Use driver event, EVENT_EAPOL_RX, for EAPOL frame indication
[libeap.git] / src / drivers / driver_test.c
1 /*
2  * Testing driver interface for a simulated network driver
3  * Copyright (c) 2004-2009, Jouni Malinen <j@w1.fi>
4  *
5  * This program is free software; you can redistribute it and/or modify
6  * it under the terms of the GNU General Public License version 2 as
7  * published by the Free Software Foundation.
8  *
9  * Alternatively, this software may be distributed under the terms of BSD
10  * license.
11  *
12  * See README and COPYING for more details.
13  */
14
15 /* Make sure we get winsock2.h for Windows build to get sockaddr_storage */
16 #include "build_config.h"
17 #ifdef CONFIG_NATIVE_WINDOWS
18 #include <winsock2.h>
19 #endif /* CONFIG_NATIVE_WINDOWS */
20
21 #include "utils/includes.h"
22
23 #ifndef CONFIG_NATIVE_WINDOWS
24 #include <sys/un.h>
25 #include <dirent.h>
26 #include <sys/stat.h>
27 #define DRIVER_TEST_UNIX
28 #endif /* CONFIG_NATIVE_WINDOWS */
29
30 #include "utils/common.h"
31 #include "utils/eloop.h"
32 #include "utils/trace.h"
33 #include "common/ieee802_11_defs.h"
34 #include "crypto/sha1.h"
35 #include "l2_packet/l2_packet.h"
36 #include "driver.h"
37
38
39 struct test_client_socket {
40         struct test_client_socket *next;
41         u8 addr[ETH_ALEN];
42         struct sockaddr_un un;
43         socklen_t unlen;
44         struct test_driver_bss *bss;
45 };
46
47 struct test_driver_bss {
48         struct test_driver_bss *next;
49         void *bss_ctx;
50         char ifname[IFNAMSIZ + 1];
51         u8 bssid[ETH_ALEN];
52         u8 *ie;
53         size_t ielen;
54         u8 *wps_beacon_ie;
55         size_t wps_beacon_ie_len;
56         u8 *wps_probe_resp_ie;
57         size_t wps_probe_resp_ie_len;
58         u8 ssid[32];
59         size_t ssid_len;
60         int privacy;
61 };
62
63 struct wpa_driver_test_global {
64         int bss_add_used;
65         u8 req_addr[ETH_ALEN];
66 };
67
68 struct wpa_driver_test_data {
69         struct wpa_driver_test_global *global;
70         void *ctx;
71         WPA_TRACE_REF(ctx);
72         char ifname[IFNAMSIZ + 1];
73         u8 own_addr[ETH_ALEN];
74         int test_socket;
75 #ifdef DRIVER_TEST_UNIX
76         struct sockaddr_un hostapd_addr;
77 #endif /* DRIVER_TEST_UNIX */
78         int hostapd_addr_set;
79         struct sockaddr_in hostapd_addr_udp;
80         int hostapd_addr_udp_set;
81         char *own_socket_path;
82         char *test_dir;
83         u8 bssid[ETH_ALEN];
84         u8 ssid[32];
85         size_t ssid_len;
86 #define MAX_SCAN_RESULTS 30
87         struct wpa_scan_res *scanres[MAX_SCAN_RESULTS];
88         size_t num_scanres;
89         int use_associnfo;
90         u8 assoc_wpa_ie[80];
91         size_t assoc_wpa_ie_len;
92         int use_mlme;
93         int associated;
94         u8 *probe_req_ie;
95         size_t probe_req_ie_len;
96         int ibss;
97         int privacy;
98         int ap;
99
100         struct test_client_socket *cli;
101         struct test_driver_bss *bss;
102         int udp_port;
103
104         int alloc_iface_idx;
105
106         int probe_req_report;
107         unsigned int remain_on_channel_freq;
108         unsigned int remain_on_channel_duration;
109
110         int current_freq;
111 };
112
113
114 static void wpa_driver_test_deinit(void *priv);
115 static int wpa_driver_test_attach(struct wpa_driver_test_data *drv,
116                                   const char *dir, int ap);
117 static void wpa_driver_test_close_test_socket(
118         struct wpa_driver_test_data *drv);
119 static void test_remain_on_channel_timeout(void *eloop_ctx, void *timeout_ctx);
120
121
122 static void test_driver_free_bss(struct test_driver_bss *bss)
123 {
124         os_free(bss->ie);
125         os_free(bss->wps_beacon_ie);
126         os_free(bss->wps_probe_resp_ie);
127         os_free(bss);
128 }
129
130
131 static void test_driver_free_bsses(struct wpa_driver_test_data *drv)
132 {
133         struct test_driver_bss *bss, *prev_bss;
134
135         bss = drv->bss;
136         while (bss) {
137                 prev_bss = bss;
138                 bss = bss->next;
139                 test_driver_free_bss(prev_bss);
140         }
141
142         drv->bss = NULL;
143 }
144
145
146 static struct test_client_socket *
147 test_driver_get_cli(struct wpa_driver_test_data *drv, struct sockaddr_un *from,
148                     socklen_t fromlen)
149 {
150         struct test_client_socket *cli = drv->cli;
151
152         while (cli) {
153                 if (cli->unlen == fromlen &&
154                     strncmp(cli->un.sun_path, from->sun_path,
155                             fromlen - sizeof(cli->un.sun_family)) == 0)
156                         return cli;
157                 cli = cli->next;
158         }
159
160         return NULL;
161 }
162
163
164 static int test_driver_send_eapol(void *priv, const u8 *addr, const u8 *data,
165                                   size_t data_len, int encrypt,
166                                   const u8 *own_addr)
167 {
168         struct wpa_driver_test_data *drv = priv;
169         struct test_client_socket *cli;
170         struct msghdr msg;
171         struct iovec io[3];
172         struct l2_ethhdr eth;
173
174         if (drv->test_socket < 0)
175                 return -1;
176
177         cli = drv->cli;
178         while (cli) {
179                 if (memcmp(cli->addr, addr, ETH_ALEN) == 0)
180                         break;
181                 cli = cli->next;
182         }
183
184         if (!cli) {
185                 wpa_printf(MSG_DEBUG, "%s: no destination client entry",
186                            __func__);
187                 return -1;
188         }
189
190         memcpy(eth.h_dest, addr, ETH_ALEN);
191         memcpy(eth.h_source, own_addr, ETH_ALEN);
192         eth.h_proto = host_to_be16(ETH_P_EAPOL);
193
194         io[0].iov_base = "EAPOL ";
195         io[0].iov_len = 6;
196         io[1].iov_base = &eth;
197         io[1].iov_len = sizeof(eth);
198         io[2].iov_base = (u8 *) data;
199         io[2].iov_len = data_len;
200
201         memset(&msg, 0, sizeof(msg));
202         msg.msg_iov = io;
203         msg.msg_iovlen = 3;
204         msg.msg_name = &cli->un;
205         msg.msg_namelen = cli->unlen;
206         return sendmsg(drv->test_socket, &msg, 0);
207 }
208
209
210 static int test_driver_send_ether(void *priv, const u8 *dst, const u8 *src,
211                                   u16 proto, const u8 *data, size_t data_len)
212 {
213         struct wpa_driver_test_data *drv = priv;
214         struct msghdr msg;
215         struct iovec io[3];
216         struct l2_ethhdr eth;
217         char desttxt[30];
218         struct sockaddr_un addr;
219         struct dirent *dent;
220         DIR *dir;
221         int ret = 0, broadcast = 0, count = 0;
222
223         if (drv->test_socket < 0 || drv->test_dir == NULL) {
224                 wpa_printf(MSG_DEBUG, "%s: invalid parameters (sock=%d "
225                            "test_dir=%p)",
226                            __func__, drv->test_socket, drv->test_dir);
227                 return -1;
228         }
229
230         broadcast = memcmp(dst, "\xff\xff\xff\xff\xff\xff", ETH_ALEN) == 0;
231         snprintf(desttxt, sizeof(desttxt), MACSTR, MAC2STR(dst));
232
233         memcpy(eth.h_dest, dst, ETH_ALEN);
234         memcpy(eth.h_source, src, ETH_ALEN);
235         eth.h_proto = host_to_be16(proto);
236
237         io[0].iov_base = "ETHER ";
238         io[0].iov_len = 6;
239         io[1].iov_base = &eth;
240         io[1].iov_len = sizeof(eth);
241         io[2].iov_base = (u8 *) data;
242         io[2].iov_len = data_len;
243
244         memset(&msg, 0, sizeof(msg));
245         msg.msg_iov = io;
246         msg.msg_iovlen = 3;
247
248         dir = opendir(drv->test_dir);
249         if (dir == NULL) {
250                 perror("test_driver: opendir");
251                 return -1;
252         }
253         while ((dent = readdir(dir))) {
254 #ifdef _DIRENT_HAVE_D_TYPE
255                 /* Skip the file if it is not a socket. Also accept
256                  * DT_UNKNOWN (0) in case the C library or underlying file
257                  * system does not support d_type. */
258                 if (dent->d_type != DT_SOCK && dent->d_type != DT_UNKNOWN)
259                         continue;
260 #endif /* _DIRENT_HAVE_D_TYPE */
261                 if (strcmp(dent->d_name, ".") == 0 ||
262                     strcmp(dent->d_name, "..") == 0)
263                         continue;
264
265                 memset(&addr, 0, sizeof(addr));
266                 addr.sun_family = AF_UNIX;
267                 snprintf(addr.sun_path, sizeof(addr.sun_path), "%s/%s",
268                          drv->test_dir, dent->d_name);
269
270                 if (strcmp(addr.sun_path, drv->own_socket_path) == 0)
271                         continue;
272                 if (!broadcast && strstr(dent->d_name, desttxt) == NULL)
273                         continue;
274
275                 wpa_printf(MSG_DEBUG, "%s: Send ether frame to %s",
276                            __func__, dent->d_name);
277
278                 msg.msg_name = &addr;
279                 msg.msg_namelen = sizeof(addr);
280                 ret = sendmsg(drv->test_socket, &msg, 0);
281                 if (ret < 0)
282                         perror("driver_test: sendmsg");
283                 count++;
284         }
285         closedir(dir);
286
287         if (!broadcast && count == 0) {
288                 wpa_printf(MSG_DEBUG, "%s: Destination " MACSTR " not found",
289                            __func__, MAC2STR(dst));
290                 return -1;
291         }
292
293         return ret;
294 }
295
296
297 static int wpa_driver_test_send_mlme(void *priv, const u8 *data,
298                                      size_t data_len)
299 {
300         struct wpa_driver_test_data *drv = priv;
301         struct msghdr msg;
302         struct iovec io[2];
303         const u8 *dest;
304         struct sockaddr_un addr;
305         struct dirent *dent;
306         DIR *dir;
307         int broadcast;
308         int ret = 0;
309         struct ieee80211_hdr *hdr;
310         u16 fc;
311         char cmd[50];
312         int freq;
313 #ifdef HOSTAPD
314         char desttxt[30];
315 #endif /* HOSTAPD */
316         union wpa_event_data event;
317
318         wpa_hexdump(MSG_MSGDUMP, "test_send_mlme", data, data_len);
319         if (drv->test_socket < 0 || data_len < 10) {
320                 wpa_printf(MSG_DEBUG, "%s: invalid parameters (sock=%d len=%lu"
321                            " test_dir=%p)",
322                            __func__, drv->test_socket,
323                            (unsigned long) data_len,
324                            drv->test_dir);
325                 return -1;
326         }
327
328         dest = data + 4;
329         broadcast = os_memcmp(dest, "\xff\xff\xff\xff\xff\xff", ETH_ALEN) == 0;
330
331 #ifdef HOSTAPD
332         snprintf(desttxt, sizeof(desttxt), MACSTR, MAC2STR(dest));
333 #endif /* HOSTAPD */
334
335         if (drv->remain_on_channel_freq)
336                 freq = drv->remain_on_channel_freq;
337         else
338                 freq = drv->current_freq;
339         wpa_printf(MSG_DEBUG, "test_driver(%s): MLME TX on freq %d MHz",
340                    drv->ifname, freq);
341         os_snprintf(cmd, sizeof(cmd), "MLME freq=%d ", freq);
342         io[0].iov_base = cmd;
343         io[0].iov_len = os_strlen(cmd);
344         io[1].iov_base = (void *) data;
345         io[1].iov_len = data_len;
346
347         os_memset(&msg, 0, sizeof(msg));
348         msg.msg_iov = io;
349         msg.msg_iovlen = 2;
350
351 #ifdef HOSTAPD
352         if (drv->test_dir == NULL) {
353                 wpa_printf(MSG_DEBUG, "%s: test_dir == NULL", __func__);
354                 return -1;
355         }
356
357         dir = opendir(drv->test_dir);
358         if (dir == NULL) {
359                 perror("test_driver: opendir");
360                 return -1;
361         }
362         while ((dent = readdir(dir))) {
363 #ifdef _DIRENT_HAVE_D_TYPE
364                 /* Skip the file if it is not a socket. Also accept
365                  * DT_UNKNOWN (0) in case the C library or underlying file
366                  * system does not support d_type. */
367                 if (dent->d_type != DT_SOCK && dent->d_type != DT_UNKNOWN)
368                         continue;
369 #endif /* _DIRENT_HAVE_D_TYPE */
370                 if (os_strcmp(dent->d_name, ".") == 0 ||
371                     os_strcmp(dent->d_name, "..") == 0)
372                         continue;
373
374                 os_memset(&addr, 0, sizeof(addr));
375                 addr.sun_family = AF_UNIX;
376                 os_snprintf(addr.sun_path, sizeof(addr.sun_path), "%s/%s",
377                             drv->test_dir, dent->d_name);
378
379                 if (os_strcmp(addr.sun_path, drv->own_socket_path) == 0)
380                         continue;
381                 if (!broadcast && os_strstr(dent->d_name, desttxt) == NULL)
382                         continue;
383
384                 wpa_printf(MSG_DEBUG, "%s: Send management frame to %s",
385                            __func__, dent->d_name);
386
387                 msg.msg_name = &addr;
388                 msg.msg_namelen = sizeof(addr);
389                 ret = sendmsg(drv->test_socket, &msg, 0);
390                 if (ret < 0)
391                         perror("driver_test: sendmsg(test_socket)");
392         }
393         closedir(dir);
394 #else /* HOSTAPD */
395
396         if (os_memcmp(dest, drv->bssid, ETH_ALEN) == 0 ||
397             drv->test_dir == NULL) {
398                 if (drv->hostapd_addr_udp_set) {
399                         msg.msg_name = &drv->hostapd_addr_udp;
400                         msg.msg_namelen = sizeof(drv->hostapd_addr_udp);
401                 } else {
402 #ifdef DRIVER_TEST_UNIX
403                         msg.msg_name = &drv->hostapd_addr;
404                         msg.msg_namelen = sizeof(drv->hostapd_addr);
405 #endif /* DRIVER_TEST_UNIX */
406                 }
407         } else if (broadcast) {
408                 dir = opendir(drv->test_dir);
409                 if (dir == NULL)
410                         return -1;
411                 while ((dent = readdir(dir))) {
412 #ifdef _DIRENT_HAVE_D_TYPE
413                         /* Skip the file if it is not a socket.
414                          * Also accept DT_UNKNOWN (0) in case
415                          * the C library or underlying file
416                          * system does not support d_type. */
417                         if (dent->d_type != DT_SOCK &&
418                             dent->d_type != DT_UNKNOWN)
419                                 continue;
420 #endif /* _DIRENT_HAVE_D_TYPE */
421                         if (os_strcmp(dent->d_name, ".") == 0 ||
422                             os_strcmp(dent->d_name, "..") == 0)
423                                 continue;
424                         wpa_printf(MSG_DEBUG, "%s: Send broadcast MLME to %s",
425                                    __func__, dent->d_name);
426                         os_memset(&addr, 0, sizeof(addr));
427                         addr.sun_family = AF_UNIX;
428                         os_snprintf(addr.sun_path, sizeof(addr.sun_path),
429                                     "%s/%s", drv->test_dir, dent->d_name);
430
431                         msg.msg_name = &addr;
432                         msg.msg_namelen = sizeof(addr);
433
434                         ret = sendmsg(drv->test_socket, &msg, 0);
435                         if (ret < 0)
436                                 perror("driver_test: sendmsg(test_socket)");
437                 }
438                 closedir(dir);
439                 return ret;
440         } else {
441                 struct stat st;
442                 os_memset(&addr, 0, sizeof(addr));
443                 addr.sun_family = AF_UNIX;
444                 os_snprintf(addr.sun_path, sizeof(addr.sun_path),
445                             "%s/AP-" MACSTR, drv->test_dir, MAC2STR(dest));
446                 if (stat(addr.sun_path, &st) < 0) {
447                         os_snprintf(addr.sun_path, sizeof(addr.sun_path),
448                                     "%s/STA-" MACSTR,
449                                     drv->test_dir, MAC2STR(dest));
450                 }
451                 msg.msg_name = &addr;
452                 msg.msg_namelen = sizeof(addr);
453         }
454
455         if (sendmsg(drv->test_socket, &msg, 0) < 0) {
456                 perror("sendmsg(test_socket)");
457                 return -1;
458         }
459 #endif /* HOSTAPD */
460
461         hdr = (struct ieee80211_hdr *) data;
462         fc = le_to_host16(hdr->frame_control);
463
464         os_memset(&event, 0, sizeof(event));
465         event.tx_status.type = WLAN_FC_GET_TYPE(fc);
466         event.tx_status.stype = WLAN_FC_GET_STYPE(fc);
467         event.tx_status.dst = hdr->addr1;
468         event.tx_status.data = data;
469         event.tx_status.data_len = data_len;
470         event.tx_status.ack = ret >= 0;
471         wpa_supplicant_event(drv->ctx, EVENT_TX_STATUS, &event);
472
473         return ret;
474 }
475
476
477 static void test_driver_scan(struct wpa_driver_test_data *drv,
478                              struct sockaddr_un *from, socklen_t fromlen,
479                              char *data)
480 {
481         char buf[512], *pos, *end;
482         int ret;
483         struct test_driver_bss *bss;
484         u8 sa[ETH_ALEN];
485         u8 ie[512];
486         size_t ielen;
487         union wpa_event_data event;
488
489         /* data: optional [ ' ' | STA-addr | ' ' | IEs(hex) ] */
490
491         wpa_printf(MSG_DEBUG, "test_driver: SCAN");
492
493         if (*data) {
494                 if (*data != ' ' ||
495                     hwaddr_aton(data + 1, sa)) {
496                         wpa_printf(MSG_DEBUG, "test_driver: Unexpected SCAN "
497                                    "command format");
498                         return;
499                 }
500
501                 data += 18;
502                 while (*data == ' ')
503                         data++;
504                 ielen = os_strlen(data) / 2;
505                 if (ielen > sizeof(ie))
506                         ielen = sizeof(ie);
507                 if (hexstr2bin(data, ie, ielen) < 0)
508                         ielen = 0;
509
510                 wpa_printf(MSG_DEBUG, "test_driver: Scan from " MACSTR,
511                            MAC2STR(sa));
512                 wpa_hexdump(MSG_MSGDUMP, "test_driver: scan IEs", ie, ielen);
513
514                 os_memset(&event, 0, sizeof(event));
515                 event.rx_probe_req.sa = sa;
516                 event.rx_probe_req.ie = ie;
517                 event.rx_probe_req.ie_len = ielen;
518                 wpa_supplicant_event(drv->ctx, EVENT_RX_PROBE_REQ, &event);
519         }
520
521         for (bss = drv->bss; bss; bss = bss->next) {
522                 pos = buf;
523                 end = buf + sizeof(buf);
524
525                 /* reply: SCANRESP BSSID SSID IEs */
526                 ret = snprintf(pos, end - pos, "SCANRESP " MACSTR " ",
527                                MAC2STR(bss->bssid));
528                 if (ret < 0 || ret >= end - pos)
529                         return;
530                 pos += ret;
531                 pos += wpa_snprintf_hex(pos, end - pos,
532                                         bss->ssid, bss->ssid_len);
533                 ret = snprintf(pos, end - pos, " ");
534                 if (ret < 0 || ret >= end - pos)
535                         return;
536                 pos += ret;
537                 pos += wpa_snprintf_hex(pos, end - pos, bss->ie, bss->ielen);
538                 pos += wpa_snprintf_hex(pos, end - pos, bss->wps_probe_resp_ie,
539                                         bss->wps_probe_resp_ie_len);
540
541                 if (bss->privacy) {
542                         ret = snprintf(pos, end - pos, " PRIVACY");
543                         if (ret < 0 || ret >= end - pos)
544                                 return;
545                         pos += ret;
546                 }
547
548                 sendto(drv->test_socket, buf, pos - buf, 0,
549                        (struct sockaddr *) from, fromlen);
550         }
551 }
552
553
554 static void test_driver_assoc(struct wpa_driver_test_data *drv,
555                               struct sockaddr_un *from, socklen_t fromlen,
556                               char *data)
557 {
558         struct test_client_socket *cli;
559         u8 ie[256], ssid[32];
560         size_t ielen, ssid_len = 0;
561         char *pos, *pos2, cmd[50];
562         struct test_driver_bss *bss;
563
564         /* data: STA-addr SSID(hex) IEs(hex) */
565
566         cli = os_zalloc(sizeof(*cli));
567         if (cli == NULL)
568                 return;
569
570         if (hwaddr_aton(data, cli->addr)) {
571                 printf("test_socket: Invalid MAC address '%s' in ASSOC\n",
572                        data);
573                 os_free(cli);
574                 return;
575         }
576         pos = data + 17;
577         while (*pos == ' ')
578                 pos++;
579         pos2 = strchr(pos, ' ');
580         ielen = 0;
581         if (pos2) {
582                 ssid_len = (pos2 - pos) / 2;
583                 if (hexstr2bin(pos, ssid, ssid_len) < 0) {
584                         wpa_printf(MSG_DEBUG, "%s: Invalid SSID", __func__);
585                         os_free(cli);
586                         return;
587                 }
588                 wpa_hexdump_ascii(MSG_DEBUG, "test_driver_assoc: SSID",
589                                   ssid, ssid_len);
590
591                 pos = pos2 + 1;
592                 ielen = strlen(pos) / 2;
593                 if (ielen > sizeof(ie))
594                         ielen = sizeof(ie);
595                 if (hexstr2bin(pos, ie, ielen) < 0)
596                         ielen = 0;
597         }
598
599         for (bss = drv->bss; bss; bss = bss->next) {
600                 if (bss->ssid_len == ssid_len &&
601                     memcmp(bss->ssid, ssid, ssid_len) == 0)
602                         break;
603         }
604         if (bss == NULL) {
605                 wpa_printf(MSG_DEBUG, "%s: No matching SSID found from "
606                            "configured BSSes", __func__);
607                 os_free(cli);
608                 return;
609         }
610
611         cli->bss = bss;
612         memcpy(&cli->un, from, sizeof(cli->un));
613         cli->unlen = fromlen;
614         cli->next = drv->cli;
615         drv->cli = cli;
616         wpa_hexdump_ascii(MSG_DEBUG, "test_socket: ASSOC sun_path",
617                           (const u8 *) cli->un.sun_path,
618                           cli->unlen - sizeof(cli->un.sun_family));
619
620         snprintf(cmd, sizeof(cmd), "ASSOCRESP " MACSTR " 0",
621                  MAC2STR(bss->bssid));
622         sendto(drv->test_socket, cmd, strlen(cmd), 0,
623                (struct sockaddr *) from, fromlen);
624
625 #ifdef HOSTAPD
626         if (hostapd_notif_assoc(bss->bss_ctx, cli->addr, ie, ielen) < 0)
627                 wpa_printf(MSG_DEBUG, "test_driver: failed to add new STA");
628 #endif /* HOSTAPD */
629 }
630
631
632 static void test_driver_disassoc(struct wpa_driver_test_data *drv,
633                                  struct sockaddr_un *from, socklen_t fromlen)
634 {
635         struct test_client_socket *cli;
636
637         cli = test_driver_get_cli(drv, from, fromlen);
638         if (!cli)
639                 return;
640
641 #ifdef HOSTAPD
642         hostapd_notif_disassoc(drv->ctx, cli->addr);
643 #endif /* HOSTAPD */
644 }
645
646
647 static void test_driver_eapol(struct wpa_driver_test_data *drv,
648                               struct sockaddr_un *from, socklen_t fromlen,
649                               u8 *data, size_t datalen)
650 {
651 #ifdef HOSTAPD
652         struct test_client_socket *cli;
653 #endif /* HOSTAPD */
654         const u8 *src = NULL;
655         union wpa_event_data event;
656         void *ctx;
657
658         if (datalen > 14) {
659                 /* Skip Ethernet header */
660                 src = data + ETH_ALEN;
661                 wpa_printf(MSG_DEBUG, "test_driver: dst=" MACSTR " src="
662                            MACSTR " proto=%04x",
663                            MAC2STR(data), MAC2STR(src),
664                            WPA_GET_BE16(data + 2 * ETH_ALEN));
665                 data += 14;
666                 datalen -= 14;
667         }
668
669         os_memset(&event, 0, sizeof(event));
670         event.eapol_rx.data = data;
671         event.eapol_rx.data_len = datalen;
672
673 #ifdef HOSTAPD
674         cli = test_driver_get_cli(drv, from, fromlen);
675         if (cli) {
676                 event.eapol_rx.src = cli->addr;
677                 ctx = cli->bss->bss_ctx;
678         } else {
679                 wpa_printf(MSG_DEBUG, "test_socket: EAPOL from unknown "
680                            "client");
681                 return;
682         }
683 #else /* HOSTAPD */
684         if (src) {
685                 event.eapol_rx.src = src;
686                 ctx = drv->ctx;
687         } else
688                 return;
689 #endif /* HOSTAPD */
690
691         wpa_supplicant_event(ctx, EVENT_EAPOL_RX, &event);
692 }
693
694
695 static void test_driver_ether(struct wpa_driver_test_data *drv,
696                               struct sockaddr_un *from, socklen_t fromlen,
697                               u8 *data, size_t datalen)
698 {
699         struct l2_ethhdr *eth;
700
701         if (datalen < sizeof(*eth))
702                 return;
703
704         eth = (struct l2_ethhdr *) data;
705         wpa_printf(MSG_DEBUG, "test_driver: RX ETHER dst=" MACSTR " src="
706                    MACSTR " proto=%04x",
707                    MAC2STR(eth->h_dest), MAC2STR(eth->h_source),
708                    be_to_host16(eth->h_proto));
709
710 #ifdef CONFIG_IEEE80211R
711         if (be_to_host16(eth->h_proto) == ETH_P_RRB) {
712                 union wpa_event_data ev;
713                 os_memset(&ev, 0, sizeof(ev));
714                 ev.ft_rrb_rx.src = eth->h_source;
715                 ev.ft_rrb_rx.data = data + sizeof(*eth);
716                 ev.ft_rrb_rx.data_len = datalen - sizeof(*eth);
717         }
718 #endif /* CONFIG_IEEE80211R */
719 }
720
721
722 static void test_driver_mlme(struct wpa_driver_test_data *drv,
723                              struct sockaddr_un *from, socklen_t fromlen,
724                              u8 *data, size_t datalen)
725 {
726         struct ieee80211_hdr *hdr;
727         u16 fc;
728         union wpa_event_data event;
729         int freq = 0, own_freq;
730
731         if (datalen > 6 && os_memcmp(data, "freq=", 5) == 0) {
732                 size_t pos;
733                 for (pos = 5; pos < datalen; pos++) {
734                         if (data[pos] == ' ')
735                                 break;
736                 }
737                 if (pos < datalen) {
738                         freq = atoi((const char *) &data[5]);
739                         wpa_printf(MSG_DEBUG, "test_driver(%s): MLME RX on "
740                                    "freq %d MHz", drv->ifname, freq);
741                         pos++;
742                         data += pos;
743                         datalen -= pos;
744                 }
745         }
746
747         if (drv->remain_on_channel_freq)
748                 own_freq = drv->remain_on_channel_freq;
749         else
750                 own_freq = drv->current_freq;
751
752         if (freq && own_freq && freq != own_freq) {
753                 wpa_printf(MSG_DEBUG, "test_driver(%s): Ignore MLME RX on "
754                            "another frequency %d MHz (own %d MHz)",
755                            drv->ifname, freq, own_freq);
756                 return;
757         }
758
759         hdr = (struct ieee80211_hdr *) data;
760
761         if (test_driver_get_cli(drv, from, fromlen) == NULL && datalen >= 16) {
762                 struct test_client_socket *cli;
763                 cli = os_zalloc(sizeof(*cli));
764                 if (cli == NULL)
765                         return;
766                 wpa_printf(MSG_DEBUG, "Adding client entry for " MACSTR,
767                            MAC2STR(hdr->addr2));
768                 memcpy(cli->addr, hdr->addr2, ETH_ALEN);
769                 memcpy(&cli->un, from, sizeof(cli->un));
770                 cli->unlen = fromlen;
771                 cli->next = drv->cli;
772                 drv->cli = cli;
773         }
774
775         wpa_hexdump(MSG_MSGDUMP, "test_driver_mlme: received frame",
776                     data, datalen);
777         fc = le_to_host16(hdr->frame_control);
778         if (WLAN_FC_GET_TYPE(fc) != WLAN_FC_TYPE_MGMT) {
779                 wpa_printf(MSG_ERROR, "%s: received non-mgmt frame",
780                            __func__);
781                 return;
782         }
783
784         os_memset(&event, 0, sizeof(event));
785         event.rx_mgmt.frame = data;
786         event.rx_mgmt.frame_len = datalen;
787         wpa_supplicant_event(drv->ctx, EVENT_RX_MGMT, &event);
788 }
789
790
791 static void test_driver_receive_unix(int sock, void *eloop_ctx, void *sock_ctx)
792 {
793         struct wpa_driver_test_data *drv = eloop_ctx;
794         char buf[2000];
795         int res;
796         struct sockaddr_un from;
797         socklen_t fromlen = sizeof(from);
798
799         res = recvfrom(sock, buf, sizeof(buf) - 1, 0,
800                        (struct sockaddr *) &from, &fromlen);
801         if (res < 0) {
802                 perror("recvfrom(test_socket)");
803                 return;
804         }
805         buf[res] = '\0';
806
807         wpa_printf(MSG_DEBUG, "test_driver: received %u bytes", res);
808
809         if (strncmp(buf, "SCAN", 4) == 0) {
810                 test_driver_scan(drv, &from, fromlen, buf + 4);
811         } else if (strncmp(buf, "ASSOC ", 6) == 0) {
812                 test_driver_assoc(drv, &from, fromlen, buf + 6);
813         } else if (strcmp(buf, "DISASSOC") == 0) {
814                 test_driver_disassoc(drv, &from, fromlen);
815         } else if (strncmp(buf, "EAPOL ", 6) == 0) {
816                 test_driver_eapol(drv, &from, fromlen, (u8 *) buf + 6,
817                                   res - 6);
818         } else if (strncmp(buf, "ETHER ", 6) == 0) {
819                 test_driver_ether(drv, &from, fromlen, (u8 *) buf + 6,
820                                   res - 6);
821         } else if (strncmp(buf, "MLME ", 5) == 0) {
822                 test_driver_mlme(drv, &from, fromlen, (u8 *) buf + 5, res - 5);
823         } else {
824                 wpa_hexdump_ascii(MSG_DEBUG, "Unknown test_socket command",
825                                   (u8 *) buf, res);
826         }
827 }
828
829
830 static struct test_driver_bss *
831 test_driver_get_bss(struct wpa_driver_test_data *drv, const char *ifname)
832 {
833         struct test_driver_bss *bss;
834
835         for (bss = drv->bss; bss; bss = bss->next) {
836                 if (os_strcmp(bss->ifname, ifname) == 0)
837                         return bss;
838         }
839         return NULL;
840 }
841
842
843 static int test_driver_set_generic_elem(const char *ifname, void *priv,
844                                         const u8 *elem, size_t elem_len)
845 {
846         struct wpa_driver_test_data *drv = priv;
847         struct test_driver_bss *bss;
848
849         bss = test_driver_get_bss(drv, ifname);
850         if (bss == NULL)
851                 return -1;
852
853         os_free(bss->ie);
854
855         if (elem == NULL) {
856                 bss->ie = NULL;
857                 bss->ielen = 0;
858                 return 0;
859         }
860
861         bss->ie = os_malloc(elem_len);
862         if (bss->ie == NULL) {
863                 bss->ielen = 0;
864                 return -1;
865         }
866
867         memcpy(bss->ie, elem, elem_len);
868         bss->ielen = elem_len;
869         return 0;
870 }
871
872
873 static int test_driver_set_ap_wps_ie(const char *ifname, void *priv,
874                                      const struct wpabuf *beacon,
875                                      const struct wpabuf *proberesp)
876 {
877         struct wpa_driver_test_data *drv = priv;
878         struct test_driver_bss *bss;
879
880         bss = test_driver_get_bss(drv, ifname);
881         if (bss == NULL)
882                 return -1;
883
884         if (beacon == NULL)
885                 wpa_printf(MSG_DEBUG, "test_driver: Clear Beacon WPS IE");
886         else
887                 wpa_hexdump_buf(MSG_DEBUG, "test_driver: Beacon WPS IE",
888                                 beacon);
889
890         os_free(bss->wps_beacon_ie);
891
892         if (beacon == NULL) {
893                 bss->wps_beacon_ie = NULL;
894                 bss->wps_beacon_ie_len = 0;
895         } else {
896                 bss->wps_beacon_ie = os_malloc(wpabuf_len(beacon));
897                 if (bss->wps_beacon_ie == NULL) {
898                         bss->wps_beacon_ie_len = 0;
899                         return -1;
900                 }
901
902                 os_memcpy(bss->wps_beacon_ie, wpabuf_head(beacon),
903                           wpabuf_len(beacon));
904                 bss->wps_beacon_ie_len = wpabuf_len(beacon);
905         }
906
907         if (proberesp == NULL)
908                 wpa_printf(MSG_DEBUG, "test_driver: Clear Probe Response WPS "
909                            "IE");
910         else
911                 wpa_hexdump_buf(MSG_DEBUG, "test_driver: Probe Response WPS "
912                                 "IE", proberesp);
913
914         os_free(bss->wps_probe_resp_ie);
915
916         if (proberesp == NULL) {
917                 bss->wps_probe_resp_ie = NULL;
918                 bss->wps_probe_resp_ie_len = 0;
919         } else {
920                 bss->wps_probe_resp_ie = os_malloc(wpabuf_len(proberesp));
921                 if (bss->wps_probe_resp_ie == NULL) {
922                         bss->wps_probe_resp_ie_len = 0;
923                         return -1;
924                 }
925
926                 os_memcpy(bss->wps_probe_resp_ie, wpabuf_head(proberesp),
927                           wpabuf_len(proberesp));
928                 bss->wps_probe_resp_ie_len = wpabuf_len(proberesp);
929         }
930
931         return 0;
932 }
933
934
935 static int test_driver_sta_deauth(void *priv, const u8 *own_addr,
936                                   const u8 *addr, int reason)
937 {
938         struct wpa_driver_test_data *drv = priv;
939         struct test_client_socket *cli;
940
941         if (drv->test_socket < 0)
942                 return -1;
943
944         cli = drv->cli;
945         while (cli) {
946                 if (memcmp(cli->addr, addr, ETH_ALEN) == 0)
947                         break;
948                 cli = cli->next;
949         }
950
951         if (!cli)
952                 return -1;
953
954         return sendto(drv->test_socket, "DEAUTH", 6, 0,
955                       (struct sockaddr *) &cli->un, cli->unlen);
956 }
957
958
959 static int test_driver_sta_disassoc(void *priv, const u8 *own_addr,
960                                     const u8 *addr, int reason)
961 {
962         struct wpa_driver_test_data *drv = priv;
963         struct test_client_socket *cli;
964
965         if (drv->test_socket < 0)
966                 return -1;
967
968         cli = drv->cli;
969         while (cli) {
970                 if (memcmp(cli->addr, addr, ETH_ALEN) == 0)
971                         break;
972                 cli = cli->next;
973         }
974
975         if (!cli)
976                 return -1;
977
978         return sendto(drv->test_socket, "DISASSOC", 8, 0,
979                       (struct sockaddr *) &cli->un, cli->unlen);
980 }
981
982
983 static int test_driver_bss_add(void *priv, const char *ifname, const u8 *bssid,
984                                void *bss_ctx)
985 {
986         struct wpa_driver_test_data *drv = priv;
987         struct test_driver_bss *bss;
988
989         wpa_printf(MSG_DEBUG, "%s(ifname=%s bssid=" MACSTR ")",
990                    __func__, ifname, MAC2STR(bssid));
991
992         bss = os_zalloc(sizeof(*bss));
993         if (bss == NULL)
994                 return -1;
995
996         bss->bss_ctx = bss_ctx;
997         os_strlcpy(bss->ifname, ifname, IFNAMSIZ);
998         memcpy(bss->bssid, bssid, ETH_ALEN);
999
1000         bss->next = drv->bss;
1001         drv->bss = bss;
1002         drv->global->bss_add_used = 1;
1003         os_memcpy(drv->global->req_addr, bssid, ETH_ALEN);
1004
1005         return 0;
1006 }
1007
1008
1009 static int test_driver_bss_remove(void *priv, const char *ifname)
1010 {
1011         struct wpa_driver_test_data *drv = priv;
1012         struct test_driver_bss *bss, *prev;
1013         struct test_client_socket *cli, *prev_c;
1014
1015         wpa_printf(MSG_DEBUG, "%s(ifname=%s)", __func__, ifname);
1016
1017         for (prev = NULL, bss = drv->bss; bss; prev = bss, bss = bss->next) {
1018                 if (strcmp(bss->ifname, ifname) != 0)
1019                         continue;
1020
1021                 if (prev)
1022                         prev->next = bss->next;
1023                 else
1024                         drv->bss = bss->next;
1025
1026                 for (prev_c = NULL, cli = drv->cli; cli;
1027                      prev_c = cli, cli = cli->next) {
1028                         if (cli->bss != bss)
1029                                 continue;
1030                         if (prev_c)
1031                                 prev_c->next = cli->next;
1032                         else
1033                                 drv->cli = cli->next;
1034                         os_free(cli);
1035                         break;
1036                 }
1037
1038                 test_driver_free_bss(bss);
1039                 return 0;
1040         }
1041
1042         return -1;
1043 }
1044
1045
1046 static int test_driver_if_add(const char *iface, void *priv,
1047                               enum wpa_driver_if_type type, const char *ifname,
1048                               const u8 *addr, void *bss_ctx)
1049 {
1050         wpa_printf(MSG_DEBUG, "%s(iface=%s type=%d ifname=%s bss_ctx=%p)",
1051                    __func__, iface, type, ifname, bss_ctx);
1052         if (type == WPA_IF_AP_BSS)
1053                 return test_driver_bss_add(priv, ifname, addr, bss_ctx);
1054         return 0;
1055 }
1056
1057
1058 static int test_driver_if_remove(void *priv, enum wpa_driver_if_type type,
1059                                  const char *ifname)
1060 {
1061         wpa_printf(MSG_DEBUG, "%s(type=%d ifname=%s)", __func__, type, ifname);
1062         if (type == WPA_IF_AP_BSS)
1063                 return test_driver_bss_remove(priv, ifname);
1064         return 0;
1065 }
1066
1067
1068 static int test_driver_valid_bss_mask(void *priv, const u8 *addr,
1069                                       const u8 *mask)
1070 {
1071         return 0;
1072 }
1073
1074
1075 static int test_driver_set_ssid(const char *ifname, void *priv, const u8 *buf,
1076                                 int len)
1077 {
1078         struct wpa_driver_test_data *drv = priv;
1079         struct test_driver_bss *bss;
1080
1081         wpa_printf(MSG_DEBUG, "%s(ifname=%s)", __func__, ifname);
1082         wpa_hexdump_ascii(MSG_DEBUG, "test_driver_set_ssid: SSID", buf, len);
1083
1084         bss = test_driver_get_bss(drv, ifname);
1085         if (bss == NULL) {
1086                 wpa_printf(MSG_DEBUG, "%s(ifname=%s): failed to find BSS data",
1087                            __func__, ifname);
1088                 return -1;
1089         }
1090
1091         if (len < 0 || (size_t) len > sizeof(bss->ssid))
1092                 return -1;
1093
1094         os_memcpy(bss->ssid, buf, len);
1095         bss->ssid_len = len;
1096
1097         return 0;
1098 }
1099
1100
1101 static int test_driver_set_privacy(const char *ifname, void *priv, int enabled)
1102 {
1103         struct wpa_driver_test_data *drv = priv;
1104         struct test_driver_bss *bss;
1105
1106         wpa_printf(MSG_DEBUG, "%s(ifname=%s enabled=%d)",
1107                    __func__, ifname, enabled);
1108
1109         bss = test_driver_get_bss(drv, ifname);
1110         if (bss == NULL)
1111                 return -1;
1112
1113         bss->privacy = enabled;
1114
1115         return 0;
1116 }
1117
1118
1119 static int test_driver_set_sta_vlan(void *priv, const u8 *addr,
1120                                     const char *ifname, int vlan_id)
1121 {
1122         wpa_printf(MSG_DEBUG, "%s(addr=" MACSTR " ifname=%s vlan_id=%d)",
1123                    __func__, MAC2STR(addr), ifname, vlan_id);
1124         return 0;
1125 }
1126
1127
1128 static int test_driver_sta_add(const char *ifname, void *priv,
1129                                struct hostapd_sta_add_params *params)
1130 {
1131         struct wpa_driver_test_data *drv = priv;
1132         struct test_client_socket *cli;
1133         struct test_driver_bss *bss;
1134
1135         wpa_printf(MSG_DEBUG, "%s(ifname=%s addr=" MACSTR " aid=%d "
1136                    "capability=0x%x listen_interval=%d)",
1137                    __func__, ifname, MAC2STR(params->addr), params->aid,
1138                    params->capability, params->listen_interval);
1139         wpa_hexdump(MSG_DEBUG, "test_driver_sta_add - supp_rates",
1140                     params->supp_rates, params->supp_rates_len);
1141
1142         cli = drv->cli;
1143         while (cli) {
1144                 if (os_memcmp(cli->addr, params->addr, ETH_ALEN) == 0)
1145                         break;
1146                 cli = cli->next;
1147         }
1148         if (!cli) {
1149                 wpa_printf(MSG_DEBUG, "%s: no matching client entry",
1150                            __func__);
1151                 return -1;
1152         }
1153
1154         bss = test_driver_get_bss(drv, ifname);
1155         if (bss == NULL) {
1156                 wpa_printf(MSG_DEBUG, "%s: No matching interface found from "
1157                            "configured BSSes", __func__);
1158                 return -1;
1159         }
1160
1161         cli->bss = bss;
1162
1163         return 0;
1164 }
1165
1166
1167 static struct wpa_driver_test_data * test_alloc_data(void *ctx,
1168                                                      const char *ifname)
1169 {
1170         struct wpa_driver_test_data *drv;
1171
1172         drv = os_zalloc(sizeof(struct wpa_driver_test_data));
1173         if (drv == NULL) {
1174                 wpa_printf(MSG_ERROR, "Could not allocate memory for test "
1175                            "driver data");
1176                 return NULL;
1177         }
1178
1179         drv->ctx = ctx;
1180         wpa_trace_add_ref(drv, ctx, ctx);
1181         os_strlcpy(drv->ifname, ifname, IFNAMSIZ);
1182
1183         /* Generate a MAC address to help testing with multiple STAs */
1184         drv->own_addr[0] = 0x02; /* locally administered */
1185         sha1_prf((const u8 *) ifname, os_strlen(ifname),
1186                  "test mac addr generation",
1187                  NULL, 0, drv->own_addr + 1, ETH_ALEN - 1);
1188
1189         return drv;
1190 }
1191
1192
1193 static void * test_driver_init(struct hostapd_data *hapd,
1194                                struct wpa_init_params *params)
1195 {
1196         struct wpa_driver_test_data *drv;
1197         struct sockaddr_un addr_un;
1198         struct sockaddr_in addr_in;
1199         struct sockaddr *addr;
1200         socklen_t alen;
1201
1202         drv = test_alloc_data(hapd, params->ifname);
1203         if (drv == NULL)
1204                 return NULL;
1205         drv->ap = 1;
1206         drv->bss = os_zalloc(sizeof(*drv->bss));
1207         if (drv->bss == NULL) {
1208                 wpa_printf(MSG_ERROR, "Could not allocate memory for test "
1209                            "driver BSS data");
1210                 os_free(drv);
1211                 return NULL;
1212         }
1213
1214         drv->bss->bss_ctx = hapd;
1215         os_strlcpy(drv->bss->ifname, params->ifname, IFNAMSIZ);
1216         os_memcpy(drv->bss->bssid, drv->own_addr, ETH_ALEN);
1217         os_memcpy(params->own_addr, drv->own_addr, ETH_ALEN);
1218
1219         if (params->test_socket) {
1220                 if (os_strlen(params->test_socket) >=
1221                     sizeof(addr_un.sun_path)) {
1222                         printf("Too long test_socket path\n");
1223                         wpa_driver_test_deinit(drv);
1224                         return NULL;
1225                 }
1226                 if (strncmp(params->test_socket, "DIR:", 4) == 0) {
1227                         size_t len = strlen(params->test_socket) + 30;
1228                         drv->test_dir = os_strdup(params->test_socket + 4);
1229                         drv->own_socket_path = os_malloc(len);
1230                         if (drv->own_socket_path) {
1231                                 snprintf(drv->own_socket_path, len,
1232                                          "%s/AP-" MACSTR,
1233                                          params->test_socket + 4,
1234                                          MAC2STR(params->own_addr));
1235                         }
1236                 } else if (strncmp(params->test_socket, "UDP:", 4) == 0) {
1237                         drv->udp_port = atoi(params->test_socket + 4);
1238                 } else {
1239                         drv->own_socket_path = os_strdup(params->test_socket);
1240                 }
1241                 if (drv->own_socket_path == NULL && drv->udp_port == 0) {
1242                         wpa_driver_test_deinit(drv);
1243                         return NULL;
1244                 }
1245
1246                 drv->test_socket = socket(drv->udp_port ? PF_INET : PF_UNIX,
1247                                           SOCK_DGRAM, 0);
1248                 if (drv->test_socket < 0) {
1249                         perror("socket");
1250                         wpa_driver_test_deinit(drv);
1251                         return NULL;
1252                 }
1253
1254                 if (drv->udp_port) {
1255                         os_memset(&addr_in, 0, sizeof(addr_in));
1256                         addr_in.sin_family = AF_INET;
1257                         addr_in.sin_port = htons(drv->udp_port);
1258                         addr = (struct sockaddr *) &addr_in;
1259                         alen = sizeof(addr_in);
1260                 } else {
1261                         os_memset(&addr_un, 0, sizeof(addr_un));
1262                         addr_un.sun_family = AF_UNIX;
1263                         os_strlcpy(addr_un.sun_path, drv->own_socket_path,
1264                                    sizeof(addr_un.sun_path));
1265                         addr = (struct sockaddr *) &addr_un;
1266                         alen = sizeof(addr_un);
1267                 }
1268                 if (bind(drv->test_socket, addr, alen) < 0) {
1269                         perror("bind(PF_UNIX)");
1270                         close(drv->test_socket);
1271                         if (drv->own_socket_path)
1272                                 unlink(drv->own_socket_path);
1273                         wpa_driver_test_deinit(drv);
1274                         return NULL;
1275                 }
1276                 eloop_register_read_sock(drv->test_socket,
1277                                          test_driver_receive_unix, drv, NULL);
1278         } else
1279                 drv->test_socket = -1;
1280
1281         return drv;
1282 }
1283
1284
1285 static void wpa_driver_test_poll(void *eloop_ctx, void *timeout_ctx)
1286 {
1287         struct wpa_driver_test_data *drv = eloop_ctx;
1288
1289 #ifdef DRIVER_TEST_UNIX
1290         if (drv->associated && drv->hostapd_addr_set) {
1291                 struct stat st;
1292                 if (stat(drv->hostapd_addr.sun_path, &st) < 0) {
1293                         wpa_printf(MSG_DEBUG, "%s: lost connection to AP: %s",
1294                                    __func__, strerror(errno));
1295                         drv->associated = 0;
1296                         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1297                 }
1298         }
1299 #endif /* DRIVER_TEST_UNIX */
1300
1301         eloop_register_timeout(1, 0, wpa_driver_test_poll, drv, NULL);
1302 }
1303
1304
1305 static void wpa_driver_test_scan_timeout(void *eloop_ctx, void *timeout_ctx)
1306 {
1307         wpa_printf(MSG_DEBUG, "Scan timeout - try to get results");
1308         wpa_supplicant_event(timeout_ctx, EVENT_SCAN_RESULTS, NULL);
1309 }
1310
1311
1312 #ifdef DRIVER_TEST_UNIX
1313 static void wpa_driver_scan_dir(struct wpa_driver_test_data *drv,
1314                                 const char *path)
1315 {
1316         struct dirent *dent;
1317         DIR *dir;
1318         struct sockaddr_un addr;
1319         char cmd[512], *pos, *end;
1320         int ret;
1321
1322         dir = opendir(path);
1323         if (dir == NULL)
1324                 return;
1325
1326         end = cmd + sizeof(cmd);
1327         pos = cmd;
1328         ret = os_snprintf(pos, end - pos, "SCAN " MACSTR,
1329                           MAC2STR(drv->own_addr));
1330         if (ret >= 0 && ret < end - pos)
1331                 pos += ret;
1332         if (drv->probe_req_ie) {
1333                 ret = os_snprintf(pos, end - pos, " ");
1334                 if (ret >= 0 && ret < end - pos)
1335                         pos += ret;
1336                 pos += wpa_snprintf_hex(pos, end - pos, drv->probe_req_ie,
1337                                         drv->probe_req_ie_len);
1338         }
1339         end[-1] = '\0';
1340
1341         while ((dent = readdir(dir))) {
1342                 if (os_strncmp(dent->d_name, "AP-", 3) != 0 &&
1343                     os_strncmp(dent->d_name, "STA-", 4) != 0)
1344                         continue;
1345                 if (drv->own_socket_path) {
1346                         size_t olen, dlen;
1347                         olen = os_strlen(drv->own_socket_path);
1348                         dlen = os_strlen(dent->d_name);
1349                         if (olen >= dlen &&
1350                             os_strcmp(dent->d_name,
1351                                       drv->own_socket_path + olen - dlen) == 0)
1352                                 continue;
1353                 }
1354                 wpa_printf(MSG_DEBUG, "%s: SCAN %s", __func__, dent->d_name);
1355
1356                 os_memset(&addr, 0, sizeof(addr));
1357                 addr.sun_family = AF_UNIX;
1358                 os_snprintf(addr.sun_path, sizeof(addr.sun_path), "%s/%s",
1359                             path, dent->d_name);
1360
1361                 if (sendto(drv->test_socket, cmd, os_strlen(cmd), 0,
1362                            (struct sockaddr *) &addr, sizeof(addr)) < 0) {
1363                         perror("sendto(test_socket)");
1364                 }
1365         }
1366         closedir(dir);
1367 }
1368 #endif /* DRIVER_TEST_UNIX */
1369
1370
1371 static int wpa_driver_test_scan(void *priv,
1372                                 struct wpa_driver_scan_params *params)
1373 {
1374         struct wpa_driver_test_data *drv = priv;
1375         size_t i;
1376
1377         wpa_printf(MSG_DEBUG, "%s: priv=%p", __func__, priv);
1378
1379         os_free(drv->probe_req_ie);
1380         if (params->extra_ies) {
1381                 drv->probe_req_ie = os_malloc(params->extra_ies_len);
1382                 if (drv->probe_req_ie == NULL) {
1383                         drv->probe_req_ie_len = 0;
1384                         return -1;
1385                 }
1386                 os_memcpy(drv->probe_req_ie, params->extra_ies,
1387                           params->extra_ies_len);
1388                 drv->probe_req_ie_len = params->extra_ies_len;
1389         } else {
1390                 drv->probe_req_ie = NULL;
1391                 drv->probe_req_ie_len = 0;
1392         }
1393
1394         for (i = 0; i < params->num_ssids; i++)
1395                 wpa_hexdump(MSG_DEBUG, "Scan SSID",
1396                             params->ssids[i].ssid, params->ssids[i].ssid_len);
1397         wpa_hexdump(MSG_DEBUG, "Scan extra IE(s)",
1398                     params->extra_ies, params->extra_ies_len);
1399
1400         drv->num_scanres = 0;
1401
1402 #ifdef DRIVER_TEST_UNIX
1403         if (drv->test_socket >= 0 && drv->test_dir)
1404                 wpa_driver_scan_dir(drv, drv->test_dir);
1405
1406         if (drv->test_socket >= 0 && drv->hostapd_addr_set &&
1407             sendto(drv->test_socket, "SCAN", 4, 0,
1408                    (struct sockaddr *) &drv->hostapd_addr,
1409                    sizeof(drv->hostapd_addr)) < 0) {
1410                 perror("sendto(test_socket)");
1411         }
1412 #endif /* DRIVER_TEST_UNIX */
1413
1414         if (drv->test_socket >= 0 && drv->hostapd_addr_udp_set &&
1415             sendto(drv->test_socket, "SCAN", 4, 0,
1416                    (struct sockaddr *) &drv->hostapd_addr_udp,
1417                    sizeof(drv->hostapd_addr_udp)) < 0) {
1418                 perror("sendto(test_socket)");
1419         }
1420
1421         eloop_cancel_timeout(wpa_driver_test_scan_timeout, drv, drv->ctx);
1422         eloop_register_timeout(1, 0, wpa_driver_test_scan_timeout, drv,
1423                                drv->ctx);
1424         return 0;
1425 }
1426
1427
1428 static struct wpa_scan_results * wpa_driver_test_get_scan_results2(void *priv)
1429 {
1430         struct wpa_driver_test_data *drv = priv;
1431         struct wpa_scan_results *res;
1432         size_t i;
1433
1434         res = os_zalloc(sizeof(*res));
1435         if (res == NULL)
1436                 return NULL;
1437
1438         res->res = os_zalloc(drv->num_scanres * sizeof(struct wpa_scan_res *));
1439         if (res->res == NULL) {
1440                 os_free(res);
1441                 return NULL;
1442         }
1443
1444         for (i = 0; i < drv->num_scanres; i++) {
1445                 struct wpa_scan_res *r;
1446                 if (drv->scanres[i] == NULL)
1447                         continue;
1448                 r = os_malloc(sizeof(*r) + drv->scanres[i]->ie_len);
1449                 if (r == NULL)
1450                         break;
1451                 os_memcpy(r, drv->scanres[i],
1452                           sizeof(*r) + drv->scanres[i]->ie_len);
1453                 res->res[res->num++] = r;
1454         }
1455
1456         return res;
1457 }
1458
1459
1460 static int wpa_driver_test_set_key(const char *ifname, void *priv,
1461                                    enum wpa_alg alg, const u8 *addr,
1462                                    int key_idx, int set_tx,
1463                                    const u8 *seq, size_t seq_len,
1464                                    const u8 *key, size_t key_len)
1465 {
1466         wpa_printf(MSG_DEBUG, "%s: ifname=%s priv=%p alg=%d key_idx=%d "
1467                    "set_tx=%d",
1468                    __func__, ifname, priv, alg, key_idx, set_tx);
1469         if (addr)
1470                 wpa_printf(MSG_DEBUG, "   addr=" MACSTR, MAC2STR(addr));
1471         if (seq)
1472                 wpa_hexdump(MSG_DEBUG, "   seq", seq, seq_len);
1473         if (key)
1474                 wpa_hexdump_key(MSG_DEBUG, "   key", key, key_len);
1475         return 0;
1476 }
1477
1478
1479 static int wpa_driver_update_mode(struct wpa_driver_test_data *drv, int ap)
1480 {
1481         if (ap && !drv->ap) {
1482                 wpa_driver_test_close_test_socket(drv);
1483                 wpa_driver_test_attach(drv, drv->test_dir, 1);
1484                 drv->ap = 1;
1485         } else if (!ap && drv->ap) {
1486                 wpa_driver_test_close_test_socket(drv);
1487                 wpa_driver_test_attach(drv, drv->test_dir, 0);
1488                 drv->ap = 0;
1489         }
1490
1491         return 0;
1492 }
1493
1494
1495 static int wpa_driver_test_associate(
1496         void *priv, struct wpa_driver_associate_params *params)
1497 {
1498         struct wpa_driver_test_data *drv = priv;
1499         wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d pairwise_suite=%d "
1500                    "group_suite=%d key_mgmt_suite=%d auth_alg=%d mode=%d",
1501                    __func__, priv, params->freq, params->pairwise_suite,
1502                    params->group_suite, params->key_mgmt_suite,
1503                    params->auth_alg, params->mode);
1504         if (params->bssid) {
1505                 wpa_printf(MSG_DEBUG, "   bssid=" MACSTR,
1506                            MAC2STR(params->bssid));
1507         }
1508         if (params->ssid) {
1509                 wpa_hexdump_ascii(MSG_DEBUG, "   ssid",
1510                                   params->ssid, params->ssid_len);
1511         }
1512         if (params->wpa_ie) {
1513                 wpa_hexdump(MSG_DEBUG, "   wpa_ie",
1514                             params->wpa_ie, params->wpa_ie_len);
1515                 drv->assoc_wpa_ie_len = params->wpa_ie_len;
1516                 if (drv->assoc_wpa_ie_len > sizeof(drv->assoc_wpa_ie))
1517                         drv->assoc_wpa_ie_len = sizeof(drv->assoc_wpa_ie);
1518                 os_memcpy(drv->assoc_wpa_ie, params->wpa_ie,
1519                           drv->assoc_wpa_ie_len);
1520         } else
1521                 drv->assoc_wpa_ie_len = 0;
1522
1523         wpa_driver_update_mode(drv, params->mode == IEEE80211_MODE_AP);
1524
1525         drv->ibss = params->mode == IEEE80211_MODE_IBSS;
1526         drv->privacy = params->key_mgmt_suite &
1527                 (WPA_KEY_MGMT_IEEE8021X |
1528                  WPA_KEY_MGMT_PSK |
1529                  WPA_KEY_MGMT_WPA_NONE |
1530                  WPA_KEY_MGMT_FT_IEEE8021X |
1531                  WPA_KEY_MGMT_FT_PSK |
1532                  WPA_KEY_MGMT_IEEE8021X_SHA256 |
1533                  WPA_KEY_MGMT_PSK_SHA256);
1534         if (params->wep_key_len[params->wep_tx_keyidx])
1535                 drv->privacy = 1;
1536
1537 #ifdef DRIVER_TEST_UNIX
1538         if (drv->test_dir && params->bssid &&
1539             params->mode != IEEE80211_MODE_IBSS) {
1540                 os_memset(&drv->hostapd_addr, 0, sizeof(drv->hostapd_addr));
1541                 drv->hostapd_addr.sun_family = AF_UNIX;
1542                 os_snprintf(drv->hostapd_addr.sun_path,
1543                             sizeof(drv->hostapd_addr.sun_path),
1544                             "%s/AP-" MACSTR,
1545                             drv->test_dir, MAC2STR(params->bssid));
1546                 drv->hostapd_addr_set = 1;
1547         }
1548 #endif /* DRIVER_TEST_UNIX */
1549
1550         if (params->mode == IEEE80211_MODE_AP) {
1551                 struct test_driver_bss *bss;
1552                 os_memcpy(drv->ssid, params->ssid, params->ssid_len);
1553                 drv->ssid_len = params->ssid_len;
1554
1555                 test_driver_free_bsses(drv);
1556                 bss = drv->bss = os_zalloc(sizeof(*drv->bss));
1557                 if (bss == NULL)
1558                         return -1;
1559                 os_strlcpy(bss->ifname, drv->ifname, IFNAMSIZ);
1560                 os_memcpy(bss->bssid, drv->own_addr, ETH_ALEN);
1561                 os_memcpy(bss->ssid, params->ssid, params->ssid_len);
1562                 bss->ssid_len = params->ssid_len;
1563                 bss->privacy = drv->privacy;
1564                 if (params->wpa_ie && params->wpa_ie_len) {
1565                         bss->ie = os_malloc(params->wpa_ie_len);
1566                         if (bss->ie) {
1567                                 os_memcpy(bss->ie, params->wpa_ie,
1568                                           params->wpa_ie_len);
1569                                 bss->ielen = params->wpa_ie_len;
1570                         }
1571                 }
1572         } else if (drv->test_socket >= 0 &&
1573                    (drv->hostapd_addr_set || drv->hostapd_addr_udp_set)) {
1574                 char cmd[200], *pos, *end;
1575                 int ret;
1576                 end = cmd + sizeof(cmd);
1577                 pos = cmd;
1578                 ret = os_snprintf(pos, end - pos, "ASSOC " MACSTR " ",
1579                                   MAC2STR(drv->own_addr));
1580                 if (ret >= 0 && ret < end - pos)
1581                         pos += ret;
1582                 pos += wpa_snprintf_hex(pos, end - pos, params->ssid,
1583                                         params->ssid_len);
1584                 ret = os_snprintf(pos, end - pos, " ");
1585                 if (ret >= 0 && ret < end - pos)
1586                         pos += ret;
1587                 pos += wpa_snprintf_hex(pos, end - pos, params->wpa_ie,
1588                                         params->wpa_ie_len);
1589                 end[-1] = '\0';
1590 #ifdef DRIVER_TEST_UNIX
1591                 if (drv->hostapd_addr_set &&
1592                     sendto(drv->test_socket, cmd, os_strlen(cmd), 0,
1593                            (struct sockaddr *) &drv->hostapd_addr,
1594                            sizeof(drv->hostapd_addr)) < 0) {
1595                         perror("sendto(test_socket)");
1596                         return -1;
1597                 }
1598 #endif /* DRIVER_TEST_UNIX */
1599                 if (drv->hostapd_addr_udp_set &&
1600                     sendto(drv->test_socket, cmd, os_strlen(cmd), 0,
1601                            (struct sockaddr *) &drv->hostapd_addr_udp,
1602                            sizeof(drv->hostapd_addr_udp)) < 0) {
1603                         perror("sendto(test_socket)");
1604                         return -1;
1605                 }
1606
1607                 os_memcpy(drv->ssid, params->ssid, params->ssid_len);
1608                 drv->ssid_len = params->ssid_len;
1609         } else {
1610                 drv->associated = 1;
1611                 if (params->mode == IEEE80211_MODE_IBSS) {
1612                         os_memcpy(drv->ssid, params->ssid, params->ssid_len);
1613                         drv->ssid_len = params->ssid_len;
1614                         if (params->bssid)
1615                                 os_memcpy(drv->bssid, params->bssid, ETH_ALEN);
1616                         else {
1617                                 os_get_random(drv->bssid, ETH_ALEN);
1618                                 drv->bssid[0] &= ~0x01;
1619                                 drv->bssid[0] |= 0x02;
1620                         }
1621                 }
1622                 wpa_supplicant_event(drv->ctx, EVENT_ASSOC, NULL);
1623         }
1624
1625         return 0;
1626 }
1627
1628
1629 static int wpa_driver_test_get_bssid(void *priv, u8 *bssid)
1630 {
1631         struct wpa_driver_test_data *drv = priv;
1632         os_memcpy(bssid, drv->bssid, ETH_ALEN);
1633         return 0;
1634 }
1635
1636
1637 static int wpa_driver_test_get_ssid(void *priv, u8 *ssid)
1638 {
1639         struct wpa_driver_test_data *drv = priv;
1640         os_memcpy(ssid, drv->ssid, 32);
1641         return drv->ssid_len;
1642 }
1643
1644
1645 static int wpa_driver_test_send_disassoc(struct wpa_driver_test_data *drv)
1646 {
1647 #ifdef DRIVER_TEST_UNIX
1648         if (drv->test_socket >= 0 &&
1649             sendto(drv->test_socket, "DISASSOC", 8, 0,
1650                    (struct sockaddr *) &drv->hostapd_addr,
1651                    sizeof(drv->hostapd_addr)) < 0) {
1652                 perror("sendto(test_socket)");
1653                 return -1;
1654         }
1655 #endif /* DRIVER_TEST_UNIX */
1656         if (drv->test_socket >= 0 && drv->hostapd_addr_udp_set &&
1657             sendto(drv->test_socket, "DISASSOC", 8, 0,
1658                    (struct sockaddr *) &drv->hostapd_addr_udp,
1659                    sizeof(drv->hostapd_addr_udp)) < 0) {
1660                 perror("sendto(test_socket)");
1661                 return -1;
1662         }
1663         return 0;
1664 }
1665
1666
1667 static int wpa_driver_test_deauthenticate(void *priv, const u8 *addr,
1668                                           int reason_code)
1669 {
1670         struct wpa_driver_test_data *drv = priv;
1671         wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
1672                    __func__, MAC2STR(addr), reason_code);
1673         os_memset(drv->bssid, 0, ETH_ALEN);
1674         drv->associated = 0;
1675         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1676         return wpa_driver_test_send_disassoc(drv);
1677 }
1678
1679
1680 static int wpa_driver_test_disassociate(void *priv, const u8 *addr,
1681                                         int reason_code)
1682 {
1683         struct wpa_driver_test_data *drv = priv;
1684         wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
1685                    __func__, MAC2STR(addr), reason_code);
1686         os_memset(drv->bssid, 0, ETH_ALEN);
1687         drv->associated = 0;
1688         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1689         return wpa_driver_test_send_disassoc(drv);
1690 }
1691
1692
1693 static void wpa_driver_test_scanresp(struct wpa_driver_test_data *drv,
1694                                      struct sockaddr *from,
1695                                      socklen_t fromlen,
1696                                      const char *data)
1697 {
1698         struct wpa_scan_res *res;
1699         const char *pos, *pos2;
1700         size_t len;
1701         u8 *ie_pos, *ie_start, *ie_end;
1702 #define MAX_IE_LEN 1000
1703
1704         wpa_printf(MSG_DEBUG, "test_driver: SCANRESP %s", data);
1705         if (drv->num_scanres >= MAX_SCAN_RESULTS) {
1706                 wpa_printf(MSG_DEBUG, "test_driver: No room for the new scan "
1707                            "result");
1708                 return;
1709         }
1710
1711         /* SCANRESP BSSID SSID IEs */
1712
1713         res = os_zalloc(sizeof(*res) + MAX_IE_LEN);
1714         if (res == NULL)
1715                 return;
1716         ie_start = ie_pos = (u8 *) (res + 1);
1717         ie_end = ie_pos + MAX_IE_LEN;
1718
1719         if (hwaddr_aton(data, res->bssid)) {
1720                 wpa_printf(MSG_DEBUG, "test_driver: invalid BSSID in scanres");
1721                 os_free(res);
1722                 return;
1723         }
1724
1725         pos = data + 17;
1726         while (*pos == ' ')
1727                 pos++;
1728         pos2 = os_strchr(pos, ' ');
1729         if (pos2 == NULL) {
1730                 wpa_printf(MSG_DEBUG, "test_driver: invalid SSID termination "
1731                            "in scanres");
1732                 os_free(res);
1733                 return;
1734         }
1735         len = (pos2 - pos) / 2;
1736         if (len > 32)
1737                 len = 32;
1738         /*
1739          * Generate SSID IE from the SSID field since this IE is not included
1740          * in the main IE field.
1741          */
1742         *ie_pos++ = WLAN_EID_SSID;
1743         *ie_pos++ = len;
1744         if (hexstr2bin(pos, ie_pos, len) < 0) {
1745                 wpa_printf(MSG_DEBUG, "test_driver: invalid SSID in scanres");
1746                 os_free(res);
1747                 return;
1748         }
1749         ie_pos += len;
1750
1751         pos = pos2 + 1;
1752         pos2 = os_strchr(pos, ' ');
1753         if (pos2 == NULL)
1754                 len = os_strlen(pos) / 2;
1755         else
1756                 len = (pos2 - pos) / 2;
1757         if ((int) len > ie_end - ie_pos)
1758                 len = ie_end - ie_pos;
1759         if (hexstr2bin(pos, ie_pos, len) < 0) {
1760                 wpa_printf(MSG_DEBUG, "test_driver: invalid IEs in scanres");
1761                 os_free(res);
1762                 return;
1763         }
1764         ie_pos += len;
1765         res->ie_len = ie_pos - ie_start;
1766
1767         if (pos2) {
1768                 pos = pos2 + 1;
1769                 while (*pos == ' ')
1770                         pos++;
1771                 if (os_strstr(pos, "PRIVACY"))
1772                         res->caps |= IEEE80211_CAP_PRIVACY;
1773                 if (os_strstr(pos, "IBSS"))
1774                         res->caps |= IEEE80211_CAP_IBSS;
1775         }
1776
1777         os_free(drv->scanres[drv->num_scanres]);
1778         drv->scanres[drv->num_scanres++] = res;
1779 }
1780
1781
1782 static void wpa_driver_test_assocresp(struct wpa_driver_test_data *drv,
1783                                       struct sockaddr *from,
1784                                       socklen_t fromlen,
1785                                       const char *data)
1786 {
1787         /* ASSOCRESP BSSID <res> */
1788         if (hwaddr_aton(data, drv->bssid)) {
1789                 wpa_printf(MSG_DEBUG, "test_driver: invalid BSSID in "
1790                            "assocresp");
1791         }
1792         if (drv->use_associnfo) {
1793                 union wpa_event_data event;
1794                 os_memset(&event, 0, sizeof(event));
1795                 event.assoc_info.req_ies = drv->assoc_wpa_ie;
1796                 event.assoc_info.req_ies_len = drv->assoc_wpa_ie_len;
1797                 wpa_supplicant_event(drv->ctx, EVENT_ASSOCINFO, &event);
1798         }
1799         drv->associated = 1;
1800         wpa_supplicant_event(drv->ctx, EVENT_ASSOC, NULL);
1801 }
1802
1803
1804 static void wpa_driver_test_disassoc(struct wpa_driver_test_data *drv,
1805                                      struct sockaddr *from,
1806                                      socklen_t fromlen)
1807 {
1808         drv->associated = 0;
1809         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1810 }
1811
1812
1813 static void wpa_driver_test_eapol(struct wpa_driver_test_data *drv,
1814                                   struct sockaddr *from,
1815                                   socklen_t fromlen,
1816                                   const u8 *data, size_t data_len)
1817 {
1818         const u8 *src = drv->bssid;
1819         union wpa_event_data event;
1820
1821         if (data_len > 14) {
1822                 /* Skip Ethernet header */
1823                 src = data + ETH_ALEN;
1824                 data += 14;
1825                 data_len -= 14;
1826         }
1827
1828         os_memset(&event, 0, sizeof(event));
1829         event.eapol_rx.src = src;
1830         event.eapol_rx.data = data;
1831         event.eapol_rx.data_len = data_len;
1832         wpa_supplicant_event(drv->ctx, EVENT_EAPOL_RX, &event);
1833 }
1834
1835
1836 static void wpa_driver_test_mlme(struct wpa_driver_test_data *drv,
1837                                  struct sockaddr *from,
1838                                  socklen_t fromlen,
1839                                  const u8 *data, size_t data_len)
1840 {
1841         int freq = 0, own_freq;
1842         union wpa_event_data event;
1843
1844         if (data_len > 6 && os_memcmp(data, "freq=", 5) == 0) {
1845                 size_t pos;
1846                 for (pos = 5; pos < data_len; pos++) {
1847                         if (data[pos] == ' ')
1848                                 break;
1849                 }
1850                 if (pos < data_len) {
1851                         freq = atoi((const char *) &data[5]);
1852                         wpa_printf(MSG_DEBUG, "test_driver(%s): MLME RX on "
1853                                    "freq %d MHz", drv->ifname, freq);
1854                         pos++;
1855                         data += pos;
1856                         data_len -= pos;
1857                 }
1858         }
1859
1860         if (drv->remain_on_channel_freq)
1861                 own_freq = drv->remain_on_channel_freq;
1862         else
1863                 own_freq = drv->current_freq;
1864
1865         if (freq && own_freq && freq != own_freq) {
1866                 wpa_printf(MSG_DEBUG, "test_driver(%s): Ignore MLME RX on "
1867                            "another frequency %d MHz (own %d MHz)",
1868                            drv->ifname, freq, own_freq);
1869                 return;
1870         }
1871
1872         os_memset(&event, 0, sizeof(event));
1873         event.mlme_rx.buf = data;
1874         event.mlme_rx.len = data_len;
1875         event.mlme_rx.freq = freq;
1876         wpa_supplicant_event(drv->ctx, EVENT_MLME_RX, &event);
1877
1878         if (drv->probe_req_report && data_len >= 24) {
1879                 const struct ieee80211_mgmt *mgmt;
1880                 u16 fc;
1881
1882                 mgmt = (const struct ieee80211_mgmt *) data;
1883                 fc = le_to_host16(mgmt->frame_control);
1884                 if (WLAN_FC_GET_TYPE(fc) == WLAN_FC_TYPE_MGMT &&
1885                     WLAN_FC_GET_STYPE(fc) == WLAN_FC_STYPE_PROBE_REQ) {
1886                         os_memset(&event, 0, sizeof(event));
1887                         event.rx_probe_req.sa = mgmt->sa;
1888                         event.rx_probe_req.ie = mgmt->u.probe_req.variable;
1889                         event.rx_probe_req.ie_len =
1890                                 data_len - (mgmt->u.probe_req.variable - data);
1891                         wpa_supplicant_event(drv->ctx, EVENT_RX_PROBE_REQ,
1892                                              &event);
1893                 }
1894         }
1895 }
1896
1897
1898 static void wpa_driver_test_scan_cmd(struct wpa_driver_test_data *drv,
1899                                      struct sockaddr *from,
1900                                      socklen_t fromlen,
1901                                      const u8 *data, size_t data_len)
1902 {
1903         char buf[512], *pos, *end;
1904         int ret;
1905
1906         /* data: optional [ STA-addr | ' ' | IEs(hex) ] */
1907
1908         if (!drv->ibss)
1909                 return;
1910
1911         pos = buf;
1912         end = buf + sizeof(buf);
1913
1914         /* reply: SCANRESP BSSID SSID IEs */
1915         ret = snprintf(pos, end - pos, "SCANRESP " MACSTR " ",
1916                        MAC2STR(drv->bssid));
1917         if (ret < 0 || ret >= end - pos)
1918                 return;
1919         pos += ret;
1920         pos += wpa_snprintf_hex(pos, end - pos,
1921                                 drv->ssid, drv->ssid_len);
1922         ret = snprintf(pos, end - pos, " ");
1923         if (ret < 0 || ret >= end - pos)
1924                 return;
1925         pos += ret;
1926         pos += wpa_snprintf_hex(pos, end - pos, drv->assoc_wpa_ie,
1927                                 drv->assoc_wpa_ie_len);
1928
1929         if (drv->privacy) {
1930                 ret = snprintf(pos, end - pos, " PRIVACY");
1931                 if (ret < 0 || ret >= end - pos)
1932                         return;
1933                 pos += ret;
1934         }
1935
1936         ret = snprintf(pos, end - pos, " IBSS");
1937         if (ret < 0 || ret >= end - pos)
1938                 return;
1939         pos += ret;
1940
1941         sendto(drv->test_socket, buf, pos - buf, 0,
1942                (struct sockaddr *) from, fromlen);
1943 }
1944
1945
1946 static void wpa_driver_test_receive_unix(int sock, void *eloop_ctx,
1947                                          void *sock_ctx)
1948 {
1949         struct wpa_driver_test_data *drv = eloop_ctx;
1950         char *buf;
1951         int res;
1952         struct sockaddr_storage from;
1953         socklen_t fromlen = sizeof(from);
1954         const size_t buflen = 2000;
1955
1956         if (drv->ap) {
1957                 test_driver_receive_unix(sock, eloop_ctx, sock_ctx);
1958                 return;
1959         }
1960
1961         buf = os_malloc(buflen);
1962         if (buf == NULL)
1963                 return;
1964         res = recvfrom(sock, buf, buflen - 1, 0,
1965                        (struct sockaddr *) &from, &fromlen);
1966         if (res < 0) {
1967                 perror("recvfrom(test_socket)");
1968                 os_free(buf);
1969                 return;
1970         }
1971         buf[res] = '\0';
1972
1973         wpa_printf(MSG_DEBUG, "test_driver: received %u bytes", res);
1974
1975         if (os_strncmp(buf, "SCANRESP ", 9) == 0) {
1976                 wpa_driver_test_scanresp(drv, (struct sockaddr *) &from,
1977                                          fromlen, buf + 9);
1978         } else if (os_strncmp(buf, "ASSOCRESP ", 10) == 0) {
1979                 wpa_driver_test_assocresp(drv, (struct sockaddr *) &from,
1980                                           fromlen, buf + 10);
1981         } else if (os_strcmp(buf, "DISASSOC") == 0) {
1982                 wpa_driver_test_disassoc(drv, (struct sockaddr *) &from,
1983                                          fromlen);
1984         } else if (os_strcmp(buf, "DEAUTH") == 0) {
1985                 wpa_driver_test_disassoc(drv, (struct sockaddr *) &from,
1986                                          fromlen);
1987         } else if (os_strncmp(buf, "EAPOL ", 6) == 0) {
1988                 wpa_driver_test_eapol(drv, (struct sockaddr *) &from, fromlen,
1989                                       (const u8 *) buf + 6, res - 6);
1990         } else if (os_strncmp(buf, "MLME ", 5) == 0) {
1991                 wpa_driver_test_mlme(drv, (struct sockaddr *) &from, fromlen,
1992                                      (const u8 *) buf + 5, res - 5);
1993         } else if (os_strncmp(buf, "SCAN ", 5) == 0) {
1994                 wpa_driver_test_scan_cmd(drv, (struct sockaddr *) &from,
1995                                          fromlen,
1996                                          (const u8 *) buf + 5, res - 5);
1997         } else {
1998                 wpa_hexdump_ascii(MSG_DEBUG, "Unknown test_socket command",
1999                                   (u8 *) buf, res);
2000         }
2001         os_free(buf);
2002 }
2003
2004
2005 static void * wpa_driver_test_init2(void *ctx, const char *ifname,
2006                                     void *global_priv)
2007 {
2008         struct wpa_driver_test_data *drv;
2009         struct wpa_driver_test_global *global = global_priv;
2010
2011         drv = test_alloc_data(ctx, ifname);
2012         if (drv == NULL)
2013                 return NULL;
2014         drv->global = global_priv;
2015         drv->test_socket = -1;
2016
2017         /* Set dummy BSSID and SSID for testing. */
2018         drv->bssid[0] = 0x02;
2019         drv->bssid[1] = 0x00;
2020         drv->bssid[2] = 0x00;
2021         drv->bssid[3] = 0x00;
2022         drv->bssid[4] = 0x00;
2023         drv->bssid[5] = 0x01;
2024         os_memcpy(drv->ssid, "test", 5);
2025         drv->ssid_len = 4;
2026
2027         if (global->bss_add_used) {
2028                 os_memcpy(drv->own_addr, global->req_addr, ETH_ALEN);
2029                 global->bss_add_used = 0;
2030         }
2031
2032         eloop_register_timeout(1, 0, wpa_driver_test_poll, drv, NULL);
2033
2034         return drv;
2035 }
2036
2037
2038 static void wpa_driver_test_close_test_socket(struct wpa_driver_test_data *drv)
2039 {
2040         if (drv->test_socket >= 0) {
2041                 eloop_unregister_read_sock(drv->test_socket);
2042                 close(drv->test_socket);
2043                 drv->test_socket = -1;
2044         }
2045
2046         if (drv->own_socket_path) {
2047                 unlink(drv->own_socket_path);
2048                 os_free(drv->own_socket_path);
2049                 drv->own_socket_path = NULL;
2050         }
2051 }
2052
2053
2054 static void wpa_driver_test_deinit(void *priv)
2055 {
2056         struct wpa_driver_test_data *drv = priv;
2057         struct test_client_socket *cli, *prev;
2058         int i;
2059
2060         cli = drv->cli;
2061         while (cli) {
2062                 prev = cli;
2063                 cli = cli->next;
2064                 os_free(prev);
2065         }
2066
2067 #ifdef HOSTAPD
2068         /* There should be only one BSS remaining at this point. */
2069         if (drv->bss == NULL)
2070                 wpa_printf(MSG_ERROR, "%s: drv->bss == NULL", __func__);
2071         else if (drv->bss->next)
2072                 wpa_printf(MSG_ERROR, "%s: drv->bss->next != NULL", __func__);
2073 #endif /* HOSTAPD */
2074
2075         test_driver_free_bsses(drv);
2076
2077         wpa_driver_test_close_test_socket(drv);
2078         eloop_cancel_timeout(wpa_driver_test_scan_timeout, drv, drv->ctx);
2079         eloop_cancel_timeout(wpa_driver_test_poll, drv, NULL);
2080         eloop_cancel_timeout(test_remain_on_channel_timeout, drv, NULL);
2081         os_free(drv->test_dir);
2082         for (i = 0; i < MAX_SCAN_RESULTS; i++)
2083                 os_free(drv->scanres[i]);
2084         os_free(drv->probe_req_ie);
2085         wpa_trace_remove_ref(drv, ctx, drv->ctx);
2086         os_free(drv);
2087 }
2088
2089
2090 static int wpa_driver_test_attach(struct wpa_driver_test_data *drv,
2091                                   const char *dir, int ap)
2092 {
2093 #ifdef DRIVER_TEST_UNIX
2094         static unsigned int counter = 0;
2095         struct sockaddr_un addr;
2096         size_t len;
2097
2098         os_free(drv->own_socket_path);
2099         if (dir) {
2100                 len = os_strlen(dir) + 30;
2101                 drv->own_socket_path = os_malloc(len);
2102                 if (drv->own_socket_path == NULL)
2103                         return -1;
2104                 os_snprintf(drv->own_socket_path, len, "%s/%s-" MACSTR,
2105                             dir, ap ? "AP" : "STA", MAC2STR(drv->own_addr));
2106         } else {
2107                 drv->own_socket_path = os_malloc(100);
2108                 if (drv->own_socket_path == NULL)
2109                         return -1;
2110                 os_snprintf(drv->own_socket_path, 100,
2111                             "/tmp/wpa_supplicant_test-%d-%d",
2112                             getpid(), counter++);
2113         }
2114
2115         drv->test_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
2116         if (drv->test_socket < 0) {
2117                 perror("socket(PF_UNIX)");
2118                 os_free(drv->own_socket_path);
2119                 drv->own_socket_path = NULL;
2120                 return -1;
2121         }
2122
2123         os_memset(&addr, 0, sizeof(addr));
2124         addr.sun_family = AF_UNIX;
2125         os_strlcpy(addr.sun_path, drv->own_socket_path, sizeof(addr.sun_path));
2126         if (bind(drv->test_socket, (struct sockaddr *) &addr,
2127                  sizeof(addr)) < 0) {
2128                 perror("bind(PF_UNIX)");
2129                 close(drv->test_socket);
2130                 unlink(drv->own_socket_path);
2131                 os_free(drv->own_socket_path);
2132                 drv->own_socket_path = NULL;
2133                 return -1;
2134         }
2135
2136         eloop_register_read_sock(drv->test_socket,
2137                                  wpa_driver_test_receive_unix, drv, NULL);
2138
2139         return 0;
2140 #else /* DRIVER_TEST_UNIX */
2141         return -1;
2142 #endif /* DRIVER_TEST_UNIX */
2143 }
2144
2145
2146 static int wpa_driver_test_attach_udp(struct wpa_driver_test_data *drv,
2147                                       char *dst)
2148 {
2149         char *pos;
2150
2151         pos = os_strchr(dst, ':');
2152         if (pos == NULL)
2153                 return -1;
2154         *pos++ = '\0';
2155         wpa_printf(MSG_DEBUG, "%s: addr=%s port=%s", __func__, dst, pos);
2156
2157         drv->test_socket = socket(PF_INET, SOCK_DGRAM, 0);
2158         if (drv->test_socket < 0) {
2159                 perror("socket(PF_INET)");
2160                 return -1;
2161         }
2162
2163         os_memset(&drv->hostapd_addr_udp, 0, sizeof(drv->hostapd_addr_udp));
2164         drv->hostapd_addr_udp.sin_family = AF_INET;
2165 #if defined(CONFIG_NATIVE_WINDOWS) || defined(CONFIG_ANSI_C_EXTRA)
2166         {
2167                 int a[4];
2168                 u8 *pos;
2169                 sscanf(dst, "%d.%d.%d.%d", &a[0], &a[1], &a[2], &a[3]);
2170                 pos = (u8 *) &drv->hostapd_addr_udp.sin_addr;
2171                 *pos++ = a[0];
2172                 *pos++ = a[1];
2173                 *pos++ = a[2];
2174                 *pos++ = a[3];
2175         }
2176 #else /* CONFIG_NATIVE_WINDOWS or CONFIG_ANSI_C_EXTRA */
2177         inet_aton(dst, &drv->hostapd_addr_udp.sin_addr);
2178 #endif /* CONFIG_NATIVE_WINDOWS or CONFIG_ANSI_C_EXTRA */
2179         drv->hostapd_addr_udp.sin_port = htons(atoi(pos));
2180
2181         drv->hostapd_addr_udp_set = 1;
2182
2183         eloop_register_read_sock(drv->test_socket,
2184                                  wpa_driver_test_receive_unix, drv, NULL);
2185
2186         return 0;
2187 }
2188
2189
2190 static int wpa_driver_test_set_param(void *priv, const char *param)
2191 {
2192         struct wpa_driver_test_data *drv = priv;
2193         const char *pos;
2194
2195         wpa_printf(MSG_DEBUG, "%s: param='%s'", __func__, param);
2196         if (param == NULL)
2197                 return 0;
2198
2199         wpa_driver_test_close_test_socket(drv);
2200
2201 #ifdef DRIVER_TEST_UNIX
2202         pos = os_strstr(param, "test_socket=");
2203         if (pos) {
2204                 const char *pos2;
2205                 size_t len;
2206
2207                 pos += 12;
2208                 pos2 = os_strchr(pos, ' ');
2209                 if (pos2)
2210                         len = pos2 - pos;
2211                 else
2212                         len = os_strlen(pos);
2213                 if (len > sizeof(drv->hostapd_addr.sun_path))
2214                         return -1;
2215                 os_memset(&drv->hostapd_addr, 0, sizeof(drv->hostapd_addr));
2216                 drv->hostapd_addr.sun_family = AF_UNIX;
2217                 os_memcpy(drv->hostapd_addr.sun_path, pos, len);
2218                 drv->hostapd_addr_set = 1;
2219         }
2220 #endif /* DRIVER_TEST_UNIX */
2221
2222         pos = os_strstr(param, "test_dir=");
2223         if (pos) {
2224                 char *end;
2225                 os_free(drv->test_dir);
2226                 drv->test_dir = os_strdup(pos + 9);
2227                 if (drv->test_dir == NULL)
2228                         return -1;
2229                 end = os_strchr(drv->test_dir, ' ');
2230                 if (end)
2231                         *end = '\0';
2232                 if (wpa_driver_test_attach(drv, drv->test_dir, 0))
2233                         return -1;
2234         } else {
2235                 pos = os_strstr(param, "test_udp=");
2236                 if (pos) {
2237                         char *dst, *epos;
2238                         dst = os_strdup(pos + 9);
2239                         if (dst == NULL)
2240                                 return -1;
2241                         epos = os_strchr(dst, ' ');
2242                         if (epos)
2243                                 *epos = '\0';
2244                         if (wpa_driver_test_attach_udp(drv, dst))
2245                                 return -1;
2246                         os_free(dst);
2247                 } else if (wpa_driver_test_attach(drv, NULL, 0))
2248                         return -1;
2249         }
2250
2251         if (os_strstr(param, "use_associnfo=1")) {
2252                 wpa_printf(MSG_DEBUG, "test_driver: Use AssocInfo events");
2253                 drv->use_associnfo = 1;
2254         }
2255
2256 #ifdef CONFIG_CLIENT_MLME
2257         if (os_strstr(param, "use_mlme=1")) {
2258                 wpa_printf(MSG_DEBUG, "test_driver: Use internal MLME");
2259                 drv->use_mlme = 1;
2260         }
2261 #endif /* CONFIG_CLIENT_MLME */
2262
2263         return 0;
2264 }
2265
2266
2267 static const u8 * wpa_driver_test_get_mac_addr(void *priv)
2268 {
2269         struct wpa_driver_test_data *drv = priv;
2270         wpa_printf(MSG_DEBUG, "%s", __func__);
2271         return drv->own_addr;
2272 }
2273
2274
2275 static int wpa_driver_test_send_eapol(void *priv, const u8 *dest, u16 proto,
2276                                       const u8 *data, size_t data_len)
2277 {
2278         struct wpa_driver_test_data *drv = priv;
2279         char *msg;
2280         size_t msg_len;
2281         struct l2_ethhdr eth;
2282         struct sockaddr *addr;
2283         socklen_t alen;
2284 #ifdef DRIVER_TEST_UNIX
2285         struct sockaddr_un addr_un;
2286 #endif /* DRIVER_TEST_UNIX */
2287
2288         wpa_hexdump(MSG_MSGDUMP, "test_send_eapol TX frame", data, data_len);
2289
2290         os_memset(&eth, 0, sizeof(eth));
2291         os_memcpy(eth.h_dest, dest, ETH_ALEN);
2292         os_memcpy(eth.h_source, drv->own_addr, ETH_ALEN);
2293         eth.h_proto = host_to_be16(proto);
2294
2295         msg_len = 6 + sizeof(eth) + data_len;
2296         msg = os_malloc(msg_len);
2297         if (msg == NULL)
2298                 return -1;
2299         os_memcpy(msg, "EAPOL ", 6);
2300         os_memcpy(msg + 6, &eth, sizeof(eth));
2301         os_memcpy(msg + 6 + sizeof(eth), data, data_len);
2302
2303         if (os_memcmp(dest, drv->bssid, ETH_ALEN) == 0 ||
2304             drv->test_dir == NULL) {
2305                 if (drv->hostapd_addr_udp_set) {
2306                         addr = (struct sockaddr *) &drv->hostapd_addr_udp;
2307                         alen = sizeof(drv->hostapd_addr_udp);
2308                 } else {
2309 #ifdef DRIVER_TEST_UNIX
2310                         addr = (struct sockaddr *) &drv->hostapd_addr;
2311                         alen = sizeof(drv->hostapd_addr);
2312 #else /* DRIVER_TEST_UNIX */
2313                         os_free(msg);
2314                         return -1;
2315 #endif /* DRIVER_TEST_UNIX */
2316                 }
2317         } else {
2318 #ifdef DRIVER_TEST_UNIX
2319                 struct stat st;
2320                 os_memset(&addr_un, 0, sizeof(addr_un));
2321                 addr_un.sun_family = AF_UNIX;
2322                 os_snprintf(addr_un.sun_path, sizeof(addr_un.sun_path),
2323                             "%s/STA-" MACSTR, drv->test_dir, MAC2STR(dest));
2324                 if (stat(addr_un.sun_path, &st) < 0) {
2325                         os_snprintf(addr_un.sun_path, sizeof(addr_un.sun_path),
2326                                     "%s/AP-" MACSTR,
2327                                     drv->test_dir, MAC2STR(dest));
2328                 }
2329                 addr = (struct sockaddr *) &addr_un;
2330                 alen = sizeof(addr_un);
2331 #else /* DRIVER_TEST_UNIX */
2332                 os_free(msg);
2333                 return -1;
2334 #endif /* DRIVER_TEST_UNIX */
2335         }
2336
2337         if (sendto(drv->test_socket, msg, msg_len, 0, addr, alen) < 0) {
2338                 perror("sendmsg(test_socket)");
2339                 os_free(msg);
2340                 return -1;
2341         }
2342
2343         os_free(msg);
2344         return 0;
2345 }
2346
2347
2348 static int wpa_driver_test_get_capa(void *priv, struct wpa_driver_capa *capa)
2349 {
2350         struct wpa_driver_test_data *drv = priv;
2351         os_memset(capa, 0, sizeof(*capa));
2352         capa->key_mgmt = WPA_DRIVER_CAPA_KEY_MGMT_WPA |
2353                 WPA_DRIVER_CAPA_KEY_MGMT_WPA2 |
2354                 WPA_DRIVER_CAPA_KEY_MGMT_WPA_PSK |
2355                 WPA_DRIVER_CAPA_KEY_MGMT_WPA2_PSK |
2356                 WPA_DRIVER_CAPA_KEY_MGMT_WPA_NONE |
2357                 WPA_DRIVER_CAPA_KEY_MGMT_FT |
2358                 WPA_DRIVER_CAPA_KEY_MGMT_FT_PSK;
2359         capa->enc = WPA_DRIVER_CAPA_ENC_WEP40 |
2360                 WPA_DRIVER_CAPA_ENC_WEP104 |
2361                 WPA_DRIVER_CAPA_ENC_TKIP |
2362                 WPA_DRIVER_CAPA_ENC_CCMP;
2363         capa->auth = WPA_DRIVER_AUTH_OPEN |
2364                 WPA_DRIVER_AUTH_SHARED |
2365                 WPA_DRIVER_AUTH_LEAP;
2366         if (drv->use_mlme)
2367                 capa->flags |= WPA_DRIVER_FLAGS_USER_SPACE_MLME;
2368         capa->flags |= WPA_DRIVER_FLAGS_AP;
2369         capa->max_scan_ssids = 2;
2370
2371         return 0;
2372 }
2373
2374
2375 static int wpa_driver_test_mlme_setprotection(void *priv, const u8 *addr,
2376                                               int protect_type,
2377                                               int key_type)
2378 {
2379         wpa_printf(MSG_DEBUG, "%s: protect_type=%d key_type=%d",
2380                    __func__, protect_type, key_type);
2381
2382         if (addr) {
2383                 wpa_printf(MSG_DEBUG, "%s: addr=" MACSTR,
2384                            __func__, MAC2STR(addr));
2385         }
2386
2387         return 0;
2388 }
2389
2390
2391 static int wpa_driver_test_set_channel(void *priv,
2392                                        enum hostapd_hw_mode phymode,
2393                                        int chan, int freq)
2394 {
2395         struct wpa_driver_test_data *drv = priv;
2396         wpa_printf(MSG_DEBUG, "%s: phymode=%d chan=%d freq=%d",
2397                    __func__, phymode, chan, freq);
2398         drv->current_freq = freq;
2399         return 0;
2400 }
2401
2402
2403 static int wpa_driver_test_mlme_add_sta(void *priv, const u8 *addr,
2404                                         const u8 *supp_rates,
2405                                         size_t supp_rates_len)
2406 {
2407         wpa_printf(MSG_DEBUG, "%s: addr=" MACSTR, __func__, MAC2STR(addr));
2408         return 0;
2409 }
2410
2411
2412 static int wpa_driver_test_mlme_remove_sta(void *priv, const u8 *addr)
2413 {
2414         wpa_printf(MSG_DEBUG, "%s: addr=" MACSTR, __func__, MAC2STR(addr));
2415         return 0;
2416 }
2417
2418
2419 static int wpa_driver_test_set_ssid(void *priv, const u8 *ssid,
2420                                     size_t ssid_len)
2421 {
2422         wpa_printf(MSG_DEBUG, "%s", __func__);
2423         return 0;
2424 }
2425
2426
2427 static int wpa_driver_test_set_bssid(void *priv, const u8 *bssid)
2428 {
2429         wpa_printf(MSG_DEBUG, "%s: bssid=" MACSTR, __func__, MAC2STR(bssid));
2430         return 0;
2431 }
2432
2433
2434 static void * wpa_driver_test_global_init(void)
2435 {
2436         struct wpa_driver_test_global *global;
2437
2438         global = os_zalloc(sizeof(*global));
2439         return global;
2440 }
2441
2442
2443 static void wpa_driver_test_global_deinit(void *priv)
2444 {
2445         struct wpa_driver_test_global *global = priv;
2446         os_free(global);
2447 }
2448
2449
2450 static struct wpa_interface_info *
2451 wpa_driver_test_get_interfaces(void *global_priv)
2452 {
2453         /* struct wpa_driver_test_global *global = priv; */
2454         struct wpa_interface_info *iface;
2455
2456         iface = os_zalloc(sizeof(*iface));
2457         if (iface == NULL)
2458                 return iface;
2459         iface->ifname = os_strdup("sta0");
2460         iface->desc = os_strdup("test interface 0");
2461         iface->drv_name = "test";
2462         iface->next = os_zalloc(sizeof(*iface));
2463         if (iface->next) {
2464                 iface->next->ifname = os_strdup("sta1");
2465                 iface->next->desc = os_strdup("test interface 1");
2466                 iface->next->drv_name = "test";
2467         }
2468
2469         return iface;
2470 }
2471
2472
2473 static struct hostapd_hw_modes *
2474 wpa_driver_test_get_hw_feature_data(void *priv, u16 *num_modes, u16 *flags)
2475 {
2476         struct hostapd_hw_modes *modes;
2477         size_t i;
2478
2479         *num_modes = 3;
2480         *flags = 0;
2481         modes = os_zalloc(*num_modes * sizeof(struct hostapd_hw_modes));
2482         if (modes == NULL)
2483                 return NULL;
2484         modes[0].mode = HOSTAPD_MODE_IEEE80211G;
2485         modes[0].num_channels = 11;
2486         modes[0].num_rates = 12;
2487         modes[0].channels =
2488                 os_zalloc(11 * sizeof(struct hostapd_channel_data));
2489         modes[0].rates = os_zalloc(modes[0].num_rates * sizeof(int));
2490         if (modes[0].channels == NULL || modes[0].rates == NULL)
2491                 goto fail;
2492         for (i = 0; i < 11; i++) {
2493                 modes[0].channels[i].chan = i + 1;
2494                 modes[0].channels[i].freq = 2412 + 5 * i;
2495                 modes[0].channels[i].flag = 0;
2496         }
2497         modes[0].rates[0] = 10;
2498         modes[0].rates[1] = 20;
2499         modes[0].rates[2] = 55;
2500         modes[0].rates[3] = 110;
2501         modes[0].rates[4] = 60;
2502         modes[0].rates[5] = 90;
2503         modes[0].rates[6] = 120;
2504         modes[0].rates[7] = 180;
2505         modes[0].rates[8] = 240;
2506         modes[0].rates[9] = 360;
2507         modes[0].rates[10] = 480;
2508         modes[0].rates[11] = 540;
2509
2510         modes[1].mode = HOSTAPD_MODE_IEEE80211B;
2511         modes[1].num_channels = 11;
2512         modes[1].num_rates = 4;
2513         modes[1].channels =
2514                 os_zalloc(11 * sizeof(struct hostapd_channel_data));
2515         modes[1].rates = os_zalloc(modes[1].num_rates * sizeof(int));
2516         if (modes[1].channels == NULL || modes[1].rates == NULL)
2517                 goto fail;
2518         for (i = 0; i < 11; i++) {
2519                 modes[1].channels[i].chan = i + 1;
2520                 modes[1].channels[i].freq = 2412 + 5 * i;
2521                 modes[1].channels[i].flag = 0;
2522         }
2523         modes[1].rates[0] = 10;
2524         modes[1].rates[1] = 20;
2525         modes[1].rates[2] = 55;
2526         modes[1].rates[3] = 110;
2527
2528         modes[2].mode = HOSTAPD_MODE_IEEE80211A;
2529         modes[2].num_channels = 1;
2530         modes[2].num_rates = 8;
2531         modes[2].channels = os_zalloc(sizeof(struct hostapd_channel_data));
2532         modes[2].rates = os_zalloc(modes[2].num_rates * sizeof(int));
2533         if (modes[2].channels == NULL || modes[2].rates == NULL)
2534                 goto fail;
2535         modes[2].channels[0].chan = 60;
2536         modes[2].channels[0].freq = 5300;
2537         modes[2].channels[0].flag = 0;
2538         modes[2].rates[0] = 60;
2539         modes[2].rates[1] = 90;
2540         modes[2].rates[2] = 120;
2541         modes[2].rates[3] = 180;
2542         modes[2].rates[4] = 240;
2543         modes[2].rates[5] = 360;
2544         modes[2].rates[6] = 480;
2545         modes[2].rates[7] = 540;
2546
2547         return modes;
2548
2549 fail:
2550         if (modes) {
2551                 for (i = 0; i < *num_modes; i++) {
2552                         os_free(modes[i].channels);
2553                         os_free(modes[i].rates);
2554                 }
2555                 os_free(modes);
2556         }
2557         return NULL;
2558 }
2559
2560
2561 static int wpa_driver_test_set_freq(void *priv,
2562                                     struct hostapd_freq_params *freq)
2563 {
2564         struct wpa_driver_test_data *drv = priv;
2565         wpa_printf(MSG_DEBUG, "test: set_freq %u MHz", freq->freq);
2566         drv->current_freq = freq->freq;
2567         return 0;
2568 }
2569
2570
2571 static int wpa_driver_test_send_action(void *priv, unsigned int freq,
2572                                        const u8 *dst, const u8 *src,
2573                                        const u8 *data, size_t data_len)
2574 {
2575         struct wpa_driver_test_data *drv = priv;
2576         int ret = -1;
2577         u8 *buf;
2578         struct ieee80211_hdr *hdr;
2579
2580         wpa_printf(MSG_DEBUG, "test: Send Action frame");
2581
2582         if ((drv->remain_on_channel_freq &&
2583              freq != drv->remain_on_channel_freq) ||
2584             (drv->remain_on_channel_freq == 0 &&
2585              freq != (unsigned int) drv->current_freq)) {
2586                 wpa_printf(MSG_DEBUG, "test: Reject Action frame TX on "
2587                            "unexpected channel: freq=%u MHz (current_freq=%u "
2588                            "MHz, remain-on-channel freq=%u MHz)",
2589                            freq, drv->current_freq,
2590                            drv->remain_on_channel_freq);
2591                 return -1;
2592         }
2593
2594         buf = os_zalloc(24 + data_len);
2595         if (buf == NULL)
2596                 return ret;
2597         os_memcpy(buf + 24, data, data_len);
2598         hdr = (struct ieee80211_hdr *) buf;
2599         hdr->frame_control =
2600                 IEEE80211_FC(WLAN_FC_TYPE_MGMT, WLAN_FC_STYPE_ACTION);
2601         os_memcpy(hdr->addr1, dst, ETH_ALEN);
2602         os_memcpy(hdr->addr2, src, ETH_ALEN);
2603         os_memcpy(hdr->addr3, "\xff\xff\xff\xff\xff\xff", ETH_ALEN);
2604
2605         ret = wpa_driver_test_send_mlme(priv, buf, 24 + data_len);
2606         os_free(buf);
2607         return ret;
2608 }
2609
2610
2611 static int wpa_driver_test_alloc_interface_addr(void *priv, u8 *addr)
2612 {
2613         struct wpa_driver_test_data *drv = priv;
2614         drv->alloc_iface_idx++;
2615         addr[0] = 0x02; /* locally administered */
2616         sha1_prf(drv->own_addr, ETH_ALEN, "hostapd test addr generation",
2617                  (const u8 *) &drv->alloc_iface_idx,
2618                  sizeof(drv->alloc_iface_idx),
2619                  addr + 1, ETH_ALEN - 1);
2620         return 0;
2621 }
2622
2623
2624 static void wpa_driver_test_release_interface_addr(void *priv, const u8 *addr)
2625 {
2626 }
2627
2628
2629 static void test_remain_on_channel_timeout(void *eloop_ctx, void *timeout_ctx)
2630 {
2631         struct wpa_driver_test_data *drv = eloop_ctx;
2632         union wpa_event_data data;
2633
2634         wpa_printf(MSG_DEBUG, "test: Remain-on-channel timeout");
2635
2636         os_memset(&data, 0, sizeof(data));
2637         data.remain_on_channel.freq = drv->remain_on_channel_freq;
2638         data.remain_on_channel.duration = drv->remain_on_channel_duration;
2639         wpa_supplicant_event(drv->ctx, EVENT_CANCEL_REMAIN_ON_CHANNEL, &data);
2640
2641         drv->remain_on_channel_freq = 0;
2642 }
2643
2644
2645 static int wpa_driver_test_remain_on_channel(void *priv, unsigned int freq,
2646                                              unsigned int duration)
2647 {
2648         struct wpa_driver_test_data *drv = priv;
2649         union wpa_event_data data;
2650
2651         wpa_printf(MSG_DEBUG, "%s(freq=%u, duration=%u)",
2652                    __func__, freq, duration);
2653         if (drv->remain_on_channel_freq &&
2654             drv->remain_on_channel_freq != freq) {
2655                 wpa_printf(MSG_DEBUG, "test: Refuse concurrent "
2656                            "remain_on_channel request");
2657                 return -1;
2658         }
2659
2660         drv->remain_on_channel_freq = freq;
2661         drv->remain_on_channel_duration = duration;
2662         eloop_cancel_timeout(test_remain_on_channel_timeout, drv, NULL);
2663         eloop_register_timeout(duration / 1000, (duration % 1000) * 1000,
2664                                test_remain_on_channel_timeout, drv, NULL);
2665
2666         os_memset(&data, 0, sizeof(data));
2667         data.remain_on_channel.freq = freq;
2668         data.remain_on_channel.duration = duration;
2669         wpa_supplicant_event(drv->ctx, EVENT_REMAIN_ON_CHANNEL, &data);
2670
2671         return 0;
2672 }
2673
2674
2675 static int wpa_driver_test_cancel_remain_on_channel(void *priv)
2676 {
2677         struct wpa_driver_test_data *drv = priv;
2678         wpa_printf(MSG_DEBUG, "%s", __func__);
2679         if (!drv->remain_on_channel_freq)
2680                 return -1;
2681         drv->remain_on_channel_freq = 0;
2682         eloop_cancel_timeout(test_remain_on_channel_timeout, drv, NULL);
2683         return 0;
2684 }
2685
2686
2687 static int wpa_driver_test_probe_req_report(void *priv, int report)
2688 {
2689         struct wpa_driver_test_data *drv = priv;
2690         wpa_printf(MSG_DEBUG, "%s(report=%d)", __func__, report);
2691         drv->probe_req_report = report;
2692         return 0;
2693 }
2694
2695
2696 const struct wpa_driver_ops wpa_driver_test_ops = {
2697         "test",
2698         "wpa_supplicant test driver",
2699         .hapd_init = test_driver_init,
2700         .hapd_deinit = wpa_driver_test_deinit,
2701         .hapd_send_eapol = test_driver_send_eapol,
2702         .send_mlme = wpa_driver_test_send_mlme,
2703         .set_generic_elem = test_driver_set_generic_elem,
2704         .sta_deauth = test_driver_sta_deauth,
2705         .sta_disassoc = test_driver_sta_disassoc,
2706         .get_hw_feature_data = wpa_driver_test_get_hw_feature_data,
2707         .if_add = test_driver_if_add,
2708         .if_remove = test_driver_if_remove,
2709         .valid_bss_mask = test_driver_valid_bss_mask,
2710         .hapd_set_ssid = test_driver_set_ssid,
2711         .set_privacy = test_driver_set_privacy,
2712         .set_sta_vlan = test_driver_set_sta_vlan,
2713         .sta_add = test_driver_sta_add,
2714         .send_ether = test_driver_send_ether,
2715         .set_ap_wps_ie = test_driver_set_ap_wps_ie,
2716         .get_bssid = wpa_driver_test_get_bssid,
2717         .get_ssid = wpa_driver_test_get_ssid,
2718         .set_key = wpa_driver_test_set_key,
2719         .deinit = wpa_driver_test_deinit,
2720         .set_param = wpa_driver_test_set_param,
2721         .deauthenticate = wpa_driver_test_deauthenticate,
2722         .disassociate = wpa_driver_test_disassociate,
2723         .associate = wpa_driver_test_associate,
2724         .get_capa = wpa_driver_test_get_capa,
2725         .get_mac_addr = wpa_driver_test_get_mac_addr,
2726         .send_eapol = wpa_driver_test_send_eapol,
2727         .mlme_setprotection = wpa_driver_test_mlme_setprotection,
2728         .set_channel = wpa_driver_test_set_channel,
2729         .set_ssid = wpa_driver_test_set_ssid,
2730         .set_bssid = wpa_driver_test_set_bssid,
2731         .mlme_add_sta = wpa_driver_test_mlme_add_sta,
2732         .mlme_remove_sta = wpa_driver_test_mlme_remove_sta,
2733         .get_scan_results2 = wpa_driver_test_get_scan_results2,
2734         .global_init = wpa_driver_test_global_init,
2735         .global_deinit = wpa_driver_test_global_deinit,
2736         .init2 = wpa_driver_test_init2,
2737         .get_interfaces = wpa_driver_test_get_interfaces,
2738         .scan2 = wpa_driver_test_scan,
2739         .set_freq = wpa_driver_test_set_freq,
2740         .send_action = wpa_driver_test_send_action,
2741         .alloc_interface_addr = wpa_driver_test_alloc_interface_addr,
2742         .release_interface_addr = wpa_driver_test_release_interface_addr,
2743         .remain_on_channel = wpa_driver_test_remain_on_channel,
2744         .cancel_remain_on_channel = wpa_driver_test_cancel_remain_on_channel,
2745         .probe_req_report = wpa_driver_test_probe_req_report,
2746 };