Add drv_event_eapol_rx() helper
[libeap.git] / src / drivers / driver_test.c
1 /*
2  * Testing driver interface for a simulated network driver
3  * Copyright (c) 2004-2009, Jouni Malinen <j@w1.fi>
4  *
5  * This program is free software; you can redistribute it and/or modify
6  * it under the terms of the GNU General Public License version 2 as
7  * published by the Free Software Foundation.
8  *
9  * Alternatively, this software may be distributed under the terms of BSD
10  * license.
11  *
12  * See README and COPYING for more details.
13  */
14
15 /* Make sure we get winsock2.h for Windows build to get sockaddr_storage */
16 #include "build_config.h"
17 #ifdef CONFIG_NATIVE_WINDOWS
18 #include <winsock2.h>
19 #endif /* CONFIG_NATIVE_WINDOWS */
20
21 #include "utils/includes.h"
22
23 #ifndef CONFIG_NATIVE_WINDOWS
24 #include <sys/un.h>
25 #include <dirent.h>
26 #include <sys/stat.h>
27 #define DRIVER_TEST_UNIX
28 #endif /* CONFIG_NATIVE_WINDOWS */
29
30 #include "utils/common.h"
31 #include "utils/eloop.h"
32 #include "utils/trace.h"
33 #include "common/ieee802_11_defs.h"
34 #include "crypto/sha1.h"
35 #include "l2_packet/l2_packet.h"
36 #include "driver.h"
37
38
39 struct test_client_socket {
40         struct test_client_socket *next;
41         u8 addr[ETH_ALEN];
42         struct sockaddr_un un;
43         socklen_t unlen;
44         struct test_driver_bss *bss;
45 };
46
47 struct test_driver_bss {
48         struct test_driver_bss *next;
49         void *bss_ctx;
50         char ifname[IFNAMSIZ + 1];
51         u8 bssid[ETH_ALEN];
52         u8 *ie;
53         size_t ielen;
54         u8 *wps_beacon_ie;
55         size_t wps_beacon_ie_len;
56         u8 *wps_probe_resp_ie;
57         size_t wps_probe_resp_ie_len;
58         u8 ssid[32];
59         size_t ssid_len;
60         int privacy;
61 };
62
63 struct wpa_driver_test_global {
64         int bss_add_used;
65         u8 req_addr[ETH_ALEN];
66 };
67
68 struct wpa_driver_test_data {
69         struct wpa_driver_test_global *global;
70         void *ctx;
71         WPA_TRACE_REF(ctx);
72         char ifname[IFNAMSIZ + 1];
73         u8 own_addr[ETH_ALEN];
74         int test_socket;
75 #ifdef DRIVER_TEST_UNIX
76         struct sockaddr_un hostapd_addr;
77 #endif /* DRIVER_TEST_UNIX */
78         int hostapd_addr_set;
79         struct sockaddr_in hostapd_addr_udp;
80         int hostapd_addr_udp_set;
81         char *own_socket_path;
82         char *test_dir;
83         u8 bssid[ETH_ALEN];
84         u8 ssid[32];
85         size_t ssid_len;
86 #define MAX_SCAN_RESULTS 30
87         struct wpa_scan_res *scanres[MAX_SCAN_RESULTS];
88         size_t num_scanres;
89         int use_associnfo;
90         u8 assoc_wpa_ie[80];
91         size_t assoc_wpa_ie_len;
92         int use_mlme;
93         int associated;
94         u8 *probe_req_ie;
95         size_t probe_req_ie_len;
96         int ibss;
97         int privacy;
98         int ap;
99
100         struct test_client_socket *cli;
101         struct test_driver_bss *bss;
102         int udp_port;
103
104         int alloc_iface_idx;
105
106         int probe_req_report;
107         unsigned int remain_on_channel_freq;
108         unsigned int remain_on_channel_duration;
109
110         int current_freq;
111 };
112
113
114 static void wpa_driver_test_deinit(void *priv);
115 static int wpa_driver_test_attach(struct wpa_driver_test_data *drv,
116                                   const char *dir, int ap);
117 static void wpa_driver_test_close_test_socket(
118         struct wpa_driver_test_data *drv);
119 static void test_remain_on_channel_timeout(void *eloop_ctx, void *timeout_ctx);
120
121
122 static void test_driver_free_bss(struct test_driver_bss *bss)
123 {
124         os_free(bss->ie);
125         os_free(bss->wps_beacon_ie);
126         os_free(bss->wps_probe_resp_ie);
127         os_free(bss);
128 }
129
130
131 static void test_driver_free_bsses(struct wpa_driver_test_data *drv)
132 {
133         struct test_driver_bss *bss, *prev_bss;
134
135         bss = drv->bss;
136         while (bss) {
137                 prev_bss = bss;
138                 bss = bss->next;
139                 test_driver_free_bss(prev_bss);
140         }
141
142         drv->bss = NULL;
143 }
144
145
146 static struct test_client_socket *
147 test_driver_get_cli(struct wpa_driver_test_data *drv, struct sockaddr_un *from,
148                     socklen_t fromlen)
149 {
150         struct test_client_socket *cli = drv->cli;
151
152         while (cli) {
153                 if (cli->unlen == fromlen &&
154                     strncmp(cli->un.sun_path, from->sun_path,
155                             fromlen - sizeof(cli->un.sun_family)) == 0)
156                         return cli;
157                 cli = cli->next;
158         }
159
160         return NULL;
161 }
162
163
164 static int test_driver_send_eapol(void *priv, const u8 *addr, const u8 *data,
165                                   size_t data_len, int encrypt,
166                                   const u8 *own_addr)
167 {
168         struct wpa_driver_test_data *drv = priv;
169         struct test_client_socket *cli;
170         struct msghdr msg;
171         struct iovec io[3];
172         struct l2_ethhdr eth;
173
174         if (drv->test_socket < 0)
175                 return -1;
176
177         cli = drv->cli;
178         while (cli) {
179                 if (memcmp(cli->addr, addr, ETH_ALEN) == 0)
180                         break;
181                 cli = cli->next;
182         }
183
184         if (!cli) {
185                 wpa_printf(MSG_DEBUG, "%s: no destination client entry",
186                            __func__);
187                 return -1;
188         }
189
190         memcpy(eth.h_dest, addr, ETH_ALEN);
191         memcpy(eth.h_source, own_addr, ETH_ALEN);
192         eth.h_proto = host_to_be16(ETH_P_EAPOL);
193
194         io[0].iov_base = "EAPOL ";
195         io[0].iov_len = 6;
196         io[1].iov_base = &eth;
197         io[1].iov_len = sizeof(eth);
198         io[2].iov_base = (u8 *) data;
199         io[2].iov_len = data_len;
200
201         memset(&msg, 0, sizeof(msg));
202         msg.msg_iov = io;
203         msg.msg_iovlen = 3;
204         msg.msg_name = &cli->un;
205         msg.msg_namelen = cli->unlen;
206         return sendmsg(drv->test_socket, &msg, 0);
207 }
208
209
210 static int test_driver_send_ether(void *priv, const u8 *dst, const u8 *src,
211                                   u16 proto, const u8 *data, size_t data_len)
212 {
213         struct wpa_driver_test_data *drv = priv;
214         struct msghdr msg;
215         struct iovec io[3];
216         struct l2_ethhdr eth;
217         char desttxt[30];
218         struct sockaddr_un addr;
219         struct dirent *dent;
220         DIR *dir;
221         int ret = 0, broadcast = 0, count = 0;
222
223         if (drv->test_socket < 0 || drv->test_dir == NULL) {
224                 wpa_printf(MSG_DEBUG, "%s: invalid parameters (sock=%d "
225                            "test_dir=%p)",
226                            __func__, drv->test_socket, drv->test_dir);
227                 return -1;
228         }
229
230         broadcast = memcmp(dst, "\xff\xff\xff\xff\xff\xff", ETH_ALEN) == 0;
231         snprintf(desttxt, sizeof(desttxt), MACSTR, MAC2STR(dst));
232
233         memcpy(eth.h_dest, dst, ETH_ALEN);
234         memcpy(eth.h_source, src, ETH_ALEN);
235         eth.h_proto = host_to_be16(proto);
236
237         io[0].iov_base = "ETHER ";
238         io[0].iov_len = 6;
239         io[1].iov_base = &eth;
240         io[1].iov_len = sizeof(eth);
241         io[2].iov_base = (u8 *) data;
242         io[2].iov_len = data_len;
243
244         memset(&msg, 0, sizeof(msg));
245         msg.msg_iov = io;
246         msg.msg_iovlen = 3;
247
248         dir = opendir(drv->test_dir);
249         if (dir == NULL) {
250                 perror("test_driver: opendir");
251                 return -1;
252         }
253         while ((dent = readdir(dir))) {
254 #ifdef _DIRENT_HAVE_D_TYPE
255                 /* Skip the file if it is not a socket. Also accept
256                  * DT_UNKNOWN (0) in case the C library or underlying file
257                  * system does not support d_type. */
258                 if (dent->d_type != DT_SOCK && dent->d_type != DT_UNKNOWN)
259                         continue;
260 #endif /* _DIRENT_HAVE_D_TYPE */
261                 if (strcmp(dent->d_name, ".") == 0 ||
262                     strcmp(dent->d_name, "..") == 0)
263                         continue;
264
265                 memset(&addr, 0, sizeof(addr));
266                 addr.sun_family = AF_UNIX;
267                 snprintf(addr.sun_path, sizeof(addr.sun_path), "%s/%s",
268                          drv->test_dir, dent->d_name);
269
270                 if (strcmp(addr.sun_path, drv->own_socket_path) == 0)
271                         continue;
272                 if (!broadcast && strstr(dent->d_name, desttxt) == NULL)
273                         continue;
274
275                 wpa_printf(MSG_DEBUG, "%s: Send ether frame to %s",
276                            __func__, dent->d_name);
277
278                 msg.msg_name = &addr;
279                 msg.msg_namelen = sizeof(addr);
280                 ret = sendmsg(drv->test_socket, &msg, 0);
281                 if (ret < 0)
282                         perror("driver_test: sendmsg");
283                 count++;
284         }
285         closedir(dir);
286
287         if (!broadcast && count == 0) {
288                 wpa_printf(MSG_DEBUG, "%s: Destination " MACSTR " not found",
289                            __func__, MAC2STR(dst));
290                 return -1;
291         }
292
293         return ret;
294 }
295
296
297 static int wpa_driver_test_send_mlme(void *priv, const u8 *data,
298                                      size_t data_len)
299 {
300         struct wpa_driver_test_data *drv = priv;
301         struct msghdr msg;
302         struct iovec io[2];
303         const u8 *dest;
304         struct sockaddr_un addr;
305         struct dirent *dent;
306         DIR *dir;
307         int broadcast;
308         int ret = 0;
309         struct ieee80211_hdr *hdr;
310         u16 fc;
311         char cmd[50];
312         int freq;
313 #ifdef HOSTAPD
314         char desttxt[30];
315 #endif /* HOSTAPD */
316         union wpa_event_data event;
317
318         wpa_hexdump(MSG_MSGDUMP, "test_send_mlme", data, data_len);
319         if (drv->test_socket < 0 || data_len < 10) {
320                 wpa_printf(MSG_DEBUG, "%s: invalid parameters (sock=%d len=%lu"
321                            " test_dir=%p)",
322                            __func__, drv->test_socket,
323                            (unsigned long) data_len,
324                            drv->test_dir);
325                 return -1;
326         }
327
328         dest = data + 4;
329         broadcast = os_memcmp(dest, "\xff\xff\xff\xff\xff\xff", ETH_ALEN) == 0;
330
331 #ifdef HOSTAPD
332         snprintf(desttxt, sizeof(desttxt), MACSTR, MAC2STR(dest));
333 #endif /* HOSTAPD */
334
335         if (drv->remain_on_channel_freq)
336                 freq = drv->remain_on_channel_freq;
337         else
338                 freq = drv->current_freq;
339         wpa_printf(MSG_DEBUG, "test_driver(%s): MLME TX on freq %d MHz",
340                    drv->ifname, freq);
341         os_snprintf(cmd, sizeof(cmd), "MLME freq=%d ", freq);
342         io[0].iov_base = cmd;
343         io[0].iov_len = os_strlen(cmd);
344         io[1].iov_base = (void *) data;
345         io[1].iov_len = data_len;
346
347         os_memset(&msg, 0, sizeof(msg));
348         msg.msg_iov = io;
349         msg.msg_iovlen = 2;
350
351 #ifdef HOSTAPD
352         if (drv->test_dir == NULL) {
353                 wpa_printf(MSG_DEBUG, "%s: test_dir == NULL", __func__);
354                 return -1;
355         }
356
357         dir = opendir(drv->test_dir);
358         if (dir == NULL) {
359                 perror("test_driver: opendir");
360                 return -1;
361         }
362         while ((dent = readdir(dir))) {
363 #ifdef _DIRENT_HAVE_D_TYPE
364                 /* Skip the file if it is not a socket. Also accept
365                  * DT_UNKNOWN (0) in case the C library or underlying file
366                  * system does not support d_type. */
367                 if (dent->d_type != DT_SOCK && dent->d_type != DT_UNKNOWN)
368                         continue;
369 #endif /* _DIRENT_HAVE_D_TYPE */
370                 if (os_strcmp(dent->d_name, ".") == 0 ||
371                     os_strcmp(dent->d_name, "..") == 0)
372                         continue;
373
374                 os_memset(&addr, 0, sizeof(addr));
375                 addr.sun_family = AF_UNIX;
376                 os_snprintf(addr.sun_path, sizeof(addr.sun_path), "%s/%s",
377                             drv->test_dir, dent->d_name);
378
379                 if (os_strcmp(addr.sun_path, drv->own_socket_path) == 0)
380                         continue;
381                 if (!broadcast && os_strstr(dent->d_name, desttxt) == NULL)
382                         continue;
383
384                 wpa_printf(MSG_DEBUG, "%s: Send management frame to %s",
385                            __func__, dent->d_name);
386
387                 msg.msg_name = &addr;
388                 msg.msg_namelen = sizeof(addr);
389                 ret = sendmsg(drv->test_socket, &msg, 0);
390                 if (ret < 0)
391                         perror("driver_test: sendmsg(test_socket)");
392         }
393         closedir(dir);
394 #else /* HOSTAPD */
395
396         if (os_memcmp(dest, drv->bssid, ETH_ALEN) == 0 ||
397             drv->test_dir == NULL) {
398                 if (drv->hostapd_addr_udp_set) {
399                         msg.msg_name = &drv->hostapd_addr_udp;
400                         msg.msg_namelen = sizeof(drv->hostapd_addr_udp);
401                 } else {
402 #ifdef DRIVER_TEST_UNIX
403                         msg.msg_name = &drv->hostapd_addr;
404                         msg.msg_namelen = sizeof(drv->hostapd_addr);
405 #endif /* DRIVER_TEST_UNIX */
406                 }
407         } else if (broadcast) {
408                 dir = opendir(drv->test_dir);
409                 if (dir == NULL)
410                         return -1;
411                 while ((dent = readdir(dir))) {
412 #ifdef _DIRENT_HAVE_D_TYPE
413                         /* Skip the file if it is not a socket.
414                          * Also accept DT_UNKNOWN (0) in case
415                          * the C library or underlying file
416                          * system does not support d_type. */
417                         if (dent->d_type != DT_SOCK &&
418                             dent->d_type != DT_UNKNOWN)
419                                 continue;
420 #endif /* _DIRENT_HAVE_D_TYPE */
421                         if (os_strcmp(dent->d_name, ".") == 0 ||
422                             os_strcmp(dent->d_name, "..") == 0)
423                                 continue;
424                         wpa_printf(MSG_DEBUG, "%s: Send broadcast MLME to %s",
425                                    __func__, dent->d_name);
426                         os_memset(&addr, 0, sizeof(addr));
427                         addr.sun_family = AF_UNIX;
428                         os_snprintf(addr.sun_path, sizeof(addr.sun_path),
429                                     "%s/%s", drv->test_dir, dent->d_name);
430
431                         msg.msg_name = &addr;
432                         msg.msg_namelen = sizeof(addr);
433
434                         ret = sendmsg(drv->test_socket, &msg, 0);
435                         if (ret < 0)
436                                 perror("driver_test: sendmsg(test_socket)");
437                 }
438                 closedir(dir);
439                 return ret;
440         } else {
441                 struct stat st;
442                 os_memset(&addr, 0, sizeof(addr));
443                 addr.sun_family = AF_UNIX;
444                 os_snprintf(addr.sun_path, sizeof(addr.sun_path),
445                             "%s/AP-" MACSTR, drv->test_dir, MAC2STR(dest));
446                 if (stat(addr.sun_path, &st) < 0) {
447                         os_snprintf(addr.sun_path, sizeof(addr.sun_path),
448                                     "%s/STA-" MACSTR,
449                                     drv->test_dir, MAC2STR(dest));
450                 }
451                 msg.msg_name = &addr;
452                 msg.msg_namelen = sizeof(addr);
453         }
454
455         if (sendmsg(drv->test_socket, &msg, 0) < 0) {
456                 perror("sendmsg(test_socket)");
457                 return -1;
458         }
459 #endif /* HOSTAPD */
460
461         hdr = (struct ieee80211_hdr *) data;
462         fc = le_to_host16(hdr->frame_control);
463
464         os_memset(&event, 0, sizeof(event));
465         event.tx_status.type = WLAN_FC_GET_TYPE(fc);
466         event.tx_status.stype = WLAN_FC_GET_STYPE(fc);
467         event.tx_status.dst = hdr->addr1;
468         event.tx_status.data = data;
469         event.tx_status.data_len = data_len;
470         event.tx_status.ack = ret >= 0;
471         wpa_supplicant_event(drv->ctx, EVENT_TX_STATUS, &event);
472
473         return ret;
474 }
475
476
477 static void test_driver_scan(struct wpa_driver_test_data *drv,
478                              struct sockaddr_un *from, socklen_t fromlen,
479                              char *data)
480 {
481         char buf[512], *pos, *end;
482         int ret;
483         struct test_driver_bss *bss;
484         u8 sa[ETH_ALEN];
485         u8 ie[512];
486         size_t ielen;
487         union wpa_event_data event;
488
489         /* data: optional [ ' ' | STA-addr | ' ' | IEs(hex) ] */
490
491         wpa_printf(MSG_DEBUG, "test_driver: SCAN");
492
493         if (*data) {
494                 if (*data != ' ' ||
495                     hwaddr_aton(data + 1, sa)) {
496                         wpa_printf(MSG_DEBUG, "test_driver: Unexpected SCAN "
497                                    "command format");
498                         return;
499                 }
500
501                 data += 18;
502                 while (*data == ' ')
503                         data++;
504                 ielen = os_strlen(data) / 2;
505                 if (ielen > sizeof(ie))
506                         ielen = sizeof(ie);
507                 if (hexstr2bin(data, ie, ielen) < 0)
508                         ielen = 0;
509
510                 wpa_printf(MSG_DEBUG, "test_driver: Scan from " MACSTR,
511                            MAC2STR(sa));
512                 wpa_hexdump(MSG_MSGDUMP, "test_driver: scan IEs", ie, ielen);
513
514                 os_memset(&event, 0, sizeof(event));
515                 event.rx_probe_req.sa = sa;
516                 event.rx_probe_req.ie = ie;
517                 event.rx_probe_req.ie_len = ielen;
518                 wpa_supplicant_event(drv->ctx, EVENT_RX_PROBE_REQ, &event);
519         }
520
521         for (bss = drv->bss; bss; bss = bss->next) {
522                 pos = buf;
523                 end = buf + sizeof(buf);
524
525                 /* reply: SCANRESP BSSID SSID IEs */
526                 ret = snprintf(pos, end - pos, "SCANRESP " MACSTR " ",
527                                MAC2STR(bss->bssid));
528                 if (ret < 0 || ret >= end - pos)
529                         return;
530                 pos += ret;
531                 pos += wpa_snprintf_hex(pos, end - pos,
532                                         bss->ssid, bss->ssid_len);
533                 ret = snprintf(pos, end - pos, " ");
534                 if (ret < 0 || ret >= end - pos)
535                         return;
536                 pos += ret;
537                 pos += wpa_snprintf_hex(pos, end - pos, bss->ie, bss->ielen);
538                 pos += wpa_snprintf_hex(pos, end - pos, bss->wps_probe_resp_ie,
539                                         bss->wps_probe_resp_ie_len);
540
541                 if (bss->privacy) {
542                         ret = snprintf(pos, end - pos, " PRIVACY");
543                         if (ret < 0 || ret >= end - pos)
544                                 return;
545                         pos += ret;
546                 }
547
548                 sendto(drv->test_socket, buf, pos - buf, 0,
549                        (struct sockaddr *) from, fromlen);
550         }
551 }
552
553
554 static void test_driver_assoc(struct wpa_driver_test_data *drv,
555                               struct sockaddr_un *from, socklen_t fromlen,
556                               char *data)
557 {
558         struct test_client_socket *cli;
559         u8 ie[256], ssid[32];
560         size_t ielen, ssid_len = 0;
561         char *pos, *pos2, cmd[50];
562         struct test_driver_bss *bss;
563
564         /* data: STA-addr SSID(hex) IEs(hex) */
565
566         cli = os_zalloc(sizeof(*cli));
567         if (cli == NULL)
568                 return;
569
570         if (hwaddr_aton(data, cli->addr)) {
571                 printf("test_socket: Invalid MAC address '%s' in ASSOC\n",
572                        data);
573                 os_free(cli);
574                 return;
575         }
576         pos = data + 17;
577         while (*pos == ' ')
578                 pos++;
579         pos2 = strchr(pos, ' ');
580         ielen = 0;
581         if (pos2) {
582                 ssid_len = (pos2 - pos) / 2;
583                 if (hexstr2bin(pos, ssid, ssid_len) < 0) {
584                         wpa_printf(MSG_DEBUG, "%s: Invalid SSID", __func__);
585                         os_free(cli);
586                         return;
587                 }
588                 wpa_hexdump_ascii(MSG_DEBUG, "test_driver_assoc: SSID",
589                                   ssid, ssid_len);
590
591                 pos = pos2 + 1;
592                 ielen = strlen(pos) / 2;
593                 if (ielen > sizeof(ie))
594                         ielen = sizeof(ie);
595                 if (hexstr2bin(pos, ie, ielen) < 0)
596                         ielen = 0;
597         }
598
599         for (bss = drv->bss; bss; bss = bss->next) {
600                 if (bss->ssid_len == ssid_len &&
601                     memcmp(bss->ssid, ssid, ssid_len) == 0)
602                         break;
603         }
604         if (bss == NULL) {
605                 wpa_printf(MSG_DEBUG, "%s: No matching SSID found from "
606                            "configured BSSes", __func__);
607                 os_free(cli);
608                 return;
609         }
610
611         cli->bss = bss;
612         memcpy(&cli->un, from, sizeof(cli->un));
613         cli->unlen = fromlen;
614         cli->next = drv->cli;
615         drv->cli = cli;
616         wpa_hexdump_ascii(MSG_DEBUG, "test_socket: ASSOC sun_path",
617                           (const u8 *) cli->un.sun_path,
618                           cli->unlen - sizeof(cli->un.sun_family));
619
620         snprintf(cmd, sizeof(cmd), "ASSOCRESP " MACSTR " 0",
621                  MAC2STR(bss->bssid));
622         sendto(drv->test_socket, cmd, strlen(cmd), 0,
623                (struct sockaddr *) from, fromlen);
624
625         drv_event_assoc(bss->bss_ctx, cli->addr, ie, ielen);
626 }
627
628
629 static void test_driver_disassoc(struct wpa_driver_test_data *drv,
630                                  struct sockaddr_un *from, socklen_t fromlen)
631 {
632         struct test_client_socket *cli;
633
634         cli = test_driver_get_cli(drv, from, fromlen);
635         if (!cli)
636                 return;
637
638         drv_event_disassoc(drv->ctx, cli->addr);
639 }
640
641
642 static void test_driver_eapol(struct wpa_driver_test_data *drv,
643                               struct sockaddr_un *from, socklen_t fromlen,
644                               u8 *data, size_t datalen)
645 {
646 #ifdef HOSTAPD
647         struct test_client_socket *cli;
648 #endif /* HOSTAPD */
649         const u8 *src = NULL;
650
651         if (datalen > 14) {
652                 /* Skip Ethernet header */
653                 src = data + ETH_ALEN;
654                 wpa_printf(MSG_DEBUG, "test_driver: dst=" MACSTR " src="
655                            MACSTR " proto=%04x",
656                            MAC2STR(data), MAC2STR(src),
657                            WPA_GET_BE16(data + 2 * ETH_ALEN));
658                 data += 14;
659                 datalen -= 14;
660         }
661
662 #ifdef HOSTAPD
663         cli = test_driver_get_cli(drv, from, fromlen);
664         if (cli) {
665                 drv_event_eapol_rx(cli->bss->bss_ctx, cli->addr, data,
666                                    datalen);
667         } else {
668                 wpa_printf(MSG_DEBUG, "test_socket: EAPOL from unknown "
669                            "client");
670         }
671 #else /* HOSTAPD */
672         if (src)
673                 drv_event_eapol_rx(drv->ctx, src, data, datalen);
674 #endif /* HOSTAPD */
675 }
676
677
678 static void test_driver_ether(struct wpa_driver_test_data *drv,
679                               struct sockaddr_un *from, socklen_t fromlen,
680                               u8 *data, size_t datalen)
681 {
682         struct l2_ethhdr *eth;
683
684         if (datalen < sizeof(*eth))
685                 return;
686
687         eth = (struct l2_ethhdr *) data;
688         wpa_printf(MSG_DEBUG, "test_driver: RX ETHER dst=" MACSTR " src="
689                    MACSTR " proto=%04x",
690                    MAC2STR(eth->h_dest), MAC2STR(eth->h_source),
691                    be_to_host16(eth->h_proto));
692
693 #ifdef CONFIG_IEEE80211R
694         if (be_to_host16(eth->h_proto) == ETH_P_RRB) {
695                 union wpa_event_data ev;
696                 os_memset(&ev, 0, sizeof(ev));
697                 ev.ft_rrb_rx.src = eth->h_source;
698                 ev.ft_rrb_rx.data = data + sizeof(*eth);
699                 ev.ft_rrb_rx.data_len = datalen - sizeof(*eth);
700         }
701 #endif /* CONFIG_IEEE80211R */
702 }
703
704
705 static void test_driver_mlme(struct wpa_driver_test_data *drv,
706                              struct sockaddr_un *from, socklen_t fromlen,
707                              u8 *data, size_t datalen)
708 {
709         struct ieee80211_hdr *hdr;
710         u16 fc;
711         union wpa_event_data event;
712         int freq = 0, own_freq;
713
714         if (datalen > 6 && os_memcmp(data, "freq=", 5) == 0) {
715                 size_t pos;
716                 for (pos = 5; pos < datalen; pos++) {
717                         if (data[pos] == ' ')
718                                 break;
719                 }
720                 if (pos < datalen) {
721                         freq = atoi((const char *) &data[5]);
722                         wpa_printf(MSG_DEBUG, "test_driver(%s): MLME RX on "
723                                    "freq %d MHz", drv->ifname, freq);
724                         pos++;
725                         data += pos;
726                         datalen -= pos;
727                 }
728         }
729
730         if (drv->remain_on_channel_freq)
731                 own_freq = drv->remain_on_channel_freq;
732         else
733                 own_freq = drv->current_freq;
734
735         if (freq && own_freq && freq != own_freq) {
736                 wpa_printf(MSG_DEBUG, "test_driver(%s): Ignore MLME RX on "
737                            "another frequency %d MHz (own %d MHz)",
738                            drv->ifname, freq, own_freq);
739                 return;
740         }
741
742         hdr = (struct ieee80211_hdr *) data;
743
744         if (test_driver_get_cli(drv, from, fromlen) == NULL && datalen >= 16) {
745                 struct test_client_socket *cli;
746                 cli = os_zalloc(sizeof(*cli));
747                 if (cli == NULL)
748                         return;
749                 wpa_printf(MSG_DEBUG, "Adding client entry for " MACSTR,
750                            MAC2STR(hdr->addr2));
751                 memcpy(cli->addr, hdr->addr2, ETH_ALEN);
752                 memcpy(&cli->un, from, sizeof(cli->un));
753                 cli->unlen = fromlen;
754                 cli->next = drv->cli;
755                 drv->cli = cli;
756         }
757
758         wpa_hexdump(MSG_MSGDUMP, "test_driver_mlme: received frame",
759                     data, datalen);
760         fc = le_to_host16(hdr->frame_control);
761         if (WLAN_FC_GET_TYPE(fc) != WLAN_FC_TYPE_MGMT) {
762                 wpa_printf(MSG_ERROR, "%s: received non-mgmt frame",
763                            __func__);
764                 return;
765         }
766
767         os_memset(&event, 0, sizeof(event));
768         event.rx_mgmt.frame = data;
769         event.rx_mgmt.frame_len = datalen;
770         wpa_supplicant_event(drv->ctx, EVENT_RX_MGMT, &event);
771 }
772
773
774 static void test_driver_receive_unix(int sock, void *eloop_ctx, void *sock_ctx)
775 {
776         struct wpa_driver_test_data *drv = eloop_ctx;
777         char buf[2000];
778         int res;
779         struct sockaddr_un from;
780         socklen_t fromlen = sizeof(from);
781
782         res = recvfrom(sock, buf, sizeof(buf) - 1, 0,
783                        (struct sockaddr *) &from, &fromlen);
784         if (res < 0) {
785                 perror("recvfrom(test_socket)");
786                 return;
787         }
788         buf[res] = '\0';
789
790         wpa_printf(MSG_DEBUG, "test_driver: received %u bytes", res);
791
792         if (strncmp(buf, "SCAN", 4) == 0) {
793                 test_driver_scan(drv, &from, fromlen, buf + 4);
794         } else if (strncmp(buf, "ASSOC ", 6) == 0) {
795                 test_driver_assoc(drv, &from, fromlen, buf + 6);
796         } else if (strcmp(buf, "DISASSOC") == 0) {
797                 test_driver_disassoc(drv, &from, fromlen);
798         } else if (strncmp(buf, "EAPOL ", 6) == 0) {
799                 test_driver_eapol(drv, &from, fromlen, (u8 *) buf + 6,
800                                   res - 6);
801         } else if (strncmp(buf, "ETHER ", 6) == 0) {
802                 test_driver_ether(drv, &from, fromlen, (u8 *) buf + 6,
803                                   res - 6);
804         } else if (strncmp(buf, "MLME ", 5) == 0) {
805                 test_driver_mlme(drv, &from, fromlen, (u8 *) buf + 5, res - 5);
806         } else {
807                 wpa_hexdump_ascii(MSG_DEBUG, "Unknown test_socket command",
808                                   (u8 *) buf, res);
809         }
810 }
811
812
813 static struct test_driver_bss *
814 test_driver_get_bss(struct wpa_driver_test_data *drv, const char *ifname)
815 {
816         struct test_driver_bss *bss;
817
818         for (bss = drv->bss; bss; bss = bss->next) {
819                 if (os_strcmp(bss->ifname, ifname) == 0)
820                         return bss;
821         }
822         return NULL;
823 }
824
825
826 static int test_driver_set_generic_elem(const char *ifname, void *priv,
827                                         const u8 *elem, size_t elem_len)
828 {
829         struct wpa_driver_test_data *drv = priv;
830         struct test_driver_bss *bss;
831
832         bss = test_driver_get_bss(drv, ifname);
833         if (bss == NULL)
834                 return -1;
835
836         os_free(bss->ie);
837
838         if (elem == NULL) {
839                 bss->ie = NULL;
840                 bss->ielen = 0;
841                 return 0;
842         }
843
844         bss->ie = os_malloc(elem_len);
845         if (bss->ie == NULL) {
846                 bss->ielen = 0;
847                 return -1;
848         }
849
850         memcpy(bss->ie, elem, elem_len);
851         bss->ielen = elem_len;
852         return 0;
853 }
854
855
856 static int test_driver_set_ap_wps_ie(const char *ifname, void *priv,
857                                      const struct wpabuf *beacon,
858                                      const struct wpabuf *proberesp)
859 {
860         struct wpa_driver_test_data *drv = priv;
861         struct test_driver_bss *bss;
862
863         bss = test_driver_get_bss(drv, ifname);
864         if (bss == NULL)
865                 return -1;
866
867         if (beacon == NULL)
868                 wpa_printf(MSG_DEBUG, "test_driver: Clear Beacon WPS IE");
869         else
870                 wpa_hexdump_buf(MSG_DEBUG, "test_driver: Beacon WPS IE",
871                                 beacon);
872
873         os_free(bss->wps_beacon_ie);
874
875         if (beacon == NULL) {
876                 bss->wps_beacon_ie = NULL;
877                 bss->wps_beacon_ie_len = 0;
878         } else {
879                 bss->wps_beacon_ie = os_malloc(wpabuf_len(beacon));
880                 if (bss->wps_beacon_ie == NULL) {
881                         bss->wps_beacon_ie_len = 0;
882                         return -1;
883                 }
884
885                 os_memcpy(bss->wps_beacon_ie, wpabuf_head(beacon),
886                           wpabuf_len(beacon));
887                 bss->wps_beacon_ie_len = wpabuf_len(beacon);
888         }
889
890         if (proberesp == NULL)
891                 wpa_printf(MSG_DEBUG, "test_driver: Clear Probe Response WPS "
892                            "IE");
893         else
894                 wpa_hexdump_buf(MSG_DEBUG, "test_driver: Probe Response WPS "
895                                 "IE", proberesp);
896
897         os_free(bss->wps_probe_resp_ie);
898
899         if (proberesp == NULL) {
900                 bss->wps_probe_resp_ie = NULL;
901                 bss->wps_probe_resp_ie_len = 0;
902         } else {
903                 bss->wps_probe_resp_ie = os_malloc(wpabuf_len(proberesp));
904                 if (bss->wps_probe_resp_ie == NULL) {
905                         bss->wps_probe_resp_ie_len = 0;
906                         return -1;
907                 }
908
909                 os_memcpy(bss->wps_probe_resp_ie, wpabuf_head(proberesp),
910                           wpabuf_len(proberesp));
911                 bss->wps_probe_resp_ie_len = wpabuf_len(proberesp);
912         }
913
914         return 0;
915 }
916
917
918 static int test_driver_sta_deauth(void *priv, const u8 *own_addr,
919                                   const u8 *addr, int reason)
920 {
921         struct wpa_driver_test_data *drv = priv;
922         struct test_client_socket *cli;
923
924         if (drv->test_socket < 0)
925                 return -1;
926
927         cli = drv->cli;
928         while (cli) {
929                 if (memcmp(cli->addr, addr, ETH_ALEN) == 0)
930                         break;
931                 cli = cli->next;
932         }
933
934         if (!cli)
935                 return -1;
936
937         return sendto(drv->test_socket, "DEAUTH", 6, 0,
938                       (struct sockaddr *) &cli->un, cli->unlen);
939 }
940
941
942 static int test_driver_sta_disassoc(void *priv, const u8 *own_addr,
943                                     const u8 *addr, int reason)
944 {
945         struct wpa_driver_test_data *drv = priv;
946         struct test_client_socket *cli;
947
948         if (drv->test_socket < 0)
949                 return -1;
950
951         cli = drv->cli;
952         while (cli) {
953                 if (memcmp(cli->addr, addr, ETH_ALEN) == 0)
954                         break;
955                 cli = cli->next;
956         }
957
958         if (!cli)
959                 return -1;
960
961         return sendto(drv->test_socket, "DISASSOC", 8, 0,
962                       (struct sockaddr *) &cli->un, cli->unlen);
963 }
964
965
966 static int test_driver_bss_add(void *priv, const char *ifname, const u8 *bssid,
967                                void *bss_ctx)
968 {
969         struct wpa_driver_test_data *drv = priv;
970         struct test_driver_bss *bss;
971
972         wpa_printf(MSG_DEBUG, "%s(ifname=%s bssid=" MACSTR ")",
973                    __func__, ifname, MAC2STR(bssid));
974
975         bss = os_zalloc(sizeof(*bss));
976         if (bss == NULL)
977                 return -1;
978
979         bss->bss_ctx = bss_ctx;
980         os_strlcpy(bss->ifname, ifname, IFNAMSIZ);
981         memcpy(bss->bssid, bssid, ETH_ALEN);
982
983         bss->next = drv->bss;
984         drv->bss = bss;
985         drv->global->bss_add_used = 1;
986         os_memcpy(drv->global->req_addr, bssid, ETH_ALEN);
987
988         return 0;
989 }
990
991
992 static int test_driver_bss_remove(void *priv, const char *ifname)
993 {
994         struct wpa_driver_test_data *drv = priv;
995         struct test_driver_bss *bss, *prev;
996         struct test_client_socket *cli, *prev_c;
997
998         wpa_printf(MSG_DEBUG, "%s(ifname=%s)", __func__, ifname);
999
1000         for (prev = NULL, bss = drv->bss; bss; prev = bss, bss = bss->next) {
1001                 if (strcmp(bss->ifname, ifname) != 0)
1002                         continue;
1003
1004                 if (prev)
1005                         prev->next = bss->next;
1006                 else
1007                         drv->bss = bss->next;
1008
1009                 for (prev_c = NULL, cli = drv->cli; cli;
1010                      prev_c = cli, cli = cli->next) {
1011                         if (cli->bss != bss)
1012                                 continue;
1013                         if (prev_c)
1014                                 prev_c->next = cli->next;
1015                         else
1016                                 drv->cli = cli->next;
1017                         os_free(cli);
1018                         break;
1019                 }
1020
1021                 test_driver_free_bss(bss);
1022                 return 0;
1023         }
1024
1025         return -1;
1026 }
1027
1028
1029 static int test_driver_if_add(const char *iface, void *priv,
1030                               enum wpa_driver_if_type type, const char *ifname,
1031                               const u8 *addr, void *bss_ctx)
1032 {
1033         wpa_printf(MSG_DEBUG, "%s(iface=%s type=%d ifname=%s bss_ctx=%p)",
1034                    __func__, iface, type, ifname, bss_ctx);
1035         if (type == WPA_IF_AP_BSS)
1036                 return test_driver_bss_add(priv, ifname, addr, bss_ctx);
1037         return 0;
1038 }
1039
1040
1041 static int test_driver_if_remove(void *priv, enum wpa_driver_if_type type,
1042                                  const char *ifname)
1043 {
1044         wpa_printf(MSG_DEBUG, "%s(type=%d ifname=%s)", __func__, type, ifname);
1045         if (type == WPA_IF_AP_BSS)
1046                 return test_driver_bss_remove(priv, ifname);
1047         return 0;
1048 }
1049
1050
1051 static int test_driver_valid_bss_mask(void *priv, const u8 *addr,
1052                                       const u8 *mask)
1053 {
1054         return 0;
1055 }
1056
1057
1058 static int test_driver_set_ssid(const char *ifname, void *priv, const u8 *buf,
1059                                 int len)
1060 {
1061         struct wpa_driver_test_data *drv = priv;
1062         struct test_driver_bss *bss;
1063
1064         wpa_printf(MSG_DEBUG, "%s(ifname=%s)", __func__, ifname);
1065         wpa_hexdump_ascii(MSG_DEBUG, "test_driver_set_ssid: SSID", buf, len);
1066
1067         bss = test_driver_get_bss(drv, ifname);
1068         if (bss == NULL) {
1069                 wpa_printf(MSG_DEBUG, "%s(ifname=%s): failed to find BSS data",
1070                            __func__, ifname);
1071                 return -1;
1072         }
1073
1074         if (len < 0 || (size_t) len > sizeof(bss->ssid))
1075                 return -1;
1076
1077         os_memcpy(bss->ssid, buf, len);
1078         bss->ssid_len = len;
1079
1080         return 0;
1081 }
1082
1083
1084 static int test_driver_set_privacy(const char *ifname, void *priv, int enabled)
1085 {
1086         struct wpa_driver_test_data *drv = priv;
1087         struct test_driver_bss *bss;
1088
1089         wpa_printf(MSG_DEBUG, "%s(ifname=%s enabled=%d)",
1090                    __func__, ifname, enabled);
1091
1092         bss = test_driver_get_bss(drv, ifname);
1093         if (bss == NULL)
1094                 return -1;
1095
1096         bss->privacy = enabled;
1097
1098         return 0;
1099 }
1100
1101
1102 static int test_driver_set_sta_vlan(void *priv, const u8 *addr,
1103                                     const char *ifname, int vlan_id)
1104 {
1105         wpa_printf(MSG_DEBUG, "%s(addr=" MACSTR " ifname=%s vlan_id=%d)",
1106                    __func__, MAC2STR(addr), ifname, vlan_id);
1107         return 0;
1108 }
1109
1110
1111 static int test_driver_sta_add(const char *ifname, void *priv,
1112                                struct hostapd_sta_add_params *params)
1113 {
1114         struct wpa_driver_test_data *drv = priv;
1115         struct test_client_socket *cli;
1116         struct test_driver_bss *bss;
1117
1118         wpa_printf(MSG_DEBUG, "%s(ifname=%s addr=" MACSTR " aid=%d "
1119                    "capability=0x%x listen_interval=%d)",
1120                    __func__, ifname, MAC2STR(params->addr), params->aid,
1121                    params->capability, params->listen_interval);
1122         wpa_hexdump(MSG_DEBUG, "test_driver_sta_add - supp_rates",
1123                     params->supp_rates, params->supp_rates_len);
1124
1125         cli = drv->cli;
1126         while (cli) {
1127                 if (os_memcmp(cli->addr, params->addr, ETH_ALEN) == 0)
1128                         break;
1129                 cli = cli->next;
1130         }
1131         if (!cli) {
1132                 wpa_printf(MSG_DEBUG, "%s: no matching client entry",
1133                            __func__);
1134                 return -1;
1135         }
1136
1137         bss = test_driver_get_bss(drv, ifname);
1138         if (bss == NULL) {
1139                 wpa_printf(MSG_DEBUG, "%s: No matching interface found from "
1140                            "configured BSSes", __func__);
1141                 return -1;
1142         }
1143
1144         cli->bss = bss;
1145
1146         return 0;
1147 }
1148
1149
1150 static struct wpa_driver_test_data * test_alloc_data(void *ctx,
1151                                                      const char *ifname)
1152 {
1153         struct wpa_driver_test_data *drv;
1154
1155         drv = os_zalloc(sizeof(struct wpa_driver_test_data));
1156         if (drv == NULL) {
1157                 wpa_printf(MSG_ERROR, "Could not allocate memory for test "
1158                            "driver data");
1159                 return NULL;
1160         }
1161
1162         drv->ctx = ctx;
1163         wpa_trace_add_ref(drv, ctx, ctx);
1164         os_strlcpy(drv->ifname, ifname, IFNAMSIZ);
1165
1166         /* Generate a MAC address to help testing with multiple STAs */
1167         drv->own_addr[0] = 0x02; /* locally administered */
1168         sha1_prf((const u8 *) ifname, os_strlen(ifname),
1169                  "test mac addr generation",
1170                  NULL, 0, drv->own_addr + 1, ETH_ALEN - 1);
1171
1172         return drv;
1173 }
1174
1175
1176 static void * test_driver_init(struct hostapd_data *hapd,
1177                                struct wpa_init_params *params)
1178 {
1179         struct wpa_driver_test_data *drv;
1180         struct sockaddr_un addr_un;
1181         struct sockaddr_in addr_in;
1182         struct sockaddr *addr;
1183         socklen_t alen;
1184
1185         drv = test_alloc_data(hapd, params->ifname);
1186         if (drv == NULL)
1187                 return NULL;
1188         drv->ap = 1;
1189         drv->bss = os_zalloc(sizeof(*drv->bss));
1190         if (drv->bss == NULL) {
1191                 wpa_printf(MSG_ERROR, "Could not allocate memory for test "
1192                            "driver BSS data");
1193                 os_free(drv);
1194                 return NULL;
1195         }
1196
1197         drv->bss->bss_ctx = hapd;
1198         os_strlcpy(drv->bss->ifname, params->ifname, IFNAMSIZ);
1199         os_memcpy(drv->bss->bssid, drv->own_addr, ETH_ALEN);
1200         os_memcpy(params->own_addr, drv->own_addr, ETH_ALEN);
1201
1202         if (params->test_socket) {
1203                 if (os_strlen(params->test_socket) >=
1204                     sizeof(addr_un.sun_path)) {
1205                         printf("Too long test_socket path\n");
1206                         wpa_driver_test_deinit(drv);
1207                         return NULL;
1208                 }
1209                 if (strncmp(params->test_socket, "DIR:", 4) == 0) {
1210                         size_t len = strlen(params->test_socket) + 30;
1211                         drv->test_dir = os_strdup(params->test_socket + 4);
1212                         drv->own_socket_path = os_malloc(len);
1213                         if (drv->own_socket_path) {
1214                                 snprintf(drv->own_socket_path, len,
1215                                          "%s/AP-" MACSTR,
1216                                          params->test_socket + 4,
1217                                          MAC2STR(params->own_addr));
1218                         }
1219                 } else if (strncmp(params->test_socket, "UDP:", 4) == 0) {
1220                         drv->udp_port = atoi(params->test_socket + 4);
1221                 } else {
1222                         drv->own_socket_path = os_strdup(params->test_socket);
1223                 }
1224                 if (drv->own_socket_path == NULL && drv->udp_port == 0) {
1225                         wpa_driver_test_deinit(drv);
1226                         return NULL;
1227                 }
1228
1229                 drv->test_socket = socket(drv->udp_port ? PF_INET : PF_UNIX,
1230                                           SOCK_DGRAM, 0);
1231                 if (drv->test_socket < 0) {
1232                         perror("socket");
1233                         wpa_driver_test_deinit(drv);
1234                         return NULL;
1235                 }
1236
1237                 if (drv->udp_port) {
1238                         os_memset(&addr_in, 0, sizeof(addr_in));
1239                         addr_in.sin_family = AF_INET;
1240                         addr_in.sin_port = htons(drv->udp_port);
1241                         addr = (struct sockaddr *) &addr_in;
1242                         alen = sizeof(addr_in);
1243                 } else {
1244                         os_memset(&addr_un, 0, sizeof(addr_un));
1245                         addr_un.sun_family = AF_UNIX;
1246                         os_strlcpy(addr_un.sun_path, drv->own_socket_path,
1247                                    sizeof(addr_un.sun_path));
1248                         addr = (struct sockaddr *) &addr_un;
1249                         alen = sizeof(addr_un);
1250                 }
1251                 if (bind(drv->test_socket, addr, alen) < 0) {
1252                         perror("bind(PF_UNIX)");
1253                         close(drv->test_socket);
1254                         if (drv->own_socket_path)
1255                                 unlink(drv->own_socket_path);
1256                         wpa_driver_test_deinit(drv);
1257                         return NULL;
1258                 }
1259                 eloop_register_read_sock(drv->test_socket,
1260                                          test_driver_receive_unix, drv, NULL);
1261         } else
1262                 drv->test_socket = -1;
1263
1264         return drv;
1265 }
1266
1267
1268 static void wpa_driver_test_poll(void *eloop_ctx, void *timeout_ctx)
1269 {
1270         struct wpa_driver_test_data *drv = eloop_ctx;
1271
1272 #ifdef DRIVER_TEST_UNIX
1273         if (drv->associated && drv->hostapd_addr_set) {
1274                 struct stat st;
1275                 if (stat(drv->hostapd_addr.sun_path, &st) < 0) {
1276                         wpa_printf(MSG_DEBUG, "%s: lost connection to AP: %s",
1277                                    __func__, strerror(errno));
1278                         drv->associated = 0;
1279                         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1280                 }
1281         }
1282 #endif /* DRIVER_TEST_UNIX */
1283
1284         eloop_register_timeout(1, 0, wpa_driver_test_poll, drv, NULL);
1285 }
1286
1287
1288 static void wpa_driver_test_scan_timeout(void *eloop_ctx, void *timeout_ctx)
1289 {
1290         wpa_printf(MSG_DEBUG, "Scan timeout - try to get results");
1291         wpa_supplicant_event(timeout_ctx, EVENT_SCAN_RESULTS, NULL);
1292 }
1293
1294
1295 #ifdef DRIVER_TEST_UNIX
1296 static void wpa_driver_scan_dir(struct wpa_driver_test_data *drv,
1297                                 const char *path)
1298 {
1299         struct dirent *dent;
1300         DIR *dir;
1301         struct sockaddr_un addr;
1302         char cmd[512], *pos, *end;
1303         int ret;
1304
1305         dir = opendir(path);
1306         if (dir == NULL)
1307                 return;
1308
1309         end = cmd + sizeof(cmd);
1310         pos = cmd;
1311         ret = os_snprintf(pos, end - pos, "SCAN " MACSTR,
1312                           MAC2STR(drv->own_addr));
1313         if (ret >= 0 && ret < end - pos)
1314                 pos += ret;
1315         if (drv->probe_req_ie) {
1316                 ret = os_snprintf(pos, end - pos, " ");
1317                 if (ret >= 0 && ret < end - pos)
1318                         pos += ret;
1319                 pos += wpa_snprintf_hex(pos, end - pos, drv->probe_req_ie,
1320                                         drv->probe_req_ie_len);
1321         }
1322         end[-1] = '\0';
1323
1324         while ((dent = readdir(dir))) {
1325                 if (os_strncmp(dent->d_name, "AP-", 3) != 0 &&
1326                     os_strncmp(dent->d_name, "STA-", 4) != 0)
1327                         continue;
1328                 if (drv->own_socket_path) {
1329                         size_t olen, dlen;
1330                         olen = os_strlen(drv->own_socket_path);
1331                         dlen = os_strlen(dent->d_name);
1332                         if (olen >= dlen &&
1333                             os_strcmp(dent->d_name,
1334                                       drv->own_socket_path + olen - dlen) == 0)
1335                                 continue;
1336                 }
1337                 wpa_printf(MSG_DEBUG, "%s: SCAN %s", __func__, dent->d_name);
1338
1339                 os_memset(&addr, 0, sizeof(addr));
1340                 addr.sun_family = AF_UNIX;
1341                 os_snprintf(addr.sun_path, sizeof(addr.sun_path), "%s/%s",
1342                             path, dent->d_name);
1343
1344                 if (sendto(drv->test_socket, cmd, os_strlen(cmd), 0,
1345                            (struct sockaddr *) &addr, sizeof(addr)) < 0) {
1346                         perror("sendto(test_socket)");
1347                 }
1348         }
1349         closedir(dir);
1350 }
1351 #endif /* DRIVER_TEST_UNIX */
1352
1353
1354 static int wpa_driver_test_scan(void *priv,
1355                                 struct wpa_driver_scan_params *params)
1356 {
1357         struct wpa_driver_test_data *drv = priv;
1358         size_t i;
1359
1360         wpa_printf(MSG_DEBUG, "%s: priv=%p", __func__, priv);
1361
1362         os_free(drv->probe_req_ie);
1363         if (params->extra_ies) {
1364                 drv->probe_req_ie = os_malloc(params->extra_ies_len);
1365                 if (drv->probe_req_ie == NULL) {
1366                         drv->probe_req_ie_len = 0;
1367                         return -1;
1368                 }
1369                 os_memcpy(drv->probe_req_ie, params->extra_ies,
1370                           params->extra_ies_len);
1371                 drv->probe_req_ie_len = params->extra_ies_len;
1372         } else {
1373                 drv->probe_req_ie = NULL;
1374                 drv->probe_req_ie_len = 0;
1375         }
1376
1377         for (i = 0; i < params->num_ssids; i++)
1378                 wpa_hexdump(MSG_DEBUG, "Scan SSID",
1379                             params->ssids[i].ssid, params->ssids[i].ssid_len);
1380         wpa_hexdump(MSG_DEBUG, "Scan extra IE(s)",
1381                     params->extra_ies, params->extra_ies_len);
1382
1383         drv->num_scanres = 0;
1384
1385 #ifdef DRIVER_TEST_UNIX
1386         if (drv->test_socket >= 0 && drv->test_dir)
1387                 wpa_driver_scan_dir(drv, drv->test_dir);
1388
1389         if (drv->test_socket >= 0 && drv->hostapd_addr_set &&
1390             sendto(drv->test_socket, "SCAN", 4, 0,
1391                    (struct sockaddr *) &drv->hostapd_addr,
1392                    sizeof(drv->hostapd_addr)) < 0) {
1393                 perror("sendto(test_socket)");
1394         }
1395 #endif /* DRIVER_TEST_UNIX */
1396
1397         if (drv->test_socket >= 0 && drv->hostapd_addr_udp_set &&
1398             sendto(drv->test_socket, "SCAN", 4, 0,
1399                    (struct sockaddr *) &drv->hostapd_addr_udp,
1400                    sizeof(drv->hostapd_addr_udp)) < 0) {
1401                 perror("sendto(test_socket)");
1402         }
1403
1404         eloop_cancel_timeout(wpa_driver_test_scan_timeout, drv, drv->ctx);
1405         eloop_register_timeout(1, 0, wpa_driver_test_scan_timeout, drv,
1406                                drv->ctx);
1407         return 0;
1408 }
1409
1410
1411 static struct wpa_scan_results * wpa_driver_test_get_scan_results2(void *priv)
1412 {
1413         struct wpa_driver_test_data *drv = priv;
1414         struct wpa_scan_results *res;
1415         size_t i;
1416
1417         res = os_zalloc(sizeof(*res));
1418         if (res == NULL)
1419                 return NULL;
1420
1421         res->res = os_zalloc(drv->num_scanres * sizeof(struct wpa_scan_res *));
1422         if (res->res == NULL) {
1423                 os_free(res);
1424                 return NULL;
1425         }
1426
1427         for (i = 0; i < drv->num_scanres; i++) {
1428                 struct wpa_scan_res *r;
1429                 if (drv->scanres[i] == NULL)
1430                         continue;
1431                 r = os_malloc(sizeof(*r) + drv->scanres[i]->ie_len);
1432                 if (r == NULL)
1433                         break;
1434                 os_memcpy(r, drv->scanres[i],
1435                           sizeof(*r) + drv->scanres[i]->ie_len);
1436                 res->res[res->num++] = r;
1437         }
1438
1439         return res;
1440 }
1441
1442
1443 static int wpa_driver_test_set_key(const char *ifname, void *priv,
1444                                    enum wpa_alg alg, const u8 *addr,
1445                                    int key_idx, int set_tx,
1446                                    const u8 *seq, size_t seq_len,
1447                                    const u8 *key, size_t key_len)
1448 {
1449         wpa_printf(MSG_DEBUG, "%s: ifname=%s priv=%p alg=%d key_idx=%d "
1450                    "set_tx=%d",
1451                    __func__, ifname, priv, alg, key_idx, set_tx);
1452         if (addr)
1453                 wpa_printf(MSG_DEBUG, "   addr=" MACSTR, MAC2STR(addr));
1454         if (seq)
1455                 wpa_hexdump(MSG_DEBUG, "   seq", seq, seq_len);
1456         if (key)
1457                 wpa_hexdump_key(MSG_DEBUG, "   key", key, key_len);
1458         return 0;
1459 }
1460
1461
1462 static int wpa_driver_update_mode(struct wpa_driver_test_data *drv, int ap)
1463 {
1464         if (ap && !drv->ap) {
1465                 wpa_driver_test_close_test_socket(drv);
1466                 wpa_driver_test_attach(drv, drv->test_dir, 1);
1467                 drv->ap = 1;
1468         } else if (!ap && drv->ap) {
1469                 wpa_driver_test_close_test_socket(drv);
1470                 wpa_driver_test_attach(drv, drv->test_dir, 0);
1471                 drv->ap = 0;
1472         }
1473
1474         return 0;
1475 }
1476
1477
1478 static int wpa_driver_test_associate(
1479         void *priv, struct wpa_driver_associate_params *params)
1480 {
1481         struct wpa_driver_test_data *drv = priv;
1482         wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d pairwise_suite=%d "
1483                    "group_suite=%d key_mgmt_suite=%d auth_alg=%d mode=%d",
1484                    __func__, priv, params->freq, params->pairwise_suite,
1485                    params->group_suite, params->key_mgmt_suite,
1486                    params->auth_alg, params->mode);
1487         if (params->bssid) {
1488                 wpa_printf(MSG_DEBUG, "   bssid=" MACSTR,
1489                            MAC2STR(params->bssid));
1490         }
1491         if (params->ssid) {
1492                 wpa_hexdump_ascii(MSG_DEBUG, "   ssid",
1493                                   params->ssid, params->ssid_len);
1494         }
1495         if (params->wpa_ie) {
1496                 wpa_hexdump(MSG_DEBUG, "   wpa_ie",
1497                             params->wpa_ie, params->wpa_ie_len);
1498                 drv->assoc_wpa_ie_len = params->wpa_ie_len;
1499                 if (drv->assoc_wpa_ie_len > sizeof(drv->assoc_wpa_ie))
1500                         drv->assoc_wpa_ie_len = sizeof(drv->assoc_wpa_ie);
1501                 os_memcpy(drv->assoc_wpa_ie, params->wpa_ie,
1502                           drv->assoc_wpa_ie_len);
1503         } else
1504                 drv->assoc_wpa_ie_len = 0;
1505
1506         wpa_driver_update_mode(drv, params->mode == IEEE80211_MODE_AP);
1507
1508         drv->ibss = params->mode == IEEE80211_MODE_IBSS;
1509         drv->privacy = params->key_mgmt_suite &
1510                 (WPA_KEY_MGMT_IEEE8021X |
1511                  WPA_KEY_MGMT_PSK |
1512                  WPA_KEY_MGMT_WPA_NONE |
1513                  WPA_KEY_MGMT_FT_IEEE8021X |
1514                  WPA_KEY_MGMT_FT_PSK |
1515                  WPA_KEY_MGMT_IEEE8021X_SHA256 |
1516                  WPA_KEY_MGMT_PSK_SHA256);
1517         if (params->wep_key_len[params->wep_tx_keyidx])
1518                 drv->privacy = 1;
1519
1520 #ifdef DRIVER_TEST_UNIX
1521         if (drv->test_dir && params->bssid &&
1522             params->mode != IEEE80211_MODE_IBSS) {
1523                 os_memset(&drv->hostapd_addr, 0, sizeof(drv->hostapd_addr));
1524                 drv->hostapd_addr.sun_family = AF_UNIX;
1525                 os_snprintf(drv->hostapd_addr.sun_path,
1526                             sizeof(drv->hostapd_addr.sun_path),
1527                             "%s/AP-" MACSTR,
1528                             drv->test_dir, MAC2STR(params->bssid));
1529                 drv->hostapd_addr_set = 1;
1530         }
1531 #endif /* DRIVER_TEST_UNIX */
1532
1533         if (params->mode == IEEE80211_MODE_AP) {
1534                 struct test_driver_bss *bss;
1535                 os_memcpy(drv->ssid, params->ssid, params->ssid_len);
1536                 drv->ssid_len = params->ssid_len;
1537
1538                 test_driver_free_bsses(drv);
1539                 bss = drv->bss = os_zalloc(sizeof(*drv->bss));
1540                 if (bss == NULL)
1541                         return -1;
1542                 os_strlcpy(bss->ifname, drv->ifname, IFNAMSIZ);
1543                 os_memcpy(bss->bssid, drv->own_addr, ETH_ALEN);
1544                 os_memcpy(bss->ssid, params->ssid, params->ssid_len);
1545                 bss->ssid_len = params->ssid_len;
1546                 bss->privacy = drv->privacy;
1547                 if (params->wpa_ie && params->wpa_ie_len) {
1548                         bss->ie = os_malloc(params->wpa_ie_len);
1549                         if (bss->ie) {
1550                                 os_memcpy(bss->ie, params->wpa_ie,
1551                                           params->wpa_ie_len);
1552                                 bss->ielen = params->wpa_ie_len;
1553                         }
1554                 }
1555         } else if (drv->test_socket >= 0 &&
1556                    (drv->hostapd_addr_set || drv->hostapd_addr_udp_set)) {
1557                 char cmd[200], *pos, *end;
1558                 int ret;
1559                 end = cmd + sizeof(cmd);
1560                 pos = cmd;
1561                 ret = os_snprintf(pos, end - pos, "ASSOC " MACSTR " ",
1562                                   MAC2STR(drv->own_addr));
1563                 if (ret >= 0 && ret < end - pos)
1564                         pos += ret;
1565                 pos += wpa_snprintf_hex(pos, end - pos, params->ssid,
1566                                         params->ssid_len);
1567                 ret = os_snprintf(pos, end - pos, " ");
1568                 if (ret >= 0 && ret < end - pos)
1569                         pos += ret;
1570                 pos += wpa_snprintf_hex(pos, end - pos, params->wpa_ie,
1571                                         params->wpa_ie_len);
1572                 end[-1] = '\0';
1573 #ifdef DRIVER_TEST_UNIX
1574                 if (drv->hostapd_addr_set &&
1575                     sendto(drv->test_socket, cmd, os_strlen(cmd), 0,
1576                            (struct sockaddr *) &drv->hostapd_addr,
1577                            sizeof(drv->hostapd_addr)) < 0) {
1578                         perror("sendto(test_socket)");
1579                         return -1;
1580                 }
1581 #endif /* DRIVER_TEST_UNIX */
1582                 if (drv->hostapd_addr_udp_set &&
1583                     sendto(drv->test_socket, cmd, os_strlen(cmd), 0,
1584                            (struct sockaddr *) &drv->hostapd_addr_udp,
1585                            sizeof(drv->hostapd_addr_udp)) < 0) {
1586                         perror("sendto(test_socket)");
1587                         return -1;
1588                 }
1589
1590                 os_memcpy(drv->ssid, params->ssid, params->ssid_len);
1591                 drv->ssid_len = params->ssid_len;
1592         } else {
1593                 drv->associated = 1;
1594                 if (params->mode == IEEE80211_MODE_IBSS) {
1595                         os_memcpy(drv->ssid, params->ssid, params->ssid_len);
1596                         drv->ssid_len = params->ssid_len;
1597                         if (params->bssid)
1598                                 os_memcpy(drv->bssid, params->bssid, ETH_ALEN);
1599                         else {
1600                                 os_get_random(drv->bssid, ETH_ALEN);
1601                                 drv->bssid[0] &= ~0x01;
1602                                 drv->bssid[0] |= 0x02;
1603                         }
1604                 }
1605                 wpa_supplicant_event(drv->ctx, EVENT_ASSOC, NULL);
1606         }
1607
1608         return 0;
1609 }
1610
1611
1612 static int wpa_driver_test_get_bssid(void *priv, u8 *bssid)
1613 {
1614         struct wpa_driver_test_data *drv = priv;
1615         os_memcpy(bssid, drv->bssid, ETH_ALEN);
1616         return 0;
1617 }
1618
1619
1620 static int wpa_driver_test_get_ssid(void *priv, u8 *ssid)
1621 {
1622         struct wpa_driver_test_data *drv = priv;
1623         os_memcpy(ssid, drv->ssid, 32);
1624         return drv->ssid_len;
1625 }
1626
1627
1628 static int wpa_driver_test_send_disassoc(struct wpa_driver_test_data *drv)
1629 {
1630 #ifdef DRIVER_TEST_UNIX
1631         if (drv->test_socket >= 0 &&
1632             sendto(drv->test_socket, "DISASSOC", 8, 0,
1633                    (struct sockaddr *) &drv->hostapd_addr,
1634                    sizeof(drv->hostapd_addr)) < 0) {
1635                 perror("sendto(test_socket)");
1636                 return -1;
1637         }
1638 #endif /* DRIVER_TEST_UNIX */
1639         if (drv->test_socket >= 0 && drv->hostapd_addr_udp_set &&
1640             sendto(drv->test_socket, "DISASSOC", 8, 0,
1641                    (struct sockaddr *) &drv->hostapd_addr_udp,
1642                    sizeof(drv->hostapd_addr_udp)) < 0) {
1643                 perror("sendto(test_socket)");
1644                 return -1;
1645         }
1646         return 0;
1647 }
1648
1649
1650 static int wpa_driver_test_deauthenticate(void *priv, const u8 *addr,
1651                                           int reason_code)
1652 {
1653         struct wpa_driver_test_data *drv = priv;
1654         wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
1655                    __func__, MAC2STR(addr), reason_code);
1656         os_memset(drv->bssid, 0, ETH_ALEN);
1657         drv->associated = 0;
1658         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1659         return wpa_driver_test_send_disassoc(drv);
1660 }
1661
1662
1663 static int wpa_driver_test_disassociate(void *priv, const u8 *addr,
1664                                         int reason_code)
1665 {
1666         struct wpa_driver_test_data *drv = priv;
1667         wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
1668                    __func__, MAC2STR(addr), reason_code);
1669         os_memset(drv->bssid, 0, ETH_ALEN);
1670         drv->associated = 0;
1671         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1672         return wpa_driver_test_send_disassoc(drv);
1673 }
1674
1675
1676 static void wpa_driver_test_scanresp(struct wpa_driver_test_data *drv,
1677                                      struct sockaddr *from,
1678                                      socklen_t fromlen,
1679                                      const char *data)
1680 {
1681         struct wpa_scan_res *res;
1682         const char *pos, *pos2;
1683         size_t len;
1684         u8 *ie_pos, *ie_start, *ie_end;
1685 #define MAX_IE_LEN 1000
1686
1687         wpa_printf(MSG_DEBUG, "test_driver: SCANRESP %s", data);
1688         if (drv->num_scanres >= MAX_SCAN_RESULTS) {
1689                 wpa_printf(MSG_DEBUG, "test_driver: No room for the new scan "
1690                            "result");
1691                 return;
1692         }
1693
1694         /* SCANRESP BSSID SSID IEs */
1695
1696         res = os_zalloc(sizeof(*res) + MAX_IE_LEN);
1697         if (res == NULL)
1698                 return;
1699         ie_start = ie_pos = (u8 *) (res + 1);
1700         ie_end = ie_pos + MAX_IE_LEN;
1701
1702         if (hwaddr_aton(data, res->bssid)) {
1703                 wpa_printf(MSG_DEBUG, "test_driver: invalid BSSID in scanres");
1704                 os_free(res);
1705                 return;
1706         }
1707
1708         pos = data + 17;
1709         while (*pos == ' ')
1710                 pos++;
1711         pos2 = os_strchr(pos, ' ');
1712         if (pos2 == NULL) {
1713                 wpa_printf(MSG_DEBUG, "test_driver: invalid SSID termination "
1714                            "in scanres");
1715                 os_free(res);
1716                 return;
1717         }
1718         len = (pos2 - pos) / 2;
1719         if (len > 32)
1720                 len = 32;
1721         /*
1722          * Generate SSID IE from the SSID field since this IE is not included
1723          * in the main IE field.
1724          */
1725         *ie_pos++ = WLAN_EID_SSID;
1726         *ie_pos++ = len;
1727         if (hexstr2bin(pos, ie_pos, len) < 0) {
1728                 wpa_printf(MSG_DEBUG, "test_driver: invalid SSID in scanres");
1729                 os_free(res);
1730                 return;
1731         }
1732         ie_pos += len;
1733
1734         pos = pos2 + 1;
1735         pos2 = os_strchr(pos, ' ');
1736         if (pos2 == NULL)
1737                 len = os_strlen(pos) / 2;
1738         else
1739                 len = (pos2 - pos) / 2;
1740         if ((int) len > ie_end - ie_pos)
1741                 len = ie_end - ie_pos;
1742         if (hexstr2bin(pos, ie_pos, len) < 0) {
1743                 wpa_printf(MSG_DEBUG, "test_driver: invalid IEs in scanres");
1744                 os_free(res);
1745                 return;
1746         }
1747         ie_pos += len;
1748         res->ie_len = ie_pos - ie_start;
1749
1750         if (pos2) {
1751                 pos = pos2 + 1;
1752                 while (*pos == ' ')
1753                         pos++;
1754                 if (os_strstr(pos, "PRIVACY"))
1755                         res->caps |= IEEE80211_CAP_PRIVACY;
1756                 if (os_strstr(pos, "IBSS"))
1757                         res->caps |= IEEE80211_CAP_IBSS;
1758         }
1759
1760         os_free(drv->scanres[drv->num_scanres]);
1761         drv->scanres[drv->num_scanres++] = res;
1762 }
1763
1764
1765 static void wpa_driver_test_assocresp(struct wpa_driver_test_data *drv,
1766                                       struct sockaddr *from,
1767                                       socklen_t fromlen,
1768                                       const char *data)
1769 {
1770         /* ASSOCRESP BSSID <res> */
1771         if (hwaddr_aton(data, drv->bssid)) {
1772                 wpa_printf(MSG_DEBUG, "test_driver: invalid BSSID in "
1773                            "assocresp");
1774         }
1775         if (drv->use_associnfo) {
1776                 union wpa_event_data event;
1777                 os_memset(&event, 0, sizeof(event));
1778                 event.assoc_info.req_ies = drv->assoc_wpa_ie;
1779                 event.assoc_info.req_ies_len = drv->assoc_wpa_ie_len;
1780                 wpa_supplicant_event(drv->ctx, EVENT_ASSOCINFO, &event);
1781         }
1782         drv->associated = 1;
1783         wpa_supplicant_event(drv->ctx, EVENT_ASSOC, NULL);
1784 }
1785
1786
1787 static void wpa_driver_test_disassoc(struct wpa_driver_test_data *drv,
1788                                      struct sockaddr *from,
1789                                      socklen_t fromlen)
1790 {
1791         drv->associated = 0;
1792         wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
1793 }
1794
1795
1796 static void wpa_driver_test_eapol(struct wpa_driver_test_data *drv,
1797                                   struct sockaddr *from,
1798                                   socklen_t fromlen,
1799                                   const u8 *data, size_t data_len)
1800 {
1801         const u8 *src = drv->bssid;
1802
1803         if (data_len > 14) {
1804                 /* Skip Ethernet header */
1805                 src = data + ETH_ALEN;
1806                 data += 14;
1807                 data_len -= 14;
1808         }
1809
1810         drv_event_eapol_rx(drv->ctx, src, data, data_len);
1811 }
1812
1813
1814 static void wpa_driver_test_mlme(struct wpa_driver_test_data *drv,
1815                                  struct sockaddr *from,
1816                                  socklen_t fromlen,
1817                                  const u8 *data, size_t data_len)
1818 {
1819         int freq = 0, own_freq;
1820         union wpa_event_data event;
1821
1822         if (data_len > 6 && os_memcmp(data, "freq=", 5) == 0) {
1823                 size_t pos;
1824                 for (pos = 5; pos < data_len; pos++) {
1825                         if (data[pos] == ' ')
1826                                 break;
1827                 }
1828                 if (pos < data_len) {
1829                         freq = atoi((const char *) &data[5]);
1830                         wpa_printf(MSG_DEBUG, "test_driver(%s): MLME RX on "
1831                                    "freq %d MHz", drv->ifname, freq);
1832                         pos++;
1833                         data += pos;
1834                         data_len -= pos;
1835                 }
1836         }
1837
1838         if (drv->remain_on_channel_freq)
1839                 own_freq = drv->remain_on_channel_freq;
1840         else
1841                 own_freq = drv->current_freq;
1842
1843         if (freq && own_freq && freq != own_freq) {
1844                 wpa_printf(MSG_DEBUG, "test_driver(%s): Ignore MLME RX on "
1845                            "another frequency %d MHz (own %d MHz)",
1846                            drv->ifname, freq, own_freq);
1847                 return;
1848         }
1849
1850         os_memset(&event, 0, sizeof(event));
1851         event.mlme_rx.buf = data;
1852         event.mlme_rx.len = data_len;
1853         event.mlme_rx.freq = freq;
1854         wpa_supplicant_event(drv->ctx, EVENT_MLME_RX, &event);
1855
1856         if (drv->probe_req_report && data_len >= 24) {
1857                 const struct ieee80211_mgmt *mgmt;
1858                 u16 fc;
1859
1860                 mgmt = (const struct ieee80211_mgmt *) data;
1861                 fc = le_to_host16(mgmt->frame_control);
1862                 if (WLAN_FC_GET_TYPE(fc) == WLAN_FC_TYPE_MGMT &&
1863                     WLAN_FC_GET_STYPE(fc) == WLAN_FC_STYPE_PROBE_REQ) {
1864                         os_memset(&event, 0, sizeof(event));
1865                         event.rx_probe_req.sa = mgmt->sa;
1866                         event.rx_probe_req.ie = mgmt->u.probe_req.variable;
1867                         event.rx_probe_req.ie_len =
1868                                 data_len - (mgmt->u.probe_req.variable - data);
1869                         wpa_supplicant_event(drv->ctx, EVENT_RX_PROBE_REQ,
1870                                              &event);
1871                 }
1872         }
1873 }
1874
1875
1876 static void wpa_driver_test_scan_cmd(struct wpa_driver_test_data *drv,
1877                                      struct sockaddr *from,
1878                                      socklen_t fromlen,
1879                                      const u8 *data, size_t data_len)
1880 {
1881         char buf[512], *pos, *end;
1882         int ret;
1883
1884         /* data: optional [ STA-addr | ' ' | IEs(hex) ] */
1885
1886         if (!drv->ibss)
1887                 return;
1888
1889         pos = buf;
1890         end = buf + sizeof(buf);
1891
1892         /* reply: SCANRESP BSSID SSID IEs */
1893         ret = snprintf(pos, end - pos, "SCANRESP " MACSTR " ",
1894                        MAC2STR(drv->bssid));
1895         if (ret < 0 || ret >= end - pos)
1896                 return;
1897         pos += ret;
1898         pos += wpa_snprintf_hex(pos, end - pos,
1899                                 drv->ssid, drv->ssid_len);
1900         ret = snprintf(pos, end - pos, " ");
1901         if (ret < 0 || ret >= end - pos)
1902                 return;
1903         pos += ret;
1904         pos += wpa_snprintf_hex(pos, end - pos, drv->assoc_wpa_ie,
1905                                 drv->assoc_wpa_ie_len);
1906
1907         if (drv->privacy) {
1908                 ret = snprintf(pos, end - pos, " PRIVACY");
1909                 if (ret < 0 || ret >= end - pos)
1910                         return;
1911                 pos += ret;
1912         }
1913
1914         ret = snprintf(pos, end - pos, " IBSS");
1915         if (ret < 0 || ret >= end - pos)
1916                 return;
1917         pos += ret;
1918
1919         sendto(drv->test_socket, buf, pos - buf, 0,
1920                (struct sockaddr *) from, fromlen);
1921 }
1922
1923
1924 static void wpa_driver_test_receive_unix(int sock, void *eloop_ctx,
1925                                          void *sock_ctx)
1926 {
1927         struct wpa_driver_test_data *drv = eloop_ctx;
1928         char *buf;
1929         int res;
1930         struct sockaddr_storage from;
1931         socklen_t fromlen = sizeof(from);
1932         const size_t buflen = 2000;
1933
1934         if (drv->ap) {
1935                 test_driver_receive_unix(sock, eloop_ctx, sock_ctx);
1936                 return;
1937         }
1938
1939         buf = os_malloc(buflen);
1940         if (buf == NULL)
1941                 return;
1942         res = recvfrom(sock, buf, buflen - 1, 0,
1943                        (struct sockaddr *) &from, &fromlen);
1944         if (res < 0) {
1945                 perror("recvfrom(test_socket)");
1946                 os_free(buf);
1947                 return;
1948         }
1949         buf[res] = '\0';
1950
1951         wpa_printf(MSG_DEBUG, "test_driver: received %u bytes", res);
1952
1953         if (os_strncmp(buf, "SCANRESP ", 9) == 0) {
1954                 wpa_driver_test_scanresp(drv, (struct sockaddr *) &from,
1955                                          fromlen, buf + 9);
1956         } else if (os_strncmp(buf, "ASSOCRESP ", 10) == 0) {
1957                 wpa_driver_test_assocresp(drv, (struct sockaddr *) &from,
1958                                           fromlen, buf + 10);
1959         } else if (os_strcmp(buf, "DISASSOC") == 0) {
1960                 wpa_driver_test_disassoc(drv, (struct sockaddr *) &from,
1961                                          fromlen);
1962         } else if (os_strcmp(buf, "DEAUTH") == 0) {
1963                 wpa_driver_test_disassoc(drv, (struct sockaddr *) &from,
1964                                          fromlen);
1965         } else if (os_strncmp(buf, "EAPOL ", 6) == 0) {
1966                 wpa_driver_test_eapol(drv, (struct sockaddr *) &from, fromlen,
1967                                       (const u8 *) buf + 6, res - 6);
1968         } else if (os_strncmp(buf, "MLME ", 5) == 0) {
1969                 wpa_driver_test_mlme(drv, (struct sockaddr *) &from, fromlen,
1970                                      (const u8 *) buf + 5, res - 5);
1971         } else if (os_strncmp(buf, "SCAN ", 5) == 0) {
1972                 wpa_driver_test_scan_cmd(drv, (struct sockaddr *) &from,
1973                                          fromlen,
1974                                          (const u8 *) buf + 5, res - 5);
1975         } else {
1976                 wpa_hexdump_ascii(MSG_DEBUG, "Unknown test_socket command",
1977                                   (u8 *) buf, res);
1978         }
1979         os_free(buf);
1980 }
1981
1982
1983 static void * wpa_driver_test_init2(void *ctx, const char *ifname,
1984                                     void *global_priv)
1985 {
1986         struct wpa_driver_test_data *drv;
1987         struct wpa_driver_test_global *global = global_priv;
1988
1989         drv = test_alloc_data(ctx, ifname);
1990         if (drv == NULL)
1991                 return NULL;
1992         drv->global = global_priv;
1993         drv->test_socket = -1;
1994
1995         /* Set dummy BSSID and SSID for testing. */
1996         drv->bssid[0] = 0x02;
1997         drv->bssid[1] = 0x00;
1998         drv->bssid[2] = 0x00;
1999         drv->bssid[3] = 0x00;
2000         drv->bssid[4] = 0x00;
2001         drv->bssid[5] = 0x01;
2002         os_memcpy(drv->ssid, "test", 5);
2003         drv->ssid_len = 4;
2004
2005         if (global->bss_add_used) {
2006                 os_memcpy(drv->own_addr, global->req_addr, ETH_ALEN);
2007                 global->bss_add_used = 0;
2008         }
2009
2010         eloop_register_timeout(1, 0, wpa_driver_test_poll, drv, NULL);
2011
2012         return drv;
2013 }
2014
2015
2016 static void wpa_driver_test_close_test_socket(struct wpa_driver_test_data *drv)
2017 {
2018         if (drv->test_socket >= 0) {
2019                 eloop_unregister_read_sock(drv->test_socket);
2020                 close(drv->test_socket);
2021                 drv->test_socket = -1;
2022         }
2023
2024         if (drv->own_socket_path) {
2025                 unlink(drv->own_socket_path);
2026                 os_free(drv->own_socket_path);
2027                 drv->own_socket_path = NULL;
2028         }
2029 }
2030
2031
2032 static void wpa_driver_test_deinit(void *priv)
2033 {
2034         struct wpa_driver_test_data *drv = priv;
2035         struct test_client_socket *cli, *prev;
2036         int i;
2037
2038         cli = drv->cli;
2039         while (cli) {
2040                 prev = cli;
2041                 cli = cli->next;
2042                 os_free(prev);
2043         }
2044
2045 #ifdef HOSTAPD
2046         /* There should be only one BSS remaining at this point. */
2047         if (drv->bss == NULL)
2048                 wpa_printf(MSG_ERROR, "%s: drv->bss == NULL", __func__);
2049         else if (drv->bss->next)
2050                 wpa_printf(MSG_ERROR, "%s: drv->bss->next != NULL", __func__);
2051 #endif /* HOSTAPD */
2052
2053         test_driver_free_bsses(drv);
2054
2055         wpa_driver_test_close_test_socket(drv);
2056         eloop_cancel_timeout(wpa_driver_test_scan_timeout, drv, drv->ctx);
2057         eloop_cancel_timeout(wpa_driver_test_poll, drv, NULL);
2058         eloop_cancel_timeout(test_remain_on_channel_timeout, drv, NULL);
2059         os_free(drv->test_dir);
2060         for (i = 0; i < MAX_SCAN_RESULTS; i++)
2061                 os_free(drv->scanres[i]);
2062         os_free(drv->probe_req_ie);
2063         wpa_trace_remove_ref(drv, ctx, drv->ctx);
2064         os_free(drv);
2065 }
2066
2067
2068 static int wpa_driver_test_attach(struct wpa_driver_test_data *drv,
2069                                   const char *dir, int ap)
2070 {
2071 #ifdef DRIVER_TEST_UNIX
2072         static unsigned int counter = 0;
2073         struct sockaddr_un addr;
2074         size_t len;
2075
2076         os_free(drv->own_socket_path);
2077         if (dir) {
2078                 len = os_strlen(dir) + 30;
2079                 drv->own_socket_path = os_malloc(len);
2080                 if (drv->own_socket_path == NULL)
2081                         return -1;
2082                 os_snprintf(drv->own_socket_path, len, "%s/%s-" MACSTR,
2083                             dir, ap ? "AP" : "STA", MAC2STR(drv->own_addr));
2084         } else {
2085                 drv->own_socket_path = os_malloc(100);
2086                 if (drv->own_socket_path == NULL)
2087                         return -1;
2088                 os_snprintf(drv->own_socket_path, 100,
2089                             "/tmp/wpa_supplicant_test-%d-%d",
2090                             getpid(), counter++);
2091         }
2092
2093         drv->test_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
2094         if (drv->test_socket < 0) {
2095                 perror("socket(PF_UNIX)");
2096                 os_free(drv->own_socket_path);
2097                 drv->own_socket_path = NULL;
2098                 return -1;
2099         }
2100
2101         os_memset(&addr, 0, sizeof(addr));
2102         addr.sun_family = AF_UNIX;
2103         os_strlcpy(addr.sun_path, drv->own_socket_path, sizeof(addr.sun_path));
2104         if (bind(drv->test_socket, (struct sockaddr *) &addr,
2105                  sizeof(addr)) < 0) {
2106                 perror("bind(PF_UNIX)");
2107                 close(drv->test_socket);
2108                 unlink(drv->own_socket_path);
2109                 os_free(drv->own_socket_path);
2110                 drv->own_socket_path = NULL;
2111                 return -1;
2112         }
2113
2114         eloop_register_read_sock(drv->test_socket,
2115                                  wpa_driver_test_receive_unix, drv, NULL);
2116
2117         return 0;
2118 #else /* DRIVER_TEST_UNIX */
2119         return -1;
2120 #endif /* DRIVER_TEST_UNIX */
2121 }
2122
2123
2124 static int wpa_driver_test_attach_udp(struct wpa_driver_test_data *drv,
2125                                       char *dst)
2126 {
2127         char *pos;
2128
2129         pos = os_strchr(dst, ':');
2130         if (pos == NULL)
2131                 return -1;
2132         *pos++ = '\0';
2133         wpa_printf(MSG_DEBUG, "%s: addr=%s port=%s", __func__, dst, pos);
2134
2135         drv->test_socket = socket(PF_INET, SOCK_DGRAM, 0);
2136         if (drv->test_socket < 0) {
2137                 perror("socket(PF_INET)");
2138                 return -1;
2139         }
2140
2141         os_memset(&drv->hostapd_addr_udp, 0, sizeof(drv->hostapd_addr_udp));
2142         drv->hostapd_addr_udp.sin_family = AF_INET;
2143 #if defined(CONFIG_NATIVE_WINDOWS) || defined(CONFIG_ANSI_C_EXTRA)
2144         {
2145                 int a[4];
2146                 u8 *pos;
2147                 sscanf(dst, "%d.%d.%d.%d", &a[0], &a[1], &a[2], &a[3]);
2148                 pos = (u8 *) &drv->hostapd_addr_udp.sin_addr;
2149                 *pos++ = a[0];
2150                 *pos++ = a[1];
2151                 *pos++ = a[2];
2152                 *pos++ = a[3];
2153         }
2154 #else /* CONFIG_NATIVE_WINDOWS or CONFIG_ANSI_C_EXTRA */
2155         inet_aton(dst, &drv->hostapd_addr_udp.sin_addr);
2156 #endif /* CONFIG_NATIVE_WINDOWS or CONFIG_ANSI_C_EXTRA */
2157         drv->hostapd_addr_udp.sin_port = htons(atoi(pos));
2158
2159         drv->hostapd_addr_udp_set = 1;
2160
2161         eloop_register_read_sock(drv->test_socket,
2162                                  wpa_driver_test_receive_unix, drv, NULL);
2163
2164         return 0;
2165 }
2166
2167
2168 static int wpa_driver_test_set_param(void *priv, const char *param)
2169 {
2170         struct wpa_driver_test_data *drv = priv;
2171         const char *pos;
2172
2173         wpa_printf(MSG_DEBUG, "%s: param='%s'", __func__, param);
2174         if (param == NULL)
2175                 return 0;
2176
2177         wpa_driver_test_close_test_socket(drv);
2178
2179 #ifdef DRIVER_TEST_UNIX
2180         pos = os_strstr(param, "test_socket=");
2181         if (pos) {
2182                 const char *pos2;
2183                 size_t len;
2184
2185                 pos += 12;
2186                 pos2 = os_strchr(pos, ' ');
2187                 if (pos2)
2188                         len = pos2 - pos;
2189                 else
2190                         len = os_strlen(pos);
2191                 if (len > sizeof(drv->hostapd_addr.sun_path))
2192                         return -1;
2193                 os_memset(&drv->hostapd_addr, 0, sizeof(drv->hostapd_addr));
2194                 drv->hostapd_addr.sun_family = AF_UNIX;
2195                 os_memcpy(drv->hostapd_addr.sun_path, pos, len);
2196                 drv->hostapd_addr_set = 1;
2197         }
2198 #endif /* DRIVER_TEST_UNIX */
2199
2200         pos = os_strstr(param, "test_dir=");
2201         if (pos) {
2202                 char *end;
2203                 os_free(drv->test_dir);
2204                 drv->test_dir = os_strdup(pos + 9);
2205                 if (drv->test_dir == NULL)
2206                         return -1;
2207                 end = os_strchr(drv->test_dir, ' ');
2208                 if (end)
2209                         *end = '\0';
2210                 if (wpa_driver_test_attach(drv, drv->test_dir, 0))
2211                         return -1;
2212         } else {
2213                 pos = os_strstr(param, "test_udp=");
2214                 if (pos) {
2215                         char *dst, *epos;
2216                         dst = os_strdup(pos + 9);
2217                         if (dst == NULL)
2218                                 return -1;
2219                         epos = os_strchr(dst, ' ');
2220                         if (epos)
2221                                 *epos = '\0';
2222                         if (wpa_driver_test_attach_udp(drv, dst))
2223                                 return -1;
2224                         os_free(dst);
2225                 } else if (wpa_driver_test_attach(drv, NULL, 0))
2226                         return -1;
2227         }
2228
2229         if (os_strstr(param, "use_associnfo=1")) {
2230                 wpa_printf(MSG_DEBUG, "test_driver: Use AssocInfo events");
2231                 drv->use_associnfo = 1;
2232         }
2233
2234 #ifdef CONFIG_CLIENT_MLME
2235         if (os_strstr(param, "use_mlme=1")) {
2236                 wpa_printf(MSG_DEBUG, "test_driver: Use internal MLME");
2237                 drv->use_mlme = 1;
2238         }
2239 #endif /* CONFIG_CLIENT_MLME */
2240
2241         return 0;
2242 }
2243
2244
2245 static const u8 * wpa_driver_test_get_mac_addr(void *priv)
2246 {
2247         struct wpa_driver_test_data *drv = priv;
2248         wpa_printf(MSG_DEBUG, "%s", __func__);
2249         return drv->own_addr;
2250 }
2251
2252
2253 static int wpa_driver_test_send_eapol(void *priv, const u8 *dest, u16 proto,
2254                                       const u8 *data, size_t data_len)
2255 {
2256         struct wpa_driver_test_data *drv = priv;
2257         char *msg;
2258         size_t msg_len;
2259         struct l2_ethhdr eth;
2260         struct sockaddr *addr;
2261         socklen_t alen;
2262 #ifdef DRIVER_TEST_UNIX
2263         struct sockaddr_un addr_un;
2264 #endif /* DRIVER_TEST_UNIX */
2265
2266         wpa_hexdump(MSG_MSGDUMP, "test_send_eapol TX frame", data, data_len);
2267
2268         os_memset(&eth, 0, sizeof(eth));
2269         os_memcpy(eth.h_dest, dest, ETH_ALEN);
2270         os_memcpy(eth.h_source, drv->own_addr, ETH_ALEN);
2271         eth.h_proto = host_to_be16(proto);
2272
2273         msg_len = 6 + sizeof(eth) + data_len;
2274         msg = os_malloc(msg_len);
2275         if (msg == NULL)
2276                 return -1;
2277         os_memcpy(msg, "EAPOL ", 6);
2278         os_memcpy(msg + 6, &eth, sizeof(eth));
2279         os_memcpy(msg + 6 + sizeof(eth), data, data_len);
2280
2281         if (os_memcmp(dest, drv->bssid, ETH_ALEN) == 0 ||
2282             drv->test_dir == NULL) {
2283                 if (drv->hostapd_addr_udp_set) {
2284                         addr = (struct sockaddr *) &drv->hostapd_addr_udp;
2285                         alen = sizeof(drv->hostapd_addr_udp);
2286                 } else {
2287 #ifdef DRIVER_TEST_UNIX
2288                         addr = (struct sockaddr *) &drv->hostapd_addr;
2289                         alen = sizeof(drv->hostapd_addr);
2290 #else /* DRIVER_TEST_UNIX */
2291                         os_free(msg);
2292                         return -1;
2293 #endif /* DRIVER_TEST_UNIX */
2294                 }
2295         } else {
2296 #ifdef DRIVER_TEST_UNIX
2297                 struct stat st;
2298                 os_memset(&addr_un, 0, sizeof(addr_un));
2299                 addr_un.sun_family = AF_UNIX;
2300                 os_snprintf(addr_un.sun_path, sizeof(addr_un.sun_path),
2301                             "%s/STA-" MACSTR, drv->test_dir, MAC2STR(dest));
2302                 if (stat(addr_un.sun_path, &st) < 0) {
2303                         os_snprintf(addr_un.sun_path, sizeof(addr_un.sun_path),
2304                                     "%s/AP-" MACSTR,
2305                                     drv->test_dir, MAC2STR(dest));
2306                 }
2307                 addr = (struct sockaddr *) &addr_un;
2308                 alen = sizeof(addr_un);
2309 #else /* DRIVER_TEST_UNIX */
2310                 os_free(msg);
2311                 return -1;
2312 #endif /* DRIVER_TEST_UNIX */
2313         }
2314
2315         if (sendto(drv->test_socket, msg, msg_len, 0, addr, alen) < 0) {
2316                 perror("sendmsg(test_socket)");
2317                 os_free(msg);
2318                 return -1;
2319         }
2320
2321         os_free(msg);
2322         return 0;
2323 }
2324
2325
2326 static int wpa_driver_test_get_capa(void *priv, struct wpa_driver_capa *capa)
2327 {
2328         struct wpa_driver_test_data *drv = priv;
2329         os_memset(capa, 0, sizeof(*capa));
2330         capa->key_mgmt = WPA_DRIVER_CAPA_KEY_MGMT_WPA |
2331                 WPA_DRIVER_CAPA_KEY_MGMT_WPA2 |
2332                 WPA_DRIVER_CAPA_KEY_MGMT_WPA_PSK |
2333                 WPA_DRIVER_CAPA_KEY_MGMT_WPA2_PSK |
2334                 WPA_DRIVER_CAPA_KEY_MGMT_WPA_NONE |
2335                 WPA_DRIVER_CAPA_KEY_MGMT_FT |
2336                 WPA_DRIVER_CAPA_KEY_MGMT_FT_PSK;
2337         capa->enc = WPA_DRIVER_CAPA_ENC_WEP40 |
2338                 WPA_DRIVER_CAPA_ENC_WEP104 |
2339                 WPA_DRIVER_CAPA_ENC_TKIP |
2340                 WPA_DRIVER_CAPA_ENC_CCMP;
2341         capa->auth = WPA_DRIVER_AUTH_OPEN |
2342                 WPA_DRIVER_AUTH_SHARED |
2343                 WPA_DRIVER_AUTH_LEAP;
2344         if (drv->use_mlme)
2345                 capa->flags |= WPA_DRIVER_FLAGS_USER_SPACE_MLME;
2346         capa->flags |= WPA_DRIVER_FLAGS_AP;
2347         capa->max_scan_ssids = 2;
2348
2349         return 0;
2350 }
2351
2352
2353 static int wpa_driver_test_mlme_setprotection(void *priv, const u8 *addr,
2354                                               int protect_type,
2355                                               int key_type)
2356 {
2357         wpa_printf(MSG_DEBUG, "%s: protect_type=%d key_type=%d",
2358                    __func__, protect_type, key_type);
2359
2360         if (addr) {
2361                 wpa_printf(MSG_DEBUG, "%s: addr=" MACSTR,
2362                            __func__, MAC2STR(addr));
2363         }
2364
2365         return 0;
2366 }
2367
2368
2369 static int wpa_driver_test_set_channel(void *priv,
2370                                        enum hostapd_hw_mode phymode,
2371                                        int chan, int freq)
2372 {
2373         struct wpa_driver_test_data *drv = priv;
2374         wpa_printf(MSG_DEBUG, "%s: phymode=%d chan=%d freq=%d",
2375                    __func__, phymode, chan, freq);
2376         drv->current_freq = freq;
2377         return 0;
2378 }
2379
2380
2381 static int wpa_driver_test_mlme_add_sta(void *priv, const u8 *addr,
2382                                         const u8 *supp_rates,
2383                                         size_t supp_rates_len)
2384 {
2385         wpa_printf(MSG_DEBUG, "%s: addr=" MACSTR, __func__, MAC2STR(addr));
2386         return 0;
2387 }
2388
2389
2390 static int wpa_driver_test_mlme_remove_sta(void *priv, const u8 *addr)
2391 {
2392         wpa_printf(MSG_DEBUG, "%s: addr=" MACSTR, __func__, MAC2STR(addr));
2393         return 0;
2394 }
2395
2396
2397 static int wpa_driver_test_set_ssid(void *priv, const u8 *ssid,
2398                                     size_t ssid_len)
2399 {
2400         wpa_printf(MSG_DEBUG, "%s", __func__);
2401         return 0;
2402 }
2403
2404
2405 static int wpa_driver_test_set_bssid(void *priv, const u8 *bssid)
2406 {
2407         wpa_printf(MSG_DEBUG, "%s: bssid=" MACSTR, __func__, MAC2STR(bssid));
2408         return 0;
2409 }
2410
2411
2412 static void * wpa_driver_test_global_init(void)
2413 {
2414         struct wpa_driver_test_global *global;
2415
2416         global = os_zalloc(sizeof(*global));
2417         return global;
2418 }
2419
2420
2421 static void wpa_driver_test_global_deinit(void *priv)
2422 {
2423         struct wpa_driver_test_global *global = priv;
2424         os_free(global);
2425 }
2426
2427
2428 static struct wpa_interface_info *
2429 wpa_driver_test_get_interfaces(void *global_priv)
2430 {
2431         /* struct wpa_driver_test_global *global = priv; */
2432         struct wpa_interface_info *iface;
2433
2434         iface = os_zalloc(sizeof(*iface));
2435         if (iface == NULL)
2436                 return iface;
2437         iface->ifname = os_strdup("sta0");
2438         iface->desc = os_strdup("test interface 0");
2439         iface->drv_name = "test";
2440         iface->next = os_zalloc(sizeof(*iface));
2441         if (iface->next) {
2442                 iface->next->ifname = os_strdup("sta1");
2443                 iface->next->desc = os_strdup("test interface 1");
2444                 iface->next->drv_name = "test";
2445         }
2446
2447         return iface;
2448 }
2449
2450
2451 static struct hostapd_hw_modes *
2452 wpa_driver_test_get_hw_feature_data(void *priv, u16 *num_modes, u16 *flags)
2453 {
2454         struct hostapd_hw_modes *modes;
2455         size_t i;
2456
2457         *num_modes = 3;
2458         *flags = 0;
2459         modes = os_zalloc(*num_modes * sizeof(struct hostapd_hw_modes));
2460         if (modes == NULL)
2461                 return NULL;
2462         modes[0].mode = HOSTAPD_MODE_IEEE80211G;
2463         modes[0].num_channels = 11;
2464         modes[0].num_rates = 12;
2465         modes[0].channels =
2466                 os_zalloc(11 * sizeof(struct hostapd_channel_data));
2467         modes[0].rates = os_zalloc(modes[0].num_rates * sizeof(int));
2468         if (modes[0].channels == NULL || modes[0].rates == NULL)
2469                 goto fail;
2470         for (i = 0; i < 11; i++) {
2471                 modes[0].channels[i].chan = i + 1;
2472                 modes[0].channels[i].freq = 2412 + 5 * i;
2473                 modes[0].channels[i].flag = 0;
2474         }
2475         modes[0].rates[0] = 10;
2476         modes[0].rates[1] = 20;
2477         modes[0].rates[2] = 55;
2478         modes[0].rates[3] = 110;
2479         modes[0].rates[4] = 60;
2480         modes[0].rates[5] = 90;
2481         modes[0].rates[6] = 120;
2482         modes[0].rates[7] = 180;
2483         modes[0].rates[8] = 240;
2484         modes[0].rates[9] = 360;
2485         modes[0].rates[10] = 480;
2486         modes[0].rates[11] = 540;
2487
2488         modes[1].mode = HOSTAPD_MODE_IEEE80211B;
2489         modes[1].num_channels = 11;
2490         modes[1].num_rates = 4;
2491         modes[1].channels =
2492                 os_zalloc(11 * sizeof(struct hostapd_channel_data));
2493         modes[1].rates = os_zalloc(modes[1].num_rates * sizeof(int));
2494         if (modes[1].channels == NULL || modes[1].rates == NULL)
2495                 goto fail;
2496         for (i = 0; i < 11; i++) {
2497                 modes[1].channels[i].chan = i + 1;
2498                 modes[1].channels[i].freq = 2412 + 5 * i;
2499                 modes[1].channels[i].flag = 0;
2500         }
2501         modes[1].rates[0] = 10;
2502         modes[1].rates[1] = 20;
2503         modes[1].rates[2] = 55;
2504         modes[1].rates[3] = 110;
2505
2506         modes[2].mode = HOSTAPD_MODE_IEEE80211A;
2507         modes[2].num_channels = 1;
2508         modes[2].num_rates = 8;
2509         modes[2].channels = os_zalloc(sizeof(struct hostapd_channel_data));
2510         modes[2].rates = os_zalloc(modes[2].num_rates * sizeof(int));
2511         if (modes[2].channels == NULL || modes[2].rates == NULL)
2512                 goto fail;
2513         modes[2].channels[0].chan = 60;
2514         modes[2].channels[0].freq = 5300;
2515         modes[2].channels[0].flag = 0;
2516         modes[2].rates[0] = 60;
2517         modes[2].rates[1] = 90;
2518         modes[2].rates[2] = 120;
2519         modes[2].rates[3] = 180;
2520         modes[2].rates[4] = 240;
2521         modes[2].rates[5] = 360;
2522         modes[2].rates[6] = 480;
2523         modes[2].rates[7] = 540;
2524
2525         return modes;
2526
2527 fail:
2528         if (modes) {
2529                 for (i = 0; i < *num_modes; i++) {
2530                         os_free(modes[i].channels);
2531                         os_free(modes[i].rates);
2532                 }
2533                 os_free(modes);
2534         }
2535         return NULL;
2536 }
2537
2538
2539 static int wpa_driver_test_set_freq(void *priv,
2540                                     struct hostapd_freq_params *freq)
2541 {
2542         struct wpa_driver_test_data *drv = priv;
2543         wpa_printf(MSG_DEBUG, "test: set_freq %u MHz", freq->freq);
2544         drv->current_freq = freq->freq;
2545         return 0;
2546 }
2547
2548
2549 static int wpa_driver_test_send_action(void *priv, unsigned int freq,
2550                                        const u8 *dst, const u8 *src,
2551                                        const u8 *data, size_t data_len)
2552 {
2553         struct wpa_driver_test_data *drv = priv;
2554         int ret = -1;
2555         u8 *buf;
2556         struct ieee80211_hdr *hdr;
2557
2558         wpa_printf(MSG_DEBUG, "test: Send Action frame");
2559
2560         if ((drv->remain_on_channel_freq &&
2561              freq != drv->remain_on_channel_freq) ||
2562             (drv->remain_on_channel_freq == 0 &&
2563              freq != (unsigned int) drv->current_freq)) {
2564                 wpa_printf(MSG_DEBUG, "test: Reject Action frame TX on "
2565                            "unexpected channel: freq=%u MHz (current_freq=%u "
2566                            "MHz, remain-on-channel freq=%u MHz)",
2567                            freq, drv->current_freq,
2568                            drv->remain_on_channel_freq);
2569                 return -1;
2570         }
2571
2572         buf = os_zalloc(24 + data_len);
2573         if (buf == NULL)
2574                 return ret;
2575         os_memcpy(buf + 24, data, data_len);
2576         hdr = (struct ieee80211_hdr *) buf;
2577         hdr->frame_control =
2578                 IEEE80211_FC(WLAN_FC_TYPE_MGMT, WLAN_FC_STYPE_ACTION);
2579         os_memcpy(hdr->addr1, dst, ETH_ALEN);
2580         os_memcpy(hdr->addr2, src, ETH_ALEN);
2581         os_memcpy(hdr->addr3, "\xff\xff\xff\xff\xff\xff", ETH_ALEN);
2582
2583         ret = wpa_driver_test_send_mlme(priv, buf, 24 + data_len);
2584         os_free(buf);
2585         return ret;
2586 }
2587
2588
2589 static int wpa_driver_test_alloc_interface_addr(void *priv, u8 *addr)
2590 {
2591         struct wpa_driver_test_data *drv = priv;
2592         drv->alloc_iface_idx++;
2593         addr[0] = 0x02; /* locally administered */
2594         sha1_prf(drv->own_addr, ETH_ALEN, "hostapd test addr generation",
2595                  (const u8 *) &drv->alloc_iface_idx,
2596                  sizeof(drv->alloc_iface_idx),
2597                  addr + 1, ETH_ALEN - 1);
2598         return 0;
2599 }
2600
2601
2602 static void wpa_driver_test_release_interface_addr(void *priv, const u8 *addr)
2603 {
2604 }
2605
2606
2607 static void test_remain_on_channel_timeout(void *eloop_ctx, void *timeout_ctx)
2608 {
2609         struct wpa_driver_test_data *drv = eloop_ctx;
2610         union wpa_event_data data;
2611
2612         wpa_printf(MSG_DEBUG, "test: Remain-on-channel timeout");
2613
2614         os_memset(&data, 0, sizeof(data));
2615         data.remain_on_channel.freq = drv->remain_on_channel_freq;
2616         data.remain_on_channel.duration = drv->remain_on_channel_duration;
2617         wpa_supplicant_event(drv->ctx, EVENT_CANCEL_REMAIN_ON_CHANNEL, &data);
2618
2619         drv->remain_on_channel_freq = 0;
2620 }
2621
2622
2623 static int wpa_driver_test_remain_on_channel(void *priv, unsigned int freq,
2624                                              unsigned int duration)
2625 {
2626         struct wpa_driver_test_data *drv = priv;
2627         union wpa_event_data data;
2628
2629         wpa_printf(MSG_DEBUG, "%s(freq=%u, duration=%u)",
2630                    __func__, freq, duration);
2631         if (drv->remain_on_channel_freq &&
2632             drv->remain_on_channel_freq != freq) {
2633                 wpa_printf(MSG_DEBUG, "test: Refuse concurrent "
2634                            "remain_on_channel request");
2635                 return -1;
2636         }
2637
2638         drv->remain_on_channel_freq = freq;
2639         drv->remain_on_channel_duration = duration;
2640         eloop_cancel_timeout(test_remain_on_channel_timeout, drv, NULL);
2641         eloop_register_timeout(duration / 1000, (duration % 1000) * 1000,
2642                                test_remain_on_channel_timeout, drv, NULL);
2643
2644         os_memset(&data, 0, sizeof(data));
2645         data.remain_on_channel.freq = freq;
2646         data.remain_on_channel.duration = duration;
2647         wpa_supplicant_event(drv->ctx, EVENT_REMAIN_ON_CHANNEL, &data);
2648
2649         return 0;
2650 }
2651
2652
2653 static int wpa_driver_test_cancel_remain_on_channel(void *priv)
2654 {
2655         struct wpa_driver_test_data *drv = priv;
2656         wpa_printf(MSG_DEBUG, "%s", __func__);
2657         if (!drv->remain_on_channel_freq)
2658                 return -1;
2659         drv->remain_on_channel_freq = 0;
2660         eloop_cancel_timeout(test_remain_on_channel_timeout, drv, NULL);
2661         return 0;
2662 }
2663
2664
2665 static int wpa_driver_test_probe_req_report(void *priv, int report)
2666 {
2667         struct wpa_driver_test_data *drv = priv;
2668         wpa_printf(MSG_DEBUG, "%s(report=%d)", __func__, report);
2669         drv->probe_req_report = report;
2670         return 0;
2671 }
2672
2673
2674 const struct wpa_driver_ops wpa_driver_test_ops = {
2675         "test",
2676         "wpa_supplicant test driver",
2677         .hapd_init = test_driver_init,
2678         .hapd_deinit = wpa_driver_test_deinit,
2679         .hapd_send_eapol = test_driver_send_eapol,
2680         .send_mlme = wpa_driver_test_send_mlme,
2681         .set_generic_elem = test_driver_set_generic_elem,
2682         .sta_deauth = test_driver_sta_deauth,
2683         .sta_disassoc = test_driver_sta_disassoc,
2684         .get_hw_feature_data = wpa_driver_test_get_hw_feature_data,
2685         .if_add = test_driver_if_add,
2686         .if_remove = test_driver_if_remove,
2687         .valid_bss_mask = test_driver_valid_bss_mask,
2688         .hapd_set_ssid = test_driver_set_ssid,
2689         .set_privacy = test_driver_set_privacy,
2690         .set_sta_vlan = test_driver_set_sta_vlan,
2691         .sta_add = test_driver_sta_add,
2692         .send_ether = test_driver_send_ether,
2693         .set_ap_wps_ie = test_driver_set_ap_wps_ie,
2694         .get_bssid = wpa_driver_test_get_bssid,
2695         .get_ssid = wpa_driver_test_get_ssid,
2696         .set_key = wpa_driver_test_set_key,
2697         .deinit = wpa_driver_test_deinit,
2698         .set_param = wpa_driver_test_set_param,
2699         .deauthenticate = wpa_driver_test_deauthenticate,
2700         .disassociate = wpa_driver_test_disassociate,
2701         .associate = wpa_driver_test_associate,
2702         .get_capa = wpa_driver_test_get_capa,
2703         .get_mac_addr = wpa_driver_test_get_mac_addr,
2704         .send_eapol = wpa_driver_test_send_eapol,
2705         .mlme_setprotection = wpa_driver_test_mlme_setprotection,
2706         .set_channel = wpa_driver_test_set_channel,
2707         .set_ssid = wpa_driver_test_set_ssid,
2708         .set_bssid = wpa_driver_test_set_bssid,
2709         .mlme_add_sta = wpa_driver_test_mlme_add_sta,
2710         .mlme_remove_sta = wpa_driver_test_mlme_remove_sta,
2711         .get_scan_results2 = wpa_driver_test_get_scan_results2,
2712         .global_init = wpa_driver_test_global_init,
2713         .global_deinit = wpa_driver_test_global_deinit,
2714         .init2 = wpa_driver_test_init2,
2715         .get_interfaces = wpa_driver_test_get_interfaces,
2716         .scan2 = wpa_driver_test_scan,
2717         .set_freq = wpa_driver_test_set_freq,
2718         .send_action = wpa_driver_test_send_action,
2719         .alloc_interface_addr = wpa_driver_test_alloc_interface_addr,
2720         .release_interface_addr = wpa_driver_test_release_interface_addr,
2721         .remain_on_channel = wpa_driver_test_remain_on_channel,
2722         .cancel_remain_on_channel = wpa_driver_test_cancel_remain_on_channel,
2723         .probe_req_report = wpa_driver_test_probe_req_report,
2724 };