE);
761         iebuf = ie.wpa_ie;
762         /* madwifi seems to return some random data if WPA/RSN IE is not set.
763          * Assume the IE was not included if the IE type is unknown. */
764         if (iebuf[0] != WLAN_EID_VENDOR_SPECIFIC)
765                 iebuf[1] = 0;
766         if (iebuf[1] == 0 && ie.rsn_ie[1] > 0) {
767                 /* madwifi-ng svn #1453 added rsn_ie. Use it, if wpa_ie was not
768                  * set. This is needed for WPA2. */
769                 iebuf = ie.rsn_ie;
770                 if (iebuf[0] != WLAN_EID_RSN)
771                         iebuf[1] = 0;
772         }
773
774         ielen = iebuf[1];
775         if (ielen == 0)
776                 iebuf = NULL;
777         else
778                 ielen += 2;
779
780 no_ie:
781         drv_event_assoc(hapd, addr, iebuf, ielen);
782
783         if (memcmp(addr, drv->acct_mac, ETH_ALEN) == 0) {
784                 /* Cached accounting data is not valid anymore. */
785                 memset(drv->acct_mac, 0, ETH_ALEN);
786                 memset(&drv->acct_data, 0, sizeof(drv->acct_data));
787         }
788 }
789
790 static void
791 madwifi_wireless_event_wireless_custom(struct madwifi_driver_data *drv,
792                                        char *custom, char *end)
793 {
794         wpa_printf(MSG_DEBUG, "Custom wireless event: '%s'", custom);
795
796         if (strncmp(custom, "MLME-MICHAELMICFAILURE.indication", 33) == 0) {
797                 char *pos;
798                 u8 addr[ETH_ALEN];
799                 pos = strstr(custom, "addr=");
800                 if (pos == NULL) {
801                         wpa_printf(MSG_DEBUG,
802                                    "MLME-MICHAELMICFAILURE.indication "
803                                    "without sender address ignored");
804                         return;
805                 }
806                 pos += 5;
807                 if (hwaddr_aton(pos, addr) == 0) {
808                         union wpa_event_data data;
809                         os_memset(&data, 0, sizeof(data));
810                         data.michael_mic_failure.unicast = 1;
811                         data.michael_mic_failure.src = addr;
812                         wpa_supplicant_event(drv->hapd,
813                                              EVENT_MICHAEL_MIC_FAILURE, &data);
814                 } else {
815                         wpa_printf(MSG_DEBUG,
816                                    "MLME-MICHAELMICFAILURE.indication "
817                                    "with invalid MAC address");
818                 }
819         } else if (strncmp(custom, "STA-TRAFFIC-STAT", 16) == 0) {
820                 char *key, *value;
821                 u32 val;
822                 key = custom;
823                 while ((key = strchr(key, '\n')) != NULL) {
824                         key++;
825                         value = strchr(key, '=');
826                         if (value == NULL)
827                                 continue;
828                         *value++ = '\0';
829                         val = strtoul(value, NULL, 10);
830                         if (strcmp(key, "mac") == 0)
831                                 hwaddr_aton(value, drv->acct_mac);
832                         else if (strcmp(key, "rx_packets") == 0)
833                                 drv->acct_data.rx_packets = val;
834                         else if (strcmp(key, "tx_packets") == 0)
835                                 drv->acct_data.tx_packets = val;
836                         else if (strcmp(key, "rx_bytes") == 0)
837                                 drv->acct_data.rx_bytes = val;
838                         else if (strcmp(key, "tx_bytes") == 0)
839                                 drv->acct_data.tx_bytes = val;
840                         key = value;
841                 }
842 #ifdef CONFIG_WPS
843         } else if (strncmp(custom, "PUSH-BUTTON.indication", 22) == 0) {
844                 /* Some atheros kernels send push button as a wireless event */
845                 /* PROBLEM! this event is received for ALL BSSs ...
846                  * so all are enabled for WPS... ugh.
847                  */
848                 wpa_supplicant_event(drv->hapd, EVENT_WPS_BUTTON_PUSHED, NULL);
849         } else if (strncmp(custom, "Manage.prob_req ", 16) == 0) {
850                 /*
851                  * Atheros driver uses a hack to pass Probe Request frames as a
852                  * binary data in the custom wireless event. The old way (using
853                  * packet sniffing) didn't work when bridging.
854                  * Format: "Manage.prob_req <frame len>" | zero padding | frame
855                  */
856 #define WPS_FRAM_TAG_SIZE 30 /* hardcoded in driver */
857                 int len = atoi(custom + 16);
858                 if (len < 0 || custom + WPS_FRAM_TAG_SIZE + len > end) {
859                         wpa_printf(MSG_DEBUG, "Invalid Manage.prob_req event "
860                                    "length %d", len);
861                         return;
862                 }
863                 madwifi_raw_receive(drv, NULL,
864                                     (u8 *) custom + WPS_FRAM_TAG_SIZE, len);
865 #endif /* CONFIG_WPS */
866         }
867 }
868
869 static void
870 madwifi_wireless_event_wireless(struct madwifi_driver_data *drv,
871                                 char *data, int len)
872 {
873         struct iw_event iwe_buf, *iwe = &iwe_buf;
874         char *pos, *end, *custom, *buf;
875
876         pos = data;
877         end = data + len;
878
879         while (pos + IW_EV_LCP_LEN <= end) {
880                 /* Event data may be unaligned, so make a local, aligned copy
881                  * before processing. */
882                 memcpy(&iwe_buf, pos, IW_EV_LCP_LEN);
883                 wpa_printf(MSG_MSGDUMP, "Wireless event: cmd=0x%x len=%d",
884                            iwe->cmd, iwe->len);
885                 if (iwe->len <= IW_EV_LCP_LEN)
886                         return;
887
888                 custom = pos + IW_EV_POINT_LEN;
889                 if (drv->we_version > 18 &&
890                     (iwe->cmd == IWEVMICHAELMICFAILURE ||
891                      iwe->cmd == IWEVASSOCREQIE ||
892                      iwe->cmd == IWEVCUSTOM)) {
893                         /* WE-19 removed the pointer from struct iw_point */
894                         char *dpos = (char *) &iwe_buf.u.data.length;
895                         int dlen = dpos - (char *) &iwe_buf;
896                         memcpy(dpos, pos + IW_EV_LCP_LEN,
897                                sizeof(struct iw_event) - dlen);
898                 } else {
899                         memcpy(&iwe_buf, pos, sizeof(struct iw_event));
900                         custom += IW_EV_POINT_OFF;
901                 }
902
903                 switch (iwe->cmd) {
904                 case IWEVEXPIRED:
905                         drv_event_disassoc(drv->hapd,
906                                            (u8 *) iwe->u.addr.sa_data);
907                         break;
908                 case IWEVREGISTERED:
909                         madwifi_new_sta(drv, (u8 *) iwe->u.addr.sa_data);
910                         break;
911                 case IWEVASSOCREQIE:
912                         /* Driver hack.. Use IWEVASSOCREQIE to bypass
913                          * IWEVCUSTOM size limitations. Need to handle this
914                          * just like IWEVCUSTOM.
915                          */
916                 case IWEVCUSTOM:
917                         if (custom + iwe->u.data.length > end)
918                                 return;
919                         buf = malloc(iwe->u.data.length + 1);
920                         if (buf == NULL)
921                                 return;         /* XXX */
922                         memcpy(buf, custom, iwe->u.data.length);
923                         buf[iwe->u.data.length] = '\0';
924                         madwifi_wireless_event_wireless_custom(
925                                 drv, buf, buf + iwe->u.data.length);
926                         free(buf);
927                         break;
928                 }
929
930                 pos += iwe->len;
931         }
932 }
933
934
935 static void
936 madwifi_wireless_event_rtm_newlink(void *ctx,
937                                    struct ifinfomsg *ifi, u8 *buf, size_t len)
938 {
939         struct madwifi_driver_data *drv = ctx;
940         int attrlen, rta_len;
941         struct rtattr *attr;
942
943         if (ifi->ifi_index != drv->ifindex)
944                 return;
945
946         attrlen = len;
947         attr = (struct rtattr *) buf;
948
949         rta_len = RTA_ALIGN(sizeof(struct rtattr));
950         while (RTA_OK(attr, attrlen)) {
951                 if (attr->rta_type == IFLA_WIRELESS) {
952                         madwifi_wireless_event_wireless(
953                                 drv, ((char *) attr) + rta_len,
954                                 attr->rta_len - rta_len);
955                 }
956                 attr = RTA_NEXT(attr, attrlen);
957         }
958 }
959
960
961 static int
962 madwifi_get_we_version(struct madwifi_driver_data *drv)
963 {
964         struct iw_range *range;
965         struct iwreq iwr;
966         int minlen;
967         size_t buflen;
968
969         drv->we_version = 0;
970
971         /*
972          * Use larger buffer than struct iw_range in order to allow the
973          * structure to grow in the future.
974          */
975         buflen = sizeof(struct iw_range) + 500;
976         range = os_zalloc(buflen);
977         if (range == NULL)
978                 return -1;
979
980         memset(&iwr, 0, sizeof(iwr));
981         os_strlcpy(iwr.ifr_name, drv->iface, IFNAMSIZ);
982         iwr.u.data.pointer = (caddr_t) range;
983         iwr.u.data.length = buflen;
984
985         minlen = ((char *) &range->enc_capa) - (char *) range +
986                 sizeof(range->enc_capa);
987
988         if (ioctl(drv->ioctl_sock, SIOCGIWRANGE, &iwr) < 0) {
989                 perror("ioctl[SIOCGIWRANGE]");
990                 free(range);
991                 return -1;
992         } else if (iwr.u.data.length >= minlen &&
993                    range->we_version_compiled >= 18) {
994                 wpa_printf(MSG_DEBUG, "SIOCGIWRANGE: WE(compiled)=%d "
995                            "WE(source)=%d enc_capa=0x%x",
996                            range->we_version_compiled,
997                            range->we_version_source,
998                            range->enc_capa);
999                 drv->we_version = range->we_version_compiled;
1000         }
1001
1002         free(range);
1003         return 0;
1004 }
1005
1006
1007 static int
1008 madwifi_wireless_event_init(struct madwifi_driver_data *drv)
1009 {
1010         struct netlink_config *cfg;
1011
1012         madwifi_get_we_version(drv);
1013
1014         cfg = os_zalloc(sizeof(*cfg));
1015         if (cfg == NULL)
1016                 return -1;
1017         cfg->ctx = drv;
1018         cfg->newlink_cb = madwifi_wireless_event_rtm_newlink;
1019         drv->netlink = netlink_init(cfg);
1020         if (drv->netlink == NULL) {
1021                 os_free(cfg);
1022                 return -1;
1023         }
1024
1025         return 0;
1026 }
1027
1028
1029 static int
1030 madwifi_send_eapol(void *priv, const u8 *addr, const u8 *data, size_t data_len,
1031                    int encrypt, const u8 *own_addr)
1032 {
1033         struct madwifi_driver_data *drv = priv;
1034         unsigned char buf[3000];
1035         unsigned char *bp = buf;
1036         struct l2_ethhdr *eth;
1037         size_t len;
1038         int status;
1039
1040         /*
1041          * Prepend the Ethernet header.  If the caller left us
1042          * space at the front we could just insert it but since
1043          * we don't know we copy to a local buffer.  Given the frequency
1044          * and size of frames this probably doesn't matter.
1045          */
1046         len = data_len + sizeof(struct l2_ethhdr);
1047         if (len > sizeof(buf)) {
1048                 bp = malloc(len);
1049                 if (bp == NULL) {
1050                         printf("EAPOL frame discarded, cannot malloc temp "
1051                                "buffer of size %lu!\n", (unsigned long) len);
1052                         return -1;
1053                 }
1054         }
1055         eth = (struct l2_ethhdr *) bp;
1056         memcpy(eth->h_dest, addr, ETH_ALEN);
1057         memcpy(eth->h_source, own_addr, ETH_ALEN);
1058         eth->h_proto = host_to_be16(ETH_P_EAPOL);
1059         memcpy(eth+1, data, data_len);
1060
1061         wpa_hexdump(MSG_MSGDUMP, "TX EAPOL", bp, len);
1062
1063         status = l2_packet_send(drv->sock_xmit, addr, ETH_P_EAPOL, bp, len);
1064
1065         if (bp != buf)
1066                 free(bp);
1067         return status;
1068 }
1069
1070 static void
1071 handle_read(void *ctx, const u8 *src_addr, const u8 *buf, size_t len)
1072 {
1073         struct madwifi_driver_data *drv = ctx;
1074         union wpa_event_data event;
1075         os_memset(&event, 0, sizeof(event));
1076         event.eapol_rx.src = src_addr;
1077         event.eapol_rx.data = buf + sizeof(struct l2_ethhdr);
1078         event.eapol_rx.data_len = len - sizeof(struct l2_ethhdr);
1079         wpa_supplicant_event(drv->hapd, EVENT_EAPOL_RX, &event);
1080 }
1081
1082 static void *
1083 madwifi_init(struct hostapd_data *hapd, struct wpa_init_params *params)
1084 {
1085         struct madwifi_driver_data *drv;
1086         struct ifreq ifr;
1087         struct iwreq iwr;
1088
1089         drv = os_zalloc(sizeof(struct madwifi_driver_data));
1090         if (drv == NULL) {
1091                 printf("Could not allocate memory for madwifi driver data\n");
1092                 return NULL;
1093         }
1094
1095         drv->hapd = hapd;
1096         drv->ioctl_sock = socket(PF_INET, SOCK_DGRAM, 0);
1097         if (drv->ioctl_sock < 0) {
1098                 perror("socket[PF_INET,SOCK_DGRAM]");
1099                 goto bad;
1100         }
1101         memcpy(drv->iface, params->ifname, sizeof(drv->iface));
1102
1103         memset(&ifr, 0, sizeof(ifr));
1104         os_strlcpy(ifr.ifr_name, drv->iface, sizeof(ifr.ifr_name));
1105         if (ioctl(drv->ioctl_sock, SIOCGIFINDEX, &ifr) != 0) {
1106                 perror("ioctl(SIOCGIFINDEX)");
1107                 goto bad;
1108         }
1109         drv->ifindex = ifr.ifr_ifindex;
1110
1111         drv->sock_xmit = l2_packet_init(drv->iface, NULL, ETH_P_EAPOL,
1112                                         handle_read, drv, 1);
1113         if (drv->sock_xmit == NULL)
1114                 goto bad;
1115         if (l2_packet_get_own_addr(drv->sock_xmit, params->own_addr))
1116                 goto bad;
1117         if (params->bridge[0]) {
1118                 wpa_printf(MSG_DEBUG, "Configure bridge %s for EAPOL traffic.",
1119                            params->bridge[0]);
1120                 drv->sock_recv = l2_packet_init(params->bridge[0], NULL,
1121                                                 ETH_P_EAPOL, handle_read, drv,
1122                                                 1);
1123                 if (drv->sock_recv == NULL)
1124                         goto bad;
1125         } else
1126                 drv->sock_recv = drv->sock_xmit;
1127
1128         memset(&iwr, 0, sizeof(iwr));
1129         os_strlcpy(iwr.ifr_name, drv->iface, IFNAMSIZ);
1130
1131         iwr.u.mode = IW_MODE_MASTER;
1132
1133         if (ioctl(drv->ioctl_sock, SIOCSIWMODE, &iwr) < 0) {
1134                 perror("ioctl[SIOCSIWMODE]");
1135                 printf("Could not set interface to master mode!\n");
1136                 goto bad;
1137         }
1138
1139         madwifi_set_iface_flags(drv, 0);        /* mark down during setup */
1140         madwifi_set_privacy(drv->iface, drv, 0); /* default to no privacy */
1141
1142         madwifi_receive_probe_req(drv);
1143
1144         if (madwifi_wireless_event_init(drv))
1145                 goto bad;
1146
1147         return drv;
1148 bad:
1149         if (drv->sock_xmit != NULL)
1150                 l2_packet_deinit(drv->sock_xmit);
1151         if (drv->ioctl_sock >= 0)
1152                 close(drv->ioctl_sock);
1153         if (drv != NULL)
1154                 free(drv);
1155         return NULL;
1156 }
1157
1158
1159 static void
1160 madwifi_deinit(void *priv)
1161 {
1162         struct madwifi_driver_data *drv = priv;
1163
1164         netlink_deinit(drv->netlink);
1165         (void) madwifi_set_iface_flags(drv, 0);
1166         if (drv->ioctl_sock >= 0)
1167                 close(drv->ioctl_sock);
1168         if (drv->sock_recv != NULL && drv->sock_recv != drv->sock_xmit)
1169                 l2_packet_deinit(drv->sock_recv);
1170         if (drv->sock_xmit != NULL)
1171                 l2_packet_deinit(drv->sock_xmit);
1172         if (drv->sock_raw)
1173                 l2_packet_deinit(drv->sock_raw);
1174         free(drv);
1175 }
1176
1177 static int
1178 madwifi_set_ssid(const char *ifname, void *priv, const u8 *buf, int len)
1179 {
1180         struct madwifi_driver_data *drv = priv;
1181         struct iwreq iwr;
1182
1183         memset(&iwr, 0, sizeof(iwr));
1184         os_strlcpy(iwr.ifr_name, drv->iface, IFNAMSIZ);
1185         iwr.u.essid.flags = 1; /* SSID active */
1186         iwr.u.essid.pointer = (caddr_t) buf;
1187         iwr.u.essid.length = len + 1;
1188
1189         if (ioctl(drv->ioctl_sock, SIOCSIWESSID, &iwr) < 0) {
1190                 perror("ioctl[SIOCSIWESSID]");
1191                 printf("len=%d\n", len);
1192                 return -1;
1193         }
1194         return 0;
1195 }
1196
1197 static int
1198 madwifi_get_ssid(const char *ifname, void *priv, u8 *buf, int len)
1199 {
1200         struct madwifi_driver_data *drv = priv;
1201         struct iwreq iwr;
1202         int ret = 0;
1203
1204         memset(&iwr, 0, sizeof(iwr));
1205         os_strlcpy(iwr.ifr_name, drv->iface, IFNAMSIZ);
1206         iwr.u.essid.pointer = (caddr_t) buf;
1207         iwr.u.essid.length = len;
1208
1209         if (ioctl(drv->ioctl_sock, SIOCGIWESSID, &iwr) < 0) {
1210                 perror("ioctl[SIOCGIWESSID]");
1211                 ret = -1;
1212         } else
1213                 ret = iwr.u.essid.length;
1214
1215         return ret;
1216 }
1217
1218 static int
1219 madwifi_set_countermeasures(void *priv, int enabled)
1220 {
1221         struct madwifi_driver_data *drv = priv;
1222         wpa_printf(MSG_DEBUG, "%s: enabled=%d", __FUNCTION__, enabled);
1223         return set80211param(drv, IEEE80211_PARAM_COUNTERMEASURES, enabled);
1224 }
1225
1226 static int
1227 madwifi_commit(void *priv)
1228 {
1229         return madwifi_set_iface_flags(priv, 1);
1230 }
1231
1232 const struct wpa_driver_ops wpa_driver_atheros_ops = {
1233         .name                   = "atheros",
1234         .hapd_init              = madwifi_init,
1235         .deinit                 = madwifi_deinit,
1236         .set_ieee8021x          = madwifi_set_ieee8021x,
1237         .set_privacy            = madwifi_set_privacy,
1238         .set_key                = madwifi_set_key,
1239         .get_seqnum             = madwifi_get_seqnum,
1240         .flush                  = madwifi_flush,
1241         .set_generic_elem       = madwifi_set_opt_ie,
1242         .sta_set_flags          = madwifi_sta_set_flags,
1243         .read_sta_data          = madwifi_read_sta_driver_data,
1244         .hapd_send_eapol        = madwifi_send_eapol,
1245         .sta_disassoc           = madwifi_sta_disassoc,
1246         .sta_deauth             = madwifi_sta_deauth,
1247         .hapd_set_ssid          = madwifi_set_ssid,
1248         .hapd_get_ssid          = madwifi_get_ssid,
1249         .set_countermeasures    = madwifi_set_countermeasures,
1250         .sta_clear_stats        = madwifi_sta_clear_stats,
1251         .commit                 = madwifi_commit,
1252         .set_ap_wps_ie          = madwifi_set_ap_wps_ie,
1253 };