WPS 2.0: Provide (Re)Association Response WPS IE to driver
[libeap.git] / src / drivers / driver_test.c
1 /*
2  * Testing driver interface for a simulated network driver
3  * Copyright (c) 2004-2010, Jouni Malinen <j@w1.fi>
4  *
5  * This program is free software; you can redistribute it and/or modify
6  * it under the terms of the GNU General Public License version 2 as
7  * published by the Free Software Foundation.
8  *
9  * Alternatively, this software may be distributed under the terms of BSD
10  * license.
11  *
12  * See README and COPYING for more details.
13  */
14
15 /* Make sure we get winsock2.h for Windows build to get sockaddr_storage */
16 #include "build_config.h"
17 #ifdef CONFIG_NATIVE_WINDOWS
18 #include <winsock2.h>
19 #endif /* CONFIG_NATIVE_WINDOWS */
20
21 #include "utils/includes.h"
22
23 #ifndef CONFIG_NATIVE_WINDOWS
24 #include <sys/un.h>
25 #include <dirent.h>
26 #include <sys/stat.h>
27 #define DRIVER_TEST_UNIX
28 #endif /* CONFIG_NATIVE_WINDOWS */
29
30 #include "utils/common.h"
31 #include "utils/eloop.h"
32 #include "utils/list.h"
33 #include "utils/trace.h"
34 #include "common/ieee802_11_defs.h"
35 #include "crypto/sha1.h"
36 #include "l2_packet/l2_packet.h"
37 #include "driver.h"
38
39
40 struct test_client_socket {
41         struct test_client_socket *next;
42         u8 addr[ETH_ALEN];
43         struct sockaddr_un un;
44         socklen_t unlen;
45         struct test_driver_bss *bss;
46 };
47
48 struct test_driver_bss {
49         struct wpa_driver_test_data *drv;
50         struct dl_list list;
51         void *bss_ctx;
52         char ifname[IFNAMSIZ];
53         u8 bssid[ETH_ALEN];
54         u8 *ie;
55         size_t ielen;
56         u8 *wps_beacon_ie;
57         size_t wps_beacon_ie_len;
58         u8 *wps_probe_resp_ie;
59         size_t wps_probe_resp_ie_len;
60         u8 ssid[32];
61         size_t ssid_len;
62         int privacy;
63 };
64
65 struct wpa_driver_test_global {
66         int bss_add_used;
67         u8 req_addr[ETH_ALEN];
68 };
69
70 struct wpa_driver_test_data {
71         struct wpa_driver_test_global *global;
72         void *ctx;
73         WPA_TRACE_REF(ctx);
74         u8 own_addr[ETH_ALEN];
75         int test_socket;
76 #ifdef DRIVER_TEST_UNIX
77         struct sockaddr_un hostapd_addr;
78 #endif /* DRIVER_TEST_UNIX */
79         int hostapd_addr_set;
80         struct sockaddr_in hostapd_addr_udp;
81         int hostapd_addr_udp_set;
82         char *own_socket_path;
83         char *test_dir;
84 #define MAX_SCAN_RESULTS 30
85         struct wpa_scan_res *scanres[MAX_SCAN_RESULTS];
86         size_t num_scanres;
87         int use_associnfo;
88         u8 assoc_wpa_ie[80];
89         size_t assoc_wpa_ie_len;
90         int use_mlme;
91         int associated;
92         u8 *probe_req_ie;
93         size_t probe_req_ie_len;
94         u8 probe_req_ssid[32];
95         size_t probe_req_ssid_len;
96         int ibss;
97         int ap;
98
99         struct test_client_socket *cli;
100         struct dl_list bss;
101         int udp_port;
102
103         int alloc_iface_idx;
104
105         int probe_req_report;
106         unsigned int remain_on_channel_freq;
107         unsigned int remain_on_channel_duration;
108
109         int current_freq;
110 };
111
112
113 static void wpa_driver_test_deinit(void *priv);
114 static int wpa_driver_test_attach(struct wpa_driver_test_data *drv,
115                                   const char *dir, int ap);
116 static void wpa_driver_test_close_test_socket(
117         struct wpa_driver_test_data *drv);
118 static void test_remain_on_channel_timeout(void *eloop_ctx, void *timeout_ctx);
119
120
121 static void test_driver_free_bss(struct test_driver_bss *bss)
122 {
123         os_free(bss->ie);
124         os_free(bss->wps_beacon_ie);
125         os_free(bss->wps_probe_resp_ie);
126         os_free(bss);
127 }
128
129
130 static void test_driver_free_bsses(struct wpa_driver_test_data *drv)
131 {
132         struct test_driver_bss *bss, *tmp;
133
134         dl_list_for_each_safe(bss, tmp, &drv->bss, struct test_driver_bss,
135                               list) {
136                 dl_list_del(&bss->list);
137                 test_driver_free_bss(bss);
138         }
139 }
140
141
142 static struct test_client_socket *
143 test_driver_get_cli(struct wpa_driver_test_data *drv, struct sockaddr_un *from,
144                     socklen_t fromlen)
145 {
146         struct test_client_socket *cli = drv->cli;
147
148         while (cli) {
149                 if (cli->unlen == fromlen &&
150                     strncmp(cli->un.sun_path, from->sun_path,
151                             fromlen - sizeof(cli->un.sun_family)) == 0)
152                         return cli;
153                 cli = cli->next;
154         }
155
156         return NULL;
157 }
158
159
160 static int test_driver_send_eapol(void *priv, const u8 *addr, const u8 *data,
161                                   size_t data_len, int encrypt,
162                                   const u8 *own_addr)
163 {
164         struct test_driver_bss *dbss = priv;
165         struct wpa_driver_test_data *drv = dbss->drv;
166         struct test_client_socket *cli;
167         struct msghdr msg;
168         struct iovec io[3];
169         struct l2_ethhdr eth;
170
171         if (drv->test_socket < 0)
172                 return -1;
173
174         cli = drv->cli;
175         while (cli) {
176                 if (memcmp(cli->addr, addr, ETH_ALEN) == 0)
177                         break;
178                 cli = cli->next;
179         }
180
181         if (!cli) {
182                 wpa_printf(MSG_DEBUG, "%s: no destination client entry",
183                            __func__);
184                 return -1;
185         }
186
187         memcpy(eth.h_dest, addr, ETH_ALEN);
188         memcpy(eth.h_source, own_addr, ETH_ALEN);
189         eth.h_proto = host_to_be16(ETH_P_EAPOL);
190
191         io[0].iov_base = "EAPOL ";
192         io[0].iov_len = 6;
193         io[1].iov_base = &eth;
194         io[1].iov_len = sizeof(eth);
195         io[2].iov_base = (u8 *) data;
196         io[2].iov_len = data_len;
197
198         memset(&msg, 0, sizeof(msg));
199         msg.msg_iov = io;
200         msg.msg_iovlen = 3;
201         msg.msg_name = &cli->un;
202         msg.msg_namelen = cli->unlen;
203         return sendmsg(drv->test_socket, &msg, 0);
204 }
205
206
207 static int test_driver_send_ether(void *priv, const u8 *dst, const u8 *src,
208                                   u16 proto, const u8 *data, size_t data_len)
209 {
210         struct test_driver_bss *dbss = priv;
211         struct wpa_driver_test_data *drv = dbss->drv;
212         struct msghdr msg;
213         struct iovec io[3];
214         struct l2_ethhdr eth;
215         char desttxt[30];
216         struct sockaddr_un addr;
217         struct dirent *dent;
218         DIR *dir;
219         int ret = 0, broadcast = 0, count = 0;
220
221         if (drv->test_socket < 0 || drv->test_dir == NULL) {
222                 wpa_printf(MSG_DEBUG, "%s: invalid parameters (sock=%d "
223                            "test_dir=%p)",
224                            __func__, drv->test_socket, drv->test_dir);
225                 return -1;
226         }
227
228         broadcast = memcmp(dst, "\xff\xff\xff\xff\xff\xff", ETH_ALEN) == 0;
229         snprintf(desttxt, sizeof(desttxt), MACSTR, MAC2STR(dst));
230
231         memcpy(eth.h_dest, dst, ETH_ALEN);
232         memcpy(eth.h_source, src, ETH_ALEN);
233         eth.h_proto = host_to_be16(proto);
234
235         io[0].iov_base = "ETHER ";
236         io[0].iov_len = 6;
237         io[1].iov_base = &eth;
238         io[1].iov_len = sizeof(eth);
239         io[2].iov_base = (u8 *) data;
240         io[2].iov_len = data_len;
241
242         memset(&msg, 0, sizeof(msg));
243         msg.msg_iov = io;
244         msg.msg_iovlen = 3;
245
246         dir = opendir(drv->test_dir);
247         if (dir == NULL) {
248                 perror("test_driver: opendir");
249                 return -1;
250         }
251         while ((dent = readdir(dir))) {
252 #ifdef _DIRENT_HAVE_D_TYPE
253                 /* Skip the file if it is not a socket. Also accept
254                  * DT_UNKNOWN (0) in case the C library or underlying file
255                  * system does not support d_type. */
256                 if (dent->d_type != DT_SOCK && dent->d_type != DT_UNKNOWN)
257                         continue;
258 #endif /* _DIRENT_HAVE_D_TYPE */
259                 if (strcmp(dent->d_name, ".") == 0 ||
260                     strcmp(dent->d_name, "..") == 0)
261                         continue;
262
263                 memset(&addr, 0, sizeof(addr));
264                 addr.sun_family = AF_UNIX;
265                 snprintf(addr.sun_path, sizeof(addr.sun_path), "%s/%s",
266                          drv->test_dir, dent->d_name);
267
268                 if (strcmp(addr.sun_path, drv->own_socket_path) == 0)
269                         continue;
270                 if (!broadcast && strstr(dent->d_name, desttxt) == NULL)
271                         continue;
272
273                 wpa_printf(MSG_DEBUG, "%s: Send ether frame to %s",
274                            __func__, dent->d_name);
275
276                 msg.msg_name = &addr;
277                 msg.msg_namelen = sizeof(addr);
278                 ret = sendmsg(drv->test_socket, &msg, 0);
279                 if (ret < 0)
280                         perror("driver_test: sendmsg");
281                 count++;
282         }
283         closedir(dir);
284
285         if (!broadcast && count == 0) {
286                 wpa_printf(MSG_DEBUG, "%s: Destination " MACSTR " not found",
287                            __func__, MAC2STR(dst));
288                 return -1;
289         }
290
291         return ret;
292 }
293
294
295 static int wpa_driver_test_send_mlme(void *priv, const u8 *data,
296                                      size_t data_len)
297 {
298         struct test_driver_bss *dbss = priv;
299         struct wpa_driver_test_data *drv = dbss->drv;
300         struct msghdr msg;
301         struct iovec io[2];
302         const u8 *dest;
303         struct sockaddr_un addr;
304         struct dirent *dent;
305         DIR *dir;
306         int broadcast;
307         int ret = 0;
308         struct ieee80211_hdr *hdr;
309         u16 fc;
310         char cmd[50];
311         int freq;
312 #ifdef HOSTAPD
313         char desttxt[30];
314 #endif /* HOSTAPD */
315         union wpa_event_data event;
316
317         wpa_hexdump(MSG_MSGDUMP, "test_send_mlme", data, data_len);
318         if (drv->test_socket < 0 || data_len < 10) {
319                 wpa_printf(MSG_DEBUG, "%s: invalid parameters (sock=%d len=%lu"
320                            " test_dir=%p)",
321                            __func__, drv->test_socket,
322                            (unsigned long) data_len,
323                            drv->test_dir);
324                 return -1;
325         }
326
327         dest = data + 4;
328         broadcast = os_memcmp(dest, "\xff\xff\xff\xff\xff\xff", ETH_ALEN) == 0;
329
330 #ifdef HOSTAPD
331         snprintf(desttxt, sizeof(desttxt), MACSTR, MAC2STR(dest));
332 #endif /* HOSTAPD */
333
334         if (drv->remain_on_channel_freq)
335                 freq = drv->remain_on_channel_freq;
336         else
337                 freq = drv->current_freq;
338         wpa_printf(MSG_DEBUG, "test_driver(%s): MLME TX on freq %d MHz",
339                    dbss->ifname, freq);
340         os_snprintf(cmd, sizeof(cmd), "MLME freq=%d ", freq);
341         io[0].iov_base = cmd;
342         io[0].iov_len = os_strlen(cmd);
343         io[1].iov_base = (void *) data;
344         io[1].iov_len = data_len;
345
346         os_memset(&msg, 0, sizeof(msg));
347         msg.msg_iov = io;
348         msg.msg_iovlen = 2;
349
350 #ifdef HOSTAPD
351         if (drv->test_dir == NULL) {
352                 wpa_printf(MSG_DEBUG, "%s: test_dir == NULL", __func__);
353                 return -1;
354         }
355
356         dir = opendir(drv->test_dir);
357         if (dir == NULL) {
358                 perror("test_driver: opendir");
359                 return -1;
360         }
361         while ((dent = readdir(dir))) {
362 #ifdef _DIRENT_HAVE_D_TYPE
363                 /* Skip the file if it is not a socket. Also accept
364                  * DT_UNKNOWN (0) in case the C library or underlying file
365                  * system does not support d_type. */
366                 if (dent->d_type != DT_SOCK && dent->d_type != DT_UNKNOWN)
367                         continue;
368 #endif /* _DIRENT_HAVE_D_TYPE */
369                 if (os_strcmp(dent->d_name, ".") == 0 ||
370                     os_strcmp(dent->d_name, "..") == 0)
371                         continue;
372
373                 os_memset(&addr, 0, sizeof(addr));
374                 addr.sun_family = AF_UNIX;
375                 os_snprintf(addr.sun_path, sizeof(addr.sun_path), "%s/%s",
376                             drv->test_dir, dent->d_name);
377
378                 if (os_strcmp(addr.sun_path, drv->own_socket_path) == 0)
379                         continue;
380                 if (!broadcast && os_strstr(dent->d_name, desttxt) == NULL)
381                         continue;
382
383                 wpa_printf(MSG_DEBUG, "%s: Send management frame to %s",
384                            __func__, dent->d_name);
385
386                 msg.msg_name = &addr;
387                 msg.msg_namelen = sizeof(addr);
388                 ret = sendmsg(drv->test_socket, &msg, 0);
389                 if (ret < 0)
390                         perror("driver_test: sendmsg(test_socket)");
391         }
392         closedir(dir);
393 #else /* HOSTAPD */
394
395         if (os_memcmp(dest, dbss->bssid, ETH_ALEN) == 0 ||
396             drv->test_dir == NULL) {
397                 if (drv->hostapd_addr_udp_set) {
398                         msg.msg_name = &drv->hostapd_addr_udp;
399                         msg.msg_namelen = sizeof(drv->hostapd_addr_udp);
400                 } else {
401 #ifdef DRIVER_TEST_UNIX
402                         msg.msg_name = &drv->hostapd_addr;
403                         msg.msg_namelen = sizeof(drv->hostapd_addr);
404 #endif /* DRIVER_TEST_UNIX */
405                 }
406         } else if (broadcast) {
407                 dir = opendir(drv->test_dir);
408                 if (dir == NULL)
409                         return -1;
410                 while ((dent = readdir(dir))) {
411 #ifdef _DIRENT_HAVE_D_TYPE
412                         /* Skip the file if it is not a socket.
413                          * Also accept DT_UNKNOWN (0) in case
414                          * the C library or underlying file
415                          * system does not support d_type. */
416                         if (dent->d_type != DT_SOCK &&
417                             dent->d_type != DT_UNKNOWN)
418                                 continue;
419 #endif /* _DIRENT_HAVE_D_TYPE */
420                         if (os_strcmp(dent->d_name, ".") == 0 ||
421                             os_strcmp(dent->d_name, "..") == 0)
422                                 continue;
423                         wpa_printf(MSG_DEBUG, "%s: Send broadcast MLME to %s",
424                                    __func__, dent->d_name);
425                         os_memset(&addr, 0, sizeof(addr));
426                         addr.sun_family = AF_UNIX;
427                         os_snprintf(addr.sun_path, sizeof(addr.sun_path),
428                                     "%s/%s", drv->test_dir, dent->d_name);
429
430                         msg.msg_name = &addr;
431                         msg.msg_namelen = sizeof(addr);
432
433                         ret = sendmsg(drv->test_socket, &msg, 0);
434                         if (ret < 0)
435                                 perror("driver_test: sendmsg(test_socket)");
436                 }
437                 closedir(dir);
438                 return ret;
439         } else {
440                 struct stat st;
441                 os_memset(&addr, 0, sizeof(addr));
442                 addr.sun_family = AF_UNIX;
443                 os_snprintf(addr.sun_path, sizeof(addr.sun_path),
444                             "%s/AP-" MACSTR, drv->test_dir, MAC2STR(dest));
445                 if (stat(addr.sun_path, &st) < 0) {
446                         os_snprintf(addr.sun_path, sizeof(addr.sun_path),
447                                     "%s/STA-" MACSTR,
448                                     drv->test_dir, MAC2STR(dest));
449                 }
450                 msg.msg_name = &addr;
451                 msg.msg_namelen = sizeof(addr);
452         }
453
454         if (sendmsg(drv->test_socket, &msg, 0) < 0) {
455                 perror("sendmsg(test_socket)");
456                 return -1;
457         }
458 #endif /* HOSTAPD */
459
460         hdr = (struct ieee80211_hdr *) data;
461         fc = le_to_host16(hdr->frame_control);
462
463         os_memset(&event, 0, sizeof(event));
464         event.tx_status.type = WLAN_FC_GET_TYPE(fc);
465         event.tx_status.stype = WLAN_FC_GET_STYPE(fc);
466         event.tx_status.dst = hdr->addr1;
467         event.tx_status.data = data;
468         event.tx_status.data_len = data_len;
469         event.tx_status.ack = ret >= 0;
470         wpa_supplicant_event(drv->ctx, EVENT_TX_STATUS, &event);
471
472         return ret;
473 }
474
475
476 static void test_driver_scan(struct wpa_driver_test_data *drv,
477                              struct sockaddr_un *from, socklen_t fromlen,
478                              char *data)
479 {
480         char buf[512], *pos, *end;
481         int ret;
482         struct test_driver_bss *bss;
483         u8 sa[ETH_ALEN];
484         u8 ie[512];
485         size_t ielen;
486         union wpa_event_data event;
487
488         /* data: optional [ ' ' | STA-addr | ' ' | IEs(hex) ] */
489
490         wpa_printf(MSG_DEBUG, "test_driver: SCAN");
491
492         if (*data) {
493                 if (*data != ' ' ||
494                     hwaddr_aton(data + 1, sa)) {
495                         wpa_printf(MSG_DEBUG, "test_driver: Unexpected SCAN "
496                                    "command format");
497                         return;
498                 }
499
500                 data += 18;
501                 while (*data == ' ')
502                         data++;
503                 ielen = os_strlen(data) / 2;
504                 if (ielen > sizeof(ie))
505                         ielen = sizeof(ie);
506                 if (hexstr2bin(data, ie, ielen) < 0)
507                         ielen = 0;
508
509                 wpa_printf(MSG_DEBUG, "test_driver: Scan from " MACSTR,
510                            MAC2STR(sa));
511                 wpa_hexdump(MSG_MSGDUMP, "test_driver: scan IEs", ie, ielen);
512
513                 os_memset(&event, 0, sizeof(event));
514                 event.rx_probe_req.sa = sa;
515                 event.rx_probe_req.ie = ie;
516                 event.rx_probe_req.ie_len = ielen;
517                 wpa_supplicant_event(drv->ctx, EVENT_RX_PROBE_REQ, &event);
518         }
519
520         dl_list_for_each(bss, &drv->bss, struct test_driver_bss, list) {
521                 pos = buf;
522                 end = buf + sizeof(buf);
523
524                 /* reply: SCANRESP BSSID SSID IEs */
525                 ret = snprintf(pos, end - pos, "SCANRESP " MACSTR " ",
526                                MAC2STR(bss->bssid));
527                 if (ret < 0 || ret >= end - pos)
528                         return;
529                 pos += ret;
530                 pos += wpa_snprintf_hex(pos, end - pos,
531                                         bss->ssid, bss->ssid_len);
532                 ret = snprintf(pos, end - pos, " ");
533                 if (ret < 0 || ret >= end - pos)
534                         return;
535                 pos += ret;
536                 pos += wpa_snprintf_hex(pos, end - pos, bss->ie, bss->ielen);
537                 pos += wpa_snprintf_hex(pos, end - pos, bss->wps_probe_resp_ie,
538                                         bss->wps_probe_resp_ie_len);
539
540                 if (bss->privacy) {
541                         ret = snprintf(pos, end - pos, " PRIVACY");
542                         if (ret < 0 || ret >= end - pos)
543                                 return;
544                         pos += ret;
545                 }
546
547                 sendto(drv->test_socket, buf, pos - buf, 0,
548                        (struct sockaddr *) from, fromlen);
549         }
550 }
551
552
553 static void test_driver_assoc(struct wpa_driver_test_data *drv,
554                               struct sockaddr_un *from, socklen_t fromlen,
555                               char *data)
556 {
557         struct test_client_socket *cli;
558         u8 ie[256], ssid[32];
559         size_t ielen, ssid_len = 0;
560         char *pos, *pos2, cmd[50];
561         struct test_driver_bss *bss, *tmp;
562
563         /* data: STA-addr SSID(hex) IEs(hex) */
564
565         cli = os_zalloc(sizeof(*cli));
566         if (cli == NULL)
567                 return;
568
569         if (hwaddr_aton(data, cli->addr)) {
570                 printf("test_socket: Invalid MAC address '%s' in ASSOC\n",
571                        data);
572                 os_free(cli);
573                 return;
574         }
575         pos = data + 17;
576         while (*pos == ' ')
577                 pos++;
578         pos2 = strchr(pos, ' ');
579         ielen = 0;
580         if (pos2) {
581                 ssid_len = (pos2 - pos) / 2;
582                 if (hexstr2bin(pos, ssid, ssid_len) < 0) {
583                         wpa_printf(MSG_DEBUG, "%s: Invalid SSID", __func__);
584                         os_free(cli);
585                         return;
586                 }
587                 wpa_hexdump_ascii(MSG_DEBUG, "test_driver_assoc: SSID",
588                                   ssid, ssid_len);
589
590                 pos = pos2 + 1;
591                 ielen = strlen(pos) / 2;
592                 if (ielen > sizeof(ie))
593                         ielen = sizeof(ie);
594                 if (hexstr2bin(pos, ie, ielen) < 0)
595                         ielen = 0;
596         }
597
598         bss = NULL;
599         dl_list_for_each(tmp, &drv->bss, struct test_driver_bss, list) {
600                 if (tmp->ssid_len == ssid_len &&
601                     os_memcmp(tmp->ssid, ssid, ssid_len) == 0) {
602                         bss = tmp;
603                         break;
604                 }
605         }
606         if (bss == NULL) {
607                 wpa_printf(MSG_DEBUG, "%s: No matching SSID found from "
608                            "configured BSSes", __func__);
609                 os_free(cli);
610                 return;
611         }
612
613         cli->bss = bss;
614         memcpy(&cli->un, from, sizeof(cli->un));
615         cli->unlen = fromlen;
616         cli->next = drv->cli;
617         drv->cli = cli;
618         wpa_hexdump_ascii(MSG_DEBUG, "test_socket: ASSOC sun_path",
619                           (const u8 *) cli->un.sun_path,
620                           cli->unlen - sizeof(cli->un.sun_family));
621
622         snprintf(cmd, sizeof(cmd), "ASSOCRESP " MACSTR " 0",
623                  MAC2STR(bss->bssid));
624         sendto(drv->test_socket, cmd, strlen(cmd), 0,
625                (struct sockaddr *) from, fromlen);
626
627         drv_event_assoc(bss->bss_ctx, cli->addr, ie, ielen);
628 }
629
630
631 static void test_driver_disassoc(struct wpa_driver_test_data *drv,
632                                  struct sockaddr_un *from, socklen_t fromlen)
633 {
634         struct test_client_socket *cli;
635
636         cli = test_driver_get_cli(drv, from, fromlen);
637         if (!cli)
638                 return;
639
640         drv_event_disassoc(drv->ctx, cli->addr);
641 }
642
643
644 static void test_driver_eapol(struct wpa_driver_test_data *drv,
645                               struct sockaddr_un *from, socklen_t fromlen,
646                               u8 *data, size_t datalen)
647 {
648 #ifdef HOSTAPD
649         struct test_client_socket *cli;
650 #endif /* HOSTAPD */
651         const u8 *src = NULL;
652
653         if (datalen > 14) {
654                 /* Skip Ethernet header */
655                 src = data + ETH_ALEN;
656                 wpa_printf(MSG_DEBUG, "test_driver: dst=" MACSTR " src="
657                            MACSTR " proto=%04x",
658                            MAC2STR(data), MAC2STR(src),
659                            WPA_GET_BE16(data + 2 * ETH_ALEN));
660                 data += 14;
661                 datalen -= 14;
662         }
663
664 #ifdef HOSTAPD
665         cli = test_driver_get_cli(drv, from, fromlen);
666         if (cli) {
667                 drv_event_eapol_rx(cli->bss->bss_ctx, cli->addr, data,
668                                    datalen);
669         } else {
670                 wpa_printf(MSG_DEBUG, "test_socket: EAPOL from unknown "
671                            "client");
672         }
673 #else /* HOSTAPD */
674         if (src)
675                 drv_event_eapol_rx(drv->ctx, src, data, datalen);
676 #endif /* HOSTAPD */
677 }
678
679
680 static void test_driver_ether(struct wpa_driver_test_data *drv,
681                               struct sockaddr_un *from, socklen_t fromlen,
682                               u8 *data, size_t datalen)
683 {
684         struct l2_ethhdr *eth;
685
686         if (datalen < sizeof(*eth))
687                 return;
688
689         eth = (struct l2_ethhdr *) data;
690         wpa_printf(MSG_DEBUG, "test_driver: RX ETHER dst=" MACSTR " src="
691                    MACSTR " proto=%04x",
692                    MAC2STR(eth->h_dest), MAC2STR(eth->h_source),
693                    be_to_host16(eth->h_proto));
694
695 #ifdef CONFIG_IEEE80211R
696         if (be_to_host16(eth->h_proto) == ETH_P_RRB) {
697                 union wpa_event_data ev;
698                 os_memset(&ev, 0, sizeof(ev));
699                 ev.ft_rrb_rx.src = eth->h_source;
700                 ev.ft_rrb_rx.data = data + sizeof(*eth);
701                 ev.ft_rrb_rx.data_len = datalen - sizeof(*eth);
702         }
703 #endif /* CONFIG_IEEE80211R */
704 }
705
706
707 static void test_driver_mlme(struct wpa_driver_test_data *drv,
708                              struct sockaddr_un *from, socklen_t fromlen,
709                              u8 *data, size_t datalen)
710 {
711         struct ieee80211_hdr *hdr;
712         u16 fc;
713         union wpa_event_data event;
714         int freq = 0, own_freq;
715         struct test_driver_bss *bss;
716
717         bss = dl_list_first(&drv->bss, struct test_driver_bss, list);
718
719         if (datalen > 6 && os_memcmp(data, "freq=", 5) == 0) {
720                 size_t pos;
721                 for (pos = 5; pos < datalen; pos++) {
722                         if (data[pos] == ' ')
723                                 break;
724                 }
725                 if (pos < datalen) {
726                         freq = atoi((const char *) &data[5]);
727                         wpa_printf(MSG_DEBUG, "test_driver(%s): MLME RX on "
728                                    "freq %d MHz", bss->ifname, freq);
729                         pos++;
730                         data += pos;
731                         datalen -= pos;
732                 }
733         }
734
735         if (drv->remain_on_channel_freq)
736                 own_freq = drv->remain_on_channel_freq;
737         else
738                 own_freq = drv->current_freq;
739
740         if (freq && own_freq && freq != own_freq) {
741                 wpa_printf(MSG_DEBUG, "test_driver(%s): Ignore MLME RX on "
742                            "another frequency %d MHz (own %d MHz)",
743                            bss->ifname, freq, own_freq);
744                 return;
745         }
746
747         hdr = (struct ieee80211_hdr *) data;
748
749         if (test_driver_get_cli(drv, from, fromlen) == NULL && datalen >= 16) {
750                 struct test_client_socket *cli;
751                 cli = os_zalloc(sizeof(*cli));
752                 if (cli == NULL)
753                         return;
754                 wpa_printf(MSG_DEBUG, "Adding client entry for " MACSTR,
755                            MAC2STR(hdr->addr2));
756                 memcpy(cli->addr, hdr->addr2, ETH_ALEN);
757                 memcpy(&cli->un, from, sizeof(cli->un));
758                 cli->unlen = fromlen;
759                 cli->next = drv->cli;
760                 drv->cli = cli;
761         }
762
763         wpa_hexdump(MSG_MSGDUMP, "test_driver_mlme: received frame",
764                     data, datalen);
765         fc = le_to_host16(hdr->frame_control);
766         if (WLAN_FC_GET_TYPE(fc) != WLAN_FC_TYPE_MGMT) {
767                 wpa_printf(MSG_ERROR, "%s: received non-mgmt frame",
768                            __func__);
769                 return;
770         }
771
772         os_memset(&event, 0, sizeof(event));
773         event.rx_mgmt.frame = data;
774         event.rx_mgmt.frame_len = datalen;
775         wpa_supplicant_event(drv->ctx, EVENT_RX_MGMT, &event);
776 }
777
778
779 static void test_driver_receive_unix(int sock, void *eloop_ctx, void *sock_ctx)
780 {
781         struct wpa_driver_test_data *drv = eloop_ctx;
782         char buf[2000];
783         int res;
784         struct sockaddr_un from;
785         socklen_t fromlen = sizeof(from);
786
787         res = recvfrom(sock, buf, sizeof(buf) - 1, 0,
788                        (struct sockaddr *) &from, &fromlen);
789         if (res < 0) {
790                 perror("recvfrom(test_socket)");
791                 return;
792         }
793         buf[res] = '\0';
794
795         wpa_printf(MSG_DEBUG, "test_driver: received %u bytes", res);
796
797         if (strncmp(buf, "SCAN", 4) == 0) {
798                 test_driver_scan(drv, &from, fromlen, buf + 4);
799         } else if (strncmp(buf, "ASSOC ", 6) == 0) {
800                 test_driver_assoc(drv, &from, fromlen, buf + 6);
801         } else if (strcmp(buf, "DISASSOC") == 0) {
802                 test_driver_disassoc(drv, &from, fromlen);
803         } else if (strncmp(buf, "EAPOL ", 6) == 0) {
804                 test_driver_eapol(drv, &from, fromlen, (u8 *) buf + 6,
805                                   res - 6);
806         } else if (strncmp(buf, "ETHER ", 6) == 0) {
807                 test_driver_ether(drv, &from, fromlen, (u8 *) buf + 6,
808                                   res - 6);
809         } else if (strncmp(buf, "MLME ", 5) == 0) {
810                 test_driver_mlme(drv, &from, fromlen, (u8 *) buf + 5, res - 5);
811         } else {
812                 wpa_hexdump_ascii(MSG_DEBUG, "Unknown test_socket command",
813                                   (u8 *) buf, res);
814         }
815 }
816
817
818 static int test_driver_set_generic_elem(void *priv,
819                                         const u8 *elem, size_t elem_len)
820 {
821         struct test_driver_bss *bss = priv;
822
823         os_free(bss->ie);
824
825         if (elem == NULL) {
826                 bss->ie = NULL;
827                 bss->ielen = 0;
828                 return 0;
829         }
830
831         bss->ie = os_malloc(elem_len);
832         if (bss->ie == NULL) {
833                 bss->ielen = 0;
834                 return -1;
835         }
836
837         memcpy(bss->ie, elem, elem_len);
838         bss->ielen = elem_len;
839         return 0;
840 }
841
842
843 static int test_driver_set_ap_wps_ie(void *priv, const struct wpabuf *beacon,
844                                      const struct wpabuf *proberesp,
845                                      const struct wpabuf *assocresp)
846 {
847         struct test_driver_bss *bss = priv;
848
849         if (beacon == NULL)
850                 wpa_printf(MSG_DEBUG, "test_driver: Clear Beacon WPS IE");
851         else
852                 wpa_hexdump_buf(MSG_DEBUG, "test_driver: Beacon WPS IE",
853                                 beacon);
854
855         os_free(bss->wps_beacon_ie);
856
857         if (beacon == NULL) {
858                 bss->wps_beacon_ie = NULL;
859                 bss->wps_beacon_ie_len = 0;
860         } else {
861                 bss->wps_beacon_ie = os_malloc(wpabuf_len(beacon));
862                 if (bss->wps_beacon_ie == NULL) {
863                         bss->wps_beacon_ie_len = 0;
864                         return -1;
865                 }
866
867                 os_memcpy(bss->wps_beacon_ie, wpabuf_head(beacon),
868                           wpabuf_len(beacon));
869                 bss->wps_beacon_ie_len = wpabuf_len(beacon);
870         }
871
872         if (proberesp == NULL)
873                 wpa_printf(MSG_DEBUG, "test_driver: Clear Probe Response WPS "
874                            "IE");
875         else
876                 wpa_hexdump_buf(MSG_DEBUG, "test_driver: Probe Response WPS "
877                                 "IE", proberesp);
878
879         os_free(bss->wps_probe_resp_ie);
880
881         if (proberesp == NULL) {
882                 bss->wps_probe_resp_ie = NULL;
883                 bss->wps_probe_resp_ie_len = 0;
884         } else {
885                 bss->wps_probe_resp_ie = os_malloc(wpabuf_len(proberesp));
886                 if (bss->wps_probe_resp_ie == NULL) {
887                         bss->wps_probe_resp_ie_len = 0;
888                         return -1;
889                 }
890
891                 os_memcpy(bss->wps_probe_resp_ie, wpabuf_head(proberesp),
892                           wpabuf_len(proberesp));
893                 bss->wps_probe_resp_ie_len = wpabuf_len(proberesp);
894         }
895
896         return 0;
897 }
898
899
900 static int test_driver_sta_deauth(void *priv, const u8 *own_addr,
901                                   const u8 *addr, int reason)
902 {
903         struct test_driver_bss *dbss = priv;
904         struct wpa_driver_test_data *drv = dbss->drv;
905         struct test_client_socket *cli;
906
907         if (drv->test_socket < 0)
908                 return -1;
909
910         cli = drv->cli;
911         while (cli) {
912                 if (memcmp(cli->addr, addr, ETH_ALEN) == 0)
913                         break;
914                 cli = cli->next;
915         }
916
917         if (!cli)
918                 return -1;
919
920         return sendto(drv->test_socket, "DEAUTH", 6, 0,
921                       (struct sockaddr *) &cli->un, cli->unlen);
922 }
923
924
925 static int test_driver_sta_disassoc(void *priv, const u8 *own_addr,
926                                     const u8 *addr, int reason)
927 {
928         struct test_driver_bss *dbss = priv;
929         struct wpa_driver_test_data *drv = dbss->drv;
930         struct test_client_socket *cli;
931
932         if (drv->test_socket < 0)
933                 return -1;
934
935         cli = drv->cli;
936         while (cli) {
937                 if (memcmp(cli->addr, addr, ETH_ALEN) == 0)
938                         break;
939                 cli = cli->next;
940         }
941
942         if (!cli)
943                 return -1;
944
945         return sendto(drv->test_socket, "DISASSOC", 8, 0,
946                       (struct sockaddr *) &cli->un, cli->unlen);
947 }
948
949
950 static int test_driver_bss_add(void *priv, const char *ifname, const u8 *bssid,
951                                void *bss_ctx, void **drv_priv)
952 {
953         struct test_driver_bss *dbss = priv;
954         struct wpa_driver_test_data *drv = dbss->drv;
955         struct test_driver_bss *bss;
956
957         wpa_printf(MSG_DEBUG, "%s(ifname=%s bssid=" MACSTR ")",
958                    __func__, ifname, MAC2STR(bssid));
959
960         bss = os_zalloc(sizeof(*bss));
961         if (bss == NULL)
962                 return -1;
963
964         bss->bss_ctx = bss_ctx;
965         bss->drv = drv;
966         os_strlcpy(bss->ifname, ifname, IFNAMSIZ);
967         os_memcpy(bss->bssid, bssid, ETH_ALEN);
968
969         dl_list_add(&drv->bss, &bss->list);
970         if (drv->global) {
971                 drv->global->bss_add_used = 1;
972                 os_memcpy(drv->global->req_addr, bssid, ETH_ALEN);
973         }
974
975         if (drv_priv)
976                 *drv_priv = bss;
977
978         return 0;
979 }
980
981
982 static int test_driver_bss_remove(void *priv, const char *ifname)
983 {
984         struct test_driver_bss *dbss = priv;
985         struct wpa_driver_test_data *drv = dbss->drv;
986         struct test_driver_bss *bss;
987         struct test_client_socket *cli, *prev_c;
988
989         wpa_printf(MSG_DEBUG, "%s(ifname=%s)", __func__, ifname);
990
991         dl_list_for_each(bss, &drv->bss, struct test_driver_bss, list) {
992                 if (strcmp(bss->ifname, ifname) != 0)
993                         continue;
994
995                 for (prev_c = NULL, cli = drv->cli; cli;
996                      prev_c = cli, cli = cli->next) {
997                         if (cli->bss != bss)
998                                 continue;
999                         if (prev_c)
1000                                 prev_c->next = cli->next;
1001                         else
1002                                 drv->cli = cli->next;
1003                         os_free(cli);
1004                         break;
1005                 }
1006
1007                 dl_list_del(&bss->list);
1008                 test_driver_free_bss(bss);
1009                 return 0;
1010         }
1011
1012         return -1;
1013 }
1014
1015
1016 static int test_driver_if_add(void *priv, enum wpa_driver_if_type type,
1017                               const char *ifname, const u8 *addr,
1018                               void *bss_ctx, void **drv_priv,
1019                               char *force_ifname, u8 *if_addr)
1020 {
1021         struct test_driver_bss *dbss = priv;
1022         struct wpa_driver_test_data *drv = dbss->drv;
1023
1024         wpa_printf(MSG_DEBUG, "%s(type=%d ifname=%s bss_ctx=%p)",
1025                    __func__, type, ifname, bss_ctx);
1026         if (addr)
1027                 os_memcpy(if_addr, addr, ETH_ALEN);
1028         else {
1029                 drv->alloc_iface_idx++;
1030                 if_addr[0] = 0x02; /* locally administered */
1031                 sha1_prf(drv->own_addr, ETH_ALEN,
1032                          "hostapd test addr generation",
1033                          (const u8 *) &drv->alloc_iface_idx,
1034                          sizeof(drv->alloc_iface_idx),
1035                          if_addr + 1, ETH_ALEN - 1);
1036         }
1037         if (type == WPA_IF_AP_BSS || type == WPA_IF_P2P_GO ||
1038             type == WPA_IF_P2P_CLIENT || type == WPA_IF_P2P_GROUP)
1039                 return test_driver_bss_add(priv, ifname, if_addr, bss_ctx,
1040                                            drv_priv);
1041         return 0;
1042 }
1043
1044
1045 static int test_driver_if_remove(void *priv, enum wpa_driver_if_type type,
1046                                  const char *ifname)
1047 {
1048         wpa_printf(MSG_DEBUG, "%s(type=%d ifname=%s)", __func__, type, ifname);
1049         if (type == WPA_IF_AP_BSS || type == WPA_IF_P2P_GO ||
1050             type == WPA_IF_P2P_CLIENT || type == WPA_IF_P2P_GROUP)
1051                 return test_driver_bss_remove(priv, ifname);
1052         return 0;
1053 }
1054
1055
1056 static int test_driver_valid_bss_mask(void *priv, const u8 *addr,
1057                                       const u8 *mask)
1058 {
1059         return 0;
1060 }
1061
1062
1063 static int test_driver_set_ssid(void *priv, const u8 *buf, int len)
1064 {
1065         struct test_driver_bss *bss = priv;
1066
1067         wpa_printf(MSG_DEBUG, "%s(ifname=%s)", __func__, bss->ifname);
1068         wpa_hexdump_ascii(MSG_DEBUG, "test_driver_set_ssid: SSID", buf, len);
1069
1070         if (len < 0 || (size_t) len > sizeof(bss->ssid))
1071                 return -1;
1072
1073         os_memcpy(bss->ssid, buf, len);
1074         bss->ssid_len = len;
1075
1076         return 0;
1077 }
1078
1079
1080 static int test_driver_set_privacy(void *priv, int enabled)
1081 {
1082         struct test_driver_bss *dbss = priv;
1083
1084         wpa_printf(MSG_DEBUG, "%s(enabled=%d)",  __func__, enabled);
1085         dbss->privacy = enabled;
1086
1087         return 0;
1088 }
1089
1090
1091 static int test_driver_set_sta_vlan(void *priv, const u8 *addr,
1092                                     const char *ifname, int vlan_id)
1093 {
1094         wpa_printf(MSG_DEBUG, "%s(addr=" MACSTR " ifname=%s vlan_id=%d)",
1095                    __func__, MAC2STR(addr), ifname, vlan_id);
1096         return 0;
1097 }
1098
1099
1100 static int test_driver_sta_add(void *priv,
1101                                struct hostapd_sta_add_params *params)
1102 {
1103         struct test_driver_bss *bss = priv;
1104         struct wpa_driver_test_data *drv = bss->drv;
1105         struct test_client_socket *cli;
1106
1107         wpa_printf(MSG_DEBUG, "%s(ifname=%s addr=" MACSTR " aid=%d "
1108                    "capability=0x%x listen_interval=%d)",
1109                    __func__, bss->ifname, MAC2STR(params->addr), params->aid,
1110                    params->capability, params->listen_interval);
1111         wpa_hexdump(MSG_DEBUG, "test_driver_sta_add - supp_rates",
1112                     params->supp_rates, params->supp_rates_len);
1113
1114         cli = drv->cli;
1115         while (cli) {
1116                 if (os_memcmp(cli->addr, params->addr, ETH_ALEN) == 0)
1117                         break;
1118                 cli = cli->next;
1119         }
1120         if (!cli) {
1121                 wpa_printf(MSG_DEBUG, "%s: no matching client entry",
1122                            __func__);
1123                 return -1;
1124         }
1125
1126         cli->bss = bss;
1127
1128         return 0;
1129 }
1130
1131
1132 static struct wpa_driver_test_data * test_alloc_data(void *ctx,
1133                                                      const char *ifname)
1134 {
1135         struct wpa_driver_test_data *drv;
1136         struct test_driver_bss *bss;
1137
1138         drv = os_zalloc(sizeof(struct wpa_driver_test_data));
1139         if (drv == NULL) {
1140                 wpa_printf(MSG_ERROR, "Could not allocate memory for test "
1141                            "driver data");
1142                 return NULL;
1143         }
1144
1145         bss = os_zalloc(sizeof(struct test_driver_bss));
1146         if (bss == NULL) {
1147                 os_free(drv);
1148                 return NULL;
1149         }
1150
1151         drv->ctx = ctx;
1152         wpa_trace_add_ref(drv, ctx, ctx);
1153         dl_list_init(&drv->bss);
1154         dl_list_add(&drv->bss, &bss->list);
1155         os_strlcpy(bss->ifname, ifname, IFNAMSIZ);
1156         bss->bss_ctx = ctx;
1157         bss->drv = drv;
1158
1159         /* Generate a MAC address to help testing with multiple STAs */
1160         drv->own_addr[0] = 0x02; /* locally administered */
1161         sha1_prf((const u8 *) ifname, os_strlen(ifname),
1162                  "test mac addr generation",
1163                  NULL, 0, drv->own_addr + 1, ETH_ALEN - 1);
1164
1165         return drv;
1166 }
1167
1168
1169 static void * test_driver_init(struct hostapd_data *hapd,
1170                                struct wpa_init_params *params)
1171 {
1172         struct wpa_driver_test_data *drv;
1173         struct sockaddr_un addr_un;
1174         struct sockaddr_in addr_in;
1175         struct sockaddr *addr;
1176         socklen_t alen;
1177         struct test_driver_bss *bss;
1178
1179         drv = test_alloc_data(hapd, params->ifname);
1180         if (drv == NULL)
1181                 return NULL;
1182         drv->ap = 1;
1183         bss = dl_list_first(&drv->bss, struct test_driver_bss, list);
1184
1185         bss->bss_ctx = hapd;
1186         os_memcpy(bss->bssid, drv->own_addr, ETH_ALEN);
1187         os_memcpy(params->own_addr, drv->own_addr, ETH_ALEN);
1188
1189         if (params->test_socket) {
1190                 if (os_strlen(params->test_socket) >=
1191                     sizeof(addr_un.sun_path)) {
1192                         printf("Too long test_socket path\n");
1193                         wpa_driver_test_deinit(bss);
1194                         return NULL;
1195                 }
1196                 if (strncmp(params->test_socket, "DIR:", 4) == 0) {
1197                         size_t len = strlen(params->test_socket) + 30;
1198                         drv->test_dir = os_strdup(params->test_socket + 4);
1199                         drv->own_socket_path = os_malloc(len);
1200                         if (drv->own_socket_path) {
1201                                 snprintf(drv->own_socket_path, len,
1202                                          "%s/AP-" MACSTR,
1203                                          params->test_socket + 4,
1204                                          MAC2STR(params->own_addr));
1205                         }
1206                 } else if (strncmp(params->test_socket, "UDP:", 4) == 0) {
1207                         drv->udp_port = atoi(params->test_socket + 4);
1208                 } else {
1209                         drv->own_socket_path = os_strdup(params->test_socket);
1210                 }
1211                 if (drv->own_socket_path == NULL && drv->udp_port == 0) {
1212                         wpa_driver_test_deinit(bss);
1213                         return NULL;
1214                 }
1215
1216                 drv->test_socket = socket(drv->udp_port ? PF_INET : PF_UNIX,
1217                                           SOCK_DGRAM, 0);
1218                 if (drv->test_socket < 0) {
1219                         perror("socket");
1220                         wpa_driver_test_deinit(bss);
1221                         return NULL;
1222                 }
1223
1224                 if (drv->udp_port) {
1225                         os_memset(&addr_in, 0, sizeof(addr_in));
1226                         addr_in.sin_family = AF_INET;
1227                         addr_in.sin_port = htons(drv->udp_port);
1228                         addr = (struct sockaddr *) &addr_in;
1229                         alen = sizeof(addr_in);
1230                 } else {
1231                         os_memset(&addr_un, 0, sizeof(addr_un));
1232                         addr_un.sun_family = AF_UNIX;
1233                         os_strlcpy(addr_un.sun_path, drv->own_socket_path,
1234                                    sizeof(addr_un.sun_path));
1235                         addr = (struct sockaddr *) &addr_un;
1236                         alen = sizeof(addr_un);
1237                 }
1238                 if (bind(drv->test_socket, addr, alen) < 0) {
1239                         perror("bind(PF_UNIX)");
1240                         close(drv->test_socket);
1241                         if (drv->own_socket_path)
1242                                 unlink(drv->own_socket_path);
1243                         wpa_driver_test_deinit(bss);
1244                         return NULL;
1245                 }
1246                 eloop_register_read_sock(drv->test_socket,
1247                                          test_driver_receive_unix, drv, NULL);
1248         } else
1249                 drv->test_socket = -1;
1250
1251         return bss;
1252 }
1253
1254
1255 static void wpa_driver_test_poll(void *eloop_ctx, void *timeout_ctx)
1256 {
1257         struct wpa_driver_test_data *drv = eloop_ctx;
1258
1259 #ifdef DRIVER_TEST_UNIX
1260         if (drv->associated && drv->hostapd_addr_set) {
1261                 struct stat st;
1262                 if (stat(drv->hostapd_addr.sun_path, &st) < 0) {
1263                         wpa_printf(MSG_DEBUG, "%s: lost connection to AP: %s",
1264                                    __func__, strerror(errno));
1265                         drv->associated = 0;
1266                         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1267                 }
1268         }
1269 #endif /* DRIVER_TEST_UNIX */
1270
1271         eloop_register_timeout(1, 0, wpa_driver_test_poll, drv, NULL);
1272 }
1273
1274
1275 static void wpa_driver_test_scan_timeout(void *eloop_ctx, void *timeout_ctx)
1276 {
1277         wpa_printf(MSG_DEBUG, "Scan timeout - try to get results");
1278         wpa_supplicant_event(timeout_ctx, EVENT_SCAN_RESULTS, NULL);
1279 }
1280
1281
1282 #ifdef DRIVER_TEST_UNIX
1283 static void wpa_driver_scan_dir(struct wpa_driver_test_data *drv,
1284                                 const char *path)
1285 {
1286         struct dirent *dent;
1287         DIR *dir;
1288         struct sockaddr_un addr;
1289         char cmd[512], *pos, *end;
1290         int ret;
1291
1292         dir = opendir(path);
1293         if (dir == NULL)
1294                 return;
1295
1296         end = cmd + sizeof(cmd);
1297         pos = cmd;
1298         ret = os_snprintf(pos, end - pos, "SCAN " MACSTR,
1299                           MAC2STR(drv->own_addr));
1300         if (ret >= 0 && ret < end - pos)
1301                 pos += ret;
1302         if (drv->probe_req_ie) {
1303                 ret = os_snprintf(pos, end - pos, " ");
1304                 if (ret >= 0 && ret < end - pos)
1305                         pos += ret;
1306                 pos += wpa_snprintf_hex(pos, end - pos, drv->probe_req_ie,
1307                                         drv->probe_req_ie_len);
1308         }
1309         if (drv->probe_req_ssid_len) {
1310                 /* Add SSID IE */
1311                 ret = os_snprintf(pos, end - pos, "%02x%02x",
1312                                   WLAN_EID_SSID,
1313                                   (unsigned int) drv->probe_req_ssid_len);
1314                 if (ret >= 0 && ret < end - pos)
1315                         pos += ret;
1316                 pos += wpa_snprintf_hex(pos, end - pos, drv->probe_req_ssid,
1317                                         drv->probe_req_ssid_len);
1318         }
1319         end[-1] = '\0';
1320
1321         while ((dent = readdir(dir))) {
1322                 if (os_strncmp(dent->d_name, "AP-", 3) != 0 &&
1323                     os_strncmp(dent->d_name, "STA-", 4) != 0)
1324                         continue;
1325                 if (drv->own_socket_path) {
1326                         size_t olen, dlen;
1327                         olen = os_strlen(drv->own_socket_path);
1328                         dlen = os_strlen(dent->d_name);
1329                         if (olen >= dlen &&
1330                             os_strcmp(dent->d_name,
1331                                       drv->own_socket_path + olen - dlen) == 0)
1332                                 continue;
1333                 }
1334                 wpa_printf(MSG_DEBUG, "%s: SCAN %s", __func__, dent->d_name);
1335
1336                 os_memset(&addr, 0, sizeof(addr));
1337                 addr.sun_family = AF_UNIX;
1338                 os_snprintf(addr.sun_path, sizeof(addr.sun_path), "%s/%s",
1339                             path, dent->d_name);
1340
1341                 if (sendto(drv->test_socket, cmd, os_strlen(cmd), 0,
1342                            (struct sockaddr *) &addr, sizeof(addr)) < 0) {
1343                         perror("sendto(test_socket)");
1344                 }
1345         }
1346         closedir(dir);
1347 }
1348 #endif /* DRIVER_TEST_UNIX */
1349
1350
1351 static int wpa_driver_test_scan(void *priv,
1352                                 struct wpa_driver_scan_params *params)
1353 {
1354         struct test_driver_bss *dbss = priv;
1355         struct wpa_driver_test_data *drv = dbss->drv;
1356         size_t i;
1357
1358         wpa_printf(MSG_DEBUG, "%s: priv=%p", __func__, priv);
1359
1360         os_free(drv->probe_req_ie);
1361         if (params->extra_ies) {
1362                 drv->probe_req_ie = os_malloc(params->extra_ies_len);
1363                 if (drv->probe_req_ie == NULL) {
1364                         drv->probe_req_ie_len = 0;
1365                         return -1;
1366                 }
1367                 os_memcpy(drv->probe_req_ie, params->extra_ies,
1368                           params->extra_ies_len);
1369                 drv->probe_req_ie_len = params->extra_ies_len;
1370         } else {
1371                 drv->probe_req_ie = NULL;
1372                 drv->probe_req_ie_len = 0;
1373         }
1374
1375         for (i = 0; i < params->num_ssids; i++)
1376                 wpa_hexdump(MSG_DEBUG, "Scan SSID",
1377                             params->ssids[i].ssid, params->ssids[i].ssid_len);
1378         drv->probe_req_ssid_len = 0;
1379         if (params->num_ssids) {
1380                 os_memcpy(drv->probe_req_ssid, params->ssids[0].ssid,
1381                           params->ssids[0].ssid_len);
1382                 drv->probe_req_ssid_len = params->ssids[0].ssid_len;
1383         }
1384         wpa_hexdump(MSG_DEBUG, "Scan extra IE(s)",
1385                     params->extra_ies, params->extra_ies_len);
1386
1387         drv->num_scanres = 0;
1388
1389 #ifdef DRIVER_TEST_UNIX
1390         if (drv->test_socket >= 0 && drv->test_dir)
1391                 wpa_driver_scan_dir(drv, drv->test_dir);
1392
1393         if (drv->test_socket >= 0 && drv->hostapd_addr_set &&
1394             sendto(drv->test_socket, "SCAN", 4, 0,
1395                    (struct sockaddr *) &drv->hostapd_addr,
1396                    sizeof(drv->hostapd_addr)) < 0) {
1397                 perror("sendto(test_socket)");
1398         }
1399 #endif /* DRIVER_TEST_UNIX */
1400
1401         if (drv->test_socket >= 0 && drv->hostapd_addr_udp_set &&
1402             sendto(drv->test_socket, "SCAN", 4, 0,
1403                    (struct sockaddr *) &drv->hostapd_addr_udp,
1404                    sizeof(drv->hostapd_addr_udp)) < 0) {
1405                 perror("sendto(test_socket)");
1406         }
1407
1408         eloop_cancel_timeout(wpa_driver_test_scan_timeout, drv, drv->ctx);
1409         eloop_register_timeout(1, 0, wpa_driver_test_scan_timeout, drv,
1410                                drv->ctx);
1411         return 0;
1412 }
1413
1414
1415 static struct wpa_scan_results * wpa_driver_test_get_scan_results2(void *priv)
1416 {
1417         struct test_driver_bss *dbss = priv;
1418         struct wpa_driver_test_data *drv = dbss->drv;
1419         struct wpa_scan_results *res;
1420         size_t i;
1421
1422         res = os_zalloc(sizeof(*res));
1423         if (res == NULL)
1424                 return NULL;
1425
1426         res->res = os_zalloc(drv->num_scanres * sizeof(struct wpa_scan_res *));
1427         if (res->res == NULL) {
1428                 os_free(res);
1429                 return NULL;
1430         }
1431
1432         for (i = 0; i < drv->num_scanres; i++) {
1433                 struct wpa_scan_res *r;
1434                 if (drv->scanres[i] == NULL)
1435                         continue;
1436                 r = os_malloc(sizeof(*r) + drv->scanres[i]->ie_len);
1437                 if (r == NULL)
1438                         break;
1439                 os_memcpy(r, drv->scanres[i],
1440                           sizeof(*r) + drv->scanres[i]->ie_len);
1441                 res->res[res->num++] = r;
1442         }
1443
1444         return res;
1445 }
1446
1447
1448 static int wpa_driver_test_set_key(const char *ifname, void *priv,
1449                                    enum wpa_alg alg, const u8 *addr,
1450                                    int key_idx, int set_tx,
1451                                    const u8 *seq, size_t seq_len,
1452                                    const u8 *key, size_t key_len)
1453 {
1454         wpa_printf(MSG_DEBUG, "%s: ifname=%s priv=%p alg=%d key_idx=%d "
1455                    "set_tx=%d",
1456                    __func__, ifname, priv, alg, key_idx, set_tx);
1457         if (addr)
1458                 wpa_printf(MSG_DEBUG, "   addr=" MACSTR, MAC2STR(addr));
1459         if (seq)
1460                 wpa_hexdump(MSG_DEBUG, "   seq", seq, seq_len);
1461         if (key)
1462                 wpa_hexdump_key(MSG_DEBUG, "   key", key, key_len);
1463         return 0;
1464 }
1465
1466
1467 static int wpa_driver_update_mode(struct wpa_driver_test_data *drv, int ap)
1468 {
1469         if (ap && !drv->ap) {
1470                 wpa_driver_test_close_test_socket(drv);
1471                 wpa_driver_test_attach(drv, drv->test_dir, 1);
1472                 drv->ap = 1;
1473         } else if (!ap && drv->ap) {
1474                 wpa_driver_test_close_test_socket(drv);
1475                 wpa_driver_test_attach(drv, drv->test_dir, 0);
1476                 drv->ap = 0;
1477         }
1478
1479         return 0;
1480 }
1481
1482
1483 static int wpa_driver_test_associate(
1484         void *priv, struct wpa_driver_associate_params *params)
1485 {
1486         struct test_driver_bss *dbss = priv;
1487         struct wpa_driver_test_data *drv = dbss->drv;
1488         wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d pairwise_suite=%d "
1489                    "group_suite=%d key_mgmt_suite=%d auth_alg=%d mode=%d",
1490                    __func__, priv, params->freq, params->pairwise_suite,
1491                    params->group_suite, params->key_mgmt_suite,
1492                    params->auth_alg, params->mode);
1493         wpa_driver_update_mode(drv, params->mode == IEEE80211_MODE_AP);
1494         if (params->bssid) {
1495                 wpa_printf(MSG_DEBUG, "   bssid=" MACSTR,
1496                            MAC2STR(params->bssid));
1497         }
1498         if (params->ssid) {
1499                 wpa_hexdump_ascii(MSG_DEBUG, "   ssid",
1500                                   params->ssid, params->ssid_len);
1501         }
1502         if (params->wpa_ie) {
1503                 wpa_hexdump(MSG_DEBUG, "   wpa_ie",
1504                             params->wpa_ie, params->wpa_ie_len);
1505                 drv->assoc_wpa_ie_len = params->wpa_ie_len;
1506                 if (drv->assoc_wpa_ie_len > sizeof(drv->assoc_wpa_ie))
1507                         drv->assoc_wpa_ie_len = sizeof(drv->assoc_wpa_ie);
1508                 os_memcpy(drv->assoc_wpa_ie, params->wpa_ie,
1509                           drv->assoc_wpa_ie_len);
1510         } else
1511                 drv->assoc_wpa_ie_len = 0;
1512
1513         wpa_driver_update_mode(drv, params->mode == IEEE80211_MODE_AP);
1514
1515         drv->ibss = params->mode == IEEE80211_MODE_IBSS;
1516         dbss->privacy = params->key_mgmt_suite &
1517                 (WPA_KEY_MGMT_IEEE8021X |
1518                  WPA_KEY_MGMT_PSK |
1519                  WPA_KEY_MGMT_WPA_NONE |
1520                  WPA_KEY_MGMT_FT_IEEE8021X |
1521                  WPA_KEY_MGMT_FT_PSK |
1522                  WPA_KEY_MGMT_IEEE8021X_SHA256 |
1523                  WPA_KEY_MGMT_PSK_SHA256);
1524         if (params->wep_key_len[params->wep_tx_keyidx])
1525                 dbss->privacy = 1;
1526
1527 #ifdef DRIVER_TEST_UNIX
1528         if (drv->test_dir && params->bssid &&
1529             params->mode != IEEE80211_MODE_IBSS) {
1530                 os_memset(&drv->hostapd_addr, 0, sizeof(drv->hostapd_addr));
1531                 drv->hostapd_addr.sun_family = AF_UNIX;
1532                 os_snprintf(drv->hostapd_addr.sun_path,
1533                             sizeof(drv->hostapd_addr.sun_path),
1534                             "%s/AP-" MACSTR,
1535                             drv->test_dir, MAC2STR(params->bssid));
1536                 drv->hostapd_addr_set = 1;
1537         }
1538 #endif /* DRIVER_TEST_UNIX */
1539
1540         if (params->mode == IEEE80211_MODE_AP) {
1541                 os_memcpy(dbss->ssid, params->ssid, params->ssid_len);
1542                 dbss->ssid_len = params->ssid_len;
1543                 os_memcpy(dbss->bssid, drv->own_addr, ETH_ALEN);
1544                 if (params->wpa_ie && params->wpa_ie_len) {
1545                         dbss->ie = os_malloc(params->wpa_ie_len);
1546                         if (dbss->ie) {
1547                                 os_memcpy(dbss->ie, params->wpa_ie,
1548                                           params->wpa_ie_len);
1549                                 dbss->ielen = params->wpa_ie_len;
1550                         }
1551                 }
1552         } else if (drv->test_socket >= 0 &&
1553                    (drv->hostapd_addr_set || drv->hostapd_addr_udp_set)) {
1554                 char cmd[200], *pos, *end;
1555                 int ret;
1556                 end = cmd + sizeof(cmd);
1557                 pos = cmd;
1558                 ret = os_snprintf(pos, end - pos, "ASSOC " MACSTR " ",
1559                                   MAC2STR(drv->own_addr));
1560                 if (ret >= 0 && ret < end - pos)
1561                         pos += ret;
1562                 pos += wpa_snprintf_hex(pos, end - pos, params->ssid,
1563                                         params->ssid_len);
1564                 ret = os_snprintf(pos, end - pos, " ");
1565                 if (ret >= 0 && ret < end - pos)
1566                         pos += ret;
1567                 pos += wpa_snprintf_hex(pos, end - pos, params->wpa_ie,
1568                                         params->wpa_ie_len);
1569                 end[-1] = '\0';
1570 #ifdef DRIVER_TEST_UNIX
1571                 if (drv->hostapd_addr_set &&
1572                     sendto(drv->test_socket, cmd, os_strlen(cmd), 0,
1573                            (struct sockaddr *) &drv->hostapd_addr,
1574                            sizeof(drv->hostapd_addr)) < 0) {
1575                         perror("sendto(test_socket)");
1576                         return -1;
1577                 }
1578 #endif /* DRIVER_TEST_UNIX */
1579                 if (drv->hostapd_addr_udp_set &&
1580                     sendto(drv->test_socket, cmd, os_strlen(cmd), 0,
1581                            (struct sockaddr *) &drv->hostapd_addr_udp,
1582                            sizeof(drv->hostapd_addr_udp)) < 0) {
1583                         perror("sendto(test_socket)");
1584                         return -1;
1585                 }
1586
1587                 os_memcpy(dbss->ssid, params->ssid, params->ssid_len);
1588                 dbss->ssid_len = params->ssid_len;
1589         } else {
1590                 drv->associated = 1;
1591                 if (params->mode == IEEE80211_MODE_IBSS) {
1592                         os_memcpy(dbss->ssid, params->ssid, params->ssid_len);
1593                         dbss->ssid_len = params->ssid_len;
1594                         if (params->bssid)
1595                                 os_memcpy(dbss->bssid, params->bssid,
1596                                           ETH_ALEN);
1597                         else {
1598                                 os_get_random(dbss->bssid, ETH_ALEN);
1599                                 dbss->bssid[0] &= ~0x01;
1600                                 dbss->bssid[0] |= 0x02;
1601                         }
1602                 }
1603                 wpa_supplicant_event(drv->ctx, EVENT_ASSOC, NULL);
1604         }
1605
1606         return 0;
1607 }
1608
1609
1610 static int wpa_driver_test_get_bssid(void *priv, u8 *bssid)
1611 {
1612         struct test_driver_bss *dbss = priv;
1613         os_memcpy(bssid, dbss->bssid, ETH_ALEN);
1614         return 0;
1615 }
1616
1617
1618 static int wpa_driver_test_get_ssid(void *priv, u8 *ssid)
1619 {
1620         struct test_driver_bss *dbss = priv;
1621         os_memcpy(ssid, dbss->ssid, 32);
1622         return dbss->ssid_len;
1623 }
1624
1625
1626 static int wpa_driver_test_send_disassoc(struct wpa_driver_test_data *drv)
1627 {
1628 #ifdef DRIVER_TEST_UNIX
1629         if (drv->test_socket >= 0 &&
1630             sendto(drv->test_socket, "DISASSOC", 8, 0,
1631                    (struct sockaddr *) &drv->hostapd_addr,
1632                    sizeof(drv->hostapd_addr)) < 0) {
1633                 perror("sendto(test_socket)");
1634                 return -1;
1635         }
1636 #endif /* DRIVER_TEST_UNIX */
1637         if (drv->test_socket >= 0 && drv->hostapd_addr_udp_set &&
1638             sendto(drv->test_socket, "DISASSOC", 8, 0,
1639                    (struct sockaddr *) &drv->hostapd_addr_udp,
1640                    sizeof(drv->hostapd_addr_udp)) < 0) {
1641                 perror("sendto(test_socket)");
1642                 return -1;
1643         }
1644         return 0;
1645 }
1646
1647
1648 static int wpa_driver_test_deauthenticate(void *priv, const u8 *addr,
1649                                           int reason_code)
1650 {
1651         struct test_driver_bss *dbss = priv;
1652         struct wpa_driver_test_data *drv = dbss->drv;
1653         wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
1654                    __func__, MAC2STR(addr), reason_code);
1655         os_memset(dbss->bssid, 0, ETH_ALEN);
1656         drv->associated = 0;
1657         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1658         return wpa_driver_test_send_disassoc(drv);
1659 }
1660
1661
1662 static int wpa_driver_test_disassociate(void *priv, const u8 *addr,
1663                                         int reason_code)
1664 {
1665         struct test_driver_bss *dbss = priv;
1666         struct wpa_driver_test_data *drv = dbss->drv;
1667         wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
1668                    __func__, MAC2STR(addr), reason_code);
1669         os_memset(dbss->bssid, 0, ETH_ALEN);
1670         drv->associated = 0;
1671         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1672         return wpa_driver_test_send_disassoc(drv);
1673 }
1674
1675
1676 static const u8 * wpa_scan_get_ie(const struct wpa_scan_res *res, u8 ie)
1677 {
1678         const u8 *end, *pos;
1679
1680         pos = (const u8 *) (res + 1);
1681         end = pos + res->ie_len;
1682
1683         while (pos + 1 < end) {
1684                 if (pos + 2 + pos[1] > end)
1685                         break;
1686                 if (pos[0] == ie)
1687                         return pos;
1688                 pos += 2 + pos[1];
1689         }
1690
1691         return NULL;
1692 }
1693
1694
1695 static void wpa_driver_test_scanresp(struct wpa_driver_test_data *drv,
1696                                      struct sockaddr *from,
1697                                      socklen_t fromlen,
1698                                      const char *data)
1699 {
1700         struct wpa_scan_res *res;
1701         const char *pos, *pos2;
1702         size_t len;
1703         u8 *ie_pos, *ie_start, *ie_end;
1704 #define MAX_IE_LEN 1000
1705         const u8 *ds_params;
1706
1707         wpa_printf(MSG_DEBUG, "test_driver: SCANRESP %s", data);
1708         if (drv->num_scanres >= MAX_SCAN_RESULTS) {
1709                 wpa_printf(MSG_DEBUG, "test_driver: No room for the new scan "
1710                            "result");
1711                 return;
1712         }
1713
1714         /* SCANRESP BSSID SSID IEs */
1715
1716         res = os_zalloc(sizeof(*res) + MAX_IE_LEN);
1717         if (res == NULL)
1718                 return;
1719         ie_start = ie_pos = (u8 *) (res + 1);
1720         ie_end = ie_pos + MAX_IE_LEN;
1721
1722         if (hwaddr_aton(data, res->bssid)) {
1723                 wpa_printf(MSG_DEBUG, "test_driver: invalid BSSID in scanres");
1724                 os_free(res);
1725                 return;
1726         }
1727
1728         pos = data + 17;
1729         while (*pos == ' ')
1730                 pos++;
1731         pos2 = os_strchr(pos, ' ');
1732         if (pos2 == NULL) {
1733                 wpa_printf(MSG_DEBUG, "test_driver: invalid SSID termination "
1734                            "in scanres");
1735                 os_free(res);
1736                 return;
1737         }
1738         len = (pos2 - pos) / 2;
1739         if (len > 32)
1740                 len = 32;
1741         /*
1742          * Generate SSID IE from the SSID field since this IE is not included
1743          * in the main IE field.
1744          */
1745         *ie_pos++ = WLAN_EID_SSID;
1746         *ie_pos++ = len;
1747         if (hexstr2bin(pos, ie_pos, len) < 0) {
1748                 wpa_printf(MSG_DEBUG, "test_driver: invalid SSID in scanres");
1749                 os_free(res);
1750                 return;
1751         }
1752         ie_pos += len;
1753
1754         pos = pos2 + 1;
1755         pos2 = os_strchr(pos, ' ');
1756         if (pos2 == NULL)
1757                 len = os_strlen(pos) / 2;
1758         else
1759                 len = (pos2 - pos) / 2;
1760         if ((int) len > ie_end - ie_pos)
1761                 len = ie_end - ie_pos;
1762         if (hexstr2bin(pos, ie_pos, len) < 0) {
1763                 wpa_printf(MSG_DEBUG, "test_driver: invalid IEs in scanres");
1764                 os_free(res);
1765                 return;
1766         }
1767         ie_pos += len;
1768         res->ie_len = ie_pos - ie_start;
1769
1770         if (pos2) {
1771                 pos = pos2 + 1;
1772                 while (*pos == ' ')
1773                         pos++;
1774                 if (os_strstr(pos, "PRIVACY"))
1775                         res->caps |= IEEE80211_CAP_PRIVACY;
1776                 if (os_strstr(pos, "IBSS"))
1777                         res->caps |= IEEE80211_CAP_IBSS;
1778         }
1779
1780         ds_params = wpa_scan_get_ie(res, WLAN_EID_DS_PARAMS);
1781         if (ds_params && ds_params[1] > 0) {
1782                 if (ds_params[2] >= 1 && ds_params[2] <= 13)
1783                         res->freq = 2407 + ds_params[2] * 5;
1784         }
1785
1786         os_free(drv->scanres[drv->num_scanres]);
1787         drv->scanres[drv->num_scanres++] = res;
1788 }
1789
1790
1791 static void wpa_driver_test_assocresp(struct wpa_driver_test_data *drv,
1792                                       struct sockaddr *from,
1793                                       socklen_t fromlen,
1794                                       const char *data)
1795 {
1796         struct test_driver_bss *bss;
1797
1798         bss = dl_list_first(&drv->bss, struct test_driver_bss, list);
1799
1800         /* ASSOCRESP BSSID <res> */
1801         if (hwaddr_aton(data, bss->bssid)) {
1802                 wpa_printf(MSG_DEBUG, "test_driver: invalid BSSID in "
1803                            "assocresp");
1804         }
1805         if (drv->use_associnfo) {
1806                 union wpa_event_data event;
1807                 os_memset(&event, 0, sizeof(event));
1808                 event.assoc_info.req_ies = drv->assoc_wpa_ie;
1809                 event.assoc_info.req_ies_len = drv->assoc_wpa_ie_len;
1810                 wpa_supplicant_event(drv->ctx, EVENT_ASSOCINFO, &event);
1811         }
1812         drv->associated = 1;
1813         wpa_supplicant_event(drv->ctx, EVENT_ASSOC, NULL);
1814 }
1815
1816
1817 static void wpa_driver_test_disassoc(struct wpa_driver_test_data *drv,
1818                                      struct sockaddr *from,
1819                                      socklen_t fromlen)
1820 {
1821         drv->associated = 0;
1822         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1823 }
1824
1825
1826 static void wpa_driver_test_eapol(struct wpa_driver_test_data *drv,
1827                                   struct sockaddr *from,
1828                                   socklen_t fromlen,
1829                                   const u8 *data, size_t data_len)
1830 {
1831         const u8 *src;
1832         struct test_driver_bss *bss;
1833
1834         bss = dl_list_first(&drv->bss, struct test_driver_bss, list);
1835
1836         if (data_len > 14) {
1837                 /* Skip Ethernet header */
1838                 src = data + ETH_ALEN;
1839                 data += 14;
1840                 data_len -= 14;
1841         } else
1842                 src = bss->bssid;
1843
1844         drv_event_eapol_rx(drv->ctx, src, data, data_len);
1845 }
1846
1847
1848 static void wpa_driver_test_mlme(struct wpa_driver_test_data *drv,
1849                                  struct sockaddr *from,
1850                                  socklen_t fromlen,
1851                                  const u8 *data, size_t data_len)
1852 {
1853         int freq = 0, own_freq;
1854         union wpa_event_data event;
1855         struct test_driver_bss *bss;
1856
1857         bss = dl_list_first(&drv->bss, struct test_driver_bss, list);
1858         if (data_len > 6 && os_memcmp(data, "freq=", 5) == 0) {
1859                 size_t pos;
1860                 for (pos = 5; pos < data_len; pos++) {
1861                         if (data[pos] == ' ')
1862                                 break;
1863                 }
1864                 if (pos < data_len) {
1865                         freq = atoi((const char *) &data[5]);
1866                         wpa_printf(MSG_DEBUG, "test_driver(%s): MLME RX on "
1867                                    "freq %d MHz", bss->ifname, freq);
1868                         pos++;
1869                         data += pos;
1870                         data_len -= pos;
1871                 }
1872         }
1873
1874         if (drv->remain_on_channel_freq)
1875                 own_freq = drv->remain_on_channel_freq;
1876         else
1877                 own_freq = drv->current_freq;
1878
1879         if (freq && own_freq && freq != own_freq) {
1880                 wpa_printf(MSG_DEBUG, "test_driver(%s): Ignore MLME RX on "
1881                            "another frequency %d MHz (own %d MHz)",
1882                            bss->ifname, freq, own_freq);
1883                 return;
1884         }
1885
1886         os_memset(&event, 0, sizeof(event));
1887         event.mlme_rx.buf = data;
1888         event.mlme_rx.len = data_len;
1889         event.mlme_rx.freq = freq;
1890         wpa_supplicant_event(drv->ctx, EVENT_MLME_RX, &event);
1891
1892         if (drv->probe_req_report && data_len >= 24) {
1893                 const struct ieee80211_mgmt *mgmt;
1894                 u16 fc;
1895
1896                 mgmt = (const struct ieee80211_mgmt *) data;
1897                 fc = le_to_host16(mgmt->frame_control);
1898                 if (WLAN_FC_GET_TYPE(fc) == WLAN_FC_TYPE_MGMT &&
1899                     WLAN_FC_GET_STYPE(fc) == WLAN_FC_STYPE_PROBE_REQ) {
1900                         os_memset(&event, 0, sizeof(event));
1901                         event.rx_probe_req.sa = mgmt->sa;
1902                         event.rx_probe_req.ie = mgmt->u.probe_req.variable;
1903                         event.rx_probe_req.ie_len =
1904                                 data_len - (mgmt->u.probe_req.variable - data);
1905                         wpa_supplicant_event(drv->ctx, EVENT_RX_PROBE_REQ,
1906                                              &event);
1907                 }
1908         }
1909 }
1910
1911
1912 static void wpa_driver_test_scan_cmd(struct wpa_driver_test_data *drv,
1913                                      struct sockaddr *from,
1914                                      socklen_t fromlen,
1915                                      const u8 *data, size_t data_len)
1916 {
1917         char buf[512], *pos, *end;
1918         int ret;
1919         struct test_driver_bss *bss;
1920
1921         bss = dl_list_first(&drv->bss, struct test_driver_bss, list);
1922
1923         /* data: optional [ STA-addr | ' ' | IEs(hex) ] */
1924
1925         if (!drv->ibss)
1926                 return;
1927
1928         pos = buf;
1929         end = buf + sizeof(buf);
1930
1931         /* reply: SCANRESP BSSID SSID IEs */
1932         ret = snprintf(pos, end - pos, "SCANRESP " MACSTR " ",
1933                        MAC2STR(bss->bssid));
1934         if (ret < 0 || ret >= end - pos)
1935                 return;
1936         pos += ret;
1937         pos += wpa_snprintf_hex(pos, end - pos,
1938                                 bss->ssid, bss->ssid_len);
1939         ret = snprintf(pos, end - pos, " ");
1940         if (ret < 0 || ret >= end - pos)
1941                 return;
1942         pos += ret;
1943         pos += wpa_snprintf_hex(pos, end - pos, drv->assoc_wpa_ie,
1944                                 drv->assoc_wpa_ie_len);
1945
1946         if (bss->privacy) {
1947                 ret = snprintf(pos, end - pos, " PRIVACY");
1948                 if (ret < 0 || ret >= end - pos)
1949                         return;
1950                 pos += ret;
1951         }
1952
1953         ret = snprintf(pos, end - pos, " IBSS");
1954         if (ret < 0 || ret >= end - pos)
1955                 return;
1956         pos += ret;
1957
1958         sendto(drv->test_socket, buf, pos - buf, 0,
1959                (struct sockaddr *) from, fromlen);
1960 }
1961
1962
1963 static void wpa_driver_test_receive_unix(int sock, void *eloop_ctx,
1964                                          void *sock_ctx)
1965 {
1966         struct wpa_driver_test_data *drv = eloop_ctx;
1967         char *buf;
1968         int res;
1969         struct sockaddr_storage from;
1970         socklen_t fromlen = sizeof(from);
1971         const size_t buflen = 2000;
1972
1973         if (drv->ap) {
1974                 test_driver_receive_unix(sock, eloop_ctx, sock_ctx);
1975                 return;
1976         }
1977
1978         buf = os_malloc(buflen);
1979         if (buf == NULL)
1980                 return;
1981         res = recvfrom(sock, buf, buflen - 1, 0,
1982                        (struct sockaddr *) &from, &fromlen);
1983         if (res < 0) {
1984                 perror("recvfrom(test_socket)");
1985                 os_free(buf);
1986                 return;
1987         }
1988         buf[res] = '\0';
1989
1990         wpa_printf(MSG_DEBUG, "test_driver: received %u bytes", res);
1991
1992         if (os_strncmp(buf, "SCANRESP ", 9) == 0) {
1993                 wpa_driver_test_scanresp(drv, (struct sockaddr *) &from,
1994                                          fromlen, buf + 9);
1995         } else if (os_strncmp(buf, "ASSOCRESP ", 10) == 0) {
1996                 wpa_driver_test_assocresp(drv, (struct sockaddr *) &from,
1997                                           fromlen, buf + 10);
1998         } else if (os_strcmp(buf, "DISASSOC") == 0) {
1999                 wpa_driver_test_disassoc(drv, (struct sockaddr *) &from,
2000                                          fromlen);
2001         } else if (os_strcmp(buf, "DEAUTH") == 0) {
2002                 wpa_driver_test_disassoc(drv, (struct sockaddr *) &from,
2003                                          fromlen);
2004         } else if (os_strncmp(buf, "EAPOL ", 6) == 0) {
2005                 wpa_driver_test_eapol(drv, (struct sockaddr *) &from, fromlen,
2006                                       (const u8 *) buf + 6, res - 6);
2007         } else if (os_strncmp(buf, "MLME ", 5) == 0) {
2008                 wpa_driver_test_mlme(drv, (struct sockaddr *) &from, fromlen,
2009                                      (const u8 *) buf + 5, res - 5);
2010         } else if (os_strncmp(buf, "SCAN ", 5) == 0) {
2011                 wpa_driver_test_scan_cmd(drv, (struct sockaddr *) &from,
2012                                          fromlen,
2013                                          (const u8 *) buf + 5, res - 5);
2014         } else {
2015                 wpa_hexdump_ascii(MSG_DEBUG, "Unknown test_socket command",
2016                                   (u8 *) buf, res);
2017         }
2018         os_free(buf);
2019 }
2020
2021
2022 static void * wpa_driver_test_init2(void *ctx, const char *ifname,
2023                                     void *global_priv)
2024 {
2025         struct wpa_driver_test_data *drv;
2026         struct wpa_driver_test_global *global = global_priv;
2027         struct test_driver_bss *bss;
2028
2029         drv = test_alloc_data(ctx, ifname);
2030         if (drv == NULL)
2031                 return NULL;
2032         bss = dl_list_first(&drv->bss, struct test_driver_bss, list);
2033         drv->global = global_priv;
2034         drv->test_socket = -1;
2035
2036         /* Set dummy BSSID and SSID for testing. */
2037         bss->bssid[0] = 0x02;
2038         bss->bssid[1] = 0x00;
2039         bss->bssid[2] = 0x00;
2040         bss->bssid[3] = 0x00;
2041         bss->bssid[4] = 0x00;
2042         bss->bssid[5] = 0x01;
2043         os_memcpy(bss->ssid, "test", 5);
2044         bss->ssid_len = 4;
2045
2046         if (global->bss_add_used) {
2047                 os_memcpy(drv->own_addr, global->req_addr, ETH_ALEN);
2048                 global->bss_add_used = 0;
2049         }
2050
2051         eloop_register_timeout(1, 0, wpa_driver_test_poll, drv, NULL);
2052
2053         return bss;
2054 }
2055
2056
2057 static void wpa_driver_test_close_test_socket(struct wpa_driver_test_data *drv)
2058 {
2059         if (drv->test_socket >= 0) {
2060                 eloop_unregister_read_sock(drv->test_socket);
2061                 close(drv->test_socket);
2062                 drv->test_socket = -1;
2063         }
2064
2065         if (drv->own_socket_path) {
2066                 unlink(drv->own_socket_path);
2067                 os_free(drv->own_socket_path);
2068                 drv->own_socket_path = NULL;
2069         }
2070 }
2071
2072
2073 static void wpa_driver_test_deinit(void *priv)
2074 {
2075         struct test_driver_bss *dbss = priv;
2076         struct wpa_driver_test_data *drv = dbss->drv;
2077         struct test_client_socket *cli, *prev;
2078         int i;
2079
2080         cli = drv->cli;
2081         while (cli) {
2082                 prev = cli;
2083                 cli = cli->next;
2084                 os_free(prev);
2085         }
2086
2087 #ifdef HOSTAPD
2088         /* There should be only one BSS remaining at this point. */
2089         if (dl_list_len(&drv->bss) != 1)
2090                 wpa_printf(MSG_ERROR, "%s: %u remaining BSS entries",
2091                            __func__, dl_list_len(&drv->bss));
2092 #endif /* HOSTAPD */
2093
2094         test_driver_free_bsses(drv);
2095
2096         wpa_driver_test_close_test_socket(drv);
2097         eloop_cancel_timeout(wpa_driver_test_scan_timeout, drv, drv->ctx);
2098         eloop_cancel_timeout(wpa_driver_test_poll, drv, NULL);
2099         eloop_cancel_timeout(test_remain_on_channel_timeout, drv, NULL);
2100         os_free(drv->test_dir);
2101         for (i = 0; i < MAX_SCAN_RESULTS; i++)
2102                 os_free(drv->scanres[i]);
2103         os_free(drv->probe_req_ie);
2104         wpa_trace_remove_ref(drv, ctx, drv->ctx);
2105         os_free(drv);
2106 }
2107
2108
2109 static int wpa_driver_test_attach(struct wpa_driver_test_data *drv,
2110                                   const char *dir, int ap)
2111 {
2112 #ifdef DRIVER_TEST_UNIX
2113         static unsigned int counter = 0;
2114         struct sockaddr_un addr;
2115         size_t len;
2116
2117         os_free(drv->own_socket_path);
2118         if (dir) {
2119                 len = os_strlen(dir) + 30;
2120                 drv->own_socket_path = os_malloc(len);
2121                 if (drv->own_socket_path == NULL)
2122                         return -1;
2123                 os_snprintf(drv->own_socket_path, len, "%s/%s-" MACSTR,
2124                             dir, ap ? "AP" : "STA", MAC2STR(drv->own_addr));
2125         } else {
2126                 drv->own_socket_path = os_malloc(100);
2127                 if (drv->own_socket_path == NULL)
2128                         return -1;
2129                 os_snprintf(drv->own_socket_path, 100,
2130                             "/tmp/wpa_supplicant_test-%d-%d",
2131                             getpid(), counter++);
2132         }
2133
2134         drv->test_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
2135         if (drv->test_socket < 0) {
2136                 perror("socket(PF_UNIX)");
2137                 os_free(drv->own_socket_path);
2138                 drv->own_socket_path = NULL;
2139                 return -1;
2140         }
2141
2142         os_memset(&addr, 0, sizeof(addr));
2143         addr.sun_family = AF_UNIX;
2144         os_strlcpy(addr.sun_path, drv->own_socket_path, sizeof(addr.sun_path));
2145         if (bind(drv->test_socket, (struct sockaddr *) &addr,
2146                  sizeof(addr)) < 0) {
2147                 perror("bind(PF_UNIX)");
2148                 close(drv->test_socket);
2149                 unlink(drv->own_socket_path);
2150                 os_free(drv->own_socket_path);
2151                 drv->own_socket_path = NULL;
2152                 return -1;
2153         }
2154
2155         eloop_register_read_sock(drv->test_socket,
2156                                  wpa_driver_test_receive_unix, drv, NULL);
2157
2158         return 0;
2159 #else /* DRIVER_TEST_UNIX */
2160         return -1;
2161 #endif /* DRIVER_TEST_UNIX */
2162 }
2163
2164
2165 static int wpa_driver_test_attach_udp(struct wpa_driver_test_data *drv,
2166                                       char *dst)
2167 {
2168         char *pos;
2169
2170         pos = os_strchr(dst, ':');
2171         if (pos == NULL)
2172                 return -1;
2173         *pos++ = '\0';
2174         wpa_printf(MSG_DEBUG, "%s: addr=%s port=%s", __func__, dst, pos);
2175
2176         drv->test_socket = socket(PF_INET, SOCK_DGRAM, 0);
2177         if (drv->test_socket < 0) {
2178                 perror("socket(PF_INET)");
2179                 return -1;
2180         }
2181
2182         os_memset(&drv->hostapd_addr_udp, 0, sizeof(drv->hostapd_addr_udp));
2183         drv->hostapd_addr_udp.sin_family = AF_INET;
2184 #if defined(CONFIG_NATIVE_WINDOWS) || defined(CONFIG_ANSI_C_EXTRA)
2185         {
2186                 int a[4];
2187                 u8 *pos;
2188                 sscanf(dst, "%d.%d.%d.%d", &a[0], &a[1], &a[2], &a[3]);
2189                 pos = (u8 *) &drv->hostapd_addr_udp.sin_addr;
2190                 *pos++ = a[0];
2191                 *pos++ = a[1];
2192                 *pos++ = a[2];
2193                 *pos++ = a[3];
2194         }
2195 #else /* CONFIG_NATIVE_WINDOWS or CONFIG_ANSI_C_EXTRA */
2196         inet_aton(dst, &drv->hostapd_addr_udp.sin_addr);
2197 #endif /* CONFIG_NATIVE_WINDOWS or CONFIG_ANSI_C_EXTRA */
2198         drv->hostapd_addr_udp.sin_port = htons(atoi(pos));
2199
2200         drv->hostapd_addr_udp_set = 1;
2201
2202         eloop_register_read_sock(drv->test_socket,
2203                                  wpa_driver_test_receive_unix, drv, NULL);
2204
2205         return 0;
2206 }
2207
2208
2209 static int wpa_driver_test_set_param(void *priv, const char *param)
2210 {
2211         struct test_driver_bss *dbss = priv;
2212         struct wpa_driver_test_data *drv = dbss->drv;
2213         const char *pos;
2214
2215         wpa_printf(MSG_DEBUG, "%s: param='%s'", __func__, param);
2216         if (param == NULL)
2217                 return 0;
2218
2219         wpa_driver_test_close_test_socket(drv);
2220
2221 #ifdef DRIVER_TEST_UNIX
2222         pos = os_strstr(param, "test_socket=");
2223         if (pos) {
2224                 const char *pos2;
2225                 size_t len;
2226
2227                 pos += 12;
2228                 pos2 = os_strchr(pos, ' ');
2229                 if (pos2)
2230                         len = pos2 - pos;
2231                 else
2232                         len = os_strlen(pos);
2233                 if (len > sizeof(drv->hostapd_addr.sun_path))
2234                         return -1;
2235                 os_memset(&drv->hostapd_addr, 0, sizeof(drv->hostapd_addr));
2236                 drv->hostapd_addr.sun_family = AF_UNIX;
2237                 os_memcpy(drv->hostapd_addr.sun_path, pos, len);
2238                 drv->hostapd_addr_set = 1;
2239         }
2240 #endif /* DRIVER_TEST_UNIX */
2241
2242         pos = os_strstr(param, "test_dir=");
2243         if (pos) {
2244                 char *end;
2245                 os_free(drv->test_dir);
2246                 drv->test_dir = os_strdup(pos + 9);
2247                 if (drv->test_dir == NULL)
2248                         return -1;
2249                 end = os_strchr(drv->test_dir, ' ');
2250                 if (end)
2251                         *end = '\0';
2252                 if (wpa_driver_test_attach(drv, drv->test_dir, 0))
2253                         return -1;
2254         } else {
2255                 pos = os_strstr(param, "test_udp=");
2256                 if (pos) {
2257                         char *dst, *epos;
2258                         dst = os_strdup(pos + 9);
2259                         if (dst == NULL)
2260                                 return -1;
2261                         epos = os_strchr(dst, ' ');
2262                         if (epos)
2263                                 *epos = '\0';
2264                         if (wpa_driver_test_attach_udp(drv, dst))
2265                                 return -1;
2266                         os_free(dst);
2267                 } else if (wpa_driver_test_attach(drv, NULL, 0))
2268                         return -1;
2269         }
2270
2271         if (os_strstr(param, "use_associnfo=1")) {
2272                 wpa_printf(MSG_DEBUG, "test_driver: Use AssocInfo events");
2273                 drv->use_associnfo = 1;
2274         }
2275
2276 #ifdef CONFIG_CLIENT_MLME
2277         if (os_strstr(param, "use_mlme=1")) {
2278                 wpa_printf(MSG_DEBUG, "test_driver: Use internal MLME");
2279                 drv->use_mlme = 1;
2280         }
2281 #endif /* CONFIG_CLIENT_MLME */
2282
2283         return 0;
2284 }
2285
2286
2287 static const u8 * wpa_driver_test_get_mac_addr(void *priv)
2288 {
2289         struct test_driver_bss *dbss = priv;
2290         struct wpa_driver_test_data *drv = dbss->drv;
2291         wpa_printf(MSG_DEBUG, "%s", __func__);
2292         return drv->own_addr;
2293 }
2294
2295
2296 static int wpa_driver_test_send_eapol(void *priv, const u8 *dest, u16 proto,
2297                                       const u8 *data, size_t data_len)
2298 {
2299         struct test_driver_bss *dbss = priv;
2300         struct wpa_driver_test_data *drv = dbss->drv;
2301         char *msg;
2302         size_t msg_len;
2303         struct l2_ethhdr eth;
2304         struct sockaddr *addr;
2305         socklen_t alen;
2306 #ifdef DRIVER_TEST_UNIX
2307         struct sockaddr_un addr_un;
2308 #endif /* DRIVER_TEST_UNIX */
2309
2310         wpa_hexdump(MSG_MSGDUMP, "test_send_eapol TX frame", data, data_len);
2311
2312         os_memset(&eth, 0, sizeof(eth));
2313         os_memcpy(eth.h_dest, dest, ETH_ALEN);
2314         os_memcpy(eth.h_source, drv->own_addr, ETH_ALEN);
2315         eth.h_proto = host_to_be16(proto);
2316
2317         msg_len = 6 + sizeof(eth) + data_len;
2318         msg = os_malloc(msg_len);
2319         if (msg == NULL)
2320                 return -1;
2321         os_memcpy(msg, "EAPOL ", 6);
2322         os_memcpy(msg + 6, &eth, sizeof(eth));
2323         os_memcpy(msg + 6 + sizeof(eth), data, data_len);
2324
2325         if (os_memcmp(dest, dbss->bssid, ETH_ALEN) == 0 ||
2326             drv->test_dir == NULL) {
2327                 if (drv->hostapd_addr_udp_set) {
2328                         addr = (struct sockaddr *) &drv->hostapd_addr_udp;
2329                         alen = sizeof(drv->hostapd_addr_udp);
2330                 } else {
2331 #ifdef DRIVER_TEST_UNIX
2332                         addr = (struct sockaddr *) &drv->hostapd_addr;
2333                         alen = sizeof(drv->hostapd_addr);
2334 #else /* DRIVER_TEST_UNIX */
2335                         os_free(msg);
2336                         return -1;
2337 #endif /* DRIVER_TEST_UNIX */
2338                 }
2339         } else {
2340 #ifdef DRIVER_TEST_UNIX
2341                 struct stat st;
2342                 os_memset(&addr_un, 0, sizeof(addr_un));
2343                 addr_un.sun_family = AF_UNIX;
2344                 os_snprintf(addr_un.sun_path, sizeof(addr_un.sun_path),
2345                             "%s/STA-" MACSTR, drv->test_dir, MAC2STR(dest));
2346                 if (stat(addr_un.sun_path, &st) < 0) {
2347                         os_snprintf(addr_un.sun_path, sizeof(addr_un.sun_path),
2348                                     "%s/AP-" MACSTR,
2349                                     drv->test_dir, MAC2STR(dest));
2350                 }
2351                 addr = (struct sockaddr *) &addr_un;
2352                 alen = sizeof(addr_un);
2353 #else /* DRIVER_TEST_UNIX */
2354                 os_free(msg);
2355                 return -1;
2356 #endif /* DRIVER_TEST_UNIX */
2357         }
2358
2359         if (sendto(drv->test_socket, msg, msg_len, 0, addr, alen) < 0) {
2360                 perror("sendmsg(test_socket)");
2361                 os_free(msg);
2362                 return -1;
2363         }
2364
2365         os_free(msg);
2366         return 0;
2367 }
2368
2369
2370 static int wpa_driver_test_get_capa(void *priv, struct wpa_driver_capa *capa)
2371 {
2372         struct test_driver_bss *dbss = priv;
2373         struct wpa_driver_test_data *drv = dbss->drv;
2374         os_memset(capa, 0, sizeof(*capa));
2375         capa->key_mgmt = WPA_DRIVER_CAPA_KEY_MGMT_WPA |
2376                 WPA_DRIVER_CAPA_KEY_MGMT_WPA2 |
2377                 WPA_DRIVER_CAPA_KEY_MGMT_WPA_PSK |
2378                 WPA_DRIVER_CAPA_KEY_MGMT_WPA2_PSK |
2379                 WPA_DRIVER_CAPA_KEY_MGMT_WPA_NONE |
2380                 WPA_DRIVER_CAPA_KEY_MGMT_FT |
2381                 WPA_DRIVER_CAPA_KEY_MGMT_FT_PSK;
2382         capa->enc = WPA_DRIVER_CAPA_ENC_WEP40 |
2383                 WPA_DRIVER_CAPA_ENC_WEP104 |
2384                 WPA_DRIVER_CAPA_ENC_TKIP |
2385                 WPA_DRIVER_CAPA_ENC_CCMP;
2386         capa->auth = WPA_DRIVER_AUTH_OPEN |
2387                 WPA_DRIVER_AUTH_SHARED |
2388                 WPA_DRIVER_AUTH_LEAP;
2389         if (drv->use_mlme)
2390                 capa->flags |= WPA_DRIVER_FLAGS_USER_SPACE_MLME;
2391         capa->flags |= WPA_DRIVER_FLAGS_AP;
2392         capa->flags |= WPA_DRIVER_FLAGS_P2P_CONCURRENT;
2393         capa->flags |= WPA_DRIVER_FLAGS_P2P_DEDICATED_INTERFACE;
2394         capa->flags |= WPA_DRIVER_FLAGS_P2P_CAPABLE;
2395         capa->max_scan_ssids = 2;
2396         capa->max_remain_on_chan = 60000;
2397
2398         return 0;
2399 }
2400
2401
2402 static int wpa_driver_test_mlme_setprotection(void *priv, const u8 *addr,
2403                                               int protect_type,
2404                                               int key_type)
2405 {
2406         wpa_printf(MSG_DEBUG, "%s: protect_type=%d key_type=%d",
2407                    __func__, protect_type, key_type);
2408
2409         if (addr) {
2410                 wpa_printf(MSG_DEBUG, "%s: addr=" MACSTR,
2411                            __func__, MAC2STR(addr));
2412         }
2413
2414         return 0;
2415 }
2416
2417
2418 static int wpa_driver_test_set_channel(void *priv,
2419                                        enum hostapd_hw_mode phymode,
2420                                        int chan, int freq)
2421 {
2422         struct test_driver_bss *dbss = priv;
2423         struct wpa_driver_test_data *drv = dbss->drv;
2424         wpa_printf(MSG_DEBUG, "%s: phymode=%d chan=%d freq=%d",
2425                    __func__, phymode, chan, freq);
2426         drv->current_freq = freq;
2427         return 0;
2428 }
2429
2430
2431 static int wpa_driver_test_mlme_add_sta(void *priv, const u8 *addr,
2432                                         const u8 *supp_rates,
2433                                         size_t supp_rates_len)
2434 {
2435         wpa_printf(MSG_DEBUG, "%s: addr=" MACSTR, __func__, MAC2STR(addr));
2436         return 0;
2437 }
2438
2439
2440 static int wpa_driver_test_mlme_remove_sta(void *priv, const u8 *addr)
2441 {
2442         wpa_printf(MSG_DEBUG, "%s: addr=" MACSTR, __func__, MAC2STR(addr));
2443         return 0;
2444 }
2445
2446
2447 static int wpa_driver_test_set_ssid(void *priv, const u8 *ssid,
2448                                     size_t ssid_len)
2449 {
2450         wpa_printf(MSG_DEBUG, "%s", __func__);
2451         return 0;
2452 }
2453
2454
2455 static int wpa_driver_test_set_bssid(void *priv, const u8 *bssid)
2456 {
2457         wpa_printf(MSG_DEBUG, "%s: bssid=" MACSTR, __func__, MAC2STR(bssid));
2458         return 0;
2459 }
2460
2461
2462 static void * wpa_driver_test_global_init(void)
2463 {
2464         struct wpa_driver_test_global *global;
2465
2466         global = os_zalloc(sizeof(*global));
2467         return global;
2468 }
2469
2470
2471 static void wpa_driver_test_global_deinit(void *priv)
2472 {
2473         struct wpa_driver_test_global *global = priv;
2474         os_free(global);
2475 }
2476
2477
2478 static struct wpa_interface_info *
2479 wpa_driver_test_get_interfaces(void *global_priv)
2480 {
2481         /* struct wpa_driver_test_global *global = priv; */
2482         struct wpa_interface_info *iface;
2483
2484         iface = os_zalloc(sizeof(*iface));
2485         if (iface == NULL)
2486                 return iface;
2487         iface->ifname = os_strdup("sta0");
2488         iface->desc = os_strdup("test interface 0");
2489         iface->drv_name = "test";
2490         iface->next = os_zalloc(sizeof(*iface));
2491         if (iface->next) {
2492                 iface->next->ifname = os_strdup("sta1");
2493                 iface->next->desc = os_strdup("test interface 1");
2494                 iface->next->drv_name = "test";
2495         }
2496
2497         return iface;
2498 }
2499
2500
2501 static struct hostapd_hw_modes *
2502 wpa_driver_test_get_hw_feature_data(void *priv, u16 *num_modes, u16 *flags)
2503 {
2504         struct hostapd_hw_modes *modes;
2505         size_t i;
2506
2507         *num_modes = 3;
2508         *flags = 0;
2509         modes = os_zalloc(*num_modes * sizeof(struct hostapd_hw_modes));
2510         if (modes == NULL)
2511                 return NULL;
2512         modes[0].mode = HOSTAPD_MODE_IEEE80211G;
2513         modes[0].num_channels = 11;
2514         modes[0].num_rates = 12;
2515         modes[0].channels =
2516                 os_zalloc(11 * sizeof(struct hostapd_channel_data));
2517         modes[0].rates = os_zalloc(modes[0].num_rates * sizeof(int));
2518         if (modes[0].channels == NULL || modes[0].rates == NULL)
2519                 goto fail;
2520         for (i = 0; i < 11; i++) {
2521                 modes[0].channels[i].chan = i + 1;
2522                 modes[0].channels[i].freq = 2412 + 5 * i;
2523                 modes[0].channels[i].flag = 0;
2524         }
2525         modes[0].rates[0] = 10;
2526         modes[0].rates[1] = 20;
2527         modes[0].rates[2] = 55;
2528         modes[0].rates[3] = 110;
2529         modes[0].rates[4] = 60;
2530         modes[0].rates[5] = 90;
2531         modes[0].rates[6] = 120;
2532         modes[0].rates[7] = 180;
2533         modes[0].rates[8] = 240;
2534         modes[0].rates[9] = 360;
2535         modes[0].rates[10] = 480;
2536         modes[0].rates[11] = 540;
2537
2538         modes[1].mode = HOSTAPD_MODE_IEEE80211B;
2539         modes[1].num_channels = 11;
2540         modes[1].num_rates = 4;
2541         modes[1].channels =
2542                 os_zalloc(11 * sizeof(struct hostapd_channel_data));
2543         modes[1].rates = os_zalloc(modes[1].num_rates * sizeof(int));
2544         if (modes[1].channels == NULL || modes[1].rates == NULL)
2545                 goto fail;
2546         for (i = 0; i < 11; i++) {
2547                 modes[1].channels[i].chan = i + 1;
2548                 modes[1].channels[i].freq = 2412 + 5 * i;
2549                 modes[1].channels[i].flag = 0;
2550         }
2551         modes[1].rates[0] = 10;
2552         modes[1].rates[1] = 20;
2553         modes[1].rates[2] = 55;
2554         modes[1].rates[3] = 110;
2555
2556         modes[2].mode = HOSTAPD_MODE_IEEE80211A;
2557         modes[2].num_channels = 1;
2558         modes[2].num_rates = 8;
2559         modes[2].channels = os_zalloc(sizeof(struct hostapd_channel_data));
2560         modes[2].rates = os_zalloc(modes[2].num_rates * sizeof(int));
2561         if (modes[2].channels == NULL || modes[2].rates == NULL)
2562                 goto fail;
2563         modes[2].channels[0].chan = 60;
2564         modes[2].channels[0].freq = 5300;
2565         modes[2].channels[0].flag = 0;
2566         modes[2].rates[0] = 60;
2567         modes[2].rates[1] = 90;
2568         modes[2].rates[2] = 120;
2569         modes[2].rates[3] = 180;
2570         modes[2].rates[4] = 240;
2571         modes[2].rates[5] = 360;
2572         modes[2].rates[6] = 480;
2573         modes[2].rates[7] = 540;
2574
2575         return modes;
2576
2577 fail:
2578         if (modes) {
2579                 for (i = 0; i < *num_modes; i++) {
2580                         os_free(modes[i].channels);
2581                         os_free(modes[i].rates);
2582                 }
2583                 os_free(modes);
2584         }
2585         return NULL;
2586 }
2587
2588
2589 static int wpa_driver_test_set_freq(void *priv,
2590                                     struct hostapd_freq_params *freq)
2591 {
2592         struct test_driver_bss *dbss = priv;
2593         struct wpa_driver_test_data *drv = dbss->drv;
2594         wpa_printf(MSG_DEBUG, "test: set_freq %u MHz", freq->freq);
2595         drv->current_freq = freq->freq;
2596         return 0;
2597 }
2598
2599
2600 static int wpa_driver_test_send_action(void *priv, unsigned int freq,
2601                                        const u8 *dst, const u8 *src,
2602                                        const u8 *bssid,
2603                                        const u8 *data, size_t data_len)
2604 {
2605         struct test_driver_bss *dbss = priv;
2606         struct wpa_driver_test_data *drv = dbss->drv;
2607         int ret = -1;
2608         u8 *buf;
2609         struct ieee80211_hdr *hdr;
2610
2611         wpa_printf(MSG_DEBUG, "test: Send Action frame");
2612
2613         if ((drv->remain_on_channel_freq &&
2614              freq != drv->remain_on_channel_freq) ||
2615             (drv->remain_on_channel_freq == 0 &&
2616              freq != (unsigned int) drv->current_freq)) {
2617                 wpa_printf(MSG_DEBUG, "test: Reject Action frame TX on "
2618                            "unexpected channel: freq=%u MHz (current_freq=%u "
2619                            "MHz, remain-on-channel freq=%u MHz)",
2620                            freq, drv->current_freq,
2621                            drv->remain_on_channel_freq);
2622                 return -1;
2623         }
2624
2625         buf = os_zalloc(24 + data_len);
2626         if (buf == NULL)
2627                 return ret;
2628         os_memcpy(buf + 24, data, data_len);
2629         hdr = (struct ieee80211_hdr *) buf;
2630         hdr->frame_control =
2631                 IEEE80211_FC(WLAN_FC_TYPE_MGMT, WLAN_FC_STYPE_ACTION);
2632         os_memcpy(hdr->addr1, dst, ETH_ALEN);
2633         os_memcpy(hdr->addr2, src, ETH_ALEN);
2634         os_memcpy(hdr->addr3, bssid, ETH_ALEN);
2635
2636         ret = wpa_driver_test_send_mlme(priv, buf, 24 + data_len);
2637         os_free(buf);
2638         return ret;
2639 }
2640
2641
2642 static void test_remain_on_channel_timeout(void *eloop_ctx, void *timeout_ctx)
2643 {
2644         struct wpa_driver_test_data *drv = eloop_ctx;
2645         union wpa_event_data data;
2646
2647         wpa_printf(MSG_DEBUG, "test: Remain-on-channel timeout");
2648
2649         os_memset(&data, 0, sizeof(data));
2650         data.remain_on_channel.freq = drv->remain_on_channel_freq;
2651         data.remain_on_channel.duration = drv->remain_on_channel_duration;
2652         wpa_supplicant_event(drv->ctx, EVENT_CANCEL_REMAIN_ON_CHANNEL, &data);
2653
2654         drv->remain_on_channel_freq = 0;
2655 }
2656
2657
2658 static int wpa_driver_test_remain_on_channel(void *priv, unsigned int freq,
2659                                              unsigned int duration)
2660 {
2661         struct test_driver_bss *dbss = priv;
2662         struct wpa_driver_test_data *drv = dbss->drv;
2663         union wpa_event_data data;
2664
2665         wpa_printf(MSG_DEBUG, "%s(freq=%u, duration=%u)",
2666                    __func__, freq, duration);
2667         if (drv->remain_on_channel_freq &&
2668             drv->remain_on_channel_freq != freq) {
2669                 wpa_printf(MSG_DEBUG, "test: Refuse concurrent "
2670                            "remain_on_channel request");
2671                 return -1;
2672         }
2673
2674         drv->remain_on_channel_freq = freq;
2675         drv->remain_on_channel_duration = duration;
2676         eloop_cancel_timeout(test_remain_on_channel_timeout, drv, NULL);
2677         eloop_register_timeout(duration / 1000, (duration % 1000) * 1000,
2678                                test_remain_on_channel_timeout, drv, NULL);
2679
2680         os_memset(&data, 0, sizeof(data));
2681         data.remain_on_channel.freq = freq;
2682         data.remain_on_channel.duration = duration;
2683         wpa_supplicant_event(drv->ctx, EVENT_REMAIN_ON_CHANNEL, &data);
2684
2685         return 0;
2686 }
2687
2688
2689 static int wpa_driver_test_cancel_remain_on_channel(void *priv)
2690 {
2691         struct test_driver_bss *dbss = priv;
2692         struct wpa_driver_test_data *drv = dbss->drv;
2693         wpa_printf(MSG_DEBUG, "%s", __func__);
2694         if (!drv->remain_on_channel_freq)
2695                 return -1;
2696         drv->remain_on_channel_freq = 0;
2697         eloop_cancel_timeout(test_remain_on_channel_timeout, drv, NULL);
2698         return 0;
2699 }
2700
2701
2702 static int wpa_driver_test_probe_req_report(void *priv, int report)
2703 {
2704         struct test_driver_bss *dbss = priv;
2705         struct wpa_driver_test_data *drv = dbss->drv;
2706         wpa_printf(MSG_DEBUG, "%s(report=%d)", __func__, report);
2707         drv->probe_req_report = report;
2708         return 0;
2709 }
2710
2711
2712 const struct wpa_driver_ops wpa_driver_test_ops = {
2713         "test",
2714         "wpa_supplicant test driver",
2715         .hapd_init = test_driver_init,
2716         .hapd_deinit = wpa_driver_test_deinit,
2717         .hapd_send_eapol = test_driver_send_eapol,
2718         .send_mlme = wpa_driver_test_send_mlme,
2719         .set_generic_elem = test_driver_set_generic_elem,
2720         .sta_deauth = test_driver_sta_deauth,
2721         .sta_disassoc = test_driver_sta_disassoc,
2722         .get_hw_feature_data = wpa_driver_test_get_hw_feature_data,
2723         .if_add = test_driver_if_add,
2724         .if_remove = test_driver_if_remove,
2725         .valid_bss_mask = test_driver_valid_bss_mask,
2726         .hapd_set_ssid = test_driver_set_ssid,
2727         .set_privacy = test_driver_set_privacy,
2728         .set_sta_vlan = test_driver_set_sta_vlan,
2729         .sta_add = test_driver_sta_add,
2730         .send_ether = test_driver_send_ether,
2731         .set_ap_wps_ie = test_driver_set_ap_wps_ie,
2732         .get_bssid = wpa_driver_test_get_bssid,
2733         .get_ssid = wpa_driver_test_get_ssid,
2734         .set_key = wpa_driver_test_set_key,
2735         .deinit = wpa_driver_test_deinit,
2736         .set_param = wpa_driver_test_set_param,
2737         .deauthenticate = wpa_driver_test_deauthenticate,
2738         .disassociate = wpa_driver_test_disassociate,
2739         .associate = wpa_driver_test_associate,
2740         .get_capa = wpa_driver_test_get_capa,
2741         .get_mac_addr = wpa_driver_test_get_mac_addr,
2742         .send_eapol = wpa_driver_test_send_eapol,
2743         .mlme_setprotection = wpa_driver_test_mlme_setprotection,
2744         .set_channel = wpa_driver_test_set_channel,
2745         .set_ssid = wpa_driver_test_set_ssid,
2746         .set_bssid = wpa_driver_test_set_bssid,
2747         .mlme_add_sta = wpa_driver_test_mlme_add_sta,
2748         .mlme_remove_sta = wpa_driver_test_mlme_remove_sta,
2749         .get_scan_results2 = wpa_driver_test_get_scan_results2,
2750         .global_init = wpa_driver_test_global_init,
2751         .global_deinit = wpa_driver_test_global_deinit,
2752         .init2 = wpa_driver_test_init2,
2753         .get_interfaces = wpa_driver_test_get_interfaces,
2754         .scan2 = wpa_driver_test_scan,
2755         .set_freq = wpa_driver_test_set_freq,
2756         .send_action = wpa_driver_test_send_action,
2757         .remain_on_channel = wpa_driver_test_remain_on_channel,
2758         .cancel_remain_on_channel = wpa_driver_test_cancel_remain_on_channel,
2759         .probe_req_report = wpa_driver_test_probe_req_report,
2760 };