2 * WPA Supplicant - privilege separated driver interface
3 * Copyright (c) 2007-2009, Jouni Malinen <j@w1.fi>
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License version 2 as
7 * published by the Free Software Foundation.
9 * Alternatively, this software may be distributed under the terms of BSD
12 * See README and COPYING for more details.
21 #include "privsep_commands.h"
24 struct wpa_driver_privsep_data {
26 u8 own_addr[ETH_ALEN];
28 char *own_socket_path;
31 struct sockaddr_un priv_addr;
36 static int wpa_priv_reg_cmd(struct wpa_driver_privsep_data *drv, int cmd)
40 res = sendto(drv->priv_socket, &cmd, sizeof(cmd), 0,
41 (struct sockaddr *) &drv->priv_addr,
42 sizeof(drv->priv_addr));
45 return res < 0 ? -1 : 0;
49 static int wpa_priv_cmd(struct wpa_driver_privsep_data *drv, int cmd,
50 const void *data, size_t data_len,
51 void *reply, size_t *reply_len)
56 io[0].iov_base = &cmd;
57 io[0].iov_len = sizeof(cmd);
58 io[1].iov_base = (u8 *) data;
59 io[1].iov_len = data_len;
61 os_memset(&msg, 0, sizeof(msg));
63 msg.msg_iovlen = data ? 2 : 1;
64 msg.msg_name = &drv->priv_addr;
65 msg.msg_namelen = sizeof(drv->priv_addr);
67 if (sendmsg(drv->cmd_socket, &msg, 0) < 0) {
68 perror("sendmsg(cmd_socket)");
78 FD_SET(drv->cmd_socket, &rfds);
81 res = select(drv->cmd_socket + 1, &rfds, NULL, NULL, &tv);
82 if (res < 0 && errno != EINTR) {
87 if (FD_ISSET(drv->cmd_socket, &rfds)) {
88 res = recv(drv->cmd_socket, reply, *reply_len, 0);
95 wpa_printf(MSG_DEBUG, "PRIVSEP: Timeout while waiting "
96 "for reply (cmd=%d)", cmd);
105 static int wpa_driver_privsep_scan(void *priv, const u8 *ssid, size_t ssid_len)
107 struct wpa_driver_privsep_data *drv = priv;
108 wpa_printf(MSG_DEBUG, "%s: priv=%p", __func__, priv);
109 return wpa_priv_cmd(drv, PRIVSEP_CMD_SCAN, ssid, ssid_len,
114 static struct wpa_scan_results *
115 wpa_driver_privsep_get_scan_results2(void *priv)
117 struct wpa_driver_privsep_data *drv = priv;
120 size_t reply_len = 60000;
121 struct wpa_scan_results *results;
122 struct wpa_scan_res *r;
124 buf = os_malloc(reply_len);
127 res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SCAN_RESULTS,
128 NULL, 0, buf, &reply_len);
134 wpa_printf(MSG_DEBUG, "privsep: Received %lu bytes of scan results",
135 (unsigned long) reply_len);
136 if (reply_len < sizeof(int)) {
137 wpa_printf(MSG_DEBUG, "privsep: Invalid scan result len %lu",
138 (unsigned long) reply_len);
144 end = buf + reply_len;
145 os_memcpy(&num, pos, sizeof(int));
146 if (num < 0 || num > 1000) {
152 results = os_zalloc(sizeof(*results));
153 if (results == NULL) {
158 results->res = os_zalloc(num * sizeof(struct wpa_scan_res *));
159 if (results->res == NULL) {
165 while (results->num < (size_t) num && pos + sizeof(int) < end) {
167 os_memcpy(&len, pos, sizeof(int));
169 if (len < 0 || len > 10000 || pos + len > end)
175 os_memcpy(r, pos, len);
177 if (sizeof(*r) + r->ie_len > (size_t) len) {
182 results->res[results->num++] = r;
190 static int wpa_driver_privsep_set_key(const char *ifname, void *priv,
191 wpa_alg alg, const u8 *addr,
192 int key_idx, int set_tx,
193 const u8 *seq, size_t seq_len,
194 const u8 *key, size_t key_len)
196 struct wpa_driver_privsep_data *drv = priv;
197 struct privsep_cmd_set_key cmd;
199 wpa_printf(MSG_DEBUG, "%s: priv=%p alg=%d key_idx=%d set_tx=%d",
200 __func__, priv, alg, key_idx, set_tx);
202 os_memset(&cmd, 0, sizeof(cmd));
205 os_memcpy(cmd.addr, addr, ETH_ALEN);
207 os_memset(cmd.addr, 0xff, ETH_ALEN);
208 cmd.key_idx = key_idx;
210 if (seq && seq_len > 0 && seq_len < sizeof(cmd.seq)) {
211 os_memcpy(cmd.seq, seq, seq_len);
212 cmd.seq_len = seq_len;
214 if (key && key_len > 0 && key_len < sizeof(cmd.key)) {
215 os_memcpy(cmd.key, key, key_len);
216 cmd.key_len = key_len;
219 return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_KEY, &cmd, sizeof(cmd),
224 static int wpa_driver_privsep_associate(
225 void *priv, struct wpa_driver_associate_params *params)
227 struct wpa_driver_privsep_data *drv = priv;
228 struct privsep_cmd_associate *data;
232 wpa_printf(MSG_DEBUG, "%s: priv=%p freq=%d pairwise_suite=%d "
233 "group_suite=%d key_mgmt_suite=%d auth_alg=%d mode=%d",
234 __func__, priv, params->freq, params->pairwise_suite,
235 params->group_suite, params->key_mgmt_suite,
236 params->auth_alg, params->mode);
238 buflen = sizeof(*data) + params->wpa_ie_len;
239 data = os_zalloc(buflen);
244 os_memcpy(data->bssid, params->bssid, ETH_ALEN);
245 os_memcpy(data->ssid, params->ssid, params->ssid_len);
246 data->ssid_len = params->ssid_len;
247 data->freq = params->freq;
248 data->pairwise_suite = params->pairwise_suite;
249 data->group_suite = params->group_suite;
250 data->key_mgmt_suite = params->key_mgmt_suite;
251 data->auth_alg = params->auth_alg;
252 data->mode = params->mode;
253 data->wpa_ie_len = params->wpa_ie_len;
255 os_memcpy(data + 1, params->wpa_ie, params->wpa_ie_len);
256 /* TODO: add support for other assoc parameters */
258 res = wpa_priv_cmd(drv, PRIVSEP_CMD_ASSOCIATE, data, buflen,
266 static int wpa_driver_privsep_get_bssid(void *priv, u8 *bssid)
268 struct wpa_driver_privsep_data *drv = priv;
270 size_t len = ETH_ALEN;
272 res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_BSSID, NULL, 0, bssid, &len);
273 if (res < 0 || len != ETH_ALEN)
279 static int wpa_driver_privsep_get_ssid(void *priv, u8 *ssid)
281 struct wpa_driver_privsep_data *drv = priv;
283 u8 reply[sizeof(int) + 32];
284 size_t len = sizeof(reply);
286 res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_SSID, NULL, 0, reply, &len);
287 if (res < 0 || len < sizeof(int))
289 os_memcpy(&ssid_len, reply, sizeof(int));
290 if (ssid_len < 0 || ssid_len > 32 || sizeof(int) + ssid_len > len) {
291 wpa_printf(MSG_DEBUG, "privsep: Invalid get SSID reply");
294 os_memcpy(ssid, &reply[sizeof(int)], ssid_len);
299 static int wpa_driver_privsep_deauthenticate(void *priv, const u8 *addr,
302 //struct wpa_driver_privsep_data *drv = priv;
303 wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
304 __func__, MAC2STR(addr), reason_code);
305 wpa_printf(MSG_DEBUG, "%s - TODO", __func__);
310 static int wpa_driver_privsep_disassociate(void *priv, const u8 *addr,
313 //struct wpa_driver_privsep_data *drv = priv;
314 wpa_printf(MSG_DEBUG, "%s addr=" MACSTR " reason_code=%d",
315 __func__, MAC2STR(addr), reason_code);
316 wpa_printf(MSG_DEBUG, "%s - TODO", __func__);
321 static void wpa_driver_privsep_event_assoc(void *ctx, wpa_event_type event,
324 union wpa_event_data data;
329 os_memset(&data, 0, sizeof(data));
334 if (end - pos < (int) sizeof(int))
336 os_memcpy(&ie_len, pos, sizeof(int));
338 if (ie_len < 0 || ie_len > end - pos)
341 data.assoc_info.req_ies = pos;
342 data.assoc_info.req_ies_len = ie_len;
347 wpa_supplicant_event(ctx, event, inc_data ? &data : NULL);
351 static void wpa_driver_privsep_event_interface_status(void *ctx, u8 *buf,
354 union wpa_event_data data;
357 if (len < sizeof(int) ||
358 len - sizeof(int) > sizeof(data.interface_status.ifname))
361 os_memcpy(&ievent, buf, sizeof(int));
363 os_memset(&data, 0, sizeof(data));
364 data.interface_status.ievent = ievent;
365 os_memcpy(data.interface_status.ifname, buf + sizeof(int),
367 wpa_supplicant_event(ctx, EVENT_INTERFACE_STATUS, &data);
371 static void wpa_driver_privsep_event_michael_mic_failure(
372 void *ctx, u8 *buf, size_t len)
374 union wpa_event_data data;
376 if (len != sizeof(int))
379 os_memset(&data, 0, sizeof(data));
380 os_memcpy(&data.michael_mic_failure.unicast, buf, sizeof(int));
381 wpa_supplicant_event(ctx, EVENT_MICHAEL_MIC_FAILURE, &data);
385 static void wpa_driver_privsep_event_pmkid_candidate(void *ctx, u8 *buf,
388 union wpa_event_data data;
390 if (len != sizeof(struct pmkid_candidate))
393 os_memset(&data, 0, sizeof(data));
394 os_memcpy(&data.pmkid_candidate, buf, len);
395 wpa_supplicant_event(ctx, EVENT_PMKID_CANDIDATE, &data);
399 static void wpa_driver_privsep_event_stkstart(void *ctx, u8 *buf, size_t len)
401 union wpa_event_data data;
406 os_memset(&data, 0, sizeof(data));
407 os_memcpy(data.stkstart.peer, buf, ETH_ALEN);
408 wpa_supplicant_event(ctx, EVENT_STKSTART, &data);
412 static void wpa_driver_privsep_event_ft_response(void *ctx, u8 *buf,
415 union wpa_event_data data;
417 if (len < sizeof(int) + ETH_ALEN)
420 os_memset(&data, 0, sizeof(data));
421 os_memcpy(&data.ft_ies.ft_action, buf, sizeof(int));
422 os_memcpy(data.ft_ies.target_ap, buf + sizeof(int), ETH_ALEN);
423 data.ft_ies.ies = buf + sizeof(int) + ETH_ALEN;
424 data.ft_ies.ies_len = len - sizeof(int) - ETH_ALEN;
425 wpa_supplicant_event(ctx, EVENT_FT_RESPONSE, &data);
429 static void wpa_driver_privsep_event_rx_eapol(void *ctx, u8 *buf, size_t len)
434 wpa_supplicant_rx_eapol(ctx, buf, buf + ETH_ALEN, len - ETH_ALEN);
438 static void wpa_driver_privsep_event_sta_rx(void *ctx, u8 *buf, size_t len)
440 #ifdef CONFIG_CLIENT_MLME
441 struct ieee80211_rx_status *rx_status;
443 if (len < sizeof(*rx_status))
445 rx_status = (struct ieee80211_rx_status *) buf;
446 buf += sizeof(*rx_status);
447 len -= sizeof(*rx_status);
449 wpa_supplicant_sta_rx(ctx, buf, len, rx_status);
450 #endif /* CONFIG_CLIENT_MLME */
454 static void wpa_driver_privsep_receive(int sock, void *eloop_ctx,
457 struct wpa_driver_privsep_data *drv = eloop_ctx;
461 enum privsep_event e;
462 struct sockaddr_un from;
463 socklen_t fromlen = sizeof(from);
464 const size_t buflen = 2000;
466 buf = os_malloc(buflen);
469 res = recvfrom(sock, buf, buflen, 0,
470 (struct sockaddr *) &from, &fromlen);
472 perror("recvfrom(priv_socket)");
477 wpa_printf(MSG_DEBUG, "privsep_driver: received %u bytes", res);
479 if (res < (int) sizeof(int)) {
480 wpa_printf(MSG_DEBUG, "Too short event message (len=%d)", res);
484 os_memcpy(&event, buf, sizeof(int));
485 event_buf = &buf[sizeof(int)];
486 event_len = res - sizeof(int);
487 wpa_printf(MSG_DEBUG, "privsep: Event %d received (len=%lu)",
488 event, (unsigned long) event_len);
492 case PRIVSEP_EVENT_SCAN_RESULTS:
493 wpa_supplicant_event(drv->ctx, EVENT_SCAN_RESULTS, NULL);
495 case PRIVSEP_EVENT_ASSOC:
496 wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOC,
497 event_buf, event_len);
499 case PRIVSEP_EVENT_DISASSOC:
500 wpa_supplicant_event(drv->ctx, EVENT_DISASSOC, NULL);
502 case PRIVSEP_EVENT_ASSOCINFO:
503 wpa_driver_privsep_event_assoc(drv->ctx, EVENT_ASSOCINFO,
504 event_buf, event_len);
506 case PRIVSEP_EVENT_MICHAEL_MIC_FAILURE:
507 wpa_driver_privsep_event_michael_mic_failure(
508 drv->ctx, event_buf, event_len);
510 case PRIVSEP_EVENT_INTERFACE_STATUS:
511 wpa_driver_privsep_event_interface_status(drv->ctx, event_buf,
514 case PRIVSEP_EVENT_PMKID_CANDIDATE:
515 wpa_driver_privsep_event_pmkid_candidate(drv->ctx, event_buf,
518 case PRIVSEP_EVENT_STKSTART:
519 wpa_driver_privsep_event_stkstart(drv->ctx, event_buf,
522 case PRIVSEP_EVENT_FT_RESPONSE:
523 wpa_driver_privsep_event_ft_response(drv->ctx, event_buf,
526 case PRIVSEP_EVENT_RX_EAPOL:
527 wpa_driver_privsep_event_rx_eapol(drv->ctx, event_buf,
530 case PRIVSEP_EVENT_STA_RX:
531 wpa_driver_privsep_event_sta_rx(drv->ctx, event_buf,
540 static void * wpa_driver_privsep_init(void *ctx, const char *ifname)
542 struct wpa_driver_privsep_data *drv;
544 drv = os_zalloc(sizeof(*drv));
548 drv->priv_socket = -1;
549 drv->cmd_socket = -1;
550 os_strlcpy(drv->ifname, ifname, sizeof(drv->ifname));
556 static void wpa_driver_privsep_deinit(void *priv)
558 struct wpa_driver_privsep_data *drv = priv;
560 if (drv->priv_socket >= 0) {
561 wpa_priv_reg_cmd(drv, PRIVSEP_CMD_UNREGISTER);
562 eloop_unregister_read_sock(drv->priv_socket);
563 close(drv->priv_socket);
566 if (drv->own_socket_path) {
567 unlink(drv->own_socket_path);
568 os_free(drv->own_socket_path);
571 if (drv->cmd_socket >= 0) {
572 eloop_unregister_read_sock(drv->cmd_socket);
573 close(drv->cmd_socket);
576 if (drv->own_cmd_path) {
577 unlink(drv->own_cmd_path);
578 os_free(drv->own_cmd_path);
585 static int wpa_driver_privsep_set_param(void *priv, const char *param)
587 struct wpa_driver_privsep_data *drv = priv;
589 char *own_dir, *priv_dir;
590 static unsigned int counter = 0;
592 struct sockaddr_un addr;
594 wpa_printf(MSG_DEBUG, "%s: param='%s'", __func__, param);
598 pos = os_strstr(param, "own_dir=");
601 own_dir = os_strdup(pos + 8);
604 end = os_strchr(own_dir, ' ');
608 own_dir = os_strdup("/tmp");
616 pos = os_strstr(param, "priv_dir=");
619 priv_dir = os_strdup(pos + 9);
620 if (priv_dir == NULL) {
624 end = os_strchr(priv_dir, ' ');
628 priv_dir = os_strdup("/var/run/wpa_priv");
629 if (priv_dir == NULL) {
635 len = os_strlen(own_dir) + 50;
636 drv->own_socket_path = os_malloc(len);
637 if (drv->own_socket_path == NULL) {
642 os_snprintf(drv->own_socket_path, len, "%s/wpa_privsep-%d-%d",
643 own_dir, getpid(), counter++);
645 len = os_strlen(own_dir) + 50;
646 drv->own_cmd_path = os_malloc(len);
647 if (drv->own_cmd_path == NULL) {
648 os_free(drv->own_socket_path);
649 drv->own_socket_path = NULL;
654 os_snprintf(drv->own_cmd_path, len, "%s/wpa_privsep-%d-%d",
655 own_dir, getpid(), counter++);
659 drv->priv_addr.sun_family = AF_UNIX;
660 os_snprintf(drv->priv_addr.sun_path, sizeof(drv->priv_addr.sun_path),
661 "%s/%s", priv_dir, drv->ifname);
664 drv->priv_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
665 if (drv->priv_socket < 0) {
666 perror("socket(PF_UNIX)");
667 os_free(drv->own_socket_path);
668 drv->own_socket_path = NULL;
672 os_memset(&addr, 0, sizeof(addr));
673 addr.sun_family = AF_UNIX;
674 os_strlcpy(addr.sun_path, drv->own_socket_path, sizeof(addr.sun_path));
675 if (bind(drv->priv_socket, (struct sockaddr *) &addr, sizeof(addr)) <
677 perror("bind(PF_UNIX)");
678 close(drv->priv_socket);
679 drv->priv_socket = -1;
680 unlink(drv->own_socket_path);
681 os_free(drv->own_socket_path);
682 drv->own_socket_path = NULL;
686 eloop_register_read_sock(drv->priv_socket, wpa_driver_privsep_receive,
689 drv->cmd_socket = socket(PF_UNIX, SOCK_DGRAM, 0);
690 if (drv->cmd_socket < 0) {
691 perror("socket(PF_UNIX)");
692 os_free(drv->own_cmd_path);
693 drv->own_cmd_path = NULL;
697 os_memset(&addr, 0, sizeof(addr));
698 addr.sun_family = AF_UNIX;
699 os_strlcpy(addr.sun_path, drv->own_cmd_path, sizeof(addr.sun_path));
700 if (bind(drv->cmd_socket, (struct sockaddr *) &addr, sizeof(addr)) < 0)
702 perror("bind(PF_UNIX)");
703 close(drv->cmd_socket);
704 drv->cmd_socket = -1;
705 unlink(drv->own_cmd_path);
706 os_free(drv->own_cmd_path);
707 drv->own_cmd_path = NULL;
711 if (wpa_priv_reg_cmd(drv, PRIVSEP_CMD_REGISTER) < 0) {
712 wpa_printf(MSG_ERROR, "Failed to register with wpa_priv");
720 static int wpa_driver_privsep_get_capa(void *priv,
721 struct wpa_driver_capa *capa)
723 struct wpa_driver_privsep_data *drv = priv;
725 size_t len = sizeof(*capa);
727 res = wpa_priv_cmd(drv, PRIVSEP_CMD_GET_CAPA, NULL, 0, capa, &len);
728 if (res < 0 || len != sizeof(*capa))
734 static const u8 * wpa_driver_privsep_get_mac_addr(void *priv)
736 struct wpa_driver_privsep_data *drv = priv;
737 wpa_printf(MSG_DEBUG, "%s", __func__);
738 return drv->own_addr;
742 static int wpa_driver_privsep_set_country(void *priv, const char *alpha2)
744 struct wpa_driver_privsep_data *drv = priv;
745 wpa_printf(MSG_DEBUG, "%s country='%s'", __func__, alpha2);
746 return wpa_priv_cmd(drv, PRIVSEP_CMD_SET_COUNTRY, alpha2,
747 os_strlen(alpha2), NULL, NULL);
751 struct wpa_driver_ops wpa_driver_privsep_ops = {
753 "wpa_supplicant privilege separated driver",
754 .get_bssid = wpa_driver_privsep_get_bssid,
755 .get_ssid = wpa_driver_privsep_get_ssid,
756 .set_key = wpa_driver_privsep_set_key,
757 .init = wpa_driver_privsep_init,
758 .deinit = wpa_driver_privsep_deinit,
759 .set_param = wpa_driver_privsep_set_param,
760 .scan = wpa_driver_privsep_scan,
761 .deauthenticate = wpa_driver_privsep_deauthenticate,
762 .disassociate = wpa_driver_privsep_disassociate,
763 .associate = wpa_driver_privsep_associate,
764 .get_capa = wpa_driver_privsep_get_capa,
765 .get_mac_addr = wpa_driver_privsep_get_mac_addr,
766 .get_scan_results2 = wpa_driver_privsep_get_scan_results2,
767 .set_country = wpa_driver_privsep_set_country,
771 struct wpa_driver_ops *wpa_drivers[] =
773 &wpa_driver_privsep_ops,