tests: Declare module test functions in a header file
[mech_eap.git] / hostapd / ctrl_iface.c
1 /*
2  * hostapd / UNIX domain socket -based control interface
3  * Copyright (c) 2004-2015, Jouni Malinen <j@w1.fi>
4  *
5  * This software may be distributed under the terms of the BSD license.
6  * See README for more details.
7  */
8
9 #include "utils/includes.h"
10
11 #ifndef CONFIG_NATIVE_WINDOWS
12
13 #ifdef CONFIG_TESTING_OPTIONS
14 #include <net/ethernet.h>
15 #include <netinet/ip.h>
16 #endif /* CONFIG_TESTING_OPTIONS */
17
18 #include <sys/un.h>
19 #include <sys/stat.h>
20 #include <stddef.h>
21
22 #ifdef CONFIG_CTRL_IFACE_UDP
23 #include <netdb.h>
24 #endif /* CONFIG_CTRL_IFACE_UDP */
25
26 #include "utils/common.h"
27 #include "utils/eloop.h"
28 #include "utils/module_tests.h"
29 #include "common/version.h"
30 #include "common/ieee802_11_defs.h"
31 #include "common/ctrl_iface_common.h"
32 #include "crypto/tls.h"
33 #include "drivers/driver.h"
34 #include "eapol_auth/eapol_auth_sm.h"
35 #include "radius/radius_client.h"
36 #include "radius/radius_server.h"
37 #include "l2_packet/l2_packet.h"
38 #include "ap/hostapd.h"
39 #include "ap/ap_config.h"
40 #include "ap/ieee802_1x.h"
41 #include "ap/wpa_auth.h"
42 #include "ap/ieee802_11.h"
43 #include "ap/sta_info.h"
44 #include "ap/wps_hostapd.h"
45 #include "ap/ctrl_iface_ap.h"
46 #include "ap/ap_drv_ops.h"
47 #include "ap/hs20.h"
48 #include "ap/wnm_ap.h"
49 #include "ap/wpa_auth.h"
50 #include "ap/beacon.h"
51 #include "ap/neighbor_db.h"
52 #include "ap/rrm.h"
53 #include "wps/wps_defs.h"
54 #include "wps/wps.h"
55 #include "fst/fst_ctrl_iface.h"
56 #include "config_file.h"
57 #include "ctrl_iface.h"
58
59
60 #define HOSTAPD_CLI_DUP_VALUE_MAX_LEN 256
61
62 #ifdef CONFIG_CTRL_IFACE_UDP
63 #define COOKIE_LEN 8
64 static unsigned char cookie[COOKIE_LEN];
65 static unsigned char gcookie[COOKIE_LEN];
66 #define HOSTAPD_CTRL_IFACE_PORT         8877
67 #define HOSTAPD_CTRL_IFACE_PORT_LIMIT   50
68 #define HOSTAPD_GLOBAL_CTRL_IFACE_PORT          8878
69 #define HOSTAPD_GLOBAL_CTRL_IFACE_PORT_LIMIT    50
70 #endif /* CONFIG_CTRL_IFACE_UDP */
71
72 static void hostapd_ctrl_iface_send(struct hostapd_data *hapd, int level,
73                                     enum wpa_msg_type type,
74                                     const char *buf, size_t len);
75
76
77 static int hostapd_ctrl_iface_attach(struct hostapd_data *hapd,
78                                      struct sockaddr_storage *from,
79                                      socklen_t fromlen)
80 {
81         return ctrl_iface_attach(&hapd->ctrl_dst, from, fromlen);
82 }
83
84
85 static int hostapd_ctrl_iface_detach(struct hostapd_data *hapd,
86                                      struct sockaddr_storage *from,
87                                      socklen_t fromlen)
88 {
89         return ctrl_iface_detach(&hapd->ctrl_dst, from, fromlen);
90 }
91
92
93 static int hostapd_ctrl_iface_level(struct hostapd_data *hapd,
94                                     struct sockaddr_storage *from,
95                                     socklen_t fromlen,
96                                     char *level)
97 {
98         return ctrl_iface_level(&hapd->ctrl_dst, from, fromlen, level);
99 }
100
101
102 static int hostapd_ctrl_iface_new_sta(struct hostapd_data *hapd,
103                                       const char *txtaddr)
104 {
105         u8 addr[ETH_ALEN];
106         struct sta_info *sta;
107
108         wpa_printf(MSG_DEBUG, "CTRL_IFACE NEW_STA %s", txtaddr);
109
110         if (hwaddr_aton(txtaddr, addr))
111                 return -1;
112
113         sta = ap_get_sta(hapd, addr);
114         if (sta)
115                 return 0;
116
117         wpa_printf(MSG_DEBUG, "Add new STA " MACSTR " based on ctrl_iface "
118                    "notification", MAC2STR(addr));
119         sta = ap_sta_add(hapd, addr);
120         if (sta == NULL)
121                 return -1;
122
123         hostapd_new_assoc_sta(hapd, sta, 0);
124         return 0;
125 }
126
127
128 #ifdef CONFIG_IEEE80211W
129 #ifdef NEED_AP_MLME
130 static int hostapd_ctrl_iface_sa_query(struct hostapd_data *hapd,
131                                        const char *txtaddr)
132 {
133         u8 addr[ETH_ALEN];
134         u8 trans_id[WLAN_SA_QUERY_TR_ID_LEN];
135
136         wpa_printf(MSG_DEBUG, "CTRL_IFACE SA_QUERY %s", txtaddr);
137
138         if (hwaddr_aton(txtaddr, addr) ||
139             os_get_random(trans_id, WLAN_SA_QUERY_TR_ID_LEN) < 0)
140                 return -1;
141
142         ieee802_11_send_sa_query_req(hapd, addr, trans_id);
143
144         return 0;
145 }
146 #endif /* NEED_AP_MLME */
147 #endif /* CONFIG_IEEE80211W */
148
149
150 #ifdef CONFIG_WPS
151 static int hostapd_ctrl_iface_wps_pin(struct hostapd_data *hapd, char *txt)
152 {
153         char *pin = os_strchr(txt, ' ');
154         char *timeout_txt;
155         int timeout;
156         u8 addr_buf[ETH_ALEN], *addr = NULL;
157         char *pos;
158
159         if (pin == NULL)
160                 return -1;
161         *pin++ = '\0';
162
163         timeout_txt = os_strchr(pin, ' ');
164         if (timeout_txt) {
165                 *timeout_txt++ = '\0';
166                 timeout = atoi(timeout_txt);
167                 pos = os_strchr(timeout_txt, ' ');
168                 if (pos) {
169                         *pos++ = '\0';
170                         if (hwaddr_aton(pos, addr_buf) == 0)
171                                 addr = addr_buf;
172                 }
173         } else
174                 timeout = 0;
175
176         return hostapd_wps_add_pin(hapd, addr, txt, pin, timeout);
177 }
178
179
180 static int hostapd_ctrl_iface_wps_check_pin(
181         struct hostapd_data *hapd, char *cmd, char *buf, size_t buflen)
182 {
183         char pin[9];
184         size_t len;
185         char *pos;
186         int ret;
187
188         wpa_hexdump_ascii_key(MSG_DEBUG, "WPS_CHECK_PIN",
189                               (u8 *) cmd, os_strlen(cmd));
190         for (pos = cmd, len = 0; *pos != '\0'; pos++) {
191                 if (*pos < '0' || *pos > '9')
192                         continue;
193                 pin[len++] = *pos;
194                 if (len == 9) {
195                         wpa_printf(MSG_DEBUG, "WPS: Too long PIN");
196                         return -1;
197                 }
198         }
199         if (len != 4 && len != 8) {
200                 wpa_printf(MSG_DEBUG, "WPS: Invalid PIN length %d", (int) len);
201                 return -1;
202         }
203         pin[len] = '\0';
204
205         if (len == 8) {
206                 unsigned int pin_val;
207                 pin_val = atoi(pin);
208                 if (!wps_pin_valid(pin_val)) {
209                         wpa_printf(MSG_DEBUG, "WPS: Invalid checksum digit");
210                         ret = os_snprintf(buf, buflen, "FAIL-CHECKSUM\n");
211                         if (os_snprintf_error(buflen, ret))
212                                 return -1;
213                         return ret;
214                 }
215         }
216
217         ret = os_snprintf(buf, buflen, "%s", pin);
218         if (os_snprintf_error(buflen, ret))
219                 return -1;
220
221         return ret;
222 }
223
224
225 #ifdef CONFIG_WPS_NFC
226 static int hostapd_ctrl_iface_wps_nfc_tag_read(struct hostapd_data *hapd,
227                                                char *pos)
228 {
229         size_t len;
230         struct wpabuf *buf;
231         int ret;
232
233         len = os_strlen(pos);
234         if (len & 0x01)
235                 return -1;
236         len /= 2;
237
238         buf = wpabuf_alloc(len);
239         if (buf == NULL)
240                 return -1;
241         if (hexstr2bin(pos, wpabuf_put(buf, len), len) < 0) {
242                 wpabuf_free(buf);
243                 return -1;
244         }
245
246         ret = hostapd_wps_nfc_tag_read(hapd, buf);
247         wpabuf_free(buf);
248
249         return ret;
250 }
251
252
253 static int hostapd_ctrl_iface_wps_nfc_config_token(struct hostapd_data *hapd,
254                                                    char *cmd, char *reply,
255                                                    size_t max_len)
256 {
257         int ndef;
258         struct wpabuf *buf;
259         int res;
260
261         if (os_strcmp(cmd, "WPS") == 0)
262                 ndef = 0;
263         else if (os_strcmp(cmd, "NDEF") == 0)
264                 ndef = 1;
265         else
266                 return -1;
267
268         buf = hostapd_wps_nfc_config_token(hapd, ndef);
269         if (buf == NULL)
270                 return -1;
271
272         res = wpa_snprintf_hex_uppercase(reply, max_len, wpabuf_head(buf),
273                                          wpabuf_len(buf));
274         reply[res++] = '\n';
275         reply[res] = '\0';
276
277         wpabuf_free(buf);
278
279         return res;
280 }
281
282
283 static int hostapd_ctrl_iface_wps_nfc_token_gen(struct hostapd_data *hapd,
284                                                 char *reply, size_t max_len,
285                                                 int ndef)
286 {
287         struct wpabuf *buf;
288         int res;
289
290         buf = hostapd_wps_nfc_token_gen(hapd, ndef);
291         if (buf == NULL)
292                 return -1;
293
294         res = wpa_snprintf_hex_uppercase(reply, max_len, wpabuf_head(buf),
295                                          wpabuf_len(buf));
296         reply[res++] = '\n';
297         reply[res] = '\0';
298
299         wpabuf_free(buf);
300
301         return res;
302 }
303
304
305 static int hostapd_ctrl_iface_wps_nfc_token(struct hostapd_data *hapd,
306                                             char *cmd, char *reply,
307                                             size_t max_len)
308 {
309         if (os_strcmp(cmd, "WPS") == 0)
310                 return hostapd_ctrl_iface_wps_nfc_token_gen(hapd, reply,
311                                                             max_len, 0);
312
313         if (os_strcmp(cmd, "NDEF") == 0)
314                 return hostapd_ctrl_iface_wps_nfc_token_gen(hapd, reply,
315                                                             max_len, 1);
316
317         if (os_strcmp(cmd, "enable") == 0)
318                 return hostapd_wps_nfc_token_enable(hapd);
319
320         if (os_strcmp(cmd, "disable") == 0) {
321                 hostapd_wps_nfc_token_disable(hapd);
322                 return 0;
323         }
324
325         return -1;
326 }
327
328
329 static int hostapd_ctrl_iface_nfc_get_handover_sel(struct hostapd_data *hapd,
330                                                    char *cmd, char *reply,
331                                                    size_t max_len)
332 {
333         struct wpabuf *buf;
334         int res;
335         char *pos;
336         int ndef;
337
338         pos = os_strchr(cmd, ' ');
339         if (pos == NULL)
340                 return -1;
341         *pos++ = '\0';
342
343         if (os_strcmp(cmd, "WPS") == 0)
344                 ndef = 0;
345         else if (os_strcmp(cmd, "NDEF") == 0)
346                 ndef = 1;
347         else
348                 return -1;
349
350         if (os_strcmp(pos, "WPS-CR") == 0)
351                 buf = hostapd_wps_nfc_hs_cr(hapd, ndef);
352         else
353                 buf = NULL;
354         if (buf == NULL)
355                 return -1;
356
357         res = wpa_snprintf_hex_uppercase(reply, max_len, wpabuf_head(buf),
358                                          wpabuf_len(buf));
359         reply[res++] = '\n';
360         reply[res] = '\0';
361
362         wpabuf_free(buf);
363
364         return res;
365 }
366
367
368 static int hostapd_ctrl_iface_nfc_report_handover(struct hostapd_data *hapd,
369                                                   char *cmd)
370 {
371         size_t len;
372         struct wpabuf *req, *sel;
373         int ret;
374         char *pos, *role, *type, *pos2;
375
376         role = cmd;
377         pos = os_strchr(role, ' ');
378         if (pos == NULL)
379                 return -1;
380         *pos++ = '\0';
381
382         type = pos;
383         pos = os_strchr(type, ' ');
384         if (pos == NULL)
385                 return -1;
386         *pos++ = '\0';
387
388         pos2 = os_strchr(pos, ' ');
389         if (pos2 == NULL)
390                 return -1;
391         *pos2++ = '\0';
392
393         len = os_strlen(pos);
394         if (len & 0x01)
395                 return -1;
396         len /= 2;
397
398         req = wpabuf_alloc(len);
399         if (req == NULL)
400                 return -1;
401         if (hexstr2bin(pos, wpabuf_put(req, len), len) < 0) {
402                 wpabuf_free(req);
403                 return -1;
404         }
405
406         len = os_strlen(pos2);
407         if (len & 0x01) {
408                 wpabuf_free(req);
409                 return -1;
410         }
411         len /= 2;
412
413         sel = wpabuf_alloc(len);
414         if (sel == NULL) {
415                 wpabuf_free(req);
416                 return -1;
417         }
418         if (hexstr2bin(pos2, wpabuf_put(sel, len), len) < 0) {
419                 wpabuf_free(req);
420                 wpabuf_free(sel);
421                 return -1;
422         }
423
424         if (os_strcmp(role, "RESP") == 0 && os_strcmp(type, "WPS") == 0) {
425                 ret = hostapd_wps_nfc_report_handover(hapd, req, sel);
426         } else {
427                 wpa_printf(MSG_DEBUG, "NFC: Unsupported connection handover "
428                            "reported: role=%s type=%s", role, type);
429                 ret = -1;
430         }
431         wpabuf_free(req);
432         wpabuf_free(sel);
433
434         return ret;
435 }
436
437 #endif /* CONFIG_WPS_NFC */
438
439
440 static int hostapd_ctrl_iface_wps_ap_pin(struct hostapd_data *hapd, char *txt,
441                                          char *buf, size_t buflen)
442 {
443         int timeout = 300;
444         char *pos;
445         const char *pin_txt;
446
447         pos = os_strchr(txt, ' ');
448         if (pos)
449                 *pos++ = '\0';
450
451         if (os_strcmp(txt, "disable") == 0) {
452                 hostapd_wps_ap_pin_disable(hapd);
453                 return os_snprintf(buf, buflen, "OK\n");
454         }
455
456         if (os_strcmp(txt, "random") == 0) {
457                 if (pos)
458                         timeout = atoi(pos);
459                 pin_txt = hostapd_wps_ap_pin_random(hapd, timeout);
460                 if (pin_txt == NULL)
461                         return -1;
462                 return os_snprintf(buf, buflen, "%s", pin_txt);
463         }
464
465         if (os_strcmp(txt, "get") == 0) {
466                 pin_txt = hostapd_wps_ap_pin_get(hapd);
467                 if (pin_txt == NULL)
468                         return -1;
469                 return os_snprintf(buf, buflen, "%s", pin_txt);
470         }
471
472         if (os_strcmp(txt, "set") == 0) {
473                 char *pin;
474                 if (pos == NULL)
475                         return -1;
476                 pin = pos;
477                 pos = os_strchr(pos, ' ');
478                 if (pos) {
479                         *pos++ = '\0';
480                         timeout = atoi(pos);
481                 }
482                 if (os_strlen(pin) > buflen)
483                         return -1;
484                 if (hostapd_wps_ap_pin_set(hapd, pin, timeout) < 0)
485                         return -1;
486                 return os_snprintf(buf, buflen, "%s", pin);
487         }
488
489         return -1;
490 }
491
492
493 static int hostapd_ctrl_iface_wps_config(struct hostapd_data *hapd, char *txt)
494 {
495         char *pos;
496         char *ssid, *auth, *encr = NULL, *key = NULL;
497
498         ssid = txt;
499         pos = os_strchr(txt, ' ');
500         if (!pos)
501                 return -1;
502         *pos++ = '\0';
503
504         auth = pos;
505         pos = os_strchr(pos, ' ');
506         if (pos) {
507                 *pos++ = '\0';
508                 encr = pos;
509                 pos = os_strchr(pos, ' ');
510                 if (pos) {
511                         *pos++ = '\0';
512                         key = pos;
513                 }
514         }
515
516         return hostapd_wps_config_ap(hapd, ssid, auth, encr, key);
517 }
518
519
520 static const char * pbc_status_str(enum pbc_status status)
521 {
522         switch (status) {
523         case WPS_PBC_STATUS_DISABLE:
524                 return "Disabled";
525         case WPS_PBC_STATUS_ACTIVE:
526                 return "Active";
527         case WPS_PBC_STATUS_TIMEOUT:
528                 return "Timed-out";
529         case WPS_PBC_STATUS_OVERLAP:
530                 return "Overlap";
531         default:
532                 return "Unknown";
533         }
534 }
535
536
537 static int hostapd_ctrl_iface_wps_get_status(struct hostapd_data *hapd,
538                                              char *buf, size_t buflen)
539 {
540         int ret;
541         char *pos, *end;
542
543         pos = buf;
544         end = buf + buflen;
545
546         ret = os_snprintf(pos, end - pos, "PBC Status: %s\n",
547                           pbc_status_str(hapd->wps_stats.pbc_status));
548
549         if (os_snprintf_error(end - pos, ret))
550                 return pos - buf;
551         pos += ret;
552
553         ret = os_snprintf(pos, end - pos, "Last WPS result: %s\n",
554                           (hapd->wps_stats.status == WPS_STATUS_SUCCESS ?
555                            "Success":
556                            (hapd->wps_stats.status == WPS_STATUS_FAILURE ?
557                             "Failed" : "None")));
558
559         if (os_snprintf_error(end - pos, ret))
560                 return pos - buf;
561         pos += ret;
562
563         /* If status == Failure - Add possible Reasons */
564         if(hapd->wps_stats.status == WPS_STATUS_FAILURE &&
565            hapd->wps_stats.failure_reason > 0) {
566                 ret = os_snprintf(pos, end - pos,
567                                   "Failure Reason: %s\n",
568                                   wps_ei_str(hapd->wps_stats.failure_reason));
569
570                 if (os_snprintf_error(end - pos, ret))
571                         return pos - buf;
572                 pos += ret;
573         }
574
575         if (hapd->wps_stats.status) {
576                 ret = os_snprintf(pos, end - pos, "Peer Address: " MACSTR "\n",
577                                   MAC2STR(hapd->wps_stats.peer_addr));
578
579                 if (os_snprintf_error(end - pos, ret))
580                         return pos - buf;
581                 pos += ret;
582         }
583
584         return pos - buf;
585 }
586
587 #endif /* CONFIG_WPS */
588
589 #ifdef CONFIG_HS20
590
591 static int hostapd_ctrl_iface_hs20_wnm_notif(struct hostapd_data *hapd,
592                                              const char *cmd)
593 {
594         u8 addr[ETH_ALEN];
595         const char *url;
596
597         if (hwaddr_aton(cmd, addr))
598                 return -1;
599         url = cmd + 17;
600         if (*url == '\0') {
601                 url = NULL;
602         } else {
603                 if (*url != ' ')
604                         return -1;
605                 url++;
606                 if (*url == '\0')
607                         url = NULL;
608         }
609
610         return hs20_send_wnm_notification(hapd, addr, 1, url);
611 }
612
613
614 static int hostapd_ctrl_iface_hs20_deauth_req(struct hostapd_data *hapd,
615                                               const char *cmd)
616 {
617         u8 addr[ETH_ALEN];
618         int code, reauth_delay, ret;
619         const char *pos;
620         size_t url_len;
621         struct wpabuf *req;
622
623         /* <STA MAC Addr> <Code(0/1)> <Re-auth-Delay(sec)> [URL] */
624         if (hwaddr_aton(cmd, addr))
625                 return -1;
626
627         pos = os_strchr(cmd, ' ');
628         if (pos == NULL)
629                 return -1;
630         pos++;
631         code = atoi(pos);
632
633         pos = os_strchr(pos, ' ');
634         if (pos == NULL)
635                 return -1;
636         pos++;
637         reauth_delay = atoi(pos);
638
639         url_len = 0;
640         pos = os_strchr(pos, ' ');
641         if (pos) {
642                 pos++;
643                 url_len = os_strlen(pos);
644         }
645
646         req = wpabuf_alloc(4 + url_len);
647         if (req == NULL)
648                 return -1;
649         wpabuf_put_u8(req, code);
650         wpabuf_put_le16(req, reauth_delay);
651         wpabuf_put_u8(req, url_len);
652         if (pos)
653                 wpabuf_put_data(req, pos, url_len);
654
655         wpa_printf(MSG_DEBUG, "HS 2.0: Send WNM-Notification to " MACSTR
656                    " to indicate imminent deauthentication (code=%d "
657                    "reauth_delay=%d)", MAC2STR(addr), code, reauth_delay);
658         ret = hs20_send_wnm_notification_deauth_req(hapd, addr, req);
659         wpabuf_free(req);
660         return ret;
661 }
662
663 #endif /* CONFIG_HS20 */
664
665
666 #ifdef CONFIG_INTERWORKING
667
668 static int hostapd_ctrl_iface_set_qos_map_set(struct hostapd_data *hapd,
669                                               const char *cmd)
670 {
671         u8 qos_map_set[16 + 2 * 21], count = 0;
672         const char *pos = cmd;
673         int val, ret;
674
675         for (;;) {
676                 if (count == sizeof(qos_map_set)) {
677                         wpa_printf(MSG_ERROR, "Too many qos_map_set parameters");
678                         return -1;
679                 }
680
681                 val = atoi(pos);
682                 if (val < 0 || val > 255) {
683                         wpa_printf(MSG_INFO, "Invalid QoS Map Set");
684                         return -1;
685                 }
686
687                 qos_map_set[count++] = val;
688                 pos = os_strchr(pos, ',');
689                 if (!pos)
690                         break;
691                 pos++;
692         }
693
694         if (count < 16 || count & 1) {
695                 wpa_printf(MSG_INFO, "Invalid QoS Map Set");
696                 return -1;
697         }
698
699         ret = hostapd_drv_set_qos_map(hapd, qos_map_set, count);
700         if (ret) {
701                 wpa_printf(MSG_INFO, "Failed to set QoS Map Set");
702                 return -1;
703         }
704
705         os_memcpy(hapd->conf->qos_map_set, qos_map_set, count);
706         hapd->conf->qos_map_set_len = count;
707
708         return 0;
709 }
710
711
712 static int hostapd_ctrl_iface_send_qos_map_conf(struct hostapd_data *hapd,
713                                                 const char *cmd)
714 {
715         u8 addr[ETH_ALEN];
716         struct sta_info *sta;
717         struct wpabuf *buf;
718         u8 *qos_map_set = hapd->conf->qos_map_set;
719         u8 qos_map_set_len = hapd->conf->qos_map_set_len;
720         int ret;
721
722         if (!qos_map_set_len) {
723                 wpa_printf(MSG_INFO, "QoS Map Set is not set");
724                 return -1;
725         }
726
727         if (hwaddr_aton(cmd, addr))
728                 return -1;
729
730         sta = ap_get_sta(hapd, addr);
731         if (sta == NULL) {
732                 wpa_printf(MSG_DEBUG, "Station " MACSTR " not found "
733                            "for QoS Map Configuration message",
734                            MAC2STR(addr));
735                 return -1;
736         }
737
738         if (!sta->qos_map_enabled) {
739                 wpa_printf(MSG_DEBUG, "Station " MACSTR " did not indicate "
740                            "support for QoS Map", MAC2STR(addr));
741                 return -1;
742         }
743
744         buf = wpabuf_alloc(2 + 2 + qos_map_set_len);
745         if (buf == NULL)
746                 return -1;
747
748         wpabuf_put_u8(buf, WLAN_ACTION_QOS);
749         wpabuf_put_u8(buf, QOS_QOS_MAP_CONFIG);
750
751         /* QoS Map Set Element */
752         wpabuf_put_u8(buf, WLAN_EID_QOS_MAP_SET);
753         wpabuf_put_u8(buf, qos_map_set_len);
754         wpabuf_put_data(buf, qos_map_set, qos_map_set_len);
755
756         ret = hostapd_drv_send_action(hapd, hapd->iface->freq, 0, addr,
757                                       wpabuf_head(buf), wpabuf_len(buf));
758         wpabuf_free(buf);
759
760         return ret;
761 }
762
763 #endif /* CONFIG_INTERWORKING */
764
765
766 #ifdef CONFIG_WNM
767
768 static int hostapd_ctrl_iface_disassoc_imminent(struct hostapd_data *hapd,
769                                                 const char *cmd)
770 {
771         u8 addr[ETH_ALEN];
772         int disassoc_timer;
773         struct sta_info *sta;
774
775         if (hwaddr_aton(cmd, addr))
776                 return -1;
777         if (cmd[17] != ' ')
778                 return -1;
779         disassoc_timer = atoi(cmd + 17);
780
781         sta = ap_get_sta(hapd, addr);
782         if (sta == NULL) {
783                 wpa_printf(MSG_DEBUG, "Station " MACSTR
784                            " not found for disassociation imminent message",
785                            MAC2STR(addr));
786                 return -1;
787         }
788
789         return wnm_send_disassoc_imminent(hapd, sta, disassoc_timer);
790 }
791
792
793 static int hostapd_ctrl_iface_ess_disassoc(struct hostapd_data *hapd,
794                                            const char *cmd)
795 {
796         u8 addr[ETH_ALEN];
797         const char *url, *timerstr;
798         int disassoc_timer;
799         struct sta_info *sta;
800
801         if (hwaddr_aton(cmd, addr))
802                 return -1;
803
804         sta = ap_get_sta(hapd, addr);
805         if (sta == NULL) {
806                 wpa_printf(MSG_DEBUG, "Station " MACSTR
807                            " not found for ESS disassociation imminent message",
808                            MAC2STR(addr));
809                 return -1;
810         }
811
812         timerstr = cmd + 17;
813         if (*timerstr != ' ')
814                 return -1;
815         timerstr++;
816         disassoc_timer = atoi(timerstr);
817         if (disassoc_timer < 0 || disassoc_timer > 65535)
818                 return -1;
819
820         url = os_strchr(timerstr, ' ');
821         if (url == NULL)
822                 return -1;
823         url++;
824
825         return wnm_send_ess_disassoc_imminent(hapd, sta, url, disassoc_timer);
826 }
827
828
829 static int hostapd_ctrl_iface_bss_tm_req(struct hostapd_data *hapd,
830                                          const char *cmd)
831 {
832         u8 addr[ETH_ALEN];
833         const char *pos, *end;
834         int disassoc_timer = 0;
835         struct sta_info *sta;
836         u8 req_mode = 0, valid_int = 0x01;
837         u8 bss_term_dur[12];
838         char *url = NULL;
839         int ret;
840         u8 nei_rep[1000];
841         u8 *nei_pos = nei_rep;
842         u8 mbo[10];
843         size_t mbo_len = 0;
844
845         if (hwaddr_aton(cmd, addr)) {
846                 wpa_printf(MSG_DEBUG, "Invalid STA MAC address");
847                 return -1;
848         }
849
850         sta = ap_get_sta(hapd, addr);
851         if (sta == NULL) {
852                 wpa_printf(MSG_DEBUG, "Station " MACSTR
853                            " not found for BSS TM Request message",
854                            MAC2STR(addr));
855                 return -1;
856         }
857
858         pos = os_strstr(cmd, " disassoc_timer=");
859         if (pos) {
860                 pos += 16;
861                 disassoc_timer = atoi(pos);
862                 if (disassoc_timer < 0 || disassoc_timer > 65535) {
863                         wpa_printf(MSG_DEBUG, "Invalid disassoc_timer");
864                         return -1;
865                 }
866         }
867
868         pos = os_strstr(cmd, " valid_int=");
869         if (pos) {
870                 pos += 11;
871                 valid_int = atoi(pos);
872         }
873
874         pos = os_strstr(cmd, " bss_term=");
875         if (pos) {
876                 pos += 10;
877                 req_mode |= WNM_BSS_TM_REQ_BSS_TERMINATION_INCLUDED;
878                 /* TODO: TSF configurable/learnable */
879                 bss_term_dur[0] = 4; /* Subelement ID */
880                 bss_term_dur[1] = 10; /* Length */
881                 os_memset(bss_term_dur, 2, 8);
882                 end = os_strchr(pos, ',');
883                 if (end == NULL) {
884                         wpa_printf(MSG_DEBUG, "Invalid bss_term data");
885                         return -1;
886                 }
887                 end++;
888                 WPA_PUT_LE16(&bss_term_dur[10], atoi(end));
889         }
890
891
892         /*
893          * BSS Transition Candidate List Entries - Neighbor Report elements
894          * neighbor=<BSSID>,<BSSID Information>,<Operating Class>,
895          * <Channel Number>,<PHY Type>[,<hexdump of Optional Subelements>]
896          */
897         pos = cmd;
898         while (pos) {
899                 u8 *nei_start;
900                 long int val;
901                 char *endptr, *tmp;
902
903                 pos = os_strstr(pos, " neighbor=");
904                 if (!pos)
905                         break;
906                 if (nei_pos + 15 > nei_rep + sizeof(nei_rep)) {
907                         wpa_printf(MSG_DEBUG,
908                                    "Not enough room for additional neighbor");
909                         return -1;
910                 }
911                 pos += 10;
912
913                 nei_start = nei_pos;
914                 *nei_pos++ = WLAN_EID_NEIGHBOR_REPORT;
915                 nei_pos++; /* length to be filled in */
916
917                 if (hwaddr_aton(pos, nei_pos)) {
918                         wpa_printf(MSG_DEBUG, "Invalid BSSID");
919                         return -1;
920                 }
921                 nei_pos += ETH_ALEN;
922                 pos += 17;
923                 if (*pos != ',') {
924                         wpa_printf(MSG_DEBUG, "Missing BSSID Information");
925                         return -1;
926                 }
927                 pos++;
928
929                 val = strtol(pos, &endptr, 0);
930                 WPA_PUT_LE32(nei_pos, val);
931                 nei_pos += 4;
932                 if (*endptr != ',') {
933                         wpa_printf(MSG_DEBUG, "Missing Operating Class");
934                         return -1;
935                 }
936                 pos = endptr + 1;
937
938                 *nei_pos++ = atoi(pos); /* Operating Class */
939                 pos = os_strchr(pos, ',');
940                 if (pos == NULL) {
941                         wpa_printf(MSG_DEBUG, "Missing Channel Number");
942                         return -1;
943                 }
944                 pos++;
945
946                 *nei_pos++ = atoi(pos); /* Channel Number */
947                 pos = os_strchr(pos, ',');
948                 if (pos == NULL) {
949                         wpa_printf(MSG_DEBUG, "Missing PHY Type");
950                         return -1;
951                 }
952                 pos++;
953
954                 *nei_pos++ = atoi(pos); /* PHY Type */
955                 end = os_strchr(pos, ' ');
956                 tmp = os_strchr(pos, ',');
957                 if (tmp && (!end || tmp < end)) {
958                         /* Optional Subelements (hexdump) */
959                         size_t len;
960
961                         pos = tmp + 1;
962                         end = os_strchr(pos, ' ');
963                         if (end)
964                                 len = end - pos;
965                         else
966                                 len = os_strlen(pos);
967                         if (nei_pos + len / 2 > nei_rep + sizeof(nei_rep)) {
968                                 wpa_printf(MSG_DEBUG,
969                                            "Not enough room for neighbor subelements");
970                                 return -1;
971                         }
972                         if (len & 0x01 ||
973                             hexstr2bin(pos, nei_pos, len / 2) < 0) {
974                                 wpa_printf(MSG_DEBUG,
975                                            "Invalid neighbor subelement info");
976                                 return -1;
977                         }
978                         nei_pos += len / 2;
979                         pos = end;
980                 }
981
982                 nei_start[1] = nei_pos - nei_start - 2;
983         }
984
985         pos = os_strstr(cmd, " url=");
986         if (pos) {
987                 size_t len;
988                 pos += 5;
989                 end = os_strchr(pos, ' ');
990                 if (end)
991                         len = end - pos;
992                 else
993                         len = os_strlen(pos);
994                 url = os_malloc(len + 1);
995                 if (url == NULL)
996                         return -1;
997                 os_memcpy(url, pos, len);
998                 url[len] = '\0';
999                 req_mode |= WNM_BSS_TM_REQ_ESS_DISASSOC_IMMINENT;
1000         }
1001
1002         if (os_strstr(cmd, " pref=1"))
1003                 req_mode |= WNM_BSS_TM_REQ_PREF_CAND_LIST_INCLUDED;
1004         if (os_strstr(cmd, " abridged=1"))
1005                 req_mode |= WNM_BSS_TM_REQ_ABRIDGED;
1006         if (os_strstr(cmd, " disassoc_imminent=1"))
1007                 req_mode |= WNM_BSS_TM_REQ_DISASSOC_IMMINENT;
1008
1009 #ifdef CONFIG_MBO
1010         pos = os_strstr(cmd, "mbo=");
1011         if (pos) {
1012                 unsigned int mbo_reason, cell_pref, reassoc_delay;
1013                 u8 *mbo_pos = mbo;
1014
1015                 ret = sscanf(pos, "mbo=%u:%u:%u", &mbo_reason,
1016                              &reassoc_delay, &cell_pref);
1017                 if (ret != 3) {
1018                         wpa_printf(MSG_DEBUG,
1019                                    "MBO requires three arguments: mbo=<reason>:<reassoc_delay>:<cell_pref>");
1020                         return -1;
1021                 }
1022
1023                 if (mbo_reason > MBO_TRANSITION_REASON_PREMIUM_AP) {
1024                         wpa_printf(MSG_DEBUG,
1025                                    "Invalid MBO transition reason code %u",
1026                                    mbo_reason);
1027                         return -1;
1028                 }
1029
1030                 /* Valid values for Cellular preference are: 0, 1, 255 */
1031                 if (cell_pref != 0 && cell_pref != 1 && cell_pref != 255) {
1032                         wpa_printf(MSG_DEBUG,
1033                                    "Invalid MBO cellular capability %u",
1034                                    cell_pref);
1035                         return -1;
1036                 }
1037
1038                 if (reassoc_delay > 65535 ||
1039                     (reassoc_delay &&
1040                      !(req_mode & WNM_BSS_TM_REQ_DISASSOC_IMMINENT))) {
1041                         wpa_printf(MSG_DEBUG,
1042                                    "MBO: Assoc retry delay is only valid in disassoc imminent mode");
1043                         return -1;
1044                 }
1045
1046                 *mbo_pos++ = MBO_ATTR_ID_TRANSITION_REASON;
1047                 *mbo_pos++ = 1;
1048                 *mbo_pos++ = mbo_reason;
1049                 *mbo_pos++ = MBO_ATTR_ID_CELL_DATA_PREF;
1050                 *mbo_pos++ = 1;
1051                 *mbo_pos++ = cell_pref;
1052
1053                 if (reassoc_delay) {
1054                         *mbo_pos++ = MBO_ATTR_ID_ASSOC_RETRY_DELAY;
1055                         *mbo_pos++ = 2;
1056                         WPA_PUT_LE16(mbo_pos, reassoc_delay);
1057                         mbo_pos += 2;
1058                 }
1059
1060                 mbo_len = mbo_pos - mbo;
1061         }
1062 #endif /* CONFIG_MBO */
1063
1064         ret = wnm_send_bss_tm_req(hapd, sta, req_mode, disassoc_timer,
1065                                   valid_int, bss_term_dur, url,
1066                                   nei_pos > nei_rep ? nei_rep : NULL,
1067                                   nei_pos - nei_rep, mbo_len ? mbo : NULL,
1068                                   mbo_len);
1069         os_free(url);
1070         return ret;
1071 }
1072
1073 #endif /* CONFIG_WNM */
1074
1075
1076 static int hostapd_ctrl_iface_get_key_mgmt(struct hostapd_data *hapd,
1077                                            char *buf, size_t buflen)
1078 {
1079         int ret = 0;
1080         char *pos, *end;
1081
1082         pos = buf;
1083         end = buf + buflen;
1084
1085         WPA_ASSERT(hapd->conf->wpa_key_mgmt);
1086
1087         if (hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_PSK) {
1088                 ret = os_snprintf(pos, end - pos, "WPA-PSK ");
1089                 if (os_snprintf_error(end - pos, ret))
1090                         return pos - buf;
1091                 pos += ret;
1092         }
1093         if (hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_IEEE8021X) {
1094                 ret = os_snprintf(pos, end - pos, "WPA-EAP ");
1095                 if (os_snprintf_error(end - pos, ret))
1096                         return pos - buf;
1097                 pos += ret;
1098         }
1099 #ifdef CONFIG_IEEE80211R
1100         if (hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_FT_PSK) {
1101                 ret = os_snprintf(pos, end - pos, "FT-PSK ");
1102                 if (os_snprintf_error(end - pos, ret))
1103                         return pos - buf;
1104                 pos += ret;
1105         }
1106         if (hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_FT_IEEE8021X) {
1107                 ret = os_snprintf(pos, end - pos, "FT-EAP ");
1108                 if (os_snprintf_error(end - pos, ret))
1109                         return pos - buf;
1110                 pos += ret;
1111         }
1112 #ifdef CONFIG_SAE
1113         if (hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_FT_SAE) {
1114                 ret = os_snprintf(pos, end - pos, "FT-SAE ");
1115                 if (os_snprintf_error(end - pos, ret))
1116                         return pos - buf;
1117                 pos += ret;
1118         }
1119 #endif /* CONFIG_SAE */
1120 #endif /* CONFIG_IEEE80211R */
1121 #ifdef CONFIG_IEEE80211W
1122         if (hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_PSK_SHA256) {
1123                 ret = os_snprintf(pos, end - pos, "WPA-PSK-SHA256 ");
1124                 if (os_snprintf_error(end - pos, ret))
1125                         return pos - buf;
1126                 pos += ret;
1127         }
1128         if (hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_IEEE8021X_SHA256) {
1129                 ret = os_snprintf(pos, end - pos, "WPA-EAP-SHA256 ");
1130                 if (os_snprintf_error(end - pos, ret))
1131                         return pos - buf;
1132                 pos += ret;
1133         }
1134 #endif /* CONFIG_IEEE80211W */
1135 #ifdef CONFIG_SAE
1136         if (hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_SAE) {
1137                 ret = os_snprintf(pos, end - pos, "SAE ");
1138                 if (os_snprintf_error(end - pos, ret))
1139                         return pos - buf;
1140                 pos += ret;
1141         }
1142 #endif /* CONFIG_SAE */
1143         if (hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_IEEE8021X_SUITE_B) {
1144                 ret = os_snprintf(pos, end - pos, "WPA-EAP-SUITE-B ");
1145                 if (os_snprintf_error(end - pos, ret))
1146                         return pos - buf;
1147                 pos += ret;
1148         }
1149         if (hapd->conf->wpa_key_mgmt &
1150             WPA_KEY_MGMT_IEEE8021X_SUITE_B_192) {
1151                 ret = os_snprintf(pos, end - pos,
1152                                   "WPA-EAP-SUITE-B-192 ");
1153                 if (os_snprintf_error(end - pos, ret))
1154                         return pos - buf;
1155                 pos += ret;
1156         }
1157
1158         if (pos > buf && *(pos - 1) == ' ') {
1159                 *(pos - 1) = '\0';
1160                 pos--;
1161         }
1162
1163         return pos - buf;
1164 }
1165
1166
1167 static int hostapd_ctrl_iface_get_config(struct hostapd_data *hapd,
1168                                          char *buf, size_t buflen)
1169 {
1170         int ret;
1171         char *pos, *end;
1172
1173         pos = buf;
1174         end = buf + buflen;
1175
1176         ret = os_snprintf(pos, end - pos, "bssid=" MACSTR "\n"
1177                           "ssid=%s\n",
1178                           MAC2STR(hapd->own_addr),
1179                           wpa_ssid_txt(hapd->conf->ssid.ssid,
1180                                        hapd->conf->ssid.ssid_len));
1181         if (os_snprintf_error(end - pos, ret))
1182                 return pos - buf;
1183         pos += ret;
1184
1185 #ifdef CONFIG_WPS
1186         ret = os_snprintf(pos, end - pos, "wps_state=%s\n",
1187                           hapd->conf->wps_state == 0 ? "disabled" :
1188                           (hapd->conf->wps_state == 1 ? "not configured" :
1189                            "configured"));
1190         if (os_snprintf_error(end - pos, ret))
1191                 return pos - buf;
1192         pos += ret;
1193
1194         if (hapd->conf->wps_state && hapd->conf->wpa &&
1195             hapd->conf->ssid.wpa_passphrase) {
1196                 ret = os_snprintf(pos, end - pos, "passphrase=%s\n",
1197                                   hapd->conf->ssid.wpa_passphrase);
1198                 if (os_snprintf_error(end - pos, ret))
1199                         return pos - buf;
1200                 pos += ret;
1201         }
1202
1203         if (hapd->conf->wps_state && hapd->conf->wpa &&
1204             hapd->conf->ssid.wpa_psk &&
1205             hapd->conf->ssid.wpa_psk->group) {
1206                 char hex[PMK_LEN * 2 + 1];
1207                 wpa_snprintf_hex(hex, sizeof(hex),
1208                                  hapd->conf->ssid.wpa_psk->psk, PMK_LEN);
1209                 ret = os_snprintf(pos, end - pos, "psk=%s\n", hex);
1210                 if (os_snprintf_error(end - pos, ret))
1211                         return pos - buf;
1212                 pos += ret;
1213         }
1214 #endif /* CONFIG_WPS */
1215
1216         if (hapd->conf->wpa) {
1217                 ret = os_snprintf(pos, end - pos, "wpa=%d\n", hapd->conf->wpa);
1218                 if (os_snprintf_error(end - pos, ret))
1219                         return pos - buf;
1220                 pos += ret;
1221         }
1222
1223         if (hapd->conf->wpa && hapd->conf->wpa_key_mgmt) {
1224                 ret = os_snprintf(pos, end - pos, "key_mgmt=");
1225                 if (os_snprintf_error(end - pos, ret))
1226                         return pos - buf;
1227                 pos += ret;
1228
1229                 pos += hostapd_ctrl_iface_get_key_mgmt(hapd, pos, end - pos);
1230
1231                 ret = os_snprintf(pos, end - pos, "\n");
1232                 if (os_snprintf_error(end - pos, ret))
1233                         return pos - buf;
1234                 pos += ret;
1235         }
1236
1237         if (hapd->conf->wpa) {
1238                 ret = os_snprintf(pos, end - pos, "group_cipher=%s\n",
1239                                   wpa_cipher_txt(hapd->conf->wpa_group));
1240                 if (os_snprintf_error(end - pos, ret))
1241                         return pos - buf;
1242                 pos += ret;
1243         }
1244
1245         if ((hapd->conf->wpa & WPA_PROTO_RSN) && hapd->conf->rsn_pairwise) {
1246                 ret = os_snprintf(pos, end - pos, "rsn_pairwise_cipher=");
1247                 if (os_snprintf_error(end - pos, ret))
1248                         return pos - buf;
1249                 pos += ret;
1250
1251                 ret = wpa_write_ciphers(pos, end, hapd->conf->rsn_pairwise,
1252                                         " ");
1253                 if (ret < 0)
1254                         return pos - buf;
1255                 pos += ret;
1256
1257                 ret = os_snprintf(pos, end - pos, "\n");
1258                 if (os_snprintf_error(end - pos, ret))
1259                         return pos - buf;
1260                 pos += ret;
1261         }
1262
1263         if ((hapd->conf->wpa & WPA_PROTO_WPA) && hapd->conf->wpa_pairwise) {
1264                 ret = os_snprintf(pos, end - pos, "wpa_pairwise_cipher=");
1265                 if (os_snprintf_error(end - pos, ret))
1266                         return pos - buf;
1267                 pos += ret;
1268
1269                 ret = wpa_write_ciphers(pos, end, hapd->conf->wpa_pairwise,
1270                                         " ");
1271                 if (ret < 0)
1272                         return pos - buf;
1273                 pos += ret;
1274
1275                 ret = os_snprintf(pos, end - pos, "\n");
1276                 if (os_snprintf_error(end - pos, ret))
1277                         return pos - buf;
1278                 pos += ret;
1279         }
1280
1281         return pos - buf;
1282 }
1283
1284
1285 static int hostapd_ctrl_iface_set(struct hostapd_data *hapd, char *cmd)
1286 {
1287         char *value;
1288         int ret = 0;
1289
1290         value = os_strchr(cmd, ' ');
1291         if (value == NULL)
1292                 return -1;
1293         *value++ = '\0';
1294
1295         wpa_printf(MSG_DEBUG, "CTRL_IFACE SET '%s'='%s'", cmd, value);
1296         if (0) {
1297 #ifdef CONFIG_WPS_TESTING
1298         } else if (os_strcasecmp(cmd, "wps_version_number") == 0) {
1299                 long int val;
1300                 val = strtol(value, NULL, 0);
1301                 if (val < 0 || val > 0xff) {
1302                         ret = -1;
1303                         wpa_printf(MSG_DEBUG, "WPS: Invalid "
1304                                    "wps_version_number %ld", val);
1305                 } else {
1306                         wps_version_number = val;
1307                         wpa_printf(MSG_DEBUG, "WPS: Testing - force WPS "
1308                                    "version %u.%u",
1309                                    (wps_version_number & 0xf0) >> 4,
1310                                    wps_version_number & 0x0f);
1311                         hostapd_wps_update_ie(hapd);
1312                 }
1313         } else if (os_strcasecmp(cmd, "wps_testing_dummy_cred") == 0) {
1314                 wps_testing_dummy_cred = atoi(value);
1315                 wpa_printf(MSG_DEBUG, "WPS: Testing - dummy_cred=%d",
1316                            wps_testing_dummy_cred);
1317         } else if (os_strcasecmp(cmd, "wps_corrupt_pkhash") == 0) {
1318                 wps_corrupt_pkhash = atoi(value);
1319                 wpa_printf(MSG_DEBUG, "WPS: Testing - wps_corrupt_pkhash=%d",
1320                            wps_corrupt_pkhash);
1321 #endif /* CONFIG_WPS_TESTING */
1322 #ifdef CONFIG_INTERWORKING
1323         } else if (os_strcasecmp(cmd, "gas_frag_limit") == 0) {
1324                 int val = atoi(value);
1325                 if (val <= 0)
1326                         ret = -1;
1327                 else
1328                         hapd->gas_frag_limit = val;
1329 #endif /* CONFIG_INTERWORKING */
1330 #ifdef CONFIG_TESTING_OPTIONS
1331         } else if (os_strcasecmp(cmd, "ext_mgmt_frame_handling") == 0) {
1332                 hapd->ext_mgmt_frame_handling = atoi(value);
1333         } else if (os_strcasecmp(cmd, "ext_eapol_frame_io") == 0) {
1334                 hapd->ext_eapol_frame_io = atoi(value);
1335 #endif /* CONFIG_TESTING_OPTIONS */
1336 #ifdef CONFIG_MBO
1337         } else if (os_strcasecmp(cmd, "mbo_assoc_disallow") == 0) {
1338                 int val;
1339
1340                 if (!hapd->conf->mbo_enabled)
1341                         return -1;
1342
1343                 val = atoi(value);
1344                 if (val < 0 || val > 1)
1345                         return -1;
1346
1347                 hapd->mbo_assoc_disallow = val;
1348                 ieee802_11_update_beacons(hapd->iface);
1349
1350                 /*
1351                  * TODO: Need to configure drivers that do AP MLME offload with
1352                  * disallowing station logic.
1353                  */
1354 #endif /* CONFIG_MBO */
1355         } else {
1356                 struct sta_info *sta;
1357                 struct vlan_description vlan_id;
1358
1359                 ret = hostapd_set_iface(hapd->iconf, hapd->conf, cmd, value);
1360                 if (ret)
1361                         return ret;
1362
1363                 if (os_strcasecmp(cmd, "deny_mac_file") == 0) {
1364                         for (sta = hapd->sta_list; sta; sta = sta->next) {
1365                                 if (hostapd_maclist_found(
1366                                             hapd->conf->deny_mac,
1367                                             hapd->conf->num_deny_mac, sta->addr,
1368                                             &vlan_id) &&
1369                                     (!vlan_id.notempty ||
1370                                      !vlan_compare(&vlan_id, sta->vlan_desc)))
1371                                         ap_sta_disconnect(
1372                                                 hapd, sta, sta->addr,
1373                                                 WLAN_REASON_UNSPECIFIED);
1374                         }
1375                 } else if (hapd->conf->macaddr_acl == DENY_UNLESS_ACCEPTED &&
1376                            os_strcasecmp(cmd, "accept_mac_file") == 0) {
1377                         for (sta = hapd->sta_list; sta; sta = sta->next) {
1378                                 if (!hostapd_maclist_found(
1379                                             hapd->conf->accept_mac,
1380                                             hapd->conf->num_accept_mac,
1381                                             sta->addr, &vlan_id) ||
1382                                     (vlan_id.notempty &&
1383                                      vlan_compare(&vlan_id, sta->vlan_desc)))
1384                                         ap_sta_disconnect(
1385                                                 hapd, sta, sta->addr,
1386                                                 WLAN_REASON_UNSPECIFIED);
1387                         }
1388                 }
1389         }
1390
1391         return ret;
1392 }
1393
1394
1395 static int hostapd_ctrl_iface_get(struct hostapd_data *hapd, char *cmd,
1396                                   char *buf, size_t buflen)
1397 {
1398         int res;
1399
1400         wpa_printf(MSG_DEBUG, "CTRL_IFACE GET '%s'", cmd);
1401
1402         if (os_strcmp(cmd, "version") == 0) {
1403                 res = os_snprintf(buf, buflen, "%s", VERSION_STR);
1404                 if (os_snprintf_error(buflen, res))
1405                         return -1;
1406                 return res;
1407         } else if (os_strcmp(cmd, "tls_library") == 0) {
1408                 res = tls_get_library_version(buf, buflen);
1409                 if (os_snprintf_error(buflen, res))
1410                         return -1;
1411                 return res;
1412         }
1413
1414         return -1;
1415 }
1416
1417
1418 static int hostapd_ctrl_iface_enable(struct hostapd_iface *iface)
1419 {
1420         if (hostapd_enable_iface(iface) < 0) {
1421                 wpa_printf(MSG_ERROR, "Enabling of interface failed");
1422                 return -1;
1423         }
1424         return 0;
1425 }
1426
1427
1428 static int hostapd_ctrl_iface_reload(struct hostapd_iface *iface)
1429 {
1430         if (hostapd_reload_iface(iface) < 0) {
1431                 wpa_printf(MSG_ERROR, "Reloading of interface failed");
1432                 return -1;
1433         }
1434         return 0;
1435 }
1436
1437
1438 static int hostapd_ctrl_iface_disable(struct hostapd_iface *iface)
1439 {
1440         if (hostapd_disable_iface(iface) < 0) {
1441                 wpa_printf(MSG_ERROR, "Disabling of interface failed");
1442                 return -1;
1443         }
1444         return 0;
1445 }
1446
1447
1448 #ifdef CONFIG_TESTING_OPTIONS
1449
1450 static int hostapd_ctrl_iface_radar(struct hostapd_data *hapd, char *cmd)
1451 {
1452         union wpa_event_data data;
1453         char *pos, *param;
1454         enum wpa_event_type event;
1455
1456         wpa_printf(MSG_DEBUG, "RADAR TEST: %s", cmd);
1457
1458         os_memset(&data, 0, sizeof(data));
1459
1460         param = os_strchr(cmd, ' ');
1461         if (param == NULL)
1462                 return -1;
1463         *param++ = '\0';
1464
1465         if (os_strcmp(cmd, "DETECTED") == 0)
1466                 event = EVENT_DFS_RADAR_DETECTED;
1467         else if (os_strcmp(cmd, "CAC-FINISHED") == 0)
1468                 event = EVENT_DFS_CAC_FINISHED;
1469         else if (os_strcmp(cmd, "CAC-ABORTED") == 0)
1470                 event = EVENT_DFS_CAC_ABORTED;
1471         else if (os_strcmp(cmd, "NOP-FINISHED") == 0)
1472                 event = EVENT_DFS_NOP_FINISHED;
1473         else {
1474                 wpa_printf(MSG_DEBUG, "Unsupported RADAR test command: %s",
1475                            cmd);
1476                 return -1;
1477         }
1478
1479         pos = os_strstr(param, "freq=");
1480         if (pos)
1481                 data.dfs_event.freq = atoi(pos + 5);
1482
1483         pos = os_strstr(param, "ht_enabled=1");
1484         if (pos)
1485                 data.dfs_event.ht_enabled = 1;
1486
1487         pos = os_strstr(param, "chan_offset=");
1488         if (pos)
1489                 data.dfs_event.chan_offset = atoi(pos + 12);
1490
1491         pos = os_strstr(param, "chan_width=");
1492         if (pos)
1493                 data.dfs_event.chan_width = atoi(pos + 11);
1494
1495         pos = os_strstr(param, "cf1=");
1496         if (pos)
1497                 data.dfs_event.cf1 = atoi(pos + 4);
1498
1499         pos = os_strstr(param, "cf2=");
1500         if (pos)
1501                 data.dfs_event.cf2 = atoi(pos + 4);
1502
1503         wpa_supplicant_event(hapd, event, &data);
1504
1505         return 0;
1506 }
1507
1508
1509 static int hostapd_ctrl_iface_mgmt_tx(struct hostapd_data *hapd, char *cmd)
1510 {
1511         size_t len;
1512         u8 *buf;
1513         int res;
1514
1515         wpa_printf(MSG_DEBUG, "External MGMT TX: %s", cmd);
1516
1517         len = os_strlen(cmd);
1518         if (len & 1)
1519                 return -1;
1520         len /= 2;
1521
1522         buf = os_malloc(len);
1523         if (buf == NULL)
1524                 return -1;
1525
1526         if (hexstr2bin(cmd, buf, len) < 0) {
1527                 os_free(buf);
1528                 return -1;
1529         }
1530
1531         res = hostapd_drv_send_mlme(hapd, buf, len, 0);
1532         os_free(buf);
1533         return res;
1534 }
1535
1536
1537 static int hostapd_ctrl_iface_eapol_rx(struct hostapd_data *hapd, char *cmd)
1538 {
1539         char *pos;
1540         u8 src[ETH_ALEN], *buf;
1541         int used;
1542         size_t len;
1543
1544         wpa_printf(MSG_DEBUG, "External EAPOL RX: %s", cmd);
1545
1546         pos = cmd;
1547         used = hwaddr_aton2(pos, src);
1548         if (used < 0)
1549                 return -1;
1550         pos += used;
1551         while (*pos == ' ')
1552                 pos++;
1553
1554         len = os_strlen(pos);
1555         if (len & 1)
1556                 return -1;
1557         len /= 2;
1558
1559         buf = os_malloc(len);
1560         if (buf == NULL)
1561                 return -1;
1562
1563         if (hexstr2bin(pos, buf, len) < 0) {
1564                 os_free(buf);
1565                 return -1;
1566         }
1567
1568         ieee802_1x_receive(hapd, src, buf, len);
1569         os_free(buf);
1570
1571         return 0;
1572 }
1573
1574
1575 static u16 ipv4_hdr_checksum(const void *buf, size_t len)
1576 {
1577         size_t i;
1578         u32 sum = 0;
1579         const u16 *pos = buf;
1580
1581         for (i = 0; i < len / 2; i++)
1582                 sum += *pos++;
1583
1584         while (sum >> 16)
1585                 sum = (sum & 0xffff) + (sum >> 16);
1586
1587         return sum ^ 0xffff;
1588 }
1589
1590
1591 #define HWSIM_PACKETLEN 1500
1592 #define HWSIM_IP_LEN (HWSIM_PACKETLEN - sizeof(struct ether_header))
1593
1594 void hostapd_data_test_rx(void *ctx, const u8 *src_addr, const u8 *buf,
1595                           size_t len)
1596 {
1597         struct hostapd_data *hapd = ctx;
1598         const struct ether_header *eth;
1599         struct iphdr ip;
1600         const u8 *pos;
1601         unsigned int i;
1602
1603         if (len != HWSIM_PACKETLEN)
1604                 return;
1605
1606         eth = (const struct ether_header *) buf;
1607         os_memcpy(&ip, eth + 1, sizeof(ip));
1608         pos = &buf[sizeof(*eth) + sizeof(ip)];
1609
1610         if (ip.ihl != 5 || ip.version != 4 ||
1611             ntohs(ip.tot_len) != HWSIM_IP_LEN)
1612                 return;
1613
1614         for (i = 0; i < HWSIM_IP_LEN - sizeof(ip); i++) {
1615                 if (*pos != (u8) i)
1616                         return;
1617                 pos++;
1618         }
1619
1620         wpa_msg(hapd->msg_ctx, MSG_INFO, "DATA-TEST-RX " MACSTR " " MACSTR,
1621                 MAC2STR(eth->ether_dhost), MAC2STR(eth->ether_shost));
1622 }
1623
1624
1625 static int hostapd_ctrl_iface_data_test_config(struct hostapd_data *hapd,
1626                                                char *cmd)
1627 {
1628         int enabled = atoi(cmd);
1629         char *pos;
1630         const char *ifname;
1631
1632         if (!enabled) {
1633                 if (hapd->l2_test) {
1634                         l2_packet_deinit(hapd->l2_test);
1635                         hapd->l2_test = NULL;
1636                         wpa_dbg(hapd->msg_ctx, MSG_DEBUG,
1637                                 "test data: Disabled");
1638                 }
1639                 return 0;
1640         }
1641
1642         if (hapd->l2_test)
1643                 return 0;
1644
1645         pos = os_strstr(cmd, " ifname=");
1646         if (pos)
1647                 ifname = pos + 8;
1648         else
1649                 ifname = hapd->conf->iface;
1650
1651         hapd->l2_test = l2_packet_init(ifname, hapd->own_addr,
1652                                         ETHERTYPE_IP, hostapd_data_test_rx,
1653                                         hapd, 1);
1654         if (hapd->l2_test == NULL)
1655                 return -1;
1656
1657         wpa_dbg(hapd->msg_ctx, MSG_DEBUG, "test data: Enabled");
1658
1659         return 0;
1660 }
1661
1662
1663 static int hostapd_ctrl_iface_data_test_tx(struct hostapd_data *hapd, char *cmd)
1664 {
1665         u8 dst[ETH_ALEN], src[ETH_ALEN];
1666         char *pos;
1667         int used;
1668         long int val;
1669         u8 tos;
1670         u8 buf[2 + HWSIM_PACKETLEN];
1671         struct ether_header *eth;
1672         struct iphdr *ip;
1673         u8 *dpos;
1674         unsigned int i;
1675
1676         if (hapd->l2_test == NULL)
1677                 return -1;
1678
1679         /* format: <dst> <src> <tos> */
1680
1681         pos = cmd;
1682         used = hwaddr_aton2(pos, dst);
1683         if (used < 0)
1684                 return -1;
1685         pos += used;
1686         while (*pos == ' ')
1687                 pos++;
1688         used = hwaddr_aton2(pos, src);
1689         if (used < 0)
1690                 return -1;
1691         pos += used;
1692
1693         val = strtol(pos, NULL, 0);
1694         if (val < 0 || val > 0xff)
1695                 return -1;
1696         tos = val;
1697
1698         eth = (struct ether_header *) &buf[2];
1699         os_memcpy(eth->ether_dhost, dst, ETH_ALEN);
1700         os_memcpy(eth->ether_shost, src, ETH_ALEN);
1701         eth->ether_type = htons(ETHERTYPE_IP);
1702         ip = (struct iphdr *) (eth + 1);
1703         os_memset(ip, 0, sizeof(*ip));
1704         ip->ihl = 5;
1705         ip->version = 4;
1706         ip->ttl = 64;
1707         ip->tos = tos;
1708         ip->tot_len = htons(HWSIM_IP_LEN);
1709         ip->protocol = 1;
1710         ip->saddr = htonl(192U << 24 | 168 << 16 | 1 << 8 | 1);
1711         ip->daddr = htonl(192U << 24 | 168 << 16 | 1 << 8 | 2);
1712         ip->check = ipv4_hdr_checksum(ip, sizeof(*ip));
1713         dpos = (u8 *) (ip + 1);
1714         for (i = 0; i < HWSIM_IP_LEN - sizeof(*ip); i++)
1715                 *dpos++ = i;
1716
1717         if (l2_packet_send(hapd->l2_test, dst, ETHERTYPE_IP, &buf[2],
1718                            HWSIM_PACKETLEN) < 0)
1719                 return -1;
1720
1721         wpa_dbg(hapd->msg_ctx, MSG_DEBUG, "test data: TX dst=" MACSTR
1722                 " src=" MACSTR " tos=0x%x", MAC2STR(dst), MAC2STR(src), tos);
1723
1724         return 0;
1725 }
1726
1727
1728 static int hostapd_ctrl_iface_data_test_frame(struct hostapd_data *hapd,
1729                                               char *cmd)
1730 {
1731         u8 *buf;
1732         struct ether_header *eth;
1733         struct l2_packet_data *l2 = NULL;
1734         size_t len;
1735         u16 ethertype;
1736         int res = -1;
1737         const char *ifname = hapd->conf->iface;
1738
1739         if (os_strncmp(cmd, "ifname=", 7) == 0) {
1740                 cmd += 7;
1741                 ifname = cmd;
1742                 cmd = os_strchr(cmd, ' ');
1743                 if (cmd == NULL)
1744                         return -1;
1745                 *cmd++ = '\0';
1746         }
1747
1748         len = os_strlen(cmd);
1749         if (len & 1 || len < ETH_HLEN * 2)
1750                 return -1;
1751         len /= 2;
1752
1753         buf = os_malloc(len);
1754         if (buf == NULL)
1755                 return -1;
1756
1757         if (hexstr2bin(cmd, buf, len) < 0)
1758                 goto done;
1759
1760         eth = (struct ether_header *) buf;
1761         ethertype = ntohs(eth->ether_type);
1762
1763         l2 = l2_packet_init(ifname, hapd->own_addr, ethertype,
1764                             hostapd_data_test_rx, hapd, 1);
1765         if (l2 == NULL)
1766                 goto done;
1767
1768         res = l2_packet_send(l2, eth->ether_dhost, ethertype, buf, len);
1769         wpa_dbg(hapd->msg_ctx, MSG_DEBUG, "test data: TX frame res=%d", res);
1770 done:
1771         if (l2)
1772                 l2_packet_deinit(l2);
1773         os_free(buf);
1774
1775         return res < 0 ? -1 : 0;
1776 }
1777
1778
1779 static int hostapd_ctrl_test_alloc_fail(struct hostapd_data *hapd, char *cmd)
1780 {
1781 #ifdef WPA_TRACE_BFD
1782         char *pos;
1783
1784         wpa_trace_fail_after = atoi(cmd);
1785         pos = os_strchr(cmd, ':');
1786         if (pos) {
1787                 pos++;
1788                 os_strlcpy(wpa_trace_fail_func, pos,
1789                            sizeof(wpa_trace_fail_func));
1790         } else {
1791                 wpa_trace_fail_after = 0;
1792         }
1793
1794         return 0;
1795 #else /* WPA_TRACE_BFD */
1796         return -1;
1797 #endif /* WPA_TRACE_BFD */
1798 }
1799
1800
1801 static int hostapd_ctrl_get_alloc_fail(struct hostapd_data *hapd,
1802                                        char *buf, size_t buflen)
1803 {
1804 #ifdef WPA_TRACE_BFD
1805         return os_snprintf(buf, buflen, "%u:%s", wpa_trace_fail_after,
1806                            wpa_trace_fail_func);
1807 #else /* WPA_TRACE_BFD */
1808         return -1;
1809 #endif /* WPA_TRACE_BFD */
1810 }
1811
1812
1813 static int hostapd_ctrl_test_fail(struct hostapd_data *hapd, char *cmd)
1814 {
1815 #ifdef WPA_TRACE_BFD
1816         char *pos;
1817
1818         wpa_trace_test_fail_after = atoi(cmd);
1819         pos = os_strchr(cmd, ':');
1820         if (pos) {
1821                 pos++;
1822                 os_strlcpy(wpa_trace_test_fail_func, pos,
1823                            sizeof(wpa_trace_test_fail_func));
1824         } else {
1825                 wpa_trace_test_fail_after = 0;
1826         }
1827
1828         return 0;
1829 #else /* WPA_TRACE_BFD */
1830         return -1;
1831 #endif /* WPA_TRACE_BFD */
1832 }
1833
1834
1835 static int hostapd_ctrl_get_fail(struct hostapd_data *hapd,
1836                                  char *buf, size_t buflen)
1837 {
1838 #ifdef WPA_TRACE_BFD
1839         return os_snprintf(buf, buflen, "%u:%s", wpa_trace_test_fail_after,
1840                            wpa_trace_test_fail_func);
1841 #else /* WPA_TRACE_BFD */
1842         return -1;
1843 #endif /* WPA_TRACE_BFD */
1844 }
1845
1846 #endif /* CONFIG_TESTING_OPTIONS */
1847
1848
1849 static int hostapd_ctrl_iface_chan_switch(struct hostapd_iface *iface,
1850                                           char *pos)
1851 {
1852 #ifdef NEED_AP_MLME
1853         struct csa_settings settings;
1854         int ret;
1855         unsigned int i;
1856
1857         ret = hostapd_parse_csa_settings(pos, &settings);
1858         if (ret)
1859                 return ret;
1860
1861         for (i = 0; i < iface->num_bss; i++) {
1862                 ret = hostapd_switch_channel(iface->bss[i], &settings);
1863                 if (ret) {
1864                         /* FIX: What do we do if CSA fails in the middle of
1865                          * submitting multi-BSS CSA requests? */
1866                         return ret;
1867                 }
1868         }
1869
1870         return 0;
1871 #else /* NEED_AP_MLME */
1872         return -1;
1873 #endif /* NEED_AP_MLME */
1874 }
1875
1876
1877 static int hostapd_ctrl_iface_mib(struct hostapd_data *hapd, char *reply,
1878                                   int reply_size, const char *param)
1879 {
1880 #ifdef RADIUS_SERVER
1881         if (os_strcmp(param, "radius_server") == 0) {
1882                 return radius_server_get_mib(hapd->radius_srv, reply,
1883                                              reply_size);
1884         }
1885 #endif /* RADIUS_SERVER */
1886         return -1;
1887 }
1888
1889
1890 static int hostapd_ctrl_iface_vendor(struct hostapd_data *hapd, char *cmd,
1891                                      char *buf, size_t buflen)
1892 {
1893         int ret;
1894         char *pos;
1895         u8 *data = NULL;
1896         unsigned int vendor_id, subcmd;
1897         struct wpabuf *reply;
1898         size_t data_len = 0;
1899
1900         /* cmd: <vendor id> <subcommand id> [<hex formatted data>] */
1901         vendor_id = strtoul(cmd, &pos, 16);
1902         if (!isblank((unsigned char) *pos))
1903                 return -EINVAL;
1904
1905         subcmd = strtoul(pos, &pos, 10);
1906
1907         if (*pos != '\0') {
1908                 if (!isblank((unsigned char) *pos++))
1909                         return -EINVAL;
1910                 data_len = os_strlen(pos);
1911         }
1912
1913         if (data_len) {
1914                 data_len /= 2;
1915                 data = os_malloc(data_len);
1916                 if (!data)
1917                         return -ENOBUFS;
1918
1919                 if (hexstr2bin(pos, data, data_len)) {
1920                         wpa_printf(MSG_DEBUG,
1921                                    "Vendor command: wrong parameter format");
1922                         os_free(data);
1923                         return -EINVAL;
1924                 }
1925         }
1926
1927         reply = wpabuf_alloc((buflen - 1) / 2);
1928         if (!reply) {
1929                 os_free(data);
1930                 return -ENOBUFS;
1931         }
1932
1933         ret = hostapd_drv_vendor_cmd(hapd, vendor_id, subcmd, data, data_len,
1934                                      reply);
1935
1936         if (ret == 0)
1937                 ret = wpa_snprintf_hex(buf, buflen, wpabuf_head_u8(reply),
1938                                        wpabuf_len(reply));
1939
1940         wpabuf_free(reply);
1941         os_free(data);
1942
1943         return ret;
1944 }
1945
1946
1947 static int hostapd_ctrl_iface_eapol_reauth(struct hostapd_data *hapd,
1948                                            const char *cmd)
1949 {
1950         u8 addr[ETH_ALEN];
1951         struct sta_info *sta;
1952
1953         if (hwaddr_aton(cmd, addr))
1954                 return -1;
1955
1956         sta = ap_get_sta(hapd, addr);
1957         if (!sta || !sta->eapol_sm)
1958                 return -1;
1959
1960         eapol_auth_reauthenticate(sta->eapol_sm);
1961         return 0;
1962 }
1963
1964
1965 static int hostapd_ctrl_iface_eapol_set(struct hostapd_data *hapd, char *cmd)
1966 {
1967         u8 addr[ETH_ALEN];
1968         struct sta_info *sta;
1969         char *pos = cmd, *param;
1970
1971         if (hwaddr_aton(pos, addr) || pos[17] != ' ')
1972                 return -1;
1973         pos += 18;
1974         param = pos;
1975         pos = os_strchr(pos, ' ');
1976         if (!pos)
1977                 return -1;
1978         *pos++ = '\0';
1979
1980         sta = ap_get_sta(hapd, addr);
1981         if (!sta || !sta->eapol_sm)
1982                 return -1;
1983
1984         return eapol_auth_set_conf(sta->eapol_sm, param, pos);
1985 }
1986
1987
1988 static int hostapd_ctrl_iface_log_level(struct hostapd_data *hapd, char *cmd,
1989                                         char *buf, size_t buflen)
1990 {
1991         char *pos, *end, *stamp;
1992         int ret;
1993
1994         /* cmd: "LOG_LEVEL [<level>]" */
1995         if (*cmd == '\0') {
1996                 pos = buf;
1997                 end = buf + buflen;
1998                 ret = os_snprintf(pos, end - pos, "Current level: %s\n"
1999                                   "Timestamp: %d\n",
2000                                   debug_level_str(wpa_debug_level),
2001                                   wpa_debug_timestamp);
2002                 if (os_snprintf_error(end - pos, ret))
2003                         ret = 0;
2004
2005                 return ret;
2006         }
2007
2008         while (*cmd == ' ')
2009                 cmd++;
2010
2011         stamp = os_strchr(cmd, ' ');
2012         if (stamp) {
2013                 *stamp++ = '\0';
2014                 while (*stamp == ' ') {
2015                         stamp++;
2016                 }
2017         }
2018
2019         if (os_strlen(cmd)) {
2020                 int level = str_to_debug_level(cmd);
2021                 if (level < 0)
2022                         return -1;
2023                 wpa_debug_level = level;
2024         }
2025
2026         if (stamp && os_strlen(stamp))
2027                 wpa_debug_timestamp = atoi(stamp);
2028
2029         os_memcpy(buf, "OK\n", 3);
2030         return 3;
2031 }
2032
2033
2034 #ifdef NEED_AP_MLME
2035 static int hostapd_ctrl_iface_track_sta_list(struct hostapd_data *hapd,
2036                                              char *buf, size_t buflen)
2037 {
2038         struct hostapd_iface *iface = hapd->iface;
2039         char *pos, *end;
2040         struct hostapd_sta_info *info;
2041         struct os_reltime now;
2042
2043         sta_track_expire(iface, 0);
2044
2045         pos = buf;
2046         end = buf + buflen;
2047
2048         os_get_reltime(&now);
2049         dl_list_for_each_reverse(info, &iface->sta_seen,
2050                                  struct hostapd_sta_info, list) {
2051                 struct os_reltime age;
2052                 int ret;
2053
2054                 os_reltime_sub(&now, &info->last_seen, &age);
2055                 ret = os_snprintf(pos, end - pos, MACSTR " %u\n",
2056                                   MAC2STR(info->addr), (unsigned int) age.sec);
2057                 if (os_snprintf_error(end - pos, ret))
2058                         break;
2059                 pos += ret;
2060         }
2061
2062         return pos - buf;
2063 }
2064 #endif /* NEED_AP_MLME */
2065
2066
2067 static int hostapd_ctrl_iface_req_lci(struct hostapd_data *hapd,
2068                                       const char *cmd)
2069 {
2070         u8 addr[ETH_ALEN];
2071
2072         if (hwaddr_aton(cmd, addr)) {
2073                 wpa_printf(MSG_INFO, "CTRL: REQ_LCI: Invalid MAC address");
2074                 return -1;
2075         }
2076
2077         return hostapd_send_lci_req(hapd, addr);
2078 }
2079
2080
2081 int hostapd_ctrl_iface_req_range(struct hostapd_data *hapd, char *cmd)
2082 {
2083         u8 addr[ETH_ALEN];
2084         char *token, *context = NULL;
2085         int random_interval, min_ap;
2086         u8 responders[ETH_ALEN * RRM_RANGE_REQ_MAX_RESPONDERS];
2087         unsigned int n_responders;
2088
2089         token = str_token(cmd, " ", &context);
2090         if (!token || hwaddr_aton(token, addr)) {
2091                 wpa_printf(MSG_INFO,
2092                            "CTRL: REQ_RANGE - Bad destination address");
2093                 return -1;
2094         }
2095
2096         token = str_token(cmd, " ", &context);
2097         if (!token)
2098                 return -1;
2099
2100         random_interval = atoi(token);
2101         if (random_interval < 0 || random_interval > 0xffff)
2102                 return -1;
2103
2104         token = str_token(cmd, " ", &context);
2105         if (!token)
2106                 return -1;
2107
2108         min_ap = atoi(token);
2109         if (min_ap <= 0 || min_ap > WLAN_RRM_RANGE_REQ_MAX_MIN_AP)
2110                 return -1;
2111
2112         n_responders = 0;
2113         while ((token = str_token(cmd, " ", &context))) {
2114                 if (n_responders == RRM_RANGE_REQ_MAX_RESPONDERS) {
2115                         wpa_printf(MSG_INFO,
2116                                    "CTRL: REQ_RANGE: Too many responders");
2117                         return -1;
2118                 }
2119
2120                 if (hwaddr_aton(token, responders + n_responders * ETH_ALEN)) {
2121                         wpa_printf(MSG_INFO,
2122                                    "CTRL: REQ_RANGE: Bad responder address");
2123                         return -1;
2124                 }
2125
2126                 n_responders++;
2127         }
2128
2129         if (!n_responders) {
2130                 wpa_printf(MSG_INFO,
2131                            "CTRL: REQ_RANGE - No FTM responder address");
2132                 return -1;
2133         }
2134
2135         return hostapd_send_range_req(hapd, addr, random_interval, min_ap,
2136                                       responders, n_responders);
2137 }
2138
2139
2140 static int hostapd_ctrl_iface_set_neighbor(struct hostapd_data *hapd, char *buf)
2141 {
2142         struct wpa_ssid_value ssid;
2143         u8 bssid[ETH_ALEN];
2144         struct wpabuf *nr, *lci = NULL, *civic = NULL;
2145         char *tmp;
2146         int ret;
2147
2148         if (!(hapd->conf->radio_measurements[0] &
2149               WLAN_RRM_CAPS_NEIGHBOR_REPORT)) {
2150                 wpa_printf(MSG_ERROR,
2151                            "CTRL: SET_NEIGHBOR: Neighbor report is not enabled");
2152                 return -1;
2153         }
2154
2155         if (hwaddr_aton(buf, bssid)) {
2156                 wpa_printf(MSG_ERROR, "CTRL: SET_NEIGHBOR: Bad BSSID");
2157                 return -1;
2158         }
2159
2160         tmp = os_strstr(buf, "ssid=");
2161         if (!tmp || ssid_parse(tmp + 5, &ssid)) {
2162                 wpa_printf(MSG_ERROR,
2163                            "CTRL: SET_NEIGHBOR: Bad or missing SSID");
2164                 return -1;
2165         }
2166         buf = os_strchr(tmp + 6, tmp[5] == '"' ? '"' : ' ');
2167         if (!buf)
2168                 return -1;
2169
2170         tmp = os_strstr(buf, "nr=");
2171         if (!tmp) {
2172                 wpa_printf(MSG_ERROR,
2173                            "CTRL: SET_NEIGHBOR: Missing Neighbor Report element");
2174                 return -1;
2175         }
2176
2177         buf = os_strchr(tmp, ' ');
2178         if (buf)
2179                 *buf++ = '\0';
2180
2181         nr = wpabuf_parse_bin(tmp + 3);
2182         if (!nr) {
2183                 wpa_printf(MSG_ERROR,
2184                            "CTRL: SET_NEIGHBOR: Bad Neighbor Report element");
2185                 return -1;
2186         }
2187
2188         if (!buf)
2189                 goto set;
2190
2191         tmp = os_strstr(buf, "lci=");
2192         if (tmp) {
2193                 buf = os_strchr(tmp, ' ');
2194                 if (buf)
2195                         *buf++ = '\0';
2196                 lci = wpabuf_parse_bin(tmp + 4);
2197                 if (!lci) {
2198                         wpa_printf(MSG_ERROR,
2199                                    "CTRL: SET_NEIGHBOR: Bad LCI subelement");
2200                         wpabuf_free(nr);
2201                         return -1;
2202                 }
2203         }
2204
2205         if (!buf)
2206                 goto set;
2207
2208         tmp = os_strstr(buf, "civic=");
2209         if (tmp) {
2210                 buf = os_strchr(tmp, ' ');
2211                 if (buf)
2212                         *buf++ = '\0';
2213                 civic = wpabuf_parse_bin(tmp + 6);
2214                 if (!civic) {
2215                         wpa_printf(MSG_ERROR,
2216                                    "CTRL: SET_NEIGHBOR: Bad civic subelement");
2217                         wpabuf_free(nr);
2218                         wpabuf_free(lci);
2219                         return -1;
2220                 }
2221         }
2222
2223 set:
2224         ret = hostapd_neighbor_set(hapd, bssid, &ssid, nr, lci, civic);
2225
2226         wpabuf_free(nr);
2227         wpabuf_free(lci);
2228         wpabuf_free(civic);
2229
2230         return ret;
2231 }
2232
2233
2234 static int hostapd_ctrl_iface_remove_neighbor(struct hostapd_data *hapd,
2235                                               char *buf)
2236 {
2237         struct wpa_ssid_value ssid;
2238         u8 bssid[ETH_ALEN];
2239         char *tmp;
2240
2241         if (hwaddr_aton(buf, bssid)) {
2242                 wpa_printf(MSG_ERROR, "CTRL: REMOVE_NEIGHBOR: Bad BSSID");
2243                 return -1;
2244         }
2245
2246         tmp = os_strstr(buf, "ssid=");
2247         if (!tmp || ssid_parse(tmp + 5, &ssid)) {
2248                 wpa_printf(MSG_ERROR,
2249                            "CTRL: REMOVE_NEIGHBORr: Bad or missing SSID");
2250                 return -1;
2251         }
2252
2253         return hostapd_neighbor_remove(hapd, bssid, &ssid);
2254 }
2255
2256
2257 static int hostapd_ctrl_iface_receive_process(struct hostapd_data *hapd,
2258                                               char *buf, char *reply,
2259                                               int reply_size,
2260                                               struct sockaddr_storage *from,
2261                                               socklen_t fromlen)
2262 {
2263         int reply_len, res;
2264
2265         os_memcpy(reply, "OK\n", 3);
2266         reply_len = 3;
2267
2268         if (os_strcmp(buf, "PING") == 0) {
2269                 os_memcpy(reply, "PONG\n", 5);
2270                 reply_len = 5;
2271         } else if (os_strncmp(buf, "RELOG", 5) == 0) {
2272                 if (wpa_debug_reopen_file() < 0)
2273                         reply_len = -1;
2274         } else if (os_strcmp(buf, "STATUS") == 0) {
2275                 reply_len = hostapd_ctrl_iface_status(hapd, reply,
2276                                                       reply_size);
2277         } else if (os_strcmp(buf, "STATUS-DRIVER") == 0) {
2278                 reply_len = hostapd_drv_status(hapd, reply, reply_size);
2279         } else if (os_strcmp(buf, "MIB") == 0) {
2280                 reply_len = ieee802_11_get_mib(hapd, reply, reply_size);
2281                 if (reply_len >= 0) {
2282                         res = wpa_get_mib(hapd->wpa_auth, reply + reply_len,
2283                                           reply_size - reply_len);
2284                         if (res < 0)
2285                                 reply_len = -1;
2286                         else
2287                                 reply_len += res;
2288                 }
2289                 if (reply_len >= 0) {
2290                         res = ieee802_1x_get_mib(hapd, reply + reply_len,
2291                                                  reply_size - reply_len);
2292                         if (res < 0)
2293                                 reply_len = -1;
2294                         else
2295                                 reply_len += res;
2296                 }
2297 #ifndef CONFIG_NO_RADIUS
2298                 if (reply_len >= 0) {
2299                         res = radius_client_get_mib(hapd->radius,
2300                                                     reply + reply_len,
2301                                                     reply_size - reply_len);
2302                         if (res < 0)
2303                                 reply_len = -1;
2304                         else
2305                                 reply_len += res;
2306                 }
2307 #endif /* CONFIG_NO_RADIUS */
2308         } else if (os_strncmp(buf, "MIB ", 4) == 0) {
2309                 reply_len = hostapd_ctrl_iface_mib(hapd, reply, reply_size,
2310                                                    buf + 4);
2311         } else if (os_strcmp(buf, "STA-FIRST") == 0) {
2312                 reply_len = hostapd_ctrl_iface_sta_first(hapd, reply,
2313                                                          reply_size);
2314         } else if (os_strncmp(buf, "STA ", 4) == 0) {
2315                 reply_len = hostapd_ctrl_iface_sta(hapd, buf + 4, reply,
2316                                                    reply_size);
2317         } else if (os_strncmp(buf, "STA-NEXT ", 9) == 0) {
2318                 reply_len = hostapd_ctrl_iface_sta_next(hapd, buf + 9, reply,
2319                                                         reply_size);
2320         } else if (os_strcmp(buf, "ATTACH") == 0) {
2321                 if (hostapd_ctrl_iface_attach(hapd, from, fromlen))
2322                         reply_len = -1;
2323         } else if (os_strcmp(buf, "DETACH") == 0) {
2324                 if (hostapd_ctrl_iface_detach(hapd, from, fromlen))
2325                         reply_len = -1;
2326         } else if (os_strncmp(buf, "LEVEL ", 6) == 0) {
2327                 if (hostapd_ctrl_iface_level(hapd, from, fromlen,
2328                                                     buf + 6))
2329                         reply_len = -1;
2330         } else if (os_strncmp(buf, "NEW_STA ", 8) == 0) {
2331                 if (hostapd_ctrl_iface_new_sta(hapd, buf + 8))
2332                         reply_len = -1;
2333         } else if (os_strncmp(buf, "DEAUTHENTICATE ", 15) == 0) {
2334                 if (hostapd_ctrl_iface_deauthenticate(hapd, buf + 15))
2335                         reply_len = -1;
2336         } else if (os_strncmp(buf, "DISASSOCIATE ", 13) == 0) {
2337                 if (hostapd_ctrl_iface_disassociate(hapd, buf + 13))
2338                         reply_len = -1;
2339         } else if (os_strncmp(buf, "POLL_STA ", 9) == 0) {
2340                 if (hostapd_ctrl_iface_poll_sta(hapd, buf + 9))
2341                         reply_len = -1;
2342         } else if (os_strcmp(buf, "STOP_AP") == 0) {
2343                 if (hostapd_ctrl_iface_stop_ap(hapd))
2344                         reply_len = -1;
2345 #ifdef CONFIG_IEEE80211W
2346 #ifdef NEED_AP_MLME
2347         } else if (os_strncmp(buf, "SA_QUERY ", 9) == 0) {
2348                 if (hostapd_ctrl_iface_sa_query(hapd, buf + 9))
2349                         reply_len = -1;
2350 #endif /* NEED_AP_MLME */
2351 #endif /* CONFIG_IEEE80211W */
2352 #ifdef CONFIG_WPS
2353         } else if (os_strncmp(buf, "WPS_PIN ", 8) == 0) {
2354                 if (hostapd_ctrl_iface_wps_pin(hapd, buf + 8))
2355                         reply_len = -1;
2356         } else if (os_strncmp(buf, "WPS_CHECK_PIN ", 14) == 0) {
2357                 reply_len = hostapd_ctrl_iface_wps_check_pin(
2358                         hapd, buf + 14, reply, reply_size);
2359         } else if (os_strcmp(buf, "WPS_PBC") == 0) {
2360                 if (hostapd_wps_button_pushed(hapd, NULL))
2361                         reply_len = -1;
2362         } else if (os_strcmp(buf, "WPS_CANCEL") == 0) {
2363                 if (hostapd_wps_cancel(hapd))
2364                         reply_len = -1;
2365         } else if (os_strncmp(buf, "WPS_AP_PIN ", 11) == 0) {
2366                 reply_len = hostapd_ctrl_iface_wps_ap_pin(hapd, buf + 11,
2367                                                           reply, reply_size);
2368         } else if (os_strncmp(buf, "WPS_CONFIG ", 11) == 0) {
2369                 if (hostapd_ctrl_iface_wps_config(hapd, buf + 11) < 0)
2370                         reply_len = -1;
2371         } else if (os_strncmp(buf, "WPS_GET_STATUS", 13) == 0) {
2372                 reply_len = hostapd_ctrl_iface_wps_get_status(hapd, reply,
2373                                                               reply_size);
2374 #ifdef CONFIG_WPS_NFC
2375         } else if (os_strncmp(buf, "WPS_NFC_TAG_READ ", 17) == 0) {
2376                 if (hostapd_ctrl_iface_wps_nfc_tag_read(hapd, buf + 17))
2377                         reply_len = -1;
2378         } else if (os_strncmp(buf, "WPS_NFC_CONFIG_TOKEN ", 21) == 0) {
2379                 reply_len = hostapd_ctrl_iface_wps_nfc_config_token(
2380                         hapd, buf + 21, reply, reply_size);
2381         } else if (os_strncmp(buf, "WPS_NFC_TOKEN ", 14) == 0) {
2382                 reply_len = hostapd_ctrl_iface_wps_nfc_token(
2383                         hapd, buf + 14, reply, reply_size);
2384         } else if (os_strncmp(buf, "NFC_GET_HANDOVER_SEL ", 21) == 0) {
2385                 reply_len = hostapd_ctrl_iface_nfc_get_handover_sel(
2386                         hapd, buf + 21, reply, reply_size);
2387         } else if (os_strncmp(buf, "NFC_REPORT_HANDOVER ", 20) == 0) {
2388                 if (hostapd_ctrl_iface_nfc_report_handover(hapd, buf + 20))
2389                         reply_len = -1;
2390 #endif /* CONFIG_WPS_NFC */
2391 #endif /* CONFIG_WPS */
2392 #ifdef CONFIG_INTERWORKING
2393         } else if (os_strncmp(buf, "SET_QOS_MAP_SET ", 16) == 0) {
2394                 if (hostapd_ctrl_iface_set_qos_map_set(hapd, buf + 16))
2395                         reply_len = -1;
2396         } else if (os_strncmp(buf, "SEND_QOS_MAP_CONF ", 18) == 0) {
2397                 if (hostapd_ctrl_iface_send_qos_map_conf(hapd, buf + 18))
2398                         reply_len = -1;
2399 #endif /* CONFIG_INTERWORKING */
2400 #ifdef CONFIG_HS20
2401         } else if (os_strncmp(buf, "HS20_WNM_NOTIF ", 15) == 0) {
2402                 if (hostapd_ctrl_iface_hs20_wnm_notif(hapd, buf + 15))
2403                         reply_len = -1;
2404         } else if (os_strncmp(buf, "HS20_DEAUTH_REQ ", 16) == 0) {
2405                 if (hostapd_ctrl_iface_hs20_deauth_req(hapd, buf + 16))
2406                         reply_len = -1;
2407 #endif /* CONFIG_HS20 */
2408 #ifdef CONFIG_WNM
2409         } else if (os_strncmp(buf, "DISASSOC_IMMINENT ", 18) == 0) {
2410                 if (hostapd_ctrl_iface_disassoc_imminent(hapd, buf + 18))
2411                         reply_len = -1;
2412         } else if (os_strncmp(buf, "ESS_DISASSOC ", 13) == 0) {
2413                 if (hostapd_ctrl_iface_ess_disassoc(hapd, buf + 13))
2414                         reply_len = -1;
2415         } else if (os_strncmp(buf, "BSS_TM_REQ ", 11) == 0) {
2416                 if (hostapd_ctrl_iface_bss_tm_req(hapd, buf + 11))
2417                         reply_len = -1;
2418 #endif /* CONFIG_WNM */
2419         } else if (os_strcmp(buf, "GET_CONFIG") == 0) {
2420                 reply_len = hostapd_ctrl_iface_get_config(hapd, reply,
2421                                                           reply_size);
2422         } else if (os_strncmp(buf, "SET ", 4) == 0) {
2423                 if (hostapd_ctrl_iface_set(hapd, buf + 4))
2424                         reply_len = -1;
2425         } else if (os_strncmp(buf, "GET ", 4) == 0) {
2426                 reply_len = hostapd_ctrl_iface_get(hapd, buf + 4, reply,
2427                                                    reply_size);
2428         } else if (os_strncmp(buf, "ENABLE", 6) == 0) {
2429                 if (hostapd_ctrl_iface_enable(hapd->iface))
2430                         reply_len = -1;
2431         } else if (os_strncmp(buf, "RELOAD", 6) == 0) {
2432                 if (hostapd_ctrl_iface_reload(hapd->iface))
2433                         reply_len = -1;
2434         } else if (os_strncmp(buf, "DISABLE", 7) == 0) {
2435                 if (hostapd_ctrl_iface_disable(hapd->iface))
2436                         reply_len = -1;
2437         } else if (os_strcmp(buf, "UPDATE_BEACON") == 0) {
2438                 if (ieee802_11_set_beacon(hapd))
2439                         reply_len = -1;
2440 #ifdef CONFIG_TESTING_OPTIONS
2441         } else if (os_strncmp(buf, "RADAR ", 6) == 0) {
2442                 if (hostapd_ctrl_iface_radar(hapd, buf + 6))
2443                         reply_len = -1;
2444         } else if (os_strncmp(buf, "MGMT_TX ", 8) == 0) {
2445                 if (hostapd_ctrl_iface_mgmt_tx(hapd, buf + 8))
2446                         reply_len = -1;
2447         } else if (os_strncmp(buf, "EAPOL_RX ", 9) == 0) {
2448                 if (hostapd_ctrl_iface_eapol_rx(hapd, buf + 9) < 0)
2449                         reply_len = -1;
2450         } else if (os_strncmp(buf, "DATA_TEST_CONFIG ", 17) == 0) {
2451                 if (hostapd_ctrl_iface_data_test_config(hapd, buf + 17) < 0)
2452                         reply_len = -1;
2453         } else if (os_strncmp(buf, "DATA_TEST_TX ", 13) == 0) {
2454                 if (hostapd_ctrl_iface_data_test_tx(hapd, buf + 13) < 0)
2455                         reply_len = -1;
2456         } else if (os_strncmp(buf, "DATA_TEST_FRAME ", 16) == 0) {
2457                 if (hostapd_ctrl_iface_data_test_frame(hapd, buf + 16) < 0)
2458                         reply_len = -1;
2459         } else if (os_strncmp(buf, "TEST_ALLOC_FAIL ", 16) == 0) {
2460                 if (hostapd_ctrl_test_alloc_fail(hapd, buf + 16) < 0)
2461                         reply_len = -1;
2462         } else if (os_strcmp(buf, "GET_ALLOC_FAIL") == 0) {
2463                 reply_len = hostapd_ctrl_get_alloc_fail(hapd, reply,
2464                                                         reply_size);
2465         } else if (os_strncmp(buf, "TEST_FAIL ", 10) == 0) {
2466                 if (hostapd_ctrl_test_fail(hapd, buf + 10) < 0)
2467                         reply_len = -1;
2468         } else if (os_strcmp(buf, "GET_FAIL") == 0) {
2469                 reply_len = hostapd_ctrl_get_fail(hapd, reply, reply_size);
2470 #endif /* CONFIG_TESTING_OPTIONS */
2471         } else if (os_strncmp(buf, "CHAN_SWITCH ", 12) == 0) {
2472                 if (hostapd_ctrl_iface_chan_switch(hapd->iface, buf + 12))
2473                         reply_len = -1;
2474         } else if (os_strncmp(buf, "VENDOR ", 7) == 0) {
2475                 reply_len = hostapd_ctrl_iface_vendor(hapd, buf + 7, reply,
2476                                                       reply_size);
2477         } else if (os_strcmp(buf, "ERP_FLUSH") == 0) {
2478                 ieee802_1x_erp_flush(hapd);
2479 #ifdef RADIUS_SERVER
2480                 radius_server_erp_flush(hapd->radius_srv);
2481 #endif /* RADIUS_SERVER */
2482         } else if (os_strncmp(buf, "EAPOL_REAUTH ", 13) == 0) {
2483                 if (hostapd_ctrl_iface_eapol_reauth(hapd, buf + 13))
2484                         reply_len = -1;
2485         } else if (os_strncmp(buf, "EAPOL_SET ", 10) == 0) {
2486                 if (hostapd_ctrl_iface_eapol_set(hapd, buf + 10))
2487                         reply_len = -1;
2488         } else if (os_strncmp(buf, "LOG_LEVEL", 9) == 0) {
2489                 reply_len = hostapd_ctrl_iface_log_level(
2490                         hapd, buf + 9, reply, reply_size);
2491 #ifdef NEED_AP_MLME
2492         } else if (os_strcmp(buf, "TRACK_STA_LIST") == 0) {
2493                 reply_len = hostapd_ctrl_iface_track_sta_list(
2494                         hapd, reply, reply_size);
2495 #endif /* NEED_AP_MLME */
2496         } else if (os_strcmp(buf, "PMKSA") == 0) {
2497                 reply_len = hostapd_ctrl_iface_pmksa_list(hapd, reply,
2498                                                           reply_size);
2499         } else if (os_strcmp(buf, "PMKSA_FLUSH") == 0) {
2500                 hostapd_ctrl_iface_pmksa_flush(hapd);
2501         } else if (os_strncmp(buf, "SET_NEIGHBOR ", 13) == 0) {
2502                 if (hostapd_ctrl_iface_set_neighbor(hapd, buf + 13))
2503                         reply_len = -1;
2504         } else if (os_strncmp(buf, "REMOVE_NEIGHBOR ", 16) == 0) {
2505                 if (hostapd_ctrl_iface_remove_neighbor(hapd, buf + 16))
2506                         reply_len = -1;
2507         } else if (os_strncmp(buf, "REQ_LCI ", 8) == 0) {
2508                 if (hostapd_ctrl_iface_req_lci(hapd, buf + 8))
2509                         reply_len = -1;
2510         } else if (os_strncmp(buf, "REQ_RANGE ", 10) == 0) {
2511                 if (hostapd_ctrl_iface_req_range(hapd, buf + 10))
2512                         reply_len = -1;
2513         } else {
2514                 os_memcpy(reply, "UNKNOWN COMMAND\n", 16);
2515                 reply_len = 16;
2516         }
2517
2518         if (reply_len < 0) {
2519                 os_memcpy(reply, "FAIL\n", 5);
2520                 reply_len = 5;
2521         }
2522
2523         return reply_len;
2524 }
2525
2526
2527 static void hostapd_ctrl_iface_receive(int sock, void *eloop_ctx,
2528                                        void *sock_ctx)
2529 {
2530         struct hostapd_data *hapd = eloop_ctx;
2531         char buf[4096];
2532         int res;
2533         struct sockaddr_storage from;
2534         socklen_t fromlen = sizeof(from);
2535         char *reply, *pos = buf;
2536         const int reply_size = 4096;
2537         int reply_len;
2538         int level = MSG_DEBUG;
2539 #ifdef CONFIG_CTRL_IFACE_UDP
2540         unsigned char lcookie[COOKIE_LEN];
2541 #endif /* CONFIG_CTRL_IFACE_UDP */
2542
2543         res = recvfrom(sock, buf, sizeof(buf) - 1, 0,
2544                        (struct sockaddr *) &from, &fromlen);
2545         if (res < 0) {
2546                 wpa_printf(MSG_ERROR, "recvfrom(ctrl_iface): %s",
2547                            strerror(errno));
2548                 return;
2549         }
2550         buf[res] = '\0';
2551
2552         reply = os_malloc(reply_size);
2553         if (reply == NULL) {
2554                 if (sendto(sock, "FAIL\n", 5, 0, (struct sockaddr *) &from,
2555                            fromlen) < 0) {
2556                         wpa_printf(MSG_DEBUG, "CTRL: sendto failed: %s",
2557                                    strerror(errno));
2558                 }
2559                 return;
2560         }
2561
2562 #ifdef CONFIG_CTRL_IFACE_UDP
2563         if (os_strcmp(buf, "GET_COOKIE") == 0) {
2564                 os_memcpy(reply, "COOKIE=", 7);
2565                 wpa_snprintf_hex(reply + 7, 2 * COOKIE_LEN + 1,
2566                                  cookie, COOKIE_LEN);
2567                 reply_len = 7 + 2 * COOKIE_LEN;
2568                 goto done;
2569         }
2570
2571         if (os_strncmp(buf, "COOKIE=", 7) != 0 ||
2572             hexstr2bin(buf + 7, lcookie, COOKIE_LEN) < 0) {
2573                 wpa_printf(MSG_DEBUG,
2574                            "CTRL: No cookie in the request - drop request");
2575                 os_free(reply);
2576                 return;
2577         }
2578
2579         if (os_memcmp(cookie, lcookie, COOKIE_LEN) != 0) {
2580                 wpa_printf(MSG_DEBUG,
2581                            "CTRL: Invalid cookie in the request - drop request");
2582                 os_free(reply);
2583                 return;
2584         }
2585
2586         pos = buf + 7 + 2 * COOKIE_LEN;
2587         while (*pos == ' ')
2588                 pos++;
2589 #endif /* CONFIG_CTRL_IFACE_UDP */
2590
2591         if (os_strcmp(pos, "PING") == 0)
2592                 level = MSG_EXCESSIVE;
2593         wpa_hexdump_ascii(level, "RX ctrl_iface", pos, res);
2594
2595         reply_len = hostapd_ctrl_iface_receive_process(hapd, pos,
2596                                                        reply, reply_size,
2597                                                        &from, fromlen);
2598
2599 #ifdef CONFIG_CTRL_IFACE_UDP
2600 done:
2601 #endif /* CONFIG_CTRL_IFACE_UDP */
2602         if (sendto(sock, reply, reply_len, 0, (struct sockaddr *) &from,
2603                    fromlen) < 0) {
2604                 wpa_printf(MSG_DEBUG, "CTRL: sendto failed: %s",
2605                            strerror(errno));
2606         }
2607         os_free(reply);
2608 }
2609
2610
2611 #ifndef CONFIG_CTRL_IFACE_UDP
2612 static char * hostapd_ctrl_iface_path(struct hostapd_data *hapd)
2613 {
2614         char *buf;
2615         size_t len;
2616
2617         if (hapd->conf->ctrl_interface == NULL)
2618                 return NULL;
2619
2620         len = os_strlen(hapd->conf->ctrl_interface) +
2621                 os_strlen(hapd->conf->iface) + 2;
2622         buf = os_malloc(len);
2623         if (buf == NULL)
2624                 return NULL;
2625
2626         os_snprintf(buf, len, "%s/%s",
2627                     hapd->conf->ctrl_interface, hapd->conf->iface);
2628         buf[len - 1] = '\0';
2629         return buf;
2630 }
2631 #endif /* CONFIG_CTRL_IFACE_UDP */
2632
2633
2634 static void hostapd_ctrl_iface_msg_cb(void *ctx, int level,
2635                                       enum wpa_msg_type type,
2636                                       const char *txt, size_t len)
2637 {
2638         struct hostapd_data *hapd = ctx;
2639         if (hapd == NULL)
2640                 return;
2641         hostapd_ctrl_iface_send(hapd, level, type, txt, len);
2642 }
2643
2644
2645 int hostapd_ctrl_iface_init(struct hostapd_data *hapd)
2646 {
2647 #ifdef CONFIG_CTRL_IFACE_UDP
2648         int port = HOSTAPD_CTRL_IFACE_PORT;
2649         char p[32] = { 0 };
2650         char port_str[40], *tmp;
2651         char *pos;
2652         struct addrinfo hints = { 0 }, *res, *saveres;
2653         int n;
2654
2655         if (hapd->ctrl_sock > -1) {
2656                 wpa_printf(MSG_DEBUG, "ctrl_iface already exists!");
2657                 return 0;
2658         }
2659
2660         if (hapd->conf->ctrl_interface == NULL)
2661                 return 0;
2662
2663         pos = os_strstr(hapd->conf->ctrl_interface, "udp:");
2664         if (pos) {
2665                 pos += 4;
2666                 port = atoi(pos);
2667                 if (port <= 0) {
2668                         wpa_printf(MSG_ERROR, "Invalid ctrl_iface UDP port");
2669                         goto fail;
2670                 }
2671         }
2672
2673         dl_list_init(&hapd->ctrl_dst);
2674         hapd->ctrl_sock = -1;
2675         os_get_random(cookie, COOKIE_LEN);
2676
2677 #ifdef CONFIG_CTRL_IFACE_UDP_REMOTE
2678         hints.ai_flags = AI_PASSIVE;
2679 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
2680
2681 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
2682         hints.ai_family = AF_INET6;
2683 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
2684         hints.ai_family = AF_INET;
2685 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
2686         hints.ai_socktype = SOCK_DGRAM;
2687
2688 try_again:
2689         os_snprintf(p, sizeof(p), "%d", port);
2690         n = getaddrinfo(NULL, p, &hints, &res);
2691         if (n) {
2692                 wpa_printf(MSG_ERROR, "getaddrinfo(): %s", gai_strerror(n));
2693                 goto fail;
2694         }
2695
2696         saveres = res;
2697         hapd->ctrl_sock = socket(res->ai_family, res->ai_socktype,
2698                                  res->ai_protocol);
2699         if (hapd->ctrl_sock < 0) {
2700                 wpa_printf(MSG_ERROR, "socket(PF_INET): %s", strerror(errno));
2701                 goto fail;
2702         }
2703
2704         if (bind(hapd->ctrl_sock, res->ai_addr, res->ai_addrlen) < 0) {
2705                 port--;
2706                 if ((HOSTAPD_CTRL_IFACE_PORT - port) <
2707                     HOSTAPD_CTRL_IFACE_PORT_LIMIT && !pos)
2708                         goto try_again;
2709                 wpa_printf(MSG_ERROR, "bind(AF_INET): %s", strerror(errno));
2710                 goto fail;
2711         }
2712
2713         freeaddrinfo(saveres);
2714
2715         os_snprintf(port_str, sizeof(port_str), "udp:%d", port);
2716         tmp = os_strdup(port_str);
2717         if (tmp) {
2718                 os_free(hapd->conf->ctrl_interface);
2719                 hapd->conf->ctrl_interface = tmp;
2720         }
2721         wpa_printf(MSG_DEBUG, "ctrl_iface_init UDP port: %d", port);
2722
2723         if (eloop_register_read_sock(hapd->ctrl_sock,
2724                                      hostapd_ctrl_iface_receive, hapd, NULL) <
2725             0) {
2726                 hostapd_ctrl_iface_deinit(hapd);
2727                 return -1;
2728         }
2729
2730         hapd->msg_ctx = hapd;
2731         wpa_msg_register_cb(hostapd_ctrl_iface_msg_cb);
2732
2733         return 0;
2734
2735 fail:
2736         if (hapd->ctrl_sock >= 0)
2737                 close(hapd->ctrl_sock);
2738         return -1;
2739 #else /* CONFIG_CTRL_IFACE_UDP */
2740         struct sockaddr_un addr;
2741         int s = -1;
2742         char *fname = NULL;
2743
2744         if (hapd->ctrl_sock > -1) {
2745                 wpa_printf(MSG_DEBUG, "ctrl_iface already exists!");
2746                 return 0;
2747         }
2748
2749         dl_list_init(&hapd->ctrl_dst);
2750
2751         if (hapd->conf->ctrl_interface == NULL)
2752                 return 0;
2753
2754         if (mkdir(hapd->conf->ctrl_interface, S_IRWXU | S_IRWXG) < 0) {
2755                 if (errno == EEXIST) {
2756                         wpa_printf(MSG_DEBUG, "Using existing control "
2757                                    "interface directory.");
2758                 } else {
2759                         wpa_printf(MSG_ERROR, "mkdir[ctrl_interface]: %s",
2760                                    strerror(errno));
2761                         goto fail;
2762                 }
2763         }
2764
2765         if (hapd->conf->ctrl_interface_gid_set &&
2766             chown(hapd->conf->ctrl_interface, -1,
2767                   hapd->conf->ctrl_interface_gid) < 0) {
2768                 wpa_printf(MSG_ERROR, "chown[ctrl_interface]: %s",
2769                            strerror(errno));
2770                 return -1;
2771         }
2772
2773         if (!hapd->conf->ctrl_interface_gid_set &&
2774             hapd->iface->interfaces->ctrl_iface_group &&
2775             chown(hapd->conf->ctrl_interface, -1,
2776                   hapd->iface->interfaces->ctrl_iface_group) < 0) {
2777                 wpa_printf(MSG_ERROR, "chown[ctrl_interface]: %s",
2778                            strerror(errno));
2779                 return -1;
2780         }
2781
2782 #ifdef ANDROID
2783         /*
2784          * Android is using umask 0077 which would leave the control interface
2785          * directory without group access. This breaks things since Wi-Fi
2786          * framework assumes that this directory can be accessed by other
2787          * applications in the wifi group. Fix this by adding group access even
2788          * if umask value would prevent this.
2789          */
2790         if (chmod(hapd->conf->ctrl_interface, S_IRWXU | S_IRWXG) < 0) {
2791                 wpa_printf(MSG_ERROR, "CTRL: Could not chmod directory: %s",
2792                            strerror(errno));
2793                 /* Try to continue anyway */
2794         }
2795 #endif /* ANDROID */
2796
2797         if (os_strlen(hapd->conf->ctrl_interface) + 1 +
2798             os_strlen(hapd->conf->iface) >= sizeof(addr.sun_path))
2799                 goto fail;
2800
2801         s = socket(PF_UNIX, SOCK_DGRAM, 0);
2802         if (s < 0) {
2803                 wpa_printf(MSG_ERROR, "socket(PF_UNIX): %s", strerror(errno));
2804                 goto fail;
2805         }
2806
2807         os_memset(&addr, 0, sizeof(addr));
2808 #ifdef __FreeBSD__
2809         addr.sun_len = sizeof(addr);
2810 #endif /* __FreeBSD__ */
2811         addr.sun_family = AF_UNIX;
2812         fname = hostapd_ctrl_iface_path(hapd);
2813         if (fname == NULL)
2814                 goto fail;
2815         os_strlcpy(addr.sun_path, fname, sizeof(addr.sun_path));
2816         if (bind(s, (struct sockaddr *) &addr, sizeof(addr)) < 0) {
2817                 wpa_printf(MSG_DEBUG, "ctrl_iface bind(PF_UNIX) failed: %s",
2818                            strerror(errno));
2819                 if (connect(s, (struct sockaddr *) &addr, sizeof(addr)) < 0) {
2820                         wpa_printf(MSG_DEBUG, "ctrl_iface exists, but does not"
2821                                    " allow connections - assuming it was left"
2822                                    "over from forced program termination");
2823                         if (unlink(fname) < 0) {
2824                                 wpa_printf(MSG_ERROR,
2825                                            "Could not unlink existing ctrl_iface socket '%s': %s",
2826                                            fname, strerror(errno));
2827                                 goto fail;
2828                         }
2829                         if (bind(s, (struct sockaddr *) &addr, sizeof(addr)) <
2830                             0) {
2831                                 wpa_printf(MSG_ERROR,
2832                                            "hostapd-ctrl-iface: bind(PF_UNIX): %s",
2833                                            strerror(errno));
2834                                 goto fail;
2835                         }
2836                         wpa_printf(MSG_DEBUG, "Successfully replaced leftover "
2837                                    "ctrl_iface socket '%s'", fname);
2838                 } else {
2839                         wpa_printf(MSG_INFO, "ctrl_iface exists and seems to "
2840                                    "be in use - cannot override it");
2841                         wpa_printf(MSG_INFO, "Delete '%s' manually if it is "
2842                                    "not used anymore", fname);
2843                         os_free(fname);
2844                         fname = NULL;
2845                         goto fail;
2846                 }
2847         }
2848
2849         if (hapd->conf->ctrl_interface_gid_set &&
2850             chown(fname, -1, hapd->conf->ctrl_interface_gid) < 0) {
2851                 wpa_printf(MSG_ERROR, "chown[ctrl_interface/ifname]: %s",
2852                            strerror(errno));
2853                 goto fail;
2854         }
2855
2856         if (!hapd->conf->ctrl_interface_gid_set &&
2857             hapd->iface->interfaces->ctrl_iface_group &&
2858             chown(fname, -1, hapd->iface->interfaces->ctrl_iface_group) < 0) {
2859                 wpa_printf(MSG_ERROR, "chown[ctrl_interface/ifname]: %s",
2860                            strerror(errno));
2861                 goto fail;
2862         }
2863
2864         if (chmod(fname, S_IRWXU | S_IRWXG) < 0) {
2865                 wpa_printf(MSG_ERROR, "chmod[ctrl_interface/ifname]: %s",
2866                            strerror(errno));
2867                 goto fail;
2868         }
2869         os_free(fname);
2870
2871         hapd->ctrl_sock = s;
2872         if (eloop_register_read_sock(s, hostapd_ctrl_iface_receive, hapd,
2873                                      NULL) < 0) {
2874                 hostapd_ctrl_iface_deinit(hapd);
2875                 return -1;
2876         }
2877         hapd->msg_ctx = hapd;
2878         wpa_msg_register_cb(hostapd_ctrl_iface_msg_cb);
2879
2880         return 0;
2881
2882 fail:
2883         if (s >= 0)
2884                 close(s);
2885         if (fname) {
2886                 unlink(fname);
2887                 os_free(fname);
2888         }
2889         return -1;
2890 #endif /* CONFIG_CTRL_IFACE_UDP */
2891 }
2892
2893
2894 void hostapd_ctrl_iface_deinit(struct hostapd_data *hapd)
2895 {
2896         struct wpa_ctrl_dst *dst, *prev;
2897
2898         if (hapd->ctrl_sock > -1) {
2899 #ifndef CONFIG_CTRL_IFACE_UDP
2900                 char *fname;
2901 #endif /* !CONFIG_CTRL_IFACE_UDP */
2902
2903                 eloop_unregister_read_sock(hapd->ctrl_sock);
2904                 close(hapd->ctrl_sock);
2905                 hapd->ctrl_sock = -1;
2906 #ifndef CONFIG_CTRL_IFACE_UDP
2907                 fname = hostapd_ctrl_iface_path(hapd);
2908                 if (fname)
2909                         unlink(fname);
2910                 os_free(fname);
2911
2912                 if (hapd->conf->ctrl_interface &&
2913                     rmdir(hapd->conf->ctrl_interface) < 0) {
2914                         if (errno == ENOTEMPTY) {
2915                                 wpa_printf(MSG_DEBUG, "Control interface "
2916                                            "directory not empty - leaving it "
2917                                            "behind");
2918                         } else {
2919                                 wpa_printf(MSG_ERROR,
2920                                            "rmdir[ctrl_interface=%s]: %s",
2921                                            hapd->conf->ctrl_interface,
2922                                            strerror(errno));
2923                         }
2924                 }
2925 #endif /* !CONFIG_CTRL_IFACE_UDP */
2926         }
2927
2928         dl_list_for_each_safe(dst, prev, &hapd->ctrl_dst, struct wpa_ctrl_dst,
2929                               list)
2930                 os_free(dst);
2931
2932 #ifdef CONFIG_TESTING_OPTIONS
2933         l2_packet_deinit(hapd->l2_test);
2934         hapd->l2_test = NULL;
2935 #endif /* CONFIG_TESTING_OPTIONS */
2936 }
2937
2938
2939 static int hostapd_ctrl_iface_add(struct hapd_interfaces *interfaces,
2940                                   char *buf)
2941 {
2942         if (hostapd_add_iface(interfaces, buf) < 0) {
2943                 wpa_printf(MSG_ERROR, "Adding interface %s failed", buf);
2944                 return -1;
2945         }
2946         return 0;
2947 }
2948
2949
2950 static int hostapd_ctrl_iface_remove(struct hapd_interfaces *interfaces,
2951                                      char *buf)
2952 {
2953         if (hostapd_remove_iface(interfaces, buf) < 0) {
2954                 wpa_printf(MSG_ERROR, "Removing interface %s failed", buf);
2955                 return -1;
2956         }
2957         return 0;
2958 }
2959
2960
2961 static int hostapd_global_ctrl_iface_attach(struct hapd_interfaces *interfaces,
2962                                             struct sockaddr_storage *from,
2963                                             socklen_t fromlen)
2964 {
2965         return ctrl_iface_attach(&interfaces->global_ctrl_dst, from, fromlen);
2966 }
2967
2968
2969 static int hostapd_global_ctrl_iface_detach(struct hapd_interfaces *interfaces,
2970                                             struct sockaddr_storage *from,
2971                                             socklen_t fromlen)
2972 {
2973         return ctrl_iface_detach(&interfaces->global_ctrl_dst, from, fromlen);
2974 }
2975
2976
2977 static void hostapd_ctrl_iface_flush(struct hapd_interfaces *interfaces)
2978 {
2979 #ifdef CONFIG_WPS_TESTING
2980         wps_version_number = 0x20;
2981         wps_testing_dummy_cred = 0;
2982         wps_corrupt_pkhash = 0;
2983 #endif /* CONFIG_WPS_TESTING */
2984 }
2985
2986
2987 #ifdef CONFIG_FST
2988
2989 static int
2990 hostapd_global_ctrl_iface_fst_attach(struct hapd_interfaces *interfaces,
2991                                      const char *cmd)
2992 {
2993         char ifname[IFNAMSIZ + 1];
2994         struct fst_iface_cfg cfg;
2995         struct hostapd_data *hapd;
2996         struct fst_wpa_obj iface_obj;
2997
2998         if (!fst_parse_attach_command(cmd, ifname, sizeof(ifname), &cfg)) {
2999                 hapd = hostapd_get_iface(interfaces, ifname);
3000                 if (hapd) {
3001                         if (hapd->iface->fst) {
3002                                 wpa_printf(MSG_INFO, "FST: Already attached");
3003                                 return -1;
3004                         }
3005                         fst_hostapd_fill_iface_obj(hapd, &iface_obj);
3006                         hapd->iface->fst = fst_attach(ifname, hapd->own_addr,
3007                                                       &iface_obj, &cfg);
3008                         if (hapd->iface->fst)
3009                                 return 0;
3010                 }
3011         }
3012
3013         return -EINVAL;
3014 }
3015
3016
3017 static int
3018 hostapd_global_ctrl_iface_fst_detach(struct hapd_interfaces *interfaces,
3019                                      const char *cmd)
3020 {
3021         char ifname[IFNAMSIZ + 1];
3022         struct hostapd_data * hapd;
3023
3024         if (!fst_parse_detach_command(cmd, ifname, sizeof(ifname))) {
3025                 hapd = hostapd_get_iface(interfaces, ifname);
3026                 if (hapd) {
3027                         if (!fst_iface_detach(ifname)) {
3028                                 hapd->iface->fst = NULL;
3029                                 hapd->iface->fst_ies = NULL;
3030                                 return 0;
3031                         }
3032                 }
3033         }
3034
3035         return -EINVAL;
3036 }
3037
3038 #endif /* CONFIG_FST */
3039
3040
3041 static struct hostapd_data *
3042 hostapd_interfaces_get_hapd(struct hapd_interfaces *interfaces,
3043                             const char *ifname)
3044 {
3045         size_t i, j;
3046
3047         for (i = 0; i < interfaces->count; i++) {
3048                 struct hostapd_iface *iface = interfaces->iface[i];
3049
3050                 for (j = 0; j < iface->num_bss; j++) {
3051                         struct hostapd_data *hapd;
3052
3053                         hapd = iface->bss[j];
3054                         if (os_strcmp(ifname, hapd->conf->iface) == 0)
3055                                 return hapd;
3056                 }
3057         }
3058
3059         return NULL;
3060 }
3061
3062
3063 static int hostapd_ctrl_iface_dup_param(struct hostapd_data *src_hapd,
3064                                         struct hostapd_data *dst_hapd,
3065                                         const char *param)
3066 {
3067         int res;
3068         char *value;
3069
3070         value = os_zalloc(HOSTAPD_CLI_DUP_VALUE_MAX_LEN);
3071         if (!value) {
3072                 wpa_printf(MSG_ERROR,
3073                            "DUP: cannot allocate buffer to stringify %s",
3074                            param);
3075                 goto error_return;
3076         }
3077
3078         if (os_strcmp(param, "wpa") == 0) {
3079                 os_snprintf(value, HOSTAPD_CLI_DUP_VALUE_MAX_LEN, "%d",
3080                             src_hapd->conf->wpa);
3081         } else if (os_strcmp(param, "wpa_key_mgmt") == 0 &&
3082                    src_hapd->conf->wpa_key_mgmt) {
3083                 res = hostapd_ctrl_iface_get_key_mgmt(
3084                         src_hapd, value, HOSTAPD_CLI_DUP_VALUE_MAX_LEN);
3085                 if (os_snprintf_error(HOSTAPD_CLI_DUP_VALUE_MAX_LEN, res))
3086                         goto error_stringify;
3087         } else if (os_strcmp(param, "wpa_pairwise") == 0 &&
3088                    src_hapd->conf->wpa_pairwise) {
3089                 res = wpa_write_ciphers(value,
3090                                         value + HOSTAPD_CLI_DUP_VALUE_MAX_LEN,
3091                                         src_hapd->conf->wpa_pairwise, " ");
3092                 if (res < 0)
3093                         goto error_stringify;
3094         } else if (os_strcmp(param, "rsn_pairwise") == 0 &&
3095                    src_hapd->conf->rsn_pairwise) {
3096                 res = wpa_write_ciphers(value,
3097                                         value + HOSTAPD_CLI_DUP_VALUE_MAX_LEN,
3098                                         src_hapd->conf->rsn_pairwise, " ");
3099                 if (res < 0)
3100                         goto error_stringify;
3101         } else if (os_strcmp(param, "wpa_passphrase") == 0 &&
3102                    src_hapd->conf->ssid.wpa_passphrase) {
3103                 os_snprintf(value, HOSTAPD_CLI_DUP_VALUE_MAX_LEN, "%s",
3104                             src_hapd->conf->ssid.wpa_passphrase);
3105         } else if (os_strcmp(param, "wpa_psk") == 0 &&
3106                    src_hapd->conf->ssid.wpa_psk_set) {
3107                 wpa_snprintf_hex(value, HOSTAPD_CLI_DUP_VALUE_MAX_LEN,
3108                         src_hapd->conf->ssid.wpa_psk->psk, PMK_LEN);
3109         } else {
3110                 wpa_printf(MSG_WARNING, "DUP: %s cannot be duplicated", param);
3111                 goto error_return;
3112         }
3113
3114         res = hostapd_set_iface(dst_hapd->iconf, dst_hapd->conf, param, value);
3115         os_free(value);
3116         return res;
3117
3118 error_stringify:
3119         wpa_printf(MSG_ERROR, "DUP: cannot stringify %s", param);
3120 error_return:
3121         os_free(value);
3122         return -1;
3123 }
3124
3125
3126 static int
3127 hostapd_global_ctrl_iface_interfaces(struct hapd_interfaces *interfaces,
3128                                      const char *input,
3129                                      char *reply, int reply_size)
3130 {
3131         size_t i, j;
3132         int res;
3133         char *pos, *end;
3134         struct hostapd_iface *iface;
3135         int show_ctrl = 0;
3136
3137         if (input)
3138                 show_ctrl = !!os_strstr(input, "ctrl");
3139
3140         pos = reply;
3141         end = reply + reply_size;
3142
3143         for (i = 0; i < interfaces->count; i++) {
3144                 iface = interfaces->iface[i];
3145
3146                 for (j = 0; j < iface->num_bss; j++) {
3147                         struct hostapd_bss_config *conf;
3148
3149                         conf = iface->conf->bss[j];
3150                         if (show_ctrl)
3151                                 res = os_snprintf(pos, end - pos,
3152                                                   "%s ctrl_iface=%s\n",
3153                                                   conf->iface,
3154                                                   conf->ctrl_interface ?
3155                                                   conf->ctrl_interface : "N/A");
3156                         else
3157                                 res = os_snprintf(pos, end - pos, "%s\n",
3158                                                   conf->iface);
3159                         if (os_snprintf_error(end - pos, res)) {
3160                                 *pos = '\0';
3161                                 return pos - reply;
3162                         }
3163                         pos += res;
3164                 }
3165         }
3166
3167         return pos - reply;
3168 }
3169
3170
3171 static int
3172 hostapd_global_ctrl_iface_dup_network(struct hapd_interfaces *interfaces,
3173                                       char *cmd)
3174 {
3175         char *p_start = cmd, *p_end;
3176         struct hostapd_data *src_hapd, *dst_hapd;
3177
3178         /* cmd: "<src ifname> <dst ifname> <variable name> */
3179
3180         p_end = os_strchr(p_start, ' ');
3181         if (!p_end) {
3182                 wpa_printf(MSG_ERROR, "DUP: no src ifname found in cmd: '%s'",
3183                            cmd);
3184                 return -1;
3185         }
3186
3187         *p_end = '\0';
3188         src_hapd = hostapd_interfaces_get_hapd(interfaces, p_start);
3189         if (!src_hapd) {
3190                 wpa_printf(MSG_ERROR, "DUP: no src ifname found: '%s'",
3191                            p_start);
3192                 return -1;
3193         }
3194
3195         p_start = p_end + 1;
3196         p_end = os_strchr(p_start, ' ');
3197         if (!p_end) {
3198                 wpa_printf(MSG_ERROR, "DUP: no dst ifname found in cmd: '%s'",
3199                            cmd);
3200                 return -1;
3201         }
3202
3203         *p_end = '\0';
3204         dst_hapd = hostapd_interfaces_get_hapd(interfaces, p_start);
3205         if (!dst_hapd) {
3206                 wpa_printf(MSG_ERROR, "DUP: no dst ifname found: '%s'",
3207                            p_start);
3208                 return -1;
3209         }
3210
3211         p_start = p_end + 1;
3212         return hostapd_ctrl_iface_dup_param(src_hapd, dst_hapd, p_start);
3213 }
3214
3215
3216 static int hostapd_global_ctrl_iface_ifname(struct hapd_interfaces *interfaces,
3217                                             const char *ifname,
3218                                             char *buf, char *reply,
3219                                             int reply_size,
3220                                             struct sockaddr_storage *from,
3221                                             socklen_t fromlen)
3222 {
3223         struct hostapd_data *hapd;
3224
3225         hapd = hostapd_interfaces_get_hapd(interfaces, ifname);
3226         if (hapd == NULL) {
3227                 int res;
3228
3229                 res = os_snprintf(reply, reply_size, "FAIL-NO-IFNAME-MATCH\n");
3230                 if (os_snprintf_error(reply_size, res))
3231                         return -1;
3232                 return res;
3233         }
3234
3235         return hostapd_ctrl_iface_receive_process(hapd, buf, reply,reply_size,
3236                                                   from, fromlen);
3237 }
3238
3239
3240 static void hostapd_global_ctrl_iface_receive(int sock, void *eloop_ctx,
3241                                               void *sock_ctx)
3242 {
3243         void *interfaces = eloop_ctx;
3244         char buffer[256], *buf = buffer;
3245         int res;
3246         struct sockaddr_storage from;
3247         socklen_t fromlen = sizeof(from);
3248         char *reply;
3249         int reply_len;
3250         const int reply_size = 4096;
3251 #ifdef CONFIG_CTRL_IFACE_UDP
3252         unsigned char lcookie[COOKIE_LEN];
3253 #endif /* CONFIG_CTRL_IFACE_UDP */
3254
3255         res = recvfrom(sock, buffer, sizeof(buffer) - 1, 0,
3256                        (struct sockaddr *) &from, &fromlen);
3257         if (res < 0) {
3258                 wpa_printf(MSG_ERROR, "recvfrom(ctrl_iface): %s",
3259                            strerror(errno));
3260                 return;
3261         }
3262         buf[res] = '\0';
3263         wpa_printf(MSG_DEBUG, "Global ctrl_iface command: %s", buf);
3264
3265         reply = os_malloc(reply_size);
3266         if (reply == NULL) {
3267                 if (sendto(sock, "FAIL\n", 5, 0, (struct sockaddr *) &from,
3268                            fromlen) < 0) {
3269                         wpa_printf(MSG_DEBUG, "CTRL: sendto failed: %s",
3270                                    strerror(errno));
3271                 }
3272                 return;
3273         }
3274
3275         os_memcpy(reply, "OK\n", 3);
3276         reply_len = 3;
3277
3278 #ifdef CONFIG_CTRL_IFACE_UDP
3279         if (os_strcmp(buf, "GET_COOKIE") == 0) {
3280                 os_memcpy(reply, "COOKIE=", 7);
3281                 wpa_snprintf_hex(reply + 7, 2 * COOKIE_LEN + 1,
3282                                  gcookie, COOKIE_LEN);
3283                 reply_len = 7 + 2 * COOKIE_LEN;
3284                 goto send_reply;
3285         }
3286
3287         if (os_strncmp(buf, "COOKIE=", 7) != 0 ||
3288             hexstr2bin(buf + 7, lcookie, COOKIE_LEN) < 0) {
3289                 wpa_printf(MSG_DEBUG,
3290                            "CTRL: No cookie in the request - drop request");
3291                 os_free(reply);
3292                 return;
3293         }
3294
3295         if (os_memcmp(gcookie, lcookie, COOKIE_LEN) != 0) {
3296                 wpa_printf(MSG_DEBUG,
3297                            "CTRL: Invalid cookie in the request - drop request");
3298                 os_free(reply);
3299                 return;
3300         }
3301
3302         buf += 7 + 2 * COOKIE_LEN;
3303         while (*buf == ' ')
3304                 buf++;
3305 #endif /* CONFIG_CTRL_IFACE_UDP */
3306
3307         if (os_strncmp(buf, "IFNAME=", 7) == 0) {
3308                 char *pos = os_strchr(buf + 7, ' ');
3309
3310                 if (pos) {
3311                         *pos++ = '\0';
3312                         reply_len = hostapd_global_ctrl_iface_ifname(
3313                                 interfaces, buf + 7, pos, reply, reply_size,
3314                                 &from, fromlen);
3315                         goto send_reply;
3316                 }
3317         }
3318
3319         if (os_strcmp(buf, "PING") == 0) {
3320                 os_memcpy(reply, "PONG\n", 5);
3321                 reply_len = 5;
3322         } else if (os_strncmp(buf, "RELOG", 5) == 0) {
3323                 if (wpa_debug_reopen_file() < 0)
3324                         reply_len = -1;
3325         } else if (os_strcmp(buf, "FLUSH") == 0) {
3326                 hostapd_ctrl_iface_flush(interfaces);
3327         } else if (os_strncmp(buf, "ADD ", 4) == 0) {
3328                 if (hostapd_ctrl_iface_add(interfaces, buf + 4) < 0)
3329                         reply_len = -1;
3330         } else if (os_strncmp(buf, "REMOVE ", 7) == 0) {
3331                 if (hostapd_ctrl_iface_remove(interfaces, buf + 7) < 0)
3332                         reply_len = -1;
3333         } else if (os_strcmp(buf, "ATTACH") == 0) {
3334                 if (hostapd_global_ctrl_iface_attach(interfaces, &from,
3335                                                      fromlen))
3336                         reply_len = -1;
3337         } else if (os_strcmp(buf, "DETACH") == 0) {
3338                 if (hostapd_global_ctrl_iface_detach(interfaces, &from,
3339                         fromlen))
3340                         reply_len = -1;
3341 #ifdef CONFIG_MODULE_TESTS
3342         } else if (os_strcmp(buf, "MODULE_TESTS") == 0) {
3343                 if (hapd_module_tests() < 0)
3344                         reply_len = -1;
3345 #endif /* CONFIG_MODULE_TESTS */
3346 #ifdef CONFIG_FST
3347         } else if (os_strncmp(buf, "FST-ATTACH ", 11) == 0) {
3348                 if (!hostapd_global_ctrl_iface_fst_attach(interfaces, buf + 11))
3349                         reply_len = os_snprintf(reply, reply_size, "OK\n");
3350                 else
3351                         reply_len = -1;
3352         } else if (os_strncmp(buf, "FST-DETACH ", 11) == 0) {
3353                 if (!hostapd_global_ctrl_iface_fst_detach(interfaces, buf + 11))
3354                         reply_len = os_snprintf(reply, reply_size, "OK\n");
3355                 else
3356                         reply_len = -1;
3357         } else if (os_strncmp(buf, "FST-MANAGER ", 12) == 0) {
3358                 reply_len = fst_ctrl_iface_receive(buf + 12, reply, reply_size);
3359 #endif /* CONFIG_FST */
3360         } else if (os_strncmp(buf, "DUP_NETWORK ", 12) == 0) {
3361                 if (!hostapd_global_ctrl_iface_dup_network(interfaces,
3362                                                            buf + 12))
3363                         reply_len = os_snprintf(reply, reply_size, "OK\n");
3364                 else
3365                         reply_len = -1;
3366         } else if (os_strncmp(buf, "INTERFACES", 10) == 0) {
3367                 reply_len = hostapd_global_ctrl_iface_interfaces(
3368                         interfaces, buf + 10, reply, sizeof(buffer));
3369         } else if (os_strcmp(buf, "TERMINATE") == 0) {
3370                 eloop_terminate();
3371         } else {
3372                 wpa_printf(MSG_DEBUG, "Unrecognized global ctrl_iface command "
3373                            "ignored");
3374                 reply_len = -1;
3375         }
3376
3377 send_reply:
3378         if (reply_len < 0) {
3379                 os_memcpy(reply, "FAIL\n", 5);
3380                 reply_len = 5;
3381         }
3382
3383         if (sendto(sock, reply, reply_len, 0, (struct sockaddr *) &from,
3384                    fromlen) < 0) {
3385                 wpa_printf(MSG_DEBUG, "CTRL: sendto failed: %s",
3386                            strerror(errno));
3387         }
3388         os_free(reply);
3389 }
3390
3391
3392 #ifndef CONFIG_CTRL_IFACE_UDP
3393 static char * hostapd_global_ctrl_iface_path(struct hapd_interfaces *interface)
3394 {
3395         char *buf;
3396         size_t len;
3397
3398         if (interface->global_iface_path == NULL)
3399                 return NULL;
3400
3401         len = os_strlen(interface->global_iface_path) +
3402                 os_strlen(interface->global_iface_name) + 2;
3403         buf = os_malloc(len);
3404         if (buf == NULL)
3405                 return NULL;
3406
3407         os_snprintf(buf, len, "%s/%s", interface->global_iface_path,
3408                     interface->global_iface_name);
3409         buf[len - 1] = '\0';
3410         return buf;
3411 }
3412 #endif /* CONFIG_CTRL_IFACE_UDP */
3413
3414
3415 int hostapd_global_ctrl_iface_init(struct hapd_interfaces *interface)
3416 {
3417 #ifdef CONFIG_CTRL_IFACE_UDP
3418         int port = HOSTAPD_GLOBAL_CTRL_IFACE_PORT;
3419         char p[32] = { 0 };
3420         char *pos;
3421         struct addrinfo hints = { 0 }, *res, *saveres;
3422         int n;
3423
3424         if (interface->global_ctrl_sock > -1) {
3425                 wpa_printf(MSG_DEBUG, "ctrl_iface already exists!");
3426                 return 0;
3427         }
3428
3429         if (interface->global_iface_path == NULL)
3430                 return 0;
3431
3432         pos = os_strstr(interface->global_iface_path, "udp:");
3433         if (pos) {
3434                 pos += 4;
3435                 port = atoi(pos);
3436                 if (port <= 0) {
3437                         wpa_printf(MSG_ERROR, "Invalid global ctrl UDP port");
3438                         goto fail;
3439                 }
3440         }
3441
3442         dl_list_init(&interface->global_ctrl_dst);
3443         interface->global_ctrl_sock = -1;
3444         os_get_random(gcookie, COOKIE_LEN);
3445
3446 #ifdef CONFIG_CTRL_IFACE_UDP_REMOTE
3447         hints.ai_flags = AI_PASSIVE;
3448 #endif /* CONFIG_CTRL_IFACE_UDP_REMOTE */
3449
3450 #ifdef CONFIG_CTRL_IFACE_UDP_IPV6
3451         hints.ai_family = AF_INET6;
3452 #else /* CONFIG_CTRL_IFACE_UDP_IPV6 */
3453         hints.ai_family = AF_INET;
3454 #endif /* CONFIG_CTRL_IFACE_UDP_IPV6 */
3455         hints.ai_socktype = SOCK_DGRAM;
3456
3457 try_again:
3458         os_snprintf(p, sizeof(p), "%d", port);
3459         n = getaddrinfo(NULL, p, &hints, &res);
3460         if (n) {
3461                 wpa_printf(MSG_ERROR, "getaddrinfo(): %s", gai_strerror(n));
3462                 goto fail;
3463         }
3464
3465         saveres = res;
3466         interface->global_ctrl_sock = socket(res->ai_family, res->ai_socktype,
3467                                              res->ai_protocol);
3468         if (interface->global_ctrl_sock < 0) {
3469                 wpa_printf(MSG_ERROR, "socket(PF_INET): %s", strerror(errno));
3470                 goto fail;
3471         }
3472
3473         if (bind(interface->global_ctrl_sock, res->ai_addr, res->ai_addrlen) <
3474             0) {
3475                 port++;
3476                 if ((port - HOSTAPD_GLOBAL_CTRL_IFACE_PORT) <
3477                     HOSTAPD_GLOBAL_CTRL_IFACE_PORT_LIMIT && !pos)
3478                         goto try_again;
3479                 wpa_printf(MSG_ERROR, "bind(AF_INET): %s", strerror(errno));
3480                 goto fail;
3481         }
3482
3483         freeaddrinfo(saveres);
3484
3485         wpa_printf(MSG_DEBUG, "global ctrl_iface_init UDP port: %d", port);
3486
3487         if (eloop_register_read_sock(interface->global_ctrl_sock,
3488                                      hostapd_global_ctrl_iface_receive,
3489                                      interface, NULL) < 0) {
3490                 hostapd_global_ctrl_iface_deinit(interface);
3491                 return -1;
3492         }
3493
3494         return 0;
3495
3496 fail:
3497         if (interface->global_ctrl_sock >= 0)
3498                 close(interface->global_ctrl_sock);
3499         return -1;
3500 #else /* CONFIG_CTRL_IFACE_UDP */
3501         struct sockaddr_un addr;
3502         int s = -1;
3503         char *fname = NULL;
3504
3505         if (interface->global_iface_path == NULL) {
3506                 wpa_printf(MSG_DEBUG, "ctrl_iface not configured!");
3507                 return 0;
3508         }
3509
3510         if (mkdir(interface->global_iface_path, S_IRWXU | S_IRWXG) < 0) {
3511                 if (errno == EEXIST) {
3512                         wpa_printf(MSG_DEBUG, "Using existing control "
3513                                    "interface directory.");
3514                 } else {
3515                         wpa_printf(MSG_ERROR, "mkdir[ctrl_interface]: %s",
3516                                    strerror(errno));
3517                         goto fail;
3518                 }
3519         } else if (interface->ctrl_iface_group &&
3520                    chown(interface->global_iface_path, -1,
3521                          interface->ctrl_iface_group) < 0) {
3522                 wpa_printf(MSG_ERROR, "chown[ctrl_interface]: %s",
3523                            strerror(errno));
3524                 goto fail;
3525         }
3526
3527         if (os_strlen(interface->global_iface_path) + 1 +
3528             os_strlen(interface->global_iface_name) >= sizeof(addr.sun_path))
3529                 goto fail;
3530
3531         s = socket(PF_UNIX, SOCK_DGRAM, 0);
3532         if (s < 0) {
3533                 wpa_printf(MSG_ERROR, "socket(PF_UNIX): %s", strerror(errno));
3534                 goto fail;
3535         }
3536
3537         os_memset(&addr, 0, sizeof(addr));
3538 #ifdef __FreeBSD__
3539         addr.sun_len = sizeof(addr);
3540 #endif /* __FreeBSD__ */
3541         addr.sun_family = AF_UNIX;
3542         fname = hostapd_global_ctrl_iface_path(interface);
3543         if (fname == NULL)
3544                 goto fail;
3545         os_strlcpy(addr.sun_path, fname, sizeof(addr.sun_path));
3546         if (bind(s, (struct sockaddr *) &addr, sizeof(addr)) < 0) {
3547                 wpa_printf(MSG_DEBUG, "ctrl_iface bind(PF_UNIX) failed: %s",
3548                            strerror(errno));
3549                 if (connect(s, (struct sockaddr *) &addr, sizeof(addr)) < 0) {
3550                         wpa_printf(MSG_DEBUG, "ctrl_iface exists, but does not"
3551                                    " allow connections - assuming it was left"
3552                                    "over from forced program termination");
3553                         if (unlink(fname) < 0) {
3554                                 wpa_printf(MSG_ERROR,
3555                                            "Could not unlink existing ctrl_iface socket '%s': %s",
3556                                            fname, strerror(errno));
3557                                 goto fail;
3558                         }
3559                         if (bind(s, (struct sockaddr *) &addr, sizeof(addr)) <
3560                             0) {
3561                                 wpa_printf(MSG_ERROR, "bind(PF_UNIX): %s",
3562                                            strerror(errno));
3563                                 goto fail;
3564                         }
3565                         wpa_printf(MSG_DEBUG, "Successfully replaced leftover "
3566                                    "ctrl_iface socket '%s'", fname);
3567                 } else {
3568                         wpa_printf(MSG_INFO, "ctrl_iface exists and seems to "
3569                                    "be in use - cannot override it");
3570                         wpa_printf(MSG_INFO, "Delete '%s' manually if it is "
3571                                    "not used anymore", fname);
3572                         os_free(fname);
3573                         fname = NULL;
3574                         goto fail;
3575                 }
3576         }
3577
3578         if (interface->ctrl_iface_group &&
3579             chown(fname, -1, interface->ctrl_iface_group) < 0) {
3580                 wpa_printf(MSG_ERROR, "chown[ctrl_interface]: %s",
3581                            strerror(errno));
3582                 goto fail;
3583         }
3584
3585         if (chmod(fname, S_IRWXU | S_IRWXG) < 0) {
3586                 wpa_printf(MSG_ERROR, "chmod[ctrl_interface/ifname]: %s",
3587                            strerror(errno));
3588                 goto fail;
3589         }
3590         os_free(fname);
3591
3592         interface->global_ctrl_sock = s;
3593         eloop_register_read_sock(s, hostapd_global_ctrl_iface_receive,
3594                                  interface, NULL);
3595
3596         return 0;
3597
3598 fail:
3599         if (s >= 0)
3600                 close(s);
3601         if (fname) {
3602                 unlink(fname);
3603                 os_free(fname);
3604         }
3605         return -1;
3606 #endif /* CONFIG_CTRL_IFACE_UDP */
3607 }
3608
3609
3610 void hostapd_global_ctrl_iface_deinit(struct hapd_interfaces *interfaces)
3611 {
3612 #ifndef CONFIG_CTRL_IFACE_UDP
3613         char *fname = NULL;
3614 #endif /* CONFIG_CTRL_IFACE_UDP */
3615         struct wpa_ctrl_dst *dst, *prev;
3616
3617         if (interfaces->global_ctrl_sock > -1) {
3618                 eloop_unregister_read_sock(interfaces->global_ctrl_sock);
3619                 close(interfaces->global_ctrl_sock);
3620                 interfaces->global_ctrl_sock = -1;
3621 #ifndef CONFIG_CTRL_IFACE_UDP
3622                 fname = hostapd_global_ctrl_iface_path(interfaces);
3623                 if (fname) {
3624                         unlink(fname);
3625                         os_free(fname);
3626                 }
3627
3628                 if (interfaces->global_iface_path &&
3629                     rmdir(interfaces->global_iface_path) < 0) {
3630                         if (errno == ENOTEMPTY) {
3631                                 wpa_printf(MSG_DEBUG, "Control interface "
3632                                            "directory not empty - leaving it "
3633                                            "behind");
3634                         } else {
3635                                 wpa_printf(MSG_ERROR,
3636                                            "rmdir[ctrl_interface=%s]: %s",
3637                                            interfaces->global_iface_path,
3638                                            strerror(errno));
3639                         }
3640                 }
3641 #endif /* CONFIG_CTRL_IFACE_UDP */
3642         }
3643
3644         os_free(interfaces->global_iface_path);
3645         interfaces->global_iface_path = NULL;
3646
3647         dl_list_for_each_safe(dst, prev, &interfaces->global_ctrl_dst,
3648                               struct wpa_ctrl_dst, list)
3649                 os_free(dst);
3650 }
3651
3652
3653 static void hostapd_ctrl_iface_send(struct hostapd_data *hapd, int level,
3654                                     enum wpa_msg_type type,
3655                                     const char *buf, size_t len)
3656 {
3657         struct wpa_ctrl_dst *dst, *next;
3658         struct dl_list *ctrl_dst;
3659         struct msghdr msg;
3660         int idx;
3661         struct iovec io[2];
3662         char levelstr[10];
3663         int s;
3664
3665         if (type != WPA_MSG_ONLY_GLOBAL) {
3666                 s = hapd->ctrl_sock;
3667                 ctrl_dst = &hapd->ctrl_dst;
3668         } else {
3669                 s = hapd->iface->interfaces->global_ctrl_sock;
3670                 ctrl_dst = &hapd->iface->interfaces->global_ctrl_dst;
3671         }
3672
3673         if (s < 0 || dl_list_empty(ctrl_dst))
3674                 return;
3675
3676         os_snprintf(levelstr, sizeof(levelstr), "<%d>", level);
3677         io[0].iov_base = levelstr;
3678         io[0].iov_len = os_strlen(levelstr);
3679         io[1].iov_base = (char *) buf;
3680         io[1].iov_len = len;
3681         os_memset(&msg, 0, sizeof(msg));
3682         msg.msg_iov = io;
3683         msg.msg_iovlen = 2;
3684
3685         idx = 0;
3686         dl_list_for_each_safe(dst, next, ctrl_dst, struct wpa_ctrl_dst, list) {
3687                 if (level >= dst->debug_level) {
3688                         sockaddr_print(MSG_DEBUG, "CTRL_IFACE monitor send",
3689                                        &dst->addr, dst->addrlen);
3690                         msg.msg_name = &dst->addr;
3691                         msg.msg_namelen = dst->addrlen;
3692                         if (sendmsg(s, &msg, 0) < 0) {
3693                                 int _errno = errno;
3694                                 wpa_printf(MSG_INFO, "CTRL_IFACE monitor[%d]: "
3695                                            "%d - %s",
3696                                            idx, errno, strerror(errno));
3697                                 dst->errors++;
3698                                 if (dst->errors > 10 || _errno == ENOENT) {
3699                                         if (type != WPA_MSG_ONLY_GLOBAL)
3700                                                 hostapd_ctrl_iface_detach(
3701                                                         hapd, &dst->addr,
3702                                                         dst->addrlen);
3703                                         else
3704                                                 hostapd_global_ctrl_iface_detach(
3705                                                         hapd->iface->interfaces,
3706                                                         &dst->addr,
3707                                                         dst->addrlen);
3708                                 }
3709                         } else
3710                                 dst->errors = 0;
3711                 }
3712                 idx++;
3713         }
3714 }
3715
3716 #endif /* CONFIG_NATIVE_WINDOWS */